sch_dsmark: fix potential NULL deref in dsmark_init()
[linux-2.6-block.git] / net / sched / sch_dsmark.c
CommitLineData
09c434b8 1// SPDX-License-Identifier: GPL-2.0-only
1da177e4
LT
2/* net/sched/sch_dsmark.c - Differentiated Services field marker */
3
4/* Written 1998-2000 by Werner Almesberger, EPFL ICA */
5
6
1da177e4
LT
7#include <linux/module.h>
8#include <linux/init.h>
5a0e3ad6 9#include <linux/slab.h>
1da177e4
LT
10#include <linux/types.h>
11#include <linux/string.h>
12#include <linux/errno.h>
13#include <linux/skbuff.h>
1da177e4 14#include <linux/rtnetlink.h>
5b0ac72b 15#include <linux/bitops.h>
1da177e4 16#include <net/pkt_sched.h>
cf1facda 17#include <net/pkt_cls.h>
1da177e4
LT
18#include <net/dsfield.h>
19#include <net/inet_ecn.h>
20#include <asm/byteorder.h>
21
1da177e4
LT
22/*
23 * classid class marking
24 * ------- ----- -------
25 * n/a 0 n/a
26 * x:0 1 use entry [0]
27 * ... ... ...
28 * x:y y>0 y+1 use entry [y]
29 * ... ... ...
30 * x:indices-1 indices use entry [indices-1]
31 * ... ... ...
32 * x:y y+1 use entry [y & (indices-1)]
33 * ... ... ...
34 * 0xffff 0x10000 use entry [indices-1]
35 */
36
37
38#define NO_DEFAULT_INDEX (1 << 16)
39
47bbbb30
ED
40struct mask_value {
41 u8 mask;
42 u8 value;
43};
44
1da177e4
LT
45struct dsmark_qdisc_data {
46 struct Qdisc *q;
25d8c0d5 47 struct tcf_proto __rcu *filter_list;
6529eaba 48 struct tcf_block *block;
47bbbb30 49 struct mask_value *mv;
af0d1141 50 u16 indices;
47bbbb30 51 u8 set_tc_index;
af0d1141 52 u32 default_index; /* index range is 0...0xffff */
47bbbb30
ED
53#define DSMARK_EMBEDDED_SZ 16
54 struct mask_value embedded[DSMARK_EMBEDDED_SZ];
1da177e4
LT
55};
56
758cc43c
TG
57static inline int dsmark_valid_index(struct dsmark_qdisc_data *p, u16 index)
58{
17569fae 59 return index <= p->indices && index > 0;
758cc43c 60}
1da177e4
LT
61
62/* ------------------------- Class/flow operations ------------------------- */
63
af0d1141 64static int dsmark_graft(struct Qdisc *sch, unsigned long arg,
653d6fd6
AA
65 struct Qdisc *new, struct Qdisc **old,
66 struct netlink_ext_ack *extack)
1da177e4 67{
81da99ed 68 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1da177e4 69
c76f2a2c
YY
70 pr_debug("%s(sch %p,[qdisc %p],new %p,old %p)\n",
71 __func__, sch, p, new, old);
486b53e5
TG
72
73 if (new == NULL) {
3511c913 74 new = qdisc_create_dflt(sch->dev_queue, &pfifo_qdisc_ops,
a38a9882 75 sch->handle, NULL);
486b53e5
TG
76 if (new == NULL)
77 new = &noop_qdisc;
78 }
79
86a7996c 80 *old = qdisc_replace(sch, new, &p->q);
10297b99 81 return 0;
1da177e4
LT
82}
83
1da177e4
LT
84static struct Qdisc *dsmark_leaf(struct Qdisc *sch, unsigned long arg)
85{
81da99ed
SH
86 struct dsmark_qdisc_data *p = qdisc_priv(sch);
87 return p->q;
1da177e4
LT
88}
89
143976ce 90static unsigned long dsmark_find(struct Qdisc *sch, u32 classid)
1da177e4 91{
af0d1141 92 return TC_H_MIN(classid) + 1;
1da177e4
LT
93}
94
1da177e4 95static unsigned long dsmark_bind_filter(struct Qdisc *sch,
af0d1141 96 unsigned long parent, u32 classid)
1da177e4 97{
143976ce
WC
98 pr_debug("%s(sch %p,[qdisc %p],classid %x)\n",
99 __func__, sch, qdisc_priv(sch), classid);
100
101 return dsmark_find(sch, classid);
1da177e4
LT
102}
103
143976ce 104static void dsmark_unbind_filter(struct Qdisc *sch, unsigned long cl)
1da177e4
LT
105{
106}
107
27a3421e
PM
108static const struct nla_policy dsmark_policy[TCA_DSMARK_MAX + 1] = {
109 [TCA_DSMARK_INDICES] = { .type = NLA_U16 },
110 [TCA_DSMARK_DEFAULT_INDEX] = { .type = NLA_U16 },
111 [TCA_DSMARK_SET_TC_INDEX] = { .type = NLA_FLAG },
112 [TCA_DSMARK_MASK] = { .type = NLA_U8 },
113 [TCA_DSMARK_VALUE] = { .type = NLA_U8 },
114};
115
1da177e4 116static int dsmark_change(struct Qdisc *sch, u32 classid, u32 parent,
793d81d6
AA
117 struct nlattr **tca, unsigned long *arg,
118 struct netlink_ext_ack *extack)
1da177e4 119{
81da99ed 120 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1e90474c
PM
121 struct nlattr *opt = tca[TCA_OPTIONS];
122 struct nlattr *tb[TCA_DSMARK_MAX + 1];
758cc43c 123 int err = -EINVAL;
1da177e4 124
c76f2a2c
YY
125 pr_debug("%s(sch %p,[qdisc %p],classid %x,parent %x), arg 0x%lx\n",
126 __func__, sch, p, classid, parent, *arg);
758cc43c
TG
127
128 if (!dsmark_valid_index(p, *arg)) {
129 err = -ENOENT;
1e90474c 130 goto errout;
1da177e4 131 }
1da177e4 132
cee63723 133 if (!opt)
1e90474c 134 goto errout;
758cc43c 135
8cb08174
JB
136 err = nla_parse_nested_deprecated(tb, TCA_DSMARK_MAX, opt,
137 dsmark_policy, NULL);
cee63723 138 if (err < 0)
27a3421e 139 goto errout;
cee63723 140
27a3421e 141 if (tb[TCA_DSMARK_VALUE])
47bbbb30 142 p->mv[*arg - 1].value = nla_get_u8(tb[TCA_DSMARK_VALUE]);
10297b99 143
1e90474c 144 if (tb[TCA_DSMARK_MASK])
47bbbb30 145 p->mv[*arg - 1].mask = nla_get_u8(tb[TCA_DSMARK_MASK]);
758cc43c
TG
146
147 err = 0;
148
1e90474c 149errout:
758cc43c
TG
150 return err;
151}
1da177e4 152
af0d1141 153static int dsmark_delete(struct Qdisc *sch, unsigned long arg)
1da177e4 154{
81da99ed 155 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1da177e4 156
af0d1141 157 if (!dsmark_valid_index(p, arg))
1da177e4 158 return -EINVAL;
10297b99 159
47bbbb30
ED
160 p->mv[arg - 1].mask = 0xff;
161 p->mv[arg - 1].value = 0;
af0d1141 162
1da177e4
LT
163 return 0;
164}
165
9d127fbd 166static void dsmark_walk(struct Qdisc *sch, struct qdisc_walker *walker)
1da177e4 167{
81da99ed 168 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1da177e4
LT
169 int i;
170
c76f2a2c
YY
171 pr_debug("%s(sch %p,[qdisc %p],walker %p)\n",
172 __func__, sch, p, walker);
af0d1141 173
1da177e4
LT
174 if (walker->stop)
175 return;
af0d1141 176
1da177e4 177 for (i = 0; i < p->indices; i++) {
47bbbb30 178 if (p->mv[i].mask == 0xff && !p->mv[i].value)
0451eb07 179 goto ignore;
1da177e4 180 if (walker->count >= walker->skip) {
cc7ec456 181 if (walker->fn(sch, i + 1, walker) < 0) {
1da177e4
LT
182 walker->stop = 1;
183 break;
184 }
185 }
10297b99 186ignore:
0451eb07 187 walker->count++;
10297b99 188 }
1da177e4
LT
189}
190
cbaacc4e
AA
191static struct tcf_block *dsmark_tcf_block(struct Qdisc *sch, unsigned long cl,
192 struct netlink_ext_ack *extack)
1da177e4 193{
81da99ed 194 struct dsmark_qdisc_data *p = qdisc_priv(sch);
6529eaba
JP
195
196 return p->block;
1da177e4
LT
197}
198
1da177e4
LT
199/* --------------------------- Qdisc operations ---------------------------- */
200
520ac30f
ED
201static int dsmark_enqueue(struct sk_buff *skb, struct Qdisc *sch,
202 struct sk_buff **to_free)
1da177e4 203{
f6bab199 204 unsigned int len = qdisc_pkt_len(skb);
81da99ed 205 struct dsmark_qdisc_data *p = qdisc_priv(sch);
af0d1141
TG
206 int err;
207
c76f2a2c 208 pr_debug("%s(skb %p,sch %p,[qdisc %p])\n", __func__, skb, sch, p);
1da177e4 209
1da177e4 210 if (p->set_tc_index) {
aea92fb2
ED
211 int wlen = skb_network_offset(skb);
212
d8b9605d 213 switch (tc_skb_protocol(skb)) {
60678040 214 case htons(ETH_P_IP):
aea92fb2
ED
215 wlen += sizeof(struct iphdr);
216 if (!pskb_may_pull(skb, wlen) ||
217 skb_try_make_writable(skb, wlen))
9d127fbd 218 goto drop;
4c30719f 219
9d127fbd
SH
220 skb->tc_index = ipv4_get_dsfield(ip_hdr(skb))
221 & ~INET_ECN_MASK;
222 break;
4c30719f 223
60678040 224 case htons(ETH_P_IPV6):
aea92fb2
ED
225 wlen += sizeof(struct ipv6hdr);
226 if (!pskb_may_pull(skb, wlen) ||
227 skb_try_make_writable(skb, wlen))
9d127fbd 228 goto drop;
4c30719f 229
9d127fbd
SH
230 skb->tc_index = ipv6_get_dsfield(ipv6_hdr(skb))
231 & ~INET_ECN_MASK;
232 break;
233 default:
234 skb->tc_index = 0;
235 break;
3ff50b79 236 }
1da177e4 237 }
af0d1141
TG
238
239 if (TC_H_MAJ(skb->priority) == sch->handle)
1da177e4 240 skb->tc_index = TC_H_MIN(skb->priority);
af0d1141
TG
241 else {
242 struct tcf_result res;
25d8c0d5 243 struct tcf_proto *fl = rcu_dereference_bh(p->filter_list);
87d83093 244 int result = tcf_classify(skb, fl, &res, false);
af0d1141 245
81da99ed 246 pr_debug("result %d class 0x%04x\n", result, res.classid);
af0d1141 247
1da177e4 248 switch (result) {
f6853e2d
PM
249#ifdef CONFIG_NET_CLS_ACT
250 case TC_ACT_QUEUED:
251 case TC_ACT_STOLEN:
e25ea21f 252 case TC_ACT_TRAP:
520ac30f 253 __qdisc_drop(skb, to_free);
378a2f09 254 return NET_XMIT_SUCCESS | __NET_XMIT_STOLEN;
4c30719f 255
f6853e2d 256 case TC_ACT_SHOT:
4c30719f 257 goto drop;
1da177e4 258#endif
c3bc7cff 259 case TC_ACT_OK:
f6853e2d
PM
260 skb->tc_index = TC_H_MIN(res.classid);
261 break;
4c30719f 262
f6853e2d
PM
263 default:
264 if (p->default_index != NO_DEFAULT_INDEX)
265 skb->tc_index = p->default_index;
266 break;
3ff50b79 267 }
1da177e4 268 }
1da177e4 269
520ac30f 270 err = qdisc_enqueue(skb, p->q, to_free);
af0d1141 271 if (err != NET_XMIT_SUCCESS) {
378a2f09 272 if (net_xmit_drop_count(err))
25331d6c 273 qdisc_qstats_drop(sch);
af0d1141 274 return err;
1da177e4 275 }
af0d1141 276
f6bab199 277 sch->qstats.backlog += len;
1da177e4 278 sch->q.qlen++;
1da177e4 279
af0d1141 280 return NET_XMIT_SUCCESS;
4c30719f
SH
281
282drop:
520ac30f 283 qdisc_drop(skb, sch, to_free);
c27f339a 284 return NET_XMIT_SUCCESS | __NET_XMIT_BYPASS;
af0d1141 285}
1da177e4
LT
286
287static struct sk_buff *dsmark_dequeue(struct Qdisc *sch)
288{
81da99ed 289 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1da177e4 290 struct sk_buff *skb;
af0d1141
TG
291 u32 index;
292
c76f2a2c 293 pr_debug("%s(sch %p,[qdisc %p])\n", __func__, sch, p);
1da177e4 294
f8b33d8e 295 skb = qdisc_dequeue_peeked(p->q);
af0d1141 296 if (skb == NULL)
1da177e4 297 return NULL;
af0d1141 298
9190b3b3 299 qdisc_bstats_update(sch, skb);
bdf17661 300 qdisc_qstats_backlog_dec(sch, skb);
1da177e4 301 sch->q.qlen--;
af0d1141
TG
302
303 index = skb->tc_index & (p->indices - 1);
81da99ed 304 pr_debug("index %d->%d\n", skb->tc_index, index);
af0d1141 305
d8b9605d 306 switch (tc_skb_protocol(skb)) {
60678040 307 case htons(ETH_P_IP):
47bbbb30
ED
308 ipv4_change_dsfield(ip_hdr(skb), p->mv[index].mask,
309 p->mv[index].value);
1da177e4 310 break;
60678040 311 case htons(ETH_P_IPV6):
47bbbb30
ED
312 ipv6_change_dsfield(ipv6_hdr(skb), p->mv[index].mask,
313 p->mv[index].value);
1da177e4 314 break;
9d127fbd
SH
315 default:
316 /*
317 * Only complain if a change was actually attempted.
318 * This way, we can send non-IP traffic through dsmark
319 * and don't need yet another qdisc as a bypass.
320 */
47bbbb30 321 if (p->mv[index].mask != 0xff || p->mv[index].value)
c76f2a2c 322 pr_warn("%s: unsupported protocol %d\n",
d8b9605d 323 __func__, ntohs(tc_skb_protocol(skb)));
9d127fbd 324 break;
3ff50b79 325 }
af0d1141 326
1da177e4
LT
327 return skb;
328}
329
8e3af978
JP
330static struct sk_buff *dsmark_peek(struct Qdisc *sch)
331{
332 struct dsmark_qdisc_data *p = qdisc_priv(sch);
333
c76f2a2c 334 pr_debug("%s(sch %p,[qdisc %p])\n", __func__, sch, p);
8e3af978
JP
335
336 return p->q->ops->peek(p->q);
337}
338
e63d7dfd
AA
339static int dsmark_init(struct Qdisc *sch, struct nlattr *opt,
340 struct netlink_ext_ack *extack)
1da177e4 341{
81da99ed 342 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1e90474c 343 struct nlattr *tb[TCA_DSMARK_MAX + 1];
9d4f97f9 344 int err = -EINVAL;
758cc43c
TG
345 u32 default_index = NO_DEFAULT_INDEX;
346 u16 indices;
47bbbb30 347 int i;
758cc43c 348
c76f2a2c 349 pr_debug("%s(sch %p,[qdisc %p],opt %p)\n", __func__, sch, p, opt);
758cc43c 350
cee63723
PM
351 if (!opt)
352 goto errout;
353
8d1a77f9 354 err = tcf_block_get(&p->block, &p->filter_list, sch, extack);
6529eaba
JP
355 if (err)
356 return err;
357
8cb08174
JB
358 err = nla_parse_nested_deprecated(tb, TCA_DSMARK_MAX, opt,
359 dsmark_policy, NULL);
cee63723 360 if (err < 0)
758cc43c
TG
361 goto errout;
362
cee63723 363 err = -EINVAL;
474f0813
ED
364 if (!tb[TCA_DSMARK_INDICES])
365 goto errout;
1e90474c 366 indices = nla_get_u16(tb[TCA_DSMARK_INDICES]);
5b0ac72b
DM
367
368 if (hweight32(indices) != 1)
758cc43c
TG
369 goto errout;
370
27a3421e 371 if (tb[TCA_DSMARK_DEFAULT_INDEX])
1e90474c 372 default_index = nla_get_u16(tb[TCA_DSMARK_DEFAULT_INDEX]);
758cc43c 373
47bbbb30
ED
374 if (indices <= DSMARK_EMBEDDED_SZ)
375 p->mv = p->embedded;
376 else
377 p->mv = kmalloc_array(indices, sizeof(*p->mv), GFP_KERNEL);
378 if (!p->mv) {
758cc43c
TG
379 err = -ENOMEM;
380 goto errout;
1da177e4 381 }
47bbbb30
ED
382 for (i = 0; i < indices; i++) {
383 p->mv[i].mask = 0xff;
384 p->mv[i].value = 0;
385 }
758cc43c
TG
386 p->indices = indices;
387 p->default_index = default_index;
1e90474c 388 p->set_tc_index = nla_get_flag(tb[TCA_DSMARK_SET_TC_INDEX]);
758cc43c 389
a38a9882
AA
390 p->q = qdisc_create_dflt(sch->dev_queue, &pfifo_qdisc_ops, sch->handle,
391 NULL);
758cc43c 392 if (p->q == NULL)
1da177e4 393 p->q = &noop_qdisc;
49b49971
JK
394 else
395 qdisc_hash_add(p->q, true);
758cc43c 396
c76f2a2c 397 pr_debug("%s: qdisc %p\n", __func__, p->q);
758cc43c
TG
398
399 err = 0;
400errout:
758cc43c 401 return err;
1da177e4
LT
402}
403
1da177e4
LT
404static void dsmark_reset(struct Qdisc *sch)
405{
81da99ed 406 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1da177e4 407
c76f2a2c 408 pr_debug("%s(sch %p,[qdisc %p])\n", __func__, sch, p);
1da177e4 409 qdisc_reset(p->q);
bdf17661 410 sch->qstats.backlog = 0;
1da177e4
LT
411 sch->q.qlen = 0;
412}
413
1da177e4
LT
414static void dsmark_destroy(struct Qdisc *sch)
415{
81da99ed 416 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1da177e4 417
c76f2a2c 418 pr_debug("%s(sch %p,[qdisc %p])\n", __func__, sch, p);
af0d1141 419
6529eaba 420 tcf_block_put(p->block);
86bd446b 421 qdisc_put(p->q);
47bbbb30
ED
422 if (p->mv != p->embedded)
423 kfree(p->mv);
1da177e4
LT
424}
425
1da177e4 426static int dsmark_dump_class(struct Qdisc *sch, unsigned long cl,
02f23f09 427 struct sk_buff *skb, struct tcmsg *tcm)
1da177e4 428{
81da99ed 429 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1e90474c 430 struct nlattr *opts = NULL;
1da177e4 431
c76f2a2c 432 pr_debug("%s(sch %p,[qdisc %p],class %ld\n", __func__, sch, p, cl);
02f23f09
TG
433
434 if (!dsmark_valid_index(p, cl))
1da177e4 435 return -EINVAL;
02f23f09 436
cc7ec456 437 tcm->tcm_handle = TC_H_MAKE(TC_H_MAJ(sch->handle), cl - 1);
cdc7f8e3 438 tcm->tcm_info = p->q->handle;
02f23f09 439
ae0be8de 440 opts = nla_nest_start_noflag(skb, TCA_OPTIONS);
1e90474c
PM
441 if (opts == NULL)
442 goto nla_put_failure;
47bbbb30
ED
443 if (nla_put_u8(skb, TCA_DSMARK_MASK, p->mv[cl - 1].mask) ||
444 nla_put_u8(skb, TCA_DSMARK_VALUE, p->mv[cl - 1].value))
1b34ec43 445 goto nla_put_failure;
02f23f09 446
1e90474c 447 return nla_nest_end(skb, opts);
1da177e4 448
1e90474c 449nla_put_failure:
bc3ed28c
TG
450 nla_nest_cancel(skb, opts);
451 return -EMSGSIZE;
1da177e4
LT
452}
453
454static int dsmark_dump(struct Qdisc *sch, struct sk_buff *skb)
455{
81da99ed 456 struct dsmark_qdisc_data *p = qdisc_priv(sch);
1e90474c 457 struct nlattr *opts = NULL;
1da177e4 458
ae0be8de 459 opts = nla_nest_start_noflag(skb, TCA_OPTIONS);
1e90474c
PM
460 if (opts == NULL)
461 goto nla_put_failure;
1b34ec43
DM
462 if (nla_put_u16(skb, TCA_DSMARK_INDICES, p->indices))
463 goto nla_put_failure;
02f23f09 464
1b34ec43
DM
465 if (p->default_index != NO_DEFAULT_INDEX &&
466 nla_put_u16(skb, TCA_DSMARK_DEFAULT_INDEX, p->default_index))
467 goto nla_put_failure;
1da177e4 468
1b34ec43
DM
469 if (p->set_tc_index &&
470 nla_put_flag(skb, TCA_DSMARK_SET_TC_INDEX))
471 goto nla_put_failure;
02f23f09 472
1e90474c 473 return nla_nest_end(skb, opts);
1da177e4 474
1e90474c 475nla_put_failure:
bc3ed28c
TG
476 nla_nest_cancel(skb, opts);
477 return -EMSGSIZE;
1da177e4
LT
478}
479
20fea08b 480static const struct Qdisc_class_ops dsmark_class_ops = {
1da177e4
LT
481 .graft = dsmark_graft,
482 .leaf = dsmark_leaf,
143976ce 483 .find = dsmark_find,
1da177e4
LT
484 .change = dsmark_change,
485 .delete = dsmark_delete,
486 .walk = dsmark_walk,
6529eaba 487 .tcf_block = dsmark_tcf_block,
1da177e4 488 .bind_tcf = dsmark_bind_filter,
143976ce 489 .unbind_tcf = dsmark_unbind_filter,
1da177e4
LT
490 .dump = dsmark_dump_class,
491};
492
20fea08b 493static struct Qdisc_ops dsmark_qdisc_ops __read_mostly = {
1da177e4
LT
494 .next = NULL,
495 .cl_ops = &dsmark_class_ops,
496 .id = "dsmark",
497 .priv_size = sizeof(struct dsmark_qdisc_data),
498 .enqueue = dsmark_enqueue,
499 .dequeue = dsmark_dequeue,
8e3af978 500 .peek = dsmark_peek,
1da177e4
LT
501 .init = dsmark_init,
502 .reset = dsmark_reset,
503 .destroy = dsmark_destroy,
504 .change = NULL,
505 .dump = dsmark_dump,
506 .owner = THIS_MODULE,
507};
508
509static int __init dsmark_module_init(void)
510{
511 return register_qdisc(&dsmark_qdisc_ops);
512}
af0d1141 513
10297b99 514static void __exit dsmark_module_exit(void)
1da177e4
LT
515{
516 unregister_qdisc(&dsmark_qdisc_ops);
517}
af0d1141 518
1da177e4
LT
519module_init(dsmark_module_init)
520module_exit(dsmark_module_exit)
af0d1141 521
1da177e4 522MODULE_LICENSE("GPL");