[NET]: Modify all rtnetlink methods to only work in the initial namespace (v2)
[deliverable/linux.git] / net / sched / cls_api.c
CommitLineData
1da177e4
LT
1/*
2 * net/sched/cls_api.c Packet classifier API.
3 *
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version
7 * 2 of the License, or (at your option) any later version.
8 *
9 * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
10 *
11 * Changes:
12 *
13 * Eduardo J. Blanco <ejbs@netlabs.com.uy> :990222: kmod support
14 *
15 */
16
1da177e4
LT
17#include <linux/module.h>
18#include <linux/types.h>
19#include <linux/kernel.h>
1da177e4 20#include <linux/string.h>
1da177e4 21#include <linux/errno.h>
1da177e4 22#include <linux/skbuff.h>
1da177e4
LT
23#include <linux/init.h>
24#include <linux/kmod.h>
dc5fc579 25#include <linux/netlink.h>
b854272b
DL
26#include <net/net_namespace.h>
27#include <net/sock.h>
dc5fc579 28#include <net/netlink.h>
1da177e4
LT
29#include <net/pkt_sched.h>
30#include <net/pkt_cls.h>
31
32#if 0 /* control */
33#define DPRINTK(format,args...) printk(KERN_DEBUG format,##args)
34#else
35#define DPRINTK(format,args...)
36#endif
37
38/* The list of all installed classifier types */
39
40static struct tcf_proto_ops *tcf_proto_base;
41
42/* Protects list of registered TC modules. It is pure SMP lock. */
43static DEFINE_RWLOCK(cls_mod_lock);
44
45/* Find classifier type by string name */
46
47static struct tcf_proto_ops * tcf_proto_lookup_ops(struct rtattr *kind)
48{
49 struct tcf_proto_ops *t = NULL;
50
51 if (kind) {
52 read_lock(&cls_mod_lock);
53 for (t = tcf_proto_base; t; t = t->next) {
54 if (rtattr_strcmp(kind, t->kind) == 0) {
55 if (!try_module_get(t->owner))
56 t = NULL;
57 break;
58 }
59 }
60 read_unlock(&cls_mod_lock);
61 }
62 return t;
63}
64
65/* Register(unregister) new classifier type */
66
67int register_tcf_proto_ops(struct tcf_proto_ops *ops)
68{
69 struct tcf_proto_ops *t, **tp;
70 int rc = -EEXIST;
71
72 write_lock(&cls_mod_lock);
73 for (tp = &tcf_proto_base; (t = *tp) != NULL; tp = &t->next)
74 if (!strcmp(ops->kind, t->kind))
75 goto out;
76
77 ops->next = NULL;
78 *tp = ops;
79 rc = 0;
80out:
81 write_unlock(&cls_mod_lock);
82 return rc;
83}
84
85int unregister_tcf_proto_ops(struct tcf_proto_ops *ops)
86{
87 struct tcf_proto_ops *t, **tp;
88 int rc = -ENOENT;
89
90 write_lock(&cls_mod_lock);
91 for (tp = &tcf_proto_base; (t=*tp) != NULL; tp = &t->next)
92 if (t == ops)
93 break;
94
95 if (!t)
96 goto out;
97 *tp = t->next;
98 rc = 0;
99out:
100 write_unlock(&cls_mod_lock);
101 return rc;
102}
103
104static int tfilter_notify(struct sk_buff *oskb, struct nlmsghdr *n,
105 struct tcf_proto *tp, unsigned long fh, int event);
106
107
108/* Select new prio value from the range, managed by kernel. */
109
110static __inline__ u32 tcf_auto_prio(struct tcf_proto *tp)
111{
112 u32 first = TC_H_MAKE(0xC0000000U,0U);
113
114 if (tp)
115 first = tp->prio-1;
116
117 return first;
118}
119
120/* Add/change/delete/get a filter node */
121
122static int tc_ctl_tfilter(struct sk_buff *skb, struct nlmsghdr *n, void *arg)
123{
b854272b 124 struct net *net = skb->sk->sk_net;
1da177e4
LT
125 struct rtattr **tca;
126 struct tcmsg *t;
127 u32 protocol;
128 u32 prio;
129 u32 nprio;
130 u32 parent;
131 struct net_device *dev;
132 struct Qdisc *q;
133 struct tcf_proto **back, **chain;
134 struct tcf_proto *tp;
135 struct tcf_proto_ops *tp_ops;
20fea08b 136 const struct Qdisc_class_ops *cops;
1da177e4
LT
137 unsigned long cl;
138 unsigned long fh;
139 int err;
140
b854272b
DL
141 if (net != &init_net)
142 return -EINVAL;
143
1da177e4
LT
144replay:
145 tca = arg;
146 t = NLMSG_DATA(n);
147 protocol = TC_H_MIN(t->tcm_info);
148 prio = TC_H_MAJ(t->tcm_info);
149 nprio = prio;
150 parent = t->tcm_parent;
151 cl = 0;
152
153 if (prio == 0) {
154 /* If no priority is given, user wants we allocated it. */
155 if (n->nlmsg_type != RTM_NEWTFILTER || !(n->nlmsg_flags&NLM_F_CREATE))
156 return -ENOENT;
157 prio = TC_H_MAKE(0x80000000U,0U);
158 }
159
160 /* Find head of filter chain. */
161
162 /* Find link */
881d966b 163 if ((dev = __dev_get_by_index(&init_net, t->tcm_ifindex)) == NULL)
1da177e4
LT
164 return -ENODEV;
165
166 /* Find qdisc */
167 if (!parent) {
168 q = dev->qdisc_sleeping;
169 parent = q->handle;
170 } else if ((q = qdisc_lookup(dev, TC_H_MAJ(t->tcm_parent))) == NULL)
171 return -EINVAL;
172
173 /* Is it classful? */
174 if ((cops = q->ops->cl_ops) == NULL)
175 return -EINVAL;
176
177 /* Do we search for filter, attached to class? */
178 if (TC_H_MIN(parent)) {
179 cl = cops->get(q, parent);
180 if (cl == 0)
181 return -ENOENT;
182 }
183
184 /* And the last stroke */
185 chain = cops->tcf_chain(q, cl);
186 err = -EINVAL;
187 if (chain == NULL)
188 goto errout;
189
190 /* Check the chain for existence of proto-tcf with this priority */
191 for (back = chain; (tp=*back) != NULL; back = &tp->next) {
192 if (tp->prio >= prio) {
193 if (tp->prio == prio) {
194 if (!nprio || (tp->protocol != protocol && protocol))
195 goto errout;
196 } else
197 tp = NULL;
198 break;
199 }
200 }
201
202 if (tp == NULL) {
203 /* Proto-tcf does not exist, create new one */
204
205 if (tca[TCA_KIND-1] == NULL || !protocol)
206 goto errout;
207
208 err = -ENOENT;
209 if (n->nlmsg_type != RTM_NEWTFILTER || !(n->nlmsg_flags&NLM_F_CREATE))
210 goto errout;
211
212
213 /* Create new proto tcf */
214
215 err = -ENOBUFS;
c7b1b249 216 if ((tp = kzalloc(sizeof(*tp), GFP_KERNEL)) == NULL)
1da177e4
LT
217 goto errout;
218 err = -EINVAL;
219 tp_ops = tcf_proto_lookup_ops(tca[TCA_KIND-1]);
220 if (tp_ops == NULL) {
221#ifdef CONFIG_KMOD
222 struct rtattr *kind = tca[TCA_KIND-1];
223 char name[IFNAMSIZ];
224
225 if (kind != NULL &&
226 rtattr_strlcpy(name, kind, IFNAMSIZ) < IFNAMSIZ) {
227 rtnl_unlock();
228 request_module("cls_%s", name);
229 rtnl_lock();
230 tp_ops = tcf_proto_lookup_ops(kind);
231 /* We dropped the RTNL semaphore in order to
232 * perform the module load. So, even if we
233 * succeeded in loading the module we have to
234 * replay the request. We indicate this using
235 * -EAGAIN.
236 */
237 if (tp_ops != NULL) {
238 module_put(tp_ops->owner);
239 err = -EAGAIN;
240 }
241 }
242#endif
243 kfree(tp);
244 goto errout;
245 }
1da177e4
LT
246 tp->ops = tp_ops;
247 tp->protocol = protocol;
248 tp->prio = nprio ? : tcf_auto_prio(*back);
249 tp->q = q;
250 tp->classify = tp_ops->classify;
251 tp->classid = parent;
252 if ((err = tp_ops->init(tp)) != 0) {
253 module_put(tp_ops->owner);
254 kfree(tp);
255 goto errout;
256 }
257
258 qdisc_lock_tree(dev);
259 tp->next = *back;
260 *back = tp;
261 qdisc_unlock_tree(dev);
262
263 } else if (tca[TCA_KIND-1] && rtattr_strcmp(tca[TCA_KIND-1], tp->ops->kind))
264 goto errout;
265
266 fh = tp->ops->get(tp, t->tcm_handle);
267
268 if (fh == 0) {
269 if (n->nlmsg_type == RTM_DELTFILTER && t->tcm_handle == 0) {
270 qdisc_lock_tree(dev);
271 *back = tp->next;
272 qdisc_unlock_tree(dev);
273
274 tfilter_notify(skb, n, tp, fh, RTM_DELTFILTER);
275 tcf_destroy(tp);
276 err = 0;
277 goto errout;
278 }
279
280 err = -ENOENT;
281 if (n->nlmsg_type != RTM_NEWTFILTER || !(n->nlmsg_flags&NLM_F_CREATE))
282 goto errout;
283 } else {
284 switch (n->nlmsg_type) {
10297b99 285 case RTM_NEWTFILTER:
1da177e4
LT
286 err = -EEXIST;
287 if (n->nlmsg_flags&NLM_F_EXCL)
288 goto errout;
289 break;
290 case RTM_DELTFILTER:
291 err = tp->ops->delete(tp, fh);
292 if (err == 0)
293 tfilter_notify(skb, n, tp, fh, RTM_DELTFILTER);
294 goto errout;
295 case RTM_GETTFILTER:
296 err = tfilter_notify(skb, n, tp, fh, RTM_NEWTFILTER);
297 goto errout;
298 default:
299 err = -EINVAL;
300 goto errout;
301 }
302 }
303
304 err = tp->ops->change(tp, cl, t->tcm_handle, tca, &fh);
305 if (err == 0)
306 tfilter_notify(skb, n, tp, fh, RTM_NEWTFILTER);
307
308errout:
309 if (cl)
310 cops->put(q, cl);
311 if (err == -EAGAIN)
312 /* Replay the request. */
313 goto replay;
314 return err;
315}
316
317static int
318tcf_fill_node(struct sk_buff *skb, struct tcf_proto *tp, unsigned long fh,
e431b8c0 319 u32 pid, u32 seq, u16 flags, int event)
1da177e4
LT
320{
321 struct tcmsg *tcm;
322 struct nlmsghdr *nlh;
27a884dc 323 unsigned char *b = skb_tail_pointer(skb);
1da177e4 324
e431b8c0 325 nlh = NLMSG_NEW(skb, pid, seq, event, sizeof(*tcm), flags);
1da177e4
LT
326 tcm = NLMSG_DATA(nlh);
327 tcm->tcm_family = AF_UNSPEC;
9ef1d4c7
PM
328 tcm->tcm__pad1 = 0;
329 tcm->tcm__pad1 = 0;
1da177e4
LT
330 tcm->tcm_ifindex = tp->q->dev->ifindex;
331 tcm->tcm_parent = tp->classid;
332 tcm->tcm_info = TC_H_MAKE(tp->prio, tp->protocol);
333 RTA_PUT(skb, TCA_KIND, IFNAMSIZ, tp->ops->kind);
334 tcm->tcm_handle = fh;
335 if (RTM_DELTFILTER != event) {
336 tcm->tcm_handle = 0;
337 if (tp->ops->dump && tp->ops->dump(tp, fh, skb, tcm) < 0)
338 goto rtattr_failure;
339 }
27a884dc 340 nlh->nlmsg_len = skb_tail_pointer(skb) - b;
1da177e4
LT
341 return skb->len;
342
343nlmsg_failure:
344rtattr_failure:
dc5fc579 345 nlmsg_trim(skb, b);
1da177e4
LT
346 return -1;
347}
348
349static int tfilter_notify(struct sk_buff *oskb, struct nlmsghdr *n,
350 struct tcf_proto *tp, unsigned long fh, int event)
351{
352 struct sk_buff *skb;
353 u32 pid = oskb ? NETLINK_CB(oskb).pid : 0;
354
355 skb = alloc_skb(NLMSG_GOODSIZE, GFP_KERNEL);
356 if (!skb)
357 return -ENOBUFS;
358
359 if (tcf_fill_node(skb, tp, fh, pid, n->nlmsg_seq, 0, event) <= 0) {
360 kfree_skb(skb);
361 return -EINVAL;
362 }
363
ac6d439d 364 return rtnetlink_send(skb, pid, RTNLGRP_TC, n->nlmsg_flags&NLM_F_ECHO);
1da177e4
LT
365}
366
367struct tcf_dump_args
368{
369 struct tcf_walker w;
370 struct sk_buff *skb;
371 struct netlink_callback *cb;
372};
373
374static int tcf_node_dump(struct tcf_proto *tp, unsigned long n, struct tcf_walker *arg)
375{
376 struct tcf_dump_args *a = (void*)arg;
377
378 return tcf_fill_node(a->skb, tp, n, NETLINK_CB(a->cb->skb).pid,
379 a->cb->nlh->nlmsg_seq, NLM_F_MULTI, RTM_NEWTFILTER);
380}
381
382static int tc_dump_tfilter(struct sk_buff *skb, struct netlink_callback *cb)
383{
b854272b 384 struct net *net = skb->sk->sk_net;
1da177e4
LT
385 int t;
386 int s_t;
387 struct net_device *dev;
388 struct Qdisc *q;
389 struct tcf_proto *tp, **chain;
390 struct tcmsg *tcm = (struct tcmsg*)NLMSG_DATA(cb->nlh);
391 unsigned long cl = 0;
20fea08b 392 const struct Qdisc_class_ops *cops;
1da177e4
LT
393 struct tcf_dump_args arg;
394
b854272b
DL
395 if (net != &init_net)
396 return 0;
397
1da177e4
LT
398 if (cb->nlh->nlmsg_len < NLMSG_LENGTH(sizeof(*tcm)))
399 return skb->len;
881d966b 400 if ((dev = dev_get_by_index(&init_net, tcm->tcm_ifindex)) == NULL)
1da177e4
LT
401 return skb->len;
402
1da177e4
LT
403 if (!tcm->tcm_parent)
404 q = dev->qdisc_sleeping;
405 else
406 q = qdisc_lookup(dev, TC_H_MAJ(tcm->tcm_parent));
407 if (!q)
408 goto out;
409 if ((cops = q->ops->cl_ops) == NULL)
410 goto errout;
411 if (TC_H_MIN(tcm->tcm_parent)) {
412 cl = cops->get(q, tcm->tcm_parent);
413 if (cl == 0)
414 goto errout;
415 }
416 chain = cops->tcf_chain(q, cl);
417 if (chain == NULL)
418 goto errout;
419
420 s_t = cb->args[0];
421
422 for (tp=*chain, t=0; tp; tp = tp->next, t++) {
423 if (t < s_t) continue;
424 if (TC_H_MAJ(tcm->tcm_info) &&
425 TC_H_MAJ(tcm->tcm_info) != tp->prio)
426 continue;
427 if (TC_H_MIN(tcm->tcm_info) &&
428 TC_H_MIN(tcm->tcm_info) != tp->protocol)
429 continue;
430 if (t > s_t)
431 memset(&cb->args[1], 0, sizeof(cb->args)-sizeof(cb->args[0]));
432 if (cb->args[1] == 0) {
433 if (tcf_fill_node(skb, tp, 0, NETLINK_CB(cb->skb).pid,
434 cb->nlh->nlmsg_seq, NLM_F_MULTI, RTM_NEWTFILTER) <= 0) {
435 break;
436 }
437 cb->args[1] = 1;
438 }
439 if (tp->ops->walk == NULL)
440 continue;
441 arg.w.fn = tcf_node_dump;
442 arg.skb = skb;
443 arg.cb = cb;
444 arg.w.stop = 0;
445 arg.w.skip = cb->args[1]-1;
446 arg.w.count = 0;
447 tp->ops->walk(tp, &arg.w);
448 cb->args[1] = arg.w.count+1;
449 if (arg.w.stop)
450 break;
451 }
452
453 cb->args[0] = t;
454
455errout:
456 if (cl)
457 cops->put(q, cl);
458out:
1da177e4
LT
459 dev_put(dev);
460 return skb->len;
461}
462
463void
464tcf_exts_destroy(struct tcf_proto *tp, struct tcf_exts *exts)
465{
466#ifdef CONFIG_NET_CLS_ACT
467 if (exts->action) {
468 tcf_action_destroy(exts->action, TCA_ACT_UNBIND);
469 exts->action = NULL;
470 }
1da177e4
LT
471#endif
472}
473
474
475int
476tcf_exts_validate(struct tcf_proto *tp, struct rtattr **tb,
10297b99
YH
477 struct rtattr *rate_tlv, struct tcf_exts *exts,
478 struct tcf_ext_map *map)
1da177e4
LT
479{
480 memset(exts, 0, sizeof(*exts));
10297b99 481
1da177e4
LT
482#ifdef CONFIG_NET_CLS_ACT
483 {
484 int err;
485 struct tc_action *act;
486
487 if (map->police && tb[map->police-1]) {
488 act = tcf_action_init_1(tb[map->police-1], rate_tlv, "police",
489 TCA_ACT_NOREPLACE, TCA_ACT_BIND, &err);
490 if (act == NULL)
491 return err;
492
493 act->type = TCA_OLD_COMPAT;
494 exts->action = act;
495 } else if (map->action && tb[map->action-1]) {
496 act = tcf_action_init(tb[map->action-1], rate_tlv, NULL,
497 TCA_ACT_NOREPLACE, TCA_ACT_BIND, &err);
498 if (act == NULL)
499 return err;
500
501 exts->action = act;
502 }
503 }
1da177e4
LT
504#else
505 if ((map->action && tb[map->action-1]) ||
506 (map->police && tb[map->police-1]))
507 return -EOPNOTSUPP;
508#endif
509
510 return 0;
511}
512
513void
514tcf_exts_change(struct tcf_proto *tp, struct tcf_exts *dst,
10297b99 515 struct tcf_exts *src)
1da177e4
LT
516{
517#ifdef CONFIG_NET_CLS_ACT
518 if (src->action) {
519 struct tc_action *act;
520 tcf_tree_lock(tp);
521 act = xchg(&dst->action, src->action);
522 tcf_tree_unlock(tp);
523 if (act)
524 tcf_action_destroy(act, TCA_ACT_UNBIND);
525 }
1da177e4
LT
526#endif
527}
528
529int
530tcf_exts_dump(struct sk_buff *skb, struct tcf_exts *exts,
531 struct tcf_ext_map *map)
532{
533#ifdef CONFIG_NET_CLS_ACT
534 if (map->action && exts->action) {
535 /*
536 * again for backward compatible mode - we want
537 * to work with both old and new modes of entering
538 * tc data even if iproute2 was newer - jhs
539 */
27a884dc 540 struct rtattr *p_rta = (struct rtattr *)skb_tail_pointer(skb);
1da177e4
LT
541
542 if (exts->action->type != TCA_OLD_COMPAT) {
543 RTA_PUT(skb, map->action, 0, NULL);
544 if (tcf_action_dump(skb, exts->action, 0, 0) < 0)
545 goto rtattr_failure;
27a884dc 546 p_rta->rta_len = skb_tail_pointer(skb) - (u8 *)p_rta;
1da177e4
LT
547 } else if (map->police) {
548 RTA_PUT(skb, map->police, 0, NULL);
549 if (tcf_action_dump_old(skb, exts->action, 0, 0) < 0)
550 goto rtattr_failure;
27a884dc 551 p_rta->rta_len = skb_tail_pointer(skb) - (u8 *)p_rta;
1da177e4
LT
552 }
553 }
1da177e4
LT
554#endif
555 return 0;
556rtattr_failure: __attribute__ ((unused))
557 return -1;
558}
559
560int
561tcf_exts_dump_stats(struct sk_buff *skb, struct tcf_exts *exts,
10297b99 562 struct tcf_ext_map *map)
1da177e4
LT
563{
564#ifdef CONFIG_NET_CLS_ACT
565 if (exts->action)
566 if (tcf_action_copy_stats(skb, exts->action, 1) < 0)
567 goto rtattr_failure;
1da177e4
LT
568#endif
569 return 0;
570rtattr_failure: __attribute__ ((unused))
571 return -1;
572}
573
574static int __init tc_filter_init(void)
575{
82623c0d
TG
576 rtnl_register(PF_UNSPEC, RTM_NEWTFILTER, tc_ctl_tfilter, NULL);
577 rtnl_register(PF_UNSPEC, RTM_DELTFILTER, tc_ctl_tfilter, NULL);
578 rtnl_register(PF_UNSPEC, RTM_GETTFILTER, tc_ctl_tfilter,
579 tc_dump_tfilter);
1da177e4 580
1da177e4
LT
581 return 0;
582}
583
584subsys_initcall(tc_filter_init);
585
586EXPORT_SYMBOL(register_tcf_proto_ops);
587EXPORT_SYMBOL(unregister_tcf_proto_ops);
588EXPORT_SYMBOL(tcf_exts_validate);
589EXPORT_SYMBOL(tcf_exts_destroy);
590EXPORT_SYMBOL(tcf_exts_change);
591EXPORT_SYMBOL(tcf_exts_dump);
592EXPORT_SYMBOL(tcf_exts_dump_stats);
This page took 0.330614 seconds and 5 git commands to generate.