]> git.proxmox.com Git - mirror_ubuntu-jammy-kernel.git/blame - include/uapi/linux/pkt_cls.h
net: only check perm protocol when register proto
[mirror_ubuntu-jammy-kernel.git] / include / uapi / linux / pkt_cls.h
CommitLineData
1da177e4
LT
1#ifndef __LINUX_PKT_CLS_H
2#define __LINUX_PKT_CLS_H
3
ed307444 4#include <linux/types.h>
1da177e4
LT
5#include <linux/pkt_sched.h>
6
bd5850d3 7#ifdef __KERNEL__
1da177e4
LT
8/* I think i could have done better macros ; for now this is stolen from
9 * some arch/mips code - jhs
10*/
11#define _TC_MAKE32(x) ((x))
12
13#define _TC_MAKEMASK1(n) (_TC_MAKE32(1) << _TC_MAKE32(n))
14#define _TC_MAKEMASK(v,n) (_TC_MAKE32((_TC_MAKE32(1)<<(v))-1) << _TC_MAKE32(n))
15#define _TC_MAKEVALUE(v,n) (_TC_MAKE32(v) << _TC_MAKE32(n))
16#define _TC_GETVALUE(v,n,m) ((_TC_MAKE32(v) & _TC_MAKE32(m)) >> _TC_MAKE32(n))
17
18/* verdict bit breakdown
19 *
20bit 0: when set -> this packet has been munged already
21
22bit 1: when set -> It is ok to munge this packet
23
24bit 2,3,4,5: Reclassify counter - sort of reverse TTL - if exceeded
25assume loop
26
27bit 6,7: Where this packet was last seen
280: Above the transmit example at the socket level
291: on the Ingress
302: on the Egress
31
32bit 8: when set --> Request not to classify on ingress.
33
34bits 9,10,11: redirect counter - redirect TTL. Loop avoidance
35
36 *
37 * */
38
1da177e4
LT
39#define S_TC_FROM _TC_MAKE32(6)
40#define M_TC_FROM _TC_MAKEMASK(2,S_TC_FROM)
41#define G_TC_FROM(x) _TC_GETVALUE(x,S_TC_FROM,M_TC_FROM)
42#define V_TC_FROM(x) _TC_MAKEVALUE(x,S_TC_FROM)
43#define SET_TC_FROM(v,n) ((V_TC_FROM(n)) | (v & ~M_TC_FROM))
44#define AT_STACK 0x0
45#define AT_INGRESS 0x1
46#define AT_EGRESS 0x2
47
48#define TC_NCLS _TC_MAKEMASK1(8)
49#define SET_TC_NCLS(v) ( TC_NCLS | (v & ~TC_NCLS))
50#define CLR_TC_NCLS(v) ( v & ~TC_NCLS)
51
1da177e4
LT
52#define S_TC_AT _TC_MAKE32(12)
53#define M_TC_AT _TC_MAKEMASK(2,S_TC_AT)
54#define G_TC_AT(x) _TC_GETVALUE(x,S_TC_AT,M_TC_AT)
55#define V_TC_AT(x) _TC_MAKEVALUE(x,S_TC_AT)
56#define SET_TC_AT(v,n) ((V_TC_AT(n)) | (v & ~M_TC_AT))
57
bd5850d3
FW
58#define MAX_REC_LOOP 4
59#define MAX_RED_LOOP 4
60#endif
61
1da177e4 62/* Action attributes */
d94d9fee 63enum {
1da177e4
LT
64 TCA_ACT_UNSPEC,
65 TCA_ACT_KIND,
66 TCA_ACT_OPTIONS,
67 TCA_ACT_INDEX,
68 TCA_ACT_STATS,
69 __TCA_ACT_MAX
70};
71
72#define TCA_ACT_MAX __TCA_ACT_MAX
73#define TCA_OLD_COMPAT (TCA_ACT_MAX+1)
74#define TCA_ACT_MAX_PRIO 32
75#define TCA_ACT_BIND 1
76#define TCA_ACT_NOBIND 0
77#define TCA_ACT_UNBIND 1
78#define TCA_ACT_NOUNBIND 0
79#define TCA_ACT_REPLACE 1
80#define TCA_ACT_NOREPLACE 0
1da177e4
LT
81
82#define TC_ACT_UNSPEC (-1)
83#define TC_ACT_OK 0
84#define TC_ACT_RECLASSIFY 1
85#define TC_ACT_SHOT 2
86#define TC_ACT_PIPE 3
87#define TC_ACT_STOLEN 4
88#define TC_ACT_QUEUED 5
89#define TC_ACT_REPEAT 6
90#define TC_ACT_JUMP 0x10000000
91
92/* Action type identifiers*/
d94d9fee 93enum {
1da177e4
LT
94 TCA_ID_UNSPEC=0,
95 TCA_ID_POLICE=1,
96 /* other actions go here */
97 __TCA_ID_MAX=255
98};
99
100#define TCA_ID_MAX __TCA_ID_MAX
101
d94d9fee 102struct tc_police {
1da177e4
LT
103 __u32 index;
104 int action;
105#define TC_POLICE_UNSPEC TC_ACT_UNSPEC
106#define TC_POLICE_OK TC_ACT_OK
107#define TC_POLICE_RECLASSIFY TC_ACT_RECLASSIFY
108#define TC_POLICE_SHOT TC_ACT_SHOT
109#define TC_POLICE_PIPE TC_ACT_PIPE
110
111 __u32 limit;
112 __u32 burst;
113 __u32 mtu;
114 struct tc_ratespec rate;
115 struct tc_ratespec peakrate;
116 int refcnt;
117 int bindcnt;
118 __u32 capab;
119};
120
d94d9fee 121struct tcf_t {
1da177e4
LT
122 __u64 install;
123 __u64 lastuse;
124 __u64 expires;
125};
126
d94d9fee 127struct tc_cnt {
1da177e4
LT
128 int refcnt;
129 int bindcnt;
130};
131
132#define tc_gen \
133 __u32 index; \
134 __u32 capab; \
135 int action; \
136 int refcnt; \
137 int bindcnt
138
d94d9fee 139enum {
1da177e4
LT
140 TCA_POLICE_UNSPEC,
141 TCA_POLICE_TBF,
142 TCA_POLICE_RATE,
143 TCA_POLICE_PEAKRATE,
144 TCA_POLICE_AVRATE,
145 TCA_POLICE_RESULT,
146 __TCA_POLICE_MAX
147#define TCA_POLICE_RESULT TCA_POLICE_RESULT
148};
149
150#define TCA_POLICE_MAX (__TCA_POLICE_MAX - 1)
151
152/* U32 filters */
153
154#define TC_U32_HTID(h) ((h)&0xFFF00000)
155#define TC_U32_USERHTID(h) (TC_U32_HTID(h)>>20)
156#define TC_U32_HASH(h) (((h)>>12)&0xFF)
157#define TC_U32_NODE(h) ((h)&0xFFF)
158#define TC_U32_KEY(h) ((h)&0xFFFFF)
159#define TC_U32_UNSPEC 0
160#define TC_U32_ROOT (0xFFF00000)
161
d94d9fee 162enum {
1da177e4
LT
163 TCA_U32_UNSPEC,
164 TCA_U32_CLASSID,
165 TCA_U32_HASH,
166 TCA_U32_LINK,
167 TCA_U32_DIVISOR,
168 TCA_U32_SEL,
169 TCA_U32_POLICE,
170 TCA_U32_ACT,
171 TCA_U32_INDEV,
172 TCA_U32_PCNT,
173 TCA_U32_MARK,
174 __TCA_U32_MAX
175};
176
177#define TCA_U32_MAX (__TCA_U32_MAX - 1)
178
d94d9fee 179struct tc_u32_key {
0382b9c3
AV
180 __be32 mask;
181 __be32 val;
1da177e4
LT
182 int off;
183 int offmask;
184};
185
d94d9fee 186struct tc_u32_sel {
1da177e4
LT
187 unsigned char flags;
188 unsigned char offshift;
189 unsigned char nkeys;
190
0382b9c3 191 __be16 offmask;
1da177e4
LT
192 __u16 off;
193 short offoff;
194
195 short hoff;
0382b9c3 196 __be32 hmask;
1da177e4
LT
197 struct tc_u32_key keys[0];
198};
199
d94d9fee 200struct tc_u32_mark {
1da177e4
LT
201 __u32 val;
202 __u32 mask;
203 __u32 success;
204};
205
d94d9fee 206struct tc_u32_pcnt {
1da177e4
LT
207 __u64 rcnt;
208 __u64 rhit;
209 __u64 kcnts[0];
210};
211
212/* Flags */
213
214#define TC_U32_TERMINAL 1
215#define TC_U32_OFFSET 2
216#define TC_U32_VAROFFSET 4
217#define TC_U32_EAT 8
218
219#define TC_U32_MAXDEPTH 8
220
221
222/* RSVP filter */
223
d94d9fee 224enum {
1da177e4
LT
225 TCA_RSVP_UNSPEC,
226 TCA_RSVP_CLASSID,
227 TCA_RSVP_DST,
228 TCA_RSVP_SRC,
229 TCA_RSVP_PINFO,
230 TCA_RSVP_POLICE,
231 TCA_RSVP_ACT,
232 __TCA_RSVP_MAX
233};
234
235#define TCA_RSVP_MAX (__TCA_RSVP_MAX - 1 )
236
d94d9fee 237struct tc_rsvp_gpi {
1da177e4
LT
238 __u32 key;
239 __u32 mask;
240 int offset;
241};
242
d94d9fee 243struct tc_rsvp_pinfo {
1da177e4
LT
244 struct tc_rsvp_gpi dpi;
245 struct tc_rsvp_gpi spi;
246 __u8 protocol;
247 __u8 tunnelid;
248 __u8 tunnelhdr;
8a47077a 249 __u8 pad;
1da177e4
LT
250};
251
252/* ROUTE filter */
253
d94d9fee 254enum {
1da177e4
LT
255 TCA_ROUTE4_UNSPEC,
256 TCA_ROUTE4_CLASSID,
257 TCA_ROUTE4_TO,
258 TCA_ROUTE4_FROM,
259 TCA_ROUTE4_IIF,
260 TCA_ROUTE4_POLICE,
261 TCA_ROUTE4_ACT,
262 __TCA_ROUTE4_MAX
263};
264
265#define TCA_ROUTE4_MAX (__TCA_ROUTE4_MAX - 1)
266
267
268/* FW filter */
269
d94d9fee 270enum {
1da177e4
LT
271 TCA_FW_UNSPEC,
272 TCA_FW_CLASSID,
273 TCA_FW_POLICE,
274 TCA_FW_INDEV, /* used by CONFIG_NET_CLS_IND */
275 TCA_FW_ACT, /* used by CONFIG_NET_CLS_ACT */
b4e9b520 276 TCA_FW_MASK,
1da177e4
LT
277 __TCA_FW_MAX
278};
279
280#define TCA_FW_MAX (__TCA_FW_MAX - 1)
281
282/* TC index filter */
283
d94d9fee 284enum {
1da177e4
LT
285 TCA_TCINDEX_UNSPEC,
286 TCA_TCINDEX_HASH,
287 TCA_TCINDEX_MASK,
288 TCA_TCINDEX_SHIFT,
289 TCA_TCINDEX_FALL_THROUGH,
290 TCA_TCINDEX_CLASSID,
291 TCA_TCINDEX_POLICE,
292 TCA_TCINDEX_ACT,
293 __TCA_TCINDEX_MAX
294};
295
296#define TCA_TCINDEX_MAX (__TCA_TCINDEX_MAX - 1)
297
e5dfb815
PM
298/* Flow filter */
299
d94d9fee 300enum {
e5dfb815
PM
301 FLOW_KEY_SRC,
302 FLOW_KEY_DST,
303 FLOW_KEY_PROTO,
304 FLOW_KEY_PROTO_SRC,
305 FLOW_KEY_PROTO_DST,
306 FLOW_KEY_IIF,
307 FLOW_KEY_PRIORITY,
308 FLOW_KEY_MARK,
309 FLOW_KEY_NFCT,
310 FLOW_KEY_NFCT_SRC,
311 FLOW_KEY_NFCT_DST,
312 FLOW_KEY_NFCT_PROTO_SRC,
313 FLOW_KEY_NFCT_PROTO_DST,
314 FLOW_KEY_RTCLASSID,
315 FLOW_KEY_SKUID,
316 FLOW_KEY_SKGID,
9ec13810 317 FLOW_KEY_VLAN_TAG,
739a91ef 318 FLOW_KEY_RXHASH,
e5dfb815
PM
319 __FLOW_KEY_MAX,
320};
321
322#define FLOW_KEY_MAX (__FLOW_KEY_MAX - 1)
323
d94d9fee 324enum {
e5dfb815
PM
325 FLOW_MODE_MAP,
326 FLOW_MODE_HASH,
327};
328
d94d9fee 329enum {
e5dfb815
PM
330 TCA_FLOW_UNSPEC,
331 TCA_FLOW_KEYS,
332 TCA_FLOW_MODE,
333 TCA_FLOW_BASECLASS,
334 TCA_FLOW_RSHIFT,
335 TCA_FLOW_ADDEND,
336 TCA_FLOW_MASK,
337 TCA_FLOW_XOR,
338 TCA_FLOW_DIVISOR,
339 TCA_FLOW_ACT,
340 TCA_FLOW_POLICE,
341 TCA_FLOW_EMATCHES,
72d9794f 342 TCA_FLOW_PERTURB,
e5dfb815
PM
343 __TCA_FLOW_MAX
344};
345
346#define TCA_FLOW_MAX (__TCA_FLOW_MAX - 1)
347
1da177e4
LT
348/* Basic filter */
349
d94d9fee 350enum {
1da177e4
LT
351 TCA_BASIC_UNSPEC,
352 TCA_BASIC_CLASSID,
353 TCA_BASIC_EMATCHES,
354 TCA_BASIC_ACT,
355 TCA_BASIC_POLICE,
356 __TCA_BASIC_MAX
357};
358
359#define TCA_BASIC_MAX (__TCA_BASIC_MAX - 1)
360
f4009237
TG
361
362/* Cgroup classifier */
363
d94d9fee 364enum {
f4009237
TG
365 TCA_CGROUP_UNSPEC,
366 TCA_CGROUP_ACT,
367 TCA_CGROUP_POLICE,
368 TCA_CGROUP_EMATCHES,
369 __TCA_CGROUP_MAX,
370};
371
372#define TCA_CGROUP_MAX (__TCA_CGROUP_MAX - 1)
373
7d1d65cb
DB
374/* BPF classifier */
375
376enum {
377 TCA_BPF_UNSPEC,
378 TCA_BPF_ACT,
379 TCA_BPF_POLICE,
380 TCA_BPF_CLASSID,
381 TCA_BPF_OPS_LEN,
382 TCA_BPF_OPS,
e2e9b654
DB
383 TCA_BPF_FD,
384 TCA_BPF_NAME,
7d1d65cb
DB
385 __TCA_BPF_MAX,
386};
387
388#define TCA_BPF_MAX (__TCA_BPF_MAX - 1)
389
77b9900e
JP
390/* Flower classifier */
391
392enum {
393 TCA_FLOWER_UNSPEC,
394 TCA_FLOWER_CLASSID,
395 TCA_FLOWER_INDEV,
396 TCA_FLOWER_ACT,
397 TCA_FLOWER_KEY_ETH_DST, /* ETH_ALEN */
398 TCA_FLOWER_KEY_ETH_DST_MASK, /* ETH_ALEN */
399 TCA_FLOWER_KEY_ETH_SRC, /* ETH_ALEN */
400 TCA_FLOWER_KEY_ETH_SRC_MASK, /* ETH_ALEN */
401 TCA_FLOWER_KEY_ETH_TYPE, /* be16 */
402 TCA_FLOWER_KEY_IP_PROTO, /* u8 */
403 TCA_FLOWER_KEY_IPV4_SRC, /* be32 */
404 TCA_FLOWER_KEY_IPV4_SRC_MASK, /* be32 */
405 TCA_FLOWER_KEY_IPV4_DST, /* be32 */
406 TCA_FLOWER_KEY_IPV4_DST_MASK, /* be32 */
407 TCA_FLOWER_KEY_IPV6_SRC, /* struct in6_addr */
408 TCA_FLOWER_KEY_IPV6_SRC_MASK, /* struct in6_addr */
409 TCA_FLOWER_KEY_IPV6_DST, /* struct in6_addr */
410 TCA_FLOWER_KEY_IPV6_DST_MASK, /* struct in6_addr */
411 TCA_FLOWER_KEY_TCP_SRC, /* be16 */
412 TCA_FLOWER_KEY_TCP_DST, /* be16 */
413 TCA_FLOWER_KEY_UDP_SRC, /* be16 */
414 TCA_FLOWER_KEY_UDP_DST, /* be16 */
415 __TCA_FLOWER_MAX,
416};
417
418#define TCA_FLOWER_MAX (__TCA_FLOWER_MAX - 1)
419
1da177e4
LT
420/* Extended Matches */
421
d94d9fee 422struct tcf_ematch_tree_hdr {
1da177e4
LT
423 __u16 nmatches;
424 __u16 progid;
425};
426
d94d9fee 427enum {
1da177e4
LT
428 TCA_EMATCH_TREE_UNSPEC,
429 TCA_EMATCH_TREE_HDR,
430 TCA_EMATCH_TREE_LIST,
431 __TCA_EMATCH_TREE_MAX
432};
433#define TCA_EMATCH_TREE_MAX (__TCA_EMATCH_TREE_MAX - 1)
434
d94d9fee 435struct tcf_ematch_hdr {
1da177e4
LT
436 __u16 matchid;
437 __u16 kind;
438 __u16 flags;
439 __u16 pad; /* currently unused */
440};
441
442/* 0 1
443 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5
444 * +-----------------------+-+-+---+
445 * | Unused |S|I| R |
446 * +-----------------------+-+-+---+
447 *
448 * R(2) ::= relation to next ematch
449 * where: 0 0 END (last ematch)
450 * 0 1 AND
451 * 1 0 OR
452 * 1 1 Unused (invalid)
453 * I(1) ::= invert result
454 * S(1) ::= simple payload
455 */
456#define TCF_EM_REL_END 0
457#define TCF_EM_REL_AND (1<<0)
458#define TCF_EM_REL_OR (1<<1)
459#define TCF_EM_INVERT (1<<2)
460#define TCF_EM_SIMPLE (1<<3)
461
462#define TCF_EM_REL_MASK 3
463#define TCF_EM_REL_VALID(v) (((v) & TCF_EM_REL_MASK) != TCF_EM_REL_MASK)
464
d94d9fee 465enum {
1da177e4
LT
466 TCF_LAYER_LINK,
467 TCF_LAYER_NETWORK,
468 TCF_LAYER_TRANSPORT,
469 __TCF_LAYER_MAX
470};
471#define TCF_LAYER_MAX (__TCF_LAYER_MAX - 1)
472
473/* Ematch type assignments
474 * 1..32767 Reserved for ematches inside kernel tree
475 * 32768..65535 Free to use, not reliable
476 */
db3d99c0
PM
477#define TCF_EM_CONTAINER 0
478#define TCF_EM_CMP 1
479#define TCF_EM_NBYTE 2
480#define TCF_EM_U32 3
481#define TCF_EM_META 4
482#define TCF_EM_TEXT 5
f057bbb6
RL
483#define TCF_EM_VLAN 6
484#define TCF_EM_CANID 7
6d4fa852
FW
485#define TCF_EM_IPSET 8
486#define TCF_EM_MAX 8
1da177e4 487
d94d9fee 488enum {
1da177e4
LT
489 TCF_EM_PROG_TC
490};
491
d94d9fee 492enum {
1da177e4
LT
493 TCF_EM_OPND_EQ,
494 TCF_EM_OPND_GT,
495 TCF_EM_OPND_LT
496};
497
498#endif