From nobody Sat Sep 26 12:26:27 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CD2FA3839B8; Tue, 1 Sep 2026 14:21:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788272504; cv=none; b=hoAa+NLXPyVmNXV4Wr1X86+FcE0BLkcM/GGoITzAjMnc2nhjd6UuZUVwyQpCNR0l8iFS4AxYm7E8uQ+42VFZge1baAm0/To0VIot72YfQHmuJFWox9m0aNa3vXYmF421d1ey1FDAYRUHCqixUDHBPHp1DqOCS9XTxRArAnCcKF0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788272504; c=relaxed/simple; bh=0VJbYk95hqb2RJMnHeFsM0o8Xpi+Qg3RyKqte29gyRc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=iqPUPODfTxiIZ+CoxKXOk19W/DPJbHzBYjS0w8A4uwhPxbe/g657v+/Wq2Bu3NLoAECMmfe/7RlOR5DbdkWMPhY02GEimDQpzy+Ggp1n7ywXa/yBe0e5ReYcnem6gA7v0KJLIfD1bwvxJ8/RG4kBXgc6n9BiFvDyY9mIujgaiaA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=RbIG6yx0; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="RbIG6yx0" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E8BF71F000E9; Tue, 1 Sep 2026 14:21:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1788272503; bh=nzdGXIZl7GaCZWCVfOEL58DKl2VbcTdF/XvyWbO/X5w=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RbIG6yx0xgUIQoyAXtfEMOkT3oEVhSC8EgLrbLfaW+M7O2fR4ZNyq+M9yjSQcj/Lc Q6atV6NjeJ/WjcTmHiL0DtP7de1ZUqbpsv1EvRkb6D7YjQfPlXyR9YZa6YzOhCJ5It ZeU1sG+vcLjhA7mjHRG4ni7Ez9+uCXkEIN/UBEC/Yhj4IizzUJUd/dSqzQm0AQr0X2 Zg0yym+WXxT5C62evyrbFrpE1A0ZLfNJFs++AHeQGY+uFuyuF+SuwNCtqOeX4QwoAP jHVtqPbP0lpIZ8Co5BNbeqmRuzddPE11WgqSTCP1AHr3ey1Azwgxa3uIRMr8F9jTGe QKPOaz+pLWK9w== From: "Masami Hiramatsu (Google)" To: Steven Rostedt , Peter Zijlstra , Ingo Molnar , x86@kernel.org Cc: Jinchao Wang , Mathieu Desnoyers , Masami Hiramatsu , Thomas Gleixner , Borislav Petkov , Dave Hansen , "H . Peter Anvin" , Alexander Shishkin , Ian Rogers , linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-perf-users@vger.kernel.org Subject: [PATCH v3 1/3] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Date: Tue, 1 Sep 2026 23:21:37 +0900 Message-ID: <178827249775.123716.7813217688423513612.stgit@devnote2> X-Mailer: git-send-email 2.43.0 In-Reply-To: <178827248631.123716.2627172171811720261.stgit@devnote2> References: <178827248631.123716.2627172171811720261.stgit@devnote2> User-Agent: StGit/0.19 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Masami Hiramatsu (Google) btf_find_struct_member() traverses into nested anonymous structures and unions by pushing members with !member->name_off onto anon_stack. However, it does not consider the unnamed bitfields (e.g. `int : 5` or `unsigned int : 0`) which also have member->name_off =3D=3D 0. If such an unnamed bitfield is pushed to anon_stack, the btf_find_struct_member() return an error even if there are other valid entries in anon_stack. To fix this, only push unnamed struct/union members to anon_stack. Also move the btf_type_is_struct() check to the entry of this function because now it is sure only struct/union are pushed to anon_stack. Fixes: 302db0f5b3d8 ("tracing/probes: Add a function to search a member of = a struct/union") Cc: stable@vger.kernel.org Reported-by: Sashiko Closes: https://lore.kernel.org/all/20260830143859.D56991F00A3D@smtp.kernel= .org/ Signed-off-by: Masami Hiramatsu (Google) Reviewed-by: Steven Rostedt --- Changes in v2: - added tags. --- kernel/trace/trace_btf.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/kernel/trace/trace_btf.c b/kernel/trace/trace_btf.c index 00172f301f25..d3ba356d5503 100644 --- a/kernel/trace/trace_btf.c +++ b/kernel/trace/trace_btf.c @@ -74,24 +74,24 @@ const struct btf_member *btf_find_struct_member(struct = btf *btf, { struct btf_anon_stack *anon_stack; const struct btf_member *member; + const struct btf_type *mtype; u32 tid, cur_offset =3D 0; const char *name; int i, top =3D 0; =20 + if (!btf_type_is_struct(type)) + return ERR_PTR(-EINVAL); + anon_stack =3D kzalloc_objs(*anon_stack, BTF_ANON_STACK_MAX); if (!anon_stack) return ERR_PTR(-ENOMEM); =20 retry: - if (!btf_type_is_struct(type)) { - member =3D ERR_PTR(-EINVAL); - goto out; - } - for_each_member(i, type, member) { if (!member->name_off) { /* Anonymous union/struct: push it for later use */ - if (btf_type_skip_modifiers(btf, member->type, &tid) && + mtype =3D btf_type_skip_modifiers(btf, member->type, &tid); + if (mtype && btf_type_is_struct(mtype) && top < BTF_ANON_STACK_MAX) { anon_stack[top].tid =3D tid; anon_stack[top++].offset =3D From nobody Sat Sep 26 12:26:27 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3684738D3FD; Tue, 1 Sep 2026 14:21:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788272516; cv=none; b=eZptBCv0+YRbSpliCQRPi5dhhm3rO0V2GGHcf9GMf7UALG7fecOC14c5wp1AbyODEDsvMRLxkYVEPuWCMHTjgKljZTvHWcAW98k64yii0cP+/w5TVoLtFfDwZspGau9IIOHrqkTIjKE4NQIjKjazj44kL3RL+GT6D2wNC8ZJG/E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788272516; c=relaxed/simple; bh=bcWdDeucekjH4dtjZhbljTqEFVKo/EJ3rtaOnEaeSi4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=sSJq7nfcqlKFfS6mSkL0R6ajRlFq6u7sXKkEq4yp/F09G3mK7dC0xDbJ/u+JC2vxbRlGIxv5Lfo2r3lZYzt/oaHVOPl/BATM1fWdXZgNEsn+OBuvFSzsDmwzkPA5hLPFQdgriwr0cgGhQ+s3UX2yC06miz5YTECV3SDETCMaguc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=RNFQu6Nh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="RNFQu6Nh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 66DAC1F000E9; Tue, 1 Sep 2026 14:21:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1788272514; bh=N1RSqeA8oOvxj7Rd5uHkQcz2LL1Drv5deATg5L0dJZE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RNFQu6Nhsybjei7NcY/opgtj12UuxiPq5oyQO3hj2C3TavGsZEmyr1uzIF0kvc0UF JTAfDEhhJ72hDZZQvhQj0nlelzIX04Ufad8SbaYL5e2NnCWWGmnish1sbYGchv43+c Xt9XeGeFpzPdwFMNUBqaJFAZ2lwzlir32e9xXyKzE4O5DuxTBU8szllNqn2ay2k8yg GTSvkx/EGwYUxy1ZVKTSUi3T9QTSATIQYHjPTTzP8MrlDnkGzBPXMX6wzD99EPrWMR rbAg5FYIvzpjtdX3WpmqakpIlamMwu8fxAvVRWhxdQmxZHKOpSeckYDDs+C1vcLM4U TnNc30Iuvkm/Q== From: "Masami Hiramatsu (Google)" To: Steven Rostedt , Peter Zijlstra , Ingo Molnar , x86@kernel.org Cc: Jinchao Wang , Mathieu Desnoyers , Masami Hiramatsu , Thomas Gleixner , Borislav Petkov , Dave Hansen , "H . Peter Anvin" , Alexander Shishkin , Ian Rogers , linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-perf-users@vger.kernel.org Subject: [PATCH v3 2/3] tracing/probes: Fix BTF kflag check for anonymous struct member access Date: Tue, 1 Sep 2026 23:21:49 +0900 Message-ID: <178827250904.123716.17452648791331881284.stgit@devnote2> X-Mailer: git-send-email 2.43.0 In-Reply-To: <178827248631.123716.2627172171811720261.stgit@devnote2> References: <178827248631.123716.2627172171811720261.stgit@devnote2> User-Agent: StGit/0.19 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Masami Hiramatsu (Google) btf_find_struct_member() traverses into nested anonymous structures and unions to find a struct member. However, get_bitoffset_of_field() in trace_probe.c checked btf_type_kflag(type) using the outer parent type instead of the actual anonymous structure/union that directly contains the found member. If the parent structure and anonymous structure have mismatched kflags (e.g., the parent has kflag=3D0 while the anonymous structure has kflag=3D1 because it contains bitfields), the bitfield size encoded in the upper 8 bits of member->offset is erroneously treated as part of the byte/bit offset, corrupting the resolved offset and failing to set last_bitsize. Similarly, btf_find_struct_member() pushed anonymous member offsets onto anon_stack without masking BTF_MEMBER_BIT_OFFSET() when kflag is set. To fix this problem, update btf_find_struct_member() to return actual containing structure/union type via member_type, use appropriate __btf_member_bit_offset() to get bit offset, and use member_type for btf_type_kflag() in get_bitoffset_of_field(). Fixes: c440adfbe302 ("tracing/probes: Support BTF based data structure fiel= d access") Cc: stable@vger.kernel.org Reported-by: Sashiko Closes: https://lore.kernel.org/all/20260822095110.0772E1F000E9@smtp.kernel= .org/ Assisted-by: Antigravity:gemini-3.7-flash Signed-off-by: Masami Hiramatsu (Google) Reviewed-by: Steven Rostedt --- Changes in v3: - Remove indent cleanup part since that is a cleanup and no need to be backported. Changes in v2: - remove unneeded NULL initializer for mtype, it should be set if btf_find_struct_member() succeeds. - Add reported-by from Sashiko. This is separated from wprobe patch series v14. - https://lore.kernel.org/all/178810003326.64882.5820404025124695636.stgit= @devnote2/ --- kernel/trace/trace_btf.c | 19 +++++++++++-------- kernel/trace/trace_btf.h | 3 ++- kernel/trace/trace_probe.c | 5 +++-- 3 files changed, 16 insertions(+), 11 deletions(-) diff --git a/kernel/trace/trace_btf.c b/kernel/trace/trace_btf.c index d3ba356d5503..ee7a04886bf6 100644 --- a/kernel/trace/trace_btf.c +++ b/kernel/trace/trace_btf.c @@ -61,16 +61,17 @@ struct btf_anon_stack { =20 /* * Find a member of data structure/union by name and return it. - * Return NULL if not found, or -EINVAL if parameter is invalid. - * If the member is an member of anonymous union/structure, the offset - * of that anonymous union/structure is stored into @anon_offset. Caller - * can calculate the correct offset from the root data structure by - * adding anon_offset to the member's offset. + * Return NULL if not found, or ERR_PTR(-EINVAL) if parameter is invalid. + * If the member is a member of an anonymous union/structure, the bit offs= et + * of that anonymous union/structure is stored into @anon_offset. + * If @member_type is non-NULL, the actual containing structure/union type + * of the found member is stored into @member_type. */ const struct btf_member *btf_find_struct_member(struct btf *btf, const struct btf_type *type, const char *member_name, - u32 *anon_offset) + u32 *anon_offset, + const struct btf_type **member_type) { struct btf_anon_stack *anon_stack; const struct btf_member *member; @@ -94,14 +95,16 @@ const struct btf_member *btf_find_struct_member(struct = btf *btf, if (mtype && btf_type_is_struct(mtype) && top < BTF_ANON_STACK_MAX) { anon_stack[top].tid =3D tid; - anon_stack[top++].offset =3D - cur_offset + member->offset; + anon_stack[top++].offset =3D cur_offset + + __btf_member_bit_offset(type, member); } } else { name =3D btf_name_by_offset(btf, member->name_off); if (name && !strcmp(member_name, name)) { if (anon_offset) *anon_offset =3D cur_offset; + if (member_type) + *member_type =3D type; goto out; } } diff --git a/kernel/trace/trace_btf.h b/kernel/trace/trace_btf.h index 4bc44bc261e6..4bd26bceae23 100644 --- a/kernel/trace/trace_btf.h +++ b/kernel/trace/trace_btf.h @@ -8,4 +8,5 @@ const struct btf_param *btf_get_func_param(const struct btf= _type *func_proto, const struct btf_member *btf_find_struct_member(struct btf *btf, const struct btf_type *type, const char *member_name, - u32 *anon_offset); + u32 *anon_offset, + const struct btf_type **member_type); diff --git a/kernel/trace/trace_probe.c b/kernel/trace/trace_probe.c index c4163904ba74..144e790077c6 100644 --- a/kernel/trace/trace_probe.c +++ b/kernel/trace/trace_probe.c @@ -625,6 +625,7 @@ static int get_bitoffset_of_field(char **pfieldname, co= nst struct btf_type **pty { const struct btf_type *type =3D *ptype; const struct btf_member *field; + const struct btf_type *mtype; struct btf *btf =3D ctx_btf(ctx); char *fieldname =3D *pfieldname; int bitoffs =3D 0; @@ -640,7 +641,7 @@ static int get_bitoffset_of_field(char **pfieldname, co= nst struct btf_type **pty =20 anon_offs =3D 0; field =3D btf_find_struct_member(btf, type, fieldname, - &anon_offs); + &anon_offs, &mtype); if (IS_ERR(field)) { trace_probe_log_err(ctx->offset, BAD_BTF_TID); return PTR_ERR(field); @@ -653,7 +654,7 @@ static int get_bitoffset_of_field(char **pfieldname, co= nst struct btf_type **pty bitoffs +=3D anon_offs; =20 /* Accumulate the bit-offsets of the dot-connected fields */ - if (btf_type_kflag(type)) { + if (btf_type_kflag(mtype)) { bitoffs +=3D BTF_MEMBER_BIT_OFFSET(field->offset); ctx->last_bitsize =3D BTF_MEMBER_BITFIELD_SIZE(field->offset); } else { From nobody Sat Sep 26 12:26:27 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 995B038D3FD; Tue, 1 Sep 2026 14:22:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788272527; cv=none; b=AFoQddqfLGBBz8nOADc868voTx7A5WNNIjAFt911qMbDqlnLBEsmqBLHztai+4LTFdTSx8lNPCwMxlxW6zT11kLh3mL0W6+JdGkpE3hGqbBRSPtDJFycfFNEk6ZvViOjqEmGg8zcP+4mrp6BbuwD2rVU24UFLD5Ac6D7OAStjKI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788272527; c=relaxed/simple; bh=q01b6Fb/Va4nk0KzfKWawKLamrcD1BX3rDo4igKbjW8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=kaXhi12VJ7T5aEZXj4gSATUgdBkKpdM6VqYvJe5f3O8QoLS/M3wnG5zzLbDDzsyOmNN7xoV0C3aonEW+aiyxixgaOyT2WngwgHkbxQYSbEFzNfL+mSVqGJkL9MbbE0ZJF0ZMmIGW3YNCvgveRdhDo3N3siEYp1ruF/08Y7igBDs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=T8HqGc58; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="T8HqGc58" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8D6ED1F000E9; Tue, 1 Sep 2026 14:22:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1788272526; bh=a6GJxWD+W33oVckwTRW6cqEZmP+mD56tlrS5kVmgWvc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=T8HqGc58IBpPp9PRRE/wDLOpN2mQOdPjXIoEXw5KjZ6uvEF9C1hcSjxsxqJNcQLfq wsamHOoA3IW1pjEjH5azaWXAU+VjN7iZJ23KQP/8BTZgnWhLjwVvGyJhCJqVSvMldl YGDvRLdZ6TM+fHAsaOMffG5NskiclYk29+JGoiZ85//I5P/QWwwTLdkBaJA1I2fifL 2Et0jbmT6kfIsDFuBE7fYusP0CHr1Kxn+6P3k2Jr+MdOGP4XoTG3HWPUgEcO1ffnVg JPAUpLeke9JpJ9niE57d8S19NLR/tG//6zThCYVr2noPsS9RfJx7E7SliK4vmuhveq jpBwmISKydhKQ== From: "Masami Hiramatsu (Google)" To: Steven Rostedt , Peter Zijlstra , Ingo Molnar , x86@kernel.org Cc: Jinchao Wang , Mathieu Desnoyers , Masami Hiramatsu , Thomas Gleixner , Borislav Petkov , Dave Hansen , "H . Peter Anvin" , Alexander Shishkin , Ian Rogers , linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-doc@vger.kernel.org, linux-perf-users@vger.kernel.org Subject: [PATCH v3 3/3] tracing/probes: Fix code indent in get_bitoffset_of_field() Date: Tue, 1 Sep 2026 23:22:00 +0900 Message-ID: <178827252027.123716.7095571176291547259.stgit@devnote2> X-Mailer: git-send-email 2.43.0 In-Reply-To: <178827248631.123716.2627172171811720261.stgit@devnote2> References: <178827248631.123716.2627172171811720261.stgit@devnote2> User-Agent: StGit/0.19 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Masami Hiramatsu (Google) Fix code block indentation introduced by commit f21834524025 ("tracing/probes: Support field specifier option for typecast"). Signed-off-by: Masami Hiramatsu (Google) Reviewed-by: Steven Rostedt --- kernel/trace/trace_probe.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/kernel/trace/trace_probe.c b/kernel/trace/trace_probe.c index 144e790077c6..908b4b6bc2df 100644 --- a/kernel/trace/trace_probe.c +++ b/kernel/trace/trace_probe.c @@ -662,11 +662,11 @@ static int get_bitoffset_of_field(char **pfieldname, = const struct btf_type **pty ctx->last_bitsize =3D 0; } =20 - type =3D btf_type_skip_modifiers(btf, field->type, NULL); - if (!type) { - trace_probe_log_err(ctx->offset, BAD_BTF_TID); - return -EINVAL; - } + type =3D btf_type_skip_modifiers(btf, field->type, NULL); + if (!type) { + trace_probe_log_err(ctx->offset, BAD_BTF_TID); + return -EINVAL; + } =20 if (next) ctx->offset +=3D next - fieldname;