1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * Minimal BPF debugger
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Minimal BPF debugger that mimics the kernel's engine (w/o extensions)
6*4882a593Smuzhiyun * and allows for single stepping through selected packets from a pcap
7*4882a593Smuzhiyun * with a provided user filter in order to facilitate verification of a
8*4882a593Smuzhiyun * BPF program. Besides others, this is useful to verify BPF programs
9*4882a593Smuzhiyun * before attaching to a live system, and can be used in socket filters,
10*4882a593Smuzhiyun * cls_bpf, xt_bpf, team driver and e.g. PTP code; in particular when a
11*4882a593Smuzhiyun * single more complex BPF program is being used. Reasons for a more
12*4882a593Smuzhiyun * complex BPF program are likely primarily to optimize execution time
13*4882a593Smuzhiyun * for making a verdict when multiple simple BPF programs are combined
14*4882a593Smuzhiyun * into one in order to prevent parsing same headers multiple times.
15*4882a593Smuzhiyun *
16*4882a593Smuzhiyun * More on how to debug BPF opcodes see Documentation/networking/filter.rst
17*4882a593Smuzhiyun * which is the main document on BPF. Mini howto for getting started:
18*4882a593Smuzhiyun *
19*4882a593Smuzhiyun * 1) `./bpf_dbg` to enter the shell (shell cmds denoted with '>'):
20*4882a593Smuzhiyun * 2) > load bpf 6,40 0 0 12,21 0 3 20... (output from `bpf_asm` or
21*4882a593Smuzhiyun * `tcpdump -iem1 -ddd port 22 | tr '\n' ','` to load as filter)
22*4882a593Smuzhiyun * 3) > load pcap foo.pcap
23*4882a593Smuzhiyun * 4) > run <n>/disassemble/dump/quit (self-explanatory)
24*4882a593Smuzhiyun * 5) > breakpoint 2 (sets bp at loaded BPF insns 2, do `run` then;
25*4882a593Smuzhiyun * multiple bps can be set, of course, a call to `breakpoint`
26*4882a593Smuzhiyun * w/o args shows currently loaded bps, `breakpoint reset` for
27*4882a593Smuzhiyun * resetting all breakpoints)
28*4882a593Smuzhiyun * 6) > select 3 (`run` etc will start from the 3rd packet in the pcap)
29*4882a593Smuzhiyun * 7) > step [-<n>, +<n>] (performs single stepping through the BPF)
30*4882a593Smuzhiyun *
31*4882a593Smuzhiyun * Copyright 2013 Daniel Borkmann <borkmann@redhat.com>
32*4882a593Smuzhiyun */
33*4882a593Smuzhiyun
34*4882a593Smuzhiyun #include <stdio.h>
35*4882a593Smuzhiyun #include <unistd.h>
36*4882a593Smuzhiyun #include <stdlib.h>
37*4882a593Smuzhiyun #include <ctype.h>
38*4882a593Smuzhiyun #include <stdbool.h>
39*4882a593Smuzhiyun #include <stdarg.h>
40*4882a593Smuzhiyun #include <setjmp.h>
41*4882a593Smuzhiyun #include <linux/filter.h>
42*4882a593Smuzhiyun #include <linux/if_packet.h>
43*4882a593Smuzhiyun #include <readline/readline.h>
44*4882a593Smuzhiyun #include <readline/history.h>
45*4882a593Smuzhiyun #include <sys/types.h>
46*4882a593Smuzhiyun #include <sys/socket.h>
47*4882a593Smuzhiyun #include <sys/stat.h>
48*4882a593Smuzhiyun #include <sys/mman.h>
49*4882a593Smuzhiyun #include <fcntl.h>
50*4882a593Smuzhiyun #include <errno.h>
51*4882a593Smuzhiyun #include <signal.h>
52*4882a593Smuzhiyun #include <arpa/inet.h>
53*4882a593Smuzhiyun #include <net/ethernet.h>
54*4882a593Smuzhiyun
55*4882a593Smuzhiyun #define TCPDUMP_MAGIC 0xa1b2c3d4
56*4882a593Smuzhiyun
57*4882a593Smuzhiyun #define BPF_LDX_B (BPF_LDX | BPF_B)
58*4882a593Smuzhiyun #define BPF_LDX_W (BPF_LDX | BPF_W)
59*4882a593Smuzhiyun #define BPF_JMP_JA (BPF_JMP | BPF_JA)
60*4882a593Smuzhiyun #define BPF_JMP_JEQ (BPF_JMP | BPF_JEQ)
61*4882a593Smuzhiyun #define BPF_JMP_JGT (BPF_JMP | BPF_JGT)
62*4882a593Smuzhiyun #define BPF_JMP_JGE (BPF_JMP | BPF_JGE)
63*4882a593Smuzhiyun #define BPF_JMP_JSET (BPF_JMP | BPF_JSET)
64*4882a593Smuzhiyun #define BPF_ALU_ADD (BPF_ALU | BPF_ADD)
65*4882a593Smuzhiyun #define BPF_ALU_SUB (BPF_ALU | BPF_SUB)
66*4882a593Smuzhiyun #define BPF_ALU_MUL (BPF_ALU | BPF_MUL)
67*4882a593Smuzhiyun #define BPF_ALU_DIV (BPF_ALU | BPF_DIV)
68*4882a593Smuzhiyun #define BPF_ALU_MOD (BPF_ALU | BPF_MOD)
69*4882a593Smuzhiyun #define BPF_ALU_NEG (BPF_ALU | BPF_NEG)
70*4882a593Smuzhiyun #define BPF_ALU_AND (BPF_ALU | BPF_AND)
71*4882a593Smuzhiyun #define BPF_ALU_OR (BPF_ALU | BPF_OR)
72*4882a593Smuzhiyun #define BPF_ALU_XOR (BPF_ALU | BPF_XOR)
73*4882a593Smuzhiyun #define BPF_ALU_LSH (BPF_ALU | BPF_LSH)
74*4882a593Smuzhiyun #define BPF_ALU_RSH (BPF_ALU | BPF_RSH)
75*4882a593Smuzhiyun #define BPF_MISC_TAX (BPF_MISC | BPF_TAX)
76*4882a593Smuzhiyun #define BPF_MISC_TXA (BPF_MISC | BPF_TXA)
77*4882a593Smuzhiyun #define BPF_LD_B (BPF_LD | BPF_B)
78*4882a593Smuzhiyun #define BPF_LD_H (BPF_LD | BPF_H)
79*4882a593Smuzhiyun #define BPF_LD_W (BPF_LD | BPF_W)
80*4882a593Smuzhiyun
81*4882a593Smuzhiyun #ifndef array_size
82*4882a593Smuzhiyun # define array_size(x) (sizeof(x) / sizeof((x)[0]))
83*4882a593Smuzhiyun #endif
84*4882a593Smuzhiyun
85*4882a593Smuzhiyun #ifndef __check_format_printf
86*4882a593Smuzhiyun # define __check_format_printf(pos_fmtstr, pos_fmtargs) \
87*4882a593Smuzhiyun __attribute__ ((format (printf, (pos_fmtstr), (pos_fmtargs))))
88*4882a593Smuzhiyun #endif
89*4882a593Smuzhiyun
90*4882a593Smuzhiyun enum {
91*4882a593Smuzhiyun CMD_OK,
92*4882a593Smuzhiyun CMD_ERR,
93*4882a593Smuzhiyun CMD_EX,
94*4882a593Smuzhiyun };
95*4882a593Smuzhiyun
96*4882a593Smuzhiyun struct shell_cmd {
97*4882a593Smuzhiyun const char *name;
98*4882a593Smuzhiyun int (*func)(char *args);
99*4882a593Smuzhiyun };
100*4882a593Smuzhiyun
101*4882a593Smuzhiyun struct pcap_filehdr {
102*4882a593Smuzhiyun uint32_t magic;
103*4882a593Smuzhiyun uint16_t version_major;
104*4882a593Smuzhiyun uint16_t version_minor;
105*4882a593Smuzhiyun int32_t thiszone;
106*4882a593Smuzhiyun uint32_t sigfigs;
107*4882a593Smuzhiyun uint32_t snaplen;
108*4882a593Smuzhiyun uint32_t linktype;
109*4882a593Smuzhiyun };
110*4882a593Smuzhiyun
111*4882a593Smuzhiyun struct pcap_timeval {
112*4882a593Smuzhiyun int32_t tv_sec;
113*4882a593Smuzhiyun int32_t tv_usec;
114*4882a593Smuzhiyun };
115*4882a593Smuzhiyun
116*4882a593Smuzhiyun struct pcap_pkthdr {
117*4882a593Smuzhiyun struct pcap_timeval ts;
118*4882a593Smuzhiyun uint32_t caplen;
119*4882a593Smuzhiyun uint32_t len;
120*4882a593Smuzhiyun };
121*4882a593Smuzhiyun
122*4882a593Smuzhiyun struct bpf_regs {
123*4882a593Smuzhiyun uint32_t A;
124*4882a593Smuzhiyun uint32_t X;
125*4882a593Smuzhiyun uint32_t M[BPF_MEMWORDS];
126*4882a593Smuzhiyun uint32_t R;
127*4882a593Smuzhiyun bool Rs;
128*4882a593Smuzhiyun uint16_t Pc;
129*4882a593Smuzhiyun };
130*4882a593Smuzhiyun
131*4882a593Smuzhiyun static struct sock_filter bpf_image[BPF_MAXINSNS + 1];
132*4882a593Smuzhiyun static unsigned int bpf_prog_len;
133*4882a593Smuzhiyun
134*4882a593Smuzhiyun static int bpf_breakpoints[64];
135*4882a593Smuzhiyun static struct bpf_regs bpf_regs[BPF_MAXINSNS + 1];
136*4882a593Smuzhiyun static struct bpf_regs bpf_curr;
137*4882a593Smuzhiyun static unsigned int bpf_regs_len;
138*4882a593Smuzhiyun
139*4882a593Smuzhiyun static int pcap_fd = -1;
140*4882a593Smuzhiyun static unsigned int pcap_packet;
141*4882a593Smuzhiyun static size_t pcap_map_size;
142*4882a593Smuzhiyun static char *pcap_ptr_va_start, *pcap_ptr_va_curr;
143*4882a593Smuzhiyun
144*4882a593Smuzhiyun static const char * const op_table[] = {
145*4882a593Smuzhiyun [BPF_ST] = "st",
146*4882a593Smuzhiyun [BPF_STX] = "stx",
147*4882a593Smuzhiyun [BPF_LD_B] = "ldb",
148*4882a593Smuzhiyun [BPF_LD_H] = "ldh",
149*4882a593Smuzhiyun [BPF_LD_W] = "ld",
150*4882a593Smuzhiyun [BPF_LDX] = "ldx",
151*4882a593Smuzhiyun [BPF_LDX_B] = "ldxb",
152*4882a593Smuzhiyun [BPF_JMP_JA] = "ja",
153*4882a593Smuzhiyun [BPF_JMP_JEQ] = "jeq",
154*4882a593Smuzhiyun [BPF_JMP_JGT] = "jgt",
155*4882a593Smuzhiyun [BPF_JMP_JGE] = "jge",
156*4882a593Smuzhiyun [BPF_JMP_JSET] = "jset",
157*4882a593Smuzhiyun [BPF_ALU_ADD] = "add",
158*4882a593Smuzhiyun [BPF_ALU_SUB] = "sub",
159*4882a593Smuzhiyun [BPF_ALU_MUL] = "mul",
160*4882a593Smuzhiyun [BPF_ALU_DIV] = "div",
161*4882a593Smuzhiyun [BPF_ALU_MOD] = "mod",
162*4882a593Smuzhiyun [BPF_ALU_NEG] = "neg",
163*4882a593Smuzhiyun [BPF_ALU_AND] = "and",
164*4882a593Smuzhiyun [BPF_ALU_OR] = "or",
165*4882a593Smuzhiyun [BPF_ALU_XOR] = "xor",
166*4882a593Smuzhiyun [BPF_ALU_LSH] = "lsh",
167*4882a593Smuzhiyun [BPF_ALU_RSH] = "rsh",
168*4882a593Smuzhiyun [BPF_MISC_TAX] = "tax",
169*4882a593Smuzhiyun [BPF_MISC_TXA] = "txa",
170*4882a593Smuzhiyun [BPF_RET] = "ret",
171*4882a593Smuzhiyun };
172*4882a593Smuzhiyun
rl_printf(const char * fmt,...)173*4882a593Smuzhiyun static __check_format_printf(1, 2) int rl_printf(const char *fmt, ...)
174*4882a593Smuzhiyun {
175*4882a593Smuzhiyun int ret;
176*4882a593Smuzhiyun va_list vl;
177*4882a593Smuzhiyun
178*4882a593Smuzhiyun va_start(vl, fmt);
179*4882a593Smuzhiyun ret = vfprintf(rl_outstream, fmt, vl);
180*4882a593Smuzhiyun va_end(vl);
181*4882a593Smuzhiyun
182*4882a593Smuzhiyun return ret;
183*4882a593Smuzhiyun }
184*4882a593Smuzhiyun
matches(const char * cmd,const char * pattern)185*4882a593Smuzhiyun static int matches(const char *cmd, const char *pattern)
186*4882a593Smuzhiyun {
187*4882a593Smuzhiyun int len = strlen(cmd);
188*4882a593Smuzhiyun
189*4882a593Smuzhiyun if (len > strlen(pattern))
190*4882a593Smuzhiyun return -1;
191*4882a593Smuzhiyun
192*4882a593Smuzhiyun return memcmp(pattern, cmd, len);
193*4882a593Smuzhiyun }
194*4882a593Smuzhiyun
hex_dump(const uint8_t * buf,size_t len)195*4882a593Smuzhiyun static void hex_dump(const uint8_t *buf, size_t len)
196*4882a593Smuzhiyun {
197*4882a593Smuzhiyun int i;
198*4882a593Smuzhiyun
199*4882a593Smuzhiyun rl_printf("%3u: ", 0);
200*4882a593Smuzhiyun for (i = 0; i < len; i++) {
201*4882a593Smuzhiyun if (i && !(i % 16))
202*4882a593Smuzhiyun rl_printf("\n%3u: ", i);
203*4882a593Smuzhiyun rl_printf("%02x ", buf[i]);
204*4882a593Smuzhiyun }
205*4882a593Smuzhiyun rl_printf("\n");
206*4882a593Smuzhiyun }
207*4882a593Smuzhiyun
bpf_prog_loaded(void)208*4882a593Smuzhiyun static bool bpf_prog_loaded(void)
209*4882a593Smuzhiyun {
210*4882a593Smuzhiyun if (bpf_prog_len == 0)
211*4882a593Smuzhiyun rl_printf("no bpf program loaded!\n");
212*4882a593Smuzhiyun
213*4882a593Smuzhiyun return bpf_prog_len > 0;
214*4882a593Smuzhiyun }
215*4882a593Smuzhiyun
bpf_disasm(const struct sock_filter f,unsigned int i)216*4882a593Smuzhiyun static void bpf_disasm(const struct sock_filter f, unsigned int i)
217*4882a593Smuzhiyun {
218*4882a593Smuzhiyun const char *op, *fmt;
219*4882a593Smuzhiyun int val = f.k;
220*4882a593Smuzhiyun char buf[256];
221*4882a593Smuzhiyun
222*4882a593Smuzhiyun switch (f.code) {
223*4882a593Smuzhiyun case BPF_RET | BPF_K:
224*4882a593Smuzhiyun op = op_table[BPF_RET];
225*4882a593Smuzhiyun fmt = "#%#x";
226*4882a593Smuzhiyun break;
227*4882a593Smuzhiyun case BPF_RET | BPF_A:
228*4882a593Smuzhiyun op = op_table[BPF_RET];
229*4882a593Smuzhiyun fmt = "a";
230*4882a593Smuzhiyun break;
231*4882a593Smuzhiyun case BPF_RET | BPF_X:
232*4882a593Smuzhiyun op = op_table[BPF_RET];
233*4882a593Smuzhiyun fmt = "x";
234*4882a593Smuzhiyun break;
235*4882a593Smuzhiyun case BPF_MISC_TAX:
236*4882a593Smuzhiyun op = op_table[BPF_MISC_TAX];
237*4882a593Smuzhiyun fmt = "";
238*4882a593Smuzhiyun break;
239*4882a593Smuzhiyun case BPF_MISC_TXA:
240*4882a593Smuzhiyun op = op_table[BPF_MISC_TXA];
241*4882a593Smuzhiyun fmt = "";
242*4882a593Smuzhiyun break;
243*4882a593Smuzhiyun case BPF_ST:
244*4882a593Smuzhiyun op = op_table[BPF_ST];
245*4882a593Smuzhiyun fmt = "M[%d]";
246*4882a593Smuzhiyun break;
247*4882a593Smuzhiyun case BPF_STX:
248*4882a593Smuzhiyun op = op_table[BPF_STX];
249*4882a593Smuzhiyun fmt = "M[%d]";
250*4882a593Smuzhiyun break;
251*4882a593Smuzhiyun case BPF_LD_W | BPF_ABS:
252*4882a593Smuzhiyun op = op_table[BPF_LD_W];
253*4882a593Smuzhiyun fmt = "[%d]";
254*4882a593Smuzhiyun break;
255*4882a593Smuzhiyun case BPF_LD_H | BPF_ABS:
256*4882a593Smuzhiyun op = op_table[BPF_LD_H];
257*4882a593Smuzhiyun fmt = "[%d]";
258*4882a593Smuzhiyun break;
259*4882a593Smuzhiyun case BPF_LD_B | BPF_ABS:
260*4882a593Smuzhiyun op = op_table[BPF_LD_B];
261*4882a593Smuzhiyun fmt = "[%d]";
262*4882a593Smuzhiyun break;
263*4882a593Smuzhiyun case BPF_LD_W | BPF_LEN:
264*4882a593Smuzhiyun op = op_table[BPF_LD_W];
265*4882a593Smuzhiyun fmt = "#len";
266*4882a593Smuzhiyun break;
267*4882a593Smuzhiyun case BPF_LD_W | BPF_IND:
268*4882a593Smuzhiyun op = op_table[BPF_LD_W];
269*4882a593Smuzhiyun fmt = "[x+%d]";
270*4882a593Smuzhiyun break;
271*4882a593Smuzhiyun case BPF_LD_H | BPF_IND:
272*4882a593Smuzhiyun op = op_table[BPF_LD_H];
273*4882a593Smuzhiyun fmt = "[x+%d]";
274*4882a593Smuzhiyun break;
275*4882a593Smuzhiyun case BPF_LD_B | BPF_IND:
276*4882a593Smuzhiyun op = op_table[BPF_LD_B];
277*4882a593Smuzhiyun fmt = "[x+%d]";
278*4882a593Smuzhiyun break;
279*4882a593Smuzhiyun case BPF_LD | BPF_IMM:
280*4882a593Smuzhiyun op = op_table[BPF_LD_W];
281*4882a593Smuzhiyun fmt = "#%#x";
282*4882a593Smuzhiyun break;
283*4882a593Smuzhiyun case BPF_LDX | BPF_IMM:
284*4882a593Smuzhiyun op = op_table[BPF_LDX];
285*4882a593Smuzhiyun fmt = "#%#x";
286*4882a593Smuzhiyun break;
287*4882a593Smuzhiyun case BPF_LDX_B | BPF_MSH:
288*4882a593Smuzhiyun op = op_table[BPF_LDX_B];
289*4882a593Smuzhiyun fmt = "4*([%d]&0xf)";
290*4882a593Smuzhiyun break;
291*4882a593Smuzhiyun case BPF_LD | BPF_MEM:
292*4882a593Smuzhiyun op = op_table[BPF_LD_W];
293*4882a593Smuzhiyun fmt = "M[%d]";
294*4882a593Smuzhiyun break;
295*4882a593Smuzhiyun case BPF_LDX | BPF_MEM:
296*4882a593Smuzhiyun op = op_table[BPF_LDX];
297*4882a593Smuzhiyun fmt = "M[%d]";
298*4882a593Smuzhiyun break;
299*4882a593Smuzhiyun case BPF_JMP_JA:
300*4882a593Smuzhiyun op = op_table[BPF_JMP_JA];
301*4882a593Smuzhiyun fmt = "%d";
302*4882a593Smuzhiyun val = i + 1 + f.k;
303*4882a593Smuzhiyun break;
304*4882a593Smuzhiyun case BPF_JMP_JGT | BPF_X:
305*4882a593Smuzhiyun op = op_table[BPF_JMP_JGT];
306*4882a593Smuzhiyun fmt = "x";
307*4882a593Smuzhiyun break;
308*4882a593Smuzhiyun case BPF_JMP_JGT | BPF_K:
309*4882a593Smuzhiyun op = op_table[BPF_JMP_JGT];
310*4882a593Smuzhiyun fmt = "#%#x";
311*4882a593Smuzhiyun break;
312*4882a593Smuzhiyun case BPF_JMP_JGE | BPF_X:
313*4882a593Smuzhiyun op = op_table[BPF_JMP_JGE];
314*4882a593Smuzhiyun fmt = "x";
315*4882a593Smuzhiyun break;
316*4882a593Smuzhiyun case BPF_JMP_JGE | BPF_K:
317*4882a593Smuzhiyun op = op_table[BPF_JMP_JGE];
318*4882a593Smuzhiyun fmt = "#%#x";
319*4882a593Smuzhiyun break;
320*4882a593Smuzhiyun case BPF_JMP_JEQ | BPF_X:
321*4882a593Smuzhiyun op = op_table[BPF_JMP_JEQ];
322*4882a593Smuzhiyun fmt = "x";
323*4882a593Smuzhiyun break;
324*4882a593Smuzhiyun case BPF_JMP_JEQ | BPF_K:
325*4882a593Smuzhiyun op = op_table[BPF_JMP_JEQ];
326*4882a593Smuzhiyun fmt = "#%#x";
327*4882a593Smuzhiyun break;
328*4882a593Smuzhiyun case BPF_JMP_JSET | BPF_X:
329*4882a593Smuzhiyun op = op_table[BPF_JMP_JSET];
330*4882a593Smuzhiyun fmt = "x";
331*4882a593Smuzhiyun break;
332*4882a593Smuzhiyun case BPF_JMP_JSET | BPF_K:
333*4882a593Smuzhiyun op = op_table[BPF_JMP_JSET];
334*4882a593Smuzhiyun fmt = "#%#x";
335*4882a593Smuzhiyun break;
336*4882a593Smuzhiyun case BPF_ALU_NEG:
337*4882a593Smuzhiyun op = op_table[BPF_ALU_NEG];
338*4882a593Smuzhiyun fmt = "";
339*4882a593Smuzhiyun break;
340*4882a593Smuzhiyun case BPF_ALU_LSH | BPF_X:
341*4882a593Smuzhiyun op = op_table[BPF_ALU_LSH];
342*4882a593Smuzhiyun fmt = "x";
343*4882a593Smuzhiyun break;
344*4882a593Smuzhiyun case BPF_ALU_LSH | BPF_K:
345*4882a593Smuzhiyun op = op_table[BPF_ALU_LSH];
346*4882a593Smuzhiyun fmt = "#%d";
347*4882a593Smuzhiyun break;
348*4882a593Smuzhiyun case BPF_ALU_RSH | BPF_X:
349*4882a593Smuzhiyun op = op_table[BPF_ALU_RSH];
350*4882a593Smuzhiyun fmt = "x";
351*4882a593Smuzhiyun break;
352*4882a593Smuzhiyun case BPF_ALU_RSH | BPF_K:
353*4882a593Smuzhiyun op = op_table[BPF_ALU_RSH];
354*4882a593Smuzhiyun fmt = "#%d";
355*4882a593Smuzhiyun break;
356*4882a593Smuzhiyun case BPF_ALU_ADD | BPF_X:
357*4882a593Smuzhiyun op = op_table[BPF_ALU_ADD];
358*4882a593Smuzhiyun fmt = "x";
359*4882a593Smuzhiyun break;
360*4882a593Smuzhiyun case BPF_ALU_ADD | BPF_K:
361*4882a593Smuzhiyun op = op_table[BPF_ALU_ADD];
362*4882a593Smuzhiyun fmt = "#%d";
363*4882a593Smuzhiyun break;
364*4882a593Smuzhiyun case BPF_ALU_SUB | BPF_X:
365*4882a593Smuzhiyun op = op_table[BPF_ALU_SUB];
366*4882a593Smuzhiyun fmt = "x";
367*4882a593Smuzhiyun break;
368*4882a593Smuzhiyun case BPF_ALU_SUB | BPF_K:
369*4882a593Smuzhiyun op = op_table[BPF_ALU_SUB];
370*4882a593Smuzhiyun fmt = "#%d";
371*4882a593Smuzhiyun break;
372*4882a593Smuzhiyun case BPF_ALU_MUL | BPF_X:
373*4882a593Smuzhiyun op = op_table[BPF_ALU_MUL];
374*4882a593Smuzhiyun fmt = "x";
375*4882a593Smuzhiyun break;
376*4882a593Smuzhiyun case BPF_ALU_MUL | BPF_K:
377*4882a593Smuzhiyun op = op_table[BPF_ALU_MUL];
378*4882a593Smuzhiyun fmt = "#%d";
379*4882a593Smuzhiyun break;
380*4882a593Smuzhiyun case BPF_ALU_DIV | BPF_X:
381*4882a593Smuzhiyun op = op_table[BPF_ALU_DIV];
382*4882a593Smuzhiyun fmt = "x";
383*4882a593Smuzhiyun break;
384*4882a593Smuzhiyun case BPF_ALU_DIV | BPF_K:
385*4882a593Smuzhiyun op = op_table[BPF_ALU_DIV];
386*4882a593Smuzhiyun fmt = "#%d";
387*4882a593Smuzhiyun break;
388*4882a593Smuzhiyun case BPF_ALU_MOD | BPF_X:
389*4882a593Smuzhiyun op = op_table[BPF_ALU_MOD];
390*4882a593Smuzhiyun fmt = "x";
391*4882a593Smuzhiyun break;
392*4882a593Smuzhiyun case BPF_ALU_MOD | BPF_K:
393*4882a593Smuzhiyun op = op_table[BPF_ALU_MOD];
394*4882a593Smuzhiyun fmt = "#%d";
395*4882a593Smuzhiyun break;
396*4882a593Smuzhiyun case BPF_ALU_AND | BPF_X:
397*4882a593Smuzhiyun op = op_table[BPF_ALU_AND];
398*4882a593Smuzhiyun fmt = "x";
399*4882a593Smuzhiyun break;
400*4882a593Smuzhiyun case BPF_ALU_AND | BPF_K:
401*4882a593Smuzhiyun op = op_table[BPF_ALU_AND];
402*4882a593Smuzhiyun fmt = "#%#x";
403*4882a593Smuzhiyun break;
404*4882a593Smuzhiyun case BPF_ALU_OR | BPF_X:
405*4882a593Smuzhiyun op = op_table[BPF_ALU_OR];
406*4882a593Smuzhiyun fmt = "x";
407*4882a593Smuzhiyun break;
408*4882a593Smuzhiyun case BPF_ALU_OR | BPF_K:
409*4882a593Smuzhiyun op = op_table[BPF_ALU_OR];
410*4882a593Smuzhiyun fmt = "#%#x";
411*4882a593Smuzhiyun break;
412*4882a593Smuzhiyun case BPF_ALU_XOR | BPF_X:
413*4882a593Smuzhiyun op = op_table[BPF_ALU_XOR];
414*4882a593Smuzhiyun fmt = "x";
415*4882a593Smuzhiyun break;
416*4882a593Smuzhiyun case BPF_ALU_XOR | BPF_K:
417*4882a593Smuzhiyun op = op_table[BPF_ALU_XOR];
418*4882a593Smuzhiyun fmt = "#%#x";
419*4882a593Smuzhiyun break;
420*4882a593Smuzhiyun default:
421*4882a593Smuzhiyun op = "nosup";
422*4882a593Smuzhiyun fmt = "%#x";
423*4882a593Smuzhiyun val = f.code;
424*4882a593Smuzhiyun break;
425*4882a593Smuzhiyun }
426*4882a593Smuzhiyun
427*4882a593Smuzhiyun memset(buf, 0, sizeof(buf));
428*4882a593Smuzhiyun snprintf(buf, sizeof(buf), fmt, val);
429*4882a593Smuzhiyun buf[sizeof(buf) - 1] = 0;
430*4882a593Smuzhiyun
431*4882a593Smuzhiyun if ((BPF_CLASS(f.code) == BPF_JMP && BPF_OP(f.code) != BPF_JA))
432*4882a593Smuzhiyun rl_printf("l%d:\t%s %s, l%d, l%d\n", i, op, buf,
433*4882a593Smuzhiyun i + 1 + f.jt, i + 1 + f.jf);
434*4882a593Smuzhiyun else
435*4882a593Smuzhiyun rl_printf("l%d:\t%s %s\n", i, op, buf);
436*4882a593Smuzhiyun }
437*4882a593Smuzhiyun
bpf_dump_curr(struct bpf_regs * r,struct sock_filter * f)438*4882a593Smuzhiyun static void bpf_dump_curr(struct bpf_regs *r, struct sock_filter *f)
439*4882a593Smuzhiyun {
440*4882a593Smuzhiyun int i, m = 0;
441*4882a593Smuzhiyun
442*4882a593Smuzhiyun rl_printf("pc: [%u]\n", r->Pc);
443*4882a593Smuzhiyun rl_printf("code: [%u] jt[%u] jf[%u] k[%u]\n",
444*4882a593Smuzhiyun f->code, f->jt, f->jf, f->k);
445*4882a593Smuzhiyun rl_printf("curr: ");
446*4882a593Smuzhiyun bpf_disasm(*f, r->Pc);
447*4882a593Smuzhiyun
448*4882a593Smuzhiyun if (f->jt || f->jf) {
449*4882a593Smuzhiyun rl_printf("jt: ");
450*4882a593Smuzhiyun bpf_disasm(*(f + f->jt + 1), r->Pc + f->jt + 1);
451*4882a593Smuzhiyun rl_printf("jf: ");
452*4882a593Smuzhiyun bpf_disasm(*(f + f->jf + 1), r->Pc + f->jf + 1);
453*4882a593Smuzhiyun }
454*4882a593Smuzhiyun
455*4882a593Smuzhiyun rl_printf("A: [%#08x][%u]\n", r->A, r->A);
456*4882a593Smuzhiyun rl_printf("X: [%#08x][%u]\n", r->X, r->X);
457*4882a593Smuzhiyun if (r->Rs)
458*4882a593Smuzhiyun rl_printf("ret: [%#08x][%u]!\n", r->R, r->R);
459*4882a593Smuzhiyun
460*4882a593Smuzhiyun for (i = 0; i < BPF_MEMWORDS; i++) {
461*4882a593Smuzhiyun if (r->M[i]) {
462*4882a593Smuzhiyun m++;
463*4882a593Smuzhiyun rl_printf("M[%d]: [%#08x][%u]\n", i, r->M[i], r->M[i]);
464*4882a593Smuzhiyun }
465*4882a593Smuzhiyun }
466*4882a593Smuzhiyun if (m == 0)
467*4882a593Smuzhiyun rl_printf("M[0,%d]: [%#08x][%u]\n", BPF_MEMWORDS - 1, 0, 0);
468*4882a593Smuzhiyun }
469*4882a593Smuzhiyun
bpf_dump_pkt(uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)470*4882a593Smuzhiyun static void bpf_dump_pkt(uint8_t *pkt, uint32_t pkt_caplen, uint32_t pkt_len)
471*4882a593Smuzhiyun {
472*4882a593Smuzhiyun if (pkt_caplen != pkt_len)
473*4882a593Smuzhiyun rl_printf("cap: %u, len: %u\n", pkt_caplen, pkt_len);
474*4882a593Smuzhiyun else
475*4882a593Smuzhiyun rl_printf("len: %u\n", pkt_len);
476*4882a593Smuzhiyun
477*4882a593Smuzhiyun hex_dump(pkt, pkt_caplen);
478*4882a593Smuzhiyun }
479*4882a593Smuzhiyun
bpf_disasm_all(const struct sock_filter * f,unsigned int len)480*4882a593Smuzhiyun static void bpf_disasm_all(const struct sock_filter *f, unsigned int len)
481*4882a593Smuzhiyun {
482*4882a593Smuzhiyun unsigned int i;
483*4882a593Smuzhiyun
484*4882a593Smuzhiyun for (i = 0; i < len; i++)
485*4882a593Smuzhiyun bpf_disasm(f[i], i);
486*4882a593Smuzhiyun }
487*4882a593Smuzhiyun
bpf_dump_all(const struct sock_filter * f,unsigned int len)488*4882a593Smuzhiyun static void bpf_dump_all(const struct sock_filter *f, unsigned int len)
489*4882a593Smuzhiyun {
490*4882a593Smuzhiyun unsigned int i;
491*4882a593Smuzhiyun
492*4882a593Smuzhiyun rl_printf("/* { op, jt, jf, k }, */\n");
493*4882a593Smuzhiyun for (i = 0; i < len; i++)
494*4882a593Smuzhiyun rl_printf("{ %#04x, %2u, %2u, %#010x },\n",
495*4882a593Smuzhiyun f[i].code, f[i].jt, f[i].jf, f[i].k);
496*4882a593Smuzhiyun }
497*4882a593Smuzhiyun
bpf_runnable(struct sock_filter * f,unsigned int len)498*4882a593Smuzhiyun static bool bpf_runnable(struct sock_filter *f, unsigned int len)
499*4882a593Smuzhiyun {
500*4882a593Smuzhiyun int sock, ret, i;
501*4882a593Smuzhiyun struct sock_fprog bpf = {
502*4882a593Smuzhiyun .filter = f,
503*4882a593Smuzhiyun .len = len,
504*4882a593Smuzhiyun };
505*4882a593Smuzhiyun
506*4882a593Smuzhiyun sock = socket(AF_INET, SOCK_DGRAM, 0);
507*4882a593Smuzhiyun if (sock < 0) {
508*4882a593Smuzhiyun rl_printf("cannot open socket!\n");
509*4882a593Smuzhiyun return false;
510*4882a593Smuzhiyun }
511*4882a593Smuzhiyun ret = setsockopt(sock, SOL_SOCKET, SO_ATTACH_FILTER, &bpf, sizeof(bpf));
512*4882a593Smuzhiyun close(sock);
513*4882a593Smuzhiyun if (ret < 0) {
514*4882a593Smuzhiyun rl_printf("program not allowed to run by kernel!\n");
515*4882a593Smuzhiyun return false;
516*4882a593Smuzhiyun }
517*4882a593Smuzhiyun for (i = 0; i < len; i++) {
518*4882a593Smuzhiyun if (BPF_CLASS(f[i].code) == BPF_LD &&
519*4882a593Smuzhiyun f[i].k > SKF_AD_OFF) {
520*4882a593Smuzhiyun rl_printf("extensions currently not supported!\n");
521*4882a593Smuzhiyun return false;
522*4882a593Smuzhiyun }
523*4882a593Smuzhiyun }
524*4882a593Smuzhiyun
525*4882a593Smuzhiyun return true;
526*4882a593Smuzhiyun }
527*4882a593Smuzhiyun
bpf_reset_breakpoints(void)528*4882a593Smuzhiyun static void bpf_reset_breakpoints(void)
529*4882a593Smuzhiyun {
530*4882a593Smuzhiyun int i;
531*4882a593Smuzhiyun
532*4882a593Smuzhiyun for (i = 0; i < array_size(bpf_breakpoints); i++)
533*4882a593Smuzhiyun bpf_breakpoints[i] = -1;
534*4882a593Smuzhiyun }
535*4882a593Smuzhiyun
bpf_set_breakpoints(unsigned int where)536*4882a593Smuzhiyun static void bpf_set_breakpoints(unsigned int where)
537*4882a593Smuzhiyun {
538*4882a593Smuzhiyun int i;
539*4882a593Smuzhiyun bool set = false;
540*4882a593Smuzhiyun
541*4882a593Smuzhiyun for (i = 0; i < array_size(bpf_breakpoints); i++) {
542*4882a593Smuzhiyun if (bpf_breakpoints[i] == (int) where) {
543*4882a593Smuzhiyun rl_printf("breakpoint already set!\n");
544*4882a593Smuzhiyun set = true;
545*4882a593Smuzhiyun break;
546*4882a593Smuzhiyun }
547*4882a593Smuzhiyun
548*4882a593Smuzhiyun if (bpf_breakpoints[i] == -1 && set == false) {
549*4882a593Smuzhiyun bpf_breakpoints[i] = where;
550*4882a593Smuzhiyun set = true;
551*4882a593Smuzhiyun }
552*4882a593Smuzhiyun }
553*4882a593Smuzhiyun
554*4882a593Smuzhiyun if (!set)
555*4882a593Smuzhiyun rl_printf("too many breakpoints set, reset first!\n");
556*4882a593Smuzhiyun }
557*4882a593Smuzhiyun
bpf_dump_breakpoints(void)558*4882a593Smuzhiyun static void bpf_dump_breakpoints(void)
559*4882a593Smuzhiyun {
560*4882a593Smuzhiyun int i;
561*4882a593Smuzhiyun
562*4882a593Smuzhiyun rl_printf("breakpoints: ");
563*4882a593Smuzhiyun
564*4882a593Smuzhiyun for (i = 0; i < array_size(bpf_breakpoints); i++) {
565*4882a593Smuzhiyun if (bpf_breakpoints[i] < 0)
566*4882a593Smuzhiyun continue;
567*4882a593Smuzhiyun rl_printf("%d ", bpf_breakpoints[i]);
568*4882a593Smuzhiyun }
569*4882a593Smuzhiyun
570*4882a593Smuzhiyun rl_printf("\n");
571*4882a593Smuzhiyun }
572*4882a593Smuzhiyun
bpf_reset(void)573*4882a593Smuzhiyun static void bpf_reset(void)
574*4882a593Smuzhiyun {
575*4882a593Smuzhiyun bpf_regs_len = 0;
576*4882a593Smuzhiyun
577*4882a593Smuzhiyun memset(bpf_regs, 0, sizeof(bpf_regs));
578*4882a593Smuzhiyun memset(&bpf_curr, 0, sizeof(bpf_curr));
579*4882a593Smuzhiyun }
580*4882a593Smuzhiyun
bpf_safe_regs(void)581*4882a593Smuzhiyun static void bpf_safe_regs(void)
582*4882a593Smuzhiyun {
583*4882a593Smuzhiyun memcpy(&bpf_regs[bpf_regs_len++], &bpf_curr, sizeof(bpf_curr));
584*4882a593Smuzhiyun }
585*4882a593Smuzhiyun
bpf_restore_regs(int off)586*4882a593Smuzhiyun static bool bpf_restore_regs(int off)
587*4882a593Smuzhiyun {
588*4882a593Smuzhiyun unsigned int index = bpf_regs_len - 1 + off;
589*4882a593Smuzhiyun
590*4882a593Smuzhiyun if (index == 0) {
591*4882a593Smuzhiyun bpf_reset();
592*4882a593Smuzhiyun return true;
593*4882a593Smuzhiyun } else if (index < bpf_regs_len) {
594*4882a593Smuzhiyun memcpy(&bpf_curr, &bpf_regs[index], sizeof(bpf_curr));
595*4882a593Smuzhiyun bpf_regs_len = index;
596*4882a593Smuzhiyun return true;
597*4882a593Smuzhiyun } else {
598*4882a593Smuzhiyun rl_printf("reached bottom of register history stack!\n");
599*4882a593Smuzhiyun return false;
600*4882a593Smuzhiyun }
601*4882a593Smuzhiyun }
602*4882a593Smuzhiyun
extract_u32(uint8_t * pkt,uint32_t off)603*4882a593Smuzhiyun static uint32_t extract_u32(uint8_t *pkt, uint32_t off)
604*4882a593Smuzhiyun {
605*4882a593Smuzhiyun uint32_t r;
606*4882a593Smuzhiyun
607*4882a593Smuzhiyun memcpy(&r, &pkt[off], sizeof(r));
608*4882a593Smuzhiyun
609*4882a593Smuzhiyun return ntohl(r);
610*4882a593Smuzhiyun }
611*4882a593Smuzhiyun
extract_u16(uint8_t * pkt,uint32_t off)612*4882a593Smuzhiyun static uint16_t extract_u16(uint8_t *pkt, uint32_t off)
613*4882a593Smuzhiyun {
614*4882a593Smuzhiyun uint16_t r;
615*4882a593Smuzhiyun
616*4882a593Smuzhiyun memcpy(&r, &pkt[off], sizeof(r));
617*4882a593Smuzhiyun
618*4882a593Smuzhiyun return ntohs(r);
619*4882a593Smuzhiyun }
620*4882a593Smuzhiyun
extract_u8(uint8_t * pkt,uint32_t off)621*4882a593Smuzhiyun static uint8_t extract_u8(uint8_t *pkt, uint32_t off)
622*4882a593Smuzhiyun {
623*4882a593Smuzhiyun return pkt[off];
624*4882a593Smuzhiyun }
625*4882a593Smuzhiyun
set_return(struct bpf_regs * r)626*4882a593Smuzhiyun static void set_return(struct bpf_regs *r)
627*4882a593Smuzhiyun {
628*4882a593Smuzhiyun r->R = 0;
629*4882a593Smuzhiyun r->Rs = true;
630*4882a593Smuzhiyun }
631*4882a593Smuzhiyun
bpf_single_step(struct bpf_regs * r,struct sock_filter * f,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)632*4882a593Smuzhiyun static void bpf_single_step(struct bpf_regs *r, struct sock_filter *f,
633*4882a593Smuzhiyun uint8_t *pkt, uint32_t pkt_caplen,
634*4882a593Smuzhiyun uint32_t pkt_len)
635*4882a593Smuzhiyun {
636*4882a593Smuzhiyun uint32_t K = f->k;
637*4882a593Smuzhiyun int d;
638*4882a593Smuzhiyun
639*4882a593Smuzhiyun switch (f->code) {
640*4882a593Smuzhiyun case BPF_RET | BPF_K:
641*4882a593Smuzhiyun r->R = K;
642*4882a593Smuzhiyun r->Rs = true;
643*4882a593Smuzhiyun break;
644*4882a593Smuzhiyun case BPF_RET | BPF_A:
645*4882a593Smuzhiyun r->R = r->A;
646*4882a593Smuzhiyun r->Rs = true;
647*4882a593Smuzhiyun break;
648*4882a593Smuzhiyun case BPF_RET | BPF_X:
649*4882a593Smuzhiyun r->R = r->X;
650*4882a593Smuzhiyun r->Rs = true;
651*4882a593Smuzhiyun break;
652*4882a593Smuzhiyun case BPF_MISC_TAX:
653*4882a593Smuzhiyun r->X = r->A;
654*4882a593Smuzhiyun break;
655*4882a593Smuzhiyun case BPF_MISC_TXA:
656*4882a593Smuzhiyun r->A = r->X;
657*4882a593Smuzhiyun break;
658*4882a593Smuzhiyun case BPF_ST:
659*4882a593Smuzhiyun r->M[K] = r->A;
660*4882a593Smuzhiyun break;
661*4882a593Smuzhiyun case BPF_STX:
662*4882a593Smuzhiyun r->M[K] = r->X;
663*4882a593Smuzhiyun break;
664*4882a593Smuzhiyun case BPF_LD_W | BPF_ABS:
665*4882a593Smuzhiyun d = pkt_caplen - K;
666*4882a593Smuzhiyun if (d >= sizeof(uint32_t))
667*4882a593Smuzhiyun r->A = extract_u32(pkt, K);
668*4882a593Smuzhiyun else
669*4882a593Smuzhiyun set_return(r);
670*4882a593Smuzhiyun break;
671*4882a593Smuzhiyun case BPF_LD_H | BPF_ABS:
672*4882a593Smuzhiyun d = pkt_caplen - K;
673*4882a593Smuzhiyun if (d >= sizeof(uint16_t))
674*4882a593Smuzhiyun r->A = extract_u16(pkt, K);
675*4882a593Smuzhiyun else
676*4882a593Smuzhiyun set_return(r);
677*4882a593Smuzhiyun break;
678*4882a593Smuzhiyun case BPF_LD_B | BPF_ABS:
679*4882a593Smuzhiyun d = pkt_caplen - K;
680*4882a593Smuzhiyun if (d >= sizeof(uint8_t))
681*4882a593Smuzhiyun r->A = extract_u8(pkt, K);
682*4882a593Smuzhiyun else
683*4882a593Smuzhiyun set_return(r);
684*4882a593Smuzhiyun break;
685*4882a593Smuzhiyun case BPF_LD_W | BPF_IND:
686*4882a593Smuzhiyun d = pkt_caplen - (r->X + K);
687*4882a593Smuzhiyun if (d >= sizeof(uint32_t))
688*4882a593Smuzhiyun r->A = extract_u32(pkt, r->X + K);
689*4882a593Smuzhiyun break;
690*4882a593Smuzhiyun case BPF_LD_H | BPF_IND:
691*4882a593Smuzhiyun d = pkt_caplen - (r->X + K);
692*4882a593Smuzhiyun if (d >= sizeof(uint16_t))
693*4882a593Smuzhiyun r->A = extract_u16(pkt, r->X + K);
694*4882a593Smuzhiyun else
695*4882a593Smuzhiyun set_return(r);
696*4882a593Smuzhiyun break;
697*4882a593Smuzhiyun case BPF_LD_B | BPF_IND:
698*4882a593Smuzhiyun d = pkt_caplen - (r->X + K);
699*4882a593Smuzhiyun if (d >= sizeof(uint8_t))
700*4882a593Smuzhiyun r->A = extract_u8(pkt, r->X + K);
701*4882a593Smuzhiyun else
702*4882a593Smuzhiyun set_return(r);
703*4882a593Smuzhiyun break;
704*4882a593Smuzhiyun case BPF_LDX_B | BPF_MSH:
705*4882a593Smuzhiyun d = pkt_caplen - K;
706*4882a593Smuzhiyun if (d >= sizeof(uint8_t)) {
707*4882a593Smuzhiyun r->X = extract_u8(pkt, K);
708*4882a593Smuzhiyun r->X = (r->X & 0xf) << 2;
709*4882a593Smuzhiyun } else
710*4882a593Smuzhiyun set_return(r);
711*4882a593Smuzhiyun break;
712*4882a593Smuzhiyun case BPF_LD_W | BPF_LEN:
713*4882a593Smuzhiyun r->A = pkt_len;
714*4882a593Smuzhiyun break;
715*4882a593Smuzhiyun case BPF_LDX_W | BPF_LEN:
716*4882a593Smuzhiyun r->A = pkt_len;
717*4882a593Smuzhiyun break;
718*4882a593Smuzhiyun case BPF_LD | BPF_IMM:
719*4882a593Smuzhiyun r->A = K;
720*4882a593Smuzhiyun break;
721*4882a593Smuzhiyun case BPF_LDX | BPF_IMM:
722*4882a593Smuzhiyun r->X = K;
723*4882a593Smuzhiyun break;
724*4882a593Smuzhiyun case BPF_LD | BPF_MEM:
725*4882a593Smuzhiyun r->A = r->M[K];
726*4882a593Smuzhiyun break;
727*4882a593Smuzhiyun case BPF_LDX | BPF_MEM:
728*4882a593Smuzhiyun r->X = r->M[K];
729*4882a593Smuzhiyun break;
730*4882a593Smuzhiyun case BPF_JMP_JA:
731*4882a593Smuzhiyun r->Pc += K;
732*4882a593Smuzhiyun break;
733*4882a593Smuzhiyun case BPF_JMP_JGT | BPF_X:
734*4882a593Smuzhiyun r->Pc += r->A > r->X ? f->jt : f->jf;
735*4882a593Smuzhiyun break;
736*4882a593Smuzhiyun case BPF_JMP_JGT | BPF_K:
737*4882a593Smuzhiyun r->Pc += r->A > K ? f->jt : f->jf;
738*4882a593Smuzhiyun break;
739*4882a593Smuzhiyun case BPF_JMP_JGE | BPF_X:
740*4882a593Smuzhiyun r->Pc += r->A >= r->X ? f->jt : f->jf;
741*4882a593Smuzhiyun break;
742*4882a593Smuzhiyun case BPF_JMP_JGE | BPF_K:
743*4882a593Smuzhiyun r->Pc += r->A >= K ? f->jt : f->jf;
744*4882a593Smuzhiyun break;
745*4882a593Smuzhiyun case BPF_JMP_JEQ | BPF_X:
746*4882a593Smuzhiyun r->Pc += r->A == r->X ? f->jt : f->jf;
747*4882a593Smuzhiyun break;
748*4882a593Smuzhiyun case BPF_JMP_JEQ | BPF_K:
749*4882a593Smuzhiyun r->Pc += r->A == K ? f->jt : f->jf;
750*4882a593Smuzhiyun break;
751*4882a593Smuzhiyun case BPF_JMP_JSET | BPF_X:
752*4882a593Smuzhiyun r->Pc += r->A & r->X ? f->jt : f->jf;
753*4882a593Smuzhiyun break;
754*4882a593Smuzhiyun case BPF_JMP_JSET | BPF_K:
755*4882a593Smuzhiyun r->Pc += r->A & K ? f->jt : f->jf;
756*4882a593Smuzhiyun break;
757*4882a593Smuzhiyun case BPF_ALU_NEG:
758*4882a593Smuzhiyun r->A = -r->A;
759*4882a593Smuzhiyun break;
760*4882a593Smuzhiyun case BPF_ALU_LSH | BPF_X:
761*4882a593Smuzhiyun r->A <<= r->X;
762*4882a593Smuzhiyun break;
763*4882a593Smuzhiyun case BPF_ALU_LSH | BPF_K:
764*4882a593Smuzhiyun r->A <<= K;
765*4882a593Smuzhiyun break;
766*4882a593Smuzhiyun case BPF_ALU_RSH | BPF_X:
767*4882a593Smuzhiyun r->A >>= r->X;
768*4882a593Smuzhiyun break;
769*4882a593Smuzhiyun case BPF_ALU_RSH | BPF_K:
770*4882a593Smuzhiyun r->A >>= K;
771*4882a593Smuzhiyun break;
772*4882a593Smuzhiyun case BPF_ALU_ADD | BPF_X:
773*4882a593Smuzhiyun r->A += r->X;
774*4882a593Smuzhiyun break;
775*4882a593Smuzhiyun case BPF_ALU_ADD | BPF_K:
776*4882a593Smuzhiyun r->A += K;
777*4882a593Smuzhiyun break;
778*4882a593Smuzhiyun case BPF_ALU_SUB | BPF_X:
779*4882a593Smuzhiyun r->A -= r->X;
780*4882a593Smuzhiyun break;
781*4882a593Smuzhiyun case BPF_ALU_SUB | BPF_K:
782*4882a593Smuzhiyun r->A -= K;
783*4882a593Smuzhiyun break;
784*4882a593Smuzhiyun case BPF_ALU_MUL | BPF_X:
785*4882a593Smuzhiyun r->A *= r->X;
786*4882a593Smuzhiyun break;
787*4882a593Smuzhiyun case BPF_ALU_MUL | BPF_K:
788*4882a593Smuzhiyun r->A *= K;
789*4882a593Smuzhiyun break;
790*4882a593Smuzhiyun case BPF_ALU_DIV | BPF_X:
791*4882a593Smuzhiyun case BPF_ALU_MOD | BPF_X:
792*4882a593Smuzhiyun if (r->X == 0) {
793*4882a593Smuzhiyun set_return(r);
794*4882a593Smuzhiyun break;
795*4882a593Smuzhiyun }
796*4882a593Smuzhiyun goto do_div;
797*4882a593Smuzhiyun case BPF_ALU_DIV | BPF_K:
798*4882a593Smuzhiyun case BPF_ALU_MOD | BPF_K:
799*4882a593Smuzhiyun if (K == 0) {
800*4882a593Smuzhiyun set_return(r);
801*4882a593Smuzhiyun break;
802*4882a593Smuzhiyun }
803*4882a593Smuzhiyun do_div:
804*4882a593Smuzhiyun switch (f->code) {
805*4882a593Smuzhiyun case BPF_ALU_DIV | BPF_X:
806*4882a593Smuzhiyun r->A /= r->X;
807*4882a593Smuzhiyun break;
808*4882a593Smuzhiyun case BPF_ALU_DIV | BPF_K:
809*4882a593Smuzhiyun r->A /= K;
810*4882a593Smuzhiyun break;
811*4882a593Smuzhiyun case BPF_ALU_MOD | BPF_X:
812*4882a593Smuzhiyun r->A %= r->X;
813*4882a593Smuzhiyun break;
814*4882a593Smuzhiyun case BPF_ALU_MOD | BPF_K:
815*4882a593Smuzhiyun r->A %= K;
816*4882a593Smuzhiyun break;
817*4882a593Smuzhiyun }
818*4882a593Smuzhiyun break;
819*4882a593Smuzhiyun case BPF_ALU_AND | BPF_X:
820*4882a593Smuzhiyun r->A &= r->X;
821*4882a593Smuzhiyun break;
822*4882a593Smuzhiyun case BPF_ALU_AND | BPF_K:
823*4882a593Smuzhiyun r->A &= K;
824*4882a593Smuzhiyun break;
825*4882a593Smuzhiyun case BPF_ALU_OR | BPF_X:
826*4882a593Smuzhiyun r->A |= r->X;
827*4882a593Smuzhiyun break;
828*4882a593Smuzhiyun case BPF_ALU_OR | BPF_K:
829*4882a593Smuzhiyun r->A |= K;
830*4882a593Smuzhiyun break;
831*4882a593Smuzhiyun case BPF_ALU_XOR | BPF_X:
832*4882a593Smuzhiyun r->A ^= r->X;
833*4882a593Smuzhiyun break;
834*4882a593Smuzhiyun case BPF_ALU_XOR | BPF_K:
835*4882a593Smuzhiyun r->A ^= K;
836*4882a593Smuzhiyun break;
837*4882a593Smuzhiyun }
838*4882a593Smuzhiyun }
839*4882a593Smuzhiyun
bpf_pc_has_breakpoint(uint16_t pc)840*4882a593Smuzhiyun static bool bpf_pc_has_breakpoint(uint16_t pc)
841*4882a593Smuzhiyun {
842*4882a593Smuzhiyun int i;
843*4882a593Smuzhiyun
844*4882a593Smuzhiyun for (i = 0; i < array_size(bpf_breakpoints); i++) {
845*4882a593Smuzhiyun if (bpf_breakpoints[i] < 0)
846*4882a593Smuzhiyun continue;
847*4882a593Smuzhiyun if (bpf_breakpoints[i] == pc)
848*4882a593Smuzhiyun return true;
849*4882a593Smuzhiyun }
850*4882a593Smuzhiyun
851*4882a593Smuzhiyun return false;
852*4882a593Smuzhiyun }
853*4882a593Smuzhiyun
bpf_handle_breakpoint(struct bpf_regs * r,struct sock_filter * f,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)854*4882a593Smuzhiyun static bool bpf_handle_breakpoint(struct bpf_regs *r, struct sock_filter *f,
855*4882a593Smuzhiyun uint8_t *pkt, uint32_t pkt_caplen,
856*4882a593Smuzhiyun uint32_t pkt_len)
857*4882a593Smuzhiyun {
858*4882a593Smuzhiyun rl_printf("-- register dump --\n");
859*4882a593Smuzhiyun bpf_dump_curr(r, &f[r->Pc]);
860*4882a593Smuzhiyun rl_printf("-- packet dump --\n");
861*4882a593Smuzhiyun bpf_dump_pkt(pkt, pkt_caplen, pkt_len);
862*4882a593Smuzhiyun rl_printf("(breakpoint)\n");
863*4882a593Smuzhiyun return true;
864*4882a593Smuzhiyun }
865*4882a593Smuzhiyun
bpf_run_all(struct sock_filter * f,uint16_t bpf_len,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len)866*4882a593Smuzhiyun static int bpf_run_all(struct sock_filter *f, uint16_t bpf_len, uint8_t *pkt,
867*4882a593Smuzhiyun uint32_t pkt_caplen, uint32_t pkt_len)
868*4882a593Smuzhiyun {
869*4882a593Smuzhiyun bool stop = false;
870*4882a593Smuzhiyun
871*4882a593Smuzhiyun while (bpf_curr.Rs == false && stop == false) {
872*4882a593Smuzhiyun bpf_safe_regs();
873*4882a593Smuzhiyun
874*4882a593Smuzhiyun if (bpf_pc_has_breakpoint(bpf_curr.Pc))
875*4882a593Smuzhiyun stop = bpf_handle_breakpoint(&bpf_curr, f, pkt,
876*4882a593Smuzhiyun pkt_caplen, pkt_len);
877*4882a593Smuzhiyun
878*4882a593Smuzhiyun bpf_single_step(&bpf_curr, &f[bpf_curr.Pc], pkt, pkt_caplen,
879*4882a593Smuzhiyun pkt_len);
880*4882a593Smuzhiyun bpf_curr.Pc++;
881*4882a593Smuzhiyun }
882*4882a593Smuzhiyun
883*4882a593Smuzhiyun return stop ? -1 : bpf_curr.R;
884*4882a593Smuzhiyun }
885*4882a593Smuzhiyun
bpf_run_stepping(struct sock_filter * f,uint16_t bpf_len,uint8_t * pkt,uint32_t pkt_caplen,uint32_t pkt_len,int next)886*4882a593Smuzhiyun static int bpf_run_stepping(struct sock_filter *f, uint16_t bpf_len,
887*4882a593Smuzhiyun uint8_t *pkt, uint32_t pkt_caplen,
888*4882a593Smuzhiyun uint32_t pkt_len, int next)
889*4882a593Smuzhiyun {
890*4882a593Smuzhiyun bool stop = false;
891*4882a593Smuzhiyun int i = 1;
892*4882a593Smuzhiyun
893*4882a593Smuzhiyun while (bpf_curr.Rs == false && stop == false) {
894*4882a593Smuzhiyun bpf_safe_regs();
895*4882a593Smuzhiyun
896*4882a593Smuzhiyun if (i++ == next)
897*4882a593Smuzhiyun stop = bpf_handle_breakpoint(&bpf_curr, f, pkt,
898*4882a593Smuzhiyun pkt_caplen, pkt_len);
899*4882a593Smuzhiyun
900*4882a593Smuzhiyun bpf_single_step(&bpf_curr, &f[bpf_curr.Pc], pkt, pkt_caplen,
901*4882a593Smuzhiyun pkt_len);
902*4882a593Smuzhiyun bpf_curr.Pc++;
903*4882a593Smuzhiyun }
904*4882a593Smuzhiyun
905*4882a593Smuzhiyun return stop ? -1 : bpf_curr.R;
906*4882a593Smuzhiyun }
907*4882a593Smuzhiyun
pcap_loaded(void)908*4882a593Smuzhiyun static bool pcap_loaded(void)
909*4882a593Smuzhiyun {
910*4882a593Smuzhiyun if (pcap_fd < 0)
911*4882a593Smuzhiyun rl_printf("no pcap file loaded!\n");
912*4882a593Smuzhiyun
913*4882a593Smuzhiyun return pcap_fd >= 0;
914*4882a593Smuzhiyun }
915*4882a593Smuzhiyun
pcap_curr_pkt(void)916*4882a593Smuzhiyun static struct pcap_pkthdr *pcap_curr_pkt(void)
917*4882a593Smuzhiyun {
918*4882a593Smuzhiyun return (void *) pcap_ptr_va_curr;
919*4882a593Smuzhiyun }
920*4882a593Smuzhiyun
pcap_next_pkt(void)921*4882a593Smuzhiyun static bool pcap_next_pkt(void)
922*4882a593Smuzhiyun {
923*4882a593Smuzhiyun struct pcap_pkthdr *hdr = pcap_curr_pkt();
924*4882a593Smuzhiyun
925*4882a593Smuzhiyun if (pcap_ptr_va_curr + sizeof(*hdr) -
926*4882a593Smuzhiyun pcap_ptr_va_start >= pcap_map_size)
927*4882a593Smuzhiyun return false;
928*4882a593Smuzhiyun if (hdr->caplen == 0 || hdr->len == 0 || hdr->caplen > hdr->len)
929*4882a593Smuzhiyun return false;
930*4882a593Smuzhiyun if (pcap_ptr_va_curr + sizeof(*hdr) + hdr->caplen -
931*4882a593Smuzhiyun pcap_ptr_va_start >= pcap_map_size)
932*4882a593Smuzhiyun return false;
933*4882a593Smuzhiyun
934*4882a593Smuzhiyun pcap_ptr_va_curr += (sizeof(*hdr) + hdr->caplen);
935*4882a593Smuzhiyun return true;
936*4882a593Smuzhiyun }
937*4882a593Smuzhiyun
pcap_reset_pkt(void)938*4882a593Smuzhiyun static void pcap_reset_pkt(void)
939*4882a593Smuzhiyun {
940*4882a593Smuzhiyun pcap_ptr_va_curr = pcap_ptr_va_start + sizeof(struct pcap_filehdr);
941*4882a593Smuzhiyun }
942*4882a593Smuzhiyun
try_load_pcap(const char * file)943*4882a593Smuzhiyun static int try_load_pcap(const char *file)
944*4882a593Smuzhiyun {
945*4882a593Smuzhiyun struct pcap_filehdr *hdr;
946*4882a593Smuzhiyun struct stat sb;
947*4882a593Smuzhiyun int ret;
948*4882a593Smuzhiyun
949*4882a593Smuzhiyun pcap_fd = open(file, O_RDONLY);
950*4882a593Smuzhiyun if (pcap_fd < 0) {
951*4882a593Smuzhiyun rl_printf("cannot open pcap [%s]!\n", strerror(errno));
952*4882a593Smuzhiyun return CMD_ERR;
953*4882a593Smuzhiyun }
954*4882a593Smuzhiyun
955*4882a593Smuzhiyun ret = fstat(pcap_fd, &sb);
956*4882a593Smuzhiyun if (ret < 0) {
957*4882a593Smuzhiyun rl_printf("cannot fstat pcap file!\n");
958*4882a593Smuzhiyun return CMD_ERR;
959*4882a593Smuzhiyun }
960*4882a593Smuzhiyun
961*4882a593Smuzhiyun if (!S_ISREG(sb.st_mode)) {
962*4882a593Smuzhiyun rl_printf("not a regular pcap file, duh!\n");
963*4882a593Smuzhiyun return CMD_ERR;
964*4882a593Smuzhiyun }
965*4882a593Smuzhiyun
966*4882a593Smuzhiyun pcap_map_size = sb.st_size;
967*4882a593Smuzhiyun if (pcap_map_size <= sizeof(struct pcap_filehdr)) {
968*4882a593Smuzhiyun rl_printf("pcap file too small!\n");
969*4882a593Smuzhiyun return CMD_ERR;
970*4882a593Smuzhiyun }
971*4882a593Smuzhiyun
972*4882a593Smuzhiyun pcap_ptr_va_start = mmap(NULL, pcap_map_size, PROT_READ,
973*4882a593Smuzhiyun MAP_SHARED | MAP_LOCKED, pcap_fd, 0);
974*4882a593Smuzhiyun if (pcap_ptr_va_start == MAP_FAILED) {
975*4882a593Smuzhiyun rl_printf("mmap of file failed!");
976*4882a593Smuzhiyun return CMD_ERR;
977*4882a593Smuzhiyun }
978*4882a593Smuzhiyun
979*4882a593Smuzhiyun hdr = (void *) pcap_ptr_va_start;
980*4882a593Smuzhiyun if (hdr->magic != TCPDUMP_MAGIC) {
981*4882a593Smuzhiyun rl_printf("wrong pcap magic!\n");
982*4882a593Smuzhiyun return CMD_ERR;
983*4882a593Smuzhiyun }
984*4882a593Smuzhiyun
985*4882a593Smuzhiyun pcap_reset_pkt();
986*4882a593Smuzhiyun
987*4882a593Smuzhiyun return CMD_OK;
988*4882a593Smuzhiyun
989*4882a593Smuzhiyun }
990*4882a593Smuzhiyun
try_close_pcap(void)991*4882a593Smuzhiyun static void try_close_pcap(void)
992*4882a593Smuzhiyun {
993*4882a593Smuzhiyun if (pcap_fd >= 0) {
994*4882a593Smuzhiyun munmap(pcap_ptr_va_start, pcap_map_size);
995*4882a593Smuzhiyun close(pcap_fd);
996*4882a593Smuzhiyun
997*4882a593Smuzhiyun pcap_ptr_va_start = pcap_ptr_va_curr = NULL;
998*4882a593Smuzhiyun pcap_map_size = 0;
999*4882a593Smuzhiyun pcap_packet = 0;
1000*4882a593Smuzhiyun pcap_fd = -1;
1001*4882a593Smuzhiyun }
1002*4882a593Smuzhiyun }
1003*4882a593Smuzhiyun
cmd_load_bpf(char * bpf_string)1004*4882a593Smuzhiyun static int cmd_load_bpf(char *bpf_string)
1005*4882a593Smuzhiyun {
1006*4882a593Smuzhiyun char sp, *token, separator = ',';
1007*4882a593Smuzhiyun unsigned short bpf_len, i = 0;
1008*4882a593Smuzhiyun struct sock_filter tmp;
1009*4882a593Smuzhiyun
1010*4882a593Smuzhiyun bpf_prog_len = 0;
1011*4882a593Smuzhiyun memset(bpf_image, 0, sizeof(bpf_image));
1012*4882a593Smuzhiyun
1013*4882a593Smuzhiyun if (sscanf(bpf_string, "%hu%c", &bpf_len, &sp) != 2 ||
1014*4882a593Smuzhiyun sp != separator || bpf_len > BPF_MAXINSNS || bpf_len == 0) {
1015*4882a593Smuzhiyun rl_printf("syntax error in head length encoding!\n");
1016*4882a593Smuzhiyun return CMD_ERR;
1017*4882a593Smuzhiyun }
1018*4882a593Smuzhiyun
1019*4882a593Smuzhiyun token = bpf_string;
1020*4882a593Smuzhiyun while ((token = strchr(token, separator)) && (++token)[0]) {
1021*4882a593Smuzhiyun if (i >= bpf_len) {
1022*4882a593Smuzhiyun rl_printf("program exceeds encoded length!\n");
1023*4882a593Smuzhiyun return CMD_ERR;
1024*4882a593Smuzhiyun }
1025*4882a593Smuzhiyun
1026*4882a593Smuzhiyun if (sscanf(token, "%hu %hhu %hhu %u,",
1027*4882a593Smuzhiyun &tmp.code, &tmp.jt, &tmp.jf, &tmp.k) != 4) {
1028*4882a593Smuzhiyun rl_printf("syntax error at instruction %d!\n", i);
1029*4882a593Smuzhiyun return CMD_ERR;
1030*4882a593Smuzhiyun }
1031*4882a593Smuzhiyun
1032*4882a593Smuzhiyun bpf_image[i].code = tmp.code;
1033*4882a593Smuzhiyun bpf_image[i].jt = tmp.jt;
1034*4882a593Smuzhiyun bpf_image[i].jf = tmp.jf;
1035*4882a593Smuzhiyun bpf_image[i].k = tmp.k;
1036*4882a593Smuzhiyun
1037*4882a593Smuzhiyun i++;
1038*4882a593Smuzhiyun }
1039*4882a593Smuzhiyun
1040*4882a593Smuzhiyun if (i != bpf_len) {
1041*4882a593Smuzhiyun rl_printf("syntax error exceeding encoded length!\n");
1042*4882a593Smuzhiyun return CMD_ERR;
1043*4882a593Smuzhiyun } else
1044*4882a593Smuzhiyun bpf_prog_len = bpf_len;
1045*4882a593Smuzhiyun if (!bpf_runnable(bpf_image, bpf_prog_len))
1046*4882a593Smuzhiyun bpf_prog_len = 0;
1047*4882a593Smuzhiyun
1048*4882a593Smuzhiyun return CMD_OK;
1049*4882a593Smuzhiyun }
1050*4882a593Smuzhiyun
cmd_load_pcap(char * file)1051*4882a593Smuzhiyun static int cmd_load_pcap(char *file)
1052*4882a593Smuzhiyun {
1053*4882a593Smuzhiyun char *file_trim, *tmp;
1054*4882a593Smuzhiyun
1055*4882a593Smuzhiyun file_trim = strtok_r(file, " ", &tmp);
1056*4882a593Smuzhiyun if (file_trim == NULL)
1057*4882a593Smuzhiyun return CMD_ERR;
1058*4882a593Smuzhiyun
1059*4882a593Smuzhiyun try_close_pcap();
1060*4882a593Smuzhiyun
1061*4882a593Smuzhiyun return try_load_pcap(file_trim);
1062*4882a593Smuzhiyun }
1063*4882a593Smuzhiyun
cmd_load(char * arg)1064*4882a593Smuzhiyun static int cmd_load(char *arg)
1065*4882a593Smuzhiyun {
1066*4882a593Smuzhiyun char *subcmd, *cont = NULL, *tmp = strdup(arg);
1067*4882a593Smuzhiyun int ret = CMD_OK;
1068*4882a593Smuzhiyun
1069*4882a593Smuzhiyun subcmd = strtok_r(tmp, " ", &cont);
1070*4882a593Smuzhiyun if (subcmd == NULL)
1071*4882a593Smuzhiyun goto out;
1072*4882a593Smuzhiyun if (matches(subcmd, "bpf") == 0) {
1073*4882a593Smuzhiyun bpf_reset();
1074*4882a593Smuzhiyun bpf_reset_breakpoints();
1075*4882a593Smuzhiyun
1076*4882a593Smuzhiyun if (!cont)
1077*4882a593Smuzhiyun ret = CMD_ERR;
1078*4882a593Smuzhiyun else
1079*4882a593Smuzhiyun ret = cmd_load_bpf(cont);
1080*4882a593Smuzhiyun } else if (matches(subcmd, "pcap") == 0) {
1081*4882a593Smuzhiyun ret = cmd_load_pcap(cont);
1082*4882a593Smuzhiyun } else {
1083*4882a593Smuzhiyun out:
1084*4882a593Smuzhiyun rl_printf("bpf <code>: load bpf code\n");
1085*4882a593Smuzhiyun rl_printf("pcap <file>: load pcap file\n");
1086*4882a593Smuzhiyun ret = CMD_ERR;
1087*4882a593Smuzhiyun }
1088*4882a593Smuzhiyun
1089*4882a593Smuzhiyun free(tmp);
1090*4882a593Smuzhiyun return ret;
1091*4882a593Smuzhiyun }
1092*4882a593Smuzhiyun
cmd_step(char * num)1093*4882a593Smuzhiyun static int cmd_step(char *num)
1094*4882a593Smuzhiyun {
1095*4882a593Smuzhiyun struct pcap_pkthdr *hdr;
1096*4882a593Smuzhiyun int steps, ret;
1097*4882a593Smuzhiyun
1098*4882a593Smuzhiyun if (!bpf_prog_loaded() || !pcap_loaded())
1099*4882a593Smuzhiyun return CMD_ERR;
1100*4882a593Smuzhiyun
1101*4882a593Smuzhiyun steps = strtol(num, NULL, 10);
1102*4882a593Smuzhiyun if (steps == 0 || strlen(num) == 0)
1103*4882a593Smuzhiyun steps = 1;
1104*4882a593Smuzhiyun if (steps < 0) {
1105*4882a593Smuzhiyun if (!bpf_restore_regs(steps))
1106*4882a593Smuzhiyun return CMD_ERR;
1107*4882a593Smuzhiyun steps = 1;
1108*4882a593Smuzhiyun }
1109*4882a593Smuzhiyun
1110*4882a593Smuzhiyun hdr = pcap_curr_pkt();
1111*4882a593Smuzhiyun ret = bpf_run_stepping(bpf_image, bpf_prog_len,
1112*4882a593Smuzhiyun (uint8_t *) hdr + sizeof(*hdr),
1113*4882a593Smuzhiyun hdr->caplen, hdr->len, steps);
1114*4882a593Smuzhiyun if (ret >= 0 || bpf_curr.Rs) {
1115*4882a593Smuzhiyun bpf_reset();
1116*4882a593Smuzhiyun if (!pcap_next_pkt()) {
1117*4882a593Smuzhiyun rl_printf("(going back to first packet)\n");
1118*4882a593Smuzhiyun pcap_reset_pkt();
1119*4882a593Smuzhiyun } else {
1120*4882a593Smuzhiyun rl_printf("(next packet)\n");
1121*4882a593Smuzhiyun }
1122*4882a593Smuzhiyun }
1123*4882a593Smuzhiyun
1124*4882a593Smuzhiyun return CMD_OK;
1125*4882a593Smuzhiyun }
1126*4882a593Smuzhiyun
cmd_select(char * num)1127*4882a593Smuzhiyun static int cmd_select(char *num)
1128*4882a593Smuzhiyun {
1129*4882a593Smuzhiyun unsigned int which, i;
1130*4882a593Smuzhiyun bool have_next = true;
1131*4882a593Smuzhiyun
1132*4882a593Smuzhiyun if (!pcap_loaded() || strlen(num) == 0)
1133*4882a593Smuzhiyun return CMD_ERR;
1134*4882a593Smuzhiyun
1135*4882a593Smuzhiyun which = strtoul(num, NULL, 10);
1136*4882a593Smuzhiyun if (which == 0) {
1137*4882a593Smuzhiyun rl_printf("packet count starts with 1, clamping!\n");
1138*4882a593Smuzhiyun which = 1;
1139*4882a593Smuzhiyun }
1140*4882a593Smuzhiyun
1141*4882a593Smuzhiyun pcap_reset_pkt();
1142*4882a593Smuzhiyun bpf_reset();
1143*4882a593Smuzhiyun
1144*4882a593Smuzhiyun for (i = 0; i < which && (have_next = pcap_next_pkt()); i++)
1145*4882a593Smuzhiyun /* noop */;
1146*4882a593Smuzhiyun if (!have_next || pcap_curr_pkt() == NULL) {
1147*4882a593Smuzhiyun rl_printf("no packet #%u available!\n", which);
1148*4882a593Smuzhiyun pcap_reset_pkt();
1149*4882a593Smuzhiyun return CMD_ERR;
1150*4882a593Smuzhiyun }
1151*4882a593Smuzhiyun
1152*4882a593Smuzhiyun return CMD_OK;
1153*4882a593Smuzhiyun }
1154*4882a593Smuzhiyun
cmd_breakpoint(char * subcmd)1155*4882a593Smuzhiyun static int cmd_breakpoint(char *subcmd)
1156*4882a593Smuzhiyun {
1157*4882a593Smuzhiyun if (!bpf_prog_loaded())
1158*4882a593Smuzhiyun return CMD_ERR;
1159*4882a593Smuzhiyun if (strlen(subcmd) == 0)
1160*4882a593Smuzhiyun bpf_dump_breakpoints();
1161*4882a593Smuzhiyun else if (matches(subcmd, "reset") == 0)
1162*4882a593Smuzhiyun bpf_reset_breakpoints();
1163*4882a593Smuzhiyun else {
1164*4882a593Smuzhiyun unsigned int where = strtoul(subcmd, NULL, 10);
1165*4882a593Smuzhiyun
1166*4882a593Smuzhiyun if (where < bpf_prog_len) {
1167*4882a593Smuzhiyun bpf_set_breakpoints(where);
1168*4882a593Smuzhiyun rl_printf("breakpoint at: ");
1169*4882a593Smuzhiyun bpf_disasm(bpf_image[where], where);
1170*4882a593Smuzhiyun }
1171*4882a593Smuzhiyun }
1172*4882a593Smuzhiyun
1173*4882a593Smuzhiyun return CMD_OK;
1174*4882a593Smuzhiyun }
1175*4882a593Smuzhiyun
cmd_run(char * num)1176*4882a593Smuzhiyun static int cmd_run(char *num)
1177*4882a593Smuzhiyun {
1178*4882a593Smuzhiyun static uint32_t pass, fail;
1179*4882a593Smuzhiyun bool has_limit = true;
1180*4882a593Smuzhiyun int pkts = 0, i = 0;
1181*4882a593Smuzhiyun
1182*4882a593Smuzhiyun if (!bpf_prog_loaded() || !pcap_loaded())
1183*4882a593Smuzhiyun return CMD_ERR;
1184*4882a593Smuzhiyun
1185*4882a593Smuzhiyun pkts = strtol(num, NULL, 10);
1186*4882a593Smuzhiyun if (pkts == 0 || strlen(num) == 0)
1187*4882a593Smuzhiyun has_limit = false;
1188*4882a593Smuzhiyun
1189*4882a593Smuzhiyun do {
1190*4882a593Smuzhiyun struct pcap_pkthdr *hdr = pcap_curr_pkt();
1191*4882a593Smuzhiyun int ret = bpf_run_all(bpf_image, bpf_prog_len,
1192*4882a593Smuzhiyun (uint8_t *) hdr + sizeof(*hdr),
1193*4882a593Smuzhiyun hdr->caplen, hdr->len);
1194*4882a593Smuzhiyun if (ret > 0)
1195*4882a593Smuzhiyun pass++;
1196*4882a593Smuzhiyun else if (ret == 0)
1197*4882a593Smuzhiyun fail++;
1198*4882a593Smuzhiyun else
1199*4882a593Smuzhiyun return CMD_OK;
1200*4882a593Smuzhiyun bpf_reset();
1201*4882a593Smuzhiyun } while (pcap_next_pkt() && (!has_limit || (has_limit && ++i < pkts)));
1202*4882a593Smuzhiyun
1203*4882a593Smuzhiyun rl_printf("bpf passes:%u fails:%u\n", pass, fail);
1204*4882a593Smuzhiyun
1205*4882a593Smuzhiyun pcap_reset_pkt();
1206*4882a593Smuzhiyun bpf_reset();
1207*4882a593Smuzhiyun
1208*4882a593Smuzhiyun pass = fail = 0;
1209*4882a593Smuzhiyun return CMD_OK;
1210*4882a593Smuzhiyun }
1211*4882a593Smuzhiyun
cmd_disassemble(char * line_string)1212*4882a593Smuzhiyun static int cmd_disassemble(char *line_string)
1213*4882a593Smuzhiyun {
1214*4882a593Smuzhiyun bool single_line = false;
1215*4882a593Smuzhiyun unsigned long line;
1216*4882a593Smuzhiyun
1217*4882a593Smuzhiyun if (!bpf_prog_loaded())
1218*4882a593Smuzhiyun return CMD_ERR;
1219*4882a593Smuzhiyun if (strlen(line_string) > 0 &&
1220*4882a593Smuzhiyun (line = strtoul(line_string, NULL, 10)) < bpf_prog_len)
1221*4882a593Smuzhiyun single_line = true;
1222*4882a593Smuzhiyun if (single_line)
1223*4882a593Smuzhiyun bpf_disasm(bpf_image[line], line);
1224*4882a593Smuzhiyun else
1225*4882a593Smuzhiyun bpf_disasm_all(bpf_image, bpf_prog_len);
1226*4882a593Smuzhiyun
1227*4882a593Smuzhiyun return CMD_OK;
1228*4882a593Smuzhiyun }
1229*4882a593Smuzhiyun
cmd_dump(char * dontcare)1230*4882a593Smuzhiyun static int cmd_dump(char *dontcare)
1231*4882a593Smuzhiyun {
1232*4882a593Smuzhiyun if (!bpf_prog_loaded())
1233*4882a593Smuzhiyun return CMD_ERR;
1234*4882a593Smuzhiyun
1235*4882a593Smuzhiyun bpf_dump_all(bpf_image, bpf_prog_len);
1236*4882a593Smuzhiyun
1237*4882a593Smuzhiyun return CMD_OK;
1238*4882a593Smuzhiyun }
1239*4882a593Smuzhiyun
cmd_quit(char * dontcare)1240*4882a593Smuzhiyun static int cmd_quit(char *dontcare)
1241*4882a593Smuzhiyun {
1242*4882a593Smuzhiyun return CMD_EX;
1243*4882a593Smuzhiyun }
1244*4882a593Smuzhiyun
1245*4882a593Smuzhiyun static const struct shell_cmd cmds[] = {
1246*4882a593Smuzhiyun { .name = "load", .func = cmd_load },
1247*4882a593Smuzhiyun { .name = "select", .func = cmd_select },
1248*4882a593Smuzhiyun { .name = "step", .func = cmd_step },
1249*4882a593Smuzhiyun { .name = "run", .func = cmd_run },
1250*4882a593Smuzhiyun { .name = "breakpoint", .func = cmd_breakpoint },
1251*4882a593Smuzhiyun { .name = "disassemble", .func = cmd_disassemble },
1252*4882a593Smuzhiyun { .name = "dump", .func = cmd_dump },
1253*4882a593Smuzhiyun { .name = "quit", .func = cmd_quit },
1254*4882a593Smuzhiyun };
1255*4882a593Smuzhiyun
execf(char * arg)1256*4882a593Smuzhiyun static int execf(char *arg)
1257*4882a593Smuzhiyun {
1258*4882a593Smuzhiyun char *cmd, *cont, *tmp = strdup(arg);
1259*4882a593Smuzhiyun int i, ret = 0, len;
1260*4882a593Smuzhiyun
1261*4882a593Smuzhiyun cmd = strtok_r(tmp, " ", &cont);
1262*4882a593Smuzhiyun if (cmd == NULL)
1263*4882a593Smuzhiyun goto out;
1264*4882a593Smuzhiyun len = strlen(cmd);
1265*4882a593Smuzhiyun for (i = 0; i < array_size(cmds); i++) {
1266*4882a593Smuzhiyun if (len != strlen(cmds[i].name))
1267*4882a593Smuzhiyun continue;
1268*4882a593Smuzhiyun if (strncmp(cmds[i].name, cmd, len) == 0) {
1269*4882a593Smuzhiyun ret = cmds[i].func(cont);
1270*4882a593Smuzhiyun break;
1271*4882a593Smuzhiyun }
1272*4882a593Smuzhiyun }
1273*4882a593Smuzhiyun out:
1274*4882a593Smuzhiyun free(tmp);
1275*4882a593Smuzhiyun return ret;
1276*4882a593Smuzhiyun }
1277*4882a593Smuzhiyun
shell_comp_gen(const char * buf,int state)1278*4882a593Smuzhiyun static char *shell_comp_gen(const char *buf, int state)
1279*4882a593Smuzhiyun {
1280*4882a593Smuzhiyun static int list_index, len;
1281*4882a593Smuzhiyun
1282*4882a593Smuzhiyun if (!state) {
1283*4882a593Smuzhiyun list_index = 0;
1284*4882a593Smuzhiyun len = strlen(buf);
1285*4882a593Smuzhiyun }
1286*4882a593Smuzhiyun
1287*4882a593Smuzhiyun for (; list_index < array_size(cmds); ) {
1288*4882a593Smuzhiyun const char *name = cmds[list_index].name;
1289*4882a593Smuzhiyun
1290*4882a593Smuzhiyun list_index++;
1291*4882a593Smuzhiyun if (strncmp(name, buf, len) == 0)
1292*4882a593Smuzhiyun return strdup(name);
1293*4882a593Smuzhiyun }
1294*4882a593Smuzhiyun
1295*4882a593Smuzhiyun return NULL;
1296*4882a593Smuzhiyun }
1297*4882a593Smuzhiyun
shell_completion(const char * buf,int start,int end)1298*4882a593Smuzhiyun static char **shell_completion(const char *buf, int start, int end)
1299*4882a593Smuzhiyun {
1300*4882a593Smuzhiyun char **matches = NULL;
1301*4882a593Smuzhiyun
1302*4882a593Smuzhiyun if (start == 0)
1303*4882a593Smuzhiyun matches = rl_completion_matches(buf, shell_comp_gen);
1304*4882a593Smuzhiyun
1305*4882a593Smuzhiyun return matches;
1306*4882a593Smuzhiyun }
1307*4882a593Smuzhiyun
intr_shell(int sig)1308*4882a593Smuzhiyun static void intr_shell(int sig)
1309*4882a593Smuzhiyun {
1310*4882a593Smuzhiyun if (rl_end)
1311*4882a593Smuzhiyun rl_kill_line(-1, 0);
1312*4882a593Smuzhiyun
1313*4882a593Smuzhiyun rl_crlf();
1314*4882a593Smuzhiyun rl_refresh_line(0, 0);
1315*4882a593Smuzhiyun rl_free_line_state();
1316*4882a593Smuzhiyun }
1317*4882a593Smuzhiyun
init_shell(FILE * fin,FILE * fout)1318*4882a593Smuzhiyun static void init_shell(FILE *fin, FILE *fout)
1319*4882a593Smuzhiyun {
1320*4882a593Smuzhiyun char file[128];
1321*4882a593Smuzhiyun
1322*4882a593Smuzhiyun snprintf(file, sizeof(file), "%s/.bpf_dbg_history", getenv("HOME"));
1323*4882a593Smuzhiyun read_history(file);
1324*4882a593Smuzhiyun
1325*4882a593Smuzhiyun rl_instream = fin;
1326*4882a593Smuzhiyun rl_outstream = fout;
1327*4882a593Smuzhiyun
1328*4882a593Smuzhiyun rl_readline_name = "bpf_dbg";
1329*4882a593Smuzhiyun rl_terminal_name = getenv("TERM");
1330*4882a593Smuzhiyun
1331*4882a593Smuzhiyun rl_catch_signals = 0;
1332*4882a593Smuzhiyun rl_catch_sigwinch = 1;
1333*4882a593Smuzhiyun
1334*4882a593Smuzhiyun rl_attempted_completion_function = shell_completion;
1335*4882a593Smuzhiyun
1336*4882a593Smuzhiyun rl_bind_key('\t', rl_complete);
1337*4882a593Smuzhiyun
1338*4882a593Smuzhiyun rl_bind_key_in_map('\t', rl_complete, emacs_meta_keymap);
1339*4882a593Smuzhiyun rl_bind_key_in_map('\033', rl_complete, emacs_meta_keymap);
1340*4882a593Smuzhiyun
1341*4882a593Smuzhiyun snprintf(file, sizeof(file), "%s/.bpf_dbg_init", getenv("HOME"));
1342*4882a593Smuzhiyun rl_read_init_file(file);
1343*4882a593Smuzhiyun
1344*4882a593Smuzhiyun rl_prep_terminal(0);
1345*4882a593Smuzhiyun rl_set_signals();
1346*4882a593Smuzhiyun
1347*4882a593Smuzhiyun signal(SIGINT, intr_shell);
1348*4882a593Smuzhiyun }
1349*4882a593Smuzhiyun
exit_shell(FILE * fin,FILE * fout)1350*4882a593Smuzhiyun static void exit_shell(FILE *fin, FILE *fout)
1351*4882a593Smuzhiyun {
1352*4882a593Smuzhiyun char file[128];
1353*4882a593Smuzhiyun
1354*4882a593Smuzhiyun snprintf(file, sizeof(file), "%s/.bpf_dbg_history", getenv("HOME"));
1355*4882a593Smuzhiyun write_history(file);
1356*4882a593Smuzhiyun
1357*4882a593Smuzhiyun clear_history();
1358*4882a593Smuzhiyun rl_deprep_terminal();
1359*4882a593Smuzhiyun
1360*4882a593Smuzhiyun try_close_pcap();
1361*4882a593Smuzhiyun
1362*4882a593Smuzhiyun if (fin != stdin)
1363*4882a593Smuzhiyun fclose(fin);
1364*4882a593Smuzhiyun if (fout != stdout)
1365*4882a593Smuzhiyun fclose(fout);
1366*4882a593Smuzhiyun }
1367*4882a593Smuzhiyun
run_shell_loop(FILE * fin,FILE * fout)1368*4882a593Smuzhiyun static int run_shell_loop(FILE *fin, FILE *fout)
1369*4882a593Smuzhiyun {
1370*4882a593Smuzhiyun char *buf;
1371*4882a593Smuzhiyun
1372*4882a593Smuzhiyun init_shell(fin, fout);
1373*4882a593Smuzhiyun
1374*4882a593Smuzhiyun while ((buf = readline("> ")) != NULL) {
1375*4882a593Smuzhiyun int ret = execf(buf);
1376*4882a593Smuzhiyun if (ret == CMD_EX)
1377*4882a593Smuzhiyun break;
1378*4882a593Smuzhiyun if (ret == CMD_OK && strlen(buf) > 0)
1379*4882a593Smuzhiyun add_history(buf);
1380*4882a593Smuzhiyun
1381*4882a593Smuzhiyun free(buf);
1382*4882a593Smuzhiyun }
1383*4882a593Smuzhiyun
1384*4882a593Smuzhiyun exit_shell(fin, fout);
1385*4882a593Smuzhiyun return 0;
1386*4882a593Smuzhiyun }
1387*4882a593Smuzhiyun
main(int argc,char ** argv)1388*4882a593Smuzhiyun int main(int argc, char **argv)
1389*4882a593Smuzhiyun {
1390*4882a593Smuzhiyun FILE *fin = NULL, *fout = NULL;
1391*4882a593Smuzhiyun
1392*4882a593Smuzhiyun if (argc >= 2)
1393*4882a593Smuzhiyun fin = fopen(argv[1], "r");
1394*4882a593Smuzhiyun if (argc >= 3)
1395*4882a593Smuzhiyun fout = fopen(argv[2], "w");
1396*4882a593Smuzhiyun
1397*4882a593Smuzhiyun return run_shell_loop(fin ? : stdin, fout ? : stdout);
1398*4882a593Smuzhiyun }
1399