2023-04-18 14:16:54

by James Clark

[permalink] [raw]
Subject: [PATCH] perf: cs-etm: Fix segfault in dso lookup

map__dso() is called before thread__find_map() which always results in a
null pointer dereference. Fix it by finding first, then checking if it
exists.

Fixes: 63df0e4bc368 ("perf map: Add accessor for dso")
Signed-off-by: James Clark <[email protected]>
---
tools/perf/util/cs-etm.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 103865968700..8dd81ddd9e4e 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -885,9 +885,11 @@ static u32 cs_etm__mem_access(struct cs_etm_queue *etmq, u8 trace_chan_id,
thread = etmq->etm->unknown_thread;
}

- dso = map__dso(al.map);
+ if (!thread__find_map(thread, cpumode, address, &al))
+ return 0;

- if (!thread__find_map(thread, cpumode, address, &al) || !dso)
+ dso = map__dso(al.map);
+ if (!dso)
return 0;

if (dso->data.status == DSO_DATA_STATUS_ERROR &&
--
2.34.1


2023-04-18 15:30:14

by Arnaldo Carvalho de Melo

[permalink] [raw]
Subject: Re: [PATCH] perf: cs-etm: Fix segfault in dso lookup

Em Tue, Apr 18, 2023 at 03:12:03PM +0100, James Clark escreveu:
> map__dso() is called before thread__find_map() which always results in a
> null pointer dereference. Fix it by finding first, then checking if it
> exists.
>
> Fixes: 63df0e4bc368 ("perf map: Add accessor for dso")

Thanks, applied, checking if another such pattern slipped by in that
cset.

- Arnaldo

> Signed-off-by: James Clark <[email protected]>
> ---
> tools/perf/util/cs-etm.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
> index 103865968700..8dd81ddd9e4e 100644
> --- a/tools/perf/util/cs-etm.c
> +++ b/tools/perf/util/cs-etm.c
> @@ -885,9 +885,11 @@ static u32 cs_etm__mem_access(struct cs_etm_queue *etmq, u8 trace_chan_id,
> thread = etmq->etm->unknown_thread;
> }
>
> - dso = map__dso(al.map);
> + if (!thread__find_map(thread, cpumode, address, &al))
> + return 0;
>
> - if (!thread__find_map(thread, cpumode, address, &al) || !dso)
> + dso = map__dso(al.map);
> + if (!dso)
> return 0;
>
> if (dso->data.status == DSO_DATA_STATUS_ERROR &&
> --
> 2.34.1
>

--

- Arnaldo