]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
bpf/bpf_get,set_sockopt: add option to set TCP-BPF sock ops flags
authorAlan Maguire <alan.maguire@oracle.com>
Thu, 8 Aug 2024 15:05:57 +0000 (16:05 +0100)
committerMartin KaFai Lau <martin.lau@kernel.org>
Thu, 8 Aug 2024 23:52:43 +0000 (16:52 -0700)
Currently the only opportunity to set sock ops flags dictating
which callbacks fire for a socket is from within a TCP-BPF sockops
program.  This is problematic if the connection is already set up
as there is no further chance to specify callbacks for that socket.
Add TCP_BPF_SOCK_OPS_CB_FLAGS to bpf_setsockopt() and bpf_getsockopt()
to allow users to specify callbacks later, either via an iterator
over sockets or via a socket-specific program triggered by a
setsockopt() on the socket.

Previous discussion on this here [1].

[1] https://lore.kernel.org/bpf/f42f157b-6e52-dd4d-3d97-9b86c84c0b00@oracle.com/

Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
Link: https://lore.kernel.org/r/20240808150558.1035626-2-alan.maguire@oracle.com
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
include/uapi/linux/bpf.h
net/core/filter.c
tools/include/uapi/linux/bpf.h

index 35bcf52dbc6526469a933f67af8a2374cad88f50..e05b39e39c3f9d77aa3ec00f1a726adcde5e4621 100644 (file)
@@ -2851,7 +2851,7 @@ union bpf_attr {
  *               **TCP_SYNCNT**, **TCP_USER_TIMEOUT**, **TCP_NOTSENT_LOWAT**,
  *               **TCP_NODELAY**, **TCP_MAXSEG**, **TCP_WINDOW_CLAMP**,
  *               **TCP_THIN_LINEAR_TIMEOUTS**, **TCP_BPF_DELACK_MAX**,
- *               **TCP_BPF_RTO_MIN**.
+ *               **TCP_BPF_RTO_MIN**, **TCP_BPF_SOCK_OPS_CB_FLAGS**.
  *             * **IPPROTO_IP**, which supports *optname* **IP_TOS**.
  *             * **IPPROTO_IPV6**, which supports the following *optname*\ s:
  *               **IPV6_TCLASS**, **IPV6_AUTOFLOWLABEL**.
@@ -7080,6 +7080,7 @@ enum {
        TCP_BPF_SYN             = 1005, /* Copy the TCP header */
        TCP_BPF_SYN_IP          = 1006, /* Copy the IP[46] and TCP header */
        TCP_BPF_SYN_MAC         = 1007, /* Copy the MAC, IP[46], and TCP header */
+       TCP_BPF_SOCK_OPS_CB_FLAGS = 1008, /* Get or Set TCP sock ops flags */
 };
 
 enum {
index f3c72cf86099745ee8eb56f56711db92e6bfc84e..d96a50f3f0166101d836c5841ce7584075cf5a92 100644 (file)
@@ -5278,6 +5278,11 @@ static int bpf_sol_tcp_setsockopt(struct sock *sk, int optname,
                        return -EINVAL;
                inet_csk(sk)->icsk_rto_min = timeout;
                break;
+       case TCP_BPF_SOCK_OPS_CB_FLAGS:
+               if (val & ~(BPF_SOCK_OPS_ALL_CB_FLAGS))
+                       return -EINVAL;
+               tp->bpf_sock_ops_cb_flags = val;
+               break;
        default:
                return -EINVAL;
        }
@@ -5366,6 +5371,17 @@ static int sol_tcp_sockopt(struct sock *sk, int optname,
                if (*optlen < 1)
                        return -EINVAL;
                break;
+       case TCP_BPF_SOCK_OPS_CB_FLAGS:
+               if (*optlen != sizeof(int))
+                       return -EINVAL;
+               if (getopt) {
+                       struct tcp_sock *tp = tcp_sk(sk);
+                       int cb_flags = tp->bpf_sock_ops_cb_flags;
+
+                       memcpy(optval, &cb_flags, *optlen);
+                       return 0;
+               }
+               return bpf_sol_tcp_setsockopt(sk, optname, optval, *optlen);
        default:
                if (getopt)
                        return -EINVAL;
index 35bcf52dbc6526469a933f67af8a2374cad88f50..e05b39e39c3f9d77aa3ec00f1a726adcde5e4621 100644 (file)
@@ -2851,7 +2851,7 @@ union bpf_attr {
  *               **TCP_SYNCNT**, **TCP_USER_TIMEOUT**, **TCP_NOTSENT_LOWAT**,
  *               **TCP_NODELAY**, **TCP_MAXSEG**, **TCP_WINDOW_CLAMP**,
  *               **TCP_THIN_LINEAR_TIMEOUTS**, **TCP_BPF_DELACK_MAX**,
- *               **TCP_BPF_RTO_MIN**.
+ *               **TCP_BPF_RTO_MIN**, **TCP_BPF_SOCK_OPS_CB_FLAGS**.
  *             * **IPPROTO_IP**, which supports *optname* **IP_TOS**.
  *             * **IPPROTO_IPV6**, which supports the following *optname*\ s:
  *               **IPV6_TCLASS**, **IPV6_AUTOFLOWLABEL**.
@@ -7080,6 +7080,7 @@ enum {
        TCP_BPF_SYN             = 1005, /* Copy the TCP header */
        TCP_BPF_SYN_IP          = 1006, /* Copy the IP[46] and TCP header */
        TCP_BPF_SYN_MAC         = 1007, /* Copy the MAC, IP[46], and TCP header */
+       TCP_BPF_SOCK_OPS_CB_FLAGS = 1008, /* Get or Set TCP sock ops flags */
 };
 
 enum {