tree: 895feb838fbb2b8cd32c900cac34fbb61aca9432 [path history] [tgz]
  1. android/
  2. arm64/
  3. loongarch/
  4. powerpc/
  5. riscv/
  6. x86/
  7. .gitignore
  8. Android.bp
  9. bashreadline.bpf.c
  10. bashreadline.c
  11. bashreadline.h
  12. bindsnoop.bpf.c
  13. bindsnoop.c
  14. bindsnoop.h
  15. biolatency.bpf.c
  16. biolatency.c
  17. biolatency.h
  18. biopattern.bpf.c
  19. biopattern.c
  20. biopattern.h
  21. biosnoop.bpf.c
  22. biosnoop.c
  23. biosnoop.h
  24. biostacks.bpf.c
  25. biostacks.c
  26. biostacks.h
  27. biotop.bpf.c
  28. biotop.c
  29. biotop.h
  30. bitesize.bpf.c
  31. bitesize.c
  32. bitesize.h
  33. bits.bpf.h
  34. blk_types.h
  35. btf_helpers.c
  36. btf_helpers.h
  37. cachestat.bpf.c
  38. cachestat.c
  39. capable.bpf.c
  40. capable.c
  41. capable.h
  42. compat.bpf.h
  43. compat.c
  44. compat.h
  45. core_fixes.bpf.h
  46. cpudist.bpf.c
  47. cpudist.c
  48. cpudist.h
  49. cpufreq.bpf.c
  50. cpufreq.c
  51. cpufreq.h
  52. drsnoop.bpf.c
  53. drsnoop.c
  54. drsnoop.h
  55. drsnoop_example.txt
  56. errno_helpers.c
  57. errno_helpers.h
  58. execsnoop.bpf.c
  59. execsnoop.c
  60. execsnoop.h
  61. exitsnoop.bpf.c
  62. exitsnoop.c
  63. exitsnoop.h
  64. filelife.bpf.c
  65. filelife.c
  66. filelife.h
  67. filetop.bpf.c
  68. filetop.c
  69. filetop.h
  70. fsdist.bpf.c
  71. fsdist.c
  72. fsdist.h
  73. fsslower.bpf.c
  74. fsslower.c
  75. fsslower.h
  76. funclatency.bpf.c
  77. funclatency.c
  78. funclatency.h
  79. gethostlatency.bpf.c
  80. gethostlatency.c
  81. gethostlatency.h
  82. hardirqs.bpf.c
  83. hardirqs.c
  84. hardirqs.h
  85. javagc.bpf.c
  86. javagc.c
  87. javagc.h
  88. kernel.config
  89. klockstat.bpf.c
  90. klockstat.c
  91. klockstat.h
  92. ksnoop.bpf.c
  93. ksnoop.c
  94. ksnoop.h
  95. llcstat.bpf.c
  96. llcstat.c
  97. llcstat.h
  98. Makefile
  99. Makefile.btfgen
  100. map_helpers.c
  101. map_helpers.h
  102. maps.bpf.h
  103. mdflush.bpf.c
  104. mdflush.c
  105. mdflush.h
  106. memleak.bpf.c
  107. memleak.c
  108. memleak.h
  109. mountsnoop.bpf.c
  110. mountsnoop.c
  111. mountsnoop.h
  112. numamove.bpf.c
  113. numamove.c
  114. offcputime.bpf.c
  115. offcputime.c
  116. offcputime.h
  117. oomkill.bpf.c
  118. oomkill.c
  119. oomkill.h
  120. opensnoop.bpf.c
  121. opensnoop.c
  122. opensnoop.h
  123. readahead.bpf.c
  124. readahead.c
  125. readahead.h
  126. README.md
  127. runqlat.bpf.c
  128. runqlat.c
  129. runqlat.h
  130. runqlen.bpf.c
  131. runqlen.c
  132. runqlen.h
  133. runqslower.bpf.c
  134. runqslower.c
  135. runqslower.h
  136. runqslower_example.txt
  137. sigsnoop.bpf.c
  138. sigsnoop.c
  139. sigsnoop.h
  140. sigsnoop_example.txt
  141. slabratetop.bpf.c
  142. slabratetop.c
  143. slabratetop.h
  144. softirqs.bpf.c
  145. softirqs.c
  146. softirqs.h
  147. solisten.bpf.c
  148. solisten.c
  149. solisten.h
  150. stat.h
  151. statsnoop.bpf.c
  152. statsnoop.c
  153. statsnoop.h
  154. syscall_helpers.c
  155. syscall_helpers.h
  156. syscount.bpf.c
  157. syscount.c
  158. syscount.h
  159. tcpconnect.bpf.c
  160. tcpconnect.c
  161. tcpconnect.h
  162. tcpconnlat.bpf.c
  163. tcpconnlat.c
  164. tcpconnlat.h
  165. tcplife.bpf.c
  166. tcplife.c
  167. tcplife.h
  168. tcppktlat.bpf.c
  169. tcppktlat.c
  170. tcppktlat.h
  171. tcppktlat_example.txt
  172. tcprtt.bpf.c
  173. tcprtt.c
  174. tcprtt.h
  175. tcpstates.bpf.c
  176. tcpstates.c
  177. tcpstates.h
  178. tcpsynbl.bpf.c
  179. tcpsynbl.c
  180. tcpsynbl.h
  181. tcptop.bpf.c
  182. tcptop.c
  183. tcptop.h
  184. tcptracer.bpf.c
  185. tcptracer.c
  186. tcptracer.h
  187. trace_helpers.c
  188. trace_helpers.h
  189. uprobe_helpers.c
  190. uprobe_helpers.h
  191. vfsstat.bpf.c
  192. vfsstat.c
  193. vfsstat.h
  194. wakeuptime.bpf.c
  195. wakeuptime.c
  196. wakeuptime.h
libbpf-tools/README.md

Useful links

Building

To build libbpf-based tools, simply run make. This will build all the listed tools/applications. All the build artifacts, by default, go into .output subdirectory to keep source code and build artifacts completely separate. The only exception is resulting tool binaries, which are put in a current directory. make clean will clean up all the build artifacts, including generated binaries.

Given that the libbpf package might not be available across wide variety of distributions, all libbpf-based tools are linked statically against a version of libbpf that BCC links against (from submodule under src/cc/libbpf). This results in binaries with minimal amount of dependencies (libc, libelf, and libz are linked dynamically, though, given their widespread availability). If your build fails because the libbpf submodule is outdated, try running git submodule update --init --recursive.

Tools are expected to follow a simple naming convention:

  • .c contains userspace C code of a tool.
  • .bpf.c contains BPF C code, which gets compiled into BPF ELF file. This ELF file is used to generate BPF skeleton .skel.h, which is subsequently is included from .c.
  • .h can optionally contain any types and constants, shared by both BPF and userspace sides of a tool.

For such cases, simply adding name to Makefile's APPS variable will ensure this tool is built alongside others.

For more complicated applications, some extra Makefile rules might need to be created. For such cases, it is advised to put application into a dedicated subdirectory and link it from main Makefile.

vmlinux.h generation

vmlinux.h contains all kernel types, both exported and internal-only. BPF CO-RE-based applications are expected to include this file in their BPF program C source code to avoid dependency on kernel headers package.

For more reproducible builds, vmlinux.h header file is pre-generated and checked in along the other sources. This is done to avoid dependency on specific user/build server's kernel configuration, because vmlinux.h generation depends on having a kernel with BTF type information built-in (which is enabled by CONFIG_DEBUG_INFO_BTF=y Kconfig option See below).

vmlinux.h is generated from upstream Linux version at particular minor version tag. E.g., vmlinux_505.h is generated from v5.5 tag. Exact set of types available in compiled kernel depends on configuration used to compile it. To generate present vmlinux.h header, default configuration was used, with only extra CONFIG_DEBUG_INFO_BTF=y option enabled.

Given different kernel version can have incompatible type definitions, it might be important to use vmlinux.h of a specific kernel version as a “base” version of header. To that extent, all vmlinux.h headers are versioned by appending suffix to a file name. There is always a symbolic link vmlinux.h, that points to whichever version is deemed to be default (usually, latest).

bpftool

bpftool is a universal tool used for inspection of BPF resources, as well as providing various extra BPF-related facilities, like code-generation of BPF program skeletons. The latter functionality is heavily used by these tools to load and interact with BPF programs.

Given bpftool package can't yet be expected to be available widely across many distributions, bpftool binary is checked in into BCC repository in bin/ subdirectory. Once bpftool package is more widely available, this can be changed in favor of using pre-packaged version of bpftool.

Re-compiling your Kernel with CONFIG_DEBUG_INFO_BTF=y

libbpf probes to see if your sys fs exports the file /sys/kernel/btf/vmlinux (from Kernel 5.5+) or if you have the ELF version in your system code Please note the ELF file could exist without the BTF info in it. Your Kconfig should contain the options below

  1. Compile options
CONFIG_DEBUG_INFO_BTF=y
CONFIG_DEBUG_INFO=y
  1. Also, make sure that you have pahole 1.13 (or preferably 1.16+) during the kernel build (it comes from dwarves package). Without it, BTF won‘t be generated, and on older kernels you’d get only warning, but still would build kernel successfully

Running in kernels without CONFIG_DEBUG_INFO_BTF=y

It‘s possible to run some tools in kernels that don’t expose /sys/kernel/btf/vmlinux. For those cases, BTFGen and BTFHub can be used to generate small BTF files for the most popular Linux distributions that are shipped with the tools in order to provide the needed information to perform the CO-RE relocations when loading the eBPF programs.

If you haven‘t cloned the btfhub-archive repository, you can run make and it’ll clone it for you into the $HOME/.local/share directory:

make ENABLE_MIN_CORE_BTFS=1 -j$(nproc)

If you have a local copy of such repository, you can pass it's location to avoid cloning it again:

make ENABLE_MIN_CORE_BTFS=1 BTF_HUB_ARCHIVE=<path_to_btfhub-archive> -j$(nproc)