BPF List
 help / color / mirror / Atom feed
* [PATCH v3 bpf-next 0/3] BTF inline functionality followups
@ 2026-09-26 17:51 Alan Maguire
  2026-09-26 17:51 ` [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
                   ` (4 more replies)
  0 siblings, 5 replies; 12+ messages in thread
From: Alan Maguire @ 2026-09-26 17:51 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Include additional vlen/flags verification for BTF_KIND_LOC_PARAM
(patch 1), and add function signatures to LOCSEC entries (patch 2),
adjusting test to cover these (patch 3).

Changes since v2 [1]

- Improved flag/vlen verification to check combinations (Alexei,
  patch 1)
- Simplified overrun ellipsis printing (Quentin, patch 2)

Changes since v1 [2]

- Fixed sign to appear after const (bots, patch 2)
- Simplified loc printing to remove vsnprintf() logic, updated
  to retain name in json (Quentin, patch 2)
- For oversized signature strings, append "..." (Quentin, patch 2)

[1] https://lore.kernel.org/bpf/20260925170854.1240637-1-alan.maguire@oracle.com/
[2] https://lore.kernel.org/bpf/20260925095231.879708-1-alan.maguire@oracle.com/

Alan Maguire (3):
  bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  bpftool: Update func representation to include function signature
  selftests/bpf: Fix up bpftool btf dump test for signatures

 kernel/bpf/btf.c                              |  43 ++++++
 tools/bpf/bpftool/btf.c                       | 123 ++++++++++++++++--
 .../bpf/prog_tests/bpftool_btf_dump.c         |  14 +-
 3 files changed, 165 insertions(+), 15 deletions(-)

-- 
2.43.5


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  2026-09-26 17:51 [PATCH v3 bpf-next 0/3] BTF inline functionality followups Alan Maguire
@ 2026-09-26 17:51 ` Alan Maguire
  2026-09-29 10:43   ` Alexei Starovoitov
  2026-09-26 17:51 ` [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
                   ` (3 subsequent siblings)
  4 siblings, 1 reply; 12+ messages in thread
From: Alan Maguire @ 2026-09-26 17:51 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Ensure that vlen and flags combinations are consistent for
BTF_KIND_LOC_PARAMs.

Fixes: 33c5a3278bdb ("btf: Extend UAPI to support BTF location (inline site) info")
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
---
 kernel/bpf/btf.c | 43 +++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 43 insertions(+)

diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 9bcfefdfb734..8cc17a1cd25c 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -4823,10 +4823,53 @@ static s32 btf_loc_param_check_meta(struct btf_verifier_env *env,
 		btf_verifier_log_type(env, t, "Invalid btf_info kind_flag");
 		return -EINVAL;
 	}
+	/* All LOC_PARAMs have vlen of at least 1 */
+	if (vlen < 1)
+		goto invalid_vlen;
+
+	switch (p->flags) {
+	case BTF_LOC_PARAM_CONST:
+	case BTF_LOC_PARAM_CONST | BTF_LOC_PARAM_SIGNED:
+	case BTF_LOC_PARAM_CONST | BTF_LOC_PARAM_ADDR:
+	case BTF_LOC_PARAM_CONST | BTF_LOC_PARAM_ADDR | BTF_LOC_PARAM_SIGNED:
+		if (vlen > 2)
+			goto invalid_vlen;
+		/* Ensure size/vlen are consistent */
+		if (size > sizeof(__u32) && vlen != 2)
+			goto invalid_vlen;
+		if (size > sizeof(__u64))
+			goto invalid_vlen;
+		break;
+	case BTF_LOC_PARAM_REG:
+		/* Reg or reg/reg pair */
+		if (vlen > 2)
+			goto invalid_vlen;
+		break;
+	case BTF_LOC_PARAM_REG | BTF_LOC_PARAM_DEREF:
+		/* A reg deref without offset can only have vlen 1 */
+		if (vlen != 1)
+			goto invalid_vlen;
+		break;
+	case BTF_LOC_PARAM_REG | BTF_LOC_PARAM_OFFSET:
+	case BTF_LOC_PARAM_REG | BTF_LOC_PARAM_OFFSET | BTF_LOC_PARAM_SIGNED:
+	case BTF_LOC_PARAM_REG | BTF_LOC_PARAM_DEREF | BTF_LOC_PARAM_OFFSET:
+	case BTF_LOC_PARAM_REG | BTF_LOC_PARAM_DEREF | BTF_LOC_PARAM_OFFSET |
+	     BTF_LOC_PARAM_SIGNED:
+		if (vlen < 2 || vlen > 3)
+			goto invalid_vlen;
+		break;
+	default:
+		btf_verifier_log_type(env, t, "Invalid flags");
+		return -EINVAL;
+	}
 
 	btf_verifier_log_type(env, t, NULL);
 
 	return meta_needed;
+
+invalid_vlen:
+	btf_verifier_log_type(env, t, "Invalid vlen");
+	return -EINVAL;
 }
 
 static void btf_loc_param_log(struct btf_verifier_env *env,
-- 
2.43.5


^ permalink raw reply related	[flat|nested] 12+ messages in thread

* [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-26 17:51 [PATCH v3 bpf-next 0/3] BTF inline functionality followups Alan Maguire
  2026-09-26 17:51 ` [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
@ 2026-09-26 17:51 ` Alan Maguire
  2026-09-28  9:39   ` Jiri Olsa
  2026-09-28 11:46   ` Quentin Monnet
  2026-09-26 17:51 ` [PATCH v3 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures Alan Maguire
                   ` (2 subsequent siblings)
  4 siblings, 2 replies; 12+ messages in thread
From: Alan Maguire @ 2026-09-26 17:51 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Augment func= output for LOCSEC entries to include a mapping from
function signature to where parameters are stored; for example:

[290179] LOCSEC 'inline.text' vlen=524941
        func='task_pid_nr(tsk [reg0])' func_type_id=136691 loc_proto_type_id=136693 offset=2097226
        func='get_current()' func_type_id=136694 loc_proto_type_id=136695 offset=2097247
        func='arch_static_branch(key [address 0x2e275e8], branch [const 0x0])' func_type_id=136697 loc_proto_type_id=136700 offset=2097296

Fixes: 321562c34d5b ("bpftool: Add ability to dump LOC_PARAM, LOC_PROTO and LOCSEC")
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
---
 tools/bpf/bpftool/btf.c | 123 +++++++++++++++++++++++++++++++++++++---
 1 file changed, 114 insertions(+), 9 deletions(-)

diff --git a/tools/bpf/bpftool/btf.c b/tools/bpf/bpftool/btf.c
index e29c8a84e224..abd661db91e6 100644
--- a/tools/bpf/bpftool/btf.c
+++ b/tools/bpf/bpftool/btf.c
@@ -150,6 +150,7 @@ static void btf_loc_param_raw_str(const struct btf_loc_param *p, __u32 vlen,
 
 static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 {
+	const char *op = "", *prefix = "";
 	const struct btf_loc_param *p;
 	__u32 i = 0, vlen;
 	__u64 value;
@@ -157,7 +158,6 @@ static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 	bool negative = false;
 	char regs[32] = {};
 	char num[32] = {};
-	const char *op = "";
 
 	if (!t || !btf_is_loc_param(t)) {
 		snprintf(str, sz, "<invalid>");
@@ -234,8 +234,12 @@ static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 						(1ULL << bits) - value;
 			}
 		}
-		snprintf(num, sizeof(num), "0x%llx%s", (unsigned long long)value,
-			 p->flags & BTF_LOC_PARAM_ADDR ? " (addr)" : "");
+		if (p->flags & BTF_LOC_PARAM_ADDR)
+			prefix = "address ";
+		else if (p->flags & BTF_LOC_PARAM_CONST)
+			prefix = "const ";
+		snprintf(num, sizeof(num), "0x%llx",
+			 (unsigned long long)value);
 	}
 	if (i != vlen) {
 		btf_loc_param_raw_str(p, vlen, str, sz);
@@ -244,14 +248,111 @@ static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 	if (num[0])
 		op = regs[0] ? (negative ? " - " : " + ") : negative ? "-" : "";
 
-	snprintf(str, sz, "%s%s%s%s%s",
+	snprintf(str, sz, "%s%s%s%s%s%s",
 		 p->flags & BTF_LOC_PARAM_DEREF ? "*(" : "",
+		 prefix,
 		 regs,
 		 op,
 		 num,
 		 p->flags & BTF_LOC_PARAM_DEREF ? ")" : "");
 }
 
+static bool btf_locsec_append(char *str, size_t sz, size_t *off,
+			      const char *suffix)
+{
+	static const char nospace_suffix[] = "...";
+	bool space_left = true;
+	size_t left = 0, len;
+
+	if (*off >= sz || sz < sizeof(nospace_suffix))
+		return false;
+	left = sz - *off;
+
+	/*
+	 * Copy as much of the string as we can in remaining space, and
+	 * append "..." if we would have overrun.
+	 */
+	len = strlen(suffix) + 1;
+	if (len > left) {
+		len = left;
+		space_left = false;
+	}
+
+	memcpy(str + *off, suffix, len);
+	*off += len - 1;
+
+	if (!space_left)
+		memcpy(str + sz - sizeof(nospace_suffix), nospace_suffix, sizeof(nospace_suffix));
+
+	return space_left;
+}
+
+static void btf_locsec_func_str(const struct btf *btf,
+				const struct btf_loc *loc, char *str, size_t sz)
+{
+	const struct btf_type *func, *func_proto, *loc_proto;
+	const struct btf_param *params;
+	const __u32 *loc_params;
+	const char *name;
+	__u32 i, vlen;
+	size_t off = 0;
+
+	if (!sz)
+		return;
+
+	str[0] = '\0';
+	func = btf__type_by_id(btf, loc->func);
+	if (!func || !btf_is_func(func))
+		goto invalid;
+
+	name = btf_str(btf, func->name_off);
+	func_proto = btf__type_by_id(btf, func->type);
+	loc_proto = btf__type_by_id(btf, loc->loc_proto);
+	if (!func_proto || !btf_is_func_proto(func_proto) ||
+	    !loc_proto || !btf_is_loc_proto(loc_proto) ||
+	    btf_vlen(func_proto) != btf_vlen(loc_proto))
+		goto invalid;
+
+	params = (const void *)(func_proto + 1);
+	loc_params = btf_loc_proto_params(loc_proto);
+	vlen = btf_vlen(func_proto);
+	if (!btf_locsec_append(str, sz, &off, name) ||
+	    !btf_locsec_append(str, sz, &off, "("))
+		return;
+	for (i = 0; i < vlen; i++) {
+		const struct btf_type *param_loc;
+		char param_str[256] = {};
+
+		if (!params[i].type) {
+			/* Handle varargs func proto, must be last parameter */
+			if (i != vlen - 1)
+				goto invalid;
+			if (!btf_locsec_append(str, sz, &off, i ? ", " : "") ||
+			    !btf_locsec_append(str, sz, &off, "..."))
+				return;
+			break;
+		} else if (loc_params[i]) {
+			param_loc = btf__type_by_id(btf, loc_params[i]);
+			btf_loc_param_str(param_loc, param_str, sizeof(param_str));
+		} else {
+			snprintf(param_str, sizeof(param_str), "<unavailable>");
+		}
+
+		if (!btf_locsec_append(str, sz, &off, i ? ", " : "") ||
+		    !btf_locsec_append(str, sz, &off,
+				       btf_str(btf, params[i].name_off)) ||
+		    !btf_locsec_append(str, sz, &off, " [") ||
+		    !btf_locsec_append(str, sz, &off, param_str) ||
+		    !btf_locsec_append(str, sz, &off, "]"))
+			return;
+	}
+	(void) btf_locsec_append(str, sz, &off, ")");
+	return;
+
+invalid:
+	snprintf(str, sz, "<invalid>");
+}
+
 static int dump_btf_type(const struct btf *btf, __u32 id,
 			 const struct btf_type *t)
 {
@@ -617,22 +718,26 @@ static int dump_btf_type(const struct btf *btf, __u32 id,
 		}
 
 		for (i = 0; i < vlen; i++, locs++) {
-			const struct btf_type *f = btf__type_by_id(btf, locs->func);
+			const struct btf_type *func;
 			const char *name = "<invalid>";
+			char func_str[1024] = {};
 
-			if (f && btf_is_func(f))
-				name = btf_str(btf, f->name_off);
+			func = btf__type_by_id(btf, locs->func);
+			if (func && btf_is_func(func))
+				name = btf_str(btf, func->name_off);
+			btf_locsec_func_str(btf, locs, func_str, sizeof(func_str));
 
 			if (json_output) {
 				jsonw_start_object(w);
 				jsonw_uint_field(w, "func_type_id", locs->func);
 				jsonw_string_field(w, "name", name);
+				jsonw_string_field(w, "func", func_str);
 				jsonw_uint_field(w, "loc_proto_type_id", locs->loc_proto);
 				jsonw_uint_field(w, "offset", locs->offset);
 				jsonw_end_object(w);
 			} else {
-				printf("\n\tname='%s' func_type_id=%u loc_proto_type_id=%u offset=%u",
-				       name, locs->func, locs->loc_proto, locs->offset);
+				printf("\n\tfunc='%s' func_type_id=%u loc_proto_type_id=%u offset=%u",
+				       func_str, locs->func, locs->loc_proto, locs->offset);
 			}
 		}
 		if (json_output)
-- 
2.43.5


^ permalink raw reply related	[flat|nested] 12+ messages in thread

* [PATCH v3 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures
  2026-09-26 17:51 [PATCH v3 bpf-next 0/3] BTF inline functionality followups Alan Maguire
  2026-09-26 17:51 ` [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
  2026-09-26 17:51 ` [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
@ 2026-09-26 17:51 ` Alan Maguire
  2026-09-28  9:39 ` [PATCH v3 bpf-next 0/3] BTF inline functionality followups Jiri Olsa
  2026-09-29 10:50 ` patchwork-bot+netdevbpf
  4 siblings, 0 replies; 12+ messages in thread
From: Alan Maguire @ 2026-09-26 17:51 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Now we show a function signature, fix up the test to expect it.
Also fix the fact that we did not add the right number of parameters
to the FUNC_PROTO, and ensure consts/addresses are prefixed
appropriately.

Fixes: 321562c34d5b ("bpftool: Add ability to dump LOC_PARAM, LOC_PROTO and LOCSEC")
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
---
 .../selftests/bpf/prog_tests/bpftool_btf_dump.c    | 14 ++++++++------
 1 file changed, 8 insertions(+), 6 deletions(-)

diff --git a/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c b/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c
index bed506badc75..abc62958b6ed 100644
--- a/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c
+++ b/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c
@@ -72,6 +72,7 @@ static struct btf *mk_loc_btf(void)
 	btf__add_func_param(btf, "arg3", 1);
 	btf__add_func_param(btf, "arg4", 1);
 	btf__add_func_param(btf, "arg5", 1);
+	btf__add_func_param(btf, "arg6", 1);
 	btf__add_func(btf, "foo", BTF_FUNC_STATIC, 2);
 
 	btf__add_loc_param(btf, 4, BTF_LOC_PARAM_REG);
@@ -230,28 +231,29 @@ static void test_loc_dump(const char *btf_path)
 {
 	const char expected[] =
 		"[1] INT 'int' size=4 bits_offset=0 nr_bits=32 encoding=SIGNED\n"
-		"[2] FUNC_PROTO '(anon)' ret_type_id=1 vlen=5\n"
+		"[2] FUNC_PROTO '(anon)' ret_type_id=1 vlen=6\n"
 		"\t'arg1' type_id=1\n"
 		"\t'arg2' type_id=1\n"
 		"\t'arg3' type_id=1\n"
 		"\t'arg4' type_id=1\n"
 		"\t'arg5' type_id=1\n"
+		"\t'arg6' type_id=1\n"
 		"[3] FUNC 'foo' type_id=2 linkage=static\n"
 		"[4] LOC_PARAM '(anon)' size=4 flags=0x8 vlen=1 values='reg1'\n"
 		"[5] LOC_PARAM '(anon)' size=8 flags=0x38 vlen=2 values='*(reg2 + 0x10)'\n"
 		"[6] LOC_PARAM '(anon)' size=8 flags=0x29 vlen=2 values='fbreg - 0x10'\n"
-		"[7] LOC_PARAM '(anon)' size=8 flags=0x6 vlen=2 values='0x123456789abcdef0 (addr)'\n"
-		"[8] LOC_PARAM '(anon)' size=8 flags=0x2 vlen=2 values='0xdeadbeeffeedface'\n"
+		"[7] LOC_PARAM '(anon)' size=8 flags=0x6 vlen=2 values='address 0x123456789abcdef0'\n"
+		"[8] LOC_PARAM '(anon)' size=8 flags=0x2 vlen=2 values='const 0xdeadbeeffeedface'\n"
 		"[9] LOC_PARAM '(anon)' size=8 flags=0x39 vlen=2 values='*(fbreg - 0x20)'\n"
 		"[10] LOC_PROTO '(anon)' vlen=6\n"
 		"\ttype_id=4 value='reg1'\n"
 		"\ttype_id=5 value='*(reg2 + 0x10)'\n"
 		"\ttype_id=6 value='fbreg - 0x10'\n"
-		"\ttype_id=7 value='0x123456789abcdef0 (addr)'\n"
-		"\ttype_id=8 value='0xdeadbeeffeedface'\n"
+		"\ttype_id=7 value='address 0x123456789abcdef0'\n"
+		"\ttype_id=8 value='const 0xdeadbeeffeedface'\n"
 		"\ttype_id=9 value='*(fbreg - 0x20)'\n"
 		"[11] LOCSEC 'inline.text' vlen=1\n"
-		"\tname='foo' func_type_id=3 loc_proto_type_id=10 offset=64\n";
+		"\tfunc='foo(arg1 [reg1], arg2 [*(reg2 + 0x10)], arg3 [fbreg - 0x10], arg4 [address 0x123456789abcdef0], arg5 [const 0xdeadbeeffeedface], arg6 [*(fbreg - 0x20)])' func_type_id=3 loc_proto_type_id=10 offset=64\n";
 	char *dump;
 
 	dump = dump_raw(btf_path);
-- 
2.43.5


^ permalink raw reply related	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-26 17:51 ` [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
@ 2026-09-28  9:39   ` Jiri Olsa
  2026-09-28  9:50     ` Alan Maguire
  2026-09-28 11:46   ` Quentin Monnet
  1 sibling, 1 reply; 12+ messages in thread
From: Jiri Olsa @ 2026-09-28  9:39 UTC (permalink / raw)
  To: Alan Maguire
  Cc: ast, andrii, eddyz87, qmo, daniel, ihor.solodrai, yonghong.song,
	song, martin.lau, memxor, emil, bpf, nsc, puranjay, yatsenko

On Sat, Sep 26, 2026 at 06:51:12PM +0100, Alan Maguire wrote:

SNIP

> +static void btf_locsec_func_str(const struct btf *btf,
> +				const struct btf_loc *loc, char *str, size_t sz)
> +{
> +	const struct btf_type *func, *func_proto, *loc_proto;
> +	const struct btf_param *params;
> +	const __u32 *loc_params;
> +	const char *name;
> +	__u32 i, vlen;
> +	size_t off = 0;
> +
> +	if (!sz)
> +		return;
> +
> +	str[0] = '\0';
> +	func = btf__type_by_id(btf, loc->func);
> +	if (!func || !btf_is_func(func))
> +		goto invalid;
> +
> +	name = btf_str(btf, func->name_off);
> +	func_proto = btf__type_by_id(btf, func->type);
> +	loc_proto = btf__type_by_id(btf, loc->loc_proto);
> +	if (!func_proto || !btf_is_func_proto(func_proto) ||
> +	    !loc_proto || !btf_is_loc_proto(loc_proto) ||
> +	    btf_vlen(func_proto) != btf_vlen(loc_proto))
> +		goto invalid;
> +
> +	params = (const void *)(func_proto + 1);
> +	loc_params = btf_loc_proto_params(loc_proto);
> +	vlen = btf_vlen(func_proto);
> +	if (!btf_locsec_append(str, sz, &off, name) ||
> +	    !btf_locsec_append(str, sz, &off, "("))
> +		return;
> +	for (i = 0; i < vlen; i++) {
> +		const struct btf_type *param_loc;
> +		char param_str[256] = {};
> +
> +		if (!params[i].type) {
> +			/* Handle varargs func proto, must be last parameter */
> +			if (i != vlen - 1)
> +				goto invalid;
> +			if (!btf_locsec_append(str, sz, &off, i ? ", " : "") ||
> +			    !btf_locsec_append(str, sz, &off, "..."))
> +				return;
> +			break;
> +		} else if (loc_params[i]) {
> +			param_loc = btf__type_by_id(btf, loc_params[i]);
> +			btf_loc_param_str(param_loc, param_str, sizeof(param_str));
> +		} else {
> +			snprintf(param_str, sizeof(param_str), "<unavailable>");

hi,
I'm getting many unavailable arguments, like:

jolsa@krava4:~/kernel/linux-qemu-1$ ./tools/bpf/bpftool/bpftool btf dump file /tmp/vmlinux+inline | grep func | grep '<unavailable>' | head -10
	func='cpumask_test_cpu(cpu [reg0], cpumask [<unavailable>])' func_type_id=171851 loc_proto_type_id=171852 offset=7674
	func='instrument_atomic_check_alignment(v [<unavailable>], size [const 0x8])' func_type_id=171855 loc_proto_type_id=171857 offset=7681
	func='instrument_atomic_read(v [<unavailable>], size [const 0x8])' func_type_id=171858 loc_proto_type_id=171857 offset=7681
	func='variable_test_bit(nr [*(reg0)], addr [<unavailable>])' func_type_id=171860 loc_proto_type_id=171862 offset=7681
	func='arch_test_bit(nr [*(reg0)], addr [<unavailable>])' func_type_id=171864 loc_proto_type_id=171862 offset=7681
	func='_test_bit(nr [*(reg0)], addr [<unavailable>])' func_type_id=171865 loc_proto_type_id=171862 offset=7681
	func='__srcu_read_lock_fast(ssp [<unavailable>])' func_type_id=171867 loc_proto_type_id=171868 offset=7691
	func='srcu_read_lock_fast_notrace(ssp [<unavailable>])' func_type_id=171869 loc_proto_type_id=171868 offset=7691
	func='class_srcu_fast_notrace_constructor(l [<unavailable>])' func_type_id=171871 loc_proto_type_id=171868 offset=7691
	func='__srcu_read_unlock_fast(ssp [<unavailable>], scp [reg3])' func_type_id=171873 loc_proto_type_id=171875 offset=7727
jolsa@krava4:~/kernel/linux-qemu-1$ ./tools/bpf/bpftool/bpftool btf dump file /tmp/vmlinux+inline | grep func | grep '<unavailable>' | wc -l
157950

I found on the pahole site 

  /* A zero id in LOC_PROTO represents unavailable location data. */

so I guess it's just not present in dwarf for some reason

jirka

^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 0/3] BTF inline functionality followups
  2026-09-26 17:51 [PATCH v3 bpf-next 0/3] BTF inline functionality followups Alan Maguire
                   ` (2 preceding siblings ...)
  2026-09-26 17:51 ` [PATCH v3 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures Alan Maguire
@ 2026-09-28  9:39 ` Jiri Olsa
  2026-09-28 11:46   ` Quentin Monnet
  2026-09-29 10:50 ` patchwork-bot+netdevbpf
  4 siblings, 1 reply; 12+ messages in thread
From: Jiri Olsa @ 2026-09-28  9:39 UTC (permalink / raw)
  To: Alan Maguire
  Cc: ast, andrii, eddyz87, qmo, daniel, ihor.solodrai, yonghong.song,
	song, martin.lau, memxor, emil, bpf, nsc, puranjay, yatsenko

On Sat, Sep 26, 2026 at 06:51:10PM +0100, Alan Maguire wrote:
> Include additional vlen/flags verification for BTF_KIND_LOC_PARAM
> (patch 1), and add function signatures to LOCSEC entries (patch 2),
> adjusting test to cover these (patch 3).
> 
> Changes since v2 [1]
> 
> - Improved flag/vlen verification to check combinations (Alexei,
>   patch 1)
> - Simplified overrun ellipsis printing (Quentin, patch 2)

Acked-by: Jiri Olsa <jolsa@kernel.org>

jirka

> 
> Changes since v1 [2]
> 
> - Fixed sign to appear after const (bots, patch 2)
> - Simplified loc printing to remove vsnprintf() logic, updated
>   to retain name in json (Quentin, patch 2)
> - For oversized signature strings, append "..." (Quentin, patch 2)
> 
> [1] https://lore.kernel.org/bpf/20260925170854.1240637-1-alan.maguire@oracle.com/
> [2] https://lore.kernel.org/bpf/20260925095231.879708-1-alan.maguire@oracle.com/
> 
> Alan Maguire (3):
>   bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
>   bpftool: Update func representation to include function signature
>   selftests/bpf: Fix up bpftool btf dump test for signatures
> 
>  kernel/bpf/btf.c                              |  43 ++++++
>  tools/bpf/bpftool/btf.c                       | 123 ++++++++++++++++--
>  .../bpf/prog_tests/bpftool_btf_dump.c         |  14 +-
>  3 files changed, 165 insertions(+), 15 deletions(-)
> 
> -- 
> 2.43.5
> 

^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-28  9:39   ` Jiri Olsa
@ 2026-09-28  9:50     ` Alan Maguire
  0 siblings, 0 replies; 12+ messages in thread
From: Alan Maguire @ 2026-09-28  9:50 UTC (permalink / raw)
  To: Jiri Olsa
  Cc: ast, andrii, eddyz87, qmo, daniel, ihor.solodrai, yonghong.song,
	song, martin.lau, memxor, emil, bpf, nsc, puranjay, yatsenko

On 28/09/2026 10:39, Jiri Olsa wrote:
> 
> On Sat, Sep 26, 2026 at 06:51:12PM +0100, Alan Maguire wrote:
> 
> SNIP
> 
>> +static void btf_locsec_func_str(const struct btf *btf,
>> +				const struct btf_loc *loc, char *str, size_t sz)
>> +{
>> +	const struct btf_type *func, *func_proto, *loc_proto;
>> +	const struct btf_param *params;
>> +	const __u32 *loc_params;
>> +	const char *name;
>> +	__u32 i, vlen;
>> +	size_t off = 0;
>> +
>> +	if (!sz)
>> +		return;
>> +
>> +	str[0] = '\0';
>> +	func = btf__type_by_id(btf, loc->func);
>> +	if (!func || !btf_is_func(func))
>> +		goto invalid;
>> +
>> +	name = btf_str(btf, func->name_off);
>> +	func_proto = btf__type_by_id(btf, func->type);
>> +	loc_proto = btf__type_by_id(btf, loc->loc_proto);
>> +	if (!func_proto || !btf_is_func_proto(func_proto) ||
>> +	    !loc_proto || !btf_is_loc_proto(loc_proto) ||
>> +	    btf_vlen(func_proto) != btf_vlen(loc_proto))
>> +		goto invalid;
>> +
>> +	params = (const void *)(func_proto + 1);
>> +	loc_params = btf_loc_proto_params(loc_proto);
>> +	vlen = btf_vlen(func_proto);
>> +	if (!btf_locsec_append(str, sz, &off, name) ||
>> +	    !btf_locsec_append(str, sz, &off, "("))
>> +		return;
>> +	for (i = 0; i < vlen; i++) {
>> +		const struct btf_type *param_loc;
>> +		char param_str[256] = {};
>> +
>> +		if (!params[i].type) {
>> +			/* Handle varargs func proto, must be last parameter */
>> +			if (i != vlen - 1)
>> +				goto invalid;
>> +			if (!btf_locsec_append(str, sz, &off, i ? ", " : "") ||
>> +			    !btf_locsec_append(str, sz, &off, "..."))
>> +				return;
>> +			break;
>> +		} else if (loc_params[i]) {
>> +			param_loc = btf__type_by_id(btf, loc_params[i]);
>> +			btf_loc_param_str(param_loc, param_str, sizeof(param_str));
>> +		} else {
>> +			snprintf(param_str, sizeof(param_str), "<unavailable>");
> 
> hi,
> I'm getting many unavailable arguments, like:
> 
> jolsa@krava4:~/kernel/linux-qemu-1$ ./tools/bpf/bpftool/bpftool btf dump file /tmp/vmlinux+inline | grep func | grep '<unavailable>' | head -10
> 	func='cpumask_test_cpu(cpu [reg0], cpumask [<unavailable>])' func_type_id=171851 loc_proto_type_id=171852 offset=7674
> 	func='instrument_atomic_check_alignment(v [<unavailable>], size [const 0x8])' func_type_id=171855 loc_proto_type_id=171857 offset=7681
> 	func='instrument_atomic_read(v [<unavailable>], size [const 0x8])' func_type_id=171858 loc_proto_type_id=171857 offset=7681
> 	func='variable_test_bit(nr [*(reg0)], addr [<unavailable>])' func_type_id=171860 loc_proto_type_id=171862 offset=7681
> 	func='arch_test_bit(nr [*(reg0)], addr [<unavailable>])' func_type_id=171864 loc_proto_type_id=171862 offset=7681
> 	func='_test_bit(nr [*(reg0)], addr [<unavailable>])' func_type_id=171865 loc_proto_type_id=171862 offset=7681
> 	func='__srcu_read_lock_fast(ssp [<unavailable>])' func_type_id=171867 loc_proto_type_id=171868 offset=7691
> 	func='srcu_read_lock_fast_notrace(ssp [<unavailable>])' func_type_id=171869 loc_proto_type_id=171868 offset=7691
> 	func='class_srcu_fast_notrace_constructor(l [<unavailable>])' func_type_id=171871 loc_proto_type_id=171868 offset=7691
> 	func='__srcu_read_unlock_fast(ssp [<unavailable>], scp [reg3])' func_type_id=171873 loc_proto_type_id=171875 offset=7727
> jolsa@krava4:~/kernel/linux-qemu-1$ ./tools/bpf/bpftool/bpftool btf dump file /tmp/vmlinux+inline | grep func | grep '<unavailable>' | wc -l
> 157950
> 
> I found on the pahole site 
> 
>   /* A zero id in LOC_PROTO represents unavailable location data. */
> 
> so I guess it's just not present in dwarf for some reason
>

yep; this matches my observation; of about 600,000 function I see around 80%
have all parameters available, so ~120,000 functions have one or more unavailable,
either due to missing location info or overly-complex location expressions.

IIRC this fits with Eduard's observations earlier on. I tried exploring adding
more location expression supports (logical operators etc) but none appeared to
add enough additional sites to be worth the added complexity. 

Thanks for testing!

Alan

^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-26 17:51 ` [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
  2026-09-28  9:39   ` Jiri Olsa
@ 2026-09-28 11:46   ` Quentin Monnet
  1 sibling, 0 replies; 12+ messages in thread
From: Quentin Monnet @ 2026-09-28 11:46 UTC (permalink / raw)
  To: Alan Maguire, ast, andrii, eddyz87
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko

2026-09-26 18:51 UTC+0100 ~ Alan Maguire <alan.maguire@oracle.com>
> Augment func= output for LOCSEC entries to include a mapping from
> function signature to where parameters are stored; for example:
> 
> [290179] LOCSEC 'inline.text' vlen=524941
>         func='task_pid_nr(tsk [reg0])' func_type_id=136691 loc_proto_type_id=136693 offset=2097226
>         func='get_current()' func_type_id=136694 loc_proto_type_id=136695 offset=2097247
>         func='arch_static_branch(key [address 0x2e275e8], branch [const 0x0])' func_type_id=136697 loc_proto_type_id=136700 offset=2097296
> 
> Fixes: 321562c34d5b ("bpftool: Add ability to dump LOC_PARAM, LOC_PROTO and LOCSEC")
> Suggested-by: Alexei Starovoitov <ast@kernel.org>
> Signed-off-by: Alan Maguire <alan.maguire@oracle.com>

Acked-by: Quentin Monnet <qmo@kernel.org>

Thanks!
Quentin

^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 0/3] BTF inline functionality followups
  2026-09-28  9:39 ` [PATCH v3 bpf-next 0/3] BTF inline functionality followups Jiri Olsa
@ 2026-09-28 11:46   ` Quentin Monnet
  0 siblings, 0 replies; 12+ messages in thread
From: Quentin Monnet @ 2026-09-28 11:46 UTC (permalink / raw)
  To: Jiri Olsa, Alan Maguire
  Cc: ast, andrii, eddyz87, daniel, ihor.solodrai, yonghong.song, song,
	martin.lau, memxor, emil, bpf, nsc, puranjay, yatsenko

2026-09-28 11:39 UTC+0200 ~ Jiri Olsa <olsajiri@gmail.com>
> On Sat, Sep 26, 2026 at 06:51:10PM +0100, Alan Maguire wrote:
>> Include additional vlen/flags verification for BTF_KIND_LOC_PARAM
>> (patch 1), and add function signatures to LOCSEC entries (patch 2),
>> adjusting test to cover these (patch 3).
>>
>> Changes since v2 [1]
>>
>> - Improved flag/vlen verification to check combinations (Alexei,
>>   patch 1)
>> - Simplified overrun ellipsis printing (Quentin, patch 2)
> 
> Acked-by: Jiri Olsa <jolsa@kernel.org>
> 
> jirka
> 
Acked-by: Quentin Monnet <qmo@kernel.org>

^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  2026-09-26 17:51 ` [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
@ 2026-09-29 10:43   ` Alexei Starovoitov
  2026-09-29 10:50     ` Alan Maguire
  0 siblings, 1 reply; 12+ messages in thread
From: Alexei Starovoitov @ 2026-09-29 10:43 UTC (permalink / raw)
  To: Alan Maguire, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko

On Sat, Sep 26, 2026 at 06:51 PM Alan Maguire <alan.maguire@oracle.com> wrote:
> +	case BTF_LOC_PARAM_CONST | BTF_LOC_PARAM_ADDR | BTF_LOC_PARAM_SIGNED:
> +		if (vlen > 2)
> +			goto invalid_vlen;
> +		/* Ensure size/vlen are consistent */
> +		if (size > sizeof(__u32) && vlen != 2)
> +			goto invalid_vlen;
> +		if (size > sizeof(__u64))
> +			goto invalid_vlen;
> +		break;

size <= 4 with vlen == 2 is still accepted.
For size=4 values={1, 2} bpftool prints 'const 0x200000001'
and 'const 0x1' when SIGNED is set.
pahole emits one word for size <= 4 and two otherwise.
Should it be
	if (vlen != (size > 4 ? 2 : 1))
?

Applied anyway, but pls followup.


^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 0/3] BTF inline functionality followups
  2026-09-26 17:51 [PATCH v3 bpf-next 0/3] BTF inline functionality followups Alan Maguire
                   ` (3 preceding siblings ...)
  2026-09-28  9:39 ` [PATCH v3 bpf-next 0/3] BTF inline functionality followups Jiri Olsa
@ 2026-09-29 10:50 ` patchwork-bot+netdevbpf
  4 siblings, 0 replies; 12+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-29 10:50 UTC (permalink / raw)
  To: Alan Maguire
  Cc: ast, andrii, eddyz87, qmo, jolsa, daniel, ihor.solodrai,
	yonghong.song, song, martin.lau, memxor, emil, bpf, nsc, puranjay,
	yatsenko

Hello:

This series was applied to bpf/bpf-next.git (master)
by Alexei Starovoitov <ast@kernel.org>:

On Sat, 26 Sep 2026 18:51:10 +0100 you wrote:
> Include additional vlen/flags verification for BTF_KIND_LOC_PARAM
> (patch 1), and add function signatures to LOCSEC entries (patch 2),
> adjusting test to cover these (patch 3).
> 
> Changes since v2 [1]
> 
> - Improved flag/vlen verification to check combinations (Alexei,
>   patch 1)
> - Simplified overrun ellipsis printing (Quentin, patch 2)
> 
> [...]

Here is the summary with links:
  - [v3,bpf-next,1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
    https://git.kernel.org/bpf/bpf-next/c/a3df11403e8c
  - [v3,bpf-next,2/3] bpftool: Update func representation to include function signature
    https://git.kernel.org/bpf/bpf-next/c/29f6453491f3
  - [v3,bpf-next,3/3] selftests/bpf: Fix up bpftool btf dump test for signatures
    https://git.kernel.org/bpf/bpf-next/c/3cc62f77b974

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 12+ messages in thread

* Re: [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  2026-09-29 10:43   ` Alexei Starovoitov
@ 2026-09-29 10:50     ` Alan Maguire
  0 siblings, 0 replies; 12+ messages in thread
From: Alan Maguire @ 2026-09-29 10:50 UTC (permalink / raw)
  To: Alexei Starovoitov, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko

On 29/09/2026 11:43, Alexei Starovoitov wrote:
> On Sat, Sep 26, 2026 at 06:51 PM Alan Maguire <alan.maguire@oracle.com> wrote:
>> +	case BTF_LOC_PARAM_CONST | BTF_LOC_PARAM_ADDR | BTF_LOC_PARAM_SIGNED:
>> +		if (vlen > 2)
>> +			goto invalid_vlen;
>> +		/* Ensure size/vlen are consistent */
>> +		if (size > sizeof(__u32) && vlen != 2)
>> +			goto invalid_vlen;
>> +		if (size > sizeof(__u64))
>> +			goto invalid_vlen;
>> +		break;
> 
> size <= 4 with vlen == 2 is still accepted.
> For size=4 values={1, 2} bpftool prints 'const 0x200000001'
> and 'const 0x1' when SIGNED is set.
> pahole emits one word for size <= 4 and two otherwise.
> Should it be
> 	if (vlen != (size > 4 ? 2 : 1))
> ?
> 
> Applied anyway, but pls followup.
> 

good catch, will do. thanks!

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-09-29 10:51 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 17:51 [PATCH v3 bpf-next 0/3] BTF inline functionality followups Alan Maguire
2026-09-26 17:51 ` [PATCH v3 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
2026-09-29 10:43   ` Alexei Starovoitov
2026-09-29 10:50     ` Alan Maguire
2026-09-26 17:51 ` [PATCH v3 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
2026-09-28  9:39   ` Jiri Olsa
2026-09-28  9:50     ` Alan Maguire
2026-09-28 11:46   ` Quentin Monnet
2026-09-26 17:51 ` [PATCH v3 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures Alan Maguire
2026-09-28  9:39 ` [PATCH v3 bpf-next 0/3] BTF inline functionality followups Jiri Olsa
2026-09-28 11:46   ` Quentin Monnet
2026-09-29 10:50 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox