blob: ce706e27700195b2ded030e1a15108dd8017c359 [file] [log] [blame]
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +05301/*
2 * sfe_ipv6.h
3 * Shortcut forwarding engine header file for IPv6.
4 *
5 * Copyright (c) 2015-2016, 2019-2020, The Linux Foundation. All rights reserved.
Guduri Prathyusha647fe3e2021-11-22 19:17:51 +05306 * Copyright (c) 2021,2022 Qualcomm Innovation Center, Inc. All rights reserved.
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +05307 *
8 * Permission to use, copy, modify, and/or distribute this software for any
9 * purpose with or without fee is hereby granted, provided that the above
10 * copyright notice and this permission notice appear in all copies.
11 *
12 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19 */
20
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053021#define CHAR_DEV_MSG_SIZE 768
22
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053023#define SFE_IPV6_DSCP_MASK 0xf03f
24#define SFE_IPV6_DSCP_SHIFT 2
25
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053026#define SFE_IPV6_FRAG_OFFSET 0xfff8
27
28/*
29 * generic IPv6 extension header
30 */
31struct sfe_ipv6_ext_hdr {
32 __u8 next_hdr;
33 __u8 hdr_len;
34 __u8 padding[6];
Ratheesh Kannoth741f7992021-10-20 07:39:52 +053035};
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053036
37/*
38 * Specifies the lower bound on ACK numbers carried in the TCP header
39 */
40#define SFE_IPV6_TCP_MAX_ACK_WINDOW 65520
41
42/*
43 * IPv6 TCP connection match additional data.
44 */
45struct sfe_ipv6_tcp_connection_match {
46 u8 win_scale; /* Window scale */
47 u32 max_win; /* Maximum window size seen */
48 u32 end; /* Sequence number of the next byte to send (seq + segment length) */
49 u32 max_end; /* Sequence number of the last byte to ack */
50};
51
52/*
53 * Bit flags for IPv6 connection matching entry.
54 */
55#define SFE_IPV6_CONNECTION_MATCH_FLAG_XLATE_SRC (1<<0)
56 /* Perform source translation */
57#define SFE_IPV6_CONNECTION_MATCH_FLAG_XLATE_DEST (1<<1)
58 /* Perform destination translation */
59#define SFE_IPV6_CONNECTION_MATCH_FLAG_NO_SEQ_CHECK (1<<2)
60 /* Ignore TCP sequence numbers */
61#define SFE_IPV6_CONNECTION_MATCH_FLAG_WRITE_FAST_ETH_HDR (1<<3)
62 /* Fast Ethernet header write */
63#define SFE_IPV6_CONNECTION_MATCH_FLAG_WRITE_L2_HDR (1<<4)
64 /* Fast Ethernet header write */
65#define SFE_IPV6_CONNECTION_MATCH_FLAG_PRIORITY_REMARK (1<<5)
66 /* remark priority of SKB */
67#define SFE_IPV6_CONNECTION_MATCH_FLAG_DSCP_REMARK (1<<6)
68 /* remark DSCP of packet */
Ratheesh Kannotha3cf0e02021-12-09 09:44:10 +053069#define SFE_IPV6_CONNECTION_MATCH_FLAG_CSUM_OFFLOAD (1<<7)
70 /* checksum offload.*/
Guduri Prathyushaeb31c902021-11-10 20:18:50 +053071#define SFE_IPV6_CONNECTION_MATCH_FLAG_PPPOE_DECAP (1<<8)
72 /* Indicates that PPPoE should be decapsulated */
73#define SFE_IPV6_CONNECTION_MATCH_FLAG_PPPOE_ENCAP (1<<9)
74 /* Indicates that PPPoE should be encapsulated */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053075
76/*
77 * IPv6 connection matching structure.
78 */
79struct sfe_ipv6_connection_match {
80 /*
81 * References to other objects.
82 */
Ratheesh Kannotha212fc52021-10-20 07:50:32 +053083 struct hlist_node hnode;
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053084 struct sfe_ipv6_connection *connection;
85 struct sfe_ipv6_connection_match *counter_match;
86 /* Matches the flow in the opposite direction as the one in connection */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053087 /*
88 * Characteristics that identify flows that match this rule.
89 */
90 struct net_device *match_dev; /* Network device */
91 u8 match_protocol; /* Protocol */
92 struct sfe_ipv6_addr match_src_ip[1]; /* Source IP address */
93 struct sfe_ipv6_addr match_dest_ip[1]; /* Destination IP address */
94 __be16 match_src_port; /* Source port/connection ident */
95 __be16 match_dest_port; /* Destination port/connection ident */
96
97 /*
98 * Control the operations of the match.
99 */
100 u32 flags; /* Bit flags */
101#ifdef CONFIG_NF_FLOW_COOKIE
102 u32 flow_cookie; /* used flow cookie, for debug */
103#endif
104#ifdef CONFIG_XFRM
105 u32 flow_accel; /* The flow accelerated or not */
106#endif
107
108 /*
109 * Connection state that we track once we match.
110 */
111 union { /* Protocol-specific state */
112 struct sfe_ipv6_tcp_connection_match tcp;
113 } protocol_state;
114 /*
115 * Stats recorded in a sync period. These stats will be added to
116 * rx_packet_count64/rx_byte_count64 after a sync period.
117 */
Ratheesh Kannotha212fc52021-10-20 07:50:32 +0530118 atomic_t rx_packet_count;
119 atomic_t rx_byte_count;
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530120
121 /*
122 * Packet translation information.
123 */
124 struct sfe_ipv6_addr xlate_src_ip[1]; /* Address after source translation */
125 __be16 xlate_src_port; /* Port/connection ident after source translation */
126 u16 xlate_src_csum_adjustment;
127 /* Transport layer checksum adjustment after source translation */
128 struct sfe_ipv6_addr xlate_dest_ip[1]; /* Address after destination translation */
129 __be16 xlate_dest_port; /* Port/connection ident after destination translation */
130 u16 xlate_dest_csum_adjustment;
131 /* Transport layer checksum adjustment after destination translation */
132
133 /*
134 * QoS information
135 */
136 u32 priority;
137 u32 dscp;
138
139 /*
140 * Packet transmit information.
141 */
142 struct net_device *xmit_dev; /* Network device on which to transmit */
143 unsigned short int xmit_dev_mtu;
144 /* Interface MTU */
145 u16 xmit_dest_mac[ETH_ALEN / 2];
146 /* Destination MAC address to use when forwarding */
147 u16 xmit_src_mac[ETH_ALEN / 2];
148 /* Source MAC address to use when forwarding */
149
150 /*
151 * Summary stats.
152 */
153 u64 rx_packet_count64;
154 u64 rx_byte_count64;
Guduri Prathyushaeb31c902021-11-10 20:18:50 +0530155
156 /*
157 * PPPoE information.
158 */
159 u16 pppoe_session_id;
160 u8 pppoe_remote_mac[ETH_ALEN];
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530161};
162
163/*
164 * Per-connection data structure.
165 */
166struct sfe_ipv6_connection {
167 struct sfe_ipv6_connection *next;
168 /* Pointer to the next entry in a hash chain */
169 struct sfe_ipv6_connection *prev;
170 /* Pointer to the previous entry in a hash chain */
171 int protocol; /* IP protocol number */
172 struct sfe_ipv6_addr src_ip[1]; /* Src IP addr pre-translation */
173 struct sfe_ipv6_addr src_ip_xlate[1]; /* Src IP addr post-translation */
174 struct sfe_ipv6_addr dest_ip[1]; /* Dest IP addr pre-translation */
175 struct sfe_ipv6_addr dest_ip_xlate[1]; /* Dest IP addr post-translation */
176 __be16 src_port; /* Src port pre-translation */
177 __be16 src_port_xlate; /* Src port post-translation */
178 __be16 dest_port; /* Dest port pre-translation */
179 __be16 dest_port_xlate; /* Dest port post-translation */
180 struct sfe_ipv6_connection_match *original_match;
181 /* Original direction matching structure */
182 struct net_device *original_dev;
183 /* Original direction source device */
184 struct sfe_ipv6_connection_match *reply_match;
185 /* Reply direction matching structure */
186 struct net_device *reply_dev; /* Reply direction source device */
187 u64 last_sync_jiffies; /* Jiffies count for the last sync */
188 struct sfe_ipv6_connection *all_connections_next;
189 /* Pointer to the next entry in the list of all connections */
190 struct sfe_ipv6_connection *all_connections_prev;
191 /* Pointer to the previous entry in the list of all connections */
Ratheesh Kannotha212fc52021-10-20 07:50:32 +0530192 bool removed; /* Indicates the connection is removed */
193 struct rcu_head rcu; /* delay rcu free */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530194 u32 mark; /* mark for outgoing packet */
195 u32 debug_read_seq; /* sequence number for debug dump */
196};
197
198/*
199 * IPv6 connections and hash table size information.
200 */
201#define SFE_IPV6_CONNECTION_HASH_SHIFT 12
202#define SFE_IPV6_CONNECTION_HASH_SIZE (1 << SFE_IPV6_CONNECTION_HASH_SHIFT)
203#define SFE_IPV6_CONNECTION_HASH_MASK (SFE_IPV6_CONNECTION_HASH_SIZE - 1)
204
205enum sfe_ipv6_exception_events {
206 SFE_IPV6_EXCEPTION_EVENT_UDP_HEADER_INCOMPLETE,
207 SFE_IPV6_EXCEPTION_EVENT_UDP_NO_CONNECTION,
208 SFE_IPV6_EXCEPTION_EVENT_UDP_IP_OPTIONS_OR_INITIAL_FRAGMENT,
209 SFE_IPV6_EXCEPTION_EVENT_UDP_SMALL_TTL,
210 SFE_IPV6_EXCEPTION_EVENT_UDP_NEEDS_FRAGMENTATION,
211 SFE_IPV6_EXCEPTION_EVENT_TCP_HEADER_INCOMPLETE,
212 SFE_IPV6_EXCEPTION_EVENT_TCP_NO_CONNECTION_SLOW_FLAGS,
213 SFE_IPV6_EXCEPTION_EVENT_TCP_NO_CONNECTION_FAST_FLAGS,
214 SFE_IPV6_EXCEPTION_EVENT_TCP_IP_OPTIONS_OR_INITIAL_FRAGMENT,
215 SFE_IPV6_EXCEPTION_EVENT_TCP_SMALL_TTL,
216 SFE_IPV6_EXCEPTION_EVENT_TCP_NEEDS_FRAGMENTATION,
217 SFE_IPV6_EXCEPTION_EVENT_TCP_FLAGS,
218 SFE_IPV6_EXCEPTION_EVENT_TCP_SEQ_EXCEEDS_RIGHT_EDGE,
219 SFE_IPV6_EXCEPTION_EVENT_TCP_SMALL_DATA_OFFS,
220 SFE_IPV6_EXCEPTION_EVENT_TCP_BAD_SACK,
221 SFE_IPV6_EXCEPTION_EVENT_TCP_BIG_DATA_OFFS,
222 SFE_IPV6_EXCEPTION_EVENT_TCP_SEQ_BEFORE_LEFT_EDGE,
223 SFE_IPV6_EXCEPTION_EVENT_TCP_ACK_EXCEEDS_RIGHT_EDGE,
224 SFE_IPV6_EXCEPTION_EVENT_TCP_ACK_BEFORE_LEFT_EDGE,
225 SFE_IPV6_EXCEPTION_EVENT_ICMP_HEADER_INCOMPLETE,
226 SFE_IPV6_EXCEPTION_EVENT_ICMP_UNHANDLED_TYPE,
227 SFE_IPV6_EXCEPTION_EVENT_ICMP_IPV6_HEADER_INCOMPLETE,
228 SFE_IPV6_EXCEPTION_EVENT_ICMP_IPV6_NON_V6,
229 SFE_IPV6_EXCEPTION_EVENT_ICMP_IPV6_IP_OPTIONS_INCOMPLETE,
230 SFE_IPV6_EXCEPTION_EVENT_ICMP_IPV6_UDP_HEADER_INCOMPLETE,
231 SFE_IPV6_EXCEPTION_EVENT_ICMP_IPV6_TCP_HEADER_INCOMPLETE,
232 SFE_IPV6_EXCEPTION_EVENT_ICMP_IPV6_UNHANDLED_PROTOCOL,
233 SFE_IPV6_EXCEPTION_EVENT_ICMP_NO_CONNECTION,
234 SFE_IPV6_EXCEPTION_EVENT_ICMP_FLUSHED_CONNECTION,
235 SFE_IPV6_EXCEPTION_EVENT_HEADER_INCOMPLETE,
236 SFE_IPV6_EXCEPTION_EVENT_BAD_TOTAL_LENGTH,
237 SFE_IPV6_EXCEPTION_EVENT_NON_V6,
238 SFE_IPV6_EXCEPTION_EVENT_NON_INITIAL_FRAGMENT,
239 SFE_IPV6_EXCEPTION_EVENT_DATAGRAM_INCOMPLETE,
240 SFE_IPV6_EXCEPTION_EVENT_IP_OPTIONS_INCOMPLETE,
241 SFE_IPV6_EXCEPTION_EVENT_UNHANDLED_PROTOCOL,
242 SFE_IPV6_EXCEPTION_EVENT_FLOW_COOKIE_ADD_FAIL,
Guduri Prathyusha79a5fee2021-11-11 17:59:10 +0530243 SFE_IPV6_EXCEPTION_EVENT_PPPOE_HEADER_ENCAP_FAILED,
Guduri Prathyusha647fe3e2021-11-22 19:17:51 +0530244 SFE_IPV6_EXCEPTION_EVENT_INVALID_PPPOE_SESSION,
245 SFE_IPV6_EXCEPTION_EVENT_INCORRECT_PPPOE_PARSING,
246 SFE_IPV6_EXCEPTION_EVENT_PPPOE_NOT_SET_IN_CME,
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530247 SFE_IPV6_EXCEPTION_EVENT_LAST
248};
249
250/*
Ratheesh Kannoth1ed95462021-10-20 07:57:45 +0530251 * Per CPU stats
252 */
253struct sfe_ipv6_stats {
254 /*
255 * Stats recorded in a sync period. These stats will be added to
256 * connection_xxx64 after a sync period.
257 */
258 u64 connection_create_requests64;
259 /* Number of IPv6 connection create requests */
260 u64 connection_create_collisions64;
261 /* Number of IPv6 connection create requests that collided with existing hash table entries */
Ratheesh Kannoth89302a72021-10-20 08:10:37 +0530262 u64 connection_create_failures64;
263 /* Number of IPv6 connection create requests failures. */
264
Ratheesh Kannoth1ed95462021-10-20 07:57:45 +0530265 u64 connection_destroy_requests64;
266 /* Number of IPv6 connection destroy requests */
267 u64 connection_destroy_misses64;
268 /* Number of IPv6 connection destroy requests that missed our hash table */
269 u64 connection_match_hash_hits64;
270 /* Number of IPv6 connection match hash hits */
271 u64 connection_match_hash_reorders64;
272 /* Number of IPv6 connection match hash reorders */
273 u64 connection_flushes64; /* Number of IPv6 connection flushes */
274 u64 packets_forwarded64; /* Number of IPv6 packets forwarded */
275 u64 packets_not_forwarded64; /* Number of IPv6 packets not forwarded */
276 u64 exception_events64[SFE_IPV6_EXCEPTION_EVENT_LAST];
Guduri Prathyusha79a5fee2021-11-11 17:59:10 +0530277 u64 pppoe_encap_packets_forwarded64; /* Number of IPv6 PPPOE encap packets forwarded */
Guduri Prathyusha647fe3e2021-11-22 19:17:51 +0530278 u64 pppoe_decap_packets_forwarded64; /* Number of IPv6 PPPOE decap packets forwarded */
Ratheesh Kannoth1ed95462021-10-20 07:57:45 +0530279};
280
281/*
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530282 * Per-module structure.
283 */
284struct sfe_ipv6 {
285 spinlock_t lock; /* Lock for SMP correctness */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530286 struct sfe_ipv6_connection *all_connections_head;
287 /* Head of the list of all connections */
288 struct sfe_ipv6_connection *all_connections_tail;
289 /* Tail of the list of all connections */
290 unsigned int num_connections; /* Number of connections */
Ken Zhu137722d2021-09-23 17:57:36 -0700291 struct delayed_work sync_dwork; /* Work to sync the statistics */
292 unsigned int work_cpu; /* The core to run stats sync on */
293
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530294 sfe_sync_rule_callback_t __rcu sync_rule_callback;
295 /* Callback function registered by a connection manager for stats syncing */
296 struct sfe_ipv6_connection *conn_hash[SFE_IPV6_CONNECTION_HASH_SIZE];
297 /* Connection hash table */
Ratheesh Kannotha212fc52021-10-20 07:50:32 +0530298 struct hlist_head hlist_conn_match_hash_head[SFE_IPV6_CONNECTION_HASH_SIZE];
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530299#ifdef CONFIG_NF_FLOW_COOKIE
300 struct sfe_ipv6_flow_cookie_entry sfe_flow_cookie_table[SFE_FLOW_COOKIE_SIZE];
301 /* flow cookie table*/
302 sfe_ipv6_flow_cookie_set_func_t flow_cookie_set_func;
303 /* function used to configure flow cookie in hardware*/
304 int flow_cookie_enable;
305 /* Enable/disable flow cookie at runtime */
306#endif
307
Ratheesh Kannoth1ed95462021-10-20 07:57:45 +0530308 struct sfe_ipv6_stats __percpu *stats_pcpu;
309 /* Common SFE counters. */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530310
Ken Zhu32b95392021-09-03 13:52:04 -0700311 struct sfe_ipv6_connection *wc_next;
312 /* The next walk point in the all connection list*/
313
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530314 /*
315 * Control state.
316 */
Ratheesh Kannoth6307bec2021-11-25 08:26:39 +0530317 struct kobject *sys_ipv6; /* sysfs linkage */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530318 int debug_dev; /* Major number of the debug char device */
319 u32 debug_read_seq; /* sequence number for debug dump */
320};
321
322/*
323 * Enumeration of the XML output.
324 */
325enum sfe_ipv6_debug_xml_states {
326 SFE_IPV6_DEBUG_XML_STATE_START,
327 SFE_IPV6_DEBUG_XML_STATE_CONNECTIONS_START,
328 SFE_IPV6_DEBUG_XML_STATE_CONNECTIONS_CONNECTION,
329 SFE_IPV6_DEBUG_XML_STATE_CONNECTIONS_END,
330 SFE_IPV6_DEBUG_XML_STATE_EXCEPTIONS_START,
331 SFE_IPV6_DEBUG_XML_STATE_EXCEPTIONS_EXCEPTION,
332 SFE_IPV6_DEBUG_XML_STATE_EXCEPTIONS_END,
333 SFE_IPV6_DEBUG_XML_STATE_STATS,
334 SFE_IPV6_DEBUG_XML_STATE_END,
335 SFE_IPV6_DEBUG_XML_STATE_DONE
336};
337
338/*
339 * XML write state.
340 */
341struct sfe_ipv6_debug_xml_write_state {
342 enum sfe_ipv6_debug_xml_states state;
343 /* XML output file state machine state */
344 int iter_exception; /* Next exception iterator */
345};
346
347typedef bool (*sfe_ipv6_debug_xml_write_method_t)(struct sfe_ipv6 *si, char *buffer, char *msg, size_t *length,
348 int *total_read, struct sfe_ipv6_debug_xml_write_state *ws);
349
Ratheesh Kannoth6307bec2021-11-25 08:26:39 +0530350/*
351 * sfe_ipv6_is_ext_hdr()
352 * check if we recognize ipv6 extension header
353 */
354static inline bool sfe_ipv6_is_ext_hdr(u8 hdr)
355{
356 return (hdr == NEXTHDR_HOP) ||
357 (hdr == NEXTHDR_ROUTING) ||
358 (hdr == NEXTHDR_FRAGMENT) ||
359 (hdr == NEXTHDR_AUTH) ||
360 (hdr == NEXTHDR_DEST) ||
361 (hdr == NEXTHDR_MOBILITY);
362}
363
364/*
365 * sfe_ipv6_change_dsfield()
366 * change dscp field in IPv6 packet
367 */
368static inline void sfe_ipv6_change_dsfield(struct ipv6hdr *iph, u8 dscp)
369{
370 __be16 *p = (__be16 *)iph;
371
372 *p = ((*p & htons(SFE_IPV6_DSCP_MASK)) | htons((u16)dscp << 4));
373}
374
375void sfe_ipv6_exception_stats_inc(struct sfe_ipv6 *si, enum sfe_ipv6_exception_events reason);
376
377struct sfe_ipv6_connection_match *
378sfe_ipv6_find_connection_match_rcu(struct sfe_ipv6 *si, struct net_device *dev, u8 protocol,
379 struct sfe_ipv6_addr *src_ip, __be16 src_port,
380 struct sfe_ipv6_addr *dest_ip, __be16 dest_port);
381
382bool sfe_ipv6_remove_connection(struct sfe_ipv6 *si, struct sfe_ipv6_connection *c);
383
384void sfe_ipv6_flush_connection(struct sfe_ipv6 *si,
385 struct sfe_ipv6_connection *c,
386 sfe_sync_reason_t reason);
387
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530388void sfe_ipv6_exit(void);
389int sfe_ipv6_init(void);