From: Yang Hongyang <yanghy@cn.fujitsu.com>
To: Jason Wang <jasowang@redhat.com>, qemu-devel@nongnu.org
Cc: thuth@redhat.com, zhang.zhanghailiang@huawei.com,
lizhijian@cn.fujitsu.com, mrhines@linux.vnet.ibm.com,
stefanha@redhat.com
Subject: Re: [Qemu-devel] [PATCH v2 5/9] netfilter: hook packets before net queue send
Date: Fri, 31 Jul 2015 17:58:40 +0800 [thread overview]
Message-ID: <55BB46D0.6030903@cn.fujitsu.com> (raw)
In-Reply-To: <55BB3B3D.5000403@redhat.com>
On 07/31/2015 05:09 PM, Jason Wang wrote:
>
>
> On 07/31/2015 04:24 PM, Yang Hongyang wrote:
>>
>>
>> On 07/31/2015 02:06 PM, Jason Wang wrote:
>>>
>>>
>>> On 07/31/2015 12:13 PM, Yang Hongyang wrote:
>>>> Capture packets that will be sent.
>>>>
>>>> Signed-off-by: Yang Hongyang <yanghy@cn.fujitsu.com>
>>>> ---
>>>> include/net/filter.h | 8 +++++++
>>>> net/filter.c | 1 +
>>>> net/net.c | 67
>>>> +++++++++++++++++++++++++++++++++++++++++++++++++++-
>>>> 3 files changed, 75 insertions(+), 1 deletion(-)
>>>>
>>>> diff --git a/include/net/filter.h b/include/net/filter.h
>>>> index 1b6f896..93579c1 100644
>>>> --- a/include/net/filter.h
>>>> +++ b/include/net/filter.h
>>>> @@ -19,11 +19,19 @@ enum {
>>>> };
>>>>
>>>> typedef void (FilterCleanup) (NetFilterState *);
>>>> +/*
>>>> + * Return:
>>>> + * 0: finished handling the packet, we should continue
>>>> + * size: filter stolen this packet, we stop pass this packet further
>>>> + */
>>>> +typedef ssize_t (FilterReceiveIOV)(NetFilterState *, NetClientState
>>>> *sender,
>>>> + unsigned flags, const struct
>>>> iovec *, int);
>>>>
>>>> typedef struct NetFilterInfo {
>>>> NetFilterOptionsKind type;
>>>> size_t size;
>>>> FilterCleanup *cleanup;
>>>> + FilterReceiveIOV *receive_iov;
>>>
>>> Please move this to patch 2.
>>
>> Ok, thanks!
>>
>>>
>>>> } NetFilterInfo;
>>>>
>>>> struct NetFilterState {
>>>> diff --git a/net/filter.c b/net/filter.c
>>>> index b3a2285..1ae9344 100644
>>>> --- a/net/filter.c
>>>> +++ b/net/filter.c
>>>> @@ -29,6 +29,7 @@ NetFilterState *qemu_new_net_filter(NetFilterInfo
>>>> *info,
>>>> NetFilterState *nf;
>>>>
>>>> assert(info->size >= sizeof(NetFilterState));
>>>> + assert(info->receive_iov);
>>>>
>>>> nf = g_malloc0(info->size);
>>>> nf->info = info;
>>>> diff --git a/net/net.c b/net/net.c
>>>> index 22748e0..b55d934 100644
>>>> --- a/net/net.c
>>>> +++ b/net/net.c
>>>> @@ -24,6 +24,7 @@
>>>> #include "config-host.h"
>>>>
>>>> #include "net/net.h"
>>>> +#include "net/filter.h"
>>>> #include "clients.h"
>>>> #include "hub.h"
>>>> #include "net/slirp.h"
>>>> @@ -592,6 +593,42 @@ int qemu_can_send_packet(NetClientState *sender)
>>>> return 1;
>>>> }
>>>>
>>>> +static ssize_t filter_receive_iov(NetClientState *nc, int chain,
>>>> + NetClientState *sender,
>>>> + unsigned flags,
>>>> + const struct iovec *iov,
>>>> + int iovcnt) {
>>>> + ssize_t ret = 0;
>>>> + Filter *filter = NULL;
>>>> + NetFilterState *nf = NULL;
>>>> + ssize_t size = iov_size(iov, iovcnt);
>>>> +
>>>> + QTAILQ_FOREACH(filter, &nc->filters, next) {
>>>> + nf = filter->nf;
>>>> + if (nf->chain == chain || nf->chain == NET_FILTER_ALL) {
>>>> + ret = nf->info->receive_iov(nf, sender, flags, iov,
>>>> iovcnt);
>>>> + if (ret == size) {
>>>> + return ret;
>>>> + }
>>>> + }
>>>> + }
>>>
>>> So if a packet is being stolen or blocked by one filter, it could only
>>> be flushed to destination? I think we need an API to flush it into next
>>> filter.
>>
>> Yes, we could, just call next filter's receive_iov, do I need to
>> introduce
>> the API now in this series? or introduce later when we actually need it?
>
> Consider it is a public API. better in this patch.
Ok, thanks, will add a patch to do this.
> .
>
--
Thanks,
Yang.
next prev parent reply other threads:[~2015-07-31 9:58 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-07-31 4:13 [Qemu-devel] [PATCH v2 0/9] For QEMU 2.5: Add a netfilter object and netbuffer filter Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 1/9] net: add a new object netfilter Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 2/9] init/cleanup of netfilter object Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 3/9] netfilter: add netfilter_{add|del} commands Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 4/9] net: add/remove filters from network backend Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 5/9] netfilter: hook packets before net queue send Yang Hongyang
2015-07-31 6:06 ` Jason Wang
2015-07-31 8:24 ` Yang Hongyang
2015-07-31 9:09 ` Jason Wang
2015-07-31 9:58 ` Yang Hongyang [this message]
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 6/9] net/queue: export qemu_net_queue_append_iov Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 7/9] move out net queue structs define Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 8/9] netfilter: add a netbuffer filter Yang Hongyang
2015-07-31 6:08 ` Jason Wang
2015-07-31 8:30 ` Yang Hongyang
2015-07-31 9:15 ` Jason Wang
2015-07-31 18:58 ` Dr. David Alan Gilbert
2015-08-03 1:10 ` Yang Hongyang
2015-07-31 4:13 ` [Qemu-devel] [PATCH v2 9/9] filter/buffer: update command description and help Yang Hongyang
2015-07-31 5:58 ` [Qemu-devel] [PATCH v2 0/9] For QEMU 2.5: Add a netfilter object and netbuffer filter Jason Wang
2015-07-31 8:20 ` Yang Hongyang
2015-07-31 9:08 ` Jason Wang
2015-07-31 9:51 ` Yang Hongyang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=55BB46D0.6030903@cn.fujitsu.com \
--to=yanghy@cn.fujitsu.com \
--cc=jasowang@redhat.com \
--cc=lizhijian@cn.fujitsu.com \
--cc=mrhines@linux.vnet.ibm.com \
--cc=qemu-devel@nongnu.org \
--cc=stefanha@redhat.com \
--cc=thuth@redhat.com \
--cc=zhang.zhanghailiang@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.