Thread (2 messages) flat view 2 messages, 2 authors, 2025-05-12

Re: [PATCH v4] tracepoint: Have tracepoints created with DECLARE_TRACE() have _tp suffix

From: Andrii Nakryiko <hidden>
Date: 2025-05-12 22:29:24
Also in: bpf, lkml, netdev

On Sat, May 10, 2025 at 1:37 PM Steven Rostedt [off-list ref] wrote:
From: Steven Rostedt <rostedt@goodmis.org>

Most tracepoints in the kernel are created with TRACE_EVENT(). The
TRACE_EVENT() macro (and DECLARE_EVENT_CLASS() and DEFINE_EVENT() where in
reality, TRACE_EVENT() is just a helper macro that calls those other two
macros), will create not only a tracepoint (the function trace_<event>()
used in the kernel), it also exposes the tracepoint to user space along
with defining what fields will be saved by that tracepoint.

There are a few places that tracepoints are created in the kernel that are
not exposed to userspace via tracefs. They can only be accessed from code
within the kernel. These tracepoints are created with DEFINE_TRACE()

Most of these tracepoints end with "_tp". This is useful as when the
developer sees that, they know that the tracepoint is for in-kernel only
(meaning it can only be accessed inside the kernel, either directly by the
kernel or indirectly via modules and BPF programs) and is not exposed to
user space.

Instead of making this only a process to add "_tp", enforce it by making
the DECLARE_TRACE() append the "_tp" suffix to the tracepoint. This
requires adding DECLARE_TRACE_EVENT() macros for the TRACE_EVENT() macro
to use that keeps the original name.

Link: https://lore.kernel.org/all/20250418083351.20a60e64@gandalf.local.home/ (local)

Acked-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Acked-by: Andrii Nakryiko <andrii@kernel.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
Changes since v3: https://lore.kernel.org/20250510092342.77371990@gandalf.local.home (local)

- Added "_tp" suffix in bpf tests to:

  tp_btf/bpf_testmod_test_raw_tp_null in raw_tp_null.c
  tp_btf/bpf_testmod_test_raw_tp_null in raw_tp_null_fail.c
  raw_tp.w/bpf_testmod_test_writable_bare in test_module_attach.c

  Hopefully this passes the bpf verifier tests.
Yep, BPF CI is happy, changes look good. Thanks!

Acked-by: Andrii Nakryiko <andrii@kernel.org>
 Documentation/trace/tracepoints.rst           | 17 ++++++---
 include/linux/tracepoint.h                    | 38 +++++++++++++------
 include/trace/bpf_probe.h                     |  8 ++--
 include/trace/define_trace.h                  | 17 ++++++++-
 include/trace/events/sched.h                  | 30 +++++++--------
 include/trace/events/tcp.h                    |  2 +-
 .../testing/selftests/bpf/progs/raw_tp_null.c |  2 +-
 .../selftests/bpf/progs/raw_tp_null_fail.c    |  2 +-
 .../selftests/bpf/progs/test_module_attach.c  |  4 +-
 .../bpf/progs/test_tp_btf_nullable.c          |  4 +-
 .../selftests/bpf/test_kmods/bpf_testmod.c    |  8 ++--
 11 files changed, 83 insertions(+), 49 deletions(-)
[...]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help