aboutsummaryrefslogtreecommitdiffhomepage
path: root/src/platform/linux
Commit message (Collapse)AuthorAgeFilesLines
* linux: rxring: fix lifetime issue for Pkt::net()dilluti0n2026-07-101-2/+2
| | | | Result should be unusable after Pkt is dropped, not rx is dropped.
* linux: rxring: fix tp_snaplen treated as the L3 length instead L2dilluti0n2026-07-101-12/+52
| | | | | | | | | While solving it, introduced Pkt abstraction so that advance() is automatically executed upon dropping it. This change still allows access to mmapped pointers within the Pkt.net() and enables the addition of other slice fields (such as mac) later.
* linux: rxring: guard div0 as EINVALdilluti0n2026-07-091-0/+3
|
* linux: rxring: fix u32 overflow on ring_size initdilluti0n2026-07-091-1/+1
|
* linux: rxring: fix possable memory ordering issuedilluti0n2026-07-091-15/+25
|
* linux: rules: abort if any rule is failed to installdilluti0n2026-07-081-5/+10
|
* linux: move firewall rule handling to mod ruledilluti0n2026-07-083-109/+198
|
* linux: fix iptables not cleanup on startupdilluti0n2026-07-081-0/+10
| | | | | | | | | cleanup_rules() relies on the global flag IS_NFT_NOT_SUPPORTED, which is always False before install_rule is called. Fixed it to always attempt cleanup for ipt/ip6/nft at startup. At the same time, implement Drop so that firewall cleanup occurs when dies due to ?.
* linux: rxring: make tp_* series configurabledilluti0n2026-07-071-17/+14
|
* linux: implement socket and mmap wrapper for rxringdilluti0n2026-07-072-32/+39
| | | | | | | Here mmap/munmap wrapper remain unsafe since mmap returns a pointer causes a memory leak when munmap is not called while dropping, and munmap has strict rule (PAGE_SIZE aligned) for addr defined on munmap(2).
* linux: libc_s: add syscall! macro to reduce redundant error handlingdilluti0n2026-07-061-29/+15
|
* linux: add PACKET_RX_RING to libc_s::setsockopt apstractiondilluti0n2026-07-062-30/+27
| | | | | | | | | The existing implementation was unsafe because UB could occur if a user-space pointer referenced by the struct sock_fprog was incorrectly passed. Rust safe model allows pointer creation and makes dereferencing unsafe. In this case, dereferencing happenes in kernel-space, Rust cannot guarantee this. So it must be handled separately.
* linux: add safe abstraction for setsockopt(SO_ATTACH_FILTER)dilluti0n2026-07-062-12/+32
| | | | | | Treating optval as just a &[u8] in setsockopt() is not appropriate for usage patterns where a struct is put into optval. Rust treats casting a struct to &[u8] as unsafe.
* linux: move poll_s() to mod libc_sdilluti0n2026-07-061-0/+9
|
* linux: drop nix, add wrapper libc_s insteaddilluti0n2026-07-061-0/+42
| | | | | | | | | | | | | When I updated nix to 0.31, `nix::fcntl::flock` became deprecated and unusable. At first I try to refactor `lock_pid_file()` to use the `lock` method of the `nix::fcntl::Flock` struct, but a situation arose where `set_len(0)` could not be called due to ownership issues. Linux system calls are fundamentally simple, stable, and backward compatible. Therefore, a compat layer is not necessary. Anticipating that this might happen again, this commit introduce the `libc_s`, which handles simple error processing for unsafe ffis in libc syscall bindings.
* linux: rxring: nit: add SPDX headerdilluti0n2026-03-151-0/+3
|
* linux: add IPv6 SYN/ACK BPF filter and increase rxring frame sizedilluti0n2026-03-061-3/+2
| | | | | | | | | | | | | | Previous BPF filter only matched IPv4 due to tcpdump failing to generate a correct combined IPv4/IPv6 filter. Replaced with manually split filter that handles both ip and ip6 paths. Also increase FRAME_SIZE from 128 to 256 to resolve this error: [WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6 packet'. 80 byte(s) would be required, but only 62 byte(s) are available based on the slice length. tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes, which exceeded the previous 128-byte limit.
* linux: iptables: nit: fix compiler warningdilluti0n2026-03-021-1/+0
|
* linux: iptables: fix SYN/ACK rules installed on iptablesdilluti0n2026-03-021-19/+0
|
* log: add debug!/info!/warn!/error! macros and refactor to use itdilluti0n2026-03-022-14/+14
|
* linux: fix rxring initialized even if fake_autottl not enableddilluti0n2026-02-261-0/+6
| | | | | | | Conditionally initialize rxring only when fake_autottl is enabled. Extract poll_once() using libc::poll directly; fd=-1 trick eliminates the need for conditional branching on optional rxring fd, as poll sets revents=0 for negative fds per POSIX. Drop nix poll feature.
* linux: refactor run() into open_nfqueue/open_rxring helpersdilluti0n2026-02-261-1/+1
| | | | | | | | Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring initialization (cBPF filter, open) into separate functions. Inline BorrowedFd scope as a let binding to eliminate floating q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into open_rxring.
* linux: rxring: implement current_packet and advancedilluti0n2026-02-261-7/+44
| | | | | | | | - Split next_packet into current_packet (read) and advance (release) to avoid TOCTOU between kernel overwrite and packet processing - Add current_frame helper to avoid duplicated pointer arithmetic - Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support - Add FRAME_SIZE comment explaining 128B is sufficient for IP header
* linux: rxring: implement RxRing::newdilluti0n2026-02-261-7/+91
|
* linux: add rxring skeleton and integrate into run loopdilluti0n2026-02-261-0/+33
| | | | | | | - Add rxring module with RxRing struct (new/next_packet unimplemented) - Attach cBPF filter for TCP src port 443 SYN/ACK packets - Multiplex nfqueue and rxring via poll in run loop - Move fake_autottl SYN/ACK handling to pkt::put_hop
* linux: nftables: drop serde_json, use nft text syntaxdilluti0n2026-02-261-98/+13
| | | | 100 lines of JSON soup -> 16 lines of actual nftables
* linux: nftables: remove syn/ack filter from nftablesdilluti0n2026-02-261-59/+0
|
* linux: iptables: implement SYN/ACK capture on --fake-autottldilluti0n2026-01-231-0/+19
| | | | | | - Add mangle/INPUT jump to DPIBREAK - Queue tcp sport 443 SYN/ACK packets (NFQUEUE --queue-bypass) - Cleanup removes INPUT jump as well
* linux: nftables: queue SYN/ACK on --fake-autottldilluti0n2026-01-231-0/+59
| | | | - simplify nftables rules by removing DPIBREAK chain
* linux: refactor rules backend into iptables/nftables modulesdilluti0n2026-01-232-0/+297
Split iptables and nftables rule management into dedicated modules. Keep linux.rs focused on shared helpers and rule dispatch. (cherry picked from commit 60c0011ca0cf5a463056fca17f2f747e762e19f9)