2 * Copyright (c) 2016 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
15 #include <vnet/ip/ip.h>
16 #include <vnet/ip/ip_source_and_port_range_check.h>
19 vlib_node_registration_t ip4_source_port_and_range_check;
21 #define foreach_ip4_source_and_port_range_check_error \
22 _(CHECK_FAIL, "ip4 source and port range check bad packets") \
23 _(CHECK_OK, "ip4 source and port range check good packets")
27 #define _(sym,str) IP4_SOURCE_AND_PORT_RANGE_CHECK_ERROR_##sym,
28 foreach_ip4_source_and_port_range_check_error
30 IP4_SOURCE_AND_PORT_RANGE_CHECK_N_ERROR,
31 } ip4_source_and_port_range_check_error_t;
33 static char *ip4_source_and_port_range_check_error_strings[] = {
34 #define _(sym,string) string,
35 foreach_ip4_source_and_port_range_check_error
44 ip4_address_t src_addr;
47 } ip4_source_and_port_range_check_trace_t;
50 format_ip4_source_and_port_range_check_trace (u8 * s, va_list * va)
52 CLIB_UNUSED (vlib_main_t * vm) = va_arg (*va, vlib_main_t *);
53 CLIB_UNUSED (vlib_node_t * node) = va_arg (*va, vlib_node_t *);
54 ip4_source_and_port_range_check_trace_t *t =
55 va_arg (*va, ip4_source_and_port_range_check_trace_t *);
58 s = format (s, "PASS (bypass case)");
60 s = format (s, "fib %d src ip %U %s dst port %d: %s",
61 t->fib_index, format_ip4_address, &t->src_addr,
62 t->is_tcp ? "TCP" : "UDP", (u32) t->dst_port,
63 (t->pass == 1) ? "PASS" : "FAIL");
69 IP4_SOURCE_AND_PORT_RANGE_CHECK_NEXT_DROP,
70 IP4_SOURCE_AND_PORT_RANGE_CHECK_N_NEXT,
71 } ip4_source_and_port_range_check_next_t;
75 check_adj_port_range_x1 (ip_adjacency_t * adj, u16 dst_port, u32 next)
77 protocol_port_range_t *range;
81 u16x8vec_t sum, sum_equal_diff2;
82 u16 sum_nonzero, sum_equal, winner_mask;
86 if (adj->lookup_next_index != IP_LOOKUP_NEXT_ICMP_ERROR || dst_port == 0)
87 return IP4_SOURCE_AND_PORT_RANGE_CHECK_NEXT_DROP;
89 rwh = (u8 *) (&adj->rewrite_header);
90 range = (protocol_port_range_t *) rwh;
92 /* Make the obvious screw-case work. A variant also works w/ no MMX */
93 if (PREDICT_FALSE (dst_port == 65535))
98 i < VLIB_BUFFER_PRE_DATA_SIZE / sizeof (protocol_port_range_t);
101 for (j = 0; j < 8; j++)
102 if (range->low.as_u16[j] == 65535)
106 return IP4_SOURCE_AND_PORT_RANGE_CHECK_NEXT_DROP;
109 key.as_u16x8 = u16x8_splat (dst_port);
111 for (i = 0; i < VLIB_BUFFER_PRE_DATA_SIZE / sizeof (protocol_port_range_t);
114 diff1.as_u16x8 = u16x8_sub_saturate (range->low.as_u16x8, key.as_u16x8);
115 diff2.as_u16x8 = u16x8_sub_saturate (range->hi.as_u16x8, key.as_u16x8);
116 sum.as_u16x8 = u16x8_add (diff1.as_u16x8, diff2.as_u16x8);
117 sum_equal_diff2.as_u16x8 =
118 u16x8_is_equal (sum.as_u16x8, diff2.as_u16x8);
119 sum_nonzero = ~u16x8_zero_byte_mask (sum.as_u16x8);
120 sum_equal = ~u16x8_zero_byte_mask (sum_equal_diff2.as_u16x8);
121 winner_mask = sum_nonzero & sum_equal;
126 return IP4_SOURCE_AND_PORT_RANGE_CHECK_NEXT_DROP;
130 ip4_source_and_port_range_check_inline
131 (vlib_main_t * vm, vlib_node_runtime_t * node, vlib_frame_t * frame)
133 ip4_main_t *im = &ip4_main;
134 ip_lookup_main_t *lm = &im->lookup_main;
135 ip_config_main_t *cm = &lm->rx_config_mains[VNET_UNICAST];
136 u32 n_left_from, *from, *to_next;
138 vlib_node_runtime_t *error_node = node;
139 u32 good_packets = 0;
142 from = vlib_frame_vector_args (frame);
143 n_left_from = frame->n_vectors;
144 next_index = node->cached_next_index;
146 while (n_left_from > 0)
150 vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
153 while (n_left_from >= 4 && n_left_to_next >= 2)
155 vlib_buffer_t *b0, *b1;
156 ip4_header_t *ip0, *ip1;
157 ip4_fib_mtrie_t *mtrie0, *mtrie1;
158 ip4_fib_mtrie_leaf_t leaf0, leaf1;
159 ip_source_and_port_range_check_config_t *c0, *c1;
160 ip_adjacency_t *adj0 = 0, *adj1 = 0;
161 u32 bi0, next0, adj_index0, pass0, save_next0, fib_index0;
162 u32 bi1, next1, adj_index1, pass1, save_next1, fib_index1;
163 udp_header_t *udp0, *udp1;
165 /* Prefetch next iteration. */
167 vlib_buffer_t *p2, *p3;
169 p2 = vlib_get_buffer (vm, from[2]);
170 p3 = vlib_get_buffer (vm, from[3]);
172 vlib_prefetch_buffer_header (p2, LOAD);
173 vlib_prefetch_buffer_header (p3, LOAD);
175 CLIB_PREFETCH (p2->data, sizeof (ip0[0]), LOAD);
176 CLIB_PREFETCH (p3->data, sizeof (ip1[0]), LOAD);
179 bi0 = to_next[0] = from[0];
180 bi1 = to_next[1] = from[1];
186 b0 = vlib_get_buffer (vm, bi0);
187 b1 = vlib_get_buffer (vm, bi1);
190 vec_elt (im->fib_index_by_sw_if_index,
191 vnet_buffer (b0)->sw_if_index[VLIB_RX]);
193 vec_elt (im->fib_index_by_sw_if_index,
194 vnet_buffer (b1)->sw_if_index[VLIB_RX]);
196 ip0 = vlib_buffer_get_current (b0);
197 ip1 = vlib_buffer_get_current (b1);
199 c0 = vnet_get_config_data (&cm->config_main,
200 &b0->current_config_index,
201 &next0, sizeof (c0[0]));
202 c1 = vnet_get_config_data (&cm->config_main,
203 &b1->current_config_index,
204 &next1, sizeof (c1[0]));
206 /* we can't use the default VRF here... */
207 for (i = 0; i < IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS; i++)
209 ASSERT (c0->fib_index[i] && c1->fib_index[i]);
213 if (ip0->protocol == IP_PROTOCOL_UDP)
215 c0->fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT];
216 if (ip0->protocol == IP_PROTOCOL_TCP)
218 c0->fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT];
220 if (PREDICT_TRUE (fib_index0 != ~0))
223 mtrie0 = &vec_elt_at_index (im->fibs, fib_index0)->mtrie;
225 leaf0 = IP4_FIB_MTRIE_LEAF_ROOT;
227 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
228 &ip0->src_address, 0);
230 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
231 &ip0->src_address, 1);
233 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
234 &ip0->src_address, 2);
236 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
237 &ip0->src_address, 3);
239 adj_index0 = ip4_fib_mtrie_leaf_get_adj_index (leaf0);
241 ASSERT (adj_index0 == ip4_fib_lookup_with_table (im, fib_index0,
247 adj0 = ip_get_adjacency (lm, adj_index0);
250 if (ip1->protocol == IP_PROTOCOL_UDP)
252 c1->fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT];
253 if (ip1->protocol == IP_PROTOCOL_TCP)
255 c1->fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT];
257 if (PREDICT_TRUE (fib_index1 != ~0))
260 mtrie1 = &vec_elt_at_index (im->fibs, fib_index1)->mtrie;
262 leaf1 = IP4_FIB_MTRIE_LEAF_ROOT;
264 leaf1 = ip4_fib_mtrie_lookup_step (mtrie1, leaf1,
265 &ip1->src_address, 0);
267 leaf1 = ip4_fib_mtrie_lookup_step (mtrie1, leaf1,
268 &ip1->src_address, 1);
270 leaf1 = ip4_fib_mtrie_lookup_step (mtrie1, leaf1,
271 &ip1->src_address, 2);
273 leaf1 = ip4_fib_mtrie_lookup_step (mtrie1, leaf1,
274 &ip1->src_address, 3);
276 adj_index1 = ip4_fib_mtrie_leaf_get_adj_index (leaf1);
278 ASSERT (adj_index1 == ip4_fib_lookup_with_table (im, fib_index1,
282 adj1 = ip_get_adjacency (lm, adj_index1);
287 pass0 |= ip4_address_is_multicast (&ip0->src_address);
289 ip0->src_address.as_u32 == clib_host_to_net_u32 (0xFFFFFFFF);
290 pass0 |= (ip0->protocol != IP_PROTOCOL_UDP)
291 && (ip0->protocol != IP_PROTOCOL_TCP);
295 pass1 |= ip4_address_is_multicast (&ip1->src_address);
297 ip1->src_address.as_u32 == clib_host_to_net_u32 (0xFFFFFFFF);
298 pass1 |= (ip1->protocol != IP_PROTOCOL_UDP)
299 && (ip1->protocol != IP_PROTOCOL_TCP);
302 udp0 = ip4_next_header (ip0);
304 udp1 = ip4_next_header (ip1);
306 if (PREDICT_TRUE (pass0 == 0))
309 next0 = check_adj_port_range_x1
310 (adj0, clib_net_to_host_u16 (udp0->dst_port), next0);
311 good_packets -= (save_next0 != next0);
312 b0->error = error_node->errors
313 [IP4_SOURCE_AND_PORT_RANGE_CHECK_ERROR_CHECK_FAIL];
316 if (PREDICT_TRUE (pass1 == 0))
319 next1 = check_adj_port_range_x1
320 (adj1, clib_net_to_host_u16 (udp1->dst_port), next1);
321 good_packets -= (save_next1 != next1);
322 b1->error = error_node->errors
323 [IP4_SOURCE_AND_PORT_RANGE_CHECK_ERROR_CHECK_FAIL];
326 if (PREDICT_FALSE ((node->flags & VLIB_NODE_FLAG_TRACE)
327 && (b0->flags & VLIB_BUFFER_IS_TRACED)))
329 ip4_source_and_port_range_check_trace_t *t =
330 vlib_add_trace (vm, node, b0, sizeof (*t));
331 t->pass = next0 == save_next0;
333 t->fib_index = fib_index0;
334 t->src_addr.as_u32 = ip0->src_address.as_u32;
335 t->dst_port = (pass0 == 0) ?
336 clib_net_to_host_u16 (udp0->dst_port) : 0;
337 t->is_tcp = ip0->protocol == IP_PROTOCOL_TCP;
340 if (PREDICT_FALSE ((node->flags & VLIB_NODE_FLAG_TRACE)
341 && (b1->flags & VLIB_BUFFER_IS_TRACED)))
343 ip4_source_and_port_range_check_trace_t *t =
344 vlib_add_trace (vm, node, b1, sizeof (*t));
345 t->pass = next1 == save_next1;
347 t->fib_index = fib_index1;
348 t->src_addr.as_u32 = ip1->src_address.as_u32;
349 t->dst_port = (pass1 == 0) ?
350 clib_net_to_host_u16 (udp1->dst_port) : 0;
351 t->is_tcp = ip1->protocol == IP_PROTOCOL_TCP;
354 vlib_validate_buffer_enqueue_x2 (vm, node, next_index,
355 to_next, n_left_to_next,
356 bi0, bi1, next0, next1);
359 while (n_left_from > 0 && n_left_to_next > 0)
363 ip4_fib_mtrie_t *mtrie0;
364 ip4_fib_mtrie_leaf_t leaf0;
365 ip_source_and_port_range_check_config_t *c0;
366 ip_adjacency_t *adj0 = 0;
367 u32 bi0, next0, adj_index0, pass0, save_next0, fib_index0;
377 b0 = vlib_get_buffer (vm, bi0);
380 vec_elt (im->fib_index_by_sw_if_index,
381 vnet_buffer (b0)->sw_if_index[VLIB_RX]);
383 ip0 = vlib_buffer_get_current (b0);
385 c0 = vnet_get_config_data
386 (&cm->config_main, &b0->current_config_index,
387 &next0, sizeof (c0[0]));
389 /* we can't use the default VRF here... */
390 for (i = 0; i < IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS; i++)
392 ASSERT (c0->fib_index[i]);
396 if (ip0->protocol == IP_PROTOCOL_UDP)
398 c0->fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT];
399 if (ip0->protocol == IP_PROTOCOL_TCP)
401 c0->fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT];
403 if (fib_index0 != ~0)
406 mtrie0 = &vec_elt_at_index (im->fibs, fib_index0)->mtrie;
408 leaf0 = IP4_FIB_MTRIE_LEAF_ROOT;
410 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
411 &ip0->src_address, 0);
413 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
414 &ip0->src_address, 1);
416 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
417 &ip0->src_address, 2);
419 leaf0 = ip4_fib_mtrie_lookup_step (mtrie0, leaf0,
420 &ip0->src_address, 3);
422 adj_index0 = ip4_fib_mtrie_leaf_get_adj_index (leaf0);
424 ASSERT (adj_index0 == ip4_fib_lookup_with_table
426 &ip0->src_address, 0 /* use default route */ ));
427 adj0 = ip_get_adjacency (lm, adj_index0);
430 * $$$ which (src,dst) categories should we always pass?
434 pass0 |= ip4_address_is_multicast (&ip0->src_address);
436 ip0->src_address.as_u32 == clib_host_to_net_u32 (0xFFFFFFFF);
437 pass0 |= (ip0->protocol != IP_PROTOCOL_UDP)
438 && (ip0->protocol != IP_PROTOCOL_TCP);
441 udp0 = ip4_next_header (ip0);
443 if (PREDICT_TRUE (pass0 == 0))
446 next0 = check_adj_port_range_x1
447 (adj0, clib_net_to_host_u16 (udp0->dst_port), next0);
448 good_packets -= (save_next0 != next0);
449 b0->error = error_node->errors
450 [IP4_SOURCE_AND_PORT_RANGE_CHECK_ERROR_CHECK_FAIL];
453 if (PREDICT_FALSE ((node->flags & VLIB_NODE_FLAG_TRACE)
454 && (b0->flags & VLIB_BUFFER_IS_TRACED)))
456 ip4_source_and_port_range_check_trace_t *t =
457 vlib_add_trace (vm, node, b0, sizeof (*t));
458 t->pass = next0 == save_next0;
460 t->fib_index = fib_index0;
461 t->src_addr.as_u32 = ip0->src_address.as_u32;
462 t->dst_port = (pass0 == 0) ?
463 clib_net_to_host_u16 (udp0->dst_port) : 0;
464 t->is_tcp = ip0->protocol == IP_PROTOCOL_TCP;
467 vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
468 to_next, n_left_to_next,
472 vlib_put_next_frame (vm, node, next_index, n_left_to_next);
475 vlib_node_increment_counter (vm, ip4_source_port_and_range_check.index,
476 IP4_SOURCE_AND_PORT_RANGE_CHECK_ERROR_CHECK_OK,
478 return frame->n_vectors;
482 ip4_source_and_port_range_check (vlib_main_t * vm,
483 vlib_node_runtime_t * node,
484 vlib_frame_t * frame)
486 return ip4_source_and_port_range_check_inline (vm, node, frame);
490 VLIB_REGISTER_NODE (ip4_source_port_and_range_check) = {
491 .function = ip4_source_and_port_range_check,
492 .name = "ip4-source-and-port-range-check",
493 .vector_size = sizeof (u32),
495 .n_errors = ARRAY_LEN(ip4_source_and_port_range_check_error_strings),
496 .error_strings = ip4_source_and_port_range_check_error_strings,
498 .n_next_nodes = IP4_SOURCE_AND_PORT_RANGE_CHECK_N_NEXT,
500 [IP4_SOURCE_AND_PORT_RANGE_CHECK_NEXT_DROP] = "error-drop",
503 .format_buffer = format_ip4_header,
504 .format_trace = format_ip4_source_and_port_range_check_trace,
509 set_ip_source_and_port_range_check (vlib_main_t * vm,
511 u32 sw_if_index, u32 is_add)
513 ip4_main_t *im = &ip4_main;
514 ip_lookup_main_t *lm = &im->lookup_main;
515 ip_config_main_t *rx_cm = &lm->rx_config_mains[VNET_UNICAST];
517 ip_source_and_port_range_check_config_t config;
522 for (i = 0; i < IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS; i++)
524 config.fib_index[i] = fib_index[i];
527 feature_index = im->ip4_unicast_rx_feature_source_and_port_range_check;
529 vec_validate (rx_cm->config_index_by_sw_if_index, sw_if_index);
531 ci = rx_cm->config_index_by_sw_if_index[sw_if_index];
533 ? vnet_config_add_feature
534 : vnet_config_del_feature)
535 (vm, &rx_cm->config_main, ci, feature_index, &config, sizeof (config));
536 rx_cm->config_index_by_sw_if_index[sw_if_index] = ci;
541 static clib_error_t *
542 set_ip_source_and_port_range_check_fn (vlib_main_t * vm,
543 unformat_input_t * input,
544 vlib_cli_command_t * cmd)
546 vnet_main_t *vnm = vnet_get_main ();
547 ip4_main_t *im = &ip4_main;
548 clib_error_t *error = 0;
550 u32 sw_if_index = ~0;
551 u32 vrf_id[IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS];
552 u32 fib_index[IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS];
559 for (i = 0; i < IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS; i++)
565 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
567 if (unformat (input, "%U", unformat_vnet_sw_interface, vnm,
572 (input, "tcp-out-vrf %d",
573 &vrf_id[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT]))
577 (input, "udp-out-vrf %d",
578 &vrf_id[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT]))
582 (input, "tcp-in-vrf %d",
583 &vrf_id[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_IN]))
587 (input, "udp-in-vrf %d",
588 &vrf_id[IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_IN]))
590 else if (unformat (input, "del"))
596 if (sw_if_index == ~0)
597 return clib_error_return (0, "Interface required but not specified");
600 return clib_error_return (0,
601 "TCP or UDP VRF ID required but not specified");
603 for (i = 0; i < IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS; i++)
607 return clib_error_return (0,
608 "TCP, UDP VRF ID should not be 0 (default). Should be distinct VRF for this purpose. ");
612 p = hash_get (im->fib_index_by_table_id, vrf_id[i]);
615 return clib_error_return (0, "Invalid VRF ID %d", vrf_id[i]);
621 set_ip_source_and_port_range_check (vm, fib_index, sw_if_index, is_add);
629 return clib_error_return
631 "set source and port-range on interface returned an unexpected value: %d",
638 VLIB_CLI_COMMAND (set_interface_ip_source_and_port_range_check_command,
640 .path = "set interface ip source-and-port-range-check",
641 .function = set_ip_source_and_port_range_check_fn,
642 .short_help = "set int ip source-and-port-range-check <intfc> [tcp-out-vrf <n>] [udp-out-vrf <n>] [tcp-in-vrf <n>] [udp-in-vrf <n>] [del]",
647 format_source_and_port_rc_adjacency (u8 * s, va_list * args)
649 CLIB_UNUSED (vnet_main_t * vnm) = va_arg (*args, vnet_main_t *);
650 ip_lookup_main_t *lm = va_arg (*args, ip_lookup_main_t *);
651 u32 adj_index = va_arg (*args, u32);
652 ip_adjacency_t *adj = ip_get_adjacency (lm, adj_index);
653 source_range_check_main_t *srm = &source_range_check_main;
654 u8 *rwh = (u8 *) (&adj->rewrite_header);
655 protocol_port_range_t *range;
659 range = (protocol_port_range_t *) rwh;
661 s = format (s, "allow ");
663 for (i = 0; i < srm->ranges_per_adjacency; i++)
665 for (j = 0; j < 8; j++)
667 if (range->low.as_u16[j])
670 s = format (s, ", ");
671 if (range->hi.as_u16[j] > (range->low.as_u16[j] + 1))
672 s = format (s, "%d-%d", (u32) range->low.as_u16[j],
673 (u32) range->hi.as_u16[j] - 1);
675 s = format (s, "%d", range->low.as_u16[j]);
685 ip4_source_and_port_range_check_init (vlib_main_t * vm)
687 source_range_check_main_t *srm = &source_range_check_main;
688 ip4_main_t *im = &ip4_main;
689 ip_lookup_main_t *lm = &im->lookup_main;
692 srm->vnet_main = vnet_get_main ();
694 srm->ranges_per_adjacency =
695 VLIB_BUFFER_PRE_DATA_SIZE / (2 * sizeof (u16x8));
696 srm->special_adjacency_format_function_index =
697 vnet_register_special_adjacency_format_function (lm,
698 format_source_and_port_rc_adjacency);
699 ASSERT (srm->special_adjacency_format_function_index);
704 VLIB_INIT_FUNCTION (ip4_source_and_port_range_check_init);
707 add_port_range_adjacency (ip4_address_t * address,
710 u16 * low_ports, u16 * high_ports, u32 fib_index)
714 source_range_check_main_t *srm = &source_range_check_main;
715 ip4_main_t *im = &ip4_main;
716 ip_lookup_main_t *lm = &im->lookup_main;
717 protocol_port_range_t *range;
720 adj = ip_get_adjacency (lm, adj_index);
721 /* $$$$ fixme: add ports if address + mask match */
722 if (adj->lookup_next_index == IP_LOOKUP_NEXT_ICMP_ERROR)
723 return VNET_API_ERROR_INCORRECT_ADJACENCY_TYPE;
725 ip_adjacency_t template_adj;
726 ip4_add_del_route_args_t a;
728 memset (&template_adj, 0, sizeof (template_adj));
730 template_adj.lookup_next_index = IP_LOOKUP_NEXT_ICMP_ERROR;
731 template_adj.if_address_index = ~0;
732 template_adj.special_adjacency_format_function_index =
733 srm->special_adjacency_format_function_index;
735 rwh = (u8 *) (&template_adj.rewrite_header);
737 range = (protocol_port_range_t *) rwh;
739 if (vec_len (low_ports) > 8 * srm->ranges_per_adjacency)
740 return VNET_API_ERROR_EXCEEDED_NUMBER_OF_RANGES_CAPACITY;
744 for (i = 0; i < vec_len (low_ports); i++)
746 for (; j < srm->ranges_per_adjacency; j++)
750 if (range->low.as_u16[k] == 0)
752 range->low.as_u16[k] = low_ports[i];
753 range->hi.as_u16[k] = high_ports[i];
767 /* Too many ports specified... */
768 return VNET_API_ERROR_EXCEEDED_NUMBER_OF_PORTS_CAPACITY;
773 memset (&a, 0, sizeof (a));
774 a.flags = IP4_ROUTE_FLAG_FIB_INDEX;
775 a.table_index_or_table_id = fib_index;
776 a.dst_address = address[0];
777 a.dst_address_length = length;
778 a.add_adj = &template_adj;
781 ip4_add_del_route (im, &a);
786 remove_port_range_adjacency (ip4_address_t * address,
789 u16 * low_ports, u16 * high_ports, u32 fib_index)
793 source_range_check_main_t *srm = &source_range_check_main;
794 ip4_main_t *im = &ip4_main;
795 ip_lookup_main_t *lm = &im->lookup_main;
796 protocol_port_range_t *range;
799 adj = ip_get_adjacency (lm, adj_index);
800 if (adj->lookup_next_index != IP_LOOKUP_NEXT_ICMP_ERROR) /* _ICMP_ERROR is a dummy placeholder */
801 return VNET_API_ERROR_INCORRECT_ADJACENCY_TYPE;
803 rwh = (u8 *) (&adj->rewrite_header);
805 for (i = 0; i < vec_len (low_ports); i++)
807 range = (protocol_port_range_t *) rwh;
808 for (j = 0; j < srm->ranges_per_adjacency; j++)
810 for (k = 0; k < 8; k++)
812 if (low_ports[i] == range->low.as_u16[k] &&
813 high_ports[i] == range->hi.as_u16[k])
815 range->low.as_u16[k] = range->hi.as_u16[k] = 0;
824 range = (protocol_port_range_t *) rwh;
825 /* Have we deleted all ranges yet? */
826 for (i = 0; i < srm->ranges_per_adjacency; i++)
828 for (j = 0; j < 8; j++)
830 if (range->low.as_u16[i] != 0)
835 /* Yes, lose the adjacency... */
837 ip4_add_del_route_args_t a;
839 memset (&a, 0, sizeof (a));
840 a.flags = IP4_ROUTE_FLAG_FIB_INDEX | IP4_ROUTE_FLAG_DEL;
841 a.table_index_or_table_id = fib_index;
842 a.dst_address = address[0];
843 a.dst_address_length = length;
844 a.adj_index = adj_index;
845 ip4_add_del_route (im, &a);
853 // This will be moved to another file and implemented post API freeze.
855 ip6_source_and_port_range_check_add_del (ip6_address_t * address,
859 u16 * high_ports, int is_add)
865 ip4_source_and_port_range_check_add_del (ip4_address_t * address,
869 u16 * high_ports, int is_add)
872 ip4_main_t *im = &ip4_main;
873 // ip_lookup_main_t * lm = &im->lookup_main;
878 p = hash_get (im->fib_index_by_table_id, vrf_id);
882 f = find_ip4_fib_by_table_index_or_id (im, vrf_id, 0 /* flags */ );
883 fib_index = f->index;
888 adj_index = ip4_fib_lookup_with_table
889 (im, fib_index, address, 0 /* disable_default_route */ );
893 remove_port_range_adjacency (address, length, adj_index, low_ports,
894 high_ports, fib_index);
898 add_port_range_adjacency (address, length, adj_index, low_ports,
899 high_ports, fib_index);
905 static clib_error_t *
906 ip_source_and_port_range_check_command_fn (vlib_main_t * vm,
907 unformat_input_t * input,
908 vlib_cli_command_t * cmd)
914 ip4_address_t ip4_addr;
915 ip6_address_t ip6_addr; //This function will be moved to generic impl when v6 done.
919 int is_add = 1, ip_ver = ~0;
923 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
925 if (unformat (input, "%U/%d", unformat_ip4_address, &ip4_addr, &length))
929 (input, "%U/%d", unformat_ip6_address, &ip6_addr, &length))
931 else if (unformat (input, "vrf %d", &vrf_id))
933 else if (unformat (input, "del"))
935 else if (unformat (input, "port %d", &tmp))
937 if (tmp == 0 || tmp > 65535)
938 return clib_error_return (0, "port %d out of range", tmp);
940 this_hi = this_low + 1;
941 vec_add1 (low_ports, this_low);
942 vec_add1 (high_ports, this_hi);
944 else if (unformat (input, "range %d - %d", &tmp, &tmp2))
947 return clib_error_return (0, "ports %d and %d out of order",
949 if (tmp == 0 || tmp > 65535)
950 return clib_error_return (0, "low port %d out of range", tmp);
951 if (tmp2 == 0 || tmp2 > 65535)
952 return clib_error_return (0, "high port %d out of range", tmp2);
955 vec_add1 (low_ports, this_low);
956 vec_add1 (high_ports, this_hi);
963 return clib_error_return (0, " <address>/<mask> not specified");
966 return clib_error_return (0, " VRF ID required, not specified");
968 if (vec_len (low_ports) == 0)
969 return clib_error_return (0,
970 " Both VRF ID and range/port must be set for a protocol.");
973 return clib_error_return (0, " VRF ID can not be 0 (default).");
977 rv = ip4_source_and_port_range_check_add_del
978 (&ip4_addr, length, vrf_id, low_ports, high_ports, is_add);
980 return clib_error_return (0, " IPv6 in subsequent patch");
987 case VNET_API_ERROR_INCORRECT_ADJACENCY_TYPE:
988 return clib_error_return
989 (0, " Incorrect adjacency for add/del operation");
991 case VNET_API_ERROR_EXCEEDED_NUMBER_OF_PORTS_CAPACITY:
992 return clib_error_return (0, " Too many ports in add/del operation");
994 case VNET_API_ERROR_EXCEEDED_NUMBER_OF_RANGES_CAPACITY:
995 return clib_error_return
996 (0, " Too many ranges requested for add operation");
999 return clib_error_return (0, " returned an unexpected value: %d", rv);
1006 VLIB_CLI_COMMAND (ip_source_and_port_range_check_command, static) = {
1007 .path = "set ip source-and-port-range-check",
1008 .function = ip_source_and_port_range_check_command_fn,
1010 "set ip source-and-port-range-check <ip-addr>/<mask> [range <nn>-<nn> tcp-vrf <id>] [vrf <id>] [del]",
1015 static clib_error_t *
1016 show_source_and_port_range_check_fn (vlib_main_t * vm,
1017 unformat_input_t * input,
1018 vlib_cli_command_t * cmd)
1020 source_range_check_main_t *srm = &source_range_check_main;
1021 ip4_main_t *im = &ip4_main;
1022 ip_lookup_main_t *lm = &im->lookup_main;
1023 protocol_port_range_t *range;
1030 ip_adjacency_t *adj;
1035 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
1037 if (unformat (input, "%U", unformat_ip4_address, &addr))
1039 else if (unformat (input, "vrf %d", &vrf_id))
1041 else if (unformat (input, "port %d", &port))
1048 return clib_error_return (0, "<address> not specified");
1051 return clib_error_return (0, "VRF ID required, not specified");
1053 p = hash_get (im->fib_index_by_table_id, vrf_id);
1055 return clib_error_return (0, "VRF %d not found", vrf_id);
1058 adj_index = ip4_fib_lookup_with_table
1059 (im, fib_index, &addr, 0 /* disable_default_route */ );
1061 adj = ip_get_adjacency (lm, adj_index);
1063 if (adj->lookup_next_index != IP_LOOKUP_NEXT_ICMP_ERROR)
1065 vlib_cli_output (vm, "%U: src address drop", format_ip4_address, &addr);
1071 rv = check_adj_port_range_x1 (adj, (u16) port, 1234);
1073 vlib_cli_output (vm, "%U port %d PASS", format_ip4_address,
1076 vlib_cli_output (vm, "%U port %d FAIL", format_ip4_address,
1083 rwh = (u8 *) (&adj->rewrite_header);
1085 s = format (0, "%U: ", format_ip4_address, &addr);
1087 range = (protocol_port_range_t *) rwh;
1089 for (i = 0; i < srm->ranges_per_adjacency; i++)
1091 for (j = 0; j < 8; j++)
1093 if (range->low.as_u16[j])
1094 s = format (s, "%d - %d ", (u32) range->low.as_u16[j],
1095 (u32) range->hi.as_u16[j]);
1099 vlib_cli_output (vm, "%s", s);
1107 VLIB_CLI_COMMAND (show_source_and_port_range_check, static) = {
1108 .path = "show ip source-and-port-range-check",
1109 .function = show_source_and_port_range_check_fn,
1111 "show ip source-and-port-range-check vrf <nn> <ip-addr> <port>",
1116 * fd.io coding-style-patch-verification: ON
1119 * eval: (c-set-style "gnu")