• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 // SPDX-License-Identifier: GPL-2.0
2 // Copyright (c) 2020 Wenbo Zhang
3 #include <vmlinux.h>
4 #include <bpf/bpf_helpers.h>
5 #include <bpf/bpf_core_read.h>
6 #include <bpf/bpf_tracing.h>
7 #include "filelife.h"
8 
9 const volatile pid_t targ_tgid = 0;
10 
11 struct {
12 	__uint(type, BPF_MAP_TYPE_HASH);
13 	__uint(max_entries, 8192);
14 	__type(key, struct dentry *);
15 	__type(value, u64);
16 } start SEC(".maps");
17 
18 struct {
19 	__uint(type, BPF_MAP_TYPE_PERF_EVENT_ARRAY);
20 	__uint(key_size, sizeof(u32));
21 	__uint(value_size, sizeof(u32));
22 } events SEC(".maps");
23 
24 static __always_inline int
probe_create(struct inode * dir,struct dentry * dentry)25 probe_create(struct inode *dir, struct dentry *dentry)
26 {
27 	u64 id = bpf_get_current_pid_tgid();
28 	u32 tgid = id >> 32;
29 	u64 ts;
30 
31 	if (targ_tgid && targ_tgid != tgid)
32 		return 0;
33 
34 	ts = bpf_ktime_get_ns();
35 	bpf_map_update_elem(&start, &dentry, &ts, 0);
36 	return 0;
37 }
38 
39 SEC("kprobe/vfs_create")
BPF_KPROBE(vfs_create,struct inode * dir,struct dentry * dentry)40 int BPF_KPROBE(vfs_create, struct inode *dir, struct dentry *dentry)
41 {
42 	return probe_create(dir, dentry);
43 }
44 
45 SEC("kprobe/security_inode_create")
BPF_KPROBE(security_inode_create,struct inode * dir,struct dentry * dentry)46 int BPF_KPROBE(security_inode_create, struct inode *dir,
47 	     struct dentry *dentry)
48 {
49 	return probe_create(dir, dentry);
50 }
51 
52 SEC("kprobe/vfs_unlink")
BPF_KPROBE(vfs_unlink,struct inode * dir,struct dentry * dentry)53 int BPF_KPROBE(vfs_unlink, struct inode *dir, struct dentry *dentry)
54 {
55 	u64 id = bpf_get_current_pid_tgid();
56 	struct event event = {};
57 	const u8 *qs_name_ptr;
58 	u32 tgid = id >> 32;
59 	u64 *tsp, delta_ns;
60 
61 	tsp = bpf_map_lookup_elem(&start, &dentry);
62 	if (!tsp)
63 		return 0;   // missed entry
64 
65 	delta_ns = bpf_ktime_get_ns() - *tsp;
66 	bpf_map_delete_elem(&start, &dentry);
67 
68 	qs_name_ptr = BPF_CORE_READ(dentry, d_name.name);
69 	bpf_probe_read_kernel_str(&event.file, sizeof(event.file), qs_name_ptr);
70 	bpf_get_current_comm(&event.task, sizeof(event.task));
71 	event.delta_ns = delta_ns;
72 	event.tgid = tgid;
73 
74 	/* output */
75 	bpf_perf_event_output(ctx, &events, BPF_F_CURRENT_CPU,
76 			      &event, sizeof(event));
77 	return 0;
78 }
79 
80 char LICENSE[] SEC("license") = "GPL";
81