GNU Linux-libre 4.14.290-gnu1
[releases.git] / net / sched / cls_u32.c
1 /*
2  * net/sched/cls_u32.c  Ugly (or Universal) 32bit key Packet Classifier.
3  *
4  *              This program is free software; you can redistribute it and/or
5  *              modify it under the terms of the GNU General Public License
6  *              as published by the Free Software Foundation; either version
7  *              2 of the License, or (at your option) any later version.
8  *
9  * Authors:     Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
10  *
11  *      The filters are packed to hash tables of key nodes
12  *      with a set of 32bit key/mask pairs at every node.
13  *      Nodes reference next level hash tables etc.
14  *
15  *      This scheme is the best universal classifier I managed to
16  *      invent; it is not super-fast, but it is not slow (provided you
17  *      program it correctly), and general enough.  And its relative
18  *      speed grows as the number of rules becomes larger.
19  *
20  *      It seems that it represents the best middle point between
21  *      speed and manageability both by human and by machine.
22  *
23  *      It is especially useful for link sharing combined with QoS;
24  *      pure RSVP doesn't need such a general approach and can use
25  *      much simpler (and faster) schemes, sort of cls_rsvp.c.
26  *
27  *      JHS: We should remove the CONFIG_NET_CLS_IND from here
28  *      eventually when the meta match extension is made available
29  *
30  *      nfmark match added by Catalin(ux aka Dino) BOIE <catab at umbrella.ro>
31  */
32
33 #include <linux/module.h>
34 #include <linux/slab.h>
35 #include <linux/types.h>
36 #include <linux/kernel.h>
37 #include <linux/string.h>
38 #include <linux/errno.h>
39 #include <linux/percpu.h>
40 #include <linux/rtnetlink.h>
41 #include <linux/skbuff.h>
42 #include <linux/bitmap.h>
43 #include <linux/netdevice.h>
44 #include <linux/hash.h>
45 #include <net/netlink.h>
46 #include <net/act_api.h>
47 #include <net/pkt_cls.h>
48 #include <linux/netdevice.h>
49
50 struct tc_u_knode {
51         struct tc_u_knode __rcu *next;
52         u32                     handle;
53         struct tc_u_hnode __rcu *ht_up;
54         struct tcf_exts         exts;
55 #ifdef CONFIG_NET_CLS_IND
56         int                     ifindex;
57 #endif
58         u8                      fshift;
59         struct tcf_result       res;
60         struct tc_u_hnode __rcu *ht_down;
61 #ifdef CONFIG_CLS_U32_PERF
62         struct tc_u32_pcnt __percpu *pf;
63 #endif
64         u32                     flags;
65 #ifdef CONFIG_CLS_U32_MARK
66         u32                     val;
67         u32                     mask;
68         u32 __percpu            *pcpu_success;
69 #endif
70         struct tcf_proto        *tp;
71         union {
72                 struct work_struct      work;
73                 struct rcu_head         rcu;
74         };
75         /* The 'sel' field MUST be the last field in structure to allow for
76          * tc_u32_keys allocated at end of structure.
77          */
78         struct tc_u32_sel       sel;
79 };
80
81 struct tc_u_hnode {
82         struct tc_u_hnode __rcu *next;
83         u32                     handle;
84         u32                     prio;
85         struct tc_u_common      *tp_c;
86         int                     refcnt;
87         unsigned int            divisor;
88         struct rcu_head         rcu;
89         /* The 'ht' field MUST be the last field in structure to allow for
90          * more entries allocated at end of structure.
91          */
92         struct tc_u_knode __rcu *ht[1];
93 };
94
95 struct tc_u_common {
96         struct tc_u_hnode __rcu *hlist;
97         struct Qdisc            *q;
98         int                     refcnt;
99         u32                     hgenerator;
100         struct hlist_node       hnode;
101         struct rcu_head         rcu;
102 };
103
104 static inline unsigned int u32_hash_fold(__be32 key,
105                                          const struct tc_u32_sel *sel,
106                                          u8 fshift)
107 {
108         unsigned int h = ntohl(key & sel->hmask) >> fshift;
109
110         return h;
111 }
112
113 static int u32_classify(struct sk_buff *skb, const struct tcf_proto *tp,
114                         struct tcf_result *res)
115 {
116         struct {
117                 struct tc_u_knode *knode;
118                 unsigned int      off;
119         } stack[TC_U32_MAXDEPTH];
120
121         struct tc_u_hnode *ht = rcu_dereference_bh(tp->root);
122         unsigned int off = skb_network_offset(skb);
123         struct tc_u_knode *n;
124         int sdepth = 0;
125         int off2 = 0;
126         int sel = 0;
127 #ifdef CONFIG_CLS_U32_PERF
128         int j;
129 #endif
130         int i, r;
131
132 next_ht:
133         n = rcu_dereference_bh(ht->ht[sel]);
134
135 next_knode:
136         if (n) {
137                 struct tc_u32_key *key = n->sel.keys;
138
139 #ifdef CONFIG_CLS_U32_PERF
140                 __this_cpu_inc(n->pf->rcnt);
141                 j = 0;
142 #endif
143
144                 if (tc_skip_sw(n->flags)) {
145                         n = rcu_dereference_bh(n->next);
146                         goto next_knode;
147                 }
148
149 #ifdef CONFIG_CLS_U32_MARK
150                 if ((skb->mark & n->mask) != n->val) {
151                         n = rcu_dereference_bh(n->next);
152                         goto next_knode;
153                 } else {
154                         __this_cpu_inc(*n->pcpu_success);
155                 }
156 #endif
157
158                 for (i = n->sel.nkeys; i > 0; i--, key++) {
159                         int toff = off + key->off + (off2 & key->offmask);
160                         __be32 *data, hdata;
161
162                         if (skb_headroom(skb) + toff > INT_MAX)
163                                 goto out;
164
165                         data = skb_header_pointer(skb, toff, 4, &hdata);
166                         if (!data)
167                                 goto out;
168                         if ((*data ^ key->val) & key->mask) {
169                                 n = rcu_dereference_bh(n->next);
170                                 goto next_knode;
171                         }
172 #ifdef CONFIG_CLS_U32_PERF
173                         __this_cpu_inc(n->pf->kcnts[j]);
174                         j++;
175 #endif
176                 }
177
178                 ht = rcu_dereference_bh(n->ht_down);
179                 if (!ht) {
180 check_terminal:
181                         if (n->sel.flags & TC_U32_TERMINAL) {
182
183                                 *res = n->res;
184 #ifdef CONFIG_NET_CLS_IND
185                                 if (!tcf_match_indev(skb, n->ifindex)) {
186                                         n = rcu_dereference_bh(n->next);
187                                         goto next_knode;
188                                 }
189 #endif
190 #ifdef CONFIG_CLS_U32_PERF
191                                 __this_cpu_inc(n->pf->rhit);
192 #endif
193                                 r = tcf_exts_exec(skb, &n->exts, res);
194                                 if (r < 0) {
195                                         n = rcu_dereference_bh(n->next);
196                                         goto next_knode;
197                                 }
198
199                                 return r;
200                         }
201                         n = rcu_dereference_bh(n->next);
202                         goto next_knode;
203                 }
204
205                 /* PUSH */
206                 if (sdepth >= TC_U32_MAXDEPTH)
207                         goto deadloop;
208                 stack[sdepth].knode = n;
209                 stack[sdepth].off = off;
210                 sdepth++;
211
212                 ht = rcu_dereference_bh(n->ht_down);
213                 sel = 0;
214                 if (ht->divisor) {
215                         __be32 *data, hdata;
216
217                         data = skb_header_pointer(skb, off + n->sel.hoff, 4,
218                                                   &hdata);
219                         if (!data)
220                                 goto out;
221                         sel = ht->divisor & u32_hash_fold(*data, &n->sel,
222                                                           n->fshift);
223                 }
224                 if (!(n->sel.flags & (TC_U32_VAROFFSET | TC_U32_OFFSET | TC_U32_EAT)))
225                         goto next_ht;
226
227                 if (n->sel.flags & (TC_U32_OFFSET | TC_U32_VAROFFSET)) {
228                         off2 = n->sel.off + 3;
229                         if (n->sel.flags & TC_U32_VAROFFSET) {
230                                 __be16 *data, hdata;
231
232                                 data = skb_header_pointer(skb,
233                                                           off + n->sel.offoff,
234                                                           2, &hdata);
235                                 if (!data)
236                                         goto out;
237                                 off2 += ntohs(n->sel.offmask & *data) >>
238                                         n->sel.offshift;
239                         }
240                         off2 &= ~3;
241                 }
242                 if (n->sel.flags & TC_U32_EAT) {
243                         off += off2;
244                         off2 = 0;
245                 }
246
247                 if (off < skb->len)
248                         goto next_ht;
249         }
250
251         /* POP */
252         if (sdepth--) {
253                 n = stack[sdepth].knode;
254                 ht = rcu_dereference_bh(n->ht_up);
255                 off = stack[sdepth].off;
256                 goto check_terminal;
257         }
258 out:
259         return -1;
260
261 deadloop:
262         net_warn_ratelimited("cls_u32: dead loop\n");
263         return -1;
264 }
265
266 static struct tc_u_hnode *u32_lookup_ht(struct tc_u_common *tp_c, u32 handle)
267 {
268         struct tc_u_hnode *ht;
269
270         for (ht = rtnl_dereference(tp_c->hlist);
271              ht;
272              ht = rtnl_dereference(ht->next))
273                 if (ht->handle == handle)
274                         break;
275
276         return ht;
277 }
278
279 static struct tc_u_knode *u32_lookup_key(struct tc_u_hnode *ht, u32 handle)
280 {
281         unsigned int sel;
282         struct tc_u_knode *n = NULL;
283
284         sel = TC_U32_HASH(handle);
285         if (sel > ht->divisor)
286                 goto out;
287
288         for (n = rtnl_dereference(ht->ht[sel]);
289              n;
290              n = rtnl_dereference(n->next))
291                 if (n->handle == handle)
292                         break;
293 out:
294         return n;
295 }
296
297
298 static void *u32_get(struct tcf_proto *tp, u32 handle)
299 {
300         struct tc_u_hnode *ht;
301         struct tc_u_common *tp_c = tp->data;
302
303         if (TC_U32_HTID(handle) == TC_U32_ROOT)
304                 ht = rtnl_dereference(tp->root);
305         else
306                 ht = u32_lookup_ht(tp_c, TC_U32_HTID(handle));
307
308         if (!ht)
309                 return NULL;
310
311         if (TC_U32_KEY(handle) == 0)
312                 return ht;
313
314         return u32_lookup_key(ht, handle);
315 }
316
317 static u32 gen_new_htid(struct tc_u_common *tp_c)
318 {
319         int i = 0x800;
320
321         /* hgenerator only used inside rtnl lock it is safe to increment
322          * without read _copy_ update semantics
323          */
324         do {
325                 if (++tp_c->hgenerator == 0x7FF)
326                         tp_c->hgenerator = 1;
327         } while (--i > 0 && u32_lookup_ht(tp_c, (tp_c->hgenerator|0x800)<<20));
328
329         return i > 0 ? (tp_c->hgenerator|0x800)<<20 : 0;
330 }
331
332 static struct hlist_head *tc_u_common_hash;
333
334 #define U32_HASH_SHIFT 10
335 #define U32_HASH_SIZE (1 << U32_HASH_SHIFT)
336
337 static unsigned int tc_u_hash(const struct tcf_proto *tp)
338 {
339         struct net_device *dev = tp->q->dev_queue->dev;
340         u32 qhandle = tp->q->handle;
341         int ifindex = dev->ifindex;
342
343         return hash_64((u64)ifindex << 32 | qhandle, U32_HASH_SHIFT);
344 }
345
346 static struct tc_u_common *tc_u_common_find(const struct tcf_proto *tp)
347 {
348         struct tc_u_common *tc;
349         unsigned int h;
350
351         h = tc_u_hash(tp);
352         hlist_for_each_entry(tc, &tc_u_common_hash[h], hnode) {
353                 if (tc->q == tp->q)
354                         return tc;
355         }
356         return NULL;
357 }
358
359 static int u32_init(struct tcf_proto *tp)
360 {
361         struct tc_u_hnode *root_ht;
362         struct tc_u_common *tp_c;
363         unsigned int h;
364
365         tp_c = tc_u_common_find(tp);
366
367         root_ht = kzalloc(sizeof(*root_ht), GFP_KERNEL);
368         if (root_ht == NULL)
369                 return -ENOBUFS;
370
371         root_ht->refcnt++;
372         root_ht->handle = tp_c ? gen_new_htid(tp_c) : 0x80000000;
373         root_ht->prio = tp->prio;
374
375         if (tp_c == NULL) {
376                 tp_c = kzalloc(sizeof(*tp_c), GFP_KERNEL);
377                 if (tp_c == NULL) {
378                         kfree(root_ht);
379                         return -ENOBUFS;
380                 }
381                 tp_c->q = tp->q;
382                 INIT_HLIST_NODE(&tp_c->hnode);
383
384                 h = tc_u_hash(tp);
385                 hlist_add_head(&tp_c->hnode, &tc_u_common_hash[h]);
386         }
387
388         tp_c->refcnt++;
389         RCU_INIT_POINTER(root_ht->next, tp_c->hlist);
390         rcu_assign_pointer(tp_c->hlist, root_ht);
391         root_ht->tp_c = tp_c;
392
393         rcu_assign_pointer(tp->root, root_ht);
394         tp->data = tp_c;
395         return 0;
396 }
397
398 static void __u32_destroy_key(struct tc_u_knode *n)
399 {
400         struct tc_u_hnode *ht = rtnl_dereference(n->ht_down);
401
402         tcf_exts_destroy(&n->exts);
403         if (ht && --ht->refcnt == 0)
404                 kfree(ht);
405         kfree(n);
406 }
407
408 static void u32_destroy_key(struct tcf_proto *tp, struct tc_u_knode *n,
409                            bool free_pf)
410 {
411         tcf_exts_put_net(&n->exts);
412 #ifdef CONFIG_CLS_U32_PERF
413         if (free_pf)
414                 free_percpu(n->pf);
415 #endif
416 #ifdef CONFIG_CLS_U32_MARK
417         if (free_pf)
418                 free_percpu(n->pcpu_success);
419 #endif
420         __u32_destroy_key(n);
421 }
422
423 /* u32_delete_key_rcu should be called when free'ing a copied
424  * version of a tc_u_knode obtained from u32_init_knode(). When
425  * copies are obtained from u32_init_knode() the statistics are
426  * shared between the old and new copies to allow readers to
427  * continue to update the statistics during the copy. To support
428  * this the u32_delete_key_rcu variant does not free the percpu
429  * statistics.
430  */
431 static void u32_delete_key_work(struct work_struct *work)
432 {
433         struct tc_u_knode *key = container_of(work, struct tc_u_knode, work);
434
435         rtnl_lock();
436         u32_destroy_key(key->tp, key, false);
437         rtnl_unlock();
438 }
439
440 static void u32_delete_key_rcu(struct rcu_head *rcu)
441 {
442         struct tc_u_knode *key = container_of(rcu, struct tc_u_knode, rcu);
443
444         INIT_WORK(&key->work, u32_delete_key_work);
445         tcf_queue_work(&key->work);
446 }
447
448 /* u32_delete_key_freepf_rcu is the rcu callback variant
449  * that free's the entire structure including the statistics
450  * percpu variables. Only use this if the key is not a copy
451  * returned by u32_init_knode(). See u32_delete_key_rcu()
452  * for the variant that should be used with keys return from
453  * u32_init_knode()
454  */
455 static void u32_delete_key_freepf_work(struct work_struct *work)
456 {
457         struct tc_u_knode *key = container_of(work, struct tc_u_knode, work);
458
459         rtnl_lock();
460         u32_destroy_key(key->tp, key, true);
461         rtnl_unlock();
462 }
463
464 static void u32_delete_key_freepf_rcu(struct rcu_head *rcu)
465 {
466         struct tc_u_knode *key = container_of(rcu, struct tc_u_knode, rcu);
467
468         INIT_WORK(&key->work, u32_delete_key_freepf_work);
469         tcf_queue_work(&key->work);
470 }
471
472 static int u32_delete_key(struct tcf_proto *tp, struct tc_u_knode *key)
473 {
474         struct tc_u_knode __rcu **kp;
475         struct tc_u_knode *pkp;
476         struct tc_u_hnode *ht = rtnl_dereference(key->ht_up);
477
478         if (ht) {
479                 kp = &ht->ht[TC_U32_HASH(key->handle)];
480                 for (pkp = rtnl_dereference(*kp); pkp;
481                      kp = &pkp->next, pkp = rtnl_dereference(*kp)) {
482                         if (pkp == key) {
483                                 RCU_INIT_POINTER(*kp, key->next);
484
485                                 tcf_unbind_filter(tp, &key->res);
486                                 tcf_exts_get_net(&key->exts);
487                                 call_rcu(&key->rcu, u32_delete_key_freepf_rcu);
488                                 return 0;
489                         }
490                 }
491         }
492         WARN_ON(1);
493         return 0;
494 }
495
496 static void u32_remove_hw_knode(struct tcf_proto *tp, u32 handle)
497 {
498         struct net_device *dev = tp->q->dev_queue->dev;
499         struct tc_cls_u32_offload cls_u32 = {};
500
501         if (!tc_should_offload(dev, 0))
502                 return;
503
504         tc_cls_common_offload_init(&cls_u32.common, tp);
505         cls_u32.command = TC_CLSU32_DELETE_KNODE;
506         cls_u32.knode.handle = handle;
507
508         dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSU32, &cls_u32);
509 }
510
511 static int u32_replace_hw_hnode(struct tcf_proto *tp, struct tc_u_hnode *h,
512                                 u32 flags)
513 {
514         struct net_device *dev = tp->q->dev_queue->dev;
515         struct tc_cls_u32_offload cls_u32 = {};
516         int err;
517
518         if (!tc_should_offload(dev, flags))
519                 return tc_skip_sw(flags) ? -EINVAL : 0;
520
521         tc_cls_common_offload_init(&cls_u32.common, tp);
522         cls_u32.command = TC_CLSU32_NEW_HNODE;
523         cls_u32.hnode.divisor = h->divisor;
524         cls_u32.hnode.handle = h->handle;
525         cls_u32.hnode.prio = h->prio;
526
527         err = dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSU32, &cls_u32);
528         if (tc_skip_sw(flags))
529                 return err;
530
531         return 0;
532 }
533
534 static void u32_clear_hw_hnode(struct tcf_proto *tp, struct tc_u_hnode *h)
535 {
536         struct net_device *dev = tp->q->dev_queue->dev;
537         struct tc_cls_u32_offload cls_u32 = {};
538
539         if (!tc_should_offload(dev, 0))
540                 return;
541
542         tc_cls_common_offload_init(&cls_u32.common, tp);
543         cls_u32.command = TC_CLSU32_DELETE_HNODE;
544         cls_u32.hnode.divisor = h->divisor;
545         cls_u32.hnode.handle = h->handle;
546         cls_u32.hnode.prio = h->prio;
547
548         dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSU32, &cls_u32);
549 }
550
551 static int u32_replace_hw_knode(struct tcf_proto *tp, struct tc_u_knode *n,
552                                 u32 flags)
553 {
554         struct net_device *dev = tp->q->dev_queue->dev;
555         struct tc_cls_u32_offload cls_u32 = {};
556         int err;
557
558         if (!tc_should_offload(dev, flags))
559                 return tc_skip_sw(flags) ? -EINVAL : 0;
560
561         tc_cls_common_offload_init(&cls_u32.common, tp);
562         cls_u32.command = TC_CLSU32_REPLACE_KNODE;
563         cls_u32.knode.handle = n->handle;
564         cls_u32.knode.fshift = n->fshift;
565 #ifdef CONFIG_CLS_U32_MARK
566         cls_u32.knode.val = n->val;
567         cls_u32.knode.mask = n->mask;
568 #else
569         cls_u32.knode.val = 0;
570         cls_u32.knode.mask = 0;
571 #endif
572         cls_u32.knode.sel = &n->sel;
573         cls_u32.knode.exts = &n->exts;
574         if (n->ht_down)
575                 cls_u32.knode.link_handle = n->ht_down->handle;
576
577         err = dev->netdev_ops->ndo_setup_tc(dev, TC_SETUP_CLSU32, &cls_u32);
578
579         if (!err)
580                 n->flags |= TCA_CLS_FLAGS_IN_HW;
581
582         if (tc_skip_sw(flags))
583                 return err;
584
585         return 0;
586 }
587
588 static void u32_clear_hnode(struct tcf_proto *tp, struct tc_u_hnode *ht)
589 {
590         struct tc_u_knode *n;
591         unsigned int h;
592
593         for (h = 0; h <= ht->divisor; h++) {
594                 while ((n = rtnl_dereference(ht->ht[h])) != NULL) {
595                         RCU_INIT_POINTER(ht->ht[h],
596                                          rtnl_dereference(n->next));
597                         tcf_unbind_filter(tp, &n->res);
598                         u32_remove_hw_knode(tp, n->handle);
599                         if (tcf_exts_get_net(&n->exts))
600                                 call_rcu(&n->rcu, u32_delete_key_freepf_rcu);
601                         else
602                                 u32_destroy_key(n->tp, n, true);
603                 }
604         }
605 }
606
607 static int u32_destroy_hnode(struct tcf_proto *tp, struct tc_u_hnode *ht)
608 {
609         struct tc_u_common *tp_c = tp->data;
610         struct tc_u_hnode __rcu **hn;
611         struct tc_u_hnode *phn;
612
613         WARN_ON(ht->refcnt);
614
615         u32_clear_hnode(tp, ht);
616
617         hn = &tp_c->hlist;
618         for (phn = rtnl_dereference(*hn);
619              phn;
620              hn = &phn->next, phn = rtnl_dereference(*hn)) {
621                 if (phn == ht) {
622                         u32_clear_hw_hnode(tp, ht);
623                         RCU_INIT_POINTER(*hn, ht->next);
624                         kfree_rcu(ht, rcu);
625                         return 0;
626                 }
627         }
628
629         return -ENOENT;
630 }
631
632 static bool ht_empty(struct tc_u_hnode *ht)
633 {
634         unsigned int h;
635
636         for (h = 0; h <= ht->divisor; h++)
637                 if (rcu_access_pointer(ht->ht[h]))
638                         return false;
639
640         return true;
641 }
642
643 static void u32_destroy(struct tcf_proto *tp)
644 {
645         struct tc_u_common *tp_c = tp->data;
646         struct tc_u_hnode *root_ht = rtnl_dereference(tp->root);
647
648         WARN_ON(root_ht == NULL);
649
650         if (root_ht && --root_ht->refcnt == 0)
651                 u32_destroy_hnode(tp, root_ht);
652
653         if (--tp_c->refcnt == 0) {
654                 struct tc_u_hnode *ht;
655
656                 hlist_del(&tp_c->hnode);
657
658                 while ((ht = rtnl_dereference(tp_c->hlist)) != NULL) {
659                         u32_clear_hnode(tp, ht);
660                         RCU_INIT_POINTER(tp_c->hlist, ht->next);
661
662                         /* u32_destroy_key() will later free ht for us, if it's
663                          * still referenced by some knode
664                          */
665                         if (--ht->refcnt == 0)
666                                 kfree_rcu(ht, rcu);
667                 }
668
669                 kfree(tp_c);
670         }
671
672         tp->data = NULL;
673 }
674
675 static int u32_delete(struct tcf_proto *tp, void *arg, bool *last)
676 {
677         struct tc_u_hnode *ht = arg;
678         struct tc_u_hnode *root_ht = rtnl_dereference(tp->root);
679         struct tc_u_common *tp_c = tp->data;
680         int ret = 0;
681
682         if (ht == NULL)
683                 goto out;
684
685         if (TC_U32_KEY(ht->handle)) {
686                 u32_remove_hw_knode(tp, ht->handle);
687                 ret = u32_delete_key(tp, (struct tc_u_knode *)ht);
688                 goto out;
689         }
690
691         if (root_ht == ht)
692                 return -EINVAL;
693
694         if (ht->refcnt == 1) {
695                 ht->refcnt--;
696                 u32_destroy_hnode(tp, ht);
697         } else {
698                 return -EBUSY;
699         }
700
701 out:
702         *last = true;
703         if (root_ht) {
704                 if (root_ht->refcnt > 1) {
705                         *last = false;
706                         goto ret;
707                 }
708                 if (root_ht->refcnt == 1) {
709                         if (!ht_empty(root_ht)) {
710                                 *last = false;
711                                 goto ret;
712                         }
713                 }
714         }
715
716         if (tp_c->refcnt > 1) {
717                 *last = false;
718                 goto ret;
719         }
720
721         if (tp_c->refcnt == 1) {
722                 struct tc_u_hnode *ht;
723
724                 for (ht = rtnl_dereference(tp_c->hlist);
725                      ht;
726                      ht = rtnl_dereference(ht->next))
727                         if (!ht_empty(ht)) {
728                                 *last = false;
729                                 break;
730                         }
731         }
732
733 ret:
734         return ret;
735 }
736
737 #define NR_U32_NODE (1<<12)
738 static u32 gen_new_kid(struct tc_u_hnode *ht, u32 handle)
739 {
740         struct tc_u_knode *n;
741         unsigned long i;
742         unsigned long *bitmap = kzalloc(BITS_TO_LONGS(NR_U32_NODE) * sizeof(unsigned long),
743                                         GFP_KERNEL);
744         if (!bitmap)
745                 return handle | 0xFFF;
746
747         for (n = rtnl_dereference(ht->ht[TC_U32_HASH(handle)]);
748              n;
749              n = rtnl_dereference(n->next))
750                 set_bit(TC_U32_NODE(n->handle), bitmap);
751
752         i = find_next_zero_bit(bitmap, NR_U32_NODE, 0x800);
753         if (i >= NR_U32_NODE)
754                 i = find_next_zero_bit(bitmap, NR_U32_NODE, 1);
755
756         kfree(bitmap);
757         return handle | (i >= NR_U32_NODE ? 0xFFF : i);
758 }
759
760 static const struct nla_policy u32_policy[TCA_U32_MAX + 1] = {
761         [TCA_U32_CLASSID]       = { .type = NLA_U32 },
762         [TCA_U32_HASH]          = { .type = NLA_U32 },
763         [TCA_U32_LINK]          = { .type = NLA_U32 },
764         [TCA_U32_DIVISOR]       = { .type = NLA_U32 },
765         [TCA_U32_SEL]           = { .len = sizeof(struct tc_u32_sel) },
766         [TCA_U32_INDEV]         = { .type = NLA_STRING, .len = IFNAMSIZ },
767         [TCA_U32_MARK]          = { .len = sizeof(struct tc_u32_mark) },
768         [TCA_U32_FLAGS]         = { .type = NLA_U32 },
769 };
770
771 static int u32_set_parms(struct net *net, struct tcf_proto *tp,
772                          unsigned long base, struct tc_u_hnode *ht,
773                          struct tc_u_knode *n, struct nlattr **tb,
774                          struct nlattr *est, bool ovr)
775 {
776         int err;
777
778         err = tcf_exts_validate(net, tp, tb, est, &n->exts, ovr);
779         if (err < 0)
780                 return err;
781
782         if (tb[TCA_U32_LINK]) {
783                 u32 handle = nla_get_u32(tb[TCA_U32_LINK]);
784                 struct tc_u_hnode *ht_down = NULL, *ht_old;
785
786                 if (TC_U32_KEY(handle))
787                         return -EINVAL;
788
789                 if (handle) {
790                         ht_down = u32_lookup_ht(ht->tp_c, handle);
791
792                         if (ht_down == NULL)
793                                 return -EINVAL;
794                         ht_down->refcnt++;
795                 }
796
797                 ht_old = rtnl_dereference(n->ht_down);
798                 rcu_assign_pointer(n->ht_down, ht_down);
799
800                 if (ht_old)
801                         ht_old->refcnt--;
802         }
803         if (tb[TCA_U32_CLASSID]) {
804                 n->res.classid = nla_get_u32(tb[TCA_U32_CLASSID]);
805                 tcf_bind_filter(tp, &n->res, base);
806         }
807
808 #ifdef CONFIG_NET_CLS_IND
809         if (tb[TCA_U32_INDEV]) {
810                 int ret;
811                 ret = tcf_change_indev(net, tb[TCA_U32_INDEV]);
812                 if (ret < 0)
813                         return -EINVAL;
814                 n->ifindex = ret;
815         }
816 #endif
817         return 0;
818 }
819
820 static void u32_replace_knode(struct tcf_proto *tp, struct tc_u_common *tp_c,
821                               struct tc_u_knode *n)
822 {
823         struct tc_u_knode __rcu **ins;
824         struct tc_u_knode *pins;
825         struct tc_u_hnode *ht;
826
827         if (TC_U32_HTID(n->handle) == TC_U32_ROOT)
828                 ht = rtnl_dereference(tp->root);
829         else
830                 ht = u32_lookup_ht(tp_c, TC_U32_HTID(n->handle));
831
832         ins = &ht->ht[TC_U32_HASH(n->handle)];
833
834         /* The node must always exist for it to be replaced if this is not the
835          * case then something went very wrong elsewhere.
836          */
837         for (pins = rtnl_dereference(*ins); ;
838              ins = &pins->next, pins = rtnl_dereference(*ins))
839                 if (pins->handle == n->handle)
840                         break;
841
842         RCU_INIT_POINTER(n->next, pins->next);
843         rcu_assign_pointer(*ins, n);
844 }
845
846 static struct tc_u_knode *u32_init_knode(struct tcf_proto *tp,
847                                          struct tc_u_knode *n)
848 {
849         struct tc_u_knode *new;
850         struct tc_u32_sel *s = &n->sel;
851
852         new = kzalloc(sizeof(*n) + s->nkeys*sizeof(struct tc_u32_key),
853                       GFP_KERNEL);
854
855         if (!new)
856                 return NULL;
857
858         RCU_INIT_POINTER(new->next, n->next);
859         new->handle = n->handle;
860         RCU_INIT_POINTER(new->ht_up, n->ht_up);
861
862 #ifdef CONFIG_NET_CLS_IND
863         new->ifindex = n->ifindex;
864 #endif
865         new->fshift = n->fshift;
866         new->res = n->res;
867         new->flags = n->flags;
868         RCU_INIT_POINTER(new->ht_down, n->ht_down);
869
870         /* bump reference count as long as we hold pointer to structure */
871         if (new->ht_down)
872                 new->ht_down->refcnt++;
873
874 #ifdef CONFIG_CLS_U32_PERF
875         /* Statistics may be incremented by readers during update
876          * so we must keep them in tact. When the node is later destroyed
877          * a special destroy call must be made to not free the pf memory.
878          */
879         new->pf = n->pf;
880 #endif
881
882 #ifdef CONFIG_CLS_U32_MARK
883         new->val = n->val;
884         new->mask = n->mask;
885         /* Similarly success statistics must be moved as pointers */
886         new->pcpu_success = n->pcpu_success;
887 #endif
888         new->tp = tp;
889         memcpy(&new->sel, s, sizeof(*s) + s->nkeys*sizeof(struct tc_u32_key));
890
891         if (tcf_exts_init(&new->exts, TCA_U32_ACT, TCA_U32_POLICE)) {
892                 kfree(new);
893                 return NULL;
894         }
895
896         return new;
897 }
898
899 static int u32_change(struct net *net, struct sk_buff *in_skb,
900                       struct tcf_proto *tp, unsigned long base, u32 handle,
901                       struct nlattr **tca, void **arg, bool ovr)
902 {
903         struct tc_u_common *tp_c = tp->data;
904         struct tc_u_hnode *ht;
905         struct tc_u_knode *n;
906         struct tc_u32_sel *s;
907         struct nlattr *opt = tca[TCA_OPTIONS];
908         struct nlattr *tb[TCA_U32_MAX + 1];
909         u32 htid, flags = 0;
910         size_t sel_size;
911         int err;
912 #ifdef CONFIG_CLS_U32_PERF
913         size_t size;
914 #endif
915
916         if (opt == NULL)
917                 return handle ? -EINVAL : 0;
918
919         err = nla_parse_nested(tb, TCA_U32_MAX, opt, u32_policy, NULL);
920         if (err < 0)
921                 return err;
922
923         if (tb[TCA_U32_FLAGS]) {
924                 flags = nla_get_u32(tb[TCA_U32_FLAGS]);
925                 if (!tc_flags_valid(flags))
926                         return -EINVAL;
927         }
928
929         n = *arg;
930         if (n) {
931                 struct tc_u_knode *new;
932
933                 if (TC_U32_KEY(n->handle) == 0)
934                         return -EINVAL;
935
936                 if ((n->flags ^ flags) &
937                     ~(TCA_CLS_FLAGS_IN_HW | TCA_CLS_FLAGS_NOT_IN_HW))
938                         return -EINVAL;
939
940                 new = u32_init_knode(tp, n);
941                 if (!new)
942                         return -ENOMEM;
943
944                 err = u32_set_parms(net, tp, base,
945                                     rtnl_dereference(n->ht_up), new, tb,
946                                     tca[TCA_RATE], ovr);
947
948                 if (err) {
949                         __u32_destroy_key(new);
950                         return err;
951                 }
952
953                 err = u32_replace_hw_knode(tp, new, flags);
954                 if (err) {
955                         __u32_destroy_key(new);
956                         return err;
957                 }
958
959                 if (!tc_in_hw(new->flags))
960                         new->flags |= TCA_CLS_FLAGS_NOT_IN_HW;
961
962                 u32_replace_knode(tp, tp_c, new);
963                 tcf_unbind_filter(tp, &n->res);
964                 tcf_exts_get_net(&n->exts);
965                 call_rcu(&n->rcu, u32_delete_key_rcu);
966                 return 0;
967         }
968
969         if (tb[TCA_U32_DIVISOR]) {
970                 unsigned int divisor = nla_get_u32(tb[TCA_U32_DIVISOR]);
971
972                 if (--divisor > 0x100)
973                         return -EINVAL;
974                 if (TC_U32_KEY(handle))
975                         return -EINVAL;
976                 if (handle == 0) {
977                         handle = gen_new_htid(tp->data);
978                         if (handle == 0)
979                                 return -ENOMEM;
980                 }
981                 ht = kzalloc(sizeof(*ht) + divisor*sizeof(void *), GFP_KERNEL);
982                 if (ht == NULL)
983                         return -ENOBUFS;
984                 ht->tp_c = tp_c;
985                 ht->refcnt = 1;
986                 ht->divisor = divisor;
987                 ht->handle = handle;
988                 ht->prio = tp->prio;
989
990                 err = u32_replace_hw_hnode(tp, ht, flags);
991                 if (err) {
992                         kfree(ht);
993                         return err;
994                 }
995
996                 RCU_INIT_POINTER(ht->next, tp_c->hlist);
997                 rcu_assign_pointer(tp_c->hlist, ht);
998                 *arg = ht;
999
1000                 return 0;
1001         }
1002
1003         if (tb[TCA_U32_HASH]) {
1004                 htid = nla_get_u32(tb[TCA_U32_HASH]);
1005                 if (TC_U32_HTID(htid) == TC_U32_ROOT) {
1006                         ht = rtnl_dereference(tp->root);
1007                         htid = ht->handle;
1008                 } else {
1009                         ht = u32_lookup_ht(tp->data, TC_U32_HTID(htid));
1010                         if (ht == NULL)
1011                                 return -EINVAL;
1012                 }
1013         } else {
1014                 ht = rtnl_dereference(tp->root);
1015                 htid = ht->handle;
1016         }
1017
1018         if (ht->divisor < TC_U32_HASH(htid))
1019                 return -EINVAL;
1020
1021         if (handle) {
1022                 if (TC_U32_HTID(handle) && TC_U32_HTID(handle^htid))
1023                         return -EINVAL;
1024                 handle = htid | TC_U32_NODE(handle);
1025         } else
1026                 handle = gen_new_kid(ht, htid);
1027
1028         if (tb[TCA_U32_SEL] == NULL)
1029                 return -EINVAL;
1030
1031         s = nla_data(tb[TCA_U32_SEL]);
1032         sel_size = sizeof(*s) + sizeof(*s->keys) * s->nkeys;
1033         if (nla_len(tb[TCA_U32_SEL]) < sel_size)
1034                 return -EINVAL;
1035
1036         n = kzalloc(offsetof(typeof(*n), sel) + sel_size, GFP_KERNEL);
1037         if (n == NULL)
1038                 return -ENOBUFS;
1039
1040 #ifdef CONFIG_CLS_U32_PERF
1041         size = sizeof(struct tc_u32_pcnt) + s->nkeys * sizeof(u64);
1042         n->pf = __alloc_percpu(size, __alignof__(struct tc_u32_pcnt));
1043         if (!n->pf) {
1044                 kfree(n);
1045                 return -ENOBUFS;
1046         }
1047 #endif
1048
1049         memcpy(&n->sel, s, sel_size);
1050         RCU_INIT_POINTER(n->ht_up, ht);
1051         n->handle = handle;
1052         n->fshift = s->hmask ? ffs(ntohl(s->hmask)) - 1 : 0;
1053         n->flags = flags;
1054         n->tp = tp;
1055
1056         err = tcf_exts_init(&n->exts, TCA_U32_ACT, TCA_U32_POLICE);
1057         if (err < 0)
1058                 goto errout;
1059
1060 #ifdef CONFIG_CLS_U32_MARK
1061         n->pcpu_success = alloc_percpu(u32);
1062         if (!n->pcpu_success) {
1063                 err = -ENOMEM;
1064                 goto errout;
1065         }
1066
1067         if (tb[TCA_U32_MARK]) {
1068                 struct tc_u32_mark *mark;
1069
1070                 mark = nla_data(tb[TCA_U32_MARK]);
1071                 n->val = mark->val;
1072                 n->mask = mark->mask;
1073         }
1074 #endif
1075
1076         err = u32_set_parms(net, tp, base, ht, n, tb, tca[TCA_RATE], ovr);
1077         if (err == 0) {
1078                 struct tc_u_knode __rcu **ins;
1079                 struct tc_u_knode *pins;
1080
1081                 err = u32_replace_hw_knode(tp, n, flags);
1082                 if (err)
1083                         goto errhw;
1084
1085                 if (!tc_in_hw(n->flags))
1086                         n->flags |= TCA_CLS_FLAGS_NOT_IN_HW;
1087
1088                 ins = &ht->ht[TC_U32_HASH(handle)];
1089                 for (pins = rtnl_dereference(*ins); pins;
1090                      ins = &pins->next, pins = rtnl_dereference(*ins))
1091                         if (TC_U32_NODE(handle) < TC_U32_NODE(pins->handle))
1092                                 break;
1093
1094                 RCU_INIT_POINTER(n->next, pins);
1095                 rcu_assign_pointer(*ins, n);
1096                 *arg = n;
1097                 return 0;
1098         }
1099
1100 errhw:
1101 #ifdef CONFIG_CLS_U32_MARK
1102         free_percpu(n->pcpu_success);
1103 #endif
1104
1105 errout:
1106         tcf_exts_destroy(&n->exts);
1107 #ifdef CONFIG_CLS_U32_PERF
1108         free_percpu(n->pf);
1109 #endif
1110         kfree(n);
1111         return err;
1112 }
1113
1114 static void u32_walk(struct tcf_proto *tp, struct tcf_walker *arg)
1115 {
1116         struct tc_u_common *tp_c = tp->data;
1117         struct tc_u_hnode *ht;
1118         struct tc_u_knode *n;
1119         unsigned int h;
1120
1121         if (arg->stop)
1122                 return;
1123
1124         for (ht = rtnl_dereference(tp_c->hlist);
1125              ht;
1126              ht = rtnl_dereference(ht->next)) {
1127                 if (ht->prio != tp->prio)
1128                         continue;
1129                 if (arg->count >= arg->skip) {
1130                         if (arg->fn(tp, ht, arg) < 0) {
1131                                 arg->stop = 1;
1132                                 return;
1133                         }
1134                 }
1135                 arg->count++;
1136                 for (h = 0; h <= ht->divisor; h++) {
1137                         for (n = rtnl_dereference(ht->ht[h]);
1138                              n;
1139                              n = rtnl_dereference(n->next)) {
1140                                 if (arg->count < arg->skip) {
1141                                         arg->count++;
1142                                         continue;
1143                                 }
1144                                 if (arg->fn(tp, n, arg) < 0) {
1145                                         arg->stop = 1;
1146                                         return;
1147                                 }
1148                                 arg->count++;
1149                         }
1150                 }
1151         }
1152 }
1153
1154 static void u32_bind_class(void *fh, u32 classid, unsigned long cl)
1155 {
1156         struct tc_u_knode *n = fh;
1157
1158         if (n && n->res.classid == classid)
1159                 n->res.class = cl;
1160 }
1161
1162 static int u32_dump(struct net *net, struct tcf_proto *tp, void *fh,
1163                     struct sk_buff *skb, struct tcmsg *t)
1164 {
1165         struct tc_u_knode *n = fh;
1166         struct tc_u_hnode *ht_up, *ht_down;
1167         struct nlattr *nest;
1168
1169         if (n == NULL)
1170                 return skb->len;
1171
1172         t->tcm_handle = n->handle;
1173
1174         nest = nla_nest_start(skb, TCA_OPTIONS);
1175         if (nest == NULL)
1176                 goto nla_put_failure;
1177
1178         if (TC_U32_KEY(n->handle) == 0) {
1179                 struct tc_u_hnode *ht = fh;
1180                 u32 divisor = ht->divisor + 1;
1181
1182                 if (nla_put_u32(skb, TCA_U32_DIVISOR, divisor))
1183                         goto nla_put_failure;
1184         } else {
1185 #ifdef CONFIG_CLS_U32_PERF
1186                 struct tc_u32_pcnt *gpf;
1187                 int cpu;
1188 #endif
1189
1190                 if (nla_put(skb, TCA_U32_SEL,
1191                             sizeof(n->sel) + n->sel.nkeys*sizeof(struct tc_u32_key),
1192                             &n->sel))
1193                         goto nla_put_failure;
1194
1195                 ht_up = rtnl_dereference(n->ht_up);
1196                 if (ht_up) {
1197                         u32 htid = n->handle & 0xFFFFF000;
1198                         if (nla_put_u32(skb, TCA_U32_HASH, htid))
1199                                 goto nla_put_failure;
1200                 }
1201                 if (n->res.classid &&
1202                     nla_put_u32(skb, TCA_U32_CLASSID, n->res.classid))
1203                         goto nla_put_failure;
1204
1205                 ht_down = rtnl_dereference(n->ht_down);
1206                 if (ht_down &&
1207                     nla_put_u32(skb, TCA_U32_LINK, ht_down->handle))
1208                         goto nla_put_failure;
1209
1210                 if (n->flags && nla_put_u32(skb, TCA_U32_FLAGS, n->flags))
1211                         goto nla_put_failure;
1212
1213 #ifdef CONFIG_CLS_U32_MARK
1214                 if ((n->val || n->mask)) {
1215                         struct tc_u32_mark mark = {.val = n->val,
1216                                                    .mask = n->mask,
1217                                                    .success = 0};
1218                         int cpum;
1219
1220                         for_each_possible_cpu(cpum) {
1221                                 __u32 cnt = *per_cpu_ptr(n->pcpu_success, cpum);
1222
1223                                 mark.success += cnt;
1224                         }
1225
1226                         if (nla_put(skb, TCA_U32_MARK, sizeof(mark), &mark))
1227                                 goto nla_put_failure;
1228                 }
1229 #endif
1230
1231                 if (tcf_exts_dump(skb, &n->exts) < 0)
1232                         goto nla_put_failure;
1233
1234 #ifdef CONFIG_NET_CLS_IND
1235                 if (n->ifindex) {
1236                         struct net_device *dev;
1237                         dev = __dev_get_by_index(net, n->ifindex);
1238                         if (dev && nla_put_string(skb, TCA_U32_INDEV, dev->name))
1239                                 goto nla_put_failure;
1240                 }
1241 #endif
1242 #ifdef CONFIG_CLS_U32_PERF
1243                 gpf = kzalloc(sizeof(struct tc_u32_pcnt) +
1244                               n->sel.nkeys * sizeof(u64),
1245                               GFP_KERNEL);
1246                 if (!gpf)
1247                         goto nla_put_failure;
1248
1249                 for_each_possible_cpu(cpu) {
1250                         int i;
1251                         struct tc_u32_pcnt *pf = per_cpu_ptr(n->pf, cpu);
1252
1253                         gpf->rcnt += pf->rcnt;
1254                         gpf->rhit += pf->rhit;
1255                         for (i = 0; i < n->sel.nkeys; i++)
1256                                 gpf->kcnts[i] += pf->kcnts[i];
1257                 }
1258
1259                 if (nla_put_64bit(skb, TCA_U32_PCNT,
1260                                   sizeof(struct tc_u32_pcnt) +
1261                                   n->sel.nkeys * sizeof(u64),
1262                                   gpf, TCA_U32_PAD)) {
1263                         kfree(gpf);
1264                         goto nla_put_failure;
1265                 }
1266                 kfree(gpf);
1267 #endif
1268         }
1269
1270         nla_nest_end(skb, nest);
1271
1272         if (TC_U32_KEY(n->handle))
1273                 if (tcf_exts_dump_stats(skb, &n->exts) < 0)
1274                         goto nla_put_failure;
1275         return skb->len;
1276
1277 nla_put_failure:
1278         nla_nest_cancel(skb, nest);
1279         return -1;
1280 }
1281
1282 static struct tcf_proto_ops cls_u32_ops __read_mostly = {
1283         .kind           =       "u32",
1284         .classify       =       u32_classify,
1285         .init           =       u32_init,
1286         .destroy        =       u32_destroy,
1287         .get            =       u32_get,
1288         .change         =       u32_change,
1289         .delete         =       u32_delete,
1290         .walk           =       u32_walk,
1291         .dump           =       u32_dump,
1292         .bind_class     =       u32_bind_class,
1293         .owner          =       THIS_MODULE,
1294 };
1295
1296 static int __init init_u32(void)
1297 {
1298         int i, ret;
1299
1300         pr_info("u32 classifier\n");
1301 #ifdef CONFIG_CLS_U32_PERF
1302         pr_info("    Performance counters on\n");
1303 #endif
1304 #ifdef CONFIG_NET_CLS_IND
1305         pr_info("    input device check on\n");
1306 #endif
1307 #ifdef CONFIG_NET_CLS_ACT
1308         pr_info("    Actions configured\n");
1309 #endif
1310         tc_u_common_hash = kvmalloc_array(U32_HASH_SIZE,
1311                                           sizeof(struct hlist_head),
1312                                           GFP_KERNEL);
1313         if (!tc_u_common_hash)
1314                 return -ENOMEM;
1315
1316         for (i = 0; i < U32_HASH_SIZE; i++)
1317                 INIT_HLIST_HEAD(&tc_u_common_hash[i]);
1318
1319         ret = register_tcf_proto_ops(&cls_u32_ops);
1320         if (ret)
1321                 kvfree(tc_u_common_hash);
1322         return ret;
1323 }
1324
1325 static void __exit exit_u32(void)
1326 {
1327         unregister_tcf_proto_ops(&cls_u32_ops);
1328         kvfree(tc_u_common_hash);
1329 }
1330
1331 module_init(init_u32)
1332 module_exit(exit_u32)
1333 MODULE_LICENSE("GPL");