summaryrefslogtreecommitdiffhomepage
path: root/src/platform/linux
Commit message (Collapse)AuthorAgeFilesLines
* linux: rxring: guard div0 as EINVALdilluti0n2026-07-091-0/+3
|
* linux: rxring: fix u32 overflow on ring_size initdilluti0n2026-07-091-1/+1
|
* linux: rxring: fix possable memory ordering issuedilluti0n2026-07-091-15/+25
|
* linux: rules: abort if any rule is failed to installdilluti0n2026-07-081-5/+10
|
* linux: move firewall rule handling to mod ruledilluti0n2026-07-083-109/+198
|
* linux: fix iptables not cleanup on startupdilluti0n2026-07-081-0/+10
| | | | | | | | | cleanup_rules() relies on the global flag IS_NFT_NOT_SUPPORTED, which is always False before install_rule is called. Fixed it to always attempt cleanup for ipt/ip6/nft at startup. At the same time, implement Drop so that firewall cleanup occurs when dies due to ?.
* linux: rxring: make tp_* series configurabledilluti0n2026-07-071-17/+14
|
* linux: implement socket and mmap wrapper for rxringdilluti0n2026-07-072-32/+39
| | | | | | | Here mmap/munmap wrapper remain unsafe since mmap returns a pointer causes a memory leak when munmap is not called while dropping, and munmap has strict rule (PAGE_SIZE aligned) for addr defined on munmap(2).
* linux: libc_s: add syscall! macro to reduce redundant error handlingdilluti0n2026-07-061-29/+15
|
* linux: add PACKET_RX_RING to libc_s::setsockopt apstractiondilluti0n2026-07-062-30/+27
| | | | | | | | | The existing implementation was unsafe because UB could occur if a user-space pointer referenced by the struct sock_fprog was incorrectly passed. Rust safe model allows pointer creation and makes dereferencing unsafe. In this case, dereferencing happenes in kernel-space, Rust cannot guarantee this. So it must be handled separately.
* linux: add safe abstraction for setsockopt(SO_ATTACH_FILTER)dilluti0n2026-07-062-12/+32
| | | | | | Treating optval as just a &[u8] in setsockopt() is not appropriate for usage patterns where a struct is put into optval. Rust treats casting a struct to &[u8] as unsafe.
* linux: move poll_s() to mod libc_sdilluti0n2026-07-061-0/+9
|
* linux: drop nix, add wrapper libc_s insteaddilluti0n2026-07-061-0/+42
| | | | | | | | | | | | | When I updated nix to 0.31, `nix::fcntl::flock` became deprecated and unusable. At first I try to refactor `lock_pid_file()` to use the `lock` method of the `nix::fcntl::Flock` struct, but a situation arose where `set_len(0)` could not be called due to ownership issues. Linux system calls are fundamentally simple, stable, and backward compatible. Therefore, a compat layer is not necessary. Anticipating that this might happen again, this commit introduce the `libc_s`, which handles simple error processing for unsafe ffis in libc syscall bindings.
* linux: rxring: nit: add SPDX headerdilluti0n2026-03-151-0/+3
|
* linux: add IPv6 SYN/ACK BPF filter and increase rxring frame sizedilluti0n2026-03-061-3/+2
| | | | | | | | | | | | | | Previous BPF filter only matched IPv4 due to tcpdump failing to generate a correct combined IPv4/IPv6 filter. Replaced with manually split filter that handles both ip and ip6 paths. Also increase FRAME_SIZE from 128 to 256 to resolve this error: [WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6 packet'. 80 byte(s) would be required, but only 62 byte(s) are available based on the slice length. tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes, which exceeded the previous 128-byte limit.
* linux: iptables: nit: fix compiler warningdilluti0n2026-03-021-1/+0
|
* linux: iptables: fix SYN/ACK rules installed on iptablesdilluti0n2026-03-021-19/+0
|
* log: add debug!/info!/warn!/error! macros and refactor to use itdilluti0n2026-03-022-14/+14
|
* linux: fix rxring initialized even if fake_autottl not enableddilluti0n2026-02-261-0/+6
| | | | | | | Conditionally initialize rxring only when fake_autottl is enabled. Extract poll_once() using libc::poll directly; fd=-1 trick eliminates the need for conditional branching on optional rxring fd, as poll sets revents=0 for negative fds per POSIX. Drop nix poll feature.
* linux: refactor run() into open_nfqueue/open_rxring helpersdilluti0n2026-02-261-1/+1
| | | | | | | | Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring initialization (cBPF filter, open) into separate functions. Inline BorrowedFd scope as a let binding to eliminate floating q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into open_rxring.
* linux: rxring: implement current_packet and advancedilluti0n2026-02-261-7/+44
| | | | | | | | - Split next_packet into current_packet (read) and advance (release) to avoid TOCTOU between kernel overwrite and packet processing - Add current_frame helper to avoid duplicated pointer arithmetic - Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support - Add FRAME_SIZE comment explaining 128B is sufficient for IP header
* linux: rxring: implement RxRing::newdilluti0n2026-02-261-7/+91
|
* linux: add rxring skeleton and integrate into run loopdilluti0n2026-02-261-0/+33
| | | | | | | - Add rxring module with RxRing struct (new/next_packet unimplemented) - Attach cBPF filter for TCP src port 443 SYN/ACK packets - Multiplex nfqueue and rxring via poll in run loop - Move fake_autottl SYN/ACK handling to pkt::put_hop
* linux: nftables: drop serde_json, use nft text syntaxdilluti0n2026-02-261-98/+13
| | | | 100 lines of JSON soup -> 16 lines of actual nftables
* linux: nftables: remove syn/ack filter from nftablesdilluti0n2026-02-261-59/+0
|
* linux: iptables: implement SYN/ACK capture on --fake-autottldilluti0n2026-01-231-0/+19
| | | | | | - Add mangle/INPUT jump to DPIBREAK - Queue tcp sport 443 SYN/ACK packets (NFQUEUE --queue-bypass) - Cleanup removes INPUT jump as well
* linux: nftables: queue SYN/ACK on --fake-autottldilluti0n2026-01-231-0/+59
| | | | - simplify nftables rules by removing DPIBREAK chain
* linux: refactor rules backend into iptables/nftables modulesdilluti0n2026-01-232-0/+297
Split iptables and nftables rule management into dedicated modules. Keep linux.rs focused on shared helpers and rule dispatch. (cherry picked from commit 60c0011ca0cf5a463056fca17f2f747e762e19f9)