lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date:   Mon, 22 Jun 2020 15:56:16 +0100
From:   Paul Durrant <xadimgnik@...il.com>
To:     "'Denis Kirjanov'" <kda@...ux-powerpc.org>
Cc:     <netdev@...r.kernel.org>, <brouer@...hat.com>, <jgross@...e.com>,
        <wei.liu@...nel.org>, <ilias.apalodimas@...aro.org>
Subject: RE: [PATCH net-next v10 3/3] xen networking: add XDP offset adjustment to xen-netback

> -----Original Message-----
> From: Denis Kirjanov <kda@...ux-powerpc.org>
> Sent: 22 June 2020 13:51
> To: paul@....org
> Cc: netdev@...r.kernel.org; brouer@...hat.com; jgross@...e.com; wei.liu@...nel.org;
> ilias.apalodimas@...aro.org
> Subject: Re: [PATCH net-next v10 3/3] xen networking: add XDP offset adjustment to xen-netback
> 
> On 6/22/20, Paul Durrant <xadimgnik@...il.com> wrote:
> >> -----Original Message-----
> >> From: Denis Kirjanov <kda@...ux-powerpc.org>
> >> Sent: 22 June 2020 10:21
> >> To: netdev@...r.kernel.org
> >> Cc: brouer@...hat.com; jgross@...e.com; wei.liu@...nel.org; paul@....org;
> >> ilias.apalodimas@...aro.org
> >> Subject: [PATCH net-next v10 3/3] xen networking: add XDP offset
> >> adjustment to xen-netback
> >>
> >> the patch basically adds the offset adjustment and netfront
> >> state reading to make XDP work on netfront side.
> >>
> >> Signed-off-by: Denis Kirjanov <kda@...ux-powerpc.org>
> >> ---
> >>  drivers/net/xen-netback/common.h    |  4 ++++
> >>  drivers/net/xen-netback/interface.c |  2 ++
> >>  drivers/net/xen-netback/netback.c   |  7 +++++++
> >>  drivers/net/xen-netback/rx.c        | 15 ++++++++++++++-
> >>  drivers/net/xen-netback/xenbus.c    | 32
> >> ++++++++++++++++++++++++++++++++
> >>  5 files changed, 59 insertions(+), 1 deletion(-)
> >>
> >> diff --git a/drivers/net/xen-netback/common.h
> >> b/drivers/net/xen-netback/common.h
> >> index 05847eb..f14dc10 100644
> >> --- a/drivers/net/xen-netback/common.h
> >> +++ b/drivers/net/xen-netback/common.h
> >> @@ -281,6 +281,9 @@ struct xenvif {
> >>  	u8 ipv6_csum:1;
> >>  	u8 multicast_control:1;
> >>
> >> +	/* headroom requested by xen-netfront */
> >> +	u16 netfront_xdp_headroom;
> >> +
> >>  	/* Is this interface disabled? True when backend discovers
> >>  	 * frontend is rogue.
> >>  	 */
> >> @@ -395,6 +398,7 @@ static inline pending_ring_idx_t
> >> nr_pending_reqs(struct xenvif_queue *queue)
> >>  irqreturn_t xenvif_interrupt(int irq, void *dev_id);
> >>
> >>  extern bool separate_tx_rx_irq;
> >> +extern bool provides_xdp_headroom;
> >>
> >>  extern unsigned int rx_drain_timeout_msecs;
> >>  extern unsigned int rx_stall_timeout_msecs;
> >> diff --git a/drivers/net/xen-netback/interface.c
> >> b/drivers/net/xen-netback/interface.c
> >> index 0c8a02a..fc16edd 100644
> >> --- a/drivers/net/xen-netback/interface.c
> >> +++ b/drivers/net/xen-netback/interface.c
> >> @@ -483,6 +483,8 @@ struct xenvif *xenvif_alloc(struct device *parent,
> >> domid_t domid,
> >>  	vif->queues = NULL;
> >>  	vif->num_queues = 0;
> >>
> >> +	vif->netfront_xdp_headroom = 0;
> >> +
> >
> Hi Paul,
> 
> > How about just 'xdp_headroom'? It's shorter to type :-)
> 
> makes sense.
> 
> >
> >>  	spin_lock_init(&vif->lock);
> >>  	INIT_LIST_HEAD(&vif->fe_mcast_addr);
> >>
> >> diff --git a/drivers/net/xen-netback/netback.c
> >> b/drivers/net/xen-netback/netback.c
> >> index 315dfc6..6dfca72 100644
> >> --- a/drivers/net/xen-netback/netback.c
> >> +++ b/drivers/net/xen-netback/netback.c
> >> @@ -96,6 +96,13 @@
> >>  module_param_named(hash_cache_size, xenvif_hash_cache_size, uint, 0644);
> >>  MODULE_PARM_DESC(hash_cache_size, "Number of flows in the hash cache");
> >>
> >> +/* The module parameter tells that we have to put data
> >> + * for xen-netfront with the XDP_PACKET_HEADROOM offset
> >> + * needed for XDP processing
> >> + */
> >> +bool provides_xdp_headroom = true;
> >> +module_param(provides_xdp_headroom, bool, 0644);
> >> +
> >>  static void xenvif_idx_release(struct xenvif_queue *queue, u16
> >> pending_idx,
> >>  			       u8 status);
> >>
> >> diff --git a/drivers/net/xen-netback/rx.c b/drivers/net/xen-netback/rx.c
> >> index ef58870..c5e9e14 100644
> >> --- a/drivers/net/xen-netback/rx.c
> >> +++ b/drivers/net/xen-netback/rx.c
> >> @@ -258,6 +258,19 @@ static void xenvif_rx_next_skb(struct xenvif_queue
> >> *queue,
> >>  		pkt->extra_count++;
> >>  	}
> >>
> >> +	if (queue->vif->netfront_xdp_headroom) {
> >> +		struct xen_netif_extra_info *extra;
> >> +
> >> +		extra = &pkt->extras[XEN_NETIF_EXTRA_TYPE_XDP - 1];
> >> +
> >> +		memset(extra, 0, sizeof(struct xen_netif_extra_info));
> >> +		extra->u.xdp.headroom = queue->vif->netfront_xdp_headroom;
> >> +		extra->type = XEN_NETIF_EXTRA_TYPE_XDP;
> >> +		extra->flags = 0;
> >> +
> >> +		pkt->extra_count++;
> >> +	}
> >> +
> >>  	if (skb->sw_hash) {
> >>  		struct xen_netif_extra_info *extra;
> >>
> >> @@ -356,7 +369,7 @@ static void xenvif_rx_data_slot(struct xenvif_queue
> >> *queue,
> >>  				struct xen_netif_rx_request *req,
> >>  				struct xen_netif_rx_response *rsp)
> >>  {
> >> -	unsigned int offset = 0;
> >> +	unsigned int offset = queue->vif->netfront_xdp_headroom;
> >>  	unsigned int flags;
> >>
> >>  	do {
> >> diff --git a/drivers/net/xen-netback/xenbus.c
> >> b/drivers/net/xen-netback/xenbus.c
> >> index 286054b..c67abc5 100644
> >> --- a/drivers/net/xen-netback/xenbus.c
> >> +++ b/drivers/net/xen-netback/xenbus.c
> >> @@ -393,6 +393,22 @@ static void set_backend_state(struct backend_info
> >> *be,
> >>  	}
> >>  }
> >>
> >> +static void read_xenbus_frontend_xdp(struct backend_info *be,
> >> +				      struct xenbus_device *dev)
> >> +{
> >> +	struct xenvif *vif = be->vif;
> >> +	u16 headroom;
> >> +	int err;
> >> +
> >> +	err = xenbus_scanf(XBT_NIL, dev->otherend,
> >> +			   "netfront-xdp-headroom", "%hu", &headroom);
> >
> > Isn't it just "xdp-headroom"? That's what the comments in netif.h state.
> >
> >> +	if (err < 0) {
> >> +		vif->netfront_xdp_headroom = 0;
> >> +		return;
> >> +	}
> >
> > What is a reasonable value for maximum headroom? Do we really want to allow
> > values all the way up to 65535?
> 
> Since the headroom is used for encapsulation I think we definitely
> don't need more than 65535
> but more that 255

Ok, I suggest documenting (and defining) the max in netif.h then and then sanity checking it here. Also I just noticed that your check on xenbus_scanf's return value is not correct since its return semantics are the same as for normal scanf(3).

  Paul

> 
> 
> >
> >   Paul
> >
> >> +	vif->netfront_xdp_headroom = headroom;
> >> +}
> >> +
> >>  /**
> >>   * Callback received when the frontend's state changes.
> >>   */
> >> @@ -417,6 +433,11 @@ static void frontend_changed(struct xenbus_device
> >> *dev,
> >>  		set_backend_state(be, XenbusStateConnected);
> >>  		break;
> >>
> >> +	case XenbusStateReconfiguring:
> >> +		read_xenbus_frontend_xdp(be, dev);
> >> +		xenbus_switch_state(dev, XenbusStateReconfigured);
> >> +		break;
> >> +
> >>  	case XenbusStateClosing:
> >>  		set_backend_state(be, XenbusStateClosing);
> >>  		break;
> >> @@ -947,6 +968,8 @@ static int read_xenbus_vif_flags(struct backend_info
> >> *be)
> >>  	vif->ipv6_csum = !!xenbus_read_unsigned(dev->otherend,
> >>  						"feature-ipv6-csum-offload", 0);
> >>
> >> +	read_xenbus_frontend_xdp(be, dev);
> >> +
> >>  	return 0;
> >>  }
> >>
> >> @@ -1036,6 +1059,15 @@ static int netback_probe(struct xenbus_device
> >> *dev,
> >>  			goto abort_transaction;
> >>  		}
> >>
> >> +		/* we can adjust a headroom for netfront XDP processing */
> >> +		err = xenbus_printf(xbt, dev->nodename,
> >> +				    "feature-xdp-headroom", "%d",
> >> +				    provides_xdp_headroom);
> >> +		if (err) {
> >> +			message = "writing feature-xdp-headroom";
> >> +			goto abort_transaction;
> >> +		}
> >> +
> >>  		/* We don't support rx-flip path (except old guests who
> >>  		 * don't grok this feature flag).
> >>  		 */
> >> --
> >> 1.8.3.1
> >
> >
> >

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ