Linux Trace Kernel
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Gabriele Monaco" <gmonaco@redhat.com>
Cc: linux-trace-kernel@vger.kernel.org, bpf@vger.kernel.org
Subject: Re: [RFC PATCH 18/20] verification/rvgen: Add support for BPF monitors
Date: Mon, 31 Aug 2026 09:41:44 +0000	[thread overview]
Message-ID: <20260831094144.DEAAD1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831090524.106845-19-gmonaco@redhat.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Generated BPF monitor arrays for state and event names lack null termination if names are 32 characters or longer, leading to out-of-bounds reads.
--

commit 53fecfe68f54b9383a7c0b099f9a1311ed5ff3ef
Author: Gabriele Monaco <gmonaco@redhat.com>

verification/rvgen: Add support for BPF monitors

This commit adds the -b flag to the rvgen monitor tool to generate BPF
monitors for deterministic automata. It updates the code generator to emit
BPF-compatible array structures and hooks while maintaining the existing
in-kernel monitor support.

> diff --git a/tools/verification/rvgen/rvgen/dot2c.py b/tools/verification/rvgen/rvgen/dot2c.py
> index 22938ce1bf6cb..5be9fe44a19b2 100644
> --- a/tools/verification/rvgen/rvgen/dot2c.py
> +++ b/tools/verification/rvgen/rvgen/dot2c.py
> @@ -111,10 +111,17 @@ class Dot2c(Automata):
>          min_type = self.get_minimun_type()
>          buff = []
>          buff.append(f"struct {self.struct_automaton_def} {{")
> -        buff.append(f"\tchar *state_names[state_max{self.enum_suffix}];")
> -        buff.append(f"\tchar *event_names[event_max{self.enum_suffix}];")
> -        if self.is_hybrid_automata():
> -            buff.append(f"\tchar *env_names[env_max{self.enum_suffix}];")
> +        if self.bpf:
> +            # BPF struggles with non-fixed string pointers
> +            buff.append(f"\tchar state_names[state_max{self.enum_suffix}][32];")
> +            buff.append(f"\tchar event_names[event_max{self.enum_suffix}][32];")
> +            if self.is_hybrid_automata():
> +                buff.append(f"\tchar env_names[env_max{self.enum_suffix}][32];")

[Severity: Medium]
Could this lead to out-of-bounds reads in BPF trace output if the monitor
model has state or event names of 32 characters or longer?

When a fixed-size character array is initialized with a string literal equal
to or larger than its size, the null terminator is silently omitted in C.
If the names generated from the model are exactly 32 bytes or longer, these
arrays will lack a null terminator.

Since the BPF verifier permits reading .rodata, string formatting helpers
reading from these fields could run past the array bounds until a null byte
is encountered in adjacent memory. This could cause garbled trace output and
a minor info leak.

Would it make sense to enforce truncation of the source string during
generation, or explicitly ensure null termination here?

> +        else:
> +            buff.append(f"\tchar *state_names[state_max{self.enum_suffix}];")
> +            buff.append(f"\tchar *event_names[event_max{self.enum_suffix}];")

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260831090524.106845-1-gmonaco@redhat.com?part=18

  reply	other threads:[~2026-08-31  9:41 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31  9:05 [RFC PATCH 00/20] rv: Add support for BPF monitors Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 01/20] sched: Add task enqueue/dequeue trace points Gabriele Monaco
2026-08-31  9:32   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 02/20] tools/rv: Skip empty pid error in selftest if command failed Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 03/20] rv: Refactor da_trace() functions to get strings internally Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 04/20] rv: Use static arrays for rv_monitor name and description Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 05/20] rv: Add in-kernel support for BPF monitors Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 06/20] rv: Add rv_get_monitor_by_name() Gabriele Monaco
2026-08-31  9:24   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 07/20] rv: Add reactors support to BPF monitors Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 08/20] rv: Cast result of model_get_*_name() Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 09/20] rv: Handle unregistered monitors safely in tracefs Gabriele Monaco
2026-08-31  9:24   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 10/20] tools/build: Add a feature test for bpftool-btf Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 11/20] tools/rv: Move argument parsing from in_kernel to utils Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 12/20] tools/rv: Export functionality for in_kernel monitors Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 13/20] tools/rv: Implement BPF monitor loading and tracing Gabriele Monaco
2026-08-31  9:34   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 14/20] tools/rv: Implement BPF monitor registration logic Gabriele Monaco
2026-08-31  9:38   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 15/20] tools/rv: Copy stripped bpf_atomic.h from libarena Gabriele Monaco
2026-08-31  9:38   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 16/20] tools/rv: Add BPF monitors Gabriele Monaco
2026-08-31  9:40   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 17/20] tools/rv: Define CONFIG_X86_64 statically for " Gabriele Monaco
2026-08-31  9:05 ` [RFC PATCH 18/20] verification/rvgen: Add support " Gabriele Monaco
2026-08-31  9:41   ` sashiko-bot [this message]
2026-08-31  9:05 ` [RFC PATCH 19/20] tools/rv: Add selftest for rv bpf Gabriele Monaco
2026-08-31  9:44   ` sashiko-bot
2026-08-31  9:05 ` [RFC PATCH 20/20] verification/rvgen: Add selftest for rvgen -b Gabriele Monaco
2026-09-01 18:35 ` [RFC PATCH 00/20] rv: Add support for BPF monitors Nam Cao
2026-09-02  6:52   ` Gabriele Monaco
2026-09-02  7:46     ` Nam Cao
2026-09-03  1:57     ` Alexei Starovoitov
2026-09-03  7:21       ` Gabriele Monaco
2026-09-03 13:02         ` Steven Rostedt
2026-09-04  3:30           ` Alexei Starovoitov
2026-09-04 11:43             ` Steven Rostedt
2026-09-04 16:16               ` Alexei Starovoitov
2026-09-04 16:31                 ` Steven Rostedt
2026-09-04 17:24                   ` Steven Rostedt
2026-09-04 11:23       ` Tomas Glozar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831094144.DEAAD1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=gmonaco@redhat.com \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox