summaryrefslogtreecommitdiffhomepage
path: root/src/platform/linux.rs
Commit message (Collapse)AuthorAgeFilesLines
* linux: rxring: fix tp_snaplen treated as the L3 length instead L2dilluti0n2026-07-101-2/+4
| | | | | | | | | While solving it, introduced Pkt abstraction so that advance() is automatically executed upon dropping it. This change still allows access to mmapped pointers within the Pkt.net() and enables the addition of other slice fields (such as mac) later.
* linux: nit: move const inside to functiondilluti0n2026-07-091-2/+2
|
* linux: move firewall rule handling to mod ruledilluti0n2026-07-081-105/+11
|
* linux: fix iptables not cleanup on startupdilluti0n2026-07-081-31/+55
| | | | | | | | | cleanup_rules() relies on the global flag IS_NFT_NOT_SUPPORTED, which is always False before install_rule is called. Fixed it to always attempt cleanup for ipt/ip6/nft at startup. At the same time, implement Drop so that firewall cleanup occurs when dies due to ?.
* Move platform-dependant codes to mod platformdilluti0n2026-07-081-0/+12
|
* linux: use syscall! macro on open_signalfd()dilluti0n2026-07-071-9/+5
| | | | | | It would be better if libc_s did not provide signalfd. The open_signalfd() function itself has issues, such as sigprocmask being applied elsewhere before opening it.
* linux: do not panic when failed to set IPV6_HDRINCLdilluti0n2026-07-071-1/+4
| | | | | This is likely new feature in kernel. (mayby 5.6 or something near there)
* linux: rxring: make tp_* series configurabledilluti0n2026-07-071-2/+9
|
* linux: move poll_s() to mod libc_sdilluti0n2026-07-061-13/+2
|
* nit: remove unused crate::dilluti0n2026-07-061-2/+2
|
* nit: move use libc::sock_filter to inside open_rxring()dilluti0n2026-07-061-4/+2
|
* linux: drop nix, add wrapper libc_s insteaddilluti0n2026-07-061-8/+8
| | | | | | | | | | | | | When I updated nix to 0.31, `nix::fcntl::flock` became deprecated and unusable. At first I try to refactor `lock_pid_file()` to use the `lock` method of the `nix::fcntl::Flock` struct, but a situation arose where `set_len(0)` could not be called due to ownership issues. Linux system calls are fundamentally simple, stable, and backward compatible. Therefore, a compat layer is not necessary. Anticipating that this might happen again, this commit introduce the `libc_s`, which handles simple error processing for unsafe ffis in libc syscall bindings.
* linux: inline poll_once and lift fds init outside the loopdilluti0n2026-06-291-41/+31
| | | | | | Keeping poll_once() separate just caused more headaches. It was also rebuilding the fds array every single time. Since poll() only overwrites revents, doing that on every loop was totally unnecessary.
* linux: drop ctrlc crate and use signalfd insteaddilluti0n2026-06-291-24/+44
| | | | | | This integrates well with the main poll loop and removes the global AtomicBool RUNNING, which previously did nothing but detect interrupts before entering the loop.
* linux: drain rxring before nfqueue in poll loopdilluti0n2026-04-081-7/+7
| | | | | | | | When both fds are ready in the same wakeup, the SYN/ACK that triggered rx_ready is causally prior to the ClientHello waiting in the nfqueue. Process the rxring first so HopTab is populated before handle_packet runs find_hop, reducing the race window for HopLookupError::NotFound under load.
* linux: add IPv6 SYN/ACK BPF filter and increase rxring frame sizedilluti0n2026-03-061-17/+23
| | | | | | | | | | | | | | Previous BPF filter only matched IPv4 due to tcpdump failing to generate a correct combined IPv4/IPv6 filter. Replaced with manually split filter that handles both ip and ip6 paths. Also increase FRAME_SIZE from 128 to 256 to resolve this error: [WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6 packet'. 80 byte(s) would be required, but only 62 byte(s) are available based on the slice length. tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes, which exceeded the previous 128-byte limit.
* log: add debug!/info!/warn!/error! macros and refactor to use itdilluti0n2026-03-021-11/+12
|
* Move cleanup/trap_exit/RUNNING to platform modulesdilluti0n2026-03-011-11/+16
| | | | | | | | - Remove global RUNNING, trap_exit, EnsureCleanup, MESSAGE_AT_RUN from main.rs - Move each into platform-specific modules (linux.rs, windows.rs) - Move MESSAGE_AT_RUN to platform.rs - Inline cleanup logic into run() instead of separate cleanup() fn - Remove service_run_1() indirection in windows.rs
* linux: fix rxring initialized even if fake_autottl not enableddilluti0n2026-02-261-27/+36
| | | | | | | Conditionally initialize rxring only when fake_autottl is enabled. Extract poll_once() using libc::poll directly; fd=-1 trick eliminates the need for conditional branching on optional rxring fd, as poll sets revents=0 for negative fds per POSIX. Drop nix poll feature.
* linux: refactor run() into open_nfqueue/open_rxring helpersdilluti0n2026-02-261-53/+59
| | | | | | | | Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring initialization (cBPF filter, open) into separate functions. Inline BorrowedFd scope as a let binding to eliminate floating q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into open_rxring.
* linux: rxring: implement current_packet and advancedilluti0n2026-02-261-17/+18
| | | | | | | | - Split next_packet into current_packet (read) and advance (release) to avoid TOCTOU between kernel overwrite and packet processing - Add current_frame helper to avoid duplicated pointer arithmetic - Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support - Add FRAME_SIZE comment explaining 128B is sufficient for IP header
* linux: rxring: implement RxRing::newdilluti0n2026-02-261-0/+2
|
* linux: add rxring skeleton and integrate into run loopdilluti0n2026-02-261-15/+63
| | | | | | | - Add rxring module with RxRing struct (new/next_packet unimplemented) - Attach cBPF filter for TCP src port 443 SYN/ACK packets - Multiplex nfqueue and rxring via poll in run loop - Move fake_autottl SYN/ACK handling to pkt::put_hop
* linux: remove Mutex from RAW4/RAW6, Socket is already Syncdilluti0n2026-02-261-13/+9
|
* Refactor send_to_raw to remove in-place packet reparsingdilluti0n2026-02-261-20/+7
| | | | | | Pass destination address from PktView::daddr() at call site instead of re-extracting it from raw bytes inside send_to_raw. Windows side ignores the argument. Also add #[inline] to PktView accessor methods.
* linux: nit: swap daemonize/daemonize_1 naming conventiondilluti0n2026-02-261-4/+4
|
* linux: add TODO on daemonizedilluti0n2026-02-161-0/+1
|
* opt: decouple set_opt() from loggingdilluti0n2026-02-161-4/+5
| | | | | | | | | | | | | | | | | | | | | | set_opt() was logging each option as it set them, which created a tight coupling between option initialization and log output timing. This was particularly problematic for daemon mode: daemonize must happen after set_opt() (to know whether -D was passed) but before logging (so output goes to the log file, not stdout). Split into set_opt() -> InitializedOpts and InitializedOpts::log(), using a typestate pattern to enforce at compile time that log() cannot be called before set_opt(). This lets each platform's bootstrap() handle daemonization between the two steps: let initialized = opt.set_opt()?; platform::bootstrap()?; // daemonize here if needed initialized.log(); // now safe to log Also: - Move daemonize_1() into platform::bootstrap() on both platforms - Make daemonize_1() / service_main() private to their platform modules - Fix the long-standing TODO about using log_println in daemonize()
* linux: fix log file truncated when daemonize failsdilluti0n2026-02-161-3/+7
| | | | | | | | | 1. open without O_APPEND (offset = 0) and O_TRUNC (original bug) 2. dup file descripter with .try_clone() and feed it to daemonize 3. truncate file with .set_len(0) on child after daemonize.start() succed Fixes: https://github.com/dilluti0n/dpibreak/issues/17
* linux: exit if not rootdilluti0n2026-02-161-1/+9
|
* linux: repurpose bootstrap to do things before requiring cleanupdilluti0n2026-02-161-4/+10
|
* linux: modify PID_FILE and log pathdilluti0n2026-02-161-2/+3
| | | | Fixes: https://github.com/dilluti0n/dpibreak/issues/16
* linux: add PID file locking for single instance enforcementdilluti0n2026-02-151-6/+24
| | | | | Prevent multiple non-daemon dpibreak instances using flock(). Show existing PID on conflict and maintain lock until process termination.
* linux: extract PID_FILE constant for reusedilluti0n2026-02-151-3/+3
|
* Consolidate setup logic into run()dilluti0n2026-02-151-2/+7
| | | | | | | | | | | The bootstrap/run separation was unnecessary. Move all initialization (cleanup + nftables setup): into run() and skip bootstrap in daemon mode. We repurpose the bootstrap() function to only run in non-daemon mode for future foreground-only initialization. - Add OPT_DAEMON option to detect daemon mode - Move cleanup() and install_rules() from bootstrap() to run() - Make bootstrap() a no-op (only called in non-daemon mode)
* linux: implement daemonizedilluti0n2026-02-151-0/+36
| | | | | Closes: #2 Link: https://github.com/dilluti0n/dpibreak/issues/2
* linux: refactor rules backend into iptables/nftables modulesdilluti0n2026-01-231-301/+13
| | | | | | | Split iptables and nftables rule management into dedicated modules. Keep linux.rs focused on shared helpers and rule dispatch. (cherry picked from commit 60c0011ca0cf5a463056fca17f2f747e762e19f9)
* linux: drop iptables crate (regex dep) to reduce binary sizedilluti0n2026-01-181-23/+75
| | | | Introduce minimal iptables wrapper.
* Refactor main.rs; modulize opt.rs and pkt.rsdilluti0n2026-01-161-20/+9
| | | | | Move option parsing to opt.rs and packet handling to pkt.rs from main.rs
* Normalize option handling and OPT_* namingdilluti0n2025-12-301-4/+4
| | | | Log runtime options on startup
* Prevent infinite loop on packet injection/filteringdilluti0n2025-12-301-4/+39
| | | | | - linux: fix infinite NFQUEUE loop by marking injected packets - windows: by marking packet to impostor
* linux: extract process execution into `exec_process` helperdilluti0n2025-12-291-17/+29
| | | | | | | | Introduce exec_process() to handle external command execution, stdin piping, and error reporting. Now cleanup() and apply_nft_rules() call exec_process() to call modprobe, nft respectively. This improves error handling for cleanup xt_u32.
* linux: ignore cleanup errors at startupdilluti0n2025-12-221-7/+3
| | | | | Do not log errors if cleanup fails during startup. Retain error logging for cleanup failures on shutdown.
* linux: switch to apply_nft_rules() from nftables-rs for rule settingdilluti0n2025-10-291-18/+13
| | | | | nftables-rs didn’t fit use case, so it was decoupled, and logging was improved.
* linux: implement apply_nft_rules() to log output sanelydilluti0n2025-10-291-0/+30
|
* linux: add option `--nft-command`dilluti0n2025-10-291-7/+11
|
* platform: linux: filter only TLS ClientHello packets on nftablesdilluti0n2025-10-031-0/+21
| | | | | | | | Add additional nftables match expressions to detect TLS records (ContentType 0x16 = Handshake): and specifically ClientHello (HandshakeType 0x01):. Packets matching this pattern are queued to NFQUEUE. Mark xt_u32 as supported when nftables filtering is successfully applied.
* platform: linux: add nftables support with iptables fallbackdilluti0n2025-10-031-11/+112
| | | | | | | | | | Introduce nftables rules under a dedicated "dpibreak" table and chain. Traffic on TCP port 443 is queued using NFQUEUE. If nftables is not supported, fall back to the existing iptables-based rules for both IPv4 and IPv6. Also update cleanup logic to remove nftables table if used, or iptables rules otherwise.
* platform: linux: split iptables helpers on bootstrap/cleanupdilluti0n2025-09-271-14/+25
|
* Refactor handle_packet to reuse external buffer for packet handlingdilluti0n2025-09-111-0/+4
| | | | This removes unnecessary allocations per packet handling.