diff options
| author | Martin KaFai Lau <kafai@fb.com> | 2016-06-30 13:28:45 -0400 |
|---|---|---|
| committer | David S. Miller <davem@davemloft.net> | 2016-07-01 16:32:13 -0400 |
| commit | a3f74617340b598dbc7eb5b68d4ed53b4a70f5eb (patch) | |
| tree | ce74217c60eeda9e99a8b5e2babcf0847ab3b24f /samples | |
| parent | 4a482f34afcc162d8456f449b137ec2a95be60d8 (diff) | |
cgroup: bpf: Add an example to do cgroup checking in BPF
test_cgrp2_array_pin.c:
A userland program that creates a bpf_map (BPF_MAP_TYPE_GROUP_ARRAY),
pouplates/updates it with a cgroup2's backed fd and pins it to a
bpf-fs's file. The pinned file can be loaded by tc and then used
by the bpf prog later. This program can also update an existing pinned
array and it could be useful for debugging/testing purpose.
test_cgrp2_tc_kern.c:
A bpf prog which should be loaded by tc. It is to demonstrate
the usage of bpf_skb_in_cgroup.
test_cgrp2_tc.sh:
A script that glues the test_cgrp2_array_pin.c and
test_cgrp2_tc_kern.c together. The idea is like:
1. Load the test_cgrp2_tc_kern.o by tc
2. Use test_cgrp2_array_pin.c to populate a BPF_MAP_TYPE_CGROUP_ARRAY
with a cgroup fd
3. Do a 'ping -6 ff02::1%ve' to ensure the packet has been
dropped because of a match on the cgroup
Most of the lines in test_cgrp2_tc.sh is the boilerplate
to setup the cgroup/bpf-fs/net-devices/netns...etc. It is
not bulletproof on errors but should work well enough and
give enough debug info if things did not go well.
Signed-off-by: Martin KaFai Lau <kafai@fb.com>
Cc: Alexei Starovoitov <ast@fb.com>
Cc: Daniel Borkmann <daniel@iogearbox.net>
Cc: Tejun Heo <tj@kernel.org>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'samples')
| -rw-r--r-- | samples/bpf/Makefile | 3 | ||||
| -rw-r--r-- | samples/bpf/bpf_helpers.h | 2 | ||||
| -rw-r--r-- | samples/bpf/test_cgrp2_array_pin.c | 109 | ||||
| -rwxr-xr-x | samples/bpf/test_cgrp2_tc.sh | 184 | ||||
| -rw-r--r-- | samples/bpf/test_cgrp2_tc_kern.c | 69 |
5 files changed, 367 insertions, 0 deletions
diff --git a/samples/bpf/Makefile b/samples/bpf/Makefile index 0bf2478cb7df..a98b780e974c 100644 --- a/samples/bpf/Makefile +++ b/samples/bpf/Makefile | |||
| @@ -20,6 +20,7 @@ hostprogs-y += offwaketime | |||
| 20 | hostprogs-y += spintest | 20 | hostprogs-y += spintest |
| 21 | hostprogs-y += map_perf_test | 21 | hostprogs-y += map_perf_test |
| 22 | hostprogs-y += test_overhead | 22 | hostprogs-y += test_overhead |
| 23 | hostprogs-y += test_cgrp2_array_pin | ||
| 23 | 24 | ||
| 24 | test_verifier-objs := test_verifier.o libbpf.o | 25 | test_verifier-objs := test_verifier.o libbpf.o |
| 25 | test_maps-objs := test_maps.o libbpf.o | 26 | test_maps-objs := test_maps.o libbpf.o |
| @@ -40,6 +41,7 @@ offwaketime-objs := bpf_load.o libbpf.o offwaketime_user.o | |||
| 40 | spintest-objs := bpf_load.o libbpf.o spintest_user.o | 41 | spintest-objs := bpf_load.o libbpf.o spintest_user.o |
| 41 | map_perf_test-objs := bpf_load.o libbpf.o map_perf_test_user.o | 42 | map_perf_test-objs := bpf_load.o libbpf.o map_perf_test_user.o |
| 42 | test_overhead-objs := bpf_load.o libbpf.o test_overhead_user.o | 43 | test_overhead-objs := bpf_load.o libbpf.o test_overhead_user.o |
| 44 | test_cgrp2_array_pin-objs := libbpf.o test_cgrp2_array_pin.o | ||
| 43 | 45 | ||
| 44 | # Tell kbuild to always build the programs | 46 | # Tell kbuild to always build the programs |
| 45 | always := $(hostprogs-y) | 47 | always := $(hostprogs-y) |
| @@ -61,6 +63,7 @@ always += map_perf_test_kern.o | |||
| 61 | always += test_overhead_tp_kern.o | 63 | always += test_overhead_tp_kern.o |
| 62 | always += test_overhead_kprobe_kern.o | 64 | always += test_overhead_kprobe_kern.o |
| 63 | always += parse_varlen.o parse_simple.o parse_ldabs.o | 65 | always += parse_varlen.o parse_simple.o parse_ldabs.o |
| 66 | always += test_cgrp2_tc_kern.o | ||
| 64 | 67 | ||
| 65 | HOSTCFLAGS += -I$(objtree)/usr/include | 68 | HOSTCFLAGS += -I$(objtree)/usr/include |
| 66 | 69 | ||
diff --git a/samples/bpf/bpf_helpers.h b/samples/bpf/bpf_helpers.h index 7904a2a493de..84e3fd919a06 100644 --- a/samples/bpf/bpf_helpers.h +++ b/samples/bpf/bpf_helpers.h | |||
| @@ -70,6 +70,8 @@ static int (*bpf_l3_csum_replace)(void *ctx, int off, int from, int to, int flag | |||
| 70 | (void *) BPF_FUNC_l3_csum_replace; | 70 | (void *) BPF_FUNC_l3_csum_replace; |
| 71 | static int (*bpf_l4_csum_replace)(void *ctx, int off, int from, int to, int flags) = | 71 | static int (*bpf_l4_csum_replace)(void *ctx, int off, int from, int to, int flags) = |
| 72 | (void *) BPF_FUNC_l4_csum_replace; | 72 | (void *) BPF_FUNC_l4_csum_replace; |
| 73 | static int (*bpf_skb_in_cgroup)(void *ctx, void *map, int index) = | ||
| 74 | (void *) BPF_FUNC_skb_in_cgroup; | ||
| 73 | 75 | ||
| 74 | #if defined(__x86_64__) | 76 | #if defined(__x86_64__) |
| 75 | 77 | ||
diff --git a/samples/bpf/test_cgrp2_array_pin.c b/samples/bpf/test_cgrp2_array_pin.c new file mode 100644 index 000000000000..70e86f7be69d --- /dev/null +++ b/samples/bpf/test_cgrp2_array_pin.c | |||
| @@ -0,0 +1,109 @@ | |||
| 1 | /* Copyright (c) 2016 Facebook | ||
| 2 | * | ||
| 3 | * This program is free software; you can redistribute it and/or | ||
| 4 | * modify it under the terms of version 2 of the GNU General Public | ||
| 5 | * License as published by the Free Software Foundation. | ||
| 6 | */ | ||
| 7 | #include <linux/unistd.h> | ||
| 8 | #include <linux/bpf.h> | ||
| 9 | |||
| 10 | #include <stdio.h> | ||
| 11 | #include <stdint.h> | ||
| 12 | #include <unistd.h> | ||
| 13 | #include <string.h> | ||
| 14 | #include <errno.h> | ||
| 15 | #include <fcntl.h> | ||
| 16 | |||
| 17 | #include "libbpf.h" | ||
| 18 | |||
| 19 | static void usage(void) | ||
| 20 | { | ||
| 21 | printf("Usage: test_cgrp2_array_pin [...]\n"); | ||
| 22 | printf(" -F <file> File to pin an BPF cgroup array\n"); | ||
| 23 | printf(" -U <file> Update an already pinned BPF cgroup array\n"); | ||
| 24 | printf(" -v <value> Full path of the cgroup2\n"); | ||
| 25 | printf(" -h Display this help\n"); | ||
| 26 | } | ||
| 27 | |||
| 28 | int main(int argc, char **argv) | ||
| 29 | { | ||
| 30 | const char *pinned_file = NULL, *cg2 = NULL; | ||
| 31 | int create_array = 1; | ||
| 32 | int array_key = 0; | ||
| 33 | int array_fd = -1; | ||
| 34 | int cg2_fd = -1; | ||
| 35 | int ret = -1; | ||
| 36 | int opt; | ||
| 37 | |||
| 38 | while ((opt = getopt(argc, argv, "F:U:v:")) != -1) { | ||
| 39 | switch (opt) { | ||
| 40 | /* General args */ | ||
| 41 | case 'F': | ||
| 42 | pinned_file = optarg; | ||
| 43 | break; | ||
| 44 | case 'U': | ||
| 45 | pinned_file = optarg; | ||
| 46 | create_array = 0; | ||
| 47 | break; | ||
| 48 | case 'v': | ||
| 49 | cg2 = optarg; | ||
| 50 | break; | ||
| 51 | default: | ||
| 52 | usage(); | ||
| 53 | goto out; | ||
| 54 | } | ||
| 55 | } | ||
| 56 | |||
| 57 | if (!cg2 || !pinned_file) { | ||
| 58 | usage(); | ||
| 59 | goto out; | ||
| 60 | } | ||
| 61 | |||
| 62 | cg2_fd = open(cg2, O_RDONLY); | ||
| 63 | if (cg2_fd < 0) { | ||
| 64 | fprintf(stderr, "open(%s,...): %s(%d)\n", | ||
| 65 | cg2, strerror(errno), errno); | ||
| 66 | goto out; | ||
| 67 | } | ||
| 68 | |||
| 69 | if (create_array) { | ||
| 70 | array_fd = bpf_create_map(BPF_MAP_TYPE_CGROUP_ARRAY, | ||
| 71 | sizeof(uint32_t), sizeof(uint32_t), | ||
| 72 | 1, 0); | ||
| 73 | if (array_fd < 0) { | ||
| 74 | fprintf(stderr, | ||
| 75 | "bpf_create_map(BPF_MAP_TYPE_CGROUP_ARRAY,...): %s(%d)\n", | ||
| 76 | strerror(errno), errno); | ||
| 77 | goto out; | ||
| 78 | } | ||
| 79 | } else { | ||
| 80 | array_fd = bpf_obj_get(pinned_file); | ||
| 81 | if (array_fd < 0) { | ||
| 82 | fprintf(stderr, "bpf_obj_get(%s): %s(%d)\n", | ||
| 83 | pinned_file, strerror(errno), errno); | ||
| 84 | goto out; | ||
| 85 | } | ||
| 86 | } | ||
| 87 | |||
| 88 | ret = bpf_update_elem(array_fd, &array_key, &cg2_fd, 0); | ||
| 89 | if (ret) { | ||
| 90 | perror("bpf_update_elem"); | ||
| 91 | goto out; | ||
| 92 | } | ||
| 93 | |||
| 94 | if (create_array) { | ||
| 95 | ret = bpf_obj_pin(array_fd, pinned_file); | ||
| 96 | if (ret) { | ||
| 97 | fprintf(stderr, "bpf_obj_pin(..., %s): %s(%d)\n", | ||
| 98 | pinned_file, strerror(errno), errno); | ||
| 99 | goto out; | ||
| 100 | } | ||
| 101 | } | ||
| 102 | |||
| 103 | out: | ||
| 104 | if (array_fd != -1) | ||
| 105 | close(array_fd); | ||
| 106 | if (cg2_fd != -1) | ||
| 107 | close(cg2_fd); | ||
| 108 | return ret; | ||
| 109 | } | ||
diff --git a/samples/bpf/test_cgrp2_tc.sh b/samples/bpf/test_cgrp2_tc.sh new file mode 100755 index 000000000000..0b119eeaf85c --- /dev/null +++ b/samples/bpf/test_cgrp2_tc.sh | |||
| @@ -0,0 +1,184 @@ | |||
| 1 | #!/bin/bash | ||
| 2 | |||
| 3 | MY_DIR=$(dirname $0) | ||
| 4 | # Details on the bpf prog | ||
| 5 | BPF_CGRP2_ARRAY_NAME='test_cgrp2_array_pin' | ||
| 6 | BPF_PROG="$MY_DIR/test_cgrp2_tc_kern.o" | ||
| 7 | BPF_SECTION='filter' | ||
| 8 | |||
| 9 | [ -z "$TC" ] && TC='tc' | ||
| 10 | [ -z "$IP" ] && IP='ip' | ||
| 11 | |||
| 12 | # Names of the veth interface, net namespace...etc. | ||
| 13 | HOST_IFC='ve' | ||
| 14 | NS_IFC='vens' | ||
| 15 | NS='ns' | ||
| 16 | |||
| 17 | find_mnt() { | ||
| 18 | cat /proc/mounts | \ | ||
| 19 | awk '{ if ($3 == "'$1'" && mnt == "") { mnt = $2 }} END { print mnt }' | ||
| 20 | } | ||
| 21 | |||
| 22 | # Init cgroup2 vars | ||
| 23 | init_cgrp2_vars() { | ||
| 24 | CGRP2_ROOT=$(find_mnt cgroup2) | ||
| 25 | if [ -z "$CGRP2_ROOT" ] | ||
| 26 | then | ||
| 27 | CGRP2_ROOT='/mnt/cgroup2' | ||
| 28 | MOUNT_CGRP2="yes" | ||
| 29 | fi | ||
| 30 | CGRP2_TC="$CGRP2_ROOT/tc" | ||
| 31 | CGRP2_TC_LEAF="$CGRP2_TC/leaf" | ||
| 32 | } | ||
| 33 | |||
| 34 | # Init bpf fs vars | ||
| 35 | init_bpf_fs_vars() { | ||
| 36 | local bpf_fs_root=$(find_mnt bpf) | ||
| 37 | [ -n "$bpf_fs_root" ] || return -1 | ||
| 38 | BPF_FS_TC_SHARE="$bpf_fs_root/tc/globals" | ||
| 39 | } | ||
| 40 | |||
| 41 | setup_cgrp2() { | ||
