From nobody Thu Sep 18 08:14:49 2025 Delivered-To: wpasupplicant.patchew@gmail.com Received: by 2002:a05:6a06:869:b0:4b8:7781:bd2f with SMTP id d41csp2574809pis; Fri, 29 Apr 2022 15:02:26 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxrrjRR65wcqsHYHBWrsPaq6s0Umvf1gQve1Y5RLaOA699oEgMp3x5jbYLxfyzc3Kqw2TOn X-Received: by 2002:a05:6808:1402:b0:325:c27:9a6b with SMTP id w2-20020a056808140200b003250c279a6bmr686265oiv.143.1651269745916; Fri, 29 Apr 2022 15:02:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1651269745; cv=none; d=google.com; s=arc-20160816; b=SipRkEXyubIR0NsVS25dhTFaEdL/JzIbAqrGuwc9rFIJCxHUM5+X7uDzmjUqC61nbu 7rsG2A+xy8lJ1jOJa2gM664Fb0S8V6ZK61p6GlkV+7PfIKGdVFyGbcmzDeuzR469fiPZ /99J6zPJ8LKhs/DEtzJbOitE34bmi25pnYWMDNQtbERqTxhuP3g1ARK4CQFhrChev6nY sZvmQwpubw/CmNaz6ZvJYhYgaZ2TQCdK6qOZcVRUKu6igzp50kwPo6SJSSJ9X/SAf7Ll pvMaVRPENTaPX9Qcsf6/sv7/t4enadIqVlMmsaNrncsGKot6Fk55pxGJwpMuSLLZzThE R8Rg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature; bh=CKZhxK0kn9BiyX3NzrmPxllUslXKUkItIBA2lzlAqmQ=; b=Qtms1ReSACPjPBoOVpHllbHfk8JiLJbedo7EsD3vt4PDOvnY+L2s3tGLxLF8djJJgb iqu9h+PALbUXf9k05zJg7o+01BHn5LIFkxonum9TtyIbzszdoRr04PyaBahbvUILVmSf ++/zgPzBsSgF7eWC/lNWqNAWUFZhjTPoH+405rdCJ/aPTxTyf7Pxg3DdarU4fsYEu0RW WUvo38Db1RajxJ2RvkFb2Evm9O47IK/v62Jx4Lyd7qBOlTAnk71XbGAMz4lsx9IjBiGI 8CNJcf8yECjOhmPSvBG8SzUJtIR8UpGuFI+KL+V0a/eP9w0wz32/MIuPw9JiBca3aCu+ 3BZA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=JzmsVuDW; spf=pass (google.com: domain of mptcp+bounces-4979-wpasupplicant.patchew=gmail.com@lists.linux.dev designates 2604:1380:4040:4f00::1 as permitted sender) smtp.mailfrom="mptcp+bounces-4979-wpasupplicant.patchew=gmail.com@lists.linux.dev"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from da.mirrors.kernel.org (da.mirrors.kernel.org. [2604:1380:4040:4f00::1]) by mx.google.com with ESMTPS id eq24-20020a056870a91800b000da7476563esi4974462oab.303.2022.04.29.15.02.25 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 29 Apr 2022 15:02:25 -0700 (PDT) Received-SPF: pass (google.com: domain of mptcp+bounces-4979-wpasupplicant.patchew=gmail.com@lists.linux.dev designates 2604:1380:4040:4f00::1 as permitted sender) client-ip=2604:1380:4040:4f00::1; Authentication-Results: mx.google.com; dkim=pass header.i=@intel.com header.s=Intel header.b=JzmsVuDW; spf=pass (google.com: domain of mptcp+bounces-4979-wpasupplicant.patchew=gmail.com@lists.linux.dev designates 2604:1380:4040:4f00::1 as permitted sender) smtp.mailfrom="mptcp+bounces-4979-wpasupplicant.patchew=gmail.com@lists.linux.dev"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by da.mirrors.kernel.org (Postfix) with ESMTPS id 94B1D2E09E4 for ; Fri, 29 Apr 2022 22:02:25 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 8C7AB1FA8; Fri, 29 Apr 2022 22:02:24 +0000 (UTC) X-Original-To: mptcp@lists.linux.dev Received: from mga12.intel.com (mga12.intel.com [192.55.52.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 495981FA5 for ; Fri, 29 Apr 2022 22:02:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1651269743; x=1682805743; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=DlnszPk3X2RPEnjbzh3vP3TQq5DteMJxTVw6ps/Fp2w=; b=JzmsVuDWZlrZBcTleQv5Q9z3KZEnBDKvfAoZ+dnVFKydXk/KBFy3Y1FE FRHOJPWYKTxcsAlnKnW1Tux/ygzVrfCvp5zK8bstvaK1EyR8SbOFKRmoa gNAsn3b8izNSkM2DE+CwC17K6ZzIruvO+0hNT6CeT5PKlVPAfnPEXT+9G B9O9M51AAvYbmIKrXQ0A5v0oGOhausSeNibI8maIQ+wHkkakUIq5biAIm jaLRWD7B9uj84rxwH+cv5UNi72Y7gilqywpeyokNO6jyQqCbMFD80OGQg owupLTlJz4USbSgSc2pM3xPPEE9+pUtoat58FE9xNG09AmA/TE1rbGp+x w==; X-IronPort-AV: E=McAfee;i="6400,9594,10332"; a="246698322" X-IronPort-AV: E=Sophos;i="5.91,186,1647327600"; d="scan'208";a="246698322" Received: from orsmga008.jf.intel.com ([10.7.209.65]) by fmsmga106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Apr 2022 15:02:09 -0700 X-IronPort-AV: E=Sophos;i="5.91,186,1647327600"; d="scan'208";a="582419796" Received: from mjmartin-desk2.amr.corp.intel.com (HELO mjmartin-desk2.intel.com) ([10.212.217.201]) by orsmga008-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Apr 2022 15:02:09 -0700 From: Mat Martineau To: netdev@vger.kernel.org, bpf@vger.kernel.org Cc: Nicolas Rybowski , ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, mptcp@lists.linux.dev, Matthieu Baerts , Mat Martineau Subject: [PATCH bpf-next v2 1/8] bpf: expose is_mptcp flag to bpf_tcp_sock Date: Fri, 29 Apr 2022 15:01:57 -0700 Message-Id: <20220429220204.353225-2-mathew.j.martineau@linux.intel.com> X-Mailer: git-send-email 2.36.0 In-Reply-To: <20220429220204.353225-1-mathew.j.martineau@linux.intel.com> References: <20220429220204.353225-1-mathew.j.martineau@linux.intel.com> Precedence: bulk X-Mailing-List: mptcp@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Nicolas Rybowski is_mptcp is a field from struct tcp_sock used to indicate that the current tcp_sock is part of the MPTCP protocol. In this protocol, a first socket (mptcp_sock) is created with sk_protocol set to IPPROTO_MPTCP (=3D262) for control purpose but it isn't directly on the wire. This is the role of the subflow (kernel) sockets which are classical tcp_sock with sk_protocol set to IPPROTO_TCP. The only way to differentiate such sockets from plain TCP sockets is the is_mptcp field from tcp_sock. Such an exposure in BPF is thus required to be able to differentiate plain TCP sockets from MPTCP subflow sockets in BPF_PROG_TYPE_SOCK_OPS programs. The choice has been made to silently pass the case when CONFIG_MPTCP is unset by defaulting is_mptcp to 0 in order to make BPF independent of the MPTCP configuration. Another solution is to make the verifier fail in 'bpf_tcp_sock_is_valid_ctx_access' but this will add an additional '#ifdef CONFIG_MPTCP' in the BPF code and a same injected BPF program will not run if MPTCP is not set. An example use-case is provided in https://github.com/multipath-tcp/mptcp_net-next/tree/scripts/bpf/examples Suggested-by: Matthieu Baerts Acked-by: Matthieu Baerts Signed-off-by: Nicolas Rybowski Signed-off-by: Mat Martineau --- include/uapi/linux/bpf.h | 1 + net/core/filter.c | 9 ++++++++- tools/include/uapi/linux/bpf.h | 1 + 3 files changed, 10 insertions(+), 1 deletion(-) diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h index 444fe6f1cf35..7043f3641534 100644 --- a/include/uapi/linux/bpf.h +++ b/include/uapi/linux/bpf.h @@ -5706,6 +5706,7 @@ struct bpf_tcp_sock { __u32 delivered; /* Total data packets delivered incl. rexmits */ __u32 delivered_ce; /* Like the above but only ECE marked packets */ __u32 icsk_retransmits; /* Number of unrecovered [RTO] timeouts */ + __u32 is_mptcp; /* Is MPTCP subflow? */ }; =20 struct bpf_sock_tuple { diff --git a/net/core/filter.c b/net/core/filter.c index b741b9f7e6a9..b474e5bd1458 100644 --- a/net/core/filter.c +++ b/net/core/filter.c @@ -6754,7 +6754,7 @@ bool bpf_tcp_sock_is_valid_access(int off, int size, = enum bpf_access_type type, struct bpf_insn_access_aux *info) { if (off < 0 || off >=3D offsetofend(struct bpf_tcp_sock, - icsk_retransmits)) + is_mptcp)) return false; =20 if (off % size !=3D 0) @@ -6888,6 +6888,13 @@ u32 bpf_tcp_sock_convert_ctx_access(enum bpf_access_= type type, case offsetof(struct bpf_tcp_sock, icsk_retransmits): BPF_INET_SOCK_GET_COMMON(icsk_retransmits); break; + case offsetof(struct bpf_tcp_sock, is_mptcp): +#ifdef CONFIG_MPTCP + BPF_TCP_SOCK_GET_COMMON(is_mptcp); +#else + *insn++ =3D BPF_MOV32_IMM(si->dst_reg, 0); +#endif + break; } =20 return insn - insn_buf; diff --git a/tools/include/uapi/linux/bpf.h b/tools/include/uapi/linux/bpf.h index 444fe6f1cf35..7043f3641534 100644 --- a/tools/include/uapi/linux/bpf.h +++ b/tools/include/uapi/linux/bpf.h @@ -5706,6 +5706,7 @@ struct bpf_tcp_sock { __u32 delivered; /* Total data packets delivered incl. rexmits */ __u32 delivered_ce; /* Like the above but only ECE marked packets */ __u32 icsk_retransmits; /* Number of unrecovered [RTO] timeouts */ + __u32 is_mptcp; /* Is MPTCP subflow? */ }; =20 struct bpf_sock_tuple { --=20 2.36.0