Linux Perf Users
 help / color / mirror / Atom feed
* [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
@ 2025-09-17  9:54 Fushuai Wang
  2025-09-17 15:31 ` Ian Rogers
  0 siblings, 1 reply; 9+ messages in thread
From: Fushuai Wang @ 2025-09-17  9:54 UTC (permalink / raw)
  To: peterz, mingo, acme, namhyung, mark.rutland, alexander.shishkin,
	jolsa, irogers, adrian.hunter, kan.liang
  Cc: linux-perf-users, linux-kernel, Fushuai Wang

The alloc_syscall_stats() function always returns an error pointer
(ERR_PTR) on failure. So replace NULL check with IS_ERR() check
after calling alloc_syscall_stats() function.

Fixes: fc00897c8a3f ("perf trace: Add --summary-mode option")
Signed-off-by: Fushuai Wang <wangfushuai@baidu.com>
---
 tools/perf/builtin-trace.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
index fe737b3ac6e6..25c41b89f8ab 100644
--- a/tools/perf/builtin-trace.c
+++ b/tools/perf/builtin-trace.c
@@ -4440,7 +4440,7 @@ static int trace__run(struct trace *trace, int argc, const char **argv)
 
 	if (trace->summary_mode == SUMMARY__BY_TOTAL && !trace->summary_bpf) {
 		trace->syscall_stats = alloc_syscall_stats();
-		if (trace->syscall_stats == NULL)
+		if (IS_ERR(trace->syscall_stats))
 			goto out_delete_evlist;
 	}
 
@@ -4748,7 +4748,7 @@ static int trace__replay(struct trace *trace)
 
 	if (trace->summary_mode == SUMMARY__BY_TOTAL) {
 		trace->syscall_stats = alloc_syscall_stats();
-		if (trace->syscall_stats == NULL)
+		if (IS_ERR(trace->syscall_stats))
 			goto out;
 	}
 
-- 
2.36.1


^ permalink raw reply related	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2025-09-17  9:54 [PATCH] perf trace: Fix IS_ERR() vs NULL check bug Fushuai Wang
@ 2025-09-17 15:31 ` Ian Rogers
  2025-09-17 16:27   ` Arnaldo Carvalho de Melo
  0 siblings, 1 reply; 9+ messages in thread
From: Ian Rogers @ 2025-09-17 15:31 UTC (permalink / raw)
  To: Fushuai Wang
  Cc: peterz, mingo, acme, namhyung, mark.rutland, alexander.shishkin,
	jolsa, adrian.hunter, kan.liang, linux-perf-users, linux-kernel

On Wed, Sep 17, 2025 at 2:54 AM Fushuai Wang <wangfushuai@baidu.com> wrote:
>
> The alloc_syscall_stats() function always returns an error pointer
> (ERR_PTR) on failure. So replace NULL check with IS_ERR() check
> after calling alloc_syscall_stats() function.
>
> Fixes: fc00897c8a3f ("perf trace: Add --summary-mode option")
> Signed-off-by: Fushuai Wang <wangfushuai@baidu.com>

Reviewed-by: Ian Rogers <irogers@google.com>

Thanks,
Ian

> ---
>  tools/perf/builtin-trace.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
> index fe737b3ac6e6..25c41b89f8ab 100644
> --- a/tools/perf/builtin-trace.c
> +++ b/tools/perf/builtin-trace.c
> @@ -4440,7 +4440,7 @@ static int trace__run(struct trace *trace, int argc, const char **argv)
>
>         if (trace->summary_mode == SUMMARY__BY_TOTAL && !trace->summary_bpf) {
>                 trace->syscall_stats = alloc_syscall_stats();
> -               if (trace->syscall_stats == NULL)
> +               if (IS_ERR(trace->syscall_stats))
>                         goto out_delete_evlist;
>         }
>
> @@ -4748,7 +4748,7 @@ static int trace__replay(struct trace *trace)
>
>         if (trace->summary_mode == SUMMARY__BY_TOTAL) {
>                 trace->syscall_stats = alloc_syscall_stats();
> -               if (trace->syscall_stats == NULL)
> +               if (IS_ERR(trace->syscall_stats))
>                         goto out;
>         }
>
> --
> 2.36.1
>

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2025-09-17 15:31 ` Ian Rogers
@ 2025-09-17 16:27   ` Arnaldo Carvalho de Melo
  0 siblings, 0 replies; 9+ messages in thread
From: Arnaldo Carvalho de Melo @ 2025-09-17 16:27 UTC (permalink / raw)
  To: Ian Rogers
  Cc: Fushuai Wang, peterz, mingo, namhyung, mark.rutland,
	alexander.shishkin, jolsa, adrian.hunter, kan.liang,
	linux-perf-users, linux-kernel

On Wed, Sep 17, 2025 at 08:31:02AM -0700, Ian Rogers wrote:
> On Wed, Sep 17, 2025 at 2:54 AM Fushuai Wang <wangfushuai@baidu.com> wrote:
> >
> > The alloc_syscall_stats() function always returns an error pointer
> > (ERR_PTR) on failure. So replace NULL check with IS_ERR() check
> > after calling alloc_syscall_stats() function.
> >
> > Fixes: fc00897c8a3f ("perf trace: Add --summary-mode option")
> > Signed-off-by: Fushuai Wang <wangfushuai@baidu.com>
> 
> Reviewed-by: Ian Rogers <irogers@google.com>

Thanks, applied to perf-tools-next,

- Arnaldo

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
@ 2026-02-26 12:22 wangguangju
  2026-02-26 15:50 ` Howard Chu
  2026-02-27 21:32 ` Namhyung Kim
  0 siblings, 2 replies; 9+ messages in thread
From: wangguangju @ 2026-02-26 12:22 UTC (permalink / raw)
  To: peterz, mingo, acme, namhyung, mark.rutland, alexander.shishkin,
	jolsa, irogers, adrian.hunter, james.clark
  Cc: linux-perf-users, linux-kernel, wangguangju

From: wangguangju <wangguangju@hygon.cn>

The alloc_syscall_stats() function always returns an error pointer
(ERR_PTR) on failure.

So replace NULL check with IS_ERR() check after calling
delete_syscall_stats() function.

Signed-off-by: wangguangju <wangguangju@hygon.cn>
---
 tools/perf/builtin-trace.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
index 311d9da9896a..295b272c6c29 100644
--- a/tools/perf/builtin-trace.c
+++ b/tools/perf/builtin-trace.c
@@ -1573,7 +1573,7 @@ static void delete_syscall_stats(struct hashmap *syscall_stats)
 	struct hashmap_entry *pos;
 	size_t bkt;
 
-	if (syscall_stats == NULL)
+	if (IS_ERR(syscall_stats))
 		return;
 
 	hashmap__for_each_entry(syscall_stats, pos, bkt)
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2026-02-26 12:22 wangguangju
@ 2026-02-26 15:50 ` Howard Chu
  2026-02-26 16:32   ` Ian Rogers
  2026-02-27 21:32 ` Namhyung Kim
  1 sibling, 1 reply; 9+ messages in thread
From: Howard Chu @ 2026-02-26 15:50 UTC (permalink / raw)
  To: wangguangju
  Cc: peterz, mingo, acme, namhyung, mark.rutland, alexander.shishkin,
	jolsa, irogers, adrian.hunter, james.clark, linux-perf-users,
	linux-kernel

Hi wangguangju,

On Thu, Feb 26, 2026 at 4:23 AM <wangguangju@hygon.cn> wrote:
>
> From: wangguangju <wangguangju@hygon.cn>
>
> The alloc_syscall_stats() function always returns an error pointer
> (ERR_PTR) on failure.
>
> So replace NULL check with IS_ERR() check after calling
> delete_syscall_stats() function.

Thanks, syscall_stats is never NULL after alloc_syscall_stats(), and
it seems like perf now frees the hashmap using the error pointer,
pretty dangerous.

>
> Signed-off-by: wangguangju <wangguangju@hygon.cn>

Reviewed-by: Howard Chu <howardchu95@gmail.com>

Thanks,
Howard

> ---
>  tools/perf/builtin-trace.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
> index 311d9da9896a..295b272c6c29 100644
> --- a/tools/perf/builtin-trace.c
> +++ b/tools/perf/builtin-trace.c
> @@ -1573,7 +1573,7 @@ static void delete_syscall_stats(struct hashmap *syscall_stats)
>         struct hashmap_entry *pos;
>         size_t bkt;
>
> -       if (syscall_stats == NULL)
> +       if (IS_ERR(syscall_stats))
>                 return;
>
>         hashmap__for_each_entry(syscall_stats, pos, bkt)
> --
> 2.43.0
>
>
>

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2026-02-26 15:50 ` Howard Chu
@ 2026-02-26 16:32   ` Ian Rogers
  0 siblings, 0 replies; 9+ messages in thread
From: Ian Rogers @ 2026-02-26 16:32 UTC (permalink / raw)
  To: Howard Chu
  Cc: wangguangju, peterz, mingo, acme, namhyung, mark.rutland,
	alexander.shishkin, jolsa, adrian.hunter, james.clark,
	linux-perf-users, linux-kernel

On Thu, Feb 26, 2026 at 7:50 AM Howard Chu <howardchu95@gmail.com> wrote:
>
> Hi wangguangju,
>
> On Thu, Feb 26, 2026 at 4:23 AM <wangguangju@hygon.cn> wrote:
> >
> > From: wangguangju <wangguangju@hygon.cn>
> >
> > The alloc_syscall_stats() function always returns an error pointer
> > (ERR_PTR) on failure.
> >
> > So replace NULL check with IS_ERR() check after calling
> > delete_syscall_stats() function.
>
> Thanks, syscall_stats is never NULL after alloc_syscall_stats(), and
> it seems like perf now frees the hashmap using the error pointer,
> pretty dangerous.
>
> >
> > Signed-off-by: wangguangju <wangguangju@hygon.cn>
>
> Reviewed-by: Howard Chu <howardchu95@gmail.com>

Acked-by: Ian Rogers <irogers@google.com>

We've been burnt by IS_ERR many times, I think in user land we should
declare it an anti-pattern and switch to using NULL and errno.
Alternatively we could wrap functions that return an error pointer by
returning some kind of struct, so the error state is checked. I
reached out to other kernel developers; they agree but the problem in
the kernel is too large to fix. In perf 90% of the problems originate
from hashmap. Alternatively, a sparse/Coccinelle build bot or
build-test that can flag the issue would be good.

Thanks,
Ian

> Thanks,
> Howard
>
> > ---
> >  tools/perf/builtin-trace.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
> > index 311d9da9896a..295b272c6c29 100644
> > --- a/tools/perf/builtin-trace.c
> > +++ b/tools/perf/builtin-trace.c
> > @@ -1573,7 +1573,7 @@ static void delete_syscall_stats(struct hashmap *syscall_stats)
> >         struct hashmap_entry *pos;
> >         size_t bkt;
> >
> > -       if (syscall_stats == NULL)
> > +       if (IS_ERR(syscall_stats))
> >                 return;
> >
> >         hashmap__for_each_entry(syscall_stats, pos, bkt)
> > --
> > 2.43.0
> >
> >
> >

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2026-02-26 12:22 wangguangju
  2026-02-26 15:50 ` Howard Chu
@ 2026-02-27 21:32 ` Namhyung Kim
  2026-02-28  6:40   ` Ian Rogers
  1 sibling, 1 reply; 9+ messages in thread
From: Namhyung Kim @ 2026-02-27 21:32 UTC (permalink / raw)
  To: peterz, mingo, acme, mark.rutland, alexander.shishkin, jolsa,
	irogers, adrian.hunter, james.clark, wangguangju
  Cc: linux-perf-users, linux-kernel

On Thu, 26 Feb 2026 20:22:08 +0800, wangguangju@hygon.cn wrote:
> The alloc_syscall_stats() function always returns an error pointer
> (ERR_PTR) on failure.
> 
> So replace NULL check with IS_ERR() check after calling
> delete_syscall_stats() function.
> 
> 
> [...]
Applied to perf-tools-next, thanks!

Best regards,
Namhyung



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2026-02-27 21:32 ` Namhyung Kim
@ 2026-02-28  6:40   ` Ian Rogers
  2026-02-28  7:06     ` Howard Chu
  0 siblings, 1 reply; 9+ messages in thread
From: Ian Rogers @ 2026-02-28  6:40 UTC (permalink / raw)
  To: Namhyung Kim
  Cc: peterz, mingo, acme, mark.rutland, alexander.shishkin, jolsa,
	adrian.hunter, james.clark, wangguangju, linux-perf-users,
	linux-kernel

On Fri, Feb 27, 2026 at 1:32 PM Namhyung Kim <namhyung@kernel.org> wrote:
>
> On Thu, 26 Feb 2026 20:22:08 +0800, wangguangju@hygon.cn wrote:
> > The alloc_syscall_stats() function always returns an error pointer
> > (ERR_PTR) on failure.
> >
> > So replace NULL check with IS_ERR() check after calling
> > delete_syscall_stats() function.
> >
> >
> > [...]
> Applied to perf-tools-next, thanks!

This broke the "perf trace summary" test for me (run `perf test -v`).
The failing command under gdb shows:
```
$ gdb --args perf trace -s -- true
...
(gdb) r
...
Program received signal SIGSEGV, Segmentation fault.
0x0000555555672210 in delete_syscall_stats (syscall_stats=0x0) at
builtin-trace.c:1579
1579            hashmap__for_each_entry(syscall_stats, pos, bkt)
(gdb) l
1574            size_t bkt;
1575
1576            if (IS_ERR(syscall_stats))
1577                    return;
1578
1579            hashmap__for_each_entry(syscall_stats, pos, bkt)
1580                    zfree(&pos->pvalue);
1581            hashmap__free(syscall_stats);
1582    }
```

As NULL is false for IS_ERR I think the correct change is:
```
if (syscall_stats == NULL || IS_ERR(syscall_stats))
```

We seem to be routinely breaking tests, which may indicate a lot of
noise in the test output. I see many failures in the type profiling
test due to the typedef vs struct issue.

Thanks,
Ian

> Best regards,
> Namhyung
>
>

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] perf trace: Fix IS_ERR() vs NULL check bug
  2026-02-28  6:40   ` Ian Rogers
@ 2026-02-28  7:06     ` Howard Chu
  0 siblings, 0 replies; 9+ messages in thread
From: Howard Chu @ 2026-02-28  7:06 UTC (permalink / raw)
  To: Ian Rogers
  Cc: Namhyung Kim, peterz, mingo, acme, mark.rutland,
	alexander.shishkin, jolsa, adrian.hunter, james.clark,
	wangguangju, linux-perf-users, linux-kernel

Hi Ian,

On Fri, Feb 27, 2026 at 10:40 PM Ian Rogers <irogers@google.com> wrote:
>
> On Fri, Feb 27, 2026 at 1:32 PM Namhyung Kim <namhyung@kernel.org> wrote:
> >
> > On Thu, 26 Feb 2026 20:22:08 +0800, wangguangju@hygon.cn wrote:
> > > The alloc_syscall_stats() function always returns an error pointer
> > > (ERR_PTR) on failure.
> > >
> > > So replace NULL check with IS_ERR() check after calling
> > > delete_syscall_stats() function.
> > >
> > >
> > > [...]
> > Applied to perf-tools-next, thanks!
>
> This broke the "perf trace summary" test for me (run `perf test -v`).
> The failing command under gdb shows:
> ```
> $ gdb --args perf trace -s -- true
> ...
> (gdb) r
> ...
> Program received signal SIGSEGV, Segmentation fault.
> 0x0000555555672210 in delete_syscall_stats (syscall_stats=0x0) at
> builtin-trace.c:1579
> 1579            hashmap__for_each_entry(syscall_stats, pos, bkt)
> (gdb) l
> 1574            size_t bkt;
> 1575
> 1576            if (IS_ERR(syscall_stats))
> 1577                    return;
> 1578
> 1579            hashmap__for_each_entry(syscall_stats, pos, bkt)
> 1580                    zfree(&pos->pvalue);
> 1581            hashmap__free(syscall_stats);
> 1582    }
> ```
>
> As NULL is false for IS_ERR I think the correct change is:
> ```
> if (syscall_stats == NULL || IS_ERR(syscall_stats))
> ```

I suspected the same thing but couldn't find a NULL assignment in the
code, so I rushed the review, I apologize. Yours looks good to me.

Thanks,
Howard

>
> We seem to be routinely breaking tests, which may indicate a lot of
> noise in the test output. I see many failures in the type profiling
> test due to the typedef vs struct issue.
>
> Thanks,
> Ian
>
> > Best regards,
> > Namhyung
> >
> >
>

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-02-28  7:06 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-09-17  9:54 [PATCH] perf trace: Fix IS_ERR() vs NULL check bug Fushuai Wang
2025-09-17 15:31 ` Ian Rogers
2025-09-17 16:27   ` Arnaldo Carvalho de Melo
  -- strict thread matches above, loose matches on Subject: below --
2026-02-26 12:22 wangguangju
2026-02-26 15:50 ` Howard Chu
2026-02-26 16:32   ` Ian Rogers
2026-02-27 21:32 ` Namhyung Kim
2026-02-28  6:40   ` Ian Rogers
2026-02-28  7:06     ` Howard Chu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox