FD.io VPP  v18.07-rc0-415-g6c78436
Vector Packet Processing
decap.c
Go to the documentation of this file.
1 /*
2  * decap.c: vxlan tunnel decap packet processing
3  *
4  * Copyright (c) 2013 Cisco and/or its affiliates.
5  * Licensed under the Apache License, Version 2.0 (the "License");
6  * you may not use this file except in compliance with the License.
7  * You may obtain a copy of the License at:
8  *
9  * http://www.apache.org/licenses/LICENSE-2.0
10  *
11  * Unless required by applicable law or agreed to in writing, software
12  * distributed under the License is distributed on an "AS IS" BASIS,
13  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14  * See the License for the specific language governing permissions and
15  * limitations under the License.
16  */
17 
18 #include <vlib/vlib.h>
19 #include <vnet/pg/pg.h>
20 #include <vnet/vxlan/vxlan.h>
21 
24 
25 typedef struct {
31 
32 static u8 * format_vxlan_rx_trace (u8 * s, va_list * args)
33 {
34  CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
35  CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
36  vxlan_rx_trace_t * t = va_arg (*args, vxlan_rx_trace_t *);
37 
38  if (t->tunnel_index != ~0)
39  {
40  s = format (s, "VXLAN decap from vxlan_tunnel%d vni %d next %d error %d",
41  t->tunnel_index, t->vni, t->next_index, t->error);
42  }
43  else
44  {
45  s = format (s, "VXLAN decap error - tunnel for vni %d does not exist",
46  t->vni);
47  }
48  return s;
49 }
50 
53 {
54  u32 sw_if_index = vnet_buffer (b)->sw_if_index[VLIB_RX];
55 
56  u32 * fib_index_by_sw_if_index = is_ip4 ?
58  u32 tx_sw_if_index = vnet_buffer (b)->sw_if_index[VLIB_TX];
59  u32 fib_index = (tx_sw_if_index == (u32) ~ 0) ?
60  vec_elt (fib_index_by_sw_if_index, sw_if_index) : tx_sw_if_index;
61 
62  return (fib_index == t->encap_fib_index);
63 }
64 
65 typedef struct
66 {
67  vxlan4_tunnel_key_t key4;
70 
71 typedef struct
72 {
73  vxlan6_tunnel_key_t key6;
76 
79  ip4_header_t * ip4_0, vxlan_header_t * vxlan0,
80  vxlan_tunnel_t ** stats_t0)
81 {
82  /* Make sure VXLAN tunnel exist according to packet SIP and VNI */
83  vxlan4_tunnel_key_t key4_0 = {
84  .src = ip4_0->src_address.as_u32,
85  .vni = vxlan0->vni_reserved,
86  };
87 
88  if (PREDICT_FALSE (key4_0.as_u64 != cache->key4.as_u64))
89  {
90  uword * p = hash_get (vxm->vxlan4_tunnel_by_key, key4_0.as_u64);
91  if (PREDICT_FALSE (p == 0))
92  return 0;
93 
94  cache->key4 = key4_0;
95  cache->tunnel_index = p[0];
96  }
98 
99  /* Validate VXLAN tunnel SIP against packet DIP */
100  if (PREDICT_TRUE (ip4_0->dst_address.as_u32 == t0->src.ip4.as_u32))
101  *stats_t0 = t0;
102  else
103  {
104  /* try multicast */
106  return 0;
107 
108  key4_0.src = ip4_0->dst_address.as_u32;
109  /* Make sure mcast VXLAN tunnel exist by packet DIP and VNI */
110  uword * p = hash_get (vxm->vxlan4_tunnel_by_key, key4_0.as_u64);
111  if (PREDICT_FALSE (p == NULL))
112  return 0;
113  *stats_t0 = pool_elt_at_index (vxm->tunnels, p[0]);
114  }
115 
116  return t0;
117 }
118 
121  ip6_header_t * ip6_0, vxlan_header_t * vxlan0,
122  vxlan_tunnel_t ** stats_t0)
123 {
124  /* Make sure VXLAN tunnel exist according to packet SIP and VNI */
125  vxlan6_tunnel_key_t key6_0 = {
126  .src = ip6_0->src_address,
127  .vni = vxlan0->vni_reserved,
128  };
129 
130  if (PREDICT_FALSE (memcmp(&key6_0, &cache->key6, sizeof key6_0) != 0))
131  {
132  uword * p = hash_get_mem (vxm->vxlan6_tunnel_by_key, &key6_0);
133  if (PREDICT_FALSE (p == NULL))
134  return 0;
135 
136  cache->key6 = key6_0;
137  cache->tunnel_index = p[0];
138  }
140 
141  /* Validate VXLAN tunnel SIP against packet DIP */
142  if (PREDICT_TRUE (ip6_address_is_equal (&ip6_0->dst_address, &t0->src.ip6)))
143  *stats_t0 = t0;
144  else
145  {
146  /* try multicast */
148  return 0;
149 
150  key6_0.src = ip6_0->dst_address;
151  /* Make sure mcast VXLAN tunnel exist by packet DIP and VNI */
152  uword * p = hash_get_mem (vxm->vxlan6_tunnel_by_key, &key6_0);
153  if (PREDICT_FALSE (p == NULL))
154  return 0;
155  *stats_t0 = pool_elt_at_index (vxm->tunnels, p[0]);
156  }
157 
158  return t0;
159 }
160 
163  vlib_node_runtime_t * node,
164  vlib_frame_t * from_frame,
165  u32 is_ip4)
166 {
167  vxlan_main_t * vxm = &vxlan_main;
168  vnet_main_t * vnm = vxm->vnet_main;
172  last_tunnel_cache4 last4 = { .tunnel_index = ~0 };
173  last_tunnel_cache6 last6 = { .tunnel_index = ~0 };
174  u32 pkts_decapsulated = 0;
175  u32 thread_index = vlib_get_thread_index();
176 
177  if (is_ip4)
178  last4.key4.as_u64 = ~0;
179  else
180  memset (&last6.key6, 0xff, sizeof last6.key6);
181 
182  u32 next_index = node->cached_next_index;
183 
184  u32 * from = vlib_frame_vector_args (from_frame);
185  u32 n_left_from = from_frame->n_vectors;
186 
187  while (n_left_from > 0)
188  {
189  u32 * to_next, n_left_to_next;
190  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
191 
192  while (n_left_from >= 4 && n_left_to_next >= 2)
193  {
194  /* Prefetch next iteration. */
195  {
196  vlib_buffer_t * p2, * p3;
197 
198  p2 = vlib_get_buffer (vm, from[2]);
199  p3 = vlib_get_buffer (vm, from[3]);
200 
201  vlib_prefetch_buffer_header (p2, LOAD);
202  vlib_prefetch_buffer_header (p3, LOAD);
203 
206  }
207 
208  u32 bi0 = to_next[0] = from[0];
209  u32 bi1 = to_next[1] = from[1];
210  from += 2;
211  to_next += 2;
212  n_left_to_next -= 2;
213  n_left_from -= 2;
214 
215  vlib_buffer_t * b0, * b1;
216  b0 = vlib_get_buffer (vm, bi0);
217  b1 = vlib_get_buffer (vm, bi1);
218 
219  /* udp leaves current_data pointing at the vxlan header */
220  void * cur0 = vlib_buffer_get_current (b0);
221  void * cur1 = vlib_buffer_get_current (b1);
222  vxlan_header_t * vxlan0 = cur0;
223  vxlan_header_t * vxlan1 = cur1;
224 
225  ip4_header_t * ip4_0, * ip4_1;
226  ip6_header_t * ip6_0, * ip6_1;
227  if (is_ip4) {
228  ip4_0 = cur0 - sizeof(udp_header_t) - sizeof(ip4_header_t);
229  ip4_1 = cur1 - sizeof(udp_header_t) - sizeof(ip4_header_t);
230  } else {
231  ip6_0 = cur0 - sizeof(udp_header_t) - sizeof(ip6_header_t);
232  ip6_1 = cur1 - sizeof(udp_header_t) - sizeof(ip6_header_t);
233  }
234 
235  /* pop vxlan */
236  vlib_buffer_advance (b0, sizeof *vxlan0);
237  vlib_buffer_advance (b1, sizeof *vxlan1);
238 
239  vxlan_tunnel_t * t0, * stats_t0;
240  vxlan_tunnel_t * t1, * stats_t1;
241  if (is_ip4)
242  {
243  t0 = vxlan4_find_tunnel (vxm, &last4, ip4_0, vxlan0, &stats_t0);
244  t1 = vxlan4_find_tunnel (vxm, &last4, ip4_1, vxlan1, &stats_t1);
245  }
246  else
247  {
248  t0 = vxlan6_find_tunnel (vxm, &last6, ip6_0, vxlan0, &stats_t0);
249  t1 = vxlan6_find_tunnel (vxm, &last6, ip6_1, vxlan1, &stats_t1);
250  }
251 
252  u32 len0 = vlib_buffer_length_in_chain (vm, b0);
253  u32 len1 = vlib_buffer_length_in_chain (vm, b1);
254 
255  u32 next0, next1;
256  u8 error0 = 0, error1 = 0;
257  /* Validate VXLAN tunnel encap-fib index agaist packet */
258  if (PREDICT_FALSE (t0 == 0 || validate_vxlan_fib (b0, t0, is_ip4) == 0 ||
259  vxlan0->flags != VXLAN_FLAGS_I))
260  {
261  next0 = VXLAN_INPUT_NEXT_DROP;
262 
263  if (t0 != 0 && vxlan0->flags != VXLAN_FLAGS_I)
264  {
265  error0 = VXLAN_ERROR_BAD_FLAGS;
267  (drop_counter, thread_index, stats_t0->sw_if_index, 1, len0);
268  }
269  else
270  error0 = VXLAN_ERROR_NO_SUCH_TUNNEL;
271  b0->error = node->errors[error0];
272  }
273  else
274  {
275  next0 = t0->decap_next_index;
276 
277  /* Required to make the l2 tag push / pop code work on l2 subifs */
278  if (PREDICT_TRUE(next0 == VXLAN_INPUT_NEXT_L2_INPUT))
279  vnet_update_l2_len (b0);
280 
281  /* Set packet input sw_if_index to unicast VXLAN tunnel for learning */
282  vnet_buffer(b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
284  (rx_counter, thread_index, stats_t0->sw_if_index, 1, len0);
285  pkts_decapsulated++;
286  }
287 
288  /* Validate VXLAN tunnel encap-fib index agaist packet */
289  if (PREDICT_FALSE (t1 == 0 || validate_vxlan_fib (b1, t1, is_ip4) == 0 ||
290  vxlan1->flags != VXLAN_FLAGS_I))
291  {
292  next1 = VXLAN_INPUT_NEXT_DROP;
293 
294  if (t1 != 0 && vxlan1->flags != VXLAN_FLAGS_I)
295  {
296  error1 = VXLAN_ERROR_BAD_FLAGS;
298  (drop_counter, thread_index, stats_t1->sw_if_index, 1, len1);
299  }
300  else
301  error1 = VXLAN_ERROR_NO_SUCH_TUNNEL;
302  b1->error = node->errors[error1];
303  }
304  else
305  {
306  next1 = t1->decap_next_index;
307 
308  /* Required to make the l2 tag push / pop code work on l2 subifs */
309  if (PREDICT_TRUE(next1 == VXLAN_INPUT_NEXT_L2_INPUT))
310  vnet_update_l2_len (b1);
311 
312  /* Set packet input sw_if_index to unicast VXLAN tunnel for learning */
313  vnet_buffer(b1)->sw_if_index[VLIB_RX] = t1->sw_if_index;
314  pkts_decapsulated++;
315 
317  (rx_counter, thread_index, stats_t1->sw_if_index, 1, len1);
318  }
319 
320  if (PREDICT_FALSE(b0->flags & VLIB_BUFFER_IS_TRACED))
321  {
322  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b0, sizeof (*tr));
323  tr->next_index = next0;
324  tr->error = error0;
325  tr->tunnel_index = t0 == 0 ? ~0 : t0 - vxm->tunnels;
326  tr->vni = vnet_get_vni (vxlan0);
327  }
328  if (PREDICT_FALSE(b1->flags & VLIB_BUFFER_IS_TRACED))
329  {
330  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b1, sizeof (*tr));
331  tr->next_index = next1;
332  tr->error = error1;
333  tr->tunnel_index = t1 == 0 ? ~0 : t1 - vxm->tunnels;
334  tr->vni = vnet_get_vni (vxlan1);
335  }
336 
337  vlib_validate_buffer_enqueue_x2 (vm, node, next_index,
338  to_next, n_left_to_next,
339  bi0, bi1, next0, next1);
340  }
341 
342  while (n_left_from > 0 && n_left_to_next > 0)
343  {
344  u32 bi0 = to_next[0] = from[0];
345  from += 1;
346  to_next += 1;
347  n_left_from -= 1;
348  n_left_to_next -= 1;
349 
350  vlib_buffer_t * b0 = vlib_get_buffer (vm, bi0);
351 
352  /* udp leaves current_data pointing at the vxlan header */
353  void * cur0 = vlib_buffer_get_current (b0);
354  vxlan_header_t * vxlan0 = cur0;
355  ip4_header_t * ip4_0;
356  ip6_header_t * ip6_0;
357  if (is_ip4)
358  ip4_0 = cur0 -sizeof(udp_header_t) - sizeof(ip4_header_t);
359  else
360  ip6_0 = cur0 -sizeof(udp_header_t) - sizeof(ip6_header_t);
361 
362  /* pop (ip, udp, vxlan) */
363  vlib_buffer_advance (b0, sizeof(*vxlan0));
364 
365  vxlan_tunnel_t * t0, * stats_t0;
366  if (is_ip4)
367  t0 = vxlan4_find_tunnel (vxm, &last4, ip4_0, vxlan0, &stats_t0);
368  else
369  t0 = vxlan6_find_tunnel (vxm, &last6, ip6_0, vxlan0, &stats_t0);
370 
371  uword len0 = vlib_buffer_length_in_chain (vm, b0);
372 
373  u32 next0;
374  u8 error0 = 0;
375  /* Validate VXLAN tunnel encap-fib index agaist packet */
376  if (PREDICT_FALSE (t0 == 0 || validate_vxlan_fib (b0, t0, is_ip4) == 0 ||
377  vxlan0->flags != VXLAN_FLAGS_I))
378  {
379  next0 = VXLAN_INPUT_NEXT_DROP;
380 
381  if (t0 != 0 && vxlan0->flags != VXLAN_FLAGS_I)
382  {
383  error0 = VXLAN_ERROR_BAD_FLAGS;
385  (drop_counter, thread_index, stats_t0->sw_if_index, 1, len0);
386  }
387  else
388  error0 = VXLAN_ERROR_NO_SUCH_TUNNEL;
389  b0->error = node->errors[error0];
390  }
391  else
392  {
393  next0 = t0->decap_next_index;
394 
395  /* Required to make the l2 tag push / pop code work on l2 subifs */
396  if (PREDICT_TRUE(next0 == VXLAN_INPUT_NEXT_L2_INPUT))
397  vnet_update_l2_len (b0);
398 
399  /* Set packet input sw_if_index to unicast VXLAN tunnel for learning */
400  vnet_buffer(b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
401  pkts_decapsulated++;
402 
404  (rx_counter, thread_index, stats_t0->sw_if_index, 1, len0);
405  }
406 
407  if (PREDICT_FALSE(b0->flags & VLIB_BUFFER_IS_TRACED))
408  {
409  vxlan_rx_trace_t *tr
410  = vlib_add_trace (vm, node, b0, sizeof (*tr));
411  tr->next_index = next0;
412  tr->error = error0;
413  tr->tunnel_index = t0 == 0 ? ~0 : t0 - vxm->tunnels;
414  tr->vni = vnet_get_vni (vxlan0);
415  }
416  vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
417  to_next, n_left_to_next,
418  bi0, next0);
419  }
420 
421  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
422  }
423  /* Do we still need this now that tunnel tx stats is kept? */
424  u32 node_idx = is_ip4 ? vxlan4_input_node.index : vxlan6_input_node.index;
425  vlib_node_increment_counter (vm, node_idx, VXLAN_ERROR_DECAPSULATED,
426  pkts_decapsulated);
427 
428  return from_frame->n_vectors;
429 }
430 
431 static uword
433  vlib_node_runtime_t * node,
434  vlib_frame_t * from_frame)
435 {
436  return vxlan_input(vm, node, from_frame, /* is_ip4 */ 1);
437 }
438 
439 static uword
441  vlib_node_runtime_t * node,
442  vlib_frame_t * from_frame)
443 {
444  return vxlan_input(vm, node, from_frame, /* is_ip4 */ 0);
445 }
446 
447 static char * vxlan_error_strings[] = {
448 #define vxlan_error(n,s) s,
450 #undef vxlan_error
451 #undef _
452 };
453 
455  .function = vxlan4_input,
456  .name = "vxlan4-input",
457  /* Takes a vector of packets. */
458  .vector_size = sizeof (u32),
459 
460  .n_errors = VXLAN_N_ERROR,
461  .error_strings = vxlan_error_strings,
462 
463  .n_next_nodes = VXLAN_INPUT_N_NEXT,
464  .next_nodes = {
465 #define _(s,n) [VXLAN_INPUT_NEXT_##s] = n,
467 #undef _
468  },
469 
470 //temp .format_buffer = format_vxlan_header,
471  .format_trace = format_vxlan_rx_trace,
472  // $$$$ .unformat_buffer = unformat_vxlan_header,
473 };
474 
476 
478  .function = vxlan6_input,
479  .name = "vxlan6-input",
480  /* Takes a vector of packets. */
481  .vector_size = sizeof (u32),
482 
483  .n_errors = VXLAN_N_ERROR,
484  .error_strings = vxlan_error_strings,
485 
486  .n_next_nodes = VXLAN_INPUT_N_NEXT,
487  .next_nodes = {
488 #define _(s,n) [VXLAN_INPUT_NEXT_##s] = n,
490 #undef _
491  },
492 
493 //temp .format_buffer = format_vxlan_header,
494  .format_trace = format_vxlan_rx_trace,
495  // $$$$ .unformat_buffer = unformat_vxlan_header,
496 };
497 
499 
500 
501 typedef enum {
506 
509  vlib_node_runtime_t * node,
510  vlib_frame_t * frame,
511  u32 is_ip4)
512 {
513  vxlan_main_t * vxm = &vxlan_main;
514  u32 * from, * to_next, n_left_from, n_left_to_next, next_index;
515  vlib_node_runtime_t * error_node = vlib_node_get_runtime (vm, ip4_input_node.index);
516  ip4_address_t addr4; /* last IPv4 address matching a local VTEP address */
517  ip6_address_t addr6; /* last IPv6 address matching a local VTEP address */
518 
519  from = vlib_frame_vector_args (frame);
520  n_left_from = frame->n_vectors;
521  next_index = node->cached_next_index;
522 
523  if (node->flags & VLIB_NODE_FLAG_TRACE)
524  ip4_forward_next_trace (vm, node, frame, VLIB_TX);
525 
526  if (is_ip4) addr4.data_u32 = ~0;
527  else ip6_address_set_zero (&addr6);
528 
529  while (n_left_from > 0)
530  {
531  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
532 
533  while (n_left_from >= 4 && n_left_to_next >= 2)
534  {
535  vlib_buffer_t * b0, * b1;
536  ip4_header_t * ip40, * ip41;
537  ip6_header_t * ip60, * ip61;
538  udp_header_t * udp0, * udp1;
539  u32 bi0, ip_len0, udp_len0, flags0, next0;
540  u32 bi1, ip_len1, udp_len1, flags1, next1;
541  i32 len_diff0, len_diff1;
542  u8 error0, good_udp0, proto0;
543  u8 error1, good_udp1, proto1;
544 
545  /* Prefetch next iteration. */
546  {
547  vlib_buffer_t * p2, * p3;
548 
549  p2 = vlib_get_buffer (vm, from[2]);
550  p3 = vlib_get_buffer (vm, from[3]);
551 
552  vlib_prefetch_buffer_header (p2, LOAD);
553  vlib_prefetch_buffer_header (p3, LOAD);
554 
557  }
558 
559  bi0 = to_next[0] = from[0];
560  bi1 = to_next[1] = from[1];
561  from += 2;
562  n_left_from -= 2;
563  to_next += 2;
564  n_left_to_next -= 2;
565 
566  b0 = vlib_get_buffer (vm, bi0);
567  b1 = vlib_get_buffer (vm, bi1);
568  if (is_ip4)
569  {
570  ip40 = vlib_buffer_get_current (b0);
571  ip41 = vlib_buffer_get_current (b1);
572  }
573  else
574  {
575  ip60 = vlib_buffer_get_current (b0);
576  ip61 = vlib_buffer_get_current (b1);
577  }
578 
579  /* Setup packet for next IP feature */
580  vnet_feature_next(vnet_buffer(b0)->sw_if_index[VLIB_RX], &next0, b0);
581  vnet_feature_next(vnet_buffer(b1)->sw_if_index[VLIB_RX], &next1, b1);
582 
583  if (is_ip4)
584  {
585  /* Treat IP frag packets as "experimental" protocol for now
586  until support of IP frag reassembly is implemented */
587  proto0 = ip4_is_fragment(ip40) ? 0xfe : ip40->protocol;
588  proto1 = ip4_is_fragment(ip41) ? 0xfe : ip41->protocol;
589  }
590  else
591  {
592  proto0 = ip60->protocol;
593  proto1 = ip61->protocol;
594  }
595 
596  /* Process packet 0 */
597  if (proto0 != IP_PROTOCOL_UDP)
598  goto exit0; /* not UDP packet */
599 
600  if (is_ip4)
601  udp0 = ip4_next_header (ip40);
602  else
603  udp0 = ip6_next_header (ip60);
604 
605  if (udp0->dst_port != clib_host_to_net_u16 (UDP_DST_PORT_vxlan))
606  goto exit0; /* not VXLAN packet */
607 
608  /* Validate DIP against VTEPs*/
609  if (is_ip4)
610  {
611  if (addr4.as_u32 != ip40->dst_address.as_u32)
612  {
613  if (!hash_get (vxm->vtep4, ip40->dst_address.as_u32))
614  goto exit0; /* no local VTEP for VXLAN packet */
615  addr4 = ip40->dst_address;
616  }
617  }
618  else
619  {
620  if (!ip6_address_is_equal (&addr6, &ip60->dst_address))
621  {
622  if (!hash_get_mem (vxm->vtep6, &ip60->dst_address))
623  goto exit0; /* no local VTEP for VXLAN packet */
624  addr6 = ip60->dst_address;
625  }
626  }
627 
628  flags0 = b0->flags;
629  good_udp0 = (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
630 
631  /* Don't verify UDP checksum for packets with explicit zero checksum. */
632  good_udp0 |= udp0->checksum == 0;
633 
634  /* Verify UDP length */
635  if (is_ip4)
636  ip_len0 = clib_net_to_host_u16 (ip40->length);
637  else
638  ip_len0 = clib_net_to_host_u16 (ip60->payload_length);
639  udp_len0 = clib_net_to_host_u16 (udp0->length);
640  len_diff0 = ip_len0 - udp_len0;
641 
642  /* Verify UDP checksum */
643  if (PREDICT_FALSE (!good_udp0))
644  {
645  if ((flags0 & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
646  {
647  if (is_ip4)
648  flags0 = ip4_tcp_udp_validate_checksum (vm, b0);
649  else
650  flags0 = ip6_tcp_udp_icmp_validate_checksum (vm, b0);
651  good_udp0 =
652  (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
653  }
654  }
655 
656  if (is_ip4)
657  {
658  error0 = good_udp0 ? 0 : IP4_ERROR_UDP_CHECKSUM;
659  error0 = (len_diff0 >= 0) ? error0 : IP4_ERROR_UDP_LENGTH;
660  }
661  else
662  {
663  error0 = good_udp0 ? 0 : IP6_ERROR_UDP_CHECKSUM;
664  error0 = (len_diff0 >= 0) ? error0 : IP6_ERROR_UDP_LENGTH;
665  }
666 
667  next0 = error0 ?
669  b0->error = error0 ? error_node->errors[error0] : 0;
670 
671  /* vxlan-input node expect current at VXLAN header */
672  if (is_ip4)
673  vlib_buffer_advance (b0, sizeof(ip4_header_t)+sizeof(udp_header_t));
674  else
675  vlib_buffer_advance (b0, sizeof(ip6_header_t)+sizeof(udp_header_t));
676 
677  exit0:
678  /* Process packet 1 */
679  if (proto1 != IP_PROTOCOL_UDP)
680  goto exit1; /* not UDP packet */
681 
682  if (is_ip4)
683  udp1 = ip4_next_header (ip41);
684  else
685  udp1 = ip6_next_header (ip61);
686 
687  if (udp1->dst_port != clib_host_to_net_u16 (UDP_DST_PORT_vxlan))
688  goto exit1; /* not VXLAN packet */
689 
690  /* Validate DIP against VTEPs*/
691  if (is_ip4)
692  {
693  if (addr4.as_u32 != ip41->dst_address.as_u32)
694  {
695  if (!hash_get (vxm->vtep4, ip41->dst_address.as_u32))
696  goto exit1; /* no local VTEP for VXLAN packet */
697  addr4 = ip41->dst_address;
698  }
699  }
700  else
701  {
702  if (!ip6_address_is_equal (&addr6, &ip61->dst_address))
703  {
704  if (!hash_get_mem (vxm->vtep6, &ip61->dst_address))
705  goto exit1; /* no local VTEP for VXLAN packet */
706  addr6 = ip61->dst_address;
707  }
708  }
709 
710  flags1 = b1->flags;
711  good_udp1 = (flags1 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
712 
713  /* Don't verify UDP checksum for packets with explicit zero checksum. */
714  good_udp1 |= udp1->checksum == 0;
715 
716  /* Verify UDP length */
717  if (is_ip4)
718  ip_len1 = clib_net_to_host_u16 (ip41->length);
719  else
720  ip_len1 = clib_net_to_host_u16 (ip61->payload_length);
721  udp_len1 = clib_net_to_host_u16 (udp1->length);
722  len_diff1 = ip_len1 - udp_len1;
723 
724  /* Verify UDP checksum */
725  if (PREDICT_FALSE (!good_udp1))
726  {
727  if ((flags1 & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
728  {
729  if (is_ip4)
730  flags1 = ip4_tcp_udp_validate_checksum (vm, b1);
731  else
732  flags1 = ip6_tcp_udp_icmp_validate_checksum (vm, b1);
733  good_udp1 =
734  (flags1 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
735  }
736  }
737 
738  if (is_ip4)
739  {
740  error1 = good_udp1 ? 0 : IP4_ERROR_UDP_CHECKSUM;
741  error1 = (len_diff1 >= 0) ? error1 : IP4_ERROR_UDP_LENGTH;
742  }
743  else
744  {
745  error1 = good_udp1 ? 0 : IP6_ERROR_UDP_CHECKSUM;
746  error1 = (len_diff1 >= 0) ? error1 : IP6_ERROR_UDP_LENGTH;
747  }
748 
749  next1 = error1 ?
751  b1->error = error1 ? error_node->errors[error1] : 0;
752 
753  /* vxlan-input node expect current at VXLAN header */
754  if (is_ip4)
755  vlib_buffer_advance (b1, sizeof(ip4_header_t)+sizeof(udp_header_t));
756  else
757  vlib_buffer_advance (b1, sizeof(ip6_header_t)+sizeof(udp_header_t));
758 
759  exit1:
760  vlib_validate_buffer_enqueue_x2 (vm, node, next_index,
761  to_next, n_left_to_next,
762  bi0, bi1, next0, next1);
763  }
764 
765  while (n_left_from > 0 && n_left_to_next > 0)
766  {
767  vlib_buffer_t * b0;
768  ip4_header_t * ip40;
769  ip6_header_t * ip60;
770  udp_header_t * udp0;
771  u32 bi0, ip_len0, udp_len0, flags0, next0;
772  i32 len_diff0;
773  u8 error0, good_udp0, proto0;
774 
775  bi0 = to_next[0] = from[0];
776  from += 1;
777  n_left_from -= 1;
778  to_next += 1;
779  n_left_to_next -= 1;
780 
781  b0 = vlib_get_buffer (vm, bi0);
782  if (is_ip4)
783  ip40 = vlib_buffer_get_current (b0);
784  else
785  ip60 = vlib_buffer_get_current (b0);
786 
787  /* Setup packet for next IP feature */
788  vnet_feature_next(vnet_buffer(b0)->sw_if_index[VLIB_RX], &next0, b0);
789 
790  if (is_ip4)
791  /* Treat IP4 frag packets as "experimental" protocol for now
792  until support of IP frag reassembly is implemented */
793  proto0 = ip4_is_fragment(ip40) ? 0xfe : ip40->protocol;
794  else
795  proto0 = ip60->protocol;
796 
797  if (proto0 != IP_PROTOCOL_UDP)
798  goto exit; /* not UDP packet */
799 
800  if (is_ip4)
801  udp0 = ip4_next_header (ip40);
802  else
803  udp0 = ip6_next_header (ip60);
804 
805  if (udp0->dst_port != clib_host_to_net_u16 (UDP_DST_PORT_vxlan))
806  goto exit; /* not VXLAN packet */
807 
808  /* Validate DIP against VTEPs*/
809  if (is_ip4)
810  {
811  if (addr4.as_u32 != ip40->dst_address.as_u32)
812  {
813  if (!hash_get (vxm->vtep4, ip40->dst_address.as_u32))
814  goto exit; /* no local VTEP for VXLAN packet */
815  addr4 = ip40->dst_address;
816  }
817  }
818  else
819  {
820  if (!ip6_address_is_equal (&addr6, &ip60->dst_address))
821  {
822  if (!hash_get_mem (vxm->vtep6, &ip60->dst_address))
823  goto exit; /* no local VTEP for VXLAN packet */
824  addr6 = ip60->dst_address;
825  }
826  }
827 
828  flags0 = b0->flags;
829  good_udp0 = (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
830 
831  /* Don't verify UDP checksum for packets with explicit zero checksum. */
832  good_udp0 |= udp0->checksum == 0;
833 
834  /* Verify UDP length */
835  if (is_ip4)
836  ip_len0 = clib_net_to_host_u16 (ip40->length);
837  else
838  ip_len0 = clib_net_to_host_u16 (ip60->payload_length);
839  udp_len0 = clib_net_to_host_u16 (udp0->length);
840  len_diff0 = ip_len0 - udp_len0;
841 
842  /* Verify UDP checksum */
843  if (PREDICT_FALSE (!good_udp0))
844  {
845  if ((flags0 & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
846  {
847  if (is_ip4)
848  flags0 = ip4_tcp_udp_validate_checksum (vm, b0);
849  else
850  flags0 = ip6_tcp_udp_icmp_validate_checksum (vm, b0);
851  good_udp0 =
852  (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
853  }
854  }
855 
856  if (is_ip4)
857  {
858  error0 = good_udp0 ? 0 : IP4_ERROR_UDP_CHECKSUM;
859  error0 = (len_diff0 >= 0) ? error0 : IP4_ERROR_UDP_LENGTH;
860  }
861  else
862  {
863  error0 = good_udp0 ? 0 : IP6_ERROR_UDP_CHECKSUM;
864  error0 = (len_diff0 >= 0) ? error0 : IP6_ERROR_UDP_LENGTH;
865  }
866 
867  next0 = error0 ?
869  b0->error = error0 ? error_node->errors[error0] : 0;
870 
871  /* vxlan-input node expect current at VXLAN header */
872  if (is_ip4)
873  vlib_buffer_advance (b0, sizeof(ip4_header_t)+sizeof(udp_header_t));
874  else
875  vlib_buffer_advance (b0, sizeof(ip6_header_t)+sizeof(udp_header_t));
876 
877  exit:
878  vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
879  to_next, n_left_to_next,
880  bi0, next0);
881  }
882 
883  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
884  }
885 
886  return frame->n_vectors;
887 }
888 
889 static uword
891  vlib_node_runtime_t * node,
892  vlib_frame_t * frame)
893 {
894  return ip_vxlan_bypass_inline (vm, node, frame, /* is_ip4 */ 1);
895 }
896 
898  .function = ip4_vxlan_bypass,
899  .name = "ip4-vxlan-bypass",
900  .vector_size = sizeof (u32),
901 
902  .n_next_nodes = IP_VXLAN_BYPASS_N_NEXT,
903  .next_nodes = {
904  [IP_VXLAN_BYPASS_NEXT_DROP] = "error-drop",
905  [IP_VXLAN_BYPASS_NEXT_VXLAN] = "vxlan4-input",
906  },
907 
908  .format_buffer = format_ip4_header,
909  .format_trace = format_ip4_forward_next_trace,
910 };
911 
913 
914 /* Dummy init function to get us linked in. */
916 { return 0; }
917 
919 
920 static uword
922  vlib_node_runtime_t * node,
923  vlib_frame_t * frame)
924 {
925  return ip_vxlan_bypass_inline (vm, node, frame, /* is_ip4 */ 0);
926 }
927 
929  .function = ip6_vxlan_bypass,
930  .name = "ip6-vxlan-bypass",
931  .vector_size = sizeof (u32),
932 
933  .n_next_nodes = IP_VXLAN_BYPASS_N_NEXT,
934  .next_nodes = {
935  [IP_VXLAN_BYPASS_NEXT_DROP] = "error-drop",
936  [IP_VXLAN_BYPASS_NEXT_VXLAN] = "vxlan6-input",
937  },
938 
939  .format_buffer = format_ip6_header,
940  .format_trace = format_ip6_forward_next_trace,
941 };
942 
944 
945 /* Dummy init function to get us linked in. */
947 { return 0; }
948 
950 
951 #define foreach_vxlan_flow_input_next \
952 _(DROP, "error-drop") \
953 _(L2_INPUT, "l2-input")
954 
955 typedef enum
956 {
957 #define _(s,n) VXLAN_FLOW_NEXT_##s,
959 #undef _
962 
963 #define foreach_vxlan_flow_error \
964  _(NONE, "no error") \
965  _(IP_CHECKSUM_ERROR, "Rx ip checksum errors") \
966  _(IP_HEADER_ERROR, "Rx ip header errors") \
967  _(UDP_CHECKSUM_ERROR, "Rx udp checksum errors") \
968  _(UDP_LENGTH_ERROR, "Rx udp length errors")
969 
970 typedef enum
971 {
972 #define _(f,s) VXLAN_FLOW_ERROR_##f,
974 #undef _
977 
978 static char *vxlan_flow_error_strings[] = {
979 #define _(n,s) s,
981 #undef _
982 };
983 
984 
987 {
988  u32 flags = b->flags;
989  enum { offset = sizeof(ip4_header_t) + sizeof(udp_header_t) + sizeof(vxlan_header_t), };
990 
991  /* Verify UDP checksum */
992  if ((flags & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
993  {
995  flags = ip4_tcp_udp_validate_checksum (vm, b);
997  }
998 
999  return (flags & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
1000 }
1001 
1004 {
1005  ip4_vxlan_header_t * hdr = vlib_buffer_get_current(b) - sizeof *hdr;
1006  udp_header_t * udp = &hdr->udp;
1007  /* Don't verify UDP checksum for packets with explicit zero checksum. */
1008  u8 good_csum = (b->flags & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0 ||
1009  udp->checksum == 0;
1010 
1011  return !good_csum;
1012 }
1013 
1016 {
1017  ip4_vxlan_header_t * hdr = vlib_buffer_get_current(b) - sizeof *hdr;
1018  u16 ip_len = clib_net_to_host_u16 (hdr->ip4.length);
1019  u16 expected = payload_len + sizeof *hdr;
1020  return ip_len > expected || hdr->ip4.ttl == 0 || hdr->ip4.ip_version_and_header_length != 0x45;
1021 }
1022 
1025 {
1026  ip4_vxlan_header_t * hdr = vlib_buffer_get_current(b) - sizeof *hdr;
1027  u16 ip_len = clib_net_to_host_u16 (hdr->ip4.length);
1028  u16 udp_len = clib_net_to_host_u16 (hdr->udp.length);
1029  return udp_len > ip_len;
1030 }
1031 
1033 vxlan_err_code (u8 ip_err0, u8 udp_err0, u8 csum_err0)
1034 {
1035  u8 error0 = VXLAN_FLOW_ERROR_NONE;
1036  if (ip_err0)
1037  error0 = VXLAN_FLOW_ERROR_IP_HEADER_ERROR;
1038  if (udp_err0)
1039  error0 = VXLAN_FLOW_ERROR_UDP_LENGTH_ERROR;
1040  if (csum_err0)
1041  error0 = VXLAN_FLOW_ERROR_UDP_CHECKSUM_ERROR;
1042  return error0;
1043 }
1044 
1046  vlib_node_runtime_t * node,
1047  vlib_frame_t * f)
1048 {
1049  enum { payload_offset = sizeof(ip4_vxlan_header_t) };
1050 
1051  vxlan_main_t * vxm = &vxlan_main;
1054  [VXLAN_FLOW_NEXT_DROP] = im->combined_sw_if_counters + VNET_INTERFACE_COUNTER_DROP,
1055  [VXLAN_FLOW_NEXT_L2_INPUT] = im->combined_sw_if_counters + VNET_INTERFACE_COUNTER_RX,
1056  };
1057  u32 thread_index = vlib_get_thread_index();
1058 
1059  u32 * from = vlib_frame_vector_args (f);
1060  u32 n_left_from = f->n_vectors;
1061  u32 next_index = VXLAN_FLOW_NEXT_L2_INPUT;
1062 
1063  while (n_left_from > 0)
1064  {
1065  u32 n_left_to_next, *to_next;
1066 
1067  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
1068 
1069  while (n_left_from > 3 && n_left_to_next > 3)
1070  {
1071  u32 bi0 = to_next[0] = from[0];
1072  u32 bi1 = to_next[1] = from[1];
1073  u32 bi2 = to_next[2] = from[2];
1074  u32 bi3 = to_next[3] = from[3];
1075  from+=4;
1076  n_left_from-=4;
1077  to_next+=4;
1078  n_left_to_next-=4;
1079 
1080  vlib_buffer_t * b0 = vlib_get_buffer (vm, bi0);
1081  vlib_buffer_t * b1 = vlib_get_buffer (vm, bi1);
1082  vlib_buffer_t * b2 = vlib_get_buffer (vm, bi2);
1083  vlib_buffer_t * b3 = vlib_get_buffer (vm, bi3);
1084 
1085  vlib_buffer_advance (b0, payload_offset);
1086  vlib_buffer_advance (b1, payload_offset);
1087  vlib_buffer_advance (b2, payload_offset);
1088  vlib_buffer_advance (b3, payload_offset);
1089 
1090  u16 len0 = vlib_buffer_length_in_chain (vm, b0);
1091  u16 len1 = vlib_buffer_length_in_chain (vm, b1);
1092  u16 len2 = vlib_buffer_length_in_chain (vm, b2);
1093  u16 len3 = vlib_buffer_length_in_chain (vm, b3);
1094 
1095  u32 next0 = VXLAN_FLOW_NEXT_L2_INPUT, next1 = VXLAN_FLOW_NEXT_L2_INPUT,
1096  next2 = VXLAN_FLOW_NEXT_L2_INPUT, next3 = VXLAN_FLOW_NEXT_L2_INPUT;
1097 
1098  u8 ip_err0 = vxlan_check_ip (b0, len0);
1099  u8 ip_err1 = vxlan_check_ip (b1, len1);
1100  u8 ip_err2 = vxlan_check_ip (b2, len2);
1101  u8 ip_err3 = vxlan_check_ip (b3, len3);
1102  u8 ip_err = ip_err0 | ip_err1 | ip_err2 | ip_err3;
1103 
1104  u8 udp_err0 = vxlan_check_ip_udp_len (b0);
1105  u8 udp_err1 = vxlan_check_ip_udp_len (b1);
1106  u8 udp_err2 = vxlan_check_ip_udp_len (b2);
1107  u8 udp_err3 = vxlan_check_ip_udp_len (b3);
1108  u8 udp_err = udp_err0 | udp_err1 | udp_err2 | udp_err3;
1109 
1110  u8 csum_err0 = vxlan_check_udp_csum (vm, b0);
1111  u8 csum_err1 = vxlan_check_udp_csum (vm, b1);
1112  u8 csum_err2 = vxlan_check_udp_csum (vm, b2);
1113  u8 csum_err3 = vxlan_check_udp_csum (vm, b3);
1114  u8 csum_err = csum_err0 | csum_err1 | csum_err2 | csum_err3;
1115 
1116  if (PREDICT_FALSE(csum_err))
1117  {
1118  if (csum_err0)
1119  csum_err0 = !vxlan_validate_udp_csum (vm, b0);
1120  if (csum_err1)
1121  csum_err1 = !vxlan_validate_udp_csum (vm, b1);
1122  if (csum_err2)
1123  csum_err2 = !vxlan_validate_udp_csum (vm, b2);
1124  if (csum_err3)
1125  csum_err3 = !vxlan_validate_udp_csum (vm, b3);
1126  csum_err = csum_err0 | csum_err1 | csum_err2 | csum_err3;
1127  }
1128 
1129  if (PREDICT_FALSE(ip_err || udp_err || csum_err))
1130  {
1131  if (ip_err0 || udp_err0 || csum_err0)
1132  {
1133  next0 = VXLAN_FLOW_NEXT_DROP;
1134  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1135  b0->error = node->errors[error0];
1136  }
1137  if (ip_err1 || udp_err1 || csum_err1)
1138  {
1139  next1 = VXLAN_FLOW_NEXT_DROP;
1140  u8 error1 = vxlan_err_code (ip_err1, udp_err1, csum_err1);
1141  b1->error = node->errors[error1];
1142  }
1143  if (ip_err2 || udp_err2 || csum_err2)
1144  {
1145  next2 = VXLAN_FLOW_NEXT_DROP;
1146  u8 error2 = vxlan_err_code (ip_err2, udp_err2, csum_err2);
1147  b2->error = node->errors[error2];
1148  }
1149  if (ip_err3 || udp_err3 || csum_err3)
1150  {
1151  next3 = VXLAN_FLOW_NEXT_DROP;
1152  u8 error3 = vxlan_err_code (ip_err3, udp_err3, csum_err3);
1153  b3->error = node->errors[error3];
1154  }
1155  }
1156 
1157  vnet_update_l2_len (b0);
1158  vnet_update_l2_len (b1);
1159  vnet_update_l2_len (b2);
1160  vnet_update_l2_len (b3);
1161 
1162  ASSERT (b0->flow_id != 0);
1163  ASSERT (b1->flow_id != 0);
1164  ASSERT (b2->flow_id != 0);
1165  ASSERT (b3->flow_id != 0);
1166 
1167  u32 t_index0 = b0->flow_id - vxm->flow_id_start;
1168  u32 t_index1 = b1->flow_id - vxm->flow_id_start;
1169  u32 t_index2 = b2->flow_id - vxm->flow_id_start;
1170  u32 t_index3 = b3->flow_id - vxm->flow_id_start;
1171 
1172  vxlan_tunnel_t * t0 = &vxm->tunnels[t_index0];
1173  vxlan_tunnel_t * t1 = &vxm->tunnels[t_index1];
1174  vxlan_tunnel_t * t2 = &vxm->tunnels[t_index2];
1175  vxlan_tunnel_t * t3 = &vxm->tunnels[t_index3];
1176 
1177  /* flow id consumed */
1178  b0->flow_id = 0;
1179  b1->flow_id = 0;
1180  b2->flow_id = 0;
1181  b3->flow_id = 0;
1182 
1183  u32 sw_if_index0 = vnet_buffer (b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
1184  u32 sw_if_index1 = vnet_buffer (b1)->sw_if_index[VLIB_RX] = t1->sw_if_index;
1185  u32 sw_if_index2 = vnet_buffer (b2)->sw_if_index[VLIB_RX] = t2->sw_if_index;
1186  u32 sw_if_index3 = vnet_buffer (b3)->sw_if_index[VLIB_RX] = t3->sw_if_index;
1187 
1188  vlib_increment_combined_counter (rx_counter[next0], thread_index, sw_if_index0, 1, len0);
1189  vlib_increment_combined_counter (rx_counter[next1], thread_index, sw_if_index1, 1, len1);
1190  vlib_increment_combined_counter (rx_counter[next2], thread_index, sw_if_index2, 1, len2);
1191  vlib_increment_combined_counter (rx_counter[next3], thread_index, sw_if_index3, 1, len3);
1192 
1193  u32 flags = b0->flags | b1->flags | b2->flags | b3->flags;
1194 
1195  if (PREDICT_FALSE(flags & VLIB_BUFFER_IS_TRACED))
1196  {
1197  if (b0->flags & VLIB_BUFFER_IS_TRACED)
1198  {
1199  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b0, sizeof *tr);
1200  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1201  *tr = (vxlan_rx_trace_t) {
1202  .next_index = next0, .error = error0, .tunnel_index = t_index0, .vni = t0->vni };
1203  }
1204  if (b1->flags & VLIB_BUFFER_IS_TRACED)
1205  {
1206  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b1, sizeof *tr);
1207  u8 error1 = vxlan_err_code (ip_err1, udp_err1, csum_err1);
1208  *tr = (vxlan_rx_trace_t) {
1209  .next_index = next1, .error = error1, .tunnel_index = t_index1, .vni = t1->vni };
1210  }
1211  if (b2->flags & VLIB_BUFFER_IS_TRACED)
1212  {
1213  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b2, sizeof *tr);
1214  u8 error2 = vxlan_err_code (ip_err2, udp_err2, csum_err2);
1215  *tr = (vxlan_rx_trace_t) {
1216  .next_index = next2, .error = error2, .tunnel_index = t_index2, .vni = t2->vni };
1217  }
1218  if (b3->flags & VLIB_BUFFER_IS_TRACED)
1219  {
1220  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b3, sizeof *tr);
1221  u8 error3 = vxlan_err_code (ip_err3, udp_err3, csum_err3);
1222  *tr = (vxlan_rx_trace_t) {
1223  .next_index = next3, .error = error3, .tunnel_index = t_index3, .vni = t3->vni };
1224  }
1225  }
1227  (vm, node, next_index, to_next, n_left_to_next,
1228  bi0, bi1, bi2, bi3, next0, next1, next2, next3);
1229  }
1230  while (n_left_from > 0 && n_left_to_next > 0)
1231  {
1232  u32 bi0 = to_next[0] = from[0];
1233  from++;
1234  n_left_from--;
1235  to_next++;
1236  n_left_to_next--;
1237 
1238  vlib_buffer_t * b0 = vlib_get_buffer (vm, bi0);
1239  vlib_buffer_advance (b0, payload_offset);
1240 
1241  u16 len0 = vlib_buffer_length_in_chain (vm, b0);
1242  u32 next0 = VXLAN_FLOW_NEXT_L2_INPUT;
1243 
1244  u8 ip_err0 = vxlan_check_ip (b0, len0);
1245  u8 udp_err0 = vxlan_check_ip_udp_len (b0);
1246  u8 csum_err0 = vxlan_check_udp_csum (vm, b0);
1247 
1248  if (csum_err0)
1249  csum_err0 = !vxlan_validate_udp_csum (vm, b0);
1250  if (ip_err0 || udp_err0 || csum_err0)
1251  {
1252  next0 = VXLAN_FLOW_NEXT_DROP;
1253  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1254  b0->error = node->errors[error0];
1255  }
1256 
1257  vnet_update_l2_len (b0);
1258 
1259  ASSERT (b0->flow_id != 0);
1260  u32 t_index0 = b0->flow_id - vxm->flow_id_start;
1261  vxlan_tunnel_t * t0 = &vxm->tunnels[t_index0];
1262  b0->flow_id = 0;
1263 
1264  u32 sw_if_index0 = vnet_buffer (b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
1265  vlib_increment_combined_counter (rx_counter[next0], thread_index, sw_if_index0, 1, len0);
1266 
1267  if (PREDICT_FALSE(b0->flags & VLIB_BUFFER_IS_TRACED))
1268  {
1269  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b0, sizeof *tr);
1270  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1271  *tr = (vxlan_rx_trace_t) {
1272  .next_index = next0, .error = error0, .tunnel_index = t_index0, .vni = t0->vni };
1273  }
1274  vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
1275  to_next, n_left_to_next,
1276  bi0, next0);
1277  }
1278 
1279  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
1280  }
1281 
1282  return f->n_vectors;
1283 }
1284 
1285 /* *INDENT-OFF* */
1286 #ifndef CLIB_MULTIARCH_VARIANT
1288  .name = "vxlan-flow-input",
1289  .type = VLIB_NODE_TYPE_INTERNAL,
1290  .vector_size = sizeof (u32),
1291 
1292  .format_trace = format_vxlan_rx_trace,
1293 
1294  .n_errors = VXLAN_FLOW_N_ERROR,
1295  .error_strings = vxlan_flow_error_strings,
1296 
1297  .n_next_nodes = VXLAN_FLOW_N_NEXT,
1298  .next_nodes = {
1299 #define _(s,n) [VXLAN_FLOW_NEXT_##s] = n,
1301 #undef _
1302  },
1303 };
1304 #endif
1305 /* *INDENT-ON* */
static_always_inline u8 vxlan_validate_udp_csum(vlib_main_t *vm, vlib_buffer_t *b)
Definition: decap.c:986
#define foreach_vxlan_flow_error
Definition: decap.c:963
#define CLIB_UNUSED(x)
Definition: clib.h:79
static u32 validate_vxlan_fib(vlib_buffer_t *b, vxlan_tunnel_t *t, u32 is_ip4)
Definition: decap.c:52
static void vlib_increment_combined_counter(vlib_combined_counter_main_t *cm, u32 thread_index, u32 index, u64 n_packets, u64 n_bytes)
Increment a combined counter.
Definition: counter.h:213
ip4_address_t src_address
Definition: ip4_packet.h:169
uword * vtep6
Definition: vxlan.h:151
static char * vxlan_flow_error_strings[]
Definition: decap.c:978
vnet_interface_main_t interface_main
Definition: vnet.h:56
format_function_t format_ip4_header
Definition: format.h:89
vlib_node_registration_t vxlan4_input_node
(constructor) VLIB_REGISTER_NODE (vxlan4_input_node)
Definition: decap.c:22
#define foreach_vxlan_input_next
Definition: vxlan.h:122
#define PREDICT_TRUE(x)
Definition: clib.h:106
u32 flow_id_start
Definition: vxlan.h:165
#define NULL
Definition: clib.h:55
static uword vxlan_input(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *from_frame, u32 is_ip4)
Definition: decap.c:162
#define vlib_validate_buffer_enqueue_x4(vm, node, next_index, to_next, n_left_to_next, bi0, bi1, bi2, bi3, next0, next1, next2, next3)
Finish enqueueing four buffers forward in the graph.
Definition: buffer_node.h:138
vlib_node_registration_t vxlan4_flow_input_node
(constructor) VLIB_REGISTER_NODE (vxlan4_flow_input_node)
Definition: decap.c:1287
u32 * fib_index_by_sw_if_index
Table index indexed by software interface.
Definition: ip4.h:111
u8 * format(u8 *s, const char *fmt,...)
Definition: format.c:419
vlib_node_registration_t ip4_vxlan_bypass_node
(constructor) VLIB_REGISTER_NODE (ip4_vxlan_bypass_node)
Definition: decap.c:897
#define VLIB_NODE_FN(node)
Definition: node.h:173
vlib_error_t * errors
Vector of errors for this node.
Definition: node.h:451
static uword vlib_buffer_length_in_chain(vlib_main_t *vm, vlib_buffer_t *b)
Get length in bytes of the buffer chain.
Definition: buffer_funcs.h:250
ip6_address_t src_address
Definition: ip6_packet.h:347
unsigned char u8
Definition: types.h:56
u32 tunnel_index
Definition: decap.c:74
static uword ip6_vxlan_bypass(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: decap.c:921
#define VXLAN_FLAGS_I
Definition: vxlan_packet.h:52
vnet_main_t * vnet_main
Definition: vxlan.h:161
#define static_always_inline
Definition: clib.h:93
u32 tunnel_index
Definition: decap.c:27
#define VLIB_INIT_FUNCTION(x)
Definition: init.h:156
#define always_inline
Definition: clib.h:92
ip4_address_t dst_address
Definition: ip4_packet.h:169
vlib_combined_counter_main_t * combined_sw_if_counters
Definition: interface.h:810
static uword ip6_address_is_equal(ip6_address_t *a, ip6_address_t *b)
Definition: ip6_packet.h:214
#define vlib_prefetch_buffer_header(b, type)
Prefetch buffer metadata.
Definition: buffer.h:184
static void * ip4_next_header(ip4_header_t *i)
Definition: ip4_packet.h:238
unsigned int u32
Definition: types.h:88
static int ip4_is_fragment(ip4_header_t *i)
Definition: ip4_packet.h:210
#define hash_get(h, key)
Definition: hash.h:249
#define pool_elt_at_index(p, i)
Returns pointer to element at given index.
Definition: pool.h:461
static_always_inline u8 vxlan_check_ip_udp_len(vlib_buffer_t *b)
Definition: decap.c:1024
vlib_node_registration_t ip4_input_node
Global ip4 input node.
Definition: ip4_input.c:316
u32 tunnel_index
Definition: decap.c:68
vxlan6_tunnel_key_t key6
Definition: decap.c:73
uword * vxlan4_tunnel_by_key
Definition: vxlan.h:145
unsigned short u16
Definition: types.h:57
vlib_node_registration_t ip6_vxlan_bypass_node
(constructor) VLIB_REGISTER_NODE (ip6_vxlan_bypass_node)
Definition: decap.c:928
static void * vlib_buffer_get_current(vlib_buffer_t *b)
Get pointer to current data to process.
Definition: buffer.h:202
vxlan_main_t vxlan_main
Definition: vxlan.c:43
static uword ip4_address_is_multicast(ip4_address_t *a)
Definition: ip4_packet.h:315
#define PREDICT_FALSE(x)
Definition: clib.h:105
vnet_main_t vnet_main
Definition: misc.c:43
vxlan4_tunnel_key_t key4
Definition: decap.c:67
u32 ip4_tcp_udp_validate_checksum(vlib_main_t *vm, vlib_buffer_t *p0)
Definition: ip4_forward.c:1113
vlib_node_registration_t vxlan6_input_node
(constructor) VLIB_REGISTER_NODE (vxlan6_input_node)
Definition: decap.c:23
#define vlib_validate_buffer_enqueue_x2(vm, node, next_index, to_next, n_left_to_next, bi0, bi1, next0, next1)
Finish enqueueing two buffers forward in the graph.
Definition: buffer_node.h:70
static_always_inline void vnet_feature_next(u32 sw_if_index, u32 *next0, vlib_buffer_t *b0)
Definition: feature.h:237
#define vlib_validate_buffer_enqueue_x1(vm, node, next_index, to_next, n_left_to_next, bi0, next0)
Finish enqueueing one buffer forward in the graph.
Definition: buffer_node.h:218
#define vlib_get_next_frame(vm, node, next_index, vectors, n_vectors_left)
Get pointer to next frame vector data by (vlib_node_runtime_t, next_index).
Definition: node_funcs.h:364
vlib_error_t error
Error code for buffers to be enqueued to error handler.
Definition: buffer.h:135
static void vlib_node_increment_counter(vlib_main_t *vm, u32 node_index, u32 counter_index, u64 increment)
Definition: node_funcs.h:1168
static vxlan_tunnel_t * vxlan4_find_tunnel(vxlan_main_t *vxm, last_tunnel_cache4 *cache, ip4_header_t *ip4_0, vxlan_header_t *vxlan0, vxlan_tunnel_t **stats_t0)
Definition: decap.c:78
#define VLIB_REGISTER_NODE(x,...)
Definition: node.h:153
static u32 vnet_get_vni(vxlan_header_t *h)
Definition: vxlan_packet.h:54
static uword vxlan4_input(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *from_frame)
Definition: decap.c:432
u32 flow_id
Generic flow identifier.
Definition: buffer.h:123
u16 n_vectors
Definition: node.h:380
static_always_inline uword vlib_get_thread_index(void)
Definition: threads.h:221
#define CLIB_PREFETCH(addr, size, type)
Definition: cache.h:77
vlib_main_t * vm
Definition: buffer.c:294
static void ip6_address_set_zero(ip6_address_t *a)
Definition: ip6_packet.h:249
static_always_inline u8 vxlan_check_udp_csum(vlib_main_t *vm, vlib_buffer_t *b)
Definition: decap.c:1003
static char * vxlan_error_strings[]
Definition: decap.c:447
static vlib_node_runtime_t * vlib_node_get_runtime(vlib_main_t *vm, u32 node_index)
Get node runtime by node index.
Definition: node_funcs.h:89
void vlib_put_next_frame(vlib_main_t *vm, vlib_node_runtime_t *r, u32 next_index, u32 n_vectors_left)
Release pointer to next frame vector data.
Definition: main.c:454
u32 decap_next_index
Definition: vxlan.h:86
static_always_inline u8 vxlan_check_ip(vlib_buffer_t *b, u16 payload_len)
Definition: decap.c:1015
vxlan_flow_input_next_t
Definition: decap.c:955
static void * ip6_next_header(ip6_header_t *i)
Definition: ip6_packet.h:374
ip_vxan_bypass_next_t
Definition: decap.c:864
static vxlan_tunnel_t * vxlan6_find_tunnel(vxlan_main_t *vxm, last_tunnel_cache6 *cache, ip6_header_t *ip6_0, vxlan_header_t *vxlan0, vxlan_tunnel_t **stats_t0)
Definition: decap.c:120
signed int i32
Definition: types.h:81
u16 cached_next_index
Next frame index that vector arguments were last enqueued to last time this node ran.
Definition: node.h:492
vxlan_flow_error_t
Definition: decap.c:970
#define ASSERT(truth)
#define foreach_vxlan_flow_input_next
Definition: decap.c:951
ip6_main_t ip6_main
Definition: ip6_forward.c:2574
uword * vtep4
Definition: vxlan.h:150
uword * vxlan6_tunnel_by_key
Definition: vxlan.h:146
u32 sw_if_index
Definition: vxlan.h:92
static void vlib_buffer_advance(vlib_buffer_t *b, word l)
Advance current data pointer by the supplied (signed!) amount.
Definition: buffer.h:215
format_function_t format_ip6_header
Definition: format.h:103
static void * vlib_add_trace(vlib_main_t *vm, vlib_node_runtime_t *r, vlib_buffer_t *b, u32 n_data_bytes)
Definition: trace_funcs.h:55
#define vec_elt(v, i)
Get vector value at index i.
struct _vlib_node_registration vlib_node_registration_t
template key/value backing page structure
Definition: bihash_doc.h:44
Definition: defs.h:47
static uword ip6_address_is_multicast(ip6_address_t *a)
Definition: ip6_packet.h:151
u16 payload_length
Definition: ip6_packet.h:338
u32 ip6_tcp_udp_icmp_validate_checksum(vlib_main_t *vm, vlib_buffer_t *p0)
Definition: ip6_forward.c:986
static void vnet_update_l2_len(vlib_buffer_t *b)
Definition: l2_input.h:221
void ip4_forward_next_trace(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame, vlib_rx_or_tx_t which_adj_index)
Definition: ip4_forward.c:967
u64 uword
Definition: types.h:112
static void * vlib_frame_vector_args(vlib_frame_t *f)
Get pointer to frame vector data.
Definition: node_funcs.h:267
static_always_inline u8 vxlan_err_code(u8 ip_err0, u8 udp_err0, u8 csum_err0)
Definition: decap.c:1033
u32 encap_fib_index
Definition: vxlan.h:89
u8 * format_ip4_forward_next_trace(u8 *s, va_list *args)
Definition: ip4_forward.c:919
A collection of combined counters.
Definition: counter.h:181
#define hash_get_mem(h, key)
Definition: hash.h:269
#define vnet_buffer(b)
Definition: buffer.h:360
VLIB_NODE_FUNCTION_MULTIARCH(l2t_decap_node, l2t_decap_node_fn)
static u8 * format_vxlan_rx_trace(u8 *s, va_list *args)
Definition: decap.c:32
ip4_main_t ip4_main
Global ip4 main structure.
Definition: ip4_forward.c:832
u8 data[0]
Packet data.
Definition: buffer.h:172
clib_error_t * ip6_vxlan_bypass_init(vlib_main_t *vm)
Definition: decap.c:946
u16 flags
Copy of main node flags.
Definition: node.h:486
#define VLIB_NODE_FLAG_TRACE
Definition: node.h:295
u32 next_index
Definition: decap.c:26
u32 flags
Definition: vhost-user.h:77
#define CLIB_CACHE_LINE_BYTES
Definition: cache.h:62
u32 flags
buffer flags: VLIB_BUFFER_FREE_LIST_INDEX_MASK: bits used to store free list index, VLIB_BUFFER_IS_TRACED: trace this buffer.
Definition: buffer.h:111
static uword ip4_vxlan_bypass(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: decap.c:890
u32 * fib_index_by_sw_if_index
Definition: ip6.h:176
static vlib_buffer_t * vlib_get_buffer(vlib_main_t *vm, u32 buffer_index)
Translate buffer index into buffer pointer.
Definition: buffer_funcs.h:57
vxlan_tunnel_t * tunnels
Definition: vxlan.h:142
static uword ip_vxlan_bypass_inline(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame, u32 is_ip4)
Definition: decap.c:508
ip46_address_t src
Definition: vxlan.h:79
static uword vxlan6_input(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *from_frame)
Definition: decap.c:440
Definition: defs.h:46
ip6_address_t dst_address
Definition: ip6_packet.h:347
clib_error_t * ip4_vxlan_bypass_init(vlib_main_t *vm)
Definition: decap.c:915
u8 * format_ip6_forward_next_trace(u8 *s, va_list *args)
Definition: ip6_forward.c:768