13b49e2e9SPablo Neira Ayuso #ifndef _NF_FLOW_TABLE_H 23b49e2e9SPablo Neira Ayuso #define _NF_FLOW_TABLE_H 33b49e2e9SPablo Neira Ayuso 4ac2a6666SPablo Neira Ayuso #include <linux/in.h> 5ac2a6666SPablo Neira Ayuso #include <linux/in6.h> 6ac2a6666SPablo Neira Ayuso #include <linux/netdevice.h> 70eb71a9dSNeilBrown #include <linux/rhashtable-types.h> 8ac2a6666SPablo Neira Ayuso #include <linux/rcupdate.h> 9a1b2f04eSJeremy Sowden #include <linux/netfilter.h> 10af81f9e7SFelix Fietkau #include <linux/netfilter/nf_conntrack_tuple_common.h> 11ac2a6666SPablo Neira Ayuso #include <net/dst.h> 123b49e2e9SPablo Neira Ayuso 133b49e2e9SPablo Neira Ayuso struct nf_flowtable; 143b49e2e9SPablo Neira Ayuso 153b49e2e9SPablo Neira Ayuso struct nf_flowtable_type { 163b49e2e9SPablo Neira Ayuso struct list_head list; 173b49e2e9SPablo Neira Ayuso int family; 18a268de77SFelix Fietkau int (*init)(struct nf_flowtable *ft); 19b408c5b0SPablo Neira Ayuso void (*free)(struct nf_flowtable *ft); 203b49e2e9SPablo Neira Ayuso nf_hookfn *hook; 213b49e2e9SPablo Neira Ayuso struct module *owner; 223b49e2e9SPablo Neira Ayuso }; 233b49e2e9SPablo Neira Ayuso 243b49e2e9SPablo Neira Ayuso struct nf_flowtable { 2584453a90SFelix Fietkau struct list_head list; 263b49e2e9SPablo Neira Ayuso struct rhashtable rhashtable; 2771a8a63bSPablo Neira Ayuso int priority; 283b49e2e9SPablo Neira Ayuso const struct nf_flowtable_type *type; 293b49e2e9SPablo Neira Ayuso struct delayed_work gc_work; 303b49e2e9SPablo Neira Ayuso }; 313b49e2e9SPablo Neira Ayuso 32ac2a6666SPablo Neira Ayuso enum flow_offload_tuple_dir { 33af81f9e7SFelix Fietkau FLOW_OFFLOAD_DIR_ORIGINAL = IP_CT_DIR_ORIGINAL, 34af81f9e7SFelix Fietkau FLOW_OFFLOAD_DIR_REPLY = IP_CT_DIR_REPLY, 35af81f9e7SFelix Fietkau FLOW_OFFLOAD_DIR_MAX = IP_CT_DIR_MAX 36ac2a6666SPablo Neira Ayuso }; 37ac2a6666SPablo Neira Ayuso 38ac2a6666SPablo Neira Ayuso struct flow_offload_tuple { 39ac2a6666SPablo Neira Ayuso union { 40ac2a6666SPablo Neira Ayuso struct in_addr src_v4; 41ac2a6666SPablo Neira Ayuso struct in6_addr src_v6; 42ac2a6666SPablo Neira Ayuso }; 43ac2a6666SPablo Neira Ayuso union { 44ac2a6666SPablo Neira Ayuso struct in_addr dst_v4; 45ac2a6666SPablo Neira Ayuso struct in6_addr dst_v6; 46ac2a6666SPablo Neira Ayuso }; 47ac2a6666SPablo Neira Ayuso struct { 48ac2a6666SPablo Neira Ayuso __be16 src_port; 49ac2a6666SPablo Neira Ayuso __be16 dst_port; 50ac2a6666SPablo Neira Ayuso }; 51ac2a6666SPablo Neira Ayuso 52ac2a6666SPablo Neira Ayuso int iifidx; 53ac2a6666SPablo Neira Ayuso 54ac2a6666SPablo Neira Ayuso u8 l3proto; 55ac2a6666SPablo Neira Ayuso u8 l4proto; 56ac2a6666SPablo Neira Ayuso u8 dir; 57ac2a6666SPablo Neira Ayuso 584f3780c0SFelix Fietkau u16 mtu; 594f3780c0SFelix Fietkau 60ac2a6666SPablo Neira Ayuso struct dst_entry *dst_cache; 61ac2a6666SPablo Neira Ayuso }; 62ac2a6666SPablo Neira Ayuso 63ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash { 64ac2a6666SPablo Neira Ayuso struct rhash_head node; 65ac2a6666SPablo Neira Ayuso struct flow_offload_tuple tuple; 66ac2a6666SPablo Neira Ayuso }; 67ac2a6666SPablo Neira Ayuso 68ac2a6666SPablo Neira Ayuso #define FLOW_OFFLOAD_SNAT 0x1 69ac2a6666SPablo Neira Ayuso #define FLOW_OFFLOAD_DNAT 0x2 70ac2a6666SPablo Neira Ayuso #define FLOW_OFFLOAD_DYING 0x4 7159c466ddSFelix Fietkau #define FLOW_OFFLOAD_TEARDOWN 0x8 72ac2a6666SPablo Neira Ayuso 73ac2a6666SPablo Neira Ayuso struct flow_offload { 74ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash tuplehash[FLOW_OFFLOAD_DIR_MAX]; 75b32d2f34SPablo Neira Ayuso struct nf_conn *ct; 76ac2a6666SPablo Neira Ayuso u32 flags; 77ac2a6666SPablo Neira Ayuso u32 timeout; 7862248df8SPablo Neira Ayuso struct rcu_head rcu_head; 79ac2a6666SPablo Neira Ayuso }; 80ac2a6666SPablo Neira Ayuso 81ac2a6666SPablo Neira Ayuso #define NF_FLOW_TIMEOUT (30 * HZ) 82ac2a6666SPablo Neira Ayuso 83ac2a6666SPablo Neira Ayuso struct nf_flow_route { 84ac2a6666SPablo Neira Ayuso struct { 85ac2a6666SPablo Neira Ayuso struct dst_entry *dst; 86ac2a6666SPablo Neira Ayuso } tuple[FLOW_OFFLOAD_DIR_MAX]; 87ac2a6666SPablo Neira Ayuso }; 88ac2a6666SPablo Neira Ayuso 89ac2a6666SPablo Neira Ayuso struct flow_offload *flow_offload_alloc(struct nf_conn *ct, 90ac2a6666SPablo Neira Ayuso struct nf_flow_route *route); 91ac2a6666SPablo Neira Ayuso void flow_offload_free(struct flow_offload *flow); 92ac2a6666SPablo Neira Ayuso 93ac2a6666SPablo Neira Ayuso int flow_offload_add(struct nf_flowtable *flow_table, struct flow_offload *flow); 94ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash *flow_offload_lookup(struct nf_flowtable *flow_table, 95ac2a6666SPablo Neira Ayuso struct flow_offload_tuple *tuple); 965f1be84aSTaehee Yoo void nf_flow_table_cleanup(struct net_device *dev); 97c0ea1bcbSPablo Neira Ayuso 98a268de77SFelix Fietkau int nf_flow_table_init(struct nf_flowtable *flow_table); 99b408c5b0SPablo Neira Ayuso void nf_flow_table_free(struct nf_flowtable *flow_table); 100ac2a6666SPablo Neira Ayuso 10159c466ddSFelix Fietkau void flow_offload_teardown(struct flow_offload *flow); 1026bdc3c68SFelix Fietkau static inline void flow_offload_dead(struct flow_offload *flow) 1036bdc3c68SFelix Fietkau { 1046bdc3c68SFelix Fietkau flow->flags |= FLOW_OFFLOAD_DYING; 1056bdc3c68SFelix Fietkau } 106ac2a6666SPablo Neira Ayuso 107ac2a6666SPablo Neira Ayuso int nf_flow_snat_port(const struct flow_offload *flow, 108ac2a6666SPablo Neira Ayuso struct sk_buff *skb, unsigned int thoff, 109ac2a6666SPablo Neira Ayuso u8 protocol, enum flow_offload_tuple_dir dir); 110ac2a6666SPablo Neira Ayuso int nf_flow_dnat_port(const struct flow_offload *flow, 111ac2a6666SPablo Neira Ayuso struct sk_buff *skb, unsigned int thoff, 112ac2a6666SPablo Neira Ayuso u8 protocol, enum flow_offload_tuple_dir dir); 113ac2a6666SPablo Neira Ayuso 114ac2a6666SPablo Neira Ayuso struct flow_ports { 115ac2a6666SPablo Neira Ayuso __be16 source, dest; 116ac2a6666SPablo Neira Ayuso }; 117ac2a6666SPablo Neira Ayuso 1187c23b629SPablo Neira Ayuso unsigned int nf_flow_offload_ip_hook(void *priv, struct sk_buff *skb, 1197c23b629SPablo Neira Ayuso const struct nf_hook_state *state); 1207c23b629SPablo Neira Ayuso unsigned int nf_flow_offload_ipv6_hook(void *priv, struct sk_buff *skb, 1217c23b629SPablo Neira Ayuso const struct nf_hook_state *state); 1227c23b629SPablo Neira Ayuso 123ac2a6666SPablo Neira Ayuso #define MODULE_ALIAS_NF_FLOWTABLE(family) \ 124ac2a6666SPablo Neira Ayuso MODULE_ALIAS("nf-flowtable-" __stringify(family)) 125ac2a6666SPablo Neira Ayuso 1260286fbc6SJeremy Sowden #endif /* _NF_FLOW_TABLE_H */ 127