4 ms·
'bpftool' provides a list of loaded bpf programs, but playing around with it just now, it is not obvious to me how to get the actual loaded bpf program details
by sillystuff 4y ago
'bpftool' provides a list of loaded bpf programs, but playing around with it just now, it is not obvious to me how to get the actual loaded bpf program details (e.g, pre-JIT version of the loaded program [or even the JIT version]). The man page is pretty terse.
'bpftool prog' / 'bpftool prog list' / 'bpftool prog show' all provided the same output (sample below), and e.g., adding the index in the list, to any of the above commands is an error.
e.g.,
# bpftool prog
8: cgroup_device name sd_devices tag 1f97e470ec084ee5 gpl
loaded_at 2022-11-02T08:58:10-0700 uid 0
xlated 464B jited 292B memlock 4096B
173: cgroup_device name sd_devices tag c7286db13d0052fa gpl
loaded_at 2022-11-05T23:53:24-0700 uid 0
xlated 464B jited 292B memlock 4096B
174: cgroup_skb name sd_fw_egress tag 6deef7357e7b4530 gpl
loaded_at 2022-11-05T23:53:24-0700 uid 0
xlated 64B jited 58B memlock 4096B
.
.
.
Does anyone know if it is possible, and how to get the details on the loaded bpf programs?
EDIT:
Loading a bpf program to snoop on mount/umount events, I get:
189: kprobe name syscall__mount tag f618bcdbd5252ac9 gpl
loaded_at 2022-11-06T10:45:24-0800 uid 0
xlated 3440B jited 2478B memlock 4096B map_ids 1
btf_id 200
190: kprobe name do_ret_sys_mount tag 6960d7da9f367709 gpl
loaded_at 2022-11-06T10:45:24-0800 uid 0
xlated 600B jited 442B memlock 4096B map_ids 1
btf_id 200
191: kprobe name syscall__umount tag d332813cc5f79072 gpl
loaded_at 2022-11-06T10:45:24-0800 uid 0
xlated 1728B jited 1223B memlock 4096B map_ids 1
btf_id 200
192: kprobe name do_ret_sys_umount tag a77da47eaebd04a3 gpl
loaded_at 2022-11-06T10:45:25-0800 uid 0
xlated 600B jited 442B memlock 4096B map_ids 1
btf_id 200
So, at least, even without any more details, it is possible to see that something is monitoring mount/unmount. But, still curious about my orginal question.
- mdaverde 4y agoYou can see the interpreter instructions through bpftool: bpftool prog dump xlated id 173 To see the JITed instructions: bpftool prog dump jited id 173 For the interpreted insns, you can also see the instructions in different forms, which is pretty neat. For example you can get a control flow graph in DOT format with `visual` specified at the end: bpftool prog dump xlated id 173 visual I learned about these commands through this blog post: https://qmonnet.github.io/whirl-offload/2021/09/23/bpftool-features-thread/ https://qmonnet.github.io/whirl-offload/2021/09/23/bpftool-f...
- sillystuff 4y agoThanks. Visibility seems to be pretty good. Something like AIDE/Tripwire for BPF might be the next step.
- nickstinemates 4y agoThis is effectively what Falco(https://falco.org/ https://falco.org/) is
- tkhattra 4y agothe bpftool-prog(8) man page documents the bpftool-prog subcommands
- alexgartrell 4y agoFWIW, programs compiled through a modern toolchain can ship their own debug data. For example, the restrict_filesystems program loaded by systemd $ sudo bpftool prog dump xlated id 50 int restrict_filesystems(unsigned long long \* ctx): ; int BPF_PROG(restrict_filesystems, struct file *file, int ret) 0: (79) r3 = *(u64 *)(r1 +0) 1: (79) r0 = *(u64 *)(r1 +8) 2: (b7) r1 = 0 ; uint32_t *value, *magic_map, zero = 0, *is_allow; 3: (63) *(u32 *)(r10 -20) = r1 ; int BPF_PROG(restrict_filesystems, struct file \*file, int ret) 4: (bf) r1 = r0 5: (67) r1 <<= 32 6: (77) r1 >>= 32 ; if (ret != 0) 7: (55) if r1 != 0x0 goto pc+59 8: (b7) r1 = 32 9: (0f) r3 += r1 10: (bf) r6 = r10 https://github.com/systemd/systemd/blob/c76691d708ac7fe13b7c4307c010d447fcbc3e9a/src/core/bpf/restrict_fs/restrict-fs.bpf.c https://github.com/systemd/systemd/blob/c76691d708ac7fe13b7c... Unfortunately, most of the programs loaded by systemd are more-or-less hand-generated (the ingress/egress programs specifically) and do not include this information. It's a surprisingly small group of folks who work in this space upstream, but I know that they're aware of this as an opportunity to improve things :)