Thread (39 messages) 39 messages, 5 authors, 2017-03-13

Re: [PATCH/RFC net-next 1/2] flow dissector: ND support

From: Jiri Pirko <jiri@resnulli.us>
Date: 2017-03-13 13:53:12

Mon, Mar 13, 2017 at 02:50:08PM CET, simon.horman@netronome.com wrote:
On Fri, Mar 10, 2017 at 03:27:32PM +0100, Jiri Pirko wrote:
quoted
Fri, Mar 10, 2017 at 03:19:13PM CET, simon.horman@netronome.com wrote:
quoted
On Tue, Feb 21, 2017 at 04:28:10PM +0100, Jiri Pirko wrote:
quoted
Thu, Feb 02, 2017 at 11:37:34AM CET, simon.horman@netronome.com wrote:
quoted
Allow dissection of Neighbour Discovery target IP, and source and
destination link-layer addresses for neighbour solicitation and
advertisement messages.

Signed-off-by: Simon Horman <redacted>
---
[...]
quoted
@@ -633,6 +702,18 @@ bool __skb_flow_dissect(const struct sk_buff *skb,
						     FLOW_DISSECTOR_KEY_ICMP,
						     target_container);
		key_icmp->icmp = skb_flow_get_be16(skb, nhoff, data, hlen);
+
+		if (dissector_uses_key(flow_dissector, FLOW_DISSECTOR_KEY_ND) &&
+		    ip_proto == IPPROTO_IPV6 && key_icmp->code == 0 &&
IPPROTO_IPV6 say "IPv6-in-IPv4 tunnelling". Please use "NEXTHDR_IPV6"
instead.
Thanks, will do.
quoted
quoted
+		    (key_icmp->type == NDISC_NEIGHBOUR_SOLICITATION ||
+		     key_icmp->type == NDISC_NEIGHBOUR_ADVERTISEMENT)) {
+			key_nd = skb_flow_dissector_target(flow_dissector,
+							   FLOW_DISSECTOR_KEY_ND,
+							   target_container);
+			if (!(skb_flow_dissect_nd(skb, key_nd, data, nhoff,
+						  hlen, ipv6_payload_len)))
+				goto out_bad;
+		}
You should put this under "switch (ip_proto) {"
I see that makes sense in terms of the check against ip_proto.
But I added it here to allow checking against key_icmp->code
and key_icmp->type as well.
Sure. Just add under "switch (ip_proto) {" and call a wrapper nd
function from there. In that function, you check dissector_uses_key and
other needed things.
Hi Jiri,

I'm sorry but I'm having a bit of trouble understanding how best to
structure the extraction of ICMP and ND.

The way I see things is this:

* ICMP extraction may occur for IPv4 or IPv6 although currently neither
 IPv4 nor IPv6 is a condition of ICMP extraction.
* ND extraction may only occur for IPv6
* ND extraction may only occur for certain ICMP code/type values;
 thus ICMP extraction should occur before ND extraction.

I wonder if a good alternative to the approach I took above in my patch
would  be to provide:
* ICMP extraction conditional on IPv4 and;
* ICMP extraction conditional on IPv6 followed by
 ND extraction conditional on ICMP type and code
Makes sense to me.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help