4 -------------------------------------------------------------------------------
5 tool for inspection of BTF data
6 -------------------------------------------------------------------------------
13 **bpftool** [*OPTIONS*] **btf** *COMMAND*
15 *OPTIONS* := { { **-j** | **--json** } [{ **-p** | **--pretty** }] }
17 *COMMANDS* := { **dump** | **help** }
22 | **bpftool** **btf** { **show** | **list** } [**id** *BTF_ID*]
23 | **bpftool** **btf dump** *BTF_SRC* [**format** *FORMAT*]
24 | **bpftool** **btf help**
26 | *BTF_SRC* := { **id** *BTF_ID* | **prog** *PROG* | **map** *MAP* [{**key** | **value** | **kv** | **all**}] | **file** *FILE* }
27 | *FORMAT* := { **raw** | **c** }
28 | *MAP* := { **id** *MAP_ID* | **pinned** *FILE* }
29 | *PROG* := { **id** *PROG_ID* | **pinned** *FILE* | **tag** *PROG_TAG* }
33 **bpftool btf { show | list }** [**id** *BTF_ID*]
34 Show information about loaded BTF objects. If a BTF ID is
35 specified, show information only about given BTF object,
36 otherwise list all BTF objects currently loaded on the
39 Since Linux 5.8 bpftool is able to discover information about
40 processes that hold open file descriptors (FDs) against BTF
41 objects. On such kernels bpftool will automatically emit this
44 **bpftool btf dump** *BTF_SRC*
45 Dump BTF entries from a given *BTF_SRC*.
47 When **id** is specified, BTF object with that ID will be
48 loaded and all its BTF types emitted.
50 When **map** is provided, it's expected that map has
51 associated BTF object with BTF types describing key and
52 value. It's possible to select whether to dump only BTF
53 type(s) associated with key (**key**), value (**value**),
54 both key and value (**kv**), or all BTF types present in
55 associated BTF object (**all**). If not specified, **kv**
58 When **prog** is provided, it's expected that program has
59 associated BTF object with BTF types.
61 When specifying *FILE*, an ELF file is expected, containing
62 .BTF section with well-defined BTF binary format data,
63 typically produced by clang or pahole.
65 **format** option can be used to override default (raw)
66 output format. Raw (**raw**) or C-syntax (**c**) output
67 formats are supported.
70 Print short help message.
75 Print short generic help message (similar to **bpftool help**).
78 Print version number (similar to **bpftool version**).
81 Generate JSON output. For commands that cannot produce JSON, this
85 Generate human-readable JSON output. Implies **-j**.
88 Print all logs available from libbpf, including debug-level
93 **# bpftool btf dump id 1226**
96 [1] PTR '(anon)' type_id=2
97 [2] STRUCT 'dummy_tracepoint_args' size=16 vlen=2
98 'pad' type_id=3 bits_offset=0
99 'sock' type_id=4 bits_offset=64
100 [3] INT 'long long unsigned int' size=8 bits_offset=0 nr_bits=64 encoding=(none)
101 [4] PTR '(anon)' type_id=5
102 [5] FWD 'sock' fwd_kind=union
104 This gives an example of default output for all supported BTF kinds.
116 typedef struct my_struct my_struct_t;
119 const unsigned int const_int_field;
120 int bitfield_field: 4;
122 const struct fwd_struct *restrict fwd_field;
123 enum my_enum enum_field;
124 volatile my_struct_t *typedef_ptr_field;
132 struct my_struct struct_global_var __attribute__((section("data_sec"))) = {
136 int global_var __attribute__((section("data_sec"))) = 7;
138 __attribute__((noinline))
139 int my_func(union my_union *arg1, int arg2)
141 static int static_var __attribute__((section("data_sec"))) = 123;
146 **$ bpftool btf dump file prog.o**
149 [1] PTR '(anon)' type_id=2
150 [2] UNION 'my_union' size=48 vlen=2
151 'a' type_id=3 bits_offset=0
152 'b' type_id=4 bits_offset=0
153 [3] INT 'int' size=4 bits_offset=0 nr_bits=32 encoding=SIGNED
154 [4] STRUCT 'my_struct' size=48 vlen=6
155 'const_int_field' type_id=5 bits_offset=0
156 'bitfield_field' type_id=3 bits_offset=32 bitfield_size=4
157 'arr_field' type_id=8 bits_offset=40
158 'fwd_field' type_id=10 bits_offset=192
159 'enum_field' type_id=14 bits_offset=256
160 'typedef_ptr_field' type_id=15 bits_offset=320
161 [5] CONST '(anon)' type_id=6
162 [6] INT 'unsigned int' size=4 bits_offset=0 nr_bits=32 encoding=(none)
163 [7] INT 'char' size=1 bits_offset=0 nr_bits=8 encoding=SIGNED
164 [8] ARRAY '(anon)' type_id=7 index_type_id=9 nr_elems=16
165 [9] INT '__ARRAY_SIZE_TYPE__' size=4 bits_offset=0 nr_bits=32 encoding=(none)
166 [10] RESTRICT '(anon)' type_id=11
167 [11] PTR '(anon)' type_id=12
168 [12] CONST '(anon)' type_id=13
169 [13] FWD 'fwd_struct' fwd_kind=union
170 [14] ENUM 'my_enum' size=4 vlen=2
173 [15] PTR '(anon)' type_id=16
174 [16] VOLATILE '(anon)' type_id=17
175 [17] TYPEDEF 'my_struct_t' type_id=4
176 [18] FUNC_PROTO '(anon)' ret_type_id=3 vlen=2
179 [19] FUNC 'my_func' type_id=18
180 [20] VAR 'struct_global_var' type_id=4, linkage=global-alloc
181 [21] VAR 'global_var' type_id=3, linkage=global-alloc
182 [22] VAR 'my_func.static_var' type_id=3, linkage=static
183 [23] DATASEC 'data_sec' size=0 vlen=3
184 type_id=20 offset=0 size=48
185 type_id=21 offset=0 size=4
186 type_id=22 offset=52 size=4
188 The following commands print BTF types associated with specified map's key,
189 value, both key and value, and all BTF types, respectively. By default, both
190 key and value types will be printed.
192 **# bpftool btf dump map id 123 key**
196 [39] TYPEDEF 'u32' type_id=37
198 **# bpftool btf dump map id 123 value**
202 [86] PTR '(anon)' type_id=87
204 **# bpftool btf dump map id 123 kv**
208 [39] TYPEDEF 'u32' type_id=37
209 [86] PTR '(anon)' type_id=87
211 **# bpftool btf dump map id 123 all**
215 [1] PTR '(anon)' type_id=0
219 [2866] ARRAY '(anon)' type_id=52 index_type_id=51 nr_elems=4
221 All the standard ways to specify map or program are supported:
223 **# bpftool btf dump map id 123**
225 **# bpftool btf dump map pinned /sys/fs/bpf/map_name**
227 **# bpftool btf dump prog id 456**
229 **# bpftool btf dump prog tag b88e0a09b1d9759d**
231 **# bpftool btf dump prog pinned /sys/fs/bpf/prog_name**
236 **bpf-helpers**\ (7),
238 **bpftool-btf**\ (8),
239 **bpftool-cgroup**\ (8),
240 **bpftool-feature**\ (8),
241 **bpftool-gen**\ (8),
242 **bpftool-iter**\ (8),
243 **bpftool-link**\ (8),
244 **bpftool-map**\ (8),
245 **bpftool-net**\ (8),
246 **bpftool-perf**\ (8),
247 **bpftool-prog**\ (8),
248 **bpftool-struct_ops**\ (8)