Linux Audio

Check our new training course

Loading...
v6.8
   1// SPDX-License-Identifier: GPL-2.0-only
   2/****************************************************************************
   3 * Driver for Solarflare network controllers and boards
   4 * Copyright 2019 Solarflare Communications Inc.
   5 * Copyright 2020-2022 Xilinx Inc.
   6 *
   7 * This program is free software; you can redistribute it and/or modify it
   8 * under the terms of the GNU General Public License version 2 as published
   9 * by the Free Software Foundation, incorporated herein by reference.
  10 */
  11
  12#include <linux/rhashtable.h>
  13#include "ef100_nic.h"
  14#include "mae.h"
  15#include "mcdi.h"
  16#include "mcdi_pcol.h"
  17#include "mcdi_pcol_mae.h"
  18#include "tc_encap_actions.h"
  19#include "tc_conntrack.h"
  20
  21int efx_mae_allocate_mport(struct efx_nic *efx, u32 *id, u32 *label)
  22{
  23	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MPORT_ALLOC_ALIAS_OUT_LEN);
  24	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_ALLOC_ALIAS_IN_LEN);
  25	size_t outlen;
  26	int rc;
  27
  28	if (WARN_ON_ONCE(!id))
  29		return -EINVAL;
  30	if (WARN_ON_ONCE(!label))
  31		return -EINVAL;
  32
  33	MCDI_SET_DWORD(inbuf, MAE_MPORT_ALLOC_ALIAS_IN_TYPE,
  34		       MC_CMD_MAE_MPORT_ALLOC_ALIAS_IN_MPORT_TYPE_ALIAS);
  35	MCDI_SET_DWORD(inbuf, MAE_MPORT_ALLOC_ALIAS_IN_DELIVER_MPORT,
  36		       MAE_MPORT_SELECTOR_ASSIGNED);
  37	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_ALLOC, inbuf, sizeof(inbuf),
  38			  outbuf, sizeof(outbuf), &outlen);
  39	if (rc)
  40		return rc;
  41	if (outlen < sizeof(outbuf))
  42		return -EIO;
  43	*id = MCDI_DWORD(outbuf, MAE_MPORT_ALLOC_ALIAS_OUT_MPORT_ID);
  44	*label = MCDI_DWORD(outbuf, MAE_MPORT_ALLOC_ALIAS_OUT_LABEL);
  45	return 0;
  46}
  47
  48int efx_mae_free_mport(struct efx_nic *efx, u32 id)
  49{
  50	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_FREE_IN_LEN);
  51
  52	BUILD_BUG_ON(MC_CMD_MAE_MPORT_FREE_OUT_LEN);
  53	MCDI_SET_DWORD(inbuf, MAE_MPORT_FREE_IN_MPORT_ID, id);
  54	return efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_FREE, inbuf, sizeof(inbuf),
  55			    NULL, 0, NULL);
  56}
  57
  58void efx_mae_mport_wire(struct efx_nic *efx, u32 *out)
  59{
  60	efx_dword_t mport;
  61
  62	EFX_POPULATE_DWORD_2(mport,
  63			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_PPORT,
  64			     MAE_MPORT_SELECTOR_PPORT_ID, efx->port_num);
  65	*out = EFX_DWORD_VAL(mport);
  66}
  67
  68void efx_mae_mport_uplink(struct efx_nic *efx __always_unused, u32 *out)
  69{
  70	efx_dword_t mport;
  71
  72	EFX_POPULATE_DWORD_3(mport,
  73			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_FUNC,
  74			     MAE_MPORT_SELECTOR_FUNC_PF_ID, MAE_MPORT_SELECTOR_FUNC_PF_ID_CALLER,
  75			     MAE_MPORT_SELECTOR_FUNC_VF_ID, MAE_MPORT_SELECTOR_FUNC_VF_ID_NULL);
  76	*out = EFX_DWORD_VAL(mport);
  77}
  78
  79void efx_mae_mport_vf(struct efx_nic *efx __always_unused, u32 vf_id, u32 *out)
  80{
  81	efx_dword_t mport;
  82
  83	EFX_POPULATE_DWORD_3(mport,
  84			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_FUNC,
  85			     MAE_MPORT_SELECTOR_FUNC_PF_ID, MAE_MPORT_SELECTOR_FUNC_PF_ID_CALLER,
  86			     MAE_MPORT_SELECTOR_FUNC_VF_ID, vf_id);
  87	*out = EFX_DWORD_VAL(mport);
  88}
  89
  90/* Constructs an mport selector from an mport ID, because they're not the same */
  91void efx_mae_mport_mport(struct efx_nic *efx __always_unused, u32 mport_id, u32 *out)
  92{
  93	efx_dword_t mport;
  94
  95	EFX_POPULATE_DWORD_2(mport,
  96			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_MPORT_ID,
  97			     MAE_MPORT_SELECTOR_MPORT_ID, mport_id);
  98	*out = EFX_DWORD_VAL(mport);
  99}
 100
 101/* id is really only 24 bits wide */
 102int efx_mae_fw_lookup_mport(struct efx_nic *efx, u32 selector, u32 *id)
 103{
 104	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MPORT_LOOKUP_OUT_LEN);
 105	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_LOOKUP_IN_LEN);
 106	size_t outlen;
 107	int rc;
 108
 109	MCDI_SET_DWORD(inbuf, MAE_MPORT_LOOKUP_IN_MPORT_SELECTOR, selector);
 110	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_LOOKUP, inbuf, sizeof(inbuf),
 111			  outbuf, sizeof(outbuf), &outlen);
 112	if (rc)
 113		return rc;
 114	if (outlen < sizeof(outbuf))
 115		return -EIO;
 116	*id = MCDI_DWORD(outbuf, MAE_MPORT_LOOKUP_OUT_MPORT_ID);
 117	return 0;
 118}
 119
 120int efx_mae_start_counters(struct efx_nic *efx, struct efx_rx_queue *rx_queue)
 121{
 122	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTERS_STREAM_START_V2_IN_LEN);
 123	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTERS_STREAM_START_OUT_LEN);
 124	u32 out_flags;
 125	size_t outlen;
 126	int rc;
 127
 128	MCDI_SET_WORD(inbuf, MAE_COUNTERS_STREAM_START_V2_IN_QID,
 129		      efx_rx_queue_index(rx_queue));
 130	MCDI_SET_WORD(inbuf, MAE_COUNTERS_STREAM_START_V2_IN_PACKET_SIZE,
 131		      efx->net_dev->mtu);
 132	MCDI_SET_DWORD(inbuf, MAE_COUNTERS_STREAM_START_V2_IN_COUNTER_TYPES_MASK,
 133		       BIT(MAE_COUNTER_TYPE_AR) | BIT(MAE_COUNTER_TYPE_CT) |
 134		       BIT(MAE_COUNTER_TYPE_OR));
 135	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTERS_STREAM_START,
 136			  inbuf, sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
 137	if (rc)
 138		return rc;
 139	if (outlen < sizeof(outbuf))
 140		return -EIO;
 141	out_flags = MCDI_DWORD(outbuf, MAE_COUNTERS_STREAM_START_OUT_FLAGS);
 142	if (out_flags & BIT(MC_CMD_MAE_COUNTERS_STREAM_START_OUT_USES_CREDITS_OFST)) {
 143		netif_dbg(efx, drv, efx->net_dev,
 144			  "MAE counter stream uses credits\n");
 145		rx_queue->grant_credits = true;
 146		out_flags &= ~BIT(MC_CMD_MAE_COUNTERS_STREAM_START_OUT_USES_CREDITS_OFST);
 147	}
 148	if (out_flags) {
 149		netif_err(efx, drv, efx->net_dev,
 150			  "MAE counter stream start: unrecognised flags %x\n",
 151			  out_flags);
 152		goto out_stop;
 153	}
 154	return 0;
 155out_stop:
 156	efx_mae_stop_counters(efx, rx_queue);
 157	return -EOPNOTSUPP;
 158}
 159
 160static bool efx_mae_counters_flushed(u32 *flush_gen, u32 *seen_gen)
 161{
 162	int i;
 163
 164	for (i = 0; i < EFX_TC_COUNTER_TYPE_MAX; i++)
 165		if ((s32)(flush_gen[i] - seen_gen[i]) > 0)
 166			return false;
 167	return true;
 168}
 169
 170int efx_mae_stop_counters(struct efx_nic *efx, struct efx_rx_queue *rx_queue)
 171{
 172	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTERS_STREAM_STOP_V2_OUT_LENMAX);
 173	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTERS_STREAM_STOP_IN_LEN);
 174	size_t outlen;
 175	int rc, i;
 176
 177	MCDI_SET_WORD(inbuf, MAE_COUNTERS_STREAM_STOP_IN_QID,
 178		      efx_rx_queue_index(rx_queue));
 179	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTERS_STREAM_STOP,
 180			  inbuf, sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
 181
 182	if (rc)
 183		return rc;
 184
 185	netif_dbg(efx, drv, efx->net_dev, "Draining counters:\n");
 186	/* Only process received generation counts */
 187	for (i = 0; (i < (outlen / 4)) && (i < EFX_TC_COUNTER_TYPE_MAX); i++) {
 188		efx->tc->flush_gen[i] = MCDI_ARRAY_DWORD(outbuf,
 189							 MAE_COUNTERS_STREAM_STOP_V2_OUT_GENERATION_COUNT,
 190							 i);
 191		netif_dbg(efx, drv, efx->net_dev,
 192			  "\ttype %u, awaiting gen %u\n", i,
 193			  efx->tc->flush_gen[i]);
 194	}
 195
 196	efx->tc->flush_counters = true;
 197
 198	/* Drain can take up to 2 seconds owing to FWRIVERHD-2884; whatever
 199	 * timeout we use, that delay is added to unload on nonresponsive
 200	 * hardware, so 2500ms seems like a reasonable compromise.
 201	 */
 202	if (!wait_event_timeout(efx->tc->flush_wq,
 203				efx_mae_counters_flushed(efx->tc->flush_gen,
 204							 efx->tc->seen_gen),
 205				msecs_to_jiffies(2500)))
 206		netif_warn(efx, drv, efx->net_dev,
 207			   "Failed to drain counters RXQ, FW may be unhappy\n");
 208
 209	efx->tc->flush_counters = false;
 210
 211	return rc;
 212}
 213
 214void efx_mae_counters_grant_credits(struct work_struct *work)
 215{
 216	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTERS_STREAM_GIVE_CREDITS_IN_LEN);
 217	struct efx_rx_queue *rx_queue = container_of(work, struct efx_rx_queue,
 218						     grant_work);
 219	struct efx_nic *efx = rx_queue->efx;
 220	unsigned int credits;
 221
 222	BUILD_BUG_ON(MC_CMD_MAE_COUNTERS_STREAM_GIVE_CREDITS_OUT_LEN);
 223	credits = READ_ONCE(rx_queue->notified_count) - rx_queue->granted_count;
 224	MCDI_SET_DWORD(inbuf, MAE_COUNTERS_STREAM_GIVE_CREDITS_IN_NUM_CREDITS,
 225		       credits);
 226	if (!efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTERS_STREAM_GIVE_CREDITS,
 227			  inbuf, sizeof(inbuf), NULL, 0, NULL))
 228		rx_queue->granted_count += credits;
 229}
 230
 231static int efx_mae_table_get_desc(struct efx_nic *efx,
 232				  struct efx_tc_table_desc *desc,
 233				  u32 table_id)
 234{
 235	MCDI_DECLARE_BUF(outbuf, MC_CMD_TABLE_DESCRIPTOR_OUT_LEN(16));
 236	MCDI_DECLARE_BUF(inbuf, MC_CMD_TABLE_DESCRIPTOR_IN_LEN);
 237	unsigned int offset = 0, i;
 238	size_t outlen;
 239	int rc;
 240
 241	memset(desc, 0, sizeof(*desc));
 242
 243	MCDI_SET_DWORD(inbuf, TABLE_DESCRIPTOR_IN_TABLE_ID, table_id);
 244more:
 245	MCDI_SET_DWORD(inbuf, TABLE_DESCRIPTOR_IN_FIRST_FIELDS_INDEX, offset);
 246	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_DESCRIPTOR, inbuf, sizeof(inbuf),
 247			  outbuf, sizeof(outbuf), &outlen);
 248	if (rc)
 249		goto fail;
 250	if (outlen < MC_CMD_TABLE_DESCRIPTOR_OUT_LEN(1)) {
 251		rc = -EIO;
 252		goto fail;
 253	}
 254	if (!offset) { /* first iteration: get metadata */
 255		desc->type = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_TYPE);
 256		desc->key_width = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_KEY_WIDTH);
 257		desc->resp_width = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_RESP_WIDTH);
 258		desc->n_keys = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_N_KEY_FIELDS);
 259		desc->n_resps = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_N_RESP_FIELDS);
 260		desc->n_prios = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_N_PRIORITIES);
 261		desc->flags = MCDI_BYTE(outbuf, TABLE_DESCRIPTOR_OUT_FLAGS);
 262		rc = -EOPNOTSUPP;
 263		if (desc->flags)
 264			goto fail;
 265		desc->scheme = MCDI_BYTE(outbuf, TABLE_DESCRIPTOR_OUT_SCHEME);
 266		if (desc->scheme)
 267			goto fail;
 268		rc = -ENOMEM;
 269		desc->keys = kcalloc(desc->n_keys,
 270				     sizeof(struct efx_tc_table_field_fmt),
 271				     GFP_KERNEL);
 272		if (!desc->keys)
 273			goto fail;
 274		desc->resps = kcalloc(desc->n_resps,
 275				      sizeof(struct efx_tc_table_field_fmt),
 276				      GFP_KERNEL);
 277		if (!desc->resps)
 278			goto fail;
 279	}
 280	/* FW could have returned more than the 16 field_descrs we
 281	 * made room for in our outbuf
 282	 */
 283	outlen = min(outlen, sizeof(outbuf));
 284	for (i = 0; i + offset < desc->n_keys + desc->n_resps; i++) {
 285		struct efx_tc_table_field_fmt *field;
 286		MCDI_DECLARE_STRUCT_PTR(fdesc);
 287
 288		if (outlen < MC_CMD_TABLE_DESCRIPTOR_OUT_LEN(i + 1)) {
 289			offset += i;
 290			goto more;
 291		}
 292		if (i + offset < desc->n_keys)
 293			field = desc->keys + i + offset;
 294		else
 295			field = desc->resps + (i + offset - desc->n_keys);
 296		fdesc = MCDI_ARRAY_STRUCT_PTR(outbuf,
 297					      TABLE_DESCRIPTOR_OUT_FIELDS, i);
 298		field->field_id = MCDI_STRUCT_WORD(fdesc,
 299						   TABLE_FIELD_DESCR_FIELD_ID);
 300		field->lbn = MCDI_STRUCT_WORD(fdesc, TABLE_FIELD_DESCR_LBN);
 301		field->width = MCDI_STRUCT_WORD(fdesc, TABLE_FIELD_DESCR_WIDTH);
 302		field->masking = MCDI_STRUCT_BYTE(fdesc, TABLE_FIELD_DESCR_MASK_TYPE);
 303		field->scheme = MCDI_STRUCT_BYTE(fdesc, TABLE_FIELD_DESCR_SCHEME);
 304	}
 305	return 0;
 306
 307fail:
 308	kfree(desc->keys);
 309	kfree(desc->resps);
 310	return rc;
 311}
 312
 313static int efx_mae_table_hook_find(u16 n_fields,
 314				   struct efx_tc_table_field_fmt *fields,
 315				   u16 field_id)
 316{
 317	unsigned int i;
 318
 319	for (i = 0; i < n_fields; i++) {
 320		if (fields[i].field_id == field_id)
 321			return i;
 322	}
 323	return -EPROTO;
 324}
 325
 326#define TABLE_FIND_KEY(_desc, _id)	\
 327	efx_mae_table_hook_find((_desc)->n_keys, (_desc)->keys, _id)
 328#define TABLE_FIND_RESP(_desc, _id)	\
 329	efx_mae_table_hook_find((_desc)->n_resps, (_desc)->resps, _id)
 330
 331#define TABLE_HOOK_KEY(_meta, _name, _mcdi_name)	({			\
 332	int _rc = TABLE_FIND_KEY(&_meta->desc, TABLE_FIELD_ID_##_mcdi_name);	\
 333										\
 334	if (_rc > U8_MAX)							\
 335		_rc = -EOPNOTSUPP;						\
 336	if (_rc >= 0) {								\
 337		_meta->keys._name##_idx = _rc;					\
 338		_rc = 0;							\
 339	}									\
 340	_rc;									\
 341})
 342#define TABLE_HOOK_RESP(_meta, _name, _mcdi_name)	({			\
 343	int _rc = TABLE_FIND_RESP(&_meta->desc, TABLE_FIELD_ID_##_mcdi_name);	\
 344										\
 345	if (_rc > U8_MAX)							\
 346		_rc = -EOPNOTSUPP;						\
 347	if (_rc >= 0) {								\
 348		_meta->resps._name##_idx = _rc;					\
 349		_rc = 0;							\
 350	}									\
 351	_rc;									\
 352})
 353
 354static int efx_mae_table_hook_ct(struct efx_nic *efx,
 355				 struct efx_tc_table_ct *meta_ct)
 356{
 357	int rc;
 358
 359	rc = TABLE_HOOK_KEY(meta_ct, eth_proto, ETHER_TYPE);
 360	if (rc)
 361		return rc;
 362	rc = TABLE_HOOK_KEY(meta_ct, ip_proto, IP_PROTO);
 363	if (rc)
 364		return rc;
 365	rc = TABLE_HOOK_KEY(meta_ct, src_ip, SRC_IP);
 366	if (rc)
 367		return rc;
 368	rc = TABLE_HOOK_KEY(meta_ct, dst_ip, DST_IP);
 369	if (rc)
 370		return rc;
 371	rc = TABLE_HOOK_KEY(meta_ct, l4_sport, SRC_PORT);
 372	if (rc)
 373		return rc;
 374	rc = TABLE_HOOK_KEY(meta_ct, l4_dport, DST_PORT);
 375	if (rc)
 376		return rc;
 377	rc = TABLE_HOOK_KEY(meta_ct, zone, DOMAIN);
 378	if (rc)
 379		return rc;
 380	rc = TABLE_HOOK_RESP(meta_ct, dnat, NAT_DIR);
 381	if (rc)
 382		return rc;
 383	rc = TABLE_HOOK_RESP(meta_ct, nat_ip, NAT_IP);
 384	if (rc)
 385		return rc;
 386	rc = TABLE_HOOK_RESP(meta_ct, l4_natport, NAT_PORT);
 387	if (rc)
 388		return rc;
 389	rc = TABLE_HOOK_RESP(meta_ct, mark, CT_MARK);
 390	if (rc)
 391		return rc;
 392	rc = TABLE_HOOK_RESP(meta_ct, counter_id, COUNTER_ID);
 393	if (rc)
 394		return rc;
 395	meta_ct->hooked = true;
 396	return 0;
 397}
 398
 399static void efx_mae_table_free_desc(struct efx_tc_table_desc *desc)
 400{
 401	kfree(desc->keys);
 402	kfree(desc->resps);
 403	memset(desc, 0, sizeof(*desc));
 404}
 405
 406static bool efx_mae_check_table_exists(struct efx_nic *efx, u32 tbl_req)
 407{
 408	MCDI_DECLARE_BUF(outbuf, MC_CMD_TABLE_LIST_OUT_LEN(16));
 409	MCDI_DECLARE_BUF(inbuf, MC_CMD_TABLE_LIST_IN_LEN);
 410	u32 tbl_id, tbl_total, tbl_cnt, pos = 0;
 411	size_t outlen, msg_max;
 412	bool ct_tbl = false;
 413	int rc, idx;
 414
 415	msg_max = sizeof(outbuf);
 416	efx->tc->meta_ct.hooked = false;
 417more:
 418	memset(outbuf, 0, sizeof(*outbuf));
 419	MCDI_SET_DWORD(inbuf, TABLE_LIST_IN_FIRST_TABLE_ID_INDEX, pos);
 420	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_LIST, inbuf, sizeof(inbuf), outbuf,
 421			  msg_max, &outlen);
 422	if (rc)
 423		return false;
 424
 425	if (outlen < MC_CMD_TABLE_LIST_OUT_LEN(1))
 426		return false;
 427
 428	tbl_total = MCDI_DWORD(outbuf, TABLE_LIST_OUT_N_TABLES);
 429	tbl_cnt = MC_CMD_TABLE_LIST_OUT_TABLE_ID_NUM(min(outlen, msg_max));
 430
 431	for (idx = 0; idx < tbl_cnt; idx++) {
 432		tbl_id = MCDI_ARRAY_DWORD(outbuf, TABLE_LIST_OUT_TABLE_ID, idx);
 433		if (tbl_id == tbl_req) {
 434			ct_tbl = true;
 435			break;
 436		}
 437	}
 438
 439	pos += tbl_cnt;
 440	if (!ct_tbl && pos < tbl_total)
 441		goto more;
 442
 443	return ct_tbl;
 444}
 445
 446int efx_mae_get_tables(struct efx_nic *efx)
 447{
 448	int rc;
 449
 450	efx->tc->meta_ct.hooked = false;
 451	if (efx_mae_check_table_exists(efx, TABLE_ID_CONNTRACK_TABLE)) {
 452		rc = efx_mae_table_get_desc(efx, &efx->tc->meta_ct.desc,
 453					    TABLE_ID_CONNTRACK_TABLE);
 454		if (rc) {
 455			pci_info(efx->pci_dev,
 456				 "FW does not support conntrack desc rc %d\n",
 457				 rc);
 458			return 0;
 459		}
 460
 461		rc = efx_mae_table_hook_ct(efx, &efx->tc->meta_ct);
 462		if (rc) {
 463			pci_info(efx->pci_dev,
 464				 "FW does not support conntrack hook rc %d\n",
 465				 rc);
 466			return 0;
 467		}
 468	} else {
 469		pci_info(efx->pci_dev,
 470			 "FW does not support conntrack table\n");
 471	}
 472	return 0;
 473}
 474
 475void efx_mae_free_tables(struct efx_nic *efx)
 476{
 477	efx_mae_table_free_desc(&efx->tc->meta_ct.desc);
 478	efx->tc->meta_ct.hooked = false;
 479}
 480
 481static int efx_mae_get_basic_caps(struct efx_nic *efx, struct mae_caps *caps)
 482{
 483	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_GET_CAPS_OUT_LEN);
 484	size_t outlen;
 485	int rc;
 486
 487	BUILD_BUG_ON(MC_CMD_MAE_GET_CAPS_IN_LEN);
 488
 489	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_GET_CAPS, NULL, 0, outbuf,
 490			  sizeof(outbuf), &outlen);
 491	if (rc)
 492		return rc;
 493	if (outlen < sizeof(outbuf))
 494		return -EIO;
 495	caps->match_field_count = MCDI_DWORD(outbuf, MAE_GET_CAPS_OUT_MATCH_FIELD_COUNT);
 496	caps->encap_types = MCDI_DWORD(outbuf, MAE_GET_CAPS_OUT_ENCAP_TYPES_SUPPORTED);
 497	caps->action_prios = MCDI_DWORD(outbuf, MAE_GET_CAPS_OUT_ACTION_PRIOS);
 498	return 0;
 499}
 500
 501static int efx_mae_get_rule_fields(struct efx_nic *efx, u32 cmd,
 502				   u8 *field_support)
 503{
 504	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_GET_AR_CAPS_OUT_LEN(MAE_NUM_FIELDS));
 505	MCDI_DECLARE_STRUCT_PTR(caps);
 506	unsigned int count;
 507	size_t outlen;
 508	int rc, i;
 509
 510	/* AR and OR caps MCDIs have identical layout, so we are using the
 511	 * same code for both.
 512	 */
 513	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_OUT_LEN(MAE_NUM_FIELDS) <
 514		     MC_CMD_MAE_GET_OR_CAPS_OUT_LEN(MAE_NUM_FIELDS));
 515	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_IN_LEN);
 516	BUILD_BUG_ON(MC_CMD_MAE_GET_OR_CAPS_IN_LEN);
 517
 518	rc = efx_mcdi_rpc(efx, cmd, NULL, 0, outbuf, sizeof(outbuf), &outlen);
 519	if (rc)
 520		return rc;
 521	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_OUT_COUNT_OFST !=
 522		     MC_CMD_MAE_GET_OR_CAPS_OUT_COUNT_OFST);
 523	count = MCDI_DWORD(outbuf, MAE_GET_AR_CAPS_OUT_COUNT);
 524	memset(field_support, MAE_FIELD_UNSUPPORTED, MAE_NUM_FIELDS);
 525	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_OUT_FIELD_FLAGS_OFST !=
 526		     MC_CMD_MAE_GET_OR_CAPS_OUT_FIELD_FLAGS_OFST);
 527	caps = _MCDI_DWORD(outbuf, MAE_GET_AR_CAPS_OUT_FIELD_FLAGS);
 528	/* We're only interested in the support status enum, not any other
 529	 * flags, so just extract that from each entry.
 530	 */
 531	for (i = 0; i < count; i++)
 532		if (i * sizeof(*outbuf) + MC_CMD_MAE_GET_AR_CAPS_OUT_FIELD_FLAGS_OFST < outlen)
 533			field_support[i] = EFX_DWORD_FIELD(caps[i], MAE_FIELD_FLAGS_SUPPORT_STATUS);
 534	return 0;
 535}
 536
 537int efx_mae_get_caps(struct efx_nic *efx, struct mae_caps *caps)
 538{
 539	int rc;
 540
 541	rc = efx_mae_get_basic_caps(efx, caps);
 542	if (rc)
 543		return rc;
 544	rc = efx_mae_get_rule_fields(efx, MC_CMD_MAE_GET_AR_CAPS,
 545				     caps->action_rule_fields);
 546	if (rc)
 547		return rc;
 548	return efx_mae_get_rule_fields(efx, MC_CMD_MAE_GET_OR_CAPS,
 549				       caps->outer_rule_fields);
 550}
 551
 552/* Bit twiddling:
 553 * Prefix: 1...110...0
 554 *      ~: 0...001...1
 555 *    + 1: 0...010...0 is power of two
 556 * so (~x) & ((~x) + 1) == 0.  Converse holds also.
 557 */
 558#define is_prefix_byte(_x)	!(((_x) ^ 0xff) & (((_x) ^ 0xff) + 1))
 559
 560enum mask_type { MASK_ONES, MASK_ZEROES, MASK_PREFIX, MASK_OTHER };
 561
 562static const char *mask_type_name(enum mask_type typ)
 563{
 564	switch (typ) {
 565	case MASK_ONES:
 566		return "all-1s";
 567	case MASK_ZEROES:
 568		return "all-0s";
 569	case MASK_PREFIX:
 570		return "prefix";
 571	case MASK_OTHER:
 572		return "arbitrary";
 573	default: /* can't happen */
 574		return "unknown";
 575	}
 576}
 577
 578/* Checks a (big-endian) bytestring is a bit prefix */
 579static enum mask_type classify_mask(const u8 *mask, size_t len)
 580{
 581	bool zeroes = true; /* All bits seen so far are zeroes */
 582	bool ones = true; /* All bits seen so far are ones */
 583	bool prefix = true; /* Valid prefix so far */
 584	size_t i;
 585
 586	for (i = 0; i < len; i++) {
 587		if (ones) {
 588			if (!is_prefix_byte(mask[i]))
 589				prefix = false;
 590		} else if (mask[i]) {
 591			prefix = false;
 592		}
 593		if (mask[i] != 0xff)
 594			ones = false;
 595		if (mask[i])
 596			zeroes = false;
 597	}
 598	if (ones)
 599		return MASK_ONES;
 600	if (zeroes)
 601		return MASK_ZEROES;
 602	if (prefix)
 603		return MASK_PREFIX;
 604	return MASK_OTHER;
 605}
 606
 607static int efx_mae_match_check_cap_typ(u8 support, enum mask_type typ)
 608{
 609	switch (support) {
 610	case MAE_FIELD_UNSUPPORTED:
 611	case MAE_FIELD_SUPPORTED_MATCH_NEVER:
 612		if (typ == MASK_ZEROES)
 613			return 0;
 614		return -EOPNOTSUPP;
 615	case MAE_FIELD_SUPPORTED_MATCH_OPTIONAL:
 616		if (typ == MASK_ZEROES)
 617			return 0;
 618		fallthrough;
 619	case MAE_FIELD_SUPPORTED_MATCH_ALWAYS:
 620		if (typ == MASK_ONES)
 621			return 0;
 622		return -EINVAL;
 623	case MAE_FIELD_SUPPORTED_MATCH_PREFIX:
 624		if (typ == MASK_OTHER)
 625			return -EOPNOTSUPP;
 626		return 0;
 627	case MAE_FIELD_SUPPORTED_MATCH_MASK:
 628		return 0;
 629	default:
 630		return -EIO;
 631	}
 632}
 633
 634/* Validate field mask against hardware capabilities.  Captures caller's 'rc' */
 635#define CHECK(_mcdi, _field)	({					       \
 636	enum mask_type typ = classify_mask((const u8 *)&mask->_field,	       \
 637					   sizeof(mask->_field));	       \
 638									       \
 639	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ ## _mcdi],\
 640					 typ);				       \
 641	if (rc)								       \
 642		NL_SET_ERR_MSG_FMT_MOD(extack,				       \
 643				       "No support for %s mask in field %s",   \
 644				       mask_type_name(typ), #_field);	       \
 645	rc;								       \
 646})
 647/* Booleans need special handling */
 648#define CHECK_BIT(_mcdi, _field)	({				       \
 649	enum mask_type typ = mask->_field ? MASK_ONES : MASK_ZEROES;	       \
 650									       \
 651	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ ## _mcdi],\
 652					 typ);				       \
 653	if (rc)								       \
 654		NL_SET_ERR_MSG_FMT_MOD(extack,				       \
 655				       "No support for %s mask in field %s",   \
 656				       mask_type_name(typ), #_field);	       \
 657	rc;								       \
 658})
 659
 660int efx_mae_match_check_caps(struct efx_nic *efx,
 661			     const struct efx_tc_match_fields *mask,
 662			     struct netlink_ext_ack *extack)
 663{
 664	const u8 *supported_fields = efx->tc->caps->action_rule_fields;
 665	__be32 ingress_port = cpu_to_be32(mask->ingress_port);
 666	enum mask_type ingress_port_mask_type;
 667	int rc;
 668
 669	/* Check for _PREFIX assumes big-endian, so we need to convert */
 670	ingress_port_mask_type = classify_mask((const u8 *)&ingress_port,
 671					       sizeof(ingress_port));
 672	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_INGRESS_PORT],
 673					 ingress_port_mask_type);
 674	if (rc) {
 675		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field ingress_port",
 676				       mask_type_name(ingress_port_mask_type));
 677		return rc;
 678	}
 679	if (CHECK(ETHER_TYPE, eth_proto) ||
 680	    CHECK(VLAN0_TCI, vlan_tci[0]) ||
 681	    CHECK(VLAN0_PROTO, vlan_proto[0]) ||
 682	    CHECK(VLAN1_TCI, vlan_tci[1]) ||
 683	    CHECK(VLAN1_PROTO, vlan_proto[1]) ||
 684	    CHECK(ETH_SADDR, eth_saddr) ||
 685	    CHECK(ETH_DADDR, eth_daddr) ||
 686	    CHECK(IP_PROTO, ip_proto) ||
 687	    CHECK(IP_TOS, ip_tos) ||
 688	    CHECK(IP_TTL, ip_ttl) ||
 689	    CHECK(SRC_IP4, src_ip) ||
 690	    CHECK(DST_IP4, dst_ip) ||
 691#ifdef CONFIG_IPV6
 692	    CHECK(SRC_IP6, src_ip6) ||
 693	    CHECK(DST_IP6, dst_ip6) ||
 694#endif
 695	    CHECK(L4_SPORT, l4_sport) ||
 696	    CHECK(L4_DPORT, l4_dport) ||
 697	    CHECK(TCP_FLAGS, tcp_flags) ||
 698	    CHECK_BIT(TCP_SYN_FIN_RST, tcp_syn_fin_rst) ||
 699	    CHECK_BIT(IS_IP_FRAG, ip_frag) ||
 700	    CHECK_BIT(IP_FIRST_FRAG, ip_firstfrag) ||
 701	    CHECK_BIT(DO_CT, ct_state_trk) ||
 702	    CHECK_BIT(CT_HIT, ct_state_est) ||
 703	    CHECK(CT_MARK, ct_mark) ||
 704	    CHECK(CT_DOMAIN, ct_zone) ||
 705	    CHECK(RECIRC_ID, recirc_id))
 706		return rc;
 707	/* Matches on outer fields are done in a separate hardware table,
 708	 * the Outer Rule table.  Thus the Action Rule merely does an
 709	 * exact match on Outer Rule ID if any outer field matches are
 710	 * present.  The exception is the VNI/VSID (enc_keyid), which is
 711	 * available to the Action Rule match iff the Outer Rule matched
 712	 * (and thus identified the encap protocol to use to extract it).
 713	 */
 714	if (efx_tc_match_is_encap(mask)) {
 715		rc = efx_mae_match_check_cap_typ(
 716				supported_fields[MAE_FIELD_OUTER_RULE_ID],
 717				MASK_ONES);
 718		if (rc) {
 719			NL_SET_ERR_MSG_MOD(extack, "No support for encap rule ID matches");
 720			return rc;
 721		}
 722		if (CHECK(ENC_VNET_ID, enc_keyid))
 723			return rc;
 724	} else if (mask->enc_keyid) {
 725		NL_SET_ERR_MSG_MOD(extack, "Match on enc_keyid requires other encap fields");
 726		return -EINVAL;
 727	}
 728	return 0;
 729}
 730
 731/* Checks for match fields not supported in LHS Outer Rules */
 732#define UNSUPPORTED(_field)	({					       \
 733	enum mask_type typ = classify_mask((const u8 *)&mask->_field,	       \
 734					   sizeof(mask->_field));	       \
 735									       \
 736	if (typ != MASK_ZEROES) {					       \
 737		NL_SET_ERR_MSG_MOD(extack, "Unsupported match field " #_field);\
 738		rc = -EOPNOTSUPP;					       \
 739	}								       \
 740	rc;								       \
 741})
 742#define UNSUPPORTED_BIT(_field)	({					       \
 743	if (mask->_field) {						       \
 744		NL_SET_ERR_MSG_MOD(extack, "Unsupported match field " #_field);\
 745		rc = -EOPNOTSUPP;					       \
 746	}								       \
 747	rc;								       \
 748})
 749
 750/* LHS rules are (normally) inserted in the Outer Rule table, which means
 751 * they use ENC_ fields in hardware to match regular (not enc_) fields from
 752 * &struct efx_tc_match_fields.
 753 */
 754int efx_mae_match_check_caps_lhs(struct efx_nic *efx,
 755				 const struct efx_tc_match_fields *mask,
 756				 struct netlink_ext_ack *extack)
 757{
 758	const u8 *supported_fields = efx->tc->caps->outer_rule_fields;
 759	__be32 ingress_port = cpu_to_be32(mask->ingress_port);
 760	enum mask_type ingress_port_mask_type;
 761	int rc;
 762
 763	/* Check for _PREFIX assumes big-endian, so we need to convert */
 764	ingress_port_mask_type = classify_mask((const u8 *)&ingress_port,
 765					       sizeof(ingress_port));
 766	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_INGRESS_PORT],
 767					 ingress_port_mask_type);
 768	if (rc) {
 769		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field %s\n",
 770				       mask_type_name(ingress_port_mask_type),
 771				       "ingress_port");
 772		return rc;
 773	}
 774	if (CHECK(ENC_ETHER_TYPE, eth_proto) ||
 775	    CHECK(ENC_VLAN0_TCI, vlan_tci[0]) ||
 776	    CHECK(ENC_VLAN0_PROTO, vlan_proto[0]) ||
 777	    CHECK(ENC_VLAN1_TCI, vlan_tci[1]) ||
 778	    CHECK(ENC_VLAN1_PROTO, vlan_proto[1]) ||
 779	    CHECK(ENC_ETH_SADDR, eth_saddr) ||
 780	    CHECK(ENC_ETH_DADDR, eth_daddr) ||
 781	    CHECK(ENC_IP_PROTO, ip_proto) ||
 782	    CHECK(ENC_IP_TOS, ip_tos) ||
 783	    CHECK(ENC_IP_TTL, ip_ttl) ||
 784	    CHECK_BIT(ENC_IP_FRAG, ip_frag) ||
 785	    UNSUPPORTED_BIT(ip_firstfrag) ||
 786	    CHECK(ENC_SRC_IP4, src_ip) ||
 787	    CHECK(ENC_DST_IP4, dst_ip) ||
 788#ifdef CONFIG_IPV6
 789	    CHECK(ENC_SRC_IP6, src_ip6) ||
 790	    CHECK(ENC_DST_IP6, dst_ip6) ||
 791#endif
 792	    CHECK(ENC_L4_SPORT, l4_sport) ||
 793	    CHECK(ENC_L4_DPORT, l4_dport) ||
 794	    UNSUPPORTED(tcp_flags) ||
 795	    CHECK_BIT(TCP_SYN_FIN_RST, tcp_syn_fin_rst))
 796		return rc;
 797	if (efx_tc_match_is_encap(mask)) {
 798		/* can't happen; disallowed for local rules, translated
 799		 * for foreign rules.
 800		 */
 801		NL_SET_ERR_MSG_MOD(extack, "Unexpected encap match in LHS rule");
 802		return -EOPNOTSUPP;
 803	}
 804	if (UNSUPPORTED(enc_keyid) ||
 805	    /* Can't filter on conntrack in LHS rules */
 806	    UNSUPPORTED_BIT(ct_state_trk) ||
 807	    UNSUPPORTED_BIT(ct_state_est) ||
 808	    UNSUPPORTED(ct_mark) ||
 809	    UNSUPPORTED(recirc_id))
 810		return rc;
 811	return 0;
 812}
 813#undef UNSUPPORTED
 814#undef CHECK_BIT
 815#undef CHECK
 816
 817#define CHECK(_mcdi)	({						       \
 818	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ ## _mcdi],\
 819					 MASK_ONES);			       \
 820	if (rc)								       \
 821		NL_SET_ERR_MSG_FMT_MOD(extack,				       \
 822				       "No support for field %s", #_mcdi);     \
 823	rc;								       \
 824})
 825/* Checks that the fields needed for encap-rule matches are supported by the
 826 * MAE.  All the fields are exact-match, except possibly ENC_IP_TOS.
 827 */
 828int efx_mae_check_encap_match_caps(struct efx_nic *efx, bool ipv6,
 829				   u8 ip_tos_mask, __be16 udp_sport_mask,
 830				   struct netlink_ext_ack *extack)
 831{
 832	u8 *supported_fields = efx->tc->caps->outer_rule_fields;
 833	enum mask_type typ;
 834	int rc;
 835
 836	if (CHECK(ENC_ETHER_TYPE))
 837		return rc;
 838	if (ipv6) {
 839		if (CHECK(ENC_SRC_IP6) ||
 840		    CHECK(ENC_DST_IP6))
 841			return rc;
 842	} else {
 843		if (CHECK(ENC_SRC_IP4) ||
 844		    CHECK(ENC_DST_IP4))
 845			return rc;
 846	}
 847	if (CHECK(ENC_L4_DPORT) ||
 848	    CHECK(ENC_IP_PROTO))
 849		return rc;
 850	typ = classify_mask((const u8 *)&udp_sport_mask, sizeof(udp_sport_mask));
 851	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ENC_L4_SPORT],
 852					 typ);
 853	if (rc) {
 854		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field %s",
 855				       mask_type_name(typ), "enc_src_port");
 856		return rc;
 857	}
 858	typ = classify_mask(&ip_tos_mask, sizeof(ip_tos_mask));
 859	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ENC_IP_TOS],
 860					 typ);
 861	if (rc) {
 862		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field %s",
 863				       mask_type_name(typ), "enc_ip_tos");
 864		return rc;
 865	}
 866	return 0;
 867}
 868#undef CHECK
 869
 870int efx_mae_check_encap_type_supported(struct efx_nic *efx, enum efx_encap_type typ)
 871{
 872	unsigned int bit;
 873
 874	switch (typ & EFX_ENCAP_TYPES_MASK) {
 875	case EFX_ENCAP_TYPE_VXLAN:
 876		bit = MC_CMD_MAE_GET_CAPS_OUT_ENCAP_TYPE_VXLAN_LBN;
 877		break;
 878	case EFX_ENCAP_TYPE_GENEVE:
 879		bit = MC_CMD_MAE_GET_CAPS_OUT_ENCAP_TYPE_GENEVE_LBN;
 880		break;
 881	default:
 882		return -EOPNOTSUPP;
 883	}
 884	if (efx->tc->caps->encap_types & BIT(bit))
 885		return 0;
 886	return -EOPNOTSUPP;
 887}
 888
 889int efx_mae_allocate_counter(struct efx_nic *efx, struct efx_tc_counter *cnt)
 890{
 891	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTER_ALLOC_OUT_LEN(1));
 892	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTER_ALLOC_V2_IN_LEN);
 893	size_t outlen;
 894	int rc;
 895
 896	if (!cnt)
 897		return -EINVAL;
 898
 899	MCDI_SET_DWORD(inbuf, MAE_COUNTER_ALLOC_V2_IN_REQUESTED_COUNT, 1);
 900	MCDI_SET_DWORD(inbuf, MAE_COUNTER_ALLOC_V2_IN_COUNTER_TYPE, cnt->type);
 901	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTER_ALLOC, inbuf, sizeof(inbuf),
 902			  outbuf, sizeof(outbuf), &outlen);
 903	if (rc)
 904		return rc;
 905	/* pcol says this can't happen, since count is 1 */
 906	if (outlen < sizeof(outbuf))
 907		return -EIO;
 908	cnt->fw_id = MCDI_DWORD(outbuf, MAE_COUNTER_ALLOC_OUT_COUNTER_ID);
 909	cnt->gen = MCDI_DWORD(outbuf, MAE_COUNTER_ALLOC_OUT_GENERATION_COUNT);
 910	return 0;
 911}
 912
 913int efx_mae_free_counter(struct efx_nic *efx, struct efx_tc_counter *cnt)
 914{
 915	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTER_FREE_OUT_LEN(1));
 916	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTER_FREE_V2_IN_LEN);
 917	size_t outlen;
 918	int rc;
 919
 920	MCDI_SET_DWORD(inbuf, MAE_COUNTER_FREE_V2_IN_COUNTER_ID_COUNT, 1);
 921	MCDI_SET_DWORD(inbuf, MAE_COUNTER_FREE_V2_IN_FREE_COUNTER_ID, cnt->fw_id);
 922	MCDI_SET_DWORD(inbuf, MAE_COUNTER_FREE_V2_IN_COUNTER_TYPE, cnt->type);
 923	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTER_FREE, inbuf, sizeof(inbuf),
 924			  outbuf, sizeof(outbuf), &outlen);
 925	if (rc)
 926		return rc;
 927	/* pcol says this can't happen, since count is 1 */
 928	if (outlen < sizeof(outbuf))
 929		return -EIO;
 930	/* FW freed a different ID than we asked for, should also never happen.
 931	 * Warn because it means we've now got a different idea to the FW of
 932	 * what counters exist, which could cause mayhem later.
 933	 */
 934	if (WARN_ON(MCDI_DWORD(outbuf, MAE_COUNTER_FREE_OUT_FREED_COUNTER_ID) !=
 935		    cnt->fw_id))
 936		return -EIO;
 937	return 0;
 938}
 939
 940static int efx_mae_encap_type_to_mae_type(enum efx_encap_type type)
 941{
 942	switch (type & EFX_ENCAP_TYPES_MASK) {
 943	case EFX_ENCAP_TYPE_NONE:
 944		return MAE_MCDI_ENCAP_TYPE_NONE;
 945	case EFX_ENCAP_TYPE_VXLAN:
 946		return MAE_MCDI_ENCAP_TYPE_VXLAN;
 947	case EFX_ENCAP_TYPE_GENEVE:
 948		return MAE_MCDI_ENCAP_TYPE_GENEVE;
 949	default:
 950		return -EOPNOTSUPP;
 951	}
 952}
 953
 954int efx_mae_allocate_encap_md(struct efx_nic *efx,
 955			      struct efx_tc_encap_action *encap)
 956{
 957	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ENCAP_HEADER_ALLOC_IN_LEN(EFX_TC_MAX_ENCAP_HDR));
 958	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ENCAP_HEADER_ALLOC_OUT_LEN);
 959	size_t inlen, outlen;
 960	int rc;
 961
 962	rc = efx_mae_encap_type_to_mae_type(encap->type);
 963	if (rc < 0)
 964		return rc;
 965	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_ALLOC_IN_ENCAP_TYPE, rc);
 966	inlen = MC_CMD_MAE_ENCAP_HEADER_ALLOC_IN_LEN(encap->encap_hdr_len);
 967	if (WARN_ON(inlen > sizeof(inbuf))) /* can't happen */
 968		return -EINVAL;
 969	memcpy(MCDI_PTR(inbuf, MAE_ENCAP_HEADER_ALLOC_IN_HDR_DATA),
 970	       encap->encap_hdr,
 971	       encap->encap_hdr_len);
 972	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ENCAP_HEADER_ALLOC, inbuf,
 973			  inlen, outbuf, sizeof(outbuf), &outlen);
 974	if (rc)
 975		return rc;
 976	if (outlen < sizeof(outbuf))
 977		return -EIO;
 978	encap->fw_id = MCDI_DWORD(outbuf, MAE_ENCAP_HEADER_ALLOC_OUT_ENCAP_HEADER_ID);
 979	return 0;
 980}
 981
 982int efx_mae_update_encap_md(struct efx_nic *efx,
 983			    struct efx_tc_encap_action *encap)
 984{
 985	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ENCAP_HEADER_UPDATE_IN_LEN(EFX_TC_MAX_ENCAP_HDR));
 986	size_t inlen;
 987	int rc;
 988
 989	rc = efx_mae_encap_type_to_mae_type(encap->type);
 990	if (rc < 0)
 991		return rc;
 992	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_UPDATE_IN_ENCAP_TYPE, rc);
 993	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_UPDATE_IN_EH_ID,
 994		       encap->fw_id);
 995	inlen = MC_CMD_MAE_ENCAP_HEADER_UPDATE_IN_LEN(encap->encap_hdr_len);
 996	if (WARN_ON(inlen > sizeof(inbuf))) /* can't happen */
 997		return -EINVAL;
 998	memcpy(MCDI_PTR(inbuf, MAE_ENCAP_HEADER_UPDATE_IN_HDR_DATA),
 999	       encap->encap_hdr,
1000	       encap->encap_hdr_len);
1001
1002	BUILD_BUG_ON(MC_CMD_MAE_ENCAP_HEADER_UPDATE_OUT_LEN != 0);
1003	return efx_mcdi_rpc(efx, MC_CMD_MAE_ENCAP_HEADER_UPDATE, inbuf,
1004			    inlen, NULL, 0, NULL);
1005}
1006
1007int efx_mae_free_encap_md(struct efx_nic *efx,
1008			  struct efx_tc_encap_action *encap)
1009{
1010	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ENCAP_HEADER_FREE_OUT_LEN(1));
1011	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ENCAP_HEADER_FREE_IN_LEN(1));
1012	size_t outlen;
1013	int rc;
1014
1015	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_FREE_IN_EH_ID, encap->fw_id);
1016	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ENCAP_HEADER_FREE, inbuf,
1017			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1018	if (rc)
1019		return rc;
1020	if (outlen < sizeof(outbuf))
1021		return -EIO;
1022	/* FW freed a different ID than we asked for, should also never happen.
1023	 * Warn because it means we've now got a different idea to the FW of
1024	 * what encap_mds exist, which could cause mayhem later.
1025	 */
1026	if (WARN_ON(MCDI_DWORD(outbuf, MAE_ENCAP_HEADER_FREE_OUT_FREED_EH_ID) != encap->fw_id))
1027		return -EIO;
1028	/* We're probably about to free @encap, but let's just make sure its
1029	 * fw_id is blatted so that it won't look valid if it leaks out.
1030	 */
1031	encap->fw_id = MC_CMD_MAE_ENCAP_HEADER_ALLOC_OUT_ENCAP_HEADER_ID_NULL;
1032	return 0;
1033}
1034
1035int efx_mae_lookup_mport(struct efx_nic *efx, u32 vf_idx, u32 *id)
1036{
1037	struct ef100_nic_data *nic_data = efx->nic_data;
1038	struct efx_mae *mae = efx->mae;
1039	struct rhashtable_iter walk;
1040	struct mae_mport_desc *m;
1041	int rc = -ENOENT;
1042
1043	rhashtable_walk_enter(&mae->mports_ht, &walk);
1044	rhashtable_walk_start(&walk);
1045	while ((m = rhashtable_walk_next(&walk)) != NULL) {
1046		if (m->mport_type == MAE_MPORT_DESC_MPORT_TYPE_VNIC &&
1047		    m->interface_idx == nic_data->local_mae_intf &&
1048		    m->pf_idx == 0 &&
1049		    m->vf_idx == vf_idx) {
1050			*id = m->mport_id;
1051			rc = 0;
1052			break;
1053		}
1054	}
1055	rhashtable_walk_stop(&walk);
1056	rhashtable_walk_exit(&walk);
1057	return rc;
1058}
1059
1060static bool efx_mae_asl_id(u32 id)
1061{
1062	return !!(id & BIT(31));
1063}
1064
1065/* mport handling */
1066static const struct rhashtable_params efx_mae_mports_ht_params = {
1067	.key_len	= sizeof(u32),
1068	.key_offset	= offsetof(struct mae_mport_desc, mport_id),
1069	.head_offset	= offsetof(struct mae_mport_desc, linkage),
1070};
1071
1072struct mae_mport_desc *efx_mae_get_mport(struct efx_nic *efx, u32 mport_id)
1073{
1074	return rhashtable_lookup_fast(&efx->mae->mports_ht, &mport_id,
1075				      efx_mae_mports_ht_params);
1076}
1077
1078static int efx_mae_add_mport(struct efx_nic *efx, struct mae_mport_desc *desc)
1079{
1080	struct efx_mae *mae = efx->mae;
1081	int rc;
1082
1083	rc = rhashtable_insert_fast(&mae->mports_ht, &desc->linkage,
1084				    efx_mae_mports_ht_params);
1085
1086	if (rc) {
1087		pci_err(efx->pci_dev, "Failed to insert MPORT %08x, rc %d\n",
1088			desc->mport_id, rc);
1089		kfree(desc);
1090		return rc;
1091	}
1092
1093	return rc;
1094}
1095
1096void efx_mae_remove_mport(void *desc, void *arg)
1097{
1098	struct mae_mport_desc *mport = desc;
1099
1100	synchronize_rcu();
1101	kfree(mport);
1102}
1103
1104static int efx_mae_process_mport(struct efx_nic *efx,
1105				 struct mae_mport_desc *desc)
1106{
1107	struct ef100_nic_data *nic_data = efx->nic_data;
1108	struct mae_mport_desc *mport;
1109
1110	mport = efx_mae_get_mport(efx, desc->mport_id);
1111	if (!IS_ERR_OR_NULL(mport)) {
1112		netif_err(efx, drv, efx->net_dev,
1113			  "mport with id %u does exist!!!\n", desc->mport_id);
1114		return -EEXIST;
1115	}
1116
1117	if (nic_data->have_own_mport &&
1118	    desc->mport_id == nic_data->own_mport) {
1119		WARN_ON(desc->mport_type != MAE_MPORT_DESC_MPORT_TYPE_VNIC);
1120		WARN_ON(desc->vnic_client_type !=
1121			MAE_MPORT_DESC_VNIC_CLIENT_TYPE_FUNCTION);
1122		nic_data->local_mae_intf = desc->interface_idx;
1123		nic_data->have_local_intf = true;
1124		pci_dbg(efx->pci_dev, "MAE interface_idx is %u\n",
1125			nic_data->local_mae_intf);
1126	}
1127
1128	return efx_mae_add_mport(efx, desc);
1129}
1130
1131#define MCDI_MPORT_JOURNAL_LEN \
1132	ALIGN(MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_LENMAX_MCDI2, 4)
1133
1134int efx_mae_enumerate_mports(struct efx_nic *efx)
1135{
1136	efx_dword_t *outbuf = kzalloc(MCDI_MPORT_JOURNAL_LEN, GFP_KERNEL);
1137	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_READ_JOURNAL_IN_LEN);
1138	MCDI_DECLARE_STRUCT_PTR(desc);
1139	size_t outlen, stride, count;
1140	int rc = 0, i;
1141
1142	if (!outbuf)
1143		return -ENOMEM;
1144	do {
1145		rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_READ_JOURNAL, inbuf,
1146				  sizeof(inbuf), outbuf,
1147				  MCDI_MPORT_JOURNAL_LEN, &outlen);
1148		if (rc)
1149			goto fail;
1150		if (outlen < MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_MPORT_DESC_DATA_OFST) {
1151			rc = -EIO;
1152			goto fail;
1153		}
1154		count = MCDI_DWORD(outbuf, MAE_MPORT_READ_JOURNAL_OUT_MPORT_DESC_COUNT);
1155		if (!count)
1156			continue; /* not break; we want to look at MORE flag */
1157		stride = MCDI_DWORD(outbuf, MAE_MPORT_READ_JOURNAL_OUT_SIZEOF_MPORT_DESC);
1158		if (stride < MAE_MPORT_DESC_LEN) {
1159			rc = -EIO;
1160			goto fail;
1161		}
1162		if (outlen < MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_LEN(count * stride)) {
1163			rc = -EIO;
1164			goto fail;
1165		}
1166
1167		for (i = 0; i < count; i++) {
1168			struct mae_mport_desc *d;
1169
1170			d = kzalloc(sizeof(*d), GFP_KERNEL);
1171			if (!d) {
1172				rc = -ENOMEM;
1173				goto fail;
1174			}
1175
1176			desc = (efx_dword_t *)
1177				_MCDI_PTR(outbuf, MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_MPORT_DESC_DATA_OFST +
1178					  i * stride);
1179			d->mport_id = MCDI_STRUCT_DWORD(desc, MAE_MPORT_DESC_MPORT_ID);
1180			d->flags = MCDI_STRUCT_DWORD(desc, MAE_MPORT_DESC_FLAGS);
1181			d->caller_flags = MCDI_STRUCT_DWORD(desc,
1182							    MAE_MPORT_DESC_CALLER_FLAGS);
1183			d->mport_type = MCDI_STRUCT_DWORD(desc,
1184							  MAE_MPORT_DESC_MPORT_TYPE);
1185			switch (d->mport_type) {
1186			case MAE_MPORT_DESC_MPORT_TYPE_NET_PORT:
1187				d->port_idx = MCDI_STRUCT_DWORD(desc,
1188								MAE_MPORT_DESC_NET_PORT_IDX);
1189				break;
1190			case MAE_MPORT_DESC_MPORT_TYPE_ALIAS:
1191				d->alias_mport_id = MCDI_STRUCT_DWORD(desc,
1192								      MAE_MPORT_DESC_ALIAS_DELIVER_MPORT_ID);
1193				break;
1194			case MAE_MPORT_DESC_MPORT_TYPE_VNIC:
1195				d->vnic_client_type = MCDI_STRUCT_DWORD(desc,
1196									MAE_MPORT_DESC_VNIC_CLIENT_TYPE);
1197				d->interface_idx = MCDI_STRUCT_DWORD(desc,
1198								     MAE_MPORT_DESC_VNIC_FUNCTION_INTERFACE);
1199				d->pf_idx = MCDI_STRUCT_WORD(desc,
1200							     MAE_MPORT_DESC_VNIC_FUNCTION_PF_IDX);
1201				d->vf_idx = MCDI_STRUCT_WORD(desc,
1202							     MAE_MPORT_DESC_VNIC_FUNCTION_VF_IDX);
1203				break;
1204			default:
1205				/* Unknown mport_type, just accept it */
1206				break;
1207			}
1208			rc = efx_mae_process_mport(efx, d);
1209			/* Any failure will be due to memory allocation faiure,
1210			 * so there is no point to try subsequent entries.
1211			 */
1212			if (rc)
1213				goto fail;
1214		}
1215	} while (MCDI_FIELD(outbuf, MAE_MPORT_READ_JOURNAL_OUT, MORE) &&
1216		 !WARN_ON(!count));
1217fail:
1218	kfree(outbuf);
1219	return rc;
1220}
1221
1222/**
1223 * efx_mae_allocate_pedit_mac() - allocate pedit MAC address in HW.
1224 * @efx:	NIC we're installing a pedit MAC address on
1225 * @ped:	pedit MAC action to be installed
1226 *
1227 * Attempts to install @ped in HW and populates its id with an index of this
1228 * entry in the firmware MAC address table on success.
1229 *
1230 * Return: negative value on error, 0 in success.
1231 */
1232int efx_mae_allocate_pedit_mac(struct efx_nic *efx,
1233			       struct efx_tc_mac_pedit_action *ped)
1234{
1235	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_LEN);
1236	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MAC_ADDR_ALLOC_IN_LEN);
1237	size_t outlen;
1238	int rc;
1239
1240	BUILD_BUG_ON(MC_CMD_MAE_MAC_ADDR_ALLOC_IN_MAC_ADDR_LEN !=
1241		     sizeof(ped->h_addr));
1242	memcpy(MCDI_PTR(inbuf, MAE_MAC_ADDR_ALLOC_IN_MAC_ADDR), ped->h_addr,
1243	       sizeof(ped->h_addr));
1244	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MAC_ADDR_ALLOC, inbuf, sizeof(inbuf),
1245			  outbuf, sizeof(outbuf), &outlen);
1246	if (rc)
1247		return rc;
1248	if (outlen < sizeof(outbuf))
1249		return -EIO;
1250	ped->fw_id = MCDI_DWORD(outbuf, MAE_MAC_ADDR_ALLOC_OUT_MAC_ID);
1251	return 0;
1252}
1253
1254/**
1255 * efx_mae_free_pedit_mac() - free pedit MAC address in HW.
1256 * @efx:	NIC we're installing a pedit MAC address on
1257 * @ped:	pedit MAC action that needs to be freed
1258 *
1259 * Frees @ped in HW, check that firmware did not free a different one and clears
1260 * the id (which denotes the index of the entry in the MAC address table).
1261 */
1262void efx_mae_free_pedit_mac(struct efx_nic *efx,
1263			    struct efx_tc_mac_pedit_action *ped)
1264{
1265	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MAC_ADDR_FREE_OUT_LEN(1));
1266	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MAC_ADDR_FREE_IN_LEN(1));
1267	size_t outlen;
1268	int rc;
1269
1270	MCDI_SET_DWORD(inbuf, MAE_MAC_ADDR_FREE_IN_MAC_ID, ped->fw_id);
1271	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MAC_ADDR_FREE, inbuf,
1272			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1273	if (rc || outlen < sizeof(outbuf))
1274		return;
1275	/* FW freed a different ID than we asked for, should also never happen.
1276	 * Warn because it means we've now got a different idea to the FW of
1277	 * what MAC addresses exist, which could cause mayhem later.
1278	 */
1279	if (WARN_ON(MCDI_DWORD(outbuf, MAE_MAC_ADDR_FREE_OUT_FREED_MAC_ID) != ped->fw_id))
1280		return;
1281	/* We're probably about to free @ped, but let's just make sure its
1282	 * fw_id is blatted so that it won't look valid if it leaks out.
1283	 */
1284	ped->fw_id = MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_MAC_ID_NULL;
1285}
1286
1287int efx_mae_alloc_action_set(struct efx_nic *efx, struct efx_tc_action_set *act)
1288{
1289	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_ALLOC_OUT_LEN);
1290	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_SET_ALLOC_IN_LEN);
1291	size_t outlen;
1292	int rc;
1293
1294	MCDI_POPULATE_DWORD_5(inbuf, MAE_ACTION_SET_ALLOC_IN_FLAGS,
1295			      MAE_ACTION_SET_ALLOC_IN_VLAN_PUSH, act->vlan_push,
1296			      MAE_ACTION_SET_ALLOC_IN_VLAN_POP, act->vlan_pop,
1297			      MAE_ACTION_SET_ALLOC_IN_DECAP, act->decap,
1298			      MAE_ACTION_SET_ALLOC_IN_DO_NAT, act->do_nat,
1299			      MAE_ACTION_SET_ALLOC_IN_DO_DECR_IP_TTL,
1300			      act->do_ttl_dec);
1301
1302	if (act->src_mac)
1303		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_SRC_MAC_ID,
1304			       act->src_mac->fw_id);
1305	else
1306		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_SRC_MAC_ID,
1307			       MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_MAC_ID_NULL);
1308
1309	if (act->dst_mac)
1310		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_DST_MAC_ID,
1311			       act->dst_mac->fw_id);
1312	else
1313		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_DST_MAC_ID,
1314			       MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_MAC_ID_NULL);
1315
1316	if (act->count && !WARN_ON(!act->count->cnt))
1317		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_COUNTER_ID,
1318			       act->count->cnt->fw_id);
1319	else
1320		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_COUNTER_ID,
1321			       MC_CMD_MAE_COUNTER_ALLOC_OUT_COUNTER_ID_NULL);
1322	MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_COUNTER_LIST_ID,
1323		       MC_CMD_MAE_COUNTER_LIST_ALLOC_OUT_COUNTER_LIST_ID_NULL);
1324	if (act->vlan_push) {
1325		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN0_TCI_BE,
1326				 act->vlan_tci[0]);
1327		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN0_PROTO_BE,
1328				 act->vlan_proto[0]);
1329	}
1330	if (act->vlan_push >= 2) {
1331		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN1_TCI_BE,
1332				 act->vlan_tci[1]);
1333		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN1_PROTO_BE,
1334				 act->vlan_proto[1]);
1335	}
1336	if (act->encap_md)
1337		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_ENCAP_HEADER_ID,
1338			       act->encap_md->fw_id);
1339	else
1340		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_ENCAP_HEADER_ID,
1341			       MC_CMD_MAE_ENCAP_HEADER_ALLOC_OUT_ENCAP_HEADER_ID_NULL);
1342	if (act->deliver)
1343		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_DELIVER,
1344			       act->dest_mport);
1345	BUILD_BUG_ON(MAE_MPORT_SELECTOR_NULL);
1346	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_ALLOC, inbuf, sizeof(inbuf),
1347			  outbuf, sizeof(outbuf), &outlen);
1348	if (rc)
1349		return rc;
1350	if (outlen < sizeof(outbuf))
1351		return -EIO;
1352	act->fw_id = MCDI_DWORD(outbuf, MAE_ACTION_SET_ALLOC_OUT_AS_ID);
1353	/* We rely on the high bit of AS IDs always being clear.
1354	 * The firmware API guarantees this, but let's check it ourselves.
1355	 */
1356	if (WARN_ON_ONCE(efx_mae_asl_id(act->fw_id))) {
1357		efx_mae_free_action_set(efx, act->fw_id);
1358		return -EIO;
1359	}
1360	return 0;
1361}
1362
1363int efx_mae_free_action_set(struct efx_nic *efx, u32 fw_id)
1364{
1365	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_FREE_OUT_LEN(1));
1366	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_SET_FREE_IN_LEN(1));
1367	size_t outlen;
1368	int rc;
1369
1370	MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_FREE_IN_AS_ID, fw_id);
1371	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_FREE, inbuf, sizeof(inbuf),
1372			  outbuf, sizeof(outbuf), &outlen);
1373	if (rc)
1374		return rc;
1375	if (outlen < sizeof(outbuf))
1376		return -EIO;
1377	/* FW freed a different ID than we asked for, should never happen.
1378	 * Warn because it means we've now got a different idea to the FW of
1379	 * what action-sets exist, which could cause mayhem later.
1380	 */
1381	if (WARN_ON(MCDI_DWORD(outbuf, MAE_ACTION_SET_FREE_OUT_FREED_AS_ID) != fw_id))
1382		return -EIO;
1383	return 0;
1384}
1385
1386int efx_mae_alloc_action_set_list(struct efx_nic *efx,
1387				  struct efx_tc_action_set_list *acts)
1388{
1389	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_LEN);
1390	struct efx_tc_action_set *act;
1391	size_t inlen, outlen, i = 0;
1392	efx_dword_t *inbuf;
1393	int rc;
1394
1395	list_for_each_entry(act, &acts->list, list)
1396		i++;
1397	if (i == 0)
1398		return -EINVAL;
1399	if (i == 1) {
1400		/* Don't wrap an ASL around a single AS, just use the AS_ID
1401		 * directly.  ASLs are a more limited resource.
1402		 */
1403		act = list_first_entry(&acts->list, struct efx_tc_action_set, list);
1404		acts->fw_id = act->fw_id;
1405		return 0;
1406	}
1407	if (i > MC_CMD_MAE_ACTION_SET_LIST_ALLOC_IN_AS_IDS_MAXNUM_MCDI2)
1408		return -EOPNOTSUPP; /* Too many actions */
1409	inlen = MC_CMD_MAE_ACTION_SET_LIST_ALLOC_IN_LEN(i);
1410	inbuf = kzalloc(inlen, GFP_KERNEL);
1411	if (!inbuf)
1412		return -ENOMEM;
1413	i = 0;
1414	list_for_each_entry(act, &acts->list, list) {
1415		MCDI_SET_ARRAY_DWORD(inbuf, MAE_ACTION_SET_LIST_ALLOC_IN_AS_IDS,
1416				     i, act->fw_id);
1417		i++;
1418	}
1419	MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_LIST_ALLOC_IN_COUNT, i);
1420	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_LIST_ALLOC, inbuf, inlen,
1421			  outbuf, sizeof(outbuf), &outlen);
1422	if (rc)
1423		goto out_free;
1424	if (outlen < sizeof(outbuf)) {
1425		rc = -EIO;
1426		goto out_free;
1427	}
1428	acts->fw_id = MCDI_DWORD(outbuf, MAE_ACTION_SET_LIST_ALLOC_OUT_ASL_ID);
1429	/* We rely on the high bit of ASL IDs always being set.
1430	 * The firmware API guarantees this, but let's check it ourselves.
1431	 */
1432	if (WARN_ON_ONCE(!efx_mae_asl_id(acts->fw_id))) {
1433		efx_mae_free_action_set_list(efx, acts);
1434		rc = -EIO;
1435	}
1436out_free:
1437	kfree(inbuf);
1438	return rc;
1439}
1440
1441int efx_mae_free_action_set_list(struct efx_nic *efx,
1442				 struct efx_tc_action_set_list *acts)
1443{
1444	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_LIST_FREE_OUT_LEN(1));
1445	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_SET_LIST_FREE_IN_LEN(1));
1446	size_t outlen;
1447	int rc;
1448
1449	/* If this is just an AS_ID with no ASL wrapper, then there is
1450	 * nothing for us to free.  (The AS will be freed later.)
1451	 */
1452	if (efx_mae_asl_id(acts->fw_id)) {
1453		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_LIST_FREE_IN_ASL_ID,
1454			       acts->fw_id);
1455		rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_LIST_FREE, inbuf,
1456				  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1457		if (rc)
1458			return rc;
1459		if (outlen < sizeof(outbuf))
1460			return -EIO;
1461		/* FW freed a different ID than we asked for, should never happen.
1462		 * Warn because it means we've now got a different idea to the FW of
1463		 * what action-set-lists exist, which could cause mayhem later.
1464		 */
1465		if (WARN_ON(MCDI_DWORD(outbuf, MAE_ACTION_SET_LIST_FREE_OUT_FREED_ASL_ID) != acts->fw_id))
1466			return -EIO;
1467	}
1468	/* We're probably about to free @acts, but let's just make sure its
1469	 * fw_id is blatted so that it won't look valid if it leaks out.
1470	 */
1471	acts->fw_id = MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL;
1472	return 0;
1473}
1474
1475int efx_mae_register_encap_match(struct efx_nic *efx,
1476				 struct efx_tc_encap_match *encap)
1477{
1478	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_INSERT_IN_LEN(MAE_ENC_FIELD_PAIRS_LEN));
1479	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_INSERT_OUT_LEN);
1480	MCDI_DECLARE_STRUCT_PTR(match_crit);
1481	size_t outlen;
1482	int rc;
1483
1484	rc = efx_mae_encap_type_to_mae_type(encap->tun_type);
1485	if (rc < 0)
1486		return rc;
1487	match_crit = _MCDI_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_FIELD_MATCH_CRITERIA);
1488	/* The struct contains IP src and dst, and udp dport.
1489	 * So we actually need to filter on IP src and dst, L4 dport, and
1490	 * ipproto == udp.
1491	 */
1492	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_ENCAP_TYPE, rc);
1493#ifdef CONFIG_IPV6
1494	if (encap->src_ip | encap->dst_ip) {
1495#endif
1496		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE,
1497					 encap->src_ip);
1498		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE_MASK,
1499					 ~(__be32)0);
1500		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE,
1501					 encap->dst_ip);
1502		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE_MASK,
1503					 ~(__be32)0);
1504		MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE,
1505					htons(ETH_P_IP));
1506#ifdef CONFIG_IPV6
1507	} else {
1508		memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE),
1509		       &encap->src_ip6, sizeof(encap->src_ip6));
1510		memset(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE_MASK),
1511		       0xff, sizeof(encap->src_ip6));
1512		memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE),
1513		       &encap->dst_ip6, sizeof(encap->dst_ip6));
1514		memset(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE_MASK),
1515		       0xff, sizeof(encap->dst_ip6));
1516		MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE,
1517					htons(ETH_P_IPV6));
1518	}
1519#endif
1520	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE_MASK,
1521				~(__be16)0);
1522	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE,
1523				encap->udp_dport);
1524	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE_MASK,
1525				~(__be16)0);
1526	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE,
1527				encap->udp_sport);
1528	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE_MASK,
1529				encap->udp_sport_mask);
1530	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO, IPPROTO_UDP);
1531	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO_MASK, ~0);
1532	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS,
1533			     encap->ip_tos);
1534	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS_MASK,
1535			     encap->ip_tos_mask);
1536	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_INSERT, inbuf,
1537			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1538	if (rc)
1539		return rc;
1540	if (outlen < sizeof(outbuf))
1541		return -EIO;
1542	encap->fw_id = MCDI_DWORD(outbuf, MAE_OUTER_RULE_INSERT_OUT_OR_ID);
1543	return 0;
1544}
1545
1546int efx_mae_unregister_encap_match(struct efx_nic *efx,
1547				   struct efx_tc_encap_match *encap)
1548{
1549	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_OUT_LEN(1));
1550	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_IN_LEN(1));
1551	size_t outlen;
1552	int rc;
1553
1554	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_REMOVE_IN_OR_ID, encap->fw_id);
1555	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_REMOVE, inbuf,
1556			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1557	if (rc)
1558		return rc;
1559	if (outlen < sizeof(outbuf))
1560		return -EIO;
1561	/* FW freed a different ID than we asked for, should also never happen.
1562	 * Warn because it means we've now got a different idea to the FW of
1563	 * what encap_mds exist, which could cause mayhem later.
1564	 */
1565	if (WARN_ON(MCDI_DWORD(outbuf, MAE_OUTER_RULE_REMOVE_OUT_REMOVED_OR_ID) != encap->fw_id))
1566		return -EIO;
1567	/* We're probably about to free @encap, but let's just make sure its
1568	 * fw_id is blatted so that it won't look valid if it leaks out.
1569	 */
1570	encap->fw_id = MC_CMD_MAE_OUTER_RULE_INSERT_OUT_OUTER_RULE_ID_NULL;
1571	return 0;
1572}
1573
1574static int efx_mae_populate_lhs_match_criteria(MCDI_DECLARE_STRUCT_PTR(match_crit),
1575					       const struct efx_tc_match *match)
1576{
1577	if (match->mask.ingress_port) {
1578		if (~match->mask.ingress_port)
1579			return -EOPNOTSUPP;
1580		MCDI_STRUCT_SET_DWORD(match_crit,
1581				      MAE_ENC_FIELD_PAIRS_INGRESS_MPORT_SELECTOR,
1582				      match->value.ingress_port);
1583	}
1584	MCDI_STRUCT_SET_DWORD(match_crit, MAE_ENC_FIELD_PAIRS_INGRESS_MPORT_SELECTOR_MASK,
1585			      match->mask.ingress_port);
1586	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE,
1587				match->value.eth_proto);
1588	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE_MASK,
1589				match->mask.eth_proto);
1590	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_TCI_BE,
1591				match->value.vlan_tci[0]);
1592	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_TCI_BE_MASK,
1593				match->mask.vlan_tci[0]);
1594	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_PROTO_BE,
1595				match->value.vlan_proto[0]);
1596	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_PROTO_BE_MASK,
1597				match->mask.vlan_proto[0]);
1598	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_TCI_BE,
1599				match->value.vlan_tci[1]);
1600	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_TCI_BE_MASK,
1601				match->mask.vlan_tci[1]);
1602	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_PROTO_BE,
1603				match->value.vlan_proto[1]);
1604	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_PROTO_BE_MASK,
1605				match->mask.vlan_proto[1]);
1606	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_SADDR_BE),
1607	       match->value.eth_saddr, ETH_ALEN);
1608	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_SADDR_BE_MASK),
1609	       match->mask.eth_saddr, ETH_ALEN);
1610	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_DADDR_BE),
1611	       match->value.eth_daddr, ETH_ALEN);
1612	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_DADDR_BE_MASK),
1613	       match->mask.eth_daddr, ETH_ALEN);
1614	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO,
1615			     match->value.ip_proto);
1616	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO_MASK,
1617			     match->mask.ip_proto);
1618	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS,
1619			     match->value.ip_tos);
1620	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS_MASK,
1621			     match->mask.ip_tos);
1622	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TTL,
1623			     match->value.ip_ttl);
1624	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TTL_MASK,
1625			     match->mask.ip_ttl);
1626	MCDI_STRUCT_POPULATE_BYTE_1(match_crit,
1627				    MAE_ENC_FIELD_PAIRS_ENC_VLAN_FLAGS,
1628				    MAE_ENC_FIELD_PAIRS_ENC_IP_FRAG,
1629				    match->value.ip_frag);
1630	MCDI_STRUCT_POPULATE_BYTE_1(match_crit,
1631				    MAE_ENC_FIELD_PAIRS_ENC_VLAN_FLAGS_MASK,
1632				    MAE_ENC_FIELD_PAIRS_ENC_IP_FRAG_MASK,
1633				    match->mask.ip_frag);
1634	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE,
1635				 match->value.src_ip);
1636	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE_MASK,
1637				 match->mask.src_ip);
1638	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE,
1639				 match->value.dst_ip);
1640	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE_MASK,
1641				 match->mask.dst_ip);
1642#ifdef CONFIG_IPV6
1643	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE),
1644	       &match->value.src_ip6, sizeof(struct in6_addr));
1645	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE_MASK),
1646	       &match->mask.src_ip6, sizeof(struct in6_addr));
1647	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE),
1648	       &match->value.dst_ip6, sizeof(struct in6_addr));
1649	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE_MASK),
1650	       &match->mask.dst_ip6, sizeof(struct in6_addr));
1651#endif
1652	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_SPORT_BE,
1653				match->value.l4_sport);
1654	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_SPORT_BE_MASK,
1655				match->mask.l4_sport);
1656	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE,
1657				match->value.l4_dport);
1658	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE_MASK,
1659				match->mask.l4_dport);
1660	/* No enc-keys in LHS rules.  Caps check should have caught this; any
1661	 * enc-keys from an fLHS should have been translated to regular keys
1662	 * and any EM should be a pseudo (we're an OR so can't have a direct
1663	 * EM with another OR).
1664	 */
1665	if (WARN_ON_ONCE(match->encap && !match->encap->type))
1666		return -EOPNOTSUPP;
1667	if (WARN_ON_ONCE(match->mask.enc_src_ip))
1668		return -EOPNOTSUPP;
1669	if (WARN_ON_ONCE(match->mask.enc_dst_ip))
1670		return -EOPNOTSUPP;
1671#ifdef CONFIG_IPV6
1672	if (WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_src_ip6)))
1673		return -EOPNOTSUPP;
1674	if (WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_dst_ip6)))
1675		return -EOPNOTSUPP;
1676#endif
1677	if (WARN_ON_ONCE(match->mask.enc_ip_tos))
1678		return -EOPNOTSUPP;
1679	if (WARN_ON_ONCE(match->mask.enc_ip_ttl))
1680		return -EOPNOTSUPP;
1681	if (WARN_ON_ONCE(match->mask.enc_sport))
1682		return -EOPNOTSUPP;
1683	if (WARN_ON_ONCE(match->mask.enc_dport))
1684		return -EOPNOTSUPP;
1685	if (WARN_ON_ONCE(match->mask.enc_keyid))
1686		return -EOPNOTSUPP;
1687	return 0;
1688}
1689
1690static int efx_mae_insert_lhs_outer_rule(struct efx_nic *efx,
1691					 struct efx_tc_lhs_rule *rule, u32 prio)
1692{
1693	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_INSERT_IN_LEN(MAE_ENC_FIELD_PAIRS_LEN));
1694	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_INSERT_OUT_LEN);
1695	MCDI_DECLARE_STRUCT_PTR(match_crit);
1696	const struct efx_tc_lhs_action *act;
1697	size_t outlen;
1698	int rc;
1699
1700	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_PRIO, prio);
1701	/* match */
1702	match_crit = _MCDI_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_FIELD_MATCH_CRITERIA);
1703	rc = efx_mae_populate_lhs_match_criteria(match_crit, &rule->match);
1704	if (rc)
1705		return rc;
1706
1707	/* action */
1708	act = &rule->lhs_act;
1709	rc = efx_mae_encap_type_to_mae_type(act->tun_type);
1710	if (rc < 0)
1711		return rc;
1712	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_ENCAP_TYPE, rc);
1713	/* We always inhibit CT lookup on TCP_INTERESTING_FLAGS, since the
1714	 * SW path needs to process the packet to update the conntrack tables
1715	 * on connection establishment (SYN) or termination (FIN, RST).
1716	 */
1717	MCDI_POPULATE_DWORD_6(inbuf, MAE_OUTER_RULE_INSERT_IN_LOOKUP_CONTROL,
1718			      MAE_OUTER_RULE_INSERT_IN_DO_CT, !!act->zone,
1719			      MAE_OUTER_RULE_INSERT_IN_CT_TCP_FLAGS_INHIBIT, 1,
1720			      MAE_OUTER_RULE_INSERT_IN_CT_DOMAIN,
1721			      act->zone ? act->zone->zone : 0,
1722			      MAE_OUTER_RULE_INSERT_IN_CT_VNI_MODE,
1723			      MAE_CT_VNI_MODE_ZERO,
1724			      MAE_OUTER_RULE_INSERT_IN_DO_COUNT, !!act->count,
1725			      MAE_OUTER_RULE_INSERT_IN_RECIRC_ID,
1726			      act->rid ? act->rid->fw_id : 0);
1727	if (act->count)
1728		MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_COUNTER_ID,
1729			       act->count->cnt->fw_id);
1730	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_INSERT, inbuf,
1731			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1732	if (rc)
1733		return rc;
1734	if (outlen < sizeof(outbuf))
1735		return -EIO;
1736	rule->fw_id = MCDI_DWORD(outbuf, MAE_OUTER_RULE_INSERT_OUT_OR_ID);
1737	return 0;
1738}
1739
1740static int efx_mae_populate_match_criteria(MCDI_DECLARE_STRUCT_PTR(match_crit),
1741					   const struct efx_tc_match *match);
1742
1743static int efx_mae_insert_lhs_action_rule(struct efx_nic *efx,
1744					  struct efx_tc_lhs_rule *rule,
1745					  u32 prio)
1746{
1747	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_INSERT_IN_LEN(MAE_FIELD_MASK_VALUE_PAIRS_V2_LEN));
1748	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_RULE_INSERT_OUT_LEN);
1749	struct efx_tc_lhs_action *act = &rule->lhs_act;
1750	MCDI_DECLARE_STRUCT_PTR(match_crit);
1751	MCDI_DECLARE_STRUCT_PTR(response);
1752	size_t outlen;
1753	int rc;
1754
1755	match_crit = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_MATCH_CRITERIA);
1756	response = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_RESPONSE);
1757	MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID,
1758			      MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL);
1759	MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID,
1760			      MC_CMD_MAE_ACTION_SET_ALLOC_OUT_ACTION_SET_ID_NULL);
1761	EFX_POPULATE_DWORD_5(*_MCDI_STRUCT_DWORD(response, MAE_ACTION_RULE_RESPONSE_LOOKUP_CONTROL),
1762			     MAE_ACTION_RULE_RESPONSE_DO_CT, !!act->zone,
1763			     MAE_ACTION_RULE_RESPONSE_DO_RECIRC,
1764			     act->rid && !act->zone,
1765			     MAE_ACTION_RULE_RESPONSE_CT_VNI_MODE,
1766			     MAE_CT_VNI_MODE_ZERO,
1767			     MAE_ACTION_RULE_RESPONSE_RECIRC_ID,
1768			     act->rid ? act->rid->fw_id : 0,
1769			     MAE_ACTION_RULE_RESPONSE_CT_DOMAIN,
1770			     act->zone ? act->zone->zone : 0);
1771	MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_COUNTER_ID,
1772			      act->count ? act->count->cnt->fw_id :
1773			      MC_CMD_MAE_COUNTER_ALLOC_OUT_COUNTER_ID_NULL);
1774	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_PRIO, prio);
1775	rc = efx_mae_populate_match_criteria(match_crit, &rule->match);
1776	if (rc)
1777		return rc;
1778
1779	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_INSERT, inbuf, sizeof(inbuf),
1780			  outbuf, sizeof(outbuf), &outlen);
1781	if (rc)
1782		return rc;
1783	if (outlen < sizeof(outbuf))
1784		return -EIO;
1785	rule->fw_id = MCDI_DWORD(outbuf, MAE_ACTION_RULE_INSERT_OUT_AR_ID);
1786	return 0;
1787}
1788
1789int efx_mae_insert_lhs_rule(struct efx_nic *efx, struct efx_tc_lhs_rule *rule,
1790			    u32 prio)
1791{
1792	if (rule->is_ar)
1793		return efx_mae_insert_lhs_action_rule(efx, rule, prio);
1794	return efx_mae_insert_lhs_outer_rule(efx, rule, prio);
1795}
1796
1797static int efx_mae_remove_lhs_outer_rule(struct efx_nic *efx,
1798					 struct efx_tc_lhs_rule *rule)
1799{
1800	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_OUT_LEN(1));
1801	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_IN_LEN(1));
1802	size_t outlen;
1803	int rc;
1804
1805	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_REMOVE_IN_OR_ID, rule->fw_id);
1806	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_REMOVE, inbuf,
1807			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1808	if (rc)
1809		return rc;
1810	if (outlen < sizeof(outbuf))
1811		return -EIO;
1812	/* FW freed a different ID than we asked for, should also never happen.
1813	 * Warn because it means we've now got a different idea to the FW of
1814	 * what encap_mds exist, which could cause mayhem later.
1815	 */
1816	if (WARN_ON(MCDI_DWORD(outbuf, MAE_OUTER_RULE_REMOVE_OUT_REMOVED_OR_ID) != rule->fw_id))
1817		return -EIO;
1818	/* We're probably about to free @rule, but let's just make sure its
1819	 * fw_id is blatted so that it won't look valid if it leaks out.
1820	 */
1821	rule->fw_id = MC_CMD_MAE_OUTER_RULE_INSERT_OUT_OUTER_RULE_ID_NULL;
1822	return 0;
1823}
1824
1825int efx_mae_remove_lhs_rule(struct efx_nic *efx, struct efx_tc_lhs_rule *rule)
1826{
1827	if (rule->is_ar)
1828		return efx_mae_delete_rule(efx, rule->fw_id);
1829	return efx_mae_remove_lhs_outer_rule(efx, rule);
1830}
1831
1832/* Populating is done by taking each byte of @value in turn and storing
1833 * it in the appropriate bits of @row.  @value must be big-endian; we
1834 * convert it to little-endianness as we go.
1835 */
1836static int efx_mae_table_populate(struct efx_tc_table_field_fmt field,
1837				  __le32 *row, size_t row_bits,
1838				  void *value, size_t value_size)
1839{
1840	unsigned int i;
1841
1842	/* For now only scheme 0 is supported for any field, so we check here
1843	 * (rather than, say, in calling code, which knows the semantics and
1844	 * could in principle encode for other schemes).
1845	 */
1846	if (field.scheme)
1847		return -EOPNOTSUPP;
1848	if (DIV_ROUND_UP(field.width, 8) != value_size)
1849		return -EINVAL;
1850	if (field.lbn + field.width > row_bits)
1851		return -EINVAL;
1852	for (i = 0; i < value_size; i++) {
1853		unsigned int bn = field.lbn + i * 8;
1854		unsigned int wn = bn / 32;
1855		u64 v;
1856
1857		v = ((u8 *)value)[value_size - i - 1];
1858		v <<= (bn % 32);
1859		row[wn] |= cpu_to_le32(v & 0xffffffff);
1860		if (wn * 32 < row_bits)
1861			row[wn + 1] |= cpu_to_le32(v >> 32);
1862	}
1863	return 0;
1864}
1865
1866static int efx_mae_table_populate_bool(struct efx_tc_table_field_fmt field,
1867				       __le32 *row, size_t row_bits, bool value)
1868{
1869	u8 v = value ? 1 : 0;
1870
1871	if (field.width != 1)
1872		return -EINVAL;
1873	return efx_mae_table_populate(field, row, row_bits, &v, 1);
1874}
1875
1876static int efx_mae_table_populate_ipv4(struct efx_tc_table_field_fmt field,
1877				       __le32 *row, size_t row_bits, __be32 value)
1878{
1879	/* IPv4 is placed in the first 4 bytes of an IPv6-sized field */
1880	struct in6_addr v = {};
1881
1882	if (field.width != 128)
1883		return -EINVAL;
1884	v.s6_addr32[0] = value;
1885	return efx_mae_table_populate(field, row, row_bits, &v, sizeof(v));
1886}
1887
1888static int efx_mae_table_populate_u24(struct efx_tc_table_field_fmt field,
1889				      __le32 *row, size_t row_bits, u32 value)
1890{
1891	__be32 v = cpu_to_be32(value);
1892
1893	/* We adjust value_size here since just 3 bytes will be copied, and
1894	 * the pointer to the value is set discarding the first byte which is
1895	 * the most significant byte for a big-endian 4-bytes value.
1896	 */
1897	return efx_mae_table_populate(field, row, row_bits, ((void *)&v) + 1,
1898				      sizeof(v) - 1);
1899}
1900
1901#define _TABLE_POPULATE(dst, dw, _field, _value) ({	\
1902	typeof(_value) _v = _value;			\
1903							\
1904	(_field.width == sizeof(_value) * 8) ?		\
1905	 efx_mae_table_populate(_field, dst, dw, &_v,	\
1906				sizeof(_v)) : -EINVAL;	\
1907})
1908#define TABLE_POPULATE_KEY_IPV4(dst, _table, _field, _value)		       \
1909	efx_mae_table_populate_ipv4(efx->tc->meta_##_table.desc.keys	       \
1910				    [efx->tc->meta_##_table.keys._field##_idx],\
1911				    dst, efx->tc->meta_##_table.desc.key_width,\
1912				    _value)
1913#define TABLE_POPULATE_KEY(dst, _table, _field, _value)			\
1914	_TABLE_POPULATE(dst, efx->tc->meta_##_table.desc.key_width,	\
1915			efx->tc->meta_##_table.desc.keys		\
1916			[efx->tc->meta_##_table.keys._field##_idx],	\
1917			_value)
1918
1919#define TABLE_POPULATE_RESP_BOOL(dst, _table, _field, _value)			\
1920	efx_mae_table_populate_bool(efx->tc->meta_##_table.desc.resps		\
1921				    [efx->tc->meta_##_table.resps._field##_idx],\
1922				    dst, efx->tc->meta_##_table.desc.resp_width,\
1923				    _value)
1924#define TABLE_POPULATE_RESP(dst, _table, _field, _value)		\
1925	_TABLE_POPULATE(dst, efx->tc->meta_##_table.desc.resp_width,	\
1926			efx->tc->meta_##_table.desc.resps		\
1927			[efx->tc->meta_##_table.resps._field##_idx],	\
1928			_value)
1929
1930#define TABLE_POPULATE_RESP_U24(dst, _table, _field, _value)		       \
1931	efx_mae_table_populate_u24(efx->tc->meta_##_table.desc.resps	       \
1932				   [efx->tc->meta_##_table.resps._field##_idx],\
1933				   dst, efx->tc->meta_##_table.desc.resp_width,\
1934				   _value)
1935
1936static int efx_mae_populate_ct_key(struct efx_nic *efx, __le32 *key, size_t kw,
1937				   struct efx_tc_ct_entry *conn)
1938{
1939	bool ipv6 = conn->eth_proto == htons(ETH_P_IPV6);
1940	int rc;
1941
1942	rc = TABLE_POPULATE_KEY(key, ct, eth_proto, conn->eth_proto);
1943	if (rc)
1944		return rc;
1945	rc = TABLE_POPULATE_KEY(key, ct, ip_proto, conn->ip_proto);
1946	if (rc)
1947		return rc;
1948	if (ipv6)
1949		rc = TABLE_POPULATE_KEY(key, ct, src_ip, conn->src_ip6);
1950	else
1951		rc = TABLE_POPULATE_KEY_IPV4(key, ct, src_ip, conn->src_ip);
1952	if (rc)
1953		return rc;
1954	if (ipv6)
1955		rc = TABLE_POPULATE_KEY(key, ct, dst_ip, conn->dst_ip6);
1956	else
1957		rc = TABLE_POPULATE_KEY_IPV4(key, ct, dst_ip, conn->dst_ip);
1958	if (rc)
1959		return rc;
1960	rc = TABLE_POPULATE_KEY(key, ct, l4_sport, conn->l4_sport);
1961	if (rc)
1962		return rc;
1963	rc = TABLE_POPULATE_KEY(key, ct, l4_dport, conn->l4_dport);
1964	if (rc)
1965		return rc;
1966	return TABLE_POPULATE_KEY(key, ct, zone, cpu_to_be16(conn->zone->zone));
1967}
1968
1969int efx_mae_insert_ct(struct efx_nic *efx, struct efx_tc_ct_entry *conn)
1970{
1971	bool ipv6 = conn->eth_proto == htons(ETH_P_IPV6);
1972	__le32 *key = NULL, *resp = NULL;
1973	size_t inlen, kw, rw;
1974	efx_dword_t *inbuf;
1975	int rc = -ENOMEM;
1976
1977	/* Check table access is supported */
1978	if (!efx->tc->meta_ct.hooked)
1979		return -EOPNOTSUPP;
1980
1981	/* key/resp widths are in bits; convert to dwords for IN_LEN */
1982	kw = DIV_ROUND_UP(efx->tc->meta_ct.desc.key_width, 32);
1983	rw = DIV_ROUND_UP(efx->tc->meta_ct.desc.resp_width, 32);
1984	BUILD_BUG_ON(sizeof(__le32) != MC_CMD_TABLE_INSERT_IN_DATA_LEN);
1985	inlen = MC_CMD_TABLE_INSERT_IN_LEN(kw + rw);
1986	if (inlen > MC_CMD_TABLE_INSERT_IN_LENMAX_MCDI2)
1987		return -E2BIG;
1988	inbuf = kzalloc(inlen, GFP_KERNEL);
1989	if (!inbuf)
1990		return -ENOMEM;
1991
1992	key = kcalloc(kw, sizeof(__le32), GFP_KERNEL);
1993	if (!key)
1994		goto out_free;
1995	resp = kcalloc(rw, sizeof(__le32), GFP_KERNEL);
1996	if (!resp)
1997		goto out_free;
1998
1999	rc = efx_mae_populate_ct_key(efx, key, kw, conn);
2000	if (rc)
2001		goto out_free;
2002
2003	rc = TABLE_POPULATE_RESP_BOOL(resp, ct, dnat, conn->dnat);
2004	if (rc)
2005		goto out_free;
2006	/* No support in hw for IPv6 NAT; field is only 32 bits */
2007	if (!ipv6)
2008		rc = TABLE_POPULATE_RESP(resp, ct, nat_ip, conn->nat_ip);
2009	if (rc)
2010		goto out_free;
2011	rc = TABLE_POPULATE_RESP(resp, ct, l4_natport, conn->l4_natport);
2012	if (rc)
2013		goto out_free;
2014	rc = TABLE_POPULATE_RESP(resp, ct, mark, cpu_to_be32(conn->mark));
2015	if (rc)
2016		goto out_free;
2017	rc = TABLE_POPULATE_RESP_U24(resp, ct, counter_id, conn->cnt->fw_id);
2018	if (rc)
2019		goto out_free;
2020
2021	MCDI_SET_DWORD(inbuf, TABLE_INSERT_IN_TABLE_ID, TABLE_ID_CONNTRACK_TABLE);
2022	MCDI_SET_WORD(inbuf, TABLE_INSERT_IN_KEY_WIDTH,
2023		      efx->tc->meta_ct.desc.key_width);
2024	/* MASK_WIDTH is zero as CT is a BCAM */
2025	MCDI_SET_WORD(inbuf, TABLE_INSERT_IN_RESP_WIDTH,
2026		      efx->tc->meta_ct.desc.resp_width);
2027	memcpy(MCDI_PTR(inbuf, TABLE_INSERT_IN_DATA), key, kw * sizeof(__le32));
2028	memcpy(MCDI_PTR(inbuf, TABLE_INSERT_IN_DATA) + kw * sizeof(__le32),
2029	       resp, rw * sizeof(__le32));
2030
2031	BUILD_BUG_ON(MC_CMD_TABLE_INSERT_OUT_LEN);
2032
2033	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_INSERT, inbuf, inlen, NULL, 0, NULL);
2034
2035out_free:
2036	kfree(resp);
2037	kfree(key);
2038	kfree(inbuf);
2039	return rc;
2040}
2041
2042int efx_mae_remove_ct(struct efx_nic *efx, struct efx_tc_ct_entry *conn)
2043{
2044	__le32 *key = NULL;
2045	efx_dword_t *inbuf;
2046	size_t inlen, kw;
2047	int rc = -ENOMEM;
2048
2049	/* Check table access is supported */
2050	if (!efx->tc->meta_ct.hooked)
2051		return -EOPNOTSUPP;
2052
2053	/* key width is in bits; convert to dwords for IN_LEN */
2054	kw = DIV_ROUND_UP(efx->tc->meta_ct.desc.key_width, 32);
2055	BUILD_BUG_ON(sizeof(__le32) != MC_CMD_TABLE_DELETE_IN_DATA_LEN);
2056	inlen = MC_CMD_TABLE_DELETE_IN_LEN(kw);
2057	if (inlen > MC_CMD_TABLE_DELETE_IN_LENMAX_MCDI2)
2058		return -E2BIG;
2059	inbuf = kzalloc(inlen, GFP_KERNEL);
2060	if (!inbuf)
2061		return -ENOMEM;
2062
2063	key = kcalloc(kw, sizeof(__le32), GFP_KERNEL);
2064	if (!key)
2065		goto out_free;
2066
2067	rc = efx_mae_populate_ct_key(efx, key, kw, conn);
2068	if (rc)
2069		goto out_free;
2070
2071	MCDI_SET_DWORD(inbuf, TABLE_DELETE_IN_TABLE_ID, TABLE_ID_CONNTRACK_TABLE);
2072	MCDI_SET_WORD(inbuf, TABLE_DELETE_IN_KEY_WIDTH,
2073		      efx->tc->meta_ct.desc.key_width);
2074	/* MASK_WIDTH is zero as CT is a BCAM */
2075	/* RESP_WIDTH is zero for DELETE */
2076	memcpy(MCDI_PTR(inbuf, TABLE_DELETE_IN_DATA), key, kw * sizeof(__le32));
2077
2078	BUILD_BUG_ON(MC_CMD_TABLE_DELETE_OUT_LEN);
2079
2080	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_DELETE, inbuf, inlen, NULL, 0, NULL);
2081
2082out_free:
2083	kfree(key);
2084	kfree(inbuf);
2085	return rc;
2086}
2087
2088static int efx_mae_populate_match_criteria(MCDI_DECLARE_STRUCT_PTR(match_crit),
2089					   const struct efx_tc_match *match)
2090{
2091	if (match->mask.ingress_port) {
2092		if (~match->mask.ingress_port)
2093			return -EOPNOTSUPP;
2094		MCDI_STRUCT_SET_DWORD(match_crit,
2095				      MAE_FIELD_MASK_VALUE_PAIRS_V2_INGRESS_MPORT_SELECTOR,
2096				      match->value.ingress_port);
2097	}
2098	MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_INGRESS_MPORT_SELECTOR_MASK,
2099			      match->mask.ingress_port);
2100	EFX_POPULATE_DWORD_5(*_MCDI_STRUCT_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_FLAGS),
2101			     MAE_FIELD_MASK_VALUE_PAIRS_V2_DO_CT,
2102			     match->value.ct_state_trk,
2103			     MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_HIT,
2104			     match->value.ct_state_est,
2105			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IS_IP_FRAG,
2106			     match->value.ip_frag,
2107			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_FIRST_FRAG,
2108			     match->value.ip_firstfrag,
2109			     MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_SYN_FIN_RST,
2110			     match->value.tcp_syn_fin_rst);
2111	EFX_POPULATE_DWORD_5(*_MCDI_STRUCT_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_FLAGS_MASK),
2112			     MAE_FIELD_MASK_VALUE_PAIRS_V2_DO_CT,
2113			     match->mask.ct_state_trk,
2114			     MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_HIT,
2115			     match->mask.ct_state_est,
2116			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IS_IP_FRAG,
2117			     match->mask.ip_frag,
2118			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_FIRST_FRAG,
2119			     match->mask.ip_firstfrag,
2120			     MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_SYN_FIN_RST,
2121			     match->mask.tcp_syn_fin_rst);
2122	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_RECIRC_ID,
2123			     match->value.recirc_id);
2124	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_RECIRC_ID_MASK,
2125			     match->mask.recirc_id);
2126	MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_MARK,
2127			      match->value.ct_mark);
2128	MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_MARK_MASK,
2129			      match->mask.ct_mark);
2130	MCDI_STRUCT_SET_WORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_DOMAIN,
2131			     match->value.ct_zone);
2132	MCDI_STRUCT_SET_WORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_DOMAIN_MASK,
2133			     match->mask.ct_zone);
2134	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETHER_TYPE_BE,
2135				match->value.eth_proto);
2136	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETHER_TYPE_BE_MASK,
2137				match->mask.eth_proto);
2138	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_TCI_BE,
2139				match->value.vlan_tci[0]);
2140	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_TCI_BE_MASK,
2141				match->mask.vlan_tci[0]);
2142	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_PROTO_BE,
2143				match->value.vlan_proto[0]);
2144	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_PROTO_BE_MASK,
2145				match->mask.vlan_proto[0]);
2146	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_TCI_BE,
2147				match->value.vlan_tci[1]);
2148	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_TCI_BE_MASK,
2149				match->mask.vlan_tci[1]);
2150	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_PROTO_BE,
2151				match->value.vlan_proto[1]);
2152	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_PROTO_BE_MASK,
2153				match->mask.vlan_proto[1]);
2154	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_SADDR_BE),
2155	       match->value.eth_saddr, ETH_ALEN);
2156	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_SADDR_BE_MASK),
2157	       match->mask.eth_saddr, ETH_ALEN);
2158	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_DADDR_BE),
2159	       match->value.eth_daddr, ETH_ALEN);
2160	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_DADDR_BE_MASK),
2161	       match->mask.eth_daddr, ETH_ALEN);
2162	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_PROTO,
2163			     match->value.ip_proto);
2164	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_PROTO_MASK,
2165			     match->mask.ip_proto);
2166	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TOS,
2167			     match->value.ip_tos);
2168	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TOS_MASK,
2169			     match->mask.ip_tos);
2170	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TTL,
2171			     match->value.ip_ttl);
2172	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TTL_MASK,
2173			     match->mask.ip_ttl);
2174	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP4_BE,
2175				 match->value.src_ip);
2176	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP4_BE_MASK,
2177				 match->mask.src_ip);
2178	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP4_BE,
2179				 match->value.dst_ip);
2180	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP4_BE_MASK,
2181				 match->mask.dst_ip);
2182#ifdef CONFIG_IPV6
2183	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP6_BE),
2184	       &match->value.src_ip6, sizeof(struct in6_addr));
2185	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP6_BE_MASK),
2186	       &match->mask.src_ip6, sizeof(struct in6_addr));
2187	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP6_BE),
2188	       &match->value.dst_ip6, sizeof(struct in6_addr));
2189	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP6_BE_MASK),
2190	       &match->mask.dst_ip6, sizeof(struct in6_addr));
2191#endif
2192	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_SPORT_BE,
2193				match->value.l4_sport);
2194	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_SPORT_BE_MASK,
2195				match->mask.l4_sport);
2196	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_DPORT_BE,
2197				match->value.l4_dport);
2198	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_DPORT_BE_MASK,
2199				match->mask.l4_dport);
2200	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_FLAGS_BE,
2201				match->value.tcp_flags);
2202	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_FLAGS_BE_MASK,
2203				match->mask.tcp_flags);
2204	/* enc-keys are handled indirectly, through encap_match ID */
2205	if (match->encap) {
2206		MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_OUTER_RULE_ID,
2207				      match->encap->fw_id);
2208		MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_OUTER_RULE_ID_MASK,
2209				      U32_MAX);
2210		/* enc_keyid (VNI/VSID) is not part of the encap_match */
2211		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ENC_VNET_ID_BE,
2212					 match->value.enc_keyid);
2213		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ENC_VNET_ID_BE_MASK,
2214					 match->mask.enc_keyid);
2215	} else if (WARN_ON_ONCE(match->mask.enc_src_ip) ||
2216		   WARN_ON_ONCE(match->mask.enc_dst_ip) ||
2217		   WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_src_ip6)) ||
2218		   WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_dst_ip6)) ||
2219		   WARN_ON_ONCE(match->mask.enc_ip_tos) ||
2220		   WARN_ON_ONCE(match->mask.enc_ip_ttl) ||
2221		   WARN_ON_ONCE(match->mask.enc_sport) ||
2222		   WARN_ON_ONCE(match->mask.enc_dport) ||
2223		   WARN_ON_ONCE(match->mask.enc_keyid)) {
2224		/* No enc-keys should appear in a rule without an encap_match */
2225		return -EOPNOTSUPP;
2226	}
2227	return 0;
2228}
2229
2230int efx_mae_insert_rule(struct efx_nic *efx, const struct efx_tc_match *match,
2231			u32 prio, u32 acts_id, u32 *id)
2232{
2233	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_INSERT_IN_LEN(MAE_FIELD_MASK_VALUE_PAIRS_V2_LEN));
2234	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_RULE_INSERT_OUT_LEN);
2235	MCDI_DECLARE_STRUCT_PTR(match_crit);
2236	MCDI_DECLARE_STRUCT_PTR(response);
2237	size_t outlen;
2238	int rc;
2239
2240	if (!id)
2241		return -EINVAL;
2242
2243	match_crit = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_MATCH_CRITERIA);
2244	response = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_RESPONSE);
2245	if (efx_mae_asl_id(acts_id)) {
2246		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID, acts_id);
2247		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID,
2248				      MC_CMD_MAE_ACTION_SET_ALLOC_OUT_ACTION_SET_ID_NULL);
2249	} else {
2250		/* We only had one AS, so we didn't wrap it in an ASL */
2251		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID,
2252				      MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL);
2253		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID, acts_id);
2254	}
2255	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_PRIO, prio);
2256	rc = efx_mae_populate_match_criteria(match_crit, match);
2257	if (rc)
2258		return rc;
2259
2260	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_INSERT, inbuf, sizeof(inbuf),
2261			  outbuf, sizeof(outbuf), &outlen);
2262	if (rc)
2263		return rc;
2264	if (outlen < sizeof(outbuf))
2265		return -EIO;
2266	*id = MCDI_DWORD(outbuf, MAE_ACTION_RULE_INSERT_OUT_AR_ID);
2267	return 0;
2268}
2269
2270int efx_mae_update_rule(struct efx_nic *efx, u32 acts_id, u32 id)
2271{
2272	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_UPDATE_IN_LEN);
2273	MCDI_DECLARE_STRUCT_PTR(response);
2274
2275	BUILD_BUG_ON(MC_CMD_MAE_ACTION_RULE_UPDATE_OUT_LEN);
2276	response = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_UPDATE_IN_RESPONSE);
2277
2278	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_UPDATE_IN_AR_ID, id);
2279	if (efx_mae_asl_id(acts_id)) {
2280		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID, acts_id);
2281		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID,
2282				      MC_CMD_MAE_ACTION_SET_ALLOC_OUT_ACTION_SET_ID_NULL);
2283	} else {
2284		/* We only had one AS, so we didn't wrap it in an ASL */
2285		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID,
2286				      MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL);
2287		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID, acts_id);
2288	}
2289	return efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_UPDATE, inbuf, sizeof(inbuf),
2290			    NULL, 0, NULL);
2291}
2292
2293int efx_mae_delete_rule(struct efx_nic *efx, u32 id)
2294{
2295	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_RULE_DELETE_OUT_LEN(1));
2296	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_DELETE_IN_LEN(1));
2297	size_t outlen;
2298	int rc;
2299
2300	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_DELETE_IN_AR_ID, id);
2301	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_DELETE, inbuf, sizeof(inbuf),
2302			  outbuf, sizeof(outbuf), &outlen);
2303	if (rc)
2304		return rc;
2305	if (outlen < sizeof(outbuf))
2306		return -EIO;
2307	/* FW freed a different ID than we asked for, should also never happen.
2308	 * Warn because it means we've now got a different idea to the FW of
2309	 * what rules exist, which could cause mayhem later.
2310	 */
2311	if (WARN_ON(MCDI_DWORD(outbuf, MAE_ACTION_RULE_DELETE_OUT_DELETED_AR_ID) != id))
2312		return -EIO;
2313	return 0;
2314}
2315
2316int efx_init_mae(struct efx_nic *efx)
2317{
2318	struct ef100_nic_data *nic_data = efx->nic_data;
2319	struct efx_mae *mae;
2320	int rc;
2321
2322	if (!nic_data->have_mport)
2323		return -EINVAL;
2324
2325	mae = kmalloc(sizeof(*mae), GFP_KERNEL);
2326	if (!mae)
2327		return -ENOMEM;
2328
2329	rc = rhashtable_init(&mae->mports_ht, &efx_mae_mports_ht_params);
2330	if (rc < 0) {
2331		kfree(mae);
2332		return rc;
2333	}
2334	efx->mae = mae;
2335	mae->efx = efx;
2336	return 0;
2337}
2338
2339void efx_fini_mae(struct efx_nic *efx)
2340{
2341	struct efx_mae *mae = efx->mae;
2342
2343	kfree(mae);
2344	efx->mae = NULL;
2345}
v6.13.7
   1// SPDX-License-Identifier: GPL-2.0-only
   2/****************************************************************************
   3 * Driver for Solarflare network controllers and boards
   4 * Copyright 2019 Solarflare Communications Inc.
   5 * Copyright 2020-2022 Xilinx Inc.
   6 *
   7 * This program is free software; you can redistribute it and/or modify it
   8 * under the terms of the GNU General Public License version 2 as published
   9 * by the Free Software Foundation, incorporated herein by reference.
  10 */
  11
  12#include <linux/rhashtable.h>
  13#include "ef100_nic.h"
  14#include "mae.h"
  15#include "mcdi.h"
  16#include "mcdi_pcol.h"
  17#include "mcdi_pcol_mae.h"
  18#include "tc_encap_actions.h"
  19#include "tc_conntrack.h"
  20
  21int efx_mae_allocate_mport(struct efx_nic *efx, u32 *id, u32 *label)
  22{
  23	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MPORT_ALLOC_ALIAS_OUT_LEN);
  24	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_ALLOC_ALIAS_IN_LEN);
  25	size_t outlen;
  26	int rc;
  27
  28	if (WARN_ON_ONCE(!id))
  29		return -EINVAL;
  30	if (WARN_ON_ONCE(!label))
  31		return -EINVAL;
  32
  33	MCDI_SET_DWORD(inbuf, MAE_MPORT_ALLOC_ALIAS_IN_TYPE,
  34		       MC_CMD_MAE_MPORT_ALLOC_ALIAS_IN_MPORT_TYPE_ALIAS);
  35	MCDI_SET_DWORD(inbuf, MAE_MPORT_ALLOC_ALIAS_IN_DELIVER_MPORT,
  36		       MAE_MPORT_SELECTOR_ASSIGNED);
  37	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_ALLOC, inbuf, sizeof(inbuf),
  38			  outbuf, sizeof(outbuf), &outlen);
  39	if (rc)
  40		return rc;
  41	if (outlen < sizeof(outbuf))
  42		return -EIO;
  43	*id = MCDI_DWORD(outbuf, MAE_MPORT_ALLOC_ALIAS_OUT_MPORT_ID);
  44	*label = MCDI_DWORD(outbuf, MAE_MPORT_ALLOC_ALIAS_OUT_LABEL);
  45	return 0;
  46}
  47
  48int efx_mae_free_mport(struct efx_nic *efx, u32 id)
  49{
  50	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_FREE_IN_LEN);
  51
  52	BUILD_BUG_ON(MC_CMD_MAE_MPORT_FREE_OUT_LEN);
  53	MCDI_SET_DWORD(inbuf, MAE_MPORT_FREE_IN_MPORT_ID, id);
  54	return efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_FREE, inbuf, sizeof(inbuf),
  55			    NULL, 0, NULL);
  56}
  57
  58void efx_mae_mport_wire(struct efx_nic *efx, u32 *out)
  59{
  60	efx_dword_t mport;
  61
  62	EFX_POPULATE_DWORD_2(mport,
  63			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_PPORT,
  64			     MAE_MPORT_SELECTOR_PPORT_ID, efx->port_num);
  65	*out = EFX_DWORD_VAL(mport);
  66}
  67
  68void efx_mae_mport_uplink(struct efx_nic *efx __always_unused, u32 *out)
  69{
  70	efx_dword_t mport;
  71
  72	EFX_POPULATE_DWORD_3(mport,
  73			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_FUNC,
  74			     MAE_MPORT_SELECTOR_FUNC_PF_ID, MAE_MPORT_SELECTOR_FUNC_PF_ID_CALLER,
  75			     MAE_MPORT_SELECTOR_FUNC_VF_ID, MAE_MPORT_SELECTOR_FUNC_VF_ID_NULL);
  76	*out = EFX_DWORD_VAL(mport);
  77}
  78
 
 
 
 
 
 
 
 
 
 
 
  79/* Constructs an mport selector from an mport ID, because they're not the same */
  80void efx_mae_mport_mport(struct efx_nic *efx __always_unused, u32 mport_id, u32 *out)
  81{
  82	efx_dword_t mport;
  83
  84	EFX_POPULATE_DWORD_2(mport,
  85			     MAE_MPORT_SELECTOR_TYPE, MAE_MPORT_SELECTOR_TYPE_MPORT_ID,
  86			     MAE_MPORT_SELECTOR_MPORT_ID, mport_id);
  87	*out = EFX_DWORD_VAL(mport);
  88}
  89
  90/* id is really only 24 bits wide */
  91int efx_mae_fw_lookup_mport(struct efx_nic *efx, u32 selector, u32 *id)
  92{
  93	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MPORT_LOOKUP_OUT_LEN);
  94	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_LOOKUP_IN_LEN);
  95	size_t outlen;
  96	int rc;
  97
  98	MCDI_SET_DWORD(inbuf, MAE_MPORT_LOOKUP_IN_MPORT_SELECTOR, selector);
  99	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_LOOKUP, inbuf, sizeof(inbuf),
 100			  outbuf, sizeof(outbuf), &outlen);
 101	if (rc)
 102		return rc;
 103	if (outlen < sizeof(outbuf))
 104		return -EIO;
 105	*id = MCDI_DWORD(outbuf, MAE_MPORT_LOOKUP_OUT_MPORT_ID);
 106	return 0;
 107}
 108
 109int efx_mae_start_counters(struct efx_nic *efx, struct efx_rx_queue *rx_queue)
 110{
 111	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTERS_STREAM_START_V2_IN_LEN);
 112	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTERS_STREAM_START_OUT_LEN);
 113	u32 out_flags;
 114	size_t outlen;
 115	int rc;
 116
 117	MCDI_SET_WORD(inbuf, MAE_COUNTERS_STREAM_START_V2_IN_QID,
 118		      efx_rx_queue_index(rx_queue));
 119	MCDI_SET_WORD(inbuf, MAE_COUNTERS_STREAM_START_V2_IN_PACKET_SIZE,
 120		      efx->net_dev->mtu);
 121	MCDI_SET_DWORD(inbuf, MAE_COUNTERS_STREAM_START_V2_IN_COUNTER_TYPES_MASK,
 122		       BIT(MAE_COUNTER_TYPE_AR) | BIT(MAE_COUNTER_TYPE_CT) |
 123		       BIT(MAE_COUNTER_TYPE_OR));
 124	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTERS_STREAM_START,
 125			  inbuf, sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
 126	if (rc)
 127		return rc;
 128	if (outlen < sizeof(outbuf))
 129		return -EIO;
 130	out_flags = MCDI_DWORD(outbuf, MAE_COUNTERS_STREAM_START_OUT_FLAGS);
 131	if (out_flags & BIT(MC_CMD_MAE_COUNTERS_STREAM_START_OUT_USES_CREDITS_OFST)) {
 132		netif_dbg(efx, drv, efx->net_dev,
 133			  "MAE counter stream uses credits\n");
 134		rx_queue->grant_credits = true;
 135		out_flags &= ~BIT(MC_CMD_MAE_COUNTERS_STREAM_START_OUT_USES_CREDITS_OFST);
 136	}
 137	if (out_flags) {
 138		netif_err(efx, drv, efx->net_dev,
 139			  "MAE counter stream start: unrecognised flags %x\n",
 140			  out_flags);
 141		goto out_stop;
 142	}
 143	return 0;
 144out_stop:
 145	efx_mae_stop_counters(efx, rx_queue);
 146	return -EOPNOTSUPP;
 147}
 148
 149static bool efx_mae_counters_flushed(u32 *flush_gen, u32 *seen_gen)
 150{
 151	int i;
 152
 153	for (i = 0; i < EFX_TC_COUNTER_TYPE_MAX; i++)
 154		if ((s32)(flush_gen[i] - seen_gen[i]) > 0)
 155			return false;
 156	return true;
 157}
 158
 159int efx_mae_stop_counters(struct efx_nic *efx, struct efx_rx_queue *rx_queue)
 160{
 161	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTERS_STREAM_STOP_V2_OUT_LENMAX);
 162	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTERS_STREAM_STOP_IN_LEN);
 163	size_t outlen;
 164	int rc, i;
 165
 166	MCDI_SET_WORD(inbuf, MAE_COUNTERS_STREAM_STOP_IN_QID,
 167		      efx_rx_queue_index(rx_queue));
 168	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTERS_STREAM_STOP,
 169			  inbuf, sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
 170
 171	if (rc)
 172		return rc;
 173
 174	netif_dbg(efx, drv, efx->net_dev, "Draining counters:\n");
 175	/* Only process received generation counts */
 176	for (i = 0; (i < (outlen / 4)) && (i < EFX_TC_COUNTER_TYPE_MAX); i++) {
 177		efx->tc->flush_gen[i] = MCDI_ARRAY_DWORD(outbuf,
 178							 MAE_COUNTERS_STREAM_STOP_V2_OUT_GENERATION_COUNT,
 179							 i);
 180		netif_dbg(efx, drv, efx->net_dev,
 181			  "\ttype %u, awaiting gen %u\n", i,
 182			  efx->tc->flush_gen[i]);
 183	}
 184
 185	efx->tc->flush_counters = true;
 186
 187	/* Drain can take up to 2 seconds owing to FWRIVERHD-2884; whatever
 188	 * timeout we use, that delay is added to unload on nonresponsive
 189	 * hardware, so 2500ms seems like a reasonable compromise.
 190	 */
 191	if (!wait_event_timeout(efx->tc->flush_wq,
 192				efx_mae_counters_flushed(efx->tc->flush_gen,
 193							 efx->tc->seen_gen),
 194				msecs_to_jiffies(2500)))
 195		netif_warn(efx, drv, efx->net_dev,
 196			   "Failed to drain counters RXQ, FW may be unhappy\n");
 197
 198	efx->tc->flush_counters = false;
 199
 200	return rc;
 201}
 202
 203void efx_mae_counters_grant_credits(struct work_struct *work)
 204{
 205	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTERS_STREAM_GIVE_CREDITS_IN_LEN);
 206	struct efx_rx_queue *rx_queue = container_of(work, struct efx_rx_queue,
 207						     grant_work);
 208	struct efx_nic *efx = rx_queue->efx;
 209	unsigned int credits;
 210
 211	BUILD_BUG_ON(MC_CMD_MAE_COUNTERS_STREAM_GIVE_CREDITS_OUT_LEN);
 212	credits = READ_ONCE(rx_queue->notified_count) - rx_queue->granted_count;
 213	MCDI_SET_DWORD(inbuf, MAE_COUNTERS_STREAM_GIVE_CREDITS_IN_NUM_CREDITS,
 214		       credits);
 215	if (!efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTERS_STREAM_GIVE_CREDITS,
 216			  inbuf, sizeof(inbuf), NULL, 0, NULL))
 217		rx_queue->granted_count += credits;
 218}
 219
 220static int efx_mae_table_get_desc(struct efx_nic *efx,
 221				  struct efx_tc_table_desc *desc,
 222				  u32 table_id)
 223{
 224	MCDI_DECLARE_BUF(outbuf, MC_CMD_TABLE_DESCRIPTOR_OUT_LEN(16));
 225	MCDI_DECLARE_BUF(inbuf, MC_CMD_TABLE_DESCRIPTOR_IN_LEN);
 226	unsigned int offset = 0, i;
 227	size_t outlen;
 228	int rc;
 229
 230	memset(desc, 0, sizeof(*desc));
 231
 232	MCDI_SET_DWORD(inbuf, TABLE_DESCRIPTOR_IN_TABLE_ID, table_id);
 233more:
 234	MCDI_SET_DWORD(inbuf, TABLE_DESCRIPTOR_IN_FIRST_FIELDS_INDEX, offset);
 235	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_DESCRIPTOR, inbuf, sizeof(inbuf),
 236			  outbuf, sizeof(outbuf), &outlen);
 237	if (rc)
 238		goto fail;
 239	if (outlen < MC_CMD_TABLE_DESCRIPTOR_OUT_LEN(1)) {
 240		rc = -EIO;
 241		goto fail;
 242	}
 243	if (!offset) { /* first iteration: get metadata */
 244		desc->type = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_TYPE);
 245		desc->key_width = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_KEY_WIDTH);
 246		desc->resp_width = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_RESP_WIDTH);
 247		desc->n_keys = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_N_KEY_FIELDS);
 248		desc->n_resps = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_N_RESP_FIELDS);
 249		desc->n_prios = MCDI_WORD(outbuf, TABLE_DESCRIPTOR_OUT_N_PRIORITIES);
 250		desc->flags = MCDI_BYTE(outbuf, TABLE_DESCRIPTOR_OUT_FLAGS);
 251		rc = -EOPNOTSUPP;
 252		if (desc->flags)
 253			goto fail;
 254		desc->scheme = MCDI_BYTE(outbuf, TABLE_DESCRIPTOR_OUT_SCHEME);
 255		if (desc->scheme)
 256			goto fail;
 257		rc = -ENOMEM;
 258		desc->keys = kcalloc(desc->n_keys,
 259				     sizeof(struct efx_tc_table_field_fmt),
 260				     GFP_KERNEL);
 261		if (!desc->keys)
 262			goto fail;
 263		desc->resps = kcalloc(desc->n_resps,
 264				      sizeof(struct efx_tc_table_field_fmt),
 265				      GFP_KERNEL);
 266		if (!desc->resps)
 267			goto fail;
 268	}
 269	/* FW could have returned more than the 16 field_descrs we
 270	 * made room for in our outbuf
 271	 */
 272	outlen = min(outlen, sizeof(outbuf));
 273	for (i = 0; i + offset < desc->n_keys + desc->n_resps; i++) {
 274		struct efx_tc_table_field_fmt *field;
 275		MCDI_DECLARE_STRUCT_PTR(fdesc);
 276
 277		if (outlen < MC_CMD_TABLE_DESCRIPTOR_OUT_LEN(i + 1)) {
 278			offset += i;
 279			goto more;
 280		}
 281		if (i + offset < desc->n_keys)
 282			field = desc->keys + i + offset;
 283		else
 284			field = desc->resps + (i + offset - desc->n_keys);
 285		fdesc = MCDI_ARRAY_STRUCT_PTR(outbuf,
 286					      TABLE_DESCRIPTOR_OUT_FIELDS, i);
 287		field->field_id = MCDI_STRUCT_WORD(fdesc,
 288						   TABLE_FIELD_DESCR_FIELD_ID);
 289		field->lbn = MCDI_STRUCT_WORD(fdesc, TABLE_FIELD_DESCR_LBN);
 290		field->width = MCDI_STRUCT_WORD(fdesc, TABLE_FIELD_DESCR_WIDTH);
 291		field->masking = MCDI_STRUCT_BYTE(fdesc, TABLE_FIELD_DESCR_MASK_TYPE);
 292		field->scheme = MCDI_STRUCT_BYTE(fdesc, TABLE_FIELD_DESCR_SCHEME);
 293	}
 294	return 0;
 295
 296fail:
 297	kfree(desc->keys);
 298	kfree(desc->resps);
 299	return rc;
 300}
 301
 302static int efx_mae_table_hook_find(u16 n_fields,
 303				   struct efx_tc_table_field_fmt *fields,
 304				   u16 field_id)
 305{
 306	unsigned int i;
 307
 308	for (i = 0; i < n_fields; i++) {
 309		if (fields[i].field_id == field_id)
 310			return i;
 311	}
 312	return -EPROTO;
 313}
 314
 315#define TABLE_FIND_KEY(_desc, _id)	\
 316	efx_mae_table_hook_find((_desc)->n_keys, (_desc)->keys, _id)
 317#define TABLE_FIND_RESP(_desc, _id)	\
 318	efx_mae_table_hook_find((_desc)->n_resps, (_desc)->resps, _id)
 319
 320#define TABLE_HOOK_KEY(_meta, _name, _mcdi_name)	({			\
 321	int _rc = TABLE_FIND_KEY(&_meta->desc, TABLE_FIELD_ID_##_mcdi_name);	\
 322										\
 323	if (_rc > U8_MAX)							\
 324		_rc = -EOPNOTSUPP;						\
 325	if (_rc >= 0) {								\
 326		_meta->keys._name##_idx = _rc;					\
 327		_rc = 0;							\
 328	}									\
 329	_rc;									\
 330})
 331#define TABLE_HOOK_RESP(_meta, _name, _mcdi_name)	({			\
 332	int _rc = TABLE_FIND_RESP(&_meta->desc, TABLE_FIELD_ID_##_mcdi_name);	\
 333										\
 334	if (_rc > U8_MAX)							\
 335		_rc = -EOPNOTSUPP;						\
 336	if (_rc >= 0) {								\
 337		_meta->resps._name##_idx = _rc;					\
 338		_rc = 0;							\
 339	}									\
 340	_rc;									\
 341})
 342
 343static int efx_mae_table_hook_ct(struct efx_nic *efx,
 344				 struct efx_tc_table_ct *meta_ct)
 345{
 346	int rc;
 347
 348	rc = TABLE_HOOK_KEY(meta_ct, eth_proto, ETHER_TYPE);
 349	if (rc)
 350		return rc;
 351	rc = TABLE_HOOK_KEY(meta_ct, ip_proto, IP_PROTO);
 352	if (rc)
 353		return rc;
 354	rc = TABLE_HOOK_KEY(meta_ct, src_ip, SRC_IP);
 355	if (rc)
 356		return rc;
 357	rc = TABLE_HOOK_KEY(meta_ct, dst_ip, DST_IP);
 358	if (rc)
 359		return rc;
 360	rc = TABLE_HOOK_KEY(meta_ct, l4_sport, SRC_PORT);
 361	if (rc)
 362		return rc;
 363	rc = TABLE_HOOK_KEY(meta_ct, l4_dport, DST_PORT);
 364	if (rc)
 365		return rc;
 366	rc = TABLE_HOOK_KEY(meta_ct, zone, DOMAIN);
 367	if (rc)
 368		return rc;
 369	rc = TABLE_HOOK_RESP(meta_ct, dnat, NAT_DIR);
 370	if (rc)
 371		return rc;
 372	rc = TABLE_HOOK_RESP(meta_ct, nat_ip, NAT_IP);
 373	if (rc)
 374		return rc;
 375	rc = TABLE_HOOK_RESP(meta_ct, l4_natport, NAT_PORT);
 376	if (rc)
 377		return rc;
 378	rc = TABLE_HOOK_RESP(meta_ct, mark, CT_MARK);
 379	if (rc)
 380		return rc;
 381	rc = TABLE_HOOK_RESP(meta_ct, counter_id, COUNTER_ID);
 382	if (rc)
 383		return rc;
 384	meta_ct->hooked = true;
 385	return 0;
 386}
 387
 388static void efx_mae_table_free_desc(struct efx_tc_table_desc *desc)
 389{
 390	kfree(desc->keys);
 391	kfree(desc->resps);
 392	memset(desc, 0, sizeof(*desc));
 393}
 394
 395static bool efx_mae_check_table_exists(struct efx_nic *efx, u32 tbl_req)
 396{
 397	MCDI_DECLARE_BUF(outbuf, MC_CMD_TABLE_LIST_OUT_LEN(16));
 398	MCDI_DECLARE_BUF(inbuf, MC_CMD_TABLE_LIST_IN_LEN);
 399	u32 tbl_id, tbl_total, tbl_cnt, pos = 0;
 400	size_t outlen, msg_max;
 401	bool ct_tbl = false;
 402	int rc, idx;
 403
 404	msg_max = sizeof(outbuf);
 405	efx->tc->meta_ct.hooked = false;
 406more:
 407	memset(outbuf, 0, sizeof(*outbuf));
 408	MCDI_SET_DWORD(inbuf, TABLE_LIST_IN_FIRST_TABLE_ID_INDEX, pos);
 409	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_LIST, inbuf, sizeof(inbuf), outbuf,
 410			  msg_max, &outlen);
 411	if (rc)
 412		return false;
 413
 414	if (outlen < MC_CMD_TABLE_LIST_OUT_LEN(1))
 415		return false;
 416
 417	tbl_total = MCDI_DWORD(outbuf, TABLE_LIST_OUT_N_TABLES);
 418	tbl_cnt = MC_CMD_TABLE_LIST_OUT_TABLE_ID_NUM(min(outlen, msg_max));
 419
 420	for (idx = 0; idx < tbl_cnt; idx++) {
 421		tbl_id = MCDI_ARRAY_DWORD(outbuf, TABLE_LIST_OUT_TABLE_ID, idx);
 422		if (tbl_id == tbl_req) {
 423			ct_tbl = true;
 424			break;
 425		}
 426	}
 427
 428	pos += tbl_cnt;
 429	if (!ct_tbl && pos < tbl_total)
 430		goto more;
 431
 432	return ct_tbl;
 433}
 434
 435int efx_mae_get_tables(struct efx_nic *efx)
 436{
 437	int rc;
 438
 439	efx->tc->meta_ct.hooked = false;
 440	if (efx_mae_check_table_exists(efx, TABLE_ID_CONNTRACK_TABLE)) {
 441		rc = efx_mae_table_get_desc(efx, &efx->tc->meta_ct.desc,
 442					    TABLE_ID_CONNTRACK_TABLE);
 443		if (rc) {
 444			pci_info(efx->pci_dev,
 445				 "FW does not support conntrack desc rc %d\n",
 446				 rc);
 447			return 0;
 448		}
 449
 450		rc = efx_mae_table_hook_ct(efx, &efx->tc->meta_ct);
 451		if (rc) {
 452			pci_info(efx->pci_dev,
 453				 "FW does not support conntrack hook rc %d\n",
 454				 rc);
 455			return 0;
 456		}
 457	} else {
 458		pci_info(efx->pci_dev,
 459			 "FW does not support conntrack table\n");
 460	}
 461	return 0;
 462}
 463
 464void efx_mae_free_tables(struct efx_nic *efx)
 465{
 466	efx_mae_table_free_desc(&efx->tc->meta_ct.desc);
 467	efx->tc->meta_ct.hooked = false;
 468}
 469
 470static int efx_mae_get_basic_caps(struct efx_nic *efx, struct mae_caps *caps)
 471{
 472	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_GET_CAPS_OUT_LEN);
 473	size_t outlen;
 474	int rc;
 475
 476	BUILD_BUG_ON(MC_CMD_MAE_GET_CAPS_IN_LEN);
 477
 478	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_GET_CAPS, NULL, 0, outbuf,
 479			  sizeof(outbuf), &outlen);
 480	if (rc)
 481		return rc;
 482	if (outlen < sizeof(outbuf))
 483		return -EIO;
 484	caps->match_field_count = MCDI_DWORD(outbuf, MAE_GET_CAPS_OUT_MATCH_FIELD_COUNT);
 485	caps->encap_types = MCDI_DWORD(outbuf, MAE_GET_CAPS_OUT_ENCAP_TYPES_SUPPORTED);
 486	caps->action_prios = MCDI_DWORD(outbuf, MAE_GET_CAPS_OUT_ACTION_PRIOS);
 487	return 0;
 488}
 489
 490static int efx_mae_get_rule_fields(struct efx_nic *efx, u32 cmd,
 491				   u8 *field_support)
 492{
 493	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_GET_AR_CAPS_OUT_LEN(MAE_NUM_FIELDS));
 494	MCDI_DECLARE_STRUCT_PTR(caps);
 495	unsigned int count;
 496	size_t outlen;
 497	int rc, i;
 498
 499	/* AR and OR caps MCDIs have identical layout, so we are using the
 500	 * same code for both.
 501	 */
 502	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_OUT_LEN(MAE_NUM_FIELDS) <
 503		     MC_CMD_MAE_GET_OR_CAPS_OUT_LEN(MAE_NUM_FIELDS));
 504	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_IN_LEN);
 505	BUILD_BUG_ON(MC_CMD_MAE_GET_OR_CAPS_IN_LEN);
 506
 507	rc = efx_mcdi_rpc(efx, cmd, NULL, 0, outbuf, sizeof(outbuf), &outlen);
 508	if (rc)
 509		return rc;
 510	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_OUT_COUNT_OFST !=
 511		     MC_CMD_MAE_GET_OR_CAPS_OUT_COUNT_OFST);
 512	count = MCDI_DWORD(outbuf, MAE_GET_AR_CAPS_OUT_COUNT);
 513	memset(field_support, MAE_FIELD_UNSUPPORTED, MAE_NUM_FIELDS);
 514	BUILD_BUG_ON(MC_CMD_MAE_GET_AR_CAPS_OUT_FIELD_FLAGS_OFST !=
 515		     MC_CMD_MAE_GET_OR_CAPS_OUT_FIELD_FLAGS_OFST);
 516	caps = _MCDI_DWORD(outbuf, MAE_GET_AR_CAPS_OUT_FIELD_FLAGS);
 517	/* We're only interested in the support status enum, not any other
 518	 * flags, so just extract that from each entry.
 519	 */
 520	for (i = 0; i < count; i++)
 521		if (i * sizeof(*outbuf) + MC_CMD_MAE_GET_AR_CAPS_OUT_FIELD_FLAGS_OFST < outlen)
 522			field_support[i] = EFX_DWORD_FIELD(caps[i], MAE_FIELD_FLAGS_SUPPORT_STATUS);
 523	return 0;
 524}
 525
 526int efx_mae_get_caps(struct efx_nic *efx, struct mae_caps *caps)
 527{
 528	int rc;
 529
 530	rc = efx_mae_get_basic_caps(efx, caps);
 531	if (rc)
 532		return rc;
 533	rc = efx_mae_get_rule_fields(efx, MC_CMD_MAE_GET_AR_CAPS,
 534				     caps->action_rule_fields);
 535	if (rc)
 536		return rc;
 537	return efx_mae_get_rule_fields(efx, MC_CMD_MAE_GET_OR_CAPS,
 538				       caps->outer_rule_fields);
 539}
 540
 541/* Bit twiddling:
 542 * Prefix: 1...110...0
 543 *      ~: 0...001...1
 544 *    + 1: 0...010...0 is power of two
 545 * so (~x) & ((~x) + 1) == 0.  Converse holds also.
 546 */
 547#define is_prefix_byte(_x)	!(((_x) ^ 0xff) & (((_x) ^ 0xff) + 1))
 548
 549enum mask_type { MASK_ONES, MASK_ZEROES, MASK_PREFIX, MASK_OTHER };
 550
 551static const char *mask_type_name(enum mask_type typ)
 552{
 553	switch (typ) {
 554	case MASK_ONES:
 555		return "all-1s";
 556	case MASK_ZEROES:
 557		return "all-0s";
 558	case MASK_PREFIX:
 559		return "prefix";
 560	case MASK_OTHER:
 561		return "arbitrary";
 562	default: /* can't happen */
 563		return "unknown";
 564	}
 565}
 566
 567/* Checks a (big-endian) bytestring is a bit prefix */
 568static enum mask_type classify_mask(const u8 *mask, size_t len)
 569{
 570	bool zeroes = true; /* All bits seen so far are zeroes */
 571	bool ones = true; /* All bits seen so far are ones */
 572	bool prefix = true; /* Valid prefix so far */
 573	size_t i;
 574
 575	for (i = 0; i < len; i++) {
 576		if (ones) {
 577			if (!is_prefix_byte(mask[i]))
 578				prefix = false;
 579		} else if (mask[i]) {
 580			prefix = false;
 581		}
 582		if (mask[i] != 0xff)
 583			ones = false;
 584		if (mask[i])
 585			zeroes = false;
 586	}
 587	if (ones)
 588		return MASK_ONES;
 589	if (zeroes)
 590		return MASK_ZEROES;
 591	if (prefix)
 592		return MASK_PREFIX;
 593	return MASK_OTHER;
 594}
 595
 596static int efx_mae_match_check_cap_typ(u8 support, enum mask_type typ)
 597{
 598	switch (support) {
 599	case MAE_FIELD_UNSUPPORTED:
 600	case MAE_FIELD_SUPPORTED_MATCH_NEVER:
 601		if (typ == MASK_ZEROES)
 602			return 0;
 603		return -EOPNOTSUPP;
 604	case MAE_FIELD_SUPPORTED_MATCH_OPTIONAL:
 605		if (typ == MASK_ZEROES)
 606			return 0;
 607		fallthrough;
 608	case MAE_FIELD_SUPPORTED_MATCH_ALWAYS:
 609		if (typ == MASK_ONES)
 610			return 0;
 611		return -EINVAL;
 612	case MAE_FIELD_SUPPORTED_MATCH_PREFIX:
 613		if (typ == MASK_OTHER)
 614			return -EOPNOTSUPP;
 615		return 0;
 616	case MAE_FIELD_SUPPORTED_MATCH_MASK:
 617		return 0;
 618	default:
 619		return -EIO;
 620	}
 621}
 622
 623/* Validate field mask against hardware capabilities.  Captures caller's 'rc' */
 624#define CHECK(_mcdi, _field)	({					       \
 625	enum mask_type typ = classify_mask((const u8 *)&mask->_field,	       \
 626					   sizeof(mask->_field));	       \
 627									       \
 628	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ ## _mcdi],\
 629					 typ);				       \
 630	if (rc)								       \
 631		NL_SET_ERR_MSG_FMT_MOD(extack,				       \
 632				       "No support for %s mask in field %s",   \
 633				       mask_type_name(typ), #_field);	       \
 634	rc;								       \
 635})
 636/* Booleans need special handling */
 637#define CHECK_BIT(_mcdi, _field)	({				       \
 638	enum mask_type typ = mask->_field ? MASK_ONES : MASK_ZEROES;	       \
 639									       \
 640	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ ## _mcdi],\
 641					 typ);				       \
 642	if (rc)								       \
 643		NL_SET_ERR_MSG_FMT_MOD(extack,				       \
 644				       "No support for %s mask in field %s",   \
 645				       mask_type_name(typ), #_field);	       \
 646	rc;								       \
 647})
 648
 649int efx_mae_match_check_caps(struct efx_nic *efx,
 650			     const struct efx_tc_match_fields *mask,
 651			     struct netlink_ext_ack *extack)
 652{
 653	const u8 *supported_fields = efx->tc->caps->action_rule_fields;
 654	__be32 ingress_port = cpu_to_be32(mask->ingress_port);
 655	enum mask_type ingress_port_mask_type;
 656	int rc;
 657
 658	/* Check for _PREFIX assumes big-endian, so we need to convert */
 659	ingress_port_mask_type = classify_mask((const u8 *)&ingress_port,
 660					       sizeof(ingress_port));
 661	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_INGRESS_PORT],
 662					 ingress_port_mask_type);
 663	if (rc) {
 664		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field ingress_port",
 665				       mask_type_name(ingress_port_mask_type));
 666		return rc;
 667	}
 668	if (CHECK(ETHER_TYPE, eth_proto) ||
 669	    CHECK(VLAN0_TCI, vlan_tci[0]) ||
 670	    CHECK(VLAN0_PROTO, vlan_proto[0]) ||
 671	    CHECK(VLAN1_TCI, vlan_tci[1]) ||
 672	    CHECK(VLAN1_PROTO, vlan_proto[1]) ||
 673	    CHECK(ETH_SADDR, eth_saddr) ||
 674	    CHECK(ETH_DADDR, eth_daddr) ||
 675	    CHECK(IP_PROTO, ip_proto) ||
 676	    CHECK(IP_TOS, ip_tos) ||
 677	    CHECK(IP_TTL, ip_ttl) ||
 678	    CHECK(SRC_IP4, src_ip) ||
 679	    CHECK(DST_IP4, dst_ip) ||
 680#ifdef CONFIG_IPV6
 681	    CHECK(SRC_IP6, src_ip6) ||
 682	    CHECK(DST_IP6, dst_ip6) ||
 683#endif
 684	    CHECK(L4_SPORT, l4_sport) ||
 685	    CHECK(L4_DPORT, l4_dport) ||
 686	    CHECK(TCP_FLAGS, tcp_flags) ||
 687	    CHECK_BIT(TCP_SYN_FIN_RST, tcp_syn_fin_rst) ||
 688	    CHECK_BIT(IS_IP_FRAG, ip_frag) ||
 689	    CHECK_BIT(IP_FIRST_FRAG, ip_firstfrag) ||
 690	    CHECK_BIT(DO_CT, ct_state_trk) ||
 691	    CHECK_BIT(CT_HIT, ct_state_est) ||
 692	    CHECK(CT_MARK, ct_mark) ||
 693	    CHECK(CT_DOMAIN, ct_zone) ||
 694	    CHECK(RECIRC_ID, recirc_id))
 695		return rc;
 696	/* Matches on outer fields are done in a separate hardware table,
 697	 * the Outer Rule table.  Thus the Action Rule merely does an
 698	 * exact match on Outer Rule ID if any outer field matches are
 699	 * present.  The exception is the VNI/VSID (enc_keyid), which is
 700	 * available to the Action Rule match iff the Outer Rule matched
 701	 * (and thus identified the encap protocol to use to extract it).
 702	 */
 703	if (efx_tc_match_is_encap(mask)) {
 704		rc = efx_mae_match_check_cap_typ(
 705				supported_fields[MAE_FIELD_OUTER_RULE_ID],
 706				MASK_ONES);
 707		if (rc) {
 708			NL_SET_ERR_MSG_MOD(extack, "No support for encap rule ID matches");
 709			return rc;
 710		}
 711		if (CHECK(ENC_VNET_ID, enc_keyid))
 712			return rc;
 713	} else if (mask->enc_keyid) {
 714		NL_SET_ERR_MSG_MOD(extack, "Match on enc_keyid requires other encap fields");
 715		return -EINVAL;
 716	}
 717	return 0;
 718}
 719
 720/* Checks for match fields not supported in LHS Outer Rules */
 721#define UNSUPPORTED(_field)	({					       \
 722	enum mask_type typ = classify_mask((const u8 *)&mask->_field,	       \
 723					   sizeof(mask->_field));	       \
 724									       \
 725	if (typ != MASK_ZEROES) {					       \
 726		NL_SET_ERR_MSG_MOD(extack, "Unsupported match field " #_field);\
 727		rc = -EOPNOTSUPP;					       \
 728	}								       \
 729	rc;								       \
 730})
 731#define UNSUPPORTED_BIT(_field)	({					       \
 732	if (mask->_field) {						       \
 733		NL_SET_ERR_MSG_MOD(extack, "Unsupported match field " #_field);\
 734		rc = -EOPNOTSUPP;					       \
 735	}								       \
 736	rc;								       \
 737})
 738
 739/* LHS rules are (normally) inserted in the Outer Rule table, which means
 740 * they use ENC_ fields in hardware to match regular (not enc_) fields from
 741 * &struct efx_tc_match_fields.
 742 */
 743int efx_mae_match_check_caps_lhs(struct efx_nic *efx,
 744				 const struct efx_tc_match_fields *mask,
 745				 struct netlink_ext_ack *extack)
 746{
 747	const u8 *supported_fields = efx->tc->caps->outer_rule_fields;
 748	__be32 ingress_port = cpu_to_be32(mask->ingress_port);
 749	enum mask_type ingress_port_mask_type;
 750	int rc;
 751
 752	/* Check for _PREFIX assumes big-endian, so we need to convert */
 753	ingress_port_mask_type = classify_mask((const u8 *)&ingress_port,
 754					       sizeof(ingress_port));
 755	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_INGRESS_PORT],
 756					 ingress_port_mask_type);
 757	if (rc) {
 758		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field %s\n",
 759				       mask_type_name(ingress_port_mask_type),
 760				       "ingress_port");
 761		return rc;
 762	}
 763	if (CHECK(ENC_ETHER_TYPE, eth_proto) ||
 764	    CHECK(ENC_VLAN0_TCI, vlan_tci[0]) ||
 765	    CHECK(ENC_VLAN0_PROTO, vlan_proto[0]) ||
 766	    CHECK(ENC_VLAN1_TCI, vlan_tci[1]) ||
 767	    CHECK(ENC_VLAN1_PROTO, vlan_proto[1]) ||
 768	    CHECK(ENC_ETH_SADDR, eth_saddr) ||
 769	    CHECK(ENC_ETH_DADDR, eth_daddr) ||
 770	    CHECK(ENC_IP_PROTO, ip_proto) ||
 771	    CHECK(ENC_IP_TOS, ip_tos) ||
 772	    CHECK(ENC_IP_TTL, ip_ttl) ||
 773	    CHECK_BIT(ENC_IP_FRAG, ip_frag) ||
 774	    UNSUPPORTED_BIT(ip_firstfrag) ||
 775	    CHECK(ENC_SRC_IP4, src_ip) ||
 776	    CHECK(ENC_DST_IP4, dst_ip) ||
 777#ifdef CONFIG_IPV6
 778	    CHECK(ENC_SRC_IP6, src_ip6) ||
 779	    CHECK(ENC_DST_IP6, dst_ip6) ||
 780#endif
 781	    CHECK(ENC_L4_SPORT, l4_sport) ||
 782	    CHECK(ENC_L4_DPORT, l4_dport) ||
 783	    UNSUPPORTED(tcp_flags) ||
 784	    CHECK_BIT(TCP_SYN_FIN_RST, tcp_syn_fin_rst))
 785		return rc;
 786	if (efx_tc_match_is_encap(mask)) {
 787		/* can't happen; disallowed for local rules, translated
 788		 * for foreign rules.
 789		 */
 790		NL_SET_ERR_MSG_MOD(extack, "Unexpected encap match in LHS rule");
 791		return -EOPNOTSUPP;
 792	}
 793	if (UNSUPPORTED(enc_keyid) ||
 794	    /* Can't filter on conntrack in LHS rules */
 795	    UNSUPPORTED_BIT(ct_state_trk) ||
 796	    UNSUPPORTED_BIT(ct_state_est) ||
 797	    UNSUPPORTED(ct_mark) ||
 798	    UNSUPPORTED(recirc_id))
 799		return rc;
 800	return 0;
 801}
 802#undef UNSUPPORTED
 803#undef CHECK_BIT
 804#undef CHECK
 805
 806#define CHECK(_mcdi)	({						       \
 807	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ ## _mcdi],\
 808					 MASK_ONES);			       \
 809	if (rc)								       \
 810		NL_SET_ERR_MSG_FMT_MOD(extack,				       \
 811				       "No support for field %s", #_mcdi);     \
 812	rc;								       \
 813})
 814/* Checks that the fields needed for encap-rule matches are supported by the
 815 * MAE.  All the fields are exact-match, except possibly ENC_IP_TOS.
 816 */
 817int efx_mae_check_encap_match_caps(struct efx_nic *efx, bool ipv6,
 818				   u8 ip_tos_mask, __be16 udp_sport_mask,
 819				   struct netlink_ext_ack *extack)
 820{
 821	u8 *supported_fields = efx->tc->caps->outer_rule_fields;
 822	enum mask_type typ;
 823	int rc;
 824
 825	if (CHECK(ENC_ETHER_TYPE))
 826		return rc;
 827	if (ipv6) {
 828		if (CHECK(ENC_SRC_IP6) ||
 829		    CHECK(ENC_DST_IP6))
 830			return rc;
 831	} else {
 832		if (CHECK(ENC_SRC_IP4) ||
 833		    CHECK(ENC_DST_IP4))
 834			return rc;
 835	}
 836	if (CHECK(ENC_L4_DPORT) ||
 837	    CHECK(ENC_IP_PROTO))
 838		return rc;
 839	typ = classify_mask((const u8 *)&udp_sport_mask, sizeof(udp_sport_mask));
 840	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ENC_L4_SPORT],
 841					 typ);
 842	if (rc) {
 843		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field %s",
 844				       mask_type_name(typ), "enc_src_port");
 845		return rc;
 846	}
 847	typ = classify_mask(&ip_tos_mask, sizeof(ip_tos_mask));
 848	rc = efx_mae_match_check_cap_typ(supported_fields[MAE_FIELD_ENC_IP_TOS],
 849					 typ);
 850	if (rc) {
 851		NL_SET_ERR_MSG_FMT_MOD(extack, "No support for %s mask in field %s",
 852				       mask_type_name(typ), "enc_ip_tos");
 853		return rc;
 854	}
 855	return 0;
 856}
 857#undef CHECK
 858
 859int efx_mae_check_encap_type_supported(struct efx_nic *efx, enum efx_encap_type typ)
 860{
 861	unsigned int bit;
 862
 863	switch (typ & EFX_ENCAP_TYPES_MASK) {
 864	case EFX_ENCAP_TYPE_VXLAN:
 865		bit = MC_CMD_MAE_GET_CAPS_OUT_ENCAP_TYPE_VXLAN_LBN;
 866		break;
 867	case EFX_ENCAP_TYPE_GENEVE:
 868		bit = MC_CMD_MAE_GET_CAPS_OUT_ENCAP_TYPE_GENEVE_LBN;
 869		break;
 870	default:
 871		return -EOPNOTSUPP;
 872	}
 873	if (efx->tc->caps->encap_types & BIT(bit))
 874		return 0;
 875	return -EOPNOTSUPP;
 876}
 877
 878int efx_mae_allocate_counter(struct efx_nic *efx, struct efx_tc_counter *cnt)
 879{
 880	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTER_ALLOC_OUT_LEN(1));
 881	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTER_ALLOC_V2_IN_LEN);
 882	size_t outlen;
 883	int rc;
 884
 885	if (!cnt)
 886		return -EINVAL;
 887
 888	MCDI_SET_DWORD(inbuf, MAE_COUNTER_ALLOC_V2_IN_REQUESTED_COUNT, 1);
 889	MCDI_SET_DWORD(inbuf, MAE_COUNTER_ALLOC_V2_IN_COUNTER_TYPE, cnt->type);
 890	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTER_ALLOC, inbuf, sizeof(inbuf),
 891			  outbuf, sizeof(outbuf), &outlen);
 892	if (rc)
 893		return rc;
 894	/* pcol says this can't happen, since count is 1 */
 895	if (outlen < sizeof(outbuf))
 896		return -EIO;
 897	cnt->fw_id = MCDI_DWORD(outbuf, MAE_COUNTER_ALLOC_OUT_COUNTER_ID);
 898	cnt->gen = MCDI_DWORD(outbuf, MAE_COUNTER_ALLOC_OUT_GENERATION_COUNT);
 899	return 0;
 900}
 901
 902int efx_mae_free_counter(struct efx_nic *efx, struct efx_tc_counter *cnt)
 903{
 904	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_COUNTER_FREE_OUT_LEN(1));
 905	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_COUNTER_FREE_V2_IN_LEN);
 906	size_t outlen;
 907	int rc;
 908
 909	MCDI_SET_DWORD(inbuf, MAE_COUNTER_FREE_V2_IN_COUNTER_ID_COUNT, 1);
 910	MCDI_SET_DWORD(inbuf, MAE_COUNTER_FREE_V2_IN_FREE_COUNTER_ID, cnt->fw_id);
 911	MCDI_SET_DWORD(inbuf, MAE_COUNTER_FREE_V2_IN_COUNTER_TYPE, cnt->type);
 912	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_COUNTER_FREE, inbuf, sizeof(inbuf),
 913			  outbuf, sizeof(outbuf), &outlen);
 914	if (rc)
 915		return rc;
 916	/* pcol says this can't happen, since count is 1 */
 917	if (outlen < sizeof(outbuf))
 918		return -EIO;
 919	/* FW freed a different ID than we asked for, should also never happen.
 920	 * Warn because it means we've now got a different idea to the FW of
 921	 * what counters exist, which could cause mayhem later.
 922	 */
 923	if (WARN_ON(MCDI_DWORD(outbuf, MAE_COUNTER_FREE_OUT_FREED_COUNTER_ID) !=
 924		    cnt->fw_id))
 925		return -EIO;
 926	return 0;
 927}
 928
 929static int efx_mae_encap_type_to_mae_type(enum efx_encap_type type)
 930{
 931	switch (type & EFX_ENCAP_TYPES_MASK) {
 932	case EFX_ENCAP_TYPE_NONE:
 933		return MAE_MCDI_ENCAP_TYPE_NONE;
 934	case EFX_ENCAP_TYPE_VXLAN:
 935		return MAE_MCDI_ENCAP_TYPE_VXLAN;
 936	case EFX_ENCAP_TYPE_GENEVE:
 937		return MAE_MCDI_ENCAP_TYPE_GENEVE;
 938	default:
 939		return -EOPNOTSUPP;
 940	}
 941}
 942
 943int efx_mae_allocate_encap_md(struct efx_nic *efx,
 944			      struct efx_tc_encap_action *encap)
 945{
 946	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ENCAP_HEADER_ALLOC_IN_LEN(EFX_TC_MAX_ENCAP_HDR));
 947	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ENCAP_HEADER_ALLOC_OUT_LEN);
 948	size_t inlen, outlen;
 949	int rc;
 950
 951	rc = efx_mae_encap_type_to_mae_type(encap->type);
 952	if (rc < 0)
 953		return rc;
 954	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_ALLOC_IN_ENCAP_TYPE, rc);
 955	inlen = MC_CMD_MAE_ENCAP_HEADER_ALLOC_IN_LEN(encap->encap_hdr_len);
 956	if (WARN_ON(inlen > sizeof(inbuf))) /* can't happen */
 957		return -EINVAL;
 958	memcpy(MCDI_PTR(inbuf, MAE_ENCAP_HEADER_ALLOC_IN_HDR_DATA),
 959	       encap->encap_hdr,
 960	       encap->encap_hdr_len);
 961	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ENCAP_HEADER_ALLOC, inbuf,
 962			  inlen, outbuf, sizeof(outbuf), &outlen);
 963	if (rc)
 964		return rc;
 965	if (outlen < sizeof(outbuf))
 966		return -EIO;
 967	encap->fw_id = MCDI_DWORD(outbuf, MAE_ENCAP_HEADER_ALLOC_OUT_ENCAP_HEADER_ID);
 968	return 0;
 969}
 970
 971int efx_mae_update_encap_md(struct efx_nic *efx,
 972			    struct efx_tc_encap_action *encap)
 973{
 974	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ENCAP_HEADER_UPDATE_IN_LEN(EFX_TC_MAX_ENCAP_HDR));
 975	size_t inlen;
 976	int rc;
 977
 978	rc = efx_mae_encap_type_to_mae_type(encap->type);
 979	if (rc < 0)
 980		return rc;
 981	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_UPDATE_IN_ENCAP_TYPE, rc);
 982	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_UPDATE_IN_EH_ID,
 983		       encap->fw_id);
 984	inlen = MC_CMD_MAE_ENCAP_HEADER_UPDATE_IN_LEN(encap->encap_hdr_len);
 985	if (WARN_ON(inlen > sizeof(inbuf))) /* can't happen */
 986		return -EINVAL;
 987	memcpy(MCDI_PTR(inbuf, MAE_ENCAP_HEADER_UPDATE_IN_HDR_DATA),
 988	       encap->encap_hdr,
 989	       encap->encap_hdr_len);
 990
 991	BUILD_BUG_ON(MC_CMD_MAE_ENCAP_HEADER_UPDATE_OUT_LEN != 0);
 992	return efx_mcdi_rpc(efx, MC_CMD_MAE_ENCAP_HEADER_UPDATE, inbuf,
 993			    inlen, NULL, 0, NULL);
 994}
 995
 996int efx_mae_free_encap_md(struct efx_nic *efx,
 997			  struct efx_tc_encap_action *encap)
 998{
 999	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ENCAP_HEADER_FREE_OUT_LEN(1));
1000	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ENCAP_HEADER_FREE_IN_LEN(1));
1001	size_t outlen;
1002	int rc;
1003
1004	MCDI_SET_DWORD(inbuf, MAE_ENCAP_HEADER_FREE_IN_EH_ID, encap->fw_id);
1005	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ENCAP_HEADER_FREE, inbuf,
1006			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1007	if (rc)
1008		return rc;
1009	if (outlen < sizeof(outbuf))
1010		return -EIO;
1011	/* FW freed a different ID than we asked for, should also never happen.
1012	 * Warn because it means we've now got a different idea to the FW of
1013	 * what encap_mds exist, which could cause mayhem later.
1014	 */
1015	if (WARN_ON(MCDI_DWORD(outbuf, MAE_ENCAP_HEADER_FREE_OUT_FREED_EH_ID) != encap->fw_id))
1016		return -EIO;
1017	/* We're probably about to free @encap, but let's just make sure its
1018	 * fw_id is blatted so that it won't look valid if it leaks out.
1019	 */
1020	encap->fw_id = MC_CMD_MAE_ENCAP_HEADER_ALLOC_OUT_ENCAP_HEADER_ID_NULL;
1021	return 0;
1022}
1023
1024int efx_mae_lookup_mport(struct efx_nic *efx, u32 vf_idx, u32 *id)
1025{
1026	struct ef100_nic_data *nic_data = efx->nic_data;
1027	struct efx_mae *mae = efx->mae;
1028	struct rhashtable_iter walk;
1029	struct mae_mport_desc *m;
1030	int rc = -ENOENT;
1031
1032	rhashtable_walk_enter(&mae->mports_ht, &walk);
1033	rhashtable_walk_start(&walk);
1034	while ((m = rhashtable_walk_next(&walk)) != NULL) {
1035		if (m->mport_type == MAE_MPORT_DESC_MPORT_TYPE_VNIC &&
1036		    m->interface_idx == nic_data->local_mae_intf &&
1037		    m->pf_idx == 0 &&
1038		    m->vf_idx == vf_idx) {
1039			*id = m->mport_id;
1040			rc = 0;
1041			break;
1042		}
1043	}
1044	rhashtable_walk_stop(&walk);
1045	rhashtable_walk_exit(&walk);
1046	return rc;
1047}
1048
1049static bool efx_mae_asl_id(u32 id)
1050{
1051	return !!(id & BIT(31));
1052}
1053
1054/* mport handling */
1055static const struct rhashtable_params efx_mae_mports_ht_params = {
1056	.key_len	= sizeof(u32),
1057	.key_offset	= offsetof(struct mae_mport_desc, mport_id),
1058	.head_offset	= offsetof(struct mae_mport_desc, linkage),
1059};
1060
1061struct mae_mport_desc *efx_mae_get_mport(struct efx_nic *efx, u32 mport_id)
1062{
1063	return rhashtable_lookup_fast(&efx->mae->mports_ht, &mport_id,
1064				      efx_mae_mports_ht_params);
1065}
1066
1067static int efx_mae_add_mport(struct efx_nic *efx, struct mae_mport_desc *desc)
1068{
1069	struct efx_mae *mae = efx->mae;
1070	int rc;
1071
1072	rc = rhashtable_insert_fast(&mae->mports_ht, &desc->linkage,
1073				    efx_mae_mports_ht_params);
1074
1075	if (rc) {
1076		pci_err(efx->pci_dev, "Failed to insert MPORT %08x, rc %d\n",
1077			desc->mport_id, rc);
1078		kfree(desc);
1079		return rc;
1080	}
1081
1082	return rc;
1083}
1084
1085void efx_mae_remove_mport(void *desc, void *arg)
1086{
1087	struct mae_mport_desc *mport = desc;
1088
1089	synchronize_rcu();
1090	kfree(mport);
1091}
1092
1093static int efx_mae_process_mport(struct efx_nic *efx,
1094				 struct mae_mport_desc *desc)
1095{
1096	struct ef100_nic_data *nic_data = efx->nic_data;
1097	struct mae_mport_desc *mport;
1098
1099	mport = efx_mae_get_mport(efx, desc->mport_id);
1100	if (!IS_ERR_OR_NULL(mport)) {
1101		netif_err(efx, drv, efx->net_dev,
1102			  "mport with id %u does exist!!!\n", desc->mport_id);
1103		return -EEXIST;
1104	}
1105
1106	if (nic_data->have_own_mport &&
1107	    desc->mport_id == nic_data->own_mport) {
1108		WARN_ON(desc->mport_type != MAE_MPORT_DESC_MPORT_TYPE_VNIC);
1109		WARN_ON(desc->vnic_client_type !=
1110			MAE_MPORT_DESC_VNIC_CLIENT_TYPE_FUNCTION);
1111		nic_data->local_mae_intf = desc->interface_idx;
1112		nic_data->have_local_intf = true;
1113		pci_dbg(efx->pci_dev, "MAE interface_idx is %u\n",
1114			nic_data->local_mae_intf);
1115	}
1116
1117	return efx_mae_add_mport(efx, desc);
1118}
1119
1120#define MCDI_MPORT_JOURNAL_LEN \
1121	ALIGN(MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_LENMAX_MCDI2, 4)
1122
1123int efx_mae_enumerate_mports(struct efx_nic *efx)
1124{
1125	efx_dword_t *outbuf = kzalloc(MCDI_MPORT_JOURNAL_LEN, GFP_KERNEL);
1126	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MPORT_READ_JOURNAL_IN_LEN);
1127	MCDI_DECLARE_STRUCT_PTR(desc);
1128	size_t outlen, stride, count;
1129	int rc = 0, i;
1130
1131	if (!outbuf)
1132		return -ENOMEM;
1133	do {
1134		rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MPORT_READ_JOURNAL, inbuf,
1135				  sizeof(inbuf), outbuf,
1136				  MCDI_MPORT_JOURNAL_LEN, &outlen);
1137		if (rc)
1138			goto fail;
1139		if (outlen < MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_MPORT_DESC_DATA_OFST) {
1140			rc = -EIO;
1141			goto fail;
1142		}
1143		count = MCDI_DWORD(outbuf, MAE_MPORT_READ_JOURNAL_OUT_MPORT_DESC_COUNT);
1144		if (!count)
1145			continue; /* not break; we want to look at MORE flag */
1146		stride = MCDI_DWORD(outbuf, MAE_MPORT_READ_JOURNAL_OUT_SIZEOF_MPORT_DESC);
1147		if (stride < MAE_MPORT_DESC_LEN) {
1148			rc = -EIO;
1149			goto fail;
1150		}
1151		if (outlen < MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_LEN(count * stride)) {
1152			rc = -EIO;
1153			goto fail;
1154		}
1155
1156		for (i = 0; i < count; i++) {
1157			struct mae_mport_desc *d;
1158
1159			d = kzalloc(sizeof(*d), GFP_KERNEL);
1160			if (!d) {
1161				rc = -ENOMEM;
1162				goto fail;
1163			}
1164
1165			desc = (efx_dword_t *)
1166				_MCDI_PTR(outbuf, MC_CMD_MAE_MPORT_READ_JOURNAL_OUT_MPORT_DESC_DATA_OFST +
1167					  i * stride);
1168			d->mport_id = MCDI_STRUCT_DWORD(desc, MAE_MPORT_DESC_MPORT_ID);
1169			d->flags = MCDI_STRUCT_DWORD(desc, MAE_MPORT_DESC_FLAGS);
1170			d->caller_flags = MCDI_STRUCT_DWORD(desc,
1171							    MAE_MPORT_DESC_CALLER_FLAGS);
1172			d->mport_type = MCDI_STRUCT_DWORD(desc,
1173							  MAE_MPORT_DESC_MPORT_TYPE);
1174			switch (d->mport_type) {
1175			case MAE_MPORT_DESC_MPORT_TYPE_NET_PORT:
1176				d->port_idx = MCDI_STRUCT_DWORD(desc,
1177								MAE_MPORT_DESC_NET_PORT_IDX);
1178				break;
1179			case MAE_MPORT_DESC_MPORT_TYPE_ALIAS:
1180				d->alias_mport_id = MCDI_STRUCT_DWORD(desc,
1181								      MAE_MPORT_DESC_ALIAS_DELIVER_MPORT_ID);
1182				break;
1183			case MAE_MPORT_DESC_MPORT_TYPE_VNIC:
1184				d->vnic_client_type = MCDI_STRUCT_DWORD(desc,
1185									MAE_MPORT_DESC_VNIC_CLIENT_TYPE);
1186				d->interface_idx = MCDI_STRUCT_DWORD(desc,
1187								     MAE_MPORT_DESC_VNIC_FUNCTION_INTERFACE);
1188				d->pf_idx = MCDI_STRUCT_WORD(desc,
1189							     MAE_MPORT_DESC_VNIC_FUNCTION_PF_IDX);
1190				d->vf_idx = MCDI_STRUCT_WORD(desc,
1191							     MAE_MPORT_DESC_VNIC_FUNCTION_VF_IDX);
1192				break;
1193			default:
1194				/* Unknown mport_type, just accept it */
1195				break;
1196			}
1197			rc = efx_mae_process_mport(efx, d);
1198			/* Any failure will be due to memory allocation faiure,
1199			 * so there is no point to try subsequent entries.
1200			 */
1201			if (rc)
1202				goto fail;
1203		}
1204	} while (MCDI_FIELD(outbuf, MAE_MPORT_READ_JOURNAL_OUT, MORE) &&
1205		 !WARN_ON(!count));
1206fail:
1207	kfree(outbuf);
1208	return rc;
1209}
1210
1211/**
1212 * efx_mae_allocate_pedit_mac() - allocate pedit MAC address in HW.
1213 * @efx:	NIC we're installing a pedit MAC address on
1214 * @ped:	pedit MAC action to be installed
1215 *
1216 * Attempts to install @ped in HW and populates its id with an index of this
1217 * entry in the firmware MAC address table on success.
1218 *
1219 * Return: negative value on error, 0 in success.
1220 */
1221int efx_mae_allocate_pedit_mac(struct efx_nic *efx,
1222			       struct efx_tc_mac_pedit_action *ped)
1223{
1224	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_LEN);
1225	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MAC_ADDR_ALLOC_IN_LEN);
1226	size_t outlen;
1227	int rc;
1228
1229	BUILD_BUG_ON(MC_CMD_MAE_MAC_ADDR_ALLOC_IN_MAC_ADDR_LEN !=
1230		     sizeof(ped->h_addr));
1231	memcpy(MCDI_PTR(inbuf, MAE_MAC_ADDR_ALLOC_IN_MAC_ADDR), ped->h_addr,
1232	       sizeof(ped->h_addr));
1233	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MAC_ADDR_ALLOC, inbuf, sizeof(inbuf),
1234			  outbuf, sizeof(outbuf), &outlen);
1235	if (rc)
1236		return rc;
1237	if (outlen < sizeof(outbuf))
1238		return -EIO;
1239	ped->fw_id = MCDI_DWORD(outbuf, MAE_MAC_ADDR_ALLOC_OUT_MAC_ID);
1240	return 0;
1241}
1242
1243/**
1244 * efx_mae_free_pedit_mac() - free pedit MAC address in HW.
1245 * @efx:	NIC we're installing a pedit MAC address on
1246 * @ped:	pedit MAC action that needs to be freed
1247 *
1248 * Frees @ped in HW, check that firmware did not free a different one and clears
1249 * the id (which denotes the index of the entry in the MAC address table).
1250 */
1251void efx_mae_free_pedit_mac(struct efx_nic *efx,
1252			    struct efx_tc_mac_pedit_action *ped)
1253{
1254	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_MAC_ADDR_FREE_OUT_LEN(1));
1255	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_MAC_ADDR_FREE_IN_LEN(1));
1256	size_t outlen;
1257	int rc;
1258
1259	MCDI_SET_DWORD(inbuf, MAE_MAC_ADDR_FREE_IN_MAC_ID, ped->fw_id);
1260	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_MAC_ADDR_FREE, inbuf,
1261			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1262	if (rc || outlen < sizeof(outbuf))
1263		return;
1264	/* FW freed a different ID than we asked for, should also never happen.
1265	 * Warn because it means we've now got a different idea to the FW of
1266	 * what MAC addresses exist, which could cause mayhem later.
1267	 */
1268	if (WARN_ON(MCDI_DWORD(outbuf, MAE_MAC_ADDR_FREE_OUT_FREED_MAC_ID) != ped->fw_id))
1269		return;
1270	/* We're probably about to free @ped, but let's just make sure its
1271	 * fw_id is blatted so that it won't look valid if it leaks out.
1272	 */
1273	ped->fw_id = MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_MAC_ID_NULL;
1274}
1275
1276int efx_mae_alloc_action_set(struct efx_nic *efx, struct efx_tc_action_set *act)
1277{
1278	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_ALLOC_OUT_LEN);
1279	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_SET_ALLOC_IN_LEN);
1280	size_t outlen;
1281	int rc;
1282
1283	MCDI_POPULATE_DWORD_5(inbuf, MAE_ACTION_SET_ALLOC_IN_FLAGS,
1284			      MAE_ACTION_SET_ALLOC_IN_VLAN_PUSH, act->vlan_push,
1285			      MAE_ACTION_SET_ALLOC_IN_VLAN_POP, act->vlan_pop,
1286			      MAE_ACTION_SET_ALLOC_IN_DECAP, act->decap,
1287			      MAE_ACTION_SET_ALLOC_IN_DO_NAT, act->do_nat,
1288			      MAE_ACTION_SET_ALLOC_IN_DO_DECR_IP_TTL,
1289			      act->do_ttl_dec);
1290
1291	if (act->src_mac)
1292		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_SRC_MAC_ID,
1293			       act->src_mac->fw_id);
1294	else
1295		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_SRC_MAC_ID,
1296			       MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_MAC_ID_NULL);
1297
1298	if (act->dst_mac)
1299		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_DST_MAC_ID,
1300			       act->dst_mac->fw_id);
1301	else
1302		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_DST_MAC_ID,
1303			       MC_CMD_MAE_MAC_ADDR_ALLOC_OUT_MAC_ID_NULL);
1304
1305	if (act->count && !WARN_ON(!act->count->cnt))
1306		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_COUNTER_ID,
1307			       act->count->cnt->fw_id);
1308	else
1309		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_COUNTER_ID,
1310			       MC_CMD_MAE_COUNTER_ALLOC_OUT_COUNTER_ID_NULL);
1311	MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_COUNTER_LIST_ID,
1312		       MC_CMD_MAE_COUNTER_LIST_ALLOC_OUT_COUNTER_LIST_ID_NULL);
1313	if (act->vlan_push) {
1314		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN0_TCI_BE,
1315				 act->vlan_tci[0]);
1316		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN0_PROTO_BE,
1317				 act->vlan_proto[0]);
1318	}
1319	if (act->vlan_push >= 2) {
1320		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN1_TCI_BE,
1321				 act->vlan_tci[1]);
1322		MCDI_SET_WORD_BE(inbuf, MAE_ACTION_SET_ALLOC_IN_VLAN1_PROTO_BE,
1323				 act->vlan_proto[1]);
1324	}
1325	if (act->encap_md)
1326		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_ENCAP_HEADER_ID,
1327			       act->encap_md->fw_id);
1328	else
1329		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_ENCAP_HEADER_ID,
1330			       MC_CMD_MAE_ENCAP_HEADER_ALLOC_OUT_ENCAP_HEADER_ID_NULL);
1331	if (act->deliver)
1332		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_ALLOC_IN_DELIVER,
1333			       act->dest_mport);
1334	BUILD_BUG_ON(MAE_MPORT_SELECTOR_NULL);
1335	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_ALLOC, inbuf, sizeof(inbuf),
1336			  outbuf, sizeof(outbuf), &outlen);
1337	if (rc)
1338		return rc;
1339	if (outlen < sizeof(outbuf))
1340		return -EIO;
1341	act->fw_id = MCDI_DWORD(outbuf, MAE_ACTION_SET_ALLOC_OUT_AS_ID);
1342	/* We rely on the high bit of AS IDs always being clear.
1343	 * The firmware API guarantees this, but let's check it ourselves.
1344	 */
1345	if (WARN_ON_ONCE(efx_mae_asl_id(act->fw_id))) {
1346		efx_mae_free_action_set(efx, act->fw_id);
1347		return -EIO;
1348	}
1349	return 0;
1350}
1351
1352int efx_mae_free_action_set(struct efx_nic *efx, u32 fw_id)
1353{
1354	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_FREE_OUT_LEN(1));
1355	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_SET_FREE_IN_LEN(1));
1356	size_t outlen;
1357	int rc;
1358
1359	MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_FREE_IN_AS_ID, fw_id);
1360	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_FREE, inbuf, sizeof(inbuf),
1361			  outbuf, sizeof(outbuf), &outlen);
1362	if (rc)
1363		return rc;
1364	if (outlen < sizeof(outbuf))
1365		return -EIO;
1366	/* FW freed a different ID than we asked for, should never happen.
1367	 * Warn because it means we've now got a different idea to the FW of
1368	 * what action-sets exist, which could cause mayhem later.
1369	 */
1370	if (WARN_ON(MCDI_DWORD(outbuf, MAE_ACTION_SET_FREE_OUT_FREED_AS_ID) != fw_id))
1371		return -EIO;
1372	return 0;
1373}
1374
1375int efx_mae_alloc_action_set_list(struct efx_nic *efx,
1376				  struct efx_tc_action_set_list *acts)
1377{
1378	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_LEN);
1379	struct efx_tc_action_set *act;
1380	size_t inlen, outlen, i = 0;
1381	efx_dword_t *inbuf;
1382	int rc;
1383
1384	list_for_each_entry(act, &acts->list, list)
1385		i++;
1386	if (i == 0)
1387		return -EINVAL;
1388	if (i == 1) {
1389		/* Don't wrap an ASL around a single AS, just use the AS_ID
1390		 * directly.  ASLs are a more limited resource.
1391		 */
1392		act = list_first_entry(&acts->list, struct efx_tc_action_set, list);
1393		acts->fw_id = act->fw_id;
1394		return 0;
1395	}
1396	if (i > MC_CMD_MAE_ACTION_SET_LIST_ALLOC_IN_AS_IDS_MAXNUM_MCDI2)
1397		return -EOPNOTSUPP; /* Too many actions */
1398	inlen = MC_CMD_MAE_ACTION_SET_LIST_ALLOC_IN_LEN(i);
1399	inbuf = kzalloc(inlen, GFP_KERNEL);
1400	if (!inbuf)
1401		return -ENOMEM;
1402	i = 0;
1403	list_for_each_entry(act, &acts->list, list) {
1404		MCDI_SET_ARRAY_DWORD(inbuf, MAE_ACTION_SET_LIST_ALLOC_IN_AS_IDS,
1405				     i, act->fw_id);
1406		i++;
1407	}
1408	MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_LIST_ALLOC_IN_COUNT, i);
1409	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_LIST_ALLOC, inbuf, inlen,
1410			  outbuf, sizeof(outbuf), &outlen);
1411	if (rc)
1412		goto out_free;
1413	if (outlen < sizeof(outbuf)) {
1414		rc = -EIO;
1415		goto out_free;
1416	}
1417	acts->fw_id = MCDI_DWORD(outbuf, MAE_ACTION_SET_LIST_ALLOC_OUT_ASL_ID);
1418	/* We rely on the high bit of ASL IDs always being set.
1419	 * The firmware API guarantees this, but let's check it ourselves.
1420	 */
1421	if (WARN_ON_ONCE(!efx_mae_asl_id(acts->fw_id))) {
1422		efx_mae_free_action_set_list(efx, acts);
1423		rc = -EIO;
1424	}
1425out_free:
1426	kfree(inbuf);
1427	return rc;
1428}
1429
1430int efx_mae_free_action_set_list(struct efx_nic *efx,
1431				 struct efx_tc_action_set_list *acts)
1432{
1433	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_SET_LIST_FREE_OUT_LEN(1));
1434	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_SET_LIST_FREE_IN_LEN(1));
1435	size_t outlen;
1436	int rc;
1437
1438	/* If this is just an AS_ID with no ASL wrapper, then there is
1439	 * nothing for us to free.  (The AS will be freed later.)
1440	 */
1441	if (efx_mae_asl_id(acts->fw_id)) {
1442		MCDI_SET_DWORD(inbuf, MAE_ACTION_SET_LIST_FREE_IN_ASL_ID,
1443			       acts->fw_id);
1444		rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_SET_LIST_FREE, inbuf,
1445				  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1446		if (rc)
1447			return rc;
1448		if (outlen < sizeof(outbuf))
1449			return -EIO;
1450		/* FW freed a different ID than we asked for, should never happen.
1451		 * Warn because it means we've now got a different idea to the FW of
1452		 * what action-set-lists exist, which could cause mayhem later.
1453		 */
1454		if (WARN_ON(MCDI_DWORD(outbuf, MAE_ACTION_SET_LIST_FREE_OUT_FREED_ASL_ID) != acts->fw_id))
1455			return -EIO;
1456	}
1457	/* We're probably about to free @acts, but let's just make sure its
1458	 * fw_id is blatted so that it won't look valid if it leaks out.
1459	 */
1460	acts->fw_id = MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL;
1461	return 0;
1462}
1463
1464int efx_mae_register_encap_match(struct efx_nic *efx,
1465				 struct efx_tc_encap_match *encap)
1466{
1467	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_INSERT_IN_LEN(MAE_ENC_FIELD_PAIRS_LEN));
1468	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_INSERT_OUT_LEN);
1469	MCDI_DECLARE_STRUCT_PTR(match_crit);
1470	size_t outlen;
1471	int rc;
1472
1473	rc = efx_mae_encap_type_to_mae_type(encap->tun_type);
1474	if (rc < 0)
1475		return rc;
1476	match_crit = _MCDI_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_FIELD_MATCH_CRITERIA);
1477	/* The struct contains IP src and dst, and udp dport.
1478	 * So we actually need to filter on IP src and dst, L4 dport, and
1479	 * ipproto == udp.
1480	 */
1481	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_ENCAP_TYPE, rc);
1482#ifdef CONFIG_IPV6
1483	if (encap->src_ip | encap->dst_ip) {
1484#endif
1485		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE,
1486					 encap->src_ip);
1487		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE_MASK,
1488					 ~(__be32)0);
1489		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE,
1490					 encap->dst_ip);
1491		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE_MASK,
1492					 ~(__be32)0);
1493		MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE,
1494					htons(ETH_P_IP));
1495#ifdef CONFIG_IPV6
1496	} else {
1497		memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE),
1498		       &encap->src_ip6, sizeof(encap->src_ip6));
1499		memset(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE_MASK),
1500		       0xff, sizeof(encap->src_ip6));
1501		memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE),
1502		       &encap->dst_ip6, sizeof(encap->dst_ip6));
1503		memset(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE_MASK),
1504		       0xff, sizeof(encap->dst_ip6));
1505		MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE,
1506					htons(ETH_P_IPV6));
1507	}
1508#endif
1509	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE_MASK,
1510				~(__be16)0);
1511	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE,
1512				encap->udp_dport);
1513	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE_MASK,
1514				~(__be16)0);
1515	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE,
1516				encap->udp_sport);
1517	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE_MASK,
1518				encap->udp_sport_mask);
1519	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO, IPPROTO_UDP);
1520	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO_MASK, ~0);
1521	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS,
1522			     encap->ip_tos);
1523	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS_MASK,
1524			     encap->ip_tos_mask);
1525	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_INSERT, inbuf,
1526			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1527	if (rc)
1528		return rc;
1529	if (outlen < sizeof(outbuf))
1530		return -EIO;
1531	encap->fw_id = MCDI_DWORD(outbuf, MAE_OUTER_RULE_INSERT_OUT_OR_ID);
1532	return 0;
1533}
1534
1535int efx_mae_unregister_encap_match(struct efx_nic *efx,
1536				   struct efx_tc_encap_match *encap)
1537{
1538	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_OUT_LEN(1));
1539	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_IN_LEN(1));
1540	size_t outlen;
1541	int rc;
1542
1543	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_REMOVE_IN_OR_ID, encap->fw_id);
1544	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_REMOVE, inbuf,
1545			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1546	if (rc)
1547		return rc;
1548	if (outlen < sizeof(outbuf))
1549		return -EIO;
1550	/* FW freed a different ID than we asked for, should also never happen.
1551	 * Warn because it means we've now got a different idea to the FW of
1552	 * what encap_mds exist, which could cause mayhem later.
1553	 */
1554	if (WARN_ON(MCDI_DWORD(outbuf, MAE_OUTER_RULE_REMOVE_OUT_REMOVED_OR_ID) != encap->fw_id))
1555		return -EIO;
1556	/* We're probably about to free @encap, but let's just make sure its
1557	 * fw_id is blatted so that it won't look valid if it leaks out.
1558	 */
1559	encap->fw_id = MC_CMD_MAE_OUTER_RULE_INSERT_OUT_OUTER_RULE_ID_NULL;
1560	return 0;
1561}
1562
1563static int efx_mae_populate_lhs_match_criteria(MCDI_DECLARE_STRUCT_PTR(match_crit),
1564					       const struct efx_tc_match *match)
1565{
1566	if (match->mask.ingress_port) {
1567		if (~match->mask.ingress_port)
1568			return -EOPNOTSUPP;
1569		MCDI_STRUCT_SET_DWORD(match_crit,
1570				      MAE_ENC_FIELD_PAIRS_INGRESS_MPORT_SELECTOR,
1571				      match->value.ingress_port);
1572	}
1573	MCDI_STRUCT_SET_DWORD(match_crit, MAE_ENC_FIELD_PAIRS_INGRESS_MPORT_SELECTOR_MASK,
1574			      match->mask.ingress_port);
1575	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE,
1576				match->value.eth_proto);
1577	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETHER_TYPE_BE_MASK,
1578				match->mask.eth_proto);
1579	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_TCI_BE,
1580				match->value.vlan_tci[0]);
1581	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_TCI_BE_MASK,
1582				match->mask.vlan_tci[0]);
1583	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_PROTO_BE,
1584				match->value.vlan_proto[0]);
1585	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN0_PROTO_BE_MASK,
1586				match->mask.vlan_proto[0]);
1587	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_TCI_BE,
1588				match->value.vlan_tci[1]);
1589	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_TCI_BE_MASK,
1590				match->mask.vlan_tci[1]);
1591	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_PROTO_BE,
1592				match->value.vlan_proto[1]);
1593	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_VLAN1_PROTO_BE_MASK,
1594				match->mask.vlan_proto[1]);
1595	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_SADDR_BE),
1596	       match->value.eth_saddr, ETH_ALEN);
1597	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_SADDR_BE_MASK),
1598	       match->mask.eth_saddr, ETH_ALEN);
1599	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_DADDR_BE),
1600	       match->value.eth_daddr, ETH_ALEN);
1601	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_ETH_DADDR_BE_MASK),
1602	       match->mask.eth_daddr, ETH_ALEN);
1603	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO,
1604			     match->value.ip_proto);
1605	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_PROTO_MASK,
1606			     match->mask.ip_proto);
1607	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS,
1608			     match->value.ip_tos);
1609	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TOS_MASK,
1610			     match->mask.ip_tos);
1611	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TTL,
1612			     match->value.ip_ttl);
1613	MCDI_STRUCT_SET_BYTE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_IP_TTL_MASK,
1614			     match->mask.ip_ttl);
1615	MCDI_STRUCT_POPULATE_BYTE_1(match_crit,
1616				    MAE_ENC_FIELD_PAIRS_ENC_VLAN_FLAGS,
1617				    MAE_ENC_FIELD_PAIRS_ENC_IP_FRAG,
1618				    match->value.ip_frag);
1619	MCDI_STRUCT_POPULATE_BYTE_1(match_crit,
1620				    MAE_ENC_FIELD_PAIRS_ENC_VLAN_FLAGS_MASK,
1621				    MAE_ENC_FIELD_PAIRS_ENC_IP_FRAG_MASK,
1622				    match->mask.ip_frag);
1623	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE,
1624				 match->value.src_ip);
1625	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP4_BE_MASK,
1626				 match->mask.src_ip);
1627	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE,
1628				 match->value.dst_ip);
1629	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP4_BE_MASK,
1630				 match->mask.dst_ip);
1631#ifdef CONFIG_IPV6
1632	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE),
1633	       &match->value.src_ip6, sizeof(struct in6_addr));
1634	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_SRC_IP6_BE_MASK),
1635	       &match->mask.src_ip6, sizeof(struct in6_addr));
1636	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE),
1637	       &match->value.dst_ip6, sizeof(struct in6_addr));
1638	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_ENC_FIELD_PAIRS_ENC_DST_IP6_BE_MASK),
1639	       &match->mask.dst_ip6, sizeof(struct in6_addr));
1640#endif
1641	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_SPORT_BE,
1642				match->value.l4_sport);
1643	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_SPORT_BE_MASK,
1644				match->mask.l4_sport);
1645	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE,
1646				match->value.l4_dport);
1647	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_ENC_FIELD_PAIRS_ENC_L4_DPORT_BE_MASK,
1648				match->mask.l4_dport);
1649	/* No enc-keys in LHS rules.  Caps check should have caught this; any
1650	 * enc-keys from an fLHS should have been translated to regular keys
1651	 * and any EM should be a pseudo (we're an OR so can't have a direct
1652	 * EM with another OR).
1653	 */
1654	if (WARN_ON_ONCE(match->encap && !match->encap->type))
1655		return -EOPNOTSUPP;
1656	if (WARN_ON_ONCE(match->mask.enc_src_ip))
1657		return -EOPNOTSUPP;
1658	if (WARN_ON_ONCE(match->mask.enc_dst_ip))
1659		return -EOPNOTSUPP;
1660#ifdef CONFIG_IPV6
1661	if (WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_src_ip6)))
1662		return -EOPNOTSUPP;
1663	if (WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_dst_ip6)))
1664		return -EOPNOTSUPP;
1665#endif
1666	if (WARN_ON_ONCE(match->mask.enc_ip_tos))
1667		return -EOPNOTSUPP;
1668	if (WARN_ON_ONCE(match->mask.enc_ip_ttl))
1669		return -EOPNOTSUPP;
1670	if (WARN_ON_ONCE(match->mask.enc_sport))
1671		return -EOPNOTSUPP;
1672	if (WARN_ON_ONCE(match->mask.enc_dport))
1673		return -EOPNOTSUPP;
1674	if (WARN_ON_ONCE(match->mask.enc_keyid))
1675		return -EOPNOTSUPP;
1676	return 0;
1677}
1678
1679static int efx_mae_insert_lhs_outer_rule(struct efx_nic *efx,
1680					 struct efx_tc_lhs_rule *rule, u32 prio)
1681{
1682	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_INSERT_IN_LEN(MAE_ENC_FIELD_PAIRS_LEN));
1683	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_INSERT_OUT_LEN);
1684	MCDI_DECLARE_STRUCT_PTR(match_crit);
1685	const struct efx_tc_lhs_action *act;
1686	size_t outlen;
1687	int rc;
1688
1689	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_PRIO, prio);
1690	/* match */
1691	match_crit = _MCDI_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_FIELD_MATCH_CRITERIA);
1692	rc = efx_mae_populate_lhs_match_criteria(match_crit, &rule->match);
1693	if (rc)
1694		return rc;
1695
1696	/* action */
1697	act = &rule->lhs_act;
1698	rc = efx_mae_encap_type_to_mae_type(act->tun_type);
1699	if (rc < 0)
1700		return rc;
1701	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_ENCAP_TYPE, rc);
1702	/* We always inhibit CT lookup on TCP_INTERESTING_FLAGS, since the
1703	 * SW path needs to process the packet to update the conntrack tables
1704	 * on connection establishment (SYN) or termination (FIN, RST).
1705	 */
1706	MCDI_POPULATE_DWORD_6(inbuf, MAE_OUTER_RULE_INSERT_IN_LOOKUP_CONTROL,
1707			      MAE_OUTER_RULE_INSERT_IN_DO_CT, !!act->zone,
1708			      MAE_OUTER_RULE_INSERT_IN_CT_TCP_FLAGS_INHIBIT, 1,
1709			      MAE_OUTER_RULE_INSERT_IN_CT_DOMAIN,
1710			      act->zone ? act->zone->zone : 0,
1711			      MAE_OUTER_RULE_INSERT_IN_CT_VNI_MODE,
1712			      MAE_CT_VNI_MODE_ZERO,
1713			      MAE_OUTER_RULE_INSERT_IN_DO_COUNT, !!act->count,
1714			      MAE_OUTER_RULE_INSERT_IN_RECIRC_ID,
1715			      act->rid ? act->rid->fw_id : 0);
1716	if (act->count)
1717		MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_INSERT_IN_COUNTER_ID,
1718			       act->count->cnt->fw_id);
1719	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_INSERT, inbuf,
1720			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1721	if (rc)
1722		return rc;
1723	if (outlen < sizeof(outbuf))
1724		return -EIO;
1725	rule->fw_id = MCDI_DWORD(outbuf, MAE_OUTER_RULE_INSERT_OUT_OR_ID);
1726	return 0;
1727}
1728
1729static int efx_mae_populate_match_criteria(MCDI_DECLARE_STRUCT_PTR(match_crit),
1730					   const struct efx_tc_match *match);
1731
1732static int efx_mae_insert_lhs_action_rule(struct efx_nic *efx,
1733					  struct efx_tc_lhs_rule *rule,
1734					  u32 prio)
1735{
1736	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_INSERT_IN_LEN(MAE_FIELD_MASK_VALUE_PAIRS_V2_LEN));
1737	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_RULE_INSERT_OUT_LEN);
1738	struct efx_tc_lhs_action *act = &rule->lhs_act;
1739	MCDI_DECLARE_STRUCT_PTR(match_crit);
1740	MCDI_DECLARE_STRUCT_PTR(response);
1741	size_t outlen;
1742	int rc;
1743
1744	match_crit = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_MATCH_CRITERIA);
1745	response = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_RESPONSE);
1746	MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID,
1747			      MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL);
1748	MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID,
1749			      MC_CMD_MAE_ACTION_SET_ALLOC_OUT_ACTION_SET_ID_NULL);
1750	EFX_POPULATE_DWORD_5(*_MCDI_STRUCT_DWORD(response, MAE_ACTION_RULE_RESPONSE_LOOKUP_CONTROL),
1751			     MAE_ACTION_RULE_RESPONSE_DO_CT, !!act->zone,
1752			     MAE_ACTION_RULE_RESPONSE_DO_RECIRC,
1753			     act->rid && !act->zone,
1754			     MAE_ACTION_RULE_RESPONSE_CT_VNI_MODE,
1755			     MAE_CT_VNI_MODE_ZERO,
1756			     MAE_ACTION_RULE_RESPONSE_RECIRC_ID,
1757			     act->rid ? act->rid->fw_id : 0,
1758			     MAE_ACTION_RULE_RESPONSE_CT_DOMAIN,
1759			     act->zone ? act->zone->zone : 0);
1760	MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_COUNTER_ID,
1761			      act->count ? act->count->cnt->fw_id :
1762			      MC_CMD_MAE_COUNTER_ALLOC_OUT_COUNTER_ID_NULL);
1763	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_PRIO, prio);
1764	rc = efx_mae_populate_match_criteria(match_crit, &rule->match);
1765	if (rc)
1766		return rc;
1767
1768	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_INSERT, inbuf, sizeof(inbuf),
1769			  outbuf, sizeof(outbuf), &outlen);
1770	if (rc)
1771		return rc;
1772	if (outlen < sizeof(outbuf))
1773		return -EIO;
1774	rule->fw_id = MCDI_DWORD(outbuf, MAE_ACTION_RULE_INSERT_OUT_AR_ID);
1775	return 0;
1776}
1777
1778int efx_mae_insert_lhs_rule(struct efx_nic *efx, struct efx_tc_lhs_rule *rule,
1779			    u32 prio)
1780{
1781	if (rule->is_ar)
1782		return efx_mae_insert_lhs_action_rule(efx, rule, prio);
1783	return efx_mae_insert_lhs_outer_rule(efx, rule, prio);
1784}
1785
1786static int efx_mae_remove_lhs_outer_rule(struct efx_nic *efx,
1787					 struct efx_tc_lhs_rule *rule)
1788{
1789	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_OUT_LEN(1));
1790	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_OUTER_RULE_REMOVE_IN_LEN(1));
1791	size_t outlen;
1792	int rc;
1793
1794	MCDI_SET_DWORD(inbuf, MAE_OUTER_RULE_REMOVE_IN_OR_ID, rule->fw_id);
1795	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_OUTER_RULE_REMOVE, inbuf,
1796			  sizeof(inbuf), outbuf, sizeof(outbuf), &outlen);
1797	if (rc)
1798		return rc;
1799	if (outlen < sizeof(outbuf))
1800		return -EIO;
1801	/* FW freed a different ID than we asked for, should also never happen.
1802	 * Warn because it means we've now got a different idea to the FW of
1803	 * what encap_mds exist, which could cause mayhem later.
1804	 */
1805	if (WARN_ON(MCDI_DWORD(outbuf, MAE_OUTER_RULE_REMOVE_OUT_REMOVED_OR_ID) != rule->fw_id))
1806		return -EIO;
1807	/* We're probably about to free @rule, but let's just make sure its
1808	 * fw_id is blatted so that it won't look valid if it leaks out.
1809	 */
1810	rule->fw_id = MC_CMD_MAE_OUTER_RULE_INSERT_OUT_OUTER_RULE_ID_NULL;
1811	return 0;
1812}
1813
1814int efx_mae_remove_lhs_rule(struct efx_nic *efx, struct efx_tc_lhs_rule *rule)
1815{
1816	if (rule->is_ar)
1817		return efx_mae_delete_rule(efx, rule->fw_id);
1818	return efx_mae_remove_lhs_outer_rule(efx, rule);
1819}
1820
1821/* Populating is done by taking each byte of @value in turn and storing
1822 * it in the appropriate bits of @row.  @value must be big-endian; we
1823 * convert it to little-endianness as we go.
1824 */
1825static int efx_mae_table_populate(struct efx_tc_table_field_fmt field,
1826				  __le32 *row, size_t row_bits,
1827				  void *value, size_t value_size)
1828{
1829	unsigned int i;
1830
1831	/* For now only scheme 0 is supported for any field, so we check here
1832	 * (rather than, say, in calling code, which knows the semantics and
1833	 * could in principle encode for other schemes).
1834	 */
1835	if (field.scheme)
1836		return -EOPNOTSUPP;
1837	if (DIV_ROUND_UP(field.width, 8) != value_size)
1838		return -EINVAL;
1839	if (field.lbn + field.width > row_bits)
1840		return -EINVAL;
1841	for (i = 0; i < value_size; i++) {
1842		unsigned int bn = field.lbn + i * 8;
1843		unsigned int wn = bn / 32;
1844		u64 v;
1845
1846		v = ((u8 *)value)[value_size - i - 1];
1847		v <<= (bn % 32);
1848		row[wn] |= cpu_to_le32(v & 0xffffffff);
1849		if (wn * 32 < row_bits)
1850			row[wn + 1] |= cpu_to_le32(v >> 32);
1851	}
1852	return 0;
1853}
1854
1855static int efx_mae_table_populate_bool(struct efx_tc_table_field_fmt field,
1856				       __le32 *row, size_t row_bits, bool value)
1857{
1858	u8 v = value ? 1 : 0;
1859
1860	if (field.width != 1)
1861		return -EINVAL;
1862	return efx_mae_table_populate(field, row, row_bits, &v, 1);
1863}
1864
1865static int efx_mae_table_populate_ipv4(struct efx_tc_table_field_fmt field,
1866				       __le32 *row, size_t row_bits, __be32 value)
1867{
1868	/* IPv4 is placed in the first 4 bytes of an IPv6-sized field */
1869	struct in6_addr v = {};
1870
1871	if (field.width != 128)
1872		return -EINVAL;
1873	v.s6_addr32[0] = value;
1874	return efx_mae_table_populate(field, row, row_bits, &v, sizeof(v));
1875}
1876
1877static int efx_mae_table_populate_u24(struct efx_tc_table_field_fmt field,
1878				      __le32 *row, size_t row_bits, u32 value)
1879{
1880	__be32 v = cpu_to_be32(value);
1881
1882	/* We adjust value_size here since just 3 bytes will be copied, and
1883	 * the pointer to the value is set discarding the first byte which is
1884	 * the most significant byte for a big-endian 4-bytes value.
1885	 */
1886	return efx_mae_table_populate(field, row, row_bits, ((void *)&v) + 1,
1887				      sizeof(v) - 1);
1888}
1889
1890#define _TABLE_POPULATE(dst, dw, _field, _value) ({	\
1891	typeof(_value) _v = _value;			\
1892							\
1893	(_field.width == sizeof(_value) * 8) ?		\
1894	 efx_mae_table_populate(_field, dst, dw, &_v,	\
1895				sizeof(_v)) : -EINVAL;	\
1896})
1897#define TABLE_POPULATE_KEY_IPV4(dst, _table, _field, _value)		       \
1898	efx_mae_table_populate_ipv4(efx->tc->meta_##_table.desc.keys	       \
1899				    [efx->tc->meta_##_table.keys._field##_idx],\
1900				    dst, efx->tc->meta_##_table.desc.key_width,\
1901				    _value)
1902#define TABLE_POPULATE_KEY(dst, _table, _field, _value)			\
1903	_TABLE_POPULATE(dst, efx->tc->meta_##_table.desc.key_width,	\
1904			efx->tc->meta_##_table.desc.keys		\
1905			[efx->tc->meta_##_table.keys._field##_idx],	\
1906			_value)
1907
1908#define TABLE_POPULATE_RESP_BOOL(dst, _table, _field, _value)			\
1909	efx_mae_table_populate_bool(efx->tc->meta_##_table.desc.resps		\
1910				    [efx->tc->meta_##_table.resps._field##_idx],\
1911				    dst, efx->tc->meta_##_table.desc.resp_width,\
1912				    _value)
1913#define TABLE_POPULATE_RESP(dst, _table, _field, _value)		\
1914	_TABLE_POPULATE(dst, efx->tc->meta_##_table.desc.resp_width,	\
1915			efx->tc->meta_##_table.desc.resps		\
1916			[efx->tc->meta_##_table.resps._field##_idx],	\
1917			_value)
1918
1919#define TABLE_POPULATE_RESP_U24(dst, _table, _field, _value)		       \
1920	efx_mae_table_populate_u24(efx->tc->meta_##_table.desc.resps	       \
1921				   [efx->tc->meta_##_table.resps._field##_idx],\
1922				   dst, efx->tc->meta_##_table.desc.resp_width,\
1923				   _value)
1924
1925static int efx_mae_populate_ct_key(struct efx_nic *efx, __le32 *key, size_t kw,
1926				   struct efx_tc_ct_entry *conn)
1927{
1928	bool ipv6 = conn->eth_proto == htons(ETH_P_IPV6);
1929	int rc;
1930
1931	rc = TABLE_POPULATE_KEY(key, ct, eth_proto, conn->eth_proto);
1932	if (rc)
1933		return rc;
1934	rc = TABLE_POPULATE_KEY(key, ct, ip_proto, conn->ip_proto);
1935	if (rc)
1936		return rc;
1937	if (ipv6)
1938		rc = TABLE_POPULATE_KEY(key, ct, src_ip, conn->src_ip6);
1939	else
1940		rc = TABLE_POPULATE_KEY_IPV4(key, ct, src_ip, conn->src_ip);
1941	if (rc)
1942		return rc;
1943	if (ipv6)
1944		rc = TABLE_POPULATE_KEY(key, ct, dst_ip, conn->dst_ip6);
1945	else
1946		rc = TABLE_POPULATE_KEY_IPV4(key, ct, dst_ip, conn->dst_ip);
1947	if (rc)
1948		return rc;
1949	rc = TABLE_POPULATE_KEY(key, ct, l4_sport, conn->l4_sport);
1950	if (rc)
1951		return rc;
1952	rc = TABLE_POPULATE_KEY(key, ct, l4_dport, conn->l4_dport);
1953	if (rc)
1954		return rc;
1955	return TABLE_POPULATE_KEY(key, ct, zone, cpu_to_be16(conn->zone->zone));
1956}
1957
1958int efx_mae_insert_ct(struct efx_nic *efx, struct efx_tc_ct_entry *conn)
1959{
1960	bool ipv6 = conn->eth_proto == htons(ETH_P_IPV6);
1961	__le32 *key = NULL, *resp = NULL;
1962	size_t inlen, kw, rw;
1963	efx_dword_t *inbuf;
1964	int rc = -ENOMEM;
1965
1966	/* Check table access is supported */
1967	if (!efx->tc->meta_ct.hooked)
1968		return -EOPNOTSUPP;
1969
1970	/* key/resp widths are in bits; convert to dwords for IN_LEN */
1971	kw = DIV_ROUND_UP(efx->tc->meta_ct.desc.key_width, 32);
1972	rw = DIV_ROUND_UP(efx->tc->meta_ct.desc.resp_width, 32);
1973	BUILD_BUG_ON(sizeof(__le32) != MC_CMD_TABLE_INSERT_IN_DATA_LEN);
1974	inlen = MC_CMD_TABLE_INSERT_IN_LEN(kw + rw);
1975	if (inlen > MC_CMD_TABLE_INSERT_IN_LENMAX_MCDI2)
1976		return -E2BIG;
1977	inbuf = kzalloc(inlen, GFP_KERNEL);
1978	if (!inbuf)
1979		return -ENOMEM;
1980
1981	key = kcalloc(kw, sizeof(__le32), GFP_KERNEL);
1982	if (!key)
1983		goto out_free;
1984	resp = kcalloc(rw, sizeof(__le32), GFP_KERNEL);
1985	if (!resp)
1986		goto out_free;
1987
1988	rc = efx_mae_populate_ct_key(efx, key, kw, conn);
1989	if (rc)
1990		goto out_free;
1991
1992	rc = TABLE_POPULATE_RESP_BOOL(resp, ct, dnat, conn->dnat);
1993	if (rc)
1994		goto out_free;
1995	/* No support in hw for IPv6 NAT; field is only 32 bits */
1996	if (!ipv6)
1997		rc = TABLE_POPULATE_RESP(resp, ct, nat_ip, conn->nat_ip);
1998	if (rc)
1999		goto out_free;
2000	rc = TABLE_POPULATE_RESP(resp, ct, l4_natport, conn->l4_natport);
2001	if (rc)
2002		goto out_free;
2003	rc = TABLE_POPULATE_RESP(resp, ct, mark, cpu_to_be32(conn->mark));
2004	if (rc)
2005		goto out_free;
2006	rc = TABLE_POPULATE_RESP_U24(resp, ct, counter_id, conn->cnt->fw_id);
2007	if (rc)
2008		goto out_free;
2009
2010	MCDI_SET_DWORD(inbuf, TABLE_INSERT_IN_TABLE_ID, TABLE_ID_CONNTRACK_TABLE);
2011	MCDI_SET_WORD(inbuf, TABLE_INSERT_IN_KEY_WIDTH,
2012		      efx->tc->meta_ct.desc.key_width);
2013	/* MASK_WIDTH is zero as CT is a BCAM */
2014	MCDI_SET_WORD(inbuf, TABLE_INSERT_IN_RESP_WIDTH,
2015		      efx->tc->meta_ct.desc.resp_width);
2016	memcpy(MCDI_PTR(inbuf, TABLE_INSERT_IN_DATA), key, kw * sizeof(__le32));
2017	memcpy(MCDI_PTR(inbuf, TABLE_INSERT_IN_DATA) + kw * sizeof(__le32),
2018	       resp, rw * sizeof(__le32));
2019
2020	BUILD_BUG_ON(MC_CMD_TABLE_INSERT_OUT_LEN);
2021
2022	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_INSERT, inbuf, inlen, NULL, 0, NULL);
2023
2024out_free:
2025	kfree(resp);
2026	kfree(key);
2027	kfree(inbuf);
2028	return rc;
2029}
2030
2031int efx_mae_remove_ct(struct efx_nic *efx, struct efx_tc_ct_entry *conn)
2032{
2033	__le32 *key = NULL;
2034	efx_dword_t *inbuf;
2035	size_t inlen, kw;
2036	int rc = -ENOMEM;
2037
2038	/* Check table access is supported */
2039	if (!efx->tc->meta_ct.hooked)
2040		return -EOPNOTSUPP;
2041
2042	/* key width is in bits; convert to dwords for IN_LEN */
2043	kw = DIV_ROUND_UP(efx->tc->meta_ct.desc.key_width, 32);
2044	BUILD_BUG_ON(sizeof(__le32) != MC_CMD_TABLE_DELETE_IN_DATA_LEN);
2045	inlen = MC_CMD_TABLE_DELETE_IN_LEN(kw);
2046	if (inlen > MC_CMD_TABLE_DELETE_IN_LENMAX_MCDI2)
2047		return -E2BIG;
2048	inbuf = kzalloc(inlen, GFP_KERNEL);
2049	if (!inbuf)
2050		return -ENOMEM;
2051
2052	key = kcalloc(kw, sizeof(__le32), GFP_KERNEL);
2053	if (!key)
2054		goto out_free;
2055
2056	rc = efx_mae_populate_ct_key(efx, key, kw, conn);
2057	if (rc)
2058		goto out_free;
2059
2060	MCDI_SET_DWORD(inbuf, TABLE_DELETE_IN_TABLE_ID, TABLE_ID_CONNTRACK_TABLE);
2061	MCDI_SET_WORD(inbuf, TABLE_DELETE_IN_KEY_WIDTH,
2062		      efx->tc->meta_ct.desc.key_width);
2063	/* MASK_WIDTH is zero as CT is a BCAM */
2064	/* RESP_WIDTH is zero for DELETE */
2065	memcpy(MCDI_PTR(inbuf, TABLE_DELETE_IN_DATA), key, kw * sizeof(__le32));
2066
2067	BUILD_BUG_ON(MC_CMD_TABLE_DELETE_OUT_LEN);
2068
2069	rc = efx_mcdi_rpc(efx, MC_CMD_TABLE_DELETE, inbuf, inlen, NULL, 0, NULL);
2070
2071out_free:
2072	kfree(key);
2073	kfree(inbuf);
2074	return rc;
2075}
2076
2077static int efx_mae_populate_match_criteria(MCDI_DECLARE_STRUCT_PTR(match_crit),
2078					   const struct efx_tc_match *match)
2079{
2080	if (match->mask.ingress_port) {
2081		if (~match->mask.ingress_port)
2082			return -EOPNOTSUPP;
2083		MCDI_STRUCT_SET_DWORD(match_crit,
2084				      MAE_FIELD_MASK_VALUE_PAIRS_V2_INGRESS_MPORT_SELECTOR,
2085				      match->value.ingress_port);
2086	}
2087	MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_INGRESS_MPORT_SELECTOR_MASK,
2088			      match->mask.ingress_port);
2089	EFX_POPULATE_DWORD_5(*_MCDI_STRUCT_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_FLAGS),
2090			     MAE_FIELD_MASK_VALUE_PAIRS_V2_DO_CT,
2091			     match->value.ct_state_trk,
2092			     MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_HIT,
2093			     match->value.ct_state_est,
2094			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IS_IP_FRAG,
2095			     match->value.ip_frag,
2096			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_FIRST_FRAG,
2097			     match->value.ip_firstfrag,
2098			     MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_SYN_FIN_RST,
2099			     match->value.tcp_syn_fin_rst);
2100	EFX_POPULATE_DWORD_5(*_MCDI_STRUCT_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_FLAGS_MASK),
2101			     MAE_FIELD_MASK_VALUE_PAIRS_V2_DO_CT,
2102			     match->mask.ct_state_trk,
2103			     MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_HIT,
2104			     match->mask.ct_state_est,
2105			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IS_IP_FRAG,
2106			     match->mask.ip_frag,
2107			     MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_FIRST_FRAG,
2108			     match->mask.ip_firstfrag,
2109			     MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_SYN_FIN_RST,
2110			     match->mask.tcp_syn_fin_rst);
2111	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_RECIRC_ID,
2112			     match->value.recirc_id);
2113	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_RECIRC_ID_MASK,
2114			     match->mask.recirc_id);
2115	MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_MARK,
2116			      match->value.ct_mark);
2117	MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_MARK_MASK,
2118			      match->mask.ct_mark);
2119	MCDI_STRUCT_SET_WORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_DOMAIN,
2120			     match->value.ct_zone);
2121	MCDI_STRUCT_SET_WORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_CT_DOMAIN_MASK,
2122			     match->mask.ct_zone);
2123	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETHER_TYPE_BE,
2124				match->value.eth_proto);
2125	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETHER_TYPE_BE_MASK,
2126				match->mask.eth_proto);
2127	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_TCI_BE,
2128				match->value.vlan_tci[0]);
2129	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_TCI_BE_MASK,
2130				match->mask.vlan_tci[0]);
2131	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_PROTO_BE,
2132				match->value.vlan_proto[0]);
2133	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN0_PROTO_BE_MASK,
2134				match->mask.vlan_proto[0]);
2135	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_TCI_BE,
2136				match->value.vlan_tci[1]);
2137	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_TCI_BE_MASK,
2138				match->mask.vlan_tci[1]);
2139	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_PROTO_BE,
2140				match->value.vlan_proto[1]);
2141	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_VLAN1_PROTO_BE_MASK,
2142				match->mask.vlan_proto[1]);
2143	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_SADDR_BE),
2144	       match->value.eth_saddr, ETH_ALEN);
2145	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_SADDR_BE_MASK),
2146	       match->mask.eth_saddr, ETH_ALEN);
2147	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_DADDR_BE),
2148	       match->value.eth_daddr, ETH_ALEN);
2149	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ETH_DADDR_BE_MASK),
2150	       match->mask.eth_daddr, ETH_ALEN);
2151	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_PROTO,
2152			     match->value.ip_proto);
2153	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_PROTO_MASK,
2154			     match->mask.ip_proto);
2155	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TOS,
2156			     match->value.ip_tos);
2157	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TOS_MASK,
2158			     match->mask.ip_tos);
2159	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TTL,
2160			     match->value.ip_ttl);
2161	MCDI_STRUCT_SET_BYTE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_IP_TTL_MASK,
2162			     match->mask.ip_ttl);
2163	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP4_BE,
2164				 match->value.src_ip);
2165	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP4_BE_MASK,
2166				 match->mask.src_ip);
2167	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP4_BE,
2168				 match->value.dst_ip);
2169	MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP4_BE_MASK,
2170				 match->mask.dst_ip);
2171#ifdef CONFIG_IPV6
2172	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP6_BE),
2173	       &match->value.src_ip6, sizeof(struct in6_addr));
2174	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_SRC_IP6_BE_MASK),
2175	       &match->mask.src_ip6, sizeof(struct in6_addr));
2176	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP6_BE),
2177	       &match->value.dst_ip6, sizeof(struct in6_addr));
2178	memcpy(MCDI_STRUCT_PTR(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_DST_IP6_BE_MASK),
2179	       &match->mask.dst_ip6, sizeof(struct in6_addr));
2180#endif
2181	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_SPORT_BE,
2182				match->value.l4_sport);
2183	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_SPORT_BE_MASK,
2184				match->mask.l4_sport);
2185	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_DPORT_BE,
2186				match->value.l4_dport);
2187	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_L4_DPORT_BE_MASK,
2188				match->mask.l4_dport);
2189	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_FLAGS_BE,
2190				match->value.tcp_flags);
2191	MCDI_STRUCT_SET_WORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_TCP_FLAGS_BE_MASK,
2192				match->mask.tcp_flags);
2193	/* enc-keys are handled indirectly, through encap_match ID */
2194	if (match->encap) {
2195		MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_OUTER_RULE_ID,
2196				      match->encap->fw_id);
2197		MCDI_STRUCT_SET_DWORD(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_OUTER_RULE_ID_MASK,
2198				      U32_MAX);
2199		/* enc_keyid (VNI/VSID) is not part of the encap_match */
2200		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ENC_VNET_ID_BE,
2201					 match->value.enc_keyid);
2202		MCDI_STRUCT_SET_DWORD_BE(match_crit, MAE_FIELD_MASK_VALUE_PAIRS_V2_ENC_VNET_ID_BE_MASK,
2203					 match->mask.enc_keyid);
2204	} else if (WARN_ON_ONCE(match->mask.enc_src_ip) ||
2205		   WARN_ON_ONCE(match->mask.enc_dst_ip) ||
2206		   WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_src_ip6)) ||
2207		   WARN_ON_ONCE(!ipv6_addr_any(&match->mask.enc_dst_ip6)) ||
2208		   WARN_ON_ONCE(match->mask.enc_ip_tos) ||
2209		   WARN_ON_ONCE(match->mask.enc_ip_ttl) ||
2210		   WARN_ON_ONCE(match->mask.enc_sport) ||
2211		   WARN_ON_ONCE(match->mask.enc_dport) ||
2212		   WARN_ON_ONCE(match->mask.enc_keyid)) {
2213		/* No enc-keys should appear in a rule without an encap_match */
2214		return -EOPNOTSUPP;
2215	}
2216	return 0;
2217}
2218
2219int efx_mae_insert_rule(struct efx_nic *efx, const struct efx_tc_match *match,
2220			u32 prio, u32 acts_id, u32 *id)
2221{
2222	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_INSERT_IN_LEN(MAE_FIELD_MASK_VALUE_PAIRS_V2_LEN));
2223	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_RULE_INSERT_OUT_LEN);
2224	MCDI_DECLARE_STRUCT_PTR(match_crit);
2225	MCDI_DECLARE_STRUCT_PTR(response);
2226	size_t outlen;
2227	int rc;
2228
2229	if (!id)
2230		return -EINVAL;
2231
2232	match_crit = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_MATCH_CRITERIA);
2233	response = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_RESPONSE);
2234	if (efx_mae_asl_id(acts_id)) {
2235		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID, acts_id);
2236		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID,
2237				      MC_CMD_MAE_ACTION_SET_ALLOC_OUT_ACTION_SET_ID_NULL);
2238	} else {
2239		/* We only had one AS, so we didn't wrap it in an ASL */
2240		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID,
2241				      MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL);
2242		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID, acts_id);
2243	}
2244	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_INSERT_IN_PRIO, prio);
2245	rc = efx_mae_populate_match_criteria(match_crit, match);
2246	if (rc)
2247		return rc;
2248
2249	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_INSERT, inbuf, sizeof(inbuf),
2250			  outbuf, sizeof(outbuf), &outlen);
2251	if (rc)
2252		return rc;
2253	if (outlen < sizeof(outbuf))
2254		return -EIO;
2255	*id = MCDI_DWORD(outbuf, MAE_ACTION_RULE_INSERT_OUT_AR_ID);
2256	return 0;
2257}
2258
2259int efx_mae_update_rule(struct efx_nic *efx, u32 acts_id, u32 id)
2260{
2261	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_UPDATE_IN_LEN);
2262	MCDI_DECLARE_STRUCT_PTR(response);
2263
2264	BUILD_BUG_ON(MC_CMD_MAE_ACTION_RULE_UPDATE_OUT_LEN);
2265	response = _MCDI_DWORD(inbuf, MAE_ACTION_RULE_UPDATE_IN_RESPONSE);
2266
2267	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_UPDATE_IN_AR_ID, id);
2268	if (efx_mae_asl_id(acts_id)) {
2269		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID, acts_id);
2270		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID,
2271				      MC_CMD_MAE_ACTION_SET_ALLOC_OUT_ACTION_SET_ID_NULL);
2272	} else {
2273		/* We only had one AS, so we didn't wrap it in an ASL */
2274		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_ASL_ID,
2275				      MC_CMD_MAE_ACTION_SET_LIST_ALLOC_OUT_ACTION_SET_LIST_ID_NULL);
2276		MCDI_STRUCT_SET_DWORD(response, MAE_ACTION_RULE_RESPONSE_AS_ID, acts_id);
2277	}
2278	return efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_UPDATE, inbuf, sizeof(inbuf),
2279			    NULL, 0, NULL);
2280}
2281
2282int efx_mae_delete_rule(struct efx_nic *efx, u32 id)
2283{
2284	MCDI_DECLARE_BUF(outbuf, MC_CMD_MAE_ACTION_RULE_DELETE_OUT_LEN(1));
2285	MCDI_DECLARE_BUF(inbuf, MC_CMD_MAE_ACTION_RULE_DELETE_IN_LEN(1));
2286	size_t outlen;
2287	int rc;
2288
2289	MCDI_SET_DWORD(inbuf, MAE_ACTION_RULE_DELETE_IN_AR_ID, id);
2290	rc = efx_mcdi_rpc(efx, MC_CMD_MAE_ACTION_RULE_DELETE, inbuf, sizeof(inbuf),
2291			  outbuf, sizeof(outbuf), &outlen);
2292	if (rc)
2293		return rc;
2294	if (outlen < sizeof(outbuf))
2295		return -EIO;
2296	/* FW freed a different ID than we asked for, should also never happen.
2297	 * Warn because it means we've now got a different idea to the FW of
2298	 * what rules exist, which could cause mayhem later.
2299	 */
2300	if (WARN_ON(MCDI_DWORD(outbuf, MAE_ACTION_RULE_DELETE_OUT_DELETED_AR_ID) != id))
2301		return -EIO;
2302	return 0;
2303}
2304
2305int efx_init_mae(struct efx_nic *efx)
2306{
2307	struct ef100_nic_data *nic_data = efx->nic_data;
2308	struct efx_mae *mae;
2309	int rc;
2310
2311	if (!nic_data->have_mport)
2312		return -EINVAL;
2313
2314	mae = kmalloc(sizeof(*mae), GFP_KERNEL);
2315	if (!mae)
2316		return -ENOMEM;
2317
2318	rc = rhashtable_init(&mae->mports_ht, &efx_mae_mports_ht_params);
2319	if (rc < 0) {
2320		kfree(mae);
2321		return rc;
2322	}
2323	efx->mae = mae;
2324	mae->efx = efx;
2325	return 0;
2326}
2327
2328void efx_fini_mae(struct efx_nic *efx)
2329{
2330	struct efx_mae *mae = efx->mae;
2331
2332	kfree(mae);
2333	efx->mae = NULL;
2334}