blob: ace17a9749acfb0e61e296ec2d28aec6dc68ba30 [file] [log] [blame]
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +05301/*
2 * sfe_ipv4.h
3 * Shortcut forwarding engine header file for IPv4.
4 *
5 * Copyright (c) 2013-2016, 2019-2020, The Linux Foundation. All rights reserved.
Guduri Prathyusha647fe3e2021-11-22 19:17:51 +05306 * Copyright (c) 2021,2022 Qualcomm Innovation Center, Inc. All rights reserved.
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +05307 *
8 * Permission to use, copy, modify, and/or distribute this software for any
9 * purpose with or without fee is hereby granted, provided that the above
10 * copyright notice and this permission notice appear in all copies.
11 *
12 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19 */
20
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053021#define SFE_IPV4_DSCP_MASK 0x3
22#define SFE_IPV4_DSCP_SHIFT 2
23
24/*
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053025 * Specifies the lower bound on ACK numbers carried in the TCP header
26 */
27#define SFE_IPV4_TCP_MAX_ACK_WINDOW 65520
28
29/*
30 * IPv4 TCP connection match additional data.
31 */
32struct sfe_ipv4_tcp_connection_match {
33 u8 win_scale; /* Window scale */
34 u32 max_win; /* Maximum window size seen */
35 u32 end; /* Sequence number of the next byte to send (seq + segment length) */
36 u32 max_end; /* Sequence number of the last byte to ack */
37};
38
39/*
40 * Bit flags for IPv4 connection matching entry.
41 */
42#define SFE_IPV4_CONNECTION_MATCH_FLAG_XLATE_SRC (1<<0)
43 /* Perform source translation */
44#define SFE_IPV4_CONNECTION_MATCH_FLAG_XLATE_DEST (1<<1)
45 /* Perform destination translation */
46#define SFE_IPV4_CONNECTION_MATCH_FLAG_NO_SEQ_CHECK (1<<2)
47 /* Ignore TCP sequence numbers */
48#define SFE_IPV4_CONNECTION_MATCH_FLAG_WRITE_FAST_ETH_HDR (1<<3)
49 /* Fast Ethernet header write */
50#define SFE_IPV4_CONNECTION_MATCH_FLAG_WRITE_L2_HDR (1<<4)
51 /* Fast Ethernet header write */
52#define SFE_IPV4_CONNECTION_MATCH_FLAG_PRIORITY_REMARK (1<<5)
53 /* remark priority of SKB */
54#define SFE_IPV4_CONNECTION_MATCH_FLAG_DSCP_REMARK (1<<6)
55 /* remark DSCP of packet */
Ratheesh Kannotha3cf0e02021-12-09 09:44:10 +053056#define SFE_IPV4_CONNECTION_MATCH_FLAG_CSUM_OFFLOAD (1<<7)
57 /* checksum offload.*/
Guduri Prathyushaeb31c902021-11-10 20:18:50 +053058#define SFE_IPV4_CONNECTION_MATCH_FLAG_PPPOE_DECAP (1<<8)
59 /* Indicates that PPPoE should be decapsulated */
60#define SFE_IPV4_CONNECTION_MATCH_FLAG_PPPOE_ENCAP (1<<9)
61 /* Indicates that PPPoE should be encapsulated */
Ratheesh Kannoth71fc51e2022-01-05 10:02:47 +053062#define SFE_IPV4_CONNECTION_MATCH_FLAG_BRIDGE_FLOW (1<<10)
63 /* Bridge flow */
Ken Zhu37040ea2021-09-09 21:11:15 -070064#define SFE_IPV4_CONNECTION_MATCH_FLAG_MARK (1<<11)
65 /* skb mark of the packet */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053066/*
67 * IPv4 connection matching structure.
68 */
69struct sfe_ipv4_connection_match {
70 /*
71 * References to other objects.
72 */
Ratheesh Kannoth94fc5b82021-10-20 07:45:06 +053073 struct hlist_node hnode;
74
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053075 struct sfe_ipv4_connection *connection;
76 struct sfe_ipv4_connection_match *counter_match;
77 /* Matches the flow in the opposite direction as the one in *connection */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053078 /*
79 * Characteristics that identify flows that match this rule.
80 */
81 struct net_device *match_dev; /* Network device */
82 u8 match_protocol; /* Protocol */
83 __be32 match_src_ip; /* Source IP address */
84 __be32 match_dest_ip; /* Destination IP address */
85 __be16 match_src_port; /* Source port/connection ident */
86 __be16 match_dest_port; /* Destination port/connection ident */
87
Amitesh Anand63be37d2021-12-24 20:51:48 +053088 struct udp_sock *up; /* Stores UDP sock information; valid only in decap path */
89
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +053090 /*
91 * Control the operations of the match.
92 */
93 u32 flags; /* Bit flags */
94#ifdef CONFIG_NF_FLOW_COOKIE
95 u32 flow_cookie; /* used flow cookie, for debug */
96#endif
97#ifdef CONFIG_XFRM
98 u32 flow_accel; /* The flow accelerated or not */
99#endif
100
101 /*
102 * Connection state that we track once we match.
103 */
104 union { /* Protocol-specific state */
105 struct sfe_ipv4_tcp_connection_match tcp;
106 } protocol_state;
107 /*
108 * Stats recorded in a sync period. These stats will be added to
109 * rx_packet_count64/rx_byte_count64 after a sync period.
110 */
Ratheesh Kannoth94fc5b82021-10-20 07:45:06 +0530111 atomic_t rx_packet_count;
112 atomic_t rx_byte_count;
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530113
114 /*
115 * Packet translation information.
116 */
117 __be32 xlate_src_ip; /* Address after source translation */
118 __be16 xlate_src_port; /* Port/connection ident after source translation */
119 u16 xlate_src_csum_adjustment;
120 /* Transport layer checksum adjustment after source translation */
121 u16 xlate_src_partial_csum_adjustment;
122 /* Transport layer pseudo header checksum adjustment after source translation */
123
124 __be32 xlate_dest_ip; /* Address after destination translation */
125 __be16 xlate_dest_port; /* Port/connection ident after destination translation */
126 u16 xlate_dest_csum_adjustment;
127 /* Transport layer checksum adjustment after destination translation */
128 u16 xlate_dest_partial_csum_adjustment;
129 /* Transport layer pseudo header checksum adjustment after destination translation */
130
131 /*
132 * QoS information
133 */
134 u32 priority;
135 u32 dscp;
Ken Zhu37040ea2021-09-09 21:11:15 -0700136 u32 mark; /* mark for outgoing packet */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530137
138 /*
139 * Packet transmit information.
140 */
141 struct net_device *xmit_dev; /* Network device on which to transmit */
142 unsigned short int xmit_dev_mtu;
143 /* Interface MTU */
144 u16 xmit_dest_mac[ETH_ALEN / 2];
145 /* Destination MAC address to use when forwarding */
146 u16 xmit_src_mac[ETH_ALEN / 2];
147 /* Source MAC address to use when forwarding */
148
149 /*
150 * Summary stats.
151 */
152 u64 rx_packet_count64;
153 u64 rx_byte_count64;
Guduri Prathyushaeb31c902021-11-10 20:18:50 +0530154
155 /*
156 * PPPoE information
157 */
158 u16 pppoe_session_id;
159 u8 pppoe_remote_mac[ETH_ALEN];
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530160};
161
162/*
163 * Per-connection data structure.
164 */
165struct sfe_ipv4_connection {
166 struct sfe_ipv4_connection *next;
167 /* Pointer to the next entry in a hash chain */
168 struct sfe_ipv4_connection *prev;
169 /* Pointer to the previous entry in a hash chain */
170 int protocol; /* IP protocol number */
171 __be32 src_ip; /* Src IP addr pre-translation */
172 __be32 src_ip_xlate; /* Src IP addr post-translation */
173 __be32 dest_ip; /* Dest IP addr pre-translation */
174 __be32 dest_ip_xlate; /* Dest IP addr post-translation */
175 __be16 src_port; /* Src port pre-translation */
176 __be16 src_port_xlate; /* Src port post-translation */
177 __be16 dest_port; /* Dest port pre-translation */
178 __be16 dest_port_xlate; /* Dest port post-translation */
179 struct sfe_ipv4_connection_match *original_match;
180 /* Original direction matching structure */
181 struct net_device *original_dev;
182 /* Original direction source device */
183 struct sfe_ipv4_connection_match *reply_match;
184 /* Reply direction matching structure */
185 struct net_device *reply_dev; /* Reply direction source device */
186 u64 last_sync_jiffies; /* Jiffies count for the last sync */
187 struct sfe_ipv4_connection *all_connections_next;
188 /* Pointer to the next entry in the list of all connections */
189 struct sfe_ipv4_connection *all_connections_prev;
190 /* Pointer to the previous entry in the list of all connections */
191 u32 mark; /* mark for outgoing packet */
192 u32 debug_read_seq; /* sequence number for debug dump */
Ratheesh Kannoth94fc5b82021-10-20 07:45:06 +0530193 bool removed; /* Indicates the connection is removed */
194 struct rcu_head rcu; /* delay rcu free */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530195};
196
197/*
198 * IPv4 connections and hash table size information.
199 */
200#define SFE_IPV4_CONNECTION_HASH_SHIFT 12
201#define SFE_IPV4_CONNECTION_HASH_SIZE (1 << SFE_IPV4_CONNECTION_HASH_SHIFT)
202#define SFE_IPV4_CONNECTION_HASH_MASK (SFE_IPV4_CONNECTION_HASH_SIZE - 1)
203
204enum sfe_ipv4_exception_events {
205 SFE_IPV4_EXCEPTION_EVENT_UDP_HEADER_INCOMPLETE,
206 SFE_IPV4_EXCEPTION_EVENT_UDP_NO_CONNECTION,
207 SFE_IPV4_EXCEPTION_EVENT_UDP_IP_OPTIONS_OR_INITIAL_FRAGMENT,
208 SFE_IPV4_EXCEPTION_EVENT_UDP_SMALL_TTL,
209 SFE_IPV4_EXCEPTION_EVENT_UDP_NEEDS_FRAGMENTATION,
210 SFE_IPV4_EXCEPTION_EVENT_TCP_HEADER_INCOMPLETE,
211 SFE_IPV4_EXCEPTION_EVENT_TCP_NO_CONNECTION_SLOW_FLAGS,
212 SFE_IPV4_EXCEPTION_EVENT_TCP_NO_CONNECTION_FAST_FLAGS,
213 SFE_IPV4_EXCEPTION_EVENT_TCP_IP_OPTIONS_OR_INITIAL_FRAGMENT,
214 SFE_IPV4_EXCEPTION_EVENT_TCP_SMALL_TTL,
215 SFE_IPV4_EXCEPTION_EVENT_TCP_NEEDS_FRAGMENTATION,
216 SFE_IPV4_EXCEPTION_EVENT_TCP_FLAGS,
217 SFE_IPV4_EXCEPTION_EVENT_TCP_SEQ_EXCEEDS_RIGHT_EDGE,
218 SFE_IPV4_EXCEPTION_EVENT_TCP_SMALL_DATA_OFFS,
219 SFE_IPV4_EXCEPTION_EVENT_TCP_BAD_SACK,
220 SFE_IPV4_EXCEPTION_EVENT_TCP_BIG_DATA_OFFS,
221 SFE_IPV4_EXCEPTION_EVENT_TCP_SEQ_BEFORE_LEFT_EDGE,
222 SFE_IPV4_EXCEPTION_EVENT_TCP_ACK_EXCEEDS_RIGHT_EDGE,
223 SFE_IPV4_EXCEPTION_EVENT_TCP_ACK_BEFORE_LEFT_EDGE,
224 SFE_IPV4_EXCEPTION_EVENT_ICMP_HEADER_INCOMPLETE,
225 SFE_IPV4_EXCEPTION_EVENT_ICMP_UNHANDLED_TYPE,
226 SFE_IPV4_EXCEPTION_EVENT_ICMP_IPV4_HEADER_INCOMPLETE,
227 SFE_IPV4_EXCEPTION_EVENT_ICMP_IPV4_NON_V4,
228 SFE_IPV4_EXCEPTION_EVENT_ICMP_IPV4_IP_OPTIONS_INCOMPLETE,
229 SFE_IPV4_EXCEPTION_EVENT_ICMP_IPV4_UDP_HEADER_INCOMPLETE,
230 SFE_IPV4_EXCEPTION_EVENT_ICMP_IPV4_TCP_HEADER_INCOMPLETE,
231 SFE_IPV4_EXCEPTION_EVENT_ICMP_IPV4_UNHANDLED_PROTOCOL,
232 SFE_IPV4_EXCEPTION_EVENT_ICMP_NO_CONNECTION,
233 SFE_IPV4_EXCEPTION_EVENT_ICMP_FLUSHED_CONNECTION,
234 SFE_IPV4_EXCEPTION_EVENT_HEADER_INCOMPLETE,
Ratheesh Kannoth43d64f82021-10-20 08:23:29 +0530235 SFE_IPV4_EXCEPTION_EVENT_HEADER_CSUM_BAD,
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530236 SFE_IPV4_EXCEPTION_EVENT_BAD_TOTAL_LENGTH,
237 SFE_IPV4_EXCEPTION_EVENT_NON_V4,
238 SFE_IPV4_EXCEPTION_EVENT_NON_INITIAL_FRAGMENT,
239 SFE_IPV4_EXCEPTION_EVENT_DATAGRAM_INCOMPLETE,
240 SFE_IPV4_EXCEPTION_EVENT_IP_OPTIONS_INCOMPLETE,
241 SFE_IPV4_EXCEPTION_EVENT_UNHANDLED_PROTOCOL,
Guduri Prathyusha79a5fee2021-11-11 17:59:10 +0530242 SFE_IPV4_EXCEPTION_EVENT_PPPOE_HEADER_ENCAP_FAILED,
Guduri Prathyusha647fe3e2021-11-22 19:17:51 +0530243 SFE_IPV4_EXCEPTION_EVENT_INVALID_PPPOE_SESSION,
244 SFE_IPV4_EXCEPTION_EVENT_INCORRECT_PPPOE_PARSING,
245 SFE_IPV4_EXCEPTION_EVENT_PPPOE_NOT_SET_IN_CME,
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530246 SFE_IPV4_EXCEPTION_EVENT_LAST
247};
248
249/*
Ratheesh Kannoth3aeb2892021-10-20 07:57:15 +0530250 * per CPU stats
251 */
252struct sfe_ipv4_stats {
253 /*
254 * Stats recorded in a sync period. These stats will be added to
255 * connection_xxx64 after a sync period.
256 */
257 u64 connection_create_requests64;
258 /* Number of IPv4 connection create requests */
259 u64 connection_create_collisions64;
260 /* Number of IPv4 connection create requests that collided with existing hash table entries */
Ratheesh Kannoth89302a72021-10-20 08:10:37 +0530261 u64 connection_create_failures64;
262 /* Number of IPv4 connection create requests that failed */
Ratheesh Kannoth3aeb2892021-10-20 07:57:15 +0530263 u64 connection_destroy_requests64;
264 /* Number of IPv4 connection destroy requests */
265 u64 connection_destroy_misses64;
266 /* Number of IPv4 connection destroy requests that missed our hash table */
267 u64 connection_match_hash_hits64;
268 /* Number of IPv4 connection match hash hits */
269 u64 connection_match_hash_reorders64;
270 /* Number of IPv4 connection match hash reorders */
271 u64 connection_flushes64; /* Number of IPv4 connection flushes */
Amitesh Anand63be37d2021-12-24 20:51:48 +0530272 u64 packets_dropped64; /* Number of IPv4 packets dropped */
Ratheesh Kannoth3aeb2892021-10-20 07:57:15 +0530273 u64 packets_forwarded64; /* Number of IPv4 packets forwarded */
274 u64 packets_not_forwarded64; /* Number of IPv4 packets not forwarded */
275 u64 exception_events64[SFE_IPV4_EXCEPTION_EVENT_LAST];
Guduri Prathyusha79a5fee2021-11-11 17:59:10 +0530276 u64 pppoe_encap_packets_forwarded64; /* Number of IPv4 PPPOE encap packets forwarded */
Guduri Prathyusha647fe3e2021-11-22 19:17:51 +0530277 u64 pppoe_decap_packets_forwarded64; /* Number of IPv4 PPPOE decap packets forwarded */
Ratheesh Kannoth3aeb2892021-10-20 07:57:15 +0530278};
279
280/*
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530281 * Per-module structure.
282 */
283struct sfe_ipv4 {
284 spinlock_t lock; /* Lock for SMP correctness */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530285 struct sfe_ipv4_connection *all_connections_head;
286 /* Head of the list of all connections */
287 struct sfe_ipv4_connection *all_connections_tail;
288 /* Tail of the list of all connections */
289 unsigned int num_connections; /* Number of connections */
Ken Zhu137722d2021-09-23 17:57:36 -0700290 struct delayed_work sync_dwork; /* Work to sync the statistics */
291 unsigned int work_cpu; /* The core to run stats sync on */
292
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530293 sfe_sync_rule_callback_t __rcu sync_rule_callback;
294 /* Callback function registered by a connection manager for stats syncing */
295 struct sfe_ipv4_connection *conn_hash[SFE_IPV4_CONNECTION_HASH_SIZE];
296 /* Connection hash table */
Ratheesh Kannoth94fc5b82021-10-20 07:45:06 +0530297
298 struct hlist_head hlist_conn_match_hash_head[SFE_IPV4_CONNECTION_HASH_SIZE];
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530299 /* Connection match hash table */
Ratheesh Kannoth94fc5b82021-10-20 07:45:06 +0530300
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530301#ifdef CONFIG_NF_FLOW_COOKIE
302 struct sfe_flow_cookie_entry sfe_flow_cookie_table[SFE_FLOW_COOKIE_SIZE];
303 /* flow cookie table*/
304 flow_cookie_set_func_t flow_cookie_set_func;
305 /* function used to configure flow cookie in hardware*/
306 int flow_cookie_enable;
307 /* Enable/disable flow cookie at runtime */
308#endif
309
Ratheesh Kannoth3aeb2892021-10-20 07:57:15 +0530310 struct sfe_ipv4_stats __percpu *stats_pcpu;
311 /* Per CPU statistics. */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530312
Ken Zhudc423672021-09-02 18:27:01 -0700313 struct sfe_ipv4_connection *wc_next; /* Connection list walk pointer for stats sync */
314
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530315 /*
316 * Control state.
317 */
Ratheesh Kannoth6307bec2021-11-25 08:26:39 +0530318 struct kobject *sys_ipv4; /* sysfs linkage */
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530319 int debug_dev; /* Major number of the debug char device */
320 u32 debug_read_seq; /* sequence number for debug dump */
321};
322
323/*
324 * Enumeration of the XML output.
325 */
326enum sfe_ipv4_debug_xml_states {
327 SFE_IPV4_DEBUG_XML_STATE_START,
328 SFE_IPV4_DEBUG_XML_STATE_CONNECTIONS_START,
329 SFE_IPV4_DEBUG_XML_STATE_CONNECTIONS_CONNECTION,
330 SFE_IPV4_DEBUG_XML_STATE_CONNECTIONS_END,
331 SFE_IPV4_DEBUG_XML_STATE_EXCEPTIONS_START,
332 SFE_IPV4_DEBUG_XML_STATE_EXCEPTIONS_EXCEPTION,
333 SFE_IPV4_DEBUG_XML_STATE_EXCEPTIONS_END,
334 SFE_IPV4_DEBUG_XML_STATE_STATS,
335 SFE_IPV4_DEBUG_XML_STATE_END,
336 SFE_IPV4_DEBUG_XML_STATE_DONE
337};
338
339/*
340 * XML write state.
341 */
342struct sfe_ipv4_debug_xml_write_state {
343 enum sfe_ipv4_debug_xml_states state;
344 /* XML output file state machine state */
345 int iter_exception; /* Next exception iterator */
346};
347
348typedef bool (*sfe_ipv4_debug_xml_write_method_t)(struct sfe_ipv4 *si, char *buffer, char *msg, size_t *length,
349 int *total_read, struct sfe_ipv4_debug_xml_write_state *ws);
350
Ratheesh Kannoth6307bec2021-11-25 08:26:39 +0530351u16 sfe_ipv4_gen_ip_csum(struct iphdr *iph);
352void sfe_ipv4_exception_stats_inc(struct sfe_ipv4 *si, enum sfe_ipv4_exception_events reason);
353bool sfe_ipv4_remove_connection(struct sfe_ipv4 *si, struct sfe_ipv4_connection *c);
354void sfe_ipv4_flush_connection(struct sfe_ipv4 *si, struct sfe_ipv4_connection *c, sfe_sync_reason_t reason);
Ken Zhu88c58152021-12-09 15:12:06 -0800355void sfe_ipv4_sync_status(struct sfe_ipv4 *si, struct sfe_ipv4_connection *c, sfe_sync_reason_t reason);
Ratheesh Kannoth6307bec2021-11-25 08:26:39 +0530356
357struct sfe_ipv4_connection_match *
358sfe_ipv4_find_connection_match_rcu(struct sfe_ipv4 *si, struct net_device *dev, u8 protocol,
359 __be32 src_ip, __be16 src_port,
360 __be32 dest_ip, __be16 dest_port);
361
Ratheesh Kannoth24fb1db2021-10-20 07:28:06 +0530362void sfe_ipv4_exit(void);
363int sfe_ipv4_init(void);