From 7f2463364140a9395fcac719ff19865b9dd1c97d Mon Sep 17 00:00:00 2001 From: Prashit Vora Date: Mon, 31 Aug 2026 18:29:24 +0530 Subject: [PATCH 1/2] modules: free kernel stack on thread deletion Signed-off-by: Prashit Vora --- .../inc/txm_module_manager_dispatch.h | 21 +++++++++++++------ 1 file changed, 15 insertions(+), 6 deletions(-) diff --git a/common_modules/module_manager/inc/txm_module_manager_dispatch.h b/common_modules/module_manager/inc/txm_module_manager_dispatch.h index 03bd86ebf..036eeeea2 100644 --- a/common_modules/module_manager/inc/txm_module_manager_dispatch.h +++ b/common_modules/module_manager/inc/txm_module_manager_dispatch.h @@ -8,6 +8,7 @@ * * SPDX-License-Identifier: MIT **************************************************************************/ +// Some portions generated by Codex (GPT-5). /**************************************************************************/ @@ -2061,7 +2062,10 @@ ALIGN_TYPE return_value; static ALIGN_TYPE _txm_module_manager_tx_thread_delete_dispatch(TXM_MODULE_INSTANCE *module_instance, ALIGN_TYPE param_0) { -ALIGN_TYPE return_value; +TX_THREAD *thread_ptr; +ALIGN_TYPE return_value; + + thread_ptr = (TX_THREAD *) param_0; if (module_instance -> txm_module_instance_property_flags & TXM_MODULE_MEMORY_PROTECTION) { @@ -2069,14 +2073,19 @@ ALIGN_TYPE return_value; return(TXM_MODULE_INVALID_MEMORY); } - return_value = (ALIGN_TYPE) _txe_thread_delete( - (TX_THREAD *) param_0 - ); + return_value = (ALIGN_TYPE) _txe_thread_delete(thread_ptr); - /* Deallocate object memory. */ + /* Deallocate the kernel stack for a user-mode thread. */ + if ((return_value == TX_SUCCESS) && + (module_instance -> txm_module_instance_property_flags & TXM_MODULE_USER_MODE)) + { + return_value = _txm_module_manager_object_deallocate(thread_ptr -> tx_thread_module_kernel_stack_start); + } + + /* Deallocate thread object memory. */ if (return_value == TX_SUCCESS) { - return_value = _txm_module_manager_object_deallocate((VOID *) param_0); + return_value = _txm_module_manager_object_deallocate((VOID *) thread_ptr); } return(return_value); } From 302fd2d62f18eec1debe136899f722232e38730b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fr=C3=A9d=C3=A9ric=20Desbiens?= Date: Tue, 8 Sep 2026 10:47:05 -0400 Subject: [PATCH 2/2] Preserved the thread object release when the kernel stack cannot be freed Releasing the kernel stack ahead of the thread object made a failure of the kernel stack deallocation abort the thread object release. The thread had already been deleted at that point, so the thread object would have stayed allocated for the lifetime of the module. The thread object is now always released once the delete succeeds, and the kernel stack failure is reported only when it does not mask a thread object failure. Assisted-by: Copilot (Opus 5) --- .../inc/txm_module_manager_dispatch.h | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/common_modules/module_manager/inc/txm_module_manager_dispatch.h b/common_modules/module_manager/inc/txm_module_manager_dispatch.h index 036eeeea2..465366068 100644 --- a/common_modules/module_manager/inc/txm_module_manager_dispatch.h +++ b/common_modules/module_manager/inc/txm_module_manager_dispatch.h @@ -9,6 +9,7 @@ * SPDX-License-Identifier: MIT **************************************************************************/ // Some portions generated by Codex (GPT-5). +// Some portions generated by Copilot (Opus 5). /**************************************************************************/ @@ -2064,8 +2065,10 @@ static ALIGN_TYPE _txm_module_manager_tx_thread_delete_dispatch(TXM_MODULE_INSTA TX_THREAD *thread_ptr; ALIGN_TYPE return_value; +ALIGN_TYPE stack_status; - thread_ptr = (TX_THREAD *) param_0; + thread_ptr = (TX_THREAD *) param_0; + stack_status = (ALIGN_TYPE) TX_SUCCESS; if (module_instance -> txm_module_instance_property_flags & TXM_MODULE_MEMORY_PROTECTION) { @@ -2079,13 +2082,21 @@ ALIGN_TYPE return_value; if ((return_value == TX_SUCCESS) && (module_instance -> txm_module_instance_property_flags & TXM_MODULE_USER_MODE)) { - return_value = _txm_module_manager_object_deallocate(thread_ptr -> tx_thread_module_kernel_stack_start); + stack_status = _txm_module_manager_object_deallocate(thread_ptr -> tx_thread_module_kernel_stack_start); } - /* Deallocate thread object memory. */ + /* Deallocate thread object memory. This must be attempted even when the kernel + stack could not be released, otherwise a successful thread delete would leave + the thread object allocated forever. */ if (return_value == TX_SUCCESS) { return_value = _txm_module_manager_object_deallocate((VOID *) thread_ptr); + + /* Report the kernel stack failure if the thread object was released. */ + if ((return_value == TX_SUCCESS) && (stack_status != TX_SUCCESS)) + { + return_value = stack_status; + } } return(return_value); }