mirror of
https://github.com/eclipse-threadx/threadx.git
synced 2026-10-06 06:59:08 +08:00
mq_send() allocates a private buffer from the queue's own byte pool, copies the caller's message into it, and passes the buffer's address through the queue. The receiver takes ownership: px_mq_receive.c releases the buffer once it has copied the message out. If tx_queue_send() fails, the message never reaches the queue, so no receiver will ever release that buffer. mq_send() returned ERROR while still holding the only pointer to it, leaking it from the pool. The failure is reachable. With TX_WAIT_FOREVER the send suspends, and tx_queue_send() then returns the thread's suspend status. tx_thread_wait_abort() sets TX_WAIT_ABORTED on a suspended sender, and the queue survives that, so the pool keeps shrinking with every aborted send. Queue deletion also reaches the branch, via TX_DELETED, but vq_message_area is a TX_BYTE_POOL embedded in the queue structure and destroyed with it, so nothing outlives the failure there. Exhausting the pool does not merely make later calls fail. tx_byte_allocate() failure runs into posix_internal_error(9999), which busy-loops forever on a non-zero code, so a caller hangs rather than getting an error back. Release the buffer before returning. The EINTR reporting is unchanged, since TX_WAIT_ABORTED maps onto it reasonably. Reported-by: K-ANOY <https://github.com/eclipse-threadx/threadx/issues/568> Assisted-by: Claude Code (Opus 5) <noreply@anthropic.com>