Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 1 | /* |
| 2 | * |
| 3 | * Generic internet FLOW. |
| 4 | * |
| 5 | */ |
| 6 | |
| 7 | #ifndef _NET_FLOW_H |
| 8 | #define _NET_FLOW_H |
| 9 | |
dpward | aa1c366 | 2011-09-05 16:47:24 +0000 | [diff] [blame] | 10 | #include <linux/socket.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 11 | #include <linux/in6.h> |
Arun Sharma | 60063497 | 2011-07-26 16:09:06 -0700 | [diff] [blame] | 12 | #include <linux/atomic.h> |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 13 | #include <net/flow_dissector.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 14 | |
Cong Wang | 6a66271 | 2014-04-15 16:25:34 -0700 | [diff] [blame] | 15 | /* |
| 16 | * ifindex generation is per-net namespace, and loopback is |
| 17 | * always the 1st device in ns (see net_dev_init), thus any |
| 18 | * loopback device should get ifindex 1 |
| 19 | */ |
| 20 | |
| 21 | #define LOOPBACK_IFINDEX 1 |
| 22 | |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 23 | struct flowi_tunnel { |
| 24 | __be64 tun_id; |
| 25 | }; |
| 26 | |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 27 | struct flowi_common { |
| 28 | int flowic_oif; |
| 29 | int flowic_iif; |
| 30 | __u32 flowic_mark; |
| 31 | __u8 flowic_tos; |
| 32 | __u8 flowic_scope; |
| 33 | __u8 flowic_proto; |
| 34 | __u8 flowic_flags; |
David S. Miller | fbef0a4 | 2011-03-11 15:55:37 -0500 | [diff] [blame] | 35 | #define FLOWI_FLAG_ANYSRC 0x01 |
Steffen Klassert | 0e0d44a | 2013-08-28 08:04:14 +0200 | [diff] [blame] | 36 | #define FLOWI_FLAG_KNOWN_NH 0x02 |
David Ahern | 6e2895a | 2015-10-05 08:51:23 -0700 | [diff] [blame] | 37 | #define FLOWI_FLAG_L3MDEV_SRC 0x04 |
David Ahern | 58189ca | 2015-09-15 15:10:50 -0700 | [diff] [blame] | 38 | #define FLOWI_FLAG_SKIP_NH_OIF 0x08 |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 39 | __u32 flowic_secid; |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 40 | struct flowi_tunnel flowic_tun_key; |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 41 | }; |
| 42 | |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 43 | union flowi_uli { |
| 44 | struct { |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 45 | __be16 dport; |
David S. Miller | 9b12c75 | 2011-03-31 18:03:35 -0700 | [diff] [blame] | 46 | __be16 sport; |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 47 | } ports; |
| 48 | |
| 49 | struct { |
| 50 | __u8 type; |
| 51 | __u8 code; |
| 52 | } icmpt; |
| 53 | |
| 54 | struct { |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 55 | __le16 dport; |
David S. Miller | 9b12c75 | 2011-03-31 18:03:35 -0700 | [diff] [blame] | 56 | __le16 sport; |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 57 | } dnports; |
| 58 | |
| 59 | __be32 spi; |
| 60 | __be32 gre_key; |
| 61 | |
| 62 | struct { |
| 63 | __u8 type; |
| 64 | } mht; |
| 65 | }; |
| 66 | |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 67 | struct flowi4 { |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 68 | struct flowi_common __fl_common; |
David S. Miller | 22bd5b9 | 2011-03-11 19:54:08 -0500 | [diff] [blame] | 69 | #define flowi4_oif __fl_common.flowic_oif |
| 70 | #define flowi4_iif __fl_common.flowic_iif |
| 71 | #define flowi4_mark __fl_common.flowic_mark |
| 72 | #define flowi4_tos __fl_common.flowic_tos |
| 73 | #define flowi4_scope __fl_common.flowic_scope |
| 74 | #define flowi4_proto __fl_common.flowic_proto |
| 75 | #define flowi4_flags __fl_common.flowic_flags |
| 76 | #define flowi4_secid __fl_common.flowic_secid |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 77 | #define flowi4_tun_key __fl_common.flowic_tun_key |
Eric Dumazet | 84f9307 | 2011-11-30 19:00:53 +0000 | [diff] [blame] | 78 | |
| 79 | /* (saddr,daddr) must be grouped, same order as in IP header */ |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 80 | __be32 saddr; |
Eric Dumazet | 84f9307 | 2011-11-30 19:00:53 +0000 | [diff] [blame] | 81 | __be32 daddr; |
| 82 | |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 83 | union flowi_uli uli; |
David S. Miller | 9cce96d | 2011-03-12 03:00:33 -0500 | [diff] [blame] | 84 | #define fl4_sport uli.ports.sport |
| 85 | #define fl4_dport uli.ports.dport |
| 86 | #define fl4_icmp_type uli.icmpt.type |
| 87 | #define fl4_icmp_code uli.icmpt.code |
| 88 | #define fl4_ipsec_spi uli.spi |
| 89 | #define fl4_mh_type uli.mht.type |
| 90 | #define fl4_gre_key uli.gre_key |
David Ward | 728871b | 2011-09-05 16:47:23 +0000 | [diff] [blame] | 91 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 92 | |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 93 | static inline void flowi4_init_output(struct flowi4 *fl4, int oif, |
| 94 | __u32 mark, __u8 tos, __u8 scope, |
| 95 | __u8 proto, __u8 flags, |
| 96 | __be32 daddr, __be32 saddr, |
Eric Dumazet | 747465e | 2012-01-16 19:27:39 +0000 | [diff] [blame] | 97 | __be16 dport, __be16 sport) |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 98 | { |
| 99 | fl4->flowi4_oif = oif; |
Cong Wang | 6a66271 | 2014-04-15 16:25:34 -0700 | [diff] [blame] | 100 | fl4->flowi4_iif = LOOPBACK_IFINDEX; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 101 | fl4->flowi4_mark = mark; |
| 102 | fl4->flowi4_tos = tos; |
| 103 | fl4->flowi4_scope = scope; |
| 104 | fl4->flowi4_proto = proto; |
| 105 | fl4->flowi4_flags = flags; |
| 106 | fl4->flowi4_secid = 0; |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 107 | fl4->flowi4_tun_key.tun_id = 0; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 108 | fl4->daddr = daddr; |
| 109 | fl4->saddr = saddr; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 110 | fl4->fl4_dport = dport; |
David S. Miller | 9b12c75 | 2011-03-31 18:03:35 -0700 | [diff] [blame] | 111 | fl4->fl4_sport = sport; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 112 | } |
Julian Anastasov | e6b4524 | 2012-02-04 13:04:46 +0000 | [diff] [blame] | 113 | |
| 114 | /* Reset some input parameters after previous lookup */ |
| 115 | static inline void flowi4_update_output(struct flowi4 *fl4, int oif, __u8 tos, |
| 116 | __be32 daddr, __be32 saddr) |
| 117 | { |
| 118 | fl4->flowi4_oif = oif; |
| 119 | fl4->flowi4_tos = tos; |
| 120 | fl4->daddr = daddr; |
| 121 | fl4->saddr = saddr; |
| 122 | } |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 123 | |
| 124 | |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 125 | struct flowi6 { |
| 126 | struct flowi_common __fl_common; |
David S. Miller | 2032656 | 2011-03-12 02:30:50 -0500 | [diff] [blame] | 127 | #define flowi6_oif __fl_common.flowic_oif |
| 128 | #define flowi6_iif __fl_common.flowic_iif |
| 129 | #define flowi6_mark __fl_common.flowic_mark |
David S. Miller | 2032656 | 2011-03-12 02:30:50 -0500 | [diff] [blame] | 130 | #define flowi6_scope __fl_common.flowic_scope |
| 131 | #define flowi6_proto __fl_common.flowic_proto |
| 132 | #define flowi6_flags __fl_common.flowic_flags |
| 133 | #define flowi6_secid __fl_common.flowic_secid |
Jiri Benc | 904af04 | 2015-08-20 13:56:31 +0200 | [diff] [blame] | 134 | #define flowi6_tun_key __fl_common.flowic_tun_key |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 135 | struct in6_addr daddr; |
| 136 | struct in6_addr saddr; |
Daniel Borkmann | 69716a2 | 2016-03-18 18:37:59 +0100 | [diff] [blame] | 137 | /* Note: flowi6_tos is encoded in flowlabel, too. */ |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 138 | __be32 flowlabel; |
| 139 | union flowi_uli uli; |
David S. Miller | 1958b85 | 2011-03-12 16:36:19 -0500 | [diff] [blame] | 140 | #define fl6_sport uli.ports.sport |
| 141 | #define fl6_dport uli.ports.dport |
| 142 | #define fl6_icmp_type uli.icmpt.type |
| 143 | #define fl6_icmp_code uli.icmpt.code |
| 144 | #define fl6_ipsec_spi uli.spi |
| 145 | #define fl6_mh_type uli.mht.type |
| 146 | #define fl6_gre_key uli.gre_key |
David Ward | 728871b | 2011-09-05 16:47:23 +0000 | [diff] [blame] | 147 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 148 | |
| 149 | struct flowidn { |
| 150 | struct flowi_common __fl_common; |
David S. Miller | bef55ae | 2011-03-12 17:17:10 -0500 | [diff] [blame] | 151 | #define flowidn_oif __fl_common.flowic_oif |
| 152 | #define flowidn_iif __fl_common.flowic_iif |
| 153 | #define flowidn_mark __fl_common.flowic_mark |
| 154 | #define flowidn_scope __fl_common.flowic_scope |
| 155 | #define flowidn_proto __fl_common.flowic_proto |
| 156 | #define flowidn_flags __fl_common.flowic_flags |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 157 | __le16 daddr; |
| 158 | __le16 saddr; |
| 159 | union flowi_uli uli; |
David S. Miller | bef55ae | 2011-03-12 17:17:10 -0500 | [diff] [blame] | 160 | #define fld_sport uli.ports.sport |
| 161 | #define fld_dport uli.ports.dport |
David Ward | 728871b | 2011-09-05 16:47:23 +0000 | [diff] [blame] | 162 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 163 | |
| 164 | struct flowi { |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 165 | union { |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 166 | struct flowi_common __fl_common; |
| 167 | struct flowi4 ip4; |
| 168 | struct flowi6 ip6; |
| 169 | struct flowidn dn; |
| 170 | } u; |
| 171 | #define flowi_oif u.__fl_common.flowic_oif |
| 172 | #define flowi_iif u.__fl_common.flowic_iif |
| 173 | #define flowi_mark u.__fl_common.flowic_mark |
| 174 | #define flowi_tos u.__fl_common.flowic_tos |
| 175 | #define flowi_scope u.__fl_common.flowic_scope |
| 176 | #define flowi_proto u.__fl_common.flowic_proto |
| 177 | #define flowi_flags u.__fl_common.flowic_flags |
| 178 | #define flowi_secid u.__fl_common.flowic_secid |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 179 | #define flowi_tun_key u.__fl_common.flowic_tun_key |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 180 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
| 181 | |
David S. Miller | 59b1a94 | 2011-03-11 19:23:02 -0500 | [diff] [blame] | 182 | static inline struct flowi *flowi4_to_flowi(struct flowi4 *fl4) |
| 183 | { |
| 184 | return container_of(fl4, struct flowi, u.ip4); |
| 185 | } |
| 186 | |
| 187 | static inline struct flowi *flowi6_to_flowi(struct flowi6 *fl6) |
| 188 | { |
| 189 | return container_of(fl6, struct flowi, u.ip6); |
| 190 | } |
| 191 | |
| 192 | static inline struct flowi *flowidn_to_flowi(struct flowidn *fldn) |
| 193 | { |
| 194 | return container_of(fldn, struct flowi, u.dn); |
| 195 | } |
| 196 | |
dpward | aa1c366 | 2011-09-05 16:47:24 +0000 | [diff] [blame] | 197 | typedef unsigned long flow_compare_t; |
| 198 | |
| 199 | static inline size_t flow_key_size(u16 family) |
| 200 | { |
| 201 | switch (family) { |
| 202 | case AF_INET: |
| 203 | BUILD_BUG_ON(sizeof(struct flowi4) % sizeof(flow_compare_t)); |
| 204 | return sizeof(struct flowi4) / sizeof(flow_compare_t); |
| 205 | case AF_INET6: |
| 206 | BUILD_BUG_ON(sizeof(struct flowi6) % sizeof(flow_compare_t)); |
| 207 | return sizeof(struct flowi6) / sizeof(flow_compare_t); |
| 208 | case AF_DECnet: |
| 209 | BUILD_BUG_ON(sizeof(struct flowidn) % sizeof(flow_compare_t)); |
| 210 | return sizeof(struct flowidn) / sizeof(flow_compare_t); |
| 211 | } |
| 212 | return 0; |
| 213 | } |
| 214 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 215 | #define FLOW_DIR_IN 0 |
| 216 | #define FLOW_DIR_OUT 1 |
| 217 | #define FLOW_DIR_FWD 2 |
| 218 | |
Alexey Dobriyan | 52479b6 | 2008-11-25 17:35:18 -0800 | [diff] [blame] | 219 | struct net; |
Trent Jaeger | df71837 | 2005-12-13 23:12:27 -0800 | [diff] [blame] | 220 | struct sock; |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 221 | struct flow_cache_ops; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 222 | |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 223 | struct flow_cache_object { |
| 224 | const struct flow_cache_ops *ops; |
| 225 | }; |
| 226 | |
| 227 | struct flow_cache_ops { |
| 228 | struct flow_cache_object *(*get)(struct flow_cache_object *); |
| 229 | int (*check)(struct flow_cache_object *); |
| 230 | void (*delete)(struct flow_cache_object *); |
| 231 | }; |
| 232 | |
| 233 | typedef struct flow_cache_object *(*flow_resolve_t)( |
David S. Miller | dee9f4b | 2011-02-22 18:44:31 -0800 | [diff] [blame] | 234 | struct net *net, const struct flowi *key, u16 family, |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 235 | u8 dir, struct flow_cache_object *oldobj, void *ctx); |
| 236 | |
Joe Perches | 4787342 | 2013-09-20 11:23:24 -0700 | [diff] [blame] | 237 | struct flow_cache_object *flow_cache_lookup(struct net *net, |
| 238 | const struct flowi *key, u16 family, |
| 239 | u8 dir, flow_resolve_t resolver, |
| 240 | void *ctx); |
Fan Du | ca925cf | 2014-01-18 09:55:27 +0800 | [diff] [blame] | 241 | int flow_cache_init(struct net *net); |
Steffen Klassert | 4a93f50 | 2014-03-12 09:43:17 +0100 | [diff] [blame] | 242 | void flow_cache_fini(struct net *net); |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 243 | |
Fan Du | ca925cf | 2014-01-18 09:55:27 +0800 | [diff] [blame] | 244 | void flow_cache_flush(struct net *net); |
| 245 | void flow_cache_flush_deferred(struct net *net); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 246 | extern atomic_t flow_cache_genid; |
| 247 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 248 | __u32 __get_hash_from_flowi6(const struct flowi6 *fl6, struct flow_keys *keys); |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 249 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 250 | static inline __u32 get_hash_from_flowi6(const struct flowi6 *fl6) |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 251 | { |
| 252 | struct flow_keys keys; |
| 253 | |
| 254 | return __get_hash_from_flowi6(fl6, &keys); |
| 255 | } |
| 256 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 257 | __u32 __get_hash_from_flowi4(const struct flowi4 *fl4, struct flow_keys *keys); |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 258 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 259 | static inline __u32 get_hash_from_flowi4(const struct flowi4 *fl4) |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 260 | { |
| 261 | struct flow_keys keys; |
| 262 | |
| 263 | return __get_hash_from_flowi4(fl4, &keys); |
| 264 | } |
| 265 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 266 | #endif |