From: Vincent Donnefort <vdonnefort@google.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length
Date: Thu, 13 Aug 2026 15:00:41 +0100 [thread overview]
Message-ID: <an3OCb8Aa1nQ9jD4@google.com> (raw)
In-Reply-To: <20260812164242.085961F000E9@smtp.kernel.org>
On Wed, Aug 12, 2026 at 04:42:41PM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
>
> New issues:
> - [High] The patch unconditionally introduces `type_len` compression for small events and hardcodes 4-byte alignment, ignoring `RB_FORCE_8BYTE_ALIGNMENT` and `RB_ARCH_ALIGNMENT`. This causes payload truncation and unaligned accesses on architectures requiring 8-byte alignment.
>
> Pre-existing issues:
> - [High] `simple_ring_buffer_reserve` lacks a bounds check to prevent `event_size` from exceeding the maximum page capacity (`PAGE_SIZE - BUF_PAGE_HDR_SIZE`).
> --
>
> --- Patch [5]: [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length ---
> commit 661f4dfe638155c632fb481b814114210260a54c
> Author: Vincent Donnefort <vdonnefort@google.com>
>
> tracing/simple_ring_buffer: Add support for compressed length
>
> This patch adds support for compressing the event length into the event
> header type for small events in the simple ring buffer, saving 32 bits
> per event. It enforces a 4-byte alignment for the compressed length.
>
> > diff --git a/kernel/trace/simple_ring_buffer.c b/kernel/trace/simple_ring_buffer.c
> > index f4642f5adda33..1a97d17cca246 100644
> > --- a/kernel/trace/simple_ring_buffer.c
> > +++ b/kernel/trace/simple_ring_buffer.c
> > @@ -207,7 +207,15 @@ static unsigned long rb_event_size(unsigned long length)
> > {
> > struct ring_buffer_event *event;
> >
> > - return length + RB_EVNT_HDR_SIZE + sizeof(event->array[0]);
> > + if (!length)
> > + length++;
> > +
> > + length = ALIGN(length, RB_ALIGNMENT);
>
> [Severity: High]
> Does this hardcoded 4-byte alignment cause unaligned access exceptions on
> architectures that require 8-byte alignment (where RB_FORCE_8BYTE_ALIGNMENT
> is 1)?
>
> It looks like using RB_ARCH_ALIGNMENT instead of RB_ALIGNMENT would prevent
> these exceptions.
I will add support for RB_FORCE_8BYTE_ALIGNMENT in v6.
>
> > +
> > + if (length > RB_MAX_SMALL_DATA)
> > + length += sizeof(event->array[0]);
> > +
> > + return length + RB_EVNT_HDR_SIZE;
> > }
>
> [ ... ]
>
> > @@ -259,9 +270,13 @@ simple_rb_reserve_next(struct simple_rb_per_cpu *cpu_buffer, unsigned long lengt
> > time_delta = 0;
> > }
> >
> > - event->type_len = 0;
> > + if (length > RB_MAX_SMALL_DATA) {
> > + event->type_len = 0;
> > + event->array[0] = array_size;
> > + } else {
> > + event->type_len = DIV_ROUND_UP(array_size, RB_ALIGNMENT);
> > + }
>
> [Severity: High]
> Can this unconditional compression cause payload truncation on architectures
> requiring 8-byte alignment?
>
> If RB_FORCE_8BYTE_ALIGNMENT is set, it seems the core ring buffer reader
> (ring_buffer_event_length) might subsequently subtract 4 bytes erroneously,
> leading to data loss and potential out-of-bounds reads when parsing the event.
>
> > event->time_delta = time_delta;
> > - event->array[0] = event_size - RB_EVNT_HDR_SIZE;
> >
> > return event;
> > }
> > @@ -284,7 +299,7 @@ void *simple_ring_buffer_reserve(struct simple_rb_per_cpu *cpu_buffer, unsigned
> >
> > rb_event = simple_rb_reserve_next(cpu_buffer, length, timestamp);
> >
> > - return &rb_event->array[1];
> > + return rb_event->type_len ? &rb_event->array[0] : &rb_event->array[1];
>
> [Severity: High]
> This is a pre-existing issue, but does simple_ring_buffer_reserve() lack a
> bounds check for events larger than the maximum page capacity?
>
> If a caller attempts to reserve an event with a length exceeding
> PAGE_SIZE - BUF_PAGE_HDR_SIZE, simple_rb_reserve_next() will move to a new
> page and set the write index beyond the page boundary. This would return a
> pointer that allows the caller to write out of bounds.
>
> Would it be safer to validate that length is smaller than the maximum buffer
> page data size before proceeding with the reservation?
Right now we just do not consider such huge events as possible.
--
Vincent
>
> > }
> > EXPORT_SYMBOL_GPL(simple_ring_buffer_reserve);
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260812161340.2417322-1-vdonnefort@google.com?part=5
next prev parent reply other threads:[~2026-08-13 14:00 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 16:13 [PATCH v5 00/18] tracing/remotes: Add printk, dump_on_panic and boot parameters Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 01/18] tracing/remotes: Gate tracefs files opening on trace remote registration Vincent Donnefort
2026-08-12 16:31 ` sashiko-bot
2026-08-13 13:16 ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 02/18] tracing/remotes: Release tracefs,eventfs on registration failure Vincent Donnefort
2026-08-12 16:25 ` sashiko-bot
2026-08-13 13:25 ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 03/18] tracing/remotes: Use kstrtobool for boolean tracefs files Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 04/18] tracing/remotes: Use a single per-remote polling work Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 05/18] tracing/simple_ring_buffer: Add support for compressed length Vincent Donnefort
2026-08-12 16:42 ` sashiko-bot
2026-08-13 14:00 ` Vincent Donnefort [this message]
2026-08-12 16:13 ` [PATCH v5 06/18] tracing/remotes: Add dmesg tracefs file Vincent Donnefort
2026-08-12 16:42 ` sashiko-bot
2026-08-13 14:02 ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 07/18] tracing/remotes: selftests: Add a test for the " Vincent Donnefort
2026-08-12 16:40 ` sashiko-bot
2026-08-13 14:06 ` Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 08/18] tracing/remotes: selftests: Prefix hypervisor folder Vincent Donnefort
2026-08-12 16:52 ` sashiko-bot
2026-08-12 16:13 ` [PATCH v5 09/18] ring-buffer: Use irqsave for the reader lock in ring_buffer_poll_remote Vincent Donnefort
2026-08-12 16:13 ` [PATCH v5 10/18] ring-buffer: Use panic-friendly locking in ring_buffer_iter interface Vincent Donnefort
2026-08-12 16:54 ` sashiko-bot
[not found] ` <20260812161340.2417322-15-vdonnefort@google.com>
2026-08-12 17:02 ` [PATCH v5 14/18] tracing/remotes: selftests: Add a test for the dump_on_panic tracefs file sashiko-bot
[not found] ` <20260812161340.2417322-14-vdonnefort@google.com>
2026-08-12 17:08 ` [PATCH v5 13/18] tracing/remotes: Add " sashiko-bot
[not found] ` <20260812161340.2417322-17-vdonnefort@google.com>
2026-08-12 17:11 ` [PATCH v5 16/18] tracing/remotes: Add trace_remote cmdline options sashiko-bot
2026-08-13 14:21 ` Vincent Donnefort
[not found] ` <20260812161340.2417322-16-vdonnefort@google.com>
2026-08-12 17:13 ` [PATCH v5 15/18] tracing/remotes: Add poll_ms tracefs file sashiko-bot
2026-08-13 14:20 ` Vincent Donnefort
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=an3OCb8Aa1nQ9jD4@google.com \
--to=vdonnefort@google.com \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox