Skip to content

Commit f2b3207

Browse files
authored
Add support for aarch64 (#240)
* Add support for aarch64 * Update version year to 2026 * Use make for building openssl * Require at least SysinternalsEBPF 1.6.1 for Debian
1 parent 6a335d5 commit f2b3207

15 files changed

Lines changed: 279 additions & 65 deletions

‎.container/install-ubuntu-dependencies.sh‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,6 @@ sudo apt-get install -y --no-install-recommends \
2323
clang \
2424
libzstd1 \
2525
libgtest-dev \
26-
libc6-dev-i386 \
2726
apt-transport-https \
2827
dirmngr \
2928
googletest \

‎BUILD.md‎

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,51 @@ cmake ..
7878
make
7979
```
8080

81+
## Cross-build for aarch64 on Ubuntu
82+
83+
First cross-build and stage SysinternalsEBPF as described in its `BUILD.md`.
84+
The commands below assume its staged installation is in
85+
`../SysinternalsEBPF/build-arm64/staging`.
86+
87+
Install the cross compiler and target development libraries:
88+
89+
```shell
90+
sudo dpkg --add-architecture arm64
91+
sudo apt update
92+
sudo apt install crossbuild-essential-arm64 binutils-aarch64-linux-gnu \
93+
libc6-dev-arm64-cross linux-libc-dev-arm64-cross \
94+
libelf-dev:arm64 zlib1g-dev:arm64 libzstd-dev:arm64 \
95+
libjson-glib-dev:arm64 libgtest-dev:arm64 libgmock-dev:arm64
96+
```
97+
98+
Build the eBPF size checker for the build host. It inspects architecture-neutral
99+
eBPF objects during the cross-build and avoids executing aarch64 programs on
100+
the build host:
101+
102+
```shell
103+
cmake -S . -B build-host
104+
cmake --build build-host --target checkEBPFsizes
105+
```
106+
107+
Configure and build the aarch64 targets:
108+
109+
```shell
110+
EBPF_STAGE="$(realpath ../SysinternalsEBPF/build-arm64/staging)"
111+
112+
cmake -S . -B build-arm64 \
113+
-DCMAKE_TOOLCHAIN_FILE=cmake/aarch64-linux-gnu.cmake \
114+
-DOPENSSL_CROSS_COMPILE=aarch64-linux-gnu- \
115+
-DSYSINTERNALS_EBPF_ROOT="$EBPF_STAGE/opt/sysinternalsEBPF" \
116+
-DSYSINTERNALS_EBPF_INCLUDE_DIR="$EBPF_STAGE/usr/local/include" \
117+
-DSYSINTERNALS_EBPF_LIBRARY="$EBPF_STAGE/usr/local/lib/libsysinternalsEBPF.so" \
118+
-DSYSMON_HOST_CHECK_EBPF_SIZES="$PWD/build-host/checkEBPFsizes"
119+
cmake --build build-arm64 --parallel
120+
```
121+
122+
The resulting `sysmon`, `sysmonLogView`, `sysmonUnitTests`, and
123+
`checkEBPFsizes` executables target aarch64. Run those executables and all
124+
runtime tests on an aarch64 Linux host; QEMU is not required.
125+
81126
## Test
82127
```
83128
./sysmonUnitTests

‎CMakeLists.txt‎

Lines changed: 162 additions & 44 deletions
Large diffs are not rendered by default.

‎cmake/aarch64-linux-gnu.cmake‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
set(CMAKE_SYSTEM_NAME Linux)
2+
set(CMAKE_SYSTEM_PROCESSOR aarch64)
3+
4+
set(CMAKE_C_COMPILER aarch64-linux-gnu-gcc)
5+
set(CMAKE_CXX_COMPILER aarch64-linux-gnu-g++)
6+
set(CMAKE_AR aarch64-linux-gnu-ar)
7+
set(CMAKE_LINKER aarch64-linux-gnu-ld)
8+
set(CMAKE_NM aarch64-linux-gnu-nm)
9+
set(CMAKE_OBJCOPY aarch64-linux-gnu-objcopy)
10+
set(CMAKE_OBJDUMP aarch64-linux-gnu-objdump)
11+
set(CMAKE_RANLIB aarch64-linux-gnu-ranlib)
12+
set(CMAKE_STRIP aarch64-linux-gnu-strip)
13+
14+
set(CMAKE_FIND_ROOT_PATH_MODE_PROGRAM NEVER)
15+
set(CMAKE_FIND_ROOT_PATH_MODE_LIBRARY BOTH)
16+
set(CMAKE_FIND_ROOT_PATH_MODE_INCLUDE BOTH)
17+
set(CMAKE_FIND_ROOT_PATH_MODE_PACKAGE BOTH)
18+
19+
set(ENV{PKG_CONFIG_LIBDIR}
20+
"/usr/lib/aarch64-linux-gnu/pkgconfig:/usr/share/pkgconfig")

‎ebpfKern/sysmonEBPF_common.h‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,10 +49,12 @@
4949
#endif
5050

5151
#include <sysinternalsEBPF_common.h>
52+
#ifndef EBPF_CO_RE
5253
#include <stdint.h>
54+
#endif
5355
#include <bpf_helpers.h>
5456
#include <bpf_core_read.h>
55-
#include <asm/unistd_64.h>
57+
#include <asm/unistd.h>
5658
#include <sysinternalsEBPFshared.h>
5759
#include "sysmon_defs.h"
5860

‎ebpfKern/sysmonFileCreate_rawtp.c‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,13 @@ int FileCreateRawExit(struct bpf_our_raw_tracepoint_args *ctx)
4242
}
4343

4444
// only handle file creation events
45+
#ifdef __NR_creat
4546
if (eventArgs->syscallId != __NR_creat) {
4647
return 0;
4748
}
49+
#else
50+
return 0;
51+
#endif
4852

4953
// set the return code
5054
if (bpf_probe_read(&eventArgs->returnCode, sizeof(int64_t), (void *)&SYSCALL_PT_REGS_RC(regs)) != 0){
@@ -66,4 +70,3 @@ int FileCreateRawExit(struct bpf_our_raw_tracepoint_args *ctx)
6670

6771
return 0;
6872
}
69-

‎ebpfKern/sysmonFileDelete_rawtp.c‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,9 +41,13 @@ int FileDeleteRawExit(struct bpf_our_raw_tracepoint_args *ctx)
4141
return 0;
4242

4343
// only handle unlink events
44+
#ifdef __NR_unlink
4445
if (eventArgs->syscallId != __NR_unlink) {
4546
return 0;
4647
}
48+
#else
49+
return 0;
50+
#endif
4751

4852
// set the return code
4953
if (bpf_probe_read(&eventArgs->returnCode, sizeof(int64_t), (void *)&SYSCALL_PT_REGS_RC(regs)) != 0){
@@ -64,4 +68,3 @@ int FileDeleteRawExit(struct bpf_our_raw_tracepoint_args *ctx)
6468

6569
return 0;
6670
}
67-

‎ebpfKern/sysmonFileOpen.c‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,11 +78,15 @@ static inline char* set_FileOpen_info(
7878
// store event time in nanoseconds for comparison
7979
eventTimeNs = bpf_ktime_get_ns() + config->bootNsSinceEpoch;
8080

81+
#ifdef __NR_open
8182
if (eventArgs->syscallId == __NR_open) {
8283
event->m_Flags = (uint32_t)eventArgs->a[1];
8384
} else {
8485
event->m_Flags = (uint32_t)eventArgs->a[2];
8586
}
87+
#else
88+
event->m_Flags = (uint32_t)eventArgs->a[2];
89+
#endif
8690

8791
ptr = (char *)(event + 1);
8892
memset(event->m_Extensions, 0, sizeof(event->m_Extensions));
@@ -211,4 +215,3 @@ static inline char* set_FileOpen_info(
211215
return (char *)eventHdr;
212216
}
213217
}
214-

‎ebpfKern/sysmonFileOpen_rawtp.c‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,11 @@ int FileOpenRawExit(struct bpf_our_raw_tracepoint_args *ctx)
4141
return 0;
4242

4343
// only handle open and openat events
44+
#ifdef __NR_open
4445
if (eventArgs->syscallId != __NR_open && eventArgs->syscallId != __NR_openat) {
46+
#else
47+
if (eventArgs->syscallId != __NR_openat) {
48+
#endif
4549
return 0;
4650
}
4751

@@ -64,4 +68,3 @@ int FileOpenRawExit(struct bpf_our_raw_tracepoint_args *ctx)
6468

6569
return 0;
6670
}
67-

‎ebpfKern/sysmonProcCreate.c‎

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,8 +28,6 @@
2828
//
2929
//====================================================================
3030

31-
#include <inttypes.h>
32-
3331
__attribute__((always_inline))
3432
static inline char* set_process_ext(
3533
PSYSMON_PROCESS_CREATE event,
@@ -191,4 +189,3 @@ static inline char* set_ProcCreate_info(
191189

192190
return set_process_ext(event, config, task);
193191
}
194-

0 commit comments

Comments
 (0)