FD.io VPP  v18.10-34-gcce845e
Vector Packet Processing
nat66_in2out.c
Go to the documentation of this file.
1 /*
2  * Copyright (c) 2018 Cisco and/or its affiliates.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at:
6  *
7  * http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 /**
16  * @file
17  * @brief NAT66 inside to outside network translation
18  */
19 
20 #include <nat/nat66.h>
21 #include <vnet/ip/ip6_to_ip4.h>
22 #include <vnet/fib/fib_table.h>
23 
24 typedef struct
25 {
29 
30 static u8 *
31 format_nat66_in2out_trace (u8 * s, va_list * args)
32 {
33  CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
34  CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
35  nat66_in2out_trace_t *t = va_arg (*args, nat66_in2out_trace_t *);
36 
37  s =
38  format (s, "NAT66-in2out: sw_if_index %d, next index %d", t->sw_if_index,
39  t->next_index);
40 
41  return s;
42 }
43 
45 
46 #define foreach_nat66_in2out_error \
47 _(IN2OUT_PACKETS, "good in2out packets processed") \
48 _(NO_TRANSLATION, "no translation") \
49 _(UNKNOWN, "unknown")
50 
51 typedef enum
52 {
53 #define _(sym,str) NAT66_IN2OUT_ERROR_##sym,
55 #undef _
58 
59 static char *nat66_in2out_error_strings[] = {
60 #define _(sym,string) string,
62 #undef _
63 };
64 
65 typedef enum
66 {
71 
72 static inline u8
73 nat66_not_translate (u32 rx_fib_index, ip6_address_t ip6_addr)
74 {
75  nat66_main_t *nm = &nat66_main;
79  fib_prefix_t pfx = {
81  .fp_len = 128,
82  .fp_addr = {
83  .ip6 = ip6_addr,
84  },
85  };
86 
87  fei = fib_table_lookup (rx_fib_index, &pfx);
88  if (FIB_NODE_INDEX_INVALID == fei)
89  return 1;
90  sw_if_index = fib_entry_get_resolving_interface (fei);
91 
92  if (sw_if_index == ~0)
93  {
94  fei = fib_table_lookup (nm->outside_fib_index, &pfx);
95  if (FIB_NODE_INDEX_INVALID == fei)
96  return 1;
97  sw_if_index = fib_entry_get_resolving_interface (fei);
98  }
99 
100  /* *INDENT-OFF* */
101  pool_foreach (i, nm->interfaces,
102  ({
103  /* NAT packet aimed at outside interface */
104  if (nat_interface_is_outside (i) && sw_if_index == i->sw_if_index)
105  return 0;
106  }));
107  /* *INDENT-ON* */
108 
109  return 1;
110 }
111 
112 static inline uword
114  vlib_frame_t * frame)
115 {
116  u32 n_left_from, *from, *to_next;
117  nat66_in2out_next_t next_index;
118  u32 pkts_processed = 0;
119  u32 thread_index = vm->thread_index;
120  nat66_main_t *nm = &nat66_main;
121 
122  from = vlib_frame_vector_args (frame);
123  n_left_from = frame->n_vectors;
124  next_index = node->cached_next_index;
125 
126  while (n_left_from > 0)
127  {
128  u32 n_left_to_next;
129 
130  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
131 
132  while (n_left_from > 0 && n_left_to_next > 0)
133  {
134  u32 bi0;
135  vlib_buffer_t *b0;
137  ip6_header_t *ip60;
138  u16 l4_offset0, frag_offset0;
139  u8 l4_protocol0;
141  u32 sw_if_index0, fib_index0;
142  udp_header_t *udp0;
143  tcp_header_t *tcp0;
144  icmp46_header_t *icmp0;
145  u16 *checksum0 = 0;
146  ip_csum_t csum0;
147 
148  /* speculatively enqueue b0 to the current next frame */
149  bi0 = from[0];
150  to_next[0] = bi0;
151  from += 1;
152  to_next += 1;
153  n_left_from -= 1;
154  n_left_to_next -= 1;
155 
156  b0 = vlib_get_buffer (vm, bi0);
157  ip60 = vlib_buffer_get_current (b0);
158 
159  if (PREDICT_FALSE
160  (ip6_parse
161  (ip60, b0->current_length, &l4_protocol0, &l4_offset0,
162  &frag_offset0)))
163  {
164  next0 = NAT66_IN2OUT_NEXT_DROP;
165  b0->error = node->errors[NAT66_IN2OUT_ERROR_UNKNOWN];
166  goto trace0;
167  }
168 
169  sw_if_index0 = vnet_buffer (b0)->sw_if_index[VLIB_RX];
170  fib_index0 =
172  sw_if_index0);
173 
174  if (nat66_not_translate (fib_index0, ip60->dst_address))
175  goto trace0;
176 
177  sm0 = nat66_static_mapping_get (&ip60->src_address, fib_index0, 1);
178  if (PREDICT_FALSE (!sm0))
179  {
180  goto trace0;
181  }
182 
183  if (l4_protocol0 == IP_PROTOCOL_UDP)
184  {
185  udp0 = (udp_header_t *) u8_ptr_add (ip60, l4_offset0);
186  checksum0 = &udp0->checksum;
187  }
188  else if (l4_protocol0 == IP_PROTOCOL_TCP)
189  {
190  tcp0 = (tcp_header_t *) u8_ptr_add (ip60, l4_offset0);
191  checksum0 = &tcp0->checksum;
192  }
193  else if (l4_protocol0 == IP_PROTOCOL_ICMP6)
194  {
195  icmp0 = (icmp46_header_t *) u8_ptr_add (ip60, l4_offset0);
196  checksum0 = &icmp0->checksum;
197  }
198  else
199  goto skip_csum0;
200 
201  csum0 = ip_csum_sub_even (*checksum0, ip60->src_address.as_u64[0]);
202  csum0 = ip_csum_sub_even (csum0, ip60->src_address.as_u64[1]);
203  csum0 = ip_csum_add_even (csum0, sm0->e_addr.as_u64[0]);
204  csum0 = ip_csum_add_even (csum0, sm0->e_addr.as_u64[1]);
205  *checksum0 = ip_csum_fold (csum0);
206 
207  skip_csum0:
208  ip60->src_address.as_u64[0] = sm0->e_addr.as_u64[0];
209  ip60->src_address.as_u64[1] = sm0->e_addr.as_u64[1];
210 
212  thread_index, sm0 - nm->sm, 1,
214  b0));
215 
216  trace0:
218  && (b0->flags & VLIB_BUFFER_IS_TRACED)))
219  {
221  vlib_add_trace (vm, node, b0, sizeof (*t));
222  t->sw_if_index = vnet_buffer (b0)->sw_if_index[VLIB_RX];
223  t->next_index = next0;
224  }
225 
226  pkts_processed += next0 != NAT66_IN2OUT_NEXT_DROP;
227 
228  /* verify speculative enqueue, maybe switch current next frame */
229  vlib_validate_buffer_enqueue_x1 (vm, node, next_index, to_next,
230  n_left_to_next, bi0, next0);
231  }
232  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
233  }
234 
236  NAT66_IN2OUT_ERROR_IN2OUT_PACKETS,
237  pkts_processed);
238  return frame->n_vectors;
239 }
240 
241 /* *INDENT-OFF* */
243  .function = nat66_in2out_node_fn,
244  .name = "nat66-in2out",
245  .vector_size = sizeof (u32),
246  .format_trace = format_nat66_in2out_trace,
247  .type = VLIB_NODE_TYPE_INTERNAL,
249  .error_strings = nat66_in2out_error_strings,
250  .n_next_nodes = NAT66_IN2OUT_N_NEXT,
251  /* edit / add dispositions here */
252  .next_nodes = {
253  [NAT66_IN2OUT_NEXT_DROP] = "error-drop",
254  [NAT66_IN2OUT_NEXT_IP6_LOOKUP] = "ip6-lookup",
255  },
256 };
257 /* *INDENT-ON* */
258 
260 
261 /*
262  * fd.io coding-style-patch-verification: ON
263  *
264  * Local Variables:
265  * eval: (c-set-style "gnu")
266  * End:
267  */
fib_protocol_t fp_proto
protocol type
Definition: fib_types.h:212
#define CLIB_UNUSED(x)
Definition: clib.h:81
static void vlib_increment_combined_counter(vlib_combined_counter_main_t *cm, u32 thread_index, u32 index, u64 n_packets, u64 n_bytes)
Increment a combined counter.
Definition: counter.h:204
u64 as_u64[2]
Definition: ip6_packet.h:51
u32 fib_table_get_index_for_sw_if_index(fib_protocol_t proto, u32 sw_if_index)
Get the index of the FIB bound to the interface.
Definition: fib_table.c:956
u32 thread_index
Definition: main.h:179
int i
uword ip_csum_t
Definition: ip_packet.h:181
u8 * format(u8 *s, const char *fmt,...)
Definition: format.c:419
vlib_error_t * errors
Vector of errors for this node.
Definition: node.h:472
static uword vlib_buffer_length_in_chain(vlib_main_t *vm, vlib_buffer_t *b)
Get length in bytes of the buffer chain.
Definition: buffer_funcs.h:263
struct _tcp_header tcp_header_t
ip6_address_t src_address
Definition: ip6_packet.h:378
unsigned char u8
Definition: types.h:56
nat66_in2out_error_t
Definition: nat66_in2out.c:51
nat66_main_t nat66_main
Definition: nat66.c:23
nat66_in2out_next_t
Definition: nat66_in2out.c:65
#define pool_foreach(VAR, POOL, BODY)
Iterate through pool.
Definition: pool.h:443
u32 sw_if_index
Definition: vxlan_gbp.api:39
Aggregrate type for a prefix.
Definition: fib_types.h:203
static_always_inline int ip6_parse(const ip6_header_t *ip6, u32 buff_len, u8 *l4_protocol, u16 *l4_offset, u16 *frag_hdr_offset)
Parse some useful information from IPv6 header.
Definition: ip6_to_ip4.h:59
unsigned int u32
Definition: types.h:88
fib_node_index_t fib_table_lookup(u32 fib_index, const fib_prefix_t *prefix)
Perfom a longest prefix match in the non-forwarding table.
Definition: fib_table.c:66
u16 current_length
Nbytes between current data and the end of this buffer.
Definition: buffer.h:113
unsigned short u16
Definition: types.h:57
static void * vlib_buffer_get_current(vlib_buffer_t *b)
Get pointer to current data to process.
Definition: buffer.h:205
#define PREDICT_FALSE(x)
Definition: clib.h:107
#define vlib_validate_buffer_enqueue_x1(vm, node, next_index, to_next, n_left_to_next, bi0, next0)
Finish enqueueing one buffer forward in the graph.
Definition: buffer_node.h:218
#define vlib_get_next_frame(vm, node, next_index, vectors, n_vectors_left)
Get pointer to next frame vector data by (vlib_node_runtime_t, next_index).
Definition: node_funcs.h:364
vlib_node_registration_t nat66_in2out_node
(constructor) VLIB_REGISTER_NODE (nat66_in2out_node)
Definition: nat66_in2out.c:44
vlib_error_t error
Error code for buffers to be enqueued to error handler.
Definition: buffer.h:138
static void vlib_node_increment_counter(vlib_main_t *vm, u32 node_index, u32 counter_index, u64 increment)
Definition: node_funcs.h:1176
u32 fib_entry_get_resolving_interface(fib_node_index_t entry_index)
Definition: fib_entry.c:1409
static u8 nat66_not_translate(u32 rx_fib_index, ip6_address_t ip6_addr)
Definition: nat66_in2out.c:73
#define VLIB_REGISTER_NODE(x,...)
Definition: node.h:155
u16 n_vectors
Definition: node.h:401
ip6_address_t e_addr
Definition: nat66.h:28
vlib_main_t * vm
Definition: buffer.c:294
snat_interface_t * interfaces
Interface pool.
Definition: nat66.h:49
u32 fib_node_index_t
A typedef of a node index.
Definition: fib_types.h:30
static char * nat66_in2out_error_strings[]
Definition: nat66_in2out.c:59
#define ARRAY_LEN(x)
Definition: clib.h:61
void vlib_put_next_frame(vlib_main_t *vm, vlib_node_runtime_t *r, u32 next_index, u32 n_vectors_left)
Release pointer to next frame vector data.
Definition: main.c:455
u16 cached_next_index
Next frame index that vector arguments were last enqueued to last time this node ran.
Definition: node.h:513
static ip_csum_t ip_csum_sub_even(ip_csum_t c, ip_csum_t x)
Definition: ip_packet.h:209
IPv6 to IPv4 translation.
#define u8_ptr_add(ptr, index)
Definition: ip.h:68
static void * vlib_add_trace(vlib_main_t *vm, vlib_node_runtime_t *r, vlib_buffer_t *b, u32 n_data_bytes)
Definition: trace_funcs.h:57
struct _vlib_node_registration vlib_node_registration_t
vlib_combined_counter_main_t session_counters
Session counters.
Definition: nat66.h:57
#define foreach_nat66_in2out_error
Definition: nat66_in2out.c:46
#define FIB_NODE_INDEX_INVALID
Definition: fib_types.h:31
static uword nat66_in2out_node_fn(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: nat66_in2out.c:113
VLIB_NODE_FUNCTION_MULTIARCH(nat66_in2out_node, nat66_in2out_node_fn)
u32 outside_fib_index
Definition: nat66.h:60
u64 uword
Definition: types.h:112
static void * vlib_frame_vector_args(vlib_frame_t *f)
Get pointer to frame vector data.
Definition: node_funcs.h:267
static u8 * format_nat66_in2out_trace(u8 *s, va_list *args)
Definition: nat66_in2out.c:31
#define vnet_buffer(b)
Definition: buffer.h:344
nat66_static_mapping_t * sm
Static mapping pool.
Definition: nat66.h:51
u16 flags
Copy of main node flags.
Definition: node.h:507
#define VLIB_NODE_FLAG_TRACE
Definition: node.h:310
NAT66 global declarations.
nat66_static_mapping_t * nat66_static_mapping_get(ip6_address_t *addr, u32 fib_index, u8 is_local)
Definition: nat66.c:115
u32 flags
buffer flags: VLIB_BUFFER_FREE_LIST_INDEX_MASK: bits used to store free list index, VLIB_BUFFER_IS_TRACED: trace this buffer.
Definition: buffer.h:116
static vlib_buffer_t * vlib_get_buffer(vlib_main_t *vm, u32 buffer_index)
Translate buffer index into buffer pointer.
Definition: buffer_funcs.h:58
static u16 ip_csum_fold(ip_csum_t c)
Definition: ip_packet.h:237
Definition: defs.h:46
static ip_csum_t ip_csum_add_even(ip_csum_t c, ip_csum_t x)
Definition: ip_packet.h:192
ip6_address_t dst_address
Definition: ip6_packet.h:378