1b2441318SGreg Kroah-Hartman /* SPDX-License-Identifier: GPL-2.0 */ 21bd758ebSJiri Pirko #ifndef _NET_FLOW_DISSECTOR_H 31bd758ebSJiri Pirko #define _NET_FLOW_DISSECTOR_H 41bd758ebSJiri Pirko 5c3f8eaebSJiri Pirko #include <linux/types.h> 6b924933cSJiri Pirko #include <linux/in6.h> 755667441SEric Dumazet #include <linux/siphash.h> 867a900ccSJiri Pirko #include <uapi/linux/if_ether.h> 9c3f8eaebSJiri Pirko 105dec597eSMatteo Croce struct sk_buff; 115dec597eSMatteo Croce 12fbff949eSJiri Pirko /** 1342aecaa9STom Herbert * struct flow_dissector_key_control: 1442aecaa9STom Herbert * @thoff: Transport header offset 1542aecaa9STom Herbert */ 1642aecaa9STom Herbert struct flow_dissector_key_control { 1742aecaa9STom Herbert u16 thoff; 18c3f83241STom Herbert u16 addr_type; 194b36993dSDavid S. Miller u32 flags; 2042aecaa9STom Herbert }; 2142aecaa9STom Herbert 224b36993dSDavid S. Miller #define FLOW_DIS_IS_FRAGMENT BIT(0) 234b36993dSDavid S. Miller #define FLOW_DIS_FIRST_FRAG BIT(1) 244b36993dSDavid S. Miller #define FLOW_DIS_ENCAPSULATION BIT(2) 254b36993dSDavid S. Miller 263a1214e8STom Herbert enum flow_dissect_ret { 273a1214e8STom Herbert FLOW_DISSECT_RET_OUT_GOOD, 283a1214e8STom Herbert FLOW_DISSECT_RET_OUT_BAD, 293a1214e8STom Herbert FLOW_DISSECT_RET_PROTO_AGAIN, 303a1214e8STom Herbert FLOW_DISSECT_RET_IPPROTO_AGAIN, 313a1214e8STom Herbert FLOW_DISSECT_RET_CONTINUE, 323a1214e8STom Herbert }; 333a1214e8STom Herbert 3442aecaa9STom Herbert /** 35fbff949eSJiri Pirko * struct flow_dissector_key_basic: 36fbff949eSJiri Pirko * @thoff: Transport header offset 37fbff949eSJiri Pirko * @n_proto: Network header protocol (eg. IPv4/IPv6) 38fbff949eSJiri Pirko * @ip_proto: Transport header protocol (eg. TCP/UDP) 39fbff949eSJiri Pirko */ 40fbff949eSJiri Pirko struct flow_dissector_key_basic { 41fbff949eSJiri Pirko __be16 n_proto; 42fbff949eSJiri Pirko u8 ip_proto; 4342aecaa9STom Herbert u8 padding; 44fbff949eSJiri Pirko }; 45fbff949eSJiri Pirko 46d34af823STom Herbert struct flow_dissector_key_tags { 47f6a66927SHadar Hen Zion u32 flow_label; 48f6a66927SHadar Hen Zion }; 49f6a66927SHadar Hen Zion 50f6a66927SHadar Hen Zion struct flow_dissector_key_vlan { 51a82055afSPablo Neira Ayuso union { 52*d1746d1eSPetr Machata struct { 53f6a66927SHadar Hen Zion u16 vlan_id:12, 54f0d2ca15SMaxime Chevallier vlan_dei:1, 55f6a66927SHadar Hen Zion vlan_priority:3; 56*d1746d1eSPetr Machata }; 57a82055afSPablo Neira Ayuso __be16 vlan_tci; 58a82055afSPablo Neira Ayuso }; 592064c3d4SJianbo Liu __be16 vlan_tpid; 60d34af823STom Herbert }; 61d34af823STom Herbert 62029c1ecbSBenjamin LaHaise struct flow_dissector_key_mpls { 63029c1ecbSBenjamin LaHaise u32 mpls_ttl:8, 64029c1ecbSBenjamin LaHaise mpls_bos:1, 65029c1ecbSBenjamin LaHaise mpls_tc:3, 66029c1ecbSBenjamin LaHaise mpls_label:20; 67029c1ecbSBenjamin LaHaise }; 68029c1ecbSBenjamin LaHaise 6992e2c405SSimon Horman #define FLOW_DIS_TUN_OPTS_MAX 255 7092e2c405SSimon Horman /** 7192e2c405SSimon Horman * struct flow_dissector_key_enc_opts: 7292e2c405SSimon Horman * @data: tunnel option data 7392e2c405SSimon Horman * @len: length of tunnel option data 7492e2c405SSimon Horman * @dst_opt_type: tunnel option type 7592e2c405SSimon Horman */ 7692e2c405SSimon Horman struct flow_dissector_key_enc_opts { 7792e2c405SSimon Horman u8 data[FLOW_DIS_TUN_OPTS_MAX]; /* Using IP_TUNNEL_OPTS_MAX is desired 7892e2c405SSimon Horman * here but seems difficult to #include 7992e2c405SSimon Horman */ 8092e2c405SSimon Horman u8 len; 8192e2c405SSimon Horman __be16 dst_opt_type; 8292e2c405SSimon Horman }; 8392e2c405SSimon Horman 841fdd512cSTom Herbert struct flow_dissector_key_keyid { 851fdd512cSTom Herbert __be32 keyid; 861fdd512cSTom Herbert }; 871fdd512cSTom Herbert 88fbff949eSJiri Pirko /** 89c3f83241STom Herbert * struct flow_dissector_key_ipv4_addrs: 90c3f83241STom Herbert * @src: source ip address 91c3f83241STom Herbert * @dst: destination ip address 92fbff949eSJiri Pirko */ 93c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs { 94fbff949eSJiri Pirko /* (src,dst) must be grouped, in the same way than in IP header */ 95fbff949eSJiri Pirko __be32 src; 96fbff949eSJiri Pirko __be32 dst; 97fbff949eSJiri Pirko }; 98fbff949eSJiri Pirko 99fbff949eSJiri Pirko /** 100c3f83241STom Herbert * struct flow_dissector_key_ipv6_addrs: 101c3f83241STom Herbert * @src: source ip address 102c3f83241STom Herbert * @dst: destination ip address 103c3f83241STom Herbert */ 104c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs { 105c3f83241STom Herbert /* (src,dst) must be grouped, in the same way than in IP header */ 106c3f83241STom Herbert struct in6_addr src; 107c3f83241STom Herbert struct in6_addr dst; 108c3f83241STom Herbert }; 109c3f83241STom Herbert 110c3f83241STom Herbert /** 1118d6e79d3SJon Maloy * struct flow_dissector_key_tipc: 1128d6e79d3SJon Maloy * @key: source node address combined with selector 1139f249089STom Herbert */ 1148d6e79d3SJon Maloy struct flow_dissector_key_tipc { 1158d6e79d3SJon Maloy __be32 key; 1169f249089STom Herbert }; 1179f249089STom Herbert 1189f249089STom Herbert /** 119c3f83241STom Herbert * struct flow_dissector_key_addrs: 120c3f83241STom Herbert * @v4addrs: IPv4 addresses 121c3f83241STom Herbert * @v6addrs: IPv6 addresses 122c3f83241STom Herbert */ 123c3f83241STom Herbert struct flow_dissector_key_addrs { 124c3f83241STom Herbert union { 125c3f83241STom Herbert struct flow_dissector_key_ipv4_addrs v4addrs; 126c3f83241STom Herbert struct flow_dissector_key_ipv6_addrs v6addrs; 1278d6e79d3SJon Maloy struct flow_dissector_key_tipc tipckey; 128c3f83241STom Herbert }; 129c3f83241STom Herbert }; 130c3f83241STom Herbert 131c3f83241STom Herbert /** 13255733350SSimon Horman * flow_dissector_key_arp: 13355733350SSimon Horman * @ports: Operation, source and target addresses for an ARP header 13455733350SSimon Horman * for Ethernet hardware addresses and IPv4 protocol addresses 13555733350SSimon Horman * sip: Sender IP address 13655733350SSimon Horman * tip: Target IP address 13755733350SSimon Horman * op: Operation 13855733350SSimon Horman * sha: Sender hardware address 13955733350SSimon Horman * tpa: Target hardware address 14055733350SSimon Horman */ 14155733350SSimon Horman struct flow_dissector_key_arp { 14255733350SSimon Horman __u32 sip; 14355733350SSimon Horman __u32 tip; 14455733350SSimon Horman __u8 op; 14555733350SSimon Horman unsigned char sha[ETH_ALEN]; 14655733350SSimon Horman unsigned char tha[ETH_ALEN]; 14755733350SSimon Horman }; 14855733350SSimon Horman 14955733350SSimon Horman /** 150fbff949eSJiri Pirko * flow_dissector_key_tp_ports: 151fbff949eSJiri Pirko * @ports: port numbers of Transport header 15259346afeSJiri Pirko * src: source port number 15359346afeSJiri Pirko * dst: destination port number 154fbff949eSJiri Pirko */ 155fbff949eSJiri Pirko struct flow_dissector_key_ports { 156fbff949eSJiri Pirko union { 157fbff949eSJiri Pirko __be32 ports; 15859346afeSJiri Pirko struct { 15959346afeSJiri Pirko __be16 src; 16059346afeSJiri Pirko __be16 dst; 16159346afeSJiri Pirko }; 162fbff949eSJiri Pirko }; 163fbff949eSJiri Pirko }; 164fbff949eSJiri Pirko 165972d3876SSimon Horman /** 166972d3876SSimon Horman * flow_dissector_key_icmp: 167972d3876SSimon Horman * type: ICMP type 168972d3876SSimon Horman * code: ICMP code 1695dec597eSMatteo Croce * id: session identifier 170972d3876SSimon Horman */ 171972d3876SSimon Horman struct flow_dissector_key_icmp { 172972d3876SSimon Horman struct { 173972d3876SSimon Horman u8 type; 174972d3876SSimon Horman u8 code; 175972d3876SSimon Horman }; 1765dec597eSMatteo Croce u16 id; 177972d3876SSimon Horman }; 178b924933cSJiri Pirko 17967a900ccSJiri Pirko /** 18067a900ccSJiri Pirko * struct flow_dissector_key_eth_addrs: 18167a900ccSJiri Pirko * @src: source Ethernet address 18267a900ccSJiri Pirko * @dst: destination Ethernet address 18367a900ccSJiri Pirko */ 18467a900ccSJiri Pirko struct flow_dissector_key_eth_addrs { 18567a900ccSJiri Pirko /* (dst,src) must be grouped, in the same way than in ETH header */ 18667a900ccSJiri Pirko unsigned char dst[ETH_ALEN]; 18767a900ccSJiri Pirko unsigned char src[ETH_ALEN]; 18867a900ccSJiri Pirko }; 18967a900ccSJiri Pirko 190ac4bb5deSJiri Pirko /** 191ac4bb5deSJiri Pirko * struct flow_dissector_key_tcp: 192ac4bb5deSJiri Pirko * @flags: flags 193ac4bb5deSJiri Pirko */ 194ac4bb5deSJiri Pirko struct flow_dissector_key_tcp { 195ac4bb5deSJiri Pirko __be16 flags; 196ac4bb5deSJiri Pirko }; 197ac4bb5deSJiri Pirko 198518d8a2eSOr Gerlitz /** 199518d8a2eSOr Gerlitz * struct flow_dissector_key_ip: 200518d8a2eSOr Gerlitz * @tos: tos 201518d8a2eSOr Gerlitz * @ttl: ttl 202518d8a2eSOr Gerlitz */ 203518d8a2eSOr Gerlitz struct flow_dissector_key_ip { 204518d8a2eSOr Gerlitz __u8 tos; 205518d8a2eSOr Gerlitz __u8 ttl; 206518d8a2eSOr Gerlitz }; 207518d8a2eSOr Gerlitz 20882828b88SJiri Pirko /** 20982828b88SJiri Pirko * struct flow_dissector_key_meta: 21082828b88SJiri Pirko * @ingress_ifindex: ingress ifindex 2118819efc9SPablo Neira Ayuso * @ingress_iftype: ingress interface type 21282828b88SJiri Pirko */ 21382828b88SJiri Pirko struct flow_dissector_key_meta { 21482828b88SJiri Pirko int ingress_ifindex; 2158819efc9SPablo Neira Ayuso u16 ingress_iftype; 21682828b88SJiri Pirko }; 21782828b88SJiri Pirko 21875a56758SPaul Blakey /** 21975a56758SPaul Blakey * struct flow_dissector_key_ct: 22075a56758SPaul Blakey * @ct_state: conntrack state after converting with map 22175a56758SPaul Blakey * @ct_mark: conttrack mark 22275a56758SPaul Blakey * @ct_zone: conntrack zone 22375a56758SPaul Blakey * @ct_labels: conntrack labels 22475a56758SPaul Blakey */ 22575a56758SPaul Blakey struct flow_dissector_key_ct { 22675a56758SPaul Blakey u16 ct_state; 22775a56758SPaul Blakey u16 ct_zone; 22875a56758SPaul Blakey u32 ct_mark; 22975a56758SPaul Blakey u32 ct_labels[4]; 23075a56758SPaul Blakey }; 23175a56758SPaul Blakey 232fbff949eSJiri Pirko enum flow_dissector_key_id { 23342aecaa9STom Herbert FLOW_DISSECTOR_KEY_CONTROL, /* struct flow_dissector_key_control */ 234fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_BASIC, /* struct flow_dissector_key_basic */ 235c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 236c3f83241STom Herbert FLOW_DISSECTOR_KEY_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 237fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_PORTS, /* struct flow_dissector_key_ports */ 238972d3876SSimon Horman FLOW_DISSECTOR_KEY_ICMP, /* struct flow_dissector_key_icmp */ 23967a900ccSJiri Pirko FLOW_DISSECTOR_KEY_ETH_ADDRS, /* struct flow_dissector_key_eth_addrs */ 2408d6e79d3SJon Maloy FLOW_DISSECTOR_KEY_TIPC, /* struct flow_dissector_key_tipc */ 24155733350SSimon Horman FLOW_DISSECTOR_KEY_ARP, /* struct flow_dissector_key_arp */ 24291c45956SEdward Cree FLOW_DISSECTOR_KEY_VLAN, /* struct flow_dissector_key_vlan */ 24391c45956SEdward Cree FLOW_DISSECTOR_KEY_FLOW_LABEL, /* struct flow_dissector_key_tags */ 2441fdd512cSTom Herbert FLOW_DISSECTOR_KEY_GRE_KEYID, /* struct flow_dissector_key_keyid */ 245b3baa0fbSTom Herbert FLOW_DISSECTOR_KEY_MPLS_ENTROPY, /* struct flow_dissector_key_keyid */ 2469ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_KEYID, /* struct flow_dissector_key_keyid */ 2479ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS, /* struct flow_dissector_key_ipv4_addrs */ 2489ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS, /* struct flow_dissector_key_ipv6_addrs */ 2499ba6a9a9SHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_CONTROL, /* struct flow_dissector_key_control */ 250f4d997fdSHadar Hen Zion FLOW_DISSECTOR_KEY_ENC_PORTS, /* struct flow_dissector_key_ports */ 251029c1ecbSBenjamin LaHaise FLOW_DISSECTOR_KEY_MPLS, /* struct flow_dissector_key_mpls */ 252ac4bb5deSJiri Pirko FLOW_DISSECTOR_KEY_TCP, /* struct flow_dissector_key_tcp */ 253518d8a2eSOr Gerlitz FLOW_DISSECTOR_KEY_IP, /* struct flow_dissector_key_ip */ 25491c45956SEdward Cree FLOW_DISSECTOR_KEY_CVLAN, /* struct flow_dissector_key_vlan */ 2555544adb9SOr Gerlitz FLOW_DISSECTOR_KEY_ENC_IP, /* struct flow_dissector_key_ip */ 25692e2c405SSimon Horman FLOW_DISSECTOR_KEY_ENC_OPTS, /* struct flow_dissector_key_enc_opts */ 25782828b88SJiri Pirko FLOW_DISSECTOR_KEY_META, /* struct flow_dissector_key_meta */ 25875a56758SPaul Blakey FLOW_DISSECTOR_KEY_CT, /* struct flow_dissector_key_ct */ 25992e2c405SSimon Horman 260fbff949eSJiri Pirko FLOW_DISSECTOR_KEY_MAX, 261fbff949eSJiri Pirko }; 262fbff949eSJiri Pirko 263807e165dSTom Herbert #define FLOW_DISSECTOR_F_PARSE_1ST_FRAG BIT(0) 2641cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_FLOW_LABEL BIT(1) 2651cc26450SStanislav Fomichev #define FLOW_DISSECTOR_F_STOP_AT_ENCAP BIT(2) 266807e165dSTom Herbert 267fbff949eSJiri Pirko struct flow_dissector_key { 268fbff949eSJiri Pirko enum flow_dissector_key_id key_id; 269fbff949eSJiri Pirko size_t offset; /* offset of struct flow_dissector_key_* 270fbff949eSJiri Pirko in target the struct */ 271fbff949eSJiri Pirko }; 272fbff949eSJiri Pirko 273fbff949eSJiri Pirko struct flow_dissector { 274fbff949eSJiri Pirko unsigned int used_keys; /* each bit repesents presence of one key id */ 275fbff949eSJiri Pirko unsigned short int offset[FLOW_DISSECTOR_KEY_MAX]; 276fbff949eSJiri Pirko }; 277fbff949eSJiri Pirko 27872a338bcSPaolo Abeni struct flow_keys_basic { 27972a338bcSPaolo Abeni struct flow_dissector_key_control control; 28072a338bcSPaolo Abeni struct flow_dissector_key_basic basic; 28172a338bcSPaolo Abeni }; 28272a338bcSPaolo Abeni 28306635a35SJiri Pirko struct flow_keys { 28442aecaa9STom Herbert struct flow_dissector_key_control control; 28542aecaa9STom Herbert #define FLOW_KEYS_HASH_START_FIELD basic 28655667441SEric Dumazet struct flow_dissector_key_basic basic __aligned(SIPHASH_ALIGNMENT); 287d34af823STom Herbert struct flow_dissector_key_tags tags; 288f6a66927SHadar Hen Zion struct flow_dissector_key_vlan vlan; 28924c590e3SJianbo Liu struct flow_dissector_key_vlan cvlan; 2901fdd512cSTom Herbert struct flow_dissector_key_keyid keyid; 29142aecaa9STom Herbert struct flow_dissector_key_ports ports; 2925dec597eSMatteo Croce struct flow_dissector_key_icmp icmp; 29398298e6cSMatteo Croce /* 'addrs' must be the last member */ 29442aecaa9STom Herbert struct flow_dissector_key_addrs addrs; 29506635a35SJiri Pirko }; 29606635a35SJiri Pirko 29742aecaa9STom Herbert #define FLOW_KEYS_HASH_OFFSET \ 29842aecaa9STom Herbert offsetof(struct flow_keys, FLOW_KEYS_HASH_START_FIELD) 29942aecaa9STom Herbert 300c3f83241STom Herbert __be32 flow_get_u32_src(const struct flow_keys *flow); 301c3f83241STom Herbert __be32 flow_get_u32_dst(const struct flow_keys *flow); 302c3f83241STom Herbert 30306635a35SJiri Pirko extern struct flow_dissector flow_keys_dissector; 30472a338bcSPaolo Abeni extern struct flow_dissector flow_keys_basic_dissector; 30506635a35SJiri Pirko 3061bd758ebSJiri Pirko /* struct flow_keys_digest: 3071bd758ebSJiri Pirko * 3081bd758ebSJiri Pirko * This structure is used to hold a digest of the full flow keys. This is a 3091bd758ebSJiri Pirko * larger "hash" of a flow to allow definitively matching specific flows where 3101bd758ebSJiri Pirko * the 32 bit skb->hash is not large enough. The size is limited to 16 bytes so 31153bc017fSWolfram Sang * that it can be used in CB of skb (see sch_choke for an example). 3121bd758ebSJiri Pirko */ 3131bd758ebSJiri Pirko #define FLOW_KEYS_DIGEST_LEN 16 3141bd758ebSJiri Pirko struct flow_keys_digest { 3151bd758ebSJiri Pirko u8 data[FLOW_KEYS_DIGEST_LEN]; 3161bd758ebSJiri Pirko }; 3171bd758ebSJiri Pirko 3181bd758ebSJiri Pirko void make_flow_keys_digest(struct flow_keys_digest *digest, 3191bd758ebSJiri Pirko const struct flow_keys *flow); 3201bd758ebSJiri Pirko 32166fdd05eSGao Feng static inline bool flow_keys_have_l4(const struct flow_keys *keys) 322bcc83839STom Herbert { 323bcc83839STom Herbert return (keys->ports.ports || keys->tags.flow_label); 324bcc83839STom Herbert } 325bcc83839STom Herbert 326c6cc1ca7STom Herbert u32 flow_hash_from_keys(struct flow_keys *keys); 3275dec597eSMatteo Croce void skb_flow_get_icmp_tci(const struct sk_buff *skb, 3285dec597eSMatteo Croce struct flow_dissector_key_icmp *key_icmp, 3295dec597eSMatteo Croce void *data, int thoff, int hlen); 330c6cc1ca7STom Herbert 3318de2d793SAmir Vadai static inline bool dissector_uses_key(const struct flow_dissector *flow_dissector, 3328de2d793SAmir Vadai enum flow_dissector_key_id key_id) 3338de2d793SAmir Vadai { 3348de2d793SAmir Vadai return flow_dissector->used_keys & (1 << key_id); 3358de2d793SAmir Vadai } 3368de2d793SAmir Vadai 3378de2d793SAmir Vadai static inline void *skb_flow_dissector_target(struct flow_dissector *flow_dissector, 3388de2d793SAmir Vadai enum flow_dissector_key_id key_id, 3398de2d793SAmir Vadai void *target_container) 3408de2d793SAmir Vadai { 3418de2d793SAmir Vadai return ((char *)target_container) + flow_dissector->offset[key_id]; 3428de2d793SAmir Vadai } 3438de2d793SAmir Vadai 344089b19a9SStanislav Fomichev struct bpf_flow_dissector { 345089b19a9SStanislav Fomichev struct bpf_flow_keys *flow_keys; 346089b19a9SStanislav Fomichev const struct sk_buff *skb; 347089b19a9SStanislav Fomichev void *data; 348089b19a9SStanislav Fomichev void *data_end; 349089b19a9SStanislav Fomichev }; 350089b19a9SStanislav Fomichev 3511bd758ebSJiri Pirko #endif 352