131123c03SMartin KaFai Lau // SPDX-License-Identifier: GPL-2.0
231123c03SMartin KaFai Lau /* Copyright (c) Meta Platforms, Inc. and affiliates. */
331123c03SMartin KaFai Lau 
431123c03SMartin KaFai Lau #include "vmlinux.h"
531123c03SMartin KaFai Lau #include "bpf_tracing_net.h"
631123c03SMartin KaFai Lau #include <bpf/bpf_core_read.h>
731123c03SMartin KaFai Lau #include <bpf/bpf_helpers.h>
831123c03SMartin KaFai Lau #include <bpf/bpf_tracing.h>
931123c03SMartin KaFai Lau 
1031123c03SMartin KaFai Lau #ifndef ARRAY_SIZE
1131123c03SMartin KaFai Lau #define ARRAY_SIZE(x) (sizeof(x) / sizeof((x)[0]))
1231123c03SMartin KaFai Lau #endif
1331123c03SMartin KaFai Lau 
1431123c03SMartin KaFai Lau extern unsigned long CONFIG_HZ __kconfig;
1531123c03SMartin KaFai Lau 
1631123c03SMartin KaFai Lau const volatile char veth[IFNAMSIZ];
1731123c03SMartin KaFai Lau const volatile int veth_ifindex;
1831123c03SMartin KaFai Lau 
1931123c03SMartin KaFai Lau int nr_listen;
2031123c03SMartin KaFai Lau int nr_passive;
2131123c03SMartin KaFai Lau int nr_active;
2231123c03SMartin KaFai Lau int nr_connect;
2331123c03SMartin KaFai Lau int nr_binddev;
2431123c03SMartin KaFai Lau int nr_socket_post_create;
25*d1246f93SKui-Feng Lee int nr_fin_wait1;
2631123c03SMartin KaFai Lau 
2731123c03SMartin KaFai Lau struct sockopt_test {
2831123c03SMartin KaFai Lau 	int opt;
2931123c03SMartin KaFai Lau 	int new;
3031123c03SMartin KaFai Lau 	int restore;
3131123c03SMartin KaFai Lau 	int expected;
3231123c03SMartin KaFai Lau 	int tcp_expected;
3331123c03SMartin KaFai Lau 	unsigned int flip:1;
3431123c03SMartin KaFai Lau };
3531123c03SMartin KaFai Lau 
3619707294SMartin KaFai Lau static const char not_exist_cc[] = "not_exist";
3731123c03SMartin KaFai Lau static const char cubic_cc[] = "cubic";
3831123c03SMartin KaFai Lau static const char reno_cc[] = "reno";
3931123c03SMartin KaFai Lau 
4031123c03SMartin KaFai Lau static const struct sockopt_test sol_socket_tests[] = {
4131123c03SMartin KaFai Lau 	{ .opt = SO_REUSEADDR, .flip = 1, },
4231123c03SMartin KaFai Lau 	{ .opt = SO_SNDBUF, .new = 8123, .expected = 8123 * 2, },
4331123c03SMartin KaFai Lau 	{ .opt = SO_RCVBUF, .new = 8123, .expected = 8123 * 2, },
4431123c03SMartin KaFai Lau 	{ .opt = SO_KEEPALIVE, .flip = 1, },
4531123c03SMartin KaFai Lau 	{ .opt = SO_PRIORITY, .new = 0xeb9f, .expected = 0xeb9f, },
4631123c03SMartin KaFai Lau 	{ .opt = SO_REUSEPORT, .flip = 1, },
4731123c03SMartin KaFai Lau 	{ .opt = SO_RCVLOWAT, .new = 8123, .expected = 8123, },
4831123c03SMartin KaFai Lau 	{ .opt = SO_MARK, .new = 0xeb9f, .expected = 0xeb9f, },
4931123c03SMartin KaFai Lau 	{ .opt = SO_MAX_PACING_RATE, .new = 0xeb9f, .expected = 0xeb9f, },
5031123c03SMartin KaFai Lau 	{ .opt = SO_TXREHASH, .flip = 1, },
5131123c03SMartin KaFai Lau 	{ .opt = 0, },
5231123c03SMartin KaFai Lau };
5331123c03SMartin KaFai Lau 
5431123c03SMartin KaFai Lau static const struct sockopt_test sol_tcp_tests[] = {
5531123c03SMartin KaFai Lau 	{ .opt = TCP_NODELAY, .flip = 1, },
5631123c03SMartin KaFai Lau 	{ .opt = TCP_KEEPIDLE, .new = 123, .expected = 123, .restore = 321, },
5731123c03SMartin KaFai Lau 	{ .opt = TCP_KEEPINTVL, .new = 123, .expected = 123, .restore = 321, },
5831123c03SMartin KaFai Lau 	{ .opt = TCP_KEEPCNT, .new = 123, .expected = 123, .restore = 124, },
5931123c03SMartin KaFai Lau 	{ .opt = TCP_SYNCNT, .new = 123, .expected = 123, .restore = 124, },
6031123c03SMartin KaFai Lau 	{ .opt = TCP_WINDOW_CLAMP, .new = 8123, .expected = 8123, .restore = 8124, },
6131123c03SMartin KaFai Lau 	{ .opt = TCP_CONGESTION, },
6231123c03SMartin KaFai Lau 	{ .opt = TCP_THIN_LINEAR_TIMEOUTS, .flip = 1, },
6331123c03SMartin KaFai Lau 	{ .opt = TCP_USER_TIMEOUT, .new = 123400, .expected = 123400, },
6431123c03SMartin KaFai Lau 	{ .opt = TCP_NOTSENT_LOWAT, .new = 1314, .expected = 1314, },
6531123c03SMartin KaFai Lau 	{ .opt = 0, },
6631123c03SMartin KaFai Lau };
6731123c03SMartin KaFai Lau 
6831123c03SMartin KaFai Lau static const struct sockopt_test sol_ip_tests[] = {
6931123c03SMartin KaFai Lau 	{ .opt = IP_TOS, .new = 0xe1, .expected = 0xe1, .tcp_expected = 0xe0, },
7031123c03SMartin KaFai Lau 	{ .opt = 0, },
7131123c03SMartin KaFai Lau };
7231123c03SMartin KaFai Lau 
7331123c03SMartin KaFai Lau static const struct sockopt_test sol_ipv6_tests[] = {
7431123c03SMartin KaFai Lau 	{ .opt = IPV6_TCLASS, .new = 0xe1, .expected = 0xe1, .tcp_expected = 0xe0, },
7531123c03SMartin KaFai Lau 	{ .opt = IPV6_AUTOFLOWLABEL, .flip = 1, },
7631123c03SMartin KaFai Lau 	{ .opt = 0, },
7731123c03SMartin KaFai Lau };
7831123c03SMartin KaFai Lau 
7931123c03SMartin KaFai Lau struct loop_ctx {
8031123c03SMartin KaFai Lau 	void *ctx;
8131123c03SMartin KaFai Lau 	struct sock *sk;
8231123c03SMartin KaFai Lau };
8331123c03SMartin KaFai Lau 
bpf_test_sockopt_flip(void * ctx,struct sock * sk,const struct sockopt_test * t,int level)8431123c03SMartin KaFai Lau static int bpf_test_sockopt_flip(void *ctx, struct sock *sk,
8531123c03SMartin KaFai Lau 				 const struct sockopt_test *t,
8631123c03SMartin KaFai Lau 				 int level)
8731123c03SMartin KaFai Lau {
8831123c03SMartin KaFai Lau 	int old, tmp, new, opt = t->opt;
8931123c03SMartin KaFai Lau 
9031123c03SMartin KaFai Lau 	opt = t->opt;
9131123c03SMartin KaFai Lau 
92f649f992SMartin KaFai Lau 	if (bpf_getsockopt(ctx, level, opt, &old, sizeof(old)))
9331123c03SMartin KaFai Lau 		return 1;
9431123c03SMartin KaFai Lau 	/* kernel initialized txrehash to 255 */
9531123c03SMartin KaFai Lau 	if (level == SOL_SOCKET && opt == SO_TXREHASH && old != 0 && old != 1)
9631123c03SMartin KaFai Lau 		old = 1;
9731123c03SMartin KaFai Lau 
9831123c03SMartin KaFai Lau 	new = !old;
9931123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, level, opt, &new, sizeof(new)))
10031123c03SMartin KaFai Lau 		return 1;
101f649f992SMartin KaFai Lau 	if (bpf_getsockopt(ctx, level, opt, &tmp, sizeof(tmp)) ||
10231123c03SMartin KaFai Lau 	    tmp != new)
10331123c03SMartin KaFai Lau 		return 1;
10431123c03SMartin KaFai Lau 
10531123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, level, opt, &old, sizeof(old)))
10631123c03SMartin KaFai Lau 		return 1;
10731123c03SMartin KaFai Lau 
10831123c03SMartin KaFai Lau 	return 0;
10931123c03SMartin KaFai Lau }
11031123c03SMartin KaFai Lau 
bpf_test_sockopt_int(void * ctx,struct sock * sk,const struct sockopt_test * t,int level)11131123c03SMartin KaFai Lau static int bpf_test_sockopt_int(void *ctx, struct sock *sk,
11231123c03SMartin KaFai Lau 				const struct sockopt_test *t,
11331123c03SMartin KaFai Lau 				int level)
11431123c03SMartin KaFai Lau {
11531123c03SMartin KaFai Lau 	int old, tmp, new, expected, opt;
11631123c03SMartin KaFai Lau 
11731123c03SMartin KaFai Lau 	opt = t->opt;
11831123c03SMartin KaFai Lau 	new = t->new;
11931123c03SMartin KaFai Lau 	if (sk->sk_type == SOCK_STREAM && t->tcp_expected)
12031123c03SMartin KaFai Lau 		expected = t->tcp_expected;
12131123c03SMartin KaFai Lau 	else
12231123c03SMartin KaFai Lau 		expected = t->expected;
12331123c03SMartin KaFai Lau 
124f649f992SMartin KaFai Lau 	if (bpf_getsockopt(ctx, level, opt, &old, sizeof(old)) ||
12531123c03SMartin KaFai Lau 	    old == new)
12631123c03SMartin KaFai Lau 		return 1;
12731123c03SMartin KaFai Lau 
12831123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, level, opt, &new, sizeof(new)))
12931123c03SMartin KaFai Lau 		return 1;
130f649f992SMartin KaFai Lau 	if (bpf_getsockopt(ctx, level, opt, &tmp, sizeof(tmp)) ||
13131123c03SMartin KaFai Lau 	    tmp != expected)
13231123c03SMartin KaFai Lau 		return 1;
13331123c03SMartin KaFai Lau 
13431123c03SMartin KaFai Lau 	if (t->restore)
13531123c03SMartin KaFai Lau 		old = t->restore;
13631123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, level, opt, &old, sizeof(old)))
13731123c03SMartin KaFai Lau 		return 1;
13831123c03SMartin KaFai Lau 
13931123c03SMartin KaFai Lau 	return 0;
14031123c03SMartin KaFai Lau }
14131123c03SMartin KaFai Lau 
bpf_test_socket_sockopt(__u32 i,struct loop_ctx * lc)14231123c03SMartin KaFai Lau static int bpf_test_socket_sockopt(__u32 i, struct loop_ctx *lc)
14331123c03SMartin KaFai Lau {
14431123c03SMartin KaFai Lau 	const struct sockopt_test *t;
14531123c03SMartin KaFai Lau 
14631123c03SMartin KaFai Lau 	if (i >= ARRAY_SIZE(sol_socket_tests))
14731123c03SMartin KaFai Lau 		return 1;
14831123c03SMartin KaFai Lau 
14931123c03SMartin KaFai Lau 	t = &sol_socket_tests[i];
15031123c03SMartin KaFai Lau 	if (!t->opt)
15131123c03SMartin KaFai Lau 		return 1;
15231123c03SMartin KaFai Lau 
15331123c03SMartin KaFai Lau 	if (t->flip)
15431123c03SMartin KaFai Lau 		return bpf_test_sockopt_flip(lc->ctx, lc->sk, t, SOL_SOCKET);
15531123c03SMartin KaFai Lau 
15631123c03SMartin KaFai Lau 	return bpf_test_sockopt_int(lc->ctx, lc->sk, t, SOL_SOCKET);
15731123c03SMartin KaFai Lau }
15831123c03SMartin KaFai Lau 
bpf_test_ip_sockopt(__u32 i,struct loop_ctx * lc)15931123c03SMartin KaFai Lau static int bpf_test_ip_sockopt(__u32 i, struct loop_ctx *lc)
16031123c03SMartin KaFai Lau {
16131123c03SMartin KaFai Lau 	const struct sockopt_test *t;
16231123c03SMartin KaFai Lau 
16331123c03SMartin KaFai Lau 	if (i >= ARRAY_SIZE(sol_ip_tests))
16431123c03SMartin KaFai Lau 		return 1;
16531123c03SMartin KaFai Lau 
16631123c03SMartin KaFai Lau 	t = &sol_ip_tests[i];
16731123c03SMartin KaFai Lau 	if (!t->opt)
16831123c03SMartin KaFai Lau 		return 1;
16931123c03SMartin KaFai Lau 
17031123c03SMartin KaFai Lau 	if (t->flip)
17131123c03SMartin KaFai Lau 		return bpf_test_sockopt_flip(lc->ctx, lc->sk, t, IPPROTO_IP);
17231123c03SMartin KaFai Lau 
17331123c03SMartin KaFai Lau 	return bpf_test_sockopt_int(lc->ctx, lc->sk, t, IPPROTO_IP);
17431123c03SMartin KaFai Lau }
17531123c03SMartin KaFai Lau 
bpf_test_ipv6_sockopt(__u32 i,struct loop_ctx * lc)17631123c03SMartin KaFai Lau static int bpf_test_ipv6_sockopt(__u32 i, struct loop_ctx *lc)
17731123c03SMartin KaFai Lau {
17831123c03SMartin KaFai Lau 	const struct sockopt_test *t;
17931123c03SMartin KaFai Lau 
18031123c03SMartin KaFai Lau 	if (i >= ARRAY_SIZE(sol_ipv6_tests))
18131123c03SMartin KaFai Lau 		return 1;
18231123c03SMartin KaFai Lau 
18331123c03SMartin KaFai Lau 	t = &sol_ipv6_tests[i];
18431123c03SMartin KaFai Lau 	if (!t->opt)
18531123c03SMartin KaFai Lau 		return 1;
18631123c03SMartin KaFai Lau 
18731123c03SMartin KaFai Lau 	if (t->flip)
18831123c03SMartin KaFai Lau 		return bpf_test_sockopt_flip(lc->ctx, lc->sk, t, IPPROTO_IPV6);
18931123c03SMartin KaFai Lau 
19031123c03SMartin KaFai Lau 	return bpf_test_sockopt_int(lc->ctx, lc->sk, t, IPPROTO_IPV6);
19131123c03SMartin KaFai Lau }
19231123c03SMartin KaFai Lau 
bpf_test_tcp_sockopt(__u32 i,struct loop_ctx * lc)19331123c03SMartin KaFai Lau static int bpf_test_tcp_sockopt(__u32 i, struct loop_ctx *lc)
19431123c03SMartin KaFai Lau {
19531123c03SMartin KaFai Lau 	const struct sockopt_test *t;
19631123c03SMartin KaFai Lau 	struct sock *sk;
19731123c03SMartin KaFai Lau 	void *ctx;
19831123c03SMartin KaFai Lau 
19931123c03SMartin KaFai Lau 	if (i >= ARRAY_SIZE(sol_tcp_tests))
20031123c03SMartin KaFai Lau 		return 1;
20131123c03SMartin KaFai Lau 
20231123c03SMartin KaFai Lau 	t = &sol_tcp_tests[i];
20331123c03SMartin KaFai Lau 	if (!t->opt)
20431123c03SMartin KaFai Lau 		return 1;
20531123c03SMartin KaFai Lau 
20631123c03SMartin KaFai Lau 	ctx = lc->ctx;
20731123c03SMartin KaFai Lau 	sk = lc->sk;
20831123c03SMartin KaFai Lau 
20931123c03SMartin KaFai Lau 	if (t->opt == TCP_CONGESTION) {
21031123c03SMartin KaFai Lau 		char old_cc[16], tmp_cc[16];
21131123c03SMartin KaFai Lau 		const char *new_cc;
2127e165d19SYang Yingliang 		int new_cc_len;
21331123c03SMartin KaFai Lau 
21419707294SMartin KaFai Lau 		if (!bpf_setsockopt(ctx, IPPROTO_TCP, TCP_CONGESTION,
21519707294SMartin KaFai Lau 				    (void *)not_exist_cc, sizeof(not_exist_cc)))
21619707294SMartin KaFai Lau 			return 1;
21731123c03SMartin KaFai Lau 		if (bpf_getsockopt(ctx, IPPROTO_TCP, TCP_CONGESTION, old_cc, sizeof(old_cc)))
21831123c03SMartin KaFai Lau 			return 1;
2197e165d19SYang Yingliang 		if (!bpf_strncmp(old_cc, sizeof(old_cc), cubic_cc)) {
22031123c03SMartin KaFai Lau 			new_cc = reno_cc;
2217e165d19SYang Yingliang 			new_cc_len = sizeof(reno_cc);
2227e165d19SYang Yingliang 		} else {
22331123c03SMartin KaFai Lau 			new_cc = cubic_cc;
2247e165d19SYang Yingliang 			new_cc_len = sizeof(cubic_cc);
2257e165d19SYang Yingliang 		}
22631123c03SMartin KaFai Lau 		if (bpf_setsockopt(ctx, IPPROTO_TCP, TCP_CONGESTION, (void *)new_cc,
2277e165d19SYang Yingliang 				   new_cc_len))
22831123c03SMartin KaFai Lau 			return 1;
22931123c03SMartin KaFai Lau 		if (bpf_getsockopt(ctx, IPPROTO_TCP, TCP_CONGESTION, tmp_cc, sizeof(tmp_cc)))
23031123c03SMartin KaFai Lau 			return 1;
23131123c03SMartin KaFai Lau 		if (bpf_strncmp(tmp_cc, sizeof(tmp_cc), new_cc))
23231123c03SMartin KaFai Lau 			return 1;
23331123c03SMartin KaFai Lau 		if (bpf_setsockopt(ctx, IPPROTO_TCP, TCP_CONGESTION, old_cc, sizeof(old_cc)))
23431123c03SMartin KaFai Lau 			return 1;
23531123c03SMartin KaFai Lau 		return 0;
23631123c03SMartin KaFai Lau 	}
23731123c03SMartin KaFai Lau 
23831123c03SMartin KaFai Lau 	if (t->flip)
23931123c03SMartin KaFai Lau 		return bpf_test_sockopt_flip(ctx, sk, t, IPPROTO_TCP);
24031123c03SMartin KaFai Lau 
24131123c03SMartin KaFai Lau 	return bpf_test_sockopt_int(ctx, sk, t, IPPROTO_TCP);
24231123c03SMartin KaFai Lau }
24331123c03SMartin KaFai Lau 
bpf_test_sockopt(void * ctx,struct sock * sk)24431123c03SMartin KaFai Lau static int bpf_test_sockopt(void *ctx, struct sock *sk)
24531123c03SMartin KaFai Lau {
24631123c03SMartin KaFai Lau 	struct loop_ctx lc = { .ctx = ctx, .sk = sk, };
24731123c03SMartin KaFai Lau 	__u16 family, proto;
24831123c03SMartin KaFai Lau 	int n;
24931123c03SMartin KaFai Lau 
25031123c03SMartin KaFai Lau 	family = sk->sk_family;
25131123c03SMartin KaFai Lau 	proto = sk->sk_protocol;
25231123c03SMartin KaFai Lau 
25331123c03SMartin KaFai Lau 	n = bpf_loop(ARRAY_SIZE(sol_socket_tests), bpf_test_socket_sockopt, &lc, 0);
25431123c03SMartin KaFai Lau 	if (n != ARRAY_SIZE(sol_socket_tests))
25531123c03SMartin KaFai Lau 		return -1;
25631123c03SMartin KaFai Lau 
25731123c03SMartin KaFai Lau 	if (proto == IPPROTO_TCP) {
25831123c03SMartin KaFai Lau 		n = bpf_loop(ARRAY_SIZE(sol_tcp_tests), bpf_test_tcp_sockopt, &lc, 0);
25931123c03SMartin KaFai Lau 		if (n != ARRAY_SIZE(sol_tcp_tests))
26031123c03SMartin KaFai Lau 			return -1;
26131123c03SMartin KaFai Lau 	}
26231123c03SMartin KaFai Lau 
26331123c03SMartin KaFai Lau 	if (family == AF_INET) {
26431123c03SMartin KaFai Lau 		n = bpf_loop(ARRAY_SIZE(sol_ip_tests), bpf_test_ip_sockopt, &lc, 0);
26531123c03SMartin KaFai Lau 		if (n != ARRAY_SIZE(sol_ip_tests))
26631123c03SMartin KaFai Lau 			return -1;
26731123c03SMartin KaFai Lau 	} else {
26831123c03SMartin KaFai Lau 		n = bpf_loop(ARRAY_SIZE(sol_ipv6_tests), bpf_test_ipv6_sockopt, &lc, 0);
26931123c03SMartin KaFai Lau 		if (n != ARRAY_SIZE(sol_ipv6_tests))
27031123c03SMartin KaFai Lau 			return -1;
27131123c03SMartin KaFai Lau 	}
27231123c03SMartin KaFai Lau 
27331123c03SMartin KaFai Lau 	return 0;
27431123c03SMartin KaFai Lau }
27531123c03SMartin KaFai Lau 
binddev_test(void * ctx)27631123c03SMartin KaFai Lau static int binddev_test(void *ctx)
27731123c03SMartin KaFai Lau {
27831123c03SMartin KaFai Lau 	const char empty_ifname[] = "";
27931123c03SMartin KaFai Lau 	int ifindex, zero = 0;
28031123c03SMartin KaFai Lau 
28131123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, SOL_SOCKET, SO_BINDTODEVICE,
28231123c03SMartin KaFai Lau 			   (void *)veth, sizeof(veth)))
28331123c03SMartin KaFai Lau 		return -1;
28431123c03SMartin KaFai Lau 	if (bpf_getsockopt(ctx, SOL_SOCKET, SO_BINDTOIFINDEX,
28531123c03SMartin KaFai Lau 			   &ifindex, sizeof(int)) ||
28631123c03SMartin KaFai Lau 	    ifindex != veth_ifindex)
28731123c03SMartin KaFai Lau 		return -1;
28831123c03SMartin KaFai Lau 
28931123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, SOL_SOCKET, SO_BINDTODEVICE,
29031123c03SMartin KaFai Lau 			   (void *)empty_ifname, sizeof(empty_ifname)))
29131123c03SMartin KaFai Lau 		return -1;
29231123c03SMartin KaFai Lau 	if (bpf_getsockopt(ctx, SOL_SOCKET, SO_BINDTOIFINDEX,
29331123c03SMartin KaFai Lau 			   &ifindex, sizeof(int)) ||
29431123c03SMartin KaFai Lau 	    ifindex != 0)
29531123c03SMartin KaFai Lau 		return -1;
29631123c03SMartin KaFai Lau 
29731123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, SOL_SOCKET, SO_BINDTOIFINDEX,
29831123c03SMartin KaFai Lau 			   (void *)&veth_ifindex, sizeof(int)))
29931123c03SMartin KaFai Lau 		return -1;
30031123c03SMartin KaFai Lau 	if (bpf_getsockopt(ctx, SOL_SOCKET, SO_BINDTOIFINDEX,
30131123c03SMartin KaFai Lau 			   &ifindex, sizeof(int)) ||
30231123c03SMartin KaFai Lau 	    ifindex != veth_ifindex)
30331123c03SMartin KaFai Lau 		return -1;
30431123c03SMartin KaFai Lau 
30531123c03SMartin KaFai Lau 	if (bpf_setsockopt(ctx, SOL_SOCKET, SO_BINDTOIFINDEX,
30631123c03SMartin KaFai Lau 			   &zero, sizeof(int)))
30731123c03SMartin KaFai Lau 		return -1;
30831123c03SMartin KaFai Lau 	if (bpf_getsockopt(ctx, SOL_SOCKET, SO_BINDTOIFINDEX,
30931123c03SMartin KaFai Lau 			   &ifindex, sizeof(int)) ||
31031123c03SMartin KaFai Lau 	    ifindex != 0)
31131123c03SMartin KaFai Lau 		return -1;
31231123c03SMartin KaFai Lau 
31331123c03SMartin KaFai Lau 	return 0;
31431123c03SMartin KaFai Lau }
31531123c03SMartin KaFai Lau 
test_tcp_maxseg(void * ctx,struct sock * sk)316f649f992SMartin KaFai Lau static int test_tcp_maxseg(void *ctx, struct sock *sk)
317f649f992SMartin KaFai Lau {
318f649f992SMartin KaFai Lau 	int val = 1314, tmp;
319f649f992SMartin KaFai Lau 
320f649f992SMartin KaFai Lau 	if (sk->sk_state != TCP_ESTABLISHED)
321f649f992SMartin KaFai Lau 		return bpf_setsockopt(ctx, IPPROTO_TCP, TCP_MAXSEG,
322f649f992SMartin KaFai Lau 				      &val, sizeof(val));
323f649f992SMartin KaFai Lau 
324f649f992SMartin KaFai Lau 	if (bpf_getsockopt(ctx, IPPROTO_TCP, TCP_MAXSEG, &tmp, sizeof(tmp)) ||
325f649f992SMartin KaFai Lau 	    tmp > val)
326f649f992SMartin KaFai Lau 		return -1;
327f649f992SMartin KaFai Lau 
328f649f992SMartin KaFai Lau 	return 0;
329f649f992SMartin KaFai Lau }
330f649f992SMartin KaFai Lau 
test_tcp_saved_syn(void * ctx,struct sock * sk)331f649f992SMartin KaFai Lau static int test_tcp_saved_syn(void *ctx, struct sock *sk)
332f649f992SMartin KaFai Lau {
333f649f992SMartin KaFai Lau 	__u8 saved_syn[20];
334f649f992SMartin KaFai Lau 	int one = 1;
335f649f992SMartin KaFai Lau 
336f649f992SMartin KaFai Lau 	if (sk->sk_state == TCP_LISTEN)
337f649f992SMartin KaFai Lau 		return bpf_setsockopt(ctx, IPPROTO_TCP, TCP_SAVE_SYN,
338f649f992SMartin KaFai Lau 				      &one, sizeof(one));
339f649f992SMartin KaFai Lau 
340f649f992SMartin KaFai Lau 	return bpf_getsockopt(ctx, IPPROTO_TCP, TCP_SAVED_SYN,
341f649f992SMartin KaFai Lau 			      saved_syn, sizeof(saved_syn));
342f649f992SMartin KaFai Lau }
343f649f992SMartin KaFai Lau 
34431123c03SMartin KaFai Lau SEC("lsm_cgroup/socket_post_create")
BPF_PROG(socket_post_create,struct socket * sock,int family,int type,int protocol,int kern)34531123c03SMartin KaFai Lau int BPF_PROG(socket_post_create, struct socket *sock, int family,
34631123c03SMartin KaFai Lau 	     int type, int protocol, int kern)
34731123c03SMartin KaFai Lau {
34831123c03SMartin KaFai Lau 	struct sock *sk = sock->sk;
34931123c03SMartin KaFai Lau 
35031123c03SMartin KaFai Lau 	if (!sk)
35131123c03SMartin KaFai Lau 		return 1;
35231123c03SMartin KaFai Lau 
35331123c03SMartin KaFai Lau 	nr_socket_post_create += !bpf_test_sockopt(sk, sk);
35431123c03SMartin KaFai Lau 	nr_binddev += !binddev_test(sk);
35531123c03SMartin KaFai Lau 
35631123c03SMartin KaFai Lau 	return 1;
35731123c03SMartin KaFai Lau }
35831123c03SMartin KaFai Lau 
35931123c03SMartin KaFai Lau SEC("sockops")
skops_sockopt(struct bpf_sock_ops * skops)36031123c03SMartin KaFai Lau int skops_sockopt(struct bpf_sock_ops *skops)
36131123c03SMartin KaFai Lau {
36231123c03SMartin KaFai Lau 	struct bpf_sock *bpf_sk = skops->sk;
36331123c03SMartin KaFai Lau 	struct sock *sk;
36431123c03SMartin KaFai Lau 
36531123c03SMartin KaFai Lau 	if (!bpf_sk)
36631123c03SMartin KaFai Lau 		return 1;
36731123c03SMartin KaFai Lau 
36831123c03SMartin KaFai Lau 	sk = (struct sock *)bpf_skc_to_tcp_sock(bpf_sk);
36931123c03SMartin KaFai Lau 	if (!sk)
37031123c03SMartin KaFai Lau 		return 1;
37131123c03SMartin KaFai Lau 
37231123c03SMartin KaFai Lau 	switch (skops->op) {
37331123c03SMartin KaFai Lau 	case BPF_SOCK_OPS_TCP_LISTEN_CB:
374f649f992SMartin KaFai Lau 		nr_listen += !(bpf_test_sockopt(skops, sk) ||
375f649f992SMartin KaFai Lau 			       test_tcp_maxseg(skops, sk) ||
376f649f992SMartin KaFai Lau 			       test_tcp_saved_syn(skops, sk));
37731123c03SMartin KaFai Lau 		break;
37831123c03SMartin KaFai Lau 	case BPF_SOCK_OPS_TCP_CONNECT_CB:
379f649f992SMartin KaFai Lau 		nr_connect += !(bpf_test_sockopt(skops, sk) ||
380f649f992SMartin KaFai Lau 				test_tcp_maxseg(skops, sk));
38131123c03SMartin KaFai Lau 		break;
38231123c03SMartin KaFai Lau 	case BPF_SOCK_OPS_ACTIVE_ESTABLISHED_CB:
383f649f992SMartin KaFai Lau 		nr_active += !(bpf_test_sockopt(skops, sk) ||
384f649f992SMartin KaFai Lau 			       test_tcp_maxseg(skops, sk));
38531123c03SMartin KaFai Lau 		break;
38631123c03SMartin KaFai Lau 	case BPF_SOCK_OPS_PASSIVE_ESTABLISHED_CB:
387f649f992SMartin KaFai Lau 		nr_passive += !(bpf_test_sockopt(skops, sk) ||
388f649f992SMartin KaFai Lau 				test_tcp_maxseg(skops, sk) ||
389f649f992SMartin KaFai Lau 				test_tcp_saved_syn(skops, sk));
390*d1246f93SKui-Feng Lee 		bpf_sock_ops_cb_flags_set(skops,
391*d1246f93SKui-Feng Lee 					  skops->bpf_sock_ops_cb_flags |
392*d1246f93SKui-Feng Lee 					  BPF_SOCK_OPS_STATE_CB_FLAG);
393*d1246f93SKui-Feng Lee 		break;
394*d1246f93SKui-Feng Lee 	case BPF_SOCK_OPS_STATE_CB:
395*d1246f93SKui-Feng Lee 		if (skops->args[1] == BPF_TCP_CLOSE_WAIT)
396*d1246f93SKui-Feng Lee 			nr_fin_wait1 += !bpf_test_sockopt(skops, sk);
39731123c03SMartin KaFai Lau 		break;
39831123c03SMartin KaFai Lau 	}
39931123c03SMartin KaFai Lau 
40031123c03SMartin KaFai Lau 	return 1;
40131123c03SMartin KaFai Lau }
40231123c03SMartin KaFai Lau 
40331123c03SMartin KaFai Lau char _license[] SEC("license") = "GPL";
404