|
| 1 | +//go:build linux |
| 2 | +// +build linux |
| 3 | + |
1 | 4 | package exectrace
|
2 | 5 |
|
3 |
| -import "bytes" |
| 6 | +import ( |
| 7 | + "bytes" |
| 8 | + "runtime" |
| 9 | + "sync" |
| 10 | + |
| 11 | + "github.com/cilium/ebpf" |
| 12 | + "github.com/cilium/ebpf/rlimit" |
| 13 | + "github.com/hashicorp/go-multierror" |
| 14 | + "golang.org/x/xerrors" |
| 15 | +) |
| 16 | + |
| 17 | +var ( |
| 18 | + errObjectsClosed = xerrors.New("objects are closed") |
| 19 | + removeMemlockOnce sync.Once |
| 20 | + |
| 21 | + // collectionOpts used for loading the BPF objects. |
| 22 | + collectionOpts = &ebpf.CollectionOptions{ |
| 23 | + Programs: ebpf.ProgramOptions{ |
| 24 | + // While debugging, it may be helpful to set this value to be much |
| 25 | + // higher (i.e. * 1000). |
| 26 | + LogSize: ebpf.DefaultVerifierLogSize, |
| 27 | + }, |
| 28 | + } |
| 29 | +) |
| 30 | + |
| 31 | +// loadBPFObjects reads and parses the programs and maps out of the embedded |
| 32 | +// BPF program. |
| 33 | +func loadBPFObjects() (*bpfObjects, error) { |
| 34 | + // Allow the current process to lock memory for eBPF resources. This does |
| 35 | + // nothing on 5.11+ kernels which don't need this. |
| 36 | + var err error |
| 37 | + removeMemlockOnce.Do(func() { |
| 38 | + err = rlimit.RemoveMemlock() |
| 39 | + }) |
| 40 | + if err != nil { |
| 41 | + return nil, xerrors.Errorf("remove kernel memlock: %w", err) |
| 42 | + } |
| 43 | + |
| 44 | + r := bytes.NewReader(bpfProgram) |
| 45 | + spec, err := ebpf.LoadCollectionSpecFromReader(r) |
| 46 | + if err != nil { |
| 47 | + return nil, xerrors.Errorf("load collection from reader: %w", err) |
| 48 | + } |
| 49 | + |
| 50 | + objs := &bpfObjects{ |
| 51 | + closeLock: sync.Mutex{}, |
| 52 | + closed: make(chan struct{}), |
| 53 | + } |
| 54 | + err = spec.LoadAndAssign(objs, collectionOpts) |
| 55 | + if err != nil { |
| 56 | + return nil, xerrors.Errorf("load and assign specs: %w", err) |
| 57 | + } |
| 58 | + |
| 59 | + return objs, nil |
| 60 | +} |
| 61 | + |
| 62 | +type bpfObjects struct { |
| 63 | + EnterExecveProg *ebpf.Program `ebpf:"enter_execve"` |
| 64 | + EventsMap *ebpf.Map `ebpf:"events"` |
| 65 | + FiltersMap *ebpf.Map `ebpf:"filters"` |
| 66 | + |
| 67 | + closeLock sync.Mutex |
| 68 | + closed chan struct{} |
| 69 | +} |
| 70 | + |
| 71 | +func (o *bpfObjects) Close() error { |
| 72 | + o.closeLock.Lock() |
| 73 | + defer o.closeLock.Unlock() |
| 74 | + select { |
| 75 | + case <-o.closed: |
| 76 | + return errObjectsClosed |
| 77 | + default: |
| 78 | + } |
| 79 | + close(o.closed) |
| 80 | + runtime.SetFinalizer(o, nil) |
| 81 | + |
| 82 | + var merr error |
| 83 | + if o.EnterExecveProg != nil { |
| 84 | + err := o.EnterExecveProg.Close() |
| 85 | + if err != nil { |
| 86 | + merr = multierror.Append(merr, xerrors.Errorf(`close BPF program "enter_execve": %w`, err)) |
| 87 | + } |
| 88 | + } |
| 89 | + if o.EventsMap != nil { |
| 90 | + err := o.EventsMap.Close() |
| 91 | + if err != nil { |
| 92 | + merr = multierror.Append(merr, xerrors.Errorf(`close BPF map "events": %w`, err)) |
| 93 | + } |
| 94 | + } |
4 | 95 |
|
5 |
| -// LoadBPFObjectsBytes is a helper for LoadBPFObjects that automatically wraps |
6 |
| -// the given byte slice with a bytes.Reader. |
7 |
| -func LoadBPFObjectsBytes(p []byte) (BPFObjects, error) { |
8 |
| - return LoadBPFObjects(bytes.NewReader(p)) |
| 96 | + return merr |
9 | 97 | }
|
0 commit comments