From: sashiko-bot@kernel.org
To: "Tengda Wu" <wutengda@huaweicloud.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v6 16/26] perf annotate-arm64: Support load instruction tracking
Date: Wed, 16 Sep 2026 01:51:46 +0000 [thread overview]
Message-ID: <20260916015146.B53C01F000FF@smtp.kernel.org> (raw)
In-Reply-To: <f95afe942520e925f209a2cd20c5f55d28c272b9.1789521520.git.wutengda@huaweicloud.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] perf annotate: stale lifetime metadata retained on load
- [Medium] perf annotate: incorrect type propagation for TSR_KIND_POINTER loads
--
commit 9763211f6135d1b6c3e44acf4ac681c34ac60395
Author: Tengda Wu <wutengda@huaweicloud.com>
perf annotate-arm64: Support load instruction tracking
Extend update_insn_state_arm64() to handle load instructions, tracking
register state changes when data is loaded from memory to registers.
> diff --git a/tools/perf/util/annotate-arch/annotate-arm64.c b/tools/perf/util/annotate-arch/annotate-arm64.c
> index d3d994a22cf92..11b2bdceaacb1 100644
> --- a/tools/perf/util/annotate-arch/annotate-arm64.c
> +++ b/tools/perf/util/annotate-arch/annotate-arm64.c
[ ... ]
> @@ -461,11 +461,210 @@ static bool is_readonly_branch_or_cmp(const char *name)
> +static int propagate_load_reg_state(struct type_state *state,
> + struct data_loc_info *dloc,
> + struct disasm_line *dl, int dreg,
> + struct annotated_op_loc *src,
> + struct type_state_reg **src_states,
> + int mem_spacing)
> +{
> + struct type_state_reg *tsr;
> + struct type_state_reg *src_tsr = src_states[0];
> + Dwarf_Die type_die;
> + u32 insn_offset = dl->al.offset;
> + int sreg = src->reg1;
> + int reg_offset;
> +
> + if (!has_reg_type(state, dreg))
> + return -1;
> +
> + tsr = &state->regs[dreg];
> + tsr->copied_from = -1;
> +
> +retry:
> + if (arch_get_reg_offset(dloc->arch, src, sreg, state, false, ®_offset))
[Severity: Medium]
When acquiring the destination register state here, shouldn't the lifetime
metadata be cleared (e.g., via tsr->lifetime_active = false;)?
If the register previously held a variable with an active DWARF lifetime, the
newly loaded value inherits this stale lifetime. During function calls,
caller-saved registers with active lifetimes are preserved rather than
invalidated. This causes the register's new type to incorrectly survive the
call, leading to stale type tracking downstream.
> + goto load_non_regoff;
> +
> + reg_offset += mem_spacing;
[ ... ]
> + /* Handle dereference of TSR_KIND_POINTER registers */
> + if (src_tsr->kind == TSR_KIND_POINTER &&
> + die_get_member_type(&src_tsr->type,
> + src_tsr->offset + reg_offset, &type_die)) {
> + tsr->type = src_tsr->type;
> + tsr->kind = TSR_KIND_TYPE;
> + tsr->offset = src_tsr->offset + reg_offset;
> + tsr->imm_value = 0;
> + tsr->ok = true;
[Severity: Medium]
Does this incorrectly assign the parent struct's type (src_tsr->type) instead
of the member's type (type_die), corrupting type tracking for the loaded
value?
If the destination register is subsequently used as a base address,
check_matching_type() will fail because it expects a TSR_KIND_TYPE register
to hold a pointer type, whereas it now holds a struct type. This breaks
downstream type inference for the loaded value.
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1789521520.git.wutengda@huaweicloud.com?part=16
next prev parent reply other threads:[~2026-09-16 1:51 UTC|newest]
Thread overview: 70+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 1:29 [PATCH v6 00/26] perf arm64: Support data type profiling Tengda Wu
2026-09-16 1:29 ` [PATCH v6 01/26] perf capstone: Symbolize address operands to match objdump on arm64 Tengda Wu
2026-09-16 1:37 ` sashiko-bot
2026-09-19 7:03 ` Namhyung Kim
2026-09-16 1:29 ` [PATCH v6 02/26] perf llvm: Fix arm64 adrp instruction disassembly mismatch with objdump Tengda Wu
2026-09-16 1:43 ` sashiko-bot
2026-09-16 2:51 ` Tengda Wu
2026-09-16 1:29 ` [PATCH v6 03/26] perf annotate-arm64: Generalize arm64_mov__parse to support more instructions Tengda Wu
2026-09-16 1:39 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 04/26] perf annotate-arm64: Handle load and store instructions Tengda Wu
2026-09-16 1:43 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 05/26] perf annotate: Normalize arch__dwarf_regnum() error return values Tengda Wu
2026-09-16 1:39 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 06/26] perf annotate: Introduce extract_op_location callback for arch-specific parsing Tengda Wu
2026-09-16 1:44 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 07/26] perf dwarf-regs: Adapt get_dwarf_regnum() for arm64 Tengda Wu
2026-09-16 1:43 ` sashiko-bot
2026-09-16 2:05 ` Tengda Wu
2026-09-16 1:29 ` [PATCH v6 08/26] perf annotate: Adapt arch__dwarf_regnum() " Tengda Wu
2026-09-16 1:43 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 09/26] perf annotate-arm64: Implement extract_op_location() callback Tengda Wu
2026-09-16 1:38 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 10/26] perf annotate: Default to --itrace=i1i for data type profiling Tengda Wu
2026-09-16 1:40 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 11/26] perf arm-spe: Set default synthesized event period to 1 Tengda Wu
2026-09-16 1:38 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 12/26] perf annotate-data: Extract invalidate_reg_state() as a common helper Tengda Wu
2026-09-16 1:37 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 13/26] perf annotate-arm64: Enable instruction tracking support Tengda Wu
2026-09-16 1:43 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 14/26] perf annotate-data: Add arch_get_reg_offset helper Tengda Wu
2026-09-16 1:39 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 15/26] perf annotate-arm64: Track return type after call instructions Tengda Wu
2026-09-16 1:37 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 16/26] perf annotate-arm64: Support load instruction tracking Tengda Wu
2026-09-16 1:51 ` sashiko-bot [this message]
2026-09-16 11:31 ` Tengda Wu
2026-09-16 1:29 ` [PATCH v6 17/26] perf annotate-arm64: Support store " Tengda Wu
2026-09-16 1:41 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 18/26] perf annotate-data: Expand type_state_reg imm_value to u64 Tengda Wu
2026-09-16 1:44 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 19/26] perf annotate-data: Track imm_value for stack variables Tengda Wu
2026-09-16 1:44 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 20/26] perf annotate-x86: Delete stale stack state on store of untracked register Tengda Wu
2026-09-16 1:43 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 21/26] perf annotate-arm64: Support stack variable tracking Tengda Wu
2026-09-16 1:49 ` sashiko-bot
2026-09-16 11:55 ` Tengda Wu
2026-09-20 1:43 ` Tengda Wu
2026-09-16 1:29 ` [PATCH v6 22/26] perf annotate-arm64: Support 'mov' instruction tracking Tengda Wu
2026-09-16 1:45 ` sashiko-bot
2026-09-16 1:29 ` [PATCH v6 23/26] perf annotate-arm64: Support 'add' " Tengda Wu
2026-09-16 1:44 ` sashiko-bot
2026-09-16 1:30 ` [PATCH v6 24/26] perf annotate-arm64: Support 'adrp' instruction to track global variables Tengda Wu
2026-09-16 1:48 ` sashiko-bot
2026-09-16 1:30 ` [PATCH v6 25/26] perf annotate-arm64: Support per-cpu variable access tracking Tengda Wu
2026-09-16 1:53 ` sashiko-bot
2026-09-17 2:16 ` Tengda Wu
2026-09-20 1:45 ` Tengda Wu
2026-09-20 1:52 ` Tengda Wu
2026-09-16 1:30 ` [PATCH v6 26/26] perf annotate-arm64: Support 'mrs' instruction to track 'current' pointer Tengda Wu
2026-09-16 1:52 ` sashiko-bot
2026-09-16 4:17 ` [PATCH v6 00/26] perf arm64: Support data type profiling Ian Rogers
2026-09-16 11:36 ` Tengda Wu
2026-09-19 7:10 ` Namhyung Kim
2026-09-19 11:22 ` Arnaldo Melo
2026-09-19 17:41 ` Namhyung Kim
2026-09-20 2:02 ` Tengda Wu
2026-09-21 6:47 ` Arnaldo Carvalho de Melo
2026-09-21 7:08 ` Tengda Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916015146.B53C01F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wutengda@huaweicloud.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox