1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * net/sched/sch_netem.c Network emulator 4 * 5 * Many of the algorithms and ideas for this came from 6 * NIST Net which is not copyrighted. 7 * 8 * Authors: Stephen Hemminger <shemminger@osdl.org> 9 * Catalin(ux aka Dino) BOIE <catab at umbrella dot ro> 10 */ 11 12 #include <linux/mm.h> 13 #include <linux/module.h> 14 #include <linux/slab.h> 15 #include <linux/types.h> 16 #include <linux/kernel.h> 17 #include <linux/errno.h> 18 #include <linux/skbuff.h> 19 #include <linux/vmalloc.h> 20 #include <linux/prandom.h> 21 #include <linux/rtnetlink.h> 22 #include <linux/reciprocal_div.h> 23 #include <linux/rbtree.h> 24 25 #include <net/gso.h> 26 #include <net/netlink.h> 27 #include <net/pkt_sched.h> 28 #include <net/inet_ecn.h> 29 30 #define VERSION "1.3" 31 32 /* Network Emulation Queuing algorithm. 33 ==================================== 34 35 Sources: [1] Mark Carson, Darrin Santay, "NIST Net - A Linux-based 36 Network Emulation Tool 37 [2] Luigi Rizzo, DummyNet for FreeBSD 38 39 ---------------------------------------------------------------- 40 41 This started out as a simple way to delay outgoing packets to 42 test TCP but has grown to include most of the functionality 43 of a full blown network emulator like NISTnet. It can delay 44 packets and add random jitter (and correlation). The random 45 distribution can be loaded from a table as well to provide 46 normal, Pareto, or experimental curves. Packet loss, 47 duplication, and reordering can also be emulated. 48 49 This qdisc does not do classification that can be handled in 50 layering other disciplines. It does not need to do bandwidth 51 control either since that can be handled by using token 52 bucket or other rate control. 53 54 Correlated Loss Generator models 55 56 Added generation of correlated loss according to the 57 "Gilbert-Elliot" model, a 4-state markov model. 58 59 References: 60 [1] NetemCLG Home http://netgroup.uniroma2.it/NetemCLG 61 [2] S. Salsano, F. Ludovici, A. Ordine, "Definition of a general 62 and intuitive loss model for packet networks and its implementation 63 in the Netem module in the Linux kernel", available in [1] 64 65 Authors: Stefano Salsano <stefano.salsano at uniroma2.it 66 Fabio Ludovici <fabio.ludovici at yahoo.it> 67 */ 68 69 struct disttable { 70 u32 size; 71 s16 table[] __counted_by(size); 72 }; 73 74 struct netem_sched_data { 75 /* internal t(ime)fifo qdisc uses t_root and sch->limit */ 76 struct rb_root t_root; 77 78 /* a linear queue; reduces rbtree rebalancing when jitter is low */ 79 struct sk_buff *t_head; 80 struct sk_buff *t_tail; 81 82 u32 t_len; 83 84 /* optional qdisc for classful handling (NULL at netem init) */ 85 struct Qdisc *qdisc; 86 87 struct qdisc_watchdog watchdog; 88 89 s64 latency; 90 s64 jitter; 91 92 u32 loss; 93 u32 ecn; 94 u32 limit; 95 u32 counter; 96 u32 gap; 97 u32 duplicate; 98 u32 reorder; 99 u32 corrupt; 100 u64 rate; 101 s32 packet_overhead; 102 u32 cell_size; 103 struct reciprocal_value cell_size_reciprocal; 104 s32 cell_overhead; 105 106 struct crndstate { 107 u32 last; 108 u32 rho; 109 } delay_cor, loss_cor, dup_cor, reorder_cor, corrupt_cor; 110 111 struct prng { 112 u64 seed; 113 struct rnd_state prng_state; 114 } prng; 115 116 struct disttable *delay_dist; 117 118 enum { 119 CLG_RANDOM, 120 CLG_4_STATES, 121 CLG_GILB_ELL, 122 } loss_model; 123 124 enum { 125 TX_IN_GAP_PERIOD = 1, 126 TX_IN_BURST_PERIOD, 127 LOST_IN_GAP_PERIOD, 128 LOST_IN_BURST_PERIOD, 129 } _4_state_model; 130 131 enum { 132 GOOD_STATE = 1, 133 BAD_STATE, 134 } GE_state_model; 135 136 /* Correlated Loss Generation models */ 137 struct clgstate { 138 /* state of the Markov chain */ 139 u8 state; 140 141 /* 4-states and Gilbert-Elliot models */ 142 u32 a1; /* p13 for 4-states or p for GE */ 143 u32 a2; /* p31 for 4-states or r for GE */ 144 u32 a3; /* p32 for 4-states or h for GE */ 145 u32 a4; /* p14 for 4-states or 1-k for GE */ 146 u32 a5; /* p23 used only in 4-states */ 147 } clg; 148 149 struct tc_netem_slot slot_config; 150 struct slotstate { 151 u64 slot_next; 152 s32 packets_left; 153 s32 bytes_left; 154 } slot; 155 156 struct disttable *slot_dist; 157 }; 158 159 /* Time stamp put into socket buffer control block 160 * Only valid when skbs are in our internal t(ime)fifo queue. 161 * 162 * As skb->rbnode uses same storage than skb->next, skb->prev and skb->tstamp, 163 * and skb->next & skb->prev are scratch space for a qdisc, 164 * we save skb->tstamp value in skb->cb[] before destroying it. 165 */ 166 struct netem_skb_cb { 167 u64 time_to_send; 168 }; 169 170 static inline struct netem_skb_cb *netem_skb_cb(struct sk_buff *skb) 171 { 172 /* we assume we can use skb next/prev/tstamp as storage for rb_node */ 173 qdisc_cb_private_validate(skb, sizeof(struct netem_skb_cb)); 174 return (struct netem_skb_cb *)qdisc_skb_cb(skb)->data; 175 } 176 177 /* init_crandom - initialize correlated random number generator 178 * Use entropy source for initial seed. 179 */ 180 static void init_crandom(struct crndstate *state, unsigned long rho) 181 { 182 state->rho = rho; 183 state->last = get_random_u32(); 184 } 185 186 /* get_crandom - correlated random number generator 187 * Next number depends on last value. 188 * rho is scaled to avoid floating point. 189 */ 190 static u32 get_crandom(struct crndstate *state, struct prng *p) 191 { 192 u64 value, rho; 193 unsigned long answer; 194 struct rnd_state *s = &p->prng_state; 195 196 if (!state || state->rho == 0) /* no correlation */ 197 return prandom_u32_state(s); 198 199 value = prandom_u32_state(s); 200 rho = (u64)state->rho + 1; 201 answer = (value * ((1ull<<32) - rho) + state->last * rho) >> 32; 202 state->last = answer; 203 return answer; 204 } 205 206 /* loss_4state - 4-state model loss generator 207 * Generates losses according to the 4-state Markov chain adopted in 208 * the GI (General and Intuitive) loss model. 209 */ 210 static bool loss_4state(struct netem_sched_data *q) 211 { 212 struct clgstate *clg = &q->clg; 213 u32 rnd = prandom_u32_state(&q->prng.prng_state); 214 215 /* 216 * Makes a comparison between rnd and the transition 217 * probabilities outgoing from the current state, then decides the 218 * next state and if the next packet has to be transmitted or lost. 219 * The four states correspond to: 220 * TX_IN_GAP_PERIOD => successfully transmitted packets within a gap period 221 * LOST_IN_GAP_PERIOD => isolated losses within a gap period 222 * LOST_IN_BURST_PERIOD => lost packets within a burst period 223 * TX_IN_BURST_PERIOD => successfully transmitted packets within a burst period 224 */ 225 switch (clg->state) { 226 case TX_IN_GAP_PERIOD: 227 if (rnd < clg->a4) { 228 clg->state = LOST_IN_GAP_PERIOD; 229 return true; 230 } else if (rnd < clg->a1 + clg->a4) { 231 clg->state = LOST_IN_BURST_PERIOD; 232 return true; 233 } else { 234 clg->state = TX_IN_GAP_PERIOD; 235 } 236 237 break; 238 case TX_IN_BURST_PERIOD: 239 if (rnd < clg->a5) { 240 clg->state = LOST_IN_BURST_PERIOD; 241 return true; 242 } else { 243 clg->state = TX_IN_BURST_PERIOD; 244 } 245 246 break; 247 case LOST_IN_BURST_PERIOD: 248 if (rnd < clg->a3) 249 clg->state = TX_IN_BURST_PERIOD; 250 else if (rnd < clg->a2 + clg->a3) { 251 clg->state = TX_IN_GAP_PERIOD; 252 } else { 253 clg->state = LOST_IN_BURST_PERIOD; 254 return true; 255 } 256 break; 257 case LOST_IN_GAP_PERIOD: 258 clg->state = TX_IN_GAP_PERIOD; 259 break; 260 } 261 262 return false; 263 } 264 265 /* loss_gilb_ell - Gilbert-Elliot model loss generator 266 * Generates losses according to the Gilbert-Elliot loss model or 267 * its special cases (Gilbert or Simple Gilbert) 268 * 269 * Makes a comparison between random number and the transition 270 * probabilities outgoing from the current state, then decides the 271 * next state. A second random number is extracted and the comparison 272 * with the loss probability of the current state decides if the next 273 * packet will be transmitted or lost. 274 */ 275 static bool loss_gilb_ell(struct netem_sched_data *q) 276 { 277 struct clgstate *clg = &q->clg; 278 struct rnd_state *s = &q->prng.prng_state; 279 280 switch (clg->state) { 281 case GOOD_STATE: 282 if (prandom_u32_state(s) < clg->a1) 283 clg->state = BAD_STATE; 284 if (prandom_u32_state(s) < clg->a4) 285 return true; 286 break; 287 case BAD_STATE: 288 if (prandom_u32_state(s) < clg->a2) 289 clg->state = GOOD_STATE; 290 if (prandom_u32_state(s) > clg->a3) 291 return true; 292 } 293 294 return false; 295 } 296 297 static bool loss_event(struct netem_sched_data *q) 298 { 299 switch (q->loss_model) { 300 case CLG_RANDOM: 301 /* Random packet drop 0 => none, ~0 => all */ 302 return q->loss && q->loss >= get_crandom(&q->loss_cor, &q->prng); 303 304 case CLG_4_STATES: 305 /* 4state loss model algorithm (used also for GI model) 306 * Extracts a value from the markov 4 state loss generator, 307 * if it is 1 drops a packet and if needed writes the event in 308 * the kernel logs 309 */ 310 return loss_4state(q); 311 312 case CLG_GILB_ELL: 313 /* Gilbert-Elliot loss model algorithm 314 * Extracts a value from the Gilbert-Elliot loss generator, 315 * if it is 1 drops a packet and if needed writes the event in 316 * the kernel logs 317 */ 318 return loss_gilb_ell(q); 319 } 320 321 return false; /* not reached */ 322 } 323 324 325 /* tabledist - return a pseudo-randomly distributed value with mean mu and 326 * std deviation sigma. Uses table lookup to approximate the desired 327 * distribution, and a uniformly-distributed pseudo-random source. 328 */ 329 static s64 tabledist(s64 mu, s32 sigma, 330 struct crndstate *state, 331 struct prng *prng, 332 const struct disttable *dist) 333 { 334 s64 x; 335 long t; 336 u32 rnd; 337 338 if (sigma == 0) 339 return mu; 340 341 rnd = get_crandom(state, prng); 342 343 /* default uniform distribution */ 344 if (dist == NULL) 345 return ((rnd % (2 * (u32)sigma)) + mu) - sigma; 346 347 t = dist->table[rnd % dist->size]; 348 x = (sigma % NETEM_DIST_SCALE) * t; 349 if (x >= 0) 350 x += NETEM_DIST_SCALE/2; 351 else 352 x -= NETEM_DIST_SCALE/2; 353 354 return x / NETEM_DIST_SCALE + (sigma / NETEM_DIST_SCALE) * t + mu; 355 } 356 357 static u64 packet_time_ns(u64 len, const struct netem_sched_data *q) 358 { 359 len += q->packet_overhead; 360 361 if (q->cell_size) { 362 u32 cells = reciprocal_divide(len, q->cell_size_reciprocal); 363 364 if (len > cells * q->cell_size) /* extra cell needed for remainder */ 365 cells++; 366 len = cells * (q->cell_size + q->cell_overhead); 367 } 368 369 return div64_u64(len * NSEC_PER_SEC, q->rate); 370 } 371 372 static void tfifo_reset(struct Qdisc *sch) 373 { 374 struct netem_sched_data *q = qdisc_priv(sch); 375 struct rb_node *p = rb_first(&q->t_root); 376 377 while (p) { 378 struct sk_buff *skb = rb_to_skb(p); 379 380 p = rb_next(p); 381 rb_erase(&skb->rbnode, &q->t_root); 382 rtnl_kfree_skbs(skb, skb); 383 } 384 385 rtnl_kfree_skbs(q->t_head, q->t_tail); 386 q->t_head = NULL; 387 q->t_tail = NULL; 388 q->t_len = 0; 389 } 390 391 static void tfifo_enqueue(struct sk_buff *nskb, struct Qdisc *sch) 392 { 393 struct netem_sched_data *q = qdisc_priv(sch); 394 u64 tnext = netem_skb_cb(nskb)->time_to_send; 395 396 if (!q->t_tail || tnext >= netem_skb_cb(q->t_tail)->time_to_send) { 397 if (q->t_tail) 398 q->t_tail->next = nskb; 399 else 400 q->t_head = nskb; 401 q->t_tail = nskb; 402 } else { 403 struct rb_node **p = &q->t_root.rb_node, *parent = NULL; 404 405 while (*p) { 406 struct sk_buff *skb; 407 408 parent = *p; 409 skb = rb_to_skb(parent); 410 if (tnext >= netem_skb_cb(skb)->time_to_send) 411 p = &parent->rb_right; 412 else 413 p = &parent->rb_left; 414 } 415 rb_link_node(&nskb->rbnode, parent, p); 416 rb_insert_color(&nskb->rbnode, &q->t_root); 417 } 418 q->t_len++; 419 sch->q.qlen++; 420 } 421 422 /* netem can't properly corrupt a megapacket (like we get from GSO), so instead 423 * when we statistically choose to corrupt one, we instead segment it, returning 424 * the first packet to be corrupted, and re-enqueue the remaining frames 425 */ 426 static struct sk_buff *netem_segment(struct sk_buff *skb, struct Qdisc *sch, 427 struct sk_buff **to_free) 428 { 429 struct sk_buff *segs; 430 netdev_features_t features = netif_skb_features(skb); 431 432 qdisc_skb_cb(skb)->pkt_segs = 1; 433 segs = skb_gso_segment(skb, features & ~NETIF_F_GSO_MASK); 434 435 if (IS_ERR_OR_NULL(segs)) { 436 qdisc_drop(skb, sch, to_free); 437 return NULL; 438 } 439 consume_skb(skb); 440 return segs; 441 } 442 443 /* 444 * Insert one skb into qdisc. 445 * Note: parent depends on return value to account for queue length. 446 * NET_XMIT_DROP: queue length didn't change. 447 * NET_XMIT_SUCCESS: one skb was queued. 448 */ 449 static int netem_enqueue(struct sk_buff *skb, struct Qdisc *sch, 450 struct sk_buff **to_free) 451 { 452 struct netem_sched_data *q = qdisc_priv(sch); 453 /* We don't fill cb now as skb_unshare() may invalidate it */ 454 struct netem_skb_cb *cb; 455 struct sk_buff *skb2 = NULL; 456 struct sk_buff *segs = NULL; 457 unsigned int prev_len = qdisc_pkt_len(skb); 458 int count = 1; 459 460 /* Do not fool qdisc_drop_all() */ 461 skb->prev = NULL; 462 463 /* Random duplication */ 464 if (q->duplicate && skb->tc_depth == 0 && 465 q->duplicate >= get_crandom(&q->dup_cor, &q->prng)) 466 ++count; 467 468 /* Drop packet? */ 469 if (loss_event(q)) { 470 if (q->ecn && INET_ECN_set_ce(skb)) 471 qdisc_qstats_drop(sch); /* mark packet */ 472 else 473 --count; 474 } 475 if (count == 0) { 476 qdisc_qstats_drop(sch); 477 __qdisc_drop(skb, to_free); 478 return NET_XMIT_SUCCESS | __NET_XMIT_BYPASS; 479 } 480 481 /* If a delay is expected, orphan the skb. (orphaning usually takes 482 * place at TX completion time, so _before_ the link transit delay) 483 */ 484 if (q->latency || q->jitter || q->rate) 485 skb_orphan_partial(skb); 486 487 /* 488 * If we need to duplicate packet, then clone it before 489 * original is modified. 490 */ 491 if (count > 1) 492 skb2 = skb_clone(skb, GFP_ATOMIC); 493 494 /* 495 * Randomized packet corruption. 496 * Make copy if needed since we are modifying 497 * If packet is going to be hardware checksummed, then 498 * do it now in software before we mangle it. 499 */ 500 if (q->corrupt && q->corrupt >= get_crandom(&q->corrupt_cor, &q->prng)) { 501 if (skb_is_gso(skb)) { 502 skb = netem_segment(skb, sch, to_free); 503 if (!skb) 504 goto finish_segs; 505 506 segs = skb->next; 507 skb_mark_not_on_list(skb); 508 qdisc_skb_cb(skb)->pkt_len = skb->len; 509 } 510 511 skb = skb_unshare(skb, GFP_ATOMIC); 512 if (unlikely(!skb)) { 513 qdisc_qstats_drop(sch); 514 goto finish_segs; 515 } 516 if (skb->ip_summed == CHECKSUM_PARTIAL && 517 skb_checksum_help(skb)) { 518 qdisc_drop(skb, sch, to_free); 519 skb = NULL; 520 goto finish_segs; 521 } 522 523 if (skb_headlen(skb)) 524 skb->data[get_random_u32_below(skb_headlen(skb))] ^= 525 1 << get_random_u32_below(8); 526 } 527 528 if (unlikely(sch->q.qlen >= sch->limit)) { 529 /* re-link segs, so that qdisc_drop_all() frees them all */ 530 skb->next = segs; 531 qdisc_drop_all(skb, sch, to_free); 532 if (skb2) 533 __qdisc_drop(skb2, to_free); 534 return NET_XMIT_DROP; 535 } 536 537 /* 538 * If doing duplication then re-insert at top of the 539 * qdisc tree, since parent queuer expects that only one 540 * skb will be queued. 541 */ 542 if (skb2) { 543 struct Qdisc *rootq = qdisc_root_bh(sch); 544 545 skb2->tc_depth++; /* prevent duplicating a dup... */ 546 rootq->enqueue(skb2, rootq, to_free); 547 skb2 = NULL; 548 } 549 550 qdisc_qstats_backlog_inc(sch, skb); 551 552 cb = netem_skb_cb(skb); 553 if (q->gap == 0 || /* not doing reordering */ 554 q->counter < q->gap - 1 || /* inside last reordering gap */ 555 q->reorder < get_crandom(&q->reorder_cor, &q->prng)) { 556 u64 now; 557 s64 delay; 558 559 delay = tabledist(q->latency, q->jitter, 560 &q->delay_cor, &q->prng, q->delay_dist); 561 562 now = ktime_get_ns(); 563 564 if (q->rate) { 565 struct netem_skb_cb *last = NULL; 566 567 if (sch->q.tail) 568 last = netem_skb_cb(sch->q.tail); 569 if (q->t_root.rb_node) { 570 struct sk_buff *t_skb; 571 struct netem_skb_cb *t_last; 572 573 t_skb = skb_rb_last(&q->t_root); 574 t_last = netem_skb_cb(t_skb); 575 if (!last || 576 t_last->time_to_send > last->time_to_send) 577 last = t_last; 578 } 579 if (q->t_tail) { 580 struct netem_skb_cb *t_last = 581 netem_skb_cb(q->t_tail); 582 583 if (!last || 584 t_last->time_to_send > last->time_to_send) 585 last = t_last; 586 } 587 588 if (last) { 589 /* 590 * Last packet in queue is reference point (now), 591 * calculate this time bonus and subtract 592 * from delay. 593 */ 594 delay -= last->time_to_send - now; 595 delay = max_t(s64, 0, delay); 596 now = last->time_to_send; 597 } 598 599 delay += packet_time_ns(qdisc_pkt_len(skb), q); 600 } 601 602 cb->time_to_send = now + delay; 603 ++q->counter; 604 tfifo_enqueue(skb, sch); 605 } else { 606 /* 607 * Do re-ordering by putting one out of N packets at the front 608 * of the queue. 609 */ 610 cb->time_to_send = ktime_get_ns(); 611 q->counter = 0; 612 613 __qdisc_enqueue_head(skb, &sch->q); 614 sch->qstats.requeues++; 615 } 616 617 finish_segs: 618 if (skb2) 619 __qdisc_drop(skb2, to_free); 620 621 if (segs) { 622 unsigned int len, last_len; 623 int rc, nb; 624 625 len = skb ? skb->len : 0; 626 nb = skb ? 1 : 0; 627 628 while (segs) { 629 skb2 = segs->next; 630 skb_mark_not_on_list(segs); 631 qdisc_skb_cb(segs)->pkt_len = segs->len; 632 last_len = segs->len; 633 rc = qdisc_enqueue(segs, sch, to_free); 634 if (rc != NET_XMIT_SUCCESS) { 635 if (net_xmit_drop_count(rc)) 636 qdisc_qstats_drop(sch); 637 } else { 638 nb++; 639 len += last_len; 640 } 641 segs = skb2; 642 } 643 /* Parent qdiscs accounted for 1 skb of size @prev_len */ 644 qdisc_tree_reduce_backlog(sch, -(nb - 1), -(len - prev_len)); 645 } else if (!skb) { 646 return NET_XMIT_DROP; 647 } 648 return NET_XMIT_SUCCESS; 649 } 650 651 /* Delay the next round with a new future slot with a 652 * correct number of bytes and packets. 653 */ 654 655 static void get_slot_next(struct netem_sched_data *q, u64 now) 656 { 657 s64 next_delay; 658 659 if (!q->slot_dist) 660 next_delay = q->slot_config.min_delay + 661 mul_u64_u32_shr(q->slot_config.max_delay - q->slot_config.min_delay, 662 get_random_u32(), 32); 663 else 664 next_delay = tabledist(q->slot_config.dist_delay, 665 (s32)(q->slot_config.dist_jitter), 666 NULL, &q->prng, q->slot_dist); 667 668 q->slot.slot_next = now + next_delay; 669 q->slot.packets_left = q->slot_config.max_packets; 670 q->slot.bytes_left = q->slot_config.max_bytes; 671 } 672 673 static struct sk_buff *netem_peek(struct netem_sched_data *q) 674 { 675 struct sk_buff *skb = skb_rb_first(&q->t_root); 676 u64 t1, t2; 677 678 if (!skb) 679 return q->t_head; 680 if (!q->t_head) 681 return skb; 682 683 t1 = netem_skb_cb(skb)->time_to_send; 684 t2 = netem_skb_cb(q->t_head)->time_to_send; 685 if (t1 < t2) 686 return skb; 687 return q->t_head; 688 } 689 690 static void netem_erase_head(struct netem_sched_data *q, struct sk_buff *skb) 691 { 692 if (skb == q->t_head) { 693 q->t_head = skb->next; 694 if (!q->t_head) 695 q->t_tail = NULL; 696 } else { 697 rb_erase(&skb->rbnode, &q->t_root); 698 } 699 } 700 701 static struct sk_buff *netem_dequeue(struct Qdisc *sch) 702 { 703 struct netem_sched_data *q = qdisc_priv(sch); 704 struct sk_buff *skb; 705 706 tfifo_dequeue: 707 skb = __qdisc_dequeue_head(&sch->q); 708 if (skb) { 709 deliver: 710 qdisc_qstats_backlog_dec(sch, skb); 711 qdisc_bstats_update(sch, skb); 712 return skb; 713 } 714 skb = netem_peek(q); 715 if (skb) { 716 u64 time_to_send; 717 u64 now = ktime_get_ns(); 718 719 /* if more time remaining? */ 720 time_to_send = netem_skb_cb(skb)->time_to_send; 721 if (q->slot.slot_next && q->slot.slot_next < time_to_send) 722 get_slot_next(q, now); 723 724 if (time_to_send <= now && q->slot.slot_next <= now) { 725 netem_erase_head(q, skb); 726 q->t_len--; 727 skb->next = NULL; 728 skb->prev = NULL; 729 /* skb->dev shares skb->rbnode area, 730 * we need to restore its value. 731 */ 732 skb->dev = qdisc_dev(sch); 733 734 if (q->slot.slot_next) { 735 q->slot.packets_left--; 736 q->slot.bytes_left -= qdisc_pkt_len(skb); 737 if (q->slot.packets_left <= 0 || 738 q->slot.bytes_left <= 0) 739 get_slot_next(q, now); 740 } 741 742 if (q->qdisc) { 743 unsigned int pkt_len = qdisc_pkt_len(skb); 744 struct sk_buff *to_free = NULL; 745 int err; 746 747 err = qdisc_enqueue(skb, q->qdisc, &to_free); 748 kfree_skb_list(to_free); 749 if (err != NET_XMIT_SUCCESS) { 750 if (net_xmit_drop_count(err)) 751 qdisc_qstats_drop(sch); 752 sch->qstats.backlog -= pkt_len; 753 sch->q.qlen--; 754 qdisc_tree_reduce_backlog(sch, 1, pkt_len); 755 } 756 goto tfifo_dequeue; 757 } 758 sch->q.qlen--; 759 goto deliver; 760 } 761 762 if (q->qdisc) { 763 skb = q->qdisc->ops->dequeue(q->qdisc); 764 if (skb) { 765 sch->q.qlen--; 766 goto deliver; 767 } 768 } 769 770 qdisc_watchdog_schedule_ns(&q->watchdog, 771 max(time_to_send, 772 q->slot.slot_next)); 773 } 774 775 if (q->qdisc) { 776 skb = q->qdisc->ops->dequeue(q->qdisc); 777 if (skb) { 778 sch->q.qlen--; 779 goto deliver; 780 } 781 } 782 return NULL; 783 } 784 785 static void netem_reset(struct Qdisc *sch) 786 { 787 struct netem_sched_data *q = qdisc_priv(sch); 788 789 qdisc_reset_queue(sch); 790 tfifo_reset(sch); 791 if (q->qdisc) 792 qdisc_reset(q->qdisc); 793 qdisc_watchdog_cancel(&q->watchdog); 794 } 795 796 static void dist_free(struct disttable *d) 797 { 798 kvfree(d); 799 } 800 801 /* 802 * Distribution data is a variable size payload containing 803 * signed 16 bit values. 804 */ 805 806 static int get_dist_table(struct disttable **tbl, const struct nlattr *attr) 807 { 808 size_t n = nla_len(attr)/sizeof(__s16); 809 const __s16 *data = nla_data(attr); 810 struct disttable *d; 811 int i; 812 813 if (!n || n > NETEM_DIST_MAX) 814 return -EINVAL; 815 816 d = kvmalloc_flex(*d, table, n); 817 if (!d) 818 return -ENOMEM; 819 820 d->size = n; 821 for (i = 0; i < n; i++) 822 d->table[i] = data[i]; 823 824 *tbl = d; 825 return 0; 826 } 827 828 static int validate_time(const struct nlattr *attr, const char *name, 829 struct netlink_ext_ack *extack) 830 { 831 if (nla_get_s64(attr) < 0) { 832 NL_SET_ERR_MSG_ATTR_FMT(extack, attr, "negative %s", name); 833 return -EINVAL; 834 } 835 return 0; 836 } 837 838 static int validate_slot(const struct nlattr *attr, struct netlink_ext_ack *extack) 839 { 840 const struct tc_netem_slot *c = nla_data(attr); 841 842 if (c->min_delay < 0 || c->max_delay < 0) { 843 NL_SET_ERR_MSG_ATTR(extack, attr, "negative slot delay"); 844 return -EINVAL; 845 } 846 if (c->min_delay > c->max_delay) { 847 NL_SET_ERR_MSG_ATTR(extack, attr, "slot min delay greater than max delay"); 848 return -EINVAL; 849 } 850 if (c->dist_delay < 0 || c->dist_jitter < 0) { 851 NL_SET_ERR_MSG_ATTR(extack, attr, "negative dist delay"); 852 return -EINVAL; 853 } 854 if (c->max_packets < 0 || c->max_bytes < 0) { 855 NL_SET_ERR_MSG_ATTR(extack, attr, "negative slot limit"); 856 return -EINVAL; 857 } 858 return 0; 859 } 860 861 static void get_slot(struct netem_sched_data *q, const struct nlattr *attr) 862 { 863 const struct tc_netem_slot *c = nla_data(attr); 864 865 q->slot_config = *c; 866 if (q->slot_config.max_packets == 0) 867 q->slot_config.max_packets = INT_MAX; 868 if (q->slot_config.max_bytes == 0) 869 q->slot_config.max_bytes = INT_MAX; 870 871 /* capping dist_jitter to the range acceptable by tabledist() */ 872 q->slot_config.dist_jitter = min_t(__s64, INT_MAX, abs(q->slot_config.dist_jitter)); 873 874 q->slot.packets_left = q->slot_config.max_packets; 875 q->slot.bytes_left = q->slot_config.max_bytes; 876 if (q->slot_config.min_delay | q->slot_config.max_delay | 877 q->slot_config.dist_jitter) 878 q->slot.slot_next = ktime_get_ns(); 879 else 880 q->slot.slot_next = 0; 881 } 882 883 static void get_correlation(struct netem_sched_data *q, const struct nlattr *attr) 884 { 885 const struct tc_netem_corr *c = nla_data(attr); 886 887 init_crandom(&q->delay_cor, c->delay_corr); 888 init_crandom(&q->loss_cor, c->loss_corr); 889 init_crandom(&q->dup_cor, c->dup_corr); 890 } 891 892 static void get_reorder(struct netem_sched_data *q, const struct nlattr *attr) 893 { 894 const struct tc_netem_reorder *r = nla_data(attr); 895 896 q->reorder = r->probability; 897 init_crandom(&q->reorder_cor, r->correlation); 898 } 899 900 static void get_corrupt(struct netem_sched_data *q, const struct nlattr *attr) 901 { 902 const struct tc_netem_corrupt *r = nla_data(attr); 903 904 q->corrupt = r->probability; 905 init_crandom(&q->corrupt_cor, r->correlation); 906 } 907 908 static void get_rate(struct netem_sched_data *q, const struct nlattr *attr) 909 { 910 const struct tc_netem_rate *r = nla_data(attr); 911 912 q->rate = r->rate; 913 q->packet_overhead = r->packet_overhead; 914 q->cell_size = r->cell_size; 915 q->cell_overhead = r->cell_overhead; 916 if (q->cell_size) 917 q->cell_size_reciprocal = reciprocal_value(q->cell_size); 918 else 919 q->cell_size_reciprocal = (struct reciprocal_value) { 0 }; 920 } 921 922 static int get_loss_clg(struct netem_sched_data *q, const struct nlattr *attr) 923 { 924 const struct nlattr *la; 925 int rem; 926 927 nla_for_each_nested(la, attr, rem) { 928 u16 type = nla_type(la); 929 930 switch (type) { 931 case NETEM_LOSS_GI: { 932 const struct tc_netem_gimodel *gi = nla_data(la); 933 934 if (nla_len(la) < sizeof(struct tc_netem_gimodel)) { 935 pr_info("netem: incorrect gi model size\n"); 936 return -EINVAL; 937 } 938 939 q->loss_model = CLG_4_STATES; 940 941 q->clg.state = TX_IN_GAP_PERIOD; 942 q->clg.a1 = gi->p13; 943 q->clg.a2 = gi->p31; 944 q->clg.a3 = gi->p32; 945 q->clg.a4 = gi->p14; 946 q->clg.a5 = gi->p23; 947 break; 948 } 949 950 case NETEM_LOSS_GE: { 951 const struct tc_netem_gemodel *ge = nla_data(la); 952 953 if (nla_len(la) < sizeof(struct tc_netem_gemodel)) { 954 pr_info("netem: incorrect ge model size\n"); 955 return -EINVAL; 956 } 957 958 q->loss_model = CLG_GILB_ELL; 959 q->clg.state = GOOD_STATE; 960 q->clg.a1 = ge->p; 961 q->clg.a2 = ge->r; 962 q->clg.a3 = ge->h; 963 q->clg.a4 = ge->k1; 964 break; 965 } 966 967 default: 968 pr_info("netem: unknown loss type %u\n", type); 969 return -EINVAL; 970 } 971 } 972 973 return 0; 974 } 975 976 static const struct nla_policy netem_policy[TCA_NETEM_MAX + 1] = { 977 [TCA_NETEM_CORR] = { .len = sizeof(struct tc_netem_corr) }, 978 [TCA_NETEM_REORDER] = { .len = sizeof(struct tc_netem_reorder) }, 979 [TCA_NETEM_CORRUPT] = { .len = sizeof(struct tc_netem_corrupt) }, 980 [TCA_NETEM_RATE] = { .len = sizeof(struct tc_netem_rate) }, 981 [TCA_NETEM_LOSS] = { .type = NLA_NESTED }, 982 [TCA_NETEM_ECN] = { .type = NLA_U32 }, 983 [TCA_NETEM_RATE64] = { .type = NLA_U64 }, 984 [TCA_NETEM_LATENCY64] = { .type = NLA_S64 }, 985 [TCA_NETEM_JITTER64] = { .type = NLA_S64 }, 986 [TCA_NETEM_SLOT] = { .len = sizeof(struct tc_netem_slot) }, 987 [TCA_NETEM_PRNG_SEED] = { .type = NLA_U64 }, 988 }; 989 990 static int parse_attr(struct nlattr *tb[], int maxtype, struct nlattr *nla, 991 const struct nla_policy *policy, int len) 992 { 993 int nested_len = nla_len(nla) - NLA_ALIGN(len); 994 995 if (nested_len < 0) { 996 pr_info("netem: invalid attributes len %d\n", nested_len); 997 return -EINVAL; 998 } 999 1000 if (nested_len >= nla_attr_size(0)) 1001 return nla_parse_deprecated(tb, maxtype, 1002 nla_data(nla) + NLA_ALIGN(len), 1003 nested_len, policy, NULL); 1004 1005 memset(tb, 0, sizeof(struct nlattr *) * (maxtype + 1)); 1006 return 0; 1007 } 1008 1009 /* Parse netlink message to set options */ 1010 static int netem_change(struct Qdisc *sch, struct nlattr *opt, 1011 struct netlink_ext_ack *extack) 1012 { 1013 struct netem_sched_data *q = qdisc_priv(sch); 1014 struct nlattr *tb[TCA_NETEM_MAX + 1]; 1015 struct disttable *delay_dist = NULL; 1016 struct disttable *slot_dist = NULL; 1017 struct tc_netem_qopt *qopt; 1018 struct clgstate old_clg; 1019 int old_loss_model = CLG_RANDOM; 1020 int ret; 1021 1022 qopt = nla_data(opt); 1023 ret = parse_attr(tb, TCA_NETEM_MAX, opt, netem_policy, sizeof(*qopt)); 1024 if (ret < 0) 1025 return ret; 1026 1027 if (tb[TCA_NETEM_DELAY_DIST]) { 1028 ret = get_dist_table(&delay_dist, tb[TCA_NETEM_DELAY_DIST]); 1029 if (ret) 1030 goto table_free; 1031 } 1032 1033 if (tb[TCA_NETEM_SLOT_DIST]) { 1034 ret = get_dist_table(&slot_dist, tb[TCA_NETEM_SLOT_DIST]); 1035 if (ret) 1036 goto table_free; 1037 } 1038 1039 if (tb[TCA_NETEM_SLOT]) { 1040 ret = validate_slot(tb[TCA_NETEM_SLOT], extack); 1041 if (ret) 1042 goto table_free; 1043 } 1044 1045 if (tb[TCA_NETEM_LATENCY64]) { 1046 ret = validate_time(tb[TCA_NETEM_LATENCY64], "latency", extack); 1047 if (ret) 1048 goto table_free; 1049 } 1050 1051 if (tb[TCA_NETEM_JITTER64]) { 1052 ret = validate_time(tb[TCA_NETEM_JITTER64], "jitter", extack); 1053 if (ret) 1054 goto table_free; 1055 } 1056 1057 sch_tree_lock(sch); 1058 /* backup q->clg and q->loss_model */ 1059 old_clg = q->clg; 1060 old_loss_model = q->loss_model; 1061 1062 if (tb[TCA_NETEM_LOSS]) { 1063 ret = get_loss_clg(q, tb[TCA_NETEM_LOSS]); 1064 if (ret) { 1065 q->loss_model = old_loss_model; 1066 q->clg = old_clg; 1067 goto unlock; 1068 } 1069 } else { 1070 q->loss_model = CLG_RANDOM; 1071 } 1072 1073 if (delay_dist) 1074 swap(q->delay_dist, delay_dist); 1075 if (slot_dist) 1076 swap(q->slot_dist, slot_dist); 1077 sch->limit = qopt->limit; 1078 1079 q->latency = PSCHED_TICKS2NS(qopt->latency); 1080 q->jitter = PSCHED_TICKS2NS(qopt->jitter); 1081 q->limit = qopt->limit; 1082 q->gap = qopt->gap; 1083 q->counter = 0; 1084 q->loss = qopt->loss; 1085 q->duplicate = qopt->duplicate; 1086 1087 /* for compatibility with earlier versions. 1088 * if gap is set, need to assume 100% probability 1089 */ 1090 if (q->gap) 1091 q->reorder = ~0; 1092 1093 if (tb[TCA_NETEM_CORR]) 1094 get_correlation(q, tb[TCA_NETEM_CORR]); 1095 1096 if (tb[TCA_NETEM_REORDER]) 1097 get_reorder(q, tb[TCA_NETEM_REORDER]); 1098 1099 if (tb[TCA_NETEM_CORRUPT]) 1100 get_corrupt(q, tb[TCA_NETEM_CORRUPT]); 1101 1102 if (tb[TCA_NETEM_RATE]) 1103 get_rate(q, tb[TCA_NETEM_RATE]); 1104 1105 if (tb[TCA_NETEM_RATE64]) 1106 q->rate = max_t(u64, q->rate, 1107 nla_get_u64(tb[TCA_NETEM_RATE64])); 1108 1109 if (tb[TCA_NETEM_LATENCY64]) 1110 q->latency = nla_get_s64(tb[TCA_NETEM_LATENCY64]); 1111 1112 if (tb[TCA_NETEM_JITTER64]) 1113 q->jitter = nla_get_s64(tb[TCA_NETEM_JITTER64]); 1114 1115 if (tb[TCA_NETEM_ECN]) 1116 q->ecn = nla_get_u32(tb[TCA_NETEM_ECN]); 1117 1118 if (tb[TCA_NETEM_SLOT]) 1119 get_slot(q, tb[TCA_NETEM_SLOT]); 1120 1121 /* capping jitter to the range acceptable by tabledist() */ 1122 q->jitter = min_t(s64, abs(q->jitter), INT_MAX); 1123 1124 if (tb[TCA_NETEM_PRNG_SEED]) { 1125 q->prng.seed = nla_get_u64(tb[TCA_NETEM_PRNG_SEED]); 1126 prandom_seed_state(&q->prng.prng_state, q->prng.seed); 1127 } 1128 1129 unlock: 1130 sch_tree_unlock(sch); 1131 1132 table_free: 1133 dist_free(delay_dist); 1134 dist_free(slot_dist); 1135 return ret; 1136 } 1137 1138 static int netem_init(struct Qdisc *sch, struct nlattr *opt, 1139 struct netlink_ext_ack *extack) 1140 { 1141 struct netem_sched_data *q = qdisc_priv(sch); 1142 int ret; 1143 1144 qdisc_watchdog_init(&q->watchdog, sch); 1145 1146 if (!opt) 1147 return -EINVAL; 1148 1149 q->loss_model = CLG_RANDOM; 1150 q->prng.seed = get_random_u64(); 1151 prandom_seed_state(&q->prng.prng_state, q->prng.seed); 1152 1153 ret = netem_change(sch, opt, extack); 1154 if (ret) 1155 pr_info("netem: change failed\n"); 1156 return ret; 1157 } 1158 1159 static void netem_destroy(struct Qdisc *sch) 1160 { 1161 struct netem_sched_data *q = qdisc_priv(sch); 1162 1163 qdisc_watchdog_cancel(&q->watchdog); 1164 if (q->qdisc) 1165 qdisc_put(q->qdisc); 1166 dist_free(q->delay_dist); 1167 dist_free(q->slot_dist); 1168 } 1169 1170 static int dump_loss_model(const struct netem_sched_data *q, 1171 struct sk_buff *skb) 1172 { 1173 struct nlattr *nest; 1174 1175 nest = nla_nest_start_noflag(skb, TCA_NETEM_LOSS); 1176 if (nest == NULL) 1177 goto nla_put_failure; 1178 1179 switch (q->loss_model) { 1180 case CLG_RANDOM: 1181 /* legacy loss model */ 1182 nla_nest_cancel(skb, nest); 1183 return 0; /* no data */ 1184 1185 case CLG_4_STATES: { 1186 struct tc_netem_gimodel gi = { 1187 .p13 = q->clg.a1, 1188 .p31 = q->clg.a2, 1189 .p32 = q->clg.a3, 1190 .p14 = q->clg.a4, 1191 .p23 = q->clg.a5, 1192 }; 1193 1194 if (nla_put(skb, NETEM_LOSS_GI, sizeof(gi), &gi)) 1195 goto nla_put_failure; 1196 break; 1197 } 1198 case CLG_GILB_ELL: { 1199 struct tc_netem_gemodel ge = { 1200 .p = q->clg.a1, 1201 .r = q->clg.a2, 1202 .h = q->clg.a3, 1203 .k1 = q->clg.a4, 1204 }; 1205 1206 if (nla_put(skb, NETEM_LOSS_GE, sizeof(ge), &ge)) 1207 goto nla_put_failure; 1208 break; 1209 } 1210 } 1211 1212 nla_nest_end(skb, nest); 1213 return 0; 1214 1215 nla_put_failure: 1216 nla_nest_cancel(skb, nest); 1217 return -1; 1218 } 1219 1220 static int netem_dump(struct Qdisc *sch, struct sk_buff *skb) 1221 { 1222 const struct netem_sched_data *q = qdisc_priv(sch); 1223 struct nlattr *nla = (struct nlattr *) skb_tail_pointer(skb); 1224 struct tc_netem_qopt qopt; 1225 struct tc_netem_corr cor; 1226 struct tc_netem_reorder reorder; 1227 struct tc_netem_corrupt corrupt; 1228 struct tc_netem_rate rate; 1229 struct tc_netem_slot slot; 1230 1231 qopt.latency = min_t(psched_time_t, PSCHED_NS2TICKS(q->latency), 1232 UINT_MAX); 1233 qopt.jitter = min_t(psched_time_t, PSCHED_NS2TICKS(q->jitter), 1234 UINT_MAX); 1235 qopt.limit = q->limit; 1236 qopt.loss = q->loss; 1237 qopt.gap = q->gap; 1238 qopt.duplicate = q->duplicate; 1239 if (nla_put(skb, TCA_OPTIONS, sizeof(qopt), &qopt)) 1240 goto nla_put_failure; 1241 1242 if (nla_put(skb, TCA_NETEM_LATENCY64, sizeof(q->latency), &q->latency)) 1243 goto nla_put_failure; 1244 1245 if (nla_put(skb, TCA_NETEM_JITTER64, sizeof(q->jitter), &q->jitter)) 1246 goto nla_put_failure; 1247 1248 cor.delay_corr = q->delay_cor.rho; 1249 cor.loss_corr = q->loss_cor.rho; 1250 cor.dup_corr = q->dup_cor.rho; 1251 if (nla_put(skb, TCA_NETEM_CORR, sizeof(cor), &cor)) 1252 goto nla_put_failure; 1253 1254 reorder.probability = q->reorder; 1255 reorder.correlation = q->reorder_cor.rho; 1256 if (nla_put(skb, TCA_NETEM_REORDER, sizeof(reorder), &reorder)) 1257 goto nla_put_failure; 1258 1259 corrupt.probability = q->corrupt; 1260 corrupt.correlation = q->corrupt_cor.rho; 1261 if (nla_put(skb, TCA_NETEM_CORRUPT, sizeof(corrupt), &corrupt)) 1262 goto nla_put_failure; 1263 1264 if (q->rate >= (1ULL << 32)) { 1265 if (nla_put_u64_64bit(skb, TCA_NETEM_RATE64, q->rate, 1266 TCA_NETEM_PAD)) 1267 goto nla_put_failure; 1268 rate.rate = ~0U; 1269 } else { 1270 rate.rate = q->rate; 1271 } 1272 rate.packet_overhead = q->packet_overhead; 1273 rate.cell_size = q->cell_size; 1274 rate.cell_overhead = q->cell_overhead; 1275 if (nla_put(skb, TCA_NETEM_RATE, sizeof(rate), &rate)) 1276 goto nla_put_failure; 1277 1278 if (q->ecn && nla_put_u32(skb, TCA_NETEM_ECN, q->ecn)) 1279 goto nla_put_failure; 1280 1281 if (dump_loss_model(q, skb) != 0) 1282 goto nla_put_failure; 1283 1284 if (q->slot_config.min_delay | q->slot_config.max_delay | 1285 q->slot_config.dist_jitter) { 1286 slot = q->slot_config; 1287 if (slot.max_packets == INT_MAX) 1288 slot.max_packets = 0; 1289 if (slot.max_bytes == INT_MAX) 1290 slot.max_bytes = 0; 1291 if (nla_put(skb, TCA_NETEM_SLOT, sizeof(slot), &slot)) 1292 goto nla_put_failure; 1293 } 1294 1295 if (nla_put_u64_64bit(skb, TCA_NETEM_PRNG_SEED, q->prng.seed, 1296 TCA_NETEM_PAD)) 1297 goto nla_put_failure; 1298 1299 return nla_nest_end(skb, nla); 1300 1301 nla_put_failure: 1302 nlmsg_trim(skb, nla); 1303 return -1; 1304 } 1305 1306 static int netem_dump_class(struct Qdisc *sch, unsigned long cl, 1307 struct sk_buff *skb, struct tcmsg *tcm) 1308 { 1309 struct netem_sched_data *q = qdisc_priv(sch); 1310 1311 if (cl != 1 || !q->qdisc) /* only one class */ 1312 return -ENOENT; 1313 1314 tcm->tcm_handle |= TC_H_MIN(1); 1315 tcm->tcm_info = q->qdisc->handle; 1316 1317 return 0; 1318 } 1319 1320 static int netem_graft(struct Qdisc *sch, unsigned long arg, struct Qdisc *new, 1321 struct Qdisc **old, struct netlink_ext_ack *extack) 1322 { 1323 struct netem_sched_data *q = qdisc_priv(sch); 1324 1325 *old = qdisc_replace(sch, new, &q->qdisc); 1326 return 0; 1327 } 1328 1329 static struct Qdisc *netem_leaf(struct Qdisc *sch, unsigned long arg) 1330 { 1331 struct netem_sched_data *q = qdisc_priv(sch); 1332 return q->qdisc; 1333 } 1334 1335 static unsigned long netem_find(struct Qdisc *sch, u32 classid) 1336 { 1337 return 1; 1338 } 1339 1340 static void netem_walk(struct Qdisc *sch, struct qdisc_walker *walker) 1341 { 1342 if (!walker->stop) { 1343 if (!tc_qdisc_stats_dump(sch, 1, walker)) 1344 return; 1345 } 1346 } 1347 1348 static const struct Qdisc_class_ops netem_class_ops = { 1349 .graft = netem_graft, 1350 .leaf = netem_leaf, 1351 .find = netem_find, 1352 .walk = netem_walk, 1353 .dump = netem_dump_class, 1354 }; 1355 1356 static struct Qdisc_ops netem_qdisc_ops __read_mostly = { 1357 .id = "netem", 1358 .cl_ops = &netem_class_ops, 1359 .priv_size = sizeof(struct netem_sched_data), 1360 .enqueue = netem_enqueue, 1361 .dequeue = netem_dequeue, 1362 .peek = qdisc_peek_dequeued, 1363 .init = netem_init, 1364 .reset = netem_reset, 1365 .destroy = netem_destroy, 1366 .change = netem_change, 1367 .dump = netem_dump, 1368 .owner = THIS_MODULE, 1369 }; 1370 MODULE_ALIAS_NET_SCH("netem"); 1371 1372 1373 static int __init netem_module_init(void) 1374 { 1375 pr_info("netem: version " VERSION "\n"); 1376 return register_qdisc(&netem_qdisc_ops); 1377 } 1378 static void __exit netem_module_exit(void) 1379 { 1380 unregister_qdisc(&netem_qdisc_ops); 1381 } 1382 module_init(netem_module_init) 1383 module_exit(netem_module_exit) 1384 MODULE_LICENSE("GPL"); 1385 MODULE_DESCRIPTION("Network characteristics emulator qdisc"); 1386