3 ms·
FWIW, programs compiled through a modern toolchain can ship their own debug data. For example, the restrict_filesystems program loaded by systemd $ sudo bp
by alexgartrell 4y ago
FWIW, programs compiled through a modern toolchain can ship their own debug data. For example, the restrict_filesystems program loaded by systemd
$ sudo bpftool prog dump xlated id 50
int restrict_filesystems(unsigned long long \* ctx):
; int BPF_PROG(restrict_filesystems, struct file *file, int ret)
0: (79) r3 = *(u64 *)(r1 +0)
1: (79) r0 = *(u64 *)(r1 +8)
2: (b7) r1 = 0
; uint32_t *value, *magic_map, zero = 0, *is_allow;
3: (63) *(u32 *)(r10 -20) = r1
; int BPF_PROG(restrict_filesystems, struct file \*file, int ret)
4: (bf) r1 = r0
5: (67) r1 <<= 32
6: (77) r1 >>= 32
; if (ret != 0)
7: (55) if r1 != 0x0 goto pc+59
8: (b7) r1 = 32
9: (0f) r3 += r1
10: (bf) r6 = r10
https://github.com/systemd/systemd/blob/c76691d708ac7fe13b7c4307c010d447fcbc3e9a/src/core/bpf/restrict_fs/restrict-fs.bpf.c https://github.com/systemd/systemd/blob/c76691d708ac7fe13b7c...
Unfortunately, most of the programs loaded by systemd are more-or-less hand-generated (the ingress/egress programs specifically) and do not include this information.
It's a surprisingly small group of folks who work in this space upstream, but I know that they're aware of this as an opportunity to improve things :)