All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Dapeng Mi" <dapeng1.mi@linux.intel.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [RESEND Patch v10 13/23] perf/x86: Support XMM sampling using sample_simd_vec_reg_* fields
Date: Mon, 24 Aug 2026 09:12:24 +0000	[thread overview]
Message-ID: <20260824091225.514D71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260824082731.1013973-14-dapeng1.mi@linux.intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Downcast of `struct pt_regs` to `struct x86_perf_regs` for software events leads to an out-of-bounds read and potential arbitrary memory read or local DoS.
--

--- Patch [13]: [RESEND Patch v10 13/23] perf/x86: Support XMM sampling using sample_simd_vec_reg_* fields ---
commit 19bc56fc15fa41117febd46977ed2032c46e92f4
Author: Dapeng Mi <dapeng1.mi@linux.intel.com>
Subject: perf/x86: Support XMM sampling using sample_simd_vec_reg_* fields

This commit supports sampling of XMM registers using the newly introduced
sample_simd_vec_reg_* fields. A new abi field is introduced in struct
x86_perf_regs to accommodate layout information for perf_reg_value.

> diff --git a/arch/x86/kernel/perf_regs.c b/arch/x86/kernel/perf_regs.c
> index 81204cb7f7239..bccf0fc275116 100644
> --- a/arch/x86/kernel/perf_regs.c
> +++ b/arch/x86/kernel/perf_regs.c
> @@ -63,6 +63,9 @@ u64 perf_reg_value(struct pt_regs *regs, int idx)
>  
>  	if (idx >= PERF_REG_X86_XMM0 && idx < PERF_REG_X86_XMM_MAX) {
>  		perf_regs = container_of(regs, struct x86_perf_regs, regs);
> +		/* SIMD registers are moved to dedicated sample_simd_vec_reg */
> +		if (perf_regs->abi & PERF_SAMPLE_REGS_ABI_SIMD)
> +			return 0;
>  		if (!perf_regs->xmm_regs)
>  			return 0;

[Severity: High]
This is a pre-existing issue, but does using container_of() here lead to an
out-of-bounds read for software events?

If a user creates a software event (e.g., PERF_TYPE_SOFTWARE) with
PERF_SAMPLE_REGS_USER and sets an XMM register bit in sample_regs_user,
perf_reg_validate() fails to reject bits >= 32. When the event triggers,
perf_output_sample_regs() calls perf_reg_value() with a raw pt_regs
pointer from task_pt_regs(current).

Because task_pt_regs is typically located at the very top of the kernel
stack page, downcasting it to struct x86_perf_regs and reading
perf_regs->abi or perf_regs->xmm_regs accesses memory past the end of
the pt_regs structure.

Can this cross into the adjacent vmap guard page and cause a kernel panic,
or leak adjacent memory if triggered via nested interrupts or kprobes
where the pt_regs is in the middle of the stack?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260824082731.1013973-1-dapeng1.mi@linux.intel.com?part=13

  reply	other threads:[~2026-08-24  9:12 UTC|newest]

Thread overview: 57+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-24  8:27 [RESEND Patch v10 00/23] Support SIMD/eGPRs/SSP registers sampling for perf Dapeng Mi
2026-08-24  8:27 ` [RESEND Patch v10 01/23] perf/x86: Move hybrid PMU initialization before x86_pmu_starting_cpu() Dapeng Mi
2026-08-24  8:44   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 02/23] perf/x86/intel: Enable large PEBS sampling for XMMs Dapeng Mi
2026-08-24  8:52   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 03/23] perf/x86/intel: Convert x86_perf_regs to per-cpu variables Dapeng Mi
2026-08-24  8:46   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 04/23] perf: Eliminate duplicate arch-specific function definitions Dapeng Mi
2026-08-24  8:44   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 05/23] perf/x86: Use x86_perf_regs in NMI handlers Dapeng Mi
2026-08-24  8:54   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 06/23] x86/fpu/xstate: Add xsaves_nmi() helper Dapeng Mi
2026-08-24  8:54   ` sashiko-bot
2026-08-25  1:03     ` Mi, Dapeng
2026-08-24  8:27 ` [RESEND Patch v10 07/23] x86/fpu: Add update_fpu_state_and_flag() helper Dapeng Mi
2026-08-24  8:47   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 08/23] perf: Move and enhance has_extended_regs() for arch-specific use Dapeng Mi
2026-08-24  8:47   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 09/23] perf/x86/intel: Centralize PERF_PMU_CAP_EXTENDED_REGS updates Dapeng Mi
2026-08-24  8:46   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 10/23] perf/x86: Enable XMM register sampling for non-PEBS events Dapeng Mi
2026-08-24  8:53   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 11/23] perf/x86: Enable XMM register sampling for REGS_USER case Dapeng Mi
2026-08-24 10:16   ` sashiko-bot
2026-08-25  1:13     ` Mi, Dapeng
2026-08-24  8:27 ` [RESEND Patch v10 12/23] perf: Add sampling support for SIMD registers Dapeng Mi
2026-08-24  8:54   ` sashiko-bot
2026-08-25  1:19     ` Mi, Dapeng
2026-08-24  8:27 ` [RESEND Patch v10 13/23] perf/x86: Support XMM sampling using sample_simd_vec_reg_* fields Dapeng Mi
2026-08-24  9:12   ` sashiko-bot [this message]
2026-08-25  1:28     ` Mi, Dapeng
2026-08-24  8:27 ` [RESEND Patch v10 14/23] perf/x86: Support YMM " Dapeng Mi
2026-08-24  8:55   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 15/23] perf/x86: Support ZMM " Dapeng Mi
2026-08-24  8:58   ` sashiko-bot
2026-08-25  1:30     ` Mi, Dapeng
2026-08-24  8:27 ` [RESEND Patch v10 16/23] perf/x86: Support OPMASK sampling using sample_simd_pred_reg_* fields Dapeng Mi
2026-08-24  8:54   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 17/23] perf: Enhance perf_reg_validate() with simd_enabled argument Dapeng Mi
2026-08-24  8:56   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 18/23] perf/x86: Support eGPRs sampling using sample_regs_* fields Dapeng Mi
2026-08-24  8:59   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 19/23] perf/x86: Support SSP " Dapeng Mi
2026-08-24  9:39   ` sashiko-bot
2026-08-25  1:34     ` Mi, Dapeng
2026-08-24  8:27 ` [RESEND Patch v10 20/23] perf/x86/intel: Support arch-PEBS based SIMD/eGPRs sampling Dapeng Mi
2026-08-24  9:09   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 21/23] perf/x86/intel: Advertise PERF_PMU_CAP_SIMD_REGS capability Dapeng Mi
2026-08-24  9:25   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 22/23] perf/x86: Activate back-to-back NMI detection for arch-PEBS induced NMIs Dapeng Mi
2026-08-24  9:06   ` sashiko-bot
2026-08-24  8:27 ` [RESEND Patch v10 23/23] perf/x86/intel: Add sanity check for PEBS record/fragment size Dapeng Mi
2026-08-24  9:08   ` sashiko-bot
2026-08-25  1:39     ` Mi, Dapeng
2026-09-01  8:55 ` [RESEND Patch v10 00/23] Support SIMD/eGPRs/SSP registers sampling for perf Mi, Dapeng
2026-09-02 11:56   ` Peter Zijlstra
2026-09-02 12:13     ` Mi, Dapeng

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260824091225.514D71F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dapeng1.mi@linux.intel.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.