15b497af4SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only 228fbcfa0SAlexei Starovoitov /* Copyright (c) 2011-2014 PLUMgrid, http://plumgrid.com 381ed18abSAlexei Starovoitov * Copyright (c) 2016,2017 Facebook 428fbcfa0SAlexei Starovoitov */ 528fbcfa0SAlexei Starovoitov #include <linux/bpf.h> 6a26ca7c9SMartin KaFai Lau #include <linux/btf.h> 728fbcfa0SAlexei Starovoitov #include <linux/err.h> 828fbcfa0SAlexei Starovoitov #include <linux/slab.h> 928fbcfa0SAlexei Starovoitov #include <linux/mm.h> 1004fd61abSAlexei Starovoitov #include <linux/filter.h> 110cdf5640SDaniel Borkmann #include <linux/perf_event.h> 12a26ca7c9SMartin KaFai Lau #include <uapi/linux/btf.h> 1328fbcfa0SAlexei Starovoitov 1456f668dfSMartin KaFai Lau #include "map_in_map.h" 1556f668dfSMartin KaFai Lau 166e71b04aSChenbo Feng #define ARRAY_CREATE_FLAG_MASK \ 17fc970227SAndrii Nakryiko (BPF_F_NUMA_NODE | BPF_F_MMAPABLE | BPF_F_ACCESS_MASK) 186e71b04aSChenbo Feng 19a10423b8SAlexei Starovoitov static void bpf_array_free_percpu(struct bpf_array *array) 20a10423b8SAlexei Starovoitov { 21a10423b8SAlexei Starovoitov int i; 22a10423b8SAlexei Starovoitov 2332fff239SEric Dumazet for (i = 0; i < array->map.max_entries; i++) { 24a10423b8SAlexei Starovoitov free_percpu(array->pptrs[i]); 2532fff239SEric Dumazet cond_resched(); 2632fff239SEric Dumazet } 27a10423b8SAlexei Starovoitov } 28a10423b8SAlexei Starovoitov 29a10423b8SAlexei Starovoitov static int bpf_array_alloc_percpu(struct bpf_array *array) 30a10423b8SAlexei Starovoitov { 31a10423b8SAlexei Starovoitov void __percpu *ptr; 32a10423b8SAlexei Starovoitov int i; 33a10423b8SAlexei Starovoitov 34a10423b8SAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) { 35a10423b8SAlexei Starovoitov ptr = __alloc_percpu_gfp(array->elem_size, 8, 36a10423b8SAlexei Starovoitov GFP_USER | __GFP_NOWARN); 37a10423b8SAlexei Starovoitov if (!ptr) { 38a10423b8SAlexei Starovoitov bpf_array_free_percpu(array); 39a10423b8SAlexei Starovoitov return -ENOMEM; 40a10423b8SAlexei Starovoitov } 41a10423b8SAlexei Starovoitov array->pptrs[i] = ptr; 4232fff239SEric Dumazet cond_resched(); 43a10423b8SAlexei Starovoitov } 44a10423b8SAlexei Starovoitov 45a10423b8SAlexei Starovoitov return 0; 46a10423b8SAlexei Starovoitov } 47a10423b8SAlexei Starovoitov 4828fbcfa0SAlexei Starovoitov /* Called from syscall */ 495dc4c4b7SMartin KaFai Lau int array_map_alloc_check(union bpf_attr *attr) 50ad46061fSJakub Kicinski { 51ad46061fSJakub Kicinski bool percpu = attr->map_type == BPF_MAP_TYPE_PERCPU_ARRAY; 52ad46061fSJakub Kicinski int numa_node = bpf_map_attr_numa_node(attr); 53ad46061fSJakub Kicinski 54ad46061fSJakub Kicinski /* check sanity of attributes */ 55ad46061fSJakub Kicinski if (attr->max_entries == 0 || attr->key_size != 4 || 56ad46061fSJakub Kicinski attr->value_size == 0 || 57ad46061fSJakub Kicinski attr->map_flags & ~ARRAY_CREATE_FLAG_MASK || 58591fe988SDaniel Borkmann !bpf_map_flags_access_ok(attr->map_flags) || 59ad46061fSJakub Kicinski (percpu && numa_node != NUMA_NO_NODE)) 60ad46061fSJakub Kicinski return -EINVAL; 61ad46061fSJakub Kicinski 62fc970227SAndrii Nakryiko if (attr->map_type != BPF_MAP_TYPE_ARRAY && 63fc970227SAndrii Nakryiko attr->map_flags & BPF_F_MMAPABLE) 64fc970227SAndrii Nakryiko return -EINVAL; 65fc970227SAndrii Nakryiko 66ad46061fSJakub Kicinski if (attr->value_size > KMALLOC_MAX_SIZE) 67ad46061fSJakub Kicinski /* if value_size is bigger, the user space won't be able to 68ad46061fSJakub Kicinski * access the elements. 69ad46061fSJakub Kicinski */ 70ad46061fSJakub Kicinski return -E2BIG; 71ad46061fSJakub Kicinski 72ad46061fSJakub Kicinski return 0; 73ad46061fSJakub Kicinski } 74ad46061fSJakub Kicinski 7528fbcfa0SAlexei Starovoitov static struct bpf_map *array_map_alloc(union bpf_attr *attr) 7628fbcfa0SAlexei Starovoitov { 77a10423b8SAlexei Starovoitov bool percpu = attr->map_type == BPF_MAP_TYPE_PERCPU_ARRAY; 789c2d63b8SDaniel Borkmann int ret, numa_node = bpf_map_attr_numa_node(attr); 79b2157399SAlexei Starovoitov u32 elem_size, index_mask, max_entries; 80b2157399SAlexei Starovoitov bool unpriv = !capable(CAP_SYS_ADMIN); 819c2d63b8SDaniel Borkmann u64 cost, array_size, mask64; 82b936ca64SRoman Gushchin struct bpf_map_memory mem; 8328fbcfa0SAlexei Starovoitov struct bpf_array *array; 8428fbcfa0SAlexei Starovoitov 8528fbcfa0SAlexei Starovoitov elem_size = round_up(attr->value_size, 8); 8628fbcfa0SAlexei Starovoitov 87b2157399SAlexei Starovoitov max_entries = attr->max_entries; 88b2157399SAlexei Starovoitov 89bbeb6e43SDaniel Borkmann /* On 32 bit archs roundup_pow_of_two() with max_entries that has 90bbeb6e43SDaniel Borkmann * upper most bit set in u32 space is undefined behavior due to 91bbeb6e43SDaniel Borkmann * resulting 1U << 32, so do it manually here in u64 space. 92bbeb6e43SDaniel Borkmann */ 93bbeb6e43SDaniel Borkmann mask64 = fls_long(max_entries - 1); 94bbeb6e43SDaniel Borkmann mask64 = 1ULL << mask64; 95bbeb6e43SDaniel Borkmann mask64 -= 1; 96bbeb6e43SDaniel Borkmann 97bbeb6e43SDaniel Borkmann index_mask = mask64; 98bbeb6e43SDaniel Borkmann if (unpriv) { 99b2157399SAlexei Starovoitov /* round up array size to nearest power of 2, 100b2157399SAlexei Starovoitov * since cpu will speculate within index_mask limits 101b2157399SAlexei Starovoitov */ 102b2157399SAlexei Starovoitov max_entries = index_mask + 1; 103bbeb6e43SDaniel Borkmann /* Check for overflows. */ 104bbeb6e43SDaniel Borkmann if (max_entries < attr->max_entries) 105bbeb6e43SDaniel Borkmann return ERR_PTR(-E2BIG); 106bbeb6e43SDaniel Borkmann } 107b2157399SAlexei Starovoitov 108a10423b8SAlexei Starovoitov array_size = sizeof(*array); 109fc970227SAndrii Nakryiko if (percpu) { 110b2157399SAlexei Starovoitov array_size += (u64) max_entries * sizeof(void *); 111fc970227SAndrii Nakryiko } else { 112fc970227SAndrii Nakryiko /* rely on vmalloc() to return page-aligned memory and 113fc970227SAndrii Nakryiko * ensure array->value is exactly page-aligned 114fc970227SAndrii Nakryiko */ 115fc970227SAndrii Nakryiko if (attr->map_flags & BPF_F_MMAPABLE) { 116fc970227SAndrii Nakryiko array_size = PAGE_ALIGN(array_size); 117fc970227SAndrii Nakryiko array_size += PAGE_ALIGN((u64) max_entries * elem_size); 118fc970227SAndrii Nakryiko } else { 119b2157399SAlexei Starovoitov array_size += (u64) max_entries * elem_size; 120fc970227SAndrii Nakryiko } 121fc970227SAndrii Nakryiko } 122a10423b8SAlexei Starovoitov 123a10423b8SAlexei Starovoitov /* make sure there is no u32 overflow later in round_up() */ 1249c2d63b8SDaniel Borkmann cost = array_size; 125c85d6913SRoman Gushchin if (percpu) 1269c2d63b8SDaniel Borkmann cost += (u64)attr->max_entries * elem_size * num_possible_cpus(); 1279c2d63b8SDaniel Borkmann 128b936ca64SRoman Gushchin ret = bpf_map_charge_init(&mem, cost); 1299c2d63b8SDaniel Borkmann if (ret < 0) 1309c2d63b8SDaniel Borkmann return ERR_PTR(ret); 131daaf427cSAlexei Starovoitov 13228fbcfa0SAlexei Starovoitov /* allocate all map elements and zero-initialize them */ 133fc970227SAndrii Nakryiko if (attr->map_flags & BPF_F_MMAPABLE) { 134fc970227SAndrii Nakryiko void *data; 135fc970227SAndrii Nakryiko 136fc970227SAndrii Nakryiko /* kmalloc'ed memory can't be mmap'ed, use explicit vmalloc */ 137fc970227SAndrii Nakryiko data = bpf_map_area_mmapable_alloc(array_size, numa_node); 138fc970227SAndrii Nakryiko if (!data) { 139fc970227SAndrii Nakryiko bpf_map_charge_finish(&mem); 140fc970227SAndrii Nakryiko return ERR_PTR(-ENOMEM); 141fc970227SAndrii Nakryiko } 142fc970227SAndrii Nakryiko array = data + PAGE_ALIGN(sizeof(struct bpf_array)) 143fc970227SAndrii Nakryiko - offsetof(struct bpf_array, value); 144fc970227SAndrii Nakryiko } else { 14596eabe7aSMartin KaFai Lau array = bpf_map_area_alloc(array_size, numa_node); 146fc970227SAndrii Nakryiko } 147b936ca64SRoman Gushchin if (!array) { 148b936ca64SRoman Gushchin bpf_map_charge_finish(&mem); 14928fbcfa0SAlexei Starovoitov return ERR_PTR(-ENOMEM); 150b936ca64SRoman Gushchin } 151b2157399SAlexei Starovoitov array->index_mask = index_mask; 152b2157399SAlexei Starovoitov array->map.unpriv_array = unpriv; 15328fbcfa0SAlexei Starovoitov 15428fbcfa0SAlexei Starovoitov /* copy mandatory map attributes */ 15532852649SJakub Kicinski bpf_map_init_from_attr(&array->map, attr); 156b936ca64SRoman Gushchin bpf_map_charge_move(&array->map.memory, &mem); 15728fbcfa0SAlexei Starovoitov array->elem_size = elem_size; 15828fbcfa0SAlexei Starovoitov 1599c2d63b8SDaniel Borkmann if (percpu && bpf_array_alloc_percpu(array)) { 160b936ca64SRoman Gushchin bpf_map_charge_finish(&array->map.memory); 161d407bd25SDaniel Borkmann bpf_map_area_free(array); 162a10423b8SAlexei Starovoitov return ERR_PTR(-ENOMEM); 163a10423b8SAlexei Starovoitov } 164a10423b8SAlexei Starovoitov 16528fbcfa0SAlexei Starovoitov return &array->map; 16628fbcfa0SAlexei Starovoitov } 16728fbcfa0SAlexei Starovoitov 16828fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 16928fbcfa0SAlexei Starovoitov static void *array_map_lookup_elem(struct bpf_map *map, void *key) 17028fbcfa0SAlexei Starovoitov { 17128fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 17228fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 17328fbcfa0SAlexei Starovoitov 174a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 17528fbcfa0SAlexei Starovoitov return NULL; 17628fbcfa0SAlexei Starovoitov 177b2157399SAlexei Starovoitov return array->value + array->elem_size * (index & array->index_mask); 17828fbcfa0SAlexei Starovoitov } 17928fbcfa0SAlexei Starovoitov 180d8eca5bbSDaniel Borkmann static int array_map_direct_value_addr(const struct bpf_map *map, u64 *imm, 181d8eca5bbSDaniel Borkmann u32 off) 182d8eca5bbSDaniel Borkmann { 183d8eca5bbSDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 184d8eca5bbSDaniel Borkmann 185d8eca5bbSDaniel Borkmann if (map->max_entries != 1) 186d8eca5bbSDaniel Borkmann return -ENOTSUPP; 187d8eca5bbSDaniel Borkmann if (off >= map->value_size) 188d8eca5bbSDaniel Borkmann return -EINVAL; 189d8eca5bbSDaniel Borkmann 190d8eca5bbSDaniel Borkmann *imm = (unsigned long)array->value; 191d8eca5bbSDaniel Borkmann return 0; 192d8eca5bbSDaniel Borkmann } 193d8eca5bbSDaniel Borkmann 194d8eca5bbSDaniel Borkmann static int array_map_direct_value_meta(const struct bpf_map *map, u64 imm, 195d8eca5bbSDaniel Borkmann u32 *off) 196d8eca5bbSDaniel Borkmann { 197d8eca5bbSDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 198d8eca5bbSDaniel Borkmann u64 base = (unsigned long)array->value; 199d8eca5bbSDaniel Borkmann u64 range = array->elem_size; 200d8eca5bbSDaniel Borkmann 201d8eca5bbSDaniel Borkmann if (map->max_entries != 1) 202d8eca5bbSDaniel Borkmann return -ENOTSUPP; 203d8eca5bbSDaniel Borkmann if (imm < base || imm >= base + range) 204d8eca5bbSDaniel Borkmann return -ENOENT; 205d8eca5bbSDaniel Borkmann 206d8eca5bbSDaniel Borkmann *off = imm - base; 207d8eca5bbSDaniel Borkmann return 0; 208d8eca5bbSDaniel Borkmann } 209d8eca5bbSDaniel Borkmann 21081ed18abSAlexei Starovoitov /* emit BPF instructions equivalent to C code of array_map_lookup_elem() */ 21181ed18abSAlexei Starovoitov static u32 array_map_gen_lookup(struct bpf_map *map, struct bpf_insn *insn_buf) 21281ed18abSAlexei Starovoitov { 213b2157399SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 21481ed18abSAlexei Starovoitov struct bpf_insn *insn = insn_buf; 215fad73a1aSMartin KaFai Lau u32 elem_size = round_up(map->value_size, 8); 21681ed18abSAlexei Starovoitov const int ret = BPF_REG_0; 21781ed18abSAlexei Starovoitov const int map_ptr = BPF_REG_1; 21881ed18abSAlexei Starovoitov const int index = BPF_REG_2; 21981ed18abSAlexei Starovoitov 22081ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_ADD, map_ptr, offsetof(struct bpf_array, value)); 22181ed18abSAlexei Starovoitov *insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0); 222b2157399SAlexei Starovoitov if (map->unpriv_array) { 223b2157399SAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 4); 224b2157399SAlexei Starovoitov *insn++ = BPF_ALU32_IMM(BPF_AND, ret, array->index_mask); 225b2157399SAlexei Starovoitov } else { 226fad73a1aSMartin KaFai Lau *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 3); 227b2157399SAlexei Starovoitov } 228fad73a1aSMartin KaFai Lau 229fad73a1aSMartin KaFai Lau if (is_power_of_2(elem_size)) { 23081ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(elem_size)); 23181ed18abSAlexei Starovoitov } else { 23281ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_IMM(BPF_MUL, ret, elem_size); 23381ed18abSAlexei Starovoitov } 23481ed18abSAlexei Starovoitov *insn++ = BPF_ALU64_REG(BPF_ADD, ret, map_ptr); 23581ed18abSAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JA, 0, 0, 1); 23681ed18abSAlexei Starovoitov *insn++ = BPF_MOV64_IMM(ret, 0); 23781ed18abSAlexei Starovoitov return insn - insn_buf; 23881ed18abSAlexei Starovoitov } 23981ed18abSAlexei Starovoitov 240a10423b8SAlexei Starovoitov /* Called from eBPF program */ 241a10423b8SAlexei Starovoitov static void *percpu_array_map_lookup_elem(struct bpf_map *map, void *key) 242a10423b8SAlexei Starovoitov { 243a10423b8SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 244a10423b8SAlexei Starovoitov u32 index = *(u32 *)key; 245a10423b8SAlexei Starovoitov 246a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 247a10423b8SAlexei Starovoitov return NULL; 248a10423b8SAlexei Starovoitov 249b2157399SAlexei Starovoitov return this_cpu_ptr(array->pptrs[index & array->index_mask]); 250a10423b8SAlexei Starovoitov } 251a10423b8SAlexei Starovoitov 25215a07b33SAlexei Starovoitov int bpf_percpu_array_copy(struct bpf_map *map, void *key, void *value) 25315a07b33SAlexei Starovoitov { 25415a07b33SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 25515a07b33SAlexei Starovoitov u32 index = *(u32 *)key; 25615a07b33SAlexei Starovoitov void __percpu *pptr; 25715a07b33SAlexei Starovoitov int cpu, off = 0; 25815a07b33SAlexei Starovoitov u32 size; 25915a07b33SAlexei Starovoitov 26015a07b33SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 26115a07b33SAlexei Starovoitov return -ENOENT; 26215a07b33SAlexei Starovoitov 26315a07b33SAlexei Starovoitov /* per_cpu areas are zero-filled and bpf programs can only 26415a07b33SAlexei Starovoitov * access 'value_size' of them, so copying rounded areas 26515a07b33SAlexei Starovoitov * will not leak any kernel data 26615a07b33SAlexei Starovoitov */ 26715a07b33SAlexei Starovoitov size = round_up(map->value_size, 8); 26815a07b33SAlexei Starovoitov rcu_read_lock(); 269b2157399SAlexei Starovoitov pptr = array->pptrs[index & array->index_mask]; 27015a07b33SAlexei Starovoitov for_each_possible_cpu(cpu) { 27115a07b33SAlexei Starovoitov bpf_long_memcpy(value + off, per_cpu_ptr(pptr, cpu), size); 27215a07b33SAlexei Starovoitov off += size; 27315a07b33SAlexei Starovoitov } 27415a07b33SAlexei Starovoitov rcu_read_unlock(); 27515a07b33SAlexei Starovoitov return 0; 27615a07b33SAlexei Starovoitov } 27715a07b33SAlexei Starovoitov 27828fbcfa0SAlexei Starovoitov /* Called from syscall */ 27928fbcfa0SAlexei Starovoitov static int array_map_get_next_key(struct bpf_map *map, void *key, void *next_key) 28028fbcfa0SAlexei Starovoitov { 28128fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 2828fe45924STeng Qin u32 index = key ? *(u32 *)key : U32_MAX; 28328fbcfa0SAlexei Starovoitov u32 *next = (u32 *)next_key; 28428fbcfa0SAlexei Starovoitov 28528fbcfa0SAlexei Starovoitov if (index >= array->map.max_entries) { 28628fbcfa0SAlexei Starovoitov *next = 0; 28728fbcfa0SAlexei Starovoitov return 0; 28828fbcfa0SAlexei Starovoitov } 28928fbcfa0SAlexei Starovoitov 29028fbcfa0SAlexei Starovoitov if (index == array->map.max_entries - 1) 29128fbcfa0SAlexei Starovoitov return -ENOENT; 29228fbcfa0SAlexei Starovoitov 29328fbcfa0SAlexei Starovoitov *next = index + 1; 29428fbcfa0SAlexei Starovoitov return 0; 29528fbcfa0SAlexei Starovoitov } 29628fbcfa0SAlexei Starovoitov 29728fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 29828fbcfa0SAlexei Starovoitov static int array_map_update_elem(struct bpf_map *map, void *key, void *value, 29928fbcfa0SAlexei Starovoitov u64 map_flags) 30028fbcfa0SAlexei Starovoitov { 30128fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 30228fbcfa0SAlexei Starovoitov u32 index = *(u32 *)key; 30396049f3aSAlexei Starovoitov char *val; 30428fbcfa0SAlexei Starovoitov 30596049f3aSAlexei Starovoitov if (unlikely((map_flags & ~BPF_F_LOCK) > BPF_EXIST)) 30628fbcfa0SAlexei Starovoitov /* unknown flags */ 30728fbcfa0SAlexei Starovoitov return -EINVAL; 30828fbcfa0SAlexei Starovoitov 309a10423b8SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 31028fbcfa0SAlexei Starovoitov /* all elements were pre-allocated, cannot insert a new one */ 31128fbcfa0SAlexei Starovoitov return -E2BIG; 31228fbcfa0SAlexei Starovoitov 31396049f3aSAlexei Starovoitov if (unlikely(map_flags & BPF_NOEXIST)) 314daaf427cSAlexei Starovoitov /* all elements already exist */ 31528fbcfa0SAlexei Starovoitov return -EEXIST; 31628fbcfa0SAlexei Starovoitov 31796049f3aSAlexei Starovoitov if (unlikely((map_flags & BPF_F_LOCK) && 31896049f3aSAlexei Starovoitov !map_value_has_spin_lock(map))) 31996049f3aSAlexei Starovoitov return -EINVAL; 32096049f3aSAlexei Starovoitov 32196049f3aSAlexei Starovoitov if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) { 322b2157399SAlexei Starovoitov memcpy(this_cpu_ptr(array->pptrs[index & array->index_mask]), 323a10423b8SAlexei Starovoitov value, map->value_size); 32496049f3aSAlexei Starovoitov } else { 32596049f3aSAlexei Starovoitov val = array->value + 32696049f3aSAlexei Starovoitov array->elem_size * (index & array->index_mask); 32796049f3aSAlexei Starovoitov if (map_flags & BPF_F_LOCK) 32896049f3aSAlexei Starovoitov copy_map_value_locked(map, val, value, false); 329a10423b8SAlexei Starovoitov else 33096049f3aSAlexei Starovoitov copy_map_value(map, val, value); 33196049f3aSAlexei Starovoitov } 33228fbcfa0SAlexei Starovoitov return 0; 33328fbcfa0SAlexei Starovoitov } 33428fbcfa0SAlexei Starovoitov 33515a07b33SAlexei Starovoitov int bpf_percpu_array_update(struct bpf_map *map, void *key, void *value, 33615a07b33SAlexei Starovoitov u64 map_flags) 33715a07b33SAlexei Starovoitov { 33815a07b33SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 33915a07b33SAlexei Starovoitov u32 index = *(u32 *)key; 34015a07b33SAlexei Starovoitov void __percpu *pptr; 34115a07b33SAlexei Starovoitov int cpu, off = 0; 34215a07b33SAlexei Starovoitov u32 size; 34315a07b33SAlexei Starovoitov 34415a07b33SAlexei Starovoitov if (unlikely(map_flags > BPF_EXIST)) 34515a07b33SAlexei Starovoitov /* unknown flags */ 34615a07b33SAlexei Starovoitov return -EINVAL; 34715a07b33SAlexei Starovoitov 34815a07b33SAlexei Starovoitov if (unlikely(index >= array->map.max_entries)) 34915a07b33SAlexei Starovoitov /* all elements were pre-allocated, cannot insert a new one */ 35015a07b33SAlexei Starovoitov return -E2BIG; 35115a07b33SAlexei Starovoitov 35215a07b33SAlexei Starovoitov if (unlikely(map_flags == BPF_NOEXIST)) 35315a07b33SAlexei Starovoitov /* all elements already exist */ 35415a07b33SAlexei Starovoitov return -EEXIST; 35515a07b33SAlexei Starovoitov 35615a07b33SAlexei Starovoitov /* the user space will provide round_up(value_size, 8) bytes that 35715a07b33SAlexei Starovoitov * will be copied into per-cpu area. bpf programs can only access 35815a07b33SAlexei Starovoitov * value_size of it. During lookup the same extra bytes will be 35915a07b33SAlexei Starovoitov * returned or zeros which were zero-filled by percpu_alloc, 36015a07b33SAlexei Starovoitov * so no kernel data leaks possible 36115a07b33SAlexei Starovoitov */ 36215a07b33SAlexei Starovoitov size = round_up(map->value_size, 8); 36315a07b33SAlexei Starovoitov rcu_read_lock(); 364b2157399SAlexei Starovoitov pptr = array->pptrs[index & array->index_mask]; 36515a07b33SAlexei Starovoitov for_each_possible_cpu(cpu) { 36615a07b33SAlexei Starovoitov bpf_long_memcpy(per_cpu_ptr(pptr, cpu), value + off, size); 36715a07b33SAlexei Starovoitov off += size; 36815a07b33SAlexei Starovoitov } 36915a07b33SAlexei Starovoitov rcu_read_unlock(); 37015a07b33SAlexei Starovoitov return 0; 37115a07b33SAlexei Starovoitov } 37215a07b33SAlexei Starovoitov 37328fbcfa0SAlexei Starovoitov /* Called from syscall or from eBPF program */ 37428fbcfa0SAlexei Starovoitov static int array_map_delete_elem(struct bpf_map *map, void *key) 37528fbcfa0SAlexei Starovoitov { 37628fbcfa0SAlexei Starovoitov return -EINVAL; 37728fbcfa0SAlexei Starovoitov } 37828fbcfa0SAlexei Starovoitov 379fc970227SAndrii Nakryiko static void *array_map_vmalloc_addr(struct bpf_array *array) 380fc970227SAndrii Nakryiko { 381fc970227SAndrii Nakryiko return (void *)round_down((unsigned long)array, PAGE_SIZE); 382fc970227SAndrii Nakryiko } 383fc970227SAndrii Nakryiko 38428fbcfa0SAlexei Starovoitov /* Called when map->refcnt goes to zero, either from workqueue or from syscall */ 38528fbcfa0SAlexei Starovoitov static void array_map_free(struct bpf_map *map) 38628fbcfa0SAlexei Starovoitov { 38728fbcfa0SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 38828fbcfa0SAlexei Starovoitov 38928fbcfa0SAlexei Starovoitov /* at this point bpf_prog->aux->refcnt == 0 and this map->refcnt == 0, 39028fbcfa0SAlexei Starovoitov * so the programs (can be more than one that used this map) were 39128fbcfa0SAlexei Starovoitov * disconnected from events. Wait for outstanding programs to complete 39228fbcfa0SAlexei Starovoitov * and free the array 39328fbcfa0SAlexei Starovoitov */ 39428fbcfa0SAlexei Starovoitov synchronize_rcu(); 39528fbcfa0SAlexei Starovoitov 396a10423b8SAlexei Starovoitov if (array->map.map_type == BPF_MAP_TYPE_PERCPU_ARRAY) 397a10423b8SAlexei Starovoitov bpf_array_free_percpu(array); 398a10423b8SAlexei Starovoitov 399fc970227SAndrii Nakryiko if (array->map.map_flags & BPF_F_MMAPABLE) 400fc970227SAndrii Nakryiko bpf_map_area_free(array_map_vmalloc_addr(array)); 401fc970227SAndrii Nakryiko else 402d407bd25SDaniel Borkmann bpf_map_area_free(array); 40328fbcfa0SAlexei Starovoitov } 40428fbcfa0SAlexei Starovoitov 405a26ca7c9SMartin KaFai Lau static void array_map_seq_show_elem(struct bpf_map *map, void *key, 406a26ca7c9SMartin KaFai Lau struct seq_file *m) 407a26ca7c9SMartin KaFai Lau { 408a26ca7c9SMartin KaFai Lau void *value; 409a26ca7c9SMartin KaFai Lau 410a26ca7c9SMartin KaFai Lau rcu_read_lock(); 411a26ca7c9SMartin KaFai Lau 412a26ca7c9SMartin KaFai Lau value = array_map_lookup_elem(map, key); 413a26ca7c9SMartin KaFai Lau if (!value) { 414a26ca7c9SMartin KaFai Lau rcu_read_unlock(); 415a26ca7c9SMartin KaFai Lau return; 416a26ca7c9SMartin KaFai Lau } 417a26ca7c9SMartin KaFai Lau 4182824ecb7SDaniel Borkmann if (map->btf_key_type_id) 419a26ca7c9SMartin KaFai Lau seq_printf(m, "%u: ", *(u32 *)key); 4209b2cf328SMartin KaFai Lau btf_type_seq_show(map->btf, map->btf_value_type_id, value, m); 421a26ca7c9SMartin KaFai Lau seq_puts(m, "\n"); 422a26ca7c9SMartin KaFai Lau 423a26ca7c9SMartin KaFai Lau rcu_read_unlock(); 424a26ca7c9SMartin KaFai Lau } 425a26ca7c9SMartin KaFai Lau 426c7b27c37SYonghong Song static void percpu_array_map_seq_show_elem(struct bpf_map *map, void *key, 427c7b27c37SYonghong Song struct seq_file *m) 428c7b27c37SYonghong Song { 429c7b27c37SYonghong Song struct bpf_array *array = container_of(map, struct bpf_array, map); 430c7b27c37SYonghong Song u32 index = *(u32 *)key; 431c7b27c37SYonghong Song void __percpu *pptr; 432c7b27c37SYonghong Song int cpu; 433c7b27c37SYonghong Song 434c7b27c37SYonghong Song rcu_read_lock(); 435c7b27c37SYonghong Song 436c7b27c37SYonghong Song seq_printf(m, "%u: {\n", *(u32 *)key); 437c7b27c37SYonghong Song pptr = array->pptrs[index & array->index_mask]; 438c7b27c37SYonghong Song for_each_possible_cpu(cpu) { 439c7b27c37SYonghong Song seq_printf(m, "\tcpu%d: ", cpu); 440c7b27c37SYonghong Song btf_type_seq_show(map->btf, map->btf_value_type_id, 441c7b27c37SYonghong Song per_cpu_ptr(pptr, cpu), m); 442c7b27c37SYonghong Song seq_puts(m, "\n"); 443c7b27c37SYonghong Song } 444c7b27c37SYonghong Song seq_puts(m, "}\n"); 445c7b27c37SYonghong Song 446c7b27c37SYonghong Song rcu_read_unlock(); 447c7b27c37SYonghong Song } 448c7b27c37SYonghong Song 449e8d2bec0SDaniel Borkmann static int array_map_check_btf(const struct bpf_map *map, 4501b2b234bSRoman Gushchin const struct btf *btf, 451e8d2bec0SDaniel Borkmann const struct btf_type *key_type, 452e8d2bec0SDaniel Borkmann const struct btf_type *value_type) 453a26ca7c9SMartin KaFai Lau { 454a26ca7c9SMartin KaFai Lau u32 int_data; 455a26ca7c9SMartin KaFai Lau 4562824ecb7SDaniel Borkmann /* One exception for keyless BTF: .bss/.data/.rodata map */ 4572824ecb7SDaniel Borkmann if (btf_type_is_void(key_type)) { 4582824ecb7SDaniel Borkmann if (map->map_type != BPF_MAP_TYPE_ARRAY || 4592824ecb7SDaniel Borkmann map->max_entries != 1) 4602824ecb7SDaniel Borkmann return -EINVAL; 4612824ecb7SDaniel Borkmann 4622824ecb7SDaniel Borkmann if (BTF_INFO_KIND(value_type->info) != BTF_KIND_DATASEC) 4632824ecb7SDaniel Borkmann return -EINVAL; 4642824ecb7SDaniel Borkmann 4652824ecb7SDaniel Borkmann return 0; 4662824ecb7SDaniel Borkmann } 4672824ecb7SDaniel Borkmann 468e8d2bec0SDaniel Borkmann if (BTF_INFO_KIND(key_type->info) != BTF_KIND_INT) 469a26ca7c9SMartin KaFai Lau return -EINVAL; 470a26ca7c9SMartin KaFai Lau 471a26ca7c9SMartin KaFai Lau int_data = *(u32 *)(key_type + 1); 472e8d2bec0SDaniel Borkmann /* bpf array can only take a u32 key. This check makes sure 473e8d2bec0SDaniel Borkmann * that the btf matches the attr used during map_create. 474a26ca7c9SMartin KaFai Lau */ 475e8d2bec0SDaniel Borkmann if (BTF_INT_BITS(int_data) != 32 || BTF_INT_OFFSET(int_data)) 476a26ca7c9SMartin KaFai Lau return -EINVAL; 477a26ca7c9SMartin KaFai Lau 478a26ca7c9SMartin KaFai Lau return 0; 479a26ca7c9SMartin KaFai Lau } 480a26ca7c9SMartin KaFai Lau 481b2e2f0e6SYueHaibing static int array_map_mmap(struct bpf_map *map, struct vm_area_struct *vma) 482fc970227SAndrii Nakryiko { 483fc970227SAndrii Nakryiko struct bpf_array *array = container_of(map, struct bpf_array, map); 484fc970227SAndrii Nakryiko pgoff_t pgoff = PAGE_ALIGN(sizeof(*array)) >> PAGE_SHIFT; 485fc970227SAndrii Nakryiko 486fc970227SAndrii Nakryiko if (!(map->map_flags & BPF_F_MMAPABLE)) 487fc970227SAndrii Nakryiko return -EINVAL; 488fc970227SAndrii Nakryiko 489fc970227SAndrii Nakryiko return remap_vmalloc_range(vma, array_map_vmalloc_addr(array), pgoff); 490fc970227SAndrii Nakryiko } 491fc970227SAndrii Nakryiko 49240077e0cSJohannes Berg const struct bpf_map_ops array_map_ops = { 493ad46061fSJakub Kicinski .map_alloc_check = array_map_alloc_check, 49428fbcfa0SAlexei Starovoitov .map_alloc = array_map_alloc, 49528fbcfa0SAlexei Starovoitov .map_free = array_map_free, 49628fbcfa0SAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 49728fbcfa0SAlexei Starovoitov .map_lookup_elem = array_map_lookup_elem, 49828fbcfa0SAlexei Starovoitov .map_update_elem = array_map_update_elem, 49928fbcfa0SAlexei Starovoitov .map_delete_elem = array_map_delete_elem, 50081ed18abSAlexei Starovoitov .map_gen_lookup = array_map_gen_lookup, 501d8eca5bbSDaniel Borkmann .map_direct_value_addr = array_map_direct_value_addr, 502d8eca5bbSDaniel Borkmann .map_direct_value_meta = array_map_direct_value_meta, 503fc970227SAndrii Nakryiko .map_mmap = array_map_mmap, 504a26ca7c9SMartin KaFai Lau .map_seq_show_elem = array_map_seq_show_elem, 505a26ca7c9SMartin KaFai Lau .map_check_btf = array_map_check_btf, 50628fbcfa0SAlexei Starovoitov }; 50728fbcfa0SAlexei Starovoitov 50840077e0cSJohannes Berg const struct bpf_map_ops percpu_array_map_ops = { 509ad46061fSJakub Kicinski .map_alloc_check = array_map_alloc_check, 510a10423b8SAlexei Starovoitov .map_alloc = array_map_alloc, 511a10423b8SAlexei Starovoitov .map_free = array_map_free, 512a10423b8SAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 513a10423b8SAlexei Starovoitov .map_lookup_elem = percpu_array_map_lookup_elem, 514a10423b8SAlexei Starovoitov .map_update_elem = array_map_update_elem, 515a10423b8SAlexei Starovoitov .map_delete_elem = array_map_delete_elem, 516c7b27c37SYonghong Song .map_seq_show_elem = percpu_array_map_seq_show_elem, 517e8d2bec0SDaniel Borkmann .map_check_btf = array_map_check_btf, 518a10423b8SAlexei Starovoitov }; 519a10423b8SAlexei Starovoitov 520ad46061fSJakub Kicinski static int fd_array_map_alloc_check(union bpf_attr *attr) 52104fd61abSAlexei Starovoitov { 5222a36f0b9SWang Nan /* only file descriptors can be stored in this type of map */ 52304fd61abSAlexei Starovoitov if (attr->value_size != sizeof(u32)) 524ad46061fSJakub Kicinski return -EINVAL; 525591fe988SDaniel Borkmann /* Program read-only/write-only not supported for special maps yet. */ 526591fe988SDaniel Borkmann if (attr->map_flags & (BPF_F_RDONLY_PROG | BPF_F_WRONLY_PROG)) 527591fe988SDaniel Borkmann return -EINVAL; 528ad46061fSJakub Kicinski return array_map_alloc_check(attr); 52904fd61abSAlexei Starovoitov } 53004fd61abSAlexei Starovoitov 5312a36f0b9SWang Nan static void fd_array_map_free(struct bpf_map *map) 53204fd61abSAlexei Starovoitov { 53304fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 53404fd61abSAlexei Starovoitov int i; 53504fd61abSAlexei Starovoitov 53604fd61abSAlexei Starovoitov synchronize_rcu(); 53704fd61abSAlexei Starovoitov 53804fd61abSAlexei Starovoitov /* make sure it's empty */ 53904fd61abSAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 5402a36f0b9SWang Nan BUG_ON(array->ptrs[i] != NULL); 541d407bd25SDaniel Borkmann 542d407bd25SDaniel Borkmann bpf_map_area_free(array); 54304fd61abSAlexei Starovoitov } 54404fd61abSAlexei Starovoitov 5452a36f0b9SWang Nan static void *fd_array_map_lookup_elem(struct bpf_map *map, void *key) 54604fd61abSAlexei Starovoitov { 5473b4a63f6SPrashant Bhole return ERR_PTR(-EOPNOTSUPP); 54804fd61abSAlexei Starovoitov } 54904fd61abSAlexei Starovoitov 55004fd61abSAlexei Starovoitov /* only called from syscall */ 55114dc6f04SMartin KaFai Lau int bpf_fd_array_map_lookup_elem(struct bpf_map *map, void *key, u32 *value) 55214dc6f04SMartin KaFai Lau { 55314dc6f04SMartin KaFai Lau void **elem, *ptr; 55414dc6f04SMartin KaFai Lau int ret = 0; 55514dc6f04SMartin KaFai Lau 55614dc6f04SMartin KaFai Lau if (!map->ops->map_fd_sys_lookup_elem) 55714dc6f04SMartin KaFai Lau return -ENOTSUPP; 55814dc6f04SMartin KaFai Lau 55914dc6f04SMartin KaFai Lau rcu_read_lock(); 56014dc6f04SMartin KaFai Lau elem = array_map_lookup_elem(map, key); 56114dc6f04SMartin KaFai Lau if (elem && (ptr = READ_ONCE(*elem))) 56214dc6f04SMartin KaFai Lau *value = map->ops->map_fd_sys_lookup_elem(ptr); 56314dc6f04SMartin KaFai Lau else 56414dc6f04SMartin KaFai Lau ret = -ENOENT; 56514dc6f04SMartin KaFai Lau rcu_read_unlock(); 56614dc6f04SMartin KaFai Lau 56714dc6f04SMartin KaFai Lau return ret; 56814dc6f04SMartin KaFai Lau } 56914dc6f04SMartin KaFai Lau 57014dc6f04SMartin KaFai Lau /* only called from syscall */ 571d056a788SDaniel Borkmann int bpf_fd_array_map_update_elem(struct bpf_map *map, struct file *map_file, 572d056a788SDaniel Borkmann void *key, void *value, u64 map_flags) 57304fd61abSAlexei Starovoitov { 57404fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 5752a36f0b9SWang Nan void *new_ptr, *old_ptr; 57604fd61abSAlexei Starovoitov u32 index = *(u32 *)key, ufd; 57704fd61abSAlexei Starovoitov 57804fd61abSAlexei Starovoitov if (map_flags != BPF_ANY) 57904fd61abSAlexei Starovoitov return -EINVAL; 58004fd61abSAlexei Starovoitov 58104fd61abSAlexei Starovoitov if (index >= array->map.max_entries) 58204fd61abSAlexei Starovoitov return -E2BIG; 58304fd61abSAlexei Starovoitov 58404fd61abSAlexei Starovoitov ufd = *(u32 *)value; 585d056a788SDaniel Borkmann new_ptr = map->ops->map_fd_get_ptr(map, map_file, ufd); 5862a36f0b9SWang Nan if (IS_ERR(new_ptr)) 5872a36f0b9SWang Nan return PTR_ERR(new_ptr); 58804fd61abSAlexei Starovoitov 589*da765a2fSDaniel Borkmann if (map->ops->map_poke_run) { 590*da765a2fSDaniel Borkmann mutex_lock(&array->aux->poke_mutex); 5912a36f0b9SWang Nan old_ptr = xchg(array->ptrs + index, new_ptr); 592*da765a2fSDaniel Borkmann map->ops->map_poke_run(map, index, old_ptr, new_ptr); 593*da765a2fSDaniel Borkmann mutex_unlock(&array->aux->poke_mutex); 594*da765a2fSDaniel Borkmann } else { 595*da765a2fSDaniel Borkmann old_ptr = xchg(array->ptrs + index, new_ptr); 596*da765a2fSDaniel Borkmann } 597*da765a2fSDaniel Borkmann 5982a36f0b9SWang Nan if (old_ptr) 5992a36f0b9SWang Nan map->ops->map_fd_put_ptr(old_ptr); 60004fd61abSAlexei Starovoitov return 0; 60104fd61abSAlexei Starovoitov } 60204fd61abSAlexei Starovoitov 6032a36f0b9SWang Nan static int fd_array_map_delete_elem(struct bpf_map *map, void *key) 60404fd61abSAlexei Starovoitov { 60504fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 6062a36f0b9SWang Nan void *old_ptr; 60704fd61abSAlexei Starovoitov u32 index = *(u32 *)key; 60804fd61abSAlexei Starovoitov 60904fd61abSAlexei Starovoitov if (index >= array->map.max_entries) 61004fd61abSAlexei Starovoitov return -E2BIG; 61104fd61abSAlexei Starovoitov 612*da765a2fSDaniel Borkmann if (map->ops->map_poke_run) { 613*da765a2fSDaniel Borkmann mutex_lock(&array->aux->poke_mutex); 6142a36f0b9SWang Nan old_ptr = xchg(array->ptrs + index, NULL); 615*da765a2fSDaniel Borkmann map->ops->map_poke_run(map, index, old_ptr, NULL); 616*da765a2fSDaniel Borkmann mutex_unlock(&array->aux->poke_mutex); 617*da765a2fSDaniel Borkmann } else { 618*da765a2fSDaniel Borkmann old_ptr = xchg(array->ptrs + index, NULL); 619*da765a2fSDaniel Borkmann } 620*da765a2fSDaniel Borkmann 6212a36f0b9SWang Nan if (old_ptr) { 6222a36f0b9SWang Nan map->ops->map_fd_put_ptr(old_ptr); 62304fd61abSAlexei Starovoitov return 0; 62404fd61abSAlexei Starovoitov } else { 62504fd61abSAlexei Starovoitov return -ENOENT; 62604fd61abSAlexei Starovoitov } 62704fd61abSAlexei Starovoitov } 62804fd61abSAlexei Starovoitov 629d056a788SDaniel Borkmann static void *prog_fd_array_get_ptr(struct bpf_map *map, 630d056a788SDaniel Borkmann struct file *map_file, int fd) 6312a36f0b9SWang Nan { 6322a36f0b9SWang Nan struct bpf_array *array = container_of(map, struct bpf_array, map); 6332a36f0b9SWang Nan struct bpf_prog *prog = bpf_prog_get(fd); 634d056a788SDaniel Borkmann 6352a36f0b9SWang Nan if (IS_ERR(prog)) 6362a36f0b9SWang Nan return prog; 6372a36f0b9SWang Nan 6382a36f0b9SWang Nan if (!bpf_prog_array_compatible(array, prog)) { 6392a36f0b9SWang Nan bpf_prog_put(prog); 6402a36f0b9SWang Nan return ERR_PTR(-EINVAL); 6412a36f0b9SWang Nan } 642d056a788SDaniel Borkmann 6432a36f0b9SWang Nan return prog; 6442a36f0b9SWang Nan } 6452a36f0b9SWang Nan 6462a36f0b9SWang Nan static void prog_fd_array_put_ptr(void *ptr) 6472a36f0b9SWang Nan { 6481aacde3dSDaniel Borkmann bpf_prog_put(ptr); 6492a36f0b9SWang Nan } 6502a36f0b9SWang Nan 65114dc6f04SMartin KaFai Lau static u32 prog_fd_array_sys_lookup_elem(void *ptr) 65214dc6f04SMartin KaFai Lau { 65314dc6f04SMartin KaFai Lau return ((struct bpf_prog *)ptr)->aux->id; 65414dc6f04SMartin KaFai Lau } 65514dc6f04SMartin KaFai Lau 65604fd61abSAlexei Starovoitov /* decrement refcnt of all bpf_progs that are stored in this map */ 657ba6b8de4SJohn Fastabend static void bpf_fd_array_map_clear(struct bpf_map *map) 65804fd61abSAlexei Starovoitov { 65904fd61abSAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 66004fd61abSAlexei Starovoitov int i; 66104fd61abSAlexei Starovoitov 66204fd61abSAlexei Starovoitov for (i = 0; i < array->map.max_entries; i++) 6632a36f0b9SWang Nan fd_array_map_delete_elem(map, &i); 66404fd61abSAlexei Starovoitov } 66504fd61abSAlexei Starovoitov 666a7c19db3SYonghong Song static void prog_array_map_seq_show_elem(struct bpf_map *map, void *key, 667a7c19db3SYonghong Song struct seq_file *m) 668a7c19db3SYonghong Song { 669a7c19db3SYonghong Song void **elem, *ptr; 670a7c19db3SYonghong Song u32 prog_id; 671a7c19db3SYonghong Song 672a7c19db3SYonghong Song rcu_read_lock(); 673a7c19db3SYonghong Song 674a7c19db3SYonghong Song elem = array_map_lookup_elem(map, key); 675a7c19db3SYonghong Song if (elem) { 676a7c19db3SYonghong Song ptr = READ_ONCE(*elem); 677a7c19db3SYonghong Song if (ptr) { 678a7c19db3SYonghong Song seq_printf(m, "%u: ", *(u32 *)key); 679a7c19db3SYonghong Song prog_id = prog_fd_array_sys_lookup_elem(ptr); 680a7c19db3SYonghong Song btf_type_seq_show(map->btf, map->btf_value_type_id, 681a7c19db3SYonghong Song &prog_id, m); 682a7c19db3SYonghong Song seq_puts(m, "\n"); 683a7c19db3SYonghong Song } 684a7c19db3SYonghong Song } 685a7c19db3SYonghong Song 686a7c19db3SYonghong Song rcu_read_unlock(); 687a7c19db3SYonghong Song } 688a7c19db3SYonghong Song 689*da765a2fSDaniel Borkmann struct prog_poke_elem { 690*da765a2fSDaniel Borkmann struct list_head list; 691*da765a2fSDaniel Borkmann struct bpf_prog_aux *aux; 692*da765a2fSDaniel Borkmann }; 693*da765a2fSDaniel Borkmann 694*da765a2fSDaniel Borkmann static int prog_array_map_poke_track(struct bpf_map *map, 695*da765a2fSDaniel Borkmann struct bpf_prog_aux *prog_aux) 696*da765a2fSDaniel Borkmann { 697*da765a2fSDaniel Borkmann struct prog_poke_elem *elem; 698*da765a2fSDaniel Borkmann struct bpf_array_aux *aux; 699*da765a2fSDaniel Borkmann int ret = 0; 700*da765a2fSDaniel Borkmann 701*da765a2fSDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 702*da765a2fSDaniel Borkmann mutex_lock(&aux->poke_mutex); 703*da765a2fSDaniel Borkmann list_for_each_entry(elem, &aux->poke_progs, list) { 704*da765a2fSDaniel Borkmann if (elem->aux == prog_aux) 705*da765a2fSDaniel Borkmann goto out; 706*da765a2fSDaniel Borkmann } 707*da765a2fSDaniel Borkmann 708*da765a2fSDaniel Borkmann elem = kmalloc(sizeof(*elem), GFP_KERNEL); 709*da765a2fSDaniel Borkmann if (!elem) { 710*da765a2fSDaniel Borkmann ret = -ENOMEM; 711*da765a2fSDaniel Borkmann goto out; 712*da765a2fSDaniel Borkmann } 713*da765a2fSDaniel Borkmann 714*da765a2fSDaniel Borkmann INIT_LIST_HEAD(&elem->list); 715*da765a2fSDaniel Borkmann /* We must track the program's aux info at this point in time 716*da765a2fSDaniel Borkmann * since the program pointer itself may not be stable yet, see 717*da765a2fSDaniel Borkmann * also comment in prog_array_map_poke_run(). 718*da765a2fSDaniel Borkmann */ 719*da765a2fSDaniel Borkmann elem->aux = prog_aux; 720*da765a2fSDaniel Borkmann 721*da765a2fSDaniel Borkmann list_add_tail(&elem->list, &aux->poke_progs); 722*da765a2fSDaniel Borkmann out: 723*da765a2fSDaniel Borkmann mutex_unlock(&aux->poke_mutex); 724*da765a2fSDaniel Borkmann return ret; 725*da765a2fSDaniel Borkmann } 726*da765a2fSDaniel Borkmann 727*da765a2fSDaniel Borkmann static void prog_array_map_poke_untrack(struct bpf_map *map, 728*da765a2fSDaniel Borkmann struct bpf_prog_aux *prog_aux) 729*da765a2fSDaniel Borkmann { 730*da765a2fSDaniel Borkmann struct prog_poke_elem *elem, *tmp; 731*da765a2fSDaniel Borkmann struct bpf_array_aux *aux; 732*da765a2fSDaniel Borkmann 733*da765a2fSDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 734*da765a2fSDaniel Borkmann mutex_lock(&aux->poke_mutex); 735*da765a2fSDaniel Borkmann list_for_each_entry_safe(elem, tmp, &aux->poke_progs, list) { 736*da765a2fSDaniel Borkmann if (elem->aux == prog_aux) { 737*da765a2fSDaniel Borkmann list_del_init(&elem->list); 738*da765a2fSDaniel Borkmann kfree(elem); 739*da765a2fSDaniel Borkmann break; 740*da765a2fSDaniel Borkmann } 741*da765a2fSDaniel Borkmann } 742*da765a2fSDaniel Borkmann mutex_unlock(&aux->poke_mutex); 743*da765a2fSDaniel Borkmann } 744*da765a2fSDaniel Borkmann 745*da765a2fSDaniel Borkmann static void prog_array_map_poke_run(struct bpf_map *map, u32 key, 746*da765a2fSDaniel Borkmann struct bpf_prog *old, 747*da765a2fSDaniel Borkmann struct bpf_prog *new) 748*da765a2fSDaniel Borkmann { 749*da765a2fSDaniel Borkmann enum bpf_text_poke_type type; 750*da765a2fSDaniel Borkmann struct prog_poke_elem *elem; 751*da765a2fSDaniel Borkmann struct bpf_array_aux *aux; 752*da765a2fSDaniel Borkmann 753*da765a2fSDaniel Borkmann if (!old && new) 754*da765a2fSDaniel Borkmann type = BPF_MOD_NOP_TO_JUMP; 755*da765a2fSDaniel Borkmann else if (old && !new) 756*da765a2fSDaniel Borkmann type = BPF_MOD_JUMP_TO_NOP; 757*da765a2fSDaniel Borkmann else if (old && new) 758*da765a2fSDaniel Borkmann type = BPF_MOD_JUMP_TO_JUMP; 759*da765a2fSDaniel Borkmann else 760*da765a2fSDaniel Borkmann return; 761*da765a2fSDaniel Borkmann 762*da765a2fSDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 763*da765a2fSDaniel Borkmann WARN_ON_ONCE(!mutex_is_locked(&aux->poke_mutex)); 764*da765a2fSDaniel Borkmann 765*da765a2fSDaniel Borkmann list_for_each_entry(elem, &aux->poke_progs, list) { 766*da765a2fSDaniel Borkmann struct bpf_jit_poke_descriptor *poke; 767*da765a2fSDaniel Borkmann int i, ret; 768*da765a2fSDaniel Borkmann 769*da765a2fSDaniel Borkmann for (i = 0; i < elem->aux->size_poke_tab; i++) { 770*da765a2fSDaniel Borkmann poke = &elem->aux->poke_tab[i]; 771*da765a2fSDaniel Borkmann 772*da765a2fSDaniel Borkmann /* Few things to be aware of: 773*da765a2fSDaniel Borkmann * 774*da765a2fSDaniel Borkmann * 1) We can only ever access aux in this context, but 775*da765a2fSDaniel Borkmann * not aux->prog since it might not be stable yet and 776*da765a2fSDaniel Borkmann * there could be danger of use after free otherwise. 777*da765a2fSDaniel Borkmann * 2) Initially when we start tracking aux, the program 778*da765a2fSDaniel Borkmann * is not JITed yet and also does not have a kallsyms 779*da765a2fSDaniel Borkmann * entry. We skip these as poke->ip_stable is not 780*da765a2fSDaniel Borkmann * active yet. The JIT will do the final fixup before 781*da765a2fSDaniel Borkmann * setting it stable. The various poke->ip_stable are 782*da765a2fSDaniel Borkmann * successively activated, so tail call updates can 783*da765a2fSDaniel Borkmann * arrive from here while JIT is still finishing its 784*da765a2fSDaniel Borkmann * final fixup for non-activated poke entries. 785*da765a2fSDaniel Borkmann * 3) On program teardown, the program's kallsym entry gets 786*da765a2fSDaniel Borkmann * removed out of RCU callback, but we can only untrack 787*da765a2fSDaniel Borkmann * from sleepable context, therefore bpf_arch_text_poke() 788*da765a2fSDaniel Borkmann * might not see that this is in BPF text section and 789*da765a2fSDaniel Borkmann * bails out with -EINVAL. As these are unreachable since 790*da765a2fSDaniel Borkmann * RCU grace period already passed, we simply skip them. 791*da765a2fSDaniel Borkmann * 4) Also programs reaching refcount of zero while patching 792*da765a2fSDaniel Borkmann * is in progress is okay since we're protected under 793*da765a2fSDaniel Borkmann * poke_mutex and untrack the programs before the JIT 794*da765a2fSDaniel Borkmann * buffer is freed. When we're still in the middle of 795*da765a2fSDaniel Borkmann * patching and suddenly kallsyms entry of the program 796*da765a2fSDaniel Borkmann * gets evicted, we just skip the rest which is fine due 797*da765a2fSDaniel Borkmann * to point 3). 798*da765a2fSDaniel Borkmann * 5) Any other error happening below from bpf_arch_text_poke() 799*da765a2fSDaniel Borkmann * is a unexpected bug. 800*da765a2fSDaniel Borkmann */ 801*da765a2fSDaniel Borkmann if (!READ_ONCE(poke->ip_stable)) 802*da765a2fSDaniel Borkmann continue; 803*da765a2fSDaniel Borkmann if (poke->reason != BPF_POKE_REASON_TAIL_CALL) 804*da765a2fSDaniel Borkmann continue; 805*da765a2fSDaniel Borkmann if (poke->tail_call.map != map || 806*da765a2fSDaniel Borkmann poke->tail_call.key != key) 807*da765a2fSDaniel Borkmann continue; 808*da765a2fSDaniel Borkmann 809*da765a2fSDaniel Borkmann ret = bpf_arch_text_poke(poke->ip, type, 810*da765a2fSDaniel Borkmann old ? (u8 *)old->bpf_func + 811*da765a2fSDaniel Borkmann poke->adj_off : NULL, 812*da765a2fSDaniel Borkmann new ? (u8 *)new->bpf_func + 813*da765a2fSDaniel Borkmann poke->adj_off : NULL); 814*da765a2fSDaniel Borkmann BUG_ON(ret < 0 && ret != -EINVAL); 815*da765a2fSDaniel Borkmann } 816*da765a2fSDaniel Borkmann } 817*da765a2fSDaniel Borkmann } 818*da765a2fSDaniel Borkmann 819*da765a2fSDaniel Borkmann static void prog_array_map_clear_deferred(struct work_struct *work) 820*da765a2fSDaniel Borkmann { 821*da765a2fSDaniel Borkmann struct bpf_map *map = container_of(work, struct bpf_array_aux, 822*da765a2fSDaniel Borkmann work)->map; 823*da765a2fSDaniel Borkmann bpf_fd_array_map_clear(map); 824*da765a2fSDaniel Borkmann bpf_map_put(map); 825*da765a2fSDaniel Borkmann } 826*da765a2fSDaniel Borkmann 827*da765a2fSDaniel Borkmann static void prog_array_map_clear(struct bpf_map *map) 828*da765a2fSDaniel Borkmann { 829*da765a2fSDaniel Borkmann struct bpf_array_aux *aux = container_of(map, struct bpf_array, 830*da765a2fSDaniel Borkmann map)->aux; 831*da765a2fSDaniel Borkmann bpf_map_inc(map); 832*da765a2fSDaniel Borkmann schedule_work(&aux->work); 833*da765a2fSDaniel Borkmann } 834*da765a2fSDaniel Borkmann 8352beee5f5SDaniel Borkmann static struct bpf_map *prog_array_map_alloc(union bpf_attr *attr) 8362beee5f5SDaniel Borkmann { 8372beee5f5SDaniel Borkmann struct bpf_array_aux *aux; 8382beee5f5SDaniel Borkmann struct bpf_map *map; 8392beee5f5SDaniel Borkmann 8402beee5f5SDaniel Borkmann aux = kzalloc(sizeof(*aux), GFP_KERNEL); 8412beee5f5SDaniel Borkmann if (!aux) 8422beee5f5SDaniel Borkmann return ERR_PTR(-ENOMEM); 8432beee5f5SDaniel Borkmann 844*da765a2fSDaniel Borkmann INIT_WORK(&aux->work, prog_array_map_clear_deferred); 845*da765a2fSDaniel Borkmann INIT_LIST_HEAD(&aux->poke_progs); 846*da765a2fSDaniel Borkmann mutex_init(&aux->poke_mutex); 847*da765a2fSDaniel Borkmann 8482beee5f5SDaniel Borkmann map = array_map_alloc(attr); 8492beee5f5SDaniel Borkmann if (IS_ERR(map)) { 8502beee5f5SDaniel Borkmann kfree(aux); 8512beee5f5SDaniel Borkmann return map; 8522beee5f5SDaniel Borkmann } 8532beee5f5SDaniel Borkmann 8542beee5f5SDaniel Borkmann container_of(map, struct bpf_array, map)->aux = aux; 855*da765a2fSDaniel Borkmann aux->map = map; 856*da765a2fSDaniel Borkmann 8572beee5f5SDaniel Borkmann return map; 8582beee5f5SDaniel Borkmann } 8592beee5f5SDaniel Borkmann 8602beee5f5SDaniel Borkmann static void prog_array_map_free(struct bpf_map *map) 8612beee5f5SDaniel Borkmann { 862*da765a2fSDaniel Borkmann struct prog_poke_elem *elem, *tmp; 8632beee5f5SDaniel Borkmann struct bpf_array_aux *aux; 8642beee5f5SDaniel Borkmann 8652beee5f5SDaniel Borkmann aux = container_of(map, struct bpf_array, map)->aux; 866*da765a2fSDaniel Borkmann list_for_each_entry_safe(elem, tmp, &aux->poke_progs, list) { 867*da765a2fSDaniel Borkmann list_del_init(&elem->list); 868*da765a2fSDaniel Borkmann kfree(elem); 869*da765a2fSDaniel Borkmann } 8702beee5f5SDaniel Borkmann kfree(aux); 8712beee5f5SDaniel Borkmann fd_array_map_free(map); 8722beee5f5SDaniel Borkmann } 8732beee5f5SDaniel Borkmann 87440077e0cSJohannes Berg const struct bpf_map_ops prog_array_map_ops = { 875ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 8762beee5f5SDaniel Borkmann .map_alloc = prog_array_map_alloc, 8772beee5f5SDaniel Borkmann .map_free = prog_array_map_free, 878*da765a2fSDaniel Borkmann .map_poke_track = prog_array_map_poke_track, 879*da765a2fSDaniel Borkmann .map_poke_untrack = prog_array_map_poke_untrack, 880*da765a2fSDaniel Borkmann .map_poke_run = prog_array_map_poke_run, 88104fd61abSAlexei Starovoitov .map_get_next_key = array_map_get_next_key, 8822a36f0b9SWang Nan .map_lookup_elem = fd_array_map_lookup_elem, 8832a36f0b9SWang Nan .map_delete_elem = fd_array_map_delete_elem, 8842a36f0b9SWang Nan .map_fd_get_ptr = prog_fd_array_get_ptr, 8852a36f0b9SWang Nan .map_fd_put_ptr = prog_fd_array_put_ptr, 88614dc6f04SMartin KaFai Lau .map_fd_sys_lookup_elem = prog_fd_array_sys_lookup_elem, 887*da765a2fSDaniel Borkmann .map_release_uref = prog_array_map_clear, 888a7c19db3SYonghong Song .map_seq_show_elem = prog_array_map_seq_show_elem, 88904fd61abSAlexei Starovoitov }; 89004fd61abSAlexei Starovoitov 8913b1efb19SDaniel Borkmann static struct bpf_event_entry *bpf_event_entry_gen(struct file *perf_file, 8923b1efb19SDaniel Borkmann struct file *map_file) 893ea317b26SKaixu Xia { 8943b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 8953b1efb19SDaniel Borkmann 896858d68f1SDaniel Borkmann ee = kzalloc(sizeof(*ee), GFP_ATOMIC); 8973b1efb19SDaniel Borkmann if (ee) { 8983b1efb19SDaniel Borkmann ee->event = perf_file->private_data; 8993b1efb19SDaniel Borkmann ee->perf_file = perf_file; 9003b1efb19SDaniel Borkmann ee->map_file = map_file; 9013b1efb19SDaniel Borkmann } 9023b1efb19SDaniel Borkmann 9033b1efb19SDaniel Borkmann return ee; 9043b1efb19SDaniel Borkmann } 9053b1efb19SDaniel Borkmann 9063b1efb19SDaniel Borkmann static void __bpf_event_entry_free(struct rcu_head *rcu) 9073b1efb19SDaniel Borkmann { 9083b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 9093b1efb19SDaniel Borkmann 9103b1efb19SDaniel Borkmann ee = container_of(rcu, struct bpf_event_entry, rcu); 9113b1efb19SDaniel Borkmann fput(ee->perf_file); 9123b1efb19SDaniel Borkmann kfree(ee); 9133b1efb19SDaniel Borkmann } 9143b1efb19SDaniel Borkmann 9153b1efb19SDaniel Borkmann static void bpf_event_entry_free_rcu(struct bpf_event_entry *ee) 9163b1efb19SDaniel Borkmann { 9173b1efb19SDaniel Borkmann call_rcu(&ee->rcu, __bpf_event_entry_free); 918ea317b26SKaixu Xia } 919ea317b26SKaixu Xia 920d056a788SDaniel Borkmann static void *perf_event_fd_array_get_ptr(struct bpf_map *map, 921d056a788SDaniel Borkmann struct file *map_file, int fd) 922ea317b26SKaixu Xia { 9233b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 9243b1efb19SDaniel Borkmann struct perf_event *event; 9253b1efb19SDaniel Borkmann struct file *perf_file; 926f91840a3SAlexei Starovoitov u64 value; 927ea317b26SKaixu Xia 9283b1efb19SDaniel Borkmann perf_file = perf_event_get(fd); 9293b1efb19SDaniel Borkmann if (IS_ERR(perf_file)) 9303b1efb19SDaniel Borkmann return perf_file; 931e03e7ee3SAlexei Starovoitov 932f91840a3SAlexei Starovoitov ee = ERR_PTR(-EOPNOTSUPP); 9333b1efb19SDaniel Borkmann event = perf_file->private_data; 93497562633SYonghong Song if (perf_event_read_local(event, &value, NULL, NULL) == -EOPNOTSUPP) 9353b1efb19SDaniel Borkmann goto err_out; 936ea317b26SKaixu Xia 9373b1efb19SDaniel Borkmann ee = bpf_event_entry_gen(perf_file, map_file); 9383b1efb19SDaniel Borkmann if (ee) 9393b1efb19SDaniel Borkmann return ee; 9403b1efb19SDaniel Borkmann ee = ERR_PTR(-ENOMEM); 9413b1efb19SDaniel Borkmann err_out: 9423b1efb19SDaniel Borkmann fput(perf_file); 9433b1efb19SDaniel Borkmann return ee; 944ea317b26SKaixu Xia } 945ea317b26SKaixu Xia 946ea317b26SKaixu Xia static void perf_event_fd_array_put_ptr(void *ptr) 947ea317b26SKaixu Xia { 9483b1efb19SDaniel Borkmann bpf_event_entry_free_rcu(ptr); 9493b1efb19SDaniel Borkmann } 9503b1efb19SDaniel Borkmann 9513b1efb19SDaniel Borkmann static void perf_event_fd_array_release(struct bpf_map *map, 9523b1efb19SDaniel Borkmann struct file *map_file) 9533b1efb19SDaniel Borkmann { 9543b1efb19SDaniel Borkmann struct bpf_array *array = container_of(map, struct bpf_array, map); 9553b1efb19SDaniel Borkmann struct bpf_event_entry *ee; 9563b1efb19SDaniel Borkmann int i; 9573b1efb19SDaniel Borkmann 9583b1efb19SDaniel Borkmann rcu_read_lock(); 9593b1efb19SDaniel Borkmann for (i = 0; i < array->map.max_entries; i++) { 9603b1efb19SDaniel Borkmann ee = READ_ONCE(array->ptrs[i]); 9613b1efb19SDaniel Borkmann if (ee && ee->map_file == map_file) 9623b1efb19SDaniel Borkmann fd_array_map_delete_elem(map, &i); 9633b1efb19SDaniel Borkmann } 9643b1efb19SDaniel Borkmann rcu_read_unlock(); 965ea317b26SKaixu Xia } 966ea317b26SKaixu Xia 96740077e0cSJohannes Berg const struct bpf_map_ops perf_event_array_map_ops = { 968ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 969ad46061fSJakub Kicinski .map_alloc = array_map_alloc, 9703b1efb19SDaniel Borkmann .map_free = fd_array_map_free, 971ea317b26SKaixu Xia .map_get_next_key = array_map_get_next_key, 972ea317b26SKaixu Xia .map_lookup_elem = fd_array_map_lookup_elem, 973ea317b26SKaixu Xia .map_delete_elem = fd_array_map_delete_elem, 974ea317b26SKaixu Xia .map_fd_get_ptr = perf_event_fd_array_get_ptr, 975ea317b26SKaixu Xia .map_fd_put_ptr = perf_event_fd_array_put_ptr, 9763b1efb19SDaniel Borkmann .map_release = perf_event_fd_array_release, 977e8d2bec0SDaniel Borkmann .map_check_btf = map_check_no_btf, 978ea317b26SKaixu Xia }; 979ea317b26SKaixu Xia 98060d20f91SSargun Dhillon #ifdef CONFIG_CGROUPS 9814ed8ec52SMartin KaFai Lau static void *cgroup_fd_array_get_ptr(struct bpf_map *map, 9824ed8ec52SMartin KaFai Lau struct file *map_file /* not used */, 9834ed8ec52SMartin KaFai Lau int fd) 9844ed8ec52SMartin KaFai Lau { 9854ed8ec52SMartin KaFai Lau return cgroup_get_from_fd(fd); 9864ed8ec52SMartin KaFai Lau } 9874ed8ec52SMartin KaFai Lau 9884ed8ec52SMartin KaFai Lau static void cgroup_fd_array_put_ptr(void *ptr) 9894ed8ec52SMartin KaFai Lau { 9904ed8ec52SMartin KaFai Lau /* cgroup_put free cgrp after a rcu grace period */ 9914ed8ec52SMartin KaFai Lau cgroup_put(ptr); 9924ed8ec52SMartin KaFai Lau } 9934ed8ec52SMartin KaFai Lau 9944ed8ec52SMartin KaFai Lau static void cgroup_fd_array_free(struct bpf_map *map) 9954ed8ec52SMartin KaFai Lau { 9964ed8ec52SMartin KaFai Lau bpf_fd_array_map_clear(map); 9974ed8ec52SMartin KaFai Lau fd_array_map_free(map); 9984ed8ec52SMartin KaFai Lau } 9994ed8ec52SMartin KaFai Lau 100040077e0cSJohannes Berg const struct bpf_map_ops cgroup_array_map_ops = { 1001ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 1002ad46061fSJakub Kicinski .map_alloc = array_map_alloc, 10034ed8ec52SMartin KaFai Lau .map_free = cgroup_fd_array_free, 10044ed8ec52SMartin KaFai Lau .map_get_next_key = array_map_get_next_key, 10054ed8ec52SMartin KaFai Lau .map_lookup_elem = fd_array_map_lookup_elem, 10064ed8ec52SMartin KaFai Lau .map_delete_elem = fd_array_map_delete_elem, 10074ed8ec52SMartin KaFai Lau .map_fd_get_ptr = cgroup_fd_array_get_ptr, 10084ed8ec52SMartin KaFai Lau .map_fd_put_ptr = cgroup_fd_array_put_ptr, 1009e8d2bec0SDaniel Borkmann .map_check_btf = map_check_no_btf, 10104ed8ec52SMartin KaFai Lau }; 10114ed8ec52SMartin KaFai Lau #endif 101256f668dfSMartin KaFai Lau 101356f668dfSMartin KaFai Lau static struct bpf_map *array_of_map_alloc(union bpf_attr *attr) 101456f668dfSMartin KaFai Lau { 101556f668dfSMartin KaFai Lau struct bpf_map *map, *inner_map_meta; 101656f668dfSMartin KaFai Lau 101756f668dfSMartin KaFai Lau inner_map_meta = bpf_map_meta_alloc(attr->inner_map_fd); 101856f668dfSMartin KaFai Lau if (IS_ERR(inner_map_meta)) 101956f668dfSMartin KaFai Lau return inner_map_meta; 102056f668dfSMartin KaFai Lau 1021ad46061fSJakub Kicinski map = array_map_alloc(attr); 102256f668dfSMartin KaFai Lau if (IS_ERR(map)) { 102356f668dfSMartin KaFai Lau bpf_map_meta_free(inner_map_meta); 102456f668dfSMartin KaFai Lau return map; 102556f668dfSMartin KaFai Lau } 102656f668dfSMartin KaFai Lau 102756f668dfSMartin KaFai Lau map->inner_map_meta = inner_map_meta; 102856f668dfSMartin KaFai Lau 102956f668dfSMartin KaFai Lau return map; 103056f668dfSMartin KaFai Lau } 103156f668dfSMartin KaFai Lau 103256f668dfSMartin KaFai Lau static void array_of_map_free(struct bpf_map *map) 103356f668dfSMartin KaFai Lau { 103456f668dfSMartin KaFai Lau /* map->inner_map_meta is only accessed by syscall which 103556f668dfSMartin KaFai Lau * is protected by fdget/fdput. 103656f668dfSMartin KaFai Lau */ 103756f668dfSMartin KaFai Lau bpf_map_meta_free(map->inner_map_meta); 103856f668dfSMartin KaFai Lau bpf_fd_array_map_clear(map); 103956f668dfSMartin KaFai Lau fd_array_map_free(map); 104056f668dfSMartin KaFai Lau } 104156f668dfSMartin KaFai Lau 104256f668dfSMartin KaFai Lau static void *array_of_map_lookup_elem(struct bpf_map *map, void *key) 104356f668dfSMartin KaFai Lau { 104456f668dfSMartin KaFai Lau struct bpf_map **inner_map = array_map_lookup_elem(map, key); 104556f668dfSMartin KaFai Lau 104656f668dfSMartin KaFai Lau if (!inner_map) 104756f668dfSMartin KaFai Lau return NULL; 104856f668dfSMartin KaFai Lau 104956f668dfSMartin KaFai Lau return READ_ONCE(*inner_map); 105056f668dfSMartin KaFai Lau } 105156f668dfSMartin KaFai Lau 10527b0c2a05SDaniel Borkmann static u32 array_of_map_gen_lookup(struct bpf_map *map, 10537b0c2a05SDaniel Borkmann struct bpf_insn *insn_buf) 10547b0c2a05SDaniel Borkmann { 1055b2157399SAlexei Starovoitov struct bpf_array *array = container_of(map, struct bpf_array, map); 10567b0c2a05SDaniel Borkmann u32 elem_size = round_up(map->value_size, 8); 10577b0c2a05SDaniel Borkmann struct bpf_insn *insn = insn_buf; 10587b0c2a05SDaniel Borkmann const int ret = BPF_REG_0; 10597b0c2a05SDaniel Borkmann const int map_ptr = BPF_REG_1; 10607b0c2a05SDaniel Borkmann const int index = BPF_REG_2; 10617b0c2a05SDaniel Borkmann 10627b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_IMM(BPF_ADD, map_ptr, offsetof(struct bpf_array, value)); 10637b0c2a05SDaniel Borkmann *insn++ = BPF_LDX_MEM(BPF_W, ret, index, 0); 1064b2157399SAlexei Starovoitov if (map->unpriv_array) { 1065b2157399SAlexei Starovoitov *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 6); 1066b2157399SAlexei Starovoitov *insn++ = BPF_ALU32_IMM(BPF_AND, ret, array->index_mask); 1067b2157399SAlexei Starovoitov } else { 10687b0c2a05SDaniel Borkmann *insn++ = BPF_JMP_IMM(BPF_JGE, ret, map->max_entries, 5); 1069b2157399SAlexei Starovoitov } 10707b0c2a05SDaniel Borkmann if (is_power_of_2(elem_size)) 10717b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_IMM(BPF_LSH, ret, ilog2(elem_size)); 10727b0c2a05SDaniel Borkmann else 10737b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_IMM(BPF_MUL, ret, elem_size); 10747b0c2a05SDaniel Borkmann *insn++ = BPF_ALU64_REG(BPF_ADD, ret, map_ptr); 10757b0c2a05SDaniel Borkmann *insn++ = BPF_LDX_MEM(BPF_DW, ret, ret, 0); 10767b0c2a05SDaniel Borkmann *insn++ = BPF_JMP_IMM(BPF_JEQ, ret, 0, 1); 10777b0c2a05SDaniel Borkmann *insn++ = BPF_JMP_IMM(BPF_JA, 0, 0, 1); 10787b0c2a05SDaniel Borkmann *insn++ = BPF_MOV64_IMM(ret, 0); 10797b0c2a05SDaniel Borkmann 10807b0c2a05SDaniel Borkmann return insn - insn_buf; 10817b0c2a05SDaniel Borkmann } 10827b0c2a05SDaniel Borkmann 108340077e0cSJohannes Berg const struct bpf_map_ops array_of_maps_map_ops = { 1084ad46061fSJakub Kicinski .map_alloc_check = fd_array_map_alloc_check, 108556f668dfSMartin KaFai Lau .map_alloc = array_of_map_alloc, 108656f668dfSMartin KaFai Lau .map_free = array_of_map_free, 108756f668dfSMartin KaFai Lau .map_get_next_key = array_map_get_next_key, 108856f668dfSMartin KaFai Lau .map_lookup_elem = array_of_map_lookup_elem, 108956f668dfSMartin KaFai Lau .map_delete_elem = fd_array_map_delete_elem, 109056f668dfSMartin KaFai Lau .map_fd_get_ptr = bpf_map_fd_get_ptr, 109156f668dfSMartin KaFai Lau .map_fd_put_ptr = bpf_map_fd_put_ptr, 109214dc6f04SMartin KaFai Lau .map_fd_sys_lookup_elem = bpf_map_fd_sys_lookup_elem, 10937b0c2a05SDaniel Borkmann .map_gen_lookup = array_of_map_gen_lookup, 1094e8d2bec0SDaniel Borkmann .map_check_btf = map_check_no_btf, 109556f668dfSMartin KaFai Lau }; 1096