syscall.c 149 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036
  1. // SPDX-License-Identifier: GPL-2.0-only
  2. /* Copyright (c) 2011-2014 PLUMgrid, http://plumgrid.com
  3. */
  4. #include <linux/bpf.h>
  5. #include <linux/bpf-cgroup.h>
  6. #include <linux/bpf_trace.h>
  7. #include <linux/bpf_lirc.h>
  8. #include <linux/bpf_verifier.h>
  9. #include <linux/bsearch.h>
  10. #include <linux/btf.h>
  11. #include <linux/syscalls.h>
  12. #include <linux/slab.h>
  13. #include <linux/sched/signal.h>
  14. #include <linux/vmalloc.h>
  15. #include <linux/mmzone.h>
  16. #include <linux/anon_inodes.h>
  17. #include <linux/fdtable.h>
  18. #include <linux/file.h>
  19. #include <linux/fs.h>
  20. #include <linux/license.h>
  21. #include <linux/filter.h>
  22. #include <linux/kernel.h>
  23. #include <linux/idr.h>
  24. #include <linux/cred.h>
  25. #include <linux/timekeeping.h>
  26. #include <linux/ctype.h>
  27. #include <linux/nospec.h>
  28. #include <linux/audit.h>
  29. #include <uapi/linux/btf.h>
  30. #include <linux/pgtable.h>
  31. #include <linux/bpf_lsm.h>
  32. #include <linux/poll.h>
  33. #include <linux/sort.h>
  34. #include <linux/bpf-netns.h>
  35. #include <linux/rcupdate_trace.h>
  36. #include <linux/memcontrol.h>
  37. #include <linux/trace_events.h>
  38. #include <linux/cookie.h>
  39. #include <net/netfilter/nf_bpf_link.h>
  40. #include <net/netkit.h>
  41. #include <net/tcx.h>
  42. #define IS_FD_ARRAY(map) ((map)->map_type == BPF_MAP_TYPE_PERF_EVENT_ARRAY || \
  43. (map)->map_type == BPF_MAP_TYPE_CGROUP_ARRAY || \
  44. (map)->map_type == BPF_MAP_TYPE_ARRAY_OF_MAPS)
  45. #define IS_FD_PROG_ARRAY(map) ((map)->map_type == BPF_MAP_TYPE_PROG_ARRAY)
  46. #define IS_FD_HASH(map) ((map)->map_type == BPF_MAP_TYPE_HASH_OF_MAPS)
  47. #define IS_FD_MAP(map) (IS_FD_ARRAY(map) || IS_FD_PROG_ARRAY(map) || \
  48. IS_FD_HASH(map))
  49. #define BPF_OBJ_FLAG_MASK (BPF_F_RDONLY | BPF_F_WRONLY)
  50. DEFINE_PER_CPU(int, bpf_prog_active);
  51. DEFINE_COOKIE(bpf_map_cookie);
  52. static DEFINE_IDR(prog_idr);
  53. static DEFINE_SPINLOCK(prog_idr_lock);
  54. static DEFINE_IDR(map_idr);
  55. static DEFINE_SPINLOCK(map_idr_lock);
  56. static DEFINE_IDR(link_idr);
  57. static DEFINE_SPINLOCK(link_idr_lock);
  58. int sysctl_unprivileged_bpf_disabled __read_mostly =
  59. IS_BUILTIN(CONFIG_BPF_UNPRIV_DEFAULT_OFF) ? 2 : 0;
  60. static const struct bpf_map_ops * const bpf_map_types[] = {
  61. #define BPF_PROG_TYPE(_id, _name, prog_ctx_type, kern_ctx_type)
  62. #define BPF_MAP_TYPE(_id, _ops) \
  63. [_id] = &_ops,
  64. #define BPF_LINK_TYPE(_id, _name)
  65. #include <linux/bpf_types.h>
  66. #undef BPF_PROG_TYPE
  67. #undef BPF_MAP_TYPE
  68. #undef BPF_LINK_TYPE
  69. };
  70. /*
  71. * If we're handed a bigger struct than we know of, ensure all the unknown bits
  72. * are 0 - i.e. new user-space does not rely on any kernel feature extensions
  73. * we don't know about yet.
  74. *
  75. * There is a ToCToU between this function call and the following
  76. * copy_from_user() call. However, this is not a concern since this function is
  77. * meant to be a future-proofing of bits.
  78. */
  79. int bpf_check_uarg_tail_zero(bpfptr_t uaddr,
  80. size_t expected_size,
  81. size_t actual_size)
  82. {
  83. int res;
  84. if (unlikely(actual_size > PAGE_SIZE)) /* silly large */
  85. return -E2BIG;
  86. if (actual_size <= expected_size)
  87. return 0;
  88. if (uaddr.is_kernel)
  89. res = memchr_inv(uaddr.kernel + expected_size, 0,
  90. actual_size - expected_size) == NULL;
  91. else
  92. res = check_zeroed_user(uaddr.user + expected_size,
  93. actual_size - expected_size);
  94. if (res < 0)
  95. return res;
  96. return res ? 0 : -E2BIG;
  97. }
  98. const struct bpf_map_ops bpf_map_offload_ops = {
  99. .map_meta_equal = bpf_map_meta_equal,
  100. .map_alloc = bpf_map_offload_map_alloc,
  101. .map_free = bpf_map_offload_map_free,
  102. .map_check_btf = map_check_no_btf,
  103. .map_mem_usage = bpf_map_offload_map_mem_usage,
  104. };
  105. static void bpf_map_write_active_inc(struct bpf_map *map)
  106. {
  107. atomic64_inc(&map->writecnt);
  108. }
  109. static void bpf_map_write_active_dec(struct bpf_map *map)
  110. {
  111. atomic64_dec(&map->writecnt);
  112. }
  113. bool bpf_map_write_active(const struct bpf_map *map)
  114. {
  115. return atomic64_read(&map->writecnt) != 0;
  116. }
  117. static u32 bpf_map_value_size(const struct bpf_map *map)
  118. {
  119. if (map->map_type == BPF_MAP_TYPE_PERCPU_HASH ||
  120. map->map_type == BPF_MAP_TYPE_LRU_PERCPU_HASH ||
  121. map->map_type == BPF_MAP_TYPE_PERCPU_ARRAY ||
  122. map->map_type == BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE)
  123. return round_up(map->value_size, 8) * num_possible_cpus();
  124. else if (IS_FD_MAP(map))
  125. return sizeof(u32);
  126. else
  127. return map->value_size;
  128. }
  129. static void maybe_wait_bpf_programs(struct bpf_map *map)
  130. {
  131. /* Wait for any running non-sleepable BPF programs to complete so that
  132. * userspace, when we return to it, knows that all non-sleepable
  133. * programs that could be running use the new map value. For sleepable
  134. * BPF programs, synchronize_rcu_tasks_trace() should be used to wait
  135. * for the completions of these programs, but considering the waiting
  136. * time can be very long and userspace may think it will hang forever,
  137. * so don't handle sleepable BPF programs now.
  138. */
  139. if (map->map_type == BPF_MAP_TYPE_HASH_OF_MAPS ||
  140. map->map_type == BPF_MAP_TYPE_ARRAY_OF_MAPS)
  141. synchronize_rcu();
  142. }
  143. static int bpf_map_update_value(struct bpf_map *map, struct file *map_file,
  144. void *key, void *value, __u64 flags)
  145. {
  146. int err;
  147. /* Need to create a kthread, thus must support schedule */
  148. if (bpf_map_is_offloaded(map)) {
  149. return bpf_map_offload_update_elem(map, key, value, flags);
  150. } else if (map->map_type == BPF_MAP_TYPE_CPUMAP ||
  151. map->map_type == BPF_MAP_TYPE_ARENA ||
  152. map->map_type == BPF_MAP_TYPE_STRUCT_OPS) {
  153. return map->ops->map_update_elem(map, key, value, flags);
  154. } else if (map->map_type == BPF_MAP_TYPE_SOCKHASH ||
  155. map->map_type == BPF_MAP_TYPE_SOCKMAP) {
  156. return sock_map_update_elem_sys(map, key, value, flags);
  157. } else if (IS_FD_PROG_ARRAY(map)) {
  158. return bpf_fd_array_map_update_elem(map, map_file, key, value,
  159. flags);
  160. }
  161. bpf_disable_instrumentation();
  162. if (map->map_type == BPF_MAP_TYPE_PERCPU_HASH ||
  163. map->map_type == BPF_MAP_TYPE_LRU_PERCPU_HASH) {
  164. err = bpf_percpu_hash_update(map, key, value, flags);
  165. } else if (map->map_type == BPF_MAP_TYPE_PERCPU_ARRAY) {
  166. err = bpf_percpu_array_update(map, key, value, flags);
  167. } else if (map->map_type == BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE) {
  168. err = bpf_percpu_cgroup_storage_update(map, key, value,
  169. flags);
  170. } else if (IS_FD_ARRAY(map)) {
  171. err = bpf_fd_array_map_update_elem(map, map_file, key, value,
  172. flags);
  173. } else if (map->map_type == BPF_MAP_TYPE_HASH_OF_MAPS) {
  174. err = bpf_fd_htab_map_update_elem(map, map_file, key, value,
  175. flags);
  176. } else if (map->map_type == BPF_MAP_TYPE_REUSEPORT_SOCKARRAY) {
  177. /* rcu_read_lock() is not needed */
  178. err = bpf_fd_reuseport_array_update_elem(map, key, value,
  179. flags);
  180. } else if (map->map_type == BPF_MAP_TYPE_QUEUE ||
  181. map->map_type == BPF_MAP_TYPE_STACK ||
  182. map->map_type == BPF_MAP_TYPE_BLOOM_FILTER) {
  183. err = map->ops->map_push_elem(map, value, flags);
  184. } else {
  185. rcu_read_lock();
  186. err = map->ops->map_update_elem(map, key, value, flags);
  187. rcu_read_unlock();
  188. }
  189. bpf_enable_instrumentation();
  190. return err;
  191. }
  192. static int bpf_map_copy_value(struct bpf_map *map, void *key, void *value,
  193. __u64 flags)
  194. {
  195. void *ptr;
  196. int err;
  197. if (bpf_map_is_offloaded(map))
  198. return bpf_map_offload_lookup_elem(map, key, value);
  199. bpf_disable_instrumentation();
  200. if (map->map_type == BPF_MAP_TYPE_PERCPU_HASH ||
  201. map->map_type == BPF_MAP_TYPE_LRU_PERCPU_HASH) {
  202. err = bpf_percpu_hash_copy(map, key, value);
  203. } else if (map->map_type == BPF_MAP_TYPE_PERCPU_ARRAY) {
  204. err = bpf_percpu_array_copy(map, key, value);
  205. } else if (map->map_type == BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE) {
  206. err = bpf_percpu_cgroup_storage_copy(map, key, value);
  207. } else if (map->map_type == BPF_MAP_TYPE_STACK_TRACE) {
  208. err = bpf_stackmap_copy(map, key, value);
  209. } else if (IS_FD_ARRAY(map) || IS_FD_PROG_ARRAY(map)) {
  210. err = bpf_fd_array_map_lookup_elem(map, key, value);
  211. } else if (IS_FD_HASH(map)) {
  212. err = bpf_fd_htab_map_lookup_elem(map, key, value);
  213. } else if (map->map_type == BPF_MAP_TYPE_REUSEPORT_SOCKARRAY) {
  214. err = bpf_fd_reuseport_array_lookup_elem(map, key, value);
  215. } else if (map->map_type == BPF_MAP_TYPE_QUEUE ||
  216. map->map_type == BPF_MAP_TYPE_STACK ||
  217. map->map_type == BPF_MAP_TYPE_BLOOM_FILTER) {
  218. err = map->ops->map_peek_elem(map, value);
  219. } else if (map->map_type == BPF_MAP_TYPE_STRUCT_OPS) {
  220. /* struct_ops map requires directly updating "value" */
  221. err = bpf_struct_ops_map_sys_lookup_elem(map, key, value);
  222. } else {
  223. rcu_read_lock();
  224. if (map->ops->map_lookup_elem_sys_only)
  225. ptr = map->ops->map_lookup_elem_sys_only(map, key);
  226. else
  227. ptr = map->ops->map_lookup_elem(map, key);
  228. if (IS_ERR(ptr)) {
  229. err = PTR_ERR(ptr);
  230. } else if (!ptr) {
  231. err = -ENOENT;
  232. } else {
  233. err = 0;
  234. if (flags & BPF_F_LOCK)
  235. /* lock 'ptr' and copy everything but lock */
  236. copy_map_value_locked(map, value, ptr, true);
  237. else
  238. copy_map_value(map, value, ptr);
  239. /* mask lock and timer, since value wasn't zero inited */
  240. check_and_init_map_value(map, value);
  241. }
  242. rcu_read_unlock();
  243. }
  244. bpf_enable_instrumentation();
  245. return err;
  246. }
  247. /* Please, do not use this function outside from the map creation path
  248. * (e.g. in map update path) without taking care of setting the active
  249. * memory cgroup (see at bpf_map_kmalloc_node() for example).
  250. */
  251. static void *__bpf_map_area_alloc(u64 size, int numa_node, bool mmapable)
  252. {
  253. /* We really just want to fail instead of triggering OOM killer
  254. * under memory pressure, therefore we set __GFP_NORETRY to kmalloc,
  255. * which is used for lower order allocation requests.
  256. *
  257. * It has been observed that higher order allocation requests done by
  258. * vmalloc with __GFP_NORETRY being set might fail due to not trying
  259. * to reclaim memory from the page cache, thus we set
  260. * __GFP_RETRY_MAYFAIL to avoid such situations.
  261. */
  262. gfp_t gfp = bpf_memcg_flags(__GFP_NOWARN | __GFP_ZERO);
  263. unsigned int flags = 0;
  264. unsigned long align = 1;
  265. void *area;
  266. if (size >= SIZE_MAX)
  267. return NULL;
  268. /* kmalloc()'ed memory can't be mmap()'ed */
  269. if (mmapable) {
  270. BUG_ON(!PAGE_ALIGNED(size));
  271. align = SHMLBA;
  272. flags = VM_USERMAP;
  273. } else if (size <= (PAGE_SIZE << PAGE_ALLOC_COSTLY_ORDER)) {
  274. area = kmalloc_node(size, gfp | GFP_USER | __GFP_NORETRY,
  275. numa_node);
  276. if (area != NULL)
  277. return area;
  278. }
  279. return __vmalloc_node_range(size, align, VMALLOC_START, VMALLOC_END,
  280. gfp | GFP_KERNEL | __GFP_RETRY_MAYFAIL, PAGE_KERNEL,
  281. flags, numa_node, __builtin_return_address(0));
  282. }
  283. void *bpf_map_area_alloc(u64 size, int numa_node)
  284. {
  285. return __bpf_map_area_alloc(size, numa_node, false);
  286. }
  287. void *bpf_map_area_mmapable_alloc(u64 size, int numa_node)
  288. {
  289. return __bpf_map_area_alloc(size, numa_node, true);
  290. }
  291. void bpf_map_area_free(void *area)
  292. {
  293. kvfree(area);
  294. }
  295. static u32 bpf_map_flags_retain_permanent(u32 flags)
  296. {
  297. /* Some map creation flags are not tied to the map object but
  298. * rather to the map fd instead, so they have no meaning upon
  299. * map object inspection since multiple file descriptors with
  300. * different (access) properties can exist here. Thus, given
  301. * this has zero meaning for the map itself, lets clear these
  302. * from here.
  303. */
  304. return flags & ~(BPF_F_RDONLY | BPF_F_WRONLY);
  305. }
  306. void bpf_map_init_from_attr(struct bpf_map *map, union bpf_attr *attr)
  307. {
  308. map->map_type = attr->map_type;
  309. map->key_size = attr->key_size;
  310. map->value_size = attr->value_size;
  311. map->max_entries = attr->max_entries;
  312. map->map_flags = bpf_map_flags_retain_permanent(attr->map_flags);
  313. map->numa_node = bpf_map_attr_numa_node(attr);
  314. map->map_extra = attr->map_extra;
  315. }
  316. static int bpf_map_alloc_id(struct bpf_map *map)
  317. {
  318. int id;
  319. idr_preload(GFP_KERNEL);
  320. spin_lock_bh(&map_idr_lock);
  321. id = idr_alloc_cyclic(&map_idr, map, 1, INT_MAX, GFP_ATOMIC);
  322. if (id > 0)
  323. map->id = id;
  324. spin_unlock_bh(&map_idr_lock);
  325. idr_preload_end();
  326. if (WARN_ON_ONCE(!id))
  327. return -ENOSPC;
  328. return id > 0 ? 0 : id;
  329. }
  330. void bpf_map_free_id(struct bpf_map *map)
  331. {
  332. unsigned long flags;
  333. /* Offloaded maps are removed from the IDR store when their device
  334. * disappears - even if someone holds an fd to them they are unusable,
  335. * the memory is gone, all ops will fail; they are simply waiting for
  336. * refcnt to drop to be freed.
  337. */
  338. if (!map->id)
  339. return;
  340. spin_lock_irqsave(&map_idr_lock, flags);
  341. idr_remove(&map_idr, map->id);
  342. map->id = 0;
  343. spin_unlock_irqrestore(&map_idr_lock, flags);
  344. }
  345. #ifdef CONFIG_MEMCG
  346. static void bpf_map_save_memcg(struct bpf_map *map)
  347. {
  348. /* Currently if a map is created by a process belonging to the root
  349. * memory cgroup, get_obj_cgroup_from_current() will return NULL.
  350. * So we have to check map->objcg for being NULL each time it's
  351. * being used.
  352. */
  353. if (memcg_bpf_enabled())
  354. map->objcg = get_obj_cgroup_from_current();
  355. }
  356. static void bpf_map_release_memcg(struct bpf_map *map)
  357. {
  358. if (map->objcg)
  359. obj_cgroup_put(map->objcg);
  360. }
  361. static struct mem_cgroup *bpf_map_get_memcg(const struct bpf_map *map)
  362. {
  363. if (map->objcg)
  364. return get_mem_cgroup_from_objcg(map->objcg);
  365. return root_mem_cgroup;
  366. }
  367. void *bpf_map_kmalloc_node(const struct bpf_map *map, size_t size, gfp_t flags,
  368. int node)
  369. {
  370. struct mem_cgroup *memcg, *old_memcg;
  371. void *ptr;
  372. memcg = bpf_map_get_memcg(map);
  373. old_memcg = set_active_memcg(memcg);
  374. ptr = kmalloc_node(size, flags | __GFP_ACCOUNT, node);
  375. set_active_memcg(old_memcg);
  376. mem_cgroup_put(memcg);
  377. return ptr;
  378. }
  379. void *bpf_map_kzalloc(const struct bpf_map *map, size_t size, gfp_t flags)
  380. {
  381. struct mem_cgroup *memcg, *old_memcg;
  382. void *ptr;
  383. memcg = bpf_map_get_memcg(map);
  384. old_memcg = set_active_memcg(memcg);
  385. ptr = kzalloc(size, flags | __GFP_ACCOUNT);
  386. set_active_memcg(old_memcg);
  387. mem_cgroup_put(memcg);
  388. return ptr;
  389. }
  390. void *bpf_map_kvcalloc(struct bpf_map *map, size_t n, size_t size,
  391. gfp_t flags)
  392. {
  393. struct mem_cgroup *memcg, *old_memcg;
  394. void *ptr;
  395. memcg = bpf_map_get_memcg(map);
  396. old_memcg = set_active_memcg(memcg);
  397. ptr = kvcalloc(n, size, flags | __GFP_ACCOUNT);
  398. set_active_memcg(old_memcg);
  399. mem_cgroup_put(memcg);
  400. return ptr;
  401. }
  402. void __percpu *bpf_map_alloc_percpu(const struct bpf_map *map, size_t size,
  403. size_t align, gfp_t flags)
  404. {
  405. struct mem_cgroup *memcg, *old_memcg;
  406. void __percpu *ptr;
  407. memcg = bpf_map_get_memcg(map);
  408. old_memcg = set_active_memcg(memcg);
  409. ptr = __alloc_percpu_gfp(size, align, flags | __GFP_ACCOUNT);
  410. set_active_memcg(old_memcg);
  411. mem_cgroup_put(memcg);
  412. return ptr;
  413. }
  414. #else
  415. static void bpf_map_save_memcg(struct bpf_map *map)
  416. {
  417. }
  418. static void bpf_map_release_memcg(struct bpf_map *map)
  419. {
  420. }
  421. #endif
  422. int bpf_map_alloc_pages(const struct bpf_map *map, gfp_t gfp, int nid,
  423. unsigned long nr_pages, struct page **pages)
  424. {
  425. unsigned long i, j;
  426. struct page *pg;
  427. int ret = 0;
  428. #ifdef CONFIG_MEMCG
  429. struct mem_cgroup *memcg, *old_memcg;
  430. memcg = bpf_map_get_memcg(map);
  431. old_memcg = set_active_memcg(memcg);
  432. #endif
  433. for (i = 0; i < nr_pages; i++) {
  434. pg = alloc_pages_node(nid, gfp | __GFP_ACCOUNT, 0);
  435. if (pg) {
  436. pages[i] = pg;
  437. continue;
  438. }
  439. for (j = 0; j < i; j++)
  440. __free_page(pages[j]);
  441. ret = -ENOMEM;
  442. break;
  443. }
  444. #ifdef CONFIG_MEMCG
  445. set_active_memcg(old_memcg);
  446. mem_cgroup_put(memcg);
  447. #endif
  448. return ret;
  449. }
  450. static int btf_field_cmp(const void *a, const void *b)
  451. {
  452. const struct btf_field *f1 = a, *f2 = b;
  453. if (f1->offset < f2->offset)
  454. return -1;
  455. else if (f1->offset > f2->offset)
  456. return 1;
  457. return 0;
  458. }
  459. struct btf_field *btf_record_find(const struct btf_record *rec, u32 offset,
  460. u32 field_mask)
  461. {
  462. struct btf_field *field;
  463. if (IS_ERR_OR_NULL(rec) || !(rec->field_mask & field_mask))
  464. return NULL;
  465. field = bsearch(&offset, rec->fields, rec->cnt, sizeof(rec->fields[0]), btf_field_cmp);
  466. if (!field || !(field->type & field_mask))
  467. return NULL;
  468. return field;
  469. }
  470. void btf_record_free(struct btf_record *rec)
  471. {
  472. int i;
  473. if (IS_ERR_OR_NULL(rec))
  474. return;
  475. for (i = 0; i < rec->cnt; i++) {
  476. switch (rec->fields[i].type) {
  477. case BPF_KPTR_UNREF:
  478. case BPF_KPTR_REF:
  479. case BPF_KPTR_PERCPU:
  480. if (rec->fields[i].kptr.module)
  481. module_put(rec->fields[i].kptr.module);
  482. if (btf_is_kernel(rec->fields[i].kptr.btf))
  483. btf_put(rec->fields[i].kptr.btf);
  484. break;
  485. case BPF_LIST_HEAD:
  486. case BPF_LIST_NODE:
  487. case BPF_RB_ROOT:
  488. case BPF_RB_NODE:
  489. case BPF_SPIN_LOCK:
  490. case BPF_TIMER:
  491. case BPF_REFCOUNT:
  492. case BPF_WORKQUEUE:
  493. /* Nothing to release */
  494. break;
  495. default:
  496. WARN_ON_ONCE(1);
  497. continue;
  498. }
  499. }
  500. kfree(rec);
  501. }
  502. void bpf_map_free_record(struct bpf_map *map)
  503. {
  504. btf_record_free(map->record);
  505. map->record = NULL;
  506. }
  507. struct btf_record *btf_record_dup(const struct btf_record *rec)
  508. {
  509. const struct btf_field *fields;
  510. struct btf_record *new_rec;
  511. int ret, size, i;
  512. if (IS_ERR_OR_NULL(rec))
  513. return NULL;
  514. size = offsetof(struct btf_record, fields[rec->cnt]);
  515. new_rec = kmemdup(rec, size, GFP_KERNEL | __GFP_NOWARN);
  516. if (!new_rec)
  517. return ERR_PTR(-ENOMEM);
  518. /* Do a deep copy of the btf_record */
  519. fields = rec->fields;
  520. new_rec->cnt = 0;
  521. for (i = 0; i < rec->cnt; i++) {
  522. switch (fields[i].type) {
  523. case BPF_KPTR_UNREF:
  524. case BPF_KPTR_REF:
  525. case BPF_KPTR_PERCPU:
  526. if (btf_is_kernel(fields[i].kptr.btf))
  527. btf_get(fields[i].kptr.btf);
  528. if (fields[i].kptr.module && !try_module_get(fields[i].kptr.module)) {
  529. ret = -ENXIO;
  530. goto free;
  531. }
  532. break;
  533. case BPF_LIST_HEAD:
  534. case BPF_LIST_NODE:
  535. case BPF_RB_ROOT:
  536. case BPF_RB_NODE:
  537. case BPF_SPIN_LOCK:
  538. case BPF_TIMER:
  539. case BPF_REFCOUNT:
  540. case BPF_WORKQUEUE:
  541. /* Nothing to acquire */
  542. break;
  543. default:
  544. ret = -EFAULT;
  545. WARN_ON_ONCE(1);
  546. goto free;
  547. }
  548. new_rec->cnt++;
  549. }
  550. return new_rec;
  551. free:
  552. btf_record_free(new_rec);
  553. return ERR_PTR(ret);
  554. }
  555. bool btf_record_equal(const struct btf_record *rec_a, const struct btf_record *rec_b)
  556. {
  557. bool a_has_fields = !IS_ERR_OR_NULL(rec_a), b_has_fields = !IS_ERR_OR_NULL(rec_b);
  558. int size;
  559. if (!a_has_fields && !b_has_fields)
  560. return true;
  561. if (a_has_fields != b_has_fields)
  562. return false;
  563. if (rec_a->cnt != rec_b->cnt)
  564. return false;
  565. size = offsetof(struct btf_record, fields[rec_a->cnt]);
  566. /* btf_parse_fields uses kzalloc to allocate a btf_record, so unused
  567. * members are zeroed out. So memcmp is safe to do without worrying
  568. * about padding/unused fields.
  569. *
  570. * While spin_lock, timer, and kptr have no relation to map BTF,
  571. * list_head metadata is specific to map BTF, the btf and value_rec
  572. * members in particular. btf is the map BTF, while value_rec points to
  573. * btf_record in that map BTF.
  574. *
  575. * So while by default, we don't rely on the map BTF (which the records
  576. * were parsed from) matching for both records, which is not backwards
  577. * compatible, in case list_head is part of it, we implicitly rely on
  578. * that by way of depending on memcmp succeeding for it.
  579. */
  580. return !memcmp(rec_a, rec_b, size);
  581. }
  582. void bpf_obj_free_timer(const struct btf_record *rec, void *obj)
  583. {
  584. if (WARN_ON_ONCE(!btf_record_has_field(rec, BPF_TIMER)))
  585. return;
  586. bpf_timer_cancel_and_free(obj + rec->timer_off);
  587. }
  588. void bpf_obj_free_workqueue(const struct btf_record *rec, void *obj)
  589. {
  590. if (WARN_ON_ONCE(!btf_record_has_field(rec, BPF_WORKQUEUE)))
  591. return;
  592. bpf_wq_cancel_and_free(obj + rec->wq_off);
  593. }
  594. void bpf_obj_free_fields(const struct btf_record *rec, void *obj)
  595. {
  596. const struct btf_field *fields;
  597. int i;
  598. if (IS_ERR_OR_NULL(rec))
  599. return;
  600. fields = rec->fields;
  601. for (i = 0; i < rec->cnt; i++) {
  602. struct btf_struct_meta *pointee_struct_meta;
  603. const struct btf_field *field = &fields[i];
  604. void *field_ptr = obj + field->offset;
  605. void *xchgd_field;
  606. switch (fields[i].type) {
  607. case BPF_SPIN_LOCK:
  608. break;
  609. case BPF_TIMER:
  610. bpf_timer_cancel_and_free(field_ptr);
  611. break;
  612. case BPF_WORKQUEUE:
  613. bpf_wq_cancel_and_free(field_ptr);
  614. break;
  615. case BPF_KPTR_UNREF:
  616. WRITE_ONCE(*(u64 *)field_ptr, 0);
  617. break;
  618. case BPF_KPTR_REF:
  619. case BPF_KPTR_PERCPU:
  620. xchgd_field = (void *)xchg((unsigned long *)field_ptr, 0);
  621. if (!xchgd_field)
  622. break;
  623. if (!btf_is_kernel(field->kptr.btf)) {
  624. pointee_struct_meta = btf_find_struct_meta(field->kptr.btf,
  625. field->kptr.btf_id);
  626. migrate_disable();
  627. __bpf_obj_drop_impl(xchgd_field, pointee_struct_meta ?
  628. pointee_struct_meta->record : NULL,
  629. fields[i].type == BPF_KPTR_PERCPU);
  630. migrate_enable();
  631. } else {
  632. field->kptr.dtor(xchgd_field);
  633. }
  634. break;
  635. case BPF_LIST_HEAD:
  636. if (WARN_ON_ONCE(rec->spin_lock_off < 0))
  637. continue;
  638. bpf_list_head_free(field, field_ptr, obj + rec->spin_lock_off);
  639. break;
  640. case BPF_RB_ROOT:
  641. if (WARN_ON_ONCE(rec->spin_lock_off < 0))
  642. continue;
  643. bpf_rb_root_free(field, field_ptr, obj + rec->spin_lock_off);
  644. break;
  645. case BPF_LIST_NODE:
  646. case BPF_RB_NODE:
  647. case BPF_REFCOUNT:
  648. break;
  649. default:
  650. WARN_ON_ONCE(1);
  651. continue;
  652. }
  653. }
  654. }
  655. static void bpf_map_free(struct bpf_map *map)
  656. {
  657. struct btf_record *rec = map->record;
  658. struct btf *btf = map->btf;
  659. /* implementation dependent freeing */
  660. map->ops->map_free(map);
  661. /* Delay freeing of btf_record for maps, as map_free
  662. * callback usually needs access to them. It is better to do it here
  663. * than require each callback to do the free itself manually.
  664. *
  665. * Note that the btf_record stashed in map->inner_map_meta->record was
  666. * already freed using the map_free callback for map in map case which
  667. * eventually calls bpf_map_free_meta, since inner_map_meta is only a
  668. * template bpf_map struct used during verification.
  669. */
  670. btf_record_free(rec);
  671. /* Delay freeing of btf for maps, as map_free callback may need
  672. * struct_meta info which will be freed with btf_put().
  673. */
  674. btf_put(btf);
  675. }
  676. /* called from workqueue */
  677. static void bpf_map_free_deferred(struct work_struct *work)
  678. {
  679. struct bpf_map *map = container_of(work, struct bpf_map, work);
  680. security_bpf_map_free(map);
  681. bpf_map_release_memcg(map);
  682. bpf_map_owner_free(map);
  683. bpf_map_free(map);
  684. }
  685. static void bpf_map_put_uref(struct bpf_map *map)
  686. {
  687. if (atomic64_dec_and_test(&map->usercnt)) {
  688. if (map->ops->map_release_uref)
  689. map->ops->map_release_uref(map);
  690. }
  691. }
  692. static void bpf_map_free_in_work(struct bpf_map *map)
  693. {
  694. INIT_WORK(&map->work, bpf_map_free_deferred);
  695. /* Avoid spawning kworkers, since they all might contend
  696. * for the same mutex like slab_mutex.
  697. */
  698. queue_work(system_unbound_wq, &map->work);
  699. }
  700. static void bpf_map_free_rcu_gp(struct rcu_head *rcu)
  701. {
  702. bpf_map_free_in_work(container_of(rcu, struct bpf_map, rcu));
  703. }
  704. static void bpf_map_free_mult_rcu_gp(struct rcu_head *rcu)
  705. {
  706. if (rcu_trace_implies_rcu_gp())
  707. bpf_map_free_rcu_gp(rcu);
  708. else
  709. call_rcu(rcu, bpf_map_free_rcu_gp);
  710. }
  711. /* decrement map refcnt and schedule it for freeing via workqueue
  712. * (underlying map implementation ops->map_free() might sleep)
  713. */
  714. void bpf_map_put(struct bpf_map *map)
  715. {
  716. if (atomic64_dec_and_test(&map->refcnt)) {
  717. /* bpf_map_free_id() must be called first */
  718. bpf_map_free_id(map);
  719. WARN_ON_ONCE(atomic64_read(&map->sleepable_refcnt));
  720. if (READ_ONCE(map->free_after_mult_rcu_gp))
  721. call_rcu_tasks_trace(&map->rcu, bpf_map_free_mult_rcu_gp);
  722. else if (READ_ONCE(map->free_after_rcu_gp))
  723. call_rcu(&map->rcu, bpf_map_free_rcu_gp);
  724. else
  725. bpf_map_free_in_work(map);
  726. }
  727. }
  728. EXPORT_SYMBOL_GPL(bpf_map_put);
  729. void bpf_map_put_with_uref(struct bpf_map *map)
  730. {
  731. bpf_map_put_uref(map);
  732. bpf_map_put(map);
  733. }
  734. static int bpf_map_release(struct inode *inode, struct file *filp)
  735. {
  736. struct bpf_map *map = filp->private_data;
  737. if (map->ops->map_release)
  738. map->ops->map_release(map, filp);
  739. bpf_map_put_with_uref(map);
  740. return 0;
  741. }
  742. static fmode_t map_get_sys_perms(struct bpf_map *map, struct fd f)
  743. {
  744. fmode_t mode = fd_file(f)->f_mode;
  745. /* Our file permissions may have been overridden by global
  746. * map permissions facing syscall side.
  747. */
  748. if (READ_ONCE(map->frozen))
  749. mode &= ~FMODE_CAN_WRITE;
  750. return mode;
  751. }
  752. #ifdef CONFIG_PROC_FS
  753. /* Show the memory usage of a bpf map */
  754. static u64 bpf_map_memory_usage(const struct bpf_map *map)
  755. {
  756. return map->ops->map_mem_usage(map);
  757. }
  758. static void bpf_map_show_fdinfo(struct seq_file *m, struct file *filp)
  759. {
  760. struct bpf_map *map = filp->private_data;
  761. u32 type = 0, jited = 0;
  762. spin_lock(&map->owner_lock);
  763. if (map->owner) {
  764. type = map->owner->type;
  765. jited = map->owner->jited;
  766. }
  767. spin_unlock(&map->owner_lock);
  768. seq_printf(m,
  769. "map_type:\t%u\n"
  770. "key_size:\t%u\n"
  771. "value_size:\t%u\n"
  772. "max_entries:\t%u\n"
  773. "map_flags:\t%#x\n"
  774. "map_extra:\t%#llx\n"
  775. "memlock:\t%llu\n"
  776. "map_id:\t%u\n"
  777. "frozen:\t%u\n",
  778. map->map_type,
  779. map->key_size,
  780. map->value_size,
  781. map->max_entries,
  782. map->map_flags,
  783. (unsigned long long)map->map_extra,
  784. bpf_map_memory_usage(map),
  785. map->id,
  786. READ_ONCE(map->frozen));
  787. if (type) {
  788. seq_printf(m, "owner_prog_type:\t%u\n", type);
  789. seq_printf(m, "owner_jited:\t%u\n", jited);
  790. }
  791. }
  792. #endif
  793. static ssize_t bpf_dummy_read(struct file *filp, char __user *buf, size_t siz,
  794. loff_t *ppos)
  795. {
  796. /* We need this handler such that alloc_file() enables
  797. * f_mode with FMODE_CAN_READ.
  798. */
  799. return -EINVAL;
  800. }
  801. static ssize_t bpf_dummy_write(struct file *filp, const char __user *buf,
  802. size_t siz, loff_t *ppos)
  803. {
  804. /* We need this handler such that alloc_file() enables
  805. * f_mode with FMODE_CAN_WRITE.
  806. */
  807. return -EINVAL;
  808. }
  809. /* called for any extra memory-mapped regions (except initial) */
  810. static void bpf_map_mmap_open(struct vm_area_struct *vma)
  811. {
  812. struct bpf_map *map = vma->vm_file->private_data;
  813. if (vma->vm_flags & VM_MAYWRITE)
  814. bpf_map_write_active_inc(map);
  815. }
  816. /* called for all unmapped memory region (including initial) */
  817. static void bpf_map_mmap_close(struct vm_area_struct *vma)
  818. {
  819. struct bpf_map *map = vma->vm_file->private_data;
  820. if (vma->vm_flags & VM_MAYWRITE)
  821. bpf_map_write_active_dec(map);
  822. }
  823. static const struct vm_operations_struct bpf_map_default_vmops = {
  824. .open = bpf_map_mmap_open,
  825. .close = bpf_map_mmap_close,
  826. };
  827. static int bpf_map_mmap(struct file *filp, struct vm_area_struct *vma)
  828. {
  829. struct bpf_map *map = filp->private_data;
  830. int err = 0;
  831. if (!map->ops->map_mmap || !IS_ERR_OR_NULL(map->record))
  832. return -ENOTSUPP;
  833. if (!(vma->vm_flags & VM_SHARED))
  834. return -EINVAL;
  835. mutex_lock(&map->freeze_mutex);
  836. if (vma->vm_flags & VM_WRITE) {
  837. if (map->frozen) {
  838. err = -EPERM;
  839. goto out;
  840. }
  841. /* map is meant to be read-only, so do not allow mapping as
  842. * writable, because it's possible to leak a writable page
  843. * reference and allows user-space to still modify it after
  844. * freezing, while verifier will assume contents do not change
  845. */
  846. if (map->map_flags & BPF_F_RDONLY_PROG) {
  847. err = -EACCES;
  848. goto out;
  849. }
  850. bpf_map_write_active_inc(map);
  851. }
  852. out:
  853. mutex_unlock(&map->freeze_mutex);
  854. if (err)
  855. return err;
  856. /* set default open/close callbacks */
  857. vma->vm_ops = &bpf_map_default_vmops;
  858. vma->vm_private_data = map;
  859. vm_flags_clear(vma, VM_MAYEXEC);
  860. /* If mapping is read-only, then disallow potentially re-mapping with
  861. * PROT_WRITE by dropping VM_MAYWRITE flag. This VM_MAYWRITE clearing
  862. * means that as far as BPF map's memory-mapped VMAs are concerned,
  863. * VM_WRITE and VM_MAYWRITE and equivalent, if one of them is set,
  864. * both should be set, so we can forget about VM_MAYWRITE and always
  865. * check just VM_WRITE
  866. */
  867. if (!(vma->vm_flags & VM_WRITE))
  868. vm_flags_clear(vma, VM_MAYWRITE);
  869. err = map->ops->map_mmap(map, vma);
  870. if (err) {
  871. if (vma->vm_flags & VM_WRITE)
  872. bpf_map_write_active_dec(map);
  873. }
  874. return err;
  875. }
  876. static __poll_t bpf_map_poll(struct file *filp, struct poll_table_struct *pts)
  877. {
  878. struct bpf_map *map = filp->private_data;
  879. if (map->ops->map_poll)
  880. return map->ops->map_poll(map, filp, pts);
  881. return EPOLLERR;
  882. }
  883. static unsigned long bpf_get_unmapped_area(struct file *filp, unsigned long addr,
  884. unsigned long len, unsigned long pgoff,
  885. unsigned long flags)
  886. {
  887. struct bpf_map *map = filp->private_data;
  888. if (map->ops->map_get_unmapped_area)
  889. return map->ops->map_get_unmapped_area(filp, addr, len, pgoff, flags);
  890. #ifdef CONFIG_MMU
  891. return mm_get_unmapped_area(current->mm, filp, addr, len, pgoff, flags);
  892. #else
  893. return addr;
  894. #endif
  895. }
  896. const struct file_operations bpf_map_fops = {
  897. #ifdef CONFIG_PROC_FS
  898. .show_fdinfo = bpf_map_show_fdinfo,
  899. #endif
  900. .release = bpf_map_release,
  901. .read = bpf_dummy_read,
  902. .write = bpf_dummy_write,
  903. .mmap = bpf_map_mmap,
  904. .poll = bpf_map_poll,
  905. .get_unmapped_area = bpf_get_unmapped_area,
  906. };
  907. int bpf_map_new_fd(struct bpf_map *map, int flags)
  908. {
  909. int ret;
  910. ret = security_bpf_map(map, OPEN_FMODE(flags));
  911. if (ret < 0)
  912. return ret;
  913. return anon_inode_getfd("bpf-map", &bpf_map_fops, map,
  914. flags | O_CLOEXEC);
  915. }
  916. int bpf_get_file_flag(int flags)
  917. {
  918. if ((flags & BPF_F_RDONLY) && (flags & BPF_F_WRONLY))
  919. return -EINVAL;
  920. if (flags & BPF_F_RDONLY)
  921. return O_RDONLY;
  922. if (flags & BPF_F_WRONLY)
  923. return O_WRONLY;
  924. return O_RDWR;
  925. }
  926. /* helper macro to check that unused fields 'union bpf_attr' are zero */
  927. #define CHECK_ATTR(CMD) \
  928. memchr_inv((void *) &attr->CMD##_LAST_FIELD + \
  929. sizeof(attr->CMD##_LAST_FIELD), 0, \
  930. sizeof(*attr) - \
  931. offsetof(union bpf_attr, CMD##_LAST_FIELD) - \
  932. sizeof(attr->CMD##_LAST_FIELD)) != NULL
  933. /* dst and src must have at least "size" number of bytes.
  934. * Return strlen on success and < 0 on error.
  935. */
  936. int bpf_obj_name_cpy(char *dst, const char *src, unsigned int size)
  937. {
  938. const char *end = src + size;
  939. const char *orig_src = src;
  940. memset(dst, 0, size);
  941. /* Copy all isalnum(), '_' and '.' chars. */
  942. while (src < end && *src) {
  943. if (!isalnum(*src) &&
  944. *src != '_' && *src != '.')
  945. return -EINVAL;
  946. *dst++ = *src++;
  947. }
  948. /* No '\0' found in "size" number of bytes */
  949. if (src == end)
  950. return -EINVAL;
  951. return src - orig_src;
  952. }
  953. int map_check_no_btf(const struct bpf_map *map,
  954. const struct btf *btf,
  955. const struct btf_type *key_type,
  956. const struct btf_type *value_type)
  957. {
  958. return -ENOTSUPP;
  959. }
  960. static int map_check_btf(struct bpf_map *map, struct bpf_token *token,
  961. const struct btf *btf, u32 btf_key_id, u32 btf_value_id)
  962. {
  963. const struct btf_type *key_type, *value_type;
  964. u32 key_size, value_size;
  965. int ret = 0;
  966. /* Some maps allow key to be unspecified. */
  967. if (btf_key_id) {
  968. key_type = btf_type_id_size(btf, &btf_key_id, &key_size);
  969. if (!key_type || key_size != map->key_size)
  970. return -EINVAL;
  971. } else {
  972. key_type = btf_type_by_id(btf, 0);
  973. if (!map->ops->map_check_btf)
  974. return -EINVAL;
  975. }
  976. value_type = btf_type_id_size(btf, &btf_value_id, &value_size);
  977. if (!value_type || value_size != map->value_size)
  978. return -EINVAL;
  979. map->record = btf_parse_fields(btf, value_type,
  980. BPF_SPIN_LOCK | BPF_TIMER | BPF_KPTR | BPF_LIST_HEAD |
  981. BPF_RB_ROOT | BPF_REFCOUNT | BPF_WORKQUEUE,
  982. map->value_size);
  983. if (!IS_ERR_OR_NULL(map->record)) {
  984. int i;
  985. if (!bpf_token_capable(token, CAP_BPF)) {
  986. ret = -EPERM;
  987. goto free_map_tab;
  988. }
  989. if (map->map_flags & (BPF_F_RDONLY_PROG | BPF_F_WRONLY_PROG)) {
  990. ret = -EACCES;
  991. goto free_map_tab;
  992. }
  993. for (i = 0; i < sizeof(map->record->field_mask) * 8; i++) {
  994. switch (map->record->field_mask & (1 << i)) {
  995. case 0:
  996. continue;
  997. case BPF_SPIN_LOCK:
  998. if (map->map_type != BPF_MAP_TYPE_HASH &&
  999. map->map_type != BPF_MAP_TYPE_ARRAY &&
  1000. map->map_type != BPF_MAP_TYPE_CGROUP_STORAGE &&
  1001. map->map_type != BPF_MAP_TYPE_SK_STORAGE &&
  1002. map->map_type != BPF_MAP_TYPE_INODE_STORAGE &&
  1003. map->map_type != BPF_MAP_TYPE_TASK_STORAGE &&
  1004. map->map_type != BPF_MAP_TYPE_CGRP_STORAGE) {
  1005. ret = -EOPNOTSUPP;
  1006. goto free_map_tab;
  1007. }
  1008. break;
  1009. case BPF_TIMER:
  1010. case BPF_WORKQUEUE:
  1011. if (map->map_type != BPF_MAP_TYPE_HASH &&
  1012. map->map_type != BPF_MAP_TYPE_LRU_HASH &&
  1013. map->map_type != BPF_MAP_TYPE_ARRAY) {
  1014. ret = -EOPNOTSUPP;
  1015. goto free_map_tab;
  1016. }
  1017. break;
  1018. case BPF_KPTR_UNREF:
  1019. case BPF_KPTR_REF:
  1020. case BPF_KPTR_PERCPU:
  1021. case BPF_REFCOUNT:
  1022. if (map->map_type != BPF_MAP_TYPE_HASH &&
  1023. map->map_type != BPF_MAP_TYPE_PERCPU_HASH &&
  1024. map->map_type != BPF_MAP_TYPE_LRU_HASH &&
  1025. map->map_type != BPF_MAP_TYPE_LRU_PERCPU_HASH &&
  1026. map->map_type != BPF_MAP_TYPE_ARRAY &&
  1027. map->map_type != BPF_MAP_TYPE_PERCPU_ARRAY &&
  1028. map->map_type != BPF_MAP_TYPE_SK_STORAGE &&
  1029. map->map_type != BPF_MAP_TYPE_INODE_STORAGE &&
  1030. map->map_type != BPF_MAP_TYPE_TASK_STORAGE &&
  1031. map->map_type != BPF_MAP_TYPE_CGRP_STORAGE) {
  1032. ret = -EOPNOTSUPP;
  1033. goto free_map_tab;
  1034. }
  1035. break;
  1036. case BPF_LIST_HEAD:
  1037. case BPF_RB_ROOT:
  1038. if (map->map_type != BPF_MAP_TYPE_HASH &&
  1039. map->map_type != BPF_MAP_TYPE_LRU_HASH &&
  1040. map->map_type != BPF_MAP_TYPE_ARRAY) {
  1041. ret = -EOPNOTSUPP;
  1042. goto free_map_tab;
  1043. }
  1044. break;
  1045. default:
  1046. /* Fail if map_type checks are missing for a field type */
  1047. ret = -EOPNOTSUPP;
  1048. goto free_map_tab;
  1049. }
  1050. }
  1051. }
  1052. ret = btf_check_and_fixup_fields(btf, map->record);
  1053. if (ret < 0)
  1054. goto free_map_tab;
  1055. if (map->ops->map_check_btf) {
  1056. ret = map->ops->map_check_btf(map, btf, key_type, value_type);
  1057. if (ret < 0)
  1058. goto free_map_tab;
  1059. }
  1060. return ret;
  1061. free_map_tab:
  1062. bpf_map_free_record(map);
  1063. return ret;
  1064. }
  1065. static bool bpf_net_capable(void)
  1066. {
  1067. return capable(CAP_NET_ADMIN) || capable(CAP_SYS_ADMIN);
  1068. }
  1069. #define BPF_MAP_CREATE_LAST_FIELD map_token_fd
  1070. /* called via syscall */
  1071. static int map_create(union bpf_attr *attr)
  1072. {
  1073. const struct bpf_map_ops *ops;
  1074. struct bpf_token *token = NULL;
  1075. int numa_node = bpf_map_attr_numa_node(attr);
  1076. u32 map_type = attr->map_type;
  1077. struct bpf_map *map;
  1078. bool token_flag;
  1079. int f_flags;
  1080. int err;
  1081. err = CHECK_ATTR(BPF_MAP_CREATE);
  1082. if (err)
  1083. return -EINVAL;
  1084. /* check BPF_F_TOKEN_FD flag, remember if it's set, and then clear it
  1085. * to avoid per-map type checks tripping on unknown flag
  1086. */
  1087. token_flag = attr->map_flags & BPF_F_TOKEN_FD;
  1088. attr->map_flags &= ~BPF_F_TOKEN_FD;
  1089. if (attr->btf_vmlinux_value_type_id) {
  1090. if (attr->map_type != BPF_MAP_TYPE_STRUCT_OPS ||
  1091. attr->btf_key_type_id || attr->btf_value_type_id)
  1092. return -EINVAL;
  1093. } else if (attr->btf_key_type_id && !attr->btf_value_type_id) {
  1094. return -EINVAL;
  1095. }
  1096. if (attr->map_type != BPF_MAP_TYPE_BLOOM_FILTER &&
  1097. attr->map_type != BPF_MAP_TYPE_ARENA &&
  1098. attr->map_extra != 0)
  1099. return -EINVAL;
  1100. f_flags = bpf_get_file_flag(attr->map_flags);
  1101. if (f_flags < 0)
  1102. return f_flags;
  1103. if (numa_node != NUMA_NO_NODE &&
  1104. ((unsigned int)numa_node >= nr_node_ids ||
  1105. !node_online(numa_node)))
  1106. return -EINVAL;
  1107. /* find map type and init map: hashtable vs rbtree vs bloom vs ... */
  1108. map_type = attr->map_type;
  1109. if (map_type >= ARRAY_SIZE(bpf_map_types))
  1110. return -EINVAL;
  1111. map_type = array_index_nospec(map_type, ARRAY_SIZE(bpf_map_types));
  1112. ops = bpf_map_types[map_type];
  1113. if (!ops)
  1114. return -EINVAL;
  1115. if (ops->map_alloc_check) {
  1116. err = ops->map_alloc_check(attr);
  1117. if (err)
  1118. return err;
  1119. }
  1120. if (attr->map_ifindex)
  1121. ops = &bpf_map_offload_ops;
  1122. if (!ops->map_mem_usage)
  1123. return -EINVAL;
  1124. if (token_flag) {
  1125. token = bpf_token_get_from_fd(attr->map_token_fd);
  1126. if (IS_ERR(token))
  1127. return PTR_ERR(token);
  1128. /* if current token doesn't grant map creation permissions,
  1129. * then we can't use this token, so ignore it and rely on
  1130. * system-wide capabilities checks
  1131. */
  1132. if (!bpf_token_allow_cmd(token, BPF_MAP_CREATE) ||
  1133. !bpf_token_allow_map_type(token, attr->map_type)) {
  1134. bpf_token_put(token);
  1135. token = NULL;
  1136. }
  1137. }
  1138. err = -EPERM;
  1139. /* Intent here is for unprivileged_bpf_disabled to block BPF map
  1140. * creation for unprivileged users; other actions depend
  1141. * on fd availability and access to bpffs, so are dependent on
  1142. * object creation success. Even with unprivileged BPF disabled,
  1143. * capability checks are still carried out.
  1144. */
  1145. if (sysctl_unprivileged_bpf_disabled && !bpf_token_capable(token, CAP_BPF))
  1146. goto put_token;
  1147. /* check privileged map type permissions */
  1148. switch (map_type) {
  1149. case BPF_MAP_TYPE_ARRAY:
  1150. case BPF_MAP_TYPE_PERCPU_ARRAY:
  1151. case BPF_MAP_TYPE_PROG_ARRAY:
  1152. case BPF_MAP_TYPE_PERF_EVENT_ARRAY:
  1153. case BPF_MAP_TYPE_CGROUP_ARRAY:
  1154. case BPF_MAP_TYPE_ARRAY_OF_MAPS:
  1155. case BPF_MAP_TYPE_HASH:
  1156. case BPF_MAP_TYPE_PERCPU_HASH:
  1157. case BPF_MAP_TYPE_HASH_OF_MAPS:
  1158. case BPF_MAP_TYPE_RINGBUF:
  1159. case BPF_MAP_TYPE_USER_RINGBUF:
  1160. case BPF_MAP_TYPE_CGROUP_STORAGE:
  1161. case BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE:
  1162. /* unprivileged */
  1163. break;
  1164. case BPF_MAP_TYPE_SK_STORAGE:
  1165. case BPF_MAP_TYPE_INODE_STORAGE:
  1166. case BPF_MAP_TYPE_TASK_STORAGE:
  1167. case BPF_MAP_TYPE_CGRP_STORAGE:
  1168. case BPF_MAP_TYPE_BLOOM_FILTER:
  1169. case BPF_MAP_TYPE_LPM_TRIE:
  1170. case BPF_MAP_TYPE_REUSEPORT_SOCKARRAY:
  1171. case BPF_MAP_TYPE_STACK_TRACE:
  1172. case BPF_MAP_TYPE_QUEUE:
  1173. case BPF_MAP_TYPE_STACK:
  1174. case BPF_MAP_TYPE_LRU_HASH:
  1175. case BPF_MAP_TYPE_LRU_PERCPU_HASH:
  1176. case BPF_MAP_TYPE_STRUCT_OPS:
  1177. case BPF_MAP_TYPE_CPUMAP:
  1178. case BPF_MAP_TYPE_ARENA:
  1179. if (!bpf_token_capable(token, CAP_BPF))
  1180. goto put_token;
  1181. break;
  1182. case BPF_MAP_TYPE_SOCKMAP:
  1183. case BPF_MAP_TYPE_SOCKHASH:
  1184. case BPF_MAP_TYPE_DEVMAP:
  1185. case BPF_MAP_TYPE_DEVMAP_HASH:
  1186. case BPF_MAP_TYPE_XSKMAP:
  1187. if (!bpf_token_capable(token, CAP_NET_ADMIN))
  1188. goto put_token;
  1189. break;
  1190. default:
  1191. WARN(1, "unsupported map type %d", map_type);
  1192. goto put_token;
  1193. }
  1194. map = ops->map_alloc(attr);
  1195. if (IS_ERR(map)) {
  1196. err = PTR_ERR(map);
  1197. goto put_token;
  1198. }
  1199. map->ops = ops;
  1200. map->map_type = map_type;
  1201. err = bpf_obj_name_cpy(map->name, attr->map_name,
  1202. sizeof(attr->map_name));
  1203. if (err < 0)
  1204. goto free_map;
  1205. preempt_disable();
  1206. map->cookie = gen_cookie_next(&bpf_map_cookie);
  1207. preempt_enable();
  1208. atomic64_set(&map->refcnt, 1);
  1209. atomic64_set(&map->usercnt, 1);
  1210. mutex_init(&map->freeze_mutex);
  1211. spin_lock_init(&map->owner_lock);
  1212. if (attr->btf_key_type_id || attr->btf_value_type_id ||
  1213. /* Even the map's value is a kernel's struct,
  1214. * the bpf_prog.o must have BTF to begin with
  1215. * to figure out the corresponding kernel's
  1216. * counter part. Thus, attr->btf_fd has
  1217. * to be valid also.
  1218. */
  1219. attr->btf_vmlinux_value_type_id) {
  1220. struct btf *btf;
  1221. btf = btf_get_by_fd(attr->btf_fd);
  1222. if (IS_ERR(btf)) {
  1223. err = PTR_ERR(btf);
  1224. goto free_map;
  1225. }
  1226. if (btf_is_kernel(btf)) {
  1227. btf_put(btf);
  1228. err = -EACCES;
  1229. goto free_map;
  1230. }
  1231. map->btf = btf;
  1232. if (attr->btf_value_type_id) {
  1233. err = map_check_btf(map, token, btf, attr->btf_key_type_id,
  1234. attr->btf_value_type_id);
  1235. if (err)
  1236. goto free_map;
  1237. }
  1238. map->btf_key_type_id = attr->btf_key_type_id;
  1239. map->btf_value_type_id = attr->btf_value_type_id;
  1240. map->btf_vmlinux_value_type_id =
  1241. attr->btf_vmlinux_value_type_id;
  1242. }
  1243. err = security_bpf_map_create(map, attr, token);
  1244. if (err)
  1245. goto free_map_sec;
  1246. err = bpf_map_alloc_id(map);
  1247. if (err)
  1248. goto free_map_sec;
  1249. bpf_map_save_memcg(map);
  1250. bpf_token_put(token);
  1251. err = bpf_map_new_fd(map, f_flags);
  1252. if (err < 0) {
  1253. /* failed to allocate fd.
  1254. * bpf_map_put_with_uref() is needed because the above
  1255. * bpf_map_alloc_id() has published the map
  1256. * to the userspace and the userspace may
  1257. * have refcnt-ed it through BPF_MAP_GET_FD_BY_ID.
  1258. */
  1259. bpf_map_put_with_uref(map);
  1260. return err;
  1261. }
  1262. return err;
  1263. free_map_sec:
  1264. security_bpf_map_free(map);
  1265. free_map:
  1266. bpf_map_free(map);
  1267. put_token:
  1268. bpf_token_put(token);
  1269. return err;
  1270. }
  1271. void bpf_map_inc(struct bpf_map *map)
  1272. {
  1273. atomic64_inc(&map->refcnt);
  1274. }
  1275. EXPORT_SYMBOL_GPL(bpf_map_inc);
  1276. void bpf_map_inc_with_uref(struct bpf_map *map)
  1277. {
  1278. atomic64_inc(&map->refcnt);
  1279. atomic64_inc(&map->usercnt);
  1280. }
  1281. EXPORT_SYMBOL_GPL(bpf_map_inc_with_uref);
  1282. struct bpf_map *bpf_map_get(u32 ufd)
  1283. {
  1284. CLASS(fd, f)(ufd);
  1285. struct bpf_map *map = __bpf_map_get(f);
  1286. if (!IS_ERR(map))
  1287. bpf_map_inc(map);
  1288. return map;
  1289. }
  1290. EXPORT_SYMBOL_NS(bpf_map_get, BPF_INTERNAL);
  1291. struct bpf_map *bpf_map_get_with_uref(u32 ufd)
  1292. {
  1293. CLASS(fd, f)(ufd);
  1294. struct bpf_map *map = __bpf_map_get(f);
  1295. if (!IS_ERR(map))
  1296. bpf_map_inc_with_uref(map);
  1297. return map;
  1298. }
  1299. /* map_idr_lock should have been held or the map should have been
  1300. * protected by rcu read lock.
  1301. */
  1302. struct bpf_map *__bpf_map_inc_not_zero(struct bpf_map *map, bool uref)
  1303. {
  1304. int refold;
  1305. refold = atomic64_fetch_add_unless(&map->refcnt, 1, 0);
  1306. if (!refold)
  1307. return ERR_PTR(-ENOENT);
  1308. if (uref)
  1309. atomic64_inc(&map->usercnt);
  1310. return map;
  1311. }
  1312. struct bpf_map *bpf_map_inc_not_zero(struct bpf_map *map)
  1313. {
  1314. spin_lock_bh(&map_idr_lock);
  1315. map = __bpf_map_inc_not_zero(map, false);
  1316. spin_unlock_bh(&map_idr_lock);
  1317. return map;
  1318. }
  1319. EXPORT_SYMBOL_GPL(bpf_map_inc_not_zero);
  1320. int __weak bpf_stackmap_copy(struct bpf_map *map, void *key, void *value)
  1321. {
  1322. return -ENOTSUPP;
  1323. }
  1324. static void *__bpf_copy_key(void __user *ukey, u64 key_size)
  1325. {
  1326. if (key_size)
  1327. return vmemdup_user(ukey, key_size);
  1328. if (ukey)
  1329. return ERR_PTR(-EINVAL);
  1330. return NULL;
  1331. }
  1332. static void *___bpf_copy_key(bpfptr_t ukey, u64 key_size)
  1333. {
  1334. if (key_size)
  1335. return kvmemdup_bpfptr(ukey, key_size);
  1336. if (!bpfptr_is_null(ukey))
  1337. return ERR_PTR(-EINVAL);
  1338. return NULL;
  1339. }
  1340. /* last field in 'union bpf_attr' used by this command */
  1341. #define BPF_MAP_LOOKUP_ELEM_LAST_FIELD flags
  1342. static int map_lookup_elem(union bpf_attr *attr)
  1343. {
  1344. void __user *ukey = u64_to_user_ptr(attr->key);
  1345. void __user *uvalue = u64_to_user_ptr(attr->value);
  1346. struct bpf_map *map;
  1347. void *key, *value;
  1348. u32 value_size;
  1349. int err;
  1350. if (CHECK_ATTR(BPF_MAP_LOOKUP_ELEM))
  1351. return -EINVAL;
  1352. if (attr->flags & ~BPF_F_LOCK)
  1353. return -EINVAL;
  1354. CLASS(fd, f)(attr->map_fd);
  1355. map = __bpf_map_get(f);
  1356. if (IS_ERR(map))
  1357. return PTR_ERR(map);
  1358. if (!(map_get_sys_perms(map, f) & FMODE_CAN_READ))
  1359. return -EPERM;
  1360. if ((attr->flags & BPF_F_LOCK) &&
  1361. !btf_record_has_field(map->record, BPF_SPIN_LOCK))
  1362. return -EINVAL;
  1363. key = __bpf_copy_key(ukey, map->key_size);
  1364. if (IS_ERR(key))
  1365. return PTR_ERR(key);
  1366. value_size = bpf_map_value_size(map);
  1367. err = -ENOMEM;
  1368. value = kvmalloc(value_size, GFP_USER | __GFP_NOWARN);
  1369. if (!value)
  1370. goto free_key;
  1371. if (map->map_type == BPF_MAP_TYPE_BLOOM_FILTER) {
  1372. if (copy_from_user(value, uvalue, value_size))
  1373. err = -EFAULT;
  1374. else
  1375. err = bpf_map_copy_value(map, key, value, attr->flags);
  1376. goto free_value;
  1377. }
  1378. err = bpf_map_copy_value(map, key, value, attr->flags);
  1379. if (err)
  1380. goto free_value;
  1381. err = -EFAULT;
  1382. if (copy_to_user(uvalue, value, value_size) != 0)
  1383. goto free_value;
  1384. err = 0;
  1385. free_value:
  1386. kvfree(value);
  1387. free_key:
  1388. kvfree(key);
  1389. return err;
  1390. }
  1391. #define BPF_MAP_UPDATE_ELEM_LAST_FIELD flags
  1392. static int map_update_elem(union bpf_attr *attr, bpfptr_t uattr)
  1393. {
  1394. bpfptr_t ukey = make_bpfptr(attr->key, uattr.is_kernel);
  1395. bpfptr_t uvalue = make_bpfptr(attr->value, uattr.is_kernel);
  1396. struct bpf_map *map;
  1397. void *key, *value;
  1398. u32 value_size;
  1399. int err;
  1400. if (CHECK_ATTR(BPF_MAP_UPDATE_ELEM))
  1401. return -EINVAL;
  1402. CLASS(fd, f)(attr->map_fd);
  1403. map = __bpf_map_get(f);
  1404. if (IS_ERR(map))
  1405. return PTR_ERR(map);
  1406. bpf_map_write_active_inc(map);
  1407. if (!(map_get_sys_perms(map, f) & FMODE_CAN_WRITE)) {
  1408. err = -EPERM;
  1409. goto err_put;
  1410. }
  1411. if ((attr->flags & BPF_F_LOCK) &&
  1412. !btf_record_has_field(map->record, BPF_SPIN_LOCK)) {
  1413. err = -EINVAL;
  1414. goto err_put;
  1415. }
  1416. key = ___bpf_copy_key(ukey, map->key_size);
  1417. if (IS_ERR(key)) {
  1418. err = PTR_ERR(key);
  1419. goto err_put;
  1420. }
  1421. value_size = bpf_map_value_size(map);
  1422. value = kvmemdup_bpfptr(uvalue, value_size);
  1423. if (IS_ERR(value)) {
  1424. err = PTR_ERR(value);
  1425. goto free_key;
  1426. }
  1427. err = bpf_map_update_value(map, fd_file(f), key, value, attr->flags);
  1428. if (!err)
  1429. maybe_wait_bpf_programs(map);
  1430. kvfree(value);
  1431. free_key:
  1432. kvfree(key);
  1433. err_put:
  1434. bpf_map_write_active_dec(map);
  1435. return err;
  1436. }
  1437. #define BPF_MAP_DELETE_ELEM_LAST_FIELD key
  1438. static int map_delete_elem(union bpf_attr *attr, bpfptr_t uattr)
  1439. {
  1440. bpfptr_t ukey = make_bpfptr(attr->key, uattr.is_kernel);
  1441. struct bpf_map *map;
  1442. void *key;
  1443. int err;
  1444. if (CHECK_ATTR(BPF_MAP_DELETE_ELEM))
  1445. return -EINVAL;
  1446. CLASS(fd, f)(attr->map_fd);
  1447. map = __bpf_map_get(f);
  1448. if (IS_ERR(map))
  1449. return PTR_ERR(map);
  1450. bpf_map_write_active_inc(map);
  1451. if (!(map_get_sys_perms(map, f) & FMODE_CAN_WRITE)) {
  1452. err = -EPERM;
  1453. goto err_put;
  1454. }
  1455. key = ___bpf_copy_key(ukey, map->key_size);
  1456. if (IS_ERR(key)) {
  1457. err = PTR_ERR(key);
  1458. goto err_put;
  1459. }
  1460. if (bpf_map_is_offloaded(map)) {
  1461. err = bpf_map_offload_delete_elem(map, key);
  1462. goto out;
  1463. } else if (IS_FD_PROG_ARRAY(map) ||
  1464. map->map_type == BPF_MAP_TYPE_STRUCT_OPS) {
  1465. /* These maps require sleepable context */
  1466. err = map->ops->map_delete_elem(map, key);
  1467. goto out;
  1468. }
  1469. bpf_disable_instrumentation();
  1470. rcu_read_lock();
  1471. err = map->ops->map_delete_elem(map, key);
  1472. rcu_read_unlock();
  1473. bpf_enable_instrumentation();
  1474. if (!err)
  1475. maybe_wait_bpf_programs(map);
  1476. out:
  1477. kvfree(key);
  1478. err_put:
  1479. bpf_map_write_active_dec(map);
  1480. return err;
  1481. }
  1482. /* last field in 'union bpf_attr' used by this command */
  1483. #define BPF_MAP_GET_NEXT_KEY_LAST_FIELD next_key
  1484. static int map_get_next_key(union bpf_attr *attr)
  1485. {
  1486. void __user *ukey = u64_to_user_ptr(attr->key);
  1487. void __user *unext_key = u64_to_user_ptr(attr->next_key);
  1488. struct bpf_map *map;
  1489. void *key, *next_key;
  1490. int err;
  1491. if (CHECK_ATTR(BPF_MAP_GET_NEXT_KEY))
  1492. return -EINVAL;
  1493. CLASS(fd, f)(attr->map_fd);
  1494. map = __bpf_map_get(f);
  1495. if (IS_ERR(map))
  1496. return PTR_ERR(map);
  1497. if (!(map_get_sys_perms(map, f) & FMODE_CAN_READ))
  1498. return -EPERM;
  1499. if (ukey) {
  1500. key = __bpf_copy_key(ukey, map->key_size);
  1501. if (IS_ERR(key))
  1502. return PTR_ERR(key);
  1503. } else {
  1504. key = NULL;
  1505. }
  1506. err = -ENOMEM;
  1507. next_key = kvmalloc(map->key_size, GFP_USER);
  1508. if (!next_key)
  1509. goto free_key;
  1510. if (bpf_map_is_offloaded(map)) {
  1511. err = bpf_map_offload_get_next_key(map, key, next_key);
  1512. goto out;
  1513. }
  1514. rcu_read_lock();
  1515. err = map->ops->map_get_next_key(map, key, next_key);
  1516. rcu_read_unlock();
  1517. out:
  1518. if (err)
  1519. goto free_next_key;
  1520. err = -EFAULT;
  1521. if (copy_to_user(unext_key, next_key, map->key_size) != 0)
  1522. goto free_next_key;
  1523. err = 0;
  1524. free_next_key:
  1525. kvfree(next_key);
  1526. free_key:
  1527. kvfree(key);
  1528. return err;
  1529. }
  1530. int generic_map_delete_batch(struct bpf_map *map,
  1531. const union bpf_attr *attr,
  1532. union bpf_attr __user *uattr)
  1533. {
  1534. void __user *keys = u64_to_user_ptr(attr->batch.keys);
  1535. u32 cp, max_count;
  1536. int err = 0;
  1537. void *key;
  1538. if (attr->batch.elem_flags & ~BPF_F_LOCK)
  1539. return -EINVAL;
  1540. if ((attr->batch.elem_flags & BPF_F_LOCK) &&
  1541. !btf_record_has_field(map->record, BPF_SPIN_LOCK)) {
  1542. return -EINVAL;
  1543. }
  1544. max_count = attr->batch.count;
  1545. if (!max_count)
  1546. return 0;
  1547. if (put_user(0, &uattr->batch.count))
  1548. return -EFAULT;
  1549. key = kvmalloc(map->key_size, GFP_USER | __GFP_NOWARN);
  1550. if (!key)
  1551. return -ENOMEM;
  1552. for (cp = 0; cp < max_count; cp++) {
  1553. err = -EFAULT;
  1554. if (copy_from_user(key, keys + cp * map->key_size,
  1555. map->key_size))
  1556. break;
  1557. if (bpf_map_is_offloaded(map)) {
  1558. err = bpf_map_offload_delete_elem(map, key);
  1559. break;
  1560. }
  1561. bpf_disable_instrumentation();
  1562. rcu_read_lock();
  1563. err = map->ops->map_delete_elem(map, key);
  1564. rcu_read_unlock();
  1565. bpf_enable_instrumentation();
  1566. if (err)
  1567. break;
  1568. cond_resched();
  1569. }
  1570. if (copy_to_user(&uattr->batch.count, &cp, sizeof(cp)))
  1571. err = -EFAULT;
  1572. kvfree(key);
  1573. return err;
  1574. }
  1575. int generic_map_update_batch(struct bpf_map *map, struct file *map_file,
  1576. const union bpf_attr *attr,
  1577. union bpf_attr __user *uattr)
  1578. {
  1579. void __user *values = u64_to_user_ptr(attr->batch.values);
  1580. void __user *keys = u64_to_user_ptr(attr->batch.keys);
  1581. u32 value_size, cp, max_count;
  1582. void *key, *value;
  1583. int err = 0;
  1584. if (attr->batch.elem_flags & ~BPF_F_LOCK)
  1585. return -EINVAL;
  1586. if ((attr->batch.elem_flags & BPF_F_LOCK) &&
  1587. !btf_record_has_field(map->record, BPF_SPIN_LOCK)) {
  1588. return -EINVAL;
  1589. }
  1590. value_size = bpf_map_value_size(map);
  1591. max_count = attr->batch.count;
  1592. if (!max_count)
  1593. return 0;
  1594. if (put_user(0, &uattr->batch.count))
  1595. return -EFAULT;
  1596. key = kvmalloc(map->key_size, GFP_USER | __GFP_NOWARN);
  1597. if (!key)
  1598. return -ENOMEM;
  1599. value = kvmalloc(value_size, GFP_USER | __GFP_NOWARN);
  1600. if (!value) {
  1601. kvfree(key);
  1602. return -ENOMEM;
  1603. }
  1604. for (cp = 0; cp < max_count; cp++) {
  1605. err = -EFAULT;
  1606. if (copy_from_user(key, keys + cp * map->key_size,
  1607. map->key_size) ||
  1608. copy_from_user(value, values + cp * value_size, value_size))
  1609. break;
  1610. err = bpf_map_update_value(map, map_file, key, value,
  1611. attr->batch.elem_flags);
  1612. if (err)
  1613. break;
  1614. cond_resched();
  1615. }
  1616. if (copy_to_user(&uattr->batch.count, &cp, sizeof(cp)))
  1617. err = -EFAULT;
  1618. kvfree(value);
  1619. kvfree(key);
  1620. return err;
  1621. }
  1622. int generic_map_lookup_batch(struct bpf_map *map,
  1623. const union bpf_attr *attr,
  1624. union bpf_attr __user *uattr)
  1625. {
  1626. void __user *uobatch = u64_to_user_ptr(attr->batch.out_batch);
  1627. void __user *ubatch = u64_to_user_ptr(attr->batch.in_batch);
  1628. void __user *values = u64_to_user_ptr(attr->batch.values);
  1629. void __user *keys = u64_to_user_ptr(attr->batch.keys);
  1630. void *buf, *buf_prevkey, *prev_key, *key, *value;
  1631. u32 value_size, cp, max_count;
  1632. int err;
  1633. if (attr->batch.elem_flags & ~BPF_F_LOCK)
  1634. return -EINVAL;
  1635. if ((attr->batch.elem_flags & BPF_F_LOCK) &&
  1636. !btf_record_has_field(map->record, BPF_SPIN_LOCK))
  1637. return -EINVAL;
  1638. value_size = bpf_map_value_size(map);
  1639. max_count = attr->batch.count;
  1640. if (!max_count)
  1641. return 0;
  1642. if (put_user(0, &uattr->batch.count))
  1643. return -EFAULT;
  1644. buf_prevkey = kvmalloc(map->key_size, GFP_USER | __GFP_NOWARN);
  1645. if (!buf_prevkey)
  1646. return -ENOMEM;
  1647. buf = kvmalloc(map->key_size + value_size, GFP_USER | __GFP_NOWARN);
  1648. if (!buf) {
  1649. kvfree(buf_prevkey);
  1650. return -ENOMEM;
  1651. }
  1652. err = -EFAULT;
  1653. prev_key = NULL;
  1654. if (ubatch && copy_from_user(buf_prevkey, ubatch, map->key_size))
  1655. goto free_buf;
  1656. key = buf;
  1657. value = key + map->key_size;
  1658. if (ubatch)
  1659. prev_key = buf_prevkey;
  1660. for (cp = 0; cp < max_count;) {
  1661. rcu_read_lock();
  1662. err = map->ops->map_get_next_key(map, prev_key, key);
  1663. rcu_read_unlock();
  1664. if (err)
  1665. break;
  1666. err = bpf_map_copy_value(map, key, value,
  1667. attr->batch.elem_flags);
  1668. if (err == -ENOENT)
  1669. goto next_key;
  1670. if (err)
  1671. goto free_buf;
  1672. if (copy_to_user(keys + cp * map->key_size, key,
  1673. map->key_size)) {
  1674. err = -EFAULT;
  1675. goto free_buf;
  1676. }
  1677. if (copy_to_user(values + cp * value_size, value, value_size)) {
  1678. err = -EFAULT;
  1679. goto free_buf;
  1680. }
  1681. cp++;
  1682. next_key:
  1683. if (!prev_key)
  1684. prev_key = buf_prevkey;
  1685. swap(prev_key, key);
  1686. cond_resched();
  1687. }
  1688. if (err == -EFAULT)
  1689. goto free_buf;
  1690. if ((copy_to_user(&uattr->batch.count, &cp, sizeof(cp)) ||
  1691. (cp && copy_to_user(uobatch, prev_key, map->key_size))))
  1692. err = -EFAULT;
  1693. free_buf:
  1694. kvfree(buf_prevkey);
  1695. kvfree(buf);
  1696. return err;
  1697. }
  1698. #define BPF_MAP_LOOKUP_AND_DELETE_ELEM_LAST_FIELD flags
  1699. static int map_lookup_and_delete_elem(union bpf_attr *attr)
  1700. {
  1701. void __user *ukey = u64_to_user_ptr(attr->key);
  1702. void __user *uvalue = u64_to_user_ptr(attr->value);
  1703. struct bpf_map *map;
  1704. void *key, *value;
  1705. u32 value_size;
  1706. int err;
  1707. if (CHECK_ATTR(BPF_MAP_LOOKUP_AND_DELETE_ELEM))
  1708. return -EINVAL;
  1709. if (attr->flags & ~BPF_F_LOCK)
  1710. return -EINVAL;
  1711. CLASS(fd, f)(attr->map_fd);
  1712. map = __bpf_map_get(f);
  1713. if (IS_ERR(map))
  1714. return PTR_ERR(map);
  1715. bpf_map_write_active_inc(map);
  1716. if (!(map_get_sys_perms(map, f) & FMODE_CAN_READ) ||
  1717. !(map_get_sys_perms(map, f) & FMODE_CAN_WRITE)) {
  1718. err = -EPERM;
  1719. goto err_put;
  1720. }
  1721. if (attr->flags &&
  1722. (map->map_type == BPF_MAP_TYPE_QUEUE ||
  1723. map->map_type == BPF_MAP_TYPE_STACK)) {
  1724. err = -EINVAL;
  1725. goto err_put;
  1726. }
  1727. if ((attr->flags & BPF_F_LOCK) &&
  1728. !btf_record_has_field(map->record, BPF_SPIN_LOCK)) {
  1729. err = -EINVAL;
  1730. goto err_put;
  1731. }
  1732. key = __bpf_copy_key(ukey, map->key_size);
  1733. if (IS_ERR(key)) {
  1734. err = PTR_ERR(key);
  1735. goto err_put;
  1736. }
  1737. value_size = bpf_map_value_size(map);
  1738. err = -ENOMEM;
  1739. value = kvmalloc(value_size, GFP_USER | __GFP_NOWARN);
  1740. if (!value)
  1741. goto free_key;
  1742. err = -ENOTSUPP;
  1743. if (map->map_type == BPF_MAP_TYPE_QUEUE ||
  1744. map->map_type == BPF_MAP_TYPE_STACK) {
  1745. err = map->ops->map_pop_elem(map, value);
  1746. } else if (map->map_type == BPF_MAP_TYPE_HASH ||
  1747. map->map_type == BPF_MAP_TYPE_PERCPU_HASH ||
  1748. map->map_type == BPF_MAP_TYPE_LRU_HASH ||
  1749. map->map_type == BPF_MAP_TYPE_LRU_PERCPU_HASH) {
  1750. if (!bpf_map_is_offloaded(map)) {
  1751. bpf_disable_instrumentation();
  1752. rcu_read_lock();
  1753. err = map->ops->map_lookup_and_delete_elem(map, key, value, attr->flags);
  1754. rcu_read_unlock();
  1755. bpf_enable_instrumentation();
  1756. }
  1757. }
  1758. if (err)
  1759. goto free_value;
  1760. if (copy_to_user(uvalue, value, value_size) != 0) {
  1761. err = -EFAULT;
  1762. goto free_value;
  1763. }
  1764. err = 0;
  1765. free_value:
  1766. kvfree(value);
  1767. free_key:
  1768. kvfree(key);
  1769. err_put:
  1770. bpf_map_write_active_dec(map);
  1771. return err;
  1772. }
  1773. #define BPF_MAP_FREEZE_LAST_FIELD map_fd
  1774. static int map_freeze(const union bpf_attr *attr)
  1775. {
  1776. int err = 0;
  1777. struct bpf_map *map;
  1778. if (CHECK_ATTR(BPF_MAP_FREEZE))
  1779. return -EINVAL;
  1780. CLASS(fd, f)(attr->map_fd);
  1781. map = __bpf_map_get(f);
  1782. if (IS_ERR(map))
  1783. return PTR_ERR(map);
  1784. if (map->map_type == BPF_MAP_TYPE_STRUCT_OPS || !IS_ERR_OR_NULL(map->record))
  1785. return -ENOTSUPP;
  1786. if (!(map_get_sys_perms(map, f) & FMODE_CAN_WRITE))
  1787. return -EPERM;
  1788. mutex_lock(&map->freeze_mutex);
  1789. if (bpf_map_write_active(map)) {
  1790. err = -EBUSY;
  1791. goto err_put;
  1792. }
  1793. if (READ_ONCE(map->frozen)) {
  1794. err = -EBUSY;
  1795. goto err_put;
  1796. }
  1797. WRITE_ONCE(map->frozen, true);
  1798. err_put:
  1799. mutex_unlock(&map->freeze_mutex);
  1800. return err;
  1801. }
  1802. static const struct bpf_prog_ops * const bpf_prog_types[] = {
  1803. #define BPF_PROG_TYPE(_id, _name, prog_ctx_type, kern_ctx_type) \
  1804. [_id] = & _name ## _prog_ops,
  1805. #define BPF_MAP_TYPE(_id, _ops)
  1806. #define BPF_LINK_TYPE(_id, _name)
  1807. #include <linux/bpf_types.h>
  1808. #undef BPF_PROG_TYPE
  1809. #undef BPF_MAP_TYPE
  1810. #undef BPF_LINK_TYPE
  1811. };
  1812. static int find_prog_type(enum bpf_prog_type type, struct bpf_prog *prog)
  1813. {
  1814. const struct bpf_prog_ops *ops;
  1815. if (type >= ARRAY_SIZE(bpf_prog_types))
  1816. return -EINVAL;
  1817. type = array_index_nospec(type, ARRAY_SIZE(bpf_prog_types));
  1818. ops = bpf_prog_types[type];
  1819. if (!ops)
  1820. return -EINVAL;
  1821. if (!bpf_prog_is_offloaded(prog->aux))
  1822. prog->aux->ops = ops;
  1823. else
  1824. prog->aux->ops = &bpf_offload_prog_ops;
  1825. prog->type = type;
  1826. return 0;
  1827. }
  1828. enum bpf_audit {
  1829. BPF_AUDIT_LOAD,
  1830. BPF_AUDIT_UNLOAD,
  1831. BPF_AUDIT_MAX,
  1832. };
  1833. static const char * const bpf_audit_str[BPF_AUDIT_MAX] = {
  1834. [BPF_AUDIT_LOAD] = "LOAD",
  1835. [BPF_AUDIT_UNLOAD] = "UNLOAD",
  1836. };
  1837. static void bpf_audit_prog(const struct bpf_prog *prog, unsigned int op)
  1838. {
  1839. struct audit_context *ctx = NULL;
  1840. struct audit_buffer *ab;
  1841. if (WARN_ON_ONCE(op >= BPF_AUDIT_MAX))
  1842. return;
  1843. if (audit_enabled == AUDIT_OFF)
  1844. return;
  1845. if (!in_irq() && !irqs_disabled())
  1846. ctx = audit_context();
  1847. ab = audit_log_start(ctx, GFP_ATOMIC, AUDIT_BPF);
  1848. if (unlikely(!ab))
  1849. return;
  1850. audit_log_format(ab, "prog-id=%u op=%s",
  1851. prog->aux->id, bpf_audit_str[op]);
  1852. audit_log_end(ab);
  1853. }
  1854. static int bpf_prog_alloc_id(struct bpf_prog *prog)
  1855. {
  1856. int id;
  1857. idr_preload(GFP_KERNEL);
  1858. spin_lock_bh(&prog_idr_lock);
  1859. id = idr_alloc_cyclic(&prog_idr, prog, 1, INT_MAX, GFP_ATOMIC);
  1860. if (id > 0)
  1861. prog->aux->id = id;
  1862. spin_unlock_bh(&prog_idr_lock);
  1863. idr_preload_end();
  1864. /* id is in [1, INT_MAX) */
  1865. if (WARN_ON_ONCE(!id))
  1866. return -ENOSPC;
  1867. return id > 0 ? 0 : id;
  1868. }
  1869. void bpf_prog_free_id(struct bpf_prog *prog)
  1870. {
  1871. unsigned long flags;
  1872. /* cBPF to eBPF migrations are currently not in the idr store.
  1873. * Offloaded programs are removed from the store when their device
  1874. * disappears - even if someone grabs an fd to them they are unusable,
  1875. * simply waiting for refcnt to drop to be freed.
  1876. */
  1877. if (!prog->aux->id)
  1878. return;
  1879. spin_lock_irqsave(&prog_idr_lock, flags);
  1880. idr_remove(&prog_idr, prog->aux->id);
  1881. prog->aux->id = 0;
  1882. spin_unlock_irqrestore(&prog_idr_lock, flags);
  1883. }
  1884. static void __bpf_prog_put_rcu(struct rcu_head *rcu)
  1885. {
  1886. struct bpf_prog_aux *aux = container_of(rcu, struct bpf_prog_aux, rcu);
  1887. kvfree(aux->func_info);
  1888. kfree(aux->func_info_aux);
  1889. free_uid(aux->user);
  1890. security_bpf_prog_free(aux->prog);
  1891. bpf_prog_free(aux->prog);
  1892. }
  1893. static void __bpf_prog_put_noref(struct bpf_prog *prog, bool deferred)
  1894. {
  1895. bpf_prog_kallsyms_del_all(prog);
  1896. btf_put(prog->aux->btf);
  1897. module_put(prog->aux->mod);
  1898. kvfree(prog->aux->jited_linfo);
  1899. kvfree(prog->aux->linfo);
  1900. kfree(prog->aux->kfunc_tab);
  1901. if (prog->aux->attach_btf)
  1902. btf_put(prog->aux->attach_btf);
  1903. if (deferred) {
  1904. if (prog->sleepable)
  1905. call_rcu_tasks_trace(&prog->aux->rcu, __bpf_prog_put_rcu);
  1906. else
  1907. call_rcu(&prog->aux->rcu, __bpf_prog_put_rcu);
  1908. } else {
  1909. __bpf_prog_put_rcu(&prog->aux->rcu);
  1910. }
  1911. }
  1912. static void bpf_prog_put_deferred(struct work_struct *work)
  1913. {
  1914. struct bpf_prog_aux *aux;
  1915. struct bpf_prog *prog;
  1916. aux = container_of(work, struct bpf_prog_aux, work);
  1917. prog = aux->prog;
  1918. perf_event_bpf_event(prog, PERF_BPF_EVENT_PROG_UNLOAD, 0);
  1919. bpf_audit_prog(prog, BPF_AUDIT_UNLOAD);
  1920. bpf_prog_free_id(prog);
  1921. __bpf_prog_put_noref(prog, true);
  1922. }
  1923. static void __bpf_prog_put(struct bpf_prog *prog)
  1924. {
  1925. struct bpf_prog_aux *aux = prog->aux;
  1926. if (atomic64_dec_and_test(&aux->refcnt)) {
  1927. if (in_irq() || irqs_disabled()) {
  1928. INIT_WORK(&aux->work, bpf_prog_put_deferred);
  1929. schedule_work(&aux->work);
  1930. } else {
  1931. bpf_prog_put_deferred(&aux->work);
  1932. }
  1933. }
  1934. }
  1935. void bpf_prog_put(struct bpf_prog *prog)
  1936. {
  1937. __bpf_prog_put(prog);
  1938. }
  1939. EXPORT_SYMBOL_GPL(bpf_prog_put);
  1940. static int bpf_prog_release(struct inode *inode, struct file *filp)
  1941. {
  1942. struct bpf_prog *prog = filp->private_data;
  1943. bpf_prog_put(prog);
  1944. return 0;
  1945. }
  1946. struct bpf_prog_kstats {
  1947. u64 nsecs;
  1948. u64 cnt;
  1949. u64 misses;
  1950. };
  1951. void notrace bpf_prog_inc_misses_counter(struct bpf_prog *prog)
  1952. {
  1953. struct bpf_prog_stats *stats;
  1954. unsigned int flags;
  1955. stats = this_cpu_ptr(prog->stats);
  1956. flags = u64_stats_update_begin_irqsave(&stats->syncp);
  1957. u64_stats_inc(&stats->misses);
  1958. u64_stats_update_end_irqrestore(&stats->syncp, flags);
  1959. }
  1960. static void bpf_prog_get_stats(const struct bpf_prog *prog,
  1961. struct bpf_prog_kstats *stats)
  1962. {
  1963. u64 nsecs = 0, cnt = 0, misses = 0;
  1964. int cpu;
  1965. for_each_possible_cpu(cpu) {
  1966. const struct bpf_prog_stats *st;
  1967. unsigned int start;
  1968. u64 tnsecs, tcnt, tmisses;
  1969. st = per_cpu_ptr(prog->stats, cpu);
  1970. do {
  1971. start = u64_stats_fetch_begin(&st->syncp);
  1972. tnsecs = u64_stats_read(&st->nsecs);
  1973. tcnt = u64_stats_read(&st->cnt);
  1974. tmisses = u64_stats_read(&st->misses);
  1975. } while (u64_stats_fetch_retry(&st->syncp, start));
  1976. nsecs += tnsecs;
  1977. cnt += tcnt;
  1978. misses += tmisses;
  1979. }
  1980. stats->nsecs = nsecs;
  1981. stats->cnt = cnt;
  1982. stats->misses = misses;
  1983. }
  1984. #ifdef CONFIG_PROC_FS
  1985. static void bpf_prog_show_fdinfo(struct seq_file *m, struct file *filp)
  1986. {
  1987. const struct bpf_prog *prog = filp->private_data;
  1988. char prog_tag[sizeof(prog->tag) * 2 + 1] = { };
  1989. struct bpf_prog_kstats stats;
  1990. bpf_prog_get_stats(prog, &stats);
  1991. bin2hex(prog_tag, prog->tag, sizeof(prog->tag));
  1992. seq_printf(m,
  1993. "prog_type:\t%u\n"
  1994. "prog_jited:\t%u\n"
  1995. "prog_tag:\t%s\n"
  1996. "memlock:\t%llu\n"
  1997. "prog_id:\t%u\n"
  1998. "run_time_ns:\t%llu\n"
  1999. "run_cnt:\t%llu\n"
  2000. "recursion_misses:\t%llu\n"
  2001. "verified_insns:\t%u\n",
  2002. prog->type,
  2003. prog->jited,
  2004. prog_tag,
  2005. prog->pages * 1ULL << PAGE_SHIFT,
  2006. prog->aux->id,
  2007. stats.nsecs,
  2008. stats.cnt,
  2009. stats.misses,
  2010. prog->aux->verified_insns);
  2011. }
  2012. #endif
  2013. const struct file_operations bpf_prog_fops = {
  2014. #ifdef CONFIG_PROC_FS
  2015. .show_fdinfo = bpf_prog_show_fdinfo,
  2016. #endif
  2017. .release = bpf_prog_release,
  2018. .read = bpf_dummy_read,
  2019. .write = bpf_dummy_write,
  2020. };
  2021. int bpf_prog_new_fd(struct bpf_prog *prog)
  2022. {
  2023. int ret;
  2024. ret = security_bpf_prog(prog);
  2025. if (ret < 0)
  2026. return ret;
  2027. return anon_inode_getfd("bpf-prog", &bpf_prog_fops, prog,
  2028. O_RDWR | O_CLOEXEC);
  2029. }
  2030. void bpf_prog_add(struct bpf_prog *prog, int i)
  2031. {
  2032. atomic64_add(i, &prog->aux->refcnt);
  2033. }
  2034. EXPORT_SYMBOL_GPL(bpf_prog_add);
  2035. void bpf_prog_sub(struct bpf_prog *prog, int i)
  2036. {
  2037. /* Only to be used for undoing previous bpf_prog_add() in some
  2038. * error path. We still know that another entity in our call
  2039. * path holds a reference to the program, thus atomic_sub() can
  2040. * be safely used in such cases!
  2041. */
  2042. WARN_ON(atomic64_sub_return(i, &prog->aux->refcnt) == 0);
  2043. }
  2044. EXPORT_SYMBOL_GPL(bpf_prog_sub);
  2045. void bpf_prog_inc(struct bpf_prog *prog)
  2046. {
  2047. atomic64_inc(&prog->aux->refcnt);
  2048. }
  2049. EXPORT_SYMBOL_GPL(bpf_prog_inc);
  2050. /* prog_idr_lock should have been held */
  2051. struct bpf_prog *bpf_prog_inc_not_zero(struct bpf_prog *prog)
  2052. {
  2053. int refold;
  2054. refold = atomic64_fetch_add_unless(&prog->aux->refcnt, 1, 0);
  2055. if (!refold)
  2056. return ERR_PTR(-ENOENT);
  2057. return prog;
  2058. }
  2059. EXPORT_SYMBOL_GPL(bpf_prog_inc_not_zero);
  2060. bool bpf_prog_get_ok(struct bpf_prog *prog,
  2061. enum bpf_prog_type *attach_type, bool attach_drv)
  2062. {
  2063. /* not an attachment, just a refcount inc, always allow */
  2064. if (!attach_type)
  2065. return true;
  2066. if (prog->type != *attach_type)
  2067. return false;
  2068. if (bpf_prog_is_offloaded(prog->aux) && !attach_drv)
  2069. return false;
  2070. return true;
  2071. }
  2072. static struct bpf_prog *__bpf_prog_get(u32 ufd, enum bpf_prog_type *attach_type,
  2073. bool attach_drv)
  2074. {
  2075. CLASS(fd, f)(ufd);
  2076. struct bpf_prog *prog;
  2077. if (fd_empty(f))
  2078. return ERR_PTR(-EBADF);
  2079. if (fd_file(f)->f_op != &bpf_prog_fops)
  2080. return ERR_PTR(-EINVAL);
  2081. prog = fd_file(f)->private_data;
  2082. if (!bpf_prog_get_ok(prog, attach_type, attach_drv))
  2083. return ERR_PTR(-EINVAL);
  2084. bpf_prog_inc(prog);
  2085. return prog;
  2086. }
  2087. struct bpf_prog *bpf_prog_get(u32 ufd)
  2088. {
  2089. return __bpf_prog_get(ufd, NULL, false);
  2090. }
  2091. struct bpf_prog *bpf_prog_get_type_dev(u32 ufd, enum bpf_prog_type type,
  2092. bool attach_drv)
  2093. {
  2094. return __bpf_prog_get(ufd, &type, attach_drv);
  2095. }
  2096. EXPORT_SYMBOL_GPL(bpf_prog_get_type_dev);
  2097. /* Initially all BPF programs could be loaded w/o specifying
  2098. * expected_attach_type. Later for some of them specifying expected_attach_type
  2099. * at load time became required so that program could be validated properly.
  2100. * Programs of types that are allowed to be loaded both w/ and w/o (for
  2101. * backward compatibility) expected_attach_type, should have the default attach
  2102. * type assigned to expected_attach_type for the latter case, so that it can be
  2103. * validated later at attach time.
  2104. *
  2105. * bpf_prog_load_fixup_attach_type() sets expected_attach_type in @attr if
  2106. * prog type requires it but has some attach types that have to be backward
  2107. * compatible.
  2108. */
  2109. static void bpf_prog_load_fixup_attach_type(union bpf_attr *attr)
  2110. {
  2111. switch (attr->prog_type) {
  2112. case BPF_PROG_TYPE_CGROUP_SOCK:
  2113. /* Unfortunately BPF_ATTACH_TYPE_UNSPEC enumeration doesn't
  2114. * exist so checking for non-zero is the way to go here.
  2115. */
  2116. if (!attr->expected_attach_type)
  2117. attr->expected_attach_type =
  2118. BPF_CGROUP_INET_SOCK_CREATE;
  2119. break;
  2120. case BPF_PROG_TYPE_SK_REUSEPORT:
  2121. if (!attr->expected_attach_type)
  2122. attr->expected_attach_type =
  2123. BPF_SK_REUSEPORT_SELECT;
  2124. break;
  2125. }
  2126. }
  2127. static int
  2128. bpf_prog_load_check_attach(enum bpf_prog_type prog_type,
  2129. enum bpf_attach_type expected_attach_type,
  2130. struct btf *attach_btf, u32 btf_id,
  2131. struct bpf_prog *dst_prog)
  2132. {
  2133. if (btf_id) {
  2134. if (btf_id > BTF_MAX_TYPE)
  2135. return -EINVAL;
  2136. if (!attach_btf && !dst_prog)
  2137. return -EINVAL;
  2138. switch (prog_type) {
  2139. case BPF_PROG_TYPE_TRACING:
  2140. case BPF_PROG_TYPE_LSM:
  2141. case BPF_PROG_TYPE_STRUCT_OPS:
  2142. case BPF_PROG_TYPE_EXT:
  2143. break;
  2144. default:
  2145. return -EINVAL;
  2146. }
  2147. }
  2148. if (attach_btf && (!btf_id || dst_prog))
  2149. return -EINVAL;
  2150. if (dst_prog && prog_type != BPF_PROG_TYPE_TRACING &&
  2151. prog_type != BPF_PROG_TYPE_EXT)
  2152. return -EINVAL;
  2153. switch (prog_type) {
  2154. case BPF_PROG_TYPE_CGROUP_SOCK:
  2155. switch (expected_attach_type) {
  2156. case BPF_CGROUP_INET_SOCK_CREATE:
  2157. case BPF_CGROUP_INET_SOCK_RELEASE:
  2158. case BPF_CGROUP_INET4_POST_BIND:
  2159. case BPF_CGROUP_INET6_POST_BIND:
  2160. return 0;
  2161. default:
  2162. return -EINVAL;
  2163. }
  2164. case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
  2165. switch (expected_attach_type) {
  2166. case BPF_CGROUP_INET4_BIND:
  2167. case BPF_CGROUP_INET6_BIND:
  2168. case BPF_CGROUP_INET4_CONNECT:
  2169. case BPF_CGROUP_INET6_CONNECT:
  2170. case BPF_CGROUP_UNIX_CONNECT:
  2171. case BPF_CGROUP_INET4_GETPEERNAME:
  2172. case BPF_CGROUP_INET6_GETPEERNAME:
  2173. case BPF_CGROUP_UNIX_GETPEERNAME:
  2174. case BPF_CGROUP_INET4_GETSOCKNAME:
  2175. case BPF_CGROUP_INET6_GETSOCKNAME:
  2176. case BPF_CGROUP_UNIX_GETSOCKNAME:
  2177. case BPF_CGROUP_UDP4_SENDMSG:
  2178. case BPF_CGROUP_UDP6_SENDMSG:
  2179. case BPF_CGROUP_UNIX_SENDMSG:
  2180. case BPF_CGROUP_UDP4_RECVMSG:
  2181. case BPF_CGROUP_UDP6_RECVMSG:
  2182. case BPF_CGROUP_UNIX_RECVMSG:
  2183. return 0;
  2184. default:
  2185. return -EINVAL;
  2186. }
  2187. case BPF_PROG_TYPE_CGROUP_SKB:
  2188. switch (expected_attach_type) {
  2189. case BPF_CGROUP_INET_INGRESS:
  2190. case BPF_CGROUP_INET_EGRESS:
  2191. return 0;
  2192. default:
  2193. return -EINVAL;
  2194. }
  2195. case BPF_PROG_TYPE_CGROUP_SOCKOPT:
  2196. switch (expected_attach_type) {
  2197. case BPF_CGROUP_SETSOCKOPT:
  2198. case BPF_CGROUP_GETSOCKOPT:
  2199. return 0;
  2200. default:
  2201. return -EINVAL;
  2202. }
  2203. case BPF_PROG_TYPE_SK_LOOKUP:
  2204. if (expected_attach_type == BPF_SK_LOOKUP)
  2205. return 0;
  2206. return -EINVAL;
  2207. case BPF_PROG_TYPE_SK_REUSEPORT:
  2208. switch (expected_attach_type) {
  2209. case BPF_SK_REUSEPORT_SELECT:
  2210. case BPF_SK_REUSEPORT_SELECT_OR_MIGRATE:
  2211. return 0;
  2212. default:
  2213. return -EINVAL;
  2214. }
  2215. case BPF_PROG_TYPE_NETFILTER:
  2216. if (expected_attach_type == BPF_NETFILTER)
  2217. return 0;
  2218. return -EINVAL;
  2219. case BPF_PROG_TYPE_SYSCALL:
  2220. case BPF_PROG_TYPE_EXT:
  2221. if (expected_attach_type)
  2222. return -EINVAL;
  2223. fallthrough;
  2224. default:
  2225. return 0;
  2226. }
  2227. }
  2228. static bool is_net_admin_prog_type(enum bpf_prog_type prog_type)
  2229. {
  2230. switch (prog_type) {
  2231. case BPF_PROG_TYPE_SCHED_CLS:
  2232. case BPF_PROG_TYPE_SCHED_ACT:
  2233. case BPF_PROG_TYPE_XDP:
  2234. case BPF_PROG_TYPE_LWT_IN:
  2235. case BPF_PROG_TYPE_LWT_OUT:
  2236. case BPF_PROG_TYPE_LWT_XMIT:
  2237. case BPF_PROG_TYPE_LWT_SEG6LOCAL:
  2238. case BPF_PROG_TYPE_SK_SKB:
  2239. case BPF_PROG_TYPE_SK_MSG:
  2240. case BPF_PROG_TYPE_FLOW_DISSECTOR:
  2241. case BPF_PROG_TYPE_CGROUP_DEVICE:
  2242. case BPF_PROG_TYPE_CGROUP_SOCK:
  2243. case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
  2244. case BPF_PROG_TYPE_CGROUP_SOCKOPT:
  2245. case BPF_PROG_TYPE_CGROUP_SYSCTL:
  2246. case BPF_PROG_TYPE_SOCK_OPS:
  2247. case BPF_PROG_TYPE_EXT: /* extends any prog */
  2248. case BPF_PROG_TYPE_NETFILTER:
  2249. return true;
  2250. case BPF_PROG_TYPE_CGROUP_SKB:
  2251. /* always unpriv */
  2252. case BPF_PROG_TYPE_SK_REUSEPORT:
  2253. /* equivalent to SOCKET_FILTER. need CAP_BPF only */
  2254. default:
  2255. return false;
  2256. }
  2257. }
  2258. static bool is_perfmon_prog_type(enum bpf_prog_type prog_type)
  2259. {
  2260. switch (prog_type) {
  2261. case BPF_PROG_TYPE_KPROBE:
  2262. case BPF_PROG_TYPE_TRACEPOINT:
  2263. case BPF_PROG_TYPE_PERF_EVENT:
  2264. case BPF_PROG_TYPE_RAW_TRACEPOINT:
  2265. case BPF_PROG_TYPE_RAW_TRACEPOINT_WRITABLE:
  2266. case BPF_PROG_TYPE_TRACING:
  2267. case BPF_PROG_TYPE_LSM:
  2268. case BPF_PROG_TYPE_STRUCT_OPS: /* has access to struct sock */
  2269. case BPF_PROG_TYPE_EXT: /* extends any prog */
  2270. return true;
  2271. default:
  2272. return false;
  2273. }
  2274. }
  2275. /* last field in 'union bpf_attr' used by this command */
  2276. #define BPF_PROG_LOAD_LAST_FIELD prog_token_fd
  2277. static int bpf_prog_load(union bpf_attr *attr, bpfptr_t uattr, u32 uattr_size)
  2278. {
  2279. enum bpf_prog_type type = attr->prog_type;
  2280. struct bpf_prog *prog, *dst_prog = NULL;
  2281. struct btf *attach_btf = NULL;
  2282. struct bpf_token *token = NULL;
  2283. bool bpf_cap;
  2284. int err;
  2285. char license[128];
  2286. if (CHECK_ATTR(BPF_PROG_LOAD))
  2287. return -EINVAL;
  2288. if (attr->prog_flags & ~(BPF_F_STRICT_ALIGNMENT |
  2289. BPF_F_ANY_ALIGNMENT |
  2290. BPF_F_TEST_STATE_FREQ |
  2291. BPF_F_SLEEPABLE |
  2292. BPF_F_TEST_RND_HI32 |
  2293. BPF_F_XDP_HAS_FRAGS |
  2294. BPF_F_XDP_DEV_BOUND_ONLY |
  2295. BPF_F_TEST_REG_INVARIANTS |
  2296. BPF_F_TOKEN_FD))
  2297. return -EINVAL;
  2298. bpf_prog_load_fixup_attach_type(attr);
  2299. if (attr->prog_flags & BPF_F_TOKEN_FD) {
  2300. token = bpf_token_get_from_fd(attr->prog_token_fd);
  2301. if (IS_ERR(token))
  2302. return PTR_ERR(token);
  2303. /* if current token doesn't grant prog loading permissions,
  2304. * then we can't use this token, so ignore it and rely on
  2305. * system-wide capabilities checks
  2306. */
  2307. if (!bpf_token_allow_cmd(token, BPF_PROG_LOAD) ||
  2308. !bpf_token_allow_prog_type(token, attr->prog_type,
  2309. attr->expected_attach_type)) {
  2310. bpf_token_put(token);
  2311. token = NULL;
  2312. }
  2313. }
  2314. bpf_cap = bpf_token_capable(token, CAP_BPF);
  2315. err = -EPERM;
  2316. if (!IS_ENABLED(CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS) &&
  2317. (attr->prog_flags & BPF_F_ANY_ALIGNMENT) &&
  2318. !bpf_cap)
  2319. goto put_token;
  2320. /* Intent here is for unprivileged_bpf_disabled to block BPF program
  2321. * creation for unprivileged users; other actions depend
  2322. * on fd availability and access to bpffs, so are dependent on
  2323. * object creation success. Even with unprivileged BPF disabled,
  2324. * capability checks are still carried out for these
  2325. * and other operations.
  2326. */
  2327. if (sysctl_unprivileged_bpf_disabled && !bpf_cap)
  2328. goto put_token;
  2329. if (attr->insn_cnt == 0 ||
  2330. attr->insn_cnt > (bpf_cap ? BPF_COMPLEXITY_LIMIT_INSNS : BPF_MAXINSNS)) {
  2331. err = -E2BIG;
  2332. goto put_token;
  2333. }
  2334. if (type != BPF_PROG_TYPE_SOCKET_FILTER &&
  2335. type != BPF_PROG_TYPE_CGROUP_SKB &&
  2336. !bpf_cap)
  2337. goto put_token;
  2338. if (is_net_admin_prog_type(type) && !bpf_token_capable(token, CAP_NET_ADMIN))
  2339. goto put_token;
  2340. if (is_perfmon_prog_type(type) && !bpf_token_capable(token, CAP_PERFMON))
  2341. goto put_token;
  2342. /* attach_prog_fd/attach_btf_obj_fd can specify fd of either bpf_prog
  2343. * or btf, we need to check which one it is
  2344. */
  2345. if (attr->attach_prog_fd) {
  2346. dst_prog = bpf_prog_get(attr->attach_prog_fd);
  2347. if (IS_ERR(dst_prog)) {
  2348. dst_prog = NULL;
  2349. attach_btf = btf_get_by_fd(attr->attach_btf_obj_fd);
  2350. if (IS_ERR(attach_btf)) {
  2351. err = -EINVAL;
  2352. goto put_token;
  2353. }
  2354. if (!btf_is_kernel(attach_btf)) {
  2355. /* attaching through specifying bpf_prog's BTF
  2356. * objects directly might be supported eventually
  2357. */
  2358. btf_put(attach_btf);
  2359. err = -ENOTSUPP;
  2360. goto put_token;
  2361. }
  2362. }
  2363. } else if (attr->attach_btf_id) {
  2364. /* fall back to vmlinux BTF, if BTF type ID is specified */
  2365. attach_btf = bpf_get_btf_vmlinux();
  2366. if (IS_ERR(attach_btf)) {
  2367. err = PTR_ERR(attach_btf);
  2368. goto put_token;
  2369. }
  2370. if (!attach_btf) {
  2371. err = -EINVAL;
  2372. goto put_token;
  2373. }
  2374. btf_get(attach_btf);
  2375. }
  2376. if (bpf_prog_load_check_attach(type, attr->expected_attach_type,
  2377. attach_btf, attr->attach_btf_id,
  2378. dst_prog)) {
  2379. if (dst_prog)
  2380. bpf_prog_put(dst_prog);
  2381. if (attach_btf)
  2382. btf_put(attach_btf);
  2383. err = -EINVAL;
  2384. goto put_token;
  2385. }
  2386. /* plain bpf_prog allocation */
  2387. prog = bpf_prog_alloc(bpf_prog_size(attr->insn_cnt), GFP_USER);
  2388. if (!prog) {
  2389. if (dst_prog)
  2390. bpf_prog_put(dst_prog);
  2391. if (attach_btf)
  2392. btf_put(attach_btf);
  2393. err = -EINVAL;
  2394. goto put_token;
  2395. }
  2396. prog->expected_attach_type = attr->expected_attach_type;
  2397. prog->sleepable = !!(attr->prog_flags & BPF_F_SLEEPABLE);
  2398. prog->aux->attach_btf = attach_btf;
  2399. prog->aux->attach_btf_id = attr->attach_btf_id;
  2400. prog->aux->dst_prog = dst_prog;
  2401. prog->aux->dev_bound = !!attr->prog_ifindex;
  2402. prog->aux->xdp_has_frags = attr->prog_flags & BPF_F_XDP_HAS_FRAGS;
  2403. /* move token into prog->aux, reuse taken refcnt */
  2404. prog->aux->token = token;
  2405. token = NULL;
  2406. prog->aux->user = get_current_user();
  2407. prog->len = attr->insn_cnt;
  2408. err = -EFAULT;
  2409. if (copy_from_bpfptr(prog->insns,
  2410. make_bpfptr(attr->insns, uattr.is_kernel),
  2411. bpf_prog_insn_size(prog)) != 0)
  2412. goto free_prog;
  2413. /* copy eBPF program license from user space */
  2414. if (strncpy_from_bpfptr(license,
  2415. make_bpfptr(attr->license, uattr.is_kernel),
  2416. sizeof(license) - 1) < 0)
  2417. goto free_prog;
  2418. license[sizeof(license) - 1] = 0;
  2419. /* eBPF programs must be GPL compatible to use GPL-ed functions */
  2420. prog->gpl_compatible = license_is_gpl_compatible(license) ? 1 : 0;
  2421. prog->orig_prog = NULL;
  2422. prog->jited = 0;
  2423. atomic64_set(&prog->aux->refcnt, 1);
  2424. if (bpf_prog_is_dev_bound(prog->aux)) {
  2425. err = bpf_prog_dev_bound_init(prog, attr);
  2426. if (err)
  2427. goto free_prog;
  2428. }
  2429. if (type == BPF_PROG_TYPE_EXT && dst_prog &&
  2430. bpf_prog_is_dev_bound(dst_prog->aux)) {
  2431. err = bpf_prog_dev_bound_inherit(prog, dst_prog);
  2432. if (err)
  2433. goto free_prog;
  2434. }
  2435. /*
  2436. * Bookkeeping for managing the program attachment chain.
  2437. *
  2438. * It might be tempting to set attach_tracing_prog flag at the attachment
  2439. * time, but this will not prevent from loading bunch of tracing prog
  2440. * first, then attach them one to another.
  2441. *
  2442. * The flag attach_tracing_prog is set for the whole program lifecycle, and
  2443. * doesn't have to be cleared in bpf_tracing_link_release, since tracing
  2444. * programs cannot change attachment target.
  2445. */
  2446. if (type == BPF_PROG_TYPE_TRACING && dst_prog &&
  2447. dst_prog->type == BPF_PROG_TYPE_TRACING) {
  2448. prog->aux->attach_tracing_prog = true;
  2449. }
  2450. /* find program type: socket_filter vs tracing_filter */
  2451. err = find_prog_type(type, prog);
  2452. if (err < 0)
  2453. goto free_prog;
  2454. prog->aux->load_time = ktime_get_boottime_ns();
  2455. err = bpf_obj_name_cpy(prog->aux->name, attr->prog_name,
  2456. sizeof(attr->prog_name));
  2457. if (err < 0)
  2458. goto free_prog;
  2459. err = security_bpf_prog_load(prog, attr, token);
  2460. if (err)
  2461. goto free_prog_sec;
  2462. /* run eBPF verifier */
  2463. err = bpf_check(&prog, attr, uattr, uattr_size);
  2464. if (err < 0)
  2465. goto free_used_maps;
  2466. prog = bpf_prog_select_runtime(prog, &err);
  2467. if (err < 0)
  2468. goto free_used_maps;
  2469. err = bpf_prog_alloc_id(prog);
  2470. if (err)
  2471. goto free_used_maps;
  2472. /* Upon success of bpf_prog_alloc_id(), the BPF prog is
  2473. * effectively publicly exposed. However, retrieving via
  2474. * bpf_prog_get_fd_by_id() will take another reference,
  2475. * therefore it cannot be gone underneath us.
  2476. *
  2477. * Only for the time /after/ successful bpf_prog_new_fd()
  2478. * and before returning to userspace, we might just hold
  2479. * one reference and any parallel close on that fd could
  2480. * rip everything out. Hence, below notifications must
  2481. * happen before bpf_prog_new_fd().
  2482. *
  2483. * Also, any failure handling from this point onwards must
  2484. * be using bpf_prog_put() given the program is exposed.
  2485. */
  2486. bpf_prog_kallsyms_add(prog);
  2487. perf_event_bpf_event(prog, PERF_BPF_EVENT_PROG_LOAD, 0);
  2488. bpf_audit_prog(prog, BPF_AUDIT_LOAD);
  2489. err = bpf_prog_new_fd(prog);
  2490. if (err < 0)
  2491. bpf_prog_put(prog);
  2492. return err;
  2493. free_used_maps:
  2494. /* In case we have subprogs, we need to wait for a grace
  2495. * period before we can tear down JIT memory since symbols
  2496. * are already exposed under kallsyms.
  2497. */
  2498. __bpf_prog_put_noref(prog, prog->aux->real_func_cnt);
  2499. return err;
  2500. free_prog_sec:
  2501. security_bpf_prog_free(prog);
  2502. free_prog:
  2503. free_uid(prog->aux->user);
  2504. if (prog->aux->attach_btf)
  2505. btf_put(prog->aux->attach_btf);
  2506. bpf_prog_free(prog);
  2507. put_token:
  2508. bpf_token_put(token);
  2509. return err;
  2510. }
  2511. #define BPF_OBJ_LAST_FIELD path_fd
  2512. static int bpf_obj_pin(const union bpf_attr *attr)
  2513. {
  2514. int path_fd;
  2515. if (CHECK_ATTR(BPF_OBJ) || attr->file_flags & ~BPF_F_PATH_FD)
  2516. return -EINVAL;
  2517. /* path_fd has to be accompanied by BPF_F_PATH_FD flag */
  2518. if (!(attr->file_flags & BPF_F_PATH_FD) && attr->path_fd)
  2519. return -EINVAL;
  2520. path_fd = attr->file_flags & BPF_F_PATH_FD ? attr->path_fd : AT_FDCWD;
  2521. return bpf_obj_pin_user(attr->bpf_fd, path_fd,
  2522. u64_to_user_ptr(attr->pathname));
  2523. }
  2524. static int bpf_obj_get(const union bpf_attr *attr)
  2525. {
  2526. int path_fd;
  2527. if (CHECK_ATTR(BPF_OBJ) || attr->bpf_fd != 0 ||
  2528. attr->file_flags & ~(BPF_OBJ_FLAG_MASK | BPF_F_PATH_FD))
  2529. return -EINVAL;
  2530. /* path_fd has to be accompanied by BPF_F_PATH_FD flag */
  2531. if (!(attr->file_flags & BPF_F_PATH_FD) && attr->path_fd)
  2532. return -EINVAL;
  2533. path_fd = attr->file_flags & BPF_F_PATH_FD ? attr->path_fd : AT_FDCWD;
  2534. return bpf_obj_get_user(path_fd, u64_to_user_ptr(attr->pathname),
  2535. attr->file_flags);
  2536. }
  2537. void bpf_link_init(struct bpf_link *link, enum bpf_link_type type,
  2538. const struct bpf_link_ops *ops, struct bpf_prog *prog)
  2539. {
  2540. WARN_ON(ops->dealloc && ops->dealloc_deferred);
  2541. atomic64_set(&link->refcnt, 1);
  2542. link->type = type;
  2543. link->id = 0;
  2544. link->ops = ops;
  2545. link->prog = prog;
  2546. }
  2547. static void bpf_link_free_id(int id)
  2548. {
  2549. if (!id)
  2550. return;
  2551. spin_lock_bh(&link_idr_lock);
  2552. idr_remove(&link_idr, id);
  2553. spin_unlock_bh(&link_idr_lock);
  2554. }
  2555. /* Clean up bpf_link and corresponding anon_inode file and FD. After
  2556. * anon_inode is created, bpf_link can't be just kfree()'d due to deferred
  2557. * anon_inode's release() call. This helper marks bpf_link as
  2558. * defunct, releases anon_inode file and puts reserved FD. bpf_prog's refcnt
  2559. * is not decremented, it's the responsibility of a calling code that failed
  2560. * to complete bpf_link initialization.
  2561. * This helper eventually calls link's dealloc callback, but does not call
  2562. * link's release callback.
  2563. */
  2564. void bpf_link_cleanup(struct bpf_link_primer *primer)
  2565. {
  2566. primer->link->prog = NULL;
  2567. bpf_link_free_id(primer->id);
  2568. fput(primer->file);
  2569. put_unused_fd(primer->fd);
  2570. }
  2571. void bpf_link_inc(struct bpf_link *link)
  2572. {
  2573. atomic64_inc(&link->refcnt);
  2574. }
  2575. static void bpf_link_dealloc(struct bpf_link *link)
  2576. {
  2577. /* now that we know that bpf_link itself can't be reached, put underlying BPF program */
  2578. if (link->prog)
  2579. bpf_prog_put(link->prog);
  2580. /* free bpf_link and its containing memory */
  2581. if (link->ops->dealloc_deferred)
  2582. link->ops->dealloc_deferred(link);
  2583. else
  2584. link->ops->dealloc(link);
  2585. }
  2586. static void bpf_link_defer_dealloc_rcu_gp(struct rcu_head *rcu)
  2587. {
  2588. struct bpf_link *link = container_of(rcu, struct bpf_link, rcu);
  2589. bpf_link_dealloc(link);
  2590. }
  2591. static void bpf_link_defer_dealloc_mult_rcu_gp(struct rcu_head *rcu)
  2592. {
  2593. if (rcu_trace_implies_rcu_gp())
  2594. bpf_link_defer_dealloc_rcu_gp(rcu);
  2595. else
  2596. call_rcu(rcu, bpf_link_defer_dealloc_rcu_gp);
  2597. }
  2598. /* bpf_link_free is guaranteed to be called from process context */
  2599. static void bpf_link_free(struct bpf_link *link)
  2600. {
  2601. const struct bpf_link_ops *ops = link->ops;
  2602. bool sleepable = false;
  2603. bpf_link_free_id(link->id);
  2604. if (link->prog) {
  2605. sleepable = link->prog->sleepable;
  2606. /* detach BPF program, clean up used resources */
  2607. ops->release(link);
  2608. }
  2609. if (ops->dealloc_deferred) {
  2610. /* schedule BPF link deallocation; if underlying BPF program
  2611. * is sleepable, we need to first wait for RCU tasks trace
  2612. * sync, then go through "classic" RCU grace period
  2613. */
  2614. if (sleepable)
  2615. call_rcu_tasks_trace(&link->rcu, bpf_link_defer_dealloc_mult_rcu_gp);
  2616. else
  2617. call_rcu(&link->rcu, bpf_link_defer_dealloc_rcu_gp);
  2618. } else if (ops->dealloc) {
  2619. bpf_link_dealloc(link);
  2620. }
  2621. }
  2622. static void bpf_link_put_deferred(struct work_struct *work)
  2623. {
  2624. struct bpf_link *link = container_of(work, struct bpf_link, work);
  2625. bpf_link_free(link);
  2626. }
  2627. /* bpf_link_put might be called from atomic context. It needs to be called
  2628. * from sleepable context in order to acquire sleeping locks during the process.
  2629. */
  2630. void bpf_link_put(struct bpf_link *link)
  2631. {
  2632. if (!atomic64_dec_and_test(&link->refcnt))
  2633. return;
  2634. INIT_WORK(&link->work, bpf_link_put_deferred);
  2635. schedule_work(&link->work);
  2636. }
  2637. EXPORT_SYMBOL(bpf_link_put);
  2638. static void bpf_link_put_direct(struct bpf_link *link)
  2639. {
  2640. if (!atomic64_dec_and_test(&link->refcnt))
  2641. return;
  2642. bpf_link_free(link);
  2643. }
  2644. static int bpf_link_release(struct inode *inode, struct file *filp)
  2645. {
  2646. struct bpf_link *link = filp->private_data;
  2647. bpf_link_put_direct(link);
  2648. return 0;
  2649. }
  2650. #ifdef CONFIG_PROC_FS
  2651. #define BPF_PROG_TYPE(_id, _name, prog_ctx_type, kern_ctx_type)
  2652. #define BPF_MAP_TYPE(_id, _ops)
  2653. #define BPF_LINK_TYPE(_id, _name) [_id] = #_name,
  2654. static const char *bpf_link_type_strs[] = {
  2655. [BPF_LINK_TYPE_UNSPEC] = "<invalid>",
  2656. #include <linux/bpf_types.h>
  2657. };
  2658. #undef BPF_PROG_TYPE
  2659. #undef BPF_MAP_TYPE
  2660. #undef BPF_LINK_TYPE
  2661. static void bpf_link_show_fdinfo(struct seq_file *m, struct file *filp)
  2662. {
  2663. const struct bpf_link *link = filp->private_data;
  2664. const struct bpf_prog *prog = link->prog;
  2665. enum bpf_link_type type = link->type;
  2666. char prog_tag[sizeof(prog->tag) * 2 + 1] = { };
  2667. if (type < ARRAY_SIZE(bpf_link_type_strs) && bpf_link_type_strs[type]) {
  2668. seq_printf(m, "link_type:\t%s\n", bpf_link_type_strs[type]);
  2669. } else {
  2670. WARN_ONCE(1, "missing BPF_LINK_TYPE(...) for link type %u\n", type);
  2671. seq_printf(m, "link_type:\t<%u>\n", type);
  2672. }
  2673. seq_printf(m, "link_id:\t%u\n", link->id);
  2674. if (prog) {
  2675. bin2hex(prog_tag, prog->tag, sizeof(prog->tag));
  2676. seq_printf(m,
  2677. "prog_tag:\t%s\n"
  2678. "prog_id:\t%u\n",
  2679. prog_tag,
  2680. prog->aux->id);
  2681. }
  2682. if (link->ops->show_fdinfo)
  2683. link->ops->show_fdinfo(link, m);
  2684. }
  2685. #endif
  2686. static __poll_t bpf_link_poll(struct file *file, struct poll_table_struct *pts)
  2687. {
  2688. struct bpf_link *link = file->private_data;
  2689. return link->ops->poll(file, pts);
  2690. }
  2691. static const struct file_operations bpf_link_fops = {
  2692. #ifdef CONFIG_PROC_FS
  2693. .show_fdinfo = bpf_link_show_fdinfo,
  2694. #endif
  2695. .release = bpf_link_release,
  2696. .read = bpf_dummy_read,
  2697. .write = bpf_dummy_write,
  2698. };
  2699. static const struct file_operations bpf_link_fops_poll = {
  2700. #ifdef CONFIG_PROC_FS
  2701. .show_fdinfo = bpf_link_show_fdinfo,
  2702. #endif
  2703. .release = bpf_link_release,
  2704. .read = bpf_dummy_read,
  2705. .write = bpf_dummy_write,
  2706. .poll = bpf_link_poll,
  2707. };
  2708. static int bpf_link_alloc_id(struct bpf_link *link)
  2709. {
  2710. int id;
  2711. idr_preload(GFP_KERNEL);
  2712. spin_lock_bh(&link_idr_lock);
  2713. id = idr_alloc_cyclic(&link_idr, link, 1, INT_MAX, GFP_ATOMIC);
  2714. spin_unlock_bh(&link_idr_lock);
  2715. idr_preload_end();
  2716. return id;
  2717. }
  2718. /* Prepare bpf_link to be exposed to user-space by allocating anon_inode file,
  2719. * reserving unused FD and allocating ID from link_idr. This is to be paired
  2720. * with bpf_link_settle() to install FD and ID and expose bpf_link to
  2721. * user-space, if bpf_link is successfully attached. If not, bpf_link and
  2722. * pre-allocated resources are to be freed with bpf_cleanup() call. All the
  2723. * transient state is passed around in struct bpf_link_primer.
  2724. * This is preferred way to create and initialize bpf_link, especially when
  2725. * there are complicated and expensive operations in between creating bpf_link
  2726. * itself and attaching it to BPF hook. By using bpf_link_prime() and
  2727. * bpf_link_settle() kernel code using bpf_link doesn't have to perform
  2728. * expensive (and potentially failing) roll back operations in a rare case
  2729. * that file, FD, or ID can't be allocated.
  2730. */
  2731. int bpf_link_prime(struct bpf_link *link, struct bpf_link_primer *primer)
  2732. {
  2733. struct file *file;
  2734. int fd, id;
  2735. fd = get_unused_fd_flags(O_CLOEXEC);
  2736. if (fd < 0)
  2737. return fd;
  2738. id = bpf_link_alloc_id(link);
  2739. if (id < 0) {
  2740. put_unused_fd(fd);
  2741. return id;
  2742. }
  2743. file = anon_inode_getfile("bpf_link",
  2744. link->ops->poll ? &bpf_link_fops_poll : &bpf_link_fops,
  2745. link, O_CLOEXEC);
  2746. if (IS_ERR(file)) {
  2747. bpf_link_free_id(id);
  2748. put_unused_fd(fd);
  2749. return PTR_ERR(file);
  2750. }
  2751. primer->link = link;
  2752. primer->file = file;
  2753. primer->fd = fd;
  2754. primer->id = id;
  2755. return 0;
  2756. }
  2757. int bpf_link_settle(struct bpf_link_primer *primer)
  2758. {
  2759. /* make bpf_link fetchable by ID */
  2760. spin_lock_bh(&link_idr_lock);
  2761. primer->link->id = primer->id;
  2762. spin_unlock_bh(&link_idr_lock);
  2763. /* make bpf_link fetchable by FD */
  2764. fd_install(primer->fd, primer->file);
  2765. /* pass through installed FD */
  2766. return primer->fd;
  2767. }
  2768. int bpf_link_new_fd(struct bpf_link *link)
  2769. {
  2770. return anon_inode_getfd("bpf-link",
  2771. link->ops->poll ? &bpf_link_fops_poll : &bpf_link_fops,
  2772. link, O_CLOEXEC);
  2773. }
  2774. struct bpf_link *bpf_link_get_from_fd(u32 ufd)
  2775. {
  2776. CLASS(fd, f)(ufd);
  2777. struct bpf_link *link;
  2778. if (fd_empty(f))
  2779. return ERR_PTR(-EBADF);
  2780. if (fd_file(f)->f_op != &bpf_link_fops && fd_file(f)->f_op != &bpf_link_fops_poll)
  2781. return ERR_PTR(-EINVAL);
  2782. link = fd_file(f)->private_data;
  2783. bpf_link_inc(link);
  2784. return link;
  2785. }
  2786. EXPORT_SYMBOL_NS(bpf_link_get_from_fd, BPF_INTERNAL);
  2787. static void bpf_tracing_link_release(struct bpf_link *link)
  2788. {
  2789. struct bpf_tracing_link *tr_link =
  2790. container_of(link, struct bpf_tracing_link, link.link);
  2791. WARN_ON_ONCE(bpf_trampoline_unlink_prog(&tr_link->link,
  2792. tr_link->trampoline,
  2793. tr_link->tgt_prog));
  2794. bpf_trampoline_put(tr_link->trampoline);
  2795. /* tgt_prog is NULL if target is a kernel function */
  2796. if (tr_link->tgt_prog)
  2797. bpf_prog_put(tr_link->tgt_prog);
  2798. }
  2799. static void bpf_tracing_link_dealloc(struct bpf_link *link)
  2800. {
  2801. struct bpf_tracing_link *tr_link =
  2802. container_of(link, struct bpf_tracing_link, link.link);
  2803. kfree(tr_link);
  2804. }
  2805. static void bpf_tracing_link_show_fdinfo(const struct bpf_link *link,
  2806. struct seq_file *seq)
  2807. {
  2808. struct bpf_tracing_link *tr_link =
  2809. container_of(link, struct bpf_tracing_link, link.link);
  2810. u32 target_btf_id, target_obj_id;
  2811. bpf_trampoline_unpack_key(tr_link->trampoline->key,
  2812. &target_obj_id, &target_btf_id);
  2813. seq_printf(seq,
  2814. "attach_type:\t%d\n"
  2815. "target_obj_id:\t%u\n"
  2816. "target_btf_id:\t%u\n",
  2817. tr_link->attach_type,
  2818. target_obj_id,
  2819. target_btf_id);
  2820. }
  2821. static int bpf_tracing_link_fill_link_info(const struct bpf_link *link,
  2822. struct bpf_link_info *info)
  2823. {
  2824. struct bpf_tracing_link *tr_link =
  2825. container_of(link, struct bpf_tracing_link, link.link);
  2826. info->tracing.attach_type = tr_link->attach_type;
  2827. bpf_trampoline_unpack_key(tr_link->trampoline->key,
  2828. &info->tracing.target_obj_id,
  2829. &info->tracing.target_btf_id);
  2830. return 0;
  2831. }
  2832. static const struct bpf_link_ops bpf_tracing_link_lops = {
  2833. .release = bpf_tracing_link_release,
  2834. .dealloc = bpf_tracing_link_dealloc,
  2835. .show_fdinfo = bpf_tracing_link_show_fdinfo,
  2836. .fill_link_info = bpf_tracing_link_fill_link_info,
  2837. };
  2838. static int bpf_tracing_prog_attach(struct bpf_prog *prog,
  2839. int tgt_prog_fd,
  2840. u32 btf_id,
  2841. u64 bpf_cookie)
  2842. {
  2843. struct bpf_link_primer link_primer;
  2844. struct bpf_prog *tgt_prog = NULL;
  2845. struct bpf_trampoline *tr = NULL;
  2846. struct bpf_tracing_link *link;
  2847. u64 key = 0;
  2848. int err;
  2849. switch (prog->type) {
  2850. case BPF_PROG_TYPE_TRACING:
  2851. if (prog->expected_attach_type != BPF_TRACE_FENTRY &&
  2852. prog->expected_attach_type != BPF_TRACE_FEXIT &&
  2853. prog->expected_attach_type != BPF_MODIFY_RETURN) {
  2854. err = -EINVAL;
  2855. goto out_put_prog;
  2856. }
  2857. break;
  2858. case BPF_PROG_TYPE_EXT:
  2859. if (prog->expected_attach_type != 0) {
  2860. err = -EINVAL;
  2861. goto out_put_prog;
  2862. }
  2863. break;
  2864. case BPF_PROG_TYPE_LSM:
  2865. if (prog->expected_attach_type != BPF_LSM_MAC) {
  2866. err = -EINVAL;
  2867. goto out_put_prog;
  2868. }
  2869. break;
  2870. default:
  2871. err = -EINVAL;
  2872. goto out_put_prog;
  2873. }
  2874. if (!!tgt_prog_fd != !!btf_id) {
  2875. err = -EINVAL;
  2876. goto out_put_prog;
  2877. }
  2878. if (tgt_prog_fd) {
  2879. /*
  2880. * For now we only allow new targets for BPF_PROG_TYPE_EXT. If this
  2881. * part would be changed to implement the same for
  2882. * BPF_PROG_TYPE_TRACING, do not forget to update the way how
  2883. * attach_tracing_prog flag is set.
  2884. */
  2885. if (prog->type != BPF_PROG_TYPE_EXT) {
  2886. err = -EINVAL;
  2887. goto out_put_prog;
  2888. }
  2889. tgt_prog = bpf_prog_get(tgt_prog_fd);
  2890. if (IS_ERR(tgt_prog)) {
  2891. err = PTR_ERR(tgt_prog);
  2892. tgt_prog = NULL;
  2893. goto out_put_prog;
  2894. }
  2895. key = bpf_trampoline_compute_key(tgt_prog, NULL, btf_id);
  2896. }
  2897. link = kzalloc(sizeof(*link), GFP_USER);
  2898. if (!link) {
  2899. err = -ENOMEM;
  2900. goto out_put_prog;
  2901. }
  2902. bpf_link_init(&link->link.link, BPF_LINK_TYPE_TRACING,
  2903. &bpf_tracing_link_lops, prog);
  2904. link->attach_type = prog->expected_attach_type;
  2905. link->link.cookie = bpf_cookie;
  2906. mutex_lock(&prog->aux->dst_mutex);
  2907. /* There are a few possible cases here:
  2908. *
  2909. * - if prog->aux->dst_trampoline is set, the program was just loaded
  2910. * and not yet attached to anything, so we can use the values stored
  2911. * in prog->aux
  2912. *
  2913. * - if prog->aux->dst_trampoline is NULL, the program has already been
  2914. * attached to a target and its initial target was cleared (below)
  2915. *
  2916. * - if tgt_prog != NULL, the caller specified tgt_prog_fd +
  2917. * target_btf_id using the link_create API.
  2918. *
  2919. * - if tgt_prog == NULL when this function was called using the old
  2920. * raw_tracepoint_open API, and we need a target from prog->aux
  2921. *
  2922. * - if prog->aux->dst_trampoline and tgt_prog is NULL, the program
  2923. * was detached and is going for re-attachment.
  2924. *
  2925. * - if prog->aux->dst_trampoline is NULL and tgt_prog and prog->aux->attach_btf
  2926. * are NULL, then program was already attached and user did not provide
  2927. * tgt_prog_fd so we have no way to find out or create trampoline
  2928. */
  2929. if (!prog->aux->dst_trampoline && !tgt_prog) {
  2930. /*
  2931. * Allow re-attach for TRACING and LSM programs. If it's
  2932. * currently linked, bpf_trampoline_link_prog will fail.
  2933. * EXT programs need to specify tgt_prog_fd, so they
  2934. * re-attach in separate code path.
  2935. */
  2936. if (prog->type != BPF_PROG_TYPE_TRACING &&
  2937. prog->type != BPF_PROG_TYPE_LSM) {
  2938. err = -EINVAL;
  2939. goto out_unlock;
  2940. }
  2941. /* We can allow re-attach only if we have valid attach_btf. */
  2942. if (!prog->aux->attach_btf) {
  2943. err = -EINVAL;
  2944. goto out_unlock;
  2945. }
  2946. btf_id = prog->aux->attach_btf_id;
  2947. key = bpf_trampoline_compute_key(NULL, prog->aux->attach_btf, btf_id);
  2948. }
  2949. if (!prog->aux->dst_trampoline ||
  2950. (key && key != prog->aux->dst_trampoline->key)) {
  2951. /* If there is no saved target, or the specified target is
  2952. * different from the destination specified at load time, we
  2953. * need a new trampoline and a check for compatibility
  2954. */
  2955. struct bpf_attach_target_info tgt_info = {};
  2956. err = bpf_check_attach_target(NULL, prog, tgt_prog, btf_id,
  2957. &tgt_info);
  2958. if (err)
  2959. goto out_unlock;
  2960. if (tgt_info.tgt_mod) {
  2961. module_put(prog->aux->mod);
  2962. prog->aux->mod = tgt_info.tgt_mod;
  2963. }
  2964. tr = bpf_trampoline_get(key, &tgt_info);
  2965. if (!tr) {
  2966. err = -ENOMEM;
  2967. goto out_unlock;
  2968. }
  2969. } else {
  2970. /* The caller didn't specify a target, or the target was the
  2971. * same as the destination supplied during program load. This
  2972. * means we can reuse the trampoline and reference from program
  2973. * load time, and there is no need to allocate a new one. This
  2974. * can only happen once for any program, as the saved values in
  2975. * prog->aux are cleared below.
  2976. */
  2977. tr = prog->aux->dst_trampoline;
  2978. tgt_prog = prog->aux->dst_prog;
  2979. }
  2980. err = bpf_link_prime(&link->link.link, &link_primer);
  2981. if (err)
  2982. goto out_unlock;
  2983. err = bpf_trampoline_link_prog(&link->link, tr, tgt_prog);
  2984. if (err) {
  2985. bpf_link_cleanup(&link_primer);
  2986. link = NULL;
  2987. goto out_unlock;
  2988. }
  2989. link->tgt_prog = tgt_prog;
  2990. link->trampoline = tr;
  2991. /* Always clear the trampoline and target prog from prog->aux to make
  2992. * sure the original attach destination is not kept alive after a
  2993. * program is (re-)attached to another target.
  2994. */
  2995. if (prog->aux->dst_prog &&
  2996. (tgt_prog_fd || tr != prog->aux->dst_trampoline))
  2997. /* got extra prog ref from syscall, or attaching to different prog */
  2998. bpf_prog_put(prog->aux->dst_prog);
  2999. if (prog->aux->dst_trampoline && tr != prog->aux->dst_trampoline)
  3000. /* we allocated a new trampoline, so free the old one */
  3001. bpf_trampoline_put(prog->aux->dst_trampoline);
  3002. prog->aux->dst_prog = NULL;
  3003. prog->aux->dst_trampoline = NULL;
  3004. mutex_unlock(&prog->aux->dst_mutex);
  3005. return bpf_link_settle(&link_primer);
  3006. out_unlock:
  3007. if (tr && tr != prog->aux->dst_trampoline)
  3008. bpf_trampoline_put(tr);
  3009. mutex_unlock(&prog->aux->dst_mutex);
  3010. kfree(link);
  3011. out_put_prog:
  3012. if (tgt_prog_fd && tgt_prog)
  3013. bpf_prog_put(tgt_prog);
  3014. return err;
  3015. }
  3016. static void bpf_raw_tp_link_release(struct bpf_link *link)
  3017. {
  3018. struct bpf_raw_tp_link *raw_tp =
  3019. container_of(link, struct bpf_raw_tp_link, link);
  3020. bpf_probe_unregister(raw_tp->btp, raw_tp);
  3021. bpf_put_raw_tracepoint(raw_tp->btp);
  3022. }
  3023. static void bpf_raw_tp_link_dealloc(struct bpf_link *link)
  3024. {
  3025. struct bpf_raw_tp_link *raw_tp =
  3026. container_of(link, struct bpf_raw_tp_link, link);
  3027. kfree(raw_tp);
  3028. }
  3029. static void bpf_raw_tp_link_show_fdinfo(const struct bpf_link *link,
  3030. struct seq_file *seq)
  3031. {
  3032. struct bpf_raw_tp_link *raw_tp_link =
  3033. container_of(link, struct bpf_raw_tp_link, link);
  3034. seq_printf(seq,
  3035. "tp_name:\t%s\n",
  3036. raw_tp_link->btp->tp->name);
  3037. }
  3038. static int bpf_copy_to_user(char __user *ubuf, const char *buf, u32 ulen,
  3039. u32 len)
  3040. {
  3041. if (ulen >= len + 1) {
  3042. if (copy_to_user(ubuf, buf, len + 1))
  3043. return -EFAULT;
  3044. } else {
  3045. char zero = '\0';
  3046. if (copy_to_user(ubuf, buf, ulen - 1))
  3047. return -EFAULT;
  3048. if (put_user(zero, ubuf + ulen - 1))
  3049. return -EFAULT;
  3050. return -ENOSPC;
  3051. }
  3052. return 0;
  3053. }
  3054. static int bpf_raw_tp_link_fill_link_info(const struct bpf_link *link,
  3055. struct bpf_link_info *info)
  3056. {
  3057. struct bpf_raw_tp_link *raw_tp_link =
  3058. container_of(link, struct bpf_raw_tp_link, link);
  3059. char __user *ubuf = u64_to_user_ptr(info->raw_tracepoint.tp_name);
  3060. const char *tp_name = raw_tp_link->btp->tp->name;
  3061. u32 ulen = info->raw_tracepoint.tp_name_len;
  3062. size_t tp_len = strlen(tp_name);
  3063. if (!ulen ^ !ubuf)
  3064. return -EINVAL;
  3065. info->raw_tracepoint.tp_name_len = tp_len + 1;
  3066. if (!ubuf)
  3067. return 0;
  3068. return bpf_copy_to_user(ubuf, tp_name, ulen, tp_len);
  3069. }
  3070. static const struct bpf_link_ops bpf_raw_tp_link_lops = {
  3071. .release = bpf_raw_tp_link_release,
  3072. .dealloc_deferred = bpf_raw_tp_link_dealloc,
  3073. .show_fdinfo = bpf_raw_tp_link_show_fdinfo,
  3074. .fill_link_info = bpf_raw_tp_link_fill_link_info,
  3075. };
  3076. #ifdef CONFIG_PERF_EVENTS
  3077. struct bpf_perf_link {
  3078. struct bpf_link link;
  3079. struct file *perf_file;
  3080. };
  3081. static void bpf_perf_link_release(struct bpf_link *link)
  3082. {
  3083. struct bpf_perf_link *perf_link = container_of(link, struct bpf_perf_link, link);
  3084. struct perf_event *event = perf_link->perf_file->private_data;
  3085. perf_event_free_bpf_prog(event);
  3086. fput(perf_link->perf_file);
  3087. }
  3088. static void bpf_perf_link_dealloc(struct bpf_link *link)
  3089. {
  3090. struct bpf_perf_link *perf_link = container_of(link, struct bpf_perf_link, link);
  3091. kfree(perf_link);
  3092. }
  3093. static int bpf_perf_link_fill_common(const struct perf_event *event,
  3094. char __user *uname, u32 *ulenp,
  3095. u64 *probe_offset, u64 *probe_addr,
  3096. u32 *fd_type, unsigned long *missed)
  3097. {
  3098. const char *buf;
  3099. u32 prog_id, ulen;
  3100. size_t len;
  3101. int err;
  3102. ulen = *ulenp;
  3103. if (!ulen ^ !uname)
  3104. return -EINVAL;
  3105. err = bpf_get_perf_event_info(event, &prog_id, fd_type, &buf,
  3106. probe_offset, probe_addr, missed);
  3107. if (err)
  3108. return err;
  3109. if (buf) {
  3110. len = strlen(buf);
  3111. *ulenp = len + 1;
  3112. } else {
  3113. *ulenp = 1;
  3114. }
  3115. if (!uname)
  3116. return 0;
  3117. if (buf) {
  3118. err = bpf_copy_to_user(uname, buf, ulen, len);
  3119. if (err)
  3120. return err;
  3121. } else {
  3122. char zero = '\0';
  3123. if (put_user(zero, uname))
  3124. return -EFAULT;
  3125. }
  3126. return 0;
  3127. }
  3128. #ifdef CONFIG_KPROBE_EVENTS
  3129. static int bpf_perf_link_fill_kprobe(const struct perf_event *event,
  3130. struct bpf_link_info *info)
  3131. {
  3132. unsigned long missed;
  3133. char __user *uname;
  3134. u64 addr, offset;
  3135. u32 ulen, type;
  3136. int err;
  3137. uname = u64_to_user_ptr(info->perf_event.kprobe.func_name);
  3138. ulen = info->perf_event.kprobe.name_len;
  3139. err = bpf_perf_link_fill_common(event, uname, &ulen, &offset, &addr,
  3140. &type, &missed);
  3141. if (err)
  3142. return err;
  3143. if (type == BPF_FD_TYPE_KRETPROBE)
  3144. info->perf_event.type = BPF_PERF_EVENT_KRETPROBE;
  3145. else
  3146. info->perf_event.type = BPF_PERF_EVENT_KPROBE;
  3147. info->perf_event.kprobe.name_len = ulen;
  3148. info->perf_event.kprobe.offset = offset;
  3149. info->perf_event.kprobe.missed = missed;
  3150. if (!kallsyms_show_value(current_cred()))
  3151. addr = 0;
  3152. info->perf_event.kprobe.addr = addr;
  3153. info->perf_event.kprobe.cookie = event->bpf_cookie;
  3154. return 0;
  3155. }
  3156. #endif
  3157. #ifdef CONFIG_UPROBE_EVENTS
  3158. static int bpf_perf_link_fill_uprobe(const struct perf_event *event,
  3159. struct bpf_link_info *info)
  3160. {
  3161. char __user *uname;
  3162. u64 addr, offset;
  3163. u32 ulen, type;
  3164. int err;
  3165. uname = u64_to_user_ptr(info->perf_event.uprobe.file_name);
  3166. ulen = info->perf_event.uprobe.name_len;
  3167. err = bpf_perf_link_fill_common(event, uname, &ulen, &offset, &addr,
  3168. &type, NULL);
  3169. if (err)
  3170. return err;
  3171. if (type == BPF_FD_TYPE_URETPROBE)
  3172. info->perf_event.type = BPF_PERF_EVENT_URETPROBE;
  3173. else
  3174. info->perf_event.type = BPF_PERF_EVENT_UPROBE;
  3175. info->perf_event.uprobe.name_len = ulen;
  3176. info->perf_event.uprobe.offset = offset;
  3177. info->perf_event.uprobe.cookie = event->bpf_cookie;
  3178. return 0;
  3179. }
  3180. #endif
  3181. static int bpf_perf_link_fill_probe(const struct perf_event *event,
  3182. struct bpf_link_info *info)
  3183. {
  3184. #ifdef CONFIG_KPROBE_EVENTS
  3185. if (event->tp_event->flags & TRACE_EVENT_FL_KPROBE)
  3186. return bpf_perf_link_fill_kprobe(event, info);
  3187. #endif
  3188. #ifdef CONFIG_UPROBE_EVENTS
  3189. if (event->tp_event->flags & TRACE_EVENT_FL_UPROBE)
  3190. return bpf_perf_link_fill_uprobe(event, info);
  3191. #endif
  3192. return -EOPNOTSUPP;
  3193. }
  3194. static int bpf_perf_link_fill_tracepoint(const struct perf_event *event,
  3195. struct bpf_link_info *info)
  3196. {
  3197. char __user *uname;
  3198. u32 ulen;
  3199. int err;
  3200. uname = u64_to_user_ptr(info->perf_event.tracepoint.tp_name);
  3201. ulen = info->perf_event.tracepoint.name_len;
  3202. err = bpf_perf_link_fill_common(event, uname, &ulen, NULL, NULL, NULL, NULL);
  3203. if (err)
  3204. return err;
  3205. info->perf_event.type = BPF_PERF_EVENT_TRACEPOINT;
  3206. info->perf_event.tracepoint.name_len = ulen;
  3207. info->perf_event.tracepoint.cookie = event->bpf_cookie;
  3208. return 0;
  3209. }
  3210. static int bpf_perf_link_fill_perf_event(const struct perf_event *event,
  3211. struct bpf_link_info *info)
  3212. {
  3213. info->perf_event.event.type = event->attr.type;
  3214. info->perf_event.event.config = event->attr.config;
  3215. info->perf_event.event.cookie = event->bpf_cookie;
  3216. info->perf_event.type = BPF_PERF_EVENT_EVENT;
  3217. return 0;
  3218. }
  3219. static int bpf_perf_link_fill_link_info(const struct bpf_link *link,
  3220. struct bpf_link_info *info)
  3221. {
  3222. struct bpf_perf_link *perf_link;
  3223. const struct perf_event *event;
  3224. perf_link = container_of(link, struct bpf_perf_link, link);
  3225. event = perf_get_event(perf_link->perf_file);
  3226. if (IS_ERR(event))
  3227. return PTR_ERR(event);
  3228. switch (event->prog->type) {
  3229. case BPF_PROG_TYPE_PERF_EVENT:
  3230. return bpf_perf_link_fill_perf_event(event, info);
  3231. case BPF_PROG_TYPE_TRACEPOINT:
  3232. return bpf_perf_link_fill_tracepoint(event, info);
  3233. case BPF_PROG_TYPE_KPROBE:
  3234. return bpf_perf_link_fill_probe(event, info);
  3235. default:
  3236. return -EOPNOTSUPP;
  3237. }
  3238. }
  3239. static const struct bpf_link_ops bpf_perf_link_lops = {
  3240. .release = bpf_perf_link_release,
  3241. .dealloc = bpf_perf_link_dealloc,
  3242. .fill_link_info = bpf_perf_link_fill_link_info,
  3243. };
  3244. static int bpf_perf_link_attach(const union bpf_attr *attr, struct bpf_prog *prog)
  3245. {
  3246. struct bpf_link_primer link_primer;
  3247. struct bpf_perf_link *link;
  3248. struct perf_event *event;
  3249. struct file *perf_file;
  3250. int err;
  3251. if (attr->link_create.flags)
  3252. return -EINVAL;
  3253. perf_file = perf_event_get(attr->link_create.target_fd);
  3254. if (IS_ERR(perf_file))
  3255. return PTR_ERR(perf_file);
  3256. link = kzalloc(sizeof(*link), GFP_USER);
  3257. if (!link) {
  3258. err = -ENOMEM;
  3259. goto out_put_file;
  3260. }
  3261. bpf_link_init(&link->link, BPF_LINK_TYPE_PERF_EVENT, &bpf_perf_link_lops, prog);
  3262. link->perf_file = perf_file;
  3263. err = bpf_link_prime(&link->link, &link_primer);
  3264. if (err) {
  3265. kfree(link);
  3266. goto out_put_file;
  3267. }
  3268. event = perf_file->private_data;
  3269. err = perf_event_set_bpf_prog(event, prog, attr->link_create.perf_event.bpf_cookie);
  3270. if (err) {
  3271. bpf_link_cleanup(&link_primer);
  3272. goto out_put_file;
  3273. }
  3274. /* perf_event_set_bpf_prog() doesn't take its own refcnt on prog */
  3275. bpf_prog_inc(prog);
  3276. return bpf_link_settle(&link_primer);
  3277. out_put_file:
  3278. fput(perf_file);
  3279. return err;
  3280. }
  3281. #else
  3282. static int bpf_perf_link_attach(const union bpf_attr *attr, struct bpf_prog *prog)
  3283. {
  3284. return -EOPNOTSUPP;
  3285. }
  3286. #endif /* CONFIG_PERF_EVENTS */
  3287. static int bpf_raw_tp_link_attach(struct bpf_prog *prog,
  3288. const char __user *user_tp_name, u64 cookie)
  3289. {
  3290. struct bpf_link_primer link_primer;
  3291. struct bpf_raw_tp_link *link;
  3292. struct bpf_raw_event_map *btp;
  3293. const char *tp_name;
  3294. char buf[128];
  3295. int err;
  3296. switch (prog->type) {
  3297. case BPF_PROG_TYPE_TRACING:
  3298. case BPF_PROG_TYPE_EXT:
  3299. case BPF_PROG_TYPE_LSM:
  3300. if (user_tp_name)
  3301. /* The attach point for this category of programs
  3302. * should be specified via btf_id during program load.
  3303. */
  3304. return -EINVAL;
  3305. if (prog->type == BPF_PROG_TYPE_TRACING &&
  3306. prog->expected_attach_type == BPF_TRACE_RAW_TP) {
  3307. tp_name = prog->aux->attach_func_name;
  3308. break;
  3309. }
  3310. return bpf_tracing_prog_attach(prog, 0, 0, 0);
  3311. case BPF_PROG_TYPE_RAW_TRACEPOINT:
  3312. case BPF_PROG_TYPE_RAW_TRACEPOINT_WRITABLE:
  3313. if (strncpy_from_user(buf, user_tp_name, sizeof(buf) - 1) < 0)
  3314. return -EFAULT;
  3315. buf[sizeof(buf) - 1] = 0;
  3316. tp_name = buf;
  3317. break;
  3318. default:
  3319. return -EINVAL;
  3320. }
  3321. btp = bpf_get_raw_tracepoint(tp_name);
  3322. if (!btp)
  3323. return -ENOENT;
  3324. link = kzalloc(sizeof(*link), GFP_USER);
  3325. if (!link) {
  3326. err = -ENOMEM;
  3327. goto out_put_btp;
  3328. }
  3329. bpf_link_init(&link->link, BPF_LINK_TYPE_RAW_TRACEPOINT,
  3330. &bpf_raw_tp_link_lops, prog);
  3331. link->btp = btp;
  3332. link->cookie = cookie;
  3333. err = bpf_link_prime(&link->link, &link_primer);
  3334. if (err) {
  3335. kfree(link);
  3336. goto out_put_btp;
  3337. }
  3338. err = bpf_probe_register(link->btp, link);
  3339. if (err) {
  3340. bpf_link_cleanup(&link_primer);
  3341. goto out_put_btp;
  3342. }
  3343. return bpf_link_settle(&link_primer);
  3344. out_put_btp:
  3345. bpf_put_raw_tracepoint(btp);
  3346. return err;
  3347. }
  3348. #define BPF_RAW_TRACEPOINT_OPEN_LAST_FIELD raw_tracepoint.cookie
  3349. static int bpf_raw_tracepoint_open(const union bpf_attr *attr)
  3350. {
  3351. struct bpf_prog *prog;
  3352. void __user *tp_name;
  3353. __u64 cookie;
  3354. int fd;
  3355. if (CHECK_ATTR(BPF_RAW_TRACEPOINT_OPEN))
  3356. return -EINVAL;
  3357. prog = bpf_prog_get(attr->raw_tracepoint.prog_fd);
  3358. if (IS_ERR(prog))
  3359. return PTR_ERR(prog);
  3360. tp_name = u64_to_user_ptr(attr->raw_tracepoint.name);
  3361. cookie = attr->raw_tracepoint.cookie;
  3362. fd = bpf_raw_tp_link_attach(prog, tp_name, cookie);
  3363. if (fd < 0)
  3364. bpf_prog_put(prog);
  3365. return fd;
  3366. }
  3367. static enum bpf_prog_type
  3368. attach_type_to_prog_type(enum bpf_attach_type attach_type)
  3369. {
  3370. switch (attach_type) {
  3371. case BPF_CGROUP_INET_INGRESS:
  3372. case BPF_CGROUP_INET_EGRESS:
  3373. return BPF_PROG_TYPE_CGROUP_SKB;
  3374. case BPF_CGROUP_INET_SOCK_CREATE:
  3375. case BPF_CGROUP_INET_SOCK_RELEASE:
  3376. case BPF_CGROUP_INET4_POST_BIND:
  3377. case BPF_CGROUP_INET6_POST_BIND:
  3378. return BPF_PROG_TYPE_CGROUP_SOCK;
  3379. case BPF_CGROUP_INET4_BIND:
  3380. case BPF_CGROUP_INET6_BIND:
  3381. case BPF_CGROUP_INET4_CONNECT:
  3382. case BPF_CGROUP_INET6_CONNECT:
  3383. case BPF_CGROUP_UNIX_CONNECT:
  3384. case BPF_CGROUP_INET4_GETPEERNAME:
  3385. case BPF_CGROUP_INET6_GETPEERNAME:
  3386. case BPF_CGROUP_UNIX_GETPEERNAME:
  3387. case BPF_CGROUP_INET4_GETSOCKNAME:
  3388. case BPF_CGROUP_INET6_GETSOCKNAME:
  3389. case BPF_CGROUP_UNIX_GETSOCKNAME:
  3390. case BPF_CGROUP_UDP4_SENDMSG:
  3391. case BPF_CGROUP_UDP6_SENDMSG:
  3392. case BPF_CGROUP_UNIX_SENDMSG:
  3393. case BPF_CGROUP_UDP4_RECVMSG:
  3394. case BPF_CGROUP_UDP6_RECVMSG:
  3395. case BPF_CGROUP_UNIX_RECVMSG:
  3396. return BPF_PROG_TYPE_CGROUP_SOCK_ADDR;
  3397. case BPF_CGROUP_SOCK_OPS:
  3398. return BPF_PROG_TYPE_SOCK_OPS;
  3399. case BPF_CGROUP_DEVICE:
  3400. return BPF_PROG_TYPE_CGROUP_DEVICE;
  3401. case BPF_SK_MSG_VERDICT:
  3402. return BPF_PROG_TYPE_SK_MSG;
  3403. case BPF_SK_SKB_STREAM_PARSER:
  3404. case BPF_SK_SKB_STREAM_VERDICT:
  3405. case BPF_SK_SKB_VERDICT:
  3406. return BPF_PROG_TYPE_SK_SKB;
  3407. case BPF_LIRC_MODE2:
  3408. return BPF_PROG_TYPE_LIRC_MODE2;
  3409. case BPF_FLOW_DISSECTOR:
  3410. return BPF_PROG_TYPE_FLOW_DISSECTOR;
  3411. case BPF_CGROUP_SYSCTL:
  3412. return BPF_PROG_TYPE_CGROUP_SYSCTL;
  3413. case BPF_CGROUP_GETSOCKOPT:
  3414. case BPF_CGROUP_SETSOCKOPT:
  3415. return BPF_PROG_TYPE_CGROUP_SOCKOPT;
  3416. case BPF_TRACE_ITER:
  3417. case BPF_TRACE_RAW_TP:
  3418. case BPF_TRACE_FENTRY:
  3419. case BPF_TRACE_FEXIT:
  3420. case BPF_MODIFY_RETURN:
  3421. return BPF_PROG_TYPE_TRACING;
  3422. case BPF_LSM_MAC:
  3423. return BPF_PROG_TYPE_LSM;
  3424. case BPF_SK_LOOKUP:
  3425. return BPF_PROG_TYPE_SK_LOOKUP;
  3426. case BPF_XDP:
  3427. return BPF_PROG_TYPE_XDP;
  3428. case BPF_LSM_CGROUP:
  3429. return BPF_PROG_TYPE_LSM;
  3430. case BPF_TCX_INGRESS:
  3431. case BPF_TCX_EGRESS:
  3432. case BPF_NETKIT_PRIMARY:
  3433. case BPF_NETKIT_PEER:
  3434. return BPF_PROG_TYPE_SCHED_CLS;
  3435. default:
  3436. return BPF_PROG_TYPE_UNSPEC;
  3437. }
  3438. }
  3439. static int bpf_prog_attach_check_attach_type(const struct bpf_prog *prog,
  3440. enum bpf_attach_type attach_type)
  3441. {
  3442. enum bpf_prog_type ptype;
  3443. switch (prog->type) {
  3444. case BPF_PROG_TYPE_CGROUP_SOCK:
  3445. case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
  3446. case BPF_PROG_TYPE_CGROUP_SOCKOPT:
  3447. case BPF_PROG_TYPE_SK_LOOKUP:
  3448. return attach_type == prog->expected_attach_type ? 0 : -EINVAL;
  3449. case BPF_PROG_TYPE_CGROUP_SKB:
  3450. if (!bpf_token_capable(prog->aux->token, CAP_NET_ADMIN))
  3451. /* cg-skb progs can be loaded by unpriv user.
  3452. * check permissions at attach time.
  3453. */
  3454. return -EPERM;
  3455. ptype = attach_type_to_prog_type(attach_type);
  3456. if (prog->type != ptype)
  3457. return -EINVAL;
  3458. return prog->enforce_expected_attach_type &&
  3459. prog->expected_attach_type != attach_type ?
  3460. -EINVAL : 0;
  3461. case BPF_PROG_TYPE_EXT:
  3462. return 0;
  3463. case BPF_PROG_TYPE_NETFILTER:
  3464. if (attach_type != BPF_NETFILTER)
  3465. return -EINVAL;
  3466. return 0;
  3467. case BPF_PROG_TYPE_PERF_EVENT:
  3468. case BPF_PROG_TYPE_TRACEPOINT:
  3469. if (attach_type != BPF_PERF_EVENT)
  3470. return -EINVAL;
  3471. return 0;
  3472. case BPF_PROG_TYPE_KPROBE:
  3473. if (prog->expected_attach_type == BPF_TRACE_KPROBE_MULTI &&
  3474. attach_type != BPF_TRACE_KPROBE_MULTI)
  3475. return -EINVAL;
  3476. if (prog->expected_attach_type == BPF_TRACE_KPROBE_SESSION &&
  3477. attach_type != BPF_TRACE_KPROBE_SESSION)
  3478. return -EINVAL;
  3479. if (prog->expected_attach_type == BPF_TRACE_UPROBE_MULTI &&
  3480. attach_type != BPF_TRACE_UPROBE_MULTI)
  3481. return -EINVAL;
  3482. if (attach_type != BPF_PERF_EVENT &&
  3483. attach_type != BPF_TRACE_KPROBE_MULTI &&
  3484. attach_type != BPF_TRACE_KPROBE_SESSION &&
  3485. attach_type != BPF_TRACE_UPROBE_MULTI)
  3486. return -EINVAL;
  3487. return 0;
  3488. case BPF_PROG_TYPE_SCHED_CLS:
  3489. if (attach_type != BPF_TCX_INGRESS &&
  3490. attach_type != BPF_TCX_EGRESS &&
  3491. attach_type != BPF_NETKIT_PRIMARY &&
  3492. attach_type != BPF_NETKIT_PEER)
  3493. return -EINVAL;
  3494. return 0;
  3495. default:
  3496. ptype = attach_type_to_prog_type(attach_type);
  3497. if (ptype == BPF_PROG_TYPE_UNSPEC || ptype != prog->type)
  3498. return -EINVAL;
  3499. return 0;
  3500. }
  3501. }
  3502. #define BPF_PROG_ATTACH_LAST_FIELD expected_revision
  3503. #define BPF_F_ATTACH_MASK_BASE \
  3504. (BPF_F_ALLOW_OVERRIDE | \
  3505. BPF_F_ALLOW_MULTI | \
  3506. BPF_F_REPLACE | \
  3507. BPF_F_PREORDER)
  3508. #define BPF_F_ATTACH_MASK_MPROG \
  3509. (BPF_F_REPLACE | \
  3510. BPF_F_BEFORE | \
  3511. BPF_F_AFTER | \
  3512. BPF_F_ID | \
  3513. BPF_F_LINK)
  3514. static int bpf_prog_attach(const union bpf_attr *attr)
  3515. {
  3516. enum bpf_prog_type ptype;
  3517. struct bpf_prog *prog;
  3518. int ret;
  3519. if (CHECK_ATTR(BPF_PROG_ATTACH))
  3520. return -EINVAL;
  3521. ptype = attach_type_to_prog_type(attr->attach_type);
  3522. if (ptype == BPF_PROG_TYPE_UNSPEC)
  3523. return -EINVAL;
  3524. if (bpf_mprog_supported(ptype)) {
  3525. if (attr->attach_flags & ~BPF_F_ATTACH_MASK_MPROG)
  3526. return -EINVAL;
  3527. } else {
  3528. if (attr->attach_flags & ~BPF_F_ATTACH_MASK_BASE)
  3529. return -EINVAL;
  3530. if (attr->relative_fd ||
  3531. attr->expected_revision)
  3532. return -EINVAL;
  3533. }
  3534. prog = bpf_prog_get_type(attr->attach_bpf_fd, ptype);
  3535. if (IS_ERR(prog))
  3536. return PTR_ERR(prog);
  3537. if (bpf_prog_attach_check_attach_type(prog, attr->attach_type)) {
  3538. bpf_prog_put(prog);
  3539. return -EINVAL;
  3540. }
  3541. switch (ptype) {
  3542. case BPF_PROG_TYPE_SK_SKB:
  3543. case BPF_PROG_TYPE_SK_MSG:
  3544. ret = sock_map_get_from_fd(attr, prog);
  3545. break;
  3546. case BPF_PROG_TYPE_LIRC_MODE2:
  3547. ret = lirc_prog_attach(attr, prog);
  3548. break;
  3549. case BPF_PROG_TYPE_FLOW_DISSECTOR:
  3550. ret = netns_bpf_prog_attach(attr, prog);
  3551. break;
  3552. case BPF_PROG_TYPE_CGROUP_DEVICE:
  3553. case BPF_PROG_TYPE_CGROUP_SKB:
  3554. case BPF_PROG_TYPE_CGROUP_SOCK:
  3555. case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
  3556. case BPF_PROG_TYPE_CGROUP_SOCKOPT:
  3557. case BPF_PROG_TYPE_CGROUP_SYSCTL:
  3558. case BPF_PROG_TYPE_SOCK_OPS:
  3559. case BPF_PROG_TYPE_LSM:
  3560. if (ptype == BPF_PROG_TYPE_LSM &&
  3561. prog->expected_attach_type != BPF_LSM_CGROUP)
  3562. ret = -EINVAL;
  3563. else
  3564. ret = cgroup_bpf_prog_attach(attr, ptype, prog);
  3565. break;
  3566. case BPF_PROG_TYPE_SCHED_CLS:
  3567. if (attr->attach_type == BPF_TCX_INGRESS ||
  3568. attr->attach_type == BPF_TCX_EGRESS)
  3569. ret = tcx_prog_attach(attr, prog);
  3570. else
  3571. ret = netkit_prog_attach(attr, prog);
  3572. break;
  3573. default:
  3574. ret = -EINVAL;
  3575. }
  3576. if (ret)
  3577. bpf_prog_put(prog);
  3578. return ret;
  3579. }
  3580. #define BPF_PROG_DETACH_LAST_FIELD expected_revision
  3581. static int bpf_prog_detach(const union bpf_attr *attr)
  3582. {
  3583. struct bpf_prog *prog = NULL;
  3584. enum bpf_prog_type ptype;
  3585. int ret;
  3586. if (CHECK_ATTR(BPF_PROG_DETACH))
  3587. return -EINVAL;
  3588. ptype = attach_type_to_prog_type(attr->attach_type);
  3589. if (bpf_mprog_supported(ptype)) {
  3590. if (ptype == BPF_PROG_TYPE_UNSPEC)
  3591. return -EINVAL;
  3592. if (attr->attach_flags & ~BPF_F_ATTACH_MASK_MPROG)
  3593. return -EINVAL;
  3594. if (attr->attach_bpf_fd) {
  3595. prog = bpf_prog_get_type(attr->attach_bpf_fd, ptype);
  3596. if (IS_ERR(prog))
  3597. return PTR_ERR(prog);
  3598. }
  3599. } else if (attr->attach_flags ||
  3600. attr->relative_fd ||
  3601. attr->expected_revision) {
  3602. return -EINVAL;
  3603. }
  3604. switch (ptype) {
  3605. case BPF_PROG_TYPE_SK_MSG:
  3606. case BPF_PROG_TYPE_SK_SKB:
  3607. ret = sock_map_prog_detach(attr, ptype);
  3608. break;
  3609. case BPF_PROG_TYPE_LIRC_MODE2:
  3610. ret = lirc_prog_detach(attr);
  3611. break;
  3612. case BPF_PROG_TYPE_FLOW_DISSECTOR:
  3613. ret = netns_bpf_prog_detach(attr, ptype);
  3614. break;
  3615. case BPF_PROG_TYPE_CGROUP_DEVICE:
  3616. case BPF_PROG_TYPE_CGROUP_SKB:
  3617. case BPF_PROG_TYPE_CGROUP_SOCK:
  3618. case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
  3619. case BPF_PROG_TYPE_CGROUP_SOCKOPT:
  3620. case BPF_PROG_TYPE_CGROUP_SYSCTL:
  3621. case BPF_PROG_TYPE_SOCK_OPS:
  3622. case BPF_PROG_TYPE_LSM:
  3623. ret = cgroup_bpf_prog_detach(attr, ptype);
  3624. break;
  3625. case BPF_PROG_TYPE_SCHED_CLS:
  3626. if (attr->attach_type == BPF_TCX_INGRESS ||
  3627. attr->attach_type == BPF_TCX_EGRESS)
  3628. ret = tcx_prog_detach(attr, prog);
  3629. else
  3630. ret = netkit_prog_detach(attr, prog);
  3631. break;
  3632. default:
  3633. ret = -EINVAL;
  3634. }
  3635. if (prog)
  3636. bpf_prog_put(prog);
  3637. return ret;
  3638. }
  3639. #define BPF_PROG_QUERY_LAST_FIELD query.revision
  3640. static int bpf_prog_query(const union bpf_attr *attr,
  3641. union bpf_attr __user *uattr)
  3642. {
  3643. if (!bpf_net_capable())
  3644. return -EPERM;
  3645. if (CHECK_ATTR(BPF_PROG_QUERY))
  3646. return -EINVAL;
  3647. if (attr->query.query_flags & ~BPF_F_QUERY_EFFECTIVE)
  3648. return -EINVAL;
  3649. switch (attr->query.attach_type) {
  3650. case BPF_CGROUP_INET_INGRESS:
  3651. case BPF_CGROUP_INET_EGRESS:
  3652. case BPF_CGROUP_INET_SOCK_CREATE:
  3653. case BPF_CGROUP_INET_SOCK_RELEASE:
  3654. case BPF_CGROUP_INET4_BIND:
  3655. case BPF_CGROUP_INET6_BIND:
  3656. case BPF_CGROUP_INET4_POST_BIND:
  3657. case BPF_CGROUP_INET6_POST_BIND:
  3658. case BPF_CGROUP_INET4_CONNECT:
  3659. case BPF_CGROUP_INET6_CONNECT:
  3660. case BPF_CGROUP_UNIX_CONNECT:
  3661. case BPF_CGROUP_INET4_GETPEERNAME:
  3662. case BPF_CGROUP_INET6_GETPEERNAME:
  3663. case BPF_CGROUP_UNIX_GETPEERNAME:
  3664. case BPF_CGROUP_INET4_GETSOCKNAME:
  3665. case BPF_CGROUP_INET6_GETSOCKNAME:
  3666. case BPF_CGROUP_UNIX_GETSOCKNAME:
  3667. case BPF_CGROUP_UDP4_SENDMSG:
  3668. case BPF_CGROUP_UDP6_SENDMSG:
  3669. case BPF_CGROUP_UNIX_SENDMSG:
  3670. case BPF_CGROUP_UDP4_RECVMSG:
  3671. case BPF_CGROUP_UDP6_RECVMSG:
  3672. case BPF_CGROUP_UNIX_RECVMSG:
  3673. case BPF_CGROUP_SOCK_OPS:
  3674. case BPF_CGROUP_DEVICE:
  3675. case BPF_CGROUP_SYSCTL:
  3676. case BPF_CGROUP_GETSOCKOPT:
  3677. case BPF_CGROUP_SETSOCKOPT:
  3678. case BPF_LSM_CGROUP:
  3679. return cgroup_bpf_prog_query(attr, uattr);
  3680. case BPF_LIRC_MODE2:
  3681. return lirc_prog_query(attr, uattr);
  3682. case BPF_FLOW_DISSECTOR:
  3683. case BPF_SK_LOOKUP:
  3684. return netns_bpf_prog_query(attr, uattr);
  3685. case BPF_SK_SKB_STREAM_PARSER:
  3686. case BPF_SK_SKB_STREAM_VERDICT:
  3687. case BPF_SK_MSG_VERDICT:
  3688. case BPF_SK_SKB_VERDICT:
  3689. return sock_map_bpf_prog_query(attr, uattr);
  3690. case BPF_TCX_INGRESS:
  3691. case BPF_TCX_EGRESS:
  3692. return tcx_prog_query(attr, uattr);
  3693. case BPF_NETKIT_PRIMARY:
  3694. case BPF_NETKIT_PEER:
  3695. return netkit_prog_query(attr, uattr);
  3696. default:
  3697. return -EINVAL;
  3698. }
  3699. }
  3700. #define BPF_PROG_TEST_RUN_LAST_FIELD test.batch_size
  3701. static int bpf_prog_test_run(const union bpf_attr *attr,
  3702. union bpf_attr __user *uattr)
  3703. {
  3704. struct bpf_prog *prog;
  3705. int ret = -ENOTSUPP;
  3706. if (CHECK_ATTR(BPF_PROG_TEST_RUN))
  3707. return -EINVAL;
  3708. if ((attr->test.ctx_size_in && !attr->test.ctx_in) ||
  3709. (!attr->test.ctx_size_in && attr->test.ctx_in))
  3710. return -EINVAL;
  3711. if ((attr->test.ctx_size_out && !attr->test.ctx_out) ||
  3712. (!attr->test.ctx_size_out && attr->test.ctx_out))
  3713. return -EINVAL;
  3714. prog = bpf_prog_get(attr->test.prog_fd);
  3715. if (IS_ERR(prog))
  3716. return PTR_ERR(prog);
  3717. if (prog->aux->ops->test_run)
  3718. ret = prog->aux->ops->test_run(prog, attr, uattr);
  3719. bpf_prog_put(prog);
  3720. return ret;
  3721. }
  3722. #define BPF_OBJ_GET_NEXT_ID_LAST_FIELD next_id
  3723. static int bpf_obj_get_next_id(const union bpf_attr *attr,
  3724. union bpf_attr __user *uattr,
  3725. struct idr *idr,
  3726. spinlock_t *lock)
  3727. {
  3728. u32 next_id = attr->start_id;
  3729. int err = 0;
  3730. if (CHECK_ATTR(BPF_OBJ_GET_NEXT_ID) || next_id >= INT_MAX)
  3731. return -EINVAL;
  3732. if (!capable(CAP_SYS_ADMIN))
  3733. return -EPERM;
  3734. next_id++;
  3735. spin_lock_bh(lock);
  3736. if (!idr_get_next(idr, &next_id))
  3737. err = -ENOENT;
  3738. spin_unlock_bh(lock);
  3739. if (!err)
  3740. err = put_user(next_id, &uattr->next_id);
  3741. return err;
  3742. }
  3743. struct bpf_map *bpf_map_get_curr_or_next(u32 *id)
  3744. {
  3745. struct bpf_map *map;
  3746. spin_lock_bh(&map_idr_lock);
  3747. again:
  3748. map = idr_get_next(&map_idr, id);
  3749. if (map) {
  3750. map = __bpf_map_inc_not_zero(map, false);
  3751. if (IS_ERR(map)) {
  3752. (*id)++;
  3753. goto again;
  3754. }
  3755. }
  3756. spin_unlock_bh(&map_idr_lock);
  3757. return map;
  3758. }
  3759. struct bpf_prog *bpf_prog_get_curr_or_next(u32 *id)
  3760. {
  3761. struct bpf_prog *prog;
  3762. spin_lock_bh(&prog_idr_lock);
  3763. again:
  3764. prog = idr_get_next(&prog_idr, id);
  3765. if (prog) {
  3766. prog = bpf_prog_inc_not_zero(prog);
  3767. if (IS_ERR(prog)) {
  3768. (*id)++;
  3769. goto again;
  3770. }
  3771. }
  3772. spin_unlock_bh(&prog_idr_lock);
  3773. return prog;
  3774. }
  3775. #define BPF_PROG_GET_FD_BY_ID_LAST_FIELD prog_id
  3776. struct bpf_prog *bpf_prog_by_id(u32 id)
  3777. {
  3778. struct bpf_prog *prog;
  3779. if (!id)
  3780. return ERR_PTR(-ENOENT);
  3781. spin_lock_bh(&prog_idr_lock);
  3782. prog = idr_find(&prog_idr, id);
  3783. if (prog)
  3784. prog = bpf_prog_inc_not_zero(prog);
  3785. else
  3786. prog = ERR_PTR(-ENOENT);
  3787. spin_unlock_bh(&prog_idr_lock);
  3788. return prog;
  3789. }
  3790. static int bpf_prog_get_fd_by_id(const union bpf_attr *attr)
  3791. {
  3792. struct bpf_prog *prog;
  3793. u32 id = attr->prog_id;
  3794. int fd;
  3795. if (CHECK_ATTR(BPF_PROG_GET_FD_BY_ID))
  3796. return -EINVAL;
  3797. if (!capable(CAP_SYS_ADMIN))
  3798. return -EPERM;
  3799. prog = bpf_prog_by_id(id);
  3800. if (IS_ERR(prog))
  3801. return PTR_ERR(prog);
  3802. fd = bpf_prog_new_fd(prog);
  3803. if (fd < 0)
  3804. bpf_prog_put(prog);
  3805. return fd;
  3806. }
  3807. #define BPF_MAP_GET_FD_BY_ID_LAST_FIELD open_flags
  3808. static int bpf_map_get_fd_by_id(const union bpf_attr *attr)
  3809. {
  3810. struct bpf_map *map;
  3811. u32 id = attr->map_id;
  3812. int f_flags;
  3813. int fd;
  3814. if (CHECK_ATTR(BPF_MAP_GET_FD_BY_ID) ||
  3815. attr->open_flags & ~BPF_OBJ_FLAG_MASK)
  3816. return -EINVAL;
  3817. if (!capable(CAP_SYS_ADMIN))
  3818. return -EPERM;
  3819. f_flags = bpf_get_file_flag(attr->open_flags);
  3820. if (f_flags < 0)
  3821. return f_flags;
  3822. spin_lock_bh(&map_idr_lock);
  3823. map = idr_find(&map_idr, id);
  3824. if (map)
  3825. map = __bpf_map_inc_not_zero(map, true);
  3826. else
  3827. map = ERR_PTR(-ENOENT);
  3828. spin_unlock_bh(&map_idr_lock);
  3829. if (IS_ERR(map))
  3830. return PTR_ERR(map);
  3831. fd = bpf_map_new_fd(map, f_flags);
  3832. if (fd < 0)
  3833. bpf_map_put_with_uref(map);
  3834. return fd;
  3835. }
  3836. static const struct bpf_map *bpf_map_from_imm(const struct bpf_prog *prog,
  3837. unsigned long addr, u32 *off,
  3838. u32 *type)
  3839. {
  3840. const struct bpf_map *map;
  3841. int i;
  3842. mutex_lock(&prog->aux->used_maps_mutex);
  3843. for (i = 0, *off = 0; i < prog->aux->used_map_cnt; i++) {
  3844. map = prog->aux->used_maps[i];
  3845. if (map == (void *)addr) {
  3846. *type = BPF_PSEUDO_MAP_FD;
  3847. goto out;
  3848. }
  3849. if (!map->ops->map_direct_value_meta)
  3850. continue;
  3851. if (!map->ops->map_direct_value_meta(map, addr, off)) {
  3852. *type = BPF_PSEUDO_MAP_VALUE;
  3853. goto out;
  3854. }
  3855. }
  3856. map = NULL;
  3857. out:
  3858. mutex_unlock(&prog->aux->used_maps_mutex);
  3859. return map;
  3860. }
  3861. static struct bpf_insn *bpf_insn_prepare_dump(const struct bpf_prog *prog,
  3862. const struct cred *f_cred)
  3863. {
  3864. const struct bpf_map *map;
  3865. struct bpf_insn *insns;
  3866. u32 off, type;
  3867. u64 imm;
  3868. u8 code;
  3869. int i;
  3870. insns = kmemdup(prog->insnsi, bpf_prog_insn_size(prog),
  3871. GFP_USER);
  3872. if (!insns)
  3873. return insns;
  3874. for (i = 0; i < prog->len; i++) {
  3875. code = insns[i].code;
  3876. if (code == (BPF_JMP | BPF_TAIL_CALL)) {
  3877. insns[i].code = BPF_JMP | BPF_CALL;
  3878. insns[i].imm = BPF_FUNC_tail_call;
  3879. /* fall-through */
  3880. }
  3881. if (code == (BPF_JMP | BPF_CALL) ||
  3882. code == (BPF_JMP | BPF_CALL_ARGS)) {
  3883. if (code == (BPF_JMP | BPF_CALL_ARGS))
  3884. insns[i].code = BPF_JMP | BPF_CALL;
  3885. if (!bpf_dump_raw_ok(f_cred))
  3886. insns[i].imm = 0;
  3887. continue;
  3888. }
  3889. if (BPF_CLASS(code) == BPF_LDX && BPF_MODE(code) == BPF_PROBE_MEM) {
  3890. insns[i].code = BPF_LDX | BPF_SIZE(code) | BPF_MEM;
  3891. continue;
  3892. }
  3893. if ((BPF_CLASS(code) == BPF_LDX || BPF_CLASS(code) == BPF_STX ||
  3894. BPF_CLASS(code) == BPF_ST) && BPF_MODE(code) == BPF_PROBE_MEM32) {
  3895. insns[i].code = BPF_CLASS(code) | BPF_SIZE(code) | BPF_MEM;
  3896. continue;
  3897. }
  3898. if (code != (BPF_LD | BPF_IMM | BPF_DW))
  3899. continue;
  3900. imm = ((u64)insns[i + 1].imm << 32) | (u32)insns[i].imm;
  3901. map = bpf_map_from_imm(prog, imm, &off, &type);
  3902. if (map) {
  3903. insns[i].src_reg = type;
  3904. insns[i].imm = map->id;
  3905. insns[i + 1].imm = off;
  3906. continue;
  3907. }
  3908. }
  3909. return insns;
  3910. }
  3911. static int set_info_rec_size(struct bpf_prog_info *info)
  3912. {
  3913. /*
  3914. * Ensure info.*_rec_size is the same as kernel expected size
  3915. *
  3916. * or
  3917. *
  3918. * Only allow zero *_rec_size if both _rec_size and _cnt are
  3919. * zero. In this case, the kernel will set the expected
  3920. * _rec_size back to the info.
  3921. */
  3922. if ((info->nr_func_info || info->func_info_rec_size) &&
  3923. info->func_info_rec_size != sizeof(struct bpf_func_info))
  3924. return -EINVAL;
  3925. if ((info->nr_line_info || info->line_info_rec_size) &&
  3926. info->line_info_rec_size != sizeof(struct bpf_line_info))
  3927. return -EINVAL;
  3928. if ((info->nr_jited_line_info || info->jited_line_info_rec_size) &&
  3929. info->jited_line_info_rec_size != sizeof(__u64))
  3930. return -EINVAL;
  3931. info->func_info_rec_size = sizeof(struct bpf_func_info);
  3932. info->line_info_rec_size = sizeof(struct bpf_line_info);
  3933. info->jited_line_info_rec_size = sizeof(__u64);
  3934. return 0;
  3935. }
  3936. static int bpf_prog_get_info_by_fd(struct file *file,
  3937. struct bpf_prog *prog,
  3938. const union bpf_attr *attr,
  3939. union bpf_attr __user *uattr)
  3940. {
  3941. struct bpf_prog_info __user *uinfo = u64_to_user_ptr(attr->info.info);
  3942. struct btf *attach_btf = bpf_prog_get_target_btf(prog);
  3943. struct bpf_prog_info info;
  3944. u32 info_len = attr->info.info_len;
  3945. struct bpf_prog_kstats stats;
  3946. char __user *uinsns;
  3947. u32 ulen;
  3948. int err;
  3949. err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), sizeof(info), info_len);
  3950. if (err)
  3951. return err;
  3952. info_len = min_t(u32, sizeof(info), info_len);
  3953. memset(&info, 0, sizeof(info));
  3954. if (copy_from_user(&info, uinfo, info_len))
  3955. return -EFAULT;
  3956. info.type = prog->type;
  3957. info.id = prog->aux->id;
  3958. info.load_time = prog->aux->load_time;
  3959. info.created_by_uid = from_kuid_munged(current_user_ns(),
  3960. prog->aux->user->uid);
  3961. info.gpl_compatible = prog->gpl_compatible;
  3962. memcpy(info.tag, prog->tag, sizeof(prog->tag));
  3963. memcpy(info.name, prog->aux->name, sizeof(prog->aux->name));
  3964. mutex_lock(&prog->aux->used_maps_mutex);
  3965. ulen = info.nr_map_ids;
  3966. info.nr_map_ids = prog->aux->used_map_cnt;
  3967. ulen = min_t(u32, info.nr_map_ids, ulen);
  3968. if (ulen) {
  3969. u32 __user *user_map_ids = u64_to_user_ptr(info.map_ids);
  3970. u32 i;
  3971. for (i = 0; i < ulen; i++)
  3972. if (put_user(prog->aux->used_maps[i]->id,
  3973. &user_map_ids[i])) {
  3974. mutex_unlock(&prog->aux->used_maps_mutex);
  3975. return -EFAULT;
  3976. }
  3977. }
  3978. mutex_unlock(&prog->aux->used_maps_mutex);
  3979. err = set_info_rec_size(&info);
  3980. if (err)
  3981. return err;
  3982. bpf_prog_get_stats(prog, &stats);
  3983. info.run_time_ns = stats.nsecs;
  3984. info.run_cnt = stats.cnt;
  3985. info.recursion_misses = stats.misses;
  3986. info.verified_insns = prog->aux->verified_insns;
  3987. if (prog->aux->btf)
  3988. info.btf_id = btf_obj_id(prog->aux->btf);
  3989. if (!bpf_capable()) {
  3990. info.jited_prog_len = 0;
  3991. info.xlated_prog_len = 0;
  3992. info.nr_jited_ksyms = 0;
  3993. info.nr_jited_func_lens = 0;
  3994. info.nr_func_info = 0;
  3995. info.nr_line_info = 0;
  3996. info.nr_jited_line_info = 0;
  3997. goto done;
  3998. }
  3999. ulen = info.xlated_prog_len;
  4000. info.xlated_prog_len = bpf_prog_insn_size(prog);
  4001. if (info.xlated_prog_len && ulen) {
  4002. struct bpf_insn *insns_sanitized;
  4003. bool fault;
  4004. if (prog->blinded && !bpf_dump_raw_ok(file->f_cred)) {
  4005. info.xlated_prog_insns = 0;
  4006. goto done;
  4007. }
  4008. insns_sanitized = bpf_insn_prepare_dump(prog, file->f_cred);
  4009. if (!insns_sanitized)
  4010. return -ENOMEM;
  4011. uinsns = u64_to_user_ptr(info.xlated_prog_insns);
  4012. ulen = min_t(u32, info.xlated_prog_len, ulen);
  4013. fault = copy_to_user(uinsns, insns_sanitized, ulen);
  4014. kfree(insns_sanitized);
  4015. if (fault)
  4016. return -EFAULT;
  4017. }
  4018. if (bpf_prog_is_offloaded(prog->aux)) {
  4019. err = bpf_prog_offload_info_fill(&info, prog);
  4020. if (err)
  4021. return err;
  4022. goto done;
  4023. }
  4024. /* NOTE: the following code is supposed to be skipped for offload.
  4025. * bpf_prog_offload_info_fill() is the place to fill similar fields
  4026. * for offload.
  4027. */
  4028. ulen = info.jited_prog_len;
  4029. if (prog->aux->func_cnt) {
  4030. u32 i;
  4031. info.jited_prog_len = 0;
  4032. for (i = 0; i < prog->aux->func_cnt; i++)
  4033. info.jited_prog_len += prog->aux->func[i]->jited_len;
  4034. } else {
  4035. info.jited_prog_len = prog->jited_len;
  4036. }
  4037. if (info.jited_prog_len && ulen) {
  4038. if (bpf_dump_raw_ok(file->f_cred)) {
  4039. uinsns = u64_to_user_ptr(info.jited_prog_insns);
  4040. ulen = min_t(u32, info.jited_prog_len, ulen);
  4041. /* for multi-function programs, copy the JITed
  4042. * instructions for all the functions
  4043. */
  4044. if (prog->aux->func_cnt) {
  4045. u32 len, free, i;
  4046. u8 *img;
  4047. free = ulen;
  4048. for (i = 0; i < prog->aux->func_cnt; i++) {
  4049. len = prog->aux->func[i]->jited_len;
  4050. len = min_t(u32, len, free);
  4051. img = (u8 *) prog->aux->func[i]->bpf_func;
  4052. if (copy_to_user(uinsns, img, len))
  4053. return -EFAULT;
  4054. uinsns += len;
  4055. free -= len;
  4056. if (!free)
  4057. break;
  4058. }
  4059. } else {
  4060. if (copy_to_user(uinsns, prog->bpf_func, ulen))
  4061. return -EFAULT;
  4062. }
  4063. } else {
  4064. info.jited_prog_insns = 0;
  4065. }
  4066. }
  4067. ulen = info.nr_jited_ksyms;
  4068. info.nr_jited_ksyms = prog->aux->func_cnt ? : 1;
  4069. if (ulen) {
  4070. if (bpf_dump_raw_ok(file->f_cred)) {
  4071. unsigned long ksym_addr;
  4072. u64 __user *user_ksyms;
  4073. u32 i;
  4074. /* copy the address of the kernel symbol
  4075. * corresponding to each function
  4076. */
  4077. ulen = min_t(u32, info.nr_jited_ksyms, ulen);
  4078. user_ksyms = u64_to_user_ptr(info.jited_ksyms);
  4079. if (prog->aux->func_cnt) {
  4080. for (i = 0; i < ulen; i++) {
  4081. ksym_addr = (unsigned long)
  4082. prog->aux->func[i]->bpf_func;
  4083. if (put_user((u64) ksym_addr,
  4084. &user_ksyms[i]))
  4085. return -EFAULT;
  4086. }
  4087. } else {
  4088. ksym_addr = (unsigned long) prog->bpf_func;
  4089. if (put_user((u64) ksym_addr, &user_ksyms[0]))
  4090. return -EFAULT;
  4091. }
  4092. } else {
  4093. info.jited_ksyms = 0;
  4094. }
  4095. }
  4096. ulen = info.nr_jited_func_lens;
  4097. info.nr_jited_func_lens = prog->aux->func_cnt ? : 1;
  4098. if (ulen) {
  4099. if (bpf_dump_raw_ok(file->f_cred)) {
  4100. u32 __user *user_lens;
  4101. u32 func_len, i;
  4102. /* copy the JITed image lengths for each function */
  4103. ulen = min_t(u32, info.nr_jited_func_lens, ulen);
  4104. user_lens = u64_to_user_ptr(info.jited_func_lens);
  4105. if (prog->aux->func_cnt) {
  4106. for (i = 0; i < ulen; i++) {
  4107. func_len =
  4108. prog->aux->func[i]->jited_len;
  4109. if (put_user(func_len, &user_lens[i]))
  4110. return -EFAULT;
  4111. }
  4112. } else {
  4113. func_len = prog->jited_len;
  4114. if (put_user(func_len, &user_lens[0]))
  4115. return -EFAULT;
  4116. }
  4117. } else {
  4118. info.jited_func_lens = 0;
  4119. }
  4120. }
  4121. info.attach_btf_id = prog->aux->attach_btf_id;
  4122. if (attach_btf)
  4123. info.attach_btf_obj_id = btf_obj_id(attach_btf);
  4124. ulen = info.nr_func_info;
  4125. info.nr_func_info = prog->aux->func_info_cnt;
  4126. if (info.nr_func_info && ulen) {
  4127. char __user *user_finfo;
  4128. user_finfo = u64_to_user_ptr(info.func_info);
  4129. ulen = min_t(u32, info.nr_func_info, ulen);
  4130. if (copy_to_user(user_finfo, prog->aux->func_info,
  4131. info.func_info_rec_size * ulen))
  4132. return -EFAULT;
  4133. }
  4134. ulen = info.nr_line_info;
  4135. info.nr_line_info = prog->aux->nr_linfo;
  4136. if (info.nr_line_info && ulen) {
  4137. __u8 __user *user_linfo;
  4138. user_linfo = u64_to_user_ptr(info.line_info);
  4139. ulen = min_t(u32, info.nr_line_info, ulen);
  4140. if (copy_to_user(user_linfo, prog->aux->linfo,
  4141. info.line_info_rec_size * ulen))
  4142. return -EFAULT;
  4143. }
  4144. ulen = info.nr_jited_line_info;
  4145. if (prog->aux->jited_linfo)
  4146. info.nr_jited_line_info = prog->aux->nr_linfo;
  4147. else
  4148. info.nr_jited_line_info = 0;
  4149. if (info.nr_jited_line_info && ulen) {
  4150. if (bpf_dump_raw_ok(file->f_cred)) {
  4151. unsigned long line_addr;
  4152. __u64 __user *user_linfo;
  4153. u32 i;
  4154. user_linfo = u64_to_user_ptr(info.jited_line_info);
  4155. ulen = min_t(u32, info.nr_jited_line_info, ulen);
  4156. for (i = 0; i < ulen; i++) {
  4157. line_addr = (unsigned long)prog->aux->jited_linfo[i];
  4158. if (put_user((__u64)line_addr, &user_linfo[i]))
  4159. return -EFAULT;
  4160. }
  4161. } else {
  4162. info.jited_line_info = 0;
  4163. }
  4164. }
  4165. ulen = info.nr_prog_tags;
  4166. info.nr_prog_tags = prog->aux->func_cnt ? : 1;
  4167. if (ulen) {
  4168. __u8 __user (*user_prog_tags)[BPF_TAG_SIZE];
  4169. u32 i;
  4170. user_prog_tags = u64_to_user_ptr(info.prog_tags);
  4171. ulen = min_t(u32, info.nr_prog_tags, ulen);
  4172. if (prog->aux->func_cnt) {
  4173. for (i = 0; i < ulen; i++) {
  4174. if (copy_to_user(user_prog_tags[i],
  4175. prog->aux->func[i]->tag,
  4176. BPF_TAG_SIZE))
  4177. return -EFAULT;
  4178. }
  4179. } else {
  4180. if (copy_to_user(user_prog_tags[0],
  4181. prog->tag, BPF_TAG_SIZE))
  4182. return -EFAULT;
  4183. }
  4184. }
  4185. done:
  4186. if (copy_to_user(uinfo, &info, info_len) ||
  4187. put_user(info_len, &uattr->info.info_len))
  4188. return -EFAULT;
  4189. return 0;
  4190. }
  4191. static int bpf_map_get_info_by_fd(struct file *file,
  4192. struct bpf_map *map,
  4193. const union bpf_attr *attr,
  4194. union bpf_attr __user *uattr)
  4195. {
  4196. struct bpf_map_info __user *uinfo = u64_to_user_ptr(attr->info.info);
  4197. struct bpf_map_info info;
  4198. u32 info_len = attr->info.info_len;
  4199. int err;
  4200. err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), sizeof(info), info_len);
  4201. if (err)
  4202. return err;
  4203. info_len = min_t(u32, sizeof(info), info_len);
  4204. memset(&info, 0, sizeof(info));
  4205. info.type = map->map_type;
  4206. info.id = map->id;
  4207. info.key_size = map->key_size;
  4208. info.value_size = map->value_size;
  4209. info.max_entries = map->max_entries;
  4210. info.map_flags = map->map_flags;
  4211. info.map_extra = map->map_extra;
  4212. memcpy(info.name, map->name, sizeof(map->name));
  4213. if (map->btf) {
  4214. info.btf_id = btf_obj_id(map->btf);
  4215. info.btf_key_type_id = map->btf_key_type_id;
  4216. info.btf_value_type_id = map->btf_value_type_id;
  4217. }
  4218. info.btf_vmlinux_value_type_id = map->btf_vmlinux_value_type_id;
  4219. if (map->map_type == BPF_MAP_TYPE_STRUCT_OPS)
  4220. bpf_map_struct_ops_info_fill(&info, map);
  4221. if (bpf_map_is_offloaded(map)) {
  4222. err = bpf_map_offload_info_fill(&info, map);
  4223. if (err)
  4224. return err;
  4225. }
  4226. if (copy_to_user(uinfo, &info, info_len) ||
  4227. put_user(info_len, &uattr->info.info_len))
  4228. return -EFAULT;
  4229. return 0;
  4230. }
  4231. static int bpf_btf_get_info_by_fd(struct file *file,
  4232. struct btf *btf,
  4233. const union bpf_attr *attr,
  4234. union bpf_attr __user *uattr)
  4235. {
  4236. struct bpf_btf_info __user *uinfo = u64_to_user_ptr(attr->info.info);
  4237. u32 info_len = attr->info.info_len;
  4238. int err;
  4239. err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), sizeof(*uinfo), info_len);
  4240. if (err)
  4241. return err;
  4242. return btf_get_info_by_fd(btf, attr, uattr);
  4243. }
  4244. static int bpf_link_get_info_by_fd(struct file *file,
  4245. struct bpf_link *link,
  4246. const union bpf_attr *attr,
  4247. union bpf_attr __user *uattr)
  4248. {
  4249. struct bpf_link_info __user *uinfo = u64_to_user_ptr(attr->info.info);
  4250. struct bpf_link_info info;
  4251. u32 info_len = attr->info.info_len;
  4252. int err;
  4253. err = bpf_check_uarg_tail_zero(USER_BPFPTR(uinfo), sizeof(info), info_len);
  4254. if (err)
  4255. return err;
  4256. info_len = min_t(u32, sizeof(info), info_len);
  4257. memset(&info, 0, sizeof(info));
  4258. if (copy_from_user(&info, uinfo, info_len))
  4259. return -EFAULT;
  4260. info.type = link->type;
  4261. info.id = link->id;
  4262. if (link->prog)
  4263. info.prog_id = link->prog->aux->id;
  4264. if (link->ops->fill_link_info) {
  4265. err = link->ops->fill_link_info(link, &info);
  4266. if (err)
  4267. return err;
  4268. }
  4269. if (copy_to_user(uinfo, &info, info_len) ||
  4270. put_user(info_len, &uattr->info.info_len))
  4271. return -EFAULT;
  4272. return 0;
  4273. }
  4274. #define BPF_OBJ_GET_INFO_BY_FD_LAST_FIELD info.info
  4275. static int bpf_obj_get_info_by_fd(const union bpf_attr *attr,
  4276. union bpf_attr __user *uattr)
  4277. {
  4278. if (CHECK_ATTR(BPF_OBJ_GET_INFO_BY_FD))
  4279. return -EINVAL;
  4280. CLASS(fd, f)(attr->info.bpf_fd);
  4281. if (fd_empty(f))
  4282. return -EBADFD;
  4283. if (fd_file(f)->f_op == &bpf_prog_fops)
  4284. return bpf_prog_get_info_by_fd(fd_file(f), fd_file(f)->private_data, attr,
  4285. uattr);
  4286. else if (fd_file(f)->f_op == &bpf_map_fops)
  4287. return bpf_map_get_info_by_fd(fd_file(f), fd_file(f)->private_data, attr,
  4288. uattr);
  4289. else if (fd_file(f)->f_op == &btf_fops)
  4290. return bpf_btf_get_info_by_fd(fd_file(f), fd_file(f)->private_data, attr, uattr);
  4291. else if (fd_file(f)->f_op == &bpf_link_fops || fd_file(f)->f_op == &bpf_link_fops_poll)
  4292. return bpf_link_get_info_by_fd(fd_file(f), fd_file(f)->private_data,
  4293. attr, uattr);
  4294. return -EINVAL;
  4295. }
  4296. #define BPF_BTF_LOAD_LAST_FIELD btf_token_fd
  4297. static int bpf_btf_load(const union bpf_attr *attr, bpfptr_t uattr, __u32 uattr_size)
  4298. {
  4299. struct bpf_token *token = NULL;
  4300. if (CHECK_ATTR(BPF_BTF_LOAD))
  4301. return -EINVAL;
  4302. if (attr->btf_flags & ~BPF_F_TOKEN_FD)
  4303. return -EINVAL;
  4304. if (attr->btf_flags & BPF_F_TOKEN_FD) {
  4305. token = bpf_token_get_from_fd(attr->btf_token_fd);
  4306. if (IS_ERR(token))
  4307. return PTR_ERR(token);
  4308. if (!bpf_token_allow_cmd(token, BPF_BTF_LOAD)) {
  4309. bpf_token_put(token);
  4310. token = NULL;
  4311. }
  4312. }
  4313. if (!bpf_token_capable(token, CAP_BPF)) {
  4314. bpf_token_put(token);
  4315. return -EPERM;
  4316. }
  4317. bpf_token_put(token);
  4318. return btf_new_fd(attr, uattr, uattr_size);
  4319. }
  4320. #define BPF_BTF_GET_FD_BY_ID_LAST_FIELD btf_id
  4321. static int bpf_btf_get_fd_by_id(const union bpf_attr *attr)
  4322. {
  4323. if (CHECK_ATTR(BPF_BTF_GET_FD_BY_ID))
  4324. return -EINVAL;
  4325. if (!capable(CAP_SYS_ADMIN))
  4326. return -EPERM;
  4327. return btf_get_fd_by_id(attr->btf_id);
  4328. }
  4329. static int bpf_task_fd_query_copy(const union bpf_attr *attr,
  4330. union bpf_attr __user *uattr,
  4331. u32 prog_id, u32 fd_type,
  4332. const char *buf, u64 probe_offset,
  4333. u64 probe_addr)
  4334. {
  4335. char __user *ubuf = u64_to_user_ptr(attr->task_fd_query.buf);
  4336. u32 len = buf ? strlen(buf) : 0, input_len;
  4337. int err = 0;
  4338. if (put_user(len, &uattr->task_fd_query.buf_len))
  4339. return -EFAULT;
  4340. input_len = attr->task_fd_query.buf_len;
  4341. if (input_len && ubuf) {
  4342. if (!len) {
  4343. /* nothing to copy, just make ubuf NULL terminated */
  4344. char zero = '\0';
  4345. if (put_user(zero, ubuf))
  4346. return -EFAULT;
  4347. } else if (input_len >= len + 1) {
  4348. /* ubuf can hold the string with NULL terminator */
  4349. if (copy_to_user(ubuf, buf, len + 1))
  4350. return -EFAULT;
  4351. } else {
  4352. /* ubuf cannot hold the string with NULL terminator,
  4353. * do a partial copy with NULL terminator.
  4354. */
  4355. char zero = '\0';
  4356. err = -ENOSPC;
  4357. if (copy_to_user(ubuf, buf, input_len - 1))
  4358. return -EFAULT;
  4359. if (put_user(zero, ubuf + input_len - 1))
  4360. return -EFAULT;
  4361. }
  4362. }
  4363. if (put_user(prog_id, &uattr->task_fd_query.prog_id) ||
  4364. put_user(fd_type, &uattr->task_fd_query.fd_type) ||
  4365. put_user(probe_offset, &uattr->task_fd_query.probe_offset) ||
  4366. put_user(probe_addr, &uattr->task_fd_query.probe_addr))
  4367. return -EFAULT;
  4368. return err;
  4369. }
  4370. #define BPF_TASK_FD_QUERY_LAST_FIELD task_fd_query.probe_addr
  4371. static int bpf_task_fd_query(const union bpf_attr *attr,
  4372. union bpf_attr __user *uattr)
  4373. {
  4374. pid_t pid = attr->task_fd_query.pid;
  4375. u32 fd = attr->task_fd_query.fd;
  4376. const struct perf_event *event;
  4377. struct task_struct *task;
  4378. struct file *file;
  4379. int err;
  4380. if (CHECK_ATTR(BPF_TASK_FD_QUERY))
  4381. return -EINVAL;
  4382. if (!capable(CAP_SYS_ADMIN))
  4383. return -EPERM;
  4384. if (attr->task_fd_query.flags != 0)
  4385. return -EINVAL;
  4386. rcu_read_lock();
  4387. task = get_pid_task(find_vpid(pid), PIDTYPE_PID);
  4388. rcu_read_unlock();
  4389. if (!task)
  4390. return -ENOENT;
  4391. err = 0;
  4392. file = fget_task(task, fd);
  4393. put_task_struct(task);
  4394. if (!file)
  4395. return -EBADF;
  4396. if (file->f_op == &bpf_link_fops || file->f_op == &bpf_link_fops_poll) {
  4397. struct bpf_link *link = file->private_data;
  4398. if (link->ops == &bpf_raw_tp_link_lops) {
  4399. struct bpf_raw_tp_link *raw_tp =
  4400. container_of(link, struct bpf_raw_tp_link, link);
  4401. struct bpf_raw_event_map *btp = raw_tp->btp;
  4402. err = bpf_task_fd_query_copy(attr, uattr,
  4403. raw_tp->link.prog->aux->id,
  4404. BPF_FD_TYPE_RAW_TRACEPOINT,
  4405. btp->tp->name, 0, 0);
  4406. goto put_file;
  4407. }
  4408. goto out_not_supp;
  4409. }
  4410. event = perf_get_event(file);
  4411. if (!IS_ERR(event)) {
  4412. u64 probe_offset, probe_addr;
  4413. u32 prog_id, fd_type;
  4414. const char *buf;
  4415. err = bpf_get_perf_event_info(event, &prog_id, &fd_type,
  4416. &buf, &probe_offset,
  4417. &probe_addr, NULL);
  4418. if (!err)
  4419. err = bpf_task_fd_query_copy(attr, uattr, prog_id,
  4420. fd_type, buf,
  4421. probe_offset,
  4422. probe_addr);
  4423. goto put_file;
  4424. }
  4425. out_not_supp:
  4426. err = -ENOTSUPP;
  4427. put_file:
  4428. fput(file);
  4429. return err;
  4430. }
  4431. #define BPF_MAP_BATCH_LAST_FIELD batch.flags
  4432. #define BPF_DO_BATCH(fn, ...) \
  4433. do { \
  4434. if (!fn) { \
  4435. err = -ENOTSUPP; \
  4436. goto err_put; \
  4437. } \
  4438. err = fn(__VA_ARGS__); \
  4439. } while (0)
  4440. static int bpf_map_do_batch(const union bpf_attr *attr,
  4441. union bpf_attr __user *uattr,
  4442. int cmd)
  4443. {
  4444. bool has_read = cmd == BPF_MAP_LOOKUP_BATCH ||
  4445. cmd == BPF_MAP_LOOKUP_AND_DELETE_BATCH;
  4446. bool has_write = cmd != BPF_MAP_LOOKUP_BATCH;
  4447. struct bpf_map *map;
  4448. int err;
  4449. if (CHECK_ATTR(BPF_MAP_BATCH))
  4450. return -EINVAL;
  4451. CLASS(fd, f)(attr->batch.map_fd);
  4452. map = __bpf_map_get(f);
  4453. if (IS_ERR(map))
  4454. return PTR_ERR(map);
  4455. if (has_write)
  4456. bpf_map_write_active_inc(map);
  4457. if (has_read && !(map_get_sys_perms(map, f) & FMODE_CAN_READ)) {
  4458. err = -EPERM;
  4459. goto err_put;
  4460. }
  4461. if (has_write && !(map_get_sys_perms(map, f) & FMODE_CAN_WRITE)) {
  4462. err = -EPERM;
  4463. goto err_put;
  4464. }
  4465. if (cmd == BPF_MAP_LOOKUP_BATCH)
  4466. BPF_DO_BATCH(map->ops->map_lookup_batch, map, attr, uattr);
  4467. else if (cmd == BPF_MAP_LOOKUP_AND_DELETE_BATCH)
  4468. BPF_DO_BATCH(map->ops->map_lookup_and_delete_batch, map, attr, uattr);
  4469. else if (cmd == BPF_MAP_UPDATE_BATCH)
  4470. BPF_DO_BATCH(map->ops->map_update_batch, map, fd_file(f), attr, uattr);
  4471. else
  4472. BPF_DO_BATCH(map->ops->map_delete_batch, map, attr, uattr);
  4473. err_put:
  4474. if (has_write) {
  4475. maybe_wait_bpf_programs(map);
  4476. bpf_map_write_active_dec(map);
  4477. }
  4478. return err;
  4479. }
  4480. #define BPF_LINK_CREATE_LAST_FIELD link_create.uprobe_multi.pid
  4481. static int link_create(union bpf_attr *attr, bpfptr_t uattr)
  4482. {
  4483. struct bpf_prog *prog;
  4484. int ret;
  4485. if (CHECK_ATTR(BPF_LINK_CREATE))
  4486. return -EINVAL;
  4487. if (attr->link_create.attach_type == BPF_STRUCT_OPS)
  4488. return bpf_struct_ops_link_create(attr);
  4489. prog = bpf_prog_get(attr->link_create.prog_fd);
  4490. if (IS_ERR(prog))
  4491. return PTR_ERR(prog);
  4492. ret = bpf_prog_attach_check_attach_type(prog,
  4493. attr->link_create.attach_type);
  4494. if (ret)
  4495. goto out;
  4496. switch (prog->type) {
  4497. case BPF_PROG_TYPE_CGROUP_SKB:
  4498. case BPF_PROG_TYPE_CGROUP_SOCK:
  4499. case BPF_PROG_TYPE_CGROUP_SOCK_ADDR:
  4500. case BPF_PROG_TYPE_SOCK_OPS:
  4501. case BPF_PROG_TYPE_CGROUP_DEVICE:
  4502. case BPF_PROG_TYPE_CGROUP_SYSCTL:
  4503. case BPF_PROG_TYPE_CGROUP_SOCKOPT:
  4504. ret = cgroup_bpf_link_attach(attr, prog);
  4505. break;
  4506. case BPF_PROG_TYPE_EXT:
  4507. ret = bpf_tracing_prog_attach(prog,
  4508. attr->link_create.target_fd,
  4509. attr->link_create.target_btf_id,
  4510. attr->link_create.tracing.cookie);
  4511. break;
  4512. case BPF_PROG_TYPE_LSM:
  4513. case BPF_PROG_TYPE_TRACING:
  4514. if (attr->link_create.attach_type != prog->expected_attach_type) {
  4515. ret = -EINVAL;
  4516. goto out;
  4517. }
  4518. if (prog->expected_attach_type == BPF_TRACE_RAW_TP)
  4519. ret = bpf_raw_tp_link_attach(prog, NULL, attr->link_create.tracing.cookie);
  4520. else if (prog->expected_attach_type == BPF_TRACE_ITER)
  4521. ret = bpf_iter_link_attach(attr, uattr, prog);
  4522. else if (prog->expected_attach_type == BPF_LSM_CGROUP)
  4523. ret = cgroup_bpf_link_attach(attr, prog);
  4524. else
  4525. ret = bpf_tracing_prog_attach(prog,
  4526. attr->link_create.target_fd,
  4527. attr->link_create.target_btf_id,
  4528. attr->link_create.tracing.cookie);
  4529. break;
  4530. case BPF_PROG_TYPE_FLOW_DISSECTOR:
  4531. case BPF_PROG_TYPE_SK_LOOKUP:
  4532. ret = netns_bpf_link_create(attr, prog);
  4533. break;
  4534. case BPF_PROG_TYPE_SK_MSG:
  4535. case BPF_PROG_TYPE_SK_SKB:
  4536. ret = sock_map_link_create(attr, prog);
  4537. break;
  4538. #ifdef CONFIG_NET
  4539. case BPF_PROG_TYPE_XDP:
  4540. ret = bpf_xdp_link_attach(attr, prog);
  4541. break;
  4542. case BPF_PROG_TYPE_SCHED_CLS:
  4543. if (attr->link_create.attach_type == BPF_TCX_INGRESS ||
  4544. attr->link_create.attach_type == BPF_TCX_EGRESS)
  4545. ret = tcx_link_attach(attr, prog);
  4546. else
  4547. ret = netkit_link_attach(attr, prog);
  4548. break;
  4549. case BPF_PROG_TYPE_NETFILTER:
  4550. ret = bpf_nf_link_attach(attr, prog);
  4551. break;
  4552. #endif
  4553. case BPF_PROG_TYPE_PERF_EVENT:
  4554. case BPF_PROG_TYPE_TRACEPOINT:
  4555. ret = bpf_perf_link_attach(attr, prog);
  4556. break;
  4557. case BPF_PROG_TYPE_KPROBE:
  4558. if (attr->link_create.attach_type == BPF_PERF_EVENT)
  4559. ret = bpf_perf_link_attach(attr, prog);
  4560. else if (attr->link_create.attach_type == BPF_TRACE_KPROBE_MULTI ||
  4561. attr->link_create.attach_type == BPF_TRACE_KPROBE_SESSION)
  4562. ret = bpf_kprobe_multi_link_attach(attr, prog);
  4563. else if (attr->link_create.attach_type == BPF_TRACE_UPROBE_MULTI)
  4564. ret = bpf_uprobe_multi_link_attach(attr, prog);
  4565. break;
  4566. default:
  4567. ret = -EINVAL;
  4568. }
  4569. out:
  4570. if (ret < 0)
  4571. bpf_prog_put(prog);
  4572. return ret;
  4573. }
  4574. static int link_update_map(struct bpf_link *link, union bpf_attr *attr)
  4575. {
  4576. struct bpf_map *new_map, *old_map = NULL;
  4577. int ret;
  4578. new_map = bpf_map_get(attr->link_update.new_map_fd);
  4579. if (IS_ERR(new_map))
  4580. return PTR_ERR(new_map);
  4581. if (attr->link_update.flags & BPF_F_REPLACE) {
  4582. old_map = bpf_map_get(attr->link_update.old_map_fd);
  4583. if (IS_ERR(old_map)) {
  4584. ret = PTR_ERR(old_map);
  4585. goto out_put;
  4586. }
  4587. } else if (attr->link_update.old_map_fd) {
  4588. ret = -EINVAL;
  4589. goto out_put;
  4590. }
  4591. ret = link->ops->update_map(link, new_map, old_map);
  4592. if (old_map)
  4593. bpf_map_put(old_map);
  4594. out_put:
  4595. bpf_map_put(new_map);
  4596. return ret;
  4597. }
  4598. #define BPF_LINK_UPDATE_LAST_FIELD link_update.old_prog_fd
  4599. static int link_update(union bpf_attr *attr)
  4600. {
  4601. struct bpf_prog *old_prog = NULL, *new_prog;
  4602. struct bpf_link *link;
  4603. u32 flags;
  4604. int ret;
  4605. if (CHECK_ATTR(BPF_LINK_UPDATE))
  4606. return -EINVAL;
  4607. flags = attr->link_update.flags;
  4608. if (flags & ~BPF_F_REPLACE)
  4609. return -EINVAL;
  4610. link = bpf_link_get_from_fd(attr->link_update.link_fd);
  4611. if (IS_ERR(link))
  4612. return PTR_ERR(link);
  4613. if (link->ops->update_map) {
  4614. ret = link_update_map(link, attr);
  4615. goto out_put_link;
  4616. }
  4617. new_prog = bpf_prog_get(attr->link_update.new_prog_fd);
  4618. if (IS_ERR(new_prog)) {
  4619. ret = PTR_ERR(new_prog);
  4620. goto out_put_link;
  4621. }
  4622. if (flags & BPF_F_REPLACE) {
  4623. old_prog = bpf_prog_get(attr->link_update.old_prog_fd);
  4624. if (IS_ERR(old_prog)) {
  4625. ret = PTR_ERR(old_prog);
  4626. old_prog = NULL;
  4627. goto out_put_progs;
  4628. }
  4629. } else if (attr->link_update.old_prog_fd) {
  4630. ret = -EINVAL;
  4631. goto out_put_progs;
  4632. }
  4633. if (link->ops->update_prog)
  4634. ret = link->ops->update_prog(link, new_prog, old_prog);
  4635. else
  4636. ret = -EINVAL;
  4637. out_put_progs:
  4638. if (old_prog)
  4639. bpf_prog_put(old_prog);
  4640. if (ret)
  4641. bpf_prog_put(new_prog);
  4642. out_put_link:
  4643. bpf_link_put_direct(link);
  4644. return ret;
  4645. }
  4646. #define BPF_LINK_DETACH_LAST_FIELD link_detach.link_fd
  4647. static int link_detach(union bpf_attr *attr)
  4648. {
  4649. struct bpf_link *link;
  4650. int ret;
  4651. if (CHECK_ATTR(BPF_LINK_DETACH))
  4652. return -EINVAL;
  4653. link = bpf_link_get_from_fd(attr->link_detach.link_fd);
  4654. if (IS_ERR(link))
  4655. return PTR_ERR(link);
  4656. if (link->ops->detach)
  4657. ret = link->ops->detach(link);
  4658. else
  4659. ret = -EOPNOTSUPP;
  4660. bpf_link_put_direct(link);
  4661. return ret;
  4662. }
  4663. struct bpf_link *bpf_link_inc_not_zero(struct bpf_link *link)
  4664. {
  4665. return atomic64_fetch_add_unless(&link->refcnt, 1, 0) ? link : ERR_PTR(-ENOENT);
  4666. }
  4667. EXPORT_SYMBOL(bpf_link_inc_not_zero);
  4668. struct bpf_link *bpf_link_by_id(u32 id)
  4669. {
  4670. struct bpf_link *link;
  4671. if (!id)
  4672. return ERR_PTR(-ENOENT);
  4673. spin_lock_bh(&link_idr_lock);
  4674. /* before link is "settled", ID is 0, pretend it doesn't exist yet */
  4675. link = idr_find(&link_idr, id);
  4676. if (link) {
  4677. if (link->id)
  4678. link = bpf_link_inc_not_zero(link);
  4679. else
  4680. link = ERR_PTR(-EAGAIN);
  4681. } else {
  4682. link = ERR_PTR(-ENOENT);
  4683. }
  4684. spin_unlock_bh(&link_idr_lock);
  4685. return link;
  4686. }
  4687. struct bpf_link *bpf_link_get_curr_or_next(u32 *id)
  4688. {
  4689. struct bpf_link *link;
  4690. spin_lock_bh(&link_idr_lock);
  4691. again:
  4692. link = idr_get_next(&link_idr, id);
  4693. if (link) {
  4694. link = bpf_link_inc_not_zero(link);
  4695. if (IS_ERR(link)) {
  4696. (*id)++;
  4697. goto again;
  4698. }
  4699. }
  4700. spin_unlock_bh(&link_idr_lock);
  4701. return link;
  4702. }
  4703. #define BPF_LINK_GET_FD_BY_ID_LAST_FIELD link_id
  4704. static int bpf_link_get_fd_by_id(const union bpf_attr *attr)
  4705. {
  4706. struct bpf_link *link;
  4707. u32 id = attr->link_id;
  4708. int fd;
  4709. if (CHECK_ATTR(BPF_LINK_GET_FD_BY_ID))
  4710. return -EINVAL;
  4711. if (!capable(CAP_SYS_ADMIN))
  4712. return -EPERM;
  4713. link = bpf_link_by_id(id);
  4714. if (IS_ERR(link))
  4715. return PTR_ERR(link);
  4716. fd = bpf_link_new_fd(link);
  4717. if (fd < 0)
  4718. bpf_link_put_direct(link);
  4719. return fd;
  4720. }
  4721. DEFINE_MUTEX(bpf_stats_enabled_mutex);
  4722. static int bpf_stats_release(struct inode *inode, struct file *file)
  4723. {
  4724. mutex_lock(&bpf_stats_enabled_mutex);
  4725. static_key_slow_dec(&bpf_stats_enabled_key.key);
  4726. mutex_unlock(&bpf_stats_enabled_mutex);
  4727. return 0;
  4728. }
  4729. static const struct file_operations bpf_stats_fops = {
  4730. .release = bpf_stats_release,
  4731. };
  4732. static int bpf_enable_runtime_stats(void)
  4733. {
  4734. int fd;
  4735. mutex_lock(&bpf_stats_enabled_mutex);
  4736. /* Set a very high limit to avoid overflow */
  4737. if (static_key_count(&bpf_stats_enabled_key.key) > INT_MAX / 2) {
  4738. mutex_unlock(&bpf_stats_enabled_mutex);
  4739. return -EBUSY;
  4740. }
  4741. fd = anon_inode_getfd("bpf-stats", &bpf_stats_fops, NULL, O_CLOEXEC);
  4742. if (fd >= 0)
  4743. static_key_slow_inc(&bpf_stats_enabled_key.key);
  4744. mutex_unlock(&bpf_stats_enabled_mutex);
  4745. return fd;
  4746. }
  4747. #define BPF_ENABLE_STATS_LAST_FIELD enable_stats.type
  4748. static int bpf_enable_stats(union bpf_attr *attr)
  4749. {
  4750. if (CHECK_ATTR(BPF_ENABLE_STATS))
  4751. return -EINVAL;
  4752. if (!capable(CAP_SYS_ADMIN))
  4753. return -EPERM;
  4754. switch (attr->enable_stats.type) {
  4755. case BPF_STATS_RUN_TIME:
  4756. return bpf_enable_runtime_stats();
  4757. default:
  4758. break;
  4759. }
  4760. return -EINVAL;
  4761. }
  4762. #define BPF_ITER_CREATE_LAST_FIELD iter_create.flags
  4763. static int bpf_iter_create(union bpf_attr *attr)
  4764. {
  4765. struct bpf_link *link;
  4766. int err;
  4767. if (CHECK_ATTR(BPF_ITER_CREATE))
  4768. return -EINVAL;
  4769. if (attr->iter_create.flags)
  4770. return -EINVAL;
  4771. link = bpf_link_get_from_fd(attr->iter_create.link_fd);
  4772. if (IS_ERR(link))
  4773. return PTR_ERR(link);
  4774. err = bpf_iter_new_fd(link);
  4775. bpf_link_put_direct(link);
  4776. return err;
  4777. }
  4778. #define BPF_PROG_BIND_MAP_LAST_FIELD prog_bind_map.flags
  4779. static int bpf_prog_bind_map(union bpf_attr *attr)
  4780. {
  4781. struct bpf_prog *prog;
  4782. struct bpf_map *map;
  4783. struct bpf_map **used_maps_old, **used_maps_new;
  4784. int i, ret = 0;
  4785. if (CHECK_ATTR(BPF_PROG_BIND_MAP))
  4786. return -EINVAL;
  4787. if (attr->prog_bind_map.flags)
  4788. return -EINVAL;
  4789. prog = bpf_prog_get(attr->prog_bind_map.prog_fd);
  4790. if (IS_ERR(prog))
  4791. return PTR_ERR(prog);
  4792. map = bpf_map_get(attr->prog_bind_map.map_fd);
  4793. if (IS_ERR(map)) {
  4794. ret = PTR_ERR(map);
  4795. goto out_prog_put;
  4796. }
  4797. mutex_lock(&prog->aux->used_maps_mutex);
  4798. used_maps_old = prog->aux->used_maps;
  4799. for (i = 0; i < prog->aux->used_map_cnt; i++)
  4800. if (used_maps_old[i] == map) {
  4801. bpf_map_put(map);
  4802. goto out_unlock;
  4803. }
  4804. used_maps_new = kmalloc_array(prog->aux->used_map_cnt + 1,
  4805. sizeof(used_maps_new[0]),
  4806. GFP_KERNEL);
  4807. if (!used_maps_new) {
  4808. ret = -ENOMEM;
  4809. goto out_unlock;
  4810. }
  4811. /* The bpf program will not access the bpf map, but for the sake of
  4812. * simplicity, increase sleepable_refcnt for sleepable program as well.
  4813. */
  4814. if (prog->sleepable)
  4815. atomic64_inc(&map->sleepable_refcnt);
  4816. memcpy(used_maps_new, used_maps_old,
  4817. sizeof(used_maps_old[0]) * prog->aux->used_map_cnt);
  4818. used_maps_new[prog->aux->used_map_cnt] = map;
  4819. prog->aux->used_map_cnt++;
  4820. prog->aux->used_maps = used_maps_new;
  4821. kfree(used_maps_old);
  4822. out_unlock:
  4823. mutex_unlock(&prog->aux->used_maps_mutex);
  4824. if (ret)
  4825. bpf_map_put(map);
  4826. out_prog_put:
  4827. bpf_prog_put(prog);
  4828. return ret;
  4829. }
  4830. #define BPF_TOKEN_CREATE_LAST_FIELD token_create.bpffs_fd
  4831. static int token_create(union bpf_attr *attr)
  4832. {
  4833. if (CHECK_ATTR(BPF_TOKEN_CREATE))
  4834. return -EINVAL;
  4835. /* no flags are supported yet */
  4836. if (attr->token_create.flags)
  4837. return -EINVAL;
  4838. return bpf_token_create(attr);
  4839. }
  4840. static int __sys_bpf(enum bpf_cmd cmd, bpfptr_t uattr, unsigned int size)
  4841. {
  4842. union bpf_attr attr;
  4843. int err;
  4844. err = bpf_check_uarg_tail_zero(uattr, sizeof(attr), size);
  4845. if (err)
  4846. return err;
  4847. size = min_t(u32, size, sizeof(attr));
  4848. /* copy attributes from user space, may be less than sizeof(bpf_attr) */
  4849. memset(&attr, 0, sizeof(attr));
  4850. if (copy_from_bpfptr(&attr, uattr, size) != 0)
  4851. return -EFAULT;
  4852. err = security_bpf(cmd, &attr, size);
  4853. if (err < 0)
  4854. return err;
  4855. switch (cmd) {
  4856. case BPF_MAP_CREATE:
  4857. err = map_create(&attr);
  4858. break;
  4859. case BPF_MAP_LOOKUP_ELEM:
  4860. err = map_lookup_elem(&attr);
  4861. break;
  4862. case BPF_MAP_UPDATE_ELEM:
  4863. err = map_update_elem(&attr, uattr);
  4864. break;
  4865. case BPF_MAP_DELETE_ELEM:
  4866. err = map_delete_elem(&attr, uattr);
  4867. break;
  4868. case BPF_MAP_GET_NEXT_KEY:
  4869. err = map_get_next_key(&attr);
  4870. break;
  4871. case BPF_MAP_FREEZE:
  4872. err = map_freeze(&attr);
  4873. break;
  4874. case BPF_PROG_LOAD:
  4875. err = bpf_prog_load(&attr, uattr, size);
  4876. break;
  4877. case BPF_OBJ_PIN:
  4878. err = bpf_obj_pin(&attr);
  4879. break;
  4880. case BPF_OBJ_GET:
  4881. err = bpf_obj_get(&attr);
  4882. break;
  4883. case BPF_PROG_ATTACH:
  4884. err = bpf_prog_attach(&attr);
  4885. break;
  4886. case BPF_PROG_DETACH:
  4887. err = bpf_prog_detach(&attr);
  4888. break;
  4889. case BPF_PROG_QUERY:
  4890. err = bpf_prog_query(&attr, uattr.user);
  4891. break;
  4892. case BPF_PROG_TEST_RUN:
  4893. err = bpf_prog_test_run(&attr, uattr.user);
  4894. break;
  4895. case BPF_PROG_GET_NEXT_ID:
  4896. err = bpf_obj_get_next_id(&attr, uattr.user,
  4897. &prog_idr, &prog_idr_lock);
  4898. break;
  4899. case BPF_MAP_GET_NEXT_ID:
  4900. err = bpf_obj_get_next_id(&attr, uattr.user,
  4901. &map_idr, &map_idr_lock);
  4902. break;
  4903. case BPF_BTF_GET_NEXT_ID:
  4904. err = bpf_obj_get_next_id(&attr, uattr.user,
  4905. &btf_idr, &btf_idr_lock);
  4906. break;
  4907. case BPF_PROG_GET_FD_BY_ID:
  4908. err = bpf_prog_get_fd_by_id(&attr);
  4909. break;
  4910. case BPF_MAP_GET_FD_BY_ID:
  4911. err = bpf_map_get_fd_by_id(&attr);
  4912. break;
  4913. case BPF_OBJ_GET_INFO_BY_FD:
  4914. err = bpf_obj_get_info_by_fd(&attr, uattr.user);
  4915. break;
  4916. case BPF_RAW_TRACEPOINT_OPEN:
  4917. err = bpf_raw_tracepoint_open(&attr);
  4918. break;
  4919. case BPF_BTF_LOAD:
  4920. err = bpf_btf_load(&attr, uattr, size);
  4921. break;
  4922. case BPF_BTF_GET_FD_BY_ID:
  4923. err = bpf_btf_get_fd_by_id(&attr);
  4924. break;
  4925. case BPF_TASK_FD_QUERY:
  4926. err = bpf_task_fd_query(&attr, uattr.user);
  4927. break;
  4928. case BPF_MAP_LOOKUP_AND_DELETE_ELEM:
  4929. err = map_lookup_and_delete_elem(&attr);
  4930. break;
  4931. case BPF_MAP_LOOKUP_BATCH:
  4932. err = bpf_map_do_batch(&attr, uattr.user, BPF_MAP_LOOKUP_BATCH);
  4933. break;
  4934. case BPF_MAP_LOOKUP_AND_DELETE_BATCH:
  4935. err = bpf_map_do_batch(&attr, uattr.user,
  4936. BPF_MAP_LOOKUP_AND_DELETE_BATCH);
  4937. break;
  4938. case BPF_MAP_UPDATE_BATCH:
  4939. err = bpf_map_do_batch(&attr, uattr.user, BPF_MAP_UPDATE_BATCH);
  4940. break;
  4941. case BPF_MAP_DELETE_BATCH:
  4942. err = bpf_map_do_batch(&attr, uattr.user, BPF_MAP_DELETE_BATCH);
  4943. break;
  4944. case BPF_LINK_CREATE:
  4945. err = link_create(&attr, uattr);
  4946. break;
  4947. case BPF_LINK_UPDATE:
  4948. err = link_update(&attr);
  4949. break;
  4950. case BPF_LINK_GET_FD_BY_ID:
  4951. err = bpf_link_get_fd_by_id(&attr);
  4952. break;
  4953. case BPF_LINK_GET_NEXT_ID:
  4954. err = bpf_obj_get_next_id(&attr, uattr.user,
  4955. &link_idr, &link_idr_lock);
  4956. break;
  4957. case BPF_ENABLE_STATS:
  4958. err = bpf_enable_stats(&attr);
  4959. break;
  4960. case BPF_ITER_CREATE:
  4961. err = bpf_iter_create(&attr);
  4962. break;
  4963. case BPF_LINK_DETACH:
  4964. err = link_detach(&attr);
  4965. break;
  4966. case BPF_PROG_BIND_MAP:
  4967. err = bpf_prog_bind_map(&attr);
  4968. break;
  4969. case BPF_TOKEN_CREATE:
  4970. err = token_create(&attr);
  4971. break;
  4972. default:
  4973. err = -EINVAL;
  4974. break;
  4975. }
  4976. return err;
  4977. }
  4978. SYSCALL_DEFINE3(bpf, int, cmd, union bpf_attr __user *, uattr, unsigned int, size)
  4979. {
  4980. return __sys_bpf(cmd, USER_BPFPTR(uattr), size);
  4981. }
  4982. static bool syscall_prog_is_valid_access(int off, int size,
  4983. enum bpf_access_type type,
  4984. const struct bpf_prog *prog,
  4985. struct bpf_insn_access_aux *info)
  4986. {
  4987. if (off < 0 || off >= U16_MAX)
  4988. return false;
  4989. if (off % size != 0)
  4990. return false;
  4991. return true;
  4992. }
  4993. BPF_CALL_3(bpf_sys_bpf, int, cmd, union bpf_attr *, attr, u32, attr_size)
  4994. {
  4995. switch (cmd) {
  4996. case BPF_MAP_CREATE:
  4997. case BPF_MAP_DELETE_ELEM:
  4998. case BPF_MAP_UPDATE_ELEM:
  4999. case BPF_MAP_FREEZE:
  5000. case BPF_MAP_GET_FD_BY_ID:
  5001. case BPF_PROG_LOAD:
  5002. case BPF_BTF_LOAD:
  5003. case BPF_LINK_CREATE:
  5004. case BPF_RAW_TRACEPOINT_OPEN:
  5005. break;
  5006. default:
  5007. return -EINVAL;
  5008. }
  5009. return __sys_bpf(cmd, KERNEL_BPFPTR(attr), attr_size);
  5010. }
  5011. /* To shut up -Wmissing-prototypes.
  5012. * This function is used by the kernel light skeleton
  5013. * to load bpf programs when modules are loaded or during kernel boot.
  5014. * See tools/lib/bpf/skel_internal.h
  5015. */
  5016. int kern_sys_bpf(int cmd, union bpf_attr *attr, unsigned int size);
  5017. int kern_sys_bpf(int cmd, union bpf_attr *attr, unsigned int size)
  5018. {
  5019. struct bpf_prog * __maybe_unused prog;
  5020. struct bpf_tramp_run_ctx __maybe_unused run_ctx;
  5021. switch (cmd) {
  5022. #ifdef CONFIG_BPF_JIT /* __bpf_prog_enter_sleepable used by trampoline and JIT */
  5023. case BPF_PROG_TEST_RUN:
  5024. if (attr->test.data_in || attr->test.data_out ||
  5025. attr->test.ctx_out || attr->test.duration ||
  5026. attr->test.repeat || attr->test.flags)
  5027. return -EINVAL;
  5028. prog = bpf_prog_get_type(attr->test.prog_fd, BPF_PROG_TYPE_SYSCALL);
  5029. if (IS_ERR(prog))
  5030. return PTR_ERR(prog);
  5031. if (attr->test.ctx_size_in < prog->aux->max_ctx_offset ||
  5032. attr->test.ctx_size_in > U16_MAX) {
  5033. bpf_prog_put(prog);
  5034. return -EINVAL;
  5035. }
  5036. run_ctx.bpf_cookie = 0;
  5037. if (!__bpf_prog_enter_sleepable_recur(prog, &run_ctx)) {
  5038. /* recursion detected */
  5039. __bpf_prog_exit_sleepable_recur(prog, 0, &run_ctx);
  5040. bpf_prog_put(prog);
  5041. return -EBUSY;
  5042. }
  5043. attr->test.retval = bpf_prog_run(prog, (void *) (long) attr->test.ctx_in);
  5044. __bpf_prog_exit_sleepable_recur(prog, 0 /* bpf_prog_run does runtime stats */,
  5045. &run_ctx);
  5046. bpf_prog_put(prog);
  5047. return 0;
  5048. #endif
  5049. default:
  5050. return ____bpf_sys_bpf(cmd, attr, size);
  5051. }
  5052. }
  5053. EXPORT_SYMBOL_NS(kern_sys_bpf, BPF_INTERNAL);
  5054. static const struct bpf_func_proto bpf_sys_bpf_proto = {
  5055. .func = bpf_sys_bpf,
  5056. .gpl_only = false,
  5057. .ret_type = RET_INTEGER,
  5058. .arg1_type = ARG_ANYTHING,
  5059. .arg2_type = ARG_PTR_TO_MEM | MEM_RDONLY,
  5060. .arg3_type = ARG_CONST_SIZE,
  5061. };
  5062. const struct bpf_func_proto * __weak
  5063. tracing_prog_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog)
  5064. {
  5065. return bpf_base_func_proto(func_id, prog);
  5066. }
  5067. BPF_CALL_1(bpf_sys_close, u32, fd)
  5068. {
  5069. /* When bpf program calls this helper there should not be
  5070. * an fdget() without matching completed fdput().
  5071. * This helper is allowed in the following callchain only:
  5072. * sys_bpf->prog_test_run->bpf_prog->bpf_sys_close
  5073. */
  5074. return close_fd(fd);
  5075. }
  5076. static const struct bpf_func_proto bpf_sys_close_proto = {
  5077. .func = bpf_sys_close,
  5078. .gpl_only = false,
  5079. .ret_type = RET_INTEGER,
  5080. .arg1_type = ARG_ANYTHING,
  5081. };
  5082. BPF_CALL_4(bpf_kallsyms_lookup_name, const char *, name, int, name_sz, int, flags, u64 *, res)
  5083. {
  5084. *res = 0;
  5085. if (flags)
  5086. return -EINVAL;
  5087. if (name_sz <= 1 || name[name_sz - 1])
  5088. return -EINVAL;
  5089. if (!bpf_dump_raw_ok(current_cred()))
  5090. return -EPERM;
  5091. *res = kallsyms_lookup_name(name);
  5092. return *res ? 0 : -ENOENT;
  5093. }
  5094. static const struct bpf_func_proto bpf_kallsyms_lookup_name_proto = {
  5095. .func = bpf_kallsyms_lookup_name,
  5096. .gpl_only = false,
  5097. .ret_type = RET_INTEGER,
  5098. .arg1_type = ARG_PTR_TO_MEM,
  5099. .arg2_type = ARG_CONST_SIZE_OR_ZERO,
  5100. .arg3_type = ARG_ANYTHING,
  5101. .arg4_type = ARG_PTR_TO_FIXED_SIZE_MEM | MEM_UNINIT | MEM_WRITE | MEM_ALIGNED,
  5102. .arg4_size = sizeof(u64),
  5103. };
  5104. static const struct bpf_func_proto *
  5105. syscall_prog_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog)
  5106. {
  5107. switch (func_id) {
  5108. case BPF_FUNC_sys_bpf:
  5109. return !bpf_token_capable(prog->aux->token, CAP_PERFMON)
  5110. ? NULL : &bpf_sys_bpf_proto;
  5111. case BPF_FUNC_btf_find_by_name_kind:
  5112. return &bpf_btf_find_by_name_kind_proto;
  5113. case BPF_FUNC_sys_close:
  5114. return &bpf_sys_close_proto;
  5115. case BPF_FUNC_kallsyms_lookup_name:
  5116. return &bpf_kallsyms_lookup_name_proto;
  5117. default:
  5118. return tracing_prog_func_proto(func_id, prog);
  5119. }
  5120. }
  5121. const struct bpf_verifier_ops bpf_syscall_verifier_ops = {
  5122. .get_func_proto = syscall_prog_func_proto,
  5123. .is_valid_access = syscall_prog_is_valid_access,
  5124. };
  5125. const struct bpf_prog_ops bpf_syscall_prog_ops = {
  5126. .test_run = bpf_prog_test_run_syscall,
  5127. };
  5128. #ifdef CONFIG_SYSCTL
  5129. static int bpf_stats_handler(const struct ctl_table *table, int write,
  5130. void *buffer, size_t *lenp, loff_t *ppos)
  5131. {
  5132. struct static_key *key = (struct static_key *)table->data;
  5133. static int saved_val;
  5134. int val, ret;
  5135. struct ctl_table tmp = {
  5136. .data = &val,
  5137. .maxlen = sizeof(val),
  5138. .mode = table->mode,
  5139. .extra1 = SYSCTL_ZERO,
  5140. .extra2 = SYSCTL_ONE,
  5141. };
  5142. if (write && !capable(CAP_SYS_ADMIN))
  5143. return -EPERM;
  5144. mutex_lock(&bpf_stats_enabled_mutex);
  5145. val = saved_val;
  5146. ret = proc_dointvec_minmax(&tmp, write, buffer, lenp, ppos);
  5147. if (write && !ret && val != saved_val) {
  5148. if (val)
  5149. static_key_slow_inc(key);
  5150. else
  5151. static_key_slow_dec(key);
  5152. saved_val = val;
  5153. }
  5154. mutex_unlock(&bpf_stats_enabled_mutex);
  5155. return ret;
  5156. }
  5157. void __weak unpriv_ebpf_notify(int new_state)
  5158. {
  5159. }
  5160. static int bpf_unpriv_handler(const struct ctl_table *table, int write,
  5161. void *buffer, size_t *lenp, loff_t *ppos)
  5162. {
  5163. int ret, unpriv_enable = *(int *)table->data;
  5164. bool locked_state = unpriv_enable == 1;
  5165. struct ctl_table tmp = *table;
  5166. if (write && !capable(CAP_SYS_ADMIN))
  5167. return -EPERM;
  5168. tmp.data = &unpriv_enable;
  5169. ret = proc_dointvec_minmax(&tmp, write, buffer, lenp, ppos);
  5170. if (write && !ret) {
  5171. if (locked_state && unpriv_enable != 1)
  5172. return -EPERM;
  5173. *(int *)table->data = unpriv_enable;
  5174. }
  5175. if (write)
  5176. unpriv_ebpf_notify(unpriv_enable);
  5177. return ret;
  5178. }
  5179. static struct ctl_table bpf_syscall_table[] = {
  5180. {
  5181. .procname = "unprivileged_bpf_disabled",
  5182. .data = &sysctl_unprivileged_bpf_disabled,
  5183. .maxlen = sizeof(sysctl_unprivileged_bpf_disabled),
  5184. .mode = 0644,
  5185. .proc_handler = bpf_unpriv_handler,
  5186. .extra1 = SYSCTL_ZERO,
  5187. .extra2 = SYSCTL_TWO,
  5188. },
  5189. {
  5190. .procname = "bpf_stats_enabled",
  5191. .data = &bpf_stats_enabled_key.key,
  5192. .mode = 0644,
  5193. .proc_handler = bpf_stats_handler,
  5194. },
  5195. };
  5196. static int __init bpf_syscall_sysctl_init(void)
  5197. {
  5198. register_sysctl_init("kernel", bpf_syscall_table);
  5199. return 0;
  5200. }
  5201. late_initcall(bpf_syscall_sysctl_init);
  5202. #endif /* CONFIG_SYSCTL */