2019-05-27 09:55:01 +03:00
// SPDX-License-Identifier: GPL-2.0-or-later
2005-04-17 02:20:36 +04:00
/*
2014-11-05 22:51:51 +03:00
* net / sched / act_gact . c Generic actions
2005-04-17 02:20:36 +04:00
*
* copyright Jamal Hadi Salim ( 2002 - 4 )
*/
# include <linux/types.h>
# include <linux/kernel.h>
# include <linux/string.h>
# include <linux/errno.h>
# include <linux/skbuff.h>
# include <linux/rtnetlink.h>
# include <linux/module.h>
# include <linux/init.h>
2007-03-26 10:06:12 +04:00
# include <net/netlink.h>
2005-04-17 02:20:36 +04:00
# include <net/pkt_sched.h>
2019-03-20 17:00:02 +03:00
# include <net/pkt_cls.h>
2005-04-17 02:20:36 +04:00
# include <linux/tc_act/tc_gact.h>
# include <net/tc_act/tc_gact.h>
2022-12-06 16:55:12 +03:00
# include <net/tc_wrapper.h>
2005-04-17 02:20:36 +04:00
2016-07-26 02:09:41 +03:00
static struct tc_action_ops act_gact_ops ;
2016-02-23 02:57:53 +03:00
2005-04-17 02:20:36 +04:00
# ifdef CONFIG_GACT_PROB
2006-08-22 10:54:55 +04:00
static int gact_net_rand ( struct tcf_gact * gact )
2005-04-17 02:20:36 +04:00
{
2015-07-06 15:18:05 +03:00
smp_rmb ( ) ; /* coupled with smp_wmb() in tcf_gact_init() */
2022-10-10 05:44:02 +03:00
if ( get_random_u32_below ( gact - > tcfg_pval ) )
2006-08-22 10:54:55 +04:00
return gact - > tcf_action ;
return gact - > tcfg_paction ;
2005-04-17 02:20:36 +04:00
}
2006-08-22 10:54:55 +04:00
static int gact_determ ( struct tcf_gact * gact )
2005-04-17 02:20:36 +04:00
{
2015-07-06 15:18:06 +03:00
u32 pack = atomic_inc_return ( & gact - > packets ) ;
2015-07-06 15:18:05 +03:00
smp_rmb ( ) ; /* coupled with smp_wmb() in tcf_gact_init() */
2015-07-06 15:18:06 +03:00
if ( pack % gact - > tcfg_pval )
2006-08-22 10:54:55 +04:00
return gact - > tcf_action ;
return gact - > tcfg_paction ;
2005-04-17 02:20:36 +04:00
}
2006-08-22 10:54:55 +04:00
typedef int ( * g_rand ) ( struct tcf_gact * gact ) ;
2011-01-19 22:26:56 +03:00
static g_rand gact_rand [ MAX_RAND ] = { NULL , gact_net_rand , gact_determ } ;
2006-08-22 10:54:55 +04:00
# endif /* CONFIG_GACT_PROB */
2005-04-17 02:20:36 +04:00
2008-01-24 07:36:30 +03:00
static const struct nla_policy gact_policy [ TCA_GACT_MAX + 1 ] = {
[ TCA_GACT_PARMS ] = { . len = sizeof ( struct tc_gact ) } ,
[ TCA_GACT_PROB ] = { . len = sizeof ( struct tc_gact_p ) } ,
} ;
2013-01-14 09:15:39 +04:00
static int tcf_gact_init ( struct net * net , struct nlattr * nla ,
2016-07-26 02:09:41 +03:00
struct nlattr * est , struct tc_action * * a ,
2019-10-30 17:09:05 +03:00
struct tcf_proto * tp , u32 flags ,
struct netlink_ext_ack * extack )
2005-04-17 02:20:36 +04:00
{
2022-09-08 07:14:33 +03:00
struct tc_action_net * tn = net_generic ( net , act_gact_ops . net_id ) ;
2021-07-30 02:12:14 +03:00
bool bind = flags & TCA_ACT_FLAGS_BIND ;
2008-01-23 09:11:50 +03:00
struct nlattr * tb [ TCA_GACT_MAX + 1 ] ;
2019-03-20 17:00:02 +03:00
struct tcf_chain * goto_ch = NULL ;
2005-04-17 02:20:36 +04:00
struct tc_gact * parm ;
2006-08-22 10:54:55 +04:00
struct tcf_gact * gact ;
2005-04-17 02:20:36 +04:00
int ret = 0 ;
2019-08-01 16:02:51 +03:00
u32 index ;
2008-01-24 07:33:32 +03:00
int err ;
2012-08-03 14:57:52 +04:00
# ifdef CONFIG_GACT_PROB
struct tc_gact_p * p_parm = NULL ;
# endif
2005-04-17 02:20:36 +04:00
2008-01-24 07:33:32 +03:00
if ( nla = = NULL )
2005-04-17 02:20:36 +04:00
return - EINVAL ;
netlink: make validation more configurable for future strictness
We currently have two levels of strict validation:
1) liberal (default)
- undefined (type >= max) & NLA_UNSPEC attributes accepted
- attribute length >= expected accepted
- garbage at end of message accepted
2) strict (opt-in)
- NLA_UNSPEC attributes accepted
- attribute length >= expected accepted
Split out parsing strictness into four different options:
* TRAILING - check that there's no trailing data after parsing
attributes (in message or nested)
* MAXTYPE - reject attrs > max known type
* UNSPEC - reject attributes with NLA_UNSPEC policy entries
* STRICT_ATTRS - strictly validate attribute size
The default for future things should be *everything*.
The current *_strict() is a combination of TRAILING and MAXTYPE,
and is renamed to _deprecated_strict().
The current regular parsing has none of this, and is renamed to
*_parse_deprecated().
Additionally it allows us to selectively set one of the new flags
even on old policies. Notably, the UNSPEC flag could be useful in
this case, since it can be arranged (by filling in the policy) to
not be an incompatible userspace ABI change, but would then going
forward prevent forgetting attribute entries. Similar can apply
to the POLICY flag.
We end up with the following renames:
* nla_parse -> nla_parse_deprecated
* nla_parse_strict -> nla_parse_deprecated_strict
* nlmsg_parse -> nlmsg_parse_deprecated
* nlmsg_parse_strict -> nlmsg_parse_deprecated_strict
* nla_parse_nested -> nla_parse_nested_deprecated
* nla_validate_nested -> nla_validate_nested_deprecated
Using spatch, of course:
@@
expression TB, MAX, HEAD, LEN, POL, EXT;
@@
-nla_parse(TB, MAX, HEAD, LEN, POL, EXT)
+nla_parse_deprecated(TB, MAX, HEAD, LEN, POL, EXT)
@@
expression NLH, HDRLEN, TB, MAX, POL, EXT;
@@
-nlmsg_parse(NLH, HDRLEN, TB, MAX, POL, EXT)
+nlmsg_parse_deprecated(NLH, HDRLEN, TB, MAX, POL, EXT)
@@
expression NLH, HDRLEN, TB, MAX, POL, EXT;
@@
-nlmsg_parse_strict(NLH, HDRLEN, TB, MAX, POL, EXT)
+nlmsg_parse_deprecated_strict(NLH, HDRLEN, TB, MAX, POL, EXT)
@@
expression TB, MAX, NLA, POL, EXT;
@@
-nla_parse_nested(TB, MAX, NLA, POL, EXT)
+nla_parse_nested_deprecated(TB, MAX, NLA, POL, EXT)
@@
expression START, MAX, POL, EXT;
@@
-nla_validate_nested(START, MAX, POL, EXT)
+nla_validate_nested_deprecated(START, MAX, POL, EXT)
@@
expression NLH, HDRLEN, MAX, POL, EXT;
@@
-nlmsg_validate(NLH, HDRLEN, MAX, POL, EXT)
+nlmsg_validate_deprecated(NLH, HDRLEN, MAX, POL, EXT)
For this patch, don't actually add the strict, non-renamed versions
yet so that it breaks compile if I get it wrong.
Also, while at it, make nla_validate and nla_parse go down to a
common __nla_validate_parse() function to avoid code duplication.
Ultimately, this allows us to have very strict validation for every
new caller of nla_parse()/nlmsg_parse() etc as re-introduced in the
next patch, while existing things will continue to work as is.
In effect then, this adds fully strict validation for any new command.
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2019-04-26 15:07:28 +03:00
err = nla_parse_nested_deprecated ( tb , TCA_GACT_MAX , nla , gact_policy ,
NULL ) ;
2008-01-24 07:33:32 +03:00
if ( err < 0 )
return err ;
2008-01-24 07:36:30 +03:00
if ( tb [ TCA_GACT_PARMS ] = = NULL )
2005-04-17 02:20:36 +04:00
return - EINVAL ;
2008-01-23 09:11:50 +03:00
parm = nla_data ( tb [ TCA_GACT_PARMS ] ) ;
2019-08-01 16:02:51 +03:00
index = parm - > index ;
2005-04-17 02:20:36 +04:00
2008-01-24 07:36:30 +03:00
# ifndef CONFIG_GACT_PROB
2008-01-23 09:11:50 +03:00
if ( tb [ TCA_GACT_PROB ] ! = NULL )
2005-04-17 02:20:36 +04:00
return - EOPNOTSUPP ;
2012-08-03 14:57:52 +04:00
# else
if ( tb [ TCA_GACT_PROB ] ) {
p_parm = nla_data ( tb [ TCA_GACT_PROB ] ) ;
if ( p_parm - > ptype > = MAX_RAND )
return - EINVAL ;
2018-10-21 00:33:07 +03:00
if ( TC_ACT_EXT_CMP ( p_parm - > paction , TC_ACT_GOTO_CHAIN ) ) {
NL_SET_ERR_MSG ( extack ,
" goto chain not allowed on fallback " ) ;
return - EINVAL ;
}
2012-08-03 14:57:52 +04:00
}
2005-04-17 02:20:36 +04:00
# endif
2019-08-01 16:02:51 +03:00
err = tcf_idr_check_alloc ( tn , & index , a , bind ) ;
2018-07-05 17:24:32 +03:00
if ( ! err ) {
2019-10-30 17:09:06 +03:00
ret = tcf_idr_create_from_flags ( tn , index , est , a ,
& act_gact_ops , bind , flags ) ;
2018-07-05 17:24:32 +03:00
if ( ret ) {
2019-08-01 16:02:51 +03:00
tcf_idr_cleanup ( tn , index ) ;
2014-02-12 05:07:31 +04:00
return ret ;
2018-07-05 17:24:32 +03:00
}
2005-04-17 02:20:36 +04:00
ret = ACT_P_CREATED ;
2018-07-05 17:24:32 +03:00
} else if ( err > 0 ) {
2013-12-23 17:02:11 +04:00
if ( bind ) /* dont override defaults */
return 0 ;
2021-07-30 02:12:14 +03:00
if ( ! ( flags & TCA_ACT_FLAGS_REPLACE ) ) {
2018-07-05 17:24:30 +03:00
tcf_idr_release ( * a , bind ) ;
2005-04-17 02:20:36 +04:00
return - EEXIST ;
2018-07-05 17:24:30 +03:00
}
2018-07-05 17:24:32 +03:00
} else {
return err ;
2005-04-17 02:20:36 +04:00
}
2019-03-20 17:00:02 +03:00
err = tcf_action_check_ctrlact ( parm - > action , tp , & goto_ch , extack ) ;
if ( err < 0 )
goto release_idr ;
2016-07-26 02:09:41 +03:00
gact = to_gact ( * a ) ;
2006-08-22 10:54:55 +04:00
2018-08-14 21:46:16 +03:00
spin_lock_bh ( & gact - > tcf_lock ) ;
2019-03-20 17:00:02 +03:00
goto_ch = tcf_action_set_ctrlact ( * a , parm - > action , goto_ch ) ;
2005-04-17 02:20:36 +04:00
# ifdef CONFIG_GACT_PROB
2012-08-03 14:57:52 +04:00
if ( p_parm ) {
2006-08-22 10:54:55 +04:00
gact - > tcfg_paction = p_parm - > paction ;
2015-07-06 15:18:05 +03:00
gact - > tcfg_pval = max_t ( u16 , 1 , p_parm - > pval ) ;
/* Make sure tcfg_pval is written before tcfg_ptype
* coupled with smp_rmb ( ) in gact_net_rand ( ) & gact_determ ( )
*/
smp_wmb ( ) ;
2006-08-22 10:54:55 +04:00
gact - > tcfg_ptype = p_parm - > ptype ;
2005-04-17 02:20:36 +04:00
}
# endif
2018-08-14 21:46:16 +03:00
spin_unlock_bh ( & gact - > tcf_lock ) ;
2018-08-10 20:51:43 +03:00
2019-03-20 17:00:02 +03:00
if ( goto_ch )
tcf_chain_put_by_act ( goto_ch ) ;
2005-04-17 02:20:36 +04:00
return ret ;
2019-03-20 17:00:02 +03:00
release_idr :
tcf_idr_release ( * a , bind ) ;
return err ;
2005-04-17 02:20:36 +04:00
}
2022-12-06 16:55:12 +03:00
TC_INDIRECT_SCOPE int tcf_gact_act ( struct sk_buff * skb ,
const struct tc_action * a ,
struct tcf_result * res )
2005-04-17 02:20:36 +04:00
{
2016-07-26 02:09:41 +03:00
struct tcf_gact * gact = to_gact ( a ) ;
2015-07-06 15:18:08 +03:00
int action = READ_ONCE ( gact - > tcf_action ) ;
2005-04-17 02:20:36 +04:00
# ifdef CONFIG_GACT_PROB
2015-07-06 15:18:07 +03:00
{
u32 ptype = READ_ONCE ( gact - > tcfg_ptype ) ;
if ( ptype )
action = gact_rand [ ptype ] ( gact ) ;
}
2005-04-17 02:20:36 +04:00
# endif
2019-10-30 17:09:01 +03:00
tcf_action_update_bstats ( & gact - > common , skb ) ;
2005-04-17 02:20:36 +04:00
if ( action = = TC_ACT_SHOT )
2019-10-30 17:09:02 +03:00
tcf_action_inc_drop_qstats ( & gact - > common ) ;
2015-07-06 15:18:08 +03:00
tcf_lastuse_update ( & gact - > tcf_tm ) ;
2005-04-17 02:20:36 +04:00
return action ;
}
2020-06-19 09:01:07 +03:00
static void tcf_gact_stats_update ( struct tc_action * a , u64 bytes , u64 packets ,
u64 drops , u64 lastuse , bool hw )
2016-05-13 15:55:36 +03:00
{
2016-07-26 02:09:41 +03:00
struct tcf_gact * gact = to_gact ( a ) ;
2016-05-13 15:55:36 +03:00
int action = READ_ONCE ( gact - > tcf_action ) ;
struct tcf_t * tm = & gact - > tcf_tm ;
2020-06-19 09:01:07 +03:00
tcf_action_update_stats ( a , bytes , packets ,
action = = TC_ACT_SHOT ? packets : drops , hw ) ;
2017-12-26 08:48:51 +03:00
tm - > lastuse = max_t ( u64 , tm - > lastuse , lastuse ) ;
2016-05-13 15:55:36 +03:00
}
2016-06-05 17:41:32 +03:00
static int tcf_gact_dump ( struct sk_buff * skb , struct tc_action * a ,
int bind , int ref )
2005-04-17 02:20:36 +04:00
{
2007-04-20 07:29:13 +04:00
unsigned char * b = skb_tail_pointer ( skb ) ;
2016-07-26 02:09:41 +03:00
struct tcf_gact * gact = to_gact ( a ) ;
2010-08-17 00:04:22 +04:00
struct tc_gact opt = {
. index = gact - > tcf_index ,
2018-07-05 17:24:24 +03:00
. refcnt = refcount_read ( & gact - > tcf_refcnt ) - ref ,
. bindcnt = atomic_read ( & gact - > tcf_bindcnt ) - bind ,
2010-08-17 00:04:22 +04:00
} ;
2005-04-17 02:20:36 +04:00
struct tcf_t t ;
2018-08-14 21:46:16 +03:00
spin_lock_bh ( & gact - > tcf_lock ) ;
2018-08-10 20:51:43 +03:00
opt . action = gact - > tcf_action ;
2012-03-29 13:11:39 +04:00
if ( nla_put ( skb , TCA_GACT_PARMS , sizeof ( opt ) , & opt ) )
goto nla_put_failure ;
2005-04-17 02:20:36 +04:00
# ifdef CONFIG_GACT_PROB
2006-08-22 10:54:55 +04:00
if ( gact - > tcfg_ptype ) {
2010-08-17 00:04:22 +04:00
struct tc_gact_p p_opt = {
. paction = gact - > tcfg_paction ,
. pval = gact - > tcfg_pval ,
. ptype = gact - > tcfg_ptype ,
} ;
2012-03-29 13:11:39 +04:00
if ( nla_put ( skb , TCA_GACT_PROB , sizeof ( p_opt ) , & p_opt ) )
goto nla_put_failure ;
2005-04-17 02:20:36 +04:00
}
# endif
2016-06-06 13:32:55 +03:00
tcf_tm_dump ( & t , & gact - > tcf_tm ) ;
2016-04-26 11:06:18 +03:00
if ( nla_put_64bit ( skb , TCA_GACT_TM , sizeof ( t ) , & t , TCA_GACT_PAD ) )
2012-03-29 13:11:39 +04:00
goto nla_put_failure ;
2018-08-14 21:46:16 +03:00
spin_unlock_bh ( & gact - > tcf_lock ) ;
2018-08-10 20:51:43 +03:00
2005-04-17 02:20:36 +04:00
return skb - > len ;
2008-01-23 09:11:50 +03:00
nla_put_failure :
2018-08-14 21:46:16 +03:00
spin_unlock_bh ( & gact - > tcf_lock ) ;
2007-03-26 10:06:12 +04:00
nlmsg_trim ( skb , b ) ;
2005-04-17 02:20:36 +04:00
return - 1 ;
}
2018-03-09 00:59:20 +03:00
static size_t tcf_gact_get_fill_size ( const struct tc_action * act )
{
size_t sz = nla_total_size ( sizeof ( struct tc_gact ) ) ; /* TCA_GACT_PARMS */
# ifdef CONFIG_GACT_PROB
if ( to_gact ( act ) - > tcfg_ptype )
/* TCA_GACT_PROB */
sz + = nla_total_size ( sizeof ( struct tc_gact_p ) ) ;
# endif
return sz ;
}
2021-12-17 21:16:21 +03:00
static int tcf_gact_offload_act_setup ( struct tc_action * act , void * entry_data ,
2022-04-07 10:35:22 +03:00
u32 * index_inc , bool bind ,
struct netlink_ext_ack * extack )
2021-12-17 21:16:21 +03:00
{
if ( bind ) {
struct flow_action_entry * entry = entry_data ;
if ( is_tcf_gact_ok ( act ) ) {
entry - > id = FLOW_ACTION_ACCEPT ;
} else if ( is_tcf_gact_shot ( act ) ) {
entry - > id = FLOW_ACTION_DROP ;
} else if ( is_tcf_gact_trap ( act ) ) {
entry - > id = FLOW_ACTION_TRAP ;
} else if ( is_tcf_gact_goto_chain ( act ) ) {
entry - > id = FLOW_ACTION_GOTO ;
entry - > chain_index = tcf_gact_goto_chain_index ( act ) ;
2022-04-07 10:35:23 +03:00
} else if ( is_tcf_gact_continue ( act ) ) {
NL_SET_ERR_MSG_MOD ( extack , " Offload of \" continue \" action is not supported " ) ;
return - EOPNOTSUPP ;
} else if ( is_tcf_gact_reclassify ( act ) ) {
NL_SET_ERR_MSG_MOD ( extack , " Offload of \" reclassify \" action is not supported " ) ;
return - EOPNOTSUPP ;
} else if ( is_tcf_gact_pipe ( act ) ) {
NL_SET_ERR_MSG_MOD ( extack , " Offload of \" pipe \" action is not supported " ) ;
return - EOPNOTSUPP ;
2021-12-17 21:16:21 +03:00
} else {
2022-04-07 10:35:23 +03:00
NL_SET_ERR_MSG_MOD ( extack , " Unsupported generic action offload " ) ;
2021-12-17 21:16:21 +03:00
return - EOPNOTSUPP ;
}
* index_inc = 1 ;
} else {
2021-12-17 21:16:22 +03:00
struct flow_offload_action * fl_action = entry_data ;
if ( is_tcf_gact_ok ( act ) )
fl_action - > id = FLOW_ACTION_ACCEPT ;
else if ( is_tcf_gact_shot ( act ) )
fl_action - > id = FLOW_ACTION_DROP ;
else if ( is_tcf_gact_trap ( act ) )
fl_action - > id = FLOW_ACTION_TRAP ;
else if ( is_tcf_gact_goto_chain ( act ) )
fl_action - > id = FLOW_ACTION_GOTO ;
else
return - EOPNOTSUPP ;
2021-12-17 21:16:21 +03:00
}
return 0 ;
}
2005-04-17 02:20:36 +04:00
static struct tc_action_ops act_gact_ops = {
. kind = " gact " ,
2019-02-10 15:25:00 +03:00
. id = TCA_ID_GACT ,
2005-04-17 02:20:36 +04:00
. owner = THIS_MODULE ,
2018-08-12 16:34:52 +03:00
. act = tcf_gact_act ,
2016-05-13 15:55:36 +03:00
. stats_update = tcf_gact_stats_update ,
2005-04-17 02:20:36 +04:00
. dump = tcf_gact_dump ,
. init = tcf_gact_init ,
2018-03-09 00:59:20 +03:00
. get_fill_size = tcf_gact_get_fill_size ,
2021-12-17 21:16:21 +03:00
. offload_act_setup = tcf_gact_offload_act_setup ,
2016-07-26 02:09:41 +03:00
. size = sizeof ( struct tcf_gact ) ,
2016-02-23 02:57:53 +03:00
} ;
static __net_init int gact_init_net ( struct net * net )
{
2022-09-08 07:14:33 +03:00
struct tc_action_net * tn = net_generic ( net , act_gact_ops . net_id ) ;
2016-02-23 02:57:53 +03:00
2019-08-25 20:01:32 +03:00
return tc_action_net_init ( net , tn , & act_gact_ops ) ;
2016-02-23 02:57:53 +03:00
}
2017-12-12 02:35:03 +03:00
static void __net_exit gact_exit_net ( struct list_head * net_list )
2016-02-23 02:57:53 +03:00
{
2022-09-08 07:14:33 +03:00
tc_action_net_exit ( net_list , act_gact_ops . net_id ) ;
2016-02-23 02:57:53 +03:00
}
static struct pernet_operations gact_net_ops = {
. init = gact_init_net ,
2017-12-12 02:35:03 +03:00
. exit_batch = gact_exit_net ,
2022-09-08 07:14:33 +03:00
. id = & act_gact_ops . net_id ,
2016-02-23 02:57:53 +03:00
. size = sizeof ( struct tc_action_net ) ,
2005-04-17 02:20:36 +04:00
} ;
MODULE_AUTHOR ( " Jamal Hadi Salim(2002-4) " ) ;
MODULE_DESCRIPTION ( " Generic Classifier actions " ) ;
MODULE_LICENSE ( " GPL " ) ;
2006-08-22 10:54:55 +04:00
static int __init gact_init_module ( void )
2005-04-17 02:20:36 +04:00
{
# ifdef CONFIG_GACT_PROB
2011-01-19 22:26:56 +03:00
pr_info ( " GACT probability on \n " ) ;
2005-04-17 02:20:36 +04:00
# else
2011-01-19 22:26:56 +03:00
pr_info ( " GACT probability NOT on \n " ) ;
2005-04-17 02:20:36 +04:00
# endif
2016-02-23 02:57:53 +03:00
return tcf_register_action ( & act_gact_ops , & gact_net_ops ) ;
2005-04-17 02:20:36 +04:00
}
2006-08-22 10:54:55 +04:00
static void __exit gact_cleanup_module ( void )
2005-04-17 02:20:36 +04:00
{
2016-02-23 02:57:53 +03:00
tcf_unregister_action ( & act_gact_ops , & gact_net_ops ) ;
2005-04-17 02:20:36 +04:00
}
module_init ( gact_init_module ) ;
module_exit ( gact_cleanup_module ) ;