From: sashiko-bot@kernel.org
To: "Arnaldo Carvalho de Melo" <acme@kernel.org>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol()
Date: Thu, 13 Aug 2026 15:26:29 +0000 [thread overview]
Message-ID: <20260813152630.0D6E71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260813151148.23169-6-acme@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Misleading error code used for bounds check failure.
--
--- Patch [5]: [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() ---
commit 99fef42823fa80b278999b8901d74d88e812bd2a
Author: Arnaldo Carvalho de Melo <acme@redhat.com>
perf dso: Replace assert with runtime check in dso__read_symbol()
This commit replaces an assert in dso__read_symbol() with a runtime bounds
check to prevent out-of-bounds heap reads or assertion failures when processing
untrusted perf.data files.
> diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c
> index 4dd64069c4348..42bfe30a3b518 100644
> --- a/tools/perf/util/dso.c
> +++ b/tools/perf/util/dso.c
> @@ -2038,7 +2038,12 @@ const u8 *dso__read_symbol(struct dso *dso, const char *symfs_filename,
> errno = SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF;
> return NULL;
> }
> - assert(len <= info_linear->info.jited_prog_len);
> + if (len > info_linear->info.jited_prog_len) {
> + pr_debug("BPF symbol length %zu exceeds jited_prog_len %u\n",
> + len, info_linear->info.jited_prog_len);
> + errno = SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF;
[Severity: Medium]
Since this is a bounds check failure in dso__read_symbol() triggered by a
corrupted perf.data file, reusing SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF might
cause tools to incorrectly report that the BPF file is missing its BTF section
instead of indicating a length mismatch.
Could this regression result in a confusing message for the user?
> + return NULL;
> + }
> *out_buf_len = len;
> return (const u8 *)(uintptr_t)(info_linear->info.jited_prog_insns);
> #else
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813151148.23169-1-acme@kernel.org?part=5
next prev parent reply other threads:[~2026-08-13 15:26 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 15:11 [PATCHES v5 0/5] perf DSO hardening series Arnaldo Carvalho de Melo
2026-08-13 15:11 ` [PATCH 1/5] perf dso: Guard against errno==0 when dso__get_filename() returns NULL Arnaldo Carvalho de Melo
2026-08-13 15:24 ` sashiko-bot
2026-08-13 15:11 ` [PATCH 2/5] perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() Arnaldo Carvalho de Melo
2026-08-13 15:16 ` sashiko-bot
2026-08-13 15:11 ` [PATCH 3/5] perf dso: Use stored fd error instead of stale errno in file_read() and file_size() Arnaldo Carvalho de Melo
2026-08-13 15:17 ` sashiko-bot
2026-08-13 15:11 ` [PATCH 4/5] perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() Arnaldo Carvalho de Melo
2026-08-13 15:29 ` sashiko-bot
2026-08-13 15:11 ` [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() Arnaldo Carvalho de Melo
2026-08-13 15:26 ` sashiko-bot [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-08-13 0:49 [PATCHES v4 0/5] perf DSO hardening series Arnaldo Carvalho de Melo
2026-08-13 0:49 ` [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() Arnaldo Carvalho de Melo
2026-08-13 0:59 ` sashiko-bot
2026-08-11 17:51 [PATCHES v3 0/5] perf DSO hardening series Arnaldo Carvalho de Melo
2026-08-11 17:51 ` [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() Arnaldo Carvalho de Melo
2026-08-11 17:11 [PATCHES v2 0/5] perf DSO hardening series Arnaldo Carvalho de Melo
2026-08-11 17:12 ` [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() Arnaldo Carvalho de Melo
2026-08-02 14:20 [PATCHES 0/5] perf DSO hardening series Arnaldo Carvalho de Melo
2026-08-02 14:20 ` [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() Arnaldo Carvalho de Melo
2026-08-02 14:54 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260813152630.0D6E71F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=acme@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.