Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v1] perf machine: Add session back pointer to fix out of bounds read
Date: Fri, 18 Sep 2026 06:36:19 +0000	[thread overview]
Message-ID: <20260918063619.78B051F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260918062620.2145220-1-irogers@google.com>

> thread__e_machine_endian() decides whether a thread is live, and so
> whether to read /proc/pid/exe rather than fall back to the perf.data
> environment, by recovering the session from the machine:
> 
> 	session = container_of(machine->machines, struct perf_session,
> 			       machines);
> 	is_live = !session->data;
> 
> That only holds when the struct machines is the one embedded in a struct
> perf_session. It is not the only one. aslr_tool keeps its own in struct
> aslr_tool, and hists_cumulate, hists_filter, hists_link, hists_output
> and thread-maps-share each put one on the stack. For those the
> container_of subtracts offsetof(struct perf_session, machines) from an
> address that was never inside a session, and the following load of
> session->data reads outside the object, which is what ASan reports.
> 
> Replace the derivation with an explicit link. machines__init() takes the
> owning session, or NULL when the machines is standalone, and
> thread__e_machine_endian() reads it back through machines__session().
> 
> A NULL session is treated as live. The tests use synthetic pids that
> have no /proc entry, so the read fails there and the e_machine falls
> back to EM_HOST as before, rather than being decided by whatever the
> out of bounds read happened to return. perf inject registers its
> session with the aslr tool once the session exists, before any event is
> processed, so that tool keeps reporting file based threads as not live.
> 
> Fixes: 70351029b556 ("perf thread: Add support for reading the e_machine type for a thread")
> Assisted-by: Antigravity:gemini-3.1-pro
> Signed-off-by: Ian Rogers <irogers@google.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918062620.2145220-1-irogers@google.com?part=1


  reply	other threads:[~2026-09-18  6:36 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18  6:26 [PATCH v1] perf machine: Add session back pointer to fix out of bounds read Ian Rogers
2026-09-18  6:36 ` sashiko-bot [this message]
2026-09-25 12:09 ` Arnaldo Carvalho de Melo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918063619.78B051F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=irogers@google.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox