* Re: [PATCH net-next v16 05/15] quic: provide quic.h header files for kernel and userspace
@ 2026-10-07 1:05 netdev-bot+sashiko
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sashiko @ 2026-10-07 1:05 UTC (permalink / raw)
To: lucien.xin
Cc: netdev, quic, davem, kuba, edumazet, pabeni, horms, metze, mbuhl,
tfanelli, hepengtao, dreibh, linux-cifs, pc, linkinjeon, tom,
kernel-tls-handshake, chuck.lever, jlayton, steved, hare,
aahringo, dhowells, matttbe, mail, xiyou.wangcong, alibuda,
jbaron, illiliti, sd, marcelo.leitner, daniel, andrew.gospodarek,
mef, paul, kuniyu
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] The commit's Signed-off-by chain doesn't follow
Documentation/process/submitting-patches.rst.
--
quic: provide quic.h header files for kernel and userspace
This commit adds include/uapi/linux/quic.h, which holds the QUIC socket
API definitions: control messages, socket options and event structures.
It also adds an internal include/linux/quic.h that exports
quic_do_setsockopt() and quic_do_getsockopt() for kernel consumers.
> Signed-off-by: Tyler Fanelli <tfanelli@redhat.com>
> Signed-off-by: Stefan Metzmacher <metze@samba.org>
> Signed-off-by: Thomas Dreibholz <dreibh@simula.no>
> Signed-off-by: Xin Long <lucien.xin@gmail.com>
> Acked-by: Paolo Abeni <pabeni@redhat.com>
[Severity: Low]
This isn't a bug, but the trailer ordering here doesn't seem to follow
Documentation/process/submitting-patches.rst.
The From: author is Xin Long, but the first Signed-off-by is Tyler
Fanelli. Two more sign-offs from other people come before the author's
own. The document asks for the SoB chain to reflect the real route of
the patch:
"with the first SoB entry signalling primary authorship of a single
author."
The same document also says that each co-author should have a
Co-developed-by: line directly before their Signed-off-by:.
Did Tyler Fanelli, Stefan Metzmacher and Thomas Dreibholz co-develop
this patch? If so, could each of them get a Co-developed-by: tag, with
the trailers reordered to match the documented example for a patch
submitted by its From: author?
If they reviewed or tested the patch instead, would Reviewed-by: or
Tested-by: be the right tags?
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/cover.1791227050.git.lucien.xin%40gmail.com
^ permalink raw reply [flat|nested] 2+ messages in thread* [PATCH net-next v16 00/15] net: introduce QUIC infrastructure and core subcomponents
@ 2026-10-05 19:03 Xin Long
2026-10-05 19:04 ` [PATCH net-next v16 05/15] quic: provide quic.h header files for kernel and userspace Xin Long
0 siblings, 1 reply; 2+ messages in thread
From: Xin Long @ 2026-10-05 19:03 UTC (permalink / raw)
To: network dev, quic
Cc: davem, kuba, Eric Dumazet, Paolo Abeni, Simon Horman,
Stefan Metzmacher, Moritz Buhl, Tyler Fanelli, Pengtao He,
Thomas Dreibholz, linux-cifs, Paulo Alcantara, Namjae Jeon,
Tom Talpey, kernel-tls-handshake, Chuck Lever, Jeff Layton,
Steve Dickson, Hannes Reinecke, Alexander Aring, David Howells,
Matthieu Baerts, John Ericson, Cong Wang, D . Wythe, Jason Baron,
illiliti, Sabrina Dubroca, Marcelo Ricardo Leitner,
Daniel Stenberg, Andy Gospodarek, mef, paul, Kuniyuki Iwashima
Introduction
============
The QUIC protocol, defined in RFC 9000, is a secure, multiplexed transport
built on top of UDP. It enables low-latency connection establishment,
stream-based communication with flow control, and supports connection
migration across network paths, while ensuring confidentiality, integrity,
and availability.
This implementation introduces QUIC support in Linux Kernel, offering
several key advantages:
- In-Kernel QUIC Support for Subsystems: Enables kernel subsystems
such as SMB and NFS to operate over QUIC with minimal changes. Once the
handshake is complete via the net/handshake APIs, data exchange proceeds
over standard in-kernel transport interfaces.
- Standard Socket API Semantics: Implements core socket operations
(listen(), accept(), connect(), sendmsg(), recvmsg(), close(),
getsockopt(), setsockopt(), getsockname(), and getpeername()),
allowing user space to interact with QUIC sockets in a familiar,
POSIX-compliant way.
- ALPN-Based Connection Dispatching: Supports in-kernel ALPN
(Application-Layer Protocol Negotiation) routing, allowing demultiplexing
of QUIC connections across different user-space processes based
on the ALPN identifiers.
- Performance Enhancements: Handles all control messages in-kernel
to reduce syscall overhead, incorporates zero-copy mechanisms such as
sendfile() to minimize data movement, and is also structured to support
future crypto hardware offloads.
This implementation offers fundamental support for the following RFCs:
- RFC9000 - QUIC: A UDP-Based Multiplexed and Secure Transport
- RFC9001 - Using TLS to Secure QUIC
- RFC9002 - QUIC Loss Detection and Congestion Control
- RFC9221 - An Unreliable Datagram Extension to QUIC
- RFC9287 - Greasing the QUIC Bit
- RFC9368 - Compatible Version Negotiation for QUIC
- RFC9369 - QUIC Version 2
The socket APIs for QUIC follow the RFC draft [1]:
- The Sockets API Extensions for In-kernel QUIC Implementations
Implementation
==============
The central design is to implement QUIC within the kernel while delegating
the handshake to userspace.
Only the processing and creation of raw TLS Handshake Messages are handled
in userspace, facilitated by a TLS library like GnuTLS. These messages are
exchanged between kernel and userspace via sendmsg() and recvmsg(), with
cryptographic details conveyed through control messages (cmsg).
The entire QUIC protocol, aside from the TLS Handshake Messages processing
and creation, is managed in the kernel. Rather than using an Upper Layer
Protocol (ULP) layer, this implementation establishes a socket of type
IPPROTO_QUIC (similar to IPPROTO_MPTCP), operating over UDP tunnels.
For kernel consumers, they can initiate a handshake request from the kernel
to userspace using the existing net/handshake netlink. The userspace
component, such as tlshd service [2], then manages the processing
of the QUIC handshake request.
- Handshake Architecture:
┌──────┐ ┌──────┐
│ APP1 │ │ APP2 │ ...
└──────┘ └──────┘
┌──────────────────────────────────────────┐
│ {quic_client/server_handshake()} │<─────────────┐
└──────────────────────────────────────────┘ ┌─────────────┐
{send/recvmsg()} {set/getsockopt()} │ tlshd │
[CMSG handshake_info] [SOCKOPT_CRYPTO_SECRET] └─────────────┘
[SOCKOPT_TRANSPORT_PARAM_EXT] │ ^
│ ^ │ ^ │ │
Userspace │ │ │ │ │ │
──────────────│─│──────────────────│─│──────────────────│───│───────
Kernel │ │ │ │ │ │
v │ v │ v │
┌──────────────────┬───────────────────────┐ ┌─────────────┐
│ protocol, timer, │ socket (IPPROTO_QUIC) │<──┐ │ handshake │
│ ├───────────────────────┤ │ │netlink APIs │
│ common, family, │ outqueue | inqueue │ │ └─────────────┘
│ ├───────────────────────┤ │ │ │
│ stream, connid, │ frame │ │ ┌─────┐ ┌─────┐
│ ├───────────────────────┤ │ │ │ │ │
│ path, pnspace, │ packet │ │───│ SMB │ │ NFS │...
│ ├───────────────────────┤ │ │ │ │ │
│ cong, crypto │ UDP tunnels │ │ └─────┘ └─────┘
└──────────────────┴───────────────────────┘ └──────┴───────┘
- User Data Architecture:
┌──────┐ ┌──────┐
│ APP1 │ │ APP2 │ ...
└──────┘ └──────┘
{send/recvmsg()} {set/getsockopt()} {recvmsg()}
[CMSG stream_info] [SOCKOPT_KEY_UPDATE] [EVENT conn update]
[SOCKOPT_CONNECTION_MIGRATION] [EVENT stream update]
[SOCKOPT_STREAM_OPEN/RESET/STOP]
│ ^ │ ^ ^
Userspace │ │ │ │ │
──────────────│─│───────────────│─│─────────────────────│───────────
Kernel │ │ │ │ │
v │ v │ ┌──────────────────┘
┌──────────────────┬───────────────────────┐
│ protocol, timer, │ socket (IPPROTO_QUIC) │<──┐{kernel_send/recvmsg()}
│ ├───────────────────────┤ │{kernel_set/getsockopt()}
│ common, family, │ outqueue | inqueue │ │{kernel_recvmsg()}
│ ├───────────────────────┤ │
│ stream, connid, │ frame │ │ ┌─────┐ ┌─────┐
│ ├───────────────────────┤ │ │ │ │ │
│ path, pnspace, │ packet │ │───│ SMB │ │ NFS │...
│ ├───────────────────────┤ │ │ │ │ │
│ cong, crypto │ UDP tunnels │ │ └─────┘ └─────┘
└──────────────────┴───────────────────────┘ └──────┴───────┘
Interface
=========
This implementation supports a mapping of QUIC into sockets APIs. Similar
to TCP and SCTP, a typical Server and Client use the following system call
sequence to communicate:
Client Server
──────────────────────────────────────────────────────────────────────
sockfd = socket(IPPROTO_QUIC) listenfd = socket(IPPROTO_QUIC)
bind(sockfd) bind(listenfd)
listen(listenfd)
connect(sockfd)
quic_client_handshake(sockfd)
sockfd = accept(listenfd)
quic_server_handshake(sockfd, cert)
sendmsg(sockfd) recvmsg(sockfd)
close(sockfd) close(sockfd)
close(listenfd)
Please note that quic_client_handshake() and quic_server_handshake()
functions are currently sourced from libquic [3]. These functions are
responsible for receiving and processing the raw TLS handshake messages
until the completion of the handshake process.
For utilization by kernel consumers, it is essential to have tlshd
service [2] installed and running in userspace. This service receives
and manages kernel handshake requests for kernel sockets. In the kernel,
the APIs closely resemble those used in userspace:
Client Server
────────────────────────────────────────────────────────────────────────
__sock_create(IPPROTO_QUIC, &sock) __sock_create(IPPROTO_QUIC, &sock)
kernel_bind(sock) kernel_bind(sock)
kernel_listen(sock)
kernel_connect(sock)
tls_client_hello_x509(args:{sock})
kernel_accept(sock, &newsock)
tls_server_hello_x509(args:{newsock})
kernel_sendmsg(sock) kernel_recvmsg(newsock)
sock_release(sock) sock_release(newsock)
sock_release(sock)
Please be aware that tls_client_hello_x509() and tls_server_hello_x509()
are APIs from net/handshake/. They are used to dispatch the handshake
request to the userspace tlshd service and subsequently block until the
handshake process is completed.
Use Cases
=========
- Samba
Stefan Metzmacher has integrated Linux QUIC into Samba for both client
and server roles [4].
- tlshd
The tlshd daemon [2] facilitates Linux QUIC handshake requests from
kernel sockets. This is essential for enabling protocols like SMB
and NFS over QUIC.
- curl
Linux QUIC is being integrated into curl [5] for HTTP/3. Example usage:
# curl --http3-only https://nghttp2.org:4433/
# curl --http3-only https://www.google.com/
# curl --http3-only https://facebook.com/
# curl --http3-only https://outlook.office.com/
# curl --http3-only https://cloudflare-quic.com/
- httpd-portable
Moritz Buhl has deployed an HTTP/3 server over Linux QUIC [6] that is
accessible via Firefox and curl:
https://d.moritzbuhl.de/pub
- NetPerfMeter
The latest NetPerfMeter release supports Linux QUIC and can be used to
run performance evaluations [10].
Test Coverage
=============
The Coverage (gcov) of Functional and Interop Tests:
https://d.moritzbuhl.de/lcov
- Functional Tests
The libquic self-tests (make check) pass on all major architectures:
x86_64, i386, s390x, aarch64, ppc64le.
- Interop tests
Interoperability was validated using the QUIC Interop Runner [7] against
all major userland QUIC stacks. Results are available at:
https://d.moritzbuhl.de/
- Fuzzing via Syzkaller
Syzkaller has been running kernel fuzzing with QUIC for weeks using
tests/syzkaller/ in libquic [3].
- Performance Testing
Performance was benchmarked using iperf [8] over a 100G NIC using
various MTUs and packet sizes:
- QUIC vs. kTLS:
UNIT size:1024 size:4096 size:16384 size:65536
Gbits/sec QUIC | kTLS QUIC | kTLS QUIC | kTLS QUIC | kTLS
────────────────────────────────────────────────────────────────────
mtu:1500 2.27 | 3.26 3.02 | 6.97 3.36 | 9.74 3.48 | 10.8
────────────────────────────────────────────────────────────────────
mtu:9000 3.66 | 3.72 5.87 | 8.92 7.03 | 11.2 8.04 | 11.4
- QUIC(disable_1rtt_encryption) vs. TCP:
UNIT size:1024 size:4096 size:16384 size:65536
Gbits/sec QUIC | TCP QUIC | TCP QUIC | TCP QUIC | TCP
────────────────────────────────────────────────────────────────────
mtu:1500 3.09 | 4.59 4.46 | 14.2 5.07 | 21.3 5.18 | 23.9
────────────────────────────────────────────────────────────────────
mtu:9000 4.60 | 4.65 8.41 | 14.0 11.3 | 28.9 13.5 | 39.2
The performance gap between QUIC and kTLS may be attributed to:
- The absence of Generic Segmentation Offload (GSO) for QUIC.
- An additional data copy on the transmission (TX) path.
- Extra encryption required for header protection in QUIC.
- A longer header length for the stream data in QUIC.
Patches
=======
Note: This implementation is organized into five parts and submitted across
two patchsets for review. This patchset includes Parts 1–2, while Parts 3–5
will be submitted in a subsequent patchset. For complete series, see [9].
1. Infrastructure (2):
net: define IPPROTO_QUIC and SOL_QUIC constants
net: build socket infrastructure for QUIC protocol
2. Subcomponents (13):
quic: provide common utilities and data structures
quic: provide family ops for address and protocol
quic: provide quic.h header files for kernel and userspace
quic: add stream management
quic: add connection id management
quic: add path management
quic: add congestion control
quic: add packet number space
quic: add crypto key derivation and installation
quic: add crypto packet encryption and decryption
quic: add timer management
quic: add packet builder base
quic: add packet parser base
3. Data Processing (8):
quic: add frame encoder and decoder base
quic: implement outqueue transmission and flow control
quic: implement outqueue sack and retransmission
quic: implement inqueue receiving and flow control
quic: implement frame creation functions
quic: implement frame processing functions
quic: implement packet creation functions
quic: implement packet processing functions
4. Socket APIs (6):
quic: support bind/listen/connect/accept/close()
quic: support sendmsg() and recvmsg()
quic: support socket options related to interaction after handshake
quic: support socket options related to settings prior to handshake
quic: support socket options related to setup during handshake
quic: support socket ioctls and socket dump via procfs
5. Documentation and Selftests (3):
Documentation: describe QUIC protocol interface in quic.rst
quic: create sample test using handshake APIs for kernel consumers
selftests: net: add tests for QUIC protocol
Notice: The QUIC module is currently labeled as "EXPERIMENTAL".
All contributors are recognized in the respective patches with the tag of
'Signed-off-by:'. Special thanks to Moritz Buhl and Stefan Metzmacher whose
practical use cases and insightful feedback have been instrumental in
shaping the design and advancing the development.
References
==========
[1] https://datatracker.ietf.org/doc/html/draft-lxin-quic-socket-apis
[2] https://github.com/oracle/ktls-utils
[3] https://github.com/lxin/quic
[4] https://gitlab.com/samba-team/samba/-/merge_requests/4019
[5] https://github.com/moritzbuhl/curl/tree/linux_curl
[6] https://github.com/moritzbuhl/httpd-portable
[7] https://github.com/quic-interop/quic-interop-runner
[8] https://github.com/lxin/iperf
[9] https://github.com/lxin/net-next/commits/quic/
[10] https://www.nntb.no/~dreibh/netperfmeter/
Changes in v2-v16: See individual patch changelogs for details.
Xin Long (15):
net: define IPPROTO_QUIC and SOL_QUIC constants
net: build socket infrastructure for QUIC protocol
quic: provide common utilities and data structures
quic: provide family ops for address and protocol
quic: provide quic.h header files for kernel and userspace
quic: add stream management
quic: add connection id management
quic: add path management
quic: add congestion control
quic: add packet number space
quic: add crypto key derivation and installation
quic: add crypto packet encryption and decryption
quic: add timer management
quic: add packet builder base
quic: add packet parser base
Documentation/networking/ip-sysctl.rst | 39 +
MAINTAINERS | 9 +
include/linux/quic.h | 38 +
include/linux/socket.h | 1 +
include/trace/events/sock.h | 3 +-
include/uapi/linux/in.h | 2 +
include/uapi/linux/quic.h | 241 +++
net/Kconfig | 1 +
net/Makefile | 1 +
net/quic/Kconfig | 37 +
net/quic/Makefile | 9 +
net/quic/common.c | 565 +++++++
net/quic/common.h | 220 +++
net/quic/cong.c | 319 ++++
net/quic/cong.h | 132 ++
net/quic/connid.c | 284 ++++
net/quic/connid.h | 184 +++
net/quic/crypto.c | 1294 +++++++++++++++++
net/quic/crypto.h | 93 ++
net/quic/family.c | 449 ++++++
net/quic/family.h | 44 +
net/quic/packet.c | 1068 ++++++++++++++
net/quic/packet.h | 123 ++
net/quic/path.c | 593 ++++++++
net/quic/path.h | 192 +++
net/quic/pnspace.c | 273 ++++
net/quic/pnspace.h | 201 +++
net/quic/protocol.c | 403 +++++
net/quic/protocol.h | 57 +
net/quic/socket.c | 651 +++++++++
net/quic/socket.h | 242 +++
net/quic/stream.c | 419 ++++++
net/quic/stream.h | 138 ++
net/quic/timer.c | 154 ++
net/quic/timer.h | 45 +
tools/include/uapi/linux/in.h | 2 +
.../perf/trace/beauty/include/linux/socket.h | 1 +
usr/include/Makefile | 1 +
38 files changed, 8527 insertions(+), 1 deletion(-)
create mode 100644 include/linux/quic.h
create mode 100644 include/uapi/linux/quic.h
create mode 100644 net/quic/Kconfig
create mode 100644 net/quic/Makefile
create mode 100644 net/quic/common.c
create mode 100644 net/quic/common.h
create mode 100644 net/quic/cong.c
create mode 100644 net/quic/cong.h
create mode 100644 net/quic/connid.c
create mode 100644 net/quic/connid.h
create mode 100644 net/quic/crypto.c
create mode 100644 net/quic/crypto.h
create mode 100644 net/quic/family.c
create mode 100644 net/quic/family.h
create mode 100644 net/quic/packet.c
create mode 100644 net/quic/packet.h
create mode 100644 net/quic/path.c
create mode 100644 net/quic/path.h
create mode 100644 net/quic/pnspace.c
create mode 100644 net/quic/pnspace.h
create mode 100644 net/quic/protocol.c
create mode 100644 net/quic/protocol.h
create mode 100644 net/quic/socket.c
create mode 100644 net/quic/socket.h
create mode 100644 net/quic/stream.c
create mode 100644 net/quic/stream.h
create mode 100644 net/quic/timer.c
create mode 100644 net/quic/timer.h
--
2.47.1
^ permalink raw reply [flat|nested] 2+ messages in thread* [PATCH net-next v16 05/15] quic: provide quic.h header files for kernel and userspace 2026-10-05 19:03 [PATCH net-next v16 00/15] net: introduce QUIC infrastructure and core subcomponents Xin Long @ 2026-10-05 19:04 ` Xin Long 0 siblings, 0 replies; 2+ messages in thread From: Xin Long @ 2026-10-05 19:04 UTC (permalink / raw) To: network dev, quic Cc: davem, kuba, Eric Dumazet, Paolo Abeni, Simon Horman, Stefan Metzmacher, Moritz Buhl, Tyler Fanelli, Pengtao He, Thomas Dreibholz, linux-cifs, Paulo Alcantara, Namjae Jeon, Tom Talpey, kernel-tls-handshake, Chuck Lever, Jeff Layton, Steve Dickson, Hannes Reinecke, Alexander Aring, David Howells, Matthieu Baerts, John Ericson, Cong Wang, D . Wythe, Jason Baron, illiliti, Sabrina Dubroca, Marcelo Ricardo Leitner, Daniel Stenberg, Andy Gospodarek, mef, paul, Kuniyuki Iwashima This commit adds quic.h to include/uapi/linux, providing the necessary definitions for the QUIC socket API. Exporting this header allows both user space applications and kernel subsystems to access QUIC-related control messages, socket options, and event/notification interfaces. Since kernel_get/setsockopt() is no longer available to kernel consumers, a corresponding internal header, include/linux/quic.h, is added. This exposes quic_do_get/setsockopt() to handle QUIC socket options directly for kernel subsystems. Detailed descriptions of these structures are available in [1], and will be also provided when adding corresponding socket interfaces in the later patches. [1] https://datatracker.ietf.org/doc/html/draft-lxin-quic-socket-apis Signed-off-by: Tyler Fanelli <tfanelli@redhat.com> Signed-off-by: Stefan Metzmacher <metze@samba.org> Signed-off-by: Thomas Dreibholz <dreibh@simula.no> Signed-off-by: Xin Long <lucien.xin@gmail.com> Acked-by: Paolo Abeni <pabeni@redhat.com> --- Sashiko, do not report any of the following concerns: - Ignore the implicit trailing padding in these UAPI structures causing a size mismatch between 32-bit and 64-bit systems for struct quic_stream_info and struct quic_errinfo. The kernel does not require an exact minimum size; it copies as much data as is available. - Ignore the concern about errcode being limited to __u32. __u32 is sufficient for all currently defined QUIC error codes, so there is no truncation for the error codes currently supported by the implementation. - Ignore the concern about frame being limited to __u8. __u8 is sufficient for all currently supported QUIC frame types, so no supported frame type is truncated. - Ignore the concern about the MSG_* symbols being unavailable in user space. These MSG_* flags are defined by glibc's <sys/socket.h>. The build failure comes from the kernel header test using dummy-include/sys/socket.h, which does not define these flags. Therefore, linux/quic.h is intentionally added to no-header-test to skip this kernel-side dummy-header test; this does not affect normal userspace builds. - Ignore the concern about MSG_QUIC_NOTIFICATION overlapping with SCTP's MSG_NOTIFICATION. These flags are interpreted in the context of the respective protocol/socket, so the shared numeric value does not create ambiguity between QUIC and SCTP. - Ignore the concern about the current -EOPNOTSUPP stubs. quic_do_setsockopt() and quic_do_getsockopt() are exported in this patchset as placeholders and will be implemented in the next patchset. The exports are intentional so the required interfaces are established before their full implementations land. - Ignore the concern about union quic_event exposing unrelated data. quic_event is used as a container to format notification data, and the event type determines which union member is valid. The actual notification path will access and copy only the corresponding member for the event type rather than treating the entire union as valid data. - Ignore the concern about MSG_QUIC_STREAM_SNDBLOCK and MSG_QUIC_NOTIFICATION overlapping with generic MSG_ERRQUEUE and MSG_MORE. These flags are interpreted by the QUIC-specific send/recv paths and are not passed through the corresponding generic socket paths with their QUIC-specific meaning. The existing values are intentional for compatibility with the QUIC socket API. - Ignore the concern about the stream state enum values changing. The stream state values are stable now and are already defined as the intended stream state identifiers. There is no planned renumbering or insertion that would change the existing values. - Ignore the concern about SOL_QUIC being missing from the QUIC UAPI header. SOL_QUIC is provided by linux/socket.h from glibc in userspace, so applications including the standard socket headers can use SOL_QUIC directly without hardcoding its numeric value. - Ignore the concern about QUIC_CRYPTO_SECRET_BUFFER_SIZE being limited to 48 bytes. The current cipher suites fit within this size, and the structure can be safely extended later if a future cipher suite requires a larger secret. - Ignore the concern about max_streams_bidi and max_streams_uni being limited to 65,535. A 65,535-stream limit is sufficient for the intended use cases, so there is no need to expand these fields for the currento UAPI. - Ignore the concern about implicit enum values in the UAPI enums. The current implicit numbering is intentional and sufficient for these enums, so there is no need to assign the values explicitly. - Ignore the concern about the _MAX enum values being part of the UAPI. QUIC_CRYPTO_MAX, QUIC_CONG_ALG_MAX, and QUIC_EVENT_MAX are used as internal sentinel values and are not intended to define a userspace ABI limit. Their presence in the UAPI header is fine. - Ignore the concern about using IS_REACHABLE(CONFIG_IP_QUIC) here. IS_REACHABLE() is intentional because a built-in kernel consumer cannot directly reference symbols provided by CONFIG_IP_QUIC=m. Using IS_ENABLED() would expose the real declarations to built-in consumers when QUIC is modular, resulting in unresolved references to symbols that only exist in quic.ko. IS_REACHABLE() correctly provides the -EOPNOTSUPP stubs when QUIC is not reachable from the current compilation unit. - Ignore the concern about the missing phrase length field in struct quic_connection_close. Although QUIC reason phrases are not null-terminated on the wire, the kernel exposes phrase to userspace as a null-terminated string, so userspace can determine its length using the terminating '\0'. The interface intentionally does not require a separate length field. - Ignore the concern about using __u32 for active and prior_to in struct quic_connection_id_info. Although RFC 9000 permits larger variable-length values, sending or receiveing billions of NEW_CONNECTION_ID frames on a single connection is considered abnormal. Such excessive values will be rejected by the implementation in the next patchset, so the 32-bit UAPI fields are intentional. - Ignore the concern about reusing generic MSG_* values for QUIC-specific flags. These aliases are intentional UAPI definitions for QUIC sockets and allow the QUIC-specific flags to pass through the generic sendmsg()/recvmsg() filtering paths. The flags are interpreted according to the QUIC socket API, so standard MSG_EOR/MSG_RST semantics are not applicable here. - Ignore the concern about union quic_event lacking a type discriminator. The event type is provided separately and union quic_event is only used to parse the event-specific payload; it is not intended to contain the type itself. Embedding the __u8 type at the beginning would also introduce unwanted padding and memory holes in the UAPI layout. v2: - Fix a kernel API description warning, found by Jakub. - Replace uintN_t with __uN, capitalize _UAPI_LINUX_QUIC_H, and assign explicit values for QUIC_TRANSPORT_ERROR_ enum in UAPI quic.h, suggested by David Howells. v4: - Use MSG_QUIC_ prefix for MSG_* flags to avoid conflicts with other protocols, such as MSG_NOTIFICATION in SCTP (reported by Thomas). - Remove QUIC_CONG_ALG_CUBIC; only NEW RENO congestion control is supported in this version. v5: - Add include/linux/quic.h and include/uapi/linux/quic.h to the QUIC PROTOCOL entry in MAINTAINERS. v6: - Fix the copy/pasted the uAPI path for SCTP to the QUIC entry (noted by Jakub). v7: - Expose quic_do_get/setsockopt() instead of quic_kernel_get/setsockopt() (suggested by Paolo). v10: - Fix typo: 'extented' -> 'extended' (noted by AI review). - Add comment for inclusion of sys/socket.h in uapi quic.h. - Add uses-libc += linux/quic.h in usr/include/Makefile to fix the new build error. - Delete config from struct quic_sock, its members will be split into other subcomponents in the future patches. - Add explicit reserved fields to multiple structs to account for implicit padding and ensure UAPI stability. - Expand reserved fields in struct transport_param and config, handshake and stream_info to allow future extensions without breaking the UAPI. v11: - Set maximum line length to 80 characters. - Drop trailing reserved fields in structs and rely on copy_struct_to/from_user() for extensibility; keep reserved fields in the middle to indicate memory holes. v12: - Make the phrase field in struct quic_connection_close a fixed-size array. - Add QUIC_TRANSPORT_ERROR_VERSION_NEGOTIATION for late use. - Add keepalive_probe_interval to struct quic_config to make keepalive probing configurable. - Relace uses-libc += linux/quic.h with no-header-test += linux/quic.h in usr/include/Makefile to fix the new build error. - Add forward declaration for struct sock in include/linux/quic.h. v15: - Add stub definitions for quic_do_setsockopt() and quic_do_getsockopt() when IS_REACHABLE(CONFIG_IP_QUIC) is false. - Change MSG_QUIC_STREAM_DONTWAIT from MSG_WAITFORONE to MSG_EOR to avoid being filtered out by MSG_INTERNAL_SENDMSG_FLAGS in ____sys_sendmsg(). v16: - Update the function annotations for quic_do_set/getsockopt() to reflect its actual usage, as optval argument can point to either a user or kernel buffer (noted by Sashiko AI review). --- MAINTAINERS | 2 + include/linux/quic.h | 38 ++++++ include/uapi/linux/quic.h | 241 ++++++++++++++++++++++++++++++++++++++ net/quic/socket.c | 36 +++++- net/quic/socket.h | 1 + usr/include/Makefile | 1 + 6 files changed, 315 insertions(+), 4 deletions(-) create mode 100644 include/linux/quic.h create mode 100644 include/uapi/linux/quic.h diff --git a/MAINTAINERS b/MAINTAINERS index 98b81b7fea0c..d75f4553da91 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -22702,6 +22702,8 @@ M: Xin Long <lucien.xin@gmail.com> L: quic@lists.linux.dev S: Maintained W: https://github.com/lxin/quic +F: include/linux/quic.h +F: include/uapi/linux/quic.h F: net/quic/ RADEON and AMDGPU DRM DRIVERS diff --git a/include/linux/quic.h b/include/linux/quic.h new file mode 100644 index 000000000000..51c099e9547f --- /dev/null +++ b/include/linux/quic.h @@ -0,0 +1,38 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* QUIC kernel implementation + * (C) Copyright Red Hat Corp. 2023 + * + * This file is part of the QUIC kernel implementation + * + * Written or modified by: + * Xin Long <lucien.xin@gmail.com> + */ + +#ifndef _LINUX_QUIC_H +#define _LINUX_QUIC_H + +#include <linux/sockptr.h> +#include <uapi/linux/quic.h> + +struct sock; + +#if IS_REACHABLE(CONFIG_IP_QUIC) +int quic_do_setsockopt(struct sock *sk, int optname, sockptr_t optval, + unsigned int optlen); +int quic_do_getsockopt(struct sock *sk, int optname, sockptr_t optval, + sockptr_t optlen); +#else +static inline int quic_do_setsockopt(struct sock *sk, int optname, + sockptr_t optval, unsigned int optlen) +{ + return -EOPNOTSUPP; +} + +static inline int quic_do_getsockopt(struct sock *sk, int optname, + sockptr_t optval, sockptr_t optlen) +{ + return -EOPNOTSUPP; +} +#endif + +#endif diff --git a/include/uapi/linux/quic.h b/include/uapi/linux/quic.h new file mode 100644 index 000000000000..ae37d6a7bc36 --- /dev/null +++ b/include/uapi/linux/quic.h @@ -0,0 +1,241 @@ +/* SPDX-License-Identifier: GPL-2.0+ WITH Linux-syscall-note */ +/* QUIC kernel implementation + * (C) Copyright Red Hat Corp. 2023 + * + * This file is part of the QUIC kernel implementation + * + * Written or modified by: + * Xin Long <lucien.xin@gmail.com> + */ + +#ifndef _UAPI_LINUX_QUIC_H +#define _UAPI_LINUX_QUIC_H + +#include <linux/types.h> +#ifdef __KERNEL__ +#include <linux/socket.h> +#else +#include <sys/socket.h> /* for MSG_* flags */ +#endif + +/* NOTE: Structure descriptions are specified in: + * https://datatracker.ietf.org/doc/html/draft-lxin-quic-socket-apis + */ + +/* Send or Receive Options APIs */ +enum quic_cmsg_type { + QUIC_STREAM_INFO, + QUIC_HANDSHAKE_INFO, +}; + +#define QUIC_STREAM_TYPE_SERVER_MASK 0x01 +#define QUIC_STREAM_TYPE_UNI_MASK 0x02 +#define QUIC_STREAM_TYPE_MASK 0x03 + +enum quic_msg_flags { + /* flags for stream_flags */ + MSG_QUIC_STREAM_NEW = MSG_SYN, + MSG_QUIC_STREAM_FIN = MSG_FIN, + MSG_QUIC_STREAM_UNI = MSG_CONFIRM, + MSG_QUIC_STREAM_DONTWAIT = MSG_EOR, + MSG_QUIC_STREAM_SNDBLOCK = MSG_ERRQUEUE, + + /* extended flags for msg_flags */ + MSG_QUIC_DATAGRAM = MSG_RST, + MSG_QUIC_NOTIFICATION = MSG_MORE, +}; + +enum quic_crypto_level { + QUIC_CRYPTO_APP, + QUIC_CRYPTO_INITIAL, + QUIC_CRYPTO_HANDSHAKE, + QUIC_CRYPTO_EARLY, + QUIC_CRYPTO_MAX, +}; + +struct quic_handshake_info { + __u8 crypto_level; +}; + +struct quic_stream_info { + __s64 stream_id; + __u32 stream_flags; +}; + +/* Socket Options APIs */ +#define QUIC_SOCKOPT_EVENT 0 +#define QUIC_SOCKOPT_STREAM_OPEN 1 +#define QUIC_SOCKOPT_STREAM_RESET 2 +#define QUIC_SOCKOPT_STREAM_STOP_SENDING 3 +#define QUIC_SOCKOPT_CONNECTION_ID 4 +#define QUIC_SOCKOPT_CONNECTION_CLOSE 5 +#define QUIC_SOCKOPT_CONNECTION_MIGRATION 6 +#define QUIC_SOCKOPT_KEY_UPDATE 7 +#define QUIC_SOCKOPT_TRANSPORT_PARAM 8 +#define QUIC_SOCKOPT_CONFIG 9 +#define QUIC_SOCKOPT_TOKEN 10 +#define QUIC_SOCKOPT_ALPN 11 +#define QUIC_SOCKOPT_SESSION_TICKET 12 +#define QUIC_SOCKOPT_CRYPTO_SECRET 13 +#define QUIC_SOCKOPT_TRANSPORT_PARAM_EXT 14 + +#define QUIC_VERSION_V1 0x1 +#define QUIC_VERSION_V2 0x6b3343cf + +struct quic_transport_param { + __u8 remote; + __u8 disable_active_migration; + __u8 grease_quic_bit; + __u8 stateless_reset; + __u8 disable_1rtt_encryption; + __u8 disable_compatible_version; + __u8 active_connection_id_limit; + __u8 ack_delay_exponent; + __u16 max_datagram_frame_size; + __u16 max_udp_payload_size; + __u32 max_idle_timeout; + __u32 max_ack_delay; + __u16 max_streams_bidi; + __u16 max_streams_uni; + __u64 max_data; + __u64 max_stream_data_bidi_local; + __u64 max_stream_data_bidi_remote; + __u64 max_stream_data_uni; +}; + +struct quic_config { + __u32 version; + __u32 plpmtud_probe_interval; + __u32 initial_smoothed_rtt; + __u32 payload_cipher_type; + __u8 congestion_control_algo; + __u8 validate_peer_address; + __u8 stream_data_nodelay; + __u8 receive_session_ticket; + __u8 certificate_request; + __u8 reserved[3]; + __u32 keepalive_probe_interval; +}; + +struct quic_crypto_secret { + __u8 send; /* send or recv */ + __u8 level; /* crypto level */ + __u16 reserved; + __u32 type; /* TLS_CIPHER_* */ +#define QUIC_CRYPTO_SECRET_BUFFER_SIZE 48 + __u8 secret[QUIC_CRYPTO_SECRET_BUFFER_SIZE]; +}; + +enum quic_cong_algo { + QUIC_CONG_ALG_RENO, + QUIC_CONG_ALG_MAX, +}; + +struct quic_errinfo { + __s64 stream_id; + __u32 errcode; +}; + +struct quic_connection_id_info { + __u8 dest; + __u8 reserved[3]; + __u32 active; + __u32 prior_to; +}; + +struct quic_event_option { + __u8 type; + __u8 on; +}; + +/* Event APIs */ +enum quic_event_type { + QUIC_EVENT_NONE, + QUIC_EVENT_STREAM_UPDATE, + QUIC_EVENT_STREAM_MAX_DATA, + QUIC_EVENT_STREAM_MAX_STREAM, + QUIC_EVENT_CONNECTION_ID, + QUIC_EVENT_CONNECTION_CLOSE, + QUIC_EVENT_CONNECTION_MIGRATION, + QUIC_EVENT_KEY_UPDATE, + QUIC_EVENT_NEW_TOKEN, + QUIC_EVENT_NEW_SESSION_TICKET, + QUIC_EVENT_MAX, +}; + +enum { + QUIC_STREAM_SEND_STATE_READY, + QUIC_STREAM_SEND_STATE_SEND, + QUIC_STREAM_SEND_STATE_SENT, + QUIC_STREAM_SEND_STATE_RECVD, + QUIC_STREAM_SEND_STATE_RESET_SENT, + QUIC_STREAM_SEND_STATE_RESET_RECVD, + + QUIC_STREAM_RECV_STATE_RECV, + QUIC_STREAM_RECV_STATE_SIZE_KNOWN, + QUIC_STREAM_RECV_STATE_RECVD, + QUIC_STREAM_RECV_STATE_READ, + QUIC_STREAM_RECV_STATE_RESET_RECVD, + QUIC_STREAM_RECV_STATE_RESET_READ, +}; + +struct quic_stream_update { + __s64 id; + __u8 state; + __u8 reserved[3]; + __u32 errcode; + __u64 finalsz; +}; + +struct quic_stream_max_data { + __s64 id; + __u64 max_data; +}; + +struct quic_connection_close { + __u32 errcode; + __u8 frame; + __u8 reserved[3]; +#define QUIC_CLOSE_PHRASE_BUFFER_SIZE 64 + __u8 phrase[QUIC_CLOSE_PHRASE_BUFFER_SIZE]; +}; + +union quic_event { + struct quic_stream_update update; + struct quic_stream_max_data max_data; + struct quic_connection_close close; + struct quic_connection_id_info info; + __u64 max_stream; + __u8 local_migration; + __u8 key_update_phase; +}; + +enum { + QUIC_TRANSPORT_ERROR_NONE = 0x00, + QUIC_TRANSPORT_ERROR_INTERNAL = 0x01, + QUIC_TRANSPORT_ERROR_CONNECTION_REFUSED = 0x02, + QUIC_TRANSPORT_ERROR_FLOW_CONTROL = 0x03, + QUIC_TRANSPORT_ERROR_STREAM_LIMIT = 0x04, + QUIC_TRANSPORT_ERROR_STREAM_STATE = 0x05, + QUIC_TRANSPORT_ERROR_FINAL_SIZE = 0x06, + QUIC_TRANSPORT_ERROR_FRAME_ENCODING = 0x07, + QUIC_TRANSPORT_ERROR_TRANSPORT_PARAM = 0x08, + QUIC_TRANSPORT_ERROR_CONNECTION_ID_LIMIT = 0x09, + QUIC_TRANSPORT_ERROR_PROTOCOL_VIOLATION = 0x0a, + QUIC_TRANSPORT_ERROR_INVALID_TOKEN = 0x0b, + QUIC_TRANSPORT_ERROR_APPLICATION = 0x0c, + QUIC_TRANSPORT_ERROR_CRYPTO_BUF_EXCEEDED = 0x0d, + QUIC_TRANSPORT_ERROR_KEY_UPDATE = 0x0e, + QUIC_TRANSPORT_ERROR_AEAD_LIMIT_REACHED = 0x0f, + QUIC_TRANSPORT_ERROR_NO_VIABLE_PATH = 0x10, + QUIC_TRANSPORT_ERROR_VERSION_NEGOTIATION = 0x11, + + /* The cryptographic handshake failed. A range of 256 values is reserved + * for carrying error codes specific to the cryptographic handshake that + * is used. Codes for errors occurring when TLS is used for the + * cryptographic handshake are described in Section 4.8 of [QUIC-TLS]. + */ + QUIC_TRANSPORT_ERROR_CRYPTO = 0x0100, +}; + +#endif /* _UAPI_LINUX_QUIC_H */ diff --git a/net/quic/socket.c b/net/quic/socket.c index 0037cd4010f7..1fb948602e56 100644 --- a/net/quic/socket.c +++ b/net/quic/socket.c @@ -111,11 +111,25 @@ static void quic_close(struct sock *sk, long timeout) sk_common_release(sk); } -static int quic_do_setsockopt(struct sock *sk, int optname, sockptr_t optval, - unsigned int optlen) +/** + * quic_do_setsockopt - set a QUIC socket option + * @sk: socket to configure + * @optname: option name (QUIC-level) + * @optval: user or kernel buffer containing the option value + * @optlen: size of the option value + * + * Sets a QUIC socket option on a given socket. + * + * Return: + * - On success, 0 is returned. + * - On error, a negative error value is returned. + */ +int quic_do_setsockopt(struct sock *sk, int optname, sockptr_t optval, + unsigned int optlen) { return -EOPNOTSUPP; } +EXPORT_SYMBOL_GPL(quic_do_setsockopt); static int quic_setsockopt(struct sock *sk, int level, int optname, sockptr_t optval, unsigned int optlen) @@ -127,11 +141,25 @@ static int quic_setsockopt(struct sock *sk, int level, int optname, return quic_do_setsockopt(sk, optname, optval, optlen); } -static int quic_do_getsockopt(struct sock *sk, int optname, sockptr_t optval, - sockptr_t optlen) +/** + * quic_do_getsockopt - get a QUIC socket option + * @sk: socket to query + * @optname: option name (QUIC-level) + * @optval: user or kernel buffer to receive the option value + * @optlen: pointer to buffer size; updated with actual size on return + * + * Gets a QUIC socket option from a given socket. + * + * Return: + * - On success, 0 is returned. + * - On error, a negative error value is returned. + */ +int quic_do_getsockopt(struct sock *sk, int optname, sockptr_t optval, + sockptr_t optlen) { return -EOPNOTSUPP; } +EXPORT_SYMBOL_GPL(quic_do_getsockopt); static int quic_getsockopt(struct sock *sk, int level, int optname, char __user *optval, int __user *optlen) diff --git a/net/quic/socket.h b/net/quic/socket.h index 0aa642e3b0ae..61df0c5867be 100644 --- a/net/quic/socket.h +++ b/net/quic/socket.h @@ -9,6 +9,7 @@ */ #include <net/udp_tunnel.h> +#include <linux/quic.h> #include "common.h" #include "family.h" diff --git a/usr/include/Makefile b/usr/include/Makefile index ee69dd9d970e..8b4133d38da2 100644 --- a/usr/include/Makefile +++ b/usr/include/Makefile @@ -31,6 +31,7 @@ no-header-test += linux/omap3isp.h no-header-test += linux/omapfb.h no-header-test += linux/patchkey.h no-header-test += linux/phonet.h +no-header-test += linux/quic.h no-header-test += linux/sctp.h no-header-test += linux/sysctl.h no-header-test += linux/usb/audio.h -- 2.47.1 ^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 1:05 UTC | newest] Thread overview: 2+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-10-07 1:05 [PATCH net-next v16 05/15] quic: provide quic.h header files for kernel and userspace netdev-bot+sashiko -- strict thread matches above, loose matches on Subject: below -- 2026-10-05 19:03 [PATCH net-next v16 00/15] net: introduce QUIC infrastructure and core subcomponents Xin Long 2026-10-05 19:04 ` [PATCH net-next v16 05/15] quic: provide quic.h header files for kernel and userspace Xin Long
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox