2 * Copyright (c) 2020 Doc.ai and/or its affiliates.
3 * Copyright (c) 2020 Cisco and/or its affiliates.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at:
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
17 #ifndef __included_wg_peer_h__
18 #define __included_wg_peer_h__
20 #include <vnet/ip/ip.h>
22 #include <wireguard/wireguard_cookie.h>
23 #include <wireguard/wireguard_timer.h>
24 #include <wireguard/wireguard_key.h>
25 #include <wireguard/wireguard_messages.h>
26 #include <wireguard/wireguard_if.h>
28 typedef struct ip4_udp_header_t_
32 } __clib_packed ip4_udp_header_t;
34 u8 *format_ip4_udp_header (u8 * s, va_list * va);
36 typedef struct wg_peer_allowed_ip_t_
39 fib_node_index_t fib_entry_index;
40 } wg_peer_allowed_ip_t;
42 typedef struct wg_peer_endpoint_t_
48 typedef struct wg_peer
50 noise_remote_t remote;
51 cookie_maker_t cookie_maker;
53 u32 input_thread_index;
54 u32 output_thread_index;
57 wg_peer_endpoint_t dst;
58 wg_peer_endpoint_t src;
60 adj_index_t adj_index;
62 /* rewrite built from address information */
65 /* Vector of allowed-ips */
66 wg_peer_allowed_ip_t *allowed_ips;
68 /* The WG interface this peer is attached to */
72 tw_timer_wheel_16t_2w_512sl_t *timer_wheel;
73 u32 timers[WG_N_TIMERS];
74 u8 timers_dispatched[WG_N_TIMERS];
75 u32 timer_handshake_attempts;
76 u16 persistent_keepalive_interval;
79 f64 last_sent_handshake;
81 f64 last_received_packet;
83 f64 rehandshake_started;
85 /* Variable intervals */
86 u32 new_handshake_interval_tick;
87 u32 rehandshake_interval_tick;
89 bool timer_need_another_keepalive;
94 typedef struct wg_peer_table_bind_ctx_t_
96 ip_address_family_t af;
99 } wg_peer_table_bind_ctx_t;
101 int wg_peer_add (u32 tun_sw_if_index,
102 const u8 public_key_64[NOISE_PUBLIC_KEY_LEN],
104 const ip46_address_t * endpoint,
105 const fib_prefix_t * allowed_ips,
106 u16 port, u16 persistent_keepalive, index_t * peer_index);
107 int wg_peer_remove (u32 peer_index);
109 typedef walk_rc_t (*wg_peer_walk_cb_t) (index_t peeri, void *arg);
110 index_t wg_peer_walk (wg_peer_walk_cb_t fn, void *data);
112 u8 *format_wg_peer (u8 * s, va_list * va);
114 walk_rc_t wg_peer_if_admin_state_change (wg_if_t * wgi, index_t peeri,
116 walk_rc_t wg_peer_if_table_change (wg_if_t * wgi, index_t peeri, void *data);
119 * Expoed for the data-plane
121 extern index_t *wg_peer_by_adj_index;
122 extern wg_peer_t *wg_peer_pool;
124 static inline wg_peer_t *
125 wg_peer_get (index_t peeri)
127 return (pool_elt_at_index (wg_peer_pool, peeri));
130 static inline index_t
131 wg_peer_get_by_adj_index (index_t ai)
133 return (wg_peer_by_adj_index[ai]);
137 * Makes choice for thread_id should be assigned.
140 wg_peer_assign_thread (u32 thread_id)
142 return ((thread_id) ? thread_id
143 : (vlib_num_workers ()?
144 ((unix_time_now_nsec () % vlib_num_workers ()) +
148 #endif // __included_wg_peer_h__
151 * fd.io coding-style-patch-verification: ON
154 * eval: (c-set-style "gnu")