1a39e17b2SJakub Kicinski /* 20cd3cbedSJakub Kicinski * Copyright (C) 2017-2018 Netronome Systems, Inc. 3a39e17b2SJakub Kicinski * 4a39e17b2SJakub Kicinski * This software is licensed under the GNU General License Version 2, 5a39e17b2SJakub Kicinski * June 1991 as shown in the file COPYING in the top-level directory of this 6a39e17b2SJakub Kicinski * source tree. 7a39e17b2SJakub Kicinski * 8a39e17b2SJakub Kicinski * THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" 9a39e17b2SJakub Kicinski * WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, 10a39e17b2SJakub Kicinski * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 11a39e17b2SJakub Kicinski * FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE 12a39e17b2SJakub Kicinski * OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME 13a39e17b2SJakub Kicinski * THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 14a39e17b2SJakub Kicinski */ 15a39e17b2SJakub Kicinski 16ab3f0063SJakub Kicinski #include <linux/bpf.h> 17ab3f0063SJakub Kicinski #include <linux/bpf_verifier.h> 18ab3f0063SJakub Kicinski #include <linux/bug.h> 19675fc275SJakub Kicinski #include <linux/kdev_t.h> 20ab3f0063SJakub Kicinski #include <linux/list.h> 219fd7c555SJakub Kicinski #include <linux/lockdep.h> 22ab3f0063SJakub Kicinski #include <linux/netdevice.h> 23ab3f0063SJakub Kicinski #include <linux/printk.h> 24675fc275SJakub Kicinski #include <linux/proc_ns.h> 259fd7c555SJakub Kicinski #include <linux/rhashtable.h> 26ab3f0063SJakub Kicinski #include <linux/rtnetlink.h> 27e0d3974aSJakub Kicinski #include <linux/rwsem.h> 28ab3f0063SJakub Kicinski 299fd7c555SJakub Kicinski /* Protects offdevs, members of bpf_offload_netdev and offload members 30a3884572SJakub Kicinski * of all progs. 31e0d3974aSJakub Kicinski * RTNL lock cannot be taken when holding this lock. 32e0d3974aSJakub Kicinski */ 33e0d3974aSJakub Kicinski static DECLARE_RWSEM(bpf_devs_lock); 349fd7c555SJakub Kicinski 35602144c2SJakub Kicinski struct bpf_offload_dev { 361385d755SQuentin Monnet const struct bpf_prog_offload_ops *ops; 37602144c2SJakub Kicinski struct list_head netdevs; 38dd27c2e3SJakub Kicinski void *priv; 39602144c2SJakub Kicinski }; 40602144c2SJakub Kicinski 419fd7c555SJakub Kicinski struct bpf_offload_netdev { 429fd7c555SJakub Kicinski struct rhash_head l; 439fd7c555SJakub Kicinski struct net_device *netdev; 44602144c2SJakub Kicinski struct bpf_offload_dev *offdev; 459fd7c555SJakub Kicinski struct list_head progs; 469fd7c555SJakub Kicinski struct list_head maps; 47602144c2SJakub Kicinski struct list_head offdev_netdevs; 489fd7c555SJakub Kicinski }; 499fd7c555SJakub Kicinski 509fd7c555SJakub Kicinski static const struct rhashtable_params offdevs_params = { 519fd7c555SJakub Kicinski .nelem_hint = 4, 529fd7c555SJakub Kicinski .key_len = sizeof(struct net_device *), 539fd7c555SJakub Kicinski .key_offset = offsetof(struct bpf_offload_netdev, netdev), 549fd7c555SJakub Kicinski .head_offset = offsetof(struct bpf_offload_netdev, l), 559fd7c555SJakub Kicinski .automatic_shrinking = true, 569fd7c555SJakub Kicinski }; 579fd7c555SJakub Kicinski 589fd7c555SJakub Kicinski static struct rhashtable offdevs; 599fd7c555SJakub Kicinski static bool offdevs_inited; 60ab3f0063SJakub Kicinski 615bc2d55cSJakub Kicinski static int bpf_dev_offload_check(struct net_device *netdev) 625bc2d55cSJakub Kicinski { 635bc2d55cSJakub Kicinski if (!netdev) 645bc2d55cSJakub Kicinski return -EINVAL; 655bc2d55cSJakub Kicinski if (!netdev->netdev_ops->ndo_bpf) 665bc2d55cSJakub Kicinski return -EOPNOTSUPP; 675bc2d55cSJakub Kicinski return 0; 685bc2d55cSJakub Kicinski } 695bc2d55cSJakub Kicinski 709fd7c555SJakub Kicinski static struct bpf_offload_netdev * 719fd7c555SJakub Kicinski bpf_offload_find_netdev(struct net_device *netdev) 729fd7c555SJakub Kicinski { 739fd7c555SJakub Kicinski lockdep_assert_held(&bpf_devs_lock); 749fd7c555SJakub Kicinski 759fd7c555SJakub Kicinski if (!offdevs_inited) 769fd7c555SJakub Kicinski return NULL; 779fd7c555SJakub Kicinski return rhashtable_lookup_fast(&offdevs, &netdev, offdevs_params); 789fd7c555SJakub Kicinski } 799fd7c555SJakub Kicinski 80ab3f0063SJakub Kicinski int bpf_prog_offload_init(struct bpf_prog *prog, union bpf_attr *attr) 81ab3f0063SJakub Kicinski { 829fd7c555SJakub Kicinski struct bpf_offload_netdev *ondev; 830a9c1991SJakub Kicinski struct bpf_prog_offload *offload; 845bc2d55cSJakub Kicinski int err; 85ab3f0063SJakub Kicinski 86649f11dcSJakub Kicinski if (attr->prog_type != BPF_PROG_TYPE_SCHED_CLS && 87649f11dcSJakub Kicinski attr->prog_type != BPF_PROG_TYPE_XDP) 88649f11dcSJakub Kicinski return -EINVAL; 89ab3f0063SJakub Kicinski 90ab3f0063SJakub Kicinski if (attr->prog_flags) 91ab3f0063SJakub Kicinski return -EINVAL; 92ab3f0063SJakub Kicinski 93ab3f0063SJakub Kicinski offload = kzalloc(sizeof(*offload), GFP_USER); 94ab3f0063SJakub Kicinski if (!offload) 95ab3f0063SJakub Kicinski return -ENOMEM; 96ab3f0063SJakub Kicinski 97ab3f0063SJakub Kicinski offload->prog = prog; 98ab3f0063SJakub Kicinski 99e0d3974aSJakub Kicinski offload->netdev = dev_get_by_index(current->nsproxy->net_ns, 100e0d3974aSJakub Kicinski attr->prog_ifindex); 1015bc2d55cSJakub Kicinski err = bpf_dev_offload_check(offload->netdev); 1025bc2d55cSJakub Kicinski if (err) 1035bc2d55cSJakub Kicinski goto err_maybe_put; 104ab3f0063SJakub Kicinski 105e0d3974aSJakub Kicinski down_write(&bpf_devs_lock); 1069fd7c555SJakub Kicinski ondev = bpf_offload_find_netdev(offload->netdev); 1079fd7c555SJakub Kicinski if (!ondev) { 1085bc2d55cSJakub Kicinski err = -EINVAL; 109e0d3974aSJakub Kicinski goto err_unlock; 1105bc2d55cSJakub Kicinski } 111341b3e7bSQuentin Monnet offload->offdev = ondev->offdev; 112ab3f0063SJakub Kicinski prog->aux->offload = offload; 1139fd7c555SJakub Kicinski list_add_tail(&offload->offloads, &ondev->progs); 114e0d3974aSJakub Kicinski dev_put(offload->netdev); 115e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 116ab3f0063SJakub Kicinski 117ab3f0063SJakub Kicinski return 0; 118e0d3974aSJakub Kicinski err_unlock: 119e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 1205bc2d55cSJakub Kicinski err_maybe_put: 1215bc2d55cSJakub Kicinski if (offload->netdev) 122e0d3974aSJakub Kicinski dev_put(offload->netdev); 123e0d3974aSJakub Kicinski kfree(offload); 1245bc2d55cSJakub Kicinski return err; 125ab3f0063SJakub Kicinski } 126ab3f0063SJakub Kicinski 127a40a2632SQuentin Monnet int bpf_prog_offload_verifier_prep(struct bpf_prog *prog) 128ab3f0063SJakub Kicinski { 12900db12c3SQuentin Monnet struct bpf_prog_offload *offload; 13000db12c3SQuentin Monnet int ret = -ENODEV; 131ab3f0063SJakub Kicinski 13200db12c3SQuentin Monnet down_read(&bpf_devs_lock); 133a40a2632SQuentin Monnet offload = prog->aux->offload; 134592ee43fSColin Ian King if (offload) { 13516a8cb5cSQuentin Monnet ret = offload->offdev->ops->prepare(prog); 13600db12c3SQuentin Monnet offload->dev_state = !ret; 137592ee43fSColin Ian King } 13800db12c3SQuentin Monnet up_read(&bpf_devs_lock); 139ab3f0063SJakub Kicinski 14000db12c3SQuentin Monnet return ret; 141ab3f0063SJakub Kicinski } 142ab3f0063SJakub Kicinski 143cae1927cSJakub Kicinski int bpf_prog_offload_verify_insn(struct bpf_verifier_env *env, 144cae1927cSJakub Kicinski int insn_idx, int prev_insn_idx) 145cae1927cSJakub Kicinski { 1460a9c1991SJakub Kicinski struct bpf_prog_offload *offload; 147cae1927cSJakub Kicinski int ret = -ENODEV; 148cae1927cSJakub Kicinski 149cae1927cSJakub Kicinski down_read(&bpf_devs_lock); 150cae1927cSJakub Kicinski offload = env->prog->aux->offload; 151ce3b9db4SJakub Kicinski if (offload) 152341b3e7bSQuentin Monnet ret = offload->offdev->ops->insn_hook(env, insn_idx, 153341b3e7bSQuentin Monnet prev_insn_idx); 154cae1927cSJakub Kicinski up_read(&bpf_devs_lock); 155cae1927cSJakub Kicinski 156cae1927cSJakub Kicinski return ret; 157cae1927cSJakub Kicinski } 158cae1927cSJakub Kicinski 159c941ce9cSQuentin Monnet int bpf_prog_offload_finalize(struct bpf_verifier_env *env) 160c941ce9cSQuentin Monnet { 161c941ce9cSQuentin Monnet struct bpf_prog_offload *offload; 162c941ce9cSQuentin Monnet int ret = -ENODEV; 163c941ce9cSQuentin Monnet 164c941ce9cSQuentin Monnet down_read(&bpf_devs_lock); 165c941ce9cSQuentin Monnet offload = env->prog->aux->offload; 166c941ce9cSQuentin Monnet if (offload) { 1676dc18fa6SQuentin Monnet if (offload->offdev->ops->finalize) 1686dc18fa6SQuentin Monnet ret = offload->offdev->ops->finalize(env); 169c941ce9cSQuentin Monnet else 170c941ce9cSQuentin Monnet ret = 0; 171c941ce9cSQuentin Monnet } 172c941ce9cSQuentin Monnet up_read(&bpf_devs_lock); 173c941ce9cSQuentin Monnet 174c941ce9cSQuentin Monnet return ret; 175c941ce9cSQuentin Monnet } 176c941ce9cSQuentin Monnet 17708ca90afSJakub Kicinski void 17808ca90afSJakub Kicinski bpf_prog_offload_replace_insn(struct bpf_verifier_env *env, u32 off, 17908ca90afSJakub Kicinski struct bpf_insn *insn) 18008ca90afSJakub Kicinski { 18108ca90afSJakub Kicinski const struct bpf_prog_offload_ops *ops; 18208ca90afSJakub Kicinski struct bpf_prog_offload *offload; 18308ca90afSJakub Kicinski int ret = -EOPNOTSUPP; 18408ca90afSJakub Kicinski 18508ca90afSJakub Kicinski down_read(&bpf_devs_lock); 18608ca90afSJakub Kicinski offload = env->prog->aux->offload; 18708ca90afSJakub Kicinski if (offload) { 18808ca90afSJakub Kicinski ops = offload->offdev->ops; 18908ca90afSJakub Kicinski if (!offload->opt_failed && ops->replace_insn) 19008ca90afSJakub Kicinski ret = ops->replace_insn(env, off, insn); 19108ca90afSJakub Kicinski offload->opt_failed |= ret; 19208ca90afSJakub Kicinski } 19308ca90afSJakub Kicinski up_read(&bpf_devs_lock); 19408ca90afSJakub Kicinski } 19508ca90afSJakub Kicinski 19608ca90afSJakub Kicinski void 19708ca90afSJakub Kicinski bpf_prog_offload_remove_insns(struct bpf_verifier_env *env, u32 off, u32 cnt) 19808ca90afSJakub Kicinski { 19908ca90afSJakub Kicinski struct bpf_prog_offload *offload; 20008ca90afSJakub Kicinski int ret = -EOPNOTSUPP; 20108ca90afSJakub Kicinski 20208ca90afSJakub Kicinski down_read(&bpf_devs_lock); 20308ca90afSJakub Kicinski offload = env->prog->aux->offload; 20408ca90afSJakub Kicinski if (offload) { 20508ca90afSJakub Kicinski if (!offload->opt_failed && offload->offdev->ops->remove_insns) 20608ca90afSJakub Kicinski ret = offload->offdev->ops->remove_insns(env, off, cnt); 20708ca90afSJakub Kicinski offload->opt_failed |= ret; 20808ca90afSJakub Kicinski } 20908ca90afSJakub Kicinski up_read(&bpf_devs_lock); 21008ca90afSJakub Kicinski } 21108ca90afSJakub Kicinski 212ab3f0063SJakub Kicinski static void __bpf_prog_offload_destroy(struct bpf_prog *prog) 213ab3f0063SJakub Kicinski { 2140a9c1991SJakub Kicinski struct bpf_prog_offload *offload = prog->aux->offload; 215ab3f0063SJakub Kicinski 216ab3f0063SJakub Kicinski if (offload->dev_state) 217eb911947SQuentin Monnet offload->offdev->ops->destroy(prog); 218ab3f0063SJakub Kicinski 219ad8ad79fSJakub Kicinski /* Make sure BPF_PROG_GET_NEXT_ID can't find this dead program */ 220ad8ad79fSJakub Kicinski bpf_prog_free_id(prog, true); 221ad8ad79fSJakub Kicinski 222ab3f0063SJakub Kicinski list_del_init(&offload->offloads); 223ce3b9db4SJakub Kicinski kfree(offload); 224ce3b9db4SJakub Kicinski prog->aux->offload = NULL; 225ab3f0063SJakub Kicinski } 226ab3f0063SJakub Kicinski 227ab3f0063SJakub Kicinski void bpf_prog_offload_destroy(struct bpf_prog *prog) 228ab3f0063SJakub Kicinski { 229e0d3974aSJakub Kicinski down_write(&bpf_devs_lock); 230ce3b9db4SJakub Kicinski if (prog->aux->offload) 231ab3f0063SJakub Kicinski __bpf_prog_offload_destroy(prog); 232e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 233ab3f0063SJakub Kicinski } 234ab3f0063SJakub Kicinski 235ab3f0063SJakub Kicinski static int bpf_prog_offload_translate(struct bpf_prog *prog) 236ab3f0063SJakub Kicinski { 237b07ade27SQuentin Monnet struct bpf_prog_offload *offload; 238b07ade27SQuentin Monnet int ret = -ENODEV; 239ab3f0063SJakub Kicinski 240b07ade27SQuentin Monnet down_read(&bpf_devs_lock); 241b07ade27SQuentin Monnet offload = prog->aux->offload; 242b07ade27SQuentin Monnet if (offload) 24316a8cb5cSQuentin Monnet ret = offload->offdev->ops->translate(prog); 244b07ade27SQuentin Monnet up_read(&bpf_devs_lock); 245ab3f0063SJakub Kicinski 246ab3f0063SJakub Kicinski return ret; 247ab3f0063SJakub Kicinski } 248ab3f0063SJakub Kicinski 249ab3f0063SJakub Kicinski static unsigned int bpf_prog_warn_on_exec(const void *ctx, 250ab3f0063SJakub Kicinski const struct bpf_insn *insn) 251ab3f0063SJakub Kicinski { 252ab3f0063SJakub Kicinski WARN(1, "attempt to execute device eBPF program on the host!"); 253ab3f0063SJakub Kicinski return 0; 254ab3f0063SJakub Kicinski } 255ab3f0063SJakub Kicinski 256ab3f0063SJakub Kicinski int bpf_prog_offload_compile(struct bpf_prog *prog) 257ab3f0063SJakub Kicinski { 258ab3f0063SJakub Kicinski prog->bpf_func = bpf_prog_warn_on_exec; 259ab3f0063SJakub Kicinski 260ab3f0063SJakub Kicinski return bpf_prog_offload_translate(prog); 261ab3f0063SJakub Kicinski } 262ab3f0063SJakub Kicinski 263675fc275SJakub Kicinski struct ns_get_path_bpf_prog_args { 264675fc275SJakub Kicinski struct bpf_prog *prog; 265675fc275SJakub Kicinski struct bpf_prog_info *info; 266675fc275SJakub Kicinski }; 267675fc275SJakub Kicinski 268675fc275SJakub Kicinski static struct ns_common *bpf_prog_offload_info_fill_ns(void *private_data) 269675fc275SJakub Kicinski { 270675fc275SJakub Kicinski struct ns_get_path_bpf_prog_args *args = private_data; 271675fc275SJakub Kicinski struct bpf_prog_aux *aux = args->prog->aux; 272675fc275SJakub Kicinski struct ns_common *ns; 273675fc275SJakub Kicinski struct net *net; 274675fc275SJakub Kicinski 275675fc275SJakub Kicinski rtnl_lock(); 276675fc275SJakub Kicinski down_read(&bpf_devs_lock); 277675fc275SJakub Kicinski 278675fc275SJakub Kicinski if (aux->offload) { 279675fc275SJakub Kicinski args->info->ifindex = aux->offload->netdev->ifindex; 280675fc275SJakub Kicinski net = dev_net(aux->offload->netdev); 281675fc275SJakub Kicinski get_net(net); 282675fc275SJakub Kicinski ns = &net->ns; 283675fc275SJakub Kicinski } else { 284675fc275SJakub Kicinski args->info->ifindex = 0; 285675fc275SJakub Kicinski ns = NULL; 286675fc275SJakub Kicinski } 287675fc275SJakub Kicinski 288675fc275SJakub Kicinski up_read(&bpf_devs_lock); 289675fc275SJakub Kicinski rtnl_unlock(); 290675fc275SJakub Kicinski 291675fc275SJakub Kicinski return ns; 292675fc275SJakub Kicinski } 293675fc275SJakub Kicinski 294675fc275SJakub Kicinski int bpf_prog_offload_info_fill(struct bpf_prog_info *info, 295675fc275SJakub Kicinski struct bpf_prog *prog) 296675fc275SJakub Kicinski { 297675fc275SJakub Kicinski struct ns_get_path_bpf_prog_args args = { 298675fc275SJakub Kicinski .prog = prog, 299675fc275SJakub Kicinski .info = info, 300675fc275SJakub Kicinski }; 301fcfb126dSJiong Wang struct bpf_prog_aux *aux = prog->aux; 302675fc275SJakub Kicinski struct inode *ns_inode; 303675fc275SJakub Kicinski struct path ns_path; 304fcfb126dSJiong Wang char __user *uinsns; 305ce623f89SAleksa Sarai int res; 306fcfb126dSJiong Wang u32 ulen; 307675fc275SJakub Kicinski 308675fc275SJakub Kicinski res = ns_get_path_cb(&ns_path, bpf_prog_offload_info_fill_ns, &args); 309ce623f89SAleksa Sarai if (res) { 310675fc275SJakub Kicinski if (!info->ifindex) 311675fc275SJakub Kicinski return -ENODEV; 312ce623f89SAleksa Sarai return res; 313675fc275SJakub Kicinski } 314675fc275SJakub Kicinski 315fcfb126dSJiong Wang down_read(&bpf_devs_lock); 316fcfb126dSJiong Wang 317fcfb126dSJiong Wang if (!aux->offload) { 318fcfb126dSJiong Wang up_read(&bpf_devs_lock); 319fcfb126dSJiong Wang return -ENODEV; 320fcfb126dSJiong Wang } 321fcfb126dSJiong Wang 322fcfb126dSJiong Wang ulen = info->jited_prog_len; 323fcfb126dSJiong Wang info->jited_prog_len = aux->offload->jited_len; 324*e20d3a05SJohannes Krude if (info->jited_prog_len && ulen) { 325fcfb126dSJiong Wang uinsns = u64_to_user_ptr(info->jited_prog_insns); 326fcfb126dSJiong Wang ulen = min_t(u32, info->jited_prog_len, ulen); 327fcfb126dSJiong Wang if (copy_to_user(uinsns, aux->offload->jited_image, ulen)) { 328fcfb126dSJiong Wang up_read(&bpf_devs_lock); 329fcfb126dSJiong Wang return -EFAULT; 330fcfb126dSJiong Wang } 331fcfb126dSJiong Wang } 332fcfb126dSJiong Wang 333fcfb126dSJiong Wang up_read(&bpf_devs_lock); 334fcfb126dSJiong Wang 335675fc275SJakub Kicinski ns_inode = ns_path.dentry->d_inode; 336675fc275SJakub Kicinski info->netns_dev = new_encode_dev(ns_inode->i_sb->s_dev); 337675fc275SJakub Kicinski info->netns_ino = ns_inode->i_ino; 338675fc275SJakub Kicinski path_put(&ns_path); 339675fc275SJakub Kicinski 340675fc275SJakub Kicinski return 0; 341675fc275SJakub Kicinski } 342675fc275SJakub Kicinski 343ab3f0063SJakub Kicinski const struct bpf_prog_ops bpf_offload_prog_ops = { 344ab3f0063SJakub Kicinski }; 345ab3f0063SJakub Kicinski 346a3884572SJakub Kicinski static int bpf_map_offload_ndo(struct bpf_offloaded_map *offmap, 347a3884572SJakub Kicinski enum bpf_netdev_command cmd) 348a3884572SJakub Kicinski { 349a3884572SJakub Kicinski struct netdev_bpf data = {}; 350a3884572SJakub Kicinski struct net_device *netdev; 351a3884572SJakub Kicinski 352a3884572SJakub Kicinski ASSERT_RTNL(); 353a3884572SJakub Kicinski 354a3884572SJakub Kicinski data.command = cmd; 355a3884572SJakub Kicinski data.offmap = offmap; 356a3884572SJakub Kicinski /* Caller must make sure netdev is valid */ 357a3884572SJakub Kicinski netdev = offmap->netdev; 358a3884572SJakub Kicinski 359a3884572SJakub Kicinski return netdev->netdev_ops->ndo_bpf(netdev, &data); 360a3884572SJakub Kicinski } 361a3884572SJakub Kicinski 362a3884572SJakub Kicinski struct bpf_map *bpf_map_offload_map_alloc(union bpf_attr *attr) 363a3884572SJakub Kicinski { 364a3884572SJakub Kicinski struct net *net = current->nsproxy->net_ns; 3659fd7c555SJakub Kicinski struct bpf_offload_netdev *ondev; 366a3884572SJakub Kicinski struct bpf_offloaded_map *offmap; 367a3884572SJakub Kicinski int err; 368a3884572SJakub Kicinski 369a3884572SJakub Kicinski if (!capable(CAP_SYS_ADMIN)) 370a3884572SJakub Kicinski return ERR_PTR(-EPERM); 3717a0ef693SJakub Kicinski if (attr->map_type != BPF_MAP_TYPE_ARRAY && 3727a0ef693SJakub Kicinski attr->map_type != BPF_MAP_TYPE_HASH) 373a3884572SJakub Kicinski return ERR_PTR(-EINVAL); 374a3884572SJakub Kicinski 375a3884572SJakub Kicinski offmap = kzalloc(sizeof(*offmap), GFP_USER); 376a3884572SJakub Kicinski if (!offmap) 377a3884572SJakub Kicinski return ERR_PTR(-ENOMEM); 378a3884572SJakub Kicinski 379a3884572SJakub Kicinski bpf_map_init_from_attr(&offmap->map, attr); 380a3884572SJakub Kicinski 381a3884572SJakub Kicinski rtnl_lock(); 382a3884572SJakub Kicinski down_write(&bpf_devs_lock); 383a3884572SJakub Kicinski offmap->netdev = __dev_get_by_index(net, attr->map_ifindex); 384a3884572SJakub Kicinski err = bpf_dev_offload_check(offmap->netdev); 385a3884572SJakub Kicinski if (err) 386a3884572SJakub Kicinski goto err_unlock; 387a3884572SJakub Kicinski 3889fd7c555SJakub Kicinski ondev = bpf_offload_find_netdev(offmap->netdev); 3899fd7c555SJakub Kicinski if (!ondev) { 3909fd7c555SJakub Kicinski err = -EINVAL; 3919fd7c555SJakub Kicinski goto err_unlock; 3929fd7c555SJakub Kicinski } 3939fd7c555SJakub Kicinski 394a3884572SJakub Kicinski err = bpf_map_offload_ndo(offmap, BPF_OFFLOAD_MAP_ALLOC); 395a3884572SJakub Kicinski if (err) 396a3884572SJakub Kicinski goto err_unlock; 397a3884572SJakub Kicinski 3989fd7c555SJakub Kicinski list_add_tail(&offmap->offloads, &ondev->maps); 399a3884572SJakub Kicinski up_write(&bpf_devs_lock); 400a3884572SJakub Kicinski rtnl_unlock(); 401a3884572SJakub Kicinski 402a3884572SJakub Kicinski return &offmap->map; 403a3884572SJakub Kicinski 404a3884572SJakub Kicinski err_unlock: 405a3884572SJakub Kicinski up_write(&bpf_devs_lock); 406a3884572SJakub Kicinski rtnl_unlock(); 407a3884572SJakub Kicinski kfree(offmap); 408a3884572SJakub Kicinski return ERR_PTR(err); 409a3884572SJakub Kicinski } 410a3884572SJakub Kicinski 411a3884572SJakub Kicinski static void __bpf_map_offload_destroy(struct bpf_offloaded_map *offmap) 412a3884572SJakub Kicinski { 413a3884572SJakub Kicinski WARN_ON(bpf_map_offload_ndo(offmap, BPF_OFFLOAD_MAP_FREE)); 414a3884572SJakub Kicinski /* Make sure BPF_MAP_GET_NEXT_ID can't find this dead map */ 415a3884572SJakub Kicinski bpf_map_free_id(&offmap->map, true); 416a3884572SJakub Kicinski list_del_init(&offmap->offloads); 417a3884572SJakub Kicinski offmap->netdev = NULL; 418a3884572SJakub Kicinski } 419a3884572SJakub Kicinski 420a3884572SJakub Kicinski void bpf_map_offload_map_free(struct bpf_map *map) 421a3884572SJakub Kicinski { 422a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 423a3884572SJakub Kicinski 424a3884572SJakub Kicinski rtnl_lock(); 425a3884572SJakub Kicinski down_write(&bpf_devs_lock); 426a3884572SJakub Kicinski if (offmap->netdev) 427a3884572SJakub Kicinski __bpf_map_offload_destroy(offmap); 428a3884572SJakub Kicinski up_write(&bpf_devs_lock); 429a3884572SJakub Kicinski rtnl_unlock(); 430a3884572SJakub Kicinski 431a3884572SJakub Kicinski kfree(offmap); 432a3884572SJakub Kicinski } 433a3884572SJakub Kicinski 434a3884572SJakub Kicinski int bpf_map_offload_lookup_elem(struct bpf_map *map, void *key, void *value) 435a3884572SJakub Kicinski { 436a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 437a3884572SJakub Kicinski int ret = -ENODEV; 438a3884572SJakub Kicinski 439a3884572SJakub Kicinski down_read(&bpf_devs_lock); 440a3884572SJakub Kicinski if (offmap->netdev) 441a3884572SJakub Kicinski ret = offmap->dev_ops->map_lookup_elem(offmap, key, value); 442a3884572SJakub Kicinski up_read(&bpf_devs_lock); 443a3884572SJakub Kicinski 444a3884572SJakub Kicinski return ret; 445a3884572SJakub Kicinski } 446a3884572SJakub Kicinski 447a3884572SJakub Kicinski int bpf_map_offload_update_elem(struct bpf_map *map, 448a3884572SJakub Kicinski void *key, void *value, u64 flags) 449a3884572SJakub Kicinski { 450a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 451a3884572SJakub Kicinski int ret = -ENODEV; 452a3884572SJakub Kicinski 453a3884572SJakub Kicinski if (unlikely(flags > BPF_EXIST)) 454a3884572SJakub Kicinski return -EINVAL; 455a3884572SJakub Kicinski 456a3884572SJakub Kicinski down_read(&bpf_devs_lock); 457a3884572SJakub Kicinski if (offmap->netdev) 458a3884572SJakub Kicinski ret = offmap->dev_ops->map_update_elem(offmap, key, value, 459a3884572SJakub Kicinski flags); 460a3884572SJakub Kicinski up_read(&bpf_devs_lock); 461a3884572SJakub Kicinski 462a3884572SJakub Kicinski return ret; 463a3884572SJakub Kicinski } 464a3884572SJakub Kicinski 465a3884572SJakub Kicinski int bpf_map_offload_delete_elem(struct bpf_map *map, void *key) 466a3884572SJakub Kicinski { 467a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 468a3884572SJakub Kicinski int ret = -ENODEV; 469a3884572SJakub Kicinski 470a3884572SJakub Kicinski down_read(&bpf_devs_lock); 471a3884572SJakub Kicinski if (offmap->netdev) 472a3884572SJakub Kicinski ret = offmap->dev_ops->map_delete_elem(offmap, key); 473a3884572SJakub Kicinski up_read(&bpf_devs_lock); 474a3884572SJakub Kicinski 475a3884572SJakub Kicinski return ret; 476a3884572SJakub Kicinski } 477a3884572SJakub Kicinski 478a3884572SJakub Kicinski int bpf_map_offload_get_next_key(struct bpf_map *map, void *key, void *next_key) 479a3884572SJakub Kicinski { 480a3884572SJakub Kicinski struct bpf_offloaded_map *offmap = map_to_offmap(map); 481a3884572SJakub Kicinski int ret = -ENODEV; 482a3884572SJakub Kicinski 483a3884572SJakub Kicinski down_read(&bpf_devs_lock); 484a3884572SJakub Kicinski if (offmap->netdev) 485a3884572SJakub Kicinski ret = offmap->dev_ops->map_get_next_key(offmap, key, next_key); 486a3884572SJakub Kicinski up_read(&bpf_devs_lock); 487a3884572SJakub Kicinski 488a3884572SJakub Kicinski return ret; 489a3884572SJakub Kicinski } 490a3884572SJakub Kicinski 49152775b33SJakub Kicinski struct ns_get_path_bpf_map_args { 49252775b33SJakub Kicinski struct bpf_offloaded_map *offmap; 49352775b33SJakub Kicinski struct bpf_map_info *info; 49452775b33SJakub Kicinski }; 49552775b33SJakub Kicinski 49652775b33SJakub Kicinski static struct ns_common *bpf_map_offload_info_fill_ns(void *private_data) 49752775b33SJakub Kicinski { 49852775b33SJakub Kicinski struct ns_get_path_bpf_map_args *args = private_data; 49952775b33SJakub Kicinski struct ns_common *ns; 50052775b33SJakub Kicinski struct net *net; 50152775b33SJakub Kicinski 50252775b33SJakub Kicinski rtnl_lock(); 50352775b33SJakub Kicinski down_read(&bpf_devs_lock); 50452775b33SJakub Kicinski 50552775b33SJakub Kicinski if (args->offmap->netdev) { 50652775b33SJakub Kicinski args->info->ifindex = args->offmap->netdev->ifindex; 50752775b33SJakub Kicinski net = dev_net(args->offmap->netdev); 50852775b33SJakub Kicinski get_net(net); 50952775b33SJakub Kicinski ns = &net->ns; 51052775b33SJakub Kicinski } else { 51152775b33SJakub Kicinski args->info->ifindex = 0; 51252775b33SJakub Kicinski ns = NULL; 51352775b33SJakub Kicinski } 51452775b33SJakub Kicinski 51552775b33SJakub Kicinski up_read(&bpf_devs_lock); 51652775b33SJakub Kicinski rtnl_unlock(); 51752775b33SJakub Kicinski 51852775b33SJakub Kicinski return ns; 51952775b33SJakub Kicinski } 52052775b33SJakub Kicinski 52152775b33SJakub Kicinski int bpf_map_offload_info_fill(struct bpf_map_info *info, struct bpf_map *map) 52252775b33SJakub Kicinski { 52352775b33SJakub Kicinski struct ns_get_path_bpf_map_args args = { 52452775b33SJakub Kicinski .offmap = map_to_offmap(map), 52552775b33SJakub Kicinski .info = info, 52652775b33SJakub Kicinski }; 52752775b33SJakub Kicinski struct inode *ns_inode; 52852775b33SJakub Kicinski struct path ns_path; 529ce623f89SAleksa Sarai int res; 53052775b33SJakub Kicinski 53152775b33SJakub Kicinski res = ns_get_path_cb(&ns_path, bpf_map_offload_info_fill_ns, &args); 532ce623f89SAleksa Sarai if (res) { 53352775b33SJakub Kicinski if (!info->ifindex) 53452775b33SJakub Kicinski return -ENODEV; 535ce623f89SAleksa Sarai return res; 53652775b33SJakub Kicinski } 53752775b33SJakub Kicinski 53852775b33SJakub Kicinski ns_inode = ns_path.dentry->d_inode; 53952775b33SJakub Kicinski info->netns_dev = new_encode_dev(ns_inode->i_sb->s_dev); 54052775b33SJakub Kicinski info->netns_ino = ns_inode->i_ino; 54152775b33SJakub Kicinski path_put(&ns_path); 54252775b33SJakub Kicinski 54352775b33SJakub Kicinski return 0; 54452775b33SJakub Kicinski } 54552775b33SJakub Kicinski 546fd4f227dSJakub Kicinski static bool __bpf_offload_dev_match(struct bpf_prog *prog, 547fd4f227dSJakub Kicinski struct net_device *netdev) 548a3884572SJakub Kicinski { 549fd4f227dSJakub Kicinski struct bpf_offload_netdev *ondev1, *ondev2; 550a3884572SJakub Kicinski struct bpf_prog_offload *offload; 551a3884572SJakub Kicinski 5520cd3cbedSJakub Kicinski if (!bpf_prog_is_dev_bound(prog->aux)) 553a3884572SJakub Kicinski return false; 554fd4f227dSJakub Kicinski 555fd4f227dSJakub Kicinski offload = prog->aux->offload; 556fd4f227dSJakub Kicinski if (!offload) 557fd4f227dSJakub Kicinski return false; 558fd4f227dSJakub Kicinski if (offload->netdev == netdev) 559fd4f227dSJakub Kicinski return true; 560fd4f227dSJakub Kicinski 561fd4f227dSJakub Kicinski ondev1 = bpf_offload_find_netdev(offload->netdev); 562fd4f227dSJakub Kicinski ondev2 = bpf_offload_find_netdev(netdev); 563fd4f227dSJakub Kicinski 564fd4f227dSJakub Kicinski return ondev1 && ondev2 && ondev1->offdev == ondev2->offdev; 565fd4f227dSJakub Kicinski } 566fd4f227dSJakub Kicinski 567fd4f227dSJakub Kicinski bool bpf_offload_dev_match(struct bpf_prog *prog, struct net_device *netdev) 568fd4f227dSJakub Kicinski { 569fd4f227dSJakub Kicinski bool ret; 570a3884572SJakub Kicinski 571a3884572SJakub Kicinski down_read(&bpf_devs_lock); 572fd4f227dSJakub Kicinski ret = __bpf_offload_dev_match(prog, netdev); 573fd4f227dSJakub Kicinski up_read(&bpf_devs_lock); 574fd4f227dSJakub Kicinski 575fd4f227dSJakub Kicinski return ret; 576fd4f227dSJakub Kicinski } 577fd4f227dSJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_match); 578fd4f227dSJakub Kicinski 579fd4f227dSJakub Kicinski bool bpf_offload_prog_map_match(struct bpf_prog *prog, struct bpf_map *map) 580fd4f227dSJakub Kicinski { 581fd4f227dSJakub Kicinski struct bpf_offloaded_map *offmap; 582fd4f227dSJakub Kicinski bool ret; 583fd4f227dSJakub Kicinski 584fd4f227dSJakub Kicinski if (!bpf_map_is_dev_bound(map)) 585fd4f227dSJakub Kicinski return bpf_map_offload_neutral(map); 586a3884572SJakub Kicinski offmap = map_to_offmap(map); 587a3884572SJakub Kicinski 588fd4f227dSJakub Kicinski down_read(&bpf_devs_lock); 589fd4f227dSJakub Kicinski ret = __bpf_offload_dev_match(prog, offmap->netdev); 590a3884572SJakub Kicinski up_read(&bpf_devs_lock); 591a3884572SJakub Kicinski 592a3884572SJakub Kicinski return ret; 593a3884572SJakub Kicinski } 594a3884572SJakub Kicinski 595602144c2SJakub Kicinski int bpf_offload_dev_netdev_register(struct bpf_offload_dev *offdev, 596602144c2SJakub Kicinski struct net_device *netdev) 597a3884572SJakub Kicinski { 5989fd7c555SJakub Kicinski struct bpf_offload_netdev *ondev; 5999fd7c555SJakub Kicinski int err; 600a3884572SJakub Kicinski 6019fd7c555SJakub Kicinski ondev = kzalloc(sizeof(*ondev), GFP_KERNEL); 6029fd7c555SJakub Kicinski if (!ondev) 6039fd7c555SJakub Kicinski return -ENOMEM; 6049fd7c555SJakub Kicinski 6059fd7c555SJakub Kicinski ondev->netdev = netdev; 606602144c2SJakub Kicinski ondev->offdev = offdev; 6079fd7c555SJakub Kicinski INIT_LIST_HEAD(&ondev->progs); 6089fd7c555SJakub Kicinski INIT_LIST_HEAD(&ondev->maps); 6099fd7c555SJakub Kicinski 6109fd7c555SJakub Kicinski down_write(&bpf_devs_lock); 6119fd7c555SJakub Kicinski err = rhashtable_insert_fast(&offdevs, &ondev->l, offdevs_params); 6129fd7c555SJakub Kicinski if (err) { 6139fd7c555SJakub Kicinski netdev_warn(netdev, "failed to register for BPF offload\n"); 6149fd7c555SJakub Kicinski goto err_unlock_free; 615a3884572SJakub Kicinski } 616a3884572SJakub Kicinski 617602144c2SJakub Kicinski list_add(&ondev->offdev_netdevs, &offdev->netdevs); 6189fd7c555SJakub Kicinski up_write(&bpf_devs_lock); 6199fd7c555SJakub Kicinski return 0; 620a3884572SJakub Kicinski 6219fd7c555SJakub Kicinski err_unlock_free: 6229fd7c555SJakub Kicinski up_write(&bpf_devs_lock); 6239fd7c555SJakub Kicinski kfree(ondev); 6249fd7c555SJakub Kicinski return err; 625a3884572SJakub Kicinski } 6269fd7c555SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_netdev_register); 627a3884572SJakub Kicinski 628602144c2SJakub Kicinski void bpf_offload_dev_netdev_unregister(struct bpf_offload_dev *offdev, 629602144c2SJakub Kicinski struct net_device *netdev) 630ab3f0063SJakub Kicinski { 631602144c2SJakub Kicinski struct bpf_offload_netdev *ondev, *altdev; 6329fd7c555SJakub Kicinski struct bpf_offloaded_map *offmap, *mtmp; 6339fd7c555SJakub Kicinski struct bpf_prog_offload *offload, *ptmp; 634ab3f0063SJakub Kicinski 635ab3f0063SJakub Kicinski ASSERT_RTNL(); 636ab3f0063SJakub Kicinski 637e0d3974aSJakub Kicinski down_write(&bpf_devs_lock); 6389fd7c555SJakub Kicinski ondev = rhashtable_lookup_fast(&offdevs, &netdev, offdevs_params); 6399fd7c555SJakub Kicinski if (WARN_ON(!ondev)) 6409fd7c555SJakub Kicinski goto unlock; 6419fd7c555SJakub Kicinski 6429fd7c555SJakub Kicinski WARN_ON(rhashtable_remove_fast(&offdevs, &ondev->l, offdevs_params)); 643602144c2SJakub Kicinski list_del(&ondev->offdev_netdevs); 6449fd7c555SJakub Kicinski 645602144c2SJakub Kicinski /* Try to move the objects to another netdev of the device */ 646602144c2SJakub Kicinski altdev = list_first_entry_or_null(&offdev->netdevs, 647602144c2SJakub Kicinski struct bpf_offload_netdev, 648602144c2SJakub Kicinski offdev_netdevs); 649602144c2SJakub Kicinski if (altdev) { 650602144c2SJakub Kicinski list_for_each_entry(offload, &ondev->progs, offloads) 651602144c2SJakub Kicinski offload->netdev = altdev->netdev; 652602144c2SJakub Kicinski list_splice_init(&ondev->progs, &altdev->progs); 653602144c2SJakub Kicinski 654602144c2SJakub Kicinski list_for_each_entry(offmap, &ondev->maps, offloads) 655602144c2SJakub Kicinski offmap->netdev = altdev->netdev; 656602144c2SJakub Kicinski list_splice_init(&ondev->maps, &altdev->maps); 657602144c2SJakub Kicinski } else { 6589fd7c555SJakub Kicinski list_for_each_entry_safe(offload, ptmp, &ondev->progs, offloads) 6599fd7c555SJakub Kicinski __bpf_prog_offload_destroy(offload->prog); 6609fd7c555SJakub Kicinski list_for_each_entry_safe(offmap, mtmp, &ondev->maps, offloads) 6619fd7c555SJakub Kicinski __bpf_map_offload_destroy(offmap); 662602144c2SJakub Kicinski } 6639fd7c555SJakub Kicinski 6649fd7c555SJakub Kicinski WARN_ON(!list_empty(&ondev->progs)); 6659fd7c555SJakub Kicinski WARN_ON(!list_empty(&ondev->maps)); 6669fd7c555SJakub Kicinski kfree(ondev); 6679fd7c555SJakub Kicinski unlock: 668e0d3974aSJakub Kicinski up_write(&bpf_devs_lock); 669ab3f0063SJakub Kicinski } 6709fd7c555SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_netdev_unregister); 671602144c2SJakub Kicinski 6721385d755SQuentin Monnet struct bpf_offload_dev * 673dd27c2e3SJakub Kicinski bpf_offload_dev_create(const struct bpf_prog_offload_ops *ops, void *priv) 674602144c2SJakub Kicinski { 675602144c2SJakub Kicinski struct bpf_offload_dev *offdev; 676602144c2SJakub Kicinski int err; 677602144c2SJakub Kicinski 678602144c2SJakub Kicinski down_write(&bpf_devs_lock); 679602144c2SJakub Kicinski if (!offdevs_inited) { 680602144c2SJakub Kicinski err = rhashtable_init(&offdevs, &offdevs_params); 681d0fbb51dSDan Carpenter if (err) { 682d0fbb51dSDan Carpenter up_write(&bpf_devs_lock); 683602144c2SJakub Kicinski return ERR_PTR(err); 684d0fbb51dSDan Carpenter } 685602144c2SJakub Kicinski offdevs_inited = true; 686602144c2SJakub Kicinski } 687602144c2SJakub Kicinski up_write(&bpf_devs_lock); 688602144c2SJakub Kicinski 689602144c2SJakub Kicinski offdev = kzalloc(sizeof(*offdev), GFP_KERNEL); 690602144c2SJakub Kicinski if (!offdev) 691602144c2SJakub Kicinski return ERR_PTR(-ENOMEM); 692602144c2SJakub Kicinski 6931385d755SQuentin Monnet offdev->ops = ops; 694dd27c2e3SJakub Kicinski offdev->priv = priv; 695602144c2SJakub Kicinski INIT_LIST_HEAD(&offdev->netdevs); 696602144c2SJakub Kicinski 697602144c2SJakub Kicinski return offdev; 698602144c2SJakub Kicinski } 699602144c2SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_create); 700602144c2SJakub Kicinski 701602144c2SJakub Kicinski void bpf_offload_dev_destroy(struct bpf_offload_dev *offdev) 702602144c2SJakub Kicinski { 703602144c2SJakub Kicinski WARN_ON(!list_empty(&offdev->netdevs)); 704602144c2SJakub Kicinski kfree(offdev); 705602144c2SJakub Kicinski } 706602144c2SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_destroy); 707dd27c2e3SJakub Kicinski 708dd27c2e3SJakub Kicinski void *bpf_offload_dev_priv(struct bpf_offload_dev *offdev) 709dd27c2e3SJakub Kicinski { 710dd27c2e3SJakub Kicinski return offdev->priv; 711dd27c2e3SJakub Kicinski } 712dd27c2e3SJakub Kicinski EXPORT_SYMBOL_GPL(bpf_offload_dev_priv); 713