From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v1 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader
Date: Mon, 20 Jul 2026 18:08:28 +0000 [thread overview]
Message-ID: <20260720180829.7AAB71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260720175455.3645946-3-irogers@google.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Error recovery via `io__drain_line()` incorrectly consumes and discards the next valid map entry if a parsing failure occurs due to a premature newline character.
- [Medium] The PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT flag is silently dropped if the truncation timeout triggers on a map entry that fails the PROT_EXEC/mmap_data filters.
--
--- Patch [2]: [PATCH v1 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader ---
commit 21e332ccbb14a1f50a59ea36a8f2a24a05ff7df8
Author: Ian Rogers <irogers@google.com>
perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader
This commit addresses logic and boundary bugs in read_proc_maps_line() and its
caller. It ensures that mid-line parsing failures invoke io__drain_line() to
preserve synchronization and replaces truncation bugs with a standard fallback
literal.
> diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic-events.c
> index 5307d707711d8..723b7323c06d9 100644
> --- a/tools/perf/util/synthetic-events.c
> +++ b/tools/perf/util/synthetic-events.c
> @@ -291,6 +291,15 @@ static int perf_event__synthesize_fork(const struct perf_tool *tool,
> return 0;
> }
>
> +static void io__drain_line(struct io *io)
> +{
> + int ch;
> +
> + do {
> + ch = io__get_char(io);
> + } while (ch >= 0 && ch != '\n');
> +}
> +
> static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end,
> u32 *prot, u32 *flags, __u64 *offset,
> u32 *maj, u32 *min,
> @@ -299,69 +308,121 @@ static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end,
> {
> __u64 temp;
> int ch;
> - char *start_pathname = pathname;
> + size_t written = 0;
> + bool overflowed = false;
>
> - if (io__get_hex(io, start) != '-')
> + if (io__get_hex(io, start) != '-') {
> + if (!io->eof)
> + io__drain_line(io);
[Severity: High]
If a parser like io__get_hex() or io__get_char() fails because it encounters a
premature newline character, does calling io__drain_line() here unintentionally
consume and discard the next valid map entry?
Since the newline character for the malformed line would have already been
consumed by the parser, it appears io__drain_line() might read until the end
of the subsequent line, causing it to be skipped.
> + return false;
> + }
[ ... ]
> @@ -487,50 +544,64 @@ int perf_event__synthesize_mmap_events(const struct perf_tool *tool,
[ ... ]
> - if ((event->mmap2.prot & PROT_EXEC) == 0) {
> - if (!mmap_data || (event->mmap2.prot & PROT_READ) == 0)
> + if ((prot & PROT_EXEC) == 0) {
> + if (!mmap_data || (prot & PROT_READ) == 0) {
> + if (truncation)
> + break;
[Severity: Medium]
When the truncation timeout triggers on a map entry that fails the PROT_EXEC
or mmap_data filters, does this break prevent the timeout flag
(PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT) from being set and emitted?
By breaking out of the loop early here, it seems the code bypasses both the
PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT assignment and the call to
perf_tool__process_synth_event(), which might leave analysis tools unaware
that the data stream was truncated.
> continue;
> + }
>
> event->header.misc |= PERF_RECORD_MISC_MMAP_DATA;
> }
>
> -out:
> if (truncation)
> event->header.misc |= PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260720175455.3645946-1-irogers@google.com?part=2
next prev parent reply other threads:[~2026-07-20 18:08 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 17:54 [PATCH v1 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-20 17:54 ` [PATCH v1 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-20 18:05 ` sashiko-bot
2026-07-20 17:54 ` [PATCH v1 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-20 18:08 ` sashiko-bot [this message]
2026-07-20 17:54 ` [PATCH v1 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-20 17:54 ` [PATCH v1 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-20 18:28 ` sashiko-bot
2026-07-20 22:51 ` [PATCH v2 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-20 22:51 ` [PATCH v2 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-20 22:51 ` [PATCH v2 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-20 23:03 ` sashiko-bot
2026-07-20 22:51 ` [PATCH v2 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-20 22:52 ` [PATCH v2 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-21 17:33 ` [PATCH v3 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-21 17:33 ` [PATCH v3 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-21 17:33 ` [PATCH v3 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-21 17:48 ` sashiko-bot
2026-07-21 17:33 ` [PATCH v3 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-21 17:47 ` sashiko-bot
2026-07-21 17:33 ` [PATCH v3 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-21 18:21 ` [PATCH v4 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-21 18:21 ` [PATCH v4 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-21 18:21 ` [PATCH v4 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-21 19:26 ` sashiko-bot
2026-07-21 18:21 ` [PATCH v4 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-21 18:21 ` [PATCH v4 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-21 19:25 ` sashiko-bot
2026-07-21 20:57 ` [PATCH v5 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-21 20:57 ` [PATCH v5 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-21 20:57 ` [PATCH v5 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-21 21:15 ` sashiko-bot
2026-07-21 20:57 ` [PATCH v5 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-21 20:57 ` [PATCH v5 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-21 23:09 ` [PATCH v6 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-21 23:09 ` [PATCH v6 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-21 23:09 ` [PATCH v6 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-21 23:24 ` sashiko-bot
2026-07-21 23:09 ` [PATCH v6 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-21 23:09 ` [PATCH v6 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-21 23:52 ` [PATCH v7 0/5] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
2026-07-21 23:52 ` [PATCH v7 1/5] perf find-map: Remove PATH_MAX 128-byte stack array restriction Ian Rogers
2026-07-21 23:52 ` [PATCH v7 2/5] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader Ian Rogers
2026-07-22 0:10 ` sashiko-bot
2026-07-21 23:52 ` [PATCH v7 3/5] perf synthetic-events: Fix stack buffer overflow and bounds in cgroup synthesis Ian Rogers
2026-07-22 0:04 ` sashiko-bot
2026-07-21 23:52 ` [PATCH v7 4/5] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis Ian Rogers
2026-07-21 23:52 ` [PATCH v7 5/5] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis Ian Rogers
2026-07-22 0:13 ` [PATCH v7 0/5] perf: Fix and optimize maps parsing, boundaries, and bounds safety Ian Rogers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720180829.7AAB71F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=irogers@google.com \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.