runtime: add uprobe_multi support - #328
Open
Officeyutong wants to merge 14 commits into
Open
Conversation
yunwei37
force-pushed
the
master
branch
3 times, most recently
from
September 11, 2024 18:08
1354316 to
a6a132b
Compare
yunwei37
marked this pull request as ready for review
April 10, 2025 17:57
yunwei37
force-pushed
the
master
branch
2 times, most recently
from
October 1, 2025 23:45
cbcb1e9 to
20acd88
Compare
maxgio92
reviewed
Mar 24, 2026
|
|
||
| } else { | ||
| SPDLOG_ERROR( | ||
| "Trying to instantiate uprobe multi (entry hook), but uretprobe is not registered"); |
There was a problem hiding this comment.
Suggested change
| "Trying to instantiate uprobe multi (entry hook), but uretprobe is not registered"); | |
| "Trying to instantiate uprobe multi (entry hook), but uprobe is not registered"); |
Shouldn't the message be that way?
maxgio92
reviewed
Mar 24, 2026
Comment on lines
+38
to
+39
| return std::string("<Frida attach private data addr=") + | ||
| std::to_string(addr); |
There was a problem hiding this comment.
Suggested change
| return std::string("<Frida attach private data addr=") + | |
| std::to_string(addr); | |
| return std::string("<Frida attach private data addr=") + | |
| std::to_string(reinterpret_cast<uintptr_t>(addr)) + ">"; |
maxgio92
reviewed
Mar 24, 2026
| // For perf event link, there should be an instantiated target | ||
| auto &[priv_data, attach_type] = | ||
| instantiated_perf_events[handler.target_id]; | ||
| SPDLOG_DEBUG("Attach private data is {}, attach type is ", |
There was a problem hiding this comment.
Suggested change
| SPDLOG_DEBUG("Attach private data is {}, attach type is ", | |
| SPDLOG_DEBUG("Attach private data is {}, attach type is {}", |
maxgio92
reviewed
Mar 24, 2026
| [=](void *mem, size_t mem_size, uint64_t *ret) -> int { | ||
| current_thread_bpf_cookie = cookie; | ||
| int err = prog->bpftime_prog_exec( | ||
| (void *)mem, mem_size, ret); | ||
| return err; | ||
| }, | ||
| *priv_data, attach_type); | ||
| native_ids.emplace_back(attach_id, attach_impl); |
There was a problem hiding this comment.
Don't we need to check if the attach failed, on attach_id?
Member
|
This branch conflicts with AI-generated response; a maintainer will review and follow up later |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
uprobe_multi is a special type of uprobe, which allows hooking multiple userspace functions in a single attach. This PR adds uprobe_multi support for uprobe_attach_impl, the corresponding example, and update CI
Closes #214
See https://lore.kernel.org/bpf/20230424160447.2005755-1-jolsa@kernel.org/ for details
Our design
In the kernel bpf, the attaching of uprobe_multi were implemented through creating a bpf link, and filling all information (such as pid, function offset, attach cookies) in the link opts. You may find it in bpf_program__attach_uprobe_multi
But in bpftime, all attaches are required to have an attach target (a.k.a perf event), so for uprobe_multi that doesn't give us a perf event, we have a slightly different implementation to the kernel: When creating a bpf link, we doesn't only record configurations from bpf_link_create_opts into the handler, but also do we create some perf events for the uprobe_multi links, and record them in the handler. In this way, we tear down a uprobe_multi into several simple uprobe attach targets, and with a total bpf link. This will not affect the hooking performance.
Main changes