bpf.h (2589B)
1// SPDX-License-Identifier: GPL-2.0 2#ifndef _PERF_BPF_H 3#define _PERF_BPF_H 4 5#include <uapi/linux/bpf.h> 6 7/* 8 * A helper structure used by eBPF C program to describe map attributes to 9 * elf_bpf loader, taken from tools/testing/selftests/bpf/bpf_helpers.h: 10 */ 11struct bpf_map { 12 unsigned int type; 13 unsigned int key_size; 14 unsigned int value_size; 15 unsigned int max_entries; 16 unsigned int map_flags; 17 unsigned int inner_map_idx; 18 unsigned int numa_node; 19}; 20 21#define bpf_map(name, _type, type_key, type_val, _max_entries) \ 22struct bpf_map SEC("maps") name = { \ 23 .type = BPF_MAP_TYPE_##_type, \ 24 .key_size = sizeof(type_key), \ 25 .value_size = sizeof(type_val), \ 26 .max_entries = _max_entries, \ 27}; \ 28struct ____btf_map_##name { \ 29 type_key key; \ 30 type_val value; \ 31}; \ 32struct ____btf_map_##name __attribute__((section(".maps." #name), used)) \ 33 ____btf_map_##name = { } 34 35/* 36 * FIXME: this should receive .max_entries as a parameter, as careful 37 * tuning of these limits is needed to avoid hitting limits that 38 * prevents other BPF constructs, such as tracepoint handlers, 39 * to get installed, with cryptic messages from libbpf, etc. 40 * For the current need, 'perf trace --filter-pids', 64 should 41 * be good enough, but this surely needs to be revisited. 42 */ 43#define pid_map(name, value_type) bpf_map(name, HASH, pid_t, value_type, 64) 44 45static int (*bpf_map_update_elem)(struct bpf_map *map, void *key, void *value, u64 flags) = (void *)BPF_FUNC_map_update_elem; 46static void *(*bpf_map_lookup_elem)(struct bpf_map *map, void *key) = (void *)BPF_FUNC_map_lookup_elem; 47 48static void (*bpf_tail_call)(void *ctx, void *map, int index) = (void *)BPF_FUNC_tail_call; 49 50#define SEC(NAME) __attribute__((section(NAME), used)) 51 52#define probe(function, vars) \ 53 SEC(#function "=" #function " " #vars) function 54 55#define syscall_enter(name) \ 56 SEC("syscalls:sys_enter_" #name) syscall_enter_ ## name 57 58#define syscall_exit(name) \ 59 SEC("syscalls:sys_exit_" #name) syscall_exit_ ## name 60 61#define license(name) \ 62char _license[] SEC("license") = #name; \ 63int _version SEC("version") = LINUX_VERSION_CODE; 64 65static int (*probe_read)(void *dst, int size, const void *unsafe_addr) = (void *)BPF_FUNC_probe_read; 66static int (*probe_read_str)(void *dst, int size, const void *unsafe_addr) = (void *)BPF_FUNC_probe_read_str; 67 68static int (*perf_event_output)(void *, struct bpf_map *, int, void *, unsigned long) = (void *)BPF_FUNC_perf_event_output; 69 70#endif /* _PERF_BPF_H */