This is the mail archive of the ecos-bugs@sources.redhat.com mailing list for the eCos project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

[Bug 1000170] SuperH context switch code vulnerable to stack corruption by ISR


http://bugs.ecos.sourceware.org/show_bug.cgi?id=1000170


jifl@ecoscentric.com changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |nickg@ecoscentric.com
             Status|UNCONFIRMED                 |ASSIGNED
     Ever Confirmed|                            |1




------- Additional Comments From jifl@ecoscentric.com  2005-18-04 11:53 -------
While your analysis makes sense, I'm concerned that this may have side-effects.
In particular because then there is a window where we may be handling interrupts
at a level appropriate for the new context (as a consequence of
hal_cpu_int_merge), but still using the stack of the old context, whatever that was.

However, perhaps it would be reasonable to assume that HAL_THREAD_LOAD_CONTEXT
is only ever called when global interrupts are completely disabled in the
current (previous) context. I'm not sure that's a good assumption so I'm CCing
Nick for his opinion.

Certainly the only non-RedBoot context that this macro is actually called from
in the current eCos code itself is from Cyg_Scheduler::start_cpu, so interrupts
will be disabled there at least. But it's a question of what the principle is.
And if interrupts are meant to be disabled, I should probably add that to the
HAL documentation.



------- You are receiving this mail because: -------
You are the QA contact for the bug, or are watching the QA contact.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]