flow_dissector.h 7.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295
  1. /* SPDX-License-Identifier: GPL-2.0 */
  2. #ifndef _NET_FLOW_DISSECTOR_H
  3. #define _NET_FLOW_DISSECTOR_H
  4. #include <linux/types.h>
  5. #include <linux/in6.h>
  6. #include <linux/siphash.h>
  7. #include <linux/string.h>
  8. #include <uapi/linux/if_ether.h>
  9. /**
  10. * struct flow_dissector_key_control:
  11. * @thoff: Transport header offset
  12. */
  13. struct flow_dissector_key_control {
  14. u16 thoff;
  15. u16 addr_type;
  16. u32 flags;
  17. };
  18. #define FLOW_DIS_IS_FRAGMENT BIT(0)
  19. #define FLOW_DIS_FIRST_FRAG BIT(1)
  20. #define FLOW_DIS_ENCAPSULATION BIT(2)
  21. enum flow_dissect_ret {
  22. FLOW_DISSECT_RET_OUT_GOOD,
  23. FLOW_DISSECT_RET_OUT_BAD,
  24. FLOW_DISSECT_RET_PROTO_AGAIN,
  25. FLOW_DISSECT_RET_IPPROTO_AGAIN,
  26. FLOW_DISSECT_RET_CONTINUE,
  27. };
  28. /**
  29. * struct flow_dissector_key_basic:
  30. * @thoff: Transport header offset
  31. * @n_proto: Network header protocol (eg. IPv4/IPv6)
  32. * @ip_proto: Transport header protocol (eg. TCP/UDP)
  33. */
  34. struct flow_dissector_key_basic {
  35. __be16 n_proto;
  36. u8 ip_proto;
  37. u8 padding;
  38. };
  39. struct flow_dissector_key_tags {
  40. u32 flow_label;
  41. };
  42. struct flow_dissector_key_vlan {
  43. u16 vlan_id:12,
  44. vlan_priority:3;
  45. u16 padding;
  46. };
  47. struct flow_dissector_key_mpls {
  48. u32 mpls_ttl:8,
  49. mpls_bos:1,
  50. mpls_tc:3,
  51. mpls_label:20;
  52. };
  53. struct flow_dissector_key_keyid {
  54. __be32 keyid;
  55. };
  56. /**
  57. * struct flow_dissector_key_ipv4_addrs:
  58. * @src: source ip address
  59. * @dst: destination ip address
  60. */
  61. struct flow_dissector_key_ipv4_addrs {
  62. /* (src,dst) must be grouped, in the same way than in IP header */
  63. __be32 src;
  64. __be32 dst;
  65. };
  66. /**
  67. * struct flow_dissector_key_ipv6_addrs:
  68. * @src: source ip address
  69. * @dst: destination ip address
  70. */
  71. struct flow_dissector_key_ipv6_addrs {
  72. /* (src,dst) must be grouped, in the same way than in IP header */
  73. struct in6_addr src;
  74. struct in6_addr dst;
  75. };
  76. /**
  77. * struct flow_dissector_key_tipc_addrs:
  78. * @srcnode: source node address
  79. */
  80. struct flow_dissector_key_tipc_addrs {
  81. __be32 srcnode;
  82. };
  83. /**
  84. * struct flow_dissector_key_addrs:
  85. * @v4addrs: IPv4 addresses
  86. * @v6addrs: IPv6 addresses
  87. */
  88. struct flow_dissector_key_addrs {
  89. union {
  90. struct flow_dissector_key_ipv4_addrs v4addrs;
  91. struct flow_dissector_key_ipv6_addrs v6addrs;
  92. struct flow_dissector_key_tipc_addrs tipcaddrs;
  93. };
  94. };
  95. /**
  96. * flow_dissector_key_arp:
  97. * @ports: Operation, source and target addresses for an ARP header
  98. * for Ethernet hardware addresses and IPv4 protocol addresses
  99. * sip: Sender IP address
  100. * tip: Target IP address
  101. * op: Operation
  102. * sha: Sender hardware address
  103. * tpa: Target hardware address
  104. */
  105. struct flow_dissector_key_arp {
  106. __u32 sip;
  107. __u32 tip;
  108. __u8 op;
  109. unsigned char sha[ETH_ALEN];
  110. unsigned char tha[ETH_ALEN];
  111. };
  112. /**
  113. * flow_dissector_key_tp_ports:
  114. * @ports: port numbers of Transport header
  115. * src: source port number
  116. * dst: destination port number
  117. */
  118. struct flow_dissector_key_ports {
  119. union {
  120. __be32 ports;
  121. struct {
  122. __be16 src;
  123. __be16 dst;
  124. };
  125. };
  126. };
  127. /**
  128. * flow_dissector_key_icmp:
  129. * @ports: type and code of ICMP header
  130. * icmp: ICMP type (high) and code (low)
  131. * type: ICMP type
  132. * code: ICMP code
  133. */
  134. struct flow_dissector_key_icmp {
  135. union {
  136. __be16 icmp;
  137. struct {
  138. u8 type;
  139. u8 code;
  140. };
  141. };
  142. };
  143. /**
  144. * struct flow_dissector_key_eth_addrs:
  145. * @src: source Ethernet address
  146. * @dst: destination Ethernet address
  147. */
  148. struct flow_dissector_key_eth_addrs {
  149. /* (dst,src) must be grouped, in the same way than in ETH header */
  150. unsigned char dst[ETH_ALEN];
  151. unsigned char src[ETH_ALEN];
  152. };
  153. /**
  154. * struct flow_dissector_key_tcp:
  155. * @flags: flags
  156. */
  157. struct flow_dissector_key_tcp {
  158. __be16 flags;
  159. };
  160. /**
  161. * struct flow_dissector_key_ip:
  162. * @tos: tos
  163. * @ttl: ttl
  164. */
  165. struct flow_dissector_key_ip {
  166. __u8 tos;
  167. __u8 ttl;
  168. };
  169. enum flow_dissector_key_id {
  170. FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */
  171. FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */
  172. FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
  173. FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
  174. FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */
  175. FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */
  176. FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */
  177. FLOW_DISSECTOR_KEY_TIPC_ADDRS, /* struct flow_dissector_key_tipc_addrs */
  178. FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */
  179. FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_flow_vlan */
  180. FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_flow_tags */
  181. FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */
  182. FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */
  183. FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */
  184. FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */
  185. FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */
  186. FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */
  187. FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */
  188. FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */
  189. FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */
  190. FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */
  191. FLOW_DISSECTOR_KEY_MAX,
  192. };
  193. #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0)
  194. #define FLOW_DISSECTOR_F_STOP_AT_L3 BIT(1)
  195. #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(2)
  196. #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(3)
  197. struct flow_dissector_key {
  198. enum flow_dissector_key_id key_id;
  199. size_t offset; /* offset of struct flow_dissector_key_*
  200. in target the struct */
  201. };
  202. struct flow_dissector {
  203. unsigned int used_keys; /* each bit repesents presence of one key id */
  204. unsigned short int offset[FLOW_DISSECTOR_KEY_MAX];
  205. };
  206. struct flow_keys {
  207. struct flow_dissector_key_control control;
  208. #define FLOW_KEYS_HASH_START_FIELD basic
  209. struct flow_dissector_key_basic basic __aligned(SIPHASH_ALIGNMENT);
  210. struct flow_dissector_key_tags tags;
  211. struct flow_dissector_key_vlan vlan;
  212. struct flow_dissector_key_keyid keyid;
  213. struct flow_dissector_key_ports ports;
  214. struct flow_dissector_key_addrs addrs;
  215. };
  216. #define FLOW_KEYS_HASH_OFFSET \
  217. offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD)
  218. __be32 flow_get_u32_src(const struct flow_keys *flow);
  219. __be32 flow_get_u32_dst(const struct flow_keys *flow);
  220. extern struct flow_dissector flow_keys_dissector;
  221. extern struct flow_dissector flow_keys_buf_dissector;
  222. /* struct flow_keys_digest:
  223. *
  224. * This structure is used to hold a digest of the full flow keys. This is a
  225. * larger "hash" of a flow to allow definitively matching specific flows where
  226. * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so
  227. * that it can by used in CB of skb (see sch_choke for an example).
  228. */
  229. #define FLOW_KEYS_DIGEST_LEN 16
  230. struct flow_keys_digest {
  231. u8 data[FLOW_KEYS_DIGEST_LEN];
  232. };
  233. void make_flow_keys_digest(struct flow_keys_digest *digest,
  234. const struct flow_keys *flow);
  235. static inline bool flow_keys_have_l4(const struct flow_keys *keys)
  236. {
  237. return (keys->ports.ports || keys->tags.flow_label);
  238. }
  239. u32 flow_hash_from_keys(struct flow_keys *keys);
  240. static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector,
  241. enum flow_dissector_key_id key_id)
  242. {
  243. return flow_dissector->used_keys & (1 << key_id);
  244. }
  245. static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector,
  246. enum flow_dissector_key_id key_id,
  247. void *target_container)
  248. {
  249. return ((char *)target_container) + flow_dissector->offset[key_id];
  250. }
  251. static inline void
  252. flow_dissector_init_keys(struct flow_dissector_key_control *key_control,
  253. struct flow_dissector_key_basic *key_basic)
  254. {
  255. memset(key_control, 0, sizeof(*key_control));
  256. memset(key_basic, 0, sizeof(*key_basic));
  257. }
  258. #endif