2 * Copyright (c) 2020 Cisco and/or its affiliates.
3 * Copyright (c) 2020 Doc.ai and/or its affiliates.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at:
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
17 #include <vnet/vnet.h>
18 #include <vlibmemory/api.h>
20 #include <vnet/format_fns.h>
21 #include <vnet/ip/ip_types_api.h>
22 #include <vlibapi/api.h>
24 #include <wireguard/wireguard.api_enum.h>
25 #include <wireguard/wireguard.api_types.h>
27 #include <wireguard/wireguard_key.h>
28 #include <wireguard/wireguard.h>
29 #include <wireguard/wireguard_if.h>
30 #include <wireguard/wireguard_peer.h>
32 #define REPLY_MSG_ID_BASE wmp->msg_id_base
33 #include <vlibapi/api_helper_macros.h>
36 vl_api_wireguard_interface_create_t_handler
37 (vl_api_wireguard_interface_create_t * mp)
39 vl_api_wireguard_interface_create_reply_t *rmp;
40 wg_main_t *wmp = &wg_main;
41 u8 private_key[NOISE_PUBLIC_KEY_LEN];
46 wg_feature_init (wmp);
48 ip_address_decode2 (&mp->interface.src_ip, &src);
50 if (AF_IP6 == ip_addr_version (&src))
51 rv = VNET_API_ERROR_INVALID_PROTOCOL;
55 curve25519_gen_secret (private_key);
57 clib_memcpy (private_key, mp->interface.private_key,
58 NOISE_PUBLIC_KEY_LEN);
60 rv = wg_if_create (ntohl (mp->interface.user_instance), private_key,
61 ntohs (mp->interface.port), &src, &sw_if_index);
65 REPLY_MACRO2(VL_API_WIREGUARD_INTERFACE_CREATE_REPLY,
67 rmp->sw_if_index = htonl(sw_if_index);
73 vl_api_wireguard_interface_delete_t_handler
74 (vl_api_wireguard_interface_delete_t * mp)
76 vl_api_wireguard_interface_delete_reply_t *rmp;
77 wg_main_t *wmp = &wg_main;
80 wg_feature_init (wmp);
82 VALIDATE_SW_IF_INDEX (mp);
84 rv = wg_if_delete (ntohl (mp->sw_if_index));
86 BAD_SW_IF_INDEX_LABEL;
89 REPLY_MACRO(VL_API_WIREGUARD_INTERFACE_DELETE_REPLY);
93 typedef struct wg_deatils_walk_t_
95 vl_api_registration_t *reg;
100 wireguard_if_send_details (index_t wgii, void *data)
102 vl_api_wireguard_interface_details_t *rmp;
103 wg_deatils_walk_t *ctx = data;
105 const noise_local_t *local;
107 wgi = wg_if_get (wgii);
108 local = noise_local_get (wgi->local_idx);
110 rmp = vl_msg_api_alloc_zero (sizeof (*rmp));
111 rmp->_vl_msg_id = htons (VL_API_WIREGUARD_INTERFACE_DETAILS +
112 wg_main.msg_id_base);
114 clib_memcpy (rmp->interface.private_key,
115 local->l_private, NOISE_PUBLIC_KEY_LEN);
116 rmp->interface.sw_if_index = htonl (wgi->sw_if_index);
117 rmp->interface.port = htons (wgi->port);
118 ip_address_encode2 (&wgi->src_ip, &rmp->interface.src_ip);
120 rmp->context = ctx->context;
122 vl_api_send_msg (ctx->reg, (u8 *) rmp);
124 return (WALK_CONTINUE);
128 vl_api_wireguard_interface_dump_t_handler (vl_api_wireguard_interface_dump_t *
131 vl_api_registration_t *reg;
132 wg_main_t *wmp = &wg_main;
134 wg_feature_init (wmp);
136 reg = vl_api_client_index_to_registration (mp->client_index);
140 wg_deatils_walk_t ctx = {
142 .context = mp->context,
145 wg_if_walk (wireguard_if_send_details, &ctx);
149 vl_api_wireguard_peer_add_t_handler (vl_api_wireguard_peer_add_t * mp)
151 vl_api_wireguard_peer_add_reply_t *rmp;
152 wg_main_t *wmp = &wg_main;
153 index_t peeri = INDEX_INVALID;
156 ip_address_t endpoint;
157 fib_prefix_t *allowed_ips = NULL;
159 VALIDATE_SW_IF_INDEX (&(mp->peer));
161 if (0 == mp->peer.n_allowed_ips)
163 rv = VNET_API_ERROR_INVALID_VALUE;
167 wg_feature_init (wmp);
169 vec_validate (allowed_ips, mp->peer.n_allowed_ips - 1);
170 ip_address_decode2 (&mp->peer.endpoint, &endpoint);
172 for (ii = 0; ii < mp->peer.n_allowed_ips; ii++)
173 ip_prefix_decode (&mp->peer.allowed_ips[ii], &allowed_ips[ii]);
175 if (AF_IP6 == ip_addr_version (&endpoint) ||
176 FIB_PROTOCOL_IP6 == allowed_ips[0].fp_proto)
177 /* ip6 currently not supported, but the API needs to support it
178 * else we'll need to change it later, and that's a PITA */
179 rv = VNET_API_ERROR_INVALID_PROTOCOL;
181 rv = wg_peer_add (ntohl (mp->peer.sw_if_index),
183 ntohl (mp->peer.table_id),
184 &ip_addr_46 (&endpoint),
186 ntohs (mp->peer.port),
187 ntohs (mp->peer.persistent_keepalive), &peeri);
189 vec_free (allowed_ips);
191 BAD_SW_IF_INDEX_LABEL;
193 REPLY_MACRO2(VL_API_WIREGUARD_PEER_ADD_REPLY,
195 rmp->peer_index = ntohl (peeri);
201 vl_api_wireguard_peer_remove_t_handler (vl_api_wireguard_peer_remove_t * mp)
203 vl_api_wireguard_peer_remove_reply_t *rmp;
204 wg_main_t *wmp = &wg_main;
207 wg_feature_init (wmp);
209 rv = wg_peer_remove (ntohl (mp->peer_index));
212 REPLY_MACRO(VL_API_WIREGUARD_PEER_REMOVE_REPLY);
217 send_wg_peers_details (index_t peeri, void *data)
219 vl_api_wireguard_peers_details_t *rmp;
220 wg_deatils_walk_t *ctx = data;
221 const wg_peer_t *peer;
225 peer = wg_peer_get (peeri);
226 n_allowed_ips = vec_len (peer->allowed_ips);
228 ss = (sizeof (*rmp) + (n_allowed_ips * sizeof (rmp->peer.allowed_ips[0])));
230 rmp = vl_msg_api_alloc_zero (ss);
232 rmp->_vl_msg_id = htons (VL_API_WIREGUARD_PEERS_DETAILS +
233 wg_main.msg_id_base);
236 rmp->peer.flags = WIREGUARD_PEER_STATUS_DEAD;
237 clib_memcpy (rmp->peer.public_key,
238 peer->remote.r_public, NOISE_PUBLIC_KEY_LEN);
240 ip_address_encode (&peer->dst.addr, IP46_TYPE_ANY, &rmp->peer.endpoint);
241 rmp->peer.port = htons (peer->dst.port);
242 rmp->peer.n_allowed_ips = n_allowed_ips;
243 rmp->peer.sw_if_index = htonl (peer->wg_sw_if_index);
246 for (ii = 0; ii < n_allowed_ips; ii++)
247 ip_prefix_encode (&peer->allowed_ips[ii].prefix,
248 &rmp->peer.allowed_ips[ii]);
250 rmp->context = ctx->context;
252 vl_api_send_msg (ctx->reg, (u8 *) rmp);
254 return (WALK_CONTINUE);
258 vl_api_wireguard_peers_dump_t_handler (vl_api_wireguard_peers_dump_t * mp)
260 vl_api_registration_t *reg;
261 wg_main_t *wmp = &wg_main;
263 wg_feature_init (wmp);
265 reg = vl_api_client_index_to_registration (mp->client_index);
269 wg_deatils_walk_t ctx = {
271 .context = mp->context,
274 wg_peer_walk (send_wg_peers_details, &ctx);
277 /* set tup the API message handling tables */
278 #include <wireguard/wireguard.api.c>
279 static clib_error_t *
280 wg_api_hookup (vlib_main_t * vm)
282 wg_main_t *wmp = &wg_main;
283 wmp->msg_id_base = setup_message_id_table ();
287 VLIB_API_INIT_FUNCTION (wg_api_hookup);
290 * fd.io coding-style-patch-verification: ON
293 * eval: (c-set-style "gnu")