[PATCH v6 10/26] perf trace: Only take augmented arguments from the BPF output event
From: Ian Rogers
Date: Mon Sep 28 2026 - 14:28:16 EST
syscall__augmented_args() treats any data after the syscall arguments as
augmented arguments. trace__sys_enter() avoids this for
raw_syscalls:sys_enter, but trace__fprintf_sys_enter() also handles
syscalls:sys_enter_* tracepoint events, whose trailing data since v6.19
holds the __data_loc strings of internal fields. Only the BPF output
event carries augmented arguments, so only look for them there.
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@xxxxxxxxxx>
---
tools/perf/builtin-trace.c | 25 ++++++++++---------------
1 file changed, 10 insertions(+), 15 deletions(-)
diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
index 6a54d8bff534..1f89f85ba2e4 100644
--- a/tools/perf/builtin-trace.c
+++ b/tools/perf/builtin-trace.c
@@ -2947,7 +2947,8 @@ static int trace__fprintf_sample(struct trace *trace, struct perf_sample *sample
return printed;
}
-static void *syscall__augmented_args(struct syscall *sc, struct perf_sample *sample, int *augmented_args_size, int raw_augmented_args_size)
+static void *syscall__augmented_args(struct trace *trace, struct syscall *sc,
+ struct perf_sample *sample, int *augmented_args_size)
{
/*
* For now with BPF raw_augmented we hook into raw_syscalls:sys_enter
@@ -2963,9 +2964,14 @@ static void *syscall__augmented_args(struct syscall *sc, struct perf_sample *sam
* use syscalls:sys_enter_NAME, so that we reduce the kernel/userspace
* traffic to just what is needed for each syscall.
*/
- int args_size = raw_augmented_args_size ?: sc->args_size;
+ int args_size = trace->raw_augmented_syscalls_args_size ?: sc->args_size;
static uintptr_t argbuf[1024]; /* assuming single-threaded */
+ *augmented_args_size = 0;
+ /* Only the BPF output event carries augmented arguments. */
+ if (sample->evsel != trace->syscalls.events.bpf_output)
+ return NULL;
+
*augmented_args_size = sample->raw_size - args_size;
/*
* The raw data is padded to a u64 boundary with stale bytes, so less
@@ -3025,18 +3031,7 @@ static int trace__sys_enter(struct trace *trace,
if (!(trace->duration_filter || trace->summary_only || trace->min_stack))
trace__printf_interrupted_entry(trace);
- /*
- * If this is raw_syscalls.sys_enter, then it always comes with the 6 possible
- * arguments, even if the syscall being handled, say "openat", uses only 4 arguments
- * this breaks syscall__augmented_args() check for augmented args, as we calculate
- * syscall->args_size using each syscalls:sys_enter_NAME tracefs format file,
- * so when handling, say the openat syscall, we end up getting 6 args for the
- * raw_syscalls:sys_enter event, when we expected just 4, we end up mistakenly
- * thinking that the extra 2 u64 args are the augmented filename, so just check
- * here and avoid using augmented syscalls when the evsel is the raw_syscalls one.
- */
- if (evsel != trace->syscalls.events.sys_enter)
- augmented_args = syscall__augmented_args(sc, sample, &augmented_args_size, trace->raw_augmented_syscalls_args_size);
+ augmented_args = syscall__augmented_args(trace, sc, sample, &augmented_args_size);
ttrace->entry_time = sample->time;
ttrace->entry_cpu = sample->cpu;
msg = ttrace->entry_str;
@@ -3099,7 +3094,7 @@ static int trace__fprintf_sys_enter(struct trace *trace, struct perf_sample *sam
goto out_put;
args = perf_evsel__sc_tp_ptr(args, sample);
- augmented_args = syscall__augmented_args(sc, sample, &augmented_args_size, trace->raw_augmented_syscalls_args_size);
+ augmented_args = syscall__augmented_args(trace, sc, sample, &augmented_args_size);
printed += syscall__scnprintf_args(sc, msg, sizeof(msg), args, augmented_args, augmented_args_size, trace, thread);
fprintf(trace->output, "%.*s", (int)printed, msg);
err = 0;
--
2.56.0.rc1.315.gc6ed9934b7-goog