2 * Copyright (c) 2016 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
17 * @brief L2 LISP-GPE decap code.
20 #include <vlib/vlib.h>
21 #include <vnet/pg/pg.h>
22 #include <vnet/lisp-gpe/lisp_gpe.h>
30 } lisp_gpe_rx_trace_t;
33 format_lisp_gpe_rx_trace (u8 * s, va_list * args)
35 CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
36 CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
37 lisp_gpe_rx_trace_t *t = va_arg (*args, lisp_gpe_rx_trace_t *);
39 if (t->tunnel_index != ~0)
41 s = format (s, "LISP-GPE: tunnel %d next %d error %d", t->tunnel_index,
42 t->next_index, t->error);
46 s = format (s, "LISP-GPE: no tunnel next %d error %d\n", t->next_index,
49 s = format (s, "\n %U", format_lisp_gpe_header_with_length, &t->h,
50 (u32) sizeof (t->h) /* max size */ );
54 static u32 next_proto_to_next_index[LISP_GPE_NEXT_PROTOS] = {
55 LISP_GPE_INPUT_NEXT_DROP,
56 LISP_GPE_INPUT_NEXT_IP4_INPUT,
57 LISP_GPE_INPUT_NEXT_IP6_INPUT,
58 LISP_GPE_INPUT_NEXT_L2_INPUT,
59 LISP_GPE_INPUT_NEXT_DROP
63 next_protocol_to_next_index (lisp_gpe_header_t * lgh, u8 * next_header)
66 if (PREDICT_TRUE ((lgh->flags & LISP_GPE_FLAGS_P)
67 && lgh->next_protocol < LISP_GPE_NEXT_PROTOS))
68 return next_proto_to_next_index[lgh->next_protocol];
69 /* legacy lisp router */
70 else if ((lgh->flags & LISP_GPE_FLAGS_P) == 0)
72 ip4_header_t *iph = (ip4_header_t *) next_header;
73 if ((iph->ip_version_and_header_length & 0xF0) == 0x40)
74 return LISP_GPE_INPUT_NEXT_IP4_INPUT;
75 else if ((iph->ip_version_and_header_length & 0xF0) == 0x60)
76 return LISP_GPE_INPUT_NEXT_IP6_INPUT;
78 return LISP_GPE_INPUT_NEXT_DROP;
81 return LISP_GPE_INPUT_NEXT_DROP;
84 always_inline tunnel_lookup_t *
85 next_index_to_iface (lisp_gpe_main_t * lgm, u32 next_index)
87 if (LISP_GPE_INPUT_NEXT_IP4_INPUT == next_index
88 || LISP_GPE_INPUT_NEXT_IP6_INPUT == next_index)
89 return &lgm->l3_ifaces;
90 else if (LISP_GPE_INPUT_NEXT_L2_INPUT == next_index)
91 return &lgm->l2_ifaces;
92 else if (LISP_GPE_INPUT_NEXT_NSH_INPUT == next_index)
93 return &lgm->nsh_ifaces;
94 clib_warning ("next_index not associated to an interface!");
98 static_always_inline void
99 incr_decap_stats (vnet_main_t * vnm, u32 cpu_index, u32 length,
100 u32 sw_if_index, u32 * last_sw_if_index, u32 * n_packets,
103 vnet_interface_main_t *im;
105 if (PREDICT_TRUE (sw_if_index == *last_sw_if_index))
112 if (PREDICT_TRUE (*last_sw_if_index != ~0))
114 im = &vnm->interface_main;
116 vlib_increment_combined_counter (im->combined_sw_if_counters +
117 VNET_INTERFACE_COUNTER_RX,
118 cpu_index, *last_sw_if_index,
119 *n_packets, *n_bytes);
121 *last_sw_if_index = sw_if_index;
128 * @brief LISP-GPE decap dispatcher.
129 * @node lisp_gpe_input_inline
131 * LISP-GPE decap dispatcher.
133 * Decaps IP-UDP-LISP-GPE header and based on the next protocol and in the
134 * GPE header and the vni decides the next node to forward the packet to.
136 * @param[in] vm vlib_main_t corresponding to current thread.
137 * @param[in] node vlib_node_runtime_t data for this node.
138 * @param[in] frame vlib_frame_t whose contents should be dispatched.
140 * @return number of vectors in frame.
143 lisp_gpe_input_inline (vlib_main_t * vm, vlib_node_runtime_t * node,
144 vlib_frame_t * from_frame, u8 is_v4)
146 u32 n_left_from, next_index, *from, *to_next, cpu_index;
147 u32 n_bytes = 0, n_packets = 0, last_sw_if_index = ~0, drops = 0;
148 lisp_gpe_main_t *lgm = vnet_lisp_gpe_get_main ();
150 cpu_index = os_get_cpu_number ();
151 from = vlib_frame_vector_args (from_frame);
152 n_left_from = from_frame->n_vectors;
154 next_index = node->cached_next_index;
156 while (n_left_from > 0)
160 vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
162 while (n_left_from >= 4 && n_left_to_next >= 2)
165 vlib_buffer_t *b0, *b1;
166 ip4_udp_lisp_gpe_header_t *iul4_0, *iul4_1;
167 ip6_udp_lisp_gpe_header_t *iul6_0, *iul6_1;
168 lisp_gpe_header_t *lh0, *lh1;
169 u32 next0, next1, error0, error1;
171 tunnel_lookup_t *tl0, *tl1;
173 /* Prefetch next iteration. */
175 vlib_buffer_t *p2, *p3;
177 p2 = vlib_get_buffer (vm, from[2]);
178 p3 = vlib_get_buffer (vm, from[3]);
180 vlib_prefetch_buffer_header (p2, LOAD);
181 vlib_prefetch_buffer_header (p3, LOAD);
183 CLIB_PREFETCH (p2->data, 2 * CLIB_CACHE_LINE_BYTES, LOAD);
184 CLIB_PREFETCH (p3->data, 2 * CLIB_CACHE_LINE_BYTES, LOAD);
196 b0 = vlib_get_buffer (vm, bi0);
197 b1 = vlib_get_buffer (vm, bi1);
199 /* udp leaves current_data pointing at the lisp header */
202 vlib_buffer_advance (b0,
203 -(word) (sizeof (udp_header_t) +
204 sizeof (ip4_header_t)));
205 vlib_buffer_advance (b1,
206 -(word) (sizeof (udp_header_t) +
207 sizeof (ip4_header_t)));
209 iul4_0 = vlib_buffer_get_current (b0);
210 iul4_1 = vlib_buffer_get_current (b1);
212 /* pop (ip, udp, lisp-gpe) */
213 vlib_buffer_advance (b0, sizeof (*iul4_0));
214 vlib_buffer_advance (b1, sizeof (*iul4_1));
221 vlib_buffer_advance (b0,
222 -(word) (sizeof (udp_header_t) +
223 sizeof (ip6_header_t)));
224 vlib_buffer_advance (b1,
225 -(word) (sizeof (udp_header_t) +
226 sizeof (ip6_header_t)));
228 iul6_0 = vlib_buffer_get_current (b0);
229 iul6_1 = vlib_buffer_get_current (b1);
231 /* pop (ip, udp, lisp-gpe) */
232 vlib_buffer_advance (b0, sizeof (*iul6_0));
233 vlib_buffer_advance (b1, sizeof (*iul6_1));
239 /* determine next_index from lisp-gpe header */
240 next0 = next_protocol_to_next_index (lh0,
241 vlib_buffer_get_current (b0));
242 next1 = next_protocol_to_next_index (lh1,
243 vlib_buffer_get_current (b1));
245 /* determine if tunnel is l2 or l3 */
246 tl0 = next_index_to_iface (lgm, next0);
247 tl1 = next_index_to_iface (lgm, next1);
249 /* map iid/vni to lisp-gpe sw_if_index which is used by ipx_input to
250 * decide the rx vrf and the input features to be applied */
251 si0 = hash_get (tl0->sw_if_index_by_vni,
252 clib_net_to_host_u32 (lh0->iid));
253 si1 = hash_get (tl1->sw_if_index_by_vni,
254 clib_net_to_host_u32 (lh1->iid));
257 /* Required to make the l2 tag push / pop code work on l2 subifs */
258 vnet_update_l2_len (b0);
259 vnet_update_l2_len (b1);
263 incr_decap_stats (lgm->vnet_main, cpu_index,
264 vlib_buffer_length_in_chain (vm, b0), si0[0],
265 &last_sw_if_index, &n_packets, &n_bytes);
266 vnet_buffer (b0)->sw_if_index[VLIB_RX] = si0[0];
271 next0 = LISP_GPE_INPUT_NEXT_DROP;
272 error0 = LISP_GPE_ERROR_NO_TUNNEL;
278 incr_decap_stats (lgm->vnet_main, cpu_index,
279 vlib_buffer_length_in_chain (vm, b1), si1[0],
280 &last_sw_if_index, &n_packets, &n_bytes);
281 vnet_buffer (b1)->sw_if_index[VLIB_RX] = si1[0];
286 next1 = LISP_GPE_INPUT_NEXT_DROP;
287 error1 = LISP_GPE_ERROR_NO_TUNNEL;
291 b0->error = error0 ? node->errors[error0] : 0;
292 b1->error = error1 ? node->errors[error1] : 0;
294 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
296 lisp_gpe_rx_trace_t *tr = vlib_add_trace (vm, node, b0,
298 tr->next_index = next0;
303 if (PREDICT_FALSE (b1->flags & VLIB_BUFFER_IS_TRACED))
305 lisp_gpe_rx_trace_t *tr = vlib_add_trace (vm, node, b1,
307 tr->next_index = next1;
312 vlib_validate_buffer_enqueue_x2 (vm, node, next_index, to_next,
313 n_left_to_next, bi0, bi1, next0,
317 while (n_left_from > 0 && n_left_to_next > 0)
322 ip4_udp_lisp_gpe_header_t *iul4_0;
323 ip6_udp_lisp_gpe_header_t *iul6_0;
324 lisp_gpe_header_t *lh0;
327 tunnel_lookup_t *tl0;
336 b0 = vlib_get_buffer (vm, bi0);
338 /* udp leaves current_data pointing at the lisp header
339 * TODO: there's no difference in processing between v4 and v6
340 * encapsulated packets so the code should be simplified if ip header
341 * info is not going to be used for dp smrs/dpsec */
344 vlib_buffer_advance (b0,
345 -(word) (sizeof (udp_header_t) +
346 sizeof (ip4_header_t)));
348 iul4_0 = vlib_buffer_get_current (b0);
350 /* pop (ip, udp, lisp-gpe) */
351 vlib_buffer_advance (b0, sizeof (*iul4_0));
357 vlib_buffer_advance (b0,
358 -(word) (sizeof (udp_header_t) +
359 sizeof (ip6_header_t)));
361 iul6_0 = vlib_buffer_get_current (b0);
363 /* pop (ip, udp, lisp-gpe) */
364 vlib_buffer_advance (b0, sizeof (*iul6_0));
369 /* TODO if security is to be implemented, something similar to RPF,
370 * probably we'd like to check that the peer is allowed to send us
371 * packets. For this, we should use the tunnel table OR check that
372 * we have a mapping for the source eid and that the outer source of
373 * the packet is one of its locators */
375 /* determine next_index from lisp-gpe header */
376 next0 = next_protocol_to_next_index (lh0,
377 vlib_buffer_get_current (b0));
379 /* determine if tunnel is l2 or l3 */
380 tl0 = next_index_to_iface (lgm, next0);
382 /* map iid/vni to lisp-gpe sw_if_index which is used by ipx_input to
383 * decide the rx vrf and the input features to be applied.
384 * NOTE: vni uses only the first 24 bits */
385 si0 = hash_get (tl0->sw_if_index_by_vni,
386 clib_net_to_host_u32 (lh0->iid << 8));
388 /* Required to make the l2 tag push / pop code work on l2 subifs */
389 vnet_update_l2_len (b0);
393 incr_decap_stats (lgm->vnet_main, cpu_index,
394 vlib_buffer_length_in_chain (vm, b0), si0[0],
395 &last_sw_if_index, &n_packets, &n_bytes);
396 vnet_buffer (b0)->sw_if_index[VLIB_RX] = si0[0];
401 next0 = LISP_GPE_INPUT_NEXT_DROP;
402 error0 = LISP_GPE_ERROR_NO_TUNNEL;
406 /* TODO error handling if security is implemented */
407 b0->error = error0 ? node->errors[error0] : 0;
409 if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
411 lisp_gpe_rx_trace_t *tr = vlib_add_trace (vm, node, b0,
413 tr->next_index = next0;
418 vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
419 n_left_to_next, bi0, next0);
422 vlib_put_next_frame (vm, node, next_index, n_left_to_next);
425 /* flush iface stats */
426 incr_decap_stats (lgm->vnet_main, cpu_index, 0, ~0, &last_sw_if_index,
427 &n_packets, &n_bytes);
428 vlib_node_increment_counter (vm, lisp_gpe_ip4_input_node.index,
429 LISP_GPE_ERROR_NO_TUNNEL, drops);
430 return from_frame->n_vectors;
434 lisp_gpe_ip4_input (vlib_main_t * vm, vlib_node_runtime_t * node,
435 vlib_frame_t * from_frame)
437 return lisp_gpe_input_inline (vm, node, from_frame, 1);
441 lisp_gpe_ip6_input (vlib_main_t * vm, vlib_node_runtime_t * node,
442 vlib_frame_t * from_frame)
444 return lisp_gpe_input_inline (vm, node, from_frame, 0);
447 static char *lisp_gpe_ip4_input_error_strings[] = {
448 #define lisp_gpe_error(n,s) s,
449 #include <vnet/lisp-gpe/lisp_gpe_error.def>
450 #undef lisp_gpe_error
454 VLIB_REGISTER_NODE (lisp_gpe_ip4_input_node) = {
455 .function = lisp_gpe_ip4_input,
456 .name = "lisp-gpe-ip4-input",
457 /* Takes a vector of packets. */
458 .vector_size = sizeof (u32),
459 .n_next_nodes = LISP_GPE_INPUT_N_NEXT,
461 #define _(s,n) [LISP_GPE_INPUT_NEXT_##s] = n,
462 foreach_lisp_gpe_ip_input_next
466 .n_errors = ARRAY_LEN (lisp_gpe_ip4_input_error_strings),
467 .error_strings = lisp_gpe_ip4_input_error_strings,
469 .format_buffer = format_lisp_gpe_header_with_length,
470 .format_trace = format_lisp_gpe_rx_trace,
471 // $$$$ .unformat_buffer = unformat_lisp_gpe_header,
476 VLIB_REGISTER_NODE (lisp_gpe_ip6_input_node) = {
477 .function = lisp_gpe_ip6_input,
478 .name = "lisp-gpe-ip6-input",
479 /* Takes a vector of packets. */
480 .vector_size = sizeof (u32),
481 .n_next_nodes = LISP_GPE_INPUT_N_NEXT,
483 #define _(s,n) [LISP_GPE_INPUT_NEXT_##s] = n,
484 foreach_lisp_gpe_ip_input_next
488 .n_errors = ARRAY_LEN (lisp_gpe_ip4_input_error_strings),
489 .error_strings = lisp_gpe_ip4_input_error_strings,
491 .format_buffer = format_lisp_gpe_header_with_length,
492 .format_trace = format_lisp_gpe_rx_trace,
493 // $$$$ .unformat_buffer = unformat_lisp_gpe_header,
498 * Adds arc from lisp-gpe-input to nsh-input if nsh-input is available
501 gpe_add_arc_from_input_to_nsh ()
503 lisp_gpe_main_t *lgm = vnet_lisp_gpe_get_main ();
504 vlib_main_t *vm = lgm->vlib_main;
505 vlib_node_t *nsh_input;
507 /* Arc already exists */
508 if (next_proto_to_next_index[LISP_GPE_NEXT_PROTO_NSH]
509 != LISP_GPE_INPUT_NEXT_DROP)
512 /* Check if nsh-input is available */
513 if ((nsh_input = vlib_get_node_by_name (vm, (u8 *) "nsh-input")))
516 slot4 = vlib_node_add_next_with_slot (vm, lisp_gpe_ip4_input_node.index,
518 LISP_GPE_NEXT_PROTO_NSH);
519 slot6 = vlib_node_add_next_with_slot (vm, lisp_gpe_ip6_input_node.index,
521 LISP_GPE_NEXT_PROTO_NSH);
522 ASSERT (slot4 == slot6 && slot4 == LISP_GPE_INPUT_NEXT_NSH_INPUT);
524 next_proto_to_next_index[LISP_GPE_NEXT_PROTO_NSH] = slot4;
528 /** GPE decap init function. */
530 gpe_decap_init (vlib_main_t * vm)
532 clib_error_t *error = 0;
534 if ((error = vlib_call_init_function (vm, lisp_gpe_init)))
537 gpe_add_arc_from_input_to_nsh ();
541 VLIB_INIT_FUNCTION (gpe_decap_init);
544 * fd.io coding-style-patch-verification: ON
547 * eval: (c-set-style "gnu")