1*12bb6ca4SYonghong Song // SPDX-License-Identifier: GPL-2.0
2*12bb6ca4SYonghong Song /* Copyright (c) 2022 Meta Platforms, Inc. and affiliates. */
3*12bb6ca4SYonghong Song 
4*12bb6ca4SYonghong Song #include "vmlinux.h"
5*12bb6ca4SYonghong Song #include <bpf/bpf_helpers.h>
6*12bb6ca4SYonghong Song #include <bpf/bpf_tracing.h>
7*12bb6ca4SYonghong Song #include "bpf_tracing_net.h"
8*12bb6ca4SYonghong Song 
9*12bb6ca4SYonghong Song char _license[] SEC("license") = "GPL";
10*12bb6ca4SYonghong Song 
11*12bb6ca4SYonghong Song struct socket_cookie {
12*12bb6ca4SYonghong Song 	__u64 cookie_key;
13*12bb6ca4SYonghong Song 	__u64 cookie_value;
14*12bb6ca4SYonghong Song };
15*12bb6ca4SYonghong Song 
16*12bb6ca4SYonghong Song struct {
17*12bb6ca4SYonghong Song 	__uint(type, BPF_MAP_TYPE_CGRP_STORAGE);
18*12bb6ca4SYonghong Song 	__uint(map_flags, BPF_F_NO_PREALLOC);
19*12bb6ca4SYonghong Song 	__type(key, int);
20*12bb6ca4SYonghong Song 	__type(value, struct socket_cookie);
21*12bb6ca4SYonghong Song } socket_cookies SEC(".maps");
22*12bb6ca4SYonghong Song 
23*12bb6ca4SYonghong Song SEC("cgroup/connect6")
set_cookie(struct bpf_sock_addr * ctx)24*12bb6ca4SYonghong Song int set_cookie(struct bpf_sock_addr *ctx)
25*12bb6ca4SYonghong Song {
26*12bb6ca4SYonghong Song 	struct socket_cookie *p;
27*12bb6ca4SYonghong Song 	struct tcp_sock *tcp_sk;
28*12bb6ca4SYonghong Song 	struct bpf_sock *sk;
29*12bb6ca4SYonghong Song 
30*12bb6ca4SYonghong Song 	if (ctx->family != AF_INET6 || ctx->user_family != AF_INET6)
31*12bb6ca4SYonghong Song 		return 1;
32*12bb6ca4SYonghong Song 
33*12bb6ca4SYonghong Song 	sk = ctx->sk;
34*12bb6ca4SYonghong Song 	if (!sk)
35*12bb6ca4SYonghong Song 		return 1;
36*12bb6ca4SYonghong Song 
37*12bb6ca4SYonghong Song 	tcp_sk = bpf_skc_to_tcp_sock(sk);
38*12bb6ca4SYonghong Song 	if (!tcp_sk)
39*12bb6ca4SYonghong Song 		return 1;
40*12bb6ca4SYonghong Song 
41*12bb6ca4SYonghong Song 	p = bpf_cgrp_storage_get(&socket_cookies,
42*12bb6ca4SYonghong Song 		tcp_sk->inet_conn.icsk_inet.sk.sk_cgrp_data.cgroup, 0,
43*12bb6ca4SYonghong Song 		BPF_LOCAL_STORAGE_GET_F_CREATE);
44*12bb6ca4SYonghong Song 	if (!p)
45*12bb6ca4SYonghong Song 		return 1;
46*12bb6ca4SYonghong Song 
47*12bb6ca4SYonghong Song 	p->cookie_value = 0xF;
48*12bb6ca4SYonghong Song 	p->cookie_key = bpf_get_socket_cookie(ctx);
49*12bb6ca4SYonghong Song 	return 1;
50*12bb6ca4SYonghong Song }
51*12bb6ca4SYonghong Song 
52*12bb6ca4SYonghong Song SEC("sockops")
update_cookie_sockops(struct bpf_sock_ops * ctx)53*12bb6ca4SYonghong Song int update_cookie_sockops(struct bpf_sock_ops *ctx)
54*12bb6ca4SYonghong Song {
55*12bb6ca4SYonghong Song 	struct socket_cookie *p;
56*12bb6ca4SYonghong Song 	struct tcp_sock *tcp_sk;
57*12bb6ca4SYonghong Song 	struct bpf_sock *sk;
58*12bb6ca4SYonghong Song 
59*12bb6ca4SYonghong Song 	if (ctx->family != AF_INET6 || ctx->op != BPF_SOCK_OPS_TCP_CONNECT_CB)
60*12bb6ca4SYonghong Song 		return 1;
61*12bb6ca4SYonghong Song 
62*12bb6ca4SYonghong Song 	sk = ctx->sk;
63*12bb6ca4SYonghong Song 	if (!sk)
64*12bb6ca4SYonghong Song 		return 1;
65*12bb6ca4SYonghong Song 
66*12bb6ca4SYonghong Song 	tcp_sk = bpf_skc_to_tcp_sock(sk);
67*12bb6ca4SYonghong Song 	if (!tcp_sk)
68*12bb6ca4SYonghong Song 		return 1;
69*12bb6ca4SYonghong Song 
70*12bb6ca4SYonghong Song 	p = bpf_cgrp_storage_get(&socket_cookies,
71*12bb6ca4SYonghong Song 		tcp_sk->inet_conn.icsk_inet.sk.sk_cgrp_data.cgroup, 0, 0);
72*12bb6ca4SYonghong Song 	if (!p)
73*12bb6ca4SYonghong Song 		return 1;
74*12bb6ca4SYonghong Song 
75*12bb6ca4SYonghong Song 	if (p->cookie_key != bpf_get_socket_cookie(ctx))
76*12bb6ca4SYonghong Song 		return 1;
77*12bb6ca4SYonghong Song 
78*12bb6ca4SYonghong Song 	p->cookie_value |= (ctx->local_port << 8);
79*12bb6ca4SYonghong Song 	return 1;
80*12bb6ca4SYonghong Song }
81*12bb6ca4SYonghong Song 
82*12bb6ca4SYonghong Song SEC("fexit/inet_stream_connect")
BPF_PROG(update_cookie_tracing,struct socket * sock,struct sockaddr * uaddr,int addr_len,int flags)83*12bb6ca4SYonghong Song int BPF_PROG(update_cookie_tracing, struct socket *sock,
84*12bb6ca4SYonghong Song 	     struct sockaddr *uaddr, int addr_len, int flags)
85*12bb6ca4SYonghong Song {
86*12bb6ca4SYonghong Song 	struct socket_cookie *p;
87*12bb6ca4SYonghong Song 
88*12bb6ca4SYonghong Song 	if (uaddr->sa_family != AF_INET6)
89*12bb6ca4SYonghong Song 		return 0;
90*12bb6ca4SYonghong Song 
91*12bb6ca4SYonghong Song 	p = bpf_cgrp_storage_get(&socket_cookies, sock->sk->sk_cgrp_data.cgroup, 0, 0);
92*12bb6ca4SYonghong Song 	if (!p)
93*12bb6ca4SYonghong Song 		return 0;
94*12bb6ca4SYonghong Song 
95*12bb6ca4SYonghong Song 	if (p->cookie_key != bpf_get_socket_cookie(sock->sk))
96*12bb6ca4SYonghong Song 		return 0;
97*12bb6ca4SYonghong Song 
98*12bb6ca4SYonghong Song 	p->cookie_value |= 0xF0;
99*12bb6ca4SYonghong Song 	return 0;
100*12bb6ca4SYonghong Song }
101