1 // SPDX-License-Identifier: GPL-2.0-or-later
3 * net/sched/cls_u32.c Ugly (or Universal) 32bit key Packet Classifier.
5 * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
7 * The filters are packed to hash tables of key nodes
8 * with a set of 32bit key/mask pairs at every node.
9 * Nodes reference next level hash tables etc.
11 * This scheme is the best universal classifier I managed to
12 * invent; it is not super-fast, but it is not slow (provided you
13 * program it correctly), and general enough. And its relative
14 * speed grows as the number of rules becomes larger.
16 * It seems that it represents the best middle point between
17 * speed and manageability both by human and by machine.
19 * It is especially useful for link sharing combined with QoS;
20 * pure RSVP doesn't need such a general approach and can use
21 * much simpler (and faster) schemes, sort of cls_rsvp.c.
23 * nfmark match added by Catalin(ux aka Dino) BOIE <catab at umbrella.ro>
26 #include <linux/module.h>
27 #include <linux/slab.h>
28 #include <linux/types.h>
29 #include <linux/kernel.h>
30 #include <linux/string.h>
31 #include <linux/errno.h>
32 #include <linux/percpu.h>
33 #include <linux/rtnetlink.h>
34 #include <linux/skbuff.h>
35 #include <linux/bitmap.h>
36 #include <linux/netdevice.h>
37 #include <linux/hash.h>
38 #include <net/netlink.h>
39 #include <net/act_api.h>
40 #include <net/pkt_cls.h>
41 #include <linux/idr.h>
42 #include <net/tc_wrapper.h>
45 struct tc_u_knode __rcu
*next
;
47 struct tc_u_hnode __rcu
*ht_up
;
51 struct tcf_result res
;
52 struct tc_u_hnode __rcu
*ht_down
;
53 #ifdef CONFIG_CLS_U32_PERF
54 struct tc_u32_pcnt __percpu
*pf
;
57 unsigned int in_hw_count
;
58 #ifdef CONFIG_CLS_U32_MARK
61 u32 __percpu
*pcpu_success
;
63 struct rcu_work rwork
;
64 /* The 'sel' field MUST be the last field in structure to allow for
65 * tc_u32_keys allocated at end of structure.
67 struct tc_u32_sel sel
;
71 struct tc_u_hnode __rcu
*next
;
76 struct idr handle_idr
;
80 /* The 'ht' field MUST be the last field in structure to allow for
81 * more entries allocated at end of structure.
83 struct tc_u_knode __rcu
*ht
[];
87 struct tc_u_hnode __rcu
*hlist
;
90 struct idr handle_idr
;
91 struct hlist_node hnode
;
95 static u32
handle2id(u32 h
)
97 return ((h
& 0x80000000) ? ((h
>> 20) & 0x7FF) : h
);
100 static u32
id2handle(u32 id
)
102 return (id
| 0x800U
) << 20;
105 static inline unsigned int u32_hash_fold(__be32 key
,
106 const struct tc_u32_sel
*sel
,
109 unsigned int h
= ntohl(key
& sel
->hmask
) >> fshift
;
114 TC_INDIRECT_SCOPE
int u32_classify(struct sk_buff
*skb
,
115 const struct tcf_proto
*tp
,
116 struct tcf_result
*res
)
119 struct tc_u_knode
*knode
;
121 } stack
[TC_U32_MAXDEPTH
];
123 struct tc_u_hnode
*ht
= rcu_dereference_bh(tp
->root
);
124 unsigned int off
= skb_network_offset(skb
);
125 struct tc_u_knode
*n
;
129 #ifdef CONFIG_CLS_U32_PERF
135 n
= rcu_dereference_bh(ht
->ht
[sel
]);
139 struct tc_u32_key
*key
= n
->sel
.keys
;
141 #ifdef CONFIG_CLS_U32_PERF
142 __this_cpu_inc(n
->pf
->rcnt
);
146 if (tc_skip_sw(n
->flags
)) {
147 n
= rcu_dereference_bh(n
->next
);
151 #ifdef CONFIG_CLS_U32_MARK
152 if ((skb
->mark
& n
->mask
) != n
->val
) {
153 n
= rcu_dereference_bh(n
->next
);
156 __this_cpu_inc(*n
->pcpu_success
);
160 for (i
= n
->sel
.nkeys
; i
> 0; i
--, key
++) {
161 int toff
= off
+ key
->off
+ (off2
& key
->offmask
);
164 if (skb_headroom(skb
) + toff
> INT_MAX
)
167 data
= skb_header_pointer(skb
, toff
, 4, &hdata
);
170 if ((*data
^ key
->val
) & key
->mask
) {
171 n
= rcu_dereference_bh(n
->next
);
174 #ifdef CONFIG_CLS_U32_PERF
175 __this_cpu_inc(n
->pf
->kcnts
[j
]);
180 ht
= rcu_dereference_bh(n
->ht_down
);
183 if (n
->sel
.flags
& TC_U32_TERMINAL
) {
186 if (!tcf_match_indev(skb
, n
->ifindex
)) {
187 n
= rcu_dereference_bh(n
->next
);
190 #ifdef CONFIG_CLS_U32_PERF
191 __this_cpu_inc(n
->pf
->rhit
);
193 r
= tcf_exts_exec(skb
, &n
->exts
, res
);
195 n
= rcu_dereference_bh(n
->next
);
201 n
= rcu_dereference_bh(n
->next
);
206 if (sdepth
>= TC_U32_MAXDEPTH
)
208 stack
[sdepth
].knode
= n
;
209 stack
[sdepth
].off
= off
;
212 ht
= rcu_dereference_bh(n
->ht_down
);
217 data
= skb_header_pointer(skb
, off
+ n
->sel
.hoff
, 4,
221 sel
= ht
->divisor
& u32_hash_fold(*data
, &n
->sel
,
224 if (!(n
->sel
.flags
& (TC_U32_VAROFFSET
| TC_U32_OFFSET
| TC_U32_EAT
)))
227 if (n
->sel
.flags
& (TC_U32_OFFSET
| TC_U32_VAROFFSET
)) {
228 off2
= n
->sel
.off
+ 3;
229 if (n
->sel
.flags
& TC_U32_VAROFFSET
) {
232 data
= skb_header_pointer(skb
,
237 off2
+= ntohs(n
->sel
.offmask
& *data
) >>
242 if (n
->sel
.flags
& TC_U32_EAT
) {
253 n
= stack
[sdepth
].knode
;
254 ht
= rcu_dereference_bh(n
->ht_up
);
255 off
= stack
[sdepth
].off
;
262 net_warn_ratelimited("cls_u32: dead loop\n");
266 static struct tc_u_hnode
*u32_lookup_ht(struct tc_u_common
*tp_c
, u32 handle
)
268 struct tc_u_hnode
*ht
;
270 for (ht
= rtnl_dereference(tp_c
->hlist
);
272 ht
= rtnl_dereference(ht
->next
))
273 if (ht
->handle
== handle
)
279 static struct tc_u_knode
*u32_lookup_key(struct tc_u_hnode
*ht
, u32 handle
)
282 struct tc_u_knode
*n
= NULL
;
284 sel
= TC_U32_HASH(handle
);
285 if (sel
> ht
->divisor
)
288 for (n
= rtnl_dereference(ht
->ht
[sel
]);
290 n
= rtnl_dereference(n
->next
))
291 if (n
->handle
== handle
)
298 static void *u32_get(struct tcf_proto
*tp
, u32 handle
)
300 struct tc_u_hnode
*ht
;
301 struct tc_u_common
*tp_c
= tp
->data
;
303 if (TC_U32_HTID(handle
) == TC_U32_ROOT
)
304 ht
= rtnl_dereference(tp
->root
);
306 ht
= u32_lookup_ht(tp_c
, TC_U32_HTID(handle
));
311 if (TC_U32_KEY(handle
) == 0)
314 return u32_lookup_key(ht
, handle
);
317 /* Protected by rtnl lock */
318 static u32
gen_new_htid(struct tc_u_common
*tp_c
, struct tc_u_hnode
*ptr
)
320 int id
= idr_alloc_cyclic(&tp_c
->handle_idr
, ptr
, 1, 0x7FF, GFP_KERNEL
);
323 return id2handle(id
);
326 static struct hlist_head
*tc_u_common_hash
;
328 #define U32_HASH_SHIFT 10
329 #define U32_HASH_SIZE (1 << U32_HASH_SHIFT)
331 static void *tc_u_common_ptr(const struct tcf_proto
*tp
)
333 struct tcf_block
*block
= tp
->chain
->block
;
335 /* The block sharing is currently supported only
336 * for classless qdiscs. In that case we use block
337 * for tc_u_common identification. In case the
338 * block is not shared, block->q is a valid pointer
339 * and we can use that. That works for classful qdiscs.
341 if (tcf_block_shared(block
))
347 static struct hlist_head
*tc_u_hash(void *key
)
349 return tc_u_common_hash
+ hash_ptr(key
, U32_HASH_SHIFT
);
352 static struct tc_u_common
*tc_u_common_find(void *key
)
354 struct tc_u_common
*tc
;
355 hlist_for_each_entry(tc
, tc_u_hash(key
), hnode
) {
362 static int u32_init(struct tcf_proto
*tp
)
364 struct tc_u_hnode
*root_ht
;
365 void *key
= tc_u_common_ptr(tp
);
366 struct tc_u_common
*tp_c
= tc_u_common_find(key
);
368 root_ht
= kzalloc(struct_size(root_ht
, ht
, 1), GFP_KERNEL
);
372 refcount_set(&root_ht
->refcnt
, 1);
373 root_ht
->handle
= tp_c
? gen_new_htid(tp_c
, root_ht
) : id2handle(0);
374 root_ht
->prio
= tp
->prio
;
375 root_ht
->is_root
= true;
376 idr_init(&root_ht
->handle_idr
);
379 tp_c
= kzalloc(sizeof(*tp_c
), GFP_KERNEL
);
384 refcount_set(&tp_c
->refcnt
, 1);
386 INIT_HLIST_NODE(&tp_c
->hnode
);
387 idr_init(&tp_c
->handle_idr
);
389 hlist_add_head(&tp_c
->hnode
, tc_u_hash(key
));
391 refcount_inc(&tp_c
->refcnt
);
394 RCU_INIT_POINTER(root_ht
->next
, tp_c
->hlist
);
395 rcu_assign_pointer(tp_c
->hlist
, root_ht
);
397 /* root_ht must be destroyed when tcf_proto is destroyed */
398 rcu_assign_pointer(tp
->root
, root_ht
);
403 static void __u32_destroy_key(struct tc_u_knode
*n
)
405 struct tc_u_hnode
*ht
= rtnl_dereference(n
->ht_down
);
407 tcf_exts_destroy(&n
->exts
);
408 if (ht
&& refcount_dec_and_test(&ht
->refcnt
))
413 static void u32_destroy_key(struct tc_u_knode
*n
, bool free_pf
)
415 tcf_exts_put_net(&n
->exts
);
416 #ifdef CONFIG_CLS_U32_PERF
420 #ifdef CONFIG_CLS_U32_MARK
422 free_percpu(n
->pcpu_success
);
424 __u32_destroy_key(n
);
427 /* u32_delete_key_rcu should be called when free'ing a copied
428 * version of a tc_u_knode obtained from u32_init_knode(). When
429 * copies are obtained from u32_init_knode() the statistics are
430 * shared between the old and new copies to allow readers to
431 * continue to update the statistics during the copy. To support
432 * this the u32_delete_key_rcu variant does not free the percpu
435 static void u32_delete_key_work(struct work_struct
*work
)
437 struct tc_u_knode
*key
= container_of(to_rcu_work(work
),
441 u32_destroy_key(key
, false);
445 /* u32_delete_key_freepf_rcu is the rcu callback variant
446 * that free's the entire structure including the statistics
447 * percpu variables. Only use this if the key is not a copy
448 * returned by u32_init_knode(). See u32_delete_key_rcu()
449 * for the variant that should be used with keys return from
452 static void u32_delete_key_freepf_work(struct work_struct
*work
)
454 struct tc_u_knode
*key
= container_of(to_rcu_work(work
),
458 u32_destroy_key(key
, true);
462 static int u32_delete_key(struct tcf_proto
*tp
, struct tc_u_knode
*key
)
464 struct tc_u_common
*tp_c
= tp
->data
;
465 struct tc_u_knode __rcu
**kp
;
466 struct tc_u_knode
*pkp
;
467 struct tc_u_hnode
*ht
= rtnl_dereference(key
->ht_up
);
470 kp
= &ht
->ht
[TC_U32_HASH(key
->handle
)];
471 for (pkp
= rtnl_dereference(*kp
); pkp
;
472 kp
= &pkp
->next
, pkp
= rtnl_dereference(*kp
)) {
474 RCU_INIT_POINTER(*kp
, key
->next
);
477 tcf_unbind_filter(tp
, &key
->res
);
478 idr_remove(&ht
->handle_idr
, key
->handle
);
479 tcf_exts_get_net(&key
->exts
);
480 tcf_queue_work(&key
->rwork
, u32_delete_key_freepf_work
);
489 static void u32_clear_hw_hnode(struct tcf_proto
*tp
, struct tc_u_hnode
*h
,
490 struct netlink_ext_ack
*extack
)
492 struct tcf_block
*block
= tp
->chain
->block
;
493 struct tc_cls_u32_offload cls_u32
= {};
495 tc_cls_common_offload_init(&cls_u32
.common
, tp
, h
->flags
, extack
);
496 cls_u32
.command
= TC_CLSU32_DELETE_HNODE
;
497 cls_u32
.hnode
.divisor
= h
->divisor
;
498 cls_u32
.hnode
.handle
= h
->handle
;
499 cls_u32
.hnode
.prio
= h
->prio
;
501 tc_setup_cb_call(block
, TC_SETUP_CLSU32
, &cls_u32
, false, true);
504 static int u32_replace_hw_hnode(struct tcf_proto
*tp
, struct tc_u_hnode
*h
,
505 u32 flags
, struct netlink_ext_ack
*extack
)
507 struct tcf_block
*block
= tp
->chain
->block
;
508 struct tc_cls_u32_offload cls_u32
= {};
509 bool skip_sw
= tc_skip_sw(flags
);
510 bool offloaded
= false;
513 tc_cls_common_offload_init(&cls_u32
.common
, tp
, flags
, extack
);
514 cls_u32
.command
= TC_CLSU32_NEW_HNODE
;
515 cls_u32
.hnode
.divisor
= h
->divisor
;
516 cls_u32
.hnode
.handle
= h
->handle
;
517 cls_u32
.hnode
.prio
= h
->prio
;
519 err
= tc_setup_cb_call(block
, TC_SETUP_CLSU32
, &cls_u32
, skip_sw
, true);
521 u32_clear_hw_hnode(tp
, h
, NULL
);
523 } else if (err
> 0) {
527 if (skip_sw
&& !offloaded
)
533 static void u32_remove_hw_knode(struct tcf_proto
*tp
, struct tc_u_knode
*n
,
534 struct netlink_ext_ack
*extack
)
536 struct tcf_block
*block
= tp
->chain
->block
;
537 struct tc_cls_u32_offload cls_u32
= {};
539 tc_cls_common_offload_init(&cls_u32
.common
, tp
, n
->flags
, extack
);
540 cls_u32
.command
= TC_CLSU32_DELETE_KNODE
;
541 cls_u32
.knode
.handle
= n
->handle
;
543 tc_setup_cb_destroy(block
, tp
, TC_SETUP_CLSU32
, &cls_u32
, false,
544 &n
->flags
, &n
->in_hw_count
, true);
547 static int u32_replace_hw_knode(struct tcf_proto
*tp
, struct tc_u_knode
*n
,
548 u32 flags
, struct netlink_ext_ack
*extack
)
550 struct tc_u_hnode
*ht
= rtnl_dereference(n
->ht_down
);
551 struct tcf_block
*block
= tp
->chain
->block
;
552 struct tc_cls_u32_offload cls_u32
= {};
553 bool skip_sw
= tc_skip_sw(flags
);
556 tc_cls_common_offload_init(&cls_u32
.common
, tp
, flags
, extack
);
557 cls_u32
.command
= TC_CLSU32_REPLACE_KNODE
;
558 cls_u32
.knode
.handle
= n
->handle
;
559 cls_u32
.knode
.fshift
= n
->fshift
;
560 #ifdef CONFIG_CLS_U32_MARK
561 cls_u32
.knode
.val
= n
->val
;
562 cls_u32
.knode
.mask
= n
->mask
;
564 cls_u32
.knode
.val
= 0;
565 cls_u32
.knode
.mask
= 0;
567 cls_u32
.knode
.sel
= &n
->sel
;
568 cls_u32
.knode
.res
= &n
->res
;
569 cls_u32
.knode
.exts
= &n
->exts
;
571 cls_u32
.knode
.link_handle
= ht
->handle
;
573 err
= tc_setup_cb_add(block
, tp
, TC_SETUP_CLSU32
, &cls_u32
, skip_sw
,
574 &n
->flags
, &n
->in_hw_count
, true);
576 u32_remove_hw_knode(tp
, n
, NULL
);
580 if (skip_sw
&& !(n
->flags
& TCA_CLS_FLAGS_IN_HW
))
586 static void u32_clear_hnode(struct tcf_proto
*tp
, struct tc_u_hnode
*ht
,
587 struct netlink_ext_ack
*extack
)
589 struct tc_u_common
*tp_c
= tp
->data
;
590 struct tc_u_knode
*n
;
593 for (h
= 0; h
<= ht
->divisor
; h
++) {
594 while ((n
= rtnl_dereference(ht
->ht
[h
])) != NULL
) {
595 RCU_INIT_POINTER(ht
->ht
[h
],
596 rtnl_dereference(n
->next
));
598 tcf_unbind_filter(tp
, &n
->res
);
599 u32_remove_hw_knode(tp
, n
, extack
);
600 idr_remove(&ht
->handle_idr
, n
->handle
);
601 if (tcf_exts_get_net(&n
->exts
))
602 tcf_queue_work(&n
->rwork
, u32_delete_key_freepf_work
);
604 u32_destroy_key(n
, true);
609 static int u32_destroy_hnode(struct tcf_proto
*tp
, struct tc_u_hnode
*ht
,
610 struct netlink_ext_ack
*extack
)
612 struct tc_u_common
*tp_c
= tp
->data
;
613 struct tc_u_hnode __rcu
**hn
;
614 struct tc_u_hnode
*phn
;
616 u32_clear_hnode(tp
, ht
, extack
);
619 for (phn
= rtnl_dereference(*hn
);
621 hn
= &phn
->next
, phn
= rtnl_dereference(*hn
)) {
623 u32_clear_hw_hnode(tp
, ht
, extack
);
624 idr_destroy(&ht
->handle_idr
);
625 idr_remove(&tp_c
->handle_idr
, handle2id(ht
->handle
));
626 RCU_INIT_POINTER(*hn
, ht
->next
);
635 static void u32_destroy(struct tcf_proto
*tp
, bool rtnl_held
,
636 struct netlink_ext_ack
*extack
)
638 struct tc_u_common
*tp_c
= tp
->data
;
639 struct tc_u_hnode
*root_ht
= rtnl_dereference(tp
->root
);
641 WARN_ON(root_ht
== NULL
);
643 if (root_ht
&& refcount_dec_and_test(&root_ht
->refcnt
))
644 u32_destroy_hnode(tp
, root_ht
, extack
);
646 if (refcount_dec_and_test(&tp_c
->refcnt
)) {
647 struct tc_u_hnode
*ht
;
649 hlist_del(&tp_c
->hnode
);
651 while ((ht
= rtnl_dereference(tp_c
->hlist
)) != NULL
) {
652 u32_clear_hnode(tp
, ht
, extack
);
653 RCU_INIT_POINTER(tp_c
->hlist
, ht
->next
);
655 /* u32_destroy_key() will later free ht for us, if it's
656 * still referenced by some knode
658 if (refcount_dec_and_test(&ht
->refcnt
))
662 idr_destroy(&tp_c
->handle_idr
);
669 static int u32_delete(struct tcf_proto
*tp
, void *arg
, bool *last
,
670 bool rtnl_held
, struct netlink_ext_ack
*extack
)
672 struct tc_u_hnode
*ht
= arg
;
673 struct tc_u_common
*tp_c
= tp
->data
;
676 if (TC_U32_KEY(ht
->handle
)) {
677 u32_remove_hw_knode(tp
, (struct tc_u_knode
*)ht
, extack
);
678 ret
= u32_delete_key(tp
, (struct tc_u_knode
*)ht
);
683 NL_SET_ERR_MSG_MOD(extack
, "Not allowed to delete root node");
687 if (refcount_dec_if_one(&ht
->refcnt
)) {
688 u32_destroy_hnode(tp
, ht
, extack
);
690 NL_SET_ERR_MSG_MOD(extack
, "Can not delete in-use filter");
695 *last
= refcount_read(&tp_c
->refcnt
) == 1 && tp_c
->knodes
== 0;
699 static u32
gen_new_kid(struct tc_u_hnode
*ht
, u32 htid
)
701 u32 index
= htid
| 0x800;
702 u32 max
= htid
| 0xFFF;
704 if (idr_alloc_u32(&ht
->handle_idr
, NULL
, &index
, max
, GFP_KERNEL
)) {
706 if (idr_alloc_u32(&ht
->handle_idr
, NULL
, &index
, max
,
714 static const struct nla_policy u32_policy
[TCA_U32_MAX
+ 1] = {
715 [TCA_U32_CLASSID
] = { .type
= NLA_U32
},
716 [TCA_U32_HASH
] = { .type
= NLA_U32
},
717 [TCA_U32_LINK
] = { .type
= NLA_U32
},
718 [TCA_U32_DIVISOR
] = { .type
= NLA_U32
},
719 [TCA_U32_SEL
] = { .len
= sizeof(struct tc_u32_sel
) },
720 [TCA_U32_INDEV
] = { .type
= NLA_STRING
, .len
= IFNAMSIZ
},
721 [TCA_U32_MARK
] = { .len
= sizeof(struct tc_u32_mark
) },
722 [TCA_U32_FLAGS
] = { .type
= NLA_U32
},
725 static void u32_unbind_filter(struct tcf_proto
*tp
, struct tc_u_knode
*n
,
728 if (tb
[TCA_U32_CLASSID
])
729 tcf_unbind_filter(tp
, &n
->res
);
732 static void u32_bind_filter(struct tcf_proto
*tp
, struct tc_u_knode
*n
,
733 unsigned long base
, struct nlattr
**tb
)
735 if (tb
[TCA_U32_CLASSID
]) {
736 n
->res
.classid
= nla_get_u32(tb
[TCA_U32_CLASSID
]);
737 tcf_bind_filter(tp
, &n
->res
, base
);
741 static int u32_set_parms(struct net
*net
, struct tcf_proto
*tp
,
742 struct tc_u_knode
*n
, struct nlattr
**tb
,
743 struct nlattr
*est
, u32 flags
, u32 fl_flags
,
744 struct netlink_ext_ack
*extack
)
746 int err
, ifindex
= -1;
748 err
= tcf_exts_validate_ex(net
, tp
, tb
, est
, &n
->exts
, flags
,
753 if (tb
[TCA_U32_INDEV
]) {
754 ifindex
= tcf_change_indev(net
, tb
[TCA_U32_INDEV
], extack
);
759 if (tb
[TCA_U32_LINK
]) {
760 u32 handle
= nla_get_u32(tb
[TCA_U32_LINK
]);
761 struct tc_u_hnode
*ht_down
= NULL
, *ht_old
;
763 if (TC_U32_KEY(handle
)) {
764 NL_SET_ERR_MSG_MOD(extack
, "u32 Link handle must be a hash table");
769 ht_down
= u32_lookup_ht(tp
->data
, handle
);
772 NL_SET_ERR_MSG_MOD(extack
, "Link hash table not found");
775 if (ht_down
->is_root
) {
776 NL_SET_ERR_MSG_MOD(extack
, "Not linking to root node");
779 refcount_inc(&ht_down
->refcnt
);
782 ht_old
= rtnl_dereference(n
->ht_down
);
783 rcu_assign_pointer(n
->ht_down
, ht_down
);
786 refcount_dec(&ht_old
->refcnt
);
790 n
->ifindex
= ifindex
;
795 static void u32_replace_knode(struct tcf_proto
*tp
, struct tc_u_common
*tp_c
,
796 struct tc_u_knode
*n
)
798 struct tc_u_knode __rcu
**ins
;
799 struct tc_u_knode
*pins
;
800 struct tc_u_hnode
*ht
;
802 if (TC_U32_HTID(n
->handle
) == TC_U32_ROOT
)
803 ht
= rtnl_dereference(tp
->root
);
805 ht
= u32_lookup_ht(tp_c
, TC_U32_HTID(n
->handle
));
807 ins
= &ht
->ht
[TC_U32_HASH(n
->handle
)];
809 /* The node must always exist for it to be replaced if this is not the
810 * case then something went very wrong elsewhere.
812 for (pins
= rtnl_dereference(*ins
); ;
813 ins
= &pins
->next
, pins
= rtnl_dereference(*ins
))
814 if (pins
->handle
== n
->handle
)
817 idr_replace(&ht
->handle_idr
, n
, n
->handle
);
818 RCU_INIT_POINTER(n
->next
, pins
->next
);
819 rcu_assign_pointer(*ins
, n
);
822 static struct tc_u_knode
*u32_init_knode(struct net
*net
, struct tcf_proto
*tp
,
823 struct tc_u_knode
*n
)
825 struct tc_u_hnode
*ht
= rtnl_dereference(n
->ht_down
);
826 struct tc_u32_sel
*s
= &n
->sel
;
827 struct tc_u_knode
*new;
829 new = kzalloc(struct_size(new, sel
.keys
, s
->nkeys
), GFP_KERNEL
);
833 RCU_INIT_POINTER(new->next
, n
->next
);
834 new->handle
= n
->handle
;
835 RCU_INIT_POINTER(new->ht_up
, n
->ht_up
);
837 new->ifindex
= n
->ifindex
;
838 new->fshift
= n
->fshift
;
839 new->flags
= n
->flags
;
840 RCU_INIT_POINTER(new->ht_down
, ht
);
842 #ifdef CONFIG_CLS_U32_PERF
843 /* Statistics may be incremented by readers during update
844 * so we must keep them in tact. When the node is later destroyed
845 * a special destroy call must be made to not free the pf memory.
850 #ifdef CONFIG_CLS_U32_MARK
853 /* Similarly success statistics must be moved as pointers */
854 new->pcpu_success
= n
->pcpu_success
;
856 memcpy(&new->sel
, s
, struct_size(s
, keys
, s
->nkeys
));
858 if (tcf_exts_init(&new->exts
, net
, TCA_U32_ACT
, TCA_U32_POLICE
)) {
863 /* bump reference count as long as we hold pointer to structure */
865 refcount_inc(&ht
->refcnt
);
870 static int u32_change(struct net
*net
, struct sk_buff
*in_skb
,
871 struct tcf_proto
*tp
, unsigned long base
, u32 handle
,
872 struct nlattr
**tca
, void **arg
, u32 flags
,
873 struct netlink_ext_ack
*extack
)
875 struct tc_u_common
*tp_c
= tp
->data
;
876 struct tc_u_hnode
*ht
;
877 struct tc_u_knode
*n
;
878 struct tc_u32_sel
*s
;
879 struct nlattr
*opt
= tca
[TCA_OPTIONS
];
880 struct nlattr
*tb
[TCA_U32_MAX
+ 1];
881 u32 htid
, userflags
= 0;
887 NL_SET_ERR_MSG_MOD(extack
, "Filter handle requires options");
894 err
= nla_parse_nested_deprecated(tb
, TCA_U32_MAX
, opt
, u32_policy
,
899 if (tb
[TCA_U32_FLAGS
]) {
900 userflags
= nla_get_u32(tb
[TCA_U32_FLAGS
]);
901 if (!tc_flags_valid(userflags
)) {
902 NL_SET_ERR_MSG_MOD(extack
, "Invalid filter flags");
909 struct tc_u_knode
*new;
911 if (TC_U32_KEY(n
->handle
) == 0) {
912 NL_SET_ERR_MSG_MOD(extack
, "Key node id cannot be zero");
916 if ((n
->flags
^ userflags
) &
917 ~(TCA_CLS_FLAGS_IN_HW
| TCA_CLS_FLAGS_NOT_IN_HW
)) {
918 NL_SET_ERR_MSG_MOD(extack
, "Key node flags do not match passed flags");
922 new = u32_init_knode(net
, tp
, n
);
926 err
= u32_set_parms(net
, tp
, new, tb
, tca
[TCA_RATE
],
927 flags
, new->flags
, extack
);
930 __u32_destroy_key(new);
934 u32_bind_filter(tp
, new, base
, tb
);
936 err
= u32_replace_hw_knode(tp
, new, flags
, extack
);
938 u32_unbind_filter(tp
, new, tb
);
940 if (tb
[TCA_U32_LINK
]) {
941 struct tc_u_hnode
*ht_old
;
943 ht_old
= rtnl_dereference(n
->ht_down
);
945 refcount_inc(&ht_old
->refcnt
);
947 __u32_destroy_key(new);
951 if (!tc_in_hw(new->flags
))
952 new->flags
|= TCA_CLS_FLAGS_NOT_IN_HW
;
954 tcf_proto_update_usesw(tp
, new->flags
);
956 u32_replace_knode(tp
, tp_c
, new);
957 tcf_unbind_filter(tp
, &n
->res
);
958 tcf_exts_get_net(&n
->exts
);
959 tcf_queue_work(&n
->rwork
, u32_delete_key_work
);
963 if (tb
[TCA_U32_DIVISOR
]) {
964 unsigned int divisor
= nla_get_u32(tb
[TCA_U32_DIVISOR
]);
966 if (!is_power_of_2(divisor
)) {
967 NL_SET_ERR_MSG_MOD(extack
, "Divisor is not a power of 2");
970 if (divisor
-- > 0x100) {
971 NL_SET_ERR_MSG_MOD(extack
, "Exceeded maximum 256 hash buckets");
974 if (TC_U32_KEY(handle
)) {
975 NL_SET_ERR_MSG_MOD(extack
, "Divisor can only be used on a hash table");
978 ht
= kzalloc(struct_size(ht
, ht
, divisor
+ 1), GFP_KERNEL
);
982 handle
= gen_new_htid(tp
->data
, ht
);
988 err
= idr_alloc_u32(&tp_c
->handle_idr
, ht
, &handle
,
995 refcount_set(&ht
->refcnt
, 1);
996 ht
->divisor
= divisor
;
999 idr_init(&ht
->handle_idr
);
1000 ht
->flags
= userflags
;
1002 err
= u32_replace_hw_hnode(tp
, ht
, userflags
, extack
);
1004 idr_remove(&tp_c
->handle_idr
, handle2id(handle
));
1009 RCU_INIT_POINTER(ht
->next
, tp_c
->hlist
);
1010 rcu_assign_pointer(tp_c
->hlist
, ht
);
1016 if (tb
[TCA_U32_HASH
]) {
1017 htid
= nla_get_u32(tb
[TCA_U32_HASH
]);
1018 if (TC_U32_HTID(htid
) == TC_U32_ROOT
) {
1019 ht
= rtnl_dereference(tp
->root
);
1022 ht
= u32_lookup_ht(tp
->data
, TC_U32_HTID(htid
));
1024 NL_SET_ERR_MSG_MOD(extack
, "Specified hash table not found");
1029 ht
= rtnl_dereference(tp
->root
);
1033 if (ht
->divisor
< TC_U32_HASH(htid
)) {
1034 NL_SET_ERR_MSG_MOD(extack
, "Specified hash table buckets exceed configured value");
1038 /* At this point, we need to derive the new handle that will be used to
1039 * uniquely map the identity of this table match entry. The
1040 * identity of the entry that we need to construct is 32 bits made of:
1041 * htid(12b):bucketid(8b):node/entryid(12b)
1043 * At this point _we have the table(ht)_ in which we will insert this
1044 * entry. We carry the table's id in variable "htid".
1045 * Note that earlier code picked the ht selection either by a) the user
1046 * providing the htid specified via TCA_U32_HASH attribute or b) when
1047 * no such attribute is passed then the root ht, is default to at ID
1048 * 0x[800][00][000]. Rule: the root table has a single bucket with ID 0.
1049 * If OTOH the user passed us the htid, they may also pass a bucketid of
1050 * choice. 0 is fine. For example a user htid is 0x[600][01][000] it is
1051 * indicating hash bucketid of 1. Rule: the entry/node ID _cannot_ be
1052 * passed via the htid, so even if it was non-zero it will be ignored.
1054 * We may also have a handle, if the user passed one. The handle also
1055 * carries the same addressing of htid(12b):bucketid(8b):node/entryid(12b).
1056 * Rule: the bucketid on the handle is ignored even if one was passed;
1057 * rather the value on "htid" is always assumed to be the bucketid.
1060 /* Rule: The htid from handle and tableid from htid must match */
1061 if (TC_U32_HTID(handle
) && TC_U32_HTID(handle
^ htid
)) {
1062 NL_SET_ERR_MSG_MOD(extack
, "Handle specified hash table address mismatch");
1065 /* Ok, so far we have a valid htid(12b):bucketid(8b) but we
1066 * need to finalize the table entry identification with the last
1067 * part - the node/entryid(12b)). Rule: Nodeid _cannot be 0_ for
1068 * entries. Rule: nodeid of 0 is reserved only for tables(see
1069 * earlier code which processes TC_U32_DIVISOR attribute).
1070 * Rule: The nodeid can only be derived from the handle (and not
1072 * Rule: if the handle specified zero for the node id example
1073 * 0x60000000, then pick a new nodeid from the pool of IDs
1074 * this hash table has been allocating from.
1075 * If OTOH it is specified (i.e for example the user passed a
1076 * handle such as 0x60000123), then we use it generate our final
1077 * handle which is used to uniquely identify the match entry.
1079 if (!TC_U32_NODE(handle
)) {
1080 handle
= gen_new_kid(ht
, htid
);
1082 handle
= htid
| TC_U32_NODE(handle
);
1083 err
= idr_alloc_u32(&ht
->handle_idr
, NULL
, &handle
,
1084 handle
, GFP_KERNEL
);
1089 /* The user did not give us a handle; lets just generate one
1090 * from the table's pool of nodeids.
1092 handle
= gen_new_kid(ht
, htid
);
1095 if (tb
[TCA_U32_SEL
] == NULL
) {
1096 NL_SET_ERR_MSG_MOD(extack
, "Selector not specified");
1101 s
= nla_data(tb
[TCA_U32_SEL
]);
1102 sel_size
= struct_size(s
, keys
, s
->nkeys
);
1103 if (nla_len(tb
[TCA_U32_SEL
]) < sel_size
) {
1108 n
= kzalloc(struct_size(n
, sel
.keys
, s
->nkeys
), GFP_KERNEL
);
1114 #ifdef CONFIG_CLS_U32_PERF
1115 n
->pf
= __alloc_percpu(struct_size(n
->pf
, kcnts
, s
->nkeys
),
1116 __alignof__(struct tc_u32_pcnt
));
1123 unsafe_memcpy(&n
->sel
, s
, sel_size
,
1124 /* A composite flex-array structure destination,
1125 * which was correctly sized with struct_size(),
1126 * bounds-checked against nla_len(), and allocated
1128 RCU_INIT_POINTER(n
->ht_up
, ht
);
1130 n
->fshift
= s
->hmask
? ffs(ntohl(s
->hmask
)) - 1 : 0;
1131 n
->flags
= userflags
;
1133 err
= tcf_exts_init(&n
->exts
, net
, TCA_U32_ACT
, TCA_U32_POLICE
);
1137 #ifdef CONFIG_CLS_U32_MARK
1138 n
->pcpu_success
= alloc_percpu(u32
);
1139 if (!n
->pcpu_success
) {
1144 if (tb
[TCA_U32_MARK
]) {
1145 struct tc_u32_mark
*mark
;
1147 mark
= nla_data(tb
[TCA_U32_MARK
]);
1149 n
->mask
= mark
->mask
;
1153 err
= u32_set_parms(net
, tp
, n
, tb
, tca
[TCA_RATE
],
1154 flags
, n
->flags
, extack
);
1156 u32_bind_filter(tp
, n
, base
, tb
);
1159 struct tc_u_knode __rcu
**ins
;
1160 struct tc_u_knode
*pins
;
1162 err
= u32_replace_hw_knode(tp
, n
, flags
, extack
);
1166 if (!tc_in_hw(n
->flags
))
1167 n
->flags
|= TCA_CLS_FLAGS_NOT_IN_HW
;
1169 tcf_proto_update_usesw(tp
, n
->flags
);
1171 ins
= &ht
->ht
[TC_U32_HASH(handle
)];
1172 for (pins
= rtnl_dereference(*ins
); pins
;
1173 ins
= &pins
->next
, pins
= rtnl_dereference(*ins
))
1174 if (TC_U32_NODE(handle
) < TC_U32_NODE(pins
->handle
))
1177 RCU_INIT_POINTER(n
->next
, pins
);
1178 rcu_assign_pointer(*ins
, n
);
1185 u32_unbind_filter(tp
, n
, tb
);
1187 #ifdef CONFIG_CLS_U32_MARK
1188 free_percpu(n
->pcpu_success
);
1192 tcf_exts_destroy(&n
->exts
);
1193 #ifdef CONFIG_CLS_U32_PERF
1199 idr_remove(&ht
->handle_idr
, handle
);
1203 static void u32_walk(struct tcf_proto
*tp
, struct tcf_walker
*arg
,
1206 struct tc_u_common
*tp_c
= tp
->data
;
1207 struct tc_u_hnode
*ht
;
1208 struct tc_u_knode
*n
;
1214 for (ht
= rtnl_dereference(tp_c
->hlist
);
1216 ht
= rtnl_dereference(ht
->next
)) {
1217 if (ht
->prio
!= tp
->prio
)
1220 if (!tc_cls_stats_dump(tp
, arg
, ht
))
1223 for (h
= 0; h
<= ht
->divisor
; h
++) {
1224 for (n
= rtnl_dereference(ht
->ht
[h
]);
1226 n
= rtnl_dereference(n
->next
)) {
1227 if (!tc_cls_stats_dump(tp
, arg
, n
))
1234 static int u32_reoffload_hnode(struct tcf_proto
*tp
, struct tc_u_hnode
*ht
,
1235 bool add
, flow_setup_cb_t
*cb
, void *cb_priv
,
1236 struct netlink_ext_ack
*extack
)
1238 struct tc_cls_u32_offload cls_u32
= {};
1241 tc_cls_common_offload_init(&cls_u32
.common
, tp
, ht
->flags
, extack
);
1242 cls_u32
.command
= add
? TC_CLSU32_NEW_HNODE
: TC_CLSU32_DELETE_HNODE
;
1243 cls_u32
.hnode
.divisor
= ht
->divisor
;
1244 cls_u32
.hnode
.handle
= ht
->handle
;
1245 cls_u32
.hnode
.prio
= ht
->prio
;
1247 err
= cb(TC_SETUP_CLSU32
, &cls_u32
, cb_priv
);
1248 if (err
&& add
&& tc_skip_sw(ht
->flags
))
1254 static int u32_reoffload_knode(struct tcf_proto
*tp
, struct tc_u_knode
*n
,
1255 bool add
, flow_setup_cb_t
*cb
, void *cb_priv
,
1256 struct netlink_ext_ack
*extack
)
1258 struct tc_u_hnode
*ht
= rtnl_dereference(n
->ht_down
);
1259 struct tcf_block
*block
= tp
->chain
->block
;
1260 struct tc_cls_u32_offload cls_u32
= {};
1262 tc_cls_common_offload_init(&cls_u32
.common
, tp
, n
->flags
, extack
);
1263 cls_u32
.command
= add
?
1264 TC_CLSU32_REPLACE_KNODE
: TC_CLSU32_DELETE_KNODE
;
1265 cls_u32
.knode
.handle
= n
->handle
;
1268 cls_u32
.knode
.fshift
= n
->fshift
;
1269 #ifdef CONFIG_CLS_U32_MARK
1270 cls_u32
.knode
.val
= n
->val
;
1271 cls_u32
.knode
.mask
= n
->mask
;
1273 cls_u32
.knode
.val
= 0;
1274 cls_u32
.knode
.mask
= 0;
1276 cls_u32
.knode
.sel
= &n
->sel
;
1277 cls_u32
.knode
.res
= &n
->res
;
1278 cls_u32
.knode
.exts
= &n
->exts
;
1280 cls_u32
.knode
.link_handle
= ht
->handle
;
1283 return tc_setup_cb_reoffload(block
, tp
, add
, cb
, TC_SETUP_CLSU32
,
1284 &cls_u32
, cb_priv
, &n
->flags
,
1288 static int u32_reoffload(struct tcf_proto
*tp
, bool add
, flow_setup_cb_t
*cb
,
1289 void *cb_priv
, struct netlink_ext_ack
*extack
)
1291 struct tc_u_common
*tp_c
= tp
->data
;
1292 struct tc_u_hnode
*ht
;
1293 struct tc_u_knode
*n
;
1297 for (ht
= rtnl_dereference(tp_c
->hlist
);
1299 ht
= rtnl_dereference(ht
->next
)) {
1300 if (ht
->prio
!= tp
->prio
)
1303 /* When adding filters to a new dev, try to offload the
1304 * hashtable first. When removing, do the filters before the
1307 if (add
&& !tc_skip_hw(ht
->flags
)) {
1308 err
= u32_reoffload_hnode(tp
, ht
, add
, cb
, cb_priv
,
1314 for (h
= 0; h
<= ht
->divisor
; h
++) {
1315 for (n
= rtnl_dereference(ht
->ht
[h
]);
1317 n
= rtnl_dereference(n
->next
)) {
1318 if (tc_skip_hw(n
->flags
))
1321 err
= u32_reoffload_knode(tp
, n
, add
, cb
,
1328 if (!add
&& !tc_skip_hw(ht
->flags
))
1329 u32_reoffload_hnode(tp
, ht
, add
, cb
, cb_priv
, extack
);
1335 static void u32_bind_class(void *fh
, u32 classid
, unsigned long cl
, void *q
,
1338 struct tc_u_knode
*n
= fh
;
1340 tc_cls_bind_class(classid
, cl
, q
, &n
->res
, base
);
1343 static int u32_dump(struct net
*net
, struct tcf_proto
*tp
, void *fh
,
1344 struct sk_buff
*skb
, struct tcmsg
*t
, bool rtnl_held
)
1346 struct tc_u_knode
*n
= fh
;
1347 struct tc_u_hnode
*ht_up
, *ht_down
;
1348 struct nlattr
*nest
;
1353 t
->tcm_handle
= n
->handle
;
1355 nest
= nla_nest_start_noflag(skb
, TCA_OPTIONS
);
1357 goto nla_put_failure
;
1359 if (TC_U32_KEY(n
->handle
) == 0) {
1360 struct tc_u_hnode
*ht
= fh
;
1361 u32 divisor
= ht
->divisor
+ 1;
1363 if (nla_put_u32(skb
, TCA_U32_DIVISOR
, divisor
))
1364 goto nla_put_failure
;
1366 #ifdef CONFIG_CLS_U32_PERF
1367 struct tc_u32_pcnt
*gpf
;
1371 if (nla_put(skb
, TCA_U32_SEL
, struct_size(&n
->sel
, keys
, n
->sel
.nkeys
),
1373 goto nla_put_failure
;
1375 ht_up
= rtnl_dereference(n
->ht_up
);
1377 u32 htid
= n
->handle
& 0xFFFFF000;
1378 if (nla_put_u32(skb
, TCA_U32_HASH
, htid
))
1379 goto nla_put_failure
;
1381 if (n
->res
.classid
&&
1382 nla_put_u32(skb
, TCA_U32_CLASSID
, n
->res
.classid
))
1383 goto nla_put_failure
;
1385 ht_down
= rtnl_dereference(n
->ht_down
);
1387 nla_put_u32(skb
, TCA_U32_LINK
, ht_down
->handle
))
1388 goto nla_put_failure
;
1390 if (n
->flags
&& nla_put_u32(skb
, TCA_U32_FLAGS
, n
->flags
))
1391 goto nla_put_failure
;
1393 #ifdef CONFIG_CLS_U32_MARK
1394 if ((n
->val
|| n
->mask
)) {
1395 struct tc_u32_mark mark
= {.val
= n
->val
,
1400 for_each_possible_cpu(cpum
) {
1401 __u32 cnt
= *per_cpu_ptr(n
->pcpu_success
, cpum
);
1403 mark
.success
+= cnt
;
1406 if (nla_put(skb
, TCA_U32_MARK
, sizeof(mark
), &mark
))
1407 goto nla_put_failure
;
1411 if (tcf_exts_dump(skb
, &n
->exts
) < 0)
1412 goto nla_put_failure
;
1415 struct net_device
*dev
;
1416 dev
= __dev_get_by_index(net
, n
->ifindex
);
1417 if (dev
&& nla_put_string(skb
, TCA_U32_INDEV
, dev
->name
))
1418 goto nla_put_failure
;
1420 #ifdef CONFIG_CLS_U32_PERF
1421 gpf
= kzalloc(struct_size(gpf
, kcnts
, n
->sel
.nkeys
), GFP_KERNEL
);
1423 goto nla_put_failure
;
1425 for_each_possible_cpu(cpu
) {
1427 struct tc_u32_pcnt
*pf
= per_cpu_ptr(n
->pf
, cpu
);
1429 gpf
->rcnt
+= pf
->rcnt
;
1430 gpf
->rhit
+= pf
->rhit
;
1431 for (i
= 0; i
< n
->sel
.nkeys
; i
++)
1432 gpf
->kcnts
[i
] += pf
->kcnts
[i
];
1435 if (nla_put_64bit(skb
, TCA_U32_PCNT
, struct_size(gpf
, kcnts
, n
->sel
.nkeys
),
1436 gpf
, TCA_U32_PAD
)) {
1438 goto nla_put_failure
;
1444 nla_nest_end(skb
, nest
);
1446 if (TC_U32_KEY(n
->handle
))
1447 if (tcf_exts_dump_stats(skb
, &n
->exts
) < 0)
1448 goto nla_put_failure
;
1452 nla_nest_cancel(skb
, nest
);
1456 static struct tcf_proto_ops cls_u32_ops __read_mostly
= {
1458 .classify
= u32_classify
,
1460 .destroy
= u32_destroy
,
1462 .change
= u32_change
,
1463 .delete = u32_delete
,
1465 .reoffload
= u32_reoffload
,
1467 .bind_class
= u32_bind_class
,
1468 .owner
= THIS_MODULE
,
1470 MODULE_ALIAS_NET_CLS("u32");
1472 static int __init
init_u32(void)
1476 pr_info("u32 classifier\n");
1477 #ifdef CONFIG_CLS_U32_PERF
1478 pr_info(" Performance counters on\n");
1480 pr_info(" input device check on\n");
1481 #ifdef CONFIG_NET_CLS_ACT
1482 pr_info(" Actions configured\n");
1484 tc_u_common_hash
= kvmalloc_array(U32_HASH_SIZE
,
1485 sizeof(struct hlist_head
),
1487 if (!tc_u_common_hash
)
1490 for (i
= 0; i
< U32_HASH_SIZE
; i
++)
1491 INIT_HLIST_HEAD(&tc_u_common_hash
[i
]);
1493 ret
= register_tcf_proto_ops(&cls_u32_ops
);
1495 kvfree(tc_u_common_hash
);
1499 static void __exit
exit_u32(void)
1501 unregister_tcf_proto_ops(&cls_u32_ops
);
1502 kvfree(tc_u_common_hash
);
1505 module_init(init_u32
)
1506 module_exit(exit_u32
)
1507 MODULE_DESCRIPTION("Universal 32bit based TC Classifier");
1508 MODULE_LICENSE("GPL");