| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
Previous BPF filter only matched IPv4 due to tcpdump failing to
generate a correct combined IPv4/IPv6 filter. Replaced with manually
split filter that handles both ip and ip6 paths.
Also increase FRAME_SIZE from 128 to 256 to resolve this error:
[WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6
packet'. 80 byte(s) would be required, but only 62 byte(s) are
available based on the slice length.
tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes,
which exceeded the previous 128-byte limit.
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
| |
Conditionally initialize rxring only when fake_autottl is enabled.
Extract poll_once() using libc::poll directly; fd=-1 trick eliminates
the need for conditional branching on optional rxring fd, as poll sets
revents=0 for negative fds per POSIX. Drop nix poll feature.
|
| |
|
|
|
|
|
|
| |
Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring
initialization (cBPF filter, open) into separate functions. Inline
BorrowedFd scope as a let binding to eliminate floating
q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into
open_rxring.
|
| |
|
|
|
|
|
|
| |
- Split next_packet into current_packet (read) and advance (release)
to avoid TOCTOU between kernel overwrite and packet processing
- Add current_frame helper to avoid duplicated pointer arithmetic
- Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support
- Add FRAME_SIZE comment explaining 128B is sufficient for IP header
|
| | |
|
| |
|
|
|
|
|
| |
- Add rxring module with RxRing struct (new/next_packet unimplemented)
- Attach cBPF filter for TCP src port 443 SYN/ACK packets
- Multiplex nfqueue and rxring via poll in run loop
- Move fake_autottl SYN/ACK handling to pkt::put_hop
|
| |
|
|
| |
100 lines of JSON soup -> 16 lines of actual nftables
|
| | |
|
| |
|
|
|
|
| |
- Add mangle/INPUT jump to DPIBREAK
- Queue tcp sport 443 SYN/ACK packets (NFQUEUE --queue-bypass)
- Cleanup removes INPUT jump as well
|
| |
|
|
| |
- simplify nftables rules by removing DPIBREAK chain
|
|
|
Split iptables and nftables rule management into dedicated modules.
Keep linux.rs focused on shared helpers and rule dispatch.
(cherry picked from commit 60c0011ca0cf5a463056fca17f2f747e762e19f9)
|