Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v7 2/6] perf ui hists: Guard against NULL hist_entry in add_script_opt()
Date: Thu, 23 Jul 2026 05:19:36 +0000	[thread overview]
Message-ID: <20260723051937.80DA01F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723045949.988740-3-irogers@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] NULL pointer dereference when toggling annotation with an empty browser selection.
--

--- Patch [2]: [PATCH v7 2/6] perf ui hists: Guard against NULL hist_entry in add_script_opt() ---
commit f95ba72ff3ba56daab82a876b00253253abac4da
Author: Ian Rogers <irogers@google.com>

perf ui hists: Guard against NULL hist_entry in add_script_opt()

This commit adds an explicit check for a NULL hist_entry in add_script_opt()
before accessing the entry's time field. This prevents a potential NULL
pointer dereference when the browser selection is empty or filtered out.

While reviewing this fix, I noticed a similar pre-existing issue in another
file.

tools/perf/builtin-c2c.c:perf_c2c__toggle_annotation()
> static int perf_c2c__toggle_annotation(struct hist_browser *browser)
> {
> 	struct hist_entry *he = browser->he_selection;
> 	// ...
> 	if (!perf_c2c__has_annotation(he->hists->hpp_list)) {

[Severity: High]
This is a pre-existing issue, but could this cause a segmentation fault if
the browser selection is empty? The code dereferences the he pointer to
access he->hists->hpp_list before validating it.

> 		ui_browser__help_window(&browser->b, "No annotation support");
> 		return 0;
> 	}
> 
> 	if (he == NULL) {

If a user opens the c2c cacheline browser on an empty or completely
filtered dataset and presses the annotation hotkey, browser->he_selection 
is NULL. Since the safety check happens after the dereference, it appears 
this would crash the perf tool.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260723045949.988740-1-irogers@google.com?part=2

  reply	other threads:[~2026-07-23  5:19 UTC|newest]

Thread overview: 89+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-08 23:46 [PATCH v1 1/3] perf ui hists: In report UI ensure thread is set Ian Rogers
2026-07-08 23:46 ` [PATCH v1 2/3] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-08 23:58   ` sashiko-bot
2026-07-08 23:46 ` [PATCH v1 3/3] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-08 23:58   ` sashiko-bot
2026-07-09  3:36 ` [PATCH v2 1/4] perf ui hists: In report UI ensure thread is set Ian Rogers
2026-07-09  3:36   ` [PATCH v2 2/4] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-09  3:52     ` sashiko-bot
2026-07-09  3:37   ` [PATCH v2 3/4] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-09  3:57     ` sashiko-bot
2026-07-09  3:37   ` [PATCH v2 4/4] perf hists browser: Increase MAX_OPTIONS to prevent stack buffer overflow Ian Rogers
2026-07-09  3:52     ` sashiko-bot
2026-07-09  3:54   ` [PATCH v2 1/4] perf ui hists: In report UI ensure thread is set sashiko-bot
2026-07-09 16:52   ` [PATCH v3 " Ian Rogers
2026-07-09 16:52     ` [PATCH v3 2/4] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-09 17:10       ` sashiko-bot
2026-07-09 16:52     ` [PATCH v3 3/4] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-09 17:04       ` sashiko-bot
2026-07-09 16:52     ` [PATCH v3 4/4] perf hists browser: Increase MAX_OPTIONS to prevent stack buffer overflow Ian Rogers
2026-07-09 17:08       ` sashiko-bot
2026-07-09 17:08     ` [PATCH v3 1/4] perf ui hists: In report UI ensure thread is set sashiko-bot
2026-07-10  2:49     ` [PATCH v4 1/9] perf hists browser: Increase MAX_OPTIONS to prevent stack buffer overflow Ian Rogers
2026-07-10  2:49       ` [PATCH v4 2/9] perf ui hists: In report UI ensure thread is set Ian Rogers
2026-07-10  3:05         ` sashiko-bot
2026-07-10  2:49       ` [PATCH v4 3/9] perf disasm: Fix potential NULL pointer dereference in arch__find() Ian Rogers
2026-07-10  2:59         ` sashiko-bot
2026-07-10  2:49       ` [PATCH v4 4/9] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure Ian Rogers
2026-07-10  3:09         ` sashiko-bot
2026-07-10  2:49       ` [PATCH v4 5/9] perf ui hists: Fix memory leak in evsel__hists_browse() interactive loop Ian Rogers
2026-07-10  3:05         ` sashiko-bot
2026-07-10  2:49       ` [PATCH v4 6/9] perf ui hists: Fix dso_filter reference leak and exit cleanup Ian Rogers
2026-07-10  3:07         ` sashiko-bot
2026-07-10  2:49       ` [PATCH v4 7/9] perf ui hists: Fix NULL pointer array gap in add_script_opt() Ian Rogers
2026-07-10  2:49       ` [PATCH v4 8/9] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-10  3:09         ` sashiko-bot
2026-07-10  2:49       ` [PATCH v4 9/9] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-10  3:17         ` sashiko-bot
2026-07-10  3:06       ` [PATCH v4 1/9] perf hists browser: Increase MAX_OPTIONS to prevent stack buffer overflow sashiko-bot
2026-07-10  5:36       ` [PATCH v5 01/10] " Ian Rogers
2026-07-10  5:36         ` [PATCH v5 02/10] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure Ian Rogers
2026-07-10  5:55           ` sashiko-bot
2026-07-10  5:36         ` [PATCH v5 03/10] perf ui hists: Include limits.h for PATH_MAX definition Ian Rogers
2026-07-10  5:36         ` [PATCH v5 04/10] perf ui hists: Fix stack use-after-return in symbol_filter_str Ian Rogers
2026-07-10  5:59           ` sashiko-bot
2026-07-10  5:36         ` [PATCH v5 05/10] perf disasm: Fix potential NULL pointer dereference and use-after-free in arch__find() Ian Rogers
2026-07-10  5:36         ` [PATCH v5 06/10] perf ui hists: Fix NULL pointer array gap in add_script_opt() Ian Rogers
2026-07-10  5:56           ` sashiko-bot
2026-07-10  5:36         ` [PATCH v5 07/10] perf ui hists: In report UI ensure thread is set with reference counting Ian Rogers
2026-07-10  5:54           ` sashiko-bot
2026-07-10  5:36         ` [PATCH v5 08/10] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-10  5:54           ` sashiko-bot
2026-07-10  5:36         ` [PATCH v5 09/10] perf ui hists: Fix dso_filter reference leak and exit zoom cleanup Ian Rogers
2026-07-10  5:58           ` sashiko-bot
2026-07-10  5:36         ` [PATCH v5 10/10] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-10  6:08           ` sashiko-bot
2026-07-10  5:54         ` [PATCH v5 01/10] perf hists browser: Increase MAX_OPTIONS to prevent stack buffer overflow sashiko-bot
2026-07-16  7:23         ` [PATCH v6 " Ian Rogers
2026-07-16  7:23           ` [PATCH v6 02/10] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure Ian Rogers
2026-07-16  7:40             ` sashiko-bot
2026-07-16  7:23           ` [PATCH v6 03/10] perf ui hists: Include limits.h for PATH_MAX definition Ian Rogers
2026-07-16  7:23           ` [PATCH v6 04/10] perf ui hists: Fix stack use-after-return in symbol_filter_str Ian Rogers
2026-07-16  7:48             ` sashiko-bot
2026-07-18  5:38               ` Namhyung Kim
2026-07-16  7:23           ` [PATCH v6 05/10] perf disasm: Fix potential NULL pointer dereference and use-after-free in arch__find() Ian Rogers
2026-07-16  7:40             ` sashiko-bot
2026-07-16  7:23           ` [PATCH v6 06/10] perf ui hists: Fix NULL pointer array gap in add_script_opt() Ian Rogers
2026-07-16  7:39             ` sashiko-bot
2026-07-16  7:23           ` [PATCH v6 07/10] perf ui hists: In report UI ensure thread is set with reference counting Ian Rogers
2026-07-16  7:35             ` sashiko-bot
2026-07-16  7:23           ` [PATCH v6 08/10] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-16  7:37             ` sashiko-bot
2026-07-18  5:38               ` Namhyung Kim
2026-07-16  7:23           ` [PATCH v6 09/10] perf ui hists: Fix dso_filter reference leak and exit zoom cleanup Ian Rogers
2026-07-16  7:49             ` sashiko-bot
2026-07-16  7:23           ` [PATCH v6 10/10] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-16  7:51             ` sashiko-bot
2026-07-20  4:45           ` [PATCH v6 01/10] perf hists browser: Increase MAX_OPTIONS to prevent stack buffer overflow Namhyung Kim
2026-07-22 16:37             ` Ian Rogers
2026-07-23  4:59           ` [PATCH v7 0/6] perf ui hists / annotate: Remaining fixes for reference counting and annotation Ian Rogers
2026-07-23  4:59             ` [PATCH v7 1/6] perf ui hists: Fix stack use-after-return in symbol_filter_str Ian Rogers
2026-07-23  5:17               ` sashiko-bot
2026-07-23  4:59             ` [PATCH v7 2/6] perf ui hists: Guard against NULL hist_entry in add_script_opt() Ian Rogers
2026-07-23  5:19               ` sashiko-bot [this message]
2026-07-23  4:59             ` [PATCH v7 3/6] perf ui hists: In report UI ensure thread is set with reference counting Ian Rogers
2026-07-23  4:59             ` [PATCH v7 4/6] perf ui hists: Fix dso_filter reference leak and exit zoom cleanup Ian Rogers
2026-07-23  4:59             ` [PATCH v7 5/6] perf annotate: Be robust to annotating without a thread Ian Rogers
2026-07-23  5:34               ` sashiko-bot
2026-07-23  4:59             ` [PATCH v7 6/6] perf ui hists: Remove duplicated thread in popup_action Ian Rogers
2026-07-23  5:32               ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723051937.80DA01F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=irogers@google.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox