2 * Copyright (c) 2020 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #include <vnet/fib/fib_source.h>
17 #include <vnet/fib/fib_table.h>
18 #include <vnet/fib/fib_entry_track.h>
19 #include <vnet/dpo/load_balance.h>
20 #include <vnet/dpo/drop_dpo.h>
22 #include <cnat/cnat_translation.h>
23 #include <cnat/cnat_session.h>
24 #include <cnat/cnat_client.h>
26 cnat_translation_t *cnat_translation_pool;
27 clib_bihash_8_8_t cnat_translation_db;
28 addr_resolution_t *tr_resolutions;
30 typedef void (*cnat_if_addr_add_cb_t) (addr_resolution_t * ar,
31 ip_address_t * address, u8 is_del);
32 cnat_if_addr_add_cb_t *cnat_if_addr_add_cbs;
34 static fib_node_type_t cnat_translation_fib_node_type;
36 vlib_combined_counter_main_t cnat_translation_counters = {
37 .name = "cnat-translation",
38 .stat_segment_name = "/net/cnat-translation",
42 cnat_translation_watch_addr (index_t cti, u64 opaque, cnat_endpoint_t * ep,
43 cnat_addr_resol_type_t type)
45 addr_resolution_t *ar;
47 if (INDEX_INVALID == ep->ce_sw_if_index)
50 pool_get (tr_resolutions, ar);
51 ar->af = ep->ce_ip.version;
52 ar->sw_if_index = ep->ce_sw_if_index;
59 cnat_resolve_ep_tuple (cnat_endpoint_tuple_t * path)
61 cnat_resolve_ep (&path->src_ep);
62 cnat_resolve_ep (&path->dst_ep);
66 cnat_translation_unwatch_addr (u32 cti, cnat_addr_resol_type_t type)
68 /* Delete tr resolution entries matching translation index */
69 addr_resolution_t *ar;
70 index_t *indexes = 0, *ari;
72 pool_foreach (ar, tr_resolutions, ({
73 if ((cti == INDEX_INVALID || ar->cti == cti) &&
74 (ar->type == type || CNAT_RESOLV_ADDR_ANY == type))
75 vec_add1(indexes, ar - tr_resolutions);
78 vec_foreach (ari, indexes) pool_put_index (tr_resolutions, *ari);
84 cnat_tracker_release (cnat_ep_trk_t * trk)
86 /* We only track fully resolved endpoints */
89 fib_entry_untrack (trk->ct_fei, trk->ct_sibling);
93 cnat_tracker_track (index_t cti, cnat_ep_trk_t * trk)
96 /* We only track fully resolved endpoints */
97 trk->is_active = trk->ct_ep[VLIB_TX].ce_flags & CNAT_EP_FLAG_RESOLVED
98 && trk->ct_ep[VLIB_RX].ce_flags & CNAT_EP_FLAG_RESOLVED;
102 ip_address_to_fib_prefix (&trk->ct_ep[VLIB_TX].ce_ip, &pfx);
103 trk->ct_fei = fib_entry_track (CNAT_FIB_TABLE,
105 cnat_translation_fib_node_type,
106 cti, &trk->ct_sibling);
108 fib_entry_contribute_forwarding (trk->ct_fei,
109 fib_forw_chain_type_from_fib_proto
110 (pfx.fp_proto), &trk->ct_dpo);
114 * Add a translation to the bihash
116 * @param cci the ID of the parent client (invalid if vip not resolved)
117 * @param vip the translation endpoint
118 * @param proto the translation proto
119 * @param cti the translation index to be used as value
122 cnat_add_translation_to_db (index_t cci, cnat_endpoint_t * vip,
123 ip_protocol_t proto, index_t cti)
125 clib_bihash_kv_8_8_t bkey;
127 if (INDEX_INVALID == cci)
129 key = proto << 8 | 0x80 | vip->ce_ip.version;
130 key = key << 16 | vip->ce_port;
131 key = key << 32 | (u32) vip->ce_sw_if_index;
136 key = key << 16 | vip->ce_port;
137 key = key << 32 | (u32) cci;
143 clib_bihash_add_del_8_8 (&cnat_translation_db, &bkey, 1);
147 * Remove a translation from the bihash
149 * @param cci the ID of the parent client
150 * @param vip the translation endpoint
151 * @param proto the translation proto
154 cnat_remove_translation_from_db (index_t cci, cnat_endpoint_t * vip,
157 clib_bihash_kv_8_8_t bkey;
159 if (INDEX_INVALID == cci)
161 key = proto << 8 | 0x80 | vip->ce_ip.version;
162 key = key << 16 | vip->ce_port;
163 key = key << 32 | (u32) vip->ce_sw_if_index;
168 key = key << 16 | vip->ce_port;
169 key = key << 32 | (u32) cci;
174 clib_bihash_add_del_8_8 (&cnat_translation_db, &bkey, 0);
178 cnat_translation_stack (cnat_translation_t * ct)
180 fib_protocol_t fproto;
186 fproto = ip_address_family_to_fib_proto (ct->ct_vip.ce_ip.version);
187 dproto = fib_proto_to_dpo (fproto);
189 vec_foreach (trk, ct->ct_paths) if (trk->is_active)
192 lbi = load_balance_create (ep_idx, fib_proto_to_dpo (fproto),
193 IP_FLOW_HASH_DEFAULT);
196 vec_foreach (trk, ct->ct_paths) if (trk->is_active)
197 load_balance_set_bucket (lbi, ep_idx++, &trk->ct_dpo);
199 dpo_set (&ct->ct_lb, DPO_LOAD_BALANCE, dproto, lbi);
200 dpo_stack (cnat_client_dpo, dproto, &ct->ct_lb, &ct->ct_lb);
204 cnat_translation_delete (u32 id)
206 cnat_translation_t *ct;
209 if (pool_is_free_index (cnat_translation_pool, id))
210 return (VNET_API_ERROR_NO_SUCH_ENTRY);
212 ct = pool_elt_at_index (cnat_translation_pool, id);
214 dpo_reset (&ct->ct_lb);
216 vec_foreach (trk, ct->ct_paths) cnat_tracker_release (trk);
218 cnat_remove_translation_from_db (ct->ct_cci, &ct->ct_vip, ct->ct_proto);
219 cnat_client_translation_deleted (ct->ct_cci);
220 cnat_translation_unwatch_addr (id, CNAT_RESOLV_ADDR_ANY);
221 pool_put (cnat_translation_pool, ct);
227 cnat_translation_update (cnat_endpoint_t * vip,
229 cnat_endpoint_tuple_t * paths, u8 flags)
231 cnat_endpoint_tuple_t *path;
232 const cnat_client_t *cc;
233 cnat_translation_t *ct;
238 if (cnat_resolve_ep (vip))
240 /* vip only contains a sw_if_index for now */
241 ct = cnat_find_translation (vip->ce_sw_if_index, vip->ce_port, proto);
246 /* do we know of this ep's vip */
247 cci = cnat_client_add (&vip->ce_ip, flags);
248 cc = cnat_client_get (cci);
250 ct = cnat_find_translation (cc->parent_cci, vip->ce_port, proto);
255 pool_get_zero (cnat_translation_pool, ct);
257 clib_memcpy (&ct->ct_vip, vip, sizeof (*vip));
258 ct->ct_proto = proto;
260 ct->index = ct - cnat_translation_pool;
262 cnat_add_translation_to_db (cci, vip, proto, ct->index);
263 cnat_client_translation_added (cci);
265 vlib_validate_combined_counter (&cnat_translation_counters, ct->index);
266 vlib_zero_combined_counter (&cnat_translation_counters, ct->index);
270 cnat_translation_unwatch_addr (ct->index, CNAT_RESOLV_ADDR_ANY);
271 cnat_translation_watch_addr (ct->index, 0, vip,
272 CNAT_RESOLV_ADDR_TRANSLATION);
274 vec_foreach (trk, ct->ct_paths)
276 cnat_tracker_release (trk);
279 vec_reset_length (ct->ct_paths);
282 vec_foreach (path, paths)
284 cnat_resolve_ep_tuple (path);
285 cnat_translation_watch_addr (ct->index,
286 path_idx << 32 | VLIB_RX, &path->src_ep,
287 CNAT_RESOLV_ADDR_BACKEND);
288 cnat_translation_watch_addr (ct->index,
289 path_idx << 32 | VLIB_TX, &path->dst_ep,
290 CNAT_RESOLV_ADDR_BACKEND);
293 vec_add2 (ct->ct_paths, trk, 1);
295 clib_memcpy (&trk->ct_ep[VLIB_TX], &path->dst_ep,
296 sizeof (trk->ct_ep[VLIB_TX]));
297 clib_memcpy (&trk->ct_ep[VLIB_RX], &path->src_ep,
298 sizeof (trk->ct_ep[VLIB_RX]));
300 cnat_tracker_track (ct->index, trk);
303 cnat_translation_stack (ct);
309 cnat_translation_walk (cnat_translation_walk_cb_t cb, void *ctx)
314 pool_foreach_index(api, cnat_translation_pool,
323 format_cnat_ep_trk (u8 * s, va_list * args)
325 cnat_ep_trk_t *ck = va_arg (*args, cnat_ep_trk_t *);
326 u32 indent = va_arg (*args, u32);
328 s = format (s, "%U->%U", format_cnat_endpoint, &ck->ct_ep[VLIB_RX],
329 format_cnat_endpoint, &ck->ct_ep[VLIB_TX]);
330 s = format (s, "\n%Ufib-entry:%d", format_white_space, indent, ck->ct_fei);
331 s = format (s, "\n%U%U",
332 format_white_space, indent, format_dpo_id, &ck->ct_dpo, 6);
338 format_cnat_translation (u8 * s, va_list * args)
340 cnat_translation_t *ct = va_arg (*args, cnat_translation_t *);
343 s = format (s, "[%d] ", ct->index);
344 s = format (s, "%U %U", format_cnat_endpoint, &ct->ct_vip,
345 format_ip_protocol, ct->ct_proto);
347 vec_foreach (ck, ct->ct_paths)
348 s = format (s, "\n%U", format_cnat_ep_trk, ck, 2);
350 /* If printing a trace, the LB object might be deleted */
351 if (!pool_is_free_index (load_balance_pool, ct->ct_lb.dpoi_index))
353 s = format (s, "\n via:");
354 s = format (s, "\n%U%U",
355 format_white_space, 2, format_dpo_id, &ct->ct_lb, 2);
361 static clib_error_t *
362 cnat_translation_show (vlib_main_t * vm,
363 unformat_input_t * input, vlib_cli_command_t * cmd)
366 cnat_translation_t *ct;
370 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
372 if (unformat (input, "%d", &cti))
375 return (clib_error_return (0, "unknown input '%U'",
376 format_unformat_error, input));
379 if (INDEX_INVALID == cti)
382 pool_foreach_index(cti, cnat_translation_pool,
384 ct = pool_elt_at_index (cnat_translation_pool, cti);
385 vlib_cli_output(vm, "%U", format_cnat_translation, ct);
391 vlib_cli_output (vm, "Invalid policy ID:%d", cti);
398 cnat_translation_purge (void)
400 /* purge all the translations */
401 index_t tri, *trp, *trs = NULL;
404 pool_foreach_index(tri, cnat_translation_pool,
410 vec_foreach (trp, trs) cnat_translation_delete (*trp);
412 ASSERT (0 == pool_elts (cnat_translation_pool));
420 VLIB_CLI_COMMAND (cnat_translation_show_cmd_node, static) = {
421 .path = "show cnat translation",
422 .function = cnat_translation_show,
423 .short_help = "show cnat translation <VIP>",
429 cnat_translation_get_node (fib_node_index_t index)
431 cnat_translation_t *ct = cnat_translation_get (index);
432 return (&(ct->ct_node));
435 static cnat_translation_t *
436 cnat_translation_get_from_node (fib_node_t * node)
438 return ((cnat_translation_t *) (((char *) node) -
439 STRUCT_OFFSET_OF (cnat_translation_t,
444 cnat_translation_last_lock_gone (fib_node_t * node)
449 * A back walk has reached this ABF policy
451 static fib_node_back_walk_rc_t
452 cnat_translation_back_walk_notify (fib_node_t * node,
453 fib_node_back_walk_ctx_t * ctx)
456 * re-stack the fmask on the n-eos of the via
458 cnat_translation_t *ct = cnat_translation_get_from_node (node);
460 cnat_translation_stack (ct);
462 return (FIB_NODE_BACK_WALK_CONTINUE);
466 * The translation's graph node virtual function table
468 static const fib_node_vft_t cnat_translation_vft = {
469 .fnv_get = cnat_translation_get_node,
470 .fnv_last_lock = cnat_translation_last_lock_gone,
471 .fnv_back_walk = cnat_translation_back_walk_notify,
474 static clib_error_t *
475 cnat_translation_cli_add_del (vlib_main_t * vm,
476 unformat_input_t * input,
477 vlib_cli_command_t * cmd)
479 u32 del_index = INDEX_INVALID;
480 ip_protocol_t proto = IP_PROTOCOL_TCP;
482 u8 flags = CNAT_FLAG_EXCLUSIVE;
483 cnat_endpoint_tuple_t tmp, *paths = NULL, *path;
485 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
487 if (unformat (input, "add"))
488 del_index = INDEX_INVALID;
489 else if (unformat (input, "del %d", &del_index))
491 else if (unformat (input, "proto %U", unformat_ip_protocol, &proto))
493 else if (unformat (input, "vip %U", unformat_cnat_ep, &vip))
494 flags = CNAT_FLAG_EXCLUSIVE;
495 else if (unformat (input, "real %U", unformat_cnat_ep, &vip))
497 else if (unformat (input, "to %U", unformat_cnat_ep_tuple, &tmp))
499 pool_get (paths, path);
500 clib_memcpy (path, &tmp, sizeof (cnat_endpoint_tuple_t));
503 return (clib_error_return (0, "unknown input '%U'",
504 format_unformat_error, input));
507 if (INDEX_INVALID == del_index)
508 cnat_translation_update (&vip, proto, paths, flags);
510 cnat_translation_delete (del_index);
517 VLIB_CLI_COMMAND (cnat_translation_cli_add_del_command, static) =
519 .path = "cnat translation",
520 .short_help = "cnat translation [add|del] proto [TCP|UDP] [vip|real] [ip|sw_if_index [v6]] [port] [to [ip|sw_if_index [v6]] [port]->[ip|sw_if_index [v6]] [port]]",
521 .function = cnat_translation_cli_add_del,
526 cnat_if_addr_add_del_translation_cb (addr_resolution_t * ar,
527 ip_address_t * address, u8 is_del)
529 cnat_translation_t *ct;
530 ct = cnat_translation_get (ar->cti);
531 if (!is_del && ct->ct_vip.ce_flags & CNAT_EP_FLAG_RESOLVED)
534 cnat_remove_translation_from_db (ct->ct_cci, &ct->ct_vip, ct->ct_proto);
538 ct->ct_vip.ce_flags &= ~CNAT_EP_FLAG_RESOLVED;
539 ct->ct_cci = INDEX_INVALID;
540 cnat_client_translation_deleted (ct->ct_cci);
541 /* Are there remaining addresses ? */
542 if (0 == cnat_resolve_addr (ar->sw_if_index, ar->af, address))
548 ct->ct_cci = cnat_client_add (address, ct->flags);
549 cnat_client_translation_added (ct->ct_cci);
550 ip_address_copy (&ct->ct_vip.ce_ip, address);
551 ct->ct_vip.ce_flags |= CNAT_EP_FLAG_RESOLVED;
554 cnat_add_translation_to_db (ct->ct_cci, &ct->ct_vip, ct->ct_proto,
559 cnat_if_addr_add_del_backend_cb (addr_resolution_t * ar,
560 ip_address_t * address, u8 is_del)
562 cnat_translation_t *ct;
566 u8 direction = ar->opaque & 0xf;
567 u32 path_idx = ar->opaque >> 32;
569 ct = cnat_translation_get (ar->cti);
571 trk = &ct->ct_paths[path_idx];
572 ep = &trk->ct_ep[direction];
574 if (!is_del && ep->ce_flags & CNAT_EP_FLAG_RESOLVED)
577 ASSERT (ep->ce_sw_if_index == ar->sw_if_index);
581 ep->ce_flags &= ~CNAT_EP_FLAG_RESOLVED;
582 /* Are there remaining addresses ? */
583 if (0 == cnat_resolve_addr (ar->sw_if_index, ar->af, address))
589 ip_address_copy (&ep->ce_ip, address);
590 ep->ce_flags |= CNAT_EP_FLAG_RESOLVED;
592 cnat_tracker_track (ar->cti, trk);
594 cnat_translation_stack (ct);
598 cnat_if_addr_add_del_snat_cb (addr_resolution_t * ar, ip_address_t * address,
602 ep = AF_IP4 == ar->af ? &cnat_main.snat_ip4 : &cnat_main.snat_ip6;
604 if (!is_del && ep->ce_flags & CNAT_EP_FLAG_RESOLVED)
609 ep->ce_flags &= ~CNAT_EP_FLAG_RESOLVED;
610 /* Are there remaining addresses ? */
611 if (0 == cnat_resolve_addr (ar->sw_if_index, ar->af, address))
617 ip_address_copy (&ep->ce_ip, address);
618 ep->ce_flags |= CNAT_EP_FLAG_RESOLVED;
624 cnat_if_addr_add_del_callback (u32 sw_if_index, ip_address_t * address,
627 addr_resolution_t *ar;
629 pool_foreach (ar, tr_resolutions, ({
630 if (ar->sw_if_index != sw_if_index)
632 if (ar->af != ip_addr_version (address))
634 cnat_if_addr_add_cbs[ar->type] (ar, address, is_del);
640 cnat_ip6_if_addr_add_del_callback (struct ip6_main_t *im,
641 uword opaque, u32 sw_if_index,
642 ip6_address_t * address,
643 u32 address_length, u32 if_address_index,
647 ip_address_set (&addr, address, AF_IP6);
648 cnat_if_addr_add_del_callback (sw_if_index, &addr, is_del);
652 cnat_ip4_if_addr_add_del_callback (struct ip4_main_t *im,
653 uword opaque, u32 sw_if_index,
654 ip4_address_t * address,
655 u32 address_length, u32 if_address_index,
659 ip_address_set (&addr, address, AF_IP4);
660 cnat_if_addr_add_del_callback (sw_if_index, &addr, is_del);
663 static clib_error_t *
664 cnat_translation_init (vlib_main_t * vm)
666 ip4_main_t *i4m = &ip4_main;
667 ip6_main_t *i6m = &ip6_main;
668 cnat_main_t *cm = &cnat_main;
669 cnat_translation_fib_node_type =
670 fib_node_register_new_type (&cnat_translation_vft);
672 clib_bihash_init_8_8 (&cnat_translation_db, "CNat translation DB",
673 cm->translation_hash_buckets,
674 cm->translation_hash_memory);
676 ip4_add_del_interface_address_callback_t cb4;
677 cb4.function = cnat_ip4_if_addr_add_del_callback;
678 vec_add1 (i4m->add_del_interface_address_callbacks, cb4);
680 ip6_add_del_interface_address_callback_t cb6;
681 cb6.function = cnat_ip6_if_addr_add_del_callback;
682 vec_add1 (i6m->add_del_interface_address_callbacks, cb6);
684 vec_validate (cnat_if_addr_add_cbs, CNAT_ADDR_N_RESOLUTIONS);
685 cnat_if_addr_add_cbs[CNAT_RESOLV_ADDR_BACKEND] =
686 cnat_if_addr_add_del_backend_cb;
687 cnat_if_addr_add_cbs[CNAT_RESOLV_ADDR_SNAT] = cnat_if_addr_add_del_snat_cb;
688 cnat_if_addr_add_cbs[CNAT_RESOLV_ADDR_TRANSLATION] =
689 cnat_if_addr_add_del_translation_cb;
693 VLIB_INIT_FUNCTION (cnat_translation_init);
696 * fd.io coding-style-patch-verification: ON
699 * eval: (c-set-style "gnu")