All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sizhe Liu" <liusizhe5@huawei.com>
Cc: linux-perf-users@vger.kernel.org, linux-pci@vger.kernel.org
Subject: Re: [PATCH v2 2/3] perf hisi-ptt: Strengthen auxtrace event handling and packet type detection
Date: Thu, 30 Jul 2026 06:50:51 +0000	[thread overview]
Message-ID: <20260730065051.E875D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260730062709.534139-3-liusizhe5@huawei.com>

> Fix pre-existing robustness issues in the hisi-ptt auxtrace decoder
> reported by Sashiko:
> 
> 1. Endianness in hisi_ptt_check_packet_type(): The first 32-bit word was
> read with a host-endian memory cast (*(uint32_t *)buf). On big-endian
> hosts analyzing a little-endian trace, the bit[31:11] 8DW magic check
> fails and every 8DW packet is misclassified as 4DW. Read the header
> with get_unaligned_le32().
> 
> 2. Heap out-of-bounds read: hisi_ptt_dump() called
> hisi_ptt_check_packet_type() which dereferenced 4 bytes of the buffer
> without any size check. A malformed or truncated event with
> auxtrace.size in {0,1,2,3} may cause a heap OOB read. Pass the buffer
> length to hisi_ptt_check_packet_type() and return (defaulting to
> 4DW) when the buffer is shorter than HISI_PTT_FIELD_LENTH.
> 
> 3. Integer truncation: event->auxtrace.size is __u64 but was stored in
> an int. Traces larger than 2GB became negative (malloc failure), and
> huge sizes wrapping to a small positive caused a short readn() that
> left unread payload in the pipe and permanently desynchronized the
> stream. Use u64 for the size, reject anything larger than SSIZE_MAX
> before malloc (same bound used by auxtrace_copy_data()), and compare
> readn()'s return value against (ssize_t)size to detect truncation.
> 
> Signed-off-by: Sizhe Liu <liusizhe5@huawei.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260730062709.534139-1-liusizhe5@huawei.com?part=2


  reply	other threads:[~2026-07-30  6:50 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30  6:27 [PATCH v2 0/3] perf hisi-ptt: Fix TLP header parsing and naming Sizhe Liu
2026-07-30  6:27 ` [PATCH v2 1/3] perf hisi-ptt: Fix PTT trace TLP header parsing Sizhe Liu
2026-07-30  6:43   ` sashiko-bot
2026-07-30  6:27 ` [PATCH v2 2/3] perf hisi-ptt: Strengthen auxtrace event handling and packet type detection Sizhe Liu
2026-07-30  6:50   ` sashiko-bot [this message]
2026-07-30  6:27 ` [PATCH v2 3/3] perf hisi-ptt: Fix spelling and abbreviation errors Sizhe Liu
2026-07-30  6:34   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260730065051.E875D1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=liusizhe5@huawei.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.