FD.io VPP  v18.07.1-19-g511ce25
Vector Packet Processing
decap.c
Go to the documentation of this file.
1 /*
2  * decap.c: vxlan tunnel decap packet processing
3  *
4  * Copyright (c) 2013 Cisco and/or its affiliates.
5  * Licensed under the Apache License, Version 2.0 (the "License");
6  * you may not use this file except in compliance with the License.
7  * You may obtain a copy of the License at:
8  *
9  * http://www.apache.org/licenses/LICENSE-2.0
10  *
11  * Unless required by applicable law or agreed to in writing, software
12  * distributed under the License is distributed on an "AS IS" BASIS,
13  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14  * See the License for the specific language governing permissions and
15  * limitations under the License.
16  */
17 
18 #include <vlib/vlib.h>
19 #include <vnet/pg/pg.h>
20 #include <vnet/vxlan/vxlan.h>
21 
24 
25 typedef struct {
31 
32 static u8 * format_vxlan_rx_trace (u8 * s, va_list * args)
33 {
34  CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
35  CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
36  vxlan_rx_trace_t * t = va_arg (*args, vxlan_rx_trace_t *);
37 
38  if (t->tunnel_index != ~0)
39  {
40  s = format (s, "VXLAN decap from vxlan_tunnel%d vni %d next %d error %d",
41  t->tunnel_index, t->vni, t->next_index, t->error);
42  }
43  else
44  {
45  s = format (s, "VXLAN decap error - tunnel for vni %d does not exist",
46  t->vni);
47  }
48  return s;
49 }
50 
53 {
54  u32 sw_if_index = vnet_buffer (b)->sw_if_index[VLIB_TX];
55  if (sw_if_index != (u32) ~ 0)
56  return sw_if_index;
57 
58  u32 * fib_index_by_sw_if_index = is_ip4 ?
60  sw_if_index = vnet_buffer (b)->sw_if_index[VLIB_RX];
61 
62  return vec_elt (fib_index_by_sw_if_index, sw_if_index);
63 }
64 
66 
69  u32 fib_index, ip4_header_t * ip4_0, vxlan_header_t * vxlan0,
70  vxlan_tunnel_t ** stats_t0)
71 {
72  /* Make sure VXLAN tunnel exist according to packet SIP and VNI */
73  vxlan4_tunnel_key_t key4 = {
74  .key = {
75  [0] = ip4_0->src_address.as_u32,
76  [1] = (((u64) fib_index) << 32) | vxlan0->vni_reserved,
77  }
78  };
79 
80  if (PREDICT_FALSE (clib_bihash_key_compare_16_8 (key4.key, cache->key) == 0))
81  {
82  int rv = clib_bihash_search_inline_16_8 (&vxm->vxlan4_tunnel_by_key, &key4);
83  if (PREDICT_FALSE (rv != 0))
84  return 0;
85 
86  *cache = key4;
87  }
88  vxlan_tunnel_t * t0 = pool_elt_at_index (vxm->tunnels, cache->value);
89 
90  /* Validate VXLAN tunnel SIP against packet DIP */
91  if (PREDICT_TRUE (ip4_0->dst_address.as_u32 == t0->src.ip4.as_u32))
92  *stats_t0 = t0;
93  else
94  {
95  /* try multicast */
97  return 0;
98 
99  key4.key[0] = ip4_0->dst_address.as_u32;
100  /* Make sure mcast VXLAN tunnel exist by packet DIP and VNI */
101  int rv = clib_bihash_search_inline_16_8 (&vxm->vxlan4_tunnel_by_key, &key4);
102  if (PREDICT_FALSE (rv != 0))
103  return 0;
104 
105  *stats_t0 = pool_elt_at_index (vxm->tunnels, key4.value);
106  }
107 
108  return t0;
109 }
110 
112 
115  u32 fib_index, ip6_header_t * ip6_0, vxlan_header_t * vxlan0,
116  vxlan_tunnel_t ** stats_t0)
117 {
118  /* Make sure VXLAN tunnel exist according to packet SIP and VNI */
119 
120  vxlan6_tunnel_key_t key6 = {
121  .key = {
122  [0] = ip6_0->src_address.as_u64[0],
123  [1] = ip6_0->src_address.as_u64[1],
124  [2] = (((u64) fib_index) << 32) | vxlan0->vni_reserved,
125  }
126  };
127 
128  if (PREDICT_FALSE (clib_bihash_key_compare_24_8 (key6.key, cache->key) == 0))
129  {
130  int rv = clib_bihash_search_inline_24_8 (&vxm->vxlan6_tunnel_by_key, &key6);
131  if (PREDICT_FALSE (rv != 0))
132  return 0;
133 
134  *cache = key6;
135  }
136  vxlan_tunnel_t * t0 = pool_elt_at_index (vxm->tunnels, cache->value);
137 
138  /* Validate VXLAN tunnel SIP against packet DIP */
139  if (PREDICT_TRUE (ip6_address_is_equal (&ip6_0->dst_address, &t0->src.ip6)))
140  *stats_t0 = t0;
141  else
142  {
143  /* try multicast */
145  return 0;
146 
147  /* Make sure mcast VXLAN tunnel exist by packet DIP and VNI */
148  key6.key[0] = ip6_0->dst_address.as_u64[0];
149  key6.key[1] = ip6_0->dst_address.as_u64[1];
150  int rv = clib_bihash_search_inline_24_8 (&vxm->vxlan6_tunnel_by_key, &key6);
151  if (PREDICT_FALSE (rv != 0))
152  return 0;
153 
154  *stats_t0 = pool_elt_at_index (vxm->tunnels, key6.value);
155  }
156 
157  return t0;
158 }
159 
162  vlib_node_runtime_t * node,
163  vlib_frame_t * from_frame,
164  u32 is_ip4)
165 {
166  vxlan_main_t * vxm = &vxlan_main;
167  vnet_main_t * vnm = vxm->vnet_main;
171  last_tunnel_cache4 last4;
172  last_tunnel_cache6 last6;
173  u32 pkts_decapsulated = 0;
174  u32 thread_index = vlib_get_thread_index();
175 
176  if (is_ip4)
177  memset (&last4, 0xff, sizeof last4);
178  else
179  memset (&last6, 0xff, sizeof last6);
180 
181  u32 next_index = node->cached_next_index;
182 
183  u32 * from = vlib_frame_vector_args (from_frame);
184  u32 n_left_from = from_frame->n_vectors;
185 
186  while (n_left_from > 0)
187  {
188  u32 * to_next, n_left_to_next;
189  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
190 
191  while (n_left_from >= 4 && n_left_to_next >= 2)
192  {
193  /* Prefetch next iteration. */
194  {
195  vlib_buffer_t * p2, * p3;
196 
197  p2 = vlib_get_buffer (vm, from[2]);
198  p3 = vlib_get_buffer (vm, from[3]);
199 
200  vlib_prefetch_buffer_header (p2, LOAD);
201  vlib_prefetch_buffer_header (p3, LOAD);
202 
205  }
206 
207  u32 bi0 = to_next[0] = from[0];
208  u32 bi1 = to_next[1] = from[1];
209  from += 2;
210  to_next += 2;
211  n_left_to_next -= 2;
212  n_left_from -= 2;
213 
214  vlib_buffer_t * b0, * b1;
215  b0 = vlib_get_buffer (vm, bi0);
216  b1 = vlib_get_buffer (vm, bi1);
217 
218  /* udp leaves current_data pointing at the vxlan header */
219  void * cur0 = vlib_buffer_get_current (b0);
220  void * cur1 = vlib_buffer_get_current (b1);
221  vxlan_header_t * vxlan0 = cur0;
222  vxlan_header_t * vxlan1 = cur1;
223 
224  ip4_header_t * ip4_0, * ip4_1;
225  ip6_header_t * ip6_0, * ip6_1;
226  if (is_ip4) {
227  ip4_0 = cur0 - sizeof(udp_header_t) - sizeof(ip4_header_t);
228  ip4_1 = cur1 - sizeof(udp_header_t) - sizeof(ip4_header_t);
229  } else {
230  ip6_0 = cur0 - sizeof(udp_header_t) - sizeof(ip6_header_t);
231  ip6_1 = cur1 - sizeof(udp_header_t) - sizeof(ip6_header_t);
232  }
233 
234  /* pop vxlan */
235  vlib_buffer_advance (b0, sizeof *vxlan0);
236  vlib_buffer_advance (b1, sizeof *vxlan1);
237 
238  u32 fi0 = buf_fib_index(b0, is_ip4);
239  u32 fi1 = buf_fib_index(b1, is_ip4);
240 
241  vxlan_tunnel_t * t0, * stats_t0;
242  vxlan_tunnel_t * t1, * stats_t1;
243  if (is_ip4)
244  {
245  t0 = vxlan4_find_tunnel (vxm, &last4, fi0, ip4_0, vxlan0, &stats_t0);
246  t1 = vxlan4_find_tunnel (vxm, &last4, fi1, ip4_1, vxlan1, &stats_t1);
247  }
248  else
249  {
250  t0 = vxlan6_find_tunnel (vxm, &last6, fi0, ip6_0, vxlan0, &stats_t0);
251  t1 = vxlan6_find_tunnel (vxm, &last6, fi1, ip6_1, vxlan1, &stats_t1);
252  }
253 
254  u32 len0 = vlib_buffer_length_in_chain (vm, b0);
255  u32 len1 = vlib_buffer_length_in_chain (vm, b1);
256 
257  u32 next0, next1;
258  u8 error0 = 0, error1 = 0;
259  /* Validate VXLAN tunnel encap-fib index agaist packet */
260  if (PREDICT_FALSE (t0 == 0 || vxlan0->flags != VXLAN_FLAGS_I))
261  {
262  next0 = VXLAN_INPUT_NEXT_DROP;
263 
264  if (t0 != 0 && vxlan0->flags != VXLAN_FLAGS_I)
265  {
266  error0 = VXLAN_ERROR_BAD_FLAGS;
268  (drop_counter, thread_index, stats_t0->sw_if_index, 1, len0);
269  }
270  else
271  error0 = VXLAN_ERROR_NO_SUCH_TUNNEL;
272  b0->error = node->errors[error0];
273  }
274  else
275  {
276  next0 = t0->decap_next_index;
277 
278  /* Required to make the l2 tag push / pop code work on l2 subifs */
279  if (PREDICT_TRUE(next0 == VXLAN_INPUT_NEXT_L2_INPUT))
280  vnet_update_l2_len (b0);
281 
282  /* Set packet input sw_if_index to unicast VXLAN tunnel for learning */
283  vnet_buffer(b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
285  (rx_counter, thread_index, stats_t0->sw_if_index, 1, len0);
286  pkts_decapsulated++;
287  }
288 
289  /* Validate VXLAN tunnel encap-fib index agaist packet */
290  if (PREDICT_FALSE (t1 == 0 || vxlan1->flags != VXLAN_FLAGS_I))
291  {
292  next1 = VXLAN_INPUT_NEXT_DROP;
293 
294  if (t1 != 0 && vxlan1->flags != VXLAN_FLAGS_I)
295  {
296  error1 = VXLAN_ERROR_BAD_FLAGS;
298  (drop_counter, thread_index, stats_t1->sw_if_index, 1, len1);
299  }
300  else
301  error1 = VXLAN_ERROR_NO_SUCH_TUNNEL;
302  b1->error = node->errors[error1];
303  }
304  else
305  {
306  next1 = t1->decap_next_index;
307 
308  /* Required to make the l2 tag push / pop code work on l2 subifs */
309  if (PREDICT_TRUE(next1 == VXLAN_INPUT_NEXT_L2_INPUT))
310  vnet_update_l2_len (b1);
311 
312  /* Set packet input sw_if_index to unicast VXLAN tunnel for learning */
313  vnet_buffer(b1)->sw_if_index[VLIB_RX] = t1->sw_if_index;
314  pkts_decapsulated++;
315 
317  (rx_counter, thread_index, stats_t1->sw_if_index, 1, len1);
318  }
319 
320  if (PREDICT_FALSE(b0->flags & VLIB_BUFFER_IS_TRACED))
321  {
322  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b0, sizeof (*tr));
323  tr->next_index = next0;
324  tr->error = error0;
325  tr->tunnel_index = t0 == 0 ? ~0 : t0 - vxm->tunnels;
326  tr->vni = vnet_get_vni (vxlan0);
327  }
328  if (PREDICT_FALSE(b1->flags & VLIB_BUFFER_IS_TRACED))
329  {
330  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b1, sizeof (*tr));
331  tr->next_index = next1;
332  tr->error = error1;
333  tr->tunnel_index = t1 == 0 ? ~0 : t1 - vxm->tunnels;
334  tr->vni = vnet_get_vni (vxlan1);
335  }
336 
337  vlib_validate_buffer_enqueue_x2 (vm, node, next_index,
338  to_next, n_left_to_next,
339  bi0, bi1, next0, next1);
340  }
341 
342  while (n_left_from > 0 && n_left_to_next > 0)
343  {
344  u32 bi0 = to_next[0] = from[0];
345  from += 1;
346  to_next += 1;
347  n_left_from -= 1;
348  n_left_to_next -= 1;
349 
350  vlib_buffer_t * b0 = vlib_get_buffer (vm, bi0);
351 
352  /* udp leaves current_data pointing at the vxlan header */
353  void * cur0 = vlib_buffer_get_current (b0);
354  vxlan_header_t * vxlan0 = cur0;
355  ip4_header_t * ip4_0;
356  ip6_header_t * ip6_0;
357  if (is_ip4)
358  ip4_0 = cur0 -sizeof(udp_header_t) - sizeof(ip4_header_t);
359  else
360  ip6_0 = cur0 -sizeof(udp_header_t) - sizeof(ip6_header_t);
361 
362  /* pop (ip, udp, vxlan) */
363  vlib_buffer_advance (b0, sizeof(*vxlan0));
364 
365  u32 fi0 = buf_fib_index(b0, is_ip4);
366 
367  vxlan_tunnel_t * t0, * stats_t0;
368  if (is_ip4)
369  t0 = vxlan4_find_tunnel (vxm, &last4, fi0, ip4_0, vxlan0, &stats_t0);
370  else
371  t0 = vxlan6_find_tunnel (vxm, &last6, fi0, ip6_0, vxlan0, &stats_t0);
372 
373  uword len0 = vlib_buffer_length_in_chain (vm, b0);
374 
375  u32 next0;
376  u8 error0 = 0;
377  /* Validate VXLAN tunnel encap-fib index agaist packet */
378  if (PREDICT_FALSE (t0 == 0 || vxlan0->flags != VXLAN_FLAGS_I))
379  {
380  next0 = VXLAN_INPUT_NEXT_DROP;
381 
382  if (t0 != 0 && vxlan0->flags != VXLAN_FLAGS_I)
383  {
384  error0 = VXLAN_ERROR_BAD_FLAGS;
386  (drop_counter, thread_index, stats_t0->sw_if_index, 1, len0);
387  }
388  else
389  error0 = VXLAN_ERROR_NO_SUCH_TUNNEL;
390  b0->error = node->errors[error0];
391  }
392  else
393  {
394  next0 = t0->decap_next_index;
395 
396  /* Required to make the l2 tag push / pop code work on l2 subifs */
397  if (PREDICT_TRUE(next0 == VXLAN_INPUT_NEXT_L2_INPUT))
398  vnet_update_l2_len (b0);
399 
400  /* Set packet input sw_if_index to unicast VXLAN tunnel for learning */
401  vnet_buffer(b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
402  pkts_decapsulated++;
403 
405  (rx_counter, thread_index, stats_t0->sw_if_index, 1, len0);
406  }
407 
408  if (PREDICT_FALSE(b0->flags & VLIB_BUFFER_IS_TRACED))
409  {
410  vxlan_rx_trace_t *tr
411  = vlib_add_trace (vm, node, b0, sizeof (*tr));
412  tr->next_index = next0;
413  tr->error = error0;
414  tr->tunnel_index = t0 == 0 ? ~0 : t0 - vxm->tunnels;
415  tr->vni = vnet_get_vni (vxlan0);
416  }
417  vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
418  to_next, n_left_to_next,
419  bi0, next0);
420  }
421 
422  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
423  }
424  /* Do we still need this now that tunnel tx stats is kept? */
425  u32 node_idx = is_ip4 ? vxlan4_input_node.index : vxlan6_input_node.index;
426  vlib_node_increment_counter (vm, node_idx, VXLAN_ERROR_DECAPSULATED,
427  pkts_decapsulated);
428 
429  return from_frame->n_vectors;
430 }
431 
432 static uword
434  vlib_node_runtime_t * node,
435  vlib_frame_t * from_frame)
436 {
437  return vxlan_input(vm, node, from_frame, /* is_ip4 */ 1);
438 }
439 
440 static uword
442  vlib_node_runtime_t * node,
443  vlib_frame_t * from_frame)
444 {
445  return vxlan_input(vm, node, from_frame, /* is_ip4 */ 0);
446 }
447 
448 static char * vxlan_error_strings[] = {
449 #define vxlan_error(n,s) s,
451 #undef vxlan_error
452 #undef _
453 };
454 
456  .function = vxlan4_input,
457  .name = "vxlan4-input",
458  /* Takes a vector of packets. */
459  .vector_size = sizeof (u32),
460 
461  .n_errors = VXLAN_N_ERROR,
462  .error_strings = vxlan_error_strings,
463 
464  .n_next_nodes = VXLAN_INPUT_N_NEXT,
465  .next_nodes = {
466 #define _(s,n) [VXLAN_INPUT_NEXT_##s] = n,
468 #undef _
469  },
470 
471 //temp .format_buffer = format_vxlan_header,
472  .format_trace = format_vxlan_rx_trace,
473  // $$$$ .unformat_buffer = unformat_vxlan_header,
474 };
475 
477 
479  .function = vxlan6_input,
480  .name = "vxlan6-input",
481  /* Takes a vector of packets. */
482  .vector_size = sizeof (u32),
483 
484  .n_errors = VXLAN_N_ERROR,
485  .error_strings = vxlan_error_strings,
486 
487  .n_next_nodes = VXLAN_INPUT_N_NEXT,
488  .next_nodes = {
489 #define _(s,n) [VXLAN_INPUT_NEXT_##s] = n,
491 #undef _
492  },
493 
494 //temp .format_buffer = format_vxlan_header,
495  .format_trace = format_vxlan_rx_trace,
496  // $$$$ .unformat_buffer = unformat_vxlan_header,
497 };
498 
500 
501 
502 typedef enum {
507 
510  vlib_node_runtime_t * node,
511  vlib_frame_t * frame,
512  u32 is_ip4)
513 {
514  vxlan_main_t * vxm = &vxlan_main;
515  u32 * from, * to_next, n_left_from, n_left_to_next, next_index;
516  vlib_node_runtime_t * error_node = vlib_node_get_runtime (vm, ip4_input_node.index);
517  ip4_address_t addr4; /* last IPv4 address matching a local VTEP address */
518  ip6_address_t addr6; /* last IPv6 address matching a local VTEP address */
519 
520  from = vlib_frame_vector_args (frame);
521  n_left_from = frame->n_vectors;
522  next_index = node->cached_next_index;
523 
524  if (node->flags & VLIB_NODE_FLAG_TRACE)
525  ip4_forward_next_trace (vm, node, frame, VLIB_TX);
526 
527  if (is_ip4) addr4.data_u32 = ~0;
528  else ip6_address_set_zero (&addr6);
529 
530  while (n_left_from > 0)
531  {
532  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
533 
534  while (n_left_from >= 4 && n_left_to_next >= 2)
535  {
536  vlib_buffer_t * b0, * b1;
537  ip4_header_t * ip40, * ip41;
538  ip6_header_t * ip60, * ip61;
539  udp_header_t * udp0, * udp1;
540  u32 bi0, ip_len0, udp_len0, flags0, next0;
541  u32 bi1, ip_len1, udp_len1, flags1, next1;
542  i32 len_diff0, len_diff1;
543  u8 error0, good_udp0, proto0;
544  u8 error1, good_udp1, proto1;
545 
546  /* Prefetch next iteration. */
547  {
548  vlib_buffer_t * p2, * p3;
549 
550  p2 = vlib_get_buffer (vm, from[2]);
551  p3 = vlib_get_buffer (vm, from[3]);
552 
553  vlib_prefetch_buffer_header (p2, LOAD);
554  vlib_prefetch_buffer_header (p3, LOAD);
555 
558  }
559 
560  bi0 = to_next[0] = from[0];
561  bi1 = to_next[1] = from[1];
562  from += 2;
563  n_left_from -= 2;
564  to_next += 2;
565  n_left_to_next -= 2;
566 
567  b0 = vlib_get_buffer (vm, bi0);
568  b1 = vlib_get_buffer (vm, bi1);
569  if (is_ip4)
570  {
571  ip40 = vlib_buffer_get_current (b0);
572  ip41 = vlib_buffer_get_current (b1);
573  }
574  else
575  {
576  ip60 = vlib_buffer_get_current (b0);
577  ip61 = vlib_buffer_get_current (b1);
578  }
579 
580  /* Setup packet for next IP feature */
581  vnet_feature_next(vnet_buffer(b0)->sw_if_index[VLIB_RX], &next0, b0);
582  vnet_feature_next(vnet_buffer(b1)->sw_if_index[VLIB_RX], &next1, b1);
583 
584  if (is_ip4)
585  {
586  /* Treat IP frag packets as "experimental" protocol for now
587  until support of IP frag reassembly is implemented */
588  proto0 = ip4_is_fragment(ip40) ? 0xfe : ip40->protocol;
589  proto1 = ip4_is_fragment(ip41) ? 0xfe : ip41->protocol;
590  }
591  else
592  {
593  proto0 = ip60->protocol;
594  proto1 = ip61->protocol;
595  }
596 
597  /* Process packet 0 */
598  if (proto0 != IP_PROTOCOL_UDP)
599  goto exit0; /* not UDP packet */
600 
601  if (is_ip4)
602  udp0 = ip4_next_header (ip40);
603  else
604  udp0 = ip6_next_header (ip60);
605 
606  if (udp0->dst_port != clib_host_to_net_u16 (UDP_DST_PORT_vxlan))
607  goto exit0; /* not VXLAN packet */
608 
609  /* Validate DIP against VTEPs*/
610  if (is_ip4)
611  {
612  if (addr4.as_u32 != ip40->dst_address.as_u32)
613  {
614  if (!hash_get (vxm->vtep4, ip40->dst_address.as_u32))
615  goto exit0; /* no local VTEP for VXLAN packet */
616  addr4 = ip40->dst_address;
617  }
618  }
619  else
620  {
621  if (!ip6_address_is_equal (&addr6, &ip60->dst_address))
622  {
623  if (!hash_get_mem (vxm->vtep6, &ip60->dst_address))
624  goto exit0; /* no local VTEP for VXLAN packet */
625  addr6 = ip60->dst_address;
626  }
627  }
628 
629  flags0 = b0->flags;
630  good_udp0 = (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
631 
632  /* Don't verify UDP checksum for packets with explicit zero checksum. */
633  good_udp0 |= udp0->checksum == 0;
634 
635  /* Verify UDP length */
636  if (is_ip4)
637  ip_len0 = clib_net_to_host_u16 (ip40->length);
638  else
639  ip_len0 = clib_net_to_host_u16 (ip60->payload_length);
640  udp_len0 = clib_net_to_host_u16 (udp0->length);
641  len_diff0 = ip_len0 - udp_len0;
642 
643  /* Verify UDP checksum */
644  if (PREDICT_FALSE (!good_udp0))
645  {
646  if ((flags0 & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
647  {
648  if (is_ip4)
649  flags0 = ip4_tcp_udp_validate_checksum (vm, b0);
650  else
651  flags0 = ip6_tcp_udp_icmp_validate_checksum (vm, b0);
652  good_udp0 =
653  (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
654  }
655  }
656 
657  if (is_ip4)
658  {
659  error0 = good_udp0 ? 0 : IP4_ERROR_UDP_CHECKSUM;
660  error0 = (len_diff0 >= 0) ? error0 : IP4_ERROR_UDP_LENGTH;
661  }
662  else
663  {
664  error0 = good_udp0 ? 0 : IP6_ERROR_UDP_CHECKSUM;
665  error0 = (len_diff0 >= 0) ? error0 : IP6_ERROR_UDP_LENGTH;
666  }
667 
668  next0 = error0 ?
670  b0->error = error0 ? error_node->errors[error0] : 0;
671 
672  /* vxlan-input node expect current at VXLAN header */
673  if (is_ip4)
674  vlib_buffer_advance (b0, sizeof(ip4_header_t)+sizeof(udp_header_t));
675  else
676  vlib_buffer_advance (b0, sizeof(ip6_header_t)+sizeof(udp_header_t));
677 
678  exit0:
679  /* Process packet 1 */
680  if (proto1 != IP_PROTOCOL_UDP)
681  goto exit1; /* not UDP packet */
682 
683  if (is_ip4)
684  udp1 = ip4_next_header (ip41);
685  else
686  udp1 = ip6_next_header (ip61);
687 
688  if (udp1->dst_port != clib_host_to_net_u16 (UDP_DST_PORT_vxlan))
689  goto exit1; /* not VXLAN packet */
690 
691  /* Validate DIP against VTEPs*/
692  if (is_ip4)
693  {
694  if (addr4.as_u32 != ip41->dst_address.as_u32)
695  {
696  if (!hash_get (vxm->vtep4, ip41->dst_address.as_u32))
697  goto exit1; /* no local VTEP for VXLAN packet */
698  addr4 = ip41->dst_address;
699  }
700  }
701  else
702  {
703  if (!ip6_address_is_equal (&addr6, &ip61->dst_address))
704  {
705  if (!hash_get_mem (vxm->vtep6, &ip61->dst_address))
706  goto exit1; /* no local VTEP for VXLAN packet */
707  addr6 = ip61->dst_address;
708  }
709  }
710 
711  flags1 = b1->flags;
712  good_udp1 = (flags1 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
713 
714  /* Don't verify UDP checksum for packets with explicit zero checksum. */
715  good_udp1 |= udp1->checksum == 0;
716 
717  /* Verify UDP length */
718  if (is_ip4)
719  ip_len1 = clib_net_to_host_u16 (ip41->length);
720  else
721  ip_len1 = clib_net_to_host_u16 (ip61->payload_length);
722  udp_len1 = clib_net_to_host_u16 (udp1->length);
723  len_diff1 = ip_len1 - udp_len1;
724 
725  /* Verify UDP checksum */
726  if (PREDICT_FALSE (!good_udp1))
727  {
728  if ((flags1 & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
729  {
730  if (is_ip4)
731  flags1 = ip4_tcp_udp_validate_checksum (vm, b1);
732  else
733  flags1 = ip6_tcp_udp_icmp_validate_checksum (vm, b1);
734  good_udp1 =
735  (flags1 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
736  }
737  }
738 
739  if (is_ip4)
740  {
741  error1 = good_udp1 ? 0 : IP4_ERROR_UDP_CHECKSUM;
742  error1 = (len_diff1 >= 0) ? error1 : IP4_ERROR_UDP_LENGTH;
743  }
744  else
745  {
746  error1 = good_udp1 ? 0 : IP6_ERROR_UDP_CHECKSUM;
747  error1 = (len_diff1 >= 0) ? error1 : IP6_ERROR_UDP_LENGTH;
748  }
749 
750  next1 = error1 ?
752  b1->error = error1 ? error_node->errors[error1] : 0;
753 
754  /* vxlan-input node expect current at VXLAN header */
755  if (is_ip4)
756  vlib_buffer_advance (b1, sizeof(ip4_header_t)+sizeof(udp_header_t));
757  else
758  vlib_buffer_advance (b1, sizeof(ip6_header_t)+sizeof(udp_header_t));
759 
760  exit1:
761  vlib_validate_buffer_enqueue_x2 (vm, node, next_index,
762  to_next, n_left_to_next,
763  bi0, bi1, next0, next1);
764  }
765 
766  while (n_left_from > 0 && n_left_to_next > 0)
767  {
768  vlib_buffer_t * b0;
769  ip4_header_t * ip40;
770  ip6_header_t * ip60;
771  udp_header_t * udp0;
772  u32 bi0, ip_len0, udp_len0, flags0, next0;
773  i32 len_diff0;
774  u8 error0, good_udp0, proto0;
775 
776  bi0 = to_next[0] = from[0];
777  from += 1;
778  n_left_from -= 1;
779  to_next += 1;
780  n_left_to_next -= 1;
781 
782  b0 = vlib_get_buffer (vm, bi0);
783  if (is_ip4)
784  ip40 = vlib_buffer_get_current (b0);
785  else
786  ip60 = vlib_buffer_get_current (b0);
787 
788  /* Setup packet for next IP feature */
789  vnet_feature_next(vnet_buffer(b0)->sw_if_index[VLIB_RX], &next0, b0);
790 
791  if (is_ip4)
792  /* Treat IP4 frag packets as "experimental" protocol for now
793  until support of IP frag reassembly is implemented */
794  proto0 = ip4_is_fragment(ip40) ? 0xfe : ip40->protocol;
795  else
796  proto0 = ip60->protocol;
797 
798  if (proto0 != IP_PROTOCOL_UDP)
799  goto exit; /* not UDP packet */
800 
801  if (is_ip4)
802  udp0 = ip4_next_header (ip40);
803  else
804  udp0 = ip6_next_header (ip60);
805 
806  if (udp0->dst_port != clib_host_to_net_u16 (UDP_DST_PORT_vxlan))
807  goto exit; /* not VXLAN packet */
808 
809  /* Validate DIP against VTEPs*/
810  if (is_ip4)
811  {
812  if (addr4.as_u32 != ip40->dst_address.as_u32)
813  {
814  if (!hash_get (vxm->vtep4, ip40->dst_address.as_u32))
815  goto exit; /* no local VTEP for VXLAN packet */
816  addr4 = ip40->dst_address;
817  }
818  }
819  else
820  {
821  if (!ip6_address_is_equal (&addr6, &ip60->dst_address))
822  {
823  if (!hash_get_mem (vxm->vtep6, &ip60->dst_address))
824  goto exit; /* no local VTEP for VXLAN packet */
825  addr6 = ip60->dst_address;
826  }
827  }
828 
829  flags0 = b0->flags;
830  good_udp0 = (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
831 
832  /* Don't verify UDP checksum for packets with explicit zero checksum. */
833  good_udp0 |= udp0->checksum == 0;
834 
835  /* Verify UDP length */
836  if (is_ip4)
837  ip_len0 = clib_net_to_host_u16 (ip40->length);
838  else
839  ip_len0 = clib_net_to_host_u16 (ip60->payload_length);
840  udp_len0 = clib_net_to_host_u16 (udp0->length);
841  len_diff0 = ip_len0 - udp_len0;
842 
843  /* Verify UDP checksum */
844  if (PREDICT_FALSE (!good_udp0))
845  {
846  if ((flags0 & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
847  {
848  if (is_ip4)
849  flags0 = ip4_tcp_udp_validate_checksum (vm, b0);
850  else
851  flags0 = ip6_tcp_udp_icmp_validate_checksum (vm, b0);
852  good_udp0 =
853  (flags0 & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
854  }
855  }
856 
857  if (is_ip4)
858  {
859  error0 = good_udp0 ? 0 : IP4_ERROR_UDP_CHECKSUM;
860  error0 = (len_diff0 >= 0) ? error0 : IP4_ERROR_UDP_LENGTH;
861  }
862  else
863  {
864  error0 = good_udp0 ? 0 : IP6_ERROR_UDP_CHECKSUM;
865  error0 = (len_diff0 >= 0) ? error0 : IP6_ERROR_UDP_LENGTH;
866  }
867 
868  next0 = error0 ?
870  b0->error = error0 ? error_node->errors[error0] : 0;
871 
872  /* vxlan-input node expect current at VXLAN header */
873  if (is_ip4)
874  vlib_buffer_advance (b0, sizeof(ip4_header_t)+sizeof(udp_header_t));
875  else
876  vlib_buffer_advance (b0, sizeof(ip6_header_t)+sizeof(udp_header_t));
877 
878  exit:
879  vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
880  to_next, n_left_to_next,
881  bi0, next0);
882  }
883 
884  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
885  }
886 
887  return frame->n_vectors;
888 }
889 
890 static uword
892  vlib_node_runtime_t * node,
893  vlib_frame_t * frame)
894 {
895  return ip_vxlan_bypass_inline (vm, node, frame, /* is_ip4 */ 1);
896 }
897 
899  .function = ip4_vxlan_bypass,
900  .name = "ip4-vxlan-bypass",
901  .vector_size = sizeof (u32),
902 
903  .n_next_nodes = IP_VXLAN_BYPASS_N_NEXT,
904  .next_nodes = {
905  [IP_VXLAN_BYPASS_NEXT_DROP] = "error-drop",
906  [IP_VXLAN_BYPASS_NEXT_VXLAN] = "vxlan4-input",
907  },
908 
909  .format_buffer = format_ip4_header,
910  .format_trace = format_ip4_forward_next_trace,
911 };
912 
914 
915 /* Dummy init function to get us linked in. */
917 { return 0; }
918 
920 
921 static uword
923  vlib_node_runtime_t * node,
924  vlib_frame_t * frame)
925 {
926  return ip_vxlan_bypass_inline (vm, node, frame, /* is_ip4 */ 0);
927 }
928 
930  .function = ip6_vxlan_bypass,
931  .name = "ip6-vxlan-bypass",
932  .vector_size = sizeof (u32),
933 
934  .n_next_nodes = IP_VXLAN_BYPASS_N_NEXT,
935  .next_nodes = {
936  [IP_VXLAN_BYPASS_NEXT_DROP] = "error-drop",
937  [IP_VXLAN_BYPASS_NEXT_VXLAN] = "vxlan6-input",
938  },
939 
940  .format_buffer = format_ip6_header,
941  .format_trace = format_ip6_forward_next_trace,
942 };
943 
945 
946 /* Dummy init function to get us linked in. */
948 { return 0; }
949 
951 
952 #define foreach_vxlan_flow_input_next \
953 _(DROP, "error-drop") \
954 _(L2_INPUT, "l2-input")
955 
956 typedef enum
957 {
958 #define _(s,n) VXLAN_FLOW_NEXT_##s,
960 #undef _
963 
964 #define foreach_vxlan_flow_error \
965  _(NONE, "no error") \
966  _(IP_CHECKSUM_ERROR, "Rx ip checksum errors") \
967  _(IP_HEADER_ERROR, "Rx ip header errors") \
968  _(UDP_CHECKSUM_ERROR, "Rx udp checksum errors") \
969  _(UDP_LENGTH_ERROR, "Rx udp length errors")
970 
971 typedef enum
972 {
973 #define _(f,s) VXLAN_FLOW_ERROR_##f,
975 #undef _
978 
979 static char *vxlan_flow_error_strings[] = {
980 #define _(n,s) s,
982 #undef _
983 };
984 
985 
988 {
989  u32 flags = b->flags;
990  enum { offset = sizeof(ip4_header_t) + sizeof(udp_header_t) + sizeof(vxlan_header_t), };
991 
992  /* Verify UDP checksum */
993  if ((flags & VNET_BUFFER_F_L4_CHECKSUM_COMPUTED) == 0)
994  {
996  flags = ip4_tcp_udp_validate_checksum (vm, b);
998  }
999 
1000  return (flags & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0;
1001 }
1002 
1005 {
1006  ip4_vxlan_header_t * hdr = vlib_buffer_get_current(b) - sizeof *hdr;
1007  udp_header_t * udp = &hdr->udp;
1008  /* Don't verify UDP checksum for packets with explicit zero checksum. */
1009  u8 good_csum = (b->flags & VNET_BUFFER_F_L4_CHECKSUM_CORRECT) != 0 ||
1010  udp->checksum == 0;
1011 
1012  return !good_csum;
1013 }
1014 
1017 {
1018  ip4_vxlan_header_t * hdr = vlib_buffer_get_current(b) - sizeof *hdr;
1019  u16 ip_len = clib_net_to_host_u16 (hdr->ip4.length);
1020  u16 expected = payload_len + sizeof *hdr;
1021  return ip_len > expected || hdr->ip4.ttl == 0 || hdr->ip4.ip_version_and_header_length != 0x45;
1022 }
1023 
1026 {
1027  ip4_vxlan_header_t * hdr = vlib_buffer_get_current(b) - sizeof *hdr;
1028  u16 ip_len = clib_net_to_host_u16 (hdr->ip4.length);
1029  u16 udp_len = clib_net_to_host_u16 (hdr->udp.length);
1030  return udp_len > ip_len;
1031 }
1032 
1034 vxlan_err_code (u8 ip_err0, u8 udp_err0, u8 csum_err0)
1035 {
1036  u8 error0 = VXLAN_FLOW_ERROR_NONE;
1037  if (ip_err0)
1038  error0 = VXLAN_FLOW_ERROR_IP_HEADER_ERROR;
1039  if (udp_err0)
1040  error0 = VXLAN_FLOW_ERROR_UDP_LENGTH_ERROR;
1041  if (csum_err0)
1042  error0 = VXLAN_FLOW_ERROR_UDP_CHECKSUM_ERROR;
1043  return error0;
1044 }
1045 
1047  vlib_node_runtime_t * node,
1048  vlib_frame_t * f)
1049 {
1050  enum { payload_offset = sizeof(ip4_vxlan_header_t) };
1051 
1052  vxlan_main_t * vxm = &vxlan_main;
1055  [VXLAN_FLOW_NEXT_DROP] = im->combined_sw_if_counters + VNET_INTERFACE_COUNTER_DROP,
1056  [VXLAN_FLOW_NEXT_L2_INPUT] = im->combined_sw_if_counters + VNET_INTERFACE_COUNTER_RX,
1057  };
1058  u32 thread_index = vlib_get_thread_index();
1059 
1060  u32 * from = vlib_frame_vector_args (f);
1061  u32 n_left_from = f->n_vectors;
1062  u32 next_index = VXLAN_FLOW_NEXT_L2_INPUT;
1063 
1064  while (n_left_from > 0)
1065  {
1066  u32 n_left_to_next, *to_next;
1067 
1068  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
1069 
1070  while (n_left_from > 3 && n_left_to_next > 3)
1071  {
1072  u32 bi0 = to_next[0] = from[0];
1073  u32 bi1 = to_next[1] = from[1];
1074  u32 bi2 = to_next[2] = from[2];
1075  u32 bi3 = to_next[3] = from[3];
1076  from+=4;
1077  n_left_from-=4;
1078  to_next+=4;
1079  n_left_to_next-=4;
1080 
1081  vlib_buffer_t * b0 = vlib_get_buffer (vm, bi0);
1082  vlib_buffer_t * b1 = vlib_get_buffer (vm, bi1);
1083  vlib_buffer_t * b2 = vlib_get_buffer (vm, bi2);
1084  vlib_buffer_t * b3 = vlib_get_buffer (vm, bi3);
1085 
1086  vlib_buffer_advance (b0, payload_offset);
1087  vlib_buffer_advance (b1, payload_offset);
1088  vlib_buffer_advance (b2, payload_offset);
1089  vlib_buffer_advance (b3, payload_offset);
1090 
1091  u16 len0 = vlib_buffer_length_in_chain (vm, b0);
1092  u16 len1 = vlib_buffer_length_in_chain (vm, b1);
1093  u16 len2 = vlib_buffer_length_in_chain (vm, b2);
1094  u16 len3 = vlib_buffer_length_in_chain (vm, b3);
1095 
1096  u32 next0 = VXLAN_FLOW_NEXT_L2_INPUT, next1 = VXLAN_FLOW_NEXT_L2_INPUT,
1097  next2 = VXLAN_FLOW_NEXT_L2_INPUT, next3 = VXLAN_FLOW_NEXT_L2_INPUT;
1098 
1099  u8 ip_err0 = vxlan_check_ip (b0, len0);
1100  u8 ip_err1 = vxlan_check_ip (b1, len1);
1101  u8 ip_err2 = vxlan_check_ip (b2, len2);
1102  u8 ip_err3 = vxlan_check_ip (b3, len3);
1103  u8 ip_err = ip_err0 | ip_err1 | ip_err2 | ip_err3;
1104 
1105  u8 udp_err0 = vxlan_check_ip_udp_len (b0);
1106  u8 udp_err1 = vxlan_check_ip_udp_len (b1);
1107  u8 udp_err2 = vxlan_check_ip_udp_len (b2);
1108  u8 udp_err3 = vxlan_check_ip_udp_len (b3);
1109  u8 udp_err = udp_err0 | udp_err1 | udp_err2 | udp_err3;
1110 
1111  u8 csum_err0 = vxlan_check_udp_csum (vm, b0);
1112  u8 csum_err1 = vxlan_check_udp_csum (vm, b1);
1113  u8 csum_err2 = vxlan_check_udp_csum (vm, b2);
1114  u8 csum_err3 = vxlan_check_udp_csum (vm, b3);
1115  u8 csum_err = csum_err0 | csum_err1 | csum_err2 | csum_err3;
1116 
1117  if (PREDICT_FALSE(csum_err))
1118  {
1119  if (csum_err0)
1120  csum_err0 = !vxlan_validate_udp_csum (vm, b0);
1121  if (csum_err1)
1122  csum_err1 = !vxlan_validate_udp_csum (vm, b1);
1123  if (csum_err2)
1124  csum_err2 = !vxlan_validate_udp_csum (vm, b2);
1125  if (csum_err3)
1126  csum_err3 = !vxlan_validate_udp_csum (vm, b3);
1127  csum_err = csum_err0 | csum_err1 | csum_err2 | csum_err3;
1128  }
1129 
1130  if (PREDICT_FALSE(ip_err || udp_err || csum_err))
1131  {
1132  if (ip_err0 || udp_err0 || csum_err0)
1133  {
1134  next0 = VXLAN_FLOW_NEXT_DROP;
1135  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1136  b0->error = node->errors[error0];
1137  }
1138  if (ip_err1 || udp_err1 || csum_err1)
1139  {
1140  next1 = VXLAN_FLOW_NEXT_DROP;
1141  u8 error1 = vxlan_err_code (ip_err1, udp_err1, csum_err1);
1142  b1->error = node->errors[error1];
1143  }
1144  if (ip_err2 || udp_err2 || csum_err2)
1145  {
1146  next2 = VXLAN_FLOW_NEXT_DROP;
1147  u8 error2 = vxlan_err_code (ip_err2, udp_err2, csum_err2);
1148  b2->error = node->errors[error2];
1149  }
1150  if (ip_err3 || udp_err3 || csum_err3)
1151  {
1152  next3 = VXLAN_FLOW_NEXT_DROP;
1153  u8 error3 = vxlan_err_code (ip_err3, udp_err3, csum_err3);
1154  b3->error = node->errors[error3];
1155  }
1156  }
1157 
1158  vnet_update_l2_len (b0);
1159  vnet_update_l2_len (b1);
1160  vnet_update_l2_len (b2);
1161  vnet_update_l2_len (b3);
1162 
1163  ASSERT (b0->flow_id != 0);
1164  ASSERT (b1->flow_id != 0);
1165  ASSERT (b2->flow_id != 0);
1166  ASSERT (b3->flow_id != 0);
1167 
1168  u32 t_index0 = b0->flow_id - vxm->flow_id_start;
1169  u32 t_index1 = b1->flow_id - vxm->flow_id_start;
1170  u32 t_index2 = b2->flow_id - vxm->flow_id_start;
1171  u32 t_index3 = b3->flow_id - vxm->flow_id_start;
1172 
1173  vxlan_tunnel_t * t0 = &vxm->tunnels[t_index0];
1174  vxlan_tunnel_t * t1 = &vxm->tunnels[t_index1];
1175  vxlan_tunnel_t * t2 = &vxm->tunnels[t_index2];
1176  vxlan_tunnel_t * t3 = &vxm->tunnels[t_index3];
1177 
1178  /* flow id consumed */
1179  b0->flow_id = 0;
1180  b1->flow_id = 0;
1181  b2->flow_id = 0;
1182  b3->flow_id = 0;
1183 
1184  u32 sw_if_index0 = vnet_buffer (b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
1185  u32 sw_if_index1 = vnet_buffer (b1)->sw_if_index[VLIB_RX] = t1->sw_if_index;
1186  u32 sw_if_index2 = vnet_buffer (b2)->sw_if_index[VLIB_RX] = t2->sw_if_index;
1187  u32 sw_if_index3 = vnet_buffer (b3)->sw_if_index[VLIB_RX] = t3->sw_if_index;
1188 
1189  vlib_increment_combined_counter (rx_counter[next0], thread_index, sw_if_index0, 1, len0);
1190  vlib_increment_combined_counter (rx_counter[next1], thread_index, sw_if_index1, 1, len1);
1191  vlib_increment_combined_counter (rx_counter[next2], thread_index, sw_if_index2, 1, len2);
1192  vlib_increment_combined_counter (rx_counter[next3], thread_index, sw_if_index3, 1, len3);
1193 
1194  u32 flags = b0->flags | b1->flags | b2->flags | b3->flags;
1195 
1196  if (PREDICT_FALSE(flags & VLIB_BUFFER_IS_TRACED))
1197  {
1198  if (b0->flags & VLIB_BUFFER_IS_TRACED)
1199  {
1200  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b0, sizeof *tr);
1201  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1202  *tr = (vxlan_rx_trace_t) {
1203  .next_index = next0, .error = error0, .tunnel_index = t_index0, .vni = t0->vni };
1204  }
1205  if (b1->flags & VLIB_BUFFER_IS_TRACED)
1206  {
1207  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b1, sizeof *tr);
1208  u8 error1 = vxlan_err_code (ip_err1, udp_err1, csum_err1);
1209  *tr = (vxlan_rx_trace_t) {
1210  .next_index = next1, .error = error1, .tunnel_index = t_index1, .vni = t1->vni };
1211  }
1212  if (b2->flags & VLIB_BUFFER_IS_TRACED)
1213  {
1214  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b2, sizeof *tr);
1215  u8 error2 = vxlan_err_code (ip_err2, udp_err2, csum_err2);
1216  *tr = (vxlan_rx_trace_t) {
1217  .next_index = next2, .error = error2, .tunnel_index = t_index2, .vni = t2->vni };
1218  }
1219  if (b3->flags & VLIB_BUFFER_IS_TRACED)
1220  {
1221  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b3, sizeof *tr);
1222  u8 error3 = vxlan_err_code (ip_err3, udp_err3, csum_err3);
1223  *tr = (vxlan_rx_trace_t) {
1224  .next_index = next3, .error = error3, .tunnel_index = t_index3, .vni = t3->vni };
1225  }
1226  }
1228  (vm, node, next_index, to_next, n_left_to_next,
1229  bi0, bi1, bi2, bi3, next0, next1, next2, next3);
1230  }
1231  while (n_left_from > 0 && n_left_to_next > 0)
1232  {
1233  u32 bi0 = to_next[0] = from[0];
1234  from++;
1235  n_left_from--;
1236  to_next++;
1237  n_left_to_next--;
1238 
1239  vlib_buffer_t * b0 = vlib_get_buffer (vm, bi0);
1240  vlib_buffer_advance (b0, payload_offset);
1241 
1242  u16 len0 = vlib_buffer_length_in_chain (vm, b0);
1243  u32 next0 = VXLAN_FLOW_NEXT_L2_INPUT;
1244 
1245  u8 ip_err0 = vxlan_check_ip (b0, len0);
1246  u8 udp_err0 = vxlan_check_ip_udp_len (b0);
1247  u8 csum_err0 = vxlan_check_udp_csum (vm, b0);
1248 
1249  if (csum_err0)
1250  csum_err0 = !vxlan_validate_udp_csum (vm, b0);
1251  if (ip_err0 || udp_err0 || csum_err0)
1252  {
1253  next0 = VXLAN_FLOW_NEXT_DROP;
1254  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1255  b0->error = node->errors[error0];
1256  }
1257 
1258  vnet_update_l2_len (b0);
1259 
1260  ASSERT (b0->flow_id != 0);
1261  u32 t_index0 = b0->flow_id - vxm->flow_id_start;
1262  vxlan_tunnel_t * t0 = &vxm->tunnels[t_index0];
1263  b0->flow_id = 0;
1264 
1265  u32 sw_if_index0 = vnet_buffer (b0)->sw_if_index[VLIB_RX] = t0->sw_if_index;
1266  vlib_increment_combined_counter (rx_counter[next0], thread_index, sw_if_index0, 1, len0);
1267 
1268  if (PREDICT_FALSE(b0->flags & VLIB_BUFFER_IS_TRACED))
1269  {
1270  vxlan_rx_trace_t *tr = vlib_add_trace (vm, node, b0, sizeof *tr);
1271  u8 error0 = vxlan_err_code (ip_err0, udp_err0, csum_err0);
1272  *tr = (vxlan_rx_trace_t) {
1273  .next_index = next0, .error = error0, .tunnel_index = t_index0, .vni = t0->vni };
1274  }
1275  vlib_validate_buffer_enqueue_x1 (vm, node, next_index,
1276  to_next, n_left_to_next,
1277  bi0, next0);
1278  }
1279 
1280  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
1281  }
1282 
1283  return f->n_vectors;
1284 }
1285 
1286 /* *INDENT-OFF* */
1287 #ifndef CLIB_MULTIARCH_VARIANT
1289  .name = "vxlan-flow-input",
1290  .type = VLIB_NODE_TYPE_INTERNAL,
1291  .vector_size = sizeof (u32),
1292 
1293  .format_trace = format_vxlan_rx_trace,
1294 
1295  .n_errors = VXLAN_FLOW_N_ERROR,
1296  .error_strings = vxlan_flow_error_strings,
1297 
1298  .n_next_nodes = VXLAN_FLOW_N_NEXT,
1299  .next_nodes = {
1300 #define _(s,n) [VXLAN_FLOW_NEXT_##s] = n,
1302 #undef _
1303  },
1304 };
1305 #endif
1306 /* *INDENT-ON* */
static_always_inline u8 vxlan_validate_udp_csum(vlib_main_t *vm, vlib_buffer_t *b)
Definition: decap.c:987
#define foreach_vxlan_flow_error
Definition: decap.c:964
#define CLIB_UNUSED(x)
Definition: clib.h:79
clib_bihash_24_8_t vxlan6_tunnel_by_key
Definition: vxlan.h:144
static void vlib_increment_combined_counter(vlib_combined_counter_main_t *cm, u32 thread_index, u32 index, u64 n_packets, u64 n_bytes)
Increment a combined counter.
Definition: counter.h:213
ip4_address_t src_address
Definition: ip4_packet.h:169
uword * vtep6
Definition: vxlan.h:149
static char * vxlan_flow_error_strings[]
Definition: decap.c:979
vnet_interface_main_t interface_main
Definition: vnet.h:56
format_function_t format_ip4_header
Definition: format.h:89
vlib_node_registration_t vxlan4_input_node
(constructor) VLIB_REGISTER_NODE (vxlan4_input_node)
Definition: decap.c:22
#define foreach_vxlan_input_next
Definition: vxlan.h:117
#define PREDICT_TRUE(x)
Definition: clib.h:106
u64 as_u64[2]
Definition: ip6_packet.h:51
unsigned long u64
Definition: types.h:89
u32 flow_id_start
Definition: vxlan.h:163
static int clib_bihash_key_compare_16_8(u64 *a, u64 *b)
Definition: bihash_16_8.h:68
static uword vxlan_input(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *from_frame, u32 is_ip4)
Definition: decap.c:161
#define vlib_validate_buffer_enqueue_x4(vm, node, next_index, to_next, n_left_to_next, bi0, bi1, bi2, bi3, next0, next1, next2, next3)
Finish enqueueing four buffers forward in the graph.
Definition: buffer_node.h:138
vlib_node_registration_t vxlan4_flow_input_node
(constructor) VLIB_REGISTER_NODE (vxlan4_flow_input_node)
Definition: decap.c:1288
u32 * fib_index_by_sw_if_index
Table index indexed by software interface.
Definition: ip4.h:111
u8 * format(u8 *s, const char *fmt,...)
Definition: format.c:419
vlib_node_registration_t ip4_vxlan_bypass_node
(constructor) VLIB_REGISTER_NODE (ip4_vxlan_bypass_node)
Definition: decap.c:898
#define VLIB_NODE_FN(node)
Definition: node.h:173
vlib_error_t * errors
Vector of errors for this node.
Definition: node.h:451
static uword vlib_buffer_length_in_chain(vlib_main_t *vm, vlib_buffer_t *b)
Get length in bytes of the buffer chain.
Definition: buffer_funcs.h:250
ip6_address_t src_address
Definition: ip6_packet.h:347
unsigned char u8
Definition: types.h:56
static uword ip6_vxlan_bypass(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: decap.c:922
static int clib_bihash_key_compare_24_8(u64 *a, u64 *b)
Definition: bihash_24_8.h:69
#define VXLAN_FLAGS_I
Definition: vxlan_packet.h:52
vnet_main_t * vnet_main
Definition: vxlan.h:159
#define static_always_inline
Definition: clib.h:93
u32 tunnel_index
Definition: decap.c:27
#define VLIB_INIT_FUNCTION(x)
Definition: init.h:156
#define always_inline
Definition: clib.h:92
ip4_address_t dst_address
Definition: ip4_packet.h:169
vlib_combined_counter_main_t * combined_sw_if_counters
Definition: interface.h:811
static uword ip6_address_is_equal(ip6_address_t *a, ip6_address_t *b)
Definition: ip6_packet.h:214
#define vlib_prefetch_buffer_header(b, type)
Prefetch buffer metadata.
Definition: buffer.h:184
static vxlan_tunnel_t * vxlan6_find_tunnel(vxlan_main_t *vxm, last_tunnel_cache6 *cache, u32 fib_index, ip6_header_t *ip6_0, vxlan_header_t *vxlan0, vxlan_tunnel_t **stats_t0)
Definition: decap.c:114
static void * ip4_next_header(ip4_header_t *i)
Definition: ip4_packet.h:240
unsigned int u32
Definition: types.h:88
static int ip4_is_fragment(ip4_header_t *i)
Definition: ip4_packet.h:212
#define hash_get(h, key)
Definition: hash.h:249
#define pool_elt_at_index(p, i)
Returns pointer to element at given index.
Definition: pool.h:464
static_always_inline u8 vxlan_check_ip_udp_len(vlib_buffer_t *b)
Definition: decap.c:1025
vlib_node_registration_t ip4_input_node
Global ip4 input node.
Definition: ip4_input.c:317
unsigned short u16
Definition: types.h:57
vlib_node_registration_t ip6_vxlan_bypass_node
(constructor) VLIB_REGISTER_NODE (ip6_vxlan_bypass_node)
Definition: decap.c:929
static void * vlib_buffer_get_current(vlib_buffer_t *b)
Get pointer to current data to process.
Definition: buffer.h:202
vxlan_main_t vxlan_main
Definition: vxlan.c:43
static uword ip4_address_is_multicast(ip4_address_t *a)
Definition: ip4_packet.h:317
#define PREDICT_FALSE(x)
Definition: clib.h:105
static vxlan_tunnel_t * vxlan4_find_tunnel(vxlan_main_t *vxm, last_tunnel_cache4 *cache, u32 fib_index, ip4_header_t *ip4_0, vxlan_header_t *vxlan0, vxlan_tunnel_t **stats_t0)
Definition: decap.c:68
vnet_main_t vnet_main
Definition: misc.c:43
u32 ip4_tcp_udp_validate_checksum(vlib_main_t *vm, vlib_buffer_t *p0)
Definition: ip4_forward.c:1113
vlib_node_registration_t vxlan6_input_node
(constructor) VLIB_REGISTER_NODE (vxlan6_input_node)
Definition: decap.c:23
#define vlib_validate_buffer_enqueue_x2(vm, node, next_index, to_next, n_left_to_next, bi0, bi1, next0, next1)
Finish enqueueing two buffers forward in the graph.
Definition: buffer_node.h:70
vxlan4_tunnel_key_t last_tunnel_cache4
Definition: decap.c:65
static_always_inline void vnet_feature_next(u32 sw_if_index, u32 *next0, vlib_buffer_t *b0)
Definition: feature.h:237
#define vlib_validate_buffer_enqueue_x1(vm, node, next_index, to_next, n_left_to_next, bi0, next0)
Finish enqueueing one buffer forward in the graph.
Definition: buffer_node.h:218
#define vlib_get_next_frame(vm, node, next_index, vectors, n_vectors_left)
Get pointer to next frame vector data by (vlib_node_runtime_t, next_index).
Definition: node_funcs.h:364
vlib_error_t error
Error code for buffers to be enqueued to error handler.
Definition: buffer.h:135
static void vlib_node_increment_counter(vlib_main_t *vm, u32 node_index, u32 counter_index, u64 increment)
Definition: node_funcs.h:1168
u32 flags
Definition: vhost_user.h:110
#define VLIB_REGISTER_NODE(x,...)
Definition: node.h:153
static u32 vnet_get_vni(vxlan_header_t *h)
Definition: vxlan_packet.h:54
static uword vxlan4_input(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *from_frame)
Definition: decap.c:433
u32 flow_id
Generic flow identifier.
Definition: buffer.h:123
u16 n_vectors
Definition: node.h:380
static_always_inline uword vlib_get_thread_index(void)
Definition: threads.h:221
#define CLIB_PREFETCH(addr, size, type)
Definition: cache.h:77
vlib_main_t * vm
Definition: buffer.c:294
static void ip6_address_set_zero(ip6_address_t *a)
Definition: ip6_packet.h:249
static_always_inline u8 vxlan_check_udp_csum(vlib_main_t *vm, vlib_buffer_t *b)
Definition: decap.c:1004
static char * vxlan_error_strings[]
Definition: decap.c:448
static vlib_node_runtime_t * vlib_node_get_runtime(vlib_main_t *vm, u32 node_index)
Get node runtime by node index.
Definition: node_funcs.h:89
vxlan6_tunnel_key_t last_tunnel_cache6
Definition: decap.c:111
void vlib_put_next_frame(vlib_main_t *vm, vlib_node_runtime_t *r, u32 next_index, u32 n_vectors_left)
Release pointer to next frame vector data.
Definition: main.c:454
u32 decap_next_index
Definition: vxlan.h:81
static_always_inline u8 vxlan_check_ip(vlib_buffer_t *b, u16 payload_len)
Definition: decap.c:1016
vxlan_flow_input_next_t
Definition: decap.c:956
static void * ip6_next_header(ip6_header_t *i)
Definition: ip6_packet.h:374
ip_vxan_bypass_next_t
Definition: decap.c:864
signed int i32
Definition: types.h:81
u16 cached_next_index
Next frame index that vector arguments were last enqueued to last time this node ran.
Definition: node.h:492
vxlan_flow_error_t
Definition: decap.c:971
#define ASSERT(truth)
#define foreach_vxlan_flow_input_next
Definition: decap.c:952
ip6_main_t ip6_main
Definition: ip6_forward.c:2574
uword * vtep4
Definition: vxlan.h:148
u32 sw_if_index
Definition: vxlan.h:87
static void vlib_buffer_advance(vlib_buffer_t *b, word l)
Advance current data pointer by the supplied (signed!) amount.
Definition: buffer.h:215
format_function_t format_ip6_header
Definition: format.h:103
static void * vlib_add_trace(vlib_main_t *vm, vlib_node_runtime_t *r, vlib_buffer_t *b, u32 n_data_bytes)
Definition: trace_funcs.h:55
#define vec_elt(v, i)
Get vector value at index i.
struct _vlib_node_registration vlib_node_registration_t
template key/value backing page structure
Definition: bihash_doc.h:44
Definition: defs.h:47
static uword ip6_address_is_multicast(ip6_address_t *a)
Definition: ip6_packet.h:151
u16 payload_length
Definition: ip6_packet.h:338
static u32 buf_fib_index(vlib_buffer_t *b, u32 is_ip4)
Definition: decap.c:52
u32 ip6_tcp_udp_icmp_validate_checksum(vlib_main_t *vm, vlib_buffer_t *p0)
Definition: ip6_forward.c:986
static void vnet_update_l2_len(vlib_buffer_t *b)
Definition: l2_input.h:221
void ip4_forward_next_trace(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame, vlib_rx_or_tx_t which_adj_index)
Definition: ip4_forward.c:967
u64 uword
Definition: types.h:112
static void * vlib_frame_vector_args(vlib_frame_t *f)
Get pointer to frame vector data.
Definition: node_funcs.h:267
static_always_inline u8 vxlan_err_code(u8 ip_err0, u8 udp_err0, u8 csum_err0)
Definition: decap.c:1034
u8 * format_ip4_forward_next_trace(u8 *s, va_list *args)
Definition: ip4_forward.c:919
A collection of combined counters.
Definition: counter.h:181
#define hash_get_mem(h, key)
Definition: hash.h:269
#define vnet_buffer(b)
Definition: buffer.h:360
VLIB_NODE_FUNCTION_MULTIARCH(l2t_decap_node, l2t_decap_node_fn)
static u8 * format_vxlan_rx_trace(u8 *s, va_list *args)
Definition: decap.c:32
ip4_main_t ip4_main
Global ip4 main structure.
Definition: ip4_forward.c:832
clib_bihash_16_8_t vxlan4_tunnel_by_key
Definition: vxlan.h:143
u8 data[0]
Packet data.
Definition: buffer.h:172
clib_error_t * ip6_vxlan_bypass_init(vlib_main_t *vm)
Definition: decap.c:947
u16 flags
Copy of main node flags.
Definition: node.h:486
#define VLIB_NODE_FLAG_TRACE
Definition: node.h:295
u32 next_index
Definition: decap.c:26
#define CLIB_CACHE_LINE_BYTES
Definition: cache.h:62
u32 flags
buffer flags: VLIB_BUFFER_FREE_LIST_INDEX_MASK: bits used to store free list index, VLIB_BUFFER_IS_TRACED: trace this buffer.
Definition: buffer.h:111
static uword ip4_vxlan_bypass(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: decap.c:891
u32 * fib_index_by_sw_if_index
Definition: ip6.h:176
static vlib_buffer_t * vlib_get_buffer(vlib_main_t *vm, u32 buffer_index)
Translate buffer index into buffer pointer.
Definition: buffer_funcs.h:57
vxlan_tunnel_t * tunnels
Definition: vxlan.h:140
static uword ip_vxlan_bypass_inline(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame, u32 is_ip4)
Definition: decap.c:509
ip46_address_t src
Definition: vxlan.h:74
static uword vxlan6_input(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *from_frame)
Definition: decap.c:441
Definition: defs.h:46
ip6_address_t dst_address
Definition: ip6_packet.h:347
clib_error_t * ip4_vxlan_bypass_init(vlib_main_t *vm)
Definition: decap.c:916
u8 * format_ip6_forward_next_trace(u8 *s, va_list *args)
Definition: ip6_forward.c:768