Thread (45 messages) 45 messages, 6 authors, 12d ago

Re: [PATCH v17 13/13] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger

From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Date: 2026-09-25 03:00:06
Also in: kvm, linux-perf-users, sashiko-reviews

On Tue, 22 Sep 2026 04:43:30 +0000
sashiko-bot@kernel.org wrote:
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] trace: incorrect BTF kflag check in get_offset_of_field() allows wild offsets
--

commit 3bc53bf9a42b7270af7bd91985c43e9cafe48496
Author: Masami Hiramatsu (Google) [off-list ref]

tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger

This commit allows the set_wprobe trigger to use BTF struct offset
resolution to specify the target address field.

Link: https://lore.kernel.org/all/59637b96946653393a7ad3c7de094094796b39c2.1785067572.git.wangjinchao600@gmail.com/ (local)
quoted
diff --git a/kernel/trace/trace_wprobe.c b/kernel/trace/trace_wprobe.c
index f1d6aa320f213..121310b72522f 100644
--- a/kernel/trace/trace_wprobe.c
+++ b/kernel/trace/trace_wprobe.c
[ ... ]
quoted
@@ -1165,6 +1166,213 @@ static void wprobe_trigger_free(struct event_trigger_data *data)
 	}
 }
 
+#ifdef CONFIG_PROBE_EVENTS_BTF_ARGS
+
+static int get_offset_of_field(struct btf *btf, const struct btf_type *type, char *field_name)
+{
+	const struct btf_member *field;
+	const struct btf_type *mtype;
+	int bitoffs = 0;
+	u32 anon_offs;
+	char *next;
+
+	do {
+		next = strchr(field_name, '.');
+		if (next)
+			*next++ = '\0';
+
+		field = btf_find_struct_member(btf, type, field_name, &anon_offs, &mtype);
+		if (IS_ERR_OR_NULL(field))
+			return -ENOENT;
+
+		if (btf_type_kflag(mtype)) {
[Severity: Medium]
Is it intentional to check btf_type_kflag() on the member type (mtype)
instead of the parent struct type (type)?
Oops, I thought I had fixed this issue...
If the member's kflag is checked instead of the parent struct's kflag,
bitfield members can bypass the explicit rejection check and compute wildly
incorrect memory offsets. This happens because field->offset contains the
bitfield size in the upper 8 bits when the parent struct's kflag is set.
Yeah, kflag is the attribute of the  parept structure's type.

Thanks,
quoted
+			/* Reject bitfield member access */
+			if (BTF_MEMBER_BITFIELD_SIZE(field->offset))
+				return -EINVAL;
+			bitoffs += anon_offs + BTF_MEMBER_BIT_OFFSET(field->offset);
+		} else {
+			bitoffs += anon_offs + field->offset;
+		}
-- 
Sashiko AI review · https://sashiko.dev/#/patchset/179005108298.388919.4535333252892590932.stgit@devnote2?part=13

-- 
Masami Hiramatsu (Google) [off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help