From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B0B5F350A05; Sat, 30 May 2026 17:16:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780161378; cv=none; b=BC4cKyz/XPMqiBuDPGZiYKSY9vn4omigq0pVi2QbpjhbP0oiyccJEroCvtJylH4MqSHAPJ9sbrWGwfHSbD218FTLjqkhPKdbGPwFOn2CjFKZF0f9/Q5HEcSuI4/48MorKDNQK5lpoj4Jvkmup9Amp1N1awekD1Y/wLU8CvEHtK4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780161378; c=relaxed/simple; bh=iE+BgybXWH8VAFxCeqk7Q25eKbAduAU7rhGPgq9Q/1g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gZcGHpD1lK9uyG46VlbVhzhOS8UTSinjRI7f2lUnjN+hLbaiA9O2Bo0rlmnajHZSQSjrVdBM/3L9Ao8JCz6++0xBe4WX294Ok40lxsiUnrScadOu7m7AGHbA0OVYqn/9DeODWdeIN6Dfgn/kBL829C8gn8tYROCADgi6RS8UsYs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=yGQMh/+8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="yGQMh/+8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 016CF1F00893; Sat, 30 May 2026 17:16:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1780161377; bh=cbPnHOSaYuRoZ0VKVj0BVsX84ADoZI3+hnnbh8ct54c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=yGQMh/+8bCeLsCAyPONtbRQFkPkuT2oCS2A68qfWPH/btbdfqvJqZu3iBfX0yAHEF VPXl2ataNp1FsAKBzGf50cZftjAvFFOxFikmCphi67kGBdYO35BUKyp5GFj1BOZzfw TFPsRkSD3/vAgkoAkeyYFnVYkDc+z6JN1SOq8MAE= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Tom Zanussi , Pengpeng Hou , "Steven Rostedt (Google)" , Sasha Levin Subject: [PATCH 6.1 599/969] tracing: Rebuild full_name on each hist_field_name() call Date: Sat, 30 May 2026 18:02:03 +0200 Message-ID: <20260530160316.962225167@linuxfoundation.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260530160300.485627683@linuxfoundation.org> References: <20260530160300.485627683@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Pengpeng Hou [ Upstream commit 5ec1d1e97de134beed3a5b08235a60fc1c51af96 ] hist_field_name() uses a static MAX_FILTER_STR_VAL buffer for fully qualified variable-reference names, but it currently appends into that buffer with strcat() without rebuilding it first. As a result, repeated calls append a new "system.event.field" name onto the previous one, which can eventually run past the end of full_name. Build the name with snprintf() on each call and return NULL if the fully qualified name does not fit in MAX_FILTER_STR_VAL. Link: https://patch.msgid.link/20260401112224.85582-1-pengpeng@iscas.ac.cn Fixes: 067fe038e70f ("tracing: Add variable reference handling to hist triggers") Reviewed-by: Tom Zanussi Tested-by: Tom Zanussi Signed-off-by: Pengpeng Hou Signed-off-by: Steven Rostedt (Google) Signed-off-by: Sasha Levin --- kernel/trace/trace_events_hist.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/kernel/trace/trace_events_hist.c b/kernel/trace/trace_events_hist.c index 356360e75f9a7..b5276f2f2cf40 100644 --- a/kernel/trace/trace_events_hist.c +++ b/kernel/trace/trace_events_hist.c @@ -1346,12 +1346,14 @@ static const char *hist_field_name(struct hist_field *field, field->flags & HIST_FIELD_FL_VAR_REF) { if (field->system) { static char full_name[MAX_FILTER_STR_VAL]; + int len; + + len = snprintf(full_name, sizeof(full_name), "%s.%s.%s", + field->system, field->event_name, + field->name); + if (len >= sizeof(full_name)) + return NULL; - strcat(full_name, field->system); - strcat(full_name, "."); - strcat(full_name, field->event_name); - strcat(full_name, "."); - strcat(full_name, field->name); field_name = full_name; } else field_name = field->name; -- 2.53.0