[PATCH 2/2] perf trace: Increase TRACE_AUG_MAX_BUF to 128 and document beauty_map encoding

From: Ian Rogers

Date: Fri Oct 02 2026 - 02:55:43 EST


With sockaddr arguments copied as buffers via beauty_map_enter, the
32-byte TRACE_AUG_MAX_BUF limit only held 2 bytes of sa_family plus 30
bytes of AF_LOCAL sun_path, truncating longer socket paths such as
"/var/run/.heim_org.h5l.kcm-socket".

Since struct augmented_arg already reserves PATH_MAX (4096) bytes,
increase TRACE_AUG_MAX_BUF to 128 (SS_MAXSIZE, the size of struct
sockaddr_storage), which covers all 110 bytes of struct sockaddr_un
without changing map sizes. Also document the 1-based negative
-(arg_idx + 1) encoding used in beauty_array for paired length
arguments.

Suggested-by: Arnaldo Carvalho de Melo <acme@xxxxxxxxxx>
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@xxxxxxxxxx>
---
tools/perf/builtin-trace.c | 8 +++++++-
tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c | 8 ++++----
2 files changed, 11 insertions(+), 5 deletions(-)

diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c
index c34c9f129836..4094141461f9 100644
--- a/tools/perf/builtin-trace.c
+++ b/tools/perf/builtin-trace.c
@@ -4174,7 +4174,12 @@ static int trace__bpf_sys_enter_beauty_map(struct trace *trace, int e_machine, i
continue;

bt = sc->arg_fmt[i].type;
- /* Copy a sockaddr as a buffer sized by the next argument, e.g. addrlen. */
+ /*
+ * Copy a sockaddr as a buffer sized by the next
+ * argument (i + 1), e.g. addrlen. A negative entry
+ * -(j + 1) encodes the 0-based length argument index j
+ * as 1-based so arg 0 is -1 rather than 0.
+ */
if (strcmp(name, "sockaddr") == 0 && field->next &&
strstr(field->next->name, "len"))
beauty_array[i] = -((i + 1) + 1);
@@ -4210,6 +4215,7 @@ static int trace__bpf_sys_enter_beauty_map(struct trace *trace, int e_machine, i
strstr(field_tmp->name, "siz") || /* size, bufsiz */
(strstr(field_tmp->name, "len") && strcmp(field_tmp->name, "filename")))) {
/* filename's got 'len' in it, we don't want that */
+ /* 1-based negative index of length arg j. */
beauty_array[i] = -(j + 1);
can_augment = true;
break;
diff --git a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
index 0b2ef9541f84..28ebb9a72776 100644
--- a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
+++ b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
@@ -28,7 +28,7 @@

#define MAX_CPUS 4096

-#define TRACE_AUG_MAX_BUF 32 /* for buffer augmentation in perf trace */
+#define TRACE_AUG_MAX_BUF 128 /* for buffer augmentation in perf trace */

/* bpf-output associated map */
struct __augmented_syscalls__ {
@@ -514,9 +514,9 @@ u64 ZERO = 0;
* value in the beauty_map. This is the relation of parameter type and its corresponding
* value in the beauty map, and how many bytes we read eventually:
*
- * string: 1 -> size of string
- * struct: size of struct -> size of struct
- * buffer: -1 * (index of paired len) -> value of paired len (maximum: TRACE_AUG_MAX_BUF)
+ * string: 1 -> size of string
+ * struct: size of struct -> size of struct
+ * buffer: -(0-based index of paired len + 1) -> value of paired len (maximum: TRACE_AUG_MAX_BUF)
*/
static inline int augment_arg(struct syscall_enter_args *args, int i,
unsigned int *beauty_map,
--
2.56.0.rc1.315.gc6ed9934b7-goog