br_forward.c 6.9 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13
/*
 *	Forwarding decision
 *	Linux ethernet bridge
 *
 *	Authors:
 *	Lennert Buytenhek		<buytenh@gnu.org>
 *
 *	This program is free software; you can redistribute it and/or
 *	modify it under the terms of the GNU General Public License
 *	as published by the Free Software Foundation; either version
 *	2 of the License, or (at your option) any later version.
 */

14
#include <linux/err.h>
15
#include <linux/slab.h>
L
Linus Torvalds 已提交
16 17
#include <linux/kernel.h>
#include <linux/netdevice.h>
W
WANG Cong 已提交
18
#include <linux/netpoll.h>
L
Linus Torvalds 已提交
19
#include <linux/skbuff.h>
20
#include <linux/if_vlan.h>
L
Linus Torvalds 已提交
21 22 23
#include <linux/netfilter_bridge.h>
#include "br_private.h"

24 25
static int deliver_clone(const struct net_bridge_port *prev,
			 struct sk_buff *skb,
26 27 28
			 void (*__packet_hook)(const struct net_bridge_port *p,
					       struct sk_buff *skb));

T
tanxiaojun 已提交
29
/* Don't forward packets to originating port or forwarding disabled */
30
static inline int should_deliver(const struct net_bridge_port *p,
L
Linus Torvalds 已提交
31 32
				 const struct sk_buff *skb)
{
33
	return ((p->flags & BR_HAIRPIN_MODE) || skb->dev != p->dev) &&
34
		br_allowed_egress(p->br, nbp_get_vlan_info(p), skb) &&
35
		p->state == BR_STATE_FORWARDING;
L
Linus Torvalds 已提交
36 37
}

38
int br_dev_queue_push_xmit(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
39
{
40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55
	if (!is_skb_forwardable(skb->dev, skb))
		goto drop;

	skb_push(skb, ETH_HLEN);
	br_drop_fake_rtable(skb);
	skb_sender_cpu_clear(skb);

	if (skb->ip_summed == CHECKSUM_PARTIAL &&
	    (skb->protocol == htons(ETH_P_8021Q) ||
	     skb->protocol == htons(ETH_P_8021AD))) {
		int depth;

		if (!__vlan_get_protocol(skb, skb->protocol, &depth))
			goto drop;

		skb_set_network_header(skb, depth);
L
Linus Torvalds 已提交
56 57
	}

58 59 60 61 62 63
	dev_queue_xmit(skb);

	return 0;

drop:
	kfree_skb(skb);
L
Linus Torvalds 已提交
64 65
	return 0;
}
66
EXPORT_SYMBOL_GPL(br_dev_queue_push_xmit);
L
Linus Torvalds 已提交
67

68
int br_forward_finish(struct sock *sk, struct sk_buff *skb)
L
Linus Torvalds 已提交
69
{
70 71
	return NF_HOOK(NFPROTO_BRIDGE, NF_BR_POST_ROUTING, sk, skb,
		       NULL, skb->dev,
72
		       br_dev_queue_push_xmit);
L
Linus Torvalds 已提交
73 74

}
75
EXPORT_SYMBOL_GPL(br_forward_finish);
L
Linus Torvalds 已提交
76 77 78

static void __br_deliver(const struct net_bridge_port *to, struct sk_buff *skb)
{
79 80 81 82
	skb = br_handle_vlan(to->br, nbp_get_vlan_info(to), skb);
	if (!skb)
		return;

L
Linus Torvalds 已提交
83
	skb->dev = to->dev;
H
Herbert Xu 已提交
84

85
	if (unlikely(netpoll_tx_running(to->br->dev))) {
86
		if (!is_skb_forwardable(skb->dev, skb))
H
Herbert Xu 已提交
87 88 89 90 91 92 93 94
			kfree_skb(skb);
		else {
			skb_push(skb, ETH_HLEN);
			br_netpoll_send_skb(to, skb);
		}
		return;
	}

95 96
	NF_HOOK(NFPROTO_BRIDGE, NF_BR_LOCAL_OUT, NULL, skb,
		NULL, skb->dev,
97
		br_forward_finish);
L
Linus Torvalds 已提交
98 99 100 101 102 103
}

static void __br_forward(const struct net_bridge_port *to, struct sk_buff *skb)
{
	struct net_device *indev;

H
Herbert Xu 已提交
104 105 106 107 108
	if (skb_warn_if_lro(skb)) {
		kfree_skb(skb);
		return;
	}

109 110 111 112
	skb = br_handle_vlan(to->br, nbp_get_vlan_info(to), skb);
	if (!skb)
		return;

L
Linus Torvalds 已提交
113 114
	indev = skb->dev;
	skb->dev = to->dev;
115
	skb_forward_csum(skb);
L
Linus Torvalds 已提交
116

117 118
	NF_HOOK(NFPROTO_BRIDGE, NF_BR_FORWARD, NULL, skb,
		indev, skb->dev,
119
		br_forward_finish);
L
Linus Torvalds 已提交
120 121 122 123 124
}

/* called with rcu_read_lock */
void br_deliver(const struct net_bridge_port *to, struct sk_buff *skb)
{
125
	if (to && should_deliver(to, skb)) {
L
Linus Torvalds 已提交
126 127 128 129 130 131
		__br_deliver(to, skb);
		return;
	}

	kfree_skb(skb);
}
132
EXPORT_SYMBOL_GPL(br_deliver);
L
Linus Torvalds 已提交
133 134

/* called with rcu_read_lock */
135
void br_forward(const struct net_bridge_port *to, struct sk_buff *skb, struct sk_buff *skb0)
L
Linus Torvalds 已提交
136
{
H
Herbert Xu 已提交
137
	if (should_deliver(to, skb)) {
138 139 140 141
		if (skb0)
			deliver_clone(to, skb, __br_forward);
		else
			__br_forward(to, skb);
L
Linus Torvalds 已提交
142 143 144
		return;
	}

145 146
	if (!skb0)
		kfree_skb(skb);
L
Linus Torvalds 已提交
147 148
}

149 150
static int deliver_clone(const struct net_bridge_port *prev,
			 struct sk_buff *skb,
151 152 153
			 void (*__packet_hook)(const struct net_bridge_port *p,
					       struct sk_buff *skb))
{
154 155
	struct net_device *dev = BR_INPUT_SKB_CB(skb)->brdev;

156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187
	skb = skb_clone(skb, GFP_ATOMIC);
	if (!skb) {
		dev->stats.tx_dropped++;
		return -ENOMEM;
	}

	__packet_hook(prev, skb);
	return 0;
}

static struct net_bridge_port *maybe_deliver(
	struct net_bridge_port *prev, struct net_bridge_port *p,
	struct sk_buff *skb,
	void (*__packet_hook)(const struct net_bridge_port *p,
			      struct sk_buff *skb))
{
	int err;

	if (!should_deliver(p, skb))
		return prev;

	if (!prev)
		goto out;

	err = deliver_clone(prev, skb, __packet_hook);
	if (err)
		return ERR_PTR(err);

out:
	return p;
}

L
Linus Torvalds 已提交
188
/* called under bridge lock */
189
static void br_flood(struct net_bridge *br, struct sk_buff *skb,
190 191
		     struct sk_buff *skb0,
		     void (*__packet_hook)(const struct net_bridge_port *p,
192 193
					   struct sk_buff *skb),
		     bool unicast)
L
Linus Torvalds 已提交
194 195 196 197 198 199 200
{
	struct net_bridge_port *p;
	struct net_bridge_port *prev;

	prev = NULL;

	list_for_each_entry_rcu(p, &br->port_list, list) {
201 202 203
		/* Do not flood unicast traffic to ports that turn it off */
		if (unicast && !(p->flags & BR_FLOOD))
			continue;
204 205 206 207

		/* Do not flood to ports that enable proxy ARP */
		if (p->flags & BR_PROXYARP)
			continue;
208 209 210
		if ((p->flags & BR_PROXYARP_WIFI) &&
		    BR_INPUT_SKB_CB(skb)->proxyarp_replied)
			continue;
211

212 213 214
		prev = maybe_deliver(prev, p, skb, __packet_hook);
		if (IS_ERR(prev))
			goto out;
L
Linus Torvalds 已提交
215 216
	}

217 218 219
	if (!prev)
		goto out;

220 221 222 223
	if (skb0)
		deliver_clone(prev, skb, __packet_hook);
	else
		__packet_hook(prev, skb);
224
	return;
L
Linus Torvalds 已提交
225

226 227 228
out:
	if (!skb0)
		kfree_skb(skb);
L
Linus Torvalds 已提交
229 230 231 232
}


/* called with rcu_read_lock */
233
void br_flood_deliver(struct net_bridge *br, struct sk_buff *skb, bool unicast)
L
Linus Torvalds 已提交
234
{
235
	br_flood(br, skb, NULL, __br_deliver, unicast);
L
Linus Torvalds 已提交
236 237 238
}

/* called under bridge lock */
239
void br_flood_forward(struct net_bridge *br, struct sk_buff *skb,
240
		      struct sk_buff *skb2, bool unicast)
L
Linus Torvalds 已提交
241
{
242
	br_flood(br, skb, skb2, __br_forward, unicast);
L
Linus Torvalds 已提交
243
}
244 245 246 247 248 249 250 251 252 253 254

#ifdef CONFIG_BRIDGE_IGMP_SNOOPING
/* called with rcu_read_lock */
static void br_multicast_flood(struct net_bridge_mdb_entry *mdst,
			       struct sk_buff *skb, struct sk_buff *skb0,
			       void (*__packet_hook)(
					const struct net_bridge_port *p,
					struct sk_buff *skb))
{
	struct net_device *dev = BR_INPUT_SKB_CB(skb)->brdev;
	struct net_bridge *br = netdev_priv(dev);
255
	struct net_bridge_port *prev = NULL;
256 257 258
	struct net_bridge_port_group *p;
	struct hlist_node *rp;

259
	rp = rcu_dereference(hlist_first_rcu(&br->router_list));
260
	p = mdst ? rcu_dereference(mdst->ports) : NULL;
261
	while (p || rp) {
262 263
		struct net_bridge_port *port, *lport, *rport;

264 265 266 267 268 269 270 271 272 273 274 275
		lport = p ? p->port : NULL;
		rport = rp ? hlist_entry(rp, struct net_bridge_port, rlist) :
			     NULL;

		port = (unsigned long)lport > (unsigned long)rport ?
		       lport : rport;

		prev = maybe_deliver(prev, port, skb, __packet_hook);
		if (IS_ERR(prev))
			goto out;

		if ((unsigned long)lport >= (unsigned long)port)
276
			p = rcu_dereference(p->next);
277
		if ((unsigned long)rport >= (unsigned long)port)
278
			rp = rcu_dereference(hlist_next_rcu(rp));
279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308
	}

	if (!prev)
		goto out;

	if (skb0)
		deliver_clone(prev, skb, __packet_hook);
	else
		__packet_hook(prev, skb);
	return;

out:
	if (!skb0)
		kfree_skb(skb);
}

/* called with rcu_read_lock */
void br_multicast_deliver(struct net_bridge_mdb_entry *mdst,
			  struct sk_buff *skb)
{
	br_multicast_flood(mdst, skb, NULL, __br_deliver);
}

/* called with rcu_read_lock */
void br_multicast_forward(struct net_bridge_mdb_entry *mdst,
			  struct sk_buff *skb, struct sk_buff *skb2)
{
	br_multicast_flood(mdst, skb, skb2, __br_forward);
}
#endif