196518518SPatrick McHardy #ifndef _NET_NF_TABLES_H
296518518SPatrick McHardy #define _NET_NF_TABLES_H
396518518SPatrick McHardy 
40b2d8a7bSPatrick McHardy #include <linux/module.h>
596518518SPatrick McHardy #include <linux/list.h>
696518518SPatrick McHardy #include <linux/netfilter.h>
767a8fc27SPatrick McHardy #include <linux/netfilter/nfnetlink.h>
80ca743a5SPablo Neira Ayuso #include <linux/netfilter/x_tables.h>
996518518SPatrick McHardy #include <linux/netfilter/nf_tables.h>
10ce355e20SEric Dumazet #include <linux/u64_stats_sync.h>
1196518518SPatrick McHardy #include <net/netlink.h>
1296518518SPatrick McHardy 
1320a69341SPatrick McHardy #define NFT_JUMP_STACK_SIZE	16
1420a69341SPatrick McHardy 
1596518518SPatrick McHardy struct nft_pktinfo {
1696518518SPatrick McHardy 	struct sk_buff			*skb;
1746448d00SEric W. Biederman 	struct net			*net;
1896518518SPatrick McHardy 	const struct net_device		*in;
1996518518SPatrick McHardy 	const struct net_device		*out;
206aa187f2SEric W. Biederman 	u8				pf;
216aa187f2SEric W. Biederman 	u8				hook;
224566bf27SPatrick McHardy 	u8				tprot;
230ca743a5SPablo Neira Ayuso 	/* for x_tables compatibility */
240ca743a5SPablo Neira Ayuso 	struct xt_action_param		xt;
2596518518SPatrick McHardy };
2696518518SPatrick McHardy 
270ca743a5SPablo Neira Ayuso static inline void nft_set_pktinfo(struct nft_pktinfo *pkt,
280ca743a5SPablo Neira Ayuso 				   struct sk_buff *skb,
29073bfd56SDavid S. Miller 				   const struct nf_hook_state *state)
300ca743a5SPablo Neira Ayuso {
310ca743a5SPablo Neira Ayuso 	pkt->skb = skb;
3246448d00SEric W. Biederman 	pkt->net = pkt->xt.net = state->net;
33073bfd56SDavid S. Miller 	pkt->in = pkt->xt.in = state->in;
34073bfd56SDavid S. Miller 	pkt->out = pkt->xt.out = state->out;
356aa187f2SEric W. Biederman 	pkt->hook = pkt->xt.hooknum = state->hook;
366aa187f2SEric W. Biederman 	pkt->pf = pkt->xt.family = state->pf;
370ca743a5SPablo Neira Ayuso }
380ca743a5SPablo Neira Ayuso 
39a55e22e9SPatrick McHardy /**
40a55e22e9SPatrick McHardy  * 	struct nft_verdict - nf_tables verdict
41a55e22e9SPatrick McHardy  *
42a55e22e9SPatrick McHardy  * 	@code: nf_tables/netfilter verdict code
43a55e22e9SPatrick McHardy  * 	@chain: destination chain for NFT_JUMP/NFT_GOTO
44a55e22e9SPatrick McHardy  */
45a55e22e9SPatrick McHardy struct nft_verdict {
46a55e22e9SPatrick McHardy 	u32				code;
47a55e22e9SPatrick McHardy 	struct nft_chain		*chain;
48a55e22e9SPatrick McHardy };
49a55e22e9SPatrick McHardy 
5096518518SPatrick McHardy struct nft_data {
5196518518SPatrick McHardy 	union {
5296518518SPatrick McHardy 		u32			data[4];
531ca2e170SPatrick McHardy 		struct nft_verdict	verdict;
5496518518SPatrick McHardy 	};
5596518518SPatrick McHardy } __attribute__((aligned(__alignof__(u64))));
5696518518SPatrick McHardy 
57a55e22e9SPatrick McHardy /**
58a55e22e9SPatrick McHardy  *	struct nft_regs - nf_tables register set
59a55e22e9SPatrick McHardy  *
60a55e22e9SPatrick McHardy  *	@data: data registers
61a55e22e9SPatrick McHardy  *	@verdict: verdict register
62a55e22e9SPatrick McHardy  *
63a55e22e9SPatrick McHardy  *	The first four data registers alias to the verdict register.
64a55e22e9SPatrick McHardy  */
65a55e22e9SPatrick McHardy struct nft_regs {
66a55e22e9SPatrick McHardy 	union {
6749499c3eSPatrick McHardy 		u32			data[20];
68a55e22e9SPatrick McHardy 		struct nft_verdict	verdict;
69a55e22e9SPatrick McHardy 	};
70a55e22e9SPatrick McHardy };
71a55e22e9SPatrick McHardy 
7249499c3eSPatrick McHardy static inline void nft_data_copy(u32 *dst, const struct nft_data *src,
7349499c3eSPatrick McHardy 				 unsigned int len)
7496518518SPatrick McHardy {
7549499c3eSPatrick McHardy 	memcpy(dst, src, len);
7696518518SPatrick McHardy }
7796518518SPatrick McHardy 
7896518518SPatrick McHardy static inline void nft_data_debug(const struct nft_data *data)
7996518518SPatrick McHardy {
8096518518SPatrick McHardy 	pr_debug("data[0]=%x data[1]=%x data[2]=%x data[3]=%x\n",
8196518518SPatrick McHardy 		 data->data[0], data->data[1],
8296518518SPatrick McHardy 		 data->data[2], data->data[3]);
8396518518SPatrick McHardy }
8496518518SPatrick McHardy 
8596518518SPatrick McHardy /**
8620a69341SPatrick McHardy  *	struct nft_ctx - nf_tables rule/set context
8796518518SPatrick McHardy  *
8899633ab2SPablo Neira Ayuso  *	@net: net namespace
8996518518SPatrick McHardy  * 	@afi: address family info
9096518518SPatrick McHardy  * 	@table: the table the chain is contained in
9196518518SPatrick McHardy  * 	@chain: the chain the rule is contained in
920ca743a5SPablo Neira Ayuso  *	@nla: netlink attributes
93128ad332SPablo Neira Ayuso  *	@portid: netlink portID of the original message
94128ad332SPablo Neira Ayuso  *	@seq: netlink sequence number
95128ad332SPablo Neira Ayuso  *	@report: notify via unicast netlink message
9696518518SPatrick McHardy  */
9796518518SPatrick McHardy struct nft_ctx {
9899633ab2SPablo Neira Ayuso 	struct net			*net;
997c95f6d8SPablo Neira Ayuso 	struct nft_af_info		*afi;
1007c95f6d8SPablo Neira Ayuso 	struct nft_table		*table;
1017c95f6d8SPablo Neira Ayuso 	struct nft_chain		*chain;
1020ca743a5SPablo Neira Ayuso 	const struct nlattr * const 	*nla;
103128ad332SPablo Neira Ayuso 	u32				portid;
104128ad332SPablo Neira Ayuso 	u32				seq;
105128ad332SPablo Neira Ayuso 	bool				report;
10696518518SPatrick McHardy };
10796518518SPatrick McHardy 
10896518518SPatrick McHardy struct nft_data_desc {
10996518518SPatrick McHardy 	enum nft_data_types		type;
11096518518SPatrick McHardy 	unsigned int			len;
11196518518SPatrick McHardy };
11296518518SPatrick McHardy 
113d0a11fc3SPatrick McHardy int nft_data_init(const struct nft_ctx *ctx,
114d0a11fc3SPatrick McHardy 		  struct nft_data *data, unsigned int size,
11596518518SPatrick McHardy 		  struct nft_data_desc *desc, const struct nlattr *nla);
1165eccdfaaSJoe Perches void nft_data_uninit(const struct nft_data *data, enum nft_data_types type);
1175eccdfaaSJoe Perches int nft_data_dump(struct sk_buff *skb, int attr, const struct nft_data *data,
11896518518SPatrick McHardy 		  enum nft_data_types type, unsigned int len);
11996518518SPatrick McHardy 
12096518518SPatrick McHardy static inline enum nft_data_types nft_dreg_to_type(enum nft_registers reg)
12196518518SPatrick McHardy {
12296518518SPatrick McHardy 	return reg == NFT_REG_VERDICT ? NFT_DATA_VERDICT : NFT_DATA_VALUE;
12396518518SPatrick McHardy }
12496518518SPatrick McHardy 
12520a69341SPatrick McHardy static inline enum nft_registers nft_type_to_reg(enum nft_data_types type)
12620a69341SPatrick McHardy {
127bf798657SPablo Neira Ayuso 	return type == NFT_DATA_VERDICT ? NFT_REG_VERDICT : NFT_REG_1 * NFT_REG_SIZE / NFT_REG32_SIZE;
12820a69341SPatrick McHardy }
12920a69341SPatrick McHardy 
130b1c96ed3SPatrick McHardy unsigned int nft_parse_register(const struct nlattr *attr);
131b1c96ed3SPatrick McHardy int nft_dump_register(struct sk_buff *skb, unsigned int attr, unsigned int reg);
132b1c96ed3SPatrick McHardy 
133d07db988SPatrick McHardy int nft_validate_register_load(enum nft_registers reg, unsigned int len);
1341ec10212SPatrick McHardy int nft_validate_register_store(const struct nft_ctx *ctx,
1351ec10212SPatrick McHardy 				enum nft_registers reg,
13696518518SPatrick McHardy 				const struct nft_data *data,
13745d9bcdaSPatrick McHardy 				enum nft_data_types type, unsigned int len);
13896518518SPatrick McHardy 
13986f1ec32SPatrick McHardy /**
14086f1ec32SPatrick McHardy  *	struct nft_userdata - user defined data associated with an object
14186f1ec32SPatrick McHardy  *
14286f1ec32SPatrick McHardy  *	@len: length of the data
14386f1ec32SPatrick McHardy  *	@data: content
14486f1ec32SPatrick McHardy  *
14586f1ec32SPatrick McHardy  *	The presence of user data is indicated in an object specific fashion,
14686f1ec32SPatrick McHardy  *	so a length of zero can't occur and the value "len" indicates data
14786f1ec32SPatrick McHardy  *	of length len + 1.
14886f1ec32SPatrick McHardy  */
14986f1ec32SPatrick McHardy struct nft_userdata {
15086f1ec32SPatrick McHardy 	u8			len;
15186f1ec32SPatrick McHardy 	unsigned char		data[0];
15286f1ec32SPatrick McHardy };
15386f1ec32SPatrick McHardy 
15496518518SPatrick McHardy /**
15520a69341SPatrick McHardy  *	struct nft_set_elem - generic representation of set elements
15620a69341SPatrick McHardy  *
15720a69341SPatrick McHardy  *	@key: element key
158fe2811ebSPatrick McHardy  *	@priv: element private data and extensions
15920a69341SPatrick McHardy  */
16020a69341SPatrick McHardy struct nft_set_elem {
1617d740264SPatrick McHardy 	union {
1627d740264SPatrick McHardy 		u32		buf[NFT_DATA_VALUE_MAXLEN / sizeof(u32)];
1637d740264SPatrick McHardy 		struct nft_data	val;
1647d740264SPatrick McHardy 	} key;
165fe2811ebSPatrick McHardy 	void			*priv;
16620a69341SPatrick McHardy };
16720a69341SPatrick McHardy 
16820a69341SPatrick McHardy struct nft_set;
16920a69341SPatrick McHardy struct nft_set_iter {
17020a69341SPatrick McHardy 	unsigned int	count;
17120a69341SPatrick McHardy 	unsigned int	skip;
17220a69341SPatrick McHardy 	int		err;
17320a69341SPatrick McHardy 	int		(*fn)(const struct nft_ctx *ctx,
17420a69341SPatrick McHardy 			      const struct nft_set *set,
17520a69341SPatrick McHardy 			      const struct nft_set_iter *iter,
17620a69341SPatrick McHardy 			      const struct nft_set_elem *elem);
17720a69341SPatrick McHardy };
17820a69341SPatrick McHardy 
17920a69341SPatrick McHardy /**
180c50b960cSPatrick McHardy  *	struct nft_set_desc - description of set elements
181c50b960cSPatrick McHardy  *
182c50b960cSPatrick McHardy  *	@klen: key length
183c50b960cSPatrick McHardy  *	@dlen: data length
184c50b960cSPatrick McHardy  *	@size: number of set elements
185c50b960cSPatrick McHardy  */
186c50b960cSPatrick McHardy struct nft_set_desc {
187c50b960cSPatrick McHardy 	unsigned int		klen;
188c50b960cSPatrick McHardy 	unsigned int		dlen;
189c50b960cSPatrick McHardy 	unsigned int		size;
190c50b960cSPatrick McHardy };
191c50b960cSPatrick McHardy 
192c50b960cSPatrick McHardy /**
193c50b960cSPatrick McHardy  *	enum nft_set_class - performance class
194c50b960cSPatrick McHardy  *
195c50b960cSPatrick McHardy  *	@NFT_LOOKUP_O_1: constant, O(1)
196c50b960cSPatrick McHardy  *	@NFT_LOOKUP_O_LOG_N: logarithmic, O(log N)
197c50b960cSPatrick McHardy  *	@NFT_LOOKUP_O_N: linear, O(N)
198c50b960cSPatrick McHardy  */
199c50b960cSPatrick McHardy enum nft_set_class {
200c50b960cSPatrick McHardy 	NFT_SET_CLASS_O_1,
201c50b960cSPatrick McHardy 	NFT_SET_CLASS_O_LOG_N,
202c50b960cSPatrick McHardy 	NFT_SET_CLASS_O_N,
203c50b960cSPatrick McHardy };
204c50b960cSPatrick McHardy 
205c50b960cSPatrick McHardy /**
206c50b960cSPatrick McHardy  *	struct nft_set_estimate - estimation of memory and performance
207c50b960cSPatrick McHardy  *				  characteristics
208c50b960cSPatrick McHardy  *
209c50b960cSPatrick McHardy  *	@size: required memory
210c50b960cSPatrick McHardy  *	@class: lookup performance class
211c50b960cSPatrick McHardy  */
212c50b960cSPatrick McHardy struct nft_set_estimate {
213c50b960cSPatrick McHardy 	unsigned int		size;
214c50b960cSPatrick McHardy 	enum nft_set_class	class;
215c50b960cSPatrick McHardy };
216c50b960cSPatrick McHardy 
217b2832dd6SPatrick McHardy struct nft_set_ext;
21822fe54d5SPatrick McHardy struct nft_expr;
219b2832dd6SPatrick McHardy 
220c50b960cSPatrick McHardy /**
22120a69341SPatrick McHardy  *	struct nft_set_ops - nf_tables set operations
22220a69341SPatrick McHardy  *
22320a69341SPatrick McHardy  *	@lookup: look up an element within the set
22420a69341SPatrick McHardy  *	@insert: insert new element into set
225cc02e457SPatrick McHardy  *	@activate: activate new element in the next generation
226cc02e457SPatrick McHardy  *	@deactivate: deactivate element in the next generation
22720a69341SPatrick McHardy  *	@remove: remove element from set
22820a69341SPatrick McHardy  *	@walk: iterate over all set elemeennts
22920a69341SPatrick McHardy  *	@privsize: function to return size of set private data
23020a69341SPatrick McHardy  *	@init: initialize private data of new set instance
23120a69341SPatrick McHardy  *	@destroy: destroy private data of set instance
23220a69341SPatrick McHardy  *	@list: nf_tables_set_ops list node
23320a69341SPatrick McHardy  *	@owner: module reference
234fe2811ebSPatrick McHardy  *	@elemsize: element private size
23520a69341SPatrick McHardy  *	@features: features supported by the implementation
23620a69341SPatrick McHardy  */
23720a69341SPatrick McHardy struct nft_set_ops {
23820a69341SPatrick McHardy 	bool				(*lookup)(const struct nft_set *set,
2398cd8937aSPatrick McHardy 						  const u32 *key,
240b2832dd6SPatrick McHardy 						  const struct nft_set_ext **ext);
24122fe54d5SPatrick McHardy 	bool				(*update)(struct nft_set *set,
2428cd8937aSPatrick McHardy 						  const u32 *key,
24322fe54d5SPatrick McHardy 						  void *(*new)(struct nft_set *,
24422fe54d5SPatrick McHardy 							       const struct nft_expr *,
245a55e22e9SPatrick McHardy 							       struct nft_regs *),
24622fe54d5SPatrick McHardy 						  const struct nft_expr *expr,
247a55e22e9SPatrick McHardy 						  struct nft_regs *regs,
24822fe54d5SPatrick McHardy 						  const struct nft_set_ext **ext);
24922fe54d5SPatrick McHardy 
25020a69341SPatrick McHardy 	int				(*insert)(const struct nft_set *set,
25120a69341SPatrick McHardy 						  const struct nft_set_elem *elem);
252cc02e457SPatrick McHardy 	void				(*activate)(const struct nft_set *set,
253cc02e457SPatrick McHardy 						    const struct nft_set_elem *elem);
254cc02e457SPatrick McHardy 	void *				(*deactivate)(const struct nft_set *set,
255cc02e457SPatrick McHardy 						      const struct nft_set_elem *elem);
25620a69341SPatrick McHardy 	void				(*remove)(const struct nft_set *set,
25720a69341SPatrick McHardy 						  const struct nft_set_elem *elem);
25820a69341SPatrick McHardy 	void				(*walk)(const struct nft_ctx *ctx,
25920a69341SPatrick McHardy 						const struct nft_set *set,
26020a69341SPatrick McHardy 						struct nft_set_iter *iter);
26120a69341SPatrick McHardy 
26220a69341SPatrick McHardy 	unsigned int			(*privsize)(const struct nlattr * const nla[]);
263c50b960cSPatrick McHardy 	bool				(*estimate)(const struct nft_set_desc *desc,
264c50b960cSPatrick McHardy 						    u32 features,
265c50b960cSPatrick McHardy 						    struct nft_set_estimate *est);
26620a69341SPatrick McHardy 	int				(*init)(const struct nft_set *set,
267c50b960cSPatrick McHardy 						const struct nft_set_desc *desc,
26820a69341SPatrick McHardy 						const struct nlattr * const nla[]);
26920a69341SPatrick McHardy 	void				(*destroy)(const struct nft_set *set);
27020a69341SPatrick McHardy 
27120a69341SPatrick McHardy 	struct list_head		list;
27220a69341SPatrick McHardy 	struct module			*owner;
273fe2811ebSPatrick McHardy 	unsigned int			elemsize;
27420a69341SPatrick McHardy 	u32				features;
27520a69341SPatrick McHardy };
27620a69341SPatrick McHardy 
2775eccdfaaSJoe Perches int nft_register_set(struct nft_set_ops *ops);
2785eccdfaaSJoe Perches void nft_unregister_set(struct nft_set_ops *ops);
27920a69341SPatrick McHardy 
28020a69341SPatrick McHardy /**
28120a69341SPatrick McHardy  * 	struct nft_set - nf_tables set instance
28220a69341SPatrick McHardy  *
28320a69341SPatrick McHardy  *	@list: table set list node
28420a69341SPatrick McHardy  *	@bindings: list of set bindings
28520a69341SPatrick McHardy  * 	@name: name of the set
28620a69341SPatrick McHardy  * 	@ktype: key type (numeric type defined by userspace, not used in the kernel)
28720a69341SPatrick McHardy  * 	@dtype: data type (verdict or numeric type defined by userspace)
288c50b960cSPatrick McHardy  * 	@size: maximum set size
289c50b960cSPatrick McHardy  * 	@nelems: number of elements
2903dd0673aSPatrick McHardy  * 	@ndeact: number of deactivated elements queued for removal
291761da293SPatrick McHardy  * 	@timeout: default timeout value in msecs
292761da293SPatrick McHardy  * 	@gc_int: garbage collection interval in msecs
2939363dc4bSArturo Borrero  *	@policy: set parameterization (see enum nft_set_policies)
294e6d8ecacSCarlos Falgueras García  *	@udlen: user data length
295e6d8ecacSCarlos Falgueras García  *	@udata: user data
29620a69341SPatrick McHardy  * 	@ops: set ops
297cc02e457SPatrick McHardy  * 	@pnet: network namespace
29820a69341SPatrick McHardy  * 	@flags: set flags
29920a69341SPatrick McHardy  * 	@klen: key length
30020a69341SPatrick McHardy  * 	@dlen: data length
30120a69341SPatrick McHardy  * 	@data: private set data
30220a69341SPatrick McHardy  */
30320a69341SPatrick McHardy struct nft_set {
30420a69341SPatrick McHardy 	struct list_head		list;
30520a69341SPatrick McHardy 	struct list_head		bindings;
306cb39ad8bSPablo Neira Ayuso 	char				name[NFT_SET_MAXNAMELEN];
30720a69341SPatrick McHardy 	u32				ktype;
30820a69341SPatrick McHardy 	u32				dtype;
309c50b960cSPatrick McHardy 	u32				size;
3103dd0673aSPatrick McHardy 	atomic_t			nelems;
3113dd0673aSPatrick McHardy 	u32				ndeact;
312761da293SPatrick McHardy 	u64				timeout;
313761da293SPatrick McHardy 	u32				gc_int;
3149363dc4bSArturo Borrero 	u16				policy;
315e6d8ecacSCarlos Falgueras García 	u16				udlen;
316e6d8ecacSCarlos Falgueras García 	unsigned char			*udata;
31720a69341SPatrick McHardy 	/* runtime data below here */
31820a69341SPatrick McHardy 	const struct nft_set_ops	*ops ____cacheline_aligned;
319cc02e457SPatrick McHardy 	possible_net_t			pnet;
32020a69341SPatrick McHardy 	u16				flags;
32120a69341SPatrick McHardy 	u8				klen;
32220a69341SPatrick McHardy 	u8				dlen;
32320a69341SPatrick McHardy 	unsigned char			data[]
32420a69341SPatrick McHardy 		__attribute__((aligned(__alignof__(u64))));
32520a69341SPatrick McHardy };
32620a69341SPatrick McHardy 
32720a69341SPatrick McHardy static inline void *nft_set_priv(const struct nft_set *set)
32820a69341SPatrick McHardy {
32920a69341SPatrick McHardy 	return (void *)set->data;
33020a69341SPatrick McHardy }
33120a69341SPatrick McHardy 
3329d098292SPatrick McHardy static inline struct nft_set *nft_set_container_of(const void *priv)
3339d098292SPatrick McHardy {
3349d098292SPatrick McHardy 	return (void *)priv - offsetof(struct nft_set, data);
3359d098292SPatrick McHardy }
3369d098292SPatrick McHardy 
3375eccdfaaSJoe Perches struct nft_set *nf_tables_set_lookup(const struct nft_table *table,
33820a69341SPatrick McHardy 				     const struct nlattr *nla);
339958bee14SPablo Neira Ayuso struct nft_set *nf_tables_set_lookup_byid(const struct net *net,
340958bee14SPablo Neira Ayuso 					  const struct nlattr *nla);
34120a69341SPatrick McHardy 
342761da293SPatrick McHardy static inline unsigned long nft_set_gc_interval(const struct nft_set *set)
343761da293SPatrick McHardy {
344761da293SPatrick McHardy 	return set->gc_int ? msecs_to_jiffies(set->gc_int) : HZ;
345761da293SPatrick McHardy }
346761da293SPatrick McHardy 
34720a69341SPatrick McHardy /**
34820a69341SPatrick McHardy  *	struct nft_set_binding - nf_tables set binding
34920a69341SPatrick McHardy  *
35020a69341SPatrick McHardy  *	@list: set bindings list node
35120a69341SPatrick McHardy  *	@chain: chain containing the rule bound to the set
35211113e19SPatrick McHardy  *	@flags: set action flags
35320a69341SPatrick McHardy  *
35420a69341SPatrick McHardy  *	A set binding contains all information necessary for validation
35520a69341SPatrick McHardy  *	of new elements added to a bound set.
35620a69341SPatrick McHardy  */
35720a69341SPatrick McHardy struct nft_set_binding {
35820a69341SPatrick McHardy 	struct list_head		list;
35920a69341SPatrick McHardy 	const struct nft_chain		*chain;
36011113e19SPatrick McHardy 	u32				flags;
36120a69341SPatrick McHardy };
36220a69341SPatrick McHardy 
3635eccdfaaSJoe Perches int nf_tables_bind_set(const struct nft_ctx *ctx, struct nft_set *set,
36420a69341SPatrick McHardy 		       struct nft_set_binding *binding);
3655eccdfaaSJoe Perches void nf_tables_unbind_set(const struct nft_ctx *ctx, struct nft_set *set,
36620a69341SPatrick McHardy 			  struct nft_set_binding *binding);
36720a69341SPatrick McHardy 
3683ac4c07aSPatrick McHardy /**
3693ac4c07aSPatrick McHardy  *	enum nft_set_extensions - set extension type IDs
3703ac4c07aSPatrick McHardy  *
3713ac4c07aSPatrick McHardy  *	@NFT_SET_EXT_KEY: element key
3723ac4c07aSPatrick McHardy  *	@NFT_SET_EXT_DATA: mapping data
3733ac4c07aSPatrick McHardy  *	@NFT_SET_EXT_FLAGS: element flags
374c3e1b005SPatrick McHardy  *	@NFT_SET_EXT_TIMEOUT: element timeout
375c3e1b005SPatrick McHardy  *	@NFT_SET_EXT_EXPIRATION: element expiration time
37668e942e8SPatrick McHardy  *	@NFT_SET_EXT_USERDATA: user data associated with the element
377f25ad2e9SPatrick McHardy  *	@NFT_SET_EXT_EXPR: expression assiociated with the element
3783ac4c07aSPatrick McHardy  *	@NFT_SET_EXT_NUM: number of extension types
3793ac4c07aSPatrick McHardy  */
3803ac4c07aSPatrick McHardy enum nft_set_extensions {
3813ac4c07aSPatrick McHardy 	NFT_SET_EXT_KEY,
3823ac4c07aSPatrick McHardy 	NFT_SET_EXT_DATA,
3833ac4c07aSPatrick McHardy 	NFT_SET_EXT_FLAGS,
384c3e1b005SPatrick McHardy 	NFT_SET_EXT_TIMEOUT,
385c3e1b005SPatrick McHardy 	NFT_SET_EXT_EXPIRATION,
38668e942e8SPatrick McHardy 	NFT_SET_EXT_USERDATA,
387f25ad2e9SPatrick McHardy 	NFT_SET_EXT_EXPR,
3883ac4c07aSPatrick McHardy 	NFT_SET_EXT_NUM
3893ac4c07aSPatrick McHardy };
3903ac4c07aSPatrick McHardy 
3913ac4c07aSPatrick McHardy /**
3923ac4c07aSPatrick McHardy  *	struct nft_set_ext_type - set extension type
3933ac4c07aSPatrick McHardy  *
3943ac4c07aSPatrick McHardy  * 	@len: fixed part length of the extension
3953ac4c07aSPatrick McHardy  * 	@align: alignment requirements of the extension
3963ac4c07aSPatrick McHardy  */
3973ac4c07aSPatrick McHardy struct nft_set_ext_type {
3983ac4c07aSPatrick McHardy 	u8	len;
3993ac4c07aSPatrick McHardy 	u8	align;
4003ac4c07aSPatrick McHardy };
4013ac4c07aSPatrick McHardy 
4023ac4c07aSPatrick McHardy extern const struct nft_set_ext_type nft_set_ext_types[];
4033ac4c07aSPatrick McHardy 
4043ac4c07aSPatrick McHardy /**
4053ac4c07aSPatrick McHardy  *	struct nft_set_ext_tmpl - set extension template
4063ac4c07aSPatrick McHardy  *
4073ac4c07aSPatrick McHardy  *	@len: length of extension area
4083ac4c07aSPatrick McHardy  *	@offset: offsets of individual extension types
4093ac4c07aSPatrick McHardy  */
4103ac4c07aSPatrick McHardy struct nft_set_ext_tmpl {
4113ac4c07aSPatrick McHardy 	u16	len;
4123ac4c07aSPatrick McHardy 	u8	offset[NFT_SET_EXT_NUM];
4133ac4c07aSPatrick McHardy };
4143ac4c07aSPatrick McHardy 
4153ac4c07aSPatrick McHardy /**
4163ac4c07aSPatrick McHardy  *	struct nft_set_ext - set extensions
4173ac4c07aSPatrick McHardy  *
418cc02e457SPatrick McHardy  *	@genmask: generation mask
4193ac4c07aSPatrick McHardy  *	@offset: offsets of individual extension types
4203ac4c07aSPatrick McHardy  *	@data: beginning of extension data
4213ac4c07aSPatrick McHardy  */
4223ac4c07aSPatrick McHardy struct nft_set_ext {
423cc02e457SPatrick McHardy 	u8	genmask;
4243ac4c07aSPatrick McHardy 	u8	offset[NFT_SET_EXT_NUM];
4253ac4c07aSPatrick McHardy 	char	data[0];
4263ac4c07aSPatrick McHardy };
4273ac4c07aSPatrick McHardy 
4283ac4c07aSPatrick McHardy static inline void nft_set_ext_prepare(struct nft_set_ext_tmpl *tmpl)
4293ac4c07aSPatrick McHardy {
4303ac4c07aSPatrick McHardy 	memset(tmpl, 0, sizeof(*tmpl));
4313ac4c07aSPatrick McHardy 	tmpl->len = sizeof(struct nft_set_ext);
4323ac4c07aSPatrick McHardy }
4333ac4c07aSPatrick McHardy 
4343ac4c07aSPatrick McHardy static inline void nft_set_ext_add_length(struct nft_set_ext_tmpl *tmpl, u8 id,
4353ac4c07aSPatrick McHardy 					  unsigned int len)
4363ac4c07aSPatrick McHardy {
4373ac4c07aSPatrick McHardy 	tmpl->len	 = ALIGN(tmpl->len, nft_set_ext_types[id].align);
4383ac4c07aSPatrick McHardy 	BUG_ON(tmpl->len > U8_MAX);
4393ac4c07aSPatrick McHardy 	tmpl->offset[id] = tmpl->len;
4403ac4c07aSPatrick McHardy 	tmpl->len	+= nft_set_ext_types[id].len + len;
4413ac4c07aSPatrick McHardy }
4423ac4c07aSPatrick McHardy 
4433ac4c07aSPatrick McHardy static inline void nft_set_ext_add(struct nft_set_ext_tmpl *tmpl, u8 id)
4443ac4c07aSPatrick McHardy {
4453ac4c07aSPatrick McHardy 	nft_set_ext_add_length(tmpl, id, 0);
4463ac4c07aSPatrick McHardy }
4473ac4c07aSPatrick McHardy 
4483ac4c07aSPatrick McHardy static inline void nft_set_ext_init(struct nft_set_ext *ext,
4493ac4c07aSPatrick McHardy 				    const struct nft_set_ext_tmpl *tmpl)
4503ac4c07aSPatrick McHardy {
4513ac4c07aSPatrick McHardy 	memcpy(ext->offset, tmpl->offset, sizeof(ext->offset));
4523ac4c07aSPatrick McHardy }
4533ac4c07aSPatrick McHardy 
4543ac4c07aSPatrick McHardy static inline bool __nft_set_ext_exists(const struct nft_set_ext *ext, u8 id)
4553ac4c07aSPatrick McHardy {
4563ac4c07aSPatrick McHardy 	return !!ext->offset[id];
4573ac4c07aSPatrick McHardy }
4583ac4c07aSPatrick McHardy 
4593ac4c07aSPatrick McHardy static inline bool nft_set_ext_exists(const struct nft_set_ext *ext, u8 id)
4603ac4c07aSPatrick McHardy {
4613ac4c07aSPatrick McHardy 	return ext && __nft_set_ext_exists(ext, id);
4623ac4c07aSPatrick McHardy }
4633ac4c07aSPatrick McHardy 
4643ac4c07aSPatrick McHardy static inline void *nft_set_ext(const struct nft_set_ext *ext, u8 id)
4653ac4c07aSPatrick McHardy {
4663ac4c07aSPatrick McHardy 	return (void *)ext + ext->offset[id];
4673ac4c07aSPatrick McHardy }
4683ac4c07aSPatrick McHardy 
4693ac4c07aSPatrick McHardy static inline struct nft_data *nft_set_ext_key(const struct nft_set_ext *ext)
4703ac4c07aSPatrick McHardy {
4713ac4c07aSPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_KEY);
4723ac4c07aSPatrick McHardy }
4733ac4c07aSPatrick McHardy 
4743ac4c07aSPatrick McHardy static inline struct nft_data *nft_set_ext_data(const struct nft_set_ext *ext)
4753ac4c07aSPatrick McHardy {
4763ac4c07aSPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_DATA);
4773ac4c07aSPatrick McHardy }
4783ac4c07aSPatrick McHardy 
4793ac4c07aSPatrick McHardy static inline u8 *nft_set_ext_flags(const struct nft_set_ext *ext)
4803ac4c07aSPatrick McHardy {
4813ac4c07aSPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_FLAGS);
4823ac4c07aSPatrick McHardy }
483ef1f7df9SPatrick McHardy 
484c3e1b005SPatrick McHardy static inline u64 *nft_set_ext_timeout(const struct nft_set_ext *ext)
485c3e1b005SPatrick McHardy {
486c3e1b005SPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_TIMEOUT);
487c3e1b005SPatrick McHardy }
488c3e1b005SPatrick McHardy 
489c3e1b005SPatrick McHardy static inline unsigned long *nft_set_ext_expiration(const struct nft_set_ext *ext)
490c3e1b005SPatrick McHardy {
491c3e1b005SPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_EXPIRATION);
492c3e1b005SPatrick McHardy }
493c3e1b005SPatrick McHardy 
49468e942e8SPatrick McHardy static inline struct nft_userdata *nft_set_ext_userdata(const struct nft_set_ext *ext)
49568e942e8SPatrick McHardy {
49668e942e8SPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_USERDATA);
49768e942e8SPatrick McHardy }
49868e942e8SPatrick McHardy 
499f25ad2e9SPatrick McHardy static inline struct nft_expr *nft_set_ext_expr(const struct nft_set_ext *ext)
500f25ad2e9SPatrick McHardy {
501f25ad2e9SPatrick McHardy 	return nft_set_ext(ext, NFT_SET_EXT_EXPR);
502f25ad2e9SPatrick McHardy }
503f25ad2e9SPatrick McHardy 
504c3e1b005SPatrick McHardy static inline bool nft_set_elem_expired(const struct nft_set_ext *ext)
505c3e1b005SPatrick McHardy {
506c3e1b005SPatrick McHardy 	return nft_set_ext_exists(ext, NFT_SET_EXT_EXPIRATION) &&
507c3e1b005SPatrick McHardy 	       time_is_before_eq_jiffies(*nft_set_ext_expiration(ext));
508c3e1b005SPatrick McHardy }
509c3e1b005SPatrick McHardy 
510fe2811ebSPatrick McHardy static inline struct nft_set_ext *nft_set_elem_ext(const struct nft_set *set,
511fe2811ebSPatrick McHardy 						   void *elem)
512fe2811ebSPatrick McHardy {
513fe2811ebSPatrick McHardy 	return elem + set->ops->elemsize;
514fe2811ebSPatrick McHardy }
515fe2811ebSPatrick McHardy 
51622fe54d5SPatrick McHardy void *nft_set_elem_init(const struct nft_set *set,
51722fe54d5SPatrick McHardy 			const struct nft_set_ext_tmpl *tmpl,
51849499c3eSPatrick McHardy 			const u32 *key, const u32 *data,
51922fe54d5SPatrick McHardy 			u64 timeout, gfp_t gfp);
52061edafbbSPatrick McHardy void nft_set_elem_destroy(const struct nft_set *set, void *elem);
52161edafbbSPatrick McHardy 
52220a69341SPatrick McHardy /**
523cfed7e1bSPatrick McHardy  *	struct nft_set_gc_batch_head - nf_tables set garbage collection batch
524cfed7e1bSPatrick McHardy  *
525cfed7e1bSPatrick McHardy  *	@rcu: rcu head
526cfed7e1bSPatrick McHardy  *	@set: set the elements belong to
527cfed7e1bSPatrick McHardy  *	@cnt: count of elements
528cfed7e1bSPatrick McHardy  */
529cfed7e1bSPatrick McHardy struct nft_set_gc_batch_head {
530cfed7e1bSPatrick McHardy 	struct rcu_head			rcu;
531cfed7e1bSPatrick McHardy 	const struct nft_set		*set;
532cfed7e1bSPatrick McHardy 	unsigned int			cnt;
533cfed7e1bSPatrick McHardy };
534cfed7e1bSPatrick McHardy 
535cfed7e1bSPatrick McHardy #define NFT_SET_GC_BATCH_SIZE	((PAGE_SIZE -				  \
536cfed7e1bSPatrick McHardy 				  sizeof(struct nft_set_gc_batch_head)) / \
537cfed7e1bSPatrick McHardy 				 sizeof(void *))
538cfed7e1bSPatrick McHardy 
539cfed7e1bSPatrick McHardy /**
540cfed7e1bSPatrick McHardy  *	struct nft_set_gc_batch - nf_tables set garbage collection batch
541cfed7e1bSPatrick McHardy  *
542cfed7e1bSPatrick McHardy  * 	@head: GC batch head
543cfed7e1bSPatrick McHardy  * 	@elems: garbage collection elements
544cfed7e1bSPatrick McHardy  */
545cfed7e1bSPatrick McHardy struct nft_set_gc_batch {
546cfed7e1bSPatrick McHardy 	struct nft_set_gc_batch_head	head;
547cfed7e1bSPatrick McHardy 	void				*elems[NFT_SET_GC_BATCH_SIZE];
548cfed7e1bSPatrick McHardy };
549cfed7e1bSPatrick McHardy 
550cfed7e1bSPatrick McHardy struct nft_set_gc_batch *nft_set_gc_batch_alloc(const struct nft_set *set,
551cfed7e1bSPatrick McHardy 						gfp_t gfp);
552cfed7e1bSPatrick McHardy void nft_set_gc_batch_release(struct rcu_head *rcu);
553cfed7e1bSPatrick McHardy 
554cfed7e1bSPatrick McHardy static inline void nft_set_gc_batch_complete(struct nft_set_gc_batch *gcb)
555cfed7e1bSPatrick McHardy {
556cfed7e1bSPatrick McHardy 	if (gcb != NULL)
557cfed7e1bSPatrick McHardy 		call_rcu(&gcb->head.rcu, nft_set_gc_batch_release);
558cfed7e1bSPatrick McHardy }
559cfed7e1bSPatrick McHardy 
560cfed7e1bSPatrick McHardy static inline struct nft_set_gc_batch *
561cfed7e1bSPatrick McHardy nft_set_gc_batch_check(const struct nft_set *set, struct nft_set_gc_batch *gcb,
562cfed7e1bSPatrick McHardy 		       gfp_t gfp)
563cfed7e1bSPatrick McHardy {
564cfed7e1bSPatrick McHardy 	if (gcb != NULL) {
565cfed7e1bSPatrick McHardy 		if (gcb->head.cnt + 1 < ARRAY_SIZE(gcb->elems))
566cfed7e1bSPatrick McHardy 			return gcb;
567cfed7e1bSPatrick McHardy 		nft_set_gc_batch_complete(gcb);
568cfed7e1bSPatrick McHardy 	}
569cfed7e1bSPatrick McHardy 	return nft_set_gc_batch_alloc(set, gfp);
570cfed7e1bSPatrick McHardy }
571cfed7e1bSPatrick McHardy 
572cfed7e1bSPatrick McHardy static inline void nft_set_gc_batch_add(struct nft_set_gc_batch *gcb,
573cfed7e1bSPatrick McHardy 					void *elem)
574cfed7e1bSPatrick McHardy {
575cfed7e1bSPatrick McHardy 	gcb->elems[gcb->head.cnt++] = elem;
576cfed7e1bSPatrick McHardy }
577cfed7e1bSPatrick McHardy 
578cfed7e1bSPatrick McHardy /**
579ef1f7df9SPatrick McHardy  *	struct nft_expr_type - nf_tables expression type
58096518518SPatrick McHardy  *
581ef1f7df9SPatrick McHardy  *	@select_ops: function to select nft_expr_ops
582ef1f7df9SPatrick McHardy  *	@ops: default ops, used when no select_ops functions is present
58396518518SPatrick McHardy  *	@list: used internally
58496518518SPatrick McHardy  *	@name: Identifier
58596518518SPatrick McHardy  *	@owner: module reference
58696518518SPatrick McHardy  *	@policy: netlink attribute policy
58796518518SPatrick McHardy  *	@maxattr: highest netlink attribute number
58864d46806SPatrick McHardy  *	@family: address family for AF-specific types
589151d799aSPatrick McHardy  *	@flags: expression type flags
590ef1f7df9SPatrick McHardy  */
591ef1f7df9SPatrick McHardy struct nft_expr_type {
5920ca743a5SPablo Neira Ayuso 	const struct nft_expr_ops	*(*select_ops)(const struct nft_ctx *,
5930ca743a5SPablo Neira Ayuso 						       const struct nlattr * const tb[]);
594ef1f7df9SPatrick McHardy 	const struct nft_expr_ops	*ops;
595ef1f7df9SPatrick McHardy 	struct list_head		list;
596ef1f7df9SPatrick McHardy 	const char			*name;
597ef1f7df9SPatrick McHardy 	struct module			*owner;
598ef1f7df9SPatrick McHardy 	const struct nla_policy		*policy;
599ef1f7df9SPatrick McHardy 	unsigned int			maxattr;
60064d46806SPatrick McHardy 	u8				family;
601151d799aSPatrick McHardy 	u8				flags;
602ef1f7df9SPatrick McHardy };
603ef1f7df9SPatrick McHardy 
604151d799aSPatrick McHardy #define NFT_EXPR_STATEFUL		0x1
605151d799aSPatrick McHardy 
606ef1f7df9SPatrick McHardy /**
607ef1f7df9SPatrick McHardy  *	struct nft_expr_ops - nf_tables expression operations
608ef1f7df9SPatrick McHardy  *
609ef1f7df9SPatrick McHardy  *	@eval: Expression evaluation function
61096518518SPatrick McHardy  *	@size: full expression size, including private data size
611ef1f7df9SPatrick McHardy  *	@init: initialization function
612ef1f7df9SPatrick McHardy  *	@destroy: destruction function
613ef1f7df9SPatrick McHardy  *	@dump: function to dump parameters
614ef1f7df9SPatrick McHardy  *	@type: expression type
6150ca743a5SPablo Neira Ayuso  *	@validate: validate expression, called during loop detection
6160ca743a5SPablo Neira Ayuso  *	@data: extra data to attach to this expression operation
61796518518SPatrick McHardy  */
61896518518SPatrick McHardy struct nft_expr;
61996518518SPatrick McHardy struct nft_expr_ops {
62096518518SPatrick McHardy 	void				(*eval)(const struct nft_expr *expr,
621a55e22e9SPatrick McHardy 						struct nft_regs *regs,
62296518518SPatrick McHardy 						const struct nft_pktinfo *pkt);
623086f3321SPablo Neira Ayuso 	int				(*clone)(struct nft_expr *dst,
624086f3321SPablo Neira Ayuso 						 const struct nft_expr *src);
625ef1f7df9SPatrick McHardy 	unsigned int			size;
626ef1f7df9SPatrick McHardy 
62796518518SPatrick McHardy 	int				(*init)(const struct nft_ctx *ctx,
62896518518SPatrick McHardy 						const struct nft_expr *expr,
62996518518SPatrick McHardy 						const struct nlattr * const tb[]);
63062472bceSPatrick McHardy 	void				(*destroy)(const struct nft_ctx *ctx,
63162472bceSPatrick McHardy 						   const struct nft_expr *expr);
63296518518SPatrick McHardy 	int				(*dump)(struct sk_buff *skb,
63396518518SPatrick McHardy 						const struct nft_expr *expr);
6340ca743a5SPablo Neira Ayuso 	int				(*validate)(const struct nft_ctx *ctx,
6350ca743a5SPablo Neira Ayuso 						    const struct nft_expr *expr,
6360ca743a5SPablo Neira Ayuso 						    const struct nft_data **data);
637ef1f7df9SPatrick McHardy 	const struct nft_expr_type	*type;
6380ca743a5SPablo Neira Ayuso 	void				*data;
63996518518SPatrick McHardy };
64096518518SPatrick McHardy 
641ef1f7df9SPatrick McHardy #define NFT_EXPR_MAXATTR		16
64296518518SPatrick McHardy #define NFT_EXPR_SIZE(size)		(sizeof(struct nft_expr) + \
64396518518SPatrick McHardy 					 ALIGN(size, __alignof__(struct nft_expr)))
64496518518SPatrick McHardy 
64596518518SPatrick McHardy /**
64696518518SPatrick McHardy  *	struct nft_expr - nf_tables expression
64796518518SPatrick McHardy  *
64896518518SPatrick McHardy  *	@ops: expression ops
64996518518SPatrick McHardy  *	@data: expression private data
65096518518SPatrick McHardy  */
65196518518SPatrick McHardy struct nft_expr {
65296518518SPatrick McHardy 	const struct nft_expr_ops	*ops;
65396518518SPatrick McHardy 	unsigned char			data[];
65496518518SPatrick McHardy };
65596518518SPatrick McHardy 
65696518518SPatrick McHardy static inline void *nft_expr_priv(const struct nft_expr *expr)
65796518518SPatrick McHardy {
65896518518SPatrick McHardy 	return (void *)expr->data;
65996518518SPatrick McHardy }
66096518518SPatrick McHardy 
6610b2d8a7bSPatrick McHardy struct nft_expr *nft_expr_init(const struct nft_ctx *ctx,
6620b2d8a7bSPatrick McHardy 			       const struct nlattr *nla);
6630b2d8a7bSPatrick McHardy void nft_expr_destroy(const struct nft_ctx *ctx, struct nft_expr *expr);
6640b2d8a7bSPatrick McHardy int nft_expr_dump(struct sk_buff *skb, unsigned int attr,
6650b2d8a7bSPatrick McHardy 		  const struct nft_expr *expr);
6660b2d8a7bSPatrick McHardy 
667086f3321SPablo Neira Ayuso static inline int nft_expr_clone(struct nft_expr *dst, struct nft_expr *src)
6680b2d8a7bSPatrick McHardy {
669086f3321SPablo Neira Ayuso 	int err;
670086f3321SPablo Neira Ayuso 
6710b2d8a7bSPatrick McHardy 	__module_get(src->ops->type->owner);
672086f3321SPablo Neira Ayuso 	if (src->ops->clone) {
673086f3321SPablo Neira Ayuso 		dst->ops = src->ops;
674086f3321SPablo Neira Ayuso 		err = src->ops->clone(dst, src);
675086f3321SPablo Neira Ayuso 		if (err < 0)
676086f3321SPablo Neira Ayuso 			return err;
677086f3321SPablo Neira Ayuso 	} else {
6780b2d8a7bSPatrick McHardy 		memcpy(dst, src, src->ops->size);
6790b2d8a7bSPatrick McHardy 	}
680086f3321SPablo Neira Ayuso 	return 0;
681086f3321SPablo Neira Ayuso }
6820b2d8a7bSPatrick McHardy 
68396518518SPatrick McHardy /**
68496518518SPatrick McHardy  *	struct nft_rule - nf_tables rule
68596518518SPatrick McHardy  *
68696518518SPatrick McHardy  *	@list: used internally
68796518518SPatrick McHardy  *	@handle: rule handle
6880628b123SPablo Neira Ayuso  *	@genmask: generation mask
68996518518SPatrick McHardy  *	@dlen: length of expression data
69086f1ec32SPatrick McHardy  *	@udata: user data is appended to the rule
69196518518SPatrick McHardy  *	@data: expression data
69296518518SPatrick McHardy  */
69396518518SPatrick McHardy struct nft_rule {
69496518518SPatrick McHardy 	struct list_head		list;
6950768b3b3SPablo Neira Ayuso 	u64				handle:42,
6960628b123SPablo Neira Ayuso 					genmask:2,
6970768b3b3SPablo Neira Ayuso 					dlen:12,
69886f1ec32SPatrick McHardy 					udata:1;
69996518518SPatrick McHardy 	unsigned char			data[]
70096518518SPatrick McHardy 		__attribute__((aligned(__alignof__(struct nft_expr))));
70196518518SPatrick McHardy };
70296518518SPatrick McHardy 
70396518518SPatrick McHardy static inline struct nft_expr *nft_expr_first(const struct nft_rule *rule)
70496518518SPatrick McHardy {
70596518518SPatrick McHardy 	return (struct nft_expr *)&rule->data[0];
70696518518SPatrick McHardy }
70796518518SPatrick McHardy 
70896518518SPatrick McHardy static inline struct nft_expr *nft_expr_next(const struct nft_expr *expr)
70996518518SPatrick McHardy {
71096518518SPatrick McHardy 	return ((void *)expr) + expr->ops->size;
71196518518SPatrick McHardy }
71296518518SPatrick McHardy 
71396518518SPatrick McHardy static inline struct nft_expr *nft_expr_last(const struct nft_rule *rule)
71496518518SPatrick McHardy {
71596518518SPatrick McHardy 	return (struct nft_expr *)&rule->data[rule->dlen];
71696518518SPatrick McHardy }
71796518518SPatrick McHardy 
71886f1ec32SPatrick McHardy static inline struct nft_userdata *nft_userdata(const struct nft_rule *rule)
7190768b3b3SPablo Neira Ayuso {
7200768b3b3SPablo Neira Ayuso 	return (void *)&rule->data[rule->dlen];
7210768b3b3SPablo Neira Ayuso }
7220768b3b3SPablo Neira Ayuso 
72396518518SPatrick McHardy /*
72496518518SPatrick McHardy  * The last pointer isn't really necessary, but the compiler isn't able to
72596518518SPatrick McHardy  * determine that the result of nft_expr_last() is always the same since it
72696518518SPatrick McHardy  * can't assume that the dlen value wasn't changed within calls in the loop.
72796518518SPatrick McHardy  */
72896518518SPatrick McHardy #define nft_rule_for_each_expr(expr, last, rule) \
72996518518SPatrick McHardy 	for ((expr) = nft_expr_first(rule), (last) = nft_expr_last(rule); \
73096518518SPatrick McHardy 	     (expr) != (last); \
73196518518SPatrick McHardy 	     (expr) = nft_expr_next(expr))
73296518518SPatrick McHardy 
73396518518SPatrick McHardy enum nft_chain_flags {
73496518518SPatrick McHardy 	NFT_BASE_CHAIN			= 0x1,
73591c7b38dSPablo Neira Ayuso 	NFT_CHAIN_INACTIVE		= 0x2,
73696518518SPatrick McHardy };
73796518518SPatrick McHardy 
73896518518SPatrick McHardy /**
73996518518SPatrick McHardy  *	struct nft_chain - nf_tables chain
74096518518SPatrick McHardy  *
74196518518SPatrick McHardy  *	@rules: list of rules in the chain
74296518518SPatrick McHardy  *	@list: used internally
743b5bc89bfSPablo Neira Ayuso  *	@table: table that this chain belongs to
74496518518SPatrick McHardy  *	@handle: chain handle
74596518518SPatrick McHardy  *	@use: number of jump references to this chain
74696518518SPatrick McHardy  *	@level: length of longest path to this chain
747a0a7379eSPablo Neira Ayuso  *	@flags: bitmask of enum nft_chain_flags
74896518518SPatrick McHardy  *	@name: name of the chain
74996518518SPatrick McHardy  */
75096518518SPatrick McHardy struct nft_chain {
75196518518SPatrick McHardy 	struct list_head		rules;
75296518518SPatrick McHardy 	struct list_head		list;
753b5bc89bfSPablo Neira Ayuso 	struct nft_table		*table;
75496518518SPatrick McHardy 	u64				handle;
755a0a7379eSPablo Neira Ayuso 	u32				use;
75696518518SPatrick McHardy 	u16				level;
757a0a7379eSPablo Neira Ayuso 	u8				flags;
75896518518SPatrick McHardy 	char				name[NFT_CHAIN_MAXNAMELEN];
75996518518SPatrick McHardy };
76096518518SPatrick McHardy 
7619370761cSPablo Neira Ayuso enum nft_chain_type {
7629370761cSPablo Neira Ayuso 	NFT_CHAIN_T_DEFAULT = 0,
7639370761cSPablo Neira Ayuso 	NFT_CHAIN_T_ROUTE,
7649370761cSPablo Neira Ayuso 	NFT_CHAIN_T_NAT,
7659370761cSPablo Neira Ayuso 	NFT_CHAIN_T_MAX
7669370761cSPablo Neira Ayuso };
7679370761cSPablo Neira Ayuso 
7681a1e1a12SPatrick McHardy /**
7691a1e1a12SPatrick McHardy  * 	struct nf_chain_type - nf_tables chain type info
7701a1e1a12SPatrick McHardy  *
7711a1e1a12SPatrick McHardy  * 	@name: name of the type
7721a1e1a12SPatrick McHardy  * 	@type: numeric identifier
7731a1e1a12SPatrick McHardy  * 	@family: address family
7741a1e1a12SPatrick McHardy  * 	@owner: module owner
7751a1e1a12SPatrick McHardy  * 	@hook_mask: mask of valid hooks
7761a1e1a12SPatrick McHardy  * 	@hooks: hookfn overrides
7771a1e1a12SPatrick McHardy  */
7781a1e1a12SPatrick McHardy struct nf_chain_type {
7791a1e1a12SPatrick McHardy 	const char			*name;
7801a1e1a12SPatrick McHardy 	enum nft_chain_type		type;
7811a1e1a12SPatrick McHardy 	int				family;
7821a1e1a12SPatrick McHardy 	struct module			*owner;
7831a1e1a12SPatrick McHardy 	unsigned int			hook_mask;
7841a1e1a12SPatrick McHardy 	nf_hookfn			*hooks[NF_MAX_HOOKS];
7851a1e1a12SPatrick McHardy };
7861a1e1a12SPatrick McHardy 
7877210e4e3SPablo Neira Ayuso int nft_chain_validate_dependency(const struct nft_chain *chain,
7887210e4e3SPablo Neira Ayuso 				  enum nft_chain_type type);
78975e8d06dSPablo Neira Ayuso int nft_chain_validate_hooks(const struct nft_chain *chain,
79075e8d06dSPablo Neira Ayuso                              unsigned int hook_flags);
7917210e4e3SPablo Neira Ayuso 
7920ca743a5SPablo Neira Ayuso struct nft_stats {
7930ca743a5SPablo Neira Ayuso 	u64			bytes;
7940ca743a5SPablo Neira Ayuso 	u64			pkts;
795ce355e20SEric Dumazet 	struct u64_stats_sync	syncp;
7960ca743a5SPablo Neira Ayuso };
7970ca743a5SPablo Neira Ayuso 
798115a60b1SPatrick McHardy #define NFT_HOOK_OPS_MAX		2
799835b8033SPablo Neira Ayuso #define NFT_BASECHAIN_DISABLED		(1 << 0)
800115a60b1SPatrick McHardy 
80196518518SPatrick McHardy /**
80296518518SPatrick McHardy  *	struct nft_base_chain - nf_tables base chain
80396518518SPatrick McHardy  *
80496518518SPatrick McHardy  *	@ops: netfilter hook ops
8055ebb335dSPatrick McHardy  *	@pnet: net namespace that this chain belongs to
8069370761cSPablo Neira Ayuso  *	@type: chain type
8070ca743a5SPablo Neira Ayuso  *	@policy: default policy
8080ca743a5SPablo Neira Ayuso  *	@stats: per-cpu chain stats
80996518518SPatrick McHardy  *	@chain: the chain
8102cbce139SPablo Neira Ayuso  *	@dev_name: device name that this base chain is attached to (if any)
81196518518SPatrick McHardy  */
81296518518SPatrick McHardy struct nft_base_chain {
813115a60b1SPatrick McHardy 	struct nf_hook_ops		ops[NFT_HOOK_OPS_MAX];
8145ebb335dSPatrick McHardy 	possible_net_t			pnet;
8152a37d755SPatrick McHardy 	const struct nf_chain_type	*type;
8160ca743a5SPablo Neira Ayuso 	u8				policy;
817835b8033SPablo Neira Ayuso 	u8				flags;
8180ca743a5SPablo Neira Ayuso 	struct nft_stats __percpu	*stats;
81996518518SPatrick McHardy 	struct nft_chain		chain;
8202cbce139SPablo Neira Ayuso 	char 				dev_name[IFNAMSIZ];
82196518518SPatrick McHardy };
82296518518SPatrick McHardy 
82396518518SPatrick McHardy static inline struct nft_base_chain *nft_base_chain(const struct nft_chain *chain)
82496518518SPatrick McHardy {
82596518518SPatrick McHardy 	return container_of(chain, struct nft_base_chain, chain);
82696518518SPatrick McHardy }
82796518518SPatrick McHardy 
8285ebe0b0eSPablo Neira Ayuso int __nft_release_basechain(struct nft_ctx *ctx);
829835b8033SPablo Neira Ayuso 
83006198b34SEric W. Biederman unsigned int nft_do_chain(struct nft_pktinfo *pkt, void *priv);
83196518518SPatrick McHardy 
83296518518SPatrick McHardy /**
83396518518SPatrick McHardy  *	struct nft_table - nf_tables table
83496518518SPatrick McHardy  *
83596518518SPatrick McHardy  *	@list: used internally
83696518518SPatrick McHardy  *	@chains: chains in the table
83796518518SPatrick McHardy  *	@sets: sets in the table
83896518518SPatrick McHardy  *	@hgenerator: handle generator state
83996518518SPatrick McHardy  *	@use: number of chain references to this table
84096518518SPatrick McHardy  *	@flags: table flag (see enum nft_table_flags)
841f2a6d766SPablo Neira Ayuso  *	@genmask: generation mask
84296518518SPatrick McHardy  *	@name: name of the table
84396518518SPatrick McHardy  */
84496518518SPatrick McHardy struct nft_table {
84596518518SPatrick McHardy 	struct list_head		list;
84696518518SPatrick McHardy 	struct list_head		chains;
84796518518SPatrick McHardy 	struct list_head		sets;
84896518518SPatrick McHardy 	u64				hgenerator;
84996518518SPatrick McHardy 	u32				use;
850f2a6d766SPablo Neira Ayuso 	u16				flags:14,
851f2a6d766SPablo Neira Ayuso 					genmask:2;
8521cae565eSPablo Neira Ayuso 	char				name[NFT_TABLE_MAXNAMELEN];
853ebddf1a8SPablo Neira Ayuso };
854ebddf1a8SPablo Neira Ayuso 
855ebddf1a8SPablo Neira Ayuso enum nft_af_flags {
856ebddf1a8SPablo Neira Ayuso 	NFT_AF_NEEDS_DEV	= (1 << 0),
85796518518SPatrick McHardy };
85896518518SPatrick McHardy 
85996518518SPatrick McHardy /**
86096518518SPatrick McHardy  *	struct nft_af_info - nf_tables address family info
86196518518SPatrick McHardy  *
86296518518SPatrick McHardy  *	@list: used internally
86396518518SPatrick McHardy  *	@family: address family
86496518518SPatrick McHardy  *	@nhooks: number of hooks in this family
86596518518SPatrick McHardy  *	@owner: module owner
86696518518SPatrick McHardy  *	@tables: used internally
867ebddf1a8SPablo Neira Ayuso  *	@flags: family flags
868115a60b1SPatrick McHardy  *	@nops: number of hook ops in this family
869115a60b1SPatrick McHardy  *	@hook_ops_init: initialization function for chain hook ops
87096518518SPatrick McHardy  *	@hooks: hookfn overrides for packet validation
87196518518SPatrick McHardy  */
87296518518SPatrick McHardy struct nft_af_info {
87396518518SPatrick McHardy 	struct list_head		list;
87496518518SPatrick McHardy 	int				family;
87596518518SPatrick McHardy 	unsigned int			nhooks;
87696518518SPatrick McHardy 	struct module			*owner;
87796518518SPatrick McHardy 	struct list_head		tables;
878ebddf1a8SPablo Neira Ayuso 	u32				flags;
879115a60b1SPatrick McHardy 	unsigned int			nops;
880115a60b1SPatrick McHardy 	void				(*hook_ops_init)(struct nf_hook_ops *,
881115a60b1SPatrick McHardy 							 unsigned int);
88296518518SPatrick McHardy 	nf_hookfn			*hooks[NF_MAX_HOOKS];
88396518518SPatrick McHardy };
88496518518SPatrick McHardy 
8855eccdfaaSJoe Perches int nft_register_afinfo(struct net *, struct nft_af_info *);
886df05ef87SPablo Neira Ayuso void nft_unregister_afinfo(struct net *, struct nft_af_info *);
88796518518SPatrick McHardy 
8882a37d755SPatrick McHardy int nft_register_chain_type(const struct nf_chain_type *);
8892a37d755SPatrick McHardy void nft_unregister_chain_type(const struct nf_chain_type *);
89096518518SPatrick McHardy 
8915eccdfaaSJoe Perches int nft_register_expr(struct nft_expr_type *);
8925eccdfaaSJoe Perches void nft_unregister_expr(struct nft_expr_type *);
89396518518SPatrick McHardy 
89433d5a7b1SFlorian Westphal int nft_verdict_dump(struct sk_buff *skb, int type,
89533d5a7b1SFlorian Westphal 		     const struct nft_verdict *v);
89633d5a7b1SFlorian Westphal 
89733d5a7b1SFlorian Westphal /**
89833d5a7b1SFlorian Westphal  *	struct nft_traceinfo - nft tracing information and state
89933d5a7b1SFlorian Westphal  *
90033d5a7b1SFlorian Westphal  *	@pkt: pktinfo currently processed
90133d5a7b1SFlorian Westphal  *	@basechain: base chain currently processed
90233d5a7b1SFlorian Westphal  *	@chain: chain currently processed
90333d5a7b1SFlorian Westphal  *	@rule:  rule that was evaluated
90433d5a7b1SFlorian Westphal  *	@verdict: verdict given by rule
90533d5a7b1SFlorian Westphal  *	@type: event type (enum nft_trace_types)
90633d5a7b1SFlorian Westphal  *	@packet_dumped: packet headers sent in a previous traceinfo message
90733d5a7b1SFlorian Westphal  *	@trace: other struct members are initialised
90833d5a7b1SFlorian Westphal  */
90933d5a7b1SFlorian Westphal struct nft_traceinfo {
91033d5a7b1SFlorian Westphal 	const struct nft_pktinfo	*pkt;
91133d5a7b1SFlorian Westphal 	const struct nft_base_chain	*basechain;
91233d5a7b1SFlorian Westphal 	const struct nft_chain		*chain;
91333d5a7b1SFlorian Westphal 	const struct nft_rule		*rule;
91433d5a7b1SFlorian Westphal 	const struct nft_verdict	*verdict;
91533d5a7b1SFlorian Westphal 	enum nft_trace_types		type;
91633d5a7b1SFlorian Westphal 	bool				packet_dumped;
91733d5a7b1SFlorian Westphal 	bool				trace;
91833d5a7b1SFlorian Westphal };
91933d5a7b1SFlorian Westphal 
92033d5a7b1SFlorian Westphal void nft_trace_init(struct nft_traceinfo *info, const struct nft_pktinfo *pkt,
92133d5a7b1SFlorian Westphal 		    const struct nft_verdict *verdict,
92233d5a7b1SFlorian Westphal 		    const struct nft_chain *basechain);
92333d5a7b1SFlorian Westphal 
92433d5a7b1SFlorian Westphal void nft_trace_notify(struct nft_traceinfo *info);
92533d5a7b1SFlorian Westphal 
92667a8fc27SPatrick McHardy #define nft_dereference(p)					\
92767a8fc27SPatrick McHardy 	nfnl_dereference(p, NFNL_SUBSYS_NFTABLES)
92867a8fc27SPatrick McHardy 
92996518518SPatrick McHardy #define MODULE_ALIAS_NFT_FAMILY(family)	\
93096518518SPatrick McHardy 	MODULE_ALIAS("nft-afinfo-" __stringify(family))
93196518518SPatrick McHardy 
9329370761cSPablo Neira Ayuso #define MODULE_ALIAS_NFT_CHAIN(family, name) \
9339370761cSPablo Neira Ayuso 	MODULE_ALIAS("nft-chain-" __stringify(family) "-" name)
93496518518SPatrick McHardy 
93564d46806SPatrick McHardy #define MODULE_ALIAS_NFT_AF_EXPR(family, name) \
93664d46806SPatrick McHardy 	MODULE_ALIAS("nft-expr-" __stringify(family) "-" name)
93764d46806SPatrick McHardy 
93896518518SPatrick McHardy #define MODULE_ALIAS_NFT_EXPR(name) \
93996518518SPatrick McHardy 	MODULE_ALIAS("nft-expr-" name)
94096518518SPatrick McHardy 
94120a69341SPatrick McHardy #define MODULE_ALIAS_NFT_SET() \
94220a69341SPatrick McHardy 	MODULE_ALIAS("nft-set")
94320a69341SPatrick McHardy 
944ea4bd995SPatrick McHardy /*
945ea4bd995SPatrick McHardy  * The gencursor defines two generations, the currently active and the
946ea4bd995SPatrick McHardy  * next one. Objects contain a bitmask of 2 bits specifying the generations
947ea4bd995SPatrick McHardy  * they're active in. A set bit means they're inactive in the generation
948ea4bd995SPatrick McHardy  * represented by that bit.
949ea4bd995SPatrick McHardy  *
950ea4bd995SPatrick McHardy  * New objects start out as inactive in the current and active in the
951ea4bd995SPatrick McHardy  * next generation. When committing the ruleset the bitmask is cleared,
952ea4bd995SPatrick McHardy  * meaning they're active in all generations. When removing an object,
953ea4bd995SPatrick McHardy  * it is set inactive in the next generation. After committing the ruleset,
954ea4bd995SPatrick McHardy  * the objects are removed.
955ea4bd995SPatrick McHardy  */
956ea4bd995SPatrick McHardy static inline unsigned int nft_gencursor_next(const struct net *net)
957ea4bd995SPatrick McHardy {
958ea4bd995SPatrick McHardy 	return net->nft.gencursor + 1 == 1 ? 1 : 0;
959ea4bd995SPatrick McHardy }
960ea4bd995SPatrick McHardy 
961ea4bd995SPatrick McHardy static inline u8 nft_genmask_next(const struct net *net)
962ea4bd995SPatrick McHardy {
963ea4bd995SPatrick McHardy 	return 1 << nft_gencursor_next(net);
964ea4bd995SPatrick McHardy }
965ea4bd995SPatrick McHardy 
966ea4bd995SPatrick McHardy static inline u8 nft_genmask_cur(const struct net *net)
967ea4bd995SPatrick McHardy {
968ea4bd995SPatrick McHardy 	/* Use ACCESS_ONCE() to prevent refetching the value for atomicity */
969ea4bd995SPatrick McHardy 	return 1 << ACCESS_ONCE(net->nft.gencursor);
970ea4bd995SPatrick McHardy }
971ea4bd995SPatrick McHardy 
97222fe54d5SPatrick McHardy #define NFT_GENMASK_ANY		((1 << 0) | (1 << 1))
97322fe54d5SPatrick McHardy 
974cc02e457SPatrick McHardy /*
975889f7ee7SPablo Neira Ayuso  * Generic transaction helpers
976889f7ee7SPablo Neira Ayuso  */
977889f7ee7SPablo Neira Ayuso 
978889f7ee7SPablo Neira Ayuso /* Check if this object is currently active. */
979889f7ee7SPablo Neira Ayuso #define nft_is_active(__net, __obj)				\
980889f7ee7SPablo Neira Ayuso 	(((__obj)->genmask & nft_genmask_cur(__net)) == 0)
981889f7ee7SPablo Neira Ayuso 
982889f7ee7SPablo Neira Ayuso /* Check if this object is active in the next generation. */
983889f7ee7SPablo Neira Ayuso #define nft_is_active_next(__net, __obj)			\
984889f7ee7SPablo Neira Ayuso 	(((__obj)->genmask & nft_genmask_next(__net)) == 0)
985889f7ee7SPablo Neira Ayuso 
986889f7ee7SPablo Neira Ayuso /* This object becomes active in the next generation. */
987889f7ee7SPablo Neira Ayuso #define nft_activate_next(__net, __obj)				\
988889f7ee7SPablo Neira Ayuso 	(__obj)->genmask = nft_genmask_cur(__net)
989889f7ee7SPablo Neira Ayuso 
990889f7ee7SPablo Neira Ayuso /* This object becomes inactive in the next generation. */
991889f7ee7SPablo Neira Ayuso #define nft_deactivate_next(__net, __obj)			\
992889f7ee7SPablo Neira Ayuso         (__obj)->genmask = nft_genmask_next(__net)
993889f7ee7SPablo Neira Ayuso 
994889f7ee7SPablo Neira Ayuso /* After committing the ruleset, clear the stale generation bit. */
995889f7ee7SPablo Neira Ayuso #define nft_clear(__net, __obj)					\
996889f7ee7SPablo Neira Ayuso 	(__obj)->genmask &= ~nft_genmask_next(__net)
997f2a6d766SPablo Neira Ayuso #define nft_active_genmask(__obj, __genmask)			\
998f2a6d766SPablo Neira Ayuso 	!((__obj)->genmask & __genmask)
999889f7ee7SPablo Neira Ayuso 
1000889f7ee7SPablo Neira Ayuso /*
1001cc02e457SPatrick McHardy  * Set element transaction helpers
1002cc02e457SPatrick McHardy  */
1003cc02e457SPatrick McHardy 
1004cc02e457SPatrick McHardy static inline bool nft_set_elem_active(const struct nft_set_ext *ext,
1005cc02e457SPatrick McHardy 				       u8 genmask)
1006cc02e457SPatrick McHardy {
1007cc02e457SPatrick McHardy 	return !(ext->genmask & genmask);
1008cc02e457SPatrick McHardy }
1009cc02e457SPatrick McHardy 
1010cc02e457SPatrick McHardy static inline void nft_set_elem_change_active(const struct nft_set *set,
1011cc02e457SPatrick McHardy 					      struct nft_set_ext *ext)
1012cc02e457SPatrick McHardy {
1013cc02e457SPatrick McHardy 	ext->genmask ^= nft_genmask_next(read_pnet(&set->pnet));
1014cc02e457SPatrick McHardy }
1015cc02e457SPatrick McHardy 
101669086658SPatrick McHardy /*
101769086658SPatrick McHardy  * We use a free bit in the genmask field to indicate the element
101869086658SPatrick McHardy  * is busy, meaning it is currently being processed either by
101969086658SPatrick McHardy  * the netlink API or GC.
102069086658SPatrick McHardy  *
102169086658SPatrick McHardy  * Even though the genmask is only a single byte wide, this works
102269086658SPatrick McHardy  * because the extension structure if fully constant once initialized,
102369086658SPatrick McHardy  * so there are no non-atomic write accesses unless it is already
102469086658SPatrick McHardy  * marked busy.
102569086658SPatrick McHardy  */
102669086658SPatrick McHardy #define NFT_SET_ELEM_BUSY_MASK	(1 << 2)
102769086658SPatrick McHardy 
102869086658SPatrick McHardy #if defined(__LITTLE_ENDIAN_BITFIELD)
102969086658SPatrick McHardy #define NFT_SET_ELEM_BUSY_BIT	2
103069086658SPatrick McHardy #elif defined(__BIG_ENDIAN_BITFIELD)
103169086658SPatrick McHardy #define NFT_SET_ELEM_BUSY_BIT	(BITS_PER_LONG - BITS_PER_BYTE + 2)
103269086658SPatrick McHardy #else
103369086658SPatrick McHardy #error
103469086658SPatrick McHardy #endif
103569086658SPatrick McHardy 
103669086658SPatrick McHardy static inline int nft_set_elem_mark_busy(struct nft_set_ext *ext)
103769086658SPatrick McHardy {
103869086658SPatrick McHardy 	unsigned long *word = (unsigned long *)ext;
103969086658SPatrick McHardy 
104069086658SPatrick McHardy 	BUILD_BUG_ON(offsetof(struct nft_set_ext, genmask) != 0);
104169086658SPatrick McHardy 	return test_and_set_bit(NFT_SET_ELEM_BUSY_BIT, word);
104269086658SPatrick McHardy }
104369086658SPatrick McHardy 
104469086658SPatrick McHardy static inline void nft_set_elem_clear_busy(struct nft_set_ext *ext)
104569086658SPatrick McHardy {
104669086658SPatrick McHardy 	unsigned long *word = (unsigned long *)ext;
104769086658SPatrick McHardy 
104869086658SPatrick McHardy 	clear_bit(NFT_SET_ELEM_BUSY_BIT, word);
104969086658SPatrick McHardy }
105069086658SPatrick McHardy 
10511a1e1a12SPatrick McHardy /**
10521a1e1a12SPatrick McHardy  *	struct nft_trans - nf_tables object update in transaction
10531a1e1a12SPatrick McHardy  *
10541a1e1a12SPatrick McHardy  *	@list: used internally
10551a1e1a12SPatrick McHardy  *	@msg_type: message type
10561a1e1a12SPatrick McHardy  *	@ctx: transaction context
10571a1e1a12SPatrick McHardy  *	@data: internal information related to the transaction
10581a1e1a12SPatrick McHardy  */
10591a1e1a12SPatrick McHardy struct nft_trans {
10601a1e1a12SPatrick McHardy 	struct list_head		list;
10611a1e1a12SPatrick McHardy 	int				msg_type;
10621a1e1a12SPatrick McHardy 	struct nft_ctx			ctx;
10631a1e1a12SPatrick McHardy 	char				data[0];
10641a1e1a12SPatrick McHardy };
10651a1e1a12SPatrick McHardy 
10661a1e1a12SPatrick McHardy struct nft_trans_rule {
10671a1e1a12SPatrick McHardy 	struct nft_rule			*rule;
10681a1e1a12SPatrick McHardy };
10691a1e1a12SPatrick McHardy 
10701a1e1a12SPatrick McHardy #define nft_trans_rule(trans)	\
10711a1e1a12SPatrick McHardy 	(((struct nft_trans_rule *)trans->data)->rule)
10721a1e1a12SPatrick McHardy 
10731a1e1a12SPatrick McHardy struct nft_trans_set {
10741a1e1a12SPatrick McHardy 	struct nft_set			*set;
10751a1e1a12SPatrick McHardy 	u32				set_id;
10761a1e1a12SPatrick McHardy };
10771a1e1a12SPatrick McHardy 
10781a1e1a12SPatrick McHardy #define nft_trans_set(trans)	\
10791a1e1a12SPatrick McHardy 	(((struct nft_trans_set *)trans->data)->set)
10801a1e1a12SPatrick McHardy #define nft_trans_set_id(trans)	\
10811a1e1a12SPatrick McHardy 	(((struct nft_trans_set *)trans->data)->set_id)
10821a1e1a12SPatrick McHardy 
10831a1e1a12SPatrick McHardy struct nft_trans_chain {
10841a1e1a12SPatrick McHardy 	bool				update;
10851a1e1a12SPatrick McHardy 	char				name[NFT_CHAIN_MAXNAMELEN];
10861a1e1a12SPatrick McHardy 	struct nft_stats __percpu	*stats;
10871a1e1a12SPatrick McHardy 	u8				policy;
10881a1e1a12SPatrick McHardy };
10891a1e1a12SPatrick McHardy 
10901a1e1a12SPatrick McHardy #define nft_trans_chain_update(trans)	\
10911a1e1a12SPatrick McHardy 	(((struct nft_trans_chain *)trans->data)->update)
10921a1e1a12SPatrick McHardy #define nft_trans_chain_name(trans)	\
10931a1e1a12SPatrick McHardy 	(((struct nft_trans_chain *)trans->data)->name)
10941a1e1a12SPatrick McHardy #define nft_trans_chain_stats(trans)	\
10951a1e1a12SPatrick McHardy 	(((struct nft_trans_chain *)trans->data)->stats)
10961a1e1a12SPatrick McHardy #define nft_trans_chain_policy(trans)	\
10971a1e1a12SPatrick McHardy 	(((struct nft_trans_chain *)trans->data)->policy)
10981a1e1a12SPatrick McHardy 
10991a1e1a12SPatrick McHardy struct nft_trans_table {
11001a1e1a12SPatrick McHardy 	bool				update;
11011a1e1a12SPatrick McHardy 	bool				enable;
11021a1e1a12SPatrick McHardy };
11031a1e1a12SPatrick McHardy 
11041a1e1a12SPatrick McHardy #define nft_trans_table_update(trans)	\
11051a1e1a12SPatrick McHardy 	(((struct nft_trans_table *)trans->data)->update)
11061a1e1a12SPatrick McHardy #define nft_trans_table_enable(trans)	\
11071a1e1a12SPatrick McHardy 	(((struct nft_trans_table *)trans->data)->enable)
11081a1e1a12SPatrick McHardy 
11091a1e1a12SPatrick McHardy struct nft_trans_elem {
11101a1e1a12SPatrick McHardy 	struct nft_set			*set;
11111a1e1a12SPatrick McHardy 	struct nft_set_elem		elem;
11121a1e1a12SPatrick McHardy };
11131a1e1a12SPatrick McHardy 
11141a1e1a12SPatrick McHardy #define nft_trans_elem_set(trans)	\
11151a1e1a12SPatrick McHardy 	(((struct nft_trans_elem *)trans->data)->set)
11161a1e1a12SPatrick McHardy #define nft_trans_elem(trans)	\
11171a1e1a12SPatrick McHardy 	(((struct nft_trans_elem *)trans->data)->elem)
11181a1e1a12SPatrick McHardy 
111996518518SPatrick McHardy #endif /* _NET_NF_TABLES_H */
1120