From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com [209.85.216.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7233943C04D for ; Tue, 21 Jul 2026 23:09:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.72 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784675397; cv=none; b=clfR1TinNA/niiZY4aXwnQUKxjkUHgDlTs4/0MZLnacy/ShcekKwHoQiYt4c+xARnimW+RmnsGyGU1zX65RJKIyNssWmMllFiPuntiOeBFlw57k6K/SfFSilcpYjgKXEYWV578P9KeiiwI+rcNLhTTIUPAHAOOswzCXzzOelAEo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784675397; c=relaxed/simple; bh=NZHqzcrqGwdK5Lc5SPDVbw2rQqp8o7YUG+AKlyMz89w=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=GjvcVpk9tPsSbzWLBthI5oG351yOVBfcqhdaiORJFPHkQqGRF01OyNjehxwd5DpMSwn6JKHAvMHxbZhwf2sd0Q2wiyJTSxQtEuKOLCheUpxdFL7cLQ1kYg9Ve0ZJ0+2WS+2QCRSFsow7r6rMy7wcMitGVDEZ0zl9SVVsPW2Mk68= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=YfGzLbT7; arc=none smtp.client-ip=209.85.216.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="YfGzLbT7" Received: by mail-pj1-f72.google.com with SMTP id 98e67ed59e1d1-381250979d5so9057795a91.0 for ; Tue, 21 Jul 2026 16:09:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784675396; x=1785280196; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=sRt81Ta6pTSr62C6hADYhlpri9jzv7r3UrqNrrgbOjo=; b=YfGzLbT7iF/0pyewcB8pnGi8bdbcLIeeoJZYoJs0U1VGqTgJNSg8fh4ViQ6vTvKHM4 mfADmLOp5gFEM8K/HS/NmOU4CrCq03d8kIUenedBUXRGltqD3el2LFqmxHYG3h1rP9f+ SP5tckK5TANB0oTP/OIFnYj8VJf91fNrU17QKU1TMR/H6oU6e2QXAjr2bp+ah0O9rMoF z2OU2fxqBIElMI0eiAXjhqKAkL33DiofezTR9/kg9K1XXVyDtoeNeUrgiMFy4KQy6ISj yNBuCdGTJhEA7WJfRRxfI2HKX4uOt6KrfTuB3+bdeDX5e5IHZF4/T7d+CHl8ZxNvQPK1 ejUA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784675396; x=1785280196; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sRt81Ta6pTSr62C6hADYhlpri9jzv7r3UrqNrrgbOjo=; b=K34yl2rMz9RMvqsTcF43riDbxHJUMbjM/ghOxf05MJ2f2qSJo15PAJgtYVG5izpMgX wyiSj398EsQj7+GSYzaYw0Y/yiPdcB7Ru4EFyVCyPCD40OhdjBVk38ReW8BP54QIjlNg mewBakNvfwHhL24/hDVzX/r348hYsdZW/h+oZv4zQKMY2gqOnuSrYmrCFGCpr/Li9aOQ R9R+k9UkLfZY3IP7I1ZpbDpHQWpggvmjV1nm4x1hbN4+WJHtq5jtKIsrO/I90+rYvkW3 pW04w1VlTrawKPcJru3ooXNMW71cQ24h+g3LxjnBI/CleNzfNC5EAbMzKHAtF6vBACNP xECw== X-Forwarded-Encrypted: i=1; AHgh+RqF1Hp9VBrQB5rP5jEofXC/hTSWVlT3WHmcfkXFVp/Z5oVx6QSht5e7anux03FK6koRYXSnQlysXV0aXAc=@vger.kernel.org X-Gm-Message-State: AOJu0YzUNLlPmDznz8AGxPgwekTRpNvBefqbY9XzJzbH77GnxYh0b18n CGrnZBZcZjmCzerxcUXQrbJ3kzWllvs08xE65KbrgUEADnYAvMCk64zD9P0zqIgJdX0iiRX7T4t GFXT2ViVdRg== X-Received: from dlbbq44.prod.google.com ([2002:a05:7022:672c:b0:13b:447c:4e36]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:2f0f:b0:387:e0db:bc31 with SMTP id 98e67ed59e1d1-38e4b56ed5fmr20715701a91.39.1784675395457; Tue, 21 Jul 2026 16:09:55 -0700 (PDT) Date: Tue, 21 Jul 2026 16:09:48 -0700 In-Reply-To: <20260721205746.183206-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721205746.183206-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721230952.267754-1-irogers@google.com> Subject: [PATCH v6 0/4] perf: Fix and optimize maps parsing, boundaries, and bounds safety From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Type: text/plain; charset="UTF-8" It turns out that PATH_MAX is respected by system calls but isn't respected by file paths in /proc/pid/maps and /proc/pid/smaps. In the kernel "//toolong" is placed in the filename of mmap/mmap2 events where the filename is longer than PATH_MAX, do the same in the mmap/mmap2 synthesis code to avoid overrunning the event buffer - note, the filename buffer is bounds checked but this makes the synthesis more similar to the kernel approach. With Gemini's help try to address other correctness and overrun issues. V6 addresses review feedback: - Ensures Patch 2 leaves perf_event__synthesize_modules_maps_cb() completely untouched, preserving the pre-existing build ID clearing logic in baseline. - Patch 3 explicitly clears PERF_RECORD_MISC_MMAP_BUILD_ID, build_id, and reserved union padding members in module synthesis callbacks to guarantee no stale Build-ID state leaks between module synthesis iterations. V5 addresses technical review feedback: - Clamps pathname buffer sizes in read_proc_maps_line() and module synthesis callbacks by subtracting machine->id_hdr_size. - Casts member array memset destination pointers to (char *)event + offsetof(...) across all synthesis handlers. - Restricts max_filename_len in perf_event__synthesize_mmap2_build_id() to the minimum of filename array capacity and union payload space. V4 addresses review feedback: - Ensures io__drain_line()'s do-while loop is committed directly in Patch 2. V3 addresses review feedback: - Updates io__drain_line() loop condition from a while loop to a do-while loop. V2 addresses community review feedback: - Corrects read_proc_maps_line() and io__drain_line() to safely handle already consumed newlines. - Restores early exit block for timeouts so TIMEOUT flag is emitted to tools. - Removes unused assignment to avoid promoting warnings to build errors. Ian Rogers (4): perf find-map: Remove PATH_MAX 128-byte stack array restriction perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis tools/perf/util/find-map.c | 10 +- tools/perf/util/synthetic-events.c | 294 ++++++++++++++++++++--------- 2 files changed, 212 insertions(+), 92 deletions(-) -- 2.55.0.229.g6434b31f56-goog