mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
Turns the recorded ACTION_REDIRECT decision into an actual rewrite of user_ip4 and user_port, so a connection that would have reached the registry directly lands on the configured target instead. The target address is copied out of the map as is. It is already held in network byte order, the same layout as ctx->user_ip4, so converting it again silently corrupts the destination: 127.0.0.1 becomes 1.0.0.127, which is routable, never answers, and shows up as a two minute hang rather than an error. Only the port is converted, since it is kept in host order for the userspace side. Verified against a dummy listener. curl to an external HTTPS host is logged as REDIRECT against its original destination, and the TLS ClientHello arrives on the local target.
42 lines
722 B
Plaintext
42 lines
722 B
Plaintext
# If you prefer the allow list template instead of the deny list, see community template:
|
|
# https://github.com/github/gitignore/blob/main/community/Golang/Go.AllowList.gitignore
|
|
#
|
|
# Binaries for programs and plugins
|
|
*.exe
|
|
*.exe~
|
|
*.dll
|
|
*.so
|
|
*.dylib
|
|
|
|
# Test binary, built with `go test -c`
|
|
*.test
|
|
|
|
# Output of the go coverage tool, specifically when used with LiteIDE
|
|
*.out
|
|
|
|
# Dependency directories (remove the comment below to include it)
|
|
# vendor/
|
|
|
|
bin/
|
|
|
|
# env file
|
|
.env
|
|
|
|
dist/
|
|
.DS_Store
|
|
|
|
# Nx
|
|
.nx/
|
|
node_modules/
|
|
|
|
# Platform package binaries (populated by sync-binaries at build time)
|
|
packages/*/bin/
|
|
|
|
# Build artifacts in wrapper package
|
|
packages/pmg/dist/
|
|
packages/pmg/README.md
|
|
|
|
ebpf-poc/pmgwatch
|
|
go.work.sum
|
|
pmgwatch
|