162306a36Sopenharmony_ci#include "vmlinux.h" 262306a36Sopenharmony_ci#include <linux/version.h> 362306a36Sopenharmony_ci#include <bpf/bpf_helpers.h> 462306a36Sopenharmony_ci#include <bpf/bpf_tracing.h> 562306a36Sopenharmony_ci#include <bpf/bpf_core_read.h> 662306a36Sopenharmony_ci 762306a36Sopenharmony_cistruct { 862306a36Sopenharmony_ci __uint(type, BPF_MAP_TYPE_PERF_EVENT_ARRAY); 962306a36Sopenharmony_ci __uint(key_size, sizeof(int)); 1062306a36Sopenharmony_ci __uint(value_size, sizeof(u32)); 1162306a36Sopenharmony_ci __uint(max_entries, 64); 1262306a36Sopenharmony_ci} counters SEC(".maps"); 1362306a36Sopenharmony_ci 1462306a36Sopenharmony_cistruct { 1562306a36Sopenharmony_ci __uint(type, BPF_MAP_TYPE_HASH); 1662306a36Sopenharmony_ci __type(key, int); 1762306a36Sopenharmony_ci __type(value, u64); 1862306a36Sopenharmony_ci __uint(max_entries, 64); 1962306a36Sopenharmony_ci} values SEC(".maps"); 2062306a36Sopenharmony_ci 2162306a36Sopenharmony_cistruct { 2262306a36Sopenharmony_ci __uint(type, BPF_MAP_TYPE_HASH); 2362306a36Sopenharmony_ci __type(key, int); 2462306a36Sopenharmony_ci __type(value, struct bpf_perf_event_value); 2562306a36Sopenharmony_ci __uint(max_entries, 64); 2662306a36Sopenharmony_ci} values2 SEC(".maps"); 2762306a36Sopenharmony_ci 2862306a36Sopenharmony_ciSEC("kprobe/htab_map_get_next_key") 2962306a36Sopenharmony_ciint bpf_prog1(struct pt_regs *ctx) 3062306a36Sopenharmony_ci{ 3162306a36Sopenharmony_ci u32 key = bpf_get_smp_processor_id(); 3262306a36Sopenharmony_ci u64 count, *val; 3362306a36Sopenharmony_ci s64 error; 3462306a36Sopenharmony_ci 3562306a36Sopenharmony_ci count = bpf_perf_event_read(&counters, key); 3662306a36Sopenharmony_ci error = (s64)count; 3762306a36Sopenharmony_ci if (error <= -2 && error >= -22) 3862306a36Sopenharmony_ci return 0; 3962306a36Sopenharmony_ci 4062306a36Sopenharmony_ci val = bpf_map_lookup_elem(&values, &key); 4162306a36Sopenharmony_ci if (val) 4262306a36Sopenharmony_ci *val = count; 4362306a36Sopenharmony_ci else 4462306a36Sopenharmony_ci bpf_map_update_elem(&values, &key, &count, BPF_NOEXIST); 4562306a36Sopenharmony_ci 4662306a36Sopenharmony_ci return 0; 4762306a36Sopenharmony_ci} 4862306a36Sopenharmony_ci 4962306a36Sopenharmony_ci/* 5062306a36Sopenharmony_ci * Since *_map_lookup_elem can't be expected to trigger bpf programs 5162306a36Sopenharmony_ci * due to potential deadlocks (bpf_disable_instrumentation), this bpf 5262306a36Sopenharmony_ci * program will be attached to bpf_map_copy_value (which is called 5362306a36Sopenharmony_ci * from map_lookup_elem) and will only filter the hashtable type. 5462306a36Sopenharmony_ci */ 5562306a36Sopenharmony_ciSEC("kprobe/bpf_map_copy_value") 5662306a36Sopenharmony_ciint BPF_KPROBE(bpf_prog2, struct bpf_map *map) 5762306a36Sopenharmony_ci{ 5862306a36Sopenharmony_ci u32 key = bpf_get_smp_processor_id(); 5962306a36Sopenharmony_ci struct bpf_perf_event_value *val, buf; 6062306a36Sopenharmony_ci enum bpf_map_type type; 6162306a36Sopenharmony_ci int error; 6262306a36Sopenharmony_ci 6362306a36Sopenharmony_ci type = BPF_CORE_READ(map, map_type); 6462306a36Sopenharmony_ci if (type != BPF_MAP_TYPE_HASH) 6562306a36Sopenharmony_ci return 0; 6662306a36Sopenharmony_ci 6762306a36Sopenharmony_ci error = bpf_perf_event_read_value(&counters, key, &buf, sizeof(buf)); 6862306a36Sopenharmony_ci if (error) 6962306a36Sopenharmony_ci return 0; 7062306a36Sopenharmony_ci 7162306a36Sopenharmony_ci val = bpf_map_lookup_elem(&values2, &key); 7262306a36Sopenharmony_ci if (val) 7362306a36Sopenharmony_ci *val = buf; 7462306a36Sopenharmony_ci else 7562306a36Sopenharmony_ci bpf_map_update_elem(&values2, &key, &buf, BPF_NOEXIST); 7662306a36Sopenharmony_ci 7762306a36Sopenharmony_ci return 0; 7862306a36Sopenharmony_ci} 7962306a36Sopenharmony_ci 8062306a36Sopenharmony_cichar _license[] SEC("license") = "GPL"; 8162306a36Sopenharmony_ciu32 _version SEC("version") = LINUX_VERSION_CODE; 82