From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 459F0CD3427 for ; Tue, 5 May 2026 14:50:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Cc:To:In-Reply-To:References :Message-Id:Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date: From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=Uvii/83DqY6EFwP86hgaXBxTGmowpdDjW+Vn1quaFeA=; b=y6a0+n84ZApz9zSIHiwccMdq+3 TJ9MhdNRaq8hemGF0mw7K1dDM7VE3t3weXEjJDskTXZZ2B3sCuV7dRaB8Ke3quonBEIykTt5NdfIT jQntqF7ICSybltft01kiPwcm0JnreQYH5HFcPWr04Bu+87Y/xT8rcfe40bRjwO6lTCm/9/ii/gk+M Cimi3FBRh+lY8mYsgOi9X5tbM0DQxdLqFfissocy6psOamKxGWaI1wfcNIG3fGx3GRgwG698HxnMb ujm7W/xumN8C33Who4q1NnylGeTnuDdDO3L8iXShURqlNDWSuZooRoAMWD1rrW396xLVYc+W6y10G GmXbiwIQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.98.2 #2 (Red Hat Linux)) id 1wKH66-0000000GZ9B-1Rdu; Tue, 05 May 2026 14:50:06 +0000 Received: from sea.source.kernel.org ([2600:3c0a:e001:78e:0:1991:8:25]) by bombadil.infradead.org with esmtps (Exim 4.98.2 #2 (Red Hat Linux)) id 1wKH63-0000000GZ6V-2pEJ; Tue, 05 May 2026 14:50:04 +0000 Received: from smtp.kernel.org (transwarp.subspace.kernel.org [100.75.92.58]) by sea.source.kernel.org (Postfix) with ESMTP id 9A91E40B7A; Tue, 5 May 2026 14:50:02 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0062FC2BCF4; Tue, 5 May 2026 14:50:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1777992602; bh=92G/hBpoy+tgBOS2x/I53r2sZ5pAyr7z2fg9vOcfHhA=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=E/H8COlVuRum6H/mSSSp2b5NDHs8p1dq3Kmw00eTRTxcDX03eARk/qKClNqhX0z6s NZZBflhEaKRd9eWxiQKAzO7eFngAppDeSNcJPUh3NIXMXGThZHBXlB/uLnea6bwAyG YMqrzDM8uV0lMHb1+eyVHdutii0ueC9SWFbCPS5AzxqoXtvT110NUPxfzrqA6PECr3 4FEeOae2TYBj4zSB0/pO9IS4q/TvrVe6MudyGMu7z7iQ0m2HH2OTxpXuKUAHq6rvQp mlGjDwtnqSIhBoNHfG1jnkd4x+HUNj79hBRMDSvoRQqBxvhhipf7WuWZBCtc5EL74j EbyOaAbsvul6w== From: Lorenzo Bianconi Date: Tue, 05 May 2026 16:49:24 +0200 Subject: [PATCH nf-next 2/4] net: netfilter: Add encap_proto to flow_offload_tunnel MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260505-b4-flowtable-sw-accel-ip6ip-v1-2-9ac39ccc9ea9@kernel.org> References: <20260505-b4-flowtable-sw-accel-ip6ip-v1-0-9ac39ccc9ea9@kernel.org> In-Reply-To: <20260505-b4-flowtable-sw-accel-ip6ip-v1-0-9ac39ccc9ea9@kernel.org> To: Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Felix Fietkau , Matthias Brugger , AngeloGioacchino Del Regno , Simon Horman , David Ahern , Ido Schimmel , Pablo Neira Ayuso , Florian Westphal , Phil Sutter , Shuah Khan Cc: linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org, netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kselftest@vger.kernel.org, Lorenzo Bianconi X-Mailer: b4 0.14.3 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260505_075003_763956_E5A95E5C X-CRM114-Status: GOOD ( 12.36 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org Add encap_proto (AF_INET or AF_INET6) to struct flow_offload_tunnel to allow its use as part of the hash table key during flowtable entry lookup. This is a preliminary change to support IPv4 over IPv6 tunneling via the flowtable infrastructure for software acceleration. Signed-off-by: Lorenzo Bianconi --- include/linux/netdevice.h | 1 + include/net/netfilter/nf_flow_table.h | 1 + net/ipv4/ipip.c | 1 + net/ipv6/ip6_tunnel.c | 1 + net/netfilter/nf_flow_table_ip.c | 2 ++ net/netfilter/nf_flow_table_path.c | 2 ++ 6 files changed, 8 insertions(+) diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h index 85bd9d46b5a0..02f593397fad 100644 --- a/include/linux/netdevice.h +++ b/include/linux/netdevice.h @@ -902,6 +902,7 @@ struct net_device_path { }; u8 l3_proto; + u8 encap_proto; } tun; struct { enum { diff --git a/include/net/netfilter/nf_flow_table.h b/include/net/netfilter/nf_flow_table.h index b09c11c048d5..96e8ecf0f530 100644 --- a/include/net/netfilter/nf_flow_table.h +++ b/include/net/netfilter/nf_flow_table.h @@ -118,6 +118,7 @@ struct flow_offload_tunnel { }; u8 l3_proto; + u8 encap_proto; }; struct flow_offload_tuple { diff --git a/net/ipv4/ipip.c b/net/ipv4/ipip.c index ff95b1b9908e..5425af051d5a 100644 --- a/net/ipv4/ipip.c +++ b/net/ipv4/ipip.c @@ -369,6 +369,7 @@ static int ipip_fill_forward_path(struct net_device_path_ctx *ctx, path->tun.src_v4.s_addr = tiph->saddr; path->tun.dst_v4.s_addr = tiph->daddr; path->tun.l3_proto = IPPROTO_IPIP; + path->tun.encap_proto = AF_INET; path->dev = ctx->dev; ctx->dev = rt->dst.dev; diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c index 3d64e672eeee..c99ed41bfc99 100644 --- a/net/ipv6/ip6_tunnel.c +++ b/net/ipv6/ip6_tunnel.c @@ -1851,6 +1851,7 @@ static int ip6_tnl_fill_forward_path(struct net_device_path_ctx *ctx, path->type = DEV_PATH_TUN; path->tun.src_v6 = t->parms.laddr; path->tun.dst_v6 = t->parms.raddr; + path->tun.encap_proto = AF_INET6; if (ctx->ether_type == cpu_to_be16(ETH_P_IP)) path->tun.l3_proto = IPPROTO_IPIP; else diff --git a/net/netfilter/nf_flow_table_ip.c b/net/netfilter/nf_flow_table_ip.c index fd56d663cb5b..9efd76b57847 100644 --- a/net/netfilter/nf_flow_table_ip.c +++ b/net/netfilter/nf_flow_table_ip.c @@ -198,6 +198,7 @@ static void nf_flow_tuple_encap(struct nf_flowtable_ctx *ctx, tuple->tun.dst_v4.s_addr = iph->daddr; tuple->tun.src_v4.s_addr = iph->saddr; tuple->tun.l3_proto = IPPROTO_IPIP; + tuple->tun.encap_proto = AF_INET; } break; case htons(ETH_P_IPV6): @@ -206,6 +207,7 @@ static void nf_flow_tuple_encap(struct nf_flowtable_ctx *ctx, tuple->tun.dst_v6 = ip6h->daddr; tuple->tun.src_v6 = ip6h->saddr; tuple->tun.l3_proto = IPPROTO_IPV6; + tuple->tun.encap_proto = AF_INET6; } break; default: diff --git a/net/netfilter/nf_flow_table_path.c b/net/netfilter/nf_flow_table_path.c index df4e180ed3c2..5a5774d9b6f5 100644 --- a/net/netfilter/nf_flow_table_path.c +++ b/net/netfilter/nf_flow_table_path.c @@ -127,6 +127,7 @@ static void nft_dev_path_info(const struct net_device_path_stack *stack, info->tun.src_v6 = path->tun.src_v6; info->tun.dst_v6 = path->tun.dst_v6; info->tun.l3_proto = path->tun.l3_proto; + info->tun.encap_proto = path->tun.encap_proto; info->num_tuns++; } else { if (info->num_encaps >= NF_FLOW_TABLE_ENCAP_MAX) { @@ -270,6 +271,7 @@ static void nft_dev_forward_path(const struct nft_pktinfo *pkt, route->tuple[!dir].in.tun.src_v6 = info.tun.dst_v6; route->tuple[!dir].in.tun.dst_v6 = info.tun.src_v6; route->tuple[!dir].in.tun.l3_proto = info.tun.l3_proto; + route->tuple[!dir].in.tun.encap_proto = info.tun.encap_proto; route->tuple[!dir].in.num_tuns = info.num_tuns; } -- 2.54.0