2 * Copyright (c) 2017 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #include "vom/acl_list.hpp"
17 #include "vom/acl_list_cmds.hpp"
18 #include "vom/logger.hpp"
19 #include "vom/singular_db_funcs.hpp"
25 l2_list::event_handler::event_handler()
27 OM::register_listener(this);
28 inspect::register_handler({ "l2-acl-list" }, "L2 ACL lists", this);
33 l2_list::event_handler::handle_populate(const client_db::key_t& key)
35 /* hack to get this function instantiated */
39 * dump VPP Bridge domains
41 std::shared_ptr<list_cmds::l2_dump_cmd> cmd =
42 std::make_shared<list_cmds::l2_dump_cmd>();
47 for (auto& record : *cmd) {
48 auto& payload = record.get_payload();
50 const handle_t hdl(payload.acl_index);
51 l2_list acl(hdl, std::string(reinterpret_cast<const char*>(payload.tag)));
53 for (unsigned int ii = 0; ii < payload.count; ii++) {
54 const route::prefix_t pfx(payload.r[ii].is_ipv6,
55 payload.r[ii].src_ip_addr,
56 payload.r[ii].src_ip_prefix_len);
57 l2_rule rule(ii, action_t::from_int(payload.r[ii].is_permit), pfx,
58 { payload.r[ii].src_mac }, { payload.r[ii].src_mac_mask });
62 VOM_LOG(log_level_t::DEBUG) << "dump: " << acl.to_string();
65 * Write each of the discovered ACLs into the OM,
66 * but disable the HW Command q whilst we do, so that no
67 * commands are sent to VPP
75 l2_list::event_handler::show(std::ostream& os)
81 l3_list::event_handler::event_handler()
83 OM::register_listener(this);
84 inspect::register_handler({ "l3-acl-list" }, "L3 ACL lists", this);
89 l3_list::event_handler::handle_populate(const client_db::key_t& key)
91 /* hack to get this function instantiated */
95 * dump L3 ACLs Bridge domains
97 std::shared_ptr<list_cmds::l3_dump_cmd> cmd =
98 std::make_shared<list_cmds::l3_dump_cmd>();
103 for (auto& record : *cmd) {
104 auto& payload = record.get_payload();
106 const handle_t hdl(payload.acl_index);
107 l3_list acl(hdl, std::string(reinterpret_cast<const char*>(payload.tag)));
109 for (unsigned int ii = 0; ii < payload.count; ii++) {
110 const route::prefix_t src(payload.r[ii].is_ipv6,
111 payload.r[ii].src_ip_addr,
112 payload.r[ii].src_ip_prefix_len);
113 const route::prefix_t dst(payload.r[ii].is_ipv6,
114 payload.r[ii].dst_ip_addr,
115 payload.r[ii].dst_ip_prefix_len);
116 l3_rule rule(ii, action_t::from_int(payload.r[ii].is_permit), src, dst);
118 rule.set_proto(payload.r[ii].proto);
119 rule.set_src_from_port(payload.r[ii].srcport_or_icmptype_first);
120 rule.set_src_to_port(payload.r[ii].srcport_or_icmptype_last);
121 rule.set_dst_from_port(payload.r[ii].dstport_or_icmpcode_first);
122 rule.set_dst_to_port(payload.r[ii].dstport_or_icmpcode_last);
123 rule.set_tcp_flags_mask(payload.r[ii].tcp_flags_mask);
124 rule.set_tcp_flags_value(payload.r[ii].tcp_flags_value);
128 VOM_LOG(log_level_t::DEBUG) << "dump: " << acl.to_string();
131 * Write each of the discovered ACLs into the OM,
132 * but disable the HW Command q whilst we do, so that no
133 * commands are sent to VPP
135 OM::commit(key, acl);
141 l3_list::event_handler::show(std::ostream& os)
148 l3_list::update(const l3_list& obj)
151 * always update the instance with the latest rule set
153 if (rc_t::OK != m_hdl.rc() || obj.m_rules != m_rules) {
154 HW::enqueue(new list_cmds::l3_update_cmd(m_hdl, m_key, m_rules));
157 * We don't, can't, read the priority from VPP,
158 * so the is equals check above does not include the priorty.
159 * but we save it now.
161 m_rules = obj.m_rules;
165 l2_list::update(const l2_list& obj)
168 * always update the instance with the latest rule set
170 if (rc_t::OK != m_hdl.rc() || obj.m_rules != m_rules) {
171 HW::enqueue(new list_cmds::l2_update_cmd(m_hdl, m_key, m_rules));
174 * We don't, can't, read the priority from VPP,
175 * so the is equals check above does not include the priorty.
176 * but we save it now.
178 m_rules = obj.m_rules;
181 * Sweep/reap the object if still stale
188 HW::enqueue(new list_cmds::l3_delete_cmd(m_hdl));
197 HW::enqueue(new list_cmds::l2_delete_cmd(m_hdl));
203 * Replay the objects state to HW
207 l3_list::replay(void)
210 m_hdl.data().reset();
211 HW::enqueue(new list_cmds::l3_update_cmd(m_hdl, m_key, m_rules));
216 l2_list::replay(void)
219 m_hdl.data().reset();
220 HW::enqueue(new list_cmds::l2_update_cmd(m_hdl, m_key, m_rules));
228 * fd.io coding-style-patch-verification: ON
231 * eval: (c-set-style "mozilla")