net: filter: split filter.h and expose eBPF to user space
allow user space to generate eBPF programs uapi/linux/bpf.h: eBPF instruction set definition linux/filter.h: the rest This patch only moves macro definitions, but practically it freezes existing eBPF instruction set, though new instructions can still be added in the future. These eBPF definitions cannot go into uapi/linux/filter.h, since the names may conflict with existing applications. Full eBPF ISA description is in Documentation/networking/filter.txt Signed-off-by: Alexei Starovoitov <ast@plumgrid.com> Acked-by: Daniel Borkmann <dborkman@redhat.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
02ab695bb3
commit
daedfb2245
|
@ -10,58 +10,12 @@
|
||||||
#include <linux/workqueue.h>
|
#include <linux/workqueue.h>
|
||||||
#include <uapi/linux/filter.h>
|
#include <uapi/linux/filter.h>
|
||||||
#include <asm/cacheflush.h>
|
#include <asm/cacheflush.h>
|
||||||
|
#include <uapi/linux/bpf.h>
|
||||||
|
|
||||||
struct sk_buff;
|
struct sk_buff;
|
||||||
struct sock;
|
struct sock;
|
||||||
struct seccomp_data;
|
struct seccomp_data;
|
||||||
|
|
||||||
/* Internally used and optimized filter representation with extended
|
|
||||||
* instruction set based on top of classic BPF.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/* instruction classes */
|
|
||||||
#define BPF_ALU64 0x07 /* alu mode in double word width */
|
|
||||||
|
|
||||||
/* ld/ldx fields */
|
|
||||||
#define BPF_DW 0x18 /* double word */
|
|
||||||
#define BPF_XADD 0xc0 /* exclusive add */
|
|
||||||
|
|
||||||
/* alu/jmp fields */
|
|
||||||
#define BPF_MOV 0xb0 /* mov reg to reg */
|
|
||||||
#define BPF_ARSH 0xc0 /* sign extending arithmetic shift right */
|
|
||||||
|
|
||||||
/* change endianness of a register */
|
|
||||||
#define BPF_END 0xd0 /* flags for endianness conversion: */
|
|
||||||
#define BPF_TO_LE 0x00 /* convert to little-endian */
|
|
||||||
#define BPF_TO_BE 0x08 /* convert to big-endian */
|
|
||||||
#define BPF_FROM_LE BPF_TO_LE
|
|
||||||
#define BPF_FROM_BE BPF_TO_BE
|
|
||||||
|
|
||||||
#define BPF_JNE 0x50 /* jump != */
|
|
||||||
#define BPF_JSGT 0x60 /* SGT is signed '>', GT in x86 */
|
|
||||||
#define BPF_JSGE 0x70 /* SGE is signed '>=', GE in x86 */
|
|
||||||
#define BPF_CALL 0x80 /* function call */
|
|
||||||
#define BPF_EXIT 0x90 /* function return */
|
|
||||||
|
|
||||||
/* Register numbers */
|
|
||||||
enum {
|
|
||||||
BPF_REG_0 = 0,
|
|
||||||
BPF_REG_1,
|
|
||||||
BPF_REG_2,
|
|
||||||
BPF_REG_3,
|
|
||||||
BPF_REG_4,
|
|
||||||
BPF_REG_5,
|
|
||||||
BPF_REG_6,
|
|
||||||
BPF_REG_7,
|
|
||||||
BPF_REG_8,
|
|
||||||
BPF_REG_9,
|
|
||||||
BPF_REG_10,
|
|
||||||
__MAX_BPF_REG,
|
|
||||||
};
|
|
||||||
|
|
||||||
/* BPF has 10 general purpose 64-bit registers and stack frame. */
|
|
||||||
#define MAX_BPF_REG __MAX_BPF_REG
|
|
||||||
|
|
||||||
/* ArgX, context and stack frame pointer register positions. Note,
|
/* ArgX, context and stack frame pointer register positions. Note,
|
||||||
* Arg1, Arg2, Arg3, etc are used as argument mappings of function
|
* Arg1, Arg2, Arg3, etc are used as argument mappings of function
|
||||||
* calls in BPF_CALL instruction.
|
* calls in BPF_CALL instruction.
|
||||||
|
@ -322,14 +276,6 @@ enum {
|
||||||
#define SK_RUN_FILTER(filter, ctx) \
|
#define SK_RUN_FILTER(filter, ctx) \
|
||||||
(*filter->prog->bpf_func)(ctx, filter->prog->insnsi)
|
(*filter->prog->bpf_func)(ctx, filter->prog->insnsi)
|
||||||
|
|
||||||
struct bpf_insn {
|
|
||||||
__u8 code; /* opcode */
|
|
||||||
__u8 dst_reg:4; /* dest register */
|
|
||||||
__u8 src_reg:4; /* source register */
|
|
||||||
__s16 off; /* signed offset */
|
|
||||||
__s32 imm; /* signed immediate constant */
|
|
||||||
};
|
|
||||||
|
|
||||||
#ifdef CONFIG_COMPAT
|
#ifdef CONFIG_COMPAT
|
||||||
/* A struct sock_filter is architecture independent. */
|
/* A struct sock_filter is architecture independent. */
|
||||||
struct compat_sock_fprog {
|
struct compat_sock_fprog {
|
||||||
|
|
|
@ -67,6 +67,7 @@ header-y += bfs_fs.h
|
||||||
header-y += binfmts.h
|
header-y += binfmts.h
|
||||||
header-y += blkpg.h
|
header-y += blkpg.h
|
||||||
header-y += blktrace_api.h
|
header-y += blktrace_api.h
|
||||||
|
header-y += bpf.h
|
||||||
header-y += bpqether.h
|
header-y += bpqether.h
|
||||||
header-y += bsg.h
|
header-y += bsg.h
|
||||||
header-y += btrfs.h
|
header-y += btrfs.h
|
||||||
|
|
|
@ -0,0 +1,65 @@
|
||||||
|
/* Copyright (c) 2011-2014 PLUMgrid, http://plumgrid.com
|
||||||
|
*
|
||||||
|
* This program is free software; you can redistribute it and/or
|
||||||
|
* modify it under the terms of version 2 of the GNU General Public
|
||||||
|
* License as published by the Free Software Foundation.
|
||||||
|
*/
|
||||||
|
#ifndef _UAPI__LINUX_BPF_H__
|
||||||
|
#define _UAPI__LINUX_BPF_H__
|
||||||
|
|
||||||
|
#include <linux/types.h>
|
||||||
|
|
||||||
|
/* Extended instruction set based on top of classic BPF */
|
||||||
|
|
||||||
|
/* instruction classes */
|
||||||
|
#define BPF_ALU64 0x07 /* alu mode in double word width */
|
||||||
|
|
||||||
|
/* ld/ldx fields */
|
||||||
|
#define BPF_DW 0x18 /* double word */
|
||||||
|
#define BPF_XADD 0xc0 /* exclusive add */
|
||||||
|
|
||||||
|
/* alu/jmp fields */
|
||||||
|
#define BPF_MOV 0xb0 /* mov reg to reg */
|
||||||
|
#define BPF_ARSH 0xc0 /* sign extending arithmetic shift right */
|
||||||
|
|
||||||
|
/* change endianness of a register */
|
||||||
|
#define BPF_END 0xd0 /* flags for endianness conversion: */
|
||||||
|
#define BPF_TO_LE 0x00 /* convert to little-endian */
|
||||||
|
#define BPF_TO_BE 0x08 /* convert to big-endian */
|
||||||
|
#define BPF_FROM_LE BPF_TO_LE
|
||||||
|
#define BPF_FROM_BE BPF_TO_BE
|
||||||
|
|
||||||
|
#define BPF_JNE 0x50 /* jump != */
|
||||||
|
#define BPF_JSGT 0x60 /* SGT is signed '>', GT in x86 */
|
||||||
|
#define BPF_JSGE 0x70 /* SGE is signed '>=', GE in x86 */
|
||||||
|
#define BPF_CALL 0x80 /* function call */
|
||||||
|
#define BPF_EXIT 0x90 /* function return */
|
||||||
|
|
||||||
|
/* Register numbers */
|
||||||
|
enum {
|
||||||
|
BPF_REG_0 = 0,
|
||||||
|
BPF_REG_1,
|
||||||
|
BPF_REG_2,
|
||||||
|
BPF_REG_3,
|
||||||
|
BPF_REG_4,
|
||||||
|
BPF_REG_5,
|
||||||
|
BPF_REG_6,
|
||||||
|
BPF_REG_7,
|
||||||
|
BPF_REG_8,
|
||||||
|
BPF_REG_9,
|
||||||
|
BPF_REG_10,
|
||||||
|
__MAX_BPF_REG,
|
||||||
|
};
|
||||||
|
|
||||||
|
/* BPF has 10 general purpose 64-bit registers and stack frame. */
|
||||||
|
#define MAX_BPF_REG __MAX_BPF_REG
|
||||||
|
|
||||||
|
struct bpf_insn {
|
||||||
|
__u8 code; /* opcode */
|
||||||
|
__u8 dst_reg:4; /* dest register */
|
||||||
|
__u8 src_reg:4; /* source register */
|
||||||
|
__s16 off; /* signed offset */
|
||||||
|
__s32 imm; /* signed immediate constant */
|
||||||
|
};
|
||||||
|
|
||||||
|
#endif /* _UAPI__LINUX_BPF_H__ */
|
Loading…
Reference in New Issue