1 // SPDX-License-Identifier: GPL-2.0
2 // Copyright (c) 2018 Facebook
3 // Copyright (c) 2019 Cloudflare
10 #include <arpa/inet.h>
11 #include <netinet/in.h>
12 #include <sys/types.h>
13 #include <sys/socket.h>
16 #include <bpf/libbpf.h>
18 #include "cgroup_helpers.h"
20 static int start_server(const struct sockaddr *addr, socklen_t len, bool dual)
25 fd = socket(addr->sa_family, SOCK_STREAM, 0);
27 log_err("Failed to create server socket");
31 if (addr->sa_family == AF_INET6) {
32 if (setsockopt(fd, IPPROTO_IPV6, IPV6_V6ONLY, (char *)&mode,
33 sizeof(mode)) == -1) {
34 log_err("Failed to set the dual-stack mode");
39 if (bind(fd, addr, len) == -1) {
40 log_err("Failed to bind server socket");
44 if (listen(fd, 128) == -1) {
45 log_err("Failed to listen on server socket");
58 static int connect_to_server(const struct sockaddr *addr, socklen_t len)
62 fd = socket(addr->sa_family, SOCK_STREAM, 0);
64 log_err("Failed to create client socket");
68 if (connect(fd, (const struct sockaddr *)addr, len) == -1) {
69 log_err("Fail to connect to server");
82 static int get_map_fd_by_prog_id(int prog_id, bool *xdp)
84 struct bpf_prog_info info = {};
85 __u32 info_len = sizeof(info);
90 prog_fd = bpf_prog_get_fd_by_id(prog_id);
92 log_err("Failed to get fd by prog id %d", prog_id);
97 info.map_ids = (__u64)(unsigned long)map_ids;
99 if (bpf_obj_get_info_by_fd(prog_fd, &info, &info_len)) {
100 log_err("Failed to get info by prog fd %d", prog_fd);
104 if (!info.nr_map_ids) {
105 log_err("No maps found for prog fd %d", prog_fd);
109 *xdp = info.type == BPF_PROG_TYPE_XDP;
111 map_fd = bpf_map_get_fd_by_id(map_ids[0]);
113 log_err("Failed to get fd by map id %d", map_ids[0]);
120 static int run_test(int server_fd, int results_fd, bool xdp,
121 const struct sockaddr *addr, socklen_t len)
123 int client = -1, srv_client = -1;
132 if (bpf_map_update_elem(results_fd, &key, &value, 0) < 0) {
133 log_err("Can't clear results");
137 if (bpf_map_update_elem(results_fd, &key_gen, &value_gen, 0) < 0) {
138 log_err("Can't clear results");
142 if (bpf_map_update_elem(results_fd, &key_mss, &value_mss, 0) < 0) {
143 log_err("Can't clear results");
147 client = connect_to_server(addr, len);
151 srv_client = accept(server_fd, NULL, 0);
152 if (srv_client == -1) {
153 log_err("Can't accept connection");
157 if (bpf_map_lookup_elem(results_fd, &key, &value) < 0) {
158 log_err("Can't lookup result");
163 log_err("Didn't match syncookie: %u", value);
167 if (bpf_map_lookup_elem(results_fd, &key_gen, &value_gen) < 0) {
168 log_err("Can't lookup result");
172 if (xdp && value_gen == 0) {
173 // SYN packets do not get passed through generic XDP, skip the
175 printf("Skipping XDP cookie check\n");
179 if (bpf_map_lookup_elem(results_fd, &key_mss, &value_mss) < 0) {
180 log_err("Can't lookup result");
184 if (value != value_gen) {
185 log_err("BPF generated cookie does not match kernel one");
189 if (value_mss < 536 || value_mss > USHRT_MAX) {
190 log_err("Unexpected MSS retrieved");
204 static bool get_port(int server_fd, in_port_t *port)
206 struct sockaddr_in addr;
207 socklen_t len = sizeof(addr);
209 if (getsockname(server_fd, (struct sockaddr *)&addr, &len)) {
210 log_err("Failed to get server addr");
214 /* sin_port and sin6_port are located at the same offset. */
215 *port = addr.sin_port;
219 int main(int argc, char **argv)
221 struct sockaddr_in addr4;
222 struct sockaddr_in6 addr6;
223 struct sockaddr_in addr4dual;
224 struct sockaddr_in6 addr6dual;
227 int server_dual = -1;
233 fprintf(stderr, "Usage: %s prog_id\n", argv[0]);
237 /* Use libbpf 1.0 API mode */
238 libbpf_set_strict_mode(LIBBPF_STRICT_ALL);
240 results = get_map_fd_by_prog_id(atoi(argv[1]), &xdp);
242 log_err("Can't get map");
246 memset(&addr4, 0, sizeof(addr4));
247 addr4.sin_family = AF_INET;
248 addr4.sin_addr.s_addr = htonl(INADDR_LOOPBACK);
250 memcpy(&addr4dual, &addr4, sizeof(addr4dual));
252 memset(&addr6, 0, sizeof(addr6));
253 addr6.sin6_family = AF_INET6;
254 addr6.sin6_addr = in6addr_loopback;
257 memset(&addr6dual, 0, sizeof(addr6dual));
258 addr6dual.sin6_family = AF_INET6;
259 addr6dual.sin6_addr = in6addr_any;
260 addr6dual.sin6_port = 0;
262 server = start_server((const struct sockaddr *)&addr4, sizeof(addr4),
264 if (server == -1 || !get_port(server, &addr4.sin_port))
267 server_v6 = start_server((const struct sockaddr *)&addr6,
268 sizeof(addr6), false);
269 if (server_v6 == -1 || !get_port(server_v6, &addr6.sin6_port))
272 server_dual = start_server((const struct sockaddr *)&addr6dual,
273 sizeof(addr6dual), true);
274 if (server_dual == -1 || !get_port(server_dual, &addr4dual.sin_port))
277 if (run_test(server, results, xdp,
278 (const struct sockaddr *)&addr4, sizeof(addr4)))
281 if (run_test(server_v6, results, xdp,
282 (const struct sockaddr *)&addr6, sizeof(addr6)))
285 if (run_test(server_dual, results, xdp,
286 (const struct sockaddr *)&addr4dual, sizeof(addr4dual)))