[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH 2/2] tools/symbols: leave room for the type byte and NUL when expanding tokens


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Mykola Kvach <mykola_kvach@xxxxxxxx>
  • Date: Wed, 7 Oct 2026 21:11:03 +0300
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=vT7c5Zm4QjQGT2duyBnbTwAOk8VXrr8iH57eJmZ0978=; b=SS0KjzNGqwVMlxizri/1vONlm9qur7XZ/Kj5IKEwHVljxeZlxYkG3D1ftF+TvSS1+hYanfu19Y5uhE5837/NypMnE3nGbR8T/9Ysr8kk9ZRRa1EqZjWB8sATfTJYhwO0OUTXdQE1SpxSdjgXyeQNvT61/cK2326pwznllUanO6ouzuT74XCGVIxq/HHNU8SlTJkO08tQA03JgUcqHbSFSeQDhIgz9UlKHYA1jboMQc1ZIT2xKbjXu+ObZxkar022png2nFkWEs9dxBu5LJ09mzJBICyGDBMeg8IKwi3yadaQbF2LgQciBZmMoq9uoaVHy2LJ35VkQq1L76nWvaaQ+w==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=cxUoUOMPREnxu2BL0e4HlLcJUeAbNFQW5U6skpwzzI8xzOpsS3U27SOl1O4fHwRFvwNHjkC1AJ2OYusyZlXX1NEoOk+fSgaIbf7WnG1PsbEMYs5NwHOTc3zQ5VRa1B6WevvGsTCifvdMcrV2VGDhw+zFbNYk1nPuopJpAcsRr9Q8yO+gYdJ7PtCmkRzYzZQbuXxFYpya7znBTgmEH0E1XdpzOXIr/SI+a5IW2lqPDeBozF3eSZFYd9484ohSyHvFZFpbOTblv59/jEHWlJ5BPYMEl/xigPbpOMO7PC9iWgxp4zcY5RtoSwo/nPt9aJRSyFpVAPQ1bIWPKQkn0p3UNQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>
  • Delivery-date: Wed, 07 Oct 2026 18:11:25 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

Symbol records in the compressed stream are stored as [type][name]: the
symbol type byte is part of the compressed data ("include the type field
in the symbol name, so that it gets compressed together"). A compression
token can therefore expand to a full record, i.e. the type byte followed
by an entire legal 127-byte name: 1 + 127 = 128 bytes.

write_src() expands every token into a local buffer to emit the token
dictionary, and expand_symbol() appends a terminating NUL to the result.
The buffer was char buf[KSYM_NAME_LEN + 1] (128 bytes) -- room for the
type and name, but not for the NUL. A token covering a full record
overruns it by one byte.

Allocate KSYM_NAME_LEN + 2 bytes, so the buffer holds type + name + NUL
(1 + 127 + 1 = 129 bytes). The previous patch limits names to
KSYM_NAME_LEN bytes, so no token can be longer than this.

This is a host generator overflow that occurs even when every symbol
name satisfies the runtime limit. It needs a token that covers a whole
record, which only happens with a very small symbol table. Real symbol
tables do not trigger it, and Xen itself is not affected.

A host reproducer supplies 64 identical 127-byte names of type T at
successive addresses. The original generator reports:

  SUMMARY: AddressSanitizer: stack-buffer-overflow xen/tools/symbols.c:307 in 
expand_symbol

The overflowing object is reported as:

  [1184, 1312) 'buf' (line 341) <== Memory access at offset 1312 overflows this 
variable

The fixed generator processes the same input successfully under
ASan/UBSan with no diagnostics.

Assisted-by: Codex:GPT-6.1
Assisted-by: Copilot:claude-sonnet-5.5 # host and x86 build tests
Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
---
 xen/tools/symbols.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/xen/tools/symbols.c b/xen/tools/symbols.c
index e15273a8ad..f6319d6259 100644
--- a/xen/tools/symbols.c
+++ b/xen/tools/symbols.c
@@ -338,7 +338,8 @@ static void write_src(void)
        unsigned int i, k, off, ends;
        unsigned int best_idx[256];
        unsigned int *markers;
-       char buf[KSYM_NAME_LEN+1];
+       /* Type byte, longest name and terminating NUL. */
+       char buf[KSYM_NAME_LEN + 2];
 
        if (map_only) {
                for (i = 0; i < table_cnt; i++)
-- 
2.53.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.