2 * Copyright (C) 2008 Jung-uk Kim <jkim@FreeBSD.org>. All rights reserved.
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
13 * THIS SOFTWARE IS PROVIDED BY AUTHOR AND CONTRIBUTORS ``AS IS'' AND
14 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
16 * ARE DISCLAIMED. IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE
17 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
18 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
19 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
20 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
21 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
22 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 #include <sys/cdefs.h>
27 __FBSDID("$FreeBSD$");
33 #include <sys/types.h>
47 static void sig_handler(int);
49 static int nins = sizeof(pc) / sizeof(pc[0]);
50 static int verbose = LOG_LEVEL;
52 #ifdef BPF_JIT_COMPILER
56 #include <net/bpf_jitter.h>
58 bpf_filter_func bpf_jit_compile(struct bpf_insn *, u_int, int *);
61 bpf_compile_and_filter(void)
63 bpf_jit_filter filter;
66 /* Do not use BPF JIT compiler for an empty program */
70 /* Allocate the filter's memory */
71 if ((filter.mem = (int *)malloc(BPF_MEMWORDS * sizeof(int))) == NULL)
74 /* Create the binary */
75 if ((filter.func = bpf_jit_compile(pc, nins, filter.mem)) == NULL)
78 ret = (*(filter.func))(pkt, wirelen, buflen);
86 if (filter.mem != NULL)
90 printf("Failed to allocate memory:\t");
98 u_int bpf_filter(struct bpf_insn *, u_char *, u_int, u_int);
104 * XXX Copied from sys/net/bpf_filter.c and modified.
106 * Return true if the 'fcode' is a valid filter program.
107 * The constraints are that each jump be forward and to a valid
108 * code. The code must terminate with either an accept or reject.
110 * The kernel needs to be able to verify an application's filter code.
111 * Otherwise, a bogus program could easily crash the system.
114 bpf_validate(const struct bpf_insn *f, int len)
117 register const struct bpf_insn *p;
119 /* Do not accept negative length filter. */
123 /* An empty filter means accept all. */
127 for (i = 0; i < len; ++i) {
129 * Check that that jumps are forward, and within
133 if (BPF_CLASS(p->code) == BPF_JMP) {
134 register int from = i + 1;
136 if (BPF_OP(p->code) == BPF_JA) {
137 if (from >= len || p->k >= (u_int)len - from)
140 else if (from >= len || p->jt >= len - from ||
145 * Check that memory operations use valid addresses.
147 if ((BPF_CLASS(p->code) == BPF_ST ||
148 (BPF_CLASS(p->code) == BPF_LD &&
149 (p->code & 0xe0) == BPF_MEM)) &&
150 p->k >= BPF_MEMWORDS)
153 * Check for constant division by 0.
155 if (p->code == (BPF_ALU|BPF_DIV|BPF_K) && p->k == 0)
158 return (BPF_CLASS(f[len - 1].code) == BPF_RET);
171 /* Try to catch all signals */
172 for (sig = SIGHUP; sig <= SIGUSR2; sig++)
173 signal(sig, sig_handler);
176 valid = bpf_validate(pc, nins);
177 if (valid != 0 && invalid != 0) {
179 printf("Validated invalid instructions:\t");
183 } else if (valid == 0 && invalid == 0) {
185 printf("Invalidated valid instructions:\t");
192 #ifdef BPF_JIT_COMPILER
193 ret = bpf_compile_and_filter();
195 ret = bpf_filter(pc, pkt, wirelen, buflen);
199 printf("Expected 0x%x but got 0x%x:\t", expect, ret);
205 printf("Expected and got 0x%x:\t", ret);
216 if (expect_signal == 0) {
218 printf("Received unexpected signal %d:\t", sig);
223 if (expect_signal != sig) {
225 printf("Expected signal %d but got %d:\t",
233 printf("Expected and got signal %d:\t", sig);