Linux Perf Users
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v2 6/8] perf inject: Extend perf inject to support bid_offset conversion
Date: Sat, 03 Oct 2026 01:33:23 +0000	[thread overview]
Message-ID: <20261003013324.02BDD1F00898@smtp.kernel.org> (raw)
In-Reply-To: <20261002173848.3228217-7-irogers@google.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf: strict aliasing violation via incompatible u32* cast
--

commit e992f40013df71934d4af6ea3359426fe5b0f8a1
Author: Ian Rogers <irogers@google.com>

perf inject: Extend perf inject to support bid_offset conversion

This commit adds the --sample-buildids option to perf inject, allowing it to
drop MMAP events and rewrite samples to use build IDs and offsets instead
of virtual addresses.

> diff --git a/tools/perf/util/inject_bid_offset.c b/tools/perf/util/inject_bid_offset.c
> new file mode 100644
> index 0000000000000..25e8f21a2d5aa
> --- /dev/null
> +++ b/tools/perf/util/inject_bid_offset.c
[ ... ]
> @@ -0,0 +1,680 @@
[ ... ]
> +	if (sample_type & PERF_SAMPLE_RAW) {
> +		size_t bytes = sizeof(u32) + sample->raw_size;
> +		u64 words = DIV_ROUND_UP(bytes, sizeof(u64));
> +		u32 *out_raw = (u32 *)&out_array[j];
> +
> +		if (i > max_i || words > max_i - i)
> +			goto err;
> +		out_array[j + words - 1] = 0;
> +		*out_raw = sample->raw_size;

[Severity: High]
Does this pointer cast and dereference in inject_bid_offset_tool__sample()
violate strict aliasing rules?

Since out_raw is an incompatible u32 pointer cast from the underlying u64
array, the compiler is allowed to assume the stores do not overlap. This
means the compiler can reorder the u64 store (out_array[j + words - 1] = 0)
and the u32 store (*out_raw = sample->raw_size).

If words == 1 (for example, when sample->raw_size <= 4), both assignments
target the exact same 8-byte memory region. Under type-based alias analysis,
reordering these independent stores could result in raw_size being zeroed
out, corrupting the perf data output.

This occurs when using --sample-buildids on an input perf.data file
containing events with PERF_SAMPLE_RAW. Unlike core kernel space, the tools/
directory assumes -fstrict-aliasing by default.

> +		memcpy(out_raw + 1, sample->raw_data, sample->raw_size);
> +		i += words;
> +		j += words;
> +	}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002173848.3228217-1-irogers@google.com?part=6

  reply	other threads:[~2026-10-03  1:33 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-24  6:19 [PATCH v1 0/5] perf: Default use of build IDs and improvements Ian Rogers
2025-04-24  6:19 ` [PATCH v1 1/5] perf build-id: Reduce size of "size" variable Ian Rogers
2025-04-24  6:19 ` [PATCH v1 2/5] perf build-id: Truncate to avoid overflowing the build_id data Ian Rogers
2025-04-24  6:19 ` [PATCH v1 3/5] perf build-id: Change sprintf functions to snprintf Ian Rogers
2025-04-24  6:19 ` [PATCH v1 4/5] perf dso: Move build_id to dso_id Ian Rogers
2025-04-24  6:19 ` [PATCH v1 5/5] perf record: Make --buildid-mmap the default Ian Rogers
2025-04-24  7:20   ` Ian Rogers
2025-04-25 14:45     ` Arnaldo Carvalho de Melo
2025-04-25 14:59       ` Arnaldo Carvalho de Melo
2025-04-25 16:03       ` Ian Rogers
2026-10-02 17:38 ` [PATCH v2 0/8] perf/core, perf/tools: Add PERF_SAMPLE_BUILD_ID_OFFSET support Ian Rogers
2026-10-02 17:38   ` [PATCH v2 1/8] perf event: Factor build_id out into its own top-level struct Ian Rogers
2026-10-03  1:33     ` sashiko-bot
2026-10-02 17:38   ` [PATCH v2 2/8] perf/core: Add BUILD_ID_OFFSET to UAPI Ian Rogers
2026-10-03  1:33     ` sashiko-bot
2026-10-02 17:38   ` [PATCH v2 3/8] perf/core: Implement BUILD_ID_OFFSET sample type Ian Rogers
2026-10-03  1:33     ` sashiko-bot
2026-10-02 17:38   ` [PATCH v2 4/8] perf: Refactor thread map and symbol APIs to take perf_sample Ian Rogers
2026-10-03  1:33     ` sashiko-bot
2026-10-02 17:38   ` [PATCH v2 5/8] perf tools: Internal support for BUILD_ID_OFFSET Ian Rogers
2026-10-03  1:33     ` sashiko-bot
2026-10-02 17:38   ` [PATCH v2 6/8] perf inject: Extend perf inject to support bid_offset conversion Ian Rogers
2026-10-03  1:33     ` sashiko-bot [this message]
2026-10-02 17:38   ` [PATCH v2 7/8] perf record: Add --buildid-offset option Ian Rogers
2026-10-03  1:33     ` sashiko-bot
2026-10-02 17:38   ` [PATCH v2 8/8] perf tests: Add build_id_offset test coverage Ian Rogers
2026-10-03  1:33     ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003013324.02BDD1F00898@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=irogers@google.com \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox