tc full packet test
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 10s
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 10s
This commit is contained in:
@@ -20,6 +20,8 @@ except Exception as exc: # pragma: no cover - depends on host runtime
|
||||
print(f"Failed to import python3-bpfcc: {exc}", file=sys.stderr, flush=True)
|
||||
raise
|
||||
|
||||
from src.utilities.packet_mark import packet_id_from_mark, verdict_from_mark
|
||||
|
||||
|
||||
IDENTITY_FIELDS = (
|
||||
"src_mac",
|
||||
@@ -75,6 +77,7 @@ struct arp_eth_ipv4_t {
|
||||
|
||||
struct event_t {
|
||||
__u64 ts_ns;
|
||||
__u32 skb_mark;
|
||||
__u32 length;
|
||||
__u32 reason;
|
||||
__u16 eth_type_raw;
|
||||
@@ -130,6 +133,7 @@ static __always_inline int parse_skb(struct sk_buff *skb, struct event_t *event)
|
||||
bpf_probe_read_kernel(&network_header, sizeof(network_header), &skb->network_header);
|
||||
bpf_probe_read_kernel(&transport_header, sizeof(transport_header), &skb->transport_header);
|
||||
bpf_probe_read_kernel(&event->length, sizeof(event->length), &skb->len);
|
||||
bpf_probe_read_kernel(&event->skb_mark, sizeof(event->skb_mark), &skb->mark);
|
||||
|
||||
if (!head) {
|
||||
return 0;
|
||||
@@ -302,6 +306,7 @@ TRACEPOINT_PROBE(net, net_dev_queue) {
|
||||
class Event(ct.Structure):
|
||||
_fields_ = [
|
||||
("ts_ns", ct.c_ulonglong),
|
||||
("skb_mark", ct.c_uint),
|
||||
("length", ct.c_uint),
|
||||
("reason", ct.c_uint),
|
||||
("eth_type_raw", ct.c_ushort),
|
||||
@@ -371,6 +376,7 @@ def _emit_event(cpu: int, data: int, size: int) -> None:
|
||||
payload: dict[str, object] = {
|
||||
"event_type": _event_name(event.event_type),
|
||||
"iface": iface,
|
||||
"skb_mark": int(event.skb_mark) or None,
|
||||
"length": int(event.length),
|
||||
"src_mac": _mac_to_str(event.src_mac),
|
||||
"dst_mac": _mac_to_str(event.dst_mac),
|
||||
@@ -391,7 +397,18 @@ def _emit_event(cpu: int, data: int, size: int) -> None:
|
||||
"reason": _reason_name(int(event.reason)) if event.event_type == 3 else None,
|
||||
"reason_code": int(event.reason) if event.event_type == 3 else None,
|
||||
}
|
||||
payload["packet_uid"] = _build_packet_uid(payload)
|
||||
packet_id = packet_id_from_mark(payload.get("skb_mark"))
|
||||
if packet_id:
|
||||
payload["packet_id"] = packet_id
|
||||
payload["correlation_key"] = f"pid:{packet_id}"
|
||||
payload["correlation_source"] = "kernel_mark"
|
||||
verdict_hint = verdict_from_mark(payload.get("skb_mark"))
|
||||
if verdict_hint:
|
||||
payload["verdict_hint"] = verdict_hint
|
||||
else:
|
||||
payload["packet_uid"] = _build_packet_uid(payload)
|
||||
payload["correlation_key"] = f"uid:{payload['packet_uid']}"
|
||||
payload["correlation_source"] = "legacy_hash"
|
||||
print(json.dumps(payload, separators=(",", ":")), flush=True)
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user