162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * net/sched/em_ipset.c ipset ematch 462306a36Sopenharmony_ci * 562306a36Sopenharmony_ci * Copyright (c) 2012 Florian Westphal <fw@strlen.de> 662306a36Sopenharmony_ci */ 762306a36Sopenharmony_ci 862306a36Sopenharmony_ci#include <linux/gfp.h> 962306a36Sopenharmony_ci#include <linux/module.h> 1062306a36Sopenharmony_ci#include <linux/types.h> 1162306a36Sopenharmony_ci#include <linux/kernel.h> 1262306a36Sopenharmony_ci#include <linux/string.h> 1362306a36Sopenharmony_ci#include <linux/skbuff.h> 1462306a36Sopenharmony_ci#include <linux/netfilter/xt_set.h> 1562306a36Sopenharmony_ci#include <linux/ipv6.h> 1662306a36Sopenharmony_ci#include <net/ip.h> 1762306a36Sopenharmony_ci#include <net/pkt_cls.h> 1862306a36Sopenharmony_ci 1962306a36Sopenharmony_cistatic int em_ipset_change(struct net *net, void *data, int data_len, 2062306a36Sopenharmony_ci struct tcf_ematch *em) 2162306a36Sopenharmony_ci{ 2262306a36Sopenharmony_ci struct xt_set_info *set = data; 2362306a36Sopenharmony_ci ip_set_id_t index; 2462306a36Sopenharmony_ci 2562306a36Sopenharmony_ci if (data_len != sizeof(*set)) 2662306a36Sopenharmony_ci return -EINVAL; 2762306a36Sopenharmony_ci 2862306a36Sopenharmony_ci index = ip_set_nfnl_get_byindex(net, set->index); 2962306a36Sopenharmony_ci if (index == IPSET_INVALID_ID) 3062306a36Sopenharmony_ci return -ENOENT; 3162306a36Sopenharmony_ci 3262306a36Sopenharmony_ci em->datalen = sizeof(*set); 3362306a36Sopenharmony_ci em->data = (unsigned long)kmemdup(data, em->datalen, GFP_KERNEL); 3462306a36Sopenharmony_ci if (em->data) 3562306a36Sopenharmony_ci return 0; 3662306a36Sopenharmony_ci 3762306a36Sopenharmony_ci ip_set_nfnl_put(net, index); 3862306a36Sopenharmony_ci return -ENOMEM; 3962306a36Sopenharmony_ci} 4062306a36Sopenharmony_ci 4162306a36Sopenharmony_cistatic void em_ipset_destroy(struct tcf_ematch *em) 4262306a36Sopenharmony_ci{ 4362306a36Sopenharmony_ci const struct xt_set_info *set = (const void *) em->data; 4462306a36Sopenharmony_ci if (set) { 4562306a36Sopenharmony_ci ip_set_nfnl_put(em->net, set->index); 4662306a36Sopenharmony_ci kfree((void *) em->data); 4762306a36Sopenharmony_ci } 4862306a36Sopenharmony_ci} 4962306a36Sopenharmony_ci 5062306a36Sopenharmony_cistatic int em_ipset_match(struct sk_buff *skb, struct tcf_ematch *em, 5162306a36Sopenharmony_ci struct tcf_pkt_info *info) 5262306a36Sopenharmony_ci{ 5362306a36Sopenharmony_ci struct ip_set_adt_opt opt; 5462306a36Sopenharmony_ci struct xt_action_param acpar; 5562306a36Sopenharmony_ci const struct xt_set_info *set = (const void *) em->data; 5662306a36Sopenharmony_ci struct net_device *dev, *indev = NULL; 5762306a36Sopenharmony_ci struct nf_hook_state state = { 5862306a36Sopenharmony_ci .net = em->net, 5962306a36Sopenharmony_ci }; 6062306a36Sopenharmony_ci int ret, network_offset; 6162306a36Sopenharmony_ci 6262306a36Sopenharmony_ci switch (skb_protocol(skb, true)) { 6362306a36Sopenharmony_ci case htons(ETH_P_IP): 6462306a36Sopenharmony_ci state.pf = NFPROTO_IPV4; 6562306a36Sopenharmony_ci if (!pskb_network_may_pull(skb, sizeof(struct iphdr))) 6662306a36Sopenharmony_ci return 0; 6762306a36Sopenharmony_ci acpar.thoff = ip_hdrlen(skb); 6862306a36Sopenharmony_ci break; 6962306a36Sopenharmony_ci case htons(ETH_P_IPV6): 7062306a36Sopenharmony_ci state.pf = NFPROTO_IPV6; 7162306a36Sopenharmony_ci if (!pskb_network_may_pull(skb, sizeof(struct ipv6hdr))) 7262306a36Sopenharmony_ci return 0; 7362306a36Sopenharmony_ci /* doesn't call ipv6_find_hdr() because ipset doesn't use thoff, yet */ 7462306a36Sopenharmony_ci acpar.thoff = sizeof(struct ipv6hdr); 7562306a36Sopenharmony_ci break; 7662306a36Sopenharmony_ci default: 7762306a36Sopenharmony_ci return 0; 7862306a36Sopenharmony_ci } 7962306a36Sopenharmony_ci 8062306a36Sopenharmony_ci opt.family = state.pf; 8162306a36Sopenharmony_ci opt.dim = set->dim; 8262306a36Sopenharmony_ci opt.flags = set->flags; 8362306a36Sopenharmony_ci opt.cmdflags = 0; 8462306a36Sopenharmony_ci opt.ext.timeout = ~0u; 8562306a36Sopenharmony_ci 8662306a36Sopenharmony_ci network_offset = skb_network_offset(skb); 8762306a36Sopenharmony_ci skb_pull(skb, network_offset); 8862306a36Sopenharmony_ci 8962306a36Sopenharmony_ci dev = skb->dev; 9062306a36Sopenharmony_ci 9162306a36Sopenharmony_ci rcu_read_lock(); 9262306a36Sopenharmony_ci 9362306a36Sopenharmony_ci if (skb->skb_iif) 9462306a36Sopenharmony_ci indev = dev_get_by_index_rcu(em->net, skb->skb_iif); 9562306a36Sopenharmony_ci 9662306a36Sopenharmony_ci state.in = indev ? indev : dev; 9762306a36Sopenharmony_ci state.out = dev; 9862306a36Sopenharmony_ci acpar.state = &state; 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_ci ret = ip_set_test(set->index, skb, &acpar, &opt); 10162306a36Sopenharmony_ci 10262306a36Sopenharmony_ci rcu_read_unlock(); 10362306a36Sopenharmony_ci 10462306a36Sopenharmony_ci skb_push(skb, network_offset); 10562306a36Sopenharmony_ci return ret; 10662306a36Sopenharmony_ci} 10762306a36Sopenharmony_ci 10862306a36Sopenharmony_cistatic struct tcf_ematch_ops em_ipset_ops = { 10962306a36Sopenharmony_ci .kind = TCF_EM_IPSET, 11062306a36Sopenharmony_ci .change = em_ipset_change, 11162306a36Sopenharmony_ci .destroy = em_ipset_destroy, 11262306a36Sopenharmony_ci .match = em_ipset_match, 11362306a36Sopenharmony_ci .owner = THIS_MODULE, 11462306a36Sopenharmony_ci .link = LIST_HEAD_INIT(em_ipset_ops.link) 11562306a36Sopenharmony_ci}; 11662306a36Sopenharmony_ci 11762306a36Sopenharmony_cistatic int __init init_em_ipset(void) 11862306a36Sopenharmony_ci{ 11962306a36Sopenharmony_ci return tcf_em_register(&em_ipset_ops); 12062306a36Sopenharmony_ci} 12162306a36Sopenharmony_ci 12262306a36Sopenharmony_cistatic void __exit exit_em_ipset(void) 12362306a36Sopenharmony_ci{ 12462306a36Sopenharmony_ci tcf_em_unregister(&em_ipset_ops); 12562306a36Sopenharmony_ci} 12662306a36Sopenharmony_ci 12762306a36Sopenharmony_ciMODULE_LICENSE("GPL"); 12862306a36Sopenharmony_ciMODULE_AUTHOR("Florian Westphal <fw@strlen.de>"); 12962306a36Sopenharmony_ciMODULE_DESCRIPTION("TC extended match for IP sets"); 13062306a36Sopenharmony_ci 13162306a36Sopenharmony_cimodule_init(init_em_ipset); 13262306a36Sopenharmony_cimodule_exit(exit_em_ipset); 13362306a36Sopenharmony_ci 13462306a36Sopenharmony_ciMODULE_ALIAS_TCF_EMATCH(TCF_EM_IPSET); 135