2 * gbp.h : Group Based Policy
4 * Copyright (c) 2018 Cisco and/or its affiliates.
5 * Licensed under the Apache License, Version 2.0 (the "License");
6 * you may not use this file except in compliance with the License.
7 * You may obtain a copy of the License at:
9 * http://www.apache.org/licenses/LICENSE-2.0
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
18 #include <plugins/gbp/gbp_endpoint.h>
19 #include <plugins/gbp/gbp_endpoint_group.h>
21 #include <vnet/ethernet/arp_packet.h>
24 * IP4 destintion address to destination EPG mapping table
26 typedef struct gbp_ip4_to_epg_db_t_
29 * use a simple hash table
32 } gbp_ip4_to_epg_db_t;
34 static gbp_ip4_to_epg_db_t gbp_ip4_to_epg_db;
37 * IP6 destintion address to destination EPG mapping table
39 typedef struct gbp_ip6_to_epg_db_t_
42 * use a memroy hash table
45 } gbp_ip6_to_epg_db_t;
47 static gbp_ip6_to_epg_db_t gbp_ip6_to_epg_db;
50 const static gbp_itf_t ITF_INVALID = {
51 .gi_epg = EPG_INVALID,
55 gbp_itf_to_epg_db_t gbp_itf_to_epg_db;
58 * Pool of GBP endpoints
60 static gbp_endpoint_t *gbp_endpoint_pool;
65 static uword *gbp_endpoint_db;
68 gbp_ip_epg_update (const ip46_address_t * ip, epg_id_t epg_id)
71 * we are dealing only with addresses here so this limited
74 if (ip46_address_is_ip4 (ip))
76 hash_set (gbp_ip4_to_epg_db.g4ie_hash, ip->ip4.as_u32, epg_id);
80 hash_set_mem (gbp_ip6_to_epg_db.g6ie_hash, &ip->ip6, epg_id);
85 gbp_ip_epg_delete (const ip46_address_t * ip)
87 if (ip46_address_is_ip4 (ip))
89 hash_unset (gbp_ip4_to_epg_db.g4ie_hash, ip->ip4.as_u32);
93 hash_unset_mem (gbp_ip6_to_epg_db.g6ie_hash, &ip->ip6);
98 gbp_itf_epg_update (u32 sw_if_index, epg_id_t src_epg, u8 do_policy)
100 vec_validate_init_empty (gbp_itf_to_epg_db.gte_vec,
101 sw_if_index, ITF_INVALID);
103 if (0 == gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_ref_count)
105 l2input_intf_bitmap_enable (sw_if_index, L2INPUT_FEAT_GBP_SRC_CLASSIFY,
107 l2input_intf_bitmap_enable (sw_if_index, L2INPUT_FEAT_GBP_FWD, 1);
109 l2output_intf_bitmap_enable (sw_if_index, L2OUTPUT_FEAT_GBP_POLICY,
112 gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_epg = src_epg;
113 gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_ref_count++;
117 gbp_itf_epg_delete (u32 sw_if_index)
119 if (vec_len (gbp_itf_to_epg_db.gte_vec) <= sw_if_index)
122 if (1 == gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_ref_count)
124 gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_epg = EPG_INVALID;
126 l2input_intf_bitmap_enable (sw_if_index, L2INPUT_FEAT_GBP_SRC_CLASSIFY,
128 l2input_intf_bitmap_enable (sw_if_index, L2INPUT_FEAT_GBP_FWD, 0);
129 l2output_intf_bitmap_enable (sw_if_index, L2OUTPUT_FEAT_GBP_POLICY, 0);
131 gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_ref_count--;
135 gbp_endpoint_update (u32 sw_if_index,
136 const ip46_address_t * ip, epg_id_t epg_id)
138 gbp_endpoint_key_t key = {
140 .gek_sw_if_index = sw_if_index,
142 gbp_endpoint_group_t *gepg;
143 gbp_endpoint_t *gbpe;
146 gepg = gbp_endpoint_group_find (epg_id);
149 return (VNET_API_ERROR_NO_SUCH_ENTRY);
151 p = hash_get_mem (gbp_endpoint_db, &key);
155 gbpe = pool_elt_at_index (gbp_endpoint_pool, p[0]);
159 pool_get (gbp_endpoint_pool, gbpe);
161 gbpe->ge_key = clib_mem_alloc (sizeof (gbp_endpoint_key_t));
162 clib_memcpy (gbpe->ge_key, &key, sizeof (gbp_endpoint_key_t));
164 hash_set_mem (gbp_endpoint_db, gbpe->ge_key, gbpe - gbp_endpoint_pool);
167 gbpe->ge_epg_id = epg_id;
169 gbp_itf_epg_update (gbpe->ge_key->gek_sw_if_index, gbpe->ge_epg_id, 1);
171 if (!ip46_address_is_zero (&gbpe->ge_key->gek_ip))
172 gbp_ip_epg_update (&gbpe->ge_key->gek_ip, gbpe->ge_epg_id);
175 * send a gratuitous ARP on the EPG's uplink. this is done so that if
176 * this EP has moved from some other place in the 'fabric', upstream
177 * devices are informed
179 if (ip46_address_is_ip4 (&gbpe->ge_key->gek_ip))
180 send_ip4_garp_w_addr (vlib_get_main (),
181 &gbpe->ge_key->gek_ip.ip4,
182 vnet_get_sup_hw_interface
183 (vnet_get_main (), gepg->gepg_uplink_sw_if_index));
185 send_ip6_na_w_addr (vlib_get_main (),
186 &gbpe->ge_key->gek_ip.ip6,
187 vnet_get_sup_hw_interface
188 (vnet_get_main (), gepg->gepg_uplink_sw_if_index));
194 gbp_endpoint_delete (u32 sw_if_index, const ip46_address_t * ip)
196 gbp_endpoint_key_t key = {
198 .gek_sw_if_index = sw_if_index,
200 gbp_endpoint_t *gbpe;
203 p = hash_get_mem (gbp_endpoint_db, &key);
207 gbpe = pool_elt_at_index (gbp_endpoint_pool, p[0]);
209 hash_unset_mem (gbp_endpoint_db, gbpe->ge_key);
211 gbp_itf_epg_delete (gbpe->ge_key->gek_sw_if_index);
212 if (!ip46_address_is_zero (&gbpe->ge_key->gek_ip))
213 gbp_ip_epg_delete (&gbpe->ge_key->gek_ip);
215 clib_mem_free (gbpe->ge_key);
217 pool_put (gbp_endpoint_pool, gbpe);
222 gbp_endpoint_walk (gbp_endpoint_cb_t cb, void *ctx)
224 gbp_endpoint_t *gbpe;
227 pool_foreach(gbpe, gbp_endpoint_pool,
235 static clib_error_t *
236 gbp_endpoint_cli (vlib_main_t * vm,
237 unformat_input_t * input, vlib_cli_command_t * cmd)
239 vnet_main_t *vnm = vnet_get_main ();
240 epg_id_t epg_id = EPG_INVALID;
241 ip46_address_t ip = { };
242 u32 sw_if_index = ~0;
245 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
247 if (unformat (input, "%U", unformat_vnet_sw_interface,
250 else if (unformat (input, "add"))
252 else if (unformat (input, "del"))
254 else if (unformat (input, "epg %d", &epg_id))
256 else if (unformat (input, "ip %U", unformat_ip4_address, &ip.ip4))
258 else if (unformat (input, "ip %U", unformat_ip6_address, &ip.ip6))
264 if (~0 == sw_if_index)
265 return clib_error_return (0, "interface must be specified");
266 if (EPG_INVALID == epg_id)
267 return clib_error_return (0, "EPG-ID must be specified");
268 if (ip46_address_is_zero (&ip))
269 return clib_error_return (0, "IP address must be specified");
272 gbp_endpoint_update (sw_if_index, &ip, epg_id);
274 gbp_endpoint_delete (sw_if_index, &ip);
281 * Configure a GBP Endpoint
284 * @cliexstart{set gbp endpoint [del] <interface> epg <ID> ip <IP>}
288 VLIB_CLI_COMMAND (gbp_endpoint_cli_node, static) = {
289 .path = "gbp endpoint",
290 .short_help = "gbp endpoint [del] <interface> epg <ID> ip <IP>",
291 .function = gbp_endpoint_cli,
296 gbp_endpoint_show_one (gbp_endpoint_t * gbpe, void *ctx)
298 vnet_main_t *vnm = vnet_get_main ();
302 vlib_cli_output (vm, " {%U, %U} -> %d",
303 format_vnet_sw_if_index_name, vnm,
304 gbpe->ge_key->gek_sw_if_index,
305 format_ip46_address, &gbpe->ge_key->gek_ip, IP46_TYPE_ANY,
311 static clib_error_t *
312 gbp_endpoint_show (vlib_main_t * vm,
313 unformat_input_t * input, vlib_cli_command_t * cmd)
315 vnet_main_t *vnm = vnet_get_main ();
316 ip46_address_t ip, *ipp;
320 vlib_cli_output (vm, "Endpoints:");
321 gbp_endpoint_walk (gbp_endpoint_show_one, vm);
323 vlib_cli_output (vm, "\nSource interface to EPG:");
325 vec_foreach_index (sw_if_index, gbp_itf_to_epg_db.gte_vec)
327 if (EPG_INVALID != gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_epg)
329 vlib_cli_output (vm, " %U -> %d",
330 format_vnet_sw_if_index_name, vnm, sw_if_index,
331 gbp_itf_to_epg_db.gte_vec[sw_if_index].gi_epg);
335 vlib_cli_output (vm, "\nDestination IP4 to EPG:");
338 hash_foreach (ip.ip4.as_u32, epg_id, gbp_ip4_to_epg_db.g4ie_hash,
340 vlib_cli_output (vm, " %U -> %d", format_ip46_address, &ip,
341 IP46_TYPE_IP4, epg_id);
345 vlib_cli_output (vm, "\nDestination IP6 to EPG:");
348 hash_foreach_mem (ipp, epg_id, gbp_ip6_to_epg_db.g6ie_hash,
350 vlib_cli_output (vm, " %U -> %d", format_ip46_address, ipp,
351 IP46_TYPE_IP6, epg_id);
360 * Show Group Based Policy Endpoints and derived information
363 * @cliexstart{show gbp endpoint}
367 VLIB_CLI_COMMAND (gbp_endpoint_show_node, static) = {
368 .path = "show gbp endpoint",
369 .short_help = "show gbp endpoint\n",
370 .function = gbp_endpoint_show,
374 static clib_error_t *
375 gbp_endpoint_init (vlib_main_t * vm)
377 gbp_endpoint_db = hash_create_mem (0,
378 sizeof (gbp_endpoint_key_t),
380 gbp_ip6_to_epg_db.g6ie_hash =
381 hash_create_mem (0, sizeof (ip6_address_t), sizeof (u32));
385 VLIB_INIT_FUNCTION (gbp_endpoint_init);
388 * fd.io coding-style-patch-verification: ON
391 * eval: (c-set-style "gnu")