2 * Copyright (c) 2021 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #ifndef __included_quic_h__
17 #define __included_quic_h__
19 #include <vnet/session/application_interface.h>
21 #include <vppinfra/lock.h>
22 #include <vppinfra/tw_timer_1t_3w_1024sl_ov.h>
23 #include <vppinfra/bihash_16_8.h>
27 #include <vnet/crypto/crypto.h>
28 #include <vppinfra/lock.h>
32 * 2 - connection/stream events
38 #define QUIC_TSTAMP_RESOLUTION 0.001 /* QUIC tick resolution (1ms) */
39 #define QUIC_TIMER_HANDLE_INVALID ((u32) ~0)
40 #define QUIC_SESSION_INVALID ((u32) ~0 - 1)
41 #define QUIC_MAX_PACKET_SIZE 1280
43 #define QUIC_INT_MAX 0x3FFFFFFFFFFFFFFF
44 #define QUIC_DEFAULT_FIFO_SIZE (64 << 10)
45 #define QUIC_SEND_PACKET_VEC_SIZE 16
46 #define QUIC_IV_LEN 17
48 #define QUIC_MAX_COALESCED_PACKET 4
50 #define QUIC_RCV_MAX_PACKETS 16
52 #define QUIC_DEFAULT_CONN_TIMEOUT (30 * 1000) /* 30 seconds */
54 /* Taken from quicly.c */
55 #define QUICLY_QUIC_BIT 0x40
57 #define QUICLY_PACKET_TYPE_INITIAL (QUICLY_LONG_HEADER_BIT | QUICLY_QUIC_BIT | 0)
58 #define QUICLY_PACKET_TYPE_0RTT (QUICLY_LONG_HEADER_BIT | QUICLY_QUIC_BIT | 0x10)
59 #define QUICLY_PACKET_TYPE_HANDSHAKE (QUICLY_LONG_HEADER_BIT | QUICLY_QUIC_BIT | 0x20)
60 #define QUICLY_PACKET_TYPE_RETRY (QUICLY_LONG_HEADER_BIT | QUICLY_QUIC_BIT | 0x30)
61 #define QUICLY_PACKET_TYPE_BITMASK 0xf0
64 #define QUIC_ERROR_FULL_FIFO 0xff10
65 #define QUIC_APP_ERROR_CLOSE_NOTIFY QUICLY_ERROR_FROM_APPLICATION_ERROR_CODE(0)
66 #define QUIC_APP_ALLOCATION_ERROR QUICLY_ERROR_FROM_APPLICATION_ERROR_CODE(0x1)
67 #define QUIC_APP_ACCEPT_NOTIFY_ERROR QUICLY_ERROR_FROM_APPLICATION_ERROR_CODE(0x2)
68 #define QUIC_APP_CONNECT_NOTIFY_ERROR QUICLY_ERROR_FROM_APPLICATION_ERROR_CODE(0x3)
70 #define QUIC_DECRYPT_PACKET_OK 0
71 #define QUIC_DECRYPT_PACKET_NOTOFFLOADED 1
72 #define QUIC_DECRYPT_PACKET_ERROR 2
75 #define QUIC_DBG(_lvl, _fmt, _args...) \
76 if (_lvl <= QUIC_DEBUG) \
77 clib_warning (_fmt, ##_args)
79 #define QUIC_DBG(_lvl, _fmt, _args...)
82 #if CLIB_ASSERT_ENABLE
83 #define QUIC_ASSERT(truth) ASSERT (truth)
85 #define QUIC_ASSERT(truth) \
87 if (PREDICT_FALSE (! (truth))) \
88 QUIC_ERR ("ASSERT(%s) failed", # truth); \
92 #define QUIC_ERR(_fmt, _args...) \
94 clib_warning ("QUIC-ERR: " _fmt, ##_args); \
99 extern vlib_node_registration_t quic_input_node;
103 #define quic_error(n,s) QUIC_ERROR_##n,
104 #include <plugins/quic/quic_error.def>
109 typedef enum quic_ctx_conn_state_
111 QUIC_CONN_STATE_OPENED,
112 QUIC_CONN_STATE_HANDSHAKE,
113 QUIC_CONN_STATE_READY,
114 QUIC_CONN_STATE_PASSIVE_CLOSING,
115 QUIC_CONN_STATE_PASSIVE_CLOSING_APP_CLOSED,
116 QUIC_CONN_STATE_PASSIVE_CLOSING_QUIC_CLOSED,
117 QUIC_CONN_STATE_ACTIVE_CLOSING,
118 } quic_ctx_conn_state_t;
120 typedef enum quic_packet_type_
122 QUIC_PACKET_TYPE_NONE,
123 QUIC_PACKET_TYPE_RECEIVE,
124 QUIC_PACKET_TYPE_MIGRATE,
125 QUIC_PACKET_TYPE_ACCEPT,
126 QUIC_PACKET_TYPE_RESET,
127 QUIC_PACKET_TYPE_DROP,
128 } quic_packet_type_t;
130 typedef enum quic_ctx_flags_
132 QUIC_F_IS_STREAM = (1 << 0),
133 QUIC_F_IS_LISTENER = (1 << 1),
136 typedef enum quic_cc_type
142 /* This structure is used to implement the concept of VPP connection for QUIC.
143 * We create one per connection and one per stream. */
144 typedef struct quic_ctx_
148 transport_connection_t connection;
150 { /** QUIC ctx case */
157 u8 _qctx_end_marker; /* Leave this at the end */
160 { /** STREAM ctx case */
161 quicly_stream_t *stream;
163 u32 quic_connection_ctx_id;
164 u8 _sctx_end_marker; /* Leave this at the end */
167 session_handle_t udp_session_handle;
169 u32 parent_app_wrk_id;
173 u32 crypto_context_index;
178 ptls_cipher_context_t *hp_ctx;
179 ptls_aead_context_t *aead_ctx;
181 int key_phase_ingress;
185 /* Make sure our custom fields don't overlap with the fields we use in
188 STATIC_ASSERT (offsetof (quic_ctx_t, _qctx_end_marker) <=
189 TRANSPORT_CONN_ID_LEN,
190 "connection data must be less than TRANSPORT_CONN_ID_LEN bytes");
191 STATIC_ASSERT (offsetof (quic_ctx_t, _sctx_end_marker) <=
192 TRANSPORT_CONN_ID_LEN,
193 "connection data must be less than TRANSPORT_CONN_ID_LEN bytes");
195 /* single-entry session cache */
196 typedef struct quic_session_cache_
198 ptls_encrypt_ticket_t super;
201 } quic_session_cache_t;
203 typedef struct quic_stream_data_
207 u32 app_rx_data_len; /**< bytes received, to be read by external app */
208 u32 app_tx_data_len; /**< bytes sent */
209 } quic_stream_data_t;
211 typedef struct quic_crypto_context_data_
213 quicly_context_t quicly_ctx;
214 char cid_key[QUIC_IV_LEN];
215 ptls_context_t ptls_ctx;
216 } quic_crypto_context_data_t;
218 typedef struct quic_worker_ctx_
220 CLIB_CACHE_LINE_ALIGN_MARK (cacheline0);
221 int64_t time_now; /**< worker time */
222 tw_timer_wheel_1t_3w_1024sl_ov_t timer_wheel; /**< worker timer wheel */
223 quicly_cid_plaintext_t next_cid;
224 crypto_context_t *crypto_ctx_pool; /**< per thread pool of crypto contexes */
225 clib_bihash_24_8_t crypto_context_hash; /**< per thread [params:crypto_ctx_index] hash */
228 typedef struct quic_rx_packet_ctx_
230 quicly_decoded_packet_t packet;
231 u8 data[QUIC_MAX_PACKET_SIZE];
237 struct sockaddr_in6 sa6;
241 session_dgram_hdr_t ph;
242 } quic_rx_packet_ctx_t;
244 typedef struct quic_main_
247 quic_ctx_t **ctx_pool;
248 quic_worker_ctx_t *wrk_ctx;
249 clib_bihash_16_8_t connection_hash; /**< quic connection id -> conn handle */
250 f64 tstamp_ticks_per_clock;
252 ptls_cipher_suite_t ***quic_ciphers; /**< available ciphers by crypto engine */
253 uword *available_crypto_engines; /**< Bitmap for registered engines */
254 u8 default_crypto_engine; /**< Used if you do connect with CRYPTO_ENGINE_NONE (0) */
255 u64 max_packets_per_key; /**< number of packets that can be sent without a key update */
258 ptls_handshake_properties_t hs_properties;
259 quic_session_cache_t session_cache;
262 u32 udp_fifo_prealloc;
263 u32 connection_timeout;
265 u8 vnet_crypto_enabled;
266 u32 *per_thread_crypto_key_indices;
269 #endif /* __included_quic_h__ */
272 * fd.io coding-style-patch-verification: ON
275 * eval: (c-set-style "gnu")