1 // SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause) 2 /* Copyright (c) 2021 Facebook */ 3 #include <stdio.h> 4 #include <stdlib.h> 5 #include <string.h> 6 #include <errno.h> 7 #include <asm/byteorder.h> 8 #include <linux/filter.h> 9 #include <sys/param.h> 10 #include "btf.h" 11 #include "bpf.h" 12 #include "libbpf.h" 13 #include "libbpf_internal.h" 14 #include "hashmap.h" 15 #include "bpf_gen_internal.h" 16 #include "skel_internal.h" 17 18 #define MAX_USED_MAPS 64 19 #define MAX_USED_PROGS 32 20 #define MAX_KFUNC_DESCS 256 21 #define MAX_FD_ARRAY_SZ (MAX_USED_MAPS + MAX_KFUNC_DESCS) 22 23 /* The following structure describes the stack layout of the loader program. 24 * In addition R6 contains the pointer to context. 25 * R7 contains the result of the last sys_bpf command (typically error or FD). 26 * R9 contains the result of the last sys_close command. 27 * 28 * Naming convention: 29 * ctx - bpf program context 30 * stack - bpf program stack 31 * blob - bpf_attr-s, strings, insns, map data. 32 * All the bytes that loader prog will use for read/write. 33 */ 34 struct loader_stack { 35 __u32 btf_fd; 36 __u32 inner_map_fd; 37 __u32 prog_fd[MAX_USED_PROGS]; 38 }; 39 40 #define stack_off(field) \ 41 (__s16)(-sizeof(struct loader_stack) + offsetof(struct loader_stack, field)) 42 43 #define attr_field(attr, field) (attr + offsetof(union bpf_attr, field)) 44 45 static int blob_fd_array_off(struct bpf_gen *gen, int index) 46 { 47 return gen->fd_array + index * sizeof(int); 48 } 49 50 static int realloc_insn_buf(struct bpf_gen *gen, __u32 size) 51 { 52 size_t off = gen->insn_cur - gen->insn_start; 53 void *insn_start; 54 55 if (gen->error) 56 return gen->error; 57 if (size > INT32_MAX || off + size > INT32_MAX) { 58 gen->error = -ERANGE; 59 return -ERANGE; 60 } 61 insn_start = realloc(gen->insn_start, off + size); 62 if (!insn_start) { 63 gen->error = -ENOMEM; 64 free(gen->insn_start); 65 gen->insn_start = NULL; 66 gen->insn_cur = NULL; 67 return -ENOMEM; 68 } 69 gen->insn_start = insn_start; 70 gen->insn_cur = insn_start + off; 71 return 0; 72 } 73 74 static int realloc_data_buf(struct bpf_gen *gen, __u32 size) 75 { 76 size_t off = gen->data_cur - gen->data_start; 77 void *data_start; 78 79 if (gen->error) 80 return gen->error; 81 if (size > INT32_MAX || off + size > INT32_MAX) { 82 gen->error = -ERANGE; 83 return -ERANGE; 84 } 85 data_start = realloc(gen->data_start, off + size); 86 if (!data_start) { 87 gen->error = -ENOMEM; 88 free(gen->data_start); 89 gen->data_start = NULL; 90 gen->data_cur = NULL; 91 return -ENOMEM; 92 } 93 gen->data_start = data_start; 94 gen->data_cur = data_start + off; 95 return 0; 96 } 97 98 static void emit(struct bpf_gen *gen, struct bpf_insn insn) 99 { 100 if (realloc_insn_buf(gen, sizeof(insn))) 101 return; 102 memcpy(gen->insn_cur, &insn, sizeof(insn)); 103 gen->insn_cur += sizeof(insn); 104 } 105 106 static void emit2(struct bpf_gen *gen, struct bpf_insn insn1, struct bpf_insn insn2) 107 { 108 emit(gen, insn1); 109 emit(gen, insn2); 110 } 111 112 static int add_data(struct bpf_gen *gen, const void *data, __u32 size); 113 static void emit_sys_close_blob(struct bpf_gen *gen, int blob_off); 114 static void emit_signature_match(struct bpf_gen *gen); 115 116 void bpf_gen__init(struct bpf_gen *gen, int log_level, int nr_progs, int nr_maps) 117 { 118 size_t stack_sz = sizeof(struct loader_stack), nr_progs_sz; 119 int i; 120 121 gen->fd_array = add_data(gen, NULL, MAX_FD_ARRAY_SZ * sizeof(int)); 122 gen->log_level = log_level; 123 /* save ctx pointer into R6 */ 124 emit(gen, BPF_MOV64_REG(BPF_REG_6, BPF_REG_1)); 125 126 /* bzero stack */ 127 emit(gen, BPF_MOV64_REG(BPF_REG_1, BPF_REG_10)); 128 emit(gen, BPF_ALU64_IMM(BPF_ADD, BPF_REG_1, -stack_sz)); 129 emit(gen, BPF_MOV64_IMM(BPF_REG_2, stack_sz)); 130 emit(gen, BPF_MOV64_IMM(BPF_REG_3, 0)); 131 emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel)); 132 133 /* amount of stack actually used, only used to calculate iterations, not stack offset */ 134 nr_progs_sz = offsetof(struct loader_stack, prog_fd[nr_progs]); 135 /* jump over cleanup code */ 136 emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 137 /* size of cleanup code below (including map fd cleanup) */ 138 (nr_progs_sz / 4) * 3 + 2 + 139 /* 6 insns for emit_sys_close_blob, 140 * 6 insns for debug_regs in emit_sys_close_blob 141 */ 142 nr_maps * (6 + (gen->log_level ? 6 : 0)))); 143 144 /* remember the label where all error branches will jump to */ 145 gen->cleanup_label = gen->insn_cur - gen->insn_start; 146 /* emit cleanup code: close all temp FDs */ 147 for (i = 0; i < nr_progs_sz; i += 4) { 148 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_1, BPF_REG_10, -stack_sz + i)); 149 emit(gen, BPF_JMP_IMM(BPF_JSLE, BPF_REG_1, 0, 1)); 150 emit(gen, BPF_EMIT_CALL(BPF_FUNC_sys_close)); 151 } 152 for (i = 0; i < nr_maps; i++) 153 emit_sys_close_blob(gen, blob_fd_array_off(gen, i)); 154 /* R7 contains the error code from sys_bpf. Copy it into R0 and exit. */ 155 emit(gen, BPF_MOV64_REG(BPF_REG_0, BPF_REG_7)); 156 emit(gen, BPF_EXIT_INSN()); 157 if (OPTS_GET(gen->opts, gen_hash, false)) 158 emit_signature_match(gen); 159 } 160 161 static int add_data(struct bpf_gen *gen, const void *data, __u32 size) 162 { 163 __u64 zero = 0; 164 __u32 size8; 165 void *prev; 166 167 if (size > INT32_MAX) { 168 gen->error = -ERANGE; 169 return 0; 170 } 171 size8 = roundup(size, 8); 172 173 if (realloc_data_buf(gen, size8)) 174 return 0; 175 prev = gen->data_cur; 176 if (data) { 177 memcpy(gen->data_cur, data, size); 178 memcpy(gen->data_cur + size, &zero, size8 - size); 179 } else { 180 memset(gen->data_cur, 0, size8); 181 } 182 gen->data_cur += size8; 183 return prev - gen->data_start; 184 } 185 186 /* Get index for map_fd/btf_fd slot in reserved fd_array, or in data relative 187 * to start of fd_array. Caller can decide if it is usable or not. 188 */ 189 static int add_map_fd(struct bpf_gen *gen) 190 { 191 if (gen->nr_maps == MAX_USED_MAPS) { 192 pr_warn("Total maps exceeds %d\n", MAX_USED_MAPS); 193 gen->error = -E2BIG; 194 return 0; 195 } 196 return gen->nr_maps++; 197 } 198 199 static int add_kfunc_btf_fd(struct bpf_gen *gen) 200 { 201 int cur; 202 203 if (gen->nr_fd_array == MAX_KFUNC_DESCS) { 204 cur = add_data(gen, NULL, sizeof(int)); 205 return (cur - gen->fd_array) / sizeof(int); 206 } 207 return MAX_USED_MAPS + gen->nr_fd_array++; 208 } 209 210 static int insn_bytes_to_bpf_size(__u32 sz) 211 { 212 switch (sz) { 213 case 8: return BPF_DW; 214 case 4: return BPF_W; 215 case 2: return BPF_H; 216 case 1: return BPF_B; 217 default: return -1; 218 } 219 } 220 221 /* *(u64 *)(blob + off) = (u64)(void *)(blob + data) */ 222 static void emit_rel_store(struct bpf_gen *gen, int off, int data) 223 { 224 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE, 225 0, 0, 0, data)); 226 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 227 0, 0, 0, off)); 228 emit(gen, BPF_STX_MEM(BPF_DW, BPF_REG_1, BPF_REG_0, 0)); 229 } 230 231 static void move_blob2blob(struct bpf_gen *gen, int off, int size, int blob_off) 232 { 233 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_2, BPF_PSEUDO_MAP_IDX_VALUE, 234 0, 0, 0, blob_off)); 235 emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_2, 0)); 236 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 237 0, 0, 0, off)); 238 emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_1, BPF_REG_0, 0)); 239 } 240 241 static void move_blob2ctx(struct bpf_gen *gen, int ctx_off, int size, int blob_off) 242 { 243 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 244 0, 0, 0, blob_off)); 245 emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_1, 0)); 246 emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_6, BPF_REG_0, ctx_off)); 247 } 248 249 static void move_ctx2blob(struct bpf_gen *gen, int off, int size, int ctx_off, 250 bool check_non_zero) 251 { 252 emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_6, ctx_off)); 253 if (check_non_zero) 254 /* If value in ctx is zero don't update the blob. 255 * For example: when ctx->map.max_entries == 0, keep default max_entries from bpf.c 256 */ 257 emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_0, 0, 3)); 258 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 259 0, 0, 0, off)); 260 emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_1, BPF_REG_0, 0)); 261 } 262 263 static void move_stack2blob(struct bpf_gen *gen, int off, int size, int stack_off) 264 { 265 emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_10, stack_off)); 266 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 267 0, 0, 0, off)); 268 emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_1, BPF_REG_0, 0)); 269 } 270 271 static void move_stack2ctx(struct bpf_gen *gen, int ctx_off, int size, int stack_off) 272 { 273 emit(gen, BPF_LDX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_0, BPF_REG_10, stack_off)); 274 emit(gen, BPF_STX_MEM(insn_bytes_to_bpf_size(size), BPF_REG_6, BPF_REG_0, ctx_off)); 275 } 276 277 static void emit_sys_bpf(struct bpf_gen *gen, int cmd, int attr, int attr_size) 278 { 279 emit(gen, BPF_MOV64_IMM(BPF_REG_1, cmd)); 280 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_2, BPF_PSEUDO_MAP_IDX_VALUE, 281 0, 0, 0, attr)); 282 emit(gen, BPF_MOV64_IMM(BPF_REG_3, attr_size)); 283 emit(gen, BPF_EMIT_CALL(BPF_FUNC_sys_bpf)); 284 /* remember the result in R7 */ 285 emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0)); 286 } 287 288 static bool is_simm16(__s64 value) 289 { 290 return value == (__s64)(__s16)value; 291 } 292 293 static void emit_check_err(struct bpf_gen *gen) 294 { 295 __s64 off = -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 1; 296 297 /* R7 contains result of last sys_bpf command. 298 * if (R7 < 0) goto cleanup; 299 */ 300 if (is_simm16(off)) { 301 emit(gen, BPF_JMP_IMM(BPF_JSLT, BPF_REG_7, 0, off)); 302 } else { 303 gen->error = -ERANGE; 304 } 305 } 306 307 /* reg1 and reg2 should not be R1 - R5. They can be R0, R6 - R10 */ 308 static void emit_debug(struct bpf_gen *gen, int reg1, int reg2, 309 const char *fmt, va_list args) 310 { 311 char buf[1024]; 312 int addr, len, ret; 313 314 if (!gen->log_level) 315 return; 316 ret = vsnprintf(buf, sizeof(buf), fmt, args); 317 if (ret < 1024 - 7 && reg1 >= 0 && reg2 < 0) 318 /* The special case to accommodate common debug_ret(): 319 * to avoid specifying BPF_REG_7 and adding " r=%%d" to 320 * prints explicitly. 321 */ 322 strcat(buf, " r=%d"); 323 len = strlen(buf) + 1; 324 addr = add_data(gen, buf, len); 325 326 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 327 0, 0, 0, addr)); 328 emit(gen, BPF_MOV64_IMM(BPF_REG_2, len)); 329 if (reg1 >= 0) 330 emit(gen, BPF_MOV64_REG(BPF_REG_3, reg1)); 331 if (reg2 >= 0) 332 emit(gen, BPF_MOV64_REG(BPF_REG_4, reg2)); 333 emit(gen, BPF_EMIT_CALL(BPF_FUNC_trace_printk)); 334 } 335 336 static void debug_regs(struct bpf_gen *gen, int reg1, int reg2, const char *fmt, ...) 337 { 338 va_list args; 339 340 va_start(args, fmt); 341 emit_debug(gen, reg1, reg2, fmt, args); 342 va_end(args); 343 } 344 345 static void debug_ret(struct bpf_gen *gen, const char *fmt, ...) 346 { 347 va_list args; 348 349 va_start(args, fmt); 350 emit_debug(gen, BPF_REG_7, -1, fmt, args); 351 va_end(args); 352 } 353 354 static void __emit_sys_close(struct bpf_gen *gen) 355 { 356 emit(gen, BPF_JMP_IMM(BPF_JSLE, BPF_REG_1, 0, 357 /* 2 is the number of the following insns 358 * * 6 is additional insns in debug_regs 359 */ 360 2 + (gen->log_level ? 6 : 0))); 361 emit(gen, BPF_MOV64_REG(BPF_REG_9, BPF_REG_1)); 362 emit(gen, BPF_EMIT_CALL(BPF_FUNC_sys_close)); 363 debug_regs(gen, BPF_REG_9, BPF_REG_0, "close(%%d) = %%d"); 364 } 365 366 static void emit_sys_close_stack(struct bpf_gen *gen, int stack_off) 367 { 368 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_1, BPF_REG_10, stack_off)); 369 __emit_sys_close(gen); 370 } 371 372 static void emit_sys_close_blob(struct bpf_gen *gen, int blob_off) 373 { 374 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE, 375 0, 0, 0, blob_off)); 376 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_1, BPF_REG_0, 0)); 377 __emit_sys_close(gen); 378 } 379 380 static void compute_sha_update_offsets(struct bpf_gen *gen); 381 382 int bpf_gen__finish(struct bpf_gen *gen, int nr_progs, int nr_maps) 383 { 384 int i; 385 386 if (nr_progs < gen->nr_progs || nr_maps != gen->nr_maps) { 387 pr_warn("nr_progs %d/%d nr_maps %d/%d mismatch\n", 388 nr_progs, gen->nr_progs, nr_maps, gen->nr_maps); 389 gen->error = -EFAULT; 390 return gen->error; 391 } 392 emit_sys_close_stack(gen, stack_off(btf_fd)); 393 for (i = 0; i < gen->nr_progs; i++) 394 move_stack2ctx(gen, 395 sizeof(struct bpf_loader_ctx) + 396 sizeof(struct bpf_map_desc) * gen->nr_maps + 397 sizeof(struct bpf_prog_desc) * i + 398 offsetof(struct bpf_prog_desc, prog_fd), 4, 399 stack_off(prog_fd[i])); 400 for (i = 0; i < gen->nr_maps; i++) 401 move_blob2ctx(gen, 402 sizeof(struct bpf_loader_ctx) + 403 sizeof(struct bpf_map_desc) * i + 404 offsetof(struct bpf_map_desc, map_fd), 4, 405 blob_fd_array_off(gen, i)); 406 emit(gen, BPF_MOV64_IMM(BPF_REG_0, 0)); 407 emit(gen, BPF_EXIT_INSN()); 408 if (!gen->error) { 409 struct gen_loader_opts *opts = gen->opts; 410 411 if (OPTS_GET(opts, gen_hash, false)) 412 compute_sha_update_offsets(gen); 413 414 opts->insns = gen->insn_start; 415 opts->insns_sz = gen->insn_cur - gen->insn_start; 416 opts->data = gen->data_start; 417 opts->data_sz = gen->data_cur - gen->data_start; 418 419 /* use target endianness for embedded loader */ 420 if (gen->swapped_endian) { 421 struct bpf_insn *insn = (struct bpf_insn *)opts->insns; 422 int insn_cnt = opts->insns_sz / sizeof(struct bpf_insn); 423 424 for (i = 0; i < insn_cnt; i++) 425 bpf_insn_bswap(insn++); 426 } 427 } 428 pr_debug("gen: finish %s\n", errstr(gen->error)); 429 return gen->error; 430 } 431 432 void bpf_gen__free(struct bpf_gen *gen) 433 { 434 if (!gen) 435 return; 436 free(gen->data_start); 437 free(gen->insn_start); 438 free(gen); 439 } 440 441 /* 442 * Fields of bpf_attr are set to values in native byte-order before being 443 * written to the target-bound data blob, and may need endian conversion. 444 * This macro allows providing the correct value in situ more simply than 445 * writing a separate converter for *all fields* of *all records* included 446 * in union bpf_attr. Note that sizeof(rval) should match the assignment 447 * target to avoid runtime problems. 448 */ 449 #define tgt_endian(rval) ({ \ 450 typeof(rval) _val = (rval); \ 451 if (gen->swapped_endian) { \ 452 switch (sizeof(_val)) { \ 453 case 1: break; \ 454 case 2: _val = bswap_16(_val); break; \ 455 case 4: _val = bswap_32(_val); break; \ 456 case 8: _val = bswap_64(_val); break; \ 457 default: pr_warn("unsupported bswap size!\n"); \ 458 } \ 459 } \ 460 _val; \ 461 }) 462 463 static void compute_sha_update_offsets(struct bpf_gen *gen) 464 { 465 __u64 sha[SHA256_DWORD_SIZE]; 466 __u64 sha_dw; 467 int i; 468 469 libbpf_sha256(gen->data_start, gen->data_cur - gen->data_start, (__u8 *)sha); 470 for (i = 0; i < SHA256_DWORD_SIZE; i++) { 471 struct bpf_insn *insn = 472 (struct bpf_insn *)(gen->insn_start + gen->hash_insn_offset[i]); 473 sha_dw = tgt_endian(sha[i]); 474 insn[0].imm = (__u32)sha_dw; 475 insn[1].imm = sha_dw >> 32; 476 } 477 } 478 479 void bpf_gen__load_btf(struct bpf_gen *gen, const void *btf_raw_data, 480 __u32 btf_raw_size) 481 { 482 int attr_size = offsetofend(union bpf_attr, btf_log_level); 483 int btf_data, btf_load_attr; 484 union bpf_attr attr; 485 486 memset(&attr, 0, attr_size); 487 btf_data = add_data(gen, btf_raw_data, btf_raw_size); 488 489 attr.btf_size = tgt_endian(btf_raw_size); 490 btf_load_attr = add_data(gen, &attr, attr_size); 491 pr_debug("gen: load_btf: off %d size %d, attr: off %d size %d\n", 492 btf_data, btf_raw_size, btf_load_attr, attr_size); 493 494 /* populate union bpf_attr with user provided log details */ 495 move_ctx2blob(gen, attr_field(btf_load_attr, btf_log_level), 4, 496 offsetof(struct bpf_loader_ctx, log_level), false); 497 move_ctx2blob(gen, attr_field(btf_load_attr, btf_log_size), 4, 498 offsetof(struct bpf_loader_ctx, log_size), false); 499 move_ctx2blob(gen, attr_field(btf_load_attr, btf_log_buf), 8, 500 offsetof(struct bpf_loader_ctx, log_buf), false); 501 /* populate union bpf_attr with a pointer to the BTF data */ 502 emit_rel_store(gen, attr_field(btf_load_attr, btf), btf_data); 503 /* emit BTF_LOAD command */ 504 emit_sys_bpf(gen, BPF_BTF_LOAD, btf_load_attr, attr_size); 505 debug_ret(gen, "btf_load size %d", btf_raw_size); 506 emit_check_err(gen); 507 /* remember btf_fd in the stack, if successful */ 508 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_10, BPF_REG_7, stack_off(btf_fd))); 509 } 510 511 void bpf_gen__map_create(struct bpf_gen *gen, 512 enum bpf_map_type map_type, 513 const char *map_name, 514 __u32 key_size, __u32 value_size, __u32 max_entries, 515 struct bpf_map_create_opts *map_attr, int map_idx) 516 { 517 int attr_size = offsetofend(union bpf_attr, map_extra); 518 bool close_inner_map_fd = false; 519 int map_create_attr, idx; 520 union bpf_attr attr; 521 522 memset(&attr, 0, attr_size); 523 attr.map_type = tgt_endian(map_type); 524 attr.key_size = tgt_endian(key_size); 525 attr.value_size = tgt_endian(value_size); 526 attr.map_flags = tgt_endian(map_attr->map_flags); 527 attr.map_extra = tgt_endian(map_attr->map_extra); 528 if (map_name) 529 libbpf_strlcpy(attr.map_name, map_name, sizeof(attr.map_name)); 530 attr.numa_node = tgt_endian(map_attr->numa_node); 531 attr.map_ifindex = tgt_endian(map_attr->map_ifindex); 532 attr.max_entries = tgt_endian(max_entries); 533 attr.btf_key_type_id = tgt_endian(map_attr->btf_key_type_id); 534 attr.btf_value_type_id = tgt_endian(map_attr->btf_value_type_id); 535 536 map_create_attr = add_data(gen, &attr, attr_size); 537 pr_debug("gen: map_create: %s idx %d type %d value_type_id %d, attr: off %d size %d\n", 538 map_name, map_idx, map_type, map_attr->btf_value_type_id, 539 map_create_attr, attr_size); 540 541 if (map_attr->btf_value_type_id) 542 /* populate union bpf_attr with btf_fd saved in the stack earlier */ 543 move_stack2blob(gen, attr_field(map_create_attr, btf_fd), 4, 544 stack_off(btf_fd)); 545 switch (map_type) { 546 case BPF_MAP_TYPE_ARRAY_OF_MAPS: 547 case BPF_MAP_TYPE_HASH_OF_MAPS: 548 move_stack2blob(gen, attr_field(map_create_attr, inner_map_fd), 4, 549 stack_off(inner_map_fd)); 550 close_inner_map_fd = true; 551 break; 552 default: 553 break; 554 } 555 556 /* 557 * Conditionally update max_entries from the host-supplied loader 558 * ctx. This sizes the map at runtime, but for a signed loader 559 * (gen_hash) it would let an untrusted host re-dimension the 560 * program's maps after emit_signature_match(), outside what the 561 * signature attests to. Keep the signer-provided max_entries 562 * baked into the blob in that case. 563 */ 564 if (map_idx >= 0 && !OPTS_GET(gen->opts, gen_hash, false)) 565 move_ctx2blob(gen, attr_field(map_create_attr, max_entries), 4, 566 sizeof(struct bpf_loader_ctx) + 567 sizeof(struct bpf_map_desc) * map_idx + 568 offsetof(struct bpf_map_desc, max_entries), 569 true /* check that max_entries != 0 */); 570 571 /* emit MAP_CREATE command */ 572 emit_sys_bpf(gen, BPF_MAP_CREATE, map_create_attr, attr_size); 573 debug_ret(gen, "map_create %s idx %d type %d value_size %d value_btf_id %d", 574 map_name, map_idx, map_type, value_size, 575 map_attr->btf_value_type_id); 576 emit_check_err(gen); 577 /* remember map_fd in the stack, if successful */ 578 if (map_idx < 0) { 579 /* This bpf_gen__map_create() function is called with map_idx >= 0 580 * for all maps that libbpf loading logic tracks. 581 * It's called with -1 to create an inner map. 582 */ 583 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_10, BPF_REG_7, 584 stack_off(inner_map_fd))); 585 } else if (map_idx != gen->nr_maps) { 586 gen->error = -EDOM; /* internal bug */ 587 return; 588 } else { 589 /* add_map_fd does gen->nr_maps++ */ 590 idx = add_map_fd(gen); 591 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 592 0, 0, 0, blob_fd_array_off(gen, idx))); 593 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_1, BPF_REG_7, 0)); 594 } 595 if (close_inner_map_fd) 596 emit_sys_close_stack(gen, stack_off(inner_map_fd)); 597 } 598 599 static void emit_signature_match(struct bpf_gen *gen) 600 { 601 __s64 off; 602 int i; 603 604 /* 605 * Reject if the metadata map is not exclusive. Without exclusivity 606 * the cached map->sha[] verified above can be stale: another BPF 607 * program with map access could have mutated the contents between 608 * BPF_OBJ_GET_INFO_BY_FD and loader execution. 609 */ 610 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX, 611 0, 0, 0, 0)); 612 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_2, BPF_REG_1, SHA256_DIGEST_LENGTH)); 613 off = -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 2; 614 if (is_simm16(off)) { 615 emit(gen, BPF_MOV64_IMM(BPF_REG_7, -EINVAL)); 616 emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_2, 1, off)); 617 } else { 618 gen->error = -ERANGE; 619 } 620 621 for (i = 0; i < SHA256_DWORD_SIZE; i++) { 622 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX, 623 0, 0, 0, 0)); 624 emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_2, BPF_REG_1, i * sizeof(__u64))); 625 gen->hash_insn_offset[i] = gen->insn_cur - gen->insn_start; 626 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_3, 0, 0, 0, 0, 0)); 627 628 off = -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 2; 629 if (is_simm16(off)) { 630 emit(gen, BPF_MOV64_IMM(BPF_REG_7, -EINVAL)); 631 emit(gen, BPF_JMP_REG(BPF_JNE, BPF_REG_2, BPF_REG_3, off)); 632 } else { 633 gen->error = -ERANGE; 634 } 635 } 636 } 637 638 void bpf_gen__record_attach_target(struct bpf_gen *gen, const char *attach_name, 639 enum bpf_attach_type type) 640 { 641 const char *prefix; 642 int kind, ret; 643 644 btf_get_kernel_prefix_kind(type, &prefix, &kind); 645 gen->attach_kind = kind; 646 ret = snprintf(gen->attach_target, sizeof(gen->attach_target), "%s%s", 647 prefix, attach_name); 648 if (ret >= sizeof(gen->attach_target)) 649 gen->error = -ENOSPC; 650 } 651 652 static void emit_find_attach_target(struct bpf_gen *gen) 653 { 654 int name, len = strlen(gen->attach_target) + 1; 655 656 pr_debug("gen: find_attach_tgt %s %d\n", gen->attach_target, gen->attach_kind); 657 name = add_data(gen, gen->attach_target, len); 658 659 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 660 0, 0, 0, name)); 661 emit(gen, BPF_MOV64_IMM(BPF_REG_2, len)); 662 emit(gen, BPF_MOV64_IMM(BPF_REG_3, gen->attach_kind)); 663 emit(gen, BPF_MOV64_IMM(BPF_REG_4, 0)); 664 emit(gen, BPF_EMIT_CALL(BPF_FUNC_btf_find_by_name_kind)); 665 emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0)); 666 debug_ret(gen, "find_by_name_kind(%s,%d)", 667 gen->attach_target, gen->attach_kind); 668 emit_check_err(gen); 669 /* if successful, btf_id is in lower 32-bit of R7 and 670 * btf_obj_fd is in upper 32-bit 671 */ 672 } 673 674 void bpf_gen__record_extern(struct bpf_gen *gen, const char *name, bool is_weak, 675 bool is_typeless, bool is_ld64, int kind, int insn_idx) 676 { 677 struct ksym_relo_desc *relo; 678 679 relo = libbpf_reallocarray(gen->relos, gen->relo_cnt + 1, sizeof(*relo)); 680 if (!relo) { 681 gen->error = -ENOMEM; 682 return; 683 } 684 gen->relos = relo; 685 relo += gen->relo_cnt; 686 relo->name = name; 687 relo->is_weak = is_weak; 688 relo->is_typeless = is_typeless; 689 relo->is_ld64 = is_ld64; 690 relo->kind = kind; 691 relo->insn_idx = insn_idx; 692 gen->relo_cnt++; 693 } 694 695 /* returns existing ksym_desc with ref incremented, or inserts a new one */ 696 static struct ksym_desc *get_ksym_desc(struct bpf_gen *gen, struct ksym_relo_desc *relo) 697 { 698 struct ksym_desc *kdesc; 699 int i; 700 701 for (i = 0; i < gen->nr_ksyms; i++) { 702 kdesc = &gen->ksyms[i]; 703 if (kdesc->kind == relo->kind && kdesc->is_ld64 == relo->is_ld64 && 704 !strcmp(kdesc->name, relo->name)) { 705 kdesc->ref++; 706 return kdesc; 707 } 708 } 709 kdesc = libbpf_reallocarray(gen->ksyms, gen->nr_ksyms + 1, sizeof(*kdesc)); 710 if (!kdesc) { 711 gen->error = -ENOMEM; 712 return NULL; 713 } 714 gen->ksyms = kdesc; 715 kdesc = &gen->ksyms[gen->nr_ksyms++]; 716 kdesc->name = relo->name; 717 kdesc->kind = relo->kind; 718 kdesc->ref = 1; 719 kdesc->off = 0; 720 kdesc->insn = 0; 721 kdesc->is_ld64 = relo->is_ld64; 722 return kdesc; 723 } 724 725 /* Overwrites BPF_REG_{0, 1, 2, 3, 4, 7} 726 * Returns result in BPF_REG_7 727 */ 728 static void emit_bpf_find_by_name_kind(struct bpf_gen *gen, struct ksym_relo_desc *relo) 729 { 730 int name_off, len = strlen(relo->name) + 1; 731 732 name_off = add_data(gen, relo->name, len); 733 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 734 0, 0, 0, name_off)); 735 emit(gen, BPF_MOV64_IMM(BPF_REG_2, len)); 736 emit(gen, BPF_MOV64_IMM(BPF_REG_3, relo->kind)); 737 emit(gen, BPF_MOV64_IMM(BPF_REG_4, 0)); 738 emit(gen, BPF_EMIT_CALL(BPF_FUNC_btf_find_by_name_kind)); 739 emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0)); 740 debug_ret(gen, "find_by_name_kind(%s,%d)", relo->name, relo->kind); 741 } 742 743 /* Overwrites BPF_REG_{0, 1, 2, 3, 4, 7} 744 * Returns result in BPF_REG_7 745 * Returns u64 symbol addr in BPF_REG_9 746 */ 747 static void emit_bpf_kallsyms_lookup_name(struct bpf_gen *gen, struct ksym_relo_desc *relo) 748 { 749 int name_off, len = strlen(relo->name) + 1, res_off; 750 751 name_off = add_data(gen, relo->name, len); 752 res_off = add_data(gen, NULL, 8); /* res is u64 */ 753 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 754 0, 0, 0, name_off)); 755 emit(gen, BPF_MOV64_IMM(BPF_REG_2, len)); 756 emit(gen, BPF_MOV64_IMM(BPF_REG_3, 0)); 757 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_4, BPF_PSEUDO_MAP_IDX_VALUE, 758 0, 0, 0, res_off)); 759 emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_4)); 760 emit(gen, BPF_EMIT_CALL(BPF_FUNC_kallsyms_lookup_name)); 761 emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_9, BPF_REG_7, 0)); 762 emit(gen, BPF_MOV64_REG(BPF_REG_7, BPF_REG_0)); 763 debug_ret(gen, "kallsyms_lookup_name(%s,%d)", relo->name, relo->kind); 764 } 765 766 /* Expects: 767 * BPF_REG_8 - pointer to instruction 768 * 769 * We need to reuse BTF fd for same symbol otherwise each relocation takes a new 770 * index, while kernel limits total kfunc BTFs to 256. For duplicate symbols, 771 * this would mean a new BTF fd index for each entry. By pairing symbol name 772 * with index, we get the insn->imm, insn->off pairing that kernel uses for 773 * kfunc_tab, which becomes the effective limit even though all of them may 774 * share same index in fd_array (such that kfunc_btf_tab has 1 element). 775 */ 776 static void emit_relo_kfunc_btf(struct bpf_gen *gen, struct ksym_relo_desc *relo, int insn) 777 { 778 struct ksym_desc *kdesc; 779 int btf_fd_idx; 780 781 kdesc = get_ksym_desc(gen, relo); 782 if (!kdesc) 783 return; 784 /* try to copy from existing bpf_insn */ 785 if (kdesc->ref > 1) { 786 move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4, 787 kdesc->insn + offsetof(struct bpf_insn, imm)); 788 move_blob2blob(gen, insn + offsetof(struct bpf_insn, off), 2, 789 kdesc->insn + offsetof(struct bpf_insn, off)); 790 goto log; 791 } 792 /* remember insn offset, so we can copy BTF ID and FD later */ 793 kdesc->insn = insn; 794 emit_bpf_find_by_name_kind(gen, relo); 795 if (!relo->is_weak) 796 emit_check_err(gen); 797 /* get index in fd_array to store BTF FD at */ 798 btf_fd_idx = add_kfunc_btf_fd(gen); 799 if (btf_fd_idx > INT16_MAX) { 800 pr_warn("BTF fd off %d for kfunc %s exceeds INT16_MAX, cannot process relocation\n", 801 btf_fd_idx, relo->name); 802 gen->error = -E2BIG; 803 return; 804 } 805 kdesc->off = btf_fd_idx; 806 /* jump to success case */ 807 emit(gen, BPF_JMP_IMM(BPF_JSGE, BPF_REG_7, 0, 3)); 808 /* set value for imm, off as 0 */ 809 emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, offsetof(struct bpf_insn, imm), 0)); 810 emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), 0)); 811 /* skip success case for ret < 0 */ 812 emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 10)); 813 /* store btf_id into insn[insn_idx].imm */ 814 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_7, offsetof(struct bpf_insn, imm))); 815 /* obtain fd in BPF_REG_9 */ 816 emit(gen, BPF_MOV64_REG(BPF_REG_9, BPF_REG_7)); 817 emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_9, 32)); 818 /* load fd_array slot pointer */ 819 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE, 820 0, 0, 0, blob_fd_array_off(gen, btf_fd_idx))); 821 /* store BTF fd in slot, 0 for vmlinux */ 822 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_0, BPF_REG_9, 0)); 823 /* jump to insn[insn_idx].off store if fd denotes module BTF */ 824 emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_9, 0, 2)); 825 /* set the default value for off */ 826 emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), 0)); 827 /* skip BTF fd store for vmlinux BTF */ 828 emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1)); 829 /* store index into insn[insn_idx].off */ 830 emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), btf_fd_idx)); 831 log: 832 if (!gen->log_level) 833 return; 834 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_8, 835 offsetof(struct bpf_insn, imm))); 836 emit(gen, BPF_LDX_MEM(BPF_H, BPF_REG_9, BPF_REG_8, 837 offsetof(struct bpf_insn, off))); 838 debug_regs(gen, BPF_REG_7, BPF_REG_9, " func (%s:count=%d): imm: %%d, off: %%d", 839 relo->name, kdesc->ref); 840 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE, 841 0, 0, 0, blob_fd_array_off(gen, kdesc->off))); 842 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_9, BPF_REG_0, 0)); 843 debug_regs(gen, BPF_REG_9, -1, " func (%s:count=%d): btf_fd", 844 relo->name, kdesc->ref); 845 } 846 847 static void emit_ksym_relo_log(struct bpf_gen *gen, struct ksym_relo_desc *relo, 848 int ref) 849 { 850 if (!gen->log_level) 851 return; 852 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_8, 853 offsetof(struct bpf_insn, imm))); 854 emit(gen, BPF_LDX_MEM(BPF_H, BPF_REG_9, BPF_REG_8, sizeof(struct bpf_insn) + 855 offsetof(struct bpf_insn, imm))); 856 debug_regs(gen, BPF_REG_7, BPF_REG_9, " var t=%d w=%d (%s:count=%d): imm[0]: %%d, imm[1]: %%d", 857 relo->is_typeless, relo->is_weak, relo->name, ref); 858 emit(gen, BPF_LDX_MEM(BPF_B, BPF_REG_9, BPF_REG_8, offsetofend(struct bpf_insn, code))); 859 debug_regs(gen, BPF_REG_9, -1, " var t=%d w=%d (%s:count=%d): insn.reg", 860 relo->is_typeless, relo->is_weak, relo->name, ref); 861 } 862 863 /* Expects: 864 * BPF_REG_8 - pointer to instruction 865 */ 866 static void emit_relo_ksym_typeless(struct bpf_gen *gen, 867 struct ksym_relo_desc *relo, int insn) 868 { 869 struct ksym_desc *kdesc; 870 871 kdesc = get_ksym_desc(gen, relo); 872 if (!kdesc) 873 return; 874 /* try to copy from existing ldimm64 insn */ 875 if (kdesc->ref > 1) { 876 move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4, 877 kdesc->insn + offsetof(struct bpf_insn, imm)); 878 move_blob2blob(gen, insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm), 4, 879 kdesc->insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm)); 880 goto log; 881 } 882 /* remember insn offset, so we can copy ksym addr later */ 883 kdesc->insn = insn; 884 /* skip typeless ksym_desc in fd closing loop in cleanup_relos */ 885 kdesc->typeless = true; 886 emit_bpf_kallsyms_lookup_name(gen, relo); 887 emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_7, -ENOENT, 1)); 888 emit_check_err(gen); 889 /* store lower half of addr into insn[insn_idx].imm */ 890 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_9, offsetof(struct bpf_insn, imm))); 891 /* store upper half of addr into insn[insn_idx + 1].imm */ 892 emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_9, 32)); 893 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_9, 894 sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm))); 895 log: 896 emit_ksym_relo_log(gen, relo, kdesc->ref); 897 } 898 899 static __u32 src_reg_mask(struct bpf_gen *gen) 900 { 901 #if defined(__LITTLE_ENDIAN_BITFIELD) /* src_reg,dst_reg,... */ 902 return gen->swapped_endian ? 0xf0 : 0x0f; 903 #elif defined(__BIG_ENDIAN_BITFIELD) /* dst_reg,src_reg,... */ 904 return gen->swapped_endian ? 0x0f : 0xf0; 905 #else 906 #error "Unsupported bit endianness, cannot proceed" 907 #endif 908 } 909 910 /* Expects: 911 * BPF_REG_8 - pointer to instruction 912 */ 913 static void emit_relo_ksym_btf(struct bpf_gen *gen, struct ksym_relo_desc *relo, int insn) 914 { 915 struct ksym_desc *kdesc; 916 __u32 reg_mask; 917 918 kdesc = get_ksym_desc(gen, relo); 919 if (!kdesc) 920 return; 921 /* try to copy from existing ldimm64 insn */ 922 if (kdesc->ref > 1) { 923 move_blob2blob(gen, insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm), 4, 924 kdesc->insn + sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm)); 925 move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4, 926 kdesc->insn + offsetof(struct bpf_insn, imm)); 927 /* jump over src_reg adjustment if imm (btf_id) is not 0, reuse BPF_REG_0 from move_blob2blob 928 * If btf_id is zero, clear BPF_PSEUDO_BTF_ID flag in src_reg of ld_imm64 insn 929 */ 930 emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_0, 0, 3)); 931 goto clear_src_reg; 932 } 933 /* remember insn offset, so we can copy BTF ID and FD later */ 934 kdesc->insn = insn; 935 emit_bpf_find_by_name_kind(gen, relo); 936 if (!relo->is_weak) 937 emit_check_err(gen); 938 /* jump to success case */ 939 emit(gen, BPF_JMP_IMM(BPF_JSGE, BPF_REG_7, 0, 3)); 940 /* set values for insn[insn_idx].imm, insn[insn_idx + 1].imm as 0 */ 941 emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, offsetof(struct bpf_insn, imm), 0)); 942 emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm), 0)); 943 /* skip success case for ret < 0 */ 944 emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 4)); 945 /* store btf_id into insn[insn_idx].imm */ 946 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_7, offsetof(struct bpf_insn, imm))); 947 /* store btf_obj_fd into insn[insn_idx + 1].imm */ 948 emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_7, 32)); 949 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_8, BPF_REG_7, 950 sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm))); 951 /* skip src_reg adjustment */ 952 emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 3)); 953 clear_src_reg: 954 /* clear bpf_object__relocate_data's src_reg assignment, otherwise we get a verifier failure */ 955 reg_mask = src_reg_mask(gen); 956 emit(gen, BPF_LDX_MEM(BPF_B, BPF_REG_9, BPF_REG_8, offsetofend(struct bpf_insn, code))); 957 emit(gen, BPF_ALU32_IMM(BPF_AND, BPF_REG_9, reg_mask)); 958 emit(gen, BPF_STX_MEM(BPF_B, BPF_REG_8, BPF_REG_9, offsetofend(struct bpf_insn, code))); 959 960 emit_ksym_relo_log(gen, relo, kdesc->ref); 961 } 962 963 void bpf_gen__record_relo_core(struct bpf_gen *gen, 964 const struct bpf_core_relo *core_relo) 965 { 966 struct bpf_core_relo *relos; 967 968 relos = libbpf_reallocarray(gen->core_relos, gen->core_relo_cnt + 1, sizeof(*relos)); 969 if (!relos) { 970 gen->error = -ENOMEM; 971 return; 972 } 973 gen->core_relos = relos; 974 relos += gen->core_relo_cnt; 975 memcpy(relos, core_relo, sizeof(*relos)); 976 gen->core_relo_cnt++; 977 } 978 979 static void emit_relo(struct bpf_gen *gen, struct ksym_relo_desc *relo, int insns) 980 { 981 int insn; 982 983 pr_debug("gen: emit_relo (%d): %s at %d %s\n", 984 relo->kind, relo->name, relo->insn_idx, relo->is_ld64 ? "ld64" : "call"); 985 insn = insns + sizeof(struct bpf_insn) * relo->insn_idx; 986 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_8, BPF_PSEUDO_MAP_IDX_VALUE, 0, 0, 0, insn)); 987 if (relo->is_ld64) { 988 if (relo->is_typeless) 989 emit_relo_ksym_typeless(gen, relo, insn); 990 else 991 emit_relo_ksym_btf(gen, relo, insn); 992 } else { 993 emit_relo_kfunc_btf(gen, relo, insn); 994 } 995 } 996 997 static void emit_relos(struct bpf_gen *gen, int insns) 998 { 999 int i; 1000 1001 for (i = 0; i < gen->relo_cnt; i++) 1002 emit_relo(gen, gen->relos + i, insns); 1003 } 1004 1005 static void cleanup_core_relo(struct bpf_gen *gen) 1006 { 1007 if (!gen->core_relo_cnt) 1008 return; 1009 free(gen->core_relos); 1010 gen->core_relo_cnt = 0; 1011 gen->core_relos = NULL; 1012 } 1013 1014 static void cleanup_relos(struct bpf_gen *gen, int insns) 1015 { 1016 struct ksym_desc *kdesc; 1017 int i, insn; 1018 1019 for (i = 0; i < gen->nr_ksyms; i++) { 1020 kdesc = &gen->ksyms[i]; 1021 /* only close fds for typed ksyms and kfuncs */ 1022 if (kdesc->is_ld64 && !kdesc->typeless) { 1023 /* close fd recorded in insn[insn_idx + 1].imm */ 1024 insn = kdesc->insn; 1025 insn += sizeof(struct bpf_insn) + offsetof(struct bpf_insn, imm); 1026 emit_sys_close_blob(gen, insn); 1027 } else if (!kdesc->is_ld64) { 1028 emit_sys_close_blob(gen, blob_fd_array_off(gen, kdesc->off)); 1029 if (kdesc->off < MAX_FD_ARRAY_SZ) 1030 gen->nr_fd_array--; 1031 } 1032 } 1033 if (gen->nr_ksyms) { 1034 free(gen->ksyms); 1035 gen->nr_ksyms = 0; 1036 gen->ksyms = NULL; 1037 } 1038 if (gen->relo_cnt) { 1039 free(gen->relos); 1040 gen->relo_cnt = 0; 1041 gen->relos = NULL; 1042 } 1043 cleanup_core_relo(gen); 1044 } 1045 1046 /* Convert func, line, and core relo info blobs to target endianness */ 1047 static void info_blob_bswap(struct bpf_gen *gen, int func_info, int line_info, 1048 int core_relos, struct bpf_prog_load_opts *load_attr) 1049 { 1050 struct bpf_func_info *fi = gen->data_start + func_info; 1051 struct bpf_line_info *li = gen->data_start + line_info; 1052 struct bpf_core_relo *cr = gen->data_start + core_relos; 1053 int i; 1054 1055 for (i = 0; i < load_attr->func_info_cnt; i++) 1056 bpf_func_info_bswap(fi++); 1057 1058 for (i = 0; i < load_attr->line_info_cnt; i++) 1059 bpf_line_info_bswap(li++); 1060 1061 for (i = 0; i < gen->core_relo_cnt; i++) 1062 bpf_core_relo_bswap(cr++); 1063 } 1064 1065 void bpf_gen__prog_load(struct bpf_gen *gen, 1066 enum bpf_prog_type prog_type, const char *prog_name, 1067 const char *license, struct bpf_insn *insns, size_t insn_cnt, 1068 struct bpf_prog_load_opts *load_attr, int prog_idx) 1069 { 1070 int func_info_tot_sz = load_attr->func_info_cnt * 1071 load_attr->func_info_rec_size; 1072 int line_info_tot_sz = load_attr->line_info_cnt * 1073 load_attr->line_info_rec_size; 1074 int core_relo_tot_sz = gen->core_relo_cnt * 1075 sizeof(struct bpf_core_relo); 1076 int prog_load_attr, license_off, insns_off, func_info, line_info, core_relos; 1077 int attr_size = offsetofend(union bpf_attr, core_relo_rec_size); 1078 union bpf_attr attr; 1079 1080 memset(&attr, 0, attr_size); 1081 /* add license string to blob of bytes */ 1082 license_off = add_data(gen, license, strlen(license) + 1); 1083 /* add insns to blob of bytes */ 1084 insns_off = add_data(gen, insns, insn_cnt * sizeof(struct bpf_insn)); 1085 pr_debug("gen: prog_load: prog_idx %d type %d insn off %d insns_cnt %zd license off %d\n", 1086 prog_idx, prog_type, insns_off, insn_cnt, license_off); 1087 1088 /* convert blob insns to target endianness */ 1089 if (gen->swapped_endian && !gen->error) { 1090 struct bpf_insn *insn = gen->data_start + insns_off; 1091 int i; 1092 1093 for (i = 0; i < insn_cnt; i++, insn++) 1094 bpf_insn_bswap(insn); 1095 } 1096 1097 attr.prog_type = tgt_endian(prog_type); 1098 attr.expected_attach_type = tgt_endian(load_attr->expected_attach_type); 1099 attr.attach_btf_id = tgt_endian(load_attr->attach_btf_id); 1100 attr.prog_ifindex = tgt_endian(load_attr->prog_ifindex); 1101 attr.kern_version = 0; 1102 attr.insn_cnt = tgt_endian((__u32)insn_cnt); 1103 attr.prog_flags = tgt_endian(load_attr->prog_flags); 1104 1105 attr.func_info_rec_size = tgt_endian(load_attr->func_info_rec_size); 1106 attr.func_info_cnt = tgt_endian(load_attr->func_info_cnt); 1107 func_info = add_data(gen, load_attr->func_info, func_info_tot_sz); 1108 pr_debug("gen: prog_load: func_info: off %d cnt %d rec size %d\n", 1109 func_info, load_attr->func_info_cnt, 1110 load_attr->func_info_rec_size); 1111 1112 attr.line_info_rec_size = tgt_endian(load_attr->line_info_rec_size); 1113 attr.line_info_cnt = tgt_endian(load_attr->line_info_cnt); 1114 line_info = add_data(gen, load_attr->line_info, line_info_tot_sz); 1115 pr_debug("gen: prog_load: line_info: off %d cnt %d rec size %d\n", 1116 line_info, load_attr->line_info_cnt, 1117 load_attr->line_info_rec_size); 1118 1119 attr.core_relo_rec_size = tgt_endian((__u32)sizeof(struct bpf_core_relo)); 1120 attr.core_relo_cnt = tgt_endian(gen->core_relo_cnt); 1121 core_relos = add_data(gen, gen->core_relos, core_relo_tot_sz); 1122 pr_debug("gen: prog_load: core_relos: off %d cnt %d rec size %zd\n", 1123 core_relos, gen->core_relo_cnt, 1124 sizeof(struct bpf_core_relo)); 1125 1126 /* convert all info blobs to target endianness */ 1127 if (gen->swapped_endian && !gen->error) 1128 info_blob_bswap(gen, func_info, line_info, core_relos, load_attr); 1129 1130 libbpf_strlcpy(attr.prog_name, prog_name, sizeof(attr.prog_name)); 1131 prog_load_attr = add_data(gen, &attr, attr_size); 1132 pr_debug("gen: prog_load: attr: off %d size %d\n", 1133 prog_load_attr, attr_size); 1134 1135 /* populate union bpf_attr with a pointer to license */ 1136 emit_rel_store(gen, attr_field(prog_load_attr, license), license_off); 1137 1138 /* populate union bpf_attr with a pointer to instructions */ 1139 emit_rel_store(gen, attr_field(prog_load_attr, insns), insns_off); 1140 1141 /* populate union bpf_attr with a pointer to func_info */ 1142 emit_rel_store(gen, attr_field(prog_load_attr, func_info), func_info); 1143 1144 /* populate union bpf_attr with a pointer to line_info */ 1145 emit_rel_store(gen, attr_field(prog_load_attr, line_info), line_info); 1146 1147 /* populate union bpf_attr with a pointer to core_relos */ 1148 emit_rel_store(gen, attr_field(prog_load_attr, core_relos), core_relos); 1149 1150 /* populate union bpf_attr fd_array with a pointer to data where map_fds are saved */ 1151 emit_rel_store(gen, attr_field(prog_load_attr, fd_array), gen->fd_array); 1152 1153 /* populate union bpf_attr with user provided log details */ 1154 move_ctx2blob(gen, attr_field(prog_load_attr, log_level), 4, 1155 offsetof(struct bpf_loader_ctx, log_level), false); 1156 move_ctx2blob(gen, attr_field(prog_load_attr, log_size), 4, 1157 offsetof(struct bpf_loader_ctx, log_size), false); 1158 move_ctx2blob(gen, attr_field(prog_load_attr, log_buf), 8, 1159 offsetof(struct bpf_loader_ctx, log_buf), false); 1160 /* populate union bpf_attr with btf_fd saved in the stack earlier */ 1161 move_stack2blob(gen, attr_field(prog_load_attr, prog_btf_fd), 4, 1162 stack_off(btf_fd)); 1163 if (gen->attach_kind) { 1164 emit_find_attach_target(gen); 1165 /* populate union bpf_attr with btf_id and btf_obj_fd found by helper */ 1166 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_0, BPF_PSEUDO_MAP_IDX_VALUE, 1167 0, 0, 0, prog_load_attr)); 1168 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_0, BPF_REG_7, 1169 offsetof(union bpf_attr, attach_btf_id))); 1170 emit(gen, BPF_ALU64_IMM(BPF_RSH, BPF_REG_7, 32)); 1171 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_0, BPF_REG_7, 1172 offsetof(union bpf_attr, attach_btf_obj_fd))); 1173 } 1174 emit_relos(gen, insns_off); 1175 /* emit PROG_LOAD command */ 1176 emit_sys_bpf(gen, BPF_PROG_LOAD, prog_load_attr, attr_size); 1177 debug_ret(gen, "prog_load %s insn_cnt %d", attr.prog_name, attr.insn_cnt); 1178 /* successful or not, close btf module FDs used in extern ksyms and attach_btf_obj_fd */ 1179 cleanup_relos(gen, insns_off); 1180 if (gen->attach_kind) { 1181 emit_sys_close_blob(gen, 1182 attr_field(prog_load_attr, attach_btf_obj_fd)); 1183 gen->attach_kind = 0; 1184 } 1185 emit_check_err(gen); 1186 /* remember prog_fd in the stack, if successful */ 1187 emit(gen, BPF_STX_MEM(BPF_W, BPF_REG_10, BPF_REG_7, 1188 stack_off(prog_fd[gen->nr_progs]))); 1189 gen->nr_progs++; 1190 } 1191 1192 void bpf_gen__map_update_elem(struct bpf_gen *gen, int map_idx, void *pvalue, 1193 __u32 value_size) 1194 { 1195 int attr_size = offsetofend(union bpf_attr, flags); 1196 int map_update_attr, value, key; 1197 union bpf_attr attr; 1198 int zero = 0; 1199 1200 memset(&attr, 0, attr_size); 1201 1202 value = add_data(gen, pvalue, value_size); 1203 key = add_data(gen, &zero, sizeof(zero)); 1204 1205 /* 1206 * if (map_desc[map_idx].initial_value) { 1207 * if (ctx->flags & BPF_SKEL_KERNEL) 1208 * bpf_probe_read_kernel(value, value_size, initial_value); 1209 * else 1210 * bpf_copy_from_user(value, value_size, initial_value); 1211 * } 1212 * 1213 * The runtime initial_value comes from the host-supplied loader 1214 * ctx and would overwrite the blob value after emit_signature_match() 1215 * has already validated map->sha[]. For a signed loader (gen_hash) 1216 * the attested blob value must be authoritative, so skip the override 1217 * and leave the hashed value in place. 1218 */ 1219 if (!OPTS_GET(gen->opts, gen_hash, false)) { 1220 emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_3, BPF_REG_6, 1221 sizeof(struct bpf_loader_ctx) + 1222 sizeof(struct bpf_map_desc) * map_idx + 1223 offsetof(struct bpf_map_desc, initial_value))); 1224 emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_3, 0, 8)); 1225 emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE, 1226 0, 0, 0, value)); 1227 emit(gen, BPF_MOV64_IMM(BPF_REG_2, value_size)); 1228 emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_0, BPF_REG_6, 1229 offsetof(struct bpf_loader_ctx, flags))); 1230 emit(gen, BPF_JMP_IMM(BPF_JSET, BPF_REG_0, BPF_SKEL_KERNEL, 2)); 1231 emit(gen, BPF_EMIT_CALL(BPF_FUNC_copy_from_user)); 1232 emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1)); 1233 emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel)); 1234 } 1235 1236 map_update_attr = add_data(gen, &attr, attr_size); 1237 pr_debug("gen: map_update_elem: idx %d, value: off %d size %d, attr: off %d size %d\n", 1238 map_idx, value, value_size, map_update_attr, attr_size); 1239 move_blob2blob(gen, attr_field(map_update_attr, map_fd), 4, 1240 blob_fd_array_off(gen, map_idx)); 1241 emit_rel_store(gen, attr_field(map_update_attr, key), key); 1242 emit_rel_store(gen, attr_field(map_update_attr, value), value); 1243 /* emit MAP_UPDATE_ELEM command */ 1244 emit_sys_bpf(gen, BPF_MAP_UPDATE_ELEM, map_update_attr, attr_size); 1245 debug_ret(gen, "update_elem idx %d value_size %d", map_idx, value_size); 1246 emit_check_err(gen); 1247 } 1248 1249 void bpf_gen__populate_outer_map(struct bpf_gen *gen, int outer_map_idx, int slot, 1250 int inner_map_idx) 1251 { 1252 int attr_size = offsetofend(union bpf_attr, flags); 1253 int map_update_attr, key; 1254 union bpf_attr attr; 1255 int tgt_slot; 1256 1257 memset(&attr, 0, attr_size); 1258 1259 tgt_slot = tgt_endian(slot); 1260 key = add_data(gen, &tgt_slot, sizeof(tgt_slot)); 1261 1262 map_update_attr = add_data(gen, &attr, attr_size); 1263 pr_debug("gen: populate_outer_map: outer %d key %d inner %d, attr: off %d size %d\n", 1264 outer_map_idx, slot, inner_map_idx, map_update_attr, attr_size); 1265 move_blob2blob(gen, attr_field(map_update_attr, map_fd), 4, 1266 blob_fd_array_off(gen, outer_map_idx)); 1267 emit_rel_store(gen, attr_field(map_update_attr, key), key); 1268 emit_rel_store(gen, attr_field(map_update_attr, value), 1269 blob_fd_array_off(gen, inner_map_idx)); 1270 1271 /* emit MAP_UPDATE_ELEM command */ 1272 emit_sys_bpf(gen, BPF_MAP_UPDATE_ELEM, map_update_attr, attr_size); 1273 debug_ret(gen, "populate_outer_map outer %d key %d inner %d", 1274 outer_map_idx, slot, inner_map_idx); 1275 emit_check_err(gen); 1276 } 1277 1278 void bpf_gen__map_freeze(struct bpf_gen *gen, int map_idx) 1279 { 1280 int attr_size = offsetofend(union bpf_attr, map_fd); 1281 int map_freeze_attr; 1282 union bpf_attr attr; 1283 1284 memset(&attr, 0, attr_size); 1285 map_freeze_attr = add_data(gen, &attr, attr_size); 1286 pr_debug("gen: map_freeze: idx %d, attr: off %d size %d\n", 1287 map_idx, map_freeze_attr, attr_size); 1288 move_blob2blob(gen, attr_field(map_freeze_attr, map_fd), 4, 1289 blob_fd_array_off(gen, map_idx)); 1290 /* emit MAP_FREEZE command */ 1291 emit_sys_bpf(gen, BPF_MAP_FREEZE, map_freeze_attr, attr_size); 1292 debug_ret(gen, "map_freeze"); 1293 emit_check_err(gen); 1294 } 1295