git: 434819b4fec5 - main - mkimg: Avoid leaking a page of mmap

From: Colin Percival <cperciva_at_FreeBSD.org>
Date: Sat, 03 Oct 2026 15:42:39 UTC
The branch main has been updated by cperciva:

URL: https://cgit.FreeBSD.org/src/commit/?id=434819b4fec5e508bdfe72f91e73402e9c2fca22

commit 434819b4fec5e508bdfe72f91e73402e9c2fca22
Author:     Colin Percival <cperciva@FreeBSD.org>
AuthorDate: 2026-09-26 00:42:40 +0000
Commit:     Colin Percival <cperciva@FreeBSD.org>
CommitDate: 2026-10-03 15:40:50 +0000

    mkimg: Avoid leaking a page of mmap
    
    The image_file_map function adjusts the provided file offset to be
    page-aligned, with a resulting increase in the size of the mapped
    region; the increased size needs to be used when unmapping as well.
    
    Reported by:    Claude Opus 5.5
    Fixes:  baf4abfc39b2 ("Allow building mkimg as cross-tool")
    MFC after:      2 weeks
    Sponsored by:   Amazon
    Differential Revision:  https://reviews.freebsd.org/D60148
---
 usr.bin/mkimg/image.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/usr.bin/mkimg/image.c b/usr.bin/mkimg/image.c
index 90817206e317..84d66af97a60 100644
--- a/usr.bin/mkimg/image.c
+++ b/usr.bin/mkimg/image.c
@@ -330,10 +330,11 @@ image_file_map(int fd, off_t ofs, size_t sz, off_t *iofp)
 }
 
 static int
-image_file_unmap(void *buffer, size_t sz)
+image_file_unmap(void *buffer, size_t sz, off_t iof)
 {
 	size_t unit;
 
+	sz += iof;
 	unit = (secsz > image_swap_pgsz) ? secsz : image_swap_pgsz;
 	sz = (sz + unit - 1) & ~(unit - 1);
 	if (madvise(buffer, sz, MADV_DONTNEED) != 0)
@@ -381,7 +382,7 @@ image_copyin_stream(lba_t blk, int fd, uint64_t *sizep)
 			error = errno;
 		else
 			error = 0;
-		image_file_unmap(buffer, iosz);
+		image_file_unmap(buffer, iosz, iof);
 		/* XXX should we relinguish unused swap space? */
 		if (error)
 			return (error);
@@ -465,7 +466,7 @@ image_copyin_mapped(lba_t blk, int fd, uint64_t *sizep)
 					buf += iof;
 					error = image_chunk_copyin(blk, buf,
 					    sz, data, fd);
-					image_file_unmap(mp, sz);
+					image_file_unmap(mp, sz, iof);
 				} else
 					error = errno;
 
@@ -590,7 +591,7 @@ image_copyout_file(int fd, size_t size, int ifd, off_t iofs)
 			return (errno);
 		buf += iof;
 		error = image_copyout_memory(fd, sz, buf);
-		image_file_unmap(mp, sz);
+		image_file_unmap(mp, sz, iof);
 		if (error)
 			return (error);
 		size -= sz;