SRv6 dynamic proxy plugin 37/10137/8
authorFrancois Clad <fclad@cisco.com>
Wed, 17 Jan 2018 11:18:41 +0000 (12:18 +0100)
committerDamjan Marion <dmarion.lists@gmail.com>
Mon, 29 Jan 2018 11:05:48 +0000 (11:05 +0000)
Change-Id: Ie460005510b8a70d00de31b6651e762cc3a63229
Signed-off-by: Francois Clad <fclad@cisco.com>
MAINTAINERS
src/configure.ac
src/plugins/Makefile.am
src/plugins/srv6-ad/ad.c [new file with mode: 0644]
src/plugins/srv6-ad/ad.h [new file with mode: 0644]
src/plugins/srv6-ad/ad_plugin_doc.md [new file with mode: 0644]
src/plugins/srv6-ad/node.c [new file with mode: 0644]
src/plugins/srv6_ad.am [new file with mode: 0644]

index 5a98df0..4fb6759 100644 (file)
@@ -159,6 +159,11 @@ M:  Hongjun Ni <hongjun.ni@intel.com>
 F:  src/plugins/pppoe/
 F:  src/plugins/pppoe.am
 
+Plugin - IPv6 Segment Routing Dynamic Proxy
+M:     Francois Clad <fclad@cisco.com>
+F:     src/plugins/srv6-ad/
+F:     src/plugins/srv6_ad.am
+
 Plugin - IPv6 Segment Routing Masquerading Proxy
 M:     Francois Clad <fclad@cisco.com>
 F:     src/plugins/srv6-am/
index 80a0fb0..2b0d226 100644 (file)
@@ -221,6 +221,7 @@ PLUGIN_ENABLED(marvell)
 PLUGIN_ENABLED(memif)
 PLUGIN_ENABLED(pppoe)
 PLUGIN_ENABLED(sixrd)
+PLUGIN_ENABLED(srv6ad)
 PLUGIN_ENABLED(srv6am)
 PLUGIN_ENABLED(srv6as)
 PLUGIN_ENABLED(nat)
index 589262e..c2621e4 100644 (file)
@@ -83,6 +83,10 @@ if ENABLE_SIXRD_PLUGIN
 include sixrd.am
 endif
 
+if ENABLE_SRV6AD_PLUGIN
+include srv6_ad.am
+endif
+
 if ENABLE_SRV6AM_PLUGIN
 include srv6_am.am
 endif
diff --git a/src/plugins/srv6-ad/ad.c b/src/plugins/srv6-ad/ad.c
new file mode 100644 (file)
index 0000000..b6f872d
--- /dev/null
@@ -0,0 +1,358 @@
+/*
+ * Copyright (c) 2015 Cisco and/or its affiliates.
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at:
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+/*
+ *------------------------------------------------------------------
+ * ad.c - SRv6 Dynamic Proxy (AD) function
+ *------------------------------------------------------------------
+ */
+
+#include <vnet/vnet.h>
+#include <vnet/adj/adj.h>
+#include <vnet/plugin/plugin.h>
+#include <vpp/app/version.h>
+#include <srv6-ad/ad.h>
+
+unsigned char function_name[] = "SRv6-AD-plugin";
+unsigned char keyword_str[] = "End.AD";
+unsigned char def_str[] =
+  "Endpoint with dynamic proxy to SR-unaware appliance";
+unsigned char params_str[] = "nh <next-hop> oif <iface-out> iif <iface-in>";
+
+
+/*****************************************/
+/* SRv6 LocalSID instantiation and removal functions */
+static int
+srv6_ad_localsid_creation_fn (ip6_sr_localsid_t * localsid)
+{
+  ip6_sr_main_t *srm = &sr_main;
+  srv6_ad_main_t *sm = &srv6_ad_main;
+  srv6_ad_localsid_t *ls_mem = localsid->plugin_mem;
+  u32 localsid_index = localsid - srm->localsids;
+
+  /* Step 1: Prepare xconnect adjacency for sending packets to the VNF */
+
+  /* Retrieve the adjacency corresponding to the (OIF, next_hop) */
+  adj_index_t nh_adj_index = ADJ_INDEX_INVALID;
+  if (ls_mem->ip_version == DA_IP4)
+    nh_adj_index = adj_nbr_add_or_lock (FIB_PROTOCOL_IP4,
+                                       VNET_LINK_IP4, &ls_mem->nh_addr,
+                                       ls_mem->sw_if_index_out);
+  else if (ls_mem->ip_version == DA_IP6)
+    nh_adj_index = adj_nbr_add_or_lock (FIB_PROTOCOL_IP6,
+                                       VNET_LINK_IP6, &ls_mem->nh_addr,
+                                       ls_mem->sw_if_index_out);
+  if (nh_adj_index == ADJ_INDEX_INVALID)
+    return -5;
+
+  ls_mem->nh_adj = nh_adj_index;
+
+
+  /* Step 2: Prepare inbound policy for packets returning from the VNF */
+
+  /* Sanitise the SW_IF_INDEX */
+  if (pool_is_free_index (sm->vnet_main->interface_main.sw_interfaces,
+                         ls_mem->sw_if_index_in))
+    return -3;
+
+  vnet_sw_interface_t *sw = vnet_get_sw_interface (sm->vnet_main,
+                                                  ls_mem->sw_if_index_in);
+  if (sw->type != VNET_SW_INTERFACE_TYPE_HARDWARE)
+    return -3;
+
+  int ret = -1;
+  if (ls_mem->ip_version == DA_IP4)
+    {
+      ret = vnet_feature_enable_disable ("ip4-unicast", "srv6-ad4-rewrite",
+                                        ls_mem->sw_if_index_in, 1, 0, 0);
+      if (ret != 0)
+       return -1;
+
+      /* FIB API calls - Recursive route through the BindingSID */
+      if (ls_mem->sw_if_index_in < vec_len (sm->sw_iface_localsid4))
+       {
+         sm->sw_iface_localsid4[ls_mem->sw_if_index_in] = localsid_index;
+       }
+      else
+       {
+         vec_resize (sm->sw_iface_localsid4,
+                     (pool_len (sm->vnet_main->interface_main.sw_interfaces)
+                      - vec_len (sm->sw_iface_localsid4)));
+         sm->sw_iface_localsid4[ls_mem->sw_if_index_in] = localsid_index;
+       }
+    }
+  else if (ls_mem->ip_version == DA_IP6)
+    {
+      ret = vnet_feature_enable_disable ("ip6-unicast", "srv6-ad6-rewrite",
+                                        ls_mem->sw_if_index_in, 1, 0, 0);
+      if (ret != 0)
+       return -1;
+
+      if (ls_mem->sw_if_index_in < vec_len (sm->sw_iface_localsid6))
+       {
+         sm->sw_iface_localsid6[ls_mem->sw_if_index_in] = localsid_index;
+       }
+      else
+       {
+         vec_resize (sm->sw_iface_localsid6,
+                     (pool_len (sm->vnet_main->interface_main.sw_interfaces)
+                      - vec_len (sm->sw_iface_localsid6)));
+         sm->sw_iface_localsid6[ls_mem->sw_if_index_in] = localsid_index;
+       }
+    }
+
+  return 0;
+}
+
+static int
+srv6_ad_localsid_removal_fn (ip6_sr_localsid_t * localsid)
+{
+  srv6_ad_main_t *sm = &srv6_ad_main;
+  srv6_ad_localsid_t *ls_mem = localsid->plugin_mem;
+
+  int ret = -1;
+  if (ls_mem->ip_version == DA_IP4)
+    {
+      /* Remove hardware indirection (from sr_steering.c:137) */
+      ret = vnet_feature_enable_disable ("ip4-unicast", "srv6-ad4-rewrite",
+                                        ls_mem->sw_if_index_in, 0, 0, 0);
+      if (ret != 0)
+       return -1;
+
+      /* Remove local SID pointer from interface table (from sr_steering.c:139) */
+      sm->sw_iface_localsid4[ls_mem->sw_if_index_in] = ~(u32) 0;
+    }
+  else if (ls_mem->ip_version == DA_IP6)
+    {
+      /* Remove hardware indirection (from sr_steering.c:137) */
+      ret = vnet_feature_enable_disable ("ip6-unicast", "srv6-ad6-rewrite",
+                                        ls_mem->sw_if_index_in, 0, 0, 0);
+      if (ret != 0)
+       return -1;
+
+      /* Remove local SID pointer from interface table (from sr_steering.c:139) */
+      sm->sw_iface_localsid6[ls_mem->sw_if_index_in] = ~(u32) 0;
+    }
+
+
+  /* Unlock (OIF, NHOP) adjacency (from sr_localsid.c:103) */
+  adj_unlock (ls_mem->nh_adj);
+
+  /* Clean up local SID memory */
+  clib_mem_free (localsid->plugin_mem);
+
+  return 0;
+}
+
+/**********************************/
+/* SRv6 LocalSID format functions */
+/*
+ * Prints nicely the parameters of a localsid
+ * Example: print "Table 5"
+ */
+u8 *
+format_srv6_ad_localsid (u8 * s, va_list * args)
+{
+  srv6_ad_localsid_t *ls_mem = va_arg (*args, void *);
+
+  vnet_main_t *vnm = vnet_get_main ();
+
+  if (ls_mem->ip_version == DA_IP4)
+    {
+      return (format (s,
+                     "Next-hop:\t%U\n"
+                     "\tOutgoing iface: %U\n"
+                     "\tIncoming iface: %U",
+                     format_ip4_address, &ls_mem->nh_addr.ip4,
+                     format_vnet_sw_if_index_name, vnm,
+                     ls_mem->sw_if_index_out, format_vnet_sw_if_index_name,
+                     vnm, ls_mem->sw_if_index_in));
+    }
+  else
+    {
+      return (format (s,
+                     "Next-hop:\t%U\n"
+                     "\tOutgoing iface: %U\n"
+                     "\tIncoming iface: %U",
+                     format_ip6_address, &ls_mem->nh_addr.ip6,
+                     format_vnet_sw_if_index_name, vnm,
+                     ls_mem->sw_if_index_out, format_vnet_sw_if_index_name,
+                     vnm, ls_mem->sw_if_index_in));
+    }
+}
+
+/*
+ * Process the parameters of a localsid
+ * Example: process from:
+ * sr localsid address cafe::1 behavior new_srv6_localsid 5
+ * everything from behavior on... so in this case 'new_srv6_localsid 5'
+ * Notice that it MUST match the keyword_str and params_str defined above.
+ */
+uword
+unformat_srv6_ad_localsid (unformat_input_t * input, va_list * args)
+{
+  void **plugin_mem_p = va_arg (*args, void **);
+  srv6_ad_localsid_t *ls_mem;
+
+  vnet_main_t *vnm = vnet_get_main ();
+
+  ip46_address_t nh_addr;
+  u32 sw_if_index_out;
+  u32 sw_if_index_in;
+
+  if (unformat (input, "end.ad nh %U oif %U iif %U",
+               unformat_ip4_address, &nh_addr.ip4,
+               unformat_vnet_sw_interface, vnm, &sw_if_index_out,
+               unformat_vnet_sw_interface, vnm, &sw_if_index_in))
+    {
+      /* Allocate a portion of memory */
+      ls_mem = clib_mem_alloc_aligned_at_offset (sizeof *ls_mem, 0, 0, 1);
+
+      /* Set to zero the memory */
+      memset (ls_mem, 0, sizeof *ls_mem);
+
+      /* Our brand-new car is ready */
+      ls_mem->ip_version = DA_IP4;
+      clib_memcpy (&ls_mem->nh_addr.ip4, &nh_addr.ip4,
+                  sizeof (ip4_address_t));
+      ls_mem->sw_if_index_out = sw_if_index_out;
+      ls_mem->sw_if_index_in = sw_if_index_in;
+
+      /* Dont forget to add it to the localsid */
+      *plugin_mem_p = ls_mem;
+      return 1;
+    }
+  else if (unformat (input, "end.ad nh %U oif %U iif %U",
+                    unformat_ip6_address, &nh_addr.ip6,
+                    unformat_vnet_sw_interface, vnm, &sw_if_index_out,
+                    unformat_vnet_sw_interface, vnm, &sw_if_index_in))
+    {
+      /* Allocate a portion of memory */
+      ls_mem = clib_mem_alloc_aligned_at_offset (sizeof *ls_mem, 0, 0, 1);
+
+      /* Set to zero the memory */
+      memset (ls_mem, 0, sizeof *ls_mem);
+
+      /* Our brand-new car is ready */
+      ls_mem->ip_version = DA_IP6;
+      clib_memcpy (&ls_mem->nh_addr.ip6, &nh_addr.ip6,
+                  sizeof (ip6_address_t));
+      ls_mem->sw_if_index_out = sw_if_index_out;
+      ls_mem->sw_if_index_in = sw_if_index_in;
+
+      /* Dont forget to add it to the localsid */
+      *plugin_mem_p = ls_mem;
+      return 1;
+    }
+  return 0;
+}
+
+/*************************/
+/* SRv6 LocalSID FIB DPO */
+static u8 *
+format_srv6_ad_dpo (u8 * s, va_list * args)
+{
+  index_t index = va_arg (*args, index_t);
+  CLIB_UNUSED (u32 indent) = va_arg (*args, u32);
+
+  return (format (s, "SR: dynamic_proxy_index:[%u]", index));
+}
+
+void
+srv6_ad_dpo_lock (dpo_id_t * dpo)
+{
+}
+
+void
+srv6_ad_dpo_unlock (dpo_id_t * dpo)
+{
+}
+
+const static dpo_vft_t srv6_ad_vft = {
+  .dv_lock = srv6_ad_dpo_lock,
+  .dv_unlock = srv6_ad_dpo_unlock,
+  .dv_format = format_srv6_ad_dpo,
+};
+
+const static char *const srv6_ad_ip6_nodes[] = {
+  "srv6-ad-localsid",
+  NULL,
+};
+
+const static char *const *const srv6_ad_nodes[DPO_PROTO_NUM] = {
+  [DPO_PROTO_IP6] = srv6_ad_ip6_nodes,
+};
+
+/**********************/
+static clib_error_t *
+srv6_ad_init (vlib_main_t * vm)
+{
+  srv6_ad_main_t *sm = &srv6_ad_main;
+  int rv = 0;
+
+  sm->vlib_main = vm;
+  sm->vnet_main = vnet_get_main ();
+
+  /* Create DPO */
+  sm->srv6_ad_dpo_type = dpo_register_new_type (&srv6_ad_vft, srv6_ad_nodes);
+
+  /* Register SRv6 LocalSID */
+  rv = sr_localsid_register_function (vm,
+                                     function_name,
+                                     keyword_str,
+                                     def_str,
+                                     params_str,
+                                     &sm->srv6_ad_dpo_type,
+                                     format_srv6_ad_localsid,
+                                     unformat_srv6_ad_localsid,
+                                     srv6_ad_localsid_creation_fn,
+                                     srv6_ad_localsid_removal_fn);
+  if (rv < 0)
+    clib_error_return (0, "SRv6 LocalSID function could not be registered.");
+  else
+    sm->srv6_localsid_behavior_id = rv;
+
+  return 0;
+}
+
+/* *INDENT-OFF* */
+VNET_FEATURE_INIT (srv6_ad4_rewrite, static) =
+{
+  .arc_name = "ip4-unicast",
+  .node_name = "srv6-ad4-rewrite",
+  .runs_before = 0,
+};
+
+VNET_FEATURE_INIT (srv6_ad6_rewrite, static) =
+{
+  .arc_name = "ip6-unicast",
+  .node_name = "srv6-ad6-rewrite",
+  .runs_before = 0,
+};
+
+VLIB_INIT_FUNCTION (srv6_ad_init);
+
+VLIB_PLUGIN_REGISTER () = {
+  .version = VPP_BUILD_VER,
+  .description = "Dynamic SRv6 proxy",
+};
+/* *INDENT-ON* */
+
+/*
+* fd.io coding-style-patch-verification: ON
+*
+* Local Variables:
+* eval: (c-set-style "gnu")
+* End:
+*/
diff --git a/src/plugins/srv6-ad/ad.h b/src/plugins/srv6-ad/ad.h
new file mode 100644 (file)
index 0000000..851d3ed
--- /dev/null
@@ -0,0 +1,77 @@
+/*
+ * Copyright (c) 2015 Cisco and/or its affiliates.
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at:
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+#ifndef __included_srv6_ad_h__
+#define __included_srv6_ad_h__
+
+#include <vnet/vnet.h>
+#include <vnet/ip/ip.h>
+#include <vnet/srv6/sr.h>
+#include <vnet/srv6/sr_packet.h>
+
+#include <vppinfra/error.h>
+#include <vppinfra/elog.h>
+
+#define DA_IP4 4
+#define DA_IP6 6
+
+typedef struct
+{
+  u16 msg_id_base;                       /**< API message ID base */
+
+  vlib_main_t *vlib_main;                /**< [convenience] vlib main */
+  vnet_main_t *vnet_main;                /**< [convenience] vnet main */
+
+  dpo_type_t srv6_ad_dpo_type;           /**< DPO type */
+
+  u32 srv6_localsid_behavior_id;         /**< SRv6 LocalSID behavior number */
+
+  u32 *sw_iface_localsid4;               /**< Retrieve local SID from iface */
+  u32 *sw_iface_localsid6;               /**< Retrieve local SID from iface */
+} srv6_ad_main_t;
+
+/*
+ * This is the memory that will be stored per each localsid
+ * the user instantiates
+ */
+typedef struct
+{
+  ip46_address_t nh_addr;                        /**< Proxied device address */
+  u32 sw_if_index_out;                                             /**< Outgoing iface to proxied dev. */
+  u32 nh_adj;                                                                  /**< Adjacency index for out. iface */
+  u8 ip_version;
+
+  u32 sw_if_index_in;                                              /**< Incoming iface from proxied dev. */
+  u8 *rewrite;                                                         /**< Headers to be rewritten */
+} srv6_ad_localsid_t;
+
+srv6_ad_main_t srv6_ad_main;
+
+format_function_t format_srv6_ad_localsid;
+unformat_function_t unformat_srv6_ad_localsid;
+
+void srv6_ad_dpo_lock (dpo_id_t * dpo);
+void srv6_ad_dpo_unlock (dpo_id_t * dpo);
+
+extern vlib_node_registration_t srv6_ad_localsid_node;
+
+#endif /* __included_srv6_ad_h__ */
+
+/*
+* fd.io coding-style-patch-verification: ON
+*
+* Local Variables:
+* eval: (c-set-style "gnu")
+* End:
+*/
diff --git a/src/plugins/srv6-ad/ad_plugin_doc.md b/src/plugins/srv6-ad/ad_plugin_doc.md
new file mode 100644 (file)
index 0000000..fc8ebfe
--- /dev/null
@@ -0,0 +1,23 @@
+# SRv6 endpoint to SR-unaware appliance via dynamic proxy (End.AD) {#srv6_ad_plugin_doc}
+
+## Overview
+
+The "Endpoint to SR-unaware appliance via dynamic proxy" (End.AD) is a two-parts
+proxy function for processing SRv6 encapsulated traffic on behalf of an
+SR-unaware appliance. The first part decapsulates the incoming traffic and sends
+it towards an appliance on a specific interface, while the second
+re-encapsulates the traffic coming back from the appliance.
+
+In this scenario, there are no restrictions on the operations that can be
+performed by the appliance on the stream of packets. It may operate at all
+protocol layers, terminate transport layer connections, generate new packets and
+initiate transport layer connections. This function may also be used to
+integrate an IPv4-only appliance into an SRv6 policy.
+
+The End.AD function relies on a local caching mechanism to learn and
+re-encapsulate the traffic with the same headers that were removed. 
+This cache is used to store the IPv6 header and its
+extension headers while the appliance processes the inner packet. In the
+following, we refer to an entry in this cache as C(type,iface), where type is
+either IPv4 or IPv6 and iface is the receiving interface on the SRv6 proxy
+(IFACE-IN).
diff --git a/src/plugins/srv6-ad/node.c b/src/plugins/srv6-ad/node.c
new file mode 100644 (file)
index 0000000..73957f5
--- /dev/null
@@ -0,0 +1,521 @@
+/*
+ * Copyright (c) 2015 Cisco and/or its affiliates.
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at:
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+#include <vlib/vlib.h>
+#include <vnet/vnet.h>
+#include <vppinfra/error.h>
+#include <srv6-ad/ad.h>
+
+
+/******************************* Packet tracing *******************************/
+
+typedef struct
+{
+  u32 localsid_index;
+} srv6_ad_localsid_trace_t;
+
+typedef struct
+{
+  ip6_address_t src, dst;
+} srv6_ad_rewrite_trace_t;
+
+static u8 *
+format_srv6_ad_localsid_trace (u8 * s, va_list * args)
+{
+  CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
+  CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
+  srv6_ad_localsid_trace_t *t = va_arg (*args, srv6_ad_localsid_trace_t *);
+
+  return format (s, "SRv6-AD-localsid: localsid_index %d", t->localsid_index);
+}
+
+static u8 *
+format_srv6_ad_rewrite_trace (u8 * s, va_list * args)
+{
+  CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
+  CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
+  srv6_ad_rewrite_trace_t *t = va_arg (*args, srv6_ad_rewrite_trace_t *);
+
+  return format (s, "SRv6-AD-rewrite: src %U dst %U",
+                format_ip6_address, &t->src, format_ip6_address, &t->dst);
+}
+
+
+/***************************** Nodes registration *****************************/
+
+vlib_node_registration_t srv6_ad4_rewrite_node;
+vlib_node_registration_t srv6_ad6_rewrite_node;
+
+
+/****************************** Packet counters *******************************/
+
+#define foreach_srv6_ad_rewrite_counter \
+_(PROCESSED, "srv6-ad rewritten packets") \
+_(NO_RW, "(Error) No header for rewriting.")
+
+typedef enum
+{
+#define _(sym,str) SRV6_AD_REWRITE_COUNTER_##sym,
+  foreach_srv6_ad_rewrite_counter
+#undef _
+    SRV6_AD_REWRITE_N_COUNTERS,
+} srv6_ad_rewrite_counters;
+
+static char *srv6_ad_rewrite_counter_strings[] = {
+#define _(sym,string) string,
+  foreach_srv6_ad_rewrite_counter
+#undef _
+};
+
+
+/********************************* Next nodes *********************************/
+
+typedef enum
+{
+  SRV6_AD_LOCALSID_NEXT_ERROR,
+  SRV6_AD_LOCALSID_NEXT_REWRITE4,
+  SRV6_AD_LOCALSID_NEXT_REWRITE6,
+  SRV6_AD_LOCALSID_N_NEXT,
+} srv6_ad_localsid_next_t;
+
+typedef enum
+{
+  SRV6_AD_REWRITE_NEXT_ERROR,
+  SRV6_AD_REWRITE_NEXT_LOOKUP,
+  SRV6_AD_REWRITE_N_NEXT,
+} srv6_ad_rewrite_next_t;
+
+
+/******************************* Local SID node *******************************/
+
+/**
+ * @brief Function doing SRH processing for AD behavior
+ */
+static_always_inline void
+end_ad_processing (vlib_buffer_t * b0,
+                  ip6_header_t * ip0,
+                  ip6_sr_header_t * sr0,
+                  ip6_sr_localsid_t * ls0, u32 * next0)
+{
+  ip6_address_t *new_dst0;
+  u16 total_size;
+  ip6_ext_header_t *next_ext_header;
+  u8 next_hdr;
+  srv6_ad_localsid_t *ls0_mem;
+
+  if (PREDICT_FALSE (ip0->protocol != IP_PROTOCOL_IPV6_ROUTE ||
+                    sr0->type != ROUTING_HEADER_TYPE_SR))
+    {
+      return;
+    }
+
+  if (PREDICT_FALSE (sr0->segments_left == 0))
+    {
+      return;
+    }
+
+  /* Decrement Segments Left and update Destination Address */
+  sr0->segments_left -= 1;
+  new_dst0 = (ip6_address_t *) (sr0->segments) + sr0->segments_left;
+  ip0->dst_address.as_u64[0] = new_dst0->as_u64[0];
+  ip0->dst_address.as_u64[1] = new_dst0->as_u64[1];
+
+  /* Compute the total size of the IPv6 header and extensions */
+  total_size = sizeof (ip6_header_t);
+  next_ext_header = (ip6_ext_header_t *) (ip0 + 1);
+  next_hdr = ip0->protocol;
+
+  while (ip6_ext_hdr (next_hdr))
+    {
+      total_size += ip6_ext_header_len (next_ext_header);
+      next_hdr = next_ext_header->next_hdr;
+      next_ext_header = ip6_ext_next_header (next_ext_header);
+    }
+
+  /* Make sure next header is IP */
+  if (PREDICT_FALSE
+      (next_hdr != IP_PROTOCOL_IPV6 && next_hdr != IP_PROTOCOL_IP_IN_IP))
+    {
+      return;
+    }
+
+  /* Retrieve SID memory */
+  ls0_mem = ls0->plugin_mem;
+
+  /* Cache IP header and extensions */
+  vec_validate (ls0_mem->rewrite, total_size - 1);
+  clib_memcpy (ls0_mem->rewrite, ip0, total_size);
+
+  /* Remove IP header and extensions */
+  vlib_buffer_advance (b0, total_size);
+
+  /* Set Xconnect adjacency to VNF */
+  vnet_buffer (b0)->ip.adj_index[VLIB_TX] = ls0_mem->nh_adj;
+
+  if (ls0_mem->ip_version == DA_IP4)
+    *next0 = SRV6_AD_LOCALSID_NEXT_REWRITE4;
+  else if (ls0_mem->ip_version == DA_IP6)
+    *next0 = SRV6_AD_LOCALSID_NEXT_REWRITE6;
+}
+
+/**
+ * @brief SRv6 AD Localsid graph node
+ */
+static uword
+srv6_ad_localsid_fn (vlib_main_t * vm,
+                    vlib_node_runtime_t * node, vlib_frame_t * frame)
+{
+  ip6_sr_main_t *sm = &sr_main;
+  u32 n_left_from, next_index, *from, *to_next;
+  u32 cnt_packets = 0;
+
+  from = vlib_frame_vector_args (frame);
+  n_left_from = frame->n_vectors;
+  next_index = node->cached_next_index;
+
+  u32 thread_index = vlib_get_thread_index ();
+
+  while (n_left_from > 0)
+    {
+      u32 n_left_to_next;
+
+      vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
+
+      /* TODO: Dual/quad loop */
+
+      while (n_left_from > 0 && n_left_to_next > 0)
+       {
+         u32 bi0;
+         vlib_buffer_t *b0;
+         ip6_header_t *ip0 = 0;
+         ip6_sr_header_t *sr0;
+         ip6_sr_localsid_t *ls0;
+         u32 next0 = SRV6_AD_LOCALSID_NEXT_ERROR;
+
+         bi0 = from[0];
+         to_next[0] = bi0;
+         from += 1;
+         to_next += 1;
+         n_left_from -= 1;
+         n_left_to_next -= 1;
+
+         b0 = vlib_get_buffer (vm, bi0);
+         ip0 = vlib_buffer_get_current (b0);
+         sr0 = (ip6_sr_header_t *) (ip0 + 1);
+
+         /* Lookup the SR End behavior based on IP DA (adj) */
+         ls0 = pool_elt_at_index (sm->localsids,
+                                  vnet_buffer (b0)->ip.adj_index[VLIB_TX]);
+
+         /* SRH processing */
+         end_ad_processing (b0, ip0, sr0, ls0, &next0);
+
+         if (PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
+           {
+             srv6_ad_localsid_trace_t *tr =
+               vlib_add_trace (vm, node, b0, sizeof *tr);
+             tr->localsid_index = ls0 - sm->localsids;
+           }
+
+         /* This increments the SRv6 per LocalSID counters. */
+         vlib_increment_combined_counter (((next0 ==
+                                            SRV6_AD_LOCALSID_NEXT_ERROR) ?
+                                           &(sm->sr_ls_invalid_counters) :
+                                           &(sm->sr_ls_valid_counters)),
+                                          thread_index, ls0 - sm->localsids,
+                                          1, vlib_buffer_length_in_chain (vm,
+                                                                          b0));
+
+         vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
+                                          n_left_to_next, bi0, next0);
+
+         cnt_packets++;
+       }
+
+      vlib_put_next_frame (vm, node, next_index, n_left_to_next);
+    }
+
+  return frame->n_vectors;
+}
+
+/* *INDENT-OFF* */
+VLIB_REGISTER_NODE (srv6_ad_localsid_node) = {
+  .function = srv6_ad_localsid_fn,
+  .name = "srv6-ad-localsid",
+  .vector_size = sizeof (u32),
+  .format_trace = format_srv6_ad_localsid_trace,
+  .type = VLIB_NODE_TYPE_INTERNAL,
+  .n_next_nodes = SRV6_AD_LOCALSID_N_NEXT,
+  .next_nodes = {
+    [SRV6_AD_LOCALSID_NEXT_REWRITE4] = "ip4-rewrite",
+    [SRV6_AD_LOCALSID_NEXT_REWRITE6] = "ip6-rewrite",
+    [SRV6_AD_LOCALSID_NEXT_ERROR] = "error-drop",
+  },
+};
+/* *INDENT-ON* */
+
+
+/******************************* Rewriting node *******************************/
+
+/**
+ * @brief Graph node for applying a SR policy into an IPv6 packet. Encapsulation
+ */
+static uword
+srv6_ad4_rewrite_fn (vlib_main_t * vm,
+                    vlib_node_runtime_t * node, vlib_frame_t * frame)
+{
+  ip6_sr_main_t *srm = &sr_main;
+  srv6_ad_main_t *sm = &srv6_ad_main;
+  u32 n_left_from, next_index, *from, *to_next;
+  u32 cnt_packets = 0;
+
+  from = vlib_frame_vector_args (frame);
+  n_left_from = frame->n_vectors;
+  next_index = node->cached_next_index;
+
+  while (n_left_from > 0)
+    {
+      u32 n_left_to_next;
+
+      vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
+
+      /* TODO: Dual/quad loop */
+
+      while (n_left_from > 0 && n_left_to_next > 0)
+       {
+         u32 bi0;
+         vlib_buffer_t *b0;
+         ip4_header_t *ip0_encap = 0;
+         ip6_header_t *ip0 = 0;
+         ip6_sr_localsid_t *ls0;
+         srv6_ad_localsid_t *ls0_mem;
+         u32 next0 = SRV6_AD_REWRITE_NEXT_LOOKUP;
+         u16 new_l0 = 0;
+
+         bi0 = from[0];
+         to_next[0] = bi0;
+         from += 1;
+         to_next += 1;
+         n_left_from -= 1;
+         n_left_to_next -= 1;
+
+         b0 = vlib_get_buffer (vm, bi0);
+         ip0_encap = vlib_buffer_get_current (b0);
+         ls0 = pool_elt_at_index (srm->localsids,
+                                  sm->sw_iface_localsid4[vnet_buffer
+                                                         (b0)->sw_if_index
+                                                         [VLIB_RX]]);
+         ls0_mem = ls0->plugin_mem;
+
+         if (PREDICT_FALSE (ls0_mem == NULL || ls0_mem->rewrite == NULL))
+           {
+             next0 = SRV6_AD_REWRITE_NEXT_ERROR;
+             b0->error = node->errors[SRV6_AD_REWRITE_COUNTER_NO_RW];
+           }
+         else
+           {
+             ASSERT (VLIB_BUFFER_PRE_DATA_SIZE >=
+                     (vec_len (ls0_mem->rewrite) + b0->current_data));
+
+             clib_memcpy (((u8 *) ip0_encap) - vec_len (ls0_mem->rewrite),
+                          ls0_mem->rewrite, vec_len (ls0_mem->rewrite));
+             vlib_buffer_advance (b0, -(word) vec_len (ls0_mem->rewrite));
+
+             ip0 = vlib_buffer_get_current (b0);
+
+             /* Update inner IPv4 TTL and checksum */
+             u32 checksum0;
+             ip0_encap->ttl -= 1;
+             checksum0 = ip0_encap->checksum + clib_host_to_net_u16 (0x0100);
+             checksum0 += checksum0 >= 0xffff;
+             ip0_encap->checksum = checksum0;
+
+             /* Update outer IPv6 length (in case it has changed) */
+             new_l0 = vec_len (ls0_mem->rewrite) - sizeof (ip6_header_t) +
+               clib_net_to_host_u16 (ip0_encap->length);
+             ip0->payload_length = clib_host_to_net_u16 (new_l0);
+           }
+
+         if (PREDICT_FALSE (node->flags & VLIB_NODE_FLAG_TRACE) &&
+             PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
+           {
+             srv6_ad_rewrite_trace_t *tr =
+               vlib_add_trace (vm, node, b0, sizeof *tr);
+             clib_memcpy (tr->src.as_u8, ip0->src_address.as_u8,
+                          sizeof tr->src.as_u8);
+             clib_memcpy (tr->dst.as_u8, ip0->dst_address.as_u8,
+                          sizeof tr->dst.as_u8);
+           }
+
+         vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
+                                          n_left_to_next, bi0, next0);
+
+         cnt_packets++;
+       }
+
+      vlib_put_next_frame (vm, node, next_index, n_left_to_next);
+    }
+
+  /* Update counters */
+  vlib_node_increment_counter (vm, srv6_ad4_rewrite_node.index,
+                              SRV6_AD_REWRITE_COUNTER_PROCESSED,
+                              cnt_packets);
+
+  return frame->n_vectors;
+}
+
+/* *INDENT-OFF* */
+VLIB_REGISTER_NODE (srv6_ad4_rewrite_node) = {
+  .function = srv6_ad4_rewrite_fn,
+  .name = "srv6-ad4-rewrite",
+  .vector_size = sizeof (u32),
+  .format_trace = format_srv6_ad_rewrite_trace,
+  .type = VLIB_NODE_TYPE_INTERNAL,
+  .n_errors = SRV6_AD_REWRITE_N_COUNTERS,
+  .error_strings = srv6_ad_rewrite_counter_strings,
+  .n_next_nodes = SRV6_AD_REWRITE_N_NEXT,
+  .next_nodes = {
+      [SRV6_AD_REWRITE_NEXT_LOOKUP] = "ip6-lookup",
+      [SRV6_AD_REWRITE_NEXT_ERROR] = "error-drop",
+  },
+};
+/* *INDENT-ON* */
+
+
+/**
+ * @brief Graph node for applying a SR policy into an IPv6 packet. Encapsulation
+ */
+static uword
+srv6_ad6_rewrite_fn (vlib_main_t * vm,
+                    vlib_node_runtime_t * node, vlib_frame_t * frame)
+{
+  ip6_sr_main_t *srm = &sr_main;
+  srv6_ad_main_t *sm = &srv6_ad_main;
+  u32 n_left_from, next_index, *from, *to_next;
+  u32 cnt_packets = 0;
+
+  from = vlib_frame_vector_args (frame);
+  n_left_from = frame->n_vectors;
+  next_index = node->cached_next_index;
+
+  while (n_left_from > 0)
+    {
+      u32 n_left_to_next;
+
+      vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
+
+      /* TODO: Dual/quad loop */
+
+      while (n_left_from > 0 && n_left_to_next > 0)
+       {
+         u32 bi0;
+         vlib_buffer_t *b0;
+         ip6_header_t *ip0 = 0, *ip0_encap = 0;
+         ip6_sr_localsid_t *ls0;
+         srv6_ad_localsid_t *ls0_mem;
+         u32 next0 = SRV6_AD_REWRITE_NEXT_LOOKUP;
+         u16 new_l0 = 0;
+
+         bi0 = from[0];
+         to_next[0] = bi0;
+         from += 1;
+         to_next += 1;
+         n_left_from -= 1;
+         n_left_to_next -= 1;
+
+         b0 = vlib_get_buffer (vm, bi0);
+         ip0_encap = vlib_buffer_get_current (b0);
+         ls0 = pool_elt_at_index (srm->localsids,
+                                  sm->sw_iface_localsid6[vnet_buffer
+                                                         (b0)->sw_if_index
+                                                         [VLIB_RX]]);
+         ls0_mem = ls0->plugin_mem;
+
+         if (PREDICT_FALSE (ls0_mem == NULL || ls0_mem->rewrite == NULL))
+           {
+             next0 = SRV6_AD_REWRITE_NEXT_ERROR;
+             b0->error = node->errors[SRV6_AD_REWRITE_COUNTER_NO_RW];
+           }
+         else
+           {
+             ASSERT (VLIB_BUFFER_PRE_DATA_SIZE >=
+                     (vec_len (ls0_mem->rewrite) + b0->current_data));
+
+             clib_memcpy (((u8 *) ip0_encap) - vec_len (ls0_mem->rewrite),
+                          ls0_mem->rewrite, vec_len (ls0_mem->rewrite));
+             vlib_buffer_advance (b0, -(word) vec_len (ls0_mem->rewrite));
+
+             ip0 = vlib_buffer_get_current (b0);
+
+             /* Update inner IPv6 hop limit */
+             ip0_encap->hop_limit -= 1;
+
+             /* Update outer IPv6 length (in case it has changed) */
+             new_l0 = vec_len (ls0_mem->rewrite) +
+               clib_net_to_host_u16 (ip0_encap->payload_length);
+             ip0->payload_length = clib_host_to_net_u16 (new_l0);
+           }
+
+         if (PREDICT_FALSE (node->flags & VLIB_NODE_FLAG_TRACE) &&
+             PREDICT_FALSE (b0->flags & VLIB_BUFFER_IS_TRACED))
+           {
+             srv6_ad_rewrite_trace_t *tr =
+               vlib_add_trace (vm, node, b0, sizeof *tr);
+             clib_memcpy (tr->src.as_u8, ip0->src_address.as_u8,
+                          sizeof tr->src.as_u8);
+             clib_memcpy (tr->dst.as_u8, ip0->dst_address.as_u8,
+                          sizeof tr->dst.as_u8);
+           }
+
+         vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
+                                          n_left_to_next, bi0, next0);
+
+         cnt_packets++;
+       }
+
+      vlib_put_next_frame (vm, node, next_index, n_left_to_next);
+    }
+
+  /* Update counters */
+  vlib_node_increment_counter (vm, srv6_ad6_rewrite_node.index,
+                              SRV6_AD_REWRITE_COUNTER_PROCESSED,
+                              cnt_packets);
+
+  return frame->n_vectors;
+}
+
+/* *INDENT-OFF* */
+VLIB_REGISTER_NODE (srv6_ad6_rewrite_node) = {
+  .function = srv6_ad6_rewrite_fn,
+  .name = "srv6-ad6-rewrite",
+  .vector_size = sizeof (u32),
+  .format_trace = format_srv6_ad_rewrite_trace,
+  .type = VLIB_NODE_TYPE_INTERNAL,
+  .n_errors = SRV6_AD_REWRITE_N_COUNTERS,
+  .error_strings = srv6_ad_rewrite_counter_strings,
+  .n_next_nodes = SRV6_AD_REWRITE_N_NEXT,
+  .next_nodes = {
+      [SRV6_AD_REWRITE_NEXT_LOOKUP] = "ip6-lookup",
+      [SRV6_AD_REWRITE_NEXT_ERROR] = "error-drop",
+  },
+};
+/* *INDENT-ON* */
+
+/*
+* fd.io coding-style-patch-verification: ON
+*
+* Local Variables:
+* eval: (c-set-style "gnu")
+* End:
+*/
diff --git a/src/plugins/srv6_ad.am b/src/plugins/srv6_ad.am
new file mode 100644 (file)
index 0000000..ea1297b
--- /dev/null
@@ -0,0 +1,22 @@
+# Copyright (c) 2016 Cisco Systems, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at:
+#
+#     http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+vppplugins_LTLIBRARIES += srv6ad_plugin.la
+
+srv6ad_plugin_la_SOURCES =                     \
+       srv6-ad/ad.c    \
+       srv6-ad/node.c
+
+noinst_HEADERS += srv6-ad/ad.h
+
+# vi:syntax=automake