Loading...
1/* SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause) */
2
3/*
4 * Common eBPF ELF object loading operations.
5 *
6 * Copyright (C) 2013-2015 Alexei Starovoitov <ast@kernel.org>
7 * Copyright (C) 2015 Wang Nan <wangnan0@huawei.com>
8 * Copyright (C) 2015 Huawei Inc.
9 */
10#ifndef __LIBBPF_LIBBPF_H
11#define __LIBBPF_LIBBPF_H
12
13#include <stdarg.h>
14#include <stdio.h>
15#include <stdint.h>
16#include <stdbool.h>
17#include <sys/types.h> // for size_t
18#include <linux/bpf.h>
19
20#include "libbpf_common.h"
21
22#ifdef __cplusplus
23extern "C" {
24#endif
25
26enum libbpf_errno {
27 __LIBBPF_ERRNO__START = 4000,
28
29 /* Something wrong in libelf */
30 LIBBPF_ERRNO__LIBELF = __LIBBPF_ERRNO__START,
31 LIBBPF_ERRNO__FORMAT, /* BPF object format invalid */
32 LIBBPF_ERRNO__KVERSION, /* Incorrect or no 'version' section */
33 LIBBPF_ERRNO__ENDIAN, /* Endian mismatch */
34 LIBBPF_ERRNO__INTERNAL, /* Internal error in libbpf */
35 LIBBPF_ERRNO__RELOC, /* Relocation failed */
36 LIBBPF_ERRNO__LOAD, /* Load program failure for unknown reason */
37 LIBBPF_ERRNO__VERIFY, /* Kernel verifier blocks program loading */
38 LIBBPF_ERRNO__PROG2BIG, /* Program too big */
39 LIBBPF_ERRNO__KVER, /* Incorrect kernel version */
40 LIBBPF_ERRNO__PROGTYPE, /* Kernel doesn't support this program type */
41 LIBBPF_ERRNO__WRNGPID, /* Wrong pid in netlink message */
42 LIBBPF_ERRNO__INVSEQ, /* Invalid netlink sequence */
43 LIBBPF_ERRNO__NLPARSE, /* netlink parsing error */
44 __LIBBPF_ERRNO__END,
45};
46
47LIBBPF_API int libbpf_strerror(int err, char *buf, size_t size);
48
49enum libbpf_print_level {
50 LIBBPF_WARN,
51 LIBBPF_INFO,
52 LIBBPF_DEBUG,
53};
54
55typedef int (*libbpf_print_fn_t)(enum libbpf_print_level level,
56 const char *, va_list ap);
57
58LIBBPF_API libbpf_print_fn_t libbpf_set_print(libbpf_print_fn_t fn);
59
60/* Hide internal to user */
61struct bpf_object;
62
63struct bpf_object_open_attr {
64 const char *file;
65 enum bpf_prog_type prog_type;
66};
67
68struct bpf_object_open_opts {
69 /* size of this struct, for forward/backward compatiblity */
70 size_t sz;
71 /* object name override, if provided:
72 * - for object open from file, this will override setting object
73 * name from file path's base name;
74 * - for object open from memory buffer, this will specify an object
75 * name and will override default "<addr>-<buf-size>" name;
76 */
77 const char *object_name;
78 /* parse map definitions non-strictly, allowing extra attributes/data */
79 bool relaxed_maps;
80 /* DEPRECATED: handle CO-RE relocations non-strictly, allowing failures.
81 * Value is ignored. Relocations always are processed non-strictly.
82 * Non-relocatable instructions are replaced with invalid ones to
83 * prevent accidental errors.
84 * */
85 bool relaxed_core_relocs;
86 /* maps that set the 'pinning' attribute in their definition will have
87 * their pin_path attribute set to a file in this directory, and be
88 * auto-pinned to that path on load; defaults to "/sys/fs/bpf".
89 */
90 const char *pin_root_path;
91 __u32 attach_prog_fd;
92 /* Additional kernel config content that augments and overrides
93 * system Kconfig for CONFIG_xxx externs.
94 */
95 const char *kconfig;
96};
97#define bpf_object_open_opts__last_field kconfig
98
99LIBBPF_API struct bpf_object *bpf_object__open(const char *path);
100LIBBPF_API struct bpf_object *
101bpf_object__open_file(const char *path, const struct bpf_object_open_opts *opts);
102LIBBPF_API struct bpf_object *
103bpf_object__open_mem(const void *obj_buf, size_t obj_buf_sz,
104 const struct bpf_object_open_opts *opts);
105
106/* deprecated bpf_object__open variants */
107LIBBPF_API struct bpf_object *
108bpf_object__open_buffer(const void *obj_buf, size_t obj_buf_sz,
109 const char *name);
110LIBBPF_API struct bpf_object *
111bpf_object__open_xattr(struct bpf_object_open_attr *attr);
112
113enum libbpf_pin_type {
114 LIBBPF_PIN_NONE,
115 /* PIN_BY_NAME: pin maps by name (in /sys/fs/bpf by default) */
116 LIBBPF_PIN_BY_NAME,
117};
118
119/* pin_maps and unpin_maps can both be called with a NULL path, in which case
120 * they will use the pin_path attribute of each map (and ignore all maps that
121 * don't have a pin_path set).
122 */
123LIBBPF_API int bpf_object__pin_maps(struct bpf_object *obj, const char *path);
124LIBBPF_API int bpf_object__unpin_maps(struct bpf_object *obj,
125 const char *path);
126LIBBPF_API int bpf_object__pin_programs(struct bpf_object *obj,
127 const char *path);
128LIBBPF_API int bpf_object__unpin_programs(struct bpf_object *obj,
129 const char *path);
130LIBBPF_API int bpf_object__pin(struct bpf_object *object, const char *path);
131LIBBPF_API void bpf_object__close(struct bpf_object *object);
132
133struct bpf_object_load_attr {
134 struct bpf_object *obj;
135 int log_level;
136 const char *target_btf_path;
137};
138
139/* Load/unload object into/from kernel */
140LIBBPF_API int bpf_object__load(struct bpf_object *obj);
141LIBBPF_API int bpf_object__load_xattr(struct bpf_object_load_attr *attr);
142LIBBPF_API int bpf_object__unload(struct bpf_object *obj);
143
144LIBBPF_API const char *bpf_object__name(const struct bpf_object *obj);
145LIBBPF_API unsigned int bpf_object__kversion(const struct bpf_object *obj);
146
147struct btf;
148LIBBPF_API struct btf *bpf_object__btf(const struct bpf_object *obj);
149LIBBPF_API int bpf_object__btf_fd(const struct bpf_object *obj);
150
151LIBBPF_API struct bpf_program *
152bpf_object__find_program_by_title(const struct bpf_object *obj,
153 const char *title);
154LIBBPF_API struct bpf_program *
155bpf_object__find_program_by_name(const struct bpf_object *obj,
156 const char *name);
157
158LIBBPF_API struct bpf_object *bpf_object__next(struct bpf_object *prev);
159#define bpf_object__for_each_safe(pos, tmp) \
160 for ((pos) = bpf_object__next(NULL), \
161 (tmp) = bpf_object__next(pos); \
162 (pos) != NULL; \
163 (pos) = (tmp), (tmp) = bpf_object__next(tmp))
164
165typedef void (*bpf_object_clear_priv_t)(struct bpf_object *, void *);
166LIBBPF_API int bpf_object__set_priv(struct bpf_object *obj, void *priv,
167 bpf_object_clear_priv_t clear_priv);
168LIBBPF_API void *bpf_object__priv(const struct bpf_object *prog);
169
170LIBBPF_API int
171libbpf_prog_type_by_name(const char *name, enum bpf_prog_type *prog_type,
172 enum bpf_attach_type *expected_attach_type);
173LIBBPF_API int libbpf_attach_type_by_name(const char *name,
174 enum bpf_attach_type *attach_type);
175LIBBPF_API int libbpf_find_vmlinux_btf_id(const char *name,
176 enum bpf_attach_type attach_type);
177
178/* Accessors of bpf_program */
179struct bpf_program;
180LIBBPF_API struct bpf_program *bpf_program__next(struct bpf_program *prog,
181 const struct bpf_object *obj);
182
183#define bpf_object__for_each_program(pos, obj) \
184 for ((pos) = bpf_program__next(NULL, (obj)); \
185 (pos) != NULL; \
186 (pos) = bpf_program__next((pos), (obj)))
187
188LIBBPF_API struct bpf_program *bpf_program__prev(struct bpf_program *prog,
189 const struct bpf_object *obj);
190
191typedef void (*bpf_program_clear_priv_t)(struct bpf_program *, void *);
192
193LIBBPF_API int bpf_program__set_priv(struct bpf_program *prog, void *priv,
194 bpf_program_clear_priv_t clear_priv);
195
196LIBBPF_API void *bpf_program__priv(const struct bpf_program *prog);
197LIBBPF_API void bpf_program__set_ifindex(struct bpf_program *prog,
198 __u32 ifindex);
199
200LIBBPF_API const char *bpf_program__name(const struct bpf_program *prog);
201LIBBPF_API const char *bpf_program__title(const struct bpf_program *prog,
202 bool needs_copy);
203LIBBPF_API bool bpf_program__autoload(const struct bpf_program *prog);
204LIBBPF_API int bpf_program__set_autoload(struct bpf_program *prog, bool autoload);
205
206/* returns program size in bytes */
207LIBBPF_API size_t bpf_program__size(const struct bpf_program *prog);
208
209LIBBPF_API int bpf_program__load(struct bpf_program *prog, char *license,
210 __u32 kern_version);
211LIBBPF_API int bpf_program__fd(const struct bpf_program *prog);
212LIBBPF_API int bpf_program__pin_instance(struct bpf_program *prog,
213 const char *path,
214 int instance);
215LIBBPF_API int bpf_program__unpin_instance(struct bpf_program *prog,
216 const char *path,
217 int instance);
218LIBBPF_API int bpf_program__pin(struct bpf_program *prog, const char *path);
219LIBBPF_API int bpf_program__unpin(struct bpf_program *prog, const char *path);
220LIBBPF_API void bpf_program__unload(struct bpf_program *prog);
221
222struct bpf_link;
223
224LIBBPF_API struct bpf_link *bpf_link__open(const char *path);
225LIBBPF_API int bpf_link__fd(const struct bpf_link *link);
226LIBBPF_API const char *bpf_link__pin_path(const struct bpf_link *link);
227LIBBPF_API int bpf_link__pin(struct bpf_link *link, const char *path);
228LIBBPF_API int bpf_link__unpin(struct bpf_link *link);
229LIBBPF_API int bpf_link__update_program(struct bpf_link *link,
230 struct bpf_program *prog);
231LIBBPF_API void bpf_link__disconnect(struct bpf_link *link);
232LIBBPF_API int bpf_link__detach(struct bpf_link *link);
233LIBBPF_API int bpf_link__destroy(struct bpf_link *link);
234
235LIBBPF_API struct bpf_link *
236bpf_program__attach(struct bpf_program *prog);
237LIBBPF_API struct bpf_link *
238bpf_program__attach_perf_event(struct bpf_program *prog, int pfd);
239LIBBPF_API struct bpf_link *
240bpf_program__attach_kprobe(struct bpf_program *prog, bool retprobe,
241 const char *func_name);
242LIBBPF_API struct bpf_link *
243bpf_program__attach_uprobe(struct bpf_program *prog, bool retprobe,
244 pid_t pid, const char *binary_path,
245 size_t func_offset);
246LIBBPF_API struct bpf_link *
247bpf_program__attach_tracepoint(struct bpf_program *prog,
248 const char *tp_category,
249 const char *tp_name);
250LIBBPF_API struct bpf_link *
251bpf_program__attach_raw_tracepoint(struct bpf_program *prog,
252 const char *tp_name);
253LIBBPF_API struct bpf_link *
254bpf_program__attach_trace(struct bpf_program *prog);
255LIBBPF_API struct bpf_link *
256bpf_program__attach_lsm(struct bpf_program *prog);
257LIBBPF_API struct bpf_link *
258bpf_program__attach_cgroup(struct bpf_program *prog, int cgroup_fd);
259LIBBPF_API struct bpf_link *
260bpf_program__attach_netns(struct bpf_program *prog, int netns_fd);
261LIBBPF_API struct bpf_link *
262bpf_program__attach_xdp(struct bpf_program *prog, int ifindex);
263
264struct bpf_map;
265
266LIBBPF_API struct bpf_link *bpf_map__attach_struct_ops(struct bpf_map *map);
267
268struct bpf_iter_attach_opts {
269 size_t sz; /* size of this struct for forward/backward compatibility */
270 union bpf_iter_link_info *link_info;
271 __u32 link_info_len;
272};
273#define bpf_iter_attach_opts__last_field link_info_len
274
275LIBBPF_API struct bpf_link *
276bpf_program__attach_iter(struct bpf_program *prog,
277 const struct bpf_iter_attach_opts *opts);
278
279struct bpf_insn;
280
281/*
282 * Libbpf allows callers to adjust BPF programs before being loaded
283 * into kernel. One program in an object file can be transformed into
284 * multiple variants to be attached to different hooks.
285 *
286 * bpf_program_prep_t, bpf_program__set_prep and bpf_program__nth_fd
287 * form an API for this purpose.
288 *
289 * - bpf_program_prep_t:
290 * Defines a 'preprocessor', which is a caller defined function
291 * passed to libbpf through bpf_program__set_prep(), and will be
292 * called before program is loaded. The processor should adjust
293 * the program one time for each instance according to the instance id
294 * passed to it.
295 *
296 * - bpf_program__set_prep:
297 * Attaches a preprocessor to a BPF program. The number of instances
298 * that should be created is also passed through this function.
299 *
300 * - bpf_program__nth_fd:
301 * After the program is loaded, get resulting FD of a given instance
302 * of the BPF program.
303 *
304 * If bpf_program__set_prep() is not used, the program would be loaded
305 * without adjustment during bpf_object__load(). The program has only
306 * one instance. In this case bpf_program__fd(prog) is equal to
307 * bpf_program__nth_fd(prog, 0).
308 */
309
310struct bpf_prog_prep_result {
311 /*
312 * If not NULL, load new instruction array.
313 * If set to NULL, don't load this instance.
314 */
315 struct bpf_insn *new_insn_ptr;
316 int new_insn_cnt;
317
318 /* If not NULL, result FD is written to it. */
319 int *pfd;
320};
321
322/*
323 * Parameters of bpf_program_prep_t:
324 * - prog: The bpf_program being loaded.
325 * - n: Index of instance being generated.
326 * - insns: BPF instructions array.
327 * - insns_cnt:Number of instructions in insns.
328 * - res: Output parameter, result of transformation.
329 *
330 * Return value:
331 * - Zero: pre-processing success.
332 * - Non-zero: pre-processing error, stop loading.
333 */
334typedef int (*bpf_program_prep_t)(struct bpf_program *prog, int n,
335 struct bpf_insn *insns, int insns_cnt,
336 struct bpf_prog_prep_result *res);
337
338LIBBPF_API int bpf_program__set_prep(struct bpf_program *prog, int nr_instance,
339 bpf_program_prep_t prep);
340
341LIBBPF_API int bpf_program__nth_fd(const struct bpf_program *prog, int n);
342
343/*
344 * Adjust type of BPF program. Default is kprobe.
345 */
346LIBBPF_API int bpf_program__set_socket_filter(struct bpf_program *prog);
347LIBBPF_API int bpf_program__set_tracepoint(struct bpf_program *prog);
348LIBBPF_API int bpf_program__set_raw_tracepoint(struct bpf_program *prog);
349LIBBPF_API int bpf_program__set_kprobe(struct bpf_program *prog);
350LIBBPF_API int bpf_program__set_lsm(struct bpf_program *prog);
351LIBBPF_API int bpf_program__set_sched_cls(struct bpf_program *prog);
352LIBBPF_API int bpf_program__set_sched_act(struct bpf_program *prog);
353LIBBPF_API int bpf_program__set_xdp(struct bpf_program *prog);
354LIBBPF_API int bpf_program__set_perf_event(struct bpf_program *prog);
355LIBBPF_API int bpf_program__set_tracing(struct bpf_program *prog);
356LIBBPF_API int bpf_program__set_struct_ops(struct bpf_program *prog);
357LIBBPF_API int bpf_program__set_extension(struct bpf_program *prog);
358LIBBPF_API int bpf_program__set_sk_lookup(struct bpf_program *prog);
359
360LIBBPF_API enum bpf_prog_type bpf_program__get_type(struct bpf_program *prog);
361LIBBPF_API void bpf_program__set_type(struct bpf_program *prog,
362 enum bpf_prog_type type);
363
364LIBBPF_API enum bpf_attach_type
365bpf_program__get_expected_attach_type(struct bpf_program *prog);
366LIBBPF_API void
367bpf_program__set_expected_attach_type(struct bpf_program *prog,
368 enum bpf_attach_type type);
369
370LIBBPF_API int
371bpf_program__set_attach_target(struct bpf_program *prog, int attach_prog_fd,
372 const char *attach_func_name);
373
374LIBBPF_API bool bpf_program__is_socket_filter(const struct bpf_program *prog);
375LIBBPF_API bool bpf_program__is_tracepoint(const struct bpf_program *prog);
376LIBBPF_API bool bpf_program__is_raw_tracepoint(const struct bpf_program *prog);
377LIBBPF_API bool bpf_program__is_kprobe(const struct bpf_program *prog);
378LIBBPF_API bool bpf_program__is_lsm(const struct bpf_program *prog);
379LIBBPF_API bool bpf_program__is_sched_cls(const struct bpf_program *prog);
380LIBBPF_API bool bpf_program__is_sched_act(const struct bpf_program *prog);
381LIBBPF_API bool bpf_program__is_xdp(const struct bpf_program *prog);
382LIBBPF_API bool bpf_program__is_perf_event(const struct bpf_program *prog);
383LIBBPF_API bool bpf_program__is_tracing(const struct bpf_program *prog);
384LIBBPF_API bool bpf_program__is_struct_ops(const struct bpf_program *prog);
385LIBBPF_API bool bpf_program__is_extension(const struct bpf_program *prog);
386LIBBPF_API bool bpf_program__is_sk_lookup(const struct bpf_program *prog);
387
388/*
389 * No need for __attribute__((packed)), all members of 'bpf_map_def'
390 * are all aligned. In addition, using __attribute__((packed))
391 * would trigger a -Wpacked warning message, and lead to an error
392 * if -Werror is set.
393 */
394struct bpf_map_def {
395 unsigned int type;
396 unsigned int key_size;
397 unsigned int value_size;
398 unsigned int max_entries;
399 unsigned int map_flags;
400};
401
402/*
403 * The 'struct bpf_map' in include/linux/bpf.h is internal to the kernel,
404 * so no need to worry about a name clash.
405 */
406LIBBPF_API struct bpf_map *
407bpf_object__find_map_by_name(const struct bpf_object *obj, const char *name);
408
409LIBBPF_API int
410bpf_object__find_map_fd_by_name(const struct bpf_object *obj, const char *name);
411
412/*
413 * Get bpf_map through the offset of corresponding struct bpf_map_def
414 * in the BPF object file.
415 */
416LIBBPF_API struct bpf_map *
417bpf_object__find_map_by_offset(struct bpf_object *obj, size_t offset);
418
419LIBBPF_API struct bpf_map *
420bpf_map__next(const struct bpf_map *map, const struct bpf_object *obj);
421#define bpf_object__for_each_map(pos, obj) \
422 for ((pos) = bpf_map__next(NULL, (obj)); \
423 (pos) != NULL; \
424 (pos) = bpf_map__next((pos), (obj)))
425#define bpf_map__for_each bpf_object__for_each_map
426
427LIBBPF_API struct bpf_map *
428bpf_map__prev(const struct bpf_map *map, const struct bpf_object *obj);
429
430/* get/set map FD */
431LIBBPF_API int bpf_map__fd(const struct bpf_map *map);
432LIBBPF_API int bpf_map__reuse_fd(struct bpf_map *map, int fd);
433/* get map definition */
434LIBBPF_API const struct bpf_map_def *bpf_map__def(const struct bpf_map *map);
435/* get map name */
436LIBBPF_API const char *bpf_map__name(const struct bpf_map *map);
437/* get/set map type */
438LIBBPF_API enum bpf_map_type bpf_map__type(const struct bpf_map *map);
439LIBBPF_API int bpf_map__set_type(struct bpf_map *map, enum bpf_map_type type);
440/* get/set map size (max_entries) */
441LIBBPF_API __u32 bpf_map__max_entries(const struct bpf_map *map);
442LIBBPF_API int bpf_map__set_max_entries(struct bpf_map *map, __u32 max_entries);
443LIBBPF_API int bpf_map__resize(struct bpf_map *map, __u32 max_entries);
444/* get/set map flags */
445LIBBPF_API __u32 bpf_map__map_flags(const struct bpf_map *map);
446LIBBPF_API int bpf_map__set_map_flags(struct bpf_map *map, __u32 flags);
447/* get/set map NUMA node */
448LIBBPF_API __u32 bpf_map__numa_node(const struct bpf_map *map);
449LIBBPF_API int bpf_map__set_numa_node(struct bpf_map *map, __u32 numa_node);
450/* get/set map key size */
451LIBBPF_API __u32 bpf_map__key_size(const struct bpf_map *map);
452LIBBPF_API int bpf_map__set_key_size(struct bpf_map *map, __u32 size);
453/* get/set map value size */
454LIBBPF_API __u32 bpf_map__value_size(const struct bpf_map *map);
455LIBBPF_API int bpf_map__set_value_size(struct bpf_map *map, __u32 size);
456/* get map key/value BTF type IDs */
457LIBBPF_API __u32 bpf_map__btf_key_type_id(const struct bpf_map *map);
458LIBBPF_API __u32 bpf_map__btf_value_type_id(const struct bpf_map *map);
459/* get/set map if_index */
460LIBBPF_API __u32 bpf_map__ifindex(const struct bpf_map *map);
461LIBBPF_API int bpf_map__set_ifindex(struct bpf_map *map, __u32 ifindex);
462
463typedef void (*bpf_map_clear_priv_t)(struct bpf_map *, void *);
464LIBBPF_API int bpf_map__set_priv(struct bpf_map *map, void *priv,
465 bpf_map_clear_priv_t clear_priv);
466LIBBPF_API void *bpf_map__priv(const struct bpf_map *map);
467LIBBPF_API int bpf_map__set_initial_value(struct bpf_map *map,
468 const void *data, size_t size);
469LIBBPF_API bool bpf_map__is_offload_neutral(const struct bpf_map *map);
470LIBBPF_API bool bpf_map__is_internal(const struct bpf_map *map);
471LIBBPF_API int bpf_map__set_pin_path(struct bpf_map *map, const char *path);
472LIBBPF_API const char *bpf_map__get_pin_path(const struct bpf_map *map);
473LIBBPF_API bool bpf_map__is_pinned(const struct bpf_map *map);
474LIBBPF_API int bpf_map__pin(struct bpf_map *map, const char *path);
475LIBBPF_API int bpf_map__unpin(struct bpf_map *map, const char *path);
476
477LIBBPF_API int bpf_map__set_inner_map_fd(struct bpf_map *map, int fd);
478
479LIBBPF_API long libbpf_get_error(const void *ptr);
480
481struct bpf_prog_load_attr {
482 const char *file;
483 enum bpf_prog_type prog_type;
484 enum bpf_attach_type expected_attach_type;
485 int ifindex;
486 int log_level;
487 int prog_flags;
488};
489
490LIBBPF_API int bpf_prog_load_xattr(const struct bpf_prog_load_attr *attr,
491 struct bpf_object **pobj, int *prog_fd);
492LIBBPF_API int bpf_prog_load(const char *file, enum bpf_prog_type type,
493 struct bpf_object **pobj, int *prog_fd);
494
495struct xdp_link_info {
496 __u32 prog_id;
497 __u32 drv_prog_id;
498 __u32 hw_prog_id;
499 __u32 skb_prog_id;
500 __u8 attach_mode;
501};
502
503struct bpf_xdp_set_link_opts {
504 size_t sz;
505 int old_fd;
506};
507#define bpf_xdp_set_link_opts__last_field old_fd
508
509LIBBPF_API int bpf_set_link_xdp_fd(int ifindex, int fd, __u32 flags);
510LIBBPF_API int bpf_set_link_xdp_fd_opts(int ifindex, int fd, __u32 flags,
511 const struct bpf_xdp_set_link_opts *opts);
512LIBBPF_API int bpf_get_link_xdp_id(int ifindex, __u32 *prog_id, __u32 flags);
513LIBBPF_API int bpf_get_link_xdp_info(int ifindex, struct xdp_link_info *info,
514 size_t info_size, __u32 flags);
515
516/* Ring buffer APIs */
517struct ring_buffer;
518
519typedef int (*ring_buffer_sample_fn)(void *ctx, void *data, size_t size);
520
521struct ring_buffer_opts {
522 size_t sz; /* size of this struct, for forward/backward compatiblity */
523};
524
525#define ring_buffer_opts__last_field sz
526
527LIBBPF_API struct ring_buffer *
528ring_buffer__new(int map_fd, ring_buffer_sample_fn sample_cb, void *ctx,
529 const struct ring_buffer_opts *opts);
530LIBBPF_API void ring_buffer__free(struct ring_buffer *rb);
531LIBBPF_API int ring_buffer__add(struct ring_buffer *rb, int map_fd,
532 ring_buffer_sample_fn sample_cb, void *ctx);
533LIBBPF_API int ring_buffer__poll(struct ring_buffer *rb, int timeout_ms);
534LIBBPF_API int ring_buffer__consume(struct ring_buffer *rb);
535
536/* Perf buffer APIs */
537struct perf_buffer;
538
539typedef void (*perf_buffer_sample_fn)(void *ctx, int cpu,
540 void *data, __u32 size);
541typedef void (*perf_buffer_lost_fn)(void *ctx, int cpu, __u64 cnt);
542
543/* common use perf buffer options */
544struct perf_buffer_opts {
545 /* if specified, sample_cb is called for each sample */
546 perf_buffer_sample_fn sample_cb;
547 /* if specified, lost_cb is called for each batch of lost samples */
548 perf_buffer_lost_fn lost_cb;
549 /* ctx is provided to sample_cb and lost_cb */
550 void *ctx;
551};
552
553LIBBPF_API struct perf_buffer *
554perf_buffer__new(int map_fd, size_t page_cnt,
555 const struct perf_buffer_opts *opts);
556
557enum bpf_perf_event_ret {
558 LIBBPF_PERF_EVENT_DONE = 0,
559 LIBBPF_PERF_EVENT_ERROR = -1,
560 LIBBPF_PERF_EVENT_CONT = -2,
561};
562
563struct perf_event_header;
564
565typedef enum bpf_perf_event_ret
566(*perf_buffer_event_fn)(void *ctx, int cpu, struct perf_event_header *event);
567
568/* raw perf buffer options, giving most power and control */
569struct perf_buffer_raw_opts {
570 /* perf event attrs passed directly into perf_event_open() */
571 struct perf_event_attr *attr;
572 /* raw event callback */
573 perf_buffer_event_fn event_cb;
574 /* ctx is provided to event_cb */
575 void *ctx;
576 /* if cpu_cnt == 0, open all on all possible CPUs (up to the number of
577 * max_entries of given PERF_EVENT_ARRAY map)
578 */
579 int cpu_cnt;
580 /* if cpu_cnt > 0, cpus is an array of CPUs to open ring buffers on */
581 int *cpus;
582 /* if cpu_cnt > 0, map_keys specify map keys to set per-CPU FDs for */
583 int *map_keys;
584};
585
586LIBBPF_API struct perf_buffer *
587perf_buffer__new_raw(int map_fd, size_t page_cnt,
588 const struct perf_buffer_raw_opts *opts);
589
590LIBBPF_API void perf_buffer__free(struct perf_buffer *pb);
591LIBBPF_API int perf_buffer__poll(struct perf_buffer *pb, int timeout_ms);
592LIBBPF_API int perf_buffer__consume(struct perf_buffer *pb);
593
594typedef enum bpf_perf_event_ret
595 (*bpf_perf_event_print_t)(struct perf_event_header *hdr,
596 void *private_data);
597LIBBPF_API enum bpf_perf_event_ret
598bpf_perf_event_read_simple(void *mmap_mem, size_t mmap_size, size_t page_size,
599 void **copy_mem, size_t *copy_size,
600 bpf_perf_event_print_t fn, void *private_data);
601
602struct bpf_prog_linfo;
603struct bpf_prog_info;
604
605LIBBPF_API void bpf_prog_linfo__free(struct bpf_prog_linfo *prog_linfo);
606LIBBPF_API struct bpf_prog_linfo *
607bpf_prog_linfo__new(const struct bpf_prog_info *info);
608LIBBPF_API const struct bpf_line_info *
609bpf_prog_linfo__lfind_addr_func(const struct bpf_prog_linfo *prog_linfo,
610 __u64 addr, __u32 func_idx, __u32 nr_skip);
611LIBBPF_API const struct bpf_line_info *
612bpf_prog_linfo__lfind(const struct bpf_prog_linfo *prog_linfo,
613 __u32 insn_off, __u32 nr_skip);
614
615/*
616 * Probe for supported system features
617 *
618 * Note that running many of these probes in a short amount of time can cause
619 * the kernel to reach the maximal size of lockable memory allowed for the
620 * user, causing subsequent probes to fail. In this case, the caller may want
621 * to adjust that limit with setrlimit().
622 */
623LIBBPF_API bool bpf_probe_prog_type(enum bpf_prog_type prog_type,
624 __u32 ifindex);
625LIBBPF_API bool bpf_probe_map_type(enum bpf_map_type map_type, __u32 ifindex);
626LIBBPF_API bool bpf_probe_helper(enum bpf_func_id id,
627 enum bpf_prog_type prog_type, __u32 ifindex);
628LIBBPF_API bool bpf_probe_large_insn_limit(__u32 ifindex);
629
630/*
631 * Get bpf_prog_info in continuous memory
632 *
633 * struct bpf_prog_info has multiple arrays. The user has option to choose
634 * arrays to fetch from kernel. The following APIs provide an uniform way to
635 * fetch these data. All arrays in bpf_prog_info are stored in a single
636 * continuous memory region. This makes it easy to store the info in a
637 * file.
638 *
639 * Before writing bpf_prog_info_linear to files, it is necessary to
640 * translate pointers in bpf_prog_info to offsets. Helper functions
641 * bpf_program__bpil_addr_to_offs() and bpf_program__bpil_offs_to_addr()
642 * are introduced to switch between pointers and offsets.
643 *
644 * Examples:
645 * # To fetch map_ids and prog_tags:
646 * __u64 arrays = (1UL << BPF_PROG_INFO_MAP_IDS) |
647 * (1UL << BPF_PROG_INFO_PROG_TAGS);
648 * struct bpf_prog_info_linear *info_linear =
649 * bpf_program__get_prog_info_linear(fd, arrays);
650 *
651 * # To save data in file
652 * bpf_program__bpil_addr_to_offs(info_linear);
653 * write(f, info_linear, sizeof(*info_linear) + info_linear->data_len);
654 *
655 * # To read data from file
656 * read(f, info_linear, <proper_size>);
657 * bpf_program__bpil_offs_to_addr(info_linear);
658 */
659enum bpf_prog_info_array {
660 BPF_PROG_INFO_FIRST_ARRAY = 0,
661 BPF_PROG_INFO_JITED_INSNS = 0,
662 BPF_PROG_INFO_XLATED_INSNS,
663 BPF_PROG_INFO_MAP_IDS,
664 BPF_PROG_INFO_JITED_KSYMS,
665 BPF_PROG_INFO_JITED_FUNC_LENS,
666 BPF_PROG_INFO_FUNC_INFO,
667 BPF_PROG_INFO_LINE_INFO,
668 BPF_PROG_INFO_JITED_LINE_INFO,
669 BPF_PROG_INFO_PROG_TAGS,
670 BPF_PROG_INFO_LAST_ARRAY,
671};
672
673struct bpf_prog_info_linear {
674 /* size of struct bpf_prog_info, when the tool is compiled */
675 __u32 info_len;
676 /* total bytes allocated for data, round up to 8 bytes */
677 __u32 data_len;
678 /* which arrays are included in data */
679 __u64 arrays;
680 struct bpf_prog_info info;
681 __u8 data[];
682};
683
684LIBBPF_API struct bpf_prog_info_linear *
685bpf_program__get_prog_info_linear(int fd, __u64 arrays);
686
687LIBBPF_API void
688bpf_program__bpil_addr_to_offs(struct bpf_prog_info_linear *info_linear);
689
690LIBBPF_API void
691bpf_program__bpil_offs_to_addr(struct bpf_prog_info_linear *info_linear);
692
693/*
694 * A helper function to get the number of possible CPUs before looking up
695 * per-CPU maps. Negative errno is returned on failure.
696 *
697 * Example usage:
698 *
699 * int ncpus = libbpf_num_possible_cpus();
700 * if (ncpus < 0) {
701 * // error handling
702 * }
703 * long values[ncpus];
704 * bpf_map_lookup_elem(per_cpu_map_fd, key, values);
705 *
706 */
707LIBBPF_API int libbpf_num_possible_cpus(void);
708
709struct bpf_map_skeleton {
710 const char *name;
711 struct bpf_map **map;
712 void **mmaped;
713};
714
715struct bpf_prog_skeleton {
716 const char *name;
717 struct bpf_program **prog;
718 struct bpf_link **link;
719};
720
721struct bpf_object_skeleton {
722 size_t sz; /* size of this struct, for forward/backward compatibility */
723
724 const char *name;
725 void *data;
726 size_t data_sz;
727
728 struct bpf_object **obj;
729
730 int map_cnt;
731 int map_skel_sz; /* sizeof(struct bpf_skeleton_map) */
732 struct bpf_map_skeleton *maps;
733
734 int prog_cnt;
735 int prog_skel_sz; /* sizeof(struct bpf_skeleton_prog) */
736 struct bpf_prog_skeleton *progs;
737};
738
739LIBBPF_API int
740bpf_object__open_skeleton(struct bpf_object_skeleton *s,
741 const struct bpf_object_open_opts *opts);
742LIBBPF_API int bpf_object__load_skeleton(struct bpf_object_skeleton *s);
743LIBBPF_API int bpf_object__attach_skeleton(struct bpf_object_skeleton *s);
744LIBBPF_API void bpf_object__detach_skeleton(struct bpf_object_skeleton *s);
745LIBBPF_API void bpf_object__destroy_skeleton(struct bpf_object_skeleton *s);
746
747enum libbpf_tristate {
748 TRI_NO = 0,
749 TRI_YES = 1,
750 TRI_MODULE = 2,
751};
752
753#ifdef __cplusplus
754} /* extern "C" */
755#endif
756
757#endif /* __LIBBPF_LIBBPF_H */
1/* SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause) */
2
3/*
4 * Common eBPF ELF object loading operations.
5 *
6 * Copyright (C) 2013-2015 Alexei Starovoitov <ast@kernel.org>
7 * Copyright (C) 2015 Wang Nan <wangnan0@huawei.com>
8 * Copyright (C) 2015 Huawei Inc.
9 */
10#ifndef __LIBBPF_LIBBPF_H
11#define __LIBBPF_LIBBPF_H
12
13#include <stdarg.h>
14#include <stdio.h>
15#include <stdint.h>
16#include <stdbool.h>
17#include <sys/types.h> // for size_t
18#include <linux/bpf.h>
19
20#include "libbpf_common.h"
21#include "libbpf_legacy.h"
22
23#ifdef __cplusplus
24extern "C" {
25#endif
26
27enum libbpf_errno {
28 __LIBBPF_ERRNO__START = 4000,
29
30 /* Something wrong in libelf */
31 LIBBPF_ERRNO__LIBELF = __LIBBPF_ERRNO__START,
32 LIBBPF_ERRNO__FORMAT, /* BPF object format invalid */
33 LIBBPF_ERRNO__KVERSION, /* Incorrect or no 'version' section */
34 LIBBPF_ERRNO__ENDIAN, /* Endian mismatch */
35 LIBBPF_ERRNO__INTERNAL, /* Internal error in libbpf */
36 LIBBPF_ERRNO__RELOC, /* Relocation failed */
37 LIBBPF_ERRNO__LOAD, /* Load program failure for unknown reason */
38 LIBBPF_ERRNO__VERIFY, /* Kernel verifier blocks program loading */
39 LIBBPF_ERRNO__PROG2BIG, /* Program too big */
40 LIBBPF_ERRNO__KVER, /* Incorrect kernel version */
41 LIBBPF_ERRNO__PROGTYPE, /* Kernel doesn't support this program type */
42 LIBBPF_ERRNO__WRNGPID, /* Wrong pid in netlink message */
43 LIBBPF_ERRNO__INVSEQ, /* Invalid netlink sequence */
44 LIBBPF_ERRNO__NLPARSE, /* netlink parsing error */
45 __LIBBPF_ERRNO__END,
46};
47
48LIBBPF_API int libbpf_strerror(int err, char *buf, size_t size);
49
50enum libbpf_print_level {
51 LIBBPF_WARN,
52 LIBBPF_INFO,
53 LIBBPF_DEBUG,
54};
55
56typedef int (*libbpf_print_fn_t)(enum libbpf_print_level level,
57 const char *, va_list ap);
58
59LIBBPF_API libbpf_print_fn_t libbpf_set_print(libbpf_print_fn_t fn);
60
61/* Hide internal to user */
62struct bpf_object;
63
64struct bpf_object_open_attr {
65 const char *file;
66 enum bpf_prog_type prog_type;
67};
68
69struct bpf_object_open_opts {
70 /* size of this struct, for forward/backward compatiblity */
71 size_t sz;
72 /* object name override, if provided:
73 * - for object open from file, this will override setting object
74 * name from file path's base name;
75 * - for object open from memory buffer, this will specify an object
76 * name and will override default "<addr>-<buf-size>" name;
77 */
78 const char *object_name;
79 /* parse map definitions non-strictly, allowing extra attributes/data */
80 bool relaxed_maps;
81 /* DEPRECATED: handle CO-RE relocations non-strictly, allowing failures.
82 * Value is ignored. Relocations always are processed non-strictly.
83 * Non-relocatable instructions are replaced with invalid ones to
84 * prevent accidental errors.
85 * */
86 bool relaxed_core_relocs;
87 /* maps that set the 'pinning' attribute in their definition will have
88 * their pin_path attribute set to a file in this directory, and be
89 * auto-pinned to that path on load; defaults to "/sys/fs/bpf".
90 */
91 const char *pin_root_path;
92 __u32 attach_prog_fd;
93 /* Additional kernel config content that augments and overrides
94 * system Kconfig for CONFIG_xxx externs.
95 */
96 const char *kconfig;
97};
98#define bpf_object_open_opts__last_field kconfig
99
100LIBBPF_API struct bpf_object *bpf_object__open(const char *path);
101LIBBPF_API struct bpf_object *
102bpf_object__open_file(const char *path, const struct bpf_object_open_opts *opts);
103LIBBPF_API struct bpf_object *
104bpf_object__open_mem(const void *obj_buf, size_t obj_buf_sz,
105 const struct bpf_object_open_opts *opts);
106
107/* deprecated bpf_object__open variants */
108LIBBPF_API struct bpf_object *
109bpf_object__open_buffer(const void *obj_buf, size_t obj_buf_sz,
110 const char *name);
111LIBBPF_API struct bpf_object *
112bpf_object__open_xattr(struct bpf_object_open_attr *attr);
113
114enum libbpf_pin_type {
115 LIBBPF_PIN_NONE,
116 /* PIN_BY_NAME: pin maps by name (in /sys/fs/bpf by default) */
117 LIBBPF_PIN_BY_NAME,
118};
119
120/* pin_maps and unpin_maps can both be called with a NULL path, in which case
121 * they will use the pin_path attribute of each map (and ignore all maps that
122 * don't have a pin_path set).
123 */
124LIBBPF_API int bpf_object__pin_maps(struct bpf_object *obj, const char *path);
125LIBBPF_API int bpf_object__unpin_maps(struct bpf_object *obj,
126 const char *path);
127LIBBPF_API int bpf_object__pin_programs(struct bpf_object *obj,
128 const char *path);
129LIBBPF_API int bpf_object__unpin_programs(struct bpf_object *obj,
130 const char *path);
131LIBBPF_API int bpf_object__pin(struct bpf_object *object, const char *path);
132LIBBPF_API void bpf_object__close(struct bpf_object *object);
133
134struct bpf_object_load_attr {
135 struct bpf_object *obj;
136 int log_level;
137 const char *target_btf_path;
138};
139
140/* Load/unload object into/from kernel */
141LIBBPF_API int bpf_object__load(struct bpf_object *obj);
142LIBBPF_API int bpf_object__load_xattr(struct bpf_object_load_attr *attr);
143LIBBPF_API int bpf_object__unload(struct bpf_object *obj);
144
145LIBBPF_API const char *bpf_object__name(const struct bpf_object *obj);
146LIBBPF_API unsigned int bpf_object__kversion(const struct bpf_object *obj);
147LIBBPF_API int bpf_object__set_kversion(struct bpf_object *obj, __u32 kern_version);
148
149struct btf;
150LIBBPF_API struct btf *bpf_object__btf(const struct bpf_object *obj);
151LIBBPF_API int bpf_object__btf_fd(const struct bpf_object *obj);
152
153LIBBPF_API struct bpf_program *
154bpf_object__find_program_by_title(const struct bpf_object *obj,
155 const char *title);
156LIBBPF_API struct bpf_program *
157bpf_object__find_program_by_name(const struct bpf_object *obj,
158 const char *name);
159
160LIBBPF_API struct bpf_object *bpf_object__next(struct bpf_object *prev);
161#define bpf_object__for_each_safe(pos, tmp) \
162 for ((pos) = bpf_object__next(NULL), \
163 (tmp) = bpf_object__next(pos); \
164 (pos) != NULL; \
165 (pos) = (tmp), (tmp) = bpf_object__next(tmp))
166
167typedef void (*bpf_object_clear_priv_t)(struct bpf_object *, void *);
168LIBBPF_API int bpf_object__set_priv(struct bpf_object *obj, void *priv,
169 bpf_object_clear_priv_t clear_priv);
170LIBBPF_API void *bpf_object__priv(const struct bpf_object *prog);
171
172LIBBPF_API int
173libbpf_prog_type_by_name(const char *name, enum bpf_prog_type *prog_type,
174 enum bpf_attach_type *expected_attach_type);
175LIBBPF_API int libbpf_attach_type_by_name(const char *name,
176 enum bpf_attach_type *attach_type);
177LIBBPF_API int libbpf_find_vmlinux_btf_id(const char *name,
178 enum bpf_attach_type attach_type);
179
180/* Accessors of bpf_program */
181struct bpf_program;
182LIBBPF_API struct bpf_program *bpf_program__next(struct bpf_program *prog,
183 const struct bpf_object *obj);
184
185#define bpf_object__for_each_program(pos, obj) \
186 for ((pos) = bpf_program__next(NULL, (obj)); \
187 (pos) != NULL; \
188 (pos) = bpf_program__next((pos), (obj)))
189
190LIBBPF_API struct bpf_program *bpf_program__prev(struct bpf_program *prog,
191 const struct bpf_object *obj);
192
193typedef void (*bpf_program_clear_priv_t)(struct bpf_program *, void *);
194
195LIBBPF_API int bpf_program__set_priv(struct bpf_program *prog, void *priv,
196 bpf_program_clear_priv_t clear_priv);
197
198LIBBPF_API void *bpf_program__priv(const struct bpf_program *prog);
199LIBBPF_API void bpf_program__set_ifindex(struct bpf_program *prog,
200 __u32 ifindex);
201
202LIBBPF_API const char *bpf_program__name(const struct bpf_program *prog);
203LIBBPF_API const char *bpf_program__section_name(const struct bpf_program *prog);
204LIBBPF_API LIBBPF_DEPRECATED("BPF program title is confusing term; please use bpf_program__section_name() instead")
205const char *bpf_program__title(const struct bpf_program *prog, bool needs_copy);
206LIBBPF_API bool bpf_program__autoload(const struct bpf_program *prog);
207LIBBPF_API int bpf_program__set_autoload(struct bpf_program *prog, bool autoload);
208
209/* returns program size in bytes */
210LIBBPF_API size_t bpf_program__size(const struct bpf_program *prog);
211
212LIBBPF_API int bpf_program__load(struct bpf_program *prog, char *license,
213 __u32 kern_version);
214LIBBPF_API int bpf_program__fd(const struct bpf_program *prog);
215LIBBPF_API int bpf_program__pin_instance(struct bpf_program *prog,
216 const char *path,
217 int instance);
218LIBBPF_API int bpf_program__unpin_instance(struct bpf_program *prog,
219 const char *path,
220 int instance);
221LIBBPF_API int bpf_program__pin(struct bpf_program *prog, const char *path);
222LIBBPF_API int bpf_program__unpin(struct bpf_program *prog, const char *path);
223LIBBPF_API void bpf_program__unload(struct bpf_program *prog);
224
225struct bpf_link;
226
227LIBBPF_API struct bpf_link *bpf_link__open(const char *path);
228LIBBPF_API int bpf_link__fd(const struct bpf_link *link);
229LIBBPF_API const char *bpf_link__pin_path(const struct bpf_link *link);
230LIBBPF_API int bpf_link__pin(struct bpf_link *link, const char *path);
231LIBBPF_API int bpf_link__unpin(struct bpf_link *link);
232LIBBPF_API int bpf_link__update_program(struct bpf_link *link,
233 struct bpf_program *prog);
234LIBBPF_API void bpf_link__disconnect(struct bpf_link *link);
235LIBBPF_API int bpf_link__detach(struct bpf_link *link);
236LIBBPF_API int bpf_link__destroy(struct bpf_link *link);
237
238LIBBPF_API struct bpf_link *
239bpf_program__attach(struct bpf_program *prog);
240LIBBPF_API struct bpf_link *
241bpf_program__attach_perf_event(struct bpf_program *prog, int pfd);
242LIBBPF_API struct bpf_link *
243bpf_program__attach_kprobe(struct bpf_program *prog, bool retprobe,
244 const char *func_name);
245LIBBPF_API struct bpf_link *
246bpf_program__attach_uprobe(struct bpf_program *prog, bool retprobe,
247 pid_t pid, const char *binary_path,
248 size_t func_offset);
249LIBBPF_API struct bpf_link *
250bpf_program__attach_tracepoint(struct bpf_program *prog,
251 const char *tp_category,
252 const char *tp_name);
253LIBBPF_API struct bpf_link *
254bpf_program__attach_raw_tracepoint(struct bpf_program *prog,
255 const char *tp_name);
256LIBBPF_API struct bpf_link *
257bpf_program__attach_trace(struct bpf_program *prog);
258LIBBPF_API struct bpf_link *
259bpf_program__attach_lsm(struct bpf_program *prog);
260LIBBPF_API struct bpf_link *
261bpf_program__attach_cgroup(struct bpf_program *prog, int cgroup_fd);
262LIBBPF_API struct bpf_link *
263bpf_program__attach_netns(struct bpf_program *prog, int netns_fd);
264LIBBPF_API struct bpf_link *
265bpf_program__attach_xdp(struct bpf_program *prog, int ifindex);
266LIBBPF_API struct bpf_link *
267bpf_program__attach_freplace(struct bpf_program *prog,
268 int target_fd, const char *attach_func_name);
269
270struct bpf_map;
271
272LIBBPF_API struct bpf_link *bpf_map__attach_struct_ops(struct bpf_map *map);
273
274struct bpf_iter_attach_opts {
275 size_t sz; /* size of this struct for forward/backward compatibility */
276 union bpf_iter_link_info *link_info;
277 __u32 link_info_len;
278};
279#define bpf_iter_attach_opts__last_field link_info_len
280
281LIBBPF_API struct bpf_link *
282bpf_program__attach_iter(struct bpf_program *prog,
283 const struct bpf_iter_attach_opts *opts);
284
285struct bpf_insn;
286
287/*
288 * Libbpf allows callers to adjust BPF programs before being loaded
289 * into kernel. One program in an object file can be transformed into
290 * multiple variants to be attached to different hooks.
291 *
292 * bpf_program_prep_t, bpf_program__set_prep and bpf_program__nth_fd
293 * form an API for this purpose.
294 *
295 * - bpf_program_prep_t:
296 * Defines a 'preprocessor', which is a caller defined function
297 * passed to libbpf through bpf_program__set_prep(), and will be
298 * called before program is loaded. The processor should adjust
299 * the program one time for each instance according to the instance id
300 * passed to it.
301 *
302 * - bpf_program__set_prep:
303 * Attaches a preprocessor to a BPF program. The number of instances
304 * that should be created is also passed through this function.
305 *
306 * - bpf_program__nth_fd:
307 * After the program is loaded, get resulting FD of a given instance
308 * of the BPF program.
309 *
310 * If bpf_program__set_prep() is not used, the program would be loaded
311 * without adjustment during bpf_object__load(). The program has only
312 * one instance. In this case bpf_program__fd(prog) is equal to
313 * bpf_program__nth_fd(prog, 0).
314 */
315
316struct bpf_prog_prep_result {
317 /*
318 * If not NULL, load new instruction array.
319 * If set to NULL, don't load this instance.
320 */
321 struct bpf_insn *new_insn_ptr;
322 int new_insn_cnt;
323
324 /* If not NULL, result FD is written to it. */
325 int *pfd;
326};
327
328/*
329 * Parameters of bpf_program_prep_t:
330 * - prog: The bpf_program being loaded.
331 * - n: Index of instance being generated.
332 * - insns: BPF instructions array.
333 * - insns_cnt:Number of instructions in insns.
334 * - res: Output parameter, result of transformation.
335 *
336 * Return value:
337 * - Zero: pre-processing success.
338 * - Non-zero: pre-processing error, stop loading.
339 */
340typedef int (*bpf_program_prep_t)(struct bpf_program *prog, int n,
341 struct bpf_insn *insns, int insns_cnt,
342 struct bpf_prog_prep_result *res);
343
344LIBBPF_API int bpf_program__set_prep(struct bpf_program *prog, int nr_instance,
345 bpf_program_prep_t prep);
346
347LIBBPF_API int bpf_program__nth_fd(const struct bpf_program *prog, int n);
348
349/*
350 * Adjust type of BPF program. Default is kprobe.
351 */
352LIBBPF_API int bpf_program__set_socket_filter(struct bpf_program *prog);
353LIBBPF_API int bpf_program__set_tracepoint(struct bpf_program *prog);
354LIBBPF_API int bpf_program__set_raw_tracepoint(struct bpf_program *prog);
355LIBBPF_API int bpf_program__set_kprobe(struct bpf_program *prog);
356LIBBPF_API int bpf_program__set_lsm(struct bpf_program *prog);
357LIBBPF_API int bpf_program__set_sched_cls(struct bpf_program *prog);
358LIBBPF_API int bpf_program__set_sched_act(struct bpf_program *prog);
359LIBBPF_API int bpf_program__set_xdp(struct bpf_program *prog);
360LIBBPF_API int bpf_program__set_perf_event(struct bpf_program *prog);
361LIBBPF_API int bpf_program__set_tracing(struct bpf_program *prog);
362LIBBPF_API int bpf_program__set_struct_ops(struct bpf_program *prog);
363LIBBPF_API int bpf_program__set_extension(struct bpf_program *prog);
364LIBBPF_API int bpf_program__set_sk_lookup(struct bpf_program *prog);
365
366LIBBPF_API enum bpf_prog_type bpf_program__get_type(const struct bpf_program *prog);
367LIBBPF_API void bpf_program__set_type(struct bpf_program *prog,
368 enum bpf_prog_type type);
369
370LIBBPF_API enum bpf_attach_type
371bpf_program__get_expected_attach_type(const struct bpf_program *prog);
372LIBBPF_API void
373bpf_program__set_expected_attach_type(struct bpf_program *prog,
374 enum bpf_attach_type type);
375
376LIBBPF_API int
377bpf_program__set_attach_target(struct bpf_program *prog, int attach_prog_fd,
378 const char *attach_func_name);
379
380LIBBPF_API bool bpf_program__is_socket_filter(const struct bpf_program *prog);
381LIBBPF_API bool bpf_program__is_tracepoint(const struct bpf_program *prog);
382LIBBPF_API bool bpf_program__is_raw_tracepoint(const struct bpf_program *prog);
383LIBBPF_API bool bpf_program__is_kprobe(const struct bpf_program *prog);
384LIBBPF_API bool bpf_program__is_lsm(const struct bpf_program *prog);
385LIBBPF_API bool bpf_program__is_sched_cls(const struct bpf_program *prog);
386LIBBPF_API bool bpf_program__is_sched_act(const struct bpf_program *prog);
387LIBBPF_API bool bpf_program__is_xdp(const struct bpf_program *prog);
388LIBBPF_API bool bpf_program__is_perf_event(const struct bpf_program *prog);
389LIBBPF_API bool bpf_program__is_tracing(const struct bpf_program *prog);
390LIBBPF_API bool bpf_program__is_struct_ops(const struct bpf_program *prog);
391LIBBPF_API bool bpf_program__is_extension(const struct bpf_program *prog);
392LIBBPF_API bool bpf_program__is_sk_lookup(const struct bpf_program *prog);
393
394/*
395 * No need for __attribute__((packed)), all members of 'bpf_map_def'
396 * are all aligned. In addition, using __attribute__((packed))
397 * would trigger a -Wpacked warning message, and lead to an error
398 * if -Werror is set.
399 */
400struct bpf_map_def {
401 unsigned int type;
402 unsigned int key_size;
403 unsigned int value_size;
404 unsigned int max_entries;
405 unsigned int map_flags;
406};
407
408/*
409 * The 'struct bpf_map' in include/linux/bpf.h is internal to the kernel,
410 * so no need to worry about a name clash.
411 */
412LIBBPF_API struct bpf_map *
413bpf_object__find_map_by_name(const struct bpf_object *obj, const char *name);
414
415LIBBPF_API int
416bpf_object__find_map_fd_by_name(const struct bpf_object *obj, const char *name);
417
418/*
419 * Get bpf_map through the offset of corresponding struct bpf_map_def
420 * in the BPF object file.
421 */
422LIBBPF_API struct bpf_map *
423bpf_object__find_map_by_offset(struct bpf_object *obj, size_t offset);
424
425LIBBPF_API struct bpf_map *
426bpf_map__next(const struct bpf_map *map, const struct bpf_object *obj);
427#define bpf_object__for_each_map(pos, obj) \
428 for ((pos) = bpf_map__next(NULL, (obj)); \
429 (pos) != NULL; \
430 (pos) = bpf_map__next((pos), (obj)))
431#define bpf_map__for_each bpf_object__for_each_map
432
433LIBBPF_API struct bpf_map *
434bpf_map__prev(const struct bpf_map *map, const struct bpf_object *obj);
435
436/* get/set map FD */
437LIBBPF_API int bpf_map__fd(const struct bpf_map *map);
438LIBBPF_API int bpf_map__reuse_fd(struct bpf_map *map, int fd);
439/* get map definition */
440LIBBPF_API const struct bpf_map_def *bpf_map__def(const struct bpf_map *map);
441/* get map name */
442LIBBPF_API const char *bpf_map__name(const struct bpf_map *map);
443/* get/set map type */
444LIBBPF_API enum bpf_map_type bpf_map__type(const struct bpf_map *map);
445LIBBPF_API int bpf_map__set_type(struct bpf_map *map, enum bpf_map_type type);
446/* get/set map size (max_entries) */
447LIBBPF_API __u32 bpf_map__max_entries(const struct bpf_map *map);
448LIBBPF_API int bpf_map__set_max_entries(struct bpf_map *map, __u32 max_entries);
449LIBBPF_API int bpf_map__resize(struct bpf_map *map, __u32 max_entries);
450/* get/set map flags */
451LIBBPF_API __u32 bpf_map__map_flags(const struct bpf_map *map);
452LIBBPF_API int bpf_map__set_map_flags(struct bpf_map *map, __u32 flags);
453/* get/set map NUMA node */
454LIBBPF_API __u32 bpf_map__numa_node(const struct bpf_map *map);
455LIBBPF_API int bpf_map__set_numa_node(struct bpf_map *map, __u32 numa_node);
456/* get/set map key size */
457LIBBPF_API __u32 bpf_map__key_size(const struct bpf_map *map);
458LIBBPF_API int bpf_map__set_key_size(struct bpf_map *map, __u32 size);
459/* get/set map value size */
460LIBBPF_API __u32 bpf_map__value_size(const struct bpf_map *map);
461LIBBPF_API int bpf_map__set_value_size(struct bpf_map *map, __u32 size);
462/* get map key/value BTF type IDs */
463LIBBPF_API __u32 bpf_map__btf_key_type_id(const struct bpf_map *map);
464LIBBPF_API __u32 bpf_map__btf_value_type_id(const struct bpf_map *map);
465/* get/set map if_index */
466LIBBPF_API __u32 bpf_map__ifindex(const struct bpf_map *map);
467LIBBPF_API int bpf_map__set_ifindex(struct bpf_map *map, __u32 ifindex);
468
469typedef void (*bpf_map_clear_priv_t)(struct bpf_map *, void *);
470LIBBPF_API int bpf_map__set_priv(struct bpf_map *map, void *priv,
471 bpf_map_clear_priv_t clear_priv);
472LIBBPF_API void *bpf_map__priv(const struct bpf_map *map);
473LIBBPF_API int bpf_map__set_initial_value(struct bpf_map *map,
474 const void *data, size_t size);
475LIBBPF_API const void *bpf_map__initial_value(struct bpf_map *map, size_t *psize);
476LIBBPF_API bool bpf_map__is_offload_neutral(const struct bpf_map *map);
477LIBBPF_API bool bpf_map__is_internal(const struct bpf_map *map);
478LIBBPF_API int bpf_map__set_pin_path(struct bpf_map *map, const char *path);
479LIBBPF_API const char *bpf_map__get_pin_path(const struct bpf_map *map);
480LIBBPF_API bool bpf_map__is_pinned(const struct bpf_map *map);
481LIBBPF_API int bpf_map__pin(struct bpf_map *map, const char *path);
482LIBBPF_API int bpf_map__unpin(struct bpf_map *map, const char *path);
483
484LIBBPF_API int bpf_map__set_inner_map_fd(struct bpf_map *map, int fd);
485LIBBPF_API struct bpf_map *bpf_map__inner_map(struct bpf_map *map);
486
487LIBBPF_API long libbpf_get_error(const void *ptr);
488
489struct bpf_prog_load_attr {
490 const char *file;
491 enum bpf_prog_type prog_type;
492 enum bpf_attach_type expected_attach_type;
493 int ifindex;
494 int log_level;
495 int prog_flags;
496};
497
498LIBBPF_API int bpf_prog_load_xattr(const struct bpf_prog_load_attr *attr,
499 struct bpf_object **pobj, int *prog_fd);
500LIBBPF_API int bpf_prog_load(const char *file, enum bpf_prog_type type,
501 struct bpf_object **pobj, int *prog_fd);
502
503/* XDP related API */
504struct xdp_link_info {
505 __u32 prog_id;
506 __u32 drv_prog_id;
507 __u32 hw_prog_id;
508 __u32 skb_prog_id;
509 __u8 attach_mode;
510};
511
512struct bpf_xdp_set_link_opts {
513 size_t sz;
514 int old_fd;
515 size_t :0;
516};
517#define bpf_xdp_set_link_opts__last_field old_fd
518
519LIBBPF_API int bpf_set_link_xdp_fd(int ifindex, int fd, __u32 flags);
520LIBBPF_API int bpf_set_link_xdp_fd_opts(int ifindex, int fd, __u32 flags,
521 const struct bpf_xdp_set_link_opts *opts);
522LIBBPF_API int bpf_get_link_xdp_id(int ifindex, __u32 *prog_id, __u32 flags);
523LIBBPF_API int bpf_get_link_xdp_info(int ifindex, struct xdp_link_info *info,
524 size_t info_size, __u32 flags);
525
526/* TC related API */
527enum bpf_tc_attach_point {
528 BPF_TC_INGRESS = 1 << 0,
529 BPF_TC_EGRESS = 1 << 1,
530 BPF_TC_CUSTOM = 1 << 2,
531};
532
533#define BPF_TC_PARENT(a, b) \
534 ((((a) << 16) & 0xFFFF0000U) | ((b) & 0x0000FFFFU))
535
536enum bpf_tc_flags {
537 BPF_TC_F_REPLACE = 1 << 0,
538};
539
540struct bpf_tc_hook {
541 size_t sz;
542 int ifindex;
543 enum bpf_tc_attach_point attach_point;
544 __u32 parent;
545 size_t :0;
546};
547#define bpf_tc_hook__last_field parent
548
549struct bpf_tc_opts {
550 size_t sz;
551 int prog_fd;
552 __u32 flags;
553 __u32 prog_id;
554 __u32 handle;
555 __u32 priority;
556 size_t :0;
557};
558#define bpf_tc_opts__last_field priority
559
560LIBBPF_API int bpf_tc_hook_create(struct bpf_tc_hook *hook);
561LIBBPF_API int bpf_tc_hook_destroy(struct bpf_tc_hook *hook);
562LIBBPF_API int bpf_tc_attach(const struct bpf_tc_hook *hook,
563 struct bpf_tc_opts *opts);
564LIBBPF_API int bpf_tc_detach(const struct bpf_tc_hook *hook,
565 const struct bpf_tc_opts *opts);
566LIBBPF_API int bpf_tc_query(const struct bpf_tc_hook *hook,
567 struct bpf_tc_opts *opts);
568
569/* Ring buffer APIs */
570struct ring_buffer;
571
572typedef int (*ring_buffer_sample_fn)(void *ctx, void *data, size_t size);
573
574struct ring_buffer_opts {
575 size_t sz; /* size of this struct, for forward/backward compatiblity */
576};
577
578#define ring_buffer_opts__last_field sz
579
580LIBBPF_API struct ring_buffer *
581ring_buffer__new(int map_fd, ring_buffer_sample_fn sample_cb, void *ctx,
582 const struct ring_buffer_opts *opts);
583LIBBPF_API void ring_buffer__free(struct ring_buffer *rb);
584LIBBPF_API int ring_buffer__add(struct ring_buffer *rb, int map_fd,
585 ring_buffer_sample_fn sample_cb, void *ctx);
586LIBBPF_API int ring_buffer__poll(struct ring_buffer *rb, int timeout_ms);
587LIBBPF_API int ring_buffer__consume(struct ring_buffer *rb);
588LIBBPF_API int ring_buffer__epoll_fd(const struct ring_buffer *rb);
589
590/* Perf buffer APIs */
591struct perf_buffer;
592
593typedef void (*perf_buffer_sample_fn)(void *ctx, int cpu,
594 void *data, __u32 size);
595typedef void (*perf_buffer_lost_fn)(void *ctx, int cpu, __u64 cnt);
596
597/* common use perf buffer options */
598struct perf_buffer_opts {
599 /* if specified, sample_cb is called for each sample */
600 perf_buffer_sample_fn sample_cb;
601 /* if specified, lost_cb is called for each batch of lost samples */
602 perf_buffer_lost_fn lost_cb;
603 /* ctx is provided to sample_cb and lost_cb */
604 void *ctx;
605};
606
607LIBBPF_API struct perf_buffer *
608perf_buffer__new(int map_fd, size_t page_cnt,
609 const struct perf_buffer_opts *opts);
610
611enum bpf_perf_event_ret {
612 LIBBPF_PERF_EVENT_DONE = 0,
613 LIBBPF_PERF_EVENT_ERROR = -1,
614 LIBBPF_PERF_EVENT_CONT = -2,
615};
616
617struct perf_event_header;
618
619typedef enum bpf_perf_event_ret
620(*perf_buffer_event_fn)(void *ctx, int cpu, struct perf_event_header *event);
621
622/* raw perf buffer options, giving most power and control */
623struct perf_buffer_raw_opts {
624 /* perf event attrs passed directly into perf_event_open() */
625 struct perf_event_attr *attr;
626 /* raw event callback */
627 perf_buffer_event_fn event_cb;
628 /* ctx is provided to event_cb */
629 void *ctx;
630 /* if cpu_cnt == 0, open all on all possible CPUs (up to the number of
631 * max_entries of given PERF_EVENT_ARRAY map)
632 */
633 int cpu_cnt;
634 /* if cpu_cnt > 0, cpus is an array of CPUs to open ring buffers on */
635 int *cpus;
636 /* if cpu_cnt > 0, map_keys specify map keys to set per-CPU FDs for */
637 int *map_keys;
638};
639
640LIBBPF_API struct perf_buffer *
641perf_buffer__new_raw(int map_fd, size_t page_cnt,
642 const struct perf_buffer_raw_opts *opts);
643
644LIBBPF_API void perf_buffer__free(struct perf_buffer *pb);
645LIBBPF_API int perf_buffer__epoll_fd(const struct perf_buffer *pb);
646LIBBPF_API int perf_buffer__poll(struct perf_buffer *pb, int timeout_ms);
647LIBBPF_API int perf_buffer__consume(struct perf_buffer *pb);
648LIBBPF_API int perf_buffer__consume_buffer(struct perf_buffer *pb, size_t buf_idx);
649LIBBPF_API size_t perf_buffer__buffer_cnt(const struct perf_buffer *pb);
650LIBBPF_API int perf_buffer__buffer_fd(const struct perf_buffer *pb, size_t buf_idx);
651
652typedef enum bpf_perf_event_ret
653 (*bpf_perf_event_print_t)(struct perf_event_header *hdr,
654 void *private_data);
655LIBBPF_API enum bpf_perf_event_ret
656bpf_perf_event_read_simple(void *mmap_mem, size_t mmap_size, size_t page_size,
657 void **copy_mem, size_t *copy_size,
658 bpf_perf_event_print_t fn, void *private_data);
659
660struct bpf_prog_linfo;
661struct bpf_prog_info;
662
663LIBBPF_API void bpf_prog_linfo__free(struct bpf_prog_linfo *prog_linfo);
664LIBBPF_API struct bpf_prog_linfo *
665bpf_prog_linfo__new(const struct bpf_prog_info *info);
666LIBBPF_API const struct bpf_line_info *
667bpf_prog_linfo__lfind_addr_func(const struct bpf_prog_linfo *prog_linfo,
668 __u64 addr, __u32 func_idx, __u32 nr_skip);
669LIBBPF_API const struct bpf_line_info *
670bpf_prog_linfo__lfind(const struct bpf_prog_linfo *prog_linfo,
671 __u32 insn_off, __u32 nr_skip);
672
673/*
674 * Probe for supported system features
675 *
676 * Note that running many of these probes in a short amount of time can cause
677 * the kernel to reach the maximal size of lockable memory allowed for the
678 * user, causing subsequent probes to fail. In this case, the caller may want
679 * to adjust that limit with setrlimit().
680 */
681LIBBPF_API bool bpf_probe_prog_type(enum bpf_prog_type prog_type,
682 __u32 ifindex);
683LIBBPF_API bool bpf_probe_map_type(enum bpf_map_type map_type, __u32 ifindex);
684LIBBPF_API bool bpf_probe_helper(enum bpf_func_id id,
685 enum bpf_prog_type prog_type, __u32 ifindex);
686LIBBPF_API bool bpf_probe_large_insn_limit(__u32 ifindex);
687
688/*
689 * Get bpf_prog_info in continuous memory
690 *
691 * struct bpf_prog_info has multiple arrays. The user has option to choose
692 * arrays to fetch from kernel. The following APIs provide an uniform way to
693 * fetch these data. All arrays in bpf_prog_info are stored in a single
694 * continuous memory region. This makes it easy to store the info in a
695 * file.
696 *
697 * Before writing bpf_prog_info_linear to files, it is necessary to
698 * translate pointers in bpf_prog_info to offsets. Helper functions
699 * bpf_program__bpil_addr_to_offs() and bpf_program__bpil_offs_to_addr()
700 * are introduced to switch between pointers and offsets.
701 *
702 * Examples:
703 * # To fetch map_ids and prog_tags:
704 * __u64 arrays = (1UL << BPF_PROG_INFO_MAP_IDS) |
705 * (1UL << BPF_PROG_INFO_PROG_TAGS);
706 * struct bpf_prog_info_linear *info_linear =
707 * bpf_program__get_prog_info_linear(fd, arrays);
708 *
709 * # To save data in file
710 * bpf_program__bpil_addr_to_offs(info_linear);
711 * write(f, info_linear, sizeof(*info_linear) + info_linear->data_len);
712 *
713 * # To read data from file
714 * read(f, info_linear, <proper_size>);
715 * bpf_program__bpil_offs_to_addr(info_linear);
716 */
717enum bpf_prog_info_array {
718 BPF_PROG_INFO_FIRST_ARRAY = 0,
719 BPF_PROG_INFO_JITED_INSNS = 0,
720 BPF_PROG_INFO_XLATED_INSNS,
721 BPF_PROG_INFO_MAP_IDS,
722 BPF_PROG_INFO_JITED_KSYMS,
723 BPF_PROG_INFO_JITED_FUNC_LENS,
724 BPF_PROG_INFO_FUNC_INFO,
725 BPF_PROG_INFO_LINE_INFO,
726 BPF_PROG_INFO_JITED_LINE_INFO,
727 BPF_PROG_INFO_PROG_TAGS,
728 BPF_PROG_INFO_LAST_ARRAY,
729};
730
731struct bpf_prog_info_linear {
732 /* size of struct bpf_prog_info, when the tool is compiled */
733 __u32 info_len;
734 /* total bytes allocated for data, round up to 8 bytes */
735 __u32 data_len;
736 /* which arrays are included in data */
737 __u64 arrays;
738 struct bpf_prog_info info;
739 __u8 data[];
740};
741
742LIBBPF_API struct bpf_prog_info_linear *
743bpf_program__get_prog_info_linear(int fd, __u64 arrays);
744
745LIBBPF_API void
746bpf_program__bpil_addr_to_offs(struct bpf_prog_info_linear *info_linear);
747
748LIBBPF_API void
749bpf_program__bpil_offs_to_addr(struct bpf_prog_info_linear *info_linear);
750
751/*
752 * A helper function to get the number of possible CPUs before looking up
753 * per-CPU maps. Negative errno is returned on failure.
754 *
755 * Example usage:
756 *
757 * int ncpus = libbpf_num_possible_cpus();
758 * if (ncpus < 0) {
759 * // error handling
760 * }
761 * long values[ncpus];
762 * bpf_map_lookup_elem(per_cpu_map_fd, key, values);
763 *
764 */
765LIBBPF_API int libbpf_num_possible_cpus(void);
766
767struct bpf_map_skeleton {
768 const char *name;
769 struct bpf_map **map;
770 void **mmaped;
771};
772
773struct bpf_prog_skeleton {
774 const char *name;
775 struct bpf_program **prog;
776 struct bpf_link **link;
777};
778
779struct bpf_object_skeleton {
780 size_t sz; /* size of this struct, for forward/backward compatibility */
781
782 const char *name;
783 void *data;
784 size_t data_sz;
785
786 struct bpf_object **obj;
787
788 int map_cnt;
789 int map_skel_sz; /* sizeof(struct bpf_skeleton_map) */
790 struct bpf_map_skeleton *maps;
791
792 int prog_cnt;
793 int prog_skel_sz; /* sizeof(struct bpf_skeleton_prog) */
794 struct bpf_prog_skeleton *progs;
795};
796
797LIBBPF_API int
798bpf_object__open_skeleton(struct bpf_object_skeleton *s,
799 const struct bpf_object_open_opts *opts);
800LIBBPF_API int bpf_object__load_skeleton(struct bpf_object_skeleton *s);
801LIBBPF_API int bpf_object__attach_skeleton(struct bpf_object_skeleton *s);
802LIBBPF_API void bpf_object__detach_skeleton(struct bpf_object_skeleton *s);
803LIBBPF_API void bpf_object__destroy_skeleton(struct bpf_object_skeleton *s);
804
805struct gen_loader_opts {
806 size_t sz; /* size of this struct, for forward/backward compatiblity */
807 const char *data;
808 const char *insns;
809 __u32 data_sz;
810 __u32 insns_sz;
811};
812
813#define gen_loader_opts__last_field insns_sz
814LIBBPF_API int bpf_object__gen_loader(struct bpf_object *obj,
815 struct gen_loader_opts *opts);
816
817enum libbpf_tristate {
818 TRI_NO = 0,
819 TRI_YES = 1,
820 TRI_MODULE = 2,
821};
822
823struct bpf_linker_opts {
824 /* size of this struct, for forward/backward compatiblity */
825 size_t sz;
826};
827#define bpf_linker_opts__last_field sz
828
829struct bpf_linker_file_opts {
830 /* size of this struct, for forward/backward compatiblity */
831 size_t sz;
832};
833#define bpf_linker_file_opts__last_field sz
834
835struct bpf_linker;
836
837LIBBPF_API struct bpf_linker *bpf_linker__new(const char *filename, struct bpf_linker_opts *opts);
838LIBBPF_API int bpf_linker__add_file(struct bpf_linker *linker,
839 const char *filename,
840 const struct bpf_linker_file_opts *opts);
841LIBBPF_API int bpf_linker__finalize(struct bpf_linker *linker);
842LIBBPF_API void bpf_linker__free(struct bpf_linker *linker);
843
844#ifdef __cplusplus
845} /* extern "C" */
846#endif
847
848#endif /* __LIBBPF_LIBBPF_H */