blob: 5b7bb968d1d4418fe6c0fb914646c0c180b525a9 [file] [log] [blame]
Jiri Pirko77b99002015-05-12 14:56:21 +02001/*
2 * net/sched/cls_flower.c Flower classifier
3 *
4 * Copyright (c) 2015 Jiri Pirko <jiri@resnulli.us>
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 */
11
12#include <linux/kernel.h>
13#include <linux/init.h>
14#include <linux/module.h>
15#include <linux/rhashtable.h>
Daniel Borkmannd9363772016-11-27 01:18:01 +010016#include <linux/workqueue.h>
Jiri Pirko77b99002015-05-12 14:56:21 +020017
18#include <linux/if_ether.h>
19#include <linux/in6.h>
20#include <linux/ip.h>
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -040021#include <linux/mpls.h>
Jiri Pirko77b99002015-05-12 14:56:21 +020022
23#include <net/sch_generic.h>
24#include <net/pkt_cls.h>
25#include <net/ip.h>
26#include <net/flow_dissector.h>
27
Amir Vadaibc3103f2016-09-08 16:23:47 +030028#include <net/dst.h>
29#include <net/dst_metadata.h>
30
Jiri Pirko77b99002015-05-12 14:56:21 +020031struct fl_flow_key {
32 int indev_ifindex;
Tom Herbert42aecaa2015-06-04 09:16:39 -070033 struct flow_dissector_key_control control;
Amir Vadaibc3103f2016-09-08 16:23:47 +030034 struct flow_dissector_key_control enc_control;
Jiri Pirko77b99002015-05-12 14:56:21 +020035 struct flow_dissector_key_basic basic;
36 struct flow_dissector_key_eth_addrs eth;
Hadar Hen Zion9399ae92016-08-17 13:36:13 +030037 struct flow_dissector_key_vlan vlan;
Jiri Pirko77b99002015-05-12 14:56:21 +020038 union {
Tom Herbertc3f83242015-06-04 09:16:40 -070039 struct flow_dissector_key_ipv4_addrs ipv4;
Jiri Pirko77b99002015-05-12 14:56:21 +020040 struct flow_dissector_key_ipv6_addrs ipv6;
41 };
42 struct flow_dissector_key_ports tp;
Simon Horman7b684882016-12-07 13:48:28 +010043 struct flow_dissector_key_icmp icmp;
Simon Horman99d31322017-01-11 14:05:43 +010044 struct flow_dissector_key_arp arp;
Amir Vadaibc3103f2016-09-08 16:23:47 +030045 struct flow_dissector_key_keyid enc_key_id;
46 union {
47 struct flow_dissector_key_ipv4_addrs enc_ipv4;
48 struct flow_dissector_key_ipv6_addrs enc_ipv6;
49 };
Hadar Hen Zionf4d997f2016-11-07 15:14:39 +020050 struct flow_dissector_key_ports enc_tp;
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -040051 struct flow_dissector_key_mpls mpls;
Jiri Pirkofdfc7dd2017-05-23 18:40:45 +020052 struct flow_dissector_key_tcp tcp;
Or Gerlitz4d80cc02017-06-01 21:37:38 +030053 struct flow_dissector_key_ip ip;
Jiri Pirko77b99002015-05-12 14:56:21 +020054} __aligned(BITS_PER_LONG / 8); /* Ensure that we can do comparisons as longs. */
55
56struct fl_flow_mask_range {
57 unsigned short int start;
58 unsigned short int end;
59};
60
61struct fl_flow_mask {
62 struct fl_flow_key key;
63 struct fl_flow_mask_range range;
64 struct rcu_head rcu;
65};
66
67struct cls_fl_head {
68 struct rhashtable ht;
69 struct fl_flow_mask mask;
70 struct flow_dissector dissector;
Jiri Pirko77b99002015-05-12 14:56:21 +020071 bool mask_assigned;
72 struct list_head filters;
73 struct rhashtable_params ht_params;
Daniel Borkmannd9363772016-11-27 01:18:01 +010074 union {
75 struct work_struct work;
76 struct rcu_head rcu;
77 };
Chris Mic15ab232017-08-30 02:31:58 -040078 struct idr handle_idr;
Jiri Pirko77b99002015-05-12 14:56:21 +020079};
80
81struct cls_fl_filter {
82 struct rhash_head ht_node;
83 struct fl_flow_key mkey;
84 struct tcf_exts exts;
85 struct tcf_result res;
86 struct fl_flow_key key;
87 struct list_head list;
88 u32 handle;
Amir Vadaie69985c2016-06-05 17:11:18 +030089 u32 flags;
Jiri Pirko77b99002015-05-12 14:56:21 +020090 struct rcu_head rcu;
91};
92
93static unsigned short int fl_mask_range(const struct fl_flow_mask *mask)
94{
95 return mask->range.end - mask->range.start;
96}
97
98static void fl_mask_update_range(struct fl_flow_mask *mask)
99{
100 const u8 *bytes = (const u8 *) &mask->key;
101 size_t size = sizeof(mask->key);
102 size_t i, first = 0, last = size - 1;
103
104 for (i = 0; i < sizeof(mask->key); i++) {
105 if (bytes[i]) {
106 if (!first && i)
107 first = i;
108 last = i;
109 }
110 }
111 mask->range.start = rounddown(first, sizeof(long));
112 mask->range.end = roundup(last + 1, sizeof(long));
113}
114
115static void *fl_key_get_start(struct fl_flow_key *key,
116 const struct fl_flow_mask *mask)
117{
118 return (u8 *) key + mask->range.start;
119}
120
121static void fl_set_masked_key(struct fl_flow_key *mkey, struct fl_flow_key *key,
122 struct fl_flow_mask *mask)
123{
124 const long *lkey = fl_key_get_start(key, mask);
125 const long *lmask = fl_key_get_start(&mask->key, mask);
126 long *lmkey = fl_key_get_start(mkey, mask);
127 int i;
128
129 for (i = 0; i < fl_mask_range(mask); i += sizeof(long))
130 *lmkey++ = *lkey++ & *lmask++;
131}
132
133static void fl_clear_masked_range(struct fl_flow_key *key,
134 struct fl_flow_mask *mask)
135{
136 memset(fl_key_get_start(key, mask), 0, fl_mask_range(mask));
137}
138
Paul Blakeya3308d82017-01-16 10:45:13 +0200139static struct cls_fl_filter *fl_lookup(struct cls_fl_head *head,
140 struct fl_flow_key *mkey)
141{
142 return rhashtable_lookup_fast(&head->ht,
143 fl_key_get_start(mkey, &head->mask),
144 head->ht_params);
145}
146
Jiri Pirko77b99002015-05-12 14:56:21 +0200147static int fl_classify(struct sk_buff *skb, const struct tcf_proto *tp,
148 struct tcf_result *res)
149{
150 struct cls_fl_head *head = rcu_dereference_bh(tp->root);
151 struct cls_fl_filter *f;
152 struct fl_flow_key skb_key;
153 struct fl_flow_key skb_mkey;
154
Amir Vadaie69985c2016-06-05 17:11:18 +0300155 if (!atomic_read(&head->ht.nelems))
156 return -1;
157
Jiri Pirko77b99002015-05-12 14:56:21 +0200158 fl_clear_masked_range(&skb_key, &head->mask);
Amir Vadaibc3103f2016-09-08 16:23:47 +0300159
Jiri Pirko77b99002015-05-12 14:56:21 +0200160 skb_key.indev_ifindex = skb->skb_iif;
161 /* skb_flow_dissect() does not set n_proto in case an unknown protocol,
162 * so do it rather here.
163 */
164 skb_key.basic.n_proto = skb->protocol;
Tom Herbertcd79a232015-09-01 09:24:27 -0700165 skb_flow_dissect(skb, &head->dissector, &skb_key, 0);
Jiri Pirko77b99002015-05-12 14:56:21 +0200166
167 fl_set_masked_key(&skb_mkey, &skb_key, &head->mask);
168
Paul Blakeya3308d82017-01-16 10:45:13 +0200169 f = fl_lookup(head, &skb_mkey);
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300170 if (f && !tc_skip_sw(f->flags)) {
Jiri Pirko77b99002015-05-12 14:56:21 +0200171 *res = f->res;
172 return tcf_exts_exec(skb, &f->exts, res);
173 }
174 return -1;
175}
176
177static int fl_init(struct tcf_proto *tp)
178{
179 struct cls_fl_head *head;
180
181 head = kzalloc(sizeof(*head), GFP_KERNEL);
182 if (!head)
183 return -ENOBUFS;
184
185 INIT_LIST_HEAD_RCU(&head->filters);
186 rcu_assign_pointer(tp->root, head);
Chris Mic15ab232017-08-30 02:31:58 -0400187 idr_init(&head->handle_idr);
Jiri Pirko77b99002015-05-12 14:56:21 +0200188
189 return 0;
190}
191
192static void fl_destroy_filter(struct rcu_head *head)
193{
194 struct cls_fl_filter *f = container_of(head, struct cls_fl_filter, rcu);
195
196 tcf_exts_destroy(&f->exts);
197 kfree(f);
198}
199
Hadar Hen Zion3036dab2016-12-01 14:06:35 +0200200static void fl_hw_destroy_filter(struct tcf_proto *tp, struct cls_fl_filter *f)
Amir Vadai5b33f482016-03-08 12:42:29 +0200201{
Jiri Pirkode4784c2017-08-07 10:15:32 +0200202 struct tc_cls_flower_offload cls_flower = {};
Jiri Pirko717503b2017-10-11 09:41:09 +0200203 struct net_device *dev = tp->q->dev_queue->dev;
Amir Vadai5b33f482016-03-08 12:42:29 +0200204
Jiri Pirkode4784c2017-08-07 10:15:32 +0200205 tc_cls_common_offload_init(&cls_flower.common, tp);
206 cls_flower.command = TC_CLSFLOWER_DESTROY;
207 cls_flower.cookie = (unsigned long) f;
Amir Vadai5b33f482016-03-08 12:42:29 +0200208
Jiri Pirko717503b2017-10-11 09:41:09 +0200209 if (tc_can_offload(dev))
210 dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSFLOWER,
211 &cls_flower);
212 tc_setup_cb_call(&f->exts, TC_SETUP_CLSFLOWER,
213 &cls_flower, false);
Amir Vadai5b33f482016-03-08 12:42:29 +0200214}
215
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300216static int fl_hw_replace_filter(struct tcf_proto *tp,
217 struct flow_dissector *dissector,
218 struct fl_flow_key *mask,
Hadar Hen Zion3036dab2016-12-01 14:06:35 +0200219 struct cls_fl_filter *f)
Amir Vadai5b33f482016-03-08 12:42:29 +0200220{
221 struct net_device *dev = tp->q->dev_queue->dev;
Jiri Pirkode4784c2017-08-07 10:15:32 +0200222 struct tc_cls_flower_offload cls_flower = {};
Jiri Pirko717503b2017-10-11 09:41:09 +0200223 bool skip_sw = tc_skip_sw(f->flags);
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300224 int err;
Amir Vadai5b33f482016-03-08 12:42:29 +0200225
Jiri Pirkode4784c2017-08-07 10:15:32 +0200226 tc_cls_common_offload_init(&cls_flower.common, tp);
227 cls_flower.command = TC_CLSFLOWER_REPLACE;
228 cls_flower.cookie = (unsigned long) f;
229 cls_flower.dissector = dissector;
230 cls_flower.mask = mask;
231 cls_flower.key = &f->mkey;
232 cls_flower.exts = &f->exts;
Amir Vadai5b33f482016-03-08 12:42:29 +0200233
Jiri Pirko717503b2017-10-11 09:41:09 +0200234 if (tc_can_offload(dev)) {
235 err = dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSFLOWER,
236 &cls_flower);
237 if (err) {
238 if (skip_sw)
239 return err;
240 } else {
241 f->flags |= TCA_CLS_FLAGS_IN_HW;
242 }
243 }
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300244
Jiri Pirko717503b2017-10-11 09:41:09 +0200245 err = tc_setup_cb_call(&f->exts, TC_SETUP_CLSFLOWER,
246 &cls_flower, skip_sw);
247 if (err < 0) {
248 fl_hw_destroy_filter(tp, f);
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300249 return err;
Jiri Pirko717503b2017-10-11 09:41:09 +0200250 } else if (err > 0) {
251 f->flags |= TCA_CLS_FLAGS_IN_HW;
252 }
253
254 if (skip_sw && !(f->flags & TCA_CLS_FLAGS_IN_HW))
255 return -EINVAL;
256
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300257 return 0;
Amir Vadai5b33f482016-03-08 12:42:29 +0200258}
259
Amir Vadai10cbc682016-05-13 12:55:37 +0000260static void fl_hw_update_stats(struct tcf_proto *tp, struct cls_fl_filter *f)
261{
Jiri Pirkode4784c2017-08-07 10:15:32 +0200262 struct tc_cls_flower_offload cls_flower = {};
Jiri Pirko717503b2017-10-11 09:41:09 +0200263 struct net_device *dev = tp->q->dev_queue->dev;
Amir Vadai10cbc682016-05-13 12:55:37 +0000264
Jiri Pirkode4784c2017-08-07 10:15:32 +0200265 tc_cls_common_offload_init(&cls_flower.common, tp);
266 cls_flower.command = TC_CLSFLOWER_STATS;
267 cls_flower.cookie = (unsigned long) f;
268 cls_flower.exts = &f->exts;
Amir Vadai10cbc682016-05-13 12:55:37 +0000269
Jiri Pirko717503b2017-10-11 09:41:09 +0200270 if (tc_can_offload(dev))
271 dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSFLOWER,
272 &cls_flower);
273 tc_setup_cb_call(&f->exts, TC_SETUP_CLSFLOWER,
274 &cls_flower, false);
Amir Vadai10cbc682016-05-13 12:55:37 +0000275}
276
Roi Dayan13fa8762016-11-01 16:08:29 +0200277static void __fl_delete(struct tcf_proto *tp, struct cls_fl_filter *f)
278{
Chris Mic15ab232017-08-30 02:31:58 -0400279 struct cls_fl_head *head = rtnl_dereference(tp->root);
280
281 idr_remove_ext(&head->handle_idr, f->handle);
Roi Dayan13fa8762016-11-01 16:08:29 +0200282 list_del_rcu(&f->list);
Hadar Hen Zion79685212016-12-01 14:06:34 +0200283 if (!tc_skip_hw(f->flags))
Hadar Hen Zion3036dab2016-12-01 14:06:35 +0200284 fl_hw_destroy_filter(tp, f);
Roi Dayan13fa8762016-11-01 16:08:29 +0200285 tcf_unbind_filter(tp, &f->res);
286 call_rcu(&f->rcu, fl_destroy_filter);
287}
288
Daniel Borkmannd9363772016-11-27 01:18:01 +0100289static void fl_destroy_sleepable(struct work_struct *work)
290{
291 struct cls_fl_head *head = container_of(work, struct cls_fl_head,
292 work);
293 if (head->mask_assigned)
294 rhashtable_destroy(&head->ht);
295 kfree(head);
296 module_put(THIS_MODULE);
297}
298
299static void fl_destroy_rcu(struct rcu_head *rcu)
300{
301 struct cls_fl_head *head = container_of(rcu, struct cls_fl_head, rcu);
302
303 INIT_WORK(&head->work, fl_destroy_sleepable);
304 schedule_work(&head->work);
305}
306
WANG Cong763dbf62017-04-19 14:21:21 -0700307static void fl_destroy(struct tcf_proto *tp)
Jiri Pirko77b99002015-05-12 14:56:21 +0200308{
309 struct cls_fl_head *head = rtnl_dereference(tp->root);
310 struct cls_fl_filter *f, *next;
311
Roi Dayan13fa8762016-11-01 16:08:29 +0200312 list_for_each_entry_safe(f, next, &head->filters, list)
313 __fl_delete(tp, f);
Chris Mic15ab232017-08-30 02:31:58 -0400314 idr_destroy(&head->handle_idr);
Daniel Borkmannd9363772016-11-27 01:18:01 +0100315
316 __module_get(THIS_MODULE);
317 call_rcu(&head->rcu, fl_destroy_rcu);
Jiri Pirko77b99002015-05-12 14:56:21 +0200318}
319
WANG Cong8113c092017-08-04 21:31:43 -0700320static void *fl_get(struct tcf_proto *tp, u32 handle)
Jiri Pirko77b99002015-05-12 14:56:21 +0200321{
322 struct cls_fl_head *head = rtnl_dereference(tp->root);
Jiri Pirko77b99002015-05-12 14:56:21 +0200323
Chris Mic15ab232017-08-30 02:31:58 -0400324 return idr_find_ext(&head->handle_idr, handle);
Jiri Pirko77b99002015-05-12 14:56:21 +0200325}
326
327static const struct nla_policy fl_policy[TCA_FLOWER_MAX + 1] = {
328 [TCA_FLOWER_UNSPEC] = { .type = NLA_UNSPEC },
329 [TCA_FLOWER_CLASSID] = { .type = NLA_U32 },
330 [TCA_FLOWER_INDEV] = { .type = NLA_STRING,
331 .len = IFNAMSIZ },
332 [TCA_FLOWER_KEY_ETH_DST] = { .len = ETH_ALEN },
333 [TCA_FLOWER_KEY_ETH_DST_MASK] = { .len = ETH_ALEN },
334 [TCA_FLOWER_KEY_ETH_SRC] = { .len = ETH_ALEN },
335 [TCA_FLOWER_KEY_ETH_SRC_MASK] = { .len = ETH_ALEN },
336 [TCA_FLOWER_KEY_ETH_TYPE] = { .type = NLA_U16 },
337 [TCA_FLOWER_KEY_IP_PROTO] = { .type = NLA_U8 },
338 [TCA_FLOWER_KEY_IPV4_SRC] = { .type = NLA_U32 },
339 [TCA_FLOWER_KEY_IPV4_SRC_MASK] = { .type = NLA_U32 },
340 [TCA_FLOWER_KEY_IPV4_DST] = { .type = NLA_U32 },
341 [TCA_FLOWER_KEY_IPV4_DST_MASK] = { .type = NLA_U32 },
342 [TCA_FLOWER_KEY_IPV6_SRC] = { .len = sizeof(struct in6_addr) },
343 [TCA_FLOWER_KEY_IPV6_SRC_MASK] = { .len = sizeof(struct in6_addr) },
344 [TCA_FLOWER_KEY_IPV6_DST] = { .len = sizeof(struct in6_addr) },
345 [TCA_FLOWER_KEY_IPV6_DST_MASK] = { .len = sizeof(struct in6_addr) },
346 [TCA_FLOWER_KEY_TCP_SRC] = { .type = NLA_U16 },
347 [TCA_FLOWER_KEY_TCP_DST] = { .type = NLA_U16 },
Jamal Hadi Salimb175c3a2015-06-25 06:55:27 -0400348 [TCA_FLOWER_KEY_UDP_SRC] = { .type = NLA_U16 },
349 [TCA_FLOWER_KEY_UDP_DST] = { .type = NLA_U16 },
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300350 [TCA_FLOWER_KEY_VLAN_ID] = { .type = NLA_U16 },
351 [TCA_FLOWER_KEY_VLAN_PRIO] = { .type = NLA_U8 },
352 [TCA_FLOWER_KEY_VLAN_ETH_TYPE] = { .type = NLA_U16 },
Amir Vadaibc3103f2016-09-08 16:23:47 +0300353 [TCA_FLOWER_KEY_ENC_KEY_ID] = { .type = NLA_U32 },
354 [TCA_FLOWER_KEY_ENC_IPV4_SRC] = { .type = NLA_U32 },
355 [TCA_FLOWER_KEY_ENC_IPV4_SRC_MASK] = { .type = NLA_U32 },
356 [TCA_FLOWER_KEY_ENC_IPV4_DST] = { .type = NLA_U32 },
357 [TCA_FLOWER_KEY_ENC_IPV4_DST_MASK] = { .type = NLA_U32 },
358 [TCA_FLOWER_KEY_ENC_IPV6_SRC] = { .len = sizeof(struct in6_addr) },
359 [TCA_FLOWER_KEY_ENC_IPV6_SRC_MASK] = { .len = sizeof(struct in6_addr) },
360 [TCA_FLOWER_KEY_ENC_IPV6_DST] = { .len = sizeof(struct in6_addr) },
361 [TCA_FLOWER_KEY_ENC_IPV6_DST_MASK] = { .len = sizeof(struct in6_addr) },
Or Gerlitzaa72d702016-09-15 15:28:22 +0300362 [TCA_FLOWER_KEY_TCP_SRC_MASK] = { .type = NLA_U16 },
363 [TCA_FLOWER_KEY_TCP_DST_MASK] = { .type = NLA_U16 },
364 [TCA_FLOWER_KEY_UDP_SRC_MASK] = { .type = NLA_U16 },
365 [TCA_FLOWER_KEY_UDP_DST_MASK] = { .type = NLA_U16 },
Simon Horman5976c5f2016-11-03 13:24:21 +0100366 [TCA_FLOWER_KEY_SCTP_SRC_MASK] = { .type = NLA_U16 },
367 [TCA_FLOWER_KEY_SCTP_DST_MASK] = { .type = NLA_U16 },
368 [TCA_FLOWER_KEY_SCTP_SRC] = { .type = NLA_U16 },
369 [TCA_FLOWER_KEY_SCTP_DST] = { .type = NLA_U16 },
Hadar Hen Zionf4d997f2016-11-07 15:14:39 +0200370 [TCA_FLOWER_KEY_ENC_UDP_SRC_PORT] = { .type = NLA_U16 },
371 [TCA_FLOWER_KEY_ENC_UDP_SRC_PORT_MASK] = { .type = NLA_U16 },
372 [TCA_FLOWER_KEY_ENC_UDP_DST_PORT] = { .type = NLA_U16 },
373 [TCA_FLOWER_KEY_ENC_UDP_DST_PORT_MASK] = { .type = NLA_U16 },
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200374 [TCA_FLOWER_KEY_FLAGS] = { .type = NLA_U32 },
375 [TCA_FLOWER_KEY_FLAGS_MASK] = { .type = NLA_U32 },
Simon Horman7b684882016-12-07 13:48:28 +0100376 [TCA_FLOWER_KEY_ICMPV4_TYPE] = { .type = NLA_U8 },
377 [TCA_FLOWER_KEY_ICMPV4_TYPE_MASK] = { .type = NLA_U8 },
378 [TCA_FLOWER_KEY_ICMPV4_CODE] = { .type = NLA_U8 },
379 [TCA_FLOWER_KEY_ICMPV4_CODE_MASK] = { .type = NLA_U8 },
380 [TCA_FLOWER_KEY_ICMPV6_TYPE] = { .type = NLA_U8 },
381 [TCA_FLOWER_KEY_ICMPV6_TYPE_MASK] = { .type = NLA_U8 },
382 [TCA_FLOWER_KEY_ICMPV6_CODE] = { .type = NLA_U8 },
383 [TCA_FLOWER_KEY_ICMPV6_CODE_MASK] = { .type = NLA_U8 },
Simon Horman99d31322017-01-11 14:05:43 +0100384 [TCA_FLOWER_KEY_ARP_SIP] = { .type = NLA_U32 },
385 [TCA_FLOWER_KEY_ARP_SIP_MASK] = { .type = NLA_U32 },
386 [TCA_FLOWER_KEY_ARP_TIP] = { .type = NLA_U32 },
387 [TCA_FLOWER_KEY_ARP_TIP_MASK] = { .type = NLA_U32 },
388 [TCA_FLOWER_KEY_ARP_OP] = { .type = NLA_U8 },
389 [TCA_FLOWER_KEY_ARP_OP_MASK] = { .type = NLA_U8 },
390 [TCA_FLOWER_KEY_ARP_SHA] = { .len = ETH_ALEN },
391 [TCA_FLOWER_KEY_ARP_SHA_MASK] = { .len = ETH_ALEN },
392 [TCA_FLOWER_KEY_ARP_THA] = { .len = ETH_ALEN },
393 [TCA_FLOWER_KEY_ARP_THA_MASK] = { .len = ETH_ALEN },
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400394 [TCA_FLOWER_KEY_MPLS_TTL] = { .type = NLA_U8 },
395 [TCA_FLOWER_KEY_MPLS_BOS] = { .type = NLA_U8 },
396 [TCA_FLOWER_KEY_MPLS_TC] = { .type = NLA_U8 },
397 [TCA_FLOWER_KEY_MPLS_LABEL] = { .type = NLA_U32 },
Jiri Pirkofdfc7dd2017-05-23 18:40:45 +0200398 [TCA_FLOWER_KEY_TCP_FLAGS] = { .type = NLA_U16 },
399 [TCA_FLOWER_KEY_TCP_FLAGS_MASK] = { .type = NLA_U16 },
Or Gerlitz4d80cc02017-06-01 21:37:38 +0300400 [TCA_FLOWER_KEY_IP_TOS] = { .type = NLA_U8 },
401 [TCA_FLOWER_KEY_IP_TOS_MASK] = { .type = NLA_U8 },
402 [TCA_FLOWER_KEY_IP_TTL] = { .type = NLA_U8 },
403 [TCA_FLOWER_KEY_IP_TTL_MASK] = { .type = NLA_U8 },
Jiri Pirko77b99002015-05-12 14:56:21 +0200404};
405
406static void fl_set_key_val(struct nlattr **tb,
407 void *val, int val_type,
408 void *mask, int mask_type, int len)
409{
410 if (!tb[val_type])
411 return;
412 memcpy(val, nla_data(tb[val_type]), len);
413 if (mask_type == TCA_FLOWER_UNSPEC || !tb[mask_type])
414 memset(mask, 0xff, len);
415 else
416 memcpy(mask, nla_data(tb[mask_type]), len);
417}
418
Benjamin LaHaise1a7fca62017-05-01 09:58:40 -0400419static int fl_set_key_mpls(struct nlattr **tb,
420 struct flow_dissector_key_mpls *key_val,
421 struct flow_dissector_key_mpls *key_mask)
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400422{
423 if (tb[TCA_FLOWER_KEY_MPLS_TTL]) {
424 key_val->mpls_ttl = nla_get_u8(tb[TCA_FLOWER_KEY_MPLS_TTL]);
425 key_mask->mpls_ttl = MPLS_TTL_MASK;
426 }
427 if (tb[TCA_FLOWER_KEY_MPLS_BOS]) {
Benjamin LaHaise1a7fca62017-05-01 09:58:40 -0400428 u8 bos = nla_get_u8(tb[TCA_FLOWER_KEY_MPLS_BOS]);
429
430 if (bos & ~MPLS_BOS_MASK)
431 return -EINVAL;
432 key_val->mpls_bos = bos;
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400433 key_mask->mpls_bos = MPLS_BOS_MASK;
434 }
435 if (tb[TCA_FLOWER_KEY_MPLS_TC]) {
Benjamin LaHaise1a7fca62017-05-01 09:58:40 -0400436 u8 tc = nla_get_u8(tb[TCA_FLOWER_KEY_MPLS_TC]);
437
438 if (tc & ~MPLS_TC_MASK)
439 return -EINVAL;
440 key_val->mpls_tc = tc;
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400441 key_mask->mpls_tc = MPLS_TC_MASK;
442 }
443 if (tb[TCA_FLOWER_KEY_MPLS_LABEL]) {
Benjamin LaHaise1a7fca62017-05-01 09:58:40 -0400444 u32 label = nla_get_u32(tb[TCA_FLOWER_KEY_MPLS_LABEL]);
445
446 if (label & ~MPLS_LABEL_MASK)
447 return -EINVAL;
448 key_val->mpls_label = label;
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400449 key_mask->mpls_label = MPLS_LABEL_MASK;
450 }
Benjamin LaHaise1a7fca62017-05-01 09:58:40 -0400451 return 0;
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400452}
453
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300454static void fl_set_key_vlan(struct nlattr **tb,
455 struct flow_dissector_key_vlan *key_val,
456 struct flow_dissector_key_vlan *key_mask)
457{
458#define VLAN_PRIORITY_MASK 0x7
459
460 if (tb[TCA_FLOWER_KEY_VLAN_ID]) {
461 key_val->vlan_id =
462 nla_get_u16(tb[TCA_FLOWER_KEY_VLAN_ID]) & VLAN_VID_MASK;
463 key_mask->vlan_id = VLAN_VID_MASK;
464 }
465 if (tb[TCA_FLOWER_KEY_VLAN_PRIO]) {
466 key_val->vlan_priority =
467 nla_get_u8(tb[TCA_FLOWER_KEY_VLAN_PRIO]) &
468 VLAN_PRIORITY_MASK;
469 key_mask->vlan_priority = VLAN_PRIORITY_MASK;
470 }
471}
472
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200473static void fl_set_key_flag(u32 flower_key, u32 flower_mask,
474 u32 *dissector_key, u32 *dissector_mask,
475 u32 flower_flag_bit, u32 dissector_flag_bit)
476{
477 if (flower_mask & flower_flag_bit) {
478 *dissector_mask |= dissector_flag_bit;
479 if (flower_key & flower_flag_bit)
480 *dissector_key |= dissector_flag_bit;
481 }
482}
483
Or Gerlitzd9724772016-12-22 14:28:15 +0200484static int fl_set_key_flags(struct nlattr **tb,
485 u32 *flags_key, u32 *flags_mask)
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200486{
487 u32 key, mask;
488
Or Gerlitzd9724772016-12-22 14:28:15 +0200489 /* mask is mandatory for flags */
490 if (!tb[TCA_FLOWER_KEY_FLAGS_MASK])
491 return -EINVAL;
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200492
493 key = be32_to_cpu(nla_get_u32(tb[TCA_FLOWER_KEY_FLAGS]));
Or Gerlitzd9724772016-12-22 14:28:15 +0200494 mask = be32_to_cpu(nla_get_u32(tb[TCA_FLOWER_KEY_FLAGS_MASK]));
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200495
496 *flags_key = 0;
497 *flags_mask = 0;
498
499 fl_set_key_flag(key, mask, flags_key, flags_mask,
500 TCA_FLOWER_KEY_FLAGS_IS_FRAGMENT, FLOW_DIS_IS_FRAGMENT);
Or Gerlitzd9724772016-12-22 14:28:15 +0200501
502 return 0;
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200503}
504
Or Gerlitz4d80cc02017-06-01 21:37:38 +0300505static void fl_set_key_ip(struct nlattr **tb,
506 struct flow_dissector_key_ip *key,
507 struct flow_dissector_key_ip *mask)
508{
509 fl_set_key_val(tb, &key->tos, TCA_FLOWER_KEY_IP_TOS,
510 &mask->tos, TCA_FLOWER_KEY_IP_TOS_MASK,
511 sizeof(key->tos));
512
513 fl_set_key_val(tb, &key->ttl, TCA_FLOWER_KEY_IP_TTL,
514 &mask->ttl, TCA_FLOWER_KEY_IP_TTL_MASK,
515 sizeof(key->ttl));
516}
517
Jiri Pirko77b99002015-05-12 14:56:21 +0200518static int fl_set_key(struct net *net, struct nlattr **tb,
519 struct fl_flow_key *key, struct fl_flow_key *mask)
520{
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300521 __be16 ethertype;
Or Gerlitzd9724772016-12-22 14:28:15 +0200522 int ret = 0;
Brian Haleydd3aa3b2015-05-14 13:20:15 -0400523#ifdef CONFIG_NET_CLS_IND
Jiri Pirko77b99002015-05-12 14:56:21 +0200524 if (tb[TCA_FLOWER_INDEV]) {
Brian Haleydd3aa3b2015-05-14 13:20:15 -0400525 int err = tcf_change_indev(net, tb[TCA_FLOWER_INDEV]);
Jiri Pirko77b99002015-05-12 14:56:21 +0200526 if (err < 0)
527 return err;
528 key->indev_ifindex = err;
529 mask->indev_ifindex = 0xffffffff;
530 }
Brian Haleydd3aa3b2015-05-14 13:20:15 -0400531#endif
Jiri Pirko77b99002015-05-12 14:56:21 +0200532
533 fl_set_key_val(tb, key->eth.dst, TCA_FLOWER_KEY_ETH_DST,
534 mask->eth.dst, TCA_FLOWER_KEY_ETH_DST_MASK,
535 sizeof(key->eth.dst));
536 fl_set_key_val(tb, key->eth.src, TCA_FLOWER_KEY_ETH_SRC,
537 mask->eth.src, TCA_FLOWER_KEY_ETH_SRC_MASK,
538 sizeof(key->eth.src));
Jamal Hadi Salim66530bd2016-01-10 11:47:01 -0500539
Arnd Bergmann0b498a52016-08-26 17:25:45 +0200540 if (tb[TCA_FLOWER_KEY_ETH_TYPE]) {
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300541 ethertype = nla_get_be16(tb[TCA_FLOWER_KEY_ETH_TYPE]);
542
Arnd Bergmann0b498a52016-08-26 17:25:45 +0200543 if (ethertype == htons(ETH_P_8021Q)) {
544 fl_set_key_vlan(tb, &key->vlan, &mask->vlan);
545 fl_set_key_val(tb, &key->basic.n_proto,
546 TCA_FLOWER_KEY_VLAN_ETH_TYPE,
547 &mask->basic.n_proto, TCA_FLOWER_UNSPEC,
548 sizeof(key->basic.n_proto));
549 } else {
550 key->basic.n_proto = ethertype;
551 mask->basic.n_proto = cpu_to_be16(~0);
552 }
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300553 }
Jamal Hadi Salim66530bd2016-01-10 11:47:01 -0500554
Jiri Pirko77b99002015-05-12 14:56:21 +0200555 if (key->basic.n_proto == htons(ETH_P_IP) ||
556 key->basic.n_proto == htons(ETH_P_IPV6)) {
557 fl_set_key_val(tb, &key->basic.ip_proto, TCA_FLOWER_KEY_IP_PROTO,
558 &mask->basic.ip_proto, TCA_FLOWER_UNSPEC,
559 sizeof(key->basic.ip_proto));
Or Gerlitz4d80cc02017-06-01 21:37:38 +0300560 fl_set_key_ip(tb, &key->ip, &mask->ip);
Jiri Pirko77b99002015-05-12 14:56:21 +0200561 }
Jamal Hadi Salim66530bd2016-01-10 11:47:01 -0500562
563 if (tb[TCA_FLOWER_KEY_IPV4_SRC] || tb[TCA_FLOWER_KEY_IPV4_DST]) {
564 key->control.addr_type = FLOW_DISSECTOR_KEY_IPV4_ADDRS;
Paul Blakey970bfcd2016-12-14 19:00:57 +0200565 mask->control.addr_type = ~0;
Jiri Pirko77b99002015-05-12 14:56:21 +0200566 fl_set_key_val(tb, &key->ipv4.src, TCA_FLOWER_KEY_IPV4_SRC,
567 &mask->ipv4.src, TCA_FLOWER_KEY_IPV4_SRC_MASK,
568 sizeof(key->ipv4.src));
569 fl_set_key_val(tb, &key->ipv4.dst, TCA_FLOWER_KEY_IPV4_DST,
570 &mask->ipv4.dst, TCA_FLOWER_KEY_IPV4_DST_MASK,
571 sizeof(key->ipv4.dst));
Jamal Hadi Salim66530bd2016-01-10 11:47:01 -0500572 } else if (tb[TCA_FLOWER_KEY_IPV6_SRC] || tb[TCA_FLOWER_KEY_IPV6_DST]) {
573 key->control.addr_type = FLOW_DISSECTOR_KEY_IPV6_ADDRS;
Paul Blakey970bfcd2016-12-14 19:00:57 +0200574 mask->control.addr_type = ~0;
Jiri Pirko77b99002015-05-12 14:56:21 +0200575 fl_set_key_val(tb, &key->ipv6.src, TCA_FLOWER_KEY_IPV6_SRC,
576 &mask->ipv6.src, TCA_FLOWER_KEY_IPV6_SRC_MASK,
577 sizeof(key->ipv6.src));
578 fl_set_key_val(tb, &key->ipv6.dst, TCA_FLOWER_KEY_IPV6_DST,
579 &mask->ipv6.dst, TCA_FLOWER_KEY_IPV6_DST_MASK,
580 sizeof(key->ipv6.dst));
581 }
Jamal Hadi Salim66530bd2016-01-10 11:47:01 -0500582
Jiri Pirko77b99002015-05-12 14:56:21 +0200583 if (key->basic.ip_proto == IPPROTO_TCP) {
584 fl_set_key_val(tb, &key->tp.src, TCA_FLOWER_KEY_TCP_SRC,
Or Gerlitzaa72d702016-09-15 15:28:22 +0300585 &mask->tp.src, TCA_FLOWER_KEY_TCP_SRC_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +0200586 sizeof(key->tp.src));
587 fl_set_key_val(tb, &key->tp.dst, TCA_FLOWER_KEY_TCP_DST,
Or Gerlitzaa72d702016-09-15 15:28:22 +0300588 &mask->tp.dst, TCA_FLOWER_KEY_TCP_DST_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +0200589 sizeof(key->tp.dst));
Jiri Pirkofdfc7dd2017-05-23 18:40:45 +0200590 fl_set_key_val(tb, &key->tcp.flags, TCA_FLOWER_KEY_TCP_FLAGS,
591 &mask->tcp.flags, TCA_FLOWER_KEY_TCP_FLAGS_MASK,
592 sizeof(key->tcp.flags));
Jiri Pirko77b99002015-05-12 14:56:21 +0200593 } else if (key->basic.ip_proto == IPPROTO_UDP) {
594 fl_set_key_val(tb, &key->tp.src, TCA_FLOWER_KEY_UDP_SRC,
Or Gerlitzaa72d702016-09-15 15:28:22 +0300595 &mask->tp.src, TCA_FLOWER_KEY_UDP_SRC_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +0200596 sizeof(key->tp.src));
597 fl_set_key_val(tb, &key->tp.dst, TCA_FLOWER_KEY_UDP_DST,
Or Gerlitzaa72d702016-09-15 15:28:22 +0300598 &mask->tp.dst, TCA_FLOWER_KEY_UDP_DST_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +0200599 sizeof(key->tp.dst));
Simon Horman5976c5f2016-11-03 13:24:21 +0100600 } else if (key->basic.ip_proto == IPPROTO_SCTP) {
601 fl_set_key_val(tb, &key->tp.src, TCA_FLOWER_KEY_SCTP_SRC,
602 &mask->tp.src, TCA_FLOWER_KEY_SCTP_SRC_MASK,
603 sizeof(key->tp.src));
604 fl_set_key_val(tb, &key->tp.dst, TCA_FLOWER_KEY_SCTP_DST,
605 &mask->tp.dst, TCA_FLOWER_KEY_SCTP_DST_MASK,
606 sizeof(key->tp.dst));
Simon Horman7b684882016-12-07 13:48:28 +0100607 } else if (key->basic.n_proto == htons(ETH_P_IP) &&
608 key->basic.ip_proto == IPPROTO_ICMP) {
609 fl_set_key_val(tb, &key->icmp.type, TCA_FLOWER_KEY_ICMPV4_TYPE,
610 &mask->icmp.type,
611 TCA_FLOWER_KEY_ICMPV4_TYPE_MASK,
612 sizeof(key->icmp.type));
613 fl_set_key_val(tb, &key->icmp.code, TCA_FLOWER_KEY_ICMPV4_CODE,
614 &mask->icmp.code,
615 TCA_FLOWER_KEY_ICMPV4_CODE_MASK,
616 sizeof(key->icmp.code));
617 } else if (key->basic.n_proto == htons(ETH_P_IPV6) &&
618 key->basic.ip_proto == IPPROTO_ICMPV6) {
619 fl_set_key_val(tb, &key->icmp.type, TCA_FLOWER_KEY_ICMPV6_TYPE,
620 &mask->icmp.type,
621 TCA_FLOWER_KEY_ICMPV6_TYPE_MASK,
622 sizeof(key->icmp.type));
Simon Horman040587a2017-01-30 16:19:02 +0100623 fl_set_key_val(tb, &key->icmp.code, TCA_FLOWER_KEY_ICMPV6_CODE,
Simon Horman7b684882016-12-07 13:48:28 +0100624 &mask->icmp.code,
Simon Horman040587a2017-01-30 16:19:02 +0100625 TCA_FLOWER_KEY_ICMPV6_CODE_MASK,
Simon Horman7b684882016-12-07 13:48:28 +0100626 sizeof(key->icmp.code));
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400627 } else if (key->basic.n_proto == htons(ETH_P_MPLS_UC) ||
628 key->basic.n_proto == htons(ETH_P_MPLS_MC)) {
Benjamin LaHaise1a7fca62017-05-01 09:58:40 -0400629 ret = fl_set_key_mpls(tb, &key->mpls, &mask->mpls);
630 if (ret)
631 return ret;
Simon Horman99d31322017-01-11 14:05:43 +0100632 } else if (key->basic.n_proto == htons(ETH_P_ARP) ||
633 key->basic.n_proto == htons(ETH_P_RARP)) {
634 fl_set_key_val(tb, &key->arp.sip, TCA_FLOWER_KEY_ARP_SIP,
635 &mask->arp.sip, TCA_FLOWER_KEY_ARP_SIP_MASK,
636 sizeof(key->arp.sip));
637 fl_set_key_val(tb, &key->arp.tip, TCA_FLOWER_KEY_ARP_TIP,
638 &mask->arp.tip, TCA_FLOWER_KEY_ARP_TIP_MASK,
639 sizeof(key->arp.tip));
640 fl_set_key_val(tb, &key->arp.op, TCA_FLOWER_KEY_ARP_OP,
641 &mask->arp.op, TCA_FLOWER_KEY_ARP_OP_MASK,
642 sizeof(key->arp.op));
643 fl_set_key_val(tb, key->arp.sha, TCA_FLOWER_KEY_ARP_SHA,
644 mask->arp.sha, TCA_FLOWER_KEY_ARP_SHA_MASK,
645 sizeof(key->arp.sha));
646 fl_set_key_val(tb, key->arp.tha, TCA_FLOWER_KEY_ARP_THA,
647 mask->arp.tha, TCA_FLOWER_KEY_ARP_THA_MASK,
648 sizeof(key->arp.tha));
Jiri Pirko77b99002015-05-12 14:56:21 +0200649 }
650
Amir Vadaibc3103f2016-09-08 16:23:47 +0300651 if (tb[TCA_FLOWER_KEY_ENC_IPV4_SRC] ||
652 tb[TCA_FLOWER_KEY_ENC_IPV4_DST]) {
653 key->enc_control.addr_type = FLOW_DISSECTOR_KEY_IPV4_ADDRS;
Paul Blakey970bfcd2016-12-14 19:00:57 +0200654 mask->enc_control.addr_type = ~0;
Amir Vadaibc3103f2016-09-08 16:23:47 +0300655 fl_set_key_val(tb, &key->enc_ipv4.src,
656 TCA_FLOWER_KEY_ENC_IPV4_SRC,
657 &mask->enc_ipv4.src,
658 TCA_FLOWER_KEY_ENC_IPV4_SRC_MASK,
659 sizeof(key->enc_ipv4.src));
660 fl_set_key_val(tb, &key->enc_ipv4.dst,
661 TCA_FLOWER_KEY_ENC_IPV4_DST,
662 &mask->enc_ipv4.dst,
663 TCA_FLOWER_KEY_ENC_IPV4_DST_MASK,
664 sizeof(key->enc_ipv4.dst));
665 }
666
667 if (tb[TCA_FLOWER_KEY_ENC_IPV6_SRC] ||
668 tb[TCA_FLOWER_KEY_ENC_IPV6_DST]) {
669 key->enc_control.addr_type = FLOW_DISSECTOR_KEY_IPV6_ADDRS;
Paul Blakey970bfcd2016-12-14 19:00:57 +0200670 mask->enc_control.addr_type = ~0;
Amir Vadaibc3103f2016-09-08 16:23:47 +0300671 fl_set_key_val(tb, &key->enc_ipv6.src,
672 TCA_FLOWER_KEY_ENC_IPV6_SRC,
673 &mask->enc_ipv6.src,
674 TCA_FLOWER_KEY_ENC_IPV6_SRC_MASK,
675 sizeof(key->enc_ipv6.src));
676 fl_set_key_val(tb, &key->enc_ipv6.dst,
677 TCA_FLOWER_KEY_ENC_IPV6_DST,
678 &mask->enc_ipv6.dst,
679 TCA_FLOWER_KEY_ENC_IPV6_DST_MASK,
680 sizeof(key->enc_ipv6.dst));
681 }
682
683 fl_set_key_val(tb, &key->enc_key_id.keyid, TCA_FLOWER_KEY_ENC_KEY_ID,
Hadar Hen Zioneb523f42016-09-27 11:21:18 +0300684 &mask->enc_key_id.keyid, TCA_FLOWER_UNSPEC,
Amir Vadaibc3103f2016-09-08 16:23:47 +0300685 sizeof(key->enc_key_id.keyid));
686
Hadar Hen Zionf4d997f2016-11-07 15:14:39 +0200687 fl_set_key_val(tb, &key->enc_tp.src, TCA_FLOWER_KEY_ENC_UDP_SRC_PORT,
688 &mask->enc_tp.src, TCA_FLOWER_KEY_ENC_UDP_SRC_PORT_MASK,
689 sizeof(key->enc_tp.src));
690
691 fl_set_key_val(tb, &key->enc_tp.dst, TCA_FLOWER_KEY_ENC_UDP_DST_PORT,
692 &mask->enc_tp.dst, TCA_FLOWER_KEY_ENC_UDP_DST_PORT_MASK,
693 sizeof(key->enc_tp.dst));
694
Or Gerlitzd9724772016-12-22 14:28:15 +0200695 if (tb[TCA_FLOWER_KEY_FLAGS])
696 ret = fl_set_key_flags(tb, &key->control.flags, &mask->control.flags);
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +0200697
Or Gerlitzd9724772016-12-22 14:28:15 +0200698 return ret;
Jiri Pirko77b99002015-05-12 14:56:21 +0200699}
700
701static bool fl_mask_eq(struct fl_flow_mask *mask1,
702 struct fl_flow_mask *mask2)
703{
704 const long *lmask1 = fl_key_get_start(&mask1->key, mask1);
705 const long *lmask2 = fl_key_get_start(&mask2->key, mask2);
706
707 return !memcmp(&mask1->range, &mask2->range, sizeof(mask1->range)) &&
708 !memcmp(lmask1, lmask2, fl_mask_range(mask1));
709}
710
711static const struct rhashtable_params fl_ht_params = {
712 .key_offset = offsetof(struct cls_fl_filter, mkey), /* base offset */
713 .head_offset = offsetof(struct cls_fl_filter, ht_node),
714 .automatic_shrinking = true,
715};
716
717static int fl_init_hashtable(struct cls_fl_head *head,
718 struct fl_flow_mask *mask)
719{
720 head->ht_params = fl_ht_params;
721 head->ht_params.key_len = fl_mask_range(mask);
722 head->ht_params.key_offset += mask->range.start;
723
724 return rhashtable_init(&head->ht, &head->ht_params);
725}
726
727#define FL_KEY_MEMBER_OFFSET(member) offsetof(struct fl_flow_key, member)
728#define FL_KEY_MEMBER_SIZE(member) (sizeof(((struct fl_flow_key *) 0)->member))
Jiri Pirko77b99002015-05-12 14:56:21 +0200729
Hadar Hen Zion339ba872016-08-17 13:36:12 +0300730#define FL_KEY_IS_MASKED(mask, member) \
731 memchr_inv(((char *)mask) + FL_KEY_MEMBER_OFFSET(member), \
732 0, FL_KEY_MEMBER_SIZE(member)) \
Jiri Pirko77b99002015-05-12 14:56:21 +0200733
734#define FL_KEY_SET(keys, cnt, id, member) \
735 do { \
736 keys[cnt].key_id = id; \
737 keys[cnt].offset = FL_KEY_MEMBER_OFFSET(member); \
738 cnt++; \
739 } while(0);
740
Hadar Hen Zion339ba872016-08-17 13:36:12 +0300741#define FL_KEY_SET_IF_MASKED(mask, keys, cnt, id, member) \
Jiri Pirko77b99002015-05-12 14:56:21 +0200742 do { \
Hadar Hen Zion339ba872016-08-17 13:36:12 +0300743 if (FL_KEY_IS_MASKED(mask, member)) \
Jiri Pirko77b99002015-05-12 14:56:21 +0200744 FL_KEY_SET(keys, cnt, id, member); \
745 } while(0);
746
747static void fl_init_dissector(struct cls_fl_head *head,
748 struct fl_flow_mask *mask)
749{
750 struct flow_dissector_key keys[FLOW_DISSECTOR_KEY_MAX];
751 size_t cnt = 0;
752
Tom Herbert42aecaa2015-06-04 09:16:39 -0700753 FL_KEY_SET(keys, cnt, FLOW_DISSECTOR_KEY_CONTROL, control);
Jiri Pirko77b99002015-05-12 14:56:21 +0200754 FL_KEY_SET(keys, cnt, FLOW_DISSECTOR_KEY_BASIC, basic);
Hadar Hen Zion339ba872016-08-17 13:36:12 +0300755 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
756 FLOW_DISSECTOR_KEY_ETH_ADDRS, eth);
757 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
758 FLOW_DISSECTOR_KEY_IPV4_ADDRS, ipv4);
759 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
760 FLOW_DISSECTOR_KEY_IPV6_ADDRS, ipv6);
761 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
762 FLOW_DISSECTOR_KEY_PORTS, tp);
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300763 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
Or Gerlitz4d80cc02017-06-01 21:37:38 +0300764 FLOW_DISSECTOR_KEY_IP, ip);
765 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
Jiri Pirkofdfc7dd2017-05-23 18:40:45 +0200766 FLOW_DISSECTOR_KEY_TCP, tcp);
767 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
Simon Horman7b684882016-12-07 13:48:28 +0100768 FLOW_DISSECTOR_KEY_ICMP, icmp);
769 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
Simon Horman99d31322017-01-11 14:05:43 +0100770 FLOW_DISSECTOR_KEY_ARP, arp);
771 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -0400772 FLOW_DISSECTOR_KEY_MPLS, mpls);
773 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
Hadar Hen Zion9399ae92016-08-17 13:36:13 +0300774 FLOW_DISSECTOR_KEY_VLAN, vlan);
Hadar Hen Zion519d1052016-11-07 15:14:38 +0200775 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
776 FLOW_DISSECTOR_KEY_ENC_KEYID, enc_key_id);
777 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
778 FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, enc_ipv4);
779 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
780 FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, enc_ipv6);
781 if (FL_KEY_IS_MASKED(&mask->key, enc_ipv4) ||
782 FL_KEY_IS_MASKED(&mask->key, enc_ipv6))
783 FL_KEY_SET(keys, cnt, FLOW_DISSECTOR_KEY_ENC_CONTROL,
784 enc_control);
Hadar Hen Zionf4d997f2016-11-07 15:14:39 +0200785 FL_KEY_SET_IF_MASKED(&mask->key, keys, cnt,
786 FLOW_DISSECTOR_KEY_ENC_PORTS, enc_tp);
Jiri Pirko77b99002015-05-12 14:56:21 +0200787
788 skb_flow_dissector_init(&head->dissector, keys, cnt);
789}
790
791static int fl_check_assign_mask(struct cls_fl_head *head,
792 struct fl_flow_mask *mask)
793{
794 int err;
795
796 if (head->mask_assigned) {
797 if (!fl_mask_eq(&head->mask, mask))
798 return -EINVAL;
799 else
800 return 0;
801 }
802
803 /* Mask is not assigned yet. So assign it and init hashtable
804 * according to that.
805 */
806 err = fl_init_hashtable(head, mask);
807 if (err)
808 return err;
809 memcpy(&head->mask, mask, sizeof(head->mask));
810 head->mask_assigned = true;
811
812 fl_init_dissector(head, mask);
813
814 return 0;
815}
816
817static int fl_set_parms(struct net *net, struct tcf_proto *tp,
818 struct cls_fl_filter *f, struct fl_flow_mask *mask,
819 unsigned long base, struct nlattr **tb,
820 struct nlattr *est, bool ovr)
821{
Jiri Pirko77b99002015-05-12 14:56:21 +0200822 int err;
823
Jiri Pirko45507522017-08-04 14:29:06 +0200824 err = tcf_exts_validate(net, tp, tb, est, &f->exts, ovr);
Jiri Pirko77b99002015-05-12 14:56:21 +0200825 if (err < 0)
826 return err;
827
828 if (tb[TCA_FLOWER_CLASSID]) {
829 f->res.classid = nla_get_u32(tb[TCA_FLOWER_CLASSID]);
830 tcf_bind_filter(tp, &f->res, base);
831 }
832
833 err = fl_set_key(net, tb, &f->key, &mask->key);
834 if (err)
Jiri Pirko45507522017-08-04 14:29:06 +0200835 return err;
Jiri Pirko77b99002015-05-12 14:56:21 +0200836
837 fl_mask_update_range(mask);
838 fl_set_masked_key(&f->mkey, &f->key, mask);
839
Jiri Pirko77b99002015-05-12 14:56:21 +0200840 return 0;
Jiri Pirko77b99002015-05-12 14:56:21 +0200841}
842
Jiri Pirko77b99002015-05-12 14:56:21 +0200843static int fl_change(struct net *net, struct sk_buff *in_skb,
844 struct tcf_proto *tp, unsigned long base,
845 u32 handle, struct nlattr **tca,
WANG Cong8113c092017-08-04 21:31:43 -0700846 void **arg, bool ovr)
Jiri Pirko77b99002015-05-12 14:56:21 +0200847{
848 struct cls_fl_head *head = rtnl_dereference(tp->root);
WANG Cong8113c092017-08-04 21:31:43 -0700849 struct cls_fl_filter *fold = *arg;
Jiri Pirko77b99002015-05-12 14:56:21 +0200850 struct cls_fl_filter *fnew;
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100851 struct nlattr **tb;
Jiri Pirko77b99002015-05-12 14:56:21 +0200852 struct fl_flow_mask mask = {};
Chris Mic15ab232017-08-30 02:31:58 -0400853 unsigned long idr_index;
Jiri Pirko77b99002015-05-12 14:56:21 +0200854 int err;
855
856 if (!tca[TCA_OPTIONS])
857 return -EINVAL;
858
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100859 tb = kcalloc(TCA_FLOWER_MAX + 1, sizeof(struct nlattr *), GFP_KERNEL);
860 if (!tb)
861 return -ENOBUFS;
862
Johannes Bergfceb6432017-04-12 14:34:07 +0200863 err = nla_parse_nested(tb, TCA_FLOWER_MAX, tca[TCA_OPTIONS],
864 fl_policy, NULL);
Jiri Pirko77b99002015-05-12 14:56:21 +0200865 if (err < 0)
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100866 goto errout_tb;
Jiri Pirko77b99002015-05-12 14:56:21 +0200867
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100868 if (fold && handle && fold->handle != handle) {
869 err = -EINVAL;
870 goto errout_tb;
871 }
Jiri Pirko77b99002015-05-12 14:56:21 +0200872
873 fnew = kzalloc(sizeof(*fnew), GFP_KERNEL);
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100874 if (!fnew) {
875 err = -ENOBUFS;
876 goto errout_tb;
877 }
Jiri Pirko77b99002015-05-12 14:56:21 +0200878
WANG Congb9a24bb2016-08-19 12:36:54 -0700879 err = tcf_exts_init(&fnew->exts, TCA_FLOWER_ACT, 0);
880 if (err < 0)
881 goto errout;
Jiri Pirko77b99002015-05-12 14:56:21 +0200882
883 if (!handle) {
Chris Mic15ab232017-08-30 02:31:58 -0400884 err = idr_alloc_ext(&head->handle_idr, fnew, &idr_index,
885 1, 0x80000000, GFP_KERNEL);
886 if (err)
Jiri Pirko77b99002015-05-12 14:56:21 +0200887 goto errout;
Chris Mic15ab232017-08-30 02:31:58 -0400888 fnew->handle = idr_index;
Jiri Pirko77b99002015-05-12 14:56:21 +0200889 }
Chris Mic15ab232017-08-30 02:31:58 -0400890
891 /* user specifies a handle and it doesn't exist */
892 if (handle && !fold) {
893 err = idr_alloc_ext(&head->handle_idr, fnew, &idr_index,
894 handle, handle + 1, GFP_KERNEL);
895 if (err)
896 goto errout;
897 fnew->handle = idr_index;
898 }
Jiri Pirko77b99002015-05-12 14:56:21 +0200899
Amir Vadaie69985c2016-06-05 17:11:18 +0300900 if (tb[TCA_FLOWER_FLAGS]) {
901 fnew->flags = nla_get_u32(tb[TCA_FLOWER_FLAGS]);
902
903 if (!tc_flags_valid(fnew->flags)) {
904 err = -EINVAL;
Cong Wangfe2502e2017-09-20 09:18:45 -0700905 goto errout_idr;
Amir Vadaie69985c2016-06-05 17:11:18 +0300906 }
907 }
Amir Vadai5b33f482016-03-08 12:42:29 +0200908
Jiri Pirko77b99002015-05-12 14:56:21 +0200909 err = fl_set_parms(net, tp, fnew, &mask, base, tb, tca[TCA_RATE], ovr);
910 if (err)
Cong Wangfe2502e2017-09-20 09:18:45 -0700911 goto errout_idr;
Jiri Pirko77b99002015-05-12 14:56:21 +0200912
913 err = fl_check_assign_mask(head, &mask);
914 if (err)
Cong Wangfe2502e2017-09-20 09:18:45 -0700915 goto errout_idr;
Jiri Pirko77b99002015-05-12 14:56:21 +0200916
Amir Vadaie8eb36c2016-06-13 12:06:39 +0300917 if (!tc_skip_sw(fnew->flags)) {
Paul Blakeya3308d82017-01-16 10:45:13 +0200918 if (!fold && fl_lookup(head, &fnew->mkey)) {
919 err = -EEXIST;
Cong Wangfe2502e2017-09-20 09:18:45 -0700920 goto errout_idr;
Paul Blakeya3308d82017-01-16 10:45:13 +0200921 }
922
Amir Vadaie69985c2016-06-05 17:11:18 +0300923 err = rhashtable_insert_fast(&head->ht, &fnew->ht_node,
924 head->ht_params);
925 if (err)
Cong Wangfe2502e2017-09-20 09:18:45 -0700926 goto errout_idr;
Amir Vadaie69985c2016-06-05 17:11:18 +0300927 }
Amir Vadai5b33f482016-03-08 12:42:29 +0200928
Hadar Hen Zion79685212016-12-01 14:06:34 +0200929 if (!tc_skip_hw(fnew->flags)) {
930 err = fl_hw_replace_filter(tp,
931 &head->dissector,
932 &mask.key,
Hadar Hen Zion3036dab2016-12-01 14:06:35 +0200933 fnew);
Hadar Hen Zion79685212016-12-01 14:06:34 +0200934 if (err)
Cong Wangfe2502e2017-09-20 09:18:45 -0700935 goto errout_idr;
Hadar Hen Zion79685212016-12-01 14:06:34 +0200936 }
Amir Vadai5b33f482016-03-08 12:42:29 +0200937
Or Gerlitz55593962017-02-16 10:31:13 +0200938 if (!tc_in_hw(fnew->flags))
939 fnew->flags |= TCA_CLS_FLAGS_NOT_IN_HW;
940
Amir Vadai5b33f482016-03-08 12:42:29 +0200941 if (fold) {
Jiri Pirko725cbb622016-11-28 15:40:13 +0100942 if (!tc_skip_sw(fold->flags))
943 rhashtable_remove_fast(&head->ht, &fold->ht_node,
944 head->ht_params);
Hadar Hen Zion79685212016-12-01 14:06:34 +0200945 if (!tc_skip_hw(fold->flags))
Hadar Hen Zion3036dab2016-12-01 14:06:35 +0200946 fl_hw_destroy_filter(tp, fold);
Amir Vadai5b33f482016-03-08 12:42:29 +0200947 }
Jiri Pirko77b99002015-05-12 14:56:21 +0200948
WANG Cong8113c092017-08-04 21:31:43 -0700949 *arg = fnew;
Jiri Pirko77b99002015-05-12 14:56:21 +0200950
951 if (fold) {
Chris Mic15ab232017-08-30 02:31:58 -0400952 fnew->handle = handle;
953 idr_replace_ext(&head->handle_idr, fnew, fnew->handle);
Daniel Borkmannff3532f2015-07-17 22:38:44 +0200954 list_replace_rcu(&fold->list, &fnew->list);
Jiri Pirko77b99002015-05-12 14:56:21 +0200955 tcf_unbind_filter(tp, &fold->res);
956 call_rcu(&fold->rcu, fl_destroy_filter);
957 } else {
958 list_add_tail_rcu(&fnew->list, &head->filters);
959 }
960
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100961 kfree(tb);
Jiri Pirko77b99002015-05-12 14:56:21 +0200962 return 0;
963
Cong Wangfe2502e2017-09-20 09:18:45 -0700964errout_idr:
965 if (fnew->handle)
966 idr_remove_ext(&head->handle_idr, fnew->handle);
Jiri Pirko77b99002015-05-12 14:56:21 +0200967errout:
WANG Congb9a24bb2016-08-19 12:36:54 -0700968 tcf_exts_destroy(&fnew->exts);
Jiri Pirko77b99002015-05-12 14:56:21 +0200969 kfree(fnew);
Arnd Bergmann39b7b6a2017-01-19 10:45:31 +0100970errout_tb:
971 kfree(tb);
Jiri Pirko77b99002015-05-12 14:56:21 +0200972 return err;
973}
974
WANG Cong8113c092017-08-04 21:31:43 -0700975static int fl_delete(struct tcf_proto *tp, void *arg, bool *last)
Jiri Pirko77b99002015-05-12 14:56:21 +0200976{
977 struct cls_fl_head *head = rtnl_dereference(tp->root);
WANG Cong8113c092017-08-04 21:31:43 -0700978 struct cls_fl_filter *f = arg;
Jiri Pirko77b99002015-05-12 14:56:21 +0200979
Jiri Pirko725cbb622016-11-28 15:40:13 +0100980 if (!tc_skip_sw(f->flags))
981 rhashtable_remove_fast(&head->ht, &f->ht_node,
982 head->ht_params);
Roi Dayan13fa8762016-11-01 16:08:29 +0200983 __fl_delete(tp, f);
WANG Cong763dbf62017-04-19 14:21:21 -0700984 *last = list_empty(&head->filters);
Jiri Pirko77b99002015-05-12 14:56:21 +0200985 return 0;
986}
987
988static void fl_walk(struct tcf_proto *tp, struct tcf_walker *arg)
989{
990 struct cls_fl_head *head = rtnl_dereference(tp->root);
991 struct cls_fl_filter *f;
992
993 list_for_each_entry_rcu(f, &head->filters, list) {
994 if (arg->count < arg->skip)
995 goto skip;
WANG Cong8113c092017-08-04 21:31:43 -0700996 if (arg->fn(tp, f, arg) < 0) {
Jiri Pirko77b99002015-05-12 14:56:21 +0200997 arg->stop = 1;
998 break;
999 }
1000skip:
1001 arg->count++;
1002 }
1003}
1004
1005static int fl_dump_key_val(struct sk_buff *skb,
1006 void *val, int val_type,
1007 void *mask, int mask_type, int len)
1008{
1009 int err;
1010
1011 if (!memchr_inv(mask, 0, len))
1012 return 0;
1013 err = nla_put(skb, val_type, len, val);
1014 if (err)
1015 return err;
1016 if (mask_type != TCA_FLOWER_UNSPEC) {
1017 err = nla_put(skb, mask_type, len, mask);
1018 if (err)
1019 return err;
1020 }
1021 return 0;
1022}
1023
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -04001024static int fl_dump_key_mpls(struct sk_buff *skb,
1025 struct flow_dissector_key_mpls *mpls_key,
1026 struct flow_dissector_key_mpls *mpls_mask)
1027{
1028 int err;
1029
1030 if (!memchr_inv(mpls_mask, 0, sizeof(*mpls_mask)))
1031 return 0;
1032 if (mpls_mask->mpls_ttl) {
1033 err = nla_put_u8(skb, TCA_FLOWER_KEY_MPLS_TTL,
1034 mpls_key->mpls_ttl);
1035 if (err)
1036 return err;
1037 }
1038 if (mpls_mask->mpls_tc) {
1039 err = nla_put_u8(skb, TCA_FLOWER_KEY_MPLS_TC,
1040 mpls_key->mpls_tc);
1041 if (err)
1042 return err;
1043 }
1044 if (mpls_mask->mpls_label) {
1045 err = nla_put_u32(skb, TCA_FLOWER_KEY_MPLS_LABEL,
1046 mpls_key->mpls_label);
1047 if (err)
1048 return err;
1049 }
1050 if (mpls_mask->mpls_bos) {
1051 err = nla_put_u8(skb, TCA_FLOWER_KEY_MPLS_BOS,
1052 mpls_key->mpls_bos);
1053 if (err)
1054 return err;
1055 }
1056 return 0;
1057}
1058
Or Gerlitz4d80cc02017-06-01 21:37:38 +03001059static int fl_dump_key_ip(struct sk_buff *skb,
1060 struct flow_dissector_key_ip *key,
1061 struct flow_dissector_key_ip *mask)
1062{
1063 if (fl_dump_key_val(skb, &key->tos, TCA_FLOWER_KEY_IP_TOS, &mask->tos,
1064 TCA_FLOWER_KEY_IP_TOS_MASK, sizeof(key->tos)) ||
1065 fl_dump_key_val(skb, &key->ttl, TCA_FLOWER_KEY_IP_TTL, &mask->ttl,
1066 TCA_FLOWER_KEY_IP_TTL_MASK, sizeof(key->ttl)))
1067 return -1;
1068
1069 return 0;
1070}
1071
Hadar Hen Zion9399ae92016-08-17 13:36:13 +03001072static int fl_dump_key_vlan(struct sk_buff *skb,
1073 struct flow_dissector_key_vlan *vlan_key,
1074 struct flow_dissector_key_vlan *vlan_mask)
1075{
1076 int err;
1077
1078 if (!memchr_inv(vlan_mask, 0, sizeof(*vlan_mask)))
1079 return 0;
1080 if (vlan_mask->vlan_id) {
1081 err = nla_put_u16(skb, TCA_FLOWER_KEY_VLAN_ID,
1082 vlan_key->vlan_id);
1083 if (err)
1084 return err;
1085 }
1086 if (vlan_mask->vlan_priority) {
1087 err = nla_put_u8(skb, TCA_FLOWER_KEY_VLAN_PRIO,
1088 vlan_key->vlan_priority);
1089 if (err)
1090 return err;
1091 }
1092 return 0;
1093}
1094
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +02001095static void fl_get_key_flag(u32 dissector_key, u32 dissector_mask,
1096 u32 *flower_key, u32 *flower_mask,
1097 u32 flower_flag_bit, u32 dissector_flag_bit)
1098{
1099 if (dissector_mask & dissector_flag_bit) {
1100 *flower_mask |= flower_flag_bit;
1101 if (dissector_key & dissector_flag_bit)
1102 *flower_key |= flower_flag_bit;
1103 }
1104}
1105
1106static int fl_dump_key_flags(struct sk_buff *skb, u32 flags_key, u32 flags_mask)
1107{
1108 u32 key, mask;
1109 __be32 _key, _mask;
1110 int err;
1111
1112 if (!memchr_inv(&flags_mask, 0, sizeof(flags_mask)))
1113 return 0;
1114
1115 key = 0;
1116 mask = 0;
1117
1118 fl_get_key_flag(flags_key, flags_mask, &key, &mask,
1119 TCA_FLOWER_KEY_FLAGS_IS_FRAGMENT, FLOW_DIS_IS_FRAGMENT);
1120
1121 _key = cpu_to_be32(key);
1122 _mask = cpu_to_be32(mask);
1123
1124 err = nla_put(skb, TCA_FLOWER_KEY_FLAGS, 4, &_key);
1125 if (err)
1126 return err;
1127
1128 return nla_put(skb, TCA_FLOWER_KEY_FLAGS_MASK, 4, &_mask);
1129}
1130
WANG Cong8113c092017-08-04 21:31:43 -07001131static int fl_dump(struct net *net, struct tcf_proto *tp, void *fh,
Jiri Pirko77b99002015-05-12 14:56:21 +02001132 struct sk_buff *skb, struct tcmsg *t)
1133{
1134 struct cls_fl_head *head = rtnl_dereference(tp->root);
WANG Cong8113c092017-08-04 21:31:43 -07001135 struct cls_fl_filter *f = fh;
Jiri Pirko77b99002015-05-12 14:56:21 +02001136 struct nlattr *nest;
1137 struct fl_flow_key *key, *mask;
1138
1139 if (!f)
1140 return skb->len;
1141
1142 t->tcm_handle = f->handle;
1143
1144 nest = nla_nest_start(skb, TCA_OPTIONS);
1145 if (!nest)
1146 goto nla_put_failure;
1147
1148 if (f->res.classid &&
1149 nla_put_u32(skb, TCA_FLOWER_CLASSID, f->res.classid))
1150 goto nla_put_failure;
1151
1152 key = &f->key;
1153 mask = &head->mask.key;
1154
1155 if (mask->indev_ifindex) {
1156 struct net_device *dev;
1157
1158 dev = __dev_get_by_index(net, key->indev_ifindex);
1159 if (dev && nla_put_string(skb, TCA_FLOWER_INDEV, dev->name))
1160 goto nla_put_failure;
1161 }
1162
Hadar Hen Zion79685212016-12-01 14:06:34 +02001163 if (!tc_skip_hw(f->flags))
1164 fl_hw_update_stats(tp, f);
Amir Vadai10cbc682016-05-13 12:55:37 +00001165
Jiri Pirko77b99002015-05-12 14:56:21 +02001166 if (fl_dump_key_val(skb, key->eth.dst, TCA_FLOWER_KEY_ETH_DST,
1167 mask->eth.dst, TCA_FLOWER_KEY_ETH_DST_MASK,
1168 sizeof(key->eth.dst)) ||
1169 fl_dump_key_val(skb, key->eth.src, TCA_FLOWER_KEY_ETH_SRC,
1170 mask->eth.src, TCA_FLOWER_KEY_ETH_SRC_MASK,
1171 sizeof(key->eth.src)) ||
1172 fl_dump_key_val(skb, &key->basic.n_proto, TCA_FLOWER_KEY_ETH_TYPE,
1173 &mask->basic.n_proto, TCA_FLOWER_UNSPEC,
1174 sizeof(key->basic.n_proto)))
1175 goto nla_put_failure;
Hadar Hen Zion9399ae92016-08-17 13:36:13 +03001176
Benjamin LaHaisea577d8f2017-04-22 16:52:47 -04001177 if (fl_dump_key_mpls(skb, &key->mpls, &mask->mpls))
1178 goto nla_put_failure;
1179
Hadar Hen Zion9399ae92016-08-17 13:36:13 +03001180 if (fl_dump_key_vlan(skb, &key->vlan, &mask->vlan))
1181 goto nla_put_failure;
1182
Jiri Pirko77b99002015-05-12 14:56:21 +02001183 if ((key->basic.n_proto == htons(ETH_P_IP) ||
1184 key->basic.n_proto == htons(ETH_P_IPV6)) &&
Or Gerlitz4d80cc02017-06-01 21:37:38 +03001185 (fl_dump_key_val(skb, &key->basic.ip_proto, TCA_FLOWER_KEY_IP_PROTO,
Jiri Pirko77b99002015-05-12 14:56:21 +02001186 &mask->basic.ip_proto, TCA_FLOWER_UNSPEC,
Or Gerlitz4d80cc02017-06-01 21:37:38 +03001187 sizeof(key->basic.ip_proto)) ||
1188 fl_dump_key_ip(skb, &key->ip, &mask->ip)))
Jiri Pirko77b99002015-05-12 14:56:21 +02001189 goto nla_put_failure;
1190
Tom Herbertc3f83242015-06-04 09:16:40 -07001191 if (key->control.addr_type == FLOW_DISSECTOR_KEY_IPV4_ADDRS &&
Jiri Pirko77b99002015-05-12 14:56:21 +02001192 (fl_dump_key_val(skb, &key->ipv4.src, TCA_FLOWER_KEY_IPV4_SRC,
1193 &mask->ipv4.src, TCA_FLOWER_KEY_IPV4_SRC_MASK,
1194 sizeof(key->ipv4.src)) ||
1195 fl_dump_key_val(skb, &key->ipv4.dst, TCA_FLOWER_KEY_IPV4_DST,
1196 &mask->ipv4.dst, TCA_FLOWER_KEY_IPV4_DST_MASK,
1197 sizeof(key->ipv4.dst))))
1198 goto nla_put_failure;
Tom Herbertc3f83242015-06-04 09:16:40 -07001199 else if (key->control.addr_type == FLOW_DISSECTOR_KEY_IPV6_ADDRS &&
Jiri Pirko77b99002015-05-12 14:56:21 +02001200 (fl_dump_key_val(skb, &key->ipv6.src, TCA_FLOWER_KEY_IPV6_SRC,
1201 &mask->ipv6.src, TCA_FLOWER_KEY_IPV6_SRC_MASK,
1202 sizeof(key->ipv6.src)) ||
1203 fl_dump_key_val(skb, &key->ipv6.dst, TCA_FLOWER_KEY_IPV6_DST,
1204 &mask->ipv6.dst, TCA_FLOWER_KEY_IPV6_DST_MASK,
1205 sizeof(key->ipv6.dst))))
1206 goto nla_put_failure;
1207
1208 if (key->basic.ip_proto == IPPROTO_TCP &&
1209 (fl_dump_key_val(skb, &key->tp.src, TCA_FLOWER_KEY_TCP_SRC,
Or Gerlitzaa72d702016-09-15 15:28:22 +03001210 &mask->tp.src, TCA_FLOWER_KEY_TCP_SRC_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +02001211 sizeof(key->tp.src)) ||
1212 fl_dump_key_val(skb, &key->tp.dst, TCA_FLOWER_KEY_TCP_DST,
Or Gerlitzaa72d702016-09-15 15:28:22 +03001213 &mask->tp.dst, TCA_FLOWER_KEY_TCP_DST_MASK,
Jiri Pirkofdfc7dd2017-05-23 18:40:45 +02001214 sizeof(key->tp.dst)) ||
1215 fl_dump_key_val(skb, &key->tcp.flags, TCA_FLOWER_KEY_TCP_FLAGS,
1216 &mask->tcp.flags, TCA_FLOWER_KEY_TCP_FLAGS_MASK,
1217 sizeof(key->tcp.flags))))
Jiri Pirko77b99002015-05-12 14:56:21 +02001218 goto nla_put_failure;
1219 else if (key->basic.ip_proto == IPPROTO_UDP &&
1220 (fl_dump_key_val(skb, &key->tp.src, TCA_FLOWER_KEY_UDP_SRC,
Or Gerlitzaa72d702016-09-15 15:28:22 +03001221 &mask->tp.src, TCA_FLOWER_KEY_UDP_SRC_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +02001222 sizeof(key->tp.src)) ||
1223 fl_dump_key_val(skb, &key->tp.dst, TCA_FLOWER_KEY_UDP_DST,
Or Gerlitzaa72d702016-09-15 15:28:22 +03001224 &mask->tp.dst, TCA_FLOWER_KEY_UDP_DST_MASK,
Jiri Pirko77b99002015-05-12 14:56:21 +02001225 sizeof(key->tp.dst))))
1226 goto nla_put_failure;
Simon Horman5976c5f2016-11-03 13:24:21 +01001227 else if (key->basic.ip_proto == IPPROTO_SCTP &&
1228 (fl_dump_key_val(skb, &key->tp.src, TCA_FLOWER_KEY_SCTP_SRC,
1229 &mask->tp.src, TCA_FLOWER_KEY_SCTP_SRC_MASK,
1230 sizeof(key->tp.src)) ||
1231 fl_dump_key_val(skb, &key->tp.dst, TCA_FLOWER_KEY_SCTP_DST,
1232 &mask->tp.dst, TCA_FLOWER_KEY_SCTP_DST_MASK,
1233 sizeof(key->tp.dst))))
1234 goto nla_put_failure;
Simon Horman7b684882016-12-07 13:48:28 +01001235 else if (key->basic.n_proto == htons(ETH_P_IP) &&
1236 key->basic.ip_proto == IPPROTO_ICMP &&
1237 (fl_dump_key_val(skb, &key->icmp.type,
1238 TCA_FLOWER_KEY_ICMPV4_TYPE, &mask->icmp.type,
1239 TCA_FLOWER_KEY_ICMPV4_TYPE_MASK,
1240 sizeof(key->icmp.type)) ||
1241 fl_dump_key_val(skb, &key->icmp.code,
1242 TCA_FLOWER_KEY_ICMPV4_CODE, &mask->icmp.code,
1243 TCA_FLOWER_KEY_ICMPV4_CODE_MASK,
1244 sizeof(key->icmp.code))))
1245 goto nla_put_failure;
1246 else if (key->basic.n_proto == htons(ETH_P_IPV6) &&
1247 key->basic.ip_proto == IPPROTO_ICMPV6 &&
1248 (fl_dump_key_val(skb, &key->icmp.type,
1249 TCA_FLOWER_KEY_ICMPV6_TYPE, &mask->icmp.type,
1250 TCA_FLOWER_KEY_ICMPV6_TYPE_MASK,
1251 sizeof(key->icmp.type)) ||
1252 fl_dump_key_val(skb, &key->icmp.code,
1253 TCA_FLOWER_KEY_ICMPV6_CODE, &mask->icmp.code,
1254 TCA_FLOWER_KEY_ICMPV6_CODE_MASK,
1255 sizeof(key->icmp.code))))
1256 goto nla_put_failure;
Simon Horman99d31322017-01-11 14:05:43 +01001257 else if ((key->basic.n_proto == htons(ETH_P_ARP) ||
1258 key->basic.n_proto == htons(ETH_P_RARP)) &&
1259 (fl_dump_key_val(skb, &key->arp.sip,
1260 TCA_FLOWER_KEY_ARP_SIP, &mask->arp.sip,
1261 TCA_FLOWER_KEY_ARP_SIP_MASK,
1262 sizeof(key->arp.sip)) ||
1263 fl_dump_key_val(skb, &key->arp.tip,
1264 TCA_FLOWER_KEY_ARP_TIP, &mask->arp.tip,
1265 TCA_FLOWER_KEY_ARP_TIP_MASK,
1266 sizeof(key->arp.tip)) ||
1267 fl_dump_key_val(skb, &key->arp.op,
1268 TCA_FLOWER_KEY_ARP_OP, &mask->arp.op,
1269 TCA_FLOWER_KEY_ARP_OP_MASK,
1270 sizeof(key->arp.op)) ||
1271 fl_dump_key_val(skb, key->arp.sha, TCA_FLOWER_KEY_ARP_SHA,
1272 mask->arp.sha, TCA_FLOWER_KEY_ARP_SHA_MASK,
1273 sizeof(key->arp.sha)) ||
1274 fl_dump_key_val(skb, key->arp.tha, TCA_FLOWER_KEY_ARP_THA,
1275 mask->arp.tha, TCA_FLOWER_KEY_ARP_THA_MASK,
1276 sizeof(key->arp.tha))))
1277 goto nla_put_failure;
Jiri Pirko77b99002015-05-12 14:56:21 +02001278
Amir Vadaibc3103f2016-09-08 16:23:47 +03001279 if (key->enc_control.addr_type == FLOW_DISSECTOR_KEY_IPV4_ADDRS &&
1280 (fl_dump_key_val(skb, &key->enc_ipv4.src,
1281 TCA_FLOWER_KEY_ENC_IPV4_SRC, &mask->enc_ipv4.src,
1282 TCA_FLOWER_KEY_ENC_IPV4_SRC_MASK,
1283 sizeof(key->enc_ipv4.src)) ||
1284 fl_dump_key_val(skb, &key->enc_ipv4.dst,
1285 TCA_FLOWER_KEY_ENC_IPV4_DST, &mask->enc_ipv4.dst,
1286 TCA_FLOWER_KEY_ENC_IPV4_DST_MASK,
1287 sizeof(key->enc_ipv4.dst))))
1288 goto nla_put_failure;
1289 else if (key->enc_control.addr_type == FLOW_DISSECTOR_KEY_IPV6_ADDRS &&
1290 (fl_dump_key_val(skb, &key->enc_ipv6.src,
1291 TCA_FLOWER_KEY_ENC_IPV6_SRC, &mask->enc_ipv6.src,
1292 TCA_FLOWER_KEY_ENC_IPV6_SRC_MASK,
1293 sizeof(key->enc_ipv6.src)) ||
1294 fl_dump_key_val(skb, &key->enc_ipv6.dst,
1295 TCA_FLOWER_KEY_ENC_IPV6_DST,
1296 &mask->enc_ipv6.dst,
1297 TCA_FLOWER_KEY_ENC_IPV6_DST_MASK,
1298 sizeof(key->enc_ipv6.dst))))
1299 goto nla_put_failure;
1300
1301 if (fl_dump_key_val(skb, &key->enc_key_id, TCA_FLOWER_KEY_ENC_KEY_ID,
Hadar Hen Zioneb523f42016-09-27 11:21:18 +03001302 &mask->enc_key_id, TCA_FLOWER_UNSPEC,
Hadar Hen Zionf4d997f2016-11-07 15:14:39 +02001303 sizeof(key->enc_key_id)) ||
1304 fl_dump_key_val(skb, &key->enc_tp.src,
1305 TCA_FLOWER_KEY_ENC_UDP_SRC_PORT,
1306 &mask->enc_tp.src,
1307 TCA_FLOWER_KEY_ENC_UDP_SRC_PORT_MASK,
1308 sizeof(key->enc_tp.src)) ||
1309 fl_dump_key_val(skb, &key->enc_tp.dst,
1310 TCA_FLOWER_KEY_ENC_UDP_DST_PORT,
1311 &mask->enc_tp.dst,
1312 TCA_FLOWER_KEY_ENC_UDP_DST_PORT_MASK,
1313 sizeof(key->enc_tp.dst)))
Amir Vadaibc3103f2016-09-08 16:23:47 +03001314 goto nla_put_failure;
1315
Or Gerlitzfaa3ffc2016-12-07 14:03:10 +02001316 if (fl_dump_key_flags(skb, key->control.flags, mask->control.flags))
1317 goto nla_put_failure;
1318
Or Gerlitz749e6722017-02-16 10:31:10 +02001319 if (f->flags && nla_put_u32(skb, TCA_FLOWER_FLAGS, f->flags))
1320 goto nla_put_failure;
Amir Vadaie69985c2016-06-05 17:11:18 +03001321
Jiri Pirko77b99002015-05-12 14:56:21 +02001322 if (tcf_exts_dump(skb, &f->exts))
1323 goto nla_put_failure;
1324
1325 nla_nest_end(skb, nest);
1326
1327 if (tcf_exts_dump_stats(skb, &f->exts) < 0)
1328 goto nla_put_failure;
1329
1330 return skb->len;
1331
1332nla_put_failure:
1333 nla_nest_cancel(skb, nest);
1334 return -1;
1335}
1336
Cong Wang07d79fc2017-08-30 14:30:36 -07001337static void fl_bind_class(void *fh, u32 classid, unsigned long cl)
1338{
1339 struct cls_fl_filter *f = fh;
1340
1341 if (f && f->res.classid == classid)
1342 f->res.class = cl;
1343}
1344
Jiri Pirko77b99002015-05-12 14:56:21 +02001345static struct tcf_proto_ops cls_fl_ops __read_mostly = {
1346 .kind = "flower",
1347 .classify = fl_classify,
1348 .init = fl_init,
1349 .destroy = fl_destroy,
1350 .get = fl_get,
1351 .change = fl_change,
1352 .delete = fl_delete,
1353 .walk = fl_walk,
1354 .dump = fl_dump,
Cong Wang07d79fc2017-08-30 14:30:36 -07001355 .bind_class = fl_bind_class,
Jiri Pirko77b99002015-05-12 14:56:21 +02001356 .owner = THIS_MODULE,
1357};
1358
1359static int __init cls_fl_init(void)
1360{
1361 return register_tcf_proto_ops(&cls_fl_ops);
1362}
1363
1364static void __exit cls_fl_exit(void)
1365{
1366 unregister_tcf_proto_ops(&cls_fl_ops);
1367}
1368
1369module_init(cls_fl_init);
1370module_exit(cls_fl_exit);
1371
1372MODULE_AUTHOR("Jiri Pirko <jiri@resnulli.us>");
1373MODULE_DESCRIPTION("Flower classifier");
1374MODULE_LICENSE("GPL v2");