Commit Graph
29 Commits
Author SHA1 Message Date
Frédéric Desbiens e99f0d4207 Corrected the module kernel stack size so it no longer overstates the usable stack (#701)
The module manager recorded tx_thread_module_kernel_stack_size as the raw
TXM_MODULE_KERNEL_STACK_SIZE constant, but the end of the kernel stack is aligned
downwards to an eight-byte boundary while _txm_module_manager_object_allocate only
guarantees ULONG alignment. The recorded size could therefore overstate the usable
stack by up to seven bytes. The scheduler copies this value into tx_thread_stack_size
whenever a user mode module thread enters the kernel, so the overstated value is
visible to RTOS-aware debuggers and to anything built on it.

The size is now derived from the aligned end minus the start. Also documented that
TX_ENABLE_STACK_CHECKING is not supported for module threads.

Refs #181

Assisted-by: Copilot (Opus 5) <noreply@github.com>
2026-09-08 16:44:48 -04:00
tardigradeandFrédéric Desbiens 29afcc3946 Fixed a kernel stack leak when deleting user-mode module threads (#692)
* modules: free kernel stack on thread deletion

Signed-off-by: Prashit Vora <prashitvora2006@gmail.com>

* Preserved the thread object release when the kernel stack cannot be freed

Releasing the kernel stack ahead of the thread object made a failure of the kernel
stack deallocation abort the thread object release. The thread had already been
deleted at that point, so the thread object would have stayed allocated for the
lifetime of the module.

The thread object is now always released once the delete succeeds, and the kernel
stack failure is reported only when it does not mask a thread object failure.



---------

Signed-off-by: Prashit Vora <prashitvora2006@gmail.com>
Co-authored-by: Frédéric Desbiens <frederic.desbiens@eclipse-foundation.org>
Assisted-by: Copilot (Opus 5) <noreply@github.com>
2026-09-08 11:17:57 -04:00
Frédéric Desbiens b0ec8bfbb9 Fixed the invalid module data pointers in the absolute module load (#699)
An absolutely located module has its code and its data placed at two
independent fixed addresses by the module's linker script. The module
preamble carries the code and data sizes but not the data address, so
_txm_module_manager_absolute_load() could not determine where the
module's data area was. It computed txm_module_instance_data_start
from the code size and the preamble size, which yields a size rather
than an address, and it set txm_module_instance_module_data_base_address
one past the end of the byte pool allocation.

Added _txm_module_manager_absolute_load_extended(), which accepts the
module's data area address from the caller. Deprecated
_txm_module_manager_absolute_load(), which now forwards to the extended
service with an unknown data area location and rejects modules that
request memory protection, since the memory protection hardware cannot
be programmed to cover an unknown data area.

Fixes #450

Assisted-by: Copilot (Opus 5) <noreply@github.com>
2026-09-08 10:03:45 -04:00
Frédéric Desbiens 2b0e4e44b9 Hardened the module converter utilities against malformed input (#580)
* Hardened the module converter utilities against malformed input

While reviewing the code_buffer leak reported in issue 571, three further
pre-existing defects turned up in the same host-side utilities.

The four ELF area allocations in module_to_binary.c and module_to_c_array.c
were unchecked, and every elf_object_read() return value was discarded, so a
truncated or crafted ELF file was read into whatever the allocation and the
reads happened to leave behind. Check each allocation, distinguishing a NULL
return for an empty area from a genuine failure, and abandon the conversion
with exit code 5 on an allocation failure and exit code 6 on a read failure.

Validate the section string table index taken from the ELF header before it
is used to subscript the section header area. AddressSanitizer confirms that
an out-of-range index produced a heap buffer overflow in both tools.

Correct the address format specifiers in module_to_c_array.c and
module_binary_to_c_array.c, which passed an unsigned long to %08X, and close
the source file on the invalid format path of module_binary_to_c_array.c.
The unused current_total local is removed. All three utilities now build
warning free with gcc -std=c99 -Wall -Wextra, and the code they emit is
unchanged byte for byte on valid input.

Refresh the version banners of all three tools, on the console and in the
header written into the generated C arrays, to the 2024 Microsoft Corp and
2026 Eclipse ThreadX contributors copyrights and version v6.5.2.202603. The
banners still advertised v5.8 and v5.4 with a 2018 build date. The .exe
suffix is dropped from the tool names, since these tools build on Linux too.

Related to https://github.com/eclipse-threadx/threadx/issues/571

Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>

* Added the missing licence header to module_binary_to_c_array.c

The file carried no copyright or licence header at all, unlike the two other
converter utilities in the same directory. Use the same MIT header they carry,
since the three tools share an origin.

Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>
2026-08-08 08:09:06 -04:00
Frédéric Desbiens bd8d30f23b Fixed code_buffer leak in the module converter utilities (#581)
The host-side module converter utilities allocated code_buffer inside the
loop over the ELF code sections and never released it, so every code
section in the input ELF leaked one buffer. The malloc() result was also
unchecked, so a failed allocation passed a null pointer on to
elf_object_read() and crashed the tool.

Release the buffer at the end of each iteration and report a clean failure
with exit code 5 when the allocation does not succeed. Verified with
AddressSanitizer on a two-code-section input: 128 bytes leaked in 2
allocations before, none after, with byte-identical output.

Fixes https://github.com/eclipse-threadx/threadx/issues/571

Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>
2026-08-08 08:01:38 -04:00
Frédéric DesbiensandCopilot 190c4d6be4 Flagged txm_module_object_pointer_get as deprecated (#562)
Added #pragma message compile-time warning to the module library
source and updated the DESCRIPTION blocks in both the library and
manager implementations.

Reason: this wrapper passes UINT_MAX as the name-buffer length to
the underlying extended search. The comparison loop can therefore
read past the end of a short name buffer, which is undefined
behaviour. Callers should use txm_module_object_pointer_get_extended()
and supply the actual buffer length.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-07-27 10:30:49 -04:00
Frédéric DesbiensandCopilot 92ce0754ed Marked txm_module_object_deallocate as deprecated (#559)
Added a compile-time #pragma message warning to the module library
source so that any module that includes or compiles this file receives
an explicit deprecation notice at build time.

Updated the internal documentation block in the manager-side
implementation to explain that this function must not be called directly
and that calling it on a live object causes a use-after-free.

The Module Manager dispatch layer already releases pool memory
automatically after a successful tx_*_delete() call. Module authors
should remove any explicit call to txm_module_object_deallocate().

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-07-27 10:30:29 -04:00
Frédéric DesbiensandCopilot 730b61874b Added copyright headers to files missing them
Applied the standard MIT license header to all project-owned C, header,
assembly, shell, and Python files that were missing a copyright notice.
Third-party, toolchain startup, and auto-generated files were excluded.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-06 21:48:06 +02:00
Frédéric Desbiens c3259a2160 Updated copyright headers and version number constants (#509)
* Updated version number constants

* Removed revision history from all files

* Added Eclipse ThreadX contributors' copyright header
2026-03-05 10:46:30 +01:00
Frédéric Desbiens ea408ebe52 Merge commit from fork
Fixed pointer validation flaw and improper parameter check in syscall implementation
2025-09-28 21:23:20 +01:00
Frédéric Desbiens 3d6b65a7d3 Merged fixes for advisories GHSA-76hh-wrj5-hr2v and GHSA-wcfg-5jpf-hhxq provided by Bill Lamie. 2025-07-14 16:58:01 -04:00
Frédéric Desbiens da0985e748 Merged fix for advisory GHSA-w8rw-fqgj-9r49 provided by Bill Lamie. 2025-07-14 16:33:19 -04:00
Bo Chen (from Dev Box) 8276bcf711 Update copyright. 2024-01-29 13:51:15 +08:00
TiejunZhou 13b700fd3e Update release version to 6.3.0 and date to 10-31-2023 (#308) 2023-10-23 15:31:03 +08:00
TiejunZhou 9ee2738aec Improved the logic to validate object from application in ThreadX Module (#307) 2023-10-23 14:33:24 +08:00
yajunxiaMS bc8bed494d Added thumb mode support under IAR for module manager on Cortex-A7 pl… (#289)
* Added thumb mode support under IAR for module manager on Cortex-A7 platform.

* update code for comments.
2023-08-07 17:35:31 +08:00
Xiuwen CaiandTiejunZhou 6b8ece0ff2 Add random number stack filling option. (#257)
Co-authored-by: TiejunZhou <50469179+TiejunMS@users.noreply.github.com>
2023-05-12 10:13:42 +08:00
Tiejun Zhou 2aa19f3de0 Release 6.2.1 on 08 Mar 2023. Expand to see details.
cee19603d Include tx_user.h conditionally.
e40e08007 Update owners
d69641273 Update release date and version
394aee52f Add tx_user.h to GNU port assembly files
5cca2ddd0 RISC-V 64 bit port for Microchip
e0f2c373c Link Winmm.lib that required by the high-resolution timer.
6af472a68 Update Win32 port with high resolution timer.
aea7b556a Add DMB ISH barrier inst in ARMv8-A SMP scheduler
19091a262 Add .section .preamble to m3 m4 m7 module ports
ced60e1b7 Add missing parenthesis in ports assembly file
309dc77ca Modules Cortex-A7 IAR new port
c752a4063 Modules Cortex-A7 GNU new port
dc224b90f Fix race condition in tx_thread_wait_abort and update regression test
6e261f5b7 create threadx cmsis-pack
2023-03-08 08:26:22 +00:00
Scott Larson 37f6d0b39c Update on 18 Jan 2023. Expand to see details.
9c3acb6ce armv8-m compile time FPU fix
37daa35e7 added tx_trace.h include to module stop.c
39824289f Remove internal deprecated files.
fe2f80f43 Add a notice for not released file.
7fdd3782a Upgrade to the latest Container Images.
2023-01-18 08:39:40 +00:00
Scott Larson 4e62226eea Update on 16 Dec 2022. Expand to see details.
b5d5df511 #include tx_user.h in assembly files for cortex-m ports
33e04e3d5 initial port of MIPS SMP for GHS and GNU
2eda2c17d capitalize extensions for M23 asm files
21c354ccb Fix armv7-m MPU settings for corner case, unify txm_module_port.h files
4a1ff93f9 remove uneeded include for ac6
c823e91ff update riscv iar example for latest iar tools
5559d185d check module stack for overlap (not kernel stack)
efa9ce7b7 apply patch from mobileye to fix time slice processing
75fdcb722 Updated copy_armv7_cm.yml
de04b9904 initialize unused MPU settings so that aliasing will work
79b317b60 add config directory to IAR RISC-V port in order to use simulator
2022-12-16 08:16:32 +00:00
Yuxin Zhou 8c3c08f108 Release 6.1.12 2022-07-26 02:04:40 +00:00
Yuxin Zhou f7f0957188 Release 6.1.10 2022-01-29 00:24:03 +00:00
Yuxin Zhou d0dab58250 Release 6.1.8 2021-07-28 07:24:02 +00:00
Bo Chen f5056f4923 Release 6.1.7 2021-06-02 06:45:05 +00:00
Yuxin Zhou b12bd44faa Release 6.1.6 2021-04-03 01:03:21 +00:00
Yuxin Zhou 10a7932b9d Release 6.1.5 2021-03-05 05:38:33 +00:00
Scott Larson f108ebdbaf update to v6.1.3 2021-01-08 13:31:36 -08:00
Scott Larson 1b5816a206 6.1 minor release 2020-09-30 15:42:41 -07:00
Scott Larson 6f61053f2a add SMP, Modules, and more processor/tools releases 2020-08-07 16:56:45 -07:00