Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add --filter-track-bpf-helpers #390

Merged
merged 4 commits into from
Sep 2, 2024
Merged

Conversation

jschwinger233
Copy link
Member

Please see commit messages for implementation details.

Using --filter-track-bpf-helpers and --output-caller together can roughly trace bpf tailcalls, such as:

0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) tcf_classify                 sch_handle_ingress.constprop.0
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_event_output         bpf_prog_306e2b9160b2fb74_cil_from_container[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_pull_data            bpf_prog_a76cce51ceb41c61_tail_handle_ipv4[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) skb_ensure_writable          bpf_skb_pull_data
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_load_bytes           bpf_prog_a76cce51ceb41c61_tail_handle_ipv4[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_a76cce51ceb41c61_tail_handle_ipv4[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_load_bytes           bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_load_bytes           bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_map_lookup_elem          bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_map_lookup_elem          bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) array_map_update_elem        bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) trie_lookup_elem             bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) percpu_array_map_lookup_elem bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_ktime_get_ns             bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_map_update_elem          bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) htab_lru_map_update_elem     bpf_map_update_elem
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) htab_lru_map_update_elem     bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) htab_percpu_map_lookup_elem  bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_event_output         bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) ip_rcv                       __netif_receive_skb_one_core

@jschwinger233 jschwinger233 force-pushed the gray/filter-bpf branch 3 times, most recently from f761547 to 2ae87e9 Compare June 21, 2024 09:00
@jschwinger233 jschwinger233 marked this pull request as ready for review June 21, 2024 09:38
@jschwinger233 jschwinger233 requested a review from a team as a code owner June 21, 2024 09:38
@jschwinger233 jschwinger233 requested review from brb and removed request for a team June 21, 2024 09:38
@brb
Copy link
Member

brb commented Jul 7, 2024

@jschwinger233 👋 could you rebase?

Copy link
Member

@brb brb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Amazing! Can you rebase to resolve the conflict?

This commit adds a new API GetBpfHelpers(), which accepts symbols (from
/proc/kallsyms) and returns all bpf helper names used at present.

The idea is to scan assembly code of each bpf functions (has
suffix [bpf]) and gather all callees, which are bpf helpers.

The steps are like:

1. Get all bpf progs:

```
 # cat /proc/kallsyms | grep '\[bpf\]$'
[...]
ffffffffc0380af8 t bpf_prog_3cdf7f3879992857_tail_ipv4_to_endpoint	[bpf]
ffffffffc0382514 t bpf_prog_e214e82dc4b46fca_cil_from_container	[bpf]
ffffffffc0382870 t bpf_prog_773159d28c0ab73a_cil_to_container	[bpf]
[...]
```

2. Get all callee addresses from each bpf prog:

```
 # gdb -ex 'x/5000i 0xffffffffc0382870' -ex q vmlinux /proc/kcore | grep call
[...]
   0xffffffffc03829ee:	call   0xffffffff9fb2ee50
   0xffffffffc0382a47:	call   0xffffffff9fb2fd20
   0xffffffffc0382ad4:	call   0xffffffffa0649120
[...]
```

3. Convert addresses to symbols

```
 # cat /proc/kallsyms | grep ffffffff9fb2ee50
ffffffff9fb2ee50 t htab_percpu_map_lookup_elem
```

Currently only x64 are taken care of.

Signed-off-by: gray <gray.liang@isovalent.com>
When --filter-track-bpf-helpers is set, --filter-track-skb-by-stackid is
enabled automatically.

Using --filter-track-bpf-helpers and --output-caller together can
roughly trace bpf tailcalls, such as:

```
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) tcf_classify                 sch_handle_ingress.constprop.0
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_event_output         bpf_prog_306e2b9160b2fb74_cil_from_container[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_pull_data            bpf_prog_a76cce51ceb41c61_tail_handle_ipv4[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) skb_ensure_writable          bpf_skb_pull_data
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_load_bytes           bpf_prog_a76cce51ceb41c61_tail_handle_ipv4[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_a76cce51ceb41c61_tail_handle_ipv4[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_load_bytes           bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_load_bytes           bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_map_lookup_elem          bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_map_lookup_elem          bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) array_map_update_elem        bpf_prog_5fd02288bd4a682e_tail_ipv4_ct_egress[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) trie_lookup_elem             bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) percpu_array_map_lookup_elem bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   ~bin/curl:227116 10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_ktime_get_ns             bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_map_update_elem          bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   curl:227116      10.244.1.141:45000->10.244.3.20:8080(tcp) htab_lru_map_update_elem     bpf_map_update_elem
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) htab_lru_map_update_elem     bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) __htab_map_lookup_elem       bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) htab_percpu_map_lookup_elem  bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) bpf_skb_event_output         bpf_prog_4f62c9416e340c61_tail_handle_ipv4_cont[bpf]
0xffff97cdbd7138e8 3   <empty>:227116   10.244.1.141:45000->10.244.3.20:8080(tcp) ip_rcv                       __netif_receive_skb_one_core
```

Signed-off-by: gray <gray.liang@isovalent.com>
Signed-off-by: gray <gray.liang@isovalent.com>
Signed-off-by: gray <gray.liang@isovalent.com>
@brb brb merged commit 3bf9d91 into cilium:main Sep 2, 2024
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants