* [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples
@ 2026-09-03 5:44 Huang Shijie
2026-09-03 5:58 ` sashiko-bot
2026-09-03 11:55 ` Ravi Bangoria
0 siblings, 2 replies; 3+ messages in thread
From: Huang Shijie @ 2026-09-03 5:44 UTC (permalink / raw)
To: peterz, mingo, acme, namhyung
Cc: zhongyuan, fangbaoshun, yingzhiwei, mark.rutland,
alexander.shishkin, jolsa, irogers, adrian.hunter, james.clark,
tglx, bp, dave.hansen, x86, hpa, linux-perf-users, linux-kernel,
liuqi, lijing, wujianyong, wangfengyu, Huang Shijie,
Ravi Bangoria
The IBS Fetch sampling does not report the physical address of the
fetched instruction even when PERF_SAMPLE_PHYS_ADDR is requested,
while IBS Op sampling does.
This patch reports physical address for IBS fetch samples which can be
used for profiling the running program.
Reviewed-by: Ravi Bangoria <ravi.bangoria@amd.com>
Signed-off-by: Huang Shijie <huangsj@hygon.cn>
---
arch/x86/events/amd/ibs.c | 22 ++++++++++++++++++++++
1 file changed, 22 insertions(+)
diff --git a/arch/x86/events/amd/ibs.c b/arch/x86/events/amd/ibs.c
index 3531f9c23b8c..e5376ad5b2ec 100644
--- a/arch/x86/events/amd/ibs.c
+++ b/arch/x86/events/amd/ibs.c
@@ -1318,11 +1318,31 @@ static void perf_ibs_parse_ld_st_data(__u64 sample_type,
}
}
+static void perf_ibs_parse_fetch_data(__u64 sample_type,
+ struct perf_ibs_data *ibs_data,
+ struct perf_sample_data *data)
+{
+ union ibs_fetch_ctl fetch_ctl;
+
+ if (!(sample_type & PERF_SAMPLE_PHYS_ADDR))
+ return;
+
+ fetch_ctl.val = ibs_data->regs[ibs_fetch_msr_idx(MSR_AMD64_IBSFETCHCTL)];
+ if (!fetch_ctl.phy_addr_valid)
+ return;
+
+ data->phys_addr = ibs_data->regs[ibs_fetch_msr_idx(MSR_AMD64_IBSFETCHPHYSAD)];
+ data->sample_flags |= PERF_SAMPLE_PHYS_ADDR;
+}
+
static bool perf_ibs_is_mem_sample_type(struct perf_ibs *perf_ibs,
struct perf_event *event)
{
u64 sample_type = event->attr.sample_type;
+ if (perf_ibs == &perf_ibs_fetch)
+ return sample_type & PERF_SAMPLE_PHYS_ADDR;
+
return perf_ibs == &perf_ibs_op &&
sample_type & (PERF_SAMPLE_DATA_SRC |
PERF_SAMPLE_WEIGHT_TYPE |
@@ -1555,6 +1575,8 @@ static int perf_ibs_handle_irq(struct perf_ibs *perf_ibs, struct pt_regs *iregs)
if (perf_ibs == &perf_ibs_op)
perf_ibs_parse_ld_st_data(event->attr.sample_type, &ibs_data, &data);
+ else
+ perf_ibs_parse_fetch_data(event->attr.sample_type, &ibs_data, &data);
/*
* rip recorded by IbsOpRip will not be consistent with rsp and rbp
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples
2026-09-03 5:44 [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples Huang Shijie
@ 2026-09-03 5:58 ` sashiko-bot
2026-09-03 11:55 ` Ravi Bangoria
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-03 5:58 UTC (permalink / raw)
To: Huang Shijie; +Cc: linux-perf-users
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Kernel stack buffer overflow when reading MSR_AMD64_IBSOPDATA4.
--
commit 7872bc1d9818cf858d57204bd43f4a048e54da52
Author: Huang Shijie <huangsj@hygon.cn>
perf/amd/ibs: Report physical address for IBS fetch samples
The IBS Fetch sampling does not report the physical address of the
fetched instruction even when PERF_SAMPLE_PHYS_ADDR is requested,
while IBS Op sampling does. This patch reports physical address for
IBS fetch samples which can be used for profiling the running program.
> diff --git a/arch/x86/events/amd/ibs.c b/arch/x86/events/amd/ibs.c
> index 3531f9c23b8c9..e5376ad5b2ecd 100644
> --- a/arch/x86/events/amd/ibs.c
> +++ b/arch/x86/events/amd/ibs.c
[ ... ]
> @@ -1555,6 +1575,8 @@ static int perf_ibs_handle_irq(struct perf_ibs *perf_ibs, struct pt_regs *iregs)
>
> if (perf_ibs == &perf_ibs_op)
> perf_ibs_parse_ld_st_data(event->attr.sample_type, &ibs_data, &data);
> + else
> + perf_ibs_parse_fetch_data(event->attr.sample_type, &ibs_data, &data);
[Severity: High]
This is a pre-existing issue, but does reading MSR_AMD64_IBSOPDATA4 earlier
in perf_ibs_handle_irq() overflow ibs_data.regs[] when both IBS_CAPS_BRNTRGT
and IBS_CAPS_OPDATA4 are present?
The ibs_data.regs array has a fixed size of MSR_AMD64_IBS_REG_COUNT_MAX (8).
If a user requests PERF_SAMPLE_RAW on a CPU supporting both features (like
Zen 4), the interrupt handler reads 7 base registers, an 8th register for
IBSBRTARGET, and a 9th for IBSOPDATA4.
This writes the 9th MSR value into ibs_data.regs[8] on the kernel stack:
if (ibs_caps & IBS_CAPS_OPDATA4) {
rdmsrq(MSR_AMD64_IBSOPDATA4, *buf++);
size++;
}
Can this corrupt adjacent stack memory when buf advances out of bounds?
>
> /*
> * rip recorded by IbsOpRip will not be consistent with rsp and rbp
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260903054422.148739-1-huangsj@hygon.cn?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples
2026-09-03 5:44 [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples Huang Shijie
2026-09-03 5:58 ` sashiko-bot
@ 2026-09-03 11:55 ` Ravi Bangoria
1 sibling, 0 replies; 3+ messages in thread
From: Ravi Bangoria @ 2026-09-03 11:55 UTC (permalink / raw)
To: Huang Shijie
Cc: peterz, mingo, acme, namhyung, zhongyuan, fangbaoshun, yingzhiwei,
mark.rutland, alexander.shishkin, jolsa, irogers, adrian.hunter,
james.clark, tglx, bp, dave.hansen, x86, hpa, linux-perf-users,
linux-kernel, liuqi, lijing, wujianyong, wangfengyu,
Ravi Bangoria
Hi Huang,
> The IBS Fetch sampling does not report the physical address of the
> fetched instruction even when PERF_SAMPLE_PHYS_ADDR is requested,
> while IBS Op sampling does.
>
> This patch reports physical address for IBS fetch samples which can be
> used for profiling the running program.
As I understand it, we decided not to pursue this because it changes
the semantics of PERF_SAMPLE_PHYS_ADDR _only_ for the IBS Fetch PMU,
which is confusing. The alternative is to use PERF_SAMPLE_RAW and
extract the physical address from the raw data.
Thanks,
Ravi
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-03 11:55 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-03 5:44 [PATCH] perf/amd/ibs: Report physical address for IBS fetch samples Huang Shijie
2026-09-03 5:58 ` sashiko-bot
2026-09-03 11:55 ` Ravi Bangoria
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox