feat(ebpf-poc): redirect eligible connections to the proxy

Turns the recorded ACTION_REDIRECT decision into an actual rewrite of
user_ip4 and user_port, so a connection that would have reached the
registry directly lands on the configured target instead.

The target address is copied out of the map as is. It is already held
in network byte order, the same layout as ctx->user_ip4, so converting
it again silently corrupts the destination: 127.0.0.1 becomes 1.0.0.127,
which is routable, never answers, and shows up as a two minute hang
rather than an error. Only the port is converted, since it is kept in
host order for the userspace side.

Verified against a dummy listener. curl to an external HTTPS host is
logged as REDIRECT against its original destination, and the TLS
ClientHello arrives on the local target.
This commit is contained in:
Sahilb315
2026-07-27 14:18:47 +05:30
parent 05a484ea5e
commit a4b99e40e7
5 changed files with 21 additions and 5 deletions
+4
View File
@@ -35,3 +35,7 @@ packages/*/bin/
# Build artifacts in wrapper package
packages/pmg/dist/
packages/pmg/README.md
ebpf-poc/pmgwatch
go.work.sum
pmgwatch