Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 1 | /* |
| 2 | * |
| 3 | * Generic internet FLOW. |
| 4 | * |
| 5 | */ |
| 6 | |
| 7 | #ifndef _NET_FLOW_H |
| 8 | #define _NET_FLOW_H |
| 9 | |
dpward | aa1c366 | 2011-09-05 16:47:24 +0000 | [diff] [blame] | 10 | #include <linux/socket.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 11 | #include <linux/in6.h> |
Arun Sharma | 60063497 | 2011-07-26 16:09:06 -0700 | [diff] [blame] | 12 | #include <linux/atomic.h> |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 13 | #include <net/flow_dissector.h> |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 14 | #include <linux/uidgid.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 15 | |
Cong Wang | 6a66271 | 2014-04-15 16:25:34 -0700 | [diff] [blame] | 16 | /* |
| 17 | * ifindex generation is per-net namespace, and loopback is |
| 18 | * always the 1st device in ns (see net_dev_init), thus any |
| 19 | * loopback device should get ifindex 1 |
| 20 | */ |
| 21 | |
| 22 | #define LOOPBACK_IFINDEX 1 |
| 23 | |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 24 | struct flowi_tunnel { |
| 25 | __be64 tun_id; |
| 26 | }; |
| 27 | |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 28 | struct flowi_common { |
| 29 | int flowic_oif; |
| 30 | int flowic_iif; |
| 31 | __u32 flowic_mark; |
| 32 | __u8 flowic_tos; |
| 33 | __u8 flowic_scope; |
| 34 | __u8 flowic_proto; |
| 35 | __u8 flowic_flags; |
David S. Miller | fbef0a4 | 2011-03-11 15:55:37 -0500 | [diff] [blame] | 36 | #define FLOWI_FLAG_ANYSRC 0x01 |
Steffen Klassert | 0e0d44a | 2013-08-28 08:04:14 +0200 | [diff] [blame] | 37 | #define FLOWI_FLAG_KNOWN_NH 0x02 |
David Ahern | c71ad3d | 2016-09-10 12:10:02 -0700 | [diff] [blame] | 38 | #define FLOWI_FLAG_SKIP_NH_OIF 0x04 |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 39 | __u32 flowic_secid; |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 40 | struct flowi_tunnel flowic_tun_key; |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 41 | kuid_t flowic_uid; |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 42 | }; |
| 43 | |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 44 | union flowi_uli { |
| 45 | struct { |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 46 | __be16 dport; |
David S. Miller | 9b12c75 | 2011-03-31 18:03:35 -0700 | [diff] [blame] | 47 | __be16 sport; |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 48 | } ports; |
| 49 | |
| 50 | struct { |
| 51 | __u8 type; |
| 52 | __u8 code; |
| 53 | } icmpt; |
| 54 | |
| 55 | struct { |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 56 | __le16 dport; |
David S. Miller | 9b12c75 | 2011-03-31 18:03:35 -0700 | [diff] [blame] | 57 | __le16 sport; |
David S. Miller | 08704bc | 2011-03-11 18:36:42 -0500 | [diff] [blame] | 58 | } dnports; |
| 59 | |
| 60 | __be32 spi; |
| 61 | __be32 gre_key; |
| 62 | |
| 63 | struct { |
| 64 | __u8 type; |
| 65 | } mht; |
| 66 | }; |
| 67 | |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 68 | struct flowi4 { |
David S. Miller | 806566c | 2011-03-11 18:22:00 -0500 | [diff] [blame] | 69 | struct flowi_common __fl_common; |
David S. Miller | 22bd5b9 | 2011-03-11 19:54:08 -0500 | [diff] [blame] | 70 | #define flowi4_oif __fl_common.flowic_oif |
| 71 | #define flowi4_iif __fl_common.flowic_iif |
| 72 | #define flowi4_mark __fl_common.flowic_mark |
| 73 | #define flowi4_tos __fl_common.flowic_tos |
| 74 | #define flowi4_scope __fl_common.flowic_scope |
| 75 | #define flowi4_proto __fl_common.flowic_proto |
| 76 | #define flowi4_flags __fl_common.flowic_flags |
| 77 | #define flowi4_secid __fl_common.flowic_secid |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 78 | #define flowi4_tun_key __fl_common.flowic_tun_key |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 79 | #define flowi4_uid __fl_common.flowic_uid |
Eric Dumazet | 84f9307 | 2011-11-30 19:00:53 +0000 | [diff] [blame] | 80 | |
| 81 | /* (saddr,daddr) must be grouped, same order as in IP header */ |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 82 | __be32 saddr; |
Eric Dumazet | 84f9307 | 2011-11-30 19:00:53 +0000 | [diff] [blame] | 83 | __be32 daddr; |
| 84 | |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 85 | union flowi_uli uli; |
David S. Miller | 9cce96d | 2011-03-12 03:00:33 -0500 | [diff] [blame] | 86 | #define fl4_sport uli.ports.sport |
| 87 | #define fl4_dport uli.ports.dport |
| 88 | #define fl4_icmp_type uli.icmpt.type |
| 89 | #define fl4_icmp_code uli.icmpt.code |
| 90 | #define fl4_ipsec_spi uli.spi |
| 91 | #define fl4_mh_type uli.mht.type |
| 92 | #define fl4_gre_key uli.gre_key |
David Ward | 728871b | 2011-09-05 16:47:23 +0000 | [diff] [blame] | 93 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 94 | |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 95 | static inline void flowi4_init_output(struct flowi4 *fl4, int oif, |
| 96 | __u32 mark, __u8 tos, __u8 scope, |
| 97 | __u8 proto, __u8 flags, |
| 98 | __be32 daddr, __be32 saddr, |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 99 | __be16 dport, __be16 sport, |
| 100 | kuid_t uid) |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 101 | { |
| 102 | fl4->flowi4_oif = oif; |
Cong Wang | 6a66271 | 2014-04-15 16:25:34 -0700 | [diff] [blame] | 103 | fl4->flowi4_iif = LOOPBACK_IFINDEX; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 104 | fl4->flowi4_mark = mark; |
| 105 | fl4->flowi4_tos = tos; |
| 106 | fl4->flowi4_scope = scope; |
| 107 | fl4->flowi4_proto = proto; |
| 108 | fl4->flowi4_flags = flags; |
| 109 | fl4->flowi4_secid = 0; |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 110 | fl4->flowi4_tun_key.tun_id = 0; |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 111 | fl4->flowi4_uid = uid; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 112 | fl4->daddr = daddr; |
| 113 | fl4->saddr = saddr; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 114 | fl4->fl4_dport = dport; |
David S. Miller | 9b12c75 | 2011-03-31 18:03:35 -0700 | [diff] [blame] | 115 | fl4->fl4_sport = sport; |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 116 | } |
Julian Anastasov | e6b4524 | 2012-02-04 13:04:46 +0000 | [diff] [blame] | 117 | |
| 118 | /* Reset some input parameters after previous lookup */ |
| 119 | static inline void flowi4_update_output(struct flowi4 *fl4, int oif, __u8 tos, |
| 120 | __be32 daddr, __be32 saddr) |
| 121 | { |
| 122 | fl4->flowi4_oif = oif; |
| 123 | fl4->flowi4_tos = tos; |
| 124 | fl4->daddr = daddr; |
| 125 | fl4->saddr = saddr; |
| 126 | } |
David S. Miller | 83229aa | 2011-03-31 04:52:14 -0700 | [diff] [blame] | 127 | |
| 128 | |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 129 | struct flowi6 { |
| 130 | struct flowi_common __fl_common; |
David S. Miller | 2032656 | 2011-03-12 02:30:50 -0500 | [diff] [blame] | 131 | #define flowi6_oif __fl_common.flowic_oif |
| 132 | #define flowi6_iif __fl_common.flowic_iif |
| 133 | #define flowi6_mark __fl_common.flowic_mark |
David S. Miller | 2032656 | 2011-03-12 02:30:50 -0500 | [diff] [blame] | 134 | #define flowi6_scope __fl_common.flowic_scope |
| 135 | #define flowi6_proto __fl_common.flowic_proto |
| 136 | #define flowi6_flags __fl_common.flowic_flags |
| 137 | #define flowi6_secid __fl_common.flowic_secid |
Jiri Benc | 904af04 | 2015-08-20 13:56:31 +0200 | [diff] [blame] | 138 | #define flowi6_tun_key __fl_common.flowic_tun_key |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 139 | #define flowi6_uid __fl_common.flowic_uid |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 140 | struct in6_addr daddr; |
| 141 | struct in6_addr saddr; |
Daniel Borkmann | 69716a2 | 2016-03-18 18:37:59 +0100 | [diff] [blame] | 142 | /* Note: flowi6_tos is encoded in flowlabel, too. */ |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 143 | __be32 flowlabel; |
| 144 | union flowi_uli uli; |
David S. Miller | 1958b85 | 2011-03-12 16:36:19 -0500 | [diff] [blame] | 145 | #define fl6_sport uli.ports.sport |
| 146 | #define fl6_dport uli.ports.dport |
| 147 | #define fl6_icmp_type uli.icmpt.type |
| 148 | #define fl6_icmp_code uli.icmpt.code |
| 149 | #define fl6_ipsec_spi uli.spi |
| 150 | #define fl6_mh_type uli.mht.type |
| 151 | #define fl6_gre_key uli.gre_key |
David Ward | 728871b | 2011-09-05 16:47:23 +0000 | [diff] [blame] | 152 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 153 | |
| 154 | struct flowidn { |
| 155 | struct flowi_common __fl_common; |
David S. Miller | bef55ae | 2011-03-12 17:17:10 -0500 | [diff] [blame] | 156 | #define flowidn_oif __fl_common.flowic_oif |
| 157 | #define flowidn_iif __fl_common.flowic_iif |
| 158 | #define flowidn_mark __fl_common.flowic_mark |
| 159 | #define flowidn_scope __fl_common.flowic_scope |
| 160 | #define flowidn_proto __fl_common.flowic_proto |
| 161 | #define flowidn_flags __fl_common.flowic_flags |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 162 | __le16 daddr; |
| 163 | __le16 saddr; |
| 164 | union flowi_uli uli; |
David S. Miller | bef55ae | 2011-03-12 17:17:10 -0500 | [diff] [blame] | 165 | #define fld_sport uli.ports.sport |
| 166 | #define fld_dport uli.ports.dport |
David Ward | 728871b | 2011-09-05 16:47:23 +0000 | [diff] [blame] | 167 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 168 | |
| 169 | struct flowi { |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 170 | union { |
David S. Miller | 56bb805 | 2011-03-12 00:44:35 -0500 | [diff] [blame] | 171 | struct flowi_common __fl_common; |
| 172 | struct flowi4 ip4; |
| 173 | struct flowi6 ip6; |
| 174 | struct flowidn dn; |
| 175 | } u; |
| 176 | #define flowi_oif u.__fl_common.flowic_oif |
| 177 | #define flowi_iif u.__fl_common.flowic_iif |
| 178 | #define flowi_mark u.__fl_common.flowic_mark |
| 179 | #define flowi_tos u.__fl_common.flowic_tos |
| 180 | #define flowi_scope u.__fl_common.flowic_scope |
| 181 | #define flowi_proto u.__fl_common.flowic_proto |
| 182 | #define flowi_flags u.__fl_common.flowic_flags |
| 183 | #define flowi_secid u.__fl_common.flowic_secid |
Thomas Graf | 1b7179d | 2015-07-21 10:43:59 +0200 | [diff] [blame] | 184 | #define flowi_tun_key u.__fl_common.flowic_tun_key |
Lorenzo Colitti | 3b82497 | 2014-03-31 16:23:51 +0900 | [diff] [blame] | 185 | #define flowi_uid u.__fl_common.flowic_uid |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 186 | } __attribute__((__aligned__(BITS_PER_LONG/8))); |
| 187 | |
David S. Miller | 59b1a94 | 2011-03-11 19:23:02 -0500 | [diff] [blame] | 188 | static inline struct flowi *flowi4_to_flowi(struct flowi4 *fl4) |
| 189 | { |
| 190 | return container_of(fl4, struct flowi, u.ip4); |
| 191 | } |
| 192 | |
| 193 | static inline struct flowi *flowi6_to_flowi(struct flowi6 *fl6) |
| 194 | { |
| 195 | return container_of(fl6, struct flowi, u.ip6); |
| 196 | } |
| 197 | |
| 198 | static inline struct flowi *flowidn_to_flowi(struct flowidn *fldn) |
| 199 | { |
| 200 | return container_of(fldn, struct flowi, u.dn); |
| 201 | } |
| 202 | |
dpward | aa1c366 | 2011-09-05 16:47:24 +0000 | [diff] [blame] | 203 | typedef unsigned long flow_compare_t; |
| 204 | |
| 205 | static inline size_t flow_key_size(u16 family) |
| 206 | { |
| 207 | switch (family) { |
| 208 | case AF_INET: |
| 209 | BUILD_BUG_ON(sizeof(struct flowi4) % sizeof(flow_compare_t)); |
| 210 | return sizeof(struct flowi4) / sizeof(flow_compare_t); |
| 211 | case AF_INET6: |
| 212 | BUILD_BUG_ON(sizeof(struct flowi6) % sizeof(flow_compare_t)); |
| 213 | return sizeof(struct flowi6) / sizeof(flow_compare_t); |
| 214 | case AF_DECnet: |
| 215 | BUILD_BUG_ON(sizeof(struct flowidn) % sizeof(flow_compare_t)); |
| 216 | return sizeof(struct flowidn) / sizeof(flow_compare_t); |
| 217 | } |
| 218 | return 0; |
| 219 | } |
| 220 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 221 | #define FLOW_DIR_IN 0 |
| 222 | #define FLOW_DIR_OUT 1 |
| 223 | #define FLOW_DIR_FWD 2 |
| 224 | |
Alexey Dobriyan | 52479b6 | 2008-11-25 17:35:18 -0800 | [diff] [blame] | 225 | struct net; |
Trent Jaeger | df71837 | 2005-12-13 23:12:27 -0800 | [diff] [blame] | 226 | struct sock; |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 227 | struct flow_cache_ops; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 228 | |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 229 | struct flow_cache_object { |
| 230 | const struct flow_cache_ops *ops; |
| 231 | }; |
| 232 | |
| 233 | struct flow_cache_ops { |
| 234 | struct flow_cache_object *(*get)(struct flow_cache_object *); |
| 235 | int (*check)(struct flow_cache_object *); |
| 236 | void (*delete)(struct flow_cache_object *); |
| 237 | }; |
| 238 | |
| 239 | typedef struct flow_cache_object *(*flow_resolve_t)( |
David S. Miller | dee9f4b | 2011-02-22 18:44:31 -0800 | [diff] [blame] | 240 | struct net *net, const struct flowi *key, u16 family, |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 241 | u8 dir, struct flow_cache_object *oldobj, void *ctx); |
| 242 | |
Joe Perches | 4787342 | 2013-09-20 11:23:24 -0700 | [diff] [blame] | 243 | struct flow_cache_object *flow_cache_lookup(struct net *net, |
| 244 | const struct flowi *key, u16 family, |
| 245 | u8 dir, flow_resolve_t resolver, |
| 246 | void *ctx); |
Fan Du | ca925cf | 2014-01-18 09:55:27 +0800 | [diff] [blame] | 247 | int flow_cache_init(struct net *net); |
Steffen Klassert | 4a93f50 | 2014-03-12 09:43:17 +0100 | [diff] [blame] | 248 | void flow_cache_fini(struct net *net); |
Timo Teräs | fe1a5f0 | 2010-04-07 00:30:04 +0000 | [diff] [blame] | 249 | |
Fan Du | ca925cf | 2014-01-18 09:55:27 +0800 | [diff] [blame] | 250 | void flow_cache_flush(struct net *net); |
| 251 | void flow_cache_flush_deferred(struct net *net); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 252 | extern atomic_t flow_cache_genid; |
| 253 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 254 | __u32 __get_hash_from_flowi6(const struct flowi6 *fl6, struct flow_keys *keys); |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 255 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 256 | static inline __u32 get_hash_from_flowi6(const struct flowi6 *fl6) |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 257 | { |
| 258 | struct flow_keys keys; |
| 259 | |
| 260 | return __get_hash_from_flowi6(fl6, &keys); |
| 261 | } |
| 262 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 263 | __u32 __get_hash_from_flowi4(const struct flowi4 *fl4, struct flow_keys *keys); |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 264 | |
David S. Miller | 20a17bf | 2015-09-01 21:19:17 -0700 | [diff] [blame] | 265 | static inline __u32 get_hash_from_flowi4(const struct flowi4 *fl4) |
Tom Herbert | c6cc1ca | 2015-09-01 09:24:25 -0700 | [diff] [blame] | 266 | { |
| 267 | struct flow_keys keys; |
| 268 | |
| 269 | return __get_hash_from_flowi4(fl4, &keys); |
| 270 | } |
| 271 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 272 | #endif |