[roll] Roll fuchsia [iob] Fix integer overflow in BlobIdAllocator::index_end()

The computation `sizeof(Header) + next_id * sizeof(Index)` can overflow
a uint32_t when next_id >= 0x20000000. The result is silently truncated
by static_cast<uint32_t>, causing IsValid() to incorrectly return true
and enabling out-of-bounds memory access via GetIndex().

A writer with mapped access to an IOB region could corrupt the header's
next_id field to trigger this overflow, leading to memory corruption.

Fix:
- index_end() now returns fit::result<fit::failed, uint32_t>, failing
  when next_id would cause the computation to exceed UINT32_MAX.
- IsValid() and RemainingBytes() propagate the failure correctly.
- GetIndex() adds ZX_DEBUG_ASSERT bounds checks as defense-in-depth.

Test: sdk/lib/iob:blob-id-allocator-tests (OverflowingNextIdIsInvalid)
Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1591668
Original-Revision: e9875f6ed69b596abded62b7e8a055f88b5c0f1e
GitOrigin-RevId: 2713e0410ef147a4ae43e648c3335175a8cd5961
Change-Id: I77585b5ad1b18d339e5ffa46b9f27f06aa07db0b
1 file changed
tree: 4360f2b29f5114810f11cf79a4f46c302bec744d
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.