2 * Copyright (c) 2015 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #ifndef included_ip_ip_source_and_port_range_check_h
17 #define included_ip_ip_source_and_port_range_check_h
23 vlib_main_t *vlib_main;
24 vnet_main_t *vnet_main;
25 } source_range_check_main_t;
27 extern source_range_check_main_t source_range_check_main;
31 IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT,
32 IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT,
33 IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_IN,
34 IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_IN,
35 IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS,
36 } ip_source_and_port_range_check_protocol_t;
40 u32 fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS];
41 } ip_source_and_port_range_check_config_t;
43 #define IP_SOURCE_AND_PORT_RANGE_CHECK_RANGE_LIMIT VLIB_BUFFER_PRE_DATA_SIZE/(2*sizeof(u16x8));
58 } protocol_port_range_t;
61 * @brief The number of supported ranges per-data path object.
62 * If more ranges are required, bump this number.
64 #define N_PORT_RANGES_PER_DPO 64
65 #define N_RANGES_PER_BLOCK (sizeof(u16x8vec_t)/2)
66 #define N_BLOCKS_PER_DPO (N_PORT_RANGES_PER_DPO/N_RANGES_PER_BLOCK)
70 * The object that is in the data-path to perform the check.
72 * Some trade-offs here; memory vs performance.
75 * the principle factor is d-cache line misses/hits.
76 * so we want the data layout to minimise the d-cache misses. This
77 * means not following dependent reads. i.e. not doing
81 * range_t *ragnes; // vector of ranges.
84 * so to read ranges[0] we would first d-cache miss on the address
85 * of the object of type B, for which we would need to wait before we
86 * can get the address of B->ranges.
87 * So this layout is better:
95 * the latter layout above is more memory hungry. And N needs to be:
96 * 1 - sized for the maximum required
97 * 2 - fixed, so that objects of type B can be pool allocated and so
98 * 'get'-able using an index.
99 * An option over fixed might be to allocate contiguous chunk from
100 * the pool (like we used to do for multi-path adjs).
102 typedef struct protocol_port_range_dpo_t_
105 * Required for pool_get_aligned
107 CLIB_CACHE_LINE_ALIGN_MARK (cacheline0);
110 * The number of blocks from the 'block' array below
111 * that have rnages configured. We keep this count so that in the data-path
112 * we can limit the loop to be only over the blocks we need
117 * The total number of free ranges from all blocks.
118 * Used to prevent overrun of the ranges available.
123 * the fixed size array of ranges
125 protocol_port_range_t blocks[N_BLOCKS_PER_DPO];
126 } protocol_port_range_dpo_t;
128 int ip4_source_and_port_range_check_add_del (ip4_address_t * address,
132 u16 * hi_ports, int is_add);
134 // This will be moved to another file in another patch -- for API freeze
135 int ip6_source_and_port_range_check_add_del (ip6_address_t * address,
139 u16 * hi_ports, int is_add);
141 int set_ip_source_and_port_range_check (vlib_main_t * vm,
143 u32 sw_if_index, u32 is_add);
145 #endif /* included ip_source_and_port_range_check_h */
148 * fd.io coding-style-patch-verification: ON
151 * eval: (c-set-style "gnu")