mirror of
https://github.com/torvalds/linux.git
synced 2026-05-13 08:39:31 +02:00
Currently, the initialization of loongarch_jump_ops does not contain an
assignment to its .free field. This causes disasm_line__free() to fall
through to ins_ops__delete() for LoongArch jump instructions.
ins_ops__delete() will free ins_operands.source.raw and
ins_operands.source.name, and these fields overlaps with
ins_operands.jump.raw_comment and ins_operands.jump.raw_func_start.
Since in loongarch_jump__parse(), these two fields are populated by
strchr()-ing the same buffer, trying to free them will lead to undefined
behavior.
This invalid free usually leads to crashes:
Process 1712902 (perf) of user 1000 dumped core.
Stack trace of thread 1712902:
#0 0x00007fffef155c58 n/a (libc.so.6 + 0x95c58)
#1 0x00007fffef0f7a94 raise (libc.so.6 + 0x37a94)
#2 0x00007fffef0dd6a8 abort (libc.so.6 + 0x1d6a8)
#3 0x00007fffef145490 n/a (libc.so.6 + 0x85490)
#4 0x00007fffef1646f4 n/a (libc.so.6 + 0xa46f4)
#5 0x00007fffef164718 n/a (libc.so.6 + 0xa4718)
#6 0x00005555583a6764 __zfree (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x106764)
#7 0x000055555854fb70 disasm_line__free (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x2afb70)
#8 0x000055555853d618 annotated_source__purge (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x29d618)
#9 0x000055555852300c __hist_entry__tui_annotate (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x28300c)
#10 0x0000555558526718 do_annotate (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x286718)
#11 0x000055555852ed94 evsel__hists_browse (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x28ed94)
#12 0x000055555831fdd0 cmd_report (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x7fdd0)
#13 0x000055555839b644 handle_internal_command (/home/csmantle/dist/linux-arch/tools/perf/perf + 0xfb644)
#14 0x00005555582fe6ac main (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x5e6ac)
#15 0x00007fffef0ddd90 n/a (libc.so.6 + 0x1dd90)
#16 0x00007fffef0ddf0c __libc_start_main (libc.so.6 + 0x1df0c)
#17 0x00005555582fed10 _start (/home/csmantle/dist/linux-arch/tools/perf/perf + 0x5ed10)
ELF object binary architecture: LoongArch
... and it can be confirmed with Valgrind:
==1721834== Invalid free() / delete / delete[] / realloc()
==1721834== at 0x4EA9014: free (in /usr/lib/valgrind/vgpreload_memcheck-loongarch64-linux.so)
==1721834== by 0x4106287: __zfree (zalloc.c:13)
==1721834== by 0x42ADC8F: disasm_line__free (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x429B737: annotated_source__purge (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x42811EB: __hist_entry__tui_annotate (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x42848D7: do_annotate (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x428CF33: evsel__hists_browse (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== Address 0x7d34303 is 35 bytes inside a block of size 62 alloc'd
==1721834== at 0x4EA59B8: malloc (in /usr/lib/valgrind/vgpreload_memcheck-loongarch64-linux.so)
==1721834== by 0x6B80B6F: strdup (strdup.c:42)
==1721834== by 0x42AD917: disasm_line__new (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x42AE5A3: symbol__disassemble_objdump (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x42AF0A7: symbol__disassemble (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x429B3CF: symbol__annotate (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x429C233: symbol__annotate2 (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x42804D3: __hist_entry__tui_annotate (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x42848D7: do_annotate (in /home/csmantle/dist/linux-arch/tools/perf/perf)
==1721834== by 0x428CF33: evsel__hists_browse (in /home/csmantle/dist/linux-arch/tools/perf/perf)
This patch adds the missing free() specialization in loongarch_jump_ops,
which prevents disasm_line__free() from invoking the default cleanup
function.
Fixes: fb7fd2a14a ("perf annotate: Move raw_comment and raw_func_start fields out of 'struct ins_operands'")
Cc: stable@vger.kernel.org
Cc: WANG Rui <wangrui@loongson.cn>
Cc: Huacai Chen <chenhuacai@kernel.org>
Cc: WANG Xuerui <kernel@xen0n.name>
Cc: loongarch@lists.linux.dev
Signed-off-by: Rong Bao <rong.bao@csmantle.top>
Tested-by: WANG Rui <wangrui@loongson.cn>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
171 lines
5.2 KiB
C
171 lines
5.2 KiB
C
// SPDX-License-Identifier: GPL-2.0
|
|
#ifndef __PERF_UTIL_DISASM_H
|
|
#define __PERF_UTIL_DISASM_H
|
|
|
|
#include "map_symbol.h"
|
|
|
|
#ifdef HAVE_LIBDW_SUPPORT
|
|
#include "dwarf-aux.h"
|
|
#endif
|
|
|
|
struct annotation_options;
|
|
struct disasm_line;
|
|
struct ins;
|
|
struct evsel;
|
|
struct symbol;
|
|
struct data_loc_info;
|
|
struct type_state;
|
|
struct disasm_line;
|
|
|
|
struct e_machine_and_e_flags {
|
|
uint32_t e_flags;
|
|
uint16_t e_machine;
|
|
};
|
|
|
|
struct arch {
|
|
/** @name: name such as "x86" or "powerpc". */
|
|
const char *name;
|
|
const struct ins *instructions;
|
|
size_t nr_instructions;
|
|
size_t nr_instructions_allocated;
|
|
const char *insn_suffix;
|
|
unsigned int model;
|
|
unsigned int family;
|
|
/** @id: ELF machine and flags associated with arch. */
|
|
struct e_machine_and_e_flags id;
|
|
bool sorted_instructions;
|
|
struct {
|
|
char comment_char;
|
|
char skip_functions_char;
|
|
char register_char;
|
|
char memory_ref_char;
|
|
char imm_char;
|
|
} objdump;
|
|
bool (*ins_is_fused)(const struct arch *arch, const char *ins1,
|
|
const char *ins2);
|
|
const struct ins_ops *(*associate_instruction_ops)(struct arch *arch, const char *name);
|
|
#ifdef HAVE_LIBDW_SUPPORT
|
|
void (*update_insn_state)(struct type_state *state,
|
|
struct data_loc_info *dloc, Dwarf_Die *cu_die,
|
|
struct disasm_line *dl);
|
|
#endif
|
|
};
|
|
|
|
struct ins {
|
|
const char *name;
|
|
const struct ins_ops *ops;
|
|
};
|
|
|
|
struct ins_operands {
|
|
char *raw;
|
|
struct {
|
|
char *raw;
|
|
char *name;
|
|
struct symbol *sym;
|
|
u64 addr;
|
|
s64 offset;
|
|
bool offset_avail;
|
|
bool outside;
|
|
bool multi_regs;
|
|
bool mem_ref;
|
|
} target;
|
|
union {
|
|
struct {
|
|
char *raw;
|
|
char *name;
|
|
u64 addr;
|
|
bool multi_regs;
|
|
bool mem_ref;
|
|
} source;
|
|
struct {
|
|
struct ins ins;
|
|
struct ins_operands *ops;
|
|
} locked;
|
|
struct {
|
|
char *raw_comment;
|
|
char *raw_func_start;
|
|
} jump;
|
|
};
|
|
};
|
|
|
|
struct ins_ops {
|
|
void (*free)(struct ins_operands *ops);
|
|
int (*parse)(const struct arch *arch, struct ins_operands *ops, struct map_symbol *ms,
|
|
struct disasm_line *dl);
|
|
int (*scnprintf)(const struct ins *ins, char *bf, size_t size,
|
|
struct ins_operands *ops, int max_ins_name);
|
|
bool is_jump;
|
|
bool is_call;
|
|
};
|
|
|
|
struct annotate_args {
|
|
const struct arch *arch;
|
|
struct map_symbol *ms;
|
|
struct annotation_options *options;
|
|
s64 offset;
|
|
char *line;
|
|
int line_nr;
|
|
char *fileloc;
|
|
};
|
|
|
|
const struct arch *arch__find(uint16_t e_machine, uint32_t e_flags, const char *cpuid);
|
|
bool arch__is_x86(const struct arch *arch);
|
|
bool arch__is_powerpc(const struct arch *arch);
|
|
|
|
extern const struct ins_ops call_ops;
|
|
extern const struct ins_ops dec_ops;
|
|
extern const struct ins_ops jump_ops;
|
|
extern const struct ins_ops mov_ops;
|
|
extern const struct ins_ops nop_ops;
|
|
extern const struct ins_ops lock_ops;
|
|
extern const struct ins_ops ret_ops;
|
|
|
|
int arch__associate_ins_ops(struct arch *arch, const char *name, const struct ins_ops *ops);
|
|
|
|
const struct arch *arch__new_arc(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_arm(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_arm64(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_csky(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_loongarch(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_mips(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_powerpc(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_riscv64(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_s390(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_sparc(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
const struct arch *arch__new_x86(const struct e_machine_and_e_flags *id, const char *cpuid);
|
|
|
|
const struct ins_ops *ins__find(const struct arch *arch, const char *name, struct disasm_line *dl);
|
|
|
|
bool ins__is_call(const struct ins *ins);
|
|
bool ins__is_jump(const struct ins *ins);
|
|
bool ins__is_fused(const struct arch *arch, const char *ins1, const char *ins2);
|
|
bool ins__is_ret(const struct ins *ins);
|
|
bool ins__is_lock(const struct ins *ins);
|
|
|
|
const struct ins_ops *check_ppc_insn(struct disasm_line *dl);
|
|
|
|
struct disasm_line *disasm_line__new(struct annotate_args *args);
|
|
void disasm_line__free(struct disasm_line *dl);
|
|
|
|
int disasm_line__scnprintf(struct disasm_line *dl, char *bf, size_t size,
|
|
bool raw, int max_ins_name);
|
|
|
|
int ins__raw_scnprintf(const struct ins *ins, char *bf, size_t size,
|
|
struct ins_operands *ops, int max_ins_name);
|
|
int ins__scnprintf(const struct ins *ins, char *bf, size_t size,
|
|
struct ins_operands *ops, int max_ins_name);
|
|
int call__scnprintf(const struct ins *ins, char *bf, size_t size,
|
|
struct ins_operands *ops, int max_ins_name);
|
|
int jump__scnprintf(const struct ins *ins, char *bf, size_t size,
|
|
struct ins_operands *ops, int max_ins_name);
|
|
int mov__scnprintf(const struct ins *ins, char *bf, size_t size,
|
|
struct ins_operands *ops, int max_ins_name);
|
|
|
|
void jump__delete(struct ins_operands *ops);
|
|
|
|
int symbol__disassemble(struct symbol *sym, struct annotate_args *args);
|
|
|
|
char *expand_tabs(char *line, char **storage, size_t *storage_len);
|
|
|
|
#endif /* __PERF_UTIL_DISASM_H */
|