All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vincent Donnefort" <vdonnefort@google.com>
Cc: linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length
Date: Wed, 12 Aug 2026 16:42:41 +0000	[thread overview]
Message-ID: <20260812164242.085961F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260812161340.2417322-6-vdonnefort@google.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [High] The patch unconditionally introduces `type_len` compression for small events and hardcodes 4-byte alignment, ignoring `RB_FORCE_8BYTE_ALIGNMENT` and `RB_ARCH_ALIGNMENT`. This causes payload truncation and unaligned accesses on architectures requiring 8-byte alignment.

Pre-existing issues:
- [High] `simple_ring_buffer_reserve` lacks a bounds check to prevent `event_size` from exceeding the maximum page capacity (`PAGE_SIZE - BUF_PAGE_HDR_SIZE`).
--

--- Patch [5]: [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length ---
commit 661f4dfe638155c632fb481b814114210260a54c
Author: Vincent Donnefort <vdonnefort@google.com>

tracing/simple_ring_buffer: Add support for compressed length

This patch adds support for compressing the event length into the event
header type for small events in the simple ring buffer, saving 32 bits
per event. It enforces a 4-byte alignment for the compressed length.

> diff --git a/kernel/trace/simple_ring_buffer.c b/kernel/trace/simple_ring_buffer.c
> index f4642f5adda33..1a97d17cca246 100644
> --- a/kernel/trace/simple_ring_buffer.c
> +++ b/kernel/trace/simple_ring_buffer.c
> @@ -207,7 +207,15 @@ static unsigned long rb_event_size(unsigned long length)
>  {
>  	struct ring_buffer_event *event;
>  
> -	return length + RB_EVNT_HDR_SIZE + sizeof(event->array[0]);
> +	if (!length)
> +		length++;
> +
> +	length = ALIGN(length, RB_ALIGNMENT);

[Severity: High]
Does this hardcoded 4-byte alignment cause unaligned access exceptions on
architectures that require 8-byte alignment (where RB_FORCE_8BYTE_ALIGNMENT
is 1)?

It looks like using RB_ARCH_ALIGNMENT instead of RB_ALIGNMENT would prevent
these exceptions.

> +
> +	if (length > RB_MAX_SMALL_DATA)
> +		length += sizeof(event->array[0]);
> +
> +	return length + RB_EVNT_HDR_SIZE;
>  }

[ ... ]

> @@ -259,9 +270,13 @@ simple_rb_reserve_next(struct simple_rb_per_cpu *cpu_buffer, unsigned long lengt
>  		time_delta = 0;
>  	}
>  
> -	event->type_len = 0;
> +	if (length > RB_MAX_SMALL_DATA) {
> +		event->type_len = 0;
> +		event->array[0] = array_size;
> +	} else {
> +		event->type_len = DIV_ROUND_UP(array_size, RB_ALIGNMENT);
> +	}

[Severity: High]
Can this unconditional compression cause payload truncation on architectures
requiring 8-byte alignment?

If RB_FORCE_8BYTE_ALIGNMENT is set, it seems the core ring buffer reader
(ring_buffer_event_length) might subsequently subtract 4 bytes erroneously,
leading to data loss and potential out-of-bounds reads when parsing the event.

>  	event->time_delta = time_delta;
> -	event->array[0] = event_size - RB_EVNT_HDR_SIZE;
>  
>  	return event;
>  }
> @@ -284,7 +299,7 @@ void *simple_ring_buffer_reserve(struct simple_rb_per_cpu *cpu_buffer, unsigned
>  
>  	rb_event = simple_rb_reserve_next(cpu_buffer, length, timestamp);
>  
> -	return &rb_event->array[1];
> +	return rb_event->type_len ? &rb_event->array[0] : &rb_event->array[1];

[Severity: High]
This is a pre-existing issue, but does simple_ring_buffer_reserve() lack a
bounds check for events larger than the maximum page capacity?

If a caller attempts to reserve an event with a length exceeding
PAGE_SIZE - BUF_PAGE_HDR_SIZE, simple_rb_reserve_next() will move to a new
page and set the write index beyond the page boundary. This would return a
pointer that allows the caller to write out of bounds.

Would it be safer to validate that length is smaller than the maximum buffer
page data size before proceeding with the reservation?

>  }
>  EXPORT_SYMBOL_GPL(simple_ring_buffer_reserve);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260812161340.2417322-1-vdonnefort@google.com?part=5

  reply	other threads:[~2026-08-12 16:42 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12 16:13 [PATCH v5 00/18] tracing/remotes: Add printk, dump_on_panic and boot parameters Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration Vincent Donnefort
2026-08-12 16:31   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 02/18] tracing/remotes: Release tracefs,eventfs on registration failure Vincent Donnefort
2026-08-12 16:25   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 03/18] tracing/remotes: Use kstrtobool for boolean tracefs files Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 04/18] tracing/remotes: Use a single per-remote polling work Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot [this message]
2026-08-12 16:13 ` [PATCH v5 06/18] tracing/remotes: Add dmesg tracefs file Vincent Donnefort
2026-08-12 16:42   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 07/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-12 16:40   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 08/18] tracing/remotes: selftests: Prefix hypervisor folder Vincent Donnefort
2026-08-12 16:52   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 09/18] ring-buffer: Use irqsave for the reader lock in ring_buffer_poll_remote Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 10/18] ring-buffer: Use panic-friendly locking in ring_buffer_iter interface Vincent Donnefort
2026-08-12 16:54   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 11/18] ring-buffer: Add ring_buffer_read_remote_meta_page() Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 12/18] ring-buffer: Add kerneldoc for ring_buffer_poll_remote Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 13/18] tracing/remotes: Add dump_on_panic tracefs file Vincent Donnefort
2026-08-12 17:08   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 14/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-12 17:02   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 15/18] tracing/remotes: Add poll_ms " Vincent Donnefort
2026-08-12 17:13   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 16/18] tracing/remotes: Add trace_remote cmdline options Vincent Donnefort
2026-08-12 17:11   ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 17/18] Documentation: tracing/remotes: Add detailed tracefs layout Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 18/18] Documentation/kernel-parameters: Add trace_remote Vincent Donnefort

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260812164242.085961F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vdonnefort@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.