android_kernel_motorola_sm6375/include/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Martin KaFai Lau fde321706d
UPSTREAM: bpf: tcp: Allow bpf prog to write and parse TCP header option
[ Note: The TCP changes here is mainly to implement the bpf
  pieces into the bpf_skops_*() functions introduced
  in the earlier patches. ]

The earlier effort in BPF-TCP-CC allows the TCP Congestion Control
algorithm to be written in BPF.  It opens up opportunities to allow
a faster turnaround time in testing/releasing new congestion control
ideas to production environment.

The same flexibility can be extended to writing TCP header option.
It is not uncommon that people want to test new TCP header option
to improve the TCP performance.  Another use case is for data-center
that has a more controlled environment and has more flexibility in
putting header options for internal only use.

For example, we want to test the idea in putting maximum delay
ACK in TCP header option which is similar to a draft RFC proposal [1].

This patch introduces the necessary BPF API and use them in the
TCP stack to allow BPF_PROG_TYPE_SOCK_OPS program to parse
and write TCP header options.  It currently supports most of
the TCP packet except RST.

Supported TCP header option:
───────────────────────────
This patch allows the bpf-prog to write any option kind.
Different bpf-progs can write its own option by calling the new helper
bpf_store_hdr_opt().  The helper will ensure there is no duplicated
option in the header.

By allowing bpf-prog to write any option kind, this gives a lot of
flexibility to the bpf-prog.  Different bpf-prog can write its
own option kind.  It could also allow the bpf-prog to support a
recently standardized option on an older kernel.

Sockops Callback Flags:
──────────────────────
The bpf program will only be called to parse/write tcp header option
if the following newly added callback flags are enabled
in tp->bpf_sock_ops_cb_flags:
BPF_SOCK_OPS_PARSE_UNKNOWN_HDR_OPT_CB_FLAG
BPF_SOCK_OPS_PARSE_ALL_HDR_OPT_CB_FLAG
BPF_SOCK_OPS_WRITE_HDR_OPT_CB_FLAG

A few words on the PARSE CB flags.  When the above PARSE CB flags are
turned on, the bpf-prog will be called on packets received
at a sk that has at least reached the ESTABLISHED state.
The parsing of the SYN-SYNACK-ACK will be discussed in the
"3 Way HandShake" section.

The default is off for all of the above new CB flags, i.e. the bpf prog
will not be called to parse or write bpf hdr option.  There are
details comment on these new cb flags in the UAPI bpf.h.

sock_ops->skb_data and bpf_load_hdr_opt()
─────────────────────────────────────────
sock_ops->skb_data and sock_ops->skb_data_end covers the whole
TCP header and its options.  They are read only.

The new bpf_load_hdr_opt() helps to read a particular option "kind"
from the skb_data.

Please refer to the comment in UAPI bpf.h.  It has details
on what skb_data contains under different sock_ops->op.

3 Way HandShake
───────────────
The bpf-prog can learn if it is sending SYN or SYNACK by reading the
sock_ops->skb_tcp_flags.

* Passive side

When writing SYNACK (i.e. sock_ops->op == BPF_SOCK_OPS_WRITE_HDR_OPT_CB),
the received SYN skb will be available to the bpf prog.  The bpf prog can
use the SYN skb (which may carry the header option sent from the remote bpf
prog) to decide what bpf header option should be written to the outgoing
SYNACK skb.  The SYN packet can be obtained by getsockopt(TCP_BPF_SYN*).
More on this later.  Also, the bpf prog can learn if it is in syncookie
mode (by checking sock_ops->args[0] == BPF_WRITE_HDR_TCP_SYNACK_COOKIE).

The bpf prog can store the received SYN pkt by using the existing
bpf_setsockopt(TCP_SAVE_SYN).  The example in a later patch does it.
[ Note that the fullsock here is a listen sk, bpf_sk_storage
  is not very useful here since the listen sk will be shared
  by many concurrent connection requests.

  Extending bpf_sk_storage support to request_sock will add weight
  to the minisock and it is not necessary better than storing the
  whole ~100 bytes SYN pkt. ]

When the connection is established, the bpf prog will be called
in the existing PASSIVE_ESTABLISHED_CB callback.  At that time,
the bpf prog can get the header option from the saved syn and
then apply the needed operation to the newly established socket.
The later patch will use the max delay ack specified in the SYN
header and set the RTO of this newly established connection
as an example.

The received ACK (that concludes the 3WHS) will also be available to
the bpf prog during PASSIVE_ESTABLISHED_CB through the sock_ops->skb_data.
It could be useful in syncookie scenario.  More on this later.

There is an existing getsockopt "TCP_SAVED_SYN" to return the whole
saved syn pkt which includes the IP[46] header and the TCP header.
A few "TCP_BPF_SYN*" getsockopt has been added to allow specifying where to
start getting from, e.g. starting from TCP header, or from IP[46] header.

The new getsockopt(TCP_BPF_SYN*) will also know where it can get
the SYN's packet from:
  - (a) the just received syn (available when the bpf prog is writing SYNACK)
        and it is the only way to get SYN during syncookie mode.
  or
  - (b) the saved syn (available in PASSIVE_ESTABLISHED_CB and also other
        existing CB).

The bpf prog does not need to know where the SYN pkt is coming from.
The getsockopt(TCP_BPF_SYN*) will hide this details.

Similarly, a flags "BPF_LOAD_HDR_OPT_TCP_SYN" is also added to
bpf_load_hdr_opt() to read a particular header option from the SYN packet.

* Fastopen

Fastopen should work the same as the regular non fastopen case.
This is a test in a later patch.

* Syncookie

For syncookie, the later example patch asks the active
side's bpf prog to resend the header options in ACK.  The server
can use bpf_load_hdr_opt() to look at the options in this
received ACK during PASSIVE_ESTABLISHED_CB.

* Active side

The bpf prog will get a chance to write the bpf header option
in the SYN packet during WRITE_HDR_OPT_CB.  The received SYNACK
pkt will also be available to the bpf prog during the existing
ACTIVE_ESTABLISHED_CB callback through the sock_ops->skb_data
and bpf_load_hdr_opt().

* Turn off header CB flags after 3WHS

If the bpf prog does not need to write/parse header options
beyond the 3WHS, the bpf prog can clear the bpf_sock_ops_cb_flags
to avoid being called for header options.
Or the bpf-prog can select to leave the UNKNOWN_HDR_OPT_CB_FLAG on
so that the kernel will only call it when there is option that
the kernel cannot handle.

[1]: draft-wang-tcpm-low-latency-opt-00
     https://tools.ietf.org/html/draft-wang-tcpm-low-latency-opt-00

Change-Id: Ib7471831fda8cfc0a33638b4e35b39307af82c55
Signed-off-by: Martin KaFai Lau <kafai@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200820190104.2885895-1-kafai@fb.com
2026-01-14 18:12:18 -08:00
..
9p
bluetooth This is the 5.4.279 stable release 2024-07-08 13:55:50 +00:00
caif
iucv
netfilter netfilter: nf_tables: do not defer rule destruction via call_rcu 2025-06-04 14:32:36 +02:00
netns UPSTREAM: bpf, netns: Keep a list of attached bpf_link's 2026-01-14 17:53:12 -08:00
nfc net: nfc: nci: Increase NCI_DATA_TIMEOUT to 3000 ms 2025-12-03 12:45:11 +01:00
phonet
sctp sctp: detect and prevent references to a freed transport in sendmsg 2025-05-02 07:39:16 +02:00
tc_act
6lowpan.h
act_api.h net: sched: extract qstats update code into functions 2025-08-28 16:21:36 +02:00
addrconf.h This is the 5.4.275 stable release 2024-05-15 16:00:38 +00:00
af_ieee802154.h
af_rxrpc.h
af_unix.h UPSTREAM: af_unix: Do not use atomic ops for unix_sk(sk)->inflight. 2024-07-02 13:43:53 +03:00
af_vsock.h
ah.h
arp.h
atmclip.h
ax25.h
ax88796.h
bond_3ad.h
bond_alb.h bonding (gcc13): synchronize bond_{a,t}lb_xmit() types 2023-06-14 10:59:58 +02:00
bond_options.h
bonding.h bonding: fix macvlan over alb bond support 2023-08-30 16:27:24 +02:00
bpf_sk_storage.h UPSTREAM: bpf: INET_DIAG support in bpf_sk_storage 2025-12-23 13:36:00 -08:00
busy_poll.h net: busy-poll: use ktime_get_ns() instead of local_clock() 2024-09-04 13:15:03 +02:00
calipso.h
cfg80211-wext.h
cfg80211.h Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:17:54 +03:00
cfg802154.h
checksum.h
cipso_ipv4.h
cls_cgroup.h UPSTREAM: bpf: Allow to retrieve cgroup v1 classid from v2 hooks 2025-12-23 13:36:09 -08:00
cnss.h
cnss2.h cnss2: Add API to send WFC mode to WLAN FW 2023-01-17 14:37:14 +05:30
cnss_logger.h
cnss_nl.h
cnss_prealloc.h
cnss_utils.h
codel.h
codel_impl.h
codel_qdisc.h
compat.h
datalink.h
dcbevent.h
dcbnl.h
devlink.h
drop_monitor.h
dsa.h
dsfield.h
dst.h Merge 5.4.248 into android11-5.4-lts 2023-06-22 16:16:24 +00:00
dst_cache.h UPSTREAM: wireguard: device: reset peer src endpoint when netns exits 2025-09-24 12:16:39 +02:00
dst_metadata.h
dst_ops.h net: fix __dst_negative_advice() race 2024-06-16 13:28:52 +02:00
erspan.h erspan: Add type I version 0 support. 2024-04-13 12:51:36 +02:00
esp.h
ethoc.h
failover.h
fib_notifier.h
fib_rules.h
firewire.h
flow.h Revert "inet: shrink struct flowi_common" 2023-11-27 17:25:07 +00:00
flow_dissector.h UPSTREAM: flow_dissector: Pull BPF program assignment up to bpf-netns 2026-01-14 17:53:12 -08:00
flow_offload.h net: extract port range fields from fl_flow_key 2025-03-13 12:43:23 +01:00
fou.h
fq.h
fq_impl.h
garp.h
gen_stats.h
genetlink.h Revert "genetlink: hold RCU in genlmsg_mcast()" 2024-11-09 16:39:42 +00:00
geneve.h
gre.h
gro_cells.h
gtp.h
gue.h
hwbm.h
icmp.h
ieee80211_radiotap.h
ieee802154_netdev.h
if_inet6.h net: ipv6: support reporting otherwise unknown prefix flags in RTM_NEWPREFIX 2023-12-20 15:41:13 +01:00
ife.h
ila.h
inet6_connection_sock.h
inet6_hashtables.h UPSTREAM: net: Track socket refcounts in skb_steal_sock() 2025-12-23 13:36:11 -08:00
inet_common.h UPSTREAM: bpf: Allow any port in bpf_bind helper 2025-12-23 13:36:18 -08:00
inet_connection_sock.h UPSTREAM: tcp: bpf: Add TCP_BPF_RTO_MIN for bpf_setsockopt 2026-01-14 18:12:17 -08:00
inet_ecn.h
inet_frag.h
inet_hashtables.h UPSTREAM: net: Track socket refcounts in skb_steal_sock() 2025-12-23 13:36:11 -08:00
inet_sock.h
inet_timewait_sock.h
inetpeer.h
ip.h Merge 5.4.245 into android11-5.4-lts 2023-06-20 16:54:26 +00:00
ip6_checksum.h
ip6_fib.h UPSTREAM: bpf: Enable bpf_iter targets registering ctx argument types 2026-01-14 17:41:40 -08:00
ip6_route.h
ip6_tunnel.h ip_gre, ip6_gre: Fix race condition on o_seqno in collect_md mode 2023-05-30 12:44:05 +01:00
ip_fib.h
ip_tunnels.h Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-12-04 19:21:35 +02:00
ip_vs.h
ipcomp.h
ipconfig.h
ipv6.h tcp: Reduce chance of collisions in inet6_hashfn(). 2023-08-11 11:53:47 +02:00
ipv6_frag.h
ipv6_stubs.h UPSTREAM: net: Refactor arguments of inet{,6}_bind 2025-12-23 13:36:18 -08:00
ipx.h
iw_handler.h
kcm.h kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
l3mdev.h vrf: use RCU protection in l3mdev_l3_out() 2025-03-13 12:43:12 +01:00
lag.h
lapb.h net: lapb: increase LAPB_HEADER_LEN 2024-12-19 18:05:03 +01:00
lib80211.h
llc.h
llc_c_ac.h
llc_c_ev.h
llc_c_st.h
llc_conn.h
llc_if.h
llc_pdu.h llc: Drop support for ETH_P_TR_802_2. 2024-02-23 08:24:50 +01:00
llc_s_ac.h
llc_s_ev.h
llc_s_st.h
llc_sap.h
lwtunnel.h lwt: Check LWTUNNEL_XMIT_CONTINUE strictly 2023-09-23 10:59:42 +02:00
mac80211.h mac80211: Add support to trigger sta disconnect on hardware restart 2024-11-08 16:20:52 +01:00
mac802154.h
macsec.h
mip6.h
mld.h
mpls.h
mpls_iptunnel.h
mrp.h mrp: introduce active flags to prevent UAF when applicant uninit 2023-01-18 11:41:37 +01:00
ncsi.h
ndisc.h
neighbour.h Merge android11-5.4.249+ (d57e792) into msm-5.4 2023-09-28 16:45:28 +05:30
net_failover.h
net_namespace.h UPSTREAM: net: push loops and nb calls into helper functions 2026-01-14 18:12:09 -08:00
net_ratelimit.h
netevent.h
netlabel.h
netlink.h
netprio_cgroup.h
netrom.h
nexthop.h
nl802154.h
nsh.h
p8022.h
page_pool.h
ping.h
pkt_cls.h
pkt_sched.h net/sched: sch_qfq: Fix null-deref in agg_dequeue 2025-12-03 12:45:04 +01:00
pptp.h
protocol.h
psample.h
psnap.h
raw.h
rawv6.h
red.h
regulatory.h
request_sock.h BACKPORT: tcp: Use a struct to represent a saved_syn 2026-01-14 18:12:17 -08:00
rmnet_config.h
rose.h
route.h
rsi_91x.h
rtnetlink.h Revert "net: rtnetlink: add msg kind names" 2025-10-31 07:58:56 +00:00
rtnh.h
sch_generic.h This is the 5.4.297 stable release 2025-09-02 10:52:40 +00:00
scm.h scm: fix MSG_CTRUNC setting condition for SO_PASSSEC 2023-05-17 11:35:41 +02:00
secure_seq.h
seg6.h UPSTREAM: seg6: fix seg6_validate_srh() to avoid slab-out-of-bounds 2026-01-14 17:48:10 -08:00
seg6_hmac.h
seg6_local.h
slhc_vj.h
smc.h
snmp.h
sock.h UPSTREAM: bpf: net: Avoid incorrect bpf_sk_reuseport_detach call 2026-01-14 18:12:02 -08:00
sock_reuseport.h UPSTREAM: net: Generate reuseport group ID on group creation 2025-12-23 13:35:57 -08:00
Space.h
stp.h
strparser.h
switchdev.h
tcp.h UPSTREAM: bpf: tcp: Allow bpf prog to write and parse TCP header option 2026-01-14 18:12:18 -08:00
tcp_states.h
TEST_MAPPING ANDROID: add TEST_MAPPING for net/, include/net 2023-01-23 17:54:01 +00:00
timewait_sock.h
tipc.h
tls.h
transp_v6.h
tso.h
tun_proto.h
udp.h UPSTREAM: net: bpf: Add bpf_seq_afinfo in udp_iter_state 2026-01-14 18:12:06 -08:00
udp_tunnel.h BACKPORT: udp_tunnel: add central NIC RX port offload infrastructure 2026-01-14 18:12:10 -08:00
udplite.h tcp/udp: Call inet6_destroy_sock() in IPv6 sk->sk_destruct(). 2023-04-26 11:24:05 +02:00
virt_wifi.h
vsock_addr.h
vxlan.h vxlan: calculate correct header length for GPE 2023-08-11 11:53:47 +02:00
wext.h
wimax.h
x25.h
x25device.h
xdp.h UPSTREAM: bpf: cpumap: Add the possibility to attach an eBPF program to cpumap 2026-01-14 18:12:04 -08:00
xdp_priv.h
xdp_sock.h UPSTREAM: xsk: Move xskmap.c to net/xdp/ 2026-01-14 17:48:04 -08:00
xfrm.h This is the 5.4.276 stable release 2024-05-17 15:29:56 +00:00