提交 222440b4 编写于 作者: F Florian Westphal 提交者: Pablo Neira Ayuso

netfilter: nf_tables: handle meta/lookup with direct call

Currently nft uses inlined variants for common operations
such as 'ip saddr 1.2.3.4' instead of an indirect call.

Also handle meta get operations and lookups without indirect call,
both are builtin.
Signed-off-by: NFlorian Westphal <fw@strlen.de>
Signed-off-by: NPablo Neira Ayuso <pablo@netfilter.org>
上级 ecbcd689
...@@ -71,4 +71,11 @@ extern struct nft_set_type nft_set_hash_fast_type; ...@@ -71,4 +71,11 @@ extern struct nft_set_type nft_set_hash_fast_type;
extern struct nft_set_type nft_set_rbtree_type; extern struct nft_set_type nft_set_rbtree_type;
extern struct nft_set_type nft_set_bitmap_type; extern struct nft_set_type nft_set_bitmap_type;
struct nft_expr;
struct nft_regs;
struct nft_pktinfo;
void nft_meta_get_eval(const struct nft_expr *expr,
struct nft_regs *regs, const struct nft_pktinfo *pkt);
void nft_lookup_eval(const struct nft_expr *expr,
struct nft_regs *regs, const struct nft_pktinfo *pkt);
#endif /* _NET_NF_TABLES_CORE_H */ #endif /* _NET_NF_TABLES_CORE_H */
...@@ -120,6 +120,20 @@ struct nft_jumpstack { ...@@ -120,6 +120,20 @@ struct nft_jumpstack {
struct nft_rule *const *rules; struct nft_rule *const *rules;
}; };
static void expr_call_ops_eval(const struct nft_expr *expr,
struct nft_regs *regs,
struct nft_pktinfo *pkt)
{
unsigned long e = (unsigned long)expr->ops->eval;
if (e == (unsigned long)nft_meta_get_eval)
nft_meta_get_eval(expr, regs, pkt);
else if (e == (unsigned long)nft_lookup_eval)
nft_lookup_eval(expr, regs, pkt);
else
expr->ops->eval(expr, regs, pkt);
}
unsigned int unsigned int
nft_do_chain(struct nft_pktinfo *pkt, void *priv) nft_do_chain(struct nft_pktinfo *pkt, void *priv)
{ {
...@@ -153,7 +167,7 @@ nft_do_chain(struct nft_pktinfo *pkt, void *priv) ...@@ -153,7 +167,7 @@ nft_do_chain(struct nft_pktinfo *pkt, void *priv)
nft_cmp_fast_eval(expr, &regs); nft_cmp_fast_eval(expr, &regs);
else if (expr->ops != &nft_payload_fast_ops || else if (expr->ops != &nft_payload_fast_ops ||
!nft_payload_fast_eval(expr, &regs, pkt)) !nft_payload_fast_eval(expr, &regs, pkt))
expr->ops->eval(expr, &regs, pkt); expr_call_ops_eval(expr, &regs, pkt);
if (regs.verdict.code != NFT_CONTINUE) if (regs.verdict.code != NFT_CONTINUE)
break; break;
......
...@@ -26,7 +26,7 @@ struct nft_lookup { ...@@ -26,7 +26,7 @@ struct nft_lookup {
struct nft_set_binding binding; struct nft_set_binding binding;
}; };
static void nft_lookup_eval(const struct nft_expr *expr, void nft_lookup_eval(const struct nft_expr *expr,
struct nft_regs *regs, struct nft_regs *regs,
const struct nft_pktinfo *pkt) const struct nft_pktinfo *pkt)
{ {
......
...@@ -41,7 +41,7 @@ static DEFINE_PER_CPU(struct rnd_state, nft_prandom_state); ...@@ -41,7 +41,7 @@ static DEFINE_PER_CPU(struct rnd_state, nft_prandom_state);
#include "../bridge/br_private.h" #include "../bridge/br_private.h"
#endif #endif
static void nft_meta_get_eval(const struct nft_expr *expr, void nft_meta_get_eval(const struct nft_expr *expr,
struct nft_regs *regs, struct nft_regs *regs,
const struct nft_pktinfo *pkt) const struct nft_pktinfo *pkt)
{ {
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册