15b497af4SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 228fbcfa0SAlexei Starovoitov /* Copyright (c) 2011-2014 PLUMgrid, http://plumgrid.com 381ed18abSAlexei Starovoitov * Copyright (c) 2016,2017 Facebook 428fbcfa0SAlexei Starovoitov */ 528fbcfa0SAlexei Starovoitov #include <linux/bpf.h> 6a26ca7c9SMartin KaFai Lau #include <linux/btf.h> 728fbcfa0SAlexei Starovoitov #include <linux/err.h> 828fbcfa0SAlexei Starovoitov #include <linux/slab.h> 928fbcfa0SAlexei Starovoitov #include <linux/mm.h> 1004fd61abSAlexei Starovoitov #include <linux/filter.h> 110cdf5640SDaniel Borkmann #include <linux/perf_event.h> 12a26ca7c9SMartin KaFai Lau #include <uapi/linux/btf.h> 131e6c62a8SAlexei Starovoitov #include <linux/rcupdate_trace.h> 14c317ab71SMenglong Dong #include <linux/btf_ids.h> 1528fbcfa0SAlexei Starovoitov 1656f668dfSMartin KaFai Lau #include "map_in_map.h" 1756f668dfSMartin KaFai Lau 186e71b04aSChenbo Feng #define ARRAY_CREATE_FLAG_MASK \ 19792cacccSSong Liu (BPF_F_NUMA_NODE | BPF_F_MMAPABLE | BPF_F_ACCESS_MASK | \ 204a8f87e6SDaniel Borkmann BPF_F_PRESERVE_ELEMS | BPF_F_INNER_MAP) 216e71b04aSChenbo Feng 22a10423b8SAlexei Starovoitov static void bpf_array_free_percpu(struct bpf_array *array) 23a10423b8SAlexei Starovoitov { 24a10423b8SAlexei Starovoitov int i; 25a10423b8SAlexei Starovoitov 2632fff239SEric Dumazet for (i = 0; i < array->map.max_entries; i++) { 27a10423b8SAlexei Starovoitov free_percpu(array->pptrs[i]); 2832fff239SEric Dumazet cond_resched(); 2932fff239SEric Dumazet } 30a10423b8SAlexei Starovoitov } 31a10423b8SAlexei Starovoitov 32a10423b8SAlexei Starovoitov static int bpf_array_alloc_percpu(struct bpf_array *array) 33a10423b8SAlexei Starovoitov { 34a10423b8SAlexei Starovoitov void __percpu *ptr; 35a10423b8SAlexei Starovoitov int i; 36a10423b8SAlexei Starovoitov 37a10423b8SAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) { 386d192c79SRoman Gushchin ptr = bpf_map_alloc_percpu(&array->map, array->elem_size, 8, 39a10423b8SAlexei Starovoitov GFP_USER | __GFP_NOWARN); 40a10423b8SAlexei Starovoitov if (!ptr) { 41a10423b8SAlexei Starovoitov bpf_array_free_percpu(array); 42a10423b8SAlexei Starovoitov return -ENOMEM; 43a10423b8SAlexei Starovoitov } 44a10423b8SAlexei Starovoitov array->pptrs[i] = ptr; 4532fff239SEric Dumazet cond_resched(); 46a10423b8SAlexei Starovoitov } 47a10423b8SAlexei Starovoitov 48a10423b8SAlexei Starovoitov return 0; 49a10423b8SAlexei Starovoitov } 50a10423b8SAlexei Starovoitov 5128fbcfa0SAlexei Starovoitov /* Called from syscall */ 525dc4c4b7SMartin KaFai Lau int array_map_alloc_check(union bpf_attr *attr) 53ad46061fSJakub Kicinski { 54ad46061fSJakub Kicinski bool percpu = attr->map_type == BPF_MAP_TYPE_PERCPU_ARRAY; 55ad46061fSJakub Kicinski int numa_node = bpf_map_attr_numa_node(attr); 56ad46061fSJakub Kicinski 57ad46061fSJakub Kicinski /* check sanity of attributes */ 58ad46061fSJakub Kicinski if (attr->max_entries == 0 || attr->key_size != 4 || 59ad46061fSJakub Kicinski attr->value_size == 0 || 60ad46061fSJakub Kicinski attr->map_flags & ~ARRAY_CREATE_FLAG_MASK || 61591fe988SDaniel Borkmann !bpf_map_flags_access_ok(attr->map_flags) || 62ad46061fSJakub Kicinski (percpu && numa_node != NUMA_NO_NODE)) 63ad46061fSJakub Kicinski return -EINVAL; 64ad46061fSJakub Kicinski 65fc970227SAndrii Nakryiko if (attr->map_type != BPF_MAP_TYPE_ARRAY && 664a8f87e6SDaniel Borkmann attr->map_flags & (BPF_F_MMAPABLE | BPF_F_INNER_MAP)) 67fc970227SAndrii Nakryiko return -EINVAL; 68fc970227SAndrii Nakryiko 69792cacccSSong Liu if (attr->map_type != BPF_MAP_TYPE_PERF_EVENT_ARRAY && 70792cacccSSong Liu attr->map_flags & BPF_F_PRESERVE_ELEMS) 71792cacccSSong Liu return -EINVAL; 72792cacccSSong Liu 73ad46061fSJakub Kicinski if (attr->value_size > KMALLOC_MAX_SIZE) 74ad46061fSJakub Kicinski /* if value_size is bigger, the user space won't be able to 75ad46061fSJakub Kicinski * access the elements. 76ad46061fSJakub Kicinski */ 77ad46061fSJakub Kicinski return -E2BIG; 78ad46061fSJakub Kicinski 79ad46061fSJakub Kicinski return 0; 80ad46061fSJakub Kicinski } 81ad46061fSJakub Kicinski 8228fbcfa0SAlexei Starovoitov static struct bpf_map *array_map_alloc(union bpf_attr *attr) 8328fbcfa0SAlexei Starovoitov { 84a10423b8SAlexei Starovoitov bool percpu = attr->map_type == BPF_MAP_TYPE_PERCPU_ARRAY; 851bc59756SRoman Gushchin int numa_node = bpf_map_attr_numa_node(attr); 86b2157399SAlexei Starovoitov u32 elem_size, index_mask, max_entries; 872c78ee89SAlexei Starovoitov bool bypass_spec_v1 = bpf_bypass_spec_v1(); 881bc59756SRoman Gushchin u64 array_size, mask64; 8928fbcfa0SAlexei Starovoitov struct bpf_array *array; 9028fbcfa0SAlexei Starovoitov 9128fbcfa0SAlexei Starovoitov elem_size = round_up(attr->value_size, 8); 9228fbcfa0SAlexei Starovoitov 93b2157399SAlexei Starovoitov max_entries = attr->max_entries; 94b2157399SAlexei Starovoitov 95bbeb6e43SDaniel Borkmann /* On 32 bit archs roundup_pow_of_two() with max_entries that has 96bbeb6e43SDaniel Borkmann * upper most bit set in u32 space is undefined behavior due to 97bbeb6e43SDaniel Borkmann * resulting 1U << 32, so do it manually here in u64 space. 98bbeb6e43SDaniel Borkmann */ 99bbeb6e43SDaniel Borkmann mask64 = fls_long(max_entries - 1); 100bbeb6e43SDaniel Borkmann mask64 = 1ULL << mask64; 101bbeb6e43SDaniel Borkmann mask64 -= 1; 102bbeb6e43SDaniel Borkmann 103bbeb6e43SDaniel Borkmann index_mask = mask64; 1042c78ee89SAlexei Starovoitov if (!bypass_spec_v1) { 105b2157399SAlexei Starovoitov /* round up array size to nearest power of 2, 106b2157399SAlexei Starovoitov * since cpu will speculate within index_mask limits 107b2157399SAlexei Starovoitov */ 108b2157399SAlexei Starovoitov max_entries = index_mask + 1; 109bbeb6e43SDaniel Borkmann /* Check for overflows. */ 110bbeb6e43SDaniel Borkmann if (max_entries < attr->max_entries) 111bbeb6e43SDaniel Borkmann return ERR_PTR(-E2BIG); 112bbeb6e43SDaniel Borkmann } 113b2157399SAlexei Starovoitov 114a10423b8SAlexei Starovoitov array_size = sizeof(*array); 115fc970227SAndrii Nakryiko if (percpu) { 116b2157399SAlexei Starovoitov array_size += (u64) max_entries * sizeof(void *); 117fc970227SAndrii Nakryiko } else { 118fc970227SAndrii Nakryiko /* rely on vmalloc() to return page-aligned memory and 119fc970227SAndrii Nakryiko * ensure array->value is exactly page-aligned 120fc970227SAndrii Nakryiko */ 121fc970227SAndrii Nakryiko if (attr->map_flags & BPF_F_MMAPABLE) { 122fc970227SAndrii Nakryiko array_size = PAGE_ALIGN(array_size); 123fc970227SAndrii Nakryiko array_size += PAGE_ALIGN((u64) max_entries * elem_size); 124fc970227SAndrii Nakryiko } else { 125b2157399SAlexei Starovoitov array_size += (u64) max_entries * elem_size; 126fc970227SAndrii Nakryiko } 127fc970227SAndrii Nakryiko } 128a10423b8SAlexei Starovoitov 12928fbcfa0SAlexei Starovoitov /* allocate all map elements and zero-initialize them */ 130fc970227SAndrii Nakryiko if (attr->map_flags & BPF_F_MMAPABLE) { 131fc970227SAndrii Nakryiko void *data; 132fc970227SAndrii Nakryiko 133fc970227SAndrii Nakryiko /* kmalloc'ed memory can't be mmap'ed, use explicit vmalloc */ 134fc970227SAndrii Nakryiko data = bpf_map_area_mmapable_alloc(array_size, numa_node); 1351bc59756SRoman Gushchin if (!data) 136fc970227SAndrii Nakryiko return ERR_PTR(-ENOMEM); 137fc970227SAndrii Nakryiko array = data + PAGE_ALIGN(sizeof(struct bpf_array)) 138fc970227SAndrii Nakryiko - offsetof(struct bpf_array, value); 139fc970227SAndrii Nakryiko } else { 14096eabe7aSMartin KaFai Lau array = bpf_map_area_alloc(array_size, numa_node); 141fc970227SAndrii Nakryiko } 1421bc59756SRoman Gushchin if (!array) 14328fbcfa0SAlexei Starovoitov return ERR_PTR(-ENOMEM); 144b2157399SAlexei Starovoitov array->index_mask = index_mask; 1452c78ee89SAlexei Starovoitov array->map.bypass_spec_v1 = bypass_spec_v1; 14628fbcfa0SAlexei Starovoitov 14728fbcfa0SAlexei Starovoitov /* copy mandatory map attributes */ 14832852649SJakub Kicinski bpf_map_init_from_attr(&array->map, attr); 14928fbcfa0SAlexei Starovoitov array->elem_size = elem_size; 15028fbcfa0SAlexei Starovoitov 1519c2d63b8SDaniel Borkmann if (percpu && bpf_array_alloc_percpu(array)) { 152d407bd25SDaniel Borkmann bpf_map_area_free(array); 153a10423b8SAlexei Starovoitov return ERR_PTR(-ENOMEM); 154a10423b8SAlexei Starovoitov } 155a10423b8SAlexei Starovoitov 15628fbcfa0SAlexei Starovoitov return &array->map; 15728fbcfa0SAlexei Starovoitov } 15828fbcfa0SAlexei Starovoitov 15928fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 16028fbcfa0SAlexei Starovoitov static void *array_map_lookup_elem(struct bpf_map *map, void *key) 16128fbcfa0SAlexei Starovoitov { 16228fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 16328fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 16428fbcfa0SAlexei Starovoitov 165a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 16628fbcfa0SAlexei Starovoitov return NULL; 16728fbcfa0SAlexei Starovoitov 168b2157399SAlexei Starovoitov return array->value + array->elem_size * (index & array->index_mask); 16928fbcfa0SAlexei Starovoitov } 17028fbcfa0SAlexei Starovoitov 171d8eca5bbSDaniel Borkmann static int array_map_direct_value_addr(const struct bpf_map *map, u64 *imm, 172d8eca5bbSDaniel Borkmann u32 off) 173d8eca5bbSDaniel Borkmann { 174d8eca5bbSDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 175d8eca5bbSDaniel Borkmann 176d8eca5bbSDaniel Borkmann if (map->max_entries != 1) 177d8eca5bbSDaniel Borkmann return -ENOTSUPP; 178d8eca5bbSDaniel Borkmann if (off >= map->value_size) 179d8eca5bbSDaniel Borkmann return -EINVAL; 180d8eca5bbSDaniel Borkmann 181d8eca5bbSDaniel Borkmann *imm = (unsigned long)array->value; 182d8eca5bbSDaniel Borkmann return 0; 183d8eca5bbSDaniel Borkmann } 184d8eca5bbSDaniel Borkmann 185d8eca5bbSDaniel Borkmann static int array_map_direct_value_meta(const struct bpf_map *map, u64 imm, 186d8eca5bbSDaniel Borkmann u32 *off) 187d8eca5bbSDaniel Borkmann { 188d8eca5bbSDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 189d8eca5bbSDaniel Borkmann u64 base = (unsigned long)array->value; 190d8eca5bbSDaniel Borkmann u64 range = array->elem_size; 191d8eca5bbSDaniel Borkmann 192d8eca5bbSDaniel Borkmann if (map->max_entries != 1) 193d8eca5bbSDaniel Borkmann return -ENOTSUPP; 194d8eca5bbSDaniel Borkmann if (imm < base || imm >= base + range) 195d8eca5bbSDaniel Borkmann return -ENOENT; 196d8eca5bbSDaniel Borkmann 197d8eca5bbSDaniel Borkmann *off = imm - base; 198d8eca5bbSDaniel Borkmann return 0; 199d8eca5bbSDaniel Borkmann } 200d8eca5bbSDaniel Borkmann 20181ed18abSAlexei Starovoitov /* emit BPF instructions equivalent to C code of array_map_lookup_elem() */ 2024a8f87e6SDaniel Borkmann static int array_map_gen_lookup(struct bpf_map *map, struct bpf_insn *insn_buf) 20381ed18abSAlexei Starovoitov { 204b2157399SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 20581ed18abSAlexei Starovoitov struct bpf_insn *insn = insn_buf; 206fad73a1aSMartin KaFai Lau u32 elem_size = round_up(map->value_size, 8); 20781ed18abSAlexei Starovoitov const int ret = BPF_REG_0; 20881ed18abSAlexei Starovoitov const int map_ptr = BPF_REG_1; 20981ed18abSAlexei Starovoitov const int index = BPF_REG_2; 21081ed18abSAlexei Starovoitov 2114a8f87e6SDaniel Borkmann if (map->map_flags & BPF_F_INNER_MAP) 2124a8f87e6SDaniel Borkmann return -EOPNOTSUPP; 2134a8f87e6SDaniel Borkmann 21481ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_ADD, map_ptr, offsetof(struct bpf_array, value)); 21581ed18abSAlexei Starovoitov *insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0); 2162c78ee89SAlexei Starovoitov if (!map->bypass_spec_v1) { 217b2157399SAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 4); 218b2157399SAlexei Starovoitov *insn++ = BPF_ALU32_IMM(BPF_AND, ret, array->index_mask); 219b2157399SAlexei Starovoitov } else { 220fad73a1aSMartin KaFai Lau *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 3); 221b2157399SAlexei Starovoitov } 222fad73a1aSMartin KaFai Lau 223fad73a1aSMartin KaFai Lau if (is_power_of_2(elem_size)) { 22481ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(elem_size)); 22581ed18abSAlexei Starovoitov } else { 22681ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_MUL, ret, elem_size); 22781ed18abSAlexei Starovoitov } 22881ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_REG(BPF_ADD, ret, map_ptr); 22981ed18abSAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JA, 0, 0, 1); 23081ed18abSAlexei Starovoitov *insn++ = BPF_MOV64_IMM(ret, 0); 23181ed18abSAlexei Starovoitov return insn - insn_buf; 23281ed18abSAlexei Starovoitov } 23381ed18abSAlexei Starovoitov 234a10423b8SAlexei Starovoitov /* Called from eBPF program */ 235a10423b8SAlexei Starovoitov static void *percpu_array_map_lookup_elem(struct bpf_map *map, void *key) 236a10423b8SAlexei Starovoitov { 237a10423b8SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 238a10423b8SAlexei Starovoitov u32 index = *(u32 *)key; 239a10423b8SAlexei Starovoitov 240a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 241a10423b8SAlexei Starovoitov return NULL; 242a10423b8SAlexei Starovoitov 243b2157399SAlexei Starovoitov return this_cpu_ptr(array->pptrs[index & array->index_mask]); 244a10423b8SAlexei Starovoitov } 245a10423b8SAlexei Starovoitov 24615a07b33SAlexei Starovoitov int bpf_percpu_array_copy(struct bpf_map *map, void *key, void *value) 24715a07b33SAlexei Starovoitov { 24815a07b33SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 24915a07b33SAlexei Starovoitov u32 index = *(u32 *)key; 25015a07b33SAlexei Starovoitov void __percpu *pptr; 25115a07b33SAlexei Starovoitov int cpu, off = 0; 25215a07b33SAlexei Starovoitov u32 size; 25315a07b33SAlexei Starovoitov 25415a07b33SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 25515a07b33SAlexei Starovoitov return -ENOENT; 25615a07b33SAlexei Starovoitov 25715a07b33SAlexei Starovoitov /* per_cpu areas are zero-filled and bpf programs can only 25815a07b33SAlexei Starovoitov * access 'value_size' of them, so copying rounded areas 25915a07b33SAlexei Starovoitov * will not leak any kernel data 26015a07b33SAlexei Starovoitov */ 26115a07b33SAlexei Starovoitov size = round_up(map->value_size, 8); 26215a07b33SAlexei Starovoitov rcu_read_lock(); 263b2157399SAlexei Starovoitov pptr = array->pptrs[index & array->index_mask]; 26415a07b33SAlexei Starovoitov for_each_possible_cpu(cpu) { 26515a07b33SAlexei Starovoitov bpf_long_memcpy(value + off, per_cpu_ptr(pptr, cpu), size); 26615a07b33SAlexei Starovoitov off += size; 26715a07b33SAlexei Starovoitov } 26815a07b33SAlexei Starovoitov rcu_read_unlock(); 26915a07b33SAlexei Starovoitov return 0; 27015a07b33SAlexei Starovoitov } 27115a07b33SAlexei Starovoitov 27228fbcfa0SAlexei Starovoitov /* Called from syscall */ 27328fbcfa0SAlexei Starovoitov static int array_map_get_next_key(struct bpf_map *map, void *key, void *next_key) 27428fbcfa0SAlexei Starovoitov { 27528fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 2768fe45924STeng Qin u32 index = key ? *(u32 *)key : U32_MAX; 27728fbcfa0SAlexei Starovoitov u32 *next = (u32 *)next_key; 27828fbcfa0SAlexei Starovoitov 27928fbcfa0SAlexei Starovoitov if (index >= array->map.max_entries) { 28028fbcfa0SAlexei Starovoitov *next = 0; 28128fbcfa0SAlexei Starovoitov return 0; 28228fbcfa0SAlexei Starovoitov } 28328fbcfa0SAlexei Starovoitov 28428fbcfa0SAlexei Starovoitov if (index == array->map.max_entries - 1) 28528fbcfa0SAlexei Starovoitov return -ENOENT; 28628fbcfa0SAlexei Starovoitov 28728fbcfa0SAlexei Starovoitov *next = index + 1; 28828fbcfa0SAlexei Starovoitov return 0; 28928fbcfa0SAlexei Starovoitov } 29028fbcfa0SAlexei Starovoitov 29114a324f6SKumar Kartikeya Dwivedi static void check_and_free_fields(struct bpf_array *arr, void *val) 29268134668SAlexei Starovoitov { 29314a324f6SKumar Kartikeya Dwivedi if (map_value_has_timer(&arr->map)) 29468134668SAlexei Starovoitov bpf_timer_cancel_and_free(val + arr->map.timer_off); 29514a324f6SKumar Kartikeya Dwivedi if (map_value_has_kptrs(&arr->map)) 29614a324f6SKumar Kartikeya Dwivedi bpf_map_free_kptrs(&arr->map, val); 29768134668SAlexei Starovoitov } 29868134668SAlexei Starovoitov 29928fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 30028fbcfa0SAlexei Starovoitov static int array_map_update_elem(struct bpf_map *map, void *key, void *value, 30128fbcfa0SAlexei Starovoitov u64 map_flags) 30228fbcfa0SAlexei Starovoitov { 30328fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 30428fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 30596049f3aSAlexei Starovoitov char *val; 30628fbcfa0SAlexei Starovoitov 30796049f3aSAlexei Starovoitov if (unlikely((map_flags & ~BPF_F_LOCK) > BPF_EXIST)) 30828fbcfa0SAlexei Starovoitov /* unknown flags */ 30928fbcfa0SAlexei Starovoitov return -EINVAL; 31028fbcfa0SAlexei Starovoitov 311a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 31228fbcfa0SAlexei Starovoitov /* all elements were pre-allocated, cannot insert a new one */ 31328fbcfa0SAlexei Starovoitov return -E2BIG; 31428fbcfa0SAlexei Starovoitov 31596049f3aSAlexei Starovoitov if (unlikely(map_flags & BPF_NOEXIST)) 316daaf427cSAlexei Starovoitov /* all elements already exist */ 31728fbcfa0SAlexei Starovoitov return -EEXIST; 31828fbcfa0SAlexei Starovoitov 31996049f3aSAlexei Starovoitov if (unlikely((map_flags & BPF_F_LOCK) && 32096049f3aSAlexei Starovoitov !map_value_has_spin_lock(map))) 32196049f3aSAlexei Starovoitov return -EINVAL; 32296049f3aSAlexei Starovoitov 32396049f3aSAlexei Starovoitov if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) { 324b2157399SAlexei Starovoitov memcpy(this_cpu_ptr(array->pptrs[index & array->index_mask]), 325a10423b8SAlexei Starovoitov value, map->value_size); 32696049f3aSAlexei Starovoitov } else { 32796049f3aSAlexei Starovoitov val = array->value + 32896049f3aSAlexei Starovoitov array->elem_size * (index & array->index_mask); 32996049f3aSAlexei Starovoitov if (map_flags & BPF_F_LOCK) 33096049f3aSAlexei Starovoitov copy_map_value_locked(map, val, value, false); 331a10423b8SAlexei Starovoitov else 33296049f3aSAlexei Starovoitov copy_map_value(map, val, value); 33314a324f6SKumar Kartikeya Dwivedi check_and_free_fields(array, val); 33496049f3aSAlexei Starovoitov } 33528fbcfa0SAlexei Starovoitov return 0; 33628fbcfa0SAlexei Starovoitov } 33728fbcfa0SAlexei Starovoitov 33815a07b33SAlexei Starovoitov int bpf_percpu_array_update(struct bpf_map *map, void *key, void *value, 33915a07b33SAlexei Starovoitov u64 map_flags) 34015a07b33SAlexei Starovoitov { 34115a07b33SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 34215a07b33SAlexei Starovoitov u32 index = *(u32 *)key; 34315a07b33SAlexei Starovoitov void __percpu *pptr; 34415a07b33SAlexei Starovoitov int cpu, off = 0; 34515a07b33SAlexei Starovoitov u32 size; 34615a07b33SAlexei Starovoitov 34715a07b33SAlexei Starovoitov if (unlikely(map_flags > BPF_EXIST)) 34815a07b33SAlexei Starovoitov /* unknown flags */ 34915a07b33SAlexei Starovoitov return -EINVAL; 35015a07b33SAlexei Starovoitov 35115a07b33SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 35215a07b33SAlexei Starovoitov /* all elements were pre-allocated, cannot insert a new one */ 35315a07b33SAlexei Starovoitov return -E2BIG; 35415a07b33SAlexei Starovoitov 35515a07b33SAlexei Starovoitov if (unlikely(map_flags == BPF_NOEXIST)) 35615a07b33SAlexei Starovoitov /* all elements already exist */ 35715a07b33SAlexei Starovoitov return -EEXIST; 35815a07b33SAlexei Starovoitov 35915a07b33SAlexei Starovoitov /* the user space will provide round_up(value_size, 8) bytes that 36015a07b33SAlexei Starovoitov * will be copied into per-cpu area. bpf programs can only access 36115a07b33SAlexei Starovoitov * value_size of it. During lookup the same extra bytes will be 36215a07b33SAlexei Starovoitov * returned or zeros which were zero-filled by percpu_alloc, 36315a07b33SAlexei Starovoitov * so no kernel data leaks possible 36415a07b33SAlexei Starovoitov */ 36515a07b33SAlexei Starovoitov size = round_up(map->value_size, 8); 36615a07b33SAlexei Starovoitov rcu_read_lock(); 367b2157399SAlexei Starovoitov pptr = array->pptrs[index & array->index_mask]; 36815a07b33SAlexei Starovoitov for_each_possible_cpu(cpu) { 36915a07b33SAlexei Starovoitov bpf_long_memcpy(per_cpu_ptr(pptr, cpu), value + off, size); 37015a07b33SAlexei Starovoitov off += size; 37115a07b33SAlexei Starovoitov } 37215a07b33SAlexei Starovoitov rcu_read_unlock(); 37315a07b33SAlexei Starovoitov return 0; 37415a07b33SAlexei Starovoitov } 37515a07b33SAlexei Starovoitov 37628fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 37728fbcfa0SAlexei Starovoitov static int array_map_delete_elem(struct bpf_map *map, void *key) 37828fbcfa0SAlexei Starovoitov { 37928fbcfa0SAlexei Starovoitov return -EINVAL; 38028fbcfa0SAlexei Starovoitov } 38128fbcfa0SAlexei Starovoitov 382fc970227SAndrii Nakryiko static void *array_map_vmalloc_addr(struct bpf_array *array) 383fc970227SAndrii Nakryiko { 384fc970227SAndrii Nakryiko return (void *)round_down((unsigned long)array, PAGE_SIZE); 385fc970227SAndrii Nakryiko } 386fc970227SAndrii Nakryiko 38768134668SAlexei Starovoitov static void array_map_free_timers(struct bpf_map *map) 38868134668SAlexei Starovoitov { 38968134668SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 39068134668SAlexei Starovoitov int i; 39168134668SAlexei Starovoitov 39214a324f6SKumar Kartikeya Dwivedi /* We don't reset or free kptr on uref dropping to zero. */ 39314a324f6SKumar Kartikeya Dwivedi if (!map_value_has_timer(map)) 39468134668SAlexei Starovoitov return; 39568134668SAlexei Starovoitov 39668134668SAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 39768134668SAlexei Starovoitov bpf_timer_cancel_and_free(array->value + array->elem_size * i + 39868134668SAlexei Starovoitov map->timer_off); 39968134668SAlexei Starovoitov } 40068134668SAlexei Starovoitov 40128fbcfa0SAlexei Starovoitov /* Called when map->refcnt goes to zero, either from workqueue or from syscall */ 40228fbcfa0SAlexei Starovoitov static void array_map_free(struct bpf_map *map) 40328fbcfa0SAlexei Starovoitov { 40428fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 40514a324f6SKumar Kartikeya Dwivedi int i; 40614a324f6SKumar Kartikeya Dwivedi 40714a324f6SKumar Kartikeya Dwivedi if (map_value_has_kptrs(map)) { 40814a324f6SKumar Kartikeya Dwivedi for (i = 0; i < array->map.max_entries; i++) 40914a324f6SKumar Kartikeya Dwivedi bpf_map_free_kptrs(map, array->value + array->elem_size * i); 41014a324f6SKumar Kartikeya Dwivedi bpf_map_free_kptr_off_tab(map); 41114a324f6SKumar Kartikeya Dwivedi } 41228fbcfa0SAlexei Starovoitov 413a10423b8SAlexei Starovoitov if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) 414a10423b8SAlexei Starovoitov bpf_array_free_percpu(array); 415a10423b8SAlexei Starovoitov 416fc970227SAndrii Nakryiko if (array->map.map_flags & BPF_F_MMAPABLE) 417fc970227SAndrii Nakryiko bpf_map_area_free(array_map_vmalloc_addr(array)); 418fc970227SAndrii Nakryiko else 419d407bd25SDaniel Borkmann bpf_map_area_free(array); 42028fbcfa0SAlexei Starovoitov } 42128fbcfa0SAlexei Starovoitov 422a26ca7c9SMartin KaFai Lau static void array_map_seq_show_elem(struct bpf_map *map, void *key, 423a26ca7c9SMartin KaFai Lau struct seq_file *m) 424a26ca7c9SMartin KaFai Lau { 425a26ca7c9SMartin KaFai Lau void *value; 426a26ca7c9SMartin KaFai Lau 427a26ca7c9SMartin KaFai Lau rcu_read_lock(); 428a26ca7c9SMartin KaFai Lau 429a26ca7c9SMartin KaFai Lau value = array_map_lookup_elem(map, key); 430a26ca7c9SMartin KaFai Lau if (!value) { 431a26ca7c9SMartin KaFai Lau rcu_read_unlock(); 432a26ca7c9SMartin KaFai Lau return; 433a26ca7c9SMartin KaFai Lau } 434a26ca7c9SMartin KaFai Lau 4352824ecb7SDaniel Borkmann if (map->btf_key_type_id) 436a26ca7c9SMartin KaFai Lau seq_printf(m, "%u: ", *(u32 *)key); 4379b2cf328SMartin KaFai Lau btf_type_seq_show(map->btf, map->btf_value_type_id, value, m); 438a26ca7c9SMartin KaFai Lau seq_puts(m, "\n"); 439a26ca7c9SMartin KaFai Lau 440a26ca7c9SMartin KaFai Lau rcu_read_unlock(); 441a26ca7c9SMartin KaFai Lau } 442a26ca7c9SMartin KaFai Lau 443c7b27c37SYonghong Song static void percpu_array_map_seq_show_elem(struct bpf_map *map, void *key, 444c7b27c37SYonghong Song struct seq_file *m) 445c7b27c37SYonghong Song { 446c7b27c37SYonghong Song struct bpf_array *array = container_of(map, struct bpf_array, map); 447c7b27c37SYonghong Song u32 index = *(u32 *)key; 448c7b27c37SYonghong Song void __percpu *pptr; 449c7b27c37SYonghong Song int cpu; 450c7b27c37SYonghong Song 451c7b27c37SYonghong Song rcu_read_lock(); 452c7b27c37SYonghong Song 453c7b27c37SYonghong Song seq_printf(m, "%u: {\n", *(u32 *)key); 454c7b27c37SYonghong Song pptr = array->pptrs[index & array->index_mask]; 455c7b27c37SYonghong Song for_each_possible_cpu(cpu) { 456c7b27c37SYonghong Song seq_printf(m, "\tcpu%d: ", cpu); 457c7b27c37SYonghong Song btf_type_seq_show(map->btf, map->btf_value_type_id, 458c7b27c37SYonghong Song per_cpu_ptr(pptr, cpu), m); 459c7b27c37SYonghong Song seq_puts(m, "\n"); 460c7b27c37SYonghong Song } 461c7b27c37SYonghong Song seq_puts(m, "}\n"); 462c7b27c37SYonghong Song 463c7b27c37SYonghong Song rcu_read_unlock(); 464c7b27c37SYonghong Song } 465c7b27c37SYonghong Song 466e8d2bec0SDaniel Borkmann static int array_map_check_btf(const struct bpf_map *map, 4671b2b234bSRoman Gushchin const struct btf *btf, 468e8d2bec0SDaniel Borkmann const struct btf_type *key_type, 469e8d2bec0SDaniel Borkmann const struct btf_type *value_type) 470a26ca7c9SMartin KaFai Lau { 471a26ca7c9SMartin KaFai Lau u32 int_data; 472a26ca7c9SMartin KaFai Lau 4732824ecb7SDaniel Borkmann /* One exception for keyless BTF: .bss/.data/.rodata map */ 4742824ecb7SDaniel Borkmann if (btf_type_is_void(key_type)) { 4752824ecb7SDaniel Borkmann if (map->map_type != BPF_MAP_TYPE_ARRAY || 4762824ecb7SDaniel Borkmann map->max_entries != 1) 4772824ecb7SDaniel Borkmann return -EINVAL; 4782824ecb7SDaniel Borkmann 4792824ecb7SDaniel Borkmann if (BTF_INFO_KIND(value_type->info) != BTF_KIND_DATASEC) 4802824ecb7SDaniel Borkmann return -EINVAL; 4812824ecb7SDaniel Borkmann 4822824ecb7SDaniel Borkmann return 0; 4832824ecb7SDaniel Borkmann } 4842824ecb7SDaniel Borkmann 485e8d2bec0SDaniel Borkmann if (BTF_INFO_KIND(key_type->info) != BTF_KIND_INT) 486a26ca7c9SMartin KaFai Lau return -EINVAL; 487a26ca7c9SMartin KaFai Lau 488a26ca7c9SMartin KaFai Lau int_data = *(u32 *)(key_type + 1); 489e8d2bec0SDaniel Borkmann /* bpf array can only take a u32 key. This check makes sure 490e8d2bec0SDaniel Borkmann * that the btf matches the attr used during map_create. 491a26ca7c9SMartin KaFai Lau */ 492e8d2bec0SDaniel Borkmann if (BTF_INT_BITS(int_data) != 32 || BTF_INT_OFFSET(int_data)) 493a26ca7c9SMartin KaFai Lau return -EINVAL; 494a26ca7c9SMartin KaFai Lau 495a26ca7c9SMartin KaFai Lau return 0; 496a26ca7c9SMartin KaFai Lau } 497a26ca7c9SMartin KaFai Lau 498b2e2f0e6SYueHaibing static int array_map_mmap(struct bpf_map *map, struct vm_area_struct *vma) 499fc970227SAndrii Nakryiko { 500fc970227SAndrii Nakryiko struct bpf_array *array = container_of(map, struct bpf_array, map); 501fc970227SAndrii Nakryiko pgoff_t pgoff = PAGE_ALIGN(sizeof(*array)) >> PAGE_SHIFT; 502fc970227SAndrii Nakryiko 503fc970227SAndrii Nakryiko if (!(map->map_flags & BPF_F_MMAPABLE)) 504fc970227SAndrii Nakryiko return -EINVAL; 505fc970227SAndrii Nakryiko 506333291ceSAndrii Nakryiko if (vma->vm_pgoff * PAGE_SIZE + (vma->vm_end - vma->vm_start) > 507333291ceSAndrii Nakryiko PAGE_ALIGN((u64)array->map.max_entries * array->elem_size)) 508333291ceSAndrii Nakryiko return -EINVAL; 509333291ceSAndrii Nakryiko 510333291ceSAndrii Nakryiko return remap_vmalloc_range(vma, array_map_vmalloc_addr(array), 511333291ceSAndrii Nakryiko vma->vm_pgoff + pgoff); 512fc970227SAndrii Nakryiko } 513fc970227SAndrii Nakryiko 514134fede4SMartin KaFai Lau static bool array_map_meta_equal(const struct bpf_map *meta0, 515134fede4SMartin KaFai Lau const struct bpf_map *meta1) 516134fede4SMartin KaFai Lau { 5174a8f87e6SDaniel Borkmann if (!bpf_map_meta_equal(meta0, meta1)) 5184a8f87e6SDaniel Borkmann return false; 5194a8f87e6SDaniel Borkmann return meta0->map_flags & BPF_F_INNER_MAP ? true : 5204a8f87e6SDaniel Borkmann meta0->max_entries == meta1->max_entries; 521134fede4SMartin KaFai Lau } 522134fede4SMartin KaFai Lau 523d3cc2ab5SYonghong Song struct bpf_iter_seq_array_map_info { 524d3cc2ab5SYonghong Song struct bpf_map *map; 525d3cc2ab5SYonghong Song void *percpu_value_buf; 526d3cc2ab5SYonghong Song u32 index; 527d3cc2ab5SYonghong Song }; 528d3cc2ab5SYonghong Song 529d3cc2ab5SYonghong Song static void *bpf_array_map_seq_start(struct seq_file *seq, loff_t *pos) 530d3cc2ab5SYonghong Song { 531d3cc2ab5SYonghong Song struct bpf_iter_seq_array_map_info *info = seq->private; 532d3cc2ab5SYonghong Song struct bpf_map *map = info->map; 533d3cc2ab5SYonghong Song struct bpf_array *array; 534d3cc2ab5SYonghong Song u32 index; 535d3cc2ab5SYonghong Song 536d3cc2ab5SYonghong Song if (info->index >= map->max_entries) 537d3cc2ab5SYonghong Song return NULL; 538d3cc2ab5SYonghong Song 539d3cc2ab5SYonghong Song if (*pos == 0) 540d3cc2ab5SYonghong Song ++*pos; 541d3cc2ab5SYonghong Song array = container_of(map, struct bpf_array, map); 542d3cc2ab5SYonghong Song index = info->index & array->index_mask; 543d3cc2ab5SYonghong Song if (info->percpu_value_buf) 544d3cc2ab5SYonghong Song return array->pptrs[index]; 545d3cc2ab5SYonghong Song return array->value + array->elem_size * index; 546d3cc2ab5SYonghong Song } 547d3cc2ab5SYonghong Song 548d3cc2ab5SYonghong Song static void *bpf_array_map_seq_next(struct seq_file *seq, void *v, loff_t *pos) 549d3cc2ab5SYonghong Song { 550d3cc2ab5SYonghong Song struct bpf_iter_seq_array_map_info *info = seq->private; 551d3cc2ab5SYonghong Song struct bpf_map *map = info->map; 552d3cc2ab5SYonghong Song struct bpf_array *array; 553d3cc2ab5SYonghong Song u32 index; 554d3cc2ab5SYonghong Song 555d3cc2ab5SYonghong Song ++*pos; 556d3cc2ab5SYonghong Song ++info->index; 557d3cc2ab5SYonghong Song if (info->index >= map->max_entries) 558d3cc2ab5SYonghong Song return NULL; 559d3cc2ab5SYonghong Song 560d3cc2ab5SYonghong Song array = container_of(map, struct bpf_array, map); 561d3cc2ab5SYonghong Song index = info->index & array->index_mask; 562d3cc2ab5SYonghong Song if (info->percpu_value_buf) 563d3cc2ab5SYonghong Song return array->pptrs[index]; 564d3cc2ab5SYonghong Song return array->value + array->elem_size * index; 565d3cc2ab5SYonghong Song } 566d3cc2ab5SYonghong Song 567d3cc2ab5SYonghong Song static int __bpf_array_map_seq_show(struct seq_file *seq, void *v) 568d3cc2ab5SYonghong Song { 569d3cc2ab5SYonghong Song struct bpf_iter_seq_array_map_info *info = seq->private; 570d3cc2ab5SYonghong Song struct bpf_iter__bpf_map_elem ctx = {}; 571d3cc2ab5SYonghong Song struct bpf_map *map = info->map; 572d3cc2ab5SYonghong Song struct bpf_iter_meta meta; 573d3cc2ab5SYonghong Song struct bpf_prog *prog; 574d3cc2ab5SYonghong Song int off = 0, cpu = 0; 575d3cc2ab5SYonghong Song void __percpu **pptr; 576d3cc2ab5SYonghong Song u32 size; 577d3cc2ab5SYonghong Song 578d3cc2ab5SYonghong Song meta.seq = seq; 579d3cc2ab5SYonghong Song prog = bpf_iter_get_info(&meta, v == NULL); 580d3cc2ab5SYonghong Song if (!prog) 581d3cc2ab5SYonghong Song return 0; 582d3cc2ab5SYonghong Song 583d3cc2ab5SYonghong Song ctx.meta = &meta; 584d3cc2ab5SYonghong Song ctx.map = info->map; 585d3cc2ab5SYonghong Song if (v) { 586d3cc2ab5SYonghong Song ctx.key = &info->index; 587d3cc2ab5SYonghong Song 588d3cc2ab5SYonghong Song if (!info->percpu_value_buf) { 589d3cc2ab5SYonghong Song ctx.value = v; 590d3cc2ab5SYonghong Song } else { 591d3cc2ab5SYonghong Song pptr = v; 592d3cc2ab5SYonghong Song size = round_up(map->value_size, 8); 593d3cc2ab5SYonghong Song for_each_possible_cpu(cpu) { 594d3cc2ab5SYonghong Song bpf_long_memcpy(info->percpu_value_buf + off, 595d3cc2ab5SYonghong Song per_cpu_ptr(pptr, cpu), 596d3cc2ab5SYonghong Song size); 597d3cc2ab5SYonghong Song off += size; 598d3cc2ab5SYonghong Song } 599d3cc2ab5SYonghong Song ctx.value = info->percpu_value_buf; 600d3cc2ab5SYonghong Song } 601d3cc2ab5SYonghong Song } 602d3cc2ab5SYonghong Song 603d3cc2ab5SYonghong Song return bpf_iter_run_prog(prog, &ctx); 604d3cc2ab5SYonghong Song } 605d3cc2ab5SYonghong Song 606d3cc2ab5SYonghong Song static int bpf_array_map_seq_show(struct seq_file *seq, void *v) 607d3cc2ab5SYonghong Song { 608d3cc2ab5SYonghong Song return __bpf_array_map_seq_show(seq, v); 609d3cc2ab5SYonghong Song } 610d3cc2ab5SYonghong Song 611d3cc2ab5SYonghong Song static void bpf_array_map_seq_stop(struct seq_file *seq, void *v) 612d3cc2ab5SYonghong Song { 613d3cc2ab5SYonghong Song if (!v) 614d3cc2ab5SYonghong Song (void)__bpf_array_map_seq_show(seq, NULL); 615d3cc2ab5SYonghong Song } 616d3cc2ab5SYonghong Song 617d3cc2ab5SYonghong Song static int bpf_iter_init_array_map(void *priv_data, 618d3cc2ab5SYonghong Song struct bpf_iter_aux_info *aux) 619d3cc2ab5SYonghong Song { 620d3cc2ab5SYonghong Song struct bpf_iter_seq_array_map_info *seq_info = priv_data; 621d3cc2ab5SYonghong Song struct bpf_map *map = aux->map; 622d3cc2ab5SYonghong Song void *value_buf; 623d3cc2ab5SYonghong Song u32 buf_size; 624d3cc2ab5SYonghong Song 625d3cc2ab5SYonghong Song if (map->map_type == BPF_MAP_TYPE_PERCPU_ARRAY) { 626d3cc2ab5SYonghong Song buf_size = round_up(map->value_size, 8) * num_possible_cpus(); 627d3cc2ab5SYonghong Song value_buf = kmalloc(buf_size, GFP_USER | __GFP_NOWARN); 628d3cc2ab5SYonghong Song if (!value_buf) 629d3cc2ab5SYonghong Song return -ENOMEM; 630d3cc2ab5SYonghong Song 631d3cc2ab5SYonghong Song seq_info->percpu_value_buf = value_buf; 632d3cc2ab5SYonghong Song } 633d3cc2ab5SYonghong Song 634d3cc2ab5SYonghong Song seq_info->map = map; 635d3cc2ab5SYonghong Song return 0; 636d3cc2ab5SYonghong Song } 637d3cc2ab5SYonghong Song 638d3cc2ab5SYonghong Song static void bpf_iter_fini_array_map(void *priv_data) 639d3cc2ab5SYonghong Song { 640d3cc2ab5SYonghong Song struct bpf_iter_seq_array_map_info *seq_info = priv_data; 641d3cc2ab5SYonghong Song 642d3cc2ab5SYonghong Song kfree(seq_info->percpu_value_buf); 643d3cc2ab5SYonghong Song } 644d3cc2ab5SYonghong Song 645d3cc2ab5SYonghong Song static const struct seq_operations bpf_array_map_seq_ops = { 646d3cc2ab5SYonghong Song .start = bpf_array_map_seq_start, 647d3cc2ab5SYonghong Song .next = bpf_array_map_seq_next, 648d3cc2ab5SYonghong Song .stop = bpf_array_map_seq_stop, 649d3cc2ab5SYonghong Song .show = bpf_array_map_seq_show, 650d3cc2ab5SYonghong Song }; 651d3cc2ab5SYonghong Song 652d3cc2ab5SYonghong Song static const struct bpf_iter_seq_info iter_seq_info = { 653d3cc2ab5SYonghong Song .seq_ops = &bpf_array_map_seq_ops, 654d3cc2ab5SYonghong Song .init_seq_private = bpf_iter_init_array_map, 655d3cc2ab5SYonghong Song .fini_seq_private = bpf_iter_fini_array_map, 656d3cc2ab5SYonghong Song .seq_priv_size = sizeof(struct bpf_iter_seq_array_map_info), 657d3cc2ab5SYonghong Song }; 658d3cc2ab5SYonghong Song 659102acbacSKees Cook static int bpf_for_each_array_elem(struct bpf_map *map, bpf_callback_t callback_fn, 66006dcdcd4SYonghong Song void *callback_ctx, u64 flags) 66106dcdcd4SYonghong Song { 66206dcdcd4SYonghong Song u32 i, key, num_elems = 0; 66306dcdcd4SYonghong Song struct bpf_array *array; 66406dcdcd4SYonghong Song bool is_percpu; 66506dcdcd4SYonghong Song u64 ret = 0; 66606dcdcd4SYonghong Song void *val; 66706dcdcd4SYonghong Song 66806dcdcd4SYonghong Song if (flags != 0) 66906dcdcd4SYonghong Song return -EINVAL; 67006dcdcd4SYonghong Song 67106dcdcd4SYonghong Song is_percpu = map->map_type == BPF_MAP_TYPE_PERCPU_ARRAY; 67206dcdcd4SYonghong Song array = container_of(map, struct bpf_array, map); 67306dcdcd4SYonghong Song if (is_percpu) 67406dcdcd4SYonghong Song migrate_disable(); 67506dcdcd4SYonghong Song for (i = 0; i < map->max_entries; i++) { 67606dcdcd4SYonghong Song if (is_percpu) 67706dcdcd4SYonghong Song val = this_cpu_ptr(array->pptrs[i]); 67806dcdcd4SYonghong Song else 67906dcdcd4SYonghong Song val = array->value + array->elem_size * i; 68006dcdcd4SYonghong Song num_elems++; 68106dcdcd4SYonghong Song key = i; 682102acbacSKees Cook ret = callback_fn((u64)(long)map, (u64)(long)&key, 683102acbacSKees Cook (u64)(long)val, (u64)(long)callback_ctx, 0); 68406dcdcd4SYonghong Song /* return value: 0 - continue, 1 - stop and return */ 68506dcdcd4SYonghong Song if (ret) 68606dcdcd4SYonghong Song break; 68706dcdcd4SYonghong Song } 68806dcdcd4SYonghong Song 68906dcdcd4SYonghong Song if (is_percpu) 69006dcdcd4SYonghong Song migrate_enable(); 69106dcdcd4SYonghong Song return num_elems; 69206dcdcd4SYonghong Song } 69306dcdcd4SYonghong Song 694c317ab71SMenglong Dong BTF_ID_LIST_SINGLE(array_map_btf_ids, struct, bpf_array) 69540077e0cSJohannes Berg const struct bpf_map_ops array_map_ops = { 696134fede4SMartin KaFai Lau .map_meta_equal = array_map_meta_equal, 697ad46061fSJakub Kicinski .map_alloc_check = array_map_alloc_check, 69828fbcfa0SAlexei Starovoitov .map_alloc = array_map_alloc, 69928fbcfa0SAlexei Starovoitov .map_free = array_map_free, 70028fbcfa0SAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 70168134668SAlexei Starovoitov .map_release_uref = array_map_free_timers, 70228fbcfa0SAlexei Starovoitov .map_lookup_elem = array_map_lookup_elem, 70328fbcfa0SAlexei Starovoitov .map_update_elem = array_map_update_elem, 70428fbcfa0SAlexei Starovoitov .map_delete_elem = array_map_delete_elem, 70581ed18abSAlexei Starovoitov .map_gen_lookup = array_map_gen_lookup, 706d8eca5bbSDaniel Borkmann .map_direct_value_addr = array_map_direct_value_addr, 707d8eca5bbSDaniel Borkmann .map_direct_value_meta = array_map_direct_value_meta, 708fc970227SAndrii Nakryiko .map_mmap = array_map_mmap, 709a26ca7c9SMartin KaFai Lau .map_seq_show_elem = array_map_seq_show_elem, 710a26ca7c9SMartin KaFai Lau .map_check_btf = array_map_check_btf, 711c60f2d28SBrian Vazquez .map_lookup_batch = generic_map_lookup_batch, 712c60f2d28SBrian Vazquez .map_update_batch = generic_map_update_batch, 71306dcdcd4SYonghong Song .map_set_for_each_callback_args = map_set_for_each_callback_args, 71406dcdcd4SYonghong Song .map_for_each_callback = bpf_for_each_array_elem, 715c317ab71SMenglong Dong .map_btf_id = &array_map_btf_ids[0], 716d3cc2ab5SYonghong Song .iter_seq_info = &iter_seq_info, 71728fbcfa0SAlexei Starovoitov }; 71828fbcfa0SAlexei Starovoitov 71940077e0cSJohannes Berg const struct bpf_map_ops percpu_array_map_ops = { 720f4d05259SMartin KaFai Lau .map_meta_equal = bpf_map_meta_equal, 721ad46061fSJakub Kicinski .map_alloc_check = array_map_alloc_check, 722a10423b8SAlexei Starovoitov .map_alloc = array_map_alloc, 723a10423b8SAlexei Starovoitov .map_free = array_map_free, 724a10423b8SAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 725a10423b8SAlexei Starovoitov .map_lookup_elem = percpu_array_map_lookup_elem, 726a10423b8SAlexei Starovoitov .map_update_elem = array_map_update_elem, 727a10423b8SAlexei Starovoitov .map_delete_elem = array_map_delete_elem, 728c7b27c37SYonghong Song .map_seq_show_elem = percpu_array_map_seq_show_elem, 729e8d2bec0SDaniel Borkmann .map_check_btf = array_map_check_btf, 730f008d732SPedro Tammela .map_lookup_batch = generic_map_lookup_batch, 731f008d732SPedro Tammela .map_update_batch = generic_map_update_batch, 73206dcdcd4SYonghong Song .map_set_for_each_callback_args = map_set_for_each_callback_args, 73306dcdcd4SYonghong Song .map_for_each_callback = bpf_for_each_array_elem, 734c317ab71SMenglong Dong .map_btf_id = &array_map_btf_ids[0], 735d3cc2ab5SYonghong Song .iter_seq_info = &iter_seq_info, 736a10423b8SAlexei Starovoitov }; 737a10423b8SAlexei Starovoitov 738ad46061fSJakub Kicinski static int fd_array_map_alloc_check(union bpf_attr *attr) 73904fd61abSAlexei Starovoitov { 7402a36f0b9SWang Nan /* only file descriptors can be stored in this type of map */ 74104fd61abSAlexei Starovoitov if (attr->value_size != sizeof(u32)) 742ad46061fSJakub Kicinski return -EINVAL; 743591fe988SDaniel Borkmann /* Program read-only/write-only not supported for special maps yet. */ 744591fe988SDaniel Borkmann if (attr->map_flags & (BPF_F_RDONLY_PROG | BPF_F_WRONLY_PROG)) 745591fe988SDaniel Borkmann return -EINVAL; 746ad46061fSJakub Kicinski return array_map_alloc_check(attr); 74704fd61abSAlexei Starovoitov } 74804fd61abSAlexei Starovoitov 7492a36f0b9SWang Nan static void fd_array_map_free(struct bpf_map *map) 75004fd61abSAlexei Starovoitov { 75104fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 75204fd61abSAlexei Starovoitov int i; 75304fd61abSAlexei Starovoitov 75404fd61abSAlexei Starovoitov /* make sure it's empty */ 75504fd61abSAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 7562a36f0b9SWang Nan BUG_ON(array->ptrs[i] != NULL); 757d407bd25SDaniel Borkmann 758d407bd25SDaniel Borkmann bpf_map_area_free(array); 75904fd61abSAlexei Starovoitov } 76004fd61abSAlexei Starovoitov 7612a36f0b9SWang Nan static void *fd_array_map_lookup_elem(struct bpf_map *map, void *key) 76204fd61abSAlexei Starovoitov { 7633b4a63f6SPrashant Bhole return ERR_PTR(-EOPNOTSUPP); 76404fd61abSAlexei Starovoitov } 76504fd61abSAlexei Starovoitov 76604fd61abSAlexei Starovoitov /* only called from syscall */ 76714dc6f04SMartin KaFai Lau int bpf_fd_array_map_lookup_elem(struct bpf_map *map, void *key, u32 *value) 76814dc6f04SMartin KaFai Lau { 76914dc6f04SMartin KaFai Lau void **elem, *ptr; 77014dc6f04SMartin KaFai Lau int ret = 0; 77114dc6f04SMartin KaFai Lau 77214dc6f04SMartin KaFai Lau if (!map->ops->map_fd_sys_lookup_elem) 77314dc6f04SMartin KaFai Lau return -ENOTSUPP; 77414dc6f04SMartin KaFai Lau 77514dc6f04SMartin KaFai Lau rcu_read_lock(); 77614dc6f04SMartin KaFai Lau elem = array_map_lookup_elem(map, key); 77714dc6f04SMartin KaFai Lau if (elem && (ptr = READ_ONCE(*elem))) 77814dc6f04SMartin KaFai Lau *value = map->ops->map_fd_sys_lookup_elem(ptr); 77914dc6f04SMartin KaFai Lau else 78014dc6f04SMartin KaFai Lau ret = -ENOENT; 78114dc6f04SMartin KaFai Lau rcu_read_unlock(); 78214dc6f04SMartin KaFai Lau 78314dc6f04SMartin KaFai Lau return ret; 78414dc6f04SMartin KaFai Lau } 78514dc6f04SMartin KaFai Lau 78614dc6f04SMartin KaFai Lau /* only called from syscall */ 787d056a788SDaniel Borkmann int bpf_fd_array_map_update_elem(struct bpf_map *map, struct file *map_file, 788d056a788SDaniel Borkmann void *key, void *value, u64 map_flags) 78904fd61abSAlexei Starovoitov { 79004fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 7912a36f0b9SWang Nan void *new_ptr, *old_ptr; 79204fd61abSAlexei Starovoitov u32 index = *(u32 *)key, ufd; 79304fd61abSAlexei Starovoitov 79404fd61abSAlexei Starovoitov if (map_flags != BPF_ANY) 79504fd61abSAlexei Starovoitov return -EINVAL; 79604fd61abSAlexei Starovoitov 79704fd61abSAlexei Starovoitov if (index >= array->map.max_entries) 79804fd61abSAlexei Starovoitov return -E2BIG; 79904fd61abSAlexei Starovoitov 80004fd61abSAlexei Starovoitov ufd = *(u32 *)value; 801d056a788SDaniel Borkmann new_ptr = map->ops->map_fd_get_ptr(map, map_file, ufd); 8022a36f0b9SWang Nan if (IS_ERR(new_ptr)) 8032a36f0b9SWang Nan return PTR_ERR(new_ptr); 80404fd61abSAlexei Starovoitov 805da765a2fSDaniel Borkmann if (map->ops->map_poke_run) { 806da765a2fSDaniel Borkmann mutex_lock(&array->aux->poke_mutex); 8072a36f0b9SWang Nan old_ptr = xchg(array->ptrs + index, new_ptr); 808da765a2fSDaniel Borkmann map->ops->map_poke_run(map, index, old_ptr, new_ptr); 809da765a2fSDaniel Borkmann mutex_unlock(&array->aux->poke_mutex); 810da765a2fSDaniel Borkmann } else { 811da765a2fSDaniel Borkmann old_ptr = xchg(array->ptrs + index, new_ptr); 812da765a2fSDaniel Borkmann } 813da765a2fSDaniel Borkmann 8142a36f0b9SWang Nan if (old_ptr) 8152a36f0b9SWang Nan map->ops->map_fd_put_ptr(old_ptr); 81604fd61abSAlexei Starovoitov return 0; 81704fd61abSAlexei Starovoitov } 81804fd61abSAlexei Starovoitov 8192a36f0b9SWang Nan static int fd_array_map_delete_elem(struct bpf_map *map, void *key) 82004fd61abSAlexei Starovoitov { 82104fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 8222a36f0b9SWang Nan void *old_ptr; 82304fd61abSAlexei Starovoitov u32 index = *(u32 *)key; 82404fd61abSAlexei Starovoitov 82504fd61abSAlexei Starovoitov if (index >= array->map.max_entries) 82604fd61abSAlexei Starovoitov return -E2BIG; 82704fd61abSAlexei Starovoitov 828da765a2fSDaniel Borkmann if (map->ops->map_poke_run) { 829da765a2fSDaniel Borkmann mutex_lock(&array->aux->poke_mutex); 8302a36f0b9SWang Nan old_ptr = xchg(array->ptrs + index, NULL); 831da765a2fSDaniel Borkmann map->ops->map_poke_run(map, index, old_ptr, NULL); 832da765a2fSDaniel Borkmann mutex_unlock(&array->aux->poke_mutex); 833da765a2fSDaniel Borkmann } else { 834da765a2fSDaniel Borkmann old_ptr = xchg(array->ptrs + index, NULL); 835da765a2fSDaniel Borkmann } 836da765a2fSDaniel Borkmann 8372a36f0b9SWang Nan if (old_ptr) { 8382a36f0b9SWang Nan map->ops->map_fd_put_ptr(old_ptr); 83904fd61abSAlexei Starovoitov return 0; 84004fd61abSAlexei Starovoitov } else { 84104fd61abSAlexei Starovoitov return -ENOENT; 84204fd61abSAlexei Starovoitov } 84304fd61abSAlexei Starovoitov } 84404fd61abSAlexei Starovoitov 845d056a788SDaniel Borkmann static void *prog_fd_array_get_ptr(struct bpf_map *map, 846d056a788SDaniel Borkmann struct file *map_file, int fd) 8472a36f0b9SWang Nan { 8482a36f0b9SWang Nan struct bpf_prog *prog = bpf_prog_get(fd); 849d056a788SDaniel Borkmann 8502a36f0b9SWang Nan if (IS_ERR(prog)) 8512a36f0b9SWang Nan return prog; 8522a36f0b9SWang Nan 853f45d5b6cSToke Hoiland-Jorgensen if (!bpf_prog_map_compatible(map, prog)) { 8542a36f0b9SWang Nan bpf_prog_put(prog); 8552a36f0b9SWang Nan return ERR_PTR(-EINVAL); 8562a36f0b9SWang Nan } 857d056a788SDaniel Borkmann 8582a36f0b9SWang Nan return prog; 8592a36f0b9SWang Nan } 8602a36f0b9SWang Nan 8612a36f0b9SWang Nan static void prog_fd_array_put_ptr(void *ptr) 8622a36f0b9SWang Nan { 8631aacde3dSDaniel Borkmann bpf_prog_put(ptr); 8642a36f0b9SWang Nan } 8652a36f0b9SWang Nan 86614dc6f04SMartin KaFai Lau static u32 prog_fd_array_sys_lookup_elem(void *ptr) 86714dc6f04SMartin KaFai Lau { 86814dc6f04SMartin KaFai Lau return ((struct bpf_prog *)ptr)->aux->id; 86914dc6f04SMartin KaFai Lau } 87014dc6f04SMartin KaFai Lau 87104fd61abSAlexei Starovoitov /* decrement refcnt of all bpf_progs that are stored in this map */ 872ba6b8de4SJohn Fastabend static void bpf_fd_array_map_clear(struct bpf_map *map) 87304fd61abSAlexei Starovoitov { 87404fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 87504fd61abSAlexei Starovoitov int i; 87604fd61abSAlexei Starovoitov 87704fd61abSAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 8782a36f0b9SWang Nan fd_array_map_delete_elem(map, &i); 87904fd61abSAlexei Starovoitov } 88004fd61abSAlexei Starovoitov 881a7c19db3SYonghong Song static void prog_array_map_seq_show_elem(struct bpf_map *map, void *key, 882a7c19db3SYonghong Song struct seq_file *m) 883a7c19db3SYonghong Song { 884a7c19db3SYonghong Song void **elem, *ptr; 885a7c19db3SYonghong Song u32 prog_id; 886a7c19db3SYonghong Song 887a7c19db3SYonghong Song rcu_read_lock(); 888a7c19db3SYonghong Song 889a7c19db3SYonghong Song elem = array_map_lookup_elem(map, key); 890a7c19db3SYonghong Song if (elem) { 891a7c19db3SYonghong Song ptr = READ_ONCE(*elem); 892a7c19db3SYonghong Song if (ptr) { 893a7c19db3SYonghong Song seq_printf(m, "%u: ", *(u32 *)key); 894a7c19db3SYonghong Song prog_id = prog_fd_array_sys_lookup_elem(ptr); 895a7c19db3SYonghong Song btf_type_seq_show(map->btf, map->btf_value_type_id, 896a7c19db3SYonghong Song &prog_id, m); 897a7c19db3SYonghong Song seq_puts(m, "\n"); 898a7c19db3SYonghong Song } 899a7c19db3SYonghong Song } 900a7c19db3SYonghong Song 901a7c19db3SYonghong Song rcu_read_unlock(); 902a7c19db3SYonghong Song } 903a7c19db3SYonghong Song 904da765a2fSDaniel Borkmann struct prog_poke_elem { 905da765a2fSDaniel Borkmann struct list_head list; 906da765a2fSDaniel Borkmann struct bpf_prog_aux *aux; 907da765a2fSDaniel Borkmann }; 908da765a2fSDaniel Borkmann 909da765a2fSDaniel Borkmann static int prog_array_map_poke_track(struct bpf_map *map, 910da765a2fSDaniel Borkmann struct bpf_prog_aux *prog_aux) 911da765a2fSDaniel Borkmann { 912da765a2fSDaniel Borkmann struct prog_poke_elem *elem; 913da765a2fSDaniel Borkmann struct bpf_array_aux *aux; 914da765a2fSDaniel Borkmann int ret = 0; 915da765a2fSDaniel Borkmann 916da765a2fSDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 917da765a2fSDaniel Borkmann mutex_lock(&aux->poke_mutex); 918da765a2fSDaniel Borkmann list_for_each_entry(elem, &aux->poke_progs, list) { 919da765a2fSDaniel Borkmann if (elem->aux == prog_aux) 920da765a2fSDaniel Borkmann goto out; 921da765a2fSDaniel Borkmann } 922da765a2fSDaniel Borkmann 923da765a2fSDaniel Borkmann elem = kmalloc(sizeof(*elem), GFP_KERNEL); 924da765a2fSDaniel Borkmann if (!elem) { 925da765a2fSDaniel Borkmann ret = -ENOMEM; 926da765a2fSDaniel Borkmann goto out; 927da765a2fSDaniel Borkmann } 928da765a2fSDaniel Borkmann 929da765a2fSDaniel Borkmann INIT_LIST_HEAD(&elem->list); 930da765a2fSDaniel Borkmann /* We must track the program's aux info at this point in time 931da765a2fSDaniel Borkmann * since the program pointer itself may not be stable yet, see 932da765a2fSDaniel Borkmann * also comment in prog_array_map_poke_run(). 933da765a2fSDaniel Borkmann */ 934da765a2fSDaniel Borkmann elem->aux = prog_aux; 935da765a2fSDaniel Borkmann 936da765a2fSDaniel Borkmann list_add_tail(&elem->list, &aux->poke_progs); 937da765a2fSDaniel Borkmann out: 938da765a2fSDaniel Borkmann mutex_unlock(&aux->poke_mutex); 939da765a2fSDaniel Borkmann return ret; 940da765a2fSDaniel Borkmann } 941da765a2fSDaniel Borkmann 942da765a2fSDaniel Borkmann static void prog_array_map_poke_untrack(struct bpf_map *map, 943da765a2fSDaniel Borkmann struct bpf_prog_aux *prog_aux) 944da765a2fSDaniel Borkmann { 945da765a2fSDaniel Borkmann struct prog_poke_elem *elem, *tmp; 946da765a2fSDaniel Borkmann struct bpf_array_aux *aux; 947da765a2fSDaniel Borkmann 948da765a2fSDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 949da765a2fSDaniel Borkmann mutex_lock(&aux->poke_mutex); 950da765a2fSDaniel Borkmann list_for_each_entry_safe(elem, tmp, &aux->poke_progs, list) { 951da765a2fSDaniel Borkmann if (elem->aux == prog_aux) { 952da765a2fSDaniel Borkmann list_del_init(&elem->list); 953da765a2fSDaniel Borkmann kfree(elem); 954da765a2fSDaniel Borkmann break; 955da765a2fSDaniel Borkmann } 956da765a2fSDaniel Borkmann } 957da765a2fSDaniel Borkmann mutex_unlock(&aux->poke_mutex); 958da765a2fSDaniel Borkmann } 959da765a2fSDaniel Borkmann 960da765a2fSDaniel Borkmann static void prog_array_map_poke_run(struct bpf_map *map, u32 key, 961da765a2fSDaniel Borkmann struct bpf_prog *old, 962da765a2fSDaniel Borkmann struct bpf_prog *new) 963da765a2fSDaniel Borkmann { 964ebf7d1f5SMaciej Fijalkowski u8 *old_addr, *new_addr, *old_bypass_addr; 965da765a2fSDaniel Borkmann struct prog_poke_elem *elem; 966da765a2fSDaniel Borkmann struct bpf_array_aux *aux; 967da765a2fSDaniel Borkmann 968da765a2fSDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 969da765a2fSDaniel Borkmann WARN_ON_ONCE(!mutex_is_locked(&aux->poke_mutex)); 970da765a2fSDaniel Borkmann 971da765a2fSDaniel Borkmann list_for_each_entry(elem, &aux->poke_progs, list) { 972da765a2fSDaniel Borkmann struct bpf_jit_poke_descriptor *poke; 973da765a2fSDaniel Borkmann int i, ret; 974da765a2fSDaniel Borkmann 975da765a2fSDaniel Borkmann for (i = 0; i < elem->aux->size_poke_tab; i++) { 976da765a2fSDaniel Borkmann poke = &elem->aux->poke_tab[i]; 977da765a2fSDaniel Borkmann 978da765a2fSDaniel Borkmann /* Few things to be aware of: 979da765a2fSDaniel Borkmann * 980da765a2fSDaniel Borkmann * 1) We can only ever access aux in this context, but 981da765a2fSDaniel Borkmann * not aux->prog since it might not be stable yet and 982da765a2fSDaniel Borkmann * there could be danger of use after free otherwise. 983da765a2fSDaniel Borkmann * 2) Initially when we start tracking aux, the program 984da765a2fSDaniel Borkmann * is not JITed yet and also does not have a kallsyms 985cf71b174SMaciej Fijalkowski * entry. We skip these as poke->tailcall_target_stable 986cf71b174SMaciej Fijalkowski * is not active yet. The JIT will do the final fixup 987cf71b174SMaciej Fijalkowski * before setting it stable. The various 988cf71b174SMaciej Fijalkowski * poke->tailcall_target_stable are successively 989cf71b174SMaciej Fijalkowski * activated, so tail call updates can arrive from here 990cf71b174SMaciej Fijalkowski * while JIT is still finishing its final fixup for 991cf71b174SMaciej Fijalkowski * non-activated poke entries. 992da765a2fSDaniel Borkmann * 3) On program teardown, the program's kallsym entry gets 993da765a2fSDaniel Borkmann * removed out of RCU callback, but we can only untrack 994da765a2fSDaniel Borkmann * from sleepable context, therefore bpf_arch_text_poke() 995da765a2fSDaniel Borkmann * might not see that this is in BPF text section and 996da765a2fSDaniel Borkmann * bails out with -EINVAL. As these are unreachable since 997da765a2fSDaniel Borkmann * RCU grace period already passed, we simply skip them. 998da765a2fSDaniel Borkmann * 4) Also programs reaching refcount of zero while patching 999da765a2fSDaniel Borkmann * is in progress is okay since we're protected under 1000da765a2fSDaniel Borkmann * poke_mutex and untrack the programs before the JIT 1001da765a2fSDaniel Borkmann * buffer is freed. When we're still in the middle of 1002da765a2fSDaniel Borkmann * patching and suddenly kallsyms entry of the program 1003da765a2fSDaniel Borkmann * gets evicted, we just skip the rest which is fine due 1004da765a2fSDaniel Borkmann * to point 3). 1005da765a2fSDaniel Borkmann * 5) Any other error happening below from bpf_arch_text_poke() 1006da765a2fSDaniel Borkmann * is a unexpected bug. 1007da765a2fSDaniel Borkmann */ 1008cf71b174SMaciej Fijalkowski if (!READ_ONCE(poke->tailcall_target_stable)) 1009da765a2fSDaniel Borkmann continue; 1010da765a2fSDaniel Borkmann if (poke->reason != BPF_POKE_REASON_TAIL_CALL) 1011da765a2fSDaniel Borkmann continue; 1012da765a2fSDaniel Borkmann if (poke->tail_call.map != map || 1013da765a2fSDaniel Borkmann poke->tail_call.key != key) 1014da765a2fSDaniel Borkmann continue; 1015da765a2fSDaniel Borkmann 1016ebf7d1f5SMaciej Fijalkowski old_bypass_addr = old ? NULL : poke->bypass_addr; 1017ebf7d1f5SMaciej Fijalkowski old_addr = old ? (u8 *)old->bpf_func + poke->adj_off : NULL; 1018ebf7d1f5SMaciej Fijalkowski new_addr = new ? (u8 *)new->bpf_func + poke->adj_off : NULL; 1019ebf7d1f5SMaciej Fijalkowski 1020ebf7d1f5SMaciej Fijalkowski if (new) { 1021ebf7d1f5SMaciej Fijalkowski ret = bpf_arch_text_poke(poke->tailcall_target, 1022ebf7d1f5SMaciej Fijalkowski BPF_MOD_JUMP, 1023ebf7d1f5SMaciej Fijalkowski old_addr, new_addr); 1024da765a2fSDaniel Borkmann BUG_ON(ret < 0 && ret != -EINVAL); 1025ebf7d1f5SMaciej Fijalkowski if (!old) { 1026ebf7d1f5SMaciej Fijalkowski ret = bpf_arch_text_poke(poke->tailcall_bypass, 1027ebf7d1f5SMaciej Fijalkowski BPF_MOD_JUMP, 1028ebf7d1f5SMaciej Fijalkowski poke->bypass_addr, 1029ebf7d1f5SMaciej Fijalkowski NULL); 1030ebf7d1f5SMaciej Fijalkowski BUG_ON(ret < 0 && ret != -EINVAL); 1031ebf7d1f5SMaciej Fijalkowski } 1032ebf7d1f5SMaciej Fijalkowski } else { 1033ebf7d1f5SMaciej Fijalkowski ret = bpf_arch_text_poke(poke->tailcall_bypass, 1034ebf7d1f5SMaciej Fijalkowski BPF_MOD_JUMP, 1035ebf7d1f5SMaciej Fijalkowski old_bypass_addr, 1036ebf7d1f5SMaciej Fijalkowski poke->bypass_addr); 1037ebf7d1f5SMaciej Fijalkowski BUG_ON(ret < 0 && ret != -EINVAL); 1038ebf7d1f5SMaciej Fijalkowski /* let other CPUs finish the execution of program 1039ebf7d1f5SMaciej Fijalkowski * so that it will not possible to expose them 1040ebf7d1f5SMaciej Fijalkowski * to invalid nop, stack unwind, nop state 1041ebf7d1f5SMaciej Fijalkowski */ 1042ebf7d1f5SMaciej Fijalkowski if (!ret) 1043ebf7d1f5SMaciej Fijalkowski synchronize_rcu(); 1044ebf7d1f5SMaciej Fijalkowski ret = bpf_arch_text_poke(poke->tailcall_target, 1045ebf7d1f5SMaciej Fijalkowski BPF_MOD_JUMP, 1046ebf7d1f5SMaciej Fijalkowski old_addr, NULL); 1047ebf7d1f5SMaciej Fijalkowski BUG_ON(ret < 0 && ret != -EINVAL); 1048ebf7d1f5SMaciej Fijalkowski } 1049da765a2fSDaniel Borkmann } 1050da765a2fSDaniel Borkmann } 1051da765a2fSDaniel Borkmann } 1052da765a2fSDaniel Borkmann 1053da765a2fSDaniel Borkmann static void prog_array_map_clear_deferred(struct work_struct *work) 1054da765a2fSDaniel Borkmann { 1055da765a2fSDaniel Borkmann struct bpf_map *map = container_of(work, struct bpf_array_aux, 1056da765a2fSDaniel Borkmann work)->map; 1057da765a2fSDaniel Borkmann bpf_fd_array_map_clear(map); 1058da765a2fSDaniel Borkmann bpf_map_put(map); 1059da765a2fSDaniel Borkmann } 1060da765a2fSDaniel Borkmann 1061da765a2fSDaniel Borkmann static void prog_array_map_clear(struct bpf_map *map) 1062da765a2fSDaniel Borkmann { 1063da765a2fSDaniel Borkmann struct bpf_array_aux *aux = container_of(map, struct bpf_array, 1064da765a2fSDaniel Borkmann map)->aux; 1065da765a2fSDaniel Borkmann bpf_map_inc(map); 1066da765a2fSDaniel Borkmann schedule_work(&aux->work); 1067da765a2fSDaniel Borkmann } 1068da765a2fSDaniel Borkmann 10692beee5f5SDaniel Borkmann static struct bpf_map *prog_array_map_alloc(union bpf_attr *attr) 10702beee5f5SDaniel Borkmann { 10712beee5f5SDaniel Borkmann struct bpf_array_aux *aux; 10722beee5f5SDaniel Borkmann struct bpf_map *map; 10732beee5f5SDaniel Borkmann 10746d192c79SRoman Gushchin aux = kzalloc(sizeof(*aux), GFP_KERNEL_ACCOUNT); 10752beee5f5SDaniel Borkmann if (!aux) 10762beee5f5SDaniel Borkmann return ERR_PTR(-ENOMEM); 10772beee5f5SDaniel Borkmann 1078da765a2fSDaniel Borkmann INIT_WORK(&aux->work, prog_array_map_clear_deferred); 1079da765a2fSDaniel Borkmann INIT_LIST_HEAD(&aux->poke_progs); 1080da765a2fSDaniel Borkmann mutex_init(&aux->poke_mutex); 1081da765a2fSDaniel Borkmann 10822beee5f5SDaniel Borkmann map = array_map_alloc(attr); 10832beee5f5SDaniel Borkmann if (IS_ERR(map)) { 10842beee5f5SDaniel Borkmann kfree(aux); 10852beee5f5SDaniel Borkmann return map; 10862beee5f5SDaniel Borkmann } 10872beee5f5SDaniel Borkmann 10882beee5f5SDaniel Borkmann container_of(map, struct bpf_array, map)->aux = aux; 1089da765a2fSDaniel Borkmann aux->map = map; 1090da765a2fSDaniel Borkmann 10912beee5f5SDaniel Borkmann return map; 10922beee5f5SDaniel Borkmann } 10932beee5f5SDaniel Borkmann 10942beee5f5SDaniel Borkmann static void prog_array_map_free(struct bpf_map *map) 10952beee5f5SDaniel Borkmann { 1096da765a2fSDaniel Borkmann struct prog_poke_elem *elem, *tmp; 10972beee5f5SDaniel Borkmann struct bpf_array_aux *aux; 10982beee5f5SDaniel Borkmann 10992beee5f5SDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 1100da765a2fSDaniel Borkmann list_for_each_entry_safe(elem, tmp, &aux->poke_progs, list) { 1101da765a2fSDaniel Borkmann list_del_init(&elem->list); 1102da765a2fSDaniel Borkmann kfree(elem); 1103da765a2fSDaniel Borkmann } 11042beee5f5SDaniel Borkmann kfree(aux); 11052beee5f5SDaniel Borkmann fd_array_map_free(map); 11062beee5f5SDaniel Borkmann } 11072beee5f5SDaniel Borkmann 1108f4d05259SMartin KaFai Lau /* prog_array->aux->{type,jited} is a runtime binding. 1109f4d05259SMartin KaFai Lau * Doing static check alone in the verifier is not enough. 1110f4d05259SMartin KaFai Lau * Thus, prog_array_map cannot be used as an inner_map 1111f4d05259SMartin KaFai Lau * and map_meta_equal is not implemented. 1112f4d05259SMartin KaFai Lau */ 111340077e0cSJohannes Berg const struct bpf_map_ops prog_array_map_ops = { 1114ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 11152beee5f5SDaniel Borkmann .map_alloc = prog_array_map_alloc, 11162beee5f5SDaniel Borkmann .map_free = prog_array_map_free, 1117da765a2fSDaniel Borkmann .map_poke_track = prog_array_map_poke_track, 1118da765a2fSDaniel Borkmann .map_poke_untrack = prog_array_map_poke_untrack, 1119da765a2fSDaniel Borkmann .map_poke_run = prog_array_map_poke_run, 112004fd61abSAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 11212a36f0b9SWang Nan .map_lookup_elem = fd_array_map_lookup_elem, 11222a36f0b9SWang Nan .map_delete_elem = fd_array_map_delete_elem, 11232a36f0b9SWang Nan .map_fd_get_ptr = prog_fd_array_get_ptr, 11242a36f0b9SWang Nan .map_fd_put_ptr = prog_fd_array_put_ptr, 112514dc6f04SMartin KaFai Lau .map_fd_sys_lookup_elem = prog_fd_array_sys_lookup_elem, 1126da765a2fSDaniel Borkmann .map_release_uref = prog_array_map_clear, 1127a7c19db3SYonghong Song .map_seq_show_elem = prog_array_map_seq_show_elem, 1128c317ab71SMenglong Dong .map_btf_id = &array_map_btf_ids[0], 112904fd61abSAlexei Starovoitov }; 113004fd61abSAlexei Starovoitov 11313b1efb19SDaniel Borkmann static struct bpf_event_entry *bpf_event_entry_gen(struct file *perf_file, 11323b1efb19SDaniel Borkmann struct file *map_file) 1133ea317b26SKaixu Xia { 11343b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 11353b1efb19SDaniel Borkmann 1136858d68f1SDaniel Borkmann ee = kzalloc(sizeof(*ee), GFP_ATOMIC); 11373b1efb19SDaniel Borkmann if (ee) { 11383b1efb19SDaniel Borkmann ee->event = perf_file->private_data; 11393b1efb19SDaniel Borkmann ee->perf_file = perf_file; 11403b1efb19SDaniel Borkmann ee->map_file = map_file; 11413b1efb19SDaniel Borkmann } 11423b1efb19SDaniel Borkmann 11433b1efb19SDaniel Borkmann return ee; 11443b1efb19SDaniel Borkmann } 11453b1efb19SDaniel Borkmann 11463b1efb19SDaniel Borkmann static void __bpf_event_entry_free(struct rcu_head *rcu) 11473b1efb19SDaniel Borkmann { 11483b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 11493b1efb19SDaniel Borkmann 11503b1efb19SDaniel Borkmann ee = container_of(rcu, struct bpf_event_entry, rcu); 11513b1efb19SDaniel Borkmann fput(ee->perf_file); 11523b1efb19SDaniel Borkmann kfree(ee); 11533b1efb19SDaniel Borkmann } 11543b1efb19SDaniel Borkmann 11553b1efb19SDaniel Borkmann static void bpf_event_entry_free_rcu(struct bpf_event_entry *ee) 11563b1efb19SDaniel Borkmann { 11573b1efb19SDaniel Borkmann call_rcu(&ee->rcu, __bpf_event_entry_free); 1158ea317b26SKaixu Xia } 1159ea317b26SKaixu Xia 1160d056a788SDaniel Borkmann static void *perf_event_fd_array_get_ptr(struct bpf_map *map, 1161d056a788SDaniel Borkmann struct file *map_file, int fd) 1162ea317b26SKaixu Xia { 11633b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 11643b1efb19SDaniel Borkmann struct perf_event *event; 11653b1efb19SDaniel Borkmann struct file *perf_file; 1166f91840a3SAlexei Starovoitov u64 value; 1167ea317b26SKaixu Xia 11683b1efb19SDaniel Borkmann perf_file = perf_event_get(fd); 11693b1efb19SDaniel Borkmann if (IS_ERR(perf_file)) 11703b1efb19SDaniel Borkmann return perf_file; 1171e03e7ee3SAlexei Starovoitov 1172f91840a3SAlexei Starovoitov ee = ERR_PTR(-EOPNOTSUPP); 11733b1efb19SDaniel Borkmann event = perf_file->private_data; 117497562633SYonghong Song if (perf_event_read_local(event, &value, NULL, NULL) == -EOPNOTSUPP) 11753b1efb19SDaniel Borkmann goto err_out; 1176ea317b26SKaixu Xia 11773b1efb19SDaniel Borkmann ee = bpf_event_entry_gen(perf_file, map_file); 11783b1efb19SDaniel Borkmann if (ee) 11793b1efb19SDaniel Borkmann return ee; 11803b1efb19SDaniel Borkmann ee = ERR_PTR(-ENOMEM); 11813b1efb19SDaniel Borkmann err_out: 11823b1efb19SDaniel Borkmann fput(perf_file); 11833b1efb19SDaniel Borkmann return ee; 1184ea317b26SKaixu Xia } 1185ea317b26SKaixu Xia 1186ea317b26SKaixu Xia static void perf_event_fd_array_put_ptr(void *ptr) 1187ea317b26SKaixu Xia { 11883b1efb19SDaniel Borkmann bpf_event_entry_free_rcu(ptr); 11893b1efb19SDaniel Borkmann } 11903b1efb19SDaniel Borkmann 11913b1efb19SDaniel Borkmann static void perf_event_fd_array_release(struct bpf_map *map, 11923b1efb19SDaniel Borkmann struct file *map_file) 11933b1efb19SDaniel Borkmann { 11943b1efb19SDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 11953b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 11963b1efb19SDaniel Borkmann int i; 11973b1efb19SDaniel Borkmann 1198792cacccSSong Liu if (map->map_flags & BPF_F_PRESERVE_ELEMS) 1199792cacccSSong Liu return; 1200792cacccSSong Liu 12013b1efb19SDaniel Borkmann rcu_read_lock(); 12023b1efb19SDaniel Borkmann for (i = 0; i < array->map.max_entries; i++) { 12033b1efb19SDaniel Borkmann ee = READ_ONCE(array->ptrs[i]); 12043b1efb19SDaniel Borkmann if (ee && ee->map_file == map_file) 12053b1efb19SDaniel Borkmann fd_array_map_delete_elem(map, &i); 12063b1efb19SDaniel Borkmann } 12073b1efb19SDaniel Borkmann rcu_read_unlock(); 1208ea317b26SKaixu Xia } 1209ea317b26SKaixu Xia 1210792cacccSSong Liu static void perf_event_fd_array_map_free(struct bpf_map *map) 1211792cacccSSong Liu { 1212792cacccSSong Liu if (map->map_flags & BPF_F_PRESERVE_ELEMS) 1213792cacccSSong Liu bpf_fd_array_map_clear(map); 1214792cacccSSong Liu fd_array_map_free(map); 1215792cacccSSong Liu } 1216792cacccSSong Liu 121740077e0cSJohannes Berg const struct bpf_map_ops perf_event_array_map_ops = { 1218f4d05259SMartin KaFai Lau .map_meta_equal = bpf_map_meta_equal, 1219ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 1220ad46061fSJakub Kicinski .map_alloc = array_map_alloc, 1221792cacccSSong Liu .map_free = perf_event_fd_array_map_free, 1222ea317b26SKaixu Xia .map_get_next_key = array_map_get_next_key, 1223ea317b26SKaixu Xia .map_lookup_elem = fd_array_map_lookup_elem, 1224ea317b26SKaixu Xia .map_delete_elem = fd_array_map_delete_elem, 1225ea317b26SKaixu Xia .map_fd_get_ptr = perf_event_fd_array_get_ptr, 1226ea317b26SKaixu Xia .map_fd_put_ptr = perf_event_fd_array_put_ptr, 12273b1efb19SDaniel Borkmann .map_release = perf_event_fd_array_release, 1228e8d2bec0SDaniel Borkmann .map_check_btf = map_check_no_btf, 1229c317ab71SMenglong Dong .map_btf_id = &array_map_btf_ids[0], 1230ea317b26SKaixu Xia }; 1231ea317b26SKaixu Xia 123260d20f91SSargun Dhillon #ifdef CONFIG_CGROUPS 12334ed8ec52SMartin KaFai Lau static void *cgroup_fd_array_get_ptr(struct bpf_map *map, 12344ed8ec52SMartin KaFai Lau struct file *map_file /* not used */, 12354ed8ec52SMartin KaFai Lau int fd) 12364ed8ec52SMartin KaFai Lau { 12374ed8ec52SMartin KaFai Lau return cgroup_get_from_fd(fd); 12384ed8ec52SMartin KaFai Lau } 12394ed8ec52SMartin KaFai Lau 12404ed8ec52SMartin KaFai Lau static void cgroup_fd_array_put_ptr(void *ptr) 12414ed8ec52SMartin KaFai Lau { 12424ed8ec52SMartin KaFai Lau /* cgroup_put free cgrp after a rcu grace period */ 12434ed8ec52SMartin KaFai Lau cgroup_put(ptr); 12444ed8ec52SMartin KaFai Lau } 12454ed8ec52SMartin KaFai Lau 12464ed8ec52SMartin KaFai Lau static void cgroup_fd_array_free(struct bpf_map *map) 12474ed8ec52SMartin KaFai Lau { 12484ed8ec52SMartin KaFai Lau bpf_fd_array_map_clear(map); 12494ed8ec52SMartin KaFai Lau fd_array_map_free(map); 12504ed8ec52SMartin KaFai Lau } 12514ed8ec52SMartin KaFai Lau 125240077e0cSJohannes Berg const struct bpf_map_ops cgroup_array_map_ops = { 1253f4d05259SMartin KaFai Lau .map_meta_equal = bpf_map_meta_equal, 1254ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 1255ad46061fSJakub Kicinski .map_alloc = array_map_alloc, 12564ed8ec52SMartin KaFai Lau .map_free = cgroup_fd_array_free, 12574ed8ec52SMartin KaFai Lau .map_get_next_key = array_map_get_next_key, 12584ed8ec52SMartin KaFai Lau .map_lookup_elem = fd_array_map_lookup_elem, 12594ed8ec52SMartin KaFai Lau .map_delete_elem = fd_array_map_delete_elem, 12604ed8ec52SMartin KaFai Lau .map_fd_get_ptr = cgroup_fd_array_get_ptr, 12614ed8ec52SMartin KaFai Lau .map_fd_put_ptr = cgroup_fd_array_put_ptr, 1262e8d2bec0SDaniel Borkmann .map_check_btf = map_check_no_btf, 1263c317ab71SMenglong Dong .map_btf_id = &array_map_btf_ids[0], 12644ed8ec52SMartin KaFai Lau }; 12654ed8ec52SMartin KaFai Lau #endif 126656f668dfSMartin KaFai Lau 126756f668dfSMartin KaFai Lau static struct bpf_map *array_of_map_alloc(union bpf_attr *attr) 126856f668dfSMartin KaFai Lau { 126956f668dfSMartin KaFai Lau struct bpf_map *map, *inner_map_meta; 127056f668dfSMartin KaFai Lau 127156f668dfSMartin KaFai Lau inner_map_meta = bpf_map_meta_alloc(attr->inner_map_fd); 127256f668dfSMartin KaFai Lau if (IS_ERR(inner_map_meta)) 127356f668dfSMartin KaFai Lau return inner_map_meta; 127456f668dfSMartin KaFai Lau 1275ad46061fSJakub Kicinski map = array_map_alloc(attr); 127656f668dfSMartin KaFai Lau if (IS_ERR(map)) { 127756f668dfSMartin KaFai Lau bpf_map_meta_free(inner_map_meta); 127856f668dfSMartin KaFai Lau return map; 127956f668dfSMartin KaFai Lau } 128056f668dfSMartin KaFai Lau 128156f668dfSMartin KaFai Lau map->inner_map_meta = inner_map_meta; 128256f668dfSMartin KaFai Lau 128356f668dfSMartin KaFai Lau return map; 128456f668dfSMartin KaFai Lau } 128556f668dfSMartin KaFai Lau 128656f668dfSMartin KaFai Lau static void array_of_map_free(struct bpf_map *map) 128756f668dfSMartin KaFai Lau { 128856f668dfSMartin KaFai Lau /* map->inner_map_meta is only accessed by syscall which 128956f668dfSMartin KaFai Lau * is protected by fdget/fdput. 129056f668dfSMartin KaFai Lau */ 129156f668dfSMartin KaFai Lau bpf_map_meta_free(map->inner_map_meta); 129256f668dfSMartin KaFai Lau bpf_fd_array_map_clear(map); 129356f668dfSMartin KaFai Lau fd_array_map_free(map); 129456f668dfSMartin KaFai Lau } 129556f668dfSMartin KaFai Lau 129656f668dfSMartin KaFai Lau static void *array_of_map_lookup_elem(struct bpf_map *map, void *key) 129756f668dfSMartin KaFai Lau { 129856f668dfSMartin KaFai Lau struct bpf_map **inner_map = array_map_lookup_elem(map, key); 129956f668dfSMartin KaFai Lau 130056f668dfSMartin KaFai Lau if (!inner_map) 130156f668dfSMartin KaFai Lau return NULL; 130256f668dfSMartin KaFai Lau 130356f668dfSMartin KaFai Lau return READ_ONCE(*inner_map); 130456f668dfSMartin KaFai Lau } 130556f668dfSMartin KaFai Lau 13064a8f87e6SDaniel Borkmann static int array_of_map_gen_lookup(struct bpf_map *map, 13077b0c2a05SDaniel Borkmann struct bpf_insn *insn_buf) 13087b0c2a05SDaniel Borkmann { 1309b2157399SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 13107b0c2a05SDaniel Borkmann u32 elem_size = round_up(map->value_size, 8); 13117b0c2a05SDaniel Borkmann struct bpf_insn *insn = insn_buf; 13127b0c2a05SDaniel Borkmann const int ret = BPF_REG_0; 13137b0c2a05SDaniel Borkmann const int map_ptr = BPF_REG_1; 13147b0c2a05SDaniel Borkmann const int index = BPF_REG_2; 13157b0c2a05SDaniel Borkmann 13167b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_IMM(BPF_ADD, map_ptr, offsetof(struct bpf_array, value)); 13177b0c2a05SDaniel Borkmann *insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0); 13182c78ee89SAlexei Starovoitov if (!map->bypass_spec_v1) { 1319b2157399SAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 6); 1320b2157399SAlexei Starovoitov *insn++ = BPF_ALU32_IMM(BPF_AND, ret, array->index_mask); 1321b2157399SAlexei Starovoitov } else { 13227b0c2a05SDaniel Borkmann *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 5); 1323b2157399SAlexei Starovoitov } 13247b0c2a05SDaniel Borkmann if (is_power_of_2(elem_size)) 13257b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(elem_size)); 13267b0c2a05SDaniel Borkmann else 13277b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_IMM(BPF_MUL, ret, elem_size); 13287b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_REG(BPF_ADD, ret, map_ptr); 13297b0c2a05SDaniel Borkmann *insn++ = BPF_LDX_MEM(BPF_DW, ret, ret, 0); 13307b0c2a05SDaniel Borkmann *insn++ = BPF_JMP_IMM(BPF_JEQ, ret, 0, 1); 13317b0c2a05SDaniel Borkmann *insn++ = BPF_JMP_IMM(BPF_JA, 0, 0, 1); 13327b0c2a05SDaniel Borkmann *insn++ = BPF_MOV64_IMM(ret, 0); 13337b0c2a05SDaniel Borkmann 13347b0c2a05SDaniel Borkmann return insn - insn_buf; 13357b0c2a05SDaniel Borkmann } 13367b0c2a05SDaniel Borkmann 133740077e0cSJohannes Berg const struct bpf_map_ops array_of_maps_map_ops = { 1338ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 133956f668dfSMartin KaFai Lau .map_alloc = array_of_map_alloc, 134056f668dfSMartin KaFai Lau .map_free = array_of_map_free, 134156f668dfSMartin KaFai Lau .map_get_next_key = array_map_get_next_key, 134256f668dfSMartin KaFai Lau .map_lookup_elem = array_of_map_lookup_elem, 134356f668dfSMartin KaFai Lau .map_delete_elem = fd_array_map_delete_elem, 134456f668dfSMartin KaFai Lau .map_fd_get_ptr = bpf_map_fd_get_ptr, 134556f668dfSMartin KaFai Lau .map_fd_put_ptr = bpf_map_fd_put_ptr, 134614dc6f04SMartin KaFai Lau .map_fd_sys_lookup_elem = bpf_map_fd_sys_lookup_elem, 13477b0c2a05SDaniel Borkmann .map_gen_lookup = array_of_map_gen_lookup, 1348*9263dddcSTakshak Chahande .map_lookup_batch = generic_map_lookup_batch, 1349*9263dddcSTakshak Chahande .map_update_batch = generic_map_update_batch, 1350e8d2bec0SDaniel Borkmann .map_check_btf = map_check_no_btf, 1351c317ab71SMenglong Dong .map_btf_id = &array_map_btf_ids[0], 135256f668dfSMartin KaFai Lau }; 1353