tcbpf1_kern.c 2.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889
  1. #include <uapi/linux/bpf.h>
  2. #include <uapi/linux/if_ether.h>
  3. #include <uapi/linux/if_packet.h>
  4. #include <uapi/linux/ip.h>
  5. #include <uapi/linux/in.h>
  6. #include <uapi/linux/tcp.h>
  7. #include <uapi/linux/filter.h>
  8. #include <uapi/linux/pkt_cls.h>
  9. #include "bpf_helpers.h"
  10. /* compiler workaround */
  11. #define _htonl __builtin_bswap32
  12. static inline void set_dst_mac(struct __sk_buff *skb, char *mac)
  13. {
  14. bpf_skb_store_bytes(skb, 0, mac, ETH_ALEN, 1);
  15. }
  16. #define IP_CSUM_OFF (ETH_HLEN + offsetof(struct iphdr, check))
  17. #define TOS_OFF (ETH_HLEN + offsetof(struct iphdr, tos))
  18. static inline void set_ip_tos(struct __sk_buff *skb, __u8 new_tos)
  19. {
  20. __u8 old_tos = load_byte(skb, TOS_OFF);
  21. bpf_l3_csum_replace(skb, IP_CSUM_OFF, htons(old_tos), htons(new_tos), 2);
  22. bpf_skb_store_bytes(skb, TOS_OFF, &new_tos, sizeof(new_tos), 0);
  23. }
  24. #define TCP_CSUM_OFF (ETH_HLEN + sizeof(struct iphdr) + offsetof(struct tcphdr, check))
  25. #define IP_SRC_OFF (ETH_HLEN + offsetof(struct iphdr, saddr))
  26. #define IS_PSEUDO 0x10
  27. static inline void set_tcp_ip_src(struct __sk_buff *skb, __u32 new_ip)
  28. {
  29. __u32 old_ip = _htonl(load_word(skb, IP_SRC_OFF));
  30. bpf_l4_csum_replace(skb, TCP_CSUM_OFF, old_ip, new_ip, IS_PSEUDO | sizeof(new_ip));
  31. bpf_l3_csum_replace(skb, IP_CSUM_OFF, old_ip, new_ip, sizeof(new_ip));
  32. bpf_skb_store_bytes(skb, IP_SRC_OFF, &new_ip, sizeof(new_ip), 0);
  33. }
  34. #define TCP_DPORT_OFF (ETH_HLEN + sizeof(struct iphdr) + offsetof(struct tcphdr, dest))
  35. static inline void set_tcp_dest_port(struct __sk_buff *skb, __u16 new_port)
  36. {
  37. __u16 old_port = htons(load_half(skb, TCP_DPORT_OFF));
  38. bpf_l4_csum_replace(skb, TCP_CSUM_OFF, old_port, new_port, sizeof(new_port));
  39. bpf_skb_store_bytes(skb, TCP_DPORT_OFF, &new_port, sizeof(new_port), 0);
  40. }
  41. SEC("classifier")
  42. int bpf_prog1(struct __sk_buff *skb)
  43. {
  44. __u8 proto = load_byte(skb, ETH_HLEN + offsetof(struct iphdr, protocol));
  45. long *value;
  46. if (proto == IPPROTO_TCP) {
  47. set_ip_tos(skb, 8);
  48. set_tcp_ip_src(skb, 0xA010101);
  49. set_tcp_dest_port(skb, 5001);
  50. }
  51. return 0;
  52. }
  53. SEC("redirect_xmit")
  54. int _redirect_xmit(struct __sk_buff *skb)
  55. {
  56. return bpf_redirect(skb->ifindex + 1, 0);
  57. }
  58. SEC("redirect_recv")
  59. int _redirect_recv(struct __sk_buff *skb)
  60. {
  61. return bpf_redirect(skb->ifindex + 1, 1);
  62. }
  63. SEC("clone_redirect_xmit")
  64. int _clone_redirect_xmit(struct __sk_buff *skb)
  65. {
  66. bpf_clone_redirect(skb, skb->ifindex + 1, 0);
  67. return TC_ACT_SHOT;
  68. }
  69. SEC("clone_redirect_recv")
  70. int _clone_redirect_recv(struct __sk_buff *skb)
  71. {
  72. bpf_clone_redirect(skb, skb->ifindex + 1, 1);
  73. return TC_ACT_SHOT;
  74. }
  75. char _license[] SEC("license") = "GPL";