2 * Copyright (c) 2017 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #include "vom/acl_l3_list.hpp"
17 #include "vom/acl_list_cmds.hpp"
18 #include "vom/logger.hpp"
19 #include "vom/singular_db_funcs.hpp"
25 * Definition of the static singular_db for ACL Lists
27 singular_db<l3_list::key_t, l3_list> l3_list::m_db;
30 * Definition of the static per-handle DB for ACL Lists
32 std::map<handle_t, std::weak_ptr<l3_list>> l3_list::m_hdl_db;
34 l3_list::event_handler l3_list::m_evh;
36 l3_list::event_handler::event_handler()
38 OM::register_listener(this);
39 inspect::register_handler({ "l3-acl-list" }, "L3 ACL lists", this);
42 l3_list::l3_list(const key_t& key)
43 : m_hdl(handle_t::INVALID)
47 l3_list::l3_list(const handle_t& hdl, const key_t& key)
52 l3_list::l3_list(const key_t& key, const rules_t& rules)
53 : m_hdl(handle_t::INVALID)
58 l3_list::l3_list(const l3_list& o)
67 m_db.release(m_key, this);
70 std::shared_ptr<l3_list>
71 l3_list::singular() const
73 return find_or_add(*this);
77 * Dump all ACLs into the stream provided
80 l3_list::dump(std::ostream& os)
86 * convert to string format for debug purposes
89 l3_list::to_string() const
92 s << "acl-list:[" << m_key << " " << m_hdl.to_string() << " rules:[";
94 for (auto rule : m_rules) {
95 s << rule.to_string() << " ";
104 l3_list::insert(const l3_rule& rule)
106 m_rules.insert(rule);
110 l3_list::remove(const l3_rule& rule)
116 l3_list::handle() const
118 return (singular()->handle_i());
121 std::shared_ptr<l3_list>
122 l3_list::find(const handle_t& handle)
124 return (m_hdl_db[handle].lock());
127 std::shared_ptr<l3_list>
128 l3_list::find(const key_t& key)
130 return (m_db.find(key));
133 std::shared_ptr<l3_list>
134 l3_list::find_or_add(const l3_list& temp)
136 return (m_db.find_or_add(temp.key(), temp));
140 l3_list::handle_i() const
142 return (m_hdl.data());
146 l3_list::add(const key_t& key, const HW::item<handle_t>& item)
148 std::shared_ptr<l3_list> sp = find(key);
151 m_hdl_db[item.data()] = sp;
156 l3_list::remove(const HW::item<handle_t>& item)
158 m_hdl_db.erase(item.data());
161 const l3_list::key_t&
167 const l3_list::rules_t&
168 l3_list::rules() const
174 l3_list::operator==(const l3_list& l) const
176 return (key() == l.key() && rules() == l.rules());
180 l3_list::event_handler::handle_populate(const client_db::key_t& key)
183 * dump L3 ACLs Bridge domains
185 std::shared_ptr<list_cmds::l3_dump_cmd> cmd =
186 std::make_shared<list_cmds::l3_dump_cmd>();
191 for (auto& record : *cmd) {
192 auto& payload = record.get_payload();
194 const handle_t hdl(payload.acl_index);
195 l3_list acl(hdl, std::string(reinterpret_cast<const char*>(payload.tag)));
197 for (unsigned int ii = 0; ii < payload.count; ii++) {
198 const route::prefix_t src(payload.r[ii].src_prefix.address.af,
199 (uint8_t*)&payload.r[ii].src_prefix.address.un,
200 payload.r[ii].src_prefix.len);
201 const route::prefix_t dst(payload.r[ii].dst_prefix.address.af,
202 (uint8_t*)&payload.r[ii].dst_prefix.address.un,
203 payload.r[ii].dst_prefix.len);
204 l3_rule rule(ii, action_t::from_int(payload.r[ii].is_permit), src, dst);
206 rule.set_proto(payload.r[ii].proto);
207 rule.set_src_from_port(payload.r[ii].srcport_or_icmptype_first);
208 rule.set_src_to_port(payload.r[ii].srcport_or_icmptype_last);
209 rule.set_dst_from_port(payload.r[ii].dstport_or_icmpcode_first);
210 rule.set_dst_to_port(payload.r[ii].dstport_or_icmpcode_last);
211 rule.set_tcp_flags_mask(payload.r[ii].tcp_flags_mask);
212 rule.set_tcp_flags_value(payload.r[ii].tcp_flags_value);
216 VOM_LOG(log_level_t::DEBUG) << "dump: " << acl.to_string();
219 * Write each of the discovered ACLs into the OM,
220 * but disable the HW Command q whilst we do, so that no
221 * commands are sent to VPP
223 OM::commit(key, acl);
228 l3_list::event_handler::show(std::ostream& os)
234 l3_list::event_handler::order() const
236 return (dependency_t::ACL);
240 l3_list::event_handler::handle_replay()
246 l3_list::update(const l3_list& obj)
249 * always update the instance with the latest rule set
251 if (rc_t::OK != m_hdl.rc() || obj.m_rules != m_rules) {
252 HW::enqueue(new list_cmds::l3_update_cmd(m_hdl, m_key, m_rules));
255 * We don't, can't, read the priority from VPP,
256 * so the is equals check above does not include the priorty.
257 * but we save it now.
259 m_rules = obj.m_rules;
263 * Sweep/reap the object if still stale
269 HW::enqueue(new list_cmds::l3_delete_cmd(m_hdl));
275 * Replay the objects state to HW
278 l3_list::replay(void)
281 m_hdl.data().reset();
282 HW::enqueue(new list_cmds::l3_update_cmd(m_hdl, m_key, m_rules));
290 * fd.io coding-style-patch-verification: ON
293 * eval: (c-set-style "mozilla")