162306a36Sopenharmony_ci// SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause) 262306a36Sopenharmony_ci/* Copyright (C) 2017-2018 Netronome Systems, Inc. */ 362306a36Sopenharmony_ci 462306a36Sopenharmony_ci#include <linux/skbuff.h> 562306a36Sopenharmony_ci#include <net/devlink.h> 662306a36Sopenharmony_ci#include <net/pkt_cls.h> 762306a36Sopenharmony_ci 862306a36Sopenharmony_ci#include "cmsg.h" 962306a36Sopenharmony_ci#include "main.h" 1062306a36Sopenharmony_ci#include "conntrack.h" 1162306a36Sopenharmony_ci#include "../nfpcore/nfp_cpp.h" 1262306a36Sopenharmony_ci#include "../nfpcore/nfp_nsp.h" 1362306a36Sopenharmony_ci#include "../nfp_app.h" 1462306a36Sopenharmony_ci#include "../nfp_main.h" 1562306a36Sopenharmony_ci#include "../nfp_net.h" 1662306a36Sopenharmony_ci#include "../nfp_port.h" 1762306a36Sopenharmony_ci 1862306a36Sopenharmony_ci#define NFP_FLOWER_SUPPORTED_TCPFLAGS \ 1962306a36Sopenharmony_ci (TCPHDR_FIN | TCPHDR_SYN | TCPHDR_RST | \ 2062306a36Sopenharmony_ci TCPHDR_PSH | TCPHDR_URG) 2162306a36Sopenharmony_ci 2262306a36Sopenharmony_ci#define NFP_FLOWER_SUPPORTED_CTLFLAGS \ 2362306a36Sopenharmony_ci (FLOW_DIS_IS_FRAGMENT | \ 2462306a36Sopenharmony_ci FLOW_DIS_FIRST_FRAG) 2562306a36Sopenharmony_ci 2662306a36Sopenharmony_ci#define NFP_FLOWER_WHITELIST_DISSECTOR \ 2762306a36Sopenharmony_ci (BIT_ULL(FLOW_DISSECTOR_KEY_CONTROL) | \ 2862306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_BASIC) | \ 2962306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_IPV4_ADDRS) | \ 3062306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_IPV6_ADDRS) | \ 3162306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_TCP) | \ 3262306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_PORTS) | \ 3362306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ETH_ADDRS) | \ 3462306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_VLAN) | \ 3562306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_CVLAN) | \ 3662306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_KEYID) | \ 3762306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS) | \ 3862306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS) | \ 3962306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_CONTROL) | \ 4062306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_PORTS) | \ 4162306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_OPTS) | \ 4262306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IP) | \ 4362306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_MPLS) | \ 4462306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_CT) | \ 4562306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_META) | \ 4662306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_IP)) 4762306a36Sopenharmony_ci 4862306a36Sopenharmony_ci#define NFP_FLOWER_WHITELIST_TUN_DISSECTOR \ 4962306a36Sopenharmony_ci (BIT_ULL(FLOW_DISSECTOR_KEY_ENC_CONTROL) | \ 5062306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_KEYID) | \ 5162306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS) | \ 5262306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS) | \ 5362306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_OPTS) | \ 5462306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_PORTS) | \ 5562306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IP)) 5662306a36Sopenharmony_ci 5762306a36Sopenharmony_ci#define NFP_FLOWER_WHITELIST_TUN_DISSECTOR_R \ 5862306a36Sopenharmony_ci (BIT_ULL(FLOW_DISSECTOR_KEY_ENC_CONTROL) | \ 5962306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IPV4_ADDRS)) 6062306a36Sopenharmony_ci 6162306a36Sopenharmony_ci#define NFP_FLOWER_WHITELIST_TUN_DISSECTOR_V6_R \ 6262306a36Sopenharmony_ci (BIT_ULL(FLOW_DISSECTOR_KEY_ENC_CONTROL) | \ 6362306a36Sopenharmony_ci BIT_ULL(FLOW_DISSECTOR_KEY_ENC_IPV6_ADDRS)) 6462306a36Sopenharmony_ci 6562306a36Sopenharmony_ci#define NFP_FLOWER_MERGE_FIELDS \ 6662306a36Sopenharmony_ci (NFP_FLOWER_LAYER_PORT | \ 6762306a36Sopenharmony_ci NFP_FLOWER_LAYER_MAC | \ 6862306a36Sopenharmony_ci NFP_FLOWER_LAYER_TP | \ 6962306a36Sopenharmony_ci NFP_FLOWER_LAYER_IPV4 | \ 7062306a36Sopenharmony_ci NFP_FLOWER_LAYER_IPV6) 7162306a36Sopenharmony_ci 7262306a36Sopenharmony_ci#define NFP_FLOWER_PRE_TUN_RULE_FIELDS \ 7362306a36Sopenharmony_ci (NFP_FLOWER_LAYER_EXT_META | \ 7462306a36Sopenharmony_ci NFP_FLOWER_LAYER_PORT | \ 7562306a36Sopenharmony_ci NFP_FLOWER_LAYER_MAC | \ 7662306a36Sopenharmony_ci NFP_FLOWER_LAYER_IPV4 | \ 7762306a36Sopenharmony_ci NFP_FLOWER_LAYER_IPV6) 7862306a36Sopenharmony_ci 7962306a36Sopenharmony_cistruct nfp_flower_merge_check { 8062306a36Sopenharmony_ci union { 8162306a36Sopenharmony_ci struct { 8262306a36Sopenharmony_ci __be16 tci; 8362306a36Sopenharmony_ci struct nfp_flower_mac_mpls l2; 8462306a36Sopenharmony_ci struct nfp_flower_tp_ports l4; 8562306a36Sopenharmony_ci union { 8662306a36Sopenharmony_ci struct nfp_flower_ipv4 ipv4; 8762306a36Sopenharmony_ci struct nfp_flower_ipv6 ipv6; 8862306a36Sopenharmony_ci }; 8962306a36Sopenharmony_ci }; 9062306a36Sopenharmony_ci unsigned long vals[8]; 9162306a36Sopenharmony_ci }; 9262306a36Sopenharmony_ci}; 9362306a36Sopenharmony_ci 9462306a36Sopenharmony_ciint 9562306a36Sopenharmony_cinfp_flower_xmit_flow(struct nfp_app *app, struct nfp_fl_payload *nfp_flow, 9662306a36Sopenharmony_ci u8 mtype) 9762306a36Sopenharmony_ci{ 9862306a36Sopenharmony_ci u32 meta_len, key_len, mask_len, act_len, tot_len; 9962306a36Sopenharmony_ci struct sk_buff *skb; 10062306a36Sopenharmony_ci unsigned char *msg; 10162306a36Sopenharmony_ci 10262306a36Sopenharmony_ci meta_len = sizeof(struct nfp_fl_rule_metadata); 10362306a36Sopenharmony_ci key_len = nfp_flow->meta.key_len; 10462306a36Sopenharmony_ci mask_len = nfp_flow->meta.mask_len; 10562306a36Sopenharmony_ci act_len = nfp_flow->meta.act_len; 10662306a36Sopenharmony_ci 10762306a36Sopenharmony_ci tot_len = meta_len + key_len + mask_len + act_len; 10862306a36Sopenharmony_ci 10962306a36Sopenharmony_ci /* Convert to long words as firmware expects 11062306a36Sopenharmony_ci * lengths in units of NFP_FL_LW_SIZ. 11162306a36Sopenharmony_ci */ 11262306a36Sopenharmony_ci nfp_flow->meta.key_len >>= NFP_FL_LW_SIZ; 11362306a36Sopenharmony_ci nfp_flow->meta.mask_len >>= NFP_FL_LW_SIZ; 11462306a36Sopenharmony_ci nfp_flow->meta.act_len >>= NFP_FL_LW_SIZ; 11562306a36Sopenharmony_ci 11662306a36Sopenharmony_ci skb = nfp_flower_cmsg_alloc(app, tot_len, mtype, GFP_KERNEL); 11762306a36Sopenharmony_ci if (!skb) 11862306a36Sopenharmony_ci return -ENOMEM; 11962306a36Sopenharmony_ci 12062306a36Sopenharmony_ci msg = nfp_flower_cmsg_get_data(skb); 12162306a36Sopenharmony_ci memcpy(msg, &nfp_flow->meta, meta_len); 12262306a36Sopenharmony_ci memcpy(&msg[meta_len], nfp_flow->unmasked_data, key_len); 12362306a36Sopenharmony_ci memcpy(&msg[meta_len + key_len], nfp_flow->mask_data, mask_len); 12462306a36Sopenharmony_ci memcpy(&msg[meta_len + key_len + mask_len], 12562306a36Sopenharmony_ci nfp_flow->action_data, act_len); 12662306a36Sopenharmony_ci 12762306a36Sopenharmony_ci /* Convert back to bytes as software expects 12862306a36Sopenharmony_ci * lengths in units of bytes. 12962306a36Sopenharmony_ci */ 13062306a36Sopenharmony_ci nfp_flow->meta.key_len <<= NFP_FL_LW_SIZ; 13162306a36Sopenharmony_ci nfp_flow->meta.mask_len <<= NFP_FL_LW_SIZ; 13262306a36Sopenharmony_ci nfp_flow->meta.act_len <<= NFP_FL_LW_SIZ; 13362306a36Sopenharmony_ci 13462306a36Sopenharmony_ci nfp_ctrl_tx(app->ctrl, skb); 13562306a36Sopenharmony_ci 13662306a36Sopenharmony_ci return 0; 13762306a36Sopenharmony_ci} 13862306a36Sopenharmony_ci 13962306a36Sopenharmony_cistatic bool nfp_flower_check_higher_than_mac(struct flow_rule *rule) 14062306a36Sopenharmony_ci{ 14162306a36Sopenharmony_ci return flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_IPV4_ADDRS) || 14262306a36Sopenharmony_ci flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_IPV6_ADDRS) || 14362306a36Sopenharmony_ci flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_PORTS) || 14462306a36Sopenharmony_ci flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ICMP); 14562306a36Sopenharmony_ci} 14662306a36Sopenharmony_ci 14762306a36Sopenharmony_cistatic bool nfp_flower_check_higher_than_l3(struct flow_rule *rule) 14862306a36Sopenharmony_ci{ 14962306a36Sopenharmony_ci return flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_PORTS) || 15062306a36Sopenharmony_ci flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ICMP); 15162306a36Sopenharmony_ci} 15262306a36Sopenharmony_ci 15362306a36Sopenharmony_cistatic int 15462306a36Sopenharmony_cinfp_flower_calc_opt_layer(struct flow_dissector_key_enc_opts *enc_opts, 15562306a36Sopenharmony_ci u32 *key_layer_two, int *key_size, bool ipv6, 15662306a36Sopenharmony_ci struct netlink_ext_ack *extack) 15762306a36Sopenharmony_ci{ 15862306a36Sopenharmony_ci if (enc_opts->len > NFP_FL_MAX_GENEVE_OPT_KEY || 15962306a36Sopenharmony_ci (ipv6 && enc_opts->len > NFP_FL_MAX_GENEVE_OPT_KEY_V6)) { 16062306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: geneve options exceed maximum length"); 16162306a36Sopenharmony_ci return -EOPNOTSUPP; 16262306a36Sopenharmony_ci } 16362306a36Sopenharmony_ci 16462306a36Sopenharmony_ci if (enc_opts->len > 0) { 16562306a36Sopenharmony_ci *key_layer_two |= NFP_FLOWER_LAYER2_GENEVE_OP; 16662306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_geneve_options); 16762306a36Sopenharmony_ci } 16862306a36Sopenharmony_ci 16962306a36Sopenharmony_ci return 0; 17062306a36Sopenharmony_ci} 17162306a36Sopenharmony_ci 17262306a36Sopenharmony_cistatic int 17362306a36Sopenharmony_cinfp_flower_calc_udp_tun_layer(struct flow_dissector_key_ports *enc_ports, 17462306a36Sopenharmony_ci struct flow_dissector_key_enc_opts *enc_op, 17562306a36Sopenharmony_ci u32 *key_layer_two, u8 *key_layer, int *key_size, 17662306a36Sopenharmony_ci struct nfp_flower_priv *priv, 17762306a36Sopenharmony_ci enum nfp_flower_tun_type *tun_type, bool ipv6, 17862306a36Sopenharmony_ci struct netlink_ext_ack *extack) 17962306a36Sopenharmony_ci{ 18062306a36Sopenharmony_ci int err; 18162306a36Sopenharmony_ci 18262306a36Sopenharmony_ci switch (enc_ports->dst) { 18362306a36Sopenharmony_ci case htons(IANA_VXLAN_UDP_PORT): 18462306a36Sopenharmony_ci *tun_type = NFP_FL_TUNNEL_VXLAN; 18562306a36Sopenharmony_ci *key_layer |= NFP_FLOWER_LAYER_VXLAN; 18662306a36Sopenharmony_ci 18762306a36Sopenharmony_ci if (ipv6) { 18862306a36Sopenharmony_ci *key_layer |= NFP_FLOWER_LAYER_EXT_META; 18962306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_ext_meta); 19062306a36Sopenharmony_ci *key_layer_two |= NFP_FLOWER_LAYER2_TUN_IPV6; 19162306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_ipv6_udp_tun); 19262306a36Sopenharmony_ci } else { 19362306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_ipv4_udp_tun); 19462306a36Sopenharmony_ci } 19562306a36Sopenharmony_ci 19662306a36Sopenharmony_ci if (enc_op) { 19762306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: encap options not supported on vxlan tunnels"); 19862306a36Sopenharmony_ci return -EOPNOTSUPP; 19962306a36Sopenharmony_ci } 20062306a36Sopenharmony_ci break; 20162306a36Sopenharmony_ci case htons(GENEVE_UDP_PORT): 20262306a36Sopenharmony_ci if (!(priv->flower_ext_feats & NFP_FL_FEATS_GENEVE)) { 20362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: loaded firmware does not support geneve offload"); 20462306a36Sopenharmony_ci return -EOPNOTSUPP; 20562306a36Sopenharmony_ci } 20662306a36Sopenharmony_ci *tun_type = NFP_FL_TUNNEL_GENEVE; 20762306a36Sopenharmony_ci *key_layer |= NFP_FLOWER_LAYER_EXT_META; 20862306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_ext_meta); 20962306a36Sopenharmony_ci *key_layer_two |= NFP_FLOWER_LAYER2_GENEVE; 21062306a36Sopenharmony_ci 21162306a36Sopenharmony_ci if (ipv6) { 21262306a36Sopenharmony_ci *key_layer_two |= NFP_FLOWER_LAYER2_TUN_IPV6; 21362306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_ipv6_udp_tun); 21462306a36Sopenharmony_ci } else { 21562306a36Sopenharmony_ci *key_size += sizeof(struct nfp_flower_ipv4_udp_tun); 21662306a36Sopenharmony_ci } 21762306a36Sopenharmony_ci 21862306a36Sopenharmony_ci if (!enc_op) 21962306a36Sopenharmony_ci break; 22062306a36Sopenharmony_ci if (!(priv->flower_ext_feats & NFP_FL_FEATS_GENEVE_OPT)) { 22162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: loaded firmware does not support geneve option offload"); 22262306a36Sopenharmony_ci return -EOPNOTSUPP; 22362306a36Sopenharmony_ci } 22462306a36Sopenharmony_ci err = nfp_flower_calc_opt_layer(enc_op, key_layer_two, key_size, 22562306a36Sopenharmony_ci ipv6, extack); 22662306a36Sopenharmony_ci if (err) 22762306a36Sopenharmony_ci return err; 22862306a36Sopenharmony_ci break; 22962306a36Sopenharmony_ci default: 23062306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: tunnel type unknown"); 23162306a36Sopenharmony_ci return -EOPNOTSUPP; 23262306a36Sopenharmony_ci } 23362306a36Sopenharmony_ci 23462306a36Sopenharmony_ci return 0; 23562306a36Sopenharmony_ci} 23662306a36Sopenharmony_ci 23762306a36Sopenharmony_ciint 23862306a36Sopenharmony_cinfp_flower_calculate_key_layers(struct nfp_app *app, 23962306a36Sopenharmony_ci struct net_device *netdev, 24062306a36Sopenharmony_ci struct nfp_fl_key_ls *ret_key_ls, 24162306a36Sopenharmony_ci struct flow_rule *rule, 24262306a36Sopenharmony_ci enum nfp_flower_tun_type *tun_type, 24362306a36Sopenharmony_ci struct netlink_ext_ack *extack) 24462306a36Sopenharmony_ci{ 24562306a36Sopenharmony_ci struct flow_dissector *dissector = rule->match.dissector; 24662306a36Sopenharmony_ci struct flow_match_basic basic = { NULL, NULL}; 24762306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 24862306a36Sopenharmony_ci u32 key_layer_two; 24962306a36Sopenharmony_ci u8 key_layer; 25062306a36Sopenharmony_ci int key_size; 25162306a36Sopenharmony_ci int err; 25262306a36Sopenharmony_ci 25362306a36Sopenharmony_ci if (dissector->used_keys & ~NFP_FLOWER_WHITELIST_DISSECTOR) { 25462306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: match not supported"); 25562306a36Sopenharmony_ci return -EOPNOTSUPP; 25662306a36Sopenharmony_ci } 25762306a36Sopenharmony_ci 25862306a36Sopenharmony_ci /* If any tun dissector is used then the required set must be used. */ 25962306a36Sopenharmony_ci if (dissector->used_keys & NFP_FLOWER_WHITELIST_TUN_DISSECTOR && 26062306a36Sopenharmony_ci (dissector->used_keys & NFP_FLOWER_WHITELIST_TUN_DISSECTOR_V6_R) 26162306a36Sopenharmony_ci != NFP_FLOWER_WHITELIST_TUN_DISSECTOR_V6_R && 26262306a36Sopenharmony_ci (dissector->used_keys & NFP_FLOWER_WHITELIST_TUN_DISSECTOR_R) 26362306a36Sopenharmony_ci != NFP_FLOWER_WHITELIST_TUN_DISSECTOR_R) { 26462306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: tunnel match not supported"); 26562306a36Sopenharmony_ci return -EOPNOTSUPP; 26662306a36Sopenharmony_ci } 26762306a36Sopenharmony_ci 26862306a36Sopenharmony_ci key_layer_two = 0; 26962306a36Sopenharmony_ci key_layer = NFP_FLOWER_LAYER_PORT; 27062306a36Sopenharmony_ci key_size = sizeof(struct nfp_flower_meta_tci) + 27162306a36Sopenharmony_ci sizeof(struct nfp_flower_in_port); 27262306a36Sopenharmony_ci 27362306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ETH_ADDRS) || 27462306a36Sopenharmony_ci flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_MPLS)) { 27562306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_MAC; 27662306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_mac_mpls); 27762306a36Sopenharmony_ci } 27862306a36Sopenharmony_ci 27962306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_VLAN)) { 28062306a36Sopenharmony_ci struct flow_match_vlan vlan; 28162306a36Sopenharmony_ci 28262306a36Sopenharmony_ci flow_rule_match_vlan(rule, &vlan); 28362306a36Sopenharmony_ci if (!(priv->flower_ext_feats & NFP_FL_FEATS_VLAN_PCP) && 28462306a36Sopenharmony_ci vlan.key->vlan_priority) { 28562306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: loaded firmware does not support VLAN PCP offload"); 28662306a36Sopenharmony_ci return -EOPNOTSUPP; 28762306a36Sopenharmony_ci } 28862306a36Sopenharmony_ci if (priv->flower_ext_feats & NFP_FL_FEATS_VLAN_QINQ && 28962306a36Sopenharmony_ci !(key_layer_two & NFP_FLOWER_LAYER2_QINQ)) { 29062306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_EXT_META; 29162306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ext_meta); 29262306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_vlan); 29362306a36Sopenharmony_ci key_layer_two |= NFP_FLOWER_LAYER2_QINQ; 29462306a36Sopenharmony_ci } 29562306a36Sopenharmony_ci } 29662306a36Sopenharmony_ci 29762306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_CVLAN)) { 29862306a36Sopenharmony_ci struct flow_match_vlan cvlan; 29962306a36Sopenharmony_ci 30062306a36Sopenharmony_ci if (!(priv->flower_ext_feats & NFP_FL_FEATS_VLAN_QINQ)) { 30162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: loaded firmware does not support VLAN QinQ offload"); 30262306a36Sopenharmony_ci return -EOPNOTSUPP; 30362306a36Sopenharmony_ci } 30462306a36Sopenharmony_ci 30562306a36Sopenharmony_ci flow_rule_match_vlan(rule, &cvlan); 30662306a36Sopenharmony_ci if (!(key_layer_two & NFP_FLOWER_LAYER2_QINQ)) { 30762306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_EXT_META; 30862306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ext_meta); 30962306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_vlan); 31062306a36Sopenharmony_ci key_layer_two |= NFP_FLOWER_LAYER2_QINQ; 31162306a36Sopenharmony_ci } 31262306a36Sopenharmony_ci } 31362306a36Sopenharmony_ci 31462306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ENC_CONTROL)) { 31562306a36Sopenharmony_ci struct flow_match_enc_opts enc_op = { NULL, NULL }; 31662306a36Sopenharmony_ci struct flow_match_ipv4_addrs ipv4_addrs; 31762306a36Sopenharmony_ci struct flow_match_ipv6_addrs ipv6_addrs; 31862306a36Sopenharmony_ci struct flow_match_control enc_ctl; 31962306a36Sopenharmony_ci struct flow_match_ports enc_ports; 32062306a36Sopenharmony_ci bool ipv6_tun = false; 32162306a36Sopenharmony_ci 32262306a36Sopenharmony_ci flow_rule_match_enc_control(rule, &enc_ctl); 32362306a36Sopenharmony_ci 32462306a36Sopenharmony_ci if (enc_ctl.mask->addr_type != 0xffff) { 32562306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: wildcarded protocols on tunnels are not supported"); 32662306a36Sopenharmony_ci return -EOPNOTSUPP; 32762306a36Sopenharmony_ci } 32862306a36Sopenharmony_ci 32962306a36Sopenharmony_ci ipv6_tun = enc_ctl.key->addr_type == 33062306a36Sopenharmony_ci FLOW_DISSECTOR_KEY_IPV6_ADDRS; 33162306a36Sopenharmony_ci if (ipv6_tun && 33262306a36Sopenharmony_ci !(priv->flower_ext_feats & NFP_FL_FEATS_IPV6_TUN)) { 33362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: firmware does not support IPv6 tunnels"); 33462306a36Sopenharmony_ci return -EOPNOTSUPP; 33562306a36Sopenharmony_ci } 33662306a36Sopenharmony_ci 33762306a36Sopenharmony_ci if (!ipv6_tun && 33862306a36Sopenharmony_ci enc_ctl.key->addr_type != FLOW_DISSECTOR_KEY_IPV4_ADDRS) { 33962306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: tunnel address type not IPv4 or IPv6"); 34062306a36Sopenharmony_ci return -EOPNOTSUPP; 34162306a36Sopenharmony_ci } 34262306a36Sopenharmony_ci 34362306a36Sopenharmony_ci if (ipv6_tun) { 34462306a36Sopenharmony_ci flow_rule_match_enc_ipv6_addrs(rule, &ipv6_addrs); 34562306a36Sopenharmony_ci if (memchr_inv(&ipv6_addrs.mask->dst, 0xff, 34662306a36Sopenharmony_ci sizeof(ipv6_addrs.mask->dst))) { 34762306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: only an exact match IPv6 destination address is supported"); 34862306a36Sopenharmony_ci return -EOPNOTSUPP; 34962306a36Sopenharmony_ci } 35062306a36Sopenharmony_ci } else { 35162306a36Sopenharmony_ci flow_rule_match_enc_ipv4_addrs(rule, &ipv4_addrs); 35262306a36Sopenharmony_ci if (ipv4_addrs.mask->dst != cpu_to_be32(~0)) { 35362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: only an exact match IPv4 destination address is supported"); 35462306a36Sopenharmony_ci return -EOPNOTSUPP; 35562306a36Sopenharmony_ci } 35662306a36Sopenharmony_ci } 35762306a36Sopenharmony_ci 35862306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ENC_OPTS)) 35962306a36Sopenharmony_ci flow_rule_match_enc_opts(rule, &enc_op); 36062306a36Sopenharmony_ci 36162306a36Sopenharmony_ci if (!flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ENC_PORTS)) { 36262306a36Sopenharmony_ci /* Check if GRE, which has no enc_ports */ 36362306a36Sopenharmony_ci if (!netif_is_gretap(netdev) && !netif_is_ip6gretap(netdev)) { 36462306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: an exact match on L4 destination port is required for non-GRE tunnels"); 36562306a36Sopenharmony_ci return -EOPNOTSUPP; 36662306a36Sopenharmony_ci } 36762306a36Sopenharmony_ci 36862306a36Sopenharmony_ci *tun_type = NFP_FL_TUNNEL_GRE; 36962306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_EXT_META; 37062306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ext_meta); 37162306a36Sopenharmony_ci key_layer_two |= NFP_FLOWER_LAYER2_GRE; 37262306a36Sopenharmony_ci 37362306a36Sopenharmony_ci if (ipv6_tun) { 37462306a36Sopenharmony_ci key_layer_two |= NFP_FLOWER_LAYER2_TUN_IPV6; 37562306a36Sopenharmony_ci key_size += 37662306a36Sopenharmony_ci sizeof(struct nfp_flower_ipv6_gre_tun); 37762306a36Sopenharmony_ci } else { 37862306a36Sopenharmony_ci key_size += 37962306a36Sopenharmony_ci sizeof(struct nfp_flower_ipv4_gre_tun); 38062306a36Sopenharmony_ci } 38162306a36Sopenharmony_ci 38262306a36Sopenharmony_ci if (enc_op.key) { 38362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: encap options not supported on GRE tunnels"); 38462306a36Sopenharmony_ci return -EOPNOTSUPP; 38562306a36Sopenharmony_ci } 38662306a36Sopenharmony_ci } else { 38762306a36Sopenharmony_ci flow_rule_match_enc_ports(rule, &enc_ports); 38862306a36Sopenharmony_ci if (enc_ports.mask->dst != cpu_to_be16(~0)) { 38962306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: only an exact match L4 destination port is supported"); 39062306a36Sopenharmony_ci return -EOPNOTSUPP; 39162306a36Sopenharmony_ci } 39262306a36Sopenharmony_ci 39362306a36Sopenharmony_ci err = nfp_flower_calc_udp_tun_layer(enc_ports.key, 39462306a36Sopenharmony_ci enc_op.key, 39562306a36Sopenharmony_ci &key_layer_two, 39662306a36Sopenharmony_ci &key_layer, 39762306a36Sopenharmony_ci &key_size, priv, 39862306a36Sopenharmony_ci tun_type, ipv6_tun, 39962306a36Sopenharmony_ci extack); 40062306a36Sopenharmony_ci if (err) 40162306a36Sopenharmony_ci return err; 40262306a36Sopenharmony_ci 40362306a36Sopenharmony_ci /* Ensure the ingress netdev matches the expected 40462306a36Sopenharmony_ci * tun type. 40562306a36Sopenharmony_ci */ 40662306a36Sopenharmony_ci if (!nfp_fl_netdev_is_tunnel_type(netdev, *tun_type)) { 40762306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: ingress netdev does not match the expected tunnel type"); 40862306a36Sopenharmony_ci return -EOPNOTSUPP; 40962306a36Sopenharmony_ci } 41062306a36Sopenharmony_ci } 41162306a36Sopenharmony_ci } 41262306a36Sopenharmony_ci 41362306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_BASIC)) 41462306a36Sopenharmony_ci flow_rule_match_basic(rule, &basic); 41562306a36Sopenharmony_ci 41662306a36Sopenharmony_ci if (basic.mask && basic.mask->n_proto) { 41762306a36Sopenharmony_ci /* Ethernet type is present in the key. */ 41862306a36Sopenharmony_ci switch (basic.key->n_proto) { 41962306a36Sopenharmony_ci case cpu_to_be16(ETH_P_IP): 42062306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_IPV4; 42162306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ipv4); 42262306a36Sopenharmony_ci break; 42362306a36Sopenharmony_ci 42462306a36Sopenharmony_ci case cpu_to_be16(ETH_P_IPV6): 42562306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_IPV6; 42662306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ipv6); 42762306a36Sopenharmony_ci break; 42862306a36Sopenharmony_ci 42962306a36Sopenharmony_ci /* Currently we do not offload ARP 43062306a36Sopenharmony_ci * because we rely on it to get to the host. 43162306a36Sopenharmony_ci */ 43262306a36Sopenharmony_ci case cpu_to_be16(ETH_P_ARP): 43362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: ARP not supported"); 43462306a36Sopenharmony_ci return -EOPNOTSUPP; 43562306a36Sopenharmony_ci 43662306a36Sopenharmony_ci case cpu_to_be16(ETH_P_MPLS_UC): 43762306a36Sopenharmony_ci case cpu_to_be16(ETH_P_MPLS_MC): 43862306a36Sopenharmony_ci if (!(key_layer & NFP_FLOWER_LAYER_MAC)) { 43962306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_MAC; 44062306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_mac_mpls); 44162306a36Sopenharmony_ci } 44262306a36Sopenharmony_ci break; 44362306a36Sopenharmony_ci 44462306a36Sopenharmony_ci /* Will be included in layer 2. */ 44562306a36Sopenharmony_ci case cpu_to_be16(ETH_P_8021Q): 44662306a36Sopenharmony_ci break; 44762306a36Sopenharmony_ci 44862306a36Sopenharmony_ci default: 44962306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: match on given EtherType is not supported"); 45062306a36Sopenharmony_ci return -EOPNOTSUPP; 45162306a36Sopenharmony_ci } 45262306a36Sopenharmony_ci } else if (nfp_flower_check_higher_than_mac(rule)) { 45362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: cannot match above L2 without specified EtherType"); 45462306a36Sopenharmony_ci return -EOPNOTSUPP; 45562306a36Sopenharmony_ci } 45662306a36Sopenharmony_ci 45762306a36Sopenharmony_ci if (basic.mask && basic.mask->ip_proto) { 45862306a36Sopenharmony_ci switch (basic.key->ip_proto) { 45962306a36Sopenharmony_ci case IPPROTO_TCP: 46062306a36Sopenharmony_ci case IPPROTO_UDP: 46162306a36Sopenharmony_ci case IPPROTO_SCTP: 46262306a36Sopenharmony_ci case IPPROTO_ICMP: 46362306a36Sopenharmony_ci case IPPROTO_ICMPV6: 46462306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_TP; 46562306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_tp_ports); 46662306a36Sopenharmony_ci break; 46762306a36Sopenharmony_ci } 46862306a36Sopenharmony_ci } 46962306a36Sopenharmony_ci 47062306a36Sopenharmony_ci if (!(key_layer & NFP_FLOWER_LAYER_TP) && 47162306a36Sopenharmony_ci nfp_flower_check_higher_than_l3(rule)) { 47262306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: cannot match on L4 information without specified IP protocol type"); 47362306a36Sopenharmony_ci return -EOPNOTSUPP; 47462306a36Sopenharmony_ci } 47562306a36Sopenharmony_ci 47662306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_TCP)) { 47762306a36Sopenharmony_ci struct flow_match_tcp tcp; 47862306a36Sopenharmony_ci u32 tcp_flags; 47962306a36Sopenharmony_ci 48062306a36Sopenharmony_ci flow_rule_match_tcp(rule, &tcp); 48162306a36Sopenharmony_ci tcp_flags = be16_to_cpu(tcp.key->flags); 48262306a36Sopenharmony_ci 48362306a36Sopenharmony_ci if (tcp_flags & ~NFP_FLOWER_SUPPORTED_TCPFLAGS) { 48462306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: no match support for selected TCP flags"); 48562306a36Sopenharmony_ci return -EOPNOTSUPP; 48662306a36Sopenharmony_ci } 48762306a36Sopenharmony_ci 48862306a36Sopenharmony_ci /* We only support PSH and URG flags when either 48962306a36Sopenharmony_ci * FIN, SYN or RST is present as well. 49062306a36Sopenharmony_ci */ 49162306a36Sopenharmony_ci if ((tcp_flags & (TCPHDR_PSH | TCPHDR_URG)) && 49262306a36Sopenharmony_ci !(tcp_flags & (TCPHDR_FIN | TCPHDR_SYN | TCPHDR_RST))) { 49362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: PSH and URG is only supported when used with FIN, SYN or RST"); 49462306a36Sopenharmony_ci return -EOPNOTSUPP; 49562306a36Sopenharmony_ci } 49662306a36Sopenharmony_ci 49762306a36Sopenharmony_ci /* We need to store TCP flags in the either the IPv4 or IPv6 key 49862306a36Sopenharmony_ci * space, thus we need to ensure we include a IPv4/IPv6 key 49962306a36Sopenharmony_ci * layer if we have not done so already. 50062306a36Sopenharmony_ci */ 50162306a36Sopenharmony_ci if (!basic.key) { 50262306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: match on TCP flags requires a match on L3 protocol"); 50362306a36Sopenharmony_ci return -EOPNOTSUPP; 50462306a36Sopenharmony_ci } 50562306a36Sopenharmony_ci 50662306a36Sopenharmony_ci if (!(key_layer & NFP_FLOWER_LAYER_IPV4) && 50762306a36Sopenharmony_ci !(key_layer & NFP_FLOWER_LAYER_IPV6)) { 50862306a36Sopenharmony_ci switch (basic.key->n_proto) { 50962306a36Sopenharmony_ci case cpu_to_be16(ETH_P_IP): 51062306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_IPV4; 51162306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ipv4); 51262306a36Sopenharmony_ci break; 51362306a36Sopenharmony_ci 51462306a36Sopenharmony_ci case cpu_to_be16(ETH_P_IPV6): 51562306a36Sopenharmony_ci key_layer |= NFP_FLOWER_LAYER_IPV6; 51662306a36Sopenharmony_ci key_size += sizeof(struct nfp_flower_ipv6); 51762306a36Sopenharmony_ci break; 51862306a36Sopenharmony_ci 51962306a36Sopenharmony_ci default: 52062306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: match on TCP flags requires a match on IPv4/IPv6"); 52162306a36Sopenharmony_ci return -EOPNOTSUPP; 52262306a36Sopenharmony_ci } 52362306a36Sopenharmony_ci } 52462306a36Sopenharmony_ci } 52562306a36Sopenharmony_ci 52662306a36Sopenharmony_ci if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_CONTROL)) { 52762306a36Sopenharmony_ci struct flow_match_control ctl; 52862306a36Sopenharmony_ci 52962306a36Sopenharmony_ci flow_rule_match_control(rule, &ctl); 53062306a36Sopenharmony_ci if (ctl.key->flags & ~NFP_FLOWER_SUPPORTED_CTLFLAGS) { 53162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported offload: match on unknown control flag"); 53262306a36Sopenharmony_ci return -EOPNOTSUPP; 53362306a36Sopenharmony_ci } 53462306a36Sopenharmony_ci } 53562306a36Sopenharmony_ci 53662306a36Sopenharmony_ci ret_key_ls->key_layer = key_layer; 53762306a36Sopenharmony_ci ret_key_ls->key_layer_two = key_layer_two; 53862306a36Sopenharmony_ci ret_key_ls->key_size = key_size; 53962306a36Sopenharmony_ci 54062306a36Sopenharmony_ci return 0; 54162306a36Sopenharmony_ci} 54262306a36Sopenharmony_ci 54362306a36Sopenharmony_cistruct nfp_fl_payload * 54462306a36Sopenharmony_cinfp_flower_allocate_new(struct nfp_fl_key_ls *key_layer) 54562306a36Sopenharmony_ci{ 54662306a36Sopenharmony_ci struct nfp_fl_payload *flow_pay; 54762306a36Sopenharmony_ci 54862306a36Sopenharmony_ci flow_pay = kmalloc(sizeof(*flow_pay), GFP_KERNEL); 54962306a36Sopenharmony_ci if (!flow_pay) 55062306a36Sopenharmony_ci return NULL; 55162306a36Sopenharmony_ci 55262306a36Sopenharmony_ci flow_pay->meta.key_len = key_layer->key_size; 55362306a36Sopenharmony_ci flow_pay->unmasked_data = kmalloc(key_layer->key_size, GFP_KERNEL); 55462306a36Sopenharmony_ci if (!flow_pay->unmasked_data) 55562306a36Sopenharmony_ci goto err_free_flow; 55662306a36Sopenharmony_ci 55762306a36Sopenharmony_ci flow_pay->meta.mask_len = key_layer->key_size; 55862306a36Sopenharmony_ci flow_pay->mask_data = kmalloc(key_layer->key_size, GFP_KERNEL); 55962306a36Sopenharmony_ci if (!flow_pay->mask_data) 56062306a36Sopenharmony_ci goto err_free_unmasked; 56162306a36Sopenharmony_ci 56262306a36Sopenharmony_ci flow_pay->action_data = kmalloc(NFP_FL_MAX_A_SIZ, GFP_KERNEL); 56362306a36Sopenharmony_ci if (!flow_pay->action_data) 56462306a36Sopenharmony_ci goto err_free_mask; 56562306a36Sopenharmony_ci 56662306a36Sopenharmony_ci flow_pay->nfp_tun_ipv4_addr = 0; 56762306a36Sopenharmony_ci flow_pay->nfp_tun_ipv6 = NULL; 56862306a36Sopenharmony_ci flow_pay->meta.flags = 0; 56962306a36Sopenharmony_ci INIT_LIST_HEAD(&flow_pay->linked_flows); 57062306a36Sopenharmony_ci flow_pay->in_hw = false; 57162306a36Sopenharmony_ci flow_pay->pre_tun_rule.dev = NULL; 57262306a36Sopenharmony_ci 57362306a36Sopenharmony_ci return flow_pay; 57462306a36Sopenharmony_ci 57562306a36Sopenharmony_cierr_free_mask: 57662306a36Sopenharmony_ci kfree(flow_pay->mask_data); 57762306a36Sopenharmony_cierr_free_unmasked: 57862306a36Sopenharmony_ci kfree(flow_pay->unmasked_data); 57962306a36Sopenharmony_cierr_free_flow: 58062306a36Sopenharmony_ci kfree(flow_pay); 58162306a36Sopenharmony_ci return NULL; 58262306a36Sopenharmony_ci} 58362306a36Sopenharmony_ci 58462306a36Sopenharmony_cistatic int 58562306a36Sopenharmony_cinfp_flower_update_merge_with_actions(struct nfp_fl_payload *flow, 58662306a36Sopenharmony_ci struct nfp_flower_merge_check *merge, 58762306a36Sopenharmony_ci u8 *last_act_id, int *act_out) 58862306a36Sopenharmony_ci{ 58962306a36Sopenharmony_ci struct nfp_fl_set_ipv6_tc_hl_fl *ipv6_tc_hl_fl; 59062306a36Sopenharmony_ci struct nfp_fl_set_ip4_ttl_tos *ipv4_ttl_tos; 59162306a36Sopenharmony_ci struct nfp_fl_set_ip4_addrs *ipv4_add; 59262306a36Sopenharmony_ci struct nfp_fl_set_ipv6_addr *ipv6_add; 59362306a36Sopenharmony_ci struct nfp_fl_push_vlan *push_vlan; 59462306a36Sopenharmony_ci struct nfp_fl_pre_tunnel *pre_tun; 59562306a36Sopenharmony_ci struct nfp_fl_set_tport *tport; 59662306a36Sopenharmony_ci struct nfp_fl_set_eth *eth; 59762306a36Sopenharmony_ci struct nfp_fl_act_head *a; 59862306a36Sopenharmony_ci unsigned int act_off = 0; 59962306a36Sopenharmony_ci bool ipv6_tun = false; 60062306a36Sopenharmony_ci u8 act_id = 0; 60162306a36Sopenharmony_ci u8 *ports; 60262306a36Sopenharmony_ci int i; 60362306a36Sopenharmony_ci 60462306a36Sopenharmony_ci while (act_off < flow->meta.act_len) { 60562306a36Sopenharmony_ci a = (struct nfp_fl_act_head *)&flow->action_data[act_off]; 60662306a36Sopenharmony_ci act_id = a->jump_id; 60762306a36Sopenharmony_ci 60862306a36Sopenharmony_ci switch (act_id) { 60962306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_OUTPUT: 61062306a36Sopenharmony_ci if (act_out) 61162306a36Sopenharmony_ci (*act_out)++; 61262306a36Sopenharmony_ci break; 61362306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_PUSH_VLAN: 61462306a36Sopenharmony_ci push_vlan = (struct nfp_fl_push_vlan *)a; 61562306a36Sopenharmony_ci if (push_vlan->vlan_tci) 61662306a36Sopenharmony_ci merge->tci = cpu_to_be16(0xffff); 61762306a36Sopenharmony_ci break; 61862306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_POP_VLAN: 61962306a36Sopenharmony_ci merge->tci = cpu_to_be16(0); 62062306a36Sopenharmony_ci break; 62162306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_TUNNEL: 62262306a36Sopenharmony_ci /* New tunnel header means l2 to l4 can be matched. */ 62362306a36Sopenharmony_ci eth_broadcast_addr(&merge->l2.mac_dst[0]); 62462306a36Sopenharmony_ci eth_broadcast_addr(&merge->l2.mac_src[0]); 62562306a36Sopenharmony_ci memset(&merge->l4, 0xff, 62662306a36Sopenharmony_ci sizeof(struct nfp_flower_tp_ports)); 62762306a36Sopenharmony_ci if (ipv6_tun) 62862306a36Sopenharmony_ci memset(&merge->ipv6, 0xff, 62962306a36Sopenharmony_ci sizeof(struct nfp_flower_ipv6)); 63062306a36Sopenharmony_ci else 63162306a36Sopenharmony_ci memset(&merge->ipv4, 0xff, 63262306a36Sopenharmony_ci sizeof(struct nfp_flower_ipv4)); 63362306a36Sopenharmony_ci break; 63462306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_ETHERNET: 63562306a36Sopenharmony_ci eth = (struct nfp_fl_set_eth *)a; 63662306a36Sopenharmony_ci for (i = 0; i < ETH_ALEN; i++) 63762306a36Sopenharmony_ci merge->l2.mac_dst[i] |= eth->eth_addr_mask[i]; 63862306a36Sopenharmony_ci for (i = 0; i < ETH_ALEN; i++) 63962306a36Sopenharmony_ci merge->l2.mac_src[i] |= 64062306a36Sopenharmony_ci eth->eth_addr_mask[ETH_ALEN + i]; 64162306a36Sopenharmony_ci break; 64262306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_IPV4_ADDRS: 64362306a36Sopenharmony_ci ipv4_add = (struct nfp_fl_set_ip4_addrs *)a; 64462306a36Sopenharmony_ci merge->ipv4.ipv4_src |= ipv4_add->ipv4_src_mask; 64562306a36Sopenharmony_ci merge->ipv4.ipv4_dst |= ipv4_add->ipv4_dst_mask; 64662306a36Sopenharmony_ci break; 64762306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_IPV4_TTL_TOS: 64862306a36Sopenharmony_ci ipv4_ttl_tos = (struct nfp_fl_set_ip4_ttl_tos *)a; 64962306a36Sopenharmony_ci merge->ipv4.ip_ext.ttl |= ipv4_ttl_tos->ipv4_ttl_mask; 65062306a36Sopenharmony_ci merge->ipv4.ip_ext.tos |= ipv4_ttl_tos->ipv4_tos_mask; 65162306a36Sopenharmony_ci break; 65262306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_IPV6_SRC: 65362306a36Sopenharmony_ci ipv6_add = (struct nfp_fl_set_ipv6_addr *)a; 65462306a36Sopenharmony_ci for (i = 0; i < 4; i++) 65562306a36Sopenharmony_ci merge->ipv6.ipv6_src.in6_u.u6_addr32[i] |= 65662306a36Sopenharmony_ci ipv6_add->ipv6[i].mask; 65762306a36Sopenharmony_ci break; 65862306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_IPV6_DST: 65962306a36Sopenharmony_ci ipv6_add = (struct nfp_fl_set_ipv6_addr *)a; 66062306a36Sopenharmony_ci for (i = 0; i < 4; i++) 66162306a36Sopenharmony_ci merge->ipv6.ipv6_dst.in6_u.u6_addr32[i] |= 66262306a36Sopenharmony_ci ipv6_add->ipv6[i].mask; 66362306a36Sopenharmony_ci break; 66462306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_IPV6_TC_HL_FL: 66562306a36Sopenharmony_ci ipv6_tc_hl_fl = (struct nfp_fl_set_ipv6_tc_hl_fl *)a; 66662306a36Sopenharmony_ci merge->ipv6.ip_ext.ttl |= 66762306a36Sopenharmony_ci ipv6_tc_hl_fl->ipv6_hop_limit_mask; 66862306a36Sopenharmony_ci merge->ipv6.ip_ext.tos |= ipv6_tc_hl_fl->ipv6_tc_mask; 66962306a36Sopenharmony_ci merge->ipv6.ipv6_flow_label_exthdr |= 67062306a36Sopenharmony_ci ipv6_tc_hl_fl->ipv6_label_mask; 67162306a36Sopenharmony_ci break; 67262306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_UDP: 67362306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_SET_TCP: 67462306a36Sopenharmony_ci tport = (struct nfp_fl_set_tport *)a; 67562306a36Sopenharmony_ci ports = (u8 *)&merge->l4.port_src; 67662306a36Sopenharmony_ci for (i = 0; i < 4; i++) 67762306a36Sopenharmony_ci ports[i] |= tport->tp_port_mask[i]; 67862306a36Sopenharmony_ci break; 67962306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_PRE_TUNNEL: 68062306a36Sopenharmony_ci pre_tun = (struct nfp_fl_pre_tunnel *)a; 68162306a36Sopenharmony_ci ipv6_tun = be16_to_cpu(pre_tun->flags) & 68262306a36Sopenharmony_ci NFP_FL_PRE_TUN_IPV6; 68362306a36Sopenharmony_ci break; 68462306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_PRE_LAG: 68562306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_PUSH_GENEVE: 68662306a36Sopenharmony_ci break; 68762306a36Sopenharmony_ci default: 68862306a36Sopenharmony_ci return -EOPNOTSUPP; 68962306a36Sopenharmony_ci } 69062306a36Sopenharmony_ci 69162306a36Sopenharmony_ci act_off += a->len_lw << NFP_FL_LW_SIZ; 69262306a36Sopenharmony_ci } 69362306a36Sopenharmony_ci 69462306a36Sopenharmony_ci if (last_act_id) 69562306a36Sopenharmony_ci *last_act_id = act_id; 69662306a36Sopenharmony_ci 69762306a36Sopenharmony_ci return 0; 69862306a36Sopenharmony_ci} 69962306a36Sopenharmony_ci 70062306a36Sopenharmony_cistatic int 70162306a36Sopenharmony_cinfp_flower_populate_merge_match(struct nfp_fl_payload *flow, 70262306a36Sopenharmony_ci struct nfp_flower_merge_check *merge, 70362306a36Sopenharmony_ci bool extra_fields) 70462306a36Sopenharmony_ci{ 70562306a36Sopenharmony_ci struct nfp_flower_meta_tci *meta_tci; 70662306a36Sopenharmony_ci u8 *mask = flow->mask_data; 70762306a36Sopenharmony_ci u8 key_layer, match_size; 70862306a36Sopenharmony_ci 70962306a36Sopenharmony_ci memset(merge, 0, sizeof(struct nfp_flower_merge_check)); 71062306a36Sopenharmony_ci 71162306a36Sopenharmony_ci meta_tci = (struct nfp_flower_meta_tci *)mask; 71262306a36Sopenharmony_ci key_layer = meta_tci->nfp_flow_key_layer; 71362306a36Sopenharmony_ci 71462306a36Sopenharmony_ci if (key_layer & ~NFP_FLOWER_MERGE_FIELDS && !extra_fields) 71562306a36Sopenharmony_ci return -EOPNOTSUPP; 71662306a36Sopenharmony_ci 71762306a36Sopenharmony_ci merge->tci = meta_tci->tci; 71862306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_meta_tci); 71962306a36Sopenharmony_ci 72062306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_EXT_META) 72162306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_ext_meta); 72262306a36Sopenharmony_ci 72362306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_in_port); 72462306a36Sopenharmony_ci 72562306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_MAC) { 72662306a36Sopenharmony_ci match_size = sizeof(struct nfp_flower_mac_mpls); 72762306a36Sopenharmony_ci memcpy(&merge->l2, mask, match_size); 72862306a36Sopenharmony_ci mask += match_size; 72962306a36Sopenharmony_ci } 73062306a36Sopenharmony_ci 73162306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_TP) { 73262306a36Sopenharmony_ci match_size = sizeof(struct nfp_flower_tp_ports); 73362306a36Sopenharmony_ci memcpy(&merge->l4, mask, match_size); 73462306a36Sopenharmony_ci mask += match_size; 73562306a36Sopenharmony_ci } 73662306a36Sopenharmony_ci 73762306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_IPV4) { 73862306a36Sopenharmony_ci match_size = sizeof(struct nfp_flower_ipv4); 73962306a36Sopenharmony_ci memcpy(&merge->ipv4, mask, match_size); 74062306a36Sopenharmony_ci } 74162306a36Sopenharmony_ci 74262306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_IPV6) { 74362306a36Sopenharmony_ci match_size = sizeof(struct nfp_flower_ipv6); 74462306a36Sopenharmony_ci memcpy(&merge->ipv6, mask, match_size); 74562306a36Sopenharmony_ci } 74662306a36Sopenharmony_ci 74762306a36Sopenharmony_ci return 0; 74862306a36Sopenharmony_ci} 74962306a36Sopenharmony_ci 75062306a36Sopenharmony_cistatic int 75162306a36Sopenharmony_cinfp_flower_can_merge(struct nfp_fl_payload *sub_flow1, 75262306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow2) 75362306a36Sopenharmony_ci{ 75462306a36Sopenharmony_ci /* Two flows can be merged if sub_flow2 only matches on bits that are 75562306a36Sopenharmony_ci * either matched by sub_flow1 or set by a sub_flow1 action. This 75662306a36Sopenharmony_ci * ensures that every packet that hits sub_flow1 and recirculates is 75762306a36Sopenharmony_ci * guaranteed to hit sub_flow2. 75862306a36Sopenharmony_ci */ 75962306a36Sopenharmony_ci struct nfp_flower_merge_check sub_flow1_merge, sub_flow2_merge; 76062306a36Sopenharmony_ci int err, act_out = 0; 76162306a36Sopenharmony_ci u8 last_act_id = 0; 76262306a36Sopenharmony_ci 76362306a36Sopenharmony_ci err = nfp_flower_populate_merge_match(sub_flow1, &sub_flow1_merge, 76462306a36Sopenharmony_ci true); 76562306a36Sopenharmony_ci if (err) 76662306a36Sopenharmony_ci return err; 76762306a36Sopenharmony_ci 76862306a36Sopenharmony_ci err = nfp_flower_populate_merge_match(sub_flow2, &sub_flow2_merge, 76962306a36Sopenharmony_ci false); 77062306a36Sopenharmony_ci if (err) 77162306a36Sopenharmony_ci return err; 77262306a36Sopenharmony_ci 77362306a36Sopenharmony_ci err = nfp_flower_update_merge_with_actions(sub_flow1, &sub_flow1_merge, 77462306a36Sopenharmony_ci &last_act_id, &act_out); 77562306a36Sopenharmony_ci if (err) 77662306a36Sopenharmony_ci return err; 77762306a36Sopenharmony_ci 77862306a36Sopenharmony_ci /* Must only be 1 output action and it must be the last in sequence. */ 77962306a36Sopenharmony_ci if (act_out != 1 || last_act_id != NFP_FL_ACTION_OPCODE_OUTPUT) 78062306a36Sopenharmony_ci return -EOPNOTSUPP; 78162306a36Sopenharmony_ci 78262306a36Sopenharmony_ci /* Reject merge if sub_flow2 matches on something that is not matched 78362306a36Sopenharmony_ci * on or set in an action by sub_flow1. 78462306a36Sopenharmony_ci */ 78562306a36Sopenharmony_ci err = bitmap_andnot(sub_flow2_merge.vals, sub_flow2_merge.vals, 78662306a36Sopenharmony_ci sub_flow1_merge.vals, 78762306a36Sopenharmony_ci sizeof(struct nfp_flower_merge_check) * 8); 78862306a36Sopenharmony_ci if (err) 78962306a36Sopenharmony_ci return -EINVAL; 79062306a36Sopenharmony_ci 79162306a36Sopenharmony_ci return 0; 79262306a36Sopenharmony_ci} 79362306a36Sopenharmony_ci 79462306a36Sopenharmony_cistatic unsigned int 79562306a36Sopenharmony_cinfp_flower_copy_pre_actions(char *act_dst, char *act_src, int len, 79662306a36Sopenharmony_ci bool *tunnel_act) 79762306a36Sopenharmony_ci{ 79862306a36Sopenharmony_ci unsigned int act_off = 0, act_len; 79962306a36Sopenharmony_ci struct nfp_fl_act_head *a; 80062306a36Sopenharmony_ci u8 act_id = 0; 80162306a36Sopenharmony_ci 80262306a36Sopenharmony_ci while (act_off < len) { 80362306a36Sopenharmony_ci a = (struct nfp_fl_act_head *)&act_src[act_off]; 80462306a36Sopenharmony_ci act_len = a->len_lw << NFP_FL_LW_SIZ; 80562306a36Sopenharmony_ci act_id = a->jump_id; 80662306a36Sopenharmony_ci 80762306a36Sopenharmony_ci switch (act_id) { 80862306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_PRE_TUNNEL: 80962306a36Sopenharmony_ci if (tunnel_act) 81062306a36Sopenharmony_ci *tunnel_act = true; 81162306a36Sopenharmony_ci fallthrough; 81262306a36Sopenharmony_ci case NFP_FL_ACTION_OPCODE_PRE_LAG: 81362306a36Sopenharmony_ci memcpy(act_dst + act_off, act_src + act_off, act_len); 81462306a36Sopenharmony_ci break; 81562306a36Sopenharmony_ci default: 81662306a36Sopenharmony_ci return act_off; 81762306a36Sopenharmony_ci } 81862306a36Sopenharmony_ci 81962306a36Sopenharmony_ci act_off += act_len; 82062306a36Sopenharmony_ci } 82162306a36Sopenharmony_ci 82262306a36Sopenharmony_ci return act_off; 82362306a36Sopenharmony_ci} 82462306a36Sopenharmony_ci 82562306a36Sopenharmony_cistatic int 82662306a36Sopenharmony_cinfp_fl_verify_post_tun_acts(char *acts, int len, struct nfp_fl_push_vlan **vlan) 82762306a36Sopenharmony_ci{ 82862306a36Sopenharmony_ci struct nfp_fl_act_head *a; 82962306a36Sopenharmony_ci unsigned int act_off = 0; 83062306a36Sopenharmony_ci 83162306a36Sopenharmony_ci while (act_off < len) { 83262306a36Sopenharmony_ci a = (struct nfp_fl_act_head *)&acts[act_off]; 83362306a36Sopenharmony_ci 83462306a36Sopenharmony_ci if (a->jump_id == NFP_FL_ACTION_OPCODE_PUSH_VLAN && !act_off) 83562306a36Sopenharmony_ci *vlan = (struct nfp_fl_push_vlan *)a; 83662306a36Sopenharmony_ci else if (a->jump_id != NFP_FL_ACTION_OPCODE_OUTPUT) 83762306a36Sopenharmony_ci return -EOPNOTSUPP; 83862306a36Sopenharmony_ci 83962306a36Sopenharmony_ci act_off += a->len_lw << NFP_FL_LW_SIZ; 84062306a36Sopenharmony_ci } 84162306a36Sopenharmony_ci 84262306a36Sopenharmony_ci /* Ensure any VLAN push also has an egress action. */ 84362306a36Sopenharmony_ci if (*vlan && act_off <= sizeof(struct nfp_fl_push_vlan)) 84462306a36Sopenharmony_ci return -EOPNOTSUPP; 84562306a36Sopenharmony_ci 84662306a36Sopenharmony_ci return 0; 84762306a36Sopenharmony_ci} 84862306a36Sopenharmony_ci 84962306a36Sopenharmony_cistatic int 85062306a36Sopenharmony_cinfp_fl_push_vlan_after_tun(char *acts, int len, struct nfp_fl_push_vlan *vlan) 85162306a36Sopenharmony_ci{ 85262306a36Sopenharmony_ci struct nfp_fl_set_tun *tun; 85362306a36Sopenharmony_ci struct nfp_fl_act_head *a; 85462306a36Sopenharmony_ci unsigned int act_off = 0; 85562306a36Sopenharmony_ci 85662306a36Sopenharmony_ci while (act_off < len) { 85762306a36Sopenharmony_ci a = (struct nfp_fl_act_head *)&acts[act_off]; 85862306a36Sopenharmony_ci 85962306a36Sopenharmony_ci if (a->jump_id == NFP_FL_ACTION_OPCODE_SET_TUNNEL) { 86062306a36Sopenharmony_ci tun = (struct nfp_fl_set_tun *)a; 86162306a36Sopenharmony_ci tun->outer_vlan_tpid = vlan->vlan_tpid; 86262306a36Sopenharmony_ci tun->outer_vlan_tci = vlan->vlan_tci; 86362306a36Sopenharmony_ci 86462306a36Sopenharmony_ci return 0; 86562306a36Sopenharmony_ci } 86662306a36Sopenharmony_ci 86762306a36Sopenharmony_ci act_off += a->len_lw << NFP_FL_LW_SIZ; 86862306a36Sopenharmony_ci } 86962306a36Sopenharmony_ci 87062306a36Sopenharmony_ci /* Return error if no tunnel action is found. */ 87162306a36Sopenharmony_ci return -EOPNOTSUPP; 87262306a36Sopenharmony_ci} 87362306a36Sopenharmony_ci 87462306a36Sopenharmony_cistatic int 87562306a36Sopenharmony_cinfp_flower_merge_action(struct nfp_fl_payload *sub_flow1, 87662306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow2, 87762306a36Sopenharmony_ci struct nfp_fl_payload *merge_flow) 87862306a36Sopenharmony_ci{ 87962306a36Sopenharmony_ci unsigned int sub1_act_len, sub2_act_len, pre_off1, pre_off2; 88062306a36Sopenharmony_ci struct nfp_fl_push_vlan *post_tun_push_vlan = NULL; 88162306a36Sopenharmony_ci bool tunnel_act = false; 88262306a36Sopenharmony_ci char *merge_act; 88362306a36Sopenharmony_ci int err; 88462306a36Sopenharmony_ci 88562306a36Sopenharmony_ci /* The last action of sub_flow1 must be output - do not merge this. */ 88662306a36Sopenharmony_ci sub1_act_len = sub_flow1->meta.act_len - sizeof(struct nfp_fl_output); 88762306a36Sopenharmony_ci sub2_act_len = sub_flow2->meta.act_len; 88862306a36Sopenharmony_ci 88962306a36Sopenharmony_ci if (!sub2_act_len) 89062306a36Sopenharmony_ci return -EINVAL; 89162306a36Sopenharmony_ci 89262306a36Sopenharmony_ci if (sub1_act_len + sub2_act_len > NFP_FL_MAX_A_SIZ) 89362306a36Sopenharmony_ci return -EINVAL; 89462306a36Sopenharmony_ci 89562306a36Sopenharmony_ci /* A shortcut can only be applied if there is a single action. */ 89662306a36Sopenharmony_ci if (sub1_act_len) 89762306a36Sopenharmony_ci merge_flow->meta.shortcut = cpu_to_be32(NFP_FL_SC_ACT_NULL); 89862306a36Sopenharmony_ci else 89962306a36Sopenharmony_ci merge_flow->meta.shortcut = sub_flow2->meta.shortcut; 90062306a36Sopenharmony_ci 90162306a36Sopenharmony_ci merge_flow->meta.act_len = sub1_act_len + sub2_act_len; 90262306a36Sopenharmony_ci merge_act = merge_flow->action_data; 90362306a36Sopenharmony_ci 90462306a36Sopenharmony_ci /* Copy any pre-actions to the start of merge flow action list. */ 90562306a36Sopenharmony_ci pre_off1 = nfp_flower_copy_pre_actions(merge_act, 90662306a36Sopenharmony_ci sub_flow1->action_data, 90762306a36Sopenharmony_ci sub1_act_len, &tunnel_act); 90862306a36Sopenharmony_ci merge_act += pre_off1; 90962306a36Sopenharmony_ci sub1_act_len -= pre_off1; 91062306a36Sopenharmony_ci pre_off2 = nfp_flower_copy_pre_actions(merge_act, 91162306a36Sopenharmony_ci sub_flow2->action_data, 91262306a36Sopenharmony_ci sub2_act_len, NULL); 91362306a36Sopenharmony_ci merge_act += pre_off2; 91462306a36Sopenharmony_ci sub2_act_len -= pre_off2; 91562306a36Sopenharmony_ci 91662306a36Sopenharmony_ci /* FW does a tunnel push when egressing, therefore, if sub_flow 1 pushes 91762306a36Sopenharmony_ci * a tunnel, there are restrictions on what sub_flow 2 actions lead to a 91862306a36Sopenharmony_ci * valid merge. 91962306a36Sopenharmony_ci */ 92062306a36Sopenharmony_ci if (tunnel_act) { 92162306a36Sopenharmony_ci char *post_tun_acts = &sub_flow2->action_data[pre_off2]; 92262306a36Sopenharmony_ci 92362306a36Sopenharmony_ci err = nfp_fl_verify_post_tun_acts(post_tun_acts, sub2_act_len, 92462306a36Sopenharmony_ci &post_tun_push_vlan); 92562306a36Sopenharmony_ci if (err) 92662306a36Sopenharmony_ci return err; 92762306a36Sopenharmony_ci 92862306a36Sopenharmony_ci if (post_tun_push_vlan) { 92962306a36Sopenharmony_ci pre_off2 += sizeof(*post_tun_push_vlan); 93062306a36Sopenharmony_ci sub2_act_len -= sizeof(*post_tun_push_vlan); 93162306a36Sopenharmony_ci } 93262306a36Sopenharmony_ci } 93362306a36Sopenharmony_ci 93462306a36Sopenharmony_ci /* Copy remaining actions from sub_flows 1 and 2. */ 93562306a36Sopenharmony_ci memcpy(merge_act, sub_flow1->action_data + pre_off1, sub1_act_len); 93662306a36Sopenharmony_ci 93762306a36Sopenharmony_ci if (post_tun_push_vlan) { 93862306a36Sopenharmony_ci /* Update tunnel action in merge to include VLAN push. */ 93962306a36Sopenharmony_ci err = nfp_fl_push_vlan_after_tun(merge_act, sub1_act_len, 94062306a36Sopenharmony_ci post_tun_push_vlan); 94162306a36Sopenharmony_ci if (err) 94262306a36Sopenharmony_ci return err; 94362306a36Sopenharmony_ci 94462306a36Sopenharmony_ci merge_flow->meta.act_len -= sizeof(*post_tun_push_vlan); 94562306a36Sopenharmony_ci } 94662306a36Sopenharmony_ci 94762306a36Sopenharmony_ci merge_act += sub1_act_len; 94862306a36Sopenharmony_ci memcpy(merge_act, sub_flow2->action_data + pre_off2, sub2_act_len); 94962306a36Sopenharmony_ci 95062306a36Sopenharmony_ci return 0; 95162306a36Sopenharmony_ci} 95262306a36Sopenharmony_ci 95362306a36Sopenharmony_ci/* Flow link code should only be accessed under RTNL. */ 95462306a36Sopenharmony_cistatic void nfp_flower_unlink_flow(struct nfp_fl_payload_link *link) 95562306a36Sopenharmony_ci{ 95662306a36Sopenharmony_ci list_del(&link->merge_flow.list); 95762306a36Sopenharmony_ci list_del(&link->sub_flow.list); 95862306a36Sopenharmony_ci kfree(link); 95962306a36Sopenharmony_ci} 96062306a36Sopenharmony_ci 96162306a36Sopenharmony_cistatic void nfp_flower_unlink_flows(struct nfp_fl_payload *merge_flow, 96262306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow) 96362306a36Sopenharmony_ci{ 96462306a36Sopenharmony_ci struct nfp_fl_payload_link *link; 96562306a36Sopenharmony_ci 96662306a36Sopenharmony_ci list_for_each_entry(link, &merge_flow->linked_flows, merge_flow.list) 96762306a36Sopenharmony_ci if (link->sub_flow.flow == sub_flow) { 96862306a36Sopenharmony_ci nfp_flower_unlink_flow(link); 96962306a36Sopenharmony_ci return; 97062306a36Sopenharmony_ci } 97162306a36Sopenharmony_ci} 97262306a36Sopenharmony_ci 97362306a36Sopenharmony_cistatic int nfp_flower_link_flows(struct nfp_fl_payload *merge_flow, 97462306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow) 97562306a36Sopenharmony_ci{ 97662306a36Sopenharmony_ci struct nfp_fl_payload_link *link; 97762306a36Sopenharmony_ci 97862306a36Sopenharmony_ci link = kmalloc(sizeof(*link), GFP_KERNEL); 97962306a36Sopenharmony_ci if (!link) 98062306a36Sopenharmony_ci return -ENOMEM; 98162306a36Sopenharmony_ci 98262306a36Sopenharmony_ci link->merge_flow.flow = merge_flow; 98362306a36Sopenharmony_ci list_add_tail(&link->merge_flow.list, &merge_flow->linked_flows); 98462306a36Sopenharmony_ci link->sub_flow.flow = sub_flow; 98562306a36Sopenharmony_ci list_add_tail(&link->sub_flow.list, &sub_flow->linked_flows); 98662306a36Sopenharmony_ci 98762306a36Sopenharmony_ci return 0; 98862306a36Sopenharmony_ci} 98962306a36Sopenharmony_ci 99062306a36Sopenharmony_ci/** 99162306a36Sopenharmony_ci * nfp_flower_merge_offloaded_flows() - Merge 2 existing flows to single flow. 99262306a36Sopenharmony_ci * @app: Pointer to the APP handle 99362306a36Sopenharmony_ci * @sub_flow1: Initial flow matched to produce merge hint 99462306a36Sopenharmony_ci * @sub_flow2: Post recirculation flow matched in merge hint 99562306a36Sopenharmony_ci * 99662306a36Sopenharmony_ci * Combines 2 flows (if valid) to a single flow, removing the initial from hw 99762306a36Sopenharmony_ci * and offloading the new, merged flow. 99862306a36Sopenharmony_ci * 99962306a36Sopenharmony_ci * Return: negative value on error, 0 in success. 100062306a36Sopenharmony_ci */ 100162306a36Sopenharmony_ciint nfp_flower_merge_offloaded_flows(struct nfp_app *app, 100262306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow1, 100362306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow2) 100462306a36Sopenharmony_ci{ 100562306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 100662306a36Sopenharmony_ci struct nfp_fl_payload *merge_flow; 100762306a36Sopenharmony_ci struct nfp_fl_key_ls merge_key_ls; 100862306a36Sopenharmony_ci struct nfp_merge_info *merge_info; 100962306a36Sopenharmony_ci u64 parent_ctx = 0; 101062306a36Sopenharmony_ci int err; 101162306a36Sopenharmony_ci 101262306a36Sopenharmony_ci if (sub_flow1 == sub_flow2 || 101362306a36Sopenharmony_ci nfp_flower_is_merge_flow(sub_flow1) || 101462306a36Sopenharmony_ci nfp_flower_is_merge_flow(sub_flow2)) 101562306a36Sopenharmony_ci return -EINVAL; 101662306a36Sopenharmony_ci 101762306a36Sopenharmony_ci /* Check if the two flows are already merged */ 101862306a36Sopenharmony_ci parent_ctx = (u64)(be32_to_cpu(sub_flow1->meta.host_ctx_id)) << 32; 101962306a36Sopenharmony_ci parent_ctx |= (u64)(be32_to_cpu(sub_flow2->meta.host_ctx_id)); 102062306a36Sopenharmony_ci if (rhashtable_lookup_fast(&priv->merge_table, 102162306a36Sopenharmony_ci &parent_ctx, merge_table_params)) { 102262306a36Sopenharmony_ci nfp_flower_cmsg_warn(app, "The two flows are already merged.\n"); 102362306a36Sopenharmony_ci return 0; 102462306a36Sopenharmony_ci } 102562306a36Sopenharmony_ci 102662306a36Sopenharmony_ci err = nfp_flower_can_merge(sub_flow1, sub_flow2); 102762306a36Sopenharmony_ci if (err) 102862306a36Sopenharmony_ci return err; 102962306a36Sopenharmony_ci 103062306a36Sopenharmony_ci merge_key_ls.key_size = sub_flow1->meta.key_len; 103162306a36Sopenharmony_ci 103262306a36Sopenharmony_ci merge_flow = nfp_flower_allocate_new(&merge_key_ls); 103362306a36Sopenharmony_ci if (!merge_flow) 103462306a36Sopenharmony_ci return -ENOMEM; 103562306a36Sopenharmony_ci 103662306a36Sopenharmony_ci merge_flow->tc_flower_cookie = (unsigned long)merge_flow; 103762306a36Sopenharmony_ci merge_flow->ingress_dev = sub_flow1->ingress_dev; 103862306a36Sopenharmony_ci 103962306a36Sopenharmony_ci memcpy(merge_flow->unmasked_data, sub_flow1->unmasked_data, 104062306a36Sopenharmony_ci sub_flow1->meta.key_len); 104162306a36Sopenharmony_ci memcpy(merge_flow->mask_data, sub_flow1->mask_data, 104262306a36Sopenharmony_ci sub_flow1->meta.mask_len); 104362306a36Sopenharmony_ci 104462306a36Sopenharmony_ci err = nfp_flower_merge_action(sub_flow1, sub_flow2, merge_flow); 104562306a36Sopenharmony_ci if (err) 104662306a36Sopenharmony_ci goto err_destroy_merge_flow; 104762306a36Sopenharmony_ci 104862306a36Sopenharmony_ci err = nfp_flower_link_flows(merge_flow, sub_flow1); 104962306a36Sopenharmony_ci if (err) 105062306a36Sopenharmony_ci goto err_destroy_merge_flow; 105162306a36Sopenharmony_ci 105262306a36Sopenharmony_ci err = nfp_flower_link_flows(merge_flow, sub_flow2); 105362306a36Sopenharmony_ci if (err) 105462306a36Sopenharmony_ci goto err_unlink_sub_flow1; 105562306a36Sopenharmony_ci 105662306a36Sopenharmony_ci err = nfp_compile_flow_metadata(app, merge_flow->tc_flower_cookie, merge_flow, 105762306a36Sopenharmony_ci merge_flow->ingress_dev, NULL); 105862306a36Sopenharmony_ci if (err) 105962306a36Sopenharmony_ci goto err_unlink_sub_flow2; 106062306a36Sopenharmony_ci 106162306a36Sopenharmony_ci err = rhashtable_insert_fast(&priv->flow_table, &merge_flow->fl_node, 106262306a36Sopenharmony_ci nfp_flower_table_params); 106362306a36Sopenharmony_ci if (err) 106462306a36Sopenharmony_ci goto err_release_metadata; 106562306a36Sopenharmony_ci 106662306a36Sopenharmony_ci merge_info = kmalloc(sizeof(*merge_info), GFP_KERNEL); 106762306a36Sopenharmony_ci if (!merge_info) { 106862306a36Sopenharmony_ci err = -ENOMEM; 106962306a36Sopenharmony_ci goto err_remove_rhash; 107062306a36Sopenharmony_ci } 107162306a36Sopenharmony_ci merge_info->parent_ctx = parent_ctx; 107262306a36Sopenharmony_ci err = rhashtable_insert_fast(&priv->merge_table, &merge_info->ht_node, 107362306a36Sopenharmony_ci merge_table_params); 107462306a36Sopenharmony_ci if (err) 107562306a36Sopenharmony_ci goto err_destroy_merge_info; 107662306a36Sopenharmony_ci 107762306a36Sopenharmony_ci err = nfp_flower_xmit_flow(app, merge_flow, 107862306a36Sopenharmony_ci NFP_FLOWER_CMSG_TYPE_FLOW_MOD); 107962306a36Sopenharmony_ci if (err) 108062306a36Sopenharmony_ci goto err_remove_merge_info; 108162306a36Sopenharmony_ci 108262306a36Sopenharmony_ci merge_flow->in_hw = true; 108362306a36Sopenharmony_ci sub_flow1->in_hw = false; 108462306a36Sopenharmony_ci 108562306a36Sopenharmony_ci return 0; 108662306a36Sopenharmony_ci 108762306a36Sopenharmony_cierr_remove_merge_info: 108862306a36Sopenharmony_ci WARN_ON_ONCE(rhashtable_remove_fast(&priv->merge_table, 108962306a36Sopenharmony_ci &merge_info->ht_node, 109062306a36Sopenharmony_ci merge_table_params)); 109162306a36Sopenharmony_cierr_destroy_merge_info: 109262306a36Sopenharmony_ci kfree(merge_info); 109362306a36Sopenharmony_cierr_remove_rhash: 109462306a36Sopenharmony_ci WARN_ON_ONCE(rhashtable_remove_fast(&priv->flow_table, 109562306a36Sopenharmony_ci &merge_flow->fl_node, 109662306a36Sopenharmony_ci nfp_flower_table_params)); 109762306a36Sopenharmony_cierr_release_metadata: 109862306a36Sopenharmony_ci nfp_modify_flow_metadata(app, merge_flow); 109962306a36Sopenharmony_cierr_unlink_sub_flow2: 110062306a36Sopenharmony_ci nfp_flower_unlink_flows(merge_flow, sub_flow2); 110162306a36Sopenharmony_cierr_unlink_sub_flow1: 110262306a36Sopenharmony_ci nfp_flower_unlink_flows(merge_flow, sub_flow1); 110362306a36Sopenharmony_cierr_destroy_merge_flow: 110462306a36Sopenharmony_ci kfree(merge_flow->action_data); 110562306a36Sopenharmony_ci kfree(merge_flow->mask_data); 110662306a36Sopenharmony_ci kfree(merge_flow->unmasked_data); 110762306a36Sopenharmony_ci kfree(merge_flow); 110862306a36Sopenharmony_ci return err; 110962306a36Sopenharmony_ci} 111062306a36Sopenharmony_ci 111162306a36Sopenharmony_ci/** 111262306a36Sopenharmony_ci * nfp_flower_validate_pre_tun_rule() 111362306a36Sopenharmony_ci * @app: Pointer to the APP handle 111462306a36Sopenharmony_ci * @flow: Pointer to NFP flow representation of rule 111562306a36Sopenharmony_ci * @key_ls: Pointer to NFP key layers structure 111662306a36Sopenharmony_ci * @extack: Netlink extended ACK report 111762306a36Sopenharmony_ci * 111862306a36Sopenharmony_ci * Verifies the flow as a pre-tunnel rule. 111962306a36Sopenharmony_ci * 112062306a36Sopenharmony_ci * Return: negative value on error, 0 if verified. 112162306a36Sopenharmony_ci */ 112262306a36Sopenharmony_cistatic int 112362306a36Sopenharmony_cinfp_flower_validate_pre_tun_rule(struct nfp_app *app, 112462306a36Sopenharmony_ci struct nfp_fl_payload *flow, 112562306a36Sopenharmony_ci struct nfp_fl_key_ls *key_ls, 112662306a36Sopenharmony_ci struct netlink_ext_ack *extack) 112762306a36Sopenharmony_ci{ 112862306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 112962306a36Sopenharmony_ci struct nfp_flower_meta_tci *meta_tci; 113062306a36Sopenharmony_ci struct nfp_flower_mac_mpls *mac; 113162306a36Sopenharmony_ci u8 *ext = flow->unmasked_data; 113262306a36Sopenharmony_ci struct nfp_fl_act_head *act; 113362306a36Sopenharmony_ci u8 *mask = flow->mask_data; 113462306a36Sopenharmony_ci bool vlan = false; 113562306a36Sopenharmony_ci int act_offset; 113662306a36Sopenharmony_ci u8 key_layer; 113762306a36Sopenharmony_ci 113862306a36Sopenharmony_ci meta_tci = (struct nfp_flower_meta_tci *)flow->unmasked_data; 113962306a36Sopenharmony_ci key_layer = key_ls->key_layer; 114062306a36Sopenharmony_ci if (!(priv->flower_ext_feats & NFP_FL_FEATS_VLAN_QINQ)) { 114162306a36Sopenharmony_ci if (meta_tci->tci & cpu_to_be16(NFP_FLOWER_MASK_VLAN_PRESENT)) { 114262306a36Sopenharmony_ci u16 vlan_tci = be16_to_cpu(meta_tci->tci); 114362306a36Sopenharmony_ci 114462306a36Sopenharmony_ci vlan_tci &= ~NFP_FLOWER_MASK_VLAN_PRESENT; 114562306a36Sopenharmony_ci flow->pre_tun_rule.vlan_tci = cpu_to_be16(vlan_tci); 114662306a36Sopenharmony_ci vlan = true; 114762306a36Sopenharmony_ci } else { 114862306a36Sopenharmony_ci flow->pre_tun_rule.vlan_tci = cpu_to_be16(0xffff); 114962306a36Sopenharmony_ci } 115062306a36Sopenharmony_ci } 115162306a36Sopenharmony_ci 115262306a36Sopenharmony_ci if (key_layer & ~NFP_FLOWER_PRE_TUN_RULE_FIELDS) { 115362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: too many match fields"); 115462306a36Sopenharmony_ci return -EOPNOTSUPP; 115562306a36Sopenharmony_ci } else if (key_ls->key_layer_two & ~NFP_FLOWER_LAYER2_QINQ) { 115662306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: non-vlan in extended match fields"); 115762306a36Sopenharmony_ci return -EOPNOTSUPP; 115862306a36Sopenharmony_ci } 115962306a36Sopenharmony_ci 116062306a36Sopenharmony_ci if (!(key_layer & NFP_FLOWER_LAYER_MAC)) { 116162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: MAC fields match required"); 116262306a36Sopenharmony_ci return -EOPNOTSUPP; 116362306a36Sopenharmony_ci } 116462306a36Sopenharmony_ci 116562306a36Sopenharmony_ci if (!(key_layer & NFP_FLOWER_LAYER_IPV4) && 116662306a36Sopenharmony_ci !(key_layer & NFP_FLOWER_LAYER_IPV6)) { 116762306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: match on ipv4/ipv6 eth_type must be present"); 116862306a36Sopenharmony_ci return -EOPNOTSUPP; 116962306a36Sopenharmony_ci } 117062306a36Sopenharmony_ci 117162306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_IPV6) 117262306a36Sopenharmony_ci flow->pre_tun_rule.is_ipv6 = true; 117362306a36Sopenharmony_ci else 117462306a36Sopenharmony_ci flow->pre_tun_rule.is_ipv6 = false; 117562306a36Sopenharmony_ci 117662306a36Sopenharmony_ci /* Skip fields known to exist. */ 117762306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_meta_tci); 117862306a36Sopenharmony_ci ext += sizeof(struct nfp_flower_meta_tci); 117962306a36Sopenharmony_ci if (key_ls->key_layer_two) { 118062306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_ext_meta); 118162306a36Sopenharmony_ci ext += sizeof(struct nfp_flower_ext_meta); 118262306a36Sopenharmony_ci } 118362306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_in_port); 118462306a36Sopenharmony_ci ext += sizeof(struct nfp_flower_in_port); 118562306a36Sopenharmony_ci 118662306a36Sopenharmony_ci /* Ensure destination MAC address is fully matched. */ 118762306a36Sopenharmony_ci mac = (struct nfp_flower_mac_mpls *)mask; 118862306a36Sopenharmony_ci if (!is_broadcast_ether_addr(&mac->mac_dst[0])) { 118962306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: dest MAC field must not be masked"); 119062306a36Sopenharmony_ci return -EOPNOTSUPP; 119162306a36Sopenharmony_ci } 119262306a36Sopenharmony_ci 119362306a36Sopenharmony_ci /* Ensure source MAC address is fully matched. This is only needed 119462306a36Sopenharmony_ci * for firmware with the DECAP_V2 feature enabled. Don't do this 119562306a36Sopenharmony_ci * for firmware without this feature to keep old behaviour. 119662306a36Sopenharmony_ci */ 119762306a36Sopenharmony_ci if (priv->flower_ext_feats & NFP_FL_FEATS_DECAP_V2) { 119862306a36Sopenharmony_ci mac = (struct nfp_flower_mac_mpls *)mask; 119962306a36Sopenharmony_ci if (!is_broadcast_ether_addr(&mac->mac_src[0])) { 120062306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, 120162306a36Sopenharmony_ci "unsupported pre-tunnel rule: source MAC field must not be masked"); 120262306a36Sopenharmony_ci return -EOPNOTSUPP; 120362306a36Sopenharmony_ci } 120462306a36Sopenharmony_ci } 120562306a36Sopenharmony_ci 120662306a36Sopenharmony_ci if (mac->mpls_lse) { 120762306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: MPLS not supported"); 120862306a36Sopenharmony_ci return -EOPNOTSUPP; 120962306a36Sopenharmony_ci } 121062306a36Sopenharmony_ci 121162306a36Sopenharmony_ci /* Ensure destination MAC address matches pre_tun_dev. */ 121262306a36Sopenharmony_ci mac = (struct nfp_flower_mac_mpls *)ext; 121362306a36Sopenharmony_ci if (memcmp(&mac->mac_dst[0], flow->pre_tun_rule.dev->dev_addr, 6)) { 121462306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, 121562306a36Sopenharmony_ci "unsupported pre-tunnel rule: dest MAC must match output dev MAC"); 121662306a36Sopenharmony_ci return -EOPNOTSUPP; 121762306a36Sopenharmony_ci } 121862306a36Sopenharmony_ci 121962306a36Sopenharmony_ci /* Save mac addresses in pre_tun_rule entry for later use */ 122062306a36Sopenharmony_ci memcpy(&flow->pre_tun_rule.loc_mac, &mac->mac_dst[0], ETH_ALEN); 122162306a36Sopenharmony_ci memcpy(&flow->pre_tun_rule.rem_mac, &mac->mac_src[0], ETH_ALEN); 122262306a36Sopenharmony_ci 122362306a36Sopenharmony_ci mask += sizeof(struct nfp_flower_mac_mpls); 122462306a36Sopenharmony_ci ext += sizeof(struct nfp_flower_mac_mpls); 122562306a36Sopenharmony_ci if (key_layer & NFP_FLOWER_LAYER_IPV4 || 122662306a36Sopenharmony_ci key_layer & NFP_FLOWER_LAYER_IPV6) { 122762306a36Sopenharmony_ci /* Flags and proto fields have same offset in IPv4 and IPv6. */ 122862306a36Sopenharmony_ci int ip_flags = offsetof(struct nfp_flower_ipv4, ip_ext.flags); 122962306a36Sopenharmony_ci int ip_proto = offsetof(struct nfp_flower_ipv4, ip_ext.proto); 123062306a36Sopenharmony_ci int size; 123162306a36Sopenharmony_ci int i; 123262306a36Sopenharmony_ci 123362306a36Sopenharmony_ci size = key_layer & NFP_FLOWER_LAYER_IPV4 ? 123462306a36Sopenharmony_ci sizeof(struct nfp_flower_ipv4) : 123562306a36Sopenharmony_ci sizeof(struct nfp_flower_ipv6); 123662306a36Sopenharmony_ci 123762306a36Sopenharmony_ci 123862306a36Sopenharmony_ci /* Ensure proto and flags are the only IP layer fields. */ 123962306a36Sopenharmony_ci for (i = 0; i < size; i++) 124062306a36Sopenharmony_ci if (mask[i] && i != ip_flags && i != ip_proto) { 124162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: only flags and proto can be matched in ip header"); 124262306a36Sopenharmony_ci return -EOPNOTSUPP; 124362306a36Sopenharmony_ci } 124462306a36Sopenharmony_ci ext += size; 124562306a36Sopenharmony_ci mask += size; 124662306a36Sopenharmony_ci } 124762306a36Sopenharmony_ci 124862306a36Sopenharmony_ci if ((priv->flower_ext_feats & NFP_FL_FEATS_VLAN_QINQ)) { 124962306a36Sopenharmony_ci if (key_ls->key_layer_two & NFP_FLOWER_LAYER2_QINQ) { 125062306a36Sopenharmony_ci struct nfp_flower_vlan *vlan_tags; 125162306a36Sopenharmony_ci u16 vlan_tpid; 125262306a36Sopenharmony_ci u16 vlan_tci; 125362306a36Sopenharmony_ci 125462306a36Sopenharmony_ci vlan_tags = (struct nfp_flower_vlan *)ext; 125562306a36Sopenharmony_ci 125662306a36Sopenharmony_ci vlan_tci = be16_to_cpu(vlan_tags->outer_tci); 125762306a36Sopenharmony_ci vlan_tpid = be16_to_cpu(vlan_tags->outer_tpid); 125862306a36Sopenharmony_ci 125962306a36Sopenharmony_ci vlan_tci &= ~NFP_FLOWER_MASK_VLAN_PRESENT; 126062306a36Sopenharmony_ci flow->pre_tun_rule.vlan_tci = cpu_to_be16(vlan_tci); 126162306a36Sopenharmony_ci flow->pre_tun_rule.vlan_tpid = cpu_to_be16(vlan_tpid); 126262306a36Sopenharmony_ci vlan = true; 126362306a36Sopenharmony_ci } else { 126462306a36Sopenharmony_ci flow->pre_tun_rule.vlan_tci = cpu_to_be16(0xffff); 126562306a36Sopenharmony_ci flow->pre_tun_rule.vlan_tpid = cpu_to_be16(0xffff); 126662306a36Sopenharmony_ci } 126762306a36Sopenharmony_ci } 126862306a36Sopenharmony_ci 126962306a36Sopenharmony_ci /* Action must be a single egress or pop_vlan and egress. */ 127062306a36Sopenharmony_ci act_offset = 0; 127162306a36Sopenharmony_ci act = (struct nfp_fl_act_head *)&flow->action_data[act_offset]; 127262306a36Sopenharmony_ci if (vlan) { 127362306a36Sopenharmony_ci if (act->jump_id != NFP_FL_ACTION_OPCODE_POP_VLAN) { 127462306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: match on VLAN must have VLAN pop as first action"); 127562306a36Sopenharmony_ci return -EOPNOTSUPP; 127662306a36Sopenharmony_ci } 127762306a36Sopenharmony_ci 127862306a36Sopenharmony_ci act_offset += act->len_lw << NFP_FL_LW_SIZ; 127962306a36Sopenharmony_ci act = (struct nfp_fl_act_head *)&flow->action_data[act_offset]; 128062306a36Sopenharmony_ci } 128162306a36Sopenharmony_ci 128262306a36Sopenharmony_ci if (act->jump_id != NFP_FL_ACTION_OPCODE_OUTPUT) { 128362306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: non egress action detected where egress was expected"); 128462306a36Sopenharmony_ci return -EOPNOTSUPP; 128562306a36Sopenharmony_ci } 128662306a36Sopenharmony_ci 128762306a36Sopenharmony_ci act_offset += act->len_lw << NFP_FL_LW_SIZ; 128862306a36Sopenharmony_ci 128962306a36Sopenharmony_ci /* Ensure there are no more actions after egress. */ 129062306a36Sopenharmony_ci if (act_offset != flow->meta.act_len) { 129162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "unsupported pre-tunnel rule: egress is not the last action"); 129262306a36Sopenharmony_ci return -EOPNOTSUPP; 129362306a36Sopenharmony_ci } 129462306a36Sopenharmony_ci 129562306a36Sopenharmony_ci return 0; 129662306a36Sopenharmony_ci} 129762306a36Sopenharmony_ci 129862306a36Sopenharmony_cistatic bool offload_pre_check(struct flow_cls_offload *flow) 129962306a36Sopenharmony_ci{ 130062306a36Sopenharmony_ci struct flow_rule *rule = flow_cls_offload_flow_rule(flow); 130162306a36Sopenharmony_ci struct flow_dissector *dissector = rule->match.dissector; 130262306a36Sopenharmony_ci struct flow_match_ct ct; 130362306a36Sopenharmony_ci 130462306a36Sopenharmony_ci if (dissector->used_keys & BIT_ULL(FLOW_DISSECTOR_KEY_CT)) { 130562306a36Sopenharmony_ci flow_rule_match_ct(rule, &ct); 130662306a36Sopenharmony_ci /* Allow special case where CT match is all 0 */ 130762306a36Sopenharmony_ci if (memchr_inv(ct.key, 0, sizeof(*ct.key))) 130862306a36Sopenharmony_ci return false; 130962306a36Sopenharmony_ci } 131062306a36Sopenharmony_ci 131162306a36Sopenharmony_ci if (flow->common.chain_index) 131262306a36Sopenharmony_ci return false; 131362306a36Sopenharmony_ci 131462306a36Sopenharmony_ci return true; 131562306a36Sopenharmony_ci} 131662306a36Sopenharmony_ci 131762306a36Sopenharmony_ci/** 131862306a36Sopenharmony_ci * nfp_flower_add_offload() - Adds a new flow to hardware. 131962306a36Sopenharmony_ci * @app: Pointer to the APP handle 132062306a36Sopenharmony_ci * @netdev: netdev structure. 132162306a36Sopenharmony_ci * @flow: TC flower classifier offload structure. 132262306a36Sopenharmony_ci * 132362306a36Sopenharmony_ci * Adds a new flow to the repeated hash structure and action payload. 132462306a36Sopenharmony_ci * 132562306a36Sopenharmony_ci * Return: negative value on error, 0 if configured successfully. 132662306a36Sopenharmony_ci */ 132762306a36Sopenharmony_cistatic int 132862306a36Sopenharmony_cinfp_flower_add_offload(struct nfp_app *app, struct net_device *netdev, 132962306a36Sopenharmony_ci struct flow_cls_offload *flow) 133062306a36Sopenharmony_ci{ 133162306a36Sopenharmony_ci struct flow_rule *rule = flow_cls_offload_flow_rule(flow); 133262306a36Sopenharmony_ci enum nfp_flower_tun_type tun_type = NFP_FL_TUNNEL_NONE; 133362306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 133462306a36Sopenharmony_ci struct netlink_ext_ack *extack = NULL; 133562306a36Sopenharmony_ci struct nfp_fl_payload *flow_pay; 133662306a36Sopenharmony_ci struct nfp_fl_key_ls *key_layer; 133762306a36Sopenharmony_ci struct nfp_port *port = NULL; 133862306a36Sopenharmony_ci int err; 133962306a36Sopenharmony_ci 134062306a36Sopenharmony_ci extack = flow->common.extack; 134162306a36Sopenharmony_ci if (nfp_netdev_is_nfp_repr(netdev)) 134262306a36Sopenharmony_ci port = nfp_port_from_netdev(netdev); 134362306a36Sopenharmony_ci 134462306a36Sopenharmony_ci if (is_pre_ct_flow(flow)) 134562306a36Sopenharmony_ci return nfp_fl_ct_handle_pre_ct(priv, netdev, flow, extack, NULL); 134662306a36Sopenharmony_ci 134762306a36Sopenharmony_ci if (is_post_ct_flow(flow)) 134862306a36Sopenharmony_ci return nfp_fl_ct_handle_post_ct(priv, netdev, flow, extack); 134962306a36Sopenharmony_ci 135062306a36Sopenharmony_ci if (!offload_pre_check(flow)) 135162306a36Sopenharmony_ci return -EOPNOTSUPP; 135262306a36Sopenharmony_ci 135362306a36Sopenharmony_ci key_layer = kmalloc(sizeof(*key_layer), GFP_KERNEL); 135462306a36Sopenharmony_ci if (!key_layer) 135562306a36Sopenharmony_ci return -ENOMEM; 135662306a36Sopenharmony_ci 135762306a36Sopenharmony_ci err = nfp_flower_calculate_key_layers(app, netdev, key_layer, rule, 135862306a36Sopenharmony_ci &tun_type, extack); 135962306a36Sopenharmony_ci if (err) 136062306a36Sopenharmony_ci goto err_free_key_ls; 136162306a36Sopenharmony_ci 136262306a36Sopenharmony_ci flow_pay = nfp_flower_allocate_new(key_layer); 136362306a36Sopenharmony_ci if (!flow_pay) { 136462306a36Sopenharmony_ci err = -ENOMEM; 136562306a36Sopenharmony_ci goto err_free_key_ls; 136662306a36Sopenharmony_ci } 136762306a36Sopenharmony_ci 136862306a36Sopenharmony_ci err = nfp_flower_compile_flow_match(app, rule, key_layer, netdev, 136962306a36Sopenharmony_ci flow_pay, tun_type, extack); 137062306a36Sopenharmony_ci if (err) 137162306a36Sopenharmony_ci goto err_destroy_flow; 137262306a36Sopenharmony_ci 137362306a36Sopenharmony_ci err = nfp_flower_compile_action(app, rule, netdev, flow_pay, extack); 137462306a36Sopenharmony_ci if (err) 137562306a36Sopenharmony_ci goto err_destroy_flow; 137662306a36Sopenharmony_ci 137762306a36Sopenharmony_ci if (flow_pay->pre_tun_rule.dev) { 137862306a36Sopenharmony_ci err = nfp_flower_validate_pre_tun_rule(app, flow_pay, key_layer, extack); 137962306a36Sopenharmony_ci if (err) 138062306a36Sopenharmony_ci goto err_destroy_flow; 138162306a36Sopenharmony_ci } 138262306a36Sopenharmony_ci 138362306a36Sopenharmony_ci err = nfp_compile_flow_metadata(app, flow->cookie, flow_pay, netdev, extack); 138462306a36Sopenharmony_ci if (err) 138562306a36Sopenharmony_ci goto err_destroy_flow; 138662306a36Sopenharmony_ci 138762306a36Sopenharmony_ci flow_pay->tc_flower_cookie = flow->cookie; 138862306a36Sopenharmony_ci err = rhashtable_insert_fast(&priv->flow_table, &flow_pay->fl_node, 138962306a36Sopenharmony_ci nfp_flower_table_params); 139062306a36Sopenharmony_ci if (err) { 139162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "invalid entry: cannot insert flow into tables for offloads"); 139262306a36Sopenharmony_ci goto err_release_metadata; 139362306a36Sopenharmony_ci } 139462306a36Sopenharmony_ci 139562306a36Sopenharmony_ci if (flow_pay->pre_tun_rule.dev) { 139662306a36Sopenharmony_ci if (priv->flower_ext_feats & NFP_FL_FEATS_DECAP_V2) { 139762306a36Sopenharmony_ci struct nfp_predt_entry *predt; 139862306a36Sopenharmony_ci 139962306a36Sopenharmony_ci predt = kzalloc(sizeof(*predt), GFP_KERNEL); 140062306a36Sopenharmony_ci if (!predt) { 140162306a36Sopenharmony_ci err = -ENOMEM; 140262306a36Sopenharmony_ci goto err_remove_rhash; 140362306a36Sopenharmony_ci } 140462306a36Sopenharmony_ci predt->flow_pay = flow_pay; 140562306a36Sopenharmony_ci INIT_LIST_HEAD(&predt->nn_list); 140662306a36Sopenharmony_ci spin_lock_bh(&priv->predt_lock); 140762306a36Sopenharmony_ci list_add(&predt->list_head, &priv->predt_list); 140862306a36Sopenharmony_ci flow_pay->pre_tun_rule.predt = predt; 140962306a36Sopenharmony_ci nfp_tun_link_and_update_nn_entries(app, predt); 141062306a36Sopenharmony_ci spin_unlock_bh(&priv->predt_lock); 141162306a36Sopenharmony_ci } else { 141262306a36Sopenharmony_ci err = nfp_flower_xmit_pre_tun_flow(app, flow_pay); 141362306a36Sopenharmony_ci } 141462306a36Sopenharmony_ci } else { 141562306a36Sopenharmony_ci err = nfp_flower_xmit_flow(app, flow_pay, 141662306a36Sopenharmony_ci NFP_FLOWER_CMSG_TYPE_FLOW_ADD); 141762306a36Sopenharmony_ci } 141862306a36Sopenharmony_ci 141962306a36Sopenharmony_ci if (err) 142062306a36Sopenharmony_ci goto err_remove_rhash; 142162306a36Sopenharmony_ci 142262306a36Sopenharmony_ci if (port) 142362306a36Sopenharmony_ci port->tc_offload_cnt++; 142462306a36Sopenharmony_ci 142562306a36Sopenharmony_ci flow_pay->in_hw = true; 142662306a36Sopenharmony_ci 142762306a36Sopenharmony_ci /* Deallocate flow payload when flower rule has been destroyed. */ 142862306a36Sopenharmony_ci kfree(key_layer); 142962306a36Sopenharmony_ci 143062306a36Sopenharmony_ci return 0; 143162306a36Sopenharmony_ci 143262306a36Sopenharmony_cierr_remove_rhash: 143362306a36Sopenharmony_ci WARN_ON_ONCE(rhashtable_remove_fast(&priv->flow_table, 143462306a36Sopenharmony_ci &flow_pay->fl_node, 143562306a36Sopenharmony_ci nfp_flower_table_params)); 143662306a36Sopenharmony_cierr_release_metadata: 143762306a36Sopenharmony_ci nfp_modify_flow_metadata(app, flow_pay); 143862306a36Sopenharmony_cierr_destroy_flow: 143962306a36Sopenharmony_ci if (flow_pay->nfp_tun_ipv6) 144062306a36Sopenharmony_ci nfp_tunnel_put_ipv6_off(app, flow_pay->nfp_tun_ipv6); 144162306a36Sopenharmony_ci kfree(flow_pay->action_data); 144262306a36Sopenharmony_ci kfree(flow_pay->mask_data); 144362306a36Sopenharmony_ci kfree(flow_pay->unmasked_data); 144462306a36Sopenharmony_ci kfree(flow_pay); 144562306a36Sopenharmony_cierr_free_key_ls: 144662306a36Sopenharmony_ci kfree(key_layer); 144762306a36Sopenharmony_ci return err; 144862306a36Sopenharmony_ci} 144962306a36Sopenharmony_ci 145062306a36Sopenharmony_cistatic void 145162306a36Sopenharmony_cinfp_flower_remove_merge_flow(struct nfp_app *app, 145262306a36Sopenharmony_ci struct nfp_fl_payload *del_sub_flow, 145362306a36Sopenharmony_ci struct nfp_fl_payload *merge_flow) 145462306a36Sopenharmony_ci{ 145562306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 145662306a36Sopenharmony_ci struct nfp_fl_payload_link *link, *temp; 145762306a36Sopenharmony_ci struct nfp_merge_info *merge_info; 145862306a36Sopenharmony_ci struct nfp_fl_payload *origin; 145962306a36Sopenharmony_ci u64 parent_ctx = 0; 146062306a36Sopenharmony_ci bool mod = false; 146162306a36Sopenharmony_ci int err; 146262306a36Sopenharmony_ci 146362306a36Sopenharmony_ci link = list_first_entry(&merge_flow->linked_flows, 146462306a36Sopenharmony_ci struct nfp_fl_payload_link, merge_flow.list); 146562306a36Sopenharmony_ci origin = link->sub_flow.flow; 146662306a36Sopenharmony_ci 146762306a36Sopenharmony_ci /* Re-add rule the merge had overwritten if it has not been deleted. */ 146862306a36Sopenharmony_ci if (origin != del_sub_flow) 146962306a36Sopenharmony_ci mod = true; 147062306a36Sopenharmony_ci 147162306a36Sopenharmony_ci err = nfp_modify_flow_metadata(app, merge_flow); 147262306a36Sopenharmony_ci if (err) { 147362306a36Sopenharmony_ci nfp_flower_cmsg_warn(app, "Metadata fail for merge flow delete.\n"); 147462306a36Sopenharmony_ci goto err_free_links; 147562306a36Sopenharmony_ci } 147662306a36Sopenharmony_ci 147762306a36Sopenharmony_ci if (!mod) { 147862306a36Sopenharmony_ci err = nfp_flower_xmit_flow(app, merge_flow, 147962306a36Sopenharmony_ci NFP_FLOWER_CMSG_TYPE_FLOW_DEL); 148062306a36Sopenharmony_ci if (err) { 148162306a36Sopenharmony_ci nfp_flower_cmsg_warn(app, "Failed to delete merged flow.\n"); 148262306a36Sopenharmony_ci goto err_free_links; 148362306a36Sopenharmony_ci } 148462306a36Sopenharmony_ci } else { 148562306a36Sopenharmony_ci __nfp_modify_flow_metadata(priv, origin); 148662306a36Sopenharmony_ci err = nfp_flower_xmit_flow(app, origin, 148762306a36Sopenharmony_ci NFP_FLOWER_CMSG_TYPE_FLOW_MOD); 148862306a36Sopenharmony_ci if (err) 148962306a36Sopenharmony_ci nfp_flower_cmsg_warn(app, "Failed to revert merge flow.\n"); 149062306a36Sopenharmony_ci origin->in_hw = true; 149162306a36Sopenharmony_ci } 149262306a36Sopenharmony_ci 149362306a36Sopenharmony_cierr_free_links: 149462306a36Sopenharmony_ci /* Clean any links connected with the merged flow. */ 149562306a36Sopenharmony_ci list_for_each_entry_safe(link, temp, &merge_flow->linked_flows, 149662306a36Sopenharmony_ci merge_flow.list) { 149762306a36Sopenharmony_ci u32 ctx_id = be32_to_cpu(link->sub_flow.flow->meta.host_ctx_id); 149862306a36Sopenharmony_ci 149962306a36Sopenharmony_ci parent_ctx = (parent_ctx << 32) | (u64)(ctx_id); 150062306a36Sopenharmony_ci nfp_flower_unlink_flow(link); 150162306a36Sopenharmony_ci } 150262306a36Sopenharmony_ci 150362306a36Sopenharmony_ci merge_info = rhashtable_lookup_fast(&priv->merge_table, 150462306a36Sopenharmony_ci &parent_ctx, 150562306a36Sopenharmony_ci merge_table_params); 150662306a36Sopenharmony_ci if (merge_info) { 150762306a36Sopenharmony_ci WARN_ON_ONCE(rhashtable_remove_fast(&priv->merge_table, 150862306a36Sopenharmony_ci &merge_info->ht_node, 150962306a36Sopenharmony_ci merge_table_params)); 151062306a36Sopenharmony_ci kfree(merge_info); 151162306a36Sopenharmony_ci } 151262306a36Sopenharmony_ci 151362306a36Sopenharmony_ci kfree(merge_flow->action_data); 151462306a36Sopenharmony_ci kfree(merge_flow->mask_data); 151562306a36Sopenharmony_ci kfree(merge_flow->unmasked_data); 151662306a36Sopenharmony_ci WARN_ON_ONCE(rhashtable_remove_fast(&priv->flow_table, 151762306a36Sopenharmony_ci &merge_flow->fl_node, 151862306a36Sopenharmony_ci nfp_flower_table_params)); 151962306a36Sopenharmony_ci kfree_rcu(merge_flow, rcu); 152062306a36Sopenharmony_ci} 152162306a36Sopenharmony_ci 152262306a36Sopenharmony_civoid 152362306a36Sopenharmony_cinfp_flower_del_linked_merge_flows(struct nfp_app *app, 152462306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow) 152562306a36Sopenharmony_ci{ 152662306a36Sopenharmony_ci struct nfp_fl_payload_link *link, *temp; 152762306a36Sopenharmony_ci 152862306a36Sopenharmony_ci /* Remove any merge flow formed from the deleted sub_flow. */ 152962306a36Sopenharmony_ci list_for_each_entry_safe(link, temp, &sub_flow->linked_flows, 153062306a36Sopenharmony_ci sub_flow.list) 153162306a36Sopenharmony_ci nfp_flower_remove_merge_flow(app, sub_flow, 153262306a36Sopenharmony_ci link->merge_flow.flow); 153362306a36Sopenharmony_ci} 153462306a36Sopenharmony_ci 153562306a36Sopenharmony_ci/** 153662306a36Sopenharmony_ci * nfp_flower_del_offload() - Removes a flow from hardware. 153762306a36Sopenharmony_ci * @app: Pointer to the APP handle 153862306a36Sopenharmony_ci * @netdev: netdev structure. 153962306a36Sopenharmony_ci * @flow: TC flower classifier offload structure 154062306a36Sopenharmony_ci * 154162306a36Sopenharmony_ci * Removes a flow from the repeated hash structure and clears the 154262306a36Sopenharmony_ci * action payload. Any flows merged from this are also deleted. 154362306a36Sopenharmony_ci * 154462306a36Sopenharmony_ci * Return: negative value on error, 0 if removed successfully. 154562306a36Sopenharmony_ci */ 154662306a36Sopenharmony_cistatic int 154762306a36Sopenharmony_cinfp_flower_del_offload(struct nfp_app *app, struct net_device *netdev, 154862306a36Sopenharmony_ci struct flow_cls_offload *flow) 154962306a36Sopenharmony_ci{ 155062306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 155162306a36Sopenharmony_ci struct nfp_fl_ct_map_entry *ct_map_ent; 155262306a36Sopenharmony_ci struct netlink_ext_ack *extack = NULL; 155362306a36Sopenharmony_ci struct nfp_fl_payload *nfp_flow; 155462306a36Sopenharmony_ci struct nfp_port *port = NULL; 155562306a36Sopenharmony_ci int err; 155662306a36Sopenharmony_ci 155762306a36Sopenharmony_ci extack = flow->common.extack; 155862306a36Sopenharmony_ci if (nfp_netdev_is_nfp_repr(netdev)) 155962306a36Sopenharmony_ci port = nfp_port_from_netdev(netdev); 156062306a36Sopenharmony_ci 156162306a36Sopenharmony_ci /* Check ct_map_table */ 156262306a36Sopenharmony_ci ct_map_ent = rhashtable_lookup_fast(&priv->ct_map_table, &flow->cookie, 156362306a36Sopenharmony_ci nfp_ct_map_params); 156462306a36Sopenharmony_ci if (ct_map_ent) { 156562306a36Sopenharmony_ci err = nfp_fl_ct_del_flow(ct_map_ent); 156662306a36Sopenharmony_ci return err; 156762306a36Sopenharmony_ci } 156862306a36Sopenharmony_ci 156962306a36Sopenharmony_ci nfp_flow = nfp_flower_search_fl_table(app, flow->cookie, netdev); 157062306a36Sopenharmony_ci if (!nfp_flow) { 157162306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "invalid entry: cannot remove flow that does not exist"); 157262306a36Sopenharmony_ci return -ENOENT; 157362306a36Sopenharmony_ci } 157462306a36Sopenharmony_ci 157562306a36Sopenharmony_ci err = nfp_modify_flow_metadata(app, nfp_flow); 157662306a36Sopenharmony_ci if (err) 157762306a36Sopenharmony_ci goto err_free_merge_flow; 157862306a36Sopenharmony_ci 157962306a36Sopenharmony_ci if (nfp_flow->nfp_tun_ipv4_addr) 158062306a36Sopenharmony_ci nfp_tunnel_del_ipv4_off(app, nfp_flow->nfp_tun_ipv4_addr); 158162306a36Sopenharmony_ci 158262306a36Sopenharmony_ci if (nfp_flow->nfp_tun_ipv6) 158362306a36Sopenharmony_ci nfp_tunnel_put_ipv6_off(app, nfp_flow->nfp_tun_ipv6); 158462306a36Sopenharmony_ci 158562306a36Sopenharmony_ci if (!nfp_flow->in_hw) { 158662306a36Sopenharmony_ci err = 0; 158762306a36Sopenharmony_ci goto err_free_merge_flow; 158862306a36Sopenharmony_ci } 158962306a36Sopenharmony_ci 159062306a36Sopenharmony_ci if (nfp_flow->pre_tun_rule.dev) { 159162306a36Sopenharmony_ci if (priv->flower_ext_feats & NFP_FL_FEATS_DECAP_V2) { 159262306a36Sopenharmony_ci struct nfp_predt_entry *predt; 159362306a36Sopenharmony_ci 159462306a36Sopenharmony_ci predt = nfp_flow->pre_tun_rule.predt; 159562306a36Sopenharmony_ci if (predt) { 159662306a36Sopenharmony_ci spin_lock_bh(&priv->predt_lock); 159762306a36Sopenharmony_ci nfp_tun_unlink_and_update_nn_entries(app, predt); 159862306a36Sopenharmony_ci list_del(&predt->list_head); 159962306a36Sopenharmony_ci spin_unlock_bh(&priv->predt_lock); 160062306a36Sopenharmony_ci kfree(predt); 160162306a36Sopenharmony_ci } 160262306a36Sopenharmony_ci } else { 160362306a36Sopenharmony_ci err = nfp_flower_xmit_pre_tun_del_flow(app, nfp_flow); 160462306a36Sopenharmony_ci } 160562306a36Sopenharmony_ci } else { 160662306a36Sopenharmony_ci err = nfp_flower_xmit_flow(app, nfp_flow, 160762306a36Sopenharmony_ci NFP_FLOWER_CMSG_TYPE_FLOW_DEL); 160862306a36Sopenharmony_ci } 160962306a36Sopenharmony_ci /* Fall through on error. */ 161062306a36Sopenharmony_ci 161162306a36Sopenharmony_cierr_free_merge_flow: 161262306a36Sopenharmony_ci nfp_flower_del_linked_merge_flows(app, nfp_flow); 161362306a36Sopenharmony_ci if (port) 161462306a36Sopenharmony_ci port->tc_offload_cnt--; 161562306a36Sopenharmony_ci kfree(nfp_flow->action_data); 161662306a36Sopenharmony_ci kfree(nfp_flow->mask_data); 161762306a36Sopenharmony_ci kfree(nfp_flow->unmasked_data); 161862306a36Sopenharmony_ci WARN_ON_ONCE(rhashtable_remove_fast(&priv->flow_table, 161962306a36Sopenharmony_ci &nfp_flow->fl_node, 162062306a36Sopenharmony_ci nfp_flower_table_params)); 162162306a36Sopenharmony_ci kfree_rcu(nfp_flow, rcu); 162262306a36Sopenharmony_ci return err; 162362306a36Sopenharmony_ci} 162462306a36Sopenharmony_ci 162562306a36Sopenharmony_cistatic void 162662306a36Sopenharmony_ci__nfp_flower_update_merge_stats(struct nfp_app *app, 162762306a36Sopenharmony_ci struct nfp_fl_payload *merge_flow) 162862306a36Sopenharmony_ci{ 162962306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 163062306a36Sopenharmony_ci struct nfp_fl_payload_link *link; 163162306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow; 163262306a36Sopenharmony_ci u64 pkts, bytes, used; 163362306a36Sopenharmony_ci u32 ctx_id; 163462306a36Sopenharmony_ci 163562306a36Sopenharmony_ci ctx_id = be32_to_cpu(merge_flow->meta.host_ctx_id); 163662306a36Sopenharmony_ci pkts = priv->stats[ctx_id].pkts; 163762306a36Sopenharmony_ci /* Do not cycle subflows if no stats to distribute. */ 163862306a36Sopenharmony_ci if (!pkts) 163962306a36Sopenharmony_ci return; 164062306a36Sopenharmony_ci bytes = priv->stats[ctx_id].bytes; 164162306a36Sopenharmony_ci used = priv->stats[ctx_id].used; 164262306a36Sopenharmony_ci 164362306a36Sopenharmony_ci /* Reset stats for the merge flow. */ 164462306a36Sopenharmony_ci priv->stats[ctx_id].pkts = 0; 164562306a36Sopenharmony_ci priv->stats[ctx_id].bytes = 0; 164662306a36Sopenharmony_ci 164762306a36Sopenharmony_ci /* The merge flow has received stats updates from firmware. 164862306a36Sopenharmony_ci * Distribute these stats to all subflows that form the merge. 164962306a36Sopenharmony_ci * The stats will collected from TC via the subflows. 165062306a36Sopenharmony_ci */ 165162306a36Sopenharmony_ci list_for_each_entry(link, &merge_flow->linked_flows, merge_flow.list) { 165262306a36Sopenharmony_ci sub_flow = link->sub_flow.flow; 165362306a36Sopenharmony_ci ctx_id = be32_to_cpu(sub_flow->meta.host_ctx_id); 165462306a36Sopenharmony_ci priv->stats[ctx_id].pkts += pkts; 165562306a36Sopenharmony_ci priv->stats[ctx_id].bytes += bytes; 165662306a36Sopenharmony_ci priv->stats[ctx_id].used = max_t(u64, used, 165762306a36Sopenharmony_ci priv->stats[ctx_id].used); 165862306a36Sopenharmony_ci } 165962306a36Sopenharmony_ci} 166062306a36Sopenharmony_ci 166162306a36Sopenharmony_civoid 166262306a36Sopenharmony_cinfp_flower_update_merge_stats(struct nfp_app *app, 166362306a36Sopenharmony_ci struct nfp_fl_payload *sub_flow) 166462306a36Sopenharmony_ci{ 166562306a36Sopenharmony_ci struct nfp_fl_payload_link *link; 166662306a36Sopenharmony_ci 166762306a36Sopenharmony_ci /* Get merge flows that the subflow forms to distribute their stats. */ 166862306a36Sopenharmony_ci list_for_each_entry(link, &sub_flow->linked_flows, sub_flow.list) 166962306a36Sopenharmony_ci __nfp_flower_update_merge_stats(app, link->merge_flow.flow); 167062306a36Sopenharmony_ci} 167162306a36Sopenharmony_ci 167262306a36Sopenharmony_ci/** 167362306a36Sopenharmony_ci * nfp_flower_get_stats() - Populates flow stats obtained from hardware. 167462306a36Sopenharmony_ci * @app: Pointer to the APP handle 167562306a36Sopenharmony_ci * @netdev: Netdev structure. 167662306a36Sopenharmony_ci * @flow: TC flower classifier offload structure 167762306a36Sopenharmony_ci * 167862306a36Sopenharmony_ci * Populates a flow statistics structure which which corresponds to a 167962306a36Sopenharmony_ci * specific flow. 168062306a36Sopenharmony_ci * 168162306a36Sopenharmony_ci * Return: negative value on error, 0 if stats populated successfully. 168262306a36Sopenharmony_ci */ 168362306a36Sopenharmony_cistatic int 168462306a36Sopenharmony_cinfp_flower_get_stats(struct nfp_app *app, struct net_device *netdev, 168562306a36Sopenharmony_ci struct flow_cls_offload *flow) 168662306a36Sopenharmony_ci{ 168762306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 168862306a36Sopenharmony_ci struct nfp_fl_ct_map_entry *ct_map_ent; 168962306a36Sopenharmony_ci struct netlink_ext_ack *extack = NULL; 169062306a36Sopenharmony_ci struct nfp_fl_payload *nfp_flow; 169162306a36Sopenharmony_ci u32 ctx_id; 169262306a36Sopenharmony_ci 169362306a36Sopenharmony_ci /* Check ct_map table first */ 169462306a36Sopenharmony_ci ct_map_ent = rhashtable_lookup_fast(&priv->ct_map_table, &flow->cookie, 169562306a36Sopenharmony_ci nfp_ct_map_params); 169662306a36Sopenharmony_ci if (ct_map_ent) 169762306a36Sopenharmony_ci return nfp_fl_ct_stats(flow, ct_map_ent); 169862306a36Sopenharmony_ci 169962306a36Sopenharmony_ci extack = flow->common.extack; 170062306a36Sopenharmony_ci nfp_flow = nfp_flower_search_fl_table(app, flow->cookie, netdev); 170162306a36Sopenharmony_ci if (!nfp_flow) { 170262306a36Sopenharmony_ci NL_SET_ERR_MSG_MOD(extack, "invalid entry: cannot dump stats for flow that does not exist"); 170362306a36Sopenharmony_ci return -EINVAL; 170462306a36Sopenharmony_ci } 170562306a36Sopenharmony_ci 170662306a36Sopenharmony_ci ctx_id = be32_to_cpu(nfp_flow->meta.host_ctx_id); 170762306a36Sopenharmony_ci 170862306a36Sopenharmony_ci spin_lock_bh(&priv->stats_lock); 170962306a36Sopenharmony_ci /* If request is for a sub_flow, update stats from merged flows. */ 171062306a36Sopenharmony_ci if (!list_empty(&nfp_flow->linked_flows)) 171162306a36Sopenharmony_ci nfp_flower_update_merge_stats(app, nfp_flow); 171262306a36Sopenharmony_ci 171362306a36Sopenharmony_ci flow_stats_update(&flow->stats, priv->stats[ctx_id].bytes, 171462306a36Sopenharmony_ci priv->stats[ctx_id].pkts, 0, priv->stats[ctx_id].used, 171562306a36Sopenharmony_ci FLOW_ACTION_HW_STATS_DELAYED); 171662306a36Sopenharmony_ci 171762306a36Sopenharmony_ci priv->stats[ctx_id].pkts = 0; 171862306a36Sopenharmony_ci priv->stats[ctx_id].bytes = 0; 171962306a36Sopenharmony_ci spin_unlock_bh(&priv->stats_lock); 172062306a36Sopenharmony_ci 172162306a36Sopenharmony_ci return 0; 172262306a36Sopenharmony_ci} 172362306a36Sopenharmony_ci 172462306a36Sopenharmony_cistatic int 172562306a36Sopenharmony_cinfp_flower_repr_offload(struct nfp_app *app, struct net_device *netdev, 172662306a36Sopenharmony_ci struct flow_cls_offload *flower) 172762306a36Sopenharmony_ci{ 172862306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 172962306a36Sopenharmony_ci int ret; 173062306a36Sopenharmony_ci 173162306a36Sopenharmony_ci if (!eth_proto_is_802_3(flower->common.protocol)) 173262306a36Sopenharmony_ci return -EOPNOTSUPP; 173362306a36Sopenharmony_ci 173462306a36Sopenharmony_ci mutex_lock(&priv->nfp_fl_lock); 173562306a36Sopenharmony_ci switch (flower->command) { 173662306a36Sopenharmony_ci case FLOW_CLS_REPLACE: 173762306a36Sopenharmony_ci ret = nfp_flower_add_offload(app, netdev, flower); 173862306a36Sopenharmony_ci break; 173962306a36Sopenharmony_ci case FLOW_CLS_DESTROY: 174062306a36Sopenharmony_ci ret = nfp_flower_del_offload(app, netdev, flower); 174162306a36Sopenharmony_ci break; 174262306a36Sopenharmony_ci case FLOW_CLS_STATS: 174362306a36Sopenharmony_ci ret = nfp_flower_get_stats(app, netdev, flower); 174462306a36Sopenharmony_ci break; 174562306a36Sopenharmony_ci default: 174662306a36Sopenharmony_ci ret = -EOPNOTSUPP; 174762306a36Sopenharmony_ci break; 174862306a36Sopenharmony_ci } 174962306a36Sopenharmony_ci mutex_unlock(&priv->nfp_fl_lock); 175062306a36Sopenharmony_ci 175162306a36Sopenharmony_ci return ret; 175262306a36Sopenharmony_ci} 175362306a36Sopenharmony_ci 175462306a36Sopenharmony_cistatic int nfp_flower_setup_tc_block_cb(enum tc_setup_type type, 175562306a36Sopenharmony_ci void *type_data, void *cb_priv) 175662306a36Sopenharmony_ci{ 175762306a36Sopenharmony_ci struct flow_cls_common_offload *common = type_data; 175862306a36Sopenharmony_ci struct nfp_repr *repr = cb_priv; 175962306a36Sopenharmony_ci 176062306a36Sopenharmony_ci if (!tc_can_offload_extack(repr->netdev, common->extack)) 176162306a36Sopenharmony_ci return -EOPNOTSUPP; 176262306a36Sopenharmony_ci 176362306a36Sopenharmony_ci switch (type) { 176462306a36Sopenharmony_ci case TC_SETUP_CLSFLOWER: 176562306a36Sopenharmony_ci return nfp_flower_repr_offload(repr->app, repr->netdev, 176662306a36Sopenharmony_ci type_data); 176762306a36Sopenharmony_ci case TC_SETUP_CLSMATCHALL: 176862306a36Sopenharmony_ci return nfp_flower_setup_qos_offload(repr->app, repr->netdev, 176962306a36Sopenharmony_ci type_data); 177062306a36Sopenharmony_ci default: 177162306a36Sopenharmony_ci return -EOPNOTSUPP; 177262306a36Sopenharmony_ci } 177362306a36Sopenharmony_ci} 177462306a36Sopenharmony_ci 177562306a36Sopenharmony_cistatic LIST_HEAD(nfp_block_cb_list); 177662306a36Sopenharmony_ci 177762306a36Sopenharmony_cistatic int nfp_flower_setup_tc_block(struct net_device *netdev, 177862306a36Sopenharmony_ci struct flow_block_offload *f) 177962306a36Sopenharmony_ci{ 178062306a36Sopenharmony_ci struct nfp_repr *repr = netdev_priv(netdev); 178162306a36Sopenharmony_ci struct nfp_flower_repr_priv *repr_priv; 178262306a36Sopenharmony_ci struct flow_block_cb *block_cb; 178362306a36Sopenharmony_ci 178462306a36Sopenharmony_ci if (f->binder_type != FLOW_BLOCK_BINDER_TYPE_CLSACT_INGRESS) 178562306a36Sopenharmony_ci return -EOPNOTSUPP; 178662306a36Sopenharmony_ci 178762306a36Sopenharmony_ci repr_priv = repr->app_priv; 178862306a36Sopenharmony_ci repr_priv->block_shared = f->block_shared; 178962306a36Sopenharmony_ci f->driver_block_list = &nfp_block_cb_list; 179062306a36Sopenharmony_ci f->unlocked_driver_cb = true; 179162306a36Sopenharmony_ci 179262306a36Sopenharmony_ci switch (f->command) { 179362306a36Sopenharmony_ci case FLOW_BLOCK_BIND: 179462306a36Sopenharmony_ci if (flow_block_cb_is_busy(nfp_flower_setup_tc_block_cb, repr, 179562306a36Sopenharmony_ci &nfp_block_cb_list)) 179662306a36Sopenharmony_ci return -EBUSY; 179762306a36Sopenharmony_ci 179862306a36Sopenharmony_ci block_cb = flow_block_cb_alloc(nfp_flower_setup_tc_block_cb, 179962306a36Sopenharmony_ci repr, repr, NULL); 180062306a36Sopenharmony_ci if (IS_ERR(block_cb)) 180162306a36Sopenharmony_ci return PTR_ERR(block_cb); 180262306a36Sopenharmony_ci 180362306a36Sopenharmony_ci flow_block_cb_add(block_cb, f); 180462306a36Sopenharmony_ci list_add_tail(&block_cb->driver_list, &nfp_block_cb_list); 180562306a36Sopenharmony_ci return 0; 180662306a36Sopenharmony_ci case FLOW_BLOCK_UNBIND: 180762306a36Sopenharmony_ci block_cb = flow_block_cb_lookup(f->block, 180862306a36Sopenharmony_ci nfp_flower_setup_tc_block_cb, 180962306a36Sopenharmony_ci repr); 181062306a36Sopenharmony_ci if (!block_cb) 181162306a36Sopenharmony_ci return -ENOENT; 181262306a36Sopenharmony_ci 181362306a36Sopenharmony_ci flow_block_cb_remove(block_cb, f); 181462306a36Sopenharmony_ci list_del(&block_cb->driver_list); 181562306a36Sopenharmony_ci return 0; 181662306a36Sopenharmony_ci default: 181762306a36Sopenharmony_ci return -EOPNOTSUPP; 181862306a36Sopenharmony_ci } 181962306a36Sopenharmony_ci} 182062306a36Sopenharmony_ci 182162306a36Sopenharmony_ciint nfp_flower_setup_tc(struct nfp_app *app, struct net_device *netdev, 182262306a36Sopenharmony_ci enum tc_setup_type type, void *type_data) 182362306a36Sopenharmony_ci{ 182462306a36Sopenharmony_ci switch (type) { 182562306a36Sopenharmony_ci case TC_SETUP_BLOCK: 182662306a36Sopenharmony_ci return nfp_flower_setup_tc_block(netdev, type_data); 182762306a36Sopenharmony_ci default: 182862306a36Sopenharmony_ci return -EOPNOTSUPP; 182962306a36Sopenharmony_ci } 183062306a36Sopenharmony_ci} 183162306a36Sopenharmony_ci 183262306a36Sopenharmony_cistruct nfp_flower_indr_block_cb_priv { 183362306a36Sopenharmony_ci struct net_device *netdev; 183462306a36Sopenharmony_ci struct nfp_app *app; 183562306a36Sopenharmony_ci struct list_head list; 183662306a36Sopenharmony_ci}; 183762306a36Sopenharmony_ci 183862306a36Sopenharmony_cistatic struct nfp_flower_indr_block_cb_priv * 183962306a36Sopenharmony_cinfp_flower_indr_block_cb_priv_lookup(struct nfp_app *app, 184062306a36Sopenharmony_ci struct net_device *netdev) 184162306a36Sopenharmony_ci{ 184262306a36Sopenharmony_ci struct nfp_flower_indr_block_cb_priv *cb_priv; 184362306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 184462306a36Sopenharmony_ci 184562306a36Sopenharmony_ci list_for_each_entry(cb_priv, &priv->indr_block_cb_priv, list) 184662306a36Sopenharmony_ci if (cb_priv->netdev == netdev) 184762306a36Sopenharmony_ci return cb_priv; 184862306a36Sopenharmony_ci 184962306a36Sopenharmony_ci return NULL; 185062306a36Sopenharmony_ci} 185162306a36Sopenharmony_ci 185262306a36Sopenharmony_cistatic int nfp_flower_setup_indr_block_cb(enum tc_setup_type type, 185362306a36Sopenharmony_ci void *type_data, void *cb_priv) 185462306a36Sopenharmony_ci{ 185562306a36Sopenharmony_ci struct nfp_flower_indr_block_cb_priv *priv = cb_priv; 185662306a36Sopenharmony_ci 185762306a36Sopenharmony_ci switch (type) { 185862306a36Sopenharmony_ci case TC_SETUP_CLSFLOWER: 185962306a36Sopenharmony_ci return nfp_flower_repr_offload(priv->app, priv->netdev, 186062306a36Sopenharmony_ci type_data); 186162306a36Sopenharmony_ci default: 186262306a36Sopenharmony_ci return -EOPNOTSUPP; 186362306a36Sopenharmony_ci } 186462306a36Sopenharmony_ci} 186562306a36Sopenharmony_ci 186662306a36Sopenharmony_civoid nfp_flower_setup_indr_tc_release(void *cb_priv) 186762306a36Sopenharmony_ci{ 186862306a36Sopenharmony_ci struct nfp_flower_indr_block_cb_priv *priv = cb_priv; 186962306a36Sopenharmony_ci 187062306a36Sopenharmony_ci list_del(&priv->list); 187162306a36Sopenharmony_ci kfree(priv); 187262306a36Sopenharmony_ci} 187362306a36Sopenharmony_ci 187462306a36Sopenharmony_cistatic int 187562306a36Sopenharmony_cinfp_flower_setup_indr_tc_block(struct net_device *netdev, struct Qdisc *sch, struct nfp_app *app, 187662306a36Sopenharmony_ci struct flow_block_offload *f, void *data, 187762306a36Sopenharmony_ci void (*cleanup)(struct flow_block_cb *block_cb)) 187862306a36Sopenharmony_ci{ 187962306a36Sopenharmony_ci struct nfp_flower_indr_block_cb_priv *cb_priv; 188062306a36Sopenharmony_ci struct nfp_flower_priv *priv = app->priv; 188162306a36Sopenharmony_ci struct flow_block_cb *block_cb; 188262306a36Sopenharmony_ci 188362306a36Sopenharmony_ci if ((f->binder_type != FLOW_BLOCK_BINDER_TYPE_CLSACT_INGRESS && 188462306a36Sopenharmony_ci !nfp_flower_internal_port_can_offload(app, netdev)) || 188562306a36Sopenharmony_ci (f->binder_type != FLOW_BLOCK_BINDER_TYPE_CLSACT_EGRESS && 188662306a36Sopenharmony_ci nfp_flower_internal_port_can_offload(app, netdev))) 188762306a36Sopenharmony_ci return -EOPNOTSUPP; 188862306a36Sopenharmony_ci 188962306a36Sopenharmony_ci f->unlocked_driver_cb = true; 189062306a36Sopenharmony_ci 189162306a36Sopenharmony_ci switch (f->command) { 189262306a36Sopenharmony_ci case FLOW_BLOCK_BIND: 189362306a36Sopenharmony_ci cb_priv = nfp_flower_indr_block_cb_priv_lookup(app, netdev); 189462306a36Sopenharmony_ci if (cb_priv && 189562306a36Sopenharmony_ci flow_block_cb_is_busy(nfp_flower_setup_indr_block_cb, 189662306a36Sopenharmony_ci cb_priv, 189762306a36Sopenharmony_ci &nfp_block_cb_list)) 189862306a36Sopenharmony_ci return -EBUSY; 189962306a36Sopenharmony_ci 190062306a36Sopenharmony_ci cb_priv = kmalloc(sizeof(*cb_priv), GFP_KERNEL); 190162306a36Sopenharmony_ci if (!cb_priv) 190262306a36Sopenharmony_ci return -ENOMEM; 190362306a36Sopenharmony_ci 190462306a36Sopenharmony_ci cb_priv->netdev = netdev; 190562306a36Sopenharmony_ci cb_priv->app = app; 190662306a36Sopenharmony_ci list_add(&cb_priv->list, &priv->indr_block_cb_priv); 190762306a36Sopenharmony_ci 190862306a36Sopenharmony_ci block_cb = flow_indr_block_cb_alloc(nfp_flower_setup_indr_block_cb, 190962306a36Sopenharmony_ci cb_priv, cb_priv, 191062306a36Sopenharmony_ci nfp_flower_setup_indr_tc_release, 191162306a36Sopenharmony_ci f, netdev, sch, data, app, cleanup); 191262306a36Sopenharmony_ci if (IS_ERR(block_cb)) { 191362306a36Sopenharmony_ci list_del(&cb_priv->list); 191462306a36Sopenharmony_ci kfree(cb_priv); 191562306a36Sopenharmony_ci return PTR_ERR(block_cb); 191662306a36Sopenharmony_ci } 191762306a36Sopenharmony_ci 191862306a36Sopenharmony_ci flow_block_cb_add(block_cb, f); 191962306a36Sopenharmony_ci list_add_tail(&block_cb->driver_list, &nfp_block_cb_list); 192062306a36Sopenharmony_ci return 0; 192162306a36Sopenharmony_ci case FLOW_BLOCK_UNBIND: 192262306a36Sopenharmony_ci cb_priv = nfp_flower_indr_block_cb_priv_lookup(app, netdev); 192362306a36Sopenharmony_ci if (!cb_priv) 192462306a36Sopenharmony_ci return -ENOENT; 192562306a36Sopenharmony_ci 192662306a36Sopenharmony_ci block_cb = flow_block_cb_lookup(f->block, 192762306a36Sopenharmony_ci nfp_flower_setup_indr_block_cb, 192862306a36Sopenharmony_ci cb_priv); 192962306a36Sopenharmony_ci if (!block_cb) 193062306a36Sopenharmony_ci return -ENOENT; 193162306a36Sopenharmony_ci 193262306a36Sopenharmony_ci flow_indr_block_cb_remove(block_cb, f); 193362306a36Sopenharmony_ci list_del(&block_cb->driver_list); 193462306a36Sopenharmony_ci return 0; 193562306a36Sopenharmony_ci default: 193662306a36Sopenharmony_ci return -EOPNOTSUPP; 193762306a36Sopenharmony_ci } 193862306a36Sopenharmony_ci return 0; 193962306a36Sopenharmony_ci} 194062306a36Sopenharmony_ci 194162306a36Sopenharmony_cistatic int 194262306a36Sopenharmony_cinfp_setup_tc_no_dev(struct nfp_app *app, enum tc_setup_type type, void *data) 194362306a36Sopenharmony_ci{ 194462306a36Sopenharmony_ci if (!data) 194562306a36Sopenharmony_ci return -EOPNOTSUPP; 194662306a36Sopenharmony_ci 194762306a36Sopenharmony_ci switch (type) { 194862306a36Sopenharmony_ci case TC_SETUP_ACT: 194962306a36Sopenharmony_ci return nfp_setup_tc_act_offload(app, data); 195062306a36Sopenharmony_ci default: 195162306a36Sopenharmony_ci return -EOPNOTSUPP; 195262306a36Sopenharmony_ci } 195362306a36Sopenharmony_ci} 195462306a36Sopenharmony_ci 195562306a36Sopenharmony_ciint 195662306a36Sopenharmony_cinfp_flower_indr_setup_tc_cb(struct net_device *netdev, struct Qdisc *sch, void *cb_priv, 195762306a36Sopenharmony_ci enum tc_setup_type type, void *type_data, 195862306a36Sopenharmony_ci void *data, 195962306a36Sopenharmony_ci void (*cleanup)(struct flow_block_cb *block_cb)) 196062306a36Sopenharmony_ci{ 196162306a36Sopenharmony_ci if (!netdev) 196262306a36Sopenharmony_ci return nfp_setup_tc_no_dev(cb_priv, type, data); 196362306a36Sopenharmony_ci 196462306a36Sopenharmony_ci if (!nfp_fl_is_netdev_to_offload(netdev)) 196562306a36Sopenharmony_ci return -EOPNOTSUPP; 196662306a36Sopenharmony_ci 196762306a36Sopenharmony_ci switch (type) { 196862306a36Sopenharmony_ci case TC_SETUP_BLOCK: 196962306a36Sopenharmony_ci return nfp_flower_setup_indr_tc_block(netdev, sch, cb_priv, 197062306a36Sopenharmony_ci type_data, data, cleanup); 197162306a36Sopenharmony_ci default: 197262306a36Sopenharmony_ci return -EOPNOTSUPP; 197362306a36Sopenharmony_ci } 197462306a36Sopenharmony_ci} 1975