flow_dissector.h 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319
  1. /* SPDX-License-Identifier: GPL-2.0 */
  2. #ifndef _NET_FLOW_DISSECTOR_H
  3. #define _NET_FLOW_DISSECTOR_H
  4. #include <linux/types.h>
  5. #include <linux/in6.h>
  6. #include <linux/siphash.h>
  7. #include <linux/string.h>
  8. #include <uapi/linux/if_ether.h>
  9. /**
  10. * struct flow_dissector_key_control:
  11. * @thoff: Transport header offset
  12. */
  13. struct flow_dissector_key_control {
  14. u16 thoff;
  15. u16 addr_type;
  16. u32 flags;
  17. };
  18. #define FLOW_DIS_IS_FRAGMENT BIT(0)
  19. #define FLOW_DIS_FIRST_FRAG BIT(1)
  20. #define FLOW_DIS_ENCAPSULATION BIT(2)
  21. enum flow_dissect_ret {
  22. FLOW_DISSECT_RET_OUT_GOOD,
  23. FLOW_DISSECT_RET_OUT_BAD,
  24. FLOW_DISSECT_RET_PROTO_AGAIN,
  25. FLOW_DISSECT_RET_IPPROTO_AGAIN,
  26. FLOW_DISSECT_RET_CONTINUE,
  27. };
  28. /**
  29. * struct flow_dissector_key_basic:
  30. * @thoff: Transport header offset
  31. * @n_proto: Network header protocol (eg. IPv4/IPv6)
  32. * @ip_proto: Transport header protocol (eg. TCP/UDP)
  33. */
  34. struct flow_dissector_key_basic {
  35. __be16 n_proto;
  36. u8 ip_proto;
  37. u8 padding;
  38. };
  39. struct flow_dissector_key_tags {
  40. u32 flow_label;
  41. };
  42. struct flow_dissector_key_vlan {
  43. u16 vlan_id:12,
  44. vlan_priority:3;
  45. __be16 vlan_tpid;
  46. };
  47. struct flow_dissector_key_mpls {
  48. u32 mpls_ttl:8,
  49. mpls_bos:1,
  50. mpls_tc:3,
  51. mpls_label:20;
  52. };
  53. #define FLOW_DIS_TUN_OPTS_MAX 255
  54. /**
  55. * struct flow_dissector_key_enc_opts:
  56. * @data: tunnel option data
  57. * @len: length of tunnel option data
  58. * @dst_opt_type: tunnel option type
  59. */
  60. struct flow_dissector_key_enc_opts {
  61. u8 data[FLOW_DIS_TUN_OPTS_MAX]; /* Using IP_TUNNEL_OPTS_MAX is desired
  62. * here but seems difficult to #include
  63. */
  64. u8 len;
  65. __be16 dst_opt_type;
  66. };
  67. struct flow_dissector_key_keyid {
  68. __be32 keyid;
  69. };
  70. /**
  71. * struct flow_dissector_key_ipv4_addrs:
  72. * @src: source ip address
  73. * @dst: destination ip address
  74. */
  75. struct flow_dissector_key_ipv4_addrs {
  76. /* (src,dst) must be grouped, in the same way than in IP header */
  77. __be32 src;
  78. __be32 dst;
  79. };
  80. /**
  81. * struct flow_dissector_key_ipv6_addrs:
  82. * @src: source ip address
  83. * @dst: destination ip address
  84. */
  85. struct flow_dissector_key_ipv6_addrs {
  86. /* (src,dst) must be grouped, in the same way than in IP header */
  87. struct in6_addr src;
  88. struct in6_addr dst;
  89. };
  90. /**
  91. * struct flow_dissector_key_tipc:
  92. * @key: source node address combined with selector
  93. */
  94. struct flow_dissector_key_tipc {
  95. __be32 key;
  96. };
  97. /**
  98. * struct flow_dissector_key_addrs:
  99. * @v4addrs: IPv4 addresses
  100. * @v6addrs: IPv6 addresses
  101. */
  102. struct flow_dissector_key_addrs {
  103. union {
  104. struct flow_dissector_key_ipv4_addrs v4addrs;
  105. struct flow_dissector_key_ipv6_addrs v6addrs;
  106. struct flow_dissector_key_tipc tipckey;
  107. };
  108. };
  109. /**
  110. * flow_dissector_key_arp:
  111. * @ports: Operation, source and target addresses for an ARP header
  112. * for Ethernet hardware addresses and IPv4 protocol addresses
  113. * sip: Sender IP address
  114. * tip: Target IP address
  115. * op: Operation
  116. * sha: Sender hardware address
  117. * tpa: Target hardware address
  118. */
  119. struct flow_dissector_key_arp {
  120. __u32 sip;
  121. __u32 tip;
  122. __u8 op;
  123. unsigned char sha[ETH_ALEN];
  124. unsigned char tha[ETH_ALEN];
  125. };
  126. /**
  127. * flow_dissector_key_tp_ports:
  128. * @ports: port numbers of Transport header
  129. * src: source port number
  130. * dst: destination port number
  131. */
  132. struct flow_dissector_key_ports {
  133. union {
  134. __be32 ports;
  135. struct {
  136. __be16 src;
  137. __be16 dst;
  138. };
  139. };
  140. };
  141. /**
  142. * flow_dissector_key_icmp:
  143. * @ports: type and code of ICMP header
  144. * icmp: ICMP type (high) and code (low)
  145. * type: ICMP type
  146. * code: ICMP code
  147. */
  148. struct flow_dissector_key_icmp {
  149. union {
  150. __be16 icmp;
  151. struct {
  152. u8 type;
  153. u8 code;
  154. };
  155. };
  156. };
  157. /**
  158. * struct flow_dissector_key_eth_addrs:
  159. * @src: source Ethernet address
  160. * @dst: destination Ethernet address
  161. */
  162. struct flow_dissector_key_eth_addrs {
  163. /* (dst,src) must be grouped, in the same way than in ETH header */
  164. unsigned char dst[ETH_ALEN];
  165. unsigned char src[ETH_ALEN];
  166. };
  167. /**
  168. * struct flow_dissector_key_tcp:
  169. * @flags: flags
  170. */
  171. struct flow_dissector_key_tcp {
  172. __be16 flags;
  173. };
  174. /**
  175. * struct flow_dissector_key_ip:
  176. * @tos: tos
  177. * @ttl: ttl
  178. */
  179. struct flow_dissector_key_ip {
  180. __u8 tos;
  181. __u8 ttl;
  182. };
  183. enum flow_dissector_key_id {
  184. FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */
  185. FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */
  186. FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
  187. FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
  188. FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */
  189. FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */
  190. FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */
  191. FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */
  192. FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */
  193. FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_flow_vlan */
  194. FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_flow_tags */
  195. FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */
  196. FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */
  197. FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */
  198. FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
  199. FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
  200. FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */
  201. FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */
  202. FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */
  203. FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */
  204. FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */
  205. FLOW_DISSECTOR_KEY_CVLAN, /* struct flow_dissector_key_flow_vlan */
  206. FLOW_DISSECTOR_KEY_ENC_IP, /* struct flow_dissector_key_ip */
  207. FLOW_DISSECTOR_KEY_ENC_OPTS, /* struct flow_dissector_key_enc_opts */
  208. FLOW_DISSECTOR_KEY_MAX,
  209. };
  210. #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0)
  211. #define FLOW_DISSECTOR_F_STOP_AT_L3 BIT(1)
  212. #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(2)
  213. #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(3)
  214. struct flow_dissector_key {
  215. enum flow_dissector_key_id key_id;
  216. size_t offset; /* offset of struct flow_dissector_key_*
  217. in target the struct */
  218. };
  219. struct flow_dissector {
  220. unsigned int used_keys; /* each bit repesents presence of one key id */
  221. unsigned short int offset[FLOW_DISSECTOR_KEY_MAX];
  222. };
  223. struct flow_keys_basic {
  224. struct flow_dissector_key_control control;
  225. struct flow_dissector_key_basic basic;
  226. };
  227. struct flow_keys {
  228. struct flow_dissector_key_control control;
  229. #define FLOW_KEYS_HASH_START_FIELD basic
  230. struct flow_dissector_key_basic basic __aligned(SIPHASH_ALIGNMENT);
  231. struct flow_dissector_key_tags tags;
  232. struct flow_dissector_key_vlan vlan;
  233. struct flow_dissector_key_vlan cvlan;
  234. struct flow_dissector_key_keyid keyid;
  235. struct flow_dissector_key_ports ports;
  236. struct flow_dissector_key_addrs addrs;
  237. };
  238. #define FLOW_KEYS_HASH_OFFSET \
  239. offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD)
  240. __be32 flow_get_u32_src(const struct flow_keys *flow);
  241. __be32 flow_get_u32_dst(const struct flow_keys *flow);
  242. extern struct flow_dissector flow_keys_dissector;
  243. extern struct flow_dissector flow_keys_basic_dissector;
  244. /* struct flow_keys_digest:
  245. *
  246. * This structure is used to hold a digest of the full flow keys. This is a
  247. * larger "hash" of a flow to allow definitively matching specific flows where
  248. * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so
  249. * that it can be used in CB of skb (see sch_choke for an example).
  250. */
  251. #define FLOW_KEYS_DIGEST_LEN 16
  252. struct flow_keys_digest {
  253. u8 data[FLOW_KEYS_DIGEST_LEN];
  254. };
  255. void make_flow_keys_digest(struct flow_keys_digest *digest,
  256. const struct flow_keys *flow);
  257. static inline bool flow_keys_have_l4(const struct flow_keys *keys)
  258. {
  259. return (keys->ports.ports || keys->tags.flow_label);
  260. }
  261. u32 flow_hash_from_keys(struct flow_keys *keys);
  262. static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector,
  263. enum flow_dissector_key_id key_id)
  264. {
  265. return flow_dissector->used_keys & (1 << key_id);
  266. }
  267. static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector,
  268. enum flow_dissector_key_id key_id,
  269. void *target_container)
  270. {
  271. return ((char *)target_container) + flow_dissector->offset[key_id];
  272. }
  273. static inline void
  274. flow_dissector_init_keys(struct flow_dissector_key_control *key_control,
  275. struct flow_dissector_key_basic *key_basic)
  276. {
  277. memset(key_control, 0, sizeof(*key_control));
  278. memset(key_basic, 0, sizeof(*key_basic));
  279. }
  280. #endif