From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:46119) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Zc91j-0006wj-GB for qemu-devel@nongnu.org; Wed, 16 Sep 2015 05:29:20 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Zc91g-0004zF-AZ for qemu-devel@nongnu.org; Wed, 16 Sep 2015 05:29:19 -0400 Received: from mx1.redhat.com ([209.132.183.28]:42267) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Zc91g-0004z7-3L for qemu-devel@nongnu.org; Wed, 16 Sep 2015 05:29:16 -0400 References: <1441783481-17698-1-git-send-email-yanghy@cn.fujitsu.com> <1441783481-17698-7-git-send-email-yanghy@cn.fujitsu.com> From: Jason Wang Message-ID: <55F93663.1050805@redhat.com> Date: Wed, 16 Sep 2015 17:29:07 +0800 MIME-Version: 1.0 In-Reply-To: <1441783481-17698-7-git-send-email-yanghy@cn.fujitsu.com> Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH v10 06/10] netfilter: add an API to pass the packet to next filter List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Yang Hongyang , qemu-devel@nongnu.org Cc: thuth@redhat.com, lizhijian@cn.fujitsu.com, armbru@redhat.com, stefanha@redhat.com, zhang.zhanghailiang@huawei.com On 09/09/2015 03:24 PM, Yang Hongyang wrote: > add an API qemu_netfilter_pass_to_next() to pass the packet > to next filter. > > Signed-off-by: Yang Hongyang > Reviewed-by: Thomas Huth > --- > v10: adjust as a NetQueueDeliverFunc > v9: fix a bug when curr filter chain is all > v5: fold params to NetPacket struct > --- > include/net/filter.h | 7 ++++++ > net/filter.c | 60 ++++++++++++++++++++++++++++++++++++++++++++++++++++ > 2 files changed, 67 insertions(+) > > diff --git a/include/net/filter.h b/include/net/filter.h > index 4557cb9..ed2bb66 100644 > --- a/include/net/filter.h > +++ b/include/net/filter.h > @@ -57,4 +57,11 @@ struct NetFilterState { > QTAILQ_ENTRY(NetFilterState) next; > }; > > +/* pass the packet to the next filter */ > +ssize_t qemu_netfilter_pass_to_next(NetClientState *sender, > + unsigned flags, > + const struct iovec *iov, > + int iovcnt, > + void *opaque); > + > #endif /* QEMU_NET_FILTER_H */ > diff --git a/net/filter.c b/net/filter.c > index 5192c6d..086f271 100644 > --- a/net/filter.c > +++ b/net/filter.c > @@ -14,9 +14,69 @@ > #include "net/net.h" > #include "net/vhost_net.h" > #include "qom/object_interfaces.h" > +#include "qemu/iov.h" > > static QTAILQ_HEAD(, NetFilterState) net_filters; > > +ssize_t qemu_netfilter_pass_to_next(NetClientState *sender, > + unsigned flags, > + const struct iovec *iov, > + int iovcnt, > + void *opaque) > +{ > + int ret = 0; > + int chain; > + NetFilterState *nf = opaque; > + NetFilterState *next = QTAILQ_NEXT(nf, next); > + > + if (!sender || !sender->peer) { > + /* no receiver, or sender been deleted, no need to pass it further */ > + goto out; > + } > + > + if (nf->chain == NET_FILTER_CHAIN_ALL) { > + if (sender == nf->netdev) { > + /* This packet is sent by netdev itself */ > + chain = NET_FILTER_CHAIN_OUT; > + } else { > + chain = NET_FILTER_CHAIN_IN; > + } > + } else { > + chain = nf->chain; > + } > + > + while (next) { > + if (next->chain == chain || next->chain == NET_FILTER_CHAIN_ALL) { > + /* > + * if qemu_netfilter_pass_to_next been called, means that > + * the packet has been hold by filter and has already retured size > + * to the sender, so sent_cb shouldn't be called later, just > + * pass NULL to next. > + */ > + ret = NETFILTER_GET_CLASS(OBJECT(next))->receive_iov( > + next, sender, flags, iov, iovcnt, NULL); > + if (ret) { > + return ret; > + } > + } > + next = QTAILQ_NEXT(next, next); > + } Nitpick: Kind of codes duplication with filter_receive(). May consider to unify them it you want to send next version. > + > + /* > + * We have gone through all filters, pass it to receiver. > + * Do the valid check again incase sender or receiver been > + * deleted while we go through filters. > + */ > + if (sender && sender->peer) { > + return qemu_net_queue_send_iov(sender->peer->incoming_queue, > + sender, flags, iov, iovcnt, NULL); > + } > + > +out: > + /* no receiver, or sender been deleted */ > + return iov_size(iov, iovcnt); > +} > + > static char *netfilter_get_netdev_id(Object *obj, Error **errp) > { > NetFilterState *nf = NETFILTER(obj);