1b2441318SGreg Kroah-Hartman /* SPDX-License-Identifier: GPL-2.0 */ 21bd758ebSJiri Pirko #ifndef _NET_FLOW_DISSECTOR_H 31bd758ebSJiri Pirko #define _NET_FLOW_DISSECTOR_H 41bd758ebSJiri Pirko 5c3f8eaebSJiri Pirko #include <linux/types.h> 6b924933cSJiri Pirko #include <linux/in6.h> 767a900ccSJiri Pirko #include <uapi/linux/if_ether.h> 8c3f8eaebSJiri Pirko 9*5dec597eSMatteo Croce struct sk_buff; 10*5dec597eSMatteo Croce 11fbff949eSJiri Pirko /** 1242aecaa9STom Herbert * struct flow_dissector_key_control: 1342aecaa9STom Herbert * @thoff: Transport header offset 1442aecaa9STom Herbert */ 1542aecaa9STom Herbert struct flow_dissector_key_control { 1642aecaa9STom Herbert u16 thoff; 17c3f83241STom Herbert u16 addr_type; 184b36993dSDavid S. Miller u32 flags; 1942aecaa9STom Herbert }; 2042aecaa9STom Herbert 214b36993dSDavid S. Miller #define FLOW_DIS_IS_FRAGMENT BIT(0) 224b36993dSDavid S. Miller #define FLOW_DIS_FIRST_FRAG BIT(1) 234b36993dSDavid S. Miller #define FLOW_DIS_ENCAPSULATION BIT(2) 244b36993dSDavid S. Miller 253a1214e8STom Herbert enum flow_dissect_ret { 263a1214e8STom Herbert FLOW_DISSECT_RET_OUT_GOOD, 273a1214e8STom Herbert FLOW_DISSECT_RET_OUT_BAD, 283a1214e8STom Herbert FLOW_DISSECT_RET_PROTO_AGAIN, 293a1214e8STom Herbert FLOW_DISSECT_RET_IPPROTO_AGAIN, 303a1214e8STom Herbert FLOW_DISSECT_RET_CONTINUE, 313a1214e8STom Herbert }; 323a1214e8STom Herbert 3342aecaa9STom Herbert /** 34fbff949eSJiri Pirko * struct flow_dissector_key_basic: 35fbff949eSJiri Pirko * @thoff: Transport header offset 36fbff949eSJiri Pirko * @n_proto: Network header protocol (eg. IPv4/IPv6) 37fbff949eSJiri Pirko * @ip_proto: Transport header protocol (eg. TCP/UDP) 38fbff949eSJiri Pirko */ 39fbff949eSJiri Pirko struct flow_dissector_key_basic { 40fbff949eSJiri Pirko __be16 n_proto; 41fbff949eSJiri Pirko u8 ip_proto; 4242aecaa9STom Herbert u8 padding; 43fbff949eSJiri Pirko }; 44fbff949eSJiri Pirko 45d34af823STom Herbert struct flow_dissector_key_tags { 46f6a66927SHadar Hen Zion u32 flow_label; 47f6a66927SHadar Hen Zion }; 48f6a66927SHadar Hen Zion 49f6a66927SHadar Hen Zion struct flow_dissector_key_vlan { 50f6a66927SHadar Hen Zion u16 vlan_id:12, 51f0d2ca15SMaxime Chevallier vlan_dei:1, 52f6a66927SHadar Hen Zion vlan_priority:3; 532064c3d4SJianbo Liu __be16 vlan_tpid; 54d34af823STom Herbert }; 55d34af823STom Herbert 56029c1ecbSBenjamin LaHaise struct flow_dissector_key_mpls { 57029c1ecbSBenjamin LaHaise u32 mpls_ttl:8, 58029c1ecbSBenjamin LaHaise mpls_bos:1, 59029c1ecbSBenjamin LaHaise mpls_tc:3, 60029c1ecbSBenjamin LaHaise mpls_label:20; 61029c1ecbSBenjamin LaHaise }; 62029c1ecbSBenjamin LaHaise 6392e2c405SSimon Horman #define FLOW_DIS_TUN_OPTS_MAX 255 6492e2c405SSimon Horman /** 6592e2c405SSimon Horman * struct flow_dissector_key_enc_opts: 6692e2c405SSimon Horman * @data: tunnel option data 6792e2c405SSimon Horman * @len: length of tunnel option data 6892e2c405SSimon Horman * @dst_opt_type: tunnel option type 6992e2c405SSimon Horman */ 7092e2c405SSimon Horman struct flow_dissector_key_enc_opts { 7192e2c405SSimon Horman u8 data[FLOW_DIS_TUN_OPTS_MAX]; /* Using IP_TUNNEL_OPTS_MAX is desired 7292e2c405SSimon Horman * here but seems difficult to #include 7392e2c405SSimon Horman */ 7492e2c405SSimon Horman u8 len; 7592e2c405SSimon Horman __be16 dst_opt_type; 7692e2c405SSimon Horman }; 7792e2c405SSimon Horman 781fdd512cSTom Herbert struct flow_dissector_key_keyid { 791fdd512cSTom Herbert __be32 keyid; 801fdd512cSTom Herbert }; 811fdd512cSTom Herbert 82fbff949eSJiri Pirko /** 83c3f83241STom Herbert * struct flow_dissector_key_ipv4_addrs: 84c3f83241STom Herbert * @src: source ip address 85c3f83241STom Herbert * @dst: destination ip address 86fbff949eSJiri Pirko */ 87c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs { 88fbff949eSJiri Pirko /* (src,dst) must be grouped, in the same way than in IP header */ 89fbff949eSJiri Pirko __be32 src; 90fbff949eSJiri Pirko __be32 dst; 91fbff949eSJiri Pirko }; 92fbff949eSJiri Pirko 93fbff949eSJiri Pirko /** 94c3f83241STom Herbert * struct flow_dissector_key_ipv6_addrs: 95c3f83241STom Herbert * @src: source ip address 96c3f83241STom Herbert * @dst: destination ip address 97c3f83241STom Herbert */ 98c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs { 99c3f83241STom Herbert /* (src,dst) must be grouped, in the same way than in IP header */ 100c3f83241STom Herbert struct in6_addr src; 101c3f83241STom Herbert struct in6_addr dst; 102c3f83241STom Herbert }; 103c3f83241STom Herbert 104c3f83241STom Herbert /** 1058d6e79d3SJon Maloy * struct flow_dissector_key_tipc: 1068d6e79d3SJon Maloy * @key: source node address combined with selector 1079f249089STom Herbert */ 1088d6e79d3SJon Maloy struct flow_dissector_key_tipc { 1098d6e79d3SJon Maloy __be32 key; 1109f249089STom Herbert }; 1119f249089STom Herbert 1129f249089STom Herbert /** 113c3f83241STom Herbert * struct flow_dissector_key_addrs: 114c3f83241STom Herbert * @v4addrs: IPv4 addresses 115c3f83241STom Herbert * @v6addrs: IPv6 addresses 116c3f83241STom Herbert */ 117c3f83241STom Herbert struct flow_dissector_key_addrs { 118c3f83241STom Herbert union { 119c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs v4addrs; 120c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs v6addrs; 1218d6e79d3SJon Maloy struct flow_dissector_key_tipc tipckey; 122c3f83241STom Herbert }; 123c3f83241STom Herbert }; 124c3f83241STom Herbert 125c3f83241STom Herbert /** 12655733350SSimon Horman * flow_dissector_key_arp: 12755733350SSimon Horman * @ports: Operation, source and target addresses for an ARP header 12855733350SSimon Horman * for Ethernet hardware addresses and IPv4 protocol addresses 12955733350SSimon Horman * sip: Sender IP address 13055733350SSimon Horman * tip: Target IP address 13155733350SSimon Horman * op: Operation 13255733350SSimon Horman * sha: Sender hardware address 13355733350SSimon Horman * tpa: Target hardware address 13455733350SSimon Horman */ 13555733350SSimon Horman struct flow_dissector_key_arp { 13655733350SSimon Horman __u32 sip; 13755733350SSimon Horman __u32 tip; 13855733350SSimon Horman __u8 op; 13955733350SSimon Horman unsigned char sha[ETH_ALEN]; 14055733350SSimon Horman unsigned char tha[ETH_ALEN]; 14155733350SSimon Horman }; 14255733350SSimon Horman 14355733350SSimon Horman /** 144fbff949eSJiri Pirko * flow_dissector_key_tp_ports: 145fbff949eSJiri Pirko * @ports: port numbers of Transport header 14659346afeSJiri Pirko * src: source port number 14759346afeSJiri Pirko * dst: destination port number 148fbff949eSJiri Pirko */ 149fbff949eSJiri Pirko struct flow_dissector_key_ports { 150fbff949eSJiri Pirko union { 151fbff949eSJiri Pirko __be32 ports; 15259346afeSJiri Pirko struct { 15359346afeSJiri Pirko __be16 src; 15459346afeSJiri Pirko __be16 dst; 15559346afeSJiri Pirko }; 156fbff949eSJiri Pirko }; 157fbff949eSJiri Pirko }; 158fbff949eSJiri Pirko 159972d3876SSimon Horman /** 160972d3876SSimon Horman * flow_dissector_key_icmp: 161972d3876SSimon Horman * type: ICMP type 162972d3876SSimon Horman * code: ICMP code 163*5dec597eSMatteo Croce * id: session identifier 164972d3876SSimon Horman */ 165972d3876SSimon Horman struct flow_dissector_key_icmp { 166972d3876SSimon Horman struct { 167972d3876SSimon Horman u8 type; 168972d3876SSimon Horman u8 code; 169972d3876SSimon Horman }; 170*5dec597eSMatteo Croce u16 id; 171972d3876SSimon Horman }; 172b924933cSJiri Pirko 17367a900ccSJiri Pirko /** 17467a900ccSJiri Pirko * struct flow_dissector_key_eth_addrs: 17567a900ccSJiri Pirko * @src: source Ethernet address 17667a900ccSJiri Pirko * @dst: destination Ethernet address 17767a900ccSJiri Pirko */ 17867a900ccSJiri Pirko struct flow_dissector_key_eth_addrs { 17967a900ccSJiri Pirko /* (dst,src) must be grouped, in the same way than in ETH header */ 18067a900ccSJiri Pirko unsigned char dst[ETH_ALEN]; 18167a900ccSJiri Pirko unsigned char src[ETH_ALEN]; 18267a900ccSJiri Pirko }; 18367a900ccSJiri Pirko 184ac4bb5deSJiri Pirko /** 185ac4bb5deSJiri Pirko * struct flow_dissector_key_tcp: 186ac4bb5deSJiri Pirko * @flags: flags 187ac4bb5deSJiri Pirko */ 188ac4bb5deSJiri Pirko struct flow_dissector_key_tcp { 189ac4bb5deSJiri Pirko __be16 flags; 190ac4bb5deSJiri Pirko }; 191ac4bb5deSJiri Pirko 192518d8a2eSOr Gerlitz /** 193518d8a2eSOr Gerlitz * struct flow_dissector_key_ip: 194518d8a2eSOr Gerlitz * @tos: tos 195518d8a2eSOr Gerlitz * @ttl: ttl 196518d8a2eSOr Gerlitz */ 197518d8a2eSOr Gerlitz struct flow_dissector_key_ip { 198518d8a2eSOr Gerlitz __u8 tos; 199518d8a2eSOr Gerlitz __u8 ttl; 200518d8a2eSOr Gerlitz }; 201518d8a2eSOr Gerlitz 20282828b88SJiri Pirko /** 20382828b88SJiri Pirko * struct flow_dissector_key_meta: 20482828b88SJiri Pirko * @ingress_ifindex: ingress ifindex 20582828b88SJiri Pirko */ 20682828b88SJiri Pirko struct flow_dissector_key_meta { 20782828b88SJiri Pirko int ingress_ifindex; 20882828b88SJiri Pirko }; 20982828b88SJiri Pirko 21075a56758SPaul Blakey /** 21175a56758SPaul Blakey * struct flow_dissector_key_ct: 21275a56758SPaul Blakey * @ct_state: conntrack state after converting with map 21375a56758SPaul Blakey * @ct_mark: conttrack mark 21475a56758SPaul Blakey * @ct_zone: conntrack zone 21575a56758SPaul Blakey * @ct_labels: conntrack labels 21675a56758SPaul Blakey */ 21775a56758SPaul Blakey struct flow_dissector_key_ct { 21875a56758SPaul Blakey u16 ct_state; 21975a56758SPaul Blakey u16 ct_zone; 22075a56758SPaul Blakey u32 ct_mark; 22175a56758SPaul Blakey u32 ct_labels[4]; 22275a56758SPaul Blakey }; 22375a56758SPaul Blakey 224fbff949eSJiri Pirko enum flow_dissector_key_id { 22542aecaa9STom Herbert FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */ 226fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */ 227c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 228c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 229fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */ 230972d3876SSimon Horman FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */ 23167a900ccSJiri Pirko FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */ 2328d6e79d3SJon Maloy FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */ 23355733350SSimon Horman FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */ 23491c45956SEdward Cree FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_vlan */ 23591c45956SEdward Cree FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_tags */ 2361fdd512cSTom Herbert FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */ 237b3baa0fbSTom Herbert FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */ 2389ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */ 2399ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 2409ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 2419ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */ 242f4d997fdSHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */ 243029c1ecbSBenjamin LaHaise FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */ 244ac4bb5deSJiri Pirko FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */ 245518d8a2eSOr Gerlitz FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */ 24691c45956SEdward Cree FLOW_DISSECTOR_KEY_CVLAN, /* struct flow_dissector_key_vlan */ 2475544adb9SOr Gerlitz FLOW_DISSECTOR_KEY_ENC_IP, /* struct flow_dissector_key_ip */ 24892e2c405SSimon Horman FLOW_DISSECTOR_KEY_ENC_OPTS, /* struct flow_dissector_key_enc_opts */ 24982828b88SJiri Pirko FLOW_DISSECTOR_KEY_META, /* struct flow_dissector_key_meta */ 25075a56758SPaul Blakey FLOW_DISSECTOR_KEY_CT, /* struct flow_dissector_key_ct */ 25192e2c405SSimon Horman 252fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_MAX, 253fbff949eSJiri Pirko }; 254fbff949eSJiri Pirko 255807e165dSTom Herbert #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0) 2561cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(1) 2571cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(2) 258807e165dSTom Herbert 259fbff949eSJiri Pirko struct flow_dissector_key { 260fbff949eSJiri Pirko enum flow_dissector_key_id key_id; 261fbff949eSJiri Pirko size_t offset; /* offset of struct flow_dissector_key_* 262fbff949eSJiri Pirko in target the struct */ 263fbff949eSJiri Pirko }; 264fbff949eSJiri Pirko 265fbff949eSJiri Pirko struct flow_dissector { 266fbff949eSJiri Pirko unsigned int used_keys; /* each bit repesents presence of one key id */ 267fbff949eSJiri Pirko unsigned short int offset[FLOW_DISSECTOR_KEY_MAX]; 268fbff949eSJiri Pirko }; 269fbff949eSJiri Pirko 27072a338bcSPaolo Abeni struct flow_keys_basic { 27172a338bcSPaolo Abeni struct flow_dissector_key_control control; 27272a338bcSPaolo Abeni struct flow_dissector_key_basic basic; 27372a338bcSPaolo Abeni }; 27472a338bcSPaolo Abeni 27506635a35SJiri Pirko struct flow_keys { 27642aecaa9STom Herbert struct flow_dissector_key_control control; 27742aecaa9STom Herbert #define FLOW_KEYS_HASH_START_FIELD basic 27806635a35SJiri Pirko struct flow_dissector_key_basic basic; 279d34af823STom Herbert struct flow_dissector_key_tags tags; 280f6a66927SHadar Hen Zion struct flow_dissector_key_vlan vlan; 28124c590e3SJianbo Liu struct flow_dissector_key_vlan cvlan; 2821fdd512cSTom Herbert struct flow_dissector_key_keyid keyid; 28342aecaa9STom Herbert struct flow_dissector_key_ports ports; 284*5dec597eSMatteo Croce struct flow_dissector_key_icmp icmp; 28598298e6cSMatteo Croce /* 'addrs' must be the last member */ 28642aecaa9STom Herbert struct flow_dissector_key_addrs addrs; 28706635a35SJiri Pirko }; 28806635a35SJiri Pirko 28942aecaa9STom Herbert #define FLOW_KEYS_HASH_OFFSET \ 29042aecaa9STom Herbert offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD) 29142aecaa9STom Herbert 292c3f83241STom Herbert __be32 flow_get_u32_src(const struct flow_keys *flow); 293c3f83241STom Herbert __be32 flow_get_u32_dst(const struct flow_keys *flow); 294c3f83241STom Herbert 29506635a35SJiri Pirko extern struct flow_dissector flow_keys_dissector; 29672a338bcSPaolo Abeni extern struct flow_dissector flow_keys_basic_dissector; 29706635a35SJiri Pirko 2981bd758ebSJiri Pirko /* struct flow_keys_digest: 2991bd758ebSJiri Pirko * 3001bd758ebSJiri Pirko * This structure is used to hold a digest of the full flow keys. This is a 3011bd758ebSJiri Pirko * larger "hash" of a flow to allow definitively matching specific flows where 3021bd758ebSJiri Pirko * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so 30353bc017fSWolfram Sang * that it can be used in CB of skb (see sch_choke for an example). 3041bd758ebSJiri Pirko */ 3051bd758ebSJiri Pirko #define FLOW_KEYS_DIGEST_LEN 16 3061bd758ebSJiri Pirko struct flow_keys_digest { 3071bd758ebSJiri Pirko u8 data[FLOW_KEYS_DIGEST_LEN]; 3081bd758ebSJiri Pirko }; 3091bd758ebSJiri Pirko 3101bd758ebSJiri Pirko void make_flow_keys_digest(struct flow_keys_digest *digest, 3111bd758ebSJiri Pirko const struct flow_keys *flow); 3121bd758ebSJiri Pirko 31366fdd05eSGao Feng static inline bool flow_keys_have_l4(const struct flow_keys *keys) 314bcc83839STom Herbert { 315bcc83839STom Herbert return (keys->ports.ports || keys->tags.flow_label); 316bcc83839STom Herbert } 317bcc83839STom Herbert 318c6cc1ca7STom Herbert u32 flow_hash_from_keys(struct flow_keys *keys); 319*5dec597eSMatteo Croce void skb_flow_get_icmp_tci(const struct sk_buff *skb, 320*5dec597eSMatteo Croce struct flow_dissector_key_icmp *key_icmp, 321*5dec597eSMatteo Croce void *data, int thoff, int hlen); 322c6cc1ca7STom Herbert 3238de2d793SAmir Vadai static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector, 3248de2d793SAmir Vadai enum flow_dissector_key_id key_id) 3258de2d793SAmir Vadai { 3268de2d793SAmir Vadai return flow_dissector->used_keys & (1 << key_id); 3278de2d793SAmir Vadai } 3288de2d793SAmir Vadai 3298de2d793SAmir Vadai static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector, 3308de2d793SAmir Vadai enum flow_dissector_key_id key_id, 3318de2d793SAmir Vadai void *target_container) 3328de2d793SAmir Vadai { 3338de2d793SAmir Vadai return ((char *)target_container) + flow_dissector->offset[key_id]; 3348de2d793SAmir Vadai } 3358de2d793SAmir Vadai 336089b19a9SStanislav Fomichev struct bpf_flow_dissector { 337089b19a9SStanislav Fomichev struct bpf_flow_keys *flow_keys; 338089b19a9SStanislav Fomichev const struct sk_buff *skb; 339089b19a9SStanislav Fomichev void *data; 340089b19a9SStanislav Fomichev void *data_end; 341089b19a9SStanislav Fomichev }; 342089b19a9SStanislav Fomichev 3431bd758ebSJiri Pirko #endif 344