eBPF for Windows
Loading...
Searching...
No Matches
ebpf_extension.h
Go to the documentation of this file.
1// Copyright (c) eBPF for Windows contributors
2// SPDX-License-Identifier: MIT
3#pragma once
4
5#include "ebpf_result.h"
6#include "ebpf_structs.h"
7#include "ebpf_windows.h"
8
9#define EBPF_MAP_OPERATION_HELPER 0x01 /* Called by a BPF program. When this flag is not set, the provider function is
10 * called in the context of the original user mode process, so the provider may
11 * implicitly use the current process's handle table (e.g., to resolve file
12 * descriptors passed as map values). */
13#define EBPF_MAP_OPERATION_UPDATE 0x02 /* Update operation. */
14#define EBPF_MAP_OPERATION_MAP_CLEANUP 0x04 /* Map cleanup operation. */
18typedef uint64_t epoch_state_t[4];
22 uint16_t version;
23 uint16_t count;
26
40 _In_ const void* extension_client_binding_context, _Inout_ void* program_context, _Out_ uint32_t* result);
41
54 size_t state_size, _Out_writes_(state_size) void* state);
55
68 _In_ const void* extension_client_binding_context,
69 _Inout_ void* program_context,
70 _Out_ uint32_t* result,
71 _In_ const void* state);
72
80typedef ebpf_result_t (*ebpf_program_batch_end_invoke_function_t)(_Inout_ void* state);
89#define EBPF_LINK_DISPATCH_TABLE_FUNCTION_COUNT_1 4
90#define EBPF_LINK_DISPATCH_TABLE_FUNCTION_COUNT_CURRENT \
91 EBPF_LINK_DISPATCH_TABLE_FUNCTION_COUNT_1
95 uint16_t version;
96 uint16_t count;
107 size_t data_size;
118
119/***
120 * The state of the execution context when the eBPF program was invoked.
121 * This is used to cache state that won't change during the execution of
122 * the eBPF program and is expensive to query.
123 */
125{
127 union
129 uint64_t thread;
130 uint32_t cpu;
131 } id;
133 struct
135 const void* next_program;
136 uint32_t count;
139
140#define EBPF_CONTEXT_HEADER uint64_t context_header[8]
141#define EBPF_CONTEXT_HEADER_SIZE (sizeof(uint64_t) * 8)
142
167 _In_ void* binding_context,
168 uint32_t map_type,
169 uint32_t key_size,
170 uint32_t value_size,
171 uint32_t max_entries,
172 _Out_ uint32_t* actual_value_size,
173 _Outptr_ void** map_context);
174
181typedef void (*ebpf_process_map_delete_t)(_In_ void* binding_context, _In_ _Post_invalid_ void* map_context);
182
208 _In_ void* binding_context,
209 _In_ void* map_context,
210 size_t key_size,
211 _In_reads_opt_(key_size) const uint8_t* key,
212 size_t in_value_size,
213 _In_reads_(in_value_size) const uint8_t* in_value,
214 size_t out_value_size,
215 _Out_writes_opt_(out_value_size) uint8_t* out_value,
216 uint32_t flags);
217
244 _In_ void* binding_context,
245 _In_ void* map_context,
246 size_t key_size,
247 _In_reads_opt_(key_size) const uint8_t* key,
248 size_t in_value_size,
249 _In_reads_(in_value_size) const uint8_t* in_value,
250 size_t out_value_size,
251 _Out_writes_opt_(out_value_size) uint8_t* out_value,
252 uint32_t flags);
253
283 _In_ void* binding_context,
284 _In_ void* map_context,
285 size_t key_size,
286 _In_reads_opt_(key_size) const uint8_t* key,
287 size_t value_size,
288 _In_reads_(value_size) const uint8_t* value,
289 uint32_t flags);
290
302 _In_ void* binding_context, _In_ void* map_context, _In_ const ebpf_program_type_t* program_type);
305{
307 bool updates_original_value; // Whether the provider updates the original value during map operations, which
308 // controls whether BPF programs can perform map CRUD operations.
310
325
334typedef _Ret_writes_maybenull_(size) void* (*ebpf_epoch_allocate_with_tag_t)(size_t size, uint32_t tag);
335
344typedef _Ret_writes_maybenull_(size) void* (*ebpf_epoch_allocate_cache_aligned_with_tag_t)(size_t size, uint32_t tag);
345
350typedef void (*ebpf_epoch_free_t)(_In_opt_ _Post_invalid_ void* memory);
351
356typedef void (*ebpf_epoch_free_cache_aligned_t)(_In_opt_ _Post_invalid_ void* pointer);
357
362typedef void (*ebpf_epoch_enter_t)(_Out_ void* epoch_state);
363
368typedef void (*ebpf_epoch_exit_t)(_In_ void* epoch_state);
369
382 _In_ const void* map, _In_ const uint8_t* key, _Outptr_ uint8_t** value);
383
415 ebpf_epoch_allocate_with_tag_t epoch_allocate_with_tag;
416 ebpf_epoch_allocate_cache_aligned_with_tag_t epoch_allocate_cache_aligned_with_tag;
420
427 uint32_t map_type;
428 uint32_t base_map_type;
432
439 uint64_t map_context_offset;
442
443#define MAP_CONTEXT(map_pointer, offset) ((void**)(((uint8_t*)(map_pointer)) + (offset)))
struct _ebpf_base_map_provider_properties ebpf_base_map_provider_properties_t
ebpf_result_t(* ebpf_program_batch_begin_invoke_function_t)(size_t state_size, _Out_writes_(state_size) void *state)
Prepare the eBPF program for batch invocation.
Definition ebpf_extension.h:50
struct _ebpf_attach_provider_data ebpf_attach_provider_data_t
ebpf_result_t(* ebpf_process_map_create_t)(void *binding_context, uint32_t map_type, uint32_t key_size, uint32_t value_size, uint32_t max_entries, uint32_t *actual_value_size, void **map_context)
Process map creation notification.
Definition ebpf_extension.h:163
ebpf_result_t(* ebpf_process_map_delete_element_t)(void *binding_context, void *map_context, size_t key_size, _In_reads_opt_(key_size) const uint8_t *key, size_t value_size, _In_reads_(value_size) const uint8_t *value, uint32_t flags)
Delete an element from a provider-backed map.
Definition ebpf_extension.h:279
ebpf_result_t(* ebpf_map_find_element_t)(const void *map, const uint8_t *key, uint8_t **value)
Find an element in an eBPF map (client/runtime helper version).
Definition ebpf_extension.h:378
ebpf_result_t(* ebpf_process_map_find_element_t)(void *binding_context, void *map_context, size_t key_size, _In_reads_opt_(key_size) const uint8_t *key, size_t in_value_size, _In_reads_(in_value_size) const uint8_t *in_value, size_t out_value_size, _Out_writes_opt_(out_value_size) uint8_t *out_value, uint32_t flags)
Find (lookup) an element in a provider-backed map.
Definition ebpf_extension.h:204
struct _ebpf_map_provider_dispatch_table ebpf_base_map_provider_dispatch_table_t
struct _ebpf_extension_dispatch_table ebpf_extension_dispatch_table_t
ebpf_result_t(* ebpf_process_map_add_element_t)(void *binding_context, void *map_context, size_t key_size, _In_reads_opt_(key_size) const uint8_t *key, size_t in_value_size, _In_reads_(in_value_size) const uint8_t *in_value, size_t out_value_size, _Out_writes_opt_(out_value_size) uint8_t *out_value, uint32_t flags)
Add or update (insert/replace) an element in a provider-backed map.
Definition ebpf_extension.h:240
void(* ebpf_epoch_exit_t)(void *epoch_state)
Exit an epoch-protected region.
Definition ebpf_extension.h:365
void(* ebpf_epoch_free_t)(void *memory)
Free memory under epoch control.
Definition ebpf_extension.h:347
struct _ebpf_map_client_data ebpf_map_client_data_t
Custom map client data.
struct _ebpf_extension_data ebpf_extension_data_t
struct _ebpf_extension_program_dispatch_table ebpf_extension_program_dispatch_table_t
enum _ebpf_link_dispatch_table_version ebpf_link_dispatch_table_version_t
ebpf_result_t(* _ebpf_extension_dispatch_function)()
Definition ebpf_extension.h:13
typedef _Ret_writes_maybenull_(size) void *(*ebpf_epoch_allocate_with_tag_t)(size_t size
Allocate memory under epoch control.
struct _ebpf_map_client_dispatch_table ebpf_base_map_client_dispatch_table_t
ebpf_result_t(* ebpf_program_batch_invoke_function_t)(const void *extension_client_binding_context, _Inout_ void *program_context, uint32_t *result, const void *state)
Invoke the eBPF program in batch mode.
Definition ebpf_extension.h:64
uint32_t tag
Definition ebpf_extension.h:331
struct _ebpf_map_provider_data ebpf_map_provider_data_t
Custom map provider data.
void(* ebpf_process_map_delete_t)(void *binding_context, void *map_context)
Process a map delete notification.
Definition ebpf_extension.h:178
struct _ebpf_execution_context_state ebpf_execution_context_state_t
void(* ebpf_epoch_enter_t)(void *epoch_state)
Enter an epoch-protected region.
Definition ebpf_extension.h:359
ebpf_result_t(* ebpf_program_batch_end_invoke_function_t)(_Inout_ void *state)
Clean up the eBPF program after batch invocation.
Definition ebpf_extension.h:77
uint64_t epoch_state_t[4]
Definition ebpf_extension.h:15
ebpf_result_t(* ebpf_map_associate_program_type_t)(void *binding_context, void *map_context, const ebpf_program_type_t *program_type)
Associate a program type with the map, which allows the map to be used by programs of that type.
Definition ebpf_extension.h:298
ebpf_result_t(* ebpf_program_invoke_function_t)(const void *extension_client_binding_context, _Inout_ void *program_context, uint32_t *result)
Invoke the eBPF program.
Definition ebpf_extension.h:36
_ebpf_link_dispatch_table_version
Definition ebpf_extension.h:80
@ EBPF_LINK_DISPATCH_TABLE_VERSION_1
Initial version of the dispatch table.
Definition ebpf_extension.h:81
@ EBPF_LINK_DISPATCH_TABLE_VERSION_CURRENT
Current version of the dispatch table.
Definition ebpf_extension.h:82
void(* ebpf_epoch_free_cache_aligned_t)(void *pointer)
Free memory under epoch control.
Definition ebpf_extension.h:353
enum ebpf_result ebpf_result_t
This file contains eBPF definitions common to eBPF programs, core execution engine as well as eBPF AP...
bpf_link_type
Definition ebpf_structs.h:272
enum bpf_attach_type bpf_attach_type_t
Definition ebpf_structs.h:353
GUID ebpf_program_type_t
Definition ebpf_windows.h:61
Definition ebpf_extension.h:109
ebpf_extension_header_t header
Definition ebpf_extension.h:110
ebpf_program_type_t supported_program_type
Definition ebpf_extension.h:111
bpf_attach_type_t bpf_attach_type
Definition ebpf_extension.h:112
enum bpf_link_type link_type
Definition ebpf_extension.h:113
Definition ebpf_extension.h:302
bool updates_original_value
Definition ebpf_extension.h:304
ebpf_extension_header_t header
Definition ebpf_extension.h:303
Definition ebpf_extension.h:122
union _ebpf_execution_context_state::@6 id
struct _ebpf_execution_context_state::@7 tail_call_state
uint8_t current_irql
Definition ebpf_extension.h:129
uint32_t count
Definition ebpf_extension.h:133
epoch_state_t epoch_state
Definition ebpf_extension.h:123
uint64_t thread
Definition ebpf_extension.h:126
const void * next_program
Definition ebpf_extension.h:132
uint32_t cpu
Definition ebpf_extension.h:127
Definition ebpf_extension.h:101
uint64_t prog_attach_flags
Definition ebpf_extension.h:105
ebpf_extension_header_t header
Definition ebpf_extension.h:102
const void * data
Definition ebpf_extension.h:103
size_t data_size
Definition ebpf_extension.h:104
Definition ebpf_extension.h:18
uint16_t version
Version of the dispatch table.
Definition ebpf_extension.h:19
uint16_t count
Number of entries in the dispatch table.
Definition ebpf_extension.h:20
_Field_size_(count) _ebpf_extension_dispatch_function function[1]
Header of an eBPF extension data structure. Every eBPF extension data structure must start with this ...
Definition ebpf_windows.h:196
Definition ebpf_extension.h:91
ebpf_program_invoke_function_t ebpf_program_invoke_function
Definition ebpf_extension.h:94
ebpf_program_batch_begin_invoke_function_t ebpf_program_batch_begin_invoke_function
Definition ebpf_extension.h:95
ebpf_program_batch_end_invoke_function_t ebpf_program_batch_end_invoke_function
Definition ebpf_extension.h:97
uint16_t version
Version of the dispatch table.
Definition ebpf_extension.h:92
ebpf_program_batch_invoke_function_t ebpf_program_batch_invoke_function
Definition ebpf_extension.h:96
uint16_t count
Number of entries in the dispatch table.
Definition ebpf_extension.h:93
Custom map client data.
Definition ebpf_extension.h:434
ebpf_base_map_client_dispatch_table_t * base_client_table
Pointer to base map client dispatch table.
Definition ebpf_extension.h:437
uint64_t map_context_offset
Offset within the map structure where the provider context data is stored.
Definition ebpf_extension.h:436
ebpf_extension_header_t header
Standard extension header containing version and size information.
Definition ebpf_extension.h:435
Definition ebpf_extension.h:407
ebpf_epoch_free_cache_aligned_t epoch_free_cache_aligned
Definition ebpf_extension.h:415
ebpf_epoch_allocate_cache_aligned_with_tag_t epoch_allocate_cache_aligned_with_tag
Definition ebpf_extension.h:413
ebpf_epoch_exit_t epoch_exit
Definition ebpf_extension.h:411
ebpf_epoch_enter_t epoch_enter
Definition ebpf_extension.h:410
ebpf_epoch_allocate_with_tag_t epoch_allocate_with_tag
Definition ebpf_extension.h:412
ebpf_epoch_free_t epoch_free
Definition ebpf_extension.h:414
ebpf_extension_header_t header
Definition ebpf_extension.h:408
ebpf_map_find_element_t find_element_function
Definition ebpf_extension.h:409
Custom map provider data.
Definition ebpf_extension.h:422
ebpf_extension_header_t header
Definition ebpf_extension.h:423
ebpf_base_map_provider_dispatch_table_t * base_provider_table
Pointer to base map provider dispatch table.
Definition ebpf_extension.h:427
uint32_t map_type
Custom map type implemented by the provider.
Definition ebpf_extension.h:424
uint32_t base_map_type
Base map type used to implement the custom map.
Definition ebpf_extension.h:425
ebpf_base_map_provider_properties_t * base_properties
Base map provider properties.
Definition ebpf_extension.h:426
Definition ebpf_extension.h:313
_Notnull_ ebpf_map_associate_program_type_t associate_program_function
Definition ebpf_extension.h:317
_Notnull_ ebpf_process_map_delete_t process_map_delete
Definition ebpf_extension.h:316
ebpf_process_map_add_element_t process_map_add_element
Definition ebpf_extension.h:319
_Notnull_ ebpf_process_map_create_t process_map_create
Definition ebpf_extension.h:315
ebpf_process_map_delete_element_t process_map_delete_element
Definition ebpf_extension.h:320
ebpf_extension_header_t header
Definition ebpf_extension.h:314
ebpf_process_map_find_element_t process_map_find_element
Definition ebpf_extension.h:318