aboutsummaryrefslogtreecommitdiffhomepage
path: root/src
Commit message (Collapse)AuthorAgeFilesLines
...
* linux: add IPv6 SYN/ACK BPF filter and increase rxring frame sizedilluti0n2026-03-062-20/+25
| | | | | | | | | | | | | | Previous BPF filter only matched IPv4 due to tcpdump failing to generate a correct combined IPv4/IPv6 filter. Replaced with manually split filter that handles both ip and ip6 paths. Also increase FRAME_SIZE from 128 to 256 to resolve this error: [WARNING] put_hop: IPv6 Packet Error: Not enough data to decode 'IPv6 packet'. 80 byte(s) would be required, but only 62 byte(s) are available based on the slice length. tpacket_hdr(~66) + eth(14) + ipv6(40) + tcp+options(60) = ~180 bytes, which exceeded the previous 128-byte limit.
* linux: iptables: nit: fix compiler warningdilluti0n2026-03-021-1/+0
|
* linux: iptables: fix SYN/ACK rules installed on iptablesdilluti0n2026-03-021-19/+0
|
* windows: remove unneeded ip checksum calculationdilluti0n2026-03-021-1/+1
|
* log: add debug!/info!/warn!/error! macros and refactor to use itdilluti0n2026-03-0210-92/+93
|
* log: add short form log macroshskimse2026-03-021-0/+5
|
* windows: print log when recv failshskimse2026-03-021-2/+3
|
* windows: fix buffer size to 65536hskimse2026-03-011-1/+1
| | | | This size is for windivert buffer, not internal pkt buffer capacity.
* windows: simplify packet handling with recv_loop macrohskimse2026-03-011-59/+28
| | | | | | | | | Replace generic spawn_recv with recv_loop macro that encapsulates the buffer allocation and receive loop. Divert handle now runs directly on the main thread, while sniff handle spawns a dedicated thread only when fake_autottl is enabled. This eliminates the mpsc channel, Event enum, and the race condition where concurrent open_handle calls during driver initialization could cause error 1058.
* windows: remove RUNNING flag and trap_exithskimse2026-03-011-30/+6
| | | | | | Non-daemon mode exits via process::exit(0) on Ctrl-C, and daemon mode is managed by SCM, so the RUNNING atomic flag and graceful shutdown loop are both unnecessary. Remove them along with the ctrlc handler.
* windows: exit immediately on Ctrl-C in non-daemon modedilluti0n2026-03-011-1/+4
| | | | | | | | | | In non-daemon mode, WinDivert driver closes all handles on process exit, so explicit cleanup is unnecessary. Call std::process::exit(0) directly from the Ctrl-C handler instead of relying on RUNNING flag and graceful shutdown loop. Also move trap_exit() call before spawn_recv() to ensure the handler is registered before any threads are spawned.
* Move cleanup/trap_exit/RUNNING to platform modulesdilluti0n2026-03-014-68/+44
| | | | | | | | - Remove global RUNNING, trap_exit, EnsureCleanup, MESSAGE_AT_RUN from main.rs - Move each into platform-specific modules (linux.rs, windows.rs) - Move MESSAGE_AT_RUN to platform.rs - Inline cleanup logic into run() instead of separate cleanup() fn - Remove service_run_1() indirection in windows.rs
* windows: spawn syn/ack filter only when `--fake-autottl` is enableddilluti0n2026-02-271-4/+7
|
* windows: add close WinDivert handles on thread exitdilluti0n2026-02-271-19/+21
| | | | | | Move handle lifecycle into spawn_recv so each handle is properly closed when RUNNING becomes false. Filter and flags are passed in instead of a pre-opened handle.
* windows: refactor thread spawnings to spawn_recv helperdilluti0n2026-02-271-29/+28
|
* windows: split WinDivert into separate recv/send/sniff handlesdilluti0n2026-02-271-40/+74
| | | | | | windows: add cleanup for SEND_HANDLE windows: fix every packet goes to send-only handle
* pkt: add hop infer log to put_hop_1dilluti0n2026-02-261-1/+10
|
* pkt: move fake_autottl check out of put_hop_1 to callerdilluti0n2026-02-262-25/+18
| | | | pkt: inline hop inference into put_hop_1, decoupling it from fake
* linux: fix rxring initialized even if fake_autottl not enableddilluti0n2026-02-262-27/+42
| | | | | | | Conditionally initialize rxring only when fake_autottl is enabled. Extract poll_once() using libc::poll directly; fd=-1 trick eliminates the need for conditional branching on optional rxring fd, as poll sets revents=0 for negative fds per POSIX. Drop nix poll feature.
* linux: refactor run() into open_nfqueue/open_rxring helpersdilluti0n2026-02-262-54/+60
| | | | | | | | Extract nfqueue initialization (open, bind, set O_NONBLOCK) and rxring initialization (cBPF filter, open) into separate functions. Inline BorrowedFd scope as a let binding to eliminate floating q_ready/rx_ready declarations. Move SYNACK_443_CBPF const into open_rxring.
* linux: rxring: implement current_packet and advancedilluti0n2026-02-262-24/+62
| | | | | | | | - Split next_packet into current_packet (read) and advance (release) to avoid TOCTOU between kernel overwrite and packet processing - Add current_frame helper to avoid duplicated pointer arithmetic - Switch AF_PACKET socket to ETH_P_ALL for future IPv6 support - Add FRAME_SIZE comment explaining 128B is sufficient for IP header
* linux: rxring: implement RxRing::newdilluti0n2026-02-262-7/+93
|
* linux: add rxring skeleton and integrate into run loopdilluti0n2026-02-263-23/+111
| | | | | | | - Add rxring module with RxRing struct (new/next_packet unimplemented) - Attach cBPF filter for TCP src port 443 SYN/ACK packets - Multiplex nfqueue and rxring via poll in run loop - Move fake_autottl SYN/ACK handling to pkt::put_hop
* linux: nftables: drop serde_json, use nft text syntaxdilluti0n2026-02-261-98/+13
| | | | 100 lines of JSON soup -> 16 lines of actual nftables
* linux: nftables: remove syn/ack filter from nftablesdilluti0n2026-02-261-59/+0
|
* pkt: fix infer_hops to use 128, not 126dilluti0n2026-02-261-2/+2
| | | | add debug log for infer_hops
* nit: rename main_0 to _1dilluti0n2026-02-261-2/+2
|
* pkt: add debug log to send_split with dst, segments, payload lendilluti0n2026-02-261-6/+10
|
* log: defer local_time() call until log level check passesdilluti0n2026-02-261-1/+1
|
* pkt: nit: rename split_packet_0/split_packet/split_packet_1dilluti0n2026-02-262-8/+8
| | | | to build_packet/build_segment/send_split
* pkt: rename hoptab public API, drop _0 suffixdilluti0n2026-02-262-9/+9
|
* linux: remove Mutex from RAW4/RAW6, Socket is already Syncdilluti0n2026-02-261-13/+9
|
* Refactor send_to_raw to remove in-place packet reparsingdilluti0n2026-02-263-23/+17
| | | | | | Pass destination address from PktView::daddr() at call site instead of re-extracting it from raw bytes inside send_to_raw. Windows side ignores the argument. Also add #[inline] to PktView accessor methods.
* windows: nit: swap service_run/service_run_1 naming conventiondilluti0n2026-02-261-4/+4
|
* linux: nit: swap daemonize/daemonize_1 naming conventiondilluti0n2026-02-261-4/+4
|
* Print version info log after daemonizedilluti0n2026-02-161-1/+1
|
* windows: fix regression intorduced in b68753e8dilluti0n2026-02-161-5/+2
|
* Log version information on startupdilluti0n2026-02-161-0/+1
|
* log: add defensive error handling for local_timedilluti0n2026-02-161-1/+3
| | | | Fallback to zeroed timestamp when time()/localtime_r() fails.
* log: drop chrono, use localtime_r and GetLocalTime directlydilluti0n2026-02-161-2/+27
| | | | 24 KiB is precious :)
* log: print time with crate chronodilluti0n2026-02-161-1/+2
|
* windows: fix nit build failurev0.4.2dilluti0n2026-02-161-3/+3
|
* linux: add TODO on daemonizedilluti0n2026-02-161-0/+1
|
* opt: decouple set_opt() from loggingdilluti0n2026-02-164-18/+36
| | | | | | | | | | | | | | | | | | | | | | set_opt() was logging each option as it set them, which created a tight coupling between option initialization and log output timing. This was particularly problematic for daemon mode: daemonize must happen after set_opt() (to know whether -D was passed) but before logging (so output goes to the log file, not stdout). Split into set_opt() -> InitializedOpts and InitializedOpts::log(), using a typestate pattern to enforce at compile time that log() cannot be called before set_opt(). This lets each platform's bootstrap() handle daemonization between the two steps: let initialized = opt.set_opt()?; platform::bootstrap()?; // daemonize here if needed initialized.log(); // now safe to log Also: - Move daemonize_1() into platform::bootstrap() on both platforms - Make daemonize_1() / service_main() private to their platform modules - Fix the long-standing TODO about using log_println in daemonize()
* linux: fix log file truncated when daemonize failsdilluti0n2026-02-161-3/+7
| | | | | | | | | 1. open without O_APPEND (offset = 0) and O_TRUNC (original bug) 2. dup file descripter with .try_clone() and feed it to daemonize 3. truncate file with .set_len(0) on child after daemonize.start() succed Fixes: https://github.com/dilluti0n/dpibreak/issues/17
* linux: exit if not rootdilluti0n2026-02-161-1/+9
|
* linux: repurpose bootstrap to do things before requiring cleanupdilluti0n2026-02-162-7/+11
|
* linux: modify PID_FILE and log pathdilluti0n2026-02-161-2/+3
| | | | Fixes: https://github.com/dilluti0n/dpibreak/issues/16
* linux: add PID file locking for single instance enforcementdilluti0n2026-02-151-6/+24
| | | | | Prevent multiple non-daemon dpibreak instances using flock(). Show existing PID on conflict and maintain lock until process termination.
* linux: extract PID_FILE constant for reusedilluti0n2026-02-152-6/+6
|