From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dy1-f201.google.com (mail-dy1-f201.google.com [74.125.82.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4F7953090C4 for ; Fri, 5 Jun 2026 06:06:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780639579; cv=none; b=HvwjWspCEYXxywCrPlUhFwvVO2sOzNS1l8kdgQNMDPEowEIqm4HQwB2YbIZTW4+FVjhuPxjSQZByMTpBgV+7FcRpQiEa+PyOsgFeUKCnr1m/Ckvi5WEkdrE/JOcQT8LvOkLW2NbQHsu1mVVM47V14FfNu81isFnErC/ug9Qkruc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780639579; c=relaxed/simple; bh=YmRJYa9tnV9W/p/d/fVpaKsqWaOWw+VYRIkEOl1kXao=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=edU7Bav1jswkR20PVeBxCp9IcO7FzJLy8OJCuiySf3Ko+2HJ5zDfiRyi6udiQ9+NHLNhsyQxoBYxhAnSI/aBwowe2LQbfKb2uXDjLszDZvjyuGm5yR3qxgWXFbK+faBLZ3bfZzCqJ5I0vvdStAyynXo/r9i5xC2nQ3LHnXrWL18= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=B4Q9ID3y; arc=none smtp.client-ip=74.125.82.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="B4Q9ID3y" Received: by mail-dy1-f201.google.com with SMTP id 5a478bee46e88-3074d4102a9so1284632eec.0 for ; Thu, 04 Jun 2026 23:06:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1780639576; x=1781244376; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=RLDzqoAhJHGWy0IaWlTQOPcDKqvuE8yyG/YnkFaABUY=; b=B4Q9ID3yJe4oywKyOE2XsE6hw8KLHg+GKs+caCD9mOF6atWdx8G9gtwzyRcheGP4xB OHjqtR/XNMSsi3pzh1/PQaayigBh6QwbVSAvLFEt6T/0DHZrX7sxemyQpXEKr60SiVAU 9Xq+JqcmL2aox3tQ4e1C8zf9y8KvqfaB5vVBSKeFyFdLW/7a/mkqwj4oGkuU8/4LRf0t b/eUdcfJ5knYooVQbZx4ezxAtRBCRyRHRRgFtOAVjxDvlURXpdKQzp9Fjp61Qp9R64eX UpG669wiA6Fbj2J5Fpw7cqF7FB42BgPK1aL48LA6T1l4Zmg/n6Uzvpx6H/HFdgwmfxu0 RsvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780639576; x=1781244376; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=RLDzqoAhJHGWy0IaWlTQOPcDKqvuE8yyG/YnkFaABUY=; b=WYgojWt2dB4JIVLPOJ1pzgYw9rX9JJAaeFemDOJXe9UDpqEkuojpzOYREfKgEQQo8s Np5HSOxcQNfp6IL2bUsXwdJpohDQ7GWTse7rfFnyxxqSDq20Ar34Gzlh4eazeAxHJT7X dNwXtufszxV9pDHpLrQEHpTTLRu9DpE3COK96JJahu2/w2rm9mq8D/tnj+zi+KHgsGpC QWTIfCQ3z8srLG9ySguuruBWGFdBJyXYWWJxNldVtIi4keTF7zlxYOEWDOjeEIUoNR+5 9Vz8LomcsBDexXtVqNr2dMM220fHWZOvK2+OTOJF9fjXLDLXUSNSShynoJvA+LZfLOlH 0ycQ== X-Forwarded-Encrypted: i=1; AFNElJ8qK56ZIQWKKvDmGAlOSm9koxDxyGof84LCvorptIK19bLkUTwwDIZXgX5joc5OQQv9TrpK7bbRu8+dx2s=@vger.kernel.org X-Gm-Message-State: AOJu0YzkXCbtgrJYmC6V0wfXQfxbSxBrNT9mwLTZ+sYObhrwSDsRDrsg MgXsdRATSaA8CfkFmT9o4JL+gmHisU2sVHWvvR3ZHEERxPi1UkLaxsm4BsR0HwHIr5dFXnu4vh3 xSW1srehfcA== X-Received: from dybir8.prod.google.com ([2002:a05:7300:c8c8:b0:304:ebf6:da3b]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:693c:2c01:b0:304:ba84:a0cc with SMTP id 5a478bee46e88-3077b33261cmr1087398eec.33.1780639576052; Thu, 04 Jun 2026 23:06:16 -0700 (PDT) Date: Thu, 4 Jun 2026 23:06:05 -0700 In-Reply-To: <20260604172850.683329-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260604172850.683329-1-irogers@google.com> X-Mailer: git-send-email 2.54.0.1032.g2f8565e1d1-goog Message-ID: <20260605060610.1529996-1-irogers@google.com> Subject: [PATCH v10 0/5] perf tools: Add inject --aslr feature, early maps loading, and decoupling fixes From: Ian Rogers To: irogers@google.com, acme@kernel.org, namhyung@kernel.org Cc: adrian.hunter@intel.com, gmx@google.com, james.clark@linaro.org, jolsa@kernel.org, linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, mingo@redhat.com, peterz@infradead.org Content-Type: text/plain; charset="UTF-8" This patch series introduces the new 'perf inject --aslr' feature to remap virtual memory addresses or drop physical memory event leaks when profile record data is shared between machines. Bundled with this feature is a bug fix inside the core map tracking tool that hardens perf session analysis against concurrent lookup data races. Detailed Mechanism of MMAP Mapping and ASLR virtual Address Allocation: The ASLR tool virtualizes the address space of the recorded processes by intercepting MMAP and MMAP2 events to build a consistent translation database, which is subsequently used to rewrite sample addresses. It maintains two primary lookup databases using hash maps: 1. 'remap_addresses': Maps an original mapping key to its new remapped base address. The key uses topological invariant coordinates: (machine, dso, invariant). The invariant is computed as (start - pgoff) for DSO-backed mappings. This invariant remains constant even when perf's internal overlap-resolution splits a VMA into fragmented pieces, ensuring split maps resolve consistently back to the same remapped base. 2. 'top_addresses': Tracks the allocation state per process (machine, pid). It maintains 'remapped_max' (the highest allocated address in the virtualized space) and 'orig_last_end' (the end address of the last processed original mapping). For each MMAP/MMAP2 event: - We look up the DSO and invariant key in 'remap_addresses'. If found, we reuse the translation, preserving the offset within the mapping. - If not found, we allocate a new remapped address space: - If the new mapping is contiguous to the previous one in the original address space (start == orig_last_end), we place it contiguously in the remapped space. This is critical to preserve the contiguity of mappings for downstream merging (e.g. symbols split by HugeTLB, or anonymous .bss segments adjacent to initialized data). - If not contiguous, we insert a 1-page gap (using page_size) from the previous maximum allocated address to prevent accidental merging of unrelated VMAs. - The event's start address (and pgoff for kernel maps) is rewritten, and the event is delegated to the output writer. To remain strictly conservative and guarantee security, the tool scrubs breakpoint addresses (bp_addr) from all synthesized stream headers, completely drops PERF_RECORD_TEXT_POKE events to prevent absolute immediate pointer operands leaks, and drops unsupported complex payloads (such as user register stacks, raw tracepoints, and hardware AUX tracing frames). Verification is reinforced with shell test ('inject_aslr.sh'). Prerequisite Bug Fix (Patch 1). During development, a core map indexing issue was identified and resolved to prevent concurrent lookup data races during session analysis. Changes since v9: - Patch 1: Added `-ENOMEM` error check inside `maps__find_symbol_by_name()` and return `NULL` early. Added map sorting state invalidation on early return in `maps__load_maps()`. - Patch 2: Fixed encapsulation by using `thread__maps()` and `thread__pid()` accessors in `aslr_tool__findnew_mapping()`. Added `pr_warning_once` warning when raw auxtrace data is dropped. - Patch 3: Fixed encapsulation by using `thread__maps()` and `thread__pid()` accessors in `aslr_tool__remap_address()`. Wrapped `evsel__parse_sample()` to temporarily disable `needs_swap` to avoid branch stack endianness corruption on cross-endian files. Fixed ISO C90 warning for declaration-after-statement for `orig_needs_swap`. - Patch 4: Fixed duplicate cleanup by explicitly removing trap handlers (`trap - EXIT TERM INT`) inside the `cleanup()` function. - Patch 5: Fixed heap corruption by adding size bounds checking before writing to `sample_regs_user` and `sample_regs_intr` fields. Added missing register mask clearing logic for the `itrace` synthesis path of `perf_event__repipe_attr()`. Ian Rogers (5): perf maps: Add maps__mutate_mapping perf inject/aslr: Add ASLR tool infrastructure and MMAP tracking perf inject/aslr: Implement sample address remapping perf test: Add inject ASLR test perf aslr: Strip sample registers tools/perf/builtin-inject.c | 79 +- tools/perf/tests/shell/inject_aslr.sh | 518 ++++++++++ tools/perf/util/Build | 1 + tools/perf/util/aslr.c | 1269 +++++++++++++++++++++++++ tools/perf/util/aslr.h | 41 + tools/perf/util/machine.c | 32 +- tools/perf/util/maps.c | 80 ++ tools/perf/util/maps.h | 3 + tools/perf/util/symbol-elf.c | 41 +- tools/perf/util/symbol.c | 17 +- 10 files changed, 2048 insertions(+), 33 deletions(-) create mode 100755 tools/perf/tests/shell/inject_aslr.sh create mode 100644 tools/perf/util/aslr.c create mode 100644 tools/perf/util/aslr.h -- 2.54.0.1032.g2f8565e1d1-goog