Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Alireza Haghdoost" <haghdoost@uber.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v3 5/6] perf script: Add --lazy-load-symbols for lazy symbol loading
Date: Fri, 25 Sep 2026 19:27:20 +0000	[thread overview]
Message-ID: <20260925192721.5BBFC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925-perf-symbol-memory-send-v3-5-3e4e234c363b@uber.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf: heap buffer overflow in dso__build_ondemand_index via concurrent ELF modification
--

commit d40c3742b741bb2166cbf2426b72bf61c6192a01
Author: Alireza Haghdoost <haghdoost@uber.com>

perf script: Add --lazy-load-symbols for lazy symbol loading

This commit adds the --lazy-load-symbols option to perf script to lazily load
eligible symbols from userspace ELF DSOs. It builds a compact sorted index per
DSO, resolving sampled addresses via binary search and reading symbol names on
demand to reduce memory and time overhead.

> diff --git a/tools/perf/util/symbol-elf.c b/tools/perf/util/symbol-elf.c
> --- a/tools/perf/util/symbol-elf.c
> +++ b/tools/perf/util/symbol-elf.c
[ ... ]
> +static int dso__build_ondemand_index(struct dso *dso, struct symsrc *syms_ss,
> +				     struct symsrc *runtime_ss,
> +				     int dynsym)
> +{
[ ... ]
> +	for (i = 0; i < nr_entries; i++) {
> +		if (!gelf_getsym(syms, i, &sym))
> +			continue;
> +		if (ondemand_sym_ok(elf, secstrs, &sym, shdr.sh_link,
> +				    ehdr.e_machine))
> +			count++;
> +	}
> +
> +	if (!count)
> +		return 0;
> +	if (check_mul_overflow((size_t)count, sizeof(*od->sorted),
> +			       &index_bytes))
> +		return -EOVERFLOW;
[ ... ]
> +	od->sorted = zalloc(index_bytes);
> +	if (!od->sorted) {
> +		symbol__unaccount_bytes(index_bytes);
> +		free(od);
> +		return -1;
> +	}
> +	od->nr_alloc = count;
> +	name_offsets = malloc(count * sizeof(*name_offsets));
> +	if (!name_offsets) {
> +		symbol__unaccount_bytes(index_bytes);
> +		free(od->sorted);
> +		free(od);
> +		return -1;
> +	}
> +
> +	j = 0;
> +	for (i = 0; i < nr_entries; i++) {
> +		u64 adjusted;
> +		GElf_Phdr phdr;
> +
> +		if (!gelf_getsym(syms, i, &sym))
> +			continue;
> +		if (!ondemand_sym_ok(elf, secstrs, &sym, shdr.sh_link,
> +				     ehdr.e_machine))
> +			continue;
[ ... ]
> +		od->sorted[j].start = adjusted;
> +		od->sorted[j].end = sym.st_size;
> +		name_offsets[j] = sym.st_name;
> +		od->sorted[j].name_off = j;
> +		od->sorted[j].binding = GELF_ST_BIND(sym.st_info);
> +		od->sorted[j].type = GELF_ST_TYPE(sym.st_info);
> +		j++;
> +	}

[Severity: High]
Does this code have a bounds checking issue if the ELF file is modified
concurrently?

The algorithm in dso__build_ondemand_index() performs a two-pass scan on the
ELF file mapped into memory by libelf. The first pass computes the count of
valid symbols and allocates the od->sorted and name_offsets arrays based on
that exact count.

If the underlying ELF file (e.g. symbol table or string table) is modified
while this process is running, the memory-mapped data can change between the
two passes. This could cause the second pass to encounter more valid symbols
than originally counted, resulting in j exceeding count (or od->nr_alloc)
without any bounds checking.

Could this result in a heap buffer overflow when writing to od->sorted[j] and
name_offsets[j] if an administrator analyzes a dynamically modified,
user-writable ELF binary?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925-perf-symbol-memory-send-v3-0-3e4e234c363b@uber.com?part=5

  reply	other threads:[~2026-09-25 19:27 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 19:09 [PATCH v3 0/6] perf script: Bounded and lazy symbol loading Alireza Haghdoost via B4 Relay
2026-09-25 19:09 ` [PATCH v3 1/6] perf symbols: Fix broken ELF_C_READ_MMAP fallback guard Alireza Haghdoost via B4 Relay
2026-09-25 19:21   ` sashiko-bot
2026-09-25 19:09 ` [PATCH v3 2/6] perf dso: Allow reading DSO data from an explicit file Alireza Haghdoost via B4 Relay
2026-09-25 19:26   ` sashiko-bot
2026-09-25 19:09 ` [PATCH v3 3/6] perf symbols: Factor out duplicate symbol selection Alireza Haghdoost via B4 Relay
2026-09-25 19:21   ` sashiko-bot
2026-09-25 19:40   ` Ian Rogers
2026-09-25 19:55     ` Alireza Haghdoost
2026-09-25 20:21       ` Ian Rogers
2026-09-25 19:09 ` [PATCH v3 4/6] perf script: Add --max-symbol-bytes to bound ELF symbol memory Alireza Haghdoost via B4 Relay
2026-09-25 19:26   ` sashiko-bot
2026-09-25 19:09 ` [PATCH v3 5/6] perf script: Add --lazy-load-symbols for lazy symbol loading Alireza Haghdoost via B4 Relay
2026-09-25 19:27   ` sashiko-bot [this message]
2026-09-25 19:09 ` [PATCH v3 6/6] perf test: Test lazy symbol loading and symbol memory limits Alireza Haghdoost via B4 Relay
2026-09-25 19:26   ` sashiko-bot
2026-09-25 20:20 ` [PATCH v3 0/6] perf script: Bounded and lazy symbol loading Ian Rogers
2026-09-25 21:28   ` Alireza Haghdoost
2026-09-25 21:55     ` Ian Rogers
2026-09-30 19:58       ` Alireza Haghdoost
2026-09-30 21:18         ` Ian Rogers

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925192721.5BBFC1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=haghdoost@uber.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox