All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2 perf-tools-next 0/6] perf trace: Validate payload bounds across augmented argument beautifiers
@ 2026-09-07  1:51 Aaron Tomlin
  2026-09-07  1:51 ` [PATCH v2 perf-tools-next 1/6] perf trace: Add upper bound checks for augmented BTF struct printing Aaron Tomlin
                   ` (6 more replies)
  0 siblings, 7 replies; 14+ messages in thread
From: Aaron Tomlin @ 2026-09-07  1:51 UTC (permalink / raw)
  To: peterz, mingo, acme, namhyung
  Cc: mark.rutland, alexander.shishkin, jolsa, irogers, adrian.hunter,
	james.clark, howardchu95, atomlin, neelx, chjohnst, sean, steve,
	rishil1999, linux-perf-users, linux-kernel

When pretty-printing augmented syscall arguments in perf trace, raw payload
data captured from BPF programs is passed to various argument formatters
via struct syscall_arg.

However, when processing malformed, truncated, or untrusted perf.data
records (e.g., truncated reads in BPF ringbuffers, cross-architecture
replays, or crafted sample records), the payload can be shorter than
expected or contain invalid size fields:
    1.  Dereferencing augmented_arg fields before validating that
        arg->augmented.size is at least sizeof(struct augmented_arg) can read
        past the available buffer.

    2.  Passing augmented_arg->size to formatters or loop counters without
        bounding it against the remaining buffer can cause out-of-bounds memory
        reads.

    3.  In multi-argument syscalls, calculating consumed bytes as:

            consumed = sizeof(*augmented_arg) + augmented_arg->size;

        without bounds checking can overflow signed integer bounds or cause
        arg->augmented.size to underflow. This advances arg->augmented.args
        out of bounds, corrupting parsing state for all subsequent
        arguments in the same syscall.

    4.  Type/family-specific beautifiers (i.e., BTF struct dump, sockaddr,
        timespec, perf_event_attr) can dereference structure fields without
        verifying that the payload contains sufficient bytes for the target
        type.

This series adds comprehensive upper-bound and payload-size checks across
all augmented argument beautifiers in perf trace. If validation fails in
any beautifier, it cleanly falls back to printing the raw pointer/hex
value.

To facilitate clean, conflict-free backports across active LTS kernels,
each formatter fix is isolated to its own commit.

Changes since v1:

 - Expanded the original single patch into a 6-patch series in response to
   reviewer feedback from sashiko-bot regarding similar bounds check
   omissions across other augmented formatters in perf trace

 - Added new patch validating payload bounds and consumed offset
   calculations in syscall_arg__scnprintf_augmented_string()

 - Added new patch validating payload bounds before byte traversal in
   syscall_arg__scnprintf_buf(), isolated to ensure an independent Fixes:
   tag for stable backports

 - Added new patch validating payload size against sizeof(struct timespec)
   in syscall_arg__scnprintf_augmented_timespec()

 - Added new patch validating payload bounds and family-specific lengths in
   syscall_arg__scnprintf_augmented_sockaddr()

 - Added new patch validating payload size against at least
   PERF_ATTR_SIZE_VER0 in
   syscall_arg__scnprintf_augmented_perf_event_attr()

 - Link to v1: https://lore.kernel.org/all/20260906011132.279321-1-atomlin@atomlin.com/

Aaron Tomlin (6):
  perf trace: Add upper bound checks for augmented BTF struct printing
  perf trace: Validate payload bounds in augmented string beautifier
  perf trace: Validate payload bounds in augmented buffer beautifier
  perf trace beauty: Validate payload size in augmented timespec
    beautifier
  perf trace beauty: Validate payload size in augmented sockaddr
    beautifier
  perf trace beauty: Validate payload size in augmented perf_event_open
    beautifier

 tools/perf/builtin-trace.c                | 36 +++++++++++++++++------
 tools/perf/trace/beauty/perf_event_open.c | 19 ++++++++++--
 tools/perf/trace/beauty/sockaddr.c        | 35 ++++++++++++++++++----
 tools/perf/trace/beauty/timespec.c        | 19 ++++++++++--
 4 files changed, 89 insertions(+), 20 deletions(-)


base-commit: 02f6847e1822714a4201b87e42f92b0d43e8549d
-- 
2.55.0


^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2026-09-19  0:31 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-07  1:51 [PATCH v2 perf-tools-next 0/6] perf trace: Validate payload bounds across augmented argument beautifiers Aaron Tomlin
2026-09-07  1:51 ` [PATCH v2 perf-tools-next 1/6] perf trace: Add upper bound checks for augmented BTF struct printing Aaron Tomlin
2026-09-07  2:02   ` sashiko-bot
2026-09-07  1:51 ` [PATCH v2 perf-tools-next 2/6] perf trace: Validate payload bounds in augmented string beautifier Aaron Tomlin
2026-09-07  2:06   ` sashiko-bot
2026-09-07  1:51 ` [PATCH v2 perf-tools-next 3/6] perf trace: Validate payload bounds in augmented buffer beautifier Aaron Tomlin
2026-09-07  2:07   ` sashiko-bot
2026-09-07  1:51 ` [PATCH v2 perf-tools-next 4/6] perf trace beauty: Validate payload size in augmented timespec beautifier Aaron Tomlin
2026-09-07  2:05   ` sashiko-bot
2026-09-07  1:51 ` [PATCH v2 perf-tools-next 5/6] perf trace beauty: Validate payload size in augmented sockaddr beautifier Aaron Tomlin
2026-09-07  2:03   ` sashiko-bot
2026-09-07  1:51 ` [PATCH v2 perf-tools-next 6/6] perf trace beauty: Validate payload size in augmented perf_event_open beautifier Aaron Tomlin
2026-09-07  2:06   ` sashiko-bot
2026-09-19  0:30 ` [PATCH v2 perf-tools-next 0/6] perf trace: Validate payload bounds across augmented argument beautifiers Aaron Tomlin

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.