xref: /OK3568_Linux_fs/kernel/tools/bpf/bpf_dbg.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * Minimal BPF debugger
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * Minimal BPF debugger that mimics the kernel's engine (w/o extensions)
6*4882a593Smuzhiyun  * and allows for single stepping through selected packets from a pcap
7*4882a593Smuzhiyun  * with a provided user filter in order to facilitate verification of a
8*4882a593Smuzhiyun  * BPF program. Besides others, this is useful to verify BPF programs
9*4882a593Smuzhiyun  * before attaching to a live system, and can be used in socket filters,
10*4882a593Smuzhiyun  * cls_bpf, xt_bpf, team driver and e.g. PTP code; in particular when a
11*4882a593Smuzhiyun  * single more complex BPF program is being used. Reasons for a more
12*4882a593Smuzhiyun  * complex BPF program are likely primarily to optimize execution time
13*4882a593Smuzhiyun  * for making a verdict when multiple simple BPF programs are combined
14*4882a593Smuzhiyun  * into one in order to prevent parsing same headers multiple times.
15*4882a593Smuzhiyun  *
16*4882a593Smuzhiyun  * More on how to debug BPF opcodes see Documentation/networking/filter.rst
17*4882a593Smuzhiyun  * which is the main document on BPF. Mini howto for getting started:
18*4882a593Smuzhiyun  *
19*4882a593Smuzhiyun  *  1) `./bpf_dbg` to enter the shell (shell cmds denoted with '>'):
20*4882a593Smuzhiyun  *  2) > load bpf 6,40 0 0 12,21 0 3 20... (output from `bpf_asm` or
21*4882a593Smuzhiyun  *     `tcpdump -iem1 -ddd port 22 | tr '\n' ','` to load as filter)
22*4882a593Smuzhiyun  *  3) > load pcap foo.pcap
23*4882a593Smuzhiyun  *  4) > run <n>/disassemble/dump/quit (self-explanatory)
24*4882a593Smuzhiyun  *  5) > breakpoint 2 (sets bp at loaded BPF insns 2, do `run` then;
25*4882a593Smuzhiyun  *       multiple bps can be set, of course, a call to `breakpoint`
26*4882a593Smuzhiyun  *       w/o args shows currently loaded bps, `breakpoint reset` for
27*4882a593Smuzhiyun  *       resetting all breakpoints)
28*4882a593Smuzhiyun  *  6) > select 3 (`run` etc will start from the 3rd packet in the pcap)
29*4882a593Smuzhiyun  *  7) > step [-<n>, +<n>] (performs single stepping through the BPF)
30*4882a593Smuzhiyun  *
31*4882a593Smuzhiyun  * Copyright 2013 Daniel Borkmann <borkmann@redhat.com>
32*4882a593Smuzhiyun  */
33*4882a593Smuzhiyun 
34*4882a593Smuzhiyun #include <stdio.h>
35*4882a593Smuzhiyun #include <unistd.h>
36*4882a593Smuzhiyun #include <stdlib.h>
37*4882a593Smuzhiyun #include <ctype.h>
38*4882a593Smuzhiyun #include <stdbool.h>
39*4882a593Smuzhiyun #include <stdarg.h>
40*4882a593Smuzhiyun #include <setjmp.h>
41*4882a593Smuzhiyun #include <linux/filter.h>
42*4882a593Smuzhiyun #include <linux/if_packet.h>
43*4882a593Smuzhiyun #include <readline/readline.h>
44*4882a593Smuzhiyun #include <readline/history.h>
45*4882a593Smuzhiyun #include <sys/types.h>
46*4882a593Smuzhiyun #include <sys/socket.h>
47*4882a593Smuzhiyun #include <sys/stat.h>
48*4882a593Smuzhiyun #include <sys/mman.h>
49*4882a593Smuzhiyun #include <fcntl.h>
50*4882a593Smuzhiyun #include <errno.h>
51*4882a593Smuzhiyun #include <signal.h>
52*4882a593Smuzhiyun #include <arpa/inet.h>
53*4882a593Smuzhiyun #include <net/ethernet.h>
54*4882a593Smuzhiyun 
55*4882a593Smuzhiyun #define TCPDUMP_MAGIC	0xa1b2c3d4
56*4882a593Smuzhiyun 
57*4882a593Smuzhiyun #define BPF_LDX_B	(BPF_LDX | BPF_B)
58*4882a593Smuzhiyun #define BPF_LDX_W	(BPF_LDX | BPF_W)
59*4882a593Smuzhiyun #define BPF_JMP_JA	(BPF_JMP | BPF_JA)
60*4882a593Smuzhiyun #define BPF_JMP_JEQ	(BPF_JMP | BPF_JEQ)
61*4882a593Smuzhiyun #define BPF_JMP_JGT	(BPF_JMP | BPF_JGT)
62*4882a593Smuzhiyun #define BPF_JMP_JGE	(BPF_JMP | BPF_JGE)
63*4882a593Smuzhiyun #define BPF_JMP_JSET	(BPF_JMP | BPF_JSET)
64*4882a593Smuzhiyun #define BPF_ALU_ADD	(BPF_ALU | BPF_ADD)
65*4882a593Smuzhiyun #define BPF_ALU_SUB	(BPF_ALU | BPF_SUB)
66*4882a593Smuzhiyun #define BPF_ALU_MUL	(BPF_ALU | BPF_MUL)
67*4882a593Smuzhiyun #define BPF_ALU_DIV	(BPF_ALU | BPF_DIV)
68*4882a593Smuzhiyun #define BPF_ALU_MOD	(BPF_ALU | BPF_MOD)
69*4882a593Smuzhiyun #define BPF_ALU_NEG	(BPF_ALU | BPF_NEG)
70*4882a593Smuzhiyun #define BPF_ALU_AND	(BPF_ALU | BPF_AND)
71*4882a593Smuzhiyun #define BPF_ALU_OR	(BPF_ALU | BPF_OR)
72*4882a593Smuzhiyun #define BPF_ALU_XOR	(BPF_ALU | BPF_XOR)
73*4882a593Smuzhiyun #define BPF_ALU_LSH	(BPF_ALU | BPF_LSH)
74*4882a593Smuzhiyun #define BPF_ALU_RSH	(BPF_ALU | BPF_RSH)
75*4882a593Smuzhiyun #define BPF_MISC_TAX	(BPF_MISC | BPF_TAX)
76*4882a593Smuzhiyun #define BPF_MISC_TXA	(BPF_MISC | BPF_TXA)
77*4882a593Smuzhiyun #define BPF_LD_B	(BPF_LD | BPF_B)
78*4882a593Smuzhiyun #define BPF_LD_H	(BPF_LD | BPF_H)
79*4882a593Smuzhiyun #define BPF_LD_W	(BPF_LD | BPF_W)
80*4882a593Smuzhiyun 
81*4882a593Smuzhiyun #ifndef array_size
82*4882a593Smuzhiyun # define array_size(x)	(sizeof(x) / sizeof((x)[0]))
83*4882a593Smuzhiyun #endif
84*4882a593Smuzhiyun 
85*4882a593Smuzhiyun #ifndef __check_format_printf
86*4882a593Smuzhiyun # define __check_format_printf(pos_fmtstr, pos_fmtargs) \
87*4882a593Smuzhiyun 	__attribute__ ((format (printf, (pos_fmtstr), (pos_fmtargs))))
88*4882a593Smuzhiyun #endif
89*4882a593Smuzhiyun 
90*4882a593Smuzhiyun enum {
91*4882a593Smuzhiyun 	CMD_OK,
92*4882a593Smuzhiyun 	CMD_ERR,
93*4882a593Smuzhiyun 	CMD_EX,
94*4882a593Smuzhiyun };
95*4882a593Smuzhiyun 
96*4882a593Smuzhiyun struct shell_cmd {
97*4882a593Smuzhiyun 	const char *name;
98*4882a593Smuzhiyun 	int (*func)(char *args);
99*4882a593Smuzhiyun };
100*4882a593Smuzhiyun 
101*4882a593Smuzhiyun struct pcap_filehdr {
102*4882a593Smuzhiyun 	uint32_t magic;
103*4882a593Smuzhiyun 	uint16_t version_major;
104*4882a593Smuzhiyun 	uint16_t version_minor;
105*4882a593Smuzhiyun 	int32_t  thiszone;
106*4882a593Smuzhiyun 	uint32_t sigfigs;
107*4882a593Smuzhiyun 	uint32_t snaplen;
108*4882a593Smuzhiyun 	uint32_t linktype;
109*4882a593Smuzhiyun };
110*4882a593Smuzhiyun 
111*4882a593Smuzhiyun struct pcap_timeval {
112*4882a593Smuzhiyun 	int32_t tv_sec;
113*4882a593Smuzhiyun 	int32_t tv_usec;
114*4882a593Smuzhiyun };
115*4882a593Smuzhiyun 
116*4882a593Smuzhiyun struct pcap_pkthdr {
117*4882a593Smuzhiyun 	struct pcap_timeval ts;
118*4882a593Smuzhiyun 	uint32_t caplen;
119*4882a593Smuzhiyun 	uint32_t len;
120*4882a593Smuzhiyun };
121*4882a593Smuzhiyun 
122*4882a593Smuzhiyun struct bpf_regs {
123*4882a593Smuzhiyun 	uint32_t A;
124*4882a593Smuzhiyun 	uint32_t X;
125*4882a593Smuzhiyun 	uint32_t M[BPF_MEMWORDS];
126*4882a593Smuzhiyun 	uint32_t R;
127*4882a593Smuzhiyun 	bool     Rs;
128*4882a593Smuzhiyun 	uint16_t Pc;
129*4882a593Smuzhiyun };
130*4882a593Smuzhiyun 
131*4882a593Smuzhiyun static struct sock_filter bpf_image[BPF_MAXINSNS + 1];
132*4882a593Smuzhiyun static unsigned int bpf_prog_len;
133*4882a593Smuzhiyun 
134*4882a593Smuzhiyun static int bpf_breakpoints[64];
135*4882a593Smuzhiyun static struct bpf_regs bpf_regs[BPF_MAXINSNS + 1];
136*4882a593Smuzhiyun static struct bpf_regs bpf_curr;
137*4882a593Smuzhiyun static unsigned int bpf_regs_len;
138*4882a593Smuzhiyun 
139*4882a593Smuzhiyun static int pcap_fd = -1;
140*4882a593Smuzhiyun static unsigned int pcap_packet;
141*4882a593Smuzhiyun static size_t pcap_map_size;
142*4882a593Smuzhiyun static char *pcap_ptr_va_start, *pcap_ptr_va_curr;
143*4882a593Smuzhiyun 
144*4882a593Smuzhiyun static const char * const op_table[] = {
145*4882a593Smuzhiyun 	[BPF_ST]	= "st",
146*4882a593Smuzhiyun 	[BPF_STX]	= "stx",
147*4882a593Smuzhiyun 	[BPF_LD_B]	= "ldb",
148*4882a593Smuzhiyun 	[BPF_LD_H]	= "ldh",
149*4882a593Smuzhiyun 	[BPF_LD_W]	= "ld",
150*4882a593Smuzhiyun 	[BPF_LDX]	= "ldx",
151*4882a593Smuzhiyun 	[BPF_LDX_B]	= "ldxb",
152*4882a593Smuzhiyun 	[BPF_JMP_JA]	= "ja",
153*4882a593Smuzhiyun 	[BPF_JMP_JEQ]	= "jeq",
154*4882a593Smuzhiyun 	[BPF_JMP_JGT]	= "jgt",
155*4882a593Smuzhiyun 	[BPF_JMP_JGE]	= "jge",
156*4882a593Smuzhiyun 	[BPF_JMP_JSET]	= "jset",
157*4882a593Smuzhiyun 	[BPF_ALU_ADD]	= "add",
158*4882a593Smuzhiyun 	[BPF_ALU_SUB]	= "sub",
159*4882a593Smuzhiyun 	[BPF_ALU_MUL]	= "mul",
160*4882a593Smuzhiyun 	[BPF_ALU_DIV]	= "div",
161*4882a593Smuzhiyun 	[BPF_ALU_MOD]	= "mod",
162*4882a593Smuzhiyun 	[BPF_ALU_NEG]	= "neg",
163*4882a593Smuzhiyun 	[BPF_ALU_AND]	= "and",
164*4882a593Smuzhiyun 	[BPF_ALU_OR]	= "or",
165*4882a593Smuzhiyun 	[BPF_ALU_XOR]	= "xor",
166*4882a593Smuzhiyun 	[BPF_ALU_LSH]	= "lsh",
167*4882a593Smuzhiyun 	[BPF_ALU_RSH]	= "rsh",
168*4882a593Smuzhiyun 	[BPF_MISC_TAX]	= "tax",
169*4882a593Smuzhiyun 	[BPF_MISC_TXA]	= "txa",
170*4882a593Smuzhiyun 	[BPF_RET]	= "ret",
171*4882a593Smuzhiyun };
172*4882a593Smuzhiyun 
rl_printf(const char * fmt,...)173*4882a593Smuzhiyun static __check_format_printf(1, 2) int rl_printf(const char *fmt, ...)
174*4882a593Smuzhiyun {
175*4882a593Smuzhiyun 	int ret;
176*4882a593Smuzhiyun 	va_list vl;
177*4882a593Smuzhiyun 
178*4882a593Smuzhiyun 	va_start(vl, fmt);
179*4882a593Smuzhiyun 	ret = vfprintf(rl_outstream, fmt, vl);
180*4882a593Smuzhiyun 	va_end(vl);
181*4882a593Smuzhiyun 
182*4882a593Smuzhiyun 	return ret;
183*4882a593Smuzhiyun }
184*4882a593Smuzhiyun 
matches(const char * cmd,const char * pattern)185*4882a593Smuzhiyun static int matches(const char *cmd, const char *pattern)
186*4882a593Smuzhiyun {
187*4882a593Smuzhiyun 	int len = strlen(cmd);
188*4882a593Smuzhiyun 
189*4882a593Smuzhiyun 	if (len > strlen(pattern))
190*4882a593Smuzhiyun 		return -1;
191*4882a593Smuzhiyun 
192*4882a593Smuzhiyun 	return memcmp(pattern, cmd, len);
193*4882a593Smuzhiyun }
194*4882a593Smuzhiyun 
hex_dump(const uint8_t * buf,size_t len)195*4882a593Smuzhiyun static void hex_dump(const uint8_t *buf, size_t len)
196*4882a593Smuzhiyun {
197*4882a593Smuzhiyun 	int i;
198*4882a593Smuzhiyun 
199*4882a593Smuzhiyun 	rl_printf("%3u: ", 0);
200*4882a593Smuzhiyun 	for (i = 0; i < len; i++) {
201*4882a593Smuzhiyun 		if (i && !(i % 16))
202*4882a593Smuzhiyun 			rl_printf("\n%3u: ", i);
203*4882a593Smuzhiyun 		rl_printf("%02x ", buf[i]);
204*4882a593Smuzhiyun 	}
205*4882a593Smuzhiyun 	rl_printf("\n");
206*4882a593Smuzhiyun }
207*4882a593Smuzhiyun 
bpf_prog_loaded(void)208*4882a593Smuzhiyun static bool bpf_prog_loaded(void)
209*4882a593Smuzhiyun {
210*4882a593Smuzhiyun 	if (bpf_prog_len == 0)
211*4882a593Smuzhiyun 		rl_printf("no bpf program loaded!\n");
212*4882a593Smuzhiyun 
213*4882a593Smuzhiyun 	return bpf_prog_len > 0;
214*4882a593Smuzhiyun }
215*4882a593Smuzhiyun 
bpf_disasm(const struct sock_filter f,unsigned int i)216*4882a593Smuzhiyun static void bpf_disasm(const struct sock_filter f, unsigned int i)
217*4882a593Smuzhiyun {
218*4882a593Smuzhiyun 	const char *op, *fmt;
219*4882a593Smuzhiyun 	int val = f.k;
220*4882a593Smuzhiyun 	char buf[256];
221*4882a593Smuzhiyun 
222*4882a593Smuzhiyun 	switch (f.code) {
223*4882a593Smuzhiyun 	case BPF_RET | BPF_K:
224*4882a593Smuzhiyun 		op = op_table[BPF_RET];
225*4882a593Smuzhiyun 		fmt = "#%#x";
226*4882a593Smuzhiyun 		break;
227*4882a593Smuzhiyun 	case BPF_RET | BPF_A:
228*4882a593Smuzhiyun 		op = op_table[BPF_RET];
229*4882a593Smuzhiyun 		fmt = "a";
230*4882a593Smuzhiyun 		break;
231*4882a593Smuzhiyun 	case BPF_RET | BPF_X:
232*4882a593Smuzhiyun 		op = op_table[BPF_RET];
233*4882a593Smuzhiyun 		fmt = "x";
234*4882a593Smuzhiyun 		break;
235*4882a593Smuzhiyun 	case BPF_MISC_TAX:
236*4882a593Smuzhiyun 		op = op_table[BPF_MISC_TAX];
237*4882a593Smuzhiyun 		fmt = "";
238*4882a593Smuzhiyun 		break;
239*4882a593Smuzhiyun 	case BPF_MISC_TXA:
240*4882a593Smuzhiyun 		op = op_table[BPF_MISC_TXA];
241*4882a593Smuzhiyun 		fmt = "";
242*4882a593Smuzhiyun 		break;
243*4882a593Smuzhiyun 	case BPF_ST:
244*4882a593Smuzhiyun 		op = op_table[BPF_ST];
245*4882a593Smuzhiyun 		fmt = "M[%d]";
246*4882a593Smuzhiyun 		break;
247*4882a593Smuzhiyun 	case BPF_STX:
248*4882a593Smuzhiyun 		op = op_table[BPF_STX];
249*4882a593Smuzhiyun 		fmt = "M[%d]";
250*4882a593Smuzhiyun 		break;
251*4882a593Smuzhiyun 	case BPF_LD_W | BPF_ABS:
252*4882a593Smuzhiyun 		op = op_table[BPF_LD_W];
253*4882a593Smuzhiyun 		fmt = "[%d]";
254*4882a593Smuzhiyun 		break;
255*4882a593Smuzhiyun 	case BPF_LD_H | BPF_ABS:
256*4882a593Smuzhiyun 		op = op_table[BPF_LD_H];
257*4882a593Smuzhiyun 		fmt = "[%d]";
258*4882a593Smuzhiyun 		break;
259*4882a593Smuzhiyun 	case BPF_LD_B | BPF_ABS:
260*4882a593Smuzhiyun 		op = op_table[BPF_LD_B];
261*4882a593Smuzhiyun 		fmt = "[%d]";
262*4882a593Smuzhiyun 		break;
263*4882a593Smuzhiyun 	case BPF_LD_W | BPF_LEN:
264*4882a593Smuzhiyun 		op = op_table[BPF_LD_W];
265*4882a593Smuzhiyun 		fmt = "#len";
266*4882a593Smuzhiyun 		break;
267*4882a593Smuzhiyun 	case BPF_LD_W | BPF_IND:
268*4882a593Smuzhiyun 		op = op_table[BPF_LD_W];
269*4882a593Smuzhiyun 		fmt = "[x+%d]";
270*4882a593Smuzhiyun 		break;
271*4882a593Smuzhiyun 	case BPF_LD_H | BPF_IND:
272*4882a593Smuzhiyun 		op = op_table[BPF_LD_H];
273*4882a593Smuzhiyun 		fmt = "[x+%d]";
274*4882a593Smuzhiyun 		break;
275*4882a593Smuzhiyun 	case BPF_LD_B | BPF_IND:
276*4882a593Smuzhiyun 		op = op_table[BPF_LD_B];
277*4882a593Smuzhiyun 		fmt = "[x+%d]";
278*4882a593Smuzhiyun 		break;
279*4882a593Smuzhiyun 	case BPF_LD | BPF_IMM:
280*4882a593Smuzhiyun 		op = op_table[BPF_LD_W];
281*4882a593Smuzhiyun 		fmt = "#%#x";
282*4882a593Smuzhiyun 		break;
283*4882a593Smuzhiyun 	case BPF_LDX | BPF_IMM:
284*4882a593Smuzhiyun 		op = op_table[BPF_LDX];
285*4882a593Smuzhiyun 		fmt = "#%#x";
286*4882a593Smuzhiyun 		break;
287*4882a593Smuzhiyun 	case BPF_LDX_B | BPF_MSH:
288*4882a593Smuzhiyun 		op = op_table[BPF_LDX_B];
289*4882a593Smuzhiyun 		fmt = "4*([%d]&0xf)";
290*4882a593Smuzhiyun 		break;
291*4882a593Smuzhiyun 	case BPF_LD | BPF_MEM:
292*4882a593Smuzhiyun 		op = op_table[BPF_LD_W];
293*4882a593Smuzhiyun 		fmt = "M[%d]";
294*4882a593Smuzhiyun 		break;
295*4882a593Smuzhiyun 	case BPF_LDX | BPF_MEM:
296*4882a593Smuzhiyun 		op = op_table[BPF_LDX];
297*4882a593Smuzhiyun 		fmt = "M[%d]";
298*4882a593Smuzhiyun 		break;
299*4882a593Smuzhiyun 	case BPF_JMP_JA:
300*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JA];
301*4882a593Smuzhiyun 		fmt = "%d";
302*4882a593Smuzhiyun 		val = i + 1 + f.k;
303*4882a593Smuzhiyun 		break;
304*4882a593Smuzhiyun 	case BPF_JMP_JGT | BPF_X:
305*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JGT];
306*4882a593Smuzhiyun 		fmt = "x";
307*4882a593Smuzhiyun 		break;
308*4882a593Smuzhiyun 	case BPF_JMP_JGT | BPF_K:
309*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JGT];
310*4882a593Smuzhiyun 		fmt = "#%#x";
311*4882a593Smuzhiyun 		break;
312*4882a593Smuzhiyun 	case BPF_JMP_JGE | BPF_X:
313*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JGE];
314*4882a593Smuzhiyun 		fmt = "x";
315*4882a593Smuzhiyun 		break;
316*4882a593Smuzhiyun 	case BPF_JMP_JGE | BPF_K:
317*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JGE];
318*4882a593Smuzhiyun 		fmt = "#%#x";
319*4882a593Smuzhiyun 		break;
320*4882a593Smuzhiyun 	case BPF_JMP_JEQ | BPF_X:
321*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JEQ];
322*4882a593Smuzhiyun 		fmt = "x";
323*4882a593Smuzhiyun 		break;
324*4882a593Smuzhiyun 	case BPF_JMP_JEQ | BPF_K:
325*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JEQ];
326*4882a593Smuzhiyun 		fmt = "#%#x";
327*4882a593Smuzhiyun 		break;
328*4882a593Smuzhiyun 	case BPF_JMP_JSET | BPF_X:
329*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JSET];
330*4882a593Smuzhiyun 		fmt = "x";
331*4882a593Smuzhiyun 		break;
332*4882a593Smuzhiyun 	case BPF_JMP_JSET | BPF_K:
333*4882a593Smuzhiyun 		op = op_table[BPF_JMP_JSET];
334*4882a593Smuzhiyun 		fmt = "#%#x";
335*4882a593Smuzhiyun 		break;
336*4882a593Smuzhiyun 	case BPF_ALU_NEG:
337*4882a593Smuzhiyun 		op = op_table[BPF_ALU_NEG];
338*4882a593Smuzhiyun 		fmt = "";
339*4882a593Smuzhiyun 		break;
340*4882a593Smuzhiyun 	case BPF_ALU_LSH | BPF_X:
341*4882a593Smuzhiyun 		op = op_table[BPF_ALU_LSH];
342*4882a593Smuzhiyun 		fmt = "x";
343*4882a593Smuzhiyun 		break;
344*4882a593Smuzhiyun 	case BPF_ALU_LSH | BPF_K:
345*4882a593Smuzhiyun 		op = op_table[BPF_ALU_LSH];
346*4882a593Smuzhiyun 		fmt = "#%d";
347*4882a593Smuzhiyun 		break;
348*4882a593Smuzhiyun 	case BPF_ALU_RSH | BPF_X:
349*4882a593Smuzhiyun 		op = op_table[BPF_ALU_RSH];
350*4882a593Smuzhiyun 		fmt = "x";
351*4882a593Smuzhiyun 		break;
352*4882a593Smuzhiyun 	case BPF_ALU_RSH | BPF_K:
353*4882a593Smuzhiyun 		op = op_table[BPF_ALU_RSH];
354*4882a593Smuzhiyun 		fmt = "#%d";
355*4882a593Smuzhiyun 		break;
356*4882a593Smuzhiyun 	case BPF_ALU_ADD | BPF_X:
357*4882a593Smuzhiyun 		op = op_table[BPF_ALU_ADD];
358*4882a593Smuzhiyun 		fmt = "x";
359*4882a593Smuzhiyun 		break;
360*4882a593Smuzhiyun 	case BPF_ALU_ADD | BPF_K:
361*4882a593Smuzhiyun 		op = op_table[BPF_ALU_ADD];
362*4882a593Smuzhiyun 		fmt = "#%d";
363*4882a593Smuzhiyun 		break;
364*4882a593Smuzhiyun 	case BPF_ALU_SUB | BPF_X:
365*4882a593Smuzhiyun 		op = op_table[BPF_ALU_SUB];
366*4882a593Smuzhiyun 		fmt = "x";
367*4882a593Smuzhiyun 		break;
368*4882a593Smuzhiyun 	case BPF_ALU_SUB | BPF_K:
369*4882a593Smuzhiyun 		op = op_table[BPF_ALU_SUB];
370*4882a593Smuzhiyun 		fmt = "#%d";
371*4882a593Smuzhiyun 		break;
372*4882a593Smuzhiyun 	case BPF_ALU_MUL | BPF_X:
373*4882a593Smuzhiyun 		op = op_table[BPF_ALU_MUL];
374*4882a593Smuzhiyun 		fmt = "x";
375*4882a593Smuzhiyun 		break;
376*4882a593Smuzhiyun 	case BPF_ALU_MUL | BPF_K:
377*4882a593Smuzhiyun 		op = op_table[BPF_ALU_MUL];
378*4882a593Smuzhiyun 		fmt = "#%d";
379*4882a593Smuzhiyun 		break;
380*4882a593Smuzhiyun 	case BPF_ALU_DIV | BPF_X:
381*4882a593Smuzhiyun 		op = op_table[BPF_ALU_DIV];
382*4882a593Smuzhiyun 		fmt = "x";
383*4882a593Smuzhiyun 		break;
384*4882a593Smuzhiyun 	case BPF_ALU_DIV | BPF_K:
385*4882a593Smuzhiyun 		op = op_table[BPF_ALU_DIV];
386*4882a593Smuzhiyun 		fmt = "#%d";
387*4882a593Smuzhiyun 		break;
388*4882a593Smuzhiyun 	case BPF_ALU_MOD | BPF_X:
389*4882a593Smuzhiyun 		op = op_table[BPF_ALU_MOD];
390*4882a593Smuzhiyun 		fmt = "x";
391*4882a593Smuzhiyun 		break;
392*4882a593Smuzhiyun 	case BPF_ALU_MOD | BPF_K:
393*4882a593Smuzhiyun 		op = op_table[BPF_ALU_MOD];
394*4882a593Smuzhiyun 		fmt = "#%d";
395*4882a593Smuzhiyun 		break;
396*4882a593Smuzhiyun 	case BPF_ALU_AND | BPF_X:
397*4882a593Smuzhiyun 		op = op_table[BPF_ALU_AND];
398*4882a593Smuzhiyun 		fmt = "x";
399*4882a593Smuzhiyun 		break;
400*4882a593Smuzhiyun 	case BPF_ALU_AND | BPF_K:
401*4882a593Smuzhiyun 		op = op_table[BPF_ALU_AND];
402*4882a593Smuzhiyun 		fmt = "#%#x";
403*4882a593Smuzhiyun 		break;
404*4882a593Smuzhiyun 	case BPF_ALU_OR | BPF_X:
405*4882a593Smuzhiyun 		op = op_table[BPF_ALU_OR];
406*4882a593Smuzhiyun 		fmt = "x";
407*4882a593Smuzhiyun 		break;
408*4882a593Smuzhiyun 	case BPF_ALU_OR | BPF_K:
409*4882a593Smuzhiyun 		op = op_table[BPF_ALU_OR];
410*4882a593Smuzhiyun 		fmt = "#%#x";
411*4882a593Smuzhiyun 		break;
412*4882a593Smuzhiyun 	case BPF_ALU_XOR | BPF_X:
413*4882a593Smuzhiyun 		op = op_table[BPF_ALU_XOR];
414*4882a593Smuzhiyun 		fmt = "x";
415*4882a593Smuzhiyun 		break;
416*4882a593Smuzhiyun 	case BPF_ALU_XOR | BPF_K:
417*4882a593Smuzhiyun 		op = op_table[BPF_ALU_XOR];
418*4882a593Smuzhiyun 		fmt = "#%#x";
419*4882a593Smuzhiyun 		break;
420*4882a593Smuzhiyun 	default:
421*4882a593Smuzhiyun 		op = "nosup";
422*4882a593Smuzhiyun 		fmt = "%#x";
423*4882a593Smuzhiyun 		val = f.code;
424*4882a593Smuzhiyun 		break;
425*4882a593Smuzhiyun 	}
426*4882a593Smuzhiyun 
427*4882a593Smuzhiyun 	memset(buf, 0, sizeof(buf));
428*4882a593Smuzhiyun 	snprintf(buf, sizeof(buf), fmt, val);
429*4882a593Smuzhiyun 	buf[sizeof(buf) - 1] = 0;
430*4882a593Smuzhiyun 
431*4882a593Smuzhiyun 	if ((BPF_CLASS(f.code) == BPF_JMP && BPF_OP(f.code) != BPF_JA))
432*4882a593Smuzhiyun 		rl_printf("l%d:\t%s %s, l%d, l%d\n", i, op, buf,
433*4882a593Smuzhiyun 			  i + 1 + f.jt, i + 1 + f.jf);
434*4882a593Smuzhiyun 	else
435*4882a593Smuzhiyun 		rl_printf("l%d:\t%s %s\n", i, op, buf);
436*4882a593Smuzhiyun }
437*4882a593Smuzhiyun 
bpf_dump_curr(struct bpf_regs * r,struct sock_filter * f)438*4882a593Smuzhiyun static void bpf_dump_curr(struct bpf_regs *r, struct sock_filter *f)
439*4882a593Smuzhiyun {
440*4882a593Smuzhiyun 	int i, m = 0;
441*4882a593Smuzhiyun 
442*4882a593Smuzhiyun 	rl_printf("pc:       [%u]\n", r->Pc);
443*4882a593Smuzhiyun 	rl_printf("code:     [%u] jt[%u] jf[%u] k[%u]\n",
444*4882a593Smuzhiyun 		  f->code, f->jt, f->jf, f->k);
445*4882a593Smuzhiyun 	rl_printf("curr:     ");
446*4882a593Smuzhiyun 	bpf_disasm(*f, r->Pc);
447*4882a593Smuzhiyun 
448*4882a593Smuzhiyun 	if (f->jt || f->jf) {
449*4882a593Smuzhiyun 		rl_printf("jt:       ");
450*4882a593Smuzhiyun 		bpf_disasm(*(f + f->jt + 1), r->Pc + f->jt + 1);
451*4882a593Smuzhiyun 		rl_printf("jf:       ");
452*4882a593Smuzhiyun 		bpf_disasm(*(f + f->jf + 1), r->Pc + f->jf + 1);
453*4882a593Smuzhiyun 	}
454*4882a593Smuzhiyun 
455*4882a593Smuzhiyun 	rl_printf("A:        [%#08x][%u]\n", r->A, r->A);
456*4882a593Smuzhiyun 	rl_printf("X:        [%#08x][%u]\n", r->X, r->X);
457*4882a593Smuzhiyun 	if (r->Rs)
458*4882a593Smuzhiyun 		rl_printf("ret:      [%#08x][%u]!\n", r->R, r->R);
459*4882a593Smuzhiyun 
460*4882a593Smuzhiyun 	for (i = 0; i < BPF_MEMWORDS; i++) {
461*4882a593Smuzhiyun 		if (r->M[i]) {
462*4882a593Smuzhiyun 			m++;
463*4882a593Smuzhiyun 			rl_printf("M[%d]: [%#08x][%u]\n", i, r->M[i], r->M[i]);
464*4882a593Smuzhiyun 		}
465*4882a593Smuzhiyun 	}
466*4882a593Smuzhiyun 	if (m == 0)
467*4882a593Smuzhiyun 		rl_printf("M[0,%d]:  [%#08x][%u]\n", BPF_MEMWORDS - 1, 0, 0);
468*4882a593Smuzhiyun }
469*4882a593Smuzhiyun 
bpf_dump_pkt(uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)470*4882a593Smuzhiyun static void bpf_dump_pkt(uint8_t *pkt, uint32_t pkt_caplen, uint32_t pkt_len)
471*4882a593Smuzhiyun {
472*4882a593Smuzhiyun 	if (pkt_caplen != pkt_len)
473*4882a593Smuzhiyun 		rl_printf("cap: %u, len: %u\n", pkt_caplen, pkt_len);
474*4882a593Smuzhiyun 	else
475*4882a593Smuzhiyun 		rl_printf("len: %u\n", pkt_len);
476*4882a593Smuzhiyun 
477*4882a593Smuzhiyun 	hex_dump(pkt, pkt_caplen);
478*4882a593Smuzhiyun }
479*4882a593Smuzhiyun 
bpf_disasm_all(const struct sock_filter * f,unsigned int len)480*4882a593Smuzhiyun static void bpf_disasm_all(const struct sock_filter *f, unsigned int len)
481*4882a593Smuzhiyun {
482*4882a593Smuzhiyun 	unsigned int i;
483*4882a593Smuzhiyun 
484*4882a593Smuzhiyun 	for (i = 0; i < len; i++)
485*4882a593Smuzhiyun 		bpf_disasm(f[i], i);
486*4882a593Smuzhiyun }
487*4882a593Smuzhiyun 
bpf_dump_all(const struct sock_filter * f,unsigned int len)488*4882a593Smuzhiyun static void bpf_dump_all(const struct sock_filter *f, unsigned int len)
489*4882a593Smuzhiyun {
490*4882a593Smuzhiyun 	unsigned int i;
491*4882a593Smuzhiyun 
492*4882a593Smuzhiyun 	rl_printf("/* { op, jt, jf, k }, */\n");
493*4882a593Smuzhiyun 	for (i = 0; i < len; i++)
494*4882a593Smuzhiyun 		rl_printf("{ %#04x, %2u, %2u, %#010x },\n",
495*4882a593Smuzhiyun 			  f[i].code, f[i].jt, f[i].jf, f[i].k);
496*4882a593Smuzhiyun }
497*4882a593Smuzhiyun 
bpf_runnable(struct sock_filter * f,unsigned int len)498*4882a593Smuzhiyun static bool bpf_runnable(struct sock_filter *f, unsigned int len)
499*4882a593Smuzhiyun {
500*4882a593Smuzhiyun 	int sock, ret, i;
501*4882a593Smuzhiyun 	struct sock_fprog bpf = {
502*4882a593Smuzhiyun 		.filter = f,
503*4882a593Smuzhiyun 		.len = len,
504*4882a593Smuzhiyun 	};
505*4882a593Smuzhiyun 
506*4882a593Smuzhiyun 	sock = socket(AF_INET, SOCK_DGRAM, 0);
507*4882a593Smuzhiyun 	if (sock < 0) {
508*4882a593Smuzhiyun 		rl_printf("cannot open socket!\n");
509*4882a593Smuzhiyun 		return false;
510*4882a593Smuzhiyun 	}
511*4882a593Smuzhiyun 	ret = setsockopt(sock, SOL_SOCKET, SO_ATTACH_FILTER, &bpf, sizeof(bpf));
512*4882a593Smuzhiyun 	close(sock);
513*4882a593Smuzhiyun 	if (ret < 0) {
514*4882a593Smuzhiyun 		rl_printf("program not allowed to run by kernel!\n");
515*4882a593Smuzhiyun 		return false;
516*4882a593Smuzhiyun 	}
517*4882a593Smuzhiyun 	for (i = 0; i < len; i++) {
518*4882a593Smuzhiyun 		if (BPF_CLASS(f[i].code) == BPF_LD &&
519*4882a593Smuzhiyun 		    f[i].k > SKF_AD_OFF) {
520*4882a593Smuzhiyun 			rl_printf("extensions currently not supported!\n");
521*4882a593Smuzhiyun 			return false;
522*4882a593Smuzhiyun 		}
523*4882a593Smuzhiyun 	}
524*4882a593Smuzhiyun 
525*4882a593Smuzhiyun 	return true;
526*4882a593Smuzhiyun }
527*4882a593Smuzhiyun 
bpf_reset_breakpoints(void)528*4882a593Smuzhiyun static void bpf_reset_breakpoints(void)
529*4882a593Smuzhiyun {
530*4882a593Smuzhiyun 	int i;
531*4882a593Smuzhiyun 
532*4882a593Smuzhiyun 	for (i = 0; i < array_size(bpf_breakpoints); i++)
533*4882a593Smuzhiyun 		bpf_breakpoints[i] = -1;
534*4882a593Smuzhiyun }
535*4882a593Smuzhiyun 
bpf_set_breakpoints(unsigned int where)536*4882a593Smuzhiyun static void bpf_set_breakpoints(unsigned int where)
537*4882a593Smuzhiyun {
538*4882a593Smuzhiyun 	int i;
539*4882a593Smuzhiyun 	bool set = false;
540*4882a593Smuzhiyun 
541*4882a593Smuzhiyun 	for (i = 0; i < array_size(bpf_breakpoints); i++) {
542*4882a593Smuzhiyun 		if (bpf_breakpoints[i] == (int) where) {
543*4882a593Smuzhiyun 			rl_printf("breakpoint already set!\n");
544*4882a593Smuzhiyun 			set = true;
545*4882a593Smuzhiyun 			break;
546*4882a593Smuzhiyun 		}
547*4882a593Smuzhiyun 
548*4882a593Smuzhiyun 		if (bpf_breakpoints[i] == -1 && set == false) {
549*4882a593Smuzhiyun 			bpf_breakpoints[i] = where;
550*4882a593Smuzhiyun 			set = true;
551*4882a593Smuzhiyun 		}
552*4882a593Smuzhiyun 	}
553*4882a593Smuzhiyun 
554*4882a593Smuzhiyun 	if (!set)
555*4882a593Smuzhiyun 		rl_printf("too many breakpoints set, reset first!\n");
556*4882a593Smuzhiyun }
557*4882a593Smuzhiyun 
bpf_dump_breakpoints(void)558*4882a593Smuzhiyun static void bpf_dump_breakpoints(void)
559*4882a593Smuzhiyun {
560*4882a593Smuzhiyun 	int i;
561*4882a593Smuzhiyun 
562*4882a593Smuzhiyun 	rl_printf("breakpoints: ");
563*4882a593Smuzhiyun 
564*4882a593Smuzhiyun 	for (i = 0; i < array_size(bpf_breakpoints); i++) {
565*4882a593Smuzhiyun 		if (bpf_breakpoints[i] < 0)
566*4882a593Smuzhiyun 			continue;
567*4882a593Smuzhiyun 		rl_printf("%d ", bpf_breakpoints[i]);
568*4882a593Smuzhiyun 	}
569*4882a593Smuzhiyun 
570*4882a593Smuzhiyun 	rl_printf("\n");
571*4882a593Smuzhiyun }
572*4882a593Smuzhiyun 
bpf_reset(void)573*4882a593Smuzhiyun static void bpf_reset(void)
574*4882a593Smuzhiyun {
575*4882a593Smuzhiyun 	bpf_regs_len = 0;
576*4882a593Smuzhiyun 
577*4882a593Smuzhiyun 	memset(bpf_regs, 0, sizeof(bpf_regs));
578*4882a593Smuzhiyun 	memset(&bpf_curr, 0, sizeof(bpf_curr));
579*4882a593Smuzhiyun }
580*4882a593Smuzhiyun 
bpf_safe_regs(void)581*4882a593Smuzhiyun static void bpf_safe_regs(void)
582*4882a593Smuzhiyun {
583*4882a593Smuzhiyun 	memcpy(&bpf_regs[bpf_regs_len++], &bpf_curr, sizeof(bpf_curr));
584*4882a593Smuzhiyun }
585*4882a593Smuzhiyun 
bpf_restore_regs(int off)586*4882a593Smuzhiyun static bool bpf_restore_regs(int off)
587*4882a593Smuzhiyun {
588*4882a593Smuzhiyun 	unsigned int index = bpf_regs_len - 1 + off;
589*4882a593Smuzhiyun 
590*4882a593Smuzhiyun 	if (index == 0) {
591*4882a593Smuzhiyun 		bpf_reset();
592*4882a593Smuzhiyun 		return true;
593*4882a593Smuzhiyun 	} else if (index < bpf_regs_len) {
594*4882a593Smuzhiyun 		memcpy(&bpf_curr, &bpf_regs[index], sizeof(bpf_curr));
595*4882a593Smuzhiyun 		bpf_regs_len = index;
596*4882a593Smuzhiyun 		return true;
597*4882a593Smuzhiyun 	} else {
598*4882a593Smuzhiyun 		rl_printf("reached bottom of register history stack!\n");
599*4882a593Smuzhiyun 		return false;
600*4882a593Smuzhiyun 	}
601*4882a593Smuzhiyun }
602*4882a593Smuzhiyun 
extract_u32(uint8_t * pkt,uint32_t off)603*4882a593Smuzhiyun static uint32_t extract_u32(uint8_t *pkt, uint32_t off)
604*4882a593Smuzhiyun {
605*4882a593Smuzhiyun 	uint32_t r;
606*4882a593Smuzhiyun 
607*4882a593Smuzhiyun 	memcpy(&r, &pkt[off], sizeof(r));
608*4882a593Smuzhiyun 
609*4882a593Smuzhiyun 	return ntohl(r);
610*4882a593Smuzhiyun }
611*4882a593Smuzhiyun 
extract_u16(uint8_t * pkt,uint32_t off)612*4882a593Smuzhiyun static uint16_t extract_u16(uint8_t *pkt, uint32_t off)
613*4882a593Smuzhiyun {
614*4882a593Smuzhiyun 	uint16_t r;
615*4882a593Smuzhiyun 
616*4882a593Smuzhiyun 	memcpy(&r, &pkt[off], sizeof(r));
617*4882a593Smuzhiyun 
618*4882a593Smuzhiyun 	return ntohs(r);
619*4882a593Smuzhiyun }
620*4882a593Smuzhiyun 
extract_u8(uint8_t * pkt,uint32_t off)621*4882a593Smuzhiyun static uint8_t extract_u8(uint8_t *pkt, uint32_t off)
622*4882a593Smuzhiyun {
623*4882a593Smuzhiyun 	return pkt[off];
624*4882a593Smuzhiyun }
625*4882a593Smuzhiyun 
set_return(struct bpf_regs * r)626*4882a593Smuzhiyun static void set_return(struct bpf_regs *r)
627*4882a593Smuzhiyun {
628*4882a593Smuzhiyun 	r->R = 0;
629*4882a593Smuzhiyun 	r->Rs = true;
630*4882a593Smuzhiyun }
631*4882a593Smuzhiyun 
bpf_single_step(struct bpf_regs * r,struct sock_filter * f,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)632*4882a593Smuzhiyun static void bpf_single_step(struct bpf_regs *r, struct sock_filter *f,
633*4882a593Smuzhiyun 			    uint8_t *pkt, uint32_t pkt_caplen,
634*4882a593Smuzhiyun 			    uint32_t pkt_len)
635*4882a593Smuzhiyun {
636*4882a593Smuzhiyun 	uint32_t K = f->k;
637*4882a593Smuzhiyun 	int d;
638*4882a593Smuzhiyun 
639*4882a593Smuzhiyun 	switch (f->code) {
640*4882a593Smuzhiyun 	case BPF_RET | BPF_K:
641*4882a593Smuzhiyun 		r->R = K;
642*4882a593Smuzhiyun 		r->Rs = true;
643*4882a593Smuzhiyun 		break;
644*4882a593Smuzhiyun 	case BPF_RET | BPF_A:
645*4882a593Smuzhiyun 		r->R = r->A;
646*4882a593Smuzhiyun 		r->Rs = true;
647*4882a593Smuzhiyun 		break;
648*4882a593Smuzhiyun 	case BPF_RET | BPF_X:
649*4882a593Smuzhiyun 		r->R = r->X;
650*4882a593Smuzhiyun 		r->Rs = true;
651*4882a593Smuzhiyun 		break;
652*4882a593Smuzhiyun 	case BPF_MISC_TAX:
653*4882a593Smuzhiyun 		r->X = r->A;
654*4882a593Smuzhiyun 		break;
655*4882a593Smuzhiyun 	case BPF_MISC_TXA:
656*4882a593Smuzhiyun 		r->A = r->X;
657*4882a593Smuzhiyun 		break;
658*4882a593Smuzhiyun 	case BPF_ST:
659*4882a593Smuzhiyun 		r->M[K] = r->A;
660*4882a593Smuzhiyun 		break;
661*4882a593Smuzhiyun 	case BPF_STX:
662*4882a593Smuzhiyun 		r->M[K] = r->X;
663*4882a593Smuzhiyun 		break;
664*4882a593Smuzhiyun 	case BPF_LD_W | BPF_ABS:
665*4882a593Smuzhiyun 		d = pkt_caplen - K;
666*4882a593Smuzhiyun 		if (d >= sizeof(uint32_t))
667*4882a593Smuzhiyun 			r->A = extract_u32(pkt, K);
668*4882a593Smuzhiyun 		else
669*4882a593Smuzhiyun 			set_return(r);
670*4882a593Smuzhiyun 		break;
671*4882a593Smuzhiyun 	case BPF_LD_H | BPF_ABS:
672*4882a593Smuzhiyun 		d = pkt_caplen - K;
673*4882a593Smuzhiyun 		if (d >= sizeof(uint16_t))
674*4882a593Smuzhiyun 			r->A = extract_u16(pkt, K);
675*4882a593Smuzhiyun 		else
676*4882a593Smuzhiyun 			set_return(r);
677*4882a593Smuzhiyun 		break;
678*4882a593Smuzhiyun 	case BPF_LD_B | BPF_ABS:
679*4882a593Smuzhiyun 		d = pkt_caplen - K;
680*4882a593Smuzhiyun 		if (d >= sizeof(uint8_t))
681*4882a593Smuzhiyun 			r->A = extract_u8(pkt, K);
682*4882a593Smuzhiyun 		else
683*4882a593Smuzhiyun 			set_return(r);
684*4882a593Smuzhiyun 		break;
685*4882a593Smuzhiyun 	case BPF_LD_W | BPF_IND:
686*4882a593Smuzhiyun 		d = pkt_caplen - (r->X + K);
687*4882a593Smuzhiyun 		if (d >= sizeof(uint32_t))
688*4882a593Smuzhiyun 			r->A = extract_u32(pkt, r->X + K);
689*4882a593Smuzhiyun 		break;
690*4882a593Smuzhiyun 	case BPF_LD_H | BPF_IND:
691*4882a593Smuzhiyun 		d = pkt_caplen - (r->X + K);
692*4882a593Smuzhiyun 		if (d >= sizeof(uint16_t))
693*4882a593Smuzhiyun 			r->A = extract_u16(pkt, r->X + K);
694*4882a593Smuzhiyun 		else
695*4882a593Smuzhiyun 			set_return(r);
696*4882a593Smuzhiyun 		break;
697*4882a593Smuzhiyun 	case BPF_LD_B | BPF_IND:
698*4882a593Smuzhiyun 		d = pkt_caplen - (r->X + K);
699*4882a593Smuzhiyun 		if (d >= sizeof(uint8_t))
700*4882a593Smuzhiyun 			r->A = extract_u8(pkt, r->X + K);
701*4882a593Smuzhiyun 		else
702*4882a593Smuzhiyun 			set_return(r);
703*4882a593Smuzhiyun 		break;
704*4882a593Smuzhiyun 	case BPF_LDX_B | BPF_MSH:
705*4882a593Smuzhiyun 		d = pkt_caplen - K;
706*4882a593Smuzhiyun 		if (d >= sizeof(uint8_t)) {
707*4882a593Smuzhiyun 			r->X = extract_u8(pkt, K);
708*4882a593Smuzhiyun 			r->X = (r->X & 0xf) << 2;
709*4882a593Smuzhiyun 		} else
710*4882a593Smuzhiyun 			set_return(r);
711*4882a593Smuzhiyun 		break;
712*4882a593Smuzhiyun 	case BPF_LD_W | BPF_LEN:
713*4882a593Smuzhiyun 		r->A = pkt_len;
714*4882a593Smuzhiyun 		break;
715*4882a593Smuzhiyun 	case BPF_LDX_W | BPF_LEN:
716*4882a593Smuzhiyun 		r->A = pkt_len;
717*4882a593Smuzhiyun 		break;
718*4882a593Smuzhiyun 	case BPF_LD | BPF_IMM:
719*4882a593Smuzhiyun 		r->A = K;
720*4882a593Smuzhiyun 		break;
721*4882a593Smuzhiyun 	case BPF_LDX | BPF_IMM:
722*4882a593Smuzhiyun 		r->X = K;
723*4882a593Smuzhiyun 		break;
724*4882a593Smuzhiyun 	case BPF_LD | BPF_MEM:
725*4882a593Smuzhiyun 		r->A = r->M[K];
726*4882a593Smuzhiyun 		break;
727*4882a593Smuzhiyun 	case BPF_LDX | BPF_MEM:
728*4882a593Smuzhiyun 		r->X = r->M[K];
729*4882a593Smuzhiyun 		break;
730*4882a593Smuzhiyun 	case BPF_JMP_JA:
731*4882a593Smuzhiyun 		r->Pc += K;
732*4882a593Smuzhiyun 		break;
733*4882a593Smuzhiyun 	case BPF_JMP_JGT | BPF_X:
734*4882a593Smuzhiyun 		r->Pc += r->A > r->X ? f->jt : f->jf;
735*4882a593Smuzhiyun 		break;
736*4882a593Smuzhiyun 	case BPF_JMP_JGT | BPF_K:
737*4882a593Smuzhiyun 		r->Pc += r->A > K ? f->jt : f->jf;
738*4882a593Smuzhiyun 		break;
739*4882a593Smuzhiyun 	case BPF_JMP_JGE | BPF_X:
740*4882a593Smuzhiyun 		r->Pc += r->A >= r->X ? f->jt : f->jf;
741*4882a593Smuzhiyun 		break;
742*4882a593Smuzhiyun 	case BPF_JMP_JGE | BPF_K:
743*4882a593Smuzhiyun 		r->Pc += r->A >= K ? f->jt : f->jf;
744*4882a593Smuzhiyun 		break;
745*4882a593Smuzhiyun 	case BPF_JMP_JEQ | BPF_X:
746*4882a593Smuzhiyun 		r->Pc += r->A == r->X ? f->jt : f->jf;
747*4882a593Smuzhiyun 		break;
748*4882a593Smuzhiyun 	case BPF_JMP_JEQ | BPF_K:
749*4882a593Smuzhiyun 		r->Pc += r->A == K ? f->jt : f->jf;
750*4882a593Smuzhiyun 		break;
751*4882a593Smuzhiyun 	case BPF_JMP_JSET | BPF_X:
752*4882a593Smuzhiyun 		r->Pc += r->A & r->X ? f->jt : f->jf;
753*4882a593Smuzhiyun 		break;
754*4882a593Smuzhiyun 	case BPF_JMP_JSET | BPF_K:
755*4882a593Smuzhiyun 		r->Pc += r->A & K ? f->jt : f->jf;
756*4882a593Smuzhiyun 		break;
757*4882a593Smuzhiyun 	case BPF_ALU_NEG:
758*4882a593Smuzhiyun 		r->A = -r->A;
759*4882a593Smuzhiyun 		break;
760*4882a593Smuzhiyun 	case BPF_ALU_LSH | BPF_X:
761*4882a593Smuzhiyun 		r->A <<= r->X;
762*4882a593Smuzhiyun 		break;
763*4882a593Smuzhiyun 	case BPF_ALU_LSH | BPF_K:
764*4882a593Smuzhiyun 		r->A <<= K;
765*4882a593Smuzhiyun 		break;
766*4882a593Smuzhiyun 	case BPF_ALU_RSH | BPF_X:
767*4882a593Smuzhiyun 		r->A >>= r->X;
768*4882a593Smuzhiyun 		break;
769*4882a593Smuzhiyun 	case BPF_ALU_RSH | BPF_K:
770*4882a593Smuzhiyun 		r->A >>= K;
771*4882a593Smuzhiyun 		break;
772*4882a593Smuzhiyun 	case BPF_ALU_ADD | BPF_X:
773*4882a593Smuzhiyun 		r->A += r->X;
774*4882a593Smuzhiyun 		break;
775*4882a593Smuzhiyun 	case BPF_ALU_ADD | BPF_K:
776*4882a593Smuzhiyun 		r->A += K;
777*4882a593Smuzhiyun 		break;
778*4882a593Smuzhiyun 	case BPF_ALU_SUB | BPF_X:
779*4882a593Smuzhiyun 		r->A -= r->X;
780*4882a593Smuzhiyun 		break;
781*4882a593Smuzhiyun 	case BPF_ALU_SUB | BPF_K:
782*4882a593Smuzhiyun 		r->A -= K;
783*4882a593Smuzhiyun 		break;
784*4882a593Smuzhiyun 	case BPF_ALU_MUL | BPF_X:
785*4882a593Smuzhiyun 		r->A *= r->X;
786*4882a593Smuzhiyun 		break;
787*4882a593Smuzhiyun 	case BPF_ALU_MUL | BPF_K:
788*4882a593Smuzhiyun 		r->A *= K;
789*4882a593Smuzhiyun 		break;
790*4882a593Smuzhiyun 	case BPF_ALU_DIV | BPF_X:
791*4882a593Smuzhiyun 	case BPF_ALU_MOD | BPF_X:
792*4882a593Smuzhiyun 		if (r->X == 0) {
793*4882a593Smuzhiyun 			set_return(r);
794*4882a593Smuzhiyun 			break;
795*4882a593Smuzhiyun 		}
796*4882a593Smuzhiyun 		goto do_div;
797*4882a593Smuzhiyun 	case BPF_ALU_DIV | BPF_K:
798*4882a593Smuzhiyun 	case BPF_ALU_MOD | BPF_K:
799*4882a593Smuzhiyun 		if (K == 0) {
800*4882a593Smuzhiyun 			set_return(r);
801*4882a593Smuzhiyun 			break;
802*4882a593Smuzhiyun 		}
803*4882a593Smuzhiyun do_div:
804*4882a593Smuzhiyun 		switch (f->code) {
805*4882a593Smuzhiyun 		case BPF_ALU_DIV | BPF_X:
806*4882a593Smuzhiyun 			r->A /= r->X;
807*4882a593Smuzhiyun 			break;
808*4882a593Smuzhiyun 		case BPF_ALU_DIV | BPF_K:
809*4882a593Smuzhiyun 			r->A /= K;
810*4882a593Smuzhiyun 			break;
811*4882a593Smuzhiyun 		case BPF_ALU_MOD | BPF_X:
812*4882a593Smuzhiyun 			r->A %= r->X;
813*4882a593Smuzhiyun 			break;
814*4882a593Smuzhiyun 		case BPF_ALU_MOD | BPF_K:
815*4882a593Smuzhiyun 			r->A %= K;
816*4882a593Smuzhiyun 			break;
817*4882a593Smuzhiyun 		}
818*4882a593Smuzhiyun 		break;
819*4882a593Smuzhiyun 	case BPF_ALU_AND | BPF_X:
820*4882a593Smuzhiyun 		r->A &= r->X;
821*4882a593Smuzhiyun 		break;
822*4882a593Smuzhiyun 	case BPF_ALU_AND | BPF_K:
823*4882a593Smuzhiyun 		r->A &= K;
824*4882a593Smuzhiyun 		break;
825*4882a593Smuzhiyun 	case BPF_ALU_OR | BPF_X:
826*4882a593Smuzhiyun 		r->A |= r->X;
827*4882a593Smuzhiyun 		break;
828*4882a593Smuzhiyun 	case BPF_ALU_OR | BPF_K:
829*4882a593Smuzhiyun 		r->A |= K;
830*4882a593Smuzhiyun 		break;
831*4882a593Smuzhiyun 	case BPF_ALU_XOR | BPF_X:
832*4882a593Smuzhiyun 		r->A ^= r->X;
833*4882a593Smuzhiyun 		break;
834*4882a593Smuzhiyun 	case BPF_ALU_XOR | BPF_K:
835*4882a593Smuzhiyun 		r->A ^= K;
836*4882a593Smuzhiyun 		break;
837*4882a593Smuzhiyun 	}
838*4882a593Smuzhiyun }
839*4882a593Smuzhiyun 
bpf_pc_has_breakpoint(uint16_t pc)840*4882a593Smuzhiyun static bool bpf_pc_has_breakpoint(uint16_t pc)
841*4882a593Smuzhiyun {
842*4882a593Smuzhiyun 	int i;
843*4882a593Smuzhiyun 
844*4882a593Smuzhiyun 	for (i = 0; i < array_size(bpf_breakpoints); i++) {
845*4882a593Smuzhiyun 		if (bpf_breakpoints[i] < 0)
846*4882a593Smuzhiyun 			continue;
847*4882a593Smuzhiyun 		if (bpf_breakpoints[i] == pc)
848*4882a593Smuzhiyun 			return true;
849*4882a593Smuzhiyun 	}
850*4882a593Smuzhiyun 
851*4882a593Smuzhiyun 	return false;
852*4882a593Smuzhiyun }
853*4882a593Smuzhiyun 
bpf_handle_breakpoint(struct bpf_regs * r,struct sock_filter * f,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)854*4882a593Smuzhiyun static bool bpf_handle_breakpoint(struct bpf_regs *r, struct sock_filter *f,
855*4882a593Smuzhiyun 				  uint8_t *pkt, uint32_t pkt_caplen,
856*4882a593Smuzhiyun 				  uint32_t pkt_len)
857*4882a593Smuzhiyun {
858*4882a593Smuzhiyun 	rl_printf("-- register dump --\n");
859*4882a593Smuzhiyun 	bpf_dump_curr(r, &f[r->Pc]);
860*4882a593Smuzhiyun 	rl_printf("-- packet dump --\n");
861*4882a593Smuzhiyun 	bpf_dump_pkt(pkt, pkt_caplen, pkt_len);
862*4882a593Smuzhiyun 	rl_printf("(breakpoint)\n");
863*4882a593Smuzhiyun 	return true;
864*4882a593Smuzhiyun }
865*4882a593Smuzhiyun 
bpf_run_all(struct sock_filter * f,uint16_t bpf_len,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)866*4882a593Smuzhiyun static int bpf_run_all(struct sock_filter *f, uint16_t bpf_len, uint8_t *pkt,
867*4882a593Smuzhiyun 		       uint32_t pkt_caplen, uint32_t pkt_len)
868*4882a593Smuzhiyun {
869*4882a593Smuzhiyun 	bool stop = false;
870*4882a593Smuzhiyun 
871*4882a593Smuzhiyun 	while (bpf_curr.Rs == false && stop == false) {
872*4882a593Smuzhiyun 		bpf_safe_regs();
873*4882a593Smuzhiyun 
874*4882a593Smuzhiyun 		if (bpf_pc_has_breakpoint(bpf_curr.Pc))
875*4882a593Smuzhiyun 			stop = bpf_handle_breakpoint(&bpf_curr, f, pkt,
876*4882a593Smuzhiyun 						     pkt_caplen, pkt_len);
877*4882a593Smuzhiyun 
878*4882a593Smuzhiyun 		bpf_single_step(&bpf_curr, &f[bpf_curr.Pc], pkt, pkt_caplen,
879*4882a593Smuzhiyun 				pkt_len);
880*4882a593Smuzhiyun 		bpf_curr.Pc++;
881*4882a593Smuzhiyun 	}
882*4882a593Smuzhiyun 
883*4882a593Smuzhiyun 	return stop ? -1 : bpf_curr.R;
884*4882a593Smuzhiyun }
885*4882a593Smuzhiyun 
bpf_run_stepping(struct sock_filter * f,uint16_t bpf_len,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len,int next)886*4882a593Smuzhiyun static int bpf_run_stepping(struct sock_filter *f, uint16_t bpf_len,
887*4882a593Smuzhiyun 			    uint8_t *pkt, uint32_t pkt_caplen,
888*4882a593Smuzhiyun 			    uint32_t pkt_len, int next)
889*4882a593Smuzhiyun {
890*4882a593Smuzhiyun 	bool stop = false;
891*4882a593Smuzhiyun 	int i = 1;
892*4882a593Smuzhiyun 
893*4882a593Smuzhiyun 	while (bpf_curr.Rs == false && stop == false) {
894*4882a593Smuzhiyun 		bpf_safe_regs();
895*4882a593Smuzhiyun 
896*4882a593Smuzhiyun 		if (i++ == next)
897*4882a593Smuzhiyun 			stop = bpf_handle_breakpoint(&bpf_curr, f, pkt,
898*4882a593Smuzhiyun 						     pkt_caplen, pkt_len);
899*4882a593Smuzhiyun 
900*4882a593Smuzhiyun 		bpf_single_step(&bpf_curr, &f[bpf_curr.Pc], pkt, pkt_caplen,
901*4882a593Smuzhiyun 				pkt_len);
902*4882a593Smuzhiyun 		bpf_curr.Pc++;
903*4882a593Smuzhiyun 	}
904*4882a593Smuzhiyun 
905*4882a593Smuzhiyun 	return stop ? -1 : bpf_curr.R;
906*4882a593Smuzhiyun }
907*4882a593Smuzhiyun 
pcap_loaded(void)908*4882a593Smuzhiyun static bool pcap_loaded(void)
909*4882a593Smuzhiyun {
910*4882a593Smuzhiyun 	if (pcap_fd < 0)
911*4882a593Smuzhiyun 		rl_printf("no pcap file loaded!\n");
912*4882a593Smuzhiyun 
913*4882a593Smuzhiyun 	return pcap_fd >= 0;
914*4882a593Smuzhiyun }
915*4882a593Smuzhiyun 
pcap_curr_pkt(void)916*4882a593Smuzhiyun static struct pcap_pkthdr *pcap_curr_pkt(void)
917*4882a593Smuzhiyun {
918*4882a593Smuzhiyun 	return (void *) pcap_ptr_va_curr;
919*4882a593Smuzhiyun }
920*4882a593Smuzhiyun 
pcap_next_pkt(void)921*4882a593Smuzhiyun static bool pcap_next_pkt(void)
922*4882a593Smuzhiyun {
923*4882a593Smuzhiyun 	struct pcap_pkthdr *hdr = pcap_curr_pkt();
924*4882a593Smuzhiyun 
925*4882a593Smuzhiyun 	if (pcap_ptr_va_curr + sizeof(*hdr) -
926*4882a593Smuzhiyun 	    pcap_ptr_va_start >= pcap_map_size)
927*4882a593Smuzhiyun 		return false;
928*4882a593Smuzhiyun 	if (hdr->caplen == 0 || hdr->len == 0 || hdr->caplen > hdr->len)
929*4882a593Smuzhiyun 		return false;
930*4882a593Smuzhiyun 	if (pcap_ptr_va_curr + sizeof(*hdr) + hdr->caplen -
931*4882a593Smuzhiyun 	    pcap_ptr_va_start >= pcap_map_size)
932*4882a593Smuzhiyun 		return false;
933*4882a593Smuzhiyun 
934*4882a593Smuzhiyun 	pcap_ptr_va_curr += (sizeof(*hdr) + hdr->caplen);
935*4882a593Smuzhiyun 	return true;
936*4882a593Smuzhiyun }
937*4882a593Smuzhiyun 
pcap_reset_pkt(void)938*4882a593Smuzhiyun static void pcap_reset_pkt(void)
939*4882a593Smuzhiyun {
940*4882a593Smuzhiyun 	pcap_ptr_va_curr = pcap_ptr_va_start + sizeof(struct pcap_filehdr);
941*4882a593Smuzhiyun }
942*4882a593Smuzhiyun 
try_load_pcap(const char * file)943*4882a593Smuzhiyun static int try_load_pcap(const char *file)
944*4882a593Smuzhiyun {
945*4882a593Smuzhiyun 	struct pcap_filehdr *hdr;
946*4882a593Smuzhiyun 	struct stat sb;
947*4882a593Smuzhiyun 	int ret;
948*4882a593Smuzhiyun 
949*4882a593Smuzhiyun 	pcap_fd = open(file, O_RDONLY);
950*4882a593Smuzhiyun 	if (pcap_fd < 0) {
951*4882a593Smuzhiyun 		rl_printf("cannot open pcap [%s]!\n", strerror(errno));
952*4882a593Smuzhiyun 		return CMD_ERR;
953*4882a593Smuzhiyun 	}
954*4882a593Smuzhiyun 
955*4882a593Smuzhiyun 	ret = fstat(pcap_fd, &sb);
956*4882a593Smuzhiyun 	if (ret < 0) {
957*4882a593Smuzhiyun 		rl_printf("cannot fstat pcap file!\n");
958*4882a593Smuzhiyun 		return CMD_ERR;
959*4882a593Smuzhiyun 	}
960*4882a593Smuzhiyun 
961*4882a593Smuzhiyun 	if (!S_ISREG(sb.st_mode)) {
962*4882a593Smuzhiyun 		rl_printf("not a regular pcap file, duh!\n");
963*4882a593Smuzhiyun 		return CMD_ERR;
964*4882a593Smuzhiyun 	}
965*4882a593Smuzhiyun 
966*4882a593Smuzhiyun 	pcap_map_size = sb.st_size;
967*4882a593Smuzhiyun 	if (pcap_map_size <= sizeof(struct pcap_filehdr)) {
968*4882a593Smuzhiyun 		rl_printf("pcap file too small!\n");
969*4882a593Smuzhiyun 		return CMD_ERR;
970*4882a593Smuzhiyun 	}
971*4882a593Smuzhiyun 
972*4882a593Smuzhiyun 	pcap_ptr_va_start = mmap(NULL, pcap_map_size, PROT_READ,
973*4882a593Smuzhiyun 				 MAP_SHARED | MAP_LOCKED, pcap_fd, 0);
974*4882a593Smuzhiyun 	if (pcap_ptr_va_start == MAP_FAILED) {
975*4882a593Smuzhiyun 		rl_printf("mmap of file failed!");
976*4882a593Smuzhiyun 		return CMD_ERR;
977*4882a593Smuzhiyun 	}
978*4882a593Smuzhiyun 
979*4882a593Smuzhiyun 	hdr = (void *) pcap_ptr_va_start;
980*4882a593Smuzhiyun 	if (hdr->magic != TCPDUMP_MAGIC) {
981*4882a593Smuzhiyun 		rl_printf("wrong pcap magic!\n");
982*4882a593Smuzhiyun 		return CMD_ERR;
983*4882a593Smuzhiyun 	}
984*4882a593Smuzhiyun 
985*4882a593Smuzhiyun 	pcap_reset_pkt();
986*4882a593Smuzhiyun 
987*4882a593Smuzhiyun 	return CMD_OK;
988*4882a593Smuzhiyun 
989*4882a593Smuzhiyun }
990*4882a593Smuzhiyun 
try_close_pcap(void)991*4882a593Smuzhiyun static void try_close_pcap(void)
992*4882a593Smuzhiyun {
993*4882a593Smuzhiyun 	if (pcap_fd >= 0) {
994*4882a593Smuzhiyun 		munmap(pcap_ptr_va_start, pcap_map_size);
995*4882a593Smuzhiyun 		close(pcap_fd);
996*4882a593Smuzhiyun 
997*4882a593Smuzhiyun 		pcap_ptr_va_start = pcap_ptr_va_curr = NULL;
998*4882a593Smuzhiyun 		pcap_map_size = 0;
999*4882a593Smuzhiyun 		pcap_packet = 0;
1000*4882a593Smuzhiyun 		pcap_fd = -1;
1001*4882a593Smuzhiyun 	}
1002*4882a593Smuzhiyun }
1003*4882a593Smuzhiyun 
cmd_load_bpf(char * bpf_string)1004*4882a593Smuzhiyun static int cmd_load_bpf(char *bpf_string)
1005*4882a593Smuzhiyun {
1006*4882a593Smuzhiyun 	char sp, *token, separator = ',';
1007*4882a593Smuzhiyun 	unsigned short bpf_len, i = 0;
1008*4882a593Smuzhiyun 	struct sock_filter tmp;
1009*4882a593Smuzhiyun 
1010*4882a593Smuzhiyun 	bpf_prog_len = 0;
1011*4882a593Smuzhiyun 	memset(bpf_image, 0, sizeof(bpf_image));
1012*4882a593Smuzhiyun 
1013*4882a593Smuzhiyun 	if (sscanf(bpf_string, "%hu%c", &bpf_len, &sp) != 2 ||
1014*4882a593Smuzhiyun 	    sp != separator || bpf_len > BPF_MAXINSNS || bpf_len == 0) {
1015*4882a593Smuzhiyun 		rl_printf("syntax error in head length encoding!\n");
1016*4882a593Smuzhiyun 		return CMD_ERR;
1017*4882a593Smuzhiyun 	}
1018*4882a593Smuzhiyun 
1019*4882a593Smuzhiyun 	token = bpf_string;
1020*4882a593Smuzhiyun 	while ((token = strchr(token, separator)) && (++token)[0]) {
1021*4882a593Smuzhiyun 		if (i >= bpf_len) {
1022*4882a593Smuzhiyun 			rl_printf("program exceeds encoded length!\n");
1023*4882a593Smuzhiyun 			return CMD_ERR;
1024*4882a593Smuzhiyun 		}
1025*4882a593Smuzhiyun 
1026*4882a593Smuzhiyun 		if (sscanf(token, "%hu %hhu %hhu %u,",
1027*4882a593Smuzhiyun 			   &tmp.code, &tmp.jt, &tmp.jf, &tmp.k) != 4) {
1028*4882a593Smuzhiyun 			rl_printf("syntax error at instruction %d!\n", i);
1029*4882a593Smuzhiyun 			return CMD_ERR;
1030*4882a593Smuzhiyun 		}
1031*4882a593Smuzhiyun 
1032*4882a593Smuzhiyun 		bpf_image[i].code = tmp.code;
1033*4882a593Smuzhiyun 		bpf_image[i].jt = tmp.jt;
1034*4882a593Smuzhiyun 		bpf_image[i].jf = tmp.jf;
1035*4882a593Smuzhiyun 		bpf_image[i].k = tmp.k;
1036*4882a593Smuzhiyun 
1037*4882a593Smuzhiyun 		i++;
1038*4882a593Smuzhiyun 	}
1039*4882a593Smuzhiyun 
1040*4882a593Smuzhiyun 	if (i != bpf_len) {
1041*4882a593Smuzhiyun 		rl_printf("syntax error exceeding encoded length!\n");
1042*4882a593Smuzhiyun 		return CMD_ERR;
1043*4882a593Smuzhiyun 	} else
1044*4882a593Smuzhiyun 		bpf_prog_len = bpf_len;
1045*4882a593Smuzhiyun 	if (!bpf_runnable(bpf_image, bpf_prog_len))
1046*4882a593Smuzhiyun 		bpf_prog_len = 0;
1047*4882a593Smuzhiyun 
1048*4882a593Smuzhiyun 	return CMD_OK;
1049*4882a593Smuzhiyun }
1050*4882a593Smuzhiyun 
cmd_load_pcap(char * file)1051*4882a593Smuzhiyun static int cmd_load_pcap(char *file)
1052*4882a593Smuzhiyun {
1053*4882a593Smuzhiyun 	char *file_trim, *tmp;
1054*4882a593Smuzhiyun 
1055*4882a593Smuzhiyun 	file_trim = strtok_r(file, " ", &tmp);
1056*4882a593Smuzhiyun 	if (file_trim == NULL)
1057*4882a593Smuzhiyun 		return CMD_ERR;
1058*4882a593Smuzhiyun 
1059*4882a593Smuzhiyun 	try_close_pcap();
1060*4882a593Smuzhiyun 
1061*4882a593Smuzhiyun 	return try_load_pcap(file_trim);
1062*4882a593Smuzhiyun }
1063*4882a593Smuzhiyun 
cmd_load(char * arg)1064*4882a593Smuzhiyun static int cmd_load(char *arg)
1065*4882a593Smuzhiyun {
1066*4882a593Smuzhiyun 	char *subcmd, *cont = NULL, *tmp = strdup(arg);
1067*4882a593Smuzhiyun 	int ret = CMD_OK;
1068*4882a593Smuzhiyun 
1069*4882a593Smuzhiyun 	subcmd = strtok_r(tmp, " ", &cont);
1070*4882a593Smuzhiyun 	if (subcmd == NULL)
1071*4882a593Smuzhiyun 		goto out;
1072*4882a593Smuzhiyun 	if (matches(subcmd, "bpf") == 0) {
1073*4882a593Smuzhiyun 		bpf_reset();
1074*4882a593Smuzhiyun 		bpf_reset_breakpoints();
1075*4882a593Smuzhiyun 
1076*4882a593Smuzhiyun 		if (!cont)
1077*4882a593Smuzhiyun 			ret = CMD_ERR;
1078*4882a593Smuzhiyun 		else
1079*4882a593Smuzhiyun 			ret = cmd_load_bpf(cont);
1080*4882a593Smuzhiyun 	} else if (matches(subcmd, "pcap") == 0) {
1081*4882a593Smuzhiyun 		ret = cmd_load_pcap(cont);
1082*4882a593Smuzhiyun 	} else {
1083*4882a593Smuzhiyun out:
1084*4882a593Smuzhiyun 		rl_printf("bpf <code>:  load bpf code\n");
1085*4882a593Smuzhiyun 		rl_printf("pcap <file>: load pcap file\n");
1086*4882a593Smuzhiyun 		ret = CMD_ERR;
1087*4882a593Smuzhiyun 	}
1088*4882a593Smuzhiyun 
1089*4882a593Smuzhiyun 	free(tmp);
1090*4882a593Smuzhiyun 	return ret;
1091*4882a593Smuzhiyun }
1092*4882a593Smuzhiyun 
cmd_step(char * num)1093*4882a593Smuzhiyun static int cmd_step(char *num)
1094*4882a593Smuzhiyun {
1095*4882a593Smuzhiyun 	struct pcap_pkthdr *hdr;
1096*4882a593Smuzhiyun 	int steps, ret;
1097*4882a593Smuzhiyun 
1098*4882a593Smuzhiyun 	if (!bpf_prog_loaded() || !pcap_loaded())
1099*4882a593Smuzhiyun 		return CMD_ERR;
1100*4882a593Smuzhiyun 
1101*4882a593Smuzhiyun 	steps = strtol(num, NULL, 10);
1102*4882a593Smuzhiyun 	if (steps == 0 || strlen(num) == 0)
1103*4882a593Smuzhiyun 		steps = 1;
1104*4882a593Smuzhiyun 	if (steps < 0) {
1105*4882a593Smuzhiyun 		if (!bpf_restore_regs(steps))
1106*4882a593Smuzhiyun 			return CMD_ERR;
1107*4882a593Smuzhiyun 		steps = 1;
1108*4882a593Smuzhiyun 	}
1109*4882a593Smuzhiyun 
1110*4882a593Smuzhiyun 	hdr = pcap_curr_pkt();
1111*4882a593Smuzhiyun 	ret = bpf_run_stepping(bpf_image, bpf_prog_len,
1112*4882a593Smuzhiyun 			       (uint8_t *) hdr + sizeof(*hdr),
1113*4882a593Smuzhiyun 			       hdr->caplen, hdr->len, steps);
1114*4882a593Smuzhiyun 	if (ret >= 0 || bpf_curr.Rs) {
1115*4882a593Smuzhiyun 		bpf_reset();
1116*4882a593Smuzhiyun 		if (!pcap_next_pkt()) {
1117*4882a593Smuzhiyun 			rl_printf("(going back to first packet)\n");
1118*4882a593Smuzhiyun 			pcap_reset_pkt();
1119*4882a593Smuzhiyun 		} else {
1120*4882a593Smuzhiyun 			rl_printf("(next packet)\n");
1121*4882a593Smuzhiyun 		}
1122*4882a593Smuzhiyun 	}
1123*4882a593Smuzhiyun 
1124*4882a593Smuzhiyun 	return CMD_OK;
1125*4882a593Smuzhiyun }
1126*4882a593Smuzhiyun 
cmd_select(char * num)1127*4882a593Smuzhiyun static int cmd_select(char *num)
1128*4882a593Smuzhiyun {
1129*4882a593Smuzhiyun 	unsigned int which, i;
1130*4882a593Smuzhiyun 	bool have_next = true;
1131*4882a593Smuzhiyun 
1132*4882a593Smuzhiyun 	if (!pcap_loaded() || strlen(num) == 0)
1133*4882a593Smuzhiyun 		return CMD_ERR;
1134*4882a593Smuzhiyun 
1135*4882a593Smuzhiyun 	which = strtoul(num, NULL, 10);
1136*4882a593Smuzhiyun 	if (which == 0) {
1137*4882a593Smuzhiyun 		rl_printf("packet count starts with 1, clamping!\n");
1138*4882a593Smuzhiyun 		which = 1;
1139*4882a593Smuzhiyun 	}
1140*4882a593Smuzhiyun 
1141*4882a593Smuzhiyun 	pcap_reset_pkt();
1142*4882a593Smuzhiyun 	bpf_reset();
1143*4882a593Smuzhiyun 
1144*4882a593Smuzhiyun 	for (i = 0; i < which && (have_next = pcap_next_pkt()); i++)
1145*4882a593Smuzhiyun 		/* noop */;
1146*4882a593Smuzhiyun 	if (!have_next || pcap_curr_pkt() == NULL) {
1147*4882a593Smuzhiyun 		rl_printf("no packet #%u available!\n", which);
1148*4882a593Smuzhiyun 		pcap_reset_pkt();
1149*4882a593Smuzhiyun 		return CMD_ERR;
1150*4882a593Smuzhiyun 	}
1151*4882a593Smuzhiyun 
1152*4882a593Smuzhiyun 	return CMD_OK;
1153*4882a593Smuzhiyun }
1154*4882a593Smuzhiyun 
cmd_breakpoint(char * subcmd)1155*4882a593Smuzhiyun static int cmd_breakpoint(char *subcmd)
1156*4882a593Smuzhiyun {
1157*4882a593Smuzhiyun 	if (!bpf_prog_loaded())
1158*4882a593Smuzhiyun 		return CMD_ERR;
1159*4882a593Smuzhiyun 	if (strlen(subcmd) == 0)
1160*4882a593Smuzhiyun 		bpf_dump_breakpoints();
1161*4882a593Smuzhiyun 	else if (matches(subcmd, "reset") == 0)
1162*4882a593Smuzhiyun 		bpf_reset_breakpoints();
1163*4882a593Smuzhiyun 	else {
1164*4882a593Smuzhiyun 		unsigned int where = strtoul(subcmd, NULL, 10);
1165*4882a593Smuzhiyun 
1166*4882a593Smuzhiyun 		if (where < bpf_prog_len) {
1167*4882a593Smuzhiyun 			bpf_set_breakpoints(where);
1168*4882a593Smuzhiyun 			rl_printf("breakpoint at: ");
1169*4882a593Smuzhiyun 			bpf_disasm(bpf_image[where], where);
1170*4882a593Smuzhiyun 		}
1171*4882a593Smuzhiyun 	}
1172*4882a593Smuzhiyun 
1173*4882a593Smuzhiyun 	return CMD_OK;
1174*4882a593Smuzhiyun }
1175*4882a593Smuzhiyun 
cmd_run(char * num)1176*4882a593Smuzhiyun static int cmd_run(char *num)
1177*4882a593Smuzhiyun {
1178*4882a593Smuzhiyun 	static uint32_t pass, fail;
1179*4882a593Smuzhiyun 	bool has_limit = true;
1180*4882a593Smuzhiyun 	int pkts = 0, i = 0;
1181*4882a593Smuzhiyun 
1182*4882a593Smuzhiyun 	if (!bpf_prog_loaded() || !pcap_loaded())
1183*4882a593Smuzhiyun 		return CMD_ERR;
1184*4882a593Smuzhiyun 
1185*4882a593Smuzhiyun 	pkts = strtol(num, NULL, 10);
1186*4882a593Smuzhiyun 	if (pkts == 0 || strlen(num) == 0)
1187*4882a593Smuzhiyun 		has_limit = false;
1188*4882a593Smuzhiyun 
1189*4882a593Smuzhiyun 	do {
1190*4882a593Smuzhiyun 		struct pcap_pkthdr *hdr = pcap_curr_pkt();
1191*4882a593Smuzhiyun 		int ret = bpf_run_all(bpf_image, bpf_prog_len,
1192*4882a593Smuzhiyun 				      (uint8_t *) hdr + sizeof(*hdr),
1193*4882a593Smuzhiyun 				      hdr->caplen, hdr->len);
1194*4882a593Smuzhiyun 		if (ret > 0)
1195*4882a593Smuzhiyun 			pass++;
1196*4882a593Smuzhiyun 		else if (ret == 0)
1197*4882a593Smuzhiyun 			fail++;
1198*4882a593Smuzhiyun 		else
1199*4882a593Smuzhiyun 			return CMD_OK;
1200*4882a593Smuzhiyun 		bpf_reset();
1201*4882a593Smuzhiyun 	} while (pcap_next_pkt() && (!has_limit || (has_limit && ++i < pkts)));
1202*4882a593Smuzhiyun 
1203*4882a593Smuzhiyun 	rl_printf("bpf passes:%u fails:%u\n", pass, fail);
1204*4882a593Smuzhiyun 
1205*4882a593Smuzhiyun 	pcap_reset_pkt();
1206*4882a593Smuzhiyun 	bpf_reset();
1207*4882a593Smuzhiyun 
1208*4882a593Smuzhiyun 	pass = fail = 0;
1209*4882a593Smuzhiyun 	return CMD_OK;
1210*4882a593Smuzhiyun }
1211*4882a593Smuzhiyun 
cmd_disassemble(char * line_string)1212*4882a593Smuzhiyun static int cmd_disassemble(char *line_string)
1213*4882a593Smuzhiyun {
1214*4882a593Smuzhiyun 	bool single_line = false;
1215*4882a593Smuzhiyun 	unsigned long line;
1216*4882a593Smuzhiyun 
1217*4882a593Smuzhiyun 	if (!bpf_prog_loaded())
1218*4882a593Smuzhiyun 		return CMD_ERR;
1219*4882a593Smuzhiyun 	if (strlen(line_string) > 0 &&
1220*4882a593Smuzhiyun 	    (line = strtoul(line_string, NULL, 10)) < bpf_prog_len)
1221*4882a593Smuzhiyun 		single_line = true;
1222*4882a593Smuzhiyun 	if (single_line)
1223*4882a593Smuzhiyun 		bpf_disasm(bpf_image[line], line);
1224*4882a593Smuzhiyun 	else
1225*4882a593Smuzhiyun 		bpf_disasm_all(bpf_image, bpf_prog_len);
1226*4882a593Smuzhiyun 
1227*4882a593Smuzhiyun 	return CMD_OK;
1228*4882a593Smuzhiyun }
1229*4882a593Smuzhiyun 
cmd_dump(char * dontcare)1230*4882a593Smuzhiyun static int cmd_dump(char *dontcare)
1231*4882a593Smuzhiyun {
1232*4882a593Smuzhiyun 	if (!bpf_prog_loaded())
1233*4882a593Smuzhiyun 		return CMD_ERR;
1234*4882a593Smuzhiyun 
1235*4882a593Smuzhiyun 	bpf_dump_all(bpf_image, bpf_prog_len);
1236*4882a593Smuzhiyun 
1237*4882a593Smuzhiyun 	return CMD_OK;
1238*4882a593Smuzhiyun }
1239*4882a593Smuzhiyun 
cmd_quit(char * dontcare)1240*4882a593Smuzhiyun static int cmd_quit(char *dontcare)
1241*4882a593Smuzhiyun {
1242*4882a593Smuzhiyun 	return CMD_EX;
1243*4882a593Smuzhiyun }
1244*4882a593Smuzhiyun 
1245*4882a593Smuzhiyun static const struct shell_cmd cmds[] = {
1246*4882a593Smuzhiyun 	{ .name = "load", .func = cmd_load },
1247*4882a593Smuzhiyun 	{ .name = "select", .func = cmd_select },
1248*4882a593Smuzhiyun 	{ .name = "step", .func = cmd_step },
1249*4882a593Smuzhiyun 	{ .name = "run", .func = cmd_run },
1250*4882a593Smuzhiyun 	{ .name = "breakpoint", .func = cmd_breakpoint },
1251*4882a593Smuzhiyun 	{ .name = "disassemble", .func = cmd_disassemble },
1252*4882a593Smuzhiyun 	{ .name = "dump", .func = cmd_dump },
1253*4882a593Smuzhiyun 	{ .name = "quit", .func = cmd_quit },
1254*4882a593Smuzhiyun };
1255*4882a593Smuzhiyun 
execf(char * arg)1256*4882a593Smuzhiyun static int execf(char *arg)
1257*4882a593Smuzhiyun {
1258*4882a593Smuzhiyun 	char *cmd, *cont, *tmp = strdup(arg);
1259*4882a593Smuzhiyun 	int i, ret = 0, len;
1260*4882a593Smuzhiyun 
1261*4882a593Smuzhiyun 	cmd = strtok_r(tmp, " ", &cont);
1262*4882a593Smuzhiyun 	if (cmd == NULL)
1263*4882a593Smuzhiyun 		goto out;
1264*4882a593Smuzhiyun 	len = strlen(cmd);
1265*4882a593Smuzhiyun 	for (i = 0; i < array_size(cmds); i++) {
1266*4882a593Smuzhiyun 		if (len != strlen(cmds[i].name))
1267*4882a593Smuzhiyun 			continue;
1268*4882a593Smuzhiyun 		if (strncmp(cmds[i].name, cmd, len) == 0) {
1269*4882a593Smuzhiyun 			ret = cmds[i].func(cont);
1270*4882a593Smuzhiyun 			break;
1271*4882a593Smuzhiyun 		}
1272*4882a593Smuzhiyun 	}
1273*4882a593Smuzhiyun out:
1274*4882a593Smuzhiyun 	free(tmp);
1275*4882a593Smuzhiyun 	return ret;
1276*4882a593Smuzhiyun }
1277*4882a593Smuzhiyun 
shell_comp_gen(const char * buf,int state)1278*4882a593Smuzhiyun static char *shell_comp_gen(const char *buf, int state)
1279*4882a593Smuzhiyun {
1280*4882a593Smuzhiyun 	static int list_index, len;
1281*4882a593Smuzhiyun 
1282*4882a593Smuzhiyun 	if (!state) {
1283*4882a593Smuzhiyun 		list_index = 0;
1284*4882a593Smuzhiyun 		len = strlen(buf);
1285*4882a593Smuzhiyun 	}
1286*4882a593Smuzhiyun 
1287*4882a593Smuzhiyun 	for (; list_index < array_size(cmds); ) {
1288*4882a593Smuzhiyun 		const char *name = cmds[list_index].name;
1289*4882a593Smuzhiyun 
1290*4882a593Smuzhiyun 		list_index++;
1291*4882a593Smuzhiyun 		if (strncmp(name, buf, len) == 0)
1292*4882a593Smuzhiyun 			return strdup(name);
1293*4882a593Smuzhiyun 	}
1294*4882a593Smuzhiyun 
1295*4882a593Smuzhiyun 	return NULL;
1296*4882a593Smuzhiyun }
1297*4882a593Smuzhiyun 
shell_completion(const char * buf,int start,int end)1298*4882a593Smuzhiyun static char **shell_completion(const char *buf, int start, int end)
1299*4882a593Smuzhiyun {
1300*4882a593Smuzhiyun 	char **matches = NULL;
1301*4882a593Smuzhiyun 
1302*4882a593Smuzhiyun 	if (start == 0)
1303*4882a593Smuzhiyun 		matches = rl_completion_matches(buf, shell_comp_gen);
1304*4882a593Smuzhiyun 
1305*4882a593Smuzhiyun 	return matches;
1306*4882a593Smuzhiyun }
1307*4882a593Smuzhiyun 
intr_shell(int sig)1308*4882a593Smuzhiyun static void intr_shell(int sig)
1309*4882a593Smuzhiyun {
1310*4882a593Smuzhiyun 	if (rl_end)
1311*4882a593Smuzhiyun 		rl_kill_line(-1, 0);
1312*4882a593Smuzhiyun 
1313*4882a593Smuzhiyun 	rl_crlf();
1314*4882a593Smuzhiyun 	rl_refresh_line(0, 0);
1315*4882a593Smuzhiyun 	rl_free_line_state();
1316*4882a593Smuzhiyun }
1317*4882a593Smuzhiyun 
init_shell(FILE * fin,FILE * fout)1318*4882a593Smuzhiyun static void init_shell(FILE *fin, FILE *fout)
1319*4882a593Smuzhiyun {
1320*4882a593Smuzhiyun 	char file[128];
1321*4882a593Smuzhiyun 
1322*4882a593Smuzhiyun 	snprintf(file, sizeof(file), "%s/.bpf_dbg_history", getenv("HOME"));
1323*4882a593Smuzhiyun 	read_history(file);
1324*4882a593Smuzhiyun 
1325*4882a593Smuzhiyun 	rl_instream = fin;
1326*4882a593Smuzhiyun 	rl_outstream = fout;
1327*4882a593Smuzhiyun 
1328*4882a593Smuzhiyun 	rl_readline_name = "bpf_dbg";
1329*4882a593Smuzhiyun 	rl_terminal_name = getenv("TERM");
1330*4882a593Smuzhiyun 
1331*4882a593Smuzhiyun 	rl_catch_signals = 0;
1332*4882a593Smuzhiyun 	rl_catch_sigwinch = 1;
1333*4882a593Smuzhiyun 
1334*4882a593Smuzhiyun 	rl_attempted_completion_function = shell_completion;
1335*4882a593Smuzhiyun 
1336*4882a593Smuzhiyun 	rl_bind_key('\t', rl_complete);
1337*4882a593Smuzhiyun 
1338*4882a593Smuzhiyun 	rl_bind_key_in_map('\t', rl_complete, emacs_meta_keymap);
1339*4882a593Smuzhiyun 	rl_bind_key_in_map('\033', rl_complete, emacs_meta_keymap);
1340*4882a593Smuzhiyun 
1341*4882a593Smuzhiyun 	snprintf(file, sizeof(file), "%s/.bpf_dbg_init", getenv("HOME"));
1342*4882a593Smuzhiyun 	rl_read_init_file(file);
1343*4882a593Smuzhiyun 
1344*4882a593Smuzhiyun 	rl_prep_terminal(0);
1345*4882a593Smuzhiyun 	rl_set_signals();
1346*4882a593Smuzhiyun 
1347*4882a593Smuzhiyun 	signal(SIGINT, intr_shell);
1348*4882a593Smuzhiyun }
1349*4882a593Smuzhiyun 
exit_shell(FILE * fin,FILE * fout)1350*4882a593Smuzhiyun static void exit_shell(FILE *fin, FILE *fout)
1351*4882a593Smuzhiyun {
1352*4882a593Smuzhiyun 	char file[128];
1353*4882a593Smuzhiyun 
1354*4882a593Smuzhiyun 	snprintf(file, sizeof(file), "%s/.bpf_dbg_history", getenv("HOME"));
1355*4882a593Smuzhiyun 	write_history(file);
1356*4882a593Smuzhiyun 
1357*4882a593Smuzhiyun 	clear_history();
1358*4882a593Smuzhiyun 	rl_deprep_terminal();
1359*4882a593Smuzhiyun 
1360*4882a593Smuzhiyun 	try_close_pcap();
1361*4882a593Smuzhiyun 
1362*4882a593Smuzhiyun 	if (fin != stdin)
1363*4882a593Smuzhiyun 		fclose(fin);
1364*4882a593Smuzhiyun 	if (fout != stdout)
1365*4882a593Smuzhiyun 		fclose(fout);
1366*4882a593Smuzhiyun }
1367*4882a593Smuzhiyun 
run_shell_loop(FILE * fin,FILE * fout)1368*4882a593Smuzhiyun static int run_shell_loop(FILE *fin, FILE *fout)
1369*4882a593Smuzhiyun {
1370*4882a593Smuzhiyun 	char *buf;
1371*4882a593Smuzhiyun 
1372*4882a593Smuzhiyun 	init_shell(fin, fout);
1373*4882a593Smuzhiyun 
1374*4882a593Smuzhiyun 	while ((buf = readline("> ")) != NULL) {
1375*4882a593Smuzhiyun 		int ret = execf(buf);
1376*4882a593Smuzhiyun 		if (ret == CMD_EX)
1377*4882a593Smuzhiyun 			break;
1378*4882a593Smuzhiyun 		if (ret == CMD_OK && strlen(buf) > 0)
1379*4882a593Smuzhiyun 			add_history(buf);
1380*4882a593Smuzhiyun 
1381*4882a593Smuzhiyun 		free(buf);
1382*4882a593Smuzhiyun 	}
1383*4882a593Smuzhiyun 
1384*4882a593Smuzhiyun 	exit_shell(fin, fout);
1385*4882a593Smuzhiyun 	return 0;
1386*4882a593Smuzhiyun }
1387*4882a593Smuzhiyun 
main(int argc,char ** argv)1388*4882a593Smuzhiyun int main(int argc, char **argv)
1389*4882a593Smuzhiyun {
1390*4882a593Smuzhiyun 	FILE *fin = NULL, *fout = NULL;
1391*4882a593Smuzhiyun 
1392*4882a593Smuzhiyun 	if (argc >= 2)
1393*4882a593Smuzhiyun 		fin = fopen(argv[1], "r");
1394*4882a593Smuzhiyun 	if (argc >= 3)
1395*4882a593Smuzhiyun 		fout = fopen(argv[2], "w");
1396*4882a593Smuzhiyun 
1397*4882a593Smuzhiyun 	return run_shell_loop(fin ? : stdin, fout ? : stdout);
1398*4882a593Smuzhiyun }
1399