13b49e2e9SPablo Neira Ayuso #ifndef _NF_FLOW_TABLE_H
23b49e2e9SPablo Neira Ayuso #define _NF_FLOW_TABLE_H
33b49e2e9SPablo Neira Ayuso 
4ac2a6666SPablo Neira Ayuso #include <linux/in.h>
5ac2a6666SPablo Neira Ayuso #include <linux/in6.h>
6ac2a6666SPablo Neira Ayuso #include <linux/netdevice.h>
70eb71a9dSNeilBrown #include <linux/rhashtable-types.h>
8ac2a6666SPablo Neira Ayuso #include <linux/rcupdate.h>
9a1b2f04eSJeremy Sowden #include <linux/netfilter.h>
10af81f9e7SFelix Fietkau #include <linux/netfilter/nf_conntrack_tuple_common.h>
118bb69f3bSPablo Neira Ayuso #include <net/flow_offload.h>
12ac2a6666SPablo Neira Ayuso #include <net/dst.h>
133b49e2e9SPablo Neira Ayuso 
143b49e2e9SPablo Neira Ayuso struct nf_flowtable;
15c29f74e0SPablo Neira Ayuso struct nf_flow_rule;
16c29f74e0SPablo Neira Ayuso struct flow_offload;
17c29f74e0SPablo Neira Ayuso enum flow_offload_tuple_dir;
183b49e2e9SPablo Neira Ayuso 
193b49e2e9SPablo Neira Ayuso struct nf_flowtable_type {
203b49e2e9SPablo Neira Ayuso 	struct list_head		list;
213b49e2e9SPablo Neira Ayuso 	int				family;
22a268de77SFelix Fietkau 	int				(*init)(struct nf_flowtable *ft);
238bb69f3bSPablo Neira Ayuso 	int				(*setup)(struct nf_flowtable *ft,
248bb69f3bSPablo Neira Ayuso 						 struct net_device *dev,
258bb69f3bSPablo Neira Ayuso 						 enum flow_block_command cmd);
26c29f74e0SPablo Neira Ayuso 	int				(*action)(struct net *net,
27c29f74e0SPablo Neira Ayuso 						  const struct flow_offload *flow,
28c29f74e0SPablo Neira Ayuso 						  enum flow_offload_tuple_dir dir,
29c29f74e0SPablo Neira Ayuso 						  struct nf_flow_rule *flow_rule);
30b408c5b0SPablo Neira Ayuso 	void				(*free)(struct nf_flowtable *ft);
313b49e2e9SPablo Neira Ayuso 	nf_hookfn			*hook;
323b49e2e9SPablo Neira Ayuso 	struct module			*owner;
333b49e2e9SPablo Neira Ayuso };
343b49e2e9SPablo Neira Ayuso 
358bb69f3bSPablo Neira Ayuso enum nf_flowtable_flags {
368bb69f3bSPablo Neira Ayuso 	NF_FLOWTABLE_HW_OFFLOAD		= 0x1,
378bb69f3bSPablo Neira Ayuso };
388bb69f3bSPablo Neira Ayuso 
393b49e2e9SPablo Neira Ayuso struct nf_flowtable {
4084453a90SFelix Fietkau 	struct list_head		list;
413b49e2e9SPablo Neira Ayuso 	struct rhashtable		rhashtable;
4271a8a63bSPablo Neira Ayuso 	int				priority;
433b49e2e9SPablo Neira Ayuso 	const struct nf_flowtable_type	*type;
443b49e2e9SPablo Neira Ayuso 	struct delayed_work		gc_work;
458bb69f3bSPablo Neira Ayuso 	unsigned int			flags;
468bb69f3bSPablo Neira Ayuso 	struct flow_block		flow_block;
478bb69f3bSPablo Neira Ayuso 	possible_net_t			net;
483b49e2e9SPablo Neira Ayuso };
493b49e2e9SPablo Neira Ayuso 
50ac2a6666SPablo Neira Ayuso enum flow_offload_tuple_dir {
51af81f9e7SFelix Fietkau 	FLOW_OFFLOAD_DIR_ORIGINAL = IP_CT_DIR_ORIGINAL,
52af81f9e7SFelix Fietkau 	FLOW_OFFLOAD_DIR_REPLY = IP_CT_DIR_REPLY,
53af81f9e7SFelix Fietkau 	FLOW_OFFLOAD_DIR_MAX = IP_CT_DIR_MAX
54ac2a6666SPablo Neira Ayuso };
55ac2a6666SPablo Neira Ayuso 
56ac2a6666SPablo Neira Ayuso struct flow_offload_tuple {
57ac2a6666SPablo Neira Ayuso 	union {
58ac2a6666SPablo Neira Ayuso 		struct in_addr		src_v4;
59ac2a6666SPablo Neira Ayuso 		struct in6_addr		src_v6;
60ac2a6666SPablo Neira Ayuso 	};
61ac2a6666SPablo Neira Ayuso 	union {
62ac2a6666SPablo Neira Ayuso 		struct in_addr		dst_v4;
63ac2a6666SPablo Neira Ayuso 		struct in6_addr		dst_v6;
64ac2a6666SPablo Neira Ayuso 	};
65ac2a6666SPablo Neira Ayuso 	struct {
66ac2a6666SPablo Neira Ayuso 		__be16			src_port;
67ac2a6666SPablo Neira Ayuso 		__be16			dst_port;
68ac2a6666SPablo Neira Ayuso 	};
69ac2a6666SPablo Neira Ayuso 
70ac2a6666SPablo Neira Ayuso 	int				iifidx;
71ac2a6666SPablo Neira Ayuso 
72ac2a6666SPablo Neira Ayuso 	u8				l3proto;
73ac2a6666SPablo Neira Ayuso 	u8				l4proto;
74ac2a6666SPablo Neira Ayuso 	u8				dir;
75ac2a6666SPablo Neira Ayuso 
764f3780c0SFelix Fietkau 	u16				mtu;
774f3780c0SFelix Fietkau 
78ac2a6666SPablo Neira Ayuso 	struct dst_entry		*dst_cache;
79ac2a6666SPablo Neira Ayuso };
80ac2a6666SPablo Neira Ayuso 
81ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash {
82ac2a6666SPablo Neira Ayuso 	struct rhash_head		node;
83ac2a6666SPablo Neira Ayuso 	struct flow_offload_tuple	tuple;
84ac2a6666SPablo Neira Ayuso };
85ac2a6666SPablo Neira Ayuso 
86ac2a6666SPablo Neira Ayuso #define FLOW_OFFLOAD_SNAT	0x1
87ac2a6666SPablo Neira Ayuso #define FLOW_OFFLOAD_DNAT	0x2
88ac2a6666SPablo Neira Ayuso #define FLOW_OFFLOAD_DYING	0x4
8959c466ddSFelix Fietkau #define FLOW_OFFLOAD_TEARDOWN	0x8
90c29f74e0SPablo Neira Ayuso #define FLOW_OFFLOAD_HW		0x10
91c29f74e0SPablo Neira Ayuso #define FLOW_OFFLOAD_HW_DYING	0x20
92c29f74e0SPablo Neira Ayuso #define FLOW_OFFLOAD_HW_DEAD	0x40
93ac2a6666SPablo Neira Ayuso 
94f1363e05SPablo Neira Ayuso enum flow_offload_type {
95f1363e05SPablo Neira Ayuso 	NF_FLOW_OFFLOAD_UNSPEC	= 0,
96f1363e05SPablo Neira Ayuso 	NF_FLOW_OFFLOAD_ROUTE,
97f1363e05SPablo Neira Ayuso };
98f1363e05SPablo Neira Ayuso 
99ac2a6666SPablo Neira Ayuso struct flow_offload {
100ac2a6666SPablo Neira Ayuso 	struct flow_offload_tuple_rhash		tuplehash[FLOW_OFFLOAD_DIR_MAX];
101b32d2f34SPablo Neira Ayuso 	struct nf_conn				*ct;
102f1363e05SPablo Neira Ayuso 	u16					flags;
103f1363e05SPablo Neira Ayuso 	u16					type;
104ac2a6666SPablo Neira Ayuso 	u32					timeout;
10562248df8SPablo Neira Ayuso 	struct rcu_head				rcu_head;
106ac2a6666SPablo Neira Ayuso };
107ac2a6666SPablo Neira Ayuso 
108ac2a6666SPablo Neira Ayuso #define NF_FLOW_TIMEOUT (30 * HZ)
109ac2a6666SPablo Neira Ayuso 
110ac2a6666SPablo Neira Ayuso struct nf_flow_route {
111ac2a6666SPablo Neira Ayuso 	struct {
112ac2a6666SPablo Neira Ayuso 		struct dst_entry	*dst;
113ac2a6666SPablo Neira Ayuso 	} tuple[FLOW_OFFLOAD_DIR_MAX];
114ac2a6666SPablo Neira Ayuso };
115ac2a6666SPablo Neira Ayuso 
116f1363e05SPablo Neira Ayuso struct flow_offload *flow_offload_alloc(struct nf_conn *ct);
117ac2a6666SPablo Neira Ayuso void flow_offload_free(struct flow_offload *flow);
118ac2a6666SPablo Neira Ayuso 
119f1363e05SPablo Neira Ayuso int flow_offload_route_init(struct flow_offload *flow,
120f1363e05SPablo Neira Ayuso 			    const struct nf_flow_route *route);
121f1363e05SPablo Neira Ayuso 
122ac2a6666SPablo Neira Ayuso int flow_offload_add(struct nf_flowtable *flow_table, struct flow_offload *flow);
123ac2a6666SPablo Neira Ayuso struct flow_offload_tuple_rhash *flow_offload_lookup(struct nf_flowtable *flow_table,
124ac2a6666SPablo Neira Ayuso 						     struct flow_offload_tuple *tuple);
1255f1be84aSTaehee Yoo void nf_flow_table_cleanup(struct net_device *dev);
126c0ea1bcbSPablo Neira Ayuso 
127a268de77SFelix Fietkau int nf_flow_table_init(struct nf_flowtable *flow_table);
128b408c5b0SPablo Neira Ayuso void nf_flow_table_free(struct nf_flowtable *flow_table);
129ac2a6666SPablo Neira Ayuso 
13059c466ddSFelix Fietkau void flow_offload_teardown(struct flow_offload *flow);
1316bdc3c68SFelix Fietkau static inline void flow_offload_dead(struct flow_offload *flow)
1326bdc3c68SFelix Fietkau {
1336bdc3c68SFelix Fietkau 	flow->flags |= FLOW_OFFLOAD_DYING;
1346bdc3c68SFelix Fietkau }
135ac2a6666SPablo Neira Ayuso 
136ac2a6666SPablo Neira Ayuso int nf_flow_snat_port(const struct flow_offload *flow,
137ac2a6666SPablo Neira Ayuso 		      struct sk_buff *skb, unsigned int thoff,
138ac2a6666SPablo Neira Ayuso 		      u8 protocol, enum flow_offload_tuple_dir dir);
139ac2a6666SPablo Neira Ayuso int nf_flow_dnat_port(const struct flow_offload *flow,
140ac2a6666SPablo Neira Ayuso 		      struct sk_buff *skb, unsigned int thoff,
141ac2a6666SPablo Neira Ayuso 		      u8 protocol, enum flow_offload_tuple_dir dir);
142ac2a6666SPablo Neira Ayuso 
143ac2a6666SPablo Neira Ayuso struct flow_ports {
144ac2a6666SPablo Neira Ayuso 	__be16 source, dest;
145ac2a6666SPablo Neira Ayuso };
146ac2a6666SPablo Neira Ayuso 
1477c23b629SPablo Neira Ayuso unsigned int nf_flow_offload_ip_hook(void *priv, struct sk_buff *skb,
1487c23b629SPablo Neira Ayuso 				     const struct nf_hook_state *state);
1497c23b629SPablo Neira Ayuso unsigned int nf_flow_offload_ipv6_hook(void *priv, struct sk_buff *skb,
1507c23b629SPablo Neira Ayuso 				       const struct nf_hook_state *state);
1517c23b629SPablo Neira Ayuso 
152ac2a6666SPablo Neira Ayuso #define MODULE_ALIAS_NF_FLOWTABLE(family)	\
153ac2a6666SPablo Neira Ayuso 	MODULE_ALIAS("nf-flowtable-" __stringify(family))
154ac2a6666SPablo Neira Ayuso 
155c29f74e0SPablo Neira Ayuso void nf_flow_offload_add(struct nf_flowtable *flowtable,
156c29f74e0SPablo Neira Ayuso 			 struct flow_offload *flow);
157c29f74e0SPablo Neira Ayuso void nf_flow_offload_del(struct nf_flowtable *flowtable,
158c29f74e0SPablo Neira Ayuso 			 struct flow_offload *flow);
159c29f74e0SPablo Neira Ayuso void nf_flow_offload_stats(struct nf_flowtable *flowtable,
160c29f74e0SPablo Neira Ayuso 			   struct flow_offload *flow);
161c29f74e0SPablo Neira Ayuso 
162c29f74e0SPablo Neira Ayuso void nf_flow_table_offload_flush(struct nf_flowtable *flowtable);
163c29f74e0SPablo Neira Ayuso int nf_flow_table_offload_setup(struct nf_flowtable *flowtable,
1648bb69f3bSPablo Neira Ayuso 				struct net_device *dev,
165c29f74e0SPablo Neira Ayuso 				enum flow_block_command cmd);
166c29f74e0SPablo Neira Ayuso int nf_flow_rule_route(struct net *net, const struct flow_offload *flow,
167c29f74e0SPablo Neira Ayuso 		       enum flow_offload_tuple_dir dir,
168c29f74e0SPablo Neira Ayuso 		       struct nf_flow_rule *flow_rule);
169c29f74e0SPablo Neira Ayuso 
170c29f74e0SPablo Neira Ayuso int nf_flow_table_offload_init(void);
171c29f74e0SPablo Neira Ayuso void nf_flow_table_offload_exit(void);
1728bb69f3bSPablo Neira Ayuso 
1730286fbc6SJeremy Sowden #endif /* _NF_FLOW_TABLE_H */
174