blob: 6a3bdd51f4426fe1804b5e086f43181940b45319 [file] [log] [blame]
Ed Warnickecb9cada2015-12-08 15:45:58 -07001/*
2 * Copyright (c) 2015 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15/*
16 * Defines used for testing various optimisation schemes
17 */
18#define MAP_ENCAP_DUAL 0
19
20#include "map.h"
21#include "../ip/ip_frag.h"
Matus Fabiana774b532017-05-02 03:15:22 -070022#include <vnet/ip/ip4_to_ip6.h>
Ed Warnickecb9cada2015-12-08 15:45:58 -070023
24vlib_node_registration_t ip4_map_reass_node;
25
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070026enum ip4_map_next_e
27{
Ed Warnickecb9cada2015-12-08 15:45:58 -070028 IP4_MAP_NEXT_IP6_LOOKUP,
29#ifdef MAP_SKIP_IP6_LOOKUP
30 IP4_MAP_NEXT_IP6_REWRITE,
31#endif
Ole Troan9fb87552016-01-13 22:30:43 +010032 IP4_MAP_NEXT_IP4_FRAGMENT,
33 IP4_MAP_NEXT_IP6_FRAGMENT,
Ed Warnickecb9cada2015-12-08 15:45:58 -070034 IP4_MAP_NEXT_REASS,
Ole Troan9fb87552016-01-13 22:30:43 +010035 IP4_MAP_NEXT_ICMP_ERROR,
Ed Warnickecb9cada2015-12-08 15:45:58 -070036 IP4_MAP_NEXT_DROP,
37 IP4_MAP_N_NEXT,
38};
39
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070040enum ip4_map_reass_next_t
41{
Ed Warnickecb9cada2015-12-08 15:45:58 -070042 IP4_MAP_REASS_NEXT_IP6_LOOKUP,
43 IP4_MAP_REASS_NEXT_IP4_FRAGMENT,
44 IP4_MAP_REASS_NEXT_DROP,
45 IP4_MAP_REASS_N_NEXT,
46};
47
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070048typedef struct
49{
Ed Warnickecb9cada2015-12-08 15:45:58 -070050 u32 map_domain_index;
51 u16 port;
52 u8 cached;
53} map_ip4_map_reass_trace_t;
54
55u8 *
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070056format_ip4_map_reass_trace (u8 * s, va_list * args)
Ed Warnickecb9cada2015-12-08 15:45:58 -070057{
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070058 CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
59 CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
Ed Warnickecb9cada2015-12-08 15:45:58 -070060 map_ip4_map_reass_trace_t *t = va_arg (*args, map_ip4_map_reass_trace_t *);
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070061 return format (s, "MAP domain index: %d L4 port: %u Status: %s",
62 t->map_domain_index, t->port,
63 t->cached ? "cached" : "forwarded");
Ed Warnickecb9cada2015-12-08 15:45:58 -070064}
65
Ed Warnickecb9cada2015-12-08 15:45:58 -070066static_always_inline u16
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070067ip4_map_port_and_security_check (map_domain_t * d, ip4_header_t * ip,
68 u32 * next, u8 * error)
Ed Warnickecb9cada2015-12-08 15:45:58 -070069{
70 u16 port = 0;
71
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070072 if (d->psid_length > 0)
73 {
74 if (ip4_get_fragment_offset (ip) == 0)
75 {
76 if (PREDICT_FALSE
77 ((ip->ip_version_and_header_length != 0x45)
78 || clib_host_to_net_u16 (ip->length) < 28))
79 {
80 return 0;
81 }
Matus Fabiana774b532017-05-02 03:15:22 -070082 port = ip4_get_port (ip, 0);
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -070083 if (port)
84 {
85 /* Verify that port is not among the well-known ports */
86 if ((d->psid_offset > 0)
87 && (clib_net_to_host_u16 (port) <
88 (0x1 << (16 - d->psid_offset))))
89 {
90 *error = MAP_ERROR_ENCAP_SEC_CHECK;
91 }
92 else
93 {
94 if (ip4_get_fragment_more (ip))
95 *next = IP4_MAP_NEXT_REASS;
96 return (port);
97 }
98 }
99 else
100 {
101 *error = MAP_ERROR_BAD_PROTOCOL;
102 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700103 }
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700104 else
105 {
106 *next = IP4_MAP_NEXT_REASS;
107 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700108 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700109 return (0);
110}
111
112/*
113 * ip4_map_vtcfl
114 */
115static_always_inline u32
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700116ip4_map_vtcfl (ip4_header_t * ip4, vlib_buffer_t * p)
Ed Warnickecb9cada2015-12-08 15:45:58 -0700117{
118 map_main_t *mm = &map_main;
119 u8 tc = mm->tc_copy ? ip4->tos : mm->tc;
120 u32 vtcfl = 0x6 << 28;
121 vtcfl |= tc << 20;
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700122 vtcfl |= vnet_buffer (p)->ip.flow_hash & 0x000fffff;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700123
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700124 return (clib_host_to_net_u32 (vtcfl));
Ed Warnickecb9cada2015-12-08 15:45:58 -0700125}
126
127static_always_inline bool
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700128ip4_map_ip6_lookup_bypass (vlib_buffer_t * p0, ip4_header_t * ip)
Ed Warnickecb9cada2015-12-08 15:45:58 -0700129{
130#ifdef MAP_SKIP_IP6_LOOKUP
Neale Ranns80823802017-02-20 18:23:41 -0800131 if (FIB_NODE_INDEX_INVALID != pre_resolved[FIB_PROTOCOL_IP6].fei)
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700132 {
Neale Ranns80823802017-02-20 18:23:41 -0800133 vnet_buffer (p0)->ip.adj_index[VLIB_TX] =
134 pre_resolved[FIB_PROTOCOL_IP6].dpo.dpoi_index;
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700135 return (true);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700136 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700137#endif
138 return (false);
139}
140
141/*
Ole Troan366ac6e2016-01-06 12:40:28 +0100142 * ip4_map_ttl
143 */
144static inline void
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700145ip4_map_decrement_ttl (ip4_header_t * ip, u8 * error)
Ole Troan366ac6e2016-01-06 12:40:28 +0100146{
147 i32 ttl = ip->ttl;
148
149 /* Input node should have reject packets with ttl 0. */
150 ASSERT (ip->ttl > 0);
151
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700152 u32 checksum = ip->checksum + clib_host_to_net_u16 (0x0100);
Ole Troan366ac6e2016-01-06 12:40:28 +0100153 checksum += checksum >= 0xffff;
154 ip->checksum = checksum;
155 ttl -= 1;
156 ip->ttl = ttl;
157 *error = ttl <= 0 ? IP4_ERROR_TIME_EXPIRED : *error;
158
159 /* Verify checksum. */
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700160 ASSERT (ip->checksum == ip4_header_checksum (ip));
Ole Troan366ac6e2016-01-06 12:40:28 +0100161}
162
Ole Troan9fb87552016-01-13 22:30:43 +0100163static u32
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700164ip4_map_fragment (vlib_buffer_t * b, u16 mtu, bool df, u8 * error)
Ole Troan9fb87552016-01-13 22:30:43 +0100165{
166 map_main_t *mm = &map_main;
167
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700168 if (mm->frag_inner)
169 {
170 ip_frag_set_vnet_buffer (b, sizeof (ip6_header_t), mtu,
171 IP4_FRAG_NEXT_IP6_LOOKUP,
172 IP_FRAG_FLAG_IP6_HEADER);
173 return (IP4_MAP_NEXT_IP4_FRAGMENT);
Ole Troan9fb87552016-01-13 22:30:43 +0100174 }
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700175 else
176 {
177 if (df && !mm->frag_ignore_df)
178 {
179 icmp4_error_set_vnet_buffer (b, ICMP4_destination_unreachable,
180 ICMP4_destination_unreachable_fragmentation_needed_and_dont_fragment_set,
181 mtu);
182 vlib_buffer_advance (b, sizeof (ip6_header_t));
183 *error = MAP_ERROR_DF_SET;
184 return (IP4_MAP_NEXT_ICMP_ERROR);
185 }
186 ip_frag_set_vnet_buffer (b, 0, mtu, IP6_FRAG_NEXT_IP6_LOOKUP,
187 IP_FRAG_FLAG_IP6_HEADER);
188 return (IP4_MAP_NEXT_IP6_FRAGMENT);
189 }
Ole Troan9fb87552016-01-13 22:30:43 +0100190}
191
Ole Troan366ac6e2016-01-06 12:40:28 +0100192/*
Ed Warnickecb9cada2015-12-08 15:45:58 -0700193 * ip4_map
194 */
195static uword
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700196ip4_map (vlib_main_t * vm, vlib_node_runtime_t * node, vlib_frame_t * frame)
Ed Warnickecb9cada2015-12-08 15:45:58 -0700197{
198 u32 n_left_from, *from, next_index, *to_next, n_left_to_next;
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700199 vlib_node_runtime_t *error_node =
200 vlib_node_get_runtime (vm, ip4_map_node.index);
201 from = vlib_frame_vector_args (frame);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700202 n_left_from = frame->n_vectors;
203 next_index = node->cached_next_index;
204 map_main_t *mm = &map_main;
205 vlib_combined_counter_main_t *cm = mm->domain_counters;
Damjan Marion586afd72017-04-05 19:18:20 +0200206 u32 thread_index = vlib_get_thread_index ();
Ed Warnickecb9cada2015-12-08 15:45:58 -0700207
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700208 while (n_left_from > 0)
209 {
210 vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700211
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700212 /* Dual loop */
213 while (n_left_from >= 4 && n_left_to_next >= 2)
214 {
215 u32 pi0, pi1;
216 vlib_buffer_t *p0, *p1;
217 map_domain_t *d0, *d1;
218 u8 error0 = MAP_ERROR_NONE, error1 = MAP_ERROR_NONE;
219 ip4_header_t *ip40, *ip41;
220 u16 port0 = 0, port1 = 0;
221 ip6_header_t *ip6h0, *ip6h1;
222 u32 map_domain_index0 = ~0, map_domain_index1 = ~0;
223 u32 next0 = IP4_MAP_NEXT_IP6_LOOKUP, next1 =
224 IP4_MAP_NEXT_IP6_LOOKUP;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700225
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700226 /* Prefetch next iteration. */
227 {
228 vlib_buffer_t *p2, *p3;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700229
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700230 p2 = vlib_get_buffer (vm, from[2]);
231 p3 = vlib_get_buffer (vm, from[3]);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700232
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700233 vlib_prefetch_buffer_header (p2, STORE);
234 vlib_prefetch_buffer_header (p3, STORE);
235 /* IPv4 + 8 = 28. possibly plus -40 */
236 CLIB_PREFETCH (p2->data - 40, 68, STORE);
237 CLIB_PREFETCH (p3->data - 40, 68, STORE);
238 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700239
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700240 pi0 = to_next[0] = from[0];
241 pi1 = to_next[1] = from[1];
242 from += 2;
243 n_left_from -= 2;
244 to_next += 2;
245 n_left_to_next -= 2;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700246
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700247 p0 = vlib_get_buffer (vm, pi0);
248 p1 = vlib_get_buffer (vm, pi1);
249 ip40 = vlib_buffer_get_current (p0);
250 ip41 = vlib_buffer_get_current (p1);
Neale Ranns9705c382017-02-20 20:29:41 -0800251 map_domain_index0 = vnet_buffer (p0)->ip.adj_index[VLIB_TX];
252 d0 = ip4_map_get_domain (map_domain_index0);
253 map_domain_index1 = vnet_buffer (p1)->ip.adj_index[VLIB_TX];
254 d1 = ip4_map_get_domain (map_domain_index1);
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700255 ASSERT (d0);
256 ASSERT (d1);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700257
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700258 /*
259 * Shared IPv4 address
260 */
261 port0 = ip4_map_port_and_security_check (d0, ip40, &next0, &error0);
262 port1 = ip4_map_port_and_security_check (d1, ip41, &next1, &error1);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700263
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700264 /* Decrement IPv4 TTL */
265 ip4_map_decrement_ttl (ip40, &error0);
266 ip4_map_decrement_ttl (ip41, &error1);
267 bool df0 =
Ed Warnicke853e7202016-08-12 11:42:26 -0700268 ip40->flags_and_fragment_offset &
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700269 clib_host_to_net_u16 (IP4_HEADER_FLAG_DONT_FRAGMENT);
270 bool df1 =
Ed Warnicke853e7202016-08-12 11:42:26 -0700271 ip41->flags_and_fragment_offset &
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700272 clib_host_to_net_u16 (IP4_HEADER_FLAG_DONT_FRAGMENT);
Ole Troan9fb87552016-01-13 22:30:43 +0100273
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700274 /* MAP calc */
275 u32 da40 = clib_net_to_host_u32 (ip40->dst_address.as_u32);
276 u32 da41 = clib_net_to_host_u32 (ip41->dst_address.as_u32);
277 u16 dp40 = clib_net_to_host_u16 (port0);
278 u16 dp41 = clib_net_to_host_u16 (port1);
279 u64 dal60 = map_get_pfx (d0, da40, dp40);
280 u64 dal61 = map_get_pfx (d1, da41, dp41);
281 u64 dar60 = map_get_sfx (d0, da40, dp40);
282 u64 dar61 = map_get_sfx (d1, da41, dp41);
283 if (dal60 == 0 && dar60 == 0 && error0 == MAP_ERROR_NONE
284 && next0 != IP4_MAP_NEXT_REASS)
285 error0 = MAP_ERROR_NO_BINDING;
286 if (dal61 == 0 && dar61 == 0 && error1 == MAP_ERROR_NONE
287 && next1 != IP4_MAP_NEXT_REASS)
288 error1 = MAP_ERROR_NO_BINDING;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700289
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700290 /* construct ipv6 header */
291 vlib_buffer_advance (p0, -sizeof (ip6_header_t));
292 vlib_buffer_advance (p1, -sizeof (ip6_header_t));
293 ip6h0 = vlib_buffer_get_current (p0);
294 ip6h1 = vlib_buffer_get_current (p1);
295 vnet_buffer (p0)->sw_if_index[VLIB_TX] = (u32) ~ 0;
296 vnet_buffer (p1)->sw_if_index[VLIB_TX] = (u32) ~ 0;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700297
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700298 ip6h0->ip_version_traffic_class_and_flow_label =
299 ip4_map_vtcfl (ip40, p0);
300 ip6h1->ip_version_traffic_class_and_flow_label =
301 ip4_map_vtcfl (ip41, p1);
302 ip6h0->payload_length = ip40->length;
303 ip6h1->payload_length = ip41->length;
304 ip6h0->protocol = IP_PROTOCOL_IP_IN_IP;
305 ip6h1->protocol = IP_PROTOCOL_IP_IN_IP;
306 ip6h0->hop_limit = 0x40;
307 ip6h1->hop_limit = 0x40;
308 ip6h0->src_address = d0->ip6_src;
309 ip6h1->src_address = d1->ip6_src;
310 ip6h0->dst_address.as_u64[0] = clib_host_to_net_u64 (dal60);
311 ip6h0->dst_address.as_u64[1] = clib_host_to_net_u64 (dar60);
312 ip6h1->dst_address.as_u64[0] = clib_host_to_net_u64 (dal61);
313 ip6h1->dst_address.as_u64[1] = clib_host_to_net_u64 (dar61);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700314
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700315 /*
316 * Determine next node. Can be one of:
317 * ip6-lookup, ip6-rewrite, ip4-fragment, ip4-virtreass, error-drop
318 */
319 if (PREDICT_TRUE (error0 == MAP_ERROR_NONE))
320 {
321 if (PREDICT_FALSE
322 (d0->mtu
323 && (clib_net_to_host_u16 (ip6h0->payload_length) +
324 sizeof (*ip6h0) > d0->mtu)))
325 {
326 next0 = ip4_map_fragment (p0, d0->mtu, df0, &error0);
327 }
328 else
329 {
330 next0 =
331 ip4_map_ip6_lookup_bypass (p0,
332 ip40) ?
333 IP4_MAP_NEXT_IP6_REWRITE : next0;
334 vlib_increment_combined_counter (cm + MAP_DOMAIN_COUNTER_TX,
Damjan Marion586afd72017-04-05 19:18:20 +0200335 thread_index,
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700336 map_domain_index0, 1,
337 clib_net_to_host_u16
338 (ip6h0->payload_length) +
339 40);
340 }
341 }
342 else
343 {
344 next0 = IP4_MAP_NEXT_DROP;
345 }
346
347 /*
348 * Determine next node. Can be one of:
349 * ip6-lookup, ip6-rewrite, ip4-fragment, ip4-virtreass, error-drop
350 */
351 if (PREDICT_TRUE (error1 == MAP_ERROR_NONE))
352 {
353 if (PREDICT_FALSE
354 (d1->mtu
355 && (clib_net_to_host_u16 (ip6h1->payload_length) +
356 sizeof (*ip6h1) > d1->mtu)))
357 {
358 next1 = ip4_map_fragment (p1, d1->mtu, df1, &error1);
359 }
360 else
361 {
362 next1 =
363 ip4_map_ip6_lookup_bypass (p1,
364 ip41) ?
365 IP4_MAP_NEXT_IP6_REWRITE : next1;
366 vlib_increment_combined_counter (cm + MAP_DOMAIN_COUNTER_TX,
Damjan Marion586afd72017-04-05 19:18:20 +0200367 thread_index,
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700368 map_domain_index1, 1,
369 clib_net_to_host_u16
370 (ip6h1->payload_length) +
371 40);
372 }
373 }
374 else
375 {
376 next1 = IP4_MAP_NEXT_DROP;
377 }
378
379 if (PREDICT_FALSE (p0->flags & VLIB_BUFFER_IS_TRACED))
380 {
381 map_trace_t *tr = vlib_add_trace (vm, node, p0, sizeof (*tr));
382 tr->map_domain_index = map_domain_index0;
383 tr->port = port0;
384 }
385 if (PREDICT_FALSE (p1->flags & VLIB_BUFFER_IS_TRACED))
386 {
387 map_trace_t *tr = vlib_add_trace (vm, node, p1, sizeof (*tr));
388 tr->map_domain_index = map_domain_index1;
389 tr->port = port1;
390 }
391
392 p0->error = error_node->errors[error0];
393 p1->error = error_node->errors[error1];
394
395 vlib_validate_buffer_enqueue_x2 (vm, node, next_index, to_next,
396 n_left_to_next, pi0, pi1, next0,
397 next1);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700398 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700399
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700400 while (n_left_from > 0 && n_left_to_next > 0)
401 {
402 u32 pi0;
403 vlib_buffer_t *p0;
404 map_domain_t *d0;
405 u8 error0 = MAP_ERROR_NONE;
406 ip4_header_t *ip40;
407 u16 port0 = 0;
408 ip6_header_t *ip6h0;
409 u32 next0 = IP4_MAP_NEXT_IP6_LOOKUP;
410 u32 map_domain_index0 = ~0;
411
412 pi0 = to_next[0] = from[0];
413 from += 1;
414 n_left_from -= 1;
415 to_next += 1;
416 n_left_to_next -= 1;
417
418 p0 = vlib_get_buffer (vm, pi0);
419 ip40 = vlib_buffer_get_current (p0);
Neale Ranns9705c382017-02-20 20:29:41 -0800420 map_domain_index0 = vnet_buffer (p0)->ip.adj_index[VLIB_TX];
421 d0 = ip4_map_get_domain (map_domain_index0);
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700422 ASSERT (d0);
423
424 /*
425 * Shared IPv4 address
426 */
427 port0 = ip4_map_port_and_security_check (d0, ip40, &next0, &error0);
428
429 /* Decrement IPv4 TTL */
430 ip4_map_decrement_ttl (ip40, &error0);
431 bool df0 =
Ed Warnicke853e7202016-08-12 11:42:26 -0700432 ip40->flags_and_fragment_offset &
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700433 clib_host_to_net_u16 (IP4_HEADER_FLAG_DONT_FRAGMENT);
434
435 /* MAP calc */
436 u32 da40 = clib_net_to_host_u32 (ip40->dst_address.as_u32);
437 u16 dp40 = clib_net_to_host_u16 (port0);
438 u64 dal60 = map_get_pfx (d0, da40, dp40);
439 u64 dar60 = map_get_sfx (d0, da40, dp40);
440 if (dal60 == 0 && dar60 == 0 && error0 == MAP_ERROR_NONE
441 && next0 != IP4_MAP_NEXT_REASS)
442 error0 = MAP_ERROR_NO_BINDING;
443
444 /* construct ipv6 header */
445 vlib_buffer_advance (p0, -(sizeof (ip6_header_t)));
446 ip6h0 = vlib_buffer_get_current (p0);
447 vnet_buffer (p0)->sw_if_index[VLIB_TX] = (u32) ~ 0;
448
449 ip6h0->ip_version_traffic_class_and_flow_label =
450 ip4_map_vtcfl (ip40, p0);
451 ip6h0->payload_length = ip40->length;
452 ip6h0->protocol = IP_PROTOCOL_IP_IN_IP;
453 ip6h0->hop_limit = 0x40;
454 ip6h0->src_address = d0->ip6_src;
455 ip6h0->dst_address.as_u64[0] = clib_host_to_net_u64 (dal60);
456 ip6h0->dst_address.as_u64[1] = clib_host_to_net_u64 (dar60);
457
458 /*
459 * Determine next node. Can be one of:
460 * ip6-lookup, ip6-rewrite, ip4-fragment, ip4-virtreass, error-drop
461 */
462 if (PREDICT_TRUE (error0 == MAP_ERROR_NONE))
463 {
464 if (PREDICT_FALSE
465 (d0->mtu
466 && (clib_net_to_host_u16 (ip6h0->payload_length) +
467 sizeof (*ip6h0) > d0->mtu)))
468 {
469 next0 = ip4_map_fragment (p0, d0->mtu, df0, &error0);
470 }
471 else
472 {
473 next0 =
474 ip4_map_ip6_lookup_bypass (p0,
475 ip40) ?
476 IP4_MAP_NEXT_IP6_REWRITE : next0;
477 vlib_increment_combined_counter (cm + MAP_DOMAIN_COUNTER_TX,
Damjan Marion586afd72017-04-05 19:18:20 +0200478 thread_index,
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700479 map_domain_index0, 1,
480 clib_net_to_host_u16
481 (ip6h0->payload_length) +
482 40);
483 }
484 }
485 else
486 {
487 next0 = IP4_MAP_NEXT_DROP;
488 }
489
490 if (PREDICT_FALSE (p0->flags & VLIB_BUFFER_IS_TRACED))
491 {
492 map_trace_t *tr = vlib_add_trace (vm, node, p0, sizeof (*tr));
493 tr->map_domain_index = map_domain_index0;
494 tr->port = port0;
495 }
496
497 p0->error = error_node->errors[error0];
498 vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
499 n_left_to_next, pi0, next0);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700500 }
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700501 vlib_put_next_frame (vm, node, next_index, n_left_to_next);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700502 }
503
Ed Warnickecb9cada2015-12-08 15:45:58 -0700504 return frame->n_vectors;
505}
506
507/*
508 * ip4_map_reass
509 */
510static uword
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700511ip4_map_reass (vlib_main_t * vm,
512 vlib_node_runtime_t * node, vlib_frame_t * frame)
Ed Warnickecb9cada2015-12-08 15:45:58 -0700513{
514 u32 n_left_from, *from, next_index, *to_next, n_left_to_next;
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700515 vlib_node_runtime_t *error_node =
516 vlib_node_get_runtime (vm, ip4_map_reass_node.index);
517 from = vlib_frame_vector_args (frame);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700518 n_left_from = frame->n_vectors;
519 next_index = node->cached_next_index;
520 map_main_t *mm = &map_main;
521 vlib_combined_counter_main_t *cm = mm->domain_counters;
Damjan Marion586afd72017-04-05 19:18:20 +0200522 u32 thread_index = vlib_get_thread_index ();
Ed Warnickecb9cada2015-12-08 15:45:58 -0700523 u32 *fragments_to_drop = NULL;
524 u32 *fragments_to_loopback = NULL;
525
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700526 while (n_left_from > 0)
527 {
528 vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700529
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700530 while (n_left_from > 0 && n_left_to_next > 0)
531 {
532 u32 pi0;
533 vlib_buffer_t *p0;
534 map_domain_t *d0;
535 u8 error0 = MAP_ERROR_NONE;
536 ip4_header_t *ip40;
537 i32 port0 = 0;
538 ip6_header_t *ip60;
539 u32 next0 = IP4_MAP_REASS_NEXT_IP6_LOOKUP;
540 u32 map_domain_index0;
541 u8 cached = 0;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700542
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700543 pi0 = to_next[0] = from[0];
544 from += 1;
545 n_left_from -= 1;
546 to_next += 1;
547 n_left_to_next -= 1;
Ed Warnickecb9cada2015-12-08 15:45:58 -0700548
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700549 p0 = vlib_get_buffer (vm, pi0);
550 ip60 = vlib_buffer_get_current (p0);
551 ip40 = (ip4_header_t *) (ip60 + 1);
Neale Ranns9705c382017-02-20 20:29:41 -0800552 map_domain_index0 = vnet_buffer (p0)->ip.adj_index[VLIB_TX];
553 d0 = ip4_map_get_domain (map_domain_index0);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700554
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700555 map_ip4_reass_lock ();
Ed Warnicke853e7202016-08-12 11:42:26 -0700556 map_ip4_reass_t *r = map_ip4_reass_get (ip40->src_address.as_u32,
557 ip40->dst_address.as_u32,
558 ip40->fragment_id,
559 ip40->protocol,
560 &fragments_to_drop);
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700561 if (PREDICT_FALSE (!r))
562 {
563 // Could not create a caching entry
564 error0 = MAP_ERROR_FRAGMENT_MEMORY;
565 }
566 else if (PREDICT_TRUE (ip4_get_fragment_offset (ip40)))
567 {
568 if (r->port >= 0)
569 {
570 // We know the port already
571 port0 = r->port;
572 }
573 else if (map_ip4_reass_add_fragment (r, pi0))
574 {
575 // Not enough space for caching
576 error0 = MAP_ERROR_FRAGMENT_MEMORY;
577 map_ip4_reass_free (r, &fragments_to_drop);
578 }
579 else
580 {
581 cached = 1;
582 }
583 }
Matus Fabiana774b532017-05-02 03:15:22 -0700584 else if ((port0 = ip4_get_port (ip40, 0)) == 0)
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700585 {
586 // Could not find port. We'll free the reassembly.
587 error0 = MAP_ERROR_BAD_PROTOCOL;
588 port0 = 0;
589 map_ip4_reass_free (r, &fragments_to_drop);
590 }
591 else
592 {
593 r->port = port0;
594 map_ip4_reass_get_fragments (r, &fragments_to_loopback);
595 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700596
597#ifdef MAP_IP4_REASS_COUNT_BYTES
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700598 if (!cached && r)
599 {
600 r->forwarded += clib_host_to_net_u16 (ip40->length) - 20;
601 if (!ip4_get_fragment_more (ip40))
602 r->expected_total =
603 ip4_get_fragment_offset (ip40) * 8 +
604 clib_host_to_net_u16 (ip40->length) - 20;
605 if (r->forwarded >= r->expected_total)
606 map_ip4_reass_free (r, &fragments_to_drop);
607 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700608#endif
609
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700610 map_ip4_reass_unlock ();
Ed Warnickecb9cada2015-12-08 15:45:58 -0700611
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700612 // NOTE: Most operations have already been performed by ip4_map
613 // All we need is the right destination address
614 ip60->dst_address.as_u64[0] =
615 map_get_pfx_net (d0, ip40->dst_address.as_u32, port0);
616 ip60->dst_address.as_u64[1] =
617 map_get_sfx_net (d0, ip40->dst_address.as_u32, port0);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700618
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700619 if (PREDICT_FALSE
620 (d0->mtu
621 && (clib_net_to_host_u16 (ip60->payload_length) +
622 sizeof (*ip60) > d0->mtu)))
623 {
624 vnet_buffer (p0)->ip_frag.header_offset = sizeof (*ip60);
625 vnet_buffer (p0)->ip_frag.next_index = IP4_FRAG_NEXT_IP6_LOOKUP;
626 vnet_buffer (p0)->ip_frag.mtu = d0->mtu;
627 vnet_buffer (p0)->ip_frag.flags = IP_FRAG_FLAG_IP6_HEADER;
628 next0 = IP4_MAP_REASS_NEXT_IP4_FRAGMENT;
629 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700630
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700631 if (PREDICT_FALSE (p0->flags & VLIB_BUFFER_IS_TRACED))
632 {
633 map_ip4_map_reass_trace_t *tr =
634 vlib_add_trace (vm, node, p0, sizeof (*tr));
635 tr->map_domain_index = map_domain_index0;
636 tr->port = port0;
637 tr->cached = cached;
638 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700639
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700640 if (cached)
641 {
642 //Dequeue the packet
643 n_left_to_next++;
644 to_next--;
645 }
646 else
647 {
648 if (error0 == MAP_ERROR_NONE)
649 vlib_increment_combined_counter (cm + MAP_DOMAIN_COUNTER_TX,
Damjan Marion586afd72017-04-05 19:18:20 +0200650 thread_index,
651 map_domain_index0, 1,
Ed Warnicke853e7202016-08-12 11:42:26 -0700652 clib_net_to_host_u16
653 (ip60->payload_length) + 40);
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700654 next0 =
655 (error0 == MAP_ERROR_NONE) ? next0 : IP4_MAP_REASS_NEXT_DROP;
656 p0->error = error_node->errors[error0];
657 vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
658 n_left_to_next, pi0, next0);
659 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700660
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700661 //Loopback when we reach the end of the inpu vector
662 if (n_left_from == 0 && vec_len (fragments_to_loopback))
663 {
664 from = vlib_frame_vector_args (frame);
665 u32 len = vec_len (fragments_to_loopback);
666 if (len <= VLIB_FRAME_SIZE)
667 {
668 clib_memcpy (from, fragments_to_loopback,
669 sizeof (u32) * len);
670 n_left_from = len;
671 vec_reset_length (fragments_to_loopback);
672 }
673 else
674 {
675 clib_memcpy (from,
676 fragments_to_loopback + (len -
677 VLIB_FRAME_SIZE),
678 sizeof (u32) * VLIB_FRAME_SIZE);
679 n_left_from = VLIB_FRAME_SIZE;
680 _vec_len (fragments_to_loopback) = len - VLIB_FRAME_SIZE;
681 }
682 }
683 }
684 vlib_put_next_frame (vm, node, next_index, n_left_to_next);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700685 }
Ed Warnickecb9cada2015-12-08 15:45:58 -0700686
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700687 map_send_all_to_node (vm, fragments_to_drop, node,
688 &error_node->errors[MAP_ERROR_FRAGMENT_DROPPED],
689 IP4_MAP_REASS_NEXT_DROP);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700690
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700691 vec_free (fragments_to_drop);
692 vec_free (fragments_to_loopback);
Ed Warnickecb9cada2015-12-08 15:45:58 -0700693 return frame->n_vectors;
694}
695
696static char *map_error_strings[] = {
697#define _(sym,string) string,
698 foreach_map_error
699#undef _
700};
701
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700702/* *INDENT-OFF* */
Ed Warnickecb9cada2015-12-08 15:45:58 -0700703VLIB_REGISTER_NODE(ip4_map_node) = {
704 .function = ip4_map,
705 .name = "ip4-map",
706 .vector_size = sizeof(u32),
707 .format_trace = format_map_trace,
708 .type = VLIB_NODE_TYPE_INTERNAL,
Damjan Marion607de1a2016-08-16 22:53:54 +0200709
Ed Warnickecb9cada2015-12-08 15:45:58 -0700710 .n_errors = MAP_N_ERROR,
711 .error_strings = map_error_strings,
712
713 .n_next_nodes = IP4_MAP_N_NEXT,
714 .next_nodes = {
715 [IP4_MAP_NEXT_IP6_LOOKUP] = "ip6-lookup",
716#ifdef MAP_SKIP_IP6_LOOKUP
Neale Ranns80823802017-02-20 18:23:41 -0800717 [IP4_MAP_NEXT_IP6_REWRITE] = "ip6-load-balance",
Ed Warnickecb9cada2015-12-08 15:45:58 -0700718#endif
Ole Troan9fb87552016-01-13 22:30:43 +0100719 [IP4_MAP_NEXT_IP4_FRAGMENT] = "ip4-frag",
720 [IP4_MAP_NEXT_IP6_FRAGMENT] = "ip6-frag",
Ed Warnickecb9cada2015-12-08 15:45:58 -0700721 [IP4_MAP_NEXT_REASS] = "ip4-map-reass",
Ole Troan9fb87552016-01-13 22:30:43 +0100722 [IP4_MAP_NEXT_ICMP_ERROR] = "ip4-icmp-error",
Ed Warnickecb9cada2015-12-08 15:45:58 -0700723 [IP4_MAP_NEXT_DROP] = "error-drop",
724 },
725};
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700726/* *INDENT-ON* */
Ed Warnickecb9cada2015-12-08 15:45:58 -0700727
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700728/* *INDENT-OFF* */
Ed Warnickecb9cada2015-12-08 15:45:58 -0700729VLIB_REGISTER_NODE(ip4_map_reass_node) = {
730 .function = ip4_map_reass,
731 .name = "ip4-map-reass",
732 .vector_size = sizeof(u32),
733 .format_trace = format_ip4_map_reass_trace,
734 .type = VLIB_NODE_TYPE_INTERNAL,
Damjan Marion607de1a2016-08-16 22:53:54 +0200735
Ed Warnickecb9cada2015-12-08 15:45:58 -0700736 .n_errors = MAP_N_ERROR,
737 .error_strings = map_error_strings,
738
739 .n_next_nodes = IP4_MAP_REASS_N_NEXT,
740 .next_nodes = {
741 [IP4_MAP_REASS_NEXT_IP6_LOOKUP] = "ip6-lookup",
742 [IP4_MAP_REASS_NEXT_IP4_FRAGMENT] = "ip4-frag",
743 [IP4_MAP_REASS_NEXT_DROP] = "error-drop",
744 },
745};
Keith Burns (alagalah)06e3d072016-08-07 08:43:18 -0700746/* *INDENT-ON* */
747
748/*
749 * fd.io coding-style-patch-verification: ON
750 *
751 * Local Variables:
752 * eval: (c-set-style "gnu")
753 * End:
754 */