2 * Copyright (c) 2020 Doc.ai and/or its affiliates.
3 * Copyright (c) 2020 Cisco and/or its affiliates.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at:
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
17 #ifndef __included_wg_peer_h__
18 #define __included_wg_peer_h__
20 #include <vlibapi/api_helper_macros.h>
22 #include <vnet/ip/ip.h>
24 #include <wireguard/wireguard_cookie.h>
25 #include <wireguard/wireguard_timer.h>
26 #include <wireguard/wireguard_key.h>
27 #include <wireguard/wireguard_messages.h>
28 #include <wireguard/wireguard_if.h>
30 typedef struct ip4_udp_header_t_
34 } __clib_packed ip4_udp_header_t;
36 typedef struct ip4_udp_wg_header_t_
41 } __clib_packed ip4_udp_wg_header_t;
43 typedef struct ip6_udp_header_t_
47 } __clib_packed ip6_udp_header_t;
49 typedef struct ip6_udp_wg_header_t_
54 } __clib_packed ip6_udp_wg_header_t;
56 u8 *format_ip4_udp_header (u8 * s, va_list * va);
57 u8 *format_ip6_udp_header (u8 *s, va_list *va);
59 typedef struct wg_peer_endpoint_t_
67 WG_PEER_STATUS_DEAD = 0x1,
68 WG_PEER_ESTABLISHED = 0x2,
71 typedef struct wg_peer_adj_t_
73 adj_index_t adj_index;
74 fib_node_index_t fib_entry_index;
78 typedef struct wg_peer
80 noise_remote_t remote;
81 cookie_maker_t cookie_maker;
83 u32 input_thread_index;
84 u32 output_thread_index;
87 wg_peer_endpoint_t dst;
88 wg_peer_endpoint_t src;
92 /* rewrite built from address information */
95 /* Vector of allowed-ips */
96 fib_prefix_t *allowed_ips;
98 /* The WG interface this peer is attached to */
101 /* API client registered for events */
102 vpe_client_registration_t *api_clients;
103 uword *api_client_by_client_index;
107 tw_timer_wheel_16t_2w_512sl_t *timer_wheel;
108 u32 timers[WG_N_TIMERS];
109 u8 timers_dispatched[WG_N_TIMERS];
110 u32 timer_handshake_attempts;
111 u16 persistent_keepalive_interval;
114 f64 last_sent_handshake;
115 f64 last_sent_packet;
116 f64 last_received_packet;
118 f64 rehandshake_started;
120 /* Variable intervals */
121 u32 new_handshake_interval_tick;
122 u32 rehandshake_interval_tick;
124 bool timer_need_another_keepalive;
127 typedef struct wg_peer_table_bind_ctx_t_
129 ip_address_family_t af;
132 } wg_peer_table_bind_ctx_t;
134 int wg_peer_add (u32 tun_sw_if_index,
135 const u8 public_key_64[NOISE_PUBLIC_KEY_LEN],
137 const ip46_address_t * endpoint,
138 const fib_prefix_t * allowed_ips,
139 u16 port, u16 persistent_keepalive, index_t * peer_index);
140 int wg_peer_remove (u32 peer_index);
142 typedef walk_rc_t (*wg_peer_walk_cb_t) (index_t peeri, void *arg);
143 index_t wg_peer_walk (wg_peer_walk_cb_t fn, void *data);
145 u8 *format_wg_peer (u8 * s, va_list * va);
147 walk_rc_t wg_peer_if_admin_state_change (index_t peeri, void *data);
148 walk_rc_t wg_peer_if_delete (index_t peeri, void *data);
149 walk_rc_t wg_peer_if_adj_change (index_t peeri, void *data);
150 adj_walk_rc_t wg_peer_adj_walk (adj_index_t ai, void *data);
152 void wg_api_peer_event (index_t peeri, wg_peer_flags flags);
153 void wg_peer_update_flags (index_t peeri, wg_peer_flags flag, bool add_del);
154 void wg_peer_update_endpoint (index_t peeri, const ip46_address_t *addr,
156 void wg_peer_update_endpoint_from_mt (index_t peeri,
157 const ip46_address_t *addr, u16 port);
160 wg_peer_is_dead (wg_peer_t *peer)
162 return peer && peer->flags & WG_PEER_STATUS_DEAD;
166 * Expoed for the data-plane
168 extern index_t *wg_peer_by_adj_index;
169 extern wg_peer_t *wg_peer_pool;
171 static inline wg_peer_t *
172 wg_peer_get (index_t peeri)
174 return (pool_elt_at_index (wg_peer_pool, peeri));
177 static inline index_t
178 wg_peer_get_by_adj_index (index_t ai)
180 if (ai >= vec_len (wg_peer_by_adj_index))
181 return INDEX_INVALID;
182 return (wg_peer_by_adj_index[ai]);
186 * Makes choice for thread_id should be assigned.
189 wg_peer_assign_thread (u32 thread_id)
191 return ((thread_id) ? thread_id
192 : (vlib_num_workers ()?
193 ((unix_time_now_nsec () % vlib_num_workers ()) +
197 static_always_inline bool
198 fib_prefix_is_cover_addr_46 (const fib_prefix_t *p1, const ip46_address_t *ip)
200 switch (p1->fp_proto)
202 case FIB_PROTOCOL_IP4:
203 return (ip4_destination_matches_route (&ip4_main, &p1->fp_addr.ip4,
204 &ip->ip4, p1->fp_len) != 0);
205 case FIB_PROTOCOL_IP6:
206 return (ip6_destination_matches_route (&ip6_main, &p1->fp_addr.ip6,
207 &ip->ip6, p1->fp_len) != 0);
208 case FIB_PROTOCOL_MPLS:
215 wg_peer_can_send (wg_peer_t *peer)
217 return peer && peer->rewrite;
220 #endif // __included_wg_peer_h__
223 * fd.io coding-style-patch-verification: ON
226 * eval: (c-set-style "gnu")