blob: 8f41c95159bd676e034f0b583241c44c6b2fd837 [file] [log] [blame]
Neale Ranns999c8ee2019-02-01 03:31:24 -08001/*
2 * Copyright (c) 2015 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16#include <vnet/ipsec/ipsec.h>
Damjan Marionc59b9a22019-03-19 15:38:40 +010017#include <vnet/ipsec/esp.h>
18#include <vnet/udp/udp.h>
Neale Ranns8d7c5022019-02-06 01:41:05 -080019#include <vnet/fib/fib_table.h>
Neale Ranns999c8ee2019-02-01 03:31:24 -080020
Neale Rannseba31ec2019-02-17 18:04:27 +000021/**
22 * @brief
23 * SA packet & bytes counters
24 */
25vlib_combined_counter_main_t ipsec_sa_counters = {
26 .name = "SA",
27 .stat_segment_name = "/net/ipsec/sa",
28};
29
30
Neale Ranns999c8ee2019-02-01 03:31:24 -080031static clib_error_t *
32ipsec_call_add_del_callbacks (ipsec_main_t * im, ipsec_sa_t * sa,
33 u32 sa_index, int is_add)
34{
35 ipsec_ah_backend_t *ab;
36 ipsec_esp_backend_t *eb;
37 switch (sa->protocol)
38 {
39 case IPSEC_PROTOCOL_AH:
40 ab = pool_elt_at_index (im->ah_backends, im->ah_current_backend);
41 if (ab->add_del_sa_sess_cb)
42 return ab->add_del_sa_sess_cb (sa_index, is_add);
43 break;
44 case IPSEC_PROTOCOL_ESP:
45 eb = pool_elt_at_index (im->esp_backends, im->esp_current_backend);
46 if (eb->add_del_sa_sess_cb)
47 return eb->add_del_sa_sess_cb (sa_index, is_add);
48 break;
49 }
50 return 0;
51}
52
Neale Ranns8d7c5022019-02-06 01:41:05 -080053void
54ipsec_mk_key (ipsec_key_t * key, const u8 * data, u8 len)
55{
56 memset (key, 0, sizeof (*key));
57
58 if (len > sizeof (key->data))
59 key->len = sizeof (key->data);
60 else
61 key->len = len;
62
63 memcpy (key->data, data, key->len);
64}
65
66/**
67 * 'stack' (resolve the recursion for) the SA tunnel destination
68 */
Neale Rannsb4cfd552019-02-13 02:08:06 -080069void
Neale Ranns8d7c5022019-02-06 01:41:05 -080070ipsec_sa_stack (ipsec_sa_t * sa)
71{
Neale Rannsb4cfd552019-02-13 02:08:06 -080072 ipsec_main_t *im = &ipsec_main;
Neale Ranns8d7c5022019-02-06 01:41:05 -080073 fib_forward_chain_type_t fct;
74 dpo_id_t tmp = DPO_INVALID;
Neale Ranns8d7c5022019-02-06 01:41:05 -080075
Damjan Mariond709cbc2019-03-26 13:16:42 +010076 fct =
77 fib_forw_chain_type_from_fib_proto ((ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
78 FIB_PROTOCOL_IP6 :
79 FIB_PROTOCOL_IP4));
Neale Ranns8d7c5022019-02-06 01:41:05 -080080
81 fib_entry_contribute_forwarding (sa->fib_entry_index, fct, &tmp);
82
Damjan Mariond709cbc2019-03-26 13:16:42 +010083 dpo_stack_from_node ((ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
Neale Rannsb4cfd552019-02-13 02:08:06 -080084 im->ah6_encrypt_node_index :
85 im->ah4_encrypt_node_index),
86 &sa->dpo[IPSEC_PROTOCOL_AH], &tmp);
Damjan Mariond709cbc2019-03-26 13:16:42 +010087 dpo_stack_from_node ((ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
Neale Rannsb4cfd552019-02-13 02:08:06 -080088 im->esp6_encrypt_node_index :
89 im->esp4_encrypt_node_index),
90 &sa->dpo[IPSEC_PROTOCOL_ESP], &tmp);
91 dpo_reset (&tmp);
Neale Ranns8d7c5022019-02-06 01:41:05 -080092}
93
Damjan Marionb966e8b2019-03-20 16:07:09 +010094void
95ipsec_sa_set_crypto_alg (ipsec_sa_t * sa, ipsec_crypto_alg_t crypto_alg)
96{
97 ipsec_main_t *im = &ipsec_main;
98 sa->crypto_alg = crypto_alg;
99 sa->crypto_iv_size = im->crypto_algs[crypto_alg].iv_size;
100 sa->crypto_block_size = im->crypto_algs[crypto_alg].block_size;
Damjan Marion060bfb92019-03-29 13:47:54 +0100101 sa->crypto_enc_op_id = im->crypto_algs[crypto_alg].enc_op_id;
102 sa->crypto_dec_op_id = im->crypto_algs[crypto_alg].dec_op_id;
Damjan Marionb4fff3a2019-03-25 15:54:40 +0100103 ASSERT (sa->crypto_iv_size <= ESP_MAX_IV_SIZE);
Damjan Marionc59b9a22019-03-19 15:38:40 +0100104 ASSERT (sa->crypto_block_size <= ESP_MAX_BLOCK_SIZE);
Neale Ranns47feb112019-04-11 15:14:07 +0000105 if (IPSEC_CRYPTO_ALG_IS_GCM (crypto_alg))
106 {
107 sa->integ_icv_size = im->crypto_algs[crypto_alg].icv_size;
108 ipsec_sa_set_IS_AEAD (sa);
109 }
Damjan Marionb966e8b2019-03-20 16:07:09 +0100110}
111
112void
113ipsec_sa_set_integ_alg (ipsec_sa_t * sa, ipsec_integ_alg_t integ_alg)
114{
115 ipsec_main_t *im = &ipsec_main;
116 sa->integ_alg = integ_alg;
Damjan Marion7c22ff72019-04-04 12:25:44 +0200117 sa->integ_icv_size = im->integ_algs[integ_alg].icv_size;
Damjan Marion060bfb92019-03-29 13:47:54 +0100118 sa->integ_op_id = im->integ_algs[integ_alg].op_id;
Damjan Marion7c22ff72019-04-04 12:25:44 +0200119 ASSERT (sa->integ_icv_size <= ESP_MAX_ICV_SIZE);
Damjan Marionb966e8b2019-03-20 16:07:09 +0100120}
121
Neale Ranns999c8ee2019-02-01 03:31:24 -0800122int
Neale Ranns8d7c5022019-02-06 01:41:05 -0800123ipsec_sa_add (u32 id,
124 u32 spi,
125 ipsec_protocol_t proto,
126 ipsec_crypto_alg_t crypto_alg,
127 const ipsec_key_t * ck,
128 ipsec_integ_alg_t integ_alg,
129 const ipsec_key_t * ik,
130 ipsec_sa_flags_t flags,
131 u32 tx_table_id,
Neale Ranns47feb112019-04-11 15:14:07 +0000132 u32 salt,
Neale Ranns8d7c5022019-02-06 01:41:05 -0800133 const ip46_address_t * tun_src,
134 const ip46_address_t * tun_dst, u32 * sa_out_index)
135{
136 ipsec_main_t *im = &ipsec_main;
137 clib_error_t *err;
138 ipsec_sa_t *sa;
139 u32 sa_index;
140 uword *p;
141
142 p = hash_get (im->sa_index_by_sa_id, id);
143 if (p)
144 return VNET_API_ERROR_ENTRY_ALREADY_EXISTS;
145
Damjan Mariond709cbc2019-03-26 13:16:42 +0100146 pool_get_aligned_zero (im->sad, sa, CLIB_CACHE_LINE_BYTES);
Neale Ranns8d7c5022019-02-06 01:41:05 -0800147
148 fib_node_init (&sa->node, FIB_NODE_TYPE_IPSEC_SA);
149 sa_index = sa - im->sad;
150
Neale Rannseba31ec2019-02-17 18:04:27 +0000151 vlib_validate_combined_counter (&ipsec_sa_counters, sa_index);
152 vlib_zero_combined_counter (&ipsec_sa_counters, sa_index);
153
Neale Ranns8d7c5022019-02-06 01:41:05 -0800154 sa->id = id;
155 sa->spi = spi;
Neale Rannseba31ec2019-02-17 18:04:27 +0000156 sa->stat_index = sa_index;
Neale Ranns8d7c5022019-02-06 01:41:05 -0800157 sa->protocol = proto;
Neale Ranns2b5ba952019-04-02 10:15:40 +0000158 sa->flags = flags;
Neale Ranns47feb112019-04-11 15:14:07 +0000159 sa->salt = salt;
Damjan Marionb966e8b2019-03-20 16:07:09 +0100160 ipsec_sa_set_integ_alg (sa, integ_alg);
Neale Ranns8d7c5022019-02-06 01:41:05 -0800161 clib_memcpy (&sa->integ_key, ik, sizeof (sa->integ_key));
Neale Ranns47feb112019-04-11 15:14:07 +0000162 ipsec_sa_set_crypto_alg (sa, crypto_alg);
163 clib_memcpy (&sa->crypto_key, ck, sizeof (sa->crypto_key));
Neale Ranns8d7c5022019-02-06 01:41:05 -0800164 ip46_address_copy (&sa->tunnel_src_addr, tun_src);
165 ip46_address_copy (&sa->tunnel_dst_addr, tun_dst);
166
Neale Ranns8d7c5022019-02-06 01:41:05 -0800167 err = ipsec_check_support_cb (im, sa);
168 if (err)
169 {
170 clib_warning ("%s", err->what);
171 pool_put (im->sad, sa);
172 return VNET_API_ERROR_UNIMPLEMENTED;
173 }
174
175 err = ipsec_call_add_del_callbacks (im, sa, sa_index, 1);
176 if (err)
177 {
178 pool_put (im->sad, sa);
179 return VNET_API_ERROR_SYSCALL_ERROR_1;
180 }
181
Neale Ranns2b5ba952019-04-02 10:15:40 +0000182 if (ipsec_sa_is_set_IS_TUNNEL (sa) && !ipsec_sa_is_set_IS_INBOUND (sa))
Neale Ranns8d7c5022019-02-06 01:41:05 -0800183 {
Damjan Mariond709cbc2019-03-26 13:16:42 +0100184 fib_protocol_t fproto = (ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
Neale Ranns8d7c5022019-02-06 01:41:05 -0800185 FIB_PROTOCOL_IP6 : FIB_PROTOCOL_IP4);
186 fib_prefix_t pfx = {
187 .fp_addr = sa->tunnel_dst_addr,
Damjan Mariond709cbc2019-03-26 13:16:42 +0100188 .fp_len = (ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ? 128 : 32),
Neale Ranns8d7c5022019-02-06 01:41:05 -0800189 .fp_proto = fproto,
190 };
191 sa->tx_fib_index = fib_table_find (fproto, tx_table_id);
192 if (sa->tx_fib_index == ~((u32) 0))
193 {
194 pool_put (im->sad, sa);
195 return VNET_API_ERROR_NO_SUCH_FIB;
196 }
197
198 sa->fib_entry_index = fib_table_entry_special_add (sa->tx_fib_index,
199 &pfx,
200 FIB_SOURCE_RR,
201 FIB_ENTRY_FLAG_NONE);
202 sa->sibling = fib_entry_child_add (sa->fib_entry_index,
203 FIB_NODE_TYPE_IPSEC_SA, sa_index);
204 ipsec_sa_stack (sa);
Damjan Marionc59b9a22019-03-19 15:38:40 +0100205
206 /* generate header templates */
Damjan Mariond709cbc2019-03-26 13:16:42 +0100207 if (ipsec_sa_is_set_IS_TUNNEL_V6 (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100208 {
209 sa->ip6_hdr.ip_version_traffic_class_and_flow_label = 0x60;
210 sa->ip6_hdr.hop_limit = 254;
211 sa->ip6_hdr.src_address.as_u64[0] =
212 sa->tunnel_src_addr.ip6.as_u64[0];
213 sa->ip6_hdr.src_address.as_u64[1] =
214 sa->tunnel_src_addr.ip6.as_u64[1];
215 sa->ip6_hdr.dst_address.as_u64[0] =
216 sa->tunnel_dst_addr.ip6.as_u64[0];
217 sa->ip6_hdr.dst_address.as_u64[1] =
218 sa->tunnel_dst_addr.ip6.as_u64[1];
Damjan Mariond709cbc2019-03-26 13:16:42 +0100219 if (ipsec_sa_is_set_UDP_ENCAP (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100220 sa->ip6_hdr.protocol = IP_PROTOCOL_UDP;
221 else
222 sa->ip6_hdr.protocol = IP_PROTOCOL_IPSEC_ESP;
223 }
224 else
225 {
226 sa->ip4_hdr.ip_version_and_header_length = 0x45;
227 sa->ip4_hdr.ttl = 254;
228 sa->ip4_hdr.src_address.as_u32 = sa->tunnel_src_addr.ip4.as_u32;
229 sa->ip4_hdr.dst_address.as_u32 = sa->tunnel_dst_addr.ip4.as_u32;
230
Damjan Mariond709cbc2019-03-26 13:16:42 +0100231 if (ipsec_sa_is_set_UDP_ENCAP (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100232 sa->ip4_hdr.protocol = IP_PROTOCOL_UDP;
233 else
234 sa->ip4_hdr.protocol = IP_PROTOCOL_IPSEC_ESP;
235 sa->ip4_hdr.checksum = ip4_header_checksum (&sa->ip4_hdr);
236 }
Neale Ranns8d7c5022019-02-06 01:41:05 -0800237 }
Damjan Marionc59b9a22019-03-19 15:38:40 +0100238
Damjan Mariond709cbc2019-03-26 13:16:42 +0100239 if (ipsec_sa_is_set_UDP_ENCAP (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100240 {
241 sa->udp_hdr.src_port = clib_host_to_net_u16 (UDP_DST_PORT_ipsec);
242 sa->udp_hdr.dst_port = clib_host_to_net_u16 (UDP_DST_PORT_ipsec);
243 }
244
Neale Ranns8d7c5022019-02-06 01:41:05 -0800245 hash_set (im->sa_index_by_sa_id, sa->id, sa_index);
246
247 if (sa_out_index)
248 *sa_out_index = sa_index;
249
250 return (0);
251}
252
253u32
254ipsec_sa_del (u32 id)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800255{
256 ipsec_main_t *im = &ipsec_main;
257 ipsec_sa_t *sa = 0;
258 uword *p;
259 u32 sa_index;
260 clib_error_t *err;
261
Neale Ranns8d7c5022019-02-06 01:41:05 -0800262 p = hash_get (im->sa_index_by_sa_id, id);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800263
Neale Ranns8d7c5022019-02-06 01:41:05 -0800264 if (!p)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800265 return VNET_API_ERROR_NO_SUCH_ENTRY;
266
Neale Ranns8d7c5022019-02-06 01:41:05 -0800267 sa_index = p[0];
268 sa = pool_elt_at_index (im->sad, sa_index);
269 if (ipsec_is_sa_used (sa_index))
Neale Ranns999c8ee2019-02-01 03:31:24 -0800270 {
Neale Ranns8d7c5022019-02-06 01:41:05 -0800271 clib_warning ("sa_id %u used in policy", sa->id);
272 /* sa used in policy */
273 return VNET_API_ERROR_SYSCALL_ERROR_1;
Neale Ranns999c8ee2019-02-01 03:31:24 -0800274 }
Neale Ranns8d7c5022019-02-06 01:41:05 -0800275 hash_unset (im->sa_index_by_sa_id, sa->id);
276 err = ipsec_call_add_del_callbacks (im, sa, sa_index, 0);
277 if (err)
Neale Ranns4f33c802019-04-10 12:39:10 +0000278 return VNET_API_ERROR_SYSCALL_ERROR_2;
Damjan Mariond709cbc2019-03-26 13:16:42 +0100279
Neale Ranns2b5ba952019-04-02 10:15:40 +0000280 if (ipsec_sa_is_set_IS_TUNNEL (sa) && !ipsec_sa_is_set_IS_INBOUND (sa))
Neale Ranns999c8ee2019-02-01 03:31:24 -0800281 {
Neale Ranns8d7c5022019-02-06 01:41:05 -0800282 fib_entry_child_remove (sa->fib_entry_index, sa->sibling);
283 fib_table_entry_special_remove
284 (sa->tx_fib_index,
285 fib_entry_get_prefix (sa->fib_entry_index), FIB_SOURCE_RR);
286 dpo_reset (&sa->dpo[IPSEC_PROTOCOL_AH]);
287 dpo_reset (&sa->dpo[IPSEC_PROTOCOL_ESP]);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800288 }
Neale Ranns8d7c5022019-02-06 01:41:05 -0800289 pool_put (im->sad, sa);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800290 return 0;
291}
292
293u8
294ipsec_is_sa_used (u32 sa_index)
295{
296 ipsec_main_t *im = &ipsec_main;
Neale Ranns999c8ee2019-02-01 03:31:24 -0800297 ipsec_tunnel_if_t *t;
Neale Rannsa09c1ff2019-02-04 01:10:30 -0800298 ipsec_policy_t *p;
Neale Ranns999c8ee2019-02-01 03:31:24 -0800299
300 /* *INDENT-OFF* */
Neale Rannsa09c1ff2019-02-04 01:10:30 -0800301 pool_foreach(p, im->policies, ({
302 if (p->policy == IPSEC_POLICY_ACTION_PROTECT)
303 {
304 if (p->sa_index == sa_index)
305 return 1;
306 }
Neale Ranns999c8ee2019-02-01 03:31:24 -0800307 }));
308
309 pool_foreach(t, im->tunnel_interfaces, ({
310 if (t->input_sa_index == sa_index)
311 return 1;
312 if (t->output_sa_index == sa_index)
313 return 1;
314 }));
315 /* *INDENT-ON* */
316
317 return 0;
318}
319
320int
Neale Ranns8d7c5022019-02-06 01:41:05 -0800321ipsec_set_sa_key (u32 id, const ipsec_key_t * ck, const ipsec_key_t * ik)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800322{
323 ipsec_main_t *im = &ipsec_main;
324 uword *p;
325 u32 sa_index;
326 ipsec_sa_t *sa = 0;
327 clib_error_t *err;
328
Neale Ranns8d7c5022019-02-06 01:41:05 -0800329 p = hash_get (im->sa_index_by_sa_id, id);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800330 if (!p)
331 return VNET_API_ERROR_SYSCALL_ERROR_1; /* no such sa-id */
332
333 sa_index = p[0];
334 sa = pool_elt_at_index (im->sad, sa_index);
335
336 /* new crypto key */
Neale Ranns8d7c5022019-02-06 01:41:05 -0800337 if (ck)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800338 {
Neale Ranns8d7c5022019-02-06 01:41:05 -0800339 clib_memcpy (&sa->crypto_key, ck, sizeof (sa->crypto_key));
Neale Ranns999c8ee2019-02-01 03:31:24 -0800340 }
341
342 /* new integ key */
Neale Ranns8d7c5022019-02-06 01:41:05 -0800343 if (ik)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800344 {
Neale Ranns8d7c5022019-02-06 01:41:05 -0800345 clib_memcpy (&sa->integ_key, 0, sizeof (sa->integ_key));
Neale Ranns999c8ee2019-02-01 03:31:24 -0800346 }
347
Neale Ranns8d7c5022019-02-06 01:41:05 -0800348 if (ck || ik)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800349 {
350 err = ipsec_call_add_del_callbacks (im, sa, sa_index, 0);
351 if (err)
Kingwel Xie364b1ca2019-02-12 04:47:33 -0800352 {
353 clib_error_free (err);
354 return VNET_API_ERROR_SYSCALL_ERROR_1;
355 }
Neale Ranns999c8ee2019-02-01 03:31:24 -0800356 }
357
358 return 0;
359}
360
361u32
362ipsec_get_sa_index_by_sa_id (u32 sa_id)
363{
364 ipsec_main_t *im = &ipsec_main;
365 uword *p = hash_get (im->sa_index_by_sa_id, sa_id);
366 if (!p)
367 return ~0;
368
369 return p[0];
370}
371
Neale Rannsb4cfd552019-02-13 02:08:06 -0800372void
373ipsec_sa_walk (ipsec_sa_walk_cb_t cb, void *ctx)
374{
375 ipsec_main_t *im = &ipsec_main;
376 ipsec_sa_t *sa;
377
378 /* *INDENT-OFF* */
379 pool_foreach (sa, im->sad,
380 ({
381 if (WALK_CONTINUE != cb(sa, ctx))
382 break;
383 }));
384 /* *INDENT-ON* */
385}
386
Neale Ranns8d7c5022019-02-06 01:41:05 -0800387/**
388 * Function definition to get a FIB node from its index
389 */
390static fib_node_t *
391ipsec_sa_fib_node_get (fib_node_index_t index)
392{
393 ipsec_main_t *im;
394 ipsec_sa_t *sa;
395
396 im = &ipsec_main;
397 sa = pool_elt_at_index (im->sad, index);
398
399 return (&sa->node);
400}
401
402/**
403 * Function definition to inform the FIB node that its last lock has gone.
404 */
405static void
406ipsec_sa_last_lock_gone (fib_node_t * node)
407{
408 /*
409 * The ipsec SA is a root of the graph. As such
410 * it never has children and thus is never locked.
411 */
412 ASSERT (0);
413}
414
415static ipsec_sa_t *
416ipsec_sa_from_fib_node (fib_node_t * node)
417{
418 ASSERT (FIB_NODE_TYPE_IPSEC_SA == node->fn_type);
419 return ((ipsec_sa_t *) (((char *) node) -
420 STRUCT_OFFSET_OF (ipsec_sa_t, node)));
421
422}
423
424/**
425 * Function definition to backwalk a FIB node
426 */
427static fib_node_back_walk_rc_t
428ipsec_sa_back_walk (fib_node_t * node, fib_node_back_walk_ctx_t * ctx)
429{
430 ipsec_sa_stack (ipsec_sa_from_fib_node (node));
431
432 return (FIB_NODE_BACK_WALK_CONTINUE);
433}
434
435/*
436 * Virtual function table registered by MPLS GRE tunnels
437 * for participation in the FIB object graph.
438 */
439const static fib_node_vft_t ipsec_sa_vft = {
440 .fnv_get = ipsec_sa_fib_node_get,
441 .fnv_last_lock = ipsec_sa_last_lock_gone,
442 .fnv_back_walk = ipsec_sa_back_walk,
443};
444
445/* force inclusion from application's main.c */
446clib_error_t *
447ipsec_sa_interface_init (vlib_main_t * vm)
448{
449 fib_node_register_type (FIB_NODE_TYPE_IPSEC_SA, &ipsec_sa_vft);
450
451 return 0;
452}
453
454VLIB_INIT_FUNCTION (ipsec_sa_interface_init);
455
Neale Ranns999c8ee2019-02-01 03:31:24 -0800456/*
457 * fd.io coding-style-patch-verification: ON
458 *
459 * Local Variables:
460 * eval: (c-set-style "gnu")
461 * End:
462 */