Commit Graph
5 Commits
Author SHA1 Message Date
Sahilb315 a4b99e40e7 feat(ebpf-poc): redirect eligible connections to the proxy
Turns the recorded ACTION_REDIRECT decision into an actual rewrite of
user_ip4 and user_port, so a connection that would have reached the
registry directly lands on the configured target instead.

The target address is copied out of the map as is. It is already held
in network byte order, the same layout as ctx->user_ip4, so converting
it again silently corrupts the destination: 127.0.0.1 becomes 1.0.0.127,
which is routable, never answers, and shows up as a two minute hang
rather than an error. Only the port is converted, since it is kept in
host order for the userspace side.

Verified against a dummy listener. curl to an external HTTPS host is
logged as REDIRECT against its original destination, and the TLS
ClientHello arrives on the local target.
2026-07-27 14:18:47 +05:30
Sahilb315 05a484ea5e implement decision logic 2026-07-27 13:51:09 +05:30
Sahilb315 b8e12c27ae fix main.go 2026-07-24 22:54:20 +05:30
Sahilb315 da6e10d2ad add protocol field 2026-07-24 22:40:35 +05:30
Sahilb315 3e1ece3257 visibility setup with ebpf 2026-07-24 21:23:23 +05:30