1 // SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause)
2 /* Copyright (c) 2019 Netronome Systems, Inc. */
3
4 #include <errno.h>
5 #include <fcntl.h>
6 #include <string.h>
7 #include <stdlib.h>
8 #include <unistd.h>
9 #include <net/if.h>
10 #include <sys/utsname.h>
11
12 #include <linux/btf.h>
13 #include <linux/filter.h>
14 #include <linux/kernel.h>
15 #include <linux/version.h>
16
17 #include "bpf.h"
18 #include "libbpf.h"
19 #include "libbpf_internal.h"
20
21 /* On Ubuntu LINUX_VERSION_CODE doesn't correspond to info.release,
22 * but Ubuntu provides /proc/version_signature file, as described at
23 * https://ubuntu.com/kernel, with an example contents below, which we
24 * can use to get a proper LINUX_VERSION_CODE.
25 *
26 * Ubuntu 5.4.0-12.15-generic 5.4.8
27 *
28 * In the above, 5.4.8 is what kernel is actually expecting, while
29 * uname() call will return 5.4.0 in info.release.
30 */
get_ubuntu_kernel_version(void)31 static __u32 get_ubuntu_kernel_version(void)
32 {
33 const char *ubuntu_kver_file = "/proc/version_signature";
34 __u32 major, minor, patch;
35 int ret;
36 FILE *f;
37
38 if (faccessat(AT_FDCWD, ubuntu_kver_file, R_OK, AT_EACCESS) != 0)
39 return 0;
40
41 f = fopen(ubuntu_kver_file, "r");
42 if (!f)
43 return 0;
44
45 ret = fscanf(f, "%*s %*s %u.%u.%u\n", &major, &minor, &patch);
46 fclose(f);
47 if (ret != 3)
48 return 0;
49
50 return KERNEL_VERSION(major, minor, patch);
51 }
52
53 /* On Debian LINUX_VERSION_CODE doesn't correspond to info.release.
54 * Instead, it is provided in info.version. An example content of
55 * Debian 10 looks like the below.
56 *
57 * utsname::release 4.19.0-22-amd64
58 * utsname::version #1 SMP Debian 4.19.260-1 (2022-09-29)
59 *
60 * In the above, 4.19.260 is what kernel is actually expecting, while
61 * uname() call will return 4.19.0 in info.release.
62 */
get_debian_kernel_version(struct utsname * info)63 static __u32 get_debian_kernel_version(struct utsname *info)
64 {
65 __u32 major, minor, patch;
66 char *p;
67
68 p = strstr(info->version, "Debian ");
69 if (!p) {
70 /* This is not a Debian kernel. */
71 return 0;
72 }
73
74 if (sscanf(p, "Debian %u.%u.%u", &major, &minor, &patch) != 3)
75 return 0;
76
77 return KERNEL_VERSION(major, minor, patch);
78 }
79
get_kernel_version(void)80 __u32 get_kernel_version(void)
81 {
82 __u32 major, minor, patch, version;
83 struct utsname info;
84
85 /* Check if this is an Ubuntu kernel. */
86 version = get_ubuntu_kernel_version();
87 if (version != 0)
88 return version;
89
90 uname(&info);
91
92 /* Check if this is a Debian kernel. */
93 version = get_debian_kernel_version(&info);
94 if (version != 0)
95 return version;
96
97 if (sscanf(info.release, "%u.%u.%u", &major, &minor, &patch) != 3)
98 return 0;
99
100 return KERNEL_VERSION(major, minor, patch);
101 }
102
probe_prog_load(enum bpf_prog_type prog_type,const struct bpf_insn * insns,size_t insns_cnt,char * log_buf,size_t log_buf_sz)103 static int probe_prog_load(enum bpf_prog_type prog_type,
104 const struct bpf_insn *insns, size_t insns_cnt,
105 char *log_buf, size_t log_buf_sz)
106 {
107 LIBBPF_OPTS(bpf_prog_load_opts, opts,
108 .log_buf = log_buf,
109 .log_size = log_buf_sz,
110 .log_level = log_buf ? 1 : 0,
111 );
112 int fd, err, exp_err = 0;
113 const char *exp_msg = NULL;
114 char buf[4096];
115
116 switch (prog_type) {
117 case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
118 opts.expected_attach_type = BPF_CGROUP_INET4_CONNECT;
119 break;
120 case BPF_PROG_TYPE_CGROUP_SOCKOPT:
121 opts.expected_attach_type = BPF_CGROUP_GETSOCKOPT;
122 break;
123 case BPF_PROG_TYPE_SK_LOOKUP:
124 opts.expected_attach_type = BPF_SK_LOOKUP;
125 break;
126 case BPF_PROG_TYPE_KPROBE:
127 opts.kern_version = get_kernel_version();
128 break;
129 case BPF_PROG_TYPE_LIRC_MODE2:
130 opts.expected_attach_type = BPF_LIRC_MODE2;
131 break;
132 case BPF_PROG_TYPE_TRACING:
133 case BPF_PROG_TYPE_LSM:
134 opts.log_buf = buf;
135 opts.log_size = sizeof(buf);
136 opts.log_level = 1;
137 if (prog_type == BPF_PROG_TYPE_TRACING)
138 opts.expected_attach_type = BPF_TRACE_FENTRY;
139 else
140 opts.expected_attach_type = BPF_MODIFY_RETURN;
141 opts.attach_btf_id = 1;
142
143 exp_err = -EINVAL;
144 exp_msg = "attach_btf_id 1 is not a function";
145 break;
146 case BPF_PROG_TYPE_EXT:
147 opts.log_buf = buf;
148 opts.log_size = sizeof(buf);
149 opts.log_level = 1;
150 opts.attach_btf_id = 1;
151
152 exp_err = -EINVAL;
153 exp_msg = "Cannot replace kernel functions";
154 break;
155 case BPF_PROG_TYPE_SYSCALL:
156 opts.prog_flags = BPF_F_SLEEPABLE;
157 break;
158 case BPF_PROG_TYPE_STRUCT_OPS:
159 exp_err = -524; /* -ENOTSUPP */
160 break;
161 case BPF_PROG_TYPE_UNSPEC:
162 case BPF_PROG_TYPE_SOCKET_FILTER:
163 case BPF_PROG_TYPE_SCHED_CLS:
164 case BPF_PROG_TYPE_SCHED_ACT:
165 case BPF_PROG_TYPE_TRACEPOINT:
166 case BPF_PROG_TYPE_XDP:
167 case BPF_PROG_TYPE_PERF_EVENT:
168 case BPF_PROG_TYPE_CGROUP_SKB:
169 case BPF_PROG_TYPE_CGROUP_SOCK:
170 case BPF_PROG_TYPE_LWT_IN:
171 case BPF_PROG_TYPE_LWT_OUT:
172 case BPF_PROG_TYPE_LWT_XMIT:
173 case BPF_PROG_TYPE_SOCK_OPS:
174 case BPF_PROG_TYPE_SK_SKB:
175 case BPF_PROG_TYPE_CGROUP_DEVICE:
176 case BPF_PROG_TYPE_SK_MSG:
177 case BPF_PROG_TYPE_RAW_TRACEPOINT:
178 case BPF_PROG_TYPE_RAW_TRACEPOINT_WRITABLE:
179 case BPF_PROG_TYPE_LWT_SEG6LOCAL:
180 case BPF_PROG_TYPE_SK_REUSEPORT:
181 case BPF_PROG_TYPE_FLOW_DISSECTOR:
182 case BPF_PROG_TYPE_CGROUP_SYSCTL:
183 break;
184 default:
185 return -EOPNOTSUPP;
186 }
187
188 fd = bpf_prog_load(prog_type, NULL, "GPL", insns, insns_cnt, &opts);
189 err = -errno;
190 if (fd >= 0)
191 close(fd);
192 if (exp_err) {
193 if (fd >= 0 || err != exp_err)
194 return 0;
195 if (exp_msg && !strstr(buf, exp_msg))
196 return 0;
197 return 1;
198 }
199 return fd >= 0 ? 1 : 0;
200 }
201
libbpf_probe_bpf_prog_type(enum bpf_prog_type prog_type,const void * opts)202 int libbpf_probe_bpf_prog_type(enum bpf_prog_type prog_type, const void *opts)
203 {
204 struct bpf_insn insns[] = {
205 BPF_MOV64_IMM(BPF_REG_0, 0),
206 BPF_EXIT_INSN()
207 };
208 const size_t insn_cnt = ARRAY_SIZE(insns);
209 int ret;
210
211 if (opts)
212 return libbpf_err(-EINVAL);
213
214 ret = probe_prog_load(prog_type, insns, insn_cnt, NULL, 0);
215 return libbpf_err(ret);
216 }
217
libbpf__load_raw_btf(const char * raw_types,size_t types_len,const char * str_sec,size_t str_len)218 int libbpf__load_raw_btf(const char *raw_types, size_t types_len,
219 const char *str_sec, size_t str_len)
220 {
221 struct btf_header hdr = {
222 .magic = BTF_MAGIC,
223 .version = BTF_VERSION,
224 .hdr_len = sizeof(struct btf_header),
225 .type_len = types_len,
226 .str_off = types_len,
227 .str_len = str_len,
228 };
229 int btf_fd, btf_len;
230 __u8 *raw_btf;
231
232 btf_len = hdr.hdr_len + hdr.type_len + hdr.str_len;
233 raw_btf = malloc(btf_len);
234 if (!raw_btf)
235 return -ENOMEM;
236
237 memcpy(raw_btf, &hdr, sizeof(hdr));
238 memcpy(raw_btf + hdr.hdr_len, raw_types, hdr.type_len);
239 memcpy(raw_btf + hdr.hdr_len + hdr.type_len, str_sec, hdr.str_len);
240
241 btf_fd = bpf_btf_load(raw_btf, btf_len, NULL);
242
243 free(raw_btf);
244 return btf_fd;
245 }
246
load_local_storage_btf(void)247 static int load_local_storage_btf(void)
248 {
249 const char strs[] = "\0bpf_spin_lock\0val\0cnt\0l";
250 /* struct bpf_spin_lock {
251 * int val;
252 * };
253 * struct val {
254 * int cnt;
255 * struct bpf_spin_lock l;
256 * };
257 */
258 __u32 types[] = {
259 /* int */
260 BTF_TYPE_INT_ENC(0, BTF_INT_SIGNED, 0, 32, 4), /* [1] */
261 /* struct bpf_spin_lock */ /* [2] */
262 BTF_TYPE_ENC(1, BTF_INFO_ENC(BTF_KIND_STRUCT, 0, 1), 4),
263 BTF_MEMBER_ENC(15, 1, 0), /* int val; */
264 /* struct val */ /* [3] */
265 BTF_TYPE_ENC(15, BTF_INFO_ENC(BTF_KIND_STRUCT, 0, 2), 8),
266 BTF_MEMBER_ENC(19, 1, 0), /* int cnt; */
267 BTF_MEMBER_ENC(23, 2, 32),/* struct bpf_spin_lock l; */
268 };
269
270 return libbpf__load_raw_btf((char *)types, sizeof(types),
271 strs, sizeof(strs));
272 }
273
probe_map_create(enum bpf_map_type map_type)274 static int probe_map_create(enum bpf_map_type map_type)
275 {
276 LIBBPF_OPTS(bpf_map_create_opts, opts);
277 int key_size, value_size, max_entries;
278 __u32 btf_key_type_id = 0, btf_value_type_id = 0;
279 int fd = -1, btf_fd = -1, fd_inner = -1, exp_err = 0, err = 0;
280
281 key_size = sizeof(__u32);
282 value_size = sizeof(__u32);
283 max_entries = 1;
284
285 switch (map_type) {
286 case BPF_MAP_TYPE_STACK_TRACE:
287 value_size = sizeof(__u64);
288 break;
289 case BPF_MAP_TYPE_LPM_TRIE:
290 key_size = sizeof(__u64);
291 value_size = sizeof(__u64);
292 opts.map_flags = BPF_F_NO_PREALLOC;
293 break;
294 case BPF_MAP_TYPE_CGROUP_STORAGE:
295 case BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE:
296 key_size = sizeof(struct bpf_cgroup_storage_key);
297 value_size = sizeof(__u64);
298 max_entries = 0;
299 break;
300 case BPF_MAP_TYPE_QUEUE:
301 case BPF_MAP_TYPE_STACK:
302 key_size = 0;
303 break;
304 case BPF_MAP_TYPE_SK_STORAGE:
305 case BPF_MAP_TYPE_INODE_STORAGE:
306 case BPF_MAP_TYPE_TASK_STORAGE:
307 case BPF_MAP_TYPE_CGRP_STORAGE:
308 btf_key_type_id = 1;
309 btf_value_type_id = 3;
310 value_size = 8;
311 max_entries = 0;
312 opts.map_flags = BPF_F_NO_PREALLOC;
313 btf_fd = load_local_storage_btf();
314 if (btf_fd < 0)
315 return btf_fd;
316 break;
317 case BPF_MAP_TYPE_RINGBUF:
318 case BPF_MAP_TYPE_USER_RINGBUF:
319 key_size = 0;
320 value_size = 0;
321 max_entries = sysconf(_SC_PAGE_SIZE);
322 break;
323 case BPF_MAP_TYPE_STRUCT_OPS:
324 /* we'll get -ENOTSUPP for invalid BTF type ID for struct_ops */
325 opts.btf_vmlinux_value_type_id = 1;
326 exp_err = -524; /* -ENOTSUPP */
327 break;
328 case BPF_MAP_TYPE_BLOOM_FILTER:
329 key_size = 0;
330 max_entries = 1;
331 break;
332 case BPF_MAP_TYPE_HASH:
333 case BPF_MAP_TYPE_ARRAY:
334 case BPF_MAP_TYPE_PROG_ARRAY:
335 case BPF_MAP_TYPE_PERF_EVENT_ARRAY:
336 case BPF_MAP_TYPE_PERCPU_HASH:
337 case BPF_MAP_TYPE_PERCPU_ARRAY:
338 case BPF_MAP_TYPE_CGROUP_ARRAY:
339 case BPF_MAP_TYPE_LRU_HASH:
340 case BPF_MAP_TYPE_LRU_PERCPU_HASH:
341 case BPF_MAP_TYPE_ARRAY_OF_MAPS:
342 case BPF_MAP_TYPE_HASH_OF_MAPS:
343 case BPF_MAP_TYPE_DEVMAP:
344 case BPF_MAP_TYPE_DEVMAP_HASH:
345 case BPF_MAP_TYPE_SOCKMAP:
346 case BPF_MAP_TYPE_CPUMAP:
347 case BPF_MAP_TYPE_XSKMAP:
348 case BPF_MAP_TYPE_SOCKHASH:
349 case BPF_MAP_TYPE_REUSEPORT_SOCKARRAY:
350 break;
351 case BPF_MAP_TYPE_UNSPEC:
352 default:
353 return -EOPNOTSUPP;
354 }
355
356 if (map_type == BPF_MAP_TYPE_ARRAY_OF_MAPS ||
357 map_type == BPF_MAP_TYPE_HASH_OF_MAPS) {
358 fd_inner = bpf_map_create(BPF_MAP_TYPE_HASH, NULL,
359 sizeof(__u32), sizeof(__u32), 1, NULL);
360 if (fd_inner < 0)
361 goto cleanup;
362
363 opts.inner_map_fd = fd_inner;
364 }
365
366 if (btf_fd >= 0) {
367 opts.btf_fd = btf_fd;
368 opts.btf_key_type_id = btf_key_type_id;
369 opts.btf_value_type_id = btf_value_type_id;
370 }
371
372 fd = bpf_map_create(map_type, NULL, key_size, value_size, max_entries, &opts);
373 err = -errno;
374
375 cleanup:
376 if (fd >= 0)
377 close(fd);
378 if (fd_inner >= 0)
379 close(fd_inner);
380 if (btf_fd >= 0)
381 close(btf_fd);
382
383 if (exp_err)
384 return fd < 0 && err == exp_err ? 1 : 0;
385 else
386 return fd >= 0 ? 1 : 0;
387 }
388
libbpf_probe_bpf_map_type(enum bpf_map_type map_type,const void * opts)389 int libbpf_probe_bpf_map_type(enum bpf_map_type map_type, const void *opts)
390 {
391 int ret;
392
393 if (opts)
394 return libbpf_err(-EINVAL);
395
396 ret = probe_map_create(map_type);
397 return libbpf_err(ret);
398 }
399
libbpf_probe_bpf_helper(enum bpf_prog_type prog_type,enum bpf_func_id helper_id,const void * opts)400 int libbpf_probe_bpf_helper(enum bpf_prog_type prog_type, enum bpf_func_id helper_id,
401 const void *opts)
402 {
403 struct bpf_insn insns[] = {
404 BPF_EMIT_CALL((__u32)helper_id),
405 BPF_EXIT_INSN(),
406 };
407 const size_t insn_cnt = ARRAY_SIZE(insns);
408 char buf[4096];
409 int ret;
410
411 if (opts)
412 return libbpf_err(-EINVAL);
413
414 /* we can't successfully load all prog types to check for BPF helper
415 * support, so bail out with -EOPNOTSUPP error
416 */
417 switch (prog_type) {
418 case BPF_PROG_TYPE_TRACING:
419 case BPF_PROG_TYPE_EXT:
420 case BPF_PROG_TYPE_LSM:
421 case BPF_PROG_TYPE_STRUCT_OPS:
422 return -EOPNOTSUPP;
423 default:
424 break;
425 }
426
427 buf[0] = '\0';
428 ret = probe_prog_load(prog_type, insns, insn_cnt, buf, sizeof(buf));
429 if (ret < 0)
430 return libbpf_err(ret);
431
432 /* If BPF verifier doesn't recognize BPF helper ID (enum bpf_func_id)
433 * at all, it will emit something like "invalid func unknown#181".
434 * If BPF verifier recognizes BPF helper but it's not supported for
435 * given BPF program type, it will emit "unknown func bpf_sys_bpf#166".
436 * In both cases, provided combination of BPF program type and BPF
437 * helper is not supported by the kernel.
438 * In all other cases, probe_prog_load() above will either succeed (e.g.,
439 * because BPF helper happens to accept no input arguments or it
440 * accepts one input argument and initial PTR_TO_CTX is fine for
441 * that), or we'll get some more specific BPF verifier error about
442 * some unsatisfied conditions.
443 */
444 if (ret == 0 && (strstr(buf, "invalid func ") || strstr(buf, "unknown func ")))
445 return 0;
446 return 1; /* assume supported */
447 }
448