git: 434819b4fec5 - main - mkimg: Avoid leaking a page of mmap
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 03 Oct 2026 15:42:39 UTC
The branch main has been updated by cperciva:
URL: https://cgit.FreeBSD.org/src/commit/?id=434819b4fec5e508bdfe72f91e73402e9c2fca22
commit 434819b4fec5e508bdfe72f91e73402e9c2fca22
Author: Colin Percival <cperciva@FreeBSD.org>
AuthorDate: 2026-09-26 00:42:40 +0000
Commit: Colin Percival <cperciva@FreeBSD.org>
CommitDate: 2026-10-03 15:40:50 +0000
mkimg: Avoid leaking a page of mmap
The image_file_map function adjusts the provided file offset to be
page-aligned, with a resulting increase in the size of the mapped
region; the increased size needs to be used when unmapping as well.
Reported by: Claude Opus 5.5
Fixes: baf4abfc39b2 ("Allow building mkimg as cross-tool")
MFC after: 2 weeks
Sponsored by: Amazon
Differential Revision: https://reviews.freebsd.org/D60148
---
usr.bin/mkimg/image.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/usr.bin/mkimg/image.c b/usr.bin/mkimg/image.c
index 90817206e317..84d66af97a60 100644
--- a/usr.bin/mkimg/image.c
+++ b/usr.bin/mkimg/image.c
@@ -330,10 +330,11 @@ image_file_map(int fd, off_t ofs, size_t sz, off_t *iofp)
}
static int
-image_file_unmap(void *buffer, size_t sz)
+image_file_unmap(void *buffer, size_t sz, off_t iof)
{
size_t unit;
+ sz += iof;
unit = (secsz > image_swap_pgsz) ? secsz : image_swap_pgsz;
sz = (sz + unit - 1) & ~(unit - 1);
if (madvise(buffer, sz, MADV_DONTNEED) != 0)
@@ -381,7 +382,7 @@ image_copyin_stream(lba_t blk, int fd, uint64_t *sizep)
error = errno;
else
error = 0;
- image_file_unmap(buffer, iosz);
+ image_file_unmap(buffer, iosz, iof);
/* XXX should we relinguish unused swap space? */
if (error)
return (error);
@@ -465,7 +466,7 @@ image_copyin_mapped(lba_t blk, int fd, uint64_t *sizep)
buf += iof;
error = image_chunk_copyin(blk, buf,
sz, data, fd);
- image_file_unmap(mp, sz);
+ image_file_unmap(mp, sz, iof);
} else
error = errno;
@@ -590,7 +591,7 @@ image_copyout_file(int fd, size_t size, int ifd, off_t iofs)
return (errno);
buf += iof;
error = image_copyout_memory(fd, sz, buf);
- image_file_unmap(mp, sz);
+ image_file_unmap(mp, sz, iof);
if (error)
return (error);
size -= sz;