From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D8024415F0F for ; Tue, 21 Jul 2026 18:22:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658122; cv=none; b=ItmhtR4Va875OevO7iMUqhZNAOrT7XYLcu8oGMqNomKIKsSKIrUPBcU7SDAGMCJRwnjN8aylgyl0KiuNOV87XOGSkioGsZ0HiPdH8OBHpkEvTKFrIFWBb7+LTTfkZQz5CHmum9ECntw/Lo+BBDONZsadIj5cgxUPvvZr/Sxo9zo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658122; c=relaxed/simple; bh=pj0KjjICAGQcYFvJa34O/R6iaQNWxgcdqHf3gBWUcgM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=fGPs7bK/ToD/9L8cXBu26sYBgNiaqaU0oU9UyMEKPZHS911DkDX6A8WzbELFxCmW5mB9k0v3pJMtBNqH91tXT0C+6NpyJ6NFd+cnntHmi02yVesAhXVBOBSODX/ogcunX5SR3pxIIWSRly45DXcDny7+XNwI3lOCJO8HDVf0yX4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=c3Yy02rF; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="c3Yy02rF" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-380b630c505so14737996a91.1 for ; Tue, 21 Jul 2026 11:22:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784658120; x=1785262920; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=c3Yy02rFw7nHjaTA/cEdX+8oKZsYsMYHSG7x+RRprzauU/kvVnDnneMkA7RKpuuTVM oHa2ExeXiA+paJeMkeaMvvG20oDUN+43sGCDI/nbk+aaFjW691FCDDPdgDHDbZhuBDRH nolvuNkV9T5ufytNm+Y42LMMebXJROWW+/dplVdURUUo2YH1iWJZZEWS24Di9nrFfNqQ Z9tVcfMmPxMvUdETXeoPGn3XrX24F/JaX4aCFf3nE0PZfPNO5eSLkE7X3/EqOC+6dj0c aM+axGY1zXwU/XbWewSZwjf+jBdxL5uq3WaIcX/rqndYbgwkJxQtQ754WfBv2HnBRmsx 5v5w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784658120; x=1785262920; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=BDuWwfuN2nCfUImYeG6SFpfB4Rwm5W1vKrVQwOYzevAlqXA5uvV+dihU/l4iapgXmg f2yuwuiUUfll8if5QGytb/3yBQCot3BxFwuZNRZR8HfPTn7c8TzxWQoQ3zdx6tg+Mpdv dZvc/0uX/nrQB1IglicGXEmV+KMVDyYuWO8++Tqd93z/V7kMkDtMMtQhrAwIorl5hUFP YQBbe59QYujWE9u1NZEtgVhuaUcn5V0eKNvhPc48wwy/v4yRxB5twZCA+ZGdzeCaVclh LQScp+gVYaSg/Jx58DsUW5bm/ZI8FsF94yS4ylmsms9/0IU6F0G0JqgMuHsc50RK+8oB 8ZHA== X-Forwarded-Encrypted: i=1; AHgh+Rpu7wlzPkQb0q36brfV6F2D4kuugS8+Eu2KiawFevVtfA5za++hKGGDDuTaLsyNOJGgj4V7ePhfczpHXA8=@vger.kernel.org X-Gm-Message-State: AOJu0YxFPiDE6kTOKTBTzm7WW+bhGzFXX6IqIp+xwsvMWL+B1jD2xccR 0jrYLbcyht7kHB5FtX0fdKqb5xoeKlAd6TcERUCQkbixbSOqlSXF5IwP4JDK8XZgW1zwWG5hYCy ppZ+FrudDQA== X-Received: from dlbem11.prod.google.com ([2002:a05:7022:100b:b0:139:b9a8:f222]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:2244:b0:381:bc4c:da5b with SMTP id 98e67ed59e1d1-38e4b43cb05mr18989294a91.18.1784658119436; Tue, 21 Jul 2026 11:21:59 -0700 (PDT) Date: Tue, 21 Jul 2026 11:21:47 -0700 In-Reply-To: <20260721182150.94016-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721173347.9163-1-irogers@google.com> <20260721182150.94016-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721182150.94016-2-irogers@google.com> Subject: [PATCH v4 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use getline() to dynamically allocate the required line buffer for maps parsing, guaranteeing bounds safety and avoiding compiler warnings by evaluating the return value in the loop condition directly. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/find-map.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/find-map.c b/tools/perf/util/find-map.c index 7b2300588ece..bba511795a69 100644 --- a/tools/perf/util/find-map.c +++ b/tools/perf/util/find-map.c @@ -1,8 +1,13 @@ // SPDX-License-Identifier: GPL-2.0 +#include +#include +#include + static int find_map(void **start, void **end, const char *name) { FILE *maps; - char line[128]; + char *line =3D NULL; + size_t len =3D 0; int found =3D 0; =20 maps =3D fopen("/proc/self/maps", "r"); @@ -11,7 +16,7 @@ static int find_map(void **start, void **end, const char = *name) return -1; } =20 - while (!found && fgets(line, sizeof(line), maps)) { + while (!found && getline(&line, &len, maps) !=3D -1) { int m =3D -1; =20 /* We care only about private r-x mappings. */ @@ -25,6 +30,7 @@ static int find_map(void **start, void **end, const char = *name) found =3D 1; } =20 + free(line); fclose(maps); return !found; } --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B16B846C4DE for ; Tue, 21 Jul 2026 18:22:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658126; cv=none; b=jycezNmP70QcPIx0jbEwnWh2+UJ14hEBzA07A9whw5Cb9U/X1QOvC1Id/qvkX1o+ikdWdFfpaX17OmZm3ndr2f8A71/O1FaGUHVZ6vYszelL2N/LzeRb0RhWqfQnICBfUYJKJlgE1oKurwh9dkftiy80lxO1l1hlOixAAjSDjXs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658126; c=relaxed/simple; bh=kVLUTo+ptXzuTq9tddNzRpgNOze6Hvci7+fPDEacyB0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=tOkvRYCLdv70+iGt0/xjb+fg7XBBL2OePTajvSzr6ZMyyrvAF6J+Xa/hE36a0FmJxtURzTYTXR9G2X8tqvU5/zhGVGQ7on62CbSAuWNms3+oBsqXblrLoWCIR1CWfbgPloC2XRlYdtMXKJH0nNNI1sGlpdA8WzQsFQLYMIme+MM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=tg2e+tiP; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="tg2e+tiP" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-ca860baea9fso19961883a12.2 for ; Tue, 21 Jul 2026 11:22:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784658124; x=1785262924; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pT1AGjFPyNgQFLzuI9oR5+KrNSsEKTbIXaPPVdP/DAs=; b=tg2e+tiPc8U1y+03tvJIQZveqqb8dIgOslRC/RHYbnEoeGB+xBSN+uL1Yroxvm1ZPO Kbkv4sbDL3EmhBwd3dEEx2VfrwRzBinidVuPz49rHUnihFH/7WyTb7VXdNIpw0jhZp0V M64i4XBmZss7TZfIwjyI/wPtZsrXQKNyJFOVBlXt2BSDnJNYydiCNr7JxfqyiKBS1aqX iRMQO4cxUV+KiQ61TobdYck7JzBSrkbfB2Afvyyy5oddM4qqFJvA5vmaeaE6OV5gBu1z pe+fqrKTG/mgL/TFKcZofpniwlgi/x3BGjwK2guYH4mi3Xn0QGMNwTi12QZypYetLbMG Q41w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784658124; x=1785262924; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pT1AGjFPyNgQFLzuI9oR5+KrNSsEKTbIXaPPVdP/DAs=; b=ifXbuXeACy2f5HXeWZkYQOEfnEbA8b0XswjkLOytFw19IaJ3qKUlZG2nLXh6cjb/SH P8R2Y3CXFv3l7M39eQQgwPsjYsnDWXESe5VOZN/+l8HZRBf3WdNcmFSe4QJhasc/khsA vIln+E34irkJd2ruAa1AUq5Vs7NDnz8sPeKYljFi/8o6ffAO4EjqSFDemG6WgAItjIc/ /wGDDg3XpFaPZoyIKDIjGiW6UqYl5CrAzFBFkYuaf0Nm7tQ5+VlTlhrCSbm//RFELDN8 iVXBYgIMhrcE5E9FieYWe7kT5CuE4wNTCg9N2yFe9V9aKfyH843/3XhTyAJALsJODQza aK0A== X-Forwarded-Encrypted: i=1; AHgh+RobKviMeV2j1uhZP/KS/7pV/8K5ll1b5nhCe3uGT8SBc0BNGB6xMtmjOCRmPjzMHCINiRcPkn7tP9W21FI=@vger.kernel.org X-Gm-Message-State: AOJu0YySij2LjFTNfE1Aw75/FvedyVdOEtd1XRdAYMMdiZhuP/SK60ni sxwV/NeADkg9spY4DLuJP1Vm+YR7DZl7f5qyW8psh/U8eXF0HQ1YDNKCskb5fXwRXrZpVo6k7Us 3NsI41n4hsw== X-Received: from dycjv4.prod.google.com ([2002:a05:7301:fa84:b0:314:53e1:705f]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a20:a109:b0:3c0:9c1b:d0be with SMTP id adf61e73a8af0-3c3ad9ff336mr21017749637.73.1784658123631; Tue, 21 Jul 2026 11:22:03 -0700 (PDT) Date: Tue, 21 Jul 2026 11:21:48 -0700 In-Reply-To: <20260721182150.94016-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721173347.9163-1-irogers@google.com> <20260721182150.94016-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721182150.94016-3-irogers@google.com> Subject: [PATCH v4 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix critical logic and boundary bugs in read_proc_maps_line() and caller. Ensure any mid-line hex/dec/char parsing failure invokes io__drain_line() safely, using a do-while loop to read and discard remaining characters until a newline or EOF is reached. Use standard '//toolong' fallback literal for over-length pathnames, emit timeout flags for truncated entries securely via goto out;, and cast event buffer pointers to avoid _FORTIFY_SOURCE array bounds aborts when zeroing trailers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 203 ++++++++++++++++++++--------- 1 file changed, 138 insertions(+), 65 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index b75f9dcf4dbf..60bdf2d918ea 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -291,6 +291,18 @@ static int perf_event__synthesize_fork(const struct pe= rf_tool *tool, return 0; } =20 +static void io__drain_line(struct io *io, int ch) +{ + if (ch =3D=3D '\n') + return; + if (ch =3D=3D -2 && io->data > io->buf && io->data[-1] =3D=3D '\n') + return; + + do { + ch =3D io__get_char(io); + } while (ch >=3D 0 && ch !=3D '\n'); +} + static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end, u32 *prot, u32 *flags, __u64 *offset, u32 *maj, u32 *min, @@ -299,69 +311,127 @@ static bool read_proc_maps_line(struct io *io, __u64= *start, __u64 *end, { __u64 temp; int ch; - char *start_pathname =3D pathname; + size_t written =3D 0; + bool overflowed =3D false; =20 - if (io__get_hex(io, start) !=3D '-') + ch =3D io__get_hex(io, start); + if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_hex(io, end) !=3D ' ') + } + ch =3D io__get_hex(io, end); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 /* map protection and flags bits */ *prot =3D 0; ch =3D io__get_char(io); if (ch =3D=3D 'r') *prot |=3D PROT_READ; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'w') *prot |=3D PROT_WRITE; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'x') *prot |=3D PROT_EXEC; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 's') *flags =3D MAP_SHARED; else if (ch =3D=3D 'p') *flags =3D MAP_PRIVATE; - else + else { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_char(io) !=3D ' ') + } + ch =3D io__get_char(io); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, offset) !=3D ' ') + ch =3D io__get_hex(io, offset); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, &temp) !=3D ':') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ':') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *maj =3D temp; - if (io__get_hex(io, &temp) !=3D ' ') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *min =3D temp; =20 ch =3D io__get_dec(io, inode); if (ch !=3D ' ') { - *pathname =3D '\0'; - return ch =3D=3D '\n'; + if (ch =3D=3D '\n') { + pathname[0] =3D '\0'; + return true; + } + if (!io->eof) + io__drain_line(io, ch); + return false; } + do { ch =3D io__get_char(io); } while (ch =3D=3D ' '); + while (true) { - if (ch < 0) - return false; - if (ch =3D=3D '\0' || ch =3D=3D '\n' || - (pathname + 1 - start_pathname) >=3D pathname_size) { - *pathname =3D '\0'; - return true; + if (ch < 0) { + if (overflowed) { + strlcpy(pathname, "//toolong", pathname_size); + return true; + } + pathname[written] =3D '\0'; + return written > 0; } - *pathname++ =3D ch; + if (ch =3D=3D '\0' || ch =3D=3D '\n') + break; + + if (written < (size_t)pathname_size - 1) + pathname[written++] =3D (char)ch; + else + overflowed =3D true; ch =3D io__get_char(io); } + + if (overflowed) + strlcpy(pathname, "//toolong", pathname_size); + else + pathname[written] =3D '\0'; + + return true; } =20 static void perf_record_mmap2__read_build_id(struct perf_record_mmap2 *eve= nt, @@ -463,45 +533,53 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, while (!io.eof) { static const char anonstr[] =3D "//anon"; size_t size, aligned_size; - - /* ensure null termination since stack will be reused. */ - event->mmap2.filename[0] =3D '\0'; + __u64 start, end, pgoff, ino; + u32 prot, flags, maj, min; =20 /* 00400000-0040c000 r-xp 00000000 fd:01 41038 /bin/cat */ - if (!read_proc_maps_line(&io, - &event->mmap2.start, - &event->mmap2.len, - &event->mmap2.prot, - &event->mmap2.flags, - &event->mmap2.pgoff, - &event->mmap2.maj, - &event->mmap2.min, - &event->mmap2.ino, - sizeof(event->mmap2.filename), - event->mmap2.filename)) + /* Read directly into event->mmap2.filename! */ + if (!read_proc_maps_line(&io, &start, &end, + &prot, &flags, &pgoff, + &maj, &min, &ino, + sizeof(event->mmap2.filename), + event->mmap2.filename)) { + if (io.eof) + break; continue; + } =20 - if ((rdclock() - t) > timeout) { - pr_warning("Reading %s/proc/%d/task/%d/maps time out. " - "You may want to increase " - "the time limit by --proc-map-timeout\n", - machine->root_dir, pid, pid); - truncation =3D true; - goto out; + if (!strcmp(event->mmap2.filename, "")) + strcpy(event->mmap2.filename, anonstr); + + if (hugetlbfs_mnt_len && + !strncmp(event->mmap2.filename, hugetlbfs_mnt, hugetlbfs_mnt_len)) { + strcpy(event->mmap2.filename, anonstr); + flags |=3D MAP_HUGETLB; } =20 - event->mmap2.ino_generation =3D 0; + size =3D strlen(event->mmap2.filename) + 1; + aligned_size =3D PERF_ALIGN(size, sizeof(u64)); + + event->mmap2.header.type =3D PERF_RECORD_MMAP2; =20 /* - * Just like the kernel, see __perf_event_mmap in kernel/perf_event.c + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) event->header.misc =3D PERF_RECORD_MISC_USER; else event->header.misc =3D PERF_RECORD_MISC_GUEST_USER; =20 - if ((event->mmap2.prot & PROT_EXEC) =3D=3D 0) { - if (!mmap_data || (event->mmap2.prot & PROT_READ) =3D=3D 0) + if ((rdclock() - t) > timeout) { + pr_warning("Reading %s/proc/%d/task/%d/maps time out. You may want to i= ncrease the time limit by --proc-map-timeout\n", + machine->root_dir, pid, pid); + truncation =3D true; + goto out; + } + + if ((prot & PROT_EXEC) =3D=3D 0) { + if (!mmap_data || (prot & PROT_READ) =3D=3D 0) continue; =20 event->header.misc |=3D PERF_RECORD_MISC_MMAP_DATA; @@ -511,26 +589,26 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, if (truncation) event->header.misc |=3D PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT; =20 - if (!strcmp(event->mmap2.filename, "")) - strcpy(event->mmap2.filename, anonstr); + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; =20 - if (hugetlbfs_mnt_len && - !strncmp(event->mmap2.filename, hugetlbfs_mnt, - hugetlbfs_mnt_len)) { - strcpy(event->mmap2.filename, anonstr); - event->mmap2.flags |=3D MAP_HUGETLB; - } + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap2, filename) + si= ze, 0, + (aligned_size - size) + machine->id_hdr_size); =20 - size =3D strlen(event->mmap2.filename) + 1; - aligned_size =3D PERF_ALIGN(size, sizeof(u64)); - event->mmap2.len -=3D event->mmap.start; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - aligned_size)); - memset(event->mmap2.filename + size, 0, machine->id_hdr_size + - (aligned_size - size)); event->mmap2.header.size +=3D machine->id_hdr_size; + event->mmap2.start =3D start; + event->mmap2.len =3D end - start; + event->mmap2.pgoff =3D pgoff; + event->mmap2.maj =3D maj; + event->mmap2.min =3D min; + event->mmap2.ino =3D ino; + event->mmap2.ino_generation =3D 0; event->mmap2.pid =3D tgid; event->mmap2.tid =3D pid; + event->mmap2.prot =3D prot; + event->mmap2.flags =3D flags; =20 if (!symbol_conf.no_buildid_mmap2) perf_record_mmap2__read_build_id(&event->mmap2, machine, false); @@ -703,11 +781,6 @@ static int perf_event__synthesize_modules_maps_cb(stru= ct map *map, void *data) =20 memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); =20 - /* Clear stale build ID from previous module iteration */ - event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; - memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); - event->mmap2.build_id_size =3D 0; - perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A63EA46DFE5 for ; Tue, 21 Jul 2026 18:22:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658128; cv=none; b=O1pAIcmSt7zTLQUNIgnsm/acIH4Sj47X0CEcl4GCFypyp8iyYOkqzb+gKXl7SwQq+eVocVH6TnpA6zOcrd9t4QJKIXbQkXzuYFAophbxEegitgg69uRM9qTDq9zhLdxe5oorPhIUyMr+kq90nVkKtOkC+o35smvlhnYYRk8uOFk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658128; c=relaxed/simple; bh=8rV2W76OrLho3Awr1l5RlnvfGj9upiyT+0adcR62kcU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=sJ7/SvKQ9v6T7fwW0Yx0bkZ7v1wRE1Yaco0lGu9zkKbtKlBNj6/tx8I2vN6tYGMpZeqwz3nXNx/TyLgH8OUTTuKII4B4NH+kslOqeK+fkKZERLFb0vefkVr44p95Xl5Q+bqcpUZmPOPWLJFhAxT+Heq2aRhnuBD8IRn7ZrkNkeo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=ihO6tUlQ; arc=none smtp.client-ip=209.85.216.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="ihO6tUlQ" Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-38de0739ab6so8719151a91.3 for ; Tue, 21 Jul 2026 11:22:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784658126; x=1785262926; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Psg2Kwj8r8r+xedYt30c9/NPeC/qe6QwRI5erzuXc+M=; b=ihO6tUlQgL89xySnv0OKKEhswzWwk1yKvHkS5Zg9HXrSFZiYwiusM76jDqt1ftczXU 22BqyUSvTc9g3OfWg0TmZXEm9l+tM0n+z6HBgYV/B3GYzfofunYVkq5O3b4+/5GoLxoP hSXxSUZnMWbFWmhq+gHTUniXQPJaPtW53z80YFcdMGY/qUuxm2FLQ6tIByVJeeWSv5ID 9fl4rR9tRzeU2WbsILeoY1u0snjZvUXbB6qAut61PGmJ3aZ6vlkix7zsKHhLQg6Nl17G iL8v/qTJVQV34f72OQ2hnXUnCtOwoFJ9Q7CC5pB4Pt0MFxAL6n1wfvGvD6YQ4Wl99UyW p2UQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784658126; x=1785262926; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Psg2Kwj8r8r+xedYt30c9/NPeC/qe6QwRI5erzuXc+M=; b=FeDj45/lJx/3qSYg0Wod72EbdZHcXU7rmZvRYp6e98c8A9clvNB6/lF+/i34Au89Ie LOkoxy9ZA+6xm8Whqr6wvl2jS6YcxQEFA/r0+yYBb5d3CWK+ZOlMP89b643+3Q1MURUJ 7U3Ds4Pb72DitoC0T9k0u+/auxaEb6KtAo/PXlGItGggj1sJtMJEu8HdLE/Usa2ZRufR PtGMBqtxvglBhUTeNCo3oul/IWO1qOm5HPVToDQXfPtSyxJ0sRSdpyEvxVrUqQG70BNO 5K/eiFSnFKm9IYrJfdI1nvem694iaIAKBmw4CEs7QF3THa7/FA31zpt4sX59vw2urLeN XurQ== X-Forwarded-Encrypted: i=1; AHgh+RrFMrHXpsxG2wzJQyKQxulOCHLs9DUOC2T4tyLVwuh1jr8aPHsdAhvMpXcChVUk1k8s3bCsGqb5B5H5Gtk=@vger.kernel.org X-Gm-Message-State: AOJu0YyxC0UCHk2s+BDrIhyoSKjPAQuvcHqDUt4shGuL7f5KbfQz5m1D GM2PBetgBU0ks9MR2JZBpNA/VS+z3TvSRpKgA5CwxXtWnDCRm+I7jX9E77saxn2NrNUoXNAvDqF JBkoSNNXY/A== X-Received: from dlf19.prod.google.com ([2002:a05:7022:413:b0:138:4fdd:447]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:510b:b0:38e:7aa3:df25 with SMTP id 98e67ed59e1d1-38e7aa3e19emr9741695a91.43.1784658125688; Tue, 21 Jul 2026 11:22:05 -0700 (PDT) Date: Tue, 21 Jul 2026 11:21:49 -0700 In-Reply-To: <20260721182150.94016-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721173347.9163-1-irogers@google.com> <20260721182150.94016-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721182150.94016-4-irogers@google.com> Subject: [PATCH v4 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Clamp long DSO names to mmap/mmap2 filename boundaries to prevent buffer overruns in perf_event__synthesize_modules_maps_cb(). Explicitly clear misc flags and union padding to prevent stale Build-ID state from leaking between module synthesis events, and cast event buffer pointers to avoid _FORTIFY_SOURCE array bounds aborts when zeroing padding trailers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 71 ++++++++++++++++++++++-------- 1 file changed, 53 insertions(+), 18 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 60bdf2d918ea..e547874b77b2 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -755,6 +755,7 @@ struct perf_event__synthesize_modules_maps_cb_args { perf_event__handler_t process; struct machine *machine; union perf_event *event; + u16 misc; }; =20 static int perf_event__synthesize_modules_maps_cb(struct map *map, void *d= ata) @@ -762,44 +763,78 @@ static int perf_event__synthesize_modules_maps_cb(str= uct map *map, void *data) struct perf_event__synthesize_modules_maps_cb_args *args =3D data; union perf_event *event =3D args->event; struct dso *dso; - size_t size; + size_t size, aligned_size; + int rc =3D 0; =20 if (!__map__is_kmodule(map)) return 0; =20 dso =3D map__dso(map); if (!symbol_conf.no_buildid_mmap2) { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap2.filename)) + size =3D sizeof(event->mmap2.filename) - 1; + + strlcpy(event->mmap2.filename, long_name, + sizeof(event->mmap2.filename)); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap2.header.type =3D PERF_RECORD_MMAP2; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - size)); - memset(event->mmap2.filename + size, 0, args->machine->id_hdr_size); + event->mmap2.header.misc =3D args->misc; + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap2, filename) + si= ze, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap2.header.size +=3D args->machine->id_hdr_size; event->mmap2.start =3D map__start(map); event->mmap2.len =3D map__size(map); event->mmap2.pid =3D args->machine->pid; =20 - memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); + /* Clear stale build ID and entire union from previous module iteration = */ + event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; + memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); + event->mmap2.build_id_size =3D 0; + event->mmap2.__reserved_1 =3D 0; + event->mmap2.__reserved_2 =3D 0; =20 perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap.filename)) + size =3D sizeof(event->mmap.filename) - 1; + + strlcpy(event->mmap.filename, long_name, + sizeof(event->mmap.filename)); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap.header.type =3D PERF_RECORD_MMAP; - event->mmap.header.size =3D (sizeof(event->mmap) - - (sizeof(event->mmap.filename) - size)); - memset(event->mmap.filename + size, 0, args->machine->id_hdr_size); + event->mmap.header.misc =3D args->misc; + event->mmap.header.size =3D + offsetof(struct perf_record_mmap, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap, filename) + siz= e, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap.header.size +=3D args->machine->id_hdr_size; event->mmap.start =3D map__start(map); event->mmap.len =3D map__size(map); event->mmap.pid =3D args->machine->pid; - - memcpy(event->mmap.filename, dso__long_name(dso), dso__long_name_len(dso= ) + 1); } =20 if (perf_tool__process_synth_event(args->tool, event, args->machine, args= ->process) !=3D 0) - return -1; + rc =3D -1; =20 - return 0; + return rc; } =20 int perf_event__synthesize_modules(const struct perf_tool *tool, perf_even= t__handler_t process, @@ -824,13 +859,13 @@ int perf_event__synthesize_modules(const struct perf_= tool *tool, perf_event__han } =20 /* - * kernel uses 0 for user space maps, see kernel/perf_event.c - * __perf_event_mmap + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) - args.event->header.misc =3D PERF_RECORD_MISC_KERNEL; + args.misc =3D PERF_RECORD_MISC_KERNEL; else - args.event->header.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; + args.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; =20 rc =3D maps__for_each_map(maps, perf_event__synthesize_modules_maps_cb, &= args); =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 179A538757B for ; Tue, 21 Jul 2026 18:22:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658133; cv=none; b=I3iNWP01at5VqfIZlNbwq1tA+f/6C+9AXdxDzge7Iluw+OD234U3tjxpCp7SxdOyfJwwYzGuGc/u8p1NGl59YS1NcPp/1Q62kstnnu1k2xRNroD8JwhgQ8DLlQsjIml5E1/9h20kyjyB8bdRZ5bee9hRVhSIVhIzYAsBPcLUpco= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784658133; c=relaxed/simple; bh=A7ELJzohcBlvD9DGCB6ldigxQdAFB2ZZ7CW9ki6fKqY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=krisxKDcXfkR6z8KtkJb55nGu7RHOZzx4QVOIrKy9k3zIMG+kIwB7izb2H8dSnDaDHMmMv0Pq1gyeg4YmD9KGaXR7DhkdUqCOiKTBfGNLjkkuGeShH8VfVQseb3E8IQtlvW60kfkjmFpAFhQ0F5s44PCkKAsK0DUlIRVWrxKz1w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=cJKqNkk0; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="cJKqNkk0" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-cab041eced3so14264205a12.1 for ; Tue, 21 Jul 2026 11:22:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784658131; x=1785262931; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=BE8WZ74FQc82iPrgnQrSwAZj7UdSUheiNt1ByX8Xbi0=; b=cJKqNkk0jYfOdpF0f/twIHfYLbkp5tnVoc499ErjaoAJFAH8CzvKdGqWnwpSJKGBh2 tXvW3UyrRKcQCmY+h1uu0BM1SUjzRaZCFUicuFGL6A1wF2ObgoSCywUnCTSMivBdNVF8 jK+7otU/FlNZVEg1kS0zrJ56ED0b/hkJHeTDTwFtE3jhb8OPoZHEJRj0cDk4yyWAQiZb 3hC5/micXblpZhhkhAxAvl0ezqJnq4u9vylY2puLxKaIjVhzO3MMR7JAFP5EgFvbODIb Cw4DNs7C7362QORr4KLj9oeOm/hHhgQbSaJrm8i2GU939fdVKmk2Hd+jeLQEfAkLBUJf T1jA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784658131; x=1785262931; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BE8WZ74FQc82iPrgnQrSwAZj7UdSUheiNt1ByX8Xbi0=; b=FHC3LKa8qyvBq59ERgo7WS37kcK04Z4BRT0Yt73TnKWCbZ4jnuuGNR6kp1HiFp/nUg Uq3GUWD8a4BgH4GAvGF+KUaHW1HDNahF09FPLn3KQ6MXv+OpIxj1E3yqE7BKsYUO8x3/ +83H5dANVG1lLxTPElWXrO3K1YcKNncfkY8LkIug+Chmf0Y30fia2dnnSFJe7MxIAV51 kVVxKFo20wYRwn0HL72udklUaU2/F8gwg/6BYQYafC3lTkeUAZcnGiWC2Em9F7bR0nQF nSvS1K+ysSneK6H/guvgqiXdsMwRYo4rbLwR9wHaudu2J856cPhw/dWRJIJ5JTl4xJqj G31Q== X-Forwarded-Encrypted: i=1; AHgh+Ro8Sy2w0qNOSc5eHbA6+MjZmnIDCxJM7mYD9KSzYLONdpbRrwnS4ray5dvjzNHQRK33n5sAHjPAUVY33EI=@vger.kernel.org X-Gm-Message-State: AOJu0YyebE29xqNDYdpvM0Q9Vae/nEqIRe9JclaGJX+EPaT4Nluet0HO 21pjB15Fjxr9DrBDvTaOKhAZK+FHLbnwDsA7CJppY0HVn0RWjPcSCjTof10Ep9PMLPU3MgLjFLC FOjgokz0v2g== X-Received: from dlbqj15.prod.google.com ([2002:a05:7022:ec0f:b0:13b:4811:2202]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a20:728a:b0:3c0:9c19:6584 with SMTP id adf61e73a8af0-3c3ad9a1868mr21570949637.62.1784658131000; Tue, 21 Jul 2026 11:22:11 -0700 (PDT) Date: Tue, 21 Jul 2026 11:21:50 -0700 In-Reply-To: <20260721182150.94016-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721173347.9163-1-irogers@google.com> <20260721182150.94016-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721182150.94016-5-irogers@google.com> Subject: [PATCH v4 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix a critical logic bug in perf_event__synthesize_mmap2_build_id() where the wrong union member structure size and offset boundaries were utilized. Safely calculate the exact maximum allowed filename length to guarantee absolute stack and alignment boundaries for ID sample trailers, preventing -E2BIG overruns on very long filenames while meeting strict standard C compliance. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index e547874b77b2..06a960e8ba85 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -2448,13 +2448,18 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, size_t filename_len =3D strlen(filename); size_t ev_len; u64 sample_type =3D sample->evsel ? sample->evsel->core.attr.sample_type = : 0; - void *array; + void *array =3D &ev; int ret; + size_t max_filename_len; =20 - if (filename_len >=3D sizeof(ev.mmap2.filename)) - return -EINVAL; + max_filename_len =3D sizeof(ev) - + (MAX_ID_HDR_ENTRIES * sizeof(__u64)) - + offsetof(struct perf_record_mmap2, filename) - 1; =20 - ev_len =3D sizeof(ev.mmap2) - sizeof(ev.mmap2.filename) + filename_len + = 1; + if (filename_len > max_filename_len) + filename_len =3D max_filename_len; + + ev_len =3D offsetof(struct perf_record_mmap2, filename) + filename_len + = 1; ev_len =3D PERF_ALIGN(ev_len, sizeof(u64)); =20 if (ev_len + MAX_ID_HDR_ENTRIES * sizeof(__u64) > sizeof(ev)) @@ -2474,16 +2479,15 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, =20 ev.mmap2.build_id_size =3D bid->size; if (ev.mmap2.build_id_size > sizeof(ev.mmap2.build_id)) - ev.build_id.size =3D sizeof(ev.mmap2.build_id); + ev.mmap2.build_id_size =3D sizeof(ev.mmap2.build_id); memcpy(ev.mmap2.build_id, bid->data, ev.mmap2.build_id_size); =20 ev.mmap2.prot =3D prot; ev.mmap2.flags =3D flags; =20 - memcpy(ev.mmap2.filename, filename, min(strlen(filename), sizeof(ev.mmap.= filename))); + strlcpy(ev.mmap2.filename, filename, filename_len + 1); =20 - array =3D &ev; - array +=3D ev.header.size; + array =3D (void *)((char *)&ev + ev.header.size); ret =3D perf_event__synthesize_id_sample(array, sample_type, sample); if (ret < 0) return ret; --=20 2.55.0.229.g6434b31f56-goog