Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Tengda Wu" <wutengda@huaweicloud.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v6 16/26] perf annotate-arm64: Support load instruction tracking
Date: Wed, 16 Sep 2026 01:51:46 +0000	[thread overview]
Message-ID: <20260916015146.B53C01F000FF@smtp.kernel.org> (raw)
In-Reply-To: <f95afe942520e925f209a2cd20c5f55d28c272b9.1789521520.git.wutengda@huaweicloud.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] perf annotate: stale lifetime metadata retained on load
- [Medium] perf annotate: incorrect type propagation for TSR_KIND_POINTER loads
--

commit 9763211f6135d1b6c3e44acf4ac681c34ac60395
Author: Tengda Wu <wutengda@huaweicloud.com>

perf annotate-arm64: Support load instruction tracking
    
Extend update_insn_state_arm64() to handle load instructions, tracking
register state changes when data is loaded from memory to registers.

> diff --git a/tools/perf/util/annotate-arch/annotate-arm64.c b/tools/perf/util/annotate-arch/annotate-arm64.c
> index d3d994a22cf92..11b2bdceaacb1 100644
> --- a/tools/perf/util/annotate-arch/annotate-arm64.c
> +++ b/tools/perf/util/annotate-arch/annotate-arm64.c

[ ... ]

> @@ -461,11 +461,210 @@ static bool is_readonly_branch_or_cmp(const char *name)
> +static int propagate_load_reg_state(struct type_state *state,
> +				    struct data_loc_info *dloc,
> +				    struct disasm_line *dl, int dreg,
> +				    struct annotated_op_loc *src,
> +				    struct type_state_reg **src_states,
> +				    int mem_spacing)
> +{
> +	struct type_state_reg *tsr;
> +	struct type_state_reg *src_tsr = src_states[0];
> +	Dwarf_Die type_die;
> +	u32 insn_offset = dl->al.offset;
> +	int sreg = src->reg1;
> +	int reg_offset;
> +
> +	if (!has_reg_type(state, dreg))
> +		return -1;
> +
> +	tsr = &state->regs[dreg];
> +	tsr->copied_from = -1;
> +
> +retry:
> +	if (arch_get_reg_offset(dloc->arch, src, sreg, state, false, &reg_offset))

[Severity: Medium]
When acquiring the destination register state here, shouldn't the lifetime
metadata be cleared (e.g., via tsr->lifetime_active = false;)?

If the register previously held a variable with an active DWARF lifetime, the
newly loaded value inherits this stale lifetime. During function calls,
caller-saved registers with active lifetimes are preserved rather than
invalidated. This causes the register's new type to incorrectly survive the
call, leading to stale type tracking downstream.

> +		goto load_non_regoff;
> +
> +	reg_offset += mem_spacing;

[ ... ]

> +	/* Handle dereference of TSR_KIND_POINTER registers */
> +	if (src_tsr->kind == TSR_KIND_POINTER &&
> +	    die_get_member_type(&src_tsr->type,
> +				src_tsr->offset + reg_offset, &type_die)) {
> +		tsr->type = src_tsr->type;
> +		tsr->kind = TSR_KIND_TYPE;
> +		tsr->offset = src_tsr->offset + reg_offset;
> +		tsr->imm_value = 0;
> +		tsr->ok = true;

[Severity: Medium]
Does this incorrectly assign the parent struct's type (src_tsr->type) instead
of the member's type (type_die), corrupting type tracking for the loaded
value?

If the destination register is subsequently used as a base address,
check_matching_type() will fail because it expects a TSR_KIND_TYPE register
to hold a pointer type, whereas it now holds a struct type. This breaks
downstream type inference for the loaded value.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1789521520.git.wutengda@huaweicloud.com?part=16

  reply	other threads:[~2026-09-16  1:51 UTC|newest]

Thread overview: 70+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-16  1:29 [PATCH v6 00/26] perf arm64: Support data type profiling Tengda Wu
2026-09-16  1:29 ` [PATCH v6 01/26] perf capstone: Symbolize address operands to match objdump on arm64 Tengda Wu
2026-09-16  1:37   ` sashiko-bot
2026-09-19  7:03   ` Namhyung Kim
2026-09-16  1:29 ` [PATCH v6 02/26] perf llvm: Fix arm64 adrp instruction disassembly mismatch with objdump Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  2:51     ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 03/26] perf annotate-arm64: Generalize arm64_mov__parse to support more instructions Tengda Wu
2026-09-16  1:39   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 04/26] perf annotate-arm64: Handle load and store instructions Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 05/26] perf annotate: Normalize arch__dwarf_regnum() error return values Tengda Wu
2026-09-16  1:39   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 06/26] perf annotate: Introduce extract_op_location callback for arch-specific parsing Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 07/26] perf dwarf-regs: Adapt get_dwarf_regnum() for arm64 Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  2:05     ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 08/26] perf annotate: Adapt arch__dwarf_regnum() " Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 09/26] perf annotate-arm64: Implement extract_op_location() callback Tengda Wu
2026-09-16  1:38   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 10/26] perf annotate: Default to --itrace=i1i for data type profiling Tengda Wu
2026-09-16  1:40   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 11/26] perf arm-spe: Set default synthesized event period to 1 Tengda Wu
2026-09-16  1:38   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 12/26] perf annotate-data: Extract invalidate_reg_state() as a common helper Tengda Wu
2026-09-16  1:37   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 13/26] perf annotate-arm64: Enable instruction tracking support Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 14/26] perf annotate-data: Add arch_get_reg_offset helper Tengda Wu
2026-09-16  1:39   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 15/26] perf annotate-arm64: Track return type after call instructions Tengda Wu
2026-09-16  1:37   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 16/26] perf annotate-arm64: Support load instruction tracking Tengda Wu
2026-09-16  1:51   ` sashiko-bot [this message]
2026-09-16 11:31     ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 17/26] perf annotate-arm64: Support store " Tengda Wu
2026-09-16  1:41   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 18/26] perf annotate-data: Expand type_state_reg imm_value to u64 Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 19/26] perf annotate-data: Track imm_value for stack variables Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 20/26] perf annotate-x86: Delete stale stack state on store of untracked register Tengda Wu
2026-09-16  1:43   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 21/26] perf annotate-arm64: Support stack variable tracking Tengda Wu
2026-09-16  1:49   ` sashiko-bot
2026-09-16 11:55     ` Tengda Wu
2026-09-20  1:43       ` Tengda Wu
2026-09-16  1:29 ` [PATCH v6 22/26] perf annotate-arm64: Support 'mov' instruction tracking Tengda Wu
2026-09-16  1:45   ` sashiko-bot
2026-09-16  1:29 ` [PATCH v6 23/26] perf annotate-arm64: Support 'add' " Tengda Wu
2026-09-16  1:44   ` sashiko-bot
2026-09-16  1:30 ` [PATCH v6 24/26] perf annotate-arm64: Support 'adrp' instruction to track global variables Tengda Wu
2026-09-16  1:48   ` sashiko-bot
2026-09-16  1:30 ` [PATCH v6 25/26] perf annotate-arm64: Support per-cpu variable access tracking Tengda Wu
2026-09-16  1:53   ` sashiko-bot
2026-09-17  2:16     ` Tengda Wu
2026-09-20  1:45       ` Tengda Wu
2026-09-20  1:52   ` Tengda Wu
2026-09-16  1:30 ` [PATCH v6 26/26] perf annotate-arm64: Support 'mrs' instruction to track 'current' pointer Tengda Wu
2026-09-16  1:52   ` sashiko-bot
2026-09-16  4:17 ` [PATCH v6 00/26] perf arm64: Support data type profiling Ian Rogers
2026-09-16 11:36   ` Tengda Wu
2026-09-19  7:10 ` Namhyung Kim
2026-09-19 11:22   ` Arnaldo Melo
2026-09-19 17:41     ` Namhyung Kim
2026-09-20  2:02   ` Tengda Wu
2026-09-21  6:47     ` Arnaldo Carvalho de Melo
2026-09-21  7:08       ` Tengda Wu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260916015146.B53C01F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wutengda@huaweicloud.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox