1b2441318SGreg Kroah-Hartman /* SPDX-License-Identifier: GPL-2.0 */ 21bd758ebSJiri Pirko #ifndef _NET_FLOW_DISSECTOR_H 31bd758ebSJiri Pirko #define _NET_FLOW_DISSECTOR_H 41bd758ebSJiri Pirko 5c3f8eaebSJiri Pirko #include <linux/types.h> 6b924933cSJiri Pirko #include <linux/in6.h> 7*55667441SEric Dumazet #include <linux/siphash.h> 867a900ccSJiri Pirko #include <uapi/linux/if_ether.h> 9c3f8eaebSJiri Pirko 10fbff949eSJiri Pirko /** 1142aecaa9STom Herbert * struct flow_dissector_key_control: 1242aecaa9STom Herbert * @thoff: Transport header offset 1342aecaa9STom Herbert */ 1442aecaa9STom Herbert struct flow_dissector_key_control { 1542aecaa9STom Herbert u16 thoff; 16c3f83241STom Herbert u16 addr_type; 174b36993dSDavid S. Miller u32 flags; 1842aecaa9STom Herbert }; 1942aecaa9STom Herbert 204b36993dSDavid S. Miller #define FLOW_DIS_IS_FRAGMENT BIT(0) 214b36993dSDavid S. Miller #define FLOW_DIS_FIRST_FRAG BIT(1) 224b36993dSDavid S. Miller #define FLOW_DIS_ENCAPSULATION BIT(2) 234b36993dSDavid S. Miller 243a1214e8STom Herbert enum flow_dissect_ret { 253a1214e8STom Herbert FLOW_DISSECT_RET_OUT_GOOD, 263a1214e8STom Herbert FLOW_DISSECT_RET_OUT_BAD, 273a1214e8STom Herbert FLOW_DISSECT_RET_PROTO_AGAIN, 283a1214e8STom Herbert FLOW_DISSECT_RET_IPPROTO_AGAIN, 293a1214e8STom Herbert FLOW_DISSECT_RET_CONTINUE, 303a1214e8STom Herbert }; 313a1214e8STom Herbert 3242aecaa9STom Herbert /** 33fbff949eSJiri Pirko * struct flow_dissector_key_basic: 34fbff949eSJiri Pirko * @thoff: Transport header offset 35fbff949eSJiri Pirko * @n_proto: Network header protocol (eg. IPv4/IPv6) 36fbff949eSJiri Pirko * @ip_proto: Transport header protocol (eg. TCP/UDP) 37fbff949eSJiri Pirko */ 38fbff949eSJiri Pirko struct flow_dissector_key_basic { 39fbff949eSJiri Pirko __be16 n_proto; 40fbff949eSJiri Pirko u8 ip_proto; 4142aecaa9STom Herbert u8 padding; 42fbff949eSJiri Pirko }; 43fbff949eSJiri Pirko 44d34af823STom Herbert struct flow_dissector_key_tags { 45f6a66927SHadar Hen Zion u32 flow_label; 46f6a66927SHadar Hen Zion }; 47f6a66927SHadar Hen Zion 48f6a66927SHadar Hen Zion struct flow_dissector_key_vlan { 49f6a66927SHadar Hen Zion u16 vlan_id:12, 50f0d2ca15SMaxime Chevallier vlan_dei:1, 51f6a66927SHadar Hen Zion vlan_priority:3; 522064c3d4SJianbo Liu __be16 vlan_tpid; 53d34af823STom Herbert }; 54d34af823STom Herbert 55029c1ecbSBenjamin LaHaise struct flow_dissector_key_mpls { 56029c1ecbSBenjamin LaHaise u32 mpls_ttl:8, 57029c1ecbSBenjamin LaHaise mpls_bos:1, 58029c1ecbSBenjamin LaHaise mpls_tc:3, 59029c1ecbSBenjamin LaHaise mpls_label:20; 60029c1ecbSBenjamin LaHaise }; 61029c1ecbSBenjamin LaHaise 6292e2c405SSimon Horman #define FLOW_DIS_TUN_OPTS_MAX 255 6392e2c405SSimon Horman /** 6492e2c405SSimon Horman * struct flow_dissector_key_enc_opts: 6592e2c405SSimon Horman * @data: tunnel option data 6692e2c405SSimon Horman * @len: length of tunnel option data 6792e2c405SSimon Horman * @dst_opt_type: tunnel option type 6892e2c405SSimon Horman */ 6992e2c405SSimon Horman struct flow_dissector_key_enc_opts { 7092e2c405SSimon Horman u8 data[FLOW_DIS_TUN_OPTS_MAX]; /* Using IP_TUNNEL_OPTS_MAX is desired 7192e2c405SSimon Horman * here but seems difficult to #include 7292e2c405SSimon Horman */ 7392e2c405SSimon Horman u8 len; 7492e2c405SSimon Horman __be16 dst_opt_type; 7592e2c405SSimon Horman }; 7692e2c405SSimon Horman 771fdd512cSTom Herbert struct flow_dissector_key_keyid { 781fdd512cSTom Herbert __be32 keyid; 791fdd512cSTom Herbert }; 801fdd512cSTom Herbert 81fbff949eSJiri Pirko /** 82c3f83241STom Herbert * struct flow_dissector_key_ipv4_addrs: 83c3f83241STom Herbert * @src: source ip address 84c3f83241STom Herbert * @dst: destination ip address 85fbff949eSJiri Pirko */ 86c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs { 87fbff949eSJiri Pirko /* (src,dst) must be grouped, in the same way than in IP header */ 88fbff949eSJiri Pirko __be32 src; 89fbff949eSJiri Pirko __be32 dst; 90fbff949eSJiri Pirko }; 91fbff949eSJiri Pirko 92fbff949eSJiri Pirko /** 93c3f83241STom Herbert * struct flow_dissector_key_ipv6_addrs: 94c3f83241STom Herbert * @src: source ip address 95c3f83241STom Herbert * @dst: destination ip address 96c3f83241STom Herbert */ 97c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs { 98c3f83241STom Herbert /* (src,dst) must be grouped, in the same way than in IP header */ 99c3f83241STom Herbert struct in6_addr src; 100c3f83241STom Herbert struct in6_addr dst; 101c3f83241STom Herbert }; 102c3f83241STom Herbert 103c3f83241STom Herbert /** 1048d6e79d3SJon Maloy * struct flow_dissector_key_tipc: 1058d6e79d3SJon Maloy * @key: source node address combined with selector 1069f249089STom Herbert */ 1078d6e79d3SJon Maloy struct flow_dissector_key_tipc { 1088d6e79d3SJon Maloy __be32 key; 1099f249089STom Herbert }; 1109f249089STom Herbert 1119f249089STom Herbert /** 112c3f83241STom Herbert * struct flow_dissector_key_addrs: 113c3f83241STom Herbert * @v4addrs: IPv4 addresses 114c3f83241STom Herbert * @v6addrs: IPv6 addresses 115c3f83241STom Herbert */ 116c3f83241STom Herbert struct flow_dissector_key_addrs { 117c3f83241STom Herbert union { 118c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs v4addrs; 119c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs v6addrs; 1208d6e79d3SJon Maloy struct flow_dissector_key_tipc tipckey; 121c3f83241STom Herbert }; 122c3f83241STom Herbert }; 123c3f83241STom Herbert 124c3f83241STom Herbert /** 12555733350SSimon Horman * flow_dissector_key_arp: 12655733350SSimon Horman * @ports: Operation, source and target addresses for an ARP header 12755733350SSimon Horman * for Ethernet hardware addresses and IPv4 protocol addresses 12855733350SSimon Horman * sip: Sender IP address 12955733350SSimon Horman * tip: Target IP address 13055733350SSimon Horman * op: Operation 13155733350SSimon Horman * sha: Sender hardware address 13255733350SSimon Horman * tpa: Target hardware address 13355733350SSimon Horman */ 13455733350SSimon Horman struct flow_dissector_key_arp { 13555733350SSimon Horman __u32 sip; 13655733350SSimon Horman __u32 tip; 13755733350SSimon Horman __u8 op; 13855733350SSimon Horman unsigned char sha[ETH_ALEN]; 13955733350SSimon Horman unsigned char tha[ETH_ALEN]; 14055733350SSimon Horman }; 14155733350SSimon Horman 14255733350SSimon Horman /** 143fbff949eSJiri Pirko * flow_dissector_key_tp_ports: 144fbff949eSJiri Pirko * @ports: port numbers of Transport header 14559346afeSJiri Pirko * src: source port number 14659346afeSJiri Pirko * dst: destination port number 147fbff949eSJiri Pirko */ 148fbff949eSJiri Pirko struct flow_dissector_key_ports { 149fbff949eSJiri Pirko union { 150fbff949eSJiri Pirko __be32 ports; 15159346afeSJiri Pirko struct { 15259346afeSJiri Pirko __be16 src; 15359346afeSJiri Pirko __be16 dst; 15459346afeSJiri Pirko }; 155fbff949eSJiri Pirko }; 156fbff949eSJiri Pirko }; 157fbff949eSJiri Pirko 158972d3876SSimon Horman /** 159972d3876SSimon Horman * flow_dissector_key_icmp: 160972d3876SSimon Horman * @ports: type and code of ICMP header 161972d3876SSimon Horman * icmp: ICMP type (high) and code (low) 162972d3876SSimon Horman * type: ICMP type 163972d3876SSimon Horman * code: ICMP code 164972d3876SSimon Horman */ 165972d3876SSimon Horman struct flow_dissector_key_icmp { 166972d3876SSimon Horman union { 167972d3876SSimon Horman __be16 icmp; 168972d3876SSimon Horman struct { 169972d3876SSimon Horman u8 type; 170972d3876SSimon Horman u8 code; 171972d3876SSimon Horman }; 172972d3876SSimon Horman }; 173972d3876SSimon Horman }; 174b924933cSJiri Pirko 17567a900ccSJiri Pirko /** 17667a900ccSJiri Pirko * struct flow_dissector_key_eth_addrs: 17767a900ccSJiri Pirko * @src: source Ethernet address 17867a900ccSJiri Pirko * @dst: destination Ethernet address 17967a900ccSJiri Pirko */ 18067a900ccSJiri Pirko struct flow_dissector_key_eth_addrs { 18167a900ccSJiri Pirko /* (dst,src) must be grouped, in the same way than in ETH header */ 18267a900ccSJiri Pirko unsigned char dst[ETH_ALEN]; 18367a900ccSJiri Pirko unsigned char src[ETH_ALEN]; 18467a900ccSJiri Pirko }; 18567a900ccSJiri Pirko 186ac4bb5deSJiri Pirko /** 187ac4bb5deSJiri Pirko * struct flow_dissector_key_tcp: 188ac4bb5deSJiri Pirko * @flags: flags 189ac4bb5deSJiri Pirko */ 190ac4bb5deSJiri Pirko struct flow_dissector_key_tcp { 191ac4bb5deSJiri Pirko __be16 flags; 192ac4bb5deSJiri Pirko }; 193ac4bb5deSJiri Pirko 194518d8a2eSOr Gerlitz /** 195518d8a2eSOr Gerlitz * struct flow_dissector_key_ip: 196518d8a2eSOr Gerlitz * @tos: tos 197518d8a2eSOr Gerlitz * @ttl: ttl 198518d8a2eSOr Gerlitz */ 199518d8a2eSOr Gerlitz struct flow_dissector_key_ip { 200518d8a2eSOr Gerlitz __u8 tos; 201518d8a2eSOr Gerlitz __u8 ttl; 202518d8a2eSOr Gerlitz }; 203518d8a2eSOr Gerlitz 20482828b88SJiri Pirko /** 20582828b88SJiri Pirko * struct flow_dissector_key_meta: 20682828b88SJiri Pirko * @ingress_ifindex: ingress ifindex 20782828b88SJiri Pirko */ 20882828b88SJiri Pirko struct flow_dissector_key_meta { 20982828b88SJiri Pirko int ingress_ifindex; 21082828b88SJiri Pirko }; 21182828b88SJiri Pirko 21275a56758SPaul Blakey /** 21375a56758SPaul Blakey * struct flow_dissector_key_ct: 21475a56758SPaul Blakey * @ct_state: conntrack state after converting with map 21575a56758SPaul Blakey * @ct_mark: conttrack mark 21675a56758SPaul Blakey * @ct_zone: conntrack zone 21775a56758SPaul Blakey * @ct_labels: conntrack labels 21875a56758SPaul Blakey */ 21975a56758SPaul Blakey struct flow_dissector_key_ct { 22075a56758SPaul Blakey u16 ct_state; 22175a56758SPaul Blakey u16 ct_zone; 22275a56758SPaul Blakey u32 ct_mark; 22375a56758SPaul Blakey u32 ct_labels[4]; 22475a56758SPaul Blakey }; 22575a56758SPaul Blakey 226fbff949eSJiri Pirko enum flow_dissector_key_id { 22742aecaa9STom Herbert FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */ 228fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */ 229c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 230c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 231fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */ 232972d3876SSimon Horman FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */ 23367a900ccSJiri Pirko FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */ 2348d6e79d3SJon Maloy FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */ 23555733350SSimon Horman FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */ 23691c45956SEdward Cree FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_vlan */ 23791c45956SEdward Cree FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_tags */ 2381fdd512cSTom Herbert FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */ 239b3baa0fbSTom Herbert FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */ 2409ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */ 2419ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 2429ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 2439ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */ 244f4d997fdSHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */ 245029c1ecbSBenjamin LaHaise FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */ 246ac4bb5deSJiri Pirko FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */ 247518d8a2eSOr Gerlitz FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */ 24891c45956SEdward Cree FLOW_DISSECTOR_KEY_CVLAN, /* struct flow_dissector_key_vlan */ 2495544adb9SOr Gerlitz FLOW_DISSECTOR_KEY_ENC_IP, /* struct flow_dissector_key_ip */ 25092e2c405SSimon Horman FLOW_DISSECTOR_KEY_ENC_OPTS, /* struct flow_dissector_key_enc_opts */ 25182828b88SJiri Pirko FLOW_DISSECTOR_KEY_META, /* struct flow_dissector_key_meta */ 25275a56758SPaul Blakey FLOW_DISSECTOR_KEY_CT, /* struct flow_dissector_key_ct */ 25392e2c405SSimon Horman 254fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_MAX, 255fbff949eSJiri Pirko }; 256fbff949eSJiri Pirko 257807e165dSTom Herbert #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0) 2581cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(1) 2591cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(2) 260807e165dSTom Herbert 261fbff949eSJiri Pirko struct flow_dissector_key { 262fbff949eSJiri Pirko enum flow_dissector_key_id key_id; 263fbff949eSJiri Pirko size_t offset; /* offset of struct flow_dissector_key_* 264fbff949eSJiri Pirko in target the struct */ 265fbff949eSJiri Pirko }; 266fbff949eSJiri Pirko 267fbff949eSJiri Pirko struct flow_dissector { 268fbff949eSJiri Pirko unsigned int used_keys; /* each bit repesents presence of one key id */ 269fbff949eSJiri Pirko unsigned short int offset[FLOW_DISSECTOR_KEY_MAX]; 270fbff949eSJiri Pirko }; 271fbff949eSJiri Pirko 27272a338bcSPaolo Abeni struct flow_keys_basic { 27372a338bcSPaolo Abeni struct flow_dissector_key_control control; 27472a338bcSPaolo Abeni struct flow_dissector_key_basic basic; 27572a338bcSPaolo Abeni }; 27672a338bcSPaolo Abeni 27706635a35SJiri Pirko struct flow_keys { 27842aecaa9STom Herbert struct flow_dissector_key_control control; 27942aecaa9STom Herbert #define FLOW_KEYS_HASH_START_FIELD basic 280*55667441SEric Dumazet struct flow_dissector_key_basic basic __aligned(SIPHASH_ALIGNMENT); 281d34af823STom Herbert struct flow_dissector_key_tags tags; 282f6a66927SHadar Hen Zion struct flow_dissector_key_vlan vlan; 28324c590e3SJianbo Liu struct flow_dissector_key_vlan cvlan; 2841fdd512cSTom Herbert struct flow_dissector_key_keyid keyid; 28542aecaa9STom Herbert struct flow_dissector_key_ports ports; 28642aecaa9STom Herbert struct flow_dissector_key_addrs addrs; 28706635a35SJiri Pirko }; 28806635a35SJiri Pirko 28942aecaa9STom Herbert #define FLOW_KEYS_HASH_OFFSET \ 29042aecaa9STom Herbert offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD) 29142aecaa9STom Herbert 292c3f83241STom Herbert __be32 flow_get_u32_src(const struct flow_keys *flow); 293c3f83241STom Herbert __be32 flow_get_u32_dst(const struct flow_keys *flow); 294c3f83241STom Herbert 29506635a35SJiri Pirko extern struct flow_dissector flow_keys_dissector; 29672a338bcSPaolo Abeni extern struct flow_dissector flow_keys_basic_dissector; 29706635a35SJiri Pirko 2981bd758ebSJiri Pirko /* struct flow_keys_digest: 2991bd758ebSJiri Pirko * 3001bd758ebSJiri Pirko * This structure is used to hold a digest of the full flow keys. This is a 3011bd758ebSJiri Pirko * larger "hash" of a flow to allow definitively matching specific flows where 3021bd758ebSJiri Pirko * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so 30353bc017fSWolfram Sang * that it can be used in CB of skb (see sch_choke for an example). 3041bd758ebSJiri Pirko */ 3051bd758ebSJiri Pirko #define FLOW_KEYS_DIGEST_LEN 16 3061bd758ebSJiri Pirko struct flow_keys_digest { 3071bd758ebSJiri Pirko u8 data[FLOW_KEYS_DIGEST_LEN]; 3081bd758ebSJiri Pirko }; 3091bd758ebSJiri Pirko 3101bd758ebSJiri Pirko void make_flow_keys_digest(struct flow_keys_digest *digest, 3111bd758ebSJiri Pirko const struct flow_keys *flow); 3121bd758ebSJiri Pirko 31366fdd05eSGao Feng static inline bool flow_keys_have_l4(const struct flow_keys *keys) 314bcc83839STom Herbert { 315bcc83839STom Herbert return (keys->ports.ports || keys->tags.flow_label); 316bcc83839STom Herbert } 317bcc83839STom Herbert 318c6cc1ca7STom Herbert u32 flow_hash_from_keys(struct flow_keys *keys); 319c6cc1ca7STom Herbert 3208de2d793SAmir Vadai static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector, 3218de2d793SAmir Vadai enum flow_dissector_key_id key_id) 3228de2d793SAmir Vadai { 3238de2d793SAmir Vadai return flow_dissector->used_keys & (1 << key_id); 3248de2d793SAmir Vadai } 3258de2d793SAmir Vadai 3268de2d793SAmir Vadai static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector, 3278de2d793SAmir Vadai enum flow_dissector_key_id key_id, 3288de2d793SAmir Vadai void *target_container) 3298de2d793SAmir Vadai { 3308de2d793SAmir Vadai return ((char *)target_container) + flow_dissector->offset[key_id]; 3318de2d793SAmir Vadai } 3328de2d793SAmir Vadai 333089b19a9SStanislav Fomichev struct bpf_flow_dissector { 334089b19a9SStanislav Fomichev struct bpf_flow_keys *flow_keys; 335089b19a9SStanislav Fomichev const struct sk_buff *skb; 336089b19a9SStanislav Fomichev void *data; 337089b19a9SStanislav Fomichev void *data_end; 338089b19a9SStanislav Fomichev }; 339089b19a9SStanislav Fomichev 3401bd758ebSJiri Pirko #endif 341