ebpf_mount.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include "ebpf.h"
  3. #include "ebpf_mount.h"
  4. static ebpf_local_maps_t mount_maps[] = {{.name = "tbl_mount", .internal_input = NETDATA_MOUNT_END,
  5. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  6. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  7. #ifdef LIBBPF_MAJOR_VERSION
  8. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  9. #endif
  10. },
  11. {.name = NULL, .internal_input = 0, .user_input = 0,
  12. .type = NETDATA_EBPF_MAP_CONTROLLER,
  13. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  14. #ifdef LIBBPF_MAJOR_VERSION
  15. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  16. #endif
  17. }};
  18. static char *mount_dimension_name[NETDATA_EBPF_MOUNT_SYSCALL] = { "mount", "umount" };
  19. static netdata_syscall_stat_t mount_aggregated_data[NETDATA_EBPF_MOUNT_SYSCALL];
  20. static netdata_publish_syscall_t mount_publish_aggregated[NETDATA_EBPF_MOUNT_SYSCALL];
  21. struct config mount_config = { .first_section = NULL, .last_section = NULL, .mutex = NETDATA_MUTEX_INITIALIZER,
  22. .index = {.avl_tree = { .root = NULL, .compar = appconfig_section_compare },
  23. .rwlock = AVL_LOCK_INITIALIZER } };
  24. static netdata_idx_t mount_hash_values[NETDATA_MOUNT_END];
  25. netdata_ebpf_targets_t mount_targets[] = { {.name = "mount", .mode = EBPF_LOAD_TRAMPOLINE},
  26. {.name = "umount", .mode = EBPF_LOAD_TRAMPOLINE},
  27. {.name = NULL, .mode = EBPF_LOAD_TRAMPOLINE}};
  28. #ifdef LIBBPF_MAJOR_VERSION
  29. /*****************************************************************
  30. *
  31. * BTF FUNCTIONS
  32. *
  33. *****************************************************************/
  34. /*
  35. * Disable probe
  36. *
  37. * Disable all probes to use exclusively another method.
  38. *
  39. * @param obj is the main structure for bpf objects.
  40. */
  41. static inline void ebpf_mount_disable_probe(struct mount_bpf *obj)
  42. {
  43. bpf_program__set_autoload(obj->progs.netdata_mount_probe, false);
  44. bpf_program__set_autoload(obj->progs.netdata_umount_probe, false);
  45. bpf_program__set_autoload(obj->progs.netdata_mount_retprobe, false);
  46. bpf_program__set_autoload(obj->progs.netdata_umount_retprobe, false);
  47. }
  48. /*
  49. * Disable tracepoint
  50. *
  51. * Disable all tracepoints to use exclusively another method.
  52. *
  53. * @param obj is the main structure for bpf objects.
  54. */
  55. static inline void ebpf_mount_disable_tracepoint(struct mount_bpf *obj)
  56. {
  57. bpf_program__set_autoload(obj->progs.netdata_mount_exit, false);
  58. bpf_program__set_autoload(obj->progs.netdata_umount_exit, false);
  59. }
  60. /*
  61. * Disable trampoline
  62. *
  63. * Disable all trampoline to use exclusively another method.
  64. *
  65. * @param obj is the main structure for bpf objects.
  66. */
  67. static inline void ebpf_mount_disable_trampoline(struct mount_bpf *obj)
  68. {
  69. bpf_program__set_autoload(obj->progs.netdata_mount_fentry, false);
  70. bpf_program__set_autoload(obj->progs.netdata_umount_fentry, false);
  71. bpf_program__set_autoload(obj->progs.netdata_mount_fexit, false);
  72. bpf_program__set_autoload(obj->progs.netdata_umount_fexit, false);
  73. }
  74. /**
  75. * Set trampoline target
  76. *
  77. * Set the targets we will monitor.
  78. *
  79. * @param obj is the main structure for bpf objects.
  80. */
  81. static inline void netdata_set_trampoline_target(struct mount_bpf *obj)
  82. {
  83. char syscall[NETDATA_EBPF_MAX_SYSCALL_LENGTH + 1];
  84. ebpf_select_host_prefix(syscall, NETDATA_EBPF_MAX_SYSCALL_LENGTH,
  85. mount_targets[NETDATA_MOUNT_SYSCALL].name, running_on_kernel);
  86. bpf_program__set_attach_target(obj->progs.netdata_mount_fentry, 0,
  87. syscall);
  88. bpf_program__set_attach_target(obj->progs.netdata_mount_fexit, 0,
  89. syscall);
  90. ebpf_select_host_prefix(syscall, NETDATA_EBPF_MAX_SYSCALL_LENGTH,
  91. mount_targets[NETDATA_UMOUNT_SYSCALL].name, running_on_kernel);
  92. bpf_program__set_attach_target(obj->progs.netdata_umount_fentry, 0,
  93. syscall);
  94. bpf_program__set_attach_target(obj->progs.netdata_umount_fexit, 0,
  95. syscall);
  96. }
  97. /**
  98. * Mount Attach Probe
  99. *
  100. * Attach probes to target
  101. *
  102. * @param obj is the main structure for bpf objects.
  103. *
  104. * @return It returns 0 on success and -1 otherwise.
  105. */
  106. static int ebpf_mount_attach_probe(struct mount_bpf *obj)
  107. {
  108. char syscall[NETDATA_EBPF_MAX_SYSCALL_LENGTH + 1];
  109. ebpf_select_host_prefix(syscall, NETDATA_EBPF_MAX_SYSCALL_LENGTH,
  110. mount_targets[NETDATA_MOUNT_SYSCALL].name, running_on_kernel);
  111. obj->links.netdata_mount_probe = bpf_program__attach_kprobe(obj->progs.netdata_mount_probe,
  112. false, syscall);
  113. int ret = (int)libbpf_get_error(obj->links.netdata_mount_probe);
  114. if (ret)
  115. return -1;
  116. obj->links.netdata_mount_retprobe = bpf_program__attach_kprobe(obj->progs.netdata_mount_retprobe,
  117. true, syscall);
  118. ret = (int)libbpf_get_error(obj->links.netdata_mount_retprobe);
  119. if (ret)
  120. return -1;
  121. ebpf_select_host_prefix(syscall, NETDATA_EBPF_MAX_SYSCALL_LENGTH,
  122. mount_targets[NETDATA_UMOUNT_SYSCALL].name, running_on_kernel);
  123. obj->links.netdata_umount_probe = bpf_program__attach_kprobe(obj->progs.netdata_umount_probe,
  124. false, syscall);
  125. ret = (int)libbpf_get_error(obj->links.netdata_umount_probe);
  126. if (ret)
  127. return -1;
  128. obj->links.netdata_umount_retprobe = bpf_program__attach_kprobe(obj->progs.netdata_umount_retprobe,
  129. true, syscall);
  130. ret = (int)libbpf_get_error(obj->links.netdata_umount_retprobe);
  131. if (ret)
  132. return -1;
  133. return 0;
  134. }
  135. /**
  136. * Set hash tables
  137. *
  138. * Set the values for maps according the value given by kernel.
  139. *
  140. * @param obj is the main structure for bpf objects.
  141. */
  142. static void ebpf_mount_set_hash_tables(struct mount_bpf *obj)
  143. {
  144. mount_maps[NETDATA_KEY_MOUNT_TABLE].map_fd = bpf_map__fd(obj->maps.tbl_mount);
  145. }
  146. /**
  147. * Load and attach
  148. *
  149. * Load and attach the eBPF code in kernel.
  150. *
  151. * @param obj is the main structure for bpf objects.
  152. * @param em structure with configuration
  153. *
  154. * @return it returns 0 on success and -1 otherwise
  155. */
  156. static inline int ebpf_mount_load_and_attach(struct mount_bpf *obj, ebpf_module_t *em)
  157. {
  158. netdata_ebpf_targets_t *mt = em->targets;
  159. netdata_ebpf_program_loaded_t test = mt[NETDATA_MOUNT_SYSCALL].mode;
  160. // We are testing only one, because all will have the same behavior
  161. if (test == EBPF_LOAD_TRAMPOLINE ) {
  162. ebpf_mount_disable_probe(obj);
  163. ebpf_mount_disable_tracepoint(obj);
  164. netdata_set_trampoline_target(obj);
  165. } else if (test == EBPF_LOAD_PROBE ||
  166. test == EBPF_LOAD_RETPROBE ) {
  167. ebpf_mount_disable_tracepoint(obj);
  168. ebpf_mount_disable_trampoline(obj);
  169. } else {
  170. ebpf_mount_disable_probe(obj);
  171. ebpf_mount_disable_trampoline(obj);
  172. }
  173. ebpf_update_map_type(obj->maps.tbl_mount, &mount_maps[NETDATA_KEY_MOUNT_TABLE]);
  174. int ret = mount_bpf__load(obj);
  175. if (!ret) {
  176. if (test != EBPF_LOAD_PROBE && test != EBPF_LOAD_RETPROBE )
  177. ret = mount_bpf__attach(obj);
  178. else
  179. ret = ebpf_mount_attach_probe(obj);
  180. if (!ret)
  181. ebpf_mount_set_hash_tables(obj);
  182. }
  183. return ret;
  184. }
  185. #endif
  186. /*****************************************************************
  187. *
  188. * FUNCTIONS TO CLOSE THE THREAD
  189. *
  190. *****************************************************************/
  191. /**
  192. * Obsolete global
  193. *
  194. * Obsolete global charts created by thread.
  195. *
  196. * @param em a pointer to `struct ebpf_module`
  197. */
  198. static void ebpf_obsolete_mount_global(ebpf_module_t *em)
  199. {
  200. ebpf_write_chart_obsolete(NETDATA_EBPF_MOUNT_GLOBAL_FAMILY,
  201. NETDATA_EBPF_MOUNT_CALLS,
  202. "",
  203. "Calls to mount and umount syscalls",
  204. EBPF_COMMON_DIMENSION_CALL,
  205. NETDATA_EBPF_MOUNT_FAMILY,
  206. NETDATA_EBPF_CHART_TYPE_LINE,
  207. NULL,
  208. NETDATA_CHART_PRIO_EBPF_MOUNT_CHARTS,
  209. em->update_every);
  210. ebpf_write_chart_obsolete(NETDATA_EBPF_MOUNT_GLOBAL_FAMILY,
  211. NETDATA_EBPF_MOUNT_ERRORS,
  212. "",
  213. "Errors to mount and umount file systems",
  214. EBPF_COMMON_DIMENSION_CALL,
  215. NETDATA_EBPF_MOUNT_FAMILY,
  216. NETDATA_EBPF_CHART_TYPE_LINE,
  217. NULL,
  218. NETDATA_CHART_PRIO_EBPF_MOUNT_CHARTS + 1,
  219. em->update_every);
  220. }
  221. /**
  222. * Mount Exit
  223. *
  224. * Cancel child thread.
  225. *
  226. * @param ptr thread data.
  227. */
  228. static void ebpf_mount_exit(void *ptr)
  229. {
  230. ebpf_module_t *em = (ebpf_module_t *)ptr;
  231. if (em->enabled == NETDATA_THREAD_EBPF_FUNCTION_RUNNING) {
  232. pthread_mutex_lock(&lock);
  233. ebpf_obsolete_mount_global(em);
  234. fflush(stdout);
  235. pthread_mutex_unlock(&lock);
  236. }
  237. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps, EBPF_ACTION_STAT_REMOVE);
  238. #ifdef LIBBPF_MAJOR_VERSION
  239. if (mount_bpf_obj) {
  240. mount_bpf__destroy(mount_bpf_obj);
  241. mount_bpf_obj = NULL;
  242. }
  243. #endif
  244. if (em->objects) {
  245. ebpf_unload_legacy_code(em->objects, em->probe_links);
  246. em->objects = NULL;
  247. em->probe_links = NULL;
  248. }
  249. pthread_mutex_lock(&ebpf_exit_cleanup);
  250. em->enabled = NETDATA_THREAD_EBPF_STOPPED;
  251. ebpf_update_stats(&plugin_statistics, em);
  252. pthread_mutex_unlock(&ebpf_exit_cleanup);
  253. }
  254. /*****************************************************************
  255. *
  256. * MAIN LOOP
  257. *
  258. *****************************************************************/
  259. /**
  260. * Read global table
  261. *
  262. * Read the table with number of calls for all functions
  263. *
  264. * @param maps_per_core do I need to read all cores?
  265. */
  266. static void ebpf_mount_read_global_table(int maps_per_core)
  267. {
  268. static netdata_idx_t *mount_values = NULL;
  269. if (!mount_values)
  270. mount_values = callocz((size_t)ebpf_nprocs + 1, sizeof(netdata_idx_t));
  271. uint32_t idx;
  272. netdata_idx_t *val = mount_hash_values;
  273. netdata_idx_t *stored = mount_values;
  274. size_t length = sizeof(netdata_idx_t);
  275. if (maps_per_core)
  276. length *= ebpf_nprocs;
  277. int fd = mount_maps[NETDATA_KEY_MOUNT_TABLE].map_fd;
  278. for (idx = NETDATA_KEY_MOUNT_CALL; idx < NETDATA_MOUNT_END; idx++) {
  279. if (!bpf_map_lookup_elem(fd, &idx, stored)) {
  280. int i;
  281. int end = (maps_per_core) ? ebpf_nprocs : 1;
  282. netdata_idx_t total = 0;
  283. for (i = 0; i < end; i++)
  284. total += stored[i];
  285. val[idx] = total;
  286. memset(stored, 0, length);
  287. }
  288. }
  289. }
  290. /**
  291. * Send data to Netdata calling auxiliary functions.
  292. */
  293. static void ebpf_mount_send_data()
  294. {
  295. int i, j;
  296. int end = NETDATA_EBPF_MOUNT_SYSCALL;
  297. for (i = NETDATA_KEY_MOUNT_CALL, j = NETDATA_KEY_MOUNT_ERROR; i < end; i++, j++) {
  298. mount_publish_aggregated[i].ncall = mount_hash_values[i];
  299. mount_publish_aggregated[i].nerr = mount_hash_values[j];
  300. }
  301. write_count_chart(NETDATA_EBPF_MOUNT_CALLS, NETDATA_EBPF_MOUNT_GLOBAL_FAMILY,
  302. mount_publish_aggregated, NETDATA_EBPF_MOUNT_SYSCALL);
  303. write_err_chart(NETDATA_EBPF_MOUNT_ERRORS, NETDATA_EBPF_MOUNT_GLOBAL_FAMILY,
  304. mount_publish_aggregated, NETDATA_EBPF_MOUNT_SYSCALL);
  305. }
  306. /**
  307. * Main loop for this collector.
  308. */
  309. static void mount_collector(ebpf_module_t *em)
  310. {
  311. memset(mount_hash_values, 0, sizeof(mount_hash_values));
  312. heartbeat_t hb;
  313. heartbeat_init(&hb);
  314. int update_every = em->update_every;
  315. int counter = update_every - 1;
  316. int maps_per_core = em->maps_per_core;
  317. uint32_t running_time = 0;
  318. uint32_t lifetime = em->lifetime;
  319. while (!ebpf_plugin_exit && running_time < lifetime) {
  320. (void)heartbeat_next(&hb, USEC_PER_SEC);
  321. if (ebpf_plugin_exit || ++counter != update_every)
  322. continue;
  323. counter = 0;
  324. ebpf_mount_read_global_table(maps_per_core);
  325. pthread_mutex_lock(&lock);
  326. ebpf_mount_send_data();
  327. pthread_mutex_unlock(&lock);
  328. pthread_mutex_lock(&ebpf_exit_cleanup);
  329. if (running_time && !em->running_time)
  330. running_time = update_every;
  331. else
  332. running_time += update_every;
  333. em->running_time = running_time;
  334. pthread_mutex_unlock(&ebpf_exit_cleanup);
  335. }
  336. }
  337. /*****************************************************************
  338. *
  339. * INITIALIZE THREAD
  340. *
  341. *****************************************************************/
  342. /**
  343. * Create mount charts
  344. *
  345. * Call ebpf_create_chart to create the charts for the collector.
  346. *
  347. * @param update_every value to overwrite the update frequency set by the server.
  348. */
  349. static void ebpf_create_mount_charts(int update_every)
  350. {
  351. ebpf_create_chart(NETDATA_EBPF_MOUNT_GLOBAL_FAMILY, NETDATA_EBPF_MOUNT_CALLS,
  352. "Calls to mount and umount syscalls",
  353. EBPF_COMMON_DIMENSION_CALL, NETDATA_EBPF_MOUNT_FAMILY,
  354. NULL,
  355. NETDATA_EBPF_CHART_TYPE_LINE,
  356. NETDATA_CHART_PRIO_EBPF_MOUNT_CHARTS,
  357. ebpf_create_global_dimension,
  358. mount_publish_aggregated, NETDATA_EBPF_MOUNT_SYSCALL,
  359. update_every, NETDATA_EBPF_MODULE_NAME_MOUNT);
  360. ebpf_create_chart(NETDATA_EBPF_MOUNT_GLOBAL_FAMILY, NETDATA_EBPF_MOUNT_ERRORS,
  361. "Errors to mount and umount file systems",
  362. EBPF_COMMON_DIMENSION_CALL, NETDATA_EBPF_MOUNT_FAMILY,
  363. NULL,
  364. NETDATA_EBPF_CHART_TYPE_LINE,
  365. NETDATA_CHART_PRIO_EBPF_MOUNT_CHARTS + 1,
  366. ebpf_create_global_dimension,
  367. mount_publish_aggregated, NETDATA_EBPF_MOUNT_SYSCALL,
  368. update_every, NETDATA_EBPF_MODULE_NAME_MOUNT);
  369. fflush(stdout);
  370. }
  371. /*****************************************************************
  372. *
  373. * MAIN THREAD
  374. *
  375. *****************************************************************/
  376. /*
  377. * Load BPF
  378. *
  379. * Load BPF files.
  380. *
  381. * @param em the structure with configuration
  382. */
  383. static int ebpf_mount_load_bpf(ebpf_module_t *em)
  384. {
  385. #ifdef LIBBPF_MAJOR_VERSION
  386. ebpf_define_map_type(em->maps, em->maps_per_core, running_on_kernel);
  387. #endif
  388. int ret = 0;
  389. if (em->load & EBPF_LOAD_LEGACY) {
  390. em->probe_links = ebpf_load_program(ebpf_plugin_dir, em, running_on_kernel, isrh, &em->objects);
  391. if (!em->probe_links) {
  392. ret = -1;
  393. }
  394. }
  395. #ifdef LIBBPF_MAJOR_VERSION
  396. else {
  397. mount_bpf_obj = mount_bpf__open();
  398. if (!mount_bpf_obj)
  399. ret = -1;
  400. else
  401. ret = ebpf_mount_load_and_attach(mount_bpf_obj, em);
  402. }
  403. #endif
  404. if (ret)
  405. netdata_log_error("%s %s", EBPF_DEFAULT_ERROR_MSG, em->info.thread_name);
  406. return ret;
  407. }
  408. /**
  409. * Mount thread
  410. *
  411. * Thread used to make mount thread
  412. *
  413. * @param ptr a pointer to `struct ebpf_module`
  414. *
  415. * @return It always returns NULL
  416. */
  417. void *ebpf_mount_thread(void *ptr)
  418. {
  419. netdata_thread_cleanup_push(ebpf_mount_exit, ptr);
  420. ebpf_module_t *em = (ebpf_module_t *)ptr;
  421. em->maps = mount_maps;
  422. #ifdef LIBBPF_MAJOR_VERSION
  423. ebpf_adjust_thread_load(em, default_btf);
  424. #endif
  425. if (ebpf_mount_load_bpf(em)) {
  426. goto endmount;
  427. }
  428. int algorithms[NETDATA_EBPF_MOUNT_SYSCALL] = { NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX };
  429. ebpf_global_labels(mount_aggregated_data, mount_publish_aggregated, mount_dimension_name, mount_dimension_name,
  430. algorithms, NETDATA_EBPF_MOUNT_SYSCALL);
  431. pthread_mutex_lock(&lock);
  432. ebpf_create_mount_charts(em->update_every);
  433. ebpf_update_stats(&plugin_statistics, em);
  434. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps, EBPF_ACTION_STAT_ADD);
  435. pthread_mutex_unlock(&lock);
  436. mount_collector(em);
  437. endmount:
  438. ebpf_update_disabled_plugin_stats(em);
  439. netdata_thread_cleanup_pop(1);
  440. return NULL;
  441. }