[roll] Roll fuchsia [starnix][ebpf] Fix off-by-one in StackOffset::is_valid boundary check

is_valid() used <= which allowed offset 512 (one past the 512-byte
stack) through validation. load() had a secondary guard that caught
this, but store() did not, enabling an OOB write at index 64 of a
0..63 array.

A blanket <= to < fix breaks helper argument validation and
read_data_ptr, where offset + size = 512 is a legitimate exclusive
upper bound.

Split is_valid() into is_valid_offset() (strict <, for element access)
and is_within_stack() (inclusive <=, for range endpoint checks). Removed
the now redundant guard and constant from load().

Original-Original-Bug: 421238695
Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1623576
Original-Original-Revision: 23c76281479b72d1dc2e42c2bc58605034886e56
GitOrigin-RevId: 54ee9fd17e8832853d27f671a3d68b230074ea14
Change-Id: Ifc39a1b5715230db354304746c3ed743248dbb89
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1642769
Cr-Commit-Position: refs/heads/main@{#194322}
1 file changed
tree: ec4083f9617b58c01921f6187576a527516c3ddf
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.