Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: linux-perf-users@vger.kernel.org, kvm@vger.kernel.org,
	linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v17 13/13] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger
Date: Tue, 22 Sep 2026 04:43:30 +0000	[thread overview]
Message-ID: <20260922044331.1EB901F000FF@smtp.kernel.org> (raw)
In-Reply-To: <179005123942.388919.17930857651144049898.stgit@devnote2>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] trace: incorrect BTF kflag check in get_offset_of_field() allows wild offsets
--

commit 3bc53bf9a42b7270af7bd91985c43e9cafe48496
Author: Masami Hiramatsu (Google) <mhiramat@kernel.org>

tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger

This commit allows the set_wprobe trigger to use BTF struct offset
resolution to specify the target address field.

Link: https://lore.kernel.org/all/59637b96946653393a7ad3c7de094094796b39c2.1785067572.git.wangjinchao600@gmail.com/

> diff --git a/kernel/trace/trace_wprobe.c b/kernel/trace/trace_wprobe.c
> index f1d6aa320f213..121310b72522f 100644
> --- a/kernel/trace/trace_wprobe.c
> +++ b/kernel/trace/trace_wprobe.c

[ ... ]

> @@ -1165,6 +1166,213 @@ static void wprobe_trigger_free(struct event_trigger_data *data)
>  	}
>  }
>  
> +#ifdef CONFIG_PROBE_EVENTS_BTF_ARGS
> +
> +static int get_offset_of_field(struct btf *btf, const struct btf_type *type, char *field_name)
> +{
> +	const struct btf_member *field;
> +	const struct btf_type *mtype;
> +	int bitoffs = 0;
> +	u32 anon_offs;
> +	char *next;
> +
> +	do {
> +		next = strchr(field_name, '.');
> +		if (next)
> +			*next++ = '\0';
> +
> +		field = btf_find_struct_member(btf, type, field_name, &anon_offs, &mtype);
> +		if (IS_ERR_OR_NULL(field))
> +			return -ENOENT;
> +
> +		if (btf_type_kflag(mtype)) {

[Severity: Medium]
Is it intentional to check btf_type_kflag() on the member type (mtype)
instead of the parent struct type (type)?

If the member's kflag is checked instead of the parent struct's kflag,
bitfield members can bypass the explicit rejection check and compute wildly
incorrect memory offsets. This happens because field->offset contains the
bitfield size in the upper 8 bits when the parent struct's kflag is set.

> +			/* Reject bitfield member access */
> +			if (BTF_MEMBER_BITFIELD_SIZE(field->offset))
> +				return -EINVAL;
> +			bitoffs += anon_offs + BTF_MEMBER_BIT_OFFSET(field->offset);
> +		} else {
> +			bitoffs += anon_offs + field->offset;
> +		}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/179005108298.388919.4535333252892590932.stgit@devnote2?part=13

  reply	other threads:[~2026-09-22  4:43 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22  4:24 [PATCH v17 00/13] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-09-22  4:24 ` [PATCH v17 01/13] x86/mce: Fix hardware debug register corruption on task migration Masami Hiramatsu (Google)
2026-09-22  4:40   ` sashiko-bot
2026-09-23  0:27   ` Borislav Petkov
2026-09-23  8:46     ` Peter Zijlstra
2026-09-23  8:56     ` Masami Hiramatsu
2026-09-22  4:25 ` [PATCH v17 02/13] perf/x86, KVM: Prevent host debug register leak into guest OS on NMI Masami Hiramatsu (Google)
2026-09-22  4:40   ` sashiko-bot
2026-09-23  8:51   ` Peter Zijlstra
2026-09-23 14:33     ` Sean Christopherson
2026-09-24  1:31       ` Masami Hiramatsu
2026-09-24  9:18       ` Peter Zijlstra
2026-09-23  9:15   ` Peter Zijlstra
2026-09-23 15:32     ` Sean Christopherson
2026-09-24  0:56       ` Masami Hiramatsu
2026-09-24  9:23       ` Peter Zijlstra
2026-09-22  4:25 ` [PATCH v17 03/13] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-09-22  4:40   ` sashiko-bot
2026-09-23  9:13   ` Peter Zijlstra
2026-09-24 12:56     ` Masami Hiramatsu
2026-09-22  4:25 ` [PATCH v17 04/13] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-22  4:39   ` sashiko-bot
2026-09-22  4:25 ` [PATCH v17 05/13] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-22  4:35   ` sashiko-bot
2026-09-22  4:25 ` [PATCH v17 06/13] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-09-22  4:41   ` sashiko-bot
2026-09-22  4:26 ` [PATCH v17 07/13] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-09-22  4:32   ` sashiko-bot
2026-09-22  4:26 ` [PATCH v17 08/13] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-09-22  4:32   ` sashiko-bot
2026-09-22  4:26 ` [PATCH v17 09/13] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-09-22  4:34   ` sashiko-bot
2026-09-22  4:26 ` [PATCH v17 10/13] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-09-22  4:43   ` sashiko-bot
2026-09-25  2:26     ` Masami Hiramatsu
2026-09-22  4:26 ` [PATCH v17 11/13] selftests: tracing: Add wprobe trigger testcases Masami Hiramatsu (Google)
2026-09-22  4:41   ` sashiko-bot
2026-09-25  3:28     ` Masami Hiramatsu
2026-09-22  4:27 ` [PATCH v17 12/13] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-09-22  4:42   ` sashiko-bot
2026-09-22  4:27 ` [PATCH v17 13/13] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
2026-09-22  4:43   ` sashiko-bot [this message]
2026-09-25  3:00     ` Masami Hiramatsu
2026-09-25  3:42     ` Masami Hiramatsu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922044331.1EB901F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mhiramat@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox