2 * Linux Socket Filter Data Structures
5 #ifndef __LINUX_FILTER_H__
6 #define __LINUX_FILTER_H__
8 #include <linux/compiler.h>
9 #include <linux/types.h>
12 #include <linux/atomic.h>
13 #include <linux/compat.h>
17 * Current version of the filter code architecture.
19 #define BPF_MAJOR_VERSION 1
20 #define BPF_MINOR_VERSION 1
23 * Try and keep these values and structures similar to BSD, especially
24 * the BPF code definitions which need to match so you can share filters
27 struct sock_filter { /* Filter block */
28 __u16 code; /* Actual filter code */
29 __u8 jt; /* Jump true */
30 __u8 jf; /* Jump false */
31 __u32 k; /* Generic multiuse field */
34 struct sock_fprog { /* Required for SO_ATTACH_FILTER. */
35 unsigned short len; /* Number of filter blocks */
36 struct sock_filter __user *filter;
43 #define BPF_CLASS(code) ((code) & 0x07)
54 #define BPF_SIZE(code) ((code) & 0x18)
58 #define BPF_MODE(code) ((code) & 0xe0)
67 #define BPF_OP(code) ((code) & 0xf0)
85 #define BPF_SRC(code) ((code) & 0x08)
89 /* ret - BPF_K and BPF_X also apply */
90 #define BPF_RVAL(code) ((code) & 0x18)
94 #define BPF_MISCOP(code) ((code) & 0xf8)
99 #define BPF_MAXINSNS 4096
103 * Macros for filter block array initializers.
106 #define BPF_STMT(code, k) { (unsigned short)(code), 0, 0, k }
109 #define BPF_JUMP(code, k, jt, jf) { (unsigned short)(code), jt, jf, k }
113 * Number of scratch memory words for: BPF_ST and BPF_STX
115 #define BPF_MEMWORDS 16
117 /* RATIONALE. Negative offsets are invalid in BPF.
118 We use them to reference ancillary data.
119 Unlike introduction new instructions, it does not break
120 existing compilers/optimizers.
122 #define SKF_AD_OFF (-0x1000)
123 #define SKF_AD_PROTOCOL 0
124 #define SKF_AD_PKTTYPE 4
125 #define SKF_AD_IFINDEX 8
126 #define SKF_AD_NLATTR 12
127 #define SKF_AD_NLATTR_NEST 16
128 #define SKF_AD_MARK 20
129 #define SKF_AD_QUEUE 24
130 #define SKF_AD_HATYPE 28
131 #define SKF_AD_RXHASH 32
132 #define SKF_AD_CPU 36
133 #define SKF_AD_ALU_XOR_X 40
134 #define SKF_AD_MAX 44
135 #define SKF_NET_OFF (-0x100000)
136 #define SKF_LL_OFF (-0x200000)
142 * A struct sock_filter is architecture independent.
144 struct compat_sock_fprog {
146 compat_uptr_t filter; /* struct sock_filter * */
156 unsigned int len; /* Number of filter blocks */
157 unsigned int (*bpf_func)(const struct sk_buff *skb,
158 const struct sock_filter *filter);
160 struct sock_filter insns[0];
163 static inline unsigned int sk_filter_len(const struct sk_filter *fp)
165 return fp->len * sizeof(struct sock_filter) + sizeof(*fp);
168 extern int sk_filter(struct sock *sk, struct sk_buff *skb);
169 extern unsigned int sk_run_filter(const struct sk_buff *skb,
170 const struct sock_filter *filter);
171 extern int sk_unattached_filter_create(struct sk_filter **pfp,
172 struct sock_fprog *fprog);
173 extern void sk_unattached_filter_destroy(struct sk_filter *fp);
174 extern int sk_attach_filter(struct sock_fprog *fprog, struct sock *sk);
175 extern int sk_detach_filter(struct sock *sk);
176 extern int sk_chk_filter(struct sock_filter *filter, unsigned int flen);
178 #ifdef CONFIG_BPF_JIT
179 extern void bpf_jit_compile(struct sk_filter *fp);
180 extern void bpf_jit_free(struct sk_filter *fp);
181 #define SK_RUN_FILTER(FILTER, SKB) (*FILTER->bpf_func)(SKB, FILTER->insns)
183 static inline void bpf_jit_compile(struct sk_filter *fp)
186 static inline void bpf_jit_free(struct sk_filter *fp)
189 #define SK_RUN_FILTER(FILTER, SKB) sk_run_filter(SKB, FILTER->insns)
247 BPF_S_ANC_NLATTR_NEST,
254 BPF_S_ANC_SECCOMP_LD_W,
257 #endif /* __KERNEL__ */
259 #endif /* __LINUX_FILTER_H__ */