Linux Perf Users
 help / color / mirror / Atom feed
From: Namhyung Kim <namhyung@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v2 09/10] perf annotate: Simplify symbol__disassemble() with dso binary_type
Date: Fri, 9 Oct 2026 23:47:06 -0700	[thread overview]
Message-ID: <asnfagqYiBIClmNS@z2> (raw)
In-Reply-To: <sashiko-outbox-162546@kernel.org>

On Wed, Oct 07, 2026 at 12:01:39AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
> - [High] perf: string truncation in symbol__disassemble() due to sizeof(pointer)
> - [High] perf: NULL pointer dereference in LLVM disassembly backend for BPF
> - [High] perf annotate: UAF in dso__get_filename due to missing dso__lock
> --
> 
> commit b52fe9a1d630e0d03a547c6ca49efe1679043beb
> Author: Namhyung Kim <namhyung@kernel.org>
> Subject: perf annotate: Simplify symbol__disassemble() with dso binary_type
> 
> Now it should set the binary type of a DSO properly.  No need to figure
> out a filename suitable for disassembly.
> 
> Just call dso__find_binary_type() and dso__get_filename() for that type.
> 
> > diff --git a/tools/perf/util/disasm.c b/tools/perf/util/disasm.c
> > index 5478c134e7e3b..07a345beb6250 100644
> > --- a/tools/perf/util/disasm.c
> > +++ b/tools/perf/util/disasm.c
> [ ... ]
> > @@ -1566,24 +1488,30 @@ int symbol__disassemble(struct symbol *sym, struct annotate_args *args)
> >  	struct annotation_options *options = args->options;
> >  	struct map *map = args->ms->map;
> >  	struct dso *dso = map__dso(map);
> > -	char symfs_filename[PATH_MAX];
> > +	char *symfs_filename;
> >  	bool delete_extract = false;
> >  	struct kcore_extract kce;
> > +	enum dso_binary_type dbt;
> >  	bool decomp = false;
> > -	int err = dso__disassemble_filename(dso, symfs_filename, sizeof(symfs_filename));
> > +	int err;
> >  
> > -	if (err)
> > -		return err;
> > +	dbt = dso__find_binary_type(dso);
> > +
> > +	if (dbt == DSO_BINARY_TYPE__KALLSYMS)
> > +		return SYMBOL_ANNOTATE_ERRNO__NO_VMLINUX;
> > +
> > +	symfs_filename = dso__get_filename(dso, "", &decomp, dbt);
> 
> [Severity: High]
> Does this call to dso__get_filename() need to be protected by dso__lock()?
> 
> The previous code had an explicit mutex_lock(dso__lock(dso)) around the
> access to dso__nsinfo(dso). dso__get_filename() reads and uses
> dso__nsinfo(dso) via dso__filename_with_chroot(), but lacks internal
> locking.
> 
> If another thread concurrently processes an MMAP event and calls
> dso__set_nsinfo(), could the nsinfo pointer be freed between the check and
> its use, leading to a use-after-free?

Ok, will add the lock.

> 
> > +	if (symfs_filename == NULL && dbt != DSO_BINARY_TYPE__BPF_PROG_INFO &&
> > +	    dbt != DSO_BINARY_TYPE__BPF_IMAGE)
> > +		return SYMBOL_ANNOTATE_ERRNO__COULDNT_DETERMINE_FILE_TYPE;
> 
> [Severity: High]
> When annotating BPF programs, this explicitly allows symfs_filename to be
> NULL. However, could this NULL pointer be passed down to the LLVM
> disassembly backend?
> 
> In the LLVM backend:
> symbol__disassemble_llvm()
>   llvm_name_for_code(..., filename, ...)
> 
> Inside llvm-c-helpers.cpp, symbolizer->symbolizeCode(dso_name, ...)
> implicitly constructs an llvm::StringRef from the dso_name pointer.
> 
> If the pointer is NULL, won't this perform a strlen(NULL) and cause a
> segmentation fault? Similarly, on PowerPC, could symbol__disassemble_raw()
> invoke pr_debug("%s", filename) or open(filename, ...) with the NULL pointer,
> triggering undefined behavior?

Will handle it properly.

> 
> >  
> >  	pr_debug("%s: filename=%s, sym=%s, start=%#" PRIx64 ", end=%#" PRIx64 "\n", __func__,
> > -		 symfs_filename, sym->name, map__unmap_ip(map, sym->start),
> > -		 map__unmap_ip(map, sym->end));
> > +		 symfs_filename ?: dso__long_name(dso), sym->name,
> > +		 map__unmap_ip(map, sym->start), map__unmap_ip(map, sym->end));
> >  
> >  	pr_debug("annotating [%p] %30s : [%p] %30s\n", dso, dso__long_name(dso), sym, sym->name);
> >  
> > -	if (dso__binary_type(dso) == DSO_BINARY_TYPE__NOT_FOUND) {
> > -		return SYMBOL_ANNOTATE_ERRNO__COULDNT_DETERMINE_FILE_TYPE;
> > -	} else if (dso__is_kcore(dso)) {
> > +	if (dso__is_kcore(dso)) {
> >  		kce.addr = map__rip_2objdump(map, sym->start);
> >  		kce.kcore_filename = symfs_filename;
> >  		kce.len = sym->end - sym->start;
> > @@ -1593,17 +1521,6 @@ int symbol__disassemble(struct symbol *sym, struct annotate_args *args)
> >  			delete_extract = true;
> >  			strlcpy(symfs_filename, kce.extract_filename, sizeof(symfs_filename));
> 
> [Severity: High]
> Since symfs_filename is now a char * pointer rather than an array of size
> PATH_MAX, doesn't sizeof(symfs_filename) evaluate to 8 (on 64-bit systems)?
> 
> Will this cause strlcpy() to truncate the kcore extraction path to 7
> characters, leading to ENOENT failures in the downstream disassemblers?

Right, will fix.

Thanks,
Namhyung


  reply	other threads:[~2026-10-10  6:47 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 23:43 [PATCH v2 00/10] perf symbol: Properly set DSO binary/symtab types Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 01/10] perf tools: Remove redundant dso data init Namhyung Kim
2026-10-06 23:49   ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 02/10] perf tools: Try linked debug files for DSO debug info Namhyung Kim
2026-10-06 23:54   ` sashiko-bot
2026-10-10  5:38     ` Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 03/10] perf symbol: Update symtab type of vmlinux from build-id cache Namhyung Kim
2026-10-06 23:54   ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 04/10] perf symbol: Set binary/symtab type for split kallsyms Namhyung Kim
2026-10-06 23:58   ` sashiko-bot
2026-10-10  5:42     ` Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 05/10] perf symbol: Set dso symtab type for libbfd Namhyung Kim
2026-10-06 23:57   ` sashiko-bot
2026-10-10  5:49     ` Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 06/10] perf tools: Factor out dso__find_binary_type() Namhyung Kim
2026-10-07  0:04   ` sashiko-bot
2026-10-10  6:17     ` Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 07/10] perf symbol: Set binary type for JIT map DSOs Namhyung Kim
2026-10-06 23:51   ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 08/10] perf symbol: Do not set binary type from symtab type Namhyung Kim
2026-10-06 23:57   ` sashiko-bot
2026-10-10  6:41     ` Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 09/10] perf annotate: Simplify symbol__disassemble() with dso binary_type Namhyung Kim
2026-10-07  0:01   ` sashiko-bot
2026-10-10  6:47     ` Namhyung Kim [this message]
2026-10-06 23:43 ` [PATCH v2 10/10] perf test: Fix dso data tests Namhyung Kim
2026-10-06 23:59   ` sashiko-bot
2026-10-10  6:48     ` Namhyung Kim

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asnfagqYiBIClmNS@z2 \
    --to=namhyung@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox