On Tue, 1 Sep 2026 09:04:42 -0400
Steven Rostedt <[email protected]> wrote:

> On Tue,  1 Sep 2026 09:47:17 +0900
> "Masami Hiramatsu (Google)" <[email protected]> wrote:
> 
> > From: Masami Hiramatsu (Google) <[email protected]>
> > 
> > btf_find_struct_member() traverses into nested anonymous structures and
> > unions to find a struct member. However, get_bitoffset_of_field() in
> > trace_probe.c checked btf_type_kflag(type) using the outer parent type
> > instead of the actual anonymous structure/union that directly contains
> > the found member.
> > 
> > If the parent structure and anonymous structure have mismatched kflags
> > (e.g., the parent has kflag=0 while the anonymous structure has kflag=1
> > because it contains bitfields), the bitfield size encoded in the upper
> > 8 bits of member->offset is erroneously treated as part of the byte/bit
> > offset, corrupting the resolved offset and failing to set last_bitsize.
> > Similarly, btf_find_struct_member() pushed anonymous member offsets
> > onto anon_stack without masking BTF_MEMBER_BIT_OFFSET() when kflag is set.
> > 
> > To fix this problem, update btf_find_struct_member() to return actual
> > containing structure/union type via member_type, use appropriate
> > __btf_member_bit_offset() to get bit offset, and use member_type for
> > btf_type_kflag() in get_bitoffset_of_field().
> > 
> > Fixes: c440adfbe302 ("tracing/probes: Support BTF based data structure 
> > field access")
> > Cc: [email protected]
> > Reported-by: Sashiko <[email protected]>
> > Closes: 
> > https://lore.kernel.org/all/[email protected]/
> > Assisted-by: Antigravity:gemini-3.7-flash
> > Signed-off-by: Masami Hiramatsu (Google) <[email protected]>
> > ---
> 
> 
> > @@ -661,11 +662,11 @@ static int get_bitoffset_of_field(char **pfieldname, 
> > const struct btf_type **pty
> >                     ctx->last_bitsize = 0;
> >             }
> >  
> > -                   type = btf_type_skip_modifiers(btf, field->type, NULL);
> > -                   if (!type) {
> > -                           trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> > -                           return -EINVAL;
> > -                   }
> > +           type = btf_type_skip_modifiers(btf, field->type, NULL);
> > +           if (!type) {
> > +                   trace_probe_log_err(ctx->offset, BAD_BTF_TID);
> > +                   return -EINVAL;
> > +           }
> 
> Is this just to fix the indentation? If so, can you make this a separate
> patch? We don't need it to be part of a patch that gets backported. It may
> make it more difficult to do so.

OK, let me split it.

Thanks,

> 
> -- Steve
> 
> 
> >  
> >             if (next)
> >                     ctx->offset += next - fieldname;
> 
> 


-- 
Masami Hiramatsu (Google) <[email protected]>

Reply via email to