samples: bpf: trivial eBPF program in C
this example does the same task as previous socket example in assembler, but this one does it in C. eBPF program in kernel does: /* assume that packet is IPv4, load one byte of IP->proto */ int index = load_byte(skb, ETH_HLEN + offsetof(struct iphdr, protocol)); long *value; value = bpf_map_lookup_elem(&my_map, &index); if (value) __sync_fetch_and_add(value, 1); Corresponding user space reads map[tcp], map[udp], map[icmp] and prints protocol stats every second Signed-off-by: Alexei Starovoitov <ast@plumgrid.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
Родитель
249b812d80
Коммит
a80857822b
|
@ -4,12 +4,26 @@ obj- := dummy.o
|
||||||
# List of programs to build
|
# List of programs to build
|
||||||
hostprogs-y := test_verifier test_maps
|
hostprogs-y := test_verifier test_maps
|
||||||
hostprogs-y += sock_example
|
hostprogs-y += sock_example
|
||||||
|
hostprogs-y += sockex1
|
||||||
|
|
||||||
test_verifier-objs := test_verifier.o libbpf.o
|
test_verifier-objs := test_verifier.o libbpf.o
|
||||||
test_maps-objs := test_maps.o libbpf.o
|
test_maps-objs := test_maps.o libbpf.o
|
||||||
sock_example-objs := sock_example.o libbpf.o
|
sock_example-objs := sock_example.o libbpf.o
|
||||||
|
sockex1-objs := bpf_load.o libbpf.o sockex1_user.o
|
||||||
|
|
||||||
# Tell kbuild to always build the programs
|
# Tell kbuild to always build the programs
|
||||||
always := $(hostprogs-y)
|
always := $(hostprogs-y)
|
||||||
|
always += sockex1_kern.o
|
||||||
|
|
||||||
HOSTCFLAGS += -I$(objtree)/usr/include
|
HOSTCFLAGS += -I$(objtree)/usr/include
|
||||||
|
|
||||||
|
HOSTCFLAGS_bpf_load.o += -I$(objtree)/usr/include -Wno-unused-variable
|
||||||
|
HOSTLOADLIBES_sockex1 += -lelf
|
||||||
|
|
||||||
|
# point this to your LLVM backend with bpf support
|
||||||
|
LLC=$(srctree)/tools/bpf/llvm/bld/Debug+Asserts/bin/llc
|
||||||
|
|
||||||
|
%.o: %.c
|
||||||
|
clang $(NOSTDINC_FLAGS) $(LINUXINCLUDE) $(EXTRA_CFLAGS) \
|
||||||
|
-D__KERNEL__ -Wno-unused-value -Wno-pointer-sign \
|
||||||
|
-O2 -emit-llvm -c $< -o -| $(LLC) -march=bpf -filetype=obj -o $@
|
||||||
|
|
|
@ -15,7 +15,7 @@ int bpf_prog_load(enum bpf_prog_type prog_type,
|
||||||
const struct bpf_insn *insns, int insn_len,
|
const struct bpf_insn *insns, int insn_len,
|
||||||
const char *license);
|
const char *license);
|
||||||
|
|
||||||
#define LOG_BUF_SIZE 8192
|
#define LOG_BUF_SIZE 65536
|
||||||
extern char bpf_log_buf[LOG_BUF_SIZE];
|
extern char bpf_log_buf[LOG_BUF_SIZE];
|
||||||
|
|
||||||
/* ALU ops on registers, bpf_add|sub|...: dst_reg += src_reg */
|
/* ALU ops on registers, bpf_add|sub|...: dst_reg += src_reg */
|
||||||
|
|
|
@ -0,0 +1,25 @@
|
||||||
|
#include <uapi/linux/bpf.h>
|
||||||
|
#include <uapi/linux/if_ether.h>
|
||||||
|
#include <uapi/linux/ip.h>
|
||||||
|
#include "bpf_helpers.h"
|
||||||
|
|
||||||
|
struct bpf_map_def SEC("maps") my_map = {
|
||||||
|
.type = BPF_MAP_TYPE_ARRAY,
|
||||||
|
.key_size = sizeof(u32),
|
||||||
|
.value_size = sizeof(long),
|
||||||
|
.max_entries = 256,
|
||||||
|
};
|
||||||
|
|
||||||
|
SEC("socket1")
|
||||||
|
int bpf_prog1(struct sk_buff *skb)
|
||||||
|
{
|
||||||
|
int index = load_byte(skb, ETH_HLEN + offsetof(struct iphdr, protocol));
|
||||||
|
long *value;
|
||||||
|
|
||||||
|
value = bpf_map_lookup_elem(&my_map, &index);
|
||||||
|
if (value)
|
||||||
|
__sync_fetch_and_add(value, 1);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
char _license[] SEC("license") = "GPL";
|
|
@ -0,0 +1,49 @@
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <assert.h>
|
||||||
|
#include <linux/bpf.h>
|
||||||
|
#include "libbpf.h"
|
||||||
|
#include "bpf_load.h"
|
||||||
|
#include <unistd.h>
|
||||||
|
#include <arpa/inet.h>
|
||||||
|
|
||||||
|
int main(int ac, char **argv)
|
||||||
|
{
|
||||||
|
char filename[256];
|
||||||
|
FILE *f;
|
||||||
|
int i, sock;
|
||||||
|
|
||||||
|
snprintf(filename, sizeof(filename), "%s_kern.o", argv[0]);
|
||||||
|
|
||||||
|
if (load_bpf_file(filename)) {
|
||||||
|
printf("%s", bpf_log_buf);
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
sock = open_raw_sock("lo");
|
||||||
|
|
||||||
|
assert(setsockopt(sock, SOL_SOCKET, SO_ATTACH_BPF, prog_fd,
|
||||||
|
sizeof(prog_fd[0])) == 0);
|
||||||
|
|
||||||
|
f = popen("ping -c5 localhost", "r");
|
||||||
|
(void) f;
|
||||||
|
|
||||||
|
for (i = 0; i < 5; i++) {
|
||||||
|
long long tcp_cnt, udp_cnt, icmp_cnt;
|
||||||
|
int key;
|
||||||
|
|
||||||
|
key = IPPROTO_TCP;
|
||||||
|
assert(bpf_lookup_elem(map_fd[0], &key, &tcp_cnt) == 0);
|
||||||
|
|
||||||
|
key = IPPROTO_UDP;
|
||||||
|
assert(bpf_lookup_elem(map_fd[0], &key, &udp_cnt) == 0);
|
||||||
|
|
||||||
|
key = IPPROTO_ICMP;
|
||||||
|
assert(bpf_lookup_elem(map_fd[0], &key, &icmp_cnt) == 0);
|
||||||
|
|
||||||
|
printf("TCP %lld UDP %lld ICMP %lld packets\n",
|
||||||
|
tcp_cnt, udp_cnt, icmp_cnt);
|
||||||
|
sleep(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
Загрузка…
Ссылка в новой задаче