geneve.c 44.7 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
/*
 * GENEVE: Generic Network Virtualization Encapsulation
 *
 * Copyright (c) 2015 Red Hat, Inc.
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/etherdevice.h>
#include <linux/hash.h>
17
#include <net/dst_metadata.h>
18
#include <net/gro_cells.h>
19 20
#include <net/rtnetlink.h>
#include <net/geneve.h>
21
#include <net/protocol.h>
22 23 24 25 26 27 28 29 30 31 32 33 34 35 36

#define GENEVE_NETDEV_VER	"0.6"

#define GENEVE_UDP_PORT		6081

#define GENEVE_N_VID		(1u << 24)
#define GENEVE_VID_MASK		(GENEVE_N_VID - 1)

#define VNI_HASH_BITS		10
#define VNI_HASH_SIZE		(1<<VNI_HASH_BITS)

static bool log_ecn_error = true;
module_param(log_ecn_error, bool, 0644);
MODULE_PARM_DESC(log_ecn_error, "Log packets received with corrupted ECN");

37 38 39
#define GENEVE_VER 0
#define GENEVE_BASE_HLEN (sizeof(struct udphdr) + sizeof(struct genevehdr))

40 41
/* per-network namespace private data for this module */
struct geneve_net {
42 43
	struct list_head	geneve_list;
	struct list_head	sock_list;
44 45
};

46
static unsigned int geneve_net_id;
47

J
Jiri Benc 已提交
48 49 50 51 52
struct geneve_dev_node {
	struct hlist_node hlist;
	struct geneve_dev *geneve;
};

53 54
/* Pseudo network device */
struct geneve_dev {
J
Jiri Benc 已提交
55 56 57 58
	struct geneve_dev_node hlist4;	/* vni hash table for IPv4 socket */
#if IS_ENABLED(CONFIG_IPV6)
	struct geneve_dev_node hlist6;	/* vni hash table for IPv6 socket */
#endif
59 60
	struct net	   *net;	/* netns for packet i/o */
	struct net_device  *dev;	/* netdev for geneve tunnel */
61
	struct ip_tunnel_info info;
62
	struct geneve_sock __rcu *sock4;	/* IPv4 socket used for geneve tunnel */
63
#if IS_ENABLED(CONFIG_IPV6)
64
	struct geneve_sock __rcu *sock6;	/* IPv6 socket used for geneve tunnel */
65
#endif
66
	struct list_head   next;	/* geneve's per namespace list */
67
	struct gro_cells   gro_cells;
68 69
	bool		   collect_md;
	bool		   use_udp6_rx_checksums;
70 71
};

72 73 74 75 76 77
struct geneve_sock {
	bool			collect_md;
	struct list_head	list;
	struct socket		*sock;
	struct rcu_head		rcu;
	int			refcnt;
78
	struct hlist_head	vni_list[VNI_HASH_SIZE];
79
};
80 81 82 83 84 85 86 87 88

static inline __u32 geneve_net_vni_hash(u8 vni[3])
{
	__u32 vnid;

	vnid = (vni[0] << 16) | (vni[1] << 8) | vni[2];
	return hash_32(vnid, VNI_HASH_BITS);
}

89 90 91 92 93 94 95 96 97 98 99
static __be64 vni_to_tunnel_id(const __u8 *vni)
{
#ifdef __BIG_ENDIAN
	return (vni[0] << 16) | (vni[1] << 8) | vni[2];
#else
	return (__force __be64)(((__force u64)vni[0] << 40) |
				((__force u64)vni[1] << 48) |
				((__force u64)vni[2] << 56));
#endif
}

100 101 102 103 104 105 106 107 108 109 110 111 112 113
/* Convert 64 bit tunnel ID to 24 bit VNI. */
static void tunnel_id_to_vni(__be64 tun_id, __u8 *vni)
{
#ifdef __BIG_ENDIAN
	vni[0] = (__force __u8)(tun_id >> 16);
	vni[1] = (__force __u8)(tun_id >> 8);
	vni[2] = (__force __u8)tun_id;
#else
	vni[0] = (__force __u8)((__force u64)tun_id >> 40);
	vni[1] = (__force __u8)((__force u64)tun_id >> 48);
	vni[2] = (__force __u8)((__force u64)tun_id >> 56);
#endif
}

114 115 116 117 118
static bool eq_tun_id_and_vni(u8 *tun_id, u8 *vni)
{
	return !memcmp(vni, &tun_id[5], 3);
}

119 120 121 122 123
static sa_family_t geneve_get_sk_family(struct geneve_sock *gs)
{
	return gs->sock->sk->sk_family;
}

124
static struct geneve_dev *geneve_lookup(struct geneve_sock *gs,
125
					__be32 addr, u8 vni[])
126 127
{
	struct hlist_head *vni_list_head;
J
Jiri Benc 已提交
128
	struct geneve_dev_node *node;
129 130 131
	__u32 hash;

	/* Find the device for this VNI */
132
	hash = geneve_net_vni_hash(vni);
133
	vni_list_head = &gs->vni_list[hash];
J
Jiri Benc 已提交
134 135 136 137
	hlist_for_each_entry_rcu(node, vni_list_head, hlist) {
		if (eq_tun_id_and_vni((u8 *)&node->geneve->info.key.tun_id, vni) &&
		    addr == node->geneve->info.key.u.ipv4.dst)
			return node->geneve;
138 139 140 141 142 143 144 145 146
	}
	return NULL;
}

#if IS_ENABLED(CONFIG_IPV6)
static struct geneve_dev *geneve6_lookup(struct geneve_sock *gs,
					 struct in6_addr addr6, u8 vni[])
{
	struct hlist_head *vni_list_head;
J
Jiri Benc 已提交
147
	struct geneve_dev_node *node;
148 149 150 151 152
	__u32 hash;

	/* Find the device for this VNI */
	hash = geneve_net_vni_hash(vni);
	vni_list_head = &gs->vni_list[hash];
J
Jiri Benc 已提交
153 154 155 156
	hlist_for_each_entry_rcu(node, vni_list_head, hlist) {
		if (eq_tun_id_and_vni((u8 *)&node->geneve->info.key.tun_id, vni) &&
		    ipv6_addr_equal(&addr6, &node->geneve->info.key.u.ipv6.dst))
			return node->geneve;
157
	}
158 159
	return NULL;
}
160
#endif
161

162 163 164 165 166
static inline struct genevehdr *geneve_hdr(const struct sk_buff *skb)
{
	return (struct genevehdr *)(udp_hdr(skb) + 1);
}

167 168
static struct geneve_dev *geneve_lookup_skb(struct geneve_sock *gs,
					    struct sk_buff *skb)
169
{
170
	static u8 zero_vni[3];
171
	u8 *vni;
172

173
	if (geneve_get_sk_family(gs) == AF_INET) {
174
		struct iphdr *iph;
175
		__be32 addr;
176

177
		iph = ip_hdr(skb); /* outer IP header... */
178

179 180 181 182
		if (gs->collect_md) {
			vni = zero_vni;
			addr = 0;
		} else {
183
			vni = geneve_hdr(skb)->vni;
184 185 186
			addr = iph->saddr;
		}

187
		return geneve_lookup(gs, addr, vni);
188
#if IS_ENABLED(CONFIG_IPV6)
189
	} else if (geneve_get_sk_family(gs) == AF_INET6) {
190
		static struct in6_addr zero_addr6;
191 192 193
		struct ipv6hdr *ip6h;
		struct in6_addr addr6;

194
		ip6h = ipv6_hdr(skb); /* outer IPv6 header... */
195

196 197 198 199
		if (gs->collect_md) {
			vni = zero_vni;
			addr6 = zero_addr6;
		} else {
200
			vni = geneve_hdr(skb)->vni;
201 202 203
			addr6 = ip6h->saddr;
		}

204
		return geneve6_lookup(gs, addr6, vni);
205 206
#endif
	}
207 208 209 210 211 212 213 214 215 216
	return NULL;
}

/* geneve receive/decap routine */
static void geneve_rx(struct geneve_dev *geneve, struct geneve_sock *gs,
		      struct sk_buff *skb)
{
	struct genevehdr *gnvh = geneve_hdr(skb);
	struct metadata_dst *tun_dst = NULL;
	struct pcpu_sw_netstats *stats;
217
	unsigned int len;
218 219
	int err = 0;
	void *oiph;
220

221
	if (ip_tunnel_collect_metadata() || gs->collect_md) {
222 223 224 225 226 227
		__be16 flags;

		flags = TUNNEL_KEY | TUNNEL_GENEVE_OPT |
			(gnvh->oam ? TUNNEL_OAM : 0) |
			(gnvh->critical ? TUNNEL_CRIT_OPT : 0);

228
		tun_dst = udp_tun_rx_dst(skb, geneve_get_sk_family(gs), flags,
229 230
					 vni_to_tunnel_id(gnvh->vni),
					 gnvh->opt_len * 4);
231 232
		if (!tun_dst) {
			geneve->dev->stats.rx_dropped++;
233
			goto drop;
234
		}
235
		/* Update tunnel dst according to Geneve options. */
236 237
		ip_tunnel_info_opts_set(&tun_dst->u.tun_info,
					gnvh->options, gnvh->opt_len * 4);
238 239 240 241
	} else {
		/* Drop packets w/ critical options,
		 * since we don't support any...
		 */
242 243 244
		if (gnvh->critical) {
			geneve->dev->stats.rx_frame_errors++;
			geneve->dev->stats.rx_errors++;
245
			goto drop;
246
		}
247
	}
248 249 250 251 252

	skb_reset_mac_header(skb);
	skb->protocol = eth_type_trans(skb, geneve->dev);
	skb_postpull_rcsum(skb, eth_hdr(skb), ETH_HLEN);

253 254 255
	if (tun_dst)
		skb_dst_set(skb, &tun_dst->dst);

256
	/* Ignore packet loops (and multicast echo) */
257 258
	if (ether_addr_equal(eth_hdr(skb)->h_source, geneve->dev->dev_addr)) {
		geneve->dev->stats.rx_errors++;
259
		goto drop;
260
	}
261

262
	oiph = skb_network_header(skb);
263 264
	skb_reset_network_header(skb);

265 266
	if (geneve_get_sk_family(gs) == AF_INET)
		err = IP_ECN_decapsulate(oiph, skb);
267
#if IS_ENABLED(CONFIG_IPV6)
268 269
	else
		err = IP6_ECN_decapsulate(oiph, skb);
270
#endif
271 272

	if (unlikely(err)) {
273
		if (log_ecn_error) {
274
			if (geneve_get_sk_family(gs) == AF_INET)
275 276
				net_info_ratelimited("non-ECT from %pI4 "
						     "with TOS=%#x\n",
277 278
						     &((struct iphdr *)oiph)->saddr,
						     ((struct iphdr *)oiph)->tos);
279
#if IS_ENABLED(CONFIG_IPV6)
280
			else
281
				net_info_ratelimited("non-ECT from %pI6\n",
282
						     &((struct ipv6hdr *)oiph)->saddr);
283 284
#endif
		}
285 286 287 288 289 290 291
		if (err > 1) {
			++geneve->dev->stats.rx_frame_errors;
			++geneve->dev->stats.rx_errors;
			goto drop;
		}
	}

292 293 294 295 296 297 298 299 300
	len = skb->len;
	err = gro_cells_receive(&geneve->gro_cells, skb);
	if (likely(err == NET_RX_SUCCESS)) {
		stats = this_cpu_ptr(geneve->dev->tstats);
		u64_stats_update_begin(&stats->syncp);
		stats->rx_packets++;
		stats->rx_bytes += len;
		u64_stats_update_end(&stats->syncp);
	}
301 302 303 304 305 306 307 308 309
	return;
drop:
	/* Consume bad packet */
	kfree_skb(skb);
}

/* Setup stats when device is created */
static int geneve_init(struct net_device *dev)
{
310 311 312
	struct geneve_dev *geneve = netdev_priv(dev);
	int err;

313 314 315
	dev->tstats = netdev_alloc_pcpu_stats(struct pcpu_sw_netstats);
	if (!dev->tstats)
		return -ENOMEM;
316 317 318 319 320 321 322

	err = gro_cells_init(&geneve->gro_cells, dev);
	if (err) {
		free_percpu(dev->tstats);
		return err;
	}

323
	err = dst_cache_init(&geneve->info.dst_cache, GFP_KERNEL);
P
Paolo Abeni 已提交
324 325 326 327 328
	if (err) {
		free_percpu(dev->tstats);
		gro_cells_destroy(&geneve->gro_cells);
		return err;
	}
329 330 331 332 333
	return 0;
}

static void geneve_uninit(struct net_device *dev)
{
334 335
	struct geneve_dev *geneve = netdev_priv(dev);

336
	dst_cache_destroy(&geneve->info.dst_cache);
337
	gro_cells_destroy(&geneve->gro_cells);
338 339 340
	free_percpu(dev->tstats);
}

341 342 343 344
/* Callback from net/ipv4/udp.c to receive packets */
static int geneve_udp_encap_recv(struct sock *sk, struct sk_buff *skb)
{
	struct genevehdr *geneveh;
345
	struct geneve_dev *geneve;
346 347 348
	struct geneve_sock *gs;
	int opts_len;

349
	/* Need UDP and Geneve header to be present */
350
	if (unlikely(!pskb_may_pull(skb, GENEVE_BASE_HLEN)))
351
		goto drop;
352 353 354 355

	/* Return packets with reserved bits set */
	geneveh = geneve_hdr(skb);
	if (unlikely(geneveh->ver != GENEVE_VER))
356
		goto drop;
357 358

	if (unlikely(geneveh->proto_type != htons(ETH_P_TEB)))
359
		goto drop;
360

361 362 363 364 365 366 367 368
	gs = rcu_dereference_sk_user_data(sk);
	if (!gs)
		goto drop;

	geneve = geneve_lookup_skb(gs, skb);
	if (!geneve)
		goto drop;

369 370
	opts_len = geneveh->opt_len * 4;
	if (iptunnel_pull_header(skb, GENEVE_BASE_HLEN + opts_len,
371
				 htons(ETH_P_TEB),
372 373
				 !net_eq(geneve->net, dev_net(geneve->dev)))) {
		geneve->dev->stats.rx_dropped++;
374
		goto drop;
375
	}
376

377
	geneve_rx(geneve, gs, skb);
378 379 380 381 382 383 384 385 386
	return 0;

drop:
	/* Consume bad packet */
	kfree_skb(skb);
	return 0;
}

static struct socket *geneve_create_sock(struct net *net, bool ipv6,
387
					 __be16 port, bool ipv6_rx_csum)
388 389 390 391 392 393 394 395 396
{
	struct socket *sock;
	struct udp_port_cfg udp_conf;
	int err;

	memset(&udp_conf, 0, sizeof(udp_conf));

	if (ipv6) {
		udp_conf.family = AF_INET6;
397
		udp_conf.ipv6_v6only = 1;
398
		udp_conf.use_udp6_rx_checksums = ipv6_rx_csum;
399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418
	} else {
		udp_conf.family = AF_INET;
		udp_conf.local_ip.s_addr = htonl(INADDR_ANY);
	}

	udp_conf.local_udp_port = port;

	/* Open UDP socket */
	err = udp_sock_create(net, &udp_conf, &sock);
	if (err < 0)
		return ERR_PTR(err);

	return sock;
}

static int geneve_hlen(struct genevehdr *gh)
{
	return sizeof(*gh) + gh->opt_len * 4;
}

419 420 421
static struct sk_buff **geneve_gro_receive(struct sock *sk,
					   struct sk_buff **head,
					   struct sk_buff *skb)
422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465
{
	struct sk_buff *p, **pp = NULL;
	struct genevehdr *gh, *gh2;
	unsigned int hlen, gh_len, off_gnv;
	const struct packet_offload *ptype;
	__be16 type;
	int flush = 1;

	off_gnv = skb_gro_offset(skb);
	hlen = off_gnv + sizeof(*gh);
	gh = skb_gro_header_fast(skb, off_gnv);
	if (skb_gro_header_hard(skb, hlen)) {
		gh = skb_gro_header_slow(skb, hlen, off_gnv);
		if (unlikely(!gh))
			goto out;
	}

	if (gh->ver != GENEVE_VER || gh->oam)
		goto out;
	gh_len = geneve_hlen(gh);

	hlen = off_gnv + gh_len;
	if (skb_gro_header_hard(skb, hlen)) {
		gh = skb_gro_header_slow(skb, hlen, off_gnv);
		if (unlikely(!gh))
			goto out;
	}

	for (p = *head; p; p = p->next) {
		if (!NAPI_GRO_CB(p)->same_flow)
			continue;

		gh2 = (struct genevehdr *)(p->data + off_gnv);
		if (gh->opt_len != gh2->opt_len ||
		    memcmp(gh, gh2, gh_len)) {
			NAPI_GRO_CB(p)->same_flow = 0;
			continue;
		}
	}

	type = gh->proto_type;

	rcu_read_lock();
	ptype = gro_find_receive_by_type(type);
466
	if (!ptype)
467 468 469 470
		goto out_unlock;

	skb_gro_pull(skb, gh_len);
	skb_gro_postpull_rcsum(skb, gh, gh_len);
S
Sabrina Dubroca 已提交
471
	pp = call_gro_receive(ptype->callbacks.gro_receive, head, skb);
472
	flush = 0;
473 474 475 476 477 478 479 480 481

out_unlock:
	rcu_read_unlock();
out:
	NAPI_GRO_CB(skb)->flush |= flush;

	return pp;
}

482 483
static int geneve_gro_complete(struct sock *sk, struct sk_buff *skb,
			       int nhoff)
484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500
{
	struct genevehdr *gh;
	struct packet_offload *ptype;
	__be16 type;
	int gh_len;
	int err = -ENOSYS;

	gh = (struct genevehdr *)(skb->data + nhoff);
	gh_len = geneve_hlen(gh);
	type = gh->proto_type;

	rcu_read_lock();
	ptype = gro_find_complete_by_type(type);
	if (ptype)
		err = ptype->callbacks.gro_complete(skb, nhoff + gh_len);

	rcu_read_unlock();
501 502 503

	skb_set_inner_mac_header(skb, nhoff + gh_len);

504 505 506 507 508
	return err;
}

/* Create new listen socket if needed */
static struct geneve_sock *geneve_socket_create(struct net *net, __be16 port,
509
						bool ipv6, bool ipv6_rx_csum)
510 511 512 513 514
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);
	struct geneve_sock *gs;
	struct socket *sock;
	struct udp_tunnel_sock_cfg tunnel_cfg;
515
	int h;
516 517 518 519 520

	gs = kzalloc(sizeof(*gs), GFP_KERNEL);
	if (!gs)
		return ERR_PTR(-ENOMEM);

521
	sock = geneve_create_sock(net, ipv6, port, ipv6_rx_csum);
522 523 524 525 526 527 528
	if (IS_ERR(sock)) {
		kfree(gs);
		return ERR_CAST(sock);
	}

	gs->sock = sock;
	gs->refcnt = 1;
529 530
	for (h = 0; h < VNI_HASH_SIZE; ++h)
		INIT_HLIST_HEAD(&gs->vni_list[h]);
531 532

	/* Initialize the geneve udp offloads structure */
533
	udp_tunnel_notify_add_rx_port(gs->sock, UDP_TUNNEL_TYPE_GENEVE);
534 535

	/* Mark socket as an encapsulation socket */
536
	memset(&tunnel_cfg, 0, sizeof(tunnel_cfg));
537 538
	tunnel_cfg.sk_user_data = gs;
	tunnel_cfg.encap_type = 1;
539 540
	tunnel_cfg.gro_receive = geneve_gro_receive;
	tunnel_cfg.gro_complete = geneve_gro_complete;
541 542 543 544 545 546 547
	tunnel_cfg.encap_rcv = geneve_udp_encap_recv;
	tunnel_cfg.encap_destroy = NULL;
	setup_udp_tunnel_sock(net, sock, &tunnel_cfg);
	list_add(&gs->list, &gn->sock_list);
	return gs;
}

548
static void __geneve_sock_release(struct geneve_sock *gs)
549
{
550
	if (!gs || --gs->refcnt)
551 552 553
		return;

	list_del(&gs->list);
554
	udp_tunnel_notify_del_rx_port(gs->sock, UDP_TUNNEL_TYPE_GENEVE);
555 556 557 558
	udp_tunnel_sock_release(gs->sock);
	kfree_rcu(gs, rcu);
}

559 560
static void geneve_sock_release(struct geneve_dev *geneve)
{
561
	struct geneve_sock *gs4 = rtnl_dereference(geneve->sock4);
562
#if IS_ENABLED(CONFIG_IPV6)
563 564 565 566 567 568 569 570 571 572 573
	struct geneve_sock *gs6 = rtnl_dereference(geneve->sock6);

	rcu_assign_pointer(geneve->sock6, NULL);
#endif

	rcu_assign_pointer(geneve->sock4, NULL);
	synchronize_net();

	__geneve_sock_release(gs4);
#if IS_ENABLED(CONFIG_IPV6)
	__geneve_sock_release(gs6);
574 575 576
#endif
}

577
static struct geneve_sock *geneve_find_sock(struct geneve_net *gn,
578
					    sa_family_t family,
579 580 581 582 583 584
					    __be16 dst_port)
{
	struct geneve_sock *gs;

	list_for_each_entry(gs, &gn->sock_list, list) {
		if (inet_sk(gs->sock->sk)->inet_sport == dst_port &&
585
		    geneve_get_sk_family(gs) == family) {
586 587 588 589 590 591
			return gs;
		}
	}
	return NULL;
}

592
static int geneve_sock_add(struct geneve_dev *geneve, bool ipv6)
593 594
{
	struct net *net = geneve->net;
595
	struct geneve_net *gn = net_generic(net, geneve_net_id);
J
Jiri Benc 已提交
596
	struct geneve_dev_node *node;
597
	struct geneve_sock *gs;
598
	__u8 vni[3];
599
	__u32 hash;
600

601
	gs = geneve_find_sock(gn, ipv6 ? AF_INET6 : AF_INET, geneve->info.key.tp_dst);
602 603 604 605 606
	if (gs) {
		gs->refcnt++;
		goto out;
	}

607 608
	gs = geneve_socket_create(net, geneve->info.key.tp_dst, ipv6,
				  geneve->use_udp6_rx_checksums);
609 610 611
	if (IS_ERR(gs))
		return PTR_ERR(gs);

612 613
out:
	gs->collect_md = geneve->collect_md;
614
#if IS_ENABLED(CONFIG_IPV6)
J
Jiri Benc 已提交
615
	if (ipv6) {
616
		rcu_assign_pointer(geneve->sock6, gs);
J
Jiri Benc 已提交
617 618
		node = &geneve->hlist6;
	} else
619
#endif
J
Jiri Benc 已提交
620
	{
621
		rcu_assign_pointer(geneve->sock4, gs);
J
Jiri Benc 已提交
622 623 624
		node = &geneve->hlist4;
	}
	node->geneve = geneve;
625

626 627
	tunnel_id_to_vni(geneve->info.key.tun_id, vni);
	hash = geneve_net_vni_hash(vni);
J
Jiri Benc 已提交
628
	hlist_add_head_rcu(&node->hlist, &gs->vni_list[hash]);
629 630 631
	return 0;
}

632 633 634
static int geneve_open(struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);
635
	bool ipv6 = !!(geneve->info.mode & IP_TUNNEL_INFO_IPV6);
636 637 638 639 640 641 642 643 644 645 646 647 648 649 650
	bool metadata = geneve->collect_md;
	int ret = 0;

#if IS_ENABLED(CONFIG_IPV6)
	if (ipv6 || metadata)
		ret = geneve_sock_add(geneve, true);
#endif
	if (!ret && (!ipv6 || metadata))
		ret = geneve_sock_add(geneve, false);
	if (ret < 0)
		geneve_sock_release(geneve);

	return ret;
}

651 652 653 654
static int geneve_stop(struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);

J
Jiri Benc 已提交
655 656 657 658
	hlist_del_init_rcu(&geneve->hlist4.hlist);
#if IS_ENABLED(CONFIG_IPV6)
	hlist_del_init_rcu(&geneve->hlist6.hlist);
#endif
659
	geneve_sock_release(geneve);
660 661 662
	return 0;
}

663
static void geneve_build_header(struct genevehdr *geneveh,
664
				const struct ip_tunnel_info *info)
665 666
{
	geneveh->ver = GENEVE_VER;
667 668 669
	geneveh->opt_len = info->options_len / 4;
	geneveh->oam = !!(info->key.tun_flags & TUNNEL_OAM);
	geneveh->critical = !!(info->key.tun_flags & TUNNEL_CRIT_OPT);
670
	geneveh->rsvd1 = 0;
671
	tunnel_id_to_vni(info->key.tun_id, geneveh->vni);
672 673 674
	geneveh->proto_type = htons(ETH_P_TEB);
	geneveh->rsvd2 = 0;

675
	ip_tunnel_info_opts_get(geneveh->options, info);
676 677
}

678 679 680
static int geneve_build_skb(struct dst_entry *dst, struct sk_buff *skb,
			    const struct ip_tunnel_info *info,
			    bool xnet, int ip_hdr_len)
681
{
682
	bool udp_sum = !!(info->key.tun_flags & TUNNEL_CSUM);
683 684 685 686
	struct genevehdr *gnvh;
	int min_headroom;
	int err;

687
	skb_reset_mac_header(skb);
688 689
	skb_scrub_packet(skb, xnet);

690 691
	min_headroom = LL_RESERVED_SPACE(dst->dev) + dst->header_len +
		       GENEVE_BASE_HLEN + info->options_len + ip_hdr_len;
692
	err = skb_cow_head(skb, min_headroom);
693
	if (unlikely(err))
694 695
		goto free_dst;

696
	err = udp_tunnel_handle_offloads(skb, udp_sum);
697
	if (err)
698 699
		goto free_dst;

700
	gnvh = __skb_push(skb, sizeof(*gnvh) + info->options_len);
701
	geneve_build_header(gnvh, info);
702 703 704 705 706 707 708 709 710 711
	skb_set_inner_protocol(skb, htons(ETH_P_TEB));
	return 0;

free_dst:
	dst_release(dst);
	return err;
}

static struct rtable *geneve_get_v4_rt(struct sk_buff *skb,
				       struct net_device *dev,
712
				       struct geneve_sock *gs4,
713
				       struct flowi4 *fl4,
714
				       const struct ip_tunnel_info *info)
715
{
716
	bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
717
	struct geneve_dev *geneve = netdev_priv(dev);
P
Paolo Abeni 已提交
718
	struct dst_cache *dst_cache;
719 720 721
	struct rtable *rt = NULL;
	__u8 tos;

722
	if (!gs4)
723 724
		return ERR_PTR(-EIO);

725 726 727
	memset(fl4, 0, sizeof(*fl4));
	fl4->flowi4_mark = skb->mark;
	fl4->flowi4_proto = IPPROTO_UDP;
728 729
	fl4->daddr = info->key.u.ipv4.dst;
	fl4->saddr = info->key.u.ipv4.src;
730

731 732 733 734
	tos = info->key.tos;
	if ((tos == 1) && !geneve->collect_md) {
		tos = ip_tunnel_get_dsfield(ip_hdr(skb), skb);
		use_cache = false;
P
Paolo Abeni 已提交
735
	}
736
	fl4->flowi4_tos = RT_TOS(tos);
P
Paolo Abeni 已提交
737

738
	dst_cache = (struct dst_cache *)&info->dst_cache;
P
Paolo Abeni 已提交
739 740 741 742
	if (use_cache) {
		rt = dst_cache_get_ip4(dst_cache, &fl4->saddr);
		if (rt)
			return rt;
743 744 745 746
	}
	rt = ip_route_output_key(geneve->net, fl4);
	if (IS_ERR(rt)) {
		netdev_dbg(dev, "no route to %pI4\n", &fl4->daddr);
747
		return ERR_PTR(-ENETUNREACH);
748 749 750 751
	}
	if (rt->dst.dev == dev) { /* is this necessary? */
		netdev_dbg(dev, "circular route to %pI4\n", &fl4->daddr);
		ip_rt_put(rt);
752
		return ERR_PTR(-ELOOP);
753
	}
P
Paolo Abeni 已提交
754 755
	if (use_cache)
		dst_cache_set_ip4(dst_cache, &rt->dst, fl4->saddr);
756 757 758
	return rt;
}

759 760 761
#if IS_ENABLED(CONFIG_IPV6)
static struct dst_entry *geneve_get_v6_dst(struct sk_buff *skb,
					   struct net_device *dev,
762
					   struct geneve_sock *gs6,
763
					   struct flowi6 *fl6,
764
					   const struct ip_tunnel_info *info)
765
{
766
	bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
767 768
	struct geneve_dev *geneve = netdev_priv(dev);
	struct dst_entry *dst = NULL;
P
Paolo Abeni 已提交
769
	struct dst_cache *dst_cache;
770
	__u8 prio;
771

772 773 774
	if (!gs6)
		return ERR_PTR(-EIO);

775 776 777
	memset(fl6, 0, sizeof(*fl6));
	fl6->flowi6_mark = skb->mark;
	fl6->flowi6_proto = IPPROTO_UDP;
778 779 780 781 782 783
	fl6->daddr = info->key.u.ipv6.dst;
	fl6->saddr = info->key.u.ipv6.src;
	prio = info->key.tos;
	if ((prio == 1) && !geneve->collect_md) {
		prio = ip_tunnel_get_dsfield(ip_hdr(skb), skb);
		use_cache = false;
P
Paolo Abeni 已提交
784 785
	}

786 787
	fl6->flowlabel = ip6_make_flowinfo(RT_TOS(prio),
					   info->key.label);
788
	dst_cache = (struct dst_cache *)&info->dst_cache;
P
Paolo Abeni 已提交
789 790 791 792
	if (use_cache) {
		dst = dst_cache_get_ip6(dst_cache, &fl6->saddr);
		if (dst)
			return dst;
793 794 795 796 797 798 799 800 801 802 803
	}
	if (ipv6_stub->ipv6_dst_lookup(geneve->net, gs6->sock->sk, &dst, fl6)) {
		netdev_dbg(dev, "no route to %pI6\n", &fl6->daddr);
		return ERR_PTR(-ENETUNREACH);
	}
	if (dst->dev == dev) { /* is this necessary? */
		netdev_dbg(dev, "circular route to %pI6\n", &fl6->daddr);
		dst_release(dst);
		return ERR_PTR(-ELOOP);
	}

P
Paolo Abeni 已提交
804 805
	if (use_cache)
		dst_cache_set_ip6(dst_cache, dst, &fl6->saddr);
806 807 808 809
	return dst;
}
#endif

810
static int geneve_xmit_skb(struct sk_buff *skb, struct net_device *dev,
811 812
			   struct geneve_dev *geneve,
			   const struct ip_tunnel_info *info)
813
{
814 815 816 817
	bool xnet = !net_eq(geneve->net, dev_net(geneve->dev));
	struct geneve_sock *gs4 = rcu_dereference(geneve->sock4);
	const struct ip_tunnel_key *key = &info->key;
	struct rtable *rt;
818
	struct flowi4 fl4;
819
	__u8 tos, ttl;
820
	__be16 sport;
821
	__be16 df;
822
	int err;
823

824
	rt = geneve_get_v4_rt(skb, dev, gs4, &fl4, info);
825 826
	if (IS_ERR(rt))
		return PTR_ERR(rt);
827

828 829 830 831
	if (skb_dst(skb)) {
		int mtu = dst_mtu(&rt->dst) - sizeof(struct iphdr) -
			  GENEVE_BASE_HLEN - info->options_len - 14;

832
		skb_dst_update_pmtu(skb, mtu);
833 834
	}

835
	sport = udp_flow_src_port(geneve->net, skb, 1, USHRT_MAX, true);
836 837
	if (geneve->collect_md) {
		tos = ip_tunnel_ecn_encap(key->tos, ip_hdr(skb), skb);
838
		ttl = key->ttl;
839
	} else {
840 841
		tos = ip_tunnel_ecn_encap(fl4.flowi4_tos, ip_hdr(skb), skb);
		ttl = key->ttl ? : ip4_dst_hoplimit(&rt->dst);
842
	}
843
	df = key->tun_flags & TUNNEL_DONT_FRAGMENT ? htons(IP_DF) : 0;
844

845
	err = geneve_build_skb(&rt->dst, skb, info, xnet, sizeof(struct iphdr));
846 847
	if (unlikely(err))
		return err;
H
Haishuang Yan 已提交
848

849 850 851 852 853
	udp_tunnel_xmit_skb(rt, gs4->sock->sk, skb, fl4.saddr, fl4.daddr,
			    tos, ttl, df, sport, geneve->info.key.tp_dst,
			    !net_eq(geneve->net, dev_net(geneve->dev)),
			    !(info->key.tun_flags & TUNNEL_CSUM));
	return 0;
854 855
}

856
#if IS_ENABLED(CONFIG_IPV6)
857
static int geneve6_xmit_skb(struct sk_buff *skb, struct net_device *dev,
858 859
			    struct geneve_dev *geneve,
			    const struct ip_tunnel_info *info)
860
{
861 862 863
	bool xnet = !net_eq(geneve->net, dev_net(geneve->dev));
	struct geneve_sock *gs6 = rcu_dereference(geneve->sock6);
	const struct ip_tunnel_key *key = &info->key;
864 865
	struct dst_entry *dst = NULL;
	struct flowi6 fl6;
866
	__u8 prio, ttl;
867
	__be16 sport;
868
	int err;
869

870
	dst = geneve_get_v6_dst(skb, dev, gs6, &fl6, info);
871 872
	if (IS_ERR(dst))
		return PTR_ERR(dst);
873

874 875 876 877
	if (skb_dst(skb)) {
		int mtu = dst_mtu(dst) - sizeof(struct ipv6hdr) -
			  GENEVE_BASE_HLEN - info->options_len - 14;

878
		skb_dst_update_pmtu(skb, mtu);
879 880
	}

881
	sport = udp_flow_src_port(geneve->net, skb, 1, USHRT_MAX, true);
882 883 884 885 886 887 888 889
	if (geneve->collect_md) {
		prio = ip_tunnel_ecn_encap(key->tos, ip_hdr(skb), skb);
		ttl = key->ttl;
	} else {
		prio = ip_tunnel_ecn_encap(ip6_tclass(fl6.flowlabel),
					   ip_hdr(skb), skb);
		ttl = key->ttl ? : ip6_dst_hoplimit(dst);
	}
890
	err = geneve_build_skb(dst, skb, info, xnet, sizeof(struct ipv6hdr));
891 892
	if (unlikely(err))
		return err;
893

894 895 896 897 898 899 900
	udp_tunnel6_xmit_skb(dst, gs6->sock->sk, skb, dev,
			     &fl6.saddr, &fl6.daddr, prio, ttl,
			     info->key.label, sport, geneve->info.key.tp_dst,
			     !(info->key.tun_flags & TUNNEL_CSUM));
	return 0;
}
#endif
901

902 903 904 905 906
static netdev_tx_t geneve_xmit(struct sk_buff *skb, struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);
	struct ip_tunnel_info *info = NULL;
	int err;
907

908 909 910 911 912
	if (geneve->collect_md) {
		info = skb_tunnel_info(skb);
		if (unlikely(!info || !(info->mode & IP_TUNNEL_INFO_TX))) {
			err = -EINVAL;
			netdev_dbg(dev, "no tunnel metadata\n");
913
			goto tx_error;
914
		}
915
	} else {
916
		info = &geneve->info;
917
	}
918

J
Jakub Kicinski 已提交
919
	rcu_read_lock();
920 921 922 923 924 925
#if IS_ENABLED(CONFIG_IPV6)
	if (info->mode & IP_TUNNEL_INFO_IPV6)
		err = geneve6_xmit_skb(skb, dev, geneve, info);
	else
#endif
		err = geneve_xmit_skb(skb, dev, geneve, info);
J
Jakub Kicinski 已提交
926
	rcu_read_unlock();
927

928 929
	if (likely(!err))
		return NETDEV_TX_OK;
930 931
tx_error:
	dev_kfree_skb(skb);
932

933 934 935 936
	if (err == -ELOOP)
		dev->stats.collisions++;
	else if (err == -ENETUNREACH)
		dev->stats.tx_carrier_errors++;
H
Haishuang Yan 已提交
937 938

	dev->stats.tx_errors++;
939 940 941
	return NETDEV_TX_OK;
}

942
static int geneve_change_mtu(struct net_device *dev, int new_mtu)
D
David Wragg 已提交
943
{
944 945
	/* Only possible if called internally, ndo_change_mtu path's new_mtu
	 * is guaranteed to be between dev->min_mtu and dev->max_mtu.
D
David Wragg 已提交
946
	 */
947 948
	if (new_mtu > dev->max_mtu)
		new_mtu = dev->max_mtu;
D
David Wragg 已提交
949

D
David Wragg 已提交
950 951 952 953
	dev->mtu = new_mtu;
	return 0;
}

954 955 956 957 958
static int geneve_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb)
{
	struct ip_tunnel_info *info = skb_tunnel_info(skb);
	struct geneve_dev *geneve = netdev_priv(dev);

959
	if (ip_tunnel_info_af(info) == AF_INET) {
960 961
		struct rtable *rt;
		struct flowi4 fl4;
962
		struct geneve_sock *gs4 = rcu_dereference(geneve->sock4);
963

964
		rt = geneve_get_v4_rt(skb, dev, gs4, &fl4, info);
965 966
		if (IS_ERR(rt))
			return PTR_ERR(rt);
967

968 969 970 971
		ip_rt_put(rt);
		info->key.u.ipv4.src = fl4.saddr;
#if IS_ENABLED(CONFIG_IPV6)
	} else if (ip_tunnel_info_af(info) == AF_INET6) {
972 973
		struct dst_entry *dst;
		struct flowi6 fl6;
974
		struct geneve_sock *gs6 = rcu_dereference(geneve->sock6);
975

976
		dst = geneve_get_v6_dst(skb, dev, gs6, &fl6, info);
977 978 979 980 981 982 983 984 985
		if (IS_ERR(dst))
			return PTR_ERR(dst);

		dst_release(dst);
		info->key.u.ipv6.src = fl6.saddr;
#endif
	} else {
		return -EINVAL;
	}
986 987 988

	info->key.tp_src = udp_flow_src_port(geneve->net, skb,
					     1, USHRT_MAX, true);
989
	info->key.tp_dst = geneve->info.key.tp_dst;
990 991 992
	return 0;
}

993 994 995 996 997 998 999
static const struct net_device_ops geneve_netdev_ops = {
	.ndo_init		= geneve_init,
	.ndo_uninit		= geneve_uninit,
	.ndo_open		= geneve_open,
	.ndo_stop		= geneve_stop,
	.ndo_start_xmit		= geneve_xmit,
	.ndo_get_stats64	= ip_tunnel_get_stats64,
D
David Wragg 已提交
1000
	.ndo_change_mtu		= geneve_change_mtu,
1001 1002
	.ndo_validate_addr	= eth_validate_addr,
	.ndo_set_mac_address	= eth_mac_addr,
1003
	.ndo_fill_metadata_dst	= geneve_fill_metadata_dst,
1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022
};

static void geneve_get_drvinfo(struct net_device *dev,
			       struct ethtool_drvinfo *drvinfo)
{
	strlcpy(drvinfo->version, GENEVE_NETDEV_VER, sizeof(drvinfo->version));
	strlcpy(drvinfo->driver, "geneve", sizeof(drvinfo->driver));
}

static const struct ethtool_ops geneve_ethtool_ops = {
	.get_drvinfo	= geneve_get_drvinfo,
	.get_link	= ethtool_op_get_link,
};

/* Info for udev, that this is a virtual tunnel endpoint */
static struct device_type geneve_type = {
	.name = "geneve",
};

1023
/* Calls the ndo_udp_tunnel_add of the caller in order to
1024
 * supply the listening GENEVE udp ports. Callers are expected
1025
 * to implement the ndo_udp_tunnel_add.
1026
 */
1027
static void geneve_offload_rx_ports(struct net_device *dev, bool push)
1028 1029 1030 1031
{
	struct net *net = dev_net(dev);
	struct geneve_net *gn = net_generic(net, geneve_net_id);
	struct geneve_sock *gs;
1032

1033
	rcu_read_lock();
1034 1035 1036 1037 1038 1039 1040 1041 1042
	list_for_each_entry_rcu(gs, &gn->sock_list, list) {
		if (push) {
			udp_tunnel_push_rx_port(dev, gs->sock,
						UDP_TUNNEL_TYPE_GENEVE);
		} else {
			udp_tunnel_drop_rx_port(dev, gs->sock,
						UDP_TUNNEL_TYPE_GENEVE);
		}
	}
1043 1044 1045
	rcu_read_unlock();
}

1046 1047 1048 1049 1050 1051 1052
/* Initialize the device structure. */
static void geneve_setup(struct net_device *dev)
{
	ether_setup(dev);

	dev->netdev_ops = &geneve_netdev_ops;
	dev->ethtool_ops = &geneve_ethtool_ops;
1053
	dev->needs_free_netdev = true;
1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064

	SET_NETDEV_DEVTYPE(dev, &geneve_type);

	dev->features    |= NETIF_F_LLTX;
	dev->features    |= NETIF_F_SG | NETIF_F_HW_CSUM;
	dev->features    |= NETIF_F_RXCSUM;
	dev->features    |= NETIF_F_GSO_SOFTWARE;

	dev->hw_features |= NETIF_F_SG | NETIF_F_HW_CSUM | NETIF_F_RXCSUM;
	dev->hw_features |= NETIF_F_GSO_SOFTWARE;

1065 1066 1067 1068 1069 1070 1071 1072
	/* MTU range: 68 - (something less than 65535) */
	dev->min_mtu = ETH_MIN_MTU;
	/* The max_mtu calculation does not take account of GENEVE
	 * options, to avoid excluding potentially valid
	 * configurations. This will be further reduced by IPvX hdr size.
	 */
	dev->max_mtu = IP_MAX_MTU - GENEVE_BASE_HLEN - dev->hard_header_len;

1073
	netif_keep_dst(dev);
J
Jiri Benc 已提交
1074
	dev->priv_flags &= ~IFF_TX_SKB_SHARING;
1075
	dev->priv_flags |= IFF_LIVE_ADDR_CHANGE | IFF_NO_QUEUE;
1076
	eth_hw_addr_random(dev);
1077 1078 1079 1080 1081
}

static const struct nla_policy geneve_policy[IFLA_GENEVE_MAX + 1] = {
	[IFLA_GENEVE_ID]		= { .type = NLA_U32 },
	[IFLA_GENEVE_REMOTE]		= { .len = FIELD_SIZEOF(struct iphdr, daddr) },
1082
	[IFLA_GENEVE_REMOTE6]		= { .len = sizeof(struct in6_addr) },
1083
	[IFLA_GENEVE_TTL]		= { .type = NLA_U8 },
1084
	[IFLA_GENEVE_TOS]		= { .type = NLA_U8 },
1085
	[IFLA_GENEVE_LABEL]		= { .type = NLA_U32 },
1086
	[IFLA_GENEVE_PORT]		= { .type = NLA_U16 },
1087
	[IFLA_GENEVE_COLLECT_METADATA]	= { .type = NLA_FLAG },
1088 1089 1090
	[IFLA_GENEVE_UDP_CSUM]		= { .type = NLA_U8 },
	[IFLA_GENEVE_UDP_ZERO_CSUM6_TX]	= { .type = NLA_U8 },
	[IFLA_GENEVE_UDP_ZERO_CSUM6_RX]	= { .type = NLA_U8 },
1091 1092
};

1093 1094
static int geneve_validate(struct nlattr *tb[], struct nlattr *data[],
			   struct netlink_ext_ack *extack)
1095 1096
{
	if (tb[IFLA_ADDRESS]) {
1097 1098 1099
		if (nla_len(tb[IFLA_ADDRESS]) != ETH_ALEN) {
			NL_SET_ERR_MSG_ATTR(extack, tb[IFLA_ADDRESS],
					    "Provided link layer address is not Ethernet");
1100
			return -EINVAL;
1101
		}
1102

1103 1104 1105
		if (!is_valid_ether_addr(nla_data(tb[IFLA_ADDRESS]))) {
			NL_SET_ERR_MSG_ATTR(extack, tb[IFLA_ADDRESS],
					    "Provided Ethernet address is not unicast");
1106
			return -EADDRNOTAVAIL;
1107
		}
1108 1109
	}

1110 1111 1112
	if (!data) {
		NL_SET_ERR_MSG(extack,
			       "Not enough attributes provided to perform the operation");
1113
		return -EINVAL;
1114
	}
1115 1116 1117 1118

	if (data[IFLA_GENEVE_ID]) {
		__u32 vni =  nla_get_u32(data[IFLA_GENEVE_ID]);

1119 1120 1121
		if (vni >= GENEVE_N_VID) {
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_ID],
					    "Geneve ID must be lower than 16777216");
1122
			return -ERANGE;
1123
		}
1124 1125 1126 1127 1128
	}

	return 0;
}

1129
static struct geneve_dev *geneve_find_dev(struct geneve_net *gn,
1130
					  const struct ip_tunnel_info *info,
1131 1132 1133
					  bool *tun_on_same_port,
					  bool *tun_collect_md)
{
1134
	struct geneve_dev *geneve, *t = NULL;
1135 1136 1137 1138

	*tun_on_same_port = false;
	*tun_collect_md = false;
	list_for_each_entry(geneve, &gn->geneve_list, next) {
1139
		if (info->key.tp_dst == geneve->info.key.tp_dst) {
1140 1141 1142
			*tun_collect_md = geneve->collect_md;
			*tun_on_same_port = true;
		}
1143 1144 1145
		if (info->key.tun_id == geneve->info.key.tun_id &&
		    info->key.tp_dst == geneve->info.key.tp_dst &&
		    !memcmp(&info->key.u, &geneve->info.key.u, sizeof(info->key.u)))
1146 1147 1148 1149 1150
			t = geneve;
	}
	return t;
}

1151 1152
static bool is_tnl_info_zero(const struct ip_tunnel_info *info)
{
1153 1154 1155
	return !(info->key.tun_id || info->key.tun_flags || info->key.tos ||
		 info->key.ttl || info->key.label || info->key.tp_src ||
		 memchr_inv(&info->key.u, 0, sizeof(info->key.u)));
1156 1157
}

1158 1159 1160 1161 1162 1163 1164 1165 1166
static bool geneve_dst_addr_equal(struct ip_tunnel_info *a,
				  struct ip_tunnel_info *b)
{
	if (ip_tunnel_info_af(a) == AF_INET)
		return a->key.u.ipv4.dst == b->key.u.ipv4.dst;
	else
		return ipv6_addr_equal(&a->key.u.ipv6.dst, &b->key.u.ipv6.dst);
}

1167
static int geneve_configure(struct net *net, struct net_device *dev,
1168
			    struct netlink_ext_ack *extack,
1169 1170
			    const struct ip_tunnel_info *info,
			    bool metadata, bool ipv6_rx_csum)
1171 1172
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);
1173 1174
	struct geneve_dev *t, *geneve = netdev_priv(dev);
	bool tun_collect_md, tun_on_same_port;
P
Paolo Abeni 已提交
1175
	int err, encap_len;
1176

1177 1178 1179
	if (metadata && !is_tnl_info_zero(info)) {
		NL_SET_ERR_MSG(extack,
			       "Device is externally controlled, so attributes (VNI, Port, and so on) must not be specified");
1180
		return -EINVAL;
1181
	}
1182 1183 1184 1185

	geneve->net = net;
	geneve->dev = dev;

1186
	t = geneve_find_dev(gn, info, &tun_on_same_port, &tun_collect_md);
1187 1188 1189
	if (t)
		return -EBUSY;

P
Paolo Abeni 已提交
1190 1191
	/* make enough headroom for basic scenario */
	encap_len = GENEVE_BASE_HLEN + ETH_HLEN;
1192
	if (!metadata && ip_tunnel_info_af(info) == AF_INET) {
P
Paolo Abeni 已提交
1193
		encap_len += sizeof(struct iphdr);
1194 1195
		dev->max_mtu -= sizeof(struct iphdr);
	} else {
P
Paolo Abeni 已提交
1196
		encap_len += sizeof(struct ipv6hdr);
1197 1198
		dev->max_mtu -= sizeof(struct ipv6hdr);
	}
P
Paolo Abeni 已提交
1199 1200
	dev->needed_headroom = encap_len + ETH_HLEN;

1201
	if (metadata) {
1202 1203 1204
		if (tun_on_same_port) {
			NL_SET_ERR_MSG(extack,
				       "There can be only one externally controlled device on a destination port");
1205
			return -EPERM;
1206
		}
1207
	} else {
1208 1209 1210
		if (tun_collect_md) {
			NL_SET_ERR_MSG(extack,
				       "There already exists an externally controlled device on this destination port");
1211
			return -EPERM;
1212
		}
1213 1214
	}

1215 1216 1217 1218
	dst_cache_reset(&geneve->info.dst_cache);
	geneve->info = *info;
	geneve->collect_md = metadata;
	geneve->use_udp6_rx_checksums = ipv6_rx_csum;
P
Paolo Abeni 已提交
1219

1220 1221 1222 1223
	err = register_netdevice(dev);
	if (err)
		return err;

1224 1225 1226 1227
	list_add(&geneve->next, &gn->geneve_list);
	return 0;
}

1228 1229 1230 1231 1232 1233
static void init_tnl_info(struct ip_tunnel_info *info, __u16 dst_port)
{
	memset(info, 0, sizeof(*info));
	info->key.tp_dst = htons(dst_port);
}

1234 1235 1236 1237
static int geneve_nl2info(struct nlattr *tb[], struct nlattr *data[],
			  struct netlink_ext_ack *extack,
			  struct ip_tunnel_info *info, bool *metadata,
			  bool *use_udp6_rx_checksums, bool changelink)
1238
{
1239 1240 1241 1242 1243
	int attrtype;

	if (data[IFLA_GENEVE_REMOTE] && data[IFLA_GENEVE_REMOTE6]) {
		NL_SET_ERR_MSG(extack,
			       "Cannot specify both IPv4 and IPv6 Remote addresses");
1244
		return -EINVAL;
1245
	}
1246 1247

	if (data[IFLA_GENEVE_REMOTE]) {
1248 1249 1250 1251
		if (changelink && (ip_tunnel_info_af(info) == AF_INET6)) {
			attrtype = IFLA_GENEVE_REMOTE;
			goto change_notsup;
		}
1252 1253

		info->key.u.ipv4.dst =
1254
			nla_get_in_addr(data[IFLA_GENEVE_REMOTE]);
1255

1256
		if (IN_MULTICAST(ntohl(info->key.u.ipv4.dst))) {
1257 1258
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE],
					    "Remote IPv4 address cannot be Multicast");
1259 1260
			return -EINVAL;
		}
1261 1262 1263
	}

	if (data[IFLA_GENEVE_REMOTE6]) {
1264
#if IS_ENABLED(CONFIG_IPV6)
1265 1266 1267 1268
		if (changelink && (ip_tunnel_info_af(info) == AF_INET)) {
			attrtype = IFLA_GENEVE_REMOTE6;
			goto change_notsup;
		}
1269 1270 1271

		info->mode = IP_TUNNEL_INFO_IPV6;
		info->key.u.ipv6.dst =
1272 1273
			nla_get_in6_addr(data[IFLA_GENEVE_REMOTE6]);

1274
		if (ipv6_addr_type(&info->key.u.ipv6.dst) &
1275
		    IPV6_ADDR_LINKLOCAL) {
1276 1277
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE6],
					    "Remote IPv6 address cannot be link-local");
1278 1279
			return -EINVAL;
		}
1280
		if (ipv6_addr_is_multicast(&info->key.u.ipv6.dst)) {
1281 1282
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE6],
					    "Remote IPv6 address cannot be Multicast");
1283 1284
			return -EINVAL;
		}
1285 1286
		info->key.tun_flags |= TUNNEL_CSUM;
		*use_udp6_rx_checksums = true;
1287
#else
1288 1289
		NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE6],
				    "IPv6 support not enabled in the kernel");
1290 1291
		return -EPFNOSUPPORT;
#endif
1292 1293
	}

1294 1295 1296
	if (data[IFLA_GENEVE_ID]) {
		__u32 vni;
		__u8 tvni[3];
1297
		__be64 tunid;
1298

1299
		vni = nla_get_u32(data[IFLA_GENEVE_ID]);
1300 1301 1302
		tvni[0] = (vni & 0x00ff0000) >> 16;
		tvni[1] = (vni & 0x0000ff00) >> 8;
		tvni[2] =  vni & 0x000000ff;
1303

1304
		tunid = vni_to_tunnel_id(tvni);
1305 1306 1307 1308
		if (changelink && (tunid != info->key.tun_id)) {
			attrtype = IFLA_GENEVE_ID;
			goto change_notsup;
		}
1309
		info->key.tun_id = tunid;
1310
	}
1311

1312
	if (data[IFLA_GENEVE_TTL])
1313
		info->key.ttl = nla_get_u8(data[IFLA_GENEVE_TTL]);
1314

1315
	if (data[IFLA_GENEVE_TOS])
1316
		info->key.tos = nla_get_u8(data[IFLA_GENEVE_TOS]);
1317

1318
	if (data[IFLA_GENEVE_LABEL]) {
1319
		info->key.label = nla_get_be32(data[IFLA_GENEVE_LABEL]) &
1320
				  IPV6_FLOWLABEL_MASK;
1321 1322 1323
		if (info->key.label && (!(info->mode & IP_TUNNEL_INFO_IPV6))) {
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_LABEL],
					    "Label attribute only applies for IPv6 Geneve devices");
1324
			return -EINVAL;
1325
		}
1326
	}
1327

1328
	if (data[IFLA_GENEVE_PORT]) {
1329 1330 1331 1332
		if (changelink) {
			attrtype = IFLA_GENEVE_PORT;
			goto change_notsup;
		}
1333 1334
		info->key.tp_dst = nla_get_be16(data[IFLA_GENEVE_PORT]);
	}
1335

1336
	if (data[IFLA_GENEVE_COLLECT_METADATA]) {
1337 1338 1339 1340
		if (changelink) {
			attrtype = IFLA_GENEVE_COLLECT_METADATA;
			goto change_notsup;
		}
1341 1342
		*metadata = true;
	}
1343

1344
	if (data[IFLA_GENEVE_UDP_CSUM]) {
1345 1346 1347 1348
		if (changelink) {
			attrtype = IFLA_GENEVE_UDP_CSUM;
			goto change_notsup;
		}
1349 1350 1351
		if (nla_get_u8(data[IFLA_GENEVE_UDP_CSUM]))
			info->key.tun_flags |= TUNNEL_CSUM;
	}
1352

1353
	if (data[IFLA_GENEVE_UDP_ZERO_CSUM6_TX]) {
1354
#if IS_ENABLED(CONFIG_IPV6)
1355 1356 1357 1358
		if (changelink) {
			attrtype = IFLA_GENEVE_UDP_ZERO_CSUM6_TX;
			goto change_notsup;
		}
1359 1360
		if (nla_get_u8(data[IFLA_GENEVE_UDP_ZERO_CSUM6_TX]))
			info->key.tun_flags &= ~TUNNEL_CSUM;
1361 1362 1363 1364 1365
#else
		NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_UDP_ZERO_CSUM6_TX],
				    "IPv6 support not enabled in the kernel");
		return -EPFNOSUPPORT;
#endif
1366
	}
1367

1368
	if (data[IFLA_GENEVE_UDP_ZERO_CSUM6_RX]) {
1369
#if IS_ENABLED(CONFIG_IPV6)
1370 1371 1372 1373
		if (changelink) {
			attrtype = IFLA_GENEVE_UDP_ZERO_CSUM6_RX;
			goto change_notsup;
		}
1374 1375
		if (nla_get_u8(data[IFLA_GENEVE_UDP_ZERO_CSUM6_RX]))
			*use_udp6_rx_checksums = false;
1376 1377 1378 1379 1380
#else
		NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_UDP_ZERO_CSUM6_RX],
				    "IPv6 support not enabled in the kernel");
		return -EPFNOSUPPORT;
#endif
1381 1382 1383
	}

	return 0;
1384 1385 1386 1387
change_notsup:
	NL_SET_ERR_MSG_ATTR(extack, data[attrtype],
			    "Changing VNI, Port, endpoint IP address family, external, and UDP checksum attributes are not supported");
	return -EOPNOTSUPP;
1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399
}

static int geneve_newlink(struct net *net, struct net_device *dev,
			  struct nlattr *tb[], struct nlattr *data[],
			  struct netlink_ext_ack *extack)
{
	bool use_udp6_rx_checksums = false;
	struct ip_tunnel_info info;
	bool metadata = false;
	int err;

	init_tnl_info(&info, GENEVE_UDP_PORT);
1400
	err = geneve_nl2info(tb, data, extack, &info, &metadata,
1401 1402 1403
			     &use_udp6_rx_checksums, false);
	if (err)
		return err;
1404

1405 1406
	return geneve_configure(net, dev, extack, &info, metadata,
				use_udp6_rx_checksums);
1407 1408
}

1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474
/* Quiesces the geneve device data path for both TX and RX.
 *
 * On transmit geneve checks for non-NULL geneve_sock before it proceeds.
 * So, if we set that socket to NULL under RCU and wait for synchronize_net()
 * to complete for the existing set of in-flight packets to be transmitted,
 * then we would have quiesced the transmit data path. All the future packets
 * will get dropped until we unquiesce the data path.
 *
 * On receive geneve dereference the geneve_sock stashed in the socket. So,
 * if we set that to NULL under RCU and wait for synchronize_net() to
 * complete, then we would have quiesced the receive data path.
 */
static void geneve_quiesce(struct geneve_dev *geneve, struct geneve_sock **gs4,
			   struct geneve_sock **gs6)
{
	*gs4 = rtnl_dereference(geneve->sock4);
	rcu_assign_pointer(geneve->sock4, NULL);
	if (*gs4)
		rcu_assign_sk_user_data((*gs4)->sock->sk, NULL);
#if IS_ENABLED(CONFIG_IPV6)
	*gs6 = rtnl_dereference(geneve->sock6);
	rcu_assign_pointer(geneve->sock6, NULL);
	if (*gs6)
		rcu_assign_sk_user_data((*gs6)->sock->sk, NULL);
#else
	*gs6 = NULL;
#endif
	synchronize_net();
}

/* Resumes the geneve device data path for both TX and RX. */
static void geneve_unquiesce(struct geneve_dev *geneve, struct geneve_sock *gs4,
			     struct geneve_sock __maybe_unused *gs6)
{
	rcu_assign_pointer(geneve->sock4, gs4);
	if (gs4)
		rcu_assign_sk_user_data(gs4->sock->sk, gs4);
#if IS_ENABLED(CONFIG_IPV6)
	rcu_assign_pointer(geneve->sock6, gs6);
	if (gs6)
		rcu_assign_sk_user_data(gs6->sock->sk, gs6);
#endif
	synchronize_net();
}

static int geneve_changelink(struct net_device *dev, struct nlattr *tb[],
			     struct nlattr *data[],
			     struct netlink_ext_ack *extack)
{
	struct geneve_dev *geneve = netdev_priv(dev);
	struct geneve_sock *gs4, *gs6;
	struct ip_tunnel_info info;
	bool metadata;
	bool use_udp6_rx_checksums;
	int err;

	/* If the geneve device is configured for metadata (or externally
	 * controlled, for example, OVS), then nothing can be changed.
	 */
	if (geneve->collect_md)
		return -EOPNOTSUPP;

	/* Start with the existing info. */
	memcpy(&info, &geneve->info, sizeof(info));
	metadata = geneve->collect_md;
	use_udp6_rx_checksums = geneve->use_udp6_rx_checksums;
1475
	err = geneve_nl2info(tb, data, extack, &info, &metadata,
1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490 1491
			     &use_udp6_rx_checksums, true);
	if (err)
		return err;

	if (!geneve_dst_addr_equal(&geneve->info, &info))
		dst_cache_reset(&info.dst_cache);

	geneve_quiesce(geneve, &gs4, &gs6);
	geneve->info = info;
	geneve->collect_md = metadata;
	geneve->use_udp6_rx_checksums = use_udp6_rx_checksums;
	geneve_unquiesce(geneve, gs4, gs6);

	return 0;
}

1492 1493 1494 1495 1496 1497 1498 1499 1500 1501 1502
static void geneve_dellink(struct net_device *dev, struct list_head *head)
{
	struct geneve_dev *geneve = netdev_priv(dev);

	list_del(&geneve->next);
	unregister_netdevice_queue(dev, head);
}

static size_t geneve_get_size(const struct net_device *dev)
{
	return nla_total_size(sizeof(__u32)) +	/* IFLA_GENEVE_ID */
1503
		nla_total_size(sizeof(struct in6_addr)) + /* IFLA_GENEVE_REMOTE{6} */
1504
		nla_total_size(sizeof(__u8)) +  /* IFLA_GENEVE_TTL */
1505
		nla_total_size(sizeof(__u8)) +  /* IFLA_GENEVE_TOS */
1506
		nla_total_size(sizeof(__be32)) +  /* IFLA_GENEVE_LABEL */
1507
		nla_total_size(sizeof(__be16)) +  /* IFLA_GENEVE_PORT */
1508
		nla_total_size(0) +	 /* IFLA_GENEVE_COLLECT_METADATA */
1509 1510 1511
		nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_UDP_CSUM */
		nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_UDP_ZERO_CSUM6_TX */
		nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_UDP_ZERO_CSUM6_RX */
1512 1513 1514 1515 1516 1517
		0;
}

static int geneve_fill_info(struct sk_buff *skb, const struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);
1518
	struct ip_tunnel_info *info = &geneve->info;
H
Hangbin Liu 已提交
1519
	bool metadata = geneve->collect_md;
1520
	__u8 tmp_vni[3];
1521 1522
	__u32 vni;

1523 1524
	tunnel_id_to_vni(info->key.tun_id, tmp_vni);
	vni = (tmp_vni[0] << 16) | (tmp_vni[1] << 8) | tmp_vni[2];
1525 1526 1527
	if (nla_put_u32(skb, IFLA_GENEVE_ID, vni))
		goto nla_put_failure;

H
Hangbin Liu 已提交
1528
	if (!metadata && ip_tunnel_info_af(info) == AF_INET) {
1529
		if (nla_put_in_addr(skb, IFLA_GENEVE_REMOTE,
1530 1531 1532 1533
				    info->key.u.ipv4.dst))
			goto nla_put_failure;
		if (nla_put_u8(skb, IFLA_GENEVE_UDP_CSUM,
			       !!(info->key.tun_flags & TUNNEL_CSUM)))
1534
			goto nla_put_failure;
1535

1536
#if IS_ENABLED(CONFIG_IPV6)
H
Hangbin Liu 已提交
1537
	} else if (!metadata) {
1538
		if (nla_put_in6_addr(skb, IFLA_GENEVE_REMOTE6,
1539 1540 1541 1542 1543
				     &info->key.u.ipv6.dst))
			goto nla_put_failure;
		if (nla_put_u8(skb, IFLA_GENEVE_UDP_ZERO_CSUM6_TX,
			       !(info->key.tun_flags & TUNNEL_CSUM)))
			goto nla_put_failure;
1544
#endif
H
Hangbin Liu 已提交
1545
	}
1546

1547 1548 1549
	if (nla_put_u8(skb, IFLA_GENEVE_TTL, info->key.ttl) ||
	    nla_put_u8(skb, IFLA_GENEVE_TOS, info->key.tos) ||
	    nla_put_be32(skb, IFLA_GENEVE_LABEL, info->key.label))
1550 1551
		goto nla_put_failure;

1552
	if (nla_put_be16(skb, IFLA_GENEVE_PORT, info->key.tp_dst))
1553 1554
		goto nla_put_failure;

H
Hangbin Liu 已提交
1555
	if (metadata && nla_put_flag(skb, IFLA_GENEVE_COLLECT_METADATA))
1556
		goto nla_put_failure;
H
Hangbin Liu 已提交
1557

1558
#if IS_ENABLED(CONFIG_IPV6)
H
Hangbin Liu 已提交
1559 1560 1561
	if (nla_put_u8(skb, IFLA_GENEVE_UDP_ZERO_CSUM6_RX,
		       !geneve->use_udp6_rx_checksums))
		goto nla_put_failure;
1562
#endif
H
Hangbin Liu 已提交
1563

1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577
	return 0;

nla_put_failure:
	return -EMSGSIZE;
}

static struct rtnl_link_ops geneve_link_ops __read_mostly = {
	.kind		= "geneve",
	.maxtype	= IFLA_GENEVE_MAX,
	.policy		= geneve_policy,
	.priv_size	= sizeof(struct geneve_dev),
	.setup		= geneve_setup,
	.validate	= geneve_validate,
	.newlink	= geneve_newlink,
1578
	.changelink	= geneve_changelink,
1579 1580 1581 1582 1583
	.dellink	= geneve_dellink,
	.get_size	= geneve_get_size,
	.fill_info	= geneve_fill_info,
};

1584 1585 1586 1587
struct net_device *geneve_dev_create_fb(struct net *net, const char *name,
					u8 name_assign_type, u16 dst_port)
{
	struct nlattr *tb[IFLA_MAX + 1];
1588
	struct ip_tunnel_info info;
1589
	struct net_device *dev;
1590
	LIST_HEAD(list_kill);
1591 1592 1593 1594 1595 1596 1597 1598
	int err;

	memset(tb, 0, sizeof(tb));
	dev = rtnl_create_link(net, name, name_assign_type,
			       &geneve_link_ops, tb);
	if (IS_ERR(dev))
		return dev;

1599
	init_tnl_info(&info, dst_port);
1600
	err = geneve_configure(net, dev, NULL, &info, true, true);
1601 1602 1603 1604
	if (err) {
		free_netdev(dev);
		return ERR_PTR(err);
	}
1605 1606 1607 1608

	/* openvswitch users expect packet sizes to be unrestricted,
	 * so set the largest MTU we can.
	 */
1609
	err = geneve_change_mtu(dev, IP_MAX_MTU);
1610 1611 1612
	if (err)
		goto err;

1613 1614 1615 1616
	err = rtnl_configure_link(dev, NULL);
	if (err < 0)
		goto err;

1617
	return dev;
1618
err:
1619 1620
	geneve_dellink(dev, &list_kill);
	unregister_netdevice_many(&list_kill);
1621
	return ERR_PTR(err);
1622 1623 1624
}
EXPORT_SYMBOL_GPL(geneve_dev_create_fb);

1625 1626 1627 1628 1629
static int geneve_netdevice_event(struct notifier_block *unused,
				  unsigned long event, void *ptr)
{
	struct net_device *dev = netdev_notifier_info_to_dev(ptr);

1630
	if (event == NETDEV_UDP_TUNNEL_PUSH_INFO ||
1631
	    event == NETDEV_UDP_TUNNEL_DROP_INFO) {
1632
		geneve_offload_rx_ports(dev, event == NETDEV_UDP_TUNNEL_PUSH_INFO);
1633 1634 1635 1636 1637
	} else if (event == NETDEV_UNREGISTER) {
		geneve_offload_rx_ports(dev, false);
	} else if (event == NETDEV_REGISTER) {
		geneve_offload_rx_ports(dev, true);
	}
1638 1639 1640 1641 1642 1643 1644 1645

	return NOTIFY_DONE;
}

static struct notifier_block geneve_notifier_block __read_mostly = {
	.notifier_call = geneve_netdevice_event,
};

1646 1647 1648 1649 1650
static __net_init int geneve_init_net(struct net *net)
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);

	INIT_LIST_HEAD(&gn->geneve_list);
1651
	INIT_LIST_HEAD(&gn->sock_list);
1652 1653 1654
	return 0;
}

1655
static void geneve_destroy_tunnels(struct net *net, struct list_head *head)
1656 1657 1658 1659 1660 1661 1662 1663
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);
	struct geneve_dev *geneve, *next;
	struct net_device *dev, *aux;

	/* gather any geneve devices that were moved into this ns */
	for_each_netdev_safe(net, dev, aux)
		if (dev->rtnl_link_ops == &geneve_link_ops)
1664
			unregister_netdevice_queue(dev, head);
1665 1666 1667 1668 1669 1670 1671

	/* now gather any other geneve devices that were created in this ns */
	list_for_each_entry_safe(geneve, next, &gn->geneve_list, next) {
		/* If geneve->dev is in the same netns, it was already added
		 * to the list by the previous loop.
		 */
		if (!net_eq(dev_net(geneve->dev), net))
1672
			unregister_netdevice_queue(geneve->dev, head);
1673 1674
	}

1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686
	WARN_ON_ONCE(!list_empty(&gn->sock_list));
}

static void __net_exit geneve_exit_batch_net(struct list_head *net_list)
{
	struct net *net;
	LIST_HEAD(list);

	rtnl_lock();
	list_for_each_entry(net, net_list, exit_list)
		geneve_destroy_tunnels(net, &list);

1687 1688 1689 1690 1691 1692 1693
	/* unregister the devices gathered above */
	unregister_netdevice_many(&list);
	rtnl_unlock();
}

static struct pernet_operations geneve_net_ops = {
	.init = geneve_init_net,
1694
	.exit_batch = geneve_exit_batch_net,
1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706
	.id   = &geneve_net_id,
	.size = sizeof(struct geneve_net),
};

static int __init geneve_init_module(void)
{
	int rc;

	rc = register_pernet_subsys(&geneve_net_ops);
	if (rc)
		goto out1;

1707
	rc = register_netdevice_notifier(&geneve_notifier_block);
1708 1709 1710
	if (rc)
		goto out2;

1711 1712 1713 1714
	rc = rtnl_link_register(&geneve_link_ops);
	if (rc)
		goto out3;

1715
	return 0;
1716 1717
out3:
	unregister_netdevice_notifier(&geneve_notifier_block);
1718 1719 1720 1721 1722 1723 1724 1725 1726 1727
out2:
	unregister_pernet_subsys(&geneve_net_ops);
out1:
	return rc;
}
late_initcall(geneve_init_module);

static void __exit geneve_cleanup_module(void)
{
	rtnl_link_unregister(&geneve_link_ops);
1728
	unregister_netdevice_notifier(&geneve_notifier_block);
1729 1730 1731 1732 1733 1734 1735 1736 1737
	unregister_pernet_subsys(&geneve_net_ops);
}
module_exit(geneve_cleanup_module);

MODULE_LICENSE("GPL");
MODULE_VERSION(GENEVE_NETDEV_VER);
MODULE_AUTHOR("John W. Linville <linville@tuxdriver.com>");
MODULE_DESCRIPTION("Interface driver for GENEVE encapsulated traffic");
MODULE_ALIAS_RTNL_LINK("geneve");