From patchwork Mon Aug 3 15:54:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Magnus Lindholm X-Patchwork-Id: 140501 X-Patchwork-Delegate: Wilco.Dijkstra@arm.com Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 2C31E4BB1C10 for ; Mon, 3 Aug 2026 15:57:45 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 2C31E4BB1C10 Authentication-Results: sourceware.org; dkim=pass (2048-bit key, unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=QkTN+DUA X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from mail-ed1-x52f.google.com (mail-ed1-x52f.google.com [IPv6:2a00:1450:4864:20::52f]) by sourceware.org (Postfix) with ESMTPS id 58FB14BA2E3C for ; Mon, 3 Aug 2026 15:56:46 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 58FB14BA2E3C Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=gmail.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 58FB14BA2E3C Authentication-Results: sourceware.org; arc=none smtp.remote-ip=2a00:1450:4864:20::52f ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1785772606; cv=none; b=AHrDpLiXgXPBuAAah/ROJW9PP89YdyTQJAm+d8EuCObM2VFZyFkezqVL3KiI+JphsUeW9OxYnORdjAnD2kfbIVRvHaEAASbDeKeanUpDQbTkWv7s8CKBoLVyMfv21yOLucWwxaiyRJnFdTUS8Qa6416rBNBnCdvudtCt7Elp/pM= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1785772606; c=relaxed/simple; bh=hJHF2sIW1F70je2BYUfZ94u1I/LLxsvTobLRLzE8Lfc=; h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version; b=JnoE2EJOPOFO+TXHj4JPybA2hWslbgmC2+6Z4AYEKRjqp4OVYKSsvuzJysGUQ+sLFus64Y2FxtE6XGIBflFJtW4bQj53Ei07eH8uvok258hbTHmqdsjtsoCK+Wc6WWskLxjh+kl3fNeFHqGuKDXjnoLH/6pZ7rViCAz7npFMPu4= ARC-Authentication-Results: i=1; sourceware.org Received: by mail-ed1-x52f.google.com with SMTP id 4fb4d7f45d1cf-6a10a1a4b11so1398236a12.2 for ; Mon, 03 Aug 2026 08:56:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785772605; x=1786377405; darn=sourceware.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=eE0qZv3zjDCKEnM2tKmt1k2ONb6YJ9tVGhzpyBNs238=; b=QkTN+DUAW+8Fn6IraatOsdxAYZqTyNopuYgtXolBlal1ipXgM8tCUE67bPxsT3IiuM 9ACb51Wsxpz7DhPBRkKFDLdbseSnaU24iJktO/Mz16yIBNLjFf7WbzHPQt2Vvr42bQnA QzOY02ZALJP4kNdqx2lMevHFLG7hYfIKTU3vGTE4TCGfyiCdRt9ZcaKeYVtAHgcpCkpr RU0vz685WvTdU8N0K4dLE4+AohYGPmNPkjAeaDOUwSvN7UnkHjCo6sKq9PsuAJebAE9a WS4jlqGLfUNv0QTK9NDW5KCfBVtkuteeHN8pRGguW0E0ZTiQL41FRMn/KBXY4pVBp5tB 3yPA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785772605; x=1786377405; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eE0qZv3zjDCKEnM2tKmt1k2ONb6YJ9tVGhzpyBNs238=; b=mp8n/wC9vRsdZQcbXIAiDpyfrTUQJ+fa5qtLPUYXVt5i9jTTx6zYiRP49+H+g2p1ze /yEy14hBV5+rXjpeEpBowTSJePu7MmENMGTSvsaGH9V8SFFswkQjiO5gYlnx4ZAXA5SC fCSi3hyruleQfthGpNJRxGEGPXhfkgwx46+N3Zku3UVWKbZZQIVX6BIWAl572Stwhoxl aFtrX3K8zo1IrI1584p+o8gxv2K594dmIrTWiR34eIsxsd+PwaZkWZfxp0q/a7vbY742 g7ehbbJoARp2QalzmiPLE+v16tRR9kLy2O5sn2610g1JBeQWf088jbhbL+K+K64rJtKg YJdA== X-Gm-Message-State: AOJu0YzXw4X8DdIRULJBzr8UCsDizBpNj/KbqAZxRHdgTwYczBN8cNmQ v+WuI8I34GyxMuu2RYfqd2hpkQd4UYgKXPmdhrAaJ589+h5JjdN9istHfGo9Kw== X-Gm-Gg: AR+sD12FUy3n4GyrPMGEJukBrnkK4pt7QvXuxW7CY8D07zL1EEZOo3kPhH86hdD9/Bx Et1zG9FfJm9myRJaAn7vONNpF0qNcUFTI4GuCeE5svMa/QZlNFn6dKELR43hT1hpoT25mbUIx+A RhlooaJ2B9h5fJnWgEDXcRokLisDS69uYwdMgdHlxHRzJM6z++Fm1gqRQx1svCGanYPubHFU5XI 9I+KCjvqoPHAdZBXt2KZAjsRyp8xCzLuENeuzx8GD4sC+B5JUYY7k18rjosKwZusl67nMQCTmXw A2DRkZmM95ulp2CG4xzLZ/HZRZs3ZUfA+PVHGXMEX7cC4sseizSoP4kSQQMevFA1kIf2MKgvXv8 uklOwP/Qb5TdYUTCGo7F38QDe3wnwhZAI62Yu4saztUv+7BLolxHvwernvElbdOxAC2/MSVllO9 Y5qHJql+Ge/V+jdxwlfO8b+89D3guO2pfptVAVpUyRunOQ0/SuAmDJtKuRiFbZfLJVPbviOoFEG cmjLYRWtlYLalnXOZlfkcXSNjSwXLE= X-Received: by 2002:a17:907:e1c2:20b0:bed:9a7:5ed1 with SMTP id a640c23a62f3a-c1fe7f60821mr655461266b.5.1785772604733; Mon, 03 Aug 2026 08:56:44 -0700 (PDT) Received: from buildhost.darklands.se ([2001:9b1:ff:d701:51eb:176f:63d9:53f8]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a09c5a098bsm5882292a12.1.2026.08.03.08.56.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 08:56:43 -0700 (PDT) From: Magnus Lindholm To: libc-alpha@sourceware.org Cc: glaubitz@physik.fu-berlin.de, zatrazz@gmail.com, Magnus Lindholm Subject: [PATCH] malloc: Reject the top chunk in mem2chunk_check Date: Mon, 3 Aug 2026 17:54:47 +0200 Message-ID: <20260803155600.3087744-1-linmag7@gmail.com> X-Mailer: git-send-email 2.53.0 MIME-Version: 1.0 X-Spam-Status: No, score=-10.1 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_ENVFROM_END_DIGIT, FREEMAIL_FROM, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_PBL, SPF_HELO_NONE, SPF_PASS, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org mem2chunk_check uses inuse to validate a candidate chunk. However, inuse obtains the chunk state from the header of the following chunk and therefore must not be called for the top chunk, which has no following chunk. The existing main-arena boundary check implicitly rejects the top chunk when the arena is contiguous. When the main arena is marked noncontiguous, that boundary check is skipped and mem2chunk_check can instead call inuse on the top chunk. This was exposed by the malloc-check tests on Alpha, where the main arena used the noncontiguous 1 MiB mmap fallback. An invalid pointer was interpreted as the top chunk, and inuse read beyond the end of the mapping, causing a segmentation fault instead of diagnosing the invalid pointer. Explicitly reject the top chunk before calling inuse. The top chunk is unallocated space and cannot be a valid result of mem2chunk_check. This fixes tst-tcfree1-malloc-check and tst-tcfree2-malloc-check on Alpha. Signed-off-by: Magnus Lindholm --- malloc/malloc-check.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/malloc/malloc-check.c b/malloc/malloc-check.c index b1a10c74b3..109076f590 100644 --- a/malloc/malloc-check.c +++ b/malloc/malloc-check.c @@ -120,7 +120,8 @@ mem2chunk_check (void *mem, unsigned char **magic_p) if ((contig && ((char *) p < mp_.sbrk_base || ((char *) p + sz) >= (mp_.sbrk_base + main_arena.system_mem))) || - sz < MINSIZE || sz & MALLOC_ALIGN_MASK || !inuse (p) || + sz < MINSIZE || sz & MALLOC_ALIGN_MASK || + p == top (&main_arena) || !inuse (p) || (!prev_inuse (p) && ((prev_size (p) & MALLOC_ALIGN_MASK) != 0 || (contig && (char *) prev_chunk (p) < mp_.sbrk_base) || next_chunk (prev_chunk (p)) != p)))