mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
conntrack refactor, no behavior changes
- Split connTrackForPacket into 2 functions instead of switching on flag - Replace hash with struct keys. - Remove prefixes where possible - Remove unused connStatus, timeout - Flatten ConnTrack struct a bit - some intermediate structs had no meaning outside of the context of their parent. - Protect conn.tcb with a mutex - Remove redundant error checking (e.g. when is pkt.NetworkHeader valid) - Clarify that HandlePacket and CreateConnFor are the expected entrypoints for ConnTrack PiperOrigin-RevId: 318407168
This commit is contained in:
committed by
gVisor bot
parent
4069461877
commit
7fb6cc286f
@@ -30,6 +30,6 @@ type JumpTarget struct {
|
||||
}
|
||||
|
||||
// Action implements stack.Target.Action.
|
||||
func (jt JumpTarget) Action(*stack.PacketBuffer, *stack.ConnTrackTable, stack.Hook, *stack.GSO, *stack.Route, tcpip.Address) (stack.RuleVerdict, int) {
|
||||
func (jt JumpTarget) Action(*stack.PacketBuffer, *stack.ConnTrack, stack.Hook, *stack.GSO, *stack.Route, tcpip.Address) (stack.RuleVerdict, int) {
|
||||
return stack.RuleJump, jt.RuleNum
|
||||
}
|
||||
|
||||
+161
-264
File diff suppressed because it is too large
Load Diff
@@ -111,9 +111,8 @@ func DefaultTables() *IPTables {
|
||||
Prerouting: []string{TablenameMangle, TablenameNat},
|
||||
Output: []string{TablenameMangle, TablenameNat, TablenameFilter},
|
||||
},
|
||||
connections: ConnTrackTable{
|
||||
CtMap: make(map[uint32]ConnTrackTupleHolder),
|
||||
Seed: generateRandUint32(),
|
||||
connections: ConnTrack{
|
||||
conns: make(map[tupleID]tuple),
|
||||
},
|
||||
}
|
||||
}
|
||||
@@ -213,7 +212,7 @@ func (it *IPTables) Check(hook Hook, pkt *PacketBuffer, gso *GSO, r *Route, addr
|
||||
|
||||
// Packets are manipulated only if connection and matching
|
||||
// NAT rule exists.
|
||||
it.connections.HandlePacket(pkt, hook, gso, r)
|
||||
it.connections.handlePacket(pkt, hook, gso, r)
|
||||
|
||||
// Go through each table containing the hook.
|
||||
for _, tablename := range it.GetPriorities(hook) {
|
||||
|
||||
@@ -24,7 +24,7 @@ import (
|
||||
type AcceptTarget struct{}
|
||||
|
||||
// Action implements Target.Action.
|
||||
func (AcceptTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
func (AcceptTarget) Action(*PacketBuffer, *ConnTrack, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
return RuleAccept, 0
|
||||
}
|
||||
|
||||
@@ -32,7 +32,7 @@ func (AcceptTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, t
|
||||
type DropTarget struct{}
|
||||
|
||||
// Action implements Target.Action.
|
||||
func (DropTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
func (DropTarget) Action(*PacketBuffer, *ConnTrack, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
return RuleDrop, 0
|
||||
}
|
||||
|
||||
@@ -41,7 +41,7 @@ func (DropTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, tcp
|
||||
type ErrorTarget struct{}
|
||||
|
||||
// Action implements Target.Action.
|
||||
func (ErrorTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
func (ErrorTarget) Action(*PacketBuffer, *ConnTrack, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
log.Debugf("ErrorTarget triggered.")
|
||||
return RuleDrop, 0
|
||||
}
|
||||
@@ -52,7 +52,7 @@ type UserChainTarget struct {
|
||||
}
|
||||
|
||||
// Action implements Target.Action.
|
||||
func (UserChainTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
func (UserChainTarget) Action(*PacketBuffer, *ConnTrack, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
panic("UserChainTarget should never be called.")
|
||||
}
|
||||
|
||||
@@ -61,7 +61,7 @@ func (UserChainTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route
|
||||
type ReturnTarget struct{}
|
||||
|
||||
// Action implements Target.Action.
|
||||
func (ReturnTarget) Action(*PacketBuffer, *ConnTrackTable, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
func (ReturnTarget) Action(*PacketBuffer, *ConnTrack, Hook, *GSO, *Route, tcpip.Address) (RuleVerdict, int) {
|
||||
return RuleReturn, 0
|
||||
}
|
||||
|
||||
@@ -92,7 +92,7 @@ type RedirectTarget struct {
|
||||
// TODO(gvisor.dev/issue/170): Parse headers without copying. The current
|
||||
// implementation only works for PREROUTING and calls pkt.Clone(), neither
|
||||
// of which should be the case.
|
||||
func (rt RedirectTarget) Action(pkt *PacketBuffer, ct *ConnTrackTable, hook Hook, gso *GSO, r *Route, address tcpip.Address) (RuleVerdict, int) {
|
||||
func (rt RedirectTarget) Action(pkt *PacketBuffer, ct *ConnTrack, hook Hook, gso *GSO, r *Route, address tcpip.Address) (RuleVerdict, int) {
|
||||
// Packet is already manipulated.
|
||||
if pkt.NatDone {
|
||||
return RuleAccept, 0
|
||||
@@ -150,12 +150,11 @@ func (rt RedirectTarget) Action(pkt *PacketBuffer, ct *ConnTrackTable, hook Hook
|
||||
return RuleAccept, 0
|
||||
}
|
||||
|
||||
// Set up conection for matching NAT rule.
|
||||
// Only the first packet of the connection comes here.
|
||||
// Other packets will be manipulated in connection tracking.
|
||||
if conn, _ := ct.connTrackForPacket(pkt, hook, true); conn != nil {
|
||||
ct.SetNatInfo(pkt, rt, hook)
|
||||
ct.HandlePacket(pkt, hook, gso, r)
|
||||
// Set up conection for matching NAT rule. Only the first
|
||||
// packet of the connection comes here. Other packets will be
|
||||
// manipulated in connection tracking.
|
||||
if conn := ct.createConnFor(pkt, hook, rt); conn != nil {
|
||||
ct.handlePacket(pkt, hook, gso, r)
|
||||
}
|
||||
default:
|
||||
return RuleDrop, 0
|
||||
|
||||
@@ -96,7 +96,7 @@ type IPTables struct {
|
||||
// don't utilize iptables.
|
||||
modified bool
|
||||
|
||||
connections ConnTrackTable
|
||||
connections ConnTrack
|
||||
}
|
||||
|
||||
// A Table defines a set of chains and hooks into the network stack. It is
|
||||
@@ -249,5 +249,5 @@ type Target interface {
|
||||
// Action takes an action on the packet and returns a verdict on how
|
||||
// traversal should (or should not) continue. If the return value is
|
||||
// Jump, it also returns the index of the rule to jump to.
|
||||
Action(packet *PacketBuffer, connections *ConnTrackTable, hook Hook, gso *GSO, r *Route, address tcpip.Address) (RuleVerdict, int)
|
||||
Action(packet *PacketBuffer, connections *ConnTrack, hook Hook, gso *GSO, r *Route, address tcpip.Address) (RuleVerdict, int)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user