| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 1 | /* net/sched/sch_ingress.c - Ingress qdisc | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 2 |  *              This program is free software; you can redistribute it and/or | 
 | 3 |  *              modify it under the terms of the GNU General Public License | 
 | 4 |  *              as published by the Free Software Foundation; either version | 
 | 5 |  *              2 of the License, or (at your option) any later version. | 
 | 6 |  * | 
 | 7 |  * Authors:     Jamal Hadi Salim 1999 | 
 | 8 |  */ | 
 | 9 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 10 | #include <linux/module.h> | 
 | 11 | #include <linux/types.h> | 
| Patrick McHardy | 0ba4805 | 2007-07-02 22:49:07 -0700 | [diff] [blame] | 12 | #include <linux/list.h> | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 13 | #include <linux/skbuff.h> | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 14 | #include <linux/rtnetlink.h> | 
 | 15 | #include <linux/netfilter_ipv4.h> | 
 | 16 | #include <linux/netfilter_ipv6.h> | 
 | 17 | #include <linux/netfilter.h> | 
| Arnaldo Carvalho de Melo | dc5fc57 | 2007-03-25 23:06:12 -0700 | [diff] [blame] | 18 | #include <net/netlink.h> | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 19 | #include <net/pkt_sched.h> | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 20 |  | 
 | 21 |  | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 22 | /* Thanks to Doron Oz for this hack */ | 
| Patrick McHardy | 1389356 | 2008-01-21 00:13:44 -0800 | [diff] [blame] | 23 | #if !defined(CONFIG_NET_CLS_ACT) && defined(CONFIG_NETFILTER) | 
| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 24 | static int nf_registered; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 25 | #endif | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 26 |  | 
 | 27 | struct ingress_qdisc_data { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 28 | 	struct tcf_proto	*filter_list; | 
 | 29 | }; | 
 | 30 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 31 | /* ------------------------- Class/flow operations ------------------------- */ | 
 | 32 |  | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 33 | static int ingress_graft(struct Qdisc *sch, unsigned long arg, | 
 | 34 | 			 struct Qdisc *new, struct Qdisc **old) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 35 | { | 
| Patrick McHardy | e037834 | 2008-01-21 00:12:32 -0800 | [diff] [blame] | 36 | 	return -EOPNOTSUPP; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 37 | } | 
 | 38 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 39 | static struct Qdisc *ingress_leaf(struct Qdisc *sch, unsigned long arg) | 
 | 40 | { | 
 | 41 | 	return NULL; | 
 | 42 | } | 
 | 43 |  | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 44 | static unsigned long ingress_get(struct Qdisc *sch, u32 classid) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 45 | { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 46 | 	return TC_H_MIN(classid) + 1; | 
 | 47 | } | 
 | 48 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 49 | static unsigned long ingress_bind_filter(struct Qdisc *sch, | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 50 | 					 unsigned long parent, u32 classid) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 51 | { | 
 | 52 | 	return ingress_get(sch, classid); | 
 | 53 | } | 
 | 54 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 55 | static void ingress_put(struct Qdisc *sch, unsigned long cl) | 
 | 56 | { | 
 | 57 | } | 
 | 58 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 59 | static int ingress_change(struct Qdisc *sch, u32 classid, u32 parent, | 
| Patrick McHardy | 1e90474 | 2008-01-22 22:11:17 -0800 | [diff] [blame] | 60 | 			  struct nlattr **tca, unsigned long *arg) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 61 | { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 62 | 	return 0; | 
 | 63 | } | 
 | 64 |  | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 65 | static void ingress_walk(struct Qdisc *sch, struct qdisc_walker *walker) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 66 | { | 
| Patrick McHardy | a478122 | 2008-01-21 00:11:21 -0800 | [diff] [blame] | 67 | 	return; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 68 | } | 
 | 69 |  | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 70 | static struct tcf_proto **ingress_find_tcf(struct Qdisc *sch, unsigned long cl) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 71 | { | 
| Patrick McHardy | cb53c04 | 2008-01-21 00:11:48 -0800 | [diff] [blame] | 72 | 	struct ingress_qdisc_data *p = qdisc_priv(sch); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 73 |  | 
 | 74 | 	return &p->filter_list; | 
 | 75 | } | 
 | 76 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 77 | /* --------------------------- Qdisc operations ---------------------------- */ | 
 | 78 |  | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 79 | static int ingress_enqueue(struct sk_buff *skb, struct Qdisc *sch) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 80 | { | 
| Patrick McHardy | cb53c04 | 2008-01-21 00:11:48 -0800 | [diff] [blame] | 81 | 	struct ingress_qdisc_data *p = qdisc_priv(sch); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 82 | 	struct tcf_result res; | 
 | 83 | 	int result; | 
 | 84 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 85 | 	result = tc_classify(skb, p->filter_list, &res); | 
| Patrick McHardy | a478122 | 2008-01-21 00:11:21 -0800 | [diff] [blame] | 86 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 87 | 	/* | 
 | 88 | 	 * Unlike normal "enqueue" functions, ingress_enqueue returns a | 
 | 89 | 	 * firewall FW_* code. | 
 | 90 | 	 */ | 
 | 91 | #ifdef CONFIG_NET_CLS_ACT | 
 | 92 | 	sch->bstats.packets++; | 
 | 93 | 	sch->bstats.bytes += skb->len; | 
 | 94 | 	switch (result) { | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 95 | 	case TC_ACT_SHOT: | 
 | 96 | 		result = TC_ACT_SHOT; | 
 | 97 | 		sch->qstats.drops++; | 
 | 98 | 		break; | 
 | 99 | 	case TC_ACT_STOLEN: | 
 | 100 | 	case TC_ACT_QUEUED: | 
 | 101 | 		result = TC_ACT_STOLEN; | 
 | 102 | 		break; | 
 | 103 | 	case TC_ACT_RECLASSIFY: | 
 | 104 | 	case TC_ACT_OK: | 
 | 105 | 		skb->tc_index = TC_H_MIN(res.classid); | 
 | 106 | 	default: | 
 | 107 | 		result = TC_ACT_OK; | 
 | 108 | 		break; | 
| Stephen Hemminger | 3ff50b7 | 2007-04-20 17:09:22 -0700 | [diff] [blame] | 109 | 	} | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 110 | #else | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 111 | 	result = NF_ACCEPT; | 
 | 112 | 	sch->bstats.packets++; | 
 | 113 | 	sch->bstats.bytes += skb->len; | 
 | 114 | #endif | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 115 |  | 
 | 116 | 	return result; | 
 | 117 | } | 
 | 118 |  | 
| Patrick McHardy | 1389356 | 2008-01-21 00:13:44 -0800 | [diff] [blame] | 119 | #if !defined(CONFIG_NET_CLS_ACT) && defined(CONFIG_NETFILTER) | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 120 | static unsigned int ing_hook(unsigned int hook, struct sk_buff *skb, | 
| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 121 | 			     const struct net_device *indev, | 
 | 122 | 			     const struct net_device *outdev, | 
 | 123 | 			     int (*okfn)(struct sk_buff *)) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 124 | { | 
| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 125 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 126 | 	struct Qdisc *q; | 
| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 127 | 	struct net_device *dev = skb->dev; | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 128 | 	int fwres = NF_ACCEPT; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 129 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 130 | 	if (dev->qdisc_ingress) { | 
| Patrick McHardy | fd44de7 | 2007-04-16 17:07:08 -0700 | [diff] [blame] | 131 | 		spin_lock(&dev->ingress_lock); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 132 | 		if ((q = dev->qdisc_ingress) != NULL) | 
 | 133 | 			fwres = q->enqueue(skb, q); | 
| Patrick McHardy | fd44de7 | 2007-04-16 17:07:08 -0700 | [diff] [blame] | 134 | 		spin_unlock(&dev->ingress_lock); | 
| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 135 | 	} | 
 | 136 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 137 | 	return fwres; | 
 | 138 | } | 
 | 139 |  | 
 | 140 | /* after ipt_filter */ | 
| Patrick McHardy | 1999414 | 2007-12-05 01:23:00 -0800 | [diff] [blame] | 141 | static struct nf_hook_ops ing_ops[] __read_mostly = { | 
| Patrick McHardy | 41c5b31 | 2007-12-05 01:22:43 -0800 | [diff] [blame] | 142 | 	{ | 
 | 143 | 		.hook           = ing_hook, | 
 | 144 | 		.owner		= THIS_MODULE, | 
 | 145 | 		.pf             = PF_INET, | 
 | 146 | 		.hooknum        = NF_INET_PRE_ROUTING, | 
 | 147 | 		.priority       = NF_IP_PRI_FILTER + 1, | 
 | 148 | 	}, | 
 | 149 | 	{ | 
 | 150 | 		.hook           = ing_hook, | 
 | 151 | 		.owner		= THIS_MODULE, | 
 | 152 | 		.pf             = PF_INET6, | 
 | 153 | 		.hooknum        = NF_INET_PRE_ROUTING, | 
 | 154 | 		.priority       = NF_IP6_PRI_FILTER + 1, | 
 | 155 | 	}, | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 156 | }; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 157 | #endif | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 158 |  | 
| Patrick McHardy | 1e90474 | 2008-01-22 22:11:17 -0800 | [diff] [blame] | 159 | static int ingress_init(struct Qdisc *sch, struct nlattr *opt) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 160 | { | 
| Patrick McHardy | 1389356 | 2008-01-21 00:13:44 -0800 | [diff] [blame] | 161 | #if !defined(CONFIG_NET_CLS_ACT) && defined(CONFIG_NETFILTER) | 
| Patrick McHardy | 645a1e3 | 2008-01-21 00:13:19 -0800 | [diff] [blame] | 162 | 	printk("Ingress scheduler: Classifier actions prefered over netfilter\n"); | 
 | 163 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 164 | 	if (!nf_registered) { | 
| Patrick McHardy | 41c5b31 | 2007-12-05 01:22:43 -0800 | [diff] [blame] | 165 | 		if (nf_register_hooks(ing_ops, ARRAY_SIZE(ing_ops)) < 0) { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 166 | 			printk("ingress qdisc registration error \n"); | 
 | 167 | 			return -EINVAL; | 
 | 168 | 		} | 
 | 169 | 		nf_registered++; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 170 | 	} | 
 | 171 | #endif | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 172 | 	return 0; | 
 | 173 | } | 
 | 174 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 175 | /* ------------------------------------------------------------- */ | 
 | 176 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 177 | static void ingress_destroy(struct Qdisc *sch) | 
 | 178 | { | 
| Patrick McHardy | cb53c04 | 2008-01-21 00:11:48 -0800 | [diff] [blame] | 179 | 	struct ingress_qdisc_data *p = qdisc_priv(sch); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 180 |  | 
| Patrick McHardy | a48b5a6 | 2007-03-23 11:29:43 -0700 | [diff] [blame] | 181 | 	tcf_destroy_chain(p->filter_list); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 182 | } | 
 | 183 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 184 | static int ingress_dump(struct Qdisc *sch, struct sk_buff *skb) | 
 | 185 | { | 
| Patrick McHardy | 4b3550ef | 2008-01-23 20:34:11 -0800 | [diff] [blame] | 186 | 	struct nlattr *nest; | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 187 |  | 
| Patrick McHardy | 4b3550ef | 2008-01-23 20:34:11 -0800 | [diff] [blame] | 188 | 	nest = nla_nest_start(skb, TCA_OPTIONS); | 
 | 189 | 	if (nest == NULL) | 
 | 190 | 		goto nla_put_failure; | 
 | 191 | 	nla_nest_end(skb, nest); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 192 | 	return skb->len; | 
 | 193 |  | 
| Patrick McHardy | 1e90474 | 2008-01-22 22:11:17 -0800 | [diff] [blame] | 194 | nla_put_failure: | 
| Patrick McHardy | 4b3550ef | 2008-01-23 20:34:11 -0800 | [diff] [blame] | 195 | 	nla_nest_cancel(skb, nest); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 196 | 	return -1; | 
 | 197 | } | 
 | 198 |  | 
| Eric Dumazet | 20fea08 | 2007-11-14 01:44:41 -0800 | [diff] [blame] | 199 | static const struct Qdisc_class_ops ingress_class_ops = { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 200 | 	.graft		=	ingress_graft, | 
 | 201 | 	.leaf		=	ingress_leaf, | 
 | 202 | 	.get		=	ingress_get, | 
 | 203 | 	.put		=	ingress_put, | 
 | 204 | 	.change		=	ingress_change, | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 205 | 	.walk		=	ingress_walk, | 
 | 206 | 	.tcf_chain	=	ingress_find_tcf, | 
 | 207 | 	.bind_tcf	=	ingress_bind_filter, | 
 | 208 | 	.unbind_tcf	=	ingress_put, | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 209 | }; | 
 | 210 |  | 
| Eric Dumazet | 20fea08 | 2007-11-14 01:44:41 -0800 | [diff] [blame] | 211 | static struct Qdisc_ops ingress_qdisc_ops __read_mostly = { | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 212 | 	.cl_ops		=	&ingress_class_ops, | 
 | 213 | 	.id		=	"ingress", | 
 | 214 | 	.priv_size	=	sizeof(struct ingress_qdisc_data), | 
 | 215 | 	.enqueue	=	ingress_enqueue, | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 216 | 	.init		=	ingress_init, | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 217 | 	.destroy	=	ingress_destroy, | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 218 | 	.dump		=	ingress_dump, | 
 | 219 | 	.owner		=	THIS_MODULE, | 
 | 220 | }; | 
 | 221 |  | 
 | 222 | static int __init ingress_module_init(void) | 
 | 223 | { | 
| Patrick McHardy | 8916876 | 2008-01-21 00:14:05 -0800 | [diff] [blame] | 224 | 	return register_qdisc(&ingress_qdisc_ops); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 225 | } | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 226 |  | 
| YOSHIFUJI Hideaki | 10297b9 | 2007-02-09 23:25:16 +0900 | [diff] [blame] | 227 | static void __exit ingress_module_exit(void) | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 228 | { | 
 | 229 | 	unregister_qdisc(&ingress_qdisc_ops); | 
| Patrick McHardy | 1389356 | 2008-01-21 00:13:44 -0800 | [diff] [blame] | 230 | #if !defined(CONFIG_NET_CLS_ACT) && defined(CONFIG_NETFILTER) | 
| Patrick McHardy | 41c5b31 | 2007-12-05 01:22:43 -0800 | [diff] [blame] | 231 | 	if (nf_registered) | 
 | 232 | 		nf_unregister_hooks(ing_ops, ARRAY_SIZE(ing_ops)); | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 233 | #endif | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 234 | } | 
| Patrick McHardy | 58f4df4 | 2008-01-21 00:11:01 -0800 | [diff] [blame] | 235 |  | 
| Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 236 | module_init(ingress_module_init) | 
 | 237 | module_exit(ingress_module_exit) | 
 | 238 | MODULE_LICENSE("GPL"); |