From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 095734611CE for ; Tue, 21 Jul 2026 23:53:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677983; cv=none; b=GJIy5vmpQzM8vBnRPp0Jb6TiVW9fVRRTaYe4U7vKxuBTOjzHjnluYgbGwL7ibFBcHaTCvGLZFYynoRk9/6Qpt14bzAmnuAbarvi/UPHCRaW0y0FWpTLuAbhVju/9Z4sRFISNbl+kjeECj6cFEEwEPPA5SKAosVQLPawjrTU6g8I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677983; c=relaxed/simple; bh=pj0KjjICAGQcYFvJa34O/R6iaQNWxgcdqHf3gBWUcgM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=eD5xSdlyD7qXLmjVQri9mwLtc4sQ3hrHEhGQn0OkfchCZvMP7GzhXqC9VPWinDjTvUhhcMh7SRslHVvzE4P23jKARh4SDmmguD/YGUYgr/04VMnIm9PibN1Gr1fWDwBYKXN6LbzswqKY0xkNFiN63lb5trRV7yUqR3j3hLNdxl8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=usekTC5Q; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="usekTC5Q" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-388cfc4848dso14982678a91.3 for ; Tue, 21 Jul 2026 16:53:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784677981; x=1785282781; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=usekTC5Qql84gIKMQz/ij6PxMtjlMlLEf+WVoyFVaizSwbXvXxzYo2IGXIJDFwdWCj YmEAD9yKd/sHHl6/KH1jR43mh880t+z340xa5XbNzq5SQp5+IH5bE2tqBORRyKBMN65x sOBAACZAQfEDg0vB3pUp7YCaoUN8wXHFiOItCPHk0qWjcHRDcVLLvjDv3rck9BNgFHRC LMQUR+kCGmlcNRP3qc0NR9cZRuLcbi69IuRca44+O5HTO3NJwacLNToYT+0yjMi3Dlyw jNWi1X2cKXC+VNMeZAfVStgOSamYoVfS/ty5LHjna9rpiUgJ6ySh4hnm1P+w6nP2BkmW p9Dw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784677981; x=1785282781; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=d5jG9NVpjcGT0OyijdNnlD4kEtCaHdlCbuAaGu1kfKk=; b=fekd53LQTVEAo5gM1jk7p/GDEh095y2Km5+kQhHfemmRUtAw8O/iVA1EOjyw4KDPRg yDSiYWfCXsxHLTGR25zcm6tfx/3b0PzgS1ylgt4HlBfDFkbRITI2k1xM/2+2Re+GO7pQ +PiRblQXSCEGrBuBeyl9uzvz3XeoLvDiKperzlARLRz1Vj0Q99WqufszLisyPAti5Icr IiX7IictMUCe5ctyIpcF3vNKyDnd5Gi1gylI0R4fpywM0QqJiQlCgDBJacviYqUoHZbg 28CIuxict8tQko8K09HyGvtDMc2l1ll+lDUbSG6Uvqvq/FQGvywiY5WR23qWVXz1aKSX 6yng== X-Forwarded-Encrypted: i=1; AHgh+RoBBRtSytf6+FGs2xgtAmrWSSdbKmKyUVuB0xiLQW3iPAYSd4f9nm0aP/fblXOc7WVC7m0fQfAzvtimPJQ=@vger.kernel.org X-Gm-Message-State: AOJu0YyPi4Z8UIcpwT6ase6myoPeVMB+7cWPwcn0yUxAPY/dc2PFjTxL 75xMZ9tuTqQsteCKSUafS6rSQcn1HM4lJ4LKgRgxdbFQOUXB7TEYgnFb/Tb+HF4/01vlbR3uGnQ Skp2Q2z/o4g== X-Received: from dlbtp2.prod.google.com ([2002:a05:7022:3b82:b0:13b:9fe2:1c73]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:2dc1:b0:37f:fdc8:71b4 with SMTP id 98e67ed59e1d1-38e4b3e1424mr20258148a91.2.1784677981089; Tue, 21 Jul 2026 16:53:01 -0700 (PDT) Date: Tue, 21 Jul 2026 16:52:50 -0700 In-Reply-To: <20260721235254.294053-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721230952.267754-1-irogers@google.com> <20260721235254.294053-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721235254.294053-2-irogers@google.com> Subject: [PATCH v7 1/5] perf find-map: Remove PATH_MAX 128-byte stack array restriction From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use getline() to dynamically allocate the required line buffer for maps parsing, guaranteeing bounds safety and avoiding compiler warnings by evaluating the return value in the loop condition directly. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/find-map.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/find-map.c b/tools/perf/util/find-map.c index 7b2300588ece..bba511795a69 100644 --- a/tools/perf/util/find-map.c +++ b/tools/perf/util/find-map.c @@ -1,8 +1,13 @@ // SPDX-License-Identifier: GPL-2.0 +#include +#include +#include + static int find_map(void **start, void **end, const char *name) { FILE *maps; - char line[128]; + char *line =3D NULL; + size_t len =3D 0; int found =3D 0; =20 maps =3D fopen("/proc/self/maps", "r"); @@ -11,7 +16,7 @@ static int find_map(void **start, void **end, const char = *name) return -1; } =20 - while (!found && fgets(line, sizeof(line), maps)) { + while (!found && getline(&line, &len, maps) !=3D -1) { int m =3D -1; =20 /* We care only about private r-x mappings. */ @@ -25,6 +30,7 @@ static int find_map(void **start, void **end, const char = *name) found =3D 1; } =20 + free(line); fclose(maps); return !found; } --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21420472558 for ; Tue, 21 Jul 2026 23:53:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677985; cv=none; b=jeZomqF6kfPJIAtDJ6Cl1LeNldvtjOZadY1TNBh8WtDVFDIGsnnIWNNaLFGRNL0uxAQ+ZO/440G5uStBUSaBW3/um+vkkydahyI1Kkqp56uXVyc7SDhbL5zq6p4+/gRMRcBWapsg+J6pN0h+EBzu8dUCJcW1bDO6YyVJHD/yQtg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677985; c=relaxed/simple; bh=vMihCiw/8AO+eHNdXnnpwYltDYk9DeshmVHLy+zLYPQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=uATc/I4ZqytuJHIYHX+583Es5BGTf71byUnh+k/jLNr3c7HNddWVslI4W9xmaq8Txu6htq6IEYUTI7wf/vgkUo9DjD9JdazcAjbGSGJY+e0Bu9QEPZ9hBeo3WyH/vPmfL3d8Tw4rHifMEalPicjhyuBvNoHHatDFcQo3nncy8tg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=nxpl0sX2; arc=none smtp.client-ip=209.85.216.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nxpl0sX2" Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-3823dcc1647so15269978a91.3 for ; Tue, 21 Jul 2026 16:53:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784677983; x=1785282783; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=4XzRy9P2Zj1BiZg4KwUnMx60z08NkGZxv94q78xdiew=; b=nxpl0sX2aj1NrkVGJvh12LrAyEIc0B2yrdgmxmoVOw9SX/MMqFKI4lyzOdIJ0nrMG7 5fHKMy09UwBNxebXyZX0DgdPxl+RIi+Xrc7JZ3gmBlxAHG8AhzzApnJ67ZRZgDlCK6kQ l1DFo4hvL3/7y2l787DqwUwBSwDujfwCQNq9Ti+4rWGquFe6kiFa2KoFbbUkj7WIQDwb UCPDSBIrI2k5OmdGYAVo3sjid5Cy6UH+qsqT3nbOoVDbE2xlv+ghCvAJnsFECC/OSnb2 DYfoKMRTXOTG9VOeF806V9iiSd2HN4onmRPrKzoIGwmpyBFKZ3oluPSOkW8yhjVgoQZi 5w4w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784677983; x=1785282783; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4XzRy9P2Zj1BiZg4KwUnMx60z08NkGZxv94q78xdiew=; b=NGGQ+TH+Wf9ih71iit5k06sOVk3K+bm1MrYKyPUpO0Cl7lDXsooyx5erfjkvxbw6Ge 7tvj86HI0soK/Aj14jPQ7bK3MWw9CAVoHQJQPZPVcyvqYZIdrLCytvOI1DCcLwZkVHGM 6CdQhssGEchefGWAgwVYKYKycGfEFHyP5J6LBnBPDW2giwvweeX5NfE0GQRGkpXRqzOP Dn4MXbpJIdAPnWllItIxYcreKOByJ9hy9CHoVDqD/uK/59jkCwq8pa6T2vSKCNTmVrXx jbXGkCufBeMRnr8oeTKbPAvx7k+CQ/9K7HkibNFkti6xeDHO4u75nqMdQ55h3MrJ1Iim jLog== X-Forwarded-Encrypted: i=1; AHgh+Rp3nJFwMTPFLkOOkik/eNV2pQJZZMHe+RfUoNc3ftCdJpaPAwJrP8s3uaOyY48XGRVQPpnoFFunsTOgXYY=@vger.kernel.org X-Gm-Message-State: AOJu0Ywv+H0e0KBjELOUPWCl/hgmmSXYAOFFCBbPKkShKvZFZsSl7PHe NmIgAKjEqanoIcfraNfF/CDDOZYVWIDRqqIDxtg3jswqp6OQiFEzpoEZTOdSGg+ZV/6YPLCVKpf AVeW+TBIv3A== X-Received: from dlep8-n2.prod.google.com ([2002:a05:701b:4588:20b0:13c:f3ec:ddf4]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:5604:b0:37f:9ce2:348f with SMTP id 98e67ed59e1d1-38e4b55ab8dmr20836628a91.32.1784677983105; Tue, 21 Jul 2026 16:53:03 -0700 (PDT) Date: Tue, 21 Jul 2026 16:52:51 -0700 In-Reply-To: <20260721235254.294053-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721230952.267754-1-irogers@google.com> <20260721235254.294053-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721235254.294053-3-irogers@google.com> Subject: [PATCH v7 2/5] perf synthetic-events: Fix line synchronization, bounds, and truncation bugs in proc maps reader From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix critical logic and boundary bugs in read_proc_maps_line() and caller. Ensure any mid-line hex/dec/char parsing failure invokes io__drain_line() safely, using a do-while loop to read and discard remaining characters until a newline or EOF is reached. Clamp pathname extraction size to account for trailing sample ID headers, use standard '//toolong' fallback literal for over-length pathnames, emit timeout flags for truncated entries securely via goto out;, and cast event buffer pointers to avoid _FORTIFY_SOURCE array bounds aborts across synthesis handlers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 204 ++++++++++++++++++++--------- 1 file changed, 142 insertions(+), 62 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index b75f9dcf4dbf..832b74ffb4db 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -179,7 +179,8 @@ static int perf_event__prepare_comm(union perf_event *e= vent, pid_t pid, pid_t ti =20 size =3D strlen(event->comm.comm) + 1; size =3D PERF_ALIGN(size, sizeof(u64)); - memset(event->comm.comm + size, 0, machine->id_hdr_size); + memset((char *)event + offsetof(struct perf_record_comm, comm) + size, + 0, machine->id_hdr_size); event->comm.header.size =3D (sizeof(event->comm) - (sizeof(event->comm.comm) - size) + machine->id_hdr_size); @@ -291,6 +292,18 @@ static int perf_event__synthesize_fork(const struct pe= rf_tool *tool, return 0; } =20 +static void io__drain_line(struct io *io, int ch) +{ + if (ch =3D=3D '\n') + return; + if (ch =3D=3D -2 && io->data > io->buf && io->data[-1] =3D=3D '\n') + return; + + do { + ch =3D io__get_char(io); + } while (ch >=3D 0 && ch !=3D '\n'); +} + static bool read_proc_maps_line(struct io *io, __u64 *start, __u64 *end, u32 *prot, u32 *flags, __u64 *offset, u32 *maj, u32 *min, @@ -299,69 +312,127 @@ static bool read_proc_maps_line(struct io *io, __u64= *start, __u64 *end, { __u64 temp; int ch; - char *start_pathname =3D pathname; + size_t written =3D 0; + bool overflowed =3D false; =20 - if (io__get_hex(io, start) !=3D '-') + ch =3D io__get_hex(io, start); + if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_hex(io, end) !=3D ' ') + } + ch =3D io__get_hex(io, end); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 /* map protection and flags bits */ *prot =3D 0; ch =3D io__get_char(io); if (ch =3D=3D 'r') *prot |=3D PROT_READ; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'w') *prot |=3D PROT_WRITE; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 'x') *prot |=3D PROT_EXEC; - else if (ch !=3D '-') + else if (ch !=3D '-') { + if (!io->eof) + io__drain_line(io, ch); return false; + } ch =3D io__get_char(io); if (ch =3D=3D 's') *flags =3D MAP_SHARED; else if (ch =3D=3D 'p') *flags =3D MAP_PRIVATE; - else + else { + if (!io->eof) + io__drain_line(io, ch); return false; - if (io__get_char(io) !=3D ' ') + } + ch =3D io__get_char(io); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, offset) !=3D ' ') + ch =3D io__get_hex(io, offset); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } =20 - if (io__get_hex(io, &temp) !=3D ':') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ':') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *maj =3D temp; - if (io__get_hex(io, &temp) !=3D ' ') + ch =3D io__get_hex(io, &temp); + if (ch !=3D ' ') { + if (!io->eof) + io__drain_line(io, ch); return false; + } *min =3D temp; =20 ch =3D io__get_dec(io, inode); if (ch !=3D ' ') { - *pathname =3D '\0'; - return ch =3D=3D '\n'; + if (ch =3D=3D '\n') { + pathname[0] =3D '\0'; + return true; + } + if (!io->eof) + io__drain_line(io, ch); + return false; } + do { ch =3D io__get_char(io); } while (ch =3D=3D ' '); + while (true) { - if (ch < 0) - return false; - if (ch =3D=3D '\0' || ch =3D=3D '\n' || - (pathname + 1 - start_pathname) >=3D pathname_size) { - *pathname =3D '\0'; - return true; + if (ch < 0) { + if (overflowed) { + strlcpy(pathname, "//toolong", pathname_size); + return true; + } + pathname[written] =3D '\0'; + return written > 0; } - *pathname++ =3D ch; + if (ch =3D=3D '\0' || ch =3D=3D '\n') + break; + + if (written < (size_t)pathname_size - 1) + pathname[written++] =3D (char)ch; + else + overflowed =3D true; ch =3D io__get_char(io); } + + if (overflowed) + strlcpy(pathname, "//toolong", pathname_size); + else + pathname[written] =3D '\0'; + + return true; } =20 static void perf_record_mmap2__read_build_id(struct perf_record_mmap2 *eve= nt, @@ -463,45 +534,53 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, while (!io.eof) { static const char anonstr[] =3D "//anon"; size_t size, aligned_size; - - /* ensure null termination since stack will be reused. */ - event->mmap2.filename[0] =3D '\0'; + __u64 start, end, pgoff, ino; + u32 prot, flags, maj, min; =20 /* 00400000-0040c000 r-xp 00000000 fd:01 41038 /bin/cat */ - if (!read_proc_maps_line(&io, - &event->mmap2.start, - &event->mmap2.len, - &event->mmap2.prot, - &event->mmap2.flags, - &event->mmap2.pgoff, - &event->mmap2.maj, - &event->mmap2.min, - &event->mmap2.ino, - sizeof(event->mmap2.filename), - event->mmap2.filename)) + /* Read directly into event->mmap2.filename, clamping for id_hdr_size! */ + if (!read_proc_maps_line(&io, &start, &end, + &prot, &flags, &pgoff, + &maj, &min, &ino, + sizeof(event->mmap2.filename) - machine->id_hdr_size, + event->mmap2.filename)) { + if (io.eof) + break; continue; + } =20 - if ((rdclock() - t) > timeout) { - pr_warning("Reading %s/proc/%d/task/%d/maps time out. " - "You may want to increase " - "the time limit by --proc-map-timeout\n", - machine->root_dir, pid, pid); - truncation =3D true; - goto out; + if (!strcmp(event->mmap2.filename, "")) + strcpy(event->mmap2.filename, anonstr); + + if (hugetlbfs_mnt_len && + !strncmp(event->mmap2.filename, hugetlbfs_mnt, hugetlbfs_mnt_len)) { + strcpy(event->mmap2.filename, anonstr); + flags |=3D MAP_HUGETLB; } =20 - event->mmap2.ino_generation =3D 0; + size =3D strlen(event->mmap2.filename) + 1; + aligned_size =3D PERF_ALIGN(size, sizeof(u64)); + + event->mmap2.header.type =3D PERF_RECORD_MMAP2; =20 /* - * Just like the kernel, see __perf_event_mmap in kernel/perf_event.c + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) event->header.misc =3D PERF_RECORD_MISC_USER; else event->header.misc =3D PERF_RECORD_MISC_GUEST_USER; =20 - if ((event->mmap2.prot & PROT_EXEC) =3D=3D 0) { - if (!mmap_data || (event->mmap2.prot & PROT_READ) =3D=3D 0) + if ((rdclock() - t) > timeout) { + pr_warning("Reading %s/proc/%d/task/%d/maps time out. You may want to i= ncrease the time limit by --proc-map-timeout\n", + machine->root_dir, pid, pid); + truncation =3D true; + goto out; + } + + if ((prot & PROT_EXEC) =3D=3D 0) { + if (!mmap_data || (prot & PROT_READ) =3D=3D 0) continue; =20 event->header.misc |=3D PERF_RECORD_MISC_MMAP_DATA; @@ -511,26 +590,26 @@ int perf_event__synthesize_mmap_events(const struct p= erf_tool *tool, if (truncation) event->header.misc |=3D PERF_RECORD_MISC_PROC_MAP_PARSE_TIMEOUT; =20 - if (!strcmp(event->mmap2.filename, "")) - strcpy(event->mmap2.filename, anonstr); + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; =20 - if (hugetlbfs_mnt_len && - !strncmp(event->mmap2.filename, hugetlbfs_mnt, - hugetlbfs_mnt_len)) { - strcpy(event->mmap2.filename, anonstr); - event->mmap2.flags |=3D MAP_HUGETLB; - } + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap2, filename) + si= ze, 0, + (aligned_size - size) + machine->id_hdr_size); =20 - size =3D strlen(event->mmap2.filename) + 1; - aligned_size =3D PERF_ALIGN(size, sizeof(u64)); - event->mmap2.len -=3D event->mmap.start; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - aligned_size)); - memset(event->mmap2.filename + size, 0, machine->id_hdr_size + - (aligned_size - size)); event->mmap2.header.size +=3D machine->id_hdr_size; + event->mmap2.start =3D start; + event->mmap2.len =3D end - start; + event->mmap2.pgoff =3D pgoff; + event->mmap2.maj =3D maj; + event->mmap2.min =3D min; + event->mmap2.ino =3D ino; + event->mmap2.ino_generation =3D 0; event->mmap2.pid =3D tgid; event->mmap2.tid =3D pid; + event->mmap2.prot =3D prot; + event->mmap2.flags =3D flags; =20 if (!symbol_conf.no_buildid_mmap2) perf_record_mmap2__read_build_id(&event->mmap2, machine, false); @@ -579,7 +658,8 @@ static int perf_event__synthesize_cgroup(const struct p= erf_tool *tool, =20 event->cgroup.id =3D handle.cgroup_id; strncpy(event->cgroup.path, path + mount_len, path_len); - memset(event->cgroup.path + path_len, 0, machine->id_hdr_size); + memset((char *)event + offsetof(struct perf_record_cgroup, path) + path_l= en, + 0, machine->id_hdr_size); =20 if (perf_tool__process_synth_event(tool, event, machine, process) < 0) { pr_debug("process synth event failed\n"); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B186945DF7A for ; Tue, 21 Jul 2026 23:53:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677987; cv=none; b=edVtEYfdN4lU4ONV4VCQLNW4S93ExNgfXCOJLxxuqSx04dU1p4MpUxVS6k7T19ISrExtOgqK7Vy1tFlbDaykKHaI2pZYtXvfVQMDPaoGNHIL/91ACp1cbrDQHnxRotEZlSE3rKWtRhLSlFWyjAeIUfCHla/zsW7q52Bo2mU0YXg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677987; c=relaxed/simple; bh=QVBzXFZ+m+PkDD6qLVSNfdTw6jXGRoWG5ySf0zcf6Co=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RGDCY8NsAqFid8tBTWbkaZeb7gjtoA5vSgMF/DssYjppF+p6l6EEtDmhIuoqwEWvBdt48RAfONNcOPouF/vZFHpD8q9FGltu5hz4DR7Bz8j16/3hPWjugCV0AGhXn7GMs64f8b6bV7t+G/K/G+jM3dUGrPHgyDAaPtbOvAecl10= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=LyLuaKM8; arc=none smtp.client-ip=209.85.215.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="LyLuaKM8" Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-cb48f41343aso4023542a12.1 for ; Tue, 21 Jul 2026 16:53:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784677985; x=1785282785; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=MmfaatJPVa3SJnEw9FgvQrwsrNHQ8Yb7V+zeXCvk3Jk=; b=LyLuaKM8SQz8Xb+gQxIbQ5A9JW2VIdD4VGSCHVPXVwz0ZWu6uDYpl4bealwsJJ/ZpE aV+zkDAIXNMiNk91Upvd3DvwFBi+IEyf/jlGJR0fwsK5+a9weK3vhgai9GMyC6PtXxe/ PdYS2Knkmks4kQV4RttNvRTv6nWZYvxdBNUTkPlbQgoWWGkZimn8SnAwyJYog5v2OHpT bN5ZJOCeXy7g6ZJpfFtajinfUEqhy2GW/9f7kPVqgRih3i8oLh67rEkRB7FqzxJsEn+V 7d8jIpBFlO5ElqkRlxUyco7GI3FhMk3fBzBhPewcLLzVqtgnVeEvQw4quyJU3n/F3Dic epSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784677985; x=1785282785; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MmfaatJPVa3SJnEw9FgvQrwsrNHQ8Yb7V+zeXCvk3Jk=; b=YCC6ma5/83inobdtbtCgoMYK8rpMLFdzcDSG8D3fwILDyXe5h78TpxF58fxX8Mx1ZJ 7eX62DvSQbisrcL4o2S9rGEAV42eeHM5yHdJAITDwSnivz7+tmbe+X6kTOqWz7fg2Nix crkVhIPw1DWb+4I48U0Fz3pC4BAodm8Dy+pmj9SjKrfyrT1jQQk9eXFIFSvh7JqkN8+c FDvumMlbDmBW24Pl/byoUC85fcUZrQqlbDgfHjWJ27QK9zEnxtXlgLUB2+B5hHBOOy/G dTXUmPADPDSVqLEck2Z5eTA1a7gpyubGlC7Q1ZR1kXulasVQDG5uYbxatBcTs6bxjqFe FxFg== X-Forwarded-Encrypted: i=1; AHgh+RrOLqX66xJ9kMeulGZRCxSmyFDO5OapAvaDOYIUuLg70ICM6hyBfx0ihlaFFO0KNXXqv7EzGO5wgQ0jvJ0=@vger.kernel.org X-Gm-Message-State: AOJu0YwHP6FAQemM2IoGC5mdBv51BWqYZ6EKVNPvasxqAbfJJcrNGwW9 N1RueTDR0j7sO2DlGxCwHznwhI+tihpaTWa/tDgTrtKSByDD/PjFiNXyUzgjZtnvRF7jrCs0csc 9EMbNIzcMNg== X-Received: from dyos40.prod.google.com ([2002:a05:7300:6ca8:b0:313:cf74:cf85]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:a06:b0:3b3:a66e:3911 with SMTP id adf61e73a8af0-3c429455fabmr1514232637.19.1784677984795; Tue, 21 Jul 2026 16:53:04 -0700 (PDT) Date: Tue, 21 Jul 2026 16:52:52 -0700 In-Reply-To: <20260721235254.294053-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721230952.267754-1-irogers@google.com> <20260721235254.294053-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721235254.294053-4-irogers@google.com> Subject: [PATCH v7 3/5] perf synthetic-events: Fix stack buffer overflow and bounds in cgroup synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fix a pre-existing stack buffer overflow bug in perf_event__synthesize_cgroup() where an in-place null padding loop wrote bytes past the end of the cgrp_root stack array buffer during cgroup tree traversal. Eliminate in-place path mutation, use PERF_ALIGN for path_len, clamp raw_path_len to prevent sample ID header trailer overruns, and use strlcpy with combined zero padding for alignment and sample ID headers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 832b74ffb4db..05075840707c 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -635,15 +635,22 @@ static int perf_event__synthesize_cgroup(const struct= perf_tool *tool, struct machine *machine) { size_t event_size =3D sizeof(event->cgroup) - sizeof(event->cgroup.path); - size_t path_len =3D strlen(path) - mount_len + 1; + size_t raw_path_len, path_len, max_path_len; struct { struct file_handle fh; uint64_t cgroup_id; } handle; int mount_id; =20 - while (path_len % sizeof(u64)) - path[mount_len + path_len++] =3D '\0'; + if (strlen(path) < mount_len) + return -1; + + max_path_len =3D sizeof(event->cgroup.path) - machine->id_hdr_size; + raw_path_len =3D strlen(path) - mount_len + 1; + if (raw_path_len > max_path_len) + raw_path_len =3D max_path_len; + + path_len =3D PERF_ALIGN(raw_path_len, sizeof(u64)); =20 memset(&event->cgroup, 0, event_size); =20 @@ -657,9 +664,9 @@ static int perf_event__synthesize_cgroup(const struct p= erf_tool *tool, } =20 event->cgroup.id =3D handle.cgroup_id; - strncpy(event->cgroup.path, path + mount_len, path_len); - memset((char *)event + offsetof(struct perf_record_cgroup, path) + path_l= en, - 0, machine->id_hdr_size); + strlcpy(event->cgroup.path, path + mount_len, raw_path_len); + memset((char *)event + offsetof(struct perf_record_cgroup, path) + raw_pa= th_len, + 0, (path_len - raw_path_len) + machine->id_hdr_size); =20 if (perf_tool__process_synth_event(tool, event, machine, process) < 0) { pr_debug("process synth event failed\n"); --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA0AC473C61 for ; Tue, 21 Jul 2026 23:53:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677990; cv=none; b=FCWLwx2r8TC8mIi8ZDHMeGILfToGVOs5/Wv6PIs+M5GF4CeJTxgHn59jM7udklink4LAYAp6VGa+5JR11p2fTurg86VQbpoo69mbeFxH65PS7UzPRT4cFLhwutAGy6eWqCB3aLDRDEVX+WyRzuYYOYCm8t+Mub8zl9QNe/cBRQI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677990; c=relaxed/simple; bh=paepAH2E0jLufHogFip8cAVfpDUXNWbxACpeWg+pSWM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=MbM6rF6GGgwX57V0rWeLY36uwwg2a3OLfp6vrrSkZ3Fy9B0Qze9qQUbJ1DjKlhWTGBjbbMwNgg3hnLZM6Nbk20bIsefG3BeAEy9XPYOFdTtB9wBGBrIpRLmeoJLlknDrTZ44qVNCeG5wp5HMj7T42CA6bGflU1UEUhuT0sqM87M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Adzc6vZj; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Adzc6vZj" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-ca8aee88725so17906564a12.3 for ; Tue, 21 Jul 2026 16:53:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784677987; x=1785282787; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=gKPG9XIny/RZplkPYLo3KKeMyTZgRDdgY2/iWOu0y/A=; b=Adzc6vZjNMdwH/pes8Ye2rbcLC/JdUNqkdW/FXsx38oB1S5GAphm0vKynoDx3/0rbe 8+1fgZLbKKsXqhWd+F47F6vriXePoSGRjkSmz5iYM8phE0QdeJTDR2dj2RIwIJgTNUAx /5kssFcTAZrz/kZTwdwnciNpTJMR2MTMvvFcR9HQKmRbALSwQYEEj5f3F97jkAXxsx3v ZwO6AptyR6vdBjXbHCWIVkDrjJFH4CofmMEUhvSCh08Xq7BQh+VzQazrc3hzjFeuNQq3 EityEM5KYGJpgM+AFgG3IniXNQOmK58bHtVwnJUwo9M0cBJ4NTmdKnkd8AZuYoNDD1NR Hwyg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784677987; x=1785282787; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=gKPG9XIny/RZplkPYLo3KKeMyTZgRDdgY2/iWOu0y/A=; b=Zk+LvPUgNoUZhhnfCsID2tjQRolAhqwGOF0o8OJ41cDrLydu1k/IL92eTs2n12gXYm fqnyi1NEALyUa3PbYMlMNTsWGicfE/2so2eMNuPps024lOCIEJxrfcqFSvzjh7GpLWJj YrkJ0Fu3GIhyDw39aIH4TYHRVRSULzj3PAUhup95XAA8ZzATbNKbURqAKSWx34KFJ20X trqm8ULKSl+R/yw+ehC86TxbTtVqt1Ix+dOU0M8Is7Irlzmj/esiaePB7SvQW1zSt0Pk 7xDFH8fWzsKFSKRXWfkfC2jB1KFooHds2NPTFGiEpwoINlnLeEPFsMrCFRd1iXUyi6SJ PMtA== X-Forwarded-Encrypted: i=1; AHgh+Rqk/IRRHikIyfE0nPVPT4AMro1GEDsYI3VfASSg+TDqw0Vo8jltn2QO4OQX5ZTPP5ihFefobaBWpJGJ2Jw=@vger.kernel.org X-Gm-Message-State: AOJu0YzFMDUFutUbbgQfshrT+S5geMV1ubSg1Om+lflNM8mWWpnZSQ4D qpVBAX675mvSYpa/ath0TVF+Uw6ZcpoGJxQSl0trpwyfI9vK2VnqZguA/e2gV3H3tuOCTPSbkMa V2z3FDfc8Nw== X-Received: from dygg9.prod.google.com ([2002:a05:693c:80c9:b0:313:d984:da01]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6300:6a17:b0:3c4:2cf9:2896 with SMTP id adf61e73a8af0-3c42cf939b3mr779017637.45.1784677986715; Tue, 21 Jul 2026 16:53:06 -0700 (PDT) Date: Tue, 21 Jul 2026 16:52:53 -0700 In-Reply-To: <20260721235254.294053-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721230952.267754-1-irogers@google.com> <20260721235254.294053-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721235254.294053-5-irogers@google.com> Subject: [PATCH v7 4/5] perf synthetic-events: Fix bounds, stale state, and misc flags in kernel module synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Clamp long DSO names to mmap/mmap2 filename boundaries accounting for sample ID headers to prevent buffer overruns in perf_event__synthesize_modules_maps_cb(). Explicitly clear misc flags and union padding to prevent stale Build-ID state from leaking between module synthesis events, and cast event buffer pointers to avoid _FORTIFY_SOURCE array bounds aborts when zeroing padding trailers. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 70 +++++++++++++++++++++--------- 1 file changed, 50 insertions(+), 20 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 05075840707c..5bbf024ad606 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -764,6 +764,7 @@ struct perf_event__synthesize_modules_maps_cb_args { perf_event__handler_t process; struct machine *machine; union perf_event *event; + u16 misc; }; =20 static int perf_event__synthesize_modules_maps_cb(struct map *map, void *d= ata) @@ -771,49 +772,78 @@ static int perf_event__synthesize_modules_maps_cb(str= uct map *map, void *data) struct perf_event__synthesize_modules_maps_cb_args *args =3D data; union perf_event *event =3D args->event; struct dso *dso; - size_t size; + size_t size, aligned_size; + int rc =3D 0; =20 if (!__map__is_kmodule(map)) return 0; =20 dso =3D map__dso(map); if (!symbol_conf.no_buildid_mmap2) { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap2.filename) - args->machine->id_hdr_size) + size =3D sizeof(event->mmap2.filename) - args->machine->id_hdr_size - 1; + + strlcpy(event->mmap2.filename, long_name, + sizeof(event->mmap2.filename) - args->machine->id_hdr_size); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap2.header.type =3D PERF_RECORD_MMAP2; - event->mmap2.header.size =3D (sizeof(event->mmap2) - - (sizeof(event->mmap2.filename) - size)); - memset(event->mmap2.filename + size, 0, args->machine->id_hdr_size); + event->mmap2.header.misc =3D args->misc; + event->mmap2.header.size =3D + offsetof(struct perf_record_mmap2, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap2, filename) + si= ze, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap2.header.size +=3D args->machine->id_hdr_size; event->mmap2.start =3D map__start(map); event->mmap2.len =3D map__size(map); event->mmap2.pid =3D args->machine->pid; =20 - memcpy(event->mmap2.filename, dso__long_name(dso), dso__long_name_len(ds= o) + 1); - - /* Clear stale build ID from previous module iteration */ + /* Clear stale build ID and entire union from previous module iteration = */ event->mmap2.header.misc &=3D ~PERF_RECORD_MISC_MMAP_BUILD_ID; memset(event->mmap2.build_id, 0, sizeof(event->mmap2.build_id)); event->mmap2.build_id_size =3D 0; + event->mmap2.__reserved_1 =3D 0; + event->mmap2.__reserved_2 =3D 0; =20 perf_record_mmap2__read_build_id(&event->mmap2, args->machine, false); } else { - size =3D PERF_ALIGN(dso__long_name_len(dso) + 1, sizeof(u64)); + const char *long_name =3D dso__long_name(dso); + + size =3D strlen(long_name); + if (size >=3D sizeof(event->mmap.filename) - args->machine->id_hdr_size) + size =3D sizeof(event->mmap.filename) - args->machine->id_hdr_size - 1; + + strlcpy(event->mmap.filename, long_name, + sizeof(event->mmap.filename) - args->machine->id_hdr_size); + + aligned_size =3D PERF_ALIGN(size + 1, sizeof(u64)); event->mmap.header.type =3D PERF_RECORD_MMAP; - event->mmap.header.size =3D (sizeof(event->mmap) - - (sizeof(event->mmap.filename) - size)); - memset(event->mmap.filename + size, 0, args->machine->id_hdr_size); + event->mmap.header.misc =3D args->misc; + event->mmap.header.size =3D + offsetof(struct perf_record_mmap, filename) + + aligned_size; + + /* Zero the padding and ID header trailer safely! */ + memset((char *)event + offsetof(struct perf_record_mmap, filename) + siz= e, 0, + (aligned_size - size) + args->machine->id_hdr_size); + event->mmap.header.size +=3D args->machine->id_hdr_size; event->mmap.start =3D map__start(map); event->mmap.len =3D map__size(map); event->mmap.pid =3D args->machine->pid; - - memcpy(event->mmap.filename, dso__long_name(dso), dso__long_name_len(dso= ) + 1); } =20 if (perf_tool__process_synth_event(args->tool, event, args->machine, args= ->process) !=3D 0) - return -1; + rc =3D -1; =20 - return 0; + return rc; } =20 int perf_event__synthesize_modules(const struct perf_tool *tool, perf_even= t__handler_t process, @@ -838,13 +868,13 @@ int perf_event__synthesize_modules(const struct perf_= tool *tool, perf_event__han } =20 /* - * kernel uses 0 for user space maps, see kernel/perf_event.c - * __perf_event_mmap + * Just like the kernel, see perf_misc_flags() in + * kernel/events/core.c */ if (machine__is_host(machine)) - args.event->header.misc =3D PERF_RECORD_MISC_KERNEL; + args.misc =3D PERF_RECORD_MISC_KERNEL; else - args.event->header.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; + args.misc =3D PERF_RECORD_MISC_GUEST_KERNEL; =20 rc =3D maps__for_each_map(maps, perf_event__synthesize_modules_maps_cb, &= args); =20 --=20 2.55.0.229.g6434b31f56-goog From nobody Sat Jul 25 00:13:36 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 59B4947607F for ; Tue, 21 Jul 2026 23:53:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677991; cv=none; b=YXP3U2vZkvVBIajYHt/RSDmar0OLIfZSpie+0OJzp8Xg3JrbPAQqprngEmcWNjsOPJPfNeMzCzwyp78go9hBPBjLRB5S47aiWBV2z5+upltzhzIbUvcbh14ig7GOgKJ1cs7RPKjMJ3vn4QvbYBjFeMUuTd3R4A55zSgTEn/J5e8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784677991; c=relaxed/simple; bh=/YeOSfAgO5rkMvf9uJr3Wv7ZqimEhbokrDMzqormkcQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=mbVU+d3qcBlEievIPq0PIm+xWaTJdf10Bfqg0uTh1EPSZ+gsCRZ5KbujPfFO5SKGjoNA7/w5pKjBgafUNmL2BhVjBsxSGa46xVM01aqTjr2ECB/ZTvz871Guntd7OKL5WdvKiDUqHVNKjIzYYujXJ/dUqeqA5bGa28F5USNH9ZE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=e4jJzwVO; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="e4jJzwVO" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-38e22137fb3so10711600a91.0 for ; Tue, 21 Jul 2026 16:53:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784677990; x=1785282790; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=CVX6X+hj30Y8z8Y2WWGsOx1d6huMMqhYwvfBgRyMVvE=; b=e4jJzwVOkgtsTZ3H6Azp+vvyEi9kYVuHUfYAVxBKWUus5WvoT6vjCntIddApbBUUbE beKpPPeVHx0+CuO6zHNR2e+qEir98gATqMHUgKGqs9gV1IfvonCxZYJ+UUqsrqPnvjwp 6qyPODAnw1zavH/3I/OsJNpT866EGFsUMmI2s9H0kLc6foD9fzDVGMHOdIbzGiUC5I5p StMMU6CycppeOk2PS++GDjZyf3YYe36KuR46u+5rSZdgIp4lnaqH1KQBoEvA0F8sM/4k TO5mvPOb5YpI7rRZuRJo0cBnYRGklTP67w2oox0tVQoEryilOSwGPGy47wexe54FFmCM +esg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784677990; x=1785282790; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CVX6X+hj30Y8z8Y2WWGsOx1d6huMMqhYwvfBgRyMVvE=; b=VinYZ0f+KSBFP2M50pXFtUNVymBlV/fC6VzKdDf47Z2Rf7+tGKJYSJ/ui6tsXqprof z8lFmoLMY8RKXNUhc9N2qORqvYXyD8QDmoHFPFvwrMw/rDDHcgGiX1QTZHLw2Z785FwQ 9mPb57ih1IrTowwJxFOO+iXmpVL09SCQpDYEwjSvNvR9za7J+k8T+kB+YYuAWzTkNdnt XCQuj2nn29vAN2UjM5PPPcK4C/I+WjopWrfIZ/mNojWztVynI8OyosXcI6d1JUahqhFO zO3LjW1wxl1367RyxprKJngD2va3b4w5LWHEtExh7WCH8rv0c0aSh4pPav/uWSV9c9w3 W11Q== X-Forwarded-Encrypted: i=1; AHgh+RoFBlRk59gizIc3O/+s2qiYAS0a3z/BN/LFCnL0UuPNQrNLxv3nl5WqvphIjbg9biKnHMLlxV3jIa2rmo8=@vger.kernel.org X-Gm-Message-State: AOJu0Yzs0N/1ptCifWeY3TG6Sxwm8HwArjGqkc09ZZBldB+HXv4qW7pV RCWxIGTxVNX4YcdnTS/hyHrm8wSA4RKkcxXAzdZ8/YVp2oIWyoDnMwGLAi6TUn8223/Nj3tdWZ6 YQRCKQE3PEg== X-Received: from dloo22-n2.prod.google.com ([2002:a05:7023:a56:20b0:13c:e1bd:718c]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4b86:b0:38e:8050:e63a with SMTP id 98e67ed59e1d1-38e8050e7b8mr9552295a91.6.1784677989362; Tue, 21 Jul 2026 16:53:09 -0700 (PDT) Date: Tue, 21 Jul 2026 16:52:54 -0700 In-Reply-To: <20260721235254.294053-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260721230952.267754-1-irogers@google.com> <20260721235254.294053-1-irogers@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260721235254.294053-6-irogers@google.com> Subject: [PATCH v7 5/5] perf synthetic-events: Fix bounds and union member access in mmap2 build_id synthesis From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, ravi.bangoria@amd.com, swapnil.sapkal@amd.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Modify bounds and union member access in mmap2 build_id synthesis. Bound max_filename_len against the minimum of filename array capacity and the outer union stack layout minus sample ID trailers. This prevents both -E2BIG overruns and _FORTIFY_SOURCE array bounds aborts on strlcpy even if the enclosing union expands. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Ian Rogers --- tools/perf/util/synthetic-events.c | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic= -events.c index 5bbf024ad606..75a32ae8ef62 100644 --- a/tools/perf/util/synthetic-events.c +++ b/tools/perf/util/synthetic-events.c @@ -2457,13 +2457,18 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, size_t filename_len =3D strlen(filename); size_t ev_len; u64 sample_type =3D sample->evsel ? sample->evsel->core.attr.sample_type = : 0; - void *array; + void *array =3D &ev; int ret; + size_t max_filename_len; =20 - if (filename_len >=3D sizeof(ev.mmap2.filename)) - return -EINVAL; + max_filename_len =3D min(sizeof(ev.mmap2.filename) - 1, + sizeof(ev) - (MAX_ID_HDR_ENTRIES * sizeof(__u64)) - + offsetof(struct perf_record_mmap2, filename) - 1); =20 - ev_len =3D sizeof(ev.mmap2) - sizeof(ev.mmap2.filename) + filename_len + = 1; + if (filename_len > max_filename_len) + filename_len =3D max_filename_len; + + ev_len =3D offsetof(struct perf_record_mmap2, filename) + filename_len + = 1; ev_len =3D PERF_ALIGN(ev_len, sizeof(u64)); =20 if (ev_len + MAX_ID_HDR_ENTRIES * sizeof(__u64) > sizeof(ev)) @@ -2483,16 +2488,15 @@ int perf_event__synthesize_mmap2_build_id(const str= uct perf_tool *tool, =20 ev.mmap2.build_id_size =3D bid->size; if (ev.mmap2.build_id_size > sizeof(ev.mmap2.build_id)) - ev.build_id.size =3D sizeof(ev.mmap2.build_id); + ev.mmap2.build_id_size =3D sizeof(ev.mmap2.build_id); memcpy(ev.mmap2.build_id, bid->data, ev.mmap2.build_id_size); =20 ev.mmap2.prot =3D prot; ev.mmap2.flags =3D flags; =20 - memcpy(ev.mmap2.filename, filename, min(strlen(filename), sizeof(ev.mmap.= filename))); + strlcpy(ev.mmap2.filename, filename, filename_len + 1); =20 - array =3D &ev; - array +=3D ev.header.size; + array =3D (void *)((char *)&ev + ev.header.size); ret =3D perf_event__synthesize_id_sample(array, sample_type, sample); if (ret < 0) return ret; --=20 2.55.0.229.g6434b31f56-goog