From: sashiko-bot@kernel.org
To: "Dapeng Mi" <dapeng1.mi@linux.intel.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [RESEND Patch v10 19/23] perf/x86: Support SSP sampling using sample_regs_* fields
Date: Mon, 24 Aug 2026 09:39:00 +0000 [thread overview]
Message-ID: <20260824093900.A8BBB1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260824082731.1013973-20-dapeng1.mi@linux.intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Critical] Arbitrary kernel memory read or kernel panic (page fault) via out-of-bounds pointer dereference in `perf_reg_value()` when triggering a hardware event via BPF.
--
--- Patch [19]: [RESEND Patch v10 19/23] perf/x86: Support SSP sampling using sample_regs_* fields ---
commit f68aca90e443a6b899f0ff2729c1f378ec1fb548
Author: Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86: Support SSP sampling using sample_regs_* fields
This commit adds support for sampling the CET SSP register via the
sample_regs_* fields. It uses the spare space reclaimed from the original
XMM space and is gated behind the sample_simd_regs_enabled flag.
> diff --git a/arch/x86/kernel/perf_regs.c b/arch/x86/kernel/perf_regs.c
> index 7d4233ed859cd..f8952f7c36cce 100644
> --- a/arch/x86/kernel/perf_regs.c
> +++ b/arch/x86/kernel/perf_regs.c
> @@ -72,6 +72,11 @@ u64 perf_reg_value(struct pt_regs *regs, int idx)
> return 0;
> return perf_regs->egpr_regs[idx - PERF_REG_X86_R16];
> }
> + if (idx == PERF_REG_X86_SSP) {
> + if (!perf_regs->ssp)
> + return 0;
> + return *perf_regs->ssp;
> + }
[Severity: Critical]
This is a pre-existing issue, but does this function correctly handle the case
where regs is not embedded in a struct x86_perf_regs?
If a hardware event is added to a BPF_MAP_TYPE_PERF_EVENT_ARRAY map and
triggered by a BPF program calling bpf_perf_event_output(),
perf_prepare_sample() uses the raw pt_regs from the BPF context.
perf_sample_regs_user() then sets the sample's user regs to
task_pt_regs(current).
When perf_output_sample_regs() subsequently calls perf_reg_value(), it blindly
casts this raw pt_regs pointer to struct x86_perf_regs using container_of():
arch/x86/kernel/perf_regs.c:perf_reg_value() {
...
if (idx > PERF_REG_X86_R15) {
perf_regs = container_of(regs, struct x86_perf_regs, regs);
if (perf_regs->abi == PERF_SAMPLE_REGS_ABI_NONE)
return 0;
...
}
Since task_pt_regs(current) is located at the very end of the task's stack
page, reading fields like the abi or xmm_regs pointer accesses the vmap stack
guard page, which can trigger a kernel panic. Can this be avoided by verifying
the origin of the regs pointer before casting?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260824082731.1013973-1-dapeng1.mi@linux.intel.com?part=19
next prev parent reply other threads:[~2026-08-24 9:39 UTC|newest]
Thread overview: 57+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 8:27 [RESEND Patch v10 00/23] Support SIMD/eGPRs/SSP registers sampling for perf Dapeng Mi
2026-08-24 8:27 ` [RESEND Patch v10 01/23] perf/x86: Move hybrid PMU initialization before x86_pmu_starting_cpu() Dapeng Mi
2026-08-24 8:44 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 02/23] perf/x86/intel: Enable large PEBS sampling for XMMs Dapeng Mi
2026-08-24 8:52 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 03/23] perf/x86/intel: Convert x86_perf_regs to per-cpu variables Dapeng Mi
2026-08-24 8:46 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 04/23] perf: Eliminate duplicate arch-specific function definitions Dapeng Mi
2026-08-24 8:44 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 05/23] perf/x86: Use x86_perf_regs in NMI handlers Dapeng Mi
2026-08-24 8:54 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 06/23] x86/fpu/xstate: Add xsaves_nmi() helper Dapeng Mi
2026-08-24 8:54 ` sashiko-bot
2026-08-25 1:03 ` Mi, Dapeng
2026-08-24 8:27 ` [RESEND Patch v10 07/23] x86/fpu: Add update_fpu_state_and_flag() helper Dapeng Mi
2026-08-24 8:47 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 08/23] perf: Move and enhance has_extended_regs() for arch-specific use Dapeng Mi
2026-08-24 8:47 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 09/23] perf/x86/intel: Centralize PERF_PMU_CAP_EXTENDED_REGS updates Dapeng Mi
2026-08-24 8:46 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 10/23] perf/x86: Enable XMM register sampling for non-PEBS events Dapeng Mi
2026-08-24 8:53 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 11/23] perf/x86: Enable XMM register sampling for REGS_USER case Dapeng Mi
2026-08-24 10:16 ` sashiko-bot
2026-08-25 1:13 ` Mi, Dapeng
2026-08-24 8:27 ` [RESEND Patch v10 12/23] perf: Add sampling support for SIMD registers Dapeng Mi
2026-08-24 8:54 ` sashiko-bot
2026-08-25 1:19 ` Mi, Dapeng
2026-08-24 8:27 ` [RESEND Patch v10 13/23] perf/x86: Support XMM sampling using sample_simd_vec_reg_* fields Dapeng Mi
2026-08-24 9:12 ` sashiko-bot
2026-08-25 1:28 ` Mi, Dapeng
2026-08-24 8:27 ` [RESEND Patch v10 14/23] perf/x86: Support YMM " Dapeng Mi
2026-08-24 8:55 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 15/23] perf/x86: Support ZMM " Dapeng Mi
2026-08-24 8:58 ` sashiko-bot
2026-08-25 1:30 ` Mi, Dapeng
2026-08-24 8:27 ` [RESEND Patch v10 16/23] perf/x86: Support OPMASK sampling using sample_simd_pred_reg_* fields Dapeng Mi
2026-08-24 8:54 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 17/23] perf: Enhance perf_reg_validate() with simd_enabled argument Dapeng Mi
2026-08-24 8:56 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 18/23] perf/x86: Support eGPRs sampling using sample_regs_* fields Dapeng Mi
2026-08-24 8:59 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 19/23] perf/x86: Support SSP " Dapeng Mi
2026-08-24 9:39 ` sashiko-bot [this message]
2026-08-25 1:34 ` Mi, Dapeng
2026-08-24 8:27 ` [RESEND Patch v10 20/23] perf/x86/intel: Support arch-PEBS based SIMD/eGPRs sampling Dapeng Mi
2026-08-24 9:09 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 21/23] perf/x86/intel: Advertise PERF_PMU_CAP_SIMD_REGS capability Dapeng Mi
2026-08-24 9:25 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 22/23] perf/x86: Activate back-to-back NMI detection for arch-PEBS induced NMIs Dapeng Mi
2026-08-24 9:06 ` sashiko-bot
2026-08-24 8:27 ` [RESEND Patch v10 23/23] perf/x86/intel: Add sanity check for PEBS record/fragment size Dapeng Mi
2026-08-24 9:08 ` sashiko-bot
2026-08-25 1:39 ` Mi, Dapeng
2026-09-01 8:55 ` [RESEND Patch v10 00/23] Support SIMD/eGPRs/SSP registers sampling for perf Mi, Dapeng
2026-09-02 11:56 ` Peter Zijlstra
2026-09-02 12:13 ` Mi, Dapeng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824093900.A8BBB1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dapeng1.mi@linux.intel.com \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.