18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0 28c2ecf20Sopenharmony_ci/* Copyright (c) 2019 Facebook */ 38c2ecf20Sopenharmony_ci#include <linux/stddef.h> 48c2ecf20Sopenharmony_ci#include <linux/if_ether.h> 58c2ecf20Sopenharmony_ci#include <linux/ipv6.h> 68c2ecf20Sopenharmony_ci#include <linux/bpf.h> 78c2ecf20Sopenharmony_ci#include <linux/tcp.h> 88c2ecf20Sopenharmony_ci#include <bpf/bpf_helpers.h> 98c2ecf20Sopenharmony_ci#include <bpf/bpf_endian.h> 108c2ecf20Sopenharmony_ci#include <bpf/bpf_tracing.h> 118c2ecf20Sopenharmony_ci 128c2ecf20Sopenharmony_cistruct sk_buff { 138c2ecf20Sopenharmony_ci unsigned int len; 148c2ecf20Sopenharmony_ci}; 158c2ecf20Sopenharmony_ci 168c2ecf20Sopenharmony_ci__u64 test_result = 0; 178c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access") 188c2ecf20Sopenharmony_ciint BPF_PROG(test_main, struct sk_buff *skb, int ret) 198c2ecf20Sopenharmony_ci{ 208c2ecf20Sopenharmony_ci int len; 218c2ecf20Sopenharmony_ci 228c2ecf20Sopenharmony_ci __builtin_preserve_access_index(({ 238c2ecf20Sopenharmony_ci len = skb->len; 248c2ecf20Sopenharmony_ci })); 258c2ecf20Sopenharmony_ci if (len != 74 || ret != 0) 268c2ecf20Sopenharmony_ci return 0; 278c2ecf20Sopenharmony_ci test_result = 1; 288c2ecf20Sopenharmony_ci return 0; 298c2ecf20Sopenharmony_ci} 308c2ecf20Sopenharmony_ci 318c2ecf20Sopenharmony_ci__u64 test_result_subprog1 = 0; 328c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access_subprog1") 338c2ecf20Sopenharmony_ciint BPF_PROG(test_subprog1, struct sk_buff *skb, int ret) 348c2ecf20Sopenharmony_ci{ 358c2ecf20Sopenharmony_ci int len; 368c2ecf20Sopenharmony_ci 378c2ecf20Sopenharmony_ci __builtin_preserve_access_index(({ 388c2ecf20Sopenharmony_ci len = skb->len; 398c2ecf20Sopenharmony_ci })); 408c2ecf20Sopenharmony_ci if (len != 74 || ret != 148) 418c2ecf20Sopenharmony_ci return 0; 428c2ecf20Sopenharmony_ci test_result_subprog1 = 1; 438c2ecf20Sopenharmony_ci return 0; 448c2ecf20Sopenharmony_ci} 458c2ecf20Sopenharmony_ci 468c2ecf20Sopenharmony_ci/* Though test_pkt_access_subprog2() is defined in C as: 478c2ecf20Sopenharmony_ci * static __attribute__ ((noinline)) 488c2ecf20Sopenharmony_ci * int test_pkt_access_subprog2(int val, volatile struct __sk_buff *skb) 498c2ecf20Sopenharmony_ci * { 508c2ecf20Sopenharmony_ci * return skb->len * val; 518c2ecf20Sopenharmony_ci * } 528c2ecf20Sopenharmony_ci * llvm optimizations remove 'int val' argument and generate BPF assembly: 538c2ecf20Sopenharmony_ci * r0 = *(u32 *)(r1 + 0) 548c2ecf20Sopenharmony_ci * w0 <<= 1 558c2ecf20Sopenharmony_ci * exit 568c2ecf20Sopenharmony_ci * In such case the verifier falls back to conservative and 578c2ecf20Sopenharmony_ci * tracing program can access arguments and return value as u64 588c2ecf20Sopenharmony_ci * instead of accurate types. 598c2ecf20Sopenharmony_ci */ 608c2ecf20Sopenharmony_cistruct args_subprog2 { 618c2ecf20Sopenharmony_ci __u64 args[5]; 628c2ecf20Sopenharmony_ci __u64 ret; 638c2ecf20Sopenharmony_ci}; 648c2ecf20Sopenharmony_ci__u64 test_result_subprog2 = 0; 658c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access_subprog2") 668c2ecf20Sopenharmony_ciint test_subprog2(struct args_subprog2 *ctx) 678c2ecf20Sopenharmony_ci{ 688c2ecf20Sopenharmony_ci struct sk_buff *skb = (void *)ctx->args[0]; 698c2ecf20Sopenharmony_ci __u64 ret; 708c2ecf20Sopenharmony_ci int len; 718c2ecf20Sopenharmony_ci 728c2ecf20Sopenharmony_ci bpf_probe_read_kernel(&len, sizeof(len), 738c2ecf20Sopenharmony_ci __builtin_preserve_access_index(&skb->len)); 748c2ecf20Sopenharmony_ci 758c2ecf20Sopenharmony_ci ret = ctx->ret; 768c2ecf20Sopenharmony_ci /* bpf_prog_load() loads "test_pkt_access.o" with BPF_F_TEST_RND_HI32 778c2ecf20Sopenharmony_ci * which randomizes upper 32 bits after BPF_ALU32 insns. 788c2ecf20Sopenharmony_ci * Hence after 'w0 <<= 1' upper bits of $rax are random. 798c2ecf20Sopenharmony_ci * That is expected and correct. Trim them. 808c2ecf20Sopenharmony_ci */ 818c2ecf20Sopenharmony_ci ret = (__u32) ret; 828c2ecf20Sopenharmony_ci if (len != 74 || ret != 148) 838c2ecf20Sopenharmony_ci return 0; 848c2ecf20Sopenharmony_ci test_result_subprog2 = 1; 858c2ecf20Sopenharmony_ci return 0; 868c2ecf20Sopenharmony_ci} 878c2ecf20Sopenharmony_ci 888c2ecf20Sopenharmony_ci__u64 test_result_subprog3 = 0; 898c2ecf20Sopenharmony_ciSEC("fexit/test_pkt_access_subprog3") 908c2ecf20Sopenharmony_ciint BPF_PROG(test_subprog3, int val, struct sk_buff *skb, int ret) 918c2ecf20Sopenharmony_ci{ 928c2ecf20Sopenharmony_ci int len; 938c2ecf20Sopenharmony_ci 948c2ecf20Sopenharmony_ci __builtin_preserve_access_index(({ 958c2ecf20Sopenharmony_ci len = skb->len; 968c2ecf20Sopenharmony_ci })); 978c2ecf20Sopenharmony_ci if (len != 74 || ret != 74 * val || val != 3) 988c2ecf20Sopenharmony_ci return 0; 998c2ecf20Sopenharmony_ci test_result_subprog3 = 1; 1008c2ecf20Sopenharmony_ci return 0; 1018c2ecf20Sopenharmony_ci} 1028c2ecf20Sopenharmony_ci 1038c2ecf20Sopenharmony_ci__u64 test_get_skb_len = 0; 1048c2ecf20Sopenharmony_ciSEC("freplace/get_skb_len") 1058c2ecf20Sopenharmony_ciint new_get_skb_len(struct __sk_buff *skb) 1068c2ecf20Sopenharmony_ci{ 1078c2ecf20Sopenharmony_ci int len = skb->len; 1088c2ecf20Sopenharmony_ci 1098c2ecf20Sopenharmony_ci if (len != 74) 1108c2ecf20Sopenharmony_ci return 0; 1118c2ecf20Sopenharmony_ci test_get_skb_len = 1; 1128c2ecf20Sopenharmony_ci return 74; /* original get_skb_len() returns skb->len */ 1138c2ecf20Sopenharmony_ci} 1148c2ecf20Sopenharmony_ci 1158c2ecf20Sopenharmony_ci__u64 test_get_skb_ifindex = 0; 1168c2ecf20Sopenharmony_ciSEC("freplace/get_skb_ifindex") 1178c2ecf20Sopenharmony_ciint new_get_skb_ifindex(int val, struct __sk_buff *skb, int var) 1188c2ecf20Sopenharmony_ci{ 1198c2ecf20Sopenharmony_ci void *data_end = (void *)(long)skb->data_end; 1208c2ecf20Sopenharmony_ci void *data = (void *)(long)skb->data; 1218c2ecf20Sopenharmony_ci struct ipv6hdr ip6, *ip6p; 1228c2ecf20Sopenharmony_ci int ifindex = skb->ifindex; 1238c2ecf20Sopenharmony_ci __u32 eth_proto; 1248c2ecf20Sopenharmony_ci __u32 nh_off; 1258c2ecf20Sopenharmony_ci 1268c2ecf20Sopenharmony_ci /* check that BPF extension can read packet via direct packet access */ 1278c2ecf20Sopenharmony_ci if (data + 14 + sizeof(ip6) > data_end) 1288c2ecf20Sopenharmony_ci return 0; 1298c2ecf20Sopenharmony_ci ip6p = data + 14; 1308c2ecf20Sopenharmony_ci 1318c2ecf20Sopenharmony_ci if (ip6p->nexthdr != 6 || ip6p->payload_len != __bpf_constant_htons(123)) 1328c2ecf20Sopenharmony_ci return 0; 1338c2ecf20Sopenharmony_ci 1348c2ecf20Sopenharmony_ci /* check that legacy packet access helper works too */ 1358c2ecf20Sopenharmony_ci if (bpf_skb_load_bytes(skb, 14, &ip6, sizeof(ip6)) < 0) 1368c2ecf20Sopenharmony_ci return 0; 1378c2ecf20Sopenharmony_ci ip6p = &ip6; 1388c2ecf20Sopenharmony_ci if (ip6p->nexthdr != 6 || ip6p->payload_len != __bpf_constant_htons(123)) 1398c2ecf20Sopenharmony_ci return 0; 1408c2ecf20Sopenharmony_ci 1418c2ecf20Sopenharmony_ci if (ifindex != 1 || val != 3 || var != 1) 1428c2ecf20Sopenharmony_ci return 0; 1438c2ecf20Sopenharmony_ci test_get_skb_ifindex = 1; 1448c2ecf20Sopenharmony_ci return 3; /* original get_skb_ifindex() returns val * ifindex * var */ 1458c2ecf20Sopenharmony_ci} 1468c2ecf20Sopenharmony_ci 1478c2ecf20Sopenharmony_civolatile __u64 test_get_constant = 0; 1488c2ecf20Sopenharmony_ciSEC("freplace/get_constant") 1498c2ecf20Sopenharmony_ciint new_get_constant(long val) 1508c2ecf20Sopenharmony_ci{ 1518c2ecf20Sopenharmony_ci if (val != 123) 1528c2ecf20Sopenharmony_ci return 0; 1538c2ecf20Sopenharmony_ci test_get_constant = 1; 1548c2ecf20Sopenharmony_ci return test_get_constant; /* original get_constant() returns val - 122 */ 1558c2ecf20Sopenharmony_ci} 1568c2ecf20Sopenharmony_ci 1578c2ecf20Sopenharmony_ci__u64 test_pkt_write_access_subprog = 0; 1588c2ecf20Sopenharmony_ciSEC("freplace/test_pkt_write_access_subprog") 1598c2ecf20Sopenharmony_ciint new_test_pkt_write_access_subprog(struct __sk_buff *skb, __u32 off) 1608c2ecf20Sopenharmony_ci{ 1618c2ecf20Sopenharmony_ci 1628c2ecf20Sopenharmony_ci void *data = (void *)(long)skb->data; 1638c2ecf20Sopenharmony_ci void *data_end = (void *)(long)skb->data_end; 1648c2ecf20Sopenharmony_ci struct tcphdr *tcp; 1658c2ecf20Sopenharmony_ci 1668c2ecf20Sopenharmony_ci if (off > sizeof(struct ethhdr) + sizeof(struct ipv6hdr)) 1678c2ecf20Sopenharmony_ci return -1; 1688c2ecf20Sopenharmony_ci 1698c2ecf20Sopenharmony_ci tcp = data + off; 1708c2ecf20Sopenharmony_ci if (tcp + 1 > data_end) 1718c2ecf20Sopenharmony_ci return -1; 1728c2ecf20Sopenharmony_ci 1738c2ecf20Sopenharmony_ci /* make modifications to the packet data */ 1748c2ecf20Sopenharmony_ci tcp->check++; 1758c2ecf20Sopenharmony_ci tcp->syn = 0; 1768c2ecf20Sopenharmony_ci 1778c2ecf20Sopenharmony_ci test_pkt_write_access_subprog = 1; 1788c2ecf20Sopenharmony_ci return 0; 1798c2ecf20Sopenharmony_ci} 1808c2ecf20Sopenharmony_ci 1818c2ecf20Sopenharmony_cichar _license[] SEC("license") = "GPL"; 182