FD.io VPP  v21.06-3-gbb25fbf28
Vector Packet Processing
ip_source_and_port_range_check.h
Go to the documentation of this file.
1 /*
2  * Copyright (c) 2015 Cisco and/or its affiliates.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at:
6  *
7  * http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 
16 #ifndef included_ip_ip_source_and_port_range_check_h
17 #define included_ip_ip_source_and_port_range_check_h
18 
19 
20 typedef struct
21 {
22  /* convenience */
26 
28 
29 typedef enum
30 {
37 
38 typedef struct
39 {
42 
43 #define IP_SOURCE_AND_PORT_RANGE_CHECK_RANGE_LIMIT VLIB_BUFFER_PRE_DATA_SIZE/(2*sizeof(u16x8));
44 
45 typedef struct
46 {
47  union
48  {
50  u16 as_u16[8];
51  };
52 } u16x8vec_t;
53 
54 typedef struct
55 {
59 
60 /**
61  * @brief The number of supported ranges per-data path object.
62  * If more ranges are required, bump this number.
63  */
64 #define N_PORT_RANGES_PER_DPO 64
65 #define N_RANGES_PER_BLOCK (sizeof(u16x8vec_t)/2)
66 #define N_BLOCKS_PER_DPO (N_PORT_RANGES_PER_DPO/N_RANGES_PER_BLOCK)
67 
68 /**
69  * @brief
70  * The object that is in the data-path to perform the check.
71  *
72  * Some trade-offs here; memory vs performance.
73  *
74  * performance:
75  * the principle factor is d-cache line misses/hits.
76  * so we want the data layout to minimise the d-cache misses. This
77  * means not following dependent reads. i.e. not doing
78  *
79  * struct B {
80  * u16 n_ranges;
81  * range_t *ranges; // vector of ranges.
82  * }
83  *
84  * so to read ranges[0] we would first d-cache miss on the address
85  * of the object of type B, for which we would need to wait before we
86  * can get the address of B->ranges.
87  * So this layout is better:
88  *
89  * struct B {
90  * u16 n_ranges;
91  * range_t ranges[N];
92  * }
93  *
94  * memory:
95  * the latter layout above is more memory hungry. And N needs to be:
96  * 1 - sized for the maximum required
97  * 2 - fixed, so that objects of type B can be pool allocated and so
98  * 'get'-able using an index.
99  * An option over fixed might be to allocate contiguous chunk from
100  * the pool (like we used to do for multi-path adjs).
101  */
103 {
104  /**
105  * Required for pool_get_aligned
106  */
107  CLIB_CACHE_LINE_ALIGN_MARK (cacheline0);
108 
109  /**
110  * The number of blocks from the 'block' array below
111  * that have ranges configured. We keep this count so that in the data-path
112  * we can limit the loop to be only over the blocks we need
113  */
115 
116  /**
117  * The total number of free ranges from all blocks.
118  * Used to prevent overrun of the ranges available.
119  */
121 
122  /**
123  * the fixed size array of ranges
124  */
127 
129  u32 length,
130  u32 vrf_id,
131  u16 * low_ports,
132  u16 * hi_ports, int is_add);
133 
134 // This will be moved to another file in another patch -- for API freeze
136  u32 length,
137  u32 vrf_id,
138  u16 * low_ports,
139  u16 * hi_ports, int is_add);
140 
142  u32 * fib_index,
143  u32 sw_if_index, u32 is_add);
144 
145 #endif /* included ip_source_and_port_range_check_h */
146 
147 /*
148  * fd.io coding-style-patch-verification: ON
149  *
150  * Local Variables:
151  * eval: (c-set-style "gnu")
152  * End:
153  */
IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_IN
@ IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_IN
Definition: ip_source_and_port_range_check.h:34
protocol_port_range_dpo_t_::blocks
protocol_port_range_t blocks[N_BLOCKS_PER_DPO]
the fixed size array of ranges
Definition: ip_source_and_port_range_check.h:125
IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT
@ IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_OUT
Definition: ip_source_and_port_range_check.h:31
ip_source_and_port_range_check_config_t
Definition: ip_source_and_port_range_check.h:38
protocol_port_range_dpo_t_::CLIB_CACHE_LINE_ALIGN_MARK
CLIB_CACHE_LINE_ALIGN_MARK(cacheline0)
Required for pool_get_aligned.
u16x8vec_t::as_u16x8
u16x8 as_u16x8
Definition: ip_source_and_port_range_check.h:49
u16
unsigned short u16
Definition: types.h:57
vm
vlib_main_t * vm
X-connect all packets from the HOST to the PHY.
Definition: nat44_ei.c:3047
set_ip_source_and_port_range_check
int set_ip_source_and_port_range_check(vlib_main_t *vm, u32 *fib_index, u32 sw_if_index, u32 is_add)
Definition: ip4_source_and_port_range_check.c:622
protocol_port_range_t
Definition: ip_source_and_port_range_check.h:54
protocol_port_range_dpo_t_::n_used_blocks
u16 n_used_blocks
The number of blocks from the 'block' array below that have ranges configured.
Definition: ip_source_and_port_range_check.h:114
source_range_check_main
source_range_check_main_t source_range_check_main
Definition: ip4_source_and_port_range_check.c:21
IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS
@ IP_SOURCE_AND_PORT_RANGE_CHECK_N_PROTOCOLS
Definition: ip_source_and_port_range_check.h:35
ip6_source_and_port_range_check_add_del
int ip6_source_and_port_range_check_add_del(ip6_address_t *address, u32 length, u32 vrf_id, u16 *low_ports, u16 *hi_ports, int is_add)
Definition: ip4_source_and_port_range_check.c:1123
address
manual_print typedef address
Definition: ip_types.api:96
source_range_check_main_t::vnet_main
vnet_main_t * vnet_main
Definition: ip_source_and_port_range_check.h:24
ip4_address_t
Definition: ip4_packet.h:50
protocol_port_range_dpo_t_
The object that is in the data-path to perform the check.
Definition: ip_source_and_port_range_check.h:102
vnet_main_t
Definition: vnet.h:76
u16x8
_mm_packus_epi16 u16x8
Definition: vector_sse42.h:196
source_range_check_main_t::vlib_main
vlib_main_t * vlib_main
Definition: ip_source_and_port_range_check.h:23
u32
unsigned int u32
Definition: types.h:88
ip_source_and_port_range_check_protocol_t
ip_source_and_port_range_check_protocol_t
Definition: ip_source_and_port_range_check.h:29
protocol_port_range_t::low
u16x8vec_t low
Definition: ip_source_and_port_range_check.h:56
protocol_port_range_t::hi
u16x8vec_t hi
Definition: ip_source_and_port_range_check.h:57
length
char const int length
Definition: cJSON.h:163
vlib_main_t
Definition: main.h:102
protocol_port_range_dpo_t
struct protocol_port_range_dpo_t_ protocol_port_range_dpo_t
The object that is in the data-path to perform the check.
protocol_port_range_dpo_t_::n_free_ranges
u16 n_free_ranges
The total number of free ranges from all blocks.
Definition: ip_source_and_port_range_check.h:120
IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT
@ IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_UDP_OUT
Definition: ip_source_and_port_range_check.h:32
vrf_id
u32 vrf_id
Definition: nat44_ed.api:1053
source_range_check_main_t
Definition: ip_source_and_port_range_check.h:20
sw_if_index
vl_api_interface_index_t sw_if_index
Definition: wireguard.api:34
u16x8vec_t
Definition: ip_source_and_port_range_check.h:45
N_BLOCKS_PER_DPO
#define N_BLOCKS_PER_DPO
Definition: ip_source_and_port_range_check.h:66
ip4_source_and_port_range_check_add_del
int ip4_source_and_port_range_check_add_del(ip4_address_t *address, u32 length, u32 vrf_id, u16 *low_ports, u16 *hi_ports, int is_add)
Definition: ip4_source_and_port_range_check.c:1141
IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_IN
@ IP_SOURCE_AND_PORT_RANGE_CHECK_PROTOCOL_TCP_IN
Definition: ip_source_and_port_range_check.h:33