2 * Copyright (c) 2018 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #include <plugins/gbp/gbp_bridge_domain.h>
17 #include <plugins/gbp/gbp_route_domain.h>
18 #include <plugins/gbp/gbp_endpoint.h>
19 #include <plugins/gbp/gbp_learn.h>
20 #include <plugins/gbp/gbp_itf.h>
22 #include <vnet/dpo/dvr_dpo.h>
23 #include <vnet/fib/fib_table.h>
24 #include <vnet/l2/l2_input.h>
25 #include <vnet/l2/feat_bitmap.h>
26 #include <vnet/l2/l2_bvi.h>
27 #include <vnet/l2/l2_fib.h>
30 * Pool of GBP bridge_domains
32 gbp_bridge_domain_t *gbp_bridge_domain_pool;
35 * DB of bridge_domains
37 gbp_bridge_domain_db_t gbp_bridge_domain_db;
40 * Map of BD index to contract scope
42 gbp_scope_t *gbp_scope_by_bd_index;
47 vlib_log_class_t gb_logger;
49 #define GBP_BD_DBG(...) \
50 vlib_log_debug (gb_logger, __VA_ARGS__);
53 gbp_bridge_domain_index (const gbp_bridge_domain_t * gbd)
55 return (gbd - gbp_bridge_domain_pool);
59 gbp_bridge_domain_lock (index_t i)
61 gbp_bridge_domain_t *gb;
63 gb = gbp_bridge_domain_get (i);
68 gbp_bridge_domain_get_bd_id (index_t gbdi)
70 gbp_bridge_domain_t *gb;
72 gb = gbp_bridge_domain_get (gbdi);
74 return (gb->gb_bd_id);
78 gbp_bridge_domain_find (u32 bd_id)
82 p = hash_get (gbp_bridge_domain_db.gbd_by_bd_id, bd_id);
87 return (INDEX_INVALID);
91 gbp_bridge_domain_find_and_lock (u32 bd_id)
95 p = hash_get (gbp_bridge_domain_db.gbd_by_bd_id, bd_id);
99 gbp_bridge_domain_lock (p[0]);
102 return (INDEX_INVALID);
106 gbp_bridge_domain_db_add (gbp_bridge_domain_t * gb)
108 index_t gbi = gb - gbp_bridge_domain_pool;
110 hash_set (gbp_bridge_domain_db.gbd_by_bd_id, gb->gb_bd_id, gbi);
111 vec_validate_init_empty (gbp_bridge_domain_db.gbd_by_bd_index,
112 gb->gb_bd_index, INDEX_INVALID);
113 gbp_bridge_domain_db.gbd_by_bd_index[gb->gb_bd_index] = gbi;
117 gbp_bridge_domain_db_remove (gbp_bridge_domain_t * gb)
119 hash_unset (gbp_bridge_domain_db.gbd_by_bd_id, gb->gb_bd_id);
120 gbp_bridge_domain_db.gbd_by_bd_index[gb->gb_bd_index] = INDEX_INVALID;
124 format_gbp_bridge_domain_flags (u8 * s, va_list * args)
126 gbp_bridge_domain_flags_t gf = va_arg (*args, gbp_bridge_domain_flags_t);
130 if (gf & GBP_BD_FLAG_DO_NOT_LEARN)
131 s = format (s, "do-not-learn ");
132 if (gf & GBP_BD_FLAG_UU_FWD_DROP)
133 s = format (s, "uu-fwd-drop ");
134 if (gf & GBP_BD_FLAG_MCAST_DROP)
135 s = format (s, "mcast-drop ");
136 if (gf & GBP_BD_FLAG_UCAST_ARP)
137 s = format (s, "ucast-arp ");
141 s = format (s, "none");
147 format_gbp_bridge_domain_ptr (u8 * s, va_list * args)
149 gbp_bridge_domain_t *gb = va_arg (*args, gbp_bridge_domain_t *);
150 vnet_main_t *vnm = vnet_get_main ();
155 "[%d] bd:[%d,%d], bvi:%U uu-flood:%U bm-flood:%U flags:%U locks:%d",
156 gb - gbp_bridge_domain_pool, gb->gb_bd_id, gb->gb_bd_index,
157 format_vnet_sw_if_index_name, vnm, gb->gb_bvi_sw_if_index,
158 format_vnet_sw_if_index_name, vnm, gb->gb_uu_fwd_sw_if_index,
159 format_gbp_itf_hdl, gb->gb_bm_flood_itf,
160 format_gbp_bridge_domain_flags, gb->gb_flags, gb->gb_locks);
162 s = format (s, "NULL");
168 format_gbp_bridge_domain (u8 * s, va_list * args)
170 index_t gbi = va_arg (*args, index_t);
173 format (s, "%U", format_gbp_bridge_domain_ptr,
174 gbp_bridge_domain_get (gbi));
180 gbp_bridge_domain_add_and_lock (u32 bd_id,
182 gbp_bridge_domain_flags_t flags,
184 u32 uu_fwd_sw_if_index,
185 u32 bm_flood_sw_if_index)
187 gbp_bridge_domain_t *gb;
190 gbi = gbp_bridge_domain_find (bd_id);
192 if (INDEX_INVALID == gbi)
194 gbp_route_domain_t *gr;
197 bd_index = bd_find_index (&bd_main, bd_id);
200 return (VNET_API_ERROR_BD_NOT_MODIFIABLE);
202 bd_flags_t bd_flags = L2_NONE;
203 if (flags & GBP_BD_FLAG_UU_FWD_DROP)
204 bd_flags |= L2_UU_FLOOD;
205 if (flags & GBP_BD_FLAG_MCAST_DROP)
206 bd_flags |= L2_FLOOD;
208 pool_get (gbp_bridge_domain_pool, gb);
209 memset (gb, 0, sizeof (*gb));
211 gbi = gb - gbp_bridge_domain_pool;
212 gb->gb_bd_id = bd_id;
213 gb->gb_bd_index = bd_index;
214 gb->gb_uu_fwd_sw_if_index = uu_fwd_sw_if_index;
215 gb->gb_bvi_sw_if_index = bvi_sw_if_index;
216 gbp_itf_hdl_reset (&gb->gb_bm_flood_itf);
218 gb->gb_flags = flags;
219 gb->gb_rdi = gbp_route_domain_find_and_lock (rd_id);
222 * set the scope from the BD's RD's scope
224 gr = gbp_route_domain_get (gb->gb_rdi);
225 vec_validate (gbp_scope_by_bd_index, gb->gb_bd_index);
226 gbp_scope_by_bd_index[gb->gb_bd_index] = gr->grd_scope;
229 * Set the BVI and uu-flood interfaces into the BD
231 gbp_bridge_domain_itf_add (gbi, gb->gb_bvi_sw_if_index,
232 L2_BD_PORT_TYPE_BVI);
234 if ((!(flags & GBP_BD_FLAG_UU_FWD_DROP) ||
235 (flags & GBP_BD_FLAG_UCAST_ARP)) &&
236 ~0 != gb->gb_uu_fwd_sw_if_index)
237 gbp_bridge_domain_itf_add (gbi, gb->gb_uu_fwd_sw_if_index,
238 L2_BD_PORT_TYPE_UU_FWD);
240 if (!(flags & GBP_BD_FLAG_MCAST_DROP) && ~0 != bm_flood_sw_if_index)
242 gb->gb_bm_flood_itf =
243 gbp_itf_l2_add_and_lock (bm_flood_sw_if_index, gbi);
244 gbp_itf_l2_set_input_feature (gb->gb_bm_flood_itf,
245 L2INPUT_FEAT_GBP_LEARN);
249 * unset any flag(s) set above
251 bd_set_flags (vlib_get_main (), bd_index, bd_flags, 0);
253 if (flags & GBP_BD_FLAG_UCAST_ARP)
255 bd_flags = L2_ARP_UFWD;
256 bd_set_flags (vlib_get_main (), bd_index, bd_flags, 1);
260 * Add the BVI's MAC to the L2FIB
262 l2fib_add_entry (vnet_sw_interface_get_hw_address
263 (vnet_get_main (), gb->gb_bvi_sw_if_index),
264 gb->gb_bd_index, gb->gb_bvi_sw_if_index,
265 (L2FIB_ENTRY_RESULT_FLAG_STATIC |
266 L2FIB_ENTRY_RESULT_FLAG_BVI));
268 gbp_bridge_domain_db_add (gb);
272 gb = gbp_bridge_domain_get (gbi);
276 GBP_BD_DBG ("add: %U", format_gbp_bridge_domain_ptr, gb);
282 gbp_bridge_domain_itf_add (index_t gbdi,
283 u32 sw_if_index, l2_bd_port_type_t type)
285 gbp_bridge_domain_t *gb;
287 gb = gbp_bridge_domain_get (gbdi);
289 set_int_l2_mode (vlib_get_main (), vnet_get_main (), MODE_L2_BRIDGE,
290 sw_if_index, gb->gb_bd_index, type, 0, 0);
292 * adding an interface to the bridge enables learning on the
293 * interface. Disable learning on the interface by default for gbp
296 l2input_intf_bitmap_enable (sw_if_index, L2INPUT_FEAT_LEARN, 0);
300 gbp_bridge_domain_itf_del (index_t gbdi,
301 u32 sw_if_index, l2_bd_port_type_t type)
303 gbp_bridge_domain_t *gb;
305 gb = gbp_bridge_domain_get (gbdi);
307 set_int_l2_mode (vlib_get_main (), vnet_get_main (), MODE_L3, sw_if_index,
308 gb->gb_bd_index, type, 0, 0);
312 gbp_bridge_domain_unlock (index_t gbdi)
314 gbp_bridge_domain_t *gb;
316 gb = gbp_bridge_domain_get (gbdi);
320 if (0 == gb->gb_locks)
322 GBP_BD_DBG ("destroy: %U", format_gbp_bridge_domain_ptr, gb);
324 l2fib_del_entry (vnet_sw_interface_get_hw_address
325 (vnet_get_main (), gb->gb_bvi_sw_if_index),
326 gb->gb_bd_index, gb->gb_bvi_sw_if_index);
328 gbp_bridge_domain_itf_del (gbdi, gb->gb_bvi_sw_if_index,
329 L2_BD_PORT_TYPE_BVI);
330 if (~0 != gb->gb_uu_fwd_sw_if_index)
331 gbp_bridge_domain_itf_del (gbdi, gb->gb_uu_fwd_sw_if_index,
332 L2_BD_PORT_TYPE_UU_FWD);
333 gbp_itf_unlock (&gb->gb_bm_flood_itf);
335 gbp_bridge_domain_db_remove (gb);
336 gbp_route_domain_unlock (gb->gb_rdi);
338 pool_put (gbp_bridge_domain_pool, gb);
343 gbp_bridge_domain_delete (u32 bd_id)
347 GBP_BD_DBG ("del: %d", bd_id);
348 gbi = gbp_bridge_domain_find (bd_id);
350 if (INDEX_INVALID != gbi)
352 GBP_BD_DBG ("del: %U", format_gbp_bridge_domain, gbi);
353 gbp_bridge_domain_unlock (gbi);
358 return (VNET_API_ERROR_NO_SUCH_ENTRY);
362 gbp_bridge_domain_walk (gbp_bridge_domain_cb_t cb, void *ctx)
364 gbp_bridge_domain_t *gbpe;
367 pool_foreach (gbpe, gbp_bridge_domain_pool)
375 static clib_error_t *
376 gbp_bridge_domain_cli (vlib_main_t * vm,
377 unformat_input_t * input, vlib_cli_command_t * cmd)
379 vnet_main_t *vnm = vnet_get_main ();
380 gbp_bridge_domain_flags_t flags;
381 u32 bm_flood_sw_if_index = ~0;
382 u32 uu_fwd_sw_if_index = ~0;
383 u32 bd_id = ~0, rd_id = ~0;
384 u32 bvi_sw_if_index = ~0;
387 flags = GBP_BD_FLAG_NONE;
389 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
391 if (unformat (input, "bvi %U", unformat_vnet_sw_interface,
392 vnm, &bvi_sw_if_index))
394 else if (unformat (input, "uu-fwd %U", unformat_vnet_sw_interface,
395 vnm, &uu_fwd_sw_if_index))
397 else if (unformat (input, "bm-flood %U", unformat_vnet_sw_interface,
398 vnm, &bm_flood_sw_if_index))
400 else if (unformat (input, "add"))
402 else if (unformat (input, "del"))
404 else if (unformat (input, "flags %d", &flags))
406 else if (unformat (input, "bd %d", &bd_id))
408 else if (unformat (input, "rd %d", &rd_id))
415 return clib_error_return (0, "BD-ID must be specified");
417 return clib_error_return (0, "RD-ID must be specified");
421 if (~0 == bvi_sw_if_index)
422 return clib_error_return (0, "interface must be specified");
424 gbp_bridge_domain_add_and_lock (bd_id, rd_id,
428 bm_flood_sw_if_index);
431 gbp_bridge_domain_delete (bd_id);
437 * Configure a GBP bridge-domain
440 * @cliexstart{gbp bridge-domain [del] bd <ID> bvi <interface> [uu-fwd <interface>] [bm-flood <interface>] [flags <flags>]}
444 VLIB_CLI_COMMAND (gbp_bridge_domain_cli_node, static) = {
445 .path = "gbp bridge-domain",
446 .short_help = "gbp bridge-domain [del] bd <ID> bvi <interface> [uu-fwd <interface>] [bm-flood <interface>] [flags <flags>]",
447 .function = gbp_bridge_domain_cli,
451 gbp_bridge_domain_show_one (gbp_bridge_domain_t *gb, void *ctx)
456 vlib_cli_output (vm, " %U", format_gbp_bridge_domain_ptr, gb);
461 static clib_error_t *
462 gbp_bridge_domain_show (vlib_main_t * vm,
463 unformat_input_t * input, vlib_cli_command_t * cmd)
465 vlib_cli_output (vm, "Bridge-Domains:");
466 gbp_bridge_domain_walk (gbp_bridge_domain_show_one, vm);
473 * Show Group Based Policy Bridge_Domains and derived information
476 * @cliexstart{show gbp bridge_domain}
480 VLIB_CLI_COMMAND (gbp_bridge_domain_show_node, static) = {
481 .path = "show gbp bridge-domain",
482 .short_help = "show gbp bridge-domain\n",
483 .function = gbp_bridge_domain_show,
487 static clib_error_t *
488 gbp_bridge_domain_init (vlib_main_t * vm)
490 gb_logger = vlib_log_register_class ("gbp", "bd");
495 VLIB_INIT_FUNCTION (gbp_bridge_domain_init);
498 * fd.io coding-style-patch-verification: ON
501 * eval: (c-set-style "gnu")