From 0f99c799d33715e72a99299eb6f265424b16f6f5 Mon Sep 17 00:00:00 2001 From: Huaicheng Li Date: Sun, 27 Sep 2026 02:44:59 -0400 Subject: [PATCH 1/2] baselines: repair older host-tool builds and Memtis vmstat guards --- baselines/README.md | 11 ++++ baselines/common/apply-build-fixes.sh | 13 +++++ baselines/common/libsubcmd-realloc.patch | 66 ++++++++++++++++++++++++ baselines/memtis/README.md | 9 ++++ baselines/memtis/memtis-vmstat.patch | 25 +++++++++ baselines/memtis/setup_memtis.sh | 2 + baselines/nomad/compile.sh | 2 + baselines/tpp/compile.sh | 2 + 8 files changed, 130 insertions(+) create mode 100644 baselines/common/apply-build-fixes.sh create mode 100644 baselines/common/libsubcmd-realloc.patch create mode 100644 baselines/memtis/memtis-vmstat.patch diff --git a/baselines/README.md b/baselines/README.md index b511001..116e4f0 100644 --- a/baselines/README.md +++ b/baselines/README.md @@ -35,3 +35,14 @@ Each baseline lives in its own subdirectory with a kernel patch, a * These directories ship the kernel patches and build scripts. They do not include per-system workload run wrappers; boot the patched kernel and drive workloads with your own launcher (PACT's own runner is in [`../`](../)). + +## Older-kernel build compatibility + +TPP, Nomad and Memtis builds also apply +[`common/libsubcmd-realloc.patch`](common/libsubcmd-realloc.patch), upstream Linux +commit `52a9dab6d892763b2a8334a568bd4e2c1a6fde66`. It fixes the host-tool +`realloc(ptr, 0)` use-after-free diagnosed by GCC 12 and newer. The patch retains +its upstream authorship and the affected file's GPL-2.0 license. It does not +change kernel tiering policy. The helper skips the fix when already present +and stops if neither patch direction applies; it does not suppress compiler +warnings. NBT and the Linux 6.3 baselines already contain this fix. diff --git a/baselines/common/apply-build-fixes.sh b/baselines/common/apply-build-fixes.sh new file mode 100644 index 0000000..8539991 --- /dev/null +++ b/baselines/common/apply-build-fixes.sh @@ -0,0 +1,13 @@ +#!/bin/bash +# Apply the upstream host-tool fix needed by pre-5.17 baseline kernels. +set -euo pipefail +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +[[ $# -eq 1 ]] || { echo "Usage: $0 KERNEL_DIR" >&2; exit 2; } +KERNEL_DIR="$1" +PATCH="$SCRIPT_DIR/libsubcmd-realloc.patch" +if git -C "$KERNEL_DIR" apply --reverse --check "$PATCH" >/dev/null 2>&1; then + echo "libsubcmd realloc fix already present" +else + git -C "$KERNEL_DIR" apply --check "$PATCH" + git -C "$KERNEL_DIR" apply "$PATCH" +fi diff --git a/baselines/common/libsubcmd-realloc.patch b/baselines/common/libsubcmd-realloc.patch new file mode 100644 index 0000000..e14d518 --- /dev/null +++ b/baselines/common/libsubcmd-realloc.patch @@ -0,0 +1,66 @@ +From 52a9dab6d892763b2a8334a568bd4e2c1a6fde66 Mon Sep 17 00:00:00 2001 +From: Kees Cook +Date: Sun, 13 Feb 2022 10:24:43 -0800 +Subject: [PATCH] libsubcmd: Fix use-after-free for realloc(..., 0) +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +GCC 12 correctly reports a potential use-after-free condition in the +xrealloc helper. Fix the warning by avoiding an implicit "free(ptr)" +when size == 0: + +In file included from help.c:12: +In function 'xrealloc', + inlined from 'add_cmdname' at help.c:24:2: subcmd-util.h:56:23: error: pointer may be used after 'realloc' [-Werror=use-after-free] + 56 | ret = realloc(ptr, size); + | ^~~~~~~~~~~~~~~~~~ +subcmd-util.h:52:21: note: call to 'realloc' here + 52 | void *ret = realloc(ptr, size); + | ^~~~~~~~~~~~~~~~~~ +subcmd-util.h:58:31: error: pointer may be used after 'realloc' [-Werror=use-after-free] + 58 | ret = realloc(ptr, 1); + | ^~~~~~~~~~~~~~~ +subcmd-util.h:52:21: note: call to 'realloc' here + 52 | void *ret = realloc(ptr, size); + | ^~~~~~~~~~~~~~~~~~ + +Fixes: 2f4ce5ec1d447beb ("perf tools: Finalize subcmd independence") +Reported-by: Valdis Klētnieks +Signed-off-by: Kees Kook +Tested-by: Valdis Klētnieks +Tested-by: Justin M. Forbes +Acked-by: Josh Poimboeuf +Cc: linux-hardening@vger.kernel.org +Cc: Valdis Klētnieks +Link: http://lore.kernel.org/lkml/20220213182443.4037039-1-keescook@chromium.org +Signed-off-by: Arnaldo Carvalho de Melo +--- + tools/lib/subcmd/subcmd-util.h | 11 ++--------- + 1 file changed, 2 insertions(+), 9 deletions(-) + +diff --git a/tools/lib/subcmd/subcmd-util.h b/tools/lib/subcmd/subcmd-util.h +index 794a375dad36..b2aec04fce8f 100644 +--- a/tools/lib/subcmd/subcmd-util.h ++++ b/tools/lib/subcmd/subcmd-util.h +@@ -50,15 +50,8 @@ static NORETURN inline void die(const char *err, ...) + static inline void *xrealloc(void *ptr, size_t size) + { + void *ret = realloc(ptr, size); +- if (!ret && !size) +- ret = realloc(ptr, 1); +- if (!ret) { +- ret = realloc(ptr, size); +- if (!ret && !size) +- ret = realloc(ptr, 1); +- if (!ret) +- die("Out of memory, realloc failed"); +- } ++ if (!ret) ++ die("Out of memory, realloc failed"); + return ret; + } + +-- +2.43.0 + diff --git a/baselines/memtis/README.md b/baselines/memtis/README.md index 564f06c..145d22c 100644 --- a/baselines/memtis/README.md +++ b/baselines/memtis/README.md @@ -72,3 +72,12 @@ Verify after reboot: uname -r # expected: 5.15.19-htmm ``` + +## Build corrections + +The setup script applies `memtis-vmstat.patch` after the original Memtis patch. +It makes HTMM counter names independent of memory-balloon support, matching +the counter enums and allowing builds with `CONFIG_MEMORY_BALLOON=n`. The +shared host-tool fix described in [`../README.md`](../README.md) also enables +compilation with newer GCC versions. Neither correction changes placement +policy. Local compilation does not establish boot or workload performance. diff --git a/baselines/memtis/memtis-vmstat.patch b/baselines/memtis/memtis-vmstat.patch new file mode 100644 index 0000000..6df577b --- /dev/null +++ b/baselines/memtis/memtis-vmstat.patch @@ -0,0 +1,25 @@ +Subject: [PATCH] mm: expose Memtis vmstat names independently of balloon support + +HTMM event enums are enabled by CONFIG_HTMM alone. The original Memtis patch +nested their text labels inside CONFIG_MEMORY_BALLOON, leaving the vmstat +array eight entries short when balloon support is disabled. Match the enum +conditionals so that those configurations compile and preserve counter names. + +--- a/mm/vmstat.c ++++ b/mm/vmstat.c +@@ -1361,6 +1361,7 @@ + #ifdef CONFIG_BALLOON_COMPACTION + "balloon_migrate", + #endif ++#endif /* CONFIG_MEMORY_BALLOON */ + #ifdef CONFIG_HTMM + "htmm_nr_promoted", + "htmm_nr_demoted", +@@ -1371,7 +1372,6 @@ + "htmm_alloc_dram", + "htmm_alloc_nvm", + #endif +-#endif /* CONFIG_MEMORY_BALLOON */ + #ifdef CONFIG_DEBUG_TLBFLUSH + "nr_tlb_remote_flush", + "nr_tlb_remote_flush_received", diff --git a/baselines/memtis/setup_memtis.sh b/baselines/memtis/setup_memtis.sh index a9c1139..1aae4db 100755 --- a/baselines/memtis/setup_memtis.sh +++ b/baselines/memtis/setup_memtis.sh @@ -53,6 +53,8 @@ patch -p1 --dry-run < "$PATCH_FILE" echo "==> Applying memtis.patch..." patch -p1 < "$PATCH_FILE" echo " Patch applied successfully." +git apply "$SCRIPT_DIR/memtis-vmstat.patch" +bash "$SCRIPT_DIR/../common/apply-build-fixes.sh" "$KERNEL_DIR" # --------------------------------------------------------------------------- # 3. Kernel configuration diff --git a/baselines/nomad/compile.sh b/baselines/nomad/compile.sh index ffc9a3a..38c642e 100755 --- a/baselines/nomad/compile.sh +++ b/baselines/nomad/compile.sh @@ -20,6 +20,8 @@ for p in "${PATCHES[@]}"; do git apply "$p" done +bash "$SCRIPT_DIR/../common/apply-build-fixes.sh" "$KERNEL_DIR" + # Base the config on the running kernel, then resolve new symbols # non-interactively. (Do NOT pipe `yes` into `make oldconfig`: under # `set -o pipefail`, `yes` dies with SIGPIPE and aborts the build.) diff --git a/baselines/tpp/compile.sh b/baselines/tpp/compile.sh index 67593d2..9cf5a47 100755 --- a/baselines/tpp/compile.sh +++ b/baselines/tpp/compile.sh @@ -22,6 +22,8 @@ else git apply "$PATCH" fi +bash "$SCRIPT_DIR/../common/apply-build-fixes.sh" "$KERNEL_DIR" + # Base the config on the running kernel, then resolve new symbols # non-interactively. (Do NOT pipe `yes` into `make oldconfig`: under # `set -o pipefail`, `yes` dies with SIGPIPE and aborts the build.) From 7f4c7d39b3749d67dd30e27b79aefb6e1f478b6e Mon Sep 17 00:00:00 2001 From: Huaicheng Li Date: Sun, 27 Sep 2026 03:05:58 -0400 Subject: [PATCH 2/2] baselines: keep Colloid tier reset builds warning-clean --- baselines/README.md | 4 ++++ baselines/colloid-tpp/compile.sh | 2 +- baselines/common/colloid-build.patch | 16 ++++++++++++++++ baselines/soar-alto/compile.sh | 2 +- 4 files changed, 22 insertions(+), 2 deletions(-) create mode 100644 baselines/common/colloid-build.patch diff --git a/baselines/README.md b/baselines/README.md index 116e4f0..b99330b 100644 --- a/baselines/README.md +++ b/baselines/README.md @@ -46,3 +46,7 @@ its upstream authorship and the affected file's GPL-2.0 license. It does not change kernel tiering policy. The helper skips the fix when already present and stops if neither patch direction applies; it does not suppress compiler warnings. NBT and the Linux 6.3 baselines already contain this fix. + +Colloid-tpp and Soar/Alto also apply `common/colloid-build.patch`, which removes +an unused declaration in the tier-reset helper so `CONFIG_WERROR=y` builds +succeed. It leaves the helper's operations and tiering policy unchanged. diff --git a/baselines/colloid-tpp/compile.sh b/baselines/colloid-tpp/compile.sh index c4c1bb9..f06287b 100755 --- a/baselines/colloid-tpp/compile.sh +++ b/baselines/colloid-tpp/compile.sh @@ -6,7 +6,7 @@ set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" KERNEL_DIR="$SCRIPT_DIR/linux" LOGF="$SCRIPT_DIR/log" -PATCHES=("$SCRIPT_DIR/colloid-skx.patch" "$SCRIPT_DIR/colloid-skx-alto.patch") +PATCHES=("$SCRIPT_DIR/colloid-skx.patch" "$SCRIPT_DIR/colloid-skx-alto.patch" "$SCRIPT_DIR/../common/colloid-build.patch") [[ -d "$KERNEL_DIR" ]] || { echo "ERROR: kernel tree not found at $KERNEL_DIR (clone Linux there first)"; exit 1; } for p in "${PATCHES[@]}"; do diff --git a/baselines/common/colloid-build.patch b/baselines/common/colloid-build.patch new file mode 100644 index 0000000..8efb499 --- /dev/null +++ b/baselines/common/colloid-build.patch @@ -0,0 +1,16 @@ +Subject: [PATCH] mm: remove unused Colloid tier-reset declaration + +The reset helper does not use a memory_tier pointer. Drop the declaration +so CONFIG_WERROR builds succeed without weakening compiler checks. + +--- a/mm/memory-tiers.c ++++ b/mm/memory-tiers.c +@@ -672,8 +672,6 @@ + EXPORT_SYMBOL_GPL(colloid_init_memory_tier); + + void colloid_clear_memory_tier(int node) { +- struct memory_tier *memtier; +- + mutex_lock(&memory_tier_lock); + clear_node_memory_tier(node); + pr_info("clear_node_memory_tier"); diff --git a/baselines/soar-alto/compile.sh b/baselines/soar-alto/compile.sh index 87e77bf..9efa52b 100755 --- a/baselines/soar-alto/compile.sh +++ b/baselines/soar-alto/compile.sh @@ -7,7 +7,7 @@ set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" KERNEL_DIR="$SCRIPT_DIR/linux" LOGF="$SCRIPT_DIR/log" -PATCHES=("$SCRIPT_DIR/colloid-skx.patch" "$SCRIPT_DIR/colloid-skx-alto.patch") +PATCHES=("$SCRIPT_DIR/colloid-skx.patch" "$SCRIPT_DIR/colloid-skx-alto.patch" "$SCRIPT_DIR/../common/colloid-build.patch") [[ -d "$KERNEL_DIR" ]] || { echo "ERROR: kernel tree not found at $KERNEL_DIR (clone Linux there first)"; exit 1; } for p in "${PATCHES[@]}"; do