From: sashiko-bot@kernel.org
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v13 05/12] tracing/wprobe: Add wprobe (watchpoint probe) trace event support
Date: Sat, 22 Aug 2026 09:49:13 +0000 [thread overview]
Message-ID: <20260822094914.09C281F000E9@smtp.kernel.org> (raw)
In-Reply-To: <178739064718.1520941.13864925402314213363.stgit@devnote2>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The trace_wprobe_show function uses %pS to format the symbol address, breaking dynamic event restoration because kstrtoint() in parse_address_spec cannot parse the appended symbol size.
- [Medium] Address validation in parse_address_spec incorrectly exempts address 0 from the kernel space TASK_SIZE check, allowing user-space tracing at address 0.
--
--- Patch [5]: [PATCH v13 05/12] tracing/wprobe: Add wprobe (watchpoint probe) trace event support ---
commit 8eff80da8ae4225daa9b5646b430ded1a73ae7ae
Author: Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/wprobe: Add wprobe (watchpoint probe) trace event support
Add hardware-breakpoint-based dynamic trace event support (wprobe).
Wprobe creates a dynamic event on data read/write accesses using
hardware breakpoints and logs the access context and fetchargs.
Link: https://lore.kernel.org/all/59637b96946653393a7ad3c7de094094796b39c2.1785067572.git.wangjinchao600@gmail.com/
> diff --git a/kernel/trace/trace_wprobe.c b/kernel/trace/trace_wprobe.c
> new file mode 100644
> index 0000000000000..a8543766a245b
> --- /dev/null
> +++ b/kernel/trace/trace_wprobe.c
[ ... ]
> +static int parse_address_spec(const char *spec, unsigned long *addr, int *type,
> + int *len, char **symbol)
> +{
[ ... ]
> + if (kstrtoul(at + 1, 0, &_addr) != 0) {
> + char *off_str = strpbrk(at + 1, "+-");
> + int offset = 0;
> +
> + if (off_str) {
> + if (kstrtoint(off_str, 0, &offset) != 0) {
> + trace_probe_log_err(off_str - _spec, BAD_PROBE_ADDR);
> + return -EINVAL;
> + }
> + *off_str = '\0';
> + }
> + _addr = kallsyms_lookup_name(at + 1);
> + if (!_addr) {
> + trace_probe_log_err(at + 1 - _spec, BAD_ACCESS_ADDR);
> + return -ENOENT;
> + }
> + _addr += offset;
> + *symbol = kstrdup(at + 1, GFP_KERNEL);
> + if (!*symbol)
> + return -ENOMEM;
> + }
> +
> + if (_addr != 0 && _addr < TASK_SIZE) {
[Severity: Medium]
Does this allow user-space tracing at address 0?
The condition explicitly exempts _addr == 0. If a user specifies an address
of 0, it appears this would bypass the TASK_SIZE check and successfully
allow setting a hardware breakpoint in user space.
> + trace_probe_log_err(at + 1 - _spec, BAD_ACCESS_ADDR);
> + return -EINVAL;
> + }
> +
> + *addr = _addr;
> + *type = _type;
> + *len = _len;
> + return 0;
> +}
[ ... ]
> +static int trace_wprobe_show(struct seq_file *m, struct dyn_event *ev)
> +{
[ ... ]
> + if (tw->len == HW_BREAKPOINT_LEN_1)
> + len = 1;
> + else if (tw->len == HW_BREAKPOINT_LEN_2)
> + len = 2;
> + else if (tw->len == HW_BREAKPOINT_LEN_4)
> + len = 4;
> + else
> + len = 8;
> +
> + if (tw->symbol)
> + seq_printf(m, " %s@%pS:%d", type_str, (void *)tw->addr, len);
[Severity: High]
Will formatting the address with %pS break dynamic event restoration?
Using %pS appends the symbol size to the output string, which results in
formats like symbol+0x0/0x100.
When this string is saved and written back to restore the event,
parse_address_spec() extracts the offset part (+0x0/0x100) and passes it
to kstrtoint(). Since kstrtoint() requires a strict integer format, won't
it fail on the /size suffix and return -EINVAL, preventing restoration?
> + else
> + seq_printf(m, " %s@0x%lx:%d", type_str, tw->addr, len);
> +
> + for (i = 0; i < tw->tp.nr_args; i++)
> + seq_printf(m, " %s=%s", tw->tp.args[i].name, tw->tp.args[i].comm);
> + seq_putc(m, '\n');
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/178739053919.1520941.17662338993878200834.stgit@devnote2?part=5
next prev parent reply other threads:[~2026-08-22 9:49 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 9:22 [PATCH v13 00/12] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-08-22 9:22 ` [PATCH v13 01/12] kprobes: Protect kprobe_blacklist with RCU Masami Hiramatsu (Google)
2026-08-22 9:31 ` sashiko-bot
2026-08-22 9:22 ` [PATCH v13 02/12] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-08-22 9:41 ` sashiko-bot
2026-08-30 5:35 ` Masami Hiramatsu
2026-08-22 9:22 ` [PATCH v13 03/12] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-08-22 9:33 ` sashiko-bot
2026-08-22 9:23 ` [PATCH v13 04/12] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-08-22 9:33 ` sashiko-bot
2026-08-22 9:24 ` [PATCH v13 05/12] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-08-22 9:49 ` sashiko-bot [this message]
2026-08-30 5:35 ` Masami Hiramatsu
2026-08-22 9:24 ` [PATCH v13 06/12] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-08-22 9:31 ` sashiko-bot
2026-08-22 9:24 ` [PATCH v13 07/12] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-08-22 9:36 ` sashiko-bot
2026-08-30 5:35 ` Masami Hiramatsu
2026-08-22 9:24 ` [PATCH v13 08/12] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-08-22 9:35 ` sashiko-bot
2026-08-30 5:35 ` Masami Hiramatsu
2026-08-22 9:24 ` [PATCH v13 09/12] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-08-22 9:42 ` sashiko-bot
2026-08-30 5:35 ` Masami Hiramatsu
2026-08-22 9:25 ` [PATCH v13 10/12] selftests: ftrace: Add wprobe trigger testcase Masami Hiramatsu (Google)
2026-08-22 9:39 ` sashiko-bot
2026-08-30 5:36 ` Masami Hiramatsu
2026-08-22 9:25 ` [PATCH v13 11/12] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-08-22 9:40 ` sashiko-bot
2026-08-22 9:25 ` [PATCH v13 12/12] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
2026-08-22 9:51 ` sashiko-bot
2026-08-30 5:36 ` Masami Hiramatsu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260822094914.09C281F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mhiramat@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.