expand.rs 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525
  1. use proc_macro2::TokenStream;
  2. use quote::quote;
  3. use syn::{
  4. parse::{Parse, ParseStream},
  5. punctuated::{Pair, Punctuated},
  6. token::Eq,
  7. Error, Ident, ItemFn, ItemStatic, LitStr, Result, Token,
  8. };
  9. pub struct NameValue {
  10. name: Ident,
  11. _eq: Eq,
  12. value: LitStr,
  13. }
  14. pub struct Args {
  15. args: Vec<NameValue>,
  16. }
  17. impl Parse for Args {
  18. fn parse(input: ParseStream) -> Result<Args> {
  19. let args = Punctuated::<NameValue, Token![,]>::parse_terminated_with(input, |input| {
  20. Ok(NameValue {
  21. name: input.parse()?,
  22. _eq: input.parse()?,
  23. value: input.parse()?,
  24. })
  25. })?
  26. .into_pairs()
  27. .map(|pair| match pair {
  28. Pair::Punctuated(name_val, _) => name_val,
  29. Pair::End(name_val) => name_val,
  30. })
  31. .collect();
  32. Ok(Args { args })
  33. }
  34. }
  35. pub struct Map {
  36. item: ItemStatic,
  37. name: String,
  38. }
  39. impl Map {
  40. pub fn from_syn(mut args: Args, item: ItemStatic) -> Result<Map> {
  41. let name = name_arg(&mut args)?.unwrap_or_else(|| item.ident.to_string());
  42. Ok(Map { item, name })
  43. }
  44. pub fn expand(&self) -> Result<TokenStream> {
  45. let section_name = format!("maps/{}", self.name);
  46. let item = &self.item;
  47. Ok(quote! {
  48. #[no_mangle]
  49. #[link_section = #section_name]
  50. #item
  51. })
  52. }
  53. }
  54. pub struct Probe {
  55. kind: ProbeKind,
  56. item: ItemFn,
  57. name: String,
  58. }
  59. impl Probe {
  60. pub fn from_syn(kind: ProbeKind, mut args: Args, item: ItemFn) -> Result<Probe> {
  61. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  62. Ok(Probe { kind, item, name })
  63. }
  64. pub fn expand(&self) -> Result<TokenStream> {
  65. let section_name = format!("{}/{}", self.kind, self.name);
  66. let fn_name = &self.item.sig.ident;
  67. let item = &self.item;
  68. Ok(quote! {
  69. #[no_mangle]
  70. #[link_section = #section_name]
  71. fn #fn_name(ctx: *mut ::core::ffi::c_void) -> u32 {
  72. let _ = #fn_name(::aya_bpf::programs::ProbeContext::new(ctx));
  73. return 0;
  74. #item
  75. }
  76. })
  77. }
  78. }
  79. pub struct SockOps {
  80. item: ItemFn,
  81. name: Option<String>,
  82. }
  83. impl SockOps {
  84. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<SockOps> {
  85. let name = name_arg(&mut args)?;
  86. Ok(SockOps { item, name })
  87. }
  88. pub fn expand(&self) -> Result<TokenStream> {
  89. let section_name = if let Some(name) = &self.name {
  90. format!("sockops/{}", name)
  91. } else {
  92. "sockops".to_owned()
  93. };
  94. let fn_name = &self.item.sig.ident;
  95. let item = &self.item;
  96. Ok(quote! {
  97. #[no_mangle]
  98. #[link_section = #section_name]
  99. fn #fn_name(ctx: *mut ::aya_bpf::bindings::bpf_sock_ops) -> u32 {
  100. return #fn_name(::aya_bpf::programs::SockOpsContext::new(ctx));
  101. #item
  102. }
  103. })
  104. }
  105. }
  106. pub struct SkMsg {
  107. item: ItemFn,
  108. name: String,
  109. }
  110. impl SkMsg {
  111. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<SkMsg> {
  112. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  113. Ok(SkMsg { item, name })
  114. }
  115. pub fn expand(&self) -> Result<TokenStream> {
  116. let section_name = format!("sk_msg/{}", self.name);
  117. let fn_name = &self.item.sig.ident;
  118. let item = &self.item;
  119. Ok(quote! {
  120. #[no_mangle]
  121. #[link_section = #section_name]
  122. fn #fn_name(ctx: *mut ::aya_bpf::bindings::sk_msg_md) -> u32 {
  123. return #fn_name(::aya_bpf::programs::SkMsgContext::new(ctx));
  124. #item
  125. }
  126. })
  127. }
  128. }
  129. pub struct Xdp {
  130. item: ItemFn,
  131. name: Option<String>,
  132. }
  133. impl Xdp {
  134. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<Xdp> {
  135. let name = name_arg(&mut args)?;
  136. Ok(Xdp { item, name })
  137. }
  138. pub fn expand(&self) -> Result<TokenStream> {
  139. let section_name = if let Some(name) = &self.name {
  140. format!("xdp/{}", name)
  141. } else {
  142. "xdp".to_owned()
  143. };
  144. let fn_name = &self.item.sig.ident;
  145. let item = &self.item;
  146. Ok(quote! {
  147. #[no_mangle]
  148. #[link_section = #section_name]
  149. fn #fn_name(ctx: *mut ::aya_bpf::bindings::xdp_md) -> u32 {
  150. return #fn_name(::aya_bpf::programs::XdpContext::new(ctx));
  151. #item
  152. }
  153. })
  154. }
  155. }
  156. pub struct SchedClassifier {
  157. item: ItemFn,
  158. name: Option<String>,
  159. }
  160. impl SchedClassifier {
  161. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<SchedClassifier> {
  162. let name = name_arg(&mut args)?;
  163. Ok(SchedClassifier { item, name })
  164. }
  165. pub fn expand(&self) -> Result<TokenStream> {
  166. let section_name = if let Some(name) = &self.name {
  167. format!("classifier/{}", name)
  168. } else {
  169. "classifier".to_owned()
  170. };
  171. let fn_name = &self.item.sig.ident;
  172. let item = &self.item;
  173. Ok(quote! {
  174. #[no_mangle]
  175. #[link_section = #section_name]
  176. fn #fn_name(ctx: *mut ::aya_bpf::bindings::__sk_buff) -> i32 {
  177. return #fn_name(::aya_bpf::programs::SkSkbContext::new(ctx));
  178. #item
  179. }
  180. })
  181. }
  182. }
  183. pub struct CgroupSkb {
  184. item: ItemFn,
  185. expected_attach_type: String,
  186. name: Option<String>,
  187. }
  188. impl CgroupSkb {
  189. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<CgroupSkb> {
  190. let name = pop_arg(&mut args, "name");
  191. let expected_attach_type = pop_arg(&mut args, "attach").unwrap_or_else(|| "skb".to_owned());
  192. Ok(CgroupSkb {
  193. item,
  194. expected_attach_type,
  195. name,
  196. })
  197. }
  198. pub fn expand(&self) -> Result<TokenStream> {
  199. let attach = &self.expected_attach_type;
  200. let section_name = if let Some(name) = &self.name {
  201. format!("cgroup_skb/{}/{}", attach, name)
  202. } else {
  203. format!("cgroup_skb/{}", attach)
  204. };
  205. let fn_name = &self.item.sig.ident;
  206. let item = &self.item;
  207. Ok(quote! {
  208. #[no_mangle]
  209. #[link_section = #section_name]
  210. fn #fn_name(ctx: *mut ::aya_bpf::bindings::__sk_buff) -> i32 {
  211. return #fn_name(::aya_bpf::programs::SkSkbContext::new(ctx));
  212. #item
  213. }
  214. })
  215. }
  216. }
  217. fn pop_arg(args: &mut Args, name: &str) -> Option<String> {
  218. match args.args.iter().position(|arg| arg.name == name) {
  219. Some(index) => Some(args.args.remove(index).value.value()),
  220. None => None,
  221. }
  222. }
  223. fn err_on_unknown_args(args: &Args) -> Result<()> {
  224. if let Some(arg) = args.args.get(0) {
  225. return Err(Error::new_spanned(&arg.name, "invalid argument"));
  226. }
  227. Ok(())
  228. }
  229. fn name_arg(args: &mut Args) -> Result<Option<String>> {
  230. let name = pop_arg(args, "name");
  231. err_on_unknown_args(args)?;
  232. Ok(name)
  233. }
  234. #[allow(clippy::enum_variant_names)]
  235. #[derive(Debug, Copy, Clone)]
  236. pub enum ProbeKind {
  237. KProbe,
  238. KRetProbe,
  239. UProbe,
  240. URetProbe,
  241. }
  242. impl std::fmt::Display for ProbeKind {
  243. fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
  244. use ProbeKind::*;
  245. match self {
  246. KProbe => write!(f, "kprobe"),
  247. KRetProbe => write!(f, "kretprobe"),
  248. UProbe => write!(f, "uprobe"),
  249. URetProbe => write!(f, "uretprobe"),
  250. }
  251. }
  252. }
  253. pub struct TracePoint {
  254. item: ItemFn,
  255. name: String,
  256. }
  257. impl TracePoint {
  258. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<TracePoint> {
  259. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  260. Ok(TracePoint { item, name })
  261. }
  262. pub fn expand(&self) -> Result<TokenStream> {
  263. let section_name = format!("tp/{}", self.name);
  264. let fn_name = &self.item.sig.ident;
  265. let item = &self.item;
  266. Ok(quote! {
  267. #[no_mangle]
  268. #[link_section = #section_name]
  269. fn #fn_name(ctx: *mut ::core::ffi::c_void) -> u32 {
  270. let _ = #fn_name(::aya_bpf::programs::TracePointContext::new(ctx));
  271. return 0;
  272. #item
  273. }
  274. })
  275. }
  276. }
  277. pub struct PerfEvent {
  278. item: ItemFn,
  279. name: String,
  280. }
  281. impl PerfEvent {
  282. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<PerfEvent> {
  283. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  284. Ok(PerfEvent { item, name })
  285. }
  286. pub fn expand(&self) -> Result<TokenStream> {
  287. let section_name = format!("perf_event/{}", self.name);
  288. let fn_name = &self.item.sig.ident;
  289. let item = &self.item;
  290. Ok(quote! {
  291. #[no_mangle]
  292. #[link_section = #section_name]
  293. fn #fn_name(ctx: *mut ::core::ffi::c_void) -> u32 {
  294. let _ = #fn_name(::aya_bpf::programs::PerfEventContext::new(ctx));
  295. return 0;
  296. #item
  297. }
  298. })
  299. }
  300. }
  301. pub struct RawTracePoint {
  302. item: ItemFn,
  303. name: String,
  304. }
  305. impl RawTracePoint {
  306. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<RawTracePoint> {
  307. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  308. Ok(RawTracePoint { item, name })
  309. }
  310. pub fn expand(&self) -> Result<TokenStream> {
  311. let section_name = format!("raw_tp/{}", self.name);
  312. let fn_name = &self.item.sig.ident;
  313. let item = &self.item;
  314. Ok(quote! {
  315. #[no_mangle]
  316. #[link_section = #section_name]
  317. fn #fn_name(ctx: *mut ::core::ffi::c_void) -> u32 {
  318. let _ = #fn_name(::aya_bpf::programs::RawTracePointContext::new(ctx));
  319. return 0;
  320. #item
  321. }
  322. })
  323. }
  324. }
  325. pub struct Lsm {
  326. item: ItemFn,
  327. name: String,
  328. }
  329. impl Lsm {
  330. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<Lsm> {
  331. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  332. Ok(Lsm { item, name })
  333. }
  334. pub fn expand(&self) -> Result<TokenStream> {
  335. let section_name = format!("lsm/{}", self.name);
  336. let fn_name = &self.item.sig.ident;
  337. let item = &self.item;
  338. // LSM probes need to return an integer corresponding to the correct
  339. // policy decision. Therefore we do not simply default to a return value
  340. // of 0 as in other program types.
  341. Ok(quote! {
  342. #[no_mangle]
  343. #[link_section = #section_name]
  344. fn #fn_name(ctx: *mut ::core::ffi::c_void) -> i32 {
  345. return #fn_name(::aya_bpf::programs::LsmContext::new(ctx));
  346. #item
  347. }
  348. })
  349. }
  350. }
  351. pub struct BtfTracePoint {
  352. item: ItemFn,
  353. name: String,
  354. }
  355. impl BtfTracePoint {
  356. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<BtfTracePoint> {
  357. let name = name_arg(&mut args)?.unwrap_or_else(|| item.sig.ident.to_string());
  358. Ok(BtfTracePoint { item, name })
  359. }
  360. pub fn expand(&self) -> Result<TokenStream> {
  361. let section_name = format!("tp_btf/{}", self.name);
  362. let fn_name = &self.item.sig.ident;
  363. let item = &self.item;
  364. Ok(quote! {
  365. #[no_mangle]
  366. #[link_section = #section_name]
  367. fn #fn_name(ctx: *mut ::core::ffi::c_void) -> i32 {
  368. let _ = #fn_name(::aya_bpf::programs::BtfTracePointContext::new(ctx));
  369. return 0;
  370. #item
  371. }
  372. })
  373. }
  374. }
  375. #[allow(clippy::enum_variant_names)]
  376. #[derive(Debug, Copy, Clone)]
  377. pub enum SkSkbKind {
  378. StreamVerdict,
  379. StreamParser,
  380. }
  381. impl std::fmt::Display for SkSkbKind {
  382. fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
  383. use SkSkbKind::*;
  384. match self {
  385. StreamVerdict => write!(f, "stream_verdict"),
  386. StreamParser => write!(f, "stream_parser"),
  387. }
  388. }
  389. }
  390. pub struct SkSkb {
  391. kind: SkSkbKind,
  392. item: ItemFn,
  393. name: Option<String>,
  394. }
  395. impl SkSkb {
  396. pub fn from_syn(kind: SkSkbKind, mut args: Args, item: ItemFn) -> Result<SkSkb> {
  397. let name = pop_arg(&mut args, "name");
  398. Ok(SkSkb { item, kind, name })
  399. }
  400. pub fn expand(&self) -> Result<TokenStream> {
  401. let kind = &self.kind;
  402. let section_name = if let Some(name) = &self.name {
  403. format!("sk_skb/{}/{}", kind, name)
  404. } else {
  405. format!("sk_skb/{}", kind)
  406. };
  407. let fn_name = &self.item.sig.ident;
  408. let item = &self.item;
  409. Ok(quote! {
  410. #[no_mangle]
  411. #[link_section = #section_name]
  412. fn #fn_name(ctx: *mut ::aya_bpf::bindings::__sk_buff) -> u32 {
  413. return #fn_name(::aya_bpf::programs::SkSkbContext::new(ctx));
  414. #item
  415. }
  416. })
  417. }
  418. }
  419. pub struct SocketFilter {
  420. item: ItemFn,
  421. name: Option<String>,
  422. }
  423. impl SocketFilter {
  424. pub fn from_syn(mut args: Args, item: ItemFn) -> Result<SocketFilter> {
  425. let name = name_arg(&mut args)?;
  426. Ok(SocketFilter { item, name })
  427. }
  428. pub fn expand(&self) -> Result<TokenStream> {
  429. let section_name = if let Some(name) = &self.name {
  430. format!("socket/{}", name)
  431. } else {
  432. "socket".to_owned()
  433. };
  434. let fn_name = &self.item.sig.ident;
  435. let item = &self.item;
  436. Ok(quote! {
  437. #[no_mangle]
  438. #[link_section = #section_name]
  439. fn #fn_name(ctx: *mut ::aya_bpf::bindings::__sk_buff) -> i64 {
  440. return #fn_name(::aya_bpf::programs::SkSkbContext::new(ctx));
  441. #item
  442. }
  443. })
  444. }
  445. }