flow_dissector.h 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438
  1. /* SPDX-License-Identifier: GPL-2.0 */
  2. #ifndef _NET_FLOW_DISSECTOR_H
  3. #define _NET_FLOW_DISSECTOR_H
  4. #include <linux/types.h>
  5. #include <linux/in6.h>
  6. #include <linux/siphash.h>
  7. #include <linux/string.h>
  8. #include <uapi/linux/if_ether.h>
  9. struct bpf_prog;
  10. struct net;
  11. struct sk_buff;
  12. /**
  13. * struct flow_dissector_key_control:
  14. * @thoff: Transport header offset
  15. */
  16. struct flow_dissector_key_control {
  17. u16 thoff;
  18. u16 addr_type;
  19. u32 flags;
  20. };
  21. #define FLOW_DIS_IS_FRAGMENT BIT(0)
  22. #define FLOW_DIS_FIRST_FRAG BIT(1)
  23. #define FLOW_DIS_ENCAPSULATION BIT(2)
  24. enum flow_dissect_ret {
  25. FLOW_DISSECT_RET_OUT_GOOD,
  26. FLOW_DISSECT_RET_OUT_BAD,
  27. FLOW_DISSECT_RET_PROTO_AGAIN,
  28. FLOW_DISSECT_RET_IPPROTO_AGAIN,
  29. FLOW_DISSECT_RET_CONTINUE,
  30. };
  31. /**
  32. * struct flow_dissector_key_basic:
  33. * @n_proto: Network header protocol (eg. IPv4/IPv6)
  34. * @ip_proto: Transport header protocol (eg. TCP/UDP)
  35. */
  36. struct flow_dissector_key_basic {
  37. __be16 n_proto;
  38. u8 ip_proto;
  39. u8 padding;
  40. };
  41. struct flow_dissector_key_tags {
  42. u32 flow_label;
  43. };
  44. struct flow_dissector_key_vlan {
  45. union {
  46. struct {
  47. u16 vlan_id:12,
  48. vlan_dei:1,
  49. vlan_priority:3;
  50. };
  51. __be16 vlan_tci;
  52. };
  53. __be16 vlan_tpid;
  54. __be16 vlan_eth_type;
  55. u16 padding;
  56. };
  57. struct flow_dissector_mpls_lse {
  58. u32 mpls_ttl:8,
  59. mpls_bos:1,
  60. mpls_tc:3,
  61. mpls_label:20;
  62. };
  63. #define FLOW_DIS_MPLS_MAX 7
  64. struct flow_dissector_key_mpls {
  65. struct flow_dissector_mpls_lse ls[FLOW_DIS_MPLS_MAX]; /* Label Stack */
  66. u8 used_lses; /* One bit set for each Label Stack Entry in use */
  67. };
  68. static inline void dissector_set_mpls_lse(struct flow_dissector_key_mpls *mpls,
  69. int lse_index)
  70. {
  71. mpls->used_lses |= 1 << lse_index;
  72. }
  73. #define FLOW_DIS_TUN_OPTS_MAX 255
  74. /**
  75. * struct flow_dissector_key_enc_opts:
  76. * @data: tunnel option data
  77. * @len: length of tunnel option data
  78. * @dst_opt_type: tunnel option type
  79. */
  80. struct flow_dissector_key_enc_opts {
  81. u8 data[FLOW_DIS_TUN_OPTS_MAX]; /* Using IP_TUNNEL_OPTS_MAX is desired
  82. * here but seems difficult to #include
  83. */
  84. u8 len;
  85. __be16 dst_opt_type;
  86. };
  87. struct flow_dissector_key_keyid {
  88. __be32 keyid;
  89. };
  90. /**
  91. * struct flow_dissector_key_ipv4_addrs:
  92. * @src: source ip address
  93. * @dst: destination ip address
  94. */
  95. struct flow_dissector_key_ipv4_addrs {
  96. /* (src,dst) must be grouped, in the same way than in IP header */
  97. __be32 src;
  98. __be32 dst;
  99. };
  100. /**
  101. * struct flow_dissector_key_ipv6_addrs:
  102. * @src: source ip address
  103. * @dst: destination ip address
  104. */
  105. struct flow_dissector_key_ipv6_addrs {
  106. /* (src,dst) must be grouped, in the same way than in IP header */
  107. struct in6_addr src;
  108. struct in6_addr dst;
  109. };
  110. /**
  111. * struct flow_dissector_key_tipc:
  112. * @key: source node address combined with selector
  113. */
  114. struct flow_dissector_key_tipc {
  115. __be32 key;
  116. };
  117. /**
  118. * struct flow_dissector_key_addrs:
  119. * @v4addrs: IPv4 addresses
  120. * @v6addrs: IPv6 addresses
  121. */
  122. struct flow_dissector_key_addrs {
  123. union {
  124. struct flow_dissector_key_ipv4_addrs v4addrs;
  125. struct flow_dissector_key_ipv6_addrs v6addrs;
  126. struct flow_dissector_key_tipc tipckey;
  127. };
  128. };
  129. /**
  130. * flow_dissector_key_arp:
  131. * @ports: Operation, source and target addresses for an ARP header
  132. * for Ethernet hardware addresses and IPv4 protocol addresses
  133. * sip: Sender IP address
  134. * tip: Target IP address
  135. * op: Operation
  136. * sha: Sender hardware address
  137. * tpa: Target hardware address
  138. */
  139. struct flow_dissector_key_arp {
  140. __u32 sip;
  141. __u32 tip;
  142. __u8 op;
  143. unsigned char sha[ETH_ALEN];
  144. unsigned char tha[ETH_ALEN];
  145. };
  146. /**
  147. * flow_dissector_key_tp_ports:
  148. * @ports: port numbers of Transport header
  149. * src: source port number
  150. * dst: destination port number
  151. */
  152. struct flow_dissector_key_ports {
  153. union {
  154. __be32 ports;
  155. struct {
  156. __be16 src;
  157. __be16 dst;
  158. };
  159. };
  160. };
  161. /**
  162. * struct flow_dissector_key_ports_range
  163. * @tp: port number from packet
  164. * @tp_min: min port number in range
  165. * @tp_max: max port number in range
  166. */
  167. struct flow_dissector_key_ports_range {
  168. union {
  169. struct flow_dissector_key_ports tp;
  170. struct {
  171. struct flow_dissector_key_ports tp_min;
  172. struct flow_dissector_key_ports tp_max;
  173. };
  174. };
  175. };
  176. /**
  177. * flow_dissector_key_icmp:
  178. * type: ICMP type
  179. * code: ICMP code
  180. * id: session identifier
  181. */
  182. struct flow_dissector_key_icmp {
  183. struct {
  184. u8 type;
  185. u8 code;
  186. };
  187. u16 id;
  188. };
  189. /**
  190. * struct flow_dissector_key_eth_addrs:
  191. * @src: source Ethernet address
  192. * @dst: destination Ethernet address
  193. */
  194. struct flow_dissector_key_eth_addrs {
  195. /* (dst,src) must be grouped, in the same way than in ETH header */
  196. unsigned char dst[ETH_ALEN];
  197. unsigned char src[ETH_ALEN];
  198. };
  199. /**
  200. * struct flow_dissector_key_tcp:
  201. * @flags: flags
  202. */
  203. struct flow_dissector_key_tcp {
  204. __be16 flags;
  205. };
  206. /**
  207. * struct flow_dissector_key_ip:
  208. * @tos: tos
  209. * @ttl: ttl
  210. */
  211. struct flow_dissector_key_ip {
  212. __u8 tos;
  213. __u8 ttl;
  214. };
  215. /**
  216. * struct flow_dissector_key_meta:
  217. * @ingress_ifindex: ingress ifindex
  218. * @ingress_iftype: ingress interface type
  219. */
  220. struct flow_dissector_key_meta {
  221. int ingress_ifindex;
  222. u16 ingress_iftype;
  223. };
  224. /**
  225. * struct flow_dissector_key_ct:
  226. * @ct_state: conntrack state after converting with map
  227. * @ct_mark: conttrack mark
  228. * @ct_zone: conntrack zone
  229. * @ct_labels: conntrack labels
  230. */
  231. struct flow_dissector_key_ct {
  232. u16 ct_state;
  233. u16 ct_zone;
  234. u32 ct_mark;
  235. u32 ct_labels[4];
  236. };
  237. /**
  238. * struct flow_dissector_key_hash:
  239. * @hash: hash value
  240. */
  241. struct flow_dissector_key_hash {
  242. u32 hash;
  243. };
  244. /**
  245. * struct flow_dissector_key_num_of_vlans:
  246. * @num_of_vlans: num_of_vlans value
  247. */
  248. struct flow_dissector_key_num_of_vlans {
  249. u8 num_of_vlans;
  250. };
  251. /**
  252. * struct flow_dissector_key_pppoe:
  253. * @session_id: pppoe session id
  254. * @ppp_proto: ppp protocol
  255. * @type: pppoe eth type
  256. */
  257. struct flow_dissector_key_pppoe {
  258. __be16 session_id;
  259. __be16 ppp_proto;
  260. __be16 type;
  261. };
  262. /**
  263. * struct flow_dissector_key_l2tpv3:
  264. * @session_id: identifier for a l2tp session
  265. */
  266. struct flow_dissector_key_l2tpv3 {
  267. __be32 session_id;
  268. };
  269. enum flow_dissector_key_id {
  270. FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */
  271. FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */
  272. FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
  273. FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
  274. FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */
  275. FLOW_DISSECTOR_KEY_PORTS_RANGE, /* struct flow_dissector_key_ports */
  276. FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */
  277. FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */
  278. FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */
  279. FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */
  280. FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_vlan */
  281. FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_tags */
  282. FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */
  283. FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */
  284. FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */
  285. FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
  286. FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
  287. FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */
  288. FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */
  289. FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */
  290. FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */
  291. FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */
  292. FLOW_DISSECTOR_KEY_CVLAN, /* struct flow_dissector_key_vlan */
  293. FLOW_DISSECTOR_KEY_ENC_IP, /* struct flow_dissector_key_ip */
  294. FLOW_DISSECTOR_KEY_ENC_OPTS, /* struct flow_dissector_key_enc_opts */
  295. FLOW_DISSECTOR_KEY_META, /* struct flow_dissector_key_meta */
  296. FLOW_DISSECTOR_KEY_CT, /* struct flow_dissector_key_ct */
  297. FLOW_DISSECTOR_KEY_HASH, /* struct flow_dissector_key_hash */
  298. FLOW_DISSECTOR_KEY_NUM_OF_VLANS, /* struct flow_dissector_key_num_of_vlans */
  299. FLOW_DISSECTOR_KEY_PPPOE, /* struct flow_dissector_key_pppoe */
  300. FLOW_DISSECTOR_KEY_L2TPV3, /* struct flow_dissector_key_l2tpv3 */
  301. FLOW_DISSECTOR_KEY_MAX,
  302. };
  303. #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0)
  304. #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(1)
  305. #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(2)
  306. #define FLOW_DISSECTOR_F_STOP_BEFORE_ENCAP BIT(3)
  307. struct flow_dissector_key {
  308. enum flow_dissector_key_id key_id;
  309. size_t offset; /* offset of struct flow_dissector_key_*
  310. in target the struct */
  311. };
  312. struct flow_dissector {
  313. unsigned int used_keys; /* each bit repesents presence of one key id */
  314. unsigned short int offset[FLOW_DISSECTOR_KEY_MAX];
  315. };
  316. struct flow_keys_basic {
  317. struct flow_dissector_key_control control;
  318. struct flow_dissector_key_basic basic;
  319. };
  320. struct flow_keys {
  321. struct flow_dissector_key_control control;
  322. #define FLOW_KEYS_HASH_START_FIELD basic
  323. struct flow_dissector_key_basic basic __aligned(SIPHASH_ALIGNMENT);
  324. struct flow_dissector_key_tags tags;
  325. struct flow_dissector_key_vlan vlan;
  326. struct flow_dissector_key_vlan cvlan;
  327. struct flow_dissector_key_keyid keyid;
  328. struct flow_dissector_key_ports ports;
  329. struct flow_dissector_key_icmp icmp;
  330. /* 'addrs' must be the last member */
  331. struct flow_dissector_key_addrs addrs;
  332. };
  333. #define FLOW_KEYS_HASH_OFFSET \
  334. offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD)
  335. __be32 flow_get_u32_src(const struct flow_keys *flow);
  336. __be32 flow_get_u32_dst(const struct flow_keys *flow);
  337. extern struct flow_dissector flow_keys_dissector;
  338. extern struct flow_dissector flow_keys_basic_dissector;
  339. /* struct flow_keys_digest:
  340. *
  341. * This structure is used to hold a digest of the full flow keys. This is a
  342. * larger "hash" of a flow to allow definitively matching specific flows where
  343. * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so
  344. * that it can be used in CB of skb (see sch_choke for an example).
  345. */
  346. #define FLOW_KEYS_DIGEST_LEN 16
  347. struct flow_keys_digest {
  348. u8 data[FLOW_KEYS_DIGEST_LEN];
  349. };
  350. void make_flow_keys_digest(struct flow_keys_digest *digest,
  351. const struct flow_keys *flow);
  352. static inline bool flow_keys_have_l4(const struct flow_keys *keys)
  353. {
  354. return (keys->ports.ports || keys->tags.flow_label);
  355. }
  356. u32 flow_hash_from_keys(struct flow_keys *keys);
  357. void skb_flow_get_icmp_tci(const struct sk_buff *skb,
  358. struct flow_dissector_key_icmp *key_icmp,
  359. const void *data, int thoff, int hlen);
  360. static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector,
  361. enum flow_dissector_key_id key_id)
  362. {
  363. return flow_dissector->used_keys & (1 << key_id);
  364. }
  365. static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector,
  366. enum flow_dissector_key_id key_id,
  367. void *target_container)
  368. {
  369. return ((char *)target_container) + flow_dissector->offset[key_id];
  370. }
  371. struct bpf_flow_dissector {
  372. struct bpf_flow_keys *flow_keys;
  373. const struct sk_buff *skb;
  374. const void *data;
  375. const void *data_end;
  376. };
  377. static inline void
  378. flow_dissector_init_keys(struct flow_dissector_key_control *key_control,
  379. struct flow_dissector_key_basic *key_basic)
  380. {
  381. memset(key_control, 0, sizeof(*key_control));
  382. memset(key_basic, 0, sizeof(*key_basic));
  383. }
  384. #ifdef CONFIG_BPF_SYSCALL
  385. int flow_dissector_bpf_prog_attach_check(struct net *net,
  386. struct bpf_prog *prog);
  387. #endif /* CONFIG_BPF_SYSCALL */
  388. #endif