act_api.c 23.6 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
/*
 * net/sched/act_api.c	Packet action API.
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 *
 * Author:	Jamal Hadi Salim
 *
 *
 */

#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/string.h>
#include <linux/errno.h>
18
#include <linux/slab.h>
L
Linus Torvalds 已提交
19 20 21
#include <linux/skbuff.h>
#include <linux/init.h>
#include <linux/kmod.h>
22
#include <linux/err.h>
23
#include <linux/module.h>
24 25
#include <net/net_namespace.h>
#include <net/sock.h>
L
Linus Torvalds 已提交
26 27
#include <net/sch_generic.h>
#include <net/act_api.h>
28
#include <net/netlink.h>
L
Linus Torvalds 已提交
29

30 31 32 33 34 35 36 37 38 39 40 41
void tcf_hash_destroy(struct tcf_common *p, struct tcf_hashinfo *hinfo)
{
	unsigned int h = tcf_hash(p->tcfc_index, hinfo->hmask);
	struct tcf_common **p1p;

	for (p1p = &hinfo->htab[h]; *p1p; p1p = &(*p1p)->tcfc_next) {
		if (*p1p == p) {
			write_lock_bh(hinfo->lock);
			*p1p = p->tcfc_next;
			write_unlock_bh(hinfo->lock);
			gen_kill_estimator(&p->tcfc_bstats,
					   &p->tcfc_rate_est);
42 43 44 45
			/*
			 * gen_estimator est_timer() might access p->tcfc_lock
			 * or bstats, wait a RCU grace period before freeing p
			 */
46
			kfree_rcu(p, tcfc_rcu);
47 48 49
			return;
		}
	}
50
	WARN_ON(1);
51 52 53 54 55 56 57 58 59 60 61 62 63
}
EXPORT_SYMBOL(tcf_hash_destroy);

int tcf_hash_release(struct tcf_common *p, int bind,
		     struct tcf_hashinfo *hinfo)
{
	int ret = 0;

	if (p) {
		if (bind)
			p->tcfc_bindcnt--;

		p->tcfc_refcnt--;
64
		if (p->tcfc_bindcnt <= 0 && p->tcfc_refcnt <= 0) {
65 66 67 68 69 70 71 72 73 74 75 76
			tcf_hash_destroy(p, hinfo);
			ret = 1;
		}
	}
	return ret;
}
EXPORT_SYMBOL(tcf_hash_release);

static int tcf_dump_walker(struct sk_buff *skb, struct netlink_callback *cb,
			   struct tc_action *a, struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p;
E
Eric Dumazet 已提交
77
	int err = 0, index = -1, i = 0, s_i = 0, n_i = 0;
78
	struct nlattr *nest;
79

80
	read_lock_bh(hinfo->lock);
81 82 83 84 85 86 87 88 89 90 91 92

	s_i = cb->args[0];

	for (i = 0; i < (hinfo->hmask + 1); i++) {
		p = hinfo->htab[tcf_hash(i, hinfo->hmask)];

		for (; p; p = p->tcfc_next) {
			index++;
			if (index < s_i)
				continue;
			a->priv = p;
			a->order = n_i;
93 94 95 96

			nest = nla_nest_start(skb, a->order);
			if (nest == NULL)
				goto nla_put_failure;
97 98 99
			err = tcf_action_dump_1(skb, a, 0, 0);
			if (err < 0) {
				index--;
100
				nlmsg_trim(skb, nest);
101 102
				goto done;
			}
103
			nla_nest_end(skb, nest);
104 105 106 107 108 109
			n_i++;
			if (n_i >= TCA_ACT_MAX_PRIO)
				goto done;
		}
	}
done:
110
	read_unlock_bh(hinfo->lock);
111 112 113 114
	if (n_i)
		cb->args[0] += n_i;
	return n_i;

115
nla_put_failure:
116
	nla_nest_cancel(skb, nest);
117 118 119 120 121 122 123
	goto done;
}

static int tcf_del_walker(struct sk_buff *skb, struct tc_action *a,
			  struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p, *s_p;
124
	struct nlattr *nest;
E
Eric Dumazet 已提交
125
	int i = 0, n_i = 0;
126

127 128 129
	nest = nla_nest_start(skb, a->order);
	if (nest == NULL)
		goto nla_put_failure;
130 131
	if (nla_put_string(skb, TCA_KIND, a->ops->kind))
		goto nla_put_failure;
132 133 134 135 136 137
	for (i = 0; i < (hinfo->hmask + 1); i++) {
		p = hinfo->htab[tcf_hash(i, hinfo->hmask)];

		while (p != NULL) {
			s_p = p->tcfc_next;
			if (ACT_P_DELETED == tcf_hash_release(p, 0, hinfo))
E
Eric Dumazet 已提交
138
				module_put(a->ops->owner);
139 140 141 142
			n_i++;
			p = s_p;
		}
	}
143 144
	if (nla_put_u32(skb, TCA_FCNT, n_i))
		goto nla_put_failure;
145
	nla_nest_end(skb, nest);
146 147

	return n_i;
148
nla_put_failure:
149
	nla_nest_cancel(skb, nest);
150 151 152 153 154 155 156 157 158 159 160 161 162
	return -EINVAL;
}

int tcf_generic_walker(struct sk_buff *skb, struct netlink_callback *cb,
		       int type, struct tc_action *a)
{
	struct tcf_hashinfo *hinfo = a->ops->hinfo;

	if (type == RTM_DELACTION) {
		return tcf_del_walker(skb, a, hinfo);
	} else if (type == RTM_GETACTION) {
		return tcf_dump_walker(skb, cb, a, hinfo);
	} else {
163
		WARN(1, "tcf_generic_walker: unknown action %d\n", type);
164 165 166 167 168 169 170 171 172
		return -EINVAL;
	}
}
EXPORT_SYMBOL(tcf_generic_walker);

struct tcf_common *tcf_hash_lookup(u32 index, struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p;

173
	read_lock_bh(hinfo->lock);
174 175 176 177 178
	for (p = hinfo->htab[tcf_hash(index, hinfo->hmask)]; p;
	     p = p->tcfc_next) {
		if (p->tcfc_index == index)
			break;
	}
179
	read_unlock_bh(hinfo->lock);
180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215

	return p;
}
EXPORT_SYMBOL(tcf_hash_lookup);

u32 tcf_hash_new_index(u32 *idx_gen, struct tcf_hashinfo *hinfo)
{
	u32 val = *idx_gen;

	do {
		if (++val == 0)
			val = 1;
	} while (tcf_hash_lookup(val, hinfo));

	return (*idx_gen = val);
}
EXPORT_SYMBOL(tcf_hash_new_index);

int tcf_hash_search(struct tc_action *a, u32 index)
{
	struct tcf_hashinfo *hinfo = a->ops->hinfo;
	struct tcf_common *p = tcf_hash_lookup(index, hinfo);

	if (p) {
		a->priv = p;
		return 1;
	}
	return 0;
}
EXPORT_SYMBOL(tcf_hash_search);

struct tcf_common *tcf_hash_check(u32 index, struct tc_action *a, int bind,
				  struct tcf_hashinfo *hinfo)
{
	struct tcf_common *p = NULL;
	if (index && (p = tcf_hash_lookup(index, hinfo)) != NULL) {
216
		if (bind)
217
			p->tcfc_bindcnt++;
218
		p->tcfc_refcnt++;
219 220 221 222 223 224
		a->priv = p;
	}
	return p;
}
EXPORT_SYMBOL(tcf_hash_check);

225 226 227
struct tcf_common *tcf_hash_create(u32 index, struct nlattr *est,
				   struct tc_action *a, int size, int bind,
				   u32 *idx_gen, struct tcf_hashinfo *hinfo)
228 229 230 231
{
	struct tcf_common *p = kzalloc(size, GFP_KERNEL);

	if (unlikely(!p))
232
		return ERR_PTR(-ENOMEM);
233 234 235 236 237 238 239 240
	p->tcfc_refcnt = 1;
	if (bind)
		p->tcfc_bindcnt = 1;

	spin_lock_init(&p->tcfc_lock);
	p->tcfc_index = index ? index : tcf_hash_new_index(idx_gen, hinfo);
	p->tcfc_tm.install = jiffies;
	p->tcfc_tm.lastuse = jiffies;
241 242 243 244 245 246 247 248 249
	if (est) {
		int err = gen_new_estimator(&p->tcfc_bstats, &p->tcfc_rate_est,
					    &p->tcfc_lock, est);
		if (err) {
			kfree(p);
			return ERR_PTR(err);
		}
	}

250 251 252 253 254 255 256 257 258 259 260 261 262 263 264
	a->priv = (void *) p;
	return p;
}
EXPORT_SYMBOL(tcf_hash_create);

void tcf_hash_insert(struct tcf_common *p, struct tcf_hashinfo *hinfo)
{
	unsigned int h = tcf_hash(p->tcfc_index, hinfo->hmask);

	write_lock_bh(hinfo->lock);
	p->tcfc_next = hinfo->htab[h];
	hinfo->htab[h] = p;
	write_unlock_bh(hinfo->lock);
}
EXPORT_SYMBOL(tcf_hash_insert);
L
Linus Torvalds 已提交
265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284

static struct tc_action_ops *act_base = NULL;
static DEFINE_RWLOCK(act_mod_lock);

int tcf_register_action(struct tc_action_ops *act)
{
	struct tc_action_ops *a, **ap;

	write_lock(&act_mod_lock);
	for (ap = &act_base; (a = *ap) != NULL; ap = &a->next) {
		if (act->type == a->type || (strcmp(act->kind, a->kind) == 0)) {
			write_unlock(&act_mod_lock);
			return -EEXIST;
		}
	}
	act->next = NULL;
	*ap = act;
	write_unlock(&act_mod_lock);
	return 0;
}
285
EXPORT_SYMBOL(tcf_register_action);
L
Linus Torvalds 已提交
286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303

int tcf_unregister_action(struct tc_action_ops *act)
{
	struct tc_action_ops *a, **ap;
	int err = -ENOENT;

	write_lock(&act_mod_lock);
	for (ap = &act_base; (a = *ap) != NULL; ap = &a->next)
		if (a == act)
			break;
	if (a) {
		*ap = a->next;
		a->next = NULL;
		err = 0;
	}
	write_unlock(&act_mod_lock);
	return err;
}
304
EXPORT_SYMBOL(tcf_unregister_action);
L
Linus Torvalds 已提交
305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326

/* lookup by name */
static struct tc_action_ops *tc_lookup_action_n(char *kind)
{
	struct tc_action_ops *a = NULL;

	if (kind) {
		read_lock(&act_mod_lock);
		for (a = act_base; a; a = a->next) {
			if (strcmp(kind, a->kind) == 0) {
				if (!try_module_get(a->owner)) {
					read_unlock(&act_mod_lock);
					return NULL;
				}
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
	return a;
}

327 328
/* lookup by nlattr */
static struct tc_action_ops *tc_lookup_action(struct nlattr *kind)
L
Linus Torvalds 已提交
329 330 331 332 333 334
{
	struct tc_action_ops *a = NULL;

	if (kind) {
		read_lock(&act_mod_lock);
		for (a = act_base; a; a = a->next) {
335
			if (nla_strcmp(kind, a->kind) == 0) {
L
Linus Torvalds 已提交
336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370
				if (!try_module_get(a->owner)) {
					read_unlock(&act_mod_lock);
					return NULL;
				}
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
	return a;
}

#if 0
/* lookup by id */
static struct tc_action_ops *tc_lookup_action_id(u32 type)
{
	struct tc_action_ops *a = NULL;

	if (type) {
		read_lock(&act_mod_lock);
		for (a = act_base; a; a = a->next) {
			if (a->type == type) {
				if (!try_module_get(a->owner)) {
					read_unlock(&act_mod_lock);
					return NULL;
				}
				break;
			}
		}
		read_unlock(&act_mod_lock);
	}
	return a;
}
#endif

371
int tcf_action_exec(struct sk_buff *skb, const struct tc_action *act,
372
		    struct tcf_result *res)
L
Linus Torvalds 已提交
373
{
374
	const struct tc_action *a;
L
Linus Torvalds 已提交
375 376 377 378 379 380 381 382 383 384
	int ret = -1;

	if (skb->tc_verd & TC_NCLS) {
		skb->tc_verd = CLR_TC_NCLS(skb->tc_verd);
		ret = TC_ACT_OK;
		goto exec_done;
	}
	while ((a = act) != NULL) {
repeat:
		if (a->ops && a->ops->act) {
385
			ret = a->ops->act(skb, a, res);
L
Linus Torvalds 已提交
386 387 388 389 390 391 392
			if (TC_MUNGED & skb->tc_verd) {
				/* copied already, allow trampling */
				skb->tc_verd = SET_TC_OK2MUNGE(skb->tc_verd);
				skb->tc_verd = CLR_TC_MUNGED(skb->tc_verd);
			}
			if (ret == TC_ACT_REPEAT)
				goto repeat;	/* we need a ttl - JHS */
J
J Hadi Salim 已提交
393 394
			if (ret != TC_ACT_PIPE)
				goto exec_done;
L
Linus Torvalds 已提交
395 396 397 398 399 400
		}
		act = a->next;
	}
exec_done:
	return ret;
}
401
EXPORT_SYMBOL(tcf_action_exec);
L
Linus Torvalds 已提交
402 403 404 405 406 407 408 409 410 411 412

void tcf_action_destroy(struct tc_action *act, int bind)
{
	struct tc_action *a;

	for (a = act; a; a = act) {
		if (a->ops && a->ops->cleanup) {
			if (a->ops->cleanup(a, bind) == ACT_P_DELETED)
				module_put(a->ops->owner);
			act = act->next;
			kfree(a);
413 414 415
		} else {
			/*FIXME: Remove later - catch insertion bugs*/
			WARN(1, "tcf_action_destroy: BUG? destroying NULL ops\n");
L
Linus Torvalds 已提交
416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435
			act = act->next;
			kfree(a);
		}
	}
}

int
tcf_action_dump_old(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{
	int err = -EINVAL;

	if (a->ops == NULL || a->ops->dump == NULL)
		return err;
	return a->ops->dump(skb, a, bind, ref);
}

int
tcf_action_dump_1(struct sk_buff *skb, struct tc_action *a, int bind, int ref)
{
	int err = -EINVAL;
436
	unsigned char *b = skb_tail_pointer(skb);
437
	struct nlattr *nest;
L
Linus Torvalds 已提交
438 439 440 441

	if (a->ops == NULL || a->ops->dump == NULL)
		return err;

442 443
	if (nla_put_string(skb, TCA_KIND, a->ops->kind))
		goto nla_put_failure;
L
Linus Torvalds 已提交
444
	if (tcf_action_copy_stats(skb, a, 0))
445
		goto nla_put_failure;
446 447 448
	nest = nla_nest_start(skb, TCA_OPTIONS);
	if (nest == NULL)
		goto nla_put_failure;
E
Eric Dumazet 已提交
449 450
	err = tcf_action_dump_old(skb, a, bind, ref);
	if (err > 0) {
451
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
452 453 454
		return err;
	}

455
nla_put_failure:
456
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
457 458
	return -1;
}
459
EXPORT_SYMBOL(tcf_action_dump_1);
L
Linus Torvalds 已提交
460 461 462 463 464 465

int
tcf_action_dump(struct sk_buff *skb, struct tc_action *act, int bind, int ref)
{
	struct tc_action *a;
	int err = -EINVAL;
466
	struct nlattr *nest;
L
Linus Torvalds 已提交
467 468 469

	while ((a = act) != NULL) {
		act = a->next;
470 471 472
		nest = nla_nest_start(skb, a->order);
		if (nest == NULL)
			goto nla_put_failure;
L
Linus Torvalds 已提交
473 474
		err = tcf_action_dump_1(skb, a, bind, ref);
		if (err < 0)
475
			goto errout;
476
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
477 478 479 480
	}

	return 0;

481
nla_put_failure:
482 483
	err = -EINVAL;
errout:
484
	nla_nest_cancel(skb, nest);
485
	return err;
L
Linus Torvalds 已提交
486 487
}

488
struct tc_action *tcf_action_init_1(struct nlattr *nla, struct nlattr *est,
489
				    char *name, int ovr, int bind)
L
Linus Torvalds 已提交
490 491 492 493
{
	struct tc_action *a;
	struct tc_action_ops *a_o;
	char act_name[IFNAMSIZ];
E
Eric Dumazet 已提交
494
	struct nlattr *tb[TCA_ACT_MAX + 1];
495
	struct nlattr *kind;
496
	int err;
L
Linus Torvalds 已提交
497 498

	if (name == NULL) {
499 500
		err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL);
		if (err < 0)
L
Linus Torvalds 已提交
501
			goto err_out;
502
		err = -EINVAL;
503
		kind = tb[TCA_ACT_KIND];
L
Linus Torvalds 已提交
504 505
		if (kind == NULL)
			goto err_out;
506
		if (nla_strlcpy(act_name, kind, IFNAMSIZ) >= IFNAMSIZ)
L
Linus Torvalds 已提交
507 508
			goto err_out;
	} else {
509
		err = -EINVAL;
L
Linus Torvalds 已提交
510 511 512 513 514 515
		if (strlcpy(act_name, name, IFNAMSIZ) >= IFNAMSIZ)
			goto err_out;
	}

	a_o = tc_lookup_action_n(act_name);
	if (a_o == NULL) {
516
#ifdef CONFIG_MODULES
L
Linus Torvalds 已提交
517
		rtnl_unlock();
518
		request_module("act_%s", act_name);
L
Linus Torvalds 已提交
519 520 521 522 523 524 525 526 527 528 529
		rtnl_lock();

		a_o = tc_lookup_action_n(act_name);

		/* We dropped the RTNL semaphore in order to
		 * perform the module load.  So, even if we
		 * succeeded in loading the module we have to
		 * tell the caller to replay the request.  We
		 * indicate this using -EAGAIN.
		 */
		if (a_o != NULL) {
530
			err = -EAGAIN;
L
Linus Torvalds 已提交
531 532 533
			goto err_mod;
		}
#endif
534
		err = -ENOENT;
L
Linus Torvalds 已提交
535 536 537
		goto err_out;
	}

538
	err = -ENOMEM;
539
	a = kzalloc(sizeof(*a), GFP_KERNEL);
L
Linus Torvalds 已提交
540 541 542 543 544
	if (a == NULL)
		goto err_mod;

	/* backward compatibility for policer */
	if (name == NULL)
545
		err = a_o->init(tb[TCA_ACT_OPTIONS], est, a, ovr, bind);
L
Linus Torvalds 已提交
546
	else
547 548
		err = a_o->init(nla, est, a, ovr, bind);
	if (err < 0)
L
Linus Torvalds 已提交
549 550 551
		goto err_free;

	/* module count goes up only when brand new policy is created
E
Eric Dumazet 已提交
552 553 554
	 * if it exists and is only bound to in a_o->init() then
	 * ACT_P_CREATED is not returned (a zero is).
	 */
555
	if (err != ACT_P_CREATED)
L
Linus Torvalds 已提交
556 557 558 559 560 561 562 563 564 565
		module_put(a_o->owner);
	a->ops = a_o;

	return a;

err_free:
	kfree(a);
err_mod:
	module_put(a_o->owner);
err_out:
566
	return ERR_PTR(err);
L
Linus Torvalds 已提交
567 568
}

569
struct tc_action *tcf_action_init(struct nlattr *nla, struct nlattr *est,
570
				  char *name, int ovr, int bind)
L
Linus Torvalds 已提交
571
{
E
Eric Dumazet 已提交
572
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
L
Linus Torvalds 已提交
573
	struct tc_action *head = NULL, *act, *act_prev = NULL;
574
	int err;
L
Linus Torvalds 已提交
575 576
	int i;

577 578 579
	err = nla_parse_nested(tb, TCA_ACT_MAX_PRIO, nla, NULL);
	if (err < 0)
		return ERR_PTR(err);
L
Linus Torvalds 已提交
580

581
	for (i = 1; i <= TCA_ACT_MAX_PRIO && tb[i]; i++) {
582 583
		act = tcf_action_init_1(tb[i], est, name, ovr, bind);
		if (IS_ERR(act))
L
Linus Torvalds 已提交
584
			goto err;
585
		act->order = i;
L
Linus Torvalds 已提交
586 587 588 589 590 591 592 593 594 595 596 597

		if (head == NULL)
			head = act;
		else
			act_prev->next = act;
		act_prev = act;
	}
	return head;

err:
	if (head != NULL)
		tcf_action_destroy(head, bind);
598
	return act;
L
Linus Torvalds 已提交
599 600 601 602 603 604 605 606
}

int tcf_action_copy_stats(struct sk_buff *skb, struct tc_action *a,
			  int compat_mode)
{
	int err = 0;
	struct gnet_dump d;
	struct tcf_act_hdr *h = a->priv;
607

L
Linus Torvalds 已提交
608 609 610 611
	if (h == NULL)
		goto errout;

	/* compat_mode being true specifies a call that is supposed
612
	 * to add additional backward compatibility statistic TLVs.
L
Linus Torvalds 已提交
613 614 615 616
	 */
	if (compat_mode) {
		if (a->type == TCA_OLD_COMPAT)
			err = gnet_stats_start_copy_compat(skb, 0,
617
				TCA_STATS, TCA_XSTATS, &h->tcf_lock, &d);
L
Linus Torvalds 已提交
618 619 620 621
		else
			return 0;
	} else
		err = gnet_stats_start_copy(skb, TCA_ACT_STATS,
622
					    &h->tcf_lock, &d);
L
Linus Torvalds 已提交
623 624 625 626 627 628 629 630

	if (err < 0)
		goto errout;

	if (a->ops != NULL && a->ops->get_stats != NULL)
		if (a->ops->get_stats(skb, a) < 0)
			goto errout;

631
	if (gnet_stats_copy_basic(&d, &h->tcf_bstats) < 0 ||
632 633
	    gnet_stats_copy_rate_est(&d, &h->tcf_bstats,
				     &h->tcf_rate_est) < 0 ||
634
	    gnet_stats_copy_queue(&d, &h->tcf_qstats) < 0)
L
Linus Torvalds 已提交
635 636 637 638 639 640 641 642 643 644 645 646 647
		goto errout;

	if (gnet_stats_finish_copy(&d) < 0)
		goto errout;

	return 0;

errout:
	return -1;
}

static int
tca_get_fill(struct sk_buff *skb, struct tc_action *a, u32 pid, u32 seq,
648
	     u16 flags, int event, int bind, int ref)
L
Linus Torvalds 已提交
649 650 651
{
	struct tcamsg *t;
	struct nlmsghdr *nlh;
652
	unsigned char *b = skb_tail_pointer(skb);
653
	struct nlattr *nest;
L
Linus Torvalds 已提交
654

655 656 657 658
	nlh = nlmsg_put(skb, pid, seq, event, sizeof(*t), flags);
	if (!nlh)
		goto out_nlmsg_trim;
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
659
	t->tca_family = AF_UNSPEC;
660 661
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
662

663 664
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
665
		goto out_nlmsg_trim;
L
Linus Torvalds 已提交
666 667

	if (tcf_action_dump(skb, a, bind, ref) < 0)
668
		goto out_nlmsg_trim;
L
Linus Torvalds 已提交
669

670
	nla_nest_end(skb, nest);
671

672
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
673 674
	return skb->len;

675
out_nlmsg_trim:
676
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
677 678 679 680
	return -1;
}

static int
681 682
act_get_notify(struct net *net, u32 pid, struct nlmsghdr *n,
	       struct tc_action *a, int event)
L
Linus Torvalds 已提交
683 684 685 686 687 688 689 690 691 692
{
	struct sk_buff *skb;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;
	if (tca_get_fill(skb, a, pid, n->nlmsg_seq, 0, event, 0, 0) <= 0) {
		kfree_skb(skb);
		return -EINVAL;
	}
693

694
	return rtnl_unicast(skb, net, pid);
L
Linus Torvalds 已提交
695 696 697
}

static struct tc_action *
698
tcf_action_get_1(struct nlattr *nla, struct nlmsghdr *n, u32 pid)
L
Linus Torvalds 已提交
699
{
E
Eric Dumazet 已提交
700
	struct nlattr *tb[TCA_ACT_MAX + 1];
L
Linus Torvalds 已提交
701 702
	struct tc_action *a;
	int index;
703
	int err;
L
Linus Torvalds 已提交
704

705 706
	err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL);
	if (err < 0)
707
		goto err_out;
L
Linus Torvalds 已提交
708

709
	err = -EINVAL;
710 711
	if (tb[TCA_ACT_INDEX] == NULL ||
	    nla_len(tb[TCA_ACT_INDEX]) < sizeof(index))
712
		goto err_out;
713
	index = nla_get_u32(tb[TCA_ACT_INDEX]);
L
Linus Torvalds 已提交
714

715
	err = -ENOMEM;
716
	a = kzalloc(sizeof(struct tc_action), GFP_KERNEL);
L
Linus Torvalds 已提交
717
	if (a == NULL)
718
		goto err_out;
L
Linus Torvalds 已提交
719

720
	err = -EINVAL;
721
	a->ops = tc_lookup_action(tb[TCA_ACT_KIND]);
L
Linus Torvalds 已提交
722 723 724 725
	if (a->ops == NULL)
		goto err_free;
	if (a->ops->lookup == NULL)
		goto err_mod;
726
	err = -ENOENT;
L
Linus Torvalds 已提交
727 728 729 730 731
	if (a->ops->lookup(a, index) == 0)
		goto err_mod;

	module_put(a->ops->owner);
	return a;
732

L
Linus Torvalds 已提交
733 734 735 736
err_mod:
	module_put(a->ops->owner);
err_free:
	kfree(a);
737 738
err_out:
	return ERR_PTR(err);
L
Linus Torvalds 已提交
739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754
}

static void cleanup_a(struct tc_action *act)
{
	struct tc_action *a;

	for (a = act; a; a = act) {
		act = a->next;
		kfree(a);
	}
}

static struct tc_action *create_a(int i)
{
	struct tc_action *act;

755
	act = kzalloc(sizeof(*act), GFP_KERNEL);
L
Linus Torvalds 已提交
756
	if (act == NULL) {
757
		pr_debug("create_a: failed to alloc!\n");
L
Linus Torvalds 已提交
758 759 760 761 762 763
		return NULL;
	}
	act->order = i;
	return act;
}

764 765
static int tca_action_flush(struct net *net, struct nlattr *nla,
			    struct nlmsghdr *n, u32 pid)
L
Linus Torvalds 已提交
766 767 768 769 770 771
{
	struct sk_buff *skb;
	unsigned char *b;
	struct nlmsghdr *nlh;
	struct tcamsg *t;
	struct netlink_callback dcb;
772
	struct nlattr *nest;
E
Eric Dumazet 已提交
773
	struct nlattr *tb[TCA_ACT_MAX + 1];
774
	struct nlattr *kind;
L
Linus Torvalds 已提交
775
	struct tc_action *a = create_a(0);
776
	int err = -ENOMEM;
L
Linus Torvalds 已提交
777 778

	if (a == NULL) {
779
		pr_debug("tca_action_flush: couldnt create tc_action\n");
L
Linus Torvalds 已提交
780 781 782 783 784
		return err;
	}

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb) {
785
		pr_debug("tca_action_flush: failed skb alloc\n");
L
Linus Torvalds 已提交
786
		kfree(a);
787
		return err;
L
Linus Torvalds 已提交
788 789
	}

790
	b = skb_tail_pointer(skb);
L
Linus Torvalds 已提交
791

792 793
	err = nla_parse_nested(tb, TCA_ACT_MAX, nla, NULL);
	if (err < 0)
L
Linus Torvalds 已提交
794 795
		goto err_out;

796
	err = -EINVAL;
797
	kind = tb[TCA_ACT_KIND];
L
Linus Torvalds 已提交
798 799 800 801
	a->ops = tc_lookup_action(kind);
	if (a->ops == NULL)
		goto err_out;

802 803 804 805
	nlh = nlmsg_put(skb, pid, n->nlmsg_seq, RTM_DELACTION, sizeof(*t), 0);
	if (!nlh)
		goto out_module_put;
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
806
	t->tca_family = AF_UNSPEC;
807 808
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
L
Linus Torvalds 已提交
809

810 811
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
812
		goto out_module_put;
L
Linus Torvalds 已提交
813 814 815

	err = a->ops->walk(skb, &dcb, RTM_DELACTION, a);
	if (err < 0)
816
		goto out_module_put;
817 818
	if (err == 0)
		goto noflush_out;
L
Linus Torvalds 已提交
819

820
	nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
821

822
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
823 824 825
	nlh->nlmsg_flags |= NLM_F_ROOT;
	module_put(a->ops->owner);
	kfree(a);
E
Eric Dumazet 已提交
826 827
	err = rtnetlink_send(skb, net, pid, RTNLGRP_TC,
			     n->nlmsg_flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
828 829 830 831 832
	if (err > 0)
		return 0;

	return err;

833
out_module_put:
834
	module_put(a->ops->owner);
L
Linus Torvalds 已提交
835
err_out:
836
noflush_out:
L
Linus Torvalds 已提交
837 838 839 840 841 842
	kfree_skb(skb);
	kfree(a);
	return err;
}

static int
843 844
tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
	      u32 pid, int event)
L
Linus Torvalds 已提交
845
{
846
	int i, ret;
E
Eric Dumazet 已提交
847
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
L
Linus Torvalds 已提交
848 849
	struct tc_action *head = NULL, *act, *act_prev = NULL;

850 851 852
	ret = nla_parse_nested(tb, TCA_ACT_MAX_PRIO, nla, NULL);
	if (ret < 0)
		return ret;
L
Linus Torvalds 已提交
853

E
Eric Dumazet 已提交
854
	if (event == RTM_DELACTION && n->nlmsg_flags & NLM_F_ROOT) {
855
		if (tb[1] != NULL)
856
			return tca_action_flush(net, tb[1], n, pid);
857 858
		else
			return -EINVAL;
L
Linus Torvalds 已提交
859 860
	}

861
	for (i = 1; i <= TCA_ACT_MAX_PRIO && tb[i]; i++) {
862 863 864
		act = tcf_action_get_1(tb[i], n, pid);
		if (IS_ERR(act)) {
			ret = PTR_ERR(act);
L
Linus Torvalds 已提交
865
			goto err;
866
		}
867
		act->order = i;
L
Linus Torvalds 已提交
868 869 870 871 872 873 874 875 876

		if (head == NULL)
			head = act;
		else
			act_prev->next = act;
		act_prev = act;
	}

	if (event == RTM_GETACTION)
877
		ret = act_get_notify(net, pid, n, head, event);
L
Linus Torvalds 已提交
878 879 880 881 882 883 884 885 886 887
	else { /* delete */
		struct sk_buff *skb;

		skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
		if (!skb) {
			ret = -ENOBUFS;
			goto err;
		}

		if (tca_get_fill(skb, head, pid, n->nlmsg_seq, 0, event,
888
				 0, 1) <= 0) {
L
Linus Torvalds 已提交
889 890 891 892 893 894 895
			kfree_skb(skb);
			ret = -EINVAL;
			goto err;
		}

		/* now do the delete */
		tcf_action_destroy(head, 0);
896
		ret = rtnetlink_send(skb, net, pid, RTNLGRP_TC,
E
Eric Dumazet 已提交
897
				     n->nlmsg_flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
898 899 900 901 902 903 904 905 906
		if (ret > 0)
			return 0;
		return ret;
	}
err:
	cleanup_a(head);
	return ret;
}

907 908
static int tcf_add_notify(struct net *net, struct tc_action *a,
			  u32 pid, u32 seq, int event, u16 flags)
L
Linus Torvalds 已提交
909 910 911 912
{
	struct tcamsg *t;
	struct nlmsghdr *nlh;
	struct sk_buff *skb;
913
	struct nlattr *nest;
L
Linus Torvalds 已提交
914 915 916 917 918 919 920
	unsigned char *b;
	int err = 0;

	skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!skb)
		return -ENOBUFS;

921
	b = skb_tail_pointer(skb);
L
Linus Torvalds 已提交
922

923 924 925 926
	nlh = nlmsg_put(skb, pid, seq, event, sizeof(*t), flags);
	if (!nlh)
		goto out_kfree_skb;
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
927
	t->tca_family = AF_UNSPEC;
928 929 930
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;

931 932
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
933
		goto out_kfree_skb;
L
Linus Torvalds 已提交
934 935

	if (tcf_action_dump(skb, a, 0, 0) < 0)
936
		goto out_kfree_skb;
L
Linus Torvalds 已提交
937

938
	nla_nest_end(skb, nest);
939

940
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
941
	NETLINK_CB(skb).dst_group = RTNLGRP_TC;
942

E
Eric Dumazet 已提交
943
	err = rtnetlink_send(skb, net, pid, RTNLGRP_TC, flags & NLM_F_ECHO);
L
Linus Torvalds 已提交
944 945 946 947
	if (err > 0)
		err = 0;
	return err;

948
out_kfree_skb:
949
	kfree_skb(skb);
L
Linus Torvalds 已提交
950 951 952
	return -1;
}

953

L
Linus Torvalds 已提交
954
static int
955 956
tcf_action_add(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
	       u32 pid, int ovr)
L
Linus Torvalds 已提交
957 958 959 960 961 962
{
	int ret = 0;
	struct tc_action *act;
	struct tc_action *a;
	u32 seq = n->nlmsg_seq;

963
	act = tcf_action_init(nla, NULL, NULL, ovr, 0);
L
Linus Torvalds 已提交
964 965
	if (act == NULL)
		goto done;
966 967 968 969
	if (IS_ERR(act)) {
		ret = PTR_ERR(act);
		goto done;
	}
L
Linus Torvalds 已提交
970 971 972

	/* dump then free all the actions after update; inserted policy
	 * stays intact
E
Eric Dumazet 已提交
973
	 */
974
	ret = tcf_add_notify(net, act, pid, seq, RTM_NEWACTION, n->nlmsg_flags);
L
Linus Torvalds 已提交
975 976 977 978 979 980 981 982 983 984
	for (a = act; a; a = act) {
		act = a->next;
		kfree(a);
	}
done:
	return ret;
}

static int tc_ctl_action(struct sk_buff *skb, struct nlmsghdr *n, void *arg)
{
985
	struct net *net = sock_net(skb->sk);
986
	struct nlattr *tca[TCA_ACT_MAX + 1];
L
Linus Torvalds 已提交
987 988 989
	u32 pid = skb ? NETLINK_CB(skb).pid : 0;
	int ret = 0, ovr = 0;

990 991 992 993 994
	ret = nlmsg_parse(n, sizeof(struct tcamsg), tca, TCA_ACT_MAX, NULL);
	if (ret < 0)
		return ret;

	if (tca[TCA_ACT_TAB] == NULL) {
995
		pr_notice("tc_ctl_action: received NO action attribs\n");
L
Linus Torvalds 已提交
996 997 998
		return -EINVAL;
	}

E
Eric Dumazet 已提交
999
	/* n->nlmsg_flags & NLM_F_CREATE */
L
Linus Torvalds 已提交
1000 1001 1002
	switch (n->nlmsg_type) {
	case RTM_NEWACTION:
		/* we are going to assume all other flags
L
Lucas De Marchi 已提交
1003
		 * imply create only if it doesn't exist
L
Linus Torvalds 已提交
1004 1005 1006 1007
		 * Note that CREATE | EXCL implies that
		 * but since we want avoid ambiguity (eg when flags
		 * is zero) then just set this
		 */
E
Eric Dumazet 已提交
1008
		if (n->nlmsg_flags & NLM_F_REPLACE)
L
Linus Torvalds 已提交
1009 1010
			ovr = 1;
replay:
1011
		ret = tcf_action_add(net, tca[TCA_ACT_TAB], n, pid, ovr);
L
Linus Torvalds 已提交
1012 1013 1014 1015
		if (ret == -EAGAIN)
			goto replay;
		break;
	case RTM_DELACTION:
1016 1017
		ret = tca_action_gd(net, tca[TCA_ACT_TAB], n,
				    pid, RTM_DELACTION);
L
Linus Torvalds 已提交
1018 1019
		break;
	case RTM_GETACTION:
1020 1021
		ret = tca_action_gd(net, tca[TCA_ACT_TAB], n,
				    pid, RTM_GETACTION);
L
Linus Torvalds 已提交
1022 1023 1024 1025 1026 1027 1028 1029
		break;
	default:
		BUG();
	}

	return ret;
}

1030
static struct nlattr *
1031
find_dump_kind(const struct nlmsghdr *n)
L
Linus Torvalds 已提交
1032
{
E
Eric Dumazet 已提交
1033
	struct nlattr *tb1, *tb2[TCA_ACT_MAX + 1];
1034 1035 1036
	struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
	struct nlattr *nla[TCAA_MAX + 1];
	struct nlattr *kind;
L
Linus Torvalds 已提交
1037

1038
	if (nlmsg_parse(n, sizeof(struct tcamsg), nla, TCAA_MAX, NULL) < 0)
L
Linus Torvalds 已提交
1039
		return NULL;
1040
	tb1 = nla[TCA_ACT_TAB];
L
Linus Torvalds 已提交
1041 1042 1043
	if (tb1 == NULL)
		return NULL;

1044 1045
	if (nla_parse(tb, TCA_ACT_MAX_PRIO, nla_data(tb1),
		      NLMSG_ALIGN(nla_len(tb1)), NULL) < 0)
L
Linus Torvalds 已提交
1046 1047
		return NULL;

1048 1049 1050 1051
	if (tb[1] == NULL)
		return NULL;
	if (nla_parse(tb2, TCA_ACT_MAX, nla_data(tb[1]),
		      nla_len(tb[1]), NULL) < 0)
L
Linus Torvalds 已提交
1052
		return NULL;
1053
	kind = tb2[TCA_ACT_KIND];
L
Linus Torvalds 已提交
1054

1055
	return kind;
L
Linus Torvalds 已提交
1056 1057 1058 1059 1060 1061
}

static int
tc_dump_action(struct sk_buff *skb, struct netlink_callback *cb)
{
	struct nlmsghdr *nlh;
1062
	unsigned char *b = skb_tail_pointer(skb);
1063
	struct nlattr *nest;
L
Linus Torvalds 已提交
1064 1065 1066
	struct tc_action_ops *a_o;
	struct tc_action a;
	int ret = 0;
1067
	struct tcamsg *t = (struct tcamsg *) nlmsg_data(cb->nlh);
1068
	struct nlattr *kind = find_dump_kind(cb->nlh);
L
Linus Torvalds 已提交
1069 1070

	if (kind == NULL) {
1071
		pr_info("tc_dump_action: action bad kind\n");
L
Linus Torvalds 已提交
1072 1073 1074
		return 0;
	}

1075
	a_o = tc_lookup_action(kind);
E
Eric Dumazet 已提交
1076
	if (a_o == NULL)
L
Linus Torvalds 已提交
1077 1078 1079 1080 1081 1082
		return 0;

	memset(&a, 0, sizeof(struct tc_action));
	a.ops = a_o;

	if (a_o->walk == NULL) {
1083 1084
		WARN(1, "tc_dump_action: %s !capable of dumping table\n",
		     a_o->kind);
1085
		goto out_module_put;
L
Linus Torvalds 已提交
1086 1087
	}

1088 1089 1090 1091 1092
	nlh = nlmsg_put(skb, NETLINK_CB(cb->skb).pid, cb->nlh->nlmsg_seq,
			cb->nlh->nlmsg_type, sizeof(*t), 0);
	if (!nlh)
		goto out_module_put;
	t = nlmsg_data(nlh);
L
Linus Torvalds 已提交
1093
	t->tca_family = AF_UNSPEC;
1094 1095
	t->tca__pad1 = 0;
	t->tca__pad2 = 0;
L
Linus Torvalds 已提交
1096

1097 1098
	nest = nla_nest_start(skb, TCA_ACT_TAB);
	if (nest == NULL)
1099
		goto out_module_put;
L
Linus Torvalds 已提交
1100 1101 1102

	ret = a_o->walk(skb, cb, RTM_GETACTION, &a);
	if (ret < 0)
1103
		goto out_module_put;
L
Linus Torvalds 已提交
1104 1105

	if (ret > 0) {
1106
		nla_nest_end(skb, nest);
L
Linus Torvalds 已提交
1107 1108
		ret = skb->len;
	} else
1109
		nla_nest_cancel(skb, nest);
L
Linus Torvalds 已提交
1110

1111
	nlh->nlmsg_len = skb_tail_pointer(skb) - b;
L
Linus Torvalds 已提交
1112 1113 1114 1115 1116
	if (NETLINK_CB(cb->skb).pid && ret)
		nlh->nlmsg_flags |= NLM_F_MULTI;
	module_put(a_o->owner);
	return skb->len;

1117
out_module_put:
L
Linus Torvalds 已提交
1118
	module_put(a_o->owner);
1119
	nlmsg_trim(skb, b);
L
Linus Torvalds 已提交
1120 1121 1122 1123 1124
	return skb->len;
}

static int __init tc_action_init(void)
{
1125 1126 1127 1128
	rtnl_register(PF_UNSPEC, RTM_NEWACTION, tc_ctl_action, NULL, NULL);
	rtnl_register(PF_UNSPEC, RTM_DELACTION, tc_ctl_action, NULL, NULL);
	rtnl_register(PF_UNSPEC, RTM_GETACTION, tc_ctl_action, tc_dump_action,
		      NULL);
L
Linus Torvalds 已提交
1129 1130 1131 1132 1133

	return 0;
}

subsys_initcall(tc_action_init);