From nobody Sat Jul 25 02:11:04 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A0B734F24C for ; Mon, 20 Jul 2026 17:55:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570123; cv=none; b=QW+970Incp/EUIuTneC9zPJJwf9YrTgCwU8FAAY708UdlQuxm74X1OM+d2mGTnD6c5OmTmP1g23KUSqXg8TiHp31aRalbf8XKDLuoUBOHLpykcEILRmgZ2Iir1Dtiw9lSXIkKct3D8dKW1eY1NF2A1G+YSegIxno9Z8dW5HNWDc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570123; c=relaxed/simple; bh=eZ+wX04/zXyvzuyqM8J6sRBfyy1fmlZivY1CAvP+j8s=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Content-Type; b=ukyEu9PgCcglU+oLBne0Gd/mWA6/em5SkZCXsUdJrWkmyHgoDE+hGHVE3kn7c6/8EopDXAFwxULx+9QzqN7LbY3ybo4cJVvNzqgGlIBCmH8edhOF1VfLm206FoCU9v9VzvGqTvPb5m9ZYNgJNqrwW8bjIsn2awUjlmjmijP6uQk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=PhcK0eeJ; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="PhcK0eeJ" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-38dbf293831so17136682a91.3 for ; Mon, 20 Jul 2026 10:55:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784570114; x=1785174914; darn=vger.kernel.org; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Hh+7obFCkE+FCg9itWlLHX9/KW1VGqY0DnXombaQNIU=; b=PhcK0eeJ8uKl7KuEHOpaS7x8ugPjxajY3qjkg8ec9nQA106azZafDg81M4/Jk1Ub/F nAZBfRhuvUBRbti4SwdAum1ZvnIkJVamTg2AVUEJ5CRvI4twqkD2RiLOCdCKnfbS+jGy 5/D31wx9sn4bKWH6aZmDnbXovL0MXsxYzhVsFnLcS0L83orJZgGS/N2PCtvug9z8FPhd oLk32Jwyn2S9R+u+8b6/zWIFs/oGrgiMAEnYDIvDvhLNVBjP6Dttukv1rTmUkSWECife ImoboMibh0RYqsiqaMPX2gCmabo7Eg0XEyX7/Dov3f/oK2Gw/q6J/pL4A3ePKyIhR7iZ JTCQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784570114; x=1785174914; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Hh+7obFCkE+FCg9itWlLHX9/KW1VGqY0DnXombaQNIU=; b=KEXDyznzwUHALpRCWZpULynY3CJehZQJykGSb4c/rxqQWz7b7PaGZ/x+a/E5CTYbwg 8ENowNAEUnpSkgwKTyPm4EIXhf+pp0/9TKyQi6pIgjf5LVunmq4zXndKebzQKBm0ml/J Twl/wEyDrULeJGvqaah8FXWJcH3/DE/9JYVE2BufNUbkGqd/09uZBNH4FEdVCqo19g6t k2iJ8KTYzv+oPWgiU/Jyxp9g1xum/yMV9TDQ4jzaqfUtbix9zD3+eWyNhW3kWGHk49jp 73Sp/cgvEGiqJJ4slDO02pf3onYmLDfIl6mqXfXIeRqgfi9hvnChrD8WDrOm49VuKsh3 +L8Q== X-Forwarded-Encrypted: i=1; AHgh+Ro+dhrVBGlTSnPkLjC+LzWkCgZmzc193hhYmkb7fyidE01IrNTNFLnD9574RR6Pmm642PPslynwUlV9fYw=@vger.kernel.org X-Gm-Message-State: AOJu0Yzs6UZL3hW9lQFOLhTUT2QpFTc7xlE3/4qajhUbMk4qZ5ezCzuI AWSnuLQRo1XLxnnnYN1YMH2y8uZSZ7Ie7az54bvUJRUTen038xzMs846twQzLz4yy0cYwnQKZlP JaHHh0OP2ag== X-Received: from dled9-n2.prod.google.com ([2002:a05:701b:42c9:20b0:13c:d017:a244]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:3dce:b0:387:e0db:3fad with SMTP id 98e67ed59e1d1-38e4b5d3ec4mr15642504a91.38.1784570113414; Mon, 20 Jul 2026 10:55:13 -0700 (PDT) Date: Mon, 20 Jul 2026 10:54:52 -0700 In-Reply-To: <20260720175455.3645946-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720175455.3645946-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260720175455.3645946-2-irogers@google.com> Subject: [PATCH v1 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction From: Ian Rogers To: Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Namhyung Kim , Jiri Olsa , Ian Rogers , Adrian Hunter , James Clark , Ravi Bangoria , Swapnil Sapkal , linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use getline() to dynamically allocate the required line buffer for maps parsing, guaranteeing bounds safety and preventing buffer overruns. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/find-map.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/find-map.c b/tools/perf/util/find-map.c index 7b2300588ece..4d740b32814f 100644 --- a/tools/perf/util/find-map.c +++ b/tools/perf/util/find-map.c @@ -1,8 +1,14 @@ // SPDX-License-Identifier: GPL-2.0 +#include +#include +#include + static int find_map(void **start, void **end, const char *name) { FILE *maps; - char line[128]; + char *line =3D NULL; + size_t len =3D 0; + ssize_t read_ret; int found =3D 0; =20 maps =3D fopen("/proc/self/maps", "r"); @@ -11,7 +17,7 @@ static int find_map(void **start, void **end, const char = *name) return -1; } =20 - while (!found && fgets(line, sizeof(line), maps)) { + while (!found && (read_ret =3D getline(&line, &len, maps)) !=3D -1) { int m =3D -1; =20 /* We care only about private r-x mappings. */ @@ -25,6 +31,7 @@ static int find_map(void **start, void **end, const char = *name) found =3D 1; } =20 + free(line); fclose(maps); return !found; } --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 02:11:04 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 63BEB448D08 for ; Mon, 20 Jul 2026 17:55:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570124; cv=none; b=lZUr10OTodCHKxBh5oQfjArO/4hsWmpxYQXmErXwNBFRwG+jPLBHyqFT4IfvlRI5OBHKun92z69eMvGtTjw27YwGY/XHGxxiFngPgE8rSNEMb3CxtyYS3fH1eeOY1oslPTBBJ6+IsXZaB47qhg1u9CY1Mx6PcBUdlTGb6Re7k/s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570124; c=relaxed/simple; bh=X+XhmvcrgDFYXJ4+suxESuvZXFjd8bAHThfTS/ZKb10=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Content-Type; b=S78j6E6F9ISznn2Phf+ErwCdhdT1mHppC6LhNVNKd/rY43VZrqQ0QBzbPiG0OU7w1Ta/7OEWEyGavR3MbvILDQekDQL9dYw57BU3MI7VveWhRhKBqQbHqPzdhXiLnUHPzCTXs/F8crHf4KM1G0PKqRnaPNN3fy0Ryf4dg2283Og= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=goITaWLU; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="goITaWLU" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-cab041eced3so12659748a12.1 for ; Mon, 20 Jul 2026 10:55:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784570116; x=1785174916; darn=vger.kernel.org; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=JKLKfwC2YgZOXdRwd5ZaICmLJk5/Gnuhh5z8C+XB7lY=; b=goITaWLUawCD1BnRwlbH8dUvPFfBuIcTsopozpsh0wnIAJD5rhz2Yv43OePPO97DMb oztvW5ibMcwR34sdUzpi15PCjJ6XfQVcBanRPD3pkLtp4xLsrl3p1IkMvyeEEyLuLWUr LDal+qysKF92zgZPDhUEin/J3ovyNfshRkuarxG1l/IsDFqaynpLuOFGwLg7fZRi8dQi jMQpxChoediBScfZGsBO7hP7dp7OifE/yljwftxajtYBN9Wwgm79tX7TfYcAxblfwhDU 6C38qmnnKDzbjGq9ggwdfCvw37XR5stWVejiQO7keVk74YhLF5N+UKN852TLsQK/owSN O/2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784570116; x=1785174916; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JKLKfwC2YgZOXdRwd5ZaICmLJk5/Gnuhh5z8C+XB7lY=; b=GNX8xqSU6NdnzO5jTs/X33PAKdOBQ0bkRTYobG/Gdi9WoIPDzWDqqGju0j3rbbqFfT +5t2CaHv7SNgo3pFN0mKpijU46YBoA6+UEhTGVkT1uIjOWfEMgJlarHLo6gNDLMXQ8P0 VS98bTYuYSMLh1t7WAnipM1fHy9b5Ww5a3JQSyatx0f6BCubVBv6fiUjgJKBBothwz0e MiWEHCPgaFlYJGzI4tb4dRg8Tp9tSPbxa8EzZ4qbU+dQfCGJMpCbQfsCU/6K/upjZ7UA zhSTg1WIjNsTnUT5OtRGVNsECq0ofAcDBqgAqymCKuNKofiRWDu35Pbw4UN4s+YKKuJd 0wag== X-Forwarded-Encrypted: i=1; AHgh+RrmuKCGgag+xQuTpE9XHs13ZCP2ntsbblm/n/n5yheIrM59z9JpCkmbAVpszr8Jv4HPmXky3VoyYjpTIBA=@vger.kernel.org X-Gm-Message-State: AOJu0Yx+AlyzksJEQUfebtEFzJU41gG1yCHIJeUCUdKbhogozeZna0+i agNkw/K/CuVzsL6li7r7gWaDW/u3raXxpr7G+ysNCqe6B0fXPzlusBCWZQY/a4pXmvqW0FUg2rS g3Jg5mwZZAA== X-Received: from dycqa12.prod.google.com ([2002:a05:7300:fe4c:b0:311:5b7d:f189]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a20:a109:b0:3bf:7110:9949 with SMTP id adf61e73a8af0-3c3ad5d6095mr16414285637.6.1784570115701; Mon, 20 Jul 2026 10:55:15 -0700 (PDT) Date: Mon, 20 Jul 2026 10:54:53 -0700 In-Reply-To: <20260720175455.3645946-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720175455.3645946-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260720175455.3645946-3-irogers@google.com> Subject: [PATCH v1 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader From: Ian Rogers To: Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Namhyung Kim , Jiri Olsa , Ian Rogers , Adrian Hunter , James Clark , Ravi Bangoria , Swapnil Sapkal , linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix critical logic and boundary bugs in read_proc_maps_line() and caller. Ensure any mid-line hex/dec/char parsing failure invokes io__drain_line() to preserve line synchronization for subsequent map entries. Replace the truncation bug (which improperly cleared over-length pathnames to an empty string) with the kernel's standard '//toolong' fallback literal, and clamp and pad structure size boundaries safely. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 183 ++++++++++++++++++++--------- 1 file changed, 127 insertions(+), 56 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index b75f9dcf4dbf..9161dc728e6e 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -291,6 +291,15 @@ static int perf_event__synthesize_fork(const struct pe= rf_tool *tool, return 0; } =20 +static void io__drain_line(struct io *io) +{ + int ch; + + do { + ch =3D io__get_char(io); + } while (ch >=3D 0 && ch !=3D '\n'); +} + static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end, u32 *prot, u32 *flags, __u64 *offset, u32 *maj, u32 *min, @@ -299,69 +308,121 @@ static bool read_proc_maps_line(struct io *io, __u64= *start, __u64 *end, { __u64 temp; int ch; - char *start_pathname =3D pathname; + size_t written =3D 0; + bool overflowed =3D false; =20 - if (io__get_hex(io, start) !=3D '-') + if (io__get_hex(io, start) !=3D '-') { + if (!io->eof) + io__drain_line(io); return false; - if (io__get_hex(io, end) !=3D ' ') + } + if (io__get_hex(io, end) !=3D ' ') { + if (!io->eof) + io__drain_line(io); return false; + } =20 /* map protection and flags bits */ *prot =3D 0; ch =3D io__get_char(io); if (ch =3D=3D 'r') *prot |=3D PROT_READ; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'w') *prot |=3D PROT_WRITE; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'x') *prot |=3D PROT_EXEC; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 's') *flags =3D MAP_SHARED; else if (ch =3D=3D 'p') *flags =3D MAP_PRIVATE; - else + else { + if (!io->eof) + io__drain_line(io); return false; - if (io__get_char(io) !=3D ' ') + } + if (io__get_char(io) !=3D ' ') { + if (!io->eof) + io__drain_line(io); return false; + } =20 - if (io__get_hex(io, offset) !=3D ' ') + if (io__get_hex(io, offset) !=3D ' ') { + if (!io->eof) + io__drain_line(io); return false; + } =20 - if (io__get_hex(io, &temp) !=3D ':') + if (io__get_hex(io, &temp) !=3D ':') { + if (!io->eof) + io__drain_line(io); return false; + } *maj =3D temp; - if (io__get_hex(io, &temp) !=3D ' ') + if (io__get_hex(io, &temp) !=3D ' ') { + if (!io->eof) + io__drain_line(io); return false; + } *min =3D temp; =20 ch =3D io__get_dec(io, inode); if (ch !=3D ' ') { - *pathname =3D '\0'; - return ch =3D=3D '\n'; + if (ch =3D=3D '\n') { + pathname[0] =3D '\0'; + return true; + } + if (!io->eof) + io__drain_line(io); + return false; } + do { ch =3D io__get_char(io); } while (ch =3D=3D ' '); + while (true) { - if (ch < 0) - return false; - if (ch =3D=3D '\0' || ch =3D=3D '\n' || - (pathname + 1 - start_pathname) >=3D pathname_size) { - *pathname =3D '\0'; - return true; + if (ch < 0) { + if (overflowed) { + strlcpy(pathname, "//toolong", pathname_size); + return true; + } + pathname[written] =3D '\0'; + return written > 0; } - *pathname++ =3D ch; + if (ch =3D=3D '\0' || ch =3D=3D '\n') + break; + + if (written < (size_t)pathname_size - 1) + pathname[written++] =3D (char)ch; + else + overflowed =3D true; ch =3D io__get_char(io); } + + if (overflowed) + strlcpy(pathname, "//toolong", pathname_size); + else + pathname[written] =3D '\0'; + + return true; } =20 static void perf_record_mmap2__read_build_id(struct perf_record_mmap2 *eve= nt, @@ -457,29 +518,25 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, } io__init(&io, io.fd, bf, sizeof(bf)); =20 - event->header.type =3D PERF_RECORD_MMAP2; t =3D rdclock(); =20 while (!io.eof) { static const char anonstr[] =3D "//anon"; size_t size, aligned_size; - - /* ensure null termination since stack will be reused. */ - event->mmap2.filename[0] =3D '\0'; + __u64 start, end, pgoff, ino; + u32 prot, flags, maj, min; =20 /* 00400000-0040c000 r-xp 00000000 fd:01 41038 /bin/cat */ - if (!read_proc_maps_line(&io, - &event->mmap2.start, - &event->mmap2.len, - &event->mmap2.prot, - &event->mmap2.flags, - &event->mmap2.pgoff, - &event->mmap2.maj, - &event->mmap2.min, - &event->mmap2.ino, - sizeof(event->mmap2.filename), - event->mmap2.filename)) + /* Read directly into event->mmap2.filename! */ + if (!read_proc_maps_line(&io, &start, &end, + &prot, &flags, &pgoff, + &maj, &min, &ino, + sizeof(event->mmap2.filename), + event->mmap2.filename)) { + if (io.eof) + break; continue; + } =20 if ((rdclock() - t) > timeout) { pr_warning("Reading %s/proc/%d/task/%d/maps time out. " @@ -487,50 +544,64 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, "the time limit by --proc-map-timeout\n", machine->root_dir, pid, pid); truncation =3D true; - goto out; } =20 - event->mmap2.ino_generation =3D 0; + if (!strcmp(event->mmap2.filename, "")) + strcpy(event->mmap2.filename, anonstr); + + if (hugetlbfs_mnt_len && + !strncmp(event->mmap2.filename, hugetlbfs_mnt, hugetlbfs_mnt_len)) { + strcpy(event->mmap2.filename, anonstr); + flags |=3D MAP_HUGETLB; + } + + size =3D strlen(event->mmap2.filename) + 1; + aligned_size =3D PERF_ALIGN(size, sizeof(u64)); + + event->mmap2.header.type =3D PERF_RECORD_MMAP2; =20 /* - * Just like the kernel, see __perf_event_mmap in kernel/perf_event.c + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) event->header.misc =3D PERF_RECORD_MISC_USER; else event->header.misc =3D PERF_RECORD_MISC_GUEST_USER; =20 - if ((event->mmap2.prot & PROT_EXEC) =3D=3D 0) { - if (!mmap_data || (event->mmap2.prot & PROT_READ) =3D=3D 0) + if ((prot & PROT_EXEC) =3D=3D 0) { + if (!mmap_data || (prot & PROT_READ) =3D=3D 0) { + if (truncation) + break; continue; + } =20 event->header.misc |=3D PERF_RECORD_MISC_MMAP_DATA; } =20 -out: if (truncation) event->header.misc |=3D PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT; =20 - if (!strcmp(event->mmap2.filename, "")) - strcpy(event->mmap2.filename, anonstr); + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; =20 - if (hugetlbfs_mnt_len && - !strncmp(event->mmap2.filename, hugetlbfs_mnt, - hugetlbfs_mnt_len)) { - strcpy(event->mmap2.filename, anonstr); - event->mmap2.flags |=3D MAP_HUGETLB; - } + /* Zero the padding and ID header trailer safely! */ + memset(event->mmap2.filename + size, 0, + (aligned_size - size) + machine->id_hdr_size); =20 - size =3D strlen(event->mmap2.filename) + 1; - aligned_size =3D PERF_ALIGN(size, sizeof(u64)); - event->mmap2.len -=3D event->mmap.start; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - aligned_size)); - memset(event->mmap2.filename + size, 0, machine->id_hdr_size + - (aligned_size - size)); event->mmap2.header.size +=3D machine->id_hdr_size; + event->mmap2.start =3D start; + event->mmap2.len =3D end - start; + event->mmap2.pgoff =3D pgoff; + event->mmap2.maj =3D maj; + event->mmap2.min =3D min; + event->mmap2.ino =3D ino; + event->mmap2.ino_generation =3D 0; event->mmap2.pid =3D tgid; event->mmap2.tid =3D pid; + event->mmap2.prot =3D prot; + event->mmap2.flags =3D flags; =20 if (!symbol_conf.no_buildid_mmap2) perf_record_mmap2__read_build_id(&event->mmap2, machine, false); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 02:11:04 2026 Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com [209.85.216.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F4D644C641 for ; Mon, 20 Jul 2026 17:55:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570127; cv=none; b=rMCHznloEsPrAZJr4tTjwu/1NXJwknlRoixzNsAfSOtl+lCNeRM6UQTk/aTD2Yxmi/5xQRXEgSl6COK7+Q1lNt5XX7oPM75YIxaBSWZrfWaJZDCiG4qng2D3+9V0kSVOMAi4yM+hc4c0VwMqxIaGjzuQ2nsbGCnKBy2KFg54f2M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570127; c=relaxed/simple; bh=3aX1EaAr1sbEmdIn9uz/KO4l+FvPsH+GN6jP8P1ep6A=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Content-Type; b=e6sEvs+qeDCm+6yMIBRnc7cseNNvfdZtuVHjuBa5DE9cKYWP6juPioBTBV2yz1uyPqnaFMOiJg3IbNeC5WexAlGojV4VQRZIQ74H8kLxzVW20LSzSzWCcskKAznesZJbuwfwNQU6lr8n+irLUyJx6mf4S1wlIHsmlgqLbRyLLZ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=FVmNwouI; arc=none smtp.client-ip=209.85.216.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="FVmNwouI" Received: by mail-pj1-f72.google.com with SMTP id 98e67ed59e1d1-38e11baa66eso7482471a91.2 for ; Mon, 20 Jul 2026 10:55:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784570118; x=1785174918; darn=vger.kernel.org; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=0RNdBnXJ5fF64ccDFnBustZkitp/xg6+f0zdlczyZFc=; b=FVmNwouIOiiv+j4iXpTvuHjBU/Hg/K+eeVJPXPNA9Ae12paQfo2w3lF4j6jRgJTJkd V56eJZ+ratMUZeWFD8R+SDOF3O5z2aoc4WUISBSoGSh7jGOrfoWA9n3ty5OLZ0suVvLd XW8tvzB5uqieSSQysDLJuAzlnskwqf98H/srox2zXUrZQdvAqqRoaJ6ly7gRouWsQw3v kAlw1sVmvCTIfzTxDMXVPB5NykGuukqhN/5FIyTHl1GvVm8HTLXoK4iLzwjvBnvyETo/ L6nGC9o3Ylmm3sr9eBw3SwJfqF89O9t/YDpIpjzanH0kvEzIn053cpPt+s47yVbAqHXb VvWw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784570118; x=1785174918; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0RNdBnXJ5fF64ccDFnBustZkitp/xg6+f0zdlczyZFc=; b=PTXnUjAuvM6rIxm6FNGZSU9KBoh1Eib7dMXTgSxpFMHECQKxNuVYl7XkChM4g/yJW/ xUtH+SDFcJUdcbmHfIuE/omjh+QGK97OqSv17hiXd204L2LmrRP9oSJXEti8TqOY0PBp 2d7voHh/aEafVeiH+WO3ZNGHvKKlN130Wzh/Hnwjr2Yy4gyifRgw8eltoE0P2ja9MZgT wBjtiWdA1uFbpf6jq6xXsg5nkOzFEPYwJb1Mk5pOP6RgkqyD8VCJ/gP9hGegVFKHPkNr j9QwLOAaGb7F828+ubHQC19mQFGw05nauaUiDghsLqUiSid2aQJj1J0aTgmkOBX+Bkq9 9uPQ== X-Forwarded-Encrypted: i=1; AHgh+Ro3LTdyjPZ95KnN+Tdit7Cw0/QsV1brQzsbTRJyM58D7I3D4BQD18Twc6HCDrqS6MXESzVQOA7cLy4XLGI=@vger.kernel.org X-Gm-Message-State: AOJu0YyBgafMVpBWm0QZSsy7FKlF9H/BBSycc82U4wJgA0nAggLHdG6S um6PudPG0Y84d6R2aYNyGLIKftItfbG/ktLD8C2frZx/2ZIrF6UXZuOKByeTY+GOiZcTB6mZl5n LahT0lxWz3A== X-Received: from dlec16-n2.prod.google.com ([2002:a05:701b:4290:20b0:13c:ce0f:370f]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4c46:b0:387:e0db:bc23 with SMTP id 98e67ed59e1d1-38e4b5536d4mr15288594a91.35.1784570117345; Mon, 20 Jul 2026 10:55:17 -0700 (PDT) Date: Mon, 20 Jul 2026 10:54:54 -0700 In-Reply-To: <20260720175455.3645946-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720175455.3645946-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260720175455.3645946-4-irogers@google.com> Subject: [PATCH v1 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis From: Ian Rogers To: Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Namhyung Kim , Jiri Olsa , Ian Rogers , Adrian Hunter , James Clark , Ravi Bangoria , Swapnil Sapkal , linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix potential buffer overruns in perf_event__synthesize_modules_maps_cb() by safely clamping long DSO names to the mmap/mmap2 filename boundaries. Explicitly assign and clear the misc flags and union padding across all iterations to prevent stale Build-ID state from leaking between module synthesis events. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 70 +++++++++++++++++++++--------- 1 file changed, 50 insertions(+), 20 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 9161dc728e6e..aab958cb3bc5 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -748,6 +748,7 @@ struct perf_event__synthesize_modules_maps_cb_args { perf_event__handler_t process; struct machine *machine; union perf_event *event; + u16 misc; }; =20 static int perf_event__synthesize_modules_maps_cb(struct map *map, void *d= ata) @@ -755,49 +756,78 @@ static int perf_event__synthesize_modules_maps_cb(str= uct map *map, void *data) struct perf_event__synthesize_modules_maps_cb_args *args =3D data; union perf_event *event =3D args->event; struct dso *dso; - size_t size; + size_t size, aligned_size; + int rc =3D 0; =20 if (!__map__is_kmodule(map)) return 0; =20 dso =3D map__dso(map); if (!symbol_conf.no_buildid_mmap2) { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap2.filename)) + size =3D sizeof(event->mmap2.filename) - 1; + + strlcpy(event->mmap2.filename, long_name, + sizeof(event->mmap2.filename)); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap2.header.type =3D PERF_RECORD_MMAP2; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - size)); - memset(event->mmap2.filename + size, 0, args->machine->id_hdr_size); + event->mmap2.header.misc =3D args->misc; + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset(event->mmap2.filename + size, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap2.header.size +=3D args->machine->id_hdr_size; event->mmap2.start =3D map__start(map); event->mmap2.len =3D map__size(map); event->mmap2.pid =3D args->machine->pid; =20 - memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); - - /* Clear stale build ID from previous module iteration */ + /* Clear stale build ID and entire union from previous module iteration = */ event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); event->mmap2.build_id_size =3D 0; + event->mmap2.__reserved_1 =3D 0; + event->mmap2.__reserved_2 =3D 0; =20 perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap.filename)) + size =3D sizeof(event->mmap.filename) - 1; + + strlcpy(event->mmap.filename, long_name, + sizeof(event->mmap.filename)); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap.header.type =3D PERF_RECORD_MMAP; - event->mmap.header.size =3D (sizeof(event->mmap) - - (sizeof(event->mmap.filename) - size)); - memset(event->mmap.filename + size, 0, args->machine->id_hdr_size); + event->mmap.header.misc =3D args->misc; + event->mmap.header.size =3D + offsetof(struct perf_record_mmap, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset(event->mmap.filename + size, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap.header.size +=3D args->machine->id_hdr_size; event->mmap.start =3D map__start(map); event->mmap.len =3D map__size(map); event->mmap.pid =3D args->machine->pid; - - memcpy(event->mmap.filename, dso__long_name(dso), dso__long_name_len(dso= ) + 1); } =20 if (perf_tool__process_synth_event(args->tool, event, args->machine, args= ->process) !=3D 0) - return -1; + rc =3D -1; =20 - return 0; + return rc; } =20 int perf_event__synthesize_modules(const struct perf_tool *tool, perf_even= t__handler_t process, @@ -822,13 +852,13 @@ int perf_event__synthesize_modules(const struct perf_= tool *tool, perf_event__han } =20 /* - * kernel uses 0 for user space maps, see kernel/perf_event.c - * __perf_event_mmap + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) - args.event->header.misc =3D PERF_RECORD_MISC_KERNEL; + args.misc =3D PERF_RECORD_MISC_KERNEL; else - args.event->header.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; + args.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; =20 rc =3D maps__for_each_map(maps, perf_event__synthesize_modules_maps_cb, &= args); =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 02:11:04 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 08256451068 for ; Mon, 20 Jul 2026 17:55:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570125; cv=none; b=YwelQaPe6v6oGoWOfRBKjnzmPagsPerQpLgdu/zJEfyePqaI/Xz3sg2Dx+rhj2MKtg1XsvFaOQXpNbboCyhrlyyuKhwdLGtz4293SjZzW5jIgmTXkjIvUnQWubjFPlox5XThnwwCCJOCeTPDXMInsD/L6fMZJPvZPxuFbx45RpY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784570125; c=relaxed/simple; bh=vVq/yAqli/Ps3YNknNL7qI/CsWifMu7Da0GMqyVVBFk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Content-Type; b=Vet5OL+BcWXPjN/tKFdmcYp32FzKJgvoRLY7zq4qM10yEgEDIFpSZ0i2ELMyB+hDMDAFMp+Y8X7EQoFMrsQc0dN43blImx2InNo4Lw7RGO0KJD9+Wzi8F6DptDmEwMTS7Pvskn4+Oy/yq5DkCCwjf7nNVUcSk4LOH7CP4aejCbw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=O2iBx5Ql; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="O2iBx5Ql" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-cb74d5db64eso1543931a12.2 for ; Mon, 20 Jul 2026 10:55:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784570119; x=1785174919; darn=vger.kernel.org; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=XH5gGKH7ZMsz/ICb8uMDOlGzTuN7H6pnWfYS/BF91AI=; b=O2iBx5QlfsA/W5FkaklzhFHWPMqq/SlnQOwBku0TcXZp36zVpvitgqOS7fw2Y62hbj WYM8VVRDZzmSWyaEkgQLqNaFdF3e4KpzPKHy3s2FKg8rLPTy7MCbRI/5+PRMKeW4aUFO JX2EYljOA8YxFQlk2B+E5yHFZKTI1o2xQtA+yGa5djGV+W+korCPzOhpEdJd3KcF5NFh xhrBTzRFXGh/US0/E5kfBYeOhL5zRiXmjlJh9iaz+dWfkzv1yg54QAPpfhot8FiGqCXy Q51FZFS10o9CTzlvmkmDb87HZtrVxPzFigTmtQCkpFi1DyuOE+0tflqM9cjj7L4Jo2uq udEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784570119; x=1785174919; h=content-type:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XH5gGKH7ZMsz/ICb8uMDOlGzTuN7H6pnWfYS/BF91AI=; b=jiJNlszj7jIbVshvn9dR7De8XRdosCHUhWjy/4aZKz69lHb0ZClmDie70YqbPAlTOe 8XFLAXFWaLtfB488GTBH+lmve99+P84NKPv5Q0o2isbd0P+c33dOD2Qen/ilRa0Duxim NV640rhwFQ0Sy9UvhKejGAfIkQf4CCStwszxUNd80RSyt0VK5bEl+aegEh/t1amF+lZF jLZbcABsRyzE+iYy4dow9wmDGc2RQ8vqKUpUk1eCdnAjYnHQXAeS1a21KRufXmOvm5C5 3w0U3nLOZ8feD74rYWTl27CD0sIboJkt5RwFXIR1O2EzpbjyC5eeczPJt1gQQK5UO0p9 aXhg== X-Forwarded-Encrypted: i=1; AHgh+RoR6QTwDxqQG51HAHZ1fkBYGq3dtzYce7DF57+wXKlflvucb2z+N7Etqb2RRuYvZMdUL5Z17g7YrIJqEwA=@vger.kernel.org X-Gm-Message-State: AOJu0Yz1aCuA15OnMoSzq7ZZN5BxefulI5NahdozvQk0Yu4a4bp7QSja mJiMTQDkTKvPR1F6NEGOYE5bvKjVWxzAVeaCAAAOFt50XLCAkDKCAYWvn1NiARITs+0qs+KnOVH PjwMRT9PPjg== X-Received: from dlj39.prod.google.com ([2002:a05:7022:527:b0:13c:e616:911a]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a20:b786:b0:3c3:8c91:5da0 with SMTP id adf61e73a8af0-3c3ad793aacmr16123503637.15.1784570119323; Mon, 20 Jul 2026 10:55:19 -0700 (PDT) Date: Mon, 20 Jul 2026 10:54:55 -0700 In-Reply-To: <20260720175455.3645946-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720175455.3645946-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260720175455.3645946-5-irogers@google.com> Subject: [PATCH v1 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis From: Ian Rogers To: Peter Zijlstra , Ingo Molnar , Arnaldo Carvalho de Melo , Namhyung Kim , Jiri Olsa , Ian Rogers , Adrian Hunter , James Clark , Ravi Bangoria , Swapnil Sapkal , linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix a critical logic bug in perf_event__synthesize_mmap2_build_id() where the wrong union member structure size and offset boundaries were utilized. Safely calculate and clamp maximum filename length to guarantee absolute stack boundary protections for ID sample trailers, and remove void-pointer arithmetic to meet strict standard C compliance. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index aab958cb3bc5..cb5b659822f5 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -2441,13 +2441,16 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, size_t filename_len =3D strlen(filename); size_t ev_len; u64 sample_type =3D sample->evsel ? sample->evsel->core.attr.sample_type = : 0; - void *array; + void *array =3D &ev; int ret; + size_t max_filename_len; =20 - if (filename_len >=3D sizeof(ev.mmap2.filename)) - return -EINVAL; + max_filename_len =3D sizeof(ev.mmap2.filename) - (MAX_ID_HDR_ENTRIES * si= zeof(__u64)); =20 - ev_len =3D sizeof(ev.mmap2) - sizeof(ev.mmap2.filename) + filename_len + = 1; + if (filename_len > max_filename_len) + filename_len =3D max_filename_len; + + ev_len =3D offsetof(struct perf_record_mmap2, filename) + filename_len + = 1; ev_len =3D PERF_ALIGN(ev_len, sizeof(u64)); =20 if (ev_len + MAX_ID_HDR_ENTRIES * sizeof(__u64) > sizeof(ev)) @@ -2467,16 +2470,15 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, =20 ev.mmap2.build_id_size =3D bid->size; if (ev.mmap2.build_id_size > sizeof(ev.mmap2.build_id)) - ev.build_id.size =3D sizeof(ev.mmap2.build_id); + ev.mmap2.build_id_size =3D sizeof(ev.mmap2.build_id); memcpy(ev.mmap2.build_id, bid->data, ev.mmap2.build_id_size); =20 ev.mmap2.prot =3D prot; ev.mmap2.flags =3D flags; =20 - memcpy(ev.mmap2.filename, filename, min(strlen(filename), sizeof(ev.mmap.= filename))); + strlcpy(ev.mmap2.filename, filename, filename_len + 1); =20 - array =3D &ev; - array +=3D ev.header.size; + array =3D (void *)((char *)&ev + ev.header.size); ret =3D perf_event__synthesize_id_sample(array, sample_type, sample); if (ret < 0) return ret; --=20 2.55.0.229.g6434b31f56-goog