1 // SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause) 2 3 /* 4 * common eBPF ELF operations. 5 * 6 * Copyright (C) 2013-2015 Alexei Starovoitov <ast@kernel.org> 7 * Copyright (C) 2015 Wang Nan <wangnan0@huawei.com> 8 * Copyright (C) 2015 Huawei Inc. 9 * 10 * This program is free software; you can redistribute it and/or 11 * modify it under the terms of the GNU Lesser General Public 12 * License as published by the Free Software Foundation; 13 * version 2.1 of the License (not later!) 14 * 15 * This program is distributed in the hope that it will be useful, 16 * but WITHOUT ANY WARRANTY; without even the implied warranty of 17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 18 * GNU Lesser General Public License for more details. 19 * 20 * You should have received a copy of the GNU Lesser General Public 21 * License along with this program; if not, see <http://www.gnu.org/licenses> 22 */ 23 24 #include <stdlib.h> 25 #include <string.h> 26 #include <memory.h> 27 #include <unistd.h> 28 #include <asm/unistd.h> 29 #include <linux/bpf.h> 30 #include "bpf.h" 31 #include "libbpf.h" 32 #include <errno.h> 33 34 /* 35 * When building perf, unistd.h is overridden. __NR_bpf is 36 * required to be defined explicitly. 37 */ 38 #ifndef __NR_bpf 39 # if defined(__i386__) 40 # define __NR_bpf 357 41 # elif defined(__x86_64__) 42 # define __NR_bpf 321 43 # elif defined(__aarch64__) 44 # define __NR_bpf 280 45 # elif defined(__sparc__) 46 # define __NR_bpf 349 47 # elif defined(__s390__) 48 # define __NR_bpf 351 49 # elif defined(__arc__) 50 # define __NR_bpf 280 51 # else 52 # error __NR_bpf not defined. libbpf does not support your arch. 53 # endif 54 #endif 55 56 #ifndef min 57 #define min(x, y) ((x) < (y) ? (x) : (y)) 58 #endif 59 60 static inline __u64 ptr_to_u64(const void *ptr) 61 { 62 return (__u64) (unsigned long) ptr; 63 } 64 65 static inline int sys_bpf(enum bpf_cmd cmd, union bpf_attr *attr, 66 unsigned int size) 67 { 68 return syscall(__NR_bpf, cmd, attr, size); 69 } 70 71 static inline int sys_bpf_prog_load(union bpf_attr *attr, unsigned int size) 72 { 73 int fd; 74 75 do { 76 fd = sys_bpf(BPF_PROG_LOAD, attr, size); 77 } while (fd < 0 && errno == EAGAIN); 78 79 return fd; 80 } 81 82 int bpf_create_map_xattr(const struct bpf_create_map_attr *create_attr) 83 { 84 union bpf_attr attr; 85 86 memset(&attr, '\0', sizeof(attr)); 87 88 attr.map_type = create_attr->map_type; 89 attr.key_size = create_attr->key_size; 90 attr.value_size = create_attr->value_size; 91 attr.max_entries = create_attr->max_entries; 92 attr.map_flags = create_attr->map_flags; 93 if (create_attr->name) 94 memcpy(attr.map_name, create_attr->name, 95 min(strlen(create_attr->name), BPF_OBJ_NAME_LEN - 1)); 96 attr.numa_node = create_attr->numa_node; 97 attr.btf_fd = create_attr->btf_fd; 98 attr.btf_key_type_id = create_attr->btf_key_type_id; 99 attr.btf_value_type_id = create_attr->btf_value_type_id; 100 attr.map_ifindex = create_attr->map_ifindex; 101 attr.inner_map_fd = create_attr->inner_map_fd; 102 103 return sys_bpf(BPF_MAP_CREATE, &attr, sizeof(attr)); 104 } 105 106 int bpf_create_map_node(enum bpf_map_type map_type, const char *name, 107 int key_size, int value_size, int max_entries, 108 __u32 map_flags, int node) 109 { 110 struct bpf_create_map_attr map_attr = {}; 111 112 map_attr.name = name; 113 map_attr.map_type = map_type; 114 map_attr.map_flags = map_flags; 115 map_attr.key_size = key_size; 116 map_attr.value_size = value_size; 117 map_attr.max_entries = max_entries; 118 if (node >= 0) { 119 map_attr.numa_node = node; 120 map_attr.map_flags |= BPF_F_NUMA_NODE; 121 } 122 123 return bpf_create_map_xattr(&map_attr); 124 } 125 126 int bpf_create_map(enum bpf_map_type map_type, int key_size, 127 int value_size, int max_entries, __u32 map_flags) 128 { 129 struct bpf_create_map_attr map_attr = {}; 130 131 map_attr.map_type = map_type; 132 map_attr.map_flags = map_flags; 133 map_attr.key_size = key_size; 134 map_attr.value_size = value_size; 135 map_attr.max_entries = max_entries; 136 137 return bpf_create_map_xattr(&map_attr); 138 } 139 140 int bpf_create_map_name(enum bpf_map_type map_type, const char *name, 141 int key_size, int value_size, int max_entries, 142 __u32 map_flags) 143 { 144 struct bpf_create_map_attr map_attr = {}; 145 146 map_attr.name = name; 147 map_attr.map_type = map_type; 148 map_attr.map_flags = map_flags; 149 map_attr.key_size = key_size; 150 map_attr.value_size = value_size; 151 map_attr.max_entries = max_entries; 152 153 return bpf_create_map_xattr(&map_attr); 154 } 155 156 int bpf_create_map_in_map_node(enum bpf_map_type map_type, const char *name, 157 int key_size, int inner_map_fd, int max_entries, 158 __u32 map_flags, int node) 159 { 160 union bpf_attr attr; 161 162 memset(&attr, '\0', sizeof(attr)); 163 164 attr.map_type = map_type; 165 attr.key_size = key_size; 166 attr.value_size = 4; 167 attr.inner_map_fd = inner_map_fd; 168 attr.max_entries = max_entries; 169 attr.map_flags = map_flags; 170 if (name) 171 memcpy(attr.map_name, name, 172 min(strlen(name), BPF_OBJ_NAME_LEN - 1)); 173 174 if (node >= 0) { 175 attr.map_flags |= BPF_F_NUMA_NODE; 176 attr.numa_node = node; 177 } 178 179 return sys_bpf(BPF_MAP_CREATE, &attr, sizeof(attr)); 180 } 181 182 int bpf_create_map_in_map(enum bpf_map_type map_type, const char *name, 183 int key_size, int inner_map_fd, int max_entries, 184 __u32 map_flags) 185 { 186 return bpf_create_map_in_map_node(map_type, name, key_size, 187 inner_map_fd, max_entries, map_flags, 188 -1); 189 } 190 191 static void * 192 alloc_zero_tailing_info(const void *orecord, __u32 cnt, 193 __u32 actual_rec_size, __u32 expected_rec_size) 194 { 195 __u64 info_len = actual_rec_size * cnt; 196 void *info, *nrecord; 197 int i; 198 199 info = malloc(info_len); 200 if (!info) 201 return NULL; 202 203 /* zero out bytes kernel does not understand */ 204 nrecord = info; 205 for (i = 0; i < cnt; i++) { 206 memcpy(nrecord, orecord, expected_rec_size); 207 memset(nrecord + expected_rec_size, 0, 208 actual_rec_size - expected_rec_size); 209 orecord += actual_rec_size; 210 nrecord += actual_rec_size; 211 } 212 213 return info; 214 } 215 216 int bpf_load_program_xattr(const struct bpf_load_program_attr *load_attr, 217 char *log_buf, size_t log_buf_sz) 218 { 219 void *finfo = NULL, *linfo = NULL; 220 union bpf_attr attr; 221 __u32 log_level; 222 int fd; 223 224 if (!load_attr || !log_buf != !log_buf_sz) 225 return -EINVAL; 226 227 log_level = load_attr->log_level; 228 if (log_level > (4 | 2 | 1) || (log_level && !log_buf)) 229 return -EINVAL; 230 231 memset(&attr, 0, sizeof(attr)); 232 attr.prog_type = load_attr->prog_type; 233 attr.expected_attach_type = load_attr->expected_attach_type; 234 attr.insn_cnt = (__u32)load_attr->insns_cnt; 235 attr.insns = ptr_to_u64(load_attr->insns); 236 attr.license = ptr_to_u64(load_attr->license); 237 238 attr.log_level = log_level; 239 if (log_level) { 240 attr.log_buf = ptr_to_u64(log_buf); 241 attr.log_size = log_buf_sz; 242 } else { 243 attr.log_buf = ptr_to_u64(NULL); 244 attr.log_size = 0; 245 } 246 247 attr.kern_version = load_attr->kern_version; 248 attr.prog_ifindex = load_attr->prog_ifindex; 249 attr.prog_btf_fd = load_attr->prog_btf_fd; 250 attr.func_info_rec_size = load_attr->func_info_rec_size; 251 attr.func_info_cnt = load_attr->func_info_cnt; 252 attr.func_info = ptr_to_u64(load_attr->func_info); 253 attr.line_info_rec_size = load_attr->line_info_rec_size; 254 attr.line_info_cnt = load_attr->line_info_cnt; 255 attr.line_info = ptr_to_u64(load_attr->line_info); 256 if (load_attr->name) 257 memcpy(attr.prog_name, load_attr->name, 258 min(strlen(load_attr->name), BPF_OBJ_NAME_LEN - 1)); 259 attr.prog_flags = load_attr->prog_flags; 260 261 fd = sys_bpf_prog_load(&attr, sizeof(attr)); 262 if (fd >= 0) 263 return fd; 264 265 /* After bpf_prog_load, the kernel may modify certain attributes 266 * to give user space a hint how to deal with loading failure. 267 * Check to see whether we can make some changes and load again. 268 */ 269 while (errno == E2BIG && (!finfo || !linfo)) { 270 if (!finfo && attr.func_info_cnt && 271 attr.func_info_rec_size < load_attr->func_info_rec_size) { 272 /* try with corrected func info records */ 273 finfo = alloc_zero_tailing_info(load_attr->func_info, 274 load_attr->func_info_cnt, 275 load_attr->func_info_rec_size, 276 attr.func_info_rec_size); 277 if (!finfo) 278 goto done; 279 280 attr.func_info = ptr_to_u64(finfo); 281 attr.func_info_rec_size = load_attr->func_info_rec_size; 282 } else if (!linfo && attr.line_info_cnt && 283 attr.line_info_rec_size < 284 load_attr->line_info_rec_size) { 285 linfo = alloc_zero_tailing_info(load_attr->line_info, 286 load_attr->line_info_cnt, 287 load_attr->line_info_rec_size, 288 attr.line_info_rec_size); 289 if (!linfo) 290 goto done; 291 292 attr.line_info = ptr_to_u64(linfo); 293 attr.line_info_rec_size = load_attr->line_info_rec_size; 294 } else { 295 break; 296 } 297 298 fd = sys_bpf_prog_load(&attr, sizeof(attr)); 299 300 if (fd >= 0) 301 goto done; 302 } 303 304 if (log_level || !log_buf) 305 goto done; 306 307 /* Try again with log */ 308 attr.log_buf = ptr_to_u64(log_buf); 309 attr.log_size = log_buf_sz; 310 attr.log_level = 1; 311 log_buf[0] = 0; 312 fd = sys_bpf_prog_load(&attr, sizeof(attr)); 313 done: 314 free(finfo); 315 free(linfo); 316 return fd; 317 } 318 319 int bpf_load_program(enum bpf_prog_type type, const struct bpf_insn *insns, 320 size_t insns_cnt, const char *license, 321 __u32 kern_version, char *log_buf, 322 size_t log_buf_sz) 323 { 324 struct bpf_load_program_attr load_attr; 325 326 memset(&load_attr, 0, sizeof(struct bpf_load_program_attr)); 327 load_attr.prog_type = type; 328 load_attr.expected_attach_type = 0; 329 load_attr.name = NULL; 330 load_attr.insns = insns; 331 load_attr.insns_cnt = insns_cnt; 332 load_attr.license = license; 333 load_attr.kern_version = kern_version; 334 335 return bpf_load_program_xattr(&load_attr, log_buf, log_buf_sz); 336 } 337 338 int bpf_verify_program(enum bpf_prog_type type, const struct bpf_insn *insns, 339 size_t insns_cnt, __u32 prog_flags, const char *license, 340 __u32 kern_version, char *log_buf, size_t log_buf_sz, 341 int log_level) 342 { 343 union bpf_attr attr; 344 345 memset(&attr, 0, sizeof(attr)); 346 attr.prog_type = type; 347 attr.insn_cnt = (__u32)insns_cnt; 348 attr.insns = ptr_to_u64(insns); 349 attr.license = ptr_to_u64(license); 350 attr.log_buf = ptr_to_u64(log_buf); 351 attr.log_size = log_buf_sz; 352 attr.log_level = log_level; 353 log_buf[0] = 0; 354 attr.kern_version = kern_version; 355 attr.prog_flags = prog_flags; 356 357 return sys_bpf_prog_load(&attr, sizeof(attr)); 358 } 359 360 int bpf_map_update_elem(int fd, const void *key, const void *value, 361 __u64 flags) 362 { 363 union bpf_attr attr; 364 365 memset(&attr, 0, sizeof(attr)); 366 attr.map_fd = fd; 367 attr.key = ptr_to_u64(key); 368 attr.value = ptr_to_u64(value); 369 attr.flags = flags; 370 371 return sys_bpf(BPF_MAP_UPDATE_ELEM, &attr, sizeof(attr)); 372 } 373 374 int bpf_map_lookup_elem(int fd, const void *key, void *value) 375 { 376 union bpf_attr attr; 377 378 memset(&attr, 0, sizeof(attr)); 379 attr.map_fd = fd; 380 attr.key = ptr_to_u64(key); 381 attr.value = ptr_to_u64(value); 382 383 return sys_bpf(BPF_MAP_LOOKUP_ELEM, &attr, sizeof(attr)); 384 } 385 386 int bpf_map_lookup_elem_flags(int fd, const void *key, void *value, __u64 flags) 387 { 388 union bpf_attr attr; 389 390 memset(&attr, 0, sizeof(attr)); 391 attr.map_fd = fd; 392 attr.key = ptr_to_u64(key); 393 attr.value = ptr_to_u64(value); 394 attr.flags = flags; 395 396 return sys_bpf(BPF_MAP_LOOKUP_ELEM, &attr, sizeof(attr)); 397 } 398 399 int bpf_map_lookup_and_delete_elem(int fd, const void *key, void *value) 400 { 401 union bpf_attr attr; 402 403 memset(&attr, 0, sizeof(attr)); 404 attr.map_fd = fd; 405 attr.key = ptr_to_u64(key); 406 attr.value = ptr_to_u64(value); 407 408 return sys_bpf(BPF_MAP_LOOKUP_AND_DELETE_ELEM, &attr, sizeof(attr)); 409 } 410 411 int bpf_map_delete_elem(int fd, const void *key) 412 { 413 union bpf_attr attr; 414 415 memset(&attr, 0, sizeof(attr)); 416 attr.map_fd = fd; 417 attr.key = ptr_to_u64(key); 418 419 return sys_bpf(BPF_MAP_DELETE_ELEM, &attr, sizeof(attr)); 420 } 421 422 int bpf_map_get_next_key(int fd, const void *key, void *next_key) 423 { 424 union bpf_attr attr; 425 426 memset(&attr, 0, sizeof(attr)); 427 attr.map_fd = fd; 428 attr.key = ptr_to_u64(key); 429 attr.next_key = ptr_to_u64(next_key); 430 431 return sys_bpf(BPF_MAP_GET_NEXT_KEY, &attr, sizeof(attr)); 432 } 433 434 int bpf_map_freeze(int fd) 435 { 436 union bpf_attr attr; 437 438 memset(&attr, 0, sizeof(attr)); 439 attr.map_fd = fd; 440 441 return sys_bpf(BPF_MAP_FREEZE, &attr, sizeof(attr)); 442 } 443 444 int bpf_obj_pin(int fd, const char *pathname) 445 { 446 union bpf_attr attr; 447 448 memset(&attr, 0, sizeof(attr)); 449 attr.pathname = ptr_to_u64((void *)pathname); 450 attr.bpf_fd = fd; 451 452 return sys_bpf(BPF_OBJ_PIN, &attr, sizeof(attr)); 453 } 454 455 int bpf_obj_get(const char *pathname) 456 { 457 union bpf_attr attr; 458 459 memset(&attr, 0, sizeof(attr)); 460 attr.pathname = ptr_to_u64((void *)pathname); 461 462 return sys_bpf(BPF_OBJ_GET, &attr, sizeof(attr)); 463 } 464 465 int bpf_prog_attach(int prog_fd, int target_fd, enum bpf_attach_type type, 466 unsigned int flags) 467 { 468 union bpf_attr attr; 469 470 memset(&attr, 0, sizeof(attr)); 471 attr.target_fd = target_fd; 472 attr.attach_bpf_fd = prog_fd; 473 attr.attach_type = type; 474 attr.attach_flags = flags; 475 476 return sys_bpf(BPF_PROG_ATTACH, &attr, sizeof(attr)); 477 } 478 479 int bpf_prog_detach(int target_fd, enum bpf_attach_type type) 480 { 481 union bpf_attr attr; 482 483 memset(&attr, 0, sizeof(attr)); 484 attr.target_fd = target_fd; 485 attr.attach_type = type; 486 487 return sys_bpf(BPF_PROG_DETACH, &attr, sizeof(attr)); 488 } 489 490 int bpf_prog_detach2(int prog_fd, int target_fd, enum bpf_attach_type type) 491 { 492 union bpf_attr attr; 493 494 memset(&attr, 0, sizeof(attr)); 495 attr.target_fd = target_fd; 496 attr.attach_bpf_fd = prog_fd; 497 attr.attach_type = type; 498 499 return sys_bpf(BPF_PROG_DETACH, &attr, sizeof(attr)); 500 } 501 502 int bpf_prog_query(int target_fd, enum bpf_attach_type type, __u32 query_flags, 503 __u32 *attach_flags, __u32 *prog_ids, __u32 *prog_cnt) 504 { 505 union bpf_attr attr; 506 int ret; 507 508 memset(&attr, 0, sizeof(attr)); 509 attr.query.target_fd = target_fd; 510 attr.query.attach_type = type; 511 attr.query.query_flags = query_flags; 512 attr.query.prog_cnt = *prog_cnt; 513 attr.query.prog_ids = ptr_to_u64(prog_ids); 514 515 ret = sys_bpf(BPF_PROG_QUERY, &attr, sizeof(attr)); 516 if (attach_flags) 517 *attach_flags = attr.query.attach_flags; 518 *prog_cnt = attr.query.prog_cnt; 519 return ret; 520 } 521 522 int bpf_prog_test_run(int prog_fd, int repeat, void *data, __u32 size, 523 void *data_out, __u32 *size_out, __u32 *retval, 524 __u32 *duration) 525 { 526 union bpf_attr attr; 527 int ret; 528 529 memset(&attr, 0, sizeof(attr)); 530 attr.test.prog_fd = prog_fd; 531 attr.test.data_in = ptr_to_u64(data); 532 attr.test.data_out = ptr_to_u64(data_out); 533 attr.test.data_size_in = size; 534 attr.test.repeat = repeat; 535 536 ret = sys_bpf(BPF_PROG_TEST_RUN, &attr, sizeof(attr)); 537 if (size_out) 538 *size_out = attr.test.data_size_out; 539 if (retval) 540 *retval = attr.test.retval; 541 if (duration) 542 *duration = attr.test.duration; 543 return ret; 544 } 545 546 int bpf_prog_test_run_xattr(struct bpf_prog_test_run_attr *test_attr) 547 { 548 union bpf_attr attr; 549 int ret; 550 551 if (!test_attr->data_out && test_attr->data_size_out > 0) 552 return -EINVAL; 553 554 memset(&attr, 0, sizeof(attr)); 555 attr.test.prog_fd = test_attr->prog_fd; 556 attr.test.data_in = ptr_to_u64(test_attr->data_in); 557 attr.test.data_out = ptr_to_u64(test_attr->data_out); 558 attr.test.data_size_in = test_attr->data_size_in; 559 attr.test.data_size_out = test_attr->data_size_out; 560 attr.test.ctx_in = ptr_to_u64(test_attr->ctx_in); 561 attr.test.ctx_out = ptr_to_u64(test_attr->ctx_out); 562 attr.test.ctx_size_in = test_attr->ctx_size_in; 563 attr.test.ctx_size_out = test_attr->ctx_size_out; 564 attr.test.repeat = test_attr->repeat; 565 566 ret = sys_bpf(BPF_PROG_TEST_RUN, &attr, sizeof(attr)); 567 test_attr->data_size_out = attr.test.data_size_out; 568 test_attr->ctx_size_out = attr.test.ctx_size_out; 569 test_attr->retval = attr.test.retval; 570 test_attr->duration = attr.test.duration; 571 return ret; 572 } 573 574 int bpf_prog_get_next_id(__u32 start_id, __u32 *next_id) 575 { 576 union bpf_attr attr; 577 int err; 578 579 memset(&attr, 0, sizeof(attr)); 580 attr.start_id = start_id; 581 582 err = sys_bpf(BPF_PROG_GET_NEXT_ID, &attr, sizeof(attr)); 583 if (!err) 584 *next_id = attr.next_id; 585 586 return err; 587 } 588 589 int bpf_map_get_next_id(__u32 start_id, __u32 *next_id) 590 { 591 union bpf_attr attr; 592 int err; 593 594 memset(&attr, 0, sizeof(attr)); 595 attr.start_id = start_id; 596 597 err = sys_bpf(BPF_MAP_GET_NEXT_ID, &attr, sizeof(attr)); 598 if (!err) 599 *next_id = attr.next_id; 600 601 return err; 602 } 603 604 int bpf_prog_get_fd_by_id(__u32 id) 605 { 606 union bpf_attr attr; 607 608 memset(&attr, 0, sizeof(attr)); 609 attr.prog_id = id; 610 611 return sys_bpf(BPF_PROG_GET_FD_BY_ID, &attr, sizeof(attr)); 612 } 613 614 int bpf_map_get_fd_by_id(__u32 id) 615 { 616 union bpf_attr attr; 617 618 memset(&attr, 0, sizeof(attr)); 619 attr.map_id = id; 620 621 return sys_bpf(BPF_MAP_GET_FD_BY_ID, &attr, sizeof(attr)); 622 } 623 624 int bpf_btf_get_fd_by_id(__u32 id) 625 { 626 union bpf_attr attr; 627 628 memset(&attr, 0, sizeof(attr)); 629 attr.btf_id = id; 630 631 return sys_bpf(BPF_BTF_GET_FD_BY_ID, &attr, sizeof(attr)); 632 } 633 634 int bpf_obj_get_info_by_fd(int prog_fd, void *info, __u32 *info_len) 635 { 636 union bpf_attr attr; 637 int err; 638 639 memset(&attr, 0, sizeof(attr)); 640 attr.info.bpf_fd = prog_fd; 641 attr.info.info_len = *info_len; 642 attr.info.info = ptr_to_u64(info); 643 644 err = sys_bpf(BPF_OBJ_GET_INFO_BY_FD, &attr, sizeof(attr)); 645 if (!err) 646 *info_len = attr.info.info_len; 647 648 return err; 649 } 650 651 int bpf_raw_tracepoint_open(const char *name, int prog_fd) 652 { 653 union bpf_attr attr; 654 655 memset(&attr, 0, sizeof(attr)); 656 attr.raw_tracepoint.name = ptr_to_u64(name); 657 attr.raw_tracepoint.prog_fd = prog_fd; 658 659 return sys_bpf(BPF_RAW_TRACEPOINT_OPEN, &attr, sizeof(attr)); 660 } 661 662 int bpf_load_btf(void *btf, __u32 btf_size, char *log_buf, __u32 log_buf_size, 663 bool do_log) 664 { 665 union bpf_attr attr = {}; 666 int fd; 667 668 attr.btf = ptr_to_u64(btf); 669 attr.btf_size = btf_size; 670 671 retry: 672 if (do_log && log_buf && log_buf_size) { 673 attr.btf_log_level = 1; 674 attr.btf_log_size = log_buf_size; 675 attr.btf_log_buf = ptr_to_u64(log_buf); 676 } 677 678 fd = sys_bpf(BPF_BTF_LOAD, &attr, sizeof(attr)); 679 if (fd == -1 && !do_log && log_buf && log_buf_size) { 680 do_log = true; 681 goto retry; 682 } 683 684 return fd; 685 } 686 687 int bpf_task_fd_query(int pid, int fd, __u32 flags, char *buf, __u32 *buf_len, 688 __u32 *prog_id, __u32 *fd_type, __u64 *probe_offset, 689 __u64 *probe_addr) 690 { 691 union bpf_attr attr = {}; 692 int err; 693 694 attr.task_fd_query.pid = pid; 695 attr.task_fd_query.fd = fd; 696 attr.task_fd_query.flags = flags; 697 attr.task_fd_query.buf = ptr_to_u64(buf); 698 attr.task_fd_query.buf_len = *buf_len; 699 700 err = sys_bpf(BPF_TASK_FD_QUERY, &attr, sizeof(attr)); 701 *buf_len = attr.task_fd_query.buf_len; 702 *prog_id = attr.task_fd_query.prog_id; 703 *fd_type = attr.task_fd_query.fd_type; 704 *probe_offset = attr.task_fd_query.probe_offset; 705 *probe_addr = attr.task_fd_query.probe_addr; 706 707 return err; 708 } 709