Linux jobworks 6.8.0-136-generic #136-Ubuntu SMP PREEMPT_DYNAMIC Wed Jul 1 21:53:05 UTC 2026 x86_64
Apache/2.4.58 (Ubuntu)
Server IP : 10.0.1.5 & Your IP : 216.73.217.52
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
src /
linux-headers-6.8.0-136 /
include /
net /
Delete
Unzip
Name
Size
Permission
Date
Action
9p
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
bluetooth
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
caif
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
iucv
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
mana
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
netfilter
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
netns
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
nfc
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
page_pool
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
phonet
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
sctp
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
tc_act
[ DIR ]
drwxr-xr-x
2026-07-17 06:29
6lowpan.h
10.03
KB
-rw-r--r--
2024-03-10 20:38
Space.h
455
B
-rw-r--r--
2024-03-10 20:38
act_api.h
9.35
KB
-rw-r--r--
2026-07-01 19:48
addrconf.h
14.28
KB
-rw-r--r--
2026-07-01 19:48
af_ieee802154.h
1.19
KB
-rw-r--r--
2024-03-10 20:38
af_rxrpc.h
3.3
KB
-rw-r--r--
2024-03-10 20:38
af_unix.h
3.76
KB
-rw-r--r--
2026-07-01 19:48
af_vsock.h
8.41
KB
-rw-r--r--
2026-07-01 19:48
ah.h
382
B
-rw-r--r--
2024-03-10 20:38
amt.h
8.35
KB
-rw-r--r--
2024-03-10 20:38
arp.h
1.95
KB
-rw-r--r--
2024-03-10 20:38
atmclip.h
1.48
KB
-rw-r--r--
2024-03-10 20:38
ax25.h
14.94
KB
-rw-r--r--
2026-07-01 19:48
ax88796.h
1.43
KB
-rw-r--r--
2024-03-10 20:38
bareudp.h
333
B
-rw-r--r--
2024-03-10 20:38
bond_3ad.h
9.5
KB
-rw-r--r--
2026-07-01 19:48
bond_alb.h
6.1
KB
-rw-r--r--
2024-03-10 20:38
bond_options.h
4.88
KB
-rw-r--r--
2026-07-01 19:48
bonding.h
21.5
KB
-rw-r--r--
2026-07-01 19:48
bpf_sk_storage.h
1.74
KB
-rw-r--r--
2024-03-10 20:38
busy_poll.h
4.28
KB
-rw-r--r--
2026-07-01 19:48
calipso.h
1.55
KB
-rw-r--r--
2024-03-10 20:38
cfg80211-wext.h
1.86
KB
-rw-r--r--
2024-03-10 20:38
cfg80211.h
336.64
KB
-rw-r--r--
2026-07-01 19:48
cfg802154.h
16.68
KB
-rw-r--r--
2026-07-01 19:48
checksum.h
4.98
KB
-rw-r--r--
2026-07-01 19:48
cipso_ipv4.h
7.37
KB
-rw-r--r--
2024-03-10 20:38
cls_cgroup.h
2.04
KB
-rw-r--r--
2026-07-01 19:48
codel.h
5.86
KB
-rw-r--r--
2024-03-10 20:38
codel_impl.h
8.3
KB
-rw-r--r--
2024-03-10 20:38
codel_qdisc.h
2.95
KB
-rw-r--r--
2024-03-10 20:38
compat.h
2.48
KB
-rw-r--r--
2024-03-10 20:38
datalink.h
590
B
-rw-r--r--
2024-03-10 20:38
dcbevent.h
766
B
-rw-r--r--
2024-03-10 20:38
dcbnl.h
4.98
KB
-rw-r--r--
2024-03-10 20:38
devlink.h
70.92
KB
-rw-r--r--
2024-03-10 20:38
dropreason-core.h
14.76
KB
-rw-r--r--
2026-07-01 19:48
dropreason.h
1.36
KB
-rw-r--r--
2024-03-10 20:38
dsa.h
41.09
KB
-rw-r--r--
2026-07-01 19:48
dsa_stubs.h
1.28
KB
-rw-r--r--
2024-03-10 20:38
dsfield.h
1.12
KB
-rw-r--r--
2024-03-10 20:38
dst.h
15.12
KB
-rw-r--r--
2026-07-01 19:48
dst_cache.h
2.96
KB
-rw-r--r--
2024-03-10 20:38
dst_metadata.h
6.34
KB
-rw-r--r--
2024-03-10 20:38
dst_ops.h
2.07
KB
-rw-r--r--
2026-07-01 19:48
erspan.h
9.04
KB
-rw-r--r--
2024-03-10 20:38
esp.h
1.18
KB
-rw-r--r--
2024-03-10 20:38
espintcp.h
966
B
-rw-r--r--
2024-03-10 20:38
ethoc.h
439
B
-rw-r--r--
2024-03-10 20:38
failover.h
1.18
KB
-rw-r--r--
2024-03-10 20:38
fib_notifier.h
1.35
KB
-rw-r--r--
2024-03-10 20:38
fib_rules.h
5.39
KB
-rw-r--r--
2024-03-10 20:38
firewire.h
599
B
-rw-r--r--
2024-03-10 20:38
flow.h
4.96
KB
-rw-r--r--
2024-03-10 20:38
flow_dissector.h
11.95
KB
-rw-r--r--
2024-03-10 20:38
flow_offload.h
17.37
KB
-rw-r--r--
2024-03-10 20:38
fou.h
578
B
-rw-r--r--
2024-03-10 20:38
fq.h
2.41
KB
-rw-r--r--
2024-03-10 20:38
fq_impl.h
7.96
KB
-rw-r--r--
2024-03-10 20:38
garp.h
2.67
KB
-rw-r--r--
2024-03-10 20:38
gen_stats.h
2.99
KB
-rw-r--r--
2024-03-10 20:38
genetlink.h
19.62
KB
-rw-r--r--
2026-07-01 19:48
geneve.h
1.84
KB
-rw-r--r--
2024-03-10 20:38
gre.h
3.29
KB
-rw-r--r--
2024-03-10 20:38
gro.h
13.38
KB
-rw-r--r--
2026-07-01 19:48
gro_cells.h
443
B
-rw-r--r--
2024-03-10 20:38
gso.h
3.2
KB
-rw-r--r--
2024-03-10 20:38
gtp.h
1.46
KB
-rw-r--r--
2024-03-10 20:38
gue.h
3.29
KB
-rw-r--r--
2024-03-10 20:38
handshake.h
1.39
KB
-rw-r--r--
2024-03-10 20:38
hwbm.h
995
B
-rw-r--r--
2024-03-10 20:38
icmp.h
1.87
KB
-rw-r--r--
2024-03-10 20:38
ieee80211_radiotap.h
23.22
KB
-rw-r--r--
2026-07-01 19:48
ieee802154_netdev.h
13.02
KB
-rw-r--r--
2024-03-10 20:38
if_inet6.h
6.6
KB
-rw-r--r--
2024-03-10 20:38
ife.h
1.03
KB
-rw-r--r--
2024-03-10 20:38
inet6_connection_sock.h
794
B
-rw-r--r--
2024-03-10 20:38
inet6_hashtables.h
5.57
KB
-rw-r--r--
2026-07-01 19:48
inet_common.h
2.83
KB
-rw-r--r--
2024-03-10 20:38
inet_connection_sock.h
11.7
KB
-rw-r--r--
2026-07-01 19:48
inet_dscp.h
1.55
KB
-rw-r--r--
2024-03-10 20:38
inet_ecn.h
7.83
KB
-rw-r--r--
2024-03-10 20:38
inet_frag.h
5.25
KB
-rw-r--r--
2026-07-01 19:48
inet_hashtables.h
16.91
KB
-rw-r--r--
2026-07-01 19:48
inet_sock.h
11.36
KB
-rw-r--r--
2026-07-01 19:48
inet_timewait_sock.h
3.71
KB
-rw-r--r--
2026-07-01 19:48
inetpeer.h
3.23
KB
-rw-r--r--
2026-07-01 19:48
ioam6.h
1.24
KB
-rw-r--r--
2026-07-01 19:48
ip.h
23.13
KB
-rw-r--r--
2026-07-01 19:48
ip6_checksum.h
2.3
KB
-rw-r--r--
2024-03-10 20:38
ip6_fib.h
17.6
KB
-rw-r--r--
2026-07-01 19:48
ip6_route.h
10.18
KB
-rw-r--r--
2026-07-01 19:48
ip6_tunnel.h
5.31
KB
-rw-r--r--
2026-07-01 19:48
ip_fib.h
16.13
KB
-rw-r--r--
2026-07-01 19:48
ip_tunnels.h
16.89
KB
-rw-r--r--
2026-07-01 19:48
ip_vs.h
53.83
KB
-rw-r--r--
2024-03-10 20:38
ipcomp.h
737
B
-rw-r--r--
2024-03-10 20:38
ipconfig.h
837
B
-rw-r--r--
2024-03-10 20:38
ipv6.h
37.62
KB
-rw-r--r--
2026-07-01 19:48
ipv6_frag.h
3.38
KB
-rw-r--r--
2024-03-10 20:38
ipv6_stubs.h
3.75
KB
-rw-r--r--
2026-07-01 19:48
iw_handler.h
20.66
KB
-rw-r--r--
2024-03-10 20:38
kcm.h
4.84
KB
-rw-r--r--
2026-07-01 19:48
l3mdev.h
7.03
KB
-rw-r--r--
2026-07-01 19:48
lag.h
409
B
-rw-r--r--
2024-03-10 20:38
lapb.h
4.82
KB
-rw-r--r--
2026-07-01 19:48
lib80211.h
3.92
KB
-rw-r--r--
2024-03-10 20:38
llc.h
4.41
KB
-rw-r--r--
2024-03-10 20:38
llc_c_ac.h
9.32
KB
-rw-r--r--
2024-03-10 20:38
llc_c_ev.h
10.61
KB
-rw-r--r--
2024-03-10 20:38
llc_c_st.h
1.77
KB
-rw-r--r--
2024-03-10 20:38
llc_conn.h
4.11
KB
-rw-r--r--
2024-03-10 20:38
llc_if.h
2.17
KB
-rw-r--r--
2024-03-10 20:38
llc_pdu.h
14.46
KB
-rw-r--r--
2024-03-10 20:38
llc_s_ac.h
1.59
KB
-rw-r--r--
2024-03-10 20:38
llc_s_ev.h
2.22
KB
-rw-r--r--
2024-03-10 20:38
llc_s_st.h
1.03
KB
-rw-r--r--
2024-03-10 20:38
llc_sap.h
1.08
KB
-rw-r--r--
2024-03-10 20:38
lwtunnel.h
6.69
KB
-rw-r--r--
2026-07-01 19:48
mac80211.h
293.31
KB
-rw-r--r--
2026-07-01 19:48
mac802154.h
14.88
KB
-rw-r--r--
2024-03-10 20:38
macsec.h
10.53
KB
-rw-r--r--
2026-07-01 19:48
mctp.h
8.1
KB
-rw-r--r--
2026-07-01 19:48
mctpdevice.h
1.26
KB
-rw-r--r--
2024-03-10 20:38
mip6.h
1016
B
-rw-r--r--
2024-03-10 20:38
mld.h
2.85
KB
-rw-r--r--
2024-03-10 20:38
mpls.h
943
B
-rw-r--r--
2024-03-10 20:38
mpls_iptunnel.h
481
B
-rw-r--r--
2024-03-10 20:38
mptcp.h
7.41
KB
-rw-r--r--
2024-03-10 20:38
mrp.h
3.13
KB
-rw-r--r--
2024-03-10 20:38
ncsi.h
1.94
KB
-rw-r--r--
2024-03-10 20:38
ndisc.h
14.64
KB
-rw-r--r--
2024-03-10 20:38
neighbour.h
16.55
KB
-rw-r--r--
2026-07-01 19:48
net_debug.h
5.08
KB
-rw-r--r--
2026-07-01 19:48
net_failover.h
1023
B
-rw-r--r--
2024-03-10 20:38
net_namespace.h
14.36
KB
-rw-r--r--
2026-07-01 19:48
net_ratelimit.h
220
B
-rw-r--r--
2024-03-10 20:38
net_trackers.h
424
B
-rw-r--r--
2024-03-10 20:38
netdev_queues.h
5.75
KB
-rw-r--r--
2024-03-10 20:38
netdev_rx_queue.h
1.32
KB
-rw-r--r--
2024-03-10 20:38
netevent.h
1.04
KB
-rw-r--r--
2024-03-10 20:38
netkit.h
1.16
KB
-rw-r--r--
2024-03-10 20:38
netlabel.h
20.15
KB
-rw-r--r--
2026-07-01 19:48
netlink.h
64.18
KB
-rw-r--r--
2024-03-10 20:38
netprio_cgroup.h
1.02
KB
-rw-r--r--
2024-03-10 20:38
netrom.h
7.73
KB
-rw-r--r--
2024-03-10 20:38
nexthop.h
11.91
KB
-rw-r--r--
2024-03-10 20:38
nl802154.h
16.04
KB
-rw-r--r--
2024-03-10 20:38
nsh.h
12.3
KB
-rw-r--r--
2024-03-10 20:38
p8022.h
403
B
-rw-r--r--
2024-03-10 20:38
pie.h
3.61
KB
-rw-r--r--
2026-07-01 19:48
ping.h
2.66
KB
-rw-r--r--
2024-03-10 20:38
pkt_cls.h
25.52
KB
-rw-r--r--
2026-07-01 19:48
pkt_sched.h
7.74
KB
-rw-r--r--
2026-07-01 19:48
pptp.h
604
B
-rw-r--r--
2024-03-10 20:38
protocol.h
3.81
KB
-rw-r--r--
2024-03-10 20:38
psample.h
1.06
KB
-rw-r--r--
2024-03-10 20:38
psnap.h
430
B
-rw-r--r--
2024-03-10 20:38
raw.h
2.46
KB
-rw-r--r--
2024-03-10 20:38
rawv6.h
862
B
-rw-r--r--
2024-03-10 20:38
red.h
11.33
KB
-rw-r--r--
2024-03-10 20:38
regulatory.h
9.96
KB
-rw-r--r--
2024-03-10 20:38
request_sock.h
6.5
KB
-rw-r--r--
2024-03-10 20:38
rose.h
8.06
KB
-rw-r--r--
2026-07-01 19:48
route.h
11.32
KB
-rw-r--r--
2026-07-01 19:48
rpl.h
749
B
-rw-r--r--
2024-03-10 20:38
rsi_91x.h
1.67
KB
-rw-r--r--
2024-03-10 20:38
rtnetlink.h
7.58
KB
-rw-r--r--
2026-07-01 19:48
rtnh.h
859
B
-rw-r--r--
2024-03-10 20:38
sch_generic.h
35.08
KB
-rw-r--r--
2026-07-01 19:48
scm.h
5.36
KB
-rw-r--r--
2026-07-01 19:48
secure_seq.h
868
B
-rw-r--r--
2024-03-10 20:38
seg6.h
2.18
KB
-rw-r--r--
2024-03-10 20:38
seg6_hmac.h
1.44
KB
-rw-r--r--
2024-03-10 20:38
seg6_local.h
644
B
-rw-r--r--
2024-03-10 20:38
selftests.h
582
B
-rw-r--r--
2024-03-10 20:38
slhc_vj.h
6.67
KB
-rw-r--r--
2024-03-10 20:38
smc.h
2.5
KB
-rw-r--r--
2026-07-01 19:48
snmp.h
5.14
KB
-rw-r--r--
2024-03-10 20:38
sock.h
85.78
KB
-rw-r--r--
2026-07-01 19:48
sock_reuseport.h
1.83
KB
-rw-r--r--
2024-03-10 20:38
stp.h
412
B
-rw-r--r--
2024-03-10 20:38
strparser.h
4.34
KB
-rw-r--r--
2026-07-01 19:48
switchdev.h
15.1
KB
-rw-r--r--
2024-03-10 20:38
tc_wrapper.h
6.29
KB
-rw-r--r--
2026-07-01 19:48
tcp.h
85.12
KB
-rw-r--r--
2026-07-01 19:48
tcp_ao.h
12.08
KB
-rw-r--r--
2026-07-01 19:48
tcp_states.h
1.3
KB
-rw-r--r--
2024-03-10 20:38
tcx.h
4.3
KB
-rw-r--r--
2026-07-01 19:48
timewait_sock.h
925
B
-rw-r--r--
2024-03-10 20:38
tipc.h
2.35
KB
-rw-r--r--
2024-03-10 20:38
tls.h
13.28
KB
-rw-r--r--
2026-07-01 19:48
tls_prot.h
1.84
KB
-rw-r--r--
2024-03-10 20:38
tls_toe.h
2.94
KB
-rw-r--r--
2024-03-10 20:38
transp_v6.h
1.88
KB
-rw-r--r--
2024-03-10 20:38
tso.h
721
B
-rw-r--r--
2024-03-10 20:38
tun_proto.h
1015
B
-rw-r--r--
2024-03-10 20:38
udp.h
15.88
KB
-rw-r--r--
2026-07-01 19:48
udp_tunnel.h
12.49
KB
-rw-r--r--
2026-07-01 19:48
udplite.h
2.3
KB
-rw-r--r--
2024-03-10 20:38
vsock_addr.h
662
B
-rw-r--r--
2024-03-10 20:38
vxlan.h
15.83
KB
-rw-r--r--
2026-07-01 19:48
wext.h
1.47
KB
-rw-r--r--
2024-03-10 20:38
x25.h
9.46
KB
-rw-r--r--
2024-03-10 20:38
x25device.h
387
B
-rw-r--r--
2024-03-10 20:38
xdp.h
16.93
KB
-rw-r--r--
2026-07-01 19:48
xdp_priv.h
427
B
-rw-r--r--
2024-03-10 20:38
xdp_sock.h
6.3
KB
-rw-r--r--
2026-07-01 19:48
xdp_sock_drv.h
10.15
KB
-rw-r--r--
2026-07-01 19:48
xfrm.h
58.29
KB
-rw-r--r--
2026-07-01 19:48
xsk_buff_pool.h
7.09
KB
-rw-r--r--
2026-07-01 19:48
Save
Rename
/* * Copyright (c) 2016-2017, Mellanox Technologies. All rights reserved. * Copyright (c) 2016-2017, Dave Watson <davejwatson@fb.com>. All rights reserved. * * This software is available to you under a choice of one of two * licenses. You may choose to be licensed under the terms of the GNU * General Public License (GPL) Version 2, available from the file * COPYING in the main directory of this source tree, or the * OpenIB.org BSD license below: * * Redistribution and use in source and binary forms, with or * without modification, are permitted provided that the following * conditions are met: * * - Redistributions of source code must retain the above * copyright notice, this list of conditions and the following * disclaimer. * * - Redistributions in binary form must reproduce the above * copyright notice, this list of conditions and the following * disclaimer in the documentation and/or other materials * provided with the distribution. * * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE * SOFTWARE. */ #ifndef _TLS_OFFLOAD_H #define _TLS_OFFLOAD_H #include <linux/types.h> #include <asm/byteorder.h> #include <linux/crypto.h> #include <linux/socket.h> #include <linux/tcp.h> #include <linux/mutex.h> #include <linux/netdevice.h> #include <linux/rcupdate.h> #include <net/net_namespace.h> #include <net/tcp.h> #include <net/strparser.h> #include <crypto/aead.h> #include <uapi/linux/tls.h> struct tls_rec; /* Maximum data size carried in a TLS record */ #define TLS_MAX_PAYLOAD_SIZE ((size_t)1 << 14) #define TLS_HEADER_SIZE 5 #define TLS_NONCE_OFFSET TLS_HEADER_SIZE #define TLS_CRYPTO_INFO_READY(info) ((info)->cipher_type) #define TLS_AAD_SPACE_SIZE 13 #define TLS_MAX_IV_SIZE 16 #define TLS_MAX_SALT_SIZE 4 #define TLS_TAG_SIZE 16 #define TLS_MAX_REC_SEQ_SIZE 8 #define TLS_MAX_AAD_SIZE TLS_AAD_SPACE_SIZE /* For CCM mode, the full 16-bytes of IV is made of '4' fields of given sizes. * * IV[16] = b0[1] || implicit nonce[4] || explicit nonce[8] || length[3] * * The field 'length' is encoded in field 'b0' as '(length width - 1)'. * Hence b0 contains (3 - 1) = 2. */ #define TLS_AES_CCM_IV_B0_BYTE 2 #define TLS_SM4_CCM_IV_B0_BYTE 2 enum { TLS_BASE, TLS_SW, TLS_HW, TLS_HW_RECORD, TLS_NUM_CONFIG, }; struct tx_work { struct delayed_work work; struct sock *sk; }; struct tls_sw_context_tx { struct crypto_aead *aead_send; struct crypto_wait async_wait; struct tx_work tx_work; struct tls_rec *open_rec; struct list_head tx_list; atomic_t encrypt_pending; u8 async_capable:1; #define BIT_TX_SCHEDULED 0 #define BIT_TX_CLOSING 1 unsigned long tx_bitmask; }; struct tls_strparser { struct sock *sk; u32 mark : 8; u32 stopped : 1; u32 copy_mode : 1; u32 mixed_decrypted : 1; bool msg_ready; struct strp_msg stm; struct sk_buff *anchor; struct work_struct work; }; struct tls_sw_context_rx { struct crypto_aead *aead_recv; struct crypto_wait async_wait; struct sk_buff_head rx_list; /* list of decrypted 'data' records */ void (*saved_data_ready)(struct sock *sk); u8 reader_present; u8 async_capable:1; u8 zc_capable:1; u8 reader_contended:1; struct tls_strparser strp; atomic_t decrypt_pending; struct sk_buff_head async_hold; struct wait_queue_head wq; }; struct tls_record_info { struct list_head list; u32 end_seq; int len; int num_frags; skb_frag_t frags[MAX_SKB_FRAGS]; }; #define TLS_DRIVER_STATE_SIZE_TX 16 struct tls_offload_context_tx { struct crypto_aead *aead_send; spinlock_t lock; /* protects records list */ struct list_head records_list; struct tls_record_info *open_record; struct tls_record_info *retransmit_hint; u64 hint_record_sn; u64 unacked_record_sn; struct scatterlist sg_tx_data[MAX_SKB_FRAGS]; void (*sk_destruct)(struct sock *sk); struct work_struct destruct_work; struct tls_context *ctx; /* The TLS layer reserves room for driver specific state * Currently the belief is that there is not enough * driver specific state to justify another layer of indirection */ u8 driver_state[TLS_DRIVER_STATE_SIZE_TX] __aligned(8); }; enum tls_context_flags { /* tls_device_down was called after the netdev went down, device state * was released, and kTLS works in software, even though rx_conf is * still TLS_HW (needed for transition). */ TLS_RX_DEV_DEGRADED = 0, /* Unlike RX where resync is driven entirely by the core in TX only * the driver knows when things went out of sync, so we need the flag * to be atomic. */ TLS_TX_SYNC_SCHED = 1, /* tls_dev_del was called for the RX side, device state was released, * but tls_ctx->netdev might still be kept, because TX-side driver * resources might not be released yet. Used to prevent the second * tls_dev_del call in tls_device_down if it happens simultaneously. */ TLS_RX_DEV_CLOSED = 2, }; struct cipher_context { char iv[TLS_MAX_IV_SIZE + TLS_MAX_SALT_SIZE]; char rec_seq[TLS_MAX_REC_SEQ_SIZE]; }; union tls_crypto_context { struct tls_crypto_info info; union { struct tls12_crypto_info_aes_gcm_128 aes_gcm_128; struct tls12_crypto_info_aes_gcm_256 aes_gcm_256; struct tls12_crypto_info_chacha20_poly1305 chacha20_poly1305; struct tls12_crypto_info_sm4_gcm sm4_gcm; struct tls12_crypto_info_sm4_ccm sm4_ccm; }; }; struct tls_prot_info { u16 version; u16 cipher_type; u16 prepend_size; u16 tag_size; u16 overhead_size; u16 iv_size; u16 salt_size; u16 rec_seq_size; u16 aad_size; u16 tail_size; }; struct tls_context { /* read-only cache line */ struct tls_prot_info prot_info; u8 tx_conf:3; u8 rx_conf:3; u8 zerocopy_sendfile:1; u8 rx_no_pad:1; int (*push_pending_record)(struct sock *sk, int flags); void (*sk_write_space)(struct sock *sk); void *priv_ctx_tx; void *priv_ctx_rx; struct net_device __rcu *netdev; /* rw cache line */ struct cipher_context tx; struct cipher_context rx; struct scatterlist *partially_sent_record; u16 partially_sent_offset; bool splicing_pages; bool pending_open_record_frags; struct mutex tx_lock; /* protects partially_sent_* fields and * per-type TX fields */ unsigned long flags; /* cache cold stuff */ struct proto *sk_proto; struct sock *sk; void (*sk_destruct)(struct sock *sk); union tls_crypto_context crypto_send; union tls_crypto_context crypto_recv; struct list_head list; refcount_t refcount; struct rcu_head rcu; }; enum tls_offload_ctx_dir { TLS_OFFLOAD_CTX_DIR_RX, TLS_OFFLOAD_CTX_DIR_TX, }; struct tlsdev_ops { int (*tls_dev_add)(struct net_device *netdev, struct sock *sk, enum tls_offload_ctx_dir direction, struct tls_crypto_info *crypto_info, u32 start_offload_tcp_sn); void (*tls_dev_del)(struct net_device *netdev, struct tls_context *ctx, enum tls_offload_ctx_dir direction); int (*tls_dev_resync)(struct net_device *netdev, struct sock *sk, u32 seq, u8 *rcd_sn, enum tls_offload_ctx_dir direction); }; enum tls_offload_sync_type { TLS_OFFLOAD_SYNC_TYPE_DRIVER_REQ = 0, TLS_OFFLOAD_SYNC_TYPE_CORE_NEXT_HINT = 1, TLS_OFFLOAD_SYNC_TYPE_DRIVER_REQ_ASYNC = 2, }; #define TLS_DEVICE_RESYNC_NH_START_IVAL 2 #define TLS_DEVICE_RESYNC_NH_MAX_IVAL 128 #define TLS_DEVICE_RESYNC_ASYNC_LOGMAX 13 struct tls_offload_resync_async { atomic64_t req; u16 loglen; u16 rcd_delta; u32 log[TLS_DEVICE_RESYNC_ASYNC_LOGMAX]; }; #define TLS_DRIVER_STATE_SIZE_RX 8 struct tls_offload_context_rx { /* sw must be the first member of tls_offload_context_rx */ struct tls_sw_context_rx sw; enum tls_offload_sync_type resync_type; /* this member is set regardless of resync_type, to avoid branches */ u8 resync_nh_reset:1; /* CORE_NEXT_HINT-only member, but use the hole here */ u8 resync_nh_do_now:1; union { /* TLS_OFFLOAD_SYNC_TYPE_DRIVER_REQ */ struct { atomic64_t resync_req; }; /* TLS_OFFLOAD_SYNC_TYPE_CORE_NEXT_HINT */ struct { u32 decrypted_failed; u32 decrypted_tgt; } resync_nh; /* TLS_OFFLOAD_SYNC_TYPE_DRIVER_REQ_ASYNC */ struct { struct tls_offload_resync_async *resync_async; }; }; /* The TLS layer reserves room for driver specific state * Currently the belief is that there is not enough * driver specific state to justify another layer of indirection */ u8 driver_state[TLS_DRIVER_STATE_SIZE_RX] __aligned(8); }; struct tls_record_info *tls_get_record(struct tls_offload_context_tx *context, u32 seq, u64 *p_record_sn); static inline bool tls_record_is_start_marker(struct tls_record_info *rec) { return rec->len == 0; } static inline u32 tls_record_start_seq(struct tls_record_info *rec) { return rec->end_seq - rec->len; } struct sk_buff * tls_validate_xmit_skb(struct sock *sk, struct net_device *dev, struct sk_buff *skb); struct sk_buff * tls_validate_xmit_skb_sw(struct sock *sk, struct net_device *dev, struct sk_buff *skb); static inline bool tls_is_skb_tx_device_offloaded(const struct sk_buff *skb) { #ifdef CONFIG_TLS_DEVICE struct sock *sk = skb->sk; return sk && sk_fullsock(sk) && (smp_load_acquire(&sk->sk_validate_xmit_skb) == &tls_validate_xmit_skb); #else return false; #endif } static inline struct tls_context *tls_get_ctx(const struct sock *sk) { struct inet_connection_sock *icsk = inet_csk(sk); /* Use RCU on icsk_ulp_data only for sock diag code, * TLS data path doesn't need rcu_dereference(). */ return (__force void *)icsk->icsk_ulp_data; } static inline struct tls_sw_context_rx *tls_sw_ctx_rx( const struct tls_context *tls_ctx) { return (struct tls_sw_context_rx *)tls_ctx->priv_ctx_rx; } static inline struct tls_sw_context_tx *tls_sw_ctx_tx( const struct tls_context *tls_ctx) { return (struct tls_sw_context_tx *)tls_ctx->priv_ctx_tx; } static inline struct tls_offload_context_tx * tls_offload_ctx_tx(const struct tls_context *tls_ctx) { return (struct tls_offload_context_tx *)tls_ctx->priv_ctx_tx; } static inline bool tls_sw_has_ctx_tx(const struct sock *sk) { struct tls_context *ctx; if (!sk_is_inet(sk) || !inet_test_bit(IS_ICSK, sk)) return false; ctx = tls_get_ctx(sk); if (!ctx) return false; return !!tls_sw_ctx_tx(ctx); } static inline bool tls_sw_has_ctx_rx(const struct sock *sk) { struct tls_context *ctx; if (!sk_is_inet(sk) || !inet_test_bit(IS_ICSK, sk)) return false; ctx = tls_get_ctx(sk); if (!ctx) return false; return !!tls_sw_ctx_rx(ctx); } static inline struct tls_offload_context_rx * tls_offload_ctx_rx(const struct tls_context *tls_ctx) { return (struct tls_offload_context_rx *)tls_ctx->priv_ctx_rx; } static inline void *__tls_driver_ctx(struct tls_context *tls_ctx, enum tls_offload_ctx_dir direction) { if (direction == TLS_OFFLOAD_CTX_DIR_TX) return tls_offload_ctx_tx(tls_ctx)->driver_state; else return tls_offload_ctx_rx(tls_ctx)->driver_state; } static inline void * tls_driver_ctx(const struct sock *sk, enum tls_offload_ctx_dir direction) { return __tls_driver_ctx(tls_get_ctx(sk), direction); } #define RESYNC_REQ BIT(0) #define RESYNC_REQ_ASYNC BIT(1) /* The TLS context is valid until sk_destruct is called */ static inline void tls_offload_rx_resync_request(struct sock *sk, __be32 seq) { struct tls_context *tls_ctx = tls_get_ctx(sk); struct tls_offload_context_rx *rx_ctx = tls_offload_ctx_rx(tls_ctx); atomic64_set(&rx_ctx->resync_req, ((u64)ntohl(seq) << 32) | RESYNC_REQ); } /* Log all TLS record header TCP sequences in [seq, seq+len] */ static inline void tls_offload_rx_resync_async_request_start(struct sock *sk, __be32 seq, u16 len) { struct tls_context *tls_ctx = tls_get_ctx(sk); struct tls_offload_context_rx *rx_ctx = tls_offload_ctx_rx(tls_ctx); atomic64_set(&rx_ctx->resync_async->req, ((u64)ntohl(seq) << 32) | ((u64)len << 16) | RESYNC_REQ | RESYNC_REQ_ASYNC); rx_ctx->resync_async->loglen = 0; rx_ctx->resync_async->rcd_delta = 0; } static inline void tls_offload_rx_resync_async_request_end(struct sock *sk, __be32 seq) { struct tls_context *tls_ctx = tls_get_ctx(sk); struct tls_offload_context_rx *rx_ctx = tls_offload_ctx_rx(tls_ctx); atomic64_set(&rx_ctx->resync_async->req, ((u64)ntohl(seq) << 32) | RESYNC_REQ); } static inline void tls_offload_rx_resync_set_type(struct sock *sk, enum tls_offload_sync_type type) { struct tls_context *tls_ctx = tls_get_ctx(sk); tls_offload_ctx_rx(tls_ctx)->resync_type = type; } /* Driver's seq tracking has to be disabled until resync succeeded */ static inline bool tls_offload_tx_resync_pending(struct sock *sk) { struct tls_context *tls_ctx = tls_get_ctx(sk); bool ret; ret = test_bit(TLS_TX_SYNC_SCHED, &tls_ctx->flags); smp_mb__after_atomic(); return ret; } struct sk_buff *tls_encrypt_skb(struct sk_buff *skb); #ifdef CONFIG_TLS_DEVICE void tls_device_sk_destruct(struct sock *sk); void tls_offload_tx_resync_request(struct sock *sk, u32 got_seq, u32 exp_seq); static inline bool tls_is_sk_rx_device_offloaded(struct sock *sk) { if (!sk_fullsock(sk) || smp_load_acquire(&sk->sk_destruct) != tls_device_sk_destruct) return false; return tls_get_ctx(sk)->rx_conf == TLS_HW; } #endif #endif /* _TLS_OFFLOAD_H */