Skip to content

[kernel/memheap] fix: stop invalid frees from corrupting heap - #11721

Merged
Rbb666 merged 1 commit into
RT-Thread:masterfrom
liulangrenaaa:new_bug2
Aug 20, 2026
Merged

[kernel/memheap] fix: stop invalid frees from corrupting heap#11721
Rbb666 merged 1 commit into
RT-Thread:masterfrom
liulangrenaaa:new_bug2

Conversation

@liulangrenaaa

@liulangrenaaa liulangrenaaa commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

RT_ASSERT() does not stop execution when RT_DEBUGING_ASSERT is disabled. Return after the existing block validation so a sequential duplicate free cannot update heap accounting or the free list in release builds.

Before fix:
memheap double-free used: before=64 alloc=224 free=64 after=4294959232

Validation:
scons -C bsp/qemu-vexpress-a9 -j$(nproc)

拉取/合并请求描述:(PR description)

为什么提交这份PR (why to submit this PR)

rt_memheap_free() 在释放内存块前会检查 block magic 和 USED 状态。

RT_DEBUGING_ASSERT 开启时,非法 free 或重复 free 会触发 RT_ASSERT()。但是当 RT_DEBUGING_ASSERT 关闭时,RT_ASSERT() 不会阻止后续代码继续执行,因此一个已经释放的 block 再次进入 rt_memheap_free() 后,仍会继续修改 available_size 和 free list,导致 memheap 元数据损坏。

实际复现中,连续释放同一个 memheap block 两次后,修复前 heap used 统计出现异常:
memheap double-free used: before=64 alloc=224 free=64 after=4294959232

你的解决方案是什么 (what is your solution)

在现有 block validation 失败路径中的两个 RT_ASSERT() 后增加 return
这样:

  • Debug 构建仍然保留现有的 assertion 诊断行为;
  • Release 构建在 validation 失败后直接返回,不再继续修改 heap accounting 和 free list;
  • 不影响合法的 rt_memheap_free() 正常释放路径。

修改仅增加一行控制流保护:

RT_ASSERT(header_ptr->magic == (RT_MEMHEAP_MAGIC | RT_MEMHEAP_USED));
RT_ASSERT((header_ptr->next->magic & RT_MEMHEAP_MASK) == RT_MEMHEAP_MAGIC);
return;

请提供验证的bsp和config (provide the config and bsp)

  • BSP:
    bsp/qemu-vexpress-a9

  • .config:
    用于复现 Release 构建下的问题:

CONFIG_RT_DEBUGING_ASSERT is not set

并完成 BSP 编译验证:
scons -C bsp/qemu-vexpress-a9 -j$(nproc)

  • action:
    待 push 分支并触发 GitHub Action 后补充链接

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • 代码是高质量的 Code in this PR is of high quality
  • 已经使用clang-format 源码格式化工具确保格式符合RT-Thread代码规范 This PR has been formatted with clang-format and complies with RT-Thread code specification
  • 如果是新增bsp, 已经添加ci检查到.github/ALL_BSP_COMPILE.json 详细请参考链接BSP自查

RT_ASSERT() does not stop execution when RT_DEBUGING_ASSERT is disabled.
Return after the existing block validation so a sequential duplicate free
cannot update heap accounting or the free list in release builds.

Before fix:
  memheap double-free used: before=64 alloc=224 free=64 after=4294959232

Validation:
scons -C bsp/qemu-vexpress-a9 -j$(nproc)

Signed-off-by: Hui Su <3164683437@qq.com>
@liulangrenaaa

Copy link
Copy Markdown
Contributor Author

我另外检查了一下这段代码的历史。

f8c171d 在 2015 年加入了 block overwrite 检查;随后 2d3b2f1 加入 USED bit 检查,commit message 明确说明是为了帮助定位 double-free 问题。这两次修改都只增加了 RT_ASSERT()。

2021 年 memheap 重构 d724eed 仍然保留了这种 validation + assert-only 的行为。我没有找到任何历史记录表明 validation 失败后仍应继续进入正常 free 路径。

当 RT_DEBUGING_ASSERT 关闭时,RT_ASSERT() 不会阻止后续代码继续执行,因此非法或已经释放的 block 会继续修改 available_size 和 free list。

本 PR 增加的 return 只是补上 Release 构建下缺失的控制流保护,同时保留现有 Debug 构建中的 assertion 诊断行为。

@github-actions github-actions Bot added the Kernel PR has src relate code label Aug 19, 2026
@github-actions

Copy link
Copy Markdown

📌 Code Review Assignment

🏷️ Tag: kernel

Reviewers: @GorrayLi @ReviewSun @hamburger-os @lianux-mm @wdfk-prog @xu18838022837

Changed Files (Click to expand)
  • src/memheap.c

📊 Current Review Status (Last Updated: 2026-08-19 17:55 CST)


📝 Review Instructions

  1. 维护者可以通过单击此处来刷新审查状态: 🔄 刷新状态
    Maintainers can refresh the review status by clicking here: 🔄 Refresh Status

  2. 确认审核通过后评论 LGTM/lgtm
    Comment LGTM/lgtm after confirming approval

  3. PR合并前需至少一位维护者确认
    PR must be confirmed by at least one maintainer before merging

ℹ️ 刷新CI状态操作需要具备仓库写入权限。
ℹ️ Refresh CI status operation requires repository Write permission.

@github-actions

Copy link
Copy Markdown

👋 感谢您对 RT-Thread 的贡献!Thank you for your contribution to RT-Thread!

为确保代码符合 RT-Thread 的编码规范,请在你的仓库中执行以下步骤运行代码格式化工作流(如果格式化CI运行失败)。
To ensure your code complies with RT-Thread's coding style, please run the code formatting workflow by following the steps below (If the formatting of CI fails to run).


🛠 操作步骤 | Steps

  1. 前往 Actions 页面 | Go to the Actions page
    点击进入工作流 → | Click to open workflow →

  2. 点击 Run workflow | Click Run workflow

  • Use workflow from 保持默认分支(通常为 master
    Keep the default branch (usually master) in Use workflow from
  • branch 输入框填写 PR 分支 new_bug2
    Enter PR branch new_bug2 in the branch field
  • 设置需排除的文件/目录(目录请以"/"结尾)
    Set files/directories to exclude (directories should end with "/")
  1. 等待工作流完成 | Wait for the workflow to complete
    格式化后的代码将作为独立提交推送至你的分支。
    The formatting changes will be pushed to your branch as a separate commit.

完成后,提交将自动更新至 new_bug2 分支,关联的 Pull Request 也会同步更新。
Once completed, commits will be pushed to the new_bug2 branch automatically, and the related Pull Request will be updated.

如有问题欢迎联系我们,再次感谢您的贡献!💐
If you have any questions, feel free to reach out. Thanks again for your contribution!

@wdfk-prog wdfk-prog left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Rbb666
Rbb666 merged commit 8234a36 into RT-Thread:master Aug 20, 2026
107 checks passed
@liulangrenaaa
liulangrenaaa deleted the new_bug2 branch August 20, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Kernel PR has src relate code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants