-
Notifications
You must be signed in to change notification settings - Fork 300
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
bpf: Handle raw tracepoint arguments
Provide an `arg()` method in `RawTracepointArgs` wrapper of `bpf_raw_tracepoint_args` and also in `RawTracepointContext`, so it's directly available in raw tracepoint programs. The methods and traits implemented here are unsafe. There is no way to reliably check the number of available arguments, so requesting a non-existing one leads to undefined behavior.
- Loading branch information
1 parent
28a28c9
commit 3e3a637
Showing
10 changed files
with
234 additions
and
6 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,19 +1,25 @@ | ||
use core::ffi::c_void; | ||
|
||
use crate::EbpfContext; | ||
use crate::{args::FromRawTracepointArgs, bindings::bpf_raw_tracepoint_args, EbpfContext}; | ||
|
||
pub struct RawTracePointContext { | ||
ctx: *mut c_void, | ||
ctx: *mut bpf_raw_tracepoint_args, | ||
} | ||
|
||
impl RawTracePointContext { | ||
pub fn new(ctx: *mut c_void) -> RawTracePointContext { | ||
RawTracePointContext { ctx } | ||
RawTracePointContext { | ||
ctx: ctx as *mut bpf_raw_tracepoint_args, | ||
} | ||
} | ||
|
||
pub unsafe fn arg<T: FromRawTracepointArgs>(&self, n: usize) -> T { | ||
T::from_argument(&*self.ctx, n) | ||
} | ||
} | ||
|
||
impl EbpfContext for RawTracePointContext { | ||
fn as_ptr(&self) -> *mut c_void { | ||
self.ctx | ||
self.ctx as *mut c_void | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
#![no_std] | ||
#![no_main] | ||
|
||
use aya_ebpf::{ | ||
macros::{map, raw_tracepoint}, | ||
maps::Array, | ||
programs::RawTracePointContext, | ||
}; | ||
use integration_common::raw_tracepoint::SysEnterEvent; | ||
|
||
#[map] | ||
static RESULT: Array<SysEnterEvent> = Array::with_max_entries(1, 0); | ||
|
||
#[raw_tracepoint(tracepoint = "sys_enter")] | ||
pub fn sys_enter(ctx: RawTracePointContext) -> i32 { | ||
let common_type: u16 = unsafe { ctx.arg(0) }; | ||
let common_flags: u8 = unsafe { ctx.arg(1) }; | ||
|
||
if let Some(ptr) = RESULT.get_ptr_mut(0) { | ||
unsafe { | ||
(*ptr).common_type = common_type; | ||
(*ptr).common_flags = common_flags; | ||
} | ||
} | ||
|
||
0 | ||
} | ||
|
||
#[cfg(not(test))] | ||
#[panic_handler] | ||
fn panic(_info: &core::panic::PanicInfo) -> ! { | ||
loop {} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -5,6 +5,7 @@ mod info; | |
mod iter; | ||
mod load; | ||
mod log; | ||
mod raw_tracepoint; | ||
mod rbpf; | ||
mod relocations; | ||
mod ring_buf; | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,34 @@ | ||
use aya::{maps::Array, programs::RawTracePoint, Ebpf}; | ||
use integration_common::raw_tracepoint::SysEnterEvent; | ||
|
||
#[test] | ||
fn raw_tracepoint() { | ||
let mut bpf = Ebpf::load(crate::RAW_TRACEPOINT).unwrap(); | ||
let map: Array<_, SysEnterEvent> = Array::try_from(bpf.map_mut("RESULT").unwrap()).unwrap(); | ||
|
||
// Check start condition. | ||
{ | ||
let SysEnterEvent { | ||
common_type, | ||
common_flags, | ||
.. | ||
} = map.get(&0, 0).unwrap(); | ||
assert_eq!(common_type, 0); | ||
assert_eq!(common_flags, 0); | ||
} | ||
|
||
let prog: &mut RawTracePoint = bpf.program_mut("sys_enter").unwrap().try_into().unwrap(); | ||
prog.load().unwrap(); | ||
prog.attach("sys_enter").unwrap(); | ||
|
||
// Check that a syscall was traced. | ||
{ | ||
let SysEnterEvent { | ||
common_type, | ||
common_flags, | ||
.. | ||
} = map.get(&0, 0).unwrap(); | ||
assert_ne!(common_type, 0); | ||
assert_ne!(common_flags, 0); | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters