Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v1 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events
Date: Tue, 29 Sep 2026 02:38:23 +0000	[thread overview]
Message-ID: <20260929023824.25F431F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260929021913.56010-2-irogers@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] perf evsel: Incorrect PERF_RECORD_TEXT_POKE payload size calculation
--

commit fc6474e9b3305fb280e04ce2b30b2a815e2f3a7e
Author: Ian Rogers <irogers@google.com>

perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events

This commit adds evsel__event_size() to clamp the effective size used to
locate the trailing id_sample for specific events. This prevents user-space
tools from reading uninitialized memory when processing data from unpatched
kernels.

Link: https://lore.kernel.org/r/20260929014206.4175245-1-irogers@google.com

> diff --git a/tools/perf/util/evsel.c b/tools/perf/util/evsel.c
> index 3367242c57640..70da6be798cca 100644
> --- a/tools/perf/util/evsel.c
> +++ b/tools/perf/util/evsel.c

[ ... ]

> @@ -3966,6 +3966,63 @@ u16 evsel__id_hdr_size(const struct evsel *evsel)
>  	return size;
>  }
>  
> +/*
> + * Prior to kernel fix, perf_event_ksymbol_output(), perf_event_bpf_output(),

[ ... ]

> +	case PERF_RECORD_TEXT_POKE: {
> +		size_t fixed = offsetof(struct perf_record_text_poke_event, bytes);
> +
> +		if (size < fixed)
> +			return size;
> +		payload = fixed + PERF_ALIGN((size_t)event->text_poke.old_len +
> +					     event->text_poke.new_len, sizeof(u64));

[Severity: Medium]
Does this misapply the 8-byte alignment only to the variable lengths rather
than the entire structure?

The kernel generates PERF_RECORD_TEXT_POKE events by padding the entire
event size to an 8-byte boundary. The payload size before id_sample is
16 + ALIGN(old_len + new_len + 4, 8).

This calculates the user-space payload as
fixed + PERF_ALIGN(old_len + new_len, 8), where fixed = 20. Because 20 is
not a multiple of 8, adding it outside the alignment yields a mathematically
incorrect size.

For example, if old_len = 1 and new_len = 1, the kernel calculates 24 bytes,
but the code here calculates 28 bytes. Calculating the wrong payload size
causes perf to index incorrectly into event->sample.array, leading to parsing
failures or out-of-bounds accesses.

> +		break;
> +	}
> +	default:
> +		return size;
> +	}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929021913.56010-1-irogers@google.com?part=1

  reply	other threads:[~2026-09-29  2:38 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  2:19 [PATCH v1 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29  2:19 ` [PATCH v1 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29  2:38   ` sashiko-bot [this message]
2026-09-29  2:19 ` [PATCH v1 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29  2:30   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29  2:25   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29  2:24   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29  2:25   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29  2:26   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29  2:24   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29  2:24   ` sashiko-bot
2026-09-29  2:19 ` [PATCH v1 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29  2:27   ` sashiko-bot
2026-09-29  6:29 ` [PATCH v2 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29  6:29   ` [PATCH v2 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29  6:41     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29  6:35     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29  6:34     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29  6:35     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29  6:37     ` sashiko-bot
2026-09-29  6:29   ` [PATCH v2 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29  6:38     ` sashiko-bot
2026-09-29  6:58   ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29  6:58     ` [PATCH v3 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29  7:08       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29  7:06       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29  7:03       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29  7:05       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29  7:04       ` sashiko-bot
2026-09-29  6:58     ` [PATCH v3 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29  7:06       ` sashiko-bot
2026-09-29 18:44     ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Arnaldo Carvalho de Melo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929023824.25F431F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=irogers@google.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox