1 // SPDX-License-Identifier: GPL-2.0-only 2 /* Copyright (c) 2016 Facebook 3 */ 4 #include <linux/bpf.h> 5 #include <linux/jhash.h> 6 #include <linux/filter.h> 7 #include <linux/kernel.h> 8 #include <linux/stacktrace.h> 9 #include <linux/perf_event.h> 10 #include <linux/btf_ids.h> 11 #include <linux/buildid.h> 12 #include "percpu_freelist.h" 13 #include "mmap_unlock_work.h" 14 15 #define STACK_CREATE_FLAG_MASK \ 16 (BPF_F_NUMA_NODE | BPF_F_RDONLY | BPF_F_WRONLY | \ 17 BPF_F_STACK_BUILD_ID) 18 19 struct stack_map_bucket { 20 struct pcpu_freelist_node fnode; 21 u32 hash; 22 u32 nr; 23 u64 data[]; 24 }; 25 26 struct bpf_stack_map { 27 struct bpf_map map; 28 void *elems; 29 struct pcpu_freelist freelist; 30 u32 n_buckets; 31 struct stack_map_bucket *buckets[]; 32 }; 33 34 static inline bool stack_map_use_build_id(struct bpf_map *map) 35 { 36 return (map->map_flags & BPF_F_STACK_BUILD_ID); 37 } 38 39 static inline int stack_map_data_size(struct bpf_map *map) 40 { 41 return stack_map_use_build_id(map) ? 42 sizeof(struct bpf_stack_build_id) : sizeof(u64); 43 } 44 45 static int prealloc_elems_and_freelist(struct bpf_stack_map *smap) 46 { 47 u64 elem_size = sizeof(struct stack_map_bucket) + 48 (u64)smap->map.value_size; 49 int err; 50 51 smap->elems = bpf_map_area_alloc(elem_size * smap->map.max_entries, 52 smap->map.numa_node); 53 if (!smap->elems) 54 return -ENOMEM; 55 56 err = pcpu_freelist_init(&smap->freelist); 57 if (err) 58 goto free_elems; 59 60 pcpu_freelist_populate(&smap->freelist, smap->elems, elem_size, 61 smap->map.max_entries); 62 return 0; 63 64 free_elems: 65 bpf_map_area_free(smap->elems); 66 return err; 67 } 68 69 /* Called from syscall */ 70 static struct bpf_map *stack_map_alloc(union bpf_attr *attr) 71 { 72 u32 value_size = attr->value_size; 73 struct bpf_stack_map *smap; 74 u64 cost, n_buckets; 75 int err; 76 77 if (!bpf_capable()) 78 return ERR_PTR(-EPERM); 79 80 if (attr->map_flags & ~STACK_CREATE_FLAG_MASK) 81 return ERR_PTR(-EINVAL); 82 83 /* check sanity of attributes */ 84 if (attr->max_entries == 0 || attr->key_size != 4 || 85 value_size < 8 || value_size % 8) 86 return ERR_PTR(-EINVAL); 87 88 BUILD_BUG_ON(sizeof(struct bpf_stack_build_id) % sizeof(u64)); 89 if (attr->map_flags & BPF_F_STACK_BUILD_ID) { 90 if (value_size % sizeof(struct bpf_stack_build_id) || 91 value_size / sizeof(struct bpf_stack_build_id) 92 > sysctl_perf_event_max_stack) 93 return ERR_PTR(-EINVAL); 94 } else if (value_size / 8 > sysctl_perf_event_max_stack) 95 return ERR_PTR(-EINVAL); 96 97 /* hash table size must be power of 2 */ 98 n_buckets = roundup_pow_of_two(attr->max_entries); 99 if (!n_buckets) 100 return ERR_PTR(-E2BIG); 101 102 cost = n_buckets * sizeof(struct stack_map_bucket *) + sizeof(*smap); 103 cost += n_buckets * (value_size + sizeof(struct stack_map_bucket)); 104 smap = bpf_map_area_alloc(cost, bpf_map_attr_numa_node(attr)); 105 if (!smap) 106 return ERR_PTR(-ENOMEM); 107 108 bpf_map_init_from_attr(&smap->map, attr); 109 smap->n_buckets = n_buckets; 110 111 err = get_callchain_buffers(sysctl_perf_event_max_stack); 112 if (err) 113 goto free_smap; 114 115 err = prealloc_elems_and_freelist(smap); 116 if (err) 117 goto put_buffers; 118 119 return &smap->map; 120 121 put_buffers: 122 put_callchain_buffers(); 123 free_smap: 124 bpf_map_area_free(smap); 125 return ERR_PTR(err); 126 } 127 128 static void stack_map_get_build_id_offset(struct bpf_stack_build_id *id_offs, 129 u64 *ips, u32 trace_nr, bool user) 130 { 131 int i; 132 struct mmap_unlock_irq_work *work = NULL; 133 bool irq_work_busy = bpf_mmap_unlock_get_irq_work(&work); 134 struct vm_area_struct *vma, *prev_vma = NULL; 135 const char *prev_build_id; 136 137 /* If the irq_work is in use, fall back to report ips. Same 138 * fallback is used for kernel stack (!user) on a stackmap with 139 * build_id. 140 */ 141 if (!user || !current || !current->mm || irq_work_busy || 142 !mmap_read_trylock(current->mm)) { 143 /* cannot access current->mm, fall back to ips */ 144 for (i = 0; i < trace_nr; i++) { 145 id_offs[i].status = BPF_STACK_BUILD_ID_IP; 146 id_offs[i].ip = ips[i]; 147 memset(id_offs[i].build_id, 0, BUILD_ID_SIZE_MAX); 148 } 149 return; 150 } 151 152 for (i = 0; i < trace_nr; i++) { 153 if (range_in_vma(prev_vma, ips[i], ips[i])) { 154 vma = prev_vma; 155 memcpy(id_offs[i].build_id, prev_build_id, 156 BUILD_ID_SIZE_MAX); 157 goto build_id_valid; 158 } 159 vma = find_vma(current->mm, ips[i]); 160 if (!vma || build_id_parse(vma, id_offs[i].build_id, NULL)) { 161 /* per entry fall back to ips */ 162 id_offs[i].status = BPF_STACK_BUILD_ID_IP; 163 id_offs[i].ip = ips[i]; 164 memset(id_offs[i].build_id, 0, BUILD_ID_SIZE_MAX); 165 continue; 166 } 167 build_id_valid: 168 id_offs[i].offset = (vma->vm_pgoff << PAGE_SHIFT) + ips[i] 169 - vma->vm_start; 170 id_offs[i].status = BPF_STACK_BUILD_ID_VALID; 171 prev_vma = vma; 172 prev_build_id = id_offs[i].build_id; 173 } 174 bpf_mmap_unlock_mm(work, current->mm); 175 } 176 177 static struct perf_callchain_entry * 178 get_callchain_entry_for_task(struct task_struct *task, u32 max_depth) 179 { 180 #ifdef CONFIG_STACKTRACE 181 struct perf_callchain_entry *entry; 182 int rctx; 183 184 entry = get_callchain_entry(&rctx); 185 186 if (!entry) 187 return NULL; 188 189 entry->nr = stack_trace_save_tsk(task, (unsigned long *)entry->ip, 190 max_depth, 0); 191 192 /* stack_trace_save_tsk() works on unsigned long array, while 193 * perf_callchain_entry uses u64 array. For 32-bit systems, it is 194 * necessary to fix this mismatch. 195 */ 196 if (__BITS_PER_LONG != 64) { 197 unsigned long *from = (unsigned long *) entry->ip; 198 u64 *to = entry->ip; 199 int i; 200 201 /* copy data from the end to avoid using extra buffer */ 202 for (i = entry->nr - 1; i >= 0; i--) 203 to[i] = (u64)(from[i]); 204 } 205 206 put_callchain_entry(rctx); 207 208 return entry; 209 #else /* CONFIG_STACKTRACE */ 210 return NULL; 211 #endif 212 } 213 214 static long __bpf_get_stackid(struct bpf_map *map, 215 struct perf_callchain_entry *trace, u64 flags) 216 { 217 struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map); 218 struct stack_map_bucket *bucket, *new_bucket, *old_bucket; 219 u32 skip = flags & BPF_F_SKIP_FIELD_MASK; 220 u32 hash, id, trace_nr, trace_len; 221 bool user = flags & BPF_F_USER_STACK; 222 u64 *ips; 223 bool hash_matches; 224 225 if (trace->nr <= skip) 226 /* skipping more than usable stack trace */ 227 return -EFAULT; 228 229 trace_nr = trace->nr - skip; 230 trace_len = trace_nr * sizeof(u64); 231 ips = trace->ip + skip; 232 hash = jhash2((u32 *)ips, trace_len / sizeof(u32), 0); 233 id = hash & (smap->n_buckets - 1); 234 bucket = READ_ONCE(smap->buckets[id]); 235 236 hash_matches = bucket && bucket->hash == hash; 237 /* fast cmp */ 238 if (hash_matches && flags & BPF_F_FAST_STACK_CMP) 239 return id; 240 241 if (stack_map_use_build_id(map)) { 242 /* for build_id+offset, pop a bucket before slow cmp */ 243 new_bucket = (struct stack_map_bucket *) 244 pcpu_freelist_pop(&smap->freelist); 245 if (unlikely(!new_bucket)) 246 return -ENOMEM; 247 new_bucket->nr = trace_nr; 248 stack_map_get_build_id_offset( 249 (struct bpf_stack_build_id *)new_bucket->data, 250 ips, trace_nr, user); 251 trace_len = trace_nr * sizeof(struct bpf_stack_build_id); 252 if (hash_matches && bucket->nr == trace_nr && 253 memcmp(bucket->data, new_bucket->data, trace_len) == 0) { 254 pcpu_freelist_push(&smap->freelist, &new_bucket->fnode); 255 return id; 256 } 257 if (bucket && !(flags & BPF_F_REUSE_STACKID)) { 258 pcpu_freelist_push(&smap->freelist, &new_bucket->fnode); 259 return -EEXIST; 260 } 261 } else { 262 if (hash_matches && bucket->nr == trace_nr && 263 memcmp(bucket->data, ips, trace_len) == 0) 264 return id; 265 if (bucket && !(flags & BPF_F_REUSE_STACKID)) 266 return -EEXIST; 267 268 new_bucket = (struct stack_map_bucket *) 269 pcpu_freelist_pop(&smap->freelist); 270 if (unlikely(!new_bucket)) 271 return -ENOMEM; 272 memcpy(new_bucket->data, ips, trace_len); 273 } 274 275 new_bucket->hash = hash; 276 new_bucket->nr = trace_nr; 277 278 old_bucket = xchg(&smap->buckets[id], new_bucket); 279 if (old_bucket) 280 pcpu_freelist_push(&smap->freelist, &old_bucket->fnode); 281 return id; 282 } 283 284 BPF_CALL_3(bpf_get_stackid, struct pt_regs *, regs, struct bpf_map *, map, 285 u64, flags) 286 { 287 u32 max_depth = map->value_size / stack_map_data_size(map); 288 u32 skip = flags & BPF_F_SKIP_FIELD_MASK; 289 bool user = flags & BPF_F_USER_STACK; 290 struct perf_callchain_entry *trace; 291 bool kernel = !user; 292 293 if (unlikely(flags & ~(BPF_F_SKIP_FIELD_MASK | BPF_F_USER_STACK | 294 BPF_F_FAST_STACK_CMP | BPF_F_REUSE_STACKID))) 295 return -EINVAL; 296 297 max_depth += skip; 298 if (max_depth > sysctl_perf_event_max_stack) 299 max_depth = sysctl_perf_event_max_stack; 300 301 trace = get_perf_callchain(regs, 0, kernel, user, max_depth, 302 false, false); 303 304 if (unlikely(!trace)) 305 /* couldn't fetch the stack trace */ 306 return -EFAULT; 307 308 return __bpf_get_stackid(map, trace, flags); 309 } 310 311 const struct bpf_func_proto bpf_get_stackid_proto = { 312 .func = bpf_get_stackid, 313 .gpl_only = true, 314 .ret_type = RET_INTEGER, 315 .arg1_type = ARG_PTR_TO_CTX, 316 .arg2_type = ARG_CONST_MAP_PTR, 317 .arg3_type = ARG_ANYTHING, 318 }; 319 320 static __u64 count_kernel_ip(struct perf_callchain_entry *trace) 321 { 322 __u64 nr_kernel = 0; 323 324 while (nr_kernel < trace->nr) { 325 if (trace->ip[nr_kernel] == PERF_CONTEXT_USER) 326 break; 327 nr_kernel++; 328 } 329 return nr_kernel; 330 } 331 332 BPF_CALL_3(bpf_get_stackid_pe, struct bpf_perf_event_data_kern *, ctx, 333 struct bpf_map *, map, u64, flags) 334 { 335 struct perf_event *event = ctx->event; 336 struct perf_callchain_entry *trace; 337 bool kernel, user; 338 __u64 nr_kernel; 339 int ret; 340 341 /* perf_sample_data doesn't have callchain, use bpf_get_stackid */ 342 if (!(event->attr.sample_type & __PERF_SAMPLE_CALLCHAIN_EARLY)) 343 return bpf_get_stackid((unsigned long)(ctx->regs), 344 (unsigned long) map, flags, 0, 0); 345 346 if (unlikely(flags & ~(BPF_F_SKIP_FIELD_MASK | BPF_F_USER_STACK | 347 BPF_F_FAST_STACK_CMP | BPF_F_REUSE_STACKID))) 348 return -EINVAL; 349 350 user = flags & BPF_F_USER_STACK; 351 kernel = !user; 352 353 trace = ctx->data->callchain; 354 if (unlikely(!trace)) 355 return -EFAULT; 356 357 nr_kernel = count_kernel_ip(trace); 358 359 if (kernel) { 360 __u64 nr = trace->nr; 361 362 trace->nr = nr_kernel; 363 ret = __bpf_get_stackid(map, trace, flags); 364 365 /* restore nr */ 366 trace->nr = nr; 367 } else { /* user */ 368 u64 skip = flags & BPF_F_SKIP_FIELD_MASK; 369 370 skip += nr_kernel; 371 if (skip > BPF_F_SKIP_FIELD_MASK) 372 return -EFAULT; 373 374 flags = (flags & ~BPF_F_SKIP_FIELD_MASK) | skip; 375 ret = __bpf_get_stackid(map, trace, flags); 376 } 377 return ret; 378 } 379 380 const struct bpf_func_proto bpf_get_stackid_proto_pe = { 381 .func = bpf_get_stackid_pe, 382 .gpl_only = false, 383 .ret_type = RET_INTEGER, 384 .arg1_type = ARG_PTR_TO_CTX, 385 .arg2_type = ARG_CONST_MAP_PTR, 386 .arg3_type = ARG_ANYTHING, 387 }; 388 389 static long __bpf_get_stack(struct pt_regs *regs, struct task_struct *task, 390 struct perf_callchain_entry *trace_in, 391 void *buf, u32 size, u64 flags) 392 { 393 u32 trace_nr, copy_len, elem_size, num_elem, max_depth; 394 bool user_build_id = flags & BPF_F_USER_BUILD_ID; 395 u32 skip = flags & BPF_F_SKIP_FIELD_MASK; 396 bool user = flags & BPF_F_USER_STACK; 397 struct perf_callchain_entry *trace; 398 bool kernel = !user; 399 int err = -EINVAL; 400 u64 *ips; 401 402 if (unlikely(flags & ~(BPF_F_SKIP_FIELD_MASK | BPF_F_USER_STACK | 403 BPF_F_USER_BUILD_ID))) 404 goto clear; 405 if (kernel && user_build_id) 406 goto clear; 407 408 elem_size = (user && user_build_id) ? sizeof(struct bpf_stack_build_id) 409 : sizeof(u64); 410 if (unlikely(size % elem_size)) 411 goto clear; 412 413 /* cannot get valid user stack for task without user_mode regs */ 414 if (task && user && !user_mode(regs)) 415 goto err_fault; 416 417 num_elem = size / elem_size; 418 max_depth = num_elem + skip; 419 if (sysctl_perf_event_max_stack < max_depth) 420 max_depth = sysctl_perf_event_max_stack; 421 422 if (trace_in) 423 trace = trace_in; 424 else if (kernel && task) 425 trace = get_callchain_entry_for_task(task, max_depth); 426 else 427 trace = get_perf_callchain(regs, 0, kernel, user, max_depth, 428 false, false); 429 if (unlikely(!trace)) 430 goto err_fault; 431 432 if (trace->nr < skip) 433 goto err_fault; 434 435 trace_nr = trace->nr - skip; 436 trace_nr = (trace_nr <= num_elem) ? trace_nr : num_elem; 437 copy_len = trace_nr * elem_size; 438 439 ips = trace->ip + skip; 440 if (user && user_build_id) 441 stack_map_get_build_id_offset(buf, ips, trace_nr, user); 442 else 443 memcpy(buf, ips, copy_len); 444 445 if (size > copy_len) 446 memset(buf + copy_len, 0, size - copy_len); 447 return copy_len; 448 449 err_fault: 450 err = -EFAULT; 451 clear: 452 memset(buf, 0, size); 453 return err; 454 } 455 456 BPF_CALL_4(bpf_get_stack, struct pt_regs *, regs, void *, buf, u32, size, 457 u64, flags) 458 { 459 return __bpf_get_stack(regs, NULL, NULL, buf, size, flags); 460 } 461 462 const struct bpf_func_proto bpf_get_stack_proto = { 463 .func = bpf_get_stack, 464 .gpl_only = true, 465 .ret_type = RET_INTEGER, 466 .arg1_type = ARG_PTR_TO_CTX, 467 .arg2_type = ARG_PTR_TO_UNINIT_MEM, 468 .arg3_type = ARG_CONST_SIZE_OR_ZERO, 469 .arg4_type = ARG_ANYTHING, 470 }; 471 472 BPF_CALL_4(bpf_get_task_stack, struct task_struct *, task, void *, buf, 473 u32, size, u64, flags) 474 { 475 struct pt_regs *regs; 476 long res = -EINVAL; 477 478 if (!try_get_task_stack(task)) 479 return -EFAULT; 480 481 regs = task_pt_regs(task); 482 if (regs) 483 res = __bpf_get_stack(regs, task, NULL, buf, size, flags); 484 put_task_stack(task); 485 486 return res; 487 } 488 489 const struct bpf_func_proto bpf_get_task_stack_proto = { 490 .func = bpf_get_task_stack, 491 .gpl_only = false, 492 .ret_type = RET_INTEGER, 493 .arg1_type = ARG_PTR_TO_BTF_ID, 494 .arg1_btf_id = &btf_tracing_ids[BTF_TRACING_TYPE_TASK], 495 .arg2_type = ARG_PTR_TO_UNINIT_MEM, 496 .arg3_type = ARG_CONST_SIZE_OR_ZERO, 497 .arg4_type = ARG_ANYTHING, 498 }; 499 500 BPF_CALL_4(bpf_get_stack_pe, struct bpf_perf_event_data_kern *, ctx, 501 void *, buf, u32, size, u64, flags) 502 { 503 struct pt_regs *regs = (struct pt_regs *)(ctx->regs); 504 struct perf_event *event = ctx->event; 505 struct perf_callchain_entry *trace; 506 bool kernel, user; 507 int err = -EINVAL; 508 __u64 nr_kernel; 509 510 if (!(event->attr.sample_type & __PERF_SAMPLE_CALLCHAIN_EARLY)) 511 return __bpf_get_stack(regs, NULL, NULL, buf, size, flags); 512 513 if (unlikely(flags & ~(BPF_F_SKIP_FIELD_MASK | BPF_F_USER_STACK | 514 BPF_F_USER_BUILD_ID))) 515 goto clear; 516 517 user = flags & BPF_F_USER_STACK; 518 kernel = !user; 519 520 err = -EFAULT; 521 trace = ctx->data->callchain; 522 if (unlikely(!trace)) 523 goto clear; 524 525 nr_kernel = count_kernel_ip(trace); 526 527 if (kernel) { 528 __u64 nr = trace->nr; 529 530 trace->nr = nr_kernel; 531 err = __bpf_get_stack(regs, NULL, trace, buf, size, flags); 532 533 /* restore nr */ 534 trace->nr = nr; 535 } else { /* user */ 536 u64 skip = flags & BPF_F_SKIP_FIELD_MASK; 537 538 skip += nr_kernel; 539 if (skip > BPF_F_SKIP_FIELD_MASK) 540 goto clear; 541 542 flags = (flags & ~BPF_F_SKIP_FIELD_MASK) | skip; 543 err = __bpf_get_stack(regs, NULL, trace, buf, size, flags); 544 } 545 return err; 546 547 clear: 548 memset(buf, 0, size); 549 return err; 550 551 } 552 553 const struct bpf_func_proto bpf_get_stack_proto_pe = { 554 .func = bpf_get_stack_pe, 555 .gpl_only = true, 556 .ret_type = RET_INTEGER, 557 .arg1_type = ARG_PTR_TO_CTX, 558 .arg2_type = ARG_PTR_TO_UNINIT_MEM, 559 .arg3_type = ARG_CONST_SIZE_OR_ZERO, 560 .arg4_type = ARG_ANYTHING, 561 }; 562 563 /* Called from eBPF program */ 564 static void *stack_map_lookup_elem(struct bpf_map *map, void *key) 565 { 566 return ERR_PTR(-EOPNOTSUPP); 567 } 568 569 /* Called from syscall */ 570 int bpf_stackmap_copy(struct bpf_map *map, void *key, void *value) 571 { 572 struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map); 573 struct stack_map_bucket *bucket, *old_bucket; 574 u32 id = *(u32 *)key, trace_len; 575 576 if (unlikely(id >= smap->n_buckets)) 577 return -ENOENT; 578 579 bucket = xchg(&smap->buckets[id], NULL); 580 if (!bucket) 581 return -ENOENT; 582 583 trace_len = bucket->nr * stack_map_data_size(map); 584 memcpy(value, bucket->data, trace_len); 585 memset(value + trace_len, 0, map->value_size - trace_len); 586 587 old_bucket = xchg(&smap->buckets[id], bucket); 588 if (old_bucket) 589 pcpu_freelist_push(&smap->freelist, &old_bucket->fnode); 590 return 0; 591 } 592 593 static int stack_map_get_next_key(struct bpf_map *map, void *key, 594 void *next_key) 595 { 596 struct bpf_stack_map *smap = container_of(map, 597 struct bpf_stack_map, map); 598 u32 id; 599 600 WARN_ON_ONCE(!rcu_read_lock_held()); 601 602 if (!key) { 603 id = 0; 604 } else { 605 id = *(u32 *)key; 606 if (id >= smap->n_buckets || !smap->buckets[id]) 607 id = 0; 608 else 609 id++; 610 } 611 612 while (id < smap->n_buckets && !smap->buckets[id]) 613 id++; 614 615 if (id >= smap->n_buckets) 616 return -ENOENT; 617 618 *(u32 *)next_key = id; 619 return 0; 620 } 621 622 static int stack_map_update_elem(struct bpf_map *map, void *key, void *value, 623 u64 map_flags) 624 { 625 return -EINVAL; 626 } 627 628 /* Called from syscall or from eBPF program */ 629 static int stack_map_delete_elem(struct bpf_map *map, void *key) 630 { 631 struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map); 632 struct stack_map_bucket *old_bucket; 633 u32 id = *(u32 *)key; 634 635 if (unlikely(id >= smap->n_buckets)) 636 return -E2BIG; 637 638 old_bucket = xchg(&smap->buckets[id], NULL); 639 if (old_bucket) { 640 pcpu_freelist_push(&smap->freelist, &old_bucket->fnode); 641 return 0; 642 } else { 643 return -ENOENT; 644 } 645 } 646 647 /* Called when map->refcnt goes to zero, either from workqueue or from syscall */ 648 static void stack_map_free(struct bpf_map *map) 649 { 650 struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map); 651 652 bpf_map_area_free(smap->elems); 653 pcpu_freelist_destroy(&smap->freelist); 654 bpf_map_area_free(smap); 655 put_callchain_buffers(); 656 } 657 658 static int stack_trace_map_btf_id; 659 const struct bpf_map_ops stack_trace_map_ops = { 660 .map_meta_equal = bpf_map_meta_equal, 661 .map_alloc = stack_map_alloc, 662 .map_free = stack_map_free, 663 .map_get_next_key = stack_map_get_next_key, 664 .map_lookup_elem = stack_map_lookup_elem, 665 .map_update_elem = stack_map_update_elem, 666 .map_delete_elem = stack_map_delete_elem, 667 .map_check_btf = map_check_no_btf, 668 .map_btf_name = "bpf_stack_map", 669 .map_btf_id = &stack_trace_map_btf_id, 670 }; 671