From patchwork Wed Jul 29 10:51:49 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yang Hongyang X-Patchwork-Id: 501650 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 64D0614028F for ; Wed, 29 Jul 2015 20:59:10 +1000 (AEST) Received: from localhost ([::1]:34528 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZKP4m-00082q-LF for incoming@patchwork.ozlabs.org; Wed, 29 Jul 2015 06:59:08 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:50889) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZKP4I-00077V-UI for qemu-devel@nongnu.org; Wed, 29 Jul 2015 06:58:40 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ZKP4H-0000r0-QA for qemu-devel@nongnu.org; Wed, 29 Jul 2015 06:58:38 -0400 Received: from [59.151.112.132] (port=37030 helo=heian.cn.fujitsu.com) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZKP4F-0000pA-Ei for qemu-devel@nongnu.org; Wed, 29 Jul 2015 06:58:37 -0400 X-IronPort-AV: E=Sophos;i="5.15,520,1432569600"; d="scan'208";a="99029569" Received: from unknown (HELO edo.cn.fujitsu.com) ([10.167.33.5]) by heian.cn.fujitsu.com with ESMTP; 29 Jul 2015 18:55:42 +0800 Received: from G08CNEXCHPEKD01.g08.fujitsu.local (localhost.localdomain [127.0.0.1]) by edo.cn.fujitsu.com (8.14.3/8.13.1) with ESMTP id t6TAoGwi019120; Wed, 29 Jul 2015 18:50:16 +0800 Received: from localhost (10.167.226.223) by G08CNEXCHPEKD01.g08.fujitsu.local (10.167.33.89) with Microsoft SMTP Server (TLS) id 14.3.181.6; Wed, 29 Jul 2015 18:52:07 +0800 From: Yang Hongyang To: Date: Wed, 29 Jul 2015 18:51:49 +0800 Message-ID: <1438167116-29270-6-git-send-email-yanghy@cn.fujitsu.com> X-Mailer: git-send-email 1.9.1 In-Reply-To: <1438167116-29270-1-git-send-email-yanghy@cn.fujitsu.com> References: <1438167116-29270-1-git-send-email-yanghy@cn.fujitsu.com> MIME-Version: 1.0 X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 59.151.112.132 Cc: thuth@redhat.com, zhang.zhanghailiang@huawei.com, jasowang@redhat.com, mrhines@linux.vnet.ibm.com, stefanha@redhat.com, Yang Hongyang Subject: [Qemu-devel] [PATCH 05/12] netfilter: hook packets before receive X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org Sender: qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org Capture packets that will be sent. Signed-off-by: Yang Hongyang --- include/net/filter.h | 16 +++++++++++++ net/net.c | 65 +++++++++++++++++++++++++++++++++++++++++++++++++++- 2 files changed, 80 insertions(+), 1 deletion(-) diff --git a/include/net/filter.h b/include/net/filter.h index 1dd86cf..5292563 100644 --- a/include/net/filter.h +++ b/include/net/filter.h @@ -12,11 +12,27 @@ #include "qemu/typedefs.h" typedef void (FilterCleanup) (NetFilterState *); +/* + * Return: + * 0: finished handling the packet, we should continue + * size: filter stolen this packet, we stop pass this packet further + */ +typedef ssize_t (FilterReceive)(NetFilterState *, NetClientState *sender, + unsigned flags, const uint8_t *, size_t); +/* + * Return: + * 0: finished handling the packet, we should continue + * size: filter stolen this packet, we stop pass this packet further + */ +typedef ssize_t (FilterReceiveIOV)(NetFilterState *, NetClientState *sender, + unsigned flags, const struct iovec *, int); typedef struct NetFilterInfo { NetFilterOptionsKind type; size_t size; FilterCleanup *cleanup; + FilterReceive *receive; + FilterReceiveIOV *receive_iov; } NetFilterInfo; struct NetFilterState { diff --git a/net/net.c b/net/net.c index 22748e0..e4c822c 100644 --- a/net/net.c +++ b/net/net.c @@ -24,6 +24,7 @@ #include "config-host.h" #include "net/net.h" +#include "net/filter.h" #include "clients.h" #include "hub.h" #include "net/slirp.h" @@ -592,6 +593,25 @@ int qemu_can_send_packet(NetClientState *sender) return 1; } +static ssize_t filter_receive(NetClientState *nc, NetClientState *sender, + unsigned flags, + const uint8_t *data, + size_t size) { + ssize_t ret = 0; + Filter *filter = NULL; + NetFilterState *nf = NULL; + + QTAILQ_FOREACH(filter, &nc->filters, next) { + nf = filter->nf; + ret = nf->info->receive(nf, sender, flags, data, size); + if (ret == size) { + return ret; + } + } + + return ret; +} + ssize_t qemu_deliver_packet(NetClientState *sender, unsigned flags, const uint8_t *data, @@ -609,6 +629,17 @@ ssize_t qemu_deliver_packet(NetClientState *sender, return 0; } + /* Let filters handle the packet first */ + ret = filter_receive(sender, sender, flags, data, size); + if (ret == size) { + return size; + } + + ret = filter_receive(nc, sender, flags, data, size); + if (ret == size) { + return size; + } + if (flags & QEMU_NET_PACKET_FLAG_RAW && nc->info->receive_raw) { ret = nc->info->receive_raw(nc, data, size); } else { @@ -697,6 +728,26 @@ ssize_t qemu_send_packet_raw(NetClientState *nc, const uint8_t *buf, int size) buf, size, NULL); } +static ssize_t filter_receive_iov(NetClientState *nc, NetClientState *sender, + unsigned flags, + const struct iovec *iov, + int iovcnt) { + ssize_t ret = 0; + Filter *filter = NULL; + NetFilterState *nf = NULL; + ssize_t size = iov_size(iov, iovcnt); + + QTAILQ_FOREACH(filter, &nc->filters, next) { + nf = filter->nf; + ret = nf->info->receive_iov(nf, sender, flags, iov, iovcnt); + if (ret == size) { + return ret; + } + } + + return ret; +} + static ssize_t nc_sendv_compat(NetClientState *nc, const struct iovec *iov, int iovcnt) { @@ -716,15 +767,27 @@ ssize_t qemu_deliver_packet_iov(NetClientState *sender, { NetClientState *nc = opaque; int ret; + ssize_t size = iov_size(iov, iovcnt); if (nc->link_down) { - return iov_size(iov, iovcnt); + return size; } if (nc->receive_disabled) { return 0; } + /* Let filters handle the packet first */ + ret = filter_receive_iov(sender, sender, flags, iov, iovcnt); + if (ret == size) { + return size; + } + + ret = filter_receive_iov(nc, sender, flags, iov, iovcnt); + if (ret == size) { + return size; + } + if (nc->info->receive_iov) { ret = nc->info->receive_iov(nc, iov, iovcnt); } else {