13b49e2e9SPablo Neira Ayuso #ifndef _NF_FLOW_TABLE_H
23b49e2e9SPablo Neira Ayuso #define _NF_FLOW_TABLE_H
33b49e2e9SPablo Neira Ayuso 
4ac2a6666SPablo Neira Ayuso #include <linux/in.h>
5ac2a6666SPablo Neira Ayuso #include <linux/in6.h>
6ac2a6666SPablo Neira Ayuso #include <linux/netdevice.h>
70eb71a9dSNeilBrown #include <linux/rhashtable-types.h>
8ac2a6666SPablo Neira Ayuso #include <linux/rcupdate.h>
9a1b2f04eSJeremy Sowden #include <linux/netfilter.h>
10af81f9e7SFelix Fietkau #include <linux/netfilter/nf_conntrack_tuple_common.h>
118bb69f3bSPablo Neira Ayuso #include <net/flow_offload.h>
12ac2a6666SPablo Neira Ayuso #include <net/dst.h>
133b49e2e9SPablo Neira Ayuso 
143b49e2e9SPablo Neira Ayuso struct nf_flowtable;
15c29f74e0SPablo Neira Ayuso struct nf_flow_rule;
16c29f74e0SPablo Neira Ayuso struct flow_offload;
17c29f74e0SPablo Neira Ayuso enum flow_offload_tuple_dir;
183b49e2e9SPablo Neira Ayuso 
199c26ba9bSPaul Blakey struct nf_flow_key {
209c26ba9bSPaul Blakey 	struct flow_dissector_key_meta			meta;
219c26ba9bSPaul Blakey 	struct flow_dissector_key_control		control;
22cfab6dbdSwenxu 	struct flow_dissector_key_control		enc_control;
239c26ba9bSPaul Blakey 	struct flow_dissector_key_basic			basic;
249c26ba9bSPaul Blakey 	union {
259c26ba9bSPaul Blakey 		struct flow_dissector_key_ipv4_addrs	ipv4;
269c26ba9bSPaul Blakey 		struct flow_dissector_key_ipv6_addrs	ipv6;
279c26ba9bSPaul Blakey 	};
28cfab6dbdSwenxu 	struct flow_dissector_key_keyid			enc_key_id;
29cfab6dbdSwenxu 	union {
30cfab6dbdSwenxu 		struct flow_dissector_key_ipv4_addrs	enc_ipv4;
31cfab6dbdSwenxu 		struct flow_dissector_key_ipv6_addrs	enc_ipv6;
32cfab6dbdSwenxu 	};
339c26ba9bSPaul Blakey 	struct flow_dissector_key_tcp			tcp;
349c26ba9bSPaul Blakey 	struct flow_dissector_key_ports			tp;
359c26ba9bSPaul Blakey } __aligned(BITS_PER_LONG / 8); /* Ensure that we can do comparisons as longs. */
369c26ba9bSPaul Blakey 
379c26ba9bSPaul Blakey struct nf_flow_match {
389c26ba9bSPaul Blakey 	struct flow_dissector	dissector;
399c26ba9bSPaul Blakey 	struct nf_flow_key	key;
409c26ba9bSPaul Blakey 	struct nf_flow_key	mask;
419c26ba9bSPaul Blakey };
429c26ba9bSPaul Blakey 
439c26ba9bSPaul Blakey struct nf_flow_rule {
449c26ba9bSPaul Blakey 	struct nf_flow_match	match;
459c26ba9bSPaul Blakey 	struct flow_rule	*rule;
469c26ba9bSPaul Blakey };
479c26ba9bSPaul Blakey 
483b49e2e9SPablo Neira Ayuso struct nf_flowtable_type {
493b49e2e9SPablo Neira Ayuso 	struct list_head		list;
503b49e2e9SPablo Neira Ayuso 	int				family;
51a268de77SFelix Fietkau 	int				(*init)(struct nf_flowtable *ft);
528bb69f3bSPablo Neira Ayuso 	int				(*setup)(struct nf_flowtable *ft,
538bb69f3bSPablo Neira Ayuso 						 struct net_device *dev,
548bb69f3bSPablo Neira Ayuso 						 enum flow_block_command cmd);
55c29f74e0SPablo Neira Ayuso 	int				(*action)(struct net *net,
56c29f74e0SPablo Neira Ayuso 						  const struct flow_offload *flow,
57c29f74e0SPablo Neira Ayuso 						  enum flow_offload_tuple_dir dir,
58c29f74e0SPablo Neira Ayuso 						  struct nf_flow_rule *flow_rule);
59b408c5b0SPablo Neira Ayuso 	void				(*free)(struct nf_flowtable *ft);
603b49e2e9SPablo Neira Ayuso 	nf_hookfn			*hook;
613b49e2e9SPablo Neira Ayuso 	struct module			*owner;
623b49e2e9SPablo Neira Ayuso };
633b49e2e9SPablo Neira Ayuso 
648bb69f3bSPablo Neira Ayuso enum nf_flowtable_flags {
65cfbd1125SPablo Neira Ayuso 	NF_FLOWTABLE_HW_OFFLOAD		= 0x1,	/* NFT_FLOWTABLE_HW_OFFLOAD */
6653c2b289SPablo Neira Ayuso 	NF_FLOWTABLE_COUNTER		= 0x2,	/* NFT_FLOWTABLE_COUNTER */
678bb69f3bSPablo Neira Ayuso };
688bb69f3bSPablo Neira Ayuso 
693b49e2e9SPablo Neira Ayuso struct nf_flowtable {
7084453a90SFelix Fietkau 	struct list_head		list;
713b49e2e9SPablo Neira Ayuso 	struct rhashtable		rhashtable;
7271a8a63bSPablo Neira Ayuso 	int				priority;
733b49e2e9SPablo Neira Ayuso 	const struct nf_flowtable_type	*type;
743b49e2e9SPablo Neira Ayuso 	struct delayed_work		gc_work;
758bb69f3bSPablo Neira Ayuso 	unsigned int			flags;
768bb69f3bSPablo Neira Ayuso 	struct flow_block		flow_block;
77422c032aSPaul Blakey 	struct rw_semaphore		flow_block_lock; /* Guards flow_block */
788bb69f3bSPablo Neira Ayuso 	possible_net_t			net;
793b49e2e9SPablo Neira Ayuso };
803b49e2e9SPablo Neira Ayuso 
81a5449cdcSPablo Neira Ayuso static inline bool nf_flowtable_hw_offload(struct nf_flowtable *flowtable)
82a5449cdcSPablo Neira Ayuso {
83a5449cdcSPablo Neira Ayuso 	return flowtable->flags & NF_FLOWTABLE_HW_OFFLOAD;
84a5449cdcSPablo Neira Ayuso }
85a5449cdcSPablo Neira Ayuso 
86ac2a6666SPablo Neira Ayuso enum flow_offload_tuple_dir {
87af81f9e7SFelix Fietkau 	FLOW_OFFLOAD_DIR_ORIGINAL = IP_CT_DIR_ORIGINAL,
88af81f9e7SFelix Fietkau 	FLOW_OFFLOAD_DIR_REPLY = IP_CT_DIR_REPLY,
89ac2a6666SPablo Neira Ayuso };
904f08f173SPablo Neira Ayuso #define FLOW_OFFLOAD_DIR_MAX	IP_CT_DIR_MAX
91ac2a6666SPablo Neira Ayuso 
925139c0c0SPablo Neira Ayuso enum flow_offload_xmit_type {
935139c0c0SPablo Neira Ayuso 	FLOW_OFFLOAD_XMIT_NEIGH		= 0,
945139c0c0SPablo Neira Ayuso 	FLOW_OFFLOAD_XMIT_XFRM,
957a27f6abSPablo Neira Ayuso 	FLOW_OFFLOAD_XMIT_DIRECT,
965139c0c0SPablo Neira Ayuso };
975139c0c0SPablo Neira Ayuso 
984cd91f7cSPablo Neira Ayuso #define NF_FLOW_TABLE_ENCAP_MAX		2
994cd91f7cSPablo Neira Ayuso 
100ac2a6666SPablo Neira Ayuso struct flow_offload_tuple {
101ac2a6666SPablo Neira Ayuso 	union {
102ac2a6666SPablo Neira Ayuso 		struct in_addr		src_v4;
103ac2a6666SPablo Neira Ayuso 		struct in6_addr		src_v6;
104ac2a6666SPablo Neira Ayuso 	};
105ac2a6666SPablo Neira Ayuso 	union {
106ac2a6666SPablo Neira Ayuso 		struct in_addr		dst_v4;
107ac2a6666SPablo Neira Ayuso 		struct in6_addr		dst_v6;
108ac2a6666SPablo Neira Ayuso 	};
109ac2a6666SPablo Neira Ayuso 	struct {
110ac2a6666SPablo Neira Ayuso 		__be16			src_port;
111ac2a6666SPablo Neira Ayuso 		__be16			dst_port;
112ac2a6666SPablo Neira Ayuso 	};
113ac2a6666SPablo Neira Ayuso 
114ac2a6666SPablo Neira Ayuso 	int				iifidx;
115ac2a6666SPablo Neira Ayuso 
116ac2a6666SPablo Neira Ayuso 	u8				l3proto;
117ac2a6666SPablo Neira Ayuso 	u8				l4proto;
1184cd91f7cSPablo Neira Ayuso 	struct {
1194cd91f7cSPablo Neira Ayuso 		u16			id;
1204cd91f7cSPablo Neira Ayuso 		__be16			proto;
1214cd91f7cSPablo Neira Ayuso 	} encap[NF_FLOW_TABLE_ENCAP_MAX];
122dbc859d9SPablo Neira Ayuso 
123dbc859d9SPablo Neira Ayuso 	/* All members above are keys for lookups, see flow_offload_hash(). */
124dbc859d9SPablo Neira Ayuso 	struct { }			__hash;
125dbc859d9SPablo Neira Ayuso 
126*26267bf9SFelix Fietkau 	u8				dir:2,
1274cd91f7cSPablo Neira Ayuso 					xmit_type:2,
128*26267bf9SFelix Fietkau 					encap_num:2,
129*26267bf9SFelix Fietkau 					in_vlan_ingress:2;
1304f3780c0SFelix Fietkau 	u16				mtu;
1317a27f6abSPablo Neira Ayuso 	union {
132ac2a6666SPablo Neira Ayuso 		struct dst_entry	*dst_cache;
1337a27f6abSPablo Neira Ayuso 		struct {
1347a27f6abSPablo Neira Ayuso 			u32		ifidx;
13573f97025SPablo Neira Ayuso 			u32		hw_ifidx;
1367a27f6abSPablo Neira Ayuso 			u8		h_source[ETH_ALEN];
1377a27f6abSPablo Neira Ayuso 			u8		h_dest[ETH_ALEN];
1387a27f6abSPablo Neira Ayuso 		} out;
1397a27f6abSPablo Neira Ayuso 	};
140ac2a6666SPablo Neira Ayuso };
141ac2a6666SPablo Neira Ayuso 
142ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash {
143ac2a6666SPablo Neira Ayuso 	struct rhash_head		node;
144ac2a6666SPablo Neira Ayuso 	struct flow_offload_tuple	tuple;
145ac2a6666SPablo Neira Ayuso };
146ac2a6666SPablo Neira Ayuso 
147355a8b13SPablo Neira Ayuso enum nf_flow_flags {
148355a8b13SPablo Neira Ayuso 	NF_FLOW_SNAT,
149355a8b13SPablo Neira Ayuso 	NF_FLOW_DNAT,
150355a8b13SPablo Neira Ayuso 	NF_FLOW_TEARDOWN,
151355a8b13SPablo Neira Ayuso 	NF_FLOW_HW,
152355a8b13SPablo Neira Ayuso 	NF_FLOW_HW_DYING,
153355a8b13SPablo Neira Ayuso 	NF_FLOW_HW_DEAD,
154f698fe40SPablo Neira Ayuso 	NF_FLOW_HW_REFRESH,
1552c889795SPaul Blakey 	NF_FLOW_HW_PENDING,
156355a8b13SPablo Neira Ayuso };
157ac2a6666SPablo Neira Ayuso 
158f1363e05SPablo Neira Ayuso enum flow_offload_type {
159f1363e05SPablo Neira Ayuso 	NF_FLOW_OFFLOAD_UNSPEC	= 0,
160f1363e05SPablo Neira Ayuso 	NF_FLOW_OFFLOAD_ROUTE,
161f1363e05SPablo Neira Ayuso };
162f1363e05SPablo Neira Ayuso 
163ac2a6666SPablo Neira Ayuso struct flow_offload {
164ac2a6666SPablo Neira Ayuso 	struct flow_offload_tuple_rhash		tuplehash[FLOW_OFFLOAD_DIR_MAX];
165b32d2f34SPablo Neira Ayuso 	struct nf_conn				*ct;
166355a8b13SPablo Neira Ayuso 	unsigned long				flags;
167f1363e05SPablo Neira Ayuso 	u16					type;
168ac2a6666SPablo Neira Ayuso 	u32					timeout;
16962248df8SPablo Neira Ayuso 	struct rcu_head				rcu_head;
170ac2a6666SPablo Neira Ayuso };
171ac2a6666SPablo Neira Ayuso 
172ac2a6666SPablo Neira Ayuso #define NF_FLOW_TIMEOUT (30 * HZ)
173fb46f1b7SPablo Neira Ayuso #define nf_flowtable_time_stamp	(u32)jiffies
174fb46f1b7SPablo Neira Ayuso 
175fb46f1b7SPablo Neira Ayuso static inline __s32 nf_flow_timeout_delta(unsigned int timeout)
176fb46f1b7SPablo Neira Ayuso {
177fb46f1b7SPablo Neira Ayuso 	return (__s32)(timeout - nf_flowtable_time_stamp);
178fb46f1b7SPablo Neira Ayuso }
179ac2a6666SPablo Neira Ayuso 
180ac2a6666SPablo Neira Ayuso struct nf_flow_route {
181ac2a6666SPablo Neira Ayuso 	struct {
182ac2a6666SPablo Neira Ayuso 		struct dst_entry		*dst;
183c63a7cc4SPablo Neira Ayuso 		struct {
184c63a7cc4SPablo Neira Ayuso 			u32			ifindex;
1854cd91f7cSPablo Neira Ayuso 			struct {
1864cd91f7cSPablo Neira Ayuso 				u16		id;
1874cd91f7cSPablo Neira Ayuso 				__be16		proto;
1884cd91f7cSPablo Neira Ayuso 			} encap[NF_FLOW_TABLE_ENCAP_MAX];
189*26267bf9SFelix Fietkau 			u8			num_encaps:2,
190*26267bf9SFelix Fietkau 						ingress_vlans:2;
191c63a7cc4SPablo Neira Ayuso 		} in;
1927a27f6abSPablo Neira Ayuso 		struct {
1937a27f6abSPablo Neira Ayuso 			u32			ifindex;
19473f97025SPablo Neira Ayuso 			u32			hw_ifindex;
1957a27f6abSPablo Neira Ayuso 			u8			h_source[ETH_ALEN];
1967a27f6abSPablo Neira Ayuso 			u8			h_dest[ETH_ALEN];
1977a27f6abSPablo Neira Ayuso 		} out;
1985139c0c0SPablo Neira Ayuso 		enum flow_offload_xmit_type	xmit_type;
199ac2a6666SPablo Neira Ayuso 	} tuple[FLOW_OFFLOAD_DIR_MAX];
200ac2a6666SPablo Neira Ayuso };
201ac2a6666SPablo Neira Ayuso 
202f1363e05SPablo Neira Ayuso struct flow_offload *flow_offload_alloc(struct nf_conn *ct);
203ac2a6666SPablo Neira Ayuso void flow_offload_free(struct flow_offload *flow);
204ac2a6666SPablo Neira Ayuso 
205505ee3a1SAlaa Hleihel static inline int
206505ee3a1SAlaa Hleihel nf_flow_table_offload_add_cb(struct nf_flowtable *flow_table,
207505ee3a1SAlaa Hleihel 			     flow_setup_cb_t *cb, void *cb_priv)
208505ee3a1SAlaa Hleihel {
209505ee3a1SAlaa Hleihel 	struct flow_block *block = &flow_table->flow_block;
210505ee3a1SAlaa Hleihel 	struct flow_block_cb *block_cb;
211505ee3a1SAlaa Hleihel 	int err = 0;
212505ee3a1SAlaa Hleihel 
213505ee3a1SAlaa Hleihel 	down_write(&flow_table->flow_block_lock);
214505ee3a1SAlaa Hleihel 	block_cb = flow_block_cb_lookup(block, cb, cb_priv);
215505ee3a1SAlaa Hleihel 	if (block_cb) {
216505ee3a1SAlaa Hleihel 		err = -EEXIST;
217505ee3a1SAlaa Hleihel 		goto unlock;
218505ee3a1SAlaa Hleihel 	}
219505ee3a1SAlaa Hleihel 
220505ee3a1SAlaa Hleihel 	block_cb = flow_block_cb_alloc(cb, cb_priv, cb_priv, NULL);
221505ee3a1SAlaa Hleihel 	if (IS_ERR(block_cb)) {
222505ee3a1SAlaa Hleihel 		err = PTR_ERR(block_cb);
223505ee3a1SAlaa Hleihel 		goto unlock;
224505ee3a1SAlaa Hleihel 	}
225505ee3a1SAlaa Hleihel 
226505ee3a1SAlaa Hleihel 	list_add_tail(&block_cb->list, &block->cb_list);
227505ee3a1SAlaa Hleihel 
228505ee3a1SAlaa Hleihel unlock:
229505ee3a1SAlaa Hleihel 	up_write(&flow_table->flow_block_lock);
230505ee3a1SAlaa Hleihel 	return err;
231505ee3a1SAlaa Hleihel }
232505ee3a1SAlaa Hleihel 
233505ee3a1SAlaa Hleihel static inline void
234505ee3a1SAlaa Hleihel nf_flow_table_offload_del_cb(struct nf_flowtable *flow_table,
235505ee3a1SAlaa Hleihel 			     flow_setup_cb_t *cb, void *cb_priv)
236505ee3a1SAlaa Hleihel {
237505ee3a1SAlaa Hleihel 	struct flow_block *block = &flow_table->flow_block;
238505ee3a1SAlaa Hleihel 	struct flow_block_cb *block_cb;
239505ee3a1SAlaa Hleihel 
240505ee3a1SAlaa Hleihel 	down_write(&flow_table->flow_block_lock);
241505ee3a1SAlaa Hleihel 	block_cb = flow_block_cb_lookup(block, cb, cb_priv);
242505ee3a1SAlaa Hleihel 	if (block_cb) {
243505ee3a1SAlaa Hleihel 		list_del(&block_cb->list);
244505ee3a1SAlaa Hleihel 		flow_block_cb_free(block_cb);
245505ee3a1SAlaa Hleihel 	} else {
246505ee3a1SAlaa Hleihel 		WARN_ON(true);
247505ee3a1SAlaa Hleihel 	}
248505ee3a1SAlaa Hleihel 	up_write(&flow_table->flow_block_lock);
249505ee3a1SAlaa Hleihel }
250978703f4SPaul Blakey 
251f1363e05SPablo Neira Ayuso int flow_offload_route_init(struct flow_offload *flow,
252f1363e05SPablo Neira Ayuso 			    const struct nf_flow_route *route);
253f1363e05SPablo Neira Ayuso 
254ac2a6666SPablo Neira Ayuso int flow_offload_add(struct nf_flowtable *flow_table, struct flow_offload *flow);
2558b3646d6SPaul Blakey void flow_offload_refresh(struct nf_flowtable *flow_table,
2568b3646d6SPaul Blakey 			  struct flow_offload *flow);
2578b3646d6SPaul Blakey 
258ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash *flow_offload_lookup(struct nf_flowtable *flow_table,
259ac2a6666SPablo Neira Ayuso 						     struct flow_offload_tuple *tuple);
260a8284c68SPablo Neira Ayuso void nf_flow_table_gc_cleanup(struct nf_flowtable *flowtable,
261a8284c68SPablo Neira Ayuso 			      struct net_device *dev);
2625f1be84aSTaehee Yoo void nf_flow_table_cleanup(struct net_device *dev);
263c0ea1bcbSPablo Neira Ayuso 
264a268de77SFelix Fietkau int nf_flow_table_init(struct nf_flowtable *flow_table);
265b408c5b0SPablo Neira Ayuso void nf_flow_table_free(struct nf_flowtable *flow_table);
266ac2a6666SPablo Neira Ayuso 
26759c466ddSFelix Fietkau void flow_offload_teardown(struct flow_offload *flow);
268ac2a6666SPablo Neira Ayuso 
269f4401262SPablo Neira Ayuso void nf_flow_snat_port(const struct flow_offload *flow,
270ac2a6666SPablo Neira Ayuso 		       struct sk_buff *skb, unsigned int thoff,
271ac2a6666SPablo Neira Ayuso 		       u8 protocol, enum flow_offload_tuple_dir dir);
272f4401262SPablo Neira Ayuso void nf_flow_dnat_port(const struct flow_offload *flow,
273ac2a6666SPablo Neira Ayuso 		       struct sk_buff *skb, unsigned int thoff,
274ac2a6666SPablo Neira Ayuso 		       u8 protocol, enum flow_offload_tuple_dir dir);
275ac2a6666SPablo Neira Ayuso 
276ac2a6666SPablo Neira Ayuso struct flow_ports {
277ac2a6666SPablo Neira Ayuso 	__be16 source, dest;
278ac2a6666SPablo Neira Ayuso };
279ac2a6666SPablo Neira Ayuso 
2807c23b629SPablo Neira Ayuso unsigned int nf_flow_offload_ip_hook(void *priv, struct sk_buff *skb,
2817c23b629SPablo Neira Ayuso 				     const struct nf_hook_state *state);
2827c23b629SPablo Neira Ayuso unsigned int nf_flow_offload_ipv6_hook(void *priv, struct sk_buff *skb,
2837c23b629SPablo Neira Ayuso 				       const struct nf_hook_state *state);
2847c23b629SPablo Neira Ayuso 
285ac2a6666SPablo Neira Ayuso #define MODULE_ALIAS_NF_FLOWTABLE(family)	\
286ac2a6666SPablo Neira Ayuso 	MODULE_ALIAS("nf-flowtable-" __stringify(family))
287ac2a6666SPablo Neira Ayuso 
288c29f74e0SPablo Neira Ayuso void nf_flow_offload_add(struct nf_flowtable *flowtable,
289c29f74e0SPablo Neira Ayuso 			 struct flow_offload *flow);
290c29f74e0SPablo Neira Ayuso void nf_flow_offload_del(struct nf_flowtable *flowtable,
291c29f74e0SPablo Neira Ayuso 			 struct flow_offload *flow);
292c29f74e0SPablo Neira Ayuso void nf_flow_offload_stats(struct nf_flowtable *flowtable,
293c29f74e0SPablo Neira Ayuso 			   struct flow_offload *flow);
294c29f74e0SPablo Neira Ayuso 
295c29f74e0SPablo Neira Ayuso void nf_flow_table_offload_flush(struct nf_flowtable *flowtable);
296c29f74e0SPablo Neira Ayuso int nf_flow_table_offload_setup(struct nf_flowtable *flowtable,
2978bb69f3bSPablo Neira Ayuso 				struct net_device *dev,
298c29f74e0SPablo Neira Ayuso 				enum flow_block_command cmd);
2995c27d8d7SPablo Neira Ayuso int nf_flow_rule_route_ipv4(struct net *net, const struct flow_offload *flow,
3005c27d8d7SPablo Neira Ayuso 			    enum flow_offload_tuple_dir dir,
3015c27d8d7SPablo Neira Ayuso 			    struct nf_flow_rule *flow_rule);
3025c27d8d7SPablo Neira Ayuso int nf_flow_rule_route_ipv6(struct net *net, const struct flow_offload *flow,
303c29f74e0SPablo Neira Ayuso 			    enum flow_offload_tuple_dir dir,
304c29f74e0SPablo Neira Ayuso 			    struct nf_flow_rule *flow_rule);
305c29f74e0SPablo Neira Ayuso 
306c29f74e0SPablo Neira Ayuso int nf_flow_table_offload_init(void);
307c29f74e0SPablo Neira Ayuso void nf_flow_table_offload_exit(void);
3088bb69f3bSPablo Neira Ayuso 
3090286fbc6SJeremy Sowden #endif /* _NF_FLOW_TABLE_H */
310