Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Leo Yan" <leo.yan@arm.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v2 05/14] perf cs-etm: Use the recorded instruction size for A32 and A64
Date: Wed, 23 Sep 2026 16:01:30 +0000	[thread overview]
Message-ID: <20260923160131.149001F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923-perf_cs_etm_fix_non_taken-v2-5-6ab8c07a5455@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf cs-etm: Missing bounds check on instruction size in cs_etm__copy_insn()
--

commit 8ca3f124dea0462e31844bee55fa404297bf8a53
Author: Leo Yan <leo.yan@arm.com>

perf cs-etm: Use the recorded instruction size for A32 and A64

Use packet->last_instr_size in cs_etm__instr_size() instead of a
hard-coded value, allowing the decoder to supply the instruction size.

> diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
> index 2d1ab34f7b6b5..0163d93ac2d53 100644
> --- a/tools/perf/util/cs-etm.c
> +++ b/tools/perf/util/cs-etm.c
> @@ -1358,8 +1358,7 @@ static inline int cs_etm__instr_size(struct cs_etm_queue *etmq,
>  	if (packet->isa == CS_ETM_ISA_T32)
>  		return cs_etm__t32_instr_size(etmq, tidq, packet, addr);
>  
> -	/* Otherwise, 4-byte instruction size for A32/A64 */
> -	return 4;
> +	return packet->last_instr_size;

[Severity: High]
Can an untrusted decoder-supplied size cause this regression to overflow
sample->insn[]?

When cs_etm__instr_size() returns packet->last_instr_size without validation,
it is assigned to sample->insn_len in cs_etm__copy_insn().

This unbounded size is then passed to cs_etm__frontend_mem_access() as the
read length, which writes into the sample->insn[] array:

tools/perf/util/cs-etm.c:cs_etm__copy_insn() {
...
	sample->insn_len = cs_etm__instr_size(etmq, tidq, packet, sample->ip);

	cs_etm__frontend_mem_access(etmq, tidq, packet, sample->ip,
				    sample->insn_len, (void *)sample->insn);
...
}

Because sample->insn[] is defined as a fixed size array (char insn[MAX_INSN])
within struct perf_sample, processing an untrusted or maliciously crafted
perf.data file where packet->last_instr_size exceeds MAX_INSN might cause an
out-of-bounds write on the stack.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-perf_cs_etm_fix_non_taken-v2-0-6ab8c07a5455@arm.com?part=5

  reply	other threads:[~2026-09-23 16:01 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 15:21 [PATCH v2 00/14] perf cs-etm: Fix bogus branch samples on exceptions Leo Yan
2026-09-23 15:21 ` [PATCH v2 01/14] perf sample: Allow decoders to supply branch return addresses Leo Yan
2026-09-23 15:29   ` sashiko-bot
2026-09-24 13:00   ` Adrian Hunter
2026-09-23 15:21 ` [PATCH v2 02/14] perf intel-pt: Preserve return addresses for asynchronous branches Leo Yan
2026-09-23 15:43   ` sashiko-bot
2026-09-24 13:00   ` Adrian Hunter
2026-09-23 15:21 ` [PATCH v2 03/14] perf cs-etm: Break branch history when instruction memory is unavailable Leo Yan
2026-09-23 15:46   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 04/14] perf cs-etm: Centralize packet ISA initialization Leo Yan
2026-09-23 15:50   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 05/14] perf cs-etm: Use the recorded instruction size for A32 and A64 Leo Yan
2026-09-23 16:01   ` sashiko-bot [this message]
2026-09-29 13:55   ` James Clark
2026-09-23 15:21 ` [PATCH v2 06/14] perf cs-etm: Mark branches that were not taken Leo Yan
2026-09-23 16:09   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 07/14] perf cs-etm: Factor out final instruction sample synthesis Leo Yan
2026-09-23 16:13   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 08/14] perf cs-etm: Centralize branch sample synthesis checks Leo Yan
2026-09-23 16:18   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 09/14] perf cs-etm: Classify exception calls using the exception packet Leo Yan
2026-09-23 16:24   ` sashiko-bot
2026-09-29 14:08   ` James Clark
2026-09-23 15:21 ` [PATCH v2 10/14] perf cs-etm: Synthesize exception entries separately from branches Leo Yan
2026-09-23 16:36   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 11/14] perf tests: Check CoreSight IRQ entry and exit Leo Yan
2026-09-23 16:40   ` sashiko-bot
2026-09-29 12:22   ` James Clark
2026-09-23 15:21 ` [PATCH v2 12/14] perf tests: Check CoreSight syscall " Leo Yan
2026-09-23 16:46   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 13/14] perf tests: Check CoreSight abort " Leo Yan
2026-09-23 16:49   ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 14/14] perf tests: Check CoreSight emulated instruction " Leo Yan
2026-09-23 16:56   ` sashiko-bot
2026-09-29 14:41 ` [PATCH v2 00/14] perf cs-etm: Fix bogus branch samples on exceptions James Clark

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923160131.149001F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=leo.yan@arm.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox