Introduce bpf_xdp_metadata_rx_checksum() kfunc in order to load the HW RX checksum results in the eBPF program binded to the NIC. Implement xmo_rx_checksum callback for veth and ice drivers.
If the hardware detects a wrong/failed checksum, it will report CHECKSUM_NONE in the packet metadata. Moreover, CHECKSUM_NONE will be returned even if the NIC can't parse the packet (e.g. if it does not support a specific protocol). A possible use case for bpf_xdp_metadata_rx_checksum() would be to implement a XDP DDoS application [1] combining the info from bpf_xdp_metadata_rx_checksum() and bpf_xdp_metadata_rx_hash() kfuncs in order to filter packets with a wrong/failed checksum. [1] https://blog.cloudflare.com/unimog-cloudflares-edge-load-balancer/ --- Changes in v5: - Add new kfunc to Documentation/networking/xdp-rx-metadata.rst documentation - Introduce bpf_skb_rx_checksum kfunc and related selftest. - Introduce selftest to check the driver invalidates the rx checksum if running in XDP mode. Changes in v4: - Report cusm and csum_level separately and convert ip_summed to a bitmask in bpf_xdp_metadata_rx_hash() - Fix endianness issue in bpf selftests - Add a comment about the driver expected behaviour if the the NIC reports CHECKSUM_UNNECESSARY or CHECKSUM_COMPLETE and the eBPF program modifes the packet - Introduce bpf_get_skb_cksum kfunc and related selftest to load the checksum result to the SCHED_CLS eBPF program attached to the qdisc. - Link to v3: https://lore.kernel.org/r/[email protected] Changes in v3: - Remoe leftover assignment from v2 in veth_xdp_rx_checksum() - Fix typos - Fix commit logs - Link to v2: https://lore.kernel.org/r/[email protected] Changes in v2: - Remove XDP_CHECKSUM_PARTIAL definition - Improve veth_xdp_rx_checksum() callback - Fix uninitialized case for cksum_meta in ice_get_rx_csum() - Fix sparse warnings in ice driver - Fix typos - Link to v1: https://lore.kernel.org/r/[email protected] Changes in v1: - Rebase on top of bpf-next - Test ice driver using xdp_hw_metadata tool available in the bpf kernel selftest - Improve cover letter with an use-case for bpf_xdp_metadata_rx_checksum() - Link to RFC v2: https://lore.kernel.org/r/[email protected] Changes in RFC v2: - Squash patch 1/6 and 2/6 - Introduce enum xdp_checksum definitions - Rework ice support to reuse ice_rx_csum codebase --- Lorenzo Bianconi (8): netlink: specs: add XDP RX checksum capability to XDP metadata specs net: veth: add xmo_rx_checksum callback to veth driver net: ice: add xmo_rx_checksum callback selftests/bpf: add selftest support for bpf_xdp_metadata_rx_checksum selftests/bpf: add bpf_xdp_metadata_rx_checksum support to xdp_hw_metadat prog net: add bpf_skb_rx_checksum kfunc to read skb checksum metadata selftests/bpf: Add test for bpf_skb_rx_checksum kfunc selftests: net: add test for XDP_PASS skb checksum invalidation Documentation/netlink/specs/netdev.yaml | 5 + Documentation/networking/xdp-rx-metadata.rst | 8 ++ drivers/net/ethernet/intel/ice/ice_txrx_lib.c | 123 ++++++++++++++------- drivers/net/veth.c | 32 ++++++ include/net/xdp.h | 13 +++ include/uapi/linux/netdev.h | 3 + net/core/filter.c | 31 ++++++ net/core/xdp.c | 32 ++++++ tools/include/uapi/linux/netdev.h | 3 + tools/testing/selftests/bpf/bpf_kfuncs.h | 8 ++ .../selftests/bpf/prog_tests/skb_rx_checksum.c | 50 +++++++++ .../selftests/bpf/prog_tests/xdp_metadata.c | 9 ++ .../testing/selftests/bpf/progs/skb_rx_checksum.c | 33 ++++++ .../testing/selftests/bpf/progs/xdp_hw_metadata.c | 7 ++ tools/testing/selftests/bpf/progs/xdp_metadata.c | 2 + tools/testing/selftests/bpf/skb_rx_checksum.h | 8 ++ tools/testing/selftests/bpf/xdp_hw_metadata.c | 31 ++++++ tools/testing/selftests/bpf/xdp_metadata.h | 13 +++ .../selftests/drivers/net/hw/xdp_metadata.py | 55 ++++++++- .../selftests/net/lib/skb_metadata_csum.bpf.c | 73 ++++++++++++ 20 files changed, 496 insertions(+), 43 deletions(-) --- base-commit: f6f3b36c15ed44de1fbb44e645e4fae8c4a4453e change-id: 20250925-bpf-xdp-meta-rxcksum-900685e2909d Best regards, -- Lorenzo Bianconi <[email protected]>
