From: sashiko-bot@kernel.org
To: "Namhyung Kim" <namhyung@kernel.org>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v2 09/10] perf annotate: Simplify symbol__disassemble() with dso binary_type
Date: Wed, 07 Oct 2026 00:01:39 +0000 [thread overview]
Message-ID: <sashiko-outbox-162546@kernel.org> (raw)
In-Reply-To: <20261006234315.920817-10-namhyung@kernel.org>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] perf: string truncation in symbol__disassemble() due to sizeof(pointer)
- [High] perf: NULL pointer dereference in LLVM disassembly backend for BPF
- [High] perf annotate: UAF in dso__get_filename due to missing dso__lock
--
commit b52fe9a1d630e0d03a547c6ca49efe1679043beb
Author: Namhyung Kim <namhyung@kernel.org>
Subject: perf annotate: Simplify symbol__disassemble() with dso binary_type
Now it should set the binary type of a DSO properly. No need to figure
out a filename suitable for disassembly.
Just call dso__find_binary_type() and dso__get_filename() for that type.
> diff --git a/tools/perf/util/disasm.c b/tools/perf/util/disasm.c
> index 5478c134e7e3b..07a345beb6250 100644
> --- a/tools/perf/util/disasm.c
> +++ b/tools/perf/util/disasm.c
[ ... ]
> @@ -1566,24 +1488,30 @@ int symbol__disassemble(struct symbol *sym, struct annotate_args *args)
> struct annotation_options *options = args->options;
> struct map *map = args->ms->map;
> struct dso *dso = map__dso(map);
> - char symfs_filename[PATH_MAX];
> + char *symfs_filename;
> bool delete_extract = false;
> struct kcore_extract kce;
> + enum dso_binary_type dbt;
> bool decomp = false;
> - int err = dso__disassemble_filename(dso, symfs_filename, sizeof(symfs_filename));
> + int err;
>
> - if (err)
> - return err;
> + dbt = dso__find_binary_type(dso);
> +
> + if (dbt == DSO_BINARY_TYPE__KALLSYMS)
> + return SYMBOL_ANNOTATE_ERRNO__NO_VMLINUX;
> +
> + symfs_filename = dso__get_filename(dso, "", &decomp, dbt);
[Severity: High]
Does this call to dso__get_filename() need to be protected by dso__lock()?
The previous code had an explicit mutex_lock(dso__lock(dso)) around the
access to dso__nsinfo(dso). dso__get_filename() reads and uses
dso__nsinfo(dso) via dso__filename_with_chroot(), but lacks internal
locking.
If another thread concurrently processes an MMAP event and calls
dso__set_nsinfo(), could the nsinfo pointer be freed between the check and
its use, leading to a use-after-free?
> + if (symfs_filename == NULL && dbt != DSO_BINARY_TYPE__BPF_PROG_INFO &&
> + dbt != DSO_BINARY_TYPE__BPF_IMAGE)
> + return SYMBOL_ANNOTATE_ERRNO__COULDNT_DETERMINE_FILE_TYPE;
[Severity: High]
When annotating BPF programs, this explicitly allows symfs_filename to be
NULL. However, could this NULL pointer be passed down to the LLVM
disassembly backend?
In the LLVM backend:
symbol__disassemble_llvm()
llvm_name_for_code(..., filename, ...)
Inside llvm-c-helpers.cpp, symbolizer->symbolizeCode(dso_name, ...)
implicitly constructs an llvm::StringRef from the dso_name pointer.
If the pointer is NULL, won't this perform a strlen(NULL) and cause a
segmentation fault? Similarly, on PowerPC, could symbol__disassemble_raw()
invoke pr_debug("%s", filename) or open(filename, ...) with the NULL pointer,
triggering undefined behavior?
>
> pr_debug("%s: filename=%s, sym=%s, start=%#" PRIx64 ", end=%#" PRIx64 "\n", __func__,
> - symfs_filename, sym->name, map__unmap_ip(map, sym->start),
> - map__unmap_ip(map, sym->end));
> + symfs_filename ?: dso__long_name(dso), sym->name,
> + map__unmap_ip(map, sym->start), map__unmap_ip(map, sym->end));
>
> pr_debug("annotating [%p] %30s : [%p] %30s\n", dso, dso__long_name(dso), sym, sym->name);
>
> - if (dso__binary_type(dso) == DSO_BINARY_TYPE__NOT_FOUND) {
> - return SYMBOL_ANNOTATE_ERRNO__COULDNT_DETERMINE_FILE_TYPE;
> - } else if (dso__is_kcore(dso)) {
> + if (dso__is_kcore(dso)) {
> kce.addr = map__rip_2objdump(map, sym->start);
> kce.kcore_filename = symfs_filename;
> kce.len = sym->end - sym->start;
> @@ -1593,17 +1521,6 @@ int symbol__disassemble(struct symbol *sym, struct annotate_args *args)
> delete_extract = true;
> strlcpy(symfs_filename, kce.extract_filename, sizeof(symfs_filename));
[Severity: High]
Since symfs_filename is now a char * pointer rather than an array of size
PATH_MAX, doesn't sizeof(symfs_filename) evaluate to 8 (on 64-bit systems)?
Will this cause strlcpy() to truncate the kcore extraction path to 7
characters, leading to ENOENT failures in the downstream disassemblers?
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006234315.920817-1-namhyung@kernel.org?part=9
next prev parent reply other threads:[~2026-10-07 0:01 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 23:43 [PATCH v2 00/10] perf symbol: Properly set DSO binary/symtab types Namhyung Kim
2026-10-06 23:43 ` [PATCH v2 01/10] perf tools: Remove redundant dso data init Namhyung Kim
2026-10-06 23:49 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 02/10] perf tools: Try linked debug files for DSO debug info Namhyung Kim
2026-10-06 23:54 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 03/10] perf symbol: Update symtab type of vmlinux from build-id cache Namhyung Kim
2026-10-06 23:54 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 04/10] perf symbol: Set binary/symtab type for split kallsyms Namhyung Kim
2026-10-06 23:58 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 05/10] perf symbol: Set dso symtab type for libbfd Namhyung Kim
2026-10-06 23:57 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 06/10] perf tools: Factor out dso__find_binary_type() Namhyung Kim
2026-10-07 0:04 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 07/10] perf symbol: Set binary type for JIT map DSOs Namhyung Kim
2026-10-06 23:51 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 08/10] perf symbol: Do not set binary type from symtab type Namhyung Kim
2026-10-06 23:57 ` sashiko-bot
2026-10-06 23:43 ` [PATCH v2 09/10] perf annotate: Simplify symbol__disassemble() with dso binary_type Namhyung Kim
2026-10-07 0:01 ` sashiko-bot [this message]
2026-10-06 23:43 ` [PATCH v2 10/10] perf test: Fix dso data tests Namhyung Kim
2026-10-06 23:59 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-162546@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=namhyung@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox