2 *------------------------------------------------------------------
5 * Copyright (c) 2014-2016 Cisco and/or its affiliates.
6 * Licensed under the Apache License, Version 2.0 (the "License");
7 * you may not use this file except in compliance with the License.
8 * You may obtain a copy of the License at:
10 * http://www.apache.org/licenses/LICENSE-2.0
12 * Unless required by applicable law or agreed to in writing, software
13 * distributed under the License is distributed on an "AS IS" BASIS,
14 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15 * See the License for the specific language governing permissions and
16 * limitations under the License.
17 *------------------------------------------------------------------
21 #include <vlibapi/api.h>
22 #include <vlibmemory/api.h>
23 #include <vppinfra/error.h>
24 #include <plugins/ikev2/ikev2.h>
26 #define __plugin_msg_base ikev2_test_main.msg_id_base
27 #include <vlibapi/vat_helper_macros.h>
29 /* Declare message IDs */
30 #include <ikev2/ikev2_msg_enum.h>
32 #define vl_typedefs /* define message structures */
33 #include <ikev2/ikev2.api.h>
36 /* declare message handlers for each api */
38 #define vl_endianfun /* define message structures */
39 #include <ikev2/ikev2.api.h>
42 /* instantiate all the print functions we know about */
43 #define vl_print(handle, ...)
45 #include <ikev2/ikev2.api.h>
48 /* Get the API version number. */
49 #define vl_api_version(n,v) static u32 api_version=(v);
50 #include <ikev2/ikev2.api.h>
55 /* API message ID base */
60 ikev2_test_main_t ikev2_test_main;
63 unformat_ikev2_auth_method (unformat_input_t * input, va_list * args)
65 u32 *r = va_arg (*args, u32 *);
68 #define _(v,f,s) else if (unformat (input, s)) *r = IKEV2_AUTH_METHOD_##f;
69 foreach_ikev2_auth_method
77 unformat_ikev2_id_type (unformat_input_t * input, va_list * args)
79 u32 *r = va_arg (*args, u32 *);
82 #define _(v,f,s) else if (unformat (input, s)) *r = IKEV2_ID_TYPE_##f;
91 * Generate boilerplate reply handlers, which
92 * dig the return value out of the xxx_reply_t API message,
93 * stick it into vam->retval, and set vam->result_ready
95 * Could also do this by pointing N message decode slots at
96 * a single function, but that could break in subtle ways.
99 #define foreach_standard_reply_retval_handler \
100 _(ikev2_profile_add_del_reply) \
101 _(ikev2_profile_set_auth_reply) \
102 _(ikev2_profile_set_id_reply) \
103 _(ikev2_profile_set_ts_reply) \
104 _(ikev2_set_local_key_reply) \
105 _(ikev2_set_responder_reply) \
106 _(ikev2_set_ike_transforms_reply) \
107 _(ikev2_set_esp_transforms_reply) \
108 _(ikev2_set_sa_lifetime_reply) \
109 _(ikev2_initiate_sa_init_reply) \
110 _(ikev2_initiate_del_ike_sa_reply) \
111 _(ikev2_initiate_del_child_sa_reply) \
112 _(ikev2_initiate_rekey_child_sa_reply)
115 static void vl_api_##n##_t_handler \
116 (vl_api_##n##_t * mp) \
118 vat_main_t * vam = ikev2_test_main.vat_main; \
119 i32 retval = ntohl(mp->retval); \
120 if (vam->async_mode) { \
121 vam->async_errors += (retval < 0); \
123 vam->retval = retval; \
124 vam->result_ready = 1; \
127 foreach_standard_reply_retval_handler;
131 * Table of message reply handlers, must include boilerplate handlers
135 #define foreach_vpe_api_reply_msg \
136 _(IKEV2_PROFILE_ADD_DEL_REPLY, ikev2_profile_add_del_reply) \
137 _(IKEV2_PROFILE_SET_AUTH_REPLY, ikev2_profile_set_auth_reply) \
138 _(IKEV2_PROFILE_SET_ID_REPLY, ikev2_profile_set_id_reply) \
139 _(IKEV2_PROFILE_SET_TS_REPLY, ikev2_profile_set_ts_reply) \
140 _(IKEV2_SET_LOCAL_KEY_REPLY, ikev2_set_local_key_reply) \
141 _(IKEV2_SET_RESPONDER_REPLY, ikev2_set_responder_reply) \
142 _(IKEV2_SET_IKE_TRANSFORMS_REPLY, ikev2_set_ike_transforms_reply) \
143 _(IKEV2_SET_ESP_TRANSFORMS_REPLY, ikev2_set_esp_transforms_reply) \
144 _(IKEV2_SET_SA_LIFETIME_REPLY, ikev2_set_sa_lifetime_reply) \
145 _(IKEV2_INITIATE_SA_INIT_REPLY, ikev2_initiate_sa_init_reply) \
146 _(IKEV2_INITIATE_DEL_IKE_SA_REPLY, ikev2_initiate_del_ike_sa_reply) \
147 _(IKEV2_INITIATE_DEL_CHILD_SA_REPLY, ikev2_initiate_del_child_sa_reply) \
148 _(IKEV2_INITIATE_REKEY_CHILD_SA_REPLY, ikev2_initiate_rekey_child_sa_reply)
152 api_ikev2_profile_add_del (vat_main_t * vam)
154 unformat_input_t *i = vam->input;
155 vl_api_ikev2_profile_add_del_t *mp;
160 const char *valid_chars = "a-zA-Z0-9_";
162 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
164 if (unformat (i, "del"))
166 else if (unformat (i, "name %U", unformat_token, valid_chars, &name))
170 errmsg ("parse error '%U'", format_unformat_error, i);
177 errmsg ("profile name must be specified");
181 if (vec_len (name) > 64)
183 errmsg ("profile name too long");
187 M (IKEV2_PROFILE_ADD_DEL, mp);
189 clib_memcpy (mp->name, name, vec_len (name));
199 api_ikev2_profile_set_auth (vat_main_t * vam)
201 unformat_input_t *i = vam->input;
202 vl_api_ikev2_profile_set_auth_t *mp;
209 const char *valid_chars = "a-zA-Z0-9_";
211 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
213 if (unformat (i, "name %U", unformat_token, valid_chars, &name))
215 else if (unformat (i, "auth_method %U",
216 unformat_ikev2_auth_method, &auth_method))
218 else if (unformat (i, "auth_data 0x%U", unformat_hex_string, &data))
220 else if (unformat (i, "auth_data %v", &data))
224 errmsg ("parse error '%U'", format_unformat_error, i);
231 errmsg ("profile name must be specified");
235 if (vec_len (name) > 64)
237 errmsg ("profile name too long");
243 errmsg ("auth_data must be specified");
249 errmsg ("auth_method must be specified");
253 M (IKEV2_PROFILE_SET_AUTH, mp);
256 mp->auth_method = (u8) auth_method;
257 mp->data_len = vec_len (data);
258 clib_memcpy (mp->name, name, vec_len (name));
259 clib_memcpy (mp->data, data, vec_len (data));
269 api_ikev2_profile_set_id (vat_main_t * vam)
271 unformat_input_t *i = vam->input;
272 vl_api_ikev2_profile_set_id_t *mp;
280 const char *valid_chars = "a-zA-Z0-9_";
282 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
284 if (unformat (i, "name %U", unformat_token, valid_chars, &name))
286 else if (unformat (i, "id_type %U", unformat_ikev2_id_type, &id_type))
288 else if (unformat (i, "id_data %U", unformat_ip4_address, &ip4))
290 data = vec_new (u8, 4);
291 clib_memcpy (data, ip4.as_u8, 4);
293 else if (unformat (i, "id_data 0x%U", unformat_hex_string, &data))
295 else if (unformat (i, "id_data %v", &data))
297 else if (unformat (i, "local"))
299 else if (unformat (i, "remote"))
303 errmsg ("parse error '%U'", format_unformat_error, i);
310 errmsg ("profile name must be specified");
314 if (vec_len (name) > 64)
316 errmsg ("profile name too long");
322 errmsg ("id_data must be specified");
328 errmsg ("id_type must be specified");
332 M (IKEV2_PROFILE_SET_ID, mp);
334 mp->is_local = is_local;
335 mp->id_type = (u8) id_type;
336 mp->data_len = vec_len (data);
337 clib_memcpy (mp->name, name, vec_len (name));
338 clib_memcpy (mp->data, data, vec_len (data));
348 api_ikev2_profile_set_ts (vat_main_t * vam)
350 unformat_input_t *i = vam->input;
351 vl_api_ikev2_profile_set_ts_t *mp;
354 u32 proto = 0, start_port = 0, end_port = (u32) ~ 0;
355 ip4_address_t start_addr, end_addr;
357 const char *valid_chars = "a-zA-Z0-9_";
360 start_addr.as_u32 = 0;
361 end_addr.as_u32 = (u32) ~ 0;
363 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
365 if (unformat (i, "name %U", unformat_token, valid_chars, &name))
367 else if (unformat (i, "protocol %d", &proto))
369 else if (unformat (i, "start_port %d", &start_port))
371 else if (unformat (i, "end_port %d", &end_port))
374 if (unformat (i, "start_addr %U", unformat_ip4_address, &start_addr))
376 else if (unformat (i, "end_addr %U", unformat_ip4_address, &end_addr))
378 else if (unformat (i, "local"))
380 else if (unformat (i, "remote"))
384 errmsg ("parse error '%U'", format_unformat_error, i);
391 errmsg ("profile name must be specified");
395 if (vec_len (name) > 64)
397 errmsg ("profile name too long");
401 M (IKEV2_PROFILE_SET_TS, mp);
403 mp->is_local = is_local;
404 mp->proto = (u8) proto;
405 mp->start_port = (u16) start_port;
406 mp->end_port = (u16) end_port;
407 mp->start_addr = start_addr.as_u32;
408 mp->end_addr = end_addr.as_u32;
409 clib_memcpy (mp->name, name, vec_len (name));
418 api_ikev2_set_local_key (vat_main_t * vam)
420 unformat_input_t *i = vam->input;
421 vl_api_ikev2_set_local_key_t *mp;
425 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
427 if (unformat (i, "file %v", &file))
431 errmsg ("parse error '%U'", format_unformat_error, i);
438 errmsg ("RSA key file must be specified");
442 if (vec_len (file) > 256)
444 errmsg ("file name too long");
448 M (IKEV2_SET_LOCAL_KEY, mp);
450 clib_memcpy (mp->key_file, file, vec_len (file));
459 api_ikev2_set_responder (vat_main_t * vam)
461 unformat_input_t *i = vam->input;
462 vl_api_ikev2_set_responder_t *mp;
465 u32 sw_if_index = ~0;
466 ip4_address_t address;
468 const char *valid_chars = "a-zA-Z0-9_";
470 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
473 (i, "%U interface %d address %U", unformat_token, valid_chars,
474 &name, &sw_if_index, unformat_ip4_address, &address))
478 errmsg ("parse error '%U'", format_unformat_error, i);
485 errmsg ("profile name must be specified");
489 if (vec_len (name) > 64)
491 errmsg ("profile name too long");
495 M (IKEV2_SET_RESPONDER, mp);
497 clib_memcpy (mp->name, name, vec_len (name));
500 mp->sw_if_index = sw_if_index;
501 clib_memcpy (mp->address, &address, sizeof (address));
509 api_ikev2_set_ike_transforms (vat_main_t * vam)
511 unformat_input_t *i = vam->input;
512 vl_api_ikev2_set_ike_transforms_t *mp;
515 u32 crypto_alg, crypto_key_size, integ_alg, dh_group;
517 const char *valid_chars = "a-zA-Z0-9_";
519 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
521 if (unformat (i, "%U %d %d %d %d", unformat_token, valid_chars, &name,
522 &crypto_alg, &crypto_key_size, &integ_alg, &dh_group))
526 errmsg ("parse error '%U'", format_unformat_error, i);
533 errmsg ("profile name must be specified");
537 if (vec_len (name) > 64)
539 errmsg ("profile name too long");
543 M (IKEV2_SET_IKE_TRANSFORMS, mp);
545 clib_memcpy (mp->name, name, vec_len (name));
547 mp->crypto_alg = crypto_alg;
548 mp->crypto_key_size = crypto_key_size;
549 mp->integ_alg = integ_alg;
550 mp->dh_group = dh_group;
559 api_ikev2_set_esp_transforms (vat_main_t * vam)
561 unformat_input_t *i = vam->input;
562 vl_api_ikev2_set_esp_transforms_t *mp;
565 u32 crypto_alg, crypto_key_size, integ_alg, dh_group;
567 const char *valid_chars = "a-zA-Z0-9_";
569 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
571 if (unformat (i, "%U %d %d %d %d", unformat_token, valid_chars, &name,
572 &crypto_alg, &crypto_key_size, &integ_alg, &dh_group))
576 errmsg ("parse error '%U'", format_unformat_error, i);
583 errmsg ("profile name must be specified");
587 if (vec_len (name) > 64)
589 errmsg ("profile name too long");
593 M (IKEV2_SET_ESP_TRANSFORMS, mp);
595 clib_memcpy (mp->name, name, vec_len (name));
597 mp->crypto_alg = crypto_alg;
598 mp->crypto_key_size = crypto_key_size;
599 mp->integ_alg = integ_alg;
600 mp->dh_group = dh_group;
608 api_ikev2_set_sa_lifetime (vat_main_t * vam)
610 unformat_input_t *i = vam->input;
611 vl_api_ikev2_set_sa_lifetime_t *mp;
614 u64 lifetime, lifetime_maxdata;
615 u32 lifetime_jitter, handover;
617 const char *valid_chars = "a-zA-Z0-9_";
619 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
621 if (unformat (i, "%U %lu %u %u %lu", unformat_token, valid_chars, &name,
622 &lifetime, &lifetime_jitter, &handover,
627 errmsg ("parse error '%U'", format_unformat_error, i);
634 errmsg ("profile name must be specified");
638 if (vec_len (name) > 64)
640 errmsg ("profile name too long");
644 M (IKEV2_SET_SA_LIFETIME, mp);
646 clib_memcpy (mp->name, name, vec_len (name));
648 mp->lifetime = lifetime;
649 mp->lifetime_jitter = lifetime_jitter;
650 mp->handover = handover;
651 mp->lifetime_maxdata = lifetime_maxdata;
659 api_ikev2_initiate_sa_init (vat_main_t * vam)
661 unformat_input_t *i = vam->input;
662 vl_api_ikev2_initiate_sa_init_t *mp;
666 const char *valid_chars = "a-zA-Z0-9_";
668 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
670 if (unformat (i, "%U", unformat_token, valid_chars, &name))
674 errmsg ("parse error '%U'", format_unformat_error, i);
681 errmsg ("profile name must be specified");
685 if (vec_len (name) > 64)
687 errmsg ("profile name too long");
691 M (IKEV2_INITIATE_SA_INIT, mp);
693 clib_memcpy (mp->name, name, vec_len (name));
702 api_ikev2_initiate_del_ike_sa (vat_main_t * vam)
704 unformat_input_t *i = vam->input;
705 vl_api_ikev2_initiate_del_ike_sa_t *mp;
710 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
712 if (unformat (i, "%lx", &ispi))
716 errmsg ("parse error '%U'", format_unformat_error, i);
721 M (IKEV2_INITIATE_DEL_IKE_SA, mp);
731 api_ikev2_initiate_del_child_sa (vat_main_t * vam)
733 unformat_input_t *i = vam->input;
734 vl_api_ikev2_initiate_del_child_sa_t *mp;
739 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
741 if (unformat (i, "%x", &ispi))
745 errmsg ("parse error '%U'", format_unformat_error, i);
750 M (IKEV2_INITIATE_DEL_CHILD_SA, mp);
760 api_ikev2_initiate_rekey_child_sa (vat_main_t * vam)
762 unformat_input_t *i = vam->input;
763 vl_api_ikev2_initiate_rekey_child_sa_t *mp;
768 while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT)
770 if (unformat (i, "%x", &ispi))
774 errmsg ("parse error '%U'", format_unformat_error, i);
779 M (IKEV2_INITIATE_REKEY_CHILD_SA, mp);
789 /* List of API message constructors, CLI names map to api_xxx */
790 #define foreach_vpe_api_msg \
791 _(ikev2_profile_add_del, "name <profile_name> [del]") \
792 _(ikev2_profile_set_auth, "name <profile_name> auth_method <method>\n" \
793 "(auth_data 0x<data> | auth_data <data>)") \
794 _(ikev2_profile_set_id, "name <profile_name> id_type <type>\n" \
795 "(id_data 0x<data> | id_data <data>) (local|remote)") \
796 _(ikev2_profile_set_ts, "name <profile_name> protocol <proto>\n" \
797 "start_port <port> end_port <port> start_addr <ip4> end_addr <ip4>\n" \
799 _(ikev2_set_local_key, "file <absolute_file_path>") \
800 _(ikev2_set_responder, "<profile_name> interface <interface> address <addr>") \
801 _(ikev2_set_ike_transforms, "<profile_name> <crypto alg> <key size> <integrity alg> <DH group>") \
802 _(ikev2_set_esp_transforms, "<profile_name> <crypto alg> <key size> <integrity alg> <DH group>") \
803 _(ikev2_set_sa_lifetime, "<profile_name> <seconds> <jitter> <handover> <max bytes>") \
804 _(ikev2_initiate_sa_init, "<profile_name>") \
805 _(ikev2_initiate_del_ike_sa, "<ispi>") \
806 _(ikev2_initiate_del_child_sa, "<ispi>") \
807 _(ikev2_initiate_rekey_child_sa, "<ispi>")
810 ikev2_vat_api_hookup (vat_main_t * vam)
812 ikev2_test_main_t *sm = &ikev2_test_main;
813 /* Hook up handlers for replies from the data plane plug-in */
815 vl_msg_api_set_handlers((VL_API_##N + sm->msg_id_base), \
817 vl_api_##n##_t_handler, \
819 vl_api_##n##_t_endian, \
820 vl_api_##n##_t_print, \
821 sizeof(vl_api_##n##_t), 1);
822 foreach_vpe_api_reply_msg;
825 /* API messages we can send */
826 #define _(n,h) hash_set_mem (vam->function_by_name, #n, api_##n);
831 #define _(n,h) hash_set_mem (vam->help_by_name, #n, h);
837 vat_plugin_register (vat_main_t * vam)
839 ikev2_test_main_t *sm = &ikev2_test_main;
844 name = format (0, "ikev2_%08x%c", api_version, 0);
845 sm->msg_id_base = vl_client_get_first_plugin_msg_id ((char *) name);
847 if (sm->msg_id_base != (u16) ~ 0)
848 ikev2_vat_api_hookup (vam);
856 * fd.io coding-style-patch-verification: ON
859 * eval: (c-set-style "gnu")