tc full packet test
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 10s
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 10s
This commit is contained in:
29
tools/ebpf/mark_packet_id.c
Normal file
29
tools/ebpf/mark_packet_id.c
Normal file
@@ -0,0 +1,29 @@
|
||||
#include <linux/bpf.h>
|
||||
#include <linux/pkt_cls.h>
|
||||
#include <bpf/bpf_helpers.h>
|
||||
|
||||
#define PACKET_ID_MASK 0x0FFFFFFF
|
||||
#define VERDICT_MASK 0xF0000000
|
||||
|
||||
struct {
|
||||
__uint(type, BPF_MAP_TYPE_ARRAY);
|
||||
__uint(max_entries, 1);
|
||||
__type(key, __u32);
|
||||
__type(value, __u32);
|
||||
} packet_counter SEC(".maps");
|
||||
|
||||
SEC("classifier")
|
||||
int classifier(struct __sk_buff *skb) {
|
||||
__u32 key = 0;
|
||||
__u32 *counter = bpf_map_lookup_elem(&packet_counter, &key);
|
||||
__u32 next = 1;
|
||||
|
||||
if (counter) {
|
||||
next = __sync_add_and_fetch(counter, 1);
|
||||
}
|
||||
|
||||
skb->mark = (skb->mark & VERDICT_MASK) | (next & PACKET_ID_MASK);
|
||||
return TC_ACT_OK;
|
||||
}
|
||||
|
||||
char LICENSE[] SEC("license") = "GPL";
|
||||
41
tools/ebpf/prepend_capture_header.c
Normal file
41
tools/ebpf/prepend_capture_header.c
Normal file
@@ -0,0 +1,41 @@
|
||||
#include <linux/bpf.h>
|
||||
#include <linux/pkt_cls.h>
|
||||
#include <bpf/bpf_endian.h>
|
||||
#include <bpf/bpf_helpers.h>
|
||||
|
||||
#define CAPTURE_MAGIC 0x4d544350
|
||||
#define CAPTURE_VERSION 1
|
||||
|
||||
struct capture_header {
|
||||
__be32 magic;
|
||||
__u8 version;
|
||||
__u8 flags;
|
||||
__be16 header_len;
|
||||
__be32 skb_mark;
|
||||
__be32 aux_value;
|
||||
} __attribute__((packed));
|
||||
|
||||
SEC("classifier")
|
||||
int classifier(struct __sk_buff *skb) {
|
||||
struct capture_header hdr = {
|
||||
.magic = bpf_htonl(CAPTURE_MAGIC),
|
||||
.version = CAPTURE_VERSION,
|
||||
.flags = 0,
|
||||
.header_len = bpf_htons(sizeof(struct capture_header)),
|
||||
.skb_mark = bpf_htonl(skb->mark),
|
||||
.aux_value = 0,
|
||||
};
|
||||
|
||||
if (!skb->mark) {
|
||||
return TC_ACT_OK;
|
||||
}
|
||||
if (bpf_skb_adjust_room(skb, sizeof(hdr), BPF_ADJ_ROOM_MAC, 0)) {
|
||||
return TC_ACT_OK;
|
||||
}
|
||||
if (bpf_skb_store_bytes(skb, 0, &hdr, sizeof(hdr), 0)) {
|
||||
return TC_ACT_OK;
|
||||
}
|
||||
return TC_ACT_OK;
|
||||
}
|
||||
|
||||
char LICENSE[] SEC("license") = "GPL";
|
||||
84
tools/setup_bridge_capture.sh
Executable file
84
tools/setup_bridge_capture.sh
Executable file
@@ -0,0 +1,84 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
usage() {
|
||||
cat <<'EOF'
|
||||
Usage: tools/setup_bridge_capture.sh --bridge <bridge> [--mirror-if mitmcap0] [--capture-if mitmcap1] [--build-dir /tmp/mitm-bpf]
|
||||
|
||||
Sets up:
|
||||
1. A veth pair used as a capture mirror target
|
||||
2. tc ingress packet-id marking on each bridge slave
|
||||
3. tc mirroring from each bridge slave into the mirror interface
|
||||
4. A capture-header injector on the capture-side interface
|
||||
|
||||
Set BACKEND_CAPTURE_INTERFACE to the capture interface printed at the end.
|
||||
EOF
|
||||
}
|
||||
|
||||
BRIDGE=""
|
||||
MIRROR_IF="mitmcap0"
|
||||
CAPTURE_IF="mitmcap1"
|
||||
BUILD_DIR="/tmp/mitm-bpf"
|
||||
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
--bridge) BRIDGE="$2"; shift 2 ;;
|
||||
--mirror-if) MIRROR_IF="$2"; shift 2 ;;
|
||||
--capture-if) CAPTURE_IF="$2"; shift 2 ;;
|
||||
--build-dir) BUILD_DIR="$2"; shift 2 ;;
|
||||
-h|--help) usage; exit 0 ;;
|
||||
*) echo "Unknown argument: $1" >&2; usage; exit 1 ;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [[ -z "$BRIDGE" ]]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! command -v tc >/dev/null 2>&1 || ! command -v clang >/dev/null 2>&1; then
|
||||
echo "Missing required tools: tc and clang must be installed." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mkdir -p "$BUILD_DIR"
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
SRC_DIR="$SCRIPT_DIR/ebpf"
|
||||
MARK_OBJ="$BUILD_DIR/mark_packet_id.o"
|
||||
CAPTURE_OBJ="$BUILD_DIR/prepend_capture_header.o"
|
||||
|
||||
clang -O2 -g -target bpf -c "$SRC_DIR/mark_packet_id.c" -o "$MARK_OBJ"
|
||||
clang -O2 -g -target bpf -c "$SRC_DIR/prepend_capture_header.c" -o "$CAPTURE_OBJ"
|
||||
|
||||
if ! ip link show "$MIRROR_IF" >/dev/null 2>&1; then
|
||||
ip link add "$MIRROR_IF" type veth peer name "$CAPTURE_IF"
|
||||
fi
|
||||
|
||||
ip link set "$MIRROR_IF" up
|
||||
ip link set "$CAPTURE_IF" up
|
||||
|
||||
mapfile -t PORTS < <(bridge link show master "$BRIDGE" | awk -F': ' '{print $2}' | awk '{print $1}')
|
||||
if [[ ${#PORTS[@]} -eq 0 ]]; then
|
||||
echo "No bridge slave interfaces found for $BRIDGE" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
for port in "${PORTS[@]}"; do
|
||||
tc qdisc replace dev "$port" clsact
|
||||
tc filter replace dev "$port" ingress pref 10 protocol all bpf direct-action obj "$MARK_OBJ" sec classifier
|
||||
tc filter replace dev "$port" ingress pref 20 protocol all matchall action mirred egress mirror dev "$MIRROR_IF"
|
||||
done
|
||||
|
||||
tc qdisc replace dev "$CAPTURE_IF" clsact
|
||||
tc filter replace dev "$CAPTURE_IF" ingress pref 10 protocol all bpf direct-action obj "$CAPTURE_OBJ" sec classifier
|
||||
|
||||
cat <<EOF
|
||||
Bridge capture pipeline ready.
|
||||
Bridge: $BRIDGE
|
||||
Bridge slave ports: ${PORTS[*]}
|
||||
Mirror tx interface: $MIRROR_IF
|
||||
Capture interface: $CAPTURE_IF
|
||||
|
||||
Set this in backend/.env:
|
||||
BACKEND_CAPTURE_INTERFACE=$CAPTURE_IF
|
||||
EOF
|
||||
33
tools/teardown_bridge_capture.sh
Executable file
33
tools/teardown_bridge_capture.sh
Executable file
@@ -0,0 +1,33 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
usage() {
|
||||
echo "Usage: tools/teardown_bridge_capture.sh --bridge <bridge> [--mirror-if mitmcap0] [--capture-if mitmcap1]"
|
||||
}
|
||||
|
||||
BRIDGE=""
|
||||
MIRROR_IF="mitmcap0"
|
||||
CAPTURE_IF="mitmcap1"
|
||||
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
--bridge) BRIDGE="$2"; shift 2 ;;
|
||||
--mirror-if) MIRROR_IF="$2"; shift 2 ;;
|
||||
--capture-if) CAPTURE_IF="$2"; shift 2 ;;
|
||||
-h|--help) usage; exit 0 ;;
|
||||
*) echo "Unknown argument: $1" >&2; usage; exit 1 ;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [[ -n "$BRIDGE" ]] && ip link show "$BRIDGE" >/dev/null 2>&1; then
|
||||
while read -r port; do
|
||||
[[ -n "$port" ]] || continue
|
||||
tc qdisc del dev "$port" clsact 2>/dev/null || true
|
||||
done < <(bridge link show master "$BRIDGE" | awk -F': ' '{print $2}' | awk '{print $1}')
|
||||
fi
|
||||
|
||||
tc qdisc del dev "$CAPTURE_IF" clsact 2>/dev/null || true
|
||||
|
||||
if ip link show "$MIRROR_IF" >/dev/null 2>&1; then
|
||||
ip link del "$MIRROR_IF"
|
||||
fi
|
||||
Reference in New Issue
Block a user