2 * Copyright (c) 2020 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #include <vnet/fib/fib_source.h>
17 #include <vnet/fib/fib_table.h>
18 #include <vnet/fib/fib_entry_track.h>
19 #include <vnet/dpo/load_balance.h>
20 #include <vnet/dpo/drop_dpo.h>
22 #include <cnat/cnat_translation.h>
23 #include <cnat/cnat_session.h>
24 #include <cnat/cnat_client.h>
26 cnat_translation_t *cnat_translation_pool;
27 clib_bihash_8_8_t cnat_translation_db;
29 static fib_node_type_t cnat_translation_fib_node_type;
31 vlib_combined_counter_main_t cnat_translation_counters = {
32 .name = "cnat-translation",
33 .stat_segment_name = "/net/cnat-translation",
37 cnat_tracker_release (cnat_ep_trk_t * trk)
39 fib_entry_untrack (trk->ct_fei, trk->ct_sibling);
43 cnat_tracker_track (index_t cti,
44 const cnat_endpoint_tuple_t * path, cnat_ep_trk_t * trk)
48 ip_address_to_fib_prefix (&path->dst_ep.ce_ip, &pfx);
50 clib_memcpy (&trk->ct_ep[VLIB_TX], &path->dst_ep,
51 sizeof (trk->ct_ep[VLIB_TX]));
52 clib_memcpy (&trk->ct_ep[VLIB_RX], &path->src_ep,
53 sizeof (trk->ct_ep[VLIB_RX]));
55 trk->ct_fei = fib_entry_track (CNAT_FIB_TABLE,
57 cnat_translation_fib_node_type,
58 cti, &trk->ct_sibling);
60 fib_entry_contribute_forwarding (trk->ct_fei,
61 fib_forw_chain_type_from_fib_proto
62 (pfx.fp_proto), &trk->ct_dpo);
66 cnat_add_translation_to_db (index_t cci, u16 port, ip_protocol_t proto,
69 clib_bihash_kv_8_8_t bkey;
72 key = (proto << 16) | port;
73 key = key << 32 | (u32) cci;
78 clib_bihash_add_del_8_8 (&cnat_translation_db, &bkey, 1);
82 cnat_remove_translation_from_db (index_t cci, u16 port, ip_protocol_t proto)
84 clib_bihash_kv_8_8_t bkey;
87 key = (proto << 16) | port;
88 key = key << 32 | (u32) cci;
92 clib_bihash_add_del_8_8 (&cnat_translation_db, &bkey, 0);
96 cnat_translation_stack (cnat_translation_t * ct)
98 fib_protocol_t fproto;
103 fproto = ip_address_family_to_fib_proto (ct->ct_vip.ce_ip.version);
104 dproto = fib_proto_to_dpo (fproto);
106 lbi = load_balance_create (vec_len (ct->ct_paths),
107 fib_proto_to_dpo (fproto), IP_FLOW_HASH_DEFAULT);
109 vec_foreach (trk, ct->ct_paths)
110 load_balance_set_bucket (lbi, trk - ct->ct_paths, &trk->ct_dpo);
112 dpo_set (&ct->ct_lb, DPO_LOAD_BALANCE, dproto, lbi);
113 dpo_stack (cnat_client_dpo, dproto, &ct->ct_lb, &ct->ct_lb);
117 cnat_translation_delete (u32 id)
119 cnat_translation_t *ct;
122 if (pool_is_free_index (cnat_translation_pool, id))
123 return (VNET_API_ERROR_NO_SUCH_ENTRY);
125 ct = pool_elt_at_index (cnat_translation_pool, id);
127 dpo_reset (&ct->ct_lb);
129 vec_foreach (trk, ct->ct_paths) cnat_tracker_release (trk);
131 cnat_remove_translation_from_db (ct->ct_cci, ct->ct_vip.ce_port,
133 cnat_client_translation_deleted (ct->ct_cci);
134 pool_put (cnat_translation_pool, ct);
140 cnat_translation_update (const cnat_endpoint_t * vip,
142 const cnat_endpoint_tuple_t * paths, u8 flags)
144 const cnat_endpoint_tuple_t *path;
145 const cnat_client_t *cc;
146 cnat_translation_t *ct;
150 /* do we know of this ep's vip */
151 cci = cnat_client_add (&vip->ce_ip, flags);
152 cc = cnat_client_get (cci);
154 ct = cnat_find_translation (cc->parent_cci, vip->ce_port, proto);
158 pool_get_zero (cnat_translation_pool, ct);
160 clib_memcpy (&ct->ct_vip, vip, sizeof (*vip));
161 ct->ct_proto = proto;
163 ct->index = ct - cnat_translation_pool;
165 cnat_add_translation_to_db (cci, ct->ct_vip.ce_port, ct->ct_proto,
167 cnat_client_translation_added (cci);
169 vlib_validate_combined_counter (&cnat_translation_counters, ct->index);
170 vlib_zero_combined_counter (&cnat_translation_counters, ct->index);
174 vec_foreach (trk, ct->ct_paths)
176 cnat_tracker_release (trk);
179 vec_reset_length (ct->ct_paths);
181 vec_foreach (path, paths)
183 vec_add2 (ct->ct_paths, trk, 1);
185 cnat_tracker_track (ct->index, path, trk);
188 cnat_translation_stack (ct);
194 cnat_translation_walk (cnat_translation_walk_cb_t cb, void *ctx)
199 pool_foreach_index(api, cnat_translation_pool,
208 format_cnat_ep_trk (u8 * s, va_list * args)
210 cnat_ep_trk_t *ck = va_arg (*args, cnat_ep_trk_t *);
211 u32 indent = va_arg (*args, u32);
213 s = format (s, "%U->%U", format_cnat_endpoint, &ck->ct_ep[VLIB_RX],
214 format_cnat_endpoint, &ck->ct_ep[VLIB_TX]);
215 s = format (s, "\n%Ufib-entry:%d", format_white_space, indent, ck->ct_fei);
216 s = format (s, "\n%U%U",
217 format_white_space, indent, format_dpo_id, &ck->ct_dpo, 6);
223 format_cnat_translation (u8 * s, va_list * args)
225 cnat_translation_t *ct = va_arg (*args, cnat_translation_t *);
228 s = format (s, "[%d] ", ct->index);
229 s = format (s, "%U %U", format_cnat_endpoint, &ct->ct_vip,
230 format_ip_protocol, ct->ct_proto);
232 vec_foreach (ck, ct->ct_paths)
233 s = format (s, "\n%U", format_cnat_ep_trk, ck, 2);
235 /* If printing a trace, the LB object might be deleted */
236 if (!pool_is_free_index (load_balance_pool, ct->ct_lb.dpoi_index))
238 s = format (s, "\n via:");
239 s = format (s, "\n%U%U",
240 format_white_space, 2, format_dpo_id, &ct->ct_lb, 2);
246 static clib_error_t *
247 cnat_translation_show (vlib_main_t * vm,
248 unformat_input_t * input, vlib_cli_command_t * cmd)
251 cnat_translation_t *ct;
255 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
257 if (unformat (input, "%d", &cti))
260 return (clib_error_return (0, "unknown input '%U'",
261 format_unformat_error, input));
264 if (INDEX_INVALID == cti)
267 pool_foreach_index(cti, cnat_translation_pool,
269 ct = pool_elt_at_index (cnat_translation_pool, cti);
270 vlib_cli_output(vm, "%U", format_cnat_translation, ct);
276 vlib_cli_output (vm, "Invalid policy ID:%d", cti);
283 cnat_translation_purge (void)
285 /* purge all the translations */
286 index_t tri, *trp, *trs = NULL;
289 pool_foreach_index(tri, cnat_translation_pool,
295 vec_foreach (trp, trs) cnat_translation_delete (*trp);
297 ASSERT (0 == pool_elts (cnat_translation_pool));
305 VLIB_CLI_COMMAND (cnat_translation_show_cmd_node, static) = {
306 .path = "show cnat translation",
307 .function = cnat_translation_show,
308 .short_help = "show cnat translation <VIP>",
314 cnat_translation_get_node (fib_node_index_t index)
316 cnat_translation_t *ct = cnat_translation_get (index);
317 return (&(ct->ct_node));
320 static cnat_translation_t *
321 cnat_translation_get_from_node (fib_node_t * node)
323 return ((cnat_translation_t *) (((char *) node) -
324 STRUCT_OFFSET_OF (cnat_translation_t,
329 cnat_translation_last_lock_gone (fib_node_t * node)
334 * A back walk has reached this ABF policy
336 static fib_node_back_walk_rc_t
337 cnat_translation_back_walk_notify (fib_node_t * node,
338 fib_node_back_walk_ctx_t * ctx)
341 * re-stack the fmask on the n-eos of the via
343 cnat_translation_t *ct = cnat_translation_get_from_node (node);
345 cnat_translation_stack (ct);
347 return (FIB_NODE_BACK_WALK_CONTINUE);
351 * The translation's graph node virtual function table
353 static const fib_node_vft_t cnat_translation_vft = {
354 .fnv_get = cnat_translation_get_node,
355 .fnv_last_lock = cnat_translation_last_lock_gone,
356 .fnv_back_walk = cnat_translation_back_walk_notify,
359 static clib_error_t *
360 cnat_translation_cli_add_del (vlib_main_t * vm,
361 unformat_input_t * input,
362 vlib_cli_command_t * cmd)
364 u32 del_index = INDEX_INVALID;
365 ip_protocol_t proto = IP_PROTOCOL_TCP;
367 u8 flags = CNAT_FLAG_EXCLUSIVE;
368 cnat_endpoint_tuple_t tmp, *paths = NULL, *path;
370 while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT)
372 if (unformat (input, "add"))
373 del_index = INDEX_INVALID;
374 else if (unformat (input, "del %d", &del_index))
376 else if (unformat (input, "proto %U", unformat_ip_protocol, &proto))
378 else if (unformat (input, "vip %U", unformat_cnat_ep, &vip))
379 flags = CNAT_FLAG_EXCLUSIVE;
380 else if (unformat (input, "real %U", unformat_cnat_ep, &vip))
382 else if (unformat (input, "to %U", unformat_cnat_ep_tuple, &tmp))
384 pool_get (paths, path);
385 clib_memcpy (path, &tmp, sizeof (cnat_endpoint_tuple_t));
388 return (clib_error_return (0, "unknown input '%U'",
389 format_unformat_error, input));
392 if (INDEX_INVALID == del_index)
393 cnat_translation_update (&vip, proto, paths, flags);
395 cnat_translation_delete (del_index);
402 VLIB_CLI_COMMAND (cnat_translation_cli_add_del_command, static) =
404 .path = "cnat translation",
405 .short_help = "cnat translation [add|del] proto [TCP|UDP] [vip|real] [ip] [port] [to [ip] [port]->[ip] [port]]",
406 .function = cnat_translation_cli_add_del,
410 static clib_error_t *
411 cnat_translation_init (vlib_main_t * vm)
413 cnat_main_t *cm = &cnat_main;
414 cnat_translation_fib_node_type =
415 fib_node_register_new_type (&cnat_translation_vft);
417 clib_bihash_init_8_8 (&cnat_translation_db, "CNat translation DB",
418 cm->translation_hash_buckets,
419 cm->translation_hash_memory);
424 VLIB_INIT_FUNCTION (cnat_translation_init);
427 * fd.io coding-style-patch-verification: ON
430 * eval: (c-set-style "gnu")