Re: [PATCH v2 2/2] tracing/probes: Fix BTF kflag check for anonymous struct member access
From: Steven Rostedt
Date: Tue Sep 01 2026 - 09:17:57 EST
On Tue, 1 Sep 2026 09:47:17 +0900
"Masami Hiramatsu (Google)" <mhiramat@xxxxxxxxxx> wrote:
> From: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
>
> btf_find_struct_member() traverses into nested anonymous structures and
> unions to find a struct member. However, get_bitoffset_of_field() in
> trace_probe.c checked btf_type_kflag(type) using the outer parent type
> instead of the actual anonymous structure/union that directly contains
> the found member.
>
> If the parent structure and anonymous structure have mismatched kflags
> (e.g., the parent has kflag=0 while the anonymous structure has kflag=1
> because it contains bitfields), the bitfield size encoded in the upper
> 8 bits of member->offset is erroneously treated as part of the byte/bit
> offset, corrupting the resolved offset and failing to set last_bitsize.
> Similarly, btf_find_struct_member() pushed anonymous member offsets
> onto anon_stack without masking BTF_MEMBER_BIT_OFFSET() when kflag is set.
>
> To fix this problem, update btf_find_struct_member() to return actual
> containing structure/union type via member_type, use appropriate
> __btf_member_bit_offset() to get bit offset, and use member_type for
> btf_type_kflag() in get_bitoffset_of_field().
>
> Fixes: c440adfbe302 ("tracing/probes: Support BTF based data structure field access")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Closes: https://lore.kernel.org/all/20260822095110.0772E1F000E9@xxxxxxxxxxxxxxx/
> Assisted-by: Antigravity:gemini-3.7-flash
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
> ---
> @@ -661,11 +662,11 @@ static int get_bitoffset_of_field(char **pfieldname, const struct btf_type **pty
> ctx->last_bitsize = 0;
> }
>
> - type = btf_type_skip_modifiers(btf, field->type, NULL);
> - if (!type) {
> - trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> - return -EINVAL;
> - }
> + type = btf_type_skip_modifiers(btf, field->type, NULL);
> + if (!type) {
> + trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> + return -EINVAL;
> + }
Is this just to fix the indentation? If so, can you make this a separate
patch? We don't need it to be part of a patch that gets backported. It may
make it more difficult to do so.
-- Steve
>
> if (next)
> ctx->offset += next - fieldname;