act_api.c 23.6 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
/*
 * net/sched/act_api.c	Packet action API.
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 *
 * Author:	Jamal Hadi Salim
 *
 *
 */

#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/string.h>
#include <linux/errno.h>
18
#include <linux/slab.h>
L
Linus Torvalds 已提交
19 20 21
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/kmod.h>
22
#include <linux/err.h>
23
#include <linux/module.h>
24 25
#include <net/net_namespace.h>
#include <net/sock.h>
L
Linus Torvalds 已提交
26 27
#include <net/sch_generic.h>
#include <net/act_api.h>
28
#include <net/netlink.h>
L
Linus Torvalds 已提交
29

30 31 32 33 34 35 36 37 38 39 40 41
void tcf_hash_destroy(struct tcf_common *p, struct tcf_hashinfo *hinfo)
{
	unsigned int h = tcf_hash(p->tcfc_index, hinfo->hmask);
	struct tcf_common **p1p;

	for (p1p = &hinfo->htab[h]; *p1p; p1p = &(*p1p)->tcfc_next) {
		if (*p1p == p) {
			write_lock_bh(hinfo->lock);
			*p1p = p->tcfc_next;
			write_unlock_bh(hinfo->lock);
			gen_kill_estimator(&p->tcfc_bstats,
					   &p->tcfc_rate_est);
42 43 44 45
			/*
			 * gen_estimator est_timer() might access p->tcfc_lock
			 * or bstats, wait a RCU grace period before freeing p
			 */
46
			kfree_rcu(p, tcfc_rcu);
47 48 49
			return;
		}
	}
50
	WARN_ON(1);
51 52 53 54 55 56 57 58 59 60 61 62 63
}
EXPORT_SYMBOL(tcf_hash_destroy);

int tcf_hash_release(struct tcf_common *p, int bind,
		     struct tcf_hashinfo *hinfo)
{
	int ret = 0;

	if (p) {
		if (bind)
			p->tcfc_bindcnt--;

		p->tcfc_refcnt--;
64
		if (p->tcfc_bindcnt <= 0 && p->tcfc_refcnt <= 0) {
65 66 67 68 69 70 71 72 73 74 75 76
			tcf_hash_destroy(p, hinfo);
			ret = 1;
		}
	}
	return ret;
}
EXPORT_SYMBOL(tcf_hash_release);

static int tcf_dump_walker(struct sk_buff *skb, struct netlink_callback *cb,
			   struct tc_action *a, struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p;
E
Eric Dumazet 已提交
77
	int err = 0, index = -1, i = 0, s_i = 0, n_i = 0;
78
	struct nlattr *nest;
79

80
	read_lock_bh(hinfo->lock);
81 82 83 84 85 86 87 88 89 90 91 92

	s_i = cb->args[0];

	for (i = 0; i < (hinfo->hmask + 1); i++) {
		p = hinfo->htab[tcf_hash(i, hinfo->hmask)];

		for (; p; p = p->tcfc_next) {
			index++;
			if (index < s_i)
				continue;
			a->priv = p;
			a->order = n_i;
93 94 95 96

			nest = nla_nest_start(skb, a->order);
			if (nest == NULL)
				goto nla_put_failure;
97 98 99
			err = tcf_action_dump_1(skb, a, 0, 0);
			if (err < 0) {
				index--;
100
				nlmsg_trim(skb, nest);
101 102
				goto done;
			}
103
			nla_nest_end(skb, nest);
104 105 106 107 108 109
			n_i++;
			if (n_i >= TCA_ACT_MAX_PRIO)
				goto done;
		}
	}
done:
110
	read_unlock_bh(hinfo->lock);
111 112 113 114
	if (n_i)
		cb->args[0] += n_i;
	return n_i;

115
nla_put_failure:
116
	nla_nest_cancel(skb, nest);
117 118 119 120 121 122 123
	goto done;
}

static int tcf_del_walker(struct sk_buff *skb, struct tc_action *a,
			  struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p, *s_p;
124
	struct nlattr *nest;
E
Eric Dumazet 已提交
125
	int i = 0, n_i = 0;
126

127 128 129
	nest = nla_nest_start(skb, a->order);
	if (nest == NULL)
		goto nla_put_failure;
130 131
	if (nla_put_string(skb, TCA_KIND, a->ops->kind))
		goto nla_put_failure;
132 133 134 135 136 137
	for (i = 0; i < (hinfo->hmask + 1); i++) {
		p = hinfo->htab[tcf_hash(i, hinfo->hmask)];

		while (p != NULL) {
			s_p = p->tcfc_next;
			if (ACT_P_DELETED == tcf_hash_release(p, 0, hinfo))
E
Eric Dumazet 已提交
138
				module_put(a->ops->owner);
139 140 141 142
			n_i++;
			p = s_p;
		}
	}
143 144
	if (nla_put_u32(skb, TCA_FCNT, n_i))
		goto nla_put_failure;
145
	nla_nest_end(skb, nest);
146 147

	return n_i;
148
nla_put_failure:
149
	nla_nest_cancel(skb, nest);
150 151 152 153 154 155 156 157 158 159 160 161 162
	return -EINVAL;
}

int tcf_generic_walker(struct sk_buff *skb, struct netlink_callback *cb,
		       int type, struct tc_action *a)
{
	struct tcf_hashinfo *hinfo = a->ops->hinfo;

	if (type == RTM_DELACTION) {
		return tcf_del_walker(skb, a, hinfo);
	} else if (type == RTM_GETACTION) {
		return tcf_dump_walker(skb, cb, a, hinfo);
	} else {
163
		WARN(1, "tcf_generic_walker: unknown action %d\n", type);
164 165 166 167 168 169 170 171 172
		return -EINVAL;
	}
}
EXPORT_SYMBOL(tcf_generic_walker);

struct tcf_common *tcf_hash_lookup(u32 index, struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p;

173
	read_lock_bh(hinfo->lock);
174 175 176 177 178
	for (p = hinfo->htab[tcf_hash(index, hinfo->hmask)]; p;
	     p = p->tcfc_next) {
		if (p->tcfc_index == index)
			break;
	}
179
	read_unlock_bh(hinfo->lock);
180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215

	return p;
}
EXPORT_SYMBOL(tcf_hash_lookup);

u32 tcf_hash_new_index(u32 *idx_gen, struct tcf_hashinfo *hinfo)
{
	u32 val = *idx_gen;

	do {
		if (++val == 0)
			val = 1;
	} while (tcf_hash_lookup(val, hinfo));

	return (*idx_gen = val);
}
EXPORT_SYMBOL(tcf_hash_new_index);

int tcf_hash_search(struct tc_action *a, u32 index)
{
	struct tcf_hashinfo *hinfo = a->ops->hinfo;
	struct tcf_common *p = tcf_hash_lookup(index, hinfo);

	if (p) {
		a->priv = p;
		return 1;
	}
	return 0;
}
EXPORT_SYMBOL(tcf_hash_search);

struct tcf_common *tcf_hash_check(u32 index, struct tc_action *a, int bind,
				  struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p = NULL;
	if (index && (p = tcf_hash_lookup(index, hinfo)) != NULL) {
216
		if (bind)
217
			p->tcfc_bindcnt++;
218
		p->tcfc_refcnt++;
219 220 221 222 223 224
		a->priv = p;
	}
	return p;
}
EXPORT_SYMBOL(tcf_hash_check);

225 226 227
struct tcf_common *tcf_hash_create(u32 index, struct nlattr *est,
				   struct tc_action *a, int size, int bind,
				   u32 *idx_gen, struct tcf_hashinfo *hinfo)
228 229 230 231
{
	struct tcf_common *p = kzalloc(size, GFP_KERNEL);

	if (unlikely(!p))
232
		return ERR_PTR(-ENOMEM);
233 234 235 236 237 238 239 240
	p->tcfc_refcnt = 1;
	if (bind)
		p->tcfc_bindcnt = 1;

	spin_lock_init(&p->tcfc_lock);
	p->tcfc_index = index ? index : tcf_hash_new_index(idx_gen, hinfo);
	p->tcfc_tm.install = jiffies;
	p->tcfc_tm.lastuse = jiffies;
241 242 243 244 245 246 247 248 249
	if (est) {
		int err = gen_new_estimator(&p->tcfc_bstats, &p->tcfc_rate_est,
					    &p->tcfc_lock, est);
		if (err) {
			kfree(p);
			return ERR_PTR(err);
		}
	}

250 251 252 253 254 255 256 257 258 259 260 261 262 263 264
	a->priv = (void *) p;
	return p;
}
EXPORT_SYMBOL(tcf_hash_create);

void tcf_hash_insert(struct tcf_common *p, struct tcf_hashinfo *hinfo)
{
	unsigned int h = tcf_hash(p->tcfc_index, hinfo->hmask);

	write_lock_bh(hinfo->lock);
	p->tcfc_next = hinfo->htab[h];
	hinfo->htab[h] = p;
	write_unlock_bh(hinfo->lock);
}
EXPORT_SYMBOL(tcf_hash_insert);
L
Linus Torvalds 已提交
265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284

static struct tc_action_ops *act_base = NULL;
static DEFINE_RWLOCK(act_mod_lock);

int tcf_register_action(struct tc_action_ops *act)
{
	struct tc_action_ops *a, **ap;

	write_lock(&act_mod_lock);
	for (ap = &act_base; (a = *ap) != NULL; ap = &a->next) {
		if (act->type == a->type || (strcmp(act->kind, a->kind) == 0)) {
			write_unlock(&act_mod_lock);
			return -EEXIST;
		}
	}
	act->next = NULL;
	*ap = act;
	write_unlock(&act_mod_lock);
	return 0;
}
285
EXPORT_SYMBOL(tcf_register_action);
L
Linus Torvalds 已提交
286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303

int tcf_unregister_action(struct tc_action_ops *act)
{
	struct tc_action_ops *a, **ap;
	int err = -ENOENT;

	write_lock(&act_mod_lock);
	for (ap = &act_base; (a = *ap) != NULL; ap = &a->next)
		if (a == act)
			break;
	if (a) {
		*ap = a->next;
		a->next = NULL;
		err = 0;
	}
	write_unlock(&act_mod_lock);
	return err;
}
304
EXPORT_SYMBOL(tcf_unregister_action);
L
Linus Torvalds 已提交
305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326

/* lookup by name */
static struct tc_action_ops *tc_lookup_action_n(char *kind)
{
	struct tc_action_ops *a = NULL;

	if (kind) {
		read_lock(&act_mod_lock);
		for (a = act_base; a; a = a->next) {
			if (strcmp(kind, a->kind) == 0) {
				if (!try_module_get(a->owner)) {
					read_unlock(&act_mod_lock);
					return NULL;
				}
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
	return a;
}

327 328
/* lookup by nlattr */
static struct tc_action_ops *tc_lookup_action(struct nlattr *kind)
L
Linus Torvalds 已提交
329 330 331 332 333 334
{
	struct tc_action_ops *a = NULL;

	if (kind) {
		read_lock(&act_mod_lock);
		for (a = act_base; a; a = a->next) {
335
			if (nla_strcmp(kind, a->kind) == 0) {
L
Linus Torvalds 已提交
336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370
				if (!try_module_get(a->owner)) {
					read_unlock(&act_mod_lock);
					return NULL;
				}
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
	return a;
}

#if 0
/* lookup by id */
static struct tc_action_ops *tc_lookup_action_id(u32 type)
{
	struct tc_action_ops *a = NULL;

	if (type) {
		read_lock(&act_mod_lock);
		for (a = act_base; a; a = a->next) {
			if (a->type == type) {
				if (!try_module_get(a->owner)) {
					read_unlock(&act_mod_lock);
					return NULL;
				}
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
	return a;
}
#endif

371
int tcf_action_exec(struct sk_buff *skb, const struct tc_action *act,
372
		    struct tcf_result *res)
L
Linus Torvalds 已提交
373
{
374
	const struct tc_action *a;
L
Linus Torvalds 已提交
375 376 377 378 379 380 381 382 383 384
	int ret = -1;

	if (skb->tc_verd & TC_NCLS) {
		skb->tc_verd = CLR_TC_NCLS(skb->tc_verd);
		ret = TC_ACT_OK;
		goto exec_done;
	}
	while ((a = act) != NULL) {
repeat:
		if (a->ops && a->ops->act) {
385
			ret = a->ops->act(skb, a, res);
L
Linus Torvalds 已提交
386 387 388 389 390 391 392
			if (TC_MUNGED & skb->tc_verd) {
				/* copied already, allow trampling */
				skb->tc_verd = SET_TC_OK2MUNGE(skb->tc_verd);
				skb->tc_verd = CLR_TC_MUNGED(skb->tc_verd);
			}
			if (ret == TC_ACT_REPEAT)
				goto repeat;	/* we need a ttl - JHS */
J
J Hadi Salim 已提交
393 394
			if (ret != TC_ACT_PIPE)
				goto exec_done;
L
Linus Torvalds 已提交
395 396 397 398 399 400
		}
		act = a->next;
	}
exec_done:
	return ret;
}
401
EXPORT_SYMBOL(tcf_action_exec);
L
Linus Torvalds 已提交
402 403 404 405 406 407 408 409 410 411 412

void tcf_action_destroy(struct tc_action *act, int bind)
{
	struct tc_action *a;

	for (a = act; a; a = act) {
		if (a->ops && a->ops->cleanup) {
			if (a->ops->cleanup(a, bind) == ACT_P_DELETED)
				module_put(a->ops->owner);
			act = act->next;
			kfree(a);
413 414 415
		} else {
			/*FIXME: Remove later - catch insertion bugs*/
			WARN(1, "tcf_action_destroy: BUG? destroying NULL ops\n");
L
Linus Torvalds 已提交
416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435
			act = act->next;
			kfree(a);
		}
	}
}

int
tcf_action_dump_old(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{
	int err = -EINVAL;

	if (a->ops == NULL || a->ops->dump == NULL)
		return err;
	return a->ops->dump(skb, a, bind, ref);
}

int
tcf_action_dump_1(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{
	int err = -EINVAL;
436
	unsigned char *b = skb_tail_pointer(skb);
437
	struct nlattr *nest;
L
Linus Torvalds 已提交
438 439 440 441

	if (a->ops == NULL || a->ops->dump == NULL)
		return err;

442 443
	if (nla_put_string(skb, TCA_KIND, a->ops->kind))
		goto nla_put_failure;
L
Linus Torvalds 已提交
444
	if (tcf_action_copy_stats(skb, a, 0))
445
		goto nla_put_failure;
446 447 448
	nest = nla_nest_start(skb, TCA_OPTIONS);
	if (nest == NULL)
		goto nla_put_failure;
E
Eric Dumazet 已提交
449 450
	err = tcf_action_dump_old(skb, a, bind, ref);
	if (err > 0) {
451
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
452 453 454
		return err;
	}

455
nla_put_failure:
456
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
457 458
	return -1;
}
459
EXPORT_SYMBOL(tcf_action_dump_1);
L
Linus Torvalds 已提交
460 461 462 463 464 465

int
tcf_action_dump(struct sk_buff *skb, struct tc_action *act, int bind, int ref)
{
	struct tc_action *a;
	int err = -EINVAL;
466
	struct nlattr *nest;
L
Linus Torvalds 已提交
467 468 469

	while ((a = act) != NULL) {
		act = a->next;
470 471 472
		nest = nla_nest_start(skb, a->order);
		if (nest == NULL)
			goto nla_put_failure;
L
Linus Torvalds 已提交
473 474
		err = tcf_action_dump_1(skb, a, bind, ref);
		if (err < 0)
475
			goto errout;
476
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
477 478 479 480
	}

	return 0;

481
nla_put_failure:
482 483
	err = -EINVAL;
errout:
484
	nla_nest_cancel(skb, nest);
485
	return err;
L
Linus Torvalds 已提交
486 487
}

488
struct tc_action *tcf_action_init_1(struct nlattr *nla, struct nlattr *est,
489
				    char *name, int ovr, int bind)
L
Linus Torvalds 已提交
490 491 492 493
{
	struct tc_action *a;
	struct tc_action_ops *a_o;
	char act_name[IFNAMSIZ];
E
Eric Dumazet 已提交
494
	struct nlattr *tb[TCA_ACT_MAX + 1];
495
	struct nlattr *kind;
496
	int err;
L
Linus Torvalds 已提交
497 498

	if (name == NULL) {
499 500
		err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL);
		if (err < 0)
L
Linus Torvalds 已提交
501
			goto err_out;
502
		err = -EINVAL;
503
		kind = tb[TCA_ACT_KIND];
L
Linus Torvalds 已提交
504 505
		if (kind == NULL)
			goto err_out;
506
		if (nla_strlcpy(act_name, kind, IFNAMSIZ) >= IFNAMSIZ)
L
Linus Torvalds 已提交
507 508
			goto err_out;
	} else {
509
		err = -EINVAL;
L
Linus Torvalds 已提交
510 511 512 513 514 515
		if (strlcpy(act_name, name, IFNAMSIZ) >= IFNAMSIZ)
			goto err_out;
	}

	a_o = tc_lookup_action_n(act_name);
	if (a_o == NULL) {
516
#ifdef CONFIG_MODULES
L
Linus Torvalds 已提交
517
		rtnl_unlock();
518
		request_module("act_%s", act_name);
L
Linus Torvalds 已提交
519 520 521 522 523 524 525 526 527 528 529
		rtnl_lock();

		a_o = tc_lookup_action_n(act_name);

		/* We dropped the RTNL semaphore in order to
		 * perform the module load.  So, even if we
		 * succeeded in loading the module we have to
		 * tell the caller to replay the request.  We
		 * indicate this using -EAGAIN.
		 */
		if (a_o != NULL) {
530
			err = -EAGAIN;
L
Linus Torvalds 已提交
531 532 533
			goto err_mod;
		}
#endif
534
		err = -ENOENT;
L
Linus Torvalds 已提交
535 536 537
		goto err_out;
	}

538
	err = -ENOMEM;
539
	a = kzalloc(sizeof(*a), GFP_KERNEL);
L
Linus Torvalds 已提交
540 541 542 543 544
	if (a == NULL)
		goto err_mod;

	/* backward compatibility for policer */
	if (name == NULL)
545
		err = a_o->init(tb[TCA_ACT_OPTIONS], est, a, ovr, bind);
L
Linus Torvalds 已提交
546
	else
547 548
		err = a_o->init(nla, est, a, ovr, bind);
	if (err < 0)
L
Linus Torvalds 已提交
549 550 551
		goto err_free;

	/* module count goes up only when brand new policy is created
E
Eric Dumazet 已提交
552 553 554
	 * if it exists and is only bound to in a_o->init() then
	 * ACT_P_CREATED is not returned (a zero is).
	 */
555
	if (err != ACT_P_CREATED)
L
Linus Torvalds 已提交
556 557 558 559 560 561 562 563 564 565
		module_put(a_o->owner);
	a->ops = a_o;

	return a;

err_free:
	kfree(a);
err_mod:
	module_put(a_o->owner);
err_out:
566
	return ERR_PTR(err);
L
Linus Torvalds 已提交
567 568
}

569
struct tc_action *tcf_action_init(struct nlattr *nla, struct nlattr *est,
570
				  char *name, int ovr, int bind)
L
Linus Torvalds 已提交
571
{
E
Eric Dumazet 已提交
572
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
L
Linus Torvalds 已提交
573
	struct tc_action *head = NULL, *act, *act_prev = NULL;
574
	int err;
L
Linus Torvalds 已提交
575 576
	int i;

577 578 579
	err = nla_parse_nested(tb, TCA_ACT_MAX_PRIO, nla, NULL);
	if (err < 0)
		return ERR_PTR(err);
L
Linus Torvalds 已提交
580

581
	for (i = 1; i <= TCA_ACT_MAX_PRIO && tb[i]; i++) {
582 583
		act = tcf_action_init_1(tb[i], est, name, ovr, bind);
		if (IS_ERR(act))
L
Linus Torvalds 已提交
584
			goto err;
585
		act->order = i;
L
Linus Torvalds 已提交
586 587 588 589 590 591 592 593 594 595 596 597

		if (head == NULL)
			head = act;
		else
			act_prev->next = act;
		act_prev = act;
	}
	return head;

err:
	if (head != NULL)
		tcf_action_destroy(head, bind);
598
	return act;
L
Linus Torvalds 已提交
599 600 601 602 603 604 605 606
}

int tcf_action_copy_stats(struct sk_buff *skb, struct tc_action *a,
			  int compat_mode)
{
	int err = 0;
	struct gnet_dump d;
	struct tcf_act_hdr *h = a->priv;
607

L
Linus Torvalds 已提交
608 609 610 611
	if (h == NULL)
		goto errout;

	/* compat_mode being true specifies a call that is supposed
612
	 * to add additional backward compatibility statistic TLVs.
L
Linus Torvalds 已提交
613 614 615 616
	 */
	if (compat_mode) {
		if (a->type == TCA_OLD_COMPAT)
			err = gnet_stats_start_copy_compat(skb, 0,
617
				TCA_STATS, TCA_XSTATS, &h->tcf_lock, &d);
L
Linus Torvalds 已提交
618 619 620 621
		else
			return 0;
	} else
		err = gnet_stats_start_copy(skb, TCA_ACT_STATS,
622
					    &h->tcf_lock, &d);
L
Linus Torvalds 已提交
623 624 625 626 627 628 629 630

	if (err < 0)
		goto errout;

	if (a->ops != NULL && a->ops->get_stats != NULL)
		if (a->ops->get_stats(skb, a) < 0)
			goto errout;

631
	if (gnet_stats_copy_basic(&d, &h->tcf_bstats) < 0 ||
632 633
	    gnet_stats_copy_rate_est(&d, &h->tcf_bstats,
				     &h->tcf_rate_est) < 0 ||
634
	    gnet_stats_copy_queue(&d, &h->tcf_qstats) < 0)
L
Linus Torvalds 已提交
635 636 637 638 639 640 641 642 643 644 645 646 647
		goto errout;

	if (gnet_stats_finish_copy(&d) < 0)
		goto errout;

	return 0;

errout:
	return -1;
}

static int
tca_get_fill(struct sk_buff *skb, struct tc_action *a, u32 pid, u32 seq,
648
	     u16 flags, int event, int bind, int ref)
L
Linus Torvalds 已提交
649 650 651
{
	struct tcamsg *t;
	struct nlmsghdr *nlh;
652
	unsigned char *b = skb_tail_pointer(skb);
653
	struct nlattr *nest;
L
Linus Torvalds 已提交
654

J
Jamal Hadi Salim 已提交
655 656
	nlh = NLMSG_NEW(skb, pid, seq, event, sizeof(*t), flags);

L
Linus Torvalds 已提交
657 658
	t = NLMSG_DATA(nlh);
	t->tca_family = AF_UNSPEC;
659 660
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
661

662 663 664
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
		goto nla_put_failure;
L
Linus Torvalds 已提交
665 666

	if (tcf_action_dump(skb, a, bind, ref) < 0)
667
		goto nla_put_failure;
L
Linus Torvalds 已提交
668

669
	nla_nest_end(skb, nest);
670

671
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
672 673
	return skb->len;

674
nla_put_failure:
L
Linus Torvalds 已提交
675
nlmsg_failure:
676
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
677 678 679 680
	return -1;
}

static int
681 682
act_get_notify(struct net *net, u32 pid, struct nlmsghdr *n,
	       struct tc_action *a, int event)
L
Linus Torvalds 已提交
683 684 685 686 687 688 689 690 691 692
{
	struct sk_buff *skb;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;
	if (tca_get_fill(skb, a, pid, n->nlmsg_seq, 0, event, 0, 0) <= 0) {
		kfree_skb(skb);
		return -EINVAL;
	}
693

694
	return rtnl_unicast(skb, net, pid);
L
Linus Torvalds 已提交
695 696 697
}

static struct tc_action *
698
tcf_action_get_1(struct nlattr *nla, struct nlmsghdr *n, u32 pid)
L
Linus Torvalds 已提交
699
{
E
Eric Dumazet 已提交
700
	struct nlattr *tb[TCA_ACT_MAX + 1];
L
Linus Torvalds 已提交
701 702
	struct tc_action *a;
	int index;
703
	int err;
L
Linus Torvalds 已提交
704

705 706
	err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL);
	if (err < 0)
707
		goto err_out;
L
Linus Torvalds 已提交
708

709
	err = -EINVAL;
710 711
	if (tb[TCA_ACT_INDEX] == NULL ||
	    nla_len(tb[TCA_ACT_INDEX]) < sizeof(index))
712
		goto err_out;
713
	index = nla_get_u32(tb[TCA_ACT_INDEX]);
L
Linus Torvalds 已提交
714

715
	err = -ENOMEM;
716
	a = kzalloc(sizeof(struct tc_action), GFP_KERNEL);
L
Linus Torvalds 已提交
717
	if (a == NULL)
718
		goto err_out;
L
Linus Torvalds 已提交
719

720
	err = -EINVAL;
721
	a->ops = tc_lookup_action(tb[TCA_ACT_KIND]);
L
Linus Torvalds 已提交
722 723 724 725
	if (a->ops == NULL)
		goto err_free;
	if (a->ops->lookup == NULL)
		goto err_mod;
726
	err = -ENOENT;
L
Linus Torvalds 已提交
727 728 729 730 731
	if (a->ops->lookup(a, index) == 0)
		goto err_mod;

	module_put(a->ops->owner);
	return a;
732

L
Linus Torvalds 已提交
733 734 735 736
err_mod:
	module_put(a->ops->owner);
err_free:
	kfree(a);
737 738
err_out:
	return ERR_PTR(err);
L
Linus Torvalds 已提交
739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754
}

static void cleanup_a(struct tc_action *act)
{
	struct tc_action *a;

	for (a = act; a; a = act) {
		act = a->next;
		kfree(a);
	}
}

static struct tc_action *create_a(int i)
{
	struct tc_action *act;

755
	act = kzalloc(sizeof(*act), GFP_KERNEL);
L
Linus Torvalds 已提交
756
	if (act == NULL) {
757
		pr_debug("create_a: failed to alloc!\n");
L
Linus Torvalds 已提交
758 759 760 761 762 763
		return NULL;
	}
	act->order = i;
	return act;
}

764 765
static int tca_action_flush(struct net *net, struct nlattr *nla,
			    struct nlmsghdr *n, u32 pid)
L
Linus Torvalds 已提交
766 767 768 769 770 771
{
	struct sk_buff *skb;
	unsigned char *b;
	struct nlmsghdr *nlh;
	struct tcamsg *t;
	struct netlink_callback dcb;
772
	struct nlattr *nest;
E
Eric Dumazet 已提交
773
	struct nlattr *tb[TCA_ACT_MAX + 1];
774
	struct nlattr *kind;
L
Linus Torvalds 已提交
775
	struct tc_action *a = create_a(0);
776
	int err = -ENOMEM;
L
Linus Torvalds 已提交
777 778

	if (a == NULL) {
779
		pr_debug("tca_action_flush: couldnt create tc_action\n");
L
Linus Torvalds 已提交
780 781 782 783 784
		return err;
	}

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb) {
785
		pr_debug("tca_action_flush: failed skb alloc\n");
L
Linus Torvalds 已提交
786
		kfree(a);
787
		return err;
L
Linus Torvalds 已提交
788 789
	}

790
	b = skb_tail_pointer(skb);
L
Linus Torvalds 已提交
791

792 793
	err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL);
	if (err < 0)
L
Linus Torvalds 已提交
794 795
		goto err_out;

796
	err = -EINVAL;
797
	kind = tb[TCA_ACT_KIND];
L
Linus Torvalds 已提交
798 799 800 801 802 803 804
	a->ops = tc_lookup_action(kind);
	if (a->ops == NULL)
		goto err_out;

	nlh = NLMSG_PUT(skb, pid, n->nlmsg_seq, RTM_DELACTION, sizeof(*t));
	t = NLMSG_DATA(nlh);
	t->tca_family = AF_UNSPEC;
805 806
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
L
Linus Torvalds 已提交
807

808 809 810
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
		goto nla_put_failure;
L
Linus Torvalds 已提交
811 812 813

	err = a->ops->walk(skb, &dcb, RTM_DELACTION, a);
	if (err < 0)
814
		goto nla_put_failure;
815 816
	if (err == 0)
		goto noflush_out;
L
Linus Torvalds 已提交
817

818
	nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
819

820
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
821 822 823
	nlh->nlmsg_flags |= NLM_F_ROOT;
	module_put(a->ops->owner);
	kfree(a);
E
Eric Dumazet 已提交
824 825
	err = rtnetlink_send(skb, net, pid, RTNLGRP_TC,
			     n->nlmsg_flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
826 827 828 829 830
	if (err > 0)
		return 0;

	return err;

831
nla_put_failure:
L
Linus Torvalds 已提交
832
nlmsg_failure:
833
	module_put(a->ops->owner);
L
Linus Torvalds 已提交
834
err_out:
835
noflush_out:
L
Linus Torvalds 已提交
836 837 838 839 840 841
	kfree_skb(skb);
	kfree(a);
	return err;
}

static int
842 843
tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
	      u32 pid, int event)
L
Linus Torvalds 已提交
844
{
845
	int i, ret;
E
Eric Dumazet 已提交
846
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
L
Linus Torvalds 已提交
847 848
	struct tc_action *head = NULL, *act, *act_prev = NULL;

849 850 851
	ret = nla_parse_nested(tb, TCA_ACT_MAX_PRIO, nla, NULL);
	if (ret < 0)
		return ret;
L
Linus Torvalds 已提交
852

E
Eric Dumazet 已提交
853
	if (event == RTM_DELACTION && n->nlmsg_flags & NLM_F_ROOT) {
854
		if (tb[1] != NULL)
855
			return tca_action_flush(net, tb[1], n, pid);
856 857
		else
			return -EINVAL;
L
Linus Torvalds 已提交
858 859
	}

860
	for (i = 1; i <= TCA_ACT_MAX_PRIO && tb[i]; i++) {
861 862 863
		act = tcf_action_get_1(tb[i], n, pid);
		if (IS_ERR(act)) {
			ret = PTR_ERR(act);
L
Linus Torvalds 已提交
864
			goto err;
865
		}
866
		act->order = i;
L
Linus Torvalds 已提交
867 868 869 870 871 872 873 874 875

		if (head == NULL)
			head = act;
		else
			act_prev->next = act;
		act_prev = act;
	}

	if (event == RTM_GETACTION)
876
		ret = act_get_notify(net, pid, n, head, event);
L
Linus Torvalds 已提交
877 878 879 880 881 882 883 884 885 886
	else { /* delete */
		struct sk_buff *skb;

		skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
		if (!skb) {
			ret = -ENOBUFS;
			goto err;
		}

		if (tca_get_fill(skb, head, pid, n->nlmsg_seq, 0, event,
887
				 0, 1) <= 0) {
L
Linus Torvalds 已提交
888 889 890 891 892 893 894
			kfree_skb(skb);
			ret = -EINVAL;
			goto err;
		}

		/* now do the delete */
		tcf_action_destroy(head, 0);
895
		ret = rtnetlink_send(skb, net, pid, RTNLGRP_TC,
E
Eric Dumazet 已提交
896
				     n->nlmsg_flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
897 898 899 900 901 902 903 904 905
		if (ret > 0)
			return 0;
		return ret;
	}
err:
	cleanup_a(head);
	return ret;
}

906 907
static int tcf_add_notify(struct net *net, struct tc_action *a,
			  u32 pid, u32 seq, int event, u16 flags)
L
Linus Torvalds 已提交
908 909 910 911
{
	struct tcamsg *t;
	struct nlmsghdr *nlh;
	struct sk_buff *skb;
912
	struct nlattr *nest;
L
Linus Torvalds 已提交
913 914 915 916 917 918 919
	unsigned char *b;
	int err = 0;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;

920
	b = skb_tail_pointer(skb);
L
Linus Torvalds 已提交
921

J
Jamal Hadi Salim 已提交
922
	nlh = NLMSG_NEW(skb, pid, seq, event, sizeof(*t), flags);
L
Linus Torvalds 已提交
923 924
	t = NLMSG_DATA(nlh);
	t->tca_family = AF_UNSPEC;
925 926 927
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;

928 929 930
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
		goto nla_put_failure;
L
Linus Torvalds 已提交
931 932

	if (tcf_action_dump(skb, a, 0, 0) < 0)
933
		goto nla_put_failure;
L
Linus Torvalds 已提交
934

935
	nla_nest_end(skb, nest);
936

937
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
938
	NETLINK_CB(skb).dst_group = RTNLGRP_TC;
939

E
Eric Dumazet 已提交
940
	err = rtnetlink_send(skb, net, pid, RTNLGRP_TC, flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
941 942 943 944
	if (err > 0)
		err = 0;
	return err;

945
nla_put_failure:
L
Linus Torvalds 已提交
946
nlmsg_failure:
947
	kfree_skb(skb);
L
Linus Torvalds 已提交
948 949 950
	return -1;
}

951

L
Linus Torvalds 已提交
952
static int
953 954
tcf_action_add(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
	       u32 pid, int ovr)
L
Linus Torvalds 已提交
955 956 957 958 959 960
{
	int ret = 0;
	struct tc_action *act;
	struct tc_action *a;
	u32 seq = n->nlmsg_seq;

961
	act = tcf_action_init(nla, NULL, NULL, ovr, 0);
L
Linus Torvalds 已提交
962 963
	if (act == NULL)
		goto done;
964 965 966 967
	if (IS_ERR(act)) {
		ret = PTR_ERR(act);
		goto done;
	}
L
Linus Torvalds 已提交
968 969 970

	/* dump then free all the actions after update; inserted policy
	 * stays intact
E
Eric Dumazet 已提交
971
	 */
972
	ret = tcf_add_notify(net, act, pid, seq, RTM_NEWACTION, n->nlmsg_flags);
L
Linus Torvalds 已提交
973 974 975 976 977 978 979 980 981 982
	for (a = act; a; a = act) {
		act = a->next;
		kfree(a);
	}
done:
	return ret;
}

static int tc_ctl_action(struct sk_buff *skb, struct nlmsghdr *n, void *arg)
{
983
	struct net *net = sock_net(skb->sk);
984
	struct nlattr *tca[TCA_ACT_MAX + 1];
L
Linus Torvalds 已提交
985 986 987
	u32 pid = skb ? NETLINK_CB(skb).pid : 0;
	int ret = 0, ovr = 0;

988 989 990 991 992
	ret = nlmsg_parse(n, sizeof(struct tcamsg), tca, TCA_ACT_MAX, NULL);
	if (ret < 0)
		return ret;

	if (tca[TCA_ACT_TAB] == NULL) {
993
		pr_notice("tc_ctl_action: received NO action attribs\n");
L
Linus Torvalds 已提交
994 995 996
		return -EINVAL;
	}

E
Eric Dumazet 已提交
997
	/* n->nlmsg_flags & NLM_F_CREATE */
L
Linus Torvalds 已提交
998 999 1000
	switch (n->nlmsg_type) {
	case RTM_NEWACTION:
		/* we are going to assume all other flags
L
Lucas De Marchi 已提交
1001
		 * imply create only if it doesn't exist
L
Linus Torvalds 已提交
1002 1003 1004 1005
		 * Note that CREATE | EXCL implies that
		 * but since we want avoid ambiguity (eg when flags
		 * is zero) then just set this
		 */
E
Eric Dumazet 已提交
1006
		if (n->nlmsg_flags & NLM_F_REPLACE)
L
Linus Torvalds 已提交
1007 1008
			ovr = 1;
replay:
1009
		ret = tcf_action_add(net, tca[TCA_ACT_TAB], n, pid, ovr);
L
Linus Torvalds 已提交
1010 1011 1012 1013
		if (ret == -EAGAIN)
			goto replay;
		break;
	case RTM_DELACTION:
1014 1015
		ret = tca_action_gd(net, tca[TCA_ACT_TAB], n,
				    pid, RTM_DELACTION);
L
Linus Torvalds 已提交
1016 1017
		break;
	case RTM_GETACTION:
1018 1019
		ret = tca_action_gd(net, tca[TCA_ACT_TAB], n,
				    pid, RTM_GETACTION);
L
Linus Torvalds 已提交
1020 1021 1022 1023 1024 1025 1026 1027
		break;
	default:
		BUG();
	}

	return ret;
}

1028
static struct nlattr *
1029
find_dump_kind(const struct nlmsghdr *n)
L
Linus Torvalds 已提交
1030
{
E
Eric Dumazet 已提交
1031
	struct nlattr *tb1, *tb2[TCA_ACT_MAX + 1];
1032 1033 1034
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
	struct nlattr *nla[TCAA_MAX + 1];
	struct nlattr *kind;
L
Linus Torvalds 已提交
1035

1036
	if (nlmsg_parse(n, sizeof(struct tcamsg), nla, TCAA_MAX, NULL) < 0)
L
Linus Torvalds 已提交
1037
		return NULL;
1038
	tb1 = nla[TCA_ACT_TAB];
L
Linus Torvalds 已提交
1039 1040 1041
	if (tb1 == NULL)
		return NULL;

1042 1043
	if (nla_parse(tb, TCA_ACT_MAX_PRIO, nla_data(tb1),
		      NLMSG_ALIGN(nla_len(tb1)), NULL) < 0)
L
Linus Torvalds 已提交
1044 1045
		return NULL;

1046 1047 1048 1049
	if (tb[1] == NULL)
		return NULL;
	if (nla_parse(tb2, TCA_ACT_MAX, nla_data(tb[1]),
		      nla_len(tb[1]), NULL) < 0)
L
Linus Torvalds 已提交
1050
		return NULL;
1051
	kind = tb2[TCA_ACT_KIND];
L
Linus Torvalds 已提交
1052

1053
	return kind;
L
Linus Torvalds 已提交
1054 1055 1056 1057 1058 1059
}

static int
tc_dump_action(struct sk_buff *skb, struct netlink_callback *cb)
{
	struct nlmsghdr *nlh;
1060
	unsigned char *b = skb_tail_pointer(skb);
1061
	struct nlattr *nest;
L
Linus Torvalds 已提交
1062 1063 1064 1065
	struct tc_action_ops *a_o;
	struct tc_action a;
	int ret = 0;
	struct tcamsg *t = (struct tcamsg *) NLMSG_DATA(cb->nlh);
1066
	struct nlattr *kind = find_dump_kind(cb->nlh);
L
Linus Torvalds 已提交
1067 1068

	if (kind == NULL) {
1069
		pr_info("tc_dump_action: action bad kind\n");
L
Linus Torvalds 已提交
1070 1071 1072
		return 0;
	}

1073
	a_o = tc_lookup_action(kind);
E
Eric Dumazet 已提交
1074
	if (a_o == NULL)
L
Linus Torvalds 已提交
1075 1076 1077 1078 1079 1080
		return 0;

	memset(&a, 0, sizeof(struct tc_action));
	a.ops = a_o;

	if (a_o->walk == NULL) {
1081 1082
		WARN(1, "tc_dump_action: %s !capable of dumping table\n",
		     a_o->kind);
1083
		goto nla_put_failure;
L
Linus Torvalds 已提交
1084 1085 1086
	}

	nlh = NLMSG_PUT(skb, NETLINK_CB(cb->skb).pid, cb->nlh->nlmsg_seq,
1087
			cb->nlh->nlmsg_type, sizeof(*t));
L
Linus Torvalds 已提交
1088 1089
	t = NLMSG_DATA(nlh);
	t->tca_family = AF_UNSPEC;
1090 1091
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
L
Linus Torvalds 已提交
1092

1093 1094 1095
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
		goto nla_put_failure;
L
Linus Torvalds 已提交
1096 1097 1098

	ret = a_o->walk(skb, cb, RTM_GETACTION, &a);
	if (ret < 0)
1099
		goto nla_put_failure;
L
Linus Torvalds 已提交
1100 1101

	if (ret > 0) {
1102
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
1103 1104
		ret = skb->len;
	} else
1105
		nla_nest_cancel(skb, nest);
L
Linus Torvalds 已提交
1106

1107
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
1108 1109 1110 1111 1112
	if (NETLINK_CB(cb->skb).pid && ret)
		nlh->nlmsg_flags |= NLM_F_MULTI;
	module_put(a_o->owner);
	return skb->len;

1113
nla_put_failure:
L
Linus Torvalds 已提交
1114 1115
nlmsg_failure:
	module_put(a_o->owner);
1116
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
1117 1118 1119 1120 1121
	return skb->len;
}

static int __init tc_action_init(void)
{
1122 1123 1124 1125
	rtnl_register(PF_UNSPEC, RTM_NEWACTION, tc_ctl_action, NULL, NULL);
	rtnl_register(PF_UNSPEC, RTM_DELACTION, tc_ctl_action, NULL, NULL);
	rtnl_register(PF_UNSPEC, RTM_GETACTION, tc_ctl_action, tc_dump_action,
		      NULL);
L
Linus Torvalds 已提交
1126 1127 1128 1129 1130

	return 0;
}

subsys_initcall(tc_action_init);