From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v1 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events
Date: Tue, 29 Sep 2026 02:38:23 +0000 [thread overview]
Message-ID: <20260929023824.25F431F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260929021913.56010-2-irogers@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] perf evsel: Incorrect PERF_RECORD_TEXT_POKE payload size calculation
--
commit fc6474e9b3305fb280e04ce2b30b2a815e2f3a7e
Author: Ian Rogers <irogers@google.com>
perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events
This commit adds evsel__event_size() to clamp the effective size used to
locate the trailing id_sample for specific events. This prevents user-space
tools from reading uninitialized memory when processing data from unpatched
kernels.
Link: https://lore.kernel.org/r/20260929014206.4175245-1-irogers@google.com
> diff --git a/tools/perf/util/evsel.c b/tools/perf/util/evsel.c
> index 3367242c57640..70da6be798cca 100644
> --- a/tools/perf/util/evsel.c
> +++ b/tools/perf/util/evsel.c
[ ... ]
> @@ -3966,6 +3966,63 @@ u16 evsel__id_hdr_size(const struct evsel *evsel)
> return size;
> }
>
> +/*
> + * Prior to kernel fix, perf_event_ksymbol_output(), perf_event_bpf_output(),
[ ... ]
> + case PERF_RECORD_TEXT_POKE: {
> + size_t fixed = offsetof(struct perf_record_text_poke_event, bytes);
> +
> + if (size < fixed)
> + return size;
> + payload = fixed + PERF_ALIGN((size_t)event->text_poke.old_len +
> + event->text_poke.new_len, sizeof(u64));
[Severity: Medium]
Does this misapply the 8-byte alignment only to the variable lengths rather
than the entire structure?
The kernel generates PERF_RECORD_TEXT_POKE events by padding the entire
event size to an 8-byte boundary. The payload size before id_sample is
16 + ALIGN(old_len + new_len + 4, 8).
This calculates the user-space payload as
fixed + PERF_ALIGN(old_len + new_len, 8), where fixed = 20. Because 20 is
not a multiple of 8, adding it outside the alignment yields a mathematically
incorrect size.
For example, if old_len = 1 and new_len = 1, the kernel calculates 24 bytes,
but the code here calculates 28 bytes. Calculating the wrong payload size
causes perf to index incorrectly into event->sample.array, leading to parsing
failures or out-of-bounds accesses.
> + break;
> + }
> + default:
> + return size;
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929021913.56010-1-irogers@google.com?part=1
next prev parent reply other threads:[~2026-09-29 2:38 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 2:19 [PATCH v1 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29 2:19 ` [PATCH v1 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29 2:38 ` sashiko-bot [this message]
2026-09-29 2:19 ` [PATCH v1 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29 2:30 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29 2:25 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29 2:24 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29 2:25 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29 2:26 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29 2:24 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29 2:24 ` sashiko-bot
2026-09-29 2:19 ` [PATCH v1 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29 2:27 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29 6:29 ` [PATCH v2 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29 6:41 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29 6:37 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29 6:37 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29 6:35 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29 6:34 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29 6:35 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29 6:37 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29 6:37 ` sashiko-bot
2026-09-29 6:29 ` [PATCH v2 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29 6:38 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29 6:58 ` [PATCH v3 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29 7:08 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29 7:06 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29 7:04 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29 7:03 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29 7:04 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29 7:04 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29 7:05 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29 7:04 ` sashiko-bot
2026-09-29 6:58 ` [PATCH v3 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29 7:06 ` sashiko-bot
2026-09-29 18:44 ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Arnaldo Carvalho de Melo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929023824.25F431F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=irogers@google.com \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox