From: sashiko-bot@kernel.org
To: "Arnaldo Carvalho de Melo" <acme@kernel.org>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH 4/4] perf test: Add false_sharing workload exhibiting cross-CPU false sharing
Date: Mon, 28 Sep 2026 16:31:48 +0000 [thread overview]
Message-ID: <20260928163148.DF0D71F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260928162250.2413383-5-acme@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] perf test: stack buffer overflow in false_sharing via CPU_SET(-1)
--
commit ca3d54512dd3bcec14cdfc83ca90f31bcb2e15f0
Author: Arnaldo Carvalho de Melo <acme@redhat.com>
perf test: Add false_sharing workload exhibiting cross-CPU false sharing
Add a 'perf test -w false_sharing' workload that hammers one shared
struct from several CPUs, shaped as a TCP connection. The packet path
runs in the main thread and up to four lookup threads hash the
five-tuple and pull the config.
> diff --git a/tools/perf/tests/workloads/false_sharing.c b/tools/perf/tests/workloads/false_sharing.c
> new file mode 100644
> index 0000000000000..6fccb81e3ed1c
> --- /dev/null
> +++ b/tools/perf/tests/workloads/false_sharing.c
[ ... ]
> +static void pin_to_cpu(int cpu)
> +{
> + cpu_set_t set;
> +
> + CPU_ZERO(&set);
> + CPU_SET(cpu, &set);
[Severity: Medium]
When false_sharing() runs on a single-core machine or a restricted cpuset
(where nallowed <= 1), it assigns -1 to the reader thread's target CPU:
false_sharing() {
...
for (i = 0; i < nreaders; i++) {
int cpu = nallowed > 1 ? allowed[(i + 1) % nallowed] : -1;
readers[i].cpu = cpu;
...
}
}
Unlike the writer thread, which correctly guards the call with
if (writer_cpu >= 0), the reader thread unconditionally calls pin_to_cpu(-1):
reader_fn() {
...
pin_to_cpu(r->cpu);
...
}
This passes -1 directly to CPU_SET() without any bounds checking. Could this
negative index result in an out-of-bounds stack write that corrupts memory?
> + /* Best effort: in a restricted cpuset this fails and the thread runs unpinned. */
> + pthread_setaffinity_np(pthread_self(), sizeof(set), &set);
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928162250.2413383-1-acme@kernel.org?part=4
next prev parent reply other threads:[~2026-09-28 16:31 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:22 [PATCH 0/4 v1] perf tools: Add progress diagnostics and a false-sharing workload Arnaldo Carvalho de Melo
2026-09-28 16:22 ` [PATCH 1/4] perf config: Move perf_config__set_variable() to util/config.c Arnaldo Carvalho de Melo
2026-09-28 16:38 ` sashiko-bot
2026-09-28 16:22 ` [PATCH 2/4] perf report: Add --progress option Arnaldo Carvalho de Melo
2026-09-28 16:31 ` sashiko-bot
2026-09-28 16:22 ` [PATCH 3/4] perf scripts: Add perf-stuck, to tell where a running perf is stuck Arnaldo Carvalho de Melo
2026-09-28 16:37 ` sashiko-bot
2026-09-28 16:22 ` [PATCH 4/4] perf test: Add false_sharing workload exhibiting cross-CPU false sharing Arnaldo Carvalho de Melo
2026-09-28 16:31 ` sashiko-bot [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-09-28 22:06 [PATCH v3 0/4] perf tools: Add progress diagnostics and a false-sharing workload Arnaldo Carvalho de Melo
2026-09-28 22:06 ` [PATCH 4/4] perf test: Add false_sharing workload exhibiting cross-CPU false sharing Arnaldo Carvalho de Melo
2026-09-28 22:14 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928163148.DF0D71F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=acme@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.