bpf: net_sched: Add basic bpf qdisc kfuncs

Add basic kfuncs for working on skb in qdisc.

Both bpf_qdisc_skb_drop() and bpf_kfree_skb() can be used to release
a reference to an skb. However, bpf_qdisc_skb_drop() can only be called
in .enqueue where a to_free skb list is available from kernel to defer
the release. bpf_kfree_skb() should be used elsewhere. It is also used
in bpf_obj_free_fields() when cleaning up skb in maps and collections.

bpf_skb_get_hash() returns the flow hash of an skb, which can be used
to build flow-based queueing algorithms.

Finally, allow users to create read-only dynptr via bpf_dynptr_from_skb().

Signed-off-by: Amery Hung <amery.hung@bytedance.com>
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
Acked-by: Toke Høiland-Jørgensen <toke@redhat.com>
Link: https://patch.msgid.link/20250409214606.2000194-4-ameryhung@gmail.com
This commit is contained in:
Amery Hung 2025-04-09 14:45:59 -07:00 committed by Martin KaFai Lau
parent c824034495
commit 870c28588a

View File

@ -8,6 +8,9 @@
#include <net/pkt_sched.h>
#include <net/pkt_cls.h>
#define QDISC_OP_IDX(op) (offsetof(struct Qdisc_ops, op) / sizeof(void (*)(void)))
#define QDISC_MOFF_IDX(moff) (moff / sizeof(void (*)(void)))
static struct bpf_struct_ops bpf_Qdisc_ops;
struct bpf_sk_buff_ptr {
@ -123,6 +126,95 @@ static int bpf_qdisc_btf_struct_access(struct bpf_verifier_log *log,
return 0;
}
__bpf_kfunc_start_defs();
/* bpf_skb_get_hash - Get the flow hash of an skb.
* @skb: The skb to get the flow hash from.
*/
__bpf_kfunc u32 bpf_skb_get_hash(struct sk_buff *skb)
{
return skb_get_hash(skb);
}
/* bpf_kfree_skb - Release an skb's reference and drop it immediately.
* @skb: The skb whose reference to be released and dropped.
*/
__bpf_kfunc void bpf_kfree_skb(struct sk_buff *skb)
{
kfree_skb(skb);
}
/* bpf_qdisc_skb_drop - Drop an skb by adding it to a deferred free list.
* @skb: The skb whose reference to be released and dropped.
* @to_free_list: The list of skbs to be dropped.
*/
__bpf_kfunc void bpf_qdisc_skb_drop(struct sk_buff *skb,
struct bpf_sk_buff_ptr *to_free_list)
{
__qdisc_drop(skb, (struct sk_buff **)to_free_list);
}
__bpf_kfunc_end_defs();
BTF_KFUNCS_START(qdisc_kfunc_ids)
BTF_ID_FLAGS(func, bpf_skb_get_hash, KF_TRUSTED_ARGS)
BTF_ID_FLAGS(func, bpf_kfree_skb, KF_RELEASE)
BTF_ID_FLAGS(func, bpf_qdisc_skb_drop, KF_RELEASE)
BTF_ID_FLAGS(func, bpf_dynptr_from_skb, KF_TRUSTED_ARGS)
BTF_KFUNCS_END(qdisc_kfunc_ids)
BTF_SET_START(qdisc_common_kfunc_set)
BTF_ID(func, bpf_skb_get_hash)
BTF_ID(func, bpf_kfree_skb)
BTF_ID(func, bpf_dynptr_from_skb)
BTF_SET_END(qdisc_common_kfunc_set)
BTF_SET_START(qdisc_enqueue_kfunc_set)
BTF_ID(func, bpf_qdisc_skb_drop)
BTF_SET_END(qdisc_enqueue_kfunc_set)
enum qdisc_ops_kf_flags {
QDISC_OPS_KF_COMMON = 0,
QDISC_OPS_KF_ENQUEUE = 1 << 0,
};
static const u32 qdisc_ops_context_flags[] = {
[QDISC_OP_IDX(enqueue)] = QDISC_OPS_KF_ENQUEUE,
[QDISC_OP_IDX(dequeue)] = QDISC_OPS_KF_COMMON,
[QDISC_OP_IDX(init)] = QDISC_OPS_KF_COMMON,
[QDISC_OP_IDX(reset)] = QDISC_OPS_KF_COMMON,
[QDISC_OP_IDX(destroy)] = QDISC_OPS_KF_COMMON,
};
static int bpf_qdisc_kfunc_filter(const struct bpf_prog *prog, u32 kfunc_id)
{
u32 moff, flags;
if (!btf_id_set8_contains(&qdisc_kfunc_ids, kfunc_id))
return 0;
if (prog->aux->st_ops != &bpf_Qdisc_ops)
return -EACCES;
moff = prog->aux->attach_st_ops_member_off;
flags = qdisc_ops_context_flags[QDISC_MOFF_IDX(moff)];
if ((flags & QDISC_OPS_KF_ENQUEUE) &&
btf_id_set_contains(&qdisc_enqueue_kfunc_set, kfunc_id))
return 0;
if (btf_id_set_contains(&qdisc_common_kfunc_set, kfunc_id))
return 0;
return -EACCES;
}
static const struct btf_kfunc_id_set bpf_qdisc_kfunc_set = {
.owner = THIS_MODULE,
.set = &qdisc_kfunc_ids,
.filter = bpf_qdisc_kfunc_filter,
};
static const struct bpf_verifier_ops bpf_qdisc_verifier_ops = {
.get_func_proto = bpf_base_func_proto,
.is_valid_access = bpf_qdisc_is_valid_access,
@ -209,8 +301,25 @@ static struct bpf_struct_ops bpf_Qdisc_ops = {
.owner = THIS_MODULE,
};
BTF_ID_LIST(bpf_sk_buff_dtor_ids)
BTF_ID(func, bpf_kfree_skb)
static int __init bpf_qdisc_kfunc_init(void)
{
return register_bpf_struct_ops(&bpf_Qdisc_ops, Qdisc_ops);
int ret;
const struct btf_id_dtor_kfunc skb_kfunc_dtors[] = {
{
.btf_id = bpf_sk_buff_ids[0],
.kfunc_btf_id = bpf_sk_buff_dtor_ids[0]
},
};
ret = register_btf_kfunc_id_set(BPF_PROG_TYPE_STRUCT_OPS, &bpf_qdisc_kfunc_set);
ret = ret ?: register_btf_id_dtor_kfuncs(skb_kfunc_dtors,
ARRAY_SIZE(skb_kfunc_dtors),
THIS_MODULE);
ret = ret ?: register_bpf_struct_ops(&bpf_Qdisc_ops, Qdisc_ops);
return ret;
}
late_initcall(bpf_qdisc_kfunc_init);