filter.c 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377
  1. /*
  2. * Copyright (c) 2015 FUJITSU LIMITED
  3. * Author: Yang Hongyang <yanghy@cn.fujitsu.com>
  4. *
  5. * This work is licensed under the terms of the GNU GPL, version 2 or
  6. * later. See the COPYING file in the top-level directory.
  7. */
  8. #include "qemu/osdep.h"
  9. #include "qapi/error.h"
  10. #include "qapi/qmp/qerror.h"
  11. #include "qemu/error-report.h"
  12. #include "net/filter.h"
  13. #include "net/net.h"
  14. #include "net/vhost_net.h"
  15. #include "qom/object_interfaces.h"
  16. #include "qemu/iov.h"
  17. #include "qemu/module.h"
  18. #include "net/colo.h"
  19. #include "migration/colo.h"
  20. static inline bool qemu_can_skip_netfilter(NetFilterState *nf)
  21. {
  22. return !nf->on;
  23. }
  24. ssize_t qemu_netfilter_receive(NetFilterState *nf,
  25. NetFilterDirection direction,
  26. NetClientState *sender,
  27. unsigned flags,
  28. const struct iovec *iov,
  29. int iovcnt,
  30. NetPacketSent *sent_cb)
  31. {
  32. if (qemu_can_skip_netfilter(nf)) {
  33. return 0;
  34. }
  35. if (nf->direction == direction ||
  36. nf->direction == NET_FILTER_DIRECTION_ALL) {
  37. return NETFILTER_GET_CLASS(OBJECT(nf))->receive_iov(
  38. nf, sender, flags, iov, iovcnt, sent_cb);
  39. }
  40. return 0;
  41. }
  42. static NetFilterState *netfilter_next(NetFilterState *nf,
  43. NetFilterDirection dir)
  44. {
  45. NetFilterState *next;
  46. if (dir == NET_FILTER_DIRECTION_TX) {
  47. /* forward walk through filters */
  48. next = QTAILQ_NEXT(nf, next);
  49. } else {
  50. /* reverse order */
  51. next = QTAILQ_PREV(nf, next);
  52. }
  53. return next;
  54. }
  55. ssize_t qemu_netfilter_pass_to_next(NetClientState *sender,
  56. unsigned flags,
  57. const struct iovec *iov,
  58. int iovcnt,
  59. void *opaque)
  60. {
  61. int ret = 0;
  62. int direction;
  63. NetFilterState *nf = opaque;
  64. NetFilterState *next = NULL;
  65. if (!sender || !sender->peer) {
  66. /* no receiver, or sender been deleted, no need to pass it further */
  67. goto out;
  68. }
  69. if (nf->direction == NET_FILTER_DIRECTION_ALL) {
  70. if (sender == nf->netdev) {
  71. /* This packet is sent by netdev itself */
  72. direction = NET_FILTER_DIRECTION_TX;
  73. } else {
  74. direction = NET_FILTER_DIRECTION_RX;
  75. }
  76. } else {
  77. direction = nf->direction;
  78. }
  79. next = netfilter_next(nf, direction);
  80. while (next) {
  81. /*
  82. * if qemu_netfilter_pass_to_next been called, means that
  83. * the packet has been hold by filter and has already retured size
  84. * to the sender, so sent_cb shouldn't be called later, just
  85. * pass NULL to next.
  86. */
  87. ret = qemu_netfilter_receive(next, direction, sender, flags, iov,
  88. iovcnt, NULL);
  89. if (ret) {
  90. return ret;
  91. }
  92. next = netfilter_next(next, direction);
  93. }
  94. /*
  95. * We have gone through all filters, pass it to receiver.
  96. * Do the valid check again incase sender or receiver been
  97. * deleted while we go through filters.
  98. */
  99. if (sender && sender->peer) {
  100. qemu_net_queue_send_iov(sender->peer->incoming_queue,
  101. sender, flags, iov, iovcnt, NULL);
  102. }
  103. out:
  104. /* no receiver, or sender been deleted */
  105. return iov_size(iov, iovcnt);
  106. }
  107. static char *netfilter_get_netdev_id(Object *obj, Error **errp)
  108. {
  109. NetFilterState *nf = NETFILTER(obj);
  110. return g_strdup(nf->netdev_id);
  111. }
  112. static void netfilter_set_netdev_id(Object *obj, const char *str, Error **errp)
  113. {
  114. NetFilterState *nf = NETFILTER(obj);
  115. nf->netdev_id = g_strdup(str);
  116. }
  117. static int netfilter_get_direction(Object *obj, Error **errp G_GNUC_UNUSED)
  118. {
  119. NetFilterState *nf = NETFILTER(obj);
  120. return nf->direction;
  121. }
  122. static void netfilter_set_direction(Object *obj, int direction, Error **errp)
  123. {
  124. NetFilterState *nf = NETFILTER(obj);
  125. nf->direction = direction;
  126. }
  127. static char *netfilter_get_status(Object *obj, Error **errp)
  128. {
  129. NetFilterState *nf = NETFILTER(obj);
  130. return nf->on ? g_strdup("on") : g_strdup("off");
  131. }
  132. static void netfilter_set_status(Object *obj, const char *str, Error **errp)
  133. {
  134. NetFilterState *nf = NETFILTER(obj);
  135. NetFilterClass *nfc = NETFILTER_GET_CLASS(obj);
  136. if (strcmp(str, "on") && strcmp(str, "off")) {
  137. error_setg(errp, "Invalid value for netfilter status, "
  138. "should be 'on' or 'off'");
  139. return;
  140. }
  141. if (nf->on == !strcmp(str, "on")) {
  142. return;
  143. }
  144. nf->on = !nf->on;
  145. if (nf->netdev && nfc->status_changed) {
  146. nfc->status_changed(nf, errp);
  147. }
  148. }
  149. static char *netfilter_get_position(Object *obj, Error **errp)
  150. {
  151. NetFilterState *nf = NETFILTER(obj);
  152. return g_strdup(nf->position);
  153. }
  154. static void netfilter_set_position(Object *obj, const char *str, Error **errp)
  155. {
  156. NetFilterState *nf = NETFILTER(obj);
  157. nf->position = g_strdup(str);
  158. }
  159. static char *netfilter_get_insert(Object *obj, Error **errp)
  160. {
  161. NetFilterState *nf = NETFILTER(obj);
  162. return nf->insert_before_flag ? g_strdup("before") : g_strdup("behind");
  163. }
  164. static void netfilter_set_insert(Object *obj, const char *str, Error **errp)
  165. {
  166. NetFilterState *nf = NETFILTER(obj);
  167. if (strcmp(str, "before") && strcmp(str, "behind")) {
  168. error_setg(errp, "Invalid value for netfilter insert, "
  169. "should be 'before' or 'behind'");
  170. return;
  171. }
  172. nf->insert_before_flag = !strcmp(str, "before");
  173. }
  174. static void netfilter_init(Object *obj)
  175. {
  176. NetFilterState *nf = NETFILTER(obj);
  177. nf->on = true;
  178. nf->insert_before_flag = false;
  179. nf->position = g_strdup("tail");
  180. object_property_add_str(obj, "netdev",
  181. netfilter_get_netdev_id, netfilter_set_netdev_id);
  182. object_property_add_enum(obj, "queue", "NetFilterDirection",
  183. &NetFilterDirection_lookup,
  184. netfilter_get_direction, netfilter_set_direction);
  185. object_property_add_str(obj, "status",
  186. netfilter_get_status, netfilter_set_status);
  187. object_property_add_str(obj, "position",
  188. netfilter_get_position, netfilter_set_position);
  189. object_property_add_str(obj, "insert",
  190. netfilter_get_insert, netfilter_set_insert);
  191. }
  192. static void netfilter_complete(UserCreatable *uc, Error **errp)
  193. {
  194. NetFilterState *nf = NETFILTER(uc);
  195. NetFilterState *position = NULL;
  196. NetClientState *ncs[MAX_QUEUE_NUM];
  197. NetFilterClass *nfc = NETFILTER_GET_CLASS(uc);
  198. int queues;
  199. Error *local_err = NULL;
  200. if (!nf->netdev_id) {
  201. error_setg(errp, "Parameter 'netdev' is required");
  202. return;
  203. }
  204. queues = qemu_find_net_clients_except(nf->netdev_id, ncs,
  205. NET_CLIENT_DRIVER_NIC,
  206. MAX_QUEUE_NUM);
  207. if (queues < 1) {
  208. error_setg(errp, QERR_INVALID_PARAMETER_VALUE, "netdev",
  209. "a network backend id");
  210. return;
  211. } else if (queues > 1) {
  212. error_setg(errp, "multiqueue is not supported");
  213. return;
  214. }
  215. if (get_vhost_net(ncs[0])) {
  216. error_setg(errp, "Vhost is not supported");
  217. return;
  218. }
  219. if (strcmp(nf->position, "head") && strcmp(nf->position, "tail")) {
  220. Object *container;
  221. Object *obj;
  222. char *position_id;
  223. if (!g_str_has_prefix(nf->position, "id=")) {
  224. error_setg(errp, QERR_INVALID_PARAMETER_VALUE, "position",
  225. "'head', 'tail' or 'id=<id>'");
  226. return;
  227. }
  228. /* get the id from the string */
  229. position_id = g_strndup(nf->position + 3, strlen(nf->position) - 3);
  230. /* Search for the position to insert before/behind */
  231. container = object_get_objects_root();
  232. obj = object_resolve_path_component(container, position_id);
  233. if (!obj) {
  234. error_setg(errp, "filter '%s' not found", position_id);
  235. g_free(position_id);
  236. return;
  237. }
  238. position = NETFILTER(obj);
  239. if (position->netdev != ncs[0]) {
  240. error_setg(errp, "filter '%s' belongs to a different netdev",
  241. position_id);
  242. g_free(position_id);
  243. return;
  244. }
  245. g_free(position_id);
  246. }
  247. nf->netdev = ncs[0];
  248. if (nfc->setup) {
  249. nfc->setup(nf, &local_err);
  250. if (local_err) {
  251. error_propagate(errp, local_err);
  252. return;
  253. }
  254. }
  255. if (position) {
  256. if (nf->insert_before_flag) {
  257. QTAILQ_INSERT_BEFORE(position, nf, next);
  258. } else {
  259. QTAILQ_INSERT_AFTER(&nf->netdev->filters, position, nf, next);
  260. }
  261. } else if (!strcmp(nf->position, "head")) {
  262. QTAILQ_INSERT_HEAD(&nf->netdev->filters, nf, next);
  263. } else if (!strcmp(nf->position, "tail")) {
  264. QTAILQ_INSERT_TAIL(&nf->netdev->filters, nf, next);
  265. }
  266. }
  267. static void netfilter_finalize(Object *obj)
  268. {
  269. NetFilterState *nf = NETFILTER(obj);
  270. NetFilterClass *nfc = NETFILTER_GET_CLASS(obj);
  271. if (nfc->cleanup) {
  272. nfc->cleanup(nf);
  273. }
  274. if (nf->netdev && !QTAILQ_EMPTY(&nf->netdev->filters) &&
  275. QTAILQ_IN_USE(nf, next)) {
  276. QTAILQ_REMOVE(&nf->netdev->filters, nf, next);
  277. }
  278. g_free(nf->netdev_id);
  279. g_free(nf->position);
  280. }
  281. static void default_handle_event(NetFilterState *nf, int event, Error **errp)
  282. {
  283. switch (event) {
  284. case COLO_EVENT_CHECKPOINT:
  285. break;
  286. case COLO_EVENT_FAILOVER:
  287. object_property_set_str(OBJECT(nf), "status", "off", errp);
  288. break;
  289. default:
  290. break;
  291. }
  292. }
  293. static void netfilter_class_init(ObjectClass *oc, void *data)
  294. {
  295. UserCreatableClass *ucc = USER_CREATABLE_CLASS(oc);
  296. NetFilterClass *nfc = NETFILTER_CLASS(oc);
  297. ucc->complete = netfilter_complete;
  298. nfc->handle_event = default_handle_event;
  299. }
  300. static const TypeInfo netfilter_info = {
  301. .name = TYPE_NETFILTER,
  302. .parent = TYPE_OBJECT,
  303. .abstract = true,
  304. .class_size = sizeof(NetFilterClass),
  305. .class_init = netfilter_class_init,
  306. .instance_size = sizeof(NetFilterState),
  307. .instance_init = netfilter_init,
  308. .instance_finalize = netfilter_finalize,
  309. .interfaces = (InterfaceInfo[]) {
  310. { TYPE_USER_CREATABLE },
  311. { }
  312. }
  313. };
  314. static void register_types(void)
  315. {
  316. type_register_static(&netfilter_info);
  317. }
  318. type_init(register_types);