All of lore.kernel.org
 help / color / mirror / Atom feed
From: Prashanth Nageshappa <prashanth@linux.vnet.ibm.com>
To: masami.hiramatsu.pt@hitachi.com, ananth@in.ibm.com,
	akpm@linux-foundation.org, linux-kernel@vger.kernel.org
Cc: jbaron@redhat.com, rostedt@goodmis.org, srikar@linux.vnet.ibm.com
Subject: [PATCH] perf - ensure offset provided during probe addition is not greater than function length
Date: Fri, 24 Feb 2012 13:11:39 +0530	[thread overview]
Message-ID: <4F473F33.4060409@linux.vnet.ibm.com> (raw)
In-Reply-To: <4F45FABE.90104@linux.vnet.ibm.com>

perf probe allows kprobe to be inserted at any offset from a function
start, which results in adding kprobes to unintended location.
(example: perf probe do_fork+10000 is allowed even though size of
do_fork is ~904)

This patch will ensure probe addition fails when the offset specified
is greater than size of the function.


Signed-off-by: Prashanth Nageshappa <prashanth@linux.vnet.ibm.com>
---

 tools/perf/util/probe-finder.c |   12 +++++++++++-
 1 files changed, 11 insertions(+), 1 deletions(-)

diff --git a/tools/perf/util/probe-finder.c b/tools/perf/util/probe-finder.c
index 5d73262..d298f94 100644
--- a/tools/perf/util/probe-finder.c
+++ b/tools/perf/util/probe-finder.c
@@ -672,7 +672,7 @@ static int find_variable(Dwarf_Die *sc_die, struct probe_finder *pf)
 static int convert_to_trace_point(Dwarf_Die *sp_die, Dwarf_Addr paddr,
 				  bool retprobe, struct probe_trace_point *tp)
 {
-	Dwarf_Addr eaddr;
+	Dwarf_Addr eaddr, highaddr;
 	const char *name;

 	/* Copy the name of probe point */
@@ -683,6 +683,16 @@ static int convert_to_trace_point(Dwarf_Die *sp_die, Dwarf_Addr paddr,
 				   dwarf_diename(sp_die));
 			return -ENOENT;
 		}
+		if (dwarf_highpc(sp_die, &highaddr) != 0) {
+			pr_warning("Failed to get end address of %s\n",
+				   dwarf_diename(sp_die));
+			return -ENOENT;
+		}
+		if (paddr > highaddr) {
+			pr_warning("Offset specified is greater than size of %s\n",
+				   dwarf_diename(sp_die));
+			return -EINVAL;
+		}
 		tp->symbol = strdup(name);
 		if (tp->symbol == NULL)
 			return -ENOMEM;


       reply	other threads:[~2012-02-24  7:41 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <4F45FABE.90104@linux.vnet.ibm.com>
2012-02-24  7:41 ` Prashanth Nageshappa [this message]
2012-02-24 10:32   ` [PATCH] perf - ensure offset provided during probe addition is not greater than function length Masami Hiramatsu
2012-02-24 11:33     ` Prashanth Nageshappa
2012-02-24 19:16       ` Arnaldo Carvalho de Melo
2012-03-02  9:50   ` [tip:perf/urgent] perf probe: Ensure offset provided " tip-bot for Prashanth Nageshappa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4F473F33.4060409@linux.vnet.ibm.com \
    --to=prashanth@linux.vnet.ibm.com \
    --cc=akpm@linux-foundation.org \
    --cc=ananth@in.ibm.com \
    --cc=jbaron@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=masami.hiramatsu.pt@hitachi.com \
    --cc=rostedt@goodmis.org \
    --cc=srikar@linux.vnet.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.