1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0
2*4882a593Smuzhiyun // Copyright (c) 2018 Facebook
3*4882a593Smuzhiyun
4*4882a593Smuzhiyun #include <string.h>
5*4882a593Smuzhiyun #include <unistd.h>
6*4882a593Smuzhiyun
7*4882a593Smuzhiyun #include <arpa/inet.h>
8*4882a593Smuzhiyun #include <netinet/in.h>
9*4882a593Smuzhiyun #include <sys/types.h>
10*4882a593Smuzhiyun #include <sys/socket.h>
11*4882a593Smuzhiyun
12*4882a593Smuzhiyun #include <bpf/bpf.h>
13*4882a593Smuzhiyun #include <bpf/libbpf.h>
14*4882a593Smuzhiyun
15*4882a593Smuzhiyun #include "bpf_rlimit.h"
16*4882a593Smuzhiyun #include "cgroup_helpers.h"
17*4882a593Smuzhiyun
18*4882a593Smuzhiyun #define CG_PATH "/foo"
19*4882a593Smuzhiyun #define SOCKET_COOKIE_PROG "./socket_cookie_prog.o"
20*4882a593Smuzhiyun
21*4882a593Smuzhiyun struct socket_cookie {
22*4882a593Smuzhiyun __u64 cookie_key;
23*4882a593Smuzhiyun __u32 cookie_value;
24*4882a593Smuzhiyun };
25*4882a593Smuzhiyun
start_server(void)26*4882a593Smuzhiyun static int start_server(void)
27*4882a593Smuzhiyun {
28*4882a593Smuzhiyun struct sockaddr_in6 addr;
29*4882a593Smuzhiyun int fd;
30*4882a593Smuzhiyun
31*4882a593Smuzhiyun fd = socket(AF_INET6, SOCK_STREAM, 0);
32*4882a593Smuzhiyun if (fd == -1) {
33*4882a593Smuzhiyun log_err("Failed to create server socket");
34*4882a593Smuzhiyun goto out;
35*4882a593Smuzhiyun }
36*4882a593Smuzhiyun
37*4882a593Smuzhiyun memset(&addr, 0, sizeof(addr));
38*4882a593Smuzhiyun addr.sin6_family = AF_INET6;
39*4882a593Smuzhiyun addr.sin6_addr = in6addr_loopback;
40*4882a593Smuzhiyun addr.sin6_port = 0;
41*4882a593Smuzhiyun
42*4882a593Smuzhiyun if (bind(fd, (const struct sockaddr *)&addr, sizeof(addr)) == -1) {
43*4882a593Smuzhiyun log_err("Failed to bind server socket");
44*4882a593Smuzhiyun goto close_out;
45*4882a593Smuzhiyun }
46*4882a593Smuzhiyun
47*4882a593Smuzhiyun if (listen(fd, 128) == -1) {
48*4882a593Smuzhiyun log_err("Failed to listen on server socket");
49*4882a593Smuzhiyun goto close_out;
50*4882a593Smuzhiyun }
51*4882a593Smuzhiyun
52*4882a593Smuzhiyun goto out;
53*4882a593Smuzhiyun
54*4882a593Smuzhiyun close_out:
55*4882a593Smuzhiyun close(fd);
56*4882a593Smuzhiyun fd = -1;
57*4882a593Smuzhiyun out:
58*4882a593Smuzhiyun return fd;
59*4882a593Smuzhiyun }
60*4882a593Smuzhiyun
connect_to_server(int server_fd)61*4882a593Smuzhiyun static int connect_to_server(int server_fd)
62*4882a593Smuzhiyun {
63*4882a593Smuzhiyun struct sockaddr_storage addr;
64*4882a593Smuzhiyun socklen_t len = sizeof(addr);
65*4882a593Smuzhiyun int fd;
66*4882a593Smuzhiyun
67*4882a593Smuzhiyun fd = socket(AF_INET6, SOCK_STREAM, 0);
68*4882a593Smuzhiyun if (fd == -1) {
69*4882a593Smuzhiyun log_err("Failed to create client socket");
70*4882a593Smuzhiyun goto out;
71*4882a593Smuzhiyun }
72*4882a593Smuzhiyun
73*4882a593Smuzhiyun if (getsockname(server_fd, (struct sockaddr *)&addr, &len)) {
74*4882a593Smuzhiyun log_err("Failed to get server addr");
75*4882a593Smuzhiyun goto close_out;
76*4882a593Smuzhiyun }
77*4882a593Smuzhiyun
78*4882a593Smuzhiyun if (connect(fd, (const struct sockaddr *)&addr, len) == -1) {
79*4882a593Smuzhiyun log_err("Fail to connect to server");
80*4882a593Smuzhiyun goto close_out;
81*4882a593Smuzhiyun }
82*4882a593Smuzhiyun
83*4882a593Smuzhiyun goto out;
84*4882a593Smuzhiyun
85*4882a593Smuzhiyun close_out:
86*4882a593Smuzhiyun close(fd);
87*4882a593Smuzhiyun fd = -1;
88*4882a593Smuzhiyun out:
89*4882a593Smuzhiyun return fd;
90*4882a593Smuzhiyun }
91*4882a593Smuzhiyun
validate_map(struct bpf_map * map,int client_fd)92*4882a593Smuzhiyun static int validate_map(struct bpf_map *map, int client_fd)
93*4882a593Smuzhiyun {
94*4882a593Smuzhiyun __u32 cookie_expected_value;
95*4882a593Smuzhiyun struct sockaddr_in6 addr;
96*4882a593Smuzhiyun socklen_t len = sizeof(addr);
97*4882a593Smuzhiyun struct socket_cookie val;
98*4882a593Smuzhiyun int err = 0;
99*4882a593Smuzhiyun int map_fd;
100*4882a593Smuzhiyun
101*4882a593Smuzhiyun if (!map) {
102*4882a593Smuzhiyun log_err("Map not found in BPF object");
103*4882a593Smuzhiyun goto err;
104*4882a593Smuzhiyun }
105*4882a593Smuzhiyun
106*4882a593Smuzhiyun map_fd = bpf_map__fd(map);
107*4882a593Smuzhiyun
108*4882a593Smuzhiyun err = bpf_map_lookup_elem(map_fd, &client_fd, &val);
109*4882a593Smuzhiyun
110*4882a593Smuzhiyun err = getsockname(client_fd, (struct sockaddr *)&addr, &len);
111*4882a593Smuzhiyun if (err) {
112*4882a593Smuzhiyun log_err("Can't get client local addr");
113*4882a593Smuzhiyun goto out;
114*4882a593Smuzhiyun }
115*4882a593Smuzhiyun
116*4882a593Smuzhiyun cookie_expected_value = (ntohs(addr.sin6_port) << 8) | 0xFF;
117*4882a593Smuzhiyun if (val.cookie_value != cookie_expected_value) {
118*4882a593Smuzhiyun log_err("Unexpected value in map: %x != %x", val.cookie_value,
119*4882a593Smuzhiyun cookie_expected_value);
120*4882a593Smuzhiyun goto err;
121*4882a593Smuzhiyun }
122*4882a593Smuzhiyun
123*4882a593Smuzhiyun goto out;
124*4882a593Smuzhiyun err:
125*4882a593Smuzhiyun err = -1;
126*4882a593Smuzhiyun out:
127*4882a593Smuzhiyun return err;
128*4882a593Smuzhiyun }
129*4882a593Smuzhiyun
run_test(int cgfd)130*4882a593Smuzhiyun static int run_test(int cgfd)
131*4882a593Smuzhiyun {
132*4882a593Smuzhiyun enum bpf_attach_type attach_type;
133*4882a593Smuzhiyun struct bpf_prog_load_attr attr;
134*4882a593Smuzhiyun struct bpf_program *prog;
135*4882a593Smuzhiyun struct bpf_object *pobj;
136*4882a593Smuzhiyun const char *prog_name;
137*4882a593Smuzhiyun int server_fd = -1;
138*4882a593Smuzhiyun int client_fd = -1;
139*4882a593Smuzhiyun int prog_fd = -1;
140*4882a593Smuzhiyun int err = 0;
141*4882a593Smuzhiyun
142*4882a593Smuzhiyun memset(&attr, 0, sizeof(attr));
143*4882a593Smuzhiyun attr.file = SOCKET_COOKIE_PROG;
144*4882a593Smuzhiyun attr.prog_type = BPF_PROG_TYPE_UNSPEC;
145*4882a593Smuzhiyun attr.prog_flags = BPF_F_TEST_RND_HI32;
146*4882a593Smuzhiyun
147*4882a593Smuzhiyun err = bpf_prog_load_xattr(&attr, &pobj, &prog_fd);
148*4882a593Smuzhiyun if (err) {
149*4882a593Smuzhiyun log_err("Failed to load %s", attr.file);
150*4882a593Smuzhiyun goto out;
151*4882a593Smuzhiyun }
152*4882a593Smuzhiyun
153*4882a593Smuzhiyun bpf_object__for_each_program(prog, pobj) {
154*4882a593Smuzhiyun prog_name = bpf_program__section_name(prog);
155*4882a593Smuzhiyun
156*4882a593Smuzhiyun if (libbpf_attach_type_by_name(prog_name, &attach_type))
157*4882a593Smuzhiyun goto err;
158*4882a593Smuzhiyun
159*4882a593Smuzhiyun err = bpf_prog_attach(bpf_program__fd(prog), cgfd, attach_type,
160*4882a593Smuzhiyun BPF_F_ALLOW_OVERRIDE);
161*4882a593Smuzhiyun if (err) {
162*4882a593Smuzhiyun log_err("Failed to attach prog %s", prog_name);
163*4882a593Smuzhiyun goto out;
164*4882a593Smuzhiyun }
165*4882a593Smuzhiyun }
166*4882a593Smuzhiyun
167*4882a593Smuzhiyun server_fd = start_server();
168*4882a593Smuzhiyun if (server_fd == -1)
169*4882a593Smuzhiyun goto err;
170*4882a593Smuzhiyun
171*4882a593Smuzhiyun client_fd = connect_to_server(server_fd);
172*4882a593Smuzhiyun if (client_fd == -1)
173*4882a593Smuzhiyun goto err;
174*4882a593Smuzhiyun
175*4882a593Smuzhiyun if (validate_map(bpf_map__next(NULL, pobj), client_fd))
176*4882a593Smuzhiyun goto err;
177*4882a593Smuzhiyun
178*4882a593Smuzhiyun goto out;
179*4882a593Smuzhiyun err:
180*4882a593Smuzhiyun err = -1;
181*4882a593Smuzhiyun out:
182*4882a593Smuzhiyun close(client_fd);
183*4882a593Smuzhiyun close(server_fd);
184*4882a593Smuzhiyun bpf_object__close(pobj);
185*4882a593Smuzhiyun printf("%s\n", err ? "FAILED" : "PASSED");
186*4882a593Smuzhiyun return err;
187*4882a593Smuzhiyun }
188*4882a593Smuzhiyun
main(int argc,char ** argv)189*4882a593Smuzhiyun int main(int argc, char **argv)
190*4882a593Smuzhiyun {
191*4882a593Smuzhiyun int cgfd = -1;
192*4882a593Smuzhiyun int err = 0;
193*4882a593Smuzhiyun
194*4882a593Smuzhiyun cgfd = cgroup_setup_and_join(CG_PATH);
195*4882a593Smuzhiyun if (cgfd < 0)
196*4882a593Smuzhiyun goto err;
197*4882a593Smuzhiyun
198*4882a593Smuzhiyun if (run_test(cgfd))
199*4882a593Smuzhiyun goto err;
200*4882a593Smuzhiyun
201*4882a593Smuzhiyun goto out;
202*4882a593Smuzhiyun err:
203*4882a593Smuzhiyun err = -1;
204*4882a593Smuzhiyun out:
205*4882a593Smuzhiyun close(cgfd);
206*4882a593Smuzhiyun cleanup_cgroup_environment();
207*4882a593Smuzhiyun return err;
208*4882a593Smuzhiyun }
209