1 /* SPDX-License-Identifier: GPL-2.0 */
2 #ifndef __NET_FIB_RULES_H
3 #define __NET_FIB_RULES_H
5 #include <linux/types.h>
6 #include <linux/slab.h>
7 #include <linux/netdevice.h>
8 #include <linux/fib_rules.h>
9 #include <linux/refcount.h>
11 #include <net/rtnetlink.h>
12 #include <net/fib_notifier.h>
13 #include <linux/indirect_call_wrapper.h>
15 struct fib_kuid_range
{
21 struct list_head list
;
34 struct fib_rule __rcu
*ctarget
;
40 int suppress_prefixlen
;
41 char iifname
[IFNAMSIZ
];
42 char oifname
[IFNAMSIZ
];
43 struct fib_kuid_range uid_range
;
44 struct fib_rule_port_range sport_range
;
45 struct fib_rule_port_range dport_range
;
49 struct fib_lookup_arg
{
51 const void *lookup_data
;
53 struct fib_rule
*rule
;
56 #define FIB_LOOKUP_NOREF 1
57 #define FIB_LOOKUP_IGNORE_LINKSTATE 2
60 struct fib_rules_ops
{
62 struct list_head list
;
67 unsigned int fib_rules_seq
;
69 int (*action
)(struct fib_rule
*,
71 struct fib_lookup_arg
*);
72 bool (*suppress
)(struct fib_rule
*,
73 struct fib_lookup_arg
*);
74 int (*match
)(struct fib_rule
*,
76 int (*configure
)(struct fib_rule
*,
78 struct fib_rule_hdr
*,
80 struct netlink_ext_ack
*);
81 int (*delete)(struct fib_rule
*);
82 int (*compare
)(struct fib_rule
*,
83 struct fib_rule_hdr
*,
85 int (*fill
)(struct fib_rule
*, struct sk_buff
*,
86 struct fib_rule_hdr
*);
87 size_t (*nlmsg_payload
)(struct fib_rule
*);
89 /* Called after modifications to the rules set, must flush
90 * the route cache if one exists. */
91 void (*flush_cache
)(struct fib_rules_ops
*ops
);
94 const struct nla_policy
*policy
;
95 struct list_head rules_list
;
101 struct fib_rule_notifier_info
{
102 struct fib_notifier_info info
; /* must be first */
103 struct fib_rule
*rule
;
106 #define FRA_GENERIC_POLICY \
107 [FRA_UNSPEC] = { .strict_start_type = FRA_DPORT_RANGE + 1 }, \
108 [FRA_IIFNAME] = { .type = NLA_STRING, .len = IFNAMSIZ - 1 }, \
109 [FRA_OIFNAME] = { .type = NLA_STRING, .len = IFNAMSIZ - 1 }, \
110 [FRA_PRIORITY] = { .type = NLA_U32 }, \
111 [FRA_FWMARK] = { .type = NLA_U32 }, \
112 [FRA_TUN_ID] = { .type = NLA_U64 }, \
113 [FRA_FWMASK] = { .type = NLA_U32 }, \
114 [FRA_TABLE] = { .type = NLA_U32 }, \
115 [FRA_SUPPRESS_PREFIXLEN] = { .type = NLA_U32 }, \
116 [FRA_SUPPRESS_IFGROUP] = { .type = NLA_U32 }, \
117 [FRA_GOTO] = { .type = NLA_U32 }, \
118 [FRA_L3MDEV] = { .type = NLA_U8 }, \
119 [FRA_UID_RANGE] = { .len = sizeof(struct fib_rule_uid_range) }, \
120 [FRA_PROTOCOL] = { .type = NLA_U8 }, \
121 [FRA_IP_PROTO] = { .type = NLA_U8 }, \
122 [FRA_SPORT_RANGE] = { .len = sizeof(struct fib_rule_port_range) }, \
123 [FRA_DPORT_RANGE] = { .len = sizeof(struct fib_rule_port_range) }
126 static inline void fib_rule_get(struct fib_rule
*rule
)
128 refcount_inc(&rule
->refcnt
);
131 static inline void fib_rule_put(struct fib_rule
*rule
)
133 if (refcount_dec_and_test(&rule
->refcnt
))
134 kfree_rcu(rule
, rcu
);
137 #ifdef CONFIG_NET_L3_MASTER_DEV
138 static inline u32
fib_rule_get_table(struct fib_rule
*rule
,
139 struct fib_lookup_arg
*arg
)
141 return rule
->l3mdev
? arg
->table
: rule
->table
;
144 static inline u32
fib_rule_get_table(struct fib_rule
*rule
,
145 struct fib_lookup_arg
*arg
)
151 static inline u32
frh_get_table(struct fib_rule_hdr
*frh
, struct nlattr
**nla
)
154 return nla_get_u32(nla
[FRA_TABLE
]);
158 static inline bool fib_rule_port_range_set(const struct fib_rule_port_range
*range
)
160 return range
->start
!= 0 && range
->end
!= 0;
163 static inline bool fib_rule_port_inrange(const struct fib_rule_port_range
*a
,
166 return ntohs(port
) >= a
->start
&&
167 ntohs(port
) <= a
->end
;
170 static inline bool fib_rule_port_range_valid(const struct fib_rule_port_range
*a
)
172 return a
->start
!= 0 && a
->end
!= 0 && a
->end
< 0xffff &&
176 static inline bool fib_rule_port_range_compare(struct fib_rule_port_range
*a
,
177 struct fib_rule_port_range
*b
)
179 return a
->start
== b
->start
&&
183 static inline bool fib_rule_requires_fldissect(struct fib_rule
*rule
)
185 return rule
->iifindex
!= LOOPBACK_IFINDEX
&& (rule
->ip_proto
||
186 fib_rule_port_range_set(&rule
->sport_range
) ||
187 fib_rule_port_range_set(&rule
->dport_range
));
190 struct fib_rules_ops
*fib_rules_register(const struct fib_rules_ops
*,
192 void fib_rules_unregister(struct fib_rules_ops
*);
194 int fib_rules_lookup(struct fib_rules_ops
*, struct flowi
*, int flags
,
195 struct fib_lookup_arg
*);
196 int fib_default_rule_add(struct fib_rules_ops
*, u32 pref
, u32 table
,
198 bool fib_rule_matchall(const struct fib_rule
*rule
);
199 int fib_rules_dump(struct net
*net
, struct notifier_block
*nb
, int family
,
200 struct netlink_ext_ack
*extack
);
201 unsigned int fib_rules_seq_read(struct net
*net
, int family
);
203 int fib_nl_newrule(struct sk_buff
*skb
, struct nlmsghdr
*nlh
,
204 struct netlink_ext_ack
*extack
);
205 int fib_nl_delrule(struct sk_buff
*skb
, struct nlmsghdr
*nlh
,
206 struct netlink_ext_ack
*extack
);
208 INDIRECT_CALLABLE_DECLARE(int fib6_rule_match(struct fib_rule
*rule
,
209 struct flowi
*fl
, int flags
));
210 INDIRECT_CALLABLE_DECLARE(int fib4_rule_match(struct fib_rule
*rule
,
211 struct flowi
*fl
, int flags
));
213 INDIRECT_CALLABLE_DECLARE(int fib6_rule_action(struct fib_rule
*rule
,
214 struct flowi
*flp
, int flags
,
215 struct fib_lookup_arg
*arg
));
216 INDIRECT_CALLABLE_DECLARE(int fib4_rule_action(struct fib_rule
*rule
,
217 struct flowi
*flp
, int flags
,
218 struct fib_lookup_arg
*arg
));
220 INDIRECT_CALLABLE_DECLARE(bool fib6_rule_suppress(struct fib_rule
*rule
,
221 struct fib_lookup_arg
*arg
));
222 INDIRECT_CALLABLE_DECLARE(bool fib4_rule_suppress(struct fib_rule
*rule
,
223 struct fib_lookup_arg
*arg
));