Jakub Kicinski | a39e17b | 2017-11-27 12:10:23 -0800 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2017 Netronome Systems, Inc. |
| 3 | * |
| 4 | * This software is licensed under the GNU General License Version 2, |
| 5 | * June 1991 as shown in the file COPYING in the top-level directory of this |
| 6 | * source tree. |
| 7 | * |
| 8 | * THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" |
| 9 | * WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, |
| 10 | * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS |
| 11 | * FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE |
| 12 | * OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME |
| 13 | * THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. |
| 14 | */ |
| 15 | |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 16 | #include <linux/bpf.h> |
| 17 | #include <linux/bpf_verifier.h> |
| 18 | #include <linux/bug.h> |
| 19 | #include <linux/list.h> |
| 20 | #include <linux/netdevice.h> |
| 21 | #include <linux/printk.h> |
| 22 | #include <linux/rtnetlink.h> |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 23 | #include <linux/rwsem.h> |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 24 | |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 25 | /* Protects bpf_prog_offload_devs and offload members of all progs. |
| 26 | * RTNL lock cannot be taken when holding this lock. |
| 27 | */ |
| 28 | static DECLARE_RWSEM(bpf_devs_lock); |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 29 | static LIST_HEAD(bpf_prog_offload_devs); |
| 30 | |
| 31 | int bpf_prog_offload_init(struct bpf_prog *prog, union bpf_attr *attr) |
| 32 | { |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 33 | struct bpf_dev_offload *offload; |
| 34 | |
Jakub Kicinski | 649f11d | 2017-11-20 15:21:52 -0800 | [diff] [blame] | 35 | if (attr->prog_type != BPF_PROG_TYPE_SCHED_CLS && |
| 36 | attr->prog_type != BPF_PROG_TYPE_XDP) |
| 37 | return -EINVAL; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 38 | |
| 39 | if (attr->prog_flags) |
| 40 | return -EINVAL; |
| 41 | |
| 42 | offload = kzalloc(sizeof(*offload), GFP_USER); |
| 43 | if (!offload) |
| 44 | return -ENOMEM; |
| 45 | |
| 46 | offload->prog = prog; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 47 | |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 48 | offload->netdev = dev_get_by_index(current->nsproxy->net_ns, |
| 49 | attr->prog_ifindex); |
| 50 | if (!offload->netdev) |
| 51 | goto err_free; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 52 | |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 53 | down_write(&bpf_devs_lock); |
| 54 | if (offload->netdev->reg_state != NETREG_REGISTERED) |
| 55 | goto err_unlock; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 56 | prog->aux->offload = offload; |
| 57 | list_add_tail(&offload->offloads, &bpf_prog_offload_devs); |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 58 | dev_put(offload->netdev); |
| 59 | up_write(&bpf_devs_lock); |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 60 | |
| 61 | return 0; |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 62 | err_unlock: |
| 63 | up_write(&bpf_devs_lock); |
| 64 | dev_put(offload->netdev); |
| 65 | err_free: |
| 66 | kfree(offload); |
| 67 | return -EINVAL; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 68 | } |
| 69 | |
| 70 | static int __bpf_offload_ndo(struct bpf_prog *prog, enum bpf_netdev_command cmd, |
| 71 | struct netdev_bpf *data) |
| 72 | { |
Jakub Kicinski | ce3b9db | 2017-12-27 18:39:06 -0800 | [diff] [blame] | 73 | struct bpf_dev_offload *offload = prog->aux->offload; |
| 74 | struct net_device *netdev; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 75 | |
| 76 | ASSERT_RTNL(); |
| 77 | |
Jakub Kicinski | ce3b9db | 2017-12-27 18:39:06 -0800 | [diff] [blame] | 78 | if (!offload) |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 79 | return -ENODEV; |
Jakub Kicinski | ce3b9db | 2017-12-27 18:39:06 -0800 | [diff] [blame] | 80 | netdev = offload->netdev; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 81 | if (!netdev->netdev_ops->ndo_bpf) |
| 82 | return -EOPNOTSUPP; |
| 83 | |
| 84 | data->command = cmd; |
| 85 | |
| 86 | return netdev->netdev_ops->ndo_bpf(netdev, data); |
| 87 | } |
| 88 | |
| 89 | int bpf_prog_offload_verifier_prep(struct bpf_verifier_env *env) |
| 90 | { |
| 91 | struct netdev_bpf data = {}; |
| 92 | int err; |
| 93 | |
| 94 | data.verifier.prog = env->prog; |
| 95 | |
| 96 | rtnl_lock(); |
| 97 | err = __bpf_offload_ndo(env->prog, BPF_OFFLOAD_VERIFIER_PREP, &data); |
| 98 | if (err) |
| 99 | goto exit_unlock; |
| 100 | |
Jakub Kicinski | cae1927 | 2017-12-27 18:39:05 -0800 | [diff] [blame] | 101 | env->prog->aux->offload->dev_ops = data.verifier.ops; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 102 | env->prog->aux->offload->dev_state = true; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 103 | exit_unlock: |
| 104 | rtnl_unlock(); |
| 105 | return err; |
| 106 | } |
| 107 | |
Jakub Kicinski | cae1927 | 2017-12-27 18:39:05 -0800 | [diff] [blame] | 108 | int bpf_prog_offload_verify_insn(struct bpf_verifier_env *env, |
| 109 | int insn_idx, int prev_insn_idx) |
| 110 | { |
| 111 | struct bpf_dev_offload *offload; |
| 112 | int ret = -ENODEV; |
| 113 | |
| 114 | down_read(&bpf_devs_lock); |
| 115 | offload = env->prog->aux->offload; |
Jakub Kicinski | ce3b9db | 2017-12-27 18:39:06 -0800 | [diff] [blame] | 116 | if (offload) |
Jakub Kicinski | cae1927 | 2017-12-27 18:39:05 -0800 | [diff] [blame] | 117 | ret = offload->dev_ops->insn_hook(env, insn_idx, prev_insn_idx); |
| 118 | up_read(&bpf_devs_lock); |
| 119 | |
| 120 | return ret; |
| 121 | } |
| 122 | |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 123 | static void __bpf_prog_offload_destroy(struct bpf_prog *prog) |
| 124 | { |
| 125 | struct bpf_dev_offload *offload = prog->aux->offload; |
| 126 | struct netdev_bpf data = {}; |
| 127 | |
| 128 | data.offload.prog = prog; |
| 129 | |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 130 | if (offload->dev_state) |
| 131 | WARN_ON(__bpf_offload_ndo(prog, BPF_OFFLOAD_DESTROY, &data)); |
| 132 | |
Jakub Kicinski | ad8ad79 | 2017-12-27 18:39:07 -0800 | [diff] [blame^] | 133 | /* Make sure BPF_PROG_GET_NEXT_ID can't find this dead program */ |
| 134 | bpf_prog_free_id(prog, true); |
| 135 | |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 136 | list_del_init(&offload->offloads); |
Jakub Kicinski | ce3b9db | 2017-12-27 18:39:06 -0800 | [diff] [blame] | 137 | kfree(offload); |
| 138 | prog->aux->offload = NULL; |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 139 | } |
| 140 | |
| 141 | void bpf_prog_offload_destroy(struct bpf_prog *prog) |
| 142 | { |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 143 | rtnl_lock(); |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 144 | down_write(&bpf_devs_lock); |
Jakub Kicinski | ce3b9db | 2017-12-27 18:39:06 -0800 | [diff] [blame] | 145 | if (prog->aux->offload) |
| 146 | __bpf_prog_offload_destroy(prog); |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 147 | up_write(&bpf_devs_lock); |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 148 | rtnl_unlock(); |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 149 | } |
| 150 | |
| 151 | static int bpf_prog_offload_translate(struct bpf_prog *prog) |
| 152 | { |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 153 | struct netdev_bpf data = {}; |
| 154 | int ret; |
| 155 | |
| 156 | data.offload.prog = prog; |
| 157 | |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 158 | rtnl_lock(); |
| 159 | ret = __bpf_offload_ndo(prog, BPF_OFFLOAD_TRANSLATE, &data); |
| 160 | rtnl_unlock(); |
| 161 | |
| 162 | return ret; |
| 163 | } |
| 164 | |
| 165 | static unsigned int bpf_prog_warn_on_exec(const void *ctx, |
| 166 | const struct bpf_insn *insn) |
| 167 | { |
| 168 | WARN(1, "attempt to execute device eBPF program on the host!"); |
| 169 | return 0; |
| 170 | } |
| 171 | |
| 172 | int bpf_prog_offload_compile(struct bpf_prog *prog) |
| 173 | { |
| 174 | prog->bpf_func = bpf_prog_warn_on_exec; |
| 175 | |
| 176 | return bpf_prog_offload_translate(prog); |
| 177 | } |
| 178 | |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 179 | const struct bpf_prog_ops bpf_offload_prog_ops = { |
| 180 | }; |
| 181 | |
| 182 | static int bpf_offload_notification(struct notifier_block *notifier, |
| 183 | ulong event, void *ptr) |
| 184 | { |
| 185 | struct net_device *netdev = netdev_notifier_info_to_dev(ptr); |
| 186 | struct bpf_dev_offload *offload, *tmp; |
| 187 | |
| 188 | ASSERT_RTNL(); |
| 189 | |
| 190 | switch (event) { |
| 191 | case NETDEV_UNREGISTER: |
Jakub Kicinski | 62c71b4 | 2017-11-20 15:21:57 -0800 | [diff] [blame] | 192 | /* ignore namespace changes */ |
| 193 | if (netdev->reg_state != NETREG_UNREGISTERING) |
| 194 | break; |
| 195 | |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 196 | down_write(&bpf_devs_lock); |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 197 | list_for_each_entry_safe(offload, tmp, &bpf_prog_offload_devs, |
| 198 | offloads) { |
| 199 | if (offload->netdev == netdev) |
| 200 | __bpf_prog_offload_destroy(offload->prog); |
| 201 | } |
Jakub Kicinski | e0d3974 | 2017-12-27 18:39:03 -0800 | [diff] [blame] | 202 | up_write(&bpf_devs_lock); |
Jakub Kicinski | ab3f006 | 2017-11-03 13:56:17 -0700 | [diff] [blame] | 203 | break; |
| 204 | default: |
| 205 | break; |
| 206 | } |
| 207 | return NOTIFY_OK; |
| 208 | } |
| 209 | |
| 210 | static struct notifier_block bpf_offload_notifier = { |
| 211 | .notifier_call = bpf_offload_notification, |
| 212 | }; |
| 213 | |
| 214 | static int __init bpf_offload_init(void) |
| 215 | { |
| 216 | register_netdevice_notifier(&bpf_offload_notifier); |
| 217 | return 0; |
| 218 | } |
| 219 | |
| 220 | subsys_initcall(bpf_offload_init); |