128fbcfa0SAlexei Starovoitov /* Copyright (c) 2011-2014 PLUMgrid, http://plumgrid.com 281ed18abSAlexei Starovoitov * Copyright (c) 2016,2017 Facebook 328fbcfa0SAlexei Starovoitov * 428fbcfa0SAlexei Starovoitov * This program is free software; you can redistribute it and/or 528fbcfa0SAlexei Starovoitov * modify it under the terms of version 2 of the GNU General Public 628fbcfa0SAlexei Starovoitov * License as published by the Free Software Foundation. 728fbcfa0SAlexei Starovoitov * 828fbcfa0SAlexei Starovoitov * This program is distributed in the hope that it will be useful, but 928fbcfa0SAlexei Starovoitov * WITHOUT ANY WARRANTY; without even the implied warranty of 1028fbcfa0SAlexei Starovoitov * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU 1128fbcfa0SAlexei Starovoitov * General Public License for more details. 1228fbcfa0SAlexei Starovoitov */ 1328fbcfa0SAlexei Starovoitov #include <linux/bpf.h> 1428fbcfa0SAlexei Starovoitov #include <linux/err.h> 1528fbcfa0SAlexei Starovoitov #include <linux/slab.h> 1628fbcfa0SAlexei Starovoitov #include <linux/mm.h> 1704fd61abSAlexei Starovoitov #include <linux/filter.h> 180cdf5640SDaniel Borkmann #include <linux/perf_event.h> 1928fbcfa0SAlexei Starovoitov 20*56f668dfSMartin KaFai Lau #include "map_in_map.h" 21*56f668dfSMartin KaFai Lau 22a10423b8SAlexei Starovoitov static void bpf_array_free_percpu(struct bpf_array *array) 23a10423b8SAlexei Starovoitov { 24a10423b8SAlexei Starovoitov int i; 25a10423b8SAlexei Starovoitov 26a10423b8SAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 27a10423b8SAlexei Starovoitov free_percpu(array->pptrs[i]); 28a10423b8SAlexei Starovoitov } 29a10423b8SAlexei Starovoitov 30a10423b8SAlexei Starovoitov static int bpf_array_alloc_percpu(struct bpf_array *array) 31a10423b8SAlexei Starovoitov { 32a10423b8SAlexei Starovoitov void __percpu *ptr; 33a10423b8SAlexei Starovoitov int i; 34a10423b8SAlexei Starovoitov 35a10423b8SAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) { 36a10423b8SAlexei Starovoitov ptr = __alloc_percpu_gfp(array->elem_size, 8, 37a10423b8SAlexei Starovoitov GFP_USER | __GFP_NOWARN); 38a10423b8SAlexei Starovoitov if (!ptr) { 39a10423b8SAlexei Starovoitov bpf_array_free_percpu(array); 40a10423b8SAlexei Starovoitov return -ENOMEM; 41a10423b8SAlexei Starovoitov } 42a10423b8SAlexei Starovoitov array->pptrs[i] = ptr; 43a10423b8SAlexei Starovoitov } 44a10423b8SAlexei Starovoitov 45a10423b8SAlexei Starovoitov return 0; 46a10423b8SAlexei Starovoitov } 47a10423b8SAlexei Starovoitov 4828fbcfa0SAlexei Starovoitov /* Called from syscall */ 4928fbcfa0SAlexei Starovoitov static struct bpf_map *array_map_alloc(union bpf_attr *attr) 5028fbcfa0SAlexei Starovoitov { 51a10423b8SAlexei Starovoitov bool percpu = attr->map_type == BPF_MAP_TYPE_PERCPU_ARRAY; 5228fbcfa0SAlexei Starovoitov struct bpf_array *array; 53a10423b8SAlexei Starovoitov u64 array_size; 54a10423b8SAlexei Starovoitov u32 elem_size; 5528fbcfa0SAlexei Starovoitov 5628fbcfa0SAlexei Starovoitov /* check sanity of attributes */ 5728fbcfa0SAlexei Starovoitov if (attr->max_entries == 0 || attr->key_size != 4 || 58823707b6SAlexei Starovoitov attr->value_size == 0 || attr->map_flags) 5928fbcfa0SAlexei Starovoitov return ERR_PTR(-EINVAL); 6028fbcfa0SAlexei Starovoitov 617984c27cSMichal Hocko if (attr->value_size > KMALLOC_MAX_SIZE) 6201b3f521SAlexei Starovoitov /* if value_size is bigger, the user space won't be able to 6301b3f521SAlexei Starovoitov * access the elements. 6401b3f521SAlexei Starovoitov */ 6501b3f521SAlexei Starovoitov return ERR_PTR(-E2BIG); 6601b3f521SAlexei Starovoitov 6728fbcfa0SAlexei Starovoitov elem_size = round_up(attr->value_size, 8); 6828fbcfa0SAlexei Starovoitov 69a10423b8SAlexei Starovoitov array_size = sizeof(*array); 70a10423b8SAlexei Starovoitov if (percpu) 71a10423b8SAlexei Starovoitov array_size += (u64) attr->max_entries * sizeof(void *); 72a10423b8SAlexei Starovoitov else 73a10423b8SAlexei Starovoitov array_size += (u64) attr->max_entries * elem_size; 74a10423b8SAlexei Starovoitov 75a10423b8SAlexei Starovoitov /* make sure there is no u32 overflow later in round_up() */ 76a10423b8SAlexei Starovoitov if (array_size >= U32_MAX - PAGE_SIZE) 77daaf427cSAlexei Starovoitov return ERR_PTR(-ENOMEM); 78daaf427cSAlexei Starovoitov 7928fbcfa0SAlexei Starovoitov /* allocate all map elements and zero-initialize them */ 80d407bd25SDaniel Borkmann array = bpf_map_area_alloc(array_size); 8128fbcfa0SAlexei Starovoitov if (!array) 8228fbcfa0SAlexei Starovoitov return ERR_PTR(-ENOMEM); 8328fbcfa0SAlexei Starovoitov 8428fbcfa0SAlexei Starovoitov /* copy mandatory map attributes */ 85a10423b8SAlexei Starovoitov array->map.map_type = attr->map_type; 8628fbcfa0SAlexei Starovoitov array->map.key_size = attr->key_size; 8728fbcfa0SAlexei Starovoitov array->map.value_size = attr->value_size; 8828fbcfa0SAlexei Starovoitov array->map.max_entries = attr->max_entries; 8928fbcfa0SAlexei Starovoitov array->elem_size = elem_size; 9028fbcfa0SAlexei Starovoitov 91a10423b8SAlexei Starovoitov if (!percpu) 92a10423b8SAlexei Starovoitov goto out; 93a10423b8SAlexei Starovoitov 94a10423b8SAlexei Starovoitov array_size += (u64) attr->max_entries * elem_size * num_possible_cpus(); 95a10423b8SAlexei Starovoitov 96a10423b8SAlexei Starovoitov if (array_size >= U32_MAX - PAGE_SIZE || 97a10423b8SAlexei Starovoitov elem_size > PCPU_MIN_UNIT_SIZE || bpf_array_alloc_percpu(array)) { 98d407bd25SDaniel Borkmann bpf_map_area_free(array); 99a10423b8SAlexei Starovoitov return ERR_PTR(-ENOMEM); 100a10423b8SAlexei Starovoitov } 101a10423b8SAlexei Starovoitov out: 102a10423b8SAlexei Starovoitov array->map.pages = round_up(array_size, PAGE_SIZE) >> PAGE_SHIFT; 103a10423b8SAlexei Starovoitov 10428fbcfa0SAlexei Starovoitov return &array->map; 10528fbcfa0SAlexei Starovoitov } 10628fbcfa0SAlexei Starovoitov 10728fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 10828fbcfa0SAlexei Starovoitov static void *array_map_lookup_elem(struct bpf_map *map, void *key) 10928fbcfa0SAlexei Starovoitov { 11028fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 11128fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 11228fbcfa0SAlexei Starovoitov 113a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 11428fbcfa0SAlexei Starovoitov return NULL; 11528fbcfa0SAlexei Starovoitov 11628fbcfa0SAlexei Starovoitov return array->value + array->elem_size * index; 11728fbcfa0SAlexei Starovoitov } 11828fbcfa0SAlexei Starovoitov 11981ed18abSAlexei Starovoitov /* emit BPF instructions equivalent to C code of array_map_lookup_elem() */ 12081ed18abSAlexei Starovoitov static u32 array_map_gen_lookup(struct bpf_map *map, struct bpf_insn *insn_buf) 12181ed18abSAlexei Starovoitov { 12281ed18abSAlexei Starovoitov struct bpf_insn *insn = insn_buf; 123fad73a1aSMartin KaFai Lau u32 elem_size = round_up(map->value_size, 8); 12481ed18abSAlexei Starovoitov const int ret = BPF_REG_0; 12581ed18abSAlexei Starovoitov const int map_ptr = BPF_REG_1; 12681ed18abSAlexei Starovoitov const int index = BPF_REG_2; 12781ed18abSAlexei Starovoitov 12881ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_ADD, map_ptr, offsetof(struct bpf_array, value)); 12981ed18abSAlexei Starovoitov *insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0); 130fad73a1aSMartin KaFai Lau *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 3); 131fad73a1aSMartin KaFai Lau 132fad73a1aSMartin KaFai Lau if (is_power_of_2(elem_size)) { 13381ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(elem_size)); 13481ed18abSAlexei Starovoitov } else { 13581ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_MUL, ret, elem_size); 13681ed18abSAlexei Starovoitov } 13781ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_REG(BPF_ADD, ret, map_ptr); 13881ed18abSAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JA, 0, 0, 1); 13981ed18abSAlexei Starovoitov *insn++ = BPF_MOV64_IMM(ret, 0); 14081ed18abSAlexei Starovoitov return insn - insn_buf; 14181ed18abSAlexei Starovoitov } 14281ed18abSAlexei Starovoitov 143a10423b8SAlexei Starovoitov /* Called from eBPF program */ 144a10423b8SAlexei Starovoitov static void *percpu_array_map_lookup_elem(struct bpf_map *map, void *key) 145a10423b8SAlexei Starovoitov { 146a10423b8SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 147a10423b8SAlexei Starovoitov u32 index = *(u32 *)key; 148a10423b8SAlexei Starovoitov 149a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 150a10423b8SAlexei Starovoitov return NULL; 151a10423b8SAlexei Starovoitov 152a10423b8SAlexei Starovoitov return this_cpu_ptr(array->pptrs[index]); 153a10423b8SAlexei Starovoitov } 154a10423b8SAlexei Starovoitov 15515a07b33SAlexei Starovoitov int bpf_percpu_array_copy(struct bpf_map *map, void *key, void *value) 15615a07b33SAlexei Starovoitov { 15715a07b33SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 15815a07b33SAlexei Starovoitov u32 index = *(u32 *)key; 15915a07b33SAlexei Starovoitov void __percpu *pptr; 16015a07b33SAlexei Starovoitov int cpu, off = 0; 16115a07b33SAlexei Starovoitov u32 size; 16215a07b33SAlexei Starovoitov 16315a07b33SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 16415a07b33SAlexei Starovoitov return -ENOENT; 16515a07b33SAlexei Starovoitov 16615a07b33SAlexei Starovoitov /* per_cpu areas are zero-filled and bpf programs can only 16715a07b33SAlexei Starovoitov * access 'value_size' of them, so copying rounded areas 16815a07b33SAlexei Starovoitov * will not leak any kernel data 16915a07b33SAlexei Starovoitov */ 17015a07b33SAlexei Starovoitov size = round_up(map->value_size, 8); 17115a07b33SAlexei Starovoitov rcu_read_lock(); 17215a07b33SAlexei Starovoitov pptr = array->pptrs[index]; 17315a07b33SAlexei Starovoitov for_each_possible_cpu(cpu) { 17415a07b33SAlexei Starovoitov bpf_long_memcpy(value + off, per_cpu_ptr(pptr, cpu), size); 17515a07b33SAlexei Starovoitov off += size; 17615a07b33SAlexei Starovoitov } 17715a07b33SAlexei Starovoitov rcu_read_unlock(); 17815a07b33SAlexei Starovoitov return 0; 17915a07b33SAlexei Starovoitov } 18015a07b33SAlexei Starovoitov 18128fbcfa0SAlexei Starovoitov /* Called from syscall */ 18228fbcfa0SAlexei Starovoitov static int array_map_get_next_key(struct bpf_map *map, void *key, void *next_key) 18328fbcfa0SAlexei Starovoitov { 18428fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 18528fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 18628fbcfa0SAlexei Starovoitov u32 *next = (u32 *)next_key; 18728fbcfa0SAlexei Starovoitov 18828fbcfa0SAlexei Starovoitov if (index >= array->map.max_entries) { 18928fbcfa0SAlexei Starovoitov *next = 0; 19028fbcfa0SAlexei Starovoitov return 0; 19128fbcfa0SAlexei Starovoitov } 19228fbcfa0SAlexei Starovoitov 19328fbcfa0SAlexei Starovoitov if (index == array->map.max_entries - 1) 19428fbcfa0SAlexei Starovoitov return -ENOENT; 19528fbcfa0SAlexei Starovoitov 19628fbcfa0SAlexei Starovoitov *next = index + 1; 19728fbcfa0SAlexei Starovoitov return 0; 19828fbcfa0SAlexei Starovoitov } 19928fbcfa0SAlexei Starovoitov 20028fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 20128fbcfa0SAlexei Starovoitov static int array_map_update_elem(struct bpf_map *map, void *key, void *value, 20228fbcfa0SAlexei Starovoitov u64 map_flags) 20328fbcfa0SAlexei Starovoitov { 20428fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 20528fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 20628fbcfa0SAlexei Starovoitov 207a10423b8SAlexei Starovoitov if (unlikely(map_flags > BPF_EXIST)) 20828fbcfa0SAlexei Starovoitov /* unknown flags */ 20928fbcfa0SAlexei Starovoitov return -EINVAL; 21028fbcfa0SAlexei Starovoitov 211a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 21228fbcfa0SAlexei Starovoitov /* all elements were pre-allocated, cannot insert a new one */ 21328fbcfa0SAlexei Starovoitov return -E2BIG; 21428fbcfa0SAlexei Starovoitov 215a10423b8SAlexei Starovoitov if (unlikely(map_flags == BPF_NOEXIST)) 216daaf427cSAlexei Starovoitov /* all elements already exist */ 21728fbcfa0SAlexei Starovoitov return -EEXIST; 21828fbcfa0SAlexei Starovoitov 219a10423b8SAlexei Starovoitov if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) 220a10423b8SAlexei Starovoitov memcpy(this_cpu_ptr(array->pptrs[index]), 221a10423b8SAlexei Starovoitov value, map->value_size); 222a10423b8SAlexei Starovoitov else 223a10423b8SAlexei Starovoitov memcpy(array->value + array->elem_size * index, 224a10423b8SAlexei Starovoitov value, map->value_size); 22528fbcfa0SAlexei Starovoitov return 0; 22628fbcfa0SAlexei Starovoitov } 22728fbcfa0SAlexei Starovoitov 22815a07b33SAlexei Starovoitov int bpf_percpu_array_update(struct bpf_map *map, void *key, void *value, 22915a07b33SAlexei Starovoitov u64 map_flags) 23015a07b33SAlexei Starovoitov { 23115a07b33SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 23215a07b33SAlexei Starovoitov u32 index = *(u32 *)key; 23315a07b33SAlexei Starovoitov void __percpu *pptr; 23415a07b33SAlexei Starovoitov int cpu, off = 0; 23515a07b33SAlexei Starovoitov u32 size; 23615a07b33SAlexei Starovoitov 23715a07b33SAlexei Starovoitov if (unlikely(map_flags > BPF_EXIST)) 23815a07b33SAlexei Starovoitov /* unknown flags */ 23915a07b33SAlexei Starovoitov return -EINVAL; 24015a07b33SAlexei Starovoitov 24115a07b33SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 24215a07b33SAlexei Starovoitov /* all elements were pre-allocated, cannot insert a new one */ 24315a07b33SAlexei Starovoitov return -E2BIG; 24415a07b33SAlexei Starovoitov 24515a07b33SAlexei Starovoitov if (unlikely(map_flags == BPF_NOEXIST)) 24615a07b33SAlexei Starovoitov /* all elements already exist */ 24715a07b33SAlexei Starovoitov return -EEXIST; 24815a07b33SAlexei Starovoitov 24915a07b33SAlexei Starovoitov /* the user space will provide round_up(value_size, 8) bytes that 25015a07b33SAlexei Starovoitov * will be copied into per-cpu area. bpf programs can only access 25115a07b33SAlexei Starovoitov * value_size of it. During lookup the same extra bytes will be 25215a07b33SAlexei Starovoitov * returned or zeros which were zero-filled by percpu_alloc, 25315a07b33SAlexei Starovoitov * so no kernel data leaks possible 25415a07b33SAlexei Starovoitov */ 25515a07b33SAlexei Starovoitov size = round_up(map->value_size, 8); 25615a07b33SAlexei Starovoitov rcu_read_lock(); 25715a07b33SAlexei Starovoitov pptr = array->pptrs[index]; 25815a07b33SAlexei Starovoitov for_each_possible_cpu(cpu) { 25915a07b33SAlexei Starovoitov bpf_long_memcpy(per_cpu_ptr(pptr, cpu), value + off, size); 26015a07b33SAlexei Starovoitov off += size; 26115a07b33SAlexei Starovoitov } 26215a07b33SAlexei Starovoitov rcu_read_unlock(); 26315a07b33SAlexei Starovoitov return 0; 26415a07b33SAlexei Starovoitov } 26515a07b33SAlexei Starovoitov 26628fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 26728fbcfa0SAlexei Starovoitov static int array_map_delete_elem(struct bpf_map *map, void *key) 26828fbcfa0SAlexei Starovoitov { 26928fbcfa0SAlexei Starovoitov return -EINVAL; 27028fbcfa0SAlexei Starovoitov } 27128fbcfa0SAlexei Starovoitov 27228fbcfa0SAlexei Starovoitov /* Called when map->refcnt goes to zero, either from workqueue or from syscall */ 27328fbcfa0SAlexei Starovoitov static void array_map_free(struct bpf_map *map) 27428fbcfa0SAlexei Starovoitov { 27528fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 27628fbcfa0SAlexei Starovoitov 27728fbcfa0SAlexei Starovoitov /* at this point bpf_prog->aux->refcnt == 0 and this map->refcnt == 0, 27828fbcfa0SAlexei Starovoitov * so the programs (can be more than one that used this map) were 27928fbcfa0SAlexei Starovoitov * disconnected from events. Wait for outstanding programs to complete 28028fbcfa0SAlexei Starovoitov * and free the array 28128fbcfa0SAlexei Starovoitov */ 28228fbcfa0SAlexei Starovoitov synchronize_rcu(); 28328fbcfa0SAlexei Starovoitov 284a10423b8SAlexei Starovoitov if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) 285a10423b8SAlexei Starovoitov bpf_array_free_percpu(array); 286a10423b8SAlexei Starovoitov 287d407bd25SDaniel Borkmann bpf_map_area_free(array); 28828fbcfa0SAlexei Starovoitov } 28928fbcfa0SAlexei Starovoitov 290a2c83fffSDaniel Borkmann static const struct bpf_map_ops array_ops = { 29128fbcfa0SAlexei Starovoitov .map_alloc = array_map_alloc, 29228fbcfa0SAlexei Starovoitov .map_free = array_map_free, 29328fbcfa0SAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 29428fbcfa0SAlexei Starovoitov .map_lookup_elem = array_map_lookup_elem, 29528fbcfa0SAlexei Starovoitov .map_update_elem = array_map_update_elem, 29628fbcfa0SAlexei Starovoitov .map_delete_elem = array_map_delete_elem, 29781ed18abSAlexei Starovoitov .map_gen_lookup = array_map_gen_lookup, 29828fbcfa0SAlexei Starovoitov }; 29928fbcfa0SAlexei Starovoitov 300c78f8bdfSDaniel Borkmann static struct bpf_map_type_list array_type __ro_after_init = { 30128fbcfa0SAlexei Starovoitov .ops = &array_ops, 30228fbcfa0SAlexei Starovoitov .type = BPF_MAP_TYPE_ARRAY, 30328fbcfa0SAlexei Starovoitov }; 30428fbcfa0SAlexei Starovoitov 305a10423b8SAlexei Starovoitov static const struct bpf_map_ops percpu_array_ops = { 306a10423b8SAlexei Starovoitov .map_alloc = array_map_alloc, 307a10423b8SAlexei Starovoitov .map_free = array_map_free, 308a10423b8SAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 309a10423b8SAlexei Starovoitov .map_lookup_elem = percpu_array_map_lookup_elem, 310a10423b8SAlexei Starovoitov .map_update_elem = array_map_update_elem, 311a10423b8SAlexei Starovoitov .map_delete_elem = array_map_delete_elem, 312a10423b8SAlexei Starovoitov }; 313a10423b8SAlexei Starovoitov 314c78f8bdfSDaniel Borkmann static struct bpf_map_type_list percpu_array_type __ro_after_init = { 315a10423b8SAlexei Starovoitov .ops = &percpu_array_ops, 316a10423b8SAlexei Starovoitov .type = BPF_MAP_TYPE_PERCPU_ARRAY, 317a10423b8SAlexei Starovoitov }; 318a10423b8SAlexei Starovoitov 31928fbcfa0SAlexei Starovoitov static int __init register_array_map(void) 32028fbcfa0SAlexei Starovoitov { 321a2c83fffSDaniel Borkmann bpf_register_map_type(&array_type); 322a10423b8SAlexei Starovoitov bpf_register_map_type(&percpu_array_type); 32328fbcfa0SAlexei Starovoitov return 0; 32428fbcfa0SAlexei Starovoitov } 32528fbcfa0SAlexei Starovoitov late_initcall(register_array_map); 32604fd61abSAlexei Starovoitov 3272a36f0b9SWang Nan static struct bpf_map *fd_array_map_alloc(union bpf_attr *attr) 32804fd61abSAlexei Starovoitov { 3292a36f0b9SWang Nan /* only file descriptors can be stored in this type of map */ 33004fd61abSAlexei Starovoitov if (attr->value_size != sizeof(u32)) 33104fd61abSAlexei Starovoitov return ERR_PTR(-EINVAL); 33204fd61abSAlexei Starovoitov return array_map_alloc(attr); 33304fd61abSAlexei Starovoitov } 33404fd61abSAlexei Starovoitov 3352a36f0b9SWang Nan static void fd_array_map_free(struct bpf_map *map) 33604fd61abSAlexei Starovoitov { 33704fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 33804fd61abSAlexei Starovoitov int i; 33904fd61abSAlexei Starovoitov 34004fd61abSAlexei Starovoitov synchronize_rcu(); 34104fd61abSAlexei Starovoitov 34204fd61abSAlexei Starovoitov /* make sure it's empty */ 34304fd61abSAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 3442a36f0b9SWang Nan BUG_ON(array->ptrs[i] != NULL); 345d407bd25SDaniel Borkmann 346d407bd25SDaniel Borkmann bpf_map_area_free(array); 34704fd61abSAlexei Starovoitov } 34804fd61abSAlexei Starovoitov 3492a36f0b9SWang Nan static void *fd_array_map_lookup_elem(struct bpf_map *map, void *key) 35004fd61abSAlexei Starovoitov { 35104fd61abSAlexei Starovoitov return NULL; 35204fd61abSAlexei Starovoitov } 35304fd61abSAlexei Starovoitov 35404fd61abSAlexei Starovoitov /* only called from syscall */ 355d056a788SDaniel Borkmann int bpf_fd_array_map_update_elem(struct bpf_map *map, struct file *map_file, 356d056a788SDaniel Borkmann void *key, void *value, u64 map_flags) 35704fd61abSAlexei Starovoitov { 35804fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 3592a36f0b9SWang Nan void *new_ptr, *old_ptr; 36004fd61abSAlexei Starovoitov u32 index = *(u32 *)key, ufd; 36104fd61abSAlexei Starovoitov 36204fd61abSAlexei Starovoitov if (map_flags != BPF_ANY) 36304fd61abSAlexei Starovoitov return -EINVAL; 36404fd61abSAlexei Starovoitov 36504fd61abSAlexei Starovoitov if (index >= array->map.max_entries) 36604fd61abSAlexei Starovoitov return -E2BIG; 36704fd61abSAlexei Starovoitov 36804fd61abSAlexei Starovoitov ufd = *(u32 *)value; 369d056a788SDaniel Borkmann new_ptr = map->ops->map_fd_get_ptr(map, map_file, ufd); 3702a36f0b9SWang Nan if (IS_ERR(new_ptr)) 3712a36f0b9SWang Nan return PTR_ERR(new_ptr); 37204fd61abSAlexei Starovoitov 3732a36f0b9SWang Nan old_ptr = xchg(array->ptrs + index, new_ptr); 3742a36f0b9SWang Nan if (old_ptr) 3752a36f0b9SWang Nan map->ops->map_fd_put_ptr(old_ptr); 37604fd61abSAlexei Starovoitov 37704fd61abSAlexei Starovoitov return 0; 37804fd61abSAlexei Starovoitov } 37904fd61abSAlexei Starovoitov 3802a36f0b9SWang Nan static int fd_array_map_delete_elem(struct bpf_map *map, void *key) 38104fd61abSAlexei Starovoitov { 38204fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 3832a36f0b9SWang Nan void *old_ptr; 38404fd61abSAlexei Starovoitov u32 index = *(u32 *)key; 38504fd61abSAlexei Starovoitov 38604fd61abSAlexei Starovoitov if (index >= array->map.max_entries) 38704fd61abSAlexei Starovoitov return -E2BIG; 38804fd61abSAlexei Starovoitov 3892a36f0b9SWang Nan old_ptr = xchg(array->ptrs + index, NULL); 3902a36f0b9SWang Nan if (old_ptr) { 3912a36f0b9SWang Nan map->ops->map_fd_put_ptr(old_ptr); 39204fd61abSAlexei Starovoitov return 0; 39304fd61abSAlexei Starovoitov } else { 39404fd61abSAlexei Starovoitov return -ENOENT; 39504fd61abSAlexei Starovoitov } 39604fd61abSAlexei Starovoitov } 39704fd61abSAlexei Starovoitov 398d056a788SDaniel Borkmann static void *prog_fd_array_get_ptr(struct bpf_map *map, 399d056a788SDaniel Borkmann struct file *map_file, int fd) 4002a36f0b9SWang Nan { 4012a36f0b9SWang Nan struct bpf_array *array = container_of(map, struct bpf_array, map); 4022a36f0b9SWang Nan struct bpf_prog *prog = bpf_prog_get(fd); 403d056a788SDaniel Borkmann 4042a36f0b9SWang Nan if (IS_ERR(prog)) 4052a36f0b9SWang Nan return prog; 4062a36f0b9SWang Nan 4072a36f0b9SWang Nan if (!bpf_prog_array_compatible(array, prog)) { 4082a36f0b9SWang Nan bpf_prog_put(prog); 4092a36f0b9SWang Nan return ERR_PTR(-EINVAL); 4102a36f0b9SWang Nan } 411d056a788SDaniel Borkmann 4122a36f0b9SWang Nan return prog; 4132a36f0b9SWang Nan } 4142a36f0b9SWang Nan 4152a36f0b9SWang Nan static void prog_fd_array_put_ptr(void *ptr) 4162a36f0b9SWang Nan { 4171aacde3dSDaniel Borkmann bpf_prog_put(ptr); 4182a36f0b9SWang Nan } 4192a36f0b9SWang Nan 42004fd61abSAlexei Starovoitov /* decrement refcnt of all bpf_progs that are stored in this map */ 4212a36f0b9SWang Nan void bpf_fd_array_map_clear(struct bpf_map *map) 42204fd61abSAlexei Starovoitov { 42304fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 42404fd61abSAlexei Starovoitov int i; 42504fd61abSAlexei Starovoitov 42604fd61abSAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 4272a36f0b9SWang Nan fd_array_map_delete_elem(map, &i); 42804fd61abSAlexei Starovoitov } 42904fd61abSAlexei Starovoitov 43004fd61abSAlexei Starovoitov static const struct bpf_map_ops prog_array_ops = { 4312a36f0b9SWang Nan .map_alloc = fd_array_map_alloc, 4322a36f0b9SWang Nan .map_free = fd_array_map_free, 43304fd61abSAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 4342a36f0b9SWang Nan .map_lookup_elem = fd_array_map_lookup_elem, 4352a36f0b9SWang Nan .map_delete_elem = fd_array_map_delete_elem, 4362a36f0b9SWang Nan .map_fd_get_ptr = prog_fd_array_get_ptr, 4372a36f0b9SWang Nan .map_fd_put_ptr = prog_fd_array_put_ptr, 43804fd61abSAlexei Starovoitov }; 43904fd61abSAlexei Starovoitov 440c78f8bdfSDaniel Borkmann static struct bpf_map_type_list prog_array_type __ro_after_init = { 44104fd61abSAlexei Starovoitov .ops = &prog_array_ops, 44204fd61abSAlexei Starovoitov .type = BPF_MAP_TYPE_PROG_ARRAY, 44304fd61abSAlexei Starovoitov }; 44404fd61abSAlexei Starovoitov 44504fd61abSAlexei Starovoitov static int __init register_prog_array_map(void) 44604fd61abSAlexei Starovoitov { 44704fd61abSAlexei Starovoitov bpf_register_map_type(&prog_array_type); 44804fd61abSAlexei Starovoitov return 0; 44904fd61abSAlexei Starovoitov } 45004fd61abSAlexei Starovoitov late_initcall(register_prog_array_map); 451ea317b26SKaixu Xia 4523b1efb19SDaniel Borkmann static struct bpf_event_entry *bpf_event_entry_gen(struct file *perf_file, 4533b1efb19SDaniel Borkmann struct file *map_file) 454ea317b26SKaixu Xia { 4553b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 4563b1efb19SDaniel Borkmann 457858d68f1SDaniel Borkmann ee = kzalloc(sizeof(*ee), GFP_ATOMIC); 4583b1efb19SDaniel Borkmann if (ee) { 4593b1efb19SDaniel Borkmann ee->event = perf_file->private_data; 4603b1efb19SDaniel Borkmann ee->perf_file = perf_file; 4613b1efb19SDaniel Borkmann ee->map_file = map_file; 4623b1efb19SDaniel Borkmann } 4633b1efb19SDaniel Borkmann 4643b1efb19SDaniel Borkmann return ee; 4653b1efb19SDaniel Borkmann } 4663b1efb19SDaniel Borkmann 4673b1efb19SDaniel Borkmann static void __bpf_event_entry_free(struct rcu_head *rcu) 4683b1efb19SDaniel Borkmann { 4693b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 4703b1efb19SDaniel Borkmann 4713b1efb19SDaniel Borkmann ee = container_of(rcu, struct bpf_event_entry, rcu); 4723b1efb19SDaniel Borkmann fput(ee->perf_file); 4733b1efb19SDaniel Borkmann kfree(ee); 4743b1efb19SDaniel Borkmann } 4753b1efb19SDaniel Borkmann 4763b1efb19SDaniel Borkmann static void bpf_event_entry_free_rcu(struct bpf_event_entry *ee) 4773b1efb19SDaniel Borkmann { 4783b1efb19SDaniel Borkmann call_rcu(&ee->rcu, __bpf_event_entry_free); 479ea317b26SKaixu Xia } 480ea317b26SKaixu Xia 481d056a788SDaniel Borkmann static void *perf_event_fd_array_get_ptr(struct bpf_map *map, 482d056a788SDaniel Borkmann struct file *map_file, int fd) 483ea317b26SKaixu Xia { 484ea317b26SKaixu Xia const struct perf_event_attr *attr; 4853b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 4863b1efb19SDaniel Borkmann struct perf_event *event; 4873b1efb19SDaniel Borkmann struct file *perf_file; 488ea317b26SKaixu Xia 4893b1efb19SDaniel Borkmann perf_file = perf_event_get(fd); 4903b1efb19SDaniel Borkmann if (IS_ERR(perf_file)) 4913b1efb19SDaniel Borkmann return perf_file; 492e03e7ee3SAlexei Starovoitov 4933b1efb19SDaniel Borkmann event = perf_file->private_data; 4943b1efb19SDaniel Borkmann ee = ERR_PTR(-EINVAL); 495ea317b26SKaixu Xia 496ea317b26SKaixu Xia attr = perf_event_attrs(event); 4973b1efb19SDaniel Borkmann if (IS_ERR(attr) || attr->inherit) 4983b1efb19SDaniel Borkmann goto err_out; 499ea317b26SKaixu Xia 5003b1efb19SDaniel Borkmann switch (attr->type) { 5013b1efb19SDaniel Borkmann case PERF_TYPE_SOFTWARE: 5023b1efb19SDaniel Borkmann if (attr->config != PERF_COUNT_SW_BPF_OUTPUT) 5033b1efb19SDaniel Borkmann goto err_out; 5043b1efb19SDaniel Borkmann /* fall-through */ 5053b1efb19SDaniel Borkmann case PERF_TYPE_RAW: 5063b1efb19SDaniel Borkmann case PERF_TYPE_HARDWARE: 5073b1efb19SDaniel Borkmann ee = bpf_event_entry_gen(perf_file, map_file); 5083b1efb19SDaniel Borkmann if (ee) 5093b1efb19SDaniel Borkmann return ee; 5103b1efb19SDaniel Borkmann ee = ERR_PTR(-ENOMEM); 5113b1efb19SDaniel Borkmann /* fall-through */ 5123b1efb19SDaniel Borkmann default: 5133b1efb19SDaniel Borkmann break; 5143b1efb19SDaniel Borkmann } 51562544ce8SAlexei Starovoitov 5163b1efb19SDaniel Borkmann err_out: 5173b1efb19SDaniel Borkmann fput(perf_file); 5183b1efb19SDaniel Borkmann return ee; 519ea317b26SKaixu Xia } 520ea317b26SKaixu Xia 521ea317b26SKaixu Xia static void perf_event_fd_array_put_ptr(void *ptr) 522ea317b26SKaixu Xia { 5233b1efb19SDaniel Borkmann bpf_event_entry_free_rcu(ptr); 5243b1efb19SDaniel Borkmann } 5253b1efb19SDaniel Borkmann 5263b1efb19SDaniel Borkmann static void perf_event_fd_array_release(struct bpf_map *map, 5273b1efb19SDaniel Borkmann struct file *map_file) 5283b1efb19SDaniel Borkmann { 5293b1efb19SDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 5303b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 5313b1efb19SDaniel Borkmann int i; 5323b1efb19SDaniel Borkmann 5333b1efb19SDaniel Borkmann rcu_read_lock(); 5343b1efb19SDaniel Borkmann for (i = 0; i < array->map.max_entries; i++) { 5353b1efb19SDaniel Borkmann ee = READ_ONCE(array->ptrs[i]); 5363b1efb19SDaniel Borkmann if (ee && ee->map_file == map_file) 5373b1efb19SDaniel Borkmann fd_array_map_delete_elem(map, &i); 5383b1efb19SDaniel Borkmann } 5393b1efb19SDaniel Borkmann rcu_read_unlock(); 540ea317b26SKaixu Xia } 541ea317b26SKaixu Xia 542ea317b26SKaixu Xia static const struct bpf_map_ops perf_event_array_ops = { 543ea317b26SKaixu Xia .map_alloc = fd_array_map_alloc, 5443b1efb19SDaniel Borkmann .map_free = fd_array_map_free, 545ea317b26SKaixu Xia .map_get_next_key = array_map_get_next_key, 546ea317b26SKaixu Xia .map_lookup_elem = fd_array_map_lookup_elem, 547ea317b26SKaixu Xia .map_delete_elem = fd_array_map_delete_elem, 548ea317b26SKaixu Xia .map_fd_get_ptr = perf_event_fd_array_get_ptr, 549ea317b26SKaixu Xia .map_fd_put_ptr = perf_event_fd_array_put_ptr, 5503b1efb19SDaniel Borkmann .map_release = perf_event_fd_array_release, 551ea317b26SKaixu Xia }; 552ea317b26SKaixu Xia 553c78f8bdfSDaniel Borkmann static struct bpf_map_type_list perf_event_array_type __ro_after_init = { 554ea317b26SKaixu Xia .ops = &perf_event_array_ops, 555ea317b26SKaixu Xia .type = BPF_MAP_TYPE_PERF_EVENT_ARRAY, 556ea317b26SKaixu Xia }; 557ea317b26SKaixu Xia 558ea317b26SKaixu Xia static int __init register_perf_event_array_map(void) 559ea317b26SKaixu Xia { 560ea317b26SKaixu Xia bpf_register_map_type(&perf_event_array_type); 561ea317b26SKaixu Xia return 0; 562ea317b26SKaixu Xia } 563ea317b26SKaixu Xia late_initcall(register_perf_event_array_map); 5644ed8ec52SMartin KaFai Lau 56560d20f91SSargun Dhillon #ifdef CONFIG_CGROUPS 5664ed8ec52SMartin KaFai Lau static void *cgroup_fd_array_get_ptr(struct bpf_map *map, 5674ed8ec52SMartin KaFai Lau struct file *map_file /* not used */, 5684ed8ec52SMartin KaFai Lau int fd) 5694ed8ec52SMartin KaFai Lau { 5704ed8ec52SMartin KaFai Lau return cgroup_get_from_fd(fd); 5714ed8ec52SMartin KaFai Lau } 5724ed8ec52SMartin KaFai Lau 5734ed8ec52SMartin KaFai Lau static void cgroup_fd_array_put_ptr(void *ptr) 5744ed8ec52SMartin KaFai Lau { 5754ed8ec52SMartin KaFai Lau /* cgroup_put free cgrp after a rcu grace period */ 5764ed8ec52SMartin KaFai Lau cgroup_put(ptr); 5774ed8ec52SMartin KaFai Lau } 5784ed8ec52SMartin KaFai Lau 5794ed8ec52SMartin KaFai Lau static void cgroup_fd_array_free(struct bpf_map *map) 5804ed8ec52SMartin KaFai Lau { 5814ed8ec52SMartin KaFai Lau bpf_fd_array_map_clear(map); 5824ed8ec52SMartin KaFai Lau fd_array_map_free(map); 5834ed8ec52SMartin KaFai Lau } 5844ed8ec52SMartin KaFai Lau 5854ed8ec52SMartin KaFai Lau static const struct bpf_map_ops cgroup_array_ops = { 5864ed8ec52SMartin KaFai Lau .map_alloc = fd_array_map_alloc, 5874ed8ec52SMartin KaFai Lau .map_free = cgroup_fd_array_free, 5884ed8ec52SMartin KaFai Lau .map_get_next_key = array_map_get_next_key, 5894ed8ec52SMartin KaFai Lau .map_lookup_elem = fd_array_map_lookup_elem, 5904ed8ec52SMartin KaFai Lau .map_delete_elem = fd_array_map_delete_elem, 5914ed8ec52SMartin KaFai Lau .map_fd_get_ptr = cgroup_fd_array_get_ptr, 5924ed8ec52SMartin KaFai Lau .map_fd_put_ptr = cgroup_fd_array_put_ptr, 5934ed8ec52SMartin KaFai Lau }; 5944ed8ec52SMartin KaFai Lau 595c78f8bdfSDaniel Borkmann static struct bpf_map_type_list cgroup_array_type __ro_after_init = { 5964ed8ec52SMartin KaFai Lau .ops = &cgroup_array_ops, 5974ed8ec52SMartin KaFai Lau .type = BPF_MAP_TYPE_CGROUP_ARRAY, 5984ed8ec52SMartin KaFai Lau }; 5994ed8ec52SMartin KaFai Lau 6004ed8ec52SMartin KaFai Lau static int __init register_cgroup_array_map(void) 6014ed8ec52SMartin KaFai Lau { 6024ed8ec52SMartin KaFai Lau bpf_register_map_type(&cgroup_array_type); 6034ed8ec52SMartin KaFai Lau return 0; 6044ed8ec52SMartin KaFai Lau } 6054ed8ec52SMartin KaFai Lau late_initcall(register_cgroup_array_map); 6064ed8ec52SMartin KaFai Lau #endif 607*56f668dfSMartin KaFai Lau 608*56f668dfSMartin KaFai Lau static struct bpf_map *array_of_map_alloc(union bpf_attr *attr) 609*56f668dfSMartin KaFai Lau { 610*56f668dfSMartin KaFai Lau struct bpf_map *map, *inner_map_meta; 611*56f668dfSMartin KaFai Lau 612*56f668dfSMartin KaFai Lau inner_map_meta = bpf_map_meta_alloc(attr->inner_map_fd); 613*56f668dfSMartin KaFai Lau if (IS_ERR(inner_map_meta)) 614*56f668dfSMartin KaFai Lau return inner_map_meta; 615*56f668dfSMartin KaFai Lau 616*56f668dfSMartin KaFai Lau map = fd_array_map_alloc(attr); 617*56f668dfSMartin KaFai Lau if (IS_ERR(map)) { 618*56f668dfSMartin KaFai Lau bpf_map_meta_free(inner_map_meta); 619*56f668dfSMartin KaFai Lau return map; 620*56f668dfSMartin KaFai Lau } 621*56f668dfSMartin KaFai Lau 622*56f668dfSMartin KaFai Lau map->inner_map_meta = inner_map_meta; 623*56f668dfSMartin KaFai Lau 624*56f668dfSMartin KaFai Lau return map; 625*56f668dfSMartin KaFai Lau } 626*56f668dfSMartin KaFai Lau 627*56f668dfSMartin KaFai Lau static void array_of_map_free(struct bpf_map *map) 628*56f668dfSMartin KaFai Lau { 629*56f668dfSMartin KaFai Lau /* map->inner_map_meta is only accessed by syscall which 630*56f668dfSMartin KaFai Lau * is protected by fdget/fdput. 631*56f668dfSMartin KaFai Lau */ 632*56f668dfSMartin KaFai Lau bpf_map_meta_free(map->inner_map_meta); 633*56f668dfSMartin KaFai Lau bpf_fd_array_map_clear(map); 634*56f668dfSMartin KaFai Lau fd_array_map_free(map); 635*56f668dfSMartin KaFai Lau } 636*56f668dfSMartin KaFai Lau 637*56f668dfSMartin KaFai Lau static void *array_of_map_lookup_elem(struct bpf_map *map, void *key) 638*56f668dfSMartin KaFai Lau { 639*56f668dfSMartin KaFai Lau struct bpf_map **inner_map = array_map_lookup_elem(map, key); 640*56f668dfSMartin KaFai Lau 641*56f668dfSMartin KaFai Lau if (!inner_map) 642*56f668dfSMartin KaFai Lau return NULL; 643*56f668dfSMartin KaFai Lau 644*56f668dfSMartin KaFai Lau return READ_ONCE(*inner_map); 645*56f668dfSMartin KaFai Lau } 646*56f668dfSMartin KaFai Lau 647*56f668dfSMartin KaFai Lau static const struct bpf_map_ops array_of_map_ops = { 648*56f668dfSMartin KaFai Lau .map_alloc = array_of_map_alloc, 649*56f668dfSMartin KaFai Lau .map_free = array_of_map_free, 650*56f668dfSMartin KaFai Lau .map_get_next_key = array_map_get_next_key, 651*56f668dfSMartin KaFai Lau .map_lookup_elem = array_of_map_lookup_elem, 652*56f668dfSMartin KaFai Lau .map_delete_elem = fd_array_map_delete_elem, 653*56f668dfSMartin KaFai Lau .map_fd_get_ptr = bpf_map_fd_get_ptr, 654*56f668dfSMartin KaFai Lau .map_fd_put_ptr = bpf_map_fd_put_ptr, 655*56f668dfSMartin KaFai Lau }; 656*56f668dfSMartin KaFai Lau 657*56f668dfSMartin KaFai Lau static struct bpf_map_type_list array_of_map_type __ro_after_init = { 658*56f668dfSMartin KaFai Lau .ops = &array_of_map_ops, 659*56f668dfSMartin KaFai Lau .type = BPF_MAP_TYPE_ARRAY_OF_MAPS, 660*56f668dfSMartin KaFai Lau }; 661*56f668dfSMartin KaFai Lau 662*56f668dfSMartin KaFai Lau static int __init register_array_of_map(void) 663*56f668dfSMartin KaFai Lau { 664*56f668dfSMartin KaFai Lau bpf_register_map_type(&array_of_map_type); 665*56f668dfSMartin KaFai Lau return 0; 666*56f668dfSMartin KaFai Lau } 667*56f668dfSMartin KaFai Lau late_initcall(register_array_of_map); 668