Linux Netfilter development
 help / color / mirror / Atom feed
From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Florian Westphal <fw@strlen.de>
Cc: netfilter-devel <netfilter-devel@vger.kernel.org>,
	Kevin Vigouroux <ke.vigouroux@laposte.net>
Subject: Re: [PATCH nft] evalute: make vlan pcp updates work
Date: Mon, 21 Apr 2025 20:37:37 +0200	[thread overview]
Message-ID: <aAaQcZdvH76tVvh_@calendula> (raw)
In-Reply-To: <20250419114442.45696-1-fw@strlen.de>

On Sat, Apr 19, 2025 at 01:44:39PM +0200, Florian Westphal wrote:
> On kernel side, nft_payload_set_vlan() requires a 2 or 4 byte
> write to the vlan header.
> 
> As-is, nft emits a 1 byte write:
>   [ payload load 1b @ link header + 14 => reg 1 ]
>   [ bitwise reg 1 = ( reg 1 & 0x0000001f ) ^ 0x00000020 ]
> 
> ... which the kernel doesn't support.  Expand all vlan header updates to
> a 2 or 4 byte write and update the existing vlan id test case.
> 
> Reported-by: Kevin Vigouroux <ke.vigouroux@laposte.net>
> Signed-off-by: Florian Westphal <fw@strlen.de>

Reviewed-by: Pablo Neira Ayuso <pablo@netfilter.org>

Thanks

> ---
>  src/evaluate.c                                | 42 +++++++++++++++++--
>  .../shell/testcases/packetpath/vlan_mangling  |  2 +
>  2 files changed, 40 insertions(+), 4 deletions(-)
> 
> diff --git a/src/evaluate.c b/src/evaluate.c
> index d13b11413244..9c7f23cb080e 100644
> --- a/src/evaluate.c
> +++ b/src/evaluate.c
> @@ -3258,6 +3258,40 @@ static bool stmt_evaluate_payload_need_csum(const struct expr *payload)
>  	return desc && desc->checksum_key;
>  }
>  
> +static bool stmt_evaluate_is_vlan(const struct expr *payload)
> +{
> +	return payload->payload.base == PROTO_BASE_LL_HDR &&
> +	       payload->payload.desc == &proto_vlan;
> +}
> +
> +/** stmt_evaluate_payload_need_aligned_fetch
> + *
> + * @payload:	payload expression to check
> + *
> + * Some types of stores need to round up to an even sized byte length,
> + * typically 1 -> 2 or 3 -> 4 bytes.
> + *
> + * This includes anything that needs inet checksum fixups and also writes
> + * to the vlan header.  This is because of VLAN header removal in the
> + * kernel: nftables kernel side provides illusion of a linear packet, i.e.
> + * ethernet_header|vlan_header|network_header.
> + *
> + * When a write to the vlan header is performed, kernel side updates the
> + * pseudoheader, but only accepts 2 or 4 byte writes to vlan proto/TCI.
> + *
> + * Return true if load needs to be expanded to cover even amount of bytes
> + */
> +static bool stmt_evaluate_payload_need_aligned_fetch(const struct expr *payload)
> +{
> +	if (stmt_evaluate_payload_need_csum(payload))
> +		return true;
> +
> +	if (stmt_evaluate_is_vlan(payload))
> +		return true;
> +
> +	return false;
> +}
> +
>  static int stmt_evaluate_exthdr(struct eval_ctx *ctx, struct stmt *stmt)
>  {
>  	struct expr *exthdr;
> @@ -3287,7 +3321,7 @@ static int stmt_evaluate_payload(struct eval_ctx *ctx, struct stmt *stmt)
>  	unsigned int masklen, extra_len = 0;
>  	struct expr *payload;
>  	mpz_t bitmask, ff;
> -	bool need_csum;
> +	bool aligned_fetch;
>  
>  	if (stmt->payload.expr->payload.inner_desc) {
>  		return expr_error(ctx->msgs, stmt->payload.expr,
> @@ -3310,7 +3344,7 @@ static int stmt_evaluate_payload(struct eval_ctx *ctx, struct stmt *stmt)
>  	if (stmt->payload.val->etype == EXPR_RANGE)
>  		return stmt_error_range(ctx, stmt, stmt->payload.val);
>  
> -	need_csum = stmt_evaluate_payload_need_csum(payload);
> +	aligned_fetch = stmt_evaluate_payload_need_aligned_fetch(payload);
>  
>  	if (!payload_needs_adjustment(payload)) {
>  
> @@ -3318,7 +3352,7 @@ static int stmt_evaluate_payload(struct eval_ctx *ctx, struct stmt *stmt)
>  		 * update checksum and the length is not even because
>  		 * kernel checksum functions cannot deal with odd lengths.
>  		 */
> -		if (!need_csum || ((payload->len / BITS_PER_BYTE) & 1) == 0)
> +		if (!aligned_fetch || ((payload->len / BITS_PER_BYTE) & 1) == 0)
>  			return 0;
>  	}
>  
> @@ -3334,7 +3368,7 @@ static int stmt_evaluate_payload(struct eval_ctx *ctx, struct stmt *stmt)
>  				  "uneven load cannot span more than %u bytes, got %u",
>  				  sizeof(data), payload_byte_size);
>  
> -	if (need_csum && payload_byte_size & 1) {
> +	if (aligned_fetch && payload_byte_size & 1) {
>  		payload_byte_size++;
>  
>  		if (payload_byte_offset & 1) { /* prefer 16bit aligned fetch */
> diff --git a/tests/shell/testcases/packetpath/vlan_mangling b/tests/shell/testcases/packetpath/vlan_mangling
> index e3fd443ebcf9..3fc2ebb2a517 100755
> --- a/tests/shell/testcases/packetpath/vlan_mangling
> +++ b/tests/shell/testcases/packetpath/vlan_mangling
> @@ -48,12 +48,14 @@ table netdev t {
>  
>  	chain in {
>  		type filter hook ingress device veth0 priority filter;
> +		vlan pcp 0 counter
>  		ether saddr da:d3:00:01:02:03 vlan id 123 jump in_update_vlan
>  	}
>  
>  	chain out_update_vlan {
>  		vlan type arp vlan id set 123 counter
>  		ip daddr 10.1.1.1 icmp type echo-reply vlan id set 123 counter
> +		vlan pcp set 6 counter
>  	}
>  
>  	chain out {
> -- 
> 2.49.0
> 
> 

      reply	other threads:[~2025-04-21 18:37 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-19 11:44 [PATCH nft] evalute: make vlan pcp updates work Florian Westphal
2025-04-21 18:37 ` Pablo Neira Ayuso [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aAaQcZdvH76tVvh_@calendula \
    --to=pablo@netfilter.org \
    --cc=fw@strlen.de \
    --cc=ke.vigouroux@laposte.net \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox