Skip to content

Commit 95da0cd

Browse files
palmtenorborkmann
authored andcommitted
bpf: add support to read sample address in bpf program
This commit adds new field "addr" to bpf_perf_event_data which could be read and used by bpf programs attached to perf events. The value of the field is copied from bpf_perf_event_data_kern.addr and contains the address value recorded by specifying sample_type with PERF_SAMPLE_ADDR when calling perf_event_open. Signed-off-by: Teng Qin <[email protected]> Signed-off-by: Daniel Borkmann <[email protected]>
1 parent a366e30 commit 95da0cd

File tree

2 files changed

+17
-4
lines changed

2 files changed

+17
-4
lines changed

include/uapi/linux/bpf_perf_event.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@
1313
struct bpf_perf_event_data {
1414
bpf_user_pt_regs_t regs;
1515
__u64 sample_period;
16+
__u64 addr;
1617
};
1718

1819
#endif /* _UAPI__LINUX_BPF_PERF_EVENT_H__ */

kernel/trace/bpf_trace.c

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -726,8 +726,7 @@ const struct bpf_prog_ops tracepoint_prog_ops = {
726726
static bool pe_prog_is_valid_access(int off, int size, enum bpf_access_type type,
727727
struct bpf_insn_access_aux *info)
728728
{
729-
const int size_sp = FIELD_SIZEOF(struct bpf_perf_event_data,
730-
sample_period);
729+
const int size_u64 = sizeof(u64);
731730

732731
if (off < 0 || off >= sizeof(struct bpf_perf_event_data))
733732
return false;
@@ -738,8 +737,13 @@ static bool pe_prog_is_valid_access(int off, int size, enum bpf_access_type type
738737

739738
switch (off) {
740739
case bpf_ctx_range(struct bpf_perf_event_data, sample_period):
741-
bpf_ctx_record_field_size(info, size_sp);
742-
if (!bpf_ctx_narrow_access_ok(off, size, size_sp))
740+
bpf_ctx_record_field_size(info, size_u64);
741+
if (!bpf_ctx_narrow_access_ok(off, size, size_u64))
742+
return false;
743+
break;
744+
case bpf_ctx_range(struct bpf_perf_event_data, addr):
745+
bpf_ctx_record_field_size(info, size_u64);
746+
if (!bpf_ctx_narrow_access_ok(off, size, size_u64))
743747
return false;
744748
break;
745749
default:
@@ -766,6 +770,14 @@ static u32 pe_prog_convert_ctx_access(enum bpf_access_type type,
766770
bpf_target_off(struct perf_sample_data, period, 8,
767771
target_size));
768772
break;
773+
case offsetof(struct bpf_perf_event_data, addr):
774+
*insn++ = BPF_LDX_MEM(BPF_FIELD_SIZEOF(struct bpf_perf_event_data_kern,
775+
data), si->dst_reg, si->src_reg,
776+
offsetof(struct bpf_perf_event_data_kern, data));
777+
*insn++ = BPF_LDX_MEM(BPF_DW, si->dst_reg, si->dst_reg,
778+
bpf_target_off(struct perf_sample_data, addr, 8,
779+
target_size));
780+
break;
769781
default:
770782
*insn++ = BPF_LDX_MEM(BPF_FIELD_SIZEOF(struct bpf_perf_event_data_kern,
771783
regs), si->dst_reg, si->src_reg,

0 commit comments

Comments
 (0)