1 /* 2 * Decoder of socket filter programs. 3 * 4 * Copyright (c) 2017 Dmitry V. Levin <ldv (at) altlinux.org> 5 * All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. The name of the author may not be used to endorse or promote products 16 * derived from this software without specific prior written permission. 17 * 18 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 19 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 20 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 21 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 22 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 23 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 24 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 25 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 26 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 27 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 28 */ 29 30 #include "defs.h" 31 32 #include "bpf_filter.h" 33 34 #include <linux/filter.h> 35 #include "xlat/skf_ad.h" 36 37 static bool 38 print_sock_filter_k(const struct bpf_filter_block *const fp) 39 { 40 if (BPF_CLASS(fp->code) == BPF_LD && BPF_MODE(fp->code) == BPF_ABS) { 41 if (fp->k >= (unsigned int) SKF_AD_OFF) { 42 tprints("SKF_AD_OFF+"); 43 printxval(skf_ad, fp->k - (unsigned int) SKF_AD_OFF, 44 "SKF_AD_???"); 45 return true; 46 } else if (fp->k >= (unsigned int) SKF_NET_OFF) { 47 tprintf("%s+%u", "SKF_NET_OFF", 48 fp->k - (unsigned int) SKF_NET_OFF); 49 return true; 50 } else if (fp->k >= (unsigned int) SKF_LL_OFF) { 51 tprintf("%s+%u", "SKF_LL_OFF", 52 fp->k - (unsigned int) SKF_LL_OFF); 53 return true; 54 } 55 } 56 57 return false; 58 } 59 60 void 61 print_sock_fprog(struct tcb *const tcp, const kernel_ulong_t addr, 62 const unsigned short len) 63 { 64 print_bpf_fprog(tcp, addr, len, print_sock_filter_k); 65 } 66 67 void 68 decode_sock_fprog(struct tcb *const tcp, const kernel_ulong_t addr) 69 { 70 decode_bpf_fprog(tcp, addr, print_sock_filter_k); 71 } 72