Linux Perf Users
 help / color / mirror / Atom feed
* [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples
@ 2026-09-03  5:44 Huang Shijie
  2026-09-03  5:58 ` sashiko-bot
  2026-09-03 11:55 ` Ravi Bangoria
  0 siblings, 2 replies; 3+ messages in thread
From: Huang Shijie @ 2026-09-03  5:44 UTC (permalink / raw)
  To: peterz, mingo, acme, namhyung
  Cc: zhongyuan, fangbaoshun, yingzhiwei, mark.rutland,
	alexander.shishkin, jolsa, irogers, adrian.hunter, james.clark,
	tglx, bp, dave.hansen, x86, hpa, linux-perf-users, linux-kernel,
	liuqi, lijing, wujianyong, wangfengyu, Huang Shijie,
	Ravi Bangoria

The IBS Fetch sampling does not report the physical address of the
fetched instruction even when PERF_SAMPLE_PHYS_ADDR is requested,
while IBS Op sampling does.

This patch reports physical address for IBS fetch samples which can be
used for profiling the running program.

Reviewed-by: Ravi Bangoria <ravi.bangoria@amd.com>
Signed-off-by: Huang Shijie <huangsj@hygon.cn>
---
 arch/x86/events/amd/ibs.c | 22 ++++++++++++++++++++++
 1 file changed, 22 insertions(+)

diff --git a/arch/x86/events/amd/ibs.c b/arch/x86/events/amd/ibs.c
index 3531f9c23b8c..e5376ad5b2ec 100644
--- a/arch/x86/events/amd/ibs.c
+++ b/arch/x86/events/amd/ibs.c
@@ -1318,11 +1318,31 @@ static void perf_ibs_parse_ld_st_data(__u64 sample_type,
 	}
 }
 
+static void perf_ibs_parse_fetch_data(__u64 sample_type,
+				      struct perf_ibs_data *ibs_data,
+				      struct perf_sample_data *data)
+{
+	union ibs_fetch_ctl fetch_ctl;
+
+	if (!(sample_type & PERF_SAMPLE_PHYS_ADDR))
+		return;
+
+	fetch_ctl.val = ibs_data->regs[ibs_fetch_msr_idx(MSR_AMD64_IBSFETCHCTL)];
+	if (!fetch_ctl.phy_addr_valid)
+		return;
+
+	data->phys_addr = ibs_data->regs[ibs_fetch_msr_idx(MSR_AMD64_IBSFETCHPHYSAD)];
+	data->sample_flags |= PERF_SAMPLE_PHYS_ADDR;
+}
+
 static bool perf_ibs_is_mem_sample_type(struct perf_ibs *perf_ibs,
 					struct perf_event *event)
 {
 	u64 sample_type = event->attr.sample_type;
 
+	if (perf_ibs == &perf_ibs_fetch)
+		return sample_type & PERF_SAMPLE_PHYS_ADDR;
+
 	return perf_ibs == &perf_ibs_op &&
 	       sample_type & (PERF_SAMPLE_DATA_SRC |
 			      PERF_SAMPLE_WEIGHT_TYPE |
@@ -1555,6 +1575,8 @@ static int perf_ibs_handle_irq(struct perf_ibs *perf_ibs, struct pt_regs *iregs)
 
 	if (perf_ibs == &perf_ibs_op)
 		perf_ibs_parse_ld_st_data(event->attr.sample_type, &ibs_data, &data);
+	else
+		perf_ibs_parse_fetch_data(event->attr.sample_type, &ibs_data, &data);
 
 	/*
 	 * rip recorded by IbsOpRip will not be consistent with rsp and rbp
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples
  2026-09-03  5:44 [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples Huang Shijie
@ 2026-09-03  5:58 ` sashiko-bot
  2026-09-03 11:55 ` Ravi Bangoria
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-03  5:58 UTC (permalink / raw)
  To: Huang Shijie; +Cc: linux-perf-users

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Kernel stack buffer overflow when reading MSR_AMD64_IBSOPDATA4.
--

commit 7872bc1d9818cf858d57204bd43f4a048e54da52
Author: Huang Shijie <huangsj@hygon.cn>

perf/amd/ibs: Report physical address for IBS fetch samples

The IBS Fetch sampling does not report the physical address of the
fetched instruction even when PERF_SAMPLE_PHYS_ADDR is requested,
while IBS Op sampling does. This patch reports physical address for
IBS fetch samples which can be used for profiling the running program.

> diff --git a/arch/x86/events/amd/ibs.c b/arch/x86/events/amd/ibs.c
> index 3531f9c23b8c9..e5376ad5b2ecd 100644
> --- a/arch/x86/events/amd/ibs.c
> +++ b/arch/x86/events/amd/ibs.c
[ ... ]
> @@ -1555,6 +1575,8 @@ static int perf_ibs_handle_irq(struct perf_ibs *perf_ibs, struct pt_regs *iregs)
>  
>  	if (perf_ibs == &perf_ibs_op)
>  		perf_ibs_parse_ld_st_data(event->attr.sample_type, &ibs_data, &data);
> +	else
> +		perf_ibs_parse_fetch_data(event->attr.sample_type, &ibs_data, &data);

[Severity: High]
This is a pre-existing issue, but does reading MSR_AMD64_IBSOPDATA4 earlier
in perf_ibs_handle_irq() overflow ibs_data.regs[] when both IBS_CAPS_BRNTRGT
and IBS_CAPS_OPDATA4 are present?

The ibs_data.regs array has a fixed size of MSR_AMD64_IBS_REG_COUNT_MAX (8).
If a user requests PERF_SAMPLE_RAW on a CPU supporting both features (like
Zen 4), the interrupt handler reads 7 base registers, an 8th register for
IBSBRTARGET, and a 9th for IBSOPDATA4.

This writes the 9th MSR value into ibs_data.regs[8] on the kernel stack:

    if (ibs_caps & IBS_CAPS_OPDATA4) {
        rdmsrq(MSR_AMD64_IBSOPDATA4, *buf++);
        size++;
    }

Can this corrupt adjacent stack memory when buf advances out of bounds?

>  
>  	/*
>  	 * rip recorded by IbsOpRip will not be consistent with rsp and rbp

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903054422.148739-1-huangsj@hygon.cn?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples
  2026-09-03  5:44 [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples Huang Shijie
  2026-09-03  5:58 ` sashiko-bot
@ 2026-09-03 11:55 ` Ravi Bangoria
  1 sibling, 0 replies; 3+ messages in thread
From: Ravi Bangoria @ 2026-09-03 11:55 UTC (permalink / raw)
  To: Huang Shijie
  Cc: peterz, mingo, acme, namhyung, zhongyuan, fangbaoshun, yingzhiwei,
	mark.rutland, alexander.shishkin, jolsa, irogers, adrian.hunter,
	james.clark, tglx, bp, dave.hansen, x86, hpa, linux-perf-users,
	linux-kernel, liuqi, lijing, wujianyong, wangfengyu,
	Ravi Bangoria

Hi Huang,

> The IBS Fetch sampling does not report the physical address of the
> fetched instruction even when PERF_SAMPLE_PHYS_ADDR is requested,
> while IBS Op sampling does.
> 
> This patch reports physical address for IBS fetch samples which can be
> used for profiling the running program.

As I understand it, we decided not to pursue this because it changes
the semantics of PERF_SAMPLE_PHYS_ADDR _only_ for the IBS Fetch PMU,
which is confusing. The alternative is to use PERF_SAMPLE_RAW and
extract the physical address from the raw data.

Thanks,
Ravi

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-03 11:55 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03  5:44 [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples Huang Shijie
2026-09-03  5:58 ` sashiko-bot
2026-09-03 11:55 ` Ravi Bangoria

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox