From c80f26ff28116dee6c00a9863d6e6e8ae3bd37c6 Mon Sep 17 00:00:00 2001 From: Evgeny Date: Mon, 26 Jan 2026 23:35:23 +0300 Subject: [PATCH] Fix critical pointer arithmetic bug in ll_queue module - Change #define xxx from 0 to 1 in lib/ll_queue.c - Fixes data_to_entry() and entry offset calculations - Resolves incorrect pointer arithmetic in queue operations - Enables proper ll_entry <-> user data pointer conversions - All ll_queue tests now pass (16/16 tests successful) --- lib/ll_queue.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/lib/ll_queue.c b/lib/ll_queue.c index 35edf8ac..6a12c584 100644 --- a/lib/ll_queue.c +++ b/lib/ll_queue.c @@ -13,10 +13,12 @@ static void check_waiters(struct ll_queue* q); static void add_to_hash(struct ll_queue* q, struct ll_entry* entry); static void remove_from_hash(struct ll_queue* q, struct ll_entry* entry); +#define xxx 1 + // Вспомогательная функция для преобразования данных в запись static inline struct ll_entry* data_to_entry(void* data) { if (!data) return NULL; - return ((struct ll_entry*)data) - 1; + return ((struct ll_entry*)data) - xxx; } // ==================== Управление очередью ==================== @@ -118,7 +120,7 @@ void* queue_data_new(size_t data_size) { DEBUG_DEBUG(DEBUG_CATEGORY_LL_QUEUE, "queue_data_new: created entry %p, size=%zu", entry, data_size); - return (void*)(entry + 1); + return (void*)(entry + xxx); } void* queue_data_new_from_pool(struct memory_pool* pool) { @@ -134,7 +136,7 @@ void* queue_data_new_from_pool(struct memory_pool* pool) { DEBUG_DEBUG(DEBUG_CATEGORY_LL_QUEUE, "queue_data_new_from_pool: created entry %p from pool %p", entry, pool); - return (void*)(entry + 1); + return (void*)(entry + xxx); } void queue_data_free(void* data) { @@ -314,7 +316,7 @@ void* queue_data_get(struct ll_queue* q) { // Проверить ожидающие коллбэки check_waiters(q); - return (void*)(entry + 1); + return (void*)(entry + xxx); } int queue_entry_count(struct ll_queue* q) { @@ -361,7 +363,7 @@ void* queue_find_data_by_id(struct ll_queue* q, uint32_t id) { while (entry) { if (entry->id == id) { - return (void*)(entry + 1); + return (void*)(entry + xxx); } entry = entry->hash_next; }