eBPF for Windows
Loading...
Searching...
No Matches
ebpf_extension.h
Go to the documentation of this file.
1// Copyright (c) eBPF for Windows contributors
2// SPDX-License-Identifier: MIT
3#pragma once
4
5#include "ebpf_result.h"
6#include "ebpf_structs.h"
7#include "ebpf_windows.h"
8
9#define EBPF_MAP_OPERATION_HELPER 0x01 /* Called by a BPF program. */
10#define EBPF_MAP_OPERATION_UPDATE 0x02 /* Update operation. */
11#define EBPF_MAP_OPERATION_MAP_CLEANUP 0x04 /* Map cleanup operation. */
12
14
15typedef uint64_t epoch_state_t[4];
16
23
37 _In_ const void* extension_client_binding_context, _Inout_ void* program_context, _Out_ uint32_t* result);
38
51 size_t state_size, _Out_writes_(state_size) void* state);
52
65 _In_ const void* extension_client_binding_context,
66 _Inout_ void* program_context,
67 _Out_ uint32_t* result,
68 _In_ const void* state);
69
78
85
86#define EBPF_LINK_DISPATCH_TABLE_FUNCTION_COUNT_1 4
87#define EBPF_LINK_DISPATCH_TABLE_FUNCTION_COUNT_CURRENT \
88 EBPF_LINK_DISPATCH_TABLE_FUNCTION_COUNT_1
89
99
107
115
116/***
117 * The state of the execution context when the eBPF program was invoked.
118 * This is used to cache state that won't change during the execution of
119 * the eBPF program and is expensive to query.
120 */
122{
124 union
125 {
126 uint64_t thread;
127 uint32_t cpu;
128 } id;
130 struct
131 {
132 const void* next_program;
133 uint32_t count;
136
137#define EBPF_CONTEXT_HEADER uint64_t context_header[8]
138#define EBPF_CONTEXT_HEADER_SIZE (sizeof(uint64_t) * 8)
139
164 _In_ void* binding_context,
165 uint32_t map_type,
166 uint32_t key_size,
167 uint32_t value_size,
168 uint32_t max_entries,
169 _Out_ uint32_t* actual_value_size,
170 _Outptr_ void** map_context);
171
178typedef void (*ebpf_process_map_delete_t)(_In_ void* binding_context, _In_ _Post_invalid_ void* map_context);
179
203 _In_ void* binding_context,
204 _In_ void* map_context,
205 size_t key_size,
206 _In_reads_opt_(key_size) const uint8_t* key,
207 size_t in_value_size,
208 _In_reads_(in_value_size) const uint8_t* in_value,
209 size_t out_value_size,
210 _Out_writes_opt_(out_value_size) uint8_t* out_value,
211 uint32_t flags);
212
237 _In_ void* binding_context,
238 _In_ void* map_context,
239 size_t key_size,
240 _In_reads_opt_(key_size) const uint8_t* key,
241 size_t in_value_size,
242 _In_reads_(in_value_size) const uint8_t* in_value,
243 size_t out_value_size,
244 _Out_writes_opt_(out_value_size) uint8_t* out_value,
245 uint32_t flags);
246
274 _In_ void* binding_context,
275 _In_ void* map_context,
276 size_t key_size,
277 _In_reads_opt_(key_size) const uint8_t* key,
278 size_t value_size,
279 _In_reads_(value_size) const uint8_t* value,
280 uint32_t flags);
281
293 _In_ void* binding_context, _In_ void* map_context, _In_ const ebpf_program_type_t* program_type);
294
296{
298 bool updates_original_value; // Whether the provider updates the original value during map operations, which
299 // controls whether BPF programs can perform map CRUD operations.
301
316
325typedef _Ret_writes_maybenull_(size) void* (*ebpf_epoch_allocate_with_tag_t)(size_t size, uint32_t tag);
326
335typedef _Ret_writes_maybenull_(size) void* (*ebpf_epoch_allocate_cache_aligned_with_tag_t)(size_t size, uint32_t tag);
336
341typedef void (*ebpf_epoch_free_t)(_In_opt_ _Post_invalid_ void* memory);
342
347typedef void (*ebpf_epoch_free_cache_aligned_t)(_In_opt_ _Post_invalid_ void* pointer);
348
353typedef void (*ebpf_epoch_enter_t)(_Out_ void* epoch_state);
354
359typedef void (*ebpf_epoch_exit_t)(_In_ void* epoch_state);
360
373 _In_ const void* map, _In_ const uint8_t* key, _Outptr_ uint8_t** value);
374
411
423
433
434#define MAP_CONTEXT(map_pointer, offset) ((void**)(((uint8_t*)(map_pointer)) + (offset)))
struct _ebpf_base_map_provider_properties ebpf_base_map_provider_properties_t
ebpf_result_t(* ebpf_program_batch_begin_invoke_function_t)(size_t state_size, _Out_writes_(state_size) void *state)
Prepare the eBPF program for batch invocation.
Definition ebpf_extension.h:50
struct _ebpf_attach_provider_data ebpf_attach_provider_data_t
ebpf_result_t(* ebpf_process_map_create_t)(void *binding_context, uint32_t map_type, uint32_t key_size, uint32_t value_size, uint32_t max_entries, uint32_t *actual_value_size, void **map_context)
Process map creation notification.
Definition ebpf_extension.h:163
ebpf_result_t(* ebpf_process_map_delete_element_t)(void *binding_context, void *map_context, size_t key_size, _In_reads_opt_(key_size) const uint8_t *key, size_t value_size, _In_reads_(value_size) const uint8_t *value, uint32_t flags)
Delete an element from a provider-backed map.
Definition ebpf_extension.h:273
ebpf_result_t(* ebpf_map_find_element_t)(const void *map, const uint8_t *key, uint8_t **value)
Find an element in an eBPF map (client/runtime helper version).
Definition ebpf_extension.h:372
ebpf_result_t(* ebpf_process_map_find_element_t)(void *binding_context, void *map_context, size_t key_size, _In_reads_opt_(key_size) const uint8_t *key, size_t in_value_size, _In_reads_(in_value_size) const uint8_t *in_value, size_t out_value_size, _Out_writes_opt_(out_value_size) uint8_t *out_value, uint32_t flags)
Find (lookup) an element in a provider-backed map.
Definition ebpf_extension.h:202
struct _ebpf_map_provider_dispatch_table ebpf_base_map_provider_dispatch_table_t
struct _ebpf_extension_dispatch_table ebpf_extension_dispatch_table_t
ebpf_result_t(* ebpf_process_map_add_element_t)(void *binding_context, void *map_context, size_t key_size, _In_reads_opt_(key_size) const uint8_t *key, size_t in_value_size, _In_reads_(in_value_size) const uint8_t *in_value, size_t out_value_size, _Out_writes_opt_(out_value_size) uint8_t *out_value, uint32_t flags)
Add or update (insert/replace) an element in a provider-backed map.
Definition ebpf_extension.h:236
void(* ebpf_epoch_exit_t)(void *epoch_state)
Exit an epoch-protected region.
Definition ebpf_extension.h:359
void(* ebpf_epoch_free_t)(void *memory)
Free memory under epoch control.
Definition ebpf_extension.h:341
struct _ebpf_map_client_data ebpf_map_client_data_t
Custom map client data.
struct _ebpf_extension_data ebpf_extension_data_t
struct _ebpf_extension_program_dispatch_table ebpf_extension_program_dispatch_table_t
enum _ebpf_link_dispatch_table_version ebpf_link_dispatch_table_version_t
ebpf_result_t(* _ebpf_extension_dispatch_function)()
Definition ebpf_extension.h:13
typedef _Ret_writes_maybenull_(size) void *(*ebpf_epoch_allocate_with_tag_t)(size_t size
Allocate memory under epoch control.
struct _ebpf_map_client_dispatch_table ebpf_base_map_client_dispatch_table_t
ebpf_result_t(* ebpf_program_batch_invoke_function_t)(const void *extension_client_binding_context, _Inout_ void *program_context, uint32_t *result, const void *state)
Invoke the eBPF program in batch mode.
Definition ebpf_extension.h:64
uint32_t tag
Definition ebpf_extension.h:325
struct _ebpf_map_provider_data ebpf_map_provider_data_t
Custom map provider data.
void(* ebpf_process_map_delete_t)(void *binding_context, void *map_context)
Process a map delete notification.
Definition ebpf_extension.h:178
struct _ebpf_execution_context_state ebpf_execution_context_state_t
void(* ebpf_epoch_enter_t)(void *epoch_state)
Enter an epoch-protected region.
Definition ebpf_extension.h:353
ebpf_result_t(* ebpf_program_batch_end_invoke_function_t)(_Inout_ void *state)
Clean up the eBPF program after batch invocation.
Definition ebpf_extension.h:77
uint64_t epoch_state_t[4]
Definition ebpf_extension.h:15
ebpf_result_t(* ebpf_map_associate_program_type_t)(void *binding_context, void *map_context, const ebpf_program_type_t *program_type)
Associate a program type with the map, which allows the map to be used by programs of that type.
Definition ebpf_extension.h:292
ebpf_result_t(* ebpf_program_invoke_function_t)(const void *extension_client_binding_context, _Inout_ void *program_context, uint32_t *result)
Invoke the eBPF program.
Definition ebpf_extension.h:36
_ebpf_link_dispatch_table_version
Definition ebpf_extension.h:80
@ EBPF_LINK_DISPATCH_TABLE_VERSION_1
Initial version of the dispatch table.
Definition ebpf_extension.h:81
@ EBPF_LINK_DISPATCH_TABLE_VERSION_CURRENT
Current version of the dispatch table.
Definition ebpf_extension.h:82
void(* ebpf_epoch_free_cache_aligned_t)(void *pointer)
Free memory under epoch control.
Definition ebpf_extension.h:347
enum ebpf_result ebpf_result_t
This file contains eBPF definitions common to eBPF programs, core execution engine as well as eBPF AP...
bpf_link_type
Definition ebpf_structs.h:272
enum bpf_attach_type bpf_attach_type_t
Definition ebpf_structs.h:353
GUID ebpf_program_type_t
Definition ebpf_windows.h:61
Definition ebpf_extension.h:109
ebpf_extension_header_t header
Definition ebpf_extension.h:110
ebpf_program_type_t supported_program_type
Definition ebpf_extension.h:111
bpf_attach_type_t bpf_attach_type
Definition ebpf_extension.h:112
enum bpf_link_type link_type
Definition ebpf_extension.h:113
Definition ebpf_extension.h:296
bool updates_original_value
Definition ebpf_extension.h:298
ebpf_extension_header_t header
Definition ebpf_extension.h:297
Definition ebpf_extension.h:122
union _ebpf_execution_context_state::@6 id
struct _ebpf_execution_context_state::@7 tail_call_state
uint8_t current_irql
Definition ebpf_extension.h:129
uint32_t count
Definition ebpf_extension.h:133
epoch_state_t epoch_state
Definition ebpf_extension.h:123
uint64_t thread
Definition ebpf_extension.h:126
const void * next_program
Definition ebpf_extension.h:132
uint32_t cpu
Definition ebpf_extension.h:127
Definition ebpf_extension.h:101
uint64_t prog_attach_flags
Definition ebpf_extension.h:105
ebpf_extension_header_t header
Definition ebpf_extension.h:102
const void * data
Definition ebpf_extension.h:103
size_t data_size
Definition ebpf_extension.h:104
Definition ebpf_extension.h:18
uint16_t version
Version of the dispatch table.
Definition ebpf_extension.h:19
uint16_t count
Number of entries in the dispatch table.
Definition ebpf_extension.h:20
_Field_size_(count) _ebpf_extension_dispatch_function function[1]
Header of an eBPF extension data structure. Every eBPF extension data structure must start with this ...
Definition ebpf_windows.h:196
Definition ebpf_extension.h:91
ebpf_program_invoke_function_t ebpf_program_invoke_function
Definition ebpf_extension.h:94
ebpf_program_batch_begin_invoke_function_t ebpf_program_batch_begin_invoke_function
Definition ebpf_extension.h:95
ebpf_program_batch_end_invoke_function_t ebpf_program_batch_end_invoke_function
Definition ebpf_extension.h:97
uint16_t version
Version of the dispatch table.
Definition ebpf_extension.h:92
ebpf_program_batch_invoke_function_t ebpf_program_batch_invoke_function
Definition ebpf_extension.h:96
uint16_t count
Number of entries in the dispatch table.
Definition ebpf_extension.h:93
Custom map client data.
Definition ebpf_extension.h:428
ebpf_base_map_client_dispatch_table_t * base_client_table
Pointer to base map client dispatch table.
Definition ebpf_extension.h:431
uint64_t map_context_offset
Offset within the map structure where the provider context data is stored.
Definition ebpf_extension.h:430
ebpf_extension_header_t header
Standard extension header containing version and size information.
Definition ebpf_extension.h:429
Definition ebpf_extension.h:401
ebpf_epoch_free_cache_aligned_t epoch_free_cache_aligned
Definition ebpf_extension.h:409
ebpf_epoch_allocate_cache_aligned_with_tag_t epoch_allocate_cache_aligned_with_tag
Definition ebpf_extension.h:407
ebpf_epoch_exit_t epoch_exit
Definition ebpf_extension.h:405
ebpf_epoch_enter_t epoch_enter
Definition ebpf_extension.h:404
ebpf_epoch_allocate_with_tag_t epoch_allocate_with_tag
Definition ebpf_extension.h:406
ebpf_epoch_free_t epoch_free
Definition ebpf_extension.h:408
ebpf_extension_header_t header
Definition ebpf_extension.h:402
ebpf_map_find_element_t find_element_function
Definition ebpf_extension.h:403
Custom map provider data.
Definition ebpf_extension.h:416
ebpf_extension_header_t header
Definition ebpf_extension.h:417
ebpf_base_map_provider_dispatch_table_t * base_provider_table
Pointer to base map provider dispatch table.
Definition ebpf_extension.h:421
uint32_t map_type
Custom map type implemented by the provider.
Definition ebpf_extension.h:418
uint32_t base_map_type
Base map type used to implement the custom map.
Definition ebpf_extension.h:419
ebpf_base_map_provider_properties_t * base_properties
Base map provider properties.
Definition ebpf_extension.h:420
Definition ebpf_extension.h:307
_Notnull_ ebpf_map_associate_program_type_t associate_program_function
Definition ebpf_extension.h:311
_Notnull_ ebpf_process_map_delete_t process_map_delete
Definition ebpf_extension.h:310
ebpf_process_map_add_element_t process_map_add_element
Definition ebpf_extension.h:313
_Notnull_ ebpf_process_map_create_t process_map_create
Definition ebpf_extension.h:309
ebpf_process_map_delete_element_t process_map_delete_element
Definition ebpf_extension.h:314
ebpf_extension_header_t header
Definition ebpf_extension.h:308
ebpf_process_map_find_element_t process_map_find_element
Definition ebpf_extension.h:312