Skip to content

Commit b9455fe

Browse files
idoschkuba-moo
authored andcommitted
ipv4: fib_rules: Add DSCP selector support
Implement support for the new DSCP selector that allows IPv4 FIB rules to match on the entire DSCP field, unlike the existing TOS selector that only matches on the three lower DSCP bits. Differentiate between both selectors by adding a new bit in the IPv4 FIB rule structure (in an existing one byte hole) that is only set when the 'FRA_DSCP' attribute is specified by user space. Reject rules that use both selectors. Signed-off-by: Ido Schimmel <idosch@nvidia.com> Reviewed-by: Guillaume Nault <gnault@redhat.com> Reviewed-by: David Ahern <dsahern@kernel.org> Link: https://patch.msgid.link/20240911093748.3662015-3-idosch@nvidia.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
1 parent c951a29 commit b9455fe

1 file changed

Lines changed: 50 additions & 4 deletions

File tree

net/ipv4/fib_rules.c

Lines changed: 50 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,7 @@ struct fib4_rule {
3737
u8 dst_len;
3838
u8 src_len;
3939
dscp_t dscp;
40+
u8 dscp_full:1; /* DSCP or TOS selector */
4041
__be32 src;
4142
__be32 srcmask;
4243
__be32 dst;
@@ -186,7 +187,15 @@ INDIRECT_CALLABLE_SCOPE int fib4_rule_match(struct fib_rule *rule,
186187
((daddr ^ r->dst) & r->dstmask))
187188
return 0;
188189

189-
if (r->dscp && !fib_dscp_masked_match(r->dscp, fl4))
190+
/* When DSCP selector is used we need to match on the entire DSCP field
191+
* in the flow information structure. When TOS selector is used we need
192+
* to mask the upper three DSCP bits prior to matching to maintain
193+
* legacy behavior.
194+
*/
195+
if (r->dscp_full && r->dscp != inet_dsfield_to_dscp(fl4->flowi4_tos))
196+
return 0;
197+
else if (!r->dscp_full && r->dscp &&
198+
!fib_dscp_masked_match(r->dscp, fl4))
190199
return 0;
191200

192201
if (rule->ip_proto && (rule->ip_proto != fl4->flowi4_proto))
@@ -217,6 +226,20 @@ static struct fib_table *fib_empty_table(struct net *net)
217226
return NULL;
218227
}
219228

229+
static int fib4_nl2rule_dscp(const struct nlattr *nla, struct fib4_rule *rule4,
230+
struct netlink_ext_ack *extack)
231+
{
232+
if (rule4->dscp) {
233+
NL_SET_ERR_MSG(extack, "Cannot specify both TOS and DSCP");
234+
return -EINVAL;
235+
}
236+
237+
rule4->dscp = inet_dsfield_to_dscp(nla_get_u8(nla) << 2);
238+
rule4->dscp_full = true;
239+
240+
return 0;
241+
}
242+
220243
static int fib4_rule_configure(struct fib_rule *rule, struct sk_buff *skb,
221244
struct fib_rule_hdr *frh,
222245
struct nlattr **tb,
@@ -238,6 +261,10 @@ static int fib4_rule_configure(struct fib_rule *rule, struct sk_buff *skb,
238261
}
239262
rule4->dscp = inet_dsfield_to_dscp(frh->tos);
240263

264+
if (tb[FRA_DSCP] &&
265+
fib4_nl2rule_dscp(tb[FRA_DSCP], rule4, extack) < 0)
266+
goto errout;
267+
241268
/* split local/main if they are not already split */
242269
err = fib_unmerge(net);
243270
if (err)
@@ -320,9 +347,19 @@ static int fib4_rule_compare(struct fib_rule *rule, struct fib_rule_hdr *frh,
320347
if (frh->dst_len && (rule4->dst_len != frh->dst_len))
321348
return 0;
322349

323-
if (frh->tos && inet_dscp_to_dsfield(rule4->dscp) != frh->tos)
350+
if (frh->tos &&
351+
(rule4->dscp_full ||
352+
inet_dscp_to_dsfield(rule4->dscp) != frh->tos))
324353
return 0;
325354

355+
if (tb[FRA_DSCP]) {
356+
dscp_t dscp;
357+
358+
dscp = inet_dsfield_to_dscp(nla_get_u8(tb[FRA_DSCP]) << 2);
359+
if (!rule4->dscp_full || rule4->dscp != dscp)
360+
return 0;
361+
}
362+
326363
#ifdef CONFIG_IP_ROUTE_CLASSID
327364
if (tb[FRA_FLOW] && (rule4->tclassid != nla_get_u32(tb[FRA_FLOW])))
328365
return 0;
@@ -344,7 +381,15 @@ static int fib4_rule_fill(struct fib_rule *rule, struct sk_buff *skb,
344381

345382
frh->dst_len = rule4->dst_len;
346383
frh->src_len = rule4->src_len;
347-
frh->tos = inet_dscp_to_dsfield(rule4->dscp);
384+
385+
if (rule4->dscp_full) {
386+
frh->tos = 0;
387+
if (nla_put_u8(skb, FRA_DSCP,
388+
inet_dscp_to_dsfield(rule4->dscp) >> 2))
389+
goto nla_put_failure;
390+
} else {
391+
frh->tos = inet_dscp_to_dsfield(rule4->dscp);
392+
}
348393

349394
if ((rule4->dst_len &&
350395
nla_put_in_addr(skb, FRA_DST, rule4->dst)) ||
@@ -366,7 +411,8 @@ static size_t fib4_rule_nlmsg_payload(struct fib_rule *rule)
366411
{
367412
return nla_total_size(4) /* dst */
368413
+ nla_total_size(4) /* src */
369-
+ nla_total_size(4); /* flow */
414+
+ nla_total_size(4) /* flow */
415+
+ nla_total_size(1); /* dscp */
370416
}
371417

372418
static void fib4_rule_flush_cache(struct fib_rules_ops *ops)

0 commit comments

Comments
 (0)