]> git.ipfire.org Git - thirdparty/linux.git/blame - net/sched/act_vlan.c
net/sched: act_tunnel_key: validate the control action inside init()
[thirdparty/linux.git] / net / sched / act_vlan.c
CommitLineData
c7e2b968
JP
1/*
2 * Copyright (c) 2014 Jiri Pirko <jiri@resnulli.us>
3 *
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License as published by
6 * the Free Software Foundation; either version 2 of the License, or
7 * (at your option) any later version.
8 */
9
10#include <linux/module.h>
11#include <linux/init.h>
12#include <linux/kernel.h>
13#include <linux/skbuff.h>
14#include <linux/rtnetlink.h>
15#include <linux/if_vlan.h>
16#include <net/netlink.h>
17#include <net/pkt_sched.h>
18
19#include <linux/tc_act/tc_vlan.h>
20#include <net/tc_act/tc_vlan.h>
21
c7d03a00 22static unsigned int vlan_net_id;
a85a970a 23static struct tc_action_ops act_vlan_ops;
ddf97ccd 24
8aa7f22e
JHS
25static int tcf_vlan_act(struct sk_buff *skb, const struct tc_action *a,
26 struct tcf_result *res)
c7e2b968 27{
a85a970a 28 struct tcf_vlan *v = to_vlan(a);
4c5b9d96 29 struct tcf_vlan_params *p;
c7e2b968
JP
30 int action;
31 int err;
45a497f2 32 u16 tci;
c7e2b968 33
9c4a4e48 34 tcf_lastuse_update(&v->tcf_tm);
e0496cbb
MK
35 bstats_cpu_update(this_cpu_ptr(v->common.cpu_bstats), skb);
36
f39acc84
SL
37 /* Ensure 'data' points at mac_header prior calling vlan manipulating
38 * functions.
39 */
40 if (skb_at_tc_ingress(skb))
41 skb_push_rcsum(skb, skb->mac_len);
42
4c5b9d96
MK
43 action = READ_ONCE(v->tcf_action);
44
7fd4b288 45 p = rcu_dereference_bh(v->vlan_p);
4c5b9d96
MK
46
47 switch (p->tcfv_action) {
c7e2b968
JP
48 case TCA_VLAN_ACT_POP:
49 err = skb_vlan_pop(skb);
50 if (err)
51 goto drop;
52 break;
53 case TCA_VLAN_ACT_PUSH:
4c5b9d96
MK
54 err = skb_vlan_push(skb, p->tcfv_push_proto, p->tcfv_push_vid |
55 (p->tcfv_push_prio << VLAN_PRIO_SHIFT));
c7e2b968
JP
56 if (err)
57 goto drop;
58 break;
45a497f2
SL
59 case TCA_VLAN_ACT_MODIFY:
60 /* No-op if no vlan tag (either hw-accel or in-payload) */
61 if (!skb_vlan_tagged(skb))
7fd4b288 62 goto out;
45a497f2
SL
63 /* extract existing tag (and guarantee no hw-accel tag) */
64 if (skb_vlan_tag_present(skb)) {
65 tci = skb_vlan_tag_get(skb);
b1817524 66 __vlan_hwaccel_clear_tag(skb);
45a497f2
SL
67 } else {
68 /* in-payload vlan tag, pop it */
69 err = __skb_vlan_pop(skb, &tci);
70 if (err)
71 goto drop;
72 }
73 /* replace the vid */
4c5b9d96 74 tci = (tci & ~VLAN_VID_MASK) | p->tcfv_push_vid;
45a497f2 75 /* replace prio bits, if tcfv_push_prio specified */
4c5b9d96 76 if (p->tcfv_push_prio) {
45a497f2 77 tci &= ~VLAN_PRIO_MASK;
4c5b9d96 78 tci |= p->tcfv_push_prio << VLAN_PRIO_SHIFT;
45a497f2
SL
79 }
80 /* put updated tci as hwaccel tag */
4c5b9d96 81 __vlan_hwaccel_put_tag(skb, p->tcfv_push_proto, tci);
45a497f2 82 break;
c7e2b968
JP
83 default:
84 BUG();
85 }
86
7fd4b288 87out:
f39acc84
SL
88 if (skb_at_tc_ingress(skb))
89 skb_pull_rcsum(skb, skb->mac_len);
90
c7e2b968 91 return action;
7fd4b288
PA
92
93drop:
94 qstats_drop_inc(this_cpu_ptr(v->common.cpu_qstats));
95 return TC_ACT_SHOT;
c7e2b968
JP
96}
97
98static const struct nla_policy vlan_policy[TCA_VLAN_MAX + 1] = {
99 [TCA_VLAN_PARMS] = { .len = sizeof(struct tc_vlan) },
100 [TCA_VLAN_PUSH_VLAN_ID] = { .type = NLA_U16 },
101 [TCA_VLAN_PUSH_VLAN_PROTOCOL] = { .type = NLA_U16 },
956af371 102 [TCA_VLAN_PUSH_VLAN_PRIORITY] = { .type = NLA_U8 },
c7e2b968
JP
103};
104
105static int tcf_vlan_init(struct net *net, struct nlattr *nla,
a85a970a 106 struct nlattr *est, struct tc_action **a,
789871bb 107 int ovr, int bind, bool rtnl_held,
85d0966f 108 struct tcf_proto *tp, struct netlink_ext_ack *extack)
c7e2b968 109{
ddf97ccd 110 struct tc_action_net *tn = net_generic(net, vlan_net_id);
c7e2b968 111 struct nlattr *tb[TCA_VLAN_MAX + 1];
764e9a24 112 struct tcf_vlan_params *p;
c7e2b968
JP
113 struct tc_vlan *parm;
114 struct tcf_vlan *v;
115 int action;
94cb5492 116 u16 push_vid = 0;
c7e2b968 117 __be16 push_proto = 0;
956af371 118 u8 push_prio = 0;
b2313077
WC
119 bool exists = false;
120 int ret = 0, err;
c7e2b968
JP
121
122 if (!nla)
123 return -EINVAL;
124
fceb6435 125 err = nla_parse_nested(tb, TCA_VLAN_MAX, nla, vlan_policy, NULL);
c7e2b968
JP
126 if (err < 0)
127 return err;
128
129 if (!tb[TCA_VLAN_PARMS])
130 return -EINVAL;
131 parm = nla_data(tb[TCA_VLAN_PARMS]);
0190c1d4
VB
132 err = tcf_idr_check_alloc(tn, &parm->index, a, bind);
133 if (err < 0)
134 return err;
135 exists = err;
5026c9b1
JHS
136 if (exists && bind)
137 return 0;
138
c7e2b968
JP
139 switch (parm->v_action) {
140 case TCA_VLAN_ACT_POP:
141 break;
142 case TCA_VLAN_ACT_PUSH:
45a497f2 143 case TCA_VLAN_ACT_MODIFY:
5026c9b1
JHS
144 if (!tb[TCA_VLAN_PUSH_VLAN_ID]) {
145 if (exists)
65a206c0 146 tcf_idr_release(*a, bind);
0190c1d4
VB
147 else
148 tcf_idr_cleanup(tn, parm->index);
c7e2b968 149 return -EINVAL;
5026c9b1 150 }
c7e2b968 151 push_vid = nla_get_u16(tb[TCA_VLAN_PUSH_VLAN_ID]);
5026c9b1
JHS
152 if (push_vid >= VLAN_VID_MASK) {
153 if (exists)
65a206c0 154 tcf_idr_release(*a, bind);
0190c1d4
VB
155 else
156 tcf_idr_cleanup(tn, parm->index);
c7e2b968 157 return -ERANGE;
5026c9b1 158 }
c7e2b968
JP
159
160 if (tb[TCA_VLAN_PUSH_VLAN_PROTOCOL]) {
161 push_proto = nla_get_be16(tb[TCA_VLAN_PUSH_VLAN_PROTOCOL]);
162 switch (push_proto) {
163 case htons(ETH_P_8021Q):
164 case htons(ETH_P_8021AD):
165 break;
166 default:
5a4931ae
DC
167 if (exists)
168 tcf_idr_release(*a, bind);
0190c1d4
VB
169 else
170 tcf_idr_cleanup(tn, parm->index);
c7e2b968
JP
171 return -EPROTONOSUPPORT;
172 }
173 } else {
174 push_proto = htons(ETH_P_8021Q);
175 }
956af371
HHZ
176
177 if (tb[TCA_VLAN_PUSH_VLAN_PRIORITY])
178 push_prio = nla_get_u8(tb[TCA_VLAN_PUSH_VLAN_PRIORITY]);
c7e2b968
JP
179 break;
180 default:
5026c9b1 181 if (exists)
65a206c0 182 tcf_idr_release(*a, bind);
0190c1d4
VB
183 else
184 tcf_idr_cleanup(tn, parm->index);
c7e2b968
JP
185 return -EINVAL;
186 }
187 action = parm->v_action;
188
5026c9b1 189 if (!exists) {
65a206c0 190 ret = tcf_idr_create(tn, parm->index, est, a,
e0496cbb 191 &act_vlan_ops, bind, true);
0190c1d4
VB
192 if (ret) {
193 tcf_idr_cleanup(tn, parm->index);
c7e2b968 194 return ret;
0190c1d4 195 }
c7e2b968
JP
196
197 ret = ACT_P_CREATED;
4e8ddd7f 198 } else if (!ovr) {
65a206c0 199 tcf_idr_release(*a, bind);
4e8ddd7f 200 return -EEXIST;
c7e2b968
JP
201 }
202
a85a970a 203 v = to_vlan(*a);
c7e2b968 204
4c5b9d96
MK
205 p = kzalloc(sizeof(*p), GFP_KERNEL);
206 if (!p) {
4e8ddd7f 207 tcf_idr_release(*a, bind);
4c5b9d96
MK
208 return -ENOMEM;
209 }
c7e2b968 210
4c5b9d96
MK
211 p->tcfv_action = action;
212 p->tcfv_push_vid = push_vid;
213 p->tcfv_push_prio = push_prio;
214 p->tcfv_push_proto = push_proto;
215
653cd284 216 spin_lock_bh(&v->tcf_lock);
764e9a24
VB
217 v->tcf_action = parm->action;
218 rcu_swap_protected(v->vlan_p, p, lockdep_is_held(&v->tcf_lock));
653cd284 219 spin_unlock_bh(&v->tcf_lock);
4c5b9d96 220
764e9a24
VB
221 if (p)
222 kfree_rcu(p, rcu);
c7e2b968
JP
223
224 if (ret == ACT_P_CREATED)
65a206c0 225 tcf_idr_insert(tn, *a);
c7e2b968
JP
226 return ret;
227}
228
9a63b255 229static void tcf_vlan_cleanup(struct tc_action *a)
4c5b9d96
MK
230{
231 struct tcf_vlan *v = to_vlan(a);
232 struct tcf_vlan_params *p;
233
234 p = rcu_dereference_protected(v->vlan_p, 1);
1edf8abe
DC
235 if (p)
236 kfree_rcu(p, rcu);
4c5b9d96
MK
237}
238
c7e2b968
JP
239static int tcf_vlan_dump(struct sk_buff *skb, struct tc_action *a,
240 int bind, int ref)
241{
242 unsigned char *b = skb_tail_pointer(skb);
a85a970a 243 struct tcf_vlan *v = to_vlan(a);
764e9a24 244 struct tcf_vlan_params *p;
c7e2b968
JP
245 struct tc_vlan opt = {
246 .index = v->tcf_index,
036bb443
VB
247 .refcnt = refcount_read(&v->tcf_refcnt) - ref,
248 .bindcnt = atomic_read(&v->tcf_bindcnt) - bind,
c7e2b968
JP
249 };
250 struct tcf_t t;
251
653cd284 252 spin_lock_bh(&v->tcf_lock);
764e9a24
VB
253 opt.action = v->tcf_action;
254 p = rcu_dereference_protected(v->vlan_p, lockdep_is_held(&v->tcf_lock));
255 opt.v_action = p->tcfv_action;
c7e2b968
JP
256 if (nla_put(skb, TCA_VLAN_PARMS, sizeof(opt), &opt))
257 goto nla_put_failure;
258
4c5b9d96
MK
259 if ((p->tcfv_action == TCA_VLAN_ACT_PUSH ||
260 p->tcfv_action == TCA_VLAN_ACT_MODIFY) &&
261 (nla_put_u16(skb, TCA_VLAN_PUSH_VLAN_ID, p->tcfv_push_vid) ||
0b0f43fe 262 nla_put_be16(skb, TCA_VLAN_PUSH_VLAN_PROTOCOL,
4c5b9d96 263 p->tcfv_push_proto) ||
956af371 264 (nla_put_u8(skb, TCA_VLAN_PUSH_VLAN_PRIORITY,
4c5b9d96 265 p->tcfv_push_prio))))
c7e2b968
JP
266 goto nla_put_failure;
267
48d8ee16 268 tcf_tm_dump(&t, &v->tcf_tm);
9854518e 269 if (nla_put_64bit(skb, TCA_VLAN_TM, sizeof(t), &t, TCA_VLAN_PAD))
c7e2b968 270 goto nla_put_failure;
653cd284 271 spin_unlock_bh(&v->tcf_lock);
764e9a24 272
c7e2b968
JP
273 return skb->len;
274
275nla_put_failure:
653cd284 276 spin_unlock_bh(&v->tcf_lock);
c7e2b968
JP
277 nlmsg_trim(skb, b);
278 return -1;
279}
280
ddf97ccd
WC
281static int tcf_vlan_walker(struct net *net, struct sk_buff *skb,
282 struct netlink_callback *cb, int type,
41780105
AA
283 const struct tc_action_ops *ops,
284 struct netlink_ext_ack *extack)
ddf97ccd
WC
285{
286 struct tc_action_net *tn = net_generic(net, vlan_net_id);
287
b3620145 288 return tcf_generic_walker(tn, skb, cb, type, ops, extack);
ddf97ccd
WC
289}
290
f061b48c 291static int tcf_vlan_search(struct net *net, struct tc_action **a, u32 index)
ddf97ccd
WC
292{
293 struct tc_action_net *tn = net_generic(net, vlan_net_id);
294
65a206c0 295 return tcf_idr_search(tn, a, index);
ddf97ccd
WC
296}
297
c7e2b968
JP
298static struct tc_action_ops act_vlan_ops = {
299 .kind = "vlan",
eddd2cf1 300 .id = TCA_ID_VLAN,
c7e2b968 301 .owner = THIS_MODULE,
8aa7f22e 302 .act = tcf_vlan_act,
c7e2b968
JP
303 .dump = tcf_vlan_dump,
304 .init = tcf_vlan_init,
4c5b9d96 305 .cleanup = tcf_vlan_cleanup,
ddf97ccd
WC
306 .walk = tcf_vlan_walker,
307 .lookup = tcf_vlan_search,
a85a970a 308 .size = sizeof(struct tcf_vlan),
ddf97ccd
WC
309};
310
311static __net_init int vlan_init_net(struct net *net)
312{
313 struct tc_action_net *tn = net_generic(net, vlan_net_id);
314
c7e460ce 315 return tc_action_net_init(tn, &act_vlan_ops);
ddf97ccd
WC
316}
317
039af9c6 318static void __net_exit vlan_exit_net(struct list_head *net_list)
ddf97ccd 319{
039af9c6 320 tc_action_net_exit(net_list, vlan_net_id);
ddf97ccd
WC
321}
322
323static struct pernet_operations vlan_net_ops = {
324 .init = vlan_init_net,
039af9c6 325 .exit_batch = vlan_exit_net,
ddf97ccd
WC
326 .id = &vlan_net_id,
327 .size = sizeof(struct tc_action_net),
c7e2b968
JP
328};
329
330static int __init vlan_init_module(void)
331{
ddf97ccd 332 return tcf_register_action(&act_vlan_ops, &vlan_net_ops);
c7e2b968
JP
333}
334
335static void __exit vlan_cleanup_module(void)
336{
ddf97ccd 337 tcf_unregister_action(&act_vlan_ops, &vlan_net_ops);
c7e2b968
JP
338}
339
340module_init(vlan_init_module);
341module_exit(vlan_cleanup_module);
342
343MODULE_AUTHOR("Jiri Pirko <jiri@resnulli.us>");
344MODULE_DESCRIPTION("vlan manipulation actions");
345MODULE_LICENSE("GPL v2");