1b2441318SGreg Kroah-Hartman /* SPDX-License-Identifier: GPL-2.0 */ 21bd758ebSJiri Pirko #ifndef _NET_FLOW_DISSECTOR_H 31bd758ebSJiri Pirko #define _NET_FLOW_DISSECTOR_H 41bd758ebSJiri Pirko 5c3f8eaebSJiri Pirko #include <linux/types.h> 6b924933cSJiri Pirko #include <linux/in6.h> 755667441SEric Dumazet #include <linux/siphash.h> 867a900ccSJiri Pirko #include <uapi/linux/if_ether.h> 9c3f8eaebSJiri Pirko 105dec597eSMatteo Croce struct sk_buff; 115dec597eSMatteo Croce 12fbff949eSJiri Pirko /** 1342aecaa9STom Herbert * struct flow_dissector_key_control: 1442aecaa9STom Herbert * @thoff: Transport header offset 1542aecaa9STom Herbert */ 1642aecaa9STom Herbert struct flow_dissector_key_control { 1742aecaa9STom Herbert u16 thoff; 18c3f83241STom Herbert u16 addr_type; 194b36993dSDavid S. Miller u32 flags; 2042aecaa9STom Herbert }; 2142aecaa9STom Herbert 224b36993dSDavid S. Miller #define FLOW_DIS_IS_FRAGMENT BIT(0) 234b36993dSDavid S. Miller #define FLOW_DIS_FIRST_FRAG BIT(1) 244b36993dSDavid S. Miller #define FLOW_DIS_ENCAPSULATION BIT(2) 254b36993dSDavid S. Miller 263a1214e8STom Herbert enum flow_dissect_ret { 273a1214e8STom Herbert FLOW_DISSECT_RET_OUT_GOOD, 283a1214e8STom Herbert FLOW_DISSECT_RET_OUT_BAD, 293a1214e8STom Herbert FLOW_DISSECT_RET_PROTO_AGAIN, 303a1214e8STom Herbert FLOW_DISSECT_RET_IPPROTO_AGAIN, 313a1214e8STom Herbert FLOW_DISSECT_RET_CONTINUE, 323a1214e8STom Herbert }; 333a1214e8STom Herbert 3442aecaa9STom Herbert /** 35fbff949eSJiri Pirko * struct flow_dissector_key_basic: 36fbff949eSJiri Pirko * @thoff: Transport header offset 37fbff949eSJiri Pirko * @n_proto: Network header protocol (eg. IPv4/IPv6) 38fbff949eSJiri Pirko * @ip_proto: Transport header protocol (eg. TCP/UDP) 39fbff949eSJiri Pirko */ 40fbff949eSJiri Pirko struct flow_dissector_key_basic { 41fbff949eSJiri Pirko __be16 n_proto; 42fbff949eSJiri Pirko u8 ip_proto; 4342aecaa9STom Herbert u8 padding; 44fbff949eSJiri Pirko }; 45fbff949eSJiri Pirko 46d34af823STom Herbert struct flow_dissector_key_tags { 47f6a66927SHadar Hen Zion u32 flow_label; 48f6a66927SHadar Hen Zion }; 49f6a66927SHadar Hen Zion 50f6a66927SHadar Hen Zion struct flow_dissector_key_vlan { 51*a82055afSPablo Neira Ayuso union { 52f6a66927SHadar Hen Zion u16 vlan_id:12, 53f0d2ca15SMaxime Chevallier vlan_dei:1, 54f6a66927SHadar Hen Zion vlan_priority:3; 55*a82055afSPablo Neira Ayuso __be16 vlan_tci; 56*a82055afSPablo Neira Ayuso }; 572064c3d4SJianbo Liu __be16 vlan_tpid; 58d34af823STom Herbert }; 59d34af823STom Herbert 60029c1ecbSBenjamin LaHaise struct flow_dissector_key_mpls { 61029c1ecbSBenjamin LaHaise u32 mpls_ttl:8, 62029c1ecbSBenjamin LaHaise mpls_bos:1, 63029c1ecbSBenjamin LaHaise mpls_tc:3, 64029c1ecbSBenjamin LaHaise mpls_label:20; 65029c1ecbSBenjamin LaHaise }; 66029c1ecbSBenjamin LaHaise 6792e2c405SSimon Horman #define FLOW_DIS_TUN_OPTS_MAX 255 6892e2c405SSimon Horman /** 6992e2c405SSimon Horman * struct flow_dissector_key_enc_opts: 7092e2c405SSimon Horman * @data: tunnel option data 7192e2c405SSimon Horman * @len: length of tunnel option data 7292e2c405SSimon Horman * @dst_opt_type: tunnel option type 7392e2c405SSimon Horman */ 7492e2c405SSimon Horman struct flow_dissector_key_enc_opts { 7592e2c405SSimon Horman u8 data[FLOW_DIS_TUN_OPTS_MAX]; /* Using IP_TUNNEL_OPTS_MAX is desired 7692e2c405SSimon Horman * here but seems difficult to #include 7792e2c405SSimon Horman */ 7892e2c405SSimon Horman u8 len; 7992e2c405SSimon Horman __be16 dst_opt_type; 8092e2c405SSimon Horman }; 8192e2c405SSimon Horman 821fdd512cSTom Herbert struct flow_dissector_key_keyid { 831fdd512cSTom Herbert __be32 keyid; 841fdd512cSTom Herbert }; 851fdd512cSTom Herbert 86fbff949eSJiri Pirko /** 87c3f83241STom Herbert * struct flow_dissector_key_ipv4_addrs: 88c3f83241STom Herbert * @src: source ip address 89c3f83241STom Herbert * @dst: destination ip address 90fbff949eSJiri Pirko */ 91c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs { 92fbff949eSJiri Pirko /* (src,dst) must be grouped, in the same way than in IP header */ 93fbff949eSJiri Pirko __be32 src; 94fbff949eSJiri Pirko __be32 dst; 95fbff949eSJiri Pirko }; 96fbff949eSJiri Pirko 97fbff949eSJiri Pirko /** 98c3f83241STom Herbert * struct flow_dissector_key_ipv6_addrs: 99c3f83241STom Herbert * @src: source ip address 100c3f83241STom Herbert * @dst: destination ip address 101c3f83241STom Herbert */ 102c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs { 103c3f83241STom Herbert /* (src,dst) must be grouped, in the same way than in IP header */ 104c3f83241STom Herbert struct in6_addr src; 105c3f83241STom Herbert struct in6_addr dst; 106c3f83241STom Herbert }; 107c3f83241STom Herbert 108c3f83241STom Herbert /** 1098d6e79d3SJon Maloy * struct flow_dissector_key_tipc: 1108d6e79d3SJon Maloy * @key: source node address combined with selector 1119f249089STom Herbert */ 1128d6e79d3SJon Maloy struct flow_dissector_key_tipc { 1138d6e79d3SJon Maloy __be32 key; 1149f249089STom Herbert }; 1159f249089STom Herbert 1169f249089STom Herbert /** 117c3f83241STom Herbert * struct flow_dissector_key_addrs: 118c3f83241STom Herbert * @v4addrs: IPv4 addresses 119c3f83241STom Herbert * @v6addrs: IPv6 addresses 120c3f83241STom Herbert */ 121c3f83241STom Herbert struct flow_dissector_key_addrs { 122c3f83241STom Herbert union { 123c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs v4addrs; 124c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs v6addrs; 1258d6e79d3SJon Maloy struct flow_dissector_key_tipc tipckey; 126c3f83241STom Herbert }; 127c3f83241STom Herbert }; 128c3f83241STom Herbert 129c3f83241STom Herbert /** 13055733350SSimon Horman * flow_dissector_key_arp: 13155733350SSimon Horman * @ports: Operation, source and target addresses for an ARP header 13255733350SSimon Horman * for Ethernet hardware addresses and IPv4 protocol addresses 13355733350SSimon Horman * sip: Sender IP address 13455733350SSimon Horman * tip: Target IP address 13555733350SSimon Horman * op: Operation 13655733350SSimon Horman * sha: Sender hardware address 13755733350SSimon Horman * tpa: Target hardware address 13855733350SSimon Horman */ 13955733350SSimon Horman struct flow_dissector_key_arp { 14055733350SSimon Horman __u32 sip; 14155733350SSimon Horman __u32 tip; 14255733350SSimon Horman __u8 op; 14355733350SSimon Horman unsigned char sha[ETH_ALEN]; 14455733350SSimon Horman unsigned char tha[ETH_ALEN]; 14555733350SSimon Horman }; 14655733350SSimon Horman 14755733350SSimon Horman /** 148fbff949eSJiri Pirko * flow_dissector_key_tp_ports: 149fbff949eSJiri Pirko * @ports: port numbers of Transport header 15059346afeSJiri Pirko * src: source port number 15159346afeSJiri Pirko * dst: destination port number 152fbff949eSJiri Pirko */ 153fbff949eSJiri Pirko struct flow_dissector_key_ports { 154fbff949eSJiri Pirko union { 155fbff949eSJiri Pirko __be32 ports; 15659346afeSJiri Pirko struct { 15759346afeSJiri Pirko __be16 src; 15859346afeSJiri Pirko __be16 dst; 15959346afeSJiri Pirko }; 160fbff949eSJiri Pirko }; 161fbff949eSJiri Pirko }; 162fbff949eSJiri Pirko 163972d3876SSimon Horman /** 164972d3876SSimon Horman * flow_dissector_key_icmp: 165972d3876SSimon Horman * type: ICMP type 166972d3876SSimon Horman * code: ICMP code 1675dec597eSMatteo Croce * id: session identifier 168972d3876SSimon Horman */ 169972d3876SSimon Horman struct flow_dissector_key_icmp { 170972d3876SSimon Horman struct { 171972d3876SSimon Horman u8 type; 172972d3876SSimon Horman u8 code; 173972d3876SSimon Horman }; 1745dec597eSMatteo Croce u16 id; 175972d3876SSimon Horman }; 176b924933cSJiri Pirko 17767a900ccSJiri Pirko /** 17867a900ccSJiri Pirko * struct flow_dissector_key_eth_addrs: 17967a900ccSJiri Pirko * @src: source Ethernet address 18067a900ccSJiri Pirko * @dst: destination Ethernet address 18167a900ccSJiri Pirko */ 18267a900ccSJiri Pirko struct flow_dissector_key_eth_addrs { 18367a900ccSJiri Pirko /* (dst,src) must be grouped, in the same way than in ETH header */ 18467a900ccSJiri Pirko unsigned char dst[ETH_ALEN]; 18567a900ccSJiri Pirko unsigned char src[ETH_ALEN]; 18667a900ccSJiri Pirko }; 18767a900ccSJiri Pirko 188ac4bb5deSJiri Pirko /** 189ac4bb5deSJiri Pirko * struct flow_dissector_key_tcp: 190ac4bb5deSJiri Pirko * @flags: flags 191ac4bb5deSJiri Pirko */ 192ac4bb5deSJiri Pirko struct flow_dissector_key_tcp { 193ac4bb5deSJiri Pirko __be16 flags; 194ac4bb5deSJiri Pirko }; 195ac4bb5deSJiri Pirko 196518d8a2eSOr Gerlitz /** 197518d8a2eSOr Gerlitz * struct flow_dissector_key_ip: 198518d8a2eSOr Gerlitz * @tos: tos 199518d8a2eSOr Gerlitz * @ttl: ttl 200518d8a2eSOr Gerlitz */ 201518d8a2eSOr Gerlitz struct flow_dissector_key_ip { 202518d8a2eSOr Gerlitz __u8 tos; 203518d8a2eSOr Gerlitz __u8 ttl; 204518d8a2eSOr Gerlitz }; 205518d8a2eSOr Gerlitz 20682828b88SJiri Pirko /** 20782828b88SJiri Pirko * struct flow_dissector_key_meta: 20882828b88SJiri Pirko * @ingress_ifindex: ingress ifindex 2098819efc9SPablo Neira Ayuso * @ingress_iftype: ingress interface type 21082828b88SJiri Pirko */ 21182828b88SJiri Pirko struct flow_dissector_key_meta { 21282828b88SJiri Pirko int ingress_ifindex; 2138819efc9SPablo Neira Ayuso u16 ingress_iftype; 21482828b88SJiri Pirko }; 21582828b88SJiri Pirko 21675a56758SPaul Blakey /** 21775a56758SPaul Blakey * struct flow_dissector_key_ct: 21875a56758SPaul Blakey * @ct_state: conntrack state after converting with map 21975a56758SPaul Blakey * @ct_mark: conttrack mark 22075a56758SPaul Blakey * @ct_zone: conntrack zone 22175a56758SPaul Blakey * @ct_labels: conntrack labels 22275a56758SPaul Blakey */ 22375a56758SPaul Blakey struct flow_dissector_key_ct { 22475a56758SPaul Blakey u16 ct_state; 22575a56758SPaul Blakey u16 ct_zone; 22675a56758SPaul Blakey u32 ct_mark; 22775a56758SPaul Blakey u32 ct_labels[4]; 22875a56758SPaul Blakey }; 22975a56758SPaul Blakey 230fbff949eSJiri Pirko enum flow_dissector_key_id { 23142aecaa9STom Herbert FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */ 232fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */ 233c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 234c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 235fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */ 236972d3876SSimon Horman FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */ 23767a900ccSJiri Pirko FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */ 2388d6e79d3SJon Maloy FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */ 23955733350SSimon Horman FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */ 24091c45956SEdward Cree FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_vlan */ 24191c45956SEdward Cree FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_tags */ 2421fdd512cSTom Herbert FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */ 243b3baa0fbSTom Herbert FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */ 2449ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */ 2459ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 2469ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 2479ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */ 248f4d997fdSHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */ 249029c1ecbSBenjamin LaHaise FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */ 250ac4bb5deSJiri Pirko FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */ 251518d8a2eSOr Gerlitz FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */ 25291c45956SEdward Cree FLOW_DISSECTOR_KEY_CVLAN, /* struct flow_dissector_key_vlan */ 2535544adb9SOr Gerlitz FLOW_DISSECTOR_KEY_ENC_IP, /* struct flow_dissector_key_ip */ 25492e2c405SSimon Horman FLOW_DISSECTOR_KEY_ENC_OPTS, /* struct flow_dissector_key_enc_opts */ 25582828b88SJiri Pirko FLOW_DISSECTOR_KEY_META, /* struct flow_dissector_key_meta */ 25675a56758SPaul Blakey FLOW_DISSECTOR_KEY_CT, /* struct flow_dissector_key_ct */ 25792e2c405SSimon Horman 258fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_MAX, 259fbff949eSJiri Pirko }; 260fbff949eSJiri Pirko 261807e165dSTom Herbert #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0) 2621cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(1) 2631cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(2) 264807e165dSTom Herbert 265fbff949eSJiri Pirko struct flow_dissector_key { 266fbff949eSJiri Pirko enum flow_dissector_key_id key_id; 267fbff949eSJiri Pirko size_t offset; /* offset of struct flow_dissector_key_* 268fbff949eSJiri Pirko in target the struct */ 269fbff949eSJiri Pirko }; 270fbff949eSJiri Pirko 271fbff949eSJiri Pirko struct flow_dissector { 272fbff949eSJiri Pirko unsigned int used_keys; /* each bit repesents presence of one key id */ 273fbff949eSJiri Pirko unsigned short int offset[FLOW_DISSECTOR_KEY_MAX]; 274fbff949eSJiri Pirko }; 275fbff949eSJiri Pirko 27672a338bcSPaolo Abeni struct flow_keys_basic { 27772a338bcSPaolo Abeni struct flow_dissector_key_control control; 27872a338bcSPaolo Abeni struct flow_dissector_key_basic basic; 27972a338bcSPaolo Abeni }; 28072a338bcSPaolo Abeni 28106635a35SJiri Pirko struct flow_keys { 28242aecaa9STom Herbert struct flow_dissector_key_control control; 28342aecaa9STom Herbert #define FLOW_KEYS_HASH_START_FIELD basic 28455667441SEric Dumazet struct flow_dissector_key_basic basic __aligned(SIPHASH_ALIGNMENT); 285d34af823STom Herbert struct flow_dissector_key_tags tags; 286f6a66927SHadar Hen Zion struct flow_dissector_key_vlan vlan; 28724c590e3SJianbo Liu struct flow_dissector_key_vlan cvlan; 2881fdd512cSTom Herbert struct flow_dissector_key_keyid keyid; 28942aecaa9STom Herbert struct flow_dissector_key_ports ports; 2905dec597eSMatteo Croce struct flow_dissector_key_icmp icmp; 29198298e6cSMatteo Croce /* 'addrs' must be the last member */ 29242aecaa9STom Herbert struct flow_dissector_key_addrs addrs; 29306635a35SJiri Pirko }; 29406635a35SJiri Pirko 29542aecaa9STom Herbert #define FLOW_KEYS_HASH_OFFSET \ 29642aecaa9STom Herbert offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD) 29742aecaa9STom Herbert 298c3f83241STom Herbert __be32 flow_get_u32_src(const struct flow_keys *flow); 299c3f83241STom Herbert __be32 flow_get_u32_dst(const struct flow_keys *flow); 300c3f83241STom Herbert 30106635a35SJiri Pirko extern struct flow_dissector flow_keys_dissector; 30272a338bcSPaolo Abeni extern struct flow_dissector flow_keys_basic_dissector; 30306635a35SJiri Pirko 3041bd758ebSJiri Pirko /* struct flow_keys_digest: 3051bd758ebSJiri Pirko * 3061bd758ebSJiri Pirko * This structure is used to hold a digest of the full flow keys. This is a 3071bd758ebSJiri Pirko * larger "hash" of a flow to allow definitively matching specific flows where 3081bd758ebSJiri Pirko * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so 30953bc017fSWolfram Sang * that it can be used in CB of skb (see sch_choke for an example). 3101bd758ebSJiri Pirko */ 3111bd758ebSJiri Pirko #define FLOW_KEYS_DIGEST_LEN 16 3121bd758ebSJiri Pirko struct flow_keys_digest { 3131bd758ebSJiri Pirko u8 data[FLOW_KEYS_DIGEST_LEN]; 3141bd758ebSJiri Pirko }; 3151bd758ebSJiri Pirko 3161bd758ebSJiri Pirko void make_flow_keys_digest(struct flow_keys_digest *digest, 3171bd758ebSJiri Pirko const struct flow_keys *flow); 3181bd758ebSJiri Pirko 31966fdd05eSGao Feng static inline bool flow_keys_have_l4(const struct flow_keys *keys) 320bcc83839STom Herbert { 321bcc83839STom Herbert return (keys->ports.ports || keys->tags.flow_label); 322bcc83839STom Herbert } 323bcc83839STom Herbert 324c6cc1ca7STom Herbert u32 flow_hash_from_keys(struct flow_keys *keys); 3255dec597eSMatteo Croce void skb_flow_get_icmp_tci(const struct sk_buff *skb, 3265dec597eSMatteo Croce struct flow_dissector_key_icmp *key_icmp, 3275dec597eSMatteo Croce void *data, int thoff, int hlen); 328c6cc1ca7STom Herbert 3298de2d793SAmir Vadai static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector, 3308de2d793SAmir Vadai enum flow_dissector_key_id key_id) 3318de2d793SAmir Vadai { 3328de2d793SAmir Vadai return flow_dissector->used_keys & (1 << key_id); 3338de2d793SAmir Vadai } 3348de2d793SAmir Vadai 3358de2d793SAmir Vadai static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector, 3368de2d793SAmir Vadai enum flow_dissector_key_id key_id, 3378de2d793SAmir Vadai void *target_container) 3388de2d793SAmir Vadai { 3398de2d793SAmir Vadai return ((char *)target_container) + flow_dissector->offset[key_id]; 3408de2d793SAmir Vadai } 3418de2d793SAmir Vadai 342089b19a9SStanislav Fomichev struct bpf_flow_dissector { 343089b19a9SStanislav Fomichev struct bpf_flow_keys *flow_keys; 344089b19a9SStanislav Fomichev const struct sk_buff *skb; 345089b19a9SStanislav Fomichev void *data; 346089b19a9SStanislav Fomichev void *data_end; 347089b19a9SStanislav Fomichev }; 348089b19a9SStanislav Fomichev 3491bd758ebSJiri Pirko #endif 350