Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

libbpf-tools/profile: Add support for PID-namespacing #5152

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 17 additions & 3 deletions libbpf-tools/profile.bpf.c
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@ const volatile bool user_stacks_only = false;
const volatile bool include_idle = false;
const volatile bool filter_by_pid = false;
const volatile bool filter_by_tid = false;
const volatile bool use_pidns = false;
const volatile __u64 pidns_dev = 0;
const volatile __u64 pidns_ino = 0;

struct {
__uint(type, BPF_MAP_TYPE_STACK_TRACE);
Expand Down Expand Up @@ -47,12 +50,23 @@ struct {
SEC("perf_event")
int do_perf_event(struct bpf_perf_event_data *ctx)
{
u64 id = bpf_get_current_pid_tgid();
u32 pid = id >> 32;
u32 tid = id;
u64 *valp;
static const u64 zero;
struct key_t key = {};
u64 id;
u32 pid;
u32 tid;
struct bpf_pidns_info ns = {};

if (use_pidns && !bpf_get_ns_current_pid_tgid(pidns_dev, pidns_ino, &ns,
sizeof(struct bpf_pidns_info))) {
pid = ns.tgid;
tid = ns.pid;
} else {
id = bpf_get_current_pid_tgid();
pid = id >> 32;
tid = id;
}

if (!include_idle && tid == 0)
return 0;
Expand Down
40 changes: 40 additions & 0 deletions libbpf-tools/profile.c
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,10 @@
#include <time.h>
#include <linux/perf_event.h>
#include <asm/unistd.h>
#include <sys/utsname.h>
#include <bpf/libbpf.h>
#include <bpf/bpf.h>
#include <sys/stat.h>
#include "profile.h"
#include "profile.skel.h"
#include "trace_helpers.h"
Expand Down Expand Up @@ -506,6 +508,40 @@ static int print_counts(int counts_map, int stack_map)
return ret;
}

static int kernel_at_least(int req_major, int req_minor) {
struct utsname u;
int major, minor;

if (uname(&u) == -1)
return -errno;

if (sscanf(u.release, "%d.%d", &major, &minor) != 2)
return -errno;

return !((major > req_major) || (major == req_major && minor >= req_minor));
}

static int set_pidns(const struct profile_bpf *obj)
{
struct stat statbuf;

/*
* Available on Linux version 5.7 and above, which includes
* the helper function bpf_get_ns_current_pid_tgid().
*/
if (kernel_at_least(5, 7))
return -EPERM;
Comment on lines +532 to +533
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The problem with fixed version check is that they will not work on kernel where a specific patch could have been backported.
Is there a way to rather check for the existence of a given bpf helper?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In bcc/tools, we have a few cases (including profile) checking kernel version for bpf_get_ns_current_pid_tgid() availability. But for libbpf-tools, I think we can do better.
See trace_helpers.c. There are a few probe_*() functions which tries to detect whether a particular feature (prog_type, map_type) is supported or not. I think we can have another probe function to check whether bpf_get_ns_current_pid_tgid() is supported or not.


if (stat("/proc/self/ns/pid", &statbuf) == -1)
return -errno;

obj->rodata->use_pidns = true;
obj->rodata->pidns_dev = statbuf.st_dev;
obj->rodata->pidns_ino = statbuf.st_ino;

return 0;
}

static void print_headers()
{
int i;
Expand Down Expand Up @@ -595,6 +631,10 @@ int main(int argc, char **argv)
env.perf_max_stack_depth * sizeof(unsigned long));
bpf_map__set_max_entries(obj->maps.stackmap, env.stack_storage_size);

err = set_pidns(obj);
if (err)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let us do 'err && env.verbose' here. We want to print out the below information under verbose mode.

fprintf(stderr, "failed to translate pidns: %s\n", strerror(-err));

err = profile_bpf__load(obj);
if (err) {
fprintf(stderr, "failed to load BPF programs\n");
Expand Down
Loading