2 * Copyright (c) 2016-2019 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
18 * @brief TCP host stack utilities
21 #include <vnet/tcp/tcp.h>
22 #include <vnet/tcp/tcp_inlines.h>
23 #include <vnet/session/session.h>
24 #include <vnet/fib/fib.h>
25 #include <vnet/dpo/load_balance.h>
32 fib_protocol_t nh_proto;
33 vnet_link_t link_type;
37 } tcp_add_del_adj_args_t;
40 tcp_add_del_adj_cb (tcp_add_del_adj_args_t * args)
45 adj_nbr_add_or_lock (args->nh_proto, args->link_type, &args->ip,
50 ai = adj_nbr_find (FIB_PROTOCOL_IP6, VNET_LINK_IP6, &args->ip,
52 if (ai != ADJ_INDEX_INVALID)
58 tcp_add_del_adjacency (tcp_connection_t * tc, u8 is_add)
60 tcp_add_del_adj_args_t args = {
61 .nh_proto = FIB_PROTOCOL_IP6,
62 .link_type = VNET_LINK_IP6,
64 .sw_if_index = tc->sw_if_index,
67 vlib_rpc_call_main_thread (tcp_add_del_adj_cb, (u8 *) & args,
72 tcp_cc_init (tcp_connection_t * tc)
74 tc->cc_algo->init (tc);
78 tcp_cc_cleanup (tcp_connection_t * tc)
80 if (tc->cc_algo->cleanup)
81 tc->cc_algo->cleanup (tc);
85 tcp_cc_algo_register (tcp_cc_algorithm_type_e type,
86 const tcp_cc_algorithm_t * vft)
88 tcp_main_t *tm = vnet_get_tcp_main ();
89 vec_validate (tm->cc_algos, type);
91 tm->cc_algos[type] = *vft;
92 hash_set_mem (tm->cc_algo_by_name, vft->name, type);
96 tcp_cc_algo_get (tcp_cc_algorithm_type_e type)
98 tcp_main_t *tm = vnet_get_tcp_main ();
99 return &tm->cc_algos[type];
102 tcp_cc_algorithm_type_e
103 tcp_cc_algo_new_type (const tcp_cc_algorithm_t * vft)
105 tcp_main_t *tm = vnet_get_tcp_main ();
106 tcp_cc_algo_register (++tm->cc_last_type, vft);
107 return tm->cc_last_type;
111 tcp_connection_bind (u32 session_index, transport_endpoint_t * lcl)
113 tcp_main_t *tm = &tcp_main;
114 tcp_connection_t *listener;
117 pool_get (tm->listener_pool, listener);
118 clib_memset (listener, 0, sizeof (*listener));
120 listener->c_c_index = listener - tm->listener_pool;
121 listener->c_lcl_port = lcl->port;
123 /* If we are provided a sw_if_index, bind using one of its ips */
124 if (ip_is_zero (&lcl->ip, 1) && lcl->sw_if_index != ENDPOINT_INVALID_INDEX)
126 if ((iface_ip = ip_interface_get_first_ip (lcl->sw_if_index,
128 ip_set (&lcl->ip, iface_ip, lcl->is_ip4);
130 ip_copy (&listener->c_lcl_ip, &lcl->ip, lcl->is_ip4);
131 listener->c_is_ip4 = lcl->is_ip4;
132 listener->c_proto = TRANSPORT_PROTO_TCP;
133 listener->c_s_index = session_index;
134 listener->c_fib_index = lcl->fib_index;
135 listener->state = TCP_STATE_LISTEN;
136 listener->cc_algo = tcp_cc_algo_get (tcp_cfg.cc_algo);
138 tcp_connection_timers_init (listener);
140 TCP_EVT (TCP_EVT_BIND, listener);
142 return listener->c_c_index;
146 tcp_session_bind (u32 session_index, transport_endpoint_t * tep)
148 return tcp_connection_bind (session_index, tep);
152 tcp_connection_unbind (u32 listener_index)
154 tcp_main_t *tm = vnet_get_tcp_main ();
155 tcp_connection_t *tc;
157 tc = pool_elt_at_index (tm->listener_pool, listener_index);
159 TCP_EVT (TCP_EVT_UNBIND, tc);
161 /* Poison the entry */
163 clib_memset (tc, 0xFA, sizeof (*tc));
165 pool_put_index (tm->listener_pool, listener_index);
169 tcp_session_unbind (u32 listener_index)
171 tcp_connection_unbind (listener_index);
175 static transport_connection_t *
176 tcp_session_get_listener (u32 listener_index)
178 tcp_main_t *tm = vnet_get_tcp_main ();
179 tcp_connection_t *tc;
180 tc = pool_elt_at_index (tm->listener_pool, listener_index);
181 return &tc->connection;
185 * Cleanup half-open connection
189 tcp_half_open_connection_del (tcp_connection_t * tc)
191 tcp_main_t *tm = vnet_get_tcp_main ();
192 clib_spinlock_lock_if_init (&tm->half_open_lock);
194 clib_memset (tc, 0xFA, sizeof (*tc));
195 pool_put (tm->half_open_connections, tc);
196 clib_spinlock_unlock_if_init (&tm->half_open_lock);
200 * Try to cleanup half-open connection
202 * If called from a thread that doesn't own tc, the call won't have any
205 * @param tc - connection to be cleaned up
206 * @return non-zero if cleanup failed.
209 tcp_half_open_connection_cleanup (tcp_connection_t * tc)
211 tcp_worker_ctx_t *wrk;
213 /* Make sure this is the owning thread */
214 if (tc->c_thread_index != vlib_get_thread_index ())
217 wrk = tcp_get_worker (tc->c_thread_index);
218 tcp_timer_reset (&wrk->timer_wheel, tc, TCP_TIMER_RETRANSMIT_SYN);
219 tcp_half_open_connection_del (tc);
223 static tcp_connection_t *
224 tcp_half_open_connection_new (void)
226 tcp_main_t *tm = vnet_get_tcp_main ();
227 tcp_connection_t *tc = 0;
228 ASSERT (vlib_get_thread_index () == 0);
229 pool_get (tm->half_open_connections, tc);
230 clib_memset (tc, 0, sizeof (*tc));
231 tc->c_c_index = tc - tm->half_open_connections;
236 * Cleans up connection state.
241 tcp_connection_cleanup (tcp_connection_t * tc)
243 TCP_EVT (TCP_EVT_DELETE, tc);
245 /* Cleanup local endpoint if this was an active connect */
246 if (!(tc->cfg_flags & TCP_CFG_F_NO_ENDPOINT))
247 transport_endpoint_cleanup (TRANSPORT_PROTO_TCP, &tc->c_lcl_ip,
250 /* Check if connection is not yet fully established */
251 if (tc->state == TCP_STATE_SYN_SENT)
253 /* Try to remove the half-open connection. If this is not the owning
254 * thread, tc won't be removed. Retransmit or establish timers will
255 * eventually expire and call again cleanup on the right thread. */
256 if (tcp_half_open_connection_cleanup (tc))
257 tc->flags |= TCP_CONN_HALF_OPEN_DONE;
261 /* Make sure all timers are cleared */
262 tcp_connection_timers_reset (tc);
264 if (!tc->c_is_ip4 && ip6_address_is_link_local_unicast (&tc->c_rmt_ip6))
265 tcp_add_del_adjacency (tc, 0);
268 vec_free (tc->snd_sacks);
269 vec_free (tc->snd_sacks_fl);
270 vec_free (tc->rcv_opts.sacks);
271 pool_free (tc->sack_sb.holes);
273 if (tc->cfg_flags & TCP_CFG_F_RATE_SAMPLE)
276 tcp_connection_free (tc);
281 * Connection removal.
283 * This should be called only once connection enters CLOSED state. Note
284 * that it notifies the session of the removal event, so if the goal is to
285 * just remove the connection, call tcp_connection_cleanup instead.
288 tcp_connection_del (tcp_connection_t * tc)
290 session_transport_delete_notify (&tc->connection);
291 tcp_connection_cleanup (tc);
295 tcp_connection_alloc (u8 thread_index)
297 tcp_worker_ctx_t *wrk = tcp_get_worker (thread_index);
298 tcp_connection_t *tc;
300 pool_get (wrk->connections, tc);
301 clib_memset (tc, 0, sizeof (*tc));
302 tc->c_c_index = tc - wrk->connections;
303 tc->c_thread_index = thread_index;
308 tcp_connection_alloc_w_base (u8 thread_index, tcp_connection_t * base)
310 tcp_worker_ctx_t *wrk = tcp_get_worker (thread_index);
311 tcp_connection_t *tc;
313 pool_get (wrk->connections, tc);
314 clib_memcpy_fast (tc, base, sizeof (*tc));
315 tc->c_c_index = tc - wrk->connections;
316 tc->c_thread_index = thread_index;
321 tcp_connection_free (tcp_connection_t * tc)
323 tcp_worker_ctx_t *wrk = tcp_get_worker (tc->c_thread_index);
326 clib_memset (tc, 0xFA, sizeof (*tc));
327 pool_put (wrk->connections, tc);
330 pool_put (wrk->connections, tc);
334 tcp_program_cleanup (tcp_worker_ctx_t * wrk, tcp_connection_t * tc)
336 tcp_cleanup_req_t *req;
337 clib_time_type_t now;
339 now = transport_time_now (tc->c_thread_index);
340 clib_fifo_add2 (wrk->pending_cleanups, req);
341 req->connection_index = tc->c_c_index;
342 req->free_time = now + tcp_cfg.cleanup_time;
346 * Begin connection closing procedure.
348 * If at the end the connection is not in CLOSED state, it is not removed.
349 * Instead, we rely on on TCP to advance through state machine to either
350 * 1) LAST_ACK (passive close) whereby when the last ACK is received
351 * tcp_connection_del is called. This notifies session of the delete and
353 * 2) TIME_WAIT (active close) whereby after 2MSL the 2MSL timer triggers
354 * and cleanup is called.
356 * N.B. Half-close connections are not supported
359 tcp_connection_close (tcp_connection_t * tc)
361 tcp_worker_ctx_t *wrk = tcp_get_worker (tc->c_thread_index);
363 TCP_EVT (TCP_EVT_CLOSE, tc);
365 /* Send/Program FIN if needed and switch state */
368 case TCP_STATE_SYN_SENT:
369 /* Try to cleanup. If not on the right thread, mark as half-open done.
370 * Connection will be cleaned up when establish timer pops */
371 tcp_connection_cleanup (tc);
373 case TCP_STATE_SYN_RCVD:
374 tcp_connection_timers_reset (tc);
376 tcp_connection_set_state (tc, TCP_STATE_FIN_WAIT_1);
377 tcp_timer_update (&wrk->timer_wheel, tc, TCP_TIMER_WAITCLOSE,
378 tcp_cfg.finwait1_time);
380 case TCP_STATE_ESTABLISHED:
381 /* If closing with unread data, reset the connection */
382 if (transport_max_rx_dequeue (&tc->connection))
385 tcp_connection_timers_reset (tc);
386 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
387 session_transport_closed_notify (&tc->connection);
388 tcp_program_cleanup (tcp_get_worker (tc->c_thread_index), tc);
389 tcp_worker_stats_inc (wrk, rst_unread, 1);
392 if (!transport_max_tx_dequeue (&tc->connection))
395 tc->flags |= TCP_CONN_FINPNDG;
396 tcp_connection_set_state (tc, TCP_STATE_FIN_WAIT_1);
397 /* Set a timer in case the peer stops responding. Otherwise the
398 * connection will be stuck here forever. */
399 ASSERT (tc->timers[TCP_TIMER_WAITCLOSE] == TCP_TIMER_HANDLE_INVALID);
400 tcp_timer_set (&wrk->timer_wheel, tc, TCP_TIMER_WAITCLOSE,
401 tcp_cfg.finwait1_time);
403 case TCP_STATE_CLOSE_WAIT:
404 if (!transport_max_tx_dequeue (&tc->connection))
407 tcp_connection_timers_reset (tc);
408 tcp_connection_set_state (tc, TCP_STATE_LAST_ACK);
409 tcp_timer_update (&wrk->timer_wheel, tc, TCP_TIMER_WAITCLOSE,
410 tcp_cfg.lastack_time);
413 tc->flags |= TCP_CONN_FINPNDG;
415 case TCP_STATE_FIN_WAIT_1:
416 tcp_timer_update (&wrk->timer_wheel, tc, TCP_TIMER_WAITCLOSE,
417 tcp_cfg.finwait1_time);
419 case TCP_STATE_CLOSED:
420 /* Cleanup should've been programmed already */
423 TCP_DBG ("state: %u", tc->state);
428 tcp_session_close (u32 conn_index, u32 thread_index)
430 tcp_connection_t *tc;
431 tc = tcp_connection_get (conn_index, thread_index);
432 tcp_connection_close (tc);
436 tcp_session_cleanup (u32 conn_index, u32 thread_index)
438 tcp_connection_t *tc;
439 tc = tcp_connection_get (conn_index, thread_index);
442 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
443 tcp_connection_cleanup (tc);
447 tcp_session_reset (u32 conn_index, u32 thread_index)
449 tcp_connection_t *tc;
450 tc = tcp_connection_get (conn_index, thread_index);
452 tcp_connection_timers_reset (tc);
453 tcp_cong_recovery_off (tc);
454 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
455 session_transport_closed_notify (&tc->connection);
456 tcp_program_cleanup (tcp_get_worker (thread_index), tc);
460 * Initialize all connection timers as invalid
463 tcp_connection_timers_init (tcp_connection_t * tc)
467 /* Set all to invalid */
468 for (i = 0; i < TCP_N_TIMERS; i++)
470 tc->timers[i] = TCP_TIMER_HANDLE_INVALID;
473 tc->rto = TCP_RTO_INIT;
477 * Stop all connection timers
480 tcp_connection_timers_reset (tcp_connection_t * tc)
482 tcp_worker_ctx_t *wrk = tcp_get_worker (tc->c_thread_index);
485 for (i = 0; i < TCP_N_TIMERS; i++)
486 tcp_timer_reset (&wrk->timer_wheel, tc, i);
490 typedef struct ip4_tcp_hdr
496 typedef struct ip6_tcp_hdr
503 tcp_connection_select_lb_bucket (tcp_connection_t * tc, const dpo_id_t * dpo,
506 const dpo_id_t *choice;
510 lb = load_balance_get (dpo->dpoi_index);
514 clib_memset (&hdr, 0, sizeof (hdr));
515 hdr.ip.protocol = IP_PROTOCOL_TCP;
516 hdr.ip.address_pair.src.as_u32 = tc->c_lcl_ip.ip4.as_u32;
517 hdr.ip.address_pair.dst.as_u32 = tc->c_rmt_ip.ip4.as_u32;
518 hdr.tcp.src_port = tc->c_lcl_port;
519 hdr.tcp.dst_port = tc->c_rmt_port;
520 hash = ip4_compute_flow_hash (&hdr.ip, lb->lb_hash_config);
525 clib_memset (&hdr, 0, sizeof (hdr));
526 hdr.ip.protocol = IP_PROTOCOL_TCP;
527 clib_memcpy_fast (&hdr.ip.src_address, &tc->c_lcl_ip.ip6,
528 sizeof (ip6_address_t));
529 clib_memcpy_fast (&hdr.ip.dst_address, &tc->c_rmt_ip.ip6,
530 sizeof (ip6_address_t));
531 hdr.tcp.src_port = tc->c_lcl_port;
532 hdr.tcp.dst_port = tc->c_rmt_port;
533 hash = ip6_compute_flow_hash (&hdr.ip, lb->lb_hash_config);
535 choice = load_balance_get_bucket_i (lb, hash & lb->lb_n_buckets_minus_1);
536 dpo_copy (result, choice);
540 tcp_lookup_rmt_in_fib (tcp_connection_t * tc)
545 clib_memcpy_fast (&prefix.fp_addr, &tc->c_rmt_ip, sizeof (prefix.fp_addr));
546 prefix.fp_proto = tc->c_is_ip4 ? FIB_PROTOCOL_IP4 : FIB_PROTOCOL_IP6;
547 prefix.fp_len = tc->c_is_ip4 ? 32 : 128;
548 fib_index = fib_table_find (prefix.fp_proto, tc->c_fib_index);
549 return fib_table_lookup (fib_index, &prefix);
553 tcp_connection_stack_on_fib_entry (tcp_connection_t * tc)
555 dpo_id_t choice = DPO_INVALID;
556 u32 output_node_index;
559 fe = fib_entry_get (tc->c_rmt_fei);
560 if (fe->fe_lb.dpoi_type != DPO_LOAD_BALANCE)
563 tcp_connection_select_lb_bucket (tc, &fe->fe_lb, &choice);
566 tc->c_is_ip4 ? tcp4_output_node.index : tcp6_output_node.index;
567 dpo_stack_from_node (output_node_index, &tc->c_rmt_dpo, &choice);
571 /** Stack tcp connection on peer's fib entry.
573 * This ultimately populates the dpo the connection will use to send packets.
576 tcp_connection_fib_attach (tcp_connection_t * tc)
578 tc->c_rmt_fei = tcp_lookup_rmt_in_fib (tc);
580 ASSERT (tc->c_rmt_fei != FIB_NODE_INDEX_INVALID);
582 tcp_connection_stack_on_fib_entry (tc);
587 * Generate random iss as per rfc6528
590 tcp_generate_random_iss (tcp_connection_t * tc)
592 tcp_main_t *tm = &tcp_main;
596 tmp = (u64) tc->c_lcl_ip.ip4.as_u32 << 32 | (u64) tc->c_rmt_ip.ip4.as_u32;
598 tmp = tc->c_lcl_ip.ip6.as_u64[0] ^ tc->c_lcl_ip.ip6.as_u64[1]
599 ^ tc->c_rmt_ip.ip6.as_u64[0] ^ tc->c_rmt_ip.ip6.as_u64[1];
601 tmp ^= tm->iss_seed.first | ((u64) tc->c_lcl_port << 16 | tc->c_rmt_port);
602 tmp ^= tm->iss_seed.second;
603 tmp = clib_xxhash (tmp) + clib_cpu_time_now ();
604 return ((tmp >> 32) ^ (tmp & 0xffffffff));
608 * Initialize max segment size we're able to process.
610 * The value is constrained by the output interface's MTU and by the size
611 * of the IP and TCP headers (see RFC6691). It is also what we advertise
615 tcp_init_rcv_mss (tcp_connection_t * tc)
619 /* Already provided at connection init time */
623 ip_hdr_len = tc->c_is_ip4 ? sizeof (ip4_header_t) : sizeof (ip6_header_t);
624 tc->mss = tcp_cfg.default_mtu - sizeof (tcp_header_t) - ip_hdr_len;
628 tcp_init_mss (tcp_connection_t * tc)
630 u16 default_min_mss = 536;
632 tcp_init_rcv_mss (tc);
634 /* TODO consider PMTU discovery */
635 tc->snd_mss = clib_min (tc->rcv_opts.mss, tc->mss);
637 if (tc->snd_mss < 45)
639 /* Assume that at least the min default mss works */
640 tc->snd_mss = default_min_mss;
641 tc->rcv_opts.mss = default_min_mss;
644 /* We should have enough space for 40 bytes of options */
645 ASSERT (tc->snd_mss > 45);
647 /* If we use timestamp option, account for it */
648 if (tcp_opts_tstamp (&tc->rcv_opts))
649 tc->snd_mss -= TCP_OPTION_LEN_TIMESTAMP;
653 * Initialize connection send variables.
656 tcp_init_snd_vars (tcp_connection_t * tc)
659 * We use the time to randomize iss and for setting up the initial
660 * timestamp. Make sure it's updated otherwise syn and ack in the
661 * handshake may make it look as if time has flown in the opposite
664 tcp_set_time_now (tcp_get_worker (vlib_get_thread_index ()));
666 tcp_init_rcv_mss (tc);
667 tc->iss = tcp_generate_random_iss (tc);
668 tc->snd_una = tc->iss;
669 tc->snd_nxt = tc->iss + 1;
670 tc->snd_una_max = tc->snd_nxt;
671 tc->srtt = 100; /* 100 ms */
673 if (!tcp_cfg.csum_offload)
674 tc->cfg_flags |= TCP_CFG_F_NO_CSUM_OFFLOAD;
678 tcp_enable_pacing (tcp_connection_t * tc)
681 byte_rate = tc->cwnd / (tc->srtt * TCP_TICK);
682 transport_connection_tx_pacer_init (&tc->connection, byte_rate, tc->cwnd);
683 tc->mrtt_us = (u32) ~ 0;
686 /** Initialize tcp connection variables
688 * Should be called after having received a msg from the peer, i.e., a SYN or
689 * a SYNACK, such that connection options have already been exchanged. */
691 tcp_connection_init_vars (tcp_connection_t * tc)
693 tcp_connection_timers_init (tc);
695 scoreboard_init (&tc->sack_sb);
696 if (tc->state == TCP_STATE_SYN_RCVD)
697 tcp_init_snd_vars (tc);
701 if (!tc->c_is_ip4 && ip6_address_is_link_local_unicast (&tc->c_rmt_ip6))
702 tcp_add_del_adjacency (tc, 1);
704 /* tcp_connection_fib_attach (tc); */
706 if (transport_connection_is_tx_paced (&tc->connection)
707 || tcp_cfg.enable_tx_pacing)
708 tcp_enable_pacing (tc);
710 if (tc->cfg_flags & TCP_CFG_F_RATE_SAMPLE)
713 if (!tcp_cfg.allow_tso)
714 tc->cfg_flags |= TCP_CFG_F_NO_TSO;
716 tc->start_ts = tcp_time_now_us (tc->c_thread_index);
720 tcp_alloc_custom_local_endpoint (tcp_main_t * tm, ip46_address_t * lcl_addr,
721 u16 * lcl_port, u8 is_ip4)
726 index = tm->last_v4_addr_rotor++;
727 if (tm->last_v4_addr_rotor >= vec_len (tcp_cfg.ip4_src_addrs))
728 tm->last_v4_addr_rotor = 0;
729 lcl_addr->ip4.as_u32 = tcp_cfg.ip4_src_addrs[index].as_u32;
733 index = tm->last_v6_addr_rotor++;
734 if (tm->last_v6_addr_rotor >= vec_len (tcp_cfg.ip6_src_addrs))
735 tm->last_v6_addr_rotor = 0;
736 clib_memcpy_fast (&lcl_addr->ip6, &tcp_cfg.ip6_src_addrs[index],
737 sizeof (ip6_address_t));
739 port = transport_alloc_local_port (TRANSPORT_PROTO_TCP, lcl_addr);
741 return SESSION_E_NOPORT;
747 tcp_session_open (transport_endpoint_cfg_t * rmt)
749 tcp_main_t *tm = vnet_get_tcp_main ();
750 tcp_connection_t *tc;
751 ip46_address_t lcl_addr;
756 * Allocate local endpoint
758 if ((rmt->is_ip4 && vec_len (tcp_cfg.ip4_src_addrs))
759 || (!rmt->is_ip4 && vec_len (tcp_cfg.ip6_src_addrs)))
760 rv = tcp_alloc_custom_local_endpoint (tm, &lcl_addr, &lcl_port,
763 rv = transport_alloc_local_endpoint (TRANSPORT_PROTO_TCP,
764 rmt, &lcl_addr, &lcl_port);
770 * Create connection and send SYN
772 clib_spinlock_lock_if_init (&tm->half_open_lock);
773 tc = tcp_half_open_connection_new ();
774 ip_copy (&tc->c_rmt_ip, &rmt->ip, rmt->is_ip4);
775 ip_copy (&tc->c_lcl_ip, &lcl_addr, rmt->is_ip4);
776 tc->c_rmt_port = rmt->port;
777 tc->c_lcl_port = clib_host_to_net_u16 (lcl_port);
778 tc->c_is_ip4 = rmt->is_ip4;
779 tc->c_proto = TRANSPORT_PROTO_TCP;
780 tc->c_fib_index = rmt->fib_index;
781 tc->cc_algo = tcp_cc_algo_get (tcp_cfg.cc_algo);
782 /* The other connection vars will be initialized after SYN ACK */
783 tcp_connection_timers_init (tc);
786 TCP_EVT (TCP_EVT_OPEN, tc);
787 tc->state = TCP_STATE_SYN_SENT;
788 tcp_init_snd_vars (tc);
790 clib_spinlock_unlock_if_init (&tm->half_open_lock);
792 return tc->c_c_index;
796 format_tcp_session (u8 * s, va_list * args)
798 u32 tci = va_arg (*args, u32);
799 u32 thread_index = va_arg (*args, u32);
800 u32 verbose = va_arg (*args, u32);
801 tcp_connection_t *tc;
803 tc = tcp_connection_get (tci, thread_index);
805 s = format (s, "%U", format_tcp_connection, tc, verbose);
807 s = format (s, "empty\n");
812 format_tcp_listener_session (u8 * s, va_list * args)
814 u32 tci = va_arg (*args, u32);
815 u32 __clib_unused thread_index = va_arg (*args, u32);
816 u32 verbose = va_arg (*args, u32);
817 tcp_connection_t *tc = tcp_listener_get (tci);
818 s = format (s, "%-50U", format_tcp_connection_id, tc);
820 s = format (s, "%-15U", format_tcp_state, tc->state);
825 format_tcp_half_open_session (u8 * s, va_list * args)
827 u32 tci = va_arg (*args, u32);
828 u32 __clib_unused thread_index = va_arg (*args, u32);
829 tcp_connection_t *tc = tcp_half_open_connection_get (tci);
830 return format (s, "%U", format_tcp_connection_id, tc);
833 static transport_connection_t *
834 tcp_session_get_transport (u32 conn_index, u32 thread_index)
836 tcp_connection_t *tc = tcp_connection_get (conn_index, thread_index);
837 if (PREDICT_FALSE (!tc))
839 return &tc->connection;
842 static transport_connection_t *
843 tcp_half_open_session_get_transport (u32 conn_index)
845 tcp_connection_t *tc = tcp_half_open_connection_get (conn_index);
846 return &tc->connection;
850 tcp_session_cal_goal_size (tcp_connection_t * tc)
852 u16 goal_size = tc->snd_mss;
854 goal_size = TCP_MAX_GSO_SZ - tc->snd_mss % TCP_MAX_GSO_SZ;
855 goal_size = clib_min (goal_size, tc->snd_wnd / 2);
857 return goal_size > tc->snd_mss ? goal_size : tc->snd_mss;
861 tcp_round_snd_space (tcp_connection_t * tc, u32 snd_space)
863 if (PREDICT_FALSE (tc->snd_wnd < tc->snd_mss))
865 return tc->snd_wnd <= snd_space ? tc->snd_wnd : 0;
868 /* If not snd_wnd constrained and we can't write at least a segment,
869 * don't try at all */
870 if (PREDICT_FALSE (snd_space < tc->snd_mss))
871 return snd_space < tc->cwnd ? 0 : snd_space;
873 /* round down to mss multiple */
874 return snd_space - (snd_space % tc->snd_mss);
878 * Compute tx window session is allowed to fill.
880 * Takes into account available send space, snd_mss and the congestion
881 * state of the connection. If possible, the value returned is a multiple
884 * @param tc tcp connection
885 * @return number of bytes session is allowed to write
888 tcp_snd_space_inline (tcp_connection_t * tc)
892 if (PREDICT_FALSE (tcp_in_fastrecovery (tc)
893 || tc->state == TCP_STATE_CLOSED))
896 snd_space = tcp_available_output_snd_space (tc);
898 /* If we got dupacks or sacked bytes but we're not yet in recovery, try
899 * to force the peer to send enough dupacks to start retransmitting as
900 * per Limited Transmit (RFC3042)
902 if (PREDICT_FALSE (tc->rcv_dupacks != 0 || tc->sack_sb.sacked_bytes))
904 if (tc->limited_transmit != tc->snd_nxt
905 && (seq_lt (tc->limited_transmit, tc->snd_nxt - 2 * tc->snd_mss)
906 || seq_gt (tc->limited_transmit, tc->snd_nxt)))
907 tc->limited_transmit = tc->snd_nxt;
909 ASSERT (seq_leq (tc->limited_transmit, tc->snd_nxt));
911 int snt_limited = tc->snd_nxt - tc->limited_transmit;
912 snd_space = clib_max ((int) 2 * tc->snd_mss - snt_limited, 0);
914 return tcp_round_snd_space (tc, snd_space);
918 tcp_snd_space (tcp_connection_t * tc)
920 return tcp_snd_space_inline (tc);
924 tcp_session_send_params (transport_connection_t * trans_conn,
925 transport_send_params_t * sp)
927 tcp_connection_t *tc = (tcp_connection_t *) trans_conn;
929 /* Ensure snd_mss does accurately reflect the amount of data we can push
930 * in a segment. This also makes sure that options are updated according to
931 * the current state of the connection. */
932 tcp_update_burst_snd_vars (tc);
934 if (PREDICT_FALSE (tc->cfg_flags & TCP_CFG_F_TSO))
935 sp->snd_mss = tcp_session_cal_goal_size (tc);
937 sp->snd_mss = tc->snd_mss;
939 sp->snd_space = clib_min (tcp_snd_space_inline (tc),
940 tc->snd_wnd - (tc->snd_nxt - tc->snd_una));
942 ASSERT (seq_geq (tc->snd_nxt, tc->snd_una));
943 /* This still works if fast retransmit is on */
944 sp->tx_offset = tc->snd_nxt - tc->snd_una;
946 sp->flags = sp->snd_space ? 0 : TRANSPORT_SND_F_DESCHED;
952 tcp_timer_waitclose_handler (tcp_connection_t * tc)
954 tcp_worker_ctx_t *wrk = tcp_get_worker (tc->c_thread_index);
958 case TCP_STATE_CLOSE_WAIT:
959 tcp_connection_timers_reset (tc);
960 /* App never returned with a close */
961 if (!(tc->flags & TCP_CONN_FINPNDG))
963 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
964 session_transport_closed_notify (&tc->connection);
965 tcp_program_cleanup (wrk, tc);
966 tcp_worker_stats_inc (wrk, to_closewait, 1);
970 /* Send FIN either way and switch to LAST_ACK. */
971 tcp_cong_recovery_off (tc);
972 /* Make sure we don't try to send unsent data */
973 tc->snd_nxt = tc->snd_una;
975 tcp_connection_set_state (tc, TCP_STATE_LAST_ACK);
976 session_transport_closed_notify (&tc->connection);
978 /* Make sure we don't wait in LAST ACK forever */
979 tcp_timer_set (&wrk->timer_wheel, tc, TCP_TIMER_WAITCLOSE,
980 tcp_cfg.lastack_time);
981 tcp_worker_stats_inc (wrk, to_closewait2, 1);
983 /* Don't delete the connection yet */
985 case TCP_STATE_FIN_WAIT_1:
986 tcp_connection_timers_reset (tc);
987 if (tc->flags & TCP_CONN_FINPNDG)
989 /* If FIN pending, we haven't sent everything, but we did try.
990 * Notify session layer that transport is closed. */
991 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
993 tcp_program_cleanup (wrk, tc);
997 /* We've sent the fin but no progress. Close the connection and
998 * to make sure everything is flushed, setup a cleanup timer */
999 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
1000 tcp_program_cleanup (wrk, tc);
1002 session_transport_closed_notify (&tc->connection);
1003 tcp_worker_stats_inc (wrk, to_finwait1, 1);
1005 case TCP_STATE_LAST_ACK:
1006 tcp_connection_timers_reset (tc);
1007 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
1008 session_transport_closed_notify (&tc->connection);
1009 tcp_program_cleanup (wrk, tc);
1010 tcp_worker_stats_inc (wrk, to_lastack, 1);
1012 case TCP_STATE_CLOSING:
1013 tcp_connection_timers_reset (tc);
1014 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
1015 session_transport_closed_notify (&tc->connection);
1016 tcp_program_cleanup (wrk, tc);
1017 tcp_worker_stats_inc (wrk, to_closing, 1);
1019 case TCP_STATE_FIN_WAIT_2:
1020 tcp_send_reset (tc);
1021 tcp_connection_timers_reset (tc);
1022 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
1023 session_transport_closed_notify (&tc->connection);
1024 tcp_program_cleanup (wrk, tc);
1025 tcp_worker_stats_inc (wrk, to_finwait2, 1);
1027 case TCP_STATE_TIME_WAIT:
1028 tcp_connection_set_state (tc, TCP_STATE_CLOSED);
1029 tcp_program_cleanup (wrk, tc);
1032 clib_warning ("waitclose in state: %U", format_tcp_state, tc->state);
1038 static timer_expiration_handler *timer_expiration_handlers[TCP_N_TIMERS] =
1040 tcp_timer_retransmit_handler,
1041 tcp_timer_delack_handler,
1042 tcp_timer_persist_handler,
1043 tcp_timer_waitclose_handler,
1044 tcp_timer_retransmit_syn_handler,
1049 tcp_dispatch_pending_timers (tcp_worker_ctx_t * wrk)
1051 u32 n_timers, connection_index, timer_id, thread_index, timer_handle;
1052 tcp_connection_t *tc;
1055 if (!(n_timers = clib_fifo_elts (wrk->pending_timers)))
1058 thread_index = wrk->vm->thread_index;
1059 for (i = 0; i < clib_min (n_timers, wrk->max_timers_per_loop); i++)
1061 clib_fifo_sub1 (wrk->pending_timers, timer_handle);
1062 connection_index = timer_handle & 0x0FFFFFFF;
1063 timer_id = timer_handle >> 28;
1065 if (PREDICT_TRUE (timer_id != TCP_TIMER_RETRANSMIT_SYN))
1066 tc = tcp_connection_get (connection_index, thread_index);
1068 tc = tcp_half_open_connection_get (connection_index);
1070 if (PREDICT_FALSE (!tc))
1073 /* Skip timer if it was rearmed while pending dispatch */
1074 if (PREDICT_FALSE (tc->timers[timer_id] != TCP_TIMER_HANDLE_INVALID))
1077 (*timer_expiration_handlers[timer_id]) (tc);
1080 if (thread_index == 0 && clib_fifo_elts (wrk->pending_timers))
1081 session_queue_run_on_main_thread (wrk->vm);
1085 tcp_handle_cleanups (tcp_worker_ctx_t * wrk, clib_time_type_t now)
1087 u32 thread_index = wrk->vm->thread_index;
1088 tcp_cleanup_req_t *req;
1089 tcp_connection_t *tc;
1091 while (clib_fifo_elts (wrk->pending_cleanups))
1093 req = clib_fifo_head (wrk->pending_cleanups);
1094 if (req->free_time > now)
1096 clib_fifo_sub2 (wrk->pending_cleanups, req);
1097 tc = tcp_connection_get (req->connection_index, thread_index);
1098 if (PREDICT_FALSE (!tc))
1100 session_transport_delete_notify (&tc->connection);
1101 tcp_connection_cleanup (tc);
1106 tcp_update_time (f64 now, u8 thread_index)
1108 tcp_worker_ctx_t *wrk = tcp_get_worker (thread_index);
1110 tcp_set_time_now (wrk);
1111 tcp_handle_cleanups (wrk, now);
1112 tw_timer_expire_timers_16t_2w_512sl (&wrk->timer_wheel, now);
1113 tcp_dispatch_pending_timers (wrk);
1117 tcp_session_flush_data (transport_connection_t * tconn)
1119 tcp_connection_t *tc = (tcp_connection_t *) tconn;
1120 if (tc->flags & TCP_CONN_PSH_PENDING)
1122 tc->flags |= TCP_CONN_PSH_PENDING;
1123 tc->psh_seq = tc->snd_una + transport_max_tx_dequeue (tconn) - 1;
1127 const static transport_proto_vft_t tcp_proto = {
1128 .enable = vnet_tcp_enable_disable,
1129 .start_listen = tcp_session_bind,
1130 .stop_listen = tcp_session_unbind,
1131 .push_header = tcp_session_push_header,
1132 .get_connection = tcp_session_get_transport,
1133 .get_listener = tcp_session_get_listener,
1134 .get_half_open = tcp_half_open_session_get_transport,
1135 .connect = tcp_session_open,
1136 .close = tcp_session_close,
1137 .cleanup = tcp_session_cleanup,
1138 .reset = tcp_session_reset,
1139 .send_params = tcp_session_send_params,
1140 .update_time = tcp_update_time,
1141 .flush_data = tcp_session_flush_data,
1142 .custom_tx = tcp_session_custom_tx,
1143 .format_connection = format_tcp_session,
1144 .format_listener = format_tcp_listener_session,
1145 .format_half_open = format_tcp_half_open_session,
1146 .transport_options = {
1149 .tx_type = TRANSPORT_TX_PEEK,
1150 .service_type = TRANSPORT_SERVICE_VC,
1156 tcp_connection_tx_pacer_update (tcp_connection_t * tc)
1158 if (!transport_connection_is_tx_paced (&tc->connection))
1161 f64 srtt = clib_min ((f64) tc->srtt * TCP_TICK, tc->mrtt_us);
1163 transport_connection_tx_pacer_update (&tc->connection,
1164 tcp_cc_get_pacing_rate (tc),
1165 srtt * CLIB_US_TIME_FREQ);
1169 tcp_connection_tx_pacer_reset (tcp_connection_t * tc, u32 window,
1172 f64 srtt = clib_min ((f64) tc->srtt * TCP_TICK, tc->mrtt_us);
1173 transport_connection_tx_pacer_reset (&tc->connection,
1174 tcp_cc_get_pacing_rate (tc),
1176 srtt * CLIB_US_TIME_FREQ);
1180 tcp_reschedule (tcp_connection_t * tc)
1182 if (tcp_in_cong_recovery (tc) || tcp_snd_space_inline (tc))
1183 transport_connection_reschedule (&tc->connection);
1187 tcp_expired_timers_dispatch (u32 * expired_timers)
1189 u32 thread_index = vlib_get_thread_index (), n_left, max_per_loop;
1190 u32 connection_index, timer_id, n_expired, max_loops;
1191 tcp_worker_ctx_t *wrk;
1192 tcp_connection_t *tc;
1195 wrk = tcp_get_worker (thread_index);
1196 n_expired = vec_len (expired_timers);
1197 tcp_worker_stats_inc (wrk, timer_expirations, n_expired);
1198 n_left = clib_fifo_elts (wrk->pending_timers);
1201 * Invalidate all timer handles before dispatching. This avoids dangling
1202 * index references to timer wheel pool entries that have been freed.
1204 for (i = 0; i < n_expired; i++)
1206 connection_index = expired_timers[i] & 0x0FFFFFFF;
1207 timer_id = expired_timers[i] >> 28;
1209 if (timer_id != TCP_TIMER_RETRANSMIT_SYN)
1210 tc = tcp_connection_get (connection_index, thread_index);
1212 tc = tcp_half_open_connection_get (connection_index);
1214 TCP_EVT (TCP_EVT_TIMER_POP, connection_index, timer_id);
1216 tc->timers[timer_id] = TCP_TIMER_HANDLE_INVALID;
1219 clib_fifo_add (wrk->pending_timers, expired_timers, n_expired);
1221 max_loops = clib_max (1, 0.5 * TCP_TIMER_TICK * wrk->vm->loops_per_second);
1222 max_per_loop = clib_max ((n_left + n_expired) / max_loops, 10);
1223 max_per_loop = clib_min (max_per_loop, VLIB_FRAME_SIZE);
1224 wrk->max_timers_per_loop = clib_max (n_left ? wrk->max_timers_per_loop : 0,
1227 if (thread_index == 0)
1228 session_queue_run_on_main_thread (wrk->vm);
1232 tcp_initialize_timer_wheels (tcp_main_t * tm)
1234 tw_timer_wheel_16t_2w_512sl_t *tw;
1236 foreach_vlib_main (({
1237 tw = &tm->wrk_ctx[ii].timer_wheel;
1238 tw_timer_wheel_init_16t_2w_512sl (tw, tcp_expired_timers_dispatch,
1239 TCP_TIMER_TICK, ~0);
1240 tw->last_run_time = vlib_time_now (this_vlib_main);
1246 tcp_initialize_iss_seed (tcp_main_t * tm)
1248 u32 default_seed = random_default_seed ();
1249 u64 time_now = clib_cpu_time_now ();
1251 tm->iss_seed.first = (u64) random_u32 (&default_seed) << 32;
1252 tm->iss_seed.second = random_u64 (&time_now);
1255 static clib_error_t *
1256 tcp_main_enable (vlib_main_t * vm)
1258 vlib_thread_main_t *vtm = vlib_get_thread_main ();
1259 u32 num_threads, n_workers, prealloc_conn_per_wrk;
1260 tcp_connection_t *tc __attribute__ ((unused));
1261 tcp_main_t *tm = vnet_get_tcp_main ();
1262 tcp_worker_ctx_t *wrk;
1263 clib_error_t *error = 0;
1266 if ((error = vlib_call_init_function (vm, ip_main_init)))
1268 if ((error = vlib_call_init_function (vm, ip4_lookup_init)))
1270 if ((error = vlib_call_init_function (vm, ip6_lookup_init)))
1277 ip4_register_protocol (IP_PROTOCOL_TCP, tcp4_input_node.index);
1278 ip6_register_protocol (IP_PROTOCOL_TCP, tcp6_input_node.index);
1281 * Initialize data structures
1284 num_threads = 1 /* main thread */ + vtm->n_threads;
1285 vec_validate (tm->wrk_ctx, num_threads - 1);
1286 n_workers = num_threads == 1 ? 1 : vtm->n_threads;
1287 prealloc_conn_per_wrk = tcp_cfg.preallocated_connections / n_workers;
1289 wrk = &tm->wrk_ctx[0];
1290 wrk->tco_next_node[0] = vlib_node_get_next (vm, session_queue_node.index,
1291 tcp4_output_node.index);
1292 wrk->tco_next_node[1] = vlib_node_get_next (vm, session_queue_node.index,
1293 tcp6_output_node.index);
1295 for (thread = 0; thread < num_threads; thread++)
1297 wrk = &tm->wrk_ctx[thread];
1299 vec_validate (wrk->pending_deq_acked, 255);
1300 vec_validate (wrk->pending_disconnects, 255);
1301 vec_validate (wrk->pending_resets, 255);
1302 vec_reset_length (wrk->pending_deq_acked);
1303 vec_reset_length (wrk->pending_disconnects);
1304 vec_reset_length (wrk->pending_resets);
1305 wrk->vm = vlib_mains[thread];
1306 wrk->max_timers_per_loop = 10;
1310 wrk->tco_next_node[0] = tm->wrk_ctx[0].tco_next_node[0];
1311 wrk->tco_next_node[1] = tm->wrk_ctx[0].tco_next_node[1];
1315 * Preallocate connections. Assume that thread 0 won't
1316 * use preallocated threads when running multi-core
1318 if ((thread > 0 || num_threads == 1) && prealloc_conn_per_wrk)
1319 pool_init_fixed (wrk->connections, prealloc_conn_per_wrk);
1323 * Use a preallocated half-open connection pool?
1325 if (tcp_cfg.preallocated_half_open_connections)
1326 pool_init_fixed (tm->half_open_connections,
1327 tcp_cfg.preallocated_half_open_connections);
1329 /* Initialize clocks per tick for TCP timestamp. Used to compute
1330 * monotonically increasing timestamps. */
1331 tm->tstamp_ticks_per_clock = vm->clib_time.seconds_per_clock
1332 / TCP_TSTAMP_RESOLUTION;
1334 if (num_threads > 1)
1336 clib_spinlock_init (&tm->half_open_lock);
1339 tcp_initialize_timer_wheels (tm);
1340 tcp_initialize_iss_seed (tm);
1342 tm->bytes_per_buffer = vlib_buffer_get_default_data_size (vm);
1343 tm->cc_last_type = TCP_CC_LAST;
1345 tm->ipl_next_node[0] = vlib_node_get_next (vm, session_queue_node.index,
1346 ip4_lookup_node.index);
1347 tm->ipl_next_node[1] = vlib_node_get_next (vm, session_queue_node.index,
1348 ip6_lookup_node.index);
1353 vnet_tcp_enable_disable (vlib_main_t * vm, u8 is_en)
1357 if (tcp_main.is_enabled)
1360 return tcp_main_enable (vm);
1364 tcp_main.is_enabled = 0;
1371 tcp_punt_unknown (vlib_main_t * vm, u8 is_ip4, u8 is_add)
1373 tcp_main_t *tm = &tcp_main;
1375 tm->punt_unknown4 = is_add;
1377 tm->punt_unknown6 = is_add;
1381 * Initialize default values for tcp parameters
1384 tcp_configuration_init (void)
1386 /* Initial wnd for SYN. Fifos are not allocated at that point so use some
1387 * predefined value. For SYN-ACK we still want the scale to be computed in
1389 tcp_cfg.max_rx_fifo = 32 << 20;
1390 tcp_cfg.min_rx_fifo = 4 << 10;
1392 tcp_cfg.default_mtu = 1500;
1393 tcp_cfg.initial_cwnd_multiplier = 0;
1394 tcp_cfg.enable_tx_pacing = 1;
1395 tcp_cfg.allow_tso = 0;
1396 tcp_cfg.csum_offload = 1;
1397 tcp_cfg.cc_algo = TCP_CC_NEWRENO;
1398 tcp_cfg.rwnd_min_update_ack = 1;
1400 /* Time constants defined as timer tick (100ms) multiples */
1401 tcp_cfg.delack_time = 1; /* 0.1s */
1402 tcp_cfg.closewait_time = 20; /* 2s */
1403 tcp_cfg.timewait_time = 100; /* 10s */
1404 tcp_cfg.finwait1_time = 600; /* 60s */
1405 tcp_cfg.lastack_time = 300; /* 30s */
1406 tcp_cfg.finwait2_time = 300; /* 30s */
1407 tcp_cfg.closing_time = 300; /* 30s */
1408 tcp_cfg.cleanup_time = 0.1; /* 100ms */
1411 static clib_error_t *
1412 tcp_init (vlib_main_t * vm)
1414 tcp_main_t *tm = vnet_get_tcp_main ();
1415 ip_main_t *im = &ip_main;
1416 ip_protocol_info_t *pi;
1418 /* Session layer, and by implication tcp, are disabled by default */
1421 /* Register with IP for header parsing */
1422 pi = ip_get_protocol_info (im, IP_PROTOCOL_TCP);
1424 return clib_error_return (0, "TCP protocol info AWOL");
1425 pi->format_header = format_tcp_header;
1426 pi->unformat_pg_edit = unformat_pg_tcp_header;
1428 /* Register as transport with session layer */
1429 transport_register_protocol (TRANSPORT_PROTO_TCP, &tcp_proto,
1430 FIB_PROTOCOL_IP4, tcp4_output_node.index);
1431 transport_register_protocol (TRANSPORT_PROTO_TCP, &tcp_proto,
1432 FIB_PROTOCOL_IP6, tcp6_output_node.index);
1434 tcp_configuration_init ();
1436 tm->cc_algo_by_name = hash_create_string (0, sizeof (uword));
1441 VLIB_INIT_FUNCTION (tcp_init);
1444 * fd.io coding-style-patch-verification: ON
1447 * eval: (c-set-style "gnu")