This patchset adds support for fetching XFRM state information from an eBPF program called from TC.
The first patch introduces a helper for fetching an XFRM state from the skb's secpath. The XFRM state is modeled using a new virtual struct which contains the SPI, peer address, and reqid values of the state; This struct can be extended in the future to provide additional state information. The second patch adds a test example in test_tunnel_bpf.sh. The sample validates the correct extraction of state information by the eBPF program. --- Eyal Birger (2): bpf: add helper for getting xfrm states samples/bpf: extend test_tunnel_bpf.sh with xfrm state test include/uapi/linux/bpf.h | 25 ++++++++++- net/core/filter.c | 46 ++++++++++++++++++++ samples/bpf/tcbpf2_kern.c | 15 +++++++ samples/bpf/test_tunnel_bpf.sh | 71 +++++++++++++++++++++++++++++++ tools/include/uapi/linux/bpf.h | 25 ++++++++++- tools/testing/selftests/bpf/bpf_helpers.h | 3 ++ 6 files changed, 183 insertions(+), 2 deletions(-) -- 2.7.4