mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
To: Peter Zijlstra <peterz@infradead.org>,
	Ingo Molnar <mingo@redhat.com>,
	Arnaldo Carvalho de Melo <acme@kernel.org>,
	Namhyung Kim <namhyung@kernel.org>,
	Ian Rogers <irogers@google.com>,
	Adrian Hunter <adrian.hunter@intel.com>,
	Alexander Shishkin <alexander.shishkin@linux.intel.com>,
	Andi Kleen <ak@linux.intel.com>,
	Eranian Stephane <eranian@google.com>
Cc: linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org,
	Dapeng Mi <dapeng1.mi@intel.com>, Zide Chen <zide.chen@intel.com>,
	Falcon Thomas <thomas.falcon@intel.com>,
	Xudong Hao <xudong.hao@intel.com>,
	Dapeng Mi <dapeng1.mi@linux.intel.com>
Subject: [PATCH 06/15] perf/x86/intel: Limit PEBS counter iteration to valid array bounds
Date: Mon, 28 Sep 2026 15:43:00 +0800	[thread overview]
Message-ID: <20260928074309.898043-7-dapeng1.mi@linux.intel.com> (raw)
In-Reply-To: <20260928074309.898043-1-dapeng1.mi@linux.intel.com>

__intel_pmu_handle_{,last_}pebs_record() iterate counter indexes up to
X86_PMC_IDX_MAX (64), while counts[] and *last[] are sized only for
INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS (48) entries.

If pebs_status were ever to contain bits above the highest valid PEBS
counter index, the loop could access those arrays out of bounds.
Although that should not happen in practice, limit the iteration bound
to INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS to match the array
sizes and keep the code consistent.

Fixes: 8807d922705f ("perf/x86/intel/ds: Factor out PEBS record processing code to functions")
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
---
 arch/x86/events/intel/ds.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/arch/x86/events/intel/ds.c b/arch/x86/events/intel/ds.c
index 0f24098587bf..f68391d60b2d 100644
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -3239,7 +3239,8 @@ __intel_pmu_handle_pebs_record(struct pt_regs *iregs,
 	struct perf_event *event;
 	int bit;
 
-	for_each_set_bit(bit, (unsigned long *)&pebs_status, X86_PMC_IDX_MAX) {
+	for_each_set_bit(bit, (unsigned long *)&pebs_status,
+			 INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS) {
 		event = cpuc->events[bit];
 
 		if (WARN_ON_ONCE(!event) ||
@@ -3268,7 +3269,8 @@ __intel_pmu_handle_last_pebs_record(struct pt_regs *iregs,
 	bool handled = false;
 	int bit;
 
-	for_each_set_bit(bit, (unsigned long *)&mask, X86_PMC_IDX_MAX) {
+	for_each_set_bit(bit, (unsigned long *)&mask,
+			 INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS) {
 		if (!counts[bit])
 			continue;
 
-- 
2.34.1


  parent reply	other threads:[~2026-09-28  7:50 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28  7:42 [PATCH 00/15] perf/x86: Fix sampling bugs and relax slots-event grouping Dapeng Mi
2026-09-28  7:42 ` [PATCH 01/15] perf/x86/intel: Guard leader sibling walk on nr_siblings Dapeng Mi
2026-09-28  7:42 ` [PATCH 02/15] perf/x86/intel: Reset active_fixed_ctrl_val on CPU teardown Dapeng Mi
2026-09-28  7:42 ` [PATCH 03/15] perf/x86/intel: Reset active_pebs_data_cfg " Dapeng Mi
2026-09-28  7:42 ` [PATCH 04/15] perf/x86/intel: Reset cached acr_cfg_b[] and cfg_c_val[] " Dapeng Mi
2026-09-28  7:42 ` [PATCH 05/15] perf/x86/intel: Pass correct PEBS counter mask to no-drain update path Dapeng Mi
2026-09-28  7:43 ` Dapeng Mi [this message]
2026-09-28  7:43 ` [PATCH 07/15] perf/x86/intel: Reject SAMPLE_READ for no-counter-snapshot ACR events Dapeng Mi
2026-09-28  7:43 ` [PATCH 08/15] perf/x86/intel: Fix stale PEBS count without counter-group support Dapeng Mi
2026-09-28  7:43 ` [PATCH 09/15] perf/x86/intel: Refactor intel_pmu_drain_arch_pebs() Dapeng Mi
2026-09-28  7:43 ` [PATCH 10/15] perf/x86/intel: Refactor intel_pmu_drain_pebs_icl() Dapeng Mi
2026-09-28  7:43 ` [PATCH 11/15] perf/x86/intel: Fix invalid PEBS counts with counter-group support Dapeng Mi
2026-09-28  7:43 ` [PATCH 12/15] perf/x86/intel: Make ACR static_call update architectural Dapeng Mi
2026-09-28  7:43 ` [PATCH 13/15] perf/x86: Validate event type before topdown/mem-loads classification Dapeng Mi
2026-09-28  7:43 ` [PATCH 14/15] perf/core: Add event_caps dependency flags Dapeng Mi
2026-09-28  7:43 ` [PATCH 15/15] perf/x86/intel: Allow Topdown metrics with a non-leader slots event Dapeng Mi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928074309.898043-7-dapeng1.mi@linux.intel.com \
    --to=dapeng1.mi@linux.intel.com \
    --cc=acme@kernel.org \
    --cc=adrian.hunter@intel.com \
    --cc=ak@linux.intel.com \
    --cc=alexander.shishkin@linux.intel.com \
    --cc=dapeng1.mi@intel.com \
    --cc=eranian@google.com \
    --cc=irogers@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=namhyung@kernel.org \
    --cc=peterz@infradead.org \
    --cc=thomas.falcon@intel.com \
    --cc=xudong.hao@intel.com \
    --cc=zide.chen@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®