/* change endianness of a register */ #define BPF_END 0xd0 /* flags for endianness conversion: */ #define BPF_TO_LE 0x00 /* convert to little-endian */ #define BPF_TO_BE 0x08 /* convert to big-endian */ #define BPF_FROM_LE BPF_TO_LE #define BPF_FROM_BE BPF_TO_BE
/* jmp encodings */ #define BPF_JNE 0x50 /* jump != */ #define BPF_JLT 0xa0 /* LT is unsigned, '<' */ #define BPF_JLE 0xb0 /* LE is unsigned, '<=' */ #define BPF_JSGT 0x60 /* SGT is signed '>', GT in x86 */ #define BPF_JSGE 0x70 /* SGE is signed '>=', GE in x86 */ #define BPF_JSLT 0xc0 /* SLT is signed, '<' */ #define BPF_JSLE 0xd0 /* SLE is signed, '<=' */ #define BPF_JCOND 0xe0 /* conditional pseudo jumps: may_goto, goto_or_nop */ #define BPF_CALL 0x80 /* function call */ #define BPF_EXIT 0x90 /* function return */
/* atomic op type fields (stored in immediate) */ #define BPF_FETCH 0x01 /* not an opcode on its own, used to build others */ #define BPF_XCHG (0xe0 | BPF_FETCH) /* atomic exchange */ #define BPF_CMPXCHG (0xf0 | BPF_FETCH) /* atomic compare-and-write */
/* Deprecated: use struct bpf_lpm_trie_key_u8 (when the "data" member is needed for *byteaccess)orstructbpf_lpm_trie_key_hdr(whenusinganalternativetypefor *thetrailingflexiblearraymember)instead.
*/ struct bpf_lpm_trie_key {
__u32 prefixlen; /* up to 32 for AF_INET, 128 for AF_INET6 */
__u8 data[0]; /* Arbitrary size */
};
/* Key of an a BPF_MAP_TYPE_LPM_TRIE entry, with trailing byte array. */ struct bpf_lpm_trie_key_u8 { union { struct bpf_lpm_trie_key_hdr hdr;
__u32 prefixlen;
};
__u8 data[]; /* Arbitrary size */
};
struct bpf_cgroup_storage_key {
__u64 cgroup_inode_id; /* cgroup inode id */
__u32 attach_type; /* program attach type (enum bpf_attach_type) */
};
enum bpf_cgroup_iter_order {
BPF_CGROUP_ITER_ORDER_UNSPEC = 0,
BPF_CGROUP_ITER_SELF_ONLY, /* process only a single object. */
BPF_CGROUP_ITER_DESCENDANTS_PRE, /* walk descendants in pre-order. */
BPF_CGROUP_ITER_DESCENDANTS_POST, /* walk descendants in post-order. */
BPF_CGROUP_ITER_ANCESTORS_UP, /* walk ancestors upward. */
};
/* At most one of cgroup_fd and cgroup_id can be non-zero. If *botharezero,thewalkstartsfromthedefaultcgroupv2 *root.Forwalkingv1hierarchy,oneshouldalwaysexplicitly *specifycgroup_fd.
*/
__u32 cgroup_fd;
__u64 cgroup_id;
} cgroup; /* Parameters of task iterators. */ struct {
__u32 tid;
__u32 pid;
__u32 pid_fd;
} task;
};
/* If BPF_F_STRICT_ALIGNMENT is used in BPF_PROG_LOAD command, the *verifierwillperformstrictalignmentcheckingasifthekernel *hasbeenbuiltwithCONFIG_EFFICIENT_UNALIGNED_ACCESSnotset, *andNET_IP_ALIGNdefinedto2.
*/ #define BPF_F_STRICT_ALIGNMENT (1U << 0)
/* If BPF_F_ANY_ALIGNMENT is used in BPF_PROG_LOAD command, the *verifierwillallowanyalignmentwhatsoever.Onplatforms *withstrictalignmentrequirementsforloadsandsstores(such *assparcandmips)theverifiervalidatesthatallloadsand *storesprovablyfollowthisrequirement.Thisflagturnsthat *checkingandenforcementoff. * *Itismostlyusedfortestingwhenwewanttovalidatethe *contextandmemoryaccessaspectsoftheverifier,butbecause *ofanunalignedaccessthealignmentcheckwouldtriggerbefore *theoneweareinterestedin.
*/ #define BPF_F_ANY_ALIGNMENT (1U << 1)
/* BPF_F_TEST_RND_HI32 is used in BPF_PROG_LOAD command for testing purpose. *Verifierdoessub-registerdef/useanalysisandidentifiesinstructionswhose *defonlymattersforlow32-bit,high32-bitisneverreferencedlater *throughimplicitzeroextension.ThereforeverifiernotifiesJITback-ends *thatitissafetoignoreclearinghigh32-bitfortheseinstructions.This *savessomeback-endsalotofcode-gen.Howeversuchoptimizationisnot *necessaryonsomearches,forexamplex86_64,arm64etc,whoseJITback-ends *hencehasn'tusedverifier'sanalysisresult.But,wereallywanttohavea *waytobeabletoverifythecorrectnessofthedescribedoptimizationon *x86_64onwhichtestsuitesarefrequentlyexercised. * *So,thisflagisintroduced.Onceitisset,verifierwillrandomizehigh *32-bitforthoseinstructionswhohasbeenidentifiedassafetoignorethem. *Then,ifverifierisnotdoingcorrectanalysis,suchrandomizationwill *regressteststoexposebugs.
*/ #define BPF_F_TEST_RND_HI32 (1U << 2)
/* The verifier internal test flag. Behavior is undefined */ #define BPF_F_TEST_STATE_FREQ (1U << 3)
/* If BPF_F_SLEEPABLE is used in BPF_PROG_LOAD command, the verifier will *restrictmapandhelperusageforsuchprograms.SleepableBPFprogramscan *onlybeattachedtohookswherekernelexecutioncontextallowssleeping. *Suchprogramsareallowedtousehelpersthatmaysleeplike *bpf_copy_from_user().
*/ #define BPF_F_SLEEPABLE (1U << 4)
/* If BPF_F_XDP_HAS_FRAGS is used in BPF_PROG_LOAD command, the loaded program *fullysupportxdpfrags.
*/ #define BPF_F_XDP_HAS_FRAGS (1U << 5)
/* If BPF_F_XDP_DEV_BOUND_ONLY is used in BPF_PROG_LOAD command, the loaded *programbecomesdevice-boundbutcanaccessXDPmetadata.
*/ #define BPF_F_XDP_DEV_BOUND_ONLY (1U << 6)
/* The verifier internal test flag. Behavior is undefined */ #define BPF_F_TEST_REG_INVARIANTS (1U << 7)
/* link_create.kprobe_multi.flags used in LINK_CREATE command for *BPF_TRACE_KPROBE_MULTIattachtypetocreatereturnprobe.
*/ enum {
BPF_F_KPROBE_MULTI_RETURN = (1U << 0)
};
/* link_create.uprobe_multi.flags used in LINK_CREATE command for *BPF_TRACE_UPROBE_MULTIattachtypetocreatereturnprobe.
*/ enum {
BPF_F_UPROBE_MULTI_RETURN = (1U << 0)
};
/* link_create.netfilter.flags used in LINK_CREATE command for *BPF_PROG_TYPE_NETFILTERtoenableIPpacketdefragmentation.
*/ #define BPF_F_NETFILTER_IP_DEFRAG (1U << 0)
/* When BPF ldimm64's insn[0].src_reg != 0 then this can have *thefollowingextensions: * *insn[0].src_reg:BPF_PSEUDO_MAP_[FD|IDX] *insn[0].imm:mapfdorfd_idx *insn[1].imm:0 *insn[0].off:0 *insn[1].off:0 *ldimm64rewrite:addressofmap *verifiertype:CONST_PTR_TO_MAP
*/ #define BPF_PSEUDO_MAP_FD 1 #define BPF_PSEUDO_MAP_IDX 5
/* flags for BPF_MAP_UPDATE_ELEM command */ enum {
BPF_ANY = 0, /* create new element or update existing */
BPF_NOEXIST = 1, /* create new element if it didn't exist */
BPF_EXIST = 2, /* update existing element */
BPF_F_LOCK = 4, /* spin_lock-ed map_lookup/map_update */
};
/* flags for BPF_MAP_CREATE command */ enum {
BPF_F_NO_PREALLOC = (1U << 0), /* Instead of having one common LRU list in the *BPF_MAP_TYPE_LRU_[PERCPU_]HASHmap,useapercpuLRUlist *whichcanscaleandperformbetter. *Note,theLRUnodes(includingfreenodes)cannotbemoved *acrossdifferentLRUlists.
*/
BPF_F_NO_COMMON_LRU = (1U << 1), /* Specify numa node during map creation */
BPF_F_NUMA_NODE = (1U << 2),
/* Flags for accessing BPF object from syscall side. */
BPF_F_RDONLY = (1U << 3),
BPF_F_WRONLY = (1U << 4),
/* Flag for stack_map, store build_id+offset instead of pointer */
BPF_F_STACK_BUILD_ID = (1U << 5),
/* Zero-initialize hash function seed. This should only be used for testing. */
BPF_F_ZERO_SEED = (1U << 6),
/* Flags for accessing BPF object from program side. */
BPF_F_RDONLY_PROG = (1U << 7),
BPF_F_WRONLY_PROG = (1U << 8),
/* Clone map from listener for newly accepted socket */
BPF_F_CLONE = (1U << 9),
/* If set, run the test on the cpu specified by bpf_attr.test.cpu */ #define BPF_F_TEST_RUN_ON_CPU (1U << 0) /* If set, XDP frames will be transmitted after processing */ #define BPF_F_TEST_XDP_LIVE_FRAMES (1U << 1) /* If set, apply CHECKSUM_COMPLETE to skb and validate the checksum */ #define BPF_F_TEST_SKB_CHECKSUM_COMPLETE (1U << 2)
/* type for BPF_ENABLE_STATS */ enum bpf_stats_type { /* enabled run_time_ns and run_cnt */
BPF_STATS_RUN_TIME = 0,
};
enum bpf_stack_build_id_status { /* user space need an empty entry to identify end of a trace */
BPF_STACK_BUILD_ID_EMPTY = 0, /* with valid build_id and offset */
BPF_STACK_BUILD_ID_VALID = 1, /* couldn't get build_id, fallback to ip */
BPF_STACK_BUILD_ID_IP = 2,
};
union bpf_attr { struct { /* anonymous struct used by BPF_MAP_CREATE command */
__u32 map_type; /* one of enum bpf_map_type */
__u32 key_size; /* size of key in bytes */
__u32 value_size; /* size of value in bytes */
__u32 max_entries; /* max number of entries in a map */
__u32 map_flags; /* BPF_MAP_CREATE related *flagsdefinedabove.
*/
__u32 inner_map_fd; /* fd pointing to the inner map */
__u32 numa_node; /* numa node (effective only if *BPF_F_NUMA_NODEisset).
*/
char map_name[BPF_OBJ_NAME_LEN];
__u32 map_ifindex; /* ifindex of netdev to create on */
__u32 btf_fd; /* fd pointing to a BTF type data */
__u32 btf_key_type_id; /* BTF type_id of the key */
__u32 btf_value_type_id; /* BTF type_id of the value */
__u32 btf_vmlinux_value_type_id;/* BTF type_id of a kernel- *structstoredasthe *mapvalue
*/ /* Any per-map-type extra fields * *BPF_MAP_TYPE_BLOOM_FILTER-thelowest4bitsindicatethe *numberofhashfunctions(if0,thebloomfilterwilldefault *tousing5hashfunctions). * *BPF_MAP_TYPE_ARENA-containstheaddresswhereuserspace *isgoingtommap()thearena.Ithastobepagealigned.
*/
__u64 map_extra;
__s32 value_type_btf_obj_fd; /* fd pointing to a BTF *typedatafor *btf_vmlinux_value_type_id.
*/ /* BPF token FD to use with BPF_MAP_CREATE operation. *Ifprovided,map_flagsshouldhaveBPF_F_TOKEN_FDflagset.
*/
__s32 map_token_fd;
};
struct { /* anonymous struct used by BPF_MAP_*_ELEM and BPF_MAP_FREEZE commands */
__u32 map_fd;
__aligned_u64 key;
union {
__aligned_u64 value;
__aligned_u64 next_key;
};
__u64 flags;
};
struct { /* anonymous struct used by BPF_PROG_LOAD command */
__u32 prog_type; /* one of enum bpf_prog_type */
__u32 insn_cnt;
__aligned_u64 insns;
__aligned_u64 license;
__u32 log_level; /* verbosity level of verifier */
__u32 log_size; /* size of user buffer */
__aligned_u64 log_buf; /* user supplied buffer */
__u32 kern_version; /* not used */
__u32 prog_flags;
char prog_name[BPF_OBJ_NAME_LEN];
__u32 prog_ifindex; /* ifindex of netdev to prep for */ /* For some prog types expected attach type must be known at *loadtimetoverifyattachtypespecificpartsofprog *(contextaccesses,allowedhelpers,etc).
*/
__u32 expected_attach_type;
__u32 prog_btf_fd; /* fd pointing to BTF type data */
__u32 func_info_rec_size; /* userspace bpf_func_info size */
__aligned_u64 func_info; /* func info */
__u32 func_info_cnt; /* number of bpf_func_info records */
__u32 line_info_rec_size; /* userspace bpf_line_info size */
__aligned_u64 line_info; /* line info */
__u32 line_info_cnt; /* number of bpf_line_info records */
__u32 attach_btf_id; /* in-kernel BTF type id to attach to */
union { /* valid prog_fd to attach to bpf prog */
__u32 attach_prog_fd; /* or valid module BTF object fd or 0 to attach to vmlinux */
__u32 attach_btf_obj_fd;
};
__u32 core_relo_cnt; /* number of bpf_core_relo */
__aligned_u64 fd_array; /* array of FDs */
__aligned_u64 core_relos;
__u32 core_relo_rec_size; /* sizeof(struct bpf_core_relo) */ /* output: actual total log contents size (including termintaing zero). *Itcouldbebothlargerthanoriginallog_size(iflogwas *truncated),orsmaller(iflogbufferwasn'tfilledcompletely).
*/
__u32 log_true_size; /* BPF token FD to use with BPF_PROG_LOAD operation. *Ifprovided,prog_flagsshouldhaveBPF_F_TOKEN_FDflagset.
*/
__s32 prog_token_fd; /* The fd_array_cnt can be used to pass the length of the *fd_arrayarray.Inthiscaseallthe[map]filedescriptors *passedinthisarraywillbeboundtotheprogram,evenif *themapsarenotreferenceddirectly.Thefunctionalityis *similartotheBPF_PROG_BIND_MAPsyscall,butmapscanbe *usedbytheverifierduringtheprogramload.Ifprovided, *thenthefd_array[0,...,fd_array_cnt-1]isexpectedtobe *continuous.
*/
__u32 fd_array_cnt;
};
struct { /* anonymous struct used by BPF_OBJ_* commands */
__aligned_u64 pathname;
__u32 bpf_fd;
__u32 file_flags; /* Same as dirfd in openat() syscall; see openat(2) *manpagefordetailsofpathFDandpathnamesemantics; *path_fdshouldaccompaniedbyBPF_F_PATH_FDflagsetin *file_flagsfield,otherwiseitshouldbesettozero; *ifBPF_F_PATH_FDflagisnotset,AT_FDCWDisassumed.
*/
__s32 path_fd;
};
struct { /* anonymous struct used by BPF_PROG_ATTACH/DETACH commands */
union {
__u32 target_fd; /* target object to attach to or ... */
__u32 target_ifindex; /* target ifindex */
};
__u32 attach_bpf_fd;
__u32 attach_type;
__u32 attach_flags;
__u32 replace_bpf_fd;
union {
__u32 relative_fd;
__u32 relative_id;
};
__u64 expected_revision;
};
struct { /* anonymous struct used by BPF_PROG_TEST_RUN command */
__u32 prog_fd;
__u32 retval;
__u32 data_size_in; /* input: len of data_in */
__u32 data_size_out; /* input/output: len of data_out *returnsENOSPCifdata_out *istoosmall.
*/
__aligned_u64 data_in;
__aligned_u64 data_out;
__u32 repeat;
__u32 duration;
__u32 ctx_size_in; /* input: len of ctx_in */
__u32 ctx_size_out; /* input/output: len of ctx_out *returnsENOSPCifctx_out *istoosmall.
*/
__aligned_u64 ctx_in;
__aligned_u64 ctx_out;
__u32 flags;
__u32 cpu;
__u32 batch_size;
} test;
struct { /* anonymous struct used by BPF_*_GET_*_ID */
union {
__u32 start_id;
__u32 prog_id;
__u32 map_id;
__u32 btf_id;
__u32 link_id;
};
__u32 next_id;
__u32 open_flags;
__s32 fd_by_id_token_fd;
};
struct { /* anonymous struct used by BPF_OBJ_GET_INFO_BY_FD */
__u32 bpf_fd;
__u32 info_len;
__aligned_u64 info;
} info;
struct { /* struct used by BPF_LINK_CREATE command */
union {
__u32 prog_fd; /* eBPF program to attach */
__u32 map_fd; /* struct_ops to attach */
};
union {
__u32 target_fd; /* target object to attach to or ... */
__u32 target_ifindex; /* target ifindex */
};
__u32 attach_type; /* attach type */
__u32 flags; /* extra flags */
union {
__u32 target_btf_id; /* btf_id of target to attach to */ struct {
__aligned_u64 iter_info; /* extra bpf_iter_link_info */
__u32 iter_info_len; /* iter_info length */
}; struct { /* black box user-provided value passed through *toBPFprogramattheexecutiontimeand *accessiblethroughbpf_get_attach_cookie()BPFhelper
*/
__u64 bpf_cookie;
} perf_event; struct {
__u32 flags;
__u32 cnt;
__aligned_u64 syms;
__aligned_u64 addrs;
__aligned_u64 cookies;
} kprobe_multi; struct { /* this is overlaid with the target_btf_id above. */
__u32 target_btf_id; /* black box user-provided value passed through *toBPFprogramattheexecutiontimeand *accessiblethroughbpf_get_attach_cookie()BPFhelper
*/
__u64 cookie;
} tracing; struct {
__u32 pf;
__u32 hooknum;
__s32 priority;
__u32 flags;
} netfilter; struct {
union {
__u32 relative_fd;
__u32 relative_id;
};
__u64 expected_revision;
} tcx; struct {
__aligned_u64 path;
__aligned_u64 offsets;
__aligned_u64 ref_ctr_offsets;
__aligned_u64 cookies;
__u32 cnt;
__u32 flags;
__u32 pid;
} uprobe_multi; struct {
union {
__u32 relative_fd;
__u32 relative_id;
};
__u64 expected_revision;
} netkit; struct {
union {
__u32 relative_fd;
__u32 relative_id;
};
__u64 expected_revision;
} cgroup;
};
} link_create;
struct { /* struct used by BPF_LINK_UPDATE command */
__u32 link_fd; /* link fd */
union { /* new program fd to update link with */
__u32 new_prog_fd; /* new struct_ops map fd to update link with */
__u32 new_map_fd;
};
__u32 flags; /* extra flags */
union { /* expected link's program fd; is specified only if *BPF_F_REPLACEflagissetinflags.
*/
__u32 old_prog_fd; /* expected link's map fd; is specified only *ifBPF_F_REPLACEflagisset.
*/
__u32 old_map_fd;
};
} link_update;
struct {
__u32 link_fd;
} link_detach;
struct { /* struct used by BPF_ENABLE_STATS command */
__u32 type;
} enable_stats;
struct { /* struct used by BPF_ITER_CREATE command */
__u32 link_fd;
__u32 flags;
} iter_create;
struct { /* struct used by BPF_PROG_BIND_MAP command */
__u32 prog_fd;
__u32 map_fd;
__u32 flags; /* extra flags */
} prog_bind_map;
struct { /* struct used by BPF_TOKEN_CREATE command */
__u32 flags;
__u32 bpffs_fd;
} token_create;
***bpf_map_lookup_elem**\(*map*,**&**\*inode*)exceptthis *helperenforcesthekeymustbeaninodeandthemapmustalso *bea**BPF_MAP_TYPE_INODE_STORAGE**. * *Underneath,thevalueisstoredlocallyat*inode*insteadof *the*map*.The*map*isusedasthebpf-local-storage *"type".Thebpf-local-storage"type"(i.e.the*map*)is *searchedagainstallbpf_local_storageresidingat*inode*. * *Anoptional*flags*(**BPF_LOCAL_STORAGE_GET_F_CREATE**)canbe *usedsuchthatanewbpf_local_storagewillbe *createdifonedoesnotexist.*value*canbeused *togetherwith**BPF_LOCAL_STORAGE_GET_F_CREATE**tospecify *theinitialvalueofabpf_local_storage.If*value*is ***NULL**,thenewbpf_local_storagewillbezeroinitialized. *Return *Abpf_local_storagepointerisreturnedonsuccess. * ***NULL**ifnotfoundortherewasanerrorinadding *anewbpf_local_storage. * *intbpf_inode_storage_delete(structbpf_map*map,void*inode) *Description *Deleteabpf_local_storagefroman*inode*. *Return *0onsuccess. * ***-ENOENT**ifthebpf_local_storagecannotbefound. * *longbpf_d_path(structpath*path,char*buf,u32sz) *Description *Returnfullpathforgiven**structpath**object,which *needstobethekernelBTF*path*object.Thepathis *returnedintheprovidedbuffer*buf*ofsize*sz*and *iszeroterminated. * *Return *Onsuccess,thestrictlypositivelengthofthestring, *includingthetrailingNULcharacter.Onerror,anegative *value. * *longbpf_copy_from_user(void*dst,u32size,constvoid*user_ptr) *Description *Read*size*bytesfromuserspaceaddress*user_ptr*andstore *thedatain*dst*.Thisisawrapperof**copy_from_user**\(). *Return *0onsuccess,oranegativeerrorincaseoffailure. * *longbpf_snprintf_btf(char*str,u32str_size,structbtf_ptr*ptr,u32btf_ptr_size,u64flags) *Description *UseBTFtostoreastringrepresentationof*ptr*->ptrin*str*, *using*ptr*->type_id.Thisvalueshouldspecifythetype *that*ptr*->ptrpointsto.LLVM__builtin_btf_type_id(type,1) *canbeusedtolookupvmlinuxBTFtypeids.Traversingthe *datastructureusingBTF,thetypeinformationandvaluesare *storedinthefirst*str_size*-1bytesof*str*.Safecopyof *thepointerdataiscarriedouttoavoidkernelcrashesduring *operation.Smallertypescanusestringspaceonthestack; *largerprogramscanusemapdatatostorethestring *representation. * *Thestringcanbesubsequentlysharedwithuserspacevia *bpf_perf_event_output()orringbufferinterfaces. *bpf_trace_printk()istobeavoidedasitplacestoosmall *alimitonstringsizetobeuseful. * **flags*isacombinationof * ***BTF_F_COMPACT** *noformattingaroundtypeinformation ***BTF_F_NONAME** *nostruct/unionmembernames/types ***BTF_F_PTR_RAW** *showraw(unobfuscated)pointervalues; *equivalenttoprintkspecifier%px. ***BTF_F_ZERO** *showzero-valuedstruct/unionmembers;they *arenotdisplayedbydefault * *Return *Thenumberofbytesthatwerewritten(orwouldhavebeen *writtenifoutputhadtobetruncatedduetostringsize), *oranegativeerrorincasesoffailure. * *longbpf_seq_printf_btf(structseq_file*m,structbtf_ptr*ptr,u32ptr_size,u64flags) *Description *UseBTFtowritetoseq_writeastringrepresentationof **ptr*->ptr,using*ptr*->type_idasperbpf_snprintf_btf(). **flags*areidenticaltothoseusedforbpf_snprintf_btf. *Return *0onsuccessoranegativeerrorincaseoffailure. * *u64bpf_skb_cgroup_classid(structsk_buff*skb) *Description *See**bpf_get_cgroup_classid**\()forthemaindescription. *Thishelperdiffersfrom**bpf_get_cgroup_classid**\()inthat *thecgroupv1net_clsclassisretrievedonlyfromthe*skb*'s *associatedsocketinsteadofthecurrentprocess. *Return *Theidisreturnedor0incasetheidcouldnotberetrieved. * *longbpf_redirect_neigh(u32ifindex,structbpf_redir_neigh*params,intplen,u64flags) *Description *Redirectthepackettoanothernetdeviceofindex*ifindex* *andfillinL2addressesfromneighboringsubsystem.Thishelper *issomewhatsimilarto**bpf_redirect**\(),exceptthatit *populatesL2addressesaswell,meaning,internally,thehelper *reliesontheneighborlookupfortheL2addressofthenexthop. * *ThehelperwillperformaFIBlookupbasedontheskb's *networkingheadertogettheaddressofthenexthop,unless *thisissuppliedbythecallerinthe*params*argument.The **plen*argumentindicatesthelenof*params*andshouldbeset *to0if*params*isNULL. * *The*flags*argumentisreservedandmustbe0.Thehelperis *currentlyonlysupportedfortcBPFprogramtypes,andenabled *forIPv4andIPv6protocols. *Return *Thehelperreturns**TC_ACT_REDIRECT**onsuccessor ***TC_ACT_SHOT**onerror. * *void*bpf_per_cpu_ptr(constvoid*percpu_ptr,u32cpu) *Description *Takeapointertoapercpuksym,*percpu_ptr*,andreturna *pointertothepercpukernelvariableon*cpu*.Aksymisan *externvariabledecoratedwith'__ksym'.Forksym,thereisa *globalvar(eitherstaticorglobal)definedofthesamename *inthekernel.Theksymispercpuiftheglobalvarispercpu. *Thereturnedpointerpointstotheglobalpercpuvaron*cpu*. * *bpf_per_cpu_ptr()hasthesamesemanticasper_cpu_ptr()inthe *kernel,exceptthatbpf_per_cpu_ptr()mayreturnNULL.This *happensif*cpu*islargerthannr_cpu_ids.Thecallerof *bpf_per_cpu_ptr()mustcheckthereturnedvalue. *Return *Apointerpointingtothekernelpercpuvariableon*cpu*,or *NULL,if*cpu*isinvalid. * *void*bpf_this_cpu_ptr(constvoid*percpu_ptr) *Description *Takeapointertoapercpuksym,*percpu_ptr*,andreturna *pointertothepercpukernelvariableonthiscpu.Seethe *descriptionof'ksym'in**bpf_per_cpu_ptr**\(). * *bpf_this_cpu_ptr()hasthesamesemanticasthis_cpu_ptr()in *thekernel.Differentfrom**bpf_per_cpu_ptr**\(),itwould *neverreturnNULL. *Return *Apointerpointingtothekernelpercpuvariableonthiscpu. * *longbpf_redirect_peer(u32ifindex,u64flags) *Description *Redirectthepackettoanothernetdeviceofindex*ifindex*. *Thishelperissomewhatsimilarto**bpf_redirect**\(),except *thattheredirectionhappenstothe*ifindex*'peerdeviceand *thenetnsswitchtakesplacefromingresstoingresswithout *goingthroughtheCPU'sbacklogqueue. * **skb*\**->mark**and*skb*\**->tstamp**arenotclearedduring *thenetnsswitch. * *The*flags*argumentisreservedandmustbe0.Thehelperis *currentlyonlysupportedfortcBPFprogramtypesatthe *ingresshookandforvethandnetkittargetdevicetypes.The *peerdevicemustresideinadifferentnetworknamespace. *Return *Thehelperreturns**TC_ACT_REDIRECT**onsuccessor ***TC_ACT_SHOT**onerror. * *void*bpf_task_storage_get(structbpf_map*map,structtask_struct*task,void*value,u64flags) *Description *Getabpf_local_storagefromthe*task*. * *Logically,itcouldbethoughtofasgettingthevaluefrom *a*map*with*task*asthe**key**.Fromthis *perspective,theusageisnotmuchdifferentfrom ***bpf_map_lookup_elem**\(*map*,**&**\*task*)exceptthis *helperenforcesthekeymustbeatask_structandthemapmustalso *bea**BPF_MAP_TYPE_TASK_STORAGE**. * *Underneath,thevalueisstoredlocallyat*task*insteadof *the*map*.The*map*isusedasthebpf-local-storage *"type".Thebpf-local-storage"type"(i.e.the*map*)is *searchedagainstallbpf_local_storageresidingat*task*. * *Anoptional*flags*(**BPF_LOCAL_STORAGE_GET_F_CREATE**)canbe *usedsuchthatanewbpf_local_storagewillbe *createdifonedoesnotexist.*value*canbeused *togetherwith**BPF_LOCAL_STORAGE_GET_F_CREATE**tospecify *theinitialvalueofabpf_local_storage.If*value*is ***NULL**,thenewbpf_local_storagewillbezeroinitialized. *Return *Abpf_local_storagepointerisreturnedonsuccess. * ***NULL**ifnotfoundortherewasanerrorinadding *anewbpf_local_storage. * *longbpf_task_storage_delete(structbpf_map*map,structtask_struct*task) *Description *Deleteabpf_local_storagefroma*task*. *Return *0onsuccess. * ***-ENOENT**ifthebpf_local_storagecannotbefound. * *structtask_struct*bpf_get_current_task_btf(void) *Description *ReturnaBTFpointertothe"current"task. *Thispointercanalsobeusedinhelpersthatacceptan **ARG_PTR_TO_BTF_ID*oftype*task_struct*. *Return *Pointertothecurrenttask. * *longbpf_bprm_opts_set(structlinux_binprm*bprm,u64flags) *Description *Setorclearcertainoptionson*bprm*: * ***BPF_F_BPRM_SECUREEXEC**Setthesecureexecbit *whichsetsthe**AT_SECURE**auxvforglibc.Thebit *isclearediftheflagisnotspecified. *Return ***-EINVAL**ifinvalid*flags*arepassed,zerootherwise. * *u64bpf_ktime_get_coarse_ns(void) *Description *Returnacoarse-grainedversionofthetimeelapsedsince *systemboot,innanoseconds.Doesnotincludetimethesystem *wassuspended. * *See:**clock_gettime**\(**CLOCK_MONOTONIC_COARSE**) *Return *Current*ktime*. * *longbpf_ima_inode_hash(structinode*inode,void*dst,u32size) *Description *ReturnsthestoredIMAhashofthe*inode*(ifit'savailable). *Ifthehashislargerthan*size*,thenonly*size* *byteswillbecopiedto*dst* *Return *The**hash_algo**isreturnedonsuccess, ***-EOPNOTSUPP**ifIMAisdisabledor**-EINVAL**if *invalidargumentsarepassed. * *structsocket*bpf_sock_from_file(structfile*file) *Description *Ifthegivenfilerepresentsasocket,returnstheassociated *socket. *Return *ApointertoastructsocketonsuccessorNULLifthefileis *notasocket. * *longbpf_check_mtu(void*ctx,u32ifindex,u32*mtu_len,s32len_diff,u64flags) *Description *CheckpacketsizeagainstexceedingMTUofnetdevice(based *on*ifindex*).Thishelperwilllikelybeusedincombination *withhelpersthatadjust/changethepacketsize. * *Theargument*len_diff*canbeusedforqueryingwithaplanned *sizechange.ThisallowstocheckMTUpriortochangingpacket *ctx.Providinga*len_diff*adjustmentthatislargerthanthe *actualpacketsize(resultinginnegativepacketsize)willin *principlenotexceedtheMTU,whichiswhyitisnotconsidered *afailure.OtherBPFhelpersareneededforperformingthe *plannedsizechange;thereforetheresponsibilityforcatching *anegativepacketsizebelongsinthosehelpers. * *Specifying*ifindex*zeromeanstheMTUcheckisperformed *againstthecurrentnetdevice.Thisispracticalifthisisn't *usedpriortoredirect. * *Oninput*mtu_len*mustbeavalidpointer,elseverifierwill *rejectBPFprogram.Ifthevalue*mtu_len*isinitializedto *zerothenthectxpacketsizeisuse.Whenvalue*mtu_len*is *providedasinputthisspecifytheL3lengththattheMTUcheck *isdoneagainst.RememberXDPandTClengthoperateatL2,but *thisvalueisL3asthiscorrelatetoMTUandIP-headertot_len *valueswhichareL3(similarbehaviorasbpf_fib_lookup). * *TheLinuxkernelroutetablecanconfigureMTUsonamore *specificperroutelevel,whichisnotprovidedbythishelper. *ForroutelevelMTUchecksusethe**bpf_fib_lookup**\() *helper. * **ctx*iseither**structxdp_md**forXDPprogramsor ***structsk_buff**fortccls_actprograms. * *The*flags*argumentcanbeacombinationofoneormoreofthe *followingvalues: * ***BPF_MTU_CHK_SEGS** *Thisflagwillonlyworksfor*ctx***structsk_buff**. *Ifpacketcontextcontainsextrapacketsegmentbuffers *(oftenknowsasGSOskb),thenMTUcheckisharderto *checkatthispoint,becauseintransmitpathitis *possiblefortheskbpackettogetre-segmented *(dependingonnetdevicefeatures).Thiscouldstillbe *aMTUviolation,sothisflagenablesperformingMTU *checkagainstsegments,withadifferentviolation *returncodetotellitapart.Checkcannotuselen_diff. * *Onreturn*mtu_len*pointercontainstheMTUvalueofthenet *device.RememberthenetdeviceconfiguredMTUistheL3size, *whichisreturnedhereandXDPandTClengthoperateatL2. *Helpertakethisintoaccountforyou,butrememberwhenusing *MTUvalueinyourBPF-code. * *Return **0onsuccess,andpopulateMTUvaluein*mtu_len*pointer. * **<0ifanyinputargumentisinvalid(*mtu_len*notupdated) * *MTUviolationsreturnpositivevalues,butalsopopulateMTU *valuein*mtu_len*pointer,asthiscanbeneededfor *implementingPMTUhanding: * ****BPF_MTU_CHK_RET_FRAG_NEEDED** ****BPF_MTU_CHK_RET_SEGS_TOOBIG** * *longbpf_for_each_map_elem(structbpf_map*map,void*callback_fn,void*callback_ctx,u64flags) *Description *Foreachelementin**map**,call**callback_fn**functionwith ***map**,**callback_ctx**andothermap-specificparameters. *The**callback_fn**shouldbeastaticfunctionand *the**callback_ctx**shouldbeapointertothestack. *The**flags**isusedtocontrolcertainaspectsofthehelper. *Currently,the**flags**mustbe0. * *Thefollowingarealistofsupportedmaptypesandtheir *respectiveexpectedcallbacksignatures: * *BPF_MAP_TYPE_HASH,BPF_MAP_TYPE_PERCPU_HASH, *BPF_MAP_TYPE_LRU_HASH,BPF_MAP_TYPE_LRU_PERCPU_HASH, *BPF_MAP_TYPE_ARRAY,BPF_MAP_TYPE_PERCPU_ARRAY * *long(\*callback_fn)(structbpf_map\*map,constvoid\*key,void\*value,void\*ctx); * *Forper_cpumaps,themap_valueisthevalueonthecpuwherethe *bpf_progisrunning. * *If**callback_fn**return0,thehelperwillcontinuetothenext *element.Ifreturnvalueis1,thehelperwillskiptherestof *elementsandreturn.Otherreturnvaluesarenotusednow. * *Return *Thenumberoftraversedmapelementsforsuccess,**-EINVAL**for *invalid**flags**. * *longbpf_snprintf(char*str,u32str_size,constchar*fmt,u64*data,u32data_len) *Description *Outputsastringintothe**str**bufferofsize**str_size** *basedonaformatstringstoredinaread-onlymappointedby ***fmt**. * *Eachformatspecifierin**fmt**correspondstooneu64element *inthe**data**array.Forstringsandpointerswherepointees *areaccessed,onlythepointervaluesarestoredinthe*data* *array.The*data_len*isthesizeof*data*inbytes-mustbe *amultipleof8. * *Formats**%s**and**%p{i,I}{4,6}**requiretoreadkernel *memory.Readingkernelmemorymayfailduetoeitherinvalid *addressorvalidaddressbutrequiringamajormemoryfault.If *readingkernelmemoryfails,thestringfor**%s**willbean *emptystring,andtheipaddressfor**%p{i,I}{4,6}**willbe0. *Notreturningerrortobpfprogramisconsistentwithwhat ***bpf_trace_printk**\()doesfornow. * *Return *Thestrictlypositivelengthoftheformattedstring,including *thetrailingzerocharacter.Ifthereturnvalueisgreaterthan ***str_size**,**str**containsatruncatedstring,guaranteedto *bezero-terminatedexceptwhen**str_size**is0. * *Or**-EBUSY**iftheper-CPUmemorycopybufferisbusy. * *longbpf_sys_bpf(u32cmd,void*attr,u32attr_size) *Description *Executebpfsyscallwithgivenarguments. *Return *Asyscallresult. * *longbpf_btf_find_by_name_kind(char*name,intname_sz,u32kind,intflags) *Description *FindBTFtypewithgivennameandkindinvmlinuxBTForinmodule'sBTFs. *Return *Returnsbtf_idandbtf_obj_fdinlowerandupper32bits. * *longbpf_sys_close(u32fd) *Description *ExecuteclosesyscallforgivenFD. *Return *Asyscallresult. * *longbpf_timer_init(structbpf_timer*timer,structbpf_map*map,u64flags) *Description *Initializethetimer. *First4bitsof*flags*specifyclockid. *OnlyCLOCK_MONOTONIC,CLOCK_REALTIME,CLOCK_BOOTTIMEareallowed. *Allotherbitsof*flags*arereserved. *Theverifierwillrejecttheprogramif*timer*isnotfrom *thesame*map*. *Return *0onsuccess. ***-EBUSY**if*timer*isalreadyinitialized. ***-EINVAL**ifinvalid*flags*arepassed. ***-EPERM**if*timer*isinamapthatdoesn'thaveanyuserreferences. *Theuserspaceshouldeitherholdafiledescriptortoamapwithtimers *orpinsuchmapinbpffs.Whenmapisunpinnedorfiledescriptoris *closedalltimersinthemapwillbecancelledandfreed. * *longbpf_timer_set_callback(structbpf_timer*timer,void*callback_fn) *Description *Configurethetimertocall*callback_fn*staticfunction. *Return *0onsuccess. ***-EINVAL**if*timer*wasnotinitializedwithbpf_timer_init()earlier. ***-EPERM**if*timer*isinamapthatdoesn'thaveanyuserreferences. *Theuserspaceshouldeitherholdafiledescriptortoamapwithtimers *orpinsuchmapinbpffs.Whenmapisunpinnedorfiledescriptoris *closedalltimersinthemapwillbecancelledandfreed. * *longbpf_timer_start(structbpf_timer*timer,u64nsecs,u64flags) *Description *SettimerexpirationNnanosecondsfromthecurrenttime.The *configuredcallbackwillbeinvokedinsoftirqcontextonsomecpu *andwillnotrepeatunlessanotherbpf_timer_start()ismade. *Insuchcasethenextinvocationcanmigratetoadifferentcpu. *Sincestructbpf_timerisafieldinsidemapelementthemap *ownsthetimer.Thebpf_timer_set_callback()willincrementrefcnt *ofBPFprogramtomakesurethatcallback_fncodestaysvalid. *Whenuserspacereferencetoamapreacheszeroalltimers *inamaparecancelledandcorrespondingprogram'srefcntsare *decremented.ThisisdonetomakesurethatCtrl-Cofauser *processdoesn'tleaveanytimersrunning.Ifmapispinnedin *bpffsthecallback_fncanre-armitselfindefinitely. *bpf_map_update/delete_elem()helpersanduserspacesys_bpfcommands *cancelandfreethetimerinthegivenmapelement. *Themapcancontaintimersthatinvokecallback_fn-sfromdifferent *programs.Thesamecallback_fncanservedifferenttimersfrom *differentmapsifkey/valuelayoutmatchesacrossmaps. *Everybpf_timer_set_callback()canhavedifferentcallback_fn. * **flags*canbeoneof: * ***BPF_F_TIMER_ABS** *Startthetimerinabsoluteexpirevalueinsteadofthe *defaultrelativeone. ***BPF_F_TIMER_CPU_PIN** *TimerwillbepinnedtotheCPUofthecaller. * *Return *0onsuccess. ***-EINVAL**if*timer*wasnotinitializedwithbpf_timer_init()earlier *orinvalid*flags*arepassed. * *longbpf_timer_cancel(structbpf_timer*timer) *Description *Cancelthetimerandwaitforcallback_fntofinishifitwasrunning. *Return *0ifthetimerwasnotactive. *1ifthetimerwasactive. ***-EINVAL**if*timer*wasnotinitializedwithbpf_timer_init()earlier. ***-EDEADLK**ifcallback_fntriedtocallbpf_timer_cancel()onits *owntimerwhichwouldhaveledtoadeadlockotherwise. * *u64bpf_get_func_ip(void*ctx) *Description *Getaddressofthetracedfunction(fortracingandkprobeprograms). * *Whencalledforkprobeprogramattachedasuprobeitreturns *probeaddressforbothentryandreturnuprobe. * *Return *Addressofthetracedfunctionforkprobe. *0forkprobesplacedwithinthefunction(notattheentry). *Addressoftheprobeforuprobeandreturnuprobe. * *u64bpf_get_attach_cookie(void*ctx) *Description *Getbpf_cookievalueprovided(optionally)duringtheprogram *attachment.Itmightbedifferentforeachindividual *attachment,evenifBPFprogramitselfisthesame. *ExpectsBPFprogramcontext*ctx*asafirstargument. * *Supportedforthefollowingprogramtypes: *-kprobe/uprobe; *-tracepoint; *-perf_event. *Return *ValuespecifiedbyuseratBPFlinkcreation/attachmenttime *or0,ifitwasnotspecified. * *longbpf_task_pt_regs(structtask_struct*task) *Description *Getthestructpt_regsassociatedwith**task**. *Return *Apointertostructpt_regs. * *longbpf_get_branch_snapshot(void*entries,u32size,u64flags) *Description *GetbranchtracefromhardwareengineslikeIntelLBR.The *hardwareengineisstoppedshortlyafterthehelperis *called.Therefore,theuserneedtofilterbranchentries *basedontheactualusecase.Tocapturebranchtrace *beforethetriggerpointoftheBPFprogram,thehelper *shouldbecalledatthebeginningoftheBPFprogram. * *Thedataisstoredasstructperf_branch_entryintooutput *buffer*entries*.*size*isthesizeof*entries*inbytes. **flags*isreservedfornowandmustbezero. * *Return *Onsuccess,numberofbyteswrittento*buf*.Onerror,a *negativevalue. * ***-EINVAL**if*flags*isnotzero. * ***-ENOENT**ifarchitecturedoesnotsupportbranchrecords. * *longbpf_trace_vprintk(constchar*fmt,u32fmt_size,constvoid*data,u32data_len) *Description *Behaveslike**bpf_trace_printk**\()helper,buttakesanarrayofu64 *toformatandcanhandlemoreformatargsasaresult. * *Argumentsaretobeusedasin**bpf_seq_printf**\()helper. *Return *Thenumberofbyteswrittentothebuffer,oranegativeerror *incaseoffailure. * *structunix_sock*bpf_skc_to_unix_sock(void*sk) *Description *Dynamicallycasta*sk*pointertoa*unix_sock*pointer. *Return **sk*ifcastingisvalid,or**NULL**otherwise. * *longbpf_kallsyms_lookup_name(constchar*name,intname_sz,intflags,u64*res) *Description *Gettheaddressofakernelsymbol,returnedin*res*.*res*is *setto0ifthesymbolisnotfound. *Return *Onsuccess,zero.Onerror,anegativevalue. * ***-EINVAL**if*flags*isnotzero. * ***-EINVAL**ifstring*name*isnotthesamesizeas*name_sz*. * ***-ENOENT**ifsymbolisnotfound. * ***-EPERM**ifcallerdoesnothavepermissiontoobtainkerneladdress. * *longbpf_find_vma(structtask_struct*task,u64addr,void*callback_fn,void*callback_ctx,u64flags) *Description *Findvmaof*task*thatcontains*addr*,call*callback_fn* *functionwith*task*,*vma*,and*callback_ctx*. *The*callback_fn*shouldbeastaticfunctionand *the*callback_ctx*shouldbeapointertothestack. *The*flags*isusedtocontrolcertainaspectsofthehelper. *Currently,the*flags*mustbe0. * *Theexpectedcallbacksignatureis * *long(\*callback_fn)(structtask_struct\*task,structvm_area_struct\*vma,void\*callback_ctx); * *Return *0onsuccess. ***-ENOENT**if*task->mm*isNULL,ornovmacontains*addr*. ***-EBUSY**iffailedtotrylockmmap_lock. ***-EINVAL**forinvalid**flags**. * *longbpf_loop(u32nr_loops,void*callback_fn,void*callback_ctx,u64flags) *Description *For**nr_loops**,call**callback_fn**function *with**callback_ctx**asthecontextparameter. *The**callback_fn**shouldbeastaticfunctionand *the**callback_ctx**shouldbeapointertothestack. *The**flags**isusedtocontrolcertainaspectsofthehelper. *Currently,the**flags**mustbe0.Currently,nr_loopsis *limitedto1<<23(~8million)loops. * *long(\*callback_fn)(u64index,void\*ctx); * *where**index**isthecurrentindexintheloop.Theindex *iszero-indexed. * ***callback_fn**returns0 the
* loop. Ifreturn value is 1, the helper will skip the rest of
* the loops andreturn. Other return values are not used now,
* and will be rejected by the verifier.
*
* Return
* The number of loops performed, **-EINVAL** for invalid **flags**,
* **-E2BIG** if **nr_loops** exceeds the maximum number of loops.
*
* long bpf_strncmp(constchar *s1, u32 s1_sz, constchar *s2)
* Description
* Do strncmp() between **s1** and **s2**. **s1** doesn't need
* to be null-terminated and **s1_sz** is the maximum storage
* size of **s1**. **s2** must be a read-only string.
* Return
* An integer less than, equal to, or greater than zero
* if the first **s1_sz** bytes of **s1** is found to be
* less than, to match, or be greater than **s2**.
*
* long bpf_get_func_arg(void *ctx, u32 n, u64 *value)
* Description
* Get **n**-th argument register (zero based) of the traced function (for tracing programs)
* returned in **value**.
*
* Return
* 0 on success.
* **-EINVAL** if n >= argument register count of traced function.
*
* long bpf_get_func_ret(void *ctx, u64 *value)
* Description
* Get return value of the traced function (for tracing programs)
* in **value**.
*
* Return
* 0 on success.
* **-EOPNOTSUPP** for tracing programs other than BPF_TRACE_FEXIT or BPF_MODIFY_RETURN.
*
* long bpf_get_func_arg_cnt(void *ctx)
* Description
* Get number of registers of the traced function (for tracing programs) where
* function arguments are stored in these registers.
*
* Return
* The number of argument registers of the traced function.
*
* int bpf_get_retval(void)
* Description
* Get the BPF program's return value that will be returned to the upper layers.
*
* This helper is currently supported by cgroup programs and only by the hooks
* where BPF program's return value is returned to the userspace via errno.
* Return
* The BPF program's return value.
*
* int bpf_set_retval(int retval)
* Description
* Set the BPF program's return value that will be returned to the upper layers.
*
* This helper is currently supported by cgroup programs and only by the hooks
* where BPF program's return value is returned to the userspace via errno.
*
* Note that there is the following corner case where the program exports an error
* via bpf_set_retval but signals success via 'return 1':
*
* bpf_set_retval(-EPERM);
* return1;
*
* In thiscase, the BPF program's return value will use helper's -EPERM. This
* still holds truefor cgroup/bind{4,6} which supports extra 'return 3' success case.
*
* Return
* 0 on success, or a negative error in case of failure.
*
* u64 bpf_xdp_get_buff_len(struct xdp_buff *xdp_md)
* Description
* Get the total size of a given xdp buff (linear and paged area)
* Return
* The total size of a given xdp buffer.
*
* long bpf_xdp_load_bytes(struct xdp_buff *xdp_md, u32 offset, void *buf, u32 len)
* Description
* This helper is provided as an easy way to load data from a
* xdp buffer. It can be used to load *len* bytes from *offset* from
* the frame associated to *xdp_md*, into the buffer pointed by
* *buf*.
* Return
* 0 on success, or a negative error in case of failure.
*
* long bpf_xdp_store_bytes(struct xdp_buff *xdp_md, u32 offset, void *buf, u32 len)
* Description
* Store *len* bytes from buffer *buf* into the frame
* associated to *xdp_md*, at *offset*.
* Return
* 0 on success, or a negative error in case of failure.
*
* long bpf_copy_from_user_task(void *dst, u32 size, constvoid *user_ptr, struct task_struct *tsk, u64 flags)
* Description
* Read *size* bytes from user space address *user_ptr* in *tsk*'s
* address space, and stores the data in *dst*. *flags* is not
* used yet and is provided for future extensibility. This helper
* can only be used by sleepable programs.
* Return
* 0 on success, or a negative error in case of failure. On error
* *dst* buffer is zeroed out.
*
* long bpf_skb_set_tstamp(struct sk_buff *skb, u64 tstamp, u32 tstamp_type)
* Description
* Change the __sk_buff->tstamp_type to *tstamp_type*
* and set *tstamp* to the __sk_buff->tstamp together.
*
* If there is no need to change the __sk_buff->tstamp_type,
* the tstamp value can be directly written to __sk_buff->tstamp
* instead.
*
* BPF_SKB_TSTAMP_DELIVERY_MONO is the only tstamp that
* will be kept during bpf_redirect_*(). A non zero
* *tstamp* must be used with the BPF_SKB_TSTAMP_DELIVERY_MONO
* *tstamp_type*.
*
* A BPF_SKB_TSTAMP_UNSPEC *tstamp_type* can only be used
* with a zero *tstamp*.
*
* Only IPv4 and IPv6 skb->protocol are supported.
*
* This function is most useful when it needs to set a
* mono delivery time to __sk_buff->tstamp and then
* bpf_redirect_*() to the egress of an iface. For example,
* changing the (rcv) timestamp in __sk_buff->tstamp at
* ingress to a mono delivery time and then bpf_redirect_*()
* to sch_fq@phy-dev.
* Return
* 0 on success.
* **-EINVAL** for invalid input
* **-EOPNOTSUPP** for unsupported protocol
*
* long bpf_ima_file_hash(struct file *file, void *dst, u32 size)
* Description
* Returns a calculated IMA hash of the *file*.
* If the hash is larger than *size*, then only *size*
* bytes will be copied to *dst*
* Return
* The **hash_algo** is returned on success,
* **-EOPNOTSUPP** if the hash calculation failed or **-EINVAL** if
* invalid arguments are passed.
*
* void *bpf_kptr_xchg(void *dst, void *ptr)
* Description
* Exchange kptr at pointer *dst* with *ptr*, and return the old value.
* *dst* can be map value or local kptr. *ptr* can be NULL, otherwise
* it must be a referenced pointer which will be released when this helper
* is called.
* Return
* The old value of kptr (which can be NULL). The returned pointer
* if not NULL, is a reference which must be released using its
* corresponding release function, or moved into a BPF map before
* program exit.
*
* void *bpf_map_lookup_percpu_elem(struct bpf_map *map, const void *key, u32 cpu)
* Description
* Perform a lookup in *percpu map* for an entry associated to
* *key* on *cpu*.
* Return
* Map value associated to *key* on *cpu*, or **NULL** if no entry
* was found or *cpu* is invalid.
*
* struct mptcp_sock *bpf_skc_to_mptcp_sock(void *sk)
* Description
* Dynamically cast a *sk* pointer to a *mptcp_sock* pointer.
* Return
* *sk* if casting is valid, or **NULL** otherwise.
*
* long bpf_dynptr_from_mem(void *data, u32 size, u64 flags, struct bpf_dynptr *ptr)
* Description
* Get a dynptr to local memory *data*.
*
* *data* must be a ptr to a map value.
* The maximum *size* supported is DYNPTR_MAX_SIZE.
* *flags* is currently unused.
* Return
* 0 on success, -E2BIG if the size exceeds DYNPTR_MAX_SIZE,
* -EINVAL if flags is not 0.
*
* long bpf_ringbuf_reserve_dynptr(void *ringbuf, u32 size, u64 flags, struct bpf_dynptr *ptr)
* Description
* Reserve *size* bytes of payload in a ring buffer *ringbuf*
* through the dynptr interface. *flags* must be 0.
*
* Please note that a corresponding bpf_ringbuf_submit_dynptr or
* bpf_ringbuf_discard_dynptr must be called on *ptr*, even if the
* reservation fails. This is enforced by the verifier.
* Return
* 0 on success, or a negative error in case of failure.
*
* void bpf_ringbuf_submit_dynptr(struct bpf_dynptr *ptr, u64 flags)
* Description
* Submit reserved ring buffer sample, pointed to by *data*,
* through the dynptr interface. This is a no-op if the dynptr is
* invalid/null.
*
* For more information on *flags*, please see
* 'bpf_ringbuf_submit'.
* Return
* Nothing. Always succeeds.
*
* void bpf_ringbuf_discard_dynptr(struct bpf_dynptr *ptr, u64 flags)
* Description
* Discard reserved ring buffer sample through the dynptr
* interface. This is a no-op if the dynptr is invalid/null.
*
* For more information on *flags*, please see
* 'bpf_ringbuf_discard'.
* Return
* Nothing. Always succeeds.
*
* long bpf_dynptr_read(void *dst, u32 len, const struct bpf_dynptr *src, u32 offset, u64 flags)
* Description
* Read *len* bytes from *src* into *dst*, starting from *offset*
* into *src*.
* *flags* is currently unused.
* Return
* 0 on success, -E2BIG if *offset* + *len* exceeds the length
* of *src*'s data, -EINVAL if *src* is an invalid dynptr or if
* *flags* is not0.
*
* long bpf_dynptr_write(conststruct bpf_dynptr *dst, u32 offset, void *src, u32 len, u64 flags)
* Description
* Write *len* bytes from *src* into *dst*, starting from *offset*
* into *dst*.
*
* *flags* must be 0 except for skb-type dynptrs.
*
* For skb-type dynptrs:
* * All data slices of the dynptr are automatically
* invalidated after **bpf_dynptr_write**\ (). This is
* because writing may pull the skb and change the
* underlying packet buffer.
*
* * For *flags*, please see the flags accepted by
* **bpf_skb_store_bytes**\ ().
* Return
* 0 on success, -E2BIG if *offset* + *len* exceeds the length
* of *dst*'s data, -EINVAL if *dst* is an invalid dynptr or if *dst*
* is a read-only dynptr orif *flags* is not correct. For skb-type dynptrs,
* other errors correspond to errors returned by **bpf_skb_store_bytes**\ ().
*
* void *bpf_dynptr_data(conststruct bpf_dynptr *ptr, u32 offset, u32 len)
* Description
* Get a pointer to the underlying dynptr data.
*
* *len* must be a statically known value. The returned data slice
* is invalidated whenever the dynptr is invalidated.
*
* skb and xdp type dynptrs may not use bpf_dynptr_data. They should
* instead use bpf_dynptr_slice and bpf_dynptr_slice_rdwr.
* Return
* Pointer to the underlying dynptr data, NULL if the dynptr is
* read-only, if the dynptr is invalid, orif the offset and length
* is out of bounds.
*
* s64 bpf_tcp_raw_gen_syncookie_ipv4(struct iphdr *iph, struct tcphdr *th, u32 th_len)
* Description
* Try to issue a SYN cookie for the packet with corresponding
* IPv4/TCP headers, *iph* and *th*, without depending on a
* listening socket.
*
* *iph* points to the IPv4 header.
*
* *th* points to the start of the TCP header, while *th_len*
* contains the length of the TCP header (at least
* **sizeof**\ (**struct tcphdr**)).
* Return
* On success, lower 32 bits hold the generated SYN cookie in
* followed by 16 bits which hold the MSS value for that cookie,
* and the top 16 bits are unused.
*
* On failure, the returned value is one of the following:
*
* **-EINVAL** if *th_len* is invalid.
*
* s64 bpf_tcp_raw_gen_syncookie_ipv6(struct ipv6hdr *iph, struct tcphdr *th, u32 th_len)
* Description
* Try to issue a SYN cookie for the packet with corresponding
* IPv6/TCP headers, *iph* and *th*, without depending on a
* listening socket.
*
* *iph* points to the IPv6 header.
*
* *th* points to the start of the TCP header, while *th_len*
* contains the length of the TCP header (at least
* **sizeof**\ (**struct tcphdr**)).
* Return
* On success, lower 32 bits hold the generated SYN cookie in
* followed by 16 bits which hold the MSS value for that cookie,
* and the top 16 bits are unused.
*
* On failure, the returned value is one of the following:
*
* **-EINVAL** if *th_len* is invalid.
*
**CONFIG_IPV6is builtin
*
* long bpf_tcp_raw_check_syncookie_ipv4(struct iphdr *iph, struct tcphdr *th)
* Description
* Check whether *iph* and *th* contain a valid SYN cookie ACK
* without depending on a listening socket.
*
* *iph* points to the IPv4 header.
*
* *th* points to the TCP header.
* Return
* 0if *iph* and *th* are a valid SYN cookie ACK.
*
* On failure, the returned value is one of the following:
*
* **-EACCES** if the SYN cookie is not valid.
*
* long bpf_tcp_raw_check_syncookie_ipv6(struct ipv6hdr *iph, struct tcphdr *th)
* Description
* Check whether *iph* and *th* contain a valid SYN cookie ACK
* without depending on a listening socket.
*
* *iph* points to the IPv6 header.
*
* *th* points to the TCP header.
* Return
* 0if *iph* and *th* are a valid SYN cookie ACK.
*
* On failure, the returned value is one of the following:
*
* **-EACCES** if the SYN cookie is not valid.
*
* **-EPROTONOSUPPORT** if CONFIG_IPV6 is not builtin.
*
* u64 bpf_ktime_get_tai_ns(void)
* Description
* A nonsettable system-wide clock derived from wall-clock time but
* ignoring leap seconds. This clock does not experience
* discontinuities and backwards jumps caused by NTP inserting leap
* seconds as CLOCK_REALTIME does.
*
* See: **clock_gettime**\ (**CLOCK_TAI**)
* Return
* Current *ktime*.
*
* long bpf_user_ringbuf_drain(struct bpf_map *map, void *callback_fn, void *ctx, u64 flags)
* Description
* Drain samples from the specified user ring buffer, and invoke
* the provided callback for each such sample:
*
* long (\*callback_fn)(conststruct bpf_dynptr \*dynptr, void \*ctx);
*
* If **callback_fn** returns 0, the helper will continue to try
* and drain the next sample, up to a maximum of
* BPF_MAX_USER_RINGBUF_SAMPLES samples. If the return value is 1,
* the helper will skip the rest of the samples andreturn. Other
* return values are not used now, and will be rejected by the
* verifier.
* Return
* The number of drained samples if no error was encountered while
* draining samples, or0if no samples were present in the ring
* buffer. If a user-space producer was epoll-waiting on this map,
* and at least one sample was drained, they will receive an event
* notification notifying them of available space in the ring
* buffer. If the BPF_RB_NO_WAKEUP flag is passed to this
* function, no wakeup notification will be sent. If the
* BPF_RB_FORCE_WAKEUP flag is passed, a wakeup notification will
* be sent even if no sample was drained.
*
* On failure, the returned value is one of the following:
*
* **-EBUSY** if the ring buffer is contended, and another calling
* context was concurrently draining the ring buffer.
*
* **-EINVAL** if user-space is not properly tracking the ring
* buffer due to the producer position not being aligned to 8
* bytes, a sample not being aligned to 8 bytes, or the producer
* position not matching the advertised length of a sample.
*
* **-E2BIG** if user-space has tried to publish a sample which is
* larger than the size of the ring buffer, or which cannot fit
* within a struct bpf_dynptr.
*
* void *bpf_cgrp_storage_get(struct bpf_map *map, struct cgroup *cgroup, void *value, u64 flags)
* Description
* Get a bpf_local_storage from the *cgroup*.
*
* Logically, it could be thought of as getting the value from
* a *map* with *cgroup* as the **key**. From this
* perspective, the usage is not much different from
* **bpf_map_lookup_elem**\ (*map*, **&**\ *cgroup*) except this
* helper enforces the key must be a cgroup structand the map must also
* be a **BPF_MAP_TYPE_CGRP_STORAGE**.
*
* In reality, the local-storage value is embedded directly inside of the
* *cgroup* object itself, rather than being located in the
* **BPF_MAP_TYPE_CGRP_STORAGE** map. When the local-storage value is
* queried for some *map* on a *cgroup* object, the kernel will perform an
* O(n) iteration over all of the live local-storage values for that
* *cgroup* object until the local-storage value for the *map* is found.
*
* An optional *flags* (**BPF_LOCAL_STORAGE_GET_F_CREATE**) can be
* used such that a new bpf_local_storage will be
* created if one does not exist. *value* can be used
* together with **BPF_LOCAL_STORAGE_GET_F_CREATE** to specify
* the initial value of a bpf_local_storage. If *value* is
* **NULL**, the new bpf_local_storage will be zero initialized.
* Return
* A bpf_local_storage pointer is returned on success.
*
* **NULL** if not found or there was an error in adding
* a new bpf_local_storage.
*
* long bpf_cgrp_storage_delete(struct bpf_map *map, struct cgroup *cgroup)
* Description
* Delete a bpf_local_storage from a *cgroup*.
* Return
* 0 on success.
*
* **-ENOENT** if the bpf_local_storage cannot be found.
*/
#define ___BPF_FUNC_MAPPER(FN, ctx...) \
FN(unspec, 0, ##ctx) \
FN(map_lookup_elem, 1, ##ctx) \
FN(map_update_elem, 2, ##ctx) \
FN(map_delete_elem, 3, ##ctx) \
FN(probe_read, 4, ##ctx) \
FN(ktime_get_ns, 5, ##ctx) \
FN(trace_printk, 6, ##ctx) \
FN(get_prandom_u32, 7, ##ctx) \
FN(get_smp_processor_id, 8, ##ctx) \
FN(skb_store_bytes, 9, ##ctx) \
FN(l3_csum_replace, 10, ##ctx) \
FN(l4_csum_replace, 11, ##ctx) \
FN(tail_call, 12, ##ctx) \
FN(clone_redirect, 13, ##ctx) \
FN(get_current_pid_tgid, 14, ##ctx) \
FN(get_current_uid_gid, 15, ##ctx) \
FN(get_current_comm, 16, ##ctx) \
FN(get_cgroup_classid, 17, ##ctx) \
FN(skb_vlan_push, 18, ##ctx) \
FN(skb_vlan_pop, 19, ##ctx) \
FN(skb_get_tunnel_key, 20, ##ctx) \
FN(skb_set_tunnel_key, 21, ##ctx) \
FN(perf_event_read, 22, ##ctx) \
FN(redirect, 23, ##ctx) \
FN(get_route_realm, 24, ##ctx) \
FN(perf_event_output, 25, ##ctx) \
FN(skb_load_bytes, 26, ##ctx) \
FN(get_stackid, 27, ##ctx) \
FN(csum_diff, 28, ##ctx) \
FN(skb_get_tunnel_opt, 29, ##ctx) \
FN(skb_set_tunnel_opt, 30, ##ctx) \
FN(skb_change_proto, 31, ##ctx) \
FN(skb_change_type, 32, ##ctx) \
FN(skb_under_cgroup, 33, ##ctx) \
FN(get_hash_recalc, 34, ##ctx) \
FN(get_current_task, 35, ##ctx) \
FN(probe_write_user, 36, ##ctx) \
FN(current_task_under_cgroup, 37, ##ctx) \
FN(skb_change_tail, 38, ##ctx) \
FN(skb_pull_data, 39, ##ctx) \
FN(csum_update, 40, ##ctx) \
FN(set_hash_invalid, 41, ##ctx) \
FN(get_numa_node_id, 42, ##ctx) \
FN(skb_change_head, 43, ##ctx) \
FN(xdp_adjust_head, 44, ##ctx) \
FN(probe_read_str, 45, ##ctx) \
FN(get_socket_cookie, 46, ##ctx) \
FN(get_socket_uid, 47, ##ctx) \
FN(set_hash, 48, ##ctx) \
FN(setsockopt, 49, ##ctx) \
FN(skb_adjust_room, 50, ##java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 27
FNverify)
FN(sk_redirect_map, 52, ##ctx) \
FN(sock_map_update, 53, ##ctx) \
FN(xdp_adjust_meta, 54, ##ctx) \
FN(perf_event_read_value, 55, ##ctx) \
FN(perf_prog_read_value, 56, ##ctx) \
FN(getsockopt, 57, ##ctx) \
FN(override_return, 58, ##ctx) \
FN(sock_ops_cb_flags_set, 59, ##ctx) \
FN(msg_redirect_map, 60, ##ctx) \
FN(msg_apply_bytes, 61, ##ctx) \
FN(msg_cork_bytes, 62, ##ctx) \
FN(msg_pull_data, 63, ##ctx) \
FN(bind, 64, ##ctx) \
FN(xdp_adjust_tail, 65, ##ctx) \
FN(skb_get_xfrm_state, 66, ##ctx) \
FN(get_stack, 67, ##ctx) \
FN(skb_load_bytes_relative, 68, ##ctx) \
FN(fib_lookup, 69, ##ctx) \
FN(sock_hash_update, 70, ##ctx) \
FN(msg_redirect_hash, 71, ##ctx) \
FN(sk_redirect_hash, 72, ##ctx) \
FN(lwt_push_encap, 73, ##ctx) \
FN(lwt_seg6_store_bytes, 74, ##ctx) \
FN(lwt_seg6_adjust_srh, 75, ##ctx) \
FN(lwt_seg6_action, 76, ##ctx) \
FN(rc_repeat, 77, ##ctx) \
FN(rc_keydown, 78, ##ctx) \
FN(skb_cgroup_id, 79, ##ctx) \
FN(get_current_cgroup_id, 80, ##ctx) \
FN(get_local_storage, 81, ##ctx) \
FN(sk_select_reuseport, 82, ##ctx) \
FN(skb_ancestor_cgroup_id, 83, ##ctx) \
FN(sk_lookup_tcp, 84, ##ctx) \
FN(sk_lookup_udp, 85, ##ctx) \
FN(sk_release, 86, ##ctx) \
FN(map_push_elem, 87, ##ctx) \
FN(map_pop_elem, 88, ##ctx) \
FN(map_peek_elem, 89, ##ctx) \
FN(msg_push_data, 90, ##ctx) \
FN(msg_pop_data, 91, ##ctx) \
FN(rc_pointer_rel, 92, ##ctx) \
FN(spin_lock, 93, ##ctx) \
FN(spin_unlock, 94, ##ctx) \
FN(sk_fullsock, 95, ##ctx) \
FN(tcp_sock, 96, ##ctx) \
FN(skb_ecn_set_ce, 97, ##ctx) \
FN(get_listener_sock, 98, ##ctx) \
FN(skc_lookup_tcp, 99, ##ctx) \
FN(tcp_check_syncookie, 100, ##ctx) \
FN(sysctl_get_name, 101, ##ctx) \
FN(sysctl_get_current_value, 102, ##ctx) \
FN(sysctl_get_new_value, 103, ##ctx) \
FN(sysctl_set_new_value, 104, ##ctx) \
FN(strtol, 105, ##ctx) \
FN(strtoul, 106, ##ctx) \
FN(sk_storage_get, 107, ##ctx) \
FN(sk_storage_delete, 108, ##ctx) \
FN(send_signal, 109, ##ctx) \
FN(tcp_gen_syncookie, 110, ##ctx) \
FN(skb_output, 111, ##ctx) \
FN(probe_read_user, 112, ##ctx) \
FN(probe_read_kernel, 113, ##ctx) \
FN(probe_read_user_str, 114, ##ctx) \
FN(probe_read_kernel_str, 115, ##ctx) \
FN(tcp_send_ack, 116, ##ctx) \
FN(send_signal_thread, 117, ##ctx) \
FN(jiffies64, 118, ##ctx) \
FN(read_branch_records, 119, ##ctx) \
FN(get_ns_current_pid_tgid, 120, ##ctx) \
FN(xdp_output, 121, ##ctx) \
FN(get_netns_cookie, 122, ##ctx) \
FN(get_current_ancestor_cgroup_id, 123, ##ctx) \
FN(sk_assign, 124, ##ctx) \
FN(ktime_get_boot_ns, 125, ##ctx) \
FN(seq_printf, 126, ##ctx) \
FN(seq_write, 127, ##ctx) \
FN(sk_cgroup_id, 128, ##ctx) \
FN(sk_ancestor_cgroup_id, 129, ##ctx) \
FN(ringbuf_output, 130, ##ctx) \
FN(ringbuf_reserve, 131, ##ctx) \
FN(ringbuf_submit, 132, ##ctx) \
FN(ringbuf_discard, 133, ##ctx) \
FN(ringbuf_query, 134, ##ctx) \
FN(csum_level, 135, ##ctx) \
FN(skc_to_tcp6_sock, 136, ##ctx) \
FN(skc_to_tcp_sock, 137, ##ctx) \
FN(skc_to_tcp_timewait_sock, 138, ##ctx) \
FN(skc_to_tcp_request_sock, 139, ##ctx) \
FN(skc_to_udp6_sock, 140, ##ctx) \
FN(get_task_stack, 141, ##ctx) \
FN(load_hdr_opt, 142, ##ctx) \
FN(store_hdr_opt, 143, ##ctx) \
FN(reserve_hdr_opt, 144, ##ctx) \
FN(inode_storage_get, 145, ##ctx) \
FN(inode_storage_delete, 146, ##ctx) \
FN(d_path, 147, ##ctx) \
FN(copy_from_user, 148, ##ctx) \
FN(snprintf_btf, 149, ##ctx) \
FN(seq_printf_btf, 150, ##ctx) \
FN(skb_cgroup_classid, 151, ##ctx) \
FN(redirect_neigh, 152, ##ctx) \
FN(per_cpu_ptr, 153, ##ctx) \
FN(this_cpu_ptr, 154, ##ctx) \
FN(redirect_peer, 155, ##ctx) \
FN(task_storage_get, 156, ##ctx) \
FN(task_storage_delete, 157, ##ctx) \
FN(get_current_task_btf, 158, ##ctx) \
FN(bprm_opts_set, 159, ##ctx) \
FN(ktime_get_coarse_ns, 160, ##ctx) \
FN(ima_inode_hash, 161, ##ctx) \
FN(sock_from_file, 162, ##ctx) \
FN(check_mtu, 163, ##ctx) \
FN(for_each_map_elem, 164, ##ctx) \
FN(snprintf, 165, ##ctx) \
FN(sys_bpf, 166, ##ctx) \
FN(btf_find_by_name_kind, 167, ##ctx) \
FN(sys_close, 168, ##ctx) \
FN(timer_init, 169, ##ctx) \
FN(timer_set_callback, 170, ##ctx) \
FN(timer_start, 171, ##ctx) \
FN(timer_cancel, 172, ##ctx) \
FN(get_func_ip, 173, ##ctx) \
FN(get_attach_cookie, 174, ##ctx) \
FN(task_pt_regs, 175, ##ctx) \
FN(get_branch_snapshot, 176, ##ctx) \
FN(trace_vprintk, 177, ##ctx) \
FN(skc_to_unix_sock, 178, ##ctx) \
FN(kallsyms_lookup_name, 179, ##ctx) \
FN(find_vma, 180, ##ctx) \
FN(loop, 181, ##ctx) \
FN(strncmp, 182, ##ctx) \
FN(get_func_arg, 183, ##ctx) \
FN(get_func_ret, 184, ##ctx) \
FN(get_func_arg_cnt, 185, ##ctx) \
FN(get_retval, 186, ##ctx) \
FN(set_retval, 187, ##ctx) \
FN(xdp_get_buff_len, 188, ##ctx) \
FN(xdp_load_bytes, 189, ##ctx) \
FN(xdp_store_bytes, 190, ##ctx) \
FN(copy_from_user_task, 191, ##ctx) \
FN(skb_set_tstamp, 192, ##ctx) \
FN(ima_file_hash, 193, ##ctx) \
FN(kptr_xchg, 194, ##ctx) \
FN(map_lookup_percpu_elem, 195, ##ctx) \
FN(skc_to_mptcp_sock, 196, ##ctx) \
FN(dynptr_from_mem, 197, ##ctx) \
FN(ringbuf_reserve_dynptr, 198, ##ctx) \
FN(ringbuf_submit_dynptr, 199, ##ctx) \
FN(ringbuf_discard_dynptr, 200, ##ctx) \
FN(dynptr_read, 201, ##ctx) \
FN(dynptr_write, 202, ##ctx) \
FN(dynptr_data, 203, ##ctx) \
FN(tcp_raw_gen_syncookie_ipv4, 204, ##ctx) \
FN(tcp_raw_gen_syncookie_ipv6, 205, ##ctx) \
FN(tcp_raw_check_syncookie_ipv4, 206, ##ctx) \
FN(tcp_raw_check_syncookie_ipv6, 207, ##ctx) \
FN(ktime_get_tai_ns, 208, ##ctx) \
FN(user_ringbuf_drain, 209, ##ctx) \
FN(cgrp_storage_get, 210, ##ctx) \
FN(cgrp_storage_delete, 211, ##ctx) \ /* This helper list is effectively frozen. If you are trying to \ *addanewhelper,youshouldaddakfuncinsteadwhichhas\ *lessstabilityguarantees.SeeDocumentation/bpf/kfuncs.rst\
*/
/* backwards-compatibility macros for users of __BPF_FUNC_MAPPER that don't *knoworcareaboutintegervaluethatisnowpassedassecondargument
*/
#define __BPF_FUNC_MAPPER_APPLY(name, value, FN) FN(name),
#define __BPF_FUNC_MAPPER(FN) ___BPF_FUNC_MAPPER(__BPF_FUNC_MAPPER_APPLY, FN)
/* integer value in 'imm' field of BPF_CALL instruction selects which helper *functioneBPFprogramintendstocall
*/
#define __BPF_ENUM_FN(x, y) BPF_FUNC_ ## x = y, enum bpf_func_id {
___BPF_FUNC_MAPPER(__BPF_ENUM_FN)
__BPF_FUNC_MAX_ID,
};
#undef __BPF_ENUM_FN
/* All flags used by eBPF helper functions, placed here. */
/* BPF_FUNC_<kernel_obj>_storage_get flags */
enum {
BPF_LOCAL_STORAGE_GET_F_CREATE = (1ULL << 0),
/* BPF_SK_STORAGE_GET_F_CREATE is only kept for backward compatibility
* and BPF_LOCAL_STORAGE_GET_F_CREATE must be used instead.
*/
BPF_SK_STORAGE_GET_F_CREATE = BPF_LOCAL_STORAGE_GET_F_CREATE,
};
/* Flags for bpf_redirect and bpf_redirect_map helpers */
enum {
BPF_F_INGRESS = (1ULL << 0), /* used for skb path */
BPF_F_BROADCAST = (1ULL << 3), /* used for XDP path */
BPF_F_EXCLUDE_INGRESS = (1ULL << 4), /* used for XDP path */
#define BPF_F_REDIRECT_FLAGS (BPF_F_INGRESS | BPF_F_BROADCAST | BPF_F_EXCLUDE_INGRESS)
};
#define __bpf_md_ptr(type, name) \
union { \
type name; \
__u64 :64; \
} __attribute__((aligned(8)))
/* The enum used in skb->tstamp_type. It specifies the clock type
* of the time stored in the skb->tstamp.
*/
enum {
BPF_SKB_TSTAMP_UNSPEC = 0, /* DEPRECATED */
BPF_SKB_TSTAMP_DELIVERY_MONO = 1, /* DEPRECATED */
BPF_SKB_CLOCK_REALTIME = 0,
BPF_SKB_CLOCK_MONOTONIC = 1,
BPF_SKB_CLOCK_TAI = 2,
/* For any future BPF_SKB_CLOCK_* that the bpf prog cannot handle,
* the bpf prog can try to deduce it by ingress/egress/skb->sk->sk_clockid.
*/
};
/* user accessible mirror of in-kernel sk_buff.
* new fields can only be added to the end of this structure
*/
struct __sk_buff {
__u32 len;
__u32 pkt_type;
__u32 mark;
__u32 queue_mapping;
__u32 protocol;
__u32 vlan_present;
__u32 vlan_tci;
__u32 vlan_proto;
__u32 priority;
__u32 ingress_ifindex;
__u32 ifindex;
__u32 tc_index;
__u32 cb[5];
__u32 hash;
__u32 tc_classid;
__u32 data;
__u32 data_end;
__u32 napi_id;
/* Accessed by BPF_PROG_TYPE_sk_skb types from here to ... */
__u32 family;
__u32 remote_ip4; /* Stored in network byte order */
__u32 local_ip4; /* Stored in network byte order */
__u32 remote_ip6[4]; /* Stored in network byte order */
__u32 local_ip6[4]; /* Stored in network byte order */
__u32 remote_port; /* Stored in network byte order */
__u32 local_port; /* stored in host byte order */
/* ... here. */
/* user accessible mirror of in-kernel xfrm_state.
* new fields can only be added to the end of this structure
*/
struct bpf_xfrm_state {
__u32 reqid;
__u32 spi; /* Stored in network byte order */
__u16 family;
__u16 ext; /* Padding, future use. */
union {
__u32 remote_ipv4; /* Stored in network byte order */
__u32 remote_ipv6[4]; /* Stored in network byte order */
};
};
/* Generic BPF return codes which all BPF program types may support.
* The values are binary compatible with their TC_ACT_* counter-part to
* provide backwards compatibility with existing SCHED_CLS and SCHED_ACT
* programs.
*
* XDP is handled seprately, see XDP_*.
*/
enum bpf_ret_code {
BPF_OK = 0,
/* 1 reserved */
BPF_DROP = 2,
/* 3-6 reserved */
BPF_REDIRECT = 7,
/* >127 are reserved for prog type specific return codes.
*
* BPF_LWT_REROUTE: used by BPF_PROG_TYPE_LWT_IN and
* BPF_PROG_TYPE_LWT_XMIT to indicate that skb had been
* changed and should be routed based on its new L3 header.
* (This is an L3 redirect, as opposed to L2 redirect
* represented by BPF_REDIRECT above).
*/
BPF_LWT_REROUTE = 128,
/* BPF_FLOW_DISSECTOR_CONTINUE: used by BPF_PROG_TYPE_FLOW_DISSECTOR
* to indicate that no custom dissection was performed, and
* fallback to standard dissector is requested.
*/
BPF_FLOW_DISSECTOR_CONTINUE = 129,
};
struct bpf_sock {
__u32 bound_dev_if;
__u32 family;
__u32 type;
__u32 protocol;
__u32 mark;
__u32 priority;
/* IP address also allows 1 and 2 bytes access */
__u32 src_ip4;
__u32 src_ip6[4];
__u32 src_port; /* host byte order */
__be16 dst_port; /* network byte order */
__u16 :16; /* zero padding */
__u32 dst_ip4;
__u32 dst_ip6[4];
__u32 state;
__s32 rx_queue_mapping;
};
struct bpf_tcp_sock {
__u32 snd_cwnd; /* Sending congestion window */
__u32 srtt_us; /* smoothed round trip time << 3 in usecs */
__u32 rtt_min;
__u32 snd_ssthresh; /* Slow start size threshold */
__u32 rcv_nxt; /* What we want to receive next */
__u32 snd_nxt; /* Next sequence we send */
__u32 snd_una; /* First byte we want an ack for */
__u32 mss_cache; /* Cached effective mss, not including SACKS */
__u32 ecn_flags; /* ECN status bits. */
__u32 rate_delivered; /* saved rate sample: packets delivered */
__u32 rate_interval_us; /* saved rate sample: time elapsed */
__u32 packets_out; /* Packets which are "in flight" */
__u32 retrans_out; /* Retransmitted packets out */
__u32 total_retrans; /* Total retransmits for entire connection */
__u32 segs_in; /* RFC4898 tcpEStatsPerfSegsIn
* total number of segments in.
*/
__u32 data_segs_in; /* RFC4898 tcpEStatsPerfDataSegsIn
* total number of data segments in.
*/
__u32 segs_out; /* RFC4898 tcpEStatsPerfSegsOut
* The total number of segments sent.
*/
__u32 data_segs_out; /* RFC4898 tcpEStatsPerfDataSegsOut
* total number of data segments sent.
*/
__u32 lost_out; /* Lost packets */
__u32 sacked_out; /* SACK'd packets */
__u64 bytes_received; /* RFC4898 tcpEStatsAppHCThruOctetsReceived
* sum(delta(rcv_nxt)), or how many bytes
* were acked.
*/
__u64 bytes_acked; /* RFC4898 tcpEStatsAppHCThruOctetsAcked
* sum(delta(snd_una)), or how many bytes
* were acked.
*/
__u32 dsack_dups; /* RFC4898 tcpEStatsStackDSACKDups
* total number of DSACK blocks received
*/
__u32 delivered; /* Total data packets delivered incl. rexmits */
__u32 delivered_ce; /* Like the above but only ECE marked packets */
__u32 icsk_retransmits; /* Number of unrecovered [RTO] timeouts */
};
/* (Simplified) user return codes for tcx prog type.
* A valid tcx program must return one of these defined values. All other
* return codes are reserved for future use. Must remain compatible with
* their TC_ACT_* counter-parts. For compatibility in behavior, unknown
* return codes are mapped to TCX_NEXT.
*/
enum tcx_action_base {
TCX_NEXT = -1,
TCX_PASS = 0,
TCX_DROP = 2,
TCX_REDIRECT = 7,
};
struct bpf_xdp_sock {
__u32 queue_id;
};
#define XDP_PACKET_HEADROOM 256
/* User return codes for XDP prog type.
* A valid XDP program must return one of these defined values. All other
* return codes are reserved for future use. Unknown return codes will
* result in packet drops and a warning via bpf_warn_invalid_xdp_action().
*/
enum xdp_action {
XDP_ABORTED = 0,
XDP_DROP,
XDP_PASS,
XDP_TX,
XDP_REDIRECT,
};
/* user accessible metadata for XDP packet hook
* new fields must be added to the end of this structure
*/
struct xdp_md {
__u32 data;
__u32 data_end;
__u32 data_meta;
/* Below access go through struct xdp_rxq_info */
__u32 ingress_ifindex; /* rxq->dev->ifindex */
__u32 rx_queue_index; /* rxq->queue_index */
__u32 egress_ifindex; /* txq->dev->ifindex */
};
/* DEVMAP map-value layout
*
* The struct data-layout of map-value is a configuration interface.
* New members can only be added to the end of this structure.
*/
struct bpf_devmap_val {
__u32 ifindex; /* device index */
union {
int fd; /* prog fd on map write */
__u32 id; /* prog id on map read */
} bpf_prog;
};
/* CPUMAP map-value layout
*
* The struct data-layout of map-value is a configuration interface.
* New members can only be added to the end of this structure.
*/
struct bpf_cpumap_val {
__u32 qsize; /* queue size to remote target CPU */
union {
int fd; /* prog fd on map write */
__u32 id; /* prog id on map read */
} bpf_prog;
};
enum sk_action {
SK_DROP = 0,
SK_PASS,
};
/* user accessible metadata for SK_MSG packet hook, new fields must
* be added to the end of this structure
*/
struct sk_msg_md {
__bpf_md_ptr(void *, data);
__bpf_md_ptr(void *, data_end);
__u32 family;
__u32 remote_ip4; /* Stored in network byte order */
__u32 local_ip4; /* Stored in network byte order */
__u32 remote_ip6[4]; /* Stored in network byte order */
__u32 local_ip6[4]; /* Stored in network byte order */
__u32 remote_port; /* Stored in network byte order */
__u32 local_port; /* stored in host byte order */
__u32 size; /* Total size of sk_msg */
__bpf_md_ptr(struct bpf_sock *, sk); /* current socket */
};
struct sk_reuseport_md {
/*
* Start of directly accessible data. It begins from
* the tcp/udp header.
*/
__bpf_md_ptr(void *, data);
/* End of directly accessible data */
__bpf_md_ptr(void *, data_end);
/*
* Total length of packet (starting from the tcp/udp header).
* Note that the directly accessible bytes (data_end - data)
* could be less than this "len". Those bytes could be
* indirectly read by a helper "bpf_skb_load_bytes()".
*/
__u32 len;
/*
* Eth protocol in the mac header (network byte order). e.g.
* ETH_P_IP(0x0800) and ETH_P_IPV6(0x86DD)
*/
__u32 eth_protocol;
__u32 ip_protocol; /* IP protocol. e.g. IPPROTO_TCP, IPPROTO_UDP */
__u32 bind_inany; /* Is sock bound to an INANY address? */
__u32 hash; /* A hash of the packet 4 tuples */
/* When reuse->migrating_sk is NULL, it is selecting a sk for the
* new incoming connection request (e.g. selecting a listen sk for
* the received SYN in the TCP case). reuse->sk is one of the sk
* in the reuseport group. The bpf prog can use reuse->sk to learn
* the local listening ip/port without looking into the skb.
*
* When reuse->migrating_sk is not NULL, reuse->sk is closed and
* reuse->migrating_sk is the socket that needs to be migrated
* to another listening socket. migrating_sk could be a fullsock
* sk that is fully established or a reqsk that is in-the-middle
* of 3-way handshake.
*/
__bpf_md_ptr(struct bpf_sock *, sk);
__bpf_md_ptr(struct bpf_sock *, migrating_sk);
};
/* User bpf_sock_addr struct to access socket fields and sockaddr struct passed
* by user and intended to be used by socket (e.g. to bind to, depends on
* attach type).
*/
struct bpf_sock_addr {
__u32 user_family; /* Allows 4-byte read, but no write. */
__u32 user_ip4; /* Allows 1,2,4-byte read and 4-byte write.
* Stored in network byte order.
*/
__u32 user_ip6[4]; /* Allows 1,2,4,8-byte read and 4,8-byte write.
* Stored in network byte order.
*/
__u32 user_port; /* Allows 1,2,4-byte read and 4-byte write.
* Stored in network byte order
*/
__u32 family; /* Allows 4-byte read, but no write */
__u32 type; /* Allows 4-byte read, but no write */
__u32 protocol; /* Allows 4-byte read, but no write */
__u32 msg_src_ip4; /* Allows 1,2,4-byte read and 4-byte write.
* Stored in network byte order.
*/
__u32 msg_src_ip6[4]; /* Allows 1,2,4,8-byte read and 4,8-byte write.
* Stored in network byte order.
*/
__bpf_md_ptr(struct bpf_sock *, sk);
};
/* User bpf_sock_ops struct to access socket values and specify request ops
* and their replies.
* Some of this fields are in network (bigendian) byte order and may need
* to be converted before use (bpf_ntohl() defined in samples/bpf/bpf_endian.h).
* New fields can only be added at the end of this structure
*/
struct bpf_sock_ops {
__u32 op;
union {
__u32 args[4]; /* Optionally passed to bpf program */
__u32 reply; /* Returned by bpf program */
__u32 replylong[4]; /* Optionally returned by bpf prog */
};
__u32 family;
__u32 remote_ip4; /* Stored in network byte order */
__u32 local_ip4; /* Stored in network byte order */
__u32 remote_ip6[4]; /* Stored in network byte order */
__u32 local_ip6[4]; /* Stored in network byte order */
__u32 remote_port; /* Stored in network byte order */
__u32 local_port; /* stored in host byte order */
__u32 is_fullsock; /* Some TCP fields are only valid if
* there is a full socket. If not, the
* fields read as zero.
*/
__u32 snd_cwnd;
__u32 srtt_us; /* Averaged RTT << 3 in usecs */
__u32 bpf_sock_ops_cb_flags; /* flags defined in uapi/linux/tcp.h */
__u32 state;
__u32 rtt_min;
__u32 snd_ssthresh;
__u32 rcv_nxt;
__u32 snd_nxt;
__u32 snd_una;
__u32 mss_cache;
__u32 ecn_flags;
__u32 rate_delivered;
__u32 rate_interval_us;
__u32 packets_out;
__u32 retrans_out;
__u32 total_retrans;
__u32 segs_in;
__u32 data_segs_in;
__u32 segs_out;
__u32 data_segs_out;
__u32 lost_out;
__u32 sacked_out;
__u32 sk_txhash;
__u64 bytes_received;
__u64 bytes_acked;
__bpf_md_ptr(struct bpf_sock *, sk);
/* [skb_data, skb_data_end) covers the whole TCP header.
*
* BPF_SOCK_OPS_PARSE_HDR_OPT_CB: The packet received
* BPF_SOCK_OPS_HDR_OPT_LEN_CB: Not useful because the
* header has not been written.
* BPF_SOCK_OPS_WRITE_HDR_OPT_CB: The header and options have
* been written so far.
* BPF_SOCK_OPS_ACTIVE_ESTABLISHED_CB: The SYNACK that concludes
* the 3WHS.
* BPF_SOCK_OPS_PASSIVE_ESTABLISHED_CB: The ACK that concludes
* the 3WHS.
*
* bpf_load_hdr_opt() can also be used to read a particular option.
*/
__bpf_md_ptr(void *, skb_data);
__bpf_md_ptr(void *, skb_data_end);
__u32 skb_len; /* The total length of a packet.
* It includes the header, options,
* and payload.
*/
__u32 skb_tcp_flags; /* tcp_flags of the header. It provides
* an easy way to check for tcp_flags
* without parsing skb_data.
*
* In particular, the skb_tcp_flags
* will still be available in
* BPF_SOCK_OPS_HDR_OPT_LEN even though
* the outgoing header has not
* been written yet.
*/
__u64 skb_hwtstamp;
};
/* Definitions for bpf_sock_ops_cb_flags */
enum {
BPF_SOCK_OPS_RTO_CB_FLAG = (1<<0),
BPF_SOCK_OPS_RETRANS_CB_FLAG = (1<<1),
BPF_SOCK_OPS_STATE_CB_FLAG = (1<<2),
BPF_SOCK_OPS_RTT_CB_FLAG = (1<<3),
/* Call bpf for all received TCP headers. The bpf prog will be
* called under sock_ops->op == BPF_SOCK_OPS_PARSE_HDR_OPT_CB
*
* Please refer to the comment in BPF_SOCK_OPS_PARSE_HDR_OPT_CB
* for the header option related helpers that will be useful
* to the bpf programs.
*
* It could be used at the client/active side (i.e. connect() side)
* when the server told it that the server was in syncookie
* mode and required the active side to resend the bpf-written
* options. The active side can keep writing the bpf-options until
* it received a valid packet from the server side to confirm
* the earlier packet (and options) has been received. The later
* example patch is using it like this at the active side when the
* server is in syncookie mode.
*
* The bpf prog will usually turn this off in the common cases.
*/
BPF_SOCK_OPS_PARSE_ALL_HDR_OPT_CB_FLAG = (1<<4),
/* Call bpf when kernel has received a header option that
* the kernel cannot handle. The bpf prog will be called under
* sock_ops->op == BPF_SOCK_OPS_PARSE_HDR_OPT_CB.
*
* Please refer to the comment in BPF_SOCK_OPS_PARSE_HDR_OPT_CB
* for the header option related helpers that will be useful
* to the bpf programs.
*/
BPF_SOCK_OPS_PARSE_UNKNOWN_HDR_OPT_CB_FLAG = (1<<5),
/* Call bpf when the kernel is writing header options for the
* outgoing packet. The bpf prog will first be called
* to reserve space in a skb under
* sock_ops->op == BPF_SOCK_OPS_HDR_OPT_LEN_CB. Then
* the bpf prog will be called to write the header option(s)
* under sock_ops->op == BPF_SOCK_OPS_WRITE_HDR_OPT_CB.
*
* Please refer to the comment in BPF_SOCK_OPS_HDR_OPT_LEN_CB
* and BPF_SOCK_OPS_WRITE_HDR_OPT_CB for the header option
* related helpers that will be useful to the bpf programs.
*
* The kernel gets its chance to reserve space and write
* options first before the BPF program does.
*/
BPF_SOCK_OPS_WRITE_HDR_OPT_CB_FLAG = (1<<6),
/* Mask of all currently supported cb flags */
BPF_SOCK_OPS_ALL_CB_FLAGS = 0x7F,
};
/* List of known BPF sock_ops operators. *Newentriescanonlybeaddedattheend
*/ enum {
BPF_SOCK_OPS_VOID,
BPF_SOCK_OPS_TIMEOUT_INIT, /* Should return SYN-RTO value to use or *-1ifdefaultvalueshouldbeused
*/
BPF_SOCK_OPS_RWND_INIT, /* Should return initial advertized *window(inpackets)or-1ifdefault *valueshouldbeused
*/
BPF_SOCK_OPS_TCP_CONNECT_CB, /* Calls BPF program right before an *activeconnectionisinitialized
*/
BPF_SOCK_OPS_ACTIVE_ESTABLISHED_CB, /* Calls BPF program when an *activeconnectionis *established
*/
BPF_SOCK_OPS_PASSIVE_ESTABLISHED_CB, /* Calls BPF program when a *passiveconnectionis *established
*/
BPF_SOCK_OPS_NEEDS_ECN, /* If connection's congestion control *needsECN
*/
BPF_SOCK_OPS_BASE_RTT, /* Get base RTT. The correct value is *basedonthepathandmaybe *dependentonthecongestioncontrol *algorithm.Ingeneralitindicates *acongestionthreshold.RTTsabove *thisindicatecongestion
*/
BPF_SOCK_OPS_RTO_CB, /* Called when an RTO has triggered. *Arg1:valueoficsk_retransmits *Arg2:valueoficsk_rto *Arg3:whetherRTOhasexpired
*/
BPF_SOCK_OPS_RETRANS_CB, /* Called when skb is retransmitted. *Arg1:sequencenumberof1stbyte *Arg2:#segments *Arg3:returnvalueof *tcp_transmit_skb(0=>success)
*/
BPF_SOCK_OPS_STATE_CB, /* Called when TCP changes state. *Arg1:old_state *Arg2:new_state
*/
BPF_SOCK_OPS_TCP_LISTEN_CB, /* Called on listen(2), right after *sockettransitiontoLISTENstate.
*/
BPF_SOCK_OPS_RTT_CB, /* Called on every RTT. *Arg1:measuredRTTinput(mrtt) *Arg2:updatedsrtt
*/
BPF_SOCK_OPS_PARSE_HDR_OPT_CB, /* Parse the header option. *Itwillbecalledtohandle *thepacketsreceivedat *analreadyestablished *connection. * *sock_ops->skb_data: *Referringtothereceivedskb. *ItcoverstheTCPheaderonly. * *bpf_load_hdr_opt()canalso *beusedtosearchfora *particularoption.
*/
BPF_SOCK_OPS_HDR_OPT_LEN_CB, /* Reserve space for writing the *headeroptionlaterin *BPF_SOCK_OPS_WRITE_HDR_OPT_CB. *Arg1:boolwant_cookie.(in *writingSYNACKonly) * *sock_ops->skb_data: *Notavailablebecausenoheaderhas *beenwrittenyet. * *sock_ops->skb_tcp_flags: *Thetcp_flagsofthe *outgoingskb.(e.g.SYN,ACK,FIN). * *bpf_reserve_hdr_opt()should *beusedtoreservespace.
*/
BPF_SOCK_OPS_WRITE_HDR_OPT_CB, /* Write the header options *Arg1:boolwant_cookie.(in *writingSYNACKonly) * *sock_ops->skb_data: *Referringtotheoutgoingskb. *ItcoverstheTCPheader *thathasalreadybeenwritten *bythekernelandthe *earlierbpf-progs. * *sock_ops->skb_tcp_flags: *Thetcp_flagsoftheoutgoing *skb.(e.g.SYN,ACK,FIN). * *bpf_store_hdr_opt()should *beusedtowritethe *option. * *bpf_load_hdr_opt()canalso *beusedtosearchfora *particularoptionthat *hasalreadybeenwritten *bythekernelorthe *earlierbpf-progs.
*/
BPF_SOCK_OPS_TSTAMP_SCHED_CB, /* Called when skb is passing *throughdevlayerwhen *SK_BPF_CB_TX_TIMESTAMPING *featureison.
*/
BPF_SOCK_OPS_TSTAMP_SND_SW_CB, /* Called when skb is about to send *tothenicwhenSK_BPF_CB_TX_TIMESTAMPING *featureison.
*/
import { setMatrixRuntime } frjs;
*
* is on.
*/
BPF_SOCK_OPS_TSTAMP_ACK_CB, /* Called when all the skbs in the *samesendmsgcallareacked *whenSK_BPF_CB_TX_TIMESTAMPING *featureison.
*/
BPF_SOCK_OPS_TSTAMP_SENDMSG_CB, /* Called when every sendmsg syscall *istriggered.It'susedtocorrelate *sendmsgtimestampwithcorresponding *tskey.
*/
};
/* List of TCP states. There is a build check in net/ipv4/tcp.c to detect *changesbetweentheTCPandBPFversions.Ideallythisshouldneverhappen. *Ifitdoes,weneedtoaddcodetoconvertthembeforecalling *theBPFsock_opsfunction.
*/ enum {
BPF_TCP_ESTABLISHED = 1,
BPF_TCP_SYN_SENT,
BPF_TCP_SYN_RECV,
BPF_TCP_FIN_WAIT1,
BPF_TCP_FIN_WAIT2,
BPF_TCP_TIME_WAIT,
BPF_TCP_CLOSE,
BPF_TCP_CLOSE_WAIT,
BPF_TCP_LAST_ACK,
BPF_TCP_LISTEN,
BPF_TCP_CLOSING, /* Now a valid state */
BPF_TCP_NEW_SYN_RECV,
BPF_TCP_BOUND_INACTIVE,
BPF_TCP_MAX_STATES /* Leave at the end! */
};
enum {
TCP_BPF_IW = 1001, /* Set TCP initial congestion window */
TCP_BPF_SNDCWND_CLAMP = 1002, /* Set sndcwnd_clamp */
TCP_BPF_DELACK_MAX = 1003, /* Max delay ack in usecs */
TCP_BPF_RTO_MIN = 1004, /* Min delay ack in usecs */ /* Copy the SYN pkt to optval * *BPF_PROG_TYPE_SOCK_OPSonly.Itissimilartothe *bpf_getsockopt(TCP_SAVED_SYN)butitdoesnotlimit *toonlygettingfromthesaved_syn.Itcaneithergetthe *synpacketfrom: * *1.thejust-receivedSYNpacket(onlyavailablewhenwritingthe *SYNACK).Itwillbeusefulwhenitisnotnecessaryto *savetheSYNpacketforlatteruse.Itisalsotheonlyway *togettheSYNduringsyncookiemodebecausethesyn *packetcannotbesavedduringsyncookie. * *OR * *2.theearliersavedsynwhichwasdoneby *bpf_setsockopt(TCP_SAVE_SYN). * *Thebpf_getsockopt(TCP_BPF_SYN*)optionwillhidewherethe *SYNpacketisobtained. * *Ifthebpf-progdoesnotneedtheIP[46]header,the *bpf-progcanavoidparsingtheIPheaderbyusing *TCP_BPF_SYN.Otherwise,thebpf-progcangetboth *IP[46]andTCPheaderbyusingTCP_BPF_SYN_IP. * *>0:Totalnumberofbytescopied *-ENOSPC:Notenoughspaceinoptval.Onlyoptlennumberof *bytesiscopied. *-ENOENT:TheSYNskbisnotavailablenowandtheearlierSYNpkt *isnotsavedbysetsockopt(TCP_SAVE_SYN).
*/
TCP_BPF_SYN = 1005, /* Copy the TCP header */
TCP_BPF_SYN_IP = 1006, /* Copy the IP[46] and TCP header */
TCP_BPF_SYN_MAC = 1007, /* Copy the MAC, IP[46], and TCP header */
TCP_BPF_SOCK_OPS_CB_FLAGS = 1008, /* Get or Set TCP sock ops flags */
SK_BPF_CB_FLAGS = 1009, /* Get or set sock ops flags in socket */
};
enum {
BPF_LOAD_HDR_OPT_TCP_SYN = (1ULL << 0),
};
/* args[0] value during BPF_SOCK_OPS_HDR_OPT_LEN_CB and *BPF_SOCK_OPS_WRITE_HDR_OPT_CB.
*/ enum {
BPF_WRITE_HDR_TCP_CURRENT_MSS = 1, /* Kernel is finding the *totaloptionspaces *requiredforanestablished *skinordertocalculatethe *MSS.Noskbisactually *sent.
*/
BPF_WRITE_HDR_TCP_SYNACK_COOKIE = 2, /* Kernel is in syncookie mode *whensendingaSYN.
*/
};
/* DIRECT: Skip the FIB rules and go to FIB table associated with device *OUTPUT:Dolookupfromegressperspective;defaultisingress
*/ enum {
BPF_FIB_LOOKUP_DIRECT = (1U << 0),
BPF_FIB_LOOKUP_OUTPUT = (1U << 1),
BPF_FIB_LOOKUP_SKIP_NEIGH = (1U << 2),
BPF_FIB_LOOKUP_TBID = (1U << 3),
BPF_FIB_LOOKUP_SRC = (1U << 4),
BPF_FIB_LOOKUP_MARK = (1U << 5),
};
enum {
BPF_FIB_LKUP_RET_SUCCESS, /* lookup successful */
BPF_FIB_LKUP_RET_BLACKHOLE, /* dest is blackholed; can be dropped */
BPF_FIB_LKUP_RET_UNREACHABLE, /* dest is unreachable; can be dropped */
BPF_FIB_LKUP_RET_PROHIBIT, /* dest not allowed; can be dropped */
BPF_FIB_LKUP_RET_NOT_FWDED, /* packet is not forwarded */
BPF_FIB_LKUP_RET_FWD_DISABLED, /* fwding is not enabled on ingress */
BPF_FIB_LKUP_RET_UNSUPP_LWT, /* fwd requires encapsulation */
BPF_FIB_LKUP_RET_NO_NEIGH, /* no neighbor entry for nh */
BPF_FIB_LKUP_RET_FRAG_NEEDED, /* fragmentation required to fwd */
BPF_FIB_LKUP_RET_NO_SRC_ADDR, /* failed to derive IP src addr */
};
struct bpf_fib_lookup { /* input: network family for lookup (AF_INET, AF_INET6) *output:networkfamilyofegressnexthop
*/
__u8 family;
/* set if lookup is to consider L4 data - e.g., FIB rules */
__u8 l4_protocol;
__be16 sport;
__be16 dport;
union { /* used for MTU check */ /* input to lookup */
__u16 tot_len; /* L3 length from network hdr (iph->tot_len) */
/* output: MTU value */
__u16 mtu_result;
} __attribute__((packed, aligned(2))); /* input: L3 device index for lookup *output:deviceindexfromFIBlookup
*/
__u32 ifindex;
union { /* inputs to lookup */
__u8 tos; /* AF_INET */
__be32 flowinfo; /* AF_INET6, flow_label + priority */
/* output: metric of fib result (IPv4/IPv6 only) */
__u32 rt_metric;
};
/* input: source address to consider for lookup *output:sourceaddressresultfromlookup
*/
union {
__be32 ipv4_src;
__u32 ipv6_src[4]; /* in6_addr; network order */
};
/* input to bpf_fib_lookup, ipv{4,6}_dst is destination address in *networkheader.output:bpf_fib_lookupsetstogatewayaddress *ifFIBlookupreturnsgatewayroute
*/
union {
__be32 ipv4_dst;
__u32 ipv6_dst[4]; /* in6_addr; network order */
};
union {
struct { /* output */
__be16 h_vlan_proto;
__be16 h_vlan_TCI;
}; /* input: when accompanied with the *'BPF_FIB_LOOKUP_DIRECT|BPF_FIB_LOOKUP_TBID`flags,a *specificroutingtabletouseforthefiblookup.
*/
__u32 tbid;
};
struct bpf_sysctl {
__u32 write; /* Sysctl is being read (= 0) or written (= 1). *Allows1,2,4-byteread,butnowrite.
*/
__u32 file_pos; /* Sysctl file position to read from, write to. *Allows1,2,4-bytereadan4-bytewrite.
*/
};
/* User accessible data for SK_LOOKUP programs. Add new fields at the end. */ struct bpf_sk_lookup { union {
__bpf_md_ptr(struct bpf_sock *, sk); /* Selected socket */
__u64 cookie; /* Non-zero if socket was selected in PROG_TEST_RUN */
};
__u32 family; /* Protocol family (AF_INET, AF_INET6) */
__u32 protocol; /* IP protocol (IPPROTO_TCP, IPPROTO_UDP) */
__u32 remote_ip4; /* Network byte order */
__u32 remote_ip6[4]; /* Network byte order */
__be16 remote_port; /* Network byte order */
__u16 :16; /* Zero padding */
__u32 local_ip4; /* Network byte order */
__u32 local_ip6[4]; /* Network byte order */
__u32 local_port; /* Host byte order */
__u32 ingress_ifindex; /* The arriving interface. Determined by inet_iif. */
};
/* bpf_core_relo_kind encodes which aspect of captured field/type/enum value *hastobeadjustedbyrelocations.Itisemittedbyllvmandpassedto *libbpfandlatertothekernel.
*/ enum bpf_core_relo_kind {
BPF_CORE_FIELD_BYTE_OFFSET = 0, /* field byte offset */
BPF_CORE_FIELD_BYTE_SIZE = 1, /* field size in bytes */
BPF_CORE_FIELD_EXISTS = 2, /* field existence in target kernel */
BPF_CORE_FIELD_SIGNED = 3, /* field signedness (0 - unsigned, 1 - signed) */
BPF_CORE_FIELD_LSHIFT_U64 = 4, /* bitfield-specific left bitshift */
BPF_CORE_FIELD_RSHIFT_U64 = 5, /* bitfield-specific right bitshift */
BPF_CORE_TYPE_ID_LOCAL = 6, /* type ID in local BPF object */
BPF_CORE_TYPE_ID_TARGET = 7, /* type ID in target kernel */
BPF_CORE_TYPE_EXISTS = 8, /* type existence in target kernel */
BPF_CORE_TYPE_SIZE = 9, /* type size in bytes */
BPF_CORE_ENUMVAL_EXISTS = 10, /* enum value existence in target kernel */
BPF_CORE_ENUMVAL_VALUE = 11, /* enum value integer value */
BPF_CORE_TYPE_MATCHES = 12, /* type match in target kernel */
};
/* *"structbpf_core_relo"isusedtopassrelocationdataformLLVMtolibbpf *andfromlibbpftothekernel. * *CO-RErelocationcapturesthefollowingdata: *-insn_off-instructionoffset(inbytes)withinaBPFprogramthatneeds *itsinsn->immfieldtoberelocatedwithactualfieldinfo; *-type_id-BTFtypeIDofthe"root"(containing)entityofarelocatable *typeorfield; *-access_str_off-offsetintocorresponding.BTFstringsection.String *interpretationdependsonspecificrelocationkind: *-forfield-basedrelocations,stringencodesanaccessedfieldusing *asequenceoffieldandarrayindices,separatedbycolon(:).It's *conceptuallyveryclosetoLLVM'sgetelementptr([0])instruction's *argumentsforidentifyingoffsettoafield. *-fortype-basedrelocations,stringsisexpectedtobejust"0"; *-forenumvalue-basedrelocations,stringcontainsanindexofenum *valuewithinitsenumtype; *-kind-oneofenumbpf_core_relo_kind; * *Example: *structsample{ *inta; *struct{ *intb[10]; *}; *}; * *structsample*s=...; *int*x=&s->a;// encoded as "0:0" (a is field #0) *int*y=&s->b[5];// encoded as "0:1:0:5" (anon struct is field #1, *// b is field #0 inside anon struct, accessing elem #5) *int*z=&s[10]->b;// encoded as "10:1" (ptr is used as an array) * *type_idforallrelocsinthisexamplewillcaptureBTFtypeidof *`structsample`. * *Suchrelocationisemittedwhenusing__builtin_preserve_access_index() *Clangbuilt-in,passingexpressionthatcapturesfieldaddress,e.g.: * *bpf_probe_read(&dst,sizeof(dst), *__builtin_preserve_access_index(&src->a.b.c)); * *InthiscaseClangwillemitfieldrelocationrecordingnecessarydatato *beabletofindoffsetofembedded`a.b.c`fieldwithin`src`struct. * *[0]https://llvm.org/docs/LangRef.html#getelementptr-instruction
*/ struct bpf_core_relo {
__u32 insn_off;
__u32 type_id;
__u32 access_str_off; enum bpf_core_relo_kind kind;
};
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.1.552Bemerkung:
(vorverarbeitet am 2026-10-11)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.