cls_api.c 28.7 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
/*
 * net/sched/cls_api.c	Packet classifier API.
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 *
 * Authors:	Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
 *
 * Changes:
 *
 * Eduardo J. Blanco <ejbs@netlabs.com.uy> :990222: kmod support
 *
 */

#include <linux/module.h>
#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/string.h>
#include <linux/errno.h>
22
#include <linux/err.h>
L
Linus Torvalds 已提交
23 24 25
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/kmod.h>
26
#include <linux/err.h>
27
#include <linux/slab.h>
28 29
#include <net/net_namespace.h>
#include <net/sock.h>
30
#include <net/netlink.h>
L
Linus Torvalds 已提交
31 32 33 34
#include <net/pkt_sched.h>
#include <net/pkt_cls.h>

/* The list of all installed classifier types */
35
static LIST_HEAD(tcf_proto_base);
L
Linus Torvalds 已提交
36 37 38 39 40 41

/* Protects list of registered TC modules. It is pure SMP lock. */
static DEFINE_RWLOCK(cls_mod_lock);

/* Find classifier type by string name */

42
static const struct tcf_proto_ops *tcf_proto_lookup_ops(const char *kind)
L
Linus Torvalds 已提交
43
{
44
	const struct tcf_proto_ops *t, *res = NULL;
L
Linus Torvalds 已提交
45 46 47

	if (kind) {
		read_lock(&cls_mod_lock);
48
		list_for_each_entry(t, &tcf_proto_base, head) {
49
			if (strcmp(kind, t->kind) == 0) {
50 51
				if (try_module_get(t->owner))
					res = t;
L
Linus Torvalds 已提交
52 53 54 55 56
				break;
			}
		}
		read_unlock(&cls_mod_lock);
	}
57
	return res;
L
Linus Torvalds 已提交
58 59 60 61 62 63
}

/* Register(unregister) new classifier type */

int register_tcf_proto_ops(struct tcf_proto_ops *ops)
{
64
	struct tcf_proto_ops *t;
L
Linus Torvalds 已提交
65 66 67
	int rc = -EEXIST;

	write_lock(&cls_mod_lock);
68
	list_for_each_entry(t, &tcf_proto_base, head)
L
Linus Torvalds 已提交
69 70 71
		if (!strcmp(ops->kind, t->kind))
			goto out;

72
	list_add_tail(&ops->head, &tcf_proto_base);
L
Linus Torvalds 已提交
73 74 75 76 77
	rc = 0;
out:
	write_unlock(&cls_mod_lock);
	return rc;
}
78
EXPORT_SYMBOL(register_tcf_proto_ops);
L
Linus Torvalds 已提交
79

80 81
static struct workqueue_struct *tc_filter_wq;

L
Linus Torvalds 已提交
82 83
int unregister_tcf_proto_ops(struct tcf_proto_ops *ops)
{
84
	struct tcf_proto_ops *t;
L
Linus Torvalds 已提交
85 86
	int rc = -ENOENT;

87 88 89 90
	/* Wait for outstanding call_rcu()s, if any, from a
	 * tcf_proto_ops's destroy() handler.
	 */
	rcu_barrier();
91
	flush_workqueue(tc_filter_wq);
92

L
Linus Torvalds 已提交
93
	write_lock(&cls_mod_lock);
94 95 96 97
	list_for_each_entry(t, &tcf_proto_base, head) {
		if (t == ops) {
			list_del(&t->head);
			rc = 0;
L
Linus Torvalds 已提交
98
			break;
99 100
		}
	}
L
Linus Torvalds 已提交
101 102 103
	write_unlock(&cls_mod_lock);
	return rc;
}
104
EXPORT_SYMBOL(unregister_tcf_proto_ops);
L
Linus Torvalds 已提交
105

106 107 108 109 110 111
bool tcf_queue_work(struct work_struct *work)
{
	return queue_work(tc_filter_wq, work);
}
EXPORT_SYMBOL(tcf_queue_work);

L
Linus Torvalds 已提交
112 113
/* Select new prio value from the range, managed by kernel. */

114
static inline u32 tcf_auto_prio(struct tcf_proto *tp)
L
Linus Torvalds 已提交
115
{
116
	u32 first = TC_H_MAKE(0xC0000000U, 0U);
L
Linus Torvalds 已提交
117 118

	if (tp)
E
Eric Dumazet 已提交
119
		first = tp->prio - 1;
L
Linus Torvalds 已提交
120

121
	return TC_H_MAJ(first);
L
Linus Torvalds 已提交
122 123
}

124
static struct tcf_proto *tcf_proto_create(const char *kind, u32 protocol,
125
					  u32 prio, u32 parent, struct Qdisc *q,
126
					  struct tcf_chain *chain)
127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161
{
	struct tcf_proto *tp;
	int err;

	tp = kzalloc(sizeof(*tp), GFP_KERNEL);
	if (!tp)
		return ERR_PTR(-ENOBUFS);

	err = -ENOENT;
	tp->ops = tcf_proto_lookup_ops(kind);
	if (!tp->ops) {
#ifdef CONFIG_MODULES
		rtnl_unlock();
		request_module("cls_%s", kind);
		rtnl_lock();
		tp->ops = tcf_proto_lookup_ops(kind);
		/* We dropped the RTNL semaphore in order to perform
		 * the module load. So, even if we succeeded in loading
		 * the module we have to replay the request. We indicate
		 * this using -EAGAIN.
		 */
		if (tp->ops) {
			module_put(tp->ops->owner);
			err = -EAGAIN;
		} else {
			err = -ENOENT;
		}
		goto errout;
#endif
	}
	tp->classify = tp->ops->classify;
	tp->protocol = protocol;
	tp->prio = prio;
	tp->classid = parent;
	tp->q = q;
162
	tp->chain = chain;
163 164 165 166 167 168 169 170 171 172 173 174 175

	err = tp->ops->init(tp);
	if (err) {
		module_put(tp->ops->owner);
		goto errout;
	}
	return tp;

errout:
	kfree(tp);
	return ERR_PTR(err);
}

176
static void tcf_proto_destroy(struct tcf_proto *tp)
177
{
178 179 180
	tp->ops->destroy(tp);
	module_put(tp->ops->owner);
	kfree_rcu(tp, rcu);
181 182
}

183 184
static struct tcf_chain *tcf_chain_create(struct tcf_block *block,
					  u32 chain_index)
185
{
186 187 188 189 190 191 192 193
	struct tcf_chain *chain;

	chain = kzalloc(sizeof(*chain), GFP_KERNEL);
	if (!chain)
		return NULL;
	list_add_tail(&chain->list, &block->chain_list);
	chain->block = block;
	chain->index = chain_index;
194
	chain->refcnt = 1;
195
	return chain;
196 197
}

J
Jiri Pirko 已提交
198
static void tcf_chain_flush(struct tcf_chain *chain)
199 200 201
{
	struct tcf_proto *tp;

202
	if (chain->p_filter_chain)
J
Jiri Pirko 已提交
203
		RCU_INIT_POINTER(*chain->p_filter_chain, NULL);
204 205
	while ((tp = rtnl_dereference(chain->filter_chain)) != NULL) {
		RCU_INIT_POINTER(chain->filter_chain, tp->next);
206
		tcf_chain_put(chain);
207
		tcf_proto_destroy(tp);
208
	}
J
Jiri Pirko 已提交
209 210 211 212
}

static void tcf_chain_destroy(struct tcf_chain *chain)
{
213 214 215
	list_del(&chain->list);
	kfree(chain);
}
216

217 218 219
static void tcf_chain_hold(struct tcf_chain *chain)
{
	++chain->refcnt;
220 221
}

222 223
struct tcf_chain *tcf_chain_get(struct tcf_block *block, u32 chain_index,
				bool create)
224 225 226 227
{
	struct tcf_chain *chain;

	list_for_each_entry(chain, &block->chain_list, list) {
228 229 230 231
		if (chain->index == chain_index) {
			tcf_chain_hold(chain);
			return chain;
		}
232
	}
233

234
	return create ? tcf_chain_create(block, chain_index) : NULL;
235 236 237 238 239
}
EXPORT_SYMBOL(tcf_chain_get);

void tcf_chain_put(struct tcf_chain *chain)
{
240
	if (--chain->refcnt == 0)
241 242 243 244
		tcf_chain_destroy(chain);
}
EXPORT_SYMBOL(tcf_chain_put);

245 246 247 248 249
static void
tcf_chain_filter_chain_ptr_set(struct tcf_chain *chain,
			       struct tcf_proto __rcu **p_filter_chain)
{
	chain->p_filter_chain = p_filter_chain;
250
}
251

252 253 254 255 256 257 258
static void tcf_block_offload_cmd(struct tcf_block *block, struct Qdisc *q,
				  struct tcf_block_ext_info *ei,
				  enum tc_block_command command)
{
	struct net_device *dev = q->dev_queue->dev;
	struct tc_block_offload bo = {};

259
	if (!dev->netdev_ops->ndo_setup_tc)
260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281
		return;
	bo.command = command;
	bo.binder_type = ei->binder_type;
	bo.block = block;
	dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_BLOCK, &bo);
}

static void tcf_block_offload_bind(struct tcf_block *block, struct Qdisc *q,
				   struct tcf_block_ext_info *ei)
{
	tcf_block_offload_cmd(block, q, ei, TC_BLOCK_BIND);
}

static void tcf_block_offload_unbind(struct tcf_block *block, struct Qdisc *q,
				     struct tcf_block_ext_info *ei)
{
	tcf_block_offload_cmd(block, q, ei, TC_BLOCK_UNBIND);
}

int tcf_block_get_ext(struct tcf_block **p_block,
		      struct tcf_proto __rcu **p_filter_chain, struct Qdisc *q,
		      struct tcf_block_ext_info *ei)
282 283
{
	struct tcf_block *block = kzalloc(sizeof(*block), GFP_KERNEL);
284
	struct tcf_chain *chain;
285
	int err;
286 287 288

	if (!block)
		return -ENOMEM;
289
	INIT_LIST_HEAD(&block->chain_list);
290 291
	INIT_LIST_HEAD(&block->cb_list);

292 293 294
	/* Create chain 0 by default, it has to be always present. */
	chain = tcf_chain_create(block, 0);
	if (!chain) {
295 296 297
		err = -ENOMEM;
		goto err_chain_create;
	}
298
	tcf_chain_filter_chain_ptr_set(chain, p_filter_chain);
299
	block->net = qdisc_net(q);
300
	block->q = q;
301
	tcf_block_offload_bind(block, q, ei);
302 303
	*p_block = block;
	return 0;
304 305 306 307

err_chain_create:
	kfree(block);
	return err;
308
}
309 310 311 312 313 314 315 316 317
EXPORT_SYMBOL(tcf_block_get_ext);

int tcf_block_get(struct tcf_block **p_block,
		  struct tcf_proto __rcu **p_filter_chain, struct Qdisc *q)
{
	struct tcf_block_ext_info ei = {0, };

	return tcf_block_get_ext(p_block, p_filter_chain, q, &ei);
}
318 319
EXPORT_SYMBOL(tcf_block_get);

320
static void tcf_block_put_final(struct work_struct *work)
321
{
322
	struct tcf_block *block = container_of(work, struct tcf_block, work);
323 324
	struct tcf_chain *chain, *tmp;

325
	rtnl_lock();
326
	/* Only chain 0 should be still here. */
327 328 329 330 331
	list_for_each_entry_safe(chain, tmp, &block->chain_list, list)
		tcf_chain_put(chain);
	rtnl_unlock();
	kfree(block);
}
332

333
/* XXX: Standalone actions are not allowed to jump to any chain, and bound
334 335
 * actions should be all removed after flushing. However, filters are now
 * destroyed in tc filter workqueue with RTNL lock, they can not race here.
336
 */
337 338 339
void tcf_block_put_ext(struct tcf_block *block,
		       struct tcf_proto __rcu **p_filter_chain, struct Qdisc *q,
		       struct tcf_block_ext_info *ei)
340
{
341
	struct tcf_chain *chain, *tmp;
342

343 344 345
	if (!block)
		return;

346
	list_for_each_entry_safe(chain, tmp, &block->chain_list, list)
347
		tcf_chain_flush(chain);
348

349 350
	tcf_block_offload_unbind(block, q, ei);

351 352 353 354 355 356 357
	INIT_WORK(&block->work, tcf_block_put_final);
	/* Wait for existing RCU callbacks to cool down, make sure their works
	 * have been queued before this. We can not flush pending works here
	 * because we are holding the RTNL lock.
	 */
	rcu_barrier();
	tcf_queue_work(&block->work);
358
}
359 360 361 362 363 364 365 366
EXPORT_SYMBOL(tcf_block_put_ext);

void tcf_block_put(struct tcf_block *block)
{
	struct tcf_block_ext_info ei = {0, };

	tcf_block_put_ext(block, NULL, block->q, &ei);
}
367

368
EXPORT_SYMBOL(tcf_block_put);
369

370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472
struct tcf_block_cb {
	struct list_head list;
	tc_setup_cb_t *cb;
	void *cb_ident;
	void *cb_priv;
	unsigned int refcnt;
};

void *tcf_block_cb_priv(struct tcf_block_cb *block_cb)
{
	return block_cb->cb_priv;
}
EXPORT_SYMBOL(tcf_block_cb_priv);

struct tcf_block_cb *tcf_block_cb_lookup(struct tcf_block *block,
					 tc_setup_cb_t *cb, void *cb_ident)
{	struct tcf_block_cb *block_cb;

	list_for_each_entry(block_cb, &block->cb_list, list)
		if (block_cb->cb == cb && block_cb->cb_ident == cb_ident)
			return block_cb;
	return NULL;
}
EXPORT_SYMBOL(tcf_block_cb_lookup);

void tcf_block_cb_incref(struct tcf_block_cb *block_cb)
{
	block_cb->refcnt++;
}
EXPORT_SYMBOL(tcf_block_cb_incref);

unsigned int tcf_block_cb_decref(struct tcf_block_cb *block_cb)
{
	return --block_cb->refcnt;
}
EXPORT_SYMBOL(tcf_block_cb_decref);

struct tcf_block_cb *__tcf_block_cb_register(struct tcf_block *block,
					     tc_setup_cb_t *cb, void *cb_ident,
					     void *cb_priv)
{
	struct tcf_block_cb *block_cb;

	block_cb = kzalloc(sizeof(*block_cb), GFP_KERNEL);
	if (!block_cb)
		return NULL;
	block_cb->cb = cb;
	block_cb->cb_ident = cb_ident;
	block_cb->cb_priv = cb_priv;
	list_add(&block_cb->list, &block->cb_list);
	return block_cb;
}
EXPORT_SYMBOL(__tcf_block_cb_register);

int tcf_block_cb_register(struct tcf_block *block,
			  tc_setup_cb_t *cb, void *cb_ident,
			  void *cb_priv)
{
	struct tcf_block_cb *block_cb;

	block_cb = __tcf_block_cb_register(block, cb, cb_ident, cb_priv);
	return block_cb ? 0 : -ENOMEM;
}
EXPORT_SYMBOL(tcf_block_cb_register);

void __tcf_block_cb_unregister(struct tcf_block_cb *block_cb)
{
	list_del(&block_cb->list);
	kfree(block_cb);
}
EXPORT_SYMBOL(__tcf_block_cb_unregister);

void tcf_block_cb_unregister(struct tcf_block *block,
			     tc_setup_cb_t *cb, void *cb_ident)
{
	struct tcf_block_cb *block_cb;

	block_cb = tcf_block_cb_lookup(block, cb, cb_ident);
	if (!block_cb)
		return;
	__tcf_block_cb_unregister(block_cb);
}
EXPORT_SYMBOL(tcf_block_cb_unregister);

static int tcf_block_cb_call(struct tcf_block *block, enum tc_setup_type type,
			     void *type_data, bool err_stop)
{
	struct tcf_block_cb *block_cb;
	int ok_count = 0;
	int err;

	list_for_each_entry(block_cb, &block->cb_list, list) {
		err = block_cb->cb(type, type_data, block_cb->cb_priv);
		if (err) {
			if (err_stop)
				return err;
		} else {
			ok_count++;
		}
	}
	return ok_count;
}

473 474 475 476 477 478 479 480 481 482
/* Main classifier routine: scans classifier chain attached
 * to this qdisc, (optionally) tests for protocol and asks
 * specific classifiers.
 */
int tcf_classify(struct sk_buff *skb, const struct tcf_proto *tp,
		 struct tcf_result *res, bool compat_mode)
{
	__be16 protocol = tc_skb_protocol(skb);
#ifdef CONFIG_NET_CLS_ACT
	const int max_reclassify_loop = 4;
483 484
	const struct tcf_proto *orig_tp = tp;
	const struct tcf_proto *first_tp;
485 486 487 488 489 490 491 492 493 494 495 496 497
	int limit = 0;

reclassify:
#endif
	for (; tp; tp = rcu_dereference_bh(tp->next)) {
		int err;

		if (tp->protocol != protocol &&
		    tp->protocol != htons(ETH_P_ALL))
			continue;

		err = tp->classify(skb, tp, res);
#ifdef CONFIG_NET_CLS_ACT
498
		if (unlikely(err == TC_ACT_RECLASSIFY && !compat_mode)) {
499
			first_tp = orig_tp;
500
			goto reset;
501
		} else if (unlikely(TC_ACT_EXT_CMP(err, TC_ACT_GOTO_CHAIN))) {
502
			first_tp = res->goto_tp;
503 504
			goto reset;
		}
505 506 507 508 509 510 511 512 513 514 515 516 517 518 519
#endif
		if (err >= 0)
			return err;
	}

	return TC_ACT_UNSPEC; /* signal: continue lookup */
#ifdef CONFIG_NET_CLS_ACT
reset:
	if (unlikely(limit++ >= max_reclassify_loop)) {
		net_notice_ratelimited("%s: reclassify loop, rule prio %u, protocol %02x\n",
				       tp->q->ops->id, tp->prio & 0xffff,
				       ntohs(tp->protocol));
		return TC_ACT_SHOT;
	}

520
	tp = first_tp;
521 522 523 524 525 526
	protocol = tc_skb_protocol(skb);
	goto reclassify;
#endif
}
EXPORT_SYMBOL(tcf_classify);

527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542
struct tcf_chain_info {
	struct tcf_proto __rcu **pprev;
	struct tcf_proto __rcu *next;
};

static struct tcf_proto *tcf_chain_tp_prev(struct tcf_chain_info *chain_info)
{
	return rtnl_dereference(*chain_info->pprev);
}

static void tcf_chain_tp_insert(struct tcf_chain *chain,
				struct tcf_chain_info *chain_info,
				struct tcf_proto *tp)
{
	if (chain->p_filter_chain &&
	    *chain_info->pprev == chain->filter_chain)
543
		rcu_assign_pointer(*chain->p_filter_chain, tp);
544 545
	RCU_INIT_POINTER(tp->next, tcf_chain_tp_prev(chain_info));
	rcu_assign_pointer(*chain_info->pprev, tp);
546
	tcf_chain_hold(chain);
547 548 549 550 551 552 553 554 555
}

static void tcf_chain_tp_remove(struct tcf_chain *chain,
				struct tcf_chain_info *chain_info,
				struct tcf_proto *tp)
{
	struct tcf_proto *next = rtnl_dereference(chain_info->next);

	if (chain->p_filter_chain && tp == chain->filter_chain)
556
		RCU_INIT_POINTER(*chain->p_filter_chain, next);
557
	RCU_INIT_POINTER(*chain_info->pprev, next);
558
	tcf_chain_put(chain);
559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587
}

static struct tcf_proto *tcf_chain_tp_find(struct tcf_chain *chain,
					   struct tcf_chain_info *chain_info,
					   u32 protocol, u32 prio,
					   bool prio_allocate)
{
	struct tcf_proto **pprev;
	struct tcf_proto *tp;

	/* Check the chain for existence of proto-tcf with this priority */
	for (pprev = &chain->filter_chain;
	     (tp = rtnl_dereference(*pprev)); pprev = &tp->next) {
		if (tp->prio >= prio) {
			if (tp->prio == prio) {
				if (prio_allocate ||
				    (tp->protocol != protocol && protocol))
					return ERR_PTR(-EINVAL);
			} else {
				tp = NULL;
			}
			break;
		}
	}
	chain_info->pprev = pprev;
	chain_info->next = tp ? tp->next : NULL;
	return tp;
}

588
static int tcf_fill_node(struct net *net, struct sk_buff *skb,
589 590
			 struct tcf_proto *tp, struct Qdisc *q, u32 parent,
			 void *fh, u32 portid, u32 seq, u16 flags, int event)
591 592 593 594 595 596 597 598 599 600 601 602
{
	struct tcmsg *tcm;
	struct nlmsghdr  *nlh;
	unsigned char *b = skb_tail_pointer(skb);

	nlh = nlmsg_put(skb, portid, seq, event, sizeof(*tcm), flags);
	if (!nlh)
		goto out_nlmsg_trim;
	tcm = nlmsg_data(nlh);
	tcm->tcm_family = AF_UNSPEC;
	tcm->tcm__pad1 = 0;
	tcm->tcm__pad2 = 0;
603 604
	tcm->tcm_ifindex = qdisc_dev(q)->ifindex;
	tcm->tcm_parent = parent;
605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626
	tcm->tcm_info = TC_H_MAKE(tp->prio, tp->protocol);
	if (nla_put_string(skb, TCA_KIND, tp->ops->kind))
		goto nla_put_failure;
	if (nla_put_u32(skb, TCA_CHAIN, tp->chain->index))
		goto nla_put_failure;
	if (!fh) {
		tcm->tcm_handle = 0;
	} else {
		if (tp->ops->dump && tp->ops->dump(net, tp, fh, skb, tcm) < 0)
			goto nla_put_failure;
	}
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
	return skb->len;

out_nlmsg_trim:
nla_put_failure:
	nlmsg_trim(skb, b);
	return -1;
}

static int tfilter_notify(struct net *net, struct sk_buff *oskb,
			  struct nlmsghdr *n, struct tcf_proto *tp,
627
			  struct Qdisc *q, u32 parent,
628 629 630 631 632 633 634 635 636
			  void *fh, int event, bool unicast)
{
	struct sk_buff *skb;
	u32 portid = oskb ? NETLINK_CB(oskb).portid : 0;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;

637
	if (tcf_fill_node(net, skb, tp, q, parent, fh, portid, n->nlmsg_seq,
638 639 640 641 642 643 644 645 646 647 648 649 650 651
			  n->nlmsg_flags, event) <= 0) {
		kfree_skb(skb);
		return -EINVAL;
	}

	if (unicast)
		return netlink_unicast(net->rtnl, skb, portid, MSG_DONTWAIT);

	return rtnetlink_send(skb, net, portid, RTNLGRP_TC,
			      n->nlmsg_flags & NLM_F_ECHO);
}

static int tfilter_del_notify(struct net *net, struct sk_buff *oskb,
			      struct nlmsghdr *n, struct tcf_proto *tp,
652
			      struct Qdisc *q, u32 parent,
653 654 655 656 657 658 659 660 661 662
			      void *fh, bool unicast, bool *last)
{
	struct sk_buff *skb;
	u32 portid = oskb ? NETLINK_CB(oskb).portid : 0;
	int err;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;

663
	if (tcf_fill_node(net, skb, tp, q, parent, fh, portid, n->nlmsg_seq,
664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682
			  n->nlmsg_flags, RTM_DELTFILTER) <= 0) {
		kfree_skb(skb);
		return -EINVAL;
	}

	err = tp->ops->delete(tp, fh, last);
	if (err) {
		kfree_skb(skb);
		return err;
	}

	if (unicast)
		return netlink_unicast(net->rtnl, skb, portid, MSG_DONTWAIT);

	return rtnetlink_send(skb, net, portid, RTNLGRP_TC,
			      n->nlmsg_flags & NLM_F_ECHO);
}

static void tfilter_notify_chain(struct net *net, struct sk_buff *oskb,
683
				 struct Qdisc *q, u32 parent,
684 685 686 687 688 689 690
				 struct nlmsghdr *n,
				 struct tcf_chain *chain, int event)
{
	struct tcf_proto *tp;

	for (tp = rtnl_dereference(chain->filter_chain);
	     tp; tp = rtnl_dereference(tp->next))
691
		tfilter_notify(net, oskb, n, tp, q, parent, 0, event, false);
692 693
}

L
Linus Torvalds 已提交
694 695
/* Add/change/delete/get a filter node */

696 697
static int tc_ctl_tfilter(struct sk_buff *skb, struct nlmsghdr *n,
			  struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
698
{
699
	struct net *net = sock_net(skb->sk);
700
	struct nlattr *tca[TCA_MAX + 1];
L
Linus Torvalds 已提交
701 702 703
	struct tcmsg *t;
	u32 protocol;
	u32 prio;
704
	bool prio_allocate;
L
Linus Torvalds 已提交
705
	u32 parent;
706
	u32 chain_index;
L
Linus Torvalds 已提交
707 708
	struct net_device *dev;
	struct Qdisc  *q;
709
	struct tcf_chain_info chain_info;
710
	struct tcf_chain *chain = NULL;
711
	struct tcf_block *block;
L
Linus Torvalds 已提交
712
	struct tcf_proto *tp;
713
	const struct Qdisc_class_ops *cops;
L
Linus Torvalds 已提交
714
	unsigned long cl;
715
	void *fh;
L
Linus Torvalds 已提交
716
	int err;
717
	int tp_created;
L
Linus Torvalds 已提交
718

719
	if ((n->nlmsg_type != RTM_GETTFILTER) &&
720
	    !netlink_ns_capable(skb, net->user_ns, CAP_NET_ADMIN))
721
		return -EPERM;
722

L
Linus Torvalds 已提交
723
replay:
724 725
	tp_created = 0;

726
	err = nlmsg_parse(n, sizeof(*t), tca, TCA_MAX, NULL, extack);
727 728 729
	if (err < 0)
		return err;

730
	t = nlmsg_data(n);
L
Linus Torvalds 已提交
731 732
	protocol = TC_H_MIN(t->tcm_info);
	prio = TC_H_MAJ(t->tcm_info);
733
	prio_allocate = false;
L
Linus Torvalds 已提交
734 735 736 737
	parent = t->tcm_parent;
	cl = 0;

	if (prio == 0) {
738 739
		switch (n->nlmsg_type) {
		case RTM_DELTFILTER:
740
			if (protocol || t->tcm_handle || tca[TCA_KIND])
741 742 743 744 745 746 747 748
				return -ENOENT;
			break;
		case RTM_NEWTFILTER:
			/* If no priority is provided by the user,
			 * we allocate one.
			 */
			if (n->nlmsg_flags & NLM_F_CREATE) {
				prio = TC_H_MAKE(0x80000000U, 0U);
749
				prio_allocate = true;
750 751 752 753
				break;
			}
			/* fall-through */
		default:
L
Linus Torvalds 已提交
754
			return -ENOENT;
755
		}
L
Linus Torvalds 已提交
756 757 758 759 760
	}

	/* Find head of filter chain. */

	/* Find link */
761
	dev = __dev_get_by_index(net, t->tcm_ifindex);
762
	if (dev == NULL)
L
Linus Torvalds 已提交
763 764 765 766
		return -ENODEV;

	/* Find qdisc */
	if (!parent) {
767
		q = dev->qdisc;
L
Linus Torvalds 已提交
768
		parent = q->handle;
769 770 771 772 773
	} else {
		q = qdisc_lookup(dev, TC_H_MAJ(t->tcm_parent));
		if (q == NULL)
			return -EINVAL;
	}
L
Linus Torvalds 已提交
774 775

	/* Is it classful? */
E
Eric Dumazet 已提交
776 777
	cops = q->ops->cl_ops;
	if (!cops)
L
Linus Torvalds 已提交
778 779
		return -EINVAL;

780
	if (!cops->tcf_block)
781 782
		return -EOPNOTSUPP;

L
Linus Torvalds 已提交
783 784
	/* Do we search for filter, attached to class? */
	if (TC_H_MIN(parent)) {
785
		cl = cops->find(q, parent);
L
Linus Torvalds 已提交
786 787 788 789 790
		if (cl == 0)
			return -ENOENT;
	}

	/* And the last stroke */
791 792
	block = cops->tcf_block(q, cl);
	if (!block) {
793
		err = -EINVAL;
L
Linus Torvalds 已提交
794
		goto errout;
795
	}
796 797 798 799 800 801

	chain_index = tca[TCA_CHAIN] ? nla_get_u32(tca[TCA_CHAIN]) : 0;
	if (chain_index > TC_ACT_EXT_VAL_MASK) {
		err = -EINVAL;
		goto errout;
	}
802 803
	chain = tcf_chain_get(block, chain_index,
			      n->nlmsg_type == RTM_NEWTFILTER);
804
	if (!chain) {
805
		err = n->nlmsg_type == RTM_NEWTFILTER ? -ENOMEM : -EINVAL;
806 807
		goto errout;
	}
808

809
	if (n->nlmsg_type == RTM_DELTFILTER && prio == 0) {
810 811
		tfilter_notify_chain(net, skb, q, parent, n,
				     chain, RTM_DELTFILTER);
J
Jiri Pirko 已提交
812
		tcf_chain_flush(chain);
813 814 815
		err = 0;
		goto errout;
	}
L
Linus Torvalds 已提交
816

817 818 819 820 821
	tp = tcf_chain_tp_find(chain, &chain_info, protocol,
			       prio, prio_allocate);
	if (IS_ERR(tp)) {
		err = PTR_ERR(tp);
		goto errout;
L
Linus Torvalds 已提交
822 823 824 825 826
	}

	if (tp == NULL) {
		/* Proto-tcf does not exist, create new one */

827 828
		if (tca[TCA_KIND] == NULL || !protocol) {
			err = -EINVAL;
L
Linus Torvalds 已提交
829
			goto errout;
830
		}
L
Linus Torvalds 已提交
831

E
Eric Dumazet 已提交
832
		if (n->nlmsg_type != RTM_NEWTFILTER ||
833 834
		    !(n->nlmsg_flags & NLM_F_CREATE)) {
			err = -ENOENT;
L
Linus Torvalds 已提交
835
			goto errout;
836
		}
L
Linus Torvalds 已提交
837

838
		if (prio_allocate)
839
			prio = tcf_auto_prio(tcf_chain_tp_prev(&chain_info));
L
Linus Torvalds 已提交
840

841
		tp = tcf_proto_create(nla_data(tca[TCA_KIND]),
842
				      protocol, prio, parent, q, chain);
843 844
		if (IS_ERR(tp)) {
			err = PTR_ERR(tp);
L
Linus Torvalds 已提交
845 846
			goto errout;
		}
847
		tp_created = 1;
848 849
	} else if (tca[TCA_KIND] && nla_strcmp(tca[TCA_KIND], tp->ops->kind)) {
		err = -EINVAL;
L
Linus Torvalds 已提交
850
		goto errout;
851
	}
L
Linus Torvalds 已提交
852 853 854

	fh = tp->ops->get(tp, t->tcm_handle);

855
	if (!fh) {
L
Linus Torvalds 已提交
856
		if (n->nlmsg_type == RTM_DELTFILTER && t->tcm_handle == 0) {
857
			tcf_chain_tp_remove(chain, &chain_info, tp);
858
			tfilter_notify(net, skb, n, tp, q, parent, fh,
859
				       RTM_DELTFILTER, false);
860
			tcf_proto_destroy(tp);
L
Linus Torvalds 已提交
861 862 863 864
			err = 0;
			goto errout;
		}

865
		if (n->nlmsg_type != RTM_NEWTFILTER ||
866 867
		    !(n->nlmsg_flags & NLM_F_CREATE)) {
			err = -ENOENT;
L
Linus Torvalds 已提交
868
			goto errout;
869
		}
L
Linus Torvalds 已提交
870
	} else {
871 872
		bool last;

L
Linus Torvalds 已提交
873
		switch (n->nlmsg_type) {
874
		case RTM_NEWTFILTER:
875 876
			if (n->nlmsg_flags & NLM_F_EXCL) {
				if (tp_created)
877
					tcf_proto_destroy(tp);
878
				err = -EEXIST;
L
Linus Torvalds 已提交
879
				goto errout;
880
			}
L
Linus Torvalds 已提交
881 882
			break;
		case RTM_DELTFILTER:
883 884
			err = tfilter_del_notify(net, skb, n, tp, q, parent,
						 fh, false, &last);
885 886
			if (err)
				goto errout;
887
			if (last) {
888
				tcf_chain_tp_remove(chain, &chain_info, tp);
889 890
				tcf_proto_destroy(tp);
			}
891
			goto errout;
L
Linus Torvalds 已提交
892
		case RTM_GETTFILTER:
893
			err = tfilter_notify(net, skb, n, tp, q, parent, fh,
894
					     RTM_NEWTFILTER, true);
L
Linus Torvalds 已提交
895 896 897 898 899 900 901
			goto errout;
		default:
			err = -EINVAL;
			goto errout;
		}
	}

902 903
	err = tp->ops->change(net, skb, tp, cl, t->tcm_handle, tca, &fh,
			      n->nlmsg_flags & NLM_F_CREATE ? TCA_ACT_NOREPLACE : TCA_ACT_REPLACE);
904
	if (err == 0) {
905 906
		if (tp_created)
			tcf_chain_tp_insert(chain, &chain_info, tp);
907 908
		tfilter_notify(net, skb, n, tp, q, parent, fh,
			       RTM_NEWTFILTER, false);
909 910
	} else {
		if (tp_created)
911
			tcf_proto_destroy(tp);
912
	}
L
Linus Torvalds 已提交
913 914

errout:
915 916
	if (chain)
		tcf_chain_put(chain);
L
Linus Torvalds 已提交
917 918 919 920 921 922
	if (err == -EAGAIN)
		/* Replay the request. */
		goto replay;
	return err;
}

923
struct tcf_dump_args {
L
Linus Torvalds 已提交
924 925 926
	struct tcf_walker w;
	struct sk_buff *skb;
	struct netlink_callback *cb;
927 928
	struct Qdisc *q;
	u32 parent;
L
Linus Torvalds 已提交
929 930
};

931
static int tcf_node_dump(struct tcf_proto *tp, void *n, struct tcf_walker *arg)
L
Linus Torvalds 已提交
932
{
933
	struct tcf_dump_args *a = (void *)arg;
934
	struct net *net = sock_net(a->skb->sk);
L
Linus Torvalds 已提交
935

936 937
	return tcf_fill_node(net, a->skb, tp, a->q, a->parent,
			     n, NETLINK_CB(a->cb->skb).portid,
J
Jamal Hadi Salim 已提交
938 939
			     a->cb->nlh->nlmsg_seq, NLM_F_MULTI,
			     RTM_NEWTFILTER);
L
Linus Torvalds 已提交
940 941
}

942 943
static bool tcf_chain_dump(struct tcf_chain *chain, struct Qdisc *q, u32 parent,
			   struct sk_buff *skb, struct netlink_callback *cb,
944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964
			   long index_start, long *p_index)
{
	struct net *net = sock_net(skb->sk);
	struct tcmsg *tcm = nlmsg_data(cb->nlh);
	struct tcf_dump_args arg;
	struct tcf_proto *tp;

	for (tp = rtnl_dereference(chain->filter_chain);
	     tp; tp = rtnl_dereference(tp->next), (*p_index)++) {
		if (*p_index < index_start)
			continue;
		if (TC_H_MAJ(tcm->tcm_info) &&
		    TC_H_MAJ(tcm->tcm_info) != tp->prio)
			continue;
		if (TC_H_MIN(tcm->tcm_info) &&
		    TC_H_MIN(tcm->tcm_info) != tp->protocol)
			continue;
		if (*p_index > index_start)
			memset(&cb->args[1], 0,
			       sizeof(cb->args) - sizeof(cb->args[0]));
		if (cb->args[1] == 0) {
965
			if (tcf_fill_node(net, skb, tp, q, parent, 0,
966 967 968
					  NETLINK_CB(cb->skb).portid,
					  cb->nlh->nlmsg_seq, NLM_F_MULTI,
					  RTM_NEWTFILTER) <= 0)
969
				return false;
970 971 972 973 974 975 976 977

			cb->args[1] = 1;
		}
		if (!tp->ops->walk)
			continue;
		arg.w.fn = tcf_node_dump;
		arg.skb = skb;
		arg.cb = cb;
978 979
		arg.q = q;
		arg.parent = parent;
980 981 982 983 984 985
		arg.w.stop = 0;
		arg.w.skip = cb->args[1] - 1;
		arg.w.count = 0;
		tp->ops->walk(tp, &arg.w);
		cb->args[1] = arg.w.count + 1;
		if (arg.w.stop)
986
			return false;
987
	}
988
	return true;
989 990
}

E
Eric Dumazet 已提交
991
/* called with RTNL */
L
Linus Torvalds 已提交
992 993
static int tc_dump_tfilter(struct sk_buff *skb, struct netlink_callback *cb)
{
994
	struct net *net = sock_net(skb->sk);
995
	struct nlattr *tca[TCA_MAX + 1];
L
Linus Torvalds 已提交
996 997
	struct net_device *dev;
	struct Qdisc *q;
998
	struct tcf_block *block;
999
	struct tcf_chain *chain;
1000
	struct tcmsg *tcm = nlmsg_data(cb->nlh);
L
Linus Torvalds 已提交
1001
	unsigned long cl = 0;
1002
	const struct Qdisc_class_ops *cops;
1003 1004
	long index_start;
	long index;
1005
	u32 parent;
1006
	int err;
L
Linus Torvalds 已提交
1007

1008
	if (nlmsg_len(cb->nlh) < sizeof(*tcm))
L
Linus Torvalds 已提交
1009
		return skb->len;
1010 1011 1012 1013 1014

	err = nlmsg_parse(cb->nlh, sizeof(*tcm), tca, TCA_MAX, NULL, NULL);
	if (err)
		return err;

E
Eric Dumazet 已提交
1015 1016
	dev = __dev_get_by_index(net, tcm->tcm_ifindex);
	if (!dev)
L
Linus Torvalds 已提交
1017 1018
		return skb->len;

1019 1020
	parent = tcm->tcm_parent;
	if (!parent) {
1021
		q = dev->qdisc;
1022 1023
		parent = q->handle;
	} else {
L
Linus Torvalds 已提交
1024
		q = qdisc_lookup(dev, TC_H_MAJ(tcm->tcm_parent));
1025
	}
L
Linus Torvalds 已提交
1026 1027
	if (!q)
		goto out;
E
Eric Dumazet 已提交
1028 1029
	cops = q->ops->cl_ops;
	if (!cops)
1030
		goto out;
1031
	if (!cops->tcf_block)
1032
		goto out;
L
Linus Torvalds 已提交
1033
	if (TC_H_MIN(tcm->tcm_parent)) {
1034
		cl = cops->find(q, tcm->tcm_parent);
L
Linus Torvalds 已提交
1035
		if (cl == 0)
1036
			goto out;
L
Linus Torvalds 已提交
1037
	}
1038 1039
	block = cops->tcf_block(q, cl);
	if (!block)
1040
		goto out;
L
Linus Torvalds 已提交
1041

1042 1043
	index_start = cb->args[0];
	index = 0;
1044 1045 1046 1047 1048

	list_for_each_entry(chain, &block->chain_list, list) {
		if (tca[TCA_CHAIN] &&
		    nla_get_u32(tca[TCA_CHAIN]) != chain->index)
			continue;
1049 1050
		if (!tcf_chain_dump(chain, q, parent, skb, cb,
				    index_start, &index))
1051 1052 1053
			break;
	}

1054
	cb->args[0] = index;
L
Linus Torvalds 已提交
1055 1056 1057 1058 1059

out:
	return skb->len;
}

1060
void tcf_exts_destroy(struct tcf_exts *exts)
L
Linus Torvalds 已提交
1061 1062
{
#ifdef CONFIG_NET_CLS_ACT
1063 1064
	LIST_HEAD(actions);

1065
	ASSERT_RTNL();
1066 1067 1068 1069
	tcf_exts_to_list(exts, &actions);
	tcf_action_destroy(&actions, TCA_ACT_UNBIND);
	kfree(exts->actions);
	exts->nr_actions = 0;
L
Linus Torvalds 已提交
1070 1071
#endif
}
1072
EXPORT_SYMBOL(tcf_exts_destroy);
L
Linus Torvalds 已提交
1073

1074
int tcf_exts_validate(struct net *net, struct tcf_proto *tp, struct nlattr **tb,
J
Jamal Hadi Salim 已提交
1075
		      struct nlattr *rate_tlv, struct tcf_exts *exts, bool ovr)
L
Linus Torvalds 已提交
1076 1077 1078 1079 1080
{
#ifdef CONFIG_NET_CLS_ACT
	{
		struct tc_action *act;

1081
		if (exts->police && tb[exts->police]) {
1082 1083 1084
			act = tcf_action_init_1(net, tp, tb[exts->police],
						rate_tlv, "police", ovr,
						TCA_ACT_BIND);
1085 1086
			if (IS_ERR(act))
				return PTR_ERR(act);
L
Linus Torvalds 已提交
1087

1088
			act->type = exts->type = TCA_OLD_COMPAT;
1089 1090
			exts->actions[0] = act;
			exts->nr_actions = 1;
1091
		} else if (exts->action && tb[exts->action]) {
1092 1093 1094
			LIST_HEAD(actions);
			int err, i = 0;

1095 1096
			err = tcf_action_init(net, tp, tb[exts->action],
					      rate_tlv, NULL, ovr, TCA_ACT_BIND,
J
Jamal Hadi Salim 已提交
1097
					      &actions);
1098 1099
			if (err)
				return err;
1100 1101 1102
			list_for_each_entry(act, &actions, list)
				exts->actions[i++] = act;
			exts->nr_actions = i;
L
Linus Torvalds 已提交
1103 1104 1105
		}
	}
#else
1106 1107
	if ((exts->action && tb[exts->action]) ||
	    (exts->police && tb[exts->police]))
L
Linus Torvalds 已提交
1108 1109 1110 1111 1112
		return -EOPNOTSUPP;
#endif

	return 0;
}
1113
EXPORT_SYMBOL(tcf_exts_validate);
L
Linus Torvalds 已提交
1114

1115
void tcf_exts_change(struct tcf_exts *dst, struct tcf_exts *src)
L
Linus Torvalds 已提交
1116 1117
{
#ifdef CONFIG_NET_CLS_ACT
1118 1119
	struct tcf_exts old = *dst;

1120
	*dst = *src;
1121
	tcf_exts_destroy(&old);
L
Linus Torvalds 已提交
1122 1123
#endif
}
1124
EXPORT_SYMBOL(tcf_exts_change);
L
Linus Torvalds 已提交
1125

1126 1127 1128 1129 1130 1131 1132 1133 1134
#ifdef CONFIG_NET_CLS_ACT
static struct tc_action *tcf_exts_first_act(struct tcf_exts *exts)
{
	if (exts->nr_actions == 0)
		return NULL;
	else
		return exts->actions[0];
}
#endif
1135

1136
int tcf_exts_dump(struct sk_buff *skb, struct tcf_exts *exts)
L
Linus Torvalds 已提交
1137 1138
{
#ifdef CONFIG_NET_CLS_ACT
1139 1140
	struct nlattr *nest;

1141
	if (exts->action && tcf_exts_has_actions(exts)) {
L
Linus Torvalds 已提交
1142 1143 1144 1145 1146
		/*
		 * again for backward compatible mode - we want
		 * to work with both old and new modes of entering
		 * tc data even if iproute2  was newer - jhs
		 */
1147
		if (exts->type != TCA_OLD_COMPAT) {
1148 1149
			LIST_HEAD(actions);

1150
			nest = nla_nest_start(skb, exts->action);
1151 1152
			if (nest == NULL)
				goto nla_put_failure;
1153 1154 1155

			tcf_exts_to_list(exts, &actions);
			if (tcf_action_dump(skb, &actions, 0, 0) < 0)
1156
				goto nla_put_failure;
1157
			nla_nest_end(skb, nest);
1158
		} else if (exts->police) {
1159
			struct tc_action *act = tcf_exts_first_act(exts);
1160
			nest = nla_nest_start(skb, exts->police);
1161
			if (nest == NULL || !act)
1162
				goto nla_put_failure;
1163
			if (tcf_action_dump_old(skb, act, 0, 0) < 0)
1164
				goto nla_put_failure;
1165
			nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
1166 1167 1168
		}
	}
	return 0;
1169 1170 1171

nla_put_failure:
	nla_nest_cancel(skb, nest);
L
Linus Torvalds 已提交
1172
	return -1;
1173 1174 1175
#else
	return 0;
#endif
L
Linus Torvalds 已提交
1176
}
1177
EXPORT_SYMBOL(tcf_exts_dump);
L
Linus Torvalds 已提交
1178

1179

1180
int tcf_exts_dump_stats(struct sk_buff *skb, struct tcf_exts *exts)
L
Linus Torvalds 已提交
1181 1182
{
#ifdef CONFIG_NET_CLS_ACT
1183
	struct tc_action *a = tcf_exts_first_act(exts);
1184
	if (a != NULL && tcf_action_copy_stats(skb, a, 1) < 0)
1185
		return -1;
L
Linus Torvalds 已提交
1186 1187 1188
#endif
	return 0;
}
1189
EXPORT_SYMBOL(tcf_exts_dump_stats);
L
Linus Torvalds 已提交
1190

1191 1192 1193
static int tc_exts_setup_cb_egdev_call(struct tcf_exts *exts,
				       enum tc_setup_type type,
				       void *type_data, bool err_stop)
1194 1195 1196 1197 1198
{
	int ok_count = 0;
#ifdef CONFIG_NET_CLS_ACT
	const struct tc_action *a;
	struct net_device *dev;
1199
	int i, ret;
1200 1201 1202 1203

	if (!tcf_exts_has_actions(exts))
		return 0;

1204 1205
	for (i = 0; i < exts->nr_actions; i++) {
		a = exts->actions[i];
1206 1207 1208
		if (!a->ops->get_dev)
			continue;
		dev = a->ops->get_dev(a);
1209
		if (!dev)
1210 1211 1212 1213 1214 1215 1216 1217 1218
			continue;
		ret = tc_setup_cb_egdev_call(dev, type, type_data, err_stop);
		if (ret < 0)
			return ret;
		ok_count += ret;
	}
#endif
	return ok_count;
}
1219

1220 1221
int tc_setup_cb_call(struct tcf_block *block, struct tcf_exts *exts,
		     enum tc_setup_type type, void *type_data, bool err_stop)
1222
{
1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238
	int ok_count;
	int ret;

	ret = tcf_block_cb_call(block, type, type_data, err_stop);
	if (ret < 0)
		return ret;
	ok_count = ret;

	if (!exts)
		return ok_count;
	ret = tc_exts_setup_cb_egdev_call(exts, type, type_data, err_stop);
	if (ret < 0)
		return ret;
	ok_count += ret;

	return ok_count;
1239 1240
}
EXPORT_SYMBOL(tc_setup_cb_call);
1241

L
Linus Torvalds 已提交
1242 1243
static int __init tc_filter_init(void)
{
1244 1245 1246 1247
	tc_filter_wq = alloc_ordered_workqueue("tc_filter_workqueue", 0);
	if (!tc_filter_wq)
		return -ENOMEM;

1248 1249
	rtnl_register(PF_UNSPEC, RTM_NEWTFILTER, tc_ctl_tfilter, NULL, 0);
	rtnl_register(PF_UNSPEC, RTM_DELTFILTER, tc_ctl_tfilter, NULL, 0);
1250
	rtnl_register(PF_UNSPEC, RTM_GETTFILTER, tc_ctl_tfilter,
1251
		      tc_dump_tfilter, 0);
L
Linus Torvalds 已提交
1252 1253 1254 1255 1256

	return 0;
}

subsys_initcall(tc_filter_init);