18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0
28c2ecf20Sopenharmony_ci/* Copyright (c) 2019 Facebook */
38c2ecf20Sopenharmony_ci#include <linux/stddef.h>
48c2ecf20Sopenharmony_ci#include <linux/if_ether.h>
58c2ecf20Sopenharmony_ci#include <linux/ipv6.h>
68c2ecf20Sopenharmony_ci#include <linux/bpf.h>
78c2ecf20Sopenharmony_ci#include <linux/tcp.h>
88c2ecf20Sopenharmony_ci#include <bpf/bpf_helpers.h>
98c2ecf20Sopenharmony_ci#include <bpf/bpf_endian.h>
108c2ecf20Sopenharmony_ci#include <bpf/bpf_tracing.h>
118c2ecf20Sopenharmony_ci
128c2ecf20Sopenharmony_cistruct sk_buff {
138c2ecf20Sopenharmony_ci	unsigned int len;
148c2ecf20Sopenharmony_ci};
158c2ecf20Sopenharmony_ci
168c2ecf20Sopenharmony_ci__u64 test_result = 0;
178c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access")
188c2ecf20Sopenharmony_ciint BPF_PROG(test_main, struct sk_buff *skb, int ret)
198c2ecf20Sopenharmony_ci{
208c2ecf20Sopenharmony_ci	int len;
218c2ecf20Sopenharmony_ci
228c2ecf20Sopenharmony_ci	__builtin_preserve_access_index(({
238c2ecf20Sopenharmony_ci		len = skb->len;
248c2ecf20Sopenharmony_ci	}));
258c2ecf20Sopenharmony_ci	if (len != 74 || ret != 0)
268c2ecf20Sopenharmony_ci		return 0;
278c2ecf20Sopenharmony_ci	test_result = 1;
288c2ecf20Sopenharmony_ci	return 0;
298c2ecf20Sopenharmony_ci}
308c2ecf20Sopenharmony_ci
318c2ecf20Sopenharmony_ci__u64 test_result_subprog1 = 0;
328c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access_subprog1")
338c2ecf20Sopenharmony_ciint BPF_PROG(test_subprog1, struct sk_buff *skb, int ret)
348c2ecf20Sopenharmony_ci{
358c2ecf20Sopenharmony_ci	int len;
368c2ecf20Sopenharmony_ci
378c2ecf20Sopenharmony_ci	__builtin_preserve_access_index(({
388c2ecf20Sopenharmony_ci		len = skb->len;
398c2ecf20Sopenharmony_ci	}));
408c2ecf20Sopenharmony_ci	if (len != 74 || ret != 148)
418c2ecf20Sopenharmony_ci		return 0;
428c2ecf20Sopenharmony_ci	test_result_subprog1 = 1;
438c2ecf20Sopenharmony_ci	return 0;
448c2ecf20Sopenharmony_ci}
458c2ecf20Sopenharmony_ci
468c2ecf20Sopenharmony_ci/* Though test_pkt_access_subprog2() is defined in C as:
478c2ecf20Sopenharmony_ci * static __attribute__ ((noinline))
488c2ecf20Sopenharmony_ci * int test_pkt_access_subprog2(int val, volatile struct __sk_buff *skb)
498c2ecf20Sopenharmony_ci * {
508c2ecf20Sopenharmony_ci *     return skb->len * val;
518c2ecf20Sopenharmony_ci * }
528c2ecf20Sopenharmony_ci * llvm optimizations remove 'int val' argument and generate BPF assembly:
538c2ecf20Sopenharmony_ci *   r0 = *(u32 *)(r1 + 0)
548c2ecf20Sopenharmony_ci *   w0 <<= 1
558c2ecf20Sopenharmony_ci *   exit
568c2ecf20Sopenharmony_ci * In such case the verifier falls back to conservative and
578c2ecf20Sopenharmony_ci * tracing program can access arguments and return value as u64
588c2ecf20Sopenharmony_ci * instead of accurate types.
598c2ecf20Sopenharmony_ci */
608c2ecf20Sopenharmony_cistruct args_subprog2 {
618c2ecf20Sopenharmony_ci	__u64 args[5];
628c2ecf20Sopenharmony_ci	__u64 ret;
638c2ecf20Sopenharmony_ci};
648c2ecf20Sopenharmony_ci__u64 test_result_subprog2 = 0;
658c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access_subprog2")
668c2ecf20Sopenharmony_ciint test_subprog2(struct args_subprog2 *ctx)
678c2ecf20Sopenharmony_ci{
688c2ecf20Sopenharmony_ci	struct sk_buff *skb = (void *)ctx->args[0];
698c2ecf20Sopenharmony_ci	__u64 ret;
708c2ecf20Sopenharmony_ci	int len;
718c2ecf20Sopenharmony_ci
728c2ecf20Sopenharmony_ci	bpf_probe_read_kernel(&len, sizeof(len),
738c2ecf20Sopenharmony_ci			      __builtin_preserve_access_index(&skb->len));
748c2ecf20Sopenharmony_ci
758c2ecf20Sopenharmony_ci	ret = ctx->ret;
768c2ecf20Sopenharmony_ci	/* bpf_prog_load() loads "test_pkt_access.o" with BPF_F_TEST_RND_HI32
778c2ecf20Sopenharmony_ci	 * which randomizes upper 32 bits after BPF_ALU32 insns.
788c2ecf20Sopenharmony_ci	 * Hence after 'w0 <<= 1' upper bits of $rax are random.
798c2ecf20Sopenharmony_ci	 * That is expected and correct. Trim them.
808c2ecf20Sopenharmony_ci	 */
818c2ecf20Sopenharmony_ci	ret = (__u32) ret;
828c2ecf20Sopenharmony_ci	if (len != 74 || ret != 148)
838c2ecf20Sopenharmony_ci		return 0;
848c2ecf20Sopenharmony_ci	test_result_subprog2 = 1;
858c2ecf20Sopenharmony_ci	return 0;
868c2ecf20Sopenharmony_ci}
878c2ecf20Sopenharmony_ci
888c2ecf20Sopenharmony_ci__u64 test_result_subprog3 = 0;
898c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access_subprog3")
908c2ecf20Sopenharmony_ciint BPF_PROG(test_subprog3, int val, struct sk_buff *skb, int ret)
918c2ecf20Sopenharmony_ci{
928c2ecf20Sopenharmony_ci	int len;
938c2ecf20Sopenharmony_ci
948c2ecf20Sopenharmony_ci	__builtin_preserve_access_index(({
958c2ecf20Sopenharmony_ci		len = skb->len;
968c2ecf20Sopenharmony_ci	}));
978c2ecf20Sopenharmony_ci	if (len != 74 || ret != 74 * val || val != 3)
988c2ecf20Sopenharmony_ci		return 0;
998c2ecf20Sopenharmony_ci	test_result_subprog3 = 1;
1008c2ecf20Sopenharmony_ci	return 0;
1018c2ecf20Sopenharmony_ci}
1028c2ecf20Sopenharmony_ci
1038c2ecf20Sopenharmony_ci__u64 test_get_skb_len = 0;
1048c2ecf20Sopenharmony_ciSEC("freplace/get_skb_len")
1058c2ecf20Sopenharmony_ciint new_get_skb_len(struct __sk_buff *skb)
1068c2ecf20Sopenharmony_ci{
1078c2ecf20Sopenharmony_ci	int len = skb->len;
1088c2ecf20Sopenharmony_ci
1098c2ecf20Sopenharmony_ci	if (len != 74)
1108c2ecf20Sopenharmony_ci		return 0;
1118c2ecf20Sopenharmony_ci	test_get_skb_len = 1;
1128c2ecf20Sopenharmony_ci	return 74; /* original get_skb_len() returns skb->len */
1138c2ecf20Sopenharmony_ci}
1148c2ecf20Sopenharmony_ci
1158c2ecf20Sopenharmony_ci__u64 test_get_skb_ifindex = 0;
1168c2ecf20Sopenharmony_ciSEC("freplace/get_skb_ifindex")
1178c2ecf20Sopenharmony_ciint new_get_skb_ifindex(int val, struct __sk_buff *skb, int var)
1188c2ecf20Sopenharmony_ci{
1198c2ecf20Sopenharmony_ci	void *data_end = (void *)(long)skb->data_end;
1208c2ecf20Sopenharmony_ci	void *data = (void *)(long)skb->data;
1218c2ecf20Sopenharmony_ci	struct ipv6hdr ip6, *ip6p;
1228c2ecf20Sopenharmony_ci	int ifindex = skb->ifindex;
1238c2ecf20Sopenharmony_ci	__u32 eth_proto;
1248c2ecf20Sopenharmony_ci	__u32 nh_off;
1258c2ecf20Sopenharmony_ci
1268c2ecf20Sopenharmony_ci	/* check that BPF extension can read packet via direct packet access */
1278c2ecf20Sopenharmony_ci	if (data + 14 + sizeof(ip6) > data_end)
1288c2ecf20Sopenharmony_ci		return 0;
1298c2ecf20Sopenharmony_ci	ip6p = data + 14;
1308c2ecf20Sopenharmony_ci
1318c2ecf20Sopenharmony_ci	if (ip6p->nexthdr != 6 || ip6p->payload_len != __bpf_constant_htons(123))
1328c2ecf20Sopenharmony_ci		return 0;
1338c2ecf20Sopenharmony_ci
1348c2ecf20Sopenharmony_ci	/* check that legacy packet access helper works too */
1358c2ecf20Sopenharmony_ci	if (bpf_skb_load_bytes(skb, 14, &ip6, sizeof(ip6)) < 0)
1368c2ecf20Sopenharmony_ci		return 0;
1378c2ecf20Sopenharmony_ci	ip6p = &ip6;
1388c2ecf20Sopenharmony_ci	if (ip6p->nexthdr != 6 || ip6p->payload_len != __bpf_constant_htons(123))
1398c2ecf20Sopenharmony_ci		return 0;
1408c2ecf20Sopenharmony_ci
1418c2ecf20Sopenharmony_ci	if (ifindex != 1 || val != 3 || var != 1)
1428c2ecf20Sopenharmony_ci		return 0;
1438c2ecf20Sopenharmony_ci	test_get_skb_ifindex = 1;
1448c2ecf20Sopenharmony_ci	return 3; /* original get_skb_ifindex() returns val * ifindex * var */
1458c2ecf20Sopenharmony_ci}
1468c2ecf20Sopenharmony_ci
1478c2ecf20Sopenharmony_civolatile __u64 test_get_constant = 0;
1488c2ecf20Sopenharmony_ciSEC("freplace/get_constant")
1498c2ecf20Sopenharmony_ciint new_get_constant(long val)
1508c2ecf20Sopenharmony_ci{
1518c2ecf20Sopenharmony_ci	if (val != 123)
1528c2ecf20Sopenharmony_ci		return 0;
1538c2ecf20Sopenharmony_ci	test_get_constant = 1;
1548c2ecf20Sopenharmony_ci	return test_get_constant; /* original get_constant() returns val - 122 */
1558c2ecf20Sopenharmony_ci}
1568c2ecf20Sopenharmony_ci
1578c2ecf20Sopenharmony_ci__u64 test_pkt_write_access_subprog = 0;
1588c2ecf20Sopenharmony_ciSEC("freplace/test_pkt_write_access_subprog")
1598c2ecf20Sopenharmony_ciint new_test_pkt_write_access_subprog(struct __sk_buff *skb, __u32 off)
1608c2ecf20Sopenharmony_ci{
1618c2ecf20Sopenharmony_ci
1628c2ecf20Sopenharmony_ci	void *data = (void *)(long)skb->data;
1638c2ecf20Sopenharmony_ci	void *data_end = (void *)(long)skb->data_end;
1648c2ecf20Sopenharmony_ci	struct tcphdr *tcp;
1658c2ecf20Sopenharmony_ci
1668c2ecf20Sopenharmony_ci	if (off > sizeof(struct ethhdr) + sizeof(struct ipv6hdr))
1678c2ecf20Sopenharmony_ci		return -1;
1688c2ecf20Sopenharmony_ci
1698c2ecf20Sopenharmony_ci	tcp = data + off;
1708c2ecf20Sopenharmony_ci	if (tcp + 1 > data_end)
1718c2ecf20Sopenharmony_ci		return -1;
1728c2ecf20Sopenharmony_ci
1738c2ecf20Sopenharmony_ci	/* make modifications to the packet data */
1748c2ecf20Sopenharmony_ci	tcp->check++;
1758c2ecf20Sopenharmony_ci	tcp->syn = 0;
1768c2ecf20Sopenharmony_ci
1778c2ecf20Sopenharmony_ci	test_pkt_write_access_subprog = 1;
1788c2ecf20Sopenharmony_ci	return 0;
1798c2ecf20Sopenharmony_ci}
1808c2ecf20Sopenharmony_ci
1818c2ecf20Sopenharmony_cichar _license[] SEC("license") = "GPL";
182