From: Namhyung Kim <namhyung@kernel.org>
To: Arnaldo Carvalho de Melo <acme@kernel.org>
Cc: Ian Rogers <irogers@google.com>, Jiri Olsa <jolsa@kernel.org>,
Adrian Hunter <adrian.hunter@intel.com>,
James Clark <james.clark@linaro.org>,
Peter Zijlstra <peterz@infradead.org>,
Ingo Molnar <mingo@kernel.org>,
LKML <linux-kernel@vger.kernel.org>,
linux-perf-users@vger.kernel.org, Zecheng Li <zli94@ncsu.edu>,
Yanbo Zhao <yzhao62@ncsu.edu>,
Tengda Wu <wutengda@huaweicloud.com>,
Shuai Xue <xueshuai@linux.alibaba.com>
Subject: [PATCH 3/4] perf annotate-date: Allow out-of-size access for flex-array types
Date: Fri, 11 Sep 2026 22:47:05 -0700 [thread overview]
Message-ID: <20260912054706.1475583-4-namhyung@kernel.org> (raw)
In-Reply-To: <20260912054706.1475583-1-namhyung@kernel.org>
Structs that have a flex array will have accesses beyond its original
size as the array was declared as 0 sized. For now, it just allow any
offset bigger than the size. It could be refined later.
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
---
tools/perf/util/annotate-data.c | 22 +++++++++++++++-------
tools/perf/util/annotate-data.h | 2 ++
2 files changed, 17 insertions(+), 7 deletions(-)
diff --git a/tools/perf/util/annotate-data.c b/tools/perf/util/annotate-data.c
index aff60a630fd05b01..ad043403ced58d98 100644
--- a/tools/perf/util/annotate-data.c
+++ b/tools/perf/util/annotate-data.c
@@ -248,8 +248,15 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
else
die_mem = member_type;
- if (dwarf_aggregate_size(&die_mem, &size) < 0)
- size = 0;
+ if (dwarf_aggregate_size(&die_mem, &size) < 0) {
+ if (dwarf_tag(&die_mem) == DW_TAG_array_type) { /* flex-array? */
+ __die_get_real_type(&die_mem, &die_mem);
+ if (dwarf_aggregate_size(&die_mem, &size) < 0)
+ size = 0;
+ } else {
+ size = 0;
+ }
+ }
if (dwarf_attr_integrate(die, DW_AT_data_member_location, &attr)) {
if (dwarf_formudata(&attr, &loc) != 0) {
@@ -399,6 +406,7 @@ static struct annotated_data_type *dso__findnew_data_type(struct dso *dso,
result->self.type_name = type_name;
result->self.size = size;
INIT_LIST_HEAD(&result->self.children);
+ result->flex_array = die_has_flex_array(type_die);
if (symbol_conf.annotate_data_member)
add_member_types(result, type_die);
@@ -559,7 +567,7 @@ static enum type_match_result check_variable(struct data_loc_info *dloc,
return PERF_TMR_NO_SIZE;
/* Minimal sanity check */
- if ((unsigned)offset >= size)
+ if ((unsigned)offset >= size && !die_has_flex_array(&sized_type))
return PERF_TMR_BAD_OFFSET;
return PERF_TMR_OK;
@@ -1168,7 +1176,7 @@ static enum type_match_result check_matching_type(struct type_state *state,
/* Get the size of the actual type */
if (dwarf_aggregate_size(&sized_type, &size) < 0 ||
- (unsigned)dloc->type_offset >= size)
+ ((unsigned)dloc->type_offset >= size && !die_has_flex_array(&sized_type)))
return PERF_TMR_BAD_OFFSET;
return PERF_TMR_OK;
@@ -1192,7 +1200,7 @@ static enum type_match_result check_matching_type(struct type_state *state,
/* Get the size of the actual type */
if (dwarf_aggregate_size(type_die, &size) < 0 ||
- (unsigned)dloc->type_offset >= size)
+ ((unsigned)dloc->type_offset >= size && !die_has_flex_array(type_die)))
return PERF_TMR_BAD_OFFSET;
return PERF_TMR_OK;
@@ -1211,7 +1219,7 @@ static enum type_match_result check_matching_type(struct type_state *state,
/* Get the size of the actual type */
if (dwarf_aggregate_size(type_die, &size) < 0 ||
- (unsigned)dloc->type_offset >= size)
+ ((unsigned)dloc->type_offset >= size && !die_has_flex_array(type_die)))
return PERF_TMR_BAIL_OUT;
return PERF_TMR_OK;
@@ -1839,7 +1847,7 @@ int annotated_data_type__update_samples(struct annotated_data_type *adt,
return -1;
}
- if (offset < 0 || offset >= adt->self.size)
+ if (offset < 0 || (offset >= adt->self.size && !adt->flex_array))
return -1;
h = &adt->histograms[evsel->core.idx];
diff --git a/tools/perf/util/annotate-data.h b/tools/perf/util/annotate-data.h
index ca2096a9ee62cbfe..27b7148b64f60350 100644
--- a/tools/perf/util/annotate-data.h
+++ b/tools/perf/util/annotate-data.h
@@ -85,6 +85,7 @@ struct type_hist {
* struct annotated_data_type - Data type to profile
* @node: RB-tree node for dso->type_tree
* @self: Actual type information
+ * @flex_array: Whethere it has a flex array
* @nr_histogram: Number of histogram entries
* @histograms: An array of histograms
*
@@ -93,6 +94,7 @@ struct type_hist {
struct annotated_data_type {
struct rb_node node;
struct annotated_member self;
+ bool flex_array;
int nr_histograms;
struct type_hist *histograms;
};
--
2.55.0.1032.g73a4cd73de-goog
next prev parent reply other threads:[~2026-09-12 5:47 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 5:47 [PATCH 0/4] perf annotate-data: Support flexible array types Namhyung Kim
2026-09-12 5:47 ` [PATCH 1/4] perf annotate-data: Convert type histogram to hashmap Namhyung Kim
2026-09-12 5:56 ` sashiko-bot
2026-09-12 5:47 ` [PATCH 2/4] perf dwarf-aux: Add die_has_flex_array() helper Namhyung Kim
2026-09-12 5:58 ` sashiko-bot
2026-09-12 5:47 ` Namhyung Kim [this message]
2026-09-12 6:02 ` [PATCH 3/4] perf annotate-date: Allow out-of-size access for flex-array types sashiko-bot
2026-09-12 5:47 ` [PATCH 4/4] perf annotate-data: Adjust type offset for flex-array Namhyung Kim
2026-09-12 5:57 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260912054706.1475583-4-namhyung@kernel.org \
--to=namhyung@kernel.org \
--cc=acme@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=irogers@google.com \
--cc=james.clark@linaro.org \
--cc=jolsa@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=mingo@kernel.org \
--cc=peterz@infradead.org \
--cc=wutengda@huaweicloud.com \
--cc=xueshuai@linux.alibaba.com \
--cc=yzhao62@ncsu.edu \
--cc=zli94@ncsu.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.