1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
// Copyright 2021 Authors of redBPF
//
// Licensed under the Apache License, Version 2.0, <LICENSE-APACHE or
// http://apache.org/licenses/LICENSE-2.0> or the MIT license <LICENSE-MIT or
// http://opensource.org/licenses/MIT>, at your option. This file may not be
// copied, modified, or distributed except according to those terms.
/*!
BPF for tc utility
tc supports attaching BPF programs to `clsact` qdisc as a direct action. You
can write BPF programs and BPF maps using `redBPF`.
# Example
```no_run
#![no_std]
#![no_main]
use redbpf_macros::map;
use redbpf_probes::tc::prelude::*;
program!(0xFFFFFFFE, "GPL");
#[map(link_section = "maps")]
static mut blocked_packets: TcHashMap<u16, u64> =
TcHashMap::<u16, u64>::with_max_entries(1024, TcMapPinning::GlobalNamespace);
#[tc_action]
fn block_ports(skb: SkBuff) -> TcActionResult {
// do some stuff ...
let port = 714;
if let Some(count) = unsafe { blocked_packets.get(&port) } {
*count += 1;
Ok(TcAction::Shot)
} else {
Ok(TcAction::Ok)
}
}
```
*/
use crateSocketError;
/// Possible actions in tc programs
///
/// Allowed return opcodes from BPF programs are listed at
/// <https://elixir.bootlin.com/linux/v5.13.2/source/net/sched/cls_bpf.c#L65>
/// Result type for tc action programs.
pub type TcActionResult = ;