All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v1 1/3] perf header: Fix HEADER_COMPRESSED validation for comp_mmap_len
@ 2026-09-10 17:37 Ian Rogers
  2026-09-10 17:37 ` [PATCH v1 2/3] perf header: Fix potential memory corruption in cpu_cache_level__read Ian Rogers
                   ` (3 more replies)
  0 siblings, 4 replies; 20+ messages in thread
From: Ian Rogers @ 2026-09-10 17:37 UTC (permalink / raw)
  To: Peter Zijlstra, Ingo Molnar, Arnaldo Carvalho de Melo,
	Namhyung Kim, Jiri Olsa, Ian Rogers, Adrian Hunter, James Clark,
	Swapnil Sapkal, linux-perf-users, linux-kernel

This commit updates process_compressed() to ignore comp_mmap_len == 0
when validating the compressed header. A zero size is valid and may
occur during testing.

Sashiko review flagged string.h was missing (preexisting problem) and
so I opportunistically fixed this and sorted the header files.

Signed-off-by: Ian Rogers <irogers@google.com>
Assisted-by: Antigravity:gemini-3.1-pro
---
 tools/perf/util/header.c | 78 +++++++++++++++++++++-------------------
 1 file changed, 41 insertions(+), 37 deletions(-)

diff --git a/tools/perf/util/header.c b/tools/perf/util/header.c
index 7db7da090a1e..bdd79d7542ef 100644
--- a/tools/perf/util/header.c
+++ b/tools/perf/util/header.c
@@ -1,65 +1,68 @@
 // SPDX-License-Identifier: GPL-2.0
+#include "header.h"
+
 #include <errno.h>
 #include <inttypes.h>
 #include <limits.h>
-#include "string2.h"
-#include <sys/param.h>
-#include <sys/types.h>
-#include <byteswap.h>
-#include <unistd.h>
-#include <regex.h>
 #include <stdio.h>
 #include <stdlib.h>
+#include <string.h>
+
+#include <asm/bug.h>
+#include <byteswap.h>
+#include <dirent.h>
+#include <linux/bitops.h>
 #include <linux/compiler.h>
-#include <linux/list.h>
+#include <linux/ctype.h>
 #include <linux/kernel.h>
-#include <linux/bitops.h>
+#include <linux/list.h>
 #include <linux/string.h>
 #include <linux/stringify.h>
+#include <linux/time64.h>
 #include <linux/zalloc.h>
+#include <regex.h>
+#include <sys/param.h>
 #include <sys/stat.h>
+#include <sys/types.h>
 #include <sys/utsname.h>
-#include <linux/time64.h>
-#include <dirent.h>
-#ifdef HAVE_LIBBPF_SUPPORT
-#include <bpf/libbpf.h>
-#endif
+#include <unistd.h>
+
+#include <api/fs/fs.h>
+#include <api/io_dir.h>
+#include <internal/lib.h>
 #include <perf/cpumap.h>
 #include <tools/libc_compat.h> // reallocarray
 
+#include "bpf-event.h"
+#include "bpf-utils.h"
+#include "build-id.h"
+#include "cacheline.h"
+#include "clockid.h"
+#include "cpumap.h"
+#include "cputopo.h"
+#include "data.h"
+#include "debug.h"
 #include "dso.h"
 #include "evlist.h"
 #include "evsel.h"
-#include "util/evsel_fprintf.h"
-#include "header.h"
+#include "evsel_fprintf.h"
 #include "memswap.h"
-#include "trace-event.h"
-#include "session.h"
-#include "symbol.h"
-#include "debug.h"
-#include "cpumap.h"
 #include "pmu.h"
 #include "pmus.h"
-#include "vdso.h"
+#include "session.h"
 #include "strbuf.h"
-#include "build-id.h"
-#include "data.h"
-#include <api/fs/fs.h>
-#include <api/io_dir.h>
-#include "asm/bug.h"
-#include "tool.h"
-#include "../perf.h"
+#include "string2.h"
+#include "symbol.h"
 #include "time-utils.h"
+#include "tool.h"
+#include "trace-event.h"
 #include "units.h"
-#include "util/util.h" // perf_exe()
-#include "cputopo.h"
-#include "bpf-event.h"
-#include "bpf-utils.h"
-#include "clockid.h"
-#include "cacheline.h"
+#include "util.h" // perf_exe()
+#include "vdso.h"
 
-#include <linux/ctype.h>
-#include <internal/lib.h>
+#ifdef HAVE_LIBBPF_SUPPORT
+#include <bpf/libbpf.h>
+#endif
 
 #ifdef HAVE_LIBTRACEEVENT
 #include <event-parse.h>
@@ -3903,7 +3906,8 @@ static int process_compressed(struct feat_fd *ff,
 	 * checks decomp_len + sizeof(struct decomp) against SIZE_MAX
 	 * before allocating, which handles 32-bit safety.
 	 */
-	if (env->comp_mmap_len < 4096 || env->comp_mmap_len % 4096) {
+	if (env->comp_mmap_len &&
+	    (env->comp_mmap_len < 4096 || env->comp_mmap_len % 4096)) {
 		pr_err("Invalid HEADER_COMPRESSED: comp_mmap_len (%u) must be a 4K-aligned value >= 4096\n",
 		       env->comp_mmap_len);
 		return -1;
-- 
2.55.0.1007.g17ff1f9808-goog


^ permalink raw reply related	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2026-09-13 21:43 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-10 17:37 [PATCH v1 1/3] perf header: Fix HEADER_COMPRESSED validation for comp_mmap_len Ian Rogers
2026-09-10 17:37 ` [PATCH v1 2/3] perf header: Fix potential memory corruption in cpu_cache_level__read Ian Rogers
2026-09-10 17:47   ` sashiko-bot
2026-09-10 17:37 ` [PATCH v1 3/3] perf header: Transition WARN macros to debug.h equivalents Ian Rogers
2026-09-10 17:46   ` sashiko-bot
2026-09-10 17:51 ` [PATCH v1 1/3] perf header: Fix HEADER_COMPRESSED validation for comp_mmap_len sashiko-bot
2026-09-10 17:56 ` [PATCH v2 1/3] perf test x86: Fix missing __msan_unpoison Ian Rogers
2026-09-10 17:56   ` [PATCH v2 2/3] perf header: Fix HEADER_COMPRESSED validation for comp_mmap_len Ian Rogers
2026-09-10 18:14     ` sashiko-bot
2026-09-10 17:56   ` [PATCH v2 3/3] perf header: Fix potential memory corruption in cpu_cache_level__read Ian Rogers
2026-09-10 18:08     ` sashiko-bot
2026-09-10 18:11   ` [PATCH v2 1/3] perf test x86: Fix missing __msan_unpoison sashiko-bot
2026-09-10 21:12   ` [PATCH v3 0/3] perf header: Fix memory corruption and unnecessary warning Ian Rogers
2026-09-10 21:12     ` [PATCH v3 1/3] perf header: Fix HEADER_COMPRESSED validation for comp_mmap_len Ian Rogers
2026-09-10 21:21       ` sashiko-bot
2026-09-10 21:12     ` [PATCH v3 2/3] perf header: Fix potential memory corruption in cpu_cache_level__read Ian Rogers
2026-09-10 21:22       ` sashiko-bot
2026-09-10 21:12     ` [PATCH v3 3/3] perf header: Transition WARN macros to debug.h equivalents Ian Rogers
2026-09-10 21:18       ` sashiko-bot
2026-09-13 21:42     ` [PATCH v3 0/3] perf header: Fix memory corruption and unnecessary warning Arnaldo Carvalho de Melo

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.