Re: [PATCH v2 2/2] tracing/probes: Fix BTF kflag check for anonymous struct member access

From: Google

Date: Tue Sep 01 2026 - 11:30:05 EST


On Tue, 1 Sep 2026 09:04:42 -0400
Steven Rostedt <rostedt@xxxxxxxxxxx> wrote:

> On Tue, 1 Sep 2026 09:47:17 +0900
> "Masami Hiramatsu (Google)" <mhiramat@xxxxxxxxxx> wrote:
>
> > From: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
> >
> > btf_find_struct_member() traverses into nested anonymous structures and
> > unions to find a struct member. However, get_bitoffset_of_field() in
> > trace_probe.c checked btf_type_kflag(type) using the outer parent type
> > instead of the actual anonymous structure/union that directly contains
> > the found member.
> >
> > If the parent structure and anonymous structure have mismatched kflags
> > (e.g., the parent has kflag=0 while the anonymous structure has kflag=1
> > because it contains bitfields), the bitfield size encoded in the upper
> > 8 bits of member->offset is erroneously treated as part of the byte/bit
> > offset, corrupting the resolved offset and failing to set last_bitsize.
> > Similarly, btf_find_struct_member() pushed anonymous member offsets
> > onto anon_stack without masking BTF_MEMBER_BIT_OFFSET() when kflag is set.
> >
> > To fix this problem, update btf_find_struct_member() to return actual
> > containing structure/union type via member_type, use appropriate
> > __btf_member_bit_offset() to get bit offset, and use member_type for
> > btf_type_kflag() in get_bitoffset_of_field().
> >
> > Fixes: c440adfbe302 ("tracing/probes: Support BTF based data structure field access")
> > Cc: stable@xxxxxxxxxxxxxxx
> > Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> > Closes: https://lore.kernel.org/all/20260822095110.0772E1F000E9@xxxxxxxxxxxxxxx/
> > Assisted-by: Antigravity:gemini-3.7-flash
> > Signed-off-by: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
> > ---
>
>
> > @@ -661,11 +662,11 @@ static int get_bitoffset_of_field(char **pfieldname, const struct btf_type **pty
> > ctx->last_bitsize = 0;
> > }
> >
> > - type = btf_type_skip_modifiers(btf, field->type, NULL);
> > - if (!type) {
> > - trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> > - return -EINVAL;
> > - }
> > + type = btf_type_skip_modifiers(btf, field->type, NULL);
> > + if (!type) {
> > + trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> > + return -EINVAL;
> > + }
>
> Is this just to fix the indentation? If so, can you make this a separate
> patch? We don't need it to be part of a patch that gets backported. It may
> make it more difficult to do so.

OK, let me split it.

Thanks,

>
> -- Steve
>
>
> >
> > if (next)
> > ctx->offset += next - fieldname;
>
>


--
Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>