mirror of
https://github.com/PX4/PX4-Autopilot.git
synced 2026-10-06 09:02:52 +08:00
fix(parameters): widen the flashfs working buffer size (#28622)
parameter_flashfs_alloc() assigns *buf_size + sizeof(flash_entry_header_t) to a static uint16_t, so it can only ever address 65535 bytes. Twenty-one boards give the parameter store a single 128 KiB sector, all of them H7 flight controllers that keep parameters in flash because they have no SD card. Half of that sector is unreachable by construction. Were a request to exceed the range, the wrap would be silent. There is no overflow: the caller uses the size written back through *buf_size rather than the one it asked for, so the copy stays inside the allocation. The result would be a truncated parameter blob written as if it were complete. Use size_t, as the rest of the interface already does. Reported by @lihnucs. Assisted-by: Claude:claude-opus-5[1m] Signed-off-by: Julian Oes <julian@oes.ch>
This commit is contained in:
@@ -112,7 +112,7 @@ typedef begin_packed_struct struct flash_entry_header_t {
|
||||
* Private Data
|
||||
****************************************************************************/
|
||||
static uint8_t *working_buffer;
|
||||
static uint16_t working_buffer_size;
|
||||
static size_t working_buffer_size;
|
||||
static bool working_buffer_static;
|
||||
static sector_descriptor_t *sector_map;
|
||||
static int last_erased;
|
||||
|
||||
Reference in New Issue
Block a user