From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8B6ED46D0BC for ; Tue, 21 Jul 2026 17:34:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655244; cv=none; b=S1Do48nZqnRdnN+P1tI3deOYwOJRskdCX9ayse1E1mZ/s9cZzHrcNM4bT56nplp6+Rst7/LQo74btSmRQkO3imgSZVbuY7hsDZq0ykKozOUKeAdMF+wiDIr/PaC0Cri/fWdmsmdP1NPAO/jiothA/ATdJ5FvSAZeqpAsxX8vpQQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655244; c=relaxed/simple; bh=pj0KjjICAGQcYFvJa34O/R6iaQNWxgcdqHf3gBWUcgM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=nB+zPd+lbMgblBDiiseBLYr4YFu7dVCEyRALcoapFTomP2/sknpHaFZ8/hcXvqJXvlJWs71PzuJWWg1UrEaGao3Xs66KfOPPgv0CcYcShNyvITWXzEKANin7d7p7CAYOrjBLZyg4bDZymZMH6R5hIXBzsh+AJNSldN4bUPaqYxs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=FBbrvtTK; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="FBbrvtTK" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-38ea32e57e2so195594a91.1 for ; Tue, 21 Jul 2026 10:34:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784655243; x=1785260043; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=FBbrvtTK5N94NskrK0GZ29oSfu2XTZX2j9SlHfAOoPiCYjoXjqTp8jJm3NlUqAjusM RAG6dV0QPSbhq6GQBqRKpjDKifSyAeizFtQdv8q0BFkw3yMVxk24SDwnDFwoxBOztDPH R+aiwamAXTvdIGbplWDvNnjED14YjqRlRoSG8KjOMbhvC2/pgBvKYY1WBQuSjFto/oUh 9m1KV/UB4WYSZPcSvPfO3hE/MIiO7Hr/rdBLm4oWpBsvH1urpU5KmjjSFpxupFub8cGb dfT9AXPJz3BEB371A5NjuXUgsqN4In1dJjtlrCsTiC3P46SP/KBBj6oh4jQvtQe7UtVz sMKg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784655243; x=1785260043; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=R/suauV1zN4Zb2e0uVHb0NMuD3jJEopbf37+K8KtpA8QGSWV3Yc/kVv3X0y5j8ldP6 6XU0zLIROBAOXJU9LfJX8snhp/PwOSw8OM7ymTmG907sPjd7Za3syqVVuAA5u45n7dyh QvyVUuYj2ZcPQjwQyLLxOZkkJMT8OzCKwosip+cpaQqKEtJJYh6gwPFeKAeztULu0gBG wDrlNF9toa80AWXCgVdo1y8vhJ6Zcs8X8wyjStXqFEe9Mx8JKOThjTzOBnDg7pu8vyt8 09aFGn0KlSH2pm10VVnsRCaSrHqWAjJq0h/Luf9mFu6zFfBBnnBAUPE8u2CvoY313diX VxaA== X-Forwarded-Encrypted: i=1; AHgh+RpRzZPpBYC9AuRDnMDzLW1MEKQgPjGaLr5A+somdt7Oy3pCQWU6XCxMV6uYT2bVe8ppjODDGz6bo5TL/NA=@vger.kernel.org X-Gm-Message-State: AOJu0YxrXGwV0fPzPuk/Ohk5HwegCk0sP94qTpJLRWo+s2a0IVfFjfjM fccnxqvcn5zH7u5LHW4TSiKYtt9jrCm1202RIisuCjCMnR/9IUxSZTtXpOFWKaiNtRe3AVEAlAu R8KuTziNYcQ== X-Received: from dlbqc12.prod.google.com ([2002:a05:7023:a8c:b0:13b:9778:570]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:528d:b0:381:9028:5945 with SMTP id 98e67ed59e1d1-38e4b44863emr20480602a91.14.1784655242600; Tue, 21 Jul 2026 10:34:02 -0700 (PDT) Date: Tue, 21 Jul 2026 10:33:44 -0700 In-Reply-To: <20260721173347.9163-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720225200.3810501-1-irogers@google.com> <20260721173347.9163-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721173347.9163-2-irogers@google.com> Subject: [PATCH v3 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use getline() to dynamically allocate the required line buffer for maps parsing, guaranteeing bounds safety and avoiding compiler warnings by evaluating the return value in the loop condition directly. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/find-map.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/find-map.c b/tools/perf/util/find-map.c index 7b2300588ece..bba511795a69 100644 --- a/tools/perf/util/find-map.c +++ b/tools/perf/util/find-map.c @@ -1,8 +1,13 @@ // SPDX-License-Identifier: GPL-2.0 +#include +#include +#include + static int find_map(void **start, void **end, const char *name) { FILE *maps; - char line[128]; + char *line =3D NULL; + size_t len =3D 0; int found =3D 0; =20 maps =3D fopen("/proc/self/maps", "r"); @@ -11,7 +16,7 @@ static int find_map(void **start, void **end, const char = *name) return -1; } =20 - while (!found && fgets(line, sizeof(line), maps)) { + while (!found && getline(&line, &len, maps) !=3D -1) { int m =3D -1; =20 /* We care only about private r-x mappings. */ @@ -25,6 +30,7 @@ static int find_map(void **start, void **end, const char = *name) found =3D 1; } =20 + free(line); fclose(maps); return !found; } --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DB66446DFE5 for ; Tue, 21 Jul 2026 17:34:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655247; cv=none; b=Tol7QyEz6ceNUZOycNW5K/cNS77WrfCT281IpZhn4uK7XkLVl6G2oNahm4kj50C4sfz0gI6joxL9N/96Y7fC8F8o47uGsUTq950STvzB3mBFLpjgdNyhDYvLLvqf2Jj2F7GWbniTonhX3751wrqK9zcJ2kgMC20abGgDSpcuz3w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655247; c=relaxed/simple; bh=3wWG303Mi00lwKOloAJVM+64fgwc2/pnNdIhwKqSm6o=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=UiM5rMv3qasM4fNBXb4PzCy78WFJx96gXIBU6Ni6FiAEULY1e/OZhHN6ecFTnGsawO7PKX+J/I6jUMdQ9kRy0eEf8w+MLLhdIowMASBISQHHufuCN+RlkwwKo8WbIFCfQUxBV61L7rdtLsw8WMItTRze6jOTvvIryeVKUCoLKbI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=JGIUPG5T; arc=none smtp.client-ip=209.85.216.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="JGIUPG5T" Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-388b404eaa4so15000649a91.0 for ; Tue, 21 Jul 2026 10:34:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784655245; x=1785260045; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QKteTyvHt7cD2g0v/QB2yYzZKHYzZC0yeBK3kqeJla0=; b=JGIUPG5Tr5EnTE1ERHDU1h99j4tJCtW6VeqCjySyvOANEY+2mn4+odMUP8VAOeAzSU 9c01fCimKFzqW00O+mp6ESbFWrlw6kTnesFvjciXKwjIuXXiopAGmzJ8dXGad1cMB6kM VV5dR/1T0aXu/DedHg2wiQccr+TdgAiY1cWWy+c11XrJbId7Imv8rMAcvJ0qOEWrjR/t tMLrrC80leTQ6qhf4mFGM+prbLY+xWEq9EE5ZlGMbi3VpMIKY9qZO930cTJIeZwkcn0H Fb7qRBMyUEwSrlwxekf3i5AsIxFQi3lk9/ouqR4p/q6Bof/4th8ANP5IoAg8XmDmGlcZ Bg4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784655245; x=1785260045; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=QKteTyvHt7cD2g0v/QB2yYzZKHYzZC0yeBK3kqeJla0=; b=TPU1FCXLODzC7FPMPNQNPDpaHoXkLFqz7bCZ9++hc+eONKLxokIdrbBo4lXBKyt7Q3 WOOUj2rmOptbhp6BkQQRYcJvE5Am05dizESmvRl3W2E4Cfg7F/cguFDmrQSApTVqUilu YzXv1pc0cD5VOeT5DxueQJPPc26SYgPBhUPbU52mNbMTlonNj5OSC9BlOHr2hrE9O+oN JMA3iCQncw17ClvlY/+HpLOYuY6cXXw9pAIw1FG8+STqYicaZNB+k98mJviL7Wuakx5v 8INdQraobgs9facrUvuFtBHiQcjwp0KH4DN0ORulMEWxy+6dh7hyzX068TxU5Ei2jsCR EXBA== X-Forwarded-Encrypted: i=1; AHgh+Rpp39lXEqTe/Qdg/RDKqaYpX9H/P4VCAR17Ki/jCI5CSXVCDqZsWlmDeR6ZeCO+8hKM73sZ6bLWsnr3xzY=@vger.kernel.org X-Gm-Message-State: AOJu0YwF/bletowU789oStDUEm3Jah9E7o5WRh1yPojv3beTf0j5++Eo 2jmtOf1Y6yonC7dodRE1sZBz8aOFJrqwEOSyVt2jVpVp/qYlK8h2M7zbvCC0B2dyHMTNTHaMrbD nQxpJ+GnhFw== X-Received: from dlbuy7.prod.google.com ([2002:a05:7022:1e07:b0:13c:f3ec:de27]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:1d52:b0:38e:dc4:3f64 with SMTP id 98e67ed59e1d1-38e4b5860f9mr20056726a91.38.1784655244846; Tue, 21 Jul 2026 10:34:04 -0700 (PDT) Date: Tue, 21 Jul 2026 10:33:45 -0700 In-Reply-To: <20260721173347.9163-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720225200.3810501-1-irogers@google.com> <20260721173347.9163-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721173347.9163-3-irogers@google.com> Subject: [PATCH v3 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix critical logic and boundary bugs in read_proc_maps_line() and caller. Ensure any mid-line hex/dec/char parsing failure invokes io__drain_line() safely, ignoring already-consumed newlines to preserve synchronization for subsequent map entries. Use standard '//toolong' fallback literal for over-length pathnames, and emit timeout flags for truncated entries securely via goto out;. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 197 ++++++++++++++++++++--------- 1 file changed, 137 insertions(+), 60 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index b75f9dcf4dbf..9a2b4d561e9e 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -291,6 +291,17 @@ static int perf_event__synthesize_fork(const struct pe= rf_tool *tool, return 0; } =20 +static void io__drain_line(struct io *io, int ch) +{ + if (ch =3D=3D '\n') + return; + if (ch =3D=3D -2 && io->data > io->buf && io->data[-1] =3D=3D '\n') + return; + + while (ch >=3D 0 && ch !=3D '\n') + ch =3D io__get_char(io); +} + static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end, u32 *prot, u32 *flags, __u64 *offset, u32 *maj, u32 *min, @@ -299,69 +310,127 @@ static bool read_proc_maps_line(struct io *io, __u64= *start, __u64 *end, { __u64 temp; int ch; - char *start_pathname =3D pathname; + size_t written =3D 0; + bool overflowed =3D false; =20 - if (io__get_hex(io, start) !=3D '-') + ch =3D io__get_hex(io, start); + if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_hex(io, end) !=3D ' ') + } + ch =3D io__get_hex(io, end); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 /* map protection and flags bits */ *prot =3D 0; ch =3D io__get_char(io); if (ch =3D=3D 'r') *prot |=3D PROT_READ; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'w') *prot |=3D PROT_WRITE; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'x') *prot |=3D PROT_EXEC; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 's') *flags =3D MAP_SHARED; else if (ch =3D=3D 'p') *flags =3D MAP_PRIVATE; - else + else { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_char(io) !=3D ' ') + } + ch =3D io__get_char(io); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, offset) !=3D ' ') + ch =3D io__get_hex(io, offset); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, &temp) !=3D ':') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ':') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *maj =3D temp; - if (io__get_hex(io, &temp) !=3D ' ') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *min =3D temp; =20 ch =3D io__get_dec(io, inode); if (ch !=3D ' ') { - *pathname =3D '\0'; - return ch =3D=3D '\n'; + if (ch =3D=3D '\n') { + pathname[0] =3D '\0'; + return true; + } + if (!io->eof) + io__drain_line(io, ch); + return false; } + do { ch =3D io__get_char(io); } while (ch =3D=3D ' '); + while (true) { - if (ch < 0) - return false; - if (ch =3D=3D '\0' || ch =3D=3D '\n' || - (pathname + 1 - start_pathname) >=3D pathname_size) { - *pathname =3D '\0'; - return true; + if (ch < 0) { + if (overflowed) { + strlcpy(pathname, "//toolong", pathname_size); + return true; + } + pathname[written] =3D '\0'; + return written > 0; } - *pathname++ =3D ch; + if (ch =3D=3D '\0' || ch =3D=3D '\n') + break; + + if (written < (size_t)pathname_size - 1) + pathname[written++] =3D (char)ch; + else + overflowed =3D true; ch =3D io__get_char(io); } + + if (overflowed) + strlcpy(pathname, "//toolong", pathname_size); + else + pathname[written] =3D '\0'; + + return true; } =20 static void perf_record_mmap2__read_build_id(struct perf_record_mmap2 *eve= nt, @@ -463,45 +532,53 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, while (!io.eof) { static const char anonstr[] =3D "//anon"; size_t size, aligned_size; - - /* ensure null termination since stack will be reused. */ - event->mmap2.filename[0] =3D '\0'; + __u64 start, end, pgoff, ino; + u32 prot, flags, maj, min; =20 /* 00400000-0040c000 r-xp 00000000 fd:01 41038 /bin/cat */ - if (!read_proc_maps_line(&io, - &event->mmap2.start, - &event->mmap2.len, - &event->mmap2.prot, - &event->mmap2.flags, - &event->mmap2.pgoff, - &event->mmap2.maj, - &event->mmap2.min, - &event->mmap2.ino, - sizeof(event->mmap2.filename), - event->mmap2.filename)) + /* Read directly into event->mmap2.filename! */ + if (!read_proc_maps_line(&io, &start, &end, + &prot, &flags, &pgoff, + &maj, &min, &ino, + sizeof(event->mmap2.filename), + event->mmap2.filename)) { + if (io.eof) + break; continue; + } =20 - if ((rdclock() - t) > timeout) { - pr_warning("Reading %s/proc/%d/task/%d/maps time out. " - "You may want to increase " - "the time limit by --proc-map-timeout\n", - machine->root_dir, pid, pid); - truncation =3D true; - goto out; + if (!strcmp(event->mmap2.filename, "")) + strcpy(event->mmap2.filename, anonstr); + + if (hugetlbfs_mnt_len && + !strncmp(event->mmap2.filename, hugetlbfs_mnt, hugetlbfs_mnt_len)) { + strcpy(event->mmap2.filename, anonstr); + flags |=3D MAP_HUGETLB; } =20 - event->mmap2.ino_generation =3D 0; + size =3D strlen(event->mmap2.filename) + 1; + aligned_size =3D PERF_ALIGN(size, sizeof(u64)); + + event->mmap2.header.type =3D PERF_RECORD_MMAP2; =20 /* - * Just like the kernel, see __perf_event_mmap in kernel/perf_event.c + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) event->header.misc =3D PERF_RECORD_MISC_USER; else event->header.misc =3D PERF_RECORD_MISC_GUEST_USER; =20 - if ((event->mmap2.prot & PROT_EXEC) =3D=3D 0) { - if (!mmap_data || (event->mmap2.prot & PROT_READ) =3D=3D 0) + if ((rdclock() - t) > timeout) { + pr_warning("Reading %s/proc/%d/task/%d/maps time out. You may want to i= ncrease the time limit by --proc-map-timeout\n", + machine->root_dir, pid, pid); + truncation =3D true; + goto out; + } + + if ((prot & PROT_EXEC) =3D=3D 0) { + if (!mmap_data || (prot & PROT_READ) =3D=3D 0) continue; =20 event->header.misc |=3D PERF_RECORD_MISC_MMAP_DATA; @@ -511,26 +588,26 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, if (truncation) event->header.misc |=3D PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT; =20 - if (!strcmp(event->mmap2.filename, "")) - strcpy(event->mmap2.filename, anonstr); + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; =20 - if (hugetlbfs_mnt_len && - !strncmp(event->mmap2.filename, hugetlbfs_mnt, - hugetlbfs_mnt_len)) { - strcpy(event->mmap2.filename, anonstr); - event->mmap2.flags |=3D MAP_HUGETLB; - } + /* Zero the padding and ID header trailer safely! */ + memset(event->mmap2.filename + size, 0, + (aligned_size - size) + machine->id_hdr_size); =20 - size =3D strlen(event->mmap2.filename) + 1; - aligned_size =3D PERF_ALIGN(size, sizeof(u64)); - event->mmap2.len -=3D event->mmap.start; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - aligned_size)); - memset(event->mmap2.filename + size, 0, machine->id_hdr_size + - (aligned_size - size)); event->mmap2.header.size +=3D machine->id_hdr_size; + event->mmap2.start =3D start; + event->mmap2.len =3D end - start; + event->mmap2.pgoff =3D pgoff; + event->mmap2.maj =3D maj; + event->mmap2.min =3D min; + event->mmap2.ino =3D ino; + event->mmap2.ino_generation =3D 0; event->mmap2.pid =3D tgid; event->mmap2.tid =3D pid; + event->mmap2.prot =3D prot; + event->mmap2.flags =3D flags; =20 if (!symbol_conf.no_buildid_mmap2) perf_record_mmap2__read_build_id(&event->mmap2, machine, false); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C2B4346E013 for ; Tue, 21 Jul 2026 17:34:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655249; cv=none; b=K/jEs/SSJOKQqu4+dP0UFG9r9hYHixZEl3YRAaoB3M9rNFB+eSR909ke49g6c8VAwt5EUHFkF27ddeNifeoFIkiXcV5l4nVqGDrjandlhDPMu3TUKDu3LJ7S/KFLLghQjJKMWVOfUUW7gF25UFs8TBb+ml+HjWFSpZwicmpihM0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655249; c=relaxed/simple; bh=5HHYV2YtuskvpVXWLLiEwNUcmcEMrY8dXvLciuEgNo4=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=rQNno9FaWjVNvYe1uwJG2+Btb7RkCoc47oXA92neoY6t2lAKsYe3aY7FQev3gxucTKKmcymXnUQrebflESypRyFiFqk5D35BllaR3h9kdhZe4vTht9be0EHcqa8RzjxrH2cJxVyhzQugU7FWpb7efWjmc1rJd08t6MHl5zF2x/Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=QrcWUTkH; arc=none smtp.client-ip=209.85.215.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="QrcWUTkH" Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-cb6ef846b33so2260733a12.1 for ; Tue, 21 Jul 2026 10:34:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784655247; x=1785260047; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=dVysXzCxvN0YWO4pl9MoMoRFZ8JrR13DJYNHpKFDQUI=; b=QrcWUTkHE114E7/73aCuWVO78Dg69vNN63FnEcdFqdB6zpCF09Hc/37JmCPGXONDr3 9YI/tnODDZEZyqRjsrGFAA5hSLHVXedOuHx5tdXgkLC1dMLpxIuCg3CfTs7CAwHJWSpy J+Nte1rb53/ht8XVL1kaZclpPm9GfOPq9QBwS6hjUF6BrEns6G/Yum1d6N8jrk3+fsY2 oK+vx3e4FR/SMoyCnAmq1iehtvZ91wgvbcFlVlCY397o3FXI+tnZbcxQ7ynsUPXDMO7E z8505BqumwTEIfg0ZPXsNjbWQaJ9EYVJWOc+HQHks33QOblarJTDi9DSOi++d+DjUD2F lYtQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784655247; x=1785260047; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dVysXzCxvN0YWO4pl9MoMoRFZ8JrR13DJYNHpKFDQUI=; b=nuwvg+Zo8cJXUb4ZcnSpLirxrq6kaJneje2NPiUYf4zMGh5IIywMOyuqmQYSiPk2VV jDaiso822GJt+S5SUDiaXwUvQacHSsKNN12MCveGcphthhiE2REUt0AS37fFJhVT5ahI /coXGaYUENsss6v9wIbGT2DuOEyivA68wgTY3ET+KIlDOGTrWzrTyhk2JbmOFlPSkNar s0YcwW531MpRfbU8itVxFEtJ7HLkRbTcUisqN4GHBGmDxLeJlPF3YlZBfauTdlduJcpP S7OLAJquqKucI0fTtejho/eP4r35VZjUCHNvZwyCeeXIcdVI3gi3njMguVkpA2ZY5m5s spFw== X-Forwarded-Encrypted: i=1; AHgh+RpBtDwbN/IuHnOjen7Sei2+NImZ6+/wkJtycUpqKy1VDqmYCqhETbnm7IjhSzCV/v7zhNiGfRCiUidE+TY=@vger.kernel.org X-Gm-Message-State: AOJu0Yxa9l8DuKUwrMesomp7DSLZXKP25t79vri767l+Oz8SZkWdV3Li w7omU3/c3PYmYyCojS1r5k2SVkk7Gxun4JcHrouKe+C5HAvwzj9PKSXcrjAOagxjH/hRIizVHbB eLPCeSxg5BA== X-Received: from dldyq2-n2.prod.google.com ([2002:a05:701b:4542:20b0:139:ce3e:27b3]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:4d05:b0:3bd:1cfc:1b9b with SMTP id adf61e73a8af0-3c4292c1e37mr586336637.10.1784655246881; Tue, 21 Jul 2026 10:34:06 -0700 (PDT) Date: Tue, 21 Jul 2026 10:33:46 -0700 In-Reply-To: <20260721173347.9163-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720225200.3810501-1-irogers@google.com> <20260721173347.9163-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721173347.9163-4-irogers@google.com> Subject: [PATCH v3 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix potential buffer overruns in perf_event__synthesize_modules_maps_cb() by safely clamping long DSO names to the mmap/mmap2 filename boundaries. Explicitly assign and clear the misc flags and union padding across all iterations to prevent stale Build-ID state from leaking between module synthesis events. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 70 +++++++++++++++++++++--------- 1 file changed, 50 insertions(+), 20 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 9a2b4d561e9e..068323b9510d 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -754,6 +754,7 @@ struct perf_event__synthesize_modules_maps_cb_args { perf_event__handler_t process; struct machine *machine; union perf_event *event; + u16 misc; }; =20 static int perf_event__synthesize_modules_maps_cb(struct map *map, void *d= ata) @@ -761,49 +762,78 @@ static int perf_event__synthesize_modules_maps_cb(str= uct map *map, void *data) struct perf_event__synthesize_modules_maps_cb_args *args =3D data; union perf_event *event =3D args->event; struct dso *dso; - size_t size; + size_t size, aligned_size; + int rc =3D 0; =20 if (!__map__is_kmodule(map)) return 0; =20 dso =3D map__dso(map); if (!symbol_conf.no_buildid_mmap2) { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap2.filename)) + size =3D sizeof(event->mmap2.filename) - 1; + + strlcpy(event->mmap2.filename, long_name, + sizeof(event->mmap2.filename)); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap2.header.type =3D PERF_RECORD_MMAP2; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - size)); - memset(event->mmap2.filename + size, 0, args->machine->id_hdr_size); + event->mmap2.header.misc =3D args->misc; + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset(event->mmap2.filename + size, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap2.header.size +=3D args->machine->id_hdr_size; event->mmap2.start =3D map__start(map); event->mmap2.len =3D map__size(map); event->mmap2.pid =3D args->machine->pid; =20 - memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); - - /* Clear stale build ID from previous module iteration */ + /* Clear stale build ID and entire union from previous module iteration = */ event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); event->mmap2.build_id_size =3D 0; + event->mmap2.__reserved_1 =3D 0; + event->mmap2.__reserved_2 =3D 0; =20 perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap.filename)) + size =3D sizeof(event->mmap.filename) - 1; + + strlcpy(event->mmap.filename, long_name, + sizeof(event->mmap.filename)); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap.header.type =3D PERF_RECORD_MMAP; - event->mmap.header.size =3D (sizeof(event->mmap) - - (sizeof(event->mmap.filename) - size)); - memset(event->mmap.filename + size, 0, args->machine->id_hdr_size); + event->mmap.header.misc =3D args->misc; + event->mmap.header.size =3D + offsetof(struct perf_record_mmap, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset(event->mmap.filename + size, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap.header.size +=3D args->machine->id_hdr_size; event->mmap.start =3D map__start(map); event->mmap.len =3D map__size(map); event->mmap.pid =3D args->machine->pid; - - memcpy(event->mmap.filename, dso__long_name(dso), dso__long_name_len(dso= ) + 1); } =20 if (perf_tool__process_synth_event(args->tool, event, args->machine, args= ->process) !=3D 0) - return -1; + rc =3D -1; =20 - return 0; + return rc; } =20 int perf_event__synthesize_modules(const struct perf_tool *tool, perf_even= t__handler_t process, @@ -828,13 +858,13 @@ int perf_event__synthesize_modules(const struct perf_= tool *tool, perf_event__han } =20 /* - * kernel uses 0 for user space maps, see kernel/perf_event.c - * __perf_event_mmap + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) - args.event->header.misc =3D PERF_RECORD_MISC_KERNEL; + args.misc =3D PERF_RECORD_MISC_KERNEL; else - args.event->header.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; + args.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; =20 rc =3D maps__for_each_map(maps, perf_event__synthesize_modules_maps_cb, &= args); =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0747447045D for ; Tue, 21 Jul 2026 17:34:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655251; cv=none; b=fIeAoevHFrJVKSkgWbkYn6z5lyqqtmL0ce3ExSuiC0/gSPaLO+UayI46A/61jOhI+3vYFGNsAZvEFxw03Tddvql/ajZ9WqzFKsDnPslqC+utIrio5SyxwTHP6MLMVqjIMrZiBD/CGO3hiGCpa7EXNX57jXvK0I+6+d/UKatTq5U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784655251; c=relaxed/simple; bh=CEzrLZPHqPdQhLMLgsk270qr2KafmCep5+ZkSOMjTrI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RPgWfhuqnt2kF2SEDukX9G9Vi3LP3H1/xroTNXUKwnB5AzLgDuOXy6UPPJEP4ClVTd8AtiFAx+uNCRSPlx9HkxI1R8gNrxbuv9BIM5Q8+/fWvccTCORsY1QIgd4fgS+C4zArAIz4R849QmyYUgHZJMIZQl7k3HJfb59bce+eQcY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=K7eqcyYp; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="K7eqcyYp" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-38dc085b0a7so17873461a91.2 for ; Tue, 21 Jul 2026 10:34:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784655249; x=1785260049; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ypc5c864N+DZk1m/raoCh7jyW2ktVuTgipXiePtRM3c=; b=K7eqcyYp+wUTsWX0N4hgLz8pLiY+jlbwg7d7Iv/5b11hRoVE+6UhisQ9hEHDwarGW6 XdjVqNwldcmvGfRzNKan0UdeJroU840ozxdZY9u1Tk09IfMdFqEEuEH1Qp0blfyX7g1/ wDcy3T8srUXmREg/WwB9H1rY1QwWpWJYu3kdNFFyS+7Fr7GtSiUTZXMplPaAH1WVMCF9 9QfExzjOKmTCOspVRbR20XD4hW6cl2Rn11uVKksZeFlrL3XB/IRZxW6B6af/KYA7xsJx f/j1TuTM2zC9Xu2mFQktJY8Tlf5mQ6crLthoCpIRXtWx6HVjM9qD/TCkaWMqufCIEB40 l0mw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784655249; x=1785260049; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ypc5c864N+DZk1m/raoCh7jyW2ktVuTgipXiePtRM3c=; b=ispdTxcInTynYJRDmkD5vUusv3UFS9B8eIoyNxVrJtv8BKdBhinfth+AHSuDBDBPD4 TFZOrglb24Y8cmmosBs/pfOF78iM3NaOutQm6BHaP/FiNUB3McCbROq87gSUcqpQ3AGM dBtIRjm0a7VAI//y6gDGKqAQp9N3yxe6RBcdm9ggEJOdDHR5zlnQxcxB8Q6zNOAHzyQI Q7OBpN8NyccOGky5sRCR9MvOxjiiOPdFfYzqtsPe2Wu8tlcHNN1ZcmI5q1fjDEvZOVhg lHfLHzKGgZufXIURS/0HMlc6cZ8ud3bLtR5StcW53drGv0TKM2xwuJmGxc580wlL+l8r mD5w== X-Forwarded-Encrypted: i=1; AHgh+RolOmrVYqRbm6SfXHWIHcBVp8QcVDKuxceRIJGiz90YILdxofR5k6Es8uNXYTZ8L1v5z99wHydfCI5qNzo=@vger.kernel.org X-Gm-Message-State: AOJu0YxoR0DJnGs1ysMK6USAIH64rTCfFhhxZ4G+sGrACFoPqyds0Qj0 kPl5NS6NuvCCi4japQOofvGtwmhAg0UTTKFLkPqfnQjZE/P3QWm8jphG1SVPHnj3daLc7vRvA64 9j89dPTr44Q== X-Received: from dlbvg20.prod.google.com ([2002:a05:7022:7f14:b0:13c:f3ec:ddf4]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:5604:b0:37f:9ce2:348f with SMTP id 98e67ed59e1d1-38e4b55ab8dmr19806756a91.32.1784655248954; Tue, 21 Jul 2026 10:34:08 -0700 (PDT) Date: Tue, 21 Jul 2026 10:33:47 -0700 In-Reply-To: <20260721173347.9163-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260720225200.3810501-1-irogers@google.com> <20260721173347.9163-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721173347.9163-5-irogers@google.com> Subject: [PATCH v3 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix a critical logic bug in perf_event__synthesize_mmap2_build_id() where the wrong union member structure size and offset boundaries were utilized. Safely calculate the exact maximum allowed filename length to guarantee absolute stack and alignment boundaries for ID sample trailers, preventing -E2BIG overruns on very long filenames while meeting strict standard C compliance. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 068323b9510d..6477a726c8ba 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -298,8 +298,9 @@ static void io__drain_line(struct io *io, int ch) if (ch =3D=3D -2 && io->data > io->buf && io->data[-1] =3D=3D '\n') return; =20 - while (ch >=3D 0 && ch !=3D '\n') + do { ch =3D io__get_char(io); + } while (ch >=3D 0 && ch !=3D '\n'); } =20 static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end, @@ -2447,13 +2448,18 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, size_t filename_len =3D strlen(filename); size_t ev_len; u64 sample_type =3D sample->evsel ? sample->evsel->core.attr.sample_type = : 0; - void *array; + void *array =3D &ev; int ret; + size_t max_filename_len; =20 - if (filename_len >=3D sizeof(ev.mmap2.filename)) - return -EINVAL; + max_filename_len =3D sizeof(ev) - + (MAX_ID_HDR_ENTRIES * sizeof(__u64)) - + offsetof(struct perf_record_mmap2, filename) - 1; =20 - ev_len =3D sizeof(ev.mmap2) - sizeof(ev.mmap2.filename) + filename_len + = 1; + if (filename_len > max_filename_len) + filename_len =3D max_filename_len; + + ev_len =3D offsetof(struct perf_record_mmap2, filename) + filename_len + = 1; ev_len =3D PERF_ALIGN(ev_len, sizeof(u64)); =20 if (ev_len + MAX_ID_HDR_ENTRIES * sizeof(__u64) > sizeof(ev)) @@ -2473,16 +2479,15 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, =20 ev.mmap2.build_id_size =3D bid->size; if (ev.mmap2.build_id_size > sizeof(ev.mmap2.build_id)) - ev.build_id.size =3D sizeof(ev.mmap2.build_id); + ev.mmap2.build_id_size =3D sizeof(ev.mmap2.build_id); memcpy(ev.mmap2.build_id, bid->data, ev.mmap2.build_id_size); =20 ev.mmap2.prot =3D prot; ev.mmap2.flags =3D flags; =20 - memcpy(ev.mmap2.filename, filename, min(strlen(filename), sizeof(ev.mmap.= filename))); + strlcpy(ev.mmap2.filename, filename, filename_len + 1); =20 - array =3D &ev; - array +=3D ev.header.size; + array =3D (void *)((char *)&ev + ev.header.size); ret =3D perf_event__synthesize_id_sample(array, sample_type, sample); if (ret < 0) return ret; --=20 2.55.0.229.g6434b31f56-goog