A dynamic tracer for Linux

ir.c 5.6KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307
  1. #include <assert.h>
  2. #include <inttypes.h>
  3. #include <stdio.h>
  4. #include <string.h>
  5. #include <linux/bpf.h>
  6. #include "ir.h"
  7. const uint16_t vreg_base = 0x8000;
  8. static const char *bpf_func_name(enum bpf_func_id id)
  9. {
  10. switch (id) {
  11. case BPF_FUNC_get_current_comm:
  12. return "get_current_comm";
  13. case BPF_FUNC_get_current_pid_tgid:
  14. return "get_current_pid_tgid";
  15. case BPF_FUNC_get_current_uid_gid:
  16. return "get_current_uid_gid";
  17. case BPF_FUNC_get_stackid:
  18. return "get_stackid";
  19. case BPF_FUNC_ktime_get_ns:
  20. return "ktime_get_ns";
  21. case BPF_FUNC_map_delete_elem:
  22. return "map_delete_elem";
  23. case BPF_FUNC_map_lookup_elem:
  24. return "map_lookup_elem";
  25. case BPF_FUNC_map_update_elem:
  26. return "map_update_elem";
  27. case BPF_FUNC_perf_event_output:
  28. return "perf_event_output";
  29. case BPF_FUNC_probe_read:
  30. return "probe_read";
  31. case BPF_FUNC_trace_printk:
  32. return "trace_printk";
  33. default:
  34. return NULL;
  35. }
  36. }
  37. static void reg_name(uint16_t reg, char *name)
  38. {
  39. if (reg & vreg_base) {
  40. sprintf(name, "v%u", reg & ~vreg_base);
  41. } else if (reg == BPF_REG_10) {
  42. strcpy(name, "bp");
  43. } else {
  44. sprintf(name, "r%u", reg);
  45. }
  46. }
  47. static void reg_dump(uint16_t reg, int16_t off, FILE *fp)
  48. {
  49. char name[8];
  50. reg_name(reg, name);
  51. if (off < 0)
  52. fprintf(fp, "[%s - 0x%x]", name, -off);
  53. else if (off > 0)
  54. fprintf(fp, "[%s + 0x%x]", name, off);
  55. else
  56. fprintf(fp, "%s", name);
  57. }
  58. static char size_name(uint8_t code)
  59. {
  60. switch (BPF_SIZE(code)) {
  61. case BPF_B: return 'b';
  62. case BPF_H: return 'h';
  63. case BPF_W: return 'w';
  64. case BPF_DW: return 'q';
  65. }
  66. return '?';
  67. }
  68. static void alu_dump(uint8_t code, FILE *fp)
  69. {
  70. switch (BPF_OP(code)) {
  71. case BPF_MOV: fputs("mov", fp); break;
  72. case BPF_ADD: fputs("add", fp); break;
  73. case BPF_SUB: fputs("sub", fp); break;
  74. case BPF_MUL: fputs("mul", fp); break;
  75. case BPF_DIV: fputs("div", fp); break;
  76. case BPF_OR : fputs("or", fp); break;
  77. case BPF_AND: fputs("and", fp); break;
  78. case BPF_LSH: fputs("lsh", fp); break;
  79. case BPF_RSH: fputs("rsh", fp); break;
  80. case BPF_NEG: fputs("neg", fp); break;
  81. case BPF_MOD: fputs("mod", fp); break;
  82. case BPF_XOR: fputs("xor", fp); break;
  83. }
  84. switch (BPF_CLASS(code)) {
  85. case BPF_ALU: fputc(size_name(BPF_W), fp);
  86. case BPF_ALU64: fputc(size_name(BPF_DW), fp);
  87. }
  88. }
  89. static void offset_dump(int16_t off, FILE *fp)
  90. {
  91. if (off < 0)
  92. fprintf(fp, "L%d", -off);
  93. else
  94. fprintf(fp, "+%d", off);
  95. }
  96. static void __insn_dump(const struct bpf_insn insn, uint16_t dst, uint16_t src,
  97. FILE *fp)
  98. {
  99. const char *name;
  100. enum {
  101. OFF_NONE,
  102. OFF_DST,
  103. OFF_SRC,
  104. OFF_EXP,
  105. } off = OFF_NONE;
  106. switch (BPF_CLASS(insn.code)) {
  107. case BPF_LD:
  108. case BPF_LDX:
  109. off = OFF_SRC;
  110. fprintf(fp, "ld%c", size_name(insn.code));
  111. break;
  112. case BPF_ST:
  113. case BPF_STX:
  114. off = OFF_DST;
  115. fprintf(fp, "st%c", size_name(insn.code));
  116. break;
  117. case BPF_ALU:
  118. case BPF_ALU64:
  119. alu_dump(insn.code, fp);
  120. break;
  121. case BPF_JMP:
  122. off = OFF_EXP;
  123. switch (BPF_OP(insn.code)) {
  124. case BPF_EXIT:
  125. fputs("exit", fp);
  126. return;
  127. case BPF_CALL:
  128. fputs("call\t", fp);
  129. name = bpf_func_name(insn.imm);
  130. if (name)
  131. fputs(name, fp);
  132. else
  133. fprintf(fp, "%d", insn.imm);
  134. return;
  135. case BPF_JA:
  136. fputs("ja\t", fp);
  137. offset_dump(insn.off, fp);
  138. return;
  139. case BPF_JEQ: fputs("jeq", fp); break;
  140. case BPF_JNE: fputs("jne", fp); break;
  141. case BPF_JGT: fputs("jgt", fp); break;
  142. case BPF_JGE: fputs("jge", fp); break;
  143. case BPF_JSGE: fputs("jsge", fp); break;
  144. case BPF_JSGT: fputs("jsgt", fp); break;
  145. default:
  146. goto unknown;
  147. }
  148. break;
  149. default:
  150. goto unknown;
  151. }
  152. fputc('\t', fp);
  153. reg_dump(dst, off == OFF_DST ? insn.off : 0, fp);
  154. fputs(", ", fp);
  155. if (BPF_CLASS(insn.code) == BPF_LDX || BPF_CLASS(insn.code) == BPF_STX)
  156. goto reg_src;
  157. switch (BPF_SRC(insn.code)) {
  158. case BPF_K:
  159. fprintf(fp, "#%s0x%x", insn.imm < 0 ? "-" : "",
  160. insn.imm < 0 ? -insn.imm : insn.imm);
  161. break;
  162. case BPF_X:
  163. reg_src:
  164. reg_dump(src, off == OFF_SRC ? insn.off : 0, fp);
  165. break;
  166. }
  167. if (off == OFF_EXP) {
  168. fputs(", ", fp);
  169. offset_dump(insn.off, fp);
  170. }
  171. return;
  172. unknown:
  173. fprintf(fp, "data\t0x%16.16" PRIx64 "\n", *((uint64_t *)&insn));
  174. }
  175. void insn_dump(struct bpf_insn insn, FILE *fp)
  176. {
  177. __insn_dump(insn, insn.dst_reg, insn.src_reg, fp);
  178. }
  179. void vinsn_dump(vinsn_t *vi, FILE *fp)
  180. {
  181. switch (vi->vitype) {
  182. case VI_INSN:
  183. __insn_dump(vi->insn.bpf, vi->insn.dst, vi->insn.src, fp);
  184. return;
  185. case VI_LABEL:
  186. offset_dump(vi->label, fp);
  187. fputc(':', fp);
  188. return;
  189. case VI_REG_GET:
  190. case VI_REG_PUT:
  191. fputs((vi->vitype == VI_REG_GET) ? "+ " : "- ", fp);
  192. reg_dump(vi->reg, 0, fp);
  193. return;
  194. }
  195. }
  196. void ir_dump(ir_t *ir, FILE *fp)
  197. {
  198. size_t i;
  199. for (i = 0; i < ir->len; i++) {
  200. if (ir->vi[i].vitype == VI_INSN)
  201. fputc('\t', fp);
  202. vinsn_dump(&ir->vi[i], fp);
  203. fputc('\n', fp);
  204. }
  205. }
  206. static void ir_emit(ir_t *ir, vinsn_t *vi)
  207. {
  208. ir->vi = realloc(ir->vi, (++ir->len)*sizeof(*vi));
  209. assert(ir->vi);
  210. ir->vi[ir->len - 1] = *vi;
  211. }
  212. void ir_emit_insn(ir_t *ir, struct bpf_insn bpf, uint16_t dst, uint16_t src)
  213. {
  214. vinsn_t vi;
  215. vi.vitype = VI_INSN;
  216. vi.insn.bpf = bpf;
  217. vi.insn.dst = dst;
  218. vi.insn.src = src;
  219. ir_emit(ir, &vi);
  220. }
  221. void ir_emit_label (ir_t *ir, int16_t label)
  222. {
  223. vinsn_t vi;
  224. vi.vitype = VI_LABEL;
  225. vi.label = label;
  226. ir_emit(ir, &vi);
  227. }
  228. void ir_emit_reg_get(ir_t *ir, uint16_t reg)
  229. {
  230. vinsn_t vi;
  231. vi.vitype = VI_REG_GET;
  232. vi.reg = reg;
  233. ir_emit(ir, &vi);
  234. }
  235. void ir_emit_reg_put(ir_t *ir, uint16_t reg)
  236. {
  237. vinsn_t vi;
  238. vi.vitype = VI_REG_PUT;
  239. vi.reg = reg;
  240. ir_emit(ir, &vi);
  241. }
  242. int16_t ir_alloc_label (ir_t *ir)
  243. {
  244. return ir->next_label--;
  245. }
  246. uint16_t ir_alloc_register(ir_t *ir)
  247. {
  248. return ir->next_reg++;
  249. }
  250. ir_t *ir_new(void)
  251. {
  252. ir_t *ir;
  253. ir = calloc(1, sizeof(*ir));
  254. assert(ir);
  255. ir->next_reg = vreg_base;
  256. ir->next_label = -1;
  257. return ir;
  258. }