Re: [PATCH v6 04/26] perf trace: Bounds check augmented arguments before reading them
From: Arnaldo Carvalho de Melo
Date: Wed Sep 30 2026 - 15:51:21 EST
On Wed, Sep 30, 2026 at 02:20:43PM -0400, Aaron Tomlin wrote:
> On Mon, Sep 28, 2026 at 11:25:43AM -0700, Ian Rogers wrote:
> > syscall_arg__scnprintf_buf() and syscall_arg__scnprintf_augmented_string()
> > trust the augmented arg's size, so a bad one reads out of bounds:
> >
> > #3 0x4c0fa0 in syscall_arg__scnprintf_buf builtin-trace.c:1955
> > #4 0x4c2f3d in syscall_arg_fmt__scnprintf_val builtin-trace.c:2632
> > #5 0x4c33ae in syscall__scnprintf_args builtin-trace.c:2722
> > #6 0x4c43d3 in trace__sys_enter builtin-trace.c:3094
> > #7 0x4c7865 in trace__handle_event builtin-trace.c:4013
> >
> > Move the check in btf_struct_scnprintf() to a helper,
> > syscall_arg__augmented_args_valid(), and use it in both. When the check
> > fails, syscall_arg__scnprintf_filename() now falls back to vfs_getname or
> > the pointer.
>
> Thank you Ian.
>
> Reviewed-by: Aaron Tomlin <atomlin@xxxxxxxxxxx>
Added to the cset.
Thanks,
- Arnaldo