[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <1524581430-11921-1-git-send-email-eyal.birger@gmail.com>
Date: Tue, 24 Apr 2018 17:50:28 +0300
From: Eyal Birger <eyal.birger@...il.com>
To: netdev@...r.kernel.org
Cc: shmulik@...anetworks.com, ast@...nel.org, daniel@...earbox.net,
Eyal Birger <eyal.birger@...il.com>
Subject: [PATCH bpf-next,v3 0/2] bpf: add helper for getting xfrm states
This patchset adds support for fetching XFRM state information from
an eBPF program called from TC.
The first patch introduces a helper for fetching an XFRM state from the
skb's secpath. The XFRM state is modeled using a new virtual struct which
contains the SPI, peer address, and reqid values of the state; This struct
can be extended in the future to provide additional state information.
The second patch adds a test example in test_tunnel_bpf.sh. The sample
validates the correct extraction of state information by the eBPF program.
---
v3:
- Kept SPI and peer IPv4 address in state in network byte order
following suggestion from Alexei Starovoitov
v2:
- Fixed two comments by Daniel Borkmann:
- disallow reserved flags in helper call
- avoid compiling in helper code when CONFIG_XFRM is off
Eyal Birger (2):
bpf: add helper for getting xfrm states
samples/bpf: extend test_tunnel_bpf.sh with xfrm state test
include/uapi/linux/bpf.h | 25 ++++++++++-
net/core/filter.c | 48 +++++++++++++++++++++
samples/bpf/tcbpf2_kern.c | 16 +++++++
samples/bpf/test_tunnel_bpf.sh | 71 +++++++++++++++++++++++++++++++
tools/include/uapi/linux/bpf.h | 25 ++++++++++-
tools/testing/selftests/bpf/bpf_helpers.h | 4 +-
6 files changed, 186 insertions(+), 3 deletions(-)
--
2.7.4
Powered by blists - more mailing lists