geneve.c 43.8 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
/*
 * GENEVE: Generic Network Virtualization Encapsulation
 *
 * Copyright (c) 2015 Red Hat, Inc.
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/etherdevice.h>
#include <linux/hash.h>
17
#include <net/dst_metadata.h>
18
#include <net/gro_cells.h>
19 20
#include <net/rtnetlink.h>
#include <net/geneve.h>
21
#include <net/protocol.h>
22 23 24 25 26 27 28 29 30 31 32 33 34 35 36

#define GENEVE_NETDEV_VER	"0.6"

#define GENEVE_UDP_PORT		6081

#define GENEVE_N_VID		(1u << 24)
#define GENEVE_VID_MASK		(GENEVE_N_VID - 1)

#define VNI_HASH_BITS		10
#define VNI_HASH_SIZE		(1<<VNI_HASH_BITS)

static bool log_ecn_error = true;
module_param(log_ecn_error, bool, 0644);
MODULE_PARM_DESC(log_ecn_error, "Log packets received with corrupted ECN");

37 38 39
#define GENEVE_VER 0
#define GENEVE_BASE_HLEN (sizeof(struct udphdr) + sizeof(struct genevehdr))

40 41
/* per-network namespace private data for this module */
struct geneve_net {
42 43
	struct list_head	geneve_list;
	struct list_head	sock_list;
44 45
};

46
static unsigned int geneve_net_id;
47

J
Jiri Benc 已提交
48 49 50 51 52
struct geneve_dev_node {
	struct hlist_node hlist;
	struct geneve_dev *geneve;
};

53 54
/* Pseudo network device */
struct geneve_dev {
J
Jiri Benc 已提交
55 56 57 58
	struct geneve_dev_node hlist4;	/* vni hash table for IPv4 socket */
#if IS_ENABLED(CONFIG_IPV6)
	struct geneve_dev_node hlist6;	/* vni hash table for IPv6 socket */
#endif
59 60
	struct net	   *net;	/* netns for packet i/o */
	struct net_device  *dev;	/* netdev for geneve tunnel */
61
	struct ip_tunnel_info info;
62
	struct geneve_sock __rcu *sock4;	/* IPv4 socket used for geneve tunnel */
63
#if IS_ENABLED(CONFIG_IPV6)
64
	struct geneve_sock __rcu *sock6;	/* IPv6 socket used for geneve tunnel */
65
#endif
66
	struct list_head   next;	/* geneve's per namespace list */
67
	struct gro_cells   gro_cells;
68 69
	bool		   collect_md;
	bool		   use_udp6_rx_checksums;
70 71
};

72 73 74 75 76 77
struct geneve_sock {
	bool			collect_md;
	struct list_head	list;
	struct socket		*sock;
	struct rcu_head		rcu;
	int			refcnt;
78
	struct hlist_head	vni_list[VNI_HASH_SIZE];
79
};
80 81 82 83 84 85 86 87 88

static inline __u32 geneve_net_vni_hash(u8 vni[3])
{
	__u32 vnid;

	vnid = (vni[0] << 16) | (vni[1] << 8) | vni[2];
	return hash_32(vnid, VNI_HASH_BITS);
}

89 90 91 92 93 94 95 96 97 98 99
static __be64 vni_to_tunnel_id(const __u8 *vni)
{
#ifdef __BIG_ENDIAN
	return (vni[0] << 16) | (vni[1] << 8) | vni[2];
#else
	return (__force __be64)(((__force u64)vni[0] << 40) |
				((__force u64)vni[1] << 48) |
				((__force u64)vni[2] << 56));
#endif
}

100 101 102 103 104 105 106 107 108 109 110 111 112 113
/* Convert 64 bit tunnel ID to 24 bit VNI. */
static void tunnel_id_to_vni(__be64 tun_id, __u8 *vni)
{
#ifdef __BIG_ENDIAN
	vni[0] = (__force __u8)(tun_id >> 16);
	vni[1] = (__force __u8)(tun_id >> 8);
	vni[2] = (__force __u8)tun_id;
#else
	vni[0] = (__force __u8)((__force u64)tun_id >> 40);
	vni[1] = (__force __u8)((__force u64)tun_id >> 48);
	vni[2] = (__force __u8)((__force u64)tun_id >> 56);
#endif
}

114 115 116 117 118
static bool eq_tun_id_and_vni(u8 *tun_id, u8 *vni)
{
	return !memcmp(vni, &tun_id[5], 3);
}

119 120 121 122 123
static sa_family_t geneve_get_sk_family(struct geneve_sock *gs)
{
	return gs->sock->sk->sk_family;
}

124
static struct geneve_dev *geneve_lookup(struct geneve_sock *gs,
125
					__be32 addr, u8 vni[])
126 127
{
	struct hlist_head *vni_list_head;
J
Jiri Benc 已提交
128
	struct geneve_dev_node *node;
129 130 131
	__u32 hash;

	/* Find the device for this VNI */
132
	hash = geneve_net_vni_hash(vni);
133
	vni_list_head = &gs->vni_list[hash];
J
Jiri Benc 已提交
134 135 136 137
	hlist_for_each_entry_rcu(node, vni_list_head, hlist) {
		if (eq_tun_id_and_vni((u8 *)&node->geneve->info.key.tun_id, vni) &&
		    addr == node->geneve->info.key.u.ipv4.dst)
			return node->geneve;
138 139 140 141 142 143 144 145 146
	}
	return NULL;
}

#if IS_ENABLED(CONFIG_IPV6)
static struct geneve_dev *geneve6_lookup(struct geneve_sock *gs,
					 struct in6_addr addr6, u8 vni[])
{
	struct hlist_head *vni_list_head;
J
Jiri Benc 已提交
147
	struct geneve_dev_node *node;
148 149 150 151 152
	__u32 hash;

	/* Find the device for this VNI */
	hash = geneve_net_vni_hash(vni);
	vni_list_head = &gs->vni_list[hash];
J
Jiri Benc 已提交
153 154 155 156
	hlist_for_each_entry_rcu(node, vni_list_head, hlist) {
		if (eq_tun_id_and_vni((u8 *)&node->geneve->info.key.tun_id, vni) &&
		    ipv6_addr_equal(&addr6, &node->geneve->info.key.u.ipv6.dst))
			return node->geneve;
157
	}
158 159
	return NULL;
}
160
#endif
161

162 163 164 165 166
static inline struct genevehdr *geneve_hdr(const struct sk_buff *skb)
{
	return (struct genevehdr *)(udp_hdr(skb) + 1);
}

167 168
static struct geneve_dev *geneve_lookup_skb(struct geneve_sock *gs,
					    struct sk_buff *skb)
169
{
170
	static u8 zero_vni[3];
171
	u8 *vni;
172

173
	if (geneve_get_sk_family(gs) == AF_INET) {
174
		struct iphdr *iph;
175
		__be32 addr;
176

177
		iph = ip_hdr(skb); /* outer IP header... */
178

179 180 181 182
		if (gs->collect_md) {
			vni = zero_vni;
			addr = 0;
		} else {
183
			vni = geneve_hdr(skb)->vni;
184 185 186
			addr = iph->saddr;
		}

187
		return geneve_lookup(gs, addr, vni);
188
#if IS_ENABLED(CONFIG_IPV6)
189
	} else if (geneve_get_sk_family(gs) == AF_INET6) {
190
		static struct in6_addr zero_addr6;
191 192 193
		struct ipv6hdr *ip6h;
		struct in6_addr addr6;

194
		ip6h = ipv6_hdr(skb); /* outer IPv6 header... */
195

196 197 198 199
		if (gs->collect_md) {
			vni = zero_vni;
			addr6 = zero_addr6;
		} else {
200
			vni = geneve_hdr(skb)->vni;
201 202 203
			addr6 = ip6h->saddr;
		}

204
		return geneve6_lookup(gs, addr6, vni);
205 206
#endif
	}
207 208 209 210 211 212 213 214 215 216
	return NULL;
}

/* geneve receive/decap routine */
static void geneve_rx(struct geneve_dev *geneve, struct geneve_sock *gs,
		      struct sk_buff *skb)
{
	struct genevehdr *gnvh = geneve_hdr(skb);
	struct metadata_dst *tun_dst = NULL;
	struct pcpu_sw_netstats *stats;
217
	unsigned int len;
218 219
	int err = 0;
	void *oiph;
220

221
	if (ip_tunnel_collect_metadata() || gs->collect_md) {
222 223 224 225 226 227
		__be16 flags;

		flags = TUNNEL_KEY | TUNNEL_GENEVE_OPT |
			(gnvh->oam ? TUNNEL_OAM : 0) |
			(gnvh->critical ? TUNNEL_CRIT_OPT : 0);

228
		tun_dst = udp_tun_rx_dst(skb, geneve_get_sk_family(gs), flags,
229 230
					 vni_to_tunnel_id(gnvh->vni),
					 gnvh->opt_len * 4);
231 232
		if (!tun_dst) {
			geneve->dev->stats.rx_dropped++;
233
			goto drop;
234
		}
235
		/* Update tunnel dst according to Geneve options. */
236 237
		ip_tunnel_info_opts_set(&tun_dst->u.tun_info,
					gnvh->options, gnvh->opt_len * 4);
238 239 240 241
	} else {
		/* Drop packets w/ critical options,
		 * since we don't support any...
		 */
242 243 244
		if (gnvh->critical) {
			geneve->dev->stats.rx_frame_errors++;
			geneve->dev->stats.rx_errors++;
245
			goto drop;
246
		}
247
	}
248 249 250 251 252

	skb_reset_mac_header(skb);
	skb->protocol = eth_type_trans(skb, geneve->dev);
	skb_postpull_rcsum(skb, eth_hdr(skb), ETH_HLEN);

253 254 255
	if (tun_dst)
		skb_dst_set(skb, &tun_dst->dst);

256
	/* Ignore packet loops (and multicast echo) */
257 258
	if (ether_addr_equal(eth_hdr(skb)->h_source, geneve->dev->dev_addr)) {
		geneve->dev->stats.rx_errors++;
259
		goto drop;
260
	}
261

262
	oiph = skb_network_header(skb);
263 264
	skb_reset_network_header(skb);

265 266
	if (geneve_get_sk_family(gs) == AF_INET)
		err = IP_ECN_decapsulate(oiph, skb);
267
#if IS_ENABLED(CONFIG_IPV6)
268 269
	else
		err = IP6_ECN_decapsulate(oiph, skb);
270
#endif
271 272

	if (unlikely(err)) {
273
		if (log_ecn_error) {
274
			if (geneve_get_sk_family(gs) == AF_INET)
275 276
				net_info_ratelimited("non-ECT from %pI4 "
						     "with TOS=%#x\n",
277 278
						     &((struct iphdr *)oiph)->saddr,
						     ((struct iphdr *)oiph)->tos);
279
#if IS_ENABLED(CONFIG_IPV6)
280
			else
281
				net_info_ratelimited("non-ECT from %pI6\n",
282
						     &((struct ipv6hdr *)oiph)->saddr);
283 284
#endif
		}
285 286 287 288 289 290 291
		if (err > 1) {
			++geneve->dev->stats.rx_frame_errors;
			++geneve->dev->stats.rx_errors;
			goto drop;
		}
	}

292 293 294 295 296 297 298 299 300
	len = skb->len;
	err = gro_cells_receive(&geneve->gro_cells, skb);
	if (likely(err == NET_RX_SUCCESS)) {
		stats = this_cpu_ptr(geneve->dev->tstats);
		u64_stats_update_begin(&stats->syncp);
		stats->rx_packets++;
		stats->rx_bytes += len;
		u64_stats_update_end(&stats->syncp);
	}
301 302 303 304 305 306 307 308 309
	return;
drop:
	/* Consume bad packet */
	kfree_skb(skb);
}

/* Setup stats when device is created */
static int geneve_init(struct net_device *dev)
{
310 311 312
	struct geneve_dev *geneve = netdev_priv(dev);
	int err;

313 314 315
	dev->tstats = netdev_alloc_pcpu_stats(struct pcpu_sw_netstats);
	if (!dev->tstats)
		return -ENOMEM;
316 317 318 319 320 321 322

	err = gro_cells_init(&geneve->gro_cells, dev);
	if (err) {
		free_percpu(dev->tstats);
		return err;
	}

323
	err = dst_cache_init(&geneve->info.dst_cache, GFP_KERNEL);
P
Paolo Abeni 已提交
324 325 326 327 328
	if (err) {
		free_percpu(dev->tstats);
		gro_cells_destroy(&geneve->gro_cells);
		return err;
	}
329 330 331 332 333
	return 0;
}

static void geneve_uninit(struct net_device *dev)
{
334 335
	struct geneve_dev *geneve = netdev_priv(dev);

336
	dst_cache_destroy(&geneve->info.dst_cache);
337
	gro_cells_destroy(&geneve->gro_cells);
338 339 340
	free_percpu(dev->tstats);
}

341 342 343 344
/* Callback from net/ipv4/udp.c to receive packets */
static int geneve_udp_encap_recv(struct sock *sk, struct sk_buff *skb)
{
	struct genevehdr *geneveh;
345
	struct geneve_dev *geneve;
346 347 348
	struct geneve_sock *gs;
	int opts_len;

349
	/* Need UDP and Geneve header to be present */
350
	if (unlikely(!pskb_may_pull(skb, GENEVE_BASE_HLEN)))
351
		goto drop;
352 353 354 355

	/* Return packets with reserved bits set */
	geneveh = geneve_hdr(skb);
	if (unlikely(geneveh->ver != GENEVE_VER))
356
		goto drop;
357 358

	if (unlikely(geneveh->proto_type != htons(ETH_P_TEB)))
359
		goto drop;
360

361 362 363 364 365 366 367 368
	gs = rcu_dereference_sk_user_data(sk);
	if (!gs)
		goto drop;

	geneve = geneve_lookup_skb(gs, skb);
	if (!geneve)
		goto drop;

369 370
	opts_len = geneveh->opt_len * 4;
	if (iptunnel_pull_header(skb, GENEVE_BASE_HLEN + opts_len,
371
				 htons(ETH_P_TEB),
372 373
				 !net_eq(geneve->net, dev_net(geneve->dev)))) {
		geneve->dev->stats.rx_dropped++;
374
		goto drop;
375
	}
376

377
	geneve_rx(geneve, gs, skb);
378 379 380 381 382 383 384 385 386
	return 0;

drop:
	/* Consume bad packet */
	kfree_skb(skb);
	return 0;
}

static struct socket *geneve_create_sock(struct net *net, bool ipv6,
387
					 __be16 port, bool ipv6_rx_csum)
388 389 390 391 392 393 394 395 396
{
	struct socket *sock;
	struct udp_port_cfg udp_conf;
	int err;

	memset(&udp_conf, 0, sizeof(udp_conf));

	if (ipv6) {
		udp_conf.family = AF_INET6;
397
		udp_conf.ipv6_v6only = 1;
398
		udp_conf.use_udp6_rx_checksums = ipv6_rx_csum;
399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418
	} else {
		udp_conf.family = AF_INET;
		udp_conf.local_ip.s_addr = htonl(INADDR_ANY);
	}

	udp_conf.local_udp_port = port;

	/* Open UDP socket */
	err = udp_sock_create(net, &udp_conf, &sock);
	if (err < 0)
		return ERR_PTR(err);

	return sock;
}

static int geneve_hlen(struct genevehdr *gh)
{
	return sizeof(*gh) + gh->opt_len * 4;
}

419 420 421
static struct sk_buff **geneve_gro_receive(struct sock *sk,
					   struct sk_buff **head,
					   struct sk_buff *skb)
422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465
{
	struct sk_buff *p, **pp = NULL;
	struct genevehdr *gh, *gh2;
	unsigned int hlen, gh_len, off_gnv;
	const struct packet_offload *ptype;
	__be16 type;
	int flush = 1;

	off_gnv = skb_gro_offset(skb);
	hlen = off_gnv + sizeof(*gh);
	gh = skb_gro_header_fast(skb, off_gnv);
	if (skb_gro_header_hard(skb, hlen)) {
		gh = skb_gro_header_slow(skb, hlen, off_gnv);
		if (unlikely(!gh))
			goto out;
	}

	if (gh->ver != GENEVE_VER || gh->oam)
		goto out;
	gh_len = geneve_hlen(gh);

	hlen = off_gnv + gh_len;
	if (skb_gro_header_hard(skb, hlen)) {
		gh = skb_gro_header_slow(skb, hlen, off_gnv);
		if (unlikely(!gh))
			goto out;
	}

	for (p = *head; p; p = p->next) {
		if (!NAPI_GRO_CB(p)->same_flow)
			continue;

		gh2 = (struct genevehdr *)(p->data + off_gnv);
		if (gh->opt_len != gh2->opt_len ||
		    memcmp(gh, gh2, gh_len)) {
			NAPI_GRO_CB(p)->same_flow = 0;
			continue;
		}
	}

	type = gh->proto_type;

	rcu_read_lock();
	ptype = gro_find_receive_by_type(type);
466
	if (!ptype)
467 468 469 470
		goto out_unlock;

	skb_gro_pull(skb, gh_len);
	skb_gro_postpull_rcsum(skb, gh, gh_len);
S
Sabrina Dubroca 已提交
471
	pp = call_gro_receive(ptype->callbacks.gro_receive, head, skb);
472
	flush = 0;
473 474 475 476 477 478 479 480 481

out_unlock:
	rcu_read_unlock();
out:
	NAPI_GRO_CB(skb)->flush |= flush;

	return pp;
}

482 483
static int geneve_gro_complete(struct sock *sk, struct sk_buff *skb,
			       int nhoff)
484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500
{
	struct genevehdr *gh;
	struct packet_offload *ptype;
	__be16 type;
	int gh_len;
	int err = -ENOSYS;

	gh = (struct genevehdr *)(skb->data + nhoff);
	gh_len = geneve_hlen(gh);
	type = gh->proto_type;

	rcu_read_lock();
	ptype = gro_find_complete_by_type(type);
	if (ptype)
		err = ptype->callbacks.gro_complete(skb, nhoff + gh_len);

	rcu_read_unlock();
501 502 503

	skb_set_inner_mac_header(skb, nhoff + gh_len);

504 505 506 507 508
	return err;
}

/* Create new listen socket if needed */
static struct geneve_sock *geneve_socket_create(struct net *net, __be16 port,
509
						bool ipv6, bool ipv6_rx_csum)
510 511 512 513 514
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);
	struct geneve_sock *gs;
	struct socket *sock;
	struct udp_tunnel_sock_cfg tunnel_cfg;
515
	int h;
516 517 518 519 520

	gs = kzalloc(sizeof(*gs), GFP_KERNEL);
	if (!gs)
		return ERR_PTR(-ENOMEM);

521
	sock = geneve_create_sock(net, ipv6, port, ipv6_rx_csum);
522 523 524 525 526 527 528
	if (IS_ERR(sock)) {
		kfree(gs);
		return ERR_CAST(sock);
	}

	gs->sock = sock;
	gs->refcnt = 1;
529 530
	for (h = 0; h < VNI_HASH_SIZE; ++h)
		INIT_HLIST_HEAD(&gs->vni_list[h]);
531 532

	/* Initialize the geneve udp offloads structure */
533
	udp_tunnel_notify_add_rx_port(gs->sock, UDP_TUNNEL_TYPE_GENEVE);
534 535

	/* Mark socket as an encapsulation socket */
536
	memset(&tunnel_cfg, 0, sizeof(tunnel_cfg));
537 538
	tunnel_cfg.sk_user_data = gs;
	tunnel_cfg.encap_type = 1;
539 540
	tunnel_cfg.gro_receive = geneve_gro_receive;
	tunnel_cfg.gro_complete = geneve_gro_complete;
541 542 543 544 545 546 547
	tunnel_cfg.encap_rcv = geneve_udp_encap_recv;
	tunnel_cfg.encap_destroy = NULL;
	setup_udp_tunnel_sock(net, sock, &tunnel_cfg);
	list_add(&gs->list, &gn->sock_list);
	return gs;
}

548
static void __geneve_sock_release(struct geneve_sock *gs)
549
{
550
	if (!gs || --gs->refcnt)
551 552 553
		return;

	list_del(&gs->list);
554
	udp_tunnel_notify_del_rx_port(gs->sock, UDP_TUNNEL_TYPE_GENEVE);
555 556 557 558
	udp_tunnel_sock_release(gs->sock);
	kfree_rcu(gs, rcu);
}

559 560
static void geneve_sock_release(struct geneve_dev *geneve)
{
561
	struct geneve_sock *gs4 = rtnl_dereference(geneve->sock4);
562
#if IS_ENABLED(CONFIG_IPV6)
563 564 565 566 567 568 569 570 571 572 573
	struct geneve_sock *gs6 = rtnl_dereference(geneve->sock6);

	rcu_assign_pointer(geneve->sock6, NULL);
#endif

	rcu_assign_pointer(geneve->sock4, NULL);
	synchronize_net();

	__geneve_sock_release(gs4);
#if IS_ENABLED(CONFIG_IPV6)
	__geneve_sock_release(gs6);
574 575 576
#endif
}

577
static struct geneve_sock *geneve_find_sock(struct geneve_net *gn,
578
					    sa_family_t family,
579 580 581 582 583 584
					    __be16 dst_port)
{
	struct geneve_sock *gs;

	list_for_each_entry(gs, &gn->sock_list, list) {
		if (inet_sk(gs->sock->sk)->inet_sport == dst_port &&
585
		    geneve_get_sk_family(gs) == family) {
586 587 588 589 590 591
			return gs;
		}
	}
	return NULL;
}

592
static int geneve_sock_add(struct geneve_dev *geneve, bool ipv6)
593 594
{
	struct net *net = geneve->net;
595
	struct geneve_net *gn = net_generic(net, geneve_net_id);
J
Jiri Benc 已提交
596
	struct geneve_dev_node *node;
597
	struct geneve_sock *gs;
598
	__u8 vni[3];
599
	__u32 hash;
600

601
	gs = geneve_find_sock(gn, ipv6 ? AF_INET6 : AF_INET, geneve->info.key.tp_dst);
602 603 604 605 606
	if (gs) {
		gs->refcnt++;
		goto out;
	}

607 608
	gs = geneve_socket_create(net, geneve->info.key.tp_dst, ipv6,
				  geneve->use_udp6_rx_checksums);
609 610 611
	if (IS_ERR(gs))
		return PTR_ERR(gs);

612 613
out:
	gs->collect_md = geneve->collect_md;
614
#if IS_ENABLED(CONFIG_IPV6)
J
Jiri Benc 已提交
615
	if (ipv6) {
616
		rcu_assign_pointer(geneve->sock6, gs);
J
Jiri Benc 已提交
617 618
		node = &geneve->hlist6;
	} else
619
#endif
J
Jiri Benc 已提交
620
	{
621
		rcu_assign_pointer(geneve->sock4, gs);
J
Jiri Benc 已提交
622 623 624
		node = &geneve->hlist4;
	}
	node->geneve = geneve;
625

626 627
	tunnel_id_to_vni(geneve->info.key.tun_id, vni);
	hash = geneve_net_vni_hash(vni);
J
Jiri Benc 已提交
628
	hlist_add_head_rcu(&node->hlist, &gs->vni_list[hash]);
629 630 631
	return 0;
}

632 633 634
static int geneve_open(struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);
635
	bool ipv6 = !!(geneve->info.mode & IP_TUNNEL_INFO_IPV6);
636 637 638 639 640 641 642 643 644 645 646 647 648 649 650
	bool metadata = geneve->collect_md;
	int ret = 0;

#if IS_ENABLED(CONFIG_IPV6)
	if (ipv6 || metadata)
		ret = geneve_sock_add(geneve, true);
#endif
	if (!ret && (!ipv6 || metadata))
		ret = geneve_sock_add(geneve, false);
	if (ret < 0)
		geneve_sock_release(geneve);

	return ret;
}

651 652 653 654
static int geneve_stop(struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);

J
Jiri Benc 已提交
655 656 657 658
	hlist_del_init_rcu(&geneve->hlist4.hlist);
#if IS_ENABLED(CONFIG_IPV6)
	hlist_del_init_rcu(&geneve->hlist6.hlist);
#endif
659
	geneve_sock_release(geneve);
660 661 662
	return 0;
}

663
static void geneve_build_header(struct genevehdr *geneveh,
664
				const struct ip_tunnel_info *info)
665 666
{
	geneveh->ver = GENEVE_VER;
667 668 669
	geneveh->opt_len = info->options_len / 4;
	geneveh->oam = !!(info->key.tun_flags & TUNNEL_OAM);
	geneveh->critical = !!(info->key.tun_flags & TUNNEL_CRIT_OPT);
670
	geneveh->rsvd1 = 0;
671
	tunnel_id_to_vni(info->key.tun_id, geneveh->vni);
672 673 674
	geneveh->proto_type = htons(ETH_P_TEB);
	geneveh->rsvd2 = 0;

675
	ip_tunnel_info_opts_get(geneveh->options, info);
676 677
}

678 679 680
static int geneve_build_skb(struct dst_entry *dst, struct sk_buff *skb,
			    const struct ip_tunnel_info *info,
			    bool xnet, int ip_hdr_len)
681
{
682
	bool udp_sum = !!(info->key.tun_flags & TUNNEL_CSUM);
683 684 685 686
	struct genevehdr *gnvh;
	int min_headroom;
	int err;

687
	skb_reset_mac_header(skb);
688 689
	skb_scrub_packet(skb, xnet);

690 691
	min_headroom = LL_RESERVED_SPACE(dst->dev) + dst->header_len +
		       GENEVE_BASE_HLEN + info->options_len + ip_hdr_len;
692
	err = skb_cow_head(skb, min_headroom);
693
	if (unlikely(err))
694 695
		goto free_dst;

696
	err = udp_tunnel_handle_offloads(skb, udp_sum);
697
	if (err)
698 699
		goto free_dst;

700
	gnvh = __skb_push(skb, sizeof(*gnvh) + info->options_len);
701
	geneve_build_header(gnvh, info);
702 703 704 705 706 707 708 709 710 711
	skb_set_inner_protocol(skb, htons(ETH_P_TEB));
	return 0;

free_dst:
	dst_release(dst);
	return err;
}

static struct rtable *geneve_get_v4_rt(struct sk_buff *skb,
				       struct net_device *dev,
712
				       struct geneve_sock *gs4,
713
				       struct flowi4 *fl4,
714
				       const struct ip_tunnel_info *info)
715
{
716
	bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
717
	struct geneve_dev *geneve = netdev_priv(dev);
P
Paolo Abeni 已提交
718
	struct dst_cache *dst_cache;
719 720 721
	struct rtable *rt = NULL;
	__u8 tos;

722
	if (!gs4)
723 724
		return ERR_PTR(-EIO);

725 726 727
	memset(fl4, 0, sizeof(*fl4));
	fl4->flowi4_mark = skb->mark;
	fl4->flowi4_proto = IPPROTO_UDP;
728 729
	fl4->daddr = info->key.u.ipv4.dst;
	fl4->saddr = info->key.u.ipv4.src;
730

731 732 733 734
	tos = info->key.tos;
	if ((tos == 1) && !geneve->collect_md) {
		tos = ip_tunnel_get_dsfield(ip_hdr(skb), skb);
		use_cache = false;
P
Paolo Abeni 已提交
735
	}
736
	fl4->flowi4_tos = RT_TOS(tos);
P
Paolo Abeni 已提交
737

738
	dst_cache = (struct dst_cache *)&info->dst_cache;
P
Paolo Abeni 已提交
739 740 741 742
	if (use_cache) {
		rt = dst_cache_get_ip4(dst_cache, &fl4->saddr);
		if (rt)
			return rt;
743 744 745 746
	}
	rt = ip_route_output_key(geneve->net, fl4);
	if (IS_ERR(rt)) {
		netdev_dbg(dev, "no route to %pI4\n", &fl4->daddr);
747
		return ERR_PTR(-ENETUNREACH);
748 749 750 751
	}
	if (rt->dst.dev == dev) { /* is this necessary? */
		netdev_dbg(dev, "circular route to %pI4\n", &fl4->daddr);
		ip_rt_put(rt);
752
		return ERR_PTR(-ELOOP);
753
	}
P
Paolo Abeni 已提交
754 755
	if (use_cache)
		dst_cache_set_ip4(dst_cache, &rt->dst, fl4->saddr);
756 757 758
	return rt;
}

759 760 761
#if IS_ENABLED(CONFIG_IPV6)
static struct dst_entry *geneve_get_v6_dst(struct sk_buff *skb,
					   struct net_device *dev,
762
					   struct geneve_sock *gs6,
763
					   struct flowi6 *fl6,
764
					   const struct ip_tunnel_info *info)
765
{
766
	bool use_cache = ip_tunnel_dst_cache_usable(skb, info);
767 768
	struct geneve_dev *geneve = netdev_priv(dev);
	struct dst_entry *dst = NULL;
P
Paolo Abeni 已提交
769
	struct dst_cache *dst_cache;
770
	__u8 prio;
771

772 773 774
	if (!gs6)
		return ERR_PTR(-EIO);

775 776 777
	memset(fl6, 0, sizeof(*fl6));
	fl6->flowi6_mark = skb->mark;
	fl6->flowi6_proto = IPPROTO_UDP;
778 779 780 781 782 783
	fl6->daddr = info->key.u.ipv6.dst;
	fl6->saddr = info->key.u.ipv6.src;
	prio = info->key.tos;
	if ((prio == 1) && !geneve->collect_md) {
		prio = ip_tunnel_get_dsfield(ip_hdr(skb), skb);
		use_cache = false;
P
Paolo Abeni 已提交
784 785
	}

786 787
	fl6->flowlabel = ip6_make_flowinfo(RT_TOS(prio),
					   info->key.label);
788
	dst_cache = (struct dst_cache *)&info->dst_cache;
P
Paolo Abeni 已提交
789 790 791 792
	if (use_cache) {
		dst = dst_cache_get_ip6(dst_cache, &fl6->saddr);
		if (dst)
			return dst;
793 794 795 796 797 798 799 800 801 802 803
	}
	if (ipv6_stub->ipv6_dst_lookup(geneve->net, gs6->sock->sk, &dst, fl6)) {
		netdev_dbg(dev, "no route to %pI6\n", &fl6->daddr);
		return ERR_PTR(-ENETUNREACH);
	}
	if (dst->dev == dev) { /* is this necessary? */
		netdev_dbg(dev, "circular route to %pI6\n", &fl6->daddr);
		dst_release(dst);
		return ERR_PTR(-ELOOP);
	}

P
Paolo Abeni 已提交
804 805
	if (use_cache)
		dst_cache_set_ip6(dst_cache, dst, &fl6->saddr);
806 807 808 809
	return dst;
}
#endif

810
static int geneve_xmit_skb(struct sk_buff *skb, struct net_device *dev,
811 812
			   struct geneve_dev *geneve,
			   const struct ip_tunnel_info *info)
813
{
814 815 816 817
	bool xnet = !net_eq(geneve->net, dev_net(geneve->dev));
	struct geneve_sock *gs4 = rcu_dereference(geneve->sock4);
	const struct ip_tunnel_key *key = &info->key;
	struct rtable *rt;
818
	struct flowi4 fl4;
819
	__u8 tos, ttl;
820
	__be16 sport;
821
	__be16 df;
822
	int err;
823

824
	rt = geneve_get_v4_rt(skb, dev, gs4, &fl4, info);
825 826
	if (IS_ERR(rt))
		return PTR_ERR(rt);
827 828

	sport = udp_flow_src_port(geneve->net, skb, 1, USHRT_MAX, true);
829 830
	if (geneve->collect_md) {
		tos = ip_tunnel_ecn_encap(key->tos, ip_hdr(skb), skb);
831
		ttl = key->ttl;
832
	} else {
833 834
		tos = ip_tunnel_ecn_encap(fl4.flowi4_tos, ip_hdr(skb), skb);
		ttl = key->ttl ? : ip4_dst_hoplimit(&rt->dst);
835
	}
836
	df = key->tun_flags & TUNNEL_DONT_FRAGMENT ? htons(IP_DF) : 0;
837

838
	err = geneve_build_skb(&rt->dst, skb, info, xnet, sizeof(struct iphdr));
839 840
	if (unlikely(err))
		return err;
H
Haishuang Yan 已提交
841

842 843 844 845 846
	udp_tunnel_xmit_skb(rt, gs4->sock->sk, skb, fl4.saddr, fl4.daddr,
			    tos, ttl, df, sport, geneve->info.key.tp_dst,
			    !net_eq(geneve->net, dev_net(geneve->dev)),
			    !(info->key.tun_flags & TUNNEL_CSUM));
	return 0;
847 848
}

849
#if IS_ENABLED(CONFIG_IPV6)
850
static int geneve6_xmit_skb(struct sk_buff *skb, struct net_device *dev,
851 852
			    struct geneve_dev *geneve,
			    const struct ip_tunnel_info *info)
853
{
854 855 856
	bool xnet = !net_eq(geneve->net, dev_net(geneve->dev));
	struct geneve_sock *gs6 = rcu_dereference(geneve->sock6);
	const struct ip_tunnel_key *key = &info->key;
857 858
	struct dst_entry *dst = NULL;
	struct flowi6 fl6;
859
	__u8 prio, ttl;
860
	__be16 sport;
861
	int err;
862

863
	dst = geneve_get_v6_dst(skb, dev, gs6, &fl6, info);
864 865
	if (IS_ERR(dst))
		return PTR_ERR(dst);
866 867

	sport = udp_flow_src_port(geneve->net, skb, 1, USHRT_MAX, true);
868 869 870 871 872 873 874 875
	if (geneve->collect_md) {
		prio = ip_tunnel_ecn_encap(key->tos, ip_hdr(skb), skb);
		ttl = key->ttl;
	} else {
		prio = ip_tunnel_ecn_encap(ip6_tclass(fl6.flowlabel),
					   ip_hdr(skb), skb);
		ttl = key->ttl ? : ip6_dst_hoplimit(dst);
	}
876
	err = geneve_build_skb(dst, skb, info, xnet, sizeof(struct ipv6hdr));
877 878
	if (unlikely(err))
		return err;
879

880 881 882 883 884 885 886
	udp_tunnel6_xmit_skb(dst, gs6->sock->sk, skb, dev,
			     &fl6.saddr, &fl6.daddr, prio, ttl,
			     info->key.label, sport, geneve->info.key.tp_dst,
			     !(info->key.tun_flags & TUNNEL_CSUM));
	return 0;
}
#endif
887

888 889 890 891 892
static netdev_tx_t geneve_xmit(struct sk_buff *skb, struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);
	struct ip_tunnel_info *info = NULL;
	int err;
893

894 895 896 897 898
	if (geneve->collect_md) {
		info = skb_tunnel_info(skb);
		if (unlikely(!info || !(info->mode & IP_TUNNEL_INFO_TX))) {
			err = -EINVAL;
			netdev_dbg(dev, "no tunnel metadata\n");
899
			goto tx_error;
900
		}
901
	} else {
902
		info = &geneve->info;
903
	}
904

J
Jakub Kicinski 已提交
905
	rcu_read_lock();
906 907 908 909 910 911
#if IS_ENABLED(CONFIG_IPV6)
	if (info->mode & IP_TUNNEL_INFO_IPV6)
		err = geneve6_xmit_skb(skb, dev, geneve, info);
	else
#endif
		err = geneve_xmit_skb(skb, dev, geneve, info);
J
Jakub Kicinski 已提交
912
	rcu_read_unlock();
913

914 915
	if (likely(!err))
		return NETDEV_TX_OK;
916 917
tx_error:
	dev_kfree_skb(skb);
918

919 920 921 922
	if (err == -ELOOP)
		dev->stats.collisions++;
	else if (err == -ENETUNREACH)
		dev->stats.tx_carrier_errors++;
H
Haishuang Yan 已提交
923 924

	dev->stats.tx_errors++;
925 926 927
	return NETDEV_TX_OK;
}

928
static int geneve_change_mtu(struct net_device *dev, int new_mtu)
D
David Wragg 已提交
929
{
930 931
	/* Only possible if called internally, ndo_change_mtu path's new_mtu
	 * is guaranteed to be between dev->min_mtu and dev->max_mtu.
D
David Wragg 已提交
932
	 */
933 934
	if (new_mtu > dev->max_mtu)
		new_mtu = dev->max_mtu;
D
David Wragg 已提交
935

D
David Wragg 已提交
936 937 938 939
	dev->mtu = new_mtu;
	return 0;
}

940 941 942 943 944
static int geneve_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb)
{
	struct ip_tunnel_info *info = skb_tunnel_info(skb);
	struct geneve_dev *geneve = netdev_priv(dev);

945
	if (ip_tunnel_info_af(info) == AF_INET) {
946 947
		struct rtable *rt;
		struct flowi4 fl4;
948
		struct geneve_sock *gs4 = rcu_dereference(geneve->sock4);
949

950
		rt = geneve_get_v4_rt(skb, dev, gs4, &fl4, info);
951 952
		if (IS_ERR(rt))
			return PTR_ERR(rt);
953

954 955 956 957
		ip_rt_put(rt);
		info->key.u.ipv4.src = fl4.saddr;
#if IS_ENABLED(CONFIG_IPV6)
	} else if (ip_tunnel_info_af(info) == AF_INET6) {
958 959
		struct dst_entry *dst;
		struct flowi6 fl6;
960
		struct geneve_sock *gs6 = rcu_dereference(geneve->sock6);
961

962
		dst = geneve_get_v6_dst(skb, dev, gs6, &fl6, info);
963 964 965 966 967 968 969 970 971
		if (IS_ERR(dst))
			return PTR_ERR(dst);

		dst_release(dst);
		info->key.u.ipv6.src = fl6.saddr;
#endif
	} else {
		return -EINVAL;
	}
972 973 974

	info->key.tp_src = udp_flow_src_port(geneve->net, skb,
					     1, USHRT_MAX, true);
975
	info->key.tp_dst = geneve->info.key.tp_dst;
976 977 978
	return 0;
}

979 980 981 982 983 984 985
static const struct net_device_ops geneve_netdev_ops = {
	.ndo_init		= geneve_init,
	.ndo_uninit		= geneve_uninit,
	.ndo_open		= geneve_open,
	.ndo_stop		= geneve_stop,
	.ndo_start_xmit		= geneve_xmit,
	.ndo_get_stats64	= ip_tunnel_get_stats64,
D
David Wragg 已提交
986
	.ndo_change_mtu		= geneve_change_mtu,
987 988
	.ndo_validate_addr	= eth_validate_addr,
	.ndo_set_mac_address	= eth_mac_addr,
989
	.ndo_fill_metadata_dst	= geneve_fill_metadata_dst,
990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008
};

static void geneve_get_drvinfo(struct net_device *dev,
			       struct ethtool_drvinfo *drvinfo)
{
	strlcpy(drvinfo->version, GENEVE_NETDEV_VER, sizeof(drvinfo->version));
	strlcpy(drvinfo->driver, "geneve", sizeof(drvinfo->driver));
}

static const struct ethtool_ops geneve_ethtool_ops = {
	.get_drvinfo	= geneve_get_drvinfo,
	.get_link	= ethtool_op_get_link,
};

/* Info for udev, that this is a virtual tunnel endpoint */
static struct device_type geneve_type = {
	.name = "geneve",
};

1009
/* Calls the ndo_udp_tunnel_add of the caller in order to
1010
 * supply the listening GENEVE udp ports. Callers are expected
1011
 * to implement the ndo_udp_tunnel_add.
1012
 */
1013
static void geneve_offload_rx_ports(struct net_device *dev, bool push)
1014 1015 1016 1017
{
	struct net *net = dev_net(dev);
	struct geneve_net *gn = net_generic(net, geneve_net_id);
	struct geneve_sock *gs;
1018

1019
	rcu_read_lock();
1020 1021 1022 1023 1024 1025 1026 1027 1028
	list_for_each_entry_rcu(gs, &gn->sock_list, list) {
		if (push) {
			udp_tunnel_push_rx_port(dev, gs->sock,
						UDP_TUNNEL_TYPE_GENEVE);
		} else {
			udp_tunnel_drop_rx_port(dev, gs->sock,
						UDP_TUNNEL_TYPE_GENEVE);
		}
	}
1029 1030 1031
	rcu_read_unlock();
}

1032 1033 1034 1035 1036 1037 1038
/* Initialize the device structure. */
static void geneve_setup(struct net_device *dev)
{
	ether_setup(dev);

	dev->netdev_ops = &geneve_netdev_ops;
	dev->ethtool_ops = &geneve_ethtool_ops;
1039
	dev->needs_free_netdev = true;
1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050

	SET_NETDEV_DEVTYPE(dev, &geneve_type);

	dev->features    |= NETIF_F_LLTX;
	dev->features    |= NETIF_F_SG | NETIF_F_HW_CSUM;
	dev->features    |= NETIF_F_RXCSUM;
	dev->features    |= NETIF_F_GSO_SOFTWARE;

	dev->hw_features |= NETIF_F_SG | NETIF_F_HW_CSUM | NETIF_F_RXCSUM;
	dev->hw_features |= NETIF_F_GSO_SOFTWARE;

1051 1052 1053 1054 1055 1056 1057 1058
	/* MTU range: 68 - (something less than 65535) */
	dev->min_mtu = ETH_MIN_MTU;
	/* The max_mtu calculation does not take account of GENEVE
	 * options, to avoid excluding potentially valid
	 * configurations. This will be further reduced by IPvX hdr size.
	 */
	dev->max_mtu = IP_MAX_MTU - GENEVE_BASE_HLEN - dev->hard_header_len;

1059
	netif_keep_dst(dev);
J
Jiri Benc 已提交
1060
	dev->priv_flags &= ~IFF_TX_SKB_SHARING;
1061
	dev->priv_flags |= IFF_LIVE_ADDR_CHANGE | IFF_NO_QUEUE;
1062
	eth_hw_addr_random(dev);
1063 1064 1065 1066 1067
}

static const struct nla_policy geneve_policy[IFLA_GENEVE_MAX + 1] = {
	[IFLA_GENEVE_ID]		= { .type = NLA_U32 },
	[IFLA_GENEVE_REMOTE]		= { .len = FIELD_SIZEOF(struct iphdr, daddr) },
1068
	[IFLA_GENEVE_REMOTE6]		= { .len = sizeof(struct in6_addr) },
1069
	[IFLA_GENEVE_TTL]		= { .type = NLA_U8 },
1070
	[IFLA_GENEVE_TOS]		= { .type = NLA_U8 },
1071
	[IFLA_GENEVE_LABEL]		= { .type = NLA_U32 },
1072
	[IFLA_GENEVE_PORT]		= { .type = NLA_U16 },
1073
	[IFLA_GENEVE_COLLECT_METADATA]	= { .type = NLA_FLAG },
1074 1075 1076
	[IFLA_GENEVE_UDP_CSUM]		= { .type = NLA_U8 },
	[IFLA_GENEVE_UDP_ZERO_CSUM6_TX]	= { .type = NLA_U8 },
	[IFLA_GENEVE_UDP_ZERO_CSUM6_RX]	= { .type = NLA_U8 },
1077 1078
};

1079 1080
static int geneve_validate(struct nlattr *tb[], struct nlattr *data[],
			   struct netlink_ext_ack *extack)
1081 1082
{
	if (tb[IFLA_ADDRESS]) {
1083 1084 1085
		if (nla_len(tb[IFLA_ADDRESS]) != ETH_ALEN) {
			NL_SET_ERR_MSG_ATTR(extack, tb[IFLA_ADDRESS],
					    "Provided link layer address is not Ethernet");
1086
			return -EINVAL;
1087
		}
1088

1089 1090 1091
		if (!is_valid_ether_addr(nla_data(tb[IFLA_ADDRESS]))) {
			NL_SET_ERR_MSG_ATTR(extack, tb[IFLA_ADDRESS],
					    "Provided Ethernet address is not unicast");
1092
			return -EADDRNOTAVAIL;
1093
		}
1094 1095
	}

1096 1097 1098
	if (!data) {
		NL_SET_ERR_MSG(extack,
			       "Not enough attributes provided to perform the operation");
1099
		return -EINVAL;
1100
	}
1101 1102 1103 1104

	if (data[IFLA_GENEVE_ID]) {
		__u32 vni =  nla_get_u32(data[IFLA_GENEVE_ID]);

1105 1106 1107
		if (vni >= GENEVE_N_VID) {
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_ID],
					    "Geneve ID must be lower than 16777216");
1108
			return -ERANGE;
1109
		}
1110 1111 1112 1113 1114
	}

	return 0;
}

1115
static struct geneve_dev *geneve_find_dev(struct geneve_net *gn,
1116
					  const struct ip_tunnel_info *info,
1117 1118 1119
					  bool *tun_on_same_port,
					  bool *tun_collect_md)
{
1120
	struct geneve_dev *geneve, *t = NULL;
1121 1122 1123 1124

	*tun_on_same_port = false;
	*tun_collect_md = false;
	list_for_each_entry(geneve, &gn->geneve_list, next) {
1125
		if (info->key.tp_dst == geneve->info.key.tp_dst) {
1126 1127 1128
			*tun_collect_md = geneve->collect_md;
			*tun_on_same_port = true;
		}
1129 1130 1131
		if (info->key.tun_id == geneve->info.key.tun_id &&
		    info->key.tp_dst == geneve->info.key.tp_dst &&
		    !memcmp(&info->key.u, &geneve->info.key.u, sizeof(info->key.u)))
1132 1133 1134 1135 1136
			t = geneve;
	}
	return t;
}

1137 1138
static bool is_tnl_info_zero(const struct ip_tunnel_info *info)
{
1139 1140 1141
	return !(info->key.tun_id || info->key.tun_flags || info->key.tos ||
		 info->key.ttl || info->key.label || info->key.tp_src ||
		 memchr_inv(&info->key.u, 0, sizeof(info->key.u)));
1142 1143
}

1144 1145 1146 1147 1148 1149 1150 1151 1152
static bool geneve_dst_addr_equal(struct ip_tunnel_info *a,
				  struct ip_tunnel_info *b)
{
	if (ip_tunnel_info_af(a) == AF_INET)
		return a->key.u.ipv4.dst == b->key.u.ipv4.dst;
	else
		return ipv6_addr_equal(&a->key.u.ipv6.dst, &b->key.u.ipv6.dst);
}

1153
static int geneve_configure(struct net *net, struct net_device *dev,
1154
			    struct netlink_ext_ack *extack,
1155 1156
			    const struct ip_tunnel_info *info,
			    bool metadata, bool ipv6_rx_csum)
1157 1158
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);
1159 1160
	struct geneve_dev *t, *geneve = netdev_priv(dev);
	bool tun_collect_md, tun_on_same_port;
P
Paolo Abeni 已提交
1161
	int err, encap_len;
1162

1163 1164 1165
	if (metadata && !is_tnl_info_zero(info)) {
		NL_SET_ERR_MSG(extack,
			       "Device is externally controlled, so attributes (VNI, Port, and so on) must not be specified");
1166
		return -EINVAL;
1167
	}
1168 1169 1170 1171

	geneve->net = net;
	geneve->dev = dev;

1172
	t = geneve_find_dev(gn, info, &tun_on_same_port, &tun_collect_md);
1173 1174 1175
	if (t)
		return -EBUSY;

P
Paolo Abeni 已提交
1176 1177
	/* make enough headroom for basic scenario */
	encap_len = GENEVE_BASE_HLEN + ETH_HLEN;
1178
	if (!metadata && ip_tunnel_info_af(info) == AF_INET) {
P
Paolo Abeni 已提交
1179
		encap_len += sizeof(struct iphdr);
1180 1181
		dev->max_mtu -= sizeof(struct iphdr);
	} else {
P
Paolo Abeni 已提交
1182
		encap_len += sizeof(struct ipv6hdr);
1183 1184
		dev->max_mtu -= sizeof(struct ipv6hdr);
	}
P
Paolo Abeni 已提交
1185 1186
	dev->needed_headroom = encap_len + ETH_HLEN;

1187
	if (metadata) {
1188 1189 1190
		if (tun_on_same_port) {
			NL_SET_ERR_MSG(extack,
				       "There can be only one externally controlled device on a destination port");
1191
			return -EPERM;
1192
		}
1193
	} else {
1194 1195 1196
		if (tun_collect_md) {
			NL_SET_ERR_MSG(extack,
				       "There already exists an externally controlled device on this destination port");
1197
			return -EPERM;
1198
		}
1199 1200
	}

1201 1202 1203 1204
	dst_cache_reset(&geneve->info.dst_cache);
	geneve->info = *info;
	geneve->collect_md = metadata;
	geneve->use_udp6_rx_checksums = ipv6_rx_csum;
P
Paolo Abeni 已提交
1205

1206 1207 1208 1209
	err = register_netdevice(dev);
	if (err)
		return err;

1210 1211 1212 1213
	list_add(&geneve->next, &gn->geneve_list);
	return 0;
}

1214 1215 1216 1217 1218 1219
static void init_tnl_info(struct ip_tunnel_info *info, __u16 dst_port)
{
	memset(info, 0, sizeof(*info));
	info->key.tp_dst = htons(dst_port);
}

1220 1221 1222 1223
static int geneve_nl2info(struct nlattr *tb[], struct nlattr *data[],
			  struct netlink_ext_ack *extack,
			  struct ip_tunnel_info *info, bool *metadata,
			  bool *use_udp6_rx_checksums, bool changelink)
1224
{
1225 1226 1227 1228 1229
	int attrtype;

	if (data[IFLA_GENEVE_REMOTE] && data[IFLA_GENEVE_REMOTE6]) {
		NL_SET_ERR_MSG(extack,
			       "Cannot specify both IPv4 and IPv6 Remote addresses");
1230
		return -EINVAL;
1231
	}
1232 1233

	if (data[IFLA_GENEVE_REMOTE]) {
1234 1235 1236 1237
		if (changelink && (ip_tunnel_info_af(info) == AF_INET6)) {
			attrtype = IFLA_GENEVE_REMOTE;
			goto change_notsup;
		}
1238 1239

		info->key.u.ipv4.dst =
1240
			nla_get_in_addr(data[IFLA_GENEVE_REMOTE]);
1241

1242
		if (IN_MULTICAST(ntohl(info->key.u.ipv4.dst))) {
1243 1244
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE],
					    "Remote IPv4 address cannot be Multicast");
1245 1246
			return -EINVAL;
		}
1247 1248 1249
	}

	if (data[IFLA_GENEVE_REMOTE6]) {
1250
 #if IS_ENABLED(CONFIG_IPV6)
1251 1252 1253 1254
		if (changelink && (ip_tunnel_info_af(info) == AF_INET)) {
			attrtype = IFLA_GENEVE_REMOTE6;
			goto change_notsup;
		}
1255 1256 1257

		info->mode = IP_TUNNEL_INFO_IPV6;
		info->key.u.ipv6.dst =
1258 1259
			nla_get_in6_addr(data[IFLA_GENEVE_REMOTE6]);

1260
		if (ipv6_addr_type(&info->key.u.ipv6.dst) &
1261
		    IPV6_ADDR_LINKLOCAL) {
1262 1263
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE6],
					    "Remote IPv6 address cannot be link-local");
1264 1265
			return -EINVAL;
		}
1266
		if (ipv6_addr_is_multicast(&info->key.u.ipv6.dst)) {
1267 1268
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE6],
					    "Remote IPv6 address cannot be Multicast");
1269 1270
			return -EINVAL;
		}
1271 1272
		info->key.tun_flags |= TUNNEL_CSUM;
		*use_udp6_rx_checksums = true;
1273
#else
1274 1275
		NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_REMOTE6],
				    "IPv6 support not enabled in the kernel");
1276 1277
		return -EPFNOSUPPORT;
#endif
1278 1279
	}

1280 1281 1282
	if (data[IFLA_GENEVE_ID]) {
		__u32 vni;
		__u8 tvni[3];
1283
		__be64 tunid;
1284

1285
		vni = nla_get_u32(data[IFLA_GENEVE_ID]);
1286 1287 1288
		tvni[0] = (vni & 0x00ff0000) >> 16;
		tvni[1] = (vni & 0x0000ff00) >> 8;
		tvni[2] =  vni & 0x000000ff;
1289

1290
		tunid = vni_to_tunnel_id(tvni);
1291 1292 1293 1294
		if (changelink && (tunid != info->key.tun_id)) {
			attrtype = IFLA_GENEVE_ID;
			goto change_notsup;
		}
1295
		info->key.tun_id = tunid;
1296
	}
1297

1298
	if (data[IFLA_GENEVE_TTL])
1299
		info->key.ttl = nla_get_u8(data[IFLA_GENEVE_TTL]);
1300

1301
	if (data[IFLA_GENEVE_TOS])
1302
		info->key.tos = nla_get_u8(data[IFLA_GENEVE_TOS]);
1303

1304
	if (data[IFLA_GENEVE_LABEL]) {
1305
		info->key.label = nla_get_be32(data[IFLA_GENEVE_LABEL]) &
1306
				  IPV6_FLOWLABEL_MASK;
1307 1308 1309
		if (info->key.label && (!(info->mode & IP_TUNNEL_INFO_IPV6))) {
			NL_SET_ERR_MSG_ATTR(extack, data[IFLA_GENEVE_LABEL],
					    "Label attribute only applies for IPv6 Geneve devices");
1310
			return -EINVAL;
1311
		}
1312
	}
1313

1314
	if (data[IFLA_GENEVE_PORT]) {
1315 1316 1317 1318
		if (changelink) {
			attrtype = IFLA_GENEVE_PORT;
			goto change_notsup;
		}
1319 1320
		info->key.tp_dst = nla_get_be16(data[IFLA_GENEVE_PORT]);
	}
1321

1322
	if (data[IFLA_GENEVE_COLLECT_METADATA]) {
1323 1324 1325 1326
		if (changelink) {
			attrtype = IFLA_GENEVE_COLLECT_METADATA;
			goto change_notsup;
		}
1327 1328
		*metadata = true;
	}
1329

1330
	if (data[IFLA_GENEVE_UDP_CSUM]) {
1331 1332 1333 1334
		if (changelink) {
			attrtype = IFLA_GENEVE_UDP_CSUM;
			goto change_notsup;
		}
1335 1336 1337
		if (nla_get_u8(data[IFLA_GENEVE_UDP_CSUM]))
			info->key.tun_flags |= TUNNEL_CSUM;
	}
1338

1339
	if (data[IFLA_GENEVE_UDP_ZERO_CSUM6_TX]) {
1340 1341 1342 1343
		if (changelink) {
			attrtype = IFLA_GENEVE_UDP_ZERO_CSUM6_TX;
			goto change_notsup;
		}
1344 1345 1346
		if (nla_get_u8(data[IFLA_GENEVE_UDP_ZERO_CSUM6_TX]))
			info->key.tun_flags &= ~TUNNEL_CSUM;
	}
1347

1348
	if (data[IFLA_GENEVE_UDP_ZERO_CSUM6_RX]) {
1349 1350 1351 1352
		if (changelink) {
			attrtype = IFLA_GENEVE_UDP_ZERO_CSUM6_RX;
			goto change_notsup;
		}
1353 1354 1355 1356 1357
		if (nla_get_u8(data[IFLA_GENEVE_UDP_ZERO_CSUM6_RX]))
			*use_udp6_rx_checksums = false;
	}

	return 0;
1358 1359 1360 1361
change_notsup:
	NL_SET_ERR_MSG_ATTR(extack, data[attrtype],
			    "Changing VNI, Port, endpoint IP address family, external, and UDP checksum attributes are not supported");
	return -EOPNOTSUPP;
1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373
}

static int geneve_newlink(struct net *net, struct net_device *dev,
			  struct nlattr *tb[], struct nlattr *data[],
			  struct netlink_ext_ack *extack)
{
	bool use_udp6_rx_checksums = false;
	struct ip_tunnel_info info;
	bool metadata = false;
	int err;

	init_tnl_info(&info, GENEVE_UDP_PORT);
1374
	err = geneve_nl2info(tb, data, extack, &info, &metadata,
1375 1376 1377
			     &use_udp6_rx_checksums, false);
	if (err)
		return err;
1378

1379 1380
	return geneve_configure(net, dev, extack, &info, metadata,
				use_udp6_rx_checksums);
1381 1382
}

1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448
/* Quiesces the geneve device data path for both TX and RX.
 *
 * On transmit geneve checks for non-NULL geneve_sock before it proceeds.
 * So, if we set that socket to NULL under RCU and wait for synchronize_net()
 * to complete for the existing set of in-flight packets to be transmitted,
 * then we would have quiesced the transmit data path. All the future packets
 * will get dropped until we unquiesce the data path.
 *
 * On receive geneve dereference the geneve_sock stashed in the socket. So,
 * if we set that to NULL under RCU and wait for synchronize_net() to
 * complete, then we would have quiesced the receive data path.
 */
static void geneve_quiesce(struct geneve_dev *geneve, struct geneve_sock **gs4,
			   struct geneve_sock **gs6)
{
	*gs4 = rtnl_dereference(geneve->sock4);
	rcu_assign_pointer(geneve->sock4, NULL);
	if (*gs4)
		rcu_assign_sk_user_data((*gs4)->sock->sk, NULL);
#if IS_ENABLED(CONFIG_IPV6)
	*gs6 = rtnl_dereference(geneve->sock6);
	rcu_assign_pointer(geneve->sock6, NULL);
	if (*gs6)
		rcu_assign_sk_user_data((*gs6)->sock->sk, NULL);
#else
	*gs6 = NULL;
#endif
	synchronize_net();
}

/* Resumes the geneve device data path for both TX and RX. */
static void geneve_unquiesce(struct geneve_dev *geneve, struct geneve_sock *gs4,
			     struct geneve_sock __maybe_unused *gs6)
{
	rcu_assign_pointer(geneve->sock4, gs4);
	if (gs4)
		rcu_assign_sk_user_data(gs4->sock->sk, gs4);
#if IS_ENABLED(CONFIG_IPV6)
	rcu_assign_pointer(geneve->sock6, gs6);
	if (gs6)
		rcu_assign_sk_user_data(gs6->sock->sk, gs6);
#endif
	synchronize_net();
}

static int geneve_changelink(struct net_device *dev, struct nlattr *tb[],
			     struct nlattr *data[],
			     struct netlink_ext_ack *extack)
{
	struct geneve_dev *geneve = netdev_priv(dev);
	struct geneve_sock *gs4, *gs6;
	struct ip_tunnel_info info;
	bool metadata;
	bool use_udp6_rx_checksums;
	int err;

	/* If the geneve device is configured for metadata (or externally
	 * controlled, for example, OVS), then nothing can be changed.
	 */
	if (geneve->collect_md)
		return -EOPNOTSUPP;

	/* Start with the existing info. */
	memcpy(&info, &geneve->info, sizeof(info));
	metadata = geneve->collect_md;
	use_udp6_rx_checksums = geneve->use_udp6_rx_checksums;
1449
	err = geneve_nl2info(tb, data, extack, &info, &metadata,
1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465
			     &use_udp6_rx_checksums, true);
	if (err)
		return err;

	if (!geneve_dst_addr_equal(&geneve->info, &info))
		dst_cache_reset(&info.dst_cache);

	geneve_quiesce(geneve, &gs4, &gs6);
	geneve->info = info;
	geneve->collect_md = metadata;
	geneve->use_udp6_rx_checksums = use_udp6_rx_checksums;
	geneve_unquiesce(geneve, gs4, gs6);

	return 0;
}

1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476
static void geneve_dellink(struct net_device *dev, struct list_head *head)
{
	struct geneve_dev *geneve = netdev_priv(dev);

	list_del(&geneve->next);
	unregister_netdevice_queue(dev, head);
}

static size_t geneve_get_size(const struct net_device *dev)
{
	return nla_total_size(sizeof(__u32)) +	/* IFLA_GENEVE_ID */
1477
		nla_total_size(sizeof(struct in6_addr)) + /* IFLA_GENEVE_REMOTE{6} */
1478
		nla_total_size(sizeof(__u8)) +  /* IFLA_GENEVE_TTL */
1479
		nla_total_size(sizeof(__u8)) +  /* IFLA_GENEVE_TOS */
1480
		nla_total_size(sizeof(__be32)) +  /* IFLA_GENEVE_LABEL */
1481
		nla_total_size(sizeof(__be16)) +  /* IFLA_GENEVE_PORT */
1482
		nla_total_size(0) +	 /* IFLA_GENEVE_COLLECT_METADATA */
1483 1484 1485
		nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_UDP_CSUM */
		nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_UDP_ZERO_CSUM6_TX */
		nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_UDP_ZERO_CSUM6_RX */
1486 1487 1488 1489 1490 1491
		0;
}

static int geneve_fill_info(struct sk_buff *skb, const struct net_device *dev)
{
	struct geneve_dev *geneve = netdev_priv(dev);
1492 1493
	struct ip_tunnel_info *info = &geneve->info;
	__u8 tmp_vni[3];
1494 1495
	__u32 vni;

1496 1497
	tunnel_id_to_vni(info->key.tun_id, tmp_vni);
	vni = (tmp_vni[0] << 16) | (tmp_vni[1] << 8) | tmp_vni[2];
1498 1499 1500
	if (nla_put_u32(skb, IFLA_GENEVE_ID, vni))
		goto nla_put_failure;

1501
	if (rtnl_dereference(geneve->sock4)) {
1502
		if (nla_put_in_addr(skb, IFLA_GENEVE_REMOTE,
1503 1504 1505 1506 1507
				    info->key.u.ipv4.dst))
			goto nla_put_failure;

		if (nla_put_u8(skb, IFLA_GENEVE_UDP_CSUM,
			       !!(info->key.tun_flags & TUNNEL_CSUM)))
1508
			goto nla_put_failure;
1509

1510 1511
	}

1512
#if IS_ENABLED(CONFIG_IPV6)
1513
	if (rtnl_dereference(geneve->sock6)) {
1514
		if (nla_put_in6_addr(skb, IFLA_GENEVE_REMOTE6,
1515 1516 1517 1518 1519 1520 1521 1522 1523
				     &info->key.u.ipv6.dst))
			goto nla_put_failure;

		if (nla_put_u8(skb, IFLA_GENEVE_UDP_ZERO_CSUM6_TX,
			       !(info->key.tun_flags & TUNNEL_CSUM)))
			goto nla_put_failure;

		if (nla_put_u8(skb, IFLA_GENEVE_UDP_ZERO_CSUM6_RX,
			       !geneve->use_udp6_rx_checksums))
1524 1525
			goto nla_put_failure;
	}
1526
#endif
1527

1528 1529 1530
	if (nla_put_u8(skb, IFLA_GENEVE_TTL, info->key.ttl) ||
	    nla_put_u8(skb, IFLA_GENEVE_TOS, info->key.tos) ||
	    nla_put_be32(skb, IFLA_GENEVE_LABEL, info->key.label))
1531 1532
		goto nla_put_failure;

1533
	if (nla_put_be16(skb, IFLA_GENEVE_PORT, info->key.tp_dst))
1534 1535
		goto nla_put_failure;

1536 1537 1538 1539
	if (geneve->collect_md) {
		if (nla_put_flag(skb, IFLA_GENEVE_COLLECT_METADATA))
			goto nla_put_failure;
	}
1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553
	return 0;

nla_put_failure:
	return -EMSGSIZE;
}

static struct rtnl_link_ops geneve_link_ops __read_mostly = {
	.kind		= "geneve",
	.maxtype	= IFLA_GENEVE_MAX,
	.policy		= geneve_policy,
	.priv_size	= sizeof(struct geneve_dev),
	.setup		= geneve_setup,
	.validate	= geneve_validate,
	.newlink	= geneve_newlink,
1554
	.changelink	= geneve_changelink,
1555 1556 1557 1558 1559
	.dellink	= geneve_dellink,
	.get_size	= geneve_get_size,
	.fill_info	= geneve_fill_info,
};

1560 1561 1562 1563
struct net_device *geneve_dev_create_fb(struct net *net, const char *name,
					u8 name_assign_type, u16 dst_port)
{
	struct nlattr *tb[IFLA_MAX + 1];
1564
	struct ip_tunnel_info info;
1565
	struct net_device *dev;
1566
	LIST_HEAD(list_kill);
1567 1568 1569 1570 1571 1572 1573 1574
	int err;

	memset(tb, 0, sizeof(tb));
	dev = rtnl_create_link(net, name, name_assign_type,
			       &geneve_link_ops, tb);
	if (IS_ERR(dev))
		return dev;

1575
	init_tnl_info(&info, dst_port);
1576
	err = geneve_configure(net, dev, NULL, &info, true, true);
1577 1578 1579 1580
	if (err) {
		free_netdev(dev);
		return ERR_PTR(err);
	}
1581 1582 1583 1584

	/* openvswitch users expect packet sizes to be unrestricted,
	 * so set the largest MTU we can.
	 */
1585
	err = geneve_change_mtu(dev, IP_MAX_MTU);
1586 1587 1588
	if (err)
		goto err;

1589 1590 1591 1592
	err = rtnl_configure_link(dev, NULL);
	if (err < 0)
		goto err;

1593
	return dev;
1594
err:
1595 1596
	geneve_dellink(dev, &list_kill);
	unregister_netdevice_many(&list_kill);
1597
	return ERR_PTR(err);
1598 1599 1600
}
EXPORT_SYMBOL_GPL(geneve_dev_create_fb);

1601 1602 1603 1604 1605
static int geneve_netdevice_event(struct notifier_block *unused,
				  unsigned long event, void *ptr)
{
	struct net_device *dev = netdev_notifier_info_to_dev(ptr);

1606
	if (event == NETDEV_UDP_TUNNEL_PUSH_INFO ||
1607
	    event == NETDEV_UDP_TUNNEL_DROP_INFO) {
1608
		geneve_offload_rx_ports(dev, event == NETDEV_UDP_TUNNEL_PUSH_INFO);
1609 1610 1611 1612 1613
	} else if (event == NETDEV_UNREGISTER) {
		geneve_offload_rx_ports(dev, false);
	} else if (event == NETDEV_REGISTER) {
		geneve_offload_rx_ports(dev, true);
	}
1614 1615 1616 1617 1618 1619 1620 1621

	return NOTIFY_DONE;
}

static struct notifier_block geneve_notifier_block __read_mostly = {
	.notifier_call = geneve_netdevice_event,
};

1622 1623 1624 1625 1626
static __net_init int geneve_init_net(struct net *net)
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);

	INIT_LIST_HEAD(&gn->geneve_list);
1627
	INIT_LIST_HEAD(&gn->sock_list);
1628 1629 1630 1631 1632 1633 1634 1635 1636 1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656
	return 0;
}

static void __net_exit geneve_exit_net(struct net *net)
{
	struct geneve_net *gn = net_generic(net, geneve_net_id);
	struct geneve_dev *geneve, *next;
	struct net_device *dev, *aux;
	LIST_HEAD(list);

	rtnl_lock();

	/* gather any geneve devices that were moved into this ns */
	for_each_netdev_safe(net, dev, aux)
		if (dev->rtnl_link_ops == &geneve_link_ops)
			unregister_netdevice_queue(dev, &list);

	/* now gather any other geneve devices that were created in this ns */
	list_for_each_entry_safe(geneve, next, &gn->geneve_list, next) {
		/* If geneve->dev is in the same netns, it was already added
		 * to the list by the previous loop.
		 */
		if (!net_eq(dev_net(geneve->dev), net))
			unregister_netdevice_queue(geneve->dev, &list);
	}

	/* unregister the devices gathered above */
	unregister_netdevice_many(&list);
	rtnl_unlock();
1657
	WARN_ON_ONCE(!list_empty(&gn->sock_list));
1658 1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674
}

static struct pernet_operations geneve_net_ops = {
	.init = geneve_init_net,
	.exit = geneve_exit_net,
	.id   = &geneve_net_id,
	.size = sizeof(struct geneve_net),
};

static int __init geneve_init_module(void)
{
	int rc;

	rc = register_pernet_subsys(&geneve_net_ops);
	if (rc)
		goto out1;

1675
	rc = register_netdevice_notifier(&geneve_notifier_block);
1676 1677 1678
	if (rc)
		goto out2;

1679 1680 1681 1682
	rc = rtnl_link_register(&geneve_link_ops);
	if (rc)
		goto out3;

1683
	return 0;
1684 1685
out3:
	unregister_netdevice_notifier(&geneve_notifier_block);
1686 1687 1688 1689 1690 1691 1692 1693 1694 1695
out2:
	unregister_pernet_subsys(&geneve_net_ops);
out1:
	return rc;
}
late_initcall(geneve_init_module);

static void __exit geneve_cleanup_module(void)
{
	rtnl_link_unregister(&geneve_link_ops);
1696
	unregister_netdevice_notifier(&geneve_notifier_block);
1697 1698 1699 1700 1701 1702 1703 1704 1705
	unregister_pernet_subsys(&geneve_net_ops);
}
module_exit(geneve_cleanup_module);

MODULE_LICENSE("GPL");
MODULE_VERSION(GENEVE_NETDEV_VER);
MODULE_AUTHOR("John W. Linville <linville@tuxdriver.com>");
MODULE_DESCRIPTION("Interface driver for GENEVE encapsulated traffic");
MODULE_ALIAS_RTNL_LINK("geneve");