gvisor-lx/pkg/ebpf/ebpf.go
Leadaxe 117243aa02 snapshot: sagernet/gvisor v0.0.0-20260727.0-sing-box-mod.1 + SPEC 048 guard
Обновление снапшота с v0.0.0-20250811.0 на пин, которого требует
sing-box после мержа 235 коммитов (upstream d620bbbf2 "Update gvisor to
20260727.0"). Прежний снапшот был взят 2026-08-04 ровно с той версии,
на которой тогда стоял апстрим; разрыв возник 2026-08-05 вместе с его
бампом.

За год апстрим-gvisor изменил ~14 000 строк в 292 файлах. Значимое для
нас — сетевой стек: tcp/connect.go (PMTU-discovery + исправление
начального RTT/RTO: раньше задержка ACK внутри стека завышала стартовый
таймаут на несколько RTT), tcp/snd.go, tcp/rcv.go, stack/conntrack.go,
stack/packet_buffer.go. Всего 30 файлов в TCP и 37 в stack.

Баг SPEC 048 апстрим НЕ исправил — проверено по коду новой версии:
handleConnecting по-прежнему проверяет состояние endpoint'а, но не ep.h,
а performHandshake так же зануляет h и отпускает мьютекс до Close().
Поэтому guard перенесён (12 строк) вместе со своим тестом (45 строк).

Red/green проверен на новой базе: без guard'а тест падает с той же
nil-паникой, что в полевом крашдампе; с ним зелёный.
2026-08-05 14:53:31 +03:00

82 lines
2.3 KiB
Go

// Copyright 2026 The gVisor Authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Package ebpf provides tools for working with extended Berkely Packet Filter (eBPF) programs.
//
// gVisor currently does not support running eBPF programs.
package ebpf
import (
"github.com/sagernet/gvisor/pkg/abi/linux"
)
// BPFID is a sequential, globally-unique (though unloaded
// programs' IDs are reused) ID for an eBPF program.
type BPFID uint32
// UnverifiedProgram represents an eBPF program provided by userspace that has not
// been validated.
//
// +stateify savable
type UnverifiedProgram struct {
// instructions is a list of eBPF instructions.
//
// Immutable.
instructions []linux.EBPFInstruction
}
// NewUnverifiedProgram creates an unverified eBPF program from a set of instructions.
func NewUnverifiedProgram(instructions []linux.EBPFInstruction) UnverifiedProgram {
return UnverifiedProgram{
instructions: instructions,
}
}
// Program represents an eBPF program that has been validated.
//
// All fields of Program are immutable.
//
// +stateify savable
type Program struct {
// instructions is a list of eBPF instructions.
instructions []linux.EBPFInstruction
// id is the program's ID.
id BPFID
// progType is the program's type.
progType linux.BPFProgramType
}
// ID returns the unique identifier for the eBPF program.
func (p *Program) ID() BPFID {
return p.id
}
// ProgType returns the type of the eBPF program.
func (p *Program) ProgType() linux.BPFProgramType {
return p.progType
}
// Validate validates an unverified eBPF program.
//
// Currently, no validation is performed, so the resulting program MUST not be run.
func (uprog *UnverifiedProgram) Validate(id BPFID, progType linux.BPFProgramType) (Program, error) {
prog := Program{
instructions: uprog.instructions,
id: id,
progType: progType,
}
return prog, nil
}