-
Notifications
You must be signed in to change notification settings - Fork 0
/
pkfilter.go
103 lines (92 loc) · 2.29 KB
/
pkfilter.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
package main
import (
"context"
"fmt"
"log"
"github.com/dropbox/goebpf"
)
func PkfilterInit(ctx context.Context, blacklistCh, unblockCh chan string) {
// Specify Interface Name
interfaceName := "lo"
// Load XDP Into App
bpf := goebpf.NewDefaultEbpfSystem()
err := bpf.LoadElf("PacketFilter/pkfilter.elf")
if err != nil {
log.Fatalf("LoadELF() failed: %s", err)
}
blacklist := bpf.GetMapByName("blacklist")
if blacklist == nil {
log.Fatalf("eBPF map 'blacklist' not found\n")
}
xdp := bpf.GetProgramByName("firewall")
if xdp == nil {
log.Fatalln("Program 'firewall' not found in Program")
}
err = xdp.Load()
if err != nil {
fmt.Printf("xdp.Attach(): %v", err)
}
err = xdp.Attach(interfaceName)
if err != nil {
log.Fatalf("Error attaching to Interface: %s", err)
}
//Ensure xdp.Detach() is called when the function exits
defer func() {
log.Println("\nDetaching XDP program...")
err := xdp.Detach()
if err != nil {
log.Printf("\nError detaching XDP program: %v 😨", err)
fmt.Printf("\nError detaching XDP program: %v 😨", err)
} else {
log.Println("\nXDP program successfully detached 😌")
fmt.Println("\nXDP program successfully detached 😌")
}
}()
// Listen for new blacklisted IPs
go func() {
for {
select {
case ip := <-blacklistCh:
err := BlockIPAddress(ip, blacklist)
if err != nil {
log.Printf("Failed to block IP %s: %v 💀", ip, err)
}
case <-ctx.Done():
return
}
}
}()
go func() {
for {
select {
case ip := <-unblockCh:
err := UnblockIPAddress(ip, blacklist)
if err != nil {
log.Printf("Failed to unblock IP %s: %v 💀", ip, err)
}
case <-ctx.Done():
return
}
}
}()
log.Println("XDP Program Loaded successfully into the Kernel.")
log.Println("Press CTRL+C to stop.")
// Wait for context cancellation
<-ctx.Done()
log.Println("Received signal to stop. Preparing to detach XDP program...")
}
// The Function That adds the IPs to the blacklist map
func BlockIPAddress(ip string, blacklist goebpf.Map) error {
err := blacklist.Insert(goebpf.CreateLPMtrieKey(ip), 1)
if err != nil {
return err
}
return nil
}
func UnblockIPAddress(ip string, blacklist goebpf.Map) error {
err := blacklist.Delete(goebpf.CreateLPMtrieKey(ip))
if err != nil {
return err
}
return nil
}