@@ -94,7 +94,8 @@ struct mlxsw_afa_set {
* kvdl_index is valid).
*/
has_trap:1,
- has_police:1;
+ has_police:1,
+ has_trap_fwd:1;
unsigned int ref_count;
struct mlxsw_afa_set *next; /* Pointer to the next set. */
struct mlxsw_afa_set *prev; /* Pointer to the previous set,
@@ -263,14 +264,23 @@ static void mlxsw_afa_set_goto_set(struct mlxsw_afa_set *set,
mlxsw_afa_set_goto_next_binding_set(actions, group_id);
}
-static void mlxsw_afa_set_next_set(struct mlxsw_afa_set *set,
+static int mlxsw_afa_set_next_set(struct mlxsw_afa_set *set,
u32 next_set_kvdl_index,
struct netlink_ext_ack *extack)
{
char *actions = set->ht_key.enc_actions;
+ /* If the forwarding action is not drop, the next/goto record must not
+ * be a next, it must be a goto.
+ */
+ if (set->has_trap_fwd) {
+ NL_SET_ERR_MSG_MOD(extack, "Only goto permissible after a trap_fwd action");
+ return -EINVAL;
+ }
+
mlxsw_afa_set_type_set(actions, MLXSW_AFA_SET_TYPE_NEXT);
mlxsw_afa_set_next_action_set_ptr_set(actions, next_set_kvdl_index);
+ return 0;
}
static struct mlxsw_afa_set *mlxsw_afa_set_create(bool is_first)
@@ -461,6 +471,7 @@ int mlxsw_afa_block_commit(struct mlxsw_afa_block *block,
{
struct mlxsw_afa_set *set = block->cur_set;
struct mlxsw_afa_set *prev_set;
+ int err;
block->cur_set = NULL;
block->finished = true;
@@ -481,8 +492,10 @@ int mlxsw_afa_block_commit(struct mlxsw_afa_block *block,
return PTR_ERR(set);
if (prev_set) {
prev_set->next = set;
- mlxsw_afa_set_next_set(prev_set, set->kvdl_index,
- extack);
+ err = mlxsw_afa_set_next_set(prev_set, set->kvdl_index,
+ extack);
+ if (err)
+ return err;
set = prev_set;
}
} while (prev_set);
@@ -1346,6 +1359,8 @@ int mlxsw_afa_block_append_trap_and_forward(struct mlxsw_afa_block *block,
if (IS_ERR(act))
return PTR_ERR(act);
+
+ block->cur_set->has_trap_fwd = true;
mlxsw_afa_trap_pack(act, MLXSW_AFA_TRAP_TRAP_ACTION_TRAP,
MLXSW_AFA_TRAP_FORWARD_ACTION_FORWARD, trap_id);
return 0;
@@ -940,6 +940,7 @@ int mlxsw_sp_acl_rulei_act_drop(struct mlxsw_sp_acl_rule_info *rulei,
const struct flow_action_cookie *fa_cookie,
struct netlink_ext_ack *extack);
int mlxsw_sp_acl_rulei_act_trap(struct mlxsw_sp_acl_rule_info *rulei);
+int mlxsw_sp_acl_rulei_act_trap_fwd(struct mlxsw_sp_acl_rule_info *rulei);
int mlxsw_sp_acl_rulei_act_mirror(struct mlxsw_sp *mlxsw_sp,
struct mlxsw_sp_acl_rule_info *rulei,
struct mlxsw_sp_flow_block *block,
@@ -401,6 +401,12 @@ int mlxsw_sp_acl_rulei_act_trap(struct mlxsw_sp_acl_rule_info *rulei)
MLXSW_TRAP_ID_ACL0);
}
+int mlxsw_sp_acl_rulei_act_trap_fwd(struct mlxsw_sp_acl_rule_info *rulei)
+{
+ return mlxsw_afa_block_append_trap_and_forward(rulei->act_block,
+ MLXSW_TRAP_ID_ACL3);
+}
+
int mlxsw_sp_acl_rulei_act_fwd(struct mlxsw_sp *mlxsw_sp,
struct mlxsw_sp_acl_rule_info *rulei,
struct net_device *out_dev,
@@ -86,6 +86,13 @@ static int mlxsw_sp_flower_parse_actions(struct mlxsw_sp *mlxsw_sp,
return err;
}
break;
+ case FLOW_ACTION_TRAP_FWD:
+ err = mlxsw_sp_acl_rulei_act_trap_fwd(rulei);
+ if (err) {
+ NL_SET_ERR_MSG_MOD(extack, "Cannot append trap_fwd action");
+ return err;
+ }
+ break;
case FLOW_ACTION_GOTO: {
u32 chain_index = act->chain_index;
struct mlxsw_sp_acl_ruleset *ruleset;
@@ -1154,6 +1154,14 @@ static const struct mlxsw_sp_trap_item mlxsw_sp_trap_items_arr[] = {
false),
},
},
+ {
+ .trap = MLXSW_SP_TRAP_CONTROL(FLOW_ACTION_TRAP_FWD,
+ ACL_TRAP, MIRROR),
+ .listeners_arr = {
+ MLXSW_SP_RXL_L3_MARK(ACL3, FLOW_LOGGING, MIRROR_TO_CPU,
+ false),
+ },
+ },
{
.trap = MLXSW_SP_TRAP_DROP(BLACKHOLE_NEXTHOP, L3_DROPS),
.listeners_arr = {
@@ -108,6 +108,8 @@ enum {
MLXSW_TRAP_ID_ACL2 = 0x1C2,
MLXSW_TRAP_ID_DISCARD_INGRESS_ACL = 0x1C3,
MLXSW_TRAP_ID_DISCARD_EGRESS_ACL = 0x1C4,
+ /* Packets trapped due to FLOW_ACTION_TRAP_FWD. */
+ MLXSW_TRAP_ID_ACL3 = 0x1C5,
MLXSW_TRAP_ID_MIRROR_SESSION0 = 0x220,
MLXSW_TRAP_ID_MIRROR_SESSION1 = 0x221,
MLXSW_TRAP_ID_MIRROR_SESSION2 = 0x222,