mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-08-09 06:14:34 +02:00
Harden PERF_RECORD_HEADER_ATTR handling against crafted perf.data: - Validate attr.size: must be >= PERF_ATTR_SIZE_VER0, a multiple of sizeof(u64), and fit within the event payload. - Copy only min(attr.size, sizeof(struct perf_event_attr)) bytes into a local attr, zeroing the rest so legacy files don't leak adjacent event data into new fields. - Keep the original attr.size so perf_event__synthesize_attr() uses it for both allocation and ID-array placement. Fix perf_event__synthesize_attr() to use attr->size (not the compiled sizeof) for event allocation and layout, so perf inject correctly re-synthesizes attrs from files recorded by a different perf version. Without this, the ID array destination pointer (computed via perf_record_header_attr_id()) would be inconsistent with the allocation when attr->size differs from sizeof. Also fix the parse-no-sample-id-all test to set attr.size, which is now validated, and improve error handling in read_attr() for short reads and invalid attr sizes. Handle ABI0 pipe/inject events where attr.size is 0: use a local attr_size variable set to PERF_ATTR_SIZE_VER0 for both the bounded copy and ID array position, instead of writing back to the event. Native-endian files may be MAP_SHARED (read-only mmap), so writing to the event buffer would SIGSEGV. The swap path handles ABI0 in perf_event__attr_swap() which writes to the MAP_PRIVATE copy. header.size alignment is now validated centrally in perf_session__process_event() (see "Add minimum event size and alignment validation"). Reported-by: sashiko-bot@kernel.org # Running on a local machine Reviewed-by: Ian Rogers <irogers@google.com> Cc: Adrian Hunter <adrian.hunter@intel.com> Cc: Jiri Olsa <jolsa@kernel.org> Cc: Namhyung Kim <namhyung@kernel.org> Assisted-by: Claude:claude-opus-4.6-1m Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
120 lines
2.7 KiB
C
120 lines
2.7 KiB
C
#include <linux/kernel.h>
|
|
#include <linux/types.h>
|
|
#include <stddef.h>
|
|
|
|
#include "tests.h"
|
|
|
|
#include "event.h"
|
|
#include "evlist.h"
|
|
#include "header.h"
|
|
#include "debug.h"
|
|
#include "util/sample.h"
|
|
|
|
static int process_event(struct evlist **pevlist, union perf_event *event)
|
|
{
|
|
struct perf_sample sample;
|
|
int ret;
|
|
|
|
if (event->header.type == PERF_RECORD_HEADER_ATTR) {
|
|
if (perf_event__process_attr(NULL, event, pevlist)) {
|
|
pr_debug("perf_event__process_attr failed\n");
|
|
return -1;
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
if (event->header.type >= PERF_RECORD_USER_TYPE_START)
|
|
return -1;
|
|
|
|
if (!*pevlist)
|
|
return -1;
|
|
|
|
perf_sample__init(&sample, /*all=*/false);
|
|
ret = evlist__parse_sample(*pevlist, event, &sample);
|
|
perf_sample__exit(&sample);
|
|
if (ret) {
|
|
pr_debug("evlist__parse_sample failed\n");
|
|
return -1;
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
|
|
static int process_events(union perf_event **events, size_t count)
|
|
{
|
|
struct evlist *evlist = NULL;
|
|
int err = 0;
|
|
size_t i;
|
|
|
|
for (i = 0; i < count && !err; i++)
|
|
err = process_event(&evlist, events[i]);
|
|
|
|
evlist__delete(evlist);
|
|
|
|
return err;
|
|
}
|
|
|
|
struct test_attr_event {
|
|
struct perf_event_header header;
|
|
struct perf_event_attr attr;
|
|
u64 id;
|
|
};
|
|
|
|
/**
|
|
* test__parse_no_sample_id_all - test parsing with no sample_id_all bit set.
|
|
*
|
|
* This function tests parsing data produced on kernel's that do not support the
|
|
* sample_id_all bit. Without the sample_id_all bit, non-sample events (such as
|
|
* mmap events) do not have an id sample appended, and consequently logic
|
|
* designed to determine the id will not work. That case happens when there is
|
|
* more than one selected event, so this test processes three events: 2
|
|
* attributes representing the selected events and one mmap event.
|
|
*
|
|
* Return: %0 on success, %-1 if the test fails.
|
|
*/
|
|
static int test__parse_no_sample_id_all(struct test_suite *test __maybe_unused,
|
|
int subtest __maybe_unused)
|
|
{
|
|
int err;
|
|
|
|
struct test_attr_event event1 = {
|
|
.header = {
|
|
.type = PERF_RECORD_HEADER_ATTR,
|
|
.size = sizeof(struct test_attr_event),
|
|
},
|
|
.attr = {
|
|
.size = sizeof(struct perf_event_attr),
|
|
},
|
|
.id = 1,
|
|
};
|
|
struct test_attr_event event2 = {
|
|
.header = {
|
|
.type = PERF_RECORD_HEADER_ATTR,
|
|
.size = sizeof(struct test_attr_event),
|
|
},
|
|
.attr = {
|
|
.size = sizeof(struct perf_event_attr),
|
|
},
|
|
.id = 2,
|
|
};
|
|
struct perf_record_mmap event3 = {
|
|
.header = {
|
|
.type = PERF_RECORD_MMAP,
|
|
.size = sizeof(struct perf_record_mmap),
|
|
},
|
|
};
|
|
union perf_event *events[] = {
|
|
(union perf_event *)&event1,
|
|
(union perf_event *)&event2,
|
|
(union perf_event *)&event3,
|
|
};
|
|
|
|
err = process_events(events, ARRAY_SIZE(events));
|
|
if (err)
|
|
return -1;
|
|
|
|
return 0;
|
|
}
|
|
|
|
DEFINE_SUITE("Parse with no sample_id_all bit set", parse_no_sample_id_all);
|