* [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper
2026-09-15 6:40 [PATCH v3 0/3] perf annotate-data: Support flexible array types Namhyung Kim
@ 2026-09-15 6:40 ` Namhyung Kim
2026-09-15 6:50 ` sashiko-bot
2026-09-16 13:54 ` Masami Hiramatsu
2026-09-15 6:40 ` [PATCH v3 2/3] perf annotate-date: Allow out-of-size access for flex-array types Namhyung Kim
2026-09-15 6:40 ` [PATCH v3 3/3] perf annotate-data: Adjust type offset for flex-array Namhyung Kim
2 siblings, 2 replies; 10+ messages in thread
From: Namhyung Kim @ 2026-09-15 6:40 UTC (permalink / raw)
To: Arnaldo Carvalho de Melo
Cc: Ian Rogers, Jiri Olsa, Adrian Hunter, James Clark, Peter Zijlstra,
Ingo Molnar, LKML, linux-perf-users, Zecheng Li, Yanbo Zhao,
Tengda Wu, Shuai Xue, Masami Hiramatsu
The die_has_flex_array() returns true when the given type is a compound
type and contains an array at the end. To prevent an infinite recursion
add a depth field to the internal function.
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
---
tools/perf/util/dwarf-aux.c | 97 +++++++++++++++++++++++++++++++++++++
tools/perf/util/dwarf-aux.h | 3 ++
2 files changed, 100 insertions(+)
diff --git a/tools/perf/util/dwarf-aux.c b/tools/perf/util/dwarf-aux.c
index d7160f87ac7d7ab3..a5aefe7d1d62d090 100644
--- a/tools/perf/util/dwarf-aux.c
+++ b/tools/perf/util/dwarf-aux.c
@@ -7,6 +7,7 @@
#include <inttypes.h>
#include <stdbool.h>
#include <stdlib.h>
+#include <string.h>
#include "debug.h"
#include "dwarf-aux.h"
#include "dwarf-regs.h"
@@ -2180,3 +2181,99 @@ Dwarf_Die *die_deref_ptr_type(Dwarf_Die *ptr_die, int offset,
return die_get_member_type(&type_die, offset, die_mem);
}
+
+static bool is_flex_array_member(Dwarf_Die *mb_die)
+{
+ Dwarf_Die type_die;
+ Dwarf_Word size;
+
+ /* get the type of the member */
+ if (die_get_real_type(mb_die, &type_die) == NULL)
+ return false;
+
+ if (dwarf_tag(&type_die) != DW_TAG_array_type)
+ return false;
+
+ return dwarf_aggregate_size(&type_die, &size) < 0 || size == 0;
+}
+
+#define MAX_FLEX_ARRAY_RECURSION 256 /* arbitrary */
+
+static bool die_has_flex_array_recurse(Dwarf_Die *parent_die, int depth)
+{
+ Dwarf_Die die_mem, last_mb;
+ int tag = dwarf_tag(parent_die);
+ bool found = false;
+ Dwarf_Word loc, last_loc = 0;
+
+ if (tag != DW_TAG_structure_type && tag != DW_TAG_union_type)
+ return false;
+
+ /* prevent infinite recursion */
+ if (depth > MAX_FLEX_ARRAY_RECURSION)
+ return false;
+
+ if (dwarf_child(parent_die, &die_mem))
+ return false;
+
+ do {
+ if (dwarf_tag(&die_mem) != DW_TAG_member)
+ continue;
+
+ if (tag == DW_TAG_union_type) {
+ if (is_flex_array_member(&die_mem))
+ return true;
+
+ if (die_get_real_type(&die_mem, &last_mb) &&
+ die_has_flex_array_recurse(&last_mb, depth + 1))
+ return true;
+ }
+
+ if (tag == DW_TAG_structure_type) {
+ if (die_get_data_member_location(&die_mem, &loc) < 0)
+ loc = 0;
+
+ if (!found || last_loc < loc) {
+ memcpy(&last_mb, &die_mem, sizeof(last_mb));
+ last_loc = loc;
+ }
+ }
+
+ found = true;
+ } while (dwarf_siblingof(&die_mem, &die_mem) == 0);
+
+ if (tag == DW_TAG_structure_type && found) {
+ if (is_flex_array_member(&last_mb))
+ return true;
+
+ if (die_get_real_type(&last_mb, &die_mem))
+ return die_has_flex_array_recurse(&die_mem, depth + 1);
+ }
+
+ return false;
+}
+
+/**
+ * die_has_flex_array - Check if the given type has a flex-array at the end
+ * @type_die: a pointer to type DIE
+ *
+ * This function returns %true iff @type_die is a struct type and has an
+ * array at the end. Note that the flex-array has no element, it should have
+ * no size and the parent size doesn't include the flex-array. So it should
+ * locate at the offset of the parent size.
+ *
+ * For simplicity, it assumes the parent size of aligned with the flex-array.
+ */
+bool die_has_flex_array(Dwarf_Die *type_die)
+{
+ Dwarf_Die real_type;
+
+ if (dwarf_tag(type_die) == DW_TAG_typedef) {
+ if (die_get_real_type(type_die, &real_type) == NULL)
+ return false;
+
+ type_die = &real_type;
+ }
+
+ return die_has_flex_array_recurse(type_die, 0);
+}
diff --git a/tools/perf/util/dwarf-aux.h b/tools/perf/util/dwarf-aux.h
index 161f0bf980b6ee6a..9b662db710220522 100644
--- a/tools/perf/util/dwarf-aux.h
+++ b/tools/perf/util/dwarf-aux.h
@@ -189,4 +189,7 @@ void die_collect_global_vars(Dwarf_Die *cu_die, struct die_var_type **var_types)
/* Get the frame base information from CFA */
int die_get_cfa(Dwarf *dwarf, u64 pc, int *preg, int *poffset);
+/* Check whether given type has a flex array */
+bool die_has_flex_array(Dwarf_Die *parent_die);
+
#endif /* _DWARF_AUX_H */
--
2.55.0.1082.g2b9226bbc0-goog
^ permalink raw reply related [flat|nested] 10+ messages in thread* Re: [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper
2026-09-15 6:40 ` [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper Namhyung Kim
@ 2026-09-15 6:50 ` sashiko-bot
2026-09-16 5:49 ` Namhyung Kim
2026-09-16 13:54 ` Masami Hiramatsu
1 sibling, 1 reply; 10+ messages in thread
From: sashiko-bot @ 2026-09-15 6:50 UTC (permalink / raw)
To: Namhyung Kim; +Cc: linux-perf-users
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [Medium] perf dwarf-aux: incorrect offset comparison masks flex arrays after empty structs
- [Medium] perf dwarf-aux: missing DW_AT_data_bit_offset support causes member offset collapse
- [Medium] perf dwarf-aux: top-level type resolution drops const/volatile modifiers
--
commit 93f74aec3d433215197c18f94befb7b584381fa4
Author: Namhyung Kim <namhyung@kernel.org>
perf dwarf-aux: Add die_has_flex_array() helper
This commit adds the die_has_flex_array() helper to identify if a given
DWARF type is a compound type containing a flexible array at the end. It
also introduces a depth parameter to the internal recursive function to
prevent infinite recursion.
> diff --git a/tools/perf/util/dwarf-aux.c b/tools/perf/util/dwarf-aux.c
> index d7160f87ac7d7..a5aefe7d1d62d 100644
> --- a/tools/perf/util/dwarf-aux.c
> +++ b/tools/perf/util/dwarf-aux.c
[ ... ]
> + if (tag == DW_TAG_structure_type) {
> + if (die_get_data_member_location(&die_mem, &loc) < 0)
> + loc = 0;
[Severity: Medium]
Will this fallback to 0 corrupt the tracking of the final member if the
struct contains members using DWARF 5 DW_AT_data_bit_offset?
When die_get_data_member_location() returns < 0 for bit-offset attributes,
setting loc = 0 silently overrides the actual offset. This could cause the
maximum-offset calculation to fail.
> +
> + if (!found || last_loc < loc) {
> + memcpy(&last_mb, &die_mem, sizeof(last_mb));
> + last_loc = loc;
> + }
[Severity: Medium]
Does this strict inequality prevent the tracking variable from updating to
the true final member if multiple members share the same maximum offset?
If a struct ends with an empty struct followed by a flexible array, both
members will have the exact same byte offset. Using a strict less-than
comparison means the tracking variable won't update to the flexible array.
This could lead to false negatives when analyzing binaries built with GNU C
empty struct extensions.
> + }
> +
> + found = true;
> + } while (dwarf_siblingof(&die_mem, &die_mem) == 0);
[ ... ]
> +bool die_has_flex_array(Dwarf_Die *type_die)
> +{
> + Dwarf_Die real_type;
> +
> + if (dwarf_tag(type_die) == DW_TAG_typedef) {
> + if (die_get_real_type(type_die, &real_type) == NULL)
> + return false;
> +
> + type_die = &real_type;
> + }
> +
> + return die_has_flex_array_recurse(type_die, 0);
> +}
[Severity: Medium]
Does this type stripping logic ignore standard qualifiers like const or
volatile?
By explicitly limiting type resolution to DW_TAG_typedef, variables
declared as const struct foo or volatile struct foo will pass a
DW_TAG_const_type or DW_TAG_volatile_type directly to
die_has_flex_array_recurse(). The recursive function will then reject it
because its tag is not a struct or union, causing flexible arrays in
qualified types to be silently ignored.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260915064035.1970175-1-namhyung@kernel.org?part=1
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper
2026-09-15 6:50 ` sashiko-bot
@ 2026-09-16 5:49 ` Namhyung Kim
0 siblings, 0 replies; 10+ messages in thread
From: Namhyung Kim @ 2026-09-16 5:49 UTC (permalink / raw)
To: sashiko-reviews; +Cc: linux-perf-users
On Tue, Sep 15, 2026 at 06:50:26AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
> - [Medium] perf dwarf-aux: incorrect offset comparison masks flex arrays after empty structs
> - [Medium] perf dwarf-aux: missing DW_AT_data_bit_offset support causes member offset collapse
> - [Medium] perf dwarf-aux: top-level type resolution drops const/volatile modifiers
> --
>
> commit 93f74aec3d433215197c18f94befb7b584381fa4
> Author: Namhyung Kim <namhyung@kernel.org>
>
> perf dwarf-aux: Add die_has_flex_array() helper
>
> This commit adds the die_has_flex_array() helper to identify if a given
> DWARF type is a compound type containing a flexible array at the end. It
> also introduces a depth parameter to the internal recursive function to
> prevent infinite recursion.
>
> > diff --git a/tools/perf/util/dwarf-aux.c b/tools/perf/util/dwarf-aux.c
> > index d7160f87ac7d7..a5aefe7d1d62d 100644
> > --- a/tools/perf/util/dwarf-aux.c
> > +++ b/tools/perf/util/dwarf-aux.c
>
> [ ... ]
>
> > + if (tag == DW_TAG_structure_type) {
> > + if (die_get_data_member_location(&die_mem, &loc) < 0)
> > + loc = 0;
>
> [Severity: Medium]
> Will this fallback to 0 corrupt the tracking of the final member if the
> struct contains members using DWARF 5 DW_AT_data_bit_offset?
>
> When die_get_data_member_location() returns < 0 for bit-offset attributes,
> setting loc = 0 silently overrides the actual offset. This could cause the
> maximum-offset calculation to fail.
I don't think we are interested in bitfield members. I suspect it's not
possible to have a flexible array with bitfields?
>
> > +
> > + if (!found || last_loc < loc) {
> > + memcpy(&last_mb, &die_mem, sizeof(last_mb));
> > + last_loc = loc;
> > + }
>
> [Severity: Medium]
> Does this strict inequality prevent the tracking variable from updating to
> the true final member if multiple members share the same maximum offset?
>
> If a struct ends with an empty struct followed by a flexible array, both
> members will have the exact same byte offset. Using a strict less-than
> comparison means the tracking variable won't update to the flexible array.
> This could lead to false negatives when analyzing binaries built with GNU C
> empty struct extensions.
Fair enough, will update with the same offset too.
>
> > + }
> > +
> > + found = true;
> > + } while (dwarf_siblingof(&die_mem, &die_mem) == 0);
>
> [ ... ]
>
> > +bool die_has_flex_array(Dwarf_Die *type_die)
> > +{
> > + Dwarf_Die real_type;
> > +
> > + if (dwarf_tag(type_die) == DW_TAG_typedef) {
> > + if (die_get_real_type(type_die, &real_type) == NULL)
> > + return false;
> > +
> > + type_die = &real_type;
> > + }
> > +
> > + return die_has_flex_array_recurse(type_die, 0);
> > +}
>
> [Severity: Medium]
> Does this type stripping logic ignore standard qualifiers like const or
> volatile?
>
> By explicitly limiting type resolution to DW_TAG_typedef, variables
> declared as const struct foo or volatile struct foo will pass a
> DW_TAG_const_type or DW_TAG_volatile_type directly to
> die_has_flex_array_recurse(). The recursive function will then reject it
> because its tag is not a struct or union, causing flexible arrays in
> qualified types to be silently ignored.
Ok, I'll skip qualifiers as well.
Thanks,
Namhyung
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper
2026-09-15 6:40 ` [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper Namhyung Kim
2026-09-15 6:50 ` sashiko-bot
@ 2026-09-16 13:54 ` Masami Hiramatsu
1 sibling, 0 replies; 10+ messages in thread
From: Masami Hiramatsu @ 2026-09-16 13:54 UTC (permalink / raw)
To: Namhyung Kim
Cc: Arnaldo Carvalho de Melo, Ian Rogers, Jiri Olsa, Adrian Hunter,
James Clark, Peter Zijlstra, Ingo Molnar, LKML, linux-perf-users,
Zecheng Li, Yanbo Zhao, Tengda Wu, Shuai Xue, Masami Hiramatsu
On Mon, 14 Sep 2026 23:40:33 -0700
Namhyung Kim <namhyung@kernel.org> wrote:
> The die_has_flex_array() returns true when the given type is a compound
> type and contains an array at the end. To prevent an infinite recursion
> add a depth field to the internal function.
>
This looks good to me.
Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Thanks!
> Cc: Masami Hiramatsu <mhiramat@kernel.org>
> Signed-off-by: Namhyung Kim <namhyung@kernel.org>
> ---
> tools/perf/util/dwarf-aux.c | 97 +++++++++++++++++++++++++++++++++++++
> tools/perf/util/dwarf-aux.h | 3 ++
> 2 files changed, 100 insertions(+)
>
> diff --git a/tools/perf/util/dwarf-aux.c b/tools/perf/util/dwarf-aux.c
> index d7160f87ac7d7ab3..a5aefe7d1d62d090 100644
> --- a/tools/perf/util/dwarf-aux.c
> +++ b/tools/perf/util/dwarf-aux.c
> @@ -7,6 +7,7 @@
> #include <inttypes.h>
> #include <stdbool.h>
> #include <stdlib.h>
> +#include <string.h>
> #include "debug.h"
> #include "dwarf-aux.h"
> #include "dwarf-regs.h"
> @@ -2180,3 +2181,99 @@ Dwarf_Die *die_deref_ptr_type(Dwarf_Die *ptr_die, int offset,
>
> return die_get_member_type(&type_die, offset, die_mem);
> }
> +
> +static bool is_flex_array_member(Dwarf_Die *mb_die)
> +{
> + Dwarf_Die type_die;
> + Dwarf_Word size;
> +
> + /* get the type of the member */
> + if (die_get_real_type(mb_die, &type_die) == NULL)
> + return false;
> +
> + if (dwarf_tag(&type_die) != DW_TAG_array_type)
> + return false;
> +
> + return dwarf_aggregate_size(&type_die, &size) < 0 || size == 0;
> +}
> +
> +#define MAX_FLEX_ARRAY_RECURSION 256 /* arbitrary */
> +
> +static bool die_has_flex_array_recurse(Dwarf_Die *parent_die, int depth)
> +{
> + Dwarf_Die die_mem, last_mb;
> + int tag = dwarf_tag(parent_die);
> + bool found = false;
> + Dwarf_Word loc, last_loc = 0;
> +
> + if (tag != DW_TAG_structure_type && tag != DW_TAG_union_type)
> + return false;
> +
> + /* prevent infinite recursion */
> + if (depth > MAX_FLEX_ARRAY_RECURSION)
> + return false;
> +
> + if (dwarf_child(parent_die, &die_mem))
> + return false;
> +
> + do {
> + if (dwarf_tag(&die_mem) != DW_TAG_member)
> + continue;
> +
> + if (tag == DW_TAG_union_type) {
> + if (is_flex_array_member(&die_mem))
> + return true;
> +
> + if (die_get_real_type(&die_mem, &last_mb) &&
> + die_has_flex_array_recurse(&last_mb, depth + 1))
> + return true;
> + }
> +
> + if (tag == DW_TAG_structure_type) {
> + if (die_get_data_member_location(&die_mem, &loc) < 0)
> + loc = 0;
> +
> + if (!found || last_loc < loc) {
> + memcpy(&last_mb, &die_mem, sizeof(last_mb));
> + last_loc = loc;
> + }
> + }
> +
> + found = true;
> + } while (dwarf_siblingof(&die_mem, &die_mem) == 0);
> +
> + if (tag == DW_TAG_structure_type && found) {
> + if (is_flex_array_member(&last_mb))
> + return true;
> +
> + if (die_get_real_type(&last_mb, &die_mem))
> + return die_has_flex_array_recurse(&die_mem, depth + 1);
> + }
> +
> + return false;
> +}
> +
> +/**
> + * die_has_flex_array - Check if the given type has a flex-array at the end
> + * @type_die: a pointer to type DIE
> + *
> + * This function returns %true iff @type_die is a struct type and has an
> + * array at the end. Note that the flex-array has no element, it should have
> + * no size and the parent size doesn't include the flex-array. So it should
> + * locate at the offset of the parent size.
> + *
> + * For simplicity, it assumes the parent size of aligned with the flex-array.
> + */
> +bool die_has_flex_array(Dwarf_Die *type_die)
> +{
> + Dwarf_Die real_type;
> +
> + if (dwarf_tag(type_die) == DW_TAG_typedef) {
> + if (die_get_real_type(type_die, &real_type) == NULL)
> + return false;
> +
> + type_die = &real_type;
> + }
> +
> + return die_has_flex_array_recurse(type_die, 0);
> +}
> diff --git a/tools/perf/util/dwarf-aux.h b/tools/perf/util/dwarf-aux.h
> index 161f0bf980b6ee6a..9b662db710220522 100644
> --- a/tools/perf/util/dwarf-aux.h
> +++ b/tools/perf/util/dwarf-aux.h
> @@ -189,4 +189,7 @@ void die_collect_global_vars(Dwarf_Die *cu_die, struct die_var_type **var_types)
> /* Get the frame base information from CFA */
> int die_get_cfa(Dwarf *dwarf, u64 pc, int *preg, int *poffset);
>
> +/* Check whether given type has a flex array */
> +bool die_has_flex_array(Dwarf_Die *parent_die);
> +
> #endif /* _DWARF_AUX_H */
> --
> 2.55.0.1082.g2b9226bbc0-goog
>
--
Masami Hiramatsu (Google) <mhiramat@kernel.org>
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH v3 2/3] perf annotate-date: Allow out-of-size access for flex-array types
2026-09-15 6:40 [PATCH v3 0/3] perf annotate-data: Support flexible array types Namhyung Kim
2026-09-15 6:40 ` [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper Namhyung Kim
@ 2026-09-15 6:40 ` Namhyung Kim
2026-09-15 6:48 ` sashiko-bot
2026-09-15 6:40 ` [PATCH v3 3/3] perf annotate-data: Adjust type offset for flex-array Namhyung Kim
2 siblings, 1 reply; 10+ messages in thread
From: Namhyung Kim @ 2026-09-15 6:40 UTC (permalink / raw)
To: Arnaldo Carvalho de Melo
Cc: Ian Rogers, Jiri Olsa, Adrian Hunter, James Clark, Peter Zijlstra,
Ingo Molnar, LKML, linux-perf-users, Zecheng Li, Yanbo Zhao,
Tengda Wu, Shuai Xue
Structs that have a flex array will have accesses beyond its original
size as the array was declared as 0 sized. For now, it just allow any
offset bigger than the size. It could be refined later.
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
---
tools/perf/util/annotate-data.c | 63 ++++++++++++++++++---------------
tools/perf/util/annotate-data.h | 2 ++
2 files changed, 36 insertions(+), 29 deletions(-)
diff --git a/tools/perf/util/annotate-data.c b/tools/perf/util/annotate-data.c
index aff60a630fd05b01..1ee2b74f99205567 100644
--- a/tools/perf/util/annotate-data.c
+++ b/tools/perf/util/annotate-data.c
@@ -7,6 +7,7 @@
#include <errno.h>
#include <stdio.h>
#include <stdlib.h>
+#include <string.h>
#include <inttypes.h>
#include <linux/zalloc.h>
@@ -248,8 +249,15 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
else
die_mem = member_type;
- if (dwarf_aggregate_size(&die_mem, &size) < 0)
- size = 0;
+ if (dwarf_aggregate_size(&die_mem, &size) < 0) {
+ if (dwarf_tag(&die_mem) == DW_TAG_array_type) { /* flex-array? */
+ die_get_real_type(&die_mem, &die_mem);
+ if (dwarf_aggregate_size(&die_mem, &size) < 0)
+ size = 0;
+ } else {
+ size = 0;
+ }
+ }
if (dwarf_attr_integrate(die, DW_AT_data_member_location, &attr)) {
if (dwarf_formudata(&attr, &loc) != 0) {
@@ -399,6 +407,7 @@ static struct annotated_data_type *dso__findnew_data_type(struct dso *dso,
result->self.type_name = type_name;
result->self.size = size;
INIT_LIST_HEAD(&result->self.children);
+ result->flex_array = die_has_flex_array(type_die);
if (symbol_conf.annotate_data_member)
add_member_types(result, type_die);
@@ -517,13 +526,30 @@ static bool is_better_type(Dwarf_Die *type_a, Dwarf_Die *type_b)
return false;
}
+static enum type_match_result check_type_offset(Dwarf_Die *type_die, int offset)
+{
+ Dwarf_Word size;
+
+ /* Get the size of the actual type */
+ if (dwarf_aggregate_size(type_die, &size) < 0)
+ return PERF_TMR_NO_SIZE;
+
+ /* Minimal sanity check */
+ if (offset < 0)
+ return PERF_TMR_BAD_OFFSET;
+
+ if ((unsigned)offset >= size && !die_has_flex_array(type_die))
+ return PERF_TMR_BAD_OFFSET;
+
+ return PERF_TMR_OK;
+}
+
/* The type info will be saved in @type_die */
static enum type_match_result check_variable(struct data_loc_info *dloc,
Dwarf_Die *var_die,
Dwarf_Die *type_die, int reg,
int offset, bool is_fbreg)
{
- Dwarf_Word size;
bool needs_pointer = true;
Dwarf_Die sized_type;
@@ -554,15 +580,7 @@ static enum type_match_result check_variable(struct data_loc_info *dloc,
else
sized_type = *type_die;
- /* Get the size of the actual type */
- if (dwarf_aggregate_size(&sized_type, &size) < 0)
- return PERF_TMR_NO_SIZE;
-
- /* Minimal sanity check */
- if ((unsigned)offset >= size)
- return PERF_TMR_BAD_OFFSET;
-
- return PERF_TMR_OK;
+ return check_type_offset(&sized_type, offset);
}
struct type_state_stack *find_stack_state(struct type_state *state,
@@ -1112,7 +1130,6 @@ static enum type_match_result check_matching_type(struct type_state *state,
struct disasm_line *dl,
Dwarf_Die *type_die)
{
- Dwarf_Word size;
u32 insn_offset = dl->al.offset;
int reg = dloc->op->reg1;
int offset = dloc->op->offset;
@@ -1166,12 +1183,7 @@ static enum type_match_result check_matching_type(struct type_state *state,
else
sized_type = *type_die;
- /* Get the size of the actual type */
- if (dwarf_aggregate_size(&sized_type, &size) < 0 ||
- (unsigned)dloc->type_offset >= size)
- return PERF_TMR_BAD_OFFSET;
-
- return PERF_TMR_OK;
+ return check_type_offset(&sized_type, dloc->type_offset);
}
if (state->regs[reg].kind == TSR_KIND_POINTER) {
@@ -1190,12 +1202,7 @@ static enum type_match_result check_matching_type(struct type_state *state,
dloc->type_offset = dloc->op->offset + state->regs[reg].offset;
- /* Get the size of the actual type */
- if (dwarf_aggregate_size(type_die, &size) < 0 ||
- (unsigned)dloc->type_offset >= size)
- return PERF_TMR_BAD_OFFSET;
-
- return PERF_TMR_OK;
+ return check_type_offset(type_die, dloc->type_offset);
}
if (state->regs[reg].kind == TSR_KIND_PERCPU_POINTER) {
@@ -1209,9 +1216,7 @@ static enum type_match_result check_matching_type(struct type_state *state,
dloc->type_offset = dloc->op->offset;
- /* Get the size of the actual type */
- if (dwarf_aggregate_size(type_die, &size) < 0 ||
- (unsigned)dloc->type_offset >= size)
+ if (check_type_offset(type_die, dloc->type_offset) != PERF_TMR_OK)
return PERF_TMR_BAIL_OUT;
return PERF_TMR_OK;
@@ -1839,7 +1844,7 @@ int annotated_data_type__update_samples(struct annotated_data_type *adt,
return -1;
}
- if (offset < 0 || offset >= adt->self.size)
+ if (offset < 0 || (offset >= adt->self.size && !adt->flex_array))
return -1;
h = &adt->histograms[evsel->core.idx];
diff --git a/tools/perf/util/annotate-data.h b/tools/perf/util/annotate-data.h
index ca2096a9ee62cbfe..957726334907cc0e 100644
--- a/tools/perf/util/annotate-data.h
+++ b/tools/perf/util/annotate-data.h
@@ -85,6 +85,7 @@ struct type_hist {
* struct annotated_data_type - Data type to profile
* @node: RB-tree node for dso->type_tree
* @self: Actual type information
+ * @flex_array: Whether it has a flex array
* @nr_histogram: Number of histogram entries
* @histograms: An array of histograms
*
@@ -93,6 +94,7 @@ struct type_hist {
struct annotated_data_type {
struct rb_node node;
struct annotated_member self;
+ bool flex_array;
int nr_histograms;
struct type_hist *histograms;
};
--
2.55.0.1082.g2b9226bbc0-goog
^ permalink raw reply related [flat|nested] 10+ messages in thread* [PATCH v3 3/3] perf annotate-data: Adjust type offset for flex-array
2026-09-15 6:40 [PATCH v3 0/3] perf annotate-data: Support flexible array types Namhyung Kim
2026-09-15 6:40 ` [PATCH v3 1/3] perf dwarf-aux: Add die_has_flex_array() helper Namhyung Kim
2026-09-15 6:40 ` [PATCH v3 2/3] perf annotate-date: Allow out-of-size access for flex-array types Namhyung Kim
@ 2026-09-15 6:40 ` Namhyung Kim
2026-09-15 6:53 ` sashiko-bot
2 siblings, 1 reply; 10+ messages in thread
From: Namhyung Kim @ 2026-09-15 6:40 UTC (permalink / raw)
To: Arnaldo Carvalho de Melo
Cc: Ian Rogers, Jiri Olsa, Adrian Hunter, James Clark, Peter Zijlstra,
Ingo Molnar, LKML, linux-perf-users, Zecheng Li, Yanbo Zhao,
Tengda Wu, Shuai Xue
The flex array members are located beyond the original type size. Also
it needs to adjust the offset in an array to find a corresponding
element using module operation. Note that we focus on access to type and
field, so array index is not important.
Make sure to find a field name for flex arrays.
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
---
tools/perf/util/annotate-data.c | 77 ++++++++++++++++++++++++++++++---
1 file changed, 70 insertions(+), 7 deletions(-)
diff --git a/tools/perf/util/annotate-data.c b/tools/perf/util/annotate-data.c
index 1ee2b74f99205567..1c19b807c4f2179d 100644
--- a/tools/perf/util/annotate-data.c
+++ b/tools/perf/util/annotate-data.c
@@ -241,7 +241,8 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
return DIE_FIND_CB_END;
strbuf_init(&sb, 32);
- die_get_typename(die, &sb);
+ if (die_get_typename(die, &sb) < 0)
+ strbuf_add(&sb, "(unknown type)", 14);
__die_get_real_type(die, &member_type);
if (dwarf_tag(&member_type) == DW_TAG_typedef)
@@ -333,19 +334,40 @@ static void delete_members(struct annotated_member *member)
}
static int fill_member_name(char *buf, size_t sz, struct annotated_member *m,
- int offset, bool first)
+ int offset, bool first, bool has_flex_array)
{
struct annotated_member *child;
+ bool found = false;
+ int len;
if (list_empty(&m->children))
return 0;
list_for_each_entry(child, &m->children, node) {
- int len;
-
if (offset < child->offset || offset >= child->offset + child->size)
continue;
+ found = true;
+ break;
+ }
+
+ if (!found && has_flex_array) {
+ /*
+ * It may have an intermediate struct that has another struct that
+ * contains a flex array. In that case, the outer struct itself is
+ * has no array and the size is less than the offset so the above
+ * logic won't find the outer struct at the offset. Let's use the
+ * last struct if it couldn't find a member for the flex array.
+ */
+ child = list_last_entry(&m->children, struct annotated_member, node);
+
+ if (offset < child->offset)
+ return 0;
+
+ found = true;
+ }
+
+ if (found) {
/* It can have anonymous struct/union members */
if (child->var_name) {
len = scnprintf(buf, sz, "%s%s",
@@ -355,15 +377,37 @@ static int fill_member_name(char *buf, size_t sz, struct annotated_member *m,
len = 0;
}
- return fill_member_name(buf + len, sz - len, child, offset, first) + len;
+ return fill_member_name(buf + len, sz - len, child, offset, first,
+ has_flex_array) + len;
}
+
return 0;
}
int annotated_data_type__get_member_name(struct annotated_data_type *adt,
char *buf, size_t sz, int member_offset)
{
- return fill_member_name(buf, sz, &adt->self, member_offset, /*first=*/true);
+ return fill_member_name(buf, sz, &adt->self, member_offset, /*first=*/true,
+ adt->flex_array);
+}
+
+static struct annotated_member *find_flex_array(struct annotated_member *m)
+{
+ struct annotated_member *child;
+
+ if (list_empty(&m->children))
+ return NULL;
+
+ child = list_last_entry(&m->children, struct annotated_member, node);
+ if (strstr(child->type_name, "[]"))
+ return child;
+
+ return find_flex_array(child);
+}
+
+static struct annotated_member *get_flex_array_member(struct annotated_data_type *adt)
+{
+ return find_flex_array(&adt->self);
}
static struct annotated_data_type *dso__findnew_data_type(struct dso *dso,
@@ -1740,6 +1784,7 @@ struct annotated_data_type *find_data_type(struct data_loc_info *dloc)
{
struct dso *dso = map__dso(dloc->ms->map);
Dwarf_Die type_die;
+ struct annotated_data_type *result;
/*
* The type offset is the same as instruction offset by default.
@@ -1752,7 +1797,25 @@ struct annotated_data_type *find_data_type(struct data_loc_info *dloc)
if (find_data_type_die(dloc, &type_die) < 0)
return NULL;
- return dso__findnew_data_type(dso, &type_die);
+ result = dso__findnew_data_type(dso, &type_die);
+ if (result == NULL)
+ return NULL;
+
+ if (result->flex_array && dloc->type_offset > result->self.size) {
+ struct annotated_member *flex_array = get_flex_array_member(result);
+
+ if (flex_array && flex_array->size > 0) {
+ int offset = dloc->type_offset;
+
+ /* adjust offset in the flex array */
+ offset -= flex_array->offset;
+ offset %= flex_array->size;
+ offset += flex_array->offset;
+
+ dloc->type_offset = offset;
+ }
+ }
+ return result;
}
static size_t data_type_hash(long key, void *ctx __maybe_unused)
--
2.55.0.1082.g2b9226bbc0-goog
^ permalink raw reply related [flat|nested] 10+ messages in thread* Re: [PATCH v3 3/3] perf annotate-data: Adjust type offset for flex-array
2026-09-15 6:40 ` [PATCH v3 3/3] perf annotate-data: Adjust type offset for flex-array Namhyung Kim
@ 2026-09-15 6:53 ` sashiko-bot
2026-09-16 5:58 ` Namhyung Kim
0 siblings, 1 reply; 10+ messages in thread
From: sashiko-bot @ 2026-09-15 6:53 UTC (permalink / raw)
To: Namhyung Kim; +Cc: linux-perf-users
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [Medium] perf: flex-array offset adjustment skips elements in tail padding
- [Medium] perf: zero-length flex-arrays bypass element size extraction
- [Medium] perf: null pointer dereference in find_flex_array() on alloc failure
--
commit f8d5c159e83503d5c3d85f5f3c22dec6b4f25c06
Author: Namhyung Kim <namhyung@kernel.org>
perf annotate-data: Adjust type offset for flex-array
This commit adjusts the type offset for flexible array members in perf's
data annotation. It ensures that the offset is properly adjusted to find
the corresponding element using modulo operations and updates the member
name resolution to correctly identify flex arrays.
> diff --git a/tools/perf/util/annotate-data.c b/tools/perf/util/annotate-data.c
> index 1ee2b74f99205..1c19b807c4f21 100644
> --- a/tools/perf/util/annotate-data.c
> +++ b/tools/perf/util/annotate-data.c
> @@ -241,7 +241,8 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
> return DIE_FIND_CB_END;
>
> strbuf_init(&sb, 32);
> - die_get_typename(die, &sb);
> + if (die_get_typename(die, &sb) < 0)
> + strbuf_add(&sb, "(unknown type)", 14);
>
> __die_get_real_type(die, &member_type);
> if (dwarf_tag(&member_type) == DW_TAG_typedef)
[Severity: Medium]
Does this code safely handle zero-length flexible arrays during element size
extraction?
Just below this change in __add_member_cb(), the logic assumes failures
for flexible arrays:
if (dwarf_aggregate_size(&die_mem, &size) < 0) {
if (dwarf_tag(&die_mem) == DW_TAG_array_type) {
die_get_real_type(&die_mem, &die_mem);
...
Since dwarf_aggregate_size() returns 0 for zero-length arrays, the < 0
condition is skipped. This disables offset adjustment for all GNU zero-length
arrays (e.g., [0]), which results in incorrect field annotations.
[ ... ]
> @@ -355,15 +377,37 @@ static int fill_member_name(char *buf, size_t sz, struct annotated_member *m,
[ ... ]
> +static struct annotated_member *find_flex_array(struct annotated_member *m)
> +{
> + struct annotated_member *child;
> +
> + if (list_empty(&m->children))
> + return NULL;
> +
> + child = list_last_entry(&m->children, struct annotated_member, node);
> + if (strstr(child->type_name, "[]"))
[Severity: Medium]
Could child->type_name be NULL here?
If strbuf_init() or strbuf_add() fails due to memory pressure during type
string construction, strbuf_detach() returns NULL. Passing an unchecked NULL
pointer to strstr() in find_flex_array() could cause a segmentation fault in
the perf tool.
> + return child;
> +
> + return find_flex_array(child);
> +}
[ ... ]
> @@ -1740,6 +1784,7 @@ struct annotated_data_type *find_data_type(struct data_loc_info *dloc)
[ ... ]
> - return dso__findnew_data_type(dso, &type_die);
> + result = dso__findnew_data_type(dso, &type_die);
> + if (result == NULL)
> + return NULL;
> +
> + if (result->flex_array && dloc->type_offset > result->self.size) {
[Severity: Medium]
Does this condition skip elements located in the tail padding of the struct?
By checking that dloc->type_offset > result->self.size, the offset adjustment
is skipped if the flexible array element being accessed has an offset less
than or equal to the total padded size of the parent struct.
The unadjusted offset fails to match children in fill_member_name(),
erroneously falling back to the last member during offline perf data analysis.
> + struct annotated_member *flex_array = get_flex_array_member(result);
> +
> + if (flex_array && flex_array->size > 0) {
> + int offset = dloc->type_offset;
> +
> + /* adjust offset in the flex array */
> + offset -= flex_array->offset;
> + offset %= flex_array->size;
> + offset += flex_array->offset;
> +
> + dloc->type_offset = offset;
> + }
> + }
> + return result;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260915064035.1970175-1-namhyung@kernel.org?part=3
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH v3 3/3] perf annotate-data: Adjust type offset for flex-array
2026-09-15 6:53 ` sashiko-bot
@ 2026-09-16 5:58 ` Namhyung Kim
0 siblings, 0 replies; 10+ messages in thread
From: Namhyung Kim @ 2026-09-16 5:58 UTC (permalink / raw)
To: sashiko-reviews; +Cc: linux-perf-users
On Tue, Sep 15, 2026 at 06:53:13AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
> - [Medium] perf: flex-array offset adjustment skips elements in tail padding
> - [Medium] perf: zero-length flex-arrays bypass element size extraction
> - [Medium] perf: null pointer dereference in find_flex_array() on alloc failure
> --
>
> commit f8d5c159e83503d5c3d85f5f3c22dec6b4f25c06
> Author: Namhyung Kim <namhyung@kernel.org>
>
> perf annotate-data: Adjust type offset for flex-array
>
> This commit adjusts the type offset for flexible array members in perf's
> data annotation. It ensures that the offset is properly adjusted to find
> the corresponding element using modulo operations and updates the member
> name resolution to correctly identify flex arrays.
>
> > diff --git a/tools/perf/util/annotate-data.c b/tools/perf/util/annotate-data.c
> > index 1ee2b74f99205..1c19b807c4f21 100644
> > --- a/tools/perf/util/annotate-data.c
> > +++ b/tools/perf/util/annotate-data.c
> > @@ -241,7 +241,8 @@ static int __add_member_cb(Dwarf_Die *die, void *arg)
> > return DIE_FIND_CB_END;
> >
> > strbuf_init(&sb, 32);
> > - die_get_typename(die, &sb);
> > + if (die_get_typename(die, &sb) < 0)
> > + strbuf_add(&sb, "(unknown type)", 14);
> >
> > __die_get_real_type(die, &member_type);
> > if (dwarf_tag(&member_type) == DW_TAG_typedef)
>
> [Severity: Medium]
> Does this code safely handle zero-length flexible arrays during element size
> extraction?
>
> Just below this change in __add_member_cb(), the logic assumes failures
> for flexible arrays:
>
> if (dwarf_aggregate_size(&die_mem, &size) < 0) {
> if (dwarf_tag(&die_mem) == DW_TAG_array_type) {
> die_get_real_type(&die_mem, &die_mem);
> ...
>
> Since dwarf_aggregate_size() returns 0 for zero-length arrays, the < 0
> condition is skipped. This disables offset adjustment for all GNU zero-length
> arrays (e.g., [0]), which results in incorrect field annotations.
Ok, will handle that too.
>
> [ ... ]
> > @@ -355,15 +377,37 @@ static int fill_member_name(char *buf, size_t sz, struct annotated_member *m,
> [ ... ]
> > +static struct annotated_member *find_flex_array(struct annotated_member *m)
> > +{
> > + struct annotated_member *child;
> > +
> > + if (list_empty(&m->children))
> > + return NULL;
> > +
> > + child = list_last_entry(&m->children, struct annotated_member, node);
> > + if (strstr(child->type_name, "[]"))
>
> [Severity: Medium]
> Could child->type_name be NULL here?
>
> If strbuf_init() or strbuf_add() fails due to memory pressure during type
> string construction, strbuf_detach() returns NULL. Passing an unchecked NULL
> pointer to strstr() in find_flex_array() could cause a segmentation fault in
> the perf tool.
I'll check the return value of strbuf_init(). Then strbuf_add() won't
fail and type_name cannot be NULL.
>
> > + return child;
> > +
> > + return find_flex_array(child);
> > +}
> [ ... ]
> > @@ -1740,6 +1784,7 @@ struct annotated_data_type *find_data_type(struct data_loc_info *dloc)
> [ ... ]
> > - return dso__findnew_data_type(dso, &type_die);
> > + result = dso__findnew_data_type(dso, &type_die);
> > + if (result == NULL)
> > + return NULL;
> > +
> > + if (result->flex_array && dloc->type_offset > result->self.size) {
>
> [Severity: Medium]
> Does this condition skip elements located in the tail padding of the struct?
>
> By checking that dloc->type_offset > result->self.size, the offset adjustment
> is skipped if the flexible array element being accessed has an offset less
> than or equal to the total padded size of the parent struct.
>
> The unadjusted offset fails to match children in fill_member_name(),
> erroneously falling back to the last member during offline perf data analysis.
As I said in the previous version, I think it's ok and it'll find the
member when the offset is less than the total size.
Thanks,
Namhyung
>
> > + struct annotated_member *flex_array = get_flex_array_member(result);
> > +
> > + if (flex_array && flex_array->size > 0) {
> > + int offset = dloc->type_offset;
> > +
> > + /* adjust offset in the flex array */
> > + offset -= flex_array->offset;
> > + offset %= flex_array->size;
> > + offset += flex_array->offset;
> > +
> > + dloc->type_offset = offset;
> > + }
> > + }
> > + return result;
> > }
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260915064035.1970175-1-namhyung@kernel.org?part=3
^ permalink raw reply [flat|nested] 10+ messages in thread