From: Masami Hiramatsu (Google) <[email protected]> Allow BTF typecast syntax (STRUCT)FETCHARG->MEMBER in wprobe event fetchargs. Previously, handle_typecast() rejected any probe context that was not a function entry/return or tracepoint event probe.
Wprobe events use $addr (the accessed address) and $value (the value at that address). By enabling BTF typecast, users can now cast these to a concrete struct type and access its fields directly. For example: echo 'w:watch rw@0:8 dflag=(dentry)$addr->d_flags' >> dynamic_events With a set_wprobe trigger pointing the watchpoint at a dentry address, the resulting trace shows d_flags being accessed at that location. Note that $addr and $value are restricted to kernel-space memory, which is consistent with the existing TPARG_FL_KERNEL flag used when parsing wprobe fetchargs. Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Masami Hiramatsu (Google) <[email protected]> --- Changes in v11: - Update trigger-wprobe-btf-typecast.tc to use trace-events-sample kernel module. - Fix commit comment. Changes in v9: - Newly added. --- kernel/trace/trace_probe.c | 13 +++- kernel/trace/trace_probe.h | 5 + tools/testing/selftests/ftrace/config | 1 .../test.d/trigger/trigger-wprobe-btf-typecast.tc | 72 ++++++++++++++++++++ 4 files changed, 90 insertions(+), 1 deletion(-) create mode 100644 tools/testing/selftests/ftrace/test.d/trigger/trigger-wprobe-btf-typecast.tc diff --git a/kernel/trace/trace_probe.c b/kernel/trace/trace_probe.c index 9f4cad18977a..af8fb2a246b6 100644 --- a/kernel/trace/trace_probe.c +++ b/kernel/trace/trace_probe.c @@ -889,6 +889,16 @@ static int query_btf_struct(const char *sname, struct traceprobe_parse_context * ctx->struct_btf = NULL; } + if (ctx->btf) { + id = btf_find_by_name_kind(ctx->btf, sname, BTF_KIND_STRUCT); + if (id > 0) { + btf_get(ctx->btf); + ctx->struct_btf = ctx->btf; + ctx->last_struct = btf_type_by_id(ctx->struct_btf, id); + return 0; + } + } + id = bpf_find_btf_id(sname, BTF_KIND_STRUCT, &btf); if (id < 0) return id; @@ -964,7 +974,8 @@ static int handle_typecast(char *arg, struct traceprobe_parse_context *ctx) if (!(tparg_is_event_probe(ctx->flags) || tparg_is_function_entry(ctx->flags) || - tparg_is_function_return(ctx->flags))) { + tparg_is_function_return(ctx->flags) || + tparg_is_wprobe(ctx->flags))) { trace_probe_log_err(ctx->offset, NOSUP_BTFARG); return -EOPNOTSUPP; } diff --git a/kernel/trace/trace_probe.h b/kernel/trace/trace_probe.h index 6543d4c2cda5..6e927bb0e8dc 100644 --- a/kernel/trace/trace_probe.h +++ b/kernel/trace/trace_probe.h @@ -437,6 +437,11 @@ static inline bool tparg_is_event_probe(unsigned int flags) return !!(flags & TPARG_FL_TEVENT); } +static inline bool tparg_is_wprobe(unsigned int flags) +{ + return !!(flags & TPARG_FL_WPROBE); +} + /* Each typecast consumes nested level. So the max number of typecast is 8. */ #define TRACEPROBE_MAX_NESTED_LEVEL 8 diff --git a/tools/testing/selftests/ftrace/config b/tools/testing/selftests/ftrace/config index ecdee77f360f..f067874902ed 100644 --- a/tools/testing/selftests/ftrace/config +++ b/tools/testing/selftests/ftrace/config @@ -1,5 +1,6 @@ CONFIG_BPF_SYSCALL=y CONFIG_DEBUG_INFO_BTF=y +CONFIG_DEBUG_INFO_BTF_MODULES=y CONFIG_DEBUG_INFO_DWARF4=y CONFIG_EPROBE_EVENTS=y CONFIG_FPROBE=y diff --git a/tools/testing/selftests/ftrace/test.d/trigger/trigger-wprobe-btf-typecast.tc b/tools/testing/selftests/ftrace/test.d/trigger/trigger-wprobe-btf-typecast.tc new file mode 100644 index 000000000000..3f2bebb28837 --- /dev/null +++ b/tools/testing/selftests/ftrace/test.d/trigger/trigger-wprobe-btf-typecast.tc @@ -0,0 +1,72 @@ +#!/bin/sh +# SPDX-License-Identifier: GPL-2.0 +# description: event trigger - test wprobe trigger with BTF typecast fetchargs +# requires: dynamic_events "w[:[<group>/][<event>]] [r|w|rw]@<addr>[:<len>]":README events/sched/sched_process_fork/trigger "[(structname[,field])]<argname>[->field[->field|.field...]]":README + +rmmod trace-events-sample ||: +if ! modprobe trace-events-sample ; then + echo "No trace-events sample module - please make CONFIG_SAMPLE_TRACE_EVENTS=m" + exit_unresolved +fi + +cleanup_wprobe_triggers() { + if [ -f events/fprobes/testevent/trigger ]; then + reset_trigger_file events/fprobes/testevent/trigger || true + fi + echo 0 > events/enable 2>/dev/null || true + echo > dynamic_events 2>/dev/null || true + sleep 1 + rmmod trace-events-sample 2>/dev/null || true + return 0 +} + +trap cleanup_wprobe_triggers EXIT + +echo 0 > tracing_on + +# we will skip this test if fprobe is not supported. +if ! grep -Fq "f[:[<group>/][<event>]] <func-name>[%return] [<args>]" README; then + echo "UNRESOLVED: fprobe is not supported" + exit_unresolved +fi + +# we will skip this test if the target function does not exist. +if ! grep -wq "sample_timer_cb" /proc/kallsyms; then + echo "UNRESOLVED: sample_timer_cb not found" + exit_unresolved +fi + +:;: "Add a wprobe event with BTF typecast fetchargs" ;: +# (foo_timer_data,timer)$addr->counter reads counter from struct foo_timer_data via BTF typecast +echo 'w:watch rw@0:8 address=$addr counter=(foo_timer_data,timer)$addr->counter' >> dynamic_events + +:;: "Check the wprobe event is registered with counter field" ;: +grep -q "counter" dynamic_events + +:;: "Add fprobe event for sample_timer_cb" ;: +echo 'f:fprobes/testevent sample_timer_cb timer=t' >> dynamic_events + +:;: "Enable all events before setting triggers" ;: +echo 1 > tracing_on +echo 1 >> events/fprobes/testevent/enable + +:;: "Set set_wprobe trigger on testevent" ;: +echo 'set_wprobe:watch:timer' >> events/fprobes/testevent/trigger +cat events/fprobes/testevent/trigger | grep ^set_wprobe + +# Wait for sample_timer_cb to fire and set_wprobe trigger to activate +sleep 3 + +:;: "Check set_wprobe trigger activated the watchpoint" ;: +cat trace | grep watch + +:;: "Remove wprobe triggers" ;: +echo '!set_wprobe:watch:timer' >> events/fprobes/testevent/trigger +! grep ^set_wprobe events/fprobes/testevent/trigger + +:;: "Disable events and remove dynamic events" ;: +echo 0 > events/enable +echo > dynamic_events +clear_trace + +exit 0
