Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Aaron Tomlin" <atomlin@atomlin.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v3 perf-tools-next 1/7] perf trace: Add upper bound checks for augmented BTF struct printing
Date: Sat, 19 Sep 2026 01:07:08 +0000	[thread overview]
Message-ID: <20260919010708.82BEC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260919005530.728615-2-atomlin@atomlin.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] perf trace: btf_struct_scnprintf() fails to consume short payloads
--

commit ff5721b95fd4d48862773d326029922c1b94fdc7
Author: Aaron Tomlin <atomlin@atomlin.com>

perf trace: Add upper bound checks for augmented BTF struct printing

This commit adds upper bound checks for augmented_arg->size against the
remaining buffer size. It prevents buffer over-reads and integer
overflows when pretty-printing augmented struct payloads using BTF.

> diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
> --- a/tools/perf/builtin-trace.c
> +++ b/tools/perf/builtin-trace.c

[ ... ]

> @@ -1133,12 +1133,13 @@ static size_t btf_struct_scnprintf(const struct btf_type *type, struct btf *btf,
>  	LIBBPF_OPTS(btf_dump_opts, dump_opts);
>  	LIBBPF_OPTS(btf_dump_type_data_opts, dump_data_opts);
>  
> -	if (arg == NULL || arg->augmented.args == NULL || arg->augmented.size <= 0 ||
> +	if (arg == NULL || arg->augmented.args == NULL || arg->augmented.size < (int)sizeof(*augmented_arg) ||
>  	    arg->fmt == NULL || !arg->fmt->from_user)
>  		return 0;
>  
>  	augmented_arg = arg->augmented.args;
> -	if (augmented_arg->size <= 0)
> +	if (augmented_arg->size <= 0 || augmented_arg->size > arg->augmented.size - (int)sizeof(*augmented_arg) ||
> +	    (size_t)augmented_arg->size < type->size)
>  		return 0;

[Severity: Medium]
Does this early return fail to consume the short payload?

By returning 0 here when the augmented payload is smaller than type->size, it
appears the parser abandons the payload without updating arg->augmented.args.

When the next syscall argument is formatted, will it read this stale struct
payload as its own augmented data, corrupting the parsing state for all
subsequent arguments?

Since short reads can occur legitimately during BPF tracing when capturing
large structs, should this gracefully advance past the short payload rather
than abandoning the update entirely?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919005530.728615-1-atomlin@atomlin.com?part=1

  reply	other threads:[~2026-09-19  1:07 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19  0:55 [PATCH v3 perf-tools-next 0/7] perf trace: Validate payload bounds across augmented argument beautifiers Aaron Tomlin
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 1/7] perf trace: Add upper bound checks for augmented BTF struct printing Aaron Tomlin
2026-09-19  1:07   ` sashiko-bot [this message]
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 2/7] perf trace: Validate payload bounds in augmented string beautifier Aaron Tomlin
2026-09-19  1:08   ` sashiko-bot
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 3/7] perf trace: Align pointer advance " Aaron Tomlin
2026-09-19  1:08   ` sashiko-bot
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 4/7] perf trace: Validate payload bounds in augmented buffer beautifier Aaron Tomlin
2026-09-19  1:09   ` sashiko-bot
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 5/7] perf trace beauty: Validate payload size in augmented timespec beautifier Aaron Tomlin
2026-09-19  1:08   ` sashiko-bot
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 6/7] perf trace beauty: Validate payload size in augmented sockaddr beautifier Aaron Tomlin
2026-09-19  1:05   ` sashiko-bot
2026-09-19  0:55 ` [PATCH v3 perf-tools-next 7/7] perf trace beauty: Validate payload size in augmented perf_event_open beautifier Aaron Tomlin
2026-09-19  1:04   ` sashiko-bot
2026-09-30 18:29 ` [PATCH v3 perf-tools-next 0/7] perf trace: Validate payload bounds across augmented argument beautifiers Aaron Tomlin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260919010708.82BEC1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=atomlin@atomlin.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox