On Tue,  1 Sep 2026 09:47:17 +0900
"Masami Hiramatsu (Google)" <[email protected]> wrote:

> From: Masami Hiramatsu (Google) <[email protected]>
> 
> btf_find_struct_member() traverses into nested anonymous structures and
> unions to find a struct member. However, get_bitoffset_of_field() in
> trace_probe.c checked btf_type_kflag(type) using the outer parent type
> instead of the actual anonymous structure/union that directly contains
> the found member.
> 
> If the parent structure and anonymous structure have mismatched kflags
> (e.g., the parent has kflag=0 while the anonymous structure has kflag=1
> because it contains bitfields), the bitfield size encoded in the upper
> 8 bits of member->offset is erroneously treated as part of the byte/bit
> offset, corrupting the resolved offset and failing to set last_bitsize.
> Similarly, btf_find_struct_member() pushed anonymous member offsets
> onto anon_stack without masking BTF_MEMBER_BIT_OFFSET() when kflag is set.
> 
> To fix this problem, update btf_find_struct_member() to return actual
> containing structure/union type via member_type, use appropriate
> __btf_member_bit_offset() to get bit offset, and use member_type for
> btf_type_kflag() in get_bitoffset_of_field().
> 
> Fixes: c440adfbe302 ("tracing/probes: Support BTF based data structure field 
> access")
> Cc: [email protected]
> Reported-by: Sashiko <[email protected]>
> Closes: 
> https://lore.kernel.org/all/[email protected]/
> Assisted-by: Antigravity:gemini-3.7-flash
> Signed-off-by: Masami Hiramatsu (Google) <[email protected]>
> ---


> @@ -661,11 +662,11 @@ static int get_bitoffset_of_field(char **pfieldname, 
> const struct btf_type **pty
>                       ctx->last_bitsize = 0;
>               }
>  
> -                     type = btf_type_skip_modifiers(btf, field->type, NULL);
> -                     if (!type) {
> -                             trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> -                             return -EINVAL;
> -                     }
> +             type = btf_type_skip_modifiers(btf, field->type, NULL);
> +             if (!type) {
> +                     trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> +                     return -EINVAL;
> +             }

Is this just to fix the indentation? If so, can you make this a separate
patch? We don't need it to be part of a patch that gets backported. It may
make it more difficult to do so.

-- Steve


>  
>               if (next)
>                       ctx->offset += next - fieldname;


Reply via email to