12874c5fdSThomas Gleixner // SPDX-License-Identifier: GPL-2.0-or-later
286da71b5SJamal Hadi Salim /*
386da71b5SJamal Hadi Salim * net/sched/act_skbmod.c skb data modifier
486da71b5SJamal Hadi Salim *
586da71b5SJamal Hadi Salim * Copyright (c) 2016 Jamal Hadi Salim <jhs@mojatatu.com>
686da71b5SJamal Hadi Salim */
786da71b5SJamal Hadi Salim
886da71b5SJamal Hadi Salim #include <linux/module.h>
9727d6a8bSPeilin Ye #include <linux/if_arp.h>
1086da71b5SJamal Hadi Salim #include <linux/init.h>
1186da71b5SJamal Hadi Salim #include <linux/kernel.h>
1286da71b5SJamal Hadi Salim #include <linux/skbuff.h>
1386da71b5SJamal Hadi Salim #include <linux/rtnetlink.h>
1456af5e74SPeilin Ye #include <net/inet_ecn.h>
1586da71b5SJamal Hadi Salim #include <net/netlink.h>
1686da71b5SJamal Hadi Salim #include <net/pkt_sched.h>
177c3d825dSDavide Caratti #include <net/pkt_cls.h>
18871cf386SPedro Tammela #include <net/tc_wrapper.h>
1986da71b5SJamal Hadi Salim
2086da71b5SJamal Hadi Salim #include <linux/tc_act/tc_skbmod.h>
2186da71b5SJamal Hadi Salim #include <net/tc_act/tc_skbmod.h>
2286da71b5SJamal Hadi Salim
2386da71b5SJamal Hadi Salim static struct tc_action_ops act_skbmod_ops;
2486da71b5SJamal Hadi Salim
tcf_skbmod_act(struct sk_buff * skb,const struct tc_action * a,struct tcf_result * res)25871cf386SPedro Tammela TC_INDIRECT_SCOPE int tcf_skbmod_act(struct sk_buff *skb,
26871cf386SPedro Tammela const struct tc_action *a,
2786da71b5SJamal Hadi Salim struct tcf_result *res)
2886da71b5SJamal Hadi Salim {
2986da71b5SJamal Hadi Salim struct tcf_skbmod *d = to_skbmod(a);
3056af5e74SPeilin Ye int action, max_edit_len, err;
3186da71b5SJamal Hadi Salim struct tcf_skbmod_params *p;
3286da71b5SJamal Hadi Salim u64 flags;
3386da71b5SJamal Hadi Salim
3486da71b5SJamal Hadi Salim tcf_lastuse_update(&d->tcf_tm);
3550dc9a85SAhmed S. Darwish bstats_update(this_cpu_ptr(d->common.cpu_bstats), skb);
3686da71b5SJamal Hadi Salim
37727d6a8bSPeilin Ye action = READ_ONCE(d->tcf_action);
38727d6a8bSPeilin Ye if (unlikely(action == TC_ACT_SHOT))
39727d6a8bSPeilin Ye goto drop;
40727d6a8bSPeilin Ye
4156af5e74SPeilin Ye max_edit_len = skb_mac_header_len(skb);
4256af5e74SPeilin Ye p = rcu_dereference_bh(d->skbmod_p);
4356af5e74SPeilin Ye flags = p->flags;
44727d6a8bSPeilin Ye
4556af5e74SPeilin Ye /* tcf_skbmod_init() guarantees "flags" to be one of the following:
4656af5e74SPeilin Ye * 1. a combination of SKBMOD_F_{DMAC,SMAC,ETYPE}
4756af5e74SPeilin Ye * 2. SKBMOD_F_SWAPMAC
4856af5e74SPeilin Ye * 3. SKBMOD_F_ECN
4956af5e74SPeilin Ye * SKBMOD_F_ECN only works with IP packets; all other flags only work with Ethernet
5056af5e74SPeilin Ye * packets.
5186da71b5SJamal Hadi Salim */
5256af5e74SPeilin Ye if (flags == SKBMOD_F_ECN) {
5356af5e74SPeilin Ye switch (skb_protocol(skb, true)) {
5456af5e74SPeilin Ye case cpu_to_be16(ETH_P_IP):
5556af5e74SPeilin Ye case cpu_to_be16(ETH_P_IPV6):
5656af5e74SPeilin Ye max_edit_len += skb_network_header_len(skb);
5756af5e74SPeilin Ye break;
5856af5e74SPeilin Ye default:
5956af5e74SPeilin Ye goto out;
6056af5e74SPeilin Ye }
6156af5e74SPeilin Ye } else if (!skb->dev || skb->dev->type != ARPHRD_ETHER) {
6256af5e74SPeilin Ye goto out;
6356af5e74SPeilin Ye }
6456af5e74SPeilin Ye
6556af5e74SPeilin Ye err = skb_ensure_writable(skb, max_edit_len);
667fd4b288SPaolo Abeni if (unlikely(err)) /* best policy is to drop on the floor */
677fd4b288SPaolo Abeni goto drop;
6886da71b5SJamal Hadi Salim
6986da71b5SJamal Hadi Salim if (flags & SKBMOD_F_DMAC)
7086da71b5SJamal Hadi Salim ether_addr_copy(eth_hdr(skb)->h_dest, p->eth_dst);
7186da71b5SJamal Hadi Salim if (flags & SKBMOD_F_SMAC)
7286da71b5SJamal Hadi Salim ether_addr_copy(eth_hdr(skb)->h_source, p->eth_src);
7386da71b5SJamal Hadi Salim if (flags & SKBMOD_F_ETYPE)
7486da71b5SJamal Hadi Salim eth_hdr(skb)->h_proto = p->eth_type;
7586da71b5SJamal Hadi Salim
7686da71b5SJamal Hadi Salim if (flags & SKBMOD_F_SWAPMAC) {
7786da71b5SJamal Hadi Salim u16 tmpaddr[ETH_ALEN / 2]; /* ether_addr_copy() requirement */
7886da71b5SJamal Hadi Salim /*XXX: I am sure we can come up with more efficient swapping*/
7986da71b5SJamal Hadi Salim ether_addr_copy((u8 *)tmpaddr, eth_hdr(skb)->h_dest);
8086da71b5SJamal Hadi Salim ether_addr_copy(eth_hdr(skb)->h_dest, eth_hdr(skb)->h_source);
8186da71b5SJamal Hadi Salim ether_addr_copy(eth_hdr(skb)->h_source, (u8 *)tmpaddr);
8286da71b5SJamal Hadi Salim }
8386da71b5SJamal Hadi Salim
8456af5e74SPeilin Ye if (flags & SKBMOD_F_ECN)
8556af5e74SPeilin Ye INET_ECN_set_ce(skb);
8656af5e74SPeilin Ye
8756af5e74SPeilin Ye out:
8886da71b5SJamal Hadi Salim return action;
897fd4b288SPaolo Abeni
907fd4b288SPaolo Abeni drop:
917fd4b288SPaolo Abeni qstats_overlimit_inc(this_cpu_ptr(d->common.cpu_qstats));
927fd4b288SPaolo Abeni return TC_ACT_SHOT;
9386da71b5SJamal Hadi Salim }
9486da71b5SJamal Hadi Salim
9586da71b5SJamal Hadi Salim static const struct nla_policy skbmod_policy[TCA_SKBMOD_MAX + 1] = {
9686da71b5SJamal Hadi Salim [TCA_SKBMOD_PARMS] = { .len = sizeof(struct tc_skbmod) },
9786da71b5SJamal Hadi Salim [TCA_SKBMOD_DMAC] = { .len = ETH_ALEN },
9886da71b5SJamal Hadi Salim [TCA_SKBMOD_SMAC] = { .len = ETH_ALEN },
9986da71b5SJamal Hadi Salim [TCA_SKBMOD_ETYPE] = { .type = NLA_U16 },
10086da71b5SJamal Hadi Salim };
10186da71b5SJamal Hadi Salim
tcf_skbmod_init(struct net * net,struct nlattr * nla,struct nlattr * est,struct tc_action ** a,struct tcf_proto * tp,u32 flags,struct netlink_ext_ack * extack)10286da71b5SJamal Hadi Salim static int tcf_skbmod_init(struct net *net, struct nlattr *nla,
10386da71b5SJamal Hadi Salim struct nlattr *est, struct tc_action **a,
104abbb0d33SVlad Buslov struct tcf_proto *tp, u32 flags,
105789871bbSVlad Buslov struct netlink_ext_ack *extack)
10686da71b5SJamal Hadi Salim {
107acd0a7abSZhengchao Shao struct tc_action_net *tn = net_generic(net, act_skbmod_ops.net_id);
108695176bfSCong Wang bool ovr = flags & TCA_ACT_FLAGS_REPLACE;
109695176bfSCong Wang bool bind = flags & TCA_ACT_FLAGS_BIND;
11086da71b5SJamal Hadi Salim struct nlattr *tb[TCA_SKBMOD_MAX + 1];
11186da71b5SJamal Hadi Salim struct tcf_skbmod_params *p, *p_old;
1127c3d825dSDavide Caratti struct tcf_chain *goto_ch = NULL;
11386da71b5SJamal Hadi Salim struct tc_skbmod *parm;
1147be8ef2cSDmytro Linkin u32 lflags = 0, index;
11586da71b5SJamal Hadi Salim struct tcf_skbmod *d;
11686da71b5SJamal Hadi Salim bool exists = false;
11786da71b5SJamal Hadi Salim u8 *daddr = NULL;
11886da71b5SJamal Hadi Salim u8 *saddr = NULL;
11986da71b5SJamal Hadi Salim u16 eth_type = 0;
12086da71b5SJamal Hadi Salim int ret = 0, err;
12186da71b5SJamal Hadi Salim
12286da71b5SJamal Hadi Salim if (!nla)
12386da71b5SJamal Hadi Salim return -EINVAL;
12486da71b5SJamal Hadi Salim
1258cb08174SJohannes Berg err = nla_parse_nested_deprecated(tb, TCA_SKBMOD_MAX, nla,
1268cb08174SJohannes Berg skbmod_policy, NULL);
12786da71b5SJamal Hadi Salim if (err < 0)
12886da71b5SJamal Hadi Salim return err;
12986da71b5SJamal Hadi Salim
13086da71b5SJamal Hadi Salim if (!tb[TCA_SKBMOD_PARMS])
13186da71b5SJamal Hadi Salim return -EINVAL;
13286da71b5SJamal Hadi Salim
13386da71b5SJamal Hadi Salim if (tb[TCA_SKBMOD_DMAC]) {
13486da71b5SJamal Hadi Salim daddr = nla_data(tb[TCA_SKBMOD_DMAC]);
13586da71b5SJamal Hadi Salim lflags |= SKBMOD_F_DMAC;
13686da71b5SJamal Hadi Salim }
13786da71b5SJamal Hadi Salim
13886da71b5SJamal Hadi Salim if (tb[TCA_SKBMOD_SMAC]) {
13986da71b5SJamal Hadi Salim saddr = nla_data(tb[TCA_SKBMOD_SMAC]);
14086da71b5SJamal Hadi Salim lflags |= SKBMOD_F_SMAC;
14186da71b5SJamal Hadi Salim }
14286da71b5SJamal Hadi Salim
14386da71b5SJamal Hadi Salim if (tb[TCA_SKBMOD_ETYPE]) {
14486da71b5SJamal Hadi Salim eth_type = nla_get_u16(tb[TCA_SKBMOD_ETYPE]);
14586da71b5SJamal Hadi Salim lflags |= SKBMOD_F_ETYPE;
14686da71b5SJamal Hadi Salim }
14786da71b5SJamal Hadi Salim
14886da71b5SJamal Hadi Salim parm = nla_data(tb[TCA_SKBMOD_PARMS]);
1497be8ef2cSDmytro Linkin index = parm->index;
15086da71b5SJamal Hadi Salim if (parm->flags & SKBMOD_F_SWAPMAC)
15186da71b5SJamal Hadi Salim lflags = SKBMOD_F_SWAPMAC;
15256af5e74SPeilin Ye if (parm->flags & SKBMOD_F_ECN)
15356af5e74SPeilin Ye lflags = SKBMOD_F_ECN;
15486da71b5SJamal Hadi Salim
1557be8ef2cSDmytro Linkin err = tcf_idr_check_alloc(tn, &index, a, bind);
1560190c1d4SVlad Buslov if (err < 0)
1570190c1d4SVlad Buslov return err;
1580190c1d4SVlad Buslov exists = err;
15986da71b5SJamal Hadi Salim if (exists && bind)
16086da71b5SJamal Hadi Salim return 0;
16186da71b5SJamal Hadi Salim
162a52956dfSRoman Mashak if (!lflags) {
163a52956dfSRoman Mashak if (exists)
164a52956dfSRoman Mashak tcf_idr_release(*a, bind);
1650190c1d4SVlad Buslov else
1667be8ef2cSDmytro Linkin tcf_idr_cleanup(tn, index);
16786da71b5SJamal Hadi Salim return -EINVAL;
168a52956dfSRoman Mashak }
16986da71b5SJamal Hadi Salim
17086da71b5SJamal Hadi Salim if (!exists) {
1717be8ef2cSDmytro Linkin ret = tcf_idr_create(tn, index, est, a,
17240bd094dSBaowen Zheng &act_skbmod_ops, bind, true, flags);
1730190c1d4SVlad Buslov if (ret) {
1747be8ef2cSDmytro Linkin tcf_idr_cleanup(tn, index);
17586da71b5SJamal Hadi Salim return ret;
1760190c1d4SVlad Buslov }
17786da71b5SJamal Hadi Salim
17886da71b5SJamal Hadi Salim ret = ACT_P_CREATED;
1794e8ddd7fSVlad Buslov } else if (!ovr) {
18065a206c0SChris Mi tcf_idr_release(*a, bind);
18186da71b5SJamal Hadi Salim return -EEXIST;
18286da71b5SJamal Hadi Salim }
1837c3d825dSDavide Caratti err = tcf_action_check_ctrlact(parm->action, tp, &goto_ch, extack);
1847c3d825dSDavide Caratti if (err < 0)
1857c3d825dSDavide Caratti goto release_idr;
18686da71b5SJamal Hadi Salim
18786da71b5SJamal Hadi Salim d = to_skbmod(*a);
18886da71b5SJamal Hadi Salim
18986da71b5SJamal Hadi Salim p = kzalloc(sizeof(struct tcf_skbmod_params), GFP_KERNEL);
19086da71b5SJamal Hadi Salim if (unlikely(!p)) {
1917c3d825dSDavide Caratti err = -ENOMEM;
1927c3d825dSDavide Caratti goto put_chain;
19386da71b5SJamal Hadi Salim }
19486da71b5SJamal Hadi Salim
19586da71b5SJamal Hadi Salim p->flags = lflags;
19686da71b5SJamal Hadi Salim
19786da71b5SJamal Hadi Salim if (ovr)
19886da71b5SJamal Hadi Salim spin_lock_bh(&d->tcf_lock);
199c8814552SVlad Buslov /* Protected by tcf_lock if overwriting existing action. */
2007c3d825dSDavide Caratti goto_ch = tcf_action_set_ctrlact(*a, parm->action, goto_ch);
201c8814552SVlad Buslov p_old = rcu_dereference_protected(d->skbmod_p, 1);
20286da71b5SJamal Hadi Salim
20386da71b5SJamal Hadi Salim if (lflags & SKBMOD_F_DMAC)
20486da71b5SJamal Hadi Salim ether_addr_copy(p->eth_dst, daddr);
20586da71b5SJamal Hadi Salim if (lflags & SKBMOD_F_SMAC)
20686da71b5SJamal Hadi Salim ether_addr_copy(p->eth_src, saddr);
20786da71b5SJamal Hadi Salim if (lflags & SKBMOD_F_ETYPE)
20886da71b5SJamal Hadi Salim p->eth_type = htons(eth_type);
20986da71b5SJamal Hadi Salim
21086da71b5SJamal Hadi Salim rcu_assign_pointer(d->skbmod_p, p);
21186da71b5SJamal Hadi Salim if (ovr)
21286da71b5SJamal Hadi Salim spin_unlock_bh(&d->tcf_lock);
21386da71b5SJamal Hadi Salim
21486da71b5SJamal Hadi Salim if (p_old)
21586da71b5SJamal Hadi Salim kfree_rcu(p_old, rcu);
2167c3d825dSDavide Caratti if (goto_ch)
2177c3d825dSDavide Caratti tcf_chain_put_by_act(goto_ch);
21886da71b5SJamal Hadi Salim
21986da71b5SJamal Hadi Salim return ret;
2207c3d825dSDavide Caratti put_chain:
2217c3d825dSDavide Caratti if (goto_ch)
2227c3d825dSDavide Caratti tcf_chain_put_by_act(goto_ch);
2237c3d825dSDavide Caratti release_idr:
2247c3d825dSDavide Caratti tcf_idr_release(*a, bind);
2257c3d825dSDavide Caratti return err;
22686da71b5SJamal Hadi Salim }
22786da71b5SJamal Hadi Salim
tcf_skbmod_cleanup(struct tc_action * a)2289a63b255SCong Wang static void tcf_skbmod_cleanup(struct tc_action *a)
22986da71b5SJamal Hadi Salim {
23086da71b5SJamal Hadi Salim struct tcf_skbmod *d = to_skbmod(a);
23186da71b5SJamal Hadi Salim struct tcf_skbmod_params *p;
23286da71b5SJamal Hadi Salim
23386da71b5SJamal Hadi Salim p = rcu_dereference_protected(d->skbmod_p, 1);
2342d433610SDavide Caratti if (p)
23586da71b5SJamal Hadi Salim kfree_rcu(p, rcu);
23686da71b5SJamal Hadi Salim }
23786da71b5SJamal Hadi Salim
tcf_skbmod_dump(struct sk_buff * skb,struct tc_action * a,int bind,int ref)23886da71b5SJamal Hadi Salim static int tcf_skbmod_dump(struct sk_buff *skb, struct tc_action *a,
23986da71b5SJamal Hadi Salim int bind, int ref)
24086da71b5SJamal Hadi Salim {
24186da71b5SJamal Hadi Salim struct tcf_skbmod *d = to_skbmod(a);
24286da71b5SJamal Hadi Salim unsigned char *b = skb_tail_pointer(skb);
243c8814552SVlad Buslov struct tcf_skbmod_params *p;
244*729ad2acSEric Dumazet struct tc_skbmod opt;
24586da71b5SJamal Hadi Salim struct tcf_t t;
24686da71b5SJamal Hadi Salim
247*729ad2acSEric Dumazet memset(&opt, 0, sizeof(opt));
248*729ad2acSEric Dumazet opt.index = d->tcf_index;
249*729ad2acSEric Dumazet opt.refcnt = refcount_read(&d->tcf_refcnt) - ref,
250*729ad2acSEric Dumazet opt.bindcnt = atomic_read(&d->tcf_bindcnt) - bind;
251c8814552SVlad Buslov spin_lock_bh(&d->tcf_lock);
252c8814552SVlad Buslov opt.action = d->tcf_action;
253c8814552SVlad Buslov p = rcu_dereference_protected(d->skbmod_p,
254c8814552SVlad Buslov lockdep_is_held(&d->tcf_lock));
25586da71b5SJamal Hadi Salim opt.flags = p->flags;
25686da71b5SJamal Hadi Salim if (nla_put(skb, TCA_SKBMOD_PARMS, sizeof(opt), &opt))
25786da71b5SJamal Hadi Salim goto nla_put_failure;
25886da71b5SJamal Hadi Salim if ((p->flags & SKBMOD_F_DMAC) &&
25986da71b5SJamal Hadi Salim nla_put(skb, TCA_SKBMOD_DMAC, ETH_ALEN, p->eth_dst))
26086da71b5SJamal Hadi Salim goto nla_put_failure;
26186da71b5SJamal Hadi Salim if ((p->flags & SKBMOD_F_SMAC) &&
26286da71b5SJamal Hadi Salim nla_put(skb, TCA_SKBMOD_SMAC, ETH_ALEN, p->eth_src))
26386da71b5SJamal Hadi Salim goto nla_put_failure;
26486da71b5SJamal Hadi Salim if ((p->flags & SKBMOD_F_ETYPE) &&
26586da71b5SJamal Hadi Salim nla_put_u16(skb, TCA_SKBMOD_ETYPE, ntohs(p->eth_type)))
26686da71b5SJamal Hadi Salim goto nla_put_failure;
26786da71b5SJamal Hadi Salim
26886da71b5SJamal Hadi Salim tcf_tm_dump(&t, &d->tcf_tm);
26986da71b5SJamal Hadi Salim if (nla_put_64bit(skb, TCA_SKBMOD_TM, sizeof(t), &t, TCA_SKBMOD_PAD))
27086da71b5SJamal Hadi Salim goto nla_put_failure;
27186da71b5SJamal Hadi Salim
272c8814552SVlad Buslov spin_unlock_bh(&d->tcf_lock);
27386da71b5SJamal Hadi Salim return skb->len;
27486da71b5SJamal Hadi Salim nla_put_failure:
275c8814552SVlad Buslov spin_unlock_bh(&d->tcf_lock);
27686da71b5SJamal Hadi Salim nlmsg_trim(skb, b);
27786da71b5SJamal Hadi Salim return -1;
27886da71b5SJamal Hadi Salim }
27986da71b5SJamal Hadi Salim
28086da71b5SJamal Hadi Salim static struct tc_action_ops act_skbmod_ops = {
28186da71b5SJamal Hadi Salim .kind = "skbmod",
282eddd2cf1SEli Cohen .id = TCA_ACT_SKBMOD,
28386da71b5SJamal Hadi Salim .owner = THIS_MODULE,
284353d2c25SJamal Hadi Salim .act = tcf_skbmod_act,
28586da71b5SJamal Hadi Salim .dump = tcf_skbmod_dump,
28686da71b5SJamal Hadi Salim .init = tcf_skbmod_init,
28786da71b5SJamal Hadi Salim .cleanup = tcf_skbmod_cleanup,
28886da71b5SJamal Hadi Salim .size = sizeof(struct tcf_skbmod),
28986da71b5SJamal Hadi Salim };
29086da71b5SJamal Hadi Salim
skbmod_init_net(struct net * net)29186da71b5SJamal Hadi Salim static __net_init int skbmod_init_net(struct net *net)
29286da71b5SJamal Hadi Salim {
293acd0a7abSZhengchao Shao struct tc_action_net *tn = net_generic(net, act_skbmod_ops.net_id);
29486da71b5SJamal Hadi Salim
295981471bdSCong Wang return tc_action_net_init(net, tn, &act_skbmod_ops);
29686da71b5SJamal Hadi Salim }
29786da71b5SJamal Hadi Salim
skbmod_exit_net(struct list_head * net_list)298039af9c6SCong Wang static void __net_exit skbmod_exit_net(struct list_head *net_list)
29986da71b5SJamal Hadi Salim {
300acd0a7abSZhengchao Shao tc_action_net_exit(net_list, act_skbmod_ops.net_id);
30186da71b5SJamal Hadi Salim }
30286da71b5SJamal Hadi Salim
30386da71b5SJamal Hadi Salim static struct pernet_operations skbmod_net_ops = {
30486da71b5SJamal Hadi Salim .init = skbmod_init_net,
305039af9c6SCong Wang .exit_batch = skbmod_exit_net,
306acd0a7abSZhengchao Shao .id = &act_skbmod_ops.net_id,
30786da71b5SJamal Hadi Salim .size = sizeof(struct tc_action_net),
30886da71b5SJamal Hadi Salim };
30986da71b5SJamal Hadi Salim
31086da71b5SJamal Hadi Salim MODULE_AUTHOR("Jamal Hadi Salim, <jhs@mojatatu.com>");
31186da71b5SJamal Hadi Salim MODULE_DESCRIPTION("SKB data mod-ing");
31286da71b5SJamal Hadi Salim MODULE_LICENSE("GPL");
31386da71b5SJamal Hadi Salim
skbmod_init_module(void)31486da71b5SJamal Hadi Salim static int __init skbmod_init_module(void)
31586da71b5SJamal Hadi Salim {
31686da71b5SJamal Hadi Salim return tcf_register_action(&act_skbmod_ops, &skbmod_net_ops);
31786da71b5SJamal Hadi Salim }
31886da71b5SJamal Hadi Salim
skbmod_cleanup_module(void)31986da71b5SJamal Hadi Salim static void __exit skbmod_cleanup_module(void)
32086da71b5SJamal Hadi Salim {
32186da71b5SJamal Hadi Salim tcf_unregister_action(&act_skbmod_ops, &skbmod_net_ops);
32286da71b5SJamal Hadi Salim }
32386da71b5SJamal Hadi Salim
32486da71b5SJamal Hadi Salim module_init(skbmod_init_module);
32586da71b5SJamal Hadi Salim module_exit(skbmod_cleanup_module);
326