| Commit message (Collapse) | Author | Age | Files | Lines |
| | |
|
| | |
|
| | |
|
| |
|
|
| |
This size is for windivert buffer, not internal pkt buffer capacity.
|
| |
|
|
|
|
|
|
|
| |
Replace generic spawn_recv with recv_loop macro that encapsulates the
buffer allocation and receive loop. Divert handle now runs directly on
the main thread, while sniff handle spawns a dedicated thread only when
fake_autottl is enabled. This eliminates the mpsc channel, Event enum,
and the race condition where concurrent open_handle calls during driver
initialization could cause error 1058.
|
| |
|
|
|
|
| |
Non-daemon mode exits via process::exit(0) on Ctrl-C, and daemon mode
is managed by SCM, so the RUNNING atomic flag and graceful shutdown
loop are both unnecessary. Remove them along with the ctrlc handler.
|
| |
|
|
|
|
|
|
|
|
| |
In non-daemon mode, WinDivert driver closes all handles on process
exit, so explicit cleanup is unnecessary. Call std::process::exit(0)
directly from the Ctrl-C handler instead of relying on RUNNING flag
and graceful shutdown loop.
Also move trap_exit() call before spawn_recv() to ensure the handler
is registered before any threads are spawned.
|
| |
|
|
|
|
|
|
| |
- Remove global RUNNING, trap_exit, EnsureCleanup, MESSAGE_AT_RUN from main.rs
- Move each into platform-specific modules (linux.rs, windows.rs)
- Move MESSAGE_AT_RUN to platform.rs
- Inline cleanup logic into run() instead of separate cleanup() fn
- Remove service_run_1() indirection in windows.rs
|
| | |
|
| |
|
|
|
|
| |
Move handle lifecycle into spawn_recv so each handle is properly
closed when RUNNING becomes false. Filter and flags are passed in
instead of a pre-opened handle.
|
| | |
|
| |
|
|
|
|
| |
windows: add cleanup for SEND_HANDLE
windows: fix every packet goes to send-only handle
|
| | |
|
| |
|
|
| |
pkt: inline hop inference into put_hop_1, decoupling it from fake
|
| |
|
|
|
|
|
| |
Conditionally initialize rxring only when fake_autottl is enabled.
Extract poll_once() using libc::poll directly; fd=-1 trick eliminates
the need for conditional branching on optional rxring fd, as poll sets
revents=0 for negative fds per POSIX. Drop nix poll feature.
|
| |
|
|
|
|
|
|
| |
Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring
initialization (cBPF filter, open) into separate functions. Inline
BorrowedFd scope as a let binding to eliminate floating
q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into
open_rxring.
|
| |
|
|
|
|
|
|
| |
- Split next_packet into current_packet (read) and advance (release)
to avoid TOCTOU between kernel overwrite and packet processing
- Add current_frame helper to avoid duplicated pointer arithmetic
- Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support
- Add FRAME_SIZE comment explaining 128B is sufficient for IP header
|
| | |
|
| |
|
|
|
|
|
| |
- Add rxring module with RxRing struct (new/next_packet unimplemented)
- Attach cBPF filter for TCP src port 443 SYN/ACK packets
- Multiplex nfqueue and rxring via poll in run loop
- Move fake_autottl SYN/ACK handling to pkt::put_hop
|
| |
|
|
| |
100 lines of JSON soup -> 16 lines of actual nftables
|
| | |
|
| |
|
|
| |
add debug log for infer_hops
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
to build_packet/build_segment/send_split
|
| | |
|
| | |
|
| |
|
|
|
|
| |
Pass destination address from PktView::daddr() at call site instead of
re-extracting it from raw bytes inside send_to_raw. Windows side
ignores the argument. Also add #[inline] to PktView accessor methods.
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
Fallback to zeroed timestamp when time()/localtime_r() fails.
|
| |
|
|
| |
24 KiB is precious :)
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
set_opt() was logging each option as it set them, which created a
tight coupling between option initialization and log output timing.
This was particularly problematic for daemon mode: daemonize must
happen after set_opt() (to know whether -D was passed) but before
logging (so output goes to the log file, not stdout).
Split into set_opt() -> InitializedOpts and InitializedOpts::log(),
using a typestate pattern to enforce at compile time that log() cannot
be called before set_opt(). This lets each platform's bootstrap()
handle daemonization between the two steps:
let initialized = opt.set_opt()?;
platform::bootstrap()?; // daemonize here if needed
initialized.log(); // now safe to log
Also:
- Move daemonize_1() into platform::bootstrap() on both platforms
- Make daemonize_1() / service_main() private to their platform modules
- Fix the long-standing TODO about using log_println in daemonize()
|
| |
|
|
|
|
|
|
|
| |
1. open without O_APPEND (offset = 0) and O_TRUNC (original bug)
2. dup file descripter with .try_clone() and feed it to daemonize
3. truncate file with .set_len(0) on child after daemonize.start()
succed
Fixes: https://github.com/dilluti0n/dpibreak/issues/17
|
| | |
|
| | |
|
| |
|
|
| |
Fixes: https://github.com/dilluti0n/dpibreak/issues/16
|
| |
|
|
|
| |
Prevent multiple non-daemon dpibreak instances using flock(). Show
existing PID on conflict and maintain lock until process termination.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
The bootstrap/run separation was unnecessary. Move all initialization
(cleanup + nftables setup): into run() and skip bootstrap in daemon
mode. We repurpose the bootstrap() function to only run in non-daemon
mode for future foreground-only initialization.
- Add OPT_DAEMON option to detect daemon mode
- Move cleanup() and install_rules() from bootstrap() to run()
- Make bootstrap() a no-op (only called in non-daemon mode)
|
| | |
|
| |
|
|
|
|
|
|
|
| |
Revert lock_handle()
send_to_raw cannot get a mutex since lock is not released per
iteration.
commit e08b57d281d8368dc02f06e3b6cd43edf88b2438
|
| |
|
|
|
| |
Closes: #2
Link: https://github.com/dilluti0n/dpibreak/issues/2
|