aboutsummaryrefslogtreecommitdiffhomepage
path: root/src/platform
Commit message (Collapse)AuthorAgeFilesLines
* windows: nit: fix build failure.. Let?dilluti0n2026-07-151-1/+1
|
* windows: touch WinDivert service at start to prevent bad state issuedilluti0n2026-07-141-0/+37
| | | | | | | | | | | | | | Query the service state with `sc query windivert` at startup, as this is observed to resolve the bad state described in commit 168a88b8 ("windows: fix some kind of race"). This is a defensive measure against the driver uninstall introduced by that commit. Normally the uninstall is attempted only after all handles opened by the current process are closed, but if another process still holds an open WinDivert handle at that point, the driver can remain stuck in a bad state on subsequent runs. Link: https://github.com/basil00/WinDivert/issues/406
* windows: use OnceLock for SEND_HANDLE to close only when openneddilluti0n2026-07-141-13/+13
|
* windows: fix some kind of racedilluti0n2026-07-141-2/+16
| | | | | | | | | | | | Uninstalling before all handles were closed resulted in a os error 1058 when try to open windivert. (sc stop windivert fixed it) Assumed the uninstallation would fail if the handle was still active, but it seems the initial uninstallation actually succeeded, while the subsequent attempt to close the remaining handles failed. Closing send handle that hadn't been closed previously and then explicitly performed the uninstallation fixes the issue.
* windows: close handles and uninstall WinDivert.sys before exitdilluti0n2026-07-141-4/+34
| | | | | | | This allows the WinDivert.sys can be removed after the program terminates, without needing to run `sc stop windivert`. Bug: https://github.com/dilluti0n/dpibreak/issues/21
* windows: insert handler for console route to shutdown recv handlesdilluti0n2026-07-141-3/+30
|
* windows: WinDivertShutdown() recv handles at service exitsdilluti0n2026-07-141-12/+31
| | | | | This inturrupts blocking recv() calls resulting WinDivert service can be safely removed.
* windows: use paexit instead std::process::exitdilluti0n2026-07-131-6/+8
| | | | See error message
* windows: fix nit build failuredilluti0n2026-07-131-2/+2
|
* linux: rxring: fix lifetime issue for Pkt::net()dilluti0n2026-07-101-2/+2
| | | | Result should be unusable after Pkt is dropped, not rx is dropped.
* linux: rxring: fix tp_snaplen treated as the L3 length instead L2dilluti0n2026-07-102-14/+56
| | | | | | | | | While solving it, introduced Pkt abstraction so that advance() is automatically executed upon dropping it. This change still allows access to mmapped pointers within the Pkt.net() and enables the addition of other slice fields (such as mac) later.
* linux: rxring: guard div0 as EINVALdilluti0n2026-07-091-0/+3
|
* linux: rxring: fix u32 overflow on ring_size initdilluti0n2026-07-091-1/+1
|
* linux: rxring: fix possable memory ordering issuedilluti0n2026-07-091-15/+25
|
* linux: nit: move const inside to functiondilluti0n2026-07-091-2/+2
|
* linux: rules: abort if any rule is failed to installdilluti0n2026-07-081-5/+10
|
* linux: move firewall rule handling to mod ruledilluti0n2026-07-084-214/+209
|
* linux: fix iptables not cleanup on startupdilluti0n2026-07-082-31/+65
| | | | | | | | | cleanup_rules() relies on the global flag IS_NFT_NOT_SUPPORTED, which is always False before install_rule is called. Fixed it to always attempt cleanup for ipt/ip6/nft at startup. At the same time, implement Drop so that firewall cleanup occurs when dies due to ?.
* Move platform-dependant codes to mod platformdilluti0n2026-07-082-0/+31
|
* linux: use syscall! macro on open_signalfd()dilluti0n2026-07-071-9/+5
| | | | | | It would be better if libc_s did not provide signalfd. The open_signalfd() function itself has issues, such as sigprocmask being applied elsewhere before opening it.
* linux: do not panic when failed to set IPV6_HDRINCLdilluti0n2026-07-071-1/+4
| | | | | This is likely new feature in kernel. (mayby 5.6 or something near there)
* linux: rxring: make tp_* series configurabledilluti0n2026-07-072-19/+23
|
* linux: implement socket and mmap wrapper for rxringdilluti0n2026-07-072-32/+39
| | | | | | | Here mmap/munmap wrapper remain unsafe since mmap returns a pointer causes a memory leak when munmap is not called while dropping, and munmap has strict rule (PAGE_SIZE aligned) for addr defined on munmap(2).
* linux: libc_s: add syscall! macro to reduce redundant error handlingdilluti0n2026-07-061-29/+15
|
* linux: add PACKET_RX_RING to libc_s::setsockopt apstractiondilluti0n2026-07-062-30/+27
| | | | | | | | | The existing implementation was unsafe because UB could occur if a user-space pointer referenced by the struct sock_fprog was incorrectly passed. Rust safe model allows pointer creation and makes dereferencing unsafe. In this case, dereferencing happenes in kernel-space, Rust cannot guarantee this. So it must be handled separately.
* linux: add safe abstraction for setsockopt(SO_ATTACH_FILTER)dilluti0n2026-07-062-12/+32
| | | | | | Treating optval as just a &[u8] in setsockopt() is not appropriate for usage patterns where a struct is put into optval. Rust treats casting a struct to &[u8] as unsafe.
* linux: move poll_s() to mod libc_sdilluti0n2026-07-062-13/+11
|
* nit: remove unused crate::dilluti0n2026-07-061-2/+2
|
* nit: move use libc::sock_filter to inside open_rxring()dilluti0n2026-07-061-4/+2
|
* linux: drop nix, add wrapper libc_s insteaddilluti0n2026-07-062-8/+50
| | | | | | | | | | | | | When I updated nix to 0.31, `nix::fcntl::flock` became deprecated and unusable. At first I try to refactor `lock_pid_file()` to use the `lock` method of the `nix::fcntl::Flock` struct, but a situation arose where `set_len(0)` could not be called due to ownership issues. Linux system calls are fundamentally simple, stable, and backward compatible. Therefore, a compat layer is not necessary. Anticipating that this might happen again, this commit introduce the `libc_s`, which handles simple error processing for unsafe ffis in libc syscall bindings.
* linux: inline poll_once and lift fds init outside the loopdilluti0n2026-06-291-41/+31
| | | | | | Keeping poll_once() separate just caused more headaches. It was also rebuilding the fds array every single time. Since poll() only overwrites revents, doing that on every loop was totally unnecessary.
* linux: drop ctrlc crate and use signalfd insteaddilluti0n2026-06-291-24/+44
| | | | | | This integrates well with the main poll loop and removes the global AtomicBool RUNNING, which previously did nothing but detect interrupts before entering the loop.
* linux: drain rxring before nfqueue in poll loopdilluti0n2026-04-081-7/+7
| | | | | | | | When both fds are ready in the same wakeup, the SYN/ACK that triggered rx_ready is causally prior to the ClientHello waiting in the nfqueue. Process the rxring first so HopTab is populated before handle_packet runs find_hop, reducing the race window for HopLookupError::NotFound under load.
* linux: rxring: nit: add SPDX headerdilluti0n2026-03-151-0/+3
|
* linux: add IPv6 SYN/ACK BPF filter and increase rxring frame sizedilluti0n2026-03-062-20/+25
| | | | | | | | | | | | | | Previous BPF filter only matched IPv4 due to tcpdump failing to generate a correct combined IPv4/IPv6 filter. Replaced with manually split filter that handles both ip and ip6 paths. Also increase FRAME_SIZE from 128 to 256 to resolve this error: [WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6 packet'. 80 byte(s) would be required, but only 62 byte(s) are available based on the slice length. tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes, which exceeded the previous 128-byte limit.
* linux: iptables: nit: fix compiler warningdilluti0n2026-03-021-1/+0
|
* linux: iptables: fix SYN/ACK rules installed on iptablesdilluti0n2026-03-021-19/+0
|
* windows: remove unneeded ip checksum calculationdilluti0n2026-03-021-1/+1
|
* log: add debug!/info!/warn!/error! macros and refactor to use itdilluti0n2026-03-024-42/+42
|
* windows: print log when recv failshskimse2026-03-021-2/+3
|
* windows: fix buffer size to 65536hskimse2026-03-011-1/+1
| | | | This size is for windivert buffer, not internal pkt buffer capacity.
* windows: simplify packet handling with recv_loop macrohskimse2026-03-011-59/+28
| | | | | | | | | Replace generic spawn_recv with recv_loop macro that encapsulates the buffer allocation and receive loop. Divert handle now runs directly on the main thread, while sniff handle spawns a dedicated thread only when fake_autottl is enabled. This eliminates the mpsc channel, Event enum, and the race condition where concurrent open_handle calls during driver initialization could cause error 1058.
* windows: remove RUNNING flag and trap_exithskimse2026-03-011-30/+6
| | | | | | Non-daemon mode exits via process::exit(0) on Ctrl-C, and daemon mode is managed by SCM, so the RUNNING atomic flag and graceful shutdown loop are both unnecessary. Remove them along with the ctrlc handler.
* windows: exit immediately on Ctrl-C in non-daemon modedilluti0n2026-03-011-1/+4
| | | | | | | | | | In non-daemon mode, WinDivert driver closes all handles on process exit, so explicit cleanup is unnecessary. Call std::process::exit(0) directly from the Ctrl-C handler instead of relying on RUNNING flag and graceful shutdown loop. Also move trap_exit() call before spawn_recv() to ensure the handler is registered before any threads are spawned.
* Move cleanup/trap_exit/RUNNING to platform modulesdilluti0n2026-03-012-37/+40
| | | | | | | | - Remove global RUNNING, trap_exit, EnsureCleanup, MESSAGE_AT_RUN from main.rs - Move each into platform-specific modules (linux.rs, windows.rs) - Move MESSAGE_AT_RUN to platform.rs - Inline cleanup logic into run() instead of separate cleanup() fn - Remove service_run_1() indirection in windows.rs
* windows: spawn syn/ack filter only when `--fake-autottl` is enableddilluti0n2026-02-271-4/+7
|
* windows: add close WinDivert handles on thread exitdilluti0n2026-02-271-19/+21
| | | | | | Move handle lifecycle into spawn_recv so each handle is properly closed when RUNNING becomes false. Filter and flags are passed in instead of a pre-opened handle.
* windows: refactor thread spawnings to spawn_recv helperdilluti0n2026-02-271-29/+28
|
* windows: split WinDivert into separate recv/send/sniff handlesdilluti0n2026-02-271-40/+74
| | | | | | windows: add cleanup for SEND_HANDLE windows: fix every packet goes to send-only handle
* linux: fix rxring initialized even if fake_autottl not enableddilluti0n2026-02-262-27/+42
| | | | | | | Conditionally initialize rxring only when fake_autottl is enabled. Extract poll_once() using libc::poll directly; fd=-1 trick eliminates the need for conditional branching on optional rxring fd, as poll sets revents=0 for negative fds per POSIX. Drop nix poll feature.