]> git.proxmox.com Git - mirror_ubuntu-bionic-kernel.git/blame - include/net/flow_dissector.h
netfilter: add missing error handling code for register functions
[mirror_ubuntu-bionic-kernel.git] / include / net / flow_dissector.h
CommitLineData
b2441318 1/* SPDX-License-Identifier: GPL-2.0 */
1bd758eb
JP
2#ifndef _NET_FLOW_DISSECTOR_H
3#define _NET_FLOW_DISSECTOR_H
0744dd00 4
c3f8eaeb 5#include <linux/types.h>
b924933c 6#include <linux/in6.h>
67a900cc 7#include <uapi/linux/if_ether.h>
c3f8eaeb 8
42aecaa9
TH
9/**
10 * struct flow_dissector_key_control:
11 * @thoff: Transport header offset
12 */
13struct flow_dissector_key_control {
14 u16 thoff;
c3f83241 15 u16 addr_type;
4b36993d 16 u32 flags;
42aecaa9
TH
17};
18
4b36993d
DM
19#define FLOW_DIS_IS_FRAGMENT BIT(0)
20#define FLOW_DIS_FIRST_FRAG BIT(1)
21#define FLOW_DIS_ENCAPSULATION BIT(2)
22
3a1214e8
TH
23enum flow_dissect_ret {
24 FLOW_DISSECT_RET_OUT_GOOD,
25 FLOW_DISSECT_RET_OUT_BAD,
26 FLOW_DISSECT_RET_PROTO_AGAIN,
27 FLOW_DISSECT_RET_IPPROTO_AGAIN,
28 FLOW_DISSECT_RET_CONTINUE,
29};
30
fbff949e
JP
31/**
32 * struct flow_dissector_key_basic:
33 * @thoff: Transport header offset
34 * @n_proto: Network header protocol (eg. IPv4/IPv6)
35 * @ip_proto: Transport header protocol (eg. TCP/UDP)
36 */
37struct flow_dissector_key_basic {
fbff949e
JP
38 __be16 n_proto;
39 u8 ip_proto;
42aecaa9 40 u8 padding;
fbff949e
JP
41};
42
d34af823 43struct flow_dissector_key_tags {
f6a66927
HHZ
44 u32 flow_label;
45};
46
47struct flow_dissector_key_vlan {
48 u16 vlan_id:12,
49 vlan_priority:3;
50 u16 padding;
d34af823
TH
51};
52
029c1ecb
BL
53struct flow_dissector_key_mpls {
54 u32 mpls_ttl:8,
55 mpls_bos:1,
56 mpls_tc:3,
57 mpls_label:20;
58};
59
1fdd512c
TH
60struct flow_dissector_key_keyid {
61 __be32 keyid;
62};
63
fbff949e 64/**
c3f83241
TH
65 * struct flow_dissector_key_ipv4_addrs:
66 * @src: source ip address
67 * @dst: destination ip address
fbff949e 68 */
c3f83241 69struct flow_dissector_key_ipv4_addrs {
fbff949e
JP
70 /* (src,dst) must be grouped, in the same way than in IP header */
71 __be32 src;
72 __be32 dst;
73};
74
c3f83241
TH
75/**
76 * struct flow_dissector_key_ipv6_addrs:
77 * @src: source ip address
78 * @dst: destination ip address
79 */
80struct flow_dissector_key_ipv6_addrs {
81 /* (src,dst) must be grouped, in the same way than in IP header */
82 struct in6_addr src;
83 struct in6_addr dst;
84};
85
9f249089 86/**
8d6e79d3
JM
87 * struct flow_dissector_key_tipc:
88 * @key: source node address combined with selector
9f249089 89 */
8d6e79d3
JM
90struct flow_dissector_key_tipc {
91 __be32 key;
9f249089
TH
92};
93
c3f83241
TH
94/**
95 * struct flow_dissector_key_addrs:
96 * @v4addrs: IPv4 addresses
97 * @v6addrs: IPv6 addresses
98 */
99struct flow_dissector_key_addrs {
100 union {
101 struct flow_dissector_key_ipv4_addrs v4addrs;
102 struct flow_dissector_key_ipv6_addrs v6addrs;
8d6e79d3 103 struct flow_dissector_key_tipc tipckey;
c3f83241
TH
104 };
105};
106
55733350
SH
107/**
108 * flow_dissector_key_arp:
109 * @ports: Operation, source and target addresses for an ARP header
110 * for Ethernet hardware addresses and IPv4 protocol addresses
111 * sip: Sender IP address
112 * tip: Target IP address
113 * op: Operation
114 * sha: Sender hardware address
115 * tpa: Target hardware address
116 */
117struct flow_dissector_key_arp {
118 __u32 sip;
119 __u32 tip;
120 __u8 op;
121 unsigned char sha[ETH_ALEN];
122 unsigned char tha[ETH_ALEN];
123};
124
fbff949e
JP
125/**
126 * flow_dissector_key_tp_ports:
127 * @ports: port numbers of Transport header
59346afe
JP
128 * src: source port number
129 * dst: destination port number
fbff949e
JP
130 */
131struct flow_dissector_key_ports {
132 union {
133 __be32 ports;
59346afe
JP
134 struct {
135 __be16 src;
136 __be16 dst;
137 };
fbff949e
JP
138 };
139};
140
972d3876
SH
141/**
142 * flow_dissector_key_icmp:
143 * @ports: type and code of ICMP header
144 * icmp: ICMP type (high) and code (low)
145 * type: ICMP type
146 * code: ICMP code
147 */
148struct flow_dissector_key_icmp {
149 union {
150 __be16 icmp;
151 struct {
152 u8 type;
153 u8 code;
154 };
155 };
156};
b924933c 157
67a900cc
JP
158/**
159 * struct flow_dissector_key_eth_addrs:
160 * @src: source Ethernet address
161 * @dst: destination Ethernet address
162 */
163struct flow_dissector_key_eth_addrs {
164 /* (dst,src) must be grouped, in the same way than in ETH header */
165 unsigned char dst[ETH_ALEN];
166 unsigned char src[ETH_ALEN];
167};
168
ac4bb5de
JP
169/**
170 * struct flow_dissector_key_tcp:
171 * @flags: flags
172 */
173struct flow_dissector_key_tcp {
174 __be16 flags;
175};
176
518d8a2e
OG
177/**
178 * struct flow_dissector_key_ip:
179 * @tos: tos
180 * @ttl: ttl
181 */
182struct flow_dissector_key_ip {
183 __u8 tos;
184 __u8 ttl;
185};
186
fbff949e 187enum flow_dissector_key_id {
42aecaa9 188 FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */
fbff949e 189 FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */
c3f83241
TH
190 FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
191 FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
fbff949e 192 FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */
972d3876 193 FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */
67a900cc 194 FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */
8d6e79d3 195 FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */
55733350 196 FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */
f6a66927 197 FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_flow_vlan */
87ee9e52 198 FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_flow_tags */
1fdd512c 199 FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */
b3baa0fb 200 FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */
9ba6a9a9
HHZ
201 FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */
202 FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
203 FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
204 FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */
f4d997fd 205 FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */
029c1ecb 206 FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */
ac4bb5de 207 FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */
518d8a2e 208 FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */
fbff949e
JP
209
210 FLOW_DISSECTOR_KEY_MAX,
211};
212
807e165d 213#define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0)
8306b688 214#define FLOW_DISSECTOR_F_STOP_AT_L3 BIT(1)
872b1abb 215#define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(2)
823b9693 216#define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(3)
807e165d 217
fbff949e
JP
218struct flow_dissector_key {
219 enum flow_dissector_key_id key_id;
220 size_t offset; /* offset of struct flow_dissector_key_*
221 in target the struct */
222};
223
224struct flow_dissector {
225 unsigned int used_keys; /* each bit repesents presence of one key id */
226 unsigned short int offset[FLOW_DISSECTOR_KEY_MAX];
227};
228
06635a35 229struct flow_keys {
42aecaa9
TH
230 struct flow_dissector_key_control control;
231#define FLOW_KEYS_HASH_START_FIELD basic
06635a35 232 struct flow_dissector_key_basic basic;
d34af823 233 struct flow_dissector_key_tags tags;
f6a66927 234 struct flow_dissector_key_vlan vlan;
1fdd512c 235 struct flow_dissector_key_keyid keyid;
42aecaa9
TH
236 struct flow_dissector_key_ports ports;
237 struct flow_dissector_key_addrs addrs;
06635a35
JP
238};
239
42aecaa9
TH
240#define FLOW_KEYS_HASH_OFFSET \
241 offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD)
242
c3f83241
TH
243__be32 flow_get_u32_src(const struct flow_keys *flow);
244__be32 flow_get_u32_dst(const struct flow_keys *flow);
245
06635a35
JP
246extern struct flow_dissector flow_keys_dissector;
247extern struct flow_dissector flow_keys_buf_dissector;
248
2f59e1eb
TH
249/* struct flow_keys_digest:
250 *
251 * This structure is used to hold a digest of the full flow keys. This is a
252 * larger "hash" of a flow to allow definitively matching specific flows where
253 * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so
254 * that it can by used in CB of skb (see sch_choke for an example).
255 */
256#define FLOW_KEYS_DIGEST_LEN 16
257struct flow_keys_digest {
258 u8 data[FLOW_KEYS_DIGEST_LEN];
259};
260
261void make_flow_keys_digest(struct flow_keys_digest *digest,
262 const struct flow_keys *flow);
263
66fdd05e 264static inline bool flow_keys_have_l4(const struct flow_keys *keys)
bcc83839
TH
265{
266 return (keys->ports.ports || keys->tags.flow_label);
267}
268
c6cc1ca7
TH
269u32 flow_hash_from_keys(struct flow_keys *keys);
270
8de2d793
AV
271static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector,
272 enum flow_dissector_key_id key_id)
273{
274 return flow_dissector->used_keys & (1 << key_id);
275}
276
277static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector,
278 enum flow_dissector_key_id key_id,
279 void *target_container)
280{
281 return ((char *)target_container) + flow_dissector->offset[key_id];
282}
283
0744dd00 284#endif