+ app_sapi_msg_t smsg = { 0 };
+ app_namespace_t *app_ns;
+ application_t *app;
+ clib_socket_t *cs;
+ u32 cs_index;
+
+ app = application_get (app_wrk->app_index);
+ app_ns = app_namespace_get (app->ns_index);
+ cs_index = appns_sapi_handle_sock_index (app_wrk->api_client_index);
+ cs = appns_sapi_get_socket (app_ns, cs_index);
+ if (PREDICT_FALSE (!cs))
+ return;
+
+ /* There's no payload for the message only the type */
+ smsg.type = APP_SAPI_MSG_TYPE_SEND_FDS;
+ clib_socket_sendmsg (cs, &smsg, sizeof (smsg), fds, n_fds);
+}
+
+static int
+mq_send_add_segment_sapi_cb (u32 app_wrk_index, u64 segment_handle)
+{
+ int fds[SESSION_N_FD_TYPE], n_fds = 0;
+ svm_msg_q_msg_t _msg, *msg = &_msg;
+ session_app_add_segment_msg_t *mp;
+ app_worker_t *app_wrk;
+ session_event_t *evt;
+ svm_msg_q_t *app_mq;
+ fifo_segment_t *fs;
+ ssvm_private_t *sp;
+ u8 fd_flags = 0;
+
+ app_wrk = app_worker_get (app_wrk_index);
+
+ fs = segment_manager_get_segment_w_handle (segment_handle);
+ sp = &fs->ssvm;
+ ASSERT (ssvm_type (sp) == SSVM_SEGMENT_MEMFD);
+
+ fd_flags |= SESSION_FD_F_MEMFD_SEGMENT;
+ fds[n_fds] = sp->fd;
+ n_fds += 1;
+
+ app_mq = app_wrk->event_queue;
+ if (mq_try_lock_and_alloc_msg (app_mq, msg))
+ return -1;
+
+ /*
+ * Send the fd over api socket
+ */
+ sapi_send_fds (app_wrk, fds, n_fds);
+
+ /*
+ * Send the actual message over mq
+ */
+ evt = svm_msg_q_msg_data (app_mq, msg);
+ clib_memset (evt, 0, sizeof (*evt));
+ evt->event_type = SESSION_CTRL_EVT_APP_ADD_SEGMENT;
+ mp = (session_app_add_segment_msg_t *) evt->data;
+ clib_memset (mp, 0, sizeof (*mp));
+ mp->segment_size = sp->ssvm_size;
+ mp->fd_flags = fd_flags;
+ mp->segment_handle = segment_handle;
+ strncpy ((char *) mp->segment_name, (char *) sp->name,
+ sizeof (mp->segment_name) - 1);
+
+ svm_msg_q_add_and_unlock (app_mq, msg);
+
+ return 0;
+}
+
+static int
+mq_send_del_segment_sapi_cb (u32 app_wrk_index, u64 segment_handle)
+{
+ svm_msg_q_msg_t _msg, *msg = &_msg;
+ session_app_del_segment_msg_t *mp;
+ app_worker_t *app_wrk;
+ session_event_t *evt;
+ svm_msg_q_t *app_mq;
+
+ app_wrk = app_worker_get (app_wrk_index);
+
+ app_mq = app_wrk->event_queue;
+ if (mq_try_lock_and_alloc_msg (app_mq, msg))
+ return -1;
+
+ evt = svm_msg_q_msg_data (app_mq, msg);
+ clib_memset (evt, 0, sizeof (*evt));
+ evt->event_type = SESSION_CTRL_EVT_APP_DEL_SEGMENT;
+ mp = (session_app_del_segment_msg_t *) evt->data;
+ clib_memset (mp, 0, sizeof (*mp));
+ mp->segment_handle = segment_handle;
+ svm_msg_q_add_and_unlock (app_mq, msg);
+
+ return 0;
+}
+
+static session_cb_vft_t session_mq_sapi_cb_vft = {
+ .session_accept_callback = mq_send_session_accepted_cb,
+ .session_disconnect_callback = mq_send_session_disconnected_cb,
+ .session_connected_callback = mq_send_session_connected_cb,
+ .session_reset_callback = mq_send_session_reset_cb,
+ .session_migrate_callback = mq_send_session_migrate_cb,
+ .session_cleanup_callback = mq_send_session_cleanup_cb,
+ .add_segment_callback = mq_send_add_segment_sapi_cb,
+ .del_segment_callback = mq_send_del_segment_sapi_cb,
+};
+
+static void
+session_api_attach_handler (app_namespace_t * app_ns, clib_socket_t * cs,
+ app_sapi_attach_msg_t * mp)
+{
+ int rv = 0, *fds = 0, n_fds = 0, i, n_workers;
+ vnet_app_attach_args_t _a, *a = &_a;
+ app_sapi_attach_reply_msg_t *rmp;
+ u8 fd_flags = 0, ctrl_thread;
+ app_ns_api_handle_t *handle;
+ fifo_segment_t *rx_mqs_seg;
+ app_sapi_msg_t msg = { 0 };
+ app_worker_t *app_wrk;
+ application_t *app;
+ svm_msg_q_t *rx_mq;
+
+ /* Make sure name is null terminated */
+ mp->name[63] = 0;
+
+ clib_memset (a, 0, sizeof (*a));
+ a->api_client_index = appns_sapi_socket_handle (app_ns, cs);
+ a->name = format (0, "%s", (char *) mp->name);
+ a->options = mp->options;
+ a->session_cb_vft = &session_mq_sapi_cb_vft;
+ a->use_sock_api = 1;
+ a->options[APP_OPTIONS_NAMESPACE] = app_namespace_index (app_ns);
+
+ if ((rv = vnet_application_attach (a)))
+ {
+ clib_warning ("attach returned: %d", rv);
+ goto done;
+ }
+
+ n_workers = vlib_num_workers ();
+ vec_validate (fds, 3 /* segs + tx evtfd */ + n_workers);
+
+ /* Send event queues segment */
+ app = application_get (a->app_index);
+ rx_mqs_seg = application_get_rx_mqs_segment (app);
+
+ fd_flags |= SESSION_FD_F_VPP_MQ_SEGMENT;
+ fds[n_fds] = rx_mqs_seg->ssvm.fd;
+ n_fds += 1;
+
+ /* Send fifo segment fd if needed */
+ if (ssvm_type (a->segment) == SSVM_SEGMENT_MEMFD)
+ {
+ fd_flags |= SESSION_FD_F_MEMFD_SEGMENT;
+ fds[n_fds] = a->segment->fd;
+ n_fds += 1;
+ }
+ if (a->options[APP_OPTIONS_FLAGS] & APP_OPTIONS_FLAGS_EVT_MQ_USE_EVENTFD)
+ {
+ fd_flags |= SESSION_FD_F_MQ_EVENTFD;
+ fds[n_fds] = svm_msg_q_get_eventfd (a->app_evt_q);
+ n_fds += 1;
+ }
+
+ if (application_use_private_rx_mqs ())
+ {
+ fd_flags |= SESSION_FD_F_VPP_MQ_EVENTFD;
+ for (i = 0; i < n_workers + 1; i++)
+ {
+ rx_mq = application_rx_mq_get (app, i);
+ fds[n_fds] = svm_msg_q_get_eventfd (rx_mq);
+ n_fds += 1;
+ }
+ }
+
+done:
+
+ msg.type = APP_SAPI_MSG_TYPE_ATTACH_REPLY;
+ rmp = &msg.attach_reply;
+ rmp->retval = rv;
+ if (!rv)
+ {
+ ctrl_thread = n_workers ? 1 : 0;
+ rmp->app_index = a->app_index;
+ rmp->app_mq =
+ fifo_segment_msg_q_offset ((fifo_segment_t *) a->segment, 0);
+ rmp->vpp_ctrl_mq = fifo_segment_msg_q_offset (rx_mqs_seg, ctrl_thread);
+ rmp->vpp_ctrl_mq_thread = ctrl_thread;
+ rmp->n_fds = n_fds;
+ rmp->fd_flags = fd_flags;
+ /* No segment name and size since we only support memfds
+ * in this configuration */
+ rmp->segment_handle = a->segment_handle;
+ rmp->api_client_handle = a->api_client_index;
+
+ /* Update app index for socket */
+ handle = (app_ns_api_handle_t *) & cs->private_data;
+ app_wrk = application_get_worker (app, 0);
+ handle->aah_app_wrk_index = app_wrk->wrk_index;
+ }
+
+ clib_socket_sendmsg (cs, &msg, sizeof (msg), fds, n_fds);
+ vec_free (a->name);
+ vec_free (fds);
+}
+
+void
+sapi_socket_close_w_handle (u32 api_handle)
+{
+ app_namespace_t *app_ns = app_namespace_get (api_handle >> 16);
+ u16 sock_index = api_handle & 0xffff;
+ app_ns_api_handle_t *handle;
+ clib_socket_t *cs;
+ clib_file_t *cf;
+
+ cs = appns_sapi_get_socket (app_ns, sock_index);
+ if (!cs)
+ return;
+
+ handle = (app_ns_api_handle_t *) & cs->private_data;
+ cf = clib_file_get (&file_main, handle->aah_file_index);
+ clib_file_del (&file_main, cf);
+
+ clib_socket_close (cs);
+ appns_sapi_free_socket (app_ns, cs);
+}
+
+static void
+sapi_add_del_worker_handler (app_namespace_t * app_ns,
+ clib_socket_t * cs,
+ app_sapi_worker_add_del_msg_t * mp)
+{
+ int rv = 0, fds[SESSION_N_FD_TYPE], n_fds = 0;
+ app_sapi_worker_add_del_reply_msg_t *rmp;
+ app_ns_api_handle_t *handle;
+ app_sapi_msg_t msg = { 0 };
+ app_worker_t *app_wrk;
+ u32 sapi_handle = -1;
+ application_t *app;
+ u8 fd_flags = 0;
+
+ app = application_get_if_valid (mp->app_index);
+ if (!app)
+ {
+ rv = VNET_API_ERROR_INVALID_VALUE;
+ goto done;
+ }
+
+ sapi_handle = appns_sapi_socket_handle (app_ns, cs);
+
+ vnet_app_worker_add_del_args_t args = {
+ .app_index = app->app_index,
+ .wrk_map_index = mp->wrk_index,
+ .api_client_index = sapi_handle,
+ .is_add = mp->is_add
+ };
+ rv = vnet_app_worker_add_del (&args);
+ if (rv)
+ {
+ clib_warning ("app worker add/del returned: %d", rv);
+ goto done;
+ }
+
+ if (!mp->is_add)
+ goto done;
+
+ /* Send fifo segment fd if needed */
+ if (ssvm_type (args.segment) == SSVM_SEGMENT_MEMFD)
+ {
+ fd_flags |= SESSION_FD_F_MEMFD_SEGMENT;
+ fds[n_fds] = args.segment->fd;
+ n_fds += 1;
+ }
+ if (application_segment_manager_properties (app)->use_mq_eventfd)
+ {
+ fd_flags |= SESSION_FD_F_MQ_EVENTFD;
+ fds[n_fds] = svm_msg_q_get_eventfd (args.evt_q);
+ n_fds += 1;
+ }
+
+done:
+
+ msg.type = APP_SAPI_MSG_TYPE_ADD_DEL_WORKER_REPLY;
+ rmp = &msg.worker_add_del_reply;
+ rmp->retval = rv;
+ rmp->is_add = mp->is_add;
+ rmp->api_client_handle = sapi_handle;
+ rmp->wrk_index = args.wrk_map_index;
+ rmp->segment_handle = args.segment_handle;
+ if (!rv && mp->is_add)
+ {
+ /* No segment name and size. This supports only memfds */
+ rmp->app_event_queue_address =
+ fifo_segment_msg_q_offset ((fifo_segment_t *) args.segment, 0);
+ rmp->n_fds = n_fds;
+ rmp->fd_flags = fd_flags;
+
+ /* Update app index for socket */
+ handle = (app_ns_api_handle_t *) & cs->private_data;
+ app_wrk = application_get_worker (app, args.wrk_map_index);
+ handle->aah_app_wrk_index = app_wrk->wrk_index;
+ }
+
+ clib_socket_sendmsg (cs, &msg, sizeof (msg), fds, n_fds);
+}
+
+static void
+sapi_add_del_cert_key_handler (app_namespace_t *app_ns, clib_socket_t *cs,
+ app_sapi_cert_key_add_del_msg_t *mp)
+{
+ vnet_app_add_cert_key_pair_args_t _a, *a = &_a;
+ app_sapi_cert_key_add_del_reply_msg_t *rmp;
+ app_sapi_msg_t msg = { 0 };
+ int rv = 0;
+
+ if (mp->is_add)
+ {
+ const u32 max_certkey_len = 2e4, max_cert_len = 1e4, max_key_len = 1e4;
+ clib_error_t *err;
+ u8 *certkey = 0;
+ u32 key_len;
+
+ if (mp->certkey_len > max_certkey_len)
+ {
+ rv = SESSION_E_INVALID;
+ goto send_reply;
+ }
+
+ vec_validate (certkey, mp->certkey_len - 1);
+ err = clib_socket_recvmsg (cs, certkey, mp->certkey_len, 0, 0);
+ if (err)
+ {
+ clib_error_report (err);
+ clib_error_free (err);
+ rv = SESSION_E_INVALID;
+ goto send_reply;
+ }
+
+ if (mp->cert_len > max_cert_len)
+ {
+ rv = SESSION_E_INVALID;
+ goto send_reply;
+ }
+
+ if (mp->certkey_len < mp->cert_len)
+ {
+ rv = SESSION_E_INVALID;
+ goto send_reply;
+ }
+
+ key_len = mp->certkey_len - mp->cert_len;
+ if (key_len > max_key_len)
+ {
+ rv = SESSION_E_INVALID;
+ goto send_reply;
+ }
+
+ clib_memset (a, 0, sizeof (*a));
+ a->cert = certkey;
+ a->key = certkey + mp->cert_len;
+ a->cert_len = mp->cert_len;
+ a->key_len = key_len;
+ rv = vnet_app_add_cert_key_pair (a);
+
+ vec_free (certkey);
+ }
+ else
+ {
+ rv = vnet_app_del_cert_key_pair (mp->index);
+ }
+
+send_reply:
+
+ msg.type = APP_SAPI_MSG_TYPE_ADD_DEL_CERT_KEY_REPLY;
+ rmp = &msg.cert_key_add_del_reply;
+ rmp->retval = rv;
+ rmp->context = mp->context;
+ if (!rv && mp->is_add)
+ rmp->index = a->index;
+
+ clib_socket_sendmsg (cs, &msg, sizeof (msg), 0, 0);
+}
+
+static void
+sapi_socket_detach (app_namespace_t * app_ns, clib_socket_t * cs)
+{
+ app_ns_api_handle_t *handle;
+ app_worker_t *app_wrk;
+ u32 api_client_handle;
+
+ api_client_handle = appns_sapi_socket_handle (app_ns, cs);
+
+ /* Cleanup everything because app worker closed socket or crashed */
+ handle = (app_ns_api_handle_t *) & cs->private_data;
+ app_wrk = app_worker_get (handle->aah_app_wrk_index);
+
+ vnet_app_worker_add_del_args_t args = {
+ .app_index = app_wrk->app_index,
+ .wrk_map_index = app_wrk->wrk_map_index,
+ .api_client_index = api_client_handle,
+ .is_add = 0
+ };
+ /* Send rpc to main thread for worker barrier */
+ vlib_rpc_call_main_thread (vnet_app_worker_add_del, (u8 *) & args,
+ sizeof (args));
+}
+
+static clib_error_t *
+sapi_sock_read_ready (clib_file_t * cf)
+{
+ app_ns_api_handle_t *handle = (app_ns_api_handle_t *) & cf->private_data;
+ vlib_main_t *vm = vlib_get_main ();
+ app_sapi_msg_t msg = { 0 };
+ app_namespace_t *app_ns;
+ clib_error_t *err = 0;
+ clib_socket_t *cs;
+
+ app_ns = app_namespace_get (handle->aah_app_ns_index);
+ cs = appns_sapi_get_socket (app_ns, handle->aah_sock_index);
+ if (!cs)
+ goto error;
+
+ err = clib_socket_recvmsg (cs, &msg, sizeof (msg), 0, 0);
+ if (err)
+ {
+ clib_error_free (err);
+ sapi_socket_detach (app_ns, cs);
+ goto error;
+ }
+
+ handle = (app_ns_api_handle_t *) & cs->private_data;
+
+ vlib_worker_thread_barrier_sync (vm);
+
+ switch (msg.type)
+ {
+ case APP_SAPI_MSG_TYPE_ATTACH:
+ session_api_attach_handler (app_ns, cs, &msg.attach);
+ break;
+ case APP_SAPI_MSG_TYPE_ADD_DEL_WORKER:
+ sapi_add_del_worker_handler (app_ns, cs, &msg.worker_add_del);
+ break;
+ case APP_SAPI_MSG_TYPE_ADD_DEL_CERT_KEY:
+ sapi_add_del_cert_key_handler (app_ns, cs, &msg.cert_key_add_del);
+ break;
+ default:
+ clib_warning ("app wrk %u unknown message type: %u",
+ handle->aah_app_wrk_index, msg.type);
+ break;
+ }
+
+ vlib_worker_thread_barrier_release (vm);
+
+error:
+ return 0;
+}
+
+static clib_error_t *
+sapi_sock_write_ready (clib_file_t * cf)
+{
+ app_ns_api_handle_t *handle = (app_ns_api_handle_t *) & cf->private_data;
+ clib_warning ("called for app ns %u", handle->aah_app_ns_index);
+ return 0;
+}