Skip to content
Navigation Menu
Toggle navigation
Sign in
In this repository
All GitHub Enterprise
↵
Jump to
↵
No suggested jump to results
In this repository
All GitHub Enterprise
↵
Jump to
↵
In this organization
All GitHub Enterprise
↵
Jump to
↵
In this repository
All GitHub Enterprise
↵
Jump to
↵
Sign in
Reseting focus
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
mariux64
/
linux
Public
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Issues
2
Pull requests
0
Actions
Projects
0
Wiki
Security
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Wiki
Security
Insights
Files
f108662
Breadcrumbs
linux
/
tools
/
testing
/
selftests
/
bpf
/
progs
/
find_vma.c
Copy path
Blame
Blame
Latest commit
History
History
69 lines (54 loc) · 1.49 KB
Breadcrumbs
linux
/
tools
/
testing
/
selftests
/
bpf
/
progs
/
find_vma.c
Top
File metadata and controls
Code
Blame
69 lines (54 loc) · 1.49 KB
Raw
// SPDX-License-Identifier: GPL-2.0 /* Copyright (c) 2021 Facebook */ #include "vmlinux.h" #include <bpf/bpf_helpers.h> #include <bpf/bpf_tracing.h> char _license[] SEC("license") = "GPL"; struct callback_ctx { int dummy; }; #define VM_EXEC 0x00000004 #define DNAME_INLINE_LEN 32 pid_t target_pid = 0; char d_iname[DNAME_INLINE_LEN] = {0}; __u32 found_vm_exec = 0; __u64 addr = 0; int find_zero_ret = -1; int find_addr_ret = -1; static long check_vma(struct task_struct *task, struct vm_area_struct *vma, struct callback_ctx *data) { if (vma->vm_file) bpf_probe_read_kernel_str(d_iname, DNAME_INLINE_LEN - 1, vma->vm_file->f_path.dentry->d_iname); /* check for VM_EXEC */ if (vma->vm_flags & VM_EXEC) found_vm_exec = 1; return 0; } SEC("raw_tp/sys_enter") int handle_getpid(void) { struct task_struct *task = bpf_get_current_task_btf(); struct callback_ctx data = {}; if (task->pid != target_pid) return 0; find_addr_ret = bpf_find_vma(task, addr, check_vma, &data, 0); /* this should return -ENOENT */ find_zero_ret = bpf_find_vma(task, 0, check_vma, &data, 0); return 0; } SEC("perf_event") int handle_pe(void) { struct task_struct *task = bpf_get_current_task_btf(); struct callback_ctx data = {}; if (task->pid != target_pid) return 0; find_addr_ret = bpf_find_vma(task, addr, check_vma, &data, 0); /* In NMI, this should return -EBUSY, as the previous call is using * the irq_work. */ find_zero_ret = bpf_find_vma(task, 0, check_vma, &data, 0); return 0; }
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
You can’t perform that action at this time.