Blame tc/e_bpf.c

Packit d3f73b
/*
Packit d3f73b
 * e_bpf.c	BPF exec proxy
Packit d3f73b
 *
Packit d3f73b
 *		This program is free software; you can distribute it and/or
Packit d3f73b
 *		modify it under the terms of the GNU General Public License
Packit d3f73b
 *		as published by the Free Software Foundation; either version
Packit d3f73b
 *		2 of the License, or (at your option) any later version.
Packit d3f73b
 *
Packit d3f73b
 * Authors:	Daniel Borkmann <daniel@iogearbox.net>
Packit d3f73b
 */
Packit d3f73b
Packit d3f73b
#include <stdio.h>
Packit d3f73b
#include <unistd.h>
Packit d3f73b
Packit d3f73b
#include "utils.h"
Packit d3f73b
Packit d3f73b
#include "tc_util.h"
Packit d3f73b
Packit d3f73b
#include "bpf_util.h"
Packit d3f73b
#include "bpf_elf.h"
Packit d3f73b
#include "bpf_scm.h"
Packit d3f73b
Packit d3f73b
#define BPF_DEFAULT_CMD	"/bin/sh"
Packit d3f73b
Packit d3f73b
static char *argv_default[] = { BPF_DEFAULT_CMD, NULL };
Packit d3f73b
Packit d3f73b
static void explain(void)
Packit d3f73b
{
Packit d3f73b
	fprintf(stderr,
Packit d3f73b
		"Usage: ... bpf [ import UDS_FILE ] [ run CMD ]\n"
Packit d3f73b
		"       ... bpf [ debug ]\n"
Packit d3f73b
		"       ... bpf [ graft MAP_FILE ] [ key KEY ]\n"
Packit d3f73b
		"          `... [ object-file OBJ_FILE ] [ type TYPE ] [ section NAME ] [ verbose ]\n"
Packit d3f73b
		"          `... [ object-pinned PROG_FILE ]\n"
Packit d3f73b
		"\n"
Packit d3f73b
		"Where UDS_FILE provides the name of a unix domain socket file\n"
Packit d3f73b
		"to import eBPF maps and the optional CMD denotes the command\n"
Packit d3f73b
		"to be executed (default: \'%s\').\n"
Packit d3f73b
		"Where MAP_FILE points to a pinned map, OBJ_FILE to an object file\n"
Packit d3f73b
		"and PROG_FILE to a pinned program. TYPE can be {cls, act}, where\n"
Packit d3f73b
		"\'cls\' is default. KEY is optional and can be inferred from the\n"
Packit d3f73b
		"section name, otherwise it needs to be provided.\n",
Packit d3f73b
		BPF_DEFAULT_CMD);
Packit d3f73b
}
Packit d3f73b
Packit d3f73b
static int bpf_num_env_entries(void)
Packit d3f73b
{
Packit d3f73b
	char **envp;
Packit d3f73b
	int num;
Packit d3f73b
Packit d3f73b
	for (num = 0, envp = environ; *envp != NULL; envp++)
Packit d3f73b
		num++;
Packit d3f73b
	return num;
Packit d3f73b
}
Packit d3f73b
Packit d3f73b
static int parse_bpf(struct exec_util *eu, int argc, char **argv)
Packit d3f73b
{
Packit d3f73b
	char **argv_run = argv_default, **envp_run, *tmp;
Packit d3f73b
	int ret, i, env_old, env_num, env_map;
Packit d3f73b
	const char *bpf_uds_name = NULL;
Packit d3f73b
	int fds[BPF_SCM_MAX_FDS] = {};
Packit d3f73b
	struct bpf_map_aux aux = {};
Packit d3f73b
Packit d3f73b
	if (argc == 0)
Packit d3f73b
		return 0;
Packit d3f73b
Packit d3f73b
	while (argc > 0) {
Packit d3f73b
		if (matches(*argv, "run") == 0) {
Packit d3f73b
			NEXT_ARG();
Packit d3f73b
			argv_run = argv;
Packit d3f73b
			break;
Packit d3f73b
		} else if (matches(*argv, "import") == 0) {
Packit d3f73b
			NEXT_ARG();
Packit d3f73b
			bpf_uds_name = *argv;
Packit d3f73b
		} else if (matches(*argv, "debug") == 0 ||
Packit d3f73b
			   matches(*argv, "dbg") == 0) {
Packit d3f73b
			if (bpf_trace_pipe())
Packit d3f73b
				fprintf(stderr,
Packit d3f73b
					"No trace pipe, tracefs not mounted?\n");
Packit d3f73b
			return -1;
Packit d3f73b
		} else if (matches(*argv, "graft") == 0) {
Packit d3f73b
			const char *bpf_map_path;
Packit d3f73b
			bool has_key = false;
Packit d3f73b
			uint32_t key;
Packit d3f73b
Packit d3f73b
			NEXT_ARG();
Packit d3f73b
			bpf_map_path = *argv;
Packit d3f73b
			NEXT_ARG();
Packit d3f73b
			if (matches(*argv, "key") == 0) {
Packit d3f73b
				NEXT_ARG();
Packit d3f73b
				if (get_unsigned(&key, *argv, 0)) {
Packit d3f73b
					fprintf(stderr, "Illegal \"key\"\n");
Packit d3f73b
					return -1;
Packit d3f73b
				}
Packit d3f73b
				has_key = true;
Packit d3f73b
				NEXT_ARG();
Packit d3f73b
			}
Packit d3f73b
			return bpf_graft_map(bpf_map_path, has_key ?
Packit d3f73b
					     &key : NULL, argc, argv);
Packit d3f73b
		} else {
Packit d3f73b
			explain();
Packit d3f73b
			return -1;
Packit d3f73b
		}
Packit d3f73b
Packit d3f73b
		NEXT_ARG_FWD();
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	if (!bpf_uds_name) {
Packit d3f73b
		fprintf(stderr, "bpf: No import parameter provided!\n");
Packit d3f73b
		explain();
Packit d3f73b
		return -1;
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	if (argv_run != argv_default && argc == 0) {
Packit d3f73b
		fprintf(stderr, "bpf: No run command provided!\n");
Packit d3f73b
		explain();
Packit d3f73b
		return -1;
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	ret = bpf_recv_map_fds(bpf_uds_name, fds, &aux, ARRAY_SIZE(fds));
Packit d3f73b
	if (ret < 0) {
Packit d3f73b
		fprintf(stderr, "bpf: Could not receive fds!\n");
Packit d3f73b
		return -1;
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	if (aux.num_ent == 0) {
Packit d3f73b
		envp_run = environ;
Packit d3f73b
		goto out;
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	env_old = bpf_num_env_entries();
Packit d3f73b
	env_num = env_old + aux.num_ent + 2;
Packit d3f73b
	env_map = env_old + 1;
Packit d3f73b
Packit d3f73b
	envp_run = malloc(sizeof(*envp_run) * env_num);
Packit d3f73b
	if (!envp_run) {
Packit d3f73b
		fprintf(stderr, "bpf: No memory left to allocate env!\n");
Packit d3f73b
		goto err;
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	for (i = 0; i < env_old; i++)
Packit d3f73b
		envp_run[i] = environ[i];
Packit d3f73b
Packit d3f73b
	ret = asprintf(&tmp, "BPF_NUM_MAPS=%u", aux.num_ent);
Packit d3f73b
	if (ret < 0)
Packit d3f73b
		goto err_free;
Packit d3f73b
Packit d3f73b
	envp_run[env_old] = tmp;
Packit d3f73b
Packit d3f73b
	for (i = env_map; i < env_num - 1; i++) {
Packit d3f73b
		ret = asprintf(&tmp, "BPF_MAP%u=%u",
Packit d3f73b
			       aux.ent[i - env_map].id,
Packit d3f73b
			       fds[i - env_map]);
Packit d3f73b
		if (ret < 0)
Packit d3f73b
			goto err_free_env;
Packit d3f73b
Packit d3f73b
		envp_run[i] = tmp;
Packit d3f73b
	}
Packit d3f73b
Packit d3f73b
	envp_run[env_num - 1] = NULL;
Packit d3f73b
out:
Packit d3f73b
	return execvpe(argv_run[0], argv_run, envp_run);
Packit d3f73b
Packit d3f73b
err_free_env:
Packit d3f73b
	for (--i; i >= env_old; i--)
Packit d3f73b
		free(envp_run[i]);
Packit d3f73b
err_free:
Packit d3f73b
	free(envp_run);
Packit d3f73b
err:
Packit d3f73b
	for (i = 0; i < aux.num_ent; i++)
Packit d3f73b
		close(fds[i]);
Packit d3f73b
	return -1;
Packit d3f73b
}
Packit d3f73b
Packit d3f73b
struct exec_util bpf_exec_util = {
Packit d3f73b
	.id		= "bpf",
Packit d3f73b
	.parse_eopt	= parse_bpf,
Packit d3f73b
};