brintos

brintos / linux-shallow public Read only

0
0
Text · 5.1 KiB · 1226a94 Raw
163 lines · plain
1.. SPDX-License-Identifier: GPL-2.02 3============================4BPF_PROG_TYPE_CGROUP_SOCKOPT5============================6 7``BPF_PROG_TYPE_CGROUP_SOCKOPT`` program type can be attached to two8cgroup hooks:9 10* ``BPF_CGROUP_GETSOCKOPT`` - called every time process executes ``getsockopt``11  system call.12* ``BPF_CGROUP_SETSOCKOPT`` - called every time process executes ``setsockopt``13  system call.14 15The context (``struct bpf_sockopt``) has associated socket (``sk``) and16all input arguments: ``level``, ``optname``, ``optval`` and ``optlen``.17 18BPF_CGROUP_SETSOCKOPT19=====================20 21``BPF_CGROUP_SETSOCKOPT`` is triggered *before* the kernel handling of22sockopt and it has writable context: it can modify the supplied arguments23before passing them down to the kernel. This hook has access to the cgroup24and socket local storage.25 26If BPF program sets ``optlen`` to -1, the control will be returned27back to the userspace after all other BPF programs in the cgroup28chain finish (i.e. kernel ``setsockopt`` handling will *not* be executed).29 30Note, that ``optlen`` can not be increased beyond the user-supplied31value. It can only be decreased or set to -1. Any other value will32trigger ``EFAULT``.33 34Return Type35-----------36 37* ``0`` - reject the syscall, ``EPERM`` will be returned to the userspace.38* ``1`` - success, continue with next BPF program in the cgroup chain.39 40BPF_CGROUP_GETSOCKOPT41=====================42 43``BPF_CGROUP_GETSOCKOPT`` is triggered *after* the kernel handing of44sockopt. The BPF hook can observe ``optval``, ``optlen`` and ``retval``45if it's interested in whatever kernel has returned. BPF hook can override46the values above, adjust ``optlen`` and reset ``retval`` to 0. If ``optlen``47has been increased above initial ``getsockopt`` value (i.e. userspace48buffer is too small), ``EFAULT`` is returned.49 50This hook has access to the cgroup and socket local storage.51 52Note, that the only acceptable value to set to ``retval`` is 0 and the53original value that the kernel returned. Any other value will trigger54``EFAULT``.55 56Return Type57-----------58 59* ``0`` - reject the syscall, ``EPERM`` will be returned to the userspace.60* ``1`` - success: copy ``optval`` and ``optlen`` to userspace, return61  ``retval`` from the syscall (note that this can be overwritten by62  the BPF program from the parent cgroup).63 64Cgroup Inheritance65==================66 67Suppose, there is the following cgroup hierarchy where each cgroup68has ``BPF_CGROUP_GETSOCKOPT`` attached at each level with69``BPF_F_ALLOW_MULTI`` flag::70 71  A (root, parent)72   \73    B (child)74 75When the application calls ``getsockopt`` syscall from the cgroup B,76the programs are executed from the bottom up: B, A. First program77(B) sees the result of kernel's ``getsockopt``. It can optionally78adjust ``optval``, ``optlen`` and reset ``retval`` to 0. After that79control will be passed to the second (A) program which will see the80same context as B including any potential modifications.81 82Same for ``BPF_CGROUP_SETSOCKOPT``: if the program is attached to83A and B, the trigger order is B, then A. If B does any changes84to the input arguments (``level``, ``optname``, ``optval``, ``optlen``),85then the next program in the chain (A) will see those changes,86*not* the original input ``setsockopt`` arguments. The potentially87modified values will be then passed down to the kernel.88 89Large optval90============91When the ``optval`` is greater than the ``PAGE_SIZE``, the BPF program92can access only the first ``PAGE_SIZE`` of that data. So it has to options:93 94* Set ``optlen`` to zero, which indicates that the kernel should95  use the original buffer from the userspace. Any modifications96  done by the BPF program to the ``optval`` are ignored.97* Set ``optlen`` to the value less than ``PAGE_SIZE``, which98  indicates that the kernel should use BPF's trimmed ``optval``.99 100When the BPF program returns with the ``optlen`` greater than101``PAGE_SIZE``, the userspace will receive original kernel102buffers without any modifications that the BPF program might have103applied.104 105Example106=======107 108Recommended way to handle BPF programs is as follows:109 110.. code-block:: c111 112	SEC("cgroup/getsockopt")113	int getsockopt(struct bpf_sockopt *ctx)114	{115		/* Custom socket option. */116		if (ctx->level == MY_SOL && ctx->optname == MY_OPTNAME) {117			ctx->retval = 0;118			optval[0] = ...;119			ctx->optlen = 1;120			return 1;121		}122 123		/* Modify kernel's socket option. */124		if (ctx->level == SOL_IP && ctx->optname == IP_FREEBIND) {125			ctx->retval = 0;126			optval[0] = ...;127			ctx->optlen = 1;128			return 1;129		}130 131		/* optval larger than PAGE_SIZE use kernel's buffer. */132		if (ctx->optlen > PAGE_SIZE)133			ctx->optlen = 0;134 135		return 1;136	}137 138	SEC("cgroup/setsockopt")139	int setsockopt(struct bpf_sockopt *ctx)140	{141		/* Custom socket option. */142		if (ctx->level == MY_SOL && ctx->optname == MY_OPTNAME) {143			/* do something */144			ctx->optlen = -1;145			return 1;146		}147 148		/* Modify kernel's socket option. */149		if (ctx->level == SOL_IP && ctx->optname == IP_FREEBIND) {150			optval[0] = ...;151			return 1;152		}153 154		/* optval larger than PAGE_SIZE use kernel's buffer. */155		if (ctx->optlen > PAGE_SIZE)156			ctx->optlen = 0;157 158		return 1;159	}160 161See ``tools/testing/selftests/bpf/progs/sockopt_sk.c`` for an example162of BPF program that handles socket options.163