2023-11-03 03:22:56 +01:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-or-later
|
|
|
|
|
|
|
|
/* PASST - Plug A Simple Socket Transport
|
|
|
|
* for qemu/UNIX domain socket mode
|
|
|
|
*
|
|
|
|
* PASTA - Pack A Subtle Tap Abstraction
|
|
|
|
* for network namespace/tap device mode
|
|
|
|
*
|
|
|
|
* port_fwd.c - Port forwarding helpers
|
|
|
|
*
|
|
|
|
* Copyright Red Hat
|
|
|
|
* Author: Stefano Brivio <sbrivio@redhat.com>
|
|
|
|
* Author: David Gibson <david@gibson.dropbear.id.au>
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <stdint.h>
|
|
|
|
#include <errno.h>
|
|
|
|
#include <fcntl.h>
|
|
|
|
#include <sched.h>
|
|
|
|
|
|
|
|
#include "util.h"
|
|
|
|
#include "port_fwd.h"
|
|
|
|
#include "passt.h"
|
|
|
|
#include "lineread.h"
|
|
|
|
|
2023-11-03 03:22:57 +01:00
|
|
|
/* See enum in kernel's include/net/tcp_states.h */
|
|
|
|
#define UDP_LISTEN 0x07
|
|
|
|
#define TCP_LISTEN 0x0a
|
|
|
|
|
2023-11-03 03:22:56 +01:00
|
|
|
/**
|
|
|
|
* procfs_scan_listen() - Set bits for listening TCP or UDP sockets from procfs
|
2023-11-03 03:22:59 +01:00
|
|
|
* @fd: fd for relevant /proc/net file
|
2023-11-03 03:22:57 +01:00
|
|
|
* @lstate: Code for listening state to scan for
|
2023-11-03 03:22:56 +01:00
|
|
|
* @map: Bitmap where numbers of ports in listening state will be set
|
|
|
|
* @exclude: Bitmap of ports to exclude from setting (and clear)
|
|
|
|
*
|
|
|
|
* #syscalls:pasta lseek
|
|
|
|
* #syscalls:pasta ppc64le:_llseek ppc64:_llseek armv6l:_llseek armv7l:_llseek
|
|
|
|
*/
|
2023-11-03 03:22:59 +01:00
|
|
|
static void procfs_scan_listen(int fd, unsigned int lstate,
|
2023-11-03 03:22:57 +01:00
|
|
|
uint8_t *map, const uint8_t *exclude)
|
2023-11-03 03:22:56 +01:00
|
|
|
{
|
|
|
|
struct lineread lr;
|
|
|
|
unsigned long port;
|
|
|
|
unsigned int state;
|
2023-11-03 03:22:57 +01:00
|
|
|
char *line;
|
2023-11-03 03:22:56 +01:00
|
|
|
|
2023-11-03 03:22:59 +01:00
|
|
|
if (lseek(fd, 0, SEEK_SET)) {
|
|
|
|
warn("lseek() failed on /proc/net file: %s", strerror(errno));
|
2023-11-03 03:22:56 +01:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2023-11-03 03:22:59 +01:00
|
|
|
lineread_init(&lr, fd);
|
2023-11-03 03:22:56 +01:00
|
|
|
lineread_get(&lr, &line); /* throw away header */
|
|
|
|
while (lineread_get(&lr, &line) > 0) {
|
|
|
|
/* NOLINTNEXTLINE(cert-err34-c): != 2 if conversion fails */
|
|
|
|
if (sscanf(line, "%*u: %*x:%lx %*x:%*x %x", &port, &state) != 2)
|
|
|
|
continue;
|
|
|
|
|
2023-11-03 03:22:57 +01:00
|
|
|
if (state != lstate)
|
2023-11-03 03:22:56 +01:00
|
|
|
continue;
|
|
|
|
|
|
|
|
if (bitmap_isset(exclude, port))
|
|
|
|
bitmap_clear(map, port);
|
|
|
|
else
|
|
|
|
bitmap_set(map, port);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2023-11-03 03:23:01 +01:00
|
|
|
* get_bound_ports_tcp() - Get maps of TCP ports with bound sockets
|
2023-11-03 03:22:56 +01:00
|
|
|
* @c: Execution context
|
|
|
|
* @ns: If set, set bitmaps for ports to tap/ns -- to init otherwise
|
|
|
|
*/
|
2023-11-03 03:23:01 +01:00
|
|
|
void get_bound_ports_tcp(struct ctx *c, int ns)
|
2023-11-03 03:22:56 +01:00
|
|
|
{
|
2023-11-03 03:23:01 +01:00
|
|
|
uint8_t *map, *excl;
|
2023-11-03 03:22:56 +01:00
|
|
|
|
|
|
|
if (ns) {
|
2023-11-03 03:23:01 +01:00
|
|
|
map = c->tcp.fwd_in.map;
|
|
|
|
excl = c->tcp.fwd_out.map;
|
2023-11-03 03:22:56 +01:00
|
|
|
} else {
|
2023-11-03 03:23:01 +01:00
|
|
|
map = c->tcp.fwd_out.map;
|
|
|
|
excl = c->tcp.fwd_in.map;
|
2023-11-03 03:22:56 +01:00
|
|
|
}
|
|
|
|
|
2023-11-03 03:23:01 +01:00
|
|
|
memset(map, 0, PORT_BITMAP_SIZE);
|
|
|
|
procfs_scan_listen(c->proc_net_tcp[V4][ns], TCP_LISTEN, map, excl);
|
|
|
|
procfs_scan_listen(c->proc_net_tcp[V6][ns], TCP_LISTEN, map, excl);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* get_bound_ports_udp() - Get maps of UDP ports with bound sockets
|
|
|
|
* @c: Execution context
|
|
|
|
* @ns: If set, set bitmaps for ports to tap/ns -- to init otherwise
|
|
|
|
*/
|
|
|
|
void get_bound_ports_udp(struct ctx *c, int ns)
|
|
|
|
{
|
|
|
|
uint8_t *map, *excl;
|
|
|
|
|
|
|
|
if (ns) {
|
|
|
|
map = c->udp.fwd_in.f.map;
|
|
|
|
excl = c->udp.fwd_out.f.map;
|
|
|
|
} else {
|
|
|
|
map = c->udp.fwd_out.f.map;
|
|
|
|
excl = c->udp.fwd_in.f.map;
|
2023-11-03 03:22:56 +01:00
|
|
|
}
|
2023-11-03 03:23:01 +01:00
|
|
|
|
|
|
|
memset(map, 0, PORT_BITMAP_SIZE);
|
|
|
|
procfs_scan_listen(c->proc_net_udp[V4][ns], UDP_LISTEN, map, excl);
|
|
|
|
procfs_scan_listen(c->proc_net_udp[V6][ns], UDP_LISTEN, map, excl);
|
|
|
|
|
|
|
|
/* Also forward UDP ports with the same numbers as bound TCP ports.
|
|
|
|
* This is useful for a handful of protocols (e.g. iperf3) where a TCP
|
|
|
|
* control port is used to set up transfers on a corresponding UDP
|
|
|
|
* port.
|
|
|
|
*/
|
|
|
|
procfs_scan_listen(c->proc_net_tcp[V4][ns], TCP_LISTEN, map, excl);
|
|
|
|
procfs_scan_listen(c->proc_net_tcp[V6][ns], TCP_LISTEN, map, excl);
|
2023-11-03 03:22:56 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* port_fwd_init() - Initial setup for port forwarding
|
|
|
|
* @c: Execution context
|
|
|
|
*/
|
|
|
|
void port_fwd_init(struct ctx *c)
|
|
|
|
{
|
2023-11-03 03:22:59 +01:00
|
|
|
const int flags = O_RDONLY | O_CLOEXEC;
|
2023-11-03 03:22:56 +01:00
|
|
|
|
|
|
|
c->proc_net_tcp[V4][0] = c->proc_net_tcp[V4][1] = -1;
|
|
|
|
c->proc_net_tcp[V6][0] = c->proc_net_tcp[V6][1] = -1;
|
|
|
|
c->proc_net_udp[V4][0] = c->proc_net_udp[V4][1] = -1;
|
|
|
|
c->proc_net_udp[V6][0] = c->proc_net_udp[V6][1] = -1;
|
|
|
|
|
|
|
|
if (c->tcp.fwd_in.mode == FWD_AUTO) {
|
2023-11-03 03:22:59 +01:00
|
|
|
c->proc_net_tcp[V4][1] = open_in_ns(c, "/proc/net/tcp", flags);
|
|
|
|
c->proc_net_tcp[V6][1] = open_in_ns(c, "/proc/net/tcp6", flags);
|
2023-11-03 03:23:01 +01:00
|
|
|
get_bound_ports_tcp(c, 1);
|
2023-11-03 03:22:56 +01:00
|
|
|
}
|
|
|
|
if (c->udp.fwd_in.f.mode == FWD_AUTO) {
|
2023-11-03 03:22:59 +01:00
|
|
|
c->proc_net_udp[V4][1] = open_in_ns(c, "/proc/net/udp", flags);
|
|
|
|
c->proc_net_udp[V6][1] = open_in_ns(c, "/proc/net/udp6", flags);
|
2023-11-03 03:23:01 +01:00
|
|
|
get_bound_ports_udp(c, 1);
|
2023-11-03 03:22:56 +01:00
|
|
|
}
|
2023-11-03 03:22:59 +01:00
|
|
|
if (c->tcp.fwd_out.mode == FWD_AUTO) {
|
|
|
|
c->proc_net_tcp[V4][0] = open("/proc/net/tcp", flags);
|
|
|
|
c->proc_net_tcp[V6][0] = open("/proc/net/tcp6", flags);
|
2023-11-03 03:23:01 +01:00
|
|
|
get_bound_ports_tcp(c, 0);
|
2023-11-03 03:22:59 +01:00
|
|
|
}
|
|
|
|
if (c->udp.fwd_out.f.mode == FWD_AUTO) {
|
|
|
|
c->proc_net_udp[V4][0] = open("/proc/net/udp", flags);
|
|
|
|
c->proc_net_udp[V6][0] = open("/proc/net/udp6", flags);
|
2023-11-03 03:23:01 +01:00
|
|
|
get_bound_ports_udp(c, 0);
|
2023-11-03 03:22:59 +01:00
|
|
|
}
|
2023-11-03 03:22:56 +01:00
|
|
|
}
|