Re: [PATCH v3 perf-tools-next 0/7] perf trace: Validate payload bounds across augmented argument beautifiers

From: Aaron Tomlin

Date: Wed Sep 30 2026 - 15:32:40 EST


On Fri, Sep 18, 2026 at 08:55:23PM -0400, Aaron Tomlin wrote:
> When pretty-printing augmented syscall arguments in perf trace, raw payload
> data captured from BPF programs is passed to various argument formatters
> via struct syscall_arg.
>
> However, when processing malformed, truncated, or untrusted perf.data
> records (e.g. truncated reads in BPF ringbuffers, cross-architecture
> replays, or crafted sample records), the payload can be shorter than
> expected or contain invalid size fields:
> 1. Dereferencing augmented_arg fields before validating that
> arg->augmented.size is at least sizeof(struct augmented_arg) can read
> past the available buffer.
>
> 2. Passing augmented_arg->size to formatters or loop counters without
> bounding it against the remaining buffer can cause out-of-bounds memory
> reads.
>
> 3. In multi-argument syscalls (e.g. rename*), calculating consumed bytes
> without 64-bit alignment advances arg->augmented.args to unaligned
> addresses. Furthermore, calculating consumed offsets without bounds
> checking can overflow signed integer bounds or cause arg->augmented.size
> to underflow, advancing arg->augmented.args out of bounds and
> corrupting the parsing state for all subsequent arguments.
>
> 4. Type/family-specific beautifiers (i.e. BTF struct dump, sockaddr,
> timespec, perf_event_attr) can dereference structure fields without
> verifying that the payload contains sufficient bytes for the target
> type, or trust embedded size fields (such as attr->size) that exceed
> the actual captured buffer.
>
> This series adds comprehensive upper-bound and payload-size checks across
> all augmented argument beautifiers in perf trace, enforces 64-bit pointer
> alignment when consuming multi-argument payloads, and ensures extensible
> dispatching for address family formatters. If validation fails in any
> beautifier, it cleanly falls back to printing the raw pointer/hex value.
>
> To facilitate clean, conflict-free backports across active LTS kernels,
> each fix is isolated to its own commit.
>
> Changes since v2:
>
> - Expanded the series from 6 to 7 patches by splitting the string
> beautifier pointer advancement and 64-bit alignment logic into a
> dedicated patch
>
> - Added a new patch to round up consumed payload bytes to 64-bit
> boundaries using PERF_ALIGN(), matching the alignment produced by the
> BPF tracepoint probes (sys_enter_rename*) in
> augmented_raw_syscalls.bpf.c
>
> - Reset arg->augmented on buffer overrun to prevent corrupted parsing
> state from reading out of bounds on subsequent arguments
>
> - Validated payload size directly against arg->augmented.size instead of
> reading augmented_arg->size, which is unpopulated by the BPF tracer
> (sys_enter_{clock_,}nanosleep) and contains stale per-CPU map data
>
> - Refactored af_scnprintfs into a dispatch table associating each
> formatter with its minimum required payload size (.min_size), preserving
> extensibility for future address families without hardcoded conditionals
>
> - Used offsetof(struct sockaddr_un, sun_path) + 1 for AF_LOCAL rather than
> sizeof(struct sockaddr_un) to correctly accommodate variable-length
> domain socket paths
>
> - Validated payload size against arg->augmented.size and payload_size
> rather than reading uninitialized augmented_arg->size
>
> - Validated payload size directly against arg->augmented.size instead of
> reading uninitialized augmented_arg->size, which is unpopulated by
> sys_enter_perf_event_open()
>
> - Verified that when attr->size is specified, it is at least
> PERF_ATTR_SIZE_VER0 and does not exceed payload_size, preventing
> out-of-bounds reads in perf_event_attr__fprintf() caused by malformed
> records or TOCTOU mutations during trace capture
>
> - Link to v2: https://lore.kernel.org/lkml/20260907015140.363076-1-atomlin@xxxxxxxxxxx/
>
> Changes since v1:
>
> - Expanded the original single patch into a 6-patch series in response to
> reviewer feedback from sashiko-bot regarding similar bounds check
> omissions across other augmented formatters in perf trace
>
> - Added new patch validating payload bounds and consumed offset
> calculations in syscall_arg__scnprintf_augmented_string()
>
> - Added new patch validating payload bounds before byte traversal in
> syscall_arg__scnprintf_buf(), isolated to ensure an independent Fixes:
> tag for stable backports
>
> - Added new patch validating payload size against sizeof(struct timespec)
> in syscall_arg__scnprintf_augmented_timespec()
>
> - Added new patch validating payload bounds and family-specific lengths in
> syscall_arg__scnprintf_augmented_sockaddr()
>
> - Added new patch validating payload size against at least
> PERF_ATTR_SIZE_VER0 in
> syscall_arg__scnprintf_augmented_perf_event_attr()
>
> - Link to v1: https://lore.kernel.org/all/20260906011132.279321-1-atomlin@xxxxxxxxxxx/
>
> Aaron Tomlin (7):
> perf trace: Add upper bound checks for augmented BTF struct printing
> perf trace: Validate payload bounds in augmented string beautifier
> perf trace: Align pointer advance in augmented string beautifier
> perf trace: Validate payload bounds in augmented buffer beautifier
> perf trace beauty: Validate payload size in augmented timespec
> beautifier
> perf trace beauty: Validate payload size in augmented sockaddr
> beautifier
> perf trace beauty: Validate payload size in augmented perf_event_open
> beautifier
>
> tools/perf/builtin-trace.c | 45 +++++++++++++++++------
> tools/perf/trace/beauty/perf_event_open.c | 23 ++++++++++--
> tools/perf/trace/beauty/sockaddr.c | 35 +++++++++++++-----
> tools/perf/trace/beauty/timespec.c | 15 ++++++--
> 4 files changed, 91 insertions(+), 27 deletions(-)
>
>
> base-commit: 02f6847e1822714a4201b87e42f92b0d43e8549d
> --
> 2.55.0
>

Ian, Namhyung, Arnaldo,

Please drop this series from consideration in favour of Ian's series
"[PATCH v6 00/26] perf trace: Fix BPF filtering and make tracing tests
non-exclusive" (specifically patches 4 [1] and 5 [2]).

Ian's series covers the same vulnerabilities using a consolidated helper
function and addresses the unaligned packing in the BTF augmenter.

[1]: https://lore.kernel.org/lkml/20260928182605.3649015-5-irogers@xxxxxxxxxx/
[2]: https://lore.kernel.org/lkml/20260928182605.3649015-6-irogers@xxxxxxxxxx/

--
Aaron Tomlin