blob: bae198b3039e6e66829c2717c1baf2baebbec6a2 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 *
3 * Generic internet FLOW.
4 *
5 */
6
7#ifndef _NET_FLOW_H
8#define _NET_FLOW_H
9
dpwardaa1c3662011-09-05 16:47:24 +000010#include <linux/socket.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070011#include <linux/in6.h>
Arun Sharma600634972011-07-26 16:09:06 -070012#include <linux/atomic.h>
Tom Herbertc6cc1ca2015-09-01 09:24:25 -070013#include <net/flow_dissector.h>
Lorenzo Colitti622ec2c2016-11-04 02:23:42 +090014#include <linux/uidgid.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -070015
Cong Wang6a662712014-04-15 16:25:34 -070016/*
17 * ifindex generation is per-net namespace, and loopback is
18 * always the 1st device in ns (see net_dev_init), thus any
19 * loopback device should get ifindex 1
20 */
21
22#define LOOPBACK_IFINDEX 1
23
Thomas Graf1b7179d2015-07-21 10:43:59 +020024struct flowi_tunnel {
25 __be64 tun_id;
26};
27
David S. Miller806566c2011-03-11 18:22:00 -050028struct flowi_common {
29 int flowic_oif;
30 int flowic_iif;
31 __u32 flowic_mark;
32 __u8 flowic_tos;
33 __u8 flowic_scope;
34 __u8 flowic_proto;
35 __u8 flowic_flags;
David S. Millerfbef0a42011-03-11 15:55:37 -050036#define FLOWI_FLAG_ANYSRC 0x01
Steffen Klassert0e0d44a2013-08-28 08:04:14 +020037#define FLOWI_FLAG_KNOWN_NH 0x02
David Ahernc71ad3d2016-09-10 12:10:02 -070038#define FLOWI_FLAG_SKIP_NH_OIF 0x04
David S. Miller806566c2011-03-11 18:22:00 -050039 __u32 flowic_secid;
Thomas Graf1b7179d2015-07-21 10:43:59 +020040 struct flowi_tunnel flowic_tun_key;
Lorenzo Colitti622ec2c2016-11-04 02:23:42 +090041 kuid_t flowic_uid;
David S. Miller806566c2011-03-11 18:22:00 -050042};
43
David S. Miller08704bc2011-03-11 18:36:42 -050044union flowi_uli {
45 struct {
David S. Miller08704bc2011-03-11 18:36:42 -050046 __be16 dport;
David S. Miller9b12c752011-03-31 18:03:35 -070047 __be16 sport;
David S. Miller08704bc2011-03-11 18:36:42 -050048 } ports;
49
50 struct {
51 __u8 type;
52 __u8 code;
53 } icmpt;
54
55 struct {
David S. Miller08704bc2011-03-11 18:36:42 -050056 __le16 dport;
David S. Miller9b12c752011-03-31 18:03:35 -070057 __le16 sport;
David S. Miller08704bc2011-03-11 18:36:42 -050058 } dnports;
59
60 __be32 spi;
61 __be32 gre_key;
62
63 struct {
64 __u8 type;
65 } mht;
66};
67
David S. Miller56bb8052011-03-12 00:44:35 -050068struct flowi4 {
David S. Miller806566c2011-03-11 18:22:00 -050069 struct flowi_common __fl_common;
David S. Miller22bd5b92011-03-11 19:54:08 -050070#define flowi4_oif __fl_common.flowic_oif
71#define flowi4_iif __fl_common.flowic_iif
72#define flowi4_mark __fl_common.flowic_mark
73#define flowi4_tos __fl_common.flowic_tos
74#define flowi4_scope __fl_common.flowic_scope
75#define flowi4_proto __fl_common.flowic_proto
76#define flowi4_flags __fl_common.flowic_flags
77#define flowi4_secid __fl_common.flowic_secid
Thomas Graf1b7179d2015-07-21 10:43:59 +020078#define flowi4_tun_key __fl_common.flowic_tun_key
Lorenzo Colitti622ec2c2016-11-04 02:23:42 +090079#define flowi4_uid __fl_common.flowic_uid
Eric Dumazet84f93072011-11-30 19:00:53 +000080
81 /* (saddr,daddr) must be grouped, same order as in IP header */
David S. Miller56bb8052011-03-12 00:44:35 -050082 __be32 saddr;
Eric Dumazet84f93072011-11-30 19:00:53 +000083 __be32 daddr;
84
David S. Miller56bb8052011-03-12 00:44:35 -050085 union flowi_uli uli;
David S. Miller9cce96d2011-03-12 03:00:33 -050086#define fl4_sport uli.ports.sport
87#define fl4_dport uli.ports.dport
88#define fl4_icmp_type uli.icmpt.type
89#define fl4_icmp_code uli.icmpt.code
90#define fl4_ipsec_spi uli.spi
91#define fl4_mh_type uli.mht.type
92#define fl4_gre_key uli.gre_key
David Ward728871b2011-09-05 16:47:23 +000093} __attribute__((__aligned__(BITS_PER_LONG/8)));
Linus Torvalds1da177e2005-04-16 15:20:36 -070094
David S. Miller83229aa2011-03-31 04:52:14 -070095static inline void flowi4_init_output(struct flowi4 *fl4, int oif,
96 __u32 mark, __u8 tos, __u8 scope,
97 __u8 proto, __u8 flags,
98 __be32 daddr, __be32 saddr,
Lorenzo Colittie2d118a2016-11-04 02:23:43 +090099 __be16 dport, __be16 sport,
100 kuid_t uid)
David S. Miller83229aa2011-03-31 04:52:14 -0700101{
102 fl4->flowi4_oif = oif;
Cong Wang6a662712014-04-15 16:25:34 -0700103 fl4->flowi4_iif = LOOPBACK_IFINDEX;
David S. Miller83229aa2011-03-31 04:52:14 -0700104 fl4->flowi4_mark = mark;
105 fl4->flowi4_tos = tos;
106 fl4->flowi4_scope = scope;
107 fl4->flowi4_proto = proto;
108 fl4->flowi4_flags = flags;
109 fl4->flowi4_secid = 0;
Thomas Graf1b7179d2015-07-21 10:43:59 +0200110 fl4->flowi4_tun_key.tun_id = 0;
Lorenzo Colittie2d118a2016-11-04 02:23:43 +0900111 fl4->flowi4_uid = uid;
David S. Miller83229aa2011-03-31 04:52:14 -0700112 fl4->daddr = daddr;
113 fl4->saddr = saddr;
David S. Miller83229aa2011-03-31 04:52:14 -0700114 fl4->fl4_dport = dport;
David S. Miller9b12c752011-03-31 18:03:35 -0700115 fl4->fl4_sport = sport;
David S. Miller83229aa2011-03-31 04:52:14 -0700116}
Julian Anastasove6b45242012-02-04 13:04:46 +0000117
118/* Reset some input parameters after previous lookup */
119static inline void flowi4_update_output(struct flowi4 *fl4, int oif, __u8 tos,
120 __be32 daddr, __be32 saddr)
121{
122 fl4->flowi4_oif = oif;
123 fl4->flowi4_tos = tos;
124 fl4->daddr = daddr;
125 fl4->saddr = saddr;
126}
David S. Miller83229aa2011-03-31 04:52:14 -0700127
128
David S. Miller56bb8052011-03-12 00:44:35 -0500129struct flowi6 {
130 struct flowi_common __fl_common;
David S. Miller20326562011-03-12 02:30:50 -0500131#define flowi6_oif __fl_common.flowic_oif
132#define flowi6_iif __fl_common.flowic_iif
133#define flowi6_mark __fl_common.flowic_mark
David S. Miller20326562011-03-12 02:30:50 -0500134#define flowi6_scope __fl_common.flowic_scope
135#define flowi6_proto __fl_common.flowic_proto
136#define flowi6_flags __fl_common.flowic_flags
137#define flowi6_secid __fl_common.flowic_secid
Jiri Benc904af042015-08-20 13:56:31 +0200138#define flowi6_tun_key __fl_common.flowic_tun_key
Lorenzo Colitti622ec2c2016-11-04 02:23:42 +0900139#define flowi6_uid __fl_common.flowic_uid
David S. Miller56bb8052011-03-12 00:44:35 -0500140 struct in6_addr daddr;
141 struct in6_addr saddr;
Daniel Borkmann69716a22016-03-18 18:37:59 +0100142 /* Note: flowi6_tos is encoded in flowlabel, too. */
David S. Miller56bb8052011-03-12 00:44:35 -0500143 __be32 flowlabel;
144 union flowi_uli uli;
David S. Miller1958b852011-03-12 16:36:19 -0500145#define fl6_sport uli.ports.sport
146#define fl6_dport uli.ports.dport
147#define fl6_icmp_type uli.icmpt.type
148#define fl6_icmp_code uli.icmpt.code
149#define fl6_ipsec_spi uli.spi
150#define fl6_mh_type uli.mht.type
151#define fl6_gre_key uli.gre_key
David Ward728871b2011-09-05 16:47:23 +0000152} __attribute__((__aligned__(BITS_PER_LONG/8)));
David S. Miller56bb8052011-03-12 00:44:35 -0500153
154struct flowidn {
155 struct flowi_common __fl_common;
David S. Millerbef55ae2011-03-12 17:17:10 -0500156#define flowidn_oif __fl_common.flowic_oif
157#define flowidn_iif __fl_common.flowic_iif
158#define flowidn_mark __fl_common.flowic_mark
159#define flowidn_scope __fl_common.flowic_scope
160#define flowidn_proto __fl_common.flowic_proto
161#define flowidn_flags __fl_common.flowic_flags
David S. Miller56bb8052011-03-12 00:44:35 -0500162 __le16 daddr;
163 __le16 saddr;
164 union flowi_uli uli;
David S. Millerbef55ae2011-03-12 17:17:10 -0500165#define fld_sport uli.ports.sport
166#define fld_dport uli.ports.dport
David Ward728871b2011-09-05 16:47:23 +0000167} __attribute__((__aligned__(BITS_PER_LONG/8)));
David S. Miller56bb8052011-03-12 00:44:35 -0500168
169struct flowi {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700170 union {
David S. Miller56bb8052011-03-12 00:44:35 -0500171 struct flowi_common __fl_common;
172 struct flowi4 ip4;
173 struct flowi6 ip6;
174 struct flowidn dn;
175 } u;
176#define flowi_oif u.__fl_common.flowic_oif
177#define flowi_iif u.__fl_common.flowic_iif
178#define flowi_mark u.__fl_common.flowic_mark
179#define flowi_tos u.__fl_common.flowic_tos
180#define flowi_scope u.__fl_common.flowic_scope
181#define flowi_proto u.__fl_common.flowic_proto
182#define flowi_flags u.__fl_common.flowic_flags
183#define flowi_secid u.__fl_common.flowic_secid
Thomas Graf1b7179d2015-07-21 10:43:59 +0200184#define flowi_tun_key u.__fl_common.flowic_tun_key
Lorenzo Colitti622ec2c2016-11-04 02:23:42 +0900185#define flowi_uid u.__fl_common.flowic_uid
Linus Torvalds1da177e2005-04-16 15:20:36 -0700186} __attribute__((__aligned__(BITS_PER_LONG/8)));
187
David S. Miller59b1a942011-03-11 19:23:02 -0500188static inline struct flowi *flowi4_to_flowi(struct flowi4 *fl4)
189{
190 return container_of(fl4, struct flowi, u.ip4);
191}
192
193static inline struct flowi *flowi6_to_flowi(struct flowi6 *fl6)
194{
195 return container_of(fl6, struct flowi, u.ip6);
196}
197
198static inline struct flowi *flowidn_to_flowi(struct flowidn *fldn)
199{
200 return container_of(fldn, struct flowi, u.dn);
201}
202
dpwardaa1c3662011-09-05 16:47:24 +0000203typedef unsigned long flow_compare_t;
204
Alexey Dobriyan5a17d9e2017-04-03 00:51:50 +0300205static inline unsigned int flow_key_size(u16 family)
dpwardaa1c3662011-09-05 16:47:24 +0000206{
207 switch (family) {
208 case AF_INET:
209 BUILD_BUG_ON(sizeof(struct flowi4) % sizeof(flow_compare_t));
210 return sizeof(struct flowi4) / sizeof(flow_compare_t);
211 case AF_INET6:
212 BUILD_BUG_ON(sizeof(struct flowi6) % sizeof(flow_compare_t));
213 return sizeof(struct flowi6) / sizeof(flow_compare_t);
214 case AF_DECnet:
215 BUILD_BUG_ON(sizeof(struct flowidn) % sizeof(flow_compare_t));
216 return sizeof(struct flowidn) / sizeof(flow_compare_t);
217 }
218 return 0;
219}
220
Linus Torvalds1da177e2005-04-16 15:20:36 -0700221#define FLOW_DIR_IN 0
222#define FLOW_DIR_OUT 1
223#define FLOW_DIR_FWD 2
224
Alexey Dobriyan52479b62008-11-25 17:35:18 -0800225struct net;
Trent Jaegerdf718372005-12-13 23:12:27 -0800226struct sock;
Timo Teräsfe1a5f02010-04-07 00:30:04 +0000227struct flow_cache_ops;
Linus Torvalds1da177e2005-04-16 15:20:36 -0700228
Timo Teräsfe1a5f02010-04-07 00:30:04 +0000229struct flow_cache_object {
230 const struct flow_cache_ops *ops;
231};
232
233struct flow_cache_ops {
234 struct flow_cache_object *(*get)(struct flow_cache_object *);
235 int (*check)(struct flow_cache_object *);
236 void (*delete)(struct flow_cache_object *);
237};
238
239typedef struct flow_cache_object *(*flow_resolve_t)(
David S. Millerdee9f4b2011-02-22 18:44:31 -0800240 struct net *net, const struct flowi *key, u16 family,
Timo Teräsfe1a5f02010-04-07 00:30:04 +0000241 u8 dir, struct flow_cache_object *oldobj, void *ctx);
242
Joe Perches47873422013-09-20 11:23:24 -0700243struct flow_cache_object *flow_cache_lookup(struct net *net,
244 const struct flowi *key, u16 family,
245 u8 dir, flow_resolve_t resolver,
246 void *ctx);
Fan Duca925cf2014-01-18 09:55:27 +0800247int flow_cache_init(struct net *net);
Steffen Klassert4a93f502014-03-12 09:43:17 +0100248void flow_cache_fini(struct net *net);
Sebastian Andrzej Siewiora4fc1bf2016-11-03 15:50:05 +0100249void flow_cache_hp_init(void);
Timo Teräsfe1a5f02010-04-07 00:30:04 +0000250
Fan Duca925cf2014-01-18 09:55:27 +0800251void flow_cache_flush(struct net *net);
252void flow_cache_flush_deferred(struct net *net);
Linus Torvalds1da177e2005-04-16 15:20:36 -0700253extern atomic_t flow_cache_genid;
254
David S. Miller20a17bf2015-09-01 21:19:17 -0700255__u32 __get_hash_from_flowi6(const struct flowi6 *fl6, struct flow_keys *keys);
Tom Herbertc6cc1ca2015-09-01 09:24:25 -0700256
David S. Miller20a17bf2015-09-01 21:19:17 -0700257static inline __u32 get_hash_from_flowi6(const struct flowi6 *fl6)
Tom Herbertc6cc1ca2015-09-01 09:24:25 -0700258{
259 struct flow_keys keys;
260
261 return __get_hash_from_flowi6(fl6, &keys);
262}
263
David S. Miller20a17bf2015-09-01 21:19:17 -0700264__u32 __get_hash_from_flowi4(const struct flowi4 *fl4, struct flow_keys *keys);
Tom Herbertc6cc1ca2015-09-01 09:24:25 -0700265
David S. Miller20a17bf2015-09-01 21:19:17 -0700266static inline __u32 get_hash_from_flowi4(const struct flowi4 *fl4)
Tom Herbertc6cc1ca2015-09-01 09:24:25 -0700267{
268 struct flow_keys keys;
269
270 return __get_hash_from_flowi4(fl4, &keys);
271}
272
Linus Torvalds1da177e2005-04-16 15:20:36 -0700273#endif