| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
| |
While solving it, introduced Pkt abstraction so that advance() is
automatically executed upon dropping it.
This change still allows access to mmapped pointers within the
Pkt.net() and enables the addition of other slice fields (such as mac)
later.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
| |
cleanup_rules() relies on the global flag IS_NFT_NOT_SUPPORTED, which
is always False before install_rule is called. Fixed it to always
attempt cleanup for ipt/ip6/nft at startup.
At the same time, implement Drop so that firewall cleanup occurs when
dies due to ?.
|
| | |
|
| |
|
|
|
|
| |
It would be better if libc_s did not provide signalfd. The
open_signalfd() function itself has issues, such as sigprocmask being
applied elsewhere before opening it.
|
| |
|
|
|
| |
This is likely new feature in kernel. (mayby 5.6 or something near
there)
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
When I updated nix to 0.31, `nix::fcntl::flock` became deprecated and
unusable. At first I try to refactor `lock_pid_file()` to use the
`lock` method of the `nix::fcntl::Flock` struct, but a situation arose
where `set_len(0)` could not be called due to ownership issues. Linux
system calls are fundamentally simple, stable, and backward
compatible. Therefore, a compat layer is not necessary.
Anticipating that this might happen again, this commit introduce the
`libc_s`, which handles simple error processing for unsafe ffis in
libc syscall bindings.
|
| |
|
|
|
|
| |
Keeping poll_once() separate just caused more headaches. It was also
rebuilding the fds array every single time. Since poll() only
overwrites revents, doing that on every loop was totally unnecessary.
|
| |
|
|
|
|
| |
This integrates well with the main poll loop and removes the global
AtomicBool RUNNING, which previously did nothing but detect interrupts
before entering the loop.
|
| |
|
|
|
|
|
|
| |
When both fds are ready in the same wakeup, the SYN/ACK that triggered
rx_ready is causally prior to the ClientHello waiting in the nfqueue.
Process the rxring first so HopTab is populated before handle_packet
runs find_hop, reducing the race window for HopLookupError::NotFound
under load.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
Previous BPF filter only matched IPv4 due to tcpdump failing to
generate a correct combined IPv4/IPv6 filter. Replaced with manually
split filter that handles both ip and ip6 paths.
Also increase FRAME_SIZE from 128 to 256 to resolve this error:
[WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6
packet'. 80 byte(s) would be required, but only 62 byte(s) are
available based on the slice length.
tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes,
which exceeded the previous 128-byte limit.
|
| | |
|
| |
|
|
|
|
|
|
| |
- Remove global RUNNING, trap_exit, EnsureCleanup, MESSAGE_AT_RUN from main.rs
- Move each into platform-specific modules (linux.rs, windows.rs)
- Move MESSAGE_AT_RUN to platform.rs
- Inline cleanup logic into run() instead of separate cleanup() fn
- Remove service_run_1() indirection in windows.rs
|
| |
|
|
|
|
|
| |
Conditionally initialize rxring only when fake_autottl is enabled.
Extract poll_once() using libc::poll directly; fd=-1 trick eliminates
the need for conditional branching on optional rxring fd, as poll sets
revents=0 for negative fds per POSIX. Drop nix poll feature.
|
| |
|
|
|
|
|
|
| |
Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring
initialization (cBPF filter, open) into separate functions. Inline
BorrowedFd scope as a let binding to eliminate floating
q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into
open_rxring.
|
| |
|
|
|
|
|
|
| |
- Split next_packet into current_packet (read) and advance (release)
to avoid TOCTOU between kernel overwrite and packet processing
- Add current_frame helper to avoid duplicated pointer arithmetic
- Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support
- Add FRAME_SIZE comment explaining 128B is sufficient for IP header
|
| | |
|
| |
|
|
|
|
|
| |
- Add rxring module with RxRing struct (new/next_packet unimplemented)
- Attach cBPF filter for TCP src port 443 SYN/ACK packets
- Multiplex nfqueue and rxring via poll in run loop
- Move fake_autottl SYN/ACK handling to pkt::put_hop
|
| | |
|
| |
|
|
|
|
| |
Pass destination address from PktView::daddr() at call site instead of
re-extracting it from raw bytes inside send_to_raw. Windows side
ignores the argument. Also add #[inline] to PktView accessor methods.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
set_opt() was logging each option as it set them, which created a
tight coupling between option initialization and log output timing.
This was particularly problematic for daemon mode: daemonize must
happen after set_opt() (to know whether -D was passed) but before
logging (so output goes to the log file, not stdout).
Split into set_opt() -> InitializedOpts and InitializedOpts::log(),
using a typestate pattern to enforce at compile time that log() cannot
be called before set_opt(). This lets each platform's bootstrap()
handle daemonization between the two steps:
let initialized = opt.set_opt()?;
platform::bootstrap()?; // daemonize here if needed
initialized.log(); // now safe to log
Also:
- Move daemonize_1() into platform::bootstrap() on both platforms
- Make daemonize_1() / service_main() private to their platform modules
- Fix the long-standing TODO about using log_println in daemonize()
|
| |
|
|
|
|
|
|
|
| |
1. open without O_APPEND (offset = 0) and O_TRUNC (original bug)
2. dup file descripter with .try_clone() and feed it to daemonize
3. truncate file with .set_len(0) on child after daemonize.start()
succed
Fixes: https://github.com/dilluti0n/dpibreak/issues/17
|
| | |
|
| | |
|
| |
|
|
| |
Fixes: https://github.com/dilluti0n/dpibreak/issues/16
|
| |
|
|
|
| |
Prevent multiple non-daemon dpibreak instances using flock(). Show
existing PID on conflict and maintain lock until process termination.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
The bootstrap/run separation was unnecessary. Move all initialization
(cleanup + nftables setup): into run() and skip bootstrap in daemon
mode. We repurpose the bootstrap() function to only run in non-daemon
mode for future foreground-only initialization.
- Add OPT_DAEMON option to detect daemon mode
- Move cleanup() and install_rules() from bootstrap() to run()
- Make bootstrap() a no-op (only called in non-daemon mode)
|
| |
|
|
|
| |
Closes: #2
Link: https://github.com/dilluti0n/dpibreak/issues/2
|
| |
|
|
|
|
|
| |
Split iptables and nftables rule management into dedicated modules.
Keep linux.rs focused on shared helpers and rule dispatch.
(cherry picked from commit 60c0011ca0cf5a463056fca17f2f747e762e19f9)
|
| |
|
|
| |
Introduce minimal iptables wrapper.
|
| |
|
|
|
| |
Move option parsing to opt.rs and packet handling to pkt.rs from
main.rs
|
| |
|
|
| |
Log runtime options on startup
|
| |
|
|
|
| |
- linux: fix infinite NFQUEUE loop by marking injected packets
- windows: by marking packet to impostor
|
| |
|
|
|
|
|
|
| |
Introduce exec_process() to handle external command execution, stdin
piping, and error reporting. Now cleanup() and apply_nft_rules() call
exec_process() to call modprobe, nft respectively.
This improves error handling for cleanup xt_u32.
|
| |
|
|
|
| |
Do not log errors if cleanup fails during startup.
Retain error logging for cleanup failures on shutdown.
|
| |
|
|
|
| |
nftables-rs didn’t fit use case, so it was decoupled, and logging was
improved.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
| |
Add additional nftables match expressions to detect TLS records
(ContentType 0x16 = Handshake): and specifically ClientHello
(HandshakeType 0x01):. Packets matching this pattern are queued to
NFQUEUE. Mark xt_u32 as supported when nftables filtering is
successfully applied.
|
| |
|
|
|
|
|
|
|
|
| |
Introduce nftables rules under a dedicated "dpibreak" table and
chain. Traffic on TCP port 443 is queued using NFQUEUE. If nftables
is not supported, fall back to the existing iptables-based rules
for both IPv4 and IPv6.
Also update cleanup logic to remove nftables table if used, or
iptables rules otherwise.
|
| | |
|
| |
|
|
| |
This removes unnecessary allocations per packet handling.
|