Skip to content

fix(commander): guard the fixed-size callback arrays in add() - #576

Open
stijncarelsbergh wants to merge 1 commit into
simplefoc:devfrom
stijncarelsbergh:fix/commander-bounds
Open

stijncarelsbergh wants to merge 1 commit into
simplefoc:devfrom
stijncarelsbergh:fix/commander-bounds

Conversation

@stijncarelsbergh

Copy link
Copy Markdown

fix(commander): guard the fixed-size callback arrays in add()

call_list/call_ids/call_label hold 20 entries and call_count was never checked, so
the 21st add() writes a function pointer, a char and a pointer past the end of the
object - out-of-bounds write, memory corruption, symptoms depending on layout.


Split out of #571 at your request: one fix per PR, against dev. The branch contains
nothing else, so it can be reviewed, amended or dropped on its own.

The CI board matrix runs automatically; I did not run any hardware test, so the behavioural
claims are from reading the code plus the compiler. Happy to adjust the wording, split it
differently or drop it - no attachment to this one.

call_list/call_ids/call_label hold 20 entries and call_count was never checked, so
the 21st add() writes a function pointer, a char and a pointer past the end of the
object - out-of-bounds write, memory corruption, symptoms depending on layout.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 22:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants