1 // SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause)
4 * common eBPF ELF operations.
8 * Copyright (C) 2015 Huawei Inc.
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU Lesser General Public
12 * License as published by the Free Software Foundation;
13 * version 2.1 of the License (not later!)
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU Lesser General Public License for more details.
20 * You should have received a copy of the GNU Lesser General Public
21 * License along with this program; if not, see <http://www.gnu.org/licenses>
27 #include <asm/unistd.h>
28 #include <linux/bpf.h>
34 * When building perf, unistd.h is overridden. __NR_bpf is
35 * required to be defined explicitly.
38 # if defined(__i386__)
40 # elif defined(__x86_64__)
42 # elif defined(__aarch64__)
44 # elif defined(__sparc__)
46 # elif defined(__s390__)
49 # error __NR_bpf not defined. libbpf does not support your arch.
54 #define min(x, y) ((x) < (y) ? (x) : (y))
57 static inline __u64 ptr_to_u64(const void *ptr)
59 return (__u64) (unsigned long) ptr;
62 static inline int sys_bpf(enum bpf_cmd cmd, union bpf_attr *attr,
65 return syscall(__NR_bpf, cmd, attr, size);
68 int bpf_create_map_xattr(const struct bpf_create_map_attr *create_attr)
70 __u32 name_len = create_attr->name ? strlen(create_attr->name) : 0;
73 memset(&attr, '\0', sizeof(attr));
75 attr.map_type = create_attr->map_type;
76 attr.key_size = create_attr->key_size;
77 attr.value_size = create_attr->value_size;
78 attr.max_entries = create_attr->max_entries;
79 attr.map_flags = create_attr->map_flags;
80 memcpy(attr.map_name, create_attr->name,
81 min(name_len, BPF_OBJ_NAME_LEN - 1));
82 attr.numa_node = create_attr->numa_node;
83 attr.btf_fd = create_attr->btf_fd;
84 attr.btf_key_type_id = create_attr->btf_key_type_id;
85 attr.btf_value_type_id = create_attr->btf_value_type_id;
86 attr.map_ifindex = create_attr->map_ifindex;
87 attr.inner_map_fd = create_attr->inner_map_fd;
89 return sys_bpf(BPF_MAP_CREATE, &attr, sizeof(attr));
92 int bpf_create_map_node(enum bpf_map_type map_type, const char *name,
93 int key_size, int value_size, int max_entries,
94 __u32 map_flags, int node)
96 struct bpf_create_map_attr map_attr = {};
99 map_attr.map_type = map_type;
100 map_attr.map_flags = map_flags;
101 map_attr.key_size = key_size;
102 map_attr.value_size = value_size;
103 map_attr.max_entries = max_entries;
105 map_attr.numa_node = node;
106 map_attr.map_flags |= BPF_F_NUMA_NODE;
109 return bpf_create_map_xattr(&map_attr);
112 int bpf_create_map(enum bpf_map_type map_type, int key_size,
113 int value_size, int max_entries, __u32 map_flags)
115 struct bpf_create_map_attr map_attr = {};
117 map_attr.map_type = map_type;
118 map_attr.map_flags = map_flags;
119 map_attr.key_size = key_size;
120 map_attr.value_size = value_size;
121 map_attr.max_entries = max_entries;
123 return bpf_create_map_xattr(&map_attr);
126 int bpf_create_map_name(enum bpf_map_type map_type, const char *name,
127 int key_size, int value_size, int max_entries,
130 struct bpf_create_map_attr map_attr = {};
132 map_attr.name = name;
133 map_attr.map_type = map_type;
134 map_attr.map_flags = map_flags;
135 map_attr.key_size = key_size;
136 map_attr.value_size = value_size;
137 map_attr.max_entries = max_entries;
139 return bpf_create_map_xattr(&map_attr);
142 int bpf_create_map_in_map_node(enum bpf_map_type map_type, const char *name,
143 int key_size, int inner_map_fd, int max_entries,
144 __u32 map_flags, int node)
146 __u32 name_len = name ? strlen(name) : 0;
149 memset(&attr, '\0', sizeof(attr));
151 attr.map_type = map_type;
152 attr.key_size = key_size;
154 attr.inner_map_fd = inner_map_fd;
155 attr.max_entries = max_entries;
156 attr.map_flags = map_flags;
157 memcpy(attr.map_name, name, min(name_len, BPF_OBJ_NAME_LEN - 1));
160 attr.map_flags |= BPF_F_NUMA_NODE;
161 attr.numa_node = node;
164 return sys_bpf(BPF_MAP_CREATE, &attr, sizeof(attr));
167 int bpf_create_map_in_map(enum bpf_map_type map_type, const char *name,
168 int key_size, int inner_map_fd, int max_entries,
171 return bpf_create_map_in_map_node(map_type, name, key_size,
172 inner_map_fd, max_entries, map_flags,
177 alloc_zero_tailing_info(const void *orecord, __u32 cnt,
178 __u32 actual_rec_size, __u32 expected_rec_size)
180 __u64 info_len = actual_rec_size * cnt;
181 void *info, *nrecord;
184 info = malloc(info_len);
188 /* zero out bytes kernel does not understand */
190 for (i = 0; i < cnt; i++) {
191 memcpy(nrecord, orecord, expected_rec_size);
192 memset(nrecord + expected_rec_size, 0,
193 actual_rec_size - expected_rec_size);
194 orecord += actual_rec_size;
195 nrecord += actual_rec_size;
201 int bpf_load_program_xattr(const struct bpf_load_program_attr *load_attr,
202 char *log_buf, size_t log_buf_sz)
204 void *finfo = NULL, *linfo = NULL;
212 name_len = load_attr->name ? strlen(load_attr->name) : 0;
214 bzero(&attr, sizeof(attr));
215 attr.prog_type = load_attr->prog_type;
216 attr.expected_attach_type = load_attr->expected_attach_type;
217 attr.insn_cnt = (__u32)load_attr->insns_cnt;
218 attr.insns = ptr_to_u64(load_attr->insns);
219 attr.license = ptr_to_u64(load_attr->license);
220 attr.log_buf = ptr_to_u64(NULL);
223 attr.kern_version = load_attr->kern_version;
224 attr.prog_ifindex = load_attr->prog_ifindex;
225 attr.prog_btf_fd = load_attr->prog_btf_fd;
226 attr.func_info_rec_size = load_attr->func_info_rec_size;
227 attr.func_info_cnt = load_attr->func_info_cnt;
228 attr.func_info = ptr_to_u64(load_attr->func_info);
229 attr.line_info_rec_size = load_attr->line_info_rec_size;
230 attr.line_info_cnt = load_attr->line_info_cnt;
231 attr.line_info = ptr_to_u64(load_attr->line_info);
232 memcpy(attr.prog_name, load_attr->name,
233 min(name_len, BPF_OBJ_NAME_LEN - 1));
235 fd = sys_bpf(BPF_PROG_LOAD, &attr, sizeof(attr));
239 /* After bpf_prog_load, the kernel may modify certain attributes
240 * to give user space a hint how to deal with loading failure.
241 * Check to see whether we can make some changes and load again.
243 while (errno == E2BIG && (!finfo || !linfo)) {
244 if (!finfo && attr.func_info_cnt &&
245 attr.func_info_rec_size < load_attr->func_info_rec_size) {
246 /* try with corrected func info records */
247 finfo = alloc_zero_tailing_info(load_attr->func_info,
248 load_attr->func_info_cnt,
249 load_attr->func_info_rec_size,
250 attr.func_info_rec_size);
254 attr.func_info = ptr_to_u64(finfo);
255 attr.func_info_rec_size = load_attr->func_info_rec_size;
256 } else if (!linfo && attr.line_info_cnt &&
257 attr.line_info_rec_size <
258 load_attr->line_info_rec_size) {
259 linfo = alloc_zero_tailing_info(load_attr->line_info,
260 load_attr->line_info_cnt,
261 load_attr->line_info_rec_size,
262 attr.line_info_rec_size);
266 attr.line_info = ptr_to_u64(linfo);
267 attr.line_info_rec_size = load_attr->line_info_rec_size;
272 fd = sys_bpf(BPF_PROG_LOAD, &attr, sizeof(attr));
278 if (!log_buf || !log_buf_sz)
281 /* Try again with log */
282 attr.log_buf = ptr_to_u64(log_buf);
283 attr.log_size = log_buf_sz;
286 fd = sys_bpf(BPF_PROG_LOAD, &attr, sizeof(attr));
293 int bpf_load_program(enum bpf_prog_type type, const struct bpf_insn *insns,
294 size_t insns_cnt, const char *license,
295 __u32 kern_version, char *log_buf,
298 struct bpf_load_program_attr load_attr;
300 memset(&load_attr, 0, sizeof(struct bpf_load_program_attr));
301 load_attr.prog_type = type;
302 load_attr.expected_attach_type = 0;
303 load_attr.name = NULL;
304 load_attr.insns = insns;
305 load_attr.insns_cnt = insns_cnt;
306 load_attr.license = license;
307 load_attr.kern_version = kern_version;
309 return bpf_load_program_xattr(&load_attr, log_buf, log_buf_sz);
312 int bpf_verify_program(enum bpf_prog_type type, const struct bpf_insn *insns,
313 size_t insns_cnt, __u32 prog_flags, const char *license,
314 __u32 kern_version, char *log_buf, size_t log_buf_sz,
319 bzero(&attr, sizeof(attr));
320 attr.prog_type = type;
321 attr.insn_cnt = (__u32)insns_cnt;
322 attr.insns = ptr_to_u64(insns);
323 attr.license = ptr_to_u64(license);
324 attr.log_buf = ptr_to_u64(log_buf);
325 attr.log_size = log_buf_sz;
326 attr.log_level = log_level;
328 attr.kern_version = kern_version;
329 attr.prog_flags = prog_flags;
331 return sys_bpf(BPF_PROG_LOAD, &attr, sizeof(attr));
334 int bpf_map_update_elem(int fd, const void *key, const void *value,
339 bzero(&attr, sizeof(attr));
341 attr.key = ptr_to_u64(key);
342 attr.value = ptr_to_u64(value);
345 return sys_bpf(BPF_MAP_UPDATE_ELEM, &attr, sizeof(attr));
348 int bpf_map_lookup_elem(int fd, const void *key, void *value)
352 bzero(&attr, sizeof(attr));
354 attr.key = ptr_to_u64(key);
355 attr.value = ptr_to_u64(value);
357 return sys_bpf(BPF_MAP_LOOKUP_ELEM, &attr, sizeof(attr));
360 int bpf_map_lookup_and_delete_elem(int fd, const void *key, void *value)
364 bzero(&attr, sizeof(attr));
366 attr.key = ptr_to_u64(key);
367 attr.value = ptr_to_u64(value);
369 return sys_bpf(BPF_MAP_LOOKUP_AND_DELETE_ELEM, &attr, sizeof(attr));
372 int bpf_map_delete_elem(int fd, const void *key)
376 bzero(&attr, sizeof(attr));
378 attr.key = ptr_to_u64(key);
380 return sys_bpf(BPF_MAP_DELETE_ELEM, &attr, sizeof(attr));
383 int bpf_map_get_next_key(int fd, const void *key, void *next_key)
387 bzero(&attr, sizeof(attr));
389 attr.key = ptr_to_u64(key);
390 attr.next_key = ptr_to_u64(next_key);
392 return sys_bpf(BPF_MAP_GET_NEXT_KEY, &attr, sizeof(attr));
395 int bpf_obj_pin(int fd, const char *pathname)
399 bzero(&attr, sizeof(attr));
400 attr.pathname = ptr_to_u64((void *)pathname);
403 return sys_bpf(BPF_OBJ_PIN, &attr, sizeof(attr));
406 int bpf_obj_get(const char *pathname)
410 bzero(&attr, sizeof(attr));
411 attr.pathname = ptr_to_u64((void *)pathname);
413 return sys_bpf(BPF_OBJ_GET, &attr, sizeof(attr));
416 int bpf_prog_attach(int prog_fd, int target_fd, enum bpf_attach_type type,
421 bzero(&attr, sizeof(attr));
422 attr.target_fd = target_fd;
423 attr.attach_bpf_fd = prog_fd;
424 attr.attach_type = type;
425 attr.attach_flags = flags;
427 return sys_bpf(BPF_PROG_ATTACH, &attr, sizeof(attr));
430 int bpf_prog_detach(int target_fd, enum bpf_attach_type type)
434 bzero(&attr, sizeof(attr));
435 attr.target_fd = target_fd;
436 attr.attach_type = type;
438 return sys_bpf(BPF_PROG_DETACH, &attr, sizeof(attr));
441 int bpf_prog_detach2(int prog_fd, int target_fd, enum bpf_attach_type type)
445 bzero(&attr, sizeof(attr));
446 attr.target_fd = target_fd;
447 attr.attach_bpf_fd = prog_fd;
448 attr.attach_type = type;
450 return sys_bpf(BPF_PROG_DETACH, &attr, sizeof(attr));
453 int bpf_prog_query(int target_fd, enum bpf_attach_type type, __u32 query_flags,
454 __u32 *attach_flags, __u32 *prog_ids, __u32 *prog_cnt)
459 bzero(&attr, sizeof(attr));
460 attr.query.target_fd = target_fd;
461 attr.query.attach_type = type;
462 attr.query.query_flags = query_flags;
463 attr.query.prog_cnt = *prog_cnt;
464 attr.query.prog_ids = ptr_to_u64(prog_ids);
466 ret = sys_bpf(BPF_PROG_QUERY, &attr, sizeof(attr));
468 *attach_flags = attr.query.attach_flags;
469 *prog_cnt = attr.query.prog_cnt;
473 int bpf_prog_test_run(int prog_fd, int repeat, void *data, __u32 size,
474 void *data_out, __u32 *size_out, __u32 *retval,
480 bzero(&attr, sizeof(attr));
481 attr.test.prog_fd = prog_fd;
482 attr.test.data_in = ptr_to_u64(data);
483 attr.test.data_out = ptr_to_u64(data_out);
484 attr.test.data_size_in = size;
485 attr.test.repeat = repeat;
487 ret = sys_bpf(BPF_PROG_TEST_RUN, &attr, sizeof(attr));
489 *size_out = attr.test.data_size_out;
491 *retval = attr.test.retval;
493 *duration = attr.test.duration;
497 int bpf_prog_test_run_xattr(struct bpf_prog_test_run_attr *test_attr)
502 if (!test_attr->data_out && test_attr->data_size_out > 0)
505 bzero(&attr, sizeof(attr));
506 attr.test.prog_fd = test_attr->prog_fd;
507 attr.test.data_in = ptr_to_u64(test_attr->data_in);
508 attr.test.data_out = ptr_to_u64(test_attr->data_out);
509 attr.test.data_size_in = test_attr->data_size_in;
510 attr.test.data_size_out = test_attr->data_size_out;
511 attr.test.repeat = test_attr->repeat;
513 ret = sys_bpf(BPF_PROG_TEST_RUN, &attr, sizeof(attr));
514 test_attr->data_size_out = attr.test.data_size_out;
515 test_attr->retval = attr.test.retval;
516 test_attr->duration = attr.test.duration;
520 int bpf_prog_get_next_id(__u32 start_id, __u32 *next_id)
525 bzero(&attr, sizeof(attr));
526 attr.start_id = start_id;
528 err = sys_bpf(BPF_PROG_GET_NEXT_ID, &attr, sizeof(attr));
530 *next_id = attr.next_id;
535 int bpf_map_get_next_id(__u32 start_id, __u32 *next_id)
540 bzero(&attr, sizeof(attr));
541 attr.start_id = start_id;
543 err = sys_bpf(BPF_MAP_GET_NEXT_ID, &attr, sizeof(attr));
545 *next_id = attr.next_id;
550 int bpf_prog_get_fd_by_id(__u32 id)
554 bzero(&attr, sizeof(attr));
557 return sys_bpf(BPF_PROG_GET_FD_BY_ID, &attr, sizeof(attr));
560 int bpf_map_get_fd_by_id(__u32 id)
564 bzero(&attr, sizeof(attr));
567 return sys_bpf(BPF_MAP_GET_FD_BY_ID, &attr, sizeof(attr));
570 int bpf_btf_get_fd_by_id(__u32 id)
574 bzero(&attr, sizeof(attr));
577 return sys_bpf(BPF_BTF_GET_FD_BY_ID, &attr, sizeof(attr));
580 int bpf_obj_get_info_by_fd(int prog_fd, void *info, __u32 *info_len)
585 bzero(&attr, sizeof(attr));
586 attr.info.bpf_fd = prog_fd;
587 attr.info.info_len = *info_len;
588 attr.info.info = ptr_to_u64(info);
590 err = sys_bpf(BPF_OBJ_GET_INFO_BY_FD, &attr, sizeof(attr));
592 *info_len = attr.info.info_len;
597 int bpf_raw_tracepoint_open(const char *name, int prog_fd)
601 bzero(&attr, sizeof(attr));
602 attr.raw_tracepoint.name = ptr_to_u64(name);
603 attr.raw_tracepoint.prog_fd = prog_fd;
605 return sys_bpf(BPF_RAW_TRACEPOINT_OPEN, &attr, sizeof(attr));
608 int bpf_load_btf(void *btf, __u32 btf_size, char *log_buf, __u32 log_buf_size,
611 union bpf_attr attr = {};
614 attr.btf = ptr_to_u64(btf);
615 attr.btf_size = btf_size;
618 if (do_log && log_buf && log_buf_size) {
619 attr.btf_log_level = 1;
620 attr.btf_log_size = log_buf_size;
621 attr.btf_log_buf = ptr_to_u64(log_buf);
624 fd = sys_bpf(BPF_BTF_LOAD, &attr, sizeof(attr));
625 if (fd == -1 && !do_log && log_buf && log_buf_size) {
633 int bpf_task_fd_query(int pid, int fd, __u32 flags, char *buf, __u32 *buf_len,
634 __u32 *prog_id, __u32 *fd_type, __u64 *probe_offset,
637 union bpf_attr attr = {};
640 attr.task_fd_query.pid = pid;
641 attr.task_fd_query.fd = fd;
642 attr.task_fd_query.flags = flags;
643 attr.task_fd_query.buf = ptr_to_u64(buf);
644 attr.task_fd_query.buf_len = *buf_len;
646 err = sys_bpf(BPF_TASK_FD_QUERY, &attr, sizeof(attr));
647 *buf_len = attr.task_fd_query.buf_len;
648 *prog_id = attr.task_fd_query.prog_id;
649 *fd_type = attr.task_fd_query.fd_type;
650 *probe_offset = attr.task_fd_query.probe_offset;
651 *probe_addr = attr.task_fd_query.probe_addr;