test_sock.c 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480
  1. // SPDX-License-Identifier: GPL-2.0
  2. // Copyright (c) 2018 Facebook
  3. #include <stdio.h>
  4. #include <unistd.h>
  5. #include <arpa/inet.h>
  6. #include <sys/types.h>
  7. #include <sys/socket.h>
  8. #include <linux/filter.h>
  9. #include <bpf/bpf.h>
  10. #include "cgroup_helpers.h"
  11. #include "bpf_rlimit.h"
  12. #ifndef ARRAY_SIZE
  13. # define ARRAY_SIZE(x) (sizeof(x) / sizeof((x)[0]))
  14. #endif
  15. #define CG_PATH "/foo"
  16. #define MAX_INSNS 512
  17. char bpf_log_buf[BPF_LOG_BUF_SIZE];
  18. struct sock_test {
  19. const char *descr;
  20. /* BPF prog properties */
  21. struct bpf_insn insns[MAX_INSNS];
  22. enum bpf_attach_type expected_attach_type;
  23. enum bpf_attach_type attach_type;
  24. /* Socket properties */
  25. int domain;
  26. int type;
  27. /* Endpoint to bind() to */
  28. const char *ip;
  29. unsigned short port;
  30. /* Expected test result */
  31. enum {
  32. LOAD_REJECT,
  33. ATTACH_REJECT,
  34. BIND_REJECT,
  35. SUCCESS,
  36. } result;
  37. };
  38. static struct sock_test tests[] = {
  39. {
  40. "bind4 load with invalid access: src_ip6",
  41. .insns = {
  42. BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
  43. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  44. offsetof(struct bpf_sock, src_ip6[0])),
  45. BPF_MOV64_IMM(BPF_REG_0, 1),
  46. BPF_EXIT_INSN(),
  47. },
  48. BPF_CGROUP_INET4_POST_BIND,
  49. BPF_CGROUP_INET4_POST_BIND,
  50. 0,
  51. 0,
  52. NULL,
  53. 0,
  54. LOAD_REJECT,
  55. },
  56. {
  57. "bind4 load with invalid access: mark",
  58. .insns = {
  59. BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
  60. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  61. offsetof(struct bpf_sock, mark)),
  62. BPF_MOV64_IMM(BPF_REG_0, 1),
  63. BPF_EXIT_INSN(),
  64. },
  65. BPF_CGROUP_INET4_POST_BIND,
  66. BPF_CGROUP_INET4_POST_BIND,
  67. 0,
  68. 0,
  69. NULL,
  70. 0,
  71. LOAD_REJECT,
  72. },
  73. {
  74. "bind6 load with invalid access: src_ip4",
  75. .insns = {
  76. BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
  77. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  78. offsetof(struct bpf_sock, src_ip4)),
  79. BPF_MOV64_IMM(BPF_REG_0, 1),
  80. BPF_EXIT_INSN(),
  81. },
  82. BPF_CGROUP_INET6_POST_BIND,
  83. BPF_CGROUP_INET6_POST_BIND,
  84. 0,
  85. 0,
  86. NULL,
  87. 0,
  88. LOAD_REJECT,
  89. },
  90. {
  91. "sock_create load with invalid access: src_port",
  92. .insns = {
  93. BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
  94. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  95. offsetof(struct bpf_sock, src_port)),
  96. BPF_MOV64_IMM(BPF_REG_0, 1),
  97. BPF_EXIT_INSN(),
  98. },
  99. BPF_CGROUP_INET_SOCK_CREATE,
  100. BPF_CGROUP_INET_SOCK_CREATE,
  101. 0,
  102. 0,
  103. NULL,
  104. 0,
  105. LOAD_REJECT,
  106. },
  107. {
  108. "sock_create load w/o expected_attach_type (compat mode)",
  109. .insns = {
  110. BPF_MOV64_IMM(BPF_REG_0, 1),
  111. BPF_EXIT_INSN(),
  112. },
  113. 0,
  114. BPF_CGROUP_INET_SOCK_CREATE,
  115. AF_INET,
  116. SOCK_STREAM,
  117. "127.0.0.1",
  118. 8097,
  119. SUCCESS,
  120. },
  121. {
  122. "sock_create load w/ expected_attach_type",
  123. .insns = {
  124. BPF_MOV64_IMM(BPF_REG_0, 1),
  125. BPF_EXIT_INSN(),
  126. },
  127. BPF_CGROUP_INET_SOCK_CREATE,
  128. BPF_CGROUP_INET_SOCK_CREATE,
  129. AF_INET,
  130. SOCK_STREAM,
  131. "127.0.0.1",
  132. 8097,
  133. SUCCESS,
  134. },
  135. {
  136. "attach type mismatch bind4 vs bind6",
  137. .insns = {
  138. BPF_MOV64_IMM(BPF_REG_0, 1),
  139. BPF_EXIT_INSN(),
  140. },
  141. BPF_CGROUP_INET4_POST_BIND,
  142. BPF_CGROUP_INET6_POST_BIND,
  143. 0,
  144. 0,
  145. NULL,
  146. 0,
  147. ATTACH_REJECT,
  148. },
  149. {
  150. "attach type mismatch bind6 vs bind4",
  151. .insns = {
  152. BPF_MOV64_IMM(BPF_REG_0, 1),
  153. BPF_EXIT_INSN(),
  154. },
  155. BPF_CGROUP_INET6_POST_BIND,
  156. BPF_CGROUP_INET4_POST_BIND,
  157. 0,
  158. 0,
  159. NULL,
  160. 0,
  161. ATTACH_REJECT,
  162. },
  163. {
  164. "attach type mismatch default vs bind4",
  165. .insns = {
  166. BPF_MOV64_IMM(BPF_REG_0, 1),
  167. BPF_EXIT_INSN(),
  168. },
  169. 0,
  170. BPF_CGROUP_INET4_POST_BIND,
  171. 0,
  172. 0,
  173. NULL,
  174. 0,
  175. ATTACH_REJECT,
  176. },
  177. {
  178. "attach type mismatch bind6 vs sock_create",
  179. .insns = {
  180. BPF_MOV64_IMM(BPF_REG_0, 1),
  181. BPF_EXIT_INSN(),
  182. },
  183. BPF_CGROUP_INET6_POST_BIND,
  184. BPF_CGROUP_INET_SOCK_CREATE,
  185. 0,
  186. 0,
  187. NULL,
  188. 0,
  189. ATTACH_REJECT,
  190. },
  191. {
  192. "bind4 reject all",
  193. .insns = {
  194. BPF_MOV64_IMM(BPF_REG_0, 0),
  195. BPF_EXIT_INSN(),
  196. },
  197. BPF_CGROUP_INET4_POST_BIND,
  198. BPF_CGROUP_INET4_POST_BIND,
  199. AF_INET,
  200. SOCK_STREAM,
  201. "0.0.0.0",
  202. 0,
  203. BIND_REJECT,
  204. },
  205. {
  206. "bind6 reject all",
  207. .insns = {
  208. BPF_MOV64_IMM(BPF_REG_0, 0),
  209. BPF_EXIT_INSN(),
  210. },
  211. BPF_CGROUP_INET6_POST_BIND,
  212. BPF_CGROUP_INET6_POST_BIND,
  213. AF_INET6,
  214. SOCK_STREAM,
  215. "::",
  216. 0,
  217. BIND_REJECT,
  218. },
  219. {
  220. "bind6 deny specific IP & port",
  221. .insns = {
  222. BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
  223. /* if (ip == expected && port == expected) */
  224. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  225. offsetof(struct bpf_sock, src_ip6[3])),
  226. BPF_JMP_IMM(BPF_JNE, BPF_REG_7, 0x01000000, 4),
  227. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  228. offsetof(struct bpf_sock, src_port)),
  229. BPF_JMP_IMM(BPF_JNE, BPF_REG_7, 0x2001, 2),
  230. /* return DENY; */
  231. BPF_MOV64_IMM(BPF_REG_0, 0),
  232. BPF_JMP_A(1),
  233. /* else return ALLOW; */
  234. BPF_MOV64_IMM(BPF_REG_0, 1),
  235. BPF_EXIT_INSN(),
  236. },
  237. BPF_CGROUP_INET6_POST_BIND,
  238. BPF_CGROUP_INET6_POST_BIND,
  239. AF_INET6,
  240. SOCK_STREAM,
  241. "::1",
  242. 8193,
  243. BIND_REJECT,
  244. },
  245. {
  246. "bind4 allow specific IP & port",
  247. .insns = {
  248. BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
  249. /* if (ip == expected && port == expected) */
  250. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  251. offsetof(struct bpf_sock, src_ip4)),
  252. BPF_JMP_IMM(BPF_JNE, BPF_REG_7, 0x0100007F, 4),
  253. BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
  254. offsetof(struct bpf_sock, src_port)),
  255. BPF_JMP_IMM(BPF_JNE, BPF_REG_7, 0x1002, 2),
  256. /* return ALLOW; */
  257. BPF_MOV64_IMM(BPF_REG_0, 1),
  258. BPF_JMP_A(1),
  259. /* else return DENY; */
  260. BPF_MOV64_IMM(BPF_REG_0, 0),
  261. BPF_EXIT_INSN(),
  262. },
  263. BPF_CGROUP_INET4_POST_BIND,
  264. BPF_CGROUP_INET4_POST_BIND,
  265. AF_INET,
  266. SOCK_STREAM,
  267. "127.0.0.1",
  268. 4098,
  269. SUCCESS,
  270. },
  271. {
  272. "bind4 allow all",
  273. .insns = {
  274. BPF_MOV64_IMM(BPF_REG_0, 1),
  275. BPF_EXIT_INSN(),
  276. },
  277. BPF_CGROUP_INET4_POST_BIND,
  278. BPF_CGROUP_INET4_POST_BIND,
  279. AF_INET,
  280. SOCK_STREAM,
  281. "0.0.0.0",
  282. 0,
  283. SUCCESS,
  284. },
  285. {
  286. "bind6 allow all",
  287. .insns = {
  288. BPF_MOV64_IMM(BPF_REG_0, 1),
  289. BPF_EXIT_INSN(),
  290. },
  291. BPF_CGROUP_INET6_POST_BIND,
  292. BPF_CGROUP_INET6_POST_BIND,
  293. AF_INET6,
  294. SOCK_STREAM,
  295. "::",
  296. 0,
  297. SUCCESS,
  298. },
  299. };
  300. static size_t probe_prog_length(const struct bpf_insn *fp)
  301. {
  302. size_t len;
  303. for (len = MAX_INSNS - 1; len > 0; --len)
  304. if (fp[len].code != 0 || fp[len].imm != 0)
  305. break;
  306. return len + 1;
  307. }
  308. static int load_sock_prog(const struct bpf_insn *prog,
  309. enum bpf_attach_type attach_type)
  310. {
  311. struct bpf_load_program_attr attr;
  312. memset(&attr, 0, sizeof(struct bpf_load_program_attr));
  313. attr.prog_type = BPF_PROG_TYPE_CGROUP_SOCK;
  314. attr.expected_attach_type = attach_type;
  315. attr.insns = prog;
  316. attr.insns_cnt = probe_prog_length(attr.insns);
  317. attr.license = "GPL";
  318. return bpf_load_program_xattr(&attr, bpf_log_buf, BPF_LOG_BUF_SIZE);
  319. }
  320. static int attach_sock_prog(int cgfd, int progfd,
  321. enum bpf_attach_type attach_type)
  322. {
  323. return bpf_prog_attach(progfd, cgfd, attach_type, BPF_F_ALLOW_OVERRIDE);
  324. }
  325. static int bind_sock(int domain, int type, const char *ip, unsigned short port)
  326. {
  327. struct sockaddr_storage addr;
  328. struct sockaddr_in6 *addr6;
  329. struct sockaddr_in *addr4;
  330. int sockfd = -1;
  331. socklen_t len;
  332. int err = 0;
  333. sockfd = socket(domain, type, 0);
  334. if (sockfd < 0)
  335. goto err;
  336. memset(&addr, 0, sizeof(addr));
  337. if (domain == AF_INET) {
  338. len = sizeof(struct sockaddr_in);
  339. addr4 = (struct sockaddr_in *)&addr;
  340. addr4->sin_family = domain;
  341. addr4->sin_port = htons(port);
  342. if (inet_pton(domain, ip, (void *)&addr4->sin_addr) != 1)
  343. goto err;
  344. } else if (domain == AF_INET6) {
  345. len = sizeof(struct sockaddr_in6);
  346. addr6 = (struct sockaddr_in6 *)&addr;
  347. addr6->sin6_family = domain;
  348. addr6->sin6_port = htons(port);
  349. if (inet_pton(domain, ip, (void *)&addr6->sin6_addr) != 1)
  350. goto err;
  351. } else {
  352. goto err;
  353. }
  354. if (bind(sockfd, (const struct sockaddr *)&addr, len) == -1)
  355. goto err;
  356. goto out;
  357. err:
  358. err = -1;
  359. out:
  360. close(sockfd);
  361. return err;
  362. }
  363. static int run_test_case(int cgfd, const struct sock_test *test)
  364. {
  365. int progfd = -1;
  366. int err = 0;
  367. printf("Test case: %s .. ", test->descr);
  368. progfd = load_sock_prog(test->insns, test->expected_attach_type);
  369. if (progfd < 0) {
  370. if (test->result == LOAD_REJECT)
  371. goto out;
  372. else
  373. goto err;
  374. }
  375. if (attach_sock_prog(cgfd, progfd, test->attach_type) == -1) {
  376. if (test->result == ATTACH_REJECT)
  377. goto out;
  378. else
  379. goto err;
  380. }
  381. if (bind_sock(test->domain, test->type, test->ip, test->port) == -1) {
  382. /* sys_bind() may fail for different reasons, errno has to be
  383. * checked to confirm that BPF program rejected it.
  384. */
  385. if (test->result == BIND_REJECT && errno == EPERM)
  386. goto out;
  387. else
  388. goto err;
  389. }
  390. if (test->result != SUCCESS)
  391. goto err;
  392. goto out;
  393. err:
  394. err = -1;
  395. out:
  396. /* Detaching w/o checking return code: best effort attempt. */
  397. if (progfd != -1)
  398. bpf_prog_detach(cgfd, test->attach_type);
  399. close(progfd);
  400. printf("[%s]\n", err ? "FAIL" : "PASS");
  401. return err;
  402. }
  403. static int run_tests(int cgfd)
  404. {
  405. int passes = 0;
  406. int fails = 0;
  407. int i;
  408. for (i = 0; i < ARRAY_SIZE(tests); ++i) {
  409. if (run_test_case(cgfd, &tests[i]))
  410. ++fails;
  411. else
  412. ++passes;
  413. }
  414. printf("Summary: %d PASSED, %d FAILED\n", passes, fails);
  415. return fails ? -1 : 0;
  416. }
  417. int main(int argc, char **argv)
  418. {
  419. int cgfd = -1;
  420. int err = 0;
  421. if (setup_cgroup_environment())
  422. goto err;
  423. cgfd = create_and_get_cgroup(CG_PATH);
  424. if (!cgfd)
  425. goto err;
  426. if (join_cgroup(CG_PATH))
  427. goto err;
  428. if (run_tests(cgfd))
  429. goto err;
  430. goto out;
  431. err:
  432. err = -1;
  433. out:
  434. close(cgfd);
  435. cleanup_cgroup_environment();
  436. return err;
  437. }