[PATCH v6 11/26] perf trace: Split unaugmented sys_exit program
From: Ian Rogers
Date: Mon Sep 28 2026 - 14:36:56 EST
From: Namhyung Kim <namhyung@xxxxxxxxxx>
We want to handle syscall exit path differently so let's split the
unaugmented exit BPF program. Currently it does nothing (same as
sys_enter).
Signed-off-by: Namhyung Kim <namhyung@xxxxxxxxxx>
Link: https://lore.kernel.org/r/20250814071754.193265-3-namhyung@xxxxxxxxxx
[ irogers: Use struct syscall_{enter,exit}_args and make
trace__find_syscall_bpf_prog() fall back to the exit program for
exits ]
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@xxxxxxxxxx>
---
tools/perf/builtin-trace.c | 10 ++++++----
tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c | 8 +++++++-
tools/perf/util/bpf_trace_augment.c | 9 +++++++--
tools/perf/util/trace_augment.h | 10 ++++++++--
4 files changed, 28 insertions(+), 9 deletions(-)
diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
index 1f89f85ba2e4..17e482ae02c9 100644
--- a/tools/perf/builtin-trace.c
+++ b/tools/perf/builtin-trace.c
@@ -4084,7 +4084,7 @@ static struct bpf_program *trace__find_syscall_bpf_prog(struct trace *trace __ma
pr_debug("Couldn't find BPF prog \"%s\" to associate with syscalls:sys_%s_%s, not augmenting it\n",
prog_name, type, sc->name);
out_unaugmented:
- return unaugmented_prog;
+ return strcmp(type, "exit") ? unaugmented_prog : augmented_syscalls__unaugmented_exit();
}
static void trace__init_syscall_bpf_progs(struct trace *trace, int e_machine, int id)
@@ -4101,13 +4101,15 @@ static void trace__init_syscall_bpf_progs(struct trace *trace, int e_machine, in
static int trace__bpf_prog_sys_enter_fd(struct trace *trace, int e_machine, int id)
{
struct syscall *sc = trace__syscall_info(trace, NULL, e_machine, id);
- return sc ? bpf_program__fd(sc->bpf_prog.sys_enter) : bpf_program__fd(unaugmented_prog);
+ return sc ? bpf_program__fd(sc->bpf_prog.sys_enter) :
+ bpf_program__fd(augmented_syscalls__unaugmented_enter());
}
static int trace__bpf_prog_sys_exit_fd(struct trace *trace, int e_machine, int id)
{
struct syscall *sc = trace__syscall_info(trace, NULL, e_machine, id);
- return sc ? bpf_program__fd(sc->bpf_prog.sys_exit) : bpf_program__fd(unaugmented_prog);
+ return sc ? bpf_program__fd(sc->bpf_prog.sys_exit) :
+ bpf_program__fd(augmented_syscalls__unaugmented_exit());
}
static int trace__bpf_sys_enter_beauty_map(struct trace *trace, int e_machine, int key, unsigned int *beauty_array)
@@ -4318,7 +4320,7 @@ static int trace__init_syscalls_bpf_prog_array_maps(struct trace *trace, int e_m
if (augmented_syscalls__get_map_fds(&map_enter_fd, &map_exit_fd, &beauty_map_fd) < 0)
return -1;
- unaugmented_prog = augmented_syscalls__unaugmented();
+ unaugmented_prog = augmented_syscalls__unaugmented_enter();
for (int i = 0, num_idx = syscalltbl__num_idx(e_machine); i < num_idx; ++i) {
int prog_fd, key = syscalltbl__id_at_idx(e_machine, i);
diff --git a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
index cc70861a23d6..18835c7512ac 100644
--- a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
+++ b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
@@ -192,7 +192,13 @@ unsigned int augmented_arg__read_str(struct augmented_arg *augmented_arg, const
}
SEC("tp/raw_syscalls/sys_enter")
-int syscall_unaugmented(struct syscall_enter_args *args)
+int sys_enter_unaugmented(struct syscall_enter_args *args)
+{
+ return 1;
+}
+
+SEC("tp/raw_syscalls/sys_exit")
+int sys_exit_unaugmented(struct syscall_exit_args *args)
{
return 1;
}
diff --git a/tools/perf/util/bpf_trace_augment.c b/tools/perf/util/bpf_trace_augment.c
index ebb26225fb04..0f510554ad9f 100644
--- a/tools/perf/util/bpf_trace_augment.c
+++ b/tools/perf/util/bpf_trace_augment.c
@@ -117,9 +117,14 @@ int augmented_syscalls__get_map_fds(int *enter_fd, int *exit_fd, int *beauty_fd)
return 0;
}
-struct bpf_program *augmented_syscalls__unaugmented(void)
+struct bpf_program *augmented_syscalls__unaugmented_enter(void)
{
- return skel->progs.syscall_unaugmented;
+ return skel->progs.sys_enter_unaugmented;
+}
+
+struct bpf_program *augmented_syscalls__unaugmented_exit(void)
+{
+ return skel->progs.sys_exit_unaugmented;
}
struct bpf_program *augmented_syscalls__find_by_title(const char *name)
diff --git a/tools/perf/util/trace_augment.h b/tools/perf/util/trace_augment.h
index a1cd9a5e0213..9c91e2569890 100644
--- a/tools/perf/util/trace_augment.h
+++ b/tools/perf/util/trace_augment.h
@@ -15,7 +15,8 @@ void augmented_syscalls__setup_bpf_output(void);
int augmented_syscalls__set_filter_pids(unsigned int nr, pid_t *pids);
int augmented_syscalls__get_map_fds(int *enter_fd, int *exit_fd, int *beauty_fd);
struct bpf_program *augmented_syscalls__find_by_title(const char *name);
-struct bpf_program *augmented_syscalls__unaugmented(void);
+struct bpf_program *augmented_syscalls__unaugmented_enter(void);
+struct bpf_program *augmented_syscalls__unaugmented_exit(void);
void augmented_syscalls__cleanup(void);
#else /* !HAVE_BPF_SKEL */
@@ -53,7 +54,12 @@ augmented_syscalls__find_by_title(const char *name __maybe_unused)
return NULL;
}
-static inline struct bpf_program *augmented_syscalls__unaugmented(void)
+static inline struct bpf_program *augmented_syscalls__unaugmented_enter(void)
+{
+ return NULL;
+}
+
+static inline struct bpf_program *augmented_syscalls__unaugmented_exit(void)
{
return NULL;
}
--
2.56.0.rc1.315.gc6ed9934b7-goog