From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dy1-f197.google.com (mail-dy1-f197.google.com [74.125.82.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DFDBD386552 for ; Mon, 28 Sep 2026 18:26:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.197 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790619983; cv=none; b=K/VRW+DaZ+SWQDA2w+Sl1WoJjklrwlQD1TBLDq2/NMaAkYfBSbDLA5wOISo1pMvmxiCKEondgcvzdGw3ytGCoECR0+nCeDVWbmXQmagOuHawUkK6RTR8fNFauVLEs7mGY5i3rUBXLwCmMSyh5I143OkqnzAhcZKVky8dikIMf/M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790619983; c=relaxed/simple; bh=a5nWc3sT/mZZe9sKh97b0E5/VmkW2VfrKL6107mIakw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=rvuwxd6U3iEzntkRAKwyGH2AS3FteLBVTyH59tSU0KMQNTT98/BOleQAsrIVyiIua+Elh7LZIih8Dhko0OlCmKK816EMAKCjuRhoJB++4bZwC1FH3PQkVGLtZYB3azHd4xpa/ySqxSHSLea65wyZWPpsJ2M9L2GUi/10J1uZaHo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=u8y9HsYG; arc=none smtp.client-ip=74.125.82.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--irogers.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="u8y9HsYG" Received: by mail-dy1-f197.google.com with SMTP id 5a478bee46e88-3441e2b3fc3so2045493eec.1 for ; Mon, 28 Sep 2026 11:26:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790619981; x=1791224781; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Ue3Wk/UGQHR+sKLjW8U0Y3mC2wPWB7OszqpJJYjXwZo=; b=u8y9HsYGSThi9qGo9TbiowwllR2MrkIu4nBKTXkQLPtZ2hncOIsJ6UYWk67Hl+BdG6 XYEY8cqIOVGF1NFqSWFW6KuFJZRDLbXZV/6/rMYDYD9M1WpL/9nqH0UAVYkDRsflrgzX Y6P6GkbuF+9ypatRv+K/gaO7jfWOElE6jm5uQ8vs42a6JCMxdGbXeENfRyI9DIAsu+3m a1MWn79lX1WVceddw8xDCYhixpaE/55jvu4gccfqkUObIVwUuqd0BNYgVVoDY4BW39/L vWohP+4I3sTVkbACGRZ2zgcrP9sT8xc8ri2QCJkzc0U0BP4/nBgvZkRe0MepPHSKULVk u6aA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790619981; x=1791224781; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Ue3Wk/UGQHR+sKLjW8U0Y3mC2wPWB7OszqpJJYjXwZo=; b=pWF5f/q+AI7+u428JzLYh4LobQfttXszOpOcSAxMFVKZ9bBH5v7q2NNDcE/c6bZMVD vw8F+AMN3gf50jWiEbBZZO8hmCzVSk/OPfQX7FrDDF+HhA6CLJ3FCvm0bVAjthgGY/CC +GYzncjc6YqVpKR49RyOXdjhKSfO9sdNotvdbZ2+KuQQA3vaL9uKyMeaxiSLlLqUErC1 B63WvF1A7NgYOkkRP1UkU4/89dST1bUO9p9ag8hRFB8rygq+T7uP/4yAHkdE3HpB0Sm5 HVhnfPEHylN2FhOpDcsQceZSxOo1t0HtZhsDlj9XN8QZMvCIgcan2zS5SiVD2YpxLnuf 7AwQ== X-Forwarded-Encrypted: i=1; AKwUvBzKSPP9nmISm+Czkndlpn5Iy+T9M6Fady5zRKv5YOtPU9ATQmfQ/3f9hf8pdc8MIQvSfrHUUYp2YEavkQs=@vger.kernel.org X-Gm-Message-State: AFq9FYLkqozoko/2+SqGuDMoQ8vv6zl2qdoVXhMYhsx5s+O5ayKDT9fP GBfhq/rGPsiyWLGIP8b1Rx/VcvAdBZ9s/8q3Zem5zLYHo9p28N/mURD1ydEcDydgI40jY1kPrQW fjiNV9rnS0w== X-Received: from dyblz39.prod.google.com ([2002:a05:7301:1627:b0:343:6340:dc83]) (user=irogers job=prod-delivery.src-stubby-dispatcher) by 2002:a05:7301:4d14:b0:33b:eae9:946d with SMTP id 5a478bee46e88-342711ab345mr9524068eec.8.1790619979498; Mon, 28 Sep 2026 11:26:19 -0700 (PDT) Date: Mon, 28 Sep 2026 11:25:42 -0700 In-Reply-To: <20260928182605.3649015-1-irogers@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260928182605.3649015-1-irogers@google.com> X-Mailer: git-send-email 2.56.0.rc1.315.gc6ed9934b7-goog Message-ID: <20260928182605.3649015-4-irogers@google.com> Subject: [PATCH v6 03/26] perf trace: Don't read sample padding as an augmented argument From: Ian Rogers To: Arnaldo Carvalho de Melo , Namhyung Kim , Aaron Tomlin Cc: Howard Chu , Jakub Brnak , Peter Zijlstra , Ingo Molnar , Jiri Olsa , Adrian Hunter , James Clark , linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org, Ian Rogers Content-Type: text/plain; charset="UTF-8" The kernel pads PERF_SAMPLE_RAW data to a u64 boundary without zeroing the padding, so a syscall record without augmented arguments still has up to 7 trailing bytes of stale data. syscall__augmented_args() passes these to the beautifiers as a struct augmented_arg, whose size is then garbage, causing a crash in syscall_arg__scnprintf_buf(). Ignore trailing data shorter than a struct augmented_arg. Reported-by: Arnaldo Carvalho de Melo Closes: https://lore.kernel.org/linux-perf-users/arJ-gpzqOHk-gF8T@x2/ Assisted-by: Antigravity:gemini-3.1-pro Signed-off-by: Ian Rogers --- tools/perf/builtin-trace.c | 35 +++++++++++++++++++---------------- 1 file changed, 19 insertions(+), 16 deletions(-) diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c index d327603ae454..c39de91140a0 100644 --- a/tools/perf/builtin-trace.c +++ b/tools/perf/builtin-trace.c @@ -2961,26 +2961,29 @@ static void *syscall__augmented_args(struct syscall *sc, struct perf_sample *sam * traffic to just what is needed for each syscall. */ int args_size = raw_augmented_args_size ?: sc->args_size; + static uintptr_t argbuf[1024]; /* assuming single-threaded */ *augmented_args_size = sample->raw_size - args_size; - if (*augmented_args_size > 0) { - static uintptr_t argbuf[1024]; /* assuming single-threaded */ - - if ((size_t)(*augmented_args_size) > sizeof(argbuf)) - return NULL; + /* + * The raw data is padded to a u64 boundary with stale bytes, so less + * than a struct augmented_arg is only padding. + */ + if (*augmented_args_size < (int)sizeof(struct augmented_arg) || + (size_t)(*augmented_args_size) > sizeof(argbuf)) { + *augmented_args_size = 0; + return NULL; + } - /* - * The perf ring-buffer is 8-byte aligned but sample->raw_data - * is not because it's preceded by u32 size. Later, beautifier - * will use the augmented args with stricter alignments like in - * some struct. To make sure it's aligned, let's copy the args - * into a static buffer as it's single-threaded for now. - */ - memcpy(argbuf, sample->raw_data + args_size, *augmented_args_size); + /* + * The perf ring-buffer is 8-byte aligned but sample->raw_data + * is not because it's preceded by u32 size. Later, beautifier + * will use the augmented args with stricter alignments like in + * some struct. To make sure it's aligned, let's copy the args + * into a static buffer as it's single-threaded for now. + */ + memcpy(argbuf, sample->raw_data + args_size, *augmented_args_size); - return argbuf; - } - return NULL; + return argbuf; } static int trace__sys_enter(struct trace *trace, -- 2.56.0.rc1.315.gc6ed9934b7-goog