blob: afdecfee10d0d247567ebb0303b64e880f3eb9e3 [file] [log] [blame]
Neale Ranns999c8ee2019-02-01 03:31:24 -08001/*
2 * Copyright (c) 2015 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
6 *
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
14 */
15
16#include <vnet/ipsec/ipsec.h>
Damjan Marionc59b9a22019-03-19 15:38:40 +010017#include <vnet/ipsec/esp.h>
18#include <vnet/udp/udp.h>
Neale Ranns8d7c5022019-02-06 01:41:05 -080019#include <vnet/fib/fib_table.h>
Neale Rannsc87b66c2019-02-07 07:26:12 -080020#include <vnet/ipsec/ipsec_tun.h>
Neale Ranns999c8ee2019-02-01 03:31:24 -080021
Neale Rannseba31ec2019-02-17 18:04:27 +000022/**
23 * @brief
24 * SA packet & bytes counters
25 */
26vlib_combined_counter_main_t ipsec_sa_counters = {
27 .name = "SA",
28 .stat_segment_name = "/net/ipsec/sa",
29};
30
31
Neale Ranns999c8ee2019-02-01 03:31:24 -080032static clib_error_t *
33ipsec_call_add_del_callbacks (ipsec_main_t * im, ipsec_sa_t * sa,
34 u32 sa_index, int is_add)
35{
36 ipsec_ah_backend_t *ab;
37 ipsec_esp_backend_t *eb;
38 switch (sa->protocol)
39 {
40 case IPSEC_PROTOCOL_AH:
41 ab = pool_elt_at_index (im->ah_backends, im->ah_current_backend);
42 if (ab->add_del_sa_sess_cb)
43 return ab->add_del_sa_sess_cb (sa_index, is_add);
44 break;
45 case IPSEC_PROTOCOL_ESP:
46 eb = pool_elt_at_index (im->esp_backends, im->esp_current_backend);
47 if (eb->add_del_sa_sess_cb)
48 return eb->add_del_sa_sess_cb (sa_index, is_add);
49 break;
50 }
51 return 0;
52}
53
Neale Ranns8d7c5022019-02-06 01:41:05 -080054void
55ipsec_mk_key (ipsec_key_t * key, const u8 * data, u8 len)
56{
57 memset (key, 0, sizeof (*key));
58
59 if (len > sizeof (key->data))
60 key->len = sizeof (key->data);
61 else
62 key->len = len;
63
64 memcpy (key->data, data, key->len);
65}
66
67/**
68 * 'stack' (resolve the recursion for) the SA tunnel destination
69 */
Neale Rannse8915fc2019-04-23 20:57:55 -040070static void
Neale Ranns8d7c5022019-02-06 01:41:05 -080071ipsec_sa_stack (ipsec_sa_t * sa)
72{
Neale Rannsb4cfd552019-02-13 02:08:06 -080073 ipsec_main_t *im = &ipsec_main;
Neale Ranns8d7c5022019-02-06 01:41:05 -080074 fib_forward_chain_type_t fct;
75 dpo_id_t tmp = DPO_INVALID;
Neale Ranns8d7c5022019-02-06 01:41:05 -080076
Damjan Mariond709cbc2019-03-26 13:16:42 +010077 fct =
78 fib_forw_chain_type_from_fib_proto ((ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
79 FIB_PROTOCOL_IP6 :
80 FIB_PROTOCOL_IP4));
Neale Ranns8d7c5022019-02-06 01:41:05 -080081
82 fib_entry_contribute_forwarding (sa->fib_entry_index, fct, &tmp);
83
Neale Ranns72f2a3a2019-06-17 15:43:38 +000084 if (IPSEC_PROTOCOL_AH == sa->protocol)
85 dpo_stack_from_node ((ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
86 im->ah6_encrypt_node_index :
87 im->ah4_encrypt_node_index), &sa->dpo, &tmp);
88 else
89 dpo_stack_from_node ((ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
90 im->esp6_encrypt_node_index :
91 im->esp4_encrypt_node_index), &sa->dpo, &tmp);
Neale Rannsb4cfd552019-02-13 02:08:06 -080092 dpo_reset (&tmp);
Neale Ranns8d7c5022019-02-06 01:41:05 -080093}
94
Damjan Marionb966e8b2019-03-20 16:07:09 +010095void
96ipsec_sa_set_crypto_alg (ipsec_sa_t * sa, ipsec_crypto_alg_t crypto_alg)
97{
98 ipsec_main_t *im = &ipsec_main;
99 sa->crypto_alg = crypto_alg;
100 sa->crypto_iv_size = im->crypto_algs[crypto_alg].iv_size;
101 sa->crypto_block_size = im->crypto_algs[crypto_alg].block_size;
Damjan Marion060bfb92019-03-29 13:47:54 +0100102 sa->crypto_enc_op_id = im->crypto_algs[crypto_alg].enc_op_id;
103 sa->crypto_dec_op_id = im->crypto_algs[crypto_alg].dec_op_id;
Damjan Mariond1bed682019-04-24 15:20:35 +0200104 sa->crypto_calg = im->crypto_algs[crypto_alg].alg;
Damjan Marionb4fff3a2019-03-25 15:54:40 +0100105 ASSERT (sa->crypto_iv_size <= ESP_MAX_IV_SIZE);
Damjan Marionc59b9a22019-03-19 15:38:40 +0100106 ASSERT (sa->crypto_block_size <= ESP_MAX_BLOCK_SIZE);
Neale Ranns47feb112019-04-11 15:14:07 +0000107 if (IPSEC_CRYPTO_ALG_IS_GCM (crypto_alg))
108 {
109 sa->integ_icv_size = im->crypto_algs[crypto_alg].icv_size;
110 ipsec_sa_set_IS_AEAD (sa);
111 }
Damjan Marionb966e8b2019-03-20 16:07:09 +0100112}
113
114void
115ipsec_sa_set_integ_alg (ipsec_sa_t * sa, ipsec_integ_alg_t integ_alg)
116{
117 ipsec_main_t *im = &ipsec_main;
118 sa->integ_alg = integ_alg;
Damjan Marion7c22ff72019-04-04 12:25:44 +0200119 sa->integ_icv_size = im->integ_algs[integ_alg].icv_size;
Damjan Marion060bfb92019-03-29 13:47:54 +0100120 sa->integ_op_id = im->integ_algs[integ_alg].op_id;
Damjan Mariond1bed682019-04-24 15:20:35 +0200121 sa->integ_calg = im->integ_algs[integ_alg].alg;
Damjan Marion7c22ff72019-04-04 12:25:44 +0200122 ASSERT (sa->integ_icv_size <= ESP_MAX_ICV_SIZE);
Damjan Marionb966e8b2019-03-20 16:07:09 +0100123}
124
Neale Ranns999c8ee2019-02-01 03:31:24 -0800125int
Neale Ranns8d7c5022019-02-06 01:41:05 -0800126ipsec_sa_add (u32 id,
127 u32 spi,
128 ipsec_protocol_t proto,
129 ipsec_crypto_alg_t crypto_alg,
130 const ipsec_key_t * ck,
131 ipsec_integ_alg_t integ_alg,
132 const ipsec_key_t * ik,
133 ipsec_sa_flags_t flags,
134 u32 tx_table_id,
Neale Ranns47feb112019-04-11 15:14:07 +0000135 u32 salt,
Neale Ranns8d7c5022019-02-06 01:41:05 -0800136 const ip46_address_t * tun_src,
137 const ip46_address_t * tun_dst, u32 * sa_out_index)
138{
Damjan Mariond1bed682019-04-24 15:20:35 +0200139 vlib_main_t *vm = vlib_get_main ();
Neale Ranns8d7c5022019-02-06 01:41:05 -0800140 ipsec_main_t *im = &ipsec_main;
141 clib_error_t *err;
142 ipsec_sa_t *sa;
143 u32 sa_index;
144 uword *p;
145
146 p = hash_get (im->sa_index_by_sa_id, id);
147 if (p)
148 return VNET_API_ERROR_ENTRY_ALREADY_EXISTS;
149
Damjan Mariond709cbc2019-03-26 13:16:42 +0100150 pool_get_aligned_zero (im->sad, sa, CLIB_CACHE_LINE_BYTES);
Neale Ranns8d7c5022019-02-06 01:41:05 -0800151
152 fib_node_init (&sa->node, FIB_NODE_TYPE_IPSEC_SA);
153 sa_index = sa - im->sad;
154
Neale Rannseba31ec2019-02-17 18:04:27 +0000155 vlib_validate_combined_counter (&ipsec_sa_counters, sa_index);
156 vlib_zero_combined_counter (&ipsec_sa_counters, sa_index);
157
Neale Ranns8d7c5022019-02-06 01:41:05 -0800158 sa->id = id;
159 sa->spi = spi;
Neale Rannseba31ec2019-02-17 18:04:27 +0000160 sa->stat_index = sa_index;
Neale Ranns8d7c5022019-02-06 01:41:05 -0800161 sa->protocol = proto;
Neale Ranns2b5ba952019-04-02 10:15:40 +0000162 sa->flags = flags;
Neale Ranns47feb112019-04-11 15:14:07 +0000163 sa->salt = salt;
Damjan Marionb966e8b2019-03-20 16:07:09 +0100164 ipsec_sa_set_integ_alg (sa, integ_alg);
Neale Ranns8d7c5022019-02-06 01:41:05 -0800165 clib_memcpy (&sa->integ_key, ik, sizeof (sa->integ_key));
Neale Ranns47feb112019-04-11 15:14:07 +0000166 ipsec_sa_set_crypto_alg (sa, crypto_alg);
167 clib_memcpy (&sa->crypto_key, ck, sizeof (sa->crypto_key));
Neale Ranns8d7c5022019-02-06 01:41:05 -0800168 ip46_address_copy (&sa->tunnel_src_addr, tun_src);
169 ip46_address_copy (&sa->tunnel_dst_addr, tun_dst);
170
Damjan Mariond1bed682019-04-24 15:20:35 +0200171 sa->crypto_key_index = vnet_crypto_key_add (vm,
172 im->crypto_algs[crypto_alg].alg,
173 (u8 *) ck->data, ck->len);
Benoît Gannebe954442019-04-29 16:05:46 +0200174 if (~0 == sa->crypto_key_index)
Neale Rannse6be7022019-06-04 15:37:34 +0000175 {
176 pool_put (im->sad, sa);
177 return VNET_API_ERROR_KEY_LENGTH;
178 }
Benoît Gannebe954442019-04-29 16:05:46 +0200179
Damjan Mariond1bed682019-04-24 15:20:35 +0200180 sa->integ_key_index = vnet_crypto_key_add (vm,
181 im->integ_algs[integ_alg].alg,
182 (u8 *) ik->data, ik->len);
Benoît Gannebe954442019-04-29 16:05:46 +0200183 if (~0 == sa->integ_key_index)
Neale Rannse6be7022019-06-04 15:37:34 +0000184 {
185 pool_put (im->sad, sa);
186 return VNET_API_ERROR_KEY_LENGTH;
187 }
Damjan Mariond1bed682019-04-24 15:20:35 +0200188
Neale Ranns8d7c5022019-02-06 01:41:05 -0800189 err = ipsec_check_support_cb (im, sa);
190 if (err)
191 {
192 clib_warning ("%s", err->what);
193 pool_put (im->sad, sa);
194 return VNET_API_ERROR_UNIMPLEMENTED;
195 }
196
197 err = ipsec_call_add_del_callbacks (im, sa, sa_index, 1);
198 if (err)
199 {
200 pool_put (im->sad, sa);
201 return VNET_API_ERROR_SYSCALL_ERROR_1;
202 }
203
Neale Ranns2b5ba952019-04-02 10:15:40 +0000204 if (ipsec_sa_is_set_IS_TUNNEL (sa) && !ipsec_sa_is_set_IS_INBOUND (sa))
Neale Ranns8d7c5022019-02-06 01:41:05 -0800205 {
Damjan Mariond709cbc2019-03-26 13:16:42 +0100206 fib_protocol_t fproto = (ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ?
Neale Ranns8d7c5022019-02-06 01:41:05 -0800207 FIB_PROTOCOL_IP6 : FIB_PROTOCOL_IP4);
208 fib_prefix_t pfx = {
209 .fp_addr = sa->tunnel_dst_addr,
Damjan Mariond709cbc2019-03-26 13:16:42 +0100210 .fp_len = (ipsec_sa_is_set_IS_TUNNEL_V6 (sa) ? 128 : 32),
Neale Ranns8d7c5022019-02-06 01:41:05 -0800211 .fp_proto = fproto,
212 };
213 sa->tx_fib_index = fib_table_find (fproto, tx_table_id);
214 if (sa->tx_fib_index == ~((u32) 0))
215 {
216 pool_put (im->sad, sa);
217 return VNET_API_ERROR_NO_SUCH_FIB;
218 }
219
220 sa->fib_entry_index = fib_table_entry_special_add (sa->tx_fib_index,
221 &pfx,
222 FIB_SOURCE_RR,
223 FIB_ENTRY_FLAG_NONE);
224 sa->sibling = fib_entry_child_add (sa->fib_entry_index,
225 FIB_NODE_TYPE_IPSEC_SA, sa_index);
226 ipsec_sa_stack (sa);
Damjan Marionc59b9a22019-03-19 15:38:40 +0100227
228 /* generate header templates */
Damjan Mariond709cbc2019-03-26 13:16:42 +0100229 if (ipsec_sa_is_set_IS_TUNNEL_V6 (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100230 {
231 sa->ip6_hdr.ip_version_traffic_class_and_flow_label = 0x60;
232 sa->ip6_hdr.hop_limit = 254;
233 sa->ip6_hdr.src_address.as_u64[0] =
234 sa->tunnel_src_addr.ip6.as_u64[0];
235 sa->ip6_hdr.src_address.as_u64[1] =
236 sa->tunnel_src_addr.ip6.as_u64[1];
237 sa->ip6_hdr.dst_address.as_u64[0] =
238 sa->tunnel_dst_addr.ip6.as_u64[0];
239 sa->ip6_hdr.dst_address.as_u64[1] =
240 sa->tunnel_dst_addr.ip6.as_u64[1];
Damjan Mariond709cbc2019-03-26 13:16:42 +0100241 if (ipsec_sa_is_set_UDP_ENCAP (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100242 sa->ip6_hdr.protocol = IP_PROTOCOL_UDP;
243 else
244 sa->ip6_hdr.protocol = IP_PROTOCOL_IPSEC_ESP;
245 }
246 else
247 {
248 sa->ip4_hdr.ip_version_and_header_length = 0x45;
249 sa->ip4_hdr.ttl = 254;
250 sa->ip4_hdr.src_address.as_u32 = sa->tunnel_src_addr.ip4.as_u32;
251 sa->ip4_hdr.dst_address.as_u32 = sa->tunnel_dst_addr.ip4.as_u32;
252
Damjan Mariond709cbc2019-03-26 13:16:42 +0100253 if (ipsec_sa_is_set_UDP_ENCAP (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100254 sa->ip4_hdr.protocol = IP_PROTOCOL_UDP;
255 else
256 sa->ip4_hdr.protocol = IP_PROTOCOL_IPSEC_ESP;
257 sa->ip4_hdr.checksum = ip4_header_checksum (&sa->ip4_hdr);
258 }
Neale Ranns8d7c5022019-02-06 01:41:05 -0800259 }
Damjan Marionc59b9a22019-03-19 15:38:40 +0100260
Damjan Mariond709cbc2019-03-26 13:16:42 +0100261 if (ipsec_sa_is_set_UDP_ENCAP (sa))
Damjan Marionc59b9a22019-03-19 15:38:40 +0100262 {
263 sa->udp_hdr.src_port = clib_host_to_net_u16 (UDP_DST_PORT_ipsec);
264 sa->udp_hdr.dst_port = clib_host_to_net_u16 (UDP_DST_PORT_ipsec);
265 }
266
Neale Ranns8d7c5022019-02-06 01:41:05 -0800267 hash_set (im->sa_index_by_sa_id, sa->id, sa_index);
268
269 if (sa_out_index)
270 *sa_out_index = sa_index;
271
272 return (0);
273}
274
275u32
276ipsec_sa_del (u32 id)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800277{
Damjan Mariond1bed682019-04-24 15:20:35 +0200278 vlib_main_t *vm = vlib_get_main ();
Neale Ranns999c8ee2019-02-01 03:31:24 -0800279 ipsec_main_t *im = &ipsec_main;
280 ipsec_sa_t *sa = 0;
281 uword *p;
282 u32 sa_index;
283 clib_error_t *err;
284
Neale Ranns8d7c5022019-02-06 01:41:05 -0800285 p = hash_get (im->sa_index_by_sa_id, id);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800286
Neale Ranns8d7c5022019-02-06 01:41:05 -0800287 if (!p)
Neale Ranns999c8ee2019-02-01 03:31:24 -0800288 return VNET_API_ERROR_NO_SUCH_ENTRY;
289
Neale Ranns8d7c5022019-02-06 01:41:05 -0800290 sa_index = p[0];
291 sa = pool_elt_at_index (im->sad, sa_index);
292 if (ipsec_is_sa_used (sa_index))
Neale Ranns999c8ee2019-02-01 03:31:24 -0800293 {
Neale Ranns8d7c5022019-02-06 01:41:05 -0800294 clib_warning ("sa_id %u used in policy", sa->id);
295 /* sa used in policy */
Neale Rannsc87b66c2019-02-07 07:26:12 -0800296 return VNET_API_ERROR_RSRC_IN_USE;
Neale Ranns999c8ee2019-02-01 03:31:24 -0800297 }
Neale Ranns8d7c5022019-02-06 01:41:05 -0800298 hash_unset (im->sa_index_by_sa_id, sa->id);
299 err = ipsec_call_add_del_callbacks (im, sa, sa_index, 0);
300 if (err)
Neale Ranns4f33c802019-04-10 12:39:10 +0000301 return VNET_API_ERROR_SYSCALL_ERROR_2;
Damjan Mariond709cbc2019-03-26 13:16:42 +0100302
Neale Ranns2b5ba952019-04-02 10:15:40 +0000303 if (ipsec_sa_is_set_IS_TUNNEL (sa) && !ipsec_sa_is_set_IS_INBOUND (sa))
Neale Ranns999c8ee2019-02-01 03:31:24 -0800304 {
Neale Ranns8d7c5022019-02-06 01:41:05 -0800305 fib_entry_child_remove (sa->fib_entry_index, sa->sibling);
306 fib_table_entry_special_remove
307 (sa->tx_fib_index,
308 fib_entry_get_prefix (sa->fib_entry_index), FIB_SOURCE_RR);
Neale Ranns72f2a3a2019-06-17 15:43:38 +0000309 dpo_reset (&sa->dpo);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800310 }
Damjan Mariond1bed682019-04-24 15:20:35 +0200311 vnet_crypto_key_del (vm, sa->crypto_key_index);
312 vnet_crypto_key_del (vm, sa->integ_key_index);
Neale Ranns8d7c5022019-02-06 01:41:05 -0800313 pool_put (im->sad, sa);
Neale Ranns999c8ee2019-02-01 03:31:24 -0800314 return 0;
315}
316
Neale Rannsc87b66c2019-02-07 07:26:12 -0800317void
318ipsec_sa_clear (index_t sai)
319{
320 vlib_zero_combined_counter (&ipsec_sa_counters, sai);
321}
322
Neale Ranns999c8ee2019-02-01 03:31:24 -0800323u8
324ipsec_is_sa_used (u32 sa_index)
325{
326 ipsec_main_t *im = &ipsec_main;
Neale Rannsc87b66c2019-02-07 07:26:12 -0800327 ipsec_tun_protect_t *itp;
Neale Ranns999c8ee2019-02-01 03:31:24 -0800328 ipsec_tunnel_if_t *t;
Neale Rannsa09c1ff2019-02-04 01:10:30 -0800329 ipsec_policy_t *p;
Neale Rannsc87b66c2019-02-07 07:26:12 -0800330 u32 sai;
Neale Ranns999c8ee2019-02-01 03:31:24 -0800331
332 /* *INDENT-OFF* */
Neale Rannsa09c1ff2019-02-04 01:10:30 -0800333 pool_foreach(p, im->policies, ({
334 if (p->policy == IPSEC_POLICY_ACTION_PROTECT)
335 {
336 if (p->sa_index == sa_index)
337 return 1;
338 }
Neale Ranns999c8ee2019-02-01 03:31:24 -0800339 }));
340
341 pool_foreach(t, im->tunnel_interfaces, ({
342 if (t->input_sa_index == sa_index)
343 return 1;
344 if (t->output_sa_index == sa_index)
345 return 1;
346 }));
Neale Rannsc87b66c2019-02-07 07:26:12 -0800347
348 /* *INDENT-OFF* */
349 pool_foreach(itp, ipsec_protect_pool, ({
350 FOR_EACH_IPSEC_PROTECT_INPUT_SAI(itp, sai,
351 ({
352 if (sai == sa_index)
353 return 1;
354 }));
355 if (itp->itp_out_sa == sa_index)
356 return 1;
357 }));
Neale Ranns999c8ee2019-02-01 03:31:24 -0800358 /* *INDENT-ON* */
359
Neale Rannsc87b66c2019-02-07 07:26:12 -0800360
Neale Ranns999c8ee2019-02-01 03:31:24 -0800361 return 0;
362}
363
Neale Ranns999c8ee2019-02-01 03:31:24 -0800364u32
365ipsec_get_sa_index_by_sa_id (u32 sa_id)
366{
367 ipsec_main_t *im = &ipsec_main;
368 uword *p = hash_get (im->sa_index_by_sa_id, sa_id);
369 if (!p)
370 return ~0;
371
372 return p[0];
373}
374
Neale Rannsb4cfd552019-02-13 02:08:06 -0800375void
376ipsec_sa_walk (ipsec_sa_walk_cb_t cb, void *ctx)
377{
378 ipsec_main_t *im = &ipsec_main;
379 ipsec_sa_t *sa;
380
381 /* *INDENT-OFF* */
382 pool_foreach (sa, im->sad,
383 ({
384 if (WALK_CONTINUE != cb(sa, ctx))
385 break;
386 }));
387 /* *INDENT-ON* */
388}
389
Neale Ranns8d7c5022019-02-06 01:41:05 -0800390/**
391 * Function definition to get a FIB node from its index
392 */
393static fib_node_t *
394ipsec_sa_fib_node_get (fib_node_index_t index)
395{
396 ipsec_main_t *im;
397 ipsec_sa_t *sa;
398
399 im = &ipsec_main;
400 sa = pool_elt_at_index (im->sad, index);
401
402 return (&sa->node);
403}
404
405/**
406 * Function definition to inform the FIB node that its last lock has gone.
407 */
408static void
409ipsec_sa_last_lock_gone (fib_node_t * node)
410{
411 /*
412 * The ipsec SA is a root of the graph. As such
413 * it never has children and thus is never locked.
414 */
415 ASSERT (0);
416}
417
418static ipsec_sa_t *
419ipsec_sa_from_fib_node (fib_node_t * node)
420{
421 ASSERT (FIB_NODE_TYPE_IPSEC_SA == node->fn_type);
422 return ((ipsec_sa_t *) (((char *) node) -
423 STRUCT_OFFSET_OF (ipsec_sa_t, node)));
424
425}
426
427/**
428 * Function definition to backwalk a FIB node
429 */
430static fib_node_back_walk_rc_t
431ipsec_sa_back_walk (fib_node_t * node, fib_node_back_walk_ctx_t * ctx)
432{
433 ipsec_sa_stack (ipsec_sa_from_fib_node (node));
434
435 return (FIB_NODE_BACK_WALK_CONTINUE);
436}
437
438/*
Neale Rannsc87b66c2019-02-07 07:26:12 -0800439 * Virtual function table registered by SAs
Neale Ranns8d7c5022019-02-06 01:41:05 -0800440 * for participation in the FIB object graph.
441 */
442const static fib_node_vft_t ipsec_sa_vft = {
443 .fnv_get = ipsec_sa_fib_node_get,
444 .fnv_last_lock = ipsec_sa_last_lock_gone,
445 .fnv_back_walk = ipsec_sa_back_walk,
446};
447
448/* force inclusion from application's main.c */
449clib_error_t *
450ipsec_sa_interface_init (vlib_main_t * vm)
451{
452 fib_node_register_type (FIB_NODE_TYPE_IPSEC_SA, &ipsec_sa_vft);
453
454 return 0;
455}
456
457VLIB_INIT_FUNCTION (ipsec_sa_interface_init);
458
Neale Ranns999c8ee2019-02-01 03:31:24 -0800459/*
460 * fd.io coding-style-patch-verification: ON
461 *
462 * Local Variables:
463 * eval: (c-set-style "gnu")
464 * End:
465 */