2 * Copyright (c) 2017 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
18 * @brief IPv4 Shallow Virtual Reassembly.
20 * This file contains the source code for IPv4 Shallow Virtual reassembly.
23 #include <vppinfra/vec.h>
24 #include <vnet/vnet.h>
25 #include <vnet/ip/ip.h>
26 #include <vnet/ip/ip4_to_ip6.h>
27 #include <vppinfra/fifo.h>
28 #include <vppinfra/bihash_16_8.h>
29 #include <vnet/ip/reass/ip4_sv_reass.h>
31 #define MSEC_PER_SEC 1000
32 #define IP4_SV_REASS_TIMEOUT_DEFAULT_MS 100
33 #define IP4_SV_REASS_EXPIRE_WALK_INTERVAL_DEFAULT_MS 10000 // 10 seconds default
34 #define IP4_SV_REASS_MAX_REASSEMBLIES_DEFAULT 1024
35 #define IP4_SV_REASS_MAX_REASSEMBLY_LENGTH_DEFAULT 3
36 #define IP4_SV_REASS_HT_LOAD_FACTOR (0.75)
41 IP4_SV_REASS_RC_TOO_MANY_FRAGMENTS,
42 IP4_SV_REASS_RC_UNSUPP_IP_PROTO,
79 clib_bihash_kv_16_8_t kv;
85 ip4_sv_reass_key_t key;
86 // time when last packet was received
88 // internal id of this reassembly
90 // trace operation counter
92 // minimum fragment length for this reassembly - used to estimate MTU
93 u16 min_fragment_length;
94 // buffer indexes of buffers in this reassembly in chronological order -
95 // including overlaps and duplicate fragments
97 // set to true when this reassembly is completed
101 u8 icmp_type_or_tcp_flags;
116 ip4_sv_reass_t *pool;
119 clib_spinlock_t lock;
124 } ip4_sv_reass_per_thread_t;
131 u32 expire_walk_interval_ms;
132 // maximum number of fragments in one reassembly
134 // maximum number of reassemblies
138 clib_bihash_16_8_t hash;
140 ip4_sv_reass_per_thread_t *per_thread_data;
143 vlib_main_t *vlib_main;
144 vnet_main_t *vnet_main;
146 // node index of ip4-drop node
148 u32 ip4_sv_reass_expire_node_idx;
150 /** Worker handoff */
152 u32 fq_feature_index;
154 // reference count for enabling/disabling feature - per interface
155 u32 *feature_use_refcount_per_intf;
157 // reference count for enabling/disabling feature - per interface
158 u32 *output_feature_use_refcount_per_intf;
160 } ip4_sv_reass_main_t;
162 extern ip4_sv_reass_main_t ip4_sv_reass_main;
164 #ifndef CLIB_MARCH_VARIANT
165 ip4_sv_reass_main_t ip4_sv_reass_main;
166 #endif /* CLIB_MARCH_VARIANT */
170 IP4_SV_REASSEMBLY_NEXT_INPUT,
171 IP4_SV_REASSEMBLY_NEXT_DROP,
172 IP4_SV_REASSEMBLY_NEXT_HANDOFF,
173 IP4_SV_REASSEMBLY_N_NEXT,
174 } ip4_sv_reass_next_t;
178 REASS_FRAGMENT_CACHE,
180 REASS_FRAGMENT_FORWARD,
182 } ip4_sv_reass_trace_operation_e;
186 ip4_sv_reass_trace_operation_e action;
192 } ip4_sv_reass_trace_t;
194 extern vlib_node_registration_t ip4_sv_reass_node;
195 extern vlib_node_registration_t ip4_sv_reass_node_feature;
198 format_ip4_sv_reass_trace (u8 * s, va_list * args)
200 CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
201 CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
202 ip4_sv_reass_trace_t *t = va_arg (*args, ip4_sv_reass_trace_t *);
203 if (REASS_PASSTHROUGH != t->action)
205 s = format (s, "reass id: %u, op id: %u ", t->reass_id, t->op_id);
209 case REASS_FRAGMENT_CACHE:
210 s = format (s, "[cached]");
214 format (s, "[finish, ip proto=%u, src_port=%u, dst_port=%u]",
215 t->ip_proto, clib_net_to_host_u16 (t->l4_src_port),
216 clib_net_to_host_u16 (t->l4_dst_port));
218 case REASS_FRAGMENT_FORWARD:
220 format (s, "[forward, ip proto=%u, src_port=%u, dst_port=%u]",
221 t->ip_proto, clib_net_to_host_u16 (t->l4_src_port),
222 clib_net_to_host_u16 (t->l4_dst_port));
224 case REASS_PASSTHROUGH:
225 s = format (s, "[not-fragmented]");
232 ip4_sv_reass_add_trace (vlib_main_t * vm, vlib_node_runtime_t * node,
233 ip4_sv_reass_main_t * rm, ip4_sv_reass_t * reass,
234 u32 bi, ip4_sv_reass_trace_operation_e action,
235 u32 ip_proto, u16 l4_src_port, u16 l4_dst_port)
237 vlib_buffer_t *b = vlib_get_buffer (vm, bi);
238 ip4_sv_reass_trace_t *t = vlib_add_trace (vm, node, b, sizeof (t[0]));
241 t->reass_id = reass->id;
242 t->op_id = reass->trace_op_counter;
243 ++reass->trace_op_counter;
246 t->ip_proto = ip_proto;
247 t->l4_src_port = l4_src_port;
248 t->l4_dst_port = l4_dst_port;
251 s = format (s, "%U", format_ip4_sv_reass_trace, NULL, NULL, t);
252 printf ("%.*s\n", vec_len (s), s);
254 vec_reset_length (s);
260 ip4_sv_reass_free (vlib_main_t * vm, ip4_sv_reass_main_t * rm,
261 ip4_sv_reass_per_thread_t * rt, ip4_sv_reass_t * reass)
263 clib_bihash_kv_16_8_t kv;
264 kv.key[0] = reass->key.as_u64[0];
265 kv.key[1] = reass->key.as_u64[1];
266 clib_bihash_add_del_16_8 (&rm->hash, &kv, 0);
267 vlib_buffer_free (vm, reass->cached_buffers,
268 vec_len (reass->cached_buffers));
269 vec_free (reass->cached_buffers);
270 reass->cached_buffers = NULL;
271 if (~0 != reass->lru_prev)
273 ip4_sv_reass_t *lru_prev =
274 pool_elt_at_index (rt->pool, reass->lru_prev);
275 lru_prev->lru_next = reass->lru_next;
277 if (~0 != reass->lru_next)
279 ip4_sv_reass_t *lru_next =
280 pool_elt_at_index (rt->pool, reass->lru_next);
281 lru_next->lru_prev = reass->lru_prev;
283 if (rt->lru_first == reass - rt->pool)
285 rt->lru_first = reass->lru_next;
287 if (rt->lru_last == reass - rt->pool)
289 rt->lru_last = reass->lru_prev;
291 pool_put (rt->pool, reass);
296 ip4_sv_reass_init (ip4_sv_reass_t * reass)
298 reass->cached_buffers = NULL;
299 reass->is_complete = false;
302 always_inline ip4_sv_reass_t *
303 ip4_sv_reass_find_or_create (vlib_main_t * vm, ip4_sv_reass_main_t * rm,
304 ip4_sv_reass_per_thread_t * rt,
305 ip4_sv_reass_kv_t * kv, u8 * do_handoff)
307 ip4_sv_reass_t *reass = NULL;
308 f64 now = vlib_time_now (rm->vlib_main);
310 if (!clib_bihash_search_16_8
311 (&rm->hash, (clib_bihash_kv_16_8_t *) kv, (clib_bihash_kv_16_8_t *) kv))
313 if (vm->thread_index != kv->v.thread_index)
318 reass = pool_elt_at_index (rt->pool, kv->v.reass_index);
320 if (now > reass->last_heard + rm->timeout)
322 ip4_sv_reass_free (vm, rm, rt, reass);
329 reass->last_heard = now;
333 if (rt->reass_n >= rm->max_reass_n && rm->max_reass_n)
335 reass = pool_elt_at_index (rt->pool, rt->lru_last);
336 ip4_sv_reass_free (vm, rm, rt, reass);
339 pool_get (rt->pool, reass);
340 clib_memset (reass, 0, sizeof (*reass));
341 reass->id = ((u64) vm->thread_index * 1000000000) + rt->id_counter;
343 ip4_sv_reass_init (reass);
345 reass->lru_prev = reass->lru_next = ~0;
347 if (~0 != rt->lru_last)
349 ip4_sv_reass_t *lru_last = pool_elt_at_index (rt->pool, rt->lru_last);
350 reass->lru_prev = rt->lru_last;
351 lru_last->lru_next = rt->lru_last = reass - rt->pool;
354 if (~0 == rt->lru_first)
356 rt->lru_first = rt->lru_last = reass - rt->pool;
359 reass->key.as_u64[0] = ((clib_bihash_kv_16_8_t *) kv)->key[0];
360 reass->key.as_u64[1] = ((clib_bihash_kv_16_8_t *) kv)->key[1];
361 kv->v.reass_index = (reass - rt->pool);
362 kv->v.thread_index = vm->thread_index;
363 reass->last_heard = now;
365 if (clib_bihash_add_del_16_8 (&rm->hash, (clib_bihash_kv_16_8_t *) kv, 1))
367 ip4_sv_reass_free (vm, rm, rt, reass);
374 always_inline ip4_sv_reass_rc_t
375 ip4_sv_reass_update (vlib_main_t * vm, vlib_node_runtime_t * node,
376 ip4_sv_reass_main_t * rm, ip4_sv_reass_per_thread_t * rt,
377 ip4_header_t * ip0, ip4_sv_reass_t * reass, u32 bi0)
379 vlib_buffer_t *b0 = vlib_get_buffer (vm, bi0);
380 ip4_sv_reass_rc_t rc = IP4_SV_REASS_RC_OK;
381 const u32 fragment_first = ip4_get_fragment_offset_bytes (ip0);
382 if (0 == fragment_first)
384 reass->ip_proto = ip0->protocol;
385 reass->l4_src_port = ip4_get_port (ip0, 1);
386 reass->l4_dst_port = ip4_get_port (ip0, 0);
387 if (!reass->l4_src_port || !reass->l4_dst_port)
388 return IP4_SV_REASS_RC_UNSUPP_IP_PROTO;
389 if (IP_PROTOCOL_TCP == reass->ip_proto)
391 reass->icmp_type_or_tcp_flags = ((tcp_header_t *) (ip0 + 1))->flags;
392 reass->tcp_ack_number = ((tcp_header_t *) (ip0 + 1))->ack_number;
393 reass->tcp_seq_number = ((tcp_header_t *) (ip0 + 1))->seq_number;
395 else if (IP_PROTOCOL_ICMP == reass->ip_proto)
397 reass->icmp_type_or_tcp_flags =
398 ((icmp46_header_t *) (ip0 + 1))->type;
400 reass->is_complete = true;
401 vlib_buffer_t *b0 = vlib_get_buffer (vm, bi0);
402 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
404 ip4_sv_reass_add_trace (vm, node, rm, reass, bi0, REASS_FINISH,
405 reass->ip_proto, reass->l4_src_port,
409 vec_add1 (reass->cached_buffers, bi0);
410 if (!reass->is_complete)
412 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
414 ip4_sv_reass_add_trace (vm, node, rm, reass, bi0,
415 REASS_FRAGMENT_CACHE, ~0, ~0, ~0);
417 if (vec_len (reass->cached_buffers) > rm->max_reass_len)
419 rc = IP4_SV_REASS_RC_TOO_MANY_FRAGMENTS;
426 ip4_sv_reass_inline (vlib_main_t * vm, vlib_node_runtime_t * node,
427 vlib_frame_t * frame, bool is_feature,
428 bool is_output_feature, bool is_custom)
430 u32 *from = vlib_frame_vector_args (frame);
431 u32 n_left_from, n_left_to_next, *to_next, next_index;
432 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
433 ip4_sv_reass_per_thread_t *rt = &rm->per_thread_data[vm->thread_index];
434 clib_spinlock_lock (&rt->lock);
436 n_left_from = frame->n_vectors;
437 next_index = node->cached_next_index;
439 while (n_left_from > 0)
441 vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
443 while (n_left_from > 0 && n_left_to_next > 0)
448 u32 error0 = IP4_ERROR_NONE;
451 b0 = vlib_get_buffer (vm, bi0);
454 (ip4_header_t *) u8_ptr_add (vlib_buffer_get_current (b0),
457 ip.save_rewrite_length);
458 if (!ip4_get_fragment_more (ip0) && !ip4_get_fragment_offset (ip0))
460 // this is a regular packet - no fragmentation
463 next0 = vnet_buffer (b0)->ip.reass.next_index;
467 next0 = IP4_SV_REASSEMBLY_NEXT_INPUT;
469 vnet_buffer (b0)->ip.reass.save_rewrite_length =
470 vnet_buffer (b0)->ip.save_rewrite_length;
471 vnet_buffer (b0)->ip.reass.is_non_first_fragment = 0;
472 vnet_buffer (b0)->ip.reass.ip_proto = ip0->protocol;
473 if (IP_PROTOCOL_TCP == ip0->protocol)
475 vnet_buffer (b0)->ip.reass.icmp_type_or_tcp_flags =
476 ((tcp_header_t *) (ip0 + 1))->flags;
477 vnet_buffer (b0)->ip.reass.tcp_ack_number =
478 ((tcp_header_t *) (ip0 + 1))->ack_number;
479 vnet_buffer (b0)->ip.reass.tcp_seq_number =
480 ((tcp_header_t *) (ip0 + 1))->seq_number;
482 else if (IP_PROTOCOL_ICMP == ip0->protocol)
484 vnet_buffer (b0)->ip.reass.icmp_type_or_tcp_flags =
485 ((icmp46_header_t *) (ip0 + 1))->type;
487 vnet_buffer (b0)->ip.reass.l4_src_port = ip4_get_port (ip0, 1);
488 vnet_buffer (b0)->ip.reass.l4_dst_port = ip4_get_port (ip0, 0);
489 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
491 ip4_sv_reass_add_trace (vm, node, rm, NULL, bi0,
493 vnet_buffer (b0)->ip.reass.ip_proto,
494 vnet_buffer (b0)->ip.
496 vnet_buffer (b0)->ip.
501 const u32 fragment_first = ip4_get_fragment_offset_bytes (ip0);
502 const u32 fragment_length =
503 clib_net_to_host_u16 (ip0->length) - ip4_header_bytes (ip0);
504 const u32 fragment_last = fragment_first + fragment_length - 1;
505 if (fragment_first > fragment_last || fragment_first + fragment_length > UINT16_MAX - 20 || (fragment_length < 8 && ip4_get_fragment_more (ip0))) // 8 is minimum frag length per RFC 791
507 next0 = IP4_SV_REASSEMBLY_NEXT_DROP;
508 error0 = IP4_ERROR_REASS_MALFORMED_PACKET;
511 ip4_sv_reass_kv_t kv;
515 (u64) vec_elt (ip4_main.fib_index_by_sw_if_index,
516 vnet_buffer (b0)->sw_if_index[VLIB_RX]) |
517 (u64) ip0->src_address.as_u32 << 32;
519 (u64) ip0->dst_address.
520 as_u32 | (u64) ip0->fragment_id << 32 | (u64) ip0->protocol << 48;
522 ip4_sv_reass_t *reass =
523 ip4_sv_reass_find_or_create (vm, rm, rt, &kv, &do_handoff);
525 if (PREDICT_FALSE (do_handoff))
527 next0 = IP4_SV_REASSEMBLY_NEXT_HANDOFF;
528 vnet_buffer (b0)->ip.reass.owner_thread_index =
535 next0 = IP4_SV_REASSEMBLY_NEXT_DROP;
536 error0 = IP4_ERROR_REASS_LIMIT_REACHED;
540 if (reass->is_complete)
544 next0 = vnet_buffer (b0)->ip.reass.next_index;
548 next0 = IP4_SV_REASSEMBLY_NEXT_INPUT;
550 vnet_buffer (b0)->ip.reass.save_rewrite_length =
551 vnet_buffer (b0)->ip.save_rewrite_length;
552 vnet_buffer (b0)->ip.reass.is_non_first_fragment =
554 vnet_buffer (b0)->ip.reass.ip_proto = reass->ip_proto;
555 vnet_buffer (b0)->ip.reass.icmp_type_or_tcp_flags =
556 reass->icmp_type_or_tcp_flags;
557 vnet_buffer (b0)->ip.reass.tcp_ack_number =
558 reass->tcp_ack_number;
559 vnet_buffer (b0)->ip.reass.tcp_seq_number =
560 reass->tcp_seq_number;
561 vnet_buffer (b0)->ip.reass.l4_src_port = reass->l4_src_port;
562 vnet_buffer (b0)->ip.reass.l4_dst_port = reass->l4_dst_port;
563 error0 = IP4_ERROR_NONE;
564 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
566 ip4_sv_reass_add_trace (vm, node, rm, reass, bi0,
567 REASS_FRAGMENT_FORWARD,
575 ip4_sv_reass_rc_t rc =
576 ip4_sv_reass_update (vm, node, rm, rt, ip0, reass, bi0);
579 case IP4_SV_REASS_RC_OK:
580 /* nothing to do here */
582 case IP4_SV_REASS_RC_TOO_MANY_FRAGMENTS:
583 vlib_node_increment_counter (vm, node->node_index,
584 IP4_ERROR_REASS_FRAGMENT_CHAIN_TOO_LONG,
586 ip4_sv_reass_free (vm, rm, rt, reass);
589 case IP4_SV_REASS_RC_UNSUPP_IP_PROTO:
590 vlib_node_increment_counter (vm, node->node_index,
591 IP4_ERROR_REASS_FRAGMENT_CHAIN_TOO_LONG,
593 ip4_sv_reass_free (vm, rm, rt, reass);
597 if (reass->is_complete)
600 vec_foreach_index (idx, reass->cached_buffers)
602 u32 bi0 = vec_elt (reass->cached_buffers, idx);
603 vlib_buffer_t *b0 = vlib_get_buffer (vm, bi0);
604 u32 next0 = IP4_SV_REASSEMBLY_NEXT_INPUT;
607 vnet_feature_next (&next0, b0);
611 next0 = vnet_buffer (b0)->ip.reass.next_index;
613 if (0 == n_left_to_next)
615 vlib_put_next_frame (vm, node, next_index,
617 vlib_get_next_frame (vm, node, next_index, to_next,
623 ASSERT (vnet_buffer (b0)->ip.save_rewrite_length < (2 << 14));
624 vnet_buffer (b0)->ip.reass.save_rewrite_length =
625 vnet_buffer (b0)->ip.save_rewrite_length;
626 vnet_buffer (b0)->ip.reass.is_non_first_fragment =
627 ! !ip4_get_fragment_offset (vlib_buffer_get_current (b0));
628 vnet_buffer (b0)->ip.reass.ip_proto = reass->ip_proto;
629 vnet_buffer (b0)->ip.reass.icmp_type_or_tcp_flags =
630 reass->icmp_type_or_tcp_flags;
631 vnet_buffer (b0)->ip.reass.tcp_ack_number =
632 reass->tcp_ack_number;
633 vnet_buffer (b0)->ip.reass.tcp_seq_number =
634 reass->tcp_seq_number;
635 vnet_buffer (b0)->ip.reass.l4_src_port = reass->l4_src_port;
636 vnet_buffer (b0)->ip.reass.l4_dst_port = reass->l4_dst_port;
637 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
639 ip4_sv_reass_add_trace (vm, node, rm, reass, bi0,
640 REASS_FRAGMENT_FORWARD,
645 vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
646 to_next, n_left_to_next, bi0,
649 _vec_len (reass->cached_buffers) = 0; // buffers are owned by frame now
654 b0->error = node->errors[error0];
659 if (is_feature && IP4_ERROR_NONE == error0)
661 b0 = vlib_get_buffer (vm, bi0);
662 vnet_feature_next (&next0, b0);
664 vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
665 to_next, n_left_to_next,
673 vlib_put_next_frame (vm, node, next_index, n_left_to_next);
676 clib_spinlock_unlock (&rt->lock);
677 return frame->n_vectors;
680 static char *ip4_sv_reass_error_strings[] = {
681 #define _(sym, string) string,
686 VLIB_NODE_FN (ip4_sv_reass_node) (vlib_main_t * vm,
687 vlib_node_runtime_t * node,
688 vlib_frame_t * frame)
690 return ip4_sv_reass_inline (vm, node, frame, false /* is_feature */ ,
691 false /* is_output_feature */ ,
692 false /* is_custom */ );
696 VLIB_REGISTER_NODE (ip4_sv_reass_node) = {
697 .name = "ip4-sv-reassembly",
698 .vector_size = sizeof (u32),
699 .format_trace = format_ip4_sv_reass_trace,
700 .n_errors = ARRAY_LEN (ip4_sv_reass_error_strings),
701 .error_strings = ip4_sv_reass_error_strings,
702 .n_next_nodes = IP4_SV_REASSEMBLY_N_NEXT,
705 [IP4_SV_REASSEMBLY_NEXT_INPUT] = "ip4-input",
706 [IP4_SV_REASSEMBLY_NEXT_DROP] = "ip4-drop",
707 [IP4_SV_REASSEMBLY_NEXT_HANDOFF] = "ip4-sv-reassembly-handoff",
713 VLIB_NODE_FN (ip4_sv_reass_node_feature) (vlib_main_t * vm,
714 vlib_node_runtime_t * node,
715 vlib_frame_t * frame)
717 return ip4_sv_reass_inline (vm, node, frame, true /* is_feature */ ,
718 false /* is_output_feature */ ,
719 false /* is_custom */ );
723 VLIB_REGISTER_NODE (ip4_sv_reass_node_feature) = {
724 .name = "ip4-sv-reassembly-feature",
725 .vector_size = sizeof (u32),
726 .format_trace = format_ip4_sv_reass_trace,
727 .n_errors = ARRAY_LEN (ip4_sv_reass_error_strings),
728 .error_strings = ip4_sv_reass_error_strings,
729 .n_next_nodes = IP4_SV_REASSEMBLY_N_NEXT,
732 [IP4_SV_REASSEMBLY_NEXT_INPUT] = "ip4-input",
733 [IP4_SV_REASSEMBLY_NEXT_DROP] = "ip4-drop",
734 [IP4_SV_REASSEMBLY_NEXT_HANDOFF] = "ip4-sv-reass-feature-hoff",
740 VNET_FEATURE_INIT (ip4_sv_reass_feature) = {
741 .arc_name = "ip4-unicast",
742 .node_name = "ip4-sv-reassembly-feature",
743 .runs_before = VNET_FEATURES ("ip4-lookup"),
748 VLIB_NODE_FN (ip4_sv_reass_node_output_feature) (vlib_main_t * vm,
749 vlib_node_runtime_t * node,
750 vlib_frame_t * frame)
752 return ip4_sv_reass_inline (vm, node, frame, true /* is_feature */ ,
753 true /* is_output_feature */ ,
754 false /* is_custom */ );
759 VLIB_REGISTER_NODE (ip4_sv_reass_node_output_feature) = {
760 .name = "ip4-sv-reassembly-output-feature",
761 .vector_size = sizeof (u32),
762 .format_trace = format_ip4_sv_reass_trace,
763 .n_errors = ARRAY_LEN (ip4_sv_reass_error_strings),
764 .error_strings = ip4_sv_reass_error_strings,
765 .n_next_nodes = IP4_SV_REASSEMBLY_N_NEXT,
768 [IP4_SV_REASSEMBLY_NEXT_INPUT] = "ip4-input",
769 [IP4_SV_REASSEMBLY_NEXT_DROP] = "ip4-drop",
770 [IP4_SV_REASSEMBLY_NEXT_HANDOFF] = "ip4-sv-reass-feature-hoff",
776 VNET_FEATURE_INIT (ip4_sv_reass_output_feature) = {
777 .arc_name = "ip4-output",
778 .node_name = "ip4-sv-reassembly-output-feature",
785 VLIB_REGISTER_NODE (ip4_sv_reass_custom_node) = {
786 .name = "ip4-sv-reassembly-custom-next",
787 .vector_size = sizeof (u32),
788 .format_trace = format_ip4_sv_reass_trace,
789 .n_errors = ARRAY_LEN (ip4_sv_reass_error_strings),
790 .error_strings = ip4_sv_reass_error_strings,
791 .n_next_nodes = IP4_SV_REASSEMBLY_N_NEXT,
794 [IP4_SV_REASSEMBLY_NEXT_INPUT] = "ip4-input",
795 [IP4_SV_REASSEMBLY_NEXT_DROP] = "ip4-drop",
796 [IP4_SV_REASSEMBLY_NEXT_HANDOFF] = "ip4-sv-reassembly-handoff",
802 VLIB_NODE_FN (ip4_sv_reass_custom_node) (vlib_main_t * vm,
803 vlib_node_runtime_t * node,
804 vlib_frame_t * frame)
806 return ip4_sv_reass_inline (vm, node, frame, false /* is_feature */ ,
807 false /* is_output_feature */ ,
808 true /* is_custom */ );
811 #ifndef CLIB_MARCH_VARIANT
813 ip4_sv_reass_get_nbuckets ()
815 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
819 nbuckets = (u32) (rm->max_reass_n / IP4_SV_REASS_HT_LOAD_FACTOR);
821 for (i = 0; i < 31; i++)
822 if ((1 << i) >= nbuckets)
828 #endif /* CLIB_MARCH_VARIANT */
832 IP4_EVENT_CONFIG_CHANGED = 1,
833 } ip4_sv_reass_event_t;
838 clib_bihash_16_8_t *new_hash;
841 #ifndef CLIB_MARCH_VARIANT
843 ip4_rehash_cb (clib_bihash_kv_16_8_t * kv, void *_ctx)
845 ip4_rehash_cb_ctx *ctx = _ctx;
846 if (clib_bihash_add_del_16_8 (ctx->new_hash, kv, 1))
850 return (BIHASH_WALK_CONTINUE);
854 ip4_sv_reass_set_params (u32 timeout_ms, u32 max_reassemblies,
855 u32 max_reassembly_length,
856 u32 expire_walk_interval_ms)
858 ip4_sv_reass_main.timeout_ms = timeout_ms;
859 ip4_sv_reass_main.timeout = (f64) timeout_ms / (f64) MSEC_PER_SEC;
860 ip4_sv_reass_main.max_reass_n = max_reassemblies;
861 ip4_sv_reass_main.max_reass_len = max_reassembly_length;
862 ip4_sv_reass_main.expire_walk_interval_ms = expire_walk_interval_ms;
866 ip4_sv_reass_set (u32 timeout_ms, u32 max_reassemblies,
867 u32 max_reassembly_length, u32 expire_walk_interval_ms)
869 u32 old_nbuckets = ip4_sv_reass_get_nbuckets ();
870 ip4_sv_reass_set_params (timeout_ms, max_reassemblies,
871 max_reassembly_length, expire_walk_interval_ms);
872 vlib_process_signal_event (ip4_sv_reass_main.vlib_main,
873 ip4_sv_reass_main.ip4_sv_reass_expire_node_idx,
874 IP4_EVENT_CONFIG_CHANGED, 0);
875 u32 new_nbuckets = ip4_sv_reass_get_nbuckets ();
876 if (ip4_sv_reass_main.max_reass_n > 0 && new_nbuckets > old_nbuckets)
878 clib_bihash_16_8_t new_hash;
879 clib_memset (&new_hash, 0, sizeof (new_hash));
880 ip4_rehash_cb_ctx ctx;
882 ctx.new_hash = &new_hash;
883 clib_bihash_init_16_8 (&new_hash, "ip4-dr", new_nbuckets,
884 new_nbuckets * 1024);
885 clib_bihash_foreach_key_value_pair_16_8 (&ip4_sv_reass_main.hash,
886 ip4_rehash_cb, &ctx);
889 clib_bihash_free_16_8 (&new_hash);
894 clib_bihash_free_16_8 (&ip4_sv_reass_main.hash);
895 clib_memcpy_fast (&ip4_sv_reass_main.hash, &new_hash,
896 sizeof (ip4_sv_reass_main.hash));
897 clib_bihash_copied (&ip4_sv_reass_main.hash, &new_hash);
904 ip4_sv_reass_get (u32 * timeout_ms, u32 * max_reassemblies,
905 u32 * max_reassembly_length, u32 * expire_walk_interval_ms)
907 *timeout_ms = ip4_sv_reass_main.timeout_ms;
908 *max_reassemblies = ip4_sv_reass_main.max_reass_n;
909 *max_reassembly_length = ip4_sv_reass_main.max_reass_len;
910 *expire_walk_interval_ms = ip4_sv_reass_main.expire_walk_interval_ms;
914 static clib_error_t *
915 ip4_sv_reass_init_function (vlib_main_t * vm)
917 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
918 clib_error_t *error = 0;
923 rm->vnet_main = vnet_get_main ();
925 vec_validate (rm->per_thread_data, vlib_num_workers ());
926 ip4_sv_reass_per_thread_t *rt;
927 vec_foreach (rt, rm->per_thread_data)
929 clib_spinlock_init (&rt->lock);
930 pool_alloc (rt->pool, rm->max_reass_n);
931 rt->lru_first = rt->lru_last = ~0;
934 node = vlib_get_node_by_name (vm, (u8 *) "ip4-sv-reassembly-expire-walk");
936 rm->ip4_sv_reass_expire_node_idx = node->index;
938 ip4_sv_reass_set_params (IP4_SV_REASS_TIMEOUT_DEFAULT_MS,
939 IP4_SV_REASS_MAX_REASSEMBLIES_DEFAULT,
940 IP4_SV_REASS_MAX_REASSEMBLY_LENGTH_DEFAULT,
941 IP4_SV_REASS_EXPIRE_WALK_INTERVAL_DEFAULT_MS);
943 nbuckets = ip4_sv_reass_get_nbuckets ();
944 clib_bihash_init_16_8 (&rm->hash, "ip4-dr", nbuckets, nbuckets * 1024);
946 node = vlib_get_node_by_name (vm, (u8 *) "ip4-drop");
948 rm->ip4_drop_idx = node->index;
950 rm->fq_index = vlib_frame_queue_main_init (ip4_sv_reass_node.index, 0);
951 rm->fq_feature_index =
952 vlib_frame_queue_main_init (ip4_sv_reass_node_feature.index, 0);
954 rm->feature_use_refcount_per_intf = NULL;
955 rm->output_feature_use_refcount_per_intf = NULL;
960 VLIB_INIT_FUNCTION (ip4_sv_reass_init_function);
961 #endif /* CLIB_MARCH_VARIANT */
964 ip4_sv_reass_walk_expired (vlib_main_t * vm,
965 vlib_node_runtime_t * node, vlib_frame_t * f)
967 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
968 uword event_type, *event_data = 0;
972 vlib_process_wait_for_event_or_clock (vm,
974 rm->expire_walk_interval_ms /
976 event_type = vlib_process_get_events (vm, &event_data);
980 case ~0: /* no events => timeout */
981 /* nothing to do here */
983 case IP4_EVENT_CONFIG_CHANGED:
986 clib_warning ("BUG: event type 0x%wx", event_type);
989 f64 now = vlib_time_now (vm);
991 ip4_sv_reass_t *reass;
992 int *pool_indexes_to_free = NULL;
994 uword thread_index = 0;
996 const uword nthreads = vlib_num_workers () + 1;
997 for (thread_index = 0; thread_index < nthreads; ++thread_index)
999 ip4_sv_reass_per_thread_t *rt = &rm->per_thread_data[thread_index];
1000 clib_spinlock_lock (&rt->lock);
1002 vec_reset_length (pool_indexes_to_free);
1004 pool_foreach_index (index, rt->pool, ({
1005 reass = pool_elt_at_index (rt->pool, index);
1006 if (now > reass->last_heard + rm->timeout)
1008 vec_add1 (pool_indexes_to_free, index);
1014 vec_foreach (i, pool_indexes_to_free)
1016 ip4_sv_reass_t *reass = pool_elt_at_index (rt->pool, i[0]);
1017 ip4_sv_reass_free (vm, rm, rt, reass);
1021 clib_spinlock_unlock (&rt->lock);
1024 vec_free (pool_indexes_to_free);
1027 _vec_len (event_data) = 0;
1035 VLIB_REGISTER_NODE (ip4_sv_reass_expire_node) = {
1036 .function = ip4_sv_reass_walk_expired,
1037 .type = VLIB_NODE_TYPE_PROCESS,
1038 .name = "ip4-sv-reassembly-expire-walk",
1039 .format_trace = format_ip4_sv_reass_trace,
1040 .n_errors = ARRAY_LEN (ip4_sv_reass_error_strings),
1041 .error_strings = ip4_sv_reass_error_strings,
1047 format_ip4_sv_reass_key (u8 * s, va_list * args)
1049 ip4_sv_reass_key_t *key = va_arg (*args, ip4_sv_reass_key_t *);
1052 "xx_id: %u, src: %U, dst: %U, frag_id: %u, proto: %u",
1053 key->xx_id, format_ip4_address, &key->src, format_ip4_address,
1054 &key->dst, clib_net_to_host_u16 (key->frag_id), key->proto);
1059 format_ip4_sv_reass (u8 * s, va_list * args)
1061 vlib_main_t *vm = va_arg (*args, vlib_main_t *);
1062 ip4_sv_reass_t *reass = va_arg (*args, ip4_sv_reass_t *);
1064 s = format (s, "ID: %lu, key: %U trace_op_counter: %u\n",
1065 reass->id, format_ip4_sv_reass_key, &reass->key,
1066 reass->trace_op_counter);
1071 vec_foreach (bip, reass->cached_buffers)
1076 b = vlib_get_buffer (vm, bi);
1077 s = format (s, " #%03u: bi: %u, ", counter, bi);
1079 bi = b->next_buffer;
1081 while (b->flags & VLIB_BUFFER_NEXT_PRESENT);
1086 static clib_error_t *
1087 show_ip4_reass (vlib_main_t * vm,
1088 unformat_input_t * input,
1089 CLIB_UNUSED (vlib_cli_command_t * lmd))
1091 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
1093 vlib_cli_output (vm, "---------------------");
1094 vlib_cli_output (vm, "IP4 reassembly status");
1095 vlib_cli_output (vm, "---------------------");
1096 bool details = false;
1097 if (unformat (input, "details"))
1102 u32 sum_reass_n = 0;
1103 ip4_sv_reass_t *reass;
1105 const uword nthreads = vlib_num_workers () + 1;
1106 for (thread_index = 0; thread_index < nthreads; ++thread_index)
1108 ip4_sv_reass_per_thread_t *rt = &rm->per_thread_data[thread_index];
1109 clib_spinlock_lock (&rt->lock);
1113 pool_foreach (reass, rt->pool, {
1114 vlib_cli_output (vm, "%U", format_ip4_sv_reass, vm, reass);
1118 sum_reass_n += rt->reass_n;
1119 clib_spinlock_unlock (&rt->lock);
1121 vlib_cli_output (vm, "---------------------");
1122 vlib_cli_output (vm, "Current IP4 reassemblies count: %lu\n",
1123 (long unsigned) sum_reass_n);
1124 vlib_cli_output (vm,
1125 "Maximum configured concurrent IP4 reassemblies per worker-thread: %lu\n",
1126 (long unsigned) rm->max_reass_n);
1131 VLIB_CLI_COMMAND (show_ip4_sv_reass_cmd, static) = {
1132 .path = "show ip4-sv-reassembly",
1133 .short_help = "show ip4-sv-reassembly [details]",
1134 .function = show_ip4_reass,
1138 #ifndef CLIB_MARCH_VARIANT
1140 ip4_sv_reass_enable_disable (u32 sw_if_index, u8 enable_disable)
1142 return ip4_sv_reass_enable_disable_with_refcnt (sw_if_index,
1145 #endif /* CLIB_MARCH_VARIANT */
1148 #define foreach_ip4_sv_reass_handoff_error \
1149 _(CONGESTION_DROP, "congestion drop")
1154 #define _(sym,str) IP4_SV_REASSEMBLY_HANDOFF_ERROR_##sym,
1155 foreach_ip4_sv_reass_handoff_error
1157 IP4_SV_REASSEMBLY_HANDOFF_N_ERROR,
1158 } ip4_sv_reass_handoff_error_t;
1160 static char *ip4_sv_reass_handoff_error_strings[] = {
1161 #define _(sym,string) string,
1162 foreach_ip4_sv_reass_handoff_error
1168 u32 next_worker_index;
1169 } ip4_sv_reass_handoff_trace_t;
1172 format_ip4_sv_reass_handoff_trace (u8 * s, va_list * args)
1174 CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
1175 CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
1176 ip4_sv_reass_handoff_trace_t *t =
1177 va_arg (*args, ip4_sv_reass_handoff_trace_t *);
1180 format (s, "ip4-sv-reassembly-handoff: next-worker %d",
1181 t->next_worker_index);
1187 ip4_sv_reass_handoff_node_inline (vlib_main_t * vm,
1188 vlib_node_runtime_t * node,
1189 vlib_frame_t * frame, bool is_feature)
1191 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
1193 vlib_buffer_t *bufs[VLIB_FRAME_SIZE], **b;
1194 u32 n_enq, n_left_from, *from;
1195 u16 thread_indices[VLIB_FRAME_SIZE], *ti;
1198 from = vlib_frame_vector_args (frame);
1199 n_left_from = frame->n_vectors;
1200 vlib_get_buffers (vm, from, bufs, n_left_from);
1203 ti = thread_indices;
1205 fq_index = (is_feature) ? rm->fq_feature_index : rm->fq_index;
1207 while (n_left_from > 0)
1209 ti[0] = vnet_buffer (b[0])->ip.reass.owner_thread_index;
1212 ((node->flags & VLIB_NODE_FLAG_TRACE)
1213 && (b[0]->flags & VLIB_BUFFER_IS_TRACED)))
1215 ip4_sv_reass_handoff_trace_t *t =
1216 vlib_add_trace (vm, node, b[0], sizeof (*t));
1217 t->next_worker_index = ti[0];
1225 vlib_buffer_enqueue_to_thread (vm, fq_index, from, thread_indices,
1226 frame->n_vectors, 1);
1228 if (n_enq < frame->n_vectors)
1229 vlib_node_increment_counter (vm, node->node_index,
1230 IP4_SV_REASSEMBLY_HANDOFF_ERROR_CONGESTION_DROP,
1231 frame->n_vectors - n_enq);
1232 return frame->n_vectors;
1235 VLIB_NODE_FN (ip4_sv_reass_handoff_node) (vlib_main_t * vm,
1236 vlib_node_runtime_t * node,
1237 vlib_frame_t * frame)
1239 return ip4_sv_reass_handoff_node_inline (vm, node, frame,
1240 false /* is_feature */ );
1245 VLIB_REGISTER_NODE (ip4_sv_reass_handoff_node) = {
1246 .name = "ip4-sv-reassembly-handoff",
1247 .vector_size = sizeof (u32),
1248 .n_errors = ARRAY_LEN(ip4_sv_reass_handoff_error_strings),
1249 .error_strings = ip4_sv_reass_handoff_error_strings,
1250 .format_trace = format_ip4_sv_reass_handoff_trace,
1262 VLIB_NODE_FN (ip4_sv_reass_feature_handoff_node) (vlib_main_t * vm,
1263 vlib_node_runtime_t *
1265 vlib_frame_t * frame)
1267 return ip4_sv_reass_handoff_node_inline (vm, node, frame,
1268 true /* is_feature */ );
1274 VLIB_REGISTER_NODE (ip4_sv_reass_feature_handoff_node) = {
1275 .name = "ip4-sv-reass-feature-hoff",
1276 .vector_size = sizeof (u32),
1277 .n_errors = ARRAY_LEN(ip4_sv_reass_handoff_error_strings),
1278 .error_strings = ip4_sv_reass_handoff_error_strings,
1279 .format_trace = format_ip4_sv_reass_handoff_trace,
1289 #ifndef CLIB_MARCH_VARIANT
1291 ip4_sv_reass_enable_disable_with_refcnt (u32 sw_if_index, int is_enable)
1293 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
1294 vec_validate (rm->feature_use_refcount_per_intf, sw_if_index);
1297 if (!rm->feature_use_refcount_per_intf[sw_if_index])
1299 ++rm->feature_use_refcount_per_intf[sw_if_index];
1300 return vnet_feature_enable_disable ("ip4-unicast",
1301 "ip4-sv-reassembly-feature",
1302 sw_if_index, 1, 0, 0);
1304 ++rm->feature_use_refcount_per_intf[sw_if_index];
1308 if (rm->feature_use_refcount_per_intf[sw_if_index])
1309 --rm->feature_use_refcount_per_intf[sw_if_index];
1310 if (!rm->feature_use_refcount_per_intf[sw_if_index])
1311 return vnet_feature_enable_disable ("ip4-unicast",
1312 "ip4-sv-reassembly-feature",
1313 sw_if_index, 0, 0, 0);
1319 ip4_sv_reass_custom_register_next_node (uword node_index)
1321 return vlib_node_add_next (vlib_get_main (), ip4_sv_reass_custom_node.index,
1326 ip4_sv_reass_output_enable_disable_with_refcnt (u32 sw_if_index,
1329 ip4_sv_reass_main_t *rm = &ip4_sv_reass_main;
1330 vec_validate (rm->output_feature_use_refcount_per_intf, sw_if_index);
1333 if (!rm->output_feature_use_refcount_per_intf[sw_if_index])
1335 ++rm->output_feature_use_refcount_per_intf[sw_if_index];
1336 return vnet_feature_enable_disable ("ip4-output",
1337 "ip4-sv-reassembly-output-feature",
1338 sw_if_index, 1, 0, 0);
1340 ++rm->output_feature_use_refcount_per_intf[sw_if_index];
1344 if (rm->output_feature_use_refcount_per_intf[sw_if_index])
1345 --rm->output_feature_use_refcount_per_intf[sw_if_index];
1346 if (!rm->output_feature_use_refcount_per_intf[sw_if_index])
1347 return vnet_feature_enable_disable ("ip4-output",
1348 "ip4-sv-reassembly-output-feature",
1349 sw_if_index, 0, 0, 0);
1356 * fd.io coding-style-patch-verification: ON
1359 * eval: (c-set-style "gnu")