Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Tengda Wu" <wutengda@huaweicloud.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v6 21/26] perf annotate-arm64: Support stack variable tracking
Date: Wed, 16 Sep 2026 01:49:05 +0000	[thread overview]
Message-ID: <20260916014905.D44C91F000FF@smtp.kernel.org> (raw)
In-Reply-To: <11bcde1a75d96b524cc5a7f6fa442025680e56a0.1789521520.git.wutengda@huaweicloud.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] perf: stale stack state due to bypassed invalidation in update_store_insn_state
--

commit 2ddb0f384d44eeb70844d8c3adc06f8d55101f68
Author: Tengda Wu <wutengda@huaweicloud.com>

perf annotate-arm64: Support stack variable tracking

Extend update_insn_state_arm64() to track data types stored on the stack. The
implementation handles stack loads and stores to follow data types as they
move between registers and memory.

> diff --git a/tools/perf/util/annotate-arch/annotate-arm64.c b/tools/perf/util/annotate-arch/annotate-arm64.c
> index a72c7703dd6b3..8339aab0d314f 100644
> --- a/tools/perf/util/annotate-arch/annotate-arm64.c
> +++ b/tools/perf/util/annotate-arch/annotate-arm64.c
[ ... ]
> +/*
> + * For store insns: propagate type from @sreg to the memory location referenced
> + * by @dst, applying @mem_spacing to account for multi-regs stores (e.g. stp).
> + */
> +static void propagate_store_reg_state(struct type_state *state,
> +				      struct data_loc_info *dloc,
> +				      struct disasm_line *dl, int sreg,
> +				      struct annotated_op_loc *dst,
> +				      int mem_spacing)
> +{
[ ... ]
> +		if (!has_reg_type(state, sreg) || !state->regs[sreg].ok) {
> +			stack = find_stack_state(state, offset);
> +			/* Preserve compound states when only a member is overwritten. */
> +			if (stack && !stack->compound)
> +				delete_stack_state(state, offset);
> +
> +			return;
> +		}
[ ... ]
> +static void update_store_insn_state(struct type_state *state,
> +				    struct data_loc_info *dloc,
> +				    struct disasm_line *dl,
> +				    struct annotated_op_loc *src,
> +				    struct annotated_op_loc *dst)
> +{
> +	int mem_spacing = 0;
> +
> +	if (!has_reg_type(state, dst->reg1))
> +		return;
> +
> +	/* Handle the first source register */
> +	if (has_reg_type(state, src->reg1))
> +		propagate_store_reg_state(state, dloc, dl, src->reg1,
> +					  dst, mem_spacing);
> +
> +	if (!src->multi_regs || !has_reg_type(state, src->reg2))
> +		goto out_adjust;

[Severity: Medium]
Does the has_reg_type() guard here inadvertently skip the stack state
invalidation logic?

Looking at propagate_store_reg_state() above, there is logic to delete the
stack state if the source register is untracked. However, because
update_store_insn_state() completely bypasses the call to
propagate_store_reg_state() when the source register is untracked, this
cleanup is never reached.

If an untracked register is stored into a stack slot previously used for a
tracked variable, could this leave stale tracking state on the stack, causing
subsequent loads from that slot to inherit the wrong type?

> +
> +	/* Handle the second source register */
> +	mem_spacing = arm64__reg_size(dl->ops.source.raw);
> +
> +	if (mem_spacing >= 0)
> +		propagate_store_reg_state(state, dloc, dl, src->reg2,
> +					  dst, mem_spacing);
> +
> +out_adjust:
> +	adjust_reg_index_state(state, dloc, dl, dst);
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1789521520.git.wutengda@huaweicloud.com?part=21

  reply	other threads:[~2026-09-16  1:49 UTC|newest]

Thread overview: 70+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-16  1:29 [PATCH v6 00/26] perf arm64: Support data type profiling Tengda Wu
2026-09-16  1:29 ` [PATCH v6 01/26] perf capstone: Symbolize address operands to match objdump on arm64 Tengda Wu
2026-09-16  1:37   ` sashiko-bot
2026-09-19  7:03   ` Namhyung Kim
2026-09-16  1:29 ` [PATCH v6 02/26] perf llvm: Fix arm64 adrp instruction disassembly mismatch with objdump Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  2:51     ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 03/26] perf annotate-arm64: Generalize arm64_mov__parse to support more instructions Tengda Wu
2026-09-16  1:39   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 04/26] perf annotate-arm64: Handle load and store instructions Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 05/26] perf annotate: Normalize arch__dwarf_regnum() error return values Tengda Wu
2026-09-16  1:39   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 06/26] perf annotate: Introduce extract_op_location callback for arch-specific parsing Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 07/26] perf dwarf-regs: Adapt get_dwarf_regnum() for arm64 Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  2:05     ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 08/26] perf annotate: Adapt arch__dwarf_regnum() " Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 09/26] perf annotate-arm64: Implement extract_op_location() callback Tengda Wu
2026-09-16  1:38   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 10/26] perf annotate: Default to --itrace=i1i for data type profiling Tengda Wu
2026-09-16  1:40   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 11/26] perf arm-spe: Set default synthesized event period to 1 Tengda Wu
2026-09-16  1:38   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 12/26] perf annotate-data: Extract invalidate_reg_state() as a common helper Tengda Wu
2026-09-16  1:37   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 13/26] perf annotate-arm64: Enable instruction tracking support Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 14/26] perf annotate-data: Add arch_get_reg_offset helper Tengda Wu
2026-09-16  1:39   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 15/26] perf annotate-arm64: Track return type after call instructions Tengda Wu
2026-09-16  1:37   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 16/26] perf annotate-arm64: Support load instruction tracking Tengda Wu
2026-09-16  1:51   ` sashiko-bot
2026-09-16 11:31     ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 17/26] perf annotate-arm64: Support store " Tengda Wu
2026-09-16  1:41   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 18/26] perf annotate-data: Expand type_state_reg imm_value to u64 Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 19/26] perf annotate-data: Track imm_value for stack variables Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 20/26] perf annotate-x86: Delete stale stack state on store of untracked register Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 21/26] perf annotate-arm64: Support stack variable tracking Tengda Wu
2026-09-16  1:49   ` sashiko-bot [this message]
2026-09-16 11:55     ` Tengda Wu
2026-09-20  1:43       ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 22/26] perf annotate-arm64: Support 'mov' instruction tracking Tengda Wu
2026-09-16  1:45   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 23/26] perf annotate-arm64: Support 'add' " Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:30 ` [PATCH v6 24/26] perf annotate-arm64: Support 'adrp' instruction to track global variables Tengda Wu
2026-09-16  1:48   ` sashiko-bot
2026-09-16  1:30 ` [PATCH v6 25/26] perf annotate-arm64: Support per-cpu variable access tracking Tengda Wu
2026-09-16  1:53   ` sashiko-bot
2026-09-17  2:16     ` Tengda Wu
2026-09-20  1:45       ` Tengda Wu
2026-09-20  1:52   ` Tengda Wu
2026-09-16  1:30 ` [PATCH v6 26/26] perf annotate-arm64: Support 'mrs' instruction to track 'current' pointer Tengda Wu
2026-09-16  1:52   ` sashiko-bot
2026-09-16  4:17 ` [PATCH v6 00/26] perf arm64: Support data type profiling Ian Rogers
2026-09-16 11:36   ` Tengda Wu
2026-09-19  7:10 ` Namhyung Kim
2026-09-19 11:22   ` Arnaldo Melo
2026-09-19 17:41     ` Namhyung Kim
2026-09-20  2:02   ` Tengda Wu
2026-09-21  6:47     ` Arnaldo Carvalho de Melo
2026-09-21  7:08       ` Tengda Wu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260916014905.D44C91F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wutengda@huaweicloud.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox