2 * Copyright (c) 2018 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #include <plugins/gbp/gbp_vxlan.h>
17 #include <plugins/gbp/gbp_itf.h>
18 #include <plugins/gbp/gbp_learn.h>
19 #include <plugins/gbp/gbp_bridge_domain.h>
20 #include <plugins/gbp/gbp_route_domain.h>
22 #include <vnet/vxlan-gbp/vxlan_gbp.h>
23 #include <vlibmemory/api.h>
24 #include <vnet/fib/fib_table.h>
25 #include <vlib/punt.h>
28 * A reference to a VXLAN-GBP tunnel created as a child/dependent tunnel
29 * of the tempplate GBP-VXLAN tunnel
31 typedef struct vxlan_tunnel_ref_t_
37 gbp_vxlan_tunnel_layer_t vxr_layer;
48 vlib_log_class_t gt_logger;
51 * Pool of template tunnels
53 gbp_vxlan_tunnel_t *gbp_vxlan_tunnel_pool;
56 * Pool of child tunnels
58 vxlan_tunnel_ref_t *vxlan_tunnel_ref_pool;
61 * DB of template interfaces by SW interface index
63 index_t *gbp_vxlan_tunnel_db;
66 * DB of child interfaces by SW interface index
68 index_t *vxlan_tunnel_ref_db;
71 * handle registered with the ;unt infra
73 static vlib_punt_hdl_t punt_hdl;
75 static char *gbp_vxlan_tunnel_layer_strings[] = {
76 #define _(n,s) [GBP_VXLAN_TUN_##n] = s,
77 forecah_gbp_vxlan_tunnel_layer
81 #define GBP_VXLAN_TUN_DBG(...) \
82 vlib_log_debug (gt_logger, __VA_ARGS__);
87 gbp_vxlan_tunnel_get (index_t gti)
89 return (pool_elt_at_index (gbp_vxlan_tunnel_pool, gti));
92 static vxlan_tunnel_ref_t *
93 vxlan_tunnel_ref_get (index_t vxri)
95 return (pool_elt_at_index (vxlan_tunnel_ref_pool, vxri));
99 format_vxlan_tunnel_ref (u8 * s, va_list * args)
101 index_t vxri = va_arg (*args, u32);
102 vxlan_tunnel_ref_t *vxr;
104 vxr = vxlan_tunnel_ref_get (vxri);
106 s = format (s, "[%U locks:%d]", format_vnet_sw_if_index_name,
107 vnet_get_main (), vxr->vxr_sw_if_index, vxr->vxr_locks);
113 gdb_vxlan_dep_add (gbp_vxlan_tunnel_t * gt,
114 const ip46_address_t * src, const ip46_address_t * dst)
116 vnet_vxlan_gbp_tunnel_add_del_args_t args = {
118 .is_ip6 = !ip46_address_is_ip4 (src),
123 .mode = (GBP_VXLAN_TUN_L2 == gt->gt_layer ?
124 VXLAN_GBP_TUNNEL_MODE_L2 : VXLAN_GBP_TUNNEL_MODE_L3),
126 vxlan_tunnel_ref_t *vxr;
132 rv = vnet_vxlan_gbp_tunnel_add_del (&args, &sw_if_index);
134 if (VNET_API_ERROR_TUNNEL_EXIST == rv)
136 vxri = vxlan_tunnel_ref_db[sw_if_index];
138 vxr = vxlan_tunnel_ref_get (vxri);
143 ASSERT (~0 != sw_if_index);
144 GBP_VXLAN_TUN_DBG ("add-dep:%U %U %U %d", format_vnet_sw_if_index_name,
145 vnet_get_main (), sw_if_index,
146 format_ip46_address, src, IP46_TYPE_ANY,
147 format_ip46_address, dst, IP46_TYPE_ANY, gt->gt_vni);
149 pool_get_zero (vxlan_tunnel_ref_pool, vxr);
151 vxri = (vxr - vxlan_tunnel_ref_pool);
152 vxr->vxr_parent = gt - gbp_vxlan_tunnel_pool;
153 vxr->vxr_sw_if_index = sw_if_index;
155 vxr->vxr_layer = gt->gt_layer;
158 * store the child both on the parent's list and the global DB
160 vec_add1 (gt->gt_tuns, vxri);
162 vec_validate_init_empty (vxlan_tunnel_ref_db,
163 vxr->vxr_sw_if_index, INDEX_INVALID);
164 vxlan_tunnel_ref_db[vxr->vxr_sw_if_index] = vxri;
166 if (GBP_VXLAN_TUN_L2 == vxr->vxr_layer)
168 l2output_feat_masks_t ofeat;
169 l2input_feat_masks_t ifeat;
170 gbp_bridge_domain_t *gbd;
172 gbd = gbp_bridge_domain_get (gt->gt_gbd);
173 vxr->vxr_itf = gbp_itf_add_and_lock (vxr->vxr_sw_if_index,
176 ofeat = L2OUTPUT_FEAT_GBP_POLICY_MAC;
177 ifeat = L2INPUT_FEAT_NONE;
179 if (!(gbd->gb_flags & GBP_BD_FLAG_DO_NOT_LEARN))
180 ifeat |= L2INPUT_FEAT_GBP_LEARN;
182 gbp_itf_set_l2_output_feature (vxr->vxr_itf,
183 vxr->vxr_sw_if_index, ofeat);
184 gbp_itf_set_l2_input_feature (vxr->vxr_itf,
185 vxr->vxr_sw_if_index, ifeat);
189 const gbp_route_domain_t *grd;
190 fib_protocol_t fproto;
192 grd = gbp_route_domain_get (gt->gt_grd);
194 FOR_EACH_FIB_IP_PROTOCOL (fproto)
195 ip_table_bind (fproto, vxr->vxr_sw_if_index,
196 grd->grd_table_id[fproto], 1);
198 gbp_learn_enable (vxr->vxr_sw_if_index, GBP_LEARN_MODE_L3);
202 return (sw_if_index);
206 vxlan_gbp_tunnel_get_parent (u32 sw_if_index)
208 ASSERT ((sw_if_index < vec_len (vxlan_tunnel_ref_db)) &&
209 (INDEX_INVALID != vxlan_tunnel_ref_db[sw_if_index]));
211 gbp_vxlan_tunnel_t *gt;
212 vxlan_tunnel_ref_t *vxr;
214 vxr = vxlan_tunnel_ref_get (vxlan_tunnel_ref_db[sw_if_index]);
215 gt = gbp_vxlan_tunnel_get (vxr->vxr_parent);
217 return (gt->gt_sw_if_index);
220 gbp_vxlan_tunnel_type_t
221 gbp_vxlan_tunnel_get_type (u32 sw_if_index)
223 if (sw_if_index < vec_len (vxlan_tunnel_ref_db) &&
224 INDEX_INVALID != vxlan_tunnel_ref_db[sw_if_index])
226 return (VXLAN_GBP_TUNNEL);
228 else if (sw_if_index < vec_len (gbp_vxlan_tunnel_db) &&
229 INDEX_INVALID != gbp_vxlan_tunnel_db[sw_if_index])
231 return (GBP_VXLAN_TEMPLATE_TUNNEL);
235 return (GBP_VXLAN_TEMPLATE_TUNNEL);
239 gbp_vxlan_tunnel_clone_and_lock (u32 sw_if_index,
240 const ip46_address_t * src,
241 const ip46_address_t * dst)
243 gbp_vxlan_tunnel_t *gt;
246 gti = gbp_vxlan_tunnel_db[sw_if_index];
248 if (INDEX_INVALID == gti)
251 gt = pool_elt_at_index (gbp_vxlan_tunnel_pool, gti);
253 return (gdb_vxlan_dep_add (gt, src, dst));
257 gdb_vxlan_dep_del (index_t vxri)
259 vxlan_tunnel_ref_t *vxr;
260 gbp_vxlan_tunnel_t *gt;
263 vxr = vxlan_tunnel_ref_get (vxri);
264 gt = gbp_vxlan_tunnel_get (vxr->vxr_parent);
266 GBP_VXLAN_TUN_DBG ("del-dep:%U", format_vxlan_tunnel_ref, vxri);
268 vxlan_tunnel_ref_db[vxr->vxr_sw_if_index] = INDEX_INVALID;
269 pos = vec_search (gt->gt_tuns, vxri);
272 vec_del1 (gt->gt_tuns, pos);
274 if (GBP_VXLAN_TUN_L2 == vxr->vxr_layer)
276 gbp_itf_set_l2_output_feature (vxr->vxr_itf, vxr->vxr_sw_if_index,
278 gbp_itf_set_l2_input_feature (vxr->vxr_itf, vxr->vxr_sw_if_index,
280 gbp_itf_unlock (vxr->vxr_itf);
284 fib_protocol_t fproto;
286 FOR_EACH_FIB_IP_PROTOCOL (fproto)
287 ip_table_bind (fproto, vxr->vxr_sw_if_index, 0, 0);
288 gbp_learn_disable (vxr->vxr_sw_if_index, GBP_LEARN_MODE_L3);
291 vnet_vxlan_gbp_tunnel_del (vxr->vxr_sw_if_index);
293 pool_put (vxlan_tunnel_ref_pool, vxr);
297 vxlan_gbp_tunnel_unlock (u32 sw_if_index)
299 vxlan_tunnel_ref_t *vxr;
302 vxri = vxlan_tunnel_ref_db[sw_if_index];
304 ASSERT (vxri != INDEX_INVALID);
306 vxr = vxlan_tunnel_ref_get (vxri);
309 if (0 == vxr->vxr_locks)
311 gdb_vxlan_dep_del (vxri);
316 vxlan_gbp_tunnel_lock (u32 sw_if_index)
318 vxlan_tunnel_ref_t *vxr;
321 vxri = vxlan_tunnel_ref_db[sw_if_index];
323 ASSERT (vxri != INDEX_INVALID);
325 vxr = vxlan_tunnel_ref_get (vxri);
330 gbp_vxlan_walk (gbp_vxlan_cb_t cb, void *ctx)
332 gbp_vxlan_tunnel_t *gt;
335 pool_foreach (gt, gbp_vxlan_tunnel_pool,
337 if (WALK_CONTINUE != cb(gt, ctx))
344 gbp_vxlan_tunnel_show_one (gbp_vxlan_tunnel_t * gt, void *ctx)
346 vlib_cli_output (ctx, "%U", format_gbp_vxlan_tunnel,
347 gt - gbp_vxlan_tunnel_pool);
349 return (WALK_CONTINUE);
353 format_gbp_vxlan_tunnel_name (u8 * s, va_list * args)
355 u32 dev_instance = va_arg (*args, u32);
357 return format (s, "gbp-vxlan-%d", dev_instance);
361 format_gbp_vxlan_tunnel_layer (u8 * s, va_list * args)
363 gbp_vxlan_tunnel_layer_t gl = va_arg (*args, gbp_vxlan_tunnel_layer_t);
364 s = format (s, "%s", gbp_vxlan_tunnel_layer_strings[gl]);
370 format_gbp_vxlan_tunnel (u8 * s, va_list * args)
372 u32 dev_instance = va_arg (*args, u32);
373 CLIB_UNUSED (int verbose) = va_arg (*args, int);
374 gbp_vxlan_tunnel_t *gt = gbp_vxlan_tunnel_get (dev_instance);
377 s = format (s, "GBP VXLAN tunnel: hw:%d sw:%d vni:%d %U",
378 gt->gt_hw_if_index, gt->gt_sw_if_index, gt->gt_vni,
379 format_gbp_vxlan_tunnel_layer, gt->gt_layer);
380 if (GBP_VXLAN_TUN_L2 == gt->gt_layer)
381 s = format (s, " BD:%d bd-index:%d", gt->gt_bd_rd_id, gt->gt_bd_index);
383 s = format (s, " RD:%d fib-index:[%d,%d]",
385 gt->gt_fib_index[FIB_PROTOCOL_IP4],
386 gt->gt_fib_index[FIB_PROTOCOL_IP6]);
388 s = format (s, " children:[");
389 vec_foreach (vxri, gt->gt_tuns)
391 s = format (s, "%U, ", format_vxlan_tunnel_ref, *vxri);
398 typedef struct gbp_vxlan_tx_trace_t_
401 } gbp_vxlan_tx_trace_t;
404 format_gbp_vxlan_tx_trace (u8 * s, va_list * args)
406 CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
407 CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
408 gbp_vxlan_tx_trace_t *t = va_arg (*args, gbp_vxlan_tx_trace_t *);
410 s = format (s, "GBP-VXLAN: vni:%d", t->vni);
416 gbp_vxlan_interface_admin_up_down (vnet_main_t * vnm,
417 u32 hw_if_index, u32 flags)
419 vnet_hw_interface_t *hi;
422 hi = vnet_get_hw_interface (vnm, hw_if_index);
424 if (NULL == gbp_vxlan_tunnel_db ||
425 hi->sw_if_index >= vec_len (gbp_vxlan_tunnel_db))
428 ti = gbp_vxlan_tunnel_db[hi->sw_if_index];
431 /* not one of ours */
434 if (flags & VNET_SW_INTERFACE_FLAG_ADMIN_UP)
435 vnet_hw_interface_set_flags (vnm, hw_if_index,
436 VNET_HW_INTERFACE_FLAG_LINK_UP);
438 vnet_hw_interface_set_flags (vnm, hw_if_index, 0);
444 gbp_vxlan_interface_tx (vlib_main_t * vm,
445 vlib_node_runtime_t * node, vlib_frame_t * frame)
447 clib_warning ("you shouldn't be here, leaking buffers...");
448 return frame->n_vectors;
452 VNET_DEVICE_CLASS (gbp_vxlan_device_class) = {
453 .name = "GBP VXLAN tunnel-template",
454 .format_device_name = format_gbp_vxlan_tunnel_name,
455 .format_device = format_gbp_vxlan_tunnel,
456 .format_tx_trace = format_gbp_vxlan_tx_trace,
457 .admin_up_down_function = gbp_vxlan_interface_admin_up_down,
458 .tx_function = gbp_vxlan_interface_tx,
461 VNET_HW_INTERFACE_CLASS (gbp_vxlan_hw_interface_class) = {
463 .flags = VNET_HW_INTERFACE_CLASS_FLAG_P2P,
468 gbp_vxlan_tunnel_add (u32 vni, gbp_vxlan_tunnel_layer_t layer,
470 const ip4_address_t * src, u32 * sw_if_indexp)
472 gbp_vxlan_tunnel_t *gt;
478 p = hash_get (gv_db, vni);
480 GBP_VXLAN_TUN_DBG ("add: %d %d %d", vni, layer, bd_rd_id);
484 vnet_sw_interface_t *si;
485 vnet_hw_interface_t *hi;
489 gbi = grdi = INDEX_INVALID;
491 if (layer == GBP_VXLAN_TUN_L2)
493 gbi = gbp_bridge_domain_find_and_lock (bd_rd_id);
495 if (INDEX_INVALID == gbi)
497 return (VNET_API_ERROR_BD_NOT_MODIFIABLE);
502 grdi = gbp_route_domain_find_and_lock (bd_rd_id);
504 if (INDEX_INVALID == grdi)
506 return (VNET_API_ERROR_NO_SUCH_FIB);
510 vnm = vnet_get_main ();
511 pool_get (gbp_vxlan_tunnel_pool, gt);
512 gti = gt - gbp_vxlan_tunnel_pool;
515 gt->gt_layer = layer;
516 gt->gt_bd_rd_id = bd_rd_id;
517 gt->gt_src.ip4.as_u32 = src->as_u32;
518 gt->gt_hw_if_index = vnet_register_interface (vnm,
519 gbp_vxlan_device_class.index,
521 gbp_vxlan_hw_interface_class.index,
524 hi = vnet_get_hw_interface (vnm, gt->gt_hw_if_index);
526 gt->gt_sw_if_index = hi->sw_if_index;
528 /* don't flood packets in a BD to these interfaces */
529 si = vnet_get_sw_interface (vnm, gt->gt_sw_if_index);
530 si->flood_class = VNET_FLOOD_CLASS_NO_FLOOD;
532 if (layer == GBP_VXLAN_TUN_L2)
534 gbp_bridge_domain_t *gb;
536 gb = gbp_bridge_domain_get (gbi);
539 gt->gt_bd_index = gb->gb_bd_index;
541 /* set it up as a GBP interface */
542 gt->gt_itf = gbp_itf_add_and_lock (gt->gt_sw_if_index,
544 gbp_learn_enable (gt->gt_sw_if_index, GBP_LEARN_MODE_L2);
548 gbp_route_domain_t *grd;
549 fib_protocol_t fproto;
551 grd = gbp_route_domain_get (grdi);
554 grd->grd_vni_sw_if_index = gt->gt_sw_if_index;
556 gbp_learn_enable (gt->gt_sw_if_index, GBP_LEARN_MODE_L3);
558 ip4_sw_interface_enable_disable (gt->gt_sw_if_index, 1);
559 ip6_sw_interface_enable_disable (gt->gt_sw_if_index, 1);
561 FOR_EACH_FIB_IP_PROTOCOL (fproto)
563 gt->gt_fib_index[fproto] = grd->grd_fib_index[fproto];
565 ip_table_bind (fproto, gt->gt_sw_if_index,
566 grd->grd_table_id[fproto], 1);
571 * save the tunnel by VNI and by sw_if_index
573 hash_set (gv_db, vni, gti);
575 vec_validate_init_empty (gbp_vxlan_tunnel_db,
576 gt->gt_sw_if_index, INDEX_INVALID);
577 gbp_vxlan_tunnel_db[gt->gt_sw_if_index] = gti;
580 *sw_if_indexp = gt->gt_sw_if_index;
582 vxlan_gbp_register_udp_ports ();
587 rv = VNET_API_ERROR_IF_ALREADY_EXISTS;
590 GBP_VXLAN_TUN_DBG ("add: %U", format_gbp_vxlan_tunnel, gti);
596 gbp_vxlan_tunnel_del (u32 vni)
598 gbp_vxlan_tunnel_t *gt;
601 p = hash_get (gv_db, vni);
607 vnm = vnet_get_main ();
608 gt = gbp_vxlan_tunnel_get (p[0]);
610 vxlan_gbp_unregister_udp_ports ();
612 GBP_VXLAN_TUN_DBG ("del: %U", format_gbp_vxlan_tunnel,
613 gt - gbp_vxlan_tunnel_pool);
615 gbp_endpoint_flush (GBP_ENDPOINT_SRC_DP, gt->gt_sw_if_index);
616 ASSERT (0 == vec_len (gt->gt_tuns));
617 vec_free (gt->gt_tuns);
619 if (GBP_VXLAN_TUN_L2 == gt->gt_layer)
621 gbp_learn_disable (gt->gt_sw_if_index, GBP_LEARN_MODE_L2);
622 gbp_itf_unlock (gt->gt_itf);
623 gbp_bridge_domain_unlock (gt->gt_gbd);
627 fib_protocol_t fproto;
629 FOR_EACH_FIB_IP_PROTOCOL (fproto)
630 ip_table_bind (fproto, gt->gt_sw_if_index, 0, 0);
632 ip4_sw_interface_enable_disable (gt->gt_sw_if_index, 0);
633 ip6_sw_interface_enable_disable (gt->gt_sw_if_index, 0);
635 gbp_learn_disable (gt->gt_sw_if_index, GBP_LEARN_MODE_L3);
636 gbp_route_domain_unlock (gt->gt_grd);
639 vnet_sw_interface_set_flags (vnm, gt->gt_sw_if_index, 0);
640 vnet_delete_hw_interface (vnm, gt->gt_hw_if_index);
642 hash_unset (gv_db, vni);
643 gbp_vxlan_tunnel_db[gt->gt_sw_if_index] = INDEX_INVALID;
645 pool_put (gbp_vxlan_tunnel_pool, gt);
648 return VNET_API_ERROR_NO_SUCH_ENTRY;
653 static clib_error_t *
654 gbp_vxlan_show (vlib_main_t * vm,
655 unformat_input_t * input, vlib_cli_command_t * cmd)
657 gbp_vxlan_walk (gbp_vxlan_tunnel_show_one, vm);
663 * Show Group Based Policy VXLAN tunnels
666 * @cliexstart{show gbp vxlan}
670 VLIB_CLI_COMMAND (gbp_vxlan_show_node, static) = {
671 .path = "show gbp vxlan",
672 .short_help = "show gbp vxlan\n",
673 .function = gbp_vxlan_show,
677 static clib_error_t *
678 gbp_vxlan_init (vlib_main_t * vm)
680 vxlan_gbp_main_t *vxm = &vxlan_gbp_main;
682 gt_logger = vlib_log_register_class ("gbp", "tun");
684 punt_hdl = vlib_punt_client_register ("gbp-vxlan");
686 vlib_punt_register (punt_hdl,
687 vxm->punt_no_such_tunnel[FIB_PROTOCOL_IP4],
694 VLIB_INIT_FUNCTION (gbp_vxlan_init) =
696 .runs_after = VLIB_INITS("punt_init", "vxlan_gbp_init"),
701 * fd.io coding-style-patch-verification: ON
704 * eval: (c-set-style "gnu")