From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com [209.85.216.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 85A673B9DB3 for ; Tue, 21 Jul 2026 20:57:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667486; cv=none; b=uHXuWqsg0bXEuBNfhUMHdc0gKP7kLwmRypoXM2CE4FJIov1ee3O+xU2+khp2t1GYIQPKT/0uWG9uHD4C48zmlkbL0l76t+vUCoM9TXyAa2qvpbO00rW5S1vyzA6q3hVoyWp7pMSGAKXjNkj00HM4dSJ+d4d2tZWfEz5alHGTPk4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667486; c=relaxed/simple; bh=pj0KjjICAGQcYFvJa34O/R6iaQNWxgcdqHf3gBWUcgM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=vAXSNPFdQO0+t63fUIBNS86wdIEyKLl+Qtu77yx888j5J5CxkLLE/IFJgQBUvev1xoysuudIPZR6xhH+Ze87JYdJnQ9XwdUgs7fq2iX+haI1LZv+tdrWJxyWsdPYENsobyb+3YhcFFQEwQMuoMiR1JiyoADg0VvYBXwPWs94GJY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=FNZyYdEt; arc=none smtp.client-ip=209.85.216.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="FNZyYdEt" Received: by mail-pj1-f72.google.com with SMTP id 98e67ed59e1d1-38e11baa66eso9100287a91.2 for ; Tue, 21 Jul 2026 13:57:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784667472; x=1785272272; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=FNZyYdEt8bN0HEwMQs0a+gX2ynSbNjSniMmYqMhMEnaKUO9Hj0lu/EH/uiDTvhH35x oIiziAhIkVEUKH+JH/bDVm3C9QNxQZ4CRrMVJpgu/WCjjlwhCiF5NlBMfCl+g7bKbP6T ycm3zG8yidhCyhVesV2FVkicrC/cZq7xoAPNrW3xwYs13nZ7M5NiqLdxvz8HiCaezBPz bL6hGRfGa8/+MTK3cUTp30+S2pP9V8MtYmOZ0vB9aLn4xowhPG223zZ+Dcb/5DNwRpff x5x8pPB18/ePHQ/sQzkJulZS7j1Yxld+N08BQYorGQk0MH9fRIiFW5mG268yQ7cbcqib kmng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784667472; x=1785272272; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=DjqmRDXP7vKMu7V1jypNCNvSDhXcMF8dpDMbf42b8UjRW7NUsfC1bfBvKkPj7BQB+r F61YzaFuxgfPz1nOo2yrIK5wJcxQHvrUtu3bn6k1yX5w9gKxkOFqtIksTiRiunlorlvi AoUGmswCtt80w6rkpmCDq/xlK4mKVYwVwcYHCsuk+lOHXCd9yfzTMjxE7Zn88sqWDT4c WWEcgGJ3xzJygoEFqn54YkFjICKRUOD7tI+ihsdE16RGqPVLw7qm9ufLxusH3aS6+kcw vi1XRifSLOnwHQqZnyRvw6p6PmAabTwMEljuCXCdGBsRNTXIjuWj6+XhwqBonjTIMZ2Z d4Dg== X-Forwarded-Encrypted: i=1; AHgh+Rq8LOtIB2i+XaWRkAWbAwy8c4rCDyTj/HZev5tdeL+Kscg+ZIqziN6BusKbEIhRMsplGXcZJ3kqoTRw7Xw=@vger.kernel.org X-Gm-Message-State: AOJu0Yw1uSuNJ3m67h26lvtsVcO7F8lNhwVbWJZx4ekqcKmy4y5E2AXO R4vMZ8LA/Cuwcfq4ZUguN4DBY59TF1P7VQ9VneSd9h0VdWIcW44oxGCRRaBsEmo1jafIXfU1k3r y4Pucsu3T1Q== X-Received: from dlyy29.prod.google.com ([2002:a05:7022:69d:b0:13b:54e0:b3ab]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90a:f94c:b0:38e:4e62:f998 with SMTP id 98e67ed59e1d1-38e4e62fbfamr14129699a91.23.1784667471878; Tue, 21 Jul 2026 13:57:51 -0700 (PDT) Date: Tue, 21 Jul 2026 13:57:43 -0700 In-Reply-To: <20260721205746.183206-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721182150.94016-1-irogers@google.com> <20260721205746.183206-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721205746.183206-2-irogers@google.com> Subject: [PATCH v5 1/4] perf find-map: Remove PATH_MAX 128-byte stack array restriction From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use getline() to dynamically allocate the required line buffer for maps parsing, guaranteeing bounds safety and avoiding compiler warnings by evaluating the return value in the loop condition directly. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/find-map.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/find-map.c b/tools/perf/util/find-map.c index 7b2300588ece..bba511795a69 100644 --- a/tools/perf/util/find-map.c +++ b/tools/perf/util/find-map.c @@ -1,8 +1,13 @@ // SPDX-License-Identifier: GPL-2.0 +#include +#include +#include + static int find_map(void **start, void **end, const char *name) { FILE *maps; - char line[128]; + char *line =3D NULL; + size_t len =3D 0; int found =3D 0; =20 maps =3D fopen("/proc/self/maps", "r"); @@ -11,7 +16,7 @@ static int find_map(void **start, void **end, const char = *name) return -1; } =20 - while (!found && fgets(line, sizeof(line), maps)) { + while (!found && getline(&line, &len, maps) !=3D -1) { int m =3D -1; =20 /* We care only about private r-x mappings. */ @@ -25,6 +30,7 @@ static int find_map(void **start, void **end, const char = *name) found =3D 1; } =20 + free(line); fclose(maps); return !found; } --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D98B3FFAC3 for ; Tue, 21 Jul 2026 20:57:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667488; cv=none; b=ZkrLrSbj71FSwhgTmKKsa3AE+moRMTry+lYGbLhIuF9xf8qZUmSPQDFM+98IM7BWvRtoaxLmjC0LqMofozA3gg6quEBS/cRlLi9McCb9lvbPNvM7qEF+QCGiR8VExhOveU3uVb/AZXPKjB5QjU/l74/WhFp/oxehbD5HZYvkLq0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667488; c=relaxed/simple; bh=Xm9lamjbtZi2pEr5IsDWXnNpazKGY5HtgWKN1punmzc=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Sfkf/VaB1niG/tgrsS4YwaPrRQ9sA+ZKg9PKx8lxDjEmPUHP3iexjpiKlHNOTOBa5q9ihmQxhY9K5MmqhgGPjX6pTIifFBHS7Vi2Qmg4DuoOtaLJUos4NSdxkaxXcN2N2qOBj1ug41E9G4RJw6EQ2G/x4ejenh2YyNNa50D4C6c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=vIR+6QKH; arc=none smtp.client-ip=209.85.214.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="vIR+6QKH" Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2cca3673560so204038375ad.1 for ; Tue, 21 Jul 2026 13:57:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784667474; x=1785272274; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=AOo4xGNKOmTSdj62MplGbtiyCINdwG7LKPF8fve2D7Q=; b=vIR+6QKH2h2gdQJarVKAVFm4VgbZ4xfkMBnv/86JPF5Y3by3vlxEFJz+Vbuva0Smnj U7TfWfMoNW/RMDunQKskjNfVPCQ5VUeRwJLfMoXCyvkH5CJYt8HOFhBKhjBMJp5qwi3B 8r7sBM5Wv/Sc5BK/T/WlPesCxMKK+PSG3ybjrpjU2FKde7vjdaKF2EFAsmxcA0EA1Xwi sqRw7JlPFQjMaaqa0zx6Nf/1F49ztByabTl0nc1/+4iuYXpuzgs2C4iquuWRDP62EA1w 6u19Q4Fi9Me9xw8tjJ98SsBl9atbzTakIC21xG/3NKYTCgo7PKEsb4us1kgl3smX2CDr M1kw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784667474; x=1785272274; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AOo4xGNKOmTSdj62MplGbtiyCINdwG7LKPF8fve2D7Q=; b=YgYo9GrhYU7mbZjCzJKgnosn+tHwRfl19MoVczk5xPFzidB+lcxYXccGmGCVV8/2U6 NqDwqZM7PDChuaFqTxYWU7NEZpPurDWbyp2Vl4xwBh2Ci21AR3Brwyt57O5tY+QcrkR2 8eaHPyeOeo/U22RqIqgqTyR560CawM3UZvdC0z2zC1CYpzBt7iSDsjXvIo/WWPetYBOS iCmG0bBMAHcgEpJOmylKIuvscSg88x2anlfMtqzWXKeDp5YXT/MCVL56ddKablqXYIsC 7GjrMHeSIzluaIHS6NrSkP9CQqPAij0ffdSq0oEy9F6VbKkIkG0i7c7wlxBPQcYIWUO5 BW6A== X-Forwarded-Encrypted: i=1; AHgh+RrOfrmujtHu3YM4Hl4c3TcKU+gOPYlDGfUiEEs2C5KXgN1+iyk/02xcrkzLeKV4z8H+M7eHOF+YkAmITek=@vger.kernel.org X-Gm-Message-State: AOJu0YxXIbCwHJ6YHerUaxybjtXaVZdXfb3vdmOdDvW642J97JNWBFii KJr1mrsHdCWKkqzzsRnEXeFgHvaGVAo4WukbMihfFugfCGRGoqsRKSlKvPclOJy8Paa5IRqE90T uEZX+ILPpJA== X-Received: from dyp8.prod.google.com ([2002:a05:693c:65c8:b0:30e:ee3a:f2f1]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:f78c:b0:2cb:3f5b:6663 with SMTP id d9443c01a7336-2cf348bee75mr215267295ad.11.1784667473472; Tue, 21 Jul 2026 13:57:53 -0700 (PDT) Date: Tue, 21 Jul 2026 13:57:44 -0700 In-Reply-To: <20260721205746.183206-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721182150.94016-1-irogers@google.com> <20260721205746.183206-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721205746.183206-3-irogers@google.com> Subject: [PATCH v5 2/4] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix critical logic and boundary bugs in read_proc_maps_line() and caller. Ensure any mid-line hex/dec/char parsing failure invokes io__drain_line() safely, using a do-while loop to read and discard remaining characters until a newline or EOF is reached. Clamp pathname extraction size to account for trailing sample ID headers, use standard '//toolong' fallback literal for over-length pathnames, emit timeout flags for truncated entries securely via goto out;, and cast event buffer pointers to avoid _FORTIFY_SOURCE array bounds aborts across synthesis handlers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 209 ++++++++++++++++++++--------- 1 file changed, 142 insertions(+), 67 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index b75f9dcf4dbf..e73f2e526e83 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -179,7 +179,8 @@ static int perf_event__prepare_comm(union perf_event *e= vent, pid_t pid, pid_t ti =20 size =3D strlen(event->comm.comm) + 1; size =3D PERF_ALIGN(size, sizeof(u64)); - memset(event->comm.comm + size, 0, machine->id_hdr_size); + memset((char *)event + offsetof(struct perf_record_comm, comm) + size, + 0, machine->id_hdr_size); event->comm.header.size =3D (sizeof(event->comm) - (sizeof(event->comm.comm) - size) + machine->id_hdr_size); @@ -291,6 +292,18 @@ static int perf_event__synthesize_fork(const struct pe= rf_tool *tool, return 0; } =20 +static void io__drain_line(struct io *io, int ch) +{ + if (ch =3D=3D '\n') + return; + if (ch =3D=3D -2 && io->data > io->buf && io->data[-1] =3D=3D '\n') + return; + + do { + ch =3D io__get_char(io); + } while (ch >=3D 0 && ch !=3D '\n'); +} + static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end, u32 *prot, u32 *flags, __u64 *offset, u32 *maj, u32 *min, @@ -299,69 +312,127 @@ static bool read_proc_maps_line(struct io *io, __u64= *start, __u64 *end, { __u64 temp; int ch; - char *start_pathname =3D pathname; + size_t written =3D 0; + bool overflowed =3D false; =20 - if (io__get_hex(io, start) !=3D '-') + ch =3D io__get_hex(io, start); + if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_hex(io, end) !=3D ' ') + } + ch =3D io__get_hex(io, end); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 /* map protection and flags bits */ *prot =3D 0; ch =3D io__get_char(io); if (ch =3D=3D 'r') *prot |=3D PROT_READ; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'w') *prot |=3D PROT_WRITE; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'x') *prot |=3D PROT_EXEC; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 's') *flags =3D MAP_SHARED; else if (ch =3D=3D 'p') *flags =3D MAP_PRIVATE; - else + else { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_char(io) !=3D ' ') + } + ch =3D io__get_char(io); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, offset) !=3D ' ') + ch =3D io__get_hex(io, offset); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, &temp) !=3D ':') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ':') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *maj =3D temp; - if (io__get_hex(io, &temp) !=3D ' ') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *min =3D temp; =20 ch =3D io__get_dec(io, inode); if (ch !=3D ' ') { - *pathname =3D '\0'; - return ch =3D=3D '\n'; + if (ch =3D=3D '\n') { + pathname[0] =3D '\0'; + return true; + } + if (!io->eof) + io__drain_line(io, ch); + return false; } + do { ch =3D io__get_char(io); } while (ch =3D=3D ' '); + while (true) { - if (ch < 0) - return false; - if (ch =3D=3D '\0' || ch =3D=3D '\n' || - (pathname + 1 - start_pathname) >=3D pathname_size) { - *pathname =3D '\0'; - return true; + if (ch < 0) { + if (overflowed) { + strlcpy(pathname, "//toolong", pathname_size); + return true; + } + pathname[written] =3D '\0'; + return written > 0; } - *pathname++ =3D ch; + if (ch =3D=3D '\0' || ch =3D=3D '\n') + break; + + if (written < (size_t)pathname_size - 1) + pathname[written++] =3D (char)ch; + else + overflowed =3D true; ch =3D io__get_char(io); } + + if (overflowed) + strlcpy(pathname, "//toolong", pathname_size); + else + pathname[written] =3D '\0'; + + return true; } =20 static void perf_record_mmap2__read_build_id(struct perf_record_mmap2 *eve= nt, @@ -463,45 +534,53 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, while (!io.eof) { static const char anonstr[] =3D "//anon"; size_t size, aligned_size; - - /* ensure null termination since stack will be reused. */ - event->mmap2.filename[0] =3D '\0'; + __u64 start, end, pgoff, ino; + u32 prot, flags, maj, min; =20 /* 00400000-0040c000 r-xp 00000000 fd:01 41038 /bin/cat */ - if (!read_proc_maps_line(&io, - &event->mmap2.start, - &event->mmap2.len, - &event->mmap2.prot, - &event->mmap2.flags, - &event->mmap2.pgoff, - &event->mmap2.maj, - &event->mmap2.min, - &event->mmap2.ino, - sizeof(event->mmap2.filename), - event->mmap2.filename)) + /* Read directly into event->mmap2.filename, clamping for id_hdr_size! */ + if (!read_proc_maps_line(&io, &start, &end, + &prot, &flags, &pgoff, + &maj, &min, &ino, + sizeof(event->mmap2.filename) - machine->id_hdr_size, + event->mmap2.filename)) { + if (io.eof) + break; continue; + } =20 - if ((rdclock() - t) > timeout) { - pr_warning("Reading %s/proc/%d/task/%d/maps time out. " - "You may want to increase " - "the time limit by --proc-map-timeout\n", - machine->root_dir, pid, pid); - truncation =3D true; - goto out; + if (!strcmp(event->mmap2.filename, "")) + strcpy(event->mmap2.filename, anonstr); + + if (hugetlbfs_mnt_len && + !strncmp(event->mmap2.filename, hugetlbfs_mnt, hugetlbfs_mnt_len)) { + strcpy(event->mmap2.filename, anonstr); + flags |=3D MAP_HUGETLB; } =20 - event->mmap2.ino_generation =3D 0; + size =3D strlen(event->mmap2.filename) + 1; + aligned_size =3D PERF_ALIGN(size, sizeof(u64)); + + event->mmap2.header.type =3D PERF_RECORD_MMAP2; =20 /* - * Just like the kernel, see __perf_event_mmap in kernel/perf_event.c + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) event->header.misc =3D PERF_RECORD_MISC_USER; else event->header.misc =3D PERF_RECORD_MISC_GUEST_USER; =20 - if ((event->mmap2.prot & PROT_EXEC) =3D=3D 0) { - if (!mmap_data || (event->mmap2.prot & PROT_READ) =3D=3D 0) + if ((rdclock() - t) > timeout) { + pr_warning("Reading %s/proc/%d/task/%d/maps time out. You may want to i= ncrease the time limit by --proc-map-timeout\n", + machine->root_dir, pid, pid); + truncation =3D true; + goto out; + } + + if ((prot & PROT_EXEC) =3D=3D 0) { + if (!mmap_data || (prot & PROT_READ) =3D=3D 0) continue; =20 event->header.misc |=3D PERF_RECORD_MISC_MMAP_DATA; @@ -511,26 +590,26 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, if (truncation) event->header.misc |=3D PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT; =20 - if (!strcmp(event->mmap2.filename, "")) - strcpy(event->mmap2.filename, anonstr); + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; =20 - if (hugetlbfs_mnt_len && - !strncmp(event->mmap2.filename, hugetlbfs_mnt, - hugetlbfs_mnt_len)) { - strcpy(event->mmap2.filename, anonstr); - event->mmap2.flags |=3D MAP_HUGETLB; - } + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap2, filename) + si= ze, 0, + (aligned_size - size) + machine->id_hdr_size); =20 - size =3D strlen(event->mmap2.filename) + 1; - aligned_size =3D PERF_ALIGN(size, sizeof(u64)); - event->mmap2.len -=3D event->mmap.start; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - aligned_size)); - memset(event->mmap2.filename + size, 0, machine->id_hdr_size + - (aligned_size - size)); event->mmap2.header.size +=3D machine->id_hdr_size; + event->mmap2.start =3D start; + event->mmap2.len =3D end - start; + event->mmap2.pgoff =3D pgoff; + event->mmap2.maj =3D maj; + event->mmap2.min =3D min; + event->mmap2.ino =3D ino; + event->mmap2.ino_generation =3D 0; event->mmap2.pid =3D tgid; event->mmap2.tid =3D pid; + event->mmap2.prot =3D prot; + event->mmap2.flags =3D flags; =20 if (!symbol_conf.no_buildid_mmap2) perf_record_mmap2__read_build_id(&event->mmap2, machine, false); @@ -579,7 +658,8 @@ static int perf_event__synthesize_cgroup(const struct p= erf_tool *tool, =20 event->cgroup.id =3D handle.cgroup_id; strncpy(event->cgroup.path, path + mount_len, path_len); - memset(event->cgroup.path + path_len, 0, machine->id_hdr_size); + memset((char *)event + offsetof(struct perf_record_cgroup, path) + path_l= en, + 0, machine->id_hdr_size); =20 if (perf_tool__process_synth_event(tool, event, machine, process) < 0) { pr_debug("process synth event failed\n"); @@ -703,11 +783,6 @@ static int perf_event__synthesize_modules_maps_cb(stru= ct map *map, void *data) =20 memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); =20 - /* Clear stale build ID from previous module iteration */ - event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; - memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); - event->mmap2.build_id_size =3D 0; - perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93BB8473C69 for ; Tue, 21 Jul 2026 20:58:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667493; cv=none; b=ffAIwdVWG3Sb/owiLBoWotYnVFwIb0WL1GsZsAG6PJ1KrpBq3rvB4zmiO0PFQtfQCM8gjJGk9uyY++s3+zOMvmYov0Ky7WNSSSv/6zrpETVUgMhSjuxyhSdTDKYzjFOcEBmciXbPY4Z3I5ay2eO3ygD4uOYltA3dQURDVXVMjN8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667493; c=relaxed/simple; bh=ilTt+lqSIVDLcJl1GrKDA8A9dhWw9mAcR6hEJFlXgzI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=VSaEda4st5/GUPThoBPm4HmPydBvxLC0MxMEP/JSkrIRA/UCymFh0T0s34SrT4HWdyRsHcVsH+OL9l+8MAQKam6v2+oe21A2B94y/Va8Q7Dj+8baTSjCgbXeUBOVVSy4QifisgbZdh755hCbYnJoSFQBwcEdXZPqLgJP1jelK9c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=q5dXfDkM; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="q5dXfDkM" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-38e7131849bso3109517a91.1 for ; Tue, 21 Jul 2026 13:58:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784667476; x=1785272276; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=eDtnweH9LMafsFo8ScEZrEnImvWALolTWFbjTPI5axQ=; b=q5dXfDkMH+rilyVq7me202/bObbkmj0jkfl8/KVm0a+/EEk+oGtBrCVjF+OAOiEXQb y7ES32w3W081sxA1cdCUUv9GMBrt2ohDMOP8m0o8NR5DDJ41uWnX4KgdP4cOXaG3WXaA qrEjyvFWjBLk3uDqwNWwkavFWybC+kV1fG9JONvg9FcSbu5aqAsj8Vvf4fRjL5hdTXGw LOeM3PAXhq6begqiIkQEIKnUDG8FGpYKpT770o6O95bqzsr4/hbMersewD0RZsdtnzbL eT4GUr1SUY62pzeq2wWFzvuoXSO5VVNxBR/RGnkAoBGIWHvRj62VLK/v7vRqVTfY8rod c1bg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784667476; x=1785272276; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eDtnweH9LMafsFo8ScEZrEnImvWALolTWFbjTPI5axQ=; b=l50nN5JnhPOf6rXzVOZll3LY1xgD5SOHJ+SXZp5Hj73Sj0o5PsL2IKS0/9traXrz7z AB69sINCawnBygfi2Ip0m8SlHeyGIsojRqqXraN5vMVmwVjKL7LL9hEqyfrx+OA+XJXP ZSxuyVWjaCoUYQbMRrwTt/sXCaWHD/PoAxsBmqVQqM2fshrj6wuCSfFsZkkYYSAacoJ0 vDMth2gPGRMIB9ivOsMB4HdtrTynLu8NwC0OWJcBNdEVtv+912ul/k1YUHdHjL4XddmM pkiC4+1byL4CumO/Q9AxsyDlVzPFmABFsKcmo0H1Li1n/LdRvYUlEshxey7ZIYEGXt+7 oRXA== X-Forwarded-Encrypted: i=1; AHgh+RphaPR4e2aocyZn/NGkspwTDxXtYHhhrVlAYKGMiv+OanePVQMz9Rq/psiZc+F37bWBAZTtt9MpKyabW9w=@vger.kernel.org X-Gm-Message-State: AOJu0YwSQpsEPG8pEDrtyGIshIPd3CHDk77dqaKwAwYGLoxdYCvaPy1x NrfC4BzZj25mBy6XANKURnfipWFMvYm71rb6s0S6dkvwmxOJKTJEWY01jI43v3s8y6PKOCEw48x irNpJVDlrTQ== X-Received: from dlcio4.prod.google.com ([2002:a05:7023:c004:b0:13b:8bb2:7330]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:3c4f:b0:38d:c50a:714 with SMTP id 98e67ed59e1d1-38e4b56dd7amr21978322a91.27.1784667475588; Tue, 21 Jul 2026 13:57:55 -0700 (PDT) Date: Tue, 21 Jul 2026 13:57:45 -0700 In-Reply-To: <20260721205746.183206-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721182150.94016-1-irogers@google.com> <20260721205746.183206-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721205746.183206-4-irogers@google.com> Subject: [PATCH v5 3/4] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Clamp long DSO names to mmap/mmap2 filename boundaries accounting for sample ID headers to prevent buffer overruns in perf_event__synthesize_modules_maps_cb(). Explicitly clear misc flags and union padding to prevent stale Build-ID state from leaking between module synthesis events, and cast event buffer pointers to avoid _FORTIFY_SOURCE array bounds aborts when zeroing padding trailers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 71 ++++++++++++++++++++++-------- 1 file changed, 53 insertions(+), 18 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index e73f2e526e83..4043d17a6140 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -757,6 +757,7 @@ struct perf_event__synthesize_modules_maps_cb_args { perf_event__handler_t process; struct machine *machine; union perf_event *event; + u16 misc; }; =20 static int perf_event__synthesize_modules_maps_cb(struct map *map, void *d= ata) @@ -764,44 +765,78 @@ static int perf_event__synthesize_modules_maps_cb(str= uct map *map, void *data) struct perf_event__synthesize_modules_maps_cb_args *args =3D data; union perf_event *event =3D args->event; struct dso *dso; - size_t size; + size_t size, aligned_size; + int rc =3D 0; =20 if (!__map__is_kmodule(map)) return 0; =20 dso =3D map__dso(map); if (!symbol_conf.no_buildid_mmap2) { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap2.filename) - args->machine->id_hdr_size) + size =3D sizeof(event->mmap2.filename) - args->machine->id_hdr_size - 1; + + strlcpy(event->mmap2.filename, long_name, + sizeof(event->mmap2.filename) - args->machine->id_hdr_size); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap2.header.type =3D PERF_RECORD_MMAP2; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - size)); - memset(event->mmap2.filename + size, 0, args->machine->id_hdr_size); + event->mmap2.header.misc =3D args->misc; + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap2, filename) + si= ze, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap2.header.size +=3D args->machine->id_hdr_size; event->mmap2.start =3D map__start(map); event->mmap2.len =3D map__size(map); event->mmap2.pid =3D args->machine->pid; =20 - memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); + /* Clear stale build ID and entire union from previous module iteration = */ + event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; + memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); + event->mmap2.build_id_size =3D 0; + event->mmap2.__reserved_1 =3D 0; + event->mmap2.__reserved_2 =3D 0; =20 perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap.filename) - args->machine->id_hdr_size) + size =3D sizeof(event->mmap.filename) - args->machine->id_hdr_size - 1; + + strlcpy(event->mmap.filename, long_name, + sizeof(event->mmap.filename) - args->machine->id_hdr_size); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap.header.type =3D PERF_RECORD_MMAP; - event->mmap.header.size =3D (sizeof(event->mmap) - - (sizeof(event->mmap.filename) - size)); - memset(event->mmap.filename + size, 0, args->machine->id_hdr_size); + event->mmap.header.misc =3D args->misc; + event->mmap.header.size =3D + offsetof(struct perf_record_mmap, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap, filename) + siz= e, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap.header.size +=3D args->machine->id_hdr_size; event->mmap.start =3D map__start(map); event->mmap.len =3D map__size(map); event->mmap.pid =3D args->machine->pid; - - memcpy(event->mmap.filename, dso__long_name(dso), dso__long_name_len(dso= ) + 1); } =20 if (perf_tool__process_synth_event(args->tool, event, args->machine, args= ->process) !=3D 0) - return -1; + rc =3D -1; =20 - return 0; + return rc; } =20 int perf_event__synthesize_modules(const struct perf_tool *tool, perf_even= t__handler_t process, @@ -826,13 +861,13 @@ int perf_event__synthesize_modules(const struct perf_= tool *tool, perf_event__han } =20 /* - * kernel uses 0 for user space maps, see kernel/perf_event.c - * __perf_event_mmap + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) - args.event->header.misc =3D PERF_RECORD_MISC_KERNEL; + args.misc =3D PERF_RECORD_MISC_KERNEL; else - args.event->header.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; + args.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; =20 rc =3D maps__for_each_map(maps, perf_event__synthesize_modules_maps_cb, &= args); =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:10:52 2026 Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com [209.85.216.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D7DF4582CF for ; Tue, 21 Jul 2026 20:58:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667493; cv=none; b=pxQW2r4iGhCAx4f6PaFaHmtp3AxEfUnoYgf4spZJHCIXlRgcYrhaZWRsUB2s+QoTGlJnkq3sNIo0Mwv5cpz/BmX6x5Qp0CfegOHTYxTjV/676tsFT4Spqx9TGjJJGStMYWdOrj57KS9Ilt1eyw1qTldOYzh/Mlz9SKEXYuern2M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784667493; c=relaxed/simple; bh=Rhr9/VWiAOU2ysPViZ6y1/ZtZdHQlWxwu4lXWxiMujo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=JpFn5d757OXSvEA0T4o+gEGHJ3Sfwzik1W7uOghtTcTNK48AC5I46tB9aw4m6bo7ZALTEfsqNe0hFGcsHK6Rlt3ohztD0UNqtvcrY80Jt7scTHX8huchkX3vht3av6HHpRRLWqfUPSFHJ+ddyEgVIS2cd/2CT1StQUf3ogAlS0s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=SaZBC2Zn; arc=none smtp.client-ip=209.85.216.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="SaZBC2Zn" Received: by mail-pj1-f72.google.com with SMTP id 98e67ed59e1d1-381250979d5so8962624a91.0 for ; Tue, 21 Jul 2026 13:58:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784667477; x=1785272277; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=WPc/SptN9OuaHPCuk46SdIx0RLVLfa1pOthKWdfhXgQ=; b=SaZBC2ZnnQ5quRLHCQeJ6pmmuIw2IMAbE1D9Ym9M+OWFUvYt+pdwk4aXbiLHwkwKCD h/02jhs6nxp6SuGG54yrmnuYZxhOzj7tcc/J68w+7o+xxxLR+xDTqOdvBSoe9juOOX7g wlsn8q8n+ZBAUONoKrHFUq/j50t5ThDgC0BbOM7QLblnQE3WkLXmV92XmlIYViF7m+gy mrUcSCNdwAO+N78SEJSiPq9Dk25bpbgp+tS1+rL0PMSkLsbstCBtq9Qlwa022mJfZWod pKfxcTU08tWslpivH6xunPQwEwHwabYO5iV8L20sI9jOKsMJJPRmnr2xF1ViwztzA1Hq ql0g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784667477; x=1785272277; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WPc/SptN9OuaHPCuk46SdIx0RLVLfa1pOthKWdfhXgQ=; b=gp2swkOJaDDCtSbhXomLd3j7oMYSllCFMrg4CkL9Dhg8x7pwcteKlAiq4TFbGPkMii GPS0Cn6r2XV0Q6J2wb4q2SNVYW62sQFIbJym6zVPZHqdNxXjhAJLYftBMTRWDEKjNjQ5 J9NyVbCJ9L8XgTYWDJojXy6JCqtU5nPkxVVhYtnz54HNuvMbtM/BqyfW76hLZAXPEdXo q5Dy1pH3ej0nUGINUHKHvWFIiaWfsVXmGCGaHqfm35NBeuhgrPUhJza61IqaHPa7TPYi rYsPh+KzIX9v7o/eTWmWgSpfCXd0/L0rd50PMKwEyT/zodwPjHg6f18rnEgS3/uqL9vR 3fCw== X-Forwarded-Encrypted: i=1; AHgh+RoV0a4q2nNJ2OgY5glORu39Ll5jBN6ToQJvuOyNq4UdVKcfG0ZMoRLb9p2Tk5owDcN0ZU4PCQ6r8ChUAGU=@vger.kernel.org X-Gm-Message-State: AOJu0Yy8w4QxWUlWb25EXQZrtK+SP6kN9pMGc81kogZf3XKYalj8wOtw 6ypYzP4+1iM0tFO7BlzmjZwNmOoOgQaIVScWiim/h29OZgA3hr38SIl4jOddgfjd8fj3wf5E79w K7GqiVAG3+A== X-Received: from dlea1-n2.prod.google.com ([2002:a05:701b:4201:20b0:13b:8289:9a55]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90a:d886:b0:37f:9cdf:f03c with SMTP id 98e67ed59e1d1-38e4b54082emr19361084a91.31.1784667477256; Tue, 21 Jul 2026 13:57:57 -0700 (PDT) Date: Tue, 21 Jul 2026 13:57:46 -0700 In-Reply-To: <20260721205746.183206-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721182150.94016-1-irogers@google.com> <20260721205746.183206-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721205746.183206-5-irogers@google.com> Subject: [PATCH v5 4/4] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Modify bounds and union member access in mmap2 build_id synthesis. Bound max_filename_len against the minimum of filename array capacity and the outer union stack layout minus sample ID trailers. This prevents both -E2BIG overruns and _FORTIFY_SOURCE array bounds aborts on strlcpy even if the enclosing union expands. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 4043d17a6140..704760e1dd5d 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -2450,13 +2450,18 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, size_t filename_len =3D strlen(filename); size_t ev_len; u64 sample_type =3D sample->evsel ? sample->evsel->core.attr.sample_type = : 0; - void *array; + void *array =3D &ev; int ret; + size_t max_filename_len; =20 - if (filename_len >=3D sizeof(ev.mmap2.filename)) - return -EINVAL; + max_filename_len =3D min(sizeof(ev.mmap2.filename) - 1, + sizeof(ev) - (MAX_ID_HDR_ENTRIES * sizeof(__u64)) - + offsetof(struct perf_record_mmap2, filename) - 1); =20 - ev_len =3D sizeof(ev.mmap2) - sizeof(ev.mmap2.filename) + filename_len + = 1; + if (filename_len > max_filename_len) + filename_len =3D max_filename_len; + + ev_len =3D offsetof(struct perf_record_mmap2, filename) + filename_len + = 1; ev_len =3D PERF_ALIGN(ev_len, sizeof(u64)); =20 if (ev_len + MAX_ID_HDR_ENTRIES * sizeof(__u64) > sizeof(ev)) @@ -2476,16 +2481,15 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, =20 ev.mmap2.build_id_size =3D bid->size; if (ev.mmap2.build_id_size > sizeof(ev.mmap2.build_id)) - ev.build_id.size =3D sizeof(ev.mmap2.build_id); + ev.mmap2.build_id_size =3D sizeof(ev.mmap2.build_id); memcpy(ev.mmap2.build_id, bid->data, ev.mmap2.build_id_size); =20 ev.mmap2.prot =3D prot; ev.mmap2.flags =3D flags; =20 - memcpy(ev.mmap2.filename, filename, min(strlen(filename), sizeof(ev.mmap.= filename))); + strlcpy(ev.mmap2.filename, filename, filename_len + 1); =20 - array =3D &ev; - array +=3D ev.header.size; + array =3D (void *)((char *)&ev + ev.header.size); ret =3D perf_event__synthesize_id_sample(array, sample_type, sample); if (ret < 0) return ret; --=20 2.55.0.229.g6434b31f56-goog