1 /* SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause) */
4 * Common eBPF ELF object loading operations.
6 * Copyright (C) 2013-2015 Alexei Starovoitov <ast@kernel.org>
7 * Copyright (C) 2015 Wang Nan <wangnan0@huawei.com>
8 * Copyright (C) 2015 Huawei Inc.
10 #ifndef __LIBBPF_LIBBPF_H
11 #define __LIBBPF_LIBBPF_H
17 #include <sys/types.h> // for size_t
18 #include <linux/bpf.h>
25 #define LIBBPF_API __attribute__((visibility("default")))
29 __LIBBPF_ERRNO__START = 4000,
31 /* Something wrong in libelf */
32 LIBBPF_ERRNO__LIBELF = __LIBBPF_ERRNO__START,
33 LIBBPF_ERRNO__FORMAT, /* BPF object format invalid */
34 LIBBPF_ERRNO__KVERSION, /* Incorrect or no 'version' section */
35 LIBBPF_ERRNO__ENDIAN, /* Endian mismatch */
36 LIBBPF_ERRNO__INTERNAL, /* Internal error in libbpf */
37 LIBBPF_ERRNO__RELOC, /* Relocation failed */
38 LIBBPF_ERRNO__LOAD, /* Load program failure for unknown reason */
39 LIBBPF_ERRNO__VERIFY, /* Kernel verifier blocks program loading */
40 LIBBPF_ERRNO__PROG2BIG, /* Program too big */
41 LIBBPF_ERRNO__KVER, /* Incorrect kernel version */
42 LIBBPF_ERRNO__PROGTYPE, /* Kernel doesn't support this program type */
43 LIBBPF_ERRNO__WRNGPID, /* Wrong pid in netlink message */
44 LIBBPF_ERRNO__INVSEQ, /* Invalid netlink sequence */
45 LIBBPF_ERRNO__NLPARSE, /* netlink parsing error */
49 LIBBPF_API int libbpf_strerror(int err, char *buf, size_t size);
51 enum libbpf_print_level {
57 typedef int (*libbpf_print_fn_t)(enum libbpf_print_level level,
58 const char *, va_list ap);
60 LIBBPF_API void libbpf_set_print(libbpf_print_fn_t fn);
62 /* Hide internal to user */
65 struct bpf_object_open_attr {
67 enum bpf_prog_type prog_type;
70 LIBBPF_API struct bpf_object *bpf_object__open(const char *path);
71 LIBBPF_API struct bpf_object *
72 bpf_object__open_xattr(struct bpf_object_open_attr *attr);
73 struct bpf_object *__bpf_object__open_xattr(struct bpf_object_open_attr *attr,
75 LIBBPF_API struct bpf_object *bpf_object__open_buffer(void *obj_buf,
78 int bpf_object__section_size(const struct bpf_object *obj, const char *name,
80 int bpf_object__variable_offset(const struct bpf_object *obj, const char *name,
82 LIBBPF_API int bpf_object__pin_maps(struct bpf_object *obj, const char *path);
83 LIBBPF_API int bpf_object__unpin_maps(struct bpf_object *obj,
85 LIBBPF_API int bpf_object__pin_programs(struct bpf_object *obj,
87 LIBBPF_API int bpf_object__unpin_programs(struct bpf_object *obj,
89 LIBBPF_API int bpf_object__pin(struct bpf_object *object, const char *path);
90 LIBBPF_API void bpf_object__close(struct bpf_object *object);
92 struct bpf_object_load_attr {
93 struct bpf_object *obj;
97 /* Load/unload object into/from kernel */
98 LIBBPF_API int bpf_object__load(struct bpf_object *obj);
99 LIBBPF_API int bpf_object__load_xattr(struct bpf_object_load_attr *attr);
100 LIBBPF_API int bpf_object__unload(struct bpf_object *obj);
101 LIBBPF_API const char *bpf_object__name(const struct bpf_object *obj);
102 LIBBPF_API unsigned int bpf_object__kversion(const struct bpf_object *obj);
105 LIBBPF_API struct btf *bpf_object__btf(const struct bpf_object *obj);
106 LIBBPF_API int bpf_object__btf_fd(const struct bpf_object *obj);
108 LIBBPF_API struct bpf_program *
109 bpf_object__find_program_by_title(const struct bpf_object *obj,
112 LIBBPF_API struct bpf_object *bpf_object__next(struct bpf_object *prev);
113 #define bpf_object__for_each_safe(pos, tmp) \
114 for ((pos) = bpf_object__next(NULL), \
115 (tmp) = bpf_object__next(pos); \
117 (pos) = (tmp), (tmp) = bpf_object__next(tmp))
119 typedef void (*bpf_object_clear_priv_t)(struct bpf_object *, void *);
120 LIBBPF_API int bpf_object__set_priv(struct bpf_object *obj, void *priv,
121 bpf_object_clear_priv_t clear_priv);
122 LIBBPF_API void *bpf_object__priv(const struct bpf_object *prog);
125 libbpf_prog_type_by_name(const char *name, enum bpf_prog_type *prog_type,
126 enum bpf_attach_type *expected_attach_type);
127 LIBBPF_API int libbpf_attach_type_by_name(const char *name,
128 enum bpf_attach_type *attach_type);
130 /* Accessors of bpf_program */
132 LIBBPF_API struct bpf_program *bpf_program__next(struct bpf_program *prog,
133 const struct bpf_object *obj);
135 #define bpf_object__for_each_program(pos, obj) \
136 for ((pos) = bpf_program__next(NULL, (obj)); \
138 (pos) = bpf_program__next((pos), (obj)))
140 LIBBPF_API struct bpf_program *bpf_program__prev(struct bpf_program *prog,
141 const struct bpf_object *obj);
143 typedef void (*bpf_program_clear_priv_t)(struct bpf_program *, void *);
145 LIBBPF_API int bpf_program__set_priv(struct bpf_program *prog, void *priv,
146 bpf_program_clear_priv_t clear_priv);
148 LIBBPF_API void *bpf_program__priv(const struct bpf_program *prog);
149 LIBBPF_API void bpf_program__set_ifindex(struct bpf_program *prog,
152 LIBBPF_API const char *bpf_program__title(const struct bpf_program *prog,
155 LIBBPF_API int bpf_program__load(struct bpf_program *prog, char *license,
157 LIBBPF_API int bpf_program__fd(const struct bpf_program *prog);
158 LIBBPF_API int bpf_program__pin_instance(struct bpf_program *prog,
161 LIBBPF_API int bpf_program__unpin_instance(struct bpf_program *prog,
164 LIBBPF_API int bpf_program__pin(struct bpf_program *prog, const char *path);
165 LIBBPF_API int bpf_program__unpin(struct bpf_program *prog, const char *path);
166 LIBBPF_API void bpf_program__unload(struct bpf_program *prog);
170 LIBBPF_API int bpf_link__destroy(struct bpf_link *link);
172 LIBBPF_API struct bpf_link *
173 bpf_program__attach_perf_event(struct bpf_program *prog, int pfd);
174 LIBBPF_API struct bpf_link *
175 bpf_program__attach_kprobe(struct bpf_program *prog, bool retprobe,
176 const char *func_name);
177 LIBBPF_API struct bpf_link *
178 bpf_program__attach_uprobe(struct bpf_program *prog, bool retprobe,
179 pid_t pid, const char *binary_path,
181 LIBBPF_API struct bpf_link *
182 bpf_program__attach_tracepoint(struct bpf_program *prog,
183 const char *tp_category,
184 const char *tp_name);
185 LIBBPF_API struct bpf_link *
186 bpf_program__attach_raw_tracepoint(struct bpf_program *prog,
187 const char *tp_name);
192 * Libbpf allows callers to adjust BPF programs before being loaded
193 * into kernel. One program in an object file can be transformed into
194 * multiple variants to be attached to different hooks.
196 * bpf_program_prep_t, bpf_program__set_prep and bpf_program__nth_fd
197 * form an API for this purpose.
199 * - bpf_program_prep_t:
200 * Defines a 'preprocessor', which is a caller defined function
201 * passed to libbpf through bpf_program__set_prep(), and will be
202 * called before program is loaded. The processor should adjust
203 * the program one time for each instance according to the instance id
206 * - bpf_program__set_prep:
207 * Attaches a preprocessor to a BPF program. The number of instances
208 * that should be created is also passed through this function.
210 * - bpf_program__nth_fd:
211 * After the program is loaded, get resulting FD of a given instance
212 * of the BPF program.
214 * If bpf_program__set_prep() is not used, the program would be loaded
215 * without adjustment during bpf_object__load(). The program has only
216 * one instance. In this case bpf_program__fd(prog) is equal to
217 * bpf_program__nth_fd(prog, 0).
220 struct bpf_prog_prep_result {
222 * If not NULL, load new instruction array.
223 * If set to NULL, don't load this instance.
225 struct bpf_insn *new_insn_ptr;
228 /* If not NULL, result FD is written to it. */
233 * Parameters of bpf_program_prep_t:
234 * - prog: The bpf_program being loaded.
235 * - n: Index of instance being generated.
236 * - insns: BPF instructions array.
237 * - insns_cnt:Number of instructions in insns.
238 * - res: Output parameter, result of transformation.
241 * - Zero: pre-processing success.
242 * - Non-zero: pre-processing error, stop loading.
244 typedef int (*bpf_program_prep_t)(struct bpf_program *prog, int n,
245 struct bpf_insn *insns, int insns_cnt,
246 struct bpf_prog_prep_result *res);
248 LIBBPF_API int bpf_program__set_prep(struct bpf_program *prog, int nr_instance,
249 bpf_program_prep_t prep);
251 LIBBPF_API int bpf_program__nth_fd(const struct bpf_program *prog, int n);
254 * Adjust type of BPF program. Default is kprobe.
256 LIBBPF_API int bpf_program__set_socket_filter(struct bpf_program *prog);
257 LIBBPF_API int bpf_program__set_tracepoint(struct bpf_program *prog);
258 LIBBPF_API int bpf_program__set_raw_tracepoint(struct bpf_program *prog);
259 LIBBPF_API int bpf_program__set_kprobe(struct bpf_program *prog);
260 LIBBPF_API int bpf_program__set_sched_cls(struct bpf_program *prog);
261 LIBBPF_API int bpf_program__set_sched_act(struct bpf_program *prog);
262 LIBBPF_API int bpf_program__set_xdp(struct bpf_program *prog);
263 LIBBPF_API int bpf_program__set_perf_event(struct bpf_program *prog);
264 LIBBPF_API void bpf_program__set_type(struct bpf_program *prog,
265 enum bpf_prog_type type);
267 bpf_program__set_expected_attach_type(struct bpf_program *prog,
268 enum bpf_attach_type type);
270 LIBBPF_API bool bpf_program__is_socket_filter(const struct bpf_program *prog);
271 LIBBPF_API bool bpf_program__is_tracepoint(const struct bpf_program *prog);
272 LIBBPF_API bool bpf_program__is_raw_tracepoint(const struct bpf_program *prog);
273 LIBBPF_API bool bpf_program__is_kprobe(const struct bpf_program *prog);
274 LIBBPF_API bool bpf_program__is_sched_cls(const struct bpf_program *prog);
275 LIBBPF_API bool bpf_program__is_sched_act(const struct bpf_program *prog);
276 LIBBPF_API bool bpf_program__is_xdp(const struct bpf_program *prog);
277 LIBBPF_API bool bpf_program__is_perf_event(const struct bpf_program *prog);
280 * No need for __attribute__((packed)), all members of 'bpf_map_def'
281 * are all aligned. In addition, using __attribute__((packed))
282 * would trigger a -Wpacked warning message, and lead to an error
287 unsigned int key_size;
288 unsigned int value_size;
289 unsigned int max_entries;
290 unsigned int map_flags;
294 * The 'struct bpf_map' in include/linux/bpf.h is internal to the kernel,
295 * so no need to worry about a name clash.
298 LIBBPF_API struct bpf_map *
299 bpf_object__find_map_by_name(const struct bpf_object *obj, const char *name);
302 bpf_object__find_map_fd_by_name(const struct bpf_object *obj, const char *name);
305 * Get bpf_map through the offset of corresponding struct bpf_map_def
306 * in the BPF object file.
308 LIBBPF_API struct bpf_map *
309 bpf_object__find_map_by_offset(struct bpf_object *obj, size_t offset);
311 LIBBPF_API struct bpf_map *
312 bpf_map__next(const struct bpf_map *map, const struct bpf_object *obj);
313 #define bpf_object__for_each_map(pos, obj) \
314 for ((pos) = bpf_map__next(NULL, (obj)); \
316 (pos) = bpf_map__next((pos), (obj)))
317 #define bpf_map__for_each bpf_object__for_each_map
319 LIBBPF_API struct bpf_map *
320 bpf_map__prev(const struct bpf_map *map, const struct bpf_object *obj);
322 LIBBPF_API int bpf_map__fd(const struct bpf_map *map);
323 LIBBPF_API const struct bpf_map_def *bpf_map__def(const struct bpf_map *map);
324 LIBBPF_API const char *bpf_map__name(const struct bpf_map *map);
325 LIBBPF_API __u32 bpf_map__btf_key_type_id(const struct bpf_map *map);
326 LIBBPF_API __u32 bpf_map__btf_value_type_id(const struct bpf_map *map);
328 typedef void (*bpf_map_clear_priv_t)(struct bpf_map *, void *);
329 LIBBPF_API int bpf_map__set_priv(struct bpf_map *map, void *priv,
330 bpf_map_clear_priv_t clear_priv);
331 LIBBPF_API void *bpf_map__priv(const struct bpf_map *map);
332 LIBBPF_API int bpf_map__reuse_fd(struct bpf_map *map, int fd);
333 LIBBPF_API int bpf_map__resize(struct bpf_map *map, __u32 max_entries);
334 LIBBPF_API bool bpf_map__is_offload_neutral(const struct bpf_map *map);
335 LIBBPF_API bool bpf_map__is_internal(const struct bpf_map *map);
336 LIBBPF_API void bpf_map__set_ifindex(struct bpf_map *map, __u32 ifindex);
337 LIBBPF_API int bpf_map__pin(struct bpf_map *map, const char *path);
338 LIBBPF_API int bpf_map__unpin(struct bpf_map *map, const char *path);
340 LIBBPF_API int bpf_map__set_inner_map_fd(struct bpf_map *map, int fd);
342 LIBBPF_API long libbpf_get_error(const void *ptr);
344 struct bpf_prog_load_attr {
346 enum bpf_prog_type prog_type;
347 enum bpf_attach_type expected_attach_type;
353 LIBBPF_API int bpf_prog_load_xattr(const struct bpf_prog_load_attr *attr,
354 struct bpf_object **pobj, int *prog_fd);
355 LIBBPF_API int bpf_prog_load(const char *file, enum bpf_prog_type type,
356 struct bpf_object **pobj, int *prog_fd);
358 LIBBPF_API int bpf_set_link_xdp_fd(int ifindex, int fd, __u32 flags);
359 LIBBPF_API int bpf_get_link_xdp_id(int ifindex, __u32 *prog_id, __u32 flags);
363 typedef void (*perf_buffer_sample_fn)(void *ctx, int cpu,
364 void *data, __u32 size);
365 typedef void (*perf_buffer_lost_fn)(void *ctx, int cpu, __u64 cnt);
367 /* common use perf buffer options */
368 struct perf_buffer_opts {
369 /* if specified, sample_cb is called for each sample */
370 perf_buffer_sample_fn sample_cb;
371 /* if specified, lost_cb is called for each batch of lost samples */
372 perf_buffer_lost_fn lost_cb;
373 /* ctx is provided to sample_cb and lost_cb */
377 LIBBPF_API struct perf_buffer *
378 perf_buffer__new(int map_fd, size_t page_cnt,
379 const struct perf_buffer_opts *opts);
381 enum bpf_perf_event_ret {
382 LIBBPF_PERF_EVENT_DONE = 0,
383 LIBBPF_PERF_EVENT_ERROR = -1,
384 LIBBPF_PERF_EVENT_CONT = -2,
387 struct perf_event_header;
389 typedef enum bpf_perf_event_ret
390 (*perf_buffer_event_fn)(void *ctx, int cpu, struct perf_event_header *event);
392 /* raw perf buffer options, giving most power and control */
393 struct perf_buffer_raw_opts {
394 /* perf event attrs passed directly into perf_event_open() */
395 struct perf_event_attr *attr;
396 /* raw event callback */
397 perf_buffer_event_fn event_cb;
398 /* ctx is provided to event_cb */
400 /* if cpu_cnt == 0, open all on all possible CPUs (up to the number of
401 * max_entries of given PERF_EVENT_ARRAY map)
404 /* if cpu_cnt > 0, cpus is an array of CPUs to open ring buffers on */
406 /* if cpu_cnt > 0, map_keys specify map keys to set per-CPU FDs for */
410 LIBBPF_API struct perf_buffer *
411 perf_buffer__new_raw(int map_fd, size_t page_cnt,
412 const struct perf_buffer_raw_opts *opts);
414 LIBBPF_API void perf_buffer__free(struct perf_buffer *pb);
415 LIBBPF_API int perf_buffer__poll(struct perf_buffer *pb, int timeout_ms);
417 typedef enum bpf_perf_event_ret
418 (*bpf_perf_event_print_t)(struct perf_event_header *hdr,
420 LIBBPF_API enum bpf_perf_event_ret
421 bpf_perf_event_read_simple(void *mmap_mem, size_t mmap_size, size_t page_size,
422 void **copy_mem, size_t *copy_size,
423 bpf_perf_event_print_t fn, void *private_data);
426 typedef int (*libbpf_dump_nlmsg_t)(void *cookie, void *msg, struct nlattr **tb);
427 int libbpf_netlink_open(unsigned int *nl_pid);
428 int libbpf_nl_get_link(int sock, unsigned int nl_pid,
429 libbpf_dump_nlmsg_t dump_link_nlmsg, void *cookie);
430 int libbpf_nl_get_class(int sock, unsigned int nl_pid, int ifindex,
431 libbpf_dump_nlmsg_t dump_class_nlmsg, void *cookie);
432 int libbpf_nl_get_qdisc(int sock, unsigned int nl_pid, int ifindex,
433 libbpf_dump_nlmsg_t dump_qdisc_nlmsg, void *cookie);
434 int libbpf_nl_get_filter(int sock, unsigned int nl_pid, int ifindex, int handle,
435 libbpf_dump_nlmsg_t dump_filter_nlmsg, void *cookie);
437 struct bpf_prog_linfo;
438 struct bpf_prog_info;
440 LIBBPF_API void bpf_prog_linfo__free(struct bpf_prog_linfo *prog_linfo);
441 LIBBPF_API struct bpf_prog_linfo *
442 bpf_prog_linfo__new(const struct bpf_prog_info *info);
443 LIBBPF_API const struct bpf_line_info *
444 bpf_prog_linfo__lfind_addr_func(const struct bpf_prog_linfo *prog_linfo,
445 __u64 addr, __u32 func_idx, __u32 nr_skip);
446 LIBBPF_API const struct bpf_line_info *
447 bpf_prog_linfo__lfind(const struct bpf_prog_linfo *prog_linfo,
448 __u32 insn_off, __u32 nr_skip);
451 * Probe for supported system features
453 * Note that running many of these probes in a short amount of time can cause
454 * the kernel to reach the maximal size of lockable memory allowed for the
455 * user, causing subsequent probes to fail. In this case, the caller may want
456 * to adjust that limit with setrlimit().
458 LIBBPF_API bool bpf_probe_prog_type(enum bpf_prog_type prog_type,
460 LIBBPF_API bool bpf_probe_map_type(enum bpf_map_type map_type, __u32 ifindex);
461 LIBBPF_API bool bpf_probe_helper(enum bpf_func_id id,
462 enum bpf_prog_type prog_type, __u32 ifindex);
465 * Get bpf_prog_info in continuous memory
467 * struct bpf_prog_info has multiple arrays. The user has option to choose
468 * arrays to fetch from kernel. The following APIs provide an uniform way to
469 * fetch these data. All arrays in bpf_prog_info are stored in a single
470 * continuous memory region. This makes it easy to store the info in a
473 * Before writing bpf_prog_info_linear to files, it is necessary to
474 * translate pointers in bpf_prog_info to offsets. Helper functions
475 * bpf_program__bpil_addr_to_offs() and bpf_program__bpil_offs_to_addr()
476 * are introduced to switch between pointers and offsets.
479 * # To fetch map_ids and prog_tags:
480 * __u64 arrays = (1UL << BPF_PROG_INFO_MAP_IDS) |
481 * (1UL << BPF_PROG_INFO_PROG_TAGS);
482 * struct bpf_prog_info_linear *info_linear =
483 * bpf_program__get_prog_info_linear(fd, arrays);
485 * # To save data in file
486 * bpf_program__bpil_addr_to_offs(info_linear);
487 * write(f, info_linear, sizeof(*info_linear) + info_linear->data_len);
489 * # To read data from file
490 * read(f, info_linear, <proper_size>);
491 * bpf_program__bpil_offs_to_addr(info_linear);
493 enum bpf_prog_info_array {
494 BPF_PROG_INFO_FIRST_ARRAY = 0,
495 BPF_PROG_INFO_JITED_INSNS = 0,
496 BPF_PROG_INFO_XLATED_INSNS,
497 BPF_PROG_INFO_MAP_IDS,
498 BPF_PROG_INFO_JITED_KSYMS,
499 BPF_PROG_INFO_JITED_FUNC_LENS,
500 BPF_PROG_INFO_FUNC_INFO,
501 BPF_PROG_INFO_LINE_INFO,
502 BPF_PROG_INFO_JITED_LINE_INFO,
503 BPF_PROG_INFO_PROG_TAGS,
504 BPF_PROG_INFO_LAST_ARRAY,
507 struct bpf_prog_info_linear {
508 /* size of struct bpf_prog_info, when the tool is compiled */
510 /* total bytes allocated for data, round up to 8 bytes */
512 /* which arrays are included in data */
514 struct bpf_prog_info info;
518 LIBBPF_API struct bpf_prog_info_linear *
519 bpf_program__get_prog_info_linear(int fd, __u64 arrays);
522 bpf_program__bpil_addr_to_offs(struct bpf_prog_info_linear *info_linear);
525 bpf_program__bpil_offs_to_addr(struct bpf_prog_info_linear *info_linear);
528 * A helper function to get the number of possible CPUs before looking up
529 * per-CPU maps. Negative errno is returned on failure.
533 * int ncpus = libbpf_num_possible_cpus();
537 * long values[ncpus];
538 * bpf_map_lookup_elem(per_cpu_map_fd, key, values);
541 LIBBPF_API int libbpf_num_possible_cpus(void);
547 #endif /* __LIBBPF_LIBBPF_H */