Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v1 5/9] perf test: Deflake failed-syscalls Python shell tests under load
Date: Tue, 29 Sep 2026 02:25:50 +0000	[thread overview]
Message-ID: <20260929022551.6B5811F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929021913.56010-6-irogers@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf test: TOCTOU symlink vulnerability via rm in /tmp
--

commit 2edcd77bcabafd7550e8af4c57dda0ca7cfe9278
Author: Ian Rogers <irogers@google.com>

perf test: Deflake failed-syscalls Python shell tests under load

This commit updates the failed-syscalls python shell tests to handle
heavy system load by adding a bounded retry loop and short sleep intervals.
It also explicitly passes the no-bpf-event flags to perf record to
prevent early exits during BPF event synthesis.

> diff --git a/tools/perf/tests/shell/test_failed_syscalls_python.sh b/tools/perf/tests/shell/test_failed_syscalls_python.sh
> index 861c2ba71c0a2..88a42e3de4f35 100755
> --- a/tools/perf/tests/shell/test_failed_syscalls_python.sh
> +++ b/tools/perf/tests/shell/test_failed_syscalls_python.sh

[ ... ]

> @@ -52,28 +54,38 @@ else
>  	EVENT="raw_syscalls:sys_exit"
>  fi
>  
> -# Run perf record with a command that fails a syscall (ls non-existent file).
> -# ls exits with non-zero, so perf record returns non-zero exit code of the workload.
> -perf record -e "${EVENT}" -o "${temp_data}" \
> -	-- ls /nonexistent_file_for_test >/dev/null 2>&1 || true
> +# Run perf record with a command that fails a syscall (ls non-existent file),
> +# sleeping briefly in the subshell so ls's PERF_RECORD_COMM and sys_exit events are flushed.
> +passed=0
> +for _ in 1 2 3 4 5; do
> +	rm -f "${temp_data}" "${temp_out}"

[Severity: High]
Does this rm command expose the script to a time-of-check to time-of-use
symlink vulnerability?

The files temp_data and temp_out are initially created securely in the
world-writable /tmp directory using mktemp. By explicitly deleting them
here in the retry loop, the filenames are freed.

During the window between this deletion and the subsequent shell
redirection, a local attacker observing /tmp could recreate these names
as symlinks. When the test redirects output or writes to them later, it
will follow the symlink and could overwrite arbitrary files on the
system. This could lead to local privilege escalation if the test is run
with elevated privileges.

> +	perf record -B -N --no-bpf-event -e "${EVENT}" -o "${temp_data}" \
> +		-- sh -c "ls /nonexistent_file_for_test 2>/dev/null; sleep 0.05 || true" \
> +		>/dev/null 2>&1 || true

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929021913.56010-1-irogers@google.com?part=5

  reply	other threads:[~2026-09-29  2:25 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  2:19 [PATCH v1 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29  2:19 ` [PATCH v1 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29  2:38   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29  2:30   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29  2:25   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29  2:24   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29  2:25   ` sashiko-bot [this message]
2026-09-29  2:19 ` [PATCH v1 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29  2:26   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29  2:24   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29  2:24   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29  2:27   ` sashiko-bot
2026-09-29  6:29 ` [PATCH v2 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29  6:29   ` [PATCH v2 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29  6:41     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29  6:35     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29  6:34     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29  6:35     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29  6:38     ` sashiko-bot
2026-09-29  6:58   ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29  6:58     ` [PATCH v3 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29  7:08       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29  7:06       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29  7:03       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29  7:05       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29  7:06       ` sashiko-bot
2026-09-29 18:44     ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Arnaldo Carvalho de Melo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929022551.6B5811F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=irogers@google.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox