* [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again
@ 2026-09-22 10:53 Ahmad Fatoum
2026-09-22 10:53 ` [PATCH 2/2] test: self: free a zero-sized buffer with free_sensitive() Ahmad Fatoum
2026-09-23 6:09 ` [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again Sascha Hauer
0 siblings, 2 replies; 3+ messages in thread
From: Ahmad Fatoum @ 2026-09-22 10:53 UTC (permalink / raw)
To: barebox; +Cc: Ahmad Fatoum
Everything in SANDBOX_PBL2PROPER_GLUE_SYMS is #defined to a barebox_
prefixed name in barebox proper, so calls end up at our wrappers
instead of directly in the host libc directly.
malloc_usable_size lost its prefix when sandbox was migrated to PBL,
which becomes quickly apparent if it's called with a ZERO_SIZE_PTR:
The barebox wrapper rejects it, while the host allocator will choke on
it under ASAN:
AddressSanitizer: attempting to call malloc_usable_size() for pointer
which is not owned: 0x000000000010
Fixes: 2aba0017c95a ("sandbox: switch to using PBL")
Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de>
---
arch/sandbox/Makefile | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/sandbox/Makefile b/arch/sandbox/Makefile
index c8f5ae8c8986..9490a1ae4b35 100644
--- a/arch/sandbox/Makefile
+++ b/arch/sandbox/Makefile
@@ -33,7 +33,8 @@ TEXT_BASE = $(CONFIG_TEXT_BASE)
SANDBOX_PBL2PROPER_GLUE_SYMS := \
putchar errno setjmp longjmp \
- malloc_stats memalign malloc free realloc calloc memleak_check brk sbrk
+ malloc_stats memalign malloc free realloc calloc malloc_usable_size \
+ memleak_check brk sbrk
KBUILD_CFLAGS += $(foreach s,$(SANDBOX_PBL2PROPER_GLUE_SYMS),-D$(s)=barebox_$(s))
--
2.47.3
^ permalink raw reply [flat|nested] 3+ messages in thread* [PATCH 2/2] test: self: free a zero-sized buffer with free_sensitive()
2026-09-22 10:53 [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again Ahmad Fatoum
@ 2026-09-22 10:53 ` Ahmad Fatoum
2026-09-23 6:09 ` [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again Sascha Hauer
1 sibling, 0 replies; 3+ messages in thread
From: Ahmad Fatoum @ 2026-09-22 10:53 UTC (permalink / raw)
To: barebox; +Cc: Ahmad Fatoum
free_sensitive() asks the allocator for the usable size of the buffer
before zeroing it, so it is one more path that has to cope with the
ZERO_SIZE_PTR that zero-sized allocations return. The sandbox got this
wrong until the previous commit and only ASAN noticed, so let's have the
allocator selftest walk over it.
Assisted-by: Claude:opus-5-1m
Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de>
---
test/self/malloc.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/test/self/malloc.c b/test/self/malloc.c
index 1ec351c3efe5..14d936f96a45 100644
--- a/test/self/malloc.c
+++ b/test/self/malloc.c
@@ -140,6 +140,11 @@ static void test_malloc(void)
__expect_cond(p == ZERO_SIZE_PTR, true, "get ZERO_SIZE_PTR for 0-size buffers", __func__, __LINE__);
free(p);
- free(tmp);
+
+ /*
+ * free_sensitive() asks the allocator for the usable size before it
+ * zeroes the buffer, so ZERO_SIZE_PTR has to survive that path too
+ */
+ free_sensitive(tmp);
}
bselftest(core, test_malloc);
--
2.47.3
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again
2026-09-22 10:53 [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again Ahmad Fatoum
2026-09-22 10:53 ` [PATCH 2/2] test: self: free a zero-sized buffer with free_sensitive() Ahmad Fatoum
@ 2026-09-23 6:09 ` Sascha Hauer
1 sibling, 0 replies; 3+ messages in thread
From: Sascha Hauer @ 2026-09-23 6:09 UTC (permalink / raw)
To: barebox, Ahmad Fatoum
On Tue, 22 Sep 2026 12:53:02 +0200, Ahmad Fatoum wrote:
> Everything in SANDBOX_PBL2PROPER_GLUE_SYMS is #defined to a barebox_
> prefixed name in barebox proper, so calls end up at our wrappers
> instead of directly in the host libc directly.
>
> malloc_usable_size lost its prefix when sandbox was migrated to PBL,
> which becomes quickly apparent if it's called with a ZERO_SIZE_PTR:
> The barebox wrapper rejects it, while the host allocator will choke on
> it under ASAN:
>
> [...]
Applied, thanks!
[1/2] sandbox: route malloc_usable_size() through the PBL glue again
https://git.pengutronix.de/cgit/barebox/commit/?id=e542d5ae713b (link may not be stable)
[2/2] test: self: free a zero-sized buffer with free_sensitive()
https://git.pengutronix.de/cgit/barebox/commit/?id=0e9ba4d8df4a (link may not be stable)
Best regards,
--
Sascha Hauer <s.hauer@pengutronix.de>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-23 6:11 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-22 10:53 [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again Ahmad Fatoum
2026-09-22 10:53 ` [PATCH 2/2] test: self: free a zero-sized buffer with free_sensitive() Ahmad Fatoum
2026-09-23 6:09 ` [PATCH 1/2] sandbox: route malloc_usable_size() through the PBL glue again Sascha Hauer
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox