From: sashiko-bot@kernel.org
To: "Andi Kleen" <ak@kernel.org>
Cc: linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org
Subject: Re: [RFC PATCH v2 06/11] ptwrite uprobes: Add basic memory references
Date: Thu, 17 Sep 2026 23:17:24 +0000 [thread overview]
Message-ID: <20260917231724.913AE1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917230127.924985-7-ak@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] x86/uprobes: missing disp32 emission for memory args causes invalid reads
--
commit a6d11e7a0c907a2ea16451bbea72e2f4d6ed70e8
Author: Andi Kleen <ak@kernel.org>
ptwrite uprobes: Add basic memory references
Add support for memory references. Currently this is only
simple cases, no indirect memory references or strings,
that would require saving/restoring registers. Only 8 and 4 byte
memory references are supported.
> diff --git a/arch/x86/kernel/uprobes.c b/arch/x86/kernel/uprobes.c
> --- a/arch/x86/kernel/uprobes.c
> +++ b/arch/x86/kernel/uprobes.c
[ ... ]
> @@ -1431,24 +1463,62 @@ int arch_uprobe_ptwrite_prepare(struct arch_uprobe *auprobe,
[ ... ]
> for (i = 0; i < desc->nargs; i++) {
> - if (desc->args[i].src == UPROBE_PTW_SRC_REG) {
> + switch (desc->args[i].src) {
[ ... ]
> + case UPROBE_PTW_SRC_MEM: {
> + u8 reg = desc->args[i].reg;
> + bool wide = desc->args[i].size == 8;
> + unsigned int arg_len = (wide ? 9 : 8) +
> + ((reg & 7) == 4) + (!wide && (reg & 8));
> +
> + PTW_NEED(arg_len);
> + *p++ = 0xf3;
> + if (wide)
> + *p++ = (reg & 8) ? 0x49 : 0x48; /* REX.W */
> + else if (reg & 8)
> + *p++ = 0x41; /* REX.B only (32-bit operand) */
> + *p++ = 0x0f;
> + *p++ = 0xae;
> + *p++ = 0xa0 | (reg & 7); /* mod 10, reg /4, rm reg */
> + if ((reg & 7) == 4) /* SIB escape: base rsp/esp/r12 */
> + *p++ = 0x24;
> + p += 4;
[Severity: High]
Does this code miss copying the displacement value for the memory access?
The stub generator in arch_uprobe_ptwrite_prepare() for memory fetch arguments
(UPROBE_PTW_SRC_MEM) configures the ptwrite instruction to use a 32-bit
displacement (mod=10) and advances the instruction pointer p by 4 bytes.
However, it appears to fail to write the requested user displacement
(desc->args[i].val) into those 4 bytes, leaving them as uninitialized zeroes.
Will the generated uprobe stub execute a memory fetch with a displacement of
0 (e.g., reading [reg + 0] instead of [reg + disp32])? This could cause the
traced application to read incorrect memory, which can lead to capturing
garbage data in the trace or crashing the application with an unintended
SIGSEGV.
> + break;
> + }
> }
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917230127.924985-2-ak@kernel.org?part=6
next prev parent reply other threads:[~2026-09-17 23:17 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 23:00 ptwrite uprobes v2 Andi Kleen
2026-09-17 23:00 ` [RFC PATCH v2 01/11] ptwrite uprobes: Add infrastructure for ptwrite uprobes Andi Kleen
2026-09-17 23:19 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 02/11] ptwrite uprobes: Add minimal low level support for x86 Andi Kleen
2026-09-17 23:25 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 03/11] ptwrite uprobes: Add a sample module to exercise interface Andi Kleen
2026-09-17 23:20 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 04/11] ptwrite uprobes: Add support to tracing infrastructure Andi Kleen
2026-09-17 23:23 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 05/11] ptwrite uprobes: Factor file-backed instruction reads Andi Kleen
2026-09-17 23:14 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 06/11] ptwrite uprobes: Add basic memory references Andi Kleen
2026-09-17 23:17 ` sashiko-bot [this message]
2026-09-17 23:00 ` [RFC PATCH v2 07/11] ptwrite uprobes: Add multinop support Andi Kleen
2026-09-17 23:22 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 08/11] ptwrite uprobes: Support instruction punning Andi Kleen
2026-09-17 23:27 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 09/11] ptwrite uprobes: Use atomic patching for multinop sites Andi Kleen
2026-09-17 23:32 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 10/11] ptwrite uprobes: Add a tutorial and overview documentation Andi Kleen
2026-09-17 23:21 ` sashiko-bot
2026-09-17 23:00 ` [RFC PATCH v2 11/11] ptwrite uprobes: Add kernel self tests Andi Kleen
2026-09-17 23:28 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917231724.913AE1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=ak@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox