filter.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377
  1. /*
  2. * Copyright (c) 2015 FUJITSU LIMITED
  3. * Author: Yang Hongyang <yanghy@cn.fujitsu.com>
  4. *
  5. * This work is licensed under the terms of the GNU GPL, version 2 or
  6. * later. See the COPYING file in the top-level directory.
  7. */
  8. #include "qemu/osdep.h"
  9. #include "qapi/error.h"
  10. #include "qapi/qmp/qerror.h"
  11. #include "qemu/error-report.h"
  12. #include "net/filter.h"
  13. #include "net/net.h"
  14. #include "net/vhost_net.h"
  15. #include "qom/object_interfaces.h"
  16. #include "qemu/iov.h"
  17. #include "qemu/module.h"
  18. #include "net/colo.h"
  19. #include "migration/colo.h"
  20. static inline bool qemu_can_skip_netfilter(NetFilterState *nf)
  21. {
  22. return !nf->on;
  23. }
  24. ssize_t qemu_netfilter_receive(NetFilterState *nf,
  25. NetFilterDirection direction,
  26. NetClientState *sender,
  27. unsigned flags,
  28. const struct iovec *iov,
  29. int iovcnt,
  30. NetPacketSent *sent_cb)
  31. {
  32. if (qemu_can_skip_netfilter(nf)) {
  33. return 0;
  34. }
  35. if (nf->direction == direction ||
  36. nf->direction == NET_FILTER_DIRECTION_ALL) {
  37. return NETFILTER_GET_CLASS(OBJECT(nf))->receive_iov(
  38. nf, sender, flags, iov, iovcnt, sent_cb);
  39. }
  40. return 0;
  41. }
  42. static NetFilterState *netfilter_next(NetFilterState *nf,
  43. NetFilterDirection dir)
  44. {
  45. NetFilterState *next;
  46. if (dir == NET_FILTER_DIRECTION_TX) {
  47. /* forward walk through filters */
  48. next = QTAILQ_NEXT(nf, next);
  49. } else {
  50. /* reverse order */
  51. next = QTAILQ_PREV(nf, next);
  52. }
  53. return next;
  54. }
  55. ssize_t qemu_netfilter_pass_to_next(NetClientState *sender,
  56. unsigned flags,
  57. const struct iovec *iov,
  58. int iovcnt,
  59. void *opaque)
  60. {
  61. int ret = 0;
  62. int direction;
  63. NetFilterState *nf = opaque;
  64. NetFilterState *next = NULL;
  65. if (!sender || !sender->peer) {
  66. /* no receiver, or sender been deleted, no need to pass it further */
  67. goto out;
  68. }
  69. if (nf->direction == NET_FILTER_DIRECTION_ALL) {
  70. if (sender == nf->netdev) {
  71. /* This packet is sent by netdev itself */
  72. direction = NET_FILTER_DIRECTION_TX;
  73. } else {
  74. direction = NET_FILTER_DIRECTION_RX;
  75. }
  76. } else {
  77. direction = nf->direction;
  78. }
  79. next = netfilter_next(nf, direction);
  80. while (next) {
  81. /*
  82. * if qemu_netfilter_pass_to_next has been called, it means that
  83. * the packet was held by a filter and has already returned size
  84. * to the sender, so sent_cb shouldn't be called later, just
  85. * pass NULL to next.
  86. */
  87. ret = qemu_netfilter_receive(next, direction, sender, flags, iov,
  88. iovcnt, NULL);
  89. if (ret) {
  90. return ret;
  91. }
  92. next = netfilter_next(next, direction);
  93. }
  94. /*
  95. * We have gone through all filters, pass it to receiver.
  96. * Do the valid check again in case sender or receiver been
  97. * deleted while we go through filters.
  98. */
  99. if (sender && sender->peer) {
  100. qemu_net_queue_send_iov(sender->peer->incoming_queue,
  101. sender, flags, iov, iovcnt, NULL);
  102. }
  103. out:
  104. /* no receiver, or sender been deleted */
  105. return iov_size(iov, iovcnt);
  106. }
  107. static char *netfilter_get_netdev_id(Object *obj, Error **errp)
  108. {
  109. NetFilterState *nf = NETFILTER(obj);
  110. return g_strdup(nf->netdev_id);
  111. }
  112. static void netfilter_set_netdev_id(Object *obj, const char *str, Error **errp)
  113. {
  114. NetFilterState *nf = NETFILTER(obj);
  115. nf->netdev_id = g_strdup(str);
  116. }
  117. static int netfilter_get_direction(Object *obj, Error **errp G_GNUC_UNUSED)
  118. {
  119. NetFilterState *nf = NETFILTER(obj);
  120. return nf->direction;
  121. }
  122. static void netfilter_set_direction(Object *obj, int direction, Error **errp)
  123. {
  124. NetFilterState *nf = NETFILTER(obj);
  125. nf->direction = direction;
  126. }
  127. static char *netfilter_get_status(Object *obj, Error **errp)
  128. {
  129. NetFilterState *nf = NETFILTER(obj);
  130. return nf->on ? g_strdup("on") : g_strdup("off");
  131. }
  132. static void netfilter_set_status(Object *obj, const char *str, Error **errp)
  133. {
  134. NetFilterState *nf = NETFILTER(obj);
  135. NetFilterClass *nfc = NETFILTER_GET_CLASS(obj);
  136. if (strcmp(str, "on") && strcmp(str, "off")) {
  137. error_setg(errp, "Invalid value for netfilter status, "
  138. "should be 'on' or 'off'");
  139. return;
  140. }
  141. if (nf->on == !strcmp(str, "on")) {
  142. return;
  143. }
  144. nf->on = !nf->on;
  145. if (nf->netdev && nfc->status_changed) {
  146. nfc->status_changed(nf, errp);
  147. }
  148. }
  149. static char *netfilter_get_position(Object *obj, Error **errp)
  150. {
  151. NetFilterState *nf = NETFILTER(obj);
  152. return g_strdup(nf->position);
  153. }
  154. static void netfilter_set_position(Object *obj, const char *str, Error **errp)
  155. {
  156. NetFilterState *nf = NETFILTER(obj);
  157. nf->position = g_strdup(str);
  158. }
  159. static char *netfilter_get_insert(Object *obj, Error **errp)
  160. {
  161. NetFilterState *nf = NETFILTER(obj);
  162. return nf->insert_before_flag ? g_strdup("before") : g_strdup("behind");
  163. }
  164. static void netfilter_set_insert(Object *obj, const char *str, Error **errp)
  165. {
  166. NetFilterState *nf = NETFILTER(obj);
  167. if (strcmp(str, "before") && strcmp(str, "behind")) {
  168. error_setg(errp, "Invalid value for netfilter insert, "
  169. "should be 'before' or 'behind'");
  170. return;
  171. }
  172. nf->insert_before_flag = !strcmp(str, "before");
  173. }
  174. static void netfilter_init(Object *obj)
  175. {
  176. NetFilterState *nf = NETFILTER(obj);
  177. nf->on = true;
  178. nf->insert_before_flag = false;
  179. nf->position = g_strdup("tail");
  180. }
  181. static void netfilter_complete(UserCreatable *uc, Error **errp)
  182. {
  183. NetFilterState *nf = NETFILTER(uc);
  184. NetFilterState *position = NULL;
  185. NetClientState *ncs[MAX_QUEUE_NUM];
  186. NetFilterClass *nfc = NETFILTER_GET_CLASS(uc);
  187. int queues;
  188. Error *local_err = NULL;
  189. if (!nf->netdev_id) {
  190. error_setg(errp, "Parameter 'netdev' is required");
  191. return;
  192. }
  193. queues = qemu_find_net_clients_except(nf->netdev_id, ncs,
  194. NET_CLIENT_DRIVER_NIC,
  195. MAX_QUEUE_NUM);
  196. if (queues < 1) {
  197. error_setg(errp, QERR_INVALID_PARAMETER_VALUE, "netdev",
  198. "a network backend id");
  199. return;
  200. } else if (queues > 1) {
  201. error_setg(errp, "multiqueue is not supported");
  202. return;
  203. }
  204. if (get_vhost_net(ncs[0])) {
  205. error_setg(errp, "Vhost is not supported");
  206. return;
  207. }
  208. if (strcmp(nf->position, "head") && strcmp(nf->position, "tail")) {
  209. Object *container;
  210. Object *obj;
  211. char *position_id;
  212. if (!g_str_has_prefix(nf->position, "id=")) {
  213. error_setg(errp, QERR_INVALID_PARAMETER_VALUE, "position",
  214. "'head', 'tail' or 'id=<id>'");
  215. return;
  216. }
  217. /* get the id from the string */
  218. position_id = g_strndup(nf->position + 3, strlen(nf->position) - 3);
  219. /* Search for the position to insert before/behind */
  220. container = object_get_objects_root();
  221. obj = object_resolve_path_component(container, position_id);
  222. if (!obj) {
  223. error_setg(errp, "filter '%s' not found", position_id);
  224. g_free(position_id);
  225. return;
  226. }
  227. position = NETFILTER(obj);
  228. if (position->netdev != ncs[0]) {
  229. error_setg(errp, "filter '%s' belongs to a different netdev",
  230. position_id);
  231. g_free(position_id);
  232. return;
  233. }
  234. g_free(position_id);
  235. }
  236. nf->netdev = ncs[0];
  237. if (nfc->setup) {
  238. nfc->setup(nf, &local_err);
  239. if (local_err) {
  240. error_propagate(errp, local_err);
  241. return;
  242. }
  243. }
  244. if (position) {
  245. if (nf->insert_before_flag) {
  246. QTAILQ_INSERT_BEFORE(position, nf, next);
  247. } else {
  248. QTAILQ_INSERT_AFTER(&nf->netdev->filters, position, nf, next);
  249. }
  250. } else if (!strcmp(nf->position, "head")) {
  251. QTAILQ_INSERT_HEAD(&nf->netdev->filters, nf, next);
  252. } else if (!strcmp(nf->position, "tail")) {
  253. QTAILQ_INSERT_TAIL(&nf->netdev->filters, nf, next);
  254. }
  255. }
  256. static void netfilter_finalize(Object *obj)
  257. {
  258. NetFilterState *nf = NETFILTER(obj);
  259. NetFilterClass *nfc = NETFILTER_GET_CLASS(obj);
  260. if (nfc->cleanup) {
  261. nfc->cleanup(nf);
  262. }
  263. if (nf->netdev && !QTAILQ_EMPTY(&nf->netdev->filters) &&
  264. QTAILQ_IN_USE(nf, next)) {
  265. QTAILQ_REMOVE(&nf->netdev->filters, nf, next);
  266. }
  267. g_free(nf->netdev_id);
  268. g_free(nf->position);
  269. }
  270. static void default_handle_event(NetFilterState *nf, int event, Error **errp)
  271. {
  272. switch (event) {
  273. case COLO_EVENT_CHECKPOINT:
  274. break;
  275. case COLO_EVENT_FAILOVER:
  276. object_property_set_str(OBJECT(nf), "status", "off", errp);
  277. break;
  278. default:
  279. break;
  280. }
  281. }
  282. static void netfilter_class_init(ObjectClass *oc, void *data)
  283. {
  284. UserCreatableClass *ucc = USER_CREATABLE_CLASS(oc);
  285. NetFilterClass *nfc = NETFILTER_CLASS(oc);
  286. object_class_property_add_str(oc, "netdev",
  287. netfilter_get_netdev_id, netfilter_set_netdev_id);
  288. object_class_property_add_enum(oc, "queue", "NetFilterDirection",
  289. &NetFilterDirection_lookup,
  290. netfilter_get_direction, netfilter_set_direction);
  291. object_class_property_add_str(oc, "status",
  292. netfilter_get_status, netfilter_set_status);
  293. object_class_property_add_str(oc, "position",
  294. netfilter_get_position, netfilter_set_position);
  295. object_class_property_add_str(oc, "insert",
  296. netfilter_get_insert, netfilter_set_insert);
  297. ucc->complete = netfilter_complete;
  298. nfc->handle_event = default_handle_event;
  299. }
  300. static const TypeInfo netfilter_info = {
  301. .name = TYPE_NETFILTER,
  302. .parent = TYPE_OBJECT,
  303. .abstract = true,
  304. .class_size = sizeof(NetFilterClass),
  305. .class_init = netfilter_class_init,
  306. .instance_size = sizeof(NetFilterState),
  307. .instance_init = netfilter_init,
  308. .instance_finalize = netfilter_finalize,
  309. .interfaces = (InterfaceInfo[]) {
  310. { TYPE_USER_CREATABLE },
  311. { }
  312. }
  313. };
  314. static void register_types(void)
  315. {
  316. type_register_static(&netfilter_info);
  317. }
  318. type_init(register_types);