From: sashiko-bot@kernel.org
To: "Leo Yan" <leo.yan@arm.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v2 05/14] perf cs-etm: Use the recorded instruction size for A32 and A64
Date: Wed, 23 Sep 2026 16:01:30 +0000 [thread overview]
Message-ID: <20260923160131.149001F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923-perf_cs_etm_fix_non_taken-v2-5-6ab8c07a5455@arm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf cs-etm: Missing bounds check on instruction size in cs_etm__copy_insn()
--
commit 8ca3f124dea0462e31844bee55fa404297bf8a53
Author: Leo Yan <leo.yan@arm.com>
perf cs-etm: Use the recorded instruction size for A32 and A64
Use packet->last_instr_size in cs_etm__instr_size() instead of a
hard-coded value, allowing the decoder to supply the instruction size.
> diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
> index 2d1ab34f7b6b5..0163d93ac2d53 100644
> --- a/tools/perf/util/cs-etm.c
> +++ b/tools/perf/util/cs-etm.c
> @@ -1358,8 +1358,7 @@ static inline int cs_etm__instr_size(struct cs_etm_queue *etmq,
> if (packet->isa == CS_ETM_ISA_T32)
> return cs_etm__t32_instr_size(etmq, tidq, packet, addr);
>
> - /* Otherwise, 4-byte instruction size for A32/A64 */
> - return 4;
> + return packet->last_instr_size;
[Severity: High]
Can an untrusted decoder-supplied size cause this regression to overflow
sample->insn[]?
When cs_etm__instr_size() returns packet->last_instr_size without validation,
it is assigned to sample->insn_len in cs_etm__copy_insn().
This unbounded size is then passed to cs_etm__frontend_mem_access() as the
read length, which writes into the sample->insn[] array:
tools/perf/util/cs-etm.c:cs_etm__copy_insn() {
...
sample->insn_len = cs_etm__instr_size(etmq, tidq, packet, sample->ip);
cs_etm__frontend_mem_access(etmq, tidq, packet, sample->ip,
sample->insn_len, (void *)sample->insn);
...
}
Because sample->insn[] is defined as a fixed size array (char insn[MAX_INSN])
within struct perf_sample, processing an untrusted or maliciously crafted
perf.data file where packet->last_instr_size exceeds MAX_INSN might cause an
out-of-bounds write on the stack.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-perf_cs_etm_fix_non_taken-v2-0-6ab8c07a5455@arm.com?part=5
next prev parent reply other threads:[~2026-09-23 16:01 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 15:21 [PATCH v2 00/14] perf cs-etm: Fix bogus branch samples on exceptions Leo Yan
2026-09-23 15:21 ` [PATCH v2 01/14] perf sample: Allow decoders to supply branch return addresses Leo Yan
2026-09-23 15:29 ` sashiko-bot
2026-09-24 13:00 ` Adrian Hunter
2026-09-23 15:21 ` [PATCH v2 02/14] perf intel-pt: Preserve return addresses for asynchronous branches Leo Yan
2026-09-23 15:43 ` sashiko-bot
2026-09-24 13:00 ` Adrian Hunter
2026-09-23 15:21 ` [PATCH v2 03/14] perf cs-etm: Break branch history when instruction memory is unavailable Leo Yan
2026-09-23 15:46 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 04/14] perf cs-etm: Centralize packet ISA initialization Leo Yan
2026-09-23 15:50 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 05/14] perf cs-etm: Use the recorded instruction size for A32 and A64 Leo Yan
2026-09-23 16:01 ` sashiko-bot [this message]
2026-09-29 13:55 ` James Clark
2026-09-23 15:21 ` [PATCH v2 06/14] perf cs-etm: Mark branches that were not taken Leo Yan
2026-09-23 16:09 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 07/14] perf cs-etm: Factor out final instruction sample synthesis Leo Yan
2026-09-23 16:13 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 08/14] perf cs-etm: Centralize branch sample synthesis checks Leo Yan
2026-09-23 16:18 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 09/14] perf cs-etm: Classify exception calls using the exception packet Leo Yan
2026-09-23 16:24 ` sashiko-bot
2026-09-29 14:08 ` James Clark
2026-09-23 15:21 ` [PATCH v2 10/14] perf cs-etm: Synthesize exception entries separately from branches Leo Yan
2026-09-23 16:36 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 11/14] perf tests: Check CoreSight IRQ entry and exit Leo Yan
2026-09-23 16:40 ` sashiko-bot
2026-09-29 12:22 ` James Clark
2026-09-23 15:21 ` [PATCH v2 12/14] perf tests: Check CoreSight syscall " Leo Yan
2026-09-23 16:46 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 13/14] perf tests: Check CoreSight abort " Leo Yan
2026-09-23 16:49 ` sashiko-bot
2026-09-23 15:21 ` [PATCH v2 14/14] perf tests: Check CoreSight emulated instruction " Leo Yan
2026-09-23 16:56 ` sashiko-bot
2026-09-29 14:41 ` [PATCH v2 00/14] perf cs-etm: Fix bogus branch samples on exceptions James Clark
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923160131.149001F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=leo.yan@arm.com \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox