mirror of
https://github.com/ArduPilot/ardupilot.git
synced 2026-10-02 10:23:25 +08:00
AP_HAL_Linux: bounds-check channel number in RCOutput write methods
RCOutput_PRU, RCOutput_AioPRU_PB2 and RCOutput_AeroIO wrote into their channel arrays without checking the channel number; every other Linux RCOutput backend already does. On PRU the overrun is particularly unpleasant as pending[MAX_PWMS] aliases the corked flag, so a write to channel 12 uncorks the backend and makes the subsequent push() a no-op. SRV_Channels::output_ch_all() already sweeps 16 channels by default, so these overruns are reachable today on pxf, erleboard and pocket2.
This commit is contained in:
committed by
Peter Barker
parent
8a6d5b2ef7
commit
985d2f6f6f
@@ -168,6 +168,10 @@ void RCOutput_AeroIO::disable_ch(uint8_t ch)
|
||||
|
||||
void RCOutput_AeroIO::write(uint8_t ch, uint16_t period_us)
|
||||
{
|
||||
if (ch >= PWM_CHAN_COUNT) {
|
||||
return;
|
||||
}
|
||||
|
||||
_pending_duty_write_mask |= (1U << ch);
|
||||
_duty_buffer[ch] = period_us;
|
||||
|
||||
|
||||
@@ -145,6 +145,10 @@ void RCOutput_AioPRU_PB2::disable_ch(uint8_t ch)
|
||||
|
||||
void RCOutput_AioPRU_PB2::write(uint8_t ch, uint16_t period_us)
|
||||
{
|
||||
if (ch >= RC_CHAN_COUNT) {
|
||||
return;
|
||||
}
|
||||
|
||||
pending_mask |= (1U << ch);
|
||||
period[ch] = period_us;
|
||||
|
||||
|
||||
@@ -68,6 +68,9 @@ void RCOutput_PRU::disable_ch(uint8_t ch)
|
||||
|
||||
void RCOutput_PRU::write(uint8_t ch, uint16_t period_us)
|
||||
{
|
||||
if (ch >= MAX_PWMS) {
|
||||
return;
|
||||
}
|
||||
if (corked) {
|
||||
pending[ch] = period_us;
|
||||
pending_mask |= (1U << ch);
|
||||
|
||||
Reference in New Issue
Block a user