/** *ice_conv_link_speed_to_virtchnl *@adv_link_support:determinestheformatofthereturnedlinkspeed *@link_speed:variablecontainingthelink_speedtobeconverted * *ConvertlinkspeedsupportedbyHWtolinkspeedsupportedbyvirtchnl. *Ifadv_link_supportistrue,thenreturnlinkspeedinMbps.Elsereturn *linkspeedasaVIRTCHNL_LINK_SPEED_*castedtoau32.Notethatthecaller *needstocastbacktoanenumvirtchnl_link_speedinthecasewhere *adv_link_supportisfalse,butwhenadv_link_supportistruethecallercan *expectthespeedinMbps.
*/
u32 ice_conv_link_speed_to_virtchnl(bool adv_link_support, u16 link_speed)
{ /* convert a BIT() value into an array index */
u32 index = fls(link_speed) - 1;
if (adv_link_support) return ice_get_link_speed(index); elseif (index < ARRAY_SIZE(ice_legacy_aq_to_vc_speed)) /* Virtchnl speeds are not defined for every speed supported in *thehardware.TomaintaincompatibilitywitholderAVF *drivers,whilereportingthespeedthenewspeedvaluesare *resolvedtotheclosestknownvirtchnlspeeds
*/ return ice_legacy_aq_to_vc_speed[index];
return VIRTCHNL_LINK_SPEED_UNKNOWN;
}
/* The mailbox overflow detection algorithm helps to check if there *isapossibilityofamaliciousVFtransmittingtoomanyMBXmessagestothe *PF. *1.Themailboxsnapshotstructure,ice_mbx_snapshot,isinitializedduring *driverinitializationinice_init_hw()usingice_mbx_init_snapshot(). *Thestructice_mbx_snapshothelpstotrackandtraverseastaticwindowof *messageswithinthemailboxqueuewhilelookingforamaliciousVF. * *2.Whenthecallerstartsprocessingitsmailboxqueueinresponsetoan *interrupt,thestructureice_mbx_snapshotisexpectedtobeclearedbefore *thealgorithmcanberunforthefirsttimeforthatinterrupt.This *requirescallingice_mbx_reset_snapshot()aswellascalling *ice_mbx_reset_vf_info()foreachVFtrackingstructure. * *3.ForeverymessagereadbythecallerfromtheMBXQueue,thecallermust *callthedetectionalgorithm'sentryfunctionice_mbx_vf_state_handler(). *Beforeeverycalltoice_mbx_vf_state_handler()thestructice_mbx_datais *filledasitisrequiredtobepassedtothealgorithm. * *4.EverytimeamessageisreadfromtheMBXqueue,atrackingstructure *fortheVFmustbepassedtothestatehandler.Thebooleanoutput *report_malvffromice_mbx_vf_state_handler()servesasanindicatortothe *callerwhetheritmustreportthisVFasmaliciousornot. * *5.WhenaVFisidentifiedtobemalicious,thecallercansendamessage *tothesystemadministrator. * *6.ThePFisresponsibleformaintainingthestructice_mbx_vf_info *structureforeachVF.ThePFshouldcleartheVFtrackingstructureifthe *VFisreset.WhenaVFisshutdownandbroughtbackup,wewillthen *assumethatthenewVFisnotmaliciousandmayreportitagainifwe *detectitagain. * *7.Thefunctionice_mbx_reset_snapshot()iscalledtoresettheinformation *inice_mbx_snapshotforeverynewmailboxinterrupthandled.
*/ #define ICE_RQ_DATA_MASK(rq_data) ((rq_data) & PF_MBX_ARQH_ARQH_M) /* Using the highest value for an unsigned 16-bit value 0xFFFF to indicate that *themaxmessagescheckmustbeignoredinthealgorithm
*/ #define ICE_IGNORE_MAX_MSG_CNT 0xFFFF
/* Clear mbx_buf in the mailbox snaphot structure and setting the *mailboxsnapshotstatetoanewcapture.
*/
memset(&snap->mbx_buf, 0, sizeof(snap->mbx_buf));
snap->mbx_buf.state = ICE_MAL_VF_DETECT_STATE_NEW_SNAPSHOT;
/* Reset message counts for all VFs to zero */
list_for_each_entry(vf_info, &snap->mbx_vf, list_entry)
vf_info->msg_count = 0;
}
if (!report_malvf || !mbx_data || !vf_info) return -EINVAL;
*report_malvf = false;
/* When entering the mailbox state machine assume that the VF *isnotmaliciousuntildetected.
*/ /* Checking if max messages allowed to be processed while servicing current *interruptisnotlessthanthedefinedAVFmessagethreshold.
*/ if (mbx_data->max_num_msgs_mbx <= ICE_ASYNC_VF_MSG_THRESHOLD) return -EINVAL;
/* The watermark value should not be lesser than the threshold limit *setforthenumberofasynchronousmessagesaVFcansendtomailbox *norshoulditbegreaterthanthemaximumnumberofmessagesinthe *mailboxservicedincurrentinterrupt.
*/ if (mbx_data->async_watermark_val < ICE_ASYNC_VF_MSG_THRESHOLD ||
mbx_data->async_watermark_val > mbx_data->max_num_msgs_mbx) return -EINVAL;
switch (snap_buf->state) { case ICE_MAL_VF_DETECT_STATE_NEW_SNAPSHOT: /* Clear any previously held data in mailbox snapshot structure. */
ice_mbx_reset_snapshot(snap);
/* Collect the pending ARQ count, number of messages processed and *themaximumnumberofmessagesallowedtobeprocessedfromthe *Mailboxforcurrentinterrupt.
*/
snap_buf->num_pending_arq = mbx_data->num_pending_arq;
snap_buf->num_msg_proc = mbx_data->num_msg_proc;
snap_buf->max_num_msgs_mbx = mbx_data->max_num_msgs_mbx;
/* Capture a new static snapshot of the mailbox by logging the *headandtailofsnapshotandsetnum_iterationstothetail *valuetomarkthestartoftheiterationthroughthesnapshot.
*/
snap_buf->head = ICE_RQ_DATA_MASK(cq->rq.next_to_clean +
mbx_data->num_pending_arq);
snap_buf->tail = ICE_RQ_DATA_MASK(cq->rq.next_to_clean - 1);
snap_buf->num_iterations = snap_buf->tail;
/* Pending ARQ messages returned by ice_clean_rq_elem *isthedifferencebetweentheheadandtailofthe *mailboxqueue.Comparingthisvalueagainstthewatermark *helpstocheckifwepotentiallyhavemaliciousVFs.
*/ if (snap_buf->num_pending_arq >=
mbx_data->async_watermark_val) {
new_state = ICE_MAL_VF_DETECT_STATE_DETECT;
status = ice_mbx_detect_malvf(hw, vf_info, &new_state, &is_malvf);
} else {
new_state = ICE_MAL_VF_DETECT_STATE_TRAVERSE;
ice_mbx_traverse(hw, &new_state);
} break;
case ICE_MAL_VF_DETECT_STATE_TRAVERSE:
new_state = ICE_MAL_VF_DETECT_STATE_TRAVERSE;
ice_mbx_traverse(hw, &new_state); break;
case ICE_MAL_VF_DETECT_STATE_DETECT:
new_state = ICE_MAL_VF_DETECT_STATE_DETECT;
status = ice_mbx_detect_malvf(hw, vf_info, &new_state, &is_malvf); break;
default:
new_state = ICE_MAL_VF_DETECT_STATE_INVALID;
status = -EIO;
}
snap_buf->state = new_state;
/* Only report VFs as malicious the first time we detect it */ if (is_malvf && !vf_info->malicious) {
vf_info->malicious = 1;
*report_malvf = true;
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.