xref: /OK3568_Linux_fs/kernel/tools/testing/selftests/bpf/test_sock_addr.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0
2*4882a593Smuzhiyun // Copyright (c) 2018 Facebook
3*4882a593Smuzhiyun 
4*4882a593Smuzhiyun #define _GNU_SOURCE
5*4882a593Smuzhiyun 
6*4882a593Smuzhiyun #include <stdio.h>
7*4882a593Smuzhiyun #include <stdlib.h>
8*4882a593Smuzhiyun #include <unistd.h>
9*4882a593Smuzhiyun 
10*4882a593Smuzhiyun #include <arpa/inet.h>
11*4882a593Smuzhiyun #include <netinet/in.h>
12*4882a593Smuzhiyun #include <sys/types.h>
13*4882a593Smuzhiyun #include <sys/select.h>
14*4882a593Smuzhiyun #include <sys/socket.h>
15*4882a593Smuzhiyun 
16*4882a593Smuzhiyun #include <linux/filter.h>
17*4882a593Smuzhiyun 
18*4882a593Smuzhiyun #include <bpf/bpf.h>
19*4882a593Smuzhiyun #include <bpf/libbpf.h>
20*4882a593Smuzhiyun 
21*4882a593Smuzhiyun #include "cgroup_helpers.h"
22*4882a593Smuzhiyun #include "bpf_rlimit.h"
23*4882a593Smuzhiyun #include "bpf_util.h"
24*4882a593Smuzhiyun 
25*4882a593Smuzhiyun #ifndef ENOTSUPP
26*4882a593Smuzhiyun # define ENOTSUPP 524
27*4882a593Smuzhiyun #endif
28*4882a593Smuzhiyun 
29*4882a593Smuzhiyun #define CG_PATH	"/foo"
30*4882a593Smuzhiyun #define CONNECT4_PROG_PATH	"./connect4_prog.o"
31*4882a593Smuzhiyun #define CONNECT6_PROG_PATH	"./connect6_prog.o"
32*4882a593Smuzhiyun #define SENDMSG4_PROG_PATH	"./sendmsg4_prog.o"
33*4882a593Smuzhiyun #define SENDMSG6_PROG_PATH	"./sendmsg6_prog.o"
34*4882a593Smuzhiyun 
35*4882a593Smuzhiyun #define SERV4_IP		"192.168.1.254"
36*4882a593Smuzhiyun #define SERV4_REWRITE_IP	"127.0.0.1"
37*4882a593Smuzhiyun #define SRC4_IP			"172.16.0.1"
38*4882a593Smuzhiyun #define SRC4_REWRITE_IP		"127.0.0.4"
39*4882a593Smuzhiyun #define SERV4_PORT		4040
40*4882a593Smuzhiyun #define SERV4_REWRITE_PORT	4444
41*4882a593Smuzhiyun 
42*4882a593Smuzhiyun #define SERV6_IP		"face:b00c:1234:5678::abcd"
43*4882a593Smuzhiyun #define SERV6_REWRITE_IP	"::1"
44*4882a593Smuzhiyun #define SERV6_V4MAPPED_IP	"::ffff:192.168.0.4"
45*4882a593Smuzhiyun #define SRC6_IP			"::1"
46*4882a593Smuzhiyun #define SRC6_REWRITE_IP		"::6"
47*4882a593Smuzhiyun #define WILDCARD6_IP		"::"
48*4882a593Smuzhiyun #define SERV6_PORT		6060
49*4882a593Smuzhiyun #define SERV6_REWRITE_PORT	6666
50*4882a593Smuzhiyun 
51*4882a593Smuzhiyun #define INET_NTOP_BUF	40
52*4882a593Smuzhiyun 
53*4882a593Smuzhiyun struct sock_addr_test;
54*4882a593Smuzhiyun 
55*4882a593Smuzhiyun typedef int (*load_fn)(const struct sock_addr_test *test);
56*4882a593Smuzhiyun typedef int (*info_fn)(int, struct sockaddr *, socklen_t *);
57*4882a593Smuzhiyun 
58*4882a593Smuzhiyun char bpf_log_buf[BPF_LOG_BUF_SIZE];
59*4882a593Smuzhiyun 
60*4882a593Smuzhiyun struct sock_addr_test {
61*4882a593Smuzhiyun 	const char *descr;
62*4882a593Smuzhiyun 	/* BPF prog properties */
63*4882a593Smuzhiyun 	load_fn loadfn;
64*4882a593Smuzhiyun 	enum bpf_attach_type expected_attach_type;
65*4882a593Smuzhiyun 	enum bpf_attach_type attach_type;
66*4882a593Smuzhiyun 	/* Socket properties */
67*4882a593Smuzhiyun 	int domain;
68*4882a593Smuzhiyun 	int type;
69*4882a593Smuzhiyun 	/* IP:port pairs for BPF prog to override */
70*4882a593Smuzhiyun 	const char *requested_ip;
71*4882a593Smuzhiyun 	unsigned short requested_port;
72*4882a593Smuzhiyun 	const char *expected_ip;
73*4882a593Smuzhiyun 	unsigned short expected_port;
74*4882a593Smuzhiyun 	const char *expected_src_ip;
75*4882a593Smuzhiyun 	/* Expected test result */
76*4882a593Smuzhiyun 	enum {
77*4882a593Smuzhiyun 		LOAD_REJECT,
78*4882a593Smuzhiyun 		ATTACH_REJECT,
79*4882a593Smuzhiyun 		ATTACH_OKAY,
80*4882a593Smuzhiyun 		SYSCALL_EPERM,
81*4882a593Smuzhiyun 		SYSCALL_ENOTSUPP,
82*4882a593Smuzhiyun 		SUCCESS,
83*4882a593Smuzhiyun 	} expected_result;
84*4882a593Smuzhiyun };
85*4882a593Smuzhiyun 
86*4882a593Smuzhiyun static int bind4_prog_load(const struct sock_addr_test *test);
87*4882a593Smuzhiyun static int bind6_prog_load(const struct sock_addr_test *test);
88*4882a593Smuzhiyun static int connect4_prog_load(const struct sock_addr_test *test);
89*4882a593Smuzhiyun static int connect6_prog_load(const struct sock_addr_test *test);
90*4882a593Smuzhiyun static int sendmsg_allow_prog_load(const struct sock_addr_test *test);
91*4882a593Smuzhiyun static int sendmsg_deny_prog_load(const struct sock_addr_test *test);
92*4882a593Smuzhiyun static int recvmsg_allow_prog_load(const struct sock_addr_test *test);
93*4882a593Smuzhiyun static int recvmsg_deny_prog_load(const struct sock_addr_test *test);
94*4882a593Smuzhiyun static int sendmsg4_rw_asm_prog_load(const struct sock_addr_test *test);
95*4882a593Smuzhiyun static int recvmsg4_rw_asm_prog_load(const struct sock_addr_test *test);
96*4882a593Smuzhiyun static int sendmsg4_rw_c_prog_load(const struct sock_addr_test *test);
97*4882a593Smuzhiyun static int sendmsg6_rw_asm_prog_load(const struct sock_addr_test *test);
98*4882a593Smuzhiyun static int recvmsg6_rw_asm_prog_load(const struct sock_addr_test *test);
99*4882a593Smuzhiyun static int sendmsg6_rw_c_prog_load(const struct sock_addr_test *test);
100*4882a593Smuzhiyun static int sendmsg6_rw_v4mapped_prog_load(const struct sock_addr_test *test);
101*4882a593Smuzhiyun static int sendmsg6_rw_wildcard_prog_load(const struct sock_addr_test *test);
102*4882a593Smuzhiyun 
103*4882a593Smuzhiyun static struct sock_addr_test tests[] = {
104*4882a593Smuzhiyun 	/* bind */
105*4882a593Smuzhiyun 	{
106*4882a593Smuzhiyun 		"bind4: load prog with wrong expected attach type",
107*4882a593Smuzhiyun 		bind4_prog_load,
108*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
109*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
110*4882a593Smuzhiyun 		AF_INET,
111*4882a593Smuzhiyun 		SOCK_STREAM,
112*4882a593Smuzhiyun 		NULL,
113*4882a593Smuzhiyun 		0,
114*4882a593Smuzhiyun 		NULL,
115*4882a593Smuzhiyun 		0,
116*4882a593Smuzhiyun 		NULL,
117*4882a593Smuzhiyun 		LOAD_REJECT,
118*4882a593Smuzhiyun 	},
119*4882a593Smuzhiyun 	{
120*4882a593Smuzhiyun 		"bind4: attach prog with wrong attach type",
121*4882a593Smuzhiyun 		bind4_prog_load,
122*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
123*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
124*4882a593Smuzhiyun 		AF_INET,
125*4882a593Smuzhiyun 		SOCK_STREAM,
126*4882a593Smuzhiyun 		NULL,
127*4882a593Smuzhiyun 		0,
128*4882a593Smuzhiyun 		NULL,
129*4882a593Smuzhiyun 		0,
130*4882a593Smuzhiyun 		NULL,
131*4882a593Smuzhiyun 		ATTACH_REJECT,
132*4882a593Smuzhiyun 	},
133*4882a593Smuzhiyun 	{
134*4882a593Smuzhiyun 		"bind4: rewrite IP & TCP port in",
135*4882a593Smuzhiyun 		bind4_prog_load,
136*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
137*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
138*4882a593Smuzhiyun 		AF_INET,
139*4882a593Smuzhiyun 		SOCK_STREAM,
140*4882a593Smuzhiyun 		SERV4_IP,
141*4882a593Smuzhiyun 		SERV4_PORT,
142*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
143*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
144*4882a593Smuzhiyun 		NULL,
145*4882a593Smuzhiyun 		SUCCESS,
146*4882a593Smuzhiyun 	},
147*4882a593Smuzhiyun 	{
148*4882a593Smuzhiyun 		"bind4: rewrite IP & UDP port in",
149*4882a593Smuzhiyun 		bind4_prog_load,
150*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
151*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
152*4882a593Smuzhiyun 		AF_INET,
153*4882a593Smuzhiyun 		SOCK_DGRAM,
154*4882a593Smuzhiyun 		SERV4_IP,
155*4882a593Smuzhiyun 		SERV4_PORT,
156*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
157*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
158*4882a593Smuzhiyun 		NULL,
159*4882a593Smuzhiyun 		SUCCESS,
160*4882a593Smuzhiyun 	},
161*4882a593Smuzhiyun 	{
162*4882a593Smuzhiyun 		"bind6: load prog with wrong expected attach type",
163*4882a593Smuzhiyun 		bind6_prog_load,
164*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
165*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
166*4882a593Smuzhiyun 		AF_INET6,
167*4882a593Smuzhiyun 		SOCK_STREAM,
168*4882a593Smuzhiyun 		NULL,
169*4882a593Smuzhiyun 		0,
170*4882a593Smuzhiyun 		NULL,
171*4882a593Smuzhiyun 		0,
172*4882a593Smuzhiyun 		NULL,
173*4882a593Smuzhiyun 		LOAD_REJECT,
174*4882a593Smuzhiyun 	},
175*4882a593Smuzhiyun 	{
176*4882a593Smuzhiyun 		"bind6: attach prog with wrong attach type",
177*4882a593Smuzhiyun 		bind6_prog_load,
178*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
179*4882a593Smuzhiyun 		BPF_CGROUP_INET4_BIND,
180*4882a593Smuzhiyun 		AF_INET,
181*4882a593Smuzhiyun 		SOCK_STREAM,
182*4882a593Smuzhiyun 		NULL,
183*4882a593Smuzhiyun 		0,
184*4882a593Smuzhiyun 		NULL,
185*4882a593Smuzhiyun 		0,
186*4882a593Smuzhiyun 		NULL,
187*4882a593Smuzhiyun 		ATTACH_REJECT,
188*4882a593Smuzhiyun 	},
189*4882a593Smuzhiyun 	{
190*4882a593Smuzhiyun 		"bind6: rewrite IP & TCP port in",
191*4882a593Smuzhiyun 		bind6_prog_load,
192*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
193*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
194*4882a593Smuzhiyun 		AF_INET6,
195*4882a593Smuzhiyun 		SOCK_STREAM,
196*4882a593Smuzhiyun 		SERV6_IP,
197*4882a593Smuzhiyun 		SERV6_PORT,
198*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
199*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
200*4882a593Smuzhiyun 		NULL,
201*4882a593Smuzhiyun 		SUCCESS,
202*4882a593Smuzhiyun 	},
203*4882a593Smuzhiyun 	{
204*4882a593Smuzhiyun 		"bind6: rewrite IP & UDP port in",
205*4882a593Smuzhiyun 		bind6_prog_load,
206*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
207*4882a593Smuzhiyun 		BPF_CGROUP_INET6_BIND,
208*4882a593Smuzhiyun 		AF_INET6,
209*4882a593Smuzhiyun 		SOCK_DGRAM,
210*4882a593Smuzhiyun 		SERV6_IP,
211*4882a593Smuzhiyun 		SERV6_PORT,
212*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
213*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
214*4882a593Smuzhiyun 		NULL,
215*4882a593Smuzhiyun 		SUCCESS,
216*4882a593Smuzhiyun 	},
217*4882a593Smuzhiyun 
218*4882a593Smuzhiyun 	/* connect */
219*4882a593Smuzhiyun 	{
220*4882a593Smuzhiyun 		"connect4: load prog with wrong expected attach type",
221*4882a593Smuzhiyun 		connect4_prog_load,
222*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
223*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
224*4882a593Smuzhiyun 		AF_INET,
225*4882a593Smuzhiyun 		SOCK_STREAM,
226*4882a593Smuzhiyun 		NULL,
227*4882a593Smuzhiyun 		0,
228*4882a593Smuzhiyun 		NULL,
229*4882a593Smuzhiyun 		0,
230*4882a593Smuzhiyun 		NULL,
231*4882a593Smuzhiyun 		LOAD_REJECT,
232*4882a593Smuzhiyun 	},
233*4882a593Smuzhiyun 	{
234*4882a593Smuzhiyun 		"connect4: attach prog with wrong attach type",
235*4882a593Smuzhiyun 		connect4_prog_load,
236*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
237*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
238*4882a593Smuzhiyun 		AF_INET,
239*4882a593Smuzhiyun 		SOCK_STREAM,
240*4882a593Smuzhiyun 		NULL,
241*4882a593Smuzhiyun 		0,
242*4882a593Smuzhiyun 		NULL,
243*4882a593Smuzhiyun 		0,
244*4882a593Smuzhiyun 		NULL,
245*4882a593Smuzhiyun 		ATTACH_REJECT,
246*4882a593Smuzhiyun 	},
247*4882a593Smuzhiyun 	{
248*4882a593Smuzhiyun 		"connect4: rewrite IP & TCP port",
249*4882a593Smuzhiyun 		connect4_prog_load,
250*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
251*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
252*4882a593Smuzhiyun 		AF_INET,
253*4882a593Smuzhiyun 		SOCK_STREAM,
254*4882a593Smuzhiyun 		SERV4_IP,
255*4882a593Smuzhiyun 		SERV4_PORT,
256*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
257*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
258*4882a593Smuzhiyun 		SRC4_REWRITE_IP,
259*4882a593Smuzhiyun 		SUCCESS,
260*4882a593Smuzhiyun 	},
261*4882a593Smuzhiyun 	{
262*4882a593Smuzhiyun 		"connect4: rewrite IP & UDP port",
263*4882a593Smuzhiyun 		connect4_prog_load,
264*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
265*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
266*4882a593Smuzhiyun 		AF_INET,
267*4882a593Smuzhiyun 		SOCK_DGRAM,
268*4882a593Smuzhiyun 		SERV4_IP,
269*4882a593Smuzhiyun 		SERV4_PORT,
270*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
271*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
272*4882a593Smuzhiyun 		SRC4_REWRITE_IP,
273*4882a593Smuzhiyun 		SUCCESS,
274*4882a593Smuzhiyun 	},
275*4882a593Smuzhiyun 	{
276*4882a593Smuzhiyun 		"connect6: load prog with wrong expected attach type",
277*4882a593Smuzhiyun 		connect6_prog_load,
278*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
279*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
280*4882a593Smuzhiyun 		AF_INET6,
281*4882a593Smuzhiyun 		SOCK_STREAM,
282*4882a593Smuzhiyun 		NULL,
283*4882a593Smuzhiyun 		0,
284*4882a593Smuzhiyun 		NULL,
285*4882a593Smuzhiyun 		0,
286*4882a593Smuzhiyun 		NULL,
287*4882a593Smuzhiyun 		LOAD_REJECT,
288*4882a593Smuzhiyun 	},
289*4882a593Smuzhiyun 	{
290*4882a593Smuzhiyun 		"connect6: attach prog with wrong attach type",
291*4882a593Smuzhiyun 		connect6_prog_load,
292*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
293*4882a593Smuzhiyun 		BPF_CGROUP_INET4_CONNECT,
294*4882a593Smuzhiyun 		AF_INET,
295*4882a593Smuzhiyun 		SOCK_STREAM,
296*4882a593Smuzhiyun 		NULL,
297*4882a593Smuzhiyun 		0,
298*4882a593Smuzhiyun 		NULL,
299*4882a593Smuzhiyun 		0,
300*4882a593Smuzhiyun 		NULL,
301*4882a593Smuzhiyun 		ATTACH_REJECT,
302*4882a593Smuzhiyun 	},
303*4882a593Smuzhiyun 	{
304*4882a593Smuzhiyun 		"connect6: rewrite IP & TCP port",
305*4882a593Smuzhiyun 		connect6_prog_load,
306*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
307*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
308*4882a593Smuzhiyun 		AF_INET6,
309*4882a593Smuzhiyun 		SOCK_STREAM,
310*4882a593Smuzhiyun 		SERV6_IP,
311*4882a593Smuzhiyun 		SERV6_PORT,
312*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
313*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
314*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
315*4882a593Smuzhiyun 		SUCCESS,
316*4882a593Smuzhiyun 	},
317*4882a593Smuzhiyun 	{
318*4882a593Smuzhiyun 		"connect6: rewrite IP & UDP port",
319*4882a593Smuzhiyun 		connect6_prog_load,
320*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
321*4882a593Smuzhiyun 		BPF_CGROUP_INET6_CONNECT,
322*4882a593Smuzhiyun 		AF_INET6,
323*4882a593Smuzhiyun 		SOCK_DGRAM,
324*4882a593Smuzhiyun 		SERV6_IP,
325*4882a593Smuzhiyun 		SERV6_PORT,
326*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
327*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
328*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
329*4882a593Smuzhiyun 		SUCCESS,
330*4882a593Smuzhiyun 	},
331*4882a593Smuzhiyun 
332*4882a593Smuzhiyun 	/* sendmsg */
333*4882a593Smuzhiyun 	{
334*4882a593Smuzhiyun 		"sendmsg4: load prog with wrong expected attach type",
335*4882a593Smuzhiyun 		sendmsg4_rw_asm_prog_load,
336*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
337*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
338*4882a593Smuzhiyun 		AF_INET,
339*4882a593Smuzhiyun 		SOCK_DGRAM,
340*4882a593Smuzhiyun 		NULL,
341*4882a593Smuzhiyun 		0,
342*4882a593Smuzhiyun 		NULL,
343*4882a593Smuzhiyun 		0,
344*4882a593Smuzhiyun 		NULL,
345*4882a593Smuzhiyun 		LOAD_REJECT,
346*4882a593Smuzhiyun 	},
347*4882a593Smuzhiyun 	{
348*4882a593Smuzhiyun 		"sendmsg4: attach prog with wrong attach type",
349*4882a593Smuzhiyun 		sendmsg4_rw_asm_prog_load,
350*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
351*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
352*4882a593Smuzhiyun 		AF_INET,
353*4882a593Smuzhiyun 		SOCK_DGRAM,
354*4882a593Smuzhiyun 		NULL,
355*4882a593Smuzhiyun 		0,
356*4882a593Smuzhiyun 		NULL,
357*4882a593Smuzhiyun 		0,
358*4882a593Smuzhiyun 		NULL,
359*4882a593Smuzhiyun 		ATTACH_REJECT,
360*4882a593Smuzhiyun 	},
361*4882a593Smuzhiyun 	{
362*4882a593Smuzhiyun 		"sendmsg4: rewrite IP & port (asm)",
363*4882a593Smuzhiyun 		sendmsg4_rw_asm_prog_load,
364*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
365*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
366*4882a593Smuzhiyun 		AF_INET,
367*4882a593Smuzhiyun 		SOCK_DGRAM,
368*4882a593Smuzhiyun 		SERV4_IP,
369*4882a593Smuzhiyun 		SERV4_PORT,
370*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
371*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
372*4882a593Smuzhiyun 		SRC4_REWRITE_IP,
373*4882a593Smuzhiyun 		SUCCESS,
374*4882a593Smuzhiyun 	},
375*4882a593Smuzhiyun 	{
376*4882a593Smuzhiyun 		"sendmsg4: rewrite IP & port (C)",
377*4882a593Smuzhiyun 		sendmsg4_rw_c_prog_load,
378*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
379*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
380*4882a593Smuzhiyun 		AF_INET,
381*4882a593Smuzhiyun 		SOCK_DGRAM,
382*4882a593Smuzhiyun 		SERV4_IP,
383*4882a593Smuzhiyun 		SERV4_PORT,
384*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
385*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
386*4882a593Smuzhiyun 		SRC4_REWRITE_IP,
387*4882a593Smuzhiyun 		SUCCESS,
388*4882a593Smuzhiyun 	},
389*4882a593Smuzhiyun 	{
390*4882a593Smuzhiyun 		"sendmsg4: deny call",
391*4882a593Smuzhiyun 		sendmsg_deny_prog_load,
392*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
393*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
394*4882a593Smuzhiyun 		AF_INET,
395*4882a593Smuzhiyun 		SOCK_DGRAM,
396*4882a593Smuzhiyun 		SERV4_IP,
397*4882a593Smuzhiyun 		SERV4_PORT,
398*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
399*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
400*4882a593Smuzhiyun 		SRC4_REWRITE_IP,
401*4882a593Smuzhiyun 		SYSCALL_EPERM,
402*4882a593Smuzhiyun 	},
403*4882a593Smuzhiyun 	{
404*4882a593Smuzhiyun 		"sendmsg6: load prog with wrong expected attach type",
405*4882a593Smuzhiyun 		sendmsg6_rw_asm_prog_load,
406*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
407*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
408*4882a593Smuzhiyun 		AF_INET6,
409*4882a593Smuzhiyun 		SOCK_DGRAM,
410*4882a593Smuzhiyun 		NULL,
411*4882a593Smuzhiyun 		0,
412*4882a593Smuzhiyun 		NULL,
413*4882a593Smuzhiyun 		0,
414*4882a593Smuzhiyun 		NULL,
415*4882a593Smuzhiyun 		LOAD_REJECT,
416*4882a593Smuzhiyun 	},
417*4882a593Smuzhiyun 	{
418*4882a593Smuzhiyun 		"sendmsg6: attach prog with wrong attach type",
419*4882a593Smuzhiyun 		sendmsg6_rw_asm_prog_load,
420*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
421*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_SENDMSG,
422*4882a593Smuzhiyun 		AF_INET6,
423*4882a593Smuzhiyun 		SOCK_DGRAM,
424*4882a593Smuzhiyun 		NULL,
425*4882a593Smuzhiyun 		0,
426*4882a593Smuzhiyun 		NULL,
427*4882a593Smuzhiyun 		0,
428*4882a593Smuzhiyun 		NULL,
429*4882a593Smuzhiyun 		ATTACH_REJECT,
430*4882a593Smuzhiyun 	},
431*4882a593Smuzhiyun 	{
432*4882a593Smuzhiyun 		"sendmsg6: rewrite IP & port (asm)",
433*4882a593Smuzhiyun 		sendmsg6_rw_asm_prog_load,
434*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
435*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
436*4882a593Smuzhiyun 		AF_INET6,
437*4882a593Smuzhiyun 		SOCK_DGRAM,
438*4882a593Smuzhiyun 		SERV6_IP,
439*4882a593Smuzhiyun 		SERV6_PORT,
440*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
441*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
442*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
443*4882a593Smuzhiyun 		SUCCESS,
444*4882a593Smuzhiyun 	},
445*4882a593Smuzhiyun 	{
446*4882a593Smuzhiyun 		"sendmsg6: rewrite IP & port (C)",
447*4882a593Smuzhiyun 		sendmsg6_rw_c_prog_load,
448*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
449*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
450*4882a593Smuzhiyun 		AF_INET6,
451*4882a593Smuzhiyun 		SOCK_DGRAM,
452*4882a593Smuzhiyun 		SERV6_IP,
453*4882a593Smuzhiyun 		SERV6_PORT,
454*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
455*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
456*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
457*4882a593Smuzhiyun 		SUCCESS,
458*4882a593Smuzhiyun 	},
459*4882a593Smuzhiyun 	{
460*4882a593Smuzhiyun 		"sendmsg6: IPv4-mapped IPv6",
461*4882a593Smuzhiyun 		sendmsg6_rw_v4mapped_prog_load,
462*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
463*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
464*4882a593Smuzhiyun 		AF_INET6,
465*4882a593Smuzhiyun 		SOCK_DGRAM,
466*4882a593Smuzhiyun 		SERV6_IP,
467*4882a593Smuzhiyun 		SERV6_PORT,
468*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
469*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
470*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
471*4882a593Smuzhiyun 		SYSCALL_ENOTSUPP,
472*4882a593Smuzhiyun 	},
473*4882a593Smuzhiyun 	{
474*4882a593Smuzhiyun 		"sendmsg6: set dst IP = [::] (BSD'ism)",
475*4882a593Smuzhiyun 		sendmsg6_rw_wildcard_prog_load,
476*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
477*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
478*4882a593Smuzhiyun 		AF_INET6,
479*4882a593Smuzhiyun 		SOCK_DGRAM,
480*4882a593Smuzhiyun 		SERV6_IP,
481*4882a593Smuzhiyun 		SERV6_PORT,
482*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
483*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
484*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
485*4882a593Smuzhiyun 		SUCCESS,
486*4882a593Smuzhiyun 	},
487*4882a593Smuzhiyun 	{
488*4882a593Smuzhiyun 		"sendmsg6: preserve dst IP = [::] (BSD'ism)",
489*4882a593Smuzhiyun 		sendmsg_allow_prog_load,
490*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
491*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
492*4882a593Smuzhiyun 		AF_INET6,
493*4882a593Smuzhiyun 		SOCK_DGRAM,
494*4882a593Smuzhiyun 		WILDCARD6_IP,
495*4882a593Smuzhiyun 		SERV6_PORT,
496*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
497*4882a593Smuzhiyun 		SERV6_PORT,
498*4882a593Smuzhiyun 		SRC6_IP,
499*4882a593Smuzhiyun 		SUCCESS,
500*4882a593Smuzhiyun 	},
501*4882a593Smuzhiyun 	{
502*4882a593Smuzhiyun 		"sendmsg6: deny call",
503*4882a593Smuzhiyun 		sendmsg_deny_prog_load,
504*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
505*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_SENDMSG,
506*4882a593Smuzhiyun 		AF_INET6,
507*4882a593Smuzhiyun 		SOCK_DGRAM,
508*4882a593Smuzhiyun 		SERV6_IP,
509*4882a593Smuzhiyun 		SERV6_PORT,
510*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
511*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
512*4882a593Smuzhiyun 		SRC6_REWRITE_IP,
513*4882a593Smuzhiyun 		SYSCALL_EPERM,
514*4882a593Smuzhiyun 	},
515*4882a593Smuzhiyun 
516*4882a593Smuzhiyun 	/* recvmsg */
517*4882a593Smuzhiyun 	{
518*4882a593Smuzhiyun 		"recvmsg4: return code ok",
519*4882a593Smuzhiyun 		recvmsg_allow_prog_load,
520*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_RECVMSG,
521*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_RECVMSG,
522*4882a593Smuzhiyun 		AF_INET,
523*4882a593Smuzhiyun 		SOCK_DGRAM,
524*4882a593Smuzhiyun 		NULL,
525*4882a593Smuzhiyun 		0,
526*4882a593Smuzhiyun 		NULL,
527*4882a593Smuzhiyun 		0,
528*4882a593Smuzhiyun 		NULL,
529*4882a593Smuzhiyun 		ATTACH_OKAY,
530*4882a593Smuzhiyun 	},
531*4882a593Smuzhiyun 	{
532*4882a593Smuzhiyun 		"recvmsg4: return code !ok",
533*4882a593Smuzhiyun 		recvmsg_deny_prog_load,
534*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_RECVMSG,
535*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_RECVMSG,
536*4882a593Smuzhiyun 		AF_INET,
537*4882a593Smuzhiyun 		SOCK_DGRAM,
538*4882a593Smuzhiyun 		NULL,
539*4882a593Smuzhiyun 		0,
540*4882a593Smuzhiyun 		NULL,
541*4882a593Smuzhiyun 		0,
542*4882a593Smuzhiyun 		NULL,
543*4882a593Smuzhiyun 		LOAD_REJECT,
544*4882a593Smuzhiyun 	},
545*4882a593Smuzhiyun 	{
546*4882a593Smuzhiyun 		"recvmsg6: return code ok",
547*4882a593Smuzhiyun 		recvmsg_allow_prog_load,
548*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_RECVMSG,
549*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_RECVMSG,
550*4882a593Smuzhiyun 		AF_INET6,
551*4882a593Smuzhiyun 		SOCK_DGRAM,
552*4882a593Smuzhiyun 		NULL,
553*4882a593Smuzhiyun 		0,
554*4882a593Smuzhiyun 		NULL,
555*4882a593Smuzhiyun 		0,
556*4882a593Smuzhiyun 		NULL,
557*4882a593Smuzhiyun 		ATTACH_OKAY,
558*4882a593Smuzhiyun 	},
559*4882a593Smuzhiyun 	{
560*4882a593Smuzhiyun 		"recvmsg6: return code !ok",
561*4882a593Smuzhiyun 		recvmsg_deny_prog_load,
562*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_RECVMSG,
563*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_RECVMSG,
564*4882a593Smuzhiyun 		AF_INET6,
565*4882a593Smuzhiyun 		SOCK_DGRAM,
566*4882a593Smuzhiyun 		NULL,
567*4882a593Smuzhiyun 		0,
568*4882a593Smuzhiyun 		NULL,
569*4882a593Smuzhiyun 		0,
570*4882a593Smuzhiyun 		NULL,
571*4882a593Smuzhiyun 		LOAD_REJECT,
572*4882a593Smuzhiyun 	},
573*4882a593Smuzhiyun 	{
574*4882a593Smuzhiyun 		"recvmsg4: rewrite IP & port (asm)",
575*4882a593Smuzhiyun 		recvmsg4_rw_asm_prog_load,
576*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_RECVMSG,
577*4882a593Smuzhiyun 		BPF_CGROUP_UDP4_RECVMSG,
578*4882a593Smuzhiyun 		AF_INET,
579*4882a593Smuzhiyun 		SOCK_DGRAM,
580*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
581*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
582*4882a593Smuzhiyun 		SERV4_REWRITE_IP,
583*4882a593Smuzhiyun 		SERV4_REWRITE_PORT,
584*4882a593Smuzhiyun 		SERV4_IP,
585*4882a593Smuzhiyun 		SUCCESS,
586*4882a593Smuzhiyun 	},
587*4882a593Smuzhiyun 	{
588*4882a593Smuzhiyun 		"recvmsg6: rewrite IP & port (asm)",
589*4882a593Smuzhiyun 		recvmsg6_rw_asm_prog_load,
590*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_RECVMSG,
591*4882a593Smuzhiyun 		BPF_CGROUP_UDP6_RECVMSG,
592*4882a593Smuzhiyun 		AF_INET6,
593*4882a593Smuzhiyun 		SOCK_DGRAM,
594*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
595*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
596*4882a593Smuzhiyun 		SERV6_REWRITE_IP,
597*4882a593Smuzhiyun 		SERV6_REWRITE_PORT,
598*4882a593Smuzhiyun 		SERV6_IP,
599*4882a593Smuzhiyun 		SUCCESS,
600*4882a593Smuzhiyun 	},
601*4882a593Smuzhiyun };
602*4882a593Smuzhiyun 
mk_sockaddr(int domain,const char * ip,unsigned short port,struct sockaddr * addr,socklen_t addr_len)603*4882a593Smuzhiyun static int mk_sockaddr(int domain, const char *ip, unsigned short port,
604*4882a593Smuzhiyun 		       struct sockaddr *addr, socklen_t addr_len)
605*4882a593Smuzhiyun {
606*4882a593Smuzhiyun 	struct sockaddr_in6 *addr6;
607*4882a593Smuzhiyun 	struct sockaddr_in *addr4;
608*4882a593Smuzhiyun 
609*4882a593Smuzhiyun 	if (domain != AF_INET && domain != AF_INET6) {
610*4882a593Smuzhiyun 		log_err("Unsupported address family");
611*4882a593Smuzhiyun 		return -1;
612*4882a593Smuzhiyun 	}
613*4882a593Smuzhiyun 
614*4882a593Smuzhiyun 	memset(addr, 0, addr_len);
615*4882a593Smuzhiyun 
616*4882a593Smuzhiyun 	if (domain == AF_INET) {
617*4882a593Smuzhiyun 		if (addr_len < sizeof(struct sockaddr_in))
618*4882a593Smuzhiyun 			return -1;
619*4882a593Smuzhiyun 		addr4 = (struct sockaddr_in *)addr;
620*4882a593Smuzhiyun 		addr4->sin_family = domain;
621*4882a593Smuzhiyun 		addr4->sin_port = htons(port);
622*4882a593Smuzhiyun 		if (inet_pton(domain, ip, (void *)&addr4->sin_addr) != 1) {
623*4882a593Smuzhiyun 			log_err("Invalid IPv4: %s", ip);
624*4882a593Smuzhiyun 			return -1;
625*4882a593Smuzhiyun 		}
626*4882a593Smuzhiyun 	} else if (domain == AF_INET6) {
627*4882a593Smuzhiyun 		if (addr_len < sizeof(struct sockaddr_in6))
628*4882a593Smuzhiyun 			return -1;
629*4882a593Smuzhiyun 		addr6 = (struct sockaddr_in6 *)addr;
630*4882a593Smuzhiyun 		addr6->sin6_family = domain;
631*4882a593Smuzhiyun 		addr6->sin6_port = htons(port);
632*4882a593Smuzhiyun 		if (inet_pton(domain, ip, (void *)&addr6->sin6_addr) != 1) {
633*4882a593Smuzhiyun 			log_err("Invalid IPv6: %s", ip);
634*4882a593Smuzhiyun 			return -1;
635*4882a593Smuzhiyun 		}
636*4882a593Smuzhiyun 	}
637*4882a593Smuzhiyun 
638*4882a593Smuzhiyun 	return 0;
639*4882a593Smuzhiyun }
640*4882a593Smuzhiyun 
load_insns(const struct sock_addr_test * test,const struct bpf_insn * insns,size_t insns_cnt)641*4882a593Smuzhiyun static int load_insns(const struct sock_addr_test *test,
642*4882a593Smuzhiyun 		      const struct bpf_insn *insns, size_t insns_cnt)
643*4882a593Smuzhiyun {
644*4882a593Smuzhiyun 	struct bpf_load_program_attr load_attr;
645*4882a593Smuzhiyun 	int ret;
646*4882a593Smuzhiyun 
647*4882a593Smuzhiyun 	memset(&load_attr, 0, sizeof(struct bpf_load_program_attr));
648*4882a593Smuzhiyun 	load_attr.prog_type = BPF_PROG_TYPE_CGROUP_SOCK_ADDR;
649*4882a593Smuzhiyun 	load_attr.expected_attach_type = test->expected_attach_type;
650*4882a593Smuzhiyun 	load_attr.insns = insns;
651*4882a593Smuzhiyun 	load_attr.insns_cnt = insns_cnt;
652*4882a593Smuzhiyun 	load_attr.license = "GPL";
653*4882a593Smuzhiyun 
654*4882a593Smuzhiyun 	ret = bpf_load_program_xattr(&load_attr, bpf_log_buf, BPF_LOG_BUF_SIZE);
655*4882a593Smuzhiyun 	if (ret < 0 && test->expected_result != LOAD_REJECT) {
656*4882a593Smuzhiyun 		log_err(">>> Loading program error.\n"
657*4882a593Smuzhiyun 			">>> Verifier output:\n%s\n-------\n", bpf_log_buf);
658*4882a593Smuzhiyun 	}
659*4882a593Smuzhiyun 
660*4882a593Smuzhiyun 	return ret;
661*4882a593Smuzhiyun }
662*4882a593Smuzhiyun 
663*4882a593Smuzhiyun /* [1] These testing programs try to read different context fields, including
664*4882a593Smuzhiyun  * narrow loads of different sizes from user_ip4 and user_ip6, and write to
665*4882a593Smuzhiyun  * those allowed to be overridden.
666*4882a593Smuzhiyun  *
667*4882a593Smuzhiyun  * [2] BPF_LD_IMM64 & BPF_JMP_REG are used below whenever there is a need to
668*4882a593Smuzhiyun  * compare a register with unsigned 32bit integer. BPF_JMP_IMM can't be used
669*4882a593Smuzhiyun  * in such cases since it accepts only _signed_ 32bit integer as IMM
670*4882a593Smuzhiyun  * argument. Also note that BPF_LD_IMM64 contains 2 instructions what matters
671*4882a593Smuzhiyun  * to count jumps properly.
672*4882a593Smuzhiyun  */
673*4882a593Smuzhiyun 
bind4_prog_load(const struct sock_addr_test * test)674*4882a593Smuzhiyun static int bind4_prog_load(const struct sock_addr_test *test)
675*4882a593Smuzhiyun {
676*4882a593Smuzhiyun 	union {
677*4882a593Smuzhiyun 		uint8_t u4_addr8[4];
678*4882a593Smuzhiyun 		uint16_t u4_addr16[2];
679*4882a593Smuzhiyun 		uint32_t u4_addr32;
680*4882a593Smuzhiyun 	} ip4, port;
681*4882a593Smuzhiyun 	struct sockaddr_in addr4_rw;
682*4882a593Smuzhiyun 
683*4882a593Smuzhiyun 	if (inet_pton(AF_INET, SERV4_IP, (void *)&ip4) != 1) {
684*4882a593Smuzhiyun 		log_err("Invalid IPv4: %s", SERV4_IP);
685*4882a593Smuzhiyun 		return -1;
686*4882a593Smuzhiyun 	}
687*4882a593Smuzhiyun 
688*4882a593Smuzhiyun 	port.u4_addr32 = htons(SERV4_PORT);
689*4882a593Smuzhiyun 
690*4882a593Smuzhiyun 	if (mk_sockaddr(AF_INET, SERV4_REWRITE_IP, SERV4_REWRITE_PORT,
691*4882a593Smuzhiyun 			(struct sockaddr *)&addr4_rw, sizeof(addr4_rw)) == -1)
692*4882a593Smuzhiyun 		return -1;
693*4882a593Smuzhiyun 
694*4882a593Smuzhiyun 	/* See [1]. */
695*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
696*4882a593Smuzhiyun 		BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
697*4882a593Smuzhiyun 
698*4882a593Smuzhiyun 		/* if (sk.family == AF_INET && */
699*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
700*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, family)),
701*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, AF_INET, 32),
702*4882a593Smuzhiyun 
703*4882a593Smuzhiyun 		/*     (sk.type == SOCK_DGRAM || sk.type == SOCK_STREAM) && */
704*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
705*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, type)),
706*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, SOCK_DGRAM, 1),
707*4882a593Smuzhiyun 		BPF_JMP_A(1),
708*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, SOCK_STREAM, 28),
709*4882a593Smuzhiyun 
710*4882a593Smuzhiyun 		/*     1st_byte_of_user_ip4 == expected && */
711*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_B, BPF_REG_7, BPF_REG_6,
712*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4)),
713*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip4.u4_addr8[0], 26),
714*4882a593Smuzhiyun 
715*4882a593Smuzhiyun 		/*     2nd_byte_of_user_ip4 == expected && */
716*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_B, BPF_REG_7, BPF_REG_6,
717*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4) + 1),
718*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip4.u4_addr8[1], 24),
719*4882a593Smuzhiyun 
720*4882a593Smuzhiyun 		/*     3rd_byte_of_user_ip4 == expected && */
721*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_B, BPF_REG_7, BPF_REG_6,
722*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4) + 2),
723*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip4.u4_addr8[2], 22),
724*4882a593Smuzhiyun 
725*4882a593Smuzhiyun 		/*     4th_byte_of_user_ip4 == expected && */
726*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_B, BPF_REG_7, BPF_REG_6,
727*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4) + 3),
728*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip4.u4_addr8[3], 20),
729*4882a593Smuzhiyun 
730*4882a593Smuzhiyun 		/*     1st_half_of_user_ip4 == expected && */
731*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_H, BPF_REG_7, BPF_REG_6,
732*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4)),
733*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip4.u4_addr16[0], 18),
734*4882a593Smuzhiyun 
735*4882a593Smuzhiyun 		/*     2nd_half_of_user_ip4 == expected && */
736*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_H, BPF_REG_7, BPF_REG_6,
737*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4) + 2),
738*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip4.u4_addr16[1], 16),
739*4882a593Smuzhiyun 
740*4882a593Smuzhiyun 		/*     whole_user_ip4 == expected && */
741*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
742*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4)),
743*4882a593Smuzhiyun 		BPF_LD_IMM64(BPF_REG_8, ip4.u4_addr32), /* See [2]. */
744*4882a593Smuzhiyun 		BPF_JMP_REG(BPF_JNE, BPF_REG_7, BPF_REG_8, 12),
745*4882a593Smuzhiyun 
746*4882a593Smuzhiyun 		/*     1st_byte_of_user_port == expected && */
747*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_B, BPF_REG_7, BPF_REG_6,
748*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
749*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, port.u4_addr8[0], 10),
750*4882a593Smuzhiyun 
751*4882a593Smuzhiyun 		/*     1st_half_of_user_port == expected && */
752*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_H, BPF_REG_7, BPF_REG_6,
753*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
754*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, port.u4_addr16[0], 8),
755*4882a593Smuzhiyun 
756*4882a593Smuzhiyun 		/*     user_port == expected) { */
757*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
758*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
759*4882a593Smuzhiyun 		BPF_LD_IMM64(BPF_REG_8, port.u4_addr32), /* See [2]. */
760*4882a593Smuzhiyun 		BPF_JMP_REG(BPF_JNE, BPF_REG_7, BPF_REG_8, 4),
761*4882a593Smuzhiyun 
762*4882a593Smuzhiyun 		/*      user_ip4 = addr4_rw.sin_addr */
763*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, addr4_rw.sin_addr.s_addr),
764*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
765*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4)),
766*4882a593Smuzhiyun 
767*4882a593Smuzhiyun 		/*      user_port = addr4_rw.sin_port */
768*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, addr4_rw.sin_port),
769*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
770*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
771*4882a593Smuzhiyun 		/* } */
772*4882a593Smuzhiyun 
773*4882a593Smuzhiyun 		/* return 1 */
774*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, 1),
775*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
776*4882a593Smuzhiyun 	};
777*4882a593Smuzhiyun 
778*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
779*4882a593Smuzhiyun }
780*4882a593Smuzhiyun 
bind6_prog_load(const struct sock_addr_test * test)781*4882a593Smuzhiyun static int bind6_prog_load(const struct sock_addr_test *test)
782*4882a593Smuzhiyun {
783*4882a593Smuzhiyun 	struct sockaddr_in6 addr6_rw;
784*4882a593Smuzhiyun 	struct in6_addr ip6;
785*4882a593Smuzhiyun 
786*4882a593Smuzhiyun 	if (inet_pton(AF_INET6, SERV6_IP, (void *)&ip6) != 1) {
787*4882a593Smuzhiyun 		log_err("Invalid IPv6: %s", SERV6_IP);
788*4882a593Smuzhiyun 		return -1;
789*4882a593Smuzhiyun 	}
790*4882a593Smuzhiyun 
791*4882a593Smuzhiyun 	if (mk_sockaddr(AF_INET6, SERV6_REWRITE_IP, SERV6_REWRITE_PORT,
792*4882a593Smuzhiyun 			(struct sockaddr *)&addr6_rw, sizeof(addr6_rw)) == -1)
793*4882a593Smuzhiyun 		return -1;
794*4882a593Smuzhiyun 
795*4882a593Smuzhiyun 	/* See [1]. */
796*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
797*4882a593Smuzhiyun 		BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
798*4882a593Smuzhiyun 
799*4882a593Smuzhiyun 		/* if (sk.family == AF_INET6 && */
800*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
801*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, family)),
802*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, AF_INET6, 18),
803*4882a593Smuzhiyun 
804*4882a593Smuzhiyun 		/*            5th_byte_of_user_ip6 == expected && */
805*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_B, BPF_REG_7, BPF_REG_6,
806*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip6[1])),
807*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip6.s6_addr[4], 16),
808*4882a593Smuzhiyun 
809*4882a593Smuzhiyun 		/*            3rd_half_of_user_ip6 == expected && */
810*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_H, BPF_REG_7, BPF_REG_6,
811*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip6[1])),
812*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, ip6.s6_addr16[2], 14),
813*4882a593Smuzhiyun 
814*4882a593Smuzhiyun 		/*            last_word_of_user_ip6 == expected) { */
815*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
816*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip6[3])),
817*4882a593Smuzhiyun 		BPF_LD_IMM64(BPF_REG_8, ip6.s6_addr32[3]),  /* See [2]. */
818*4882a593Smuzhiyun 		BPF_JMP_REG(BPF_JNE, BPF_REG_7, BPF_REG_8, 10),
819*4882a593Smuzhiyun 
820*4882a593Smuzhiyun 
821*4882a593Smuzhiyun #define STORE_IPV6_WORD(N)						       \
822*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, addr6_rw.sin6_addr.s6_addr32[N]),     \
823*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,		       \
824*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip6[N]))
825*4882a593Smuzhiyun 
826*4882a593Smuzhiyun 		/*      user_ip6 = addr6_rw.sin6_addr */
827*4882a593Smuzhiyun 		STORE_IPV6_WORD(0),
828*4882a593Smuzhiyun 		STORE_IPV6_WORD(1),
829*4882a593Smuzhiyun 		STORE_IPV6_WORD(2),
830*4882a593Smuzhiyun 		STORE_IPV6_WORD(3),
831*4882a593Smuzhiyun 
832*4882a593Smuzhiyun 		/*      user_port = addr6_rw.sin6_port */
833*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, addr6_rw.sin6_port),
834*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
835*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
836*4882a593Smuzhiyun 
837*4882a593Smuzhiyun 		/* } */
838*4882a593Smuzhiyun 
839*4882a593Smuzhiyun 		/* return 1 */
840*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, 1),
841*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
842*4882a593Smuzhiyun 	};
843*4882a593Smuzhiyun 
844*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
845*4882a593Smuzhiyun }
846*4882a593Smuzhiyun 
load_path(const struct sock_addr_test * test,const char * path)847*4882a593Smuzhiyun static int load_path(const struct sock_addr_test *test, const char *path)
848*4882a593Smuzhiyun {
849*4882a593Smuzhiyun 	struct bpf_prog_load_attr attr;
850*4882a593Smuzhiyun 	struct bpf_object *obj;
851*4882a593Smuzhiyun 	int prog_fd;
852*4882a593Smuzhiyun 
853*4882a593Smuzhiyun 	memset(&attr, 0, sizeof(struct bpf_prog_load_attr));
854*4882a593Smuzhiyun 	attr.file = path;
855*4882a593Smuzhiyun 	attr.prog_type = BPF_PROG_TYPE_CGROUP_SOCK_ADDR;
856*4882a593Smuzhiyun 	attr.expected_attach_type = test->expected_attach_type;
857*4882a593Smuzhiyun 	attr.prog_flags = BPF_F_TEST_RND_HI32;
858*4882a593Smuzhiyun 
859*4882a593Smuzhiyun 	if (bpf_prog_load_xattr(&attr, &obj, &prog_fd)) {
860*4882a593Smuzhiyun 		if (test->expected_result != LOAD_REJECT)
861*4882a593Smuzhiyun 			log_err(">>> Loading program (%s) error.\n", path);
862*4882a593Smuzhiyun 		return -1;
863*4882a593Smuzhiyun 	}
864*4882a593Smuzhiyun 
865*4882a593Smuzhiyun 	return prog_fd;
866*4882a593Smuzhiyun }
867*4882a593Smuzhiyun 
connect4_prog_load(const struct sock_addr_test * test)868*4882a593Smuzhiyun static int connect4_prog_load(const struct sock_addr_test *test)
869*4882a593Smuzhiyun {
870*4882a593Smuzhiyun 	return load_path(test, CONNECT4_PROG_PATH);
871*4882a593Smuzhiyun }
872*4882a593Smuzhiyun 
connect6_prog_load(const struct sock_addr_test * test)873*4882a593Smuzhiyun static int connect6_prog_load(const struct sock_addr_test *test)
874*4882a593Smuzhiyun {
875*4882a593Smuzhiyun 	return load_path(test, CONNECT6_PROG_PATH);
876*4882a593Smuzhiyun }
877*4882a593Smuzhiyun 
xmsg_ret_only_prog_load(const struct sock_addr_test * test,int32_t rc)878*4882a593Smuzhiyun static int xmsg_ret_only_prog_load(const struct sock_addr_test *test,
879*4882a593Smuzhiyun 				   int32_t rc)
880*4882a593Smuzhiyun {
881*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
882*4882a593Smuzhiyun 		/* return rc */
883*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, rc),
884*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
885*4882a593Smuzhiyun 	};
886*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
887*4882a593Smuzhiyun }
888*4882a593Smuzhiyun 
sendmsg_allow_prog_load(const struct sock_addr_test * test)889*4882a593Smuzhiyun static int sendmsg_allow_prog_load(const struct sock_addr_test *test)
890*4882a593Smuzhiyun {
891*4882a593Smuzhiyun 	return xmsg_ret_only_prog_load(test, /*rc*/ 1);
892*4882a593Smuzhiyun }
893*4882a593Smuzhiyun 
sendmsg_deny_prog_load(const struct sock_addr_test * test)894*4882a593Smuzhiyun static int sendmsg_deny_prog_load(const struct sock_addr_test *test)
895*4882a593Smuzhiyun {
896*4882a593Smuzhiyun 	return xmsg_ret_only_prog_load(test, /*rc*/ 0);
897*4882a593Smuzhiyun }
898*4882a593Smuzhiyun 
recvmsg_allow_prog_load(const struct sock_addr_test * test)899*4882a593Smuzhiyun static int recvmsg_allow_prog_load(const struct sock_addr_test *test)
900*4882a593Smuzhiyun {
901*4882a593Smuzhiyun 	return xmsg_ret_only_prog_load(test, /*rc*/ 1);
902*4882a593Smuzhiyun }
903*4882a593Smuzhiyun 
recvmsg_deny_prog_load(const struct sock_addr_test * test)904*4882a593Smuzhiyun static int recvmsg_deny_prog_load(const struct sock_addr_test *test)
905*4882a593Smuzhiyun {
906*4882a593Smuzhiyun 	return xmsg_ret_only_prog_load(test, /*rc*/ 0);
907*4882a593Smuzhiyun }
908*4882a593Smuzhiyun 
sendmsg4_rw_asm_prog_load(const struct sock_addr_test * test)909*4882a593Smuzhiyun static int sendmsg4_rw_asm_prog_load(const struct sock_addr_test *test)
910*4882a593Smuzhiyun {
911*4882a593Smuzhiyun 	struct sockaddr_in dst4_rw_addr;
912*4882a593Smuzhiyun 	struct in_addr src4_rw_ip;
913*4882a593Smuzhiyun 
914*4882a593Smuzhiyun 	if (inet_pton(AF_INET, SRC4_REWRITE_IP, (void *)&src4_rw_ip) != 1) {
915*4882a593Smuzhiyun 		log_err("Invalid IPv4: %s", SRC4_REWRITE_IP);
916*4882a593Smuzhiyun 		return -1;
917*4882a593Smuzhiyun 	}
918*4882a593Smuzhiyun 
919*4882a593Smuzhiyun 	if (mk_sockaddr(AF_INET, SERV4_REWRITE_IP, SERV4_REWRITE_PORT,
920*4882a593Smuzhiyun 			(struct sockaddr *)&dst4_rw_addr,
921*4882a593Smuzhiyun 			sizeof(dst4_rw_addr)) == -1)
922*4882a593Smuzhiyun 		return -1;
923*4882a593Smuzhiyun 
924*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
925*4882a593Smuzhiyun 		BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
926*4882a593Smuzhiyun 
927*4882a593Smuzhiyun 		/* if (sk.family == AF_INET && */
928*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
929*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, family)),
930*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, AF_INET, 8),
931*4882a593Smuzhiyun 
932*4882a593Smuzhiyun 		/*     sk.type == SOCK_DGRAM)  { */
933*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
934*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, type)),
935*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, SOCK_DGRAM, 6),
936*4882a593Smuzhiyun 
937*4882a593Smuzhiyun 		/*      msg_src_ip4 = src4_rw_ip */
938*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, src4_rw_ip.s_addr),
939*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
940*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, msg_src_ip4)),
941*4882a593Smuzhiyun 
942*4882a593Smuzhiyun 		/*      user_ip4 = dst4_rw_addr.sin_addr */
943*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, dst4_rw_addr.sin_addr.s_addr),
944*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
945*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4)),
946*4882a593Smuzhiyun 
947*4882a593Smuzhiyun 		/*      user_port = dst4_rw_addr.sin_port */
948*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, dst4_rw_addr.sin_port),
949*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
950*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
951*4882a593Smuzhiyun 		/* } */
952*4882a593Smuzhiyun 
953*4882a593Smuzhiyun 		/* return 1 */
954*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, 1),
955*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
956*4882a593Smuzhiyun 	};
957*4882a593Smuzhiyun 
958*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
959*4882a593Smuzhiyun }
960*4882a593Smuzhiyun 
recvmsg4_rw_asm_prog_load(const struct sock_addr_test * test)961*4882a593Smuzhiyun static int recvmsg4_rw_asm_prog_load(const struct sock_addr_test *test)
962*4882a593Smuzhiyun {
963*4882a593Smuzhiyun 	struct sockaddr_in src4_rw_addr;
964*4882a593Smuzhiyun 
965*4882a593Smuzhiyun 	if (mk_sockaddr(AF_INET, SERV4_IP, SERV4_PORT,
966*4882a593Smuzhiyun 			(struct sockaddr *)&src4_rw_addr,
967*4882a593Smuzhiyun 			sizeof(src4_rw_addr)) == -1)
968*4882a593Smuzhiyun 		return -1;
969*4882a593Smuzhiyun 
970*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
971*4882a593Smuzhiyun 		BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
972*4882a593Smuzhiyun 
973*4882a593Smuzhiyun 		/* if (sk.family == AF_INET && */
974*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
975*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, family)),
976*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, AF_INET, 6),
977*4882a593Smuzhiyun 
978*4882a593Smuzhiyun 		/*     sk.type == SOCK_DGRAM)  { */
979*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
980*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, type)),
981*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, SOCK_DGRAM, 4),
982*4882a593Smuzhiyun 
983*4882a593Smuzhiyun 		/*      user_ip4 = src4_rw_addr.sin_addr */
984*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, src4_rw_addr.sin_addr.s_addr),
985*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
986*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_ip4)),
987*4882a593Smuzhiyun 
988*4882a593Smuzhiyun 		/*      user_port = src4_rw_addr.sin_port */
989*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, src4_rw_addr.sin_port),
990*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
991*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
992*4882a593Smuzhiyun 		/* } */
993*4882a593Smuzhiyun 
994*4882a593Smuzhiyun 		/* return 1 */
995*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, 1),
996*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
997*4882a593Smuzhiyun 	};
998*4882a593Smuzhiyun 
999*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
1000*4882a593Smuzhiyun }
1001*4882a593Smuzhiyun 
sendmsg4_rw_c_prog_load(const struct sock_addr_test * test)1002*4882a593Smuzhiyun static int sendmsg4_rw_c_prog_load(const struct sock_addr_test *test)
1003*4882a593Smuzhiyun {
1004*4882a593Smuzhiyun 	return load_path(test, SENDMSG4_PROG_PATH);
1005*4882a593Smuzhiyun }
1006*4882a593Smuzhiyun 
sendmsg6_rw_dst_asm_prog_load(const struct sock_addr_test * test,const char * rw_dst_ip)1007*4882a593Smuzhiyun static int sendmsg6_rw_dst_asm_prog_load(const struct sock_addr_test *test,
1008*4882a593Smuzhiyun 					 const char *rw_dst_ip)
1009*4882a593Smuzhiyun {
1010*4882a593Smuzhiyun 	struct sockaddr_in6 dst6_rw_addr;
1011*4882a593Smuzhiyun 	struct in6_addr src6_rw_ip;
1012*4882a593Smuzhiyun 
1013*4882a593Smuzhiyun 	if (inet_pton(AF_INET6, SRC6_REWRITE_IP, (void *)&src6_rw_ip) != 1) {
1014*4882a593Smuzhiyun 		log_err("Invalid IPv6: %s", SRC6_REWRITE_IP);
1015*4882a593Smuzhiyun 		return -1;
1016*4882a593Smuzhiyun 	}
1017*4882a593Smuzhiyun 
1018*4882a593Smuzhiyun 	if (mk_sockaddr(AF_INET6, rw_dst_ip, SERV6_REWRITE_PORT,
1019*4882a593Smuzhiyun 			(struct sockaddr *)&dst6_rw_addr,
1020*4882a593Smuzhiyun 			sizeof(dst6_rw_addr)) == -1)
1021*4882a593Smuzhiyun 		return -1;
1022*4882a593Smuzhiyun 
1023*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
1024*4882a593Smuzhiyun 		BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
1025*4882a593Smuzhiyun 
1026*4882a593Smuzhiyun 		/* if (sk.family == AF_INET6) { */
1027*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
1028*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, family)),
1029*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, AF_INET6, 18),
1030*4882a593Smuzhiyun 
1031*4882a593Smuzhiyun #define STORE_IPV6_WORD_N(DST, SRC, N)					       \
1032*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, SRC[N]),			       \
1033*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,		       \
1034*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, DST[N]))
1035*4882a593Smuzhiyun 
1036*4882a593Smuzhiyun #define STORE_IPV6(DST, SRC)						       \
1037*4882a593Smuzhiyun 		STORE_IPV6_WORD_N(DST, SRC, 0),				       \
1038*4882a593Smuzhiyun 		STORE_IPV6_WORD_N(DST, SRC, 1),				       \
1039*4882a593Smuzhiyun 		STORE_IPV6_WORD_N(DST, SRC, 2),				       \
1040*4882a593Smuzhiyun 		STORE_IPV6_WORD_N(DST, SRC, 3)
1041*4882a593Smuzhiyun 
1042*4882a593Smuzhiyun 		STORE_IPV6(msg_src_ip6, src6_rw_ip.s6_addr32),
1043*4882a593Smuzhiyun 		STORE_IPV6(user_ip6, dst6_rw_addr.sin6_addr.s6_addr32),
1044*4882a593Smuzhiyun 
1045*4882a593Smuzhiyun 		/*      user_port = dst6_rw_addr.sin6_port */
1046*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, dst6_rw_addr.sin6_port),
1047*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
1048*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
1049*4882a593Smuzhiyun 
1050*4882a593Smuzhiyun 		/* } */
1051*4882a593Smuzhiyun 
1052*4882a593Smuzhiyun 		/* return 1 */
1053*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, 1),
1054*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
1055*4882a593Smuzhiyun 	};
1056*4882a593Smuzhiyun 
1057*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
1058*4882a593Smuzhiyun }
1059*4882a593Smuzhiyun 
sendmsg6_rw_asm_prog_load(const struct sock_addr_test * test)1060*4882a593Smuzhiyun static int sendmsg6_rw_asm_prog_load(const struct sock_addr_test *test)
1061*4882a593Smuzhiyun {
1062*4882a593Smuzhiyun 	return sendmsg6_rw_dst_asm_prog_load(test, SERV6_REWRITE_IP);
1063*4882a593Smuzhiyun }
1064*4882a593Smuzhiyun 
recvmsg6_rw_asm_prog_load(const struct sock_addr_test * test)1065*4882a593Smuzhiyun static int recvmsg6_rw_asm_prog_load(const struct sock_addr_test *test)
1066*4882a593Smuzhiyun {
1067*4882a593Smuzhiyun 	struct sockaddr_in6 src6_rw_addr;
1068*4882a593Smuzhiyun 
1069*4882a593Smuzhiyun 	if (mk_sockaddr(AF_INET6, SERV6_IP, SERV6_PORT,
1070*4882a593Smuzhiyun 			(struct sockaddr *)&src6_rw_addr,
1071*4882a593Smuzhiyun 			sizeof(src6_rw_addr)) == -1)
1072*4882a593Smuzhiyun 		return -1;
1073*4882a593Smuzhiyun 
1074*4882a593Smuzhiyun 	struct bpf_insn insns[] = {
1075*4882a593Smuzhiyun 		BPF_MOV64_REG(BPF_REG_6, BPF_REG_1),
1076*4882a593Smuzhiyun 
1077*4882a593Smuzhiyun 		/* if (sk.family == AF_INET6) { */
1078*4882a593Smuzhiyun 		BPF_LDX_MEM(BPF_W, BPF_REG_7, BPF_REG_6,
1079*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, family)),
1080*4882a593Smuzhiyun 		BPF_JMP_IMM(BPF_JNE, BPF_REG_7, AF_INET6, 10),
1081*4882a593Smuzhiyun 
1082*4882a593Smuzhiyun 		STORE_IPV6(user_ip6, src6_rw_addr.sin6_addr.s6_addr32),
1083*4882a593Smuzhiyun 
1084*4882a593Smuzhiyun 		/*      user_port = dst6_rw_addr.sin6_port */
1085*4882a593Smuzhiyun 		BPF_MOV32_IMM(BPF_REG_7, src6_rw_addr.sin6_port),
1086*4882a593Smuzhiyun 		BPF_STX_MEM(BPF_W, BPF_REG_6, BPF_REG_7,
1087*4882a593Smuzhiyun 			    offsetof(struct bpf_sock_addr, user_port)),
1088*4882a593Smuzhiyun 		/* } */
1089*4882a593Smuzhiyun 
1090*4882a593Smuzhiyun 		/* return 1 */
1091*4882a593Smuzhiyun 		BPF_MOV64_IMM(BPF_REG_0, 1),
1092*4882a593Smuzhiyun 		BPF_EXIT_INSN(),
1093*4882a593Smuzhiyun 	};
1094*4882a593Smuzhiyun 
1095*4882a593Smuzhiyun 	return load_insns(test, insns, sizeof(insns) / sizeof(struct bpf_insn));
1096*4882a593Smuzhiyun }
1097*4882a593Smuzhiyun 
sendmsg6_rw_v4mapped_prog_load(const struct sock_addr_test * test)1098*4882a593Smuzhiyun static int sendmsg6_rw_v4mapped_prog_load(const struct sock_addr_test *test)
1099*4882a593Smuzhiyun {
1100*4882a593Smuzhiyun 	return sendmsg6_rw_dst_asm_prog_load(test, SERV6_V4MAPPED_IP);
1101*4882a593Smuzhiyun }
1102*4882a593Smuzhiyun 
sendmsg6_rw_wildcard_prog_load(const struct sock_addr_test * test)1103*4882a593Smuzhiyun static int sendmsg6_rw_wildcard_prog_load(const struct sock_addr_test *test)
1104*4882a593Smuzhiyun {
1105*4882a593Smuzhiyun 	return sendmsg6_rw_dst_asm_prog_load(test, WILDCARD6_IP);
1106*4882a593Smuzhiyun }
1107*4882a593Smuzhiyun 
sendmsg6_rw_c_prog_load(const struct sock_addr_test * test)1108*4882a593Smuzhiyun static int sendmsg6_rw_c_prog_load(const struct sock_addr_test *test)
1109*4882a593Smuzhiyun {
1110*4882a593Smuzhiyun 	return load_path(test, SENDMSG6_PROG_PATH);
1111*4882a593Smuzhiyun }
1112*4882a593Smuzhiyun 
cmp_addr(const struct sockaddr_storage * addr1,const struct sockaddr_storage * addr2,int cmp_port)1113*4882a593Smuzhiyun static int cmp_addr(const struct sockaddr_storage *addr1,
1114*4882a593Smuzhiyun 		    const struct sockaddr_storage *addr2, int cmp_port)
1115*4882a593Smuzhiyun {
1116*4882a593Smuzhiyun 	const struct sockaddr_in *four1, *four2;
1117*4882a593Smuzhiyun 	const struct sockaddr_in6 *six1, *six2;
1118*4882a593Smuzhiyun 
1119*4882a593Smuzhiyun 	if (addr1->ss_family != addr2->ss_family)
1120*4882a593Smuzhiyun 		return -1;
1121*4882a593Smuzhiyun 
1122*4882a593Smuzhiyun 	if (addr1->ss_family == AF_INET) {
1123*4882a593Smuzhiyun 		four1 = (const struct sockaddr_in *)addr1;
1124*4882a593Smuzhiyun 		four2 = (const struct sockaddr_in *)addr2;
1125*4882a593Smuzhiyun 		return !((four1->sin_port == four2->sin_port || !cmp_port) &&
1126*4882a593Smuzhiyun 			 four1->sin_addr.s_addr == four2->sin_addr.s_addr);
1127*4882a593Smuzhiyun 	} else if (addr1->ss_family == AF_INET6) {
1128*4882a593Smuzhiyun 		six1 = (const struct sockaddr_in6 *)addr1;
1129*4882a593Smuzhiyun 		six2 = (const struct sockaddr_in6 *)addr2;
1130*4882a593Smuzhiyun 		return !((six1->sin6_port == six2->sin6_port || !cmp_port) &&
1131*4882a593Smuzhiyun 			 !memcmp(&six1->sin6_addr, &six2->sin6_addr,
1132*4882a593Smuzhiyun 				 sizeof(struct in6_addr)));
1133*4882a593Smuzhiyun 	}
1134*4882a593Smuzhiyun 
1135*4882a593Smuzhiyun 	return -1;
1136*4882a593Smuzhiyun }
1137*4882a593Smuzhiyun 
cmp_sock_addr(info_fn fn,int sock1,const struct sockaddr_storage * addr2,int cmp_port)1138*4882a593Smuzhiyun static int cmp_sock_addr(info_fn fn, int sock1,
1139*4882a593Smuzhiyun 			 const struct sockaddr_storage *addr2, int cmp_port)
1140*4882a593Smuzhiyun {
1141*4882a593Smuzhiyun 	struct sockaddr_storage addr1;
1142*4882a593Smuzhiyun 	socklen_t len1 = sizeof(addr1);
1143*4882a593Smuzhiyun 
1144*4882a593Smuzhiyun 	memset(&addr1, 0, len1);
1145*4882a593Smuzhiyun 	if (fn(sock1, (struct sockaddr *)&addr1, (socklen_t *)&len1) != 0)
1146*4882a593Smuzhiyun 		return -1;
1147*4882a593Smuzhiyun 
1148*4882a593Smuzhiyun 	return cmp_addr(&addr1, addr2, cmp_port);
1149*4882a593Smuzhiyun }
1150*4882a593Smuzhiyun 
cmp_local_ip(int sock1,const struct sockaddr_storage * addr2)1151*4882a593Smuzhiyun static int cmp_local_ip(int sock1, const struct sockaddr_storage *addr2)
1152*4882a593Smuzhiyun {
1153*4882a593Smuzhiyun 	return cmp_sock_addr(getsockname, sock1, addr2, /*cmp_port*/ 0);
1154*4882a593Smuzhiyun }
1155*4882a593Smuzhiyun 
cmp_local_addr(int sock1,const struct sockaddr_storage * addr2)1156*4882a593Smuzhiyun static int cmp_local_addr(int sock1, const struct sockaddr_storage *addr2)
1157*4882a593Smuzhiyun {
1158*4882a593Smuzhiyun 	return cmp_sock_addr(getsockname, sock1, addr2, /*cmp_port*/ 1);
1159*4882a593Smuzhiyun }
1160*4882a593Smuzhiyun 
cmp_peer_addr(int sock1,const struct sockaddr_storage * addr2)1161*4882a593Smuzhiyun static int cmp_peer_addr(int sock1, const struct sockaddr_storage *addr2)
1162*4882a593Smuzhiyun {
1163*4882a593Smuzhiyun 	return cmp_sock_addr(getpeername, sock1, addr2, /*cmp_port*/ 1);
1164*4882a593Smuzhiyun }
1165*4882a593Smuzhiyun 
start_server(int type,const struct sockaddr_storage * addr,socklen_t addr_len)1166*4882a593Smuzhiyun static int start_server(int type, const struct sockaddr_storage *addr,
1167*4882a593Smuzhiyun 			socklen_t addr_len)
1168*4882a593Smuzhiyun {
1169*4882a593Smuzhiyun 	int fd;
1170*4882a593Smuzhiyun 
1171*4882a593Smuzhiyun 	fd = socket(addr->ss_family, type, 0);
1172*4882a593Smuzhiyun 	if (fd == -1) {
1173*4882a593Smuzhiyun 		log_err("Failed to create server socket");
1174*4882a593Smuzhiyun 		goto out;
1175*4882a593Smuzhiyun 	}
1176*4882a593Smuzhiyun 
1177*4882a593Smuzhiyun 	if (bind(fd, (const struct sockaddr *)addr, addr_len) == -1) {
1178*4882a593Smuzhiyun 		log_err("Failed to bind server socket");
1179*4882a593Smuzhiyun 		goto close_out;
1180*4882a593Smuzhiyun 	}
1181*4882a593Smuzhiyun 
1182*4882a593Smuzhiyun 	if (type == SOCK_STREAM) {
1183*4882a593Smuzhiyun 		if (listen(fd, 128) == -1) {
1184*4882a593Smuzhiyun 			log_err("Failed to listen on server socket");
1185*4882a593Smuzhiyun 			goto close_out;
1186*4882a593Smuzhiyun 		}
1187*4882a593Smuzhiyun 	}
1188*4882a593Smuzhiyun 
1189*4882a593Smuzhiyun 	goto out;
1190*4882a593Smuzhiyun close_out:
1191*4882a593Smuzhiyun 	close(fd);
1192*4882a593Smuzhiyun 	fd = -1;
1193*4882a593Smuzhiyun out:
1194*4882a593Smuzhiyun 	return fd;
1195*4882a593Smuzhiyun }
1196*4882a593Smuzhiyun 
connect_to_server(int type,const struct sockaddr_storage * addr,socklen_t addr_len)1197*4882a593Smuzhiyun static int connect_to_server(int type, const struct sockaddr_storage *addr,
1198*4882a593Smuzhiyun 			     socklen_t addr_len)
1199*4882a593Smuzhiyun {
1200*4882a593Smuzhiyun 	int domain;
1201*4882a593Smuzhiyun 	int fd = -1;
1202*4882a593Smuzhiyun 
1203*4882a593Smuzhiyun 	domain = addr->ss_family;
1204*4882a593Smuzhiyun 
1205*4882a593Smuzhiyun 	if (domain != AF_INET && domain != AF_INET6) {
1206*4882a593Smuzhiyun 		log_err("Unsupported address family");
1207*4882a593Smuzhiyun 		goto err;
1208*4882a593Smuzhiyun 	}
1209*4882a593Smuzhiyun 
1210*4882a593Smuzhiyun 	fd = socket(domain, type, 0);
1211*4882a593Smuzhiyun 	if (fd == -1) {
1212*4882a593Smuzhiyun 		log_err("Failed to create client socket");
1213*4882a593Smuzhiyun 		goto err;
1214*4882a593Smuzhiyun 	}
1215*4882a593Smuzhiyun 
1216*4882a593Smuzhiyun 	if (connect(fd, (const struct sockaddr *)addr, addr_len) == -1) {
1217*4882a593Smuzhiyun 		log_err("Fail to connect to server");
1218*4882a593Smuzhiyun 		goto err;
1219*4882a593Smuzhiyun 	}
1220*4882a593Smuzhiyun 
1221*4882a593Smuzhiyun 	goto out;
1222*4882a593Smuzhiyun err:
1223*4882a593Smuzhiyun 	close(fd);
1224*4882a593Smuzhiyun 	fd = -1;
1225*4882a593Smuzhiyun out:
1226*4882a593Smuzhiyun 	return fd;
1227*4882a593Smuzhiyun }
1228*4882a593Smuzhiyun 
init_pktinfo(int domain,struct cmsghdr * cmsg)1229*4882a593Smuzhiyun int init_pktinfo(int domain, struct cmsghdr *cmsg)
1230*4882a593Smuzhiyun {
1231*4882a593Smuzhiyun 	struct in6_pktinfo *pktinfo6;
1232*4882a593Smuzhiyun 	struct in_pktinfo *pktinfo4;
1233*4882a593Smuzhiyun 
1234*4882a593Smuzhiyun 	if (domain == AF_INET) {
1235*4882a593Smuzhiyun 		cmsg->cmsg_level = SOL_IP;
1236*4882a593Smuzhiyun 		cmsg->cmsg_type = IP_PKTINFO;
1237*4882a593Smuzhiyun 		cmsg->cmsg_len = CMSG_LEN(sizeof(struct in_pktinfo));
1238*4882a593Smuzhiyun 		pktinfo4 = (struct in_pktinfo *)CMSG_DATA(cmsg);
1239*4882a593Smuzhiyun 		memset(pktinfo4, 0, sizeof(struct in_pktinfo));
1240*4882a593Smuzhiyun 		if (inet_pton(domain, SRC4_IP,
1241*4882a593Smuzhiyun 			      (void *)&pktinfo4->ipi_spec_dst) != 1)
1242*4882a593Smuzhiyun 			return -1;
1243*4882a593Smuzhiyun 	} else if (domain == AF_INET6) {
1244*4882a593Smuzhiyun 		cmsg->cmsg_level = SOL_IPV6;
1245*4882a593Smuzhiyun 		cmsg->cmsg_type = IPV6_PKTINFO;
1246*4882a593Smuzhiyun 		cmsg->cmsg_len = CMSG_LEN(sizeof(struct in6_pktinfo));
1247*4882a593Smuzhiyun 		pktinfo6 = (struct in6_pktinfo *)CMSG_DATA(cmsg);
1248*4882a593Smuzhiyun 		memset(pktinfo6, 0, sizeof(struct in6_pktinfo));
1249*4882a593Smuzhiyun 		if (inet_pton(domain, SRC6_IP,
1250*4882a593Smuzhiyun 			      (void *)&pktinfo6->ipi6_addr) != 1)
1251*4882a593Smuzhiyun 			return -1;
1252*4882a593Smuzhiyun 	} else {
1253*4882a593Smuzhiyun 		return -1;
1254*4882a593Smuzhiyun 	}
1255*4882a593Smuzhiyun 
1256*4882a593Smuzhiyun 	return 0;
1257*4882a593Smuzhiyun }
1258*4882a593Smuzhiyun 
sendmsg_to_server(int type,const struct sockaddr_storage * addr,socklen_t addr_len,int set_cmsg,int flags,int * syscall_err)1259*4882a593Smuzhiyun static int sendmsg_to_server(int type, const struct sockaddr_storage *addr,
1260*4882a593Smuzhiyun 			     socklen_t addr_len, int set_cmsg, int flags,
1261*4882a593Smuzhiyun 			     int *syscall_err)
1262*4882a593Smuzhiyun {
1263*4882a593Smuzhiyun 	union {
1264*4882a593Smuzhiyun 		char buf[CMSG_SPACE(sizeof(struct in6_pktinfo))];
1265*4882a593Smuzhiyun 		struct cmsghdr align;
1266*4882a593Smuzhiyun 	} control6;
1267*4882a593Smuzhiyun 	union {
1268*4882a593Smuzhiyun 		char buf[CMSG_SPACE(sizeof(struct in_pktinfo))];
1269*4882a593Smuzhiyun 		struct cmsghdr align;
1270*4882a593Smuzhiyun 	} control4;
1271*4882a593Smuzhiyun 	struct msghdr hdr;
1272*4882a593Smuzhiyun 	struct iovec iov;
1273*4882a593Smuzhiyun 	char data = 'a';
1274*4882a593Smuzhiyun 	int domain;
1275*4882a593Smuzhiyun 	int fd = -1;
1276*4882a593Smuzhiyun 
1277*4882a593Smuzhiyun 	domain = addr->ss_family;
1278*4882a593Smuzhiyun 
1279*4882a593Smuzhiyun 	if (domain != AF_INET && domain != AF_INET6) {
1280*4882a593Smuzhiyun 		log_err("Unsupported address family");
1281*4882a593Smuzhiyun 		goto err;
1282*4882a593Smuzhiyun 	}
1283*4882a593Smuzhiyun 
1284*4882a593Smuzhiyun 	fd = socket(domain, type, 0);
1285*4882a593Smuzhiyun 	if (fd == -1) {
1286*4882a593Smuzhiyun 		log_err("Failed to create client socket");
1287*4882a593Smuzhiyun 		goto err;
1288*4882a593Smuzhiyun 	}
1289*4882a593Smuzhiyun 
1290*4882a593Smuzhiyun 	memset(&iov, 0, sizeof(iov));
1291*4882a593Smuzhiyun 	iov.iov_base = &data;
1292*4882a593Smuzhiyun 	iov.iov_len = sizeof(data);
1293*4882a593Smuzhiyun 
1294*4882a593Smuzhiyun 	memset(&hdr, 0, sizeof(hdr));
1295*4882a593Smuzhiyun 	hdr.msg_name = (void *)addr;
1296*4882a593Smuzhiyun 	hdr.msg_namelen = addr_len;
1297*4882a593Smuzhiyun 	hdr.msg_iov = &iov;
1298*4882a593Smuzhiyun 	hdr.msg_iovlen = 1;
1299*4882a593Smuzhiyun 
1300*4882a593Smuzhiyun 	if (set_cmsg) {
1301*4882a593Smuzhiyun 		if (domain == AF_INET) {
1302*4882a593Smuzhiyun 			hdr.msg_control = &control4;
1303*4882a593Smuzhiyun 			hdr.msg_controllen = sizeof(control4.buf);
1304*4882a593Smuzhiyun 		} else if (domain == AF_INET6) {
1305*4882a593Smuzhiyun 			hdr.msg_control = &control6;
1306*4882a593Smuzhiyun 			hdr.msg_controllen = sizeof(control6.buf);
1307*4882a593Smuzhiyun 		}
1308*4882a593Smuzhiyun 		if (init_pktinfo(domain, CMSG_FIRSTHDR(&hdr))) {
1309*4882a593Smuzhiyun 			log_err("Fail to init pktinfo");
1310*4882a593Smuzhiyun 			goto err;
1311*4882a593Smuzhiyun 		}
1312*4882a593Smuzhiyun 	}
1313*4882a593Smuzhiyun 
1314*4882a593Smuzhiyun 	if (sendmsg(fd, &hdr, flags) != sizeof(data)) {
1315*4882a593Smuzhiyun 		log_err("Fail to send message to server");
1316*4882a593Smuzhiyun 		*syscall_err = errno;
1317*4882a593Smuzhiyun 		goto err;
1318*4882a593Smuzhiyun 	}
1319*4882a593Smuzhiyun 
1320*4882a593Smuzhiyun 	goto out;
1321*4882a593Smuzhiyun err:
1322*4882a593Smuzhiyun 	close(fd);
1323*4882a593Smuzhiyun 	fd = -1;
1324*4882a593Smuzhiyun out:
1325*4882a593Smuzhiyun 	return fd;
1326*4882a593Smuzhiyun }
1327*4882a593Smuzhiyun 
fastconnect_to_server(const struct sockaddr_storage * addr,socklen_t addr_len)1328*4882a593Smuzhiyun static int fastconnect_to_server(const struct sockaddr_storage *addr,
1329*4882a593Smuzhiyun 				 socklen_t addr_len)
1330*4882a593Smuzhiyun {
1331*4882a593Smuzhiyun 	int sendmsg_err;
1332*4882a593Smuzhiyun 
1333*4882a593Smuzhiyun 	return sendmsg_to_server(SOCK_STREAM, addr, addr_len, /*set_cmsg*/0,
1334*4882a593Smuzhiyun 				 MSG_FASTOPEN, &sendmsg_err);
1335*4882a593Smuzhiyun }
1336*4882a593Smuzhiyun 
recvmsg_from_client(int sockfd,struct sockaddr_storage * src_addr)1337*4882a593Smuzhiyun static int recvmsg_from_client(int sockfd, struct sockaddr_storage *src_addr)
1338*4882a593Smuzhiyun {
1339*4882a593Smuzhiyun 	struct timeval tv;
1340*4882a593Smuzhiyun 	struct msghdr hdr;
1341*4882a593Smuzhiyun 	struct iovec iov;
1342*4882a593Smuzhiyun 	char data[64];
1343*4882a593Smuzhiyun 	fd_set rfds;
1344*4882a593Smuzhiyun 
1345*4882a593Smuzhiyun 	FD_ZERO(&rfds);
1346*4882a593Smuzhiyun 	FD_SET(sockfd, &rfds);
1347*4882a593Smuzhiyun 
1348*4882a593Smuzhiyun 	tv.tv_sec = 2;
1349*4882a593Smuzhiyun 	tv.tv_usec = 0;
1350*4882a593Smuzhiyun 
1351*4882a593Smuzhiyun 	if (select(sockfd + 1, &rfds, NULL, NULL, &tv) <= 0 ||
1352*4882a593Smuzhiyun 	    !FD_ISSET(sockfd, &rfds))
1353*4882a593Smuzhiyun 		return -1;
1354*4882a593Smuzhiyun 
1355*4882a593Smuzhiyun 	memset(&iov, 0, sizeof(iov));
1356*4882a593Smuzhiyun 	iov.iov_base = data;
1357*4882a593Smuzhiyun 	iov.iov_len = sizeof(data);
1358*4882a593Smuzhiyun 
1359*4882a593Smuzhiyun 	memset(&hdr, 0, sizeof(hdr));
1360*4882a593Smuzhiyun 	hdr.msg_name = src_addr;
1361*4882a593Smuzhiyun 	hdr.msg_namelen = sizeof(struct sockaddr_storage);
1362*4882a593Smuzhiyun 	hdr.msg_iov = &iov;
1363*4882a593Smuzhiyun 	hdr.msg_iovlen = 1;
1364*4882a593Smuzhiyun 
1365*4882a593Smuzhiyun 	return recvmsg(sockfd, &hdr, 0);
1366*4882a593Smuzhiyun }
1367*4882a593Smuzhiyun 
init_addrs(const struct sock_addr_test * test,struct sockaddr_storage * requested_addr,struct sockaddr_storage * expected_addr,struct sockaddr_storage * expected_src_addr)1368*4882a593Smuzhiyun static int init_addrs(const struct sock_addr_test *test,
1369*4882a593Smuzhiyun 		      struct sockaddr_storage *requested_addr,
1370*4882a593Smuzhiyun 		      struct sockaddr_storage *expected_addr,
1371*4882a593Smuzhiyun 		      struct sockaddr_storage *expected_src_addr)
1372*4882a593Smuzhiyun {
1373*4882a593Smuzhiyun 	socklen_t addr_len = sizeof(struct sockaddr_storage);
1374*4882a593Smuzhiyun 
1375*4882a593Smuzhiyun 	if (mk_sockaddr(test->domain, test->expected_ip, test->expected_port,
1376*4882a593Smuzhiyun 			(struct sockaddr *)expected_addr, addr_len) == -1)
1377*4882a593Smuzhiyun 		goto err;
1378*4882a593Smuzhiyun 
1379*4882a593Smuzhiyun 	if (mk_sockaddr(test->domain, test->requested_ip, test->requested_port,
1380*4882a593Smuzhiyun 			(struct sockaddr *)requested_addr, addr_len) == -1)
1381*4882a593Smuzhiyun 		goto err;
1382*4882a593Smuzhiyun 
1383*4882a593Smuzhiyun 	if (test->expected_src_ip &&
1384*4882a593Smuzhiyun 	    mk_sockaddr(test->domain, test->expected_src_ip, 0,
1385*4882a593Smuzhiyun 			(struct sockaddr *)expected_src_addr, addr_len) == -1)
1386*4882a593Smuzhiyun 		goto err;
1387*4882a593Smuzhiyun 
1388*4882a593Smuzhiyun 	return 0;
1389*4882a593Smuzhiyun err:
1390*4882a593Smuzhiyun 	return -1;
1391*4882a593Smuzhiyun }
1392*4882a593Smuzhiyun 
run_bind_test_case(const struct sock_addr_test * test)1393*4882a593Smuzhiyun static int run_bind_test_case(const struct sock_addr_test *test)
1394*4882a593Smuzhiyun {
1395*4882a593Smuzhiyun 	socklen_t addr_len = sizeof(struct sockaddr_storage);
1396*4882a593Smuzhiyun 	struct sockaddr_storage requested_addr;
1397*4882a593Smuzhiyun 	struct sockaddr_storage expected_addr;
1398*4882a593Smuzhiyun 	int clientfd = -1;
1399*4882a593Smuzhiyun 	int servfd = -1;
1400*4882a593Smuzhiyun 	int err = 0;
1401*4882a593Smuzhiyun 
1402*4882a593Smuzhiyun 	if (init_addrs(test, &requested_addr, &expected_addr, NULL))
1403*4882a593Smuzhiyun 		goto err;
1404*4882a593Smuzhiyun 
1405*4882a593Smuzhiyun 	servfd = start_server(test->type, &requested_addr, addr_len);
1406*4882a593Smuzhiyun 	if (servfd == -1)
1407*4882a593Smuzhiyun 		goto err;
1408*4882a593Smuzhiyun 
1409*4882a593Smuzhiyun 	if (cmp_local_addr(servfd, &expected_addr))
1410*4882a593Smuzhiyun 		goto err;
1411*4882a593Smuzhiyun 
1412*4882a593Smuzhiyun 	/* Try to connect to server just in case */
1413*4882a593Smuzhiyun 	clientfd = connect_to_server(test->type, &expected_addr, addr_len);
1414*4882a593Smuzhiyun 	if (clientfd == -1)
1415*4882a593Smuzhiyun 		goto err;
1416*4882a593Smuzhiyun 
1417*4882a593Smuzhiyun 	goto out;
1418*4882a593Smuzhiyun err:
1419*4882a593Smuzhiyun 	err = -1;
1420*4882a593Smuzhiyun out:
1421*4882a593Smuzhiyun 	close(clientfd);
1422*4882a593Smuzhiyun 	close(servfd);
1423*4882a593Smuzhiyun 	return err;
1424*4882a593Smuzhiyun }
1425*4882a593Smuzhiyun 
run_connect_test_case(const struct sock_addr_test * test)1426*4882a593Smuzhiyun static int run_connect_test_case(const struct sock_addr_test *test)
1427*4882a593Smuzhiyun {
1428*4882a593Smuzhiyun 	socklen_t addr_len = sizeof(struct sockaddr_storage);
1429*4882a593Smuzhiyun 	struct sockaddr_storage expected_src_addr;
1430*4882a593Smuzhiyun 	struct sockaddr_storage requested_addr;
1431*4882a593Smuzhiyun 	struct sockaddr_storage expected_addr;
1432*4882a593Smuzhiyun 	int clientfd = -1;
1433*4882a593Smuzhiyun 	int servfd = -1;
1434*4882a593Smuzhiyun 	int err = 0;
1435*4882a593Smuzhiyun 
1436*4882a593Smuzhiyun 	if (init_addrs(test, &requested_addr, &expected_addr,
1437*4882a593Smuzhiyun 		       &expected_src_addr))
1438*4882a593Smuzhiyun 		goto err;
1439*4882a593Smuzhiyun 
1440*4882a593Smuzhiyun 	/* Prepare server to connect to */
1441*4882a593Smuzhiyun 	servfd = start_server(test->type, &expected_addr, addr_len);
1442*4882a593Smuzhiyun 	if (servfd == -1)
1443*4882a593Smuzhiyun 		goto err;
1444*4882a593Smuzhiyun 
1445*4882a593Smuzhiyun 	clientfd = connect_to_server(test->type, &requested_addr, addr_len);
1446*4882a593Smuzhiyun 	if (clientfd == -1)
1447*4882a593Smuzhiyun 		goto err;
1448*4882a593Smuzhiyun 
1449*4882a593Smuzhiyun 	/* Make sure src and dst addrs were overridden properly */
1450*4882a593Smuzhiyun 	if (cmp_peer_addr(clientfd, &expected_addr))
1451*4882a593Smuzhiyun 		goto err;
1452*4882a593Smuzhiyun 
1453*4882a593Smuzhiyun 	if (cmp_local_ip(clientfd, &expected_src_addr))
1454*4882a593Smuzhiyun 		goto err;
1455*4882a593Smuzhiyun 
1456*4882a593Smuzhiyun 	if (test->type == SOCK_STREAM) {
1457*4882a593Smuzhiyun 		/* Test TCP Fast Open scenario */
1458*4882a593Smuzhiyun 		clientfd = fastconnect_to_server(&requested_addr, addr_len);
1459*4882a593Smuzhiyun 		if (clientfd == -1)
1460*4882a593Smuzhiyun 			goto err;
1461*4882a593Smuzhiyun 
1462*4882a593Smuzhiyun 		/* Make sure src and dst addrs were overridden properly */
1463*4882a593Smuzhiyun 		if (cmp_peer_addr(clientfd, &expected_addr))
1464*4882a593Smuzhiyun 			goto err;
1465*4882a593Smuzhiyun 
1466*4882a593Smuzhiyun 		if (cmp_local_ip(clientfd, &expected_src_addr))
1467*4882a593Smuzhiyun 			goto err;
1468*4882a593Smuzhiyun 	}
1469*4882a593Smuzhiyun 
1470*4882a593Smuzhiyun 	goto out;
1471*4882a593Smuzhiyun err:
1472*4882a593Smuzhiyun 	err = -1;
1473*4882a593Smuzhiyun out:
1474*4882a593Smuzhiyun 	close(clientfd);
1475*4882a593Smuzhiyun 	close(servfd);
1476*4882a593Smuzhiyun 	return err;
1477*4882a593Smuzhiyun }
1478*4882a593Smuzhiyun 
run_xmsg_test_case(const struct sock_addr_test * test,int max_cmsg)1479*4882a593Smuzhiyun static int run_xmsg_test_case(const struct sock_addr_test *test, int max_cmsg)
1480*4882a593Smuzhiyun {
1481*4882a593Smuzhiyun 	socklen_t addr_len = sizeof(struct sockaddr_storage);
1482*4882a593Smuzhiyun 	struct sockaddr_storage expected_addr;
1483*4882a593Smuzhiyun 	struct sockaddr_storage server_addr;
1484*4882a593Smuzhiyun 	struct sockaddr_storage sendmsg_addr;
1485*4882a593Smuzhiyun 	struct sockaddr_storage recvmsg_addr;
1486*4882a593Smuzhiyun 	int clientfd = -1;
1487*4882a593Smuzhiyun 	int servfd = -1;
1488*4882a593Smuzhiyun 	int set_cmsg;
1489*4882a593Smuzhiyun 	int err = 0;
1490*4882a593Smuzhiyun 
1491*4882a593Smuzhiyun 	if (test->type != SOCK_DGRAM)
1492*4882a593Smuzhiyun 		goto err;
1493*4882a593Smuzhiyun 
1494*4882a593Smuzhiyun 	if (init_addrs(test, &sendmsg_addr, &server_addr, &expected_addr))
1495*4882a593Smuzhiyun 		goto err;
1496*4882a593Smuzhiyun 
1497*4882a593Smuzhiyun 	/* Prepare server to sendmsg to */
1498*4882a593Smuzhiyun 	servfd = start_server(test->type, &server_addr, addr_len);
1499*4882a593Smuzhiyun 	if (servfd == -1)
1500*4882a593Smuzhiyun 		goto err;
1501*4882a593Smuzhiyun 
1502*4882a593Smuzhiyun 	for (set_cmsg = 0; set_cmsg <= max_cmsg; ++set_cmsg) {
1503*4882a593Smuzhiyun 		if (clientfd >= 0)
1504*4882a593Smuzhiyun 			close(clientfd);
1505*4882a593Smuzhiyun 
1506*4882a593Smuzhiyun 		clientfd = sendmsg_to_server(test->type, &sendmsg_addr,
1507*4882a593Smuzhiyun 					     addr_len, set_cmsg, /*flags*/0,
1508*4882a593Smuzhiyun 					     &err);
1509*4882a593Smuzhiyun 		if (err)
1510*4882a593Smuzhiyun 			goto out;
1511*4882a593Smuzhiyun 		else if (clientfd == -1)
1512*4882a593Smuzhiyun 			goto err;
1513*4882a593Smuzhiyun 
1514*4882a593Smuzhiyun 		/* Try to receive message on server instead of using
1515*4882a593Smuzhiyun 		 * getpeername(2) on client socket, to check that client's
1516*4882a593Smuzhiyun 		 * destination address was rewritten properly, since
1517*4882a593Smuzhiyun 		 * getpeername(2) doesn't work with unconnected datagram
1518*4882a593Smuzhiyun 		 * sockets.
1519*4882a593Smuzhiyun 		 *
1520*4882a593Smuzhiyun 		 * Get source address from recvmsg(2) as well to make sure
1521*4882a593Smuzhiyun 		 * source was rewritten properly: getsockname(2) can't be used
1522*4882a593Smuzhiyun 		 * since socket is unconnected and source defined for one
1523*4882a593Smuzhiyun 		 * specific packet may differ from the one used by default and
1524*4882a593Smuzhiyun 		 * returned by getsockname(2).
1525*4882a593Smuzhiyun 		 */
1526*4882a593Smuzhiyun 		if (recvmsg_from_client(servfd, &recvmsg_addr) == -1)
1527*4882a593Smuzhiyun 			goto err;
1528*4882a593Smuzhiyun 
1529*4882a593Smuzhiyun 		if (cmp_addr(&recvmsg_addr, &expected_addr, /*cmp_port*/0))
1530*4882a593Smuzhiyun 			goto err;
1531*4882a593Smuzhiyun 	}
1532*4882a593Smuzhiyun 
1533*4882a593Smuzhiyun 	goto out;
1534*4882a593Smuzhiyun err:
1535*4882a593Smuzhiyun 	err = -1;
1536*4882a593Smuzhiyun out:
1537*4882a593Smuzhiyun 	close(clientfd);
1538*4882a593Smuzhiyun 	close(servfd);
1539*4882a593Smuzhiyun 	return err;
1540*4882a593Smuzhiyun }
1541*4882a593Smuzhiyun 
run_test_case(int cgfd,const struct sock_addr_test * test)1542*4882a593Smuzhiyun static int run_test_case(int cgfd, const struct sock_addr_test *test)
1543*4882a593Smuzhiyun {
1544*4882a593Smuzhiyun 	int progfd = -1;
1545*4882a593Smuzhiyun 	int err = 0;
1546*4882a593Smuzhiyun 
1547*4882a593Smuzhiyun 	printf("Test case: %s .. ", test->descr);
1548*4882a593Smuzhiyun 
1549*4882a593Smuzhiyun 	progfd = test->loadfn(test);
1550*4882a593Smuzhiyun 	if (test->expected_result == LOAD_REJECT && progfd < 0)
1551*4882a593Smuzhiyun 		goto out;
1552*4882a593Smuzhiyun 	else if (test->expected_result == LOAD_REJECT || progfd < 0)
1553*4882a593Smuzhiyun 		goto err;
1554*4882a593Smuzhiyun 
1555*4882a593Smuzhiyun 	err = bpf_prog_attach(progfd, cgfd, test->attach_type,
1556*4882a593Smuzhiyun 			      BPF_F_ALLOW_OVERRIDE);
1557*4882a593Smuzhiyun 	if (test->expected_result == ATTACH_REJECT && err) {
1558*4882a593Smuzhiyun 		err = 0; /* error was expected, reset it */
1559*4882a593Smuzhiyun 		goto out;
1560*4882a593Smuzhiyun 	} else if (test->expected_result == ATTACH_REJECT || err) {
1561*4882a593Smuzhiyun 		goto err;
1562*4882a593Smuzhiyun 	} else if (test->expected_result == ATTACH_OKAY) {
1563*4882a593Smuzhiyun 		err = 0;
1564*4882a593Smuzhiyun 		goto out;
1565*4882a593Smuzhiyun 	}
1566*4882a593Smuzhiyun 
1567*4882a593Smuzhiyun 	switch (test->attach_type) {
1568*4882a593Smuzhiyun 	case BPF_CGROUP_INET4_BIND:
1569*4882a593Smuzhiyun 	case BPF_CGROUP_INET6_BIND:
1570*4882a593Smuzhiyun 		err = run_bind_test_case(test);
1571*4882a593Smuzhiyun 		break;
1572*4882a593Smuzhiyun 	case BPF_CGROUP_INET4_CONNECT:
1573*4882a593Smuzhiyun 	case BPF_CGROUP_INET6_CONNECT:
1574*4882a593Smuzhiyun 		err = run_connect_test_case(test);
1575*4882a593Smuzhiyun 		break;
1576*4882a593Smuzhiyun 	case BPF_CGROUP_UDP4_SENDMSG:
1577*4882a593Smuzhiyun 	case BPF_CGROUP_UDP6_SENDMSG:
1578*4882a593Smuzhiyun 		err = run_xmsg_test_case(test, 1);
1579*4882a593Smuzhiyun 		break;
1580*4882a593Smuzhiyun 	case BPF_CGROUP_UDP4_RECVMSG:
1581*4882a593Smuzhiyun 	case BPF_CGROUP_UDP6_RECVMSG:
1582*4882a593Smuzhiyun 		err = run_xmsg_test_case(test, 0);
1583*4882a593Smuzhiyun 		break;
1584*4882a593Smuzhiyun 	default:
1585*4882a593Smuzhiyun 		goto err;
1586*4882a593Smuzhiyun 	}
1587*4882a593Smuzhiyun 
1588*4882a593Smuzhiyun 	if (test->expected_result == SYSCALL_EPERM && err == EPERM) {
1589*4882a593Smuzhiyun 		err = 0; /* error was expected, reset it */
1590*4882a593Smuzhiyun 		goto out;
1591*4882a593Smuzhiyun 	}
1592*4882a593Smuzhiyun 
1593*4882a593Smuzhiyun 	if (test->expected_result == SYSCALL_ENOTSUPP && err == ENOTSUPP) {
1594*4882a593Smuzhiyun 		err = 0; /* error was expected, reset it */
1595*4882a593Smuzhiyun 		goto out;
1596*4882a593Smuzhiyun 	}
1597*4882a593Smuzhiyun 
1598*4882a593Smuzhiyun 	if (err || test->expected_result != SUCCESS)
1599*4882a593Smuzhiyun 		goto err;
1600*4882a593Smuzhiyun 
1601*4882a593Smuzhiyun 	goto out;
1602*4882a593Smuzhiyun err:
1603*4882a593Smuzhiyun 	err = -1;
1604*4882a593Smuzhiyun out:
1605*4882a593Smuzhiyun 	/* Detaching w/o checking return code: best effort attempt. */
1606*4882a593Smuzhiyun 	if (progfd != -1)
1607*4882a593Smuzhiyun 		bpf_prog_detach(cgfd, test->attach_type);
1608*4882a593Smuzhiyun 	close(progfd);
1609*4882a593Smuzhiyun 	printf("[%s]\n", err ? "FAIL" : "PASS");
1610*4882a593Smuzhiyun 	return err;
1611*4882a593Smuzhiyun }
1612*4882a593Smuzhiyun 
run_tests(int cgfd)1613*4882a593Smuzhiyun static int run_tests(int cgfd)
1614*4882a593Smuzhiyun {
1615*4882a593Smuzhiyun 	int passes = 0;
1616*4882a593Smuzhiyun 	int fails = 0;
1617*4882a593Smuzhiyun 	int i;
1618*4882a593Smuzhiyun 
1619*4882a593Smuzhiyun 	for (i = 0; i < ARRAY_SIZE(tests); ++i) {
1620*4882a593Smuzhiyun 		if (run_test_case(cgfd, &tests[i]))
1621*4882a593Smuzhiyun 			++fails;
1622*4882a593Smuzhiyun 		else
1623*4882a593Smuzhiyun 			++passes;
1624*4882a593Smuzhiyun 	}
1625*4882a593Smuzhiyun 	printf("Summary: %d PASSED, %d FAILED\n", passes, fails);
1626*4882a593Smuzhiyun 	return fails ? -1 : 0;
1627*4882a593Smuzhiyun }
1628*4882a593Smuzhiyun 
main(int argc,char ** argv)1629*4882a593Smuzhiyun int main(int argc, char **argv)
1630*4882a593Smuzhiyun {
1631*4882a593Smuzhiyun 	int cgfd = -1;
1632*4882a593Smuzhiyun 	int err = 0;
1633*4882a593Smuzhiyun 
1634*4882a593Smuzhiyun 	if (argc < 2) {
1635*4882a593Smuzhiyun 		fprintf(stderr,
1636*4882a593Smuzhiyun 			"%s has to be run via %s.sh. Skip direct run.\n",
1637*4882a593Smuzhiyun 			argv[0], argv[0]);
1638*4882a593Smuzhiyun 		exit(err);
1639*4882a593Smuzhiyun 	}
1640*4882a593Smuzhiyun 
1641*4882a593Smuzhiyun 	cgfd = cgroup_setup_and_join(CG_PATH);
1642*4882a593Smuzhiyun 	if (cgfd < 0)
1643*4882a593Smuzhiyun 		goto err;
1644*4882a593Smuzhiyun 
1645*4882a593Smuzhiyun 	if (run_tests(cgfd))
1646*4882a593Smuzhiyun 		goto err;
1647*4882a593Smuzhiyun 
1648*4882a593Smuzhiyun 	goto out;
1649*4882a593Smuzhiyun err:
1650*4882a593Smuzhiyun 	err = -1;
1651*4882a593Smuzhiyun out:
1652*4882a593Smuzhiyun 	close(cgfd);
1653*4882a593Smuzhiyun 	cleanup_cgroup_environment();
1654*4882a593Smuzhiyun 	return err;
1655*4882a593Smuzhiyun }
1656