act_api.c 40.3 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
/*
 * net/sched/act_api.c	Packet action API.
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 *
 * Author:	Jamal Hadi Salim
 *
 *
 */

#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/string.h>
#include <linux/errno.h>
18
#include <linux/slab.h>
L
Linus Torvalds 已提交
19 20 21
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/kmod.h>
22
#include <linux/err.h>
23
#include <linux/module.h>
24 25
#include <linux/rhashtable.h>
#include <linux/list.h>
26 27
#include <net/net_namespace.h>
#include <net/sock.h>
L
Linus Torvalds 已提交
28
#include <net/sch_generic.h>
29
#include <net/pkt_cls.h>
L
Linus Torvalds 已提交
30
#include <net/act_api.h>
31
#include <net/netlink.h>
L
Linus Torvalds 已提交
32

33 34 35 36 37 38
static int tcf_action_goto_chain_init(struct tc_action *a, struct tcf_proto *tp)
{
	u32 chain_index = a->tcfa_action & TC_ACT_EXT_VAL_MASK;

	if (!tp)
		return -EINVAL;
39
	a->goto_chain = tcf_chain_get(tp->chain->block, chain_index, true);
40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57
	if (!a->goto_chain)
		return -ENOMEM;
	return 0;
}

static void tcf_action_goto_chain_fini(struct tc_action *a)
{
	tcf_chain_put(a->goto_chain);
}

static void tcf_action_goto_chain_exec(const struct tc_action *a,
				       struct tcf_result *res)
{
	const struct tcf_chain *chain = a->goto_chain;

	res->goto_tp = rcu_dereference_bh(chain->filter_chain);
}

58 59 60 61 62 63 64 65 66 67 68 69 70
static void tcf_free_cookie_rcu(struct rcu_head *p)
{
	struct tc_cookie *cookie = container_of(p, struct tc_cookie, rcu);

	kfree(cookie->data);
	kfree(cookie);
}

static void tcf_set_action_cookie(struct tc_cookie __rcu **old_cookie,
				  struct tc_cookie *new_cookie)
{
	struct tc_cookie *old;

71
	old = xchg((__force struct tc_cookie **)old_cookie, new_cookie);
72 73 74 75
	if (old)
		call_rcu(&old->rcu, tcf_free_cookie_rcu);
}

C
Cong Wang 已提交
76 77 78 79 80 81
/* XXX: For standalone actions, we don't need a RCU grace period either, because
 * actions are always connected to filters and filters are already destroyed in
 * RCU callbacks, so after a RCU grace period actions are already disconnected
 * from filters. Readers later can not find us.
 */
static void free_tcf(struct tc_action *p)
82 83 84
{
	free_percpu(p->cpu_bstats);
	free_percpu(p->cpu_qstats);
85

86
	tcf_set_action_cookie(&p->act_cookie, NULL);
87 88
	if (p->goto_chain)
		tcf_action_goto_chain_fini(p);
89

90 91 92
	kfree(p);
}

93
static void tcf_action_cleanup(struct tc_action *p)
94
{
95 96 97
	if (p->ops->cleanup)
		p->ops->cleanup(p);

98
	gen_kill_estimator(&p->tcfa_rate_est);
C
Cong Wang 已提交
99
	free_tcf(p);
100 101
}

102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121
static int __tcf_action_put(struct tc_action *p, bool bind)
{
	struct tcf_idrinfo *idrinfo = p->idrinfo;

	if (refcount_dec_and_lock(&p->tcfa_refcnt, &idrinfo->lock)) {
		if (bind)
			atomic_dec(&p->tcfa_bindcnt);
		idr_remove(&idrinfo->action_idr, p->tcfa_index);
		spin_unlock(&idrinfo->lock);

		tcf_action_cleanup(p);
		return 1;
	}

	if (bind)
		atomic_dec(&p->tcfa_bindcnt);

	return 0;
}

122
int __tcf_idr_release(struct tc_action *p, bool bind, bool strict)
123 124 125
{
	int ret = 0;

126 127 128 129 130 131 132 133 134 135 136 137
	/* Release with strict==1 and bind==0 is only called through act API
	 * interface (classifiers always bind). Only case when action with
	 * positive reference count and zero bind count can exist is when it was
	 * also created with act API (unbinding last classifier will destroy the
	 * action if it was created by classifier). So only case when bind count
	 * can be changed after initial check is when unbound action is
	 * destroyed by act API while classifier binds to action with same id
	 * concurrently. This result either creation of new action(same behavior
	 * as before), or reusing existing action if concurrent process
	 * increments reference count before action is deleted. Both scenarios
	 * are acceptable.
	 */
138
	if (p) {
139
		if (!bind && strict && atomic_read(&p->tcfa_bindcnt) > 0)
140
			return -EPERM;
141

142
		if (__tcf_action_put(p, bind))
143
			ret = ACT_P_DELETED;
144
	}
145

146 147
	return ret;
}
148
EXPORT_SYMBOL(__tcf_idr_release);
149

150 151
static size_t tcf_action_shared_attrs_size(const struct tc_action *act)
{
152
	struct tc_cookie *act_cookie;
153 154
	u32 cookie_len = 0;

155 156 157 158 159 160
	rcu_read_lock();
	act_cookie = rcu_dereference(act->act_cookie);

	if (act_cookie)
		cookie_len = nla_total_size(act_cookie->len);
	rcu_read_unlock();
161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190

	return  nla_total_size(0) /* action number nested */
		+ nla_total_size(IFNAMSIZ) /* TCA_ACT_KIND */
		+ cookie_len /* TCA_ACT_COOKIE */
		+ nla_total_size(0) /* TCA_ACT_STATS nested */
		/* TCA_STATS_BASIC */
		+ nla_total_size_64bit(sizeof(struct gnet_stats_basic))
		/* TCA_STATS_QUEUE */
		+ nla_total_size_64bit(sizeof(struct gnet_stats_queue))
		+ nla_total_size(0) /* TCA_OPTIONS nested */
		+ nla_total_size(sizeof(struct tcf_t)); /* TCA_GACT_TM */
}

static size_t tcf_action_full_attrs_size(size_t sz)
{
	return NLMSG_HDRLEN                     /* struct nlmsghdr */
		+ sizeof(struct tcamsg)
		+ nla_total_size(0)             /* TCA_ACT_TAB nested */
		+ sz;
}

static size_t tcf_action_fill_size(const struct tc_action *act)
{
	size_t sz = tcf_action_shared_attrs_size(act);

	if (act->ops->get_fill_size)
		return act->ops->get_fill_size(act) + sz;
	return sz;
}

191
static int tcf_dump_walker(struct tcf_idrinfo *idrinfo, struct sk_buff *skb,
192
			   struct netlink_callback *cb)
193
{
194
	int err = 0, index = -1, s_i = 0, n_i = 0;
195
	u32 act_flags = cb->args[2];
196
	unsigned long jiffy_since = cb->args[3];
197
	struct nlattr *nest;
198 199 200
	struct idr *idr = &idrinfo->action_idr;
	struct tc_action *p;
	unsigned long id = 1;
201

202
	spin_lock(&idrinfo->lock);
203 204 205

	s_i = cb->args[0];

206
	idr_for_each_entry_ul(idr, p, id) {
207 208 209 210 211 212 213 214 215 216
		index++;
		if (index < s_i)
			continue;

		if (jiffy_since &&
		    time_after(jiffy_since,
			       (unsigned long)p->tcfa_tm.lastuse))
			continue;

		nest = nla_nest_start(skb, n_i);
217 218
		if (!nest) {
			index--;
219
			goto nla_put_failure;
220
		}
221 222 223 224 225
		err = tcf_action_dump_1(skb, p, 0, 0);
		if (err < 0) {
			index--;
			nlmsg_trim(skb, nest);
			goto done;
226
		}
227 228 229 230 231
		nla_nest_end(skb, nest);
		n_i++;
		if (!(act_flags & TCA_FLAG_LARGE_DUMP_ON) &&
		    n_i >= TCA_ACT_MAX_PRIO)
			goto done;
232 233
	}
done:
234 235 236
	if (index >= 0)
		cb->args[0] = index + 1;

237
	spin_unlock(&idrinfo->lock);
238 239 240 241
	if (n_i) {
		if (act_flags & TCA_FLAG_LARGE_DUMP_ON)
			cb->args[1] = n_i;
	}
242 243
	return n_i;

244
nla_put_failure:
245
	nla_nest_cancel(skb, nest);
246 247 248
	goto done;
}

249
static int tcf_del_walker(struct tcf_idrinfo *idrinfo, struct sk_buff *skb,
250
			  const struct tc_action_ops *ops)
251
{
252
	struct nlattr *nest;
253
	int n_i = 0;
254
	int ret = -EINVAL;
255 256 257
	struct idr *idr = &idrinfo->action_idr;
	struct tc_action *p;
	unsigned long id = 1;
258

259
	nest = nla_nest_start(skb, 0);
260 261
	if (nest == NULL)
		goto nla_put_failure;
262
	if (nla_put_string(skb, TCA_KIND, ops->kind))
263
		goto nla_put_failure;
264

265
	idr_for_each_entry_ul(idr, p, id) {
266 267
		ret = __tcf_idr_release(p, false, true);
		if (ret == ACT_P_DELETED) {
268
			module_put(ops->owner);
269 270 271
			n_i++;
		} else if (ret < 0) {
			goto nla_put_failure;
272 273
		}
	}
274 275
	if (nla_put_u32(skb, TCA_FCNT, n_i))
		goto nla_put_failure;
276
	nla_nest_end(skb, nest);
277 278

	return n_i;
279
nla_put_failure:
280
	nla_nest_cancel(skb, nest);
281
	return ret;
282 283
}

284 285
int tcf_generic_walker(struct tc_action_net *tn, struct sk_buff *skb,
		       struct netlink_callback *cb, int type,
286 287
		       const struct tc_action_ops *ops,
		       struct netlink_ext_ack *extack)
288
{
289
	struct tcf_idrinfo *idrinfo = tn->idrinfo;
290

291
	if (type == RTM_DELACTION) {
292
		return tcf_del_walker(idrinfo, skb, ops);
293
	} else if (type == RTM_GETACTION) {
294
		return tcf_dump_walker(idrinfo, skb, cb);
295
	} else {
296 297
		WARN(1, "tcf_generic_walker: unknown command %d\n", type);
		NL_SET_ERR_MSG(extack, "tcf_generic_walker: unknown command");
298 299 300
		return -EINVAL;
	}
}
301
EXPORT_SYMBOL(tcf_generic_walker);
302

303 304
static bool __tcf_idr_check(struct tc_action_net *tn, u32 index,
			    struct tc_action **a, int bind)
305
{
306 307
	struct tcf_idrinfo *idrinfo = tn->idrinfo;
	struct tc_action *p;
308

309
	spin_lock(&idrinfo->lock);
310
	p = idr_find(&idrinfo->action_idr, index);
311 312 313
	if (IS_ERR(p)) {
		p = NULL;
	} else if (p) {
314 315 316 317
		refcount_inc(&p->tcfa_refcnt);
		if (bind)
			atomic_inc(&p->tcfa_bindcnt);
	}
318
	spin_unlock(&idrinfo->lock);
319

320 321 322 323 324
	if (p) {
		*a = p;
		return true;
	}
	return false;
325 326
}

327
int tcf_idr_search(struct tc_action_net *tn, struct tc_action **a, u32 index)
328
{
329
	return __tcf_idr_check(tn, index, a, 0);
330
}
331
EXPORT_SYMBOL(tcf_idr_search);
332

333 334
bool tcf_idr_check(struct tc_action_net *tn, u32 index, struct tc_action **a,
		   int bind)
335
{
336
	return __tcf_idr_check(tn, index, a, bind);
337
}
338
EXPORT_SYMBOL(tcf_idr_check);
339

340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360
int tcf_idr_delete_index(struct tc_action_net *tn, u32 index)
{
	struct tcf_idrinfo *idrinfo = tn->idrinfo;
	struct tc_action *p;
	int ret = 0;

	spin_lock(&idrinfo->lock);
	p = idr_find(&idrinfo->action_idr, index);
	if (!p) {
		spin_unlock(&idrinfo->lock);
		return -ENOENT;
	}

	if (!atomic_read(&p->tcfa_bindcnt)) {
		if (refcount_dec_and_test(&p->tcfa_refcnt)) {
			struct module *owner = p->ops->owner;

			WARN_ON(p != idr_remove(&idrinfo->action_idr,
						p->tcfa_index));
			spin_unlock(&idrinfo->lock);

361
			tcf_action_cleanup(p);
362 363 364 365 366 367 368 369 370 371 372 373 374
			module_put(owner);
			return 0;
		}
		ret = 0;
	} else {
		ret = -EPERM;
	}

	spin_unlock(&idrinfo->lock);
	return ret;
}
EXPORT_SYMBOL(tcf_idr_delete_index);

375 376 377
int tcf_idr_create(struct tc_action_net *tn, u32 index, struct nlattr *est,
		   struct tc_action **a, const struct tc_action_ops *ops,
		   int bind, bool cpustats)
378
{
379
	struct tc_action *p = kzalloc(ops->size, GFP_KERNEL);
380
	struct tcf_idrinfo *idrinfo = tn->idrinfo;
381
	int err = -ENOMEM;
382 383

	if (unlikely(!p))
384
		return -ENOMEM;
385
	refcount_set(&p->tcfa_refcnt, 1);
386
	if (bind)
387
		atomic_set(&p->tcfa_bindcnt, 1);
388

389 390
	if (cpustats) {
		p->cpu_bstats = netdev_alloc_pcpu_stats(struct gnet_stats_basic_cpu);
391
		if (!p->cpu_bstats)
392
			goto err1;
393 394 395
		p->cpu_qstats = alloc_percpu(struct gnet_stats_queue);
		if (!p->cpu_qstats)
			goto err2;
396
	}
397
	spin_lock_init(&p->tcfa_lock);
398
	p->tcfa_index = index;
399 400 401
	p->tcfa_tm.install = jiffies;
	p->tcfa_tm.lastuse = jiffies;
	p->tcfa_tm.firstuse = 0;
402
	if (est) {
403 404 405
		err = gen_new_estimator(&p->tcfa_bstats, p->cpu_bstats,
					&p->tcfa_rate_est,
					&p->tcfa_lock, NULL, est);
406
		if (err)
407
			goto err3;
408 409
	}

410
	p->idrinfo = idrinfo;
411 412 413
	p->ops = ops;
	INIT_LIST_HEAD(&p->list);
	*a = p;
414
	return 0;
415 416 417 418 419 420 421
err3:
	free_percpu(p->cpu_qstats);
err2:
	free_percpu(p->cpu_bstats);
err1:
	kfree(p);
	return err;
422
}
423
EXPORT_SYMBOL(tcf_idr_create);
424

425
void tcf_idr_insert(struct tc_action_net *tn, struct tc_action *a)
426
{
427
	struct tcf_idrinfo *idrinfo = tn->idrinfo;
428

429
	spin_lock(&idrinfo->lock);
430 431
	/* Replace ERR_PTR(-EBUSY) allocated by tcf_idr_check_alloc */
	WARN_ON(!IS_ERR(idr_replace(&idrinfo->action_idr, a, a->tcfa_index)));
432
	spin_unlock(&idrinfo->lock);
433
}
434
EXPORT_SYMBOL(tcf_idr_insert);
L
Linus Torvalds 已提交
435

436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501
/* Cleanup idr index that was allocated but not initialized. */

void tcf_idr_cleanup(struct tc_action_net *tn, u32 index)
{
	struct tcf_idrinfo *idrinfo = tn->idrinfo;

	spin_lock(&idrinfo->lock);
	/* Remove ERR_PTR(-EBUSY) allocated by tcf_idr_check_alloc */
	WARN_ON(!IS_ERR(idr_remove(&idrinfo->action_idr, index)));
	spin_unlock(&idrinfo->lock);
}
EXPORT_SYMBOL(tcf_idr_cleanup);

/* Check if action with specified index exists. If actions is found, increments
 * its reference and bind counters, and return 1. Otherwise insert temporary
 * error pointer (to prevent concurrent users from inserting actions with same
 * index) and return 0.
 */

int tcf_idr_check_alloc(struct tc_action_net *tn, u32 *index,
			struct tc_action **a, int bind)
{
	struct tcf_idrinfo *idrinfo = tn->idrinfo;
	struct tc_action *p;
	int ret;

again:
	spin_lock(&idrinfo->lock);
	if (*index) {
		p = idr_find(&idrinfo->action_idr, *index);
		if (IS_ERR(p)) {
			/* This means that another process allocated
			 * index but did not assign the pointer yet.
			 */
			spin_unlock(&idrinfo->lock);
			goto again;
		}

		if (p) {
			refcount_inc(&p->tcfa_refcnt);
			if (bind)
				atomic_inc(&p->tcfa_bindcnt);
			*a = p;
			ret = 1;
		} else {
			*a = NULL;
			ret = idr_alloc_u32(&idrinfo->action_idr, NULL, index,
					    *index, GFP_ATOMIC);
			if (!ret)
				idr_replace(&idrinfo->action_idr,
					    ERR_PTR(-EBUSY), *index);
		}
	} else {
		*index = 1;
		*a = NULL;
		ret = idr_alloc_u32(&idrinfo->action_idr, NULL, index,
				    UINT_MAX, GFP_ATOMIC);
		if (!ret)
			idr_replace(&idrinfo->action_idr, ERR_PTR(-EBUSY),
				    *index);
	}
	spin_unlock(&idrinfo->lock);
	return ret;
}
EXPORT_SYMBOL(tcf_idr_check_alloc);

502 503
void tcf_idrinfo_destroy(const struct tc_action_ops *ops,
			 struct tcf_idrinfo *idrinfo)
504
{
505 506 507 508
	struct idr *idr = &idrinfo->action_idr;
	struct tc_action *p;
	int ret;
	unsigned long id = 1;
509

510
	idr_for_each_entry_ul(idr, p, id) {
511 512 513 514 515
		ret = __tcf_idr_release(p, false, true);
		if (ret == ACT_P_DELETED)
			module_put(ops->owner);
		else if (ret < 0)
			return;
516
	}
517
	idr_destroy(&idrinfo->action_idr);
518
}
519
EXPORT_SYMBOL(tcf_idrinfo_destroy);
520

521
static LIST_HEAD(act_base);
L
Linus Torvalds 已提交
522 523
static DEFINE_RWLOCK(act_mod_lock);

524 525
int tcf_register_action(struct tc_action_ops *act,
			struct pernet_operations *ops)
L
Linus Torvalds 已提交
526
{
527
	struct tc_action_ops *a;
528
	int ret;
L
Linus Torvalds 已提交
529

530
	if (!act->act || !act->dump || !act->init || !act->walk || !act->lookup)
531 532
		return -EINVAL;

533 534 535 536 537 538 539 540
	/* We have to register pernet ops before making the action ops visible,
	 * otherwise tcf_action_init_1() could get a partially initialized
	 * netns.
	 */
	ret = register_pernet_subsys(ops);
	if (ret)
		return ret;

L
Linus Torvalds 已提交
541
	write_lock(&act_mod_lock);
542
	list_for_each_entry(a, &act_base, head) {
L
Linus Torvalds 已提交
543 544
		if (act->type == a->type || (strcmp(act->kind, a->kind) == 0)) {
			write_unlock(&act_mod_lock);
545
			unregister_pernet_subsys(ops);
L
Linus Torvalds 已提交
546 547 548
			return -EEXIST;
		}
	}
549
	list_add_tail(&act->head, &act_base);
L
Linus Torvalds 已提交
550
	write_unlock(&act_mod_lock);
551

L
Linus Torvalds 已提交
552 553
	return 0;
}
554
EXPORT_SYMBOL(tcf_register_action);
L
Linus Torvalds 已提交
555

556 557
int tcf_unregister_action(struct tc_action_ops *act,
			  struct pernet_operations *ops)
L
Linus Torvalds 已提交
558
{
559
	struct tc_action_ops *a;
L
Linus Torvalds 已提交
560 561 562
	int err = -ENOENT;

	write_lock(&act_mod_lock);
563 564 565 566
	list_for_each_entry(a, &act_base, head) {
		if (a == act) {
			list_del(&act->head);
			err = 0;
L
Linus Torvalds 已提交
567
			break;
568
		}
L
Linus Torvalds 已提交
569 570
	}
	write_unlock(&act_mod_lock);
571 572
	if (!err)
		unregister_pernet_subsys(ops);
L
Linus Torvalds 已提交
573 574
	return err;
}
575
EXPORT_SYMBOL(tcf_unregister_action);
L
Linus Torvalds 已提交
576 577 578 579

/* lookup by name */
static struct tc_action_ops *tc_lookup_action_n(char *kind)
{
580
	struct tc_action_ops *a, *res = NULL;
L
Linus Torvalds 已提交
581 582 583

	if (kind) {
		read_lock(&act_mod_lock);
584
		list_for_each_entry(a, &act_base, head) {
L
Linus Torvalds 已提交
585
			if (strcmp(kind, a->kind) == 0) {
586 587
				if (try_module_get(a->owner))
					res = a;
L
Linus Torvalds 已提交
588 589 590 591 592
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
593
	return res;
L
Linus Torvalds 已提交
594 595
}

596 597
/* lookup by nlattr */
static struct tc_action_ops *tc_lookup_action(struct nlattr *kind)
L
Linus Torvalds 已提交
598
{
599
	struct tc_action_ops *a, *res = NULL;
L
Linus Torvalds 已提交
600 601 602

	if (kind) {
		read_lock(&act_mod_lock);
603
		list_for_each_entry(a, &act_base, head) {
604
			if (nla_strcmp(kind, a->kind) == 0) {
605 606
				if (try_module_get(a->owner))
					res = a;
L
Linus Torvalds 已提交
607 608 609 610 611
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
612
	return res;
L
Linus Torvalds 已提交
613 614
}

615 616
/*TCA_ACT_MAX_PRIO is 32, there count upto 32 */
#define TCA_ACT_MAX_PRIO_MASK 0x1FF
617 618
int tcf_action_exec(struct sk_buff *skb, struct tc_action **actions,
		    int nr_actions, struct tcf_result *res)
L
Linus Torvalds 已提交
619
{
620 621
	u32 jmp_prgcnt = 0;
	u32 jmp_ttl = TCA_ACT_MAX_PRIO; /*matches actions per filter */
622 623
	int i;
	int ret = TC_ACT_OK;
L
Linus Torvalds 已提交
624

625 626 627
	if (skb_skip_tc_classify(skb))
		return TC_ACT_OK;

628
restart_act_graph:
629 630 631
	for (i = 0; i < nr_actions; i++) {
		const struct tc_action *a = actions[i];

632 633 634 635
		if (jmp_prgcnt > 0) {
			jmp_prgcnt -= 1;
			continue;
		}
L
Linus Torvalds 已提交
636
repeat:
637 638 639
		ret = a->ops->act(skb, a, res);
		if (ret == TC_ACT_REPEAT)
			goto repeat;	/* we need a ttl - JHS */
640

641
		if (TC_ACT_EXT_CMP(ret, TC_ACT_JUMP)) {
642 643 644 645 646 647 648 649 650 651 652
			jmp_prgcnt = ret & TCA_ACT_MAX_PRIO_MASK;
			if (!jmp_prgcnt || (jmp_prgcnt > nr_actions)) {
				/* faulty opcode, stop pipeline */
				return TC_ACT_OK;
			} else {
				jmp_ttl -= 1;
				if (jmp_ttl > 0)
					goto restart_act_graph;
				else /* faulty graph, stop pipeline */
					return TC_ACT_OK;
			}
653 654
		} else if (TC_ACT_EXT_CMP(ret, TC_ACT_GOTO_CHAIN)) {
			tcf_action_goto_chain_exec(a, res);
655 656
		}

657
		if (ret != TC_ACT_PIPE)
658
			break;
L
Linus Torvalds 已提交
659
	}
660

L
Linus Torvalds 已提交
661 662
	return ret;
}
663
EXPORT_SYMBOL(tcf_action_exec);
L
Linus Torvalds 已提交
664

665
int tcf_action_destroy(struct tc_action *actions[], int bind)
L
Linus Torvalds 已提交
666
{
667
	const struct tc_action_ops *ops;
668 669
	struct tc_action *a;
	int ret = 0, i;
L
Linus Torvalds 已提交
670

671 672 673
	for (i = 0; i < TCA_ACT_MAX_PRIO && actions[i]; i++) {
		a = actions[i];
		actions[i] = NULL;
674
		ops = a->ops;
675
		ret = __tcf_idr_release(a, bind, true);
676
		if (ret == ACT_P_DELETED)
677
			module_put(ops->owner);
678 679
		else if (ret < 0)
			return ret;
L
Linus Torvalds 已提交
680
	}
681
	return ret;
L
Linus Torvalds 已提交
682 683
}

684 685 686 687 688
static int tcf_action_put(struct tc_action *p)
{
	return __tcf_action_put(p, false);
}

689
static void tcf_action_put_many(struct tc_action *actions[])
690
{
691
	int i;
692

693 694
	for (i = 0; i < TCA_ACT_MAX_PRIO && actions[i]; i++) {
		struct tc_action *a = actions[i];
695 696 697 698 699 700 701
		const struct tc_action_ops *ops = a->ops;

		if (tcf_action_put(a))
			module_put(ops->owner);
	}
}

L
Linus Torvalds 已提交
702 703 704 705 706 707 708 709 710 711
int
tcf_action_dump_old(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{
	return a->ops->dump(skb, a, bind, ref);
}

int
tcf_action_dump_1(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{
	int err = -EINVAL;
712
	unsigned char *b = skb_tail_pointer(skb);
713
	struct nlattr *nest;
714
	struct tc_cookie *cookie;
L
Linus Torvalds 已提交
715

716 717
	if (nla_put_string(skb, TCA_KIND, a->ops->kind))
		goto nla_put_failure;
L
Linus Torvalds 已提交
718
	if (tcf_action_copy_stats(skb, a, 0))
719
		goto nla_put_failure;
720 721 722 723 724 725

	rcu_read_lock();
	cookie = rcu_dereference(a->act_cookie);
	if (cookie) {
		if (nla_put(skb, TCA_ACT_COOKIE, cookie->len, cookie->data)) {
			rcu_read_unlock();
726
			goto nla_put_failure;
727
		}
728
	}
729
	rcu_read_unlock();
730

731 732 733
	nest = nla_nest_start(skb, TCA_OPTIONS);
	if (nest == NULL)
		goto nla_put_failure;
E
Eric Dumazet 已提交
734 735
	err = tcf_action_dump_old(skb, a, bind, ref);
	if (err > 0) {
736
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
737 738 739
		return err;
	}

740
nla_put_failure:
741
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
742 743
	return -1;
}
744
EXPORT_SYMBOL(tcf_action_dump_1);
L
Linus Torvalds 已提交
745

746
int tcf_action_dump(struct sk_buff *skb, struct tc_action *actions[],
747
		    int bind, int ref)
L
Linus Torvalds 已提交
748 749
{
	struct tc_action *a;
750
	int err = -EINVAL, i;
751
	struct nlattr *nest;
L
Linus Torvalds 已提交
752

753 754
	for (i = 0; i < TCA_ACT_MAX_PRIO && actions[i]; i++) {
		a = actions[i];
755 756 757
		nest = nla_nest_start(skb, a->order);
		if (nest == NULL)
			goto nla_put_failure;
L
Linus Torvalds 已提交
758 759
		err = tcf_action_dump_1(skb, a, bind, ref);
		if (err < 0)
760
			goto errout;
761
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
762 763 764 765
	}

	return 0;

766
nla_put_failure:
767 768
	err = -EINVAL;
errout:
769
	nla_nest_cancel(skb, nest);
770
	return err;
L
Linus Torvalds 已提交
771 772
}

773
static struct tc_cookie *nla_memdup_cookie(struct nlattr **tb)
774
{
775 776 777 778 779 780 781 782
	struct tc_cookie *c = kzalloc(sizeof(*c), GFP_KERNEL);
	if (!c)
		return NULL;

	c->data = nla_memdup(tb[TCA_ACT_COOKIE], GFP_KERNEL);
	if (!c->data) {
		kfree(c);
		return NULL;
783
	}
784
	c->len = nla_len(tb[TCA_ACT_COOKIE]);
785

786
	return c;
787 788
}

789 790
struct tc_action *tcf_action_init_1(struct net *net, struct tcf_proto *tp,
				    struct nlattr *nla, struct nlattr *est,
791
				    char *name, int ovr, int bind,
792
				    bool rtnl_held,
793
				    struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
794 795 796
{
	struct tc_action *a;
	struct tc_action_ops *a_o;
797
	struct tc_cookie *cookie = NULL;
L
Linus Torvalds 已提交
798
	char act_name[IFNAMSIZ];
E
Eric Dumazet 已提交
799
	struct nlattr *tb[TCA_ACT_MAX + 1];
800
	struct nlattr *kind;
801
	int err;
L
Linus Torvalds 已提交
802 803

	if (name == NULL) {
804
		err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL, extack);
805
		if (err < 0)
L
Linus Torvalds 已提交
806
			goto err_out;
807
		err = -EINVAL;
808
		kind = tb[TCA_ACT_KIND];
809 810
		if (!kind) {
			NL_SET_ERR_MSG(extack, "TC action kind must be specified");
L
Linus Torvalds 已提交
811
			goto err_out;
812 813 814
		}
		if (nla_strlcpy(act_name, kind, IFNAMSIZ) >= IFNAMSIZ) {
			NL_SET_ERR_MSG(extack, "TC action name too long");
L
Linus Torvalds 已提交
815
			goto err_out;
816
		}
817 818 819
		if (tb[TCA_ACT_COOKIE]) {
			int cklen = nla_len(tb[TCA_ACT_COOKIE]);

820 821
			if (cklen > TC_COOKIE_MAX_SIZE) {
				NL_SET_ERR_MSG(extack, "TC cookie size above the maximum");
822
				goto err_out;
823
			}
824 825 826

			cookie = nla_memdup_cookie(tb);
			if (!cookie) {
827
				NL_SET_ERR_MSG(extack, "No memory to generate TC cookie");
828 829 830 831
				err = -ENOMEM;
				goto err_out;
			}
		}
L
Linus Torvalds 已提交
832
	} else {
833 834 835
		if (strlcpy(act_name, name, IFNAMSIZ) >= IFNAMSIZ) {
			NL_SET_ERR_MSG(extack, "TC action name too long");
			err = -EINVAL;
L
Linus Torvalds 已提交
836
			goto err_out;
837
		}
L
Linus Torvalds 已提交
838 839 840 841
	}

	a_o = tc_lookup_action_n(act_name);
	if (a_o == NULL) {
842
#ifdef CONFIG_MODULES
843 844
		if (rtnl_held)
			rtnl_unlock();
845
		request_module("act_%s", act_name);
846 847
		if (rtnl_held)
			rtnl_lock();
L
Linus Torvalds 已提交
848 849 850 851 852 853 854 855 856 857

		a_o = tc_lookup_action_n(act_name);

		/* We dropped the RTNL semaphore in order to
		 * perform the module load.  So, even if we
		 * succeeded in loading the module we have to
		 * tell the caller to replay the request.  We
		 * indicate this using -EAGAIN.
		 */
		if (a_o != NULL) {
858
			err = -EAGAIN;
L
Linus Torvalds 已提交
859 860 861
			goto err_mod;
		}
#endif
862
		NL_SET_ERR_MSG(extack, "Failed to load TC action module");
863
		err = -ENOENT;
L
Linus Torvalds 已提交
864 865 866 867 868
		goto err_out;
	}

	/* backward compatibility for policer */
	if (name == NULL)
869
		err = a_o->init(net, tb[TCA_ACT_OPTIONS], est, &a, ovr, bind,
870
				rtnl_held, extack);
L
Linus Torvalds 已提交
871
	else
872 873
		err = a_o->init(net, nla, est, &a, ovr, bind, rtnl_held,
				extack);
874
	if (err < 0)
875
		goto err_mod;
L
Linus Torvalds 已提交
876

877 878
	if (!name && tb[TCA_ACT_COOKIE])
		tcf_set_action_cookie(&a->act_cookie, cookie);
879

L
Linus Torvalds 已提交
880
	/* module count goes up only when brand new policy is created
E
Eric Dumazet 已提交
881 882 883
	 * if it exists and is only bound to in a_o->init() then
	 * ACT_P_CREATED is not returned (a zero is).
	 */
884
	if (err != ACT_P_CREATED)
L
Linus Torvalds 已提交
885 886
		module_put(a_o->owner);

887 888 889
	if (TC_ACT_EXT_CMP(a->tcfa_action, TC_ACT_GOTO_CHAIN)) {
		err = tcf_action_goto_chain_init(a, tp);
		if (err) {
890
			struct tc_action *actions[] = { a, NULL };
891

892
			tcf_action_destroy(actions, bind);
893
			NL_SET_ERR_MSG(extack, "Failed to init TC action chain");
894 895 896 897
			return ERR_PTR(err);
		}
	}

L
Linus Torvalds 已提交
898 899 900 901 902
	return a;

err_mod:
	module_put(a_o->owner);
err_out:
903 904 905 906
	if (cookie) {
		kfree(cookie->data);
		kfree(cookie);
	}
907
	return ERR_PTR(err);
L
Linus Torvalds 已提交
908 909
}

910 911
/* Returns numbers of initialized actions or negative error. */

912 913
int tcf_action_init(struct net *net, struct tcf_proto *tp, struct nlattr *nla,
		    struct nlattr *est, char *name, int ovr, int bind,
914
		    struct tc_action *actions[], size_t *attr_size,
915
		    bool rtnl_held, struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
916
{
E
Eric Dumazet 已提交
917
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
918
	struct tc_action *act;
919
	size_t sz = 0;
920
	int err;
L
Linus Torvalds 已提交
921 922
	int i;

923
	err = nla_parse_nested(tb, TCA_ACT_MAX_PRIO, nla, NULL, extack);
924
	if (err < 0)
925
		return err;
L
Linus Torvalds 已提交
926

927
	for (i = 1; i <= TCA_ACT_MAX_PRIO && tb[i]; i++) {
928
		act = tcf_action_init_1(net, tp, tb[i], est, name, ovr, bind,
929
					rtnl_held, extack);
930 931
		if (IS_ERR(act)) {
			err = PTR_ERR(act);
L
Linus Torvalds 已提交
932
			goto err;
933
		}
934
		act->order = i;
935
		sz += tcf_action_fill_size(act);
936 937
		/* Start from index 0 */
		actions[i - 1] = act;
L
Linus Torvalds 已提交
938
	}
939

940
	*attr_size = tcf_action_full_attrs_size(sz);
941
	return i - 1;
L
Linus Torvalds 已提交
942 943

err:
944 945
	tcf_action_destroy(actions, bind);
	return err;
L
Linus Torvalds 已提交
946 947
}

948
int tcf_action_copy_stats(struct sk_buff *skb, struct tc_action *p,
L
Linus Torvalds 已提交
949 950 951 952
			  int compat_mode)
{
	int err = 0;
	struct gnet_dump d;
953

954
	if (p == NULL)
L
Linus Torvalds 已提交
955 956 957
		goto errout;

	/* compat_mode being true specifies a call that is supposed
958
	 * to add additional backward compatibility statistic TLVs.
L
Linus Torvalds 已提交
959 960
	 */
	if (compat_mode) {
961
		if (p->type == TCA_OLD_COMPAT)
L
Linus Torvalds 已提交
962
			err = gnet_stats_start_copy_compat(skb, 0,
963 964
							   TCA_STATS,
							   TCA_XSTATS,
965
							   &p->tcfa_lock, &d,
966
							   TCA_PAD);
L
Linus Torvalds 已提交
967 968 969 970
		else
			return 0;
	} else
		err = gnet_stats_start_copy(skb, TCA_ACT_STATS,
971
					    &p->tcfa_lock, &d, TCA_ACT_PAD);
L
Linus Torvalds 已提交
972 973 974 975

	if (err < 0)
		goto errout;

976
	if (gnet_stats_copy_basic(NULL, &d, p->cpu_bstats, &p->tcfa_bstats) < 0 ||
977
	    gnet_stats_copy_rate_est(&d, &p->tcfa_rate_est) < 0 ||
978
	    gnet_stats_copy_queue(&d, p->cpu_qstats,
979 980
				  &p->tcfa_qstats,
				  p->tcfa_qstats.qlen) < 0)
L
Linus Torvalds 已提交
981 982 983 984 985 986 987 988 989 990 991
		goto errout;

	if (gnet_stats_finish_copy(&d) < 0)
		goto errout;

	return 0;

errout:
	return -1;
}

992
static int tca_get_fill(struct sk_buff *skb, struct tc_action *actions[],
993 994
			u32 portid, u32 seq, u16 flags, int event, int bind,
			int ref)
L
Linus Torvalds 已提交
995 996 997
{
	struct tcamsg *t;
	struct nlmsghdr *nlh;
998
	unsigned char *b = skb_tail_pointer(skb);
999
	struct nlattr *nest;
L
Linus Torvalds 已提交
1000

1001
	nlh = nlmsg_put(skb, portid, seq, event, sizeof(*t), flags);
1002 1003 1004
	if (!nlh)
		goto out_nlmsg_trim;
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
1005
	t->tca_family = AF_UNSPEC;
1006 1007
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
1008

1009
	nest = nla_nest_start(skb, TCA_ACT_TAB);
1010
	if (!nest)
1011
		goto out_nlmsg_trim;
L
Linus Torvalds 已提交
1012

1013
	if (tcf_action_dump(skb, actions, bind, ref) < 0)
1014
		goto out_nlmsg_trim;
L
Linus Torvalds 已提交
1015

1016
	nla_nest_end(skb, nest);
1017

1018
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
1019 1020
	return skb->len;

1021
out_nlmsg_trim:
1022
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
1023 1024 1025 1026
	return -1;
}

static int
1027
tcf_get_notify(struct net *net, u32 portid, struct nlmsghdr *n,
1028
	       struct tc_action *actions[], int event,
1029
	       struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1030 1031 1032 1033 1034 1035
{
	struct sk_buff *skb;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;
1036
	if (tca_get_fill(skb, actions, portid, n->nlmsg_seq, 0, event,
1037
			 0, 1) <= 0) {
1038
		NL_SET_ERR_MSG(extack, "Failed to fill netlink attributes while adding TC action");
L
Linus Torvalds 已提交
1039 1040 1041
		kfree_skb(skb);
		return -EINVAL;
	}
1042

1043
	return rtnl_unicast(skb, net, portid);
L
Linus Torvalds 已提交
1044 1045
}

1046
static struct tc_action *tcf_action_get_1(struct net *net, struct nlattr *nla,
1047 1048
					  struct nlmsghdr *n, u32 portid,
					  struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1049
{
E
Eric Dumazet 已提交
1050
	struct nlattr *tb[TCA_ACT_MAX + 1];
1051
	const struct tc_action_ops *ops;
L
Linus Torvalds 已提交
1052 1053
	struct tc_action *a;
	int index;
1054
	int err;
L
Linus Torvalds 已提交
1055

1056
	err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL, extack);
1057
	if (err < 0)
1058
		goto err_out;
L
Linus Torvalds 已提交
1059

1060
	err = -EINVAL;
1061
	if (tb[TCA_ACT_INDEX] == NULL ||
1062 1063
	    nla_len(tb[TCA_ACT_INDEX]) < sizeof(index)) {
		NL_SET_ERR_MSG(extack, "Invalid TC action index value");
1064
		goto err_out;
1065
	}
1066
	index = nla_get_u32(tb[TCA_ACT_INDEX]);
L
Linus Torvalds 已提交
1067

1068
	err = -EINVAL;
1069
	ops = tc_lookup_action(tb[TCA_ACT_KIND]);
1070 1071
	if (!ops) { /* could happen in batch of actions */
		NL_SET_ERR_MSG(extack, "Specified TC action not found");
1072
		goto err_out;
1073
	}
1074
	err = -ENOENT;
1075
	if (ops->lookup(net, &a, index, extack) == 0)
L
Linus Torvalds 已提交
1076 1077
		goto err_mod;

1078
	module_put(ops->owner);
L
Linus Torvalds 已提交
1079
	return a;
1080

L
Linus Torvalds 已提交
1081
err_mod:
1082
	module_put(ops->owner);
1083 1084
err_out:
	return ERR_PTR(err);
L
Linus Torvalds 已提交
1085 1086
}

1087
static int tca_action_flush(struct net *net, struct nlattr *nla,
1088 1089
			    struct nlmsghdr *n, u32 portid,
			    struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1090 1091 1092 1093 1094 1095
{
	struct sk_buff *skb;
	unsigned char *b;
	struct nlmsghdr *nlh;
	struct tcamsg *t;
	struct netlink_callback dcb;
1096
	struct nlattr *nest;
E
Eric Dumazet 已提交
1097
	struct nlattr *tb[TCA_ACT_MAX + 1];
1098
	const struct tc_action_ops *ops;
1099
	struct nlattr *kind;
1100
	int err = -ENOMEM;
L
Linus Torvalds 已提交
1101 1102

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
1103
	if (!skb)
1104
		return err;
L
Linus Torvalds 已提交
1105

1106
	b = skb_tail_pointer(skb);
L
Linus Torvalds 已提交
1107

1108
	err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL, extack);
1109
	if (err < 0)
L
Linus Torvalds 已提交
1110 1111
		goto err_out;

1112
	err = -EINVAL;
1113
	kind = tb[TCA_ACT_KIND];
1114
	ops = tc_lookup_action(kind);
1115 1116
	if (!ops) { /*some idjot trying to flush unknown action */
		NL_SET_ERR_MSG(extack, "Cannot flush unknown TC action");
L
Linus Torvalds 已提交
1117
		goto err_out;
1118
	}
L
Linus Torvalds 已提交
1119

1120 1121
	nlh = nlmsg_put(skb, portid, n->nlmsg_seq, RTM_DELACTION,
			sizeof(*t), 0);
1122 1123
	if (!nlh) {
		NL_SET_ERR_MSG(extack, "Failed to create TC action flush notification");
1124
		goto out_module_put;
1125
	}
1126
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
1127
	t->tca_family = AF_UNSPEC;
1128 1129
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
L
Linus Torvalds 已提交
1130

1131
	nest = nla_nest_start(skb, TCA_ACT_TAB);
1132 1133
	if (!nest) {
		NL_SET_ERR_MSG(extack, "Failed to add new netlink message");
1134
		goto out_module_put;
1135
	}
L
Linus Torvalds 已提交
1136

1137
	err = ops->walk(net, skb, &dcb, RTM_DELACTION, ops, extack);
1138 1139
	if (err <= 0) {
		nla_nest_cancel(skb, nest);
1140
		goto out_module_put;
1141
	}
L
Linus Torvalds 已提交
1142

1143
	nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
1144

1145
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
1146
	nlh->nlmsg_flags |= NLM_F_ROOT;
1147
	module_put(ops->owner);
1148
	err = rtnetlink_send(skb, net, portid, RTNLGRP_TC,
E
Eric Dumazet 已提交
1149
			     n->nlmsg_flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
1150 1151
	if (err > 0)
		return 0;
1152 1153
	if (err < 0)
		NL_SET_ERR_MSG(extack, "Failed to send TC action flush notification");
L
Linus Torvalds 已提交
1154 1155 1156

	return err;

1157
out_module_put:
1158
	module_put(ops->owner);
L
Linus Torvalds 已提交
1159 1160 1161 1162 1163
err_out:
	kfree_skb(skb);
	return err;
}

1164 1165
static int tcf_action_delete(struct net *net, struct tc_action *actions[],
			     int *acts_deleted, struct netlink_ext_ack *extack)
1166 1167
{
	u32 act_index;
1168
	int ret, i;
1169

1170 1171
	for (i = 0; i < TCA_ACT_MAX_PRIO && actions[i]; i++) {
		struct tc_action *a = actions[i];
1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184
		const struct tc_action_ops *ops = a->ops;

		/* Actions can be deleted concurrently so we must save their
		 * type and id to search again after reference is released.
		 */
		act_index = a->tcfa_index;

		if (tcf_action_put(a)) {
			/* last reference, action was deleted concurrently */
			module_put(ops->owner);
		} else  {
			/* now do the delete */
			ret = ops->delete(net, act_index);
1185 1186
			if (ret < 0) {
				*acts_deleted = i + 1;
1187
				return ret;
1188
			}
1189 1190
		}
	}
1191
	*acts_deleted = i;
1192 1193 1194
	return 0;
}

1195
static int
1196 1197 1198
tcf_del_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
	       int *acts_deleted, u32 portid, size_t attr_size,
	       struct netlink_ext_ack *extack)
1199 1200 1201 1202
{
	int ret;
	struct sk_buff *skb;

1203 1204
	skb = alloc_skb(attr_size <= NLMSG_GOODSIZE ? NLMSG_GOODSIZE : attr_size,
			GFP_KERNEL);
1205 1206 1207 1208
	if (!skb)
		return -ENOBUFS;

	if (tca_get_fill(skb, actions, portid, n->nlmsg_seq, 0, RTM_DELACTION,
1209
			 0, 2) <= 0) {
1210
		NL_SET_ERR_MSG(extack, "Failed to fill netlink TC action attributes");
1211 1212 1213 1214 1215
		kfree_skb(skb);
		return -EINVAL;
	}

	/* now do the delete */
1216
	ret = tcf_action_delete(net, actions, acts_deleted, extack);
1217
	if (ret < 0) {
1218
		NL_SET_ERR_MSG(extack, "Failed to delete TC action");
1219 1220 1221
		kfree_skb(skb);
		return ret;
	}
1222 1223 1224 1225 1226 1227 1228 1229

	ret = rtnetlink_send(skb, net, portid, RTNLGRP_TC,
			     n->nlmsg_flags & NLM_F_ECHO);
	if (ret > 0)
		return 0;
	return ret;
}

L
Linus Torvalds 已提交
1230
static int
1231
tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
1232
	      u32 portid, int event, struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1233
{
1234
	int i, ret;
E
Eric Dumazet 已提交
1235
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
1236
	struct tc_action *act;
1237
	size_t attr_size = 0;
1238 1239
	struct tc_action *actions[TCA_ACT_MAX_PRIO + 1] = {};
	int acts_deleted = 0;
L
Linus Torvalds 已提交
1240

1241
	ret = nla_parse_nested(tb, TCA_ACT_MAX_PRIO, nla, NULL, extack);
1242 1243
	if (ret < 0)
		return ret;
L
Linus Torvalds 已提交
1244

E
Eric Dumazet 已提交
1245
	if (event == RTM_DELACTION && n->nlmsg_flags & NLM_F_ROOT) {
1246
		if (tb[1])
1247
			return tca_action_flush(net, tb[1], n, portid, extack);
1248

1249
		NL_SET_ERR_MSG(extack, "Invalid netlink attributes while flushing TC action");
1250
		return -EINVAL;
L
Linus Torvalds 已提交
1251 1252
	}

1253
	for (i = 1; i <= TCA_ACT_MAX_PRIO && tb[i]; i++) {
1254
		act = tcf_action_get_1(net, tb[i], n, portid, extack);
1255 1256
		if (IS_ERR(act)) {
			ret = PTR_ERR(act);
L
Linus Torvalds 已提交
1257
			goto err;
1258
		}
1259
		act->order = i;
1260
		attr_size += tcf_action_fill_size(act);
1261
		actions[i - 1] = act;
L
Linus Torvalds 已提交
1262
	}
1263 1264

	attr_size = tcf_action_full_attrs_size(attr_size);
L
Linus Torvalds 已提交
1265 1266

	if (event == RTM_GETACTION)
1267
		ret = tcf_get_notify(net, portid, n, actions, event, extack);
L
Linus Torvalds 已提交
1268
	else { /* delete */
1269 1270
		ret = tcf_del_notify(net, n, actions, &acts_deleted, portid,
				     attr_size, extack);
1271
		if (ret)
L
Linus Torvalds 已提交
1272 1273 1274 1275
			goto err;
		return ret;
	}
err:
1276
	tcf_action_put_many(&actions[acts_deleted]);
L
Linus Torvalds 已提交
1277 1278 1279
	return ret;
}

1280
static int
1281
tcf_add_notify(struct net *net, struct nlmsghdr *n, struct tc_action *actions[],
1282
	       u32 portid, size_t attr_size, struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1283 1284 1285 1286
{
	struct sk_buff *skb;
	int err = 0;

1287 1288
	skb = alloc_skb(attr_size <= NLMSG_GOODSIZE ? NLMSG_GOODSIZE : attr_size,
			GFP_KERNEL);
L
Linus Torvalds 已提交
1289 1290 1291
	if (!skb)
		return -ENOBUFS;

1292 1293
	if (tca_get_fill(skb, actions, portid, n->nlmsg_seq, n->nlmsg_flags,
			 RTM_NEWACTION, 0, 0) <= 0) {
1294
		NL_SET_ERR_MSG(extack, "Failed to fill netlink attributes while adding TC action");
1295 1296 1297
		kfree_skb(skb);
		return -EINVAL;
	}
1298

1299 1300
	err = rtnetlink_send(skb, net, portid, RTNLGRP_TC,
			     n->nlmsg_flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
1301 1302 1303 1304 1305
	if (err > 0)
		err = 0;
	return err;
}

J
Jamal Hadi Salim 已提交
1306
static int tcf_action_add(struct net *net, struct nlattr *nla,
1307 1308
			  struct nlmsghdr *n, u32 portid, int ovr,
			  struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1309
{
1310
	size_t attr_size = 0;
L
Linus Torvalds 已提交
1311
	int ret = 0;
1312
	struct tc_action *actions[TCA_ACT_MAX_PRIO] = {};
L
Linus Torvalds 已提交
1313

1314
	ret = tcf_action_init(net, NULL, nla, NULL, NULL, ovr, 0, actions,
1315
			      &attr_size, true, extack);
1316
	if (ret < 0)
1317
		return ret;
1318
	ret = tcf_add_notify(net, n, actions, portid, attr_size, extack);
1319
	if (ovr)
1320
		tcf_action_put_many(actions);
L
Linus Torvalds 已提交
1321

1322
	return ret;
L
Linus Torvalds 已提交
1323 1324
}

1325 1326 1327 1328
static u32 tcaa_root_flags_allowed = TCA_FLAG_LARGE_DUMP_ON;
static const struct nla_policy tcaa_policy[TCA_ROOT_MAX + 1] = {
	[TCA_ROOT_FLAGS] = { .type = NLA_BITFIELD32,
			     .validation_data = &tcaa_root_flags_allowed },
1329
	[TCA_ROOT_TIME_DELTA]      = { .type = NLA_U32 },
1330 1331
};

1332 1333
static int tc_ctl_action(struct sk_buff *skb, struct nlmsghdr *n,
			 struct netlink_ext_ack *extack)
L
Linus Torvalds 已提交
1334
{
1335
	struct net *net = sock_net(skb->sk);
1336
	struct nlattr *tca[TCA_ROOT_MAX + 1];
1337
	u32 portid = skb ? NETLINK_CB(skb).portid : 0;
L
Linus Torvalds 已提交
1338 1339
	int ret = 0, ovr = 0;

1340 1341
	if ((n->nlmsg_type != RTM_GETACTION) &&
	    !netlink_capable(skb, CAP_NET_ADMIN))
1342 1343
		return -EPERM;

1344
	ret = nlmsg_parse(n, sizeof(struct tcamsg), tca, TCA_ROOT_MAX, NULL,
1345
			  extack);
1346 1347 1348 1349
	if (ret < 0)
		return ret;

	if (tca[TCA_ACT_TAB] == NULL) {
1350
		NL_SET_ERR_MSG(extack, "Netlink action attributes missing");
L
Linus Torvalds 已提交
1351 1352 1353
		return -EINVAL;
	}

E
Eric Dumazet 已提交
1354
	/* n->nlmsg_flags & NLM_F_CREATE */
L
Linus Torvalds 已提交
1355 1356 1357
	switch (n->nlmsg_type) {
	case RTM_NEWACTION:
		/* we are going to assume all other flags
L
Lucas De Marchi 已提交
1358
		 * imply create only if it doesn't exist
L
Linus Torvalds 已提交
1359 1360 1361 1362
		 * Note that CREATE | EXCL implies that
		 * but since we want avoid ambiguity (eg when flags
		 * is zero) then just set this
		 */
E
Eric Dumazet 已提交
1363
		if (n->nlmsg_flags & NLM_F_REPLACE)
L
Linus Torvalds 已提交
1364 1365
			ovr = 1;
replay:
1366 1367
		ret = tcf_action_add(net, tca[TCA_ACT_TAB], n, portid, ovr,
				     extack);
L
Linus Torvalds 已提交
1368 1369 1370 1371
		if (ret == -EAGAIN)
			goto replay;
		break;
	case RTM_DELACTION:
1372
		ret = tca_action_gd(net, tca[TCA_ACT_TAB], n,
1373
				    portid, RTM_DELACTION, extack);
L
Linus Torvalds 已提交
1374 1375
		break;
	case RTM_GETACTION:
1376
		ret = tca_action_gd(net, tca[TCA_ACT_TAB], n,
1377
				    portid, RTM_GETACTION, extack);
L
Linus Torvalds 已提交
1378 1379 1380 1381 1382 1383 1384 1385
		break;
	default:
		BUG();
	}

	return ret;
}

1386
static struct nlattr *find_dump_kind(struct nlattr **nla)
L
Linus Torvalds 已提交
1387
{
E
Eric Dumazet 已提交
1388
	struct nlattr *tb1, *tb2[TCA_ACT_MAX + 1];
1389 1390
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
	struct nlattr *kind;
L
Linus Torvalds 已提交
1391

1392
	tb1 = nla[TCA_ACT_TAB];
L
Linus Torvalds 已提交
1393 1394 1395
	if (tb1 == NULL)
		return NULL;

1396
	if (nla_parse(tb, TCA_ACT_MAX_PRIO, nla_data(tb1),
1397
		      NLMSG_ALIGN(nla_len(tb1)), NULL, NULL) < 0)
L
Linus Torvalds 已提交
1398 1399
		return NULL;

1400 1401
	if (tb[1] == NULL)
		return NULL;
1402
	if (nla_parse_nested(tb2, TCA_ACT_MAX, tb[1], NULL, NULL) < 0)
L
Linus Torvalds 已提交
1403
		return NULL;
1404
	kind = tb2[TCA_ACT_KIND];
L
Linus Torvalds 已提交
1405

1406
	return kind;
L
Linus Torvalds 已提交
1407 1408
}

J
Jamal Hadi Salim 已提交
1409
static int tc_dump_action(struct sk_buff *skb, struct netlink_callback *cb)
L
Linus Torvalds 已提交
1410
{
1411
	struct net *net = sock_net(skb->sk);
L
Linus Torvalds 已提交
1412
	struct nlmsghdr *nlh;
1413
	unsigned char *b = skb_tail_pointer(skb);
1414
	struct nlattr *nest;
L
Linus Torvalds 已提交
1415 1416
	struct tc_action_ops *a_o;
	int ret = 0;
1417
	struct tcamsg *t = (struct tcamsg *) nlmsg_data(cb->nlh);
1418 1419
	struct nlattr *tb[TCA_ROOT_MAX + 1];
	struct nlattr *count_attr = NULL;
1420
	unsigned long jiffy_since = 0;
1421 1422
	struct nlattr *kind = NULL;
	struct nla_bitfield32 bf;
1423
	u32 msecs_since = 0;
1424 1425 1426 1427 1428 1429
	u32 act_count = 0;

	ret = nlmsg_parse(cb->nlh, sizeof(struct tcamsg), tb, TCA_ROOT_MAX,
			  tcaa_policy, NULL);
	if (ret < 0)
		return ret;
L
Linus Torvalds 已提交
1430

1431
	kind = find_dump_kind(tb);
L
Linus Torvalds 已提交
1432
	if (kind == NULL) {
1433
		pr_info("tc_dump_action: action bad kind\n");
L
Linus Torvalds 已提交
1434 1435 1436
		return 0;
	}

1437
	a_o = tc_lookup_action(kind);
E
Eric Dumazet 已提交
1438
	if (a_o == NULL)
L
Linus Torvalds 已提交
1439 1440
		return 0;

1441 1442 1443 1444 1445 1446
	cb->args[2] = 0;
	if (tb[TCA_ROOT_FLAGS]) {
		bf = nla_get_bitfield32(tb[TCA_ROOT_FLAGS]);
		cb->args[2] = bf.value;
	}

1447 1448 1449 1450
	if (tb[TCA_ROOT_TIME_DELTA]) {
		msecs_since = nla_get_u32(tb[TCA_ROOT_TIME_DELTA]);
	}

1451
	nlh = nlmsg_put(skb, NETLINK_CB(cb->skb).portid, cb->nlh->nlmsg_seq,
1452 1453 1454
			cb->nlh->nlmsg_type, sizeof(*t), 0);
	if (!nlh)
		goto out_module_put;
1455

1456 1457 1458
	if (msecs_since)
		jiffy_since = jiffies - msecs_to_jiffies(msecs_since);

1459
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
1460
	t->tca_family = AF_UNSPEC;
1461 1462
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
1463
	cb->args[3] = jiffy_since;
1464 1465 1466
	count_attr = nla_reserve(skb, TCA_ROOT_COUNT, sizeof(u32));
	if (!count_attr)
		goto out_module_put;
L
Linus Torvalds 已提交
1467

1468 1469
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
1470
		goto out_module_put;
L
Linus Torvalds 已提交
1471

1472
	ret = a_o->walk(net, skb, cb, RTM_GETACTION, a_o, NULL);
L
Linus Torvalds 已提交
1473
	if (ret < 0)
1474
		goto out_module_put;
L
Linus Torvalds 已提交
1475 1476

	if (ret > 0) {
1477
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
1478
		ret = skb->len;
1479 1480 1481
		act_count = cb->args[1];
		memcpy(nla_data(count_attr), &act_count, sizeof(u32));
		cb->args[1] = 0;
L
Linus Torvalds 已提交
1482
	} else
1483
		nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
1484

1485
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
1486
	if (NETLINK_CB(cb->skb).portid && ret)
L
Linus Torvalds 已提交
1487 1488 1489 1490
		nlh->nlmsg_flags |= NLM_F_MULTI;
	module_put(a_o->owner);
	return skb->len;

1491
out_module_put:
L
Linus Torvalds 已提交
1492
	module_put(a_o->owner);
1493
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
1494 1495 1496
	return skb->len;
}

1497 1498 1499 1500 1501 1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545
struct tcf_action_net {
	struct rhashtable egdev_ht;
};

static unsigned int tcf_action_net_id;

struct tcf_action_egdev_cb {
	struct list_head list;
	tc_setup_cb_t *cb;
	void *cb_priv;
};

struct tcf_action_egdev {
	struct rhash_head ht_node;
	const struct net_device *dev;
	unsigned int refcnt;
	struct list_head cb_list;
};

static const struct rhashtable_params tcf_action_egdev_ht_params = {
	.key_offset = offsetof(struct tcf_action_egdev, dev),
	.head_offset = offsetof(struct tcf_action_egdev, ht_node),
	.key_len = sizeof(const struct net_device *),
};

static struct tcf_action_egdev *
tcf_action_egdev_lookup(const struct net_device *dev)
{
	struct net *net = dev_net(dev);
	struct tcf_action_net *tan = net_generic(net, tcf_action_net_id);

	return rhashtable_lookup_fast(&tan->egdev_ht, &dev,
				      tcf_action_egdev_ht_params);
}

static struct tcf_action_egdev *
tcf_action_egdev_get(const struct net_device *dev)
{
	struct tcf_action_egdev *egdev;
	struct tcf_action_net *tan;

	egdev = tcf_action_egdev_lookup(dev);
	if (egdev)
		goto inc_ref;

	egdev = kzalloc(sizeof(*egdev), GFP_KERNEL);
	if (!egdev)
		return NULL;
	INIT_LIST_HEAD(&egdev->cb_list);
1546
	egdev->dev = dev;
1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707 1708 1709
	tan = net_generic(dev_net(dev), tcf_action_net_id);
	rhashtable_insert_fast(&tan->egdev_ht, &egdev->ht_node,
			       tcf_action_egdev_ht_params);

inc_ref:
	egdev->refcnt++;
	return egdev;
}

static void tcf_action_egdev_put(struct tcf_action_egdev *egdev)
{
	struct tcf_action_net *tan;

	if (--egdev->refcnt)
		return;
	tan = net_generic(dev_net(egdev->dev), tcf_action_net_id);
	rhashtable_remove_fast(&tan->egdev_ht, &egdev->ht_node,
			       tcf_action_egdev_ht_params);
	kfree(egdev);
}

static struct tcf_action_egdev_cb *
tcf_action_egdev_cb_lookup(struct tcf_action_egdev *egdev,
			   tc_setup_cb_t *cb, void *cb_priv)
{
	struct tcf_action_egdev_cb *egdev_cb;

	list_for_each_entry(egdev_cb, &egdev->cb_list, list)
		if (egdev_cb->cb == cb && egdev_cb->cb_priv == cb_priv)
			return egdev_cb;
	return NULL;
}

static int tcf_action_egdev_cb_call(struct tcf_action_egdev *egdev,
				    enum tc_setup_type type,
				    void *type_data, bool err_stop)
{
	struct tcf_action_egdev_cb *egdev_cb;
	int ok_count = 0;
	int err;

	list_for_each_entry(egdev_cb, &egdev->cb_list, list) {
		err = egdev_cb->cb(type, type_data, egdev_cb->cb_priv);
		if (err) {
			if (err_stop)
				return err;
		} else {
			ok_count++;
		}
	}
	return ok_count;
}

static int tcf_action_egdev_cb_add(struct tcf_action_egdev *egdev,
				   tc_setup_cb_t *cb, void *cb_priv)
{
	struct tcf_action_egdev_cb *egdev_cb;

	egdev_cb = tcf_action_egdev_cb_lookup(egdev, cb, cb_priv);
	if (WARN_ON(egdev_cb))
		return -EEXIST;
	egdev_cb = kzalloc(sizeof(*egdev_cb), GFP_KERNEL);
	if (!egdev_cb)
		return -ENOMEM;
	egdev_cb->cb = cb;
	egdev_cb->cb_priv = cb_priv;
	list_add(&egdev_cb->list, &egdev->cb_list);
	return 0;
}

static void tcf_action_egdev_cb_del(struct tcf_action_egdev *egdev,
				    tc_setup_cb_t *cb, void *cb_priv)
{
	struct tcf_action_egdev_cb *egdev_cb;

	egdev_cb = tcf_action_egdev_cb_lookup(egdev, cb, cb_priv);
	if (WARN_ON(!egdev_cb))
		return;
	list_del(&egdev_cb->list);
	kfree(egdev_cb);
}

static int __tc_setup_cb_egdev_register(const struct net_device *dev,
					tc_setup_cb_t *cb, void *cb_priv)
{
	struct tcf_action_egdev *egdev = tcf_action_egdev_get(dev);
	int err;

	if (!egdev)
		return -ENOMEM;
	err = tcf_action_egdev_cb_add(egdev, cb, cb_priv);
	if (err)
		goto err_cb_add;
	return 0;

err_cb_add:
	tcf_action_egdev_put(egdev);
	return err;
}
int tc_setup_cb_egdev_register(const struct net_device *dev,
			       tc_setup_cb_t *cb, void *cb_priv)
{
	int err;

	rtnl_lock();
	err = __tc_setup_cb_egdev_register(dev, cb, cb_priv);
	rtnl_unlock();
	return err;
}
EXPORT_SYMBOL_GPL(tc_setup_cb_egdev_register);

static void __tc_setup_cb_egdev_unregister(const struct net_device *dev,
					   tc_setup_cb_t *cb, void *cb_priv)
{
	struct tcf_action_egdev *egdev = tcf_action_egdev_lookup(dev);

	if (WARN_ON(!egdev))
		return;
	tcf_action_egdev_cb_del(egdev, cb, cb_priv);
	tcf_action_egdev_put(egdev);
}
void tc_setup_cb_egdev_unregister(const struct net_device *dev,
				  tc_setup_cb_t *cb, void *cb_priv)
{
	rtnl_lock();
	__tc_setup_cb_egdev_unregister(dev, cb, cb_priv);
	rtnl_unlock();
}
EXPORT_SYMBOL_GPL(tc_setup_cb_egdev_unregister);

int tc_setup_cb_egdev_call(const struct net_device *dev,
			   enum tc_setup_type type, void *type_data,
			   bool err_stop)
{
	struct tcf_action_egdev *egdev = tcf_action_egdev_lookup(dev);

	if (!egdev)
		return 0;
	return tcf_action_egdev_cb_call(egdev, type, type_data, err_stop);
}
EXPORT_SYMBOL_GPL(tc_setup_cb_egdev_call);

static __net_init int tcf_action_net_init(struct net *net)
{
	struct tcf_action_net *tan = net_generic(net, tcf_action_net_id);

	return rhashtable_init(&tan->egdev_ht, &tcf_action_egdev_ht_params);
}

static void __net_exit tcf_action_net_exit(struct net *net)
{
	struct tcf_action_net *tan = net_generic(net, tcf_action_net_id);

	rhashtable_destroy(&tan->egdev_ht);
}

static struct pernet_operations tcf_action_net_ops = {
	.init = tcf_action_net_init,
	.exit = tcf_action_net_exit,
	.id = &tcf_action_net_id,
	.size = sizeof(struct tcf_action_net),
};

L
Linus Torvalds 已提交
1710 1711
static int __init tc_action_init(void)
{
1712 1713 1714 1715 1716 1717
	int err;

	err = register_pernet_subsys(&tcf_action_net_ops);
	if (err)
		return err;

1718 1719
	rtnl_register(PF_UNSPEC, RTM_NEWACTION, tc_ctl_action, NULL, 0);
	rtnl_register(PF_UNSPEC, RTM_DELACTION, tc_ctl_action, NULL, 0);
1720
	rtnl_register(PF_UNSPEC, RTM_GETACTION, tc_ctl_action, tc_dump_action,
1721
		      0);
L
Linus Torvalds 已提交
1722 1723 1724 1725 1726

	return 0;
}

subsys_initcall(tc_action_init);