2 * Decoder of classic BPF programs.
4 * Copyright (c) 2015-2017 Dmitry V. Levin <ldv@altlinux.org>
5 * Copyright (c) 2017-2018 The strace developers.
8 * SPDX-License-Identifier: LGPL-2.1-or-later
13 #include "bpf_filter.h"
14 #include "bpf_fprog.h"
16 #include <linux/filter.h>
18 #include "xlat/bpf_class.h"
19 #include "xlat/bpf_miscop.h"
20 #include "xlat/bpf_mode.h"
21 #include "xlat/bpf_op_alu.h"
22 #include "xlat/bpf_op_jmp.h"
23 #include "xlat/bpf_rval.h"
24 #include "xlat/bpf_size.h"
25 #include "xlat/bpf_src.h"
27 #include "xlat/ebpf_class.h"
28 #include "xlat/ebpf_mode.h"
29 #include "xlat/ebpf_op_alu.h"
30 #include "xlat/ebpf_op_jmp.h"
31 #include "xlat/ebpf_size.h"
34 print_bpf_filter_code(const uint16_t code, bool extended)
36 const struct xlat *mode = extended ? ebpf_mode : bpf_mode;
37 uint16_t i = code & ~BPF_CLASS(code);
39 printxval(extended ? ebpf_class : bpf_class, BPF_CLASS(code),
41 switch (BPF_CLASS(code)) {
47 tprints_comment("BPF_???");
51 ATTRIBUTE_FALLTHROUGH; /* extended == true */
56 printxvals(BPF_SIZE(code), "BPF_???",
57 bpf_size, extended ? ebpf_size : NULL, NULL);
59 printxval(mode, BPF_MODE(code), "BPF_???");
62 case BPF_MISC: /* BPF_ALU64 in eBPF */
65 printxval(bpf_miscop, BPF_MISCOP(code), "BPF_???");
66 i &= ~BPF_MISCOP(code);
69 tprints_comment("BPF_???");
73 ATTRIBUTE_FALLTHROUGH; /* extended == true */
77 printxval(bpf_src, BPF_SRC(code), "BPF_???");
79 printxvals(BPF_OP(code), "BPF_???",
81 extended ? ebpf_op_alu : NULL, NULL);
86 printxval(bpf_src, BPF_SRC(code), "BPF_???");
88 printxvals(BPF_OP(code), "BPF_???",
89 bpf_op_jmp, extended ? ebpf_op_jmp : NULL, NULL);
92 case BPF_RET: /* Reserved in eBPF */
95 printxval(bpf_rval, BPF_RVAL(code), "BPF_???");
101 tprints_comment("BPF_???");
109 print_bpf_filter_stmt(const struct bpf_filter_block *const filter,
110 const print_bpf_filter_fn print_k)
112 tprints("BPF_STMT(");
113 print_bpf_filter_code(filter->code, false);
115 if (!print_k || !print_k(filter))
116 tprintf("%#x", filter->k);
121 print_bpf_filter_jump(const struct bpf_filter_block *const filter)
123 tprints("BPF_JUMP(");
124 print_bpf_filter_code(filter->code, false);
125 tprintf(", %#x, %#x, %#x)", filter->k, filter->jt, filter->jf);
128 struct bpf_filter_block_data {
129 const print_bpf_filter_fn fn;
134 print_bpf_filter_block(struct tcb *const tcp, void *const elem_buf,
135 const size_t elem_size, void *const data)
137 const struct bpf_filter_block *const filter = elem_buf;
138 struct bpf_filter_block_data *const fbd = data;
140 if (fbd->count++ >= BPF_MAXINSNS) {
145 if (filter->jt || filter->jf)
146 print_bpf_filter_jump(filter);
148 print_bpf_filter_stmt(filter, fbd->fn);
154 print_bpf_fprog(struct tcb *const tcp, const kernel_ulong_t addr,
155 const unsigned short len, const print_bpf_filter_fn print_k)
160 struct bpf_filter_block_data fbd = { .fn = print_k };
161 struct bpf_filter_block filter;
163 print_array(tcp, addr, len, &filter, sizeof(filter),
164 tfetch_mem, print_bpf_filter_block, &fbd);
169 decode_bpf_fprog(struct tcb *const tcp, const kernel_ulong_t addr,
170 const print_bpf_filter_fn print_k)
172 struct bpf_fprog fprog;
174 if (fetch_bpf_fprog(tcp, addr, &fprog)) {
175 tprintf("{len=%hu, filter=", fprog.len);
176 print_bpf_fprog(tcp, fprog.filter, fprog.len, print_k);