1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * Minimal BPF JIT image disassembler
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Disassembles BPF JIT compiler emitted opcodes back to asm insn's for
6*4882a593Smuzhiyun * debugging or verification purposes.
7*4882a593Smuzhiyun *
8*4882a593Smuzhiyun * To get the disassembly of the JIT code, do the following:
9*4882a593Smuzhiyun *
10*4882a593Smuzhiyun * 1) `echo 2 > /proc/sys/net/core/bpf_jit_enable`
11*4882a593Smuzhiyun * 2) Load a BPF filter (e.g. `tcpdump -p -n -s 0 -i eth1 host 192.168.20.0/24`)
12*4882a593Smuzhiyun * 3) Run e.g. `bpf_jit_disasm -o` to read out the last JIT code
13*4882a593Smuzhiyun *
14*4882a593Smuzhiyun * Copyright 2013 Daniel Borkmann <borkmann@redhat.com>
15*4882a593Smuzhiyun */
16*4882a593Smuzhiyun
17*4882a593Smuzhiyun #include <stdint.h>
18*4882a593Smuzhiyun #include <stdio.h>
19*4882a593Smuzhiyun #include <stdlib.h>
20*4882a593Smuzhiyun #include <assert.h>
21*4882a593Smuzhiyun #include <unistd.h>
22*4882a593Smuzhiyun #include <string.h>
23*4882a593Smuzhiyun #include <bfd.h>
24*4882a593Smuzhiyun #include <dis-asm.h>
25*4882a593Smuzhiyun #include <regex.h>
26*4882a593Smuzhiyun #include <fcntl.h>
27*4882a593Smuzhiyun #include <sys/klog.h>
28*4882a593Smuzhiyun #include <sys/types.h>
29*4882a593Smuzhiyun #include <sys/stat.h>
30*4882a593Smuzhiyun #include <limits.h>
31*4882a593Smuzhiyun
32*4882a593Smuzhiyun #define CMD_ACTION_SIZE_BUFFER 10
33*4882a593Smuzhiyun #define CMD_ACTION_READ_ALL 3
34*4882a593Smuzhiyun
get_exec_path(char * tpath,size_t size)35*4882a593Smuzhiyun static void get_exec_path(char *tpath, size_t size)
36*4882a593Smuzhiyun {
37*4882a593Smuzhiyun char *path;
38*4882a593Smuzhiyun ssize_t len;
39*4882a593Smuzhiyun
40*4882a593Smuzhiyun snprintf(tpath, size, "/proc/%d/exe", (int) getpid());
41*4882a593Smuzhiyun tpath[size - 1] = 0;
42*4882a593Smuzhiyun
43*4882a593Smuzhiyun path = strdup(tpath);
44*4882a593Smuzhiyun assert(path);
45*4882a593Smuzhiyun
46*4882a593Smuzhiyun len = readlink(path, tpath, size);
47*4882a593Smuzhiyun tpath[len] = 0;
48*4882a593Smuzhiyun
49*4882a593Smuzhiyun free(path);
50*4882a593Smuzhiyun }
51*4882a593Smuzhiyun
get_asm_insns(uint8_t * image,size_t len,int opcodes)52*4882a593Smuzhiyun static void get_asm_insns(uint8_t *image, size_t len, int opcodes)
53*4882a593Smuzhiyun {
54*4882a593Smuzhiyun int count, i, pc = 0;
55*4882a593Smuzhiyun char tpath[PATH_MAX];
56*4882a593Smuzhiyun struct disassemble_info info;
57*4882a593Smuzhiyun disassembler_ftype disassemble;
58*4882a593Smuzhiyun bfd *bfdf;
59*4882a593Smuzhiyun
60*4882a593Smuzhiyun memset(tpath, 0, sizeof(tpath));
61*4882a593Smuzhiyun get_exec_path(tpath, sizeof(tpath));
62*4882a593Smuzhiyun
63*4882a593Smuzhiyun bfdf = bfd_openr(tpath, NULL);
64*4882a593Smuzhiyun assert(bfdf);
65*4882a593Smuzhiyun assert(bfd_check_format(bfdf, bfd_object));
66*4882a593Smuzhiyun
67*4882a593Smuzhiyun init_disassemble_info(&info, stdout, (fprintf_ftype) fprintf);
68*4882a593Smuzhiyun info.arch = bfd_get_arch(bfdf);
69*4882a593Smuzhiyun info.mach = bfd_get_mach(bfdf);
70*4882a593Smuzhiyun info.buffer = image;
71*4882a593Smuzhiyun info.buffer_length = len;
72*4882a593Smuzhiyun
73*4882a593Smuzhiyun disassemble_init_for_target(&info);
74*4882a593Smuzhiyun
75*4882a593Smuzhiyun #ifdef DISASM_FOUR_ARGS_SIGNATURE
76*4882a593Smuzhiyun disassemble = disassembler(info.arch,
77*4882a593Smuzhiyun bfd_big_endian(bfdf),
78*4882a593Smuzhiyun info.mach,
79*4882a593Smuzhiyun bfdf);
80*4882a593Smuzhiyun #else
81*4882a593Smuzhiyun disassemble = disassembler(bfdf);
82*4882a593Smuzhiyun #endif
83*4882a593Smuzhiyun assert(disassemble);
84*4882a593Smuzhiyun
85*4882a593Smuzhiyun do {
86*4882a593Smuzhiyun printf("%4x:\t", pc);
87*4882a593Smuzhiyun
88*4882a593Smuzhiyun count = disassemble(pc, &info);
89*4882a593Smuzhiyun
90*4882a593Smuzhiyun if (opcodes) {
91*4882a593Smuzhiyun printf("\n\t");
92*4882a593Smuzhiyun for (i = 0; i < count; ++i)
93*4882a593Smuzhiyun printf("%02x ", (uint8_t) image[pc + i]);
94*4882a593Smuzhiyun }
95*4882a593Smuzhiyun printf("\n");
96*4882a593Smuzhiyun
97*4882a593Smuzhiyun pc += count;
98*4882a593Smuzhiyun } while(count > 0 && pc < len);
99*4882a593Smuzhiyun
100*4882a593Smuzhiyun bfd_close(bfdf);
101*4882a593Smuzhiyun }
102*4882a593Smuzhiyun
get_klog_buff(unsigned int * klen)103*4882a593Smuzhiyun static char *get_klog_buff(unsigned int *klen)
104*4882a593Smuzhiyun {
105*4882a593Smuzhiyun int ret, len;
106*4882a593Smuzhiyun char *buff;
107*4882a593Smuzhiyun
108*4882a593Smuzhiyun len = klogctl(CMD_ACTION_SIZE_BUFFER, NULL, 0);
109*4882a593Smuzhiyun if (len < 0)
110*4882a593Smuzhiyun return NULL;
111*4882a593Smuzhiyun
112*4882a593Smuzhiyun buff = malloc(len);
113*4882a593Smuzhiyun if (!buff)
114*4882a593Smuzhiyun return NULL;
115*4882a593Smuzhiyun
116*4882a593Smuzhiyun ret = klogctl(CMD_ACTION_READ_ALL, buff, len);
117*4882a593Smuzhiyun if (ret < 0) {
118*4882a593Smuzhiyun free(buff);
119*4882a593Smuzhiyun return NULL;
120*4882a593Smuzhiyun }
121*4882a593Smuzhiyun
122*4882a593Smuzhiyun *klen = ret;
123*4882a593Smuzhiyun return buff;
124*4882a593Smuzhiyun }
125*4882a593Smuzhiyun
get_flog_buff(const char * file,unsigned int * klen)126*4882a593Smuzhiyun static char *get_flog_buff(const char *file, unsigned int *klen)
127*4882a593Smuzhiyun {
128*4882a593Smuzhiyun int fd, ret, len;
129*4882a593Smuzhiyun struct stat fi;
130*4882a593Smuzhiyun char *buff;
131*4882a593Smuzhiyun
132*4882a593Smuzhiyun fd = open(file, O_RDONLY);
133*4882a593Smuzhiyun if (fd < 0)
134*4882a593Smuzhiyun return NULL;
135*4882a593Smuzhiyun
136*4882a593Smuzhiyun ret = fstat(fd, &fi);
137*4882a593Smuzhiyun if (ret < 0 || !S_ISREG(fi.st_mode))
138*4882a593Smuzhiyun goto out;
139*4882a593Smuzhiyun
140*4882a593Smuzhiyun len = fi.st_size + 1;
141*4882a593Smuzhiyun buff = malloc(len);
142*4882a593Smuzhiyun if (!buff)
143*4882a593Smuzhiyun goto out;
144*4882a593Smuzhiyun
145*4882a593Smuzhiyun memset(buff, 0, len);
146*4882a593Smuzhiyun ret = read(fd, buff, len - 1);
147*4882a593Smuzhiyun if (ret <= 0)
148*4882a593Smuzhiyun goto out_free;
149*4882a593Smuzhiyun
150*4882a593Smuzhiyun close(fd);
151*4882a593Smuzhiyun *klen = ret;
152*4882a593Smuzhiyun return buff;
153*4882a593Smuzhiyun out_free:
154*4882a593Smuzhiyun free(buff);
155*4882a593Smuzhiyun out:
156*4882a593Smuzhiyun close(fd);
157*4882a593Smuzhiyun return NULL;
158*4882a593Smuzhiyun }
159*4882a593Smuzhiyun
get_log_buff(const char * file,unsigned int * klen)160*4882a593Smuzhiyun static char *get_log_buff(const char *file, unsigned int *klen)
161*4882a593Smuzhiyun {
162*4882a593Smuzhiyun return file ? get_flog_buff(file, klen) : get_klog_buff(klen);
163*4882a593Smuzhiyun }
164*4882a593Smuzhiyun
put_log_buff(char * buff)165*4882a593Smuzhiyun static void put_log_buff(char *buff)
166*4882a593Smuzhiyun {
167*4882a593Smuzhiyun free(buff);
168*4882a593Smuzhiyun }
169*4882a593Smuzhiyun
get_last_jit_image(char * haystack,size_t hlen,unsigned int * ilen)170*4882a593Smuzhiyun static uint8_t *get_last_jit_image(char *haystack, size_t hlen,
171*4882a593Smuzhiyun unsigned int *ilen)
172*4882a593Smuzhiyun {
173*4882a593Smuzhiyun char *ptr, *pptr, *tmp;
174*4882a593Smuzhiyun off_t off = 0;
175*4882a593Smuzhiyun unsigned int proglen;
176*4882a593Smuzhiyun int ret, flen, pass, ulen = 0;
177*4882a593Smuzhiyun regmatch_t pmatch[1];
178*4882a593Smuzhiyun unsigned long base;
179*4882a593Smuzhiyun regex_t regex;
180*4882a593Smuzhiyun uint8_t *image;
181*4882a593Smuzhiyun
182*4882a593Smuzhiyun if (hlen == 0)
183*4882a593Smuzhiyun return NULL;
184*4882a593Smuzhiyun
185*4882a593Smuzhiyun ret = regcomp(®ex, "flen=[[:alnum:]]+ proglen=[[:digit:]]+ "
186*4882a593Smuzhiyun "pass=[[:digit:]]+ image=[[:xdigit:]]+", REG_EXTENDED);
187*4882a593Smuzhiyun assert(ret == 0);
188*4882a593Smuzhiyun
189*4882a593Smuzhiyun ptr = haystack;
190*4882a593Smuzhiyun memset(pmatch, 0, sizeof(pmatch));
191*4882a593Smuzhiyun
192*4882a593Smuzhiyun while (1) {
193*4882a593Smuzhiyun ret = regexec(®ex, ptr, 1, pmatch, 0);
194*4882a593Smuzhiyun if (ret == 0) {
195*4882a593Smuzhiyun ptr += pmatch[0].rm_eo;
196*4882a593Smuzhiyun off += pmatch[0].rm_eo;
197*4882a593Smuzhiyun assert(off < hlen);
198*4882a593Smuzhiyun } else
199*4882a593Smuzhiyun break;
200*4882a593Smuzhiyun }
201*4882a593Smuzhiyun
202*4882a593Smuzhiyun ptr = haystack + off - (pmatch[0].rm_eo - pmatch[0].rm_so);
203*4882a593Smuzhiyun ret = sscanf(ptr, "flen=%d proglen=%u pass=%d image=%lx",
204*4882a593Smuzhiyun &flen, &proglen, &pass, &base);
205*4882a593Smuzhiyun if (ret != 4) {
206*4882a593Smuzhiyun regfree(®ex);
207*4882a593Smuzhiyun return NULL;
208*4882a593Smuzhiyun }
209*4882a593Smuzhiyun if (proglen > 1000000) {
210*4882a593Smuzhiyun printf("proglen of %d too big, stopping\n", proglen);
211*4882a593Smuzhiyun return NULL;
212*4882a593Smuzhiyun }
213*4882a593Smuzhiyun
214*4882a593Smuzhiyun image = malloc(proglen);
215*4882a593Smuzhiyun if (!image) {
216*4882a593Smuzhiyun printf("Out of memory\n");
217*4882a593Smuzhiyun return NULL;
218*4882a593Smuzhiyun }
219*4882a593Smuzhiyun memset(image, 0, proglen);
220*4882a593Smuzhiyun
221*4882a593Smuzhiyun tmp = ptr = haystack + off;
222*4882a593Smuzhiyun while ((ptr = strtok(tmp, "\n")) != NULL && ulen < proglen) {
223*4882a593Smuzhiyun tmp = NULL;
224*4882a593Smuzhiyun if (!strstr(ptr, "JIT code"))
225*4882a593Smuzhiyun continue;
226*4882a593Smuzhiyun pptr = ptr;
227*4882a593Smuzhiyun while ((ptr = strstr(pptr, ":")))
228*4882a593Smuzhiyun pptr = ptr + 1;
229*4882a593Smuzhiyun ptr = pptr;
230*4882a593Smuzhiyun do {
231*4882a593Smuzhiyun image[ulen++] = (uint8_t) strtoul(pptr, &pptr, 16);
232*4882a593Smuzhiyun if (ptr == pptr) {
233*4882a593Smuzhiyun ulen--;
234*4882a593Smuzhiyun break;
235*4882a593Smuzhiyun }
236*4882a593Smuzhiyun if (ulen >= proglen)
237*4882a593Smuzhiyun break;
238*4882a593Smuzhiyun ptr = pptr;
239*4882a593Smuzhiyun } while (1);
240*4882a593Smuzhiyun }
241*4882a593Smuzhiyun
242*4882a593Smuzhiyun assert(ulen == proglen);
243*4882a593Smuzhiyun printf("%u bytes emitted from JIT compiler (pass:%d, flen:%d)\n",
244*4882a593Smuzhiyun proglen, pass, flen);
245*4882a593Smuzhiyun printf("%lx + <x>:\n", base);
246*4882a593Smuzhiyun
247*4882a593Smuzhiyun regfree(®ex);
248*4882a593Smuzhiyun *ilen = ulen;
249*4882a593Smuzhiyun return image;
250*4882a593Smuzhiyun }
251*4882a593Smuzhiyun
usage(void)252*4882a593Smuzhiyun static void usage(void)
253*4882a593Smuzhiyun {
254*4882a593Smuzhiyun printf("Usage: bpf_jit_disasm [...]\n");
255*4882a593Smuzhiyun printf(" -o Also display related opcodes (default: off).\n");
256*4882a593Smuzhiyun printf(" -O <file> Write binary image of code to file, don't disassemble to stdout.\n");
257*4882a593Smuzhiyun printf(" -f <file> Read last image dump from file or stdin (default: klog).\n");
258*4882a593Smuzhiyun printf(" -h Display this help.\n");
259*4882a593Smuzhiyun }
260*4882a593Smuzhiyun
main(int argc,char ** argv)261*4882a593Smuzhiyun int main(int argc, char **argv)
262*4882a593Smuzhiyun {
263*4882a593Smuzhiyun unsigned int len, klen, opt, opcodes = 0;
264*4882a593Smuzhiyun char *kbuff, *file = NULL;
265*4882a593Smuzhiyun char *ofile = NULL;
266*4882a593Smuzhiyun int ofd;
267*4882a593Smuzhiyun ssize_t nr;
268*4882a593Smuzhiyun uint8_t *pos;
269*4882a593Smuzhiyun uint8_t *image = NULL;
270*4882a593Smuzhiyun
271*4882a593Smuzhiyun while ((opt = getopt(argc, argv, "of:O:")) != -1) {
272*4882a593Smuzhiyun switch (opt) {
273*4882a593Smuzhiyun case 'o':
274*4882a593Smuzhiyun opcodes = 1;
275*4882a593Smuzhiyun break;
276*4882a593Smuzhiyun case 'O':
277*4882a593Smuzhiyun ofile = optarg;
278*4882a593Smuzhiyun break;
279*4882a593Smuzhiyun case 'f':
280*4882a593Smuzhiyun file = optarg;
281*4882a593Smuzhiyun break;
282*4882a593Smuzhiyun default:
283*4882a593Smuzhiyun usage();
284*4882a593Smuzhiyun return -1;
285*4882a593Smuzhiyun }
286*4882a593Smuzhiyun }
287*4882a593Smuzhiyun
288*4882a593Smuzhiyun bfd_init();
289*4882a593Smuzhiyun
290*4882a593Smuzhiyun kbuff = get_log_buff(file, &klen);
291*4882a593Smuzhiyun if (!kbuff) {
292*4882a593Smuzhiyun fprintf(stderr, "Could not retrieve log buffer!\n");
293*4882a593Smuzhiyun return -1;
294*4882a593Smuzhiyun }
295*4882a593Smuzhiyun
296*4882a593Smuzhiyun image = get_last_jit_image(kbuff, klen, &len);
297*4882a593Smuzhiyun if (!image) {
298*4882a593Smuzhiyun fprintf(stderr, "No JIT image found!\n");
299*4882a593Smuzhiyun goto done;
300*4882a593Smuzhiyun }
301*4882a593Smuzhiyun if (!ofile) {
302*4882a593Smuzhiyun get_asm_insns(image, len, opcodes);
303*4882a593Smuzhiyun goto done;
304*4882a593Smuzhiyun }
305*4882a593Smuzhiyun
306*4882a593Smuzhiyun ofd = open(ofile, O_WRONLY | O_CREAT | O_TRUNC, DEFFILEMODE);
307*4882a593Smuzhiyun if (ofd < 0) {
308*4882a593Smuzhiyun fprintf(stderr, "Could not open file %s for writing: ", ofile);
309*4882a593Smuzhiyun perror(NULL);
310*4882a593Smuzhiyun goto done;
311*4882a593Smuzhiyun }
312*4882a593Smuzhiyun pos = image;
313*4882a593Smuzhiyun do {
314*4882a593Smuzhiyun nr = write(ofd, pos, len);
315*4882a593Smuzhiyun if (nr < 0) {
316*4882a593Smuzhiyun fprintf(stderr, "Could not write data to %s: ", ofile);
317*4882a593Smuzhiyun perror(NULL);
318*4882a593Smuzhiyun goto done;
319*4882a593Smuzhiyun }
320*4882a593Smuzhiyun len -= nr;
321*4882a593Smuzhiyun pos += nr;
322*4882a593Smuzhiyun } while (len);
323*4882a593Smuzhiyun close(ofd);
324*4882a593Smuzhiyun
325*4882a593Smuzhiyun done:
326*4882a593Smuzhiyun put_log_buff(kbuff);
327*4882a593Smuzhiyun free(image);
328*4882a593Smuzhiyun return 0;
329*4882a593Smuzhiyun }
330