blob: e65e230873679285cdba21bee8f9c07429ef626d [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001/*
2 * Linux Socket Filter Data Structures
3 */
Linus Torvalds1da177e2005-04-16 15:20:36 -07004#ifndef __LINUX_FILTER_H__
5#define __LINUX_FILTER_H__
6
Arun Sharma600634972011-07-26 16:09:06 -07007#include <linux/atomic.h>
Will Drewry0c5fe1b2012-04-12 16:47:53 -05008#include <linux/compat.h>
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -07009#include <linux/workqueue.h>
David Howells607ca462012-10-13 10:46:48 +010010#include <uapi/linux/filter.h>
Heiko Carstens792d4b52011-05-22 07:08:11 +000011
Will Drewry0c5fe1b2012-04-12 16:47:53 -050012#ifdef CONFIG_COMPAT
13/*
14 * A struct sock_filter is architecture independent.
15 */
16struct compat_sock_fprog {
17 u16 len;
18 compat_uptr_t filter; /* struct sock_filter * */
19};
20#endif
21
Heiko Carstens792d4b52011-05-22 07:08:11 +000022struct sk_buff;
23struct sock;
24
Stephen Hemmingerb7156312008-04-10 01:33:47 -070025struct sk_filter
26{
27 atomic_t refcnt;
Daniel Borkmannf8bbbfc2014-03-28 18:58:18 +010028 u32 jited:1, /* Is our filter JIT'ed? */
29 len:31; /* Number of filter blocks */
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -070030 struct rcu_head rcu;
Eric Dumazet0a148422011-04-20 09:27:32 +000031 unsigned int (*bpf_func)(const struct sk_buff *skb,
32 const struct sock_filter *filter);
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -070033 union {
34 struct sock_filter insns[0];
35 struct work_struct work;
36 };
Stephen Hemmingerb7156312008-04-10 01:33:47 -070037};
38
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -070039static inline unsigned int sk_filter_size(unsigned int proglen)
Stephen Hemmingerb7156312008-04-10 01:33:47 -070040{
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -070041 return max(sizeof(struct sk_filter),
42 offsetof(struct sk_filter, insns[proglen]));
Stephen Hemmingerb7156312008-04-10 01:33:47 -070043}
44
Stephen Hemminger43db6d62008-04-10 01:43:09 -070045extern int sk_filter(struct sock *sk, struct sk_buff *skb);
Eric Dumazet62ab0812010-12-06 20:50:09 +000046extern unsigned int sk_run_filter(const struct sk_buff *skb,
Eric Dumazet93aaae22010-11-19 09:49:59 -080047 const struct sock_filter *filter);
Jiri Pirko302d6632012-03-31 11:01:19 +000048extern int sk_unattached_filter_create(struct sk_filter **pfp,
49 struct sock_fprog *fprog);
50extern void sk_unattached_filter_destroy(struct sk_filter *fp);
Linus Torvalds1da177e2005-04-16 15:20:36 -070051extern int sk_attach_filter(struct sock_fprog *fprog, struct sock *sk);
Pavel Emelyanov55b33322007-10-17 21:21:26 -070052extern int sk_detach_filter(struct sock *sk);
Dan Carpenter4f25af22011-10-17 21:04:20 +000053extern int sk_chk_filter(struct sock_filter *filter, unsigned int flen);
Pavel Emelyanova8fc9272012-11-01 02:01:48 +000054extern int sk_get_filter(struct sock *sk, struct sock_filter __user *filter, unsigned len);
Nicolas Dichteled139982013-06-05 15:30:55 +020055extern void sk_decode_filter(struct sock_filter *filt, struct sock_filter *to);
Eric Dumazet0a148422011-04-20 09:27:32 +000056
57#ifdef CONFIG_BPF_JIT
Xi Wang20074f32013-05-01 16:24:08 -040058#include <stdarg.h>
Chen Ganga691ce72013-03-28 15:24:53 +000059#include <linux/linkage.h>
60#include <linux/printk.h>
61
Eric Dumazet0a148422011-04-20 09:27:32 +000062extern void bpf_jit_compile(struct sk_filter *fp);
63extern void bpf_jit_free(struct sk_filter *fp);
Daniel Borkmann79617802013-03-21 22:22:03 +010064
65static inline void bpf_jit_dump(unsigned int flen, unsigned int proglen,
66 u32 pass, void *image)
67{
Eric Dumazet16495442013-05-17 16:57:37 +000068 pr_err("flen=%u proglen=%u pass=%u image=%pK\n",
Daniel Borkmann79617802013-03-21 22:22:03 +010069 flen, proglen, pass, image);
70 if (image)
Eric Dumazet16495442013-05-17 16:57:37 +000071 print_hex_dump(KERN_ERR, "JIT code: ", DUMP_PREFIX_OFFSET,
Daniel Borkmann79617802013-03-21 22:22:03 +010072 16, 1, image, proglen, false);
73}
Eric Dumazet0a148422011-04-20 09:27:32 +000074#define SK_RUN_FILTER(FILTER, SKB) (*FILTER->bpf_func)(SKB, FILTER->insns)
75#else
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -070076#include <linux/slab.h>
Eric Dumazet0a148422011-04-20 09:27:32 +000077static inline void bpf_jit_compile(struct sk_filter *fp)
78{
79}
80static inline void bpf_jit_free(struct sk_filter *fp)
81{
Alexei Starovoitovd45ed4a2013-10-04 00:14:06 -070082 kfree(fp);
Eric Dumazet0a148422011-04-20 09:27:32 +000083}
84#define SK_RUN_FILTER(FILTER, SKB) sk_run_filter(SKB, FILTER->insns)
85#endif
86
Michal Sekletarea02f942014-01-17 17:09:45 +010087static inline int bpf_tell_extensions(void)
88{
Daniel Borkmann37692292014-01-21 00:19:37 +010089 return SKF_AD_MAX;
Michal Sekletarea02f942014-01-17 17:09:45 +010090}
91
Eric Dumazet0a148422011-04-20 09:27:32 +000092enum {
93 BPF_S_RET_K = 1,
94 BPF_S_RET_A,
95 BPF_S_ALU_ADD_K,
96 BPF_S_ALU_ADD_X,
97 BPF_S_ALU_SUB_K,
98 BPF_S_ALU_SUB_X,
99 BPF_S_ALU_MUL_K,
100 BPF_S_ALU_MUL_X,
101 BPF_S_ALU_DIV_X,
Eric Dumazetb6069a92012-09-07 22:03:35 +0000102 BPF_S_ALU_MOD_K,
103 BPF_S_ALU_MOD_X,
Eric Dumazet0a148422011-04-20 09:27:32 +0000104 BPF_S_ALU_AND_K,
105 BPF_S_ALU_AND_X,
106 BPF_S_ALU_OR_K,
107 BPF_S_ALU_OR_X,
Daniel Borkmann9e49e882012-09-24 02:23:59 +0000108 BPF_S_ALU_XOR_K,
109 BPF_S_ALU_XOR_X,
Eric Dumazet0a148422011-04-20 09:27:32 +0000110 BPF_S_ALU_LSH_K,
111 BPF_S_ALU_LSH_X,
112 BPF_S_ALU_RSH_K,
113 BPF_S_ALU_RSH_X,
114 BPF_S_ALU_NEG,
115 BPF_S_LD_W_ABS,
116 BPF_S_LD_H_ABS,
117 BPF_S_LD_B_ABS,
118 BPF_S_LD_W_LEN,
119 BPF_S_LD_W_IND,
120 BPF_S_LD_H_IND,
121 BPF_S_LD_B_IND,
122 BPF_S_LD_IMM,
123 BPF_S_LDX_W_LEN,
124 BPF_S_LDX_B_MSH,
125 BPF_S_LDX_IMM,
126 BPF_S_MISC_TAX,
127 BPF_S_MISC_TXA,
128 BPF_S_ALU_DIV_K,
129 BPF_S_LD_MEM,
130 BPF_S_LDX_MEM,
131 BPF_S_ST,
132 BPF_S_STX,
133 BPF_S_JMP_JA,
134 BPF_S_JMP_JEQ_K,
135 BPF_S_JMP_JEQ_X,
136 BPF_S_JMP_JGE_K,
137 BPF_S_JMP_JGE_X,
138 BPF_S_JMP_JGT_K,
139 BPF_S_JMP_JGT_X,
140 BPF_S_JMP_JSET_K,
141 BPF_S_JMP_JSET_X,
142 /* Ancillary data */
143 BPF_S_ANC_PROTOCOL,
144 BPF_S_ANC_PKTTYPE,
145 BPF_S_ANC_IFINDEX,
146 BPF_S_ANC_NLATTR,
147 BPF_S_ANC_NLATTR_NEST,
148 BPF_S_ANC_MARK,
149 BPF_S_ANC_QUEUE,
150 BPF_S_ANC_HATYPE,
151 BPF_S_ANC_RXHASH,
152 BPF_S_ANC_CPU,
Jiri Pirkoffe06c12012-03-31 11:01:20 +0000153 BPF_S_ANC_ALU_XOR_X,
Will Drewry46b325c2012-04-12 16:47:52 -0500154 BPF_S_ANC_SECCOMP_LD_W,
Eric Dumazetf3335032012-10-27 02:26:17 +0000155 BPF_S_ANC_VLAN_TAG,
156 BPF_S_ANC_VLAN_TAG_PRESENT,
Daniel Borkmann3e5289d2013-03-19 06:39:31 +0000157 BPF_S_ANC_PAY_OFFSET,
Eric Dumazet0a148422011-04-20 09:27:32 +0000158};
159
Linus Torvalds1da177e2005-04-16 15:20:36 -0700160#endif /* __LINUX_FILTER_H__ */