Coverage Report

Created: 2026-05-16 06:03

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libbpf/src/gen_loader.c
Line
Count
Source
1
// SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause)
2
/* Copyright (c) 2021 Facebook */
3
#include <stdio.h>
4
#include <stdlib.h>
5
#include <string.h>
6
#include <errno.h>
7
#include <asm/byteorder.h>
8
#include <linux/filter.h>
9
#include <sys/param.h>
10
#include "btf.h"
11
#include "bpf.h"
12
#include "libbpf.h"
13
#include "libbpf_internal.h"
14
#include "hashmap.h"
15
#include "bpf_gen_internal.h"
16
#include "skel_internal.h"
17
18
0
#define MAX_USED_MAPS 64
19
#define MAX_USED_PROGS  32
20
0
#define MAX_KFUNC_DESCS 256
21
0
#define MAX_FD_ARRAY_SZ (MAX_USED_MAPS + MAX_KFUNC_DESCS)
22
23
/* The following structure describes the stack layout of the loader program.
24
 * In addition R6 contains the pointer to context.
25
 * R7 contains the result of the last sys_bpf command (typically error or FD).
26
 * R9 contains the result of the last sys_close command.
27
 *
28
 * Naming convention:
29
 * ctx - bpf program context
30
 * stack - bpf program stack
31
 * blob - bpf_attr-s, strings, insns, map data.
32
 *        All the bytes that loader prog will use for read/write.
33
 */
34
struct loader_stack {
35
  __u32 btf_fd;
36
  __u32 inner_map_fd;
37
  __u32 prog_fd[MAX_USED_PROGS];
38
};
39
40
#define stack_off(field) \
41
0
  (__s16)(-sizeof(struct loader_stack) + offsetof(struct loader_stack, field))
42
43
0
#define attr_field(attr, field) (attr + offsetof(union bpf_attr, field))
44
45
static int blob_fd_array_off(struct bpf_gen *gen, int index)
46
0
{
47
0
  return gen->fd_array + index * sizeof(int);
48
0
}
49
50
static int realloc_insn_buf(struct bpf_gen *gen, __u32 size)
51
0
{
52
0
  size_t off = gen->insn_cur - gen->insn_start;
53
0
  void *insn_start;
54
55
0
  if (gen->error)
56
0
    return gen->error;
57
0
  if (size > INT32_MAX || off + size > INT32_MAX) {
58
0
    gen->error = -ERANGE;
59
0
    return -ERANGE;
60
0
  }
61
0
  insn_start = realloc(gen->insn_start, off + size);
62
0
  if (!insn_start) {
63
0
    gen->error = -ENOMEM;
64
0
    free(gen->insn_start);
65
0
    gen->insn_start = NULL;
66
0
    return -ENOMEM;
67
0
  }
68
0
  gen->insn_start = insn_start;
69
0
  gen->insn_cur = insn_start + off;
70
0
  return 0;
71
0
}
72
73
static int realloc_data_buf(struct bpf_gen *gen, __u32 size)
74
0
{
75
0
  size_t off = gen->data_cur - gen->data_start;
76
0
  void *data_start;
77
78
0
  if (gen->error)
79
0
    return gen->error;
80
0
  if (size > INT32_MAX || off + size > INT32_MAX) {
81
0
    gen->error = -ERANGE;
82
0
    return -ERANGE;
83
0
  }
84
0
  data_start = realloc(gen->data_start, off + size);
85
0
  if (!data_start) {
86
0
    gen->error = -ENOMEM;
87
0
    free(gen->data_start);
88
0
    gen->data_start = NULL;
89
0
    return -ENOMEM;
90
0
  }
91
0
  gen->data_start = data_start;
92
0
  gen->data_cur = data_start + off;
93
0
  return 0;
94
0
}
95
96
static void emit(struct bpf_gen *gen, struct bpf_insn insn)
97
0
{
98
0
  if (realloc_insn_buf(gen, sizeof(insn)))
99
0
    return;
100
0
  memcpy(gen->insn_cur, &insn, sizeof(insn));
101
0
  gen->insn_cur += sizeof(insn);
102
0
}
103
104
static void emit2(struct bpf_gen *gen, struct bpf_insn insn1, struct bpf_insn insn2)
105
0
{
106
0
  emit(gen, insn1);
107
0
  emit(gen, insn2);
108
0
}
109
110
static int add_data(struct bpf_gen *gen, const void *data, __u32 size);
111
static void emit_sys_close_blob(struct bpf_gen *gen, int blob_off);
112
static void emit_signature_match(struct bpf_gen *gen);
113
114
void bpf_gen__init(struct bpf_gen *gen, int log_level, int nr_progs, int nr_maps)
115
0
{
116
0
  size_t stack_sz = sizeof(struct loader_stack), nr_progs_sz;
117
0
  int i;
118
119
0
  gen->fd_array = add_data(gen, NULL, MAX_FD_ARRAY_SZ * sizeof(int));
120
0
  gen->log_level = log_level;
121
  /* save ctx pointer into R6 */
122
0
  emit(gen, BPF_MOV64_REG(BPF_REG_6, BPF_REG_1));
123
124
  /* bzero stack */
125
0
  emit(gen, BPF_MOV64_REG(BPF_REG_1, BPF_REG_10));
126
0
  emit(gen, BPF_ALU64_IMM(BPF_ADD, BPF_REG_1, -stack_sz));
127
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_2, stack_sz));
128
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_3, 0));
129
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel));
130
131
  /* amount of stack actually used, only used to calculate iterations, not stack offset */
132
0
  nr_progs_sz = offsetof(struct loader_stack, prog_fd[nr_progs]);
133
  /* jump over cleanup code */
134
0
  emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0,
135
            /* size of cleanup code below (including map fd cleanup) */
136
0
            (nr_progs_sz / 4) * 3 + 2 +
137
            /* 6 insns for emit_sys_close_blob,
138
             * 6 insns for debug_regs in emit_sys_close_blob
139
             */
140
0
            nr_maps * (6 + (gen->log_level ? 6 : 0))));
141
142
  /* remember the label where all error branches will jump to */
143
0
  gen->cleanup_label = gen->insn_cur - gen->insn_start;
144
  /* emit cleanup code: close all temp FDs */
145
0
  for (i = 0; i < nr_progs_sz; i += 4) {
146
0
    emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_1, BPF_REG_10, -stack_sz + i));
147
0
    emit(gen, BPF_JMP_IMM(BPF_JSLE, BPF_REG_1, 0, 1));
148
0
    emit(gen, BPF_EMIT_CALL(BPF_FUNC_sys_close));
149
0
  }
150
0
  for (i = 0; i < nr_maps; i++)
151
0
    emit_sys_close_blob(gen, blob_fd_array_off(gen, i));
152
  /* R7 contains the error code from sys_bpf. Copy it into R0 and exit. */
153
0
  emit(gen, BPF_MOV64_REG(BPF_REG_0, BPF_REG_7));
154
0
  emit(gen, BPF_EXIT_INSN());
155
0
  if (OPTS_GET(gen->opts, gen_hash, false))
156
0
    emit_signature_match(gen);
157
0
}
158
159
static int add_data(struct bpf_gen *gen, const void *data, __u32 size)
160
0
{
161
0
  __u32 size8 = roundup(size, 8);
162
0
  __u64 zero = 0;
163
0
  void *prev;
164
165
0
  if (realloc_data_buf(gen, size8))
166
0
    return 0;
167
0
  prev = gen->data_cur;
168
0
  if (data) {
169
0
    memcpy(gen->data_cur, data, size);
170
0
    memcpy(gen->data_cur + size, &zero, size8 - size);
171
0
  } else {
172
0
    memset(gen->data_cur, 0, size8);
173
0
  }
174
0
  gen->data_cur += size8;
175
0
  return prev - gen->data_start;
176
0
}
177
178
/* Get index for map_fd/btf_fd slot in reserved fd_array, or in data relative
179
 * to start of fd_array. Caller can decide if it is usable or not.
180
 */
181
static int add_map_fd(struct bpf_gen *gen)
182
0
{
183
0
  if (gen->nr_maps == MAX_USED_MAPS) {
184
0
    pr_warn("Total maps exceeds %d\n", MAX_USED_MAPS);
185
0
    gen->error = -E2BIG;
186
0
    return 0;
187
0
  }
188
0
  return gen->nr_maps++;
189
0
}
190
191
static int add_kfunc_btf_fd(struct bpf_gen *gen)
192
0
{
193
0
  int cur;
194
195
0
  if (gen->nr_fd_array == MAX_KFUNC_DESCS) {
196
0
    cur = add_data(gen, NULL, sizeof(int));
197
0
    return (cur - gen->fd_array) / sizeof(int);
198
0
  }
199
0
  return MAX_USED_MAPS + gen->nr_fd_array++;
200
0
}
201
202
static int insn_bytes_to_bpf_size(__u32 sz)
203
0
{
204
0
  switch (sz) {
205
0
  case 8: return BPF_DW;
206
0
  case 4: return BPF_W;
207
0
  case 2: return BPF_H;
208
0
  case 1: return BPF_B;
209
0
  default: return -1;
210
0
  }
211
0
}
212
213
/* *(u64 *)(blob + off) = (u64)(void *)(blob + data) */
214
static void emit_rel_store(struct bpf_gen *gen, int off, int data)
215
0
{
216
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE,
217
0
           0, 0, 0, data));
218
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
219
0
           0, 0, 0, off));
220
0
  emit(gen, BPF_STX_MEM(BPF_DW, BPF_REG_1, BPF_REG_0, 0));
221
0
}
222
223
static void move_blob2blob(struct bpf_gen *gen, int off, int size, int blob_off)
224
0
{
225
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_2, BPF_PSEUDO_MAP_IDX_VALUE,
226
0
           0, 0, 0, blob_off));
227
0
  emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_2, 0));
228
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
229
0
           0, 0, 0, off));
230
0
  emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_1, BPF_REG_0, 0));
231
0
}
232
233
static void move_blob2ctx(struct bpf_gen *gen, int ctx_off, int size, int blob_off)
234
0
{
235
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
236
0
           0, 0, 0, blob_off));
237
0
  emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_1, 0));
238
0
  emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_6, BPF_REG_0, ctx_off));
239
0
}
240
241
static void move_ctx2blob(struct bpf_gen *gen, int off, int size, int ctx_off,
242
           bool check_non_zero)
243
0
{
244
0
  emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_6, ctx_off));
245
0
  if (check_non_zero)
246
    /* If value in ctx is zero don't update the blob.
247
     * For example: when ctx->map.max_entries == 0, keep default max_entries from bpf.c
248
     */
249
0
    emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_0, 0, 3));
250
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
251
0
           0, 0, 0, off));
252
0
  emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_1, BPF_REG_0, 0));
253
0
}
254
255
static void move_stack2blob(struct bpf_gen *gen, int off, int size, int stack_off)
256
0
{
257
0
  emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_10, stack_off));
258
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
259
0
           0, 0, 0, off));
260
0
  emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_1, BPF_REG_0, 0));
261
0
}
262
263
static void move_stack2ctx(struct bpf_gen *gen, int ctx_off, int size, int stack_off)
264
0
{
265
0
  emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_10, stack_off));
266
0
  emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_6, BPF_REG_0, ctx_off));
267
0
}
268
269
static void emit_sys_bpf(struct bpf_gen *gen, int cmd, int attr, int attr_size)
270
0
{
271
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_1, cmd));
272
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_2, BPF_PSEUDO_MAP_IDX_VALUE,
273
0
           0, 0, 0, attr));
274
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_3, attr_size));
275
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_sys_bpf));
276
  /* remember the result in R7 */
277
0
  emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0));
278
0
}
279
280
static bool is_simm16(__s64 value)
281
0
{
282
0
  return value == (__s64)(__s16)value;
283
0
}
284
285
static void emit_check_err(struct bpf_gen *gen)
286
0
{
287
0
  __s64 off = -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 1;
288
289
  /* R7 contains result of last sys_bpf command.
290
   * if (R7 < 0) goto cleanup;
291
   */
292
0
  if (is_simm16(off)) {
293
0
    emit(gen, BPF_JMP_IMM(BPF_JSLT, BPF_REG_7, 0, off));
294
0
  } else {
295
0
    gen->error = -ERANGE;
296
0
    emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, -1));
297
0
  }
298
0
}
299
300
/* reg1 and reg2 should not be R1 - R5. They can be R0, R6 - R10 */
301
static void emit_debug(struct bpf_gen *gen, int reg1, int reg2,
302
           const char *fmt, va_list args)
303
0
{
304
0
  char buf[1024];
305
0
  int addr, len, ret;
306
307
0
  if (!gen->log_level)
308
0
    return;
309
0
  ret = vsnprintf(buf, sizeof(buf), fmt, args);
310
0
  if (ret < 1024 - 7 && reg1 >= 0 && reg2 < 0)
311
    /* The special case to accommodate common debug_ret():
312
     * to avoid specifying BPF_REG_7 and adding " r=%%d" to
313
     * prints explicitly.
314
     */
315
0
    strcat(buf, " r=%d");
316
0
  len = strlen(buf) + 1;
317
0
  addr = add_data(gen, buf, len);
318
319
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
320
0
           0, 0, 0, addr));
321
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_2, len));
322
0
  if (reg1 >= 0)
323
0
    emit(gen, BPF_MOV64_REG(BPF_REG_3, reg1));
324
0
  if (reg2 >= 0)
325
0
    emit(gen, BPF_MOV64_REG(BPF_REG_4, reg2));
326
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_trace_printk));
327
0
}
328
329
static void debug_regs(struct bpf_gen *gen, int reg1, int reg2, const char *fmt, ...)
330
0
{
331
0
  va_list args;
332
333
0
  va_start(args, fmt);
334
0
  emit_debug(gen, reg1, reg2, fmt, args);
335
0
  va_end(args);
336
0
}
337
338
static void debug_ret(struct bpf_gen *gen, const char *fmt, ...)
339
0
{
340
0
  va_list args;
341
342
0
  va_start(args, fmt);
343
0
  emit_debug(gen, BPF_REG_7, -1, fmt, args);
344
0
  va_end(args);
345
0
}
346
347
static void __emit_sys_close(struct bpf_gen *gen)
348
0
{
349
0
  emit(gen, BPF_JMP_IMM(BPF_JSLE, BPF_REG_1, 0,
350
            /* 2 is the number of the following insns
351
             * * 6 is additional insns in debug_regs
352
             */
353
0
            2 + (gen->log_level ? 6 : 0)));
354
0
  emit(gen, BPF_MOV64_REG(BPF_REG_9, BPF_REG_1));
355
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_sys_close));
356
0
  debug_regs(gen, BPF_REG_9, BPF_REG_0, "close(%%d) = %%d");
357
0
}
358
359
static void emit_sys_close_stack(struct bpf_gen *gen, int stack_off)
360
0
{
361
0
  emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_1, BPF_REG_10, stack_off));
362
0
  __emit_sys_close(gen);
363
0
}
364
365
static void emit_sys_close_blob(struct bpf_gen *gen, int blob_off)
366
0
{
367
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE,
368
0
           0, 0, 0, blob_off));
369
0
  emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_1, BPF_REG_0, 0));
370
0
  __emit_sys_close(gen);
371
0
}
372
373
static void compute_sha_update_offsets(struct bpf_gen *gen);
374
375
int bpf_gen__finish(struct bpf_gen *gen, int nr_progs, int nr_maps)
376
0
{
377
0
  int i;
378
379
0
  if (nr_progs < gen->nr_progs || nr_maps != gen->nr_maps) {
380
0
    pr_warn("nr_progs %d/%d nr_maps %d/%d mismatch\n",
381
0
      nr_progs, gen->nr_progs, nr_maps, gen->nr_maps);
382
0
    gen->error = -EFAULT;
383
0
    return gen->error;
384
0
  }
385
0
  emit_sys_close_stack(gen, stack_off(btf_fd));
386
0
  for (i = 0; i < gen->nr_progs; i++)
387
0
    move_stack2ctx(gen,
388
0
             sizeof(struct bpf_loader_ctx) +
389
0
             sizeof(struct bpf_map_desc) * gen->nr_maps +
390
0
             sizeof(struct bpf_prog_desc) * i +
391
0
             offsetof(struct bpf_prog_desc, prog_fd), 4,
392
0
             stack_off(prog_fd[i]));
393
0
  for (i = 0; i < gen->nr_maps; i++)
394
0
    move_blob2ctx(gen,
395
0
            sizeof(struct bpf_loader_ctx) +
396
0
            sizeof(struct bpf_map_desc) * i +
397
0
            offsetof(struct bpf_map_desc, map_fd), 4,
398
0
            blob_fd_array_off(gen, i));
399
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_0, 0));
400
0
  emit(gen, BPF_EXIT_INSN());
401
0
  if (OPTS_GET(gen->opts, gen_hash, false))
402
0
    compute_sha_update_offsets(gen);
403
404
0
  pr_debug("gen: finish %s\n", errstr(gen->error));
405
0
  if (!gen->error) {
406
0
    struct gen_loader_opts *opts = gen->opts;
407
408
0
    opts->insns = gen->insn_start;
409
0
    opts->insns_sz = gen->insn_cur - gen->insn_start;
410
0
    opts->data = gen->data_start;
411
0
    opts->data_sz = gen->data_cur - gen->data_start;
412
413
    /* use target endianness for embedded loader */
414
0
    if (gen->swapped_endian) {
415
0
      struct bpf_insn *insn = (struct bpf_insn *)opts->insns;
416
0
      int insn_cnt = opts->insns_sz / sizeof(struct bpf_insn);
417
418
0
      for (i = 0; i < insn_cnt; i++)
419
0
        bpf_insn_bswap(insn++);
420
0
    }
421
0
  }
422
0
  return gen->error;
423
0
}
424
425
void bpf_gen__free(struct bpf_gen *gen)
426
10.9k
{
427
10.9k
  if (!gen)
428
10.9k
    return;
429
0
  free(gen->data_start);
430
0
  free(gen->insn_start);
431
0
  free(gen);
432
0
}
433
434
/*
435
 * Fields of bpf_attr are set to values in native byte-order before being
436
 * written to the target-bound data blob, and may need endian conversion.
437
 * This macro allows providing the correct value in situ more simply than
438
 * writing a separate converter for *all fields* of *all records* included
439
 * in union bpf_attr. Note that sizeof(rval) should match the assignment
440
 * target to avoid runtime problems.
441
 */
442
0
#define tgt_endian(rval) ({          \
443
0
  typeof(rval) _val = (rval);       \
444
0
  if (gen->swapped_endian) {       \
445
0
    switch (sizeof(_val)) {       \
446
0
    case 1: break;         \
447
0
    case 2: _val = bswap_16(_val); break;   \
448
0
    case 4: _val = bswap_32(_val); break;   \
449
0
    case 8: _val = bswap_64(_val); break;   \
450
0
    default: pr_warn("unsupported bswap size!\n");  \
451
0
    }           \
452
0
  }             \
453
0
  _val;             \
454
0
})
455
456
static void compute_sha_update_offsets(struct bpf_gen *gen)
457
0
{
458
0
  __u64 sha[SHA256_DWORD_SIZE];
459
0
  __u64 sha_dw;
460
0
  int i;
461
462
0
  libbpf_sha256(gen->data_start, gen->data_cur - gen->data_start, (__u8 *)sha);
463
0
  for (i = 0; i < SHA256_DWORD_SIZE; i++) {
464
0
    struct bpf_insn *insn =
465
0
      (struct bpf_insn *)(gen->insn_start + gen->hash_insn_offset[i]);
466
0
    sha_dw = tgt_endian(sha[i]);
467
0
    insn[0].imm = (__u32)sha_dw;
468
0
    insn[1].imm = sha_dw >> 32;
469
0
  }
470
0
}
471
472
void bpf_gen__load_btf(struct bpf_gen *gen, const void *btf_raw_data,
473
           __u32 btf_raw_size)
474
0
{
475
0
  int attr_size = offsetofend(union bpf_attr, btf_log_level);
476
0
  int btf_data, btf_load_attr;
477
0
  union bpf_attr attr;
478
479
0
  memset(&attr, 0, attr_size);
480
0
  btf_data = add_data(gen, btf_raw_data, btf_raw_size);
481
482
0
  attr.btf_size = tgt_endian(btf_raw_size);
483
0
  btf_load_attr = add_data(gen, &attr, attr_size);
484
0
  pr_debug("gen: load_btf: off %d size %d, attr: off %d size %d\n",
485
0
     btf_data, btf_raw_size, btf_load_attr, attr_size);
486
487
  /* populate union bpf_attr with user provided log details */
488
0
  move_ctx2blob(gen, attr_field(btf_load_attr, btf_log_level), 4,
489
0
          offsetof(struct bpf_loader_ctx, log_level), false);
490
0
  move_ctx2blob(gen, attr_field(btf_load_attr, btf_log_size), 4,
491
0
          offsetof(struct bpf_loader_ctx, log_size), false);
492
0
  move_ctx2blob(gen, attr_field(btf_load_attr, btf_log_buf), 8,
493
0
          offsetof(struct bpf_loader_ctx, log_buf), false);
494
  /* populate union bpf_attr with a pointer to the BTF data */
495
0
  emit_rel_store(gen, attr_field(btf_load_attr, btf), btf_data);
496
  /* emit BTF_LOAD command */
497
0
  emit_sys_bpf(gen, BPF_BTF_LOAD, btf_load_attr, attr_size);
498
0
  debug_ret(gen, "btf_load size %d", btf_raw_size);
499
0
  emit_check_err(gen);
500
  /* remember btf_fd in the stack, if successful */
501
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_10, BPF_REG_7, stack_off(btf_fd)));
502
0
}
503
504
void bpf_gen__map_create(struct bpf_gen *gen,
505
       enum bpf_map_type map_type,
506
       const char *map_name,
507
       __u32 key_size, __u32 value_size, __u32 max_entries,
508
       struct bpf_map_create_opts *map_attr, int map_idx)
509
0
{
510
0
  int attr_size = offsetofend(union bpf_attr, map_extra);
511
0
  bool close_inner_map_fd = false;
512
0
  int map_create_attr, idx;
513
0
  union bpf_attr attr;
514
515
0
  memset(&attr, 0, attr_size);
516
0
  attr.map_type = tgt_endian(map_type);
517
0
  attr.key_size = tgt_endian(key_size);
518
0
  attr.value_size = tgt_endian(value_size);
519
0
  attr.map_flags = tgt_endian(map_attr->map_flags);
520
0
  attr.map_extra = tgt_endian(map_attr->map_extra);
521
0
  if (map_name)
522
0
    libbpf_strlcpy(attr.map_name, map_name, sizeof(attr.map_name));
523
0
  attr.numa_node = tgt_endian(map_attr->numa_node);
524
0
  attr.map_ifindex = tgt_endian(map_attr->map_ifindex);
525
0
  attr.max_entries = tgt_endian(max_entries);
526
0
  attr.btf_key_type_id = tgt_endian(map_attr->btf_key_type_id);
527
0
  attr.btf_value_type_id = tgt_endian(map_attr->btf_value_type_id);
528
529
0
  map_create_attr = add_data(gen, &attr, attr_size);
530
0
  pr_debug("gen: map_create: %s idx %d type %d value_type_id %d, attr: off %d size %d\n",
531
0
     map_name, map_idx, map_type, map_attr->btf_value_type_id,
532
0
     map_create_attr, attr_size);
533
534
0
  if (map_attr->btf_value_type_id)
535
    /* populate union bpf_attr with btf_fd saved in the stack earlier */
536
0
    move_stack2blob(gen, attr_field(map_create_attr, btf_fd), 4,
537
0
        stack_off(btf_fd));
538
0
  switch (map_type) {
539
0
  case BPF_MAP_TYPE_ARRAY_OF_MAPS:
540
0
  case BPF_MAP_TYPE_HASH_OF_MAPS:
541
0
    move_stack2blob(gen, attr_field(map_create_attr, inner_map_fd), 4,
542
0
        stack_off(inner_map_fd));
543
0
    close_inner_map_fd = true;
544
0
    break;
545
0
  default:
546
0
    break;
547
0
  }
548
  /* conditionally update max_entries */
549
0
  if (map_idx >= 0)
550
0
    move_ctx2blob(gen, attr_field(map_create_attr, max_entries), 4,
551
0
            sizeof(struct bpf_loader_ctx) +
552
0
            sizeof(struct bpf_map_desc) * map_idx +
553
0
            offsetof(struct bpf_map_desc, max_entries),
554
0
            true /* check that max_entries != 0 */);
555
  /* emit MAP_CREATE command */
556
0
  emit_sys_bpf(gen, BPF_MAP_CREATE, map_create_attr, attr_size);
557
0
  debug_ret(gen, "map_create %s idx %d type %d value_size %d value_btf_id %d",
558
0
      map_name, map_idx, map_type, value_size,
559
0
      map_attr->btf_value_type_id);
560
0
  emit_check_err(gen);
561
  /* remember map_fd in the stack, if successful */
562
0
  if (map_idx < 0) {
563
    /* This bpf_gen__map_create() function is called with map_idx >= 0
564
     * for all maps that libbpf loading logic tracks.
565
     * It's called with -1 to create an inner map.
566
     */
567
0
    emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_10, BPF_REG_7,
568
0
              stack_off(inner_map_fd)));
569
0
  } else if (map_idx != gen->nr_maps) {
570
0
    gen->error = -EDOM; /* internal bug */
571
0
    return;
572
0
  } else {
573
    /* add_map_fd does gen->nr_maps++ */
574
0
    idx = add_map_fd(gen);
575
0
    emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
576
0
             0, 0, 0, blob_fd_array_off(gen, idx)));
577
0
    emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_1, BPF_REG_7, 0));
578
0
  }
579
0
  if (close_inner_map_fd)
580
0
    emit_sys_close_stack(gen, stack_off(inner_map_fd));
581
0
}
582
583
static void emit_signature_match(struct bpf_gen *gen)
584
0
{
585
0
  __s64 off;
586
0
  int i;
587
588
0
  for (i = 0; i < SHA256_DWORD_SIZE; i++) {
589
0
    emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX,
590
0
             0, 0, 0, 0));
591
0
    emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_2, BPF_REG_1, i * sizeof(__u64)));
592
0
    gen->hash_insn_offset[i] = gen->insn_cur - gen->insn_start;
593
0
    emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_3, 0, 0, 0, 0, 0));
594
595
0
    off =  -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 1;
596
0
    if (is_simm16(off)) {
597
0
      emit(gen, BPF_MOV64_IMM(BPF_REG_7, -EINVAL));
598
0
      emit(gen, BPF_JMP_REG(BPF_JNE, BPF_REG_2, BPF_REG_3, off));
599
0
    } else {
600
0
      gen->error = -ERANGE;
601
0
      emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, -1));
602
0
    }
603
0
  }
604
0
}
605
606
void bpf_gen__record_attach_target(struct bpf_gen *gen, const char *attach_name,
607
           enum bpf_attach_type type)
608
0
{
609
0
  const char *prefix;
610
0
  int kind, ret;
611
612
0
  btf_get_kernel_prefix_kind(type, &prefix, &kind);
613
0
  gen->attach_kind = kind;
614
0
  ret = snprintf(gen->attach_target, sizeof(gen->attach_target), "%s%s",
615
0
           prefix, attach_name);
616
0
  if (ret >= sizeof(gen->attach_target))
617
0
    gen->error = -ENOSPC;
618
0
}
619
620
static void emit_find_attach_target(struct bpf_gen *gen)
621
0
{
622
0
  int name, len = strlen(gen->attach_target) + 1;
623
624
0
  pr_debug("gen: find_attach_tgt %s %d\n", gen->attach_target, gen->attach_kind);
625
0
  name = add_data(gen, gen->attach_target, len);
626
627
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
628
0
           0, 0, 0, name));
629
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_2, len));
630
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_3, gen->attach_kind));
631
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_4, 0));
632
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_btf_find_by_name_kind));
633
0
  emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0));
634
0
  debug_ret(gen, "find_by_name_kind(%s,%d)",
635
0
      gen->attach_target, gen->attach_kind);
636
0
  emit_check_err(gen);
637
  /* if successful, btf_id is in lower 32-bit of R7 and
638
   * btf_obj_fd is in upper 32-bit
639
   */
640
0
}
641
642
void bpf_gen__record_extern(struct bpf_gen *gen, const char *name, bool is_weak,
643
          bool is_typeless, bool is_ld64, int kind, int insn_idx)
644
0
{
645
0
  struct ksym_relo_desc *relo;
646
647
0
  relo = libbpf_reallocarray(gen->relos, gen->relo_cnt + 1, sizeof(*relo));
648
0
  if (!relo) {
649
0
    gen->error = -ENOMEM;
650
0
    return;
651
0
  }
652
0
  gen->relos = relo;
653
0
  relo += gen->relo_cnt;
654
0
  relo->name = name;
655
0
  relo->is_weak = is_weak;
656
0
  relo->is_typeless = is_typeless;
657
0
  relo->is_ld64 = is_ld64;
658
0
  relo->kind = kind;
659
0
  relo->insn_idx = insn_idx;
660
0
  gen->relo_cnt++;
661
0
}
662
663
/* returns existing ksym_desc with ref incremented, or inserts a new one */
664
static struct ksym_desc *get_ksym_desc(struct bpf_gen *gen, struct ksym_relo_desc *relo)
665
0
{
666
0
  struct ksym_desc *kdesc;
667
0
  int i;
668
669
0
  for (i = 0; i < gen->nr_ksyms; i++) {
670
0
    kdesc = &gen->ksyms[i];
671
0
    if (kdesc->kind == relo->kind && kdesc->is_ld64 == relo->is_ld64 &&
672
0
        !strcmp(kdesc->name, relo->name)) {
673
0
      kdesc->ref++;
674
0
      return kdesc;
675
0
    }
676
0
  }
677
0
  kdesc = libbpf_reallocarray(gen->ksyms, gen->nr_ksyms + 1, sizeof(*kdesc));
678
0
  if (!kdesc) {
679
0
    gen->error = -ENOMEM;
680
0
    return NULL;
681
0
  }
682
0
  gen->ksyms = kdesc;
683
0
  kdesc = &gen->ksyms[gen->nr_ksyms++];
684
0
  kdesc->name = relo->name;
685
0
  kdesc->kind = relo->kind;
686
0
  kdesc->ref = 1;
687
0
  kdesc->off = 0;
688
0
  kdesc->insn = 0;
689
0
  kdesc->is_ld64 = relo->is_ld64;
690
0
  return kdesc;
691
0
}
692
693
/* Overwrites BPF_REG_{0, 1, 2, 3, 4, 7}
694
 * Returns result in BPF_REG_7
695
 */
696
static void emit_bpf_find_by_name_kind(struct bpf_gen *gen, struct ksym_relo_desc *relo)
697
0
{
698
0
  int name_off, len = strlen(relo->name) + 1;
699
700
0
  name_off = add_data(gen, relo->name, len);
701
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
702
0
           0, 0, 0, name_off));
703
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_2, len));
704
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_3, relo->kind));
705
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_4, 0));
706
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_btf_find_by_name_kind));
707
0
  emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0));
708
0
  debug_ret(gen, "find_by_name_kind(%s,%d)", relo->name, relo->kind);
709
0
}
710
711
/* Overwrites BPF_REG_{0, 1, 2, 3, 4, 7}
712
 * Returns result in BPF_REG_7
713
 * Returns u64 symbol addr in BPF_REG_9
714
 */
715
static void emit_bpf_kallsyms_lookup_name(struct bpf_gen *gen, struct ksym_relo_desc *relo)
716
0
{
717
0
  int name_off, len = strlen(relo->name) + 1, res_off;
718
719
0
  name_off = add_data(gen, relo->name, len);
720
0
  res_off = add_data(gen, NULL, 8); /* res is u64 */
721
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
722
0
           0, 0, 0, name_off));
723
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_2, len));
724
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_3, 0));
725
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_4, BPF_PSEUDO_MAP_IDX_VALUE,
726
0
           0, 0, 0, res_off));
727
0
  emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_4));
728
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_kallsyms_lookup_name));
729
0
  emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_9, BPF_REG_7, 0));
730
0
  emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0));
731
0
  debug_ret(gen, "kallsyms_lookup_name(%s,%d)", relo->name, relo->kind);
732
0
}
733
734
/* Expects:
735
 * BPF_REG_8 - pointer to instruction
736
 *
737
 * We need to reuse BTF fd for same symbol otherwise each relocation takes a new
738
 * index, while kernel limits total kfunc BTFs to 256. For duplicate symbols,
739
 * this would mean a new BTF fd index for each entry. By pairing symbol name
740
 * with index, we get the insn->imm, insn->off pairing that kernel uses for
741
 * kfunc_tab, which becomes the effective limit even though all of them may
742
 * share same index in fd_array (such that kfunc_btf_tab has 1 element).
743
 */
744
static void emit_relo_kfunc_btf(struct bpf_gen *gen, struct ksym_relo_desc *relo, int insn)
745
0
{
746
0
  struct ksym_desc *kdesc;
747
0
  int btf_fd_idx;
748
749
0
  kdesc = get_ksym_desc(gen, relo);
750
0
  if (!kdesc)
751
0
    return;
752
  /* try to copy from existing bpf_insn */
753
0
  if (kdesc->ref > 1) {
754
0
    move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4,
755
0
             kdesc->insn + offsetof(struct bpf_insn, imm));
756
0
    move_blob2blob(gen, insn + offsetof(struct bpf_insn, off), 2,
757
0
             kdesc->insn + offsetof(struct bpf_insn, off));
758
0
    goto log;
759
0
  }
760
  /* remember insn offset, so we can copy BTF ID and FD later */
761
0
  kdesc->insn = insn;
762
0
  emit_bpf_find_by_name_kind(gen, relo);
763
0
  if (!relo->is_weak)
764
0
    emit_check_err(gen);
765
  /* get index in fd_array to store BTF FD at */
766
0
  btf_fd_idx = add_kfunc_btf_fd(gen);
767
0
  if (btf_fd_idx > INT16_MAX) {
768
0
    pr_warn("BTF fd off %d for kfunc %s exceeds INT16_MAX, cannot process relocation\n",
769
0
      btf_fd_idx, relo->name);
770
0
    gen->error = -E2BIG;
771
0
    return;
772
0
  }
773
0
  kdesc->off = btf_fd_idx;
774
  /* jump to success case */
775
0
  emit(gen, BPF_JMP_IMM(BPF_JSGE, BPF_REG_7, 0, 3));
776
  /* set value for imm, off as 0 */
777
0
  emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, offsetof(struct bpf_insn, imm), 0));
778
0
  emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), 0));
779
  /* skip success case for ret < 0 */
780
0
  emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 10));
781
  /* store btf_id into insn[insn_idx].imm */
782
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_7, offsetof(struct bpf_insn, imm)));
783
  /* obtain fd in BPF_REG_9 */
784
0
  emit(gen, BPF_MOV64_REG(BPF_REG_9, BPF_REG_7));
785
0
  emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_9, 32));
786
  /* load fd_array slot pointer */
787
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE,
788
0
           0, 0, 0, blob_fd_array_off(gen, btf_fd_idx)));
789
  /* store BTF fd in slot, 0 for vmlinux */
790
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_0, BPF_REG_9, 0));
791
  /* jump to insn[insn_idx].off store if fd denotes module BTF */
792
0
  emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_9, 0, 2));
793
  /* set the default value for off */
794
0
  emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), 0));
795
  /* skip BTF fd store for vmlinux BTF */
796
0
  emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1));
797
  /* store index into insn[insn_idx].off */
798
0
  emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), btf_fd_idx));
799
0
log:
800
0
  if (!gen->log_level)
801
0
    return;
802
0
  emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_8,
803
0
            offsetof(struct bpf_insn, imm)));
804
0
  emit(gen, BPF_LDX_MEM(BPF_H, BPF_REG_9, BPF_REG_8,
805
0
            offsetof(struct bpf_insn, off)));
806
0
  debug_regs(gen, BPF_REG_7, BPF_REG_9, " func (%s:count=%d): imm: %%d, off: %%d",
807
0
       relo->name, kdesc->ref);
808
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE,
809
0
           0, 0, 0, blob_fd_array_off(gen, kdesc->off)));
810
0
  emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_9, BPF_REG_0, 0));
811
0
  debug_regs(gen, BPF_REG_9, -1, " func (%s:count=%d): btf_fd",
812
0
       relo->name, kdesc->ref);
813
0
}
814
815
static void emit_ksym_relo_log(struct bpf_gen *gen, struct ksym_relo_desc *relo,
816
             int ref)
817
0
{
818
0
  if (!gen->log_level)
819
0
    return;
820
0
  emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_8,
821
0
            offsetof(struct bpf_insn, imm)));
822
0
  emit(gen, BPF_LDX_MEM(BPF_H, BPF_REG_9, BPF_REG_8, sizeof(struct bpf_insn) +
823
0
            offsetof(struct bpf_insn, imm)));
824
0
  debug_regs(gen, BPF_REG_7, BPF_REG_9, " var t=%d w=%d (%s:count=%d): imm[0]: %%d, imm[1]: %%d",
825
0
       relo->is_typeless, relo->is_weak, relo->name, ref);
826
0
  emit(gen, BPF_LDX_MEM(BPF_B, BPF_REG_9, BPF_REG_8, offsetofend(struct bpf_insn, code)));
827
0
  debug_regs(gen, BPF_REG_9, -1, " var t=%d w=%d (%s:count=%d): insn.reg",
828
0
       relo->is_typeless, relo->is_weak, relo->name, ref);
829
0
}
830
831
/* Expects:
832
 * BPF_REG_8 - pointer to instruction
833
 */
834
static void emit_relo_ksym_typeless(struct bpf_gen *gen,
835
            struct ksym_relo_desc *relo, int insn)
836
0
{
837
0
  struct ksym_desc *kdesc;
838
839
0
  kdesc = get_ksym_desc(gen, relo);
840
0
  if (!kdesc)
841
0
    return;
842
  /* try to copy from existing ldimm64 insn */
843
0
  if (kdesc->ref > 1) {
844
0
    move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4,
845
0
             kdesc->insn + offsetof(struct bpf_insn, imm));
846
0
    move_blob2blob(gen, insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm), 4,
847
0
             kdesc->insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm));
848
0
    goto log;
849
0
  }
850
  /* remember insn offset, so we can copy ksym addr later */
851
0
  kdesc->insn = insn;
852
  /* skip typeless ksym_desc in fd closing loop in cleanup_relos */
853
0
  kdesc->typeless = true;
854
0
  emit_bpf_kallsyms_lookup_name(gen, relo);
855
0
  emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_7, -ENOENT, 1));
856
0
  emit_check_err(gen);
857
  /* store lower half of addr into insn[insn_idx].imm */
858
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_9, offsetof(struct bpf_insn, imm)));
859
  /* store upper half of addr into insn[insn_idx + 1].imm */
860
0
  emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_9, 32));
861
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_9,
862
0
          sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm)));
863
0
log:
864
0
  emit_ksym_relo_log(gen, relo, kdesc->ref);
865
0
}
866
867
static __u32 src_reg_mask(struct bpf_gen *gen)
868
0
{
869
0
#if defined(__LITTLE_ENDIAN_BITFIELD) /* src_reg,dst_reg,... */
870
0
  return gen->swapped_endian ? 0xf0 : 0x0f;
871
#elif defined(__BIG_ENDIAN_BITFIELD) /* dst_reg,src_reg,... */
872
  return gen->swapped_endian ? 0x0f : 0xf0;
873
#else
874
#error "Unsupported bit endianness, cannot proceed"
875
#endif
876
0
}
877
878
/* Expects:
879
 * BPF_REG_8 - pointer to instruction
880
 */
881
static void emit_relo_ksym_btf(struct bpf_gen *gen, struct ksym_relo_desc *relo, int insn)
882
0
{
883
0
  struct ksym_desc *kdesc;
884
0
  __u32 reg_mask;
885
886
0
  kdesc = get_ksym_desc(gen, relo);
887
0
  if (!kdesc)
888
0
    return;
889
  /* try to copy from existing ldimm64 insn */
890
0
  if (kdesc->ref > 1) {
891
0
    move_blob2blob(gen, insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm), 4,
892
0
             kdesc->insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm));
893
0
    move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4,
894
0
             kdesc->insn + offsetof(struct bpf_insn, imm));
895
    /* jump over src_reg adjustment if imm (btf_id) is not 0, reuse BPF_REG_0 from move_blob2blob
896
     * If btf_id is zero, clear BPF_PSEUDO_BTF_ID flag in src_reg of ld_imm64 insn
897
     */
898
0
    emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_0, 0, 3));
899
0
    goto clear_src_reg;
900
0
  }
901
  /* remember insn offset, so we can copy BTF ID and FD later */
902
0
  kdesc->insn = insn;
903
0
  emit_bpf_find_by_name_kind(gen, relo);
904
0
  if (!relo->is_weak)
905
0
    emit_check_err(gen);
906
  /* jump to success case */
907
0
  emit(gen, BPF_JMP_IMM(BPF_JSGE, BPF_REG_7, 0, 3));
908
  /* set values for insn[insn_idx].imm, insn[insn_idx + 1].imm as 0 */
909
0
  emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, offsetof(struct bpf_insn, imm), 0));
910
0
  emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm), 0));
911
  /* skip success case for ret < 0 */
912
0
  emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 4));
913
  /* store btf_id into insn[insn_idx].imm */
914
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_7, offsetof(struct bpf_insn, imm)));
915
  /* store btf_obj_fd into insn[insn_idx + 1].imm */
916
0
  emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_7, 32));
917
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_7,
918
0
            sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm)));
919
  /* skip src_reg adjustment */
920
0
  emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 3));
921
0
clear_src_reg:
922
  /* clear bpf_object__relocate_data's src_reg assignment, otherwise we get a verifier failure */
923
0
  reg_mask = src_reg_mask(gen);
924
0
  emit(gen, BPF_LDX_MEM(BPF_B, BPF_REG_9, BPF_REG_8, offsetofend(struct bpf_insn, code)));
925
0
  emit(gen, BPF_ALU32_IMM(BPF_AND, BPF_REG_9, reg_mask));
926
0
  emit(gen, BPF_STX_MEM(BPF_B, BPF_REG_8, BPF_REG_9, offsetofend(struct bpf_insn, code)));
927
928
0
  emit_ksym_relo_log(gen, relo, kdesc->ref);
929
0
}
930
931
void bpf_gen__record_relo_core(struct bpf_gen *gen,
932
             const struct bpf_core_relo *core_relo)
933
0
{
934
0
  struct bpf_core_relo *relos;
935
936
0
  relos = libbpf_reallocarray(gen->core_relos, gen->core_relo_cnt + 1, sizeof(*relos));
937
0
  if (!relos) {
938
0
    gen->error = -ENOMEM;
939
0
    return;
940
0
  }
941
0
  gen->core_relos = relos;
942
0
  relos += gen->core_relo_cnt;
943
0
  memcpy(relos, core_relo, sizeof(*relos));
944
0
  gen->core_relo_cnt++;
945
0
}
946
947
static void emit_relo(struct bpf_gen *gen, struct ksym_relo_desc *relo, int insns)
948
0
{
949
0
  int insn;
950
951
0
  pr_debug("gen: emit_relo (%d): %s at %d %s\n",
952
0
     relo->kind, relo->name, relo->insn_idx, relo->is_ld64 ? "ld64" : "call");
953
0
  insn = insns + sizeof(struct bpf_insn) * relo->insn_idx;
954
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_8, BPF_PSEUDO_MAP_IDX_VALUE, 0, 0, 0, insn));
955
0
  if (relo->is_ld64) {
956
0
    if (relo->is_typeless)
957
0
      emit_relo_ksym_typeless(gen, relo, insn);
958
0
    else
959
0
      emit_relo_ksym_btf(gen, relo, insn);
960
0
  } else {
961
0
    emit_relo_kfunc_btf(gen, relo, insn);
962
0
  }
963
0
}
964
965
static void emit_relos(struct bpf_gen *gen, int insns)
966
0
{
967
0
  int i;
968
969
0
  for (i = 0; i < gen->relo_cnt; i++)
970
0
    emit_relo(gen, gen->relos + i, insns);
971
0
}
972
973
static void cleanup_core_relo(struct bpf_gen *gen)
974
0
{
975
0
  if (!gen->core_relo_cnt)
976
0
    return;
977
0
  free(gen->core_relos);
978
0
  gen->core_relo_cnt = 0;
979
0
  gen->core_relos = NULL;
980
0
}
981
982
static void cleanup_relos(struct bpf_gen *gen, int insns)
983
0
{
984
0
  struct ksym_desc *kdesc;
985
0
  int i, insn;
986
987
0
  for (i = 0; i < gen->nr_ksyms; i++) {
988
0
    kdesc = &gen->ksyms[i];
989
    /* only close fds for typed ksyms and kfuncs */
990
0
    if (kdesc->is_ld64 && !kdesc->typeless) {
991
      /* close fd recorded in insn[insn_idx + 1].imm */
992
0
      insn = kdesc->insn;
993
0
      insn += sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm);
994
0
      emit_sys_close_blob(gen, insn);
995
0
    } else if (!kdesc->is_ld64) {
996
0
      emit_sys_close_blob(gen, blob_fd_array_off(gen, kdesc->off));
997
0
      if (kdesc->off < MAX_FD_ARRAY_SZ)
998
0
        gen->nr_fd_array--;
999
0
    }
1000
0
  }
1001
0
  if (gen->nr_ksyms) {
1002
0
    free(gen->ksyms);
1003
0
    gen->nr_ksyms = 0;
1004
0
    gen->ksyms = NULL;
1005
0
  }
1006
0
  if (gen->relo_cnt) {
1007
0
    free(gen->relos);
1008
0
    gen->relo_cnt = 0;
1009
0
    gen->relos = NULL;
1010
0
  }
1011
0
  cleanup_core_relo(gen);
1012
0
}
1013
1014
/* Convert func, line, and core relo info blobs to target endianness */
1015
static void info_blob_bswap(struct bpf_gen *gen, int func_info, int line_info,
1016
          int core_relos, struct bpf_prog_load_opts *load_attr)
1017
0
{
1018
0
  struct bpf_func_info *fi = gen->data_start + func_info;
1019
0
  struct bpf_line_info *li = gen->data_start + line_info;
1020
0
  struct bpf_core_relo *cr = gen->data_start + core_relos;
1021
0
  int i;
1022
1023
0
  for (i = 0; i < load_attr->func_info_cnt; i++)
1024
0
    bpf_func_info_bswap(fi++);
1025
1026
0
  for (i = 0; i < load_attr->line_info_cnt; i++)
1027
0
    bpf_line_info_bswap(li++);
1028
1029
0
  for (i = 0; i < gen->core_relo_cnt; i++)
1030
0
    bpf_core_relo_bswap(cr++);
1031
0
}
1032
1033
void bpf_gen__prog_load(struct bpf_gen *gen,
1034
      enum bpf_prog_type prog_type, const char *prog_name,
1035
      const char *license, struct bpf_insn *insns, size_t insn_cnt,
1036
      struct bpf_prog_load_opts *load_attr, int prog_idx)
1037
0
{
1038
0
  int func_info_tot_sz = load_attr->func_info_cnt *
1039
0
             load_attr->func_info_rec_size;
1040
0
  int line_info_tot_sz = load_attr->line_info_cnt *
1041
0
             load_attr->line_info_rec_size;
1042
0
  int core_relo_tot_sz = gen->core_relo_cnt *
1043
0
             sizeof(struct bpf_core_relo);
1044
0
  int prog_load_attr, license_off, insns_off, func_info, line_info, core_relos;
1045
0
  int attr_size = offsetofend(union bpf_attr, core_relo_rec_size);
1046
0
  union bpf_attr attr;
1047
1048
0
  memset(&attr, 0, attr_size);
1049
  /* add license string to blob of bytes */
1050
0
  license_off = add_data(gen, license, strlen(license) + 1);
1051
  /* add insns to blob of bytes */
1052
0
  insns_off = add_data(gen, insns, insn_cnt * sizeof(struct bpf_insn));
1053
0
  pr_debug("gen: prog_load: prog_idx %d type %d insn off %d insns_cnt %zd license off %d\n",
1054
0
     prog_idx, prog_type, insns_off, insn_cnt, license_off);
1055
1056
  /* convert blob insns to target endianness */
1057
0
  if (gen->swapped_endian) {
1058
0
    struct bpf_insn *insn = gen->data_start + insns_off;
1059
0
    int i;
1060
1061
0
    for (i = 0; i < insn_cnt; i++, insn++)
1062
0
      bpf_insn_bswap(insn);
1063
0
  }
1064
1065
0
  attr.prog_type = tgt_endian(prog_type);
1066
0
  attr.expected_attach_type = tgt_endian(load_attr->expected_attach_type);
1067
0
  attr.attach_btf_id = tgt_endian(load_attr->attach_btf_id);
1068
0
  attr.prog_ifindex = tgt_endian(load_attr->prog_ifindex);
1069
0
  attr.kern_version = 0;
1070
0
  attr.insn_cnt = tgt_endian((__u32)insn_cnt);
1071
0
  attr.prog_flags = tgt_endian(load_attr->prog_flags);
1072
1073
0
  attr.func_info_rec_size = tgt_endian(load_attr->func_info_rec_size);
1074
0
  attr.func_info_cnt = tgt_endian(load_attr->func_info_cnt);
1075
0
  func_info = add_data(gen, load_attr->func_info, func_info_tot_sz);
1076
0
  pr_debug("gen: prog_load: func_info: off %d cnt %d rec size %d\n",
1077
0
     func_info, load_attr->func_info_cnt,
1078
0
     load_attr->func_info_rec_size);
1079
1080
0
  attr.line_info_rec_size = tgt_endian(load_attr->line_info_rec_size);
1081
0
  attr.line_info_cnt = tgt_endian(load_attr->line_info_cnt);
1082
0
  line_info = add_data(gen, load_attr->line_info, line_info_tot_sz);
1083
0
  pr_debug("gen: prog_load: line_info: off %d cnt %d rec size %d\n",
1084
0
     line_info, load_attr->line_info_cnt,
1085
0
     load_attr->line_info_rec_size);
1086
1087
0
  attr.core_relo_rec_size = tgt_endian((__u32)sizeof(struct bpf_core_relo));
1088
0
  attr.core_relo_cnt = tgt_endian(gen->core_relo_cnt);
1089
0
  core_relos = add_data(gen, gen->core_relos, core_relo_tot_sz);
1090
0
  pr_debug("gen: prog_load: core_relos: off %d cnt %d rec size %zd\n",
1091
0
     core_relos, gen->core_relo_cnt,
1092
0
     sizeof(struct bpf_core_relo));
1093
1094
  /* convert all info blobs to target endianness */
1095
0
  if (gen->swapped_endian)
1096
0
    info_blob_bswap(gen, func_info, line_info, core_relos, load_attr);
1097
1098
0
  libbpf_strlcpy(attr.prog_name, prog_name, sizeof(attr.prog_name));
1099
0
  prog_load_attr = add_data(gen, &attr, attr_size);
1100
0
  pr_debug("gen: prog_load: attr: off %d size %d\n",
1101
0
     prog_load_attr, attr_size);
1102
1103
  /* populate union bpf_attr with a pointer to license */
1104
0
  emit_rel_store(gen, attr_field(prog_load_attr, license), license_off);
1105
1106
  /* populate union bpf_attr with a pointer to instructions */
1107
0
  emit_rel_store(gen, attr_field(prog_load_attr, insns), insns_off);
1108
1109
  /* populate union bpf_attr with a pointer to func_info */
1110
0
  emit_rel_store(gen, attr_field(prog_load_attr, func_info), func_info);
1111
1112
  /* populate union bpf_attr with a pointer to line_info */
1113
0
  emit_rel_store(gen, attr_field(prog_load_attr, line_info), line_info);
1114
1115
  /* populate union bpf_attr with a pointer to core_relos */
1116
0
  emit_rel_store(gen, attr_field(prog_load_attr, core_relos), core_relos);
1117
1118
  /* populate union bpf_attr fd_array with a pointer to data where map_fds are saved */
1119
0
  emit_rel_store(gen, attr_field(prog_load_attr, fd_array), gen->fd_array);
1120
1121
  /* populate union bpf_attr with user provided log details */
1122
0
  move_ctx2blob(gen, attr_field(prog_load_attr, log_level), 4,
1123
0
          offsetof(struct bpf_loader_ctx, log_level), false);
1124
0
  move_ctx2blob(gen, attr_field(prog_load_attr, log_size), 4,
1125
0
          offsetof(struct bpf_loader_ctx, log_size), false);
1126
0
  move_ctx2blob(gen, attr_field(prog_load_attr, log_buf), 8,
1127
0
          offsetof(struct bpf_loader_ctx, log_buf), false);
1128
  /* populate union bpf_attr with btf_fd saved in the stack earlier */
1129
0
  move_stack2blob(gen, attr_field(prog_load_attr, prog_btf_fd), 4,
1130
0
      stack_off(btf_fd));
1131
0
  if (gen->attach_kind) {
1132
0
    emit_find_attach_target(gen);
1133
    /* populate union bpf_attr with btf_id and btf_obj_fd found by helper */
1134
0
    emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE,
1135
0
             0, 0, 0, prog_load_attr));
1136
0
    emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_0, BPF_REG_7,
1137
0
              offsetof(union bpf_attr, attach_btf_id)));
1138
0
    emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_7, 32));
1139
0
    emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_0, BPF_REG_7,
1140
0
              offsetof(union bpf_attr, attach_btf_obj_fd)));
1141
0
  }
1142
0
  emit_relos(gen, insns_off);
1143
  /* emit PROG_LOAD command */
1144
0
  emit_sys_bpf(gen, BPF_PROG_LOAD, prog_load_attr, attr_size);
1145
0
  debug_ret(gen, "prog_load %s insn_cnt %d", attr.prog_name, attr.insn_cnt);
1146
  /* successful or not, close btf module FDs used in extern ksyms and attach_btf_obj_fd */
1147
0
  cleanup_relos(gen, insns_off);
1148
0
  if (gen->attach_kind) {
1149
0
    emit_sys_close_blob(gen,
1150
0
            attr_field(prog_load_attr, attach_btf_obj_fd));
1151
0
    gen->attach_kind = 0;
1152
0
  }
1153
0
  emit_check_err(gen);
1154
  /* remember prog_fd in the stack, if successful */
1155
0
  emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_10, BPF_REG_7,
1156
0
            stack_off(prog_fd[gen->nr_progs])));
1157
0
  gen->nr_progs++;
1158
0
}
1159
1160
void bpf_gen__map_update_elem(struct bpf_gen *gen, int map_idx, void *pvalue,
1161
            __u32 value_size)
1162
0
{
1163
0
  int attr_size = offsetofend(union bpf_attr, flags);
1164
0
  int map_update_attr, value, key;
1165
0
  union bpf_attr attr;
1166
0
  int zero = 0;
1167
1168
0
  memset(&attr, 0, attr_size);
1169
1170
0
  value = add_data(gen, pvalue, value_size);
1171
0
  key = add_data(gen, &zero, sizeof(zero));
1172
1173
  /* if (map_desc[map_idx].initial_value) {
1174
   *    if (ctx->flags & BPF_SKEL_KERNEL)
1175
   *        bpf_probe_read_kernel(value, value_size, initial_value);
1176
   *    else
1177
   *        bpf_copy_from_user(value, value_size, initial_value);
1178
   * }
1179
   */
1180
0
  emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_3, BPF_REG_6,
1181
0
            sizeof(struct bpf_loader_ctx) +
1182
0
            sizeof(struct bpf_map_desc) * map_idx +
1183
0
            offsetof(struct bpf_map_desc, initial_value)));
1184
0
  emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_3, 0, 8));
1185
0
  emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
1186
0
           0, 0, 0, value));
1187
0
  emit(gen, BPF_MOV64_IMM(BPF_REG_2, value_size));
1188
0
  emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_0, BPF_REG_6,
1189
0
            offsetof(struct bpf_loader_ctx, flags)));
1190
0
  emit(gen, BPF_JMP_IMM(BPF_JSET, BPF_REG_0, BPF_SKEL_KERNEL, 2));
1191
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_copy_from_user));
1192
0
  emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1));
1193
0
  emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel));
1194
1195
0
  map_update_attr = add_data(gen, &attr, attr_size);
1196
0
  pr_debug("gen: map_update_elem: idx %d, value: off %d size %d, attr: off %d size %d\n",
1197
0
     map_idx, value, value_size, map_update_attr, attr_size);
1198
0
  move_blob2blob(gen, attr_field(map_update_attr, map_fd), 4,
1199
0
           blob_fd_array_off(gen, map_idx));
1200
0
  emit_rel_store(gen, attr_field(map_update_attr, key), key);
1201
0
  emit_rel_store(gen, attr_field(map_update_attr, value), value);
1202
  /* emit MAP_UPDATE_ELEM command */
1203
0
  emit_sys_bpf(gen, BPF_MAP_UPDATE_ELEM, map_update_attr, attr_size);
1204
0
  debug_ret(gen, "update_elem idx %d value_size %d", map_idx, value_size);
1205
0
  emit_check_err(gen);
1206
0
}
1207
1208
void bpf_gen__populate_outer_map(struct bpf_gen *gen, int outer_map_idx, int slot,
1209
         int inner_map_idx)
1210
0
{
1211
0
  int attr_size = offsetofend(union bpf_attr, flags);
1212
0
  int map_update_attr, key;
1213
0
  union bpf_attr attr;
1214
0
  int tgt_slot;
1215
1216
0
  memset(&attr, 0, attr_size);
1217
1218
0
  tgt_slot = tgt_endian(slot);
1219
0
  key = add_data(gen, &tgt_slot, sizeof(tgt_slot));
1220
1221
0
  map_update_attr = add_data(gen, &attr, attr_size);
1222
0
  pr_debug("gen: populate_outer_map: outer %d key %d inner %d, attr: off %d size %d\n",
1223
0
     outer_map_idx, slot, inner_map_idx, map_update_attr, attr_size);
1224
0
  move_blob2blob(gen, attr_field(map_update_attr, map_fd), 4,
1225
0
           blob_fd_array_off(gen, outer_map_idx));
1226
0
  emit_rel_store(gen, attr_field(map_update_attr, key), key);
1227
0
  emit_rel_store(gen, attr_field(map_update_attr, value),
1228
0
           blob_fd_array_off(gen, inner_map_idx));
1229
1230
  /* emit MAP_UPDATE_ELEM command */
1231
0
  emit_sys_bpf(gen, BPF_MAP_UPDATE_ELEM, map_update_attr, attr_size);
1232
0
  debug_ret(gen, "populate_outer_map outer %d key %d inner %d",
1233
0
      outer_map_idx, slot, inner_map_idx);
1234
0
  emit_check_err(gen);
1235
0
}
1236
1237
void bpf_gen__map_freeze(struct bpf_gen *gen, int map_idx)
1238
0
{
1239
0
  int attr_size = offsetofend(union bpf_attr, map_fd);
1240
0
  int map_freeze_attr;
1241
0
  union bpf_attr attr;
1242
1243
0
  memset(&attr, 0, attr_size);
1244
0
  map_freeze_attr = add_data(gen, &attr, attr_size);
1245
0
  pr_debug("gen: map_freeze: idx %d, attr: off %d size %d\n",
1246
0
     map_idx, map_freeze_attr, attr_size);
1247
0
  move_blob2blob(gen, attr_field(map_freeze_attr, map_fd), 4,
1248
0
           blob_fd_array_off(gen, map_idx));
1249
  /* emit MAP_FREEZE command */
1250
0
  emit_sys_bpf(gen, BPF_MAP_FREEZE, map_freeze_attr, attr_size);
1251
0
  debug_ret(gen, "map_freeze");
1252
0
  emit_check_err(gen);
1253
0
}