1a39e17b2SJakub Kicinski /* 20cd3cbedSJakub Kicinski * Copyright (C) 2017-2018 Netronome Systems, Inc. 3a39e17b2SJakub Kicinski * 4a39e17b2SJakub Kicinski * This software is licensed under the GNU General License Version 2, 5a39e17b2SJakub Kicinski * June 1991 as shown in the file COPYING in the top-level directory of this 6a39e17b2SJakub Kicinski * source tree. 7a39e17b2SJakub Kicinski * 8a39e17b2SJakub Kicinski * THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" 9a39e17b2SJakub Kicinski * WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, 10a39e17b2SJakub Kicinski * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 11a39e17b2SJakub Kicinski * FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE 12a39e17b2SJakub Kicinski * OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME 13a39e17b2SJakub Kicinski * THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 14a39e17b2SJakub Kicinski */ 15a39e17b2SJakub Kicinski 16ab3f0063SJakub Kicinski #include <linux/bpf.h> 17ab3f0063SJakub Kicinski #include <linux/bpf_verifier.h> 18ab3f0063SJakub Kicinski #include <linux/bug.h> 19675fc275SJakub Kicinski #include <linux/kdev_t.h> 20ab3f0063SJakub Kicinski #include <linux/list.h> 219fd7c555SJakub Kicinski #include <linux/lockdep.h> 22ab3f0063SJakub Kicinski #include <linux/netdevice.h> 23ab3f0063SJakub Kicinski #include <linux/printk.h> 24675fc275SJakub Kicinski #include <linux/proc_ns.h> 259fd7c555SJakub Kicinski #include <linux/rhashtable.h> 26ab3f0063SJakub Kicinski #include <linux/rtnetlink.h> 27e0d3974aSJakub Kicinski #include <linux/rwsem.h> 28ab3f0063SJakub Kicinski 299fd7c555SJakub Kicinski /* Protects offdevs, members of bpf_offload_netdev and offload members 30a3884572SJakub Kicinski * of all progs. 31e0d3974aSJakub Kicinski * RTNL lock cannot be taken when holding this lock. 32e0d3974aSJakub Kicinski */ 33e0d3974aSJakub Kicinski static DECLARE_RWSEM(bpf_devs_lock); 349fd7c555SJakub Kicinski 35602144c2SJakub Kicinski struct bpf_offload_dev { 36602144c2SJakub Kicinski struct list_head netdevs; 37602144c2SJakub Kicinski }; 38602144c2SJakub Kicinski 399fd7c555SJakub Kicinski struct bpf_offload_netdev { 409fd7c555SJakub Kicinski struct rhash_head l; 419fd7c555SJakub Kicinski struct net_device *netdev; 42602144c2SJakub Kicinski struct bpf_offload_dev *offdev; 439fd7c555SJakub Kicinski struct list_head progs; 449fd7c555SJakub Kicinski struct list_head maps; 45602144c2SJakub Kicinski struct list_head offdev_netdevs; 469fd7c555SJakub Kicinski }; 479fd7c555SJakub Kicinski 489fd7c555SJakub Kicinski static const struct rhashtable_params offdevs_params = { 499fd7c555SJakub Kicinski .nelem_hint = 4, 509fd7c555SJakub Kicinski .key_len = sizeof(struct net_device *), 519fd7c555SJakub Kicinski .key_offset = offsetof(struct bpf_offload_netdev, netdev), 529fd7c555SJakub Kicinski .head_offset = offsetof(struct bpf_offload_netdev, l), 539fd7c555SJakub Kicinski .automatic_shrinking = true, 549fd7c555SJakub Kicinski }; 559fd7c555SJakub Kicinski 569fd7c555SJakub Kicinski static struct rhashtable offdevs; 579fd7c555SJakub Kicinski static bool offdevs_inited; 58ab3f0063SJakub Kicinski 595bc2d55cSJakub Kicinski static int bpf_dev_offload_check(struct net_device *netdev) 605bc2d55cSJakub Kicinski { 615bc2d55cSJakub Kicinski if (!netdev) 625bc2d55cSJakub Kicinski return -EINVAL; 635bc2d55cSJakub Kicinski if (!netdev->netdev_ops->ndo_bpf) 645bc2d55cSJakub Kicinski return -EOPNOTSUPP; 655bc2d55cSJakub Kicinski return 0; 665bc2d55cSJakub Kicinski } 675bc2d55cSJakub Kicinski 689fd7c555SJakub Kicinski static struct bpf_offload_netdev * 699fd7c555SJakub Kicinski bpf_offload_find_netdev(struct net_device *netdev) 709fd7c555SJakub Kicinski { 719fd7c555SJakub Kicinski lockdep_assert_held(&bpf_devs_lock); 729fd7c555SJakub Kicinski 739fd7c555SJakub Kicinski if (!offdevs_inited) 749fd7c555SJakub Kicinski return NULL; 759fd7c555SJakub Kicinski return rhashtable_lookup_fast(&offdevs, &netdev, offdevs_params); 769fd7c555SJakub Kicinski } 779fd7c555SJakub Kicinski 78ab3f0063SJakub Kicinski int bpf_prog_offload_init(struct bpf_prog *prog, union bpf_attr *attr) 79ab3f0063SJakub Kicinski { 809fd7c555SJakub Kicinski struct bpf_offload_netdev *ondev; 810a9c1991SJakub Kicinski struct bpf_prog_offload *offload; 825bc2d55cSJakub Kicinski int err; 83ab3f0063SJakub Kicinski 84649f11dcSJakub Kicinski if (attr->prog_type != BPF_PROG_TYPE_SCHED_CLS && 85649f11dcSJakub Kicinski attr->prog_type != BPF_PROG_TYPE_XDP) 86649f11dcSJakub Kicinski return -EINVAL; 87ab3f0063SJakub Kicinski 88ab3f0063SJakub Kicinski if (attr->prog_flags) 89ab3f0063SJakub Kicinski return -EINVAL; 90ab3f0063SJakub Kicinski 91ab3f0063SJakub Kicinski offload = kzalloc(sizeof(*offload), GFP_USER); 92ab3f0063SJakub Kicinski if (!offload) 93ab3f0063SJakub Kicinski return -ENOMEM; 94ab3f0063SJakub Kicinski 95ab3f0063SJakub Kicinski offload->prog = prog; 96ab3f0063SJakub Kicinski 97e0d3974aSJakub Kicinski offload->netdev = dev_get_by_index(current->nsproxy->net_ns, 98e0d3974aSJakub Kicinski attr->prog_ifindex); 995bc2d55cSJakub Kicinski err = bpf_dev_offload_check(offload->netdev); 1005bc2d55cSJakub Kicinski if (err) 1015bc2d55cSJakub Kicinski goto err_maybe_put; 102ab3f0063SJakub Kicinski 103e0d3974aSJakub Kicinski down_write(&bpf_devs_lock); 1049fd7c555SJakub Kicinski ondev = bpf_offload_find_netdev(offload->netdev); 1059fd7c555SJakub Kicinski if (!ondev) { 1065bc2d55cSJakub Kicinski err = -EINVAL; 107e0d3974aSJakub Kicinski goto err_unlock; 1085bc2d55cSJakub Kicinski } 109ab3f0063SJakub Kicinski prog->aux->offload = offload; 1109fd7c555SJakub Kicinski list_add_tail(&offload->offloads, &ondev->progs); 111e0d3974aSJakub Kicinski dev_put(offload->netdev); 112e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 113ab3f0063SJakub Kicinski 114ab3f0063SJakub Kicinski return 0; 115e0d3974aSJakub Kicinski err_unlock: 116e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 1175bc2d55cSJakub Kicinski err_maybe_put: 1185bc2d55cSJakub Kicinski if (offload->netdev) 119e0d3974aSJakub Kicinski dev_put(offload->netdev); 120e0d3974aSJakub Kicinski kfree(offload); 1215bc2d55cSJakub Kicinski return err; 122ab3f0063SJakub Kicinski } 123ab3f0063SJakub Kicinski 124ab3f0063SJakub Kicinski static int __bpf_offload_ndo(struct bpf_prog *prog, enum bpf_netdev_command cmd, 125ab3f0063SJakub Kicinski struct netdev_bpf *data) 126ab3f0063SJakub Kicinski { 1270a9c1991SJakub Kicinski struct bpf_prog_offload *offload = prog->aux->offload; 128ce3b9db4SJakub Kicinski struct net_device *netdev; 129ab3f0063SJakub Kicinski 130ab3f0063SJakub Kicinski ASSERT_RTNL(); 131ab3f0063SJakub Kicinski 132ce3b9db4SJakub Kicinski if (!offload) 133ab3f0063SJakub Kicinski return -ENODEV; 134ce3b9db4SJakub Kicinski netdev = offload->netdev; 135ab3f0063SJakub Kicinski 136ab3f0063SJakub Kicinski data->command = cmd; 137ab3f0063SJakub Kicinski 138ab3f0063SJakub Kicinski return netdev->netdev_ops->ndo_bpf(netdev, data); 139ab3f0063SJakub Kicinski } 140ab3f0063SJakub Kicinski 141ab3f0063SJakub Kicinski int bpf_prog_offload_verifier_prep(struct bpf_verifier_env *env) 142ab3f0063SJakub Kicinski { 143ab3f0063SJakub Kicinski struct netdev_bpf data = {}; 144ab3f0063SJakub Kicinski int err; 145ab3f0063SJakub Kicinski 146ab3f0063SJakub Kicinski data.verifier.prog = env->prog; 147ab3f0063SJakub Kicinski 148ab3f0063SJakub Kicinski rtnl_lock(); 149ab3f0063SJakub Kicinski err = __bpf_offload_ndo(env->prog, BPF_OFFLOAD_VERIFIER_PREP, &data); 150ab3f0063SJakub Kicinski if (err) 151ab3f0063SJakub Kicinski goto exit_unlock; 152ab3f0063SJakub Kicinski 153cae1927cSJakub Kicinski env->prog->aux->offload->dev_ops = data.verifier.ops; 154ab3f0063SJakub Kicinski env->prog->aux->offload->dev_state = true; 155ab3f0063SJakub Kicinski exit_unlock: 156ab3f0063SJakub Kicinski rtnl_unlock(); 157ab3f0063SJakub Kicinski return err; 158ab3f0063SJakub Kicinski } 159ab3f0063SJakub Kicinski 160cae1927cSJakub Kicinski int bpf_prog_offload_verify_insn(struct bpf_verifier_env *env, 161cae1927cSJakub Kicinski int insn_idx, int prev_insn_idx) 162cae1927cSJakub Kicinski { 1630a9c1991SJakub Kicinski struct bpf_prog_offload *offload; 164cae1927cSJakub Kicinski int ret = -ENODEV; 165cae1927cSJakub Kicinski 166cae1927cSJakub Kicinski down_read(&bpf_devs_lock); 167cae1927cSJakub Kicinski offload = env->prog->aux->offload; 168ce3b9db4SJakub Kicinski if (offload) 169cae1927cSJakub Kicinski ret = offload->dev_ops->insn_hook(env, insn_idx, prev_insn_idx); 170cae1927cSJakub Kicinski up_read(&bpf_devs_lock); 171cae1927cSJakub Kicinski 172cae1927cSJakub Kicinski return ret; 173cae1927cSJakub Kicinski } 174cae1927cSJakub Kicinski 175*c941ce9cSQuentin Monnet int bpf_prog_offload_finalize(struct bpf_verifier_env *env) 176*c941ce9cSQuentin Monnet { 177*c941ce9cSQuentin Monnet struct bpf_prog_offload *offload; 178*c941ce9cSQuentin Monnet int ret = -ENODEV; 179*c941ce9cSQuentin Monnet 180*c941ce9cSQuentin Monnet down_read(&bpf_devs_lock); 181*c941ce9cSQuentin Monnet offload = env->prog->aux->offload; 182*c941ce9cSQuentin Monnet if (offload) { 183*c941ce9cSQuentin Monnet if (offload->dev_ops->finalize) 184*c941ce9cSQuentin Monnet ret = offload->dev_ops->finalize(env); 185*c941ce9cSQuentin Monnet else 186*c941ce9cSQuentin Monnet ret = 0; 187*c941ce9cSQuentin Monnet } 188*c941ce9cSQuentin Monnet up_read(&bpf_devs_lock); 189*c941ce9cSQuentin Monnet 190*c941ce9cSQuentin Monnet return ret; 191*c941ce9cSQuentin Monnet } 192*c941ce9cSQuentin Monnet 193ab3f0063SJakub Kicinski static void __bpf_prog_offload_destroy(struct bpf_prog *prog) 194ab3f0063SJakub Kicinski { 1950a9c1991SJakub Kicinski struct bpf_prog_offload *offload = prog->aux->offload; 196ab3f0063SJakub Kicinski struct netdev_bpf data = {}; 197ab3f0063SJakub Kicinski 198ab3f0063SJakub Kicinski data.offload.prog = prog; 199ab3f0063SJakub Kicinski 200ab3f0063SJakub Kicinski if (offload->dev_state) 201ab3f0063SJakub Kicinski WARN_ON(__bpf_offload_ndo(prog, BPF_OFFLOAD_DESTROY, &data)); 202ab3f0063SJakub Kicinski 203ad8ad79fSJakub Kicinski /* Make sure BPF_PROG_GET_NEXT_ID can't find this dead program */ 204ad8ad79fSJakub Kicinski bpf_prog_free_id(prog, true); 205ad8ad79fSJakub Kicinski 206ab3f0063SJakub Kicinski list_del_init(&offload->offloads); 207ce3b9db4SJakub Kicinski kfree(offload); 208ce3b9db4SJakub Kicinski prog->aux->offload = NULL; 209ab3f0063SJakub Kicinski } 210ab3f0063SJakub Kicinski 211ab3f0063SJakub Kicinski void bpf_prog_offload_destroy(struct bpf_prog *prog) 212ab3f0063SJakub Kicinski { 213ab3f0063SJakub Kicinski rtnl_lock(); 214e0d3974aSJakub Kicinski down_write(&bpf_devs_lock); 215ce3b9db4SJakub Kicinski if (prog->aux->offload) 216ab3f0063SJakub Kicinski __bpf_prog_offload_destroy(prog); 217e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 218ab3f0063SJakub Kicinski rtnl_unlock(); 219ab3f0063SJakub Kicinski } 220ab3f0063SJakub Kicinski 221ab3f0063SJakub Kicinski static int bpf_prog_offload_translate(struct bpf_prog *prog) 222ab3f0063SJakub Kicinski { 223ab3f0063SJakub Kicinski struct netdev_bpf data = {}; 224ab3f0063SJakub Kicinski int ret; 225ab3f0063SJakub Kicinski 226ab3f0063SJakub Kicinski data.offload.prog = prog; 227ab3f0063SJakub Kicinski 228ab3f0063SJakub Kicinski rtnl_lock(); 229ab3f0063SJakub Kicinski ret = __bpf_offload_ndo(prog, BPF_OFFLOAD_TRANSLATE, &data); 230ab3f0063SJakub Kicinski rtnl_unlock(); 231ab3f0063SJakub Kicinski 232ab3f0063SJakub Kicinski return ret; 233ab3f0063SJakub Kicinski } 234ab3f0063SJakub Kicinski 235ab3f0063SJakub Kicinski static unsigned int bpf_prog_warn_on_exec(const void *ctx, 236ab3f0063SJakub Kicinski const struct bpf_insn *insn) 237ab3f0063SJakub Kicinski { 238ab3f0063SJakub Kicinski WARN(1, "attempt to execute device eBPF program on the host!"); 239ab3f0063SJakub Kicinski return 0; 240ab3f0063SJakub Kicinski } 241ab3f0063SJakub Kicinski 242ab3f0063SJakub Kicinski int bpf_prog_offload_compile(struct bpf_prog *prog) 243ab3f0063SJakub Kicinski { 244ab3f0063SJakub Kicinski prog->bpf_func = bpf_prog_warn_on_exec; 245ab3f0063SJakub Kicinski 246ab3f0063SJakub Kicinski return bpf_prog_offload_translate(prog); 247ab3f0063SJakub Kicinski } 248ab3f0063SJakub Kicinski 249675fc275SJakub Kicinski struct ns_get_path_bpf_prog_args { 250675fc275SJakub Kicinski struct bpf_prog *prog; 251675fc275SJakub Kicinski struct bpf_prog_info *info; 252675fc275SJakub Kicinski }; 253675fc275SJakub Kicinski 254675fc275SJakub Kicinski static struct ns_common *bpf_prog_offload_info_fill_ns(void *private_data) 255675fc275SJakub Kicinski { 256675fc275SJakub Kicinski struct ns_get_path_bpf_prog_args *args = private_data; 257675fc275SJakub Kicinski struct bpf_prog_aux *aux = args->prog->aux; 258675fc275SJakub Kicinski struct ns_common *ns; 259675fc275SJakub Kicinski struct net *net; 260675fc275SJakub Kicinski 261675fc275SJakub Kicinski rtnl_lock(); 262675fc275SJakub Kicinski down_read(&bpf_devs_lock); 263675fc275SJakub Kicinski 264675fc275SJakub Kicinski if (aux->offload) { 265675fc275SJakub Kicinski args->info->ifindex = aux->offload->netdev->ifindex; 266675fc275SJakub Kicinski net = dev_net(aux->offload->netdev); 267675fc275SJakub Kicinski get_net(net); 268675fc275SJakub Kicinski ns = &net->ns; 269675fc275SJakub Kicinski } else { 270675fc275SJakub Kicinski args->info->ifindex = 0; 271675fc275SJakub Kicinski ns = NULL; 272675fc275SJakub Kicinski } 273675fc275SJakub Kicinski 274675fc275SJakub Kicinski up_read(&bpf_devs_lock); 275675fc275SJakub Kicinski rtnl_unlock(); 276675fc275SJakub Kicinski 277675fc275SJakub Kicinski return ns; 278675fc275SJakub Kicinski } 279675fc275SJakub Kicinski 280675fc275SJakub Kicinski int bpf_prog_offload_info_fill(struct bpf_prog_info *info, 281675fc275SJakub Kicinski struct bpf_prog *prog) 282675fc275SJakub Kicinski { 283675fc275SJakub Kicinski struct ns_get_path_bpf_prog_args args = { 284675fc275SJakub Kicinski .prog = prog, 285675fc275SJakub Kicinski .info = info, 286675fc275SJakub Kicinski }; 287fcfb126dSJiong Wang struct bpf_prog_aux *aux = prog->aux; 288675fc275SJakub Kicinski struct inode *ns_inode; 289675fc275SJakub Kicinski struct path ns_path; 290fcfb126dSJiong Wang char __user *uinsns; 291675fc275SJakub Kicinski void *res; 292fcfb126dSJiong Wang u32 ulen; 293675fc275SJakub Kicinski 294675fc275SJakub Kicinski res = ns_get_path_cb(&ns_path, bpf_prog_offload_info_fill_ns, &args); 295675fc275SJakub Kicinski if (IS_ERR(res)) { 296675fc275SJakub Kicinski if (!info->ifindex) 297675fc275SJakub Kicinski return -ENODEV; 298675fc275SJakub Kicinski return PTR_ERR(res); 299675fc275SJakub Kicinski } 300675fc275SJakub Kicinski 301fcfb126dSJiong Wang down_read(&bpf_devs_lock); 302fcfb126dSJiong Wang 303fcfb126dSJiong Wang if (!aux->offload) { 304fcfb126dSJiong Wang up_read(&bpf_devs_lock); 305fcfb126dSJiong Wang return -ENODEV; 306fcfb126dSJiong Wang } 307fcfb126dSJiong Wang 308fcfb126dSJiong Wang ulen = info->jited_prog_len; 309fcfb126dSJiong Wang info->jited_prog_len = aux->offload->jited_len; 310fcfb126dSJiong Wang if (info->jited_prog_len & ulen) { 311fcfb126dSJiong Wang uinsns = u64_to_user_ptr(info->jited_prog_insns); 312fcfb126dSJiong Wang ulen = min_t(u32, info->jited_prog_len, ulen); 313fcfb126dSJiong Wang if (copy_to_user(uinsns, aux->offload->jited_image, ulen)) { 314fcfb126dSJiong Wang up_read(&bpf_devs_lock); 315fcfb126dSJiong Wang return -EFAULT; 316fcfb126dSJiong Wang } 317fcfb126dSJiong Wang } 318fcfb126dSJiong Wang 319fcfb126dSJiong Wang up_read(&bpf_devs_lock); 320fcfb126dSJiong Wang 321675fc275SJakub Kicinski ns_inode = ns_path.dentry->d_inode; 322675fc275SJakub Kicinski info->netns_dev = new_encode_dev(ns_inode->i_sb->s_dev); 323675fc275SJakub Kicinski info->netns_ino = ns_inode->i_ino; 324675fc275SJakub Kicinski path_put(&ns_path); 325675fc275SJakub Kicinski 326675fc275SJakub Kicinski return 0; 327675fc275SJakub Kicinski } 328675fc275SJakub Kicinski 329ab3f0063SJakub Kicinski const struct bpf_prog_ops bpf_offload_prog_ops = { 330ab3f0063SJakub Kicinski }; 331ab3f0063SJakub Kicinski 332a3884572SJakub Kicinski static int bpf_map_offload_ndo(struct bpf_offloaded_map *offmap, 333a3884572SJakub Kicinski enum bpf_netdev_command cmd) 334a3884572SJakub Kicinski { 335a3884572SJakub Kicinski struct netdev_bpf data = {}; 336a3884572SJakub Kicinski struct net_device *netdev; 337a3884572SJakub Kicinski 338a3884572SJakub Kicinski ASSERT_RTNL(); 339a3884572SJakub Kicinski 340a3884572SJakub Kicinski data.command = cmd; 341a3884572SJakub Kicinski data.offmap = offmap; 342a3884572SJakub Kicinski /* Caller must make sure netdev is valid */ 343a3884572SJakub Kicinski netdev = offmap->netdev; 344a3884572SJakub Kicinski 345a3884572SJakub Kicinski return netdev->netdev_ops->ndo_bpf(netdev, &data); 346a3884572SJakub Kicinski } 347a3884572SJakub Kicinski 348a3884572SJakub Kicinski struct bpf_map *bpf_map_offload_map_alloc(union bpf_attr *attr) 349a3884572SJakub Kicinski { 350a3884572SJakub Kicinski struct net *net = current->nsproxy->net_ns; 3519fd7c555SJakub Kicinski struct bpf_offload_netdev *ondev; 352a3884572SJakub Kicinski struct bpf_offloaded_map *offmap; 353a3884572SJakub Kicinski int err; 354a3884572SJakub Kicinski 355a3884572SJakub Kicinski if (!capable(CAP_SYS_ADMIN)) 356a3884572SJakub Kicinski return ERR_PTR(-EPERM); 3577a0ef693SJakub Kicinski if (attr->map_type != BPF_MAP_TYPE_ARRAY && 3587a0ef693SJakub Kicinski attr->map_type != BPF_MAP_TYPE_HASH) 359a3884572SJakub Kicinski return ERR_PTR(-EINVAL); 360a3884572SJakub Kicinski 361a3884572SJakub Kicinski offmap = kzalloc(sizeof(*offmap), GFP_USER); 362a3884572SJakub Kicinski if (!offmap) 363a3884572SJakub Kicinski return ERR_PTR(-ENOMEM); 364a3884572SJakub Kicinski 365a3884572SJakub Kicinski bpf_map_init_from_attr(&offmap->map, attr); 366a3884572SJakub Kicinski 367a3884572SJakub Kicinski rtnl_lock(); 368a3884572SJakub Kicinski down_write(&bpf_devs_lock); 369a3884572SJakub Kicinski offmap->netdev = __dev_get_by_index(net, attr->map_ifindex); 370a3884572SJakub Kicinski err = bpf_dev_offload_check(offmap->netdev); 371a3884572SJakub Kicinski if (err) 372a3884572SJakub Kicinski goto err_unlock; 373a3884572SJakub Kicinski 3749fd7c555SJakub Kicinski ondev = bpf_offload_find_netdev(offmap->netdev); 3759fd7c555SJakub Kicinski if (!ondev) { 3769fd7c555SJakub Kicinski err = -EINVAL; 3779fd7c555SJakub Kicinski goto err_unlock; 3789fd7c555SJakub Kicinski } 3799fd7c555SJakub Kicinski 380a3884572SJakub Kicinski err = bpf_map_offload_ndo(offmap, BPF_OFFLOAD_MAP_ALLOC); 381a3884572SJakub Kicinski if (err) 382a3884572SJakub Kicinski goto err_unlock; 383a3884572SJakub Kicinski 3849fd7c555SJakub Kicinski list_add_tail(&offmap->offloads, &ondev->maps); 385a3884572SJakub Kicinski up_write(&bpf_devs_lock); 386a3884572SJakub Kicinski rtnl_unlock(); 387a3884572SJakub Kicinski 388a3884572SJakub Kicinski return &offmap->map; 389a3884572SJakub Kicinski 390a3884572SJakub Kicinski err_unlock: 391a3884572SJakub Kicinski up_write(&bpf_devs_lock); 392a3884572SJakub Kicinski rtnl_unlock(); 393a3884572SJakub Kicinski kfree(offmap); 394a3884572SJakub Kicinski return ERR_PTR(err); 395a3884572SJakub Kicinski } 396a3884572SJakub Kicinski 397a3884572SJakub Kicinski static void __bpf_map_offload_destroy(struct bpf_offloaded_map *offmap) 398a3884572SJakub Kicinski { 399a3884572SJakub Kicinski WARN_ON(bpf_map_offload_ndo(offmap, BPF_OFFLOAD_MAP_FREE)); 400a3884572SJakub Kicinski /* Make sure BPF_MAP_GET_NEXT_ID can't find this dead map */ 401a3884572SJakub Kicinski bpf_map_free_id(&offmap->map, true); 402a3884572SJakub Kicinski list_del_init(&offmap->offloads); 403a3884572SJakub Kicinski offmap->netdev = NULL; 404a3884572SJakub Kicinski } 405a3884572SJakub Kicinski 406a3884572SJakub Kicinski void bpf_map_offload_map_free(struct bpf_map *map) 407a3884572SJakub Kicinski { 408a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 409a3884572SJakub Kicinski 410a3884572SJakub Kicinski rtnl_lock(); 411a3884572SJakub Kicinski down_write(&bpf_devs_lock); 412a3884572SJakub Kicinski if (offmap->netdev) 413a3884572SJakub Kicinski __bpf_map_offload_destroy(offmap); 414a3884572SJakub Kicinski up_write(&bpf_devs_lock); 415a3884572SJakub Kicinski rtnl_unlock(); 416a3884572SJakub Kicinski 417a3884572SJakub Kicinski kfree(offmap); 418a3884572SJakub Kicinski } 419a3884572SJakub Kicinski 420a3884572SJakub Kicinski int bpf_map_offload_lookup_elem(struct bpf_map *map, void *key, void *value) 421a3884572SJakub Kicinski { 422a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 423a3884572SJakub Kicinski int ret = -ENODEV; 424a3884572SJakub Kicinski 425a3884572SJakub Kicinski down_read(&bpf_devs_lock); 426a3884572SJakub Kicinski if (offmap->netdev) 427a3884572SJakub Kicinski ret = offmap->dev_ops->map_lookup_elem(offmap, key, value); 428a3884572SJakub Kicinski up_read(&bpf_devs_lock); 429a3884572SJakub Kicinski 430a3884572SJakub Kicinski return ret; 431a3884572SJakub Kicinski } 432a3884572SJakub Kicinski 433a3884572SJakub Kicinski int bpf_map_offload_update_elem(struct bpf_map *map, 434a3884572SJakub Kicinski void *key, void *value, u64 flags) 435a3884572SJakub Kicinski { 436a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 437a3884572SJakub Kicinski int ret = -ENODEV; 438a3884572SJakub Kicinski 439a3884572SJakub Kicinski if (unlikely(flags > BPF_EXIST)) 440a3884572SJakub Kicinski return -EINVAL; 441a3884572SJakub Kicinski 442a3884572SJakub Kicinski down_read(&bpf_devs_lock); 443a3884572SJakub Kicinski if (offmap->netdev) 444a3884572SJakub Kicinski ret = offmap->dev_ops->map_update_elem(offmap, key, value, 445a3884572SJakub Kicinski flags); 446a3884572SJakub Kicinski up_read(&bpf_devs_lock); 447a3884572SJakub Kicinski 448a3884572SJakub Kicinski return ret; 449a3884572SJakub Kicinski } 450a3884572SJakub Kicinski 451a3884572SJakub Kicinski int bpf_map_offload_delete_elem(struct bpf_map *map, void *key) 452a3884572SJakub Kicinski { 453a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 454a3884572SJakub Kicinski int ret = -ENODEV; 455a3884572SJakub Kicinski 456a3884572SJakub Kicinski down_read(&bpf_devs_lock); 457a3884572SJakub Kicinski if (offmap->netdev) 458a3884572SJakub Kicinski ret = offmap->dev_ops->map_delete_elem(offmap, key); 459a3884572SJakub Kicinski up_read(&bpf_devs_lock); 460a3884572SJakub Kicinski 461a3884572SJakub Kicinski return ret; 462a3884572SJakub Kicinski } 463a3884572SJakub Kicinski 464a3884572SJakub Kicinski int bpf_map_offload_get_next_key(struct bpf_map *map, void *key, void *next_key) 465a3884572SJakub Kicinski { 466a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 467a3884572SJakub Kicinski int ret = -ENODEV; 468a3884572SJakub Kicinski 469a3884572SJakub Kicinski down_read(&bpf_devs_lock); 470a3884572SJakub Kicinski if (offmap->netdev) 471a3884572SJakub Kicinski ret = offmap->dev_ops->map_get_next_key(offmap, key, next_key); 472a3884572SJakub Kicinski up_read(&bpf_devs_lock); 473a3884572SJakub Kicinski 474a3884572SJakub Kicinski return ret; 475a3884572SJakub Kicinski } 476a3884572SJakub Kicinski 47752775b33SJakub Kicinski struct ns_get_path_bpf_map_args { 47852775b33SJakub Kicinski struct bpf_offloaded_map *offmap; 47952775b33SJakub Kicinski struct bpf_map_info *info; 48052775b33SJakub Kicinski }; 48152775b33SJakub Kicinski 48252775b33SJakub Kicinski static struct ns_common *bpf_map_offload_info_fill_ns(void *private_data) 48352775b33SJakub Kicinski { 48452775b33SJakub Kicinski struct ns_get_path_bpf_map_args *args = private_data; 48552775b33SJakub Kicinski struct ns_common *ns; 48652775b33SJakub Kicinski struct net *net; 48752775b33SJakub Kicinski 48852775b33SJakub Kicinski rtnl_lock(); 48952775b33SJakub Kicinski down_read(&bpf_devs_lock); 49052775b33SJakub Kicinski 49152775b33SJakub Kicinski if (args->offmap->netdev) { 49252775b33SJakub Kicinski args->info->ifindex = args->offmap->netdev->ifindex; 49352775b33SJakub Kicinski net = dev_net(args->offmap->netdev); 49452775b33SJakub Kicinski get_net(net); 49552775b33SJakub Kicinski ns = &net->ns; 49652775b33SJakub Kicinski } else { 49752775b33SJakub Kicinski args->info->ifindex = 0; 49852775b33SJakub Kicinski ns = NULL; 49952775b33SJakub Kicinski } 50052775b33SJakub Kicinski 50152775b33SJakub Kicinski up_read(&bpf_devs_lock); 50252775b33SJakub Kicinski rtnl_unlock(); 50352775b33SJakub Kicinski 50452775b33SJakub Kicinski return ns; 50552775b33SJakub Kicinski } 50652775b33SJakub Kicinski 50752775b33SJakub Kicinski int bpf_map_offload_info_fill(struct bpf_map_info *info, struct bpf_map *map) 50852775b33SJakub Kicinski { 50952775b33SJakub Kicinski struct ns_get_path_bpf_map_args args = { 51052775b33SJakub Kicinski .offmap = map_to_offmap(map), 51152775b33SJakub Kicinski .info = info, 51252775b33SJakub Kicinski }; 51352775b33SJakub Kicinski struct inode *ns_inode; 51452775b33SJakub Kicinski struct path ns_path; 51552775b33SJakub Kicinski void *res; 51652775b33SJakub Kicinski 51752775b33SJakub Kicinski res = ns_get_path_cb(&ns_path, bpf_map_offload_info_fill_ns, &args); 51852775b33SJakub Kicinski if (IS_ERR(res)) { 51952775b33SJakub Kicinski if (!info->ifindex) 52052775b33SJakub Kicinski return -ENODEV; 52152775b33SJakub Kicinski return PTR_ERR(res); 52252775b33SJakub Kicinski } 52352775b33SJakub Kicinski 52452775b33SJakub Kicinski ns_inode = ns_path.dentry->d_inode; 52552775b33SJakub Kicinski info->netns_dev = new_encode_dev(ns_inode->i_sb->s_dev); 52652775b33SJakub Kicinski info->netns_ino = ns_inode->i_ino; 52752775b33SJakub Kicinski path_put(&ns_path); 52852775b33SJakub Kicinski 52952775b33SJakub Kicinski return 0; 53052775b33SJakub Kicinski } 53152775b33SJakub Kicinski 532fd4f227dSJakub Kicinski static bool __bpf_offload_dev_match(struct bpf_prog *prog, 533fd4f227dSJakub Kicinski struct net_device *netdev) 534a3884572SJakub Kicinski { 535fd4f227dSJakub Kicinski struct bpf_offload_netdev *ondev1, *ondev2; 536a3884572SJakub Kicinski struct bpf_prog_offload *offload; 537a3884572SJakub Kicinski 5380cd3cbedSJakub Kicinski if (!bpf_prog_is_dev_bound(prog->aux)) 539a3884572SJakub Kicinski return false; 540fd4f227dSJakub Kicinski 541fd4f227dSJakub Kicinski offload = prog->aux->offload; 542fd4f227dSJakub Kicinski if (!offload) 543fd4f227dSJakub Kicinski return false; 544fd4f227dSJakub Kicinski if (offload->netdev == netdev) 545fd4f227dSJakub Kicinski return true; 546fd4f227dSJakub Kicinski 547fd4f227dSJakub Kicinski ondev1 = bpf_offload_find_netdev(offload->netdev); 548fd4f227dSJakub Kicinski ondev2 = bpf_offload_find_netdev(netdev); 549fd4f227dSJakub Kicinski 550fd4f227dSJakub Kicinski return ondev1 && ondev2 && ondev1->offdev == ondev2->offdev; 551fd4f227dSJakub Kicinski } 552fd4f227dSJakub Kicinski 553fd4f227dSJakub Kicinski bool bpf_offload_dev_match(struct bpf_prog *prog, struct net_device *netdev) 554fd4f227dSJakub Kicinski { 555fd4f227dSJakub Kicinski bool ret; 556a3884572SJakub Kicinski 557a3884572SJakub Kicinski down_read(&bpf_devs_lock); 558fd4f227dSJakub Kicinski ret = __bpf_offload_dev_match(prog, netdev); 559fd4f227dSJakub Kicinski up_read(&bpf_devs_lock); 560fd4f227dSJakub Kicinski 561fd4f227dSJakub Kicinski return ret; 562fd4f227dSJakub Kicinski } 563fd4f227dSJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_match); 564fd4f227dSJakub Kicinski 565fd4f227dSJakub Kicinski bool bpf_offload_prog_map_match(struct bpf_prog *prog, struct bpf_map *map) 566fd4f227dSJakub Kicinski { 567fd4f227dSJakub Kicinski struct bpf_offloaded_map *offmap; 568fd4f227dSJakub Kicinski bool ret; 569fd4f227dSJakub Kicinski 570fd4f227dSJakub Kicinski if (!bpf_map_is_dev_bound(map)) 571fd4f227dSJakub Kicinski return bpf_map_offload_neutral(map); 572a3884572SJakub Kicinski offmap = map_to_offmap(map); 573a3884572SJakub Kicinski 574fd4f227dSJakub Kicinski down_read(&bpf_devs_lock); 575fd4f227dSJakub Kicinski ret = __bpf_offload_dev_match(prog, offmap->netdev); 576a3884572SJakub Kicinski up_read(&bpf_devs_lock); 577a3884572SJakub Kicinski 578a3884572SJakub Kicinski return ret; 579a3884572SJakub Kicinski } 580a3884572SJakub Kicinski 581602144c2SJakub Kicinski int bpf_offload_dev_netdev_register(struct bpf_offload_dev *offdev, 582602144c2SJakub Kicinski struct net_device *netdev) 583a3884572SJakub Kicinski { 5849fd7c555SJakub Kicinski struct bpf_offload_netdev *ondev; 5859fd7c555SJakub Kicinski int err; 586a3884572SJakub Kicinski 5879fd7c555SJakub Kicinski ondev = kzalloc(sizeof(*ondev), GFP_KERNEL); 5889fd7c555SJakub Kicinski if (!ondev) 5899fd7c555SJakub Kicinski return -ENOMEM; 5909fd7c555SJakub Kicinski 5919fd7c555SJakub Kicinski ondev->netdev = netdev; 592602144c2SJakub Kicinski ondev->offdev = offdev; 5939fd7c555SJakub Kicinski INIT_LIST_HEAD(&ondev->progs); 5949fd7c555SJakub Kicinski INIT_LIST_HEAD(&ondev->maps); 5959fd7c555SJakub Kicinski 5969fd7c555SJakub Kicinski down_write(&bpf_devs_lock); 5979fd7c555SJakub Kicinski err = rhashtable_insert_fast(&offdevs, &ondev->l, offdevs_params); 5989fd7c555SJakub Kicinski if (err) { 5999fd7c555SJakub Kicinski netdev_warn(netdev, "failed to register for BPF offload\n"); 6009fd7c555SJakub Kicinski goto err_unlock_free; 601a3884572SJakub Kicinski } 602a3884572SJakub Kicinski 603602144c2SJakub Kicinski list_add(&ondev->offdev_netdevs, &offdev->netdevs); 6049fd7c555SJakub Kicinski up_write(&bpf_devs_lock); 6059fd7c555SJakub Kicinski return 0; 606a3884572SJakub Kicinski 6079fd7c555SJakub Kicinski err_unlock_free: 6089fd7c555SJakub Kicinski up_write(&bpf_devs_lock); 6099fd7c555SJakub Kicinski kfree(ondev); 6109fd7c555SJakub Kicinski return err; 611a3884572SJakub Kicinski } 6129fd7c555SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_netdev_register); 613a3884572SJakub Kicinski 614602144c2SJakub Kicinski void bpf_offload_dev_netdev_unregister(struct bpf_offload_dev *offdev, 615602144c2SJakub Kicinski struct net_device *netdev) 616ab3f0063SJakub Kicinski { 617602144c2SJakub Kicinski struct bpf_offload_netdev *ondev, *altdev; 6189fd7c555SJakub Kicinski struct bpf_offloaded_map *offmap, *mtmp; 6199fd7c555SJakub Kicinski struct bpf_prog_offload *offload, *ptmp; 620ab3f0063SJakub Kicinski 621ab3f0063SJakub Kicinski ASSERT_RTNL(); 622ab3f0063SJakub Kicinski 623e0d3974aSJakub Kicinski down_write(&bpf_devs_lock); 6249fd7c555SJakub Kicinski ondev = rhashtable_lookup_fast(&offdevs, &netdev, offdevs_params); 6259fd7c555SJakub Kicinski if (WARN_ON(!ondev)) 6269fd7c555SJakub Kicinski goto unlock; 6279fd7c555SJakub Kicinski 6289fd7c555SJakub Kicinski WARN_ON(rhashtable_remove_fast(&offdevs, &ondev->l, offdevs_params)); 629602144c2SJakub Kicinski list_del(&ondev->offdev_netdevs); 6309fd7c555SJakub Kicinski 631602144c2SJakub Kicinski /* Try to move the objects to another netdev of the device */ 632602144c2SJakub Kicinski altdev = list_first_entry_or_null(&offdev->netdevs, 633602144c2SJakub Kicinski struct bpf_offload_netdev, 634602144c2SJakub Kicinski offdev_netdevs); 635602144c2SJakub Kicinski if (altdev) { 636602144c2SJakub Kicinski list_for_each_entry(offload, &ondev->progs, offloads) 637602144c2SJakub Kicinski offload->netdev = altdev->netdev; 638602144c2SJakub Kicinski list_splice_init(&ondev->progs, &altdev->progs); 639602144c2SJakub Kicinski 640602144c2SJakub Kicinski list_for_each_entry(offmap, &ondev->maps, offloads) 641602144c2SJakub Kicinski offmap->netdev = altdev->netdev; 642602144c2SJakub Kicinski list_splice_init(&ondev->maps, &altdev->maps); 643602144c2SJakub Kicinski } else { 6449fd7c555SJakub Kicinski list_for_each_entry_safe(offload, ptmp, &ondev->progs, offloads) 6459fd7c555SJakub Kicinski __bpf_prog_offload_destroy(offload->prog); 6469fd7c555SJakub Kicinski list_for_each_entry_safe(offmap, mtmp, &ondev->maps, offloads) 6479fd7c555SJakub Kicinski __bpf_map_offload_destroy(offmap); 648602144c2SJakub Kicinski } 6499fd7c555SJakub Kicinski 6509fd7c555SJakub Kicinski WARN_ON(!list_empty(&ondev->progs)); 6519fd7c555SJakub Kicinski WARN_ON(!list_empty(&ondev->maps)); 6529fd7c555SJakub Kicinski kfree(ondev); 6539fd7c555SJakub Kicinski unlock: 654e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 655ab3f0063SJakub Kicinski } 6569fd7c555SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_netdev_unregister); 657602144c2SJakub Kicinski 658602144c2SJakub Kicinski struct bpf_offload_dev *bpf_offload_dev_create(void) 659602144c2SJakub Kicinski { 660602144c2SJakub Kicinski struct bpf_offload_dev *offdev; 661602144c2SJakub Kicinski int err; 662602144c2SJakub Kicinski 663602144c2SJakub Kicinski down_write(&bpf_devs_lock); 664602144c2SJakub Kicinski if (!offdevs_inited) { 665602144c2SJakub Kicinski err = rhashtable_init(&offdevs, &offdevs_params); 666602144c2SJakub Kicinski if (err) 667602144c2SJakub Kicinski return ERR_PTR(err); 668602144c2SJakub Kicinski offdevs_inited = true; 669602144c2SJakub Kicinski } 670602144c2SJakub Kicinski up_write(&bpf_devs_lock); 671602144c2SJakub Kicinski 672602144c2SJakub Kicinski offdev = kzalloc(sizeof(*offdev), GFP_KERNEL); 673602144c2SJakub Kicinski if (!offdev) 674602144c2SJakub Kicinski return ERR_PTR(-ENOMEM); 675602144c2SJakub Kicinski 676602144c2SJakub Kicinski INIT_LIST_HEAD(&offdev->netdevs); 677602144c2SJakub Kicinski 678602144c2SJakub Kicinski return offdev; 679602144c2SJakub Kicinski } 680602144c2SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_create); 681602144c2SJakub Kicinski 682602144c2SJakub Kicinski void bpf_offload_dev_destroy(struct bpf_offload_dev *offdev) 683602144c2SJakub Kicinski { 684602144c2SJakub Kicinski WARN_ON(!list_empty(&offdev->netdevs)); 685602144c2SJakub Kicinski kfree(offdev); 686602144c2SJakub Kicinski } 687602144c2SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_destroy); 688