FD.io VPP  v21.10.1-2-g0a485f517
Vector Packet Processing
nat44_ed_classify.c
Go to the documentation of this file.
1 /*
2  * Copyright (c) 2018 Cisco and/or its affiliates.
3  * Licensed under the Apache License, Version 2.0 (the "License");
4  * you may not use this file except in compliance with the License.
5  * You may obtain a copy of the License at:
6  *
7  * http://www.apache.org/licenses/LICENSE-2.0
8  *
9  * Unless required by applicable law or agreed to in writing, software
10  * distributed under the License is distributed on an "AS IS" BASIS,
11  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12  * See the License for the specific language governing permissions and
13  * limitations under the License.
14  */
15 /**
16  * @file
17  * @brief Classify for one armed NAT44 (in+out interface)
18  */
19 
20 #include <vlib/vlib.h>
21 #include <vnet/vnet.h>
22 #include <vnet/fib/ip4_fib.h>
23 
24 #include <nat/nat44-ed/nat44_ed.h>
26 
27 #define foreach_nat44_classify_error \
28 _(NEXT_IN2OUT, "next in2out") \
29 _(NEXT_OUT2IN, "next out2in") \
30 _(FRAG_CACHED, "fragment cached")
31 
32 typedef enum
33 {
34 #define _(sym,str) NAT44_CLASSIFY_ERROR_##sym,
36 #undef _
39 
40 typedef enum
41 {
47 
48 typedef struct
49 {
53 
54 static u8 *
55 format_nat44_classify_trace (u8 * s, va_list * args)
56 {
57  CLIB_UNUSED (vlib_main_t * vm) = va_arg (*args, vlib_main_t *);
58  CLIB_UNUSED (vlib_node_t * node) = va_arg (*args, vlib_node_t *);
59  nat44_classify_trace_t *t = va_arg (*args, nat44_classify_trace_t *);
60  char *next;
61 
62  if (t->cached)
63  s = format (s, "nat44-classify: fragment cached");
64  else
65  {
66  next = t->next_in2out ? "nat44-ed-in2out" : "nat44-ed-out2in";
67  s = format (s, "nat44-classify: next %s", next);
68  }
69 
70  return s;
71 }
72 
73 static inline uword
77 {
78  u32 n_left_from, *from, *to_next;
80  snat_main_t *sm = &snat_main;
82  u32 next_in2out = 0, next_out2in = 0;
83 
85  n_left_from = frame->n_vectors;
86  next_index = node->cached_next_index;
87 
88  while (n_left_from > 0)
89  {
90  u32 n_left_to_next;
91 
92  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
93 
94  while (n_left_from > 0 && n_left_to_next > 0)
95  {
96  u32 bi0;
97  vlib_buffer_t *b0;
99  ip4_header_t *ip0;
100  snat_address_t *ap;
101  clib_bihash_kv_8_8_t kv0, value0;
102 
103  /* speculatively enqueue b0 to the current next frame */
104  bi0 = from[0];
105  to_next[0] = bi0;
106  from += 1;
107  to_next += 1;
108  n_left_from -= 1;
109  n_left_to_next -= 1;
110 
111  b0 = vlib_get_buffer (vm, bi0);
112  ip0 = vlib_buffer_get_current (b0);
113 
114  vec_foreach (ap, sm->addresses)
115  {
116  if (ip0->dst_address.as_u32 == ap->addr.as_u32)
117  {
118  next0 = NAT_NEXT_OUT2IN_CLASSIFY;
119  goto enqueue0;
120  }
121  }
122 
124  {
125  init_nat_k (&kv0, ip0->dst_address, 0, 0, 0);
126  /* try to classify the fragment based on IP header alone */
127  if (!clib_bihash_search_8_8 (&sm->static_mapping_by_external,
128  &kv0, &value0))
129  {
130  m = pool_elt_at_index (sm->static_mappings, value0.value);
131  if (m->local_addr.as_u32 != m->external_addr.as_u32)
132  next0 = NAT_NEXT_OUT2IN_CLASSIFY;
133  goto enqueue0;
134  }
135  init_nat_k (&kv0, ip0->dst_address,
136  vnet_buffer (b0)->ip.reass.l4_dst_port, 0,
138  if (!clib_bihash_search_8_8
139  (&sm->static_mapping_by_external, &kv0, &value0))
140  {
141  m = pool_elt_at_index (sm->static_mappings, value0.value);
142  if (m->local_addr.as_u32 != m->external_addr.as_u32)
143  next0 = NAT_NEXT_OUT2IN_CLASSIFY;
144  }
145  }
146 
147  enqueue0:
148  if (PREDICT_FALSE ((node->flags & VLIB_NODE_FLAG_TRACE)
149  && (b0->flags & VLIB_BUFFER_IS_TRACED)))
150  {
152  vlib_add_trace (vm, node, b0, sizeof (*t));
153  t->cached = 0;
154  t->next_in2out = next0 == NAT_NEXT_IN2OUT_CLASSIFY ? 1 : 0;
155  }
156 
157  next_in2out += next0 == NAT_NEXT_IN2OUT_CLASSIFY;
158  next_out2in += next0 == NAT_NEXT_OUT2IN_CLASSIFY;
159 
160  /* verify speculative enqueue, maybe switch current next frame */
162  to_next, n_left_to_next,
163  bi0, next0);
164  }
165 
166  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
167  }
168 
169  vlib_node_increment_counter (vm, node->node_index,
170  NAT44_CLASSIFY_ERROR_NEXT_IN2OUT, next_in2out);
171  vlib_node_increment_counter (vm, node->node_index,
172  NAT44_CLASSIFY_ERROR_NEXT_OUT2IN, next_out2in);
173  return frame->n_vectors;
174 }
175 
176 static inline uword
180 {
181  u32 n_left_from, *from, *to_next;
183  snat_main_t *sm = &snat_main;
185  u32 next_in2out = 0, next_out2in = 0;
186 
188  n_left_from = frame->n_vectors;
189  next_index = node->cached_next_index;
190 
191  while (n_left_from > 0)
192  {
193  u32 n_left_to_next;
194 
195  vlib_get_next_frame (vm, node, next_index, to_next, n_left_to_next);
196 
197  while (n_left_from > 0 && n_left_to_next > 0)
198  {
199  u32 bi0;
200  vlib_buffer_t *b0;
202  u32 sw_if_index0, rx_fib_index0;
203  ip4_header_t *ip0;
204  snat_address_t *ap;
205  clib_bihash_kv_8_8_t kv0, value0;
206  clib_bihash_kv_16_8_t ed_kv0, ed_value0;
207 
208  /* speculatively enqueue b0 to the current next frame */
209  bi0 = from[0];
210  to_next[0] = bi0;
211  from += 1;
212  to_next += 1;
213  n_left_from -= 1;
214  n_left_to_next -= 1;
215 
216  b0 = vlib_get_buffer (vm, bi0);
217  ip0 = vlib_buffer_get_current (b0);
218 
219  u32 arc_next;
220  vnet_feature_next (&arc_next, b0);
221  vnet_buffer2 (b0)->nat.arc_next = arc_next;
222 
223  if (ip0->protocol != IP_PROTOCOL_ICMP)
224  {
225  /* process leading fragment/whole packet (with L4 header) */
226  sw_if_index0 = vnet_buffer (b0)->sw_if_index[VLIB_RX];
227  rx_fib_index0 =
229  sw_if_index0);
230  init_ed_k (&ed_kv0, ip0->src_address,
231  vnet_buffer (b0)->ip.reass.l4_src_port,
232  ip0->dst_address,
233  vnet_buffer (b0)->ip.reass.l4_dst_port,
234  rx_fib_index0, ip0->protocol);
235  /* process whole packet */
236  if (!clib_bihash_search_16_8 (&sm->flow_hash, &ed_kv0,
237  &ed_value0))
238  {
239  ASSERT (vm->thread_index ==
240  ed_value_get_thread_index (&ed_value0));
243  snat_session_t *s = pool_elt_at_index (
244  tsm->sessions, ed_value_get_session_index (&ed_value0));
245  clib_bihash_kv_16_8_t i2o_kv;
246  nat_6t_flow_to_ed_k (&i2o_kv, &s->i2o);
247  vnet_buffer2 (b0)->nat.cached_session_index =
248  ed_value_get_session_index (&ed_value0);
249  if (i2o_kv.key[0] == ed_kv0.key[0] &&
250  i2o_kv.key[1] == ed_kv0.key[1])
251  {
253  }
254  else
255  {
257  }
258 
259  goto enqueue0;
260  }
261  /* session doesn't exist so continue in code */
262  }
263 
264  vec_foreach (ap, sm->addresses)
265  {
266  if (ip0->dst_address.as_u32 == ap->addr.as_u32)
267  {
269  goto enqueue0;
270  }
271  }
272 
274  {
275  init_nat_k (&kv0, ip0->dst_address, 0, 0, 0);
276  /* try to classify the fragment based on IP header alone */
277  if (!clib_bihash_search_8_8 (&sm->static_mapping_by_external,
278  &kv0, &value0))
279  {
280  m = pool_elt_at_index (sm->static_mappings, value0.value);
281  if (m->local_addr.as_u32 != m->external_addr.as_u32)
283  goto enqueue0;
284  }
285  init_nat_k (&kv0, ip0->dst_address,
286  vnet_buffer (b0)->ip.reass.l4_dst_port, 0,
288  if (!clib_bihash_search_8_8
289  (&sm->static_mapping_by_external, &kv0, &value0))
290  {
291  m = pool_elt_at_index (sm->static_mappings, value0.value);
292  if (m->local_addr.as_u32 != m->external_addr.as_u32)
294  }
295  }
296 
297  enqueue0:
298  if (PREDICT_FALSE ((node->flags & VLIB_NODE_FLAG_TRACE)
299  && (b0->flags & VLIB_BUFFER_IS_TRACED)))
300  {
302  vlib_add_trace (vm, node, b0, sizeof (*t));
303  t->cached = 0;
304  t->next_in2out = next0 == NAT_NEXT_IN2OUT_ED_FAST_PATH ? 1 : 0;
305  }
306 
307  next_in2out += next0 == NAT_NEXT_IN2OUT_ED_FAST_PATH;
308  next_out2in += next0 == NAT_NEXT_OUT2IN_ED_FAST_PATH;
309 
310  /* verify speculative enqueue, maybe switch current next frame */
312  to_next, n_left_to_next,
313  bi0, next0);
314  }
315 
316  vlib_put_next_frame (vm, node, next_index, n_left_to_next);
317  }
318 
319  vlib_node_increment_counter (vm, node->node_index,
320  NAT44_CLASSIFY_ERROR_NEXT_IN2OUT, next_in2out);
321  vlib_node_increment_counter (vm, node->node_index,
322  NAT44_CLASSIFY_ERROR_NEXT_OUT2IN, next_out2in);
323  return frame->n_vectors;
324 }
325 
329 {
331 }
332 
334  .name = "nat44-ed-classify",
335  .vector_size = sizeof (u32),
336  .sibling_of = "nat-default",
337  .format_trace = format_nat44_classify_trace,
339 };
340 
344 {
346 }
347 
349  .name = "nat44-handoff-classify",
350  .vector_size = sizeof (u32),
351  .sibling_of = "nat-default",
352  .format_trace = format_nat44_classify_trace,
354 };
355 
356 /*
357  * fd.io coding-style-patch-verification: ON
358  *
359  * Local Variables:
360  * eval: (c-set-style "gnu")
361  * End:
362  */
vlib.h
ed_value_get_thread_index
static u32 ed_value_get_thread_index(clib_bihash_kv_16_8_t *value)
Definition: nat44_ed_inlines.h:140
nat44_ed_classify_node
vlib_node_registration_t nat44_ed_classify_node
(constructor) VLIB_REGISTER_NODE (nat44_ed_classify_node)
Definition: nat44_ed_classify.c:333
ed_value_get_session_index
static u32 ed_value_get_session_index(clib_bihash_kv_16_8_t *value)
Definition: nat44_ed_inlines.h:146
snat_main_s::static_mappings
snat_static_mapping_t * static_mappings
Definition: nat44_ed.h:531
frame
vlib_main_t vlib_node_runtime_t vlib_frame_t * frame
Definition: nat44_ei.c:3048
nat_6t_flow_to_ed_k
static_always_inline void nat_6t_flow_to_ed_k(clib_bihash_kv_16_8_t *kv, nat_6t_flow_t *f)
Definition: nat44_ed_inlines.h:301
next_index
nat44_ei_hairpin_src_next_t next_index
Definition: nat44_ei_hairpinning.c:412
vlib_get_buffer
static vlib_buffer_t * vlib_get_buffer(vlib_main_t *vm, u32 buffer_index)
Translate buffer index into buffer pointer.
Definition: buffer_funcs.h:111
pool_elt_at_index
#define pool_elt_at_index(p, i)
Returns pointer to element at given index.
Definition: pool.h:549
NAT_NEXT_IN2OUT_CLASSIFY
@ NAT_NEXT_IN2OUT_CLASSIFY
Definition: nat44_ed.h:83
ip_proto_to_nat_proto
static nat_protocol_t ip_proto_to_nat_proto(u8 ip_proto)
Common NAT inline functions.
Definition: inlines.h:24
next
u16 * next
Definition: nat44_ei_out2in.c:718
VLIB_NODE_TYPE_INTERNAL
@ VLIB_NODE_TYPE_INTERNAL
Definition: node.h:72
node
vlib_main_t vlib_node_runtime_t * node
Definition: nat44_ei.c:3047
clib_bihash_kv_8_8_t::value
u64 value
the value
Definition: bihash_8_8.h:44
ip4_address_t::as_u32
u32 as_u32
Definition: ip4_packet.h:57
vm
vlib_main_t * vm
X-connect all packets from the HOST to the PHY.
Definition: nat44_ei.c:3047
VLIB_RX
@ VLIB_RX
Definition: defs.h:46
nat44_handoff_classify_node_fn_inline
static uword nat44_handoff_classify_node_fn_inline(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: nat44_ed_classify.c:74
format_nat44_classify_trace
static u8 * format_nat44_classify_trace(u8 *s, va_list *args)
Definition: nat44_ed_classify.c:55
vnet_buffer2
#define vnet_buffer2(b)
Definition: buffer.h:505
snat_static_mapping_t::local_addr
ip4_address_t local_addr
Definition: nat44_ed.h:418
snat_main_s::addresses
snat_address_t * addresses
Definition: nat44_ed.h:545
vlib_frame_t
Definition: node.h:372
snat_main_s::static_mapping_by_external
clib_bihash_8_8_t static_mapping_by_external
Definition: nat44_ed.h:528
NAT44_CLASSIFY_NEXT_DROP
@ NAT44_CLASSIFY_NEXT_DROP
Definition: nat44_ed_classify.c:44
ip4_header_t
Definition: ip4_packet.h:87
nat44_classify_error_t
nat44_classify_error_t
Definition: nat44_ed_classify.c:32
snat_address_t
Definition: nat44_ed.h:355
snat_main_s::per_thread_data
snat_main_per_thread_data_t * per_thread_data
Definition: nat44_ed.h:522
VLIB_NODE_FN
#define VLIB_NODE_FN(node)
Definition: node.h:202
snat_main_s::flow_hash
clib_bihash_16_8_t flow_hash
Definition: nat44_ed.h:538
foreach_nat44_classify_error
#define foreach_nat44_classify_error
Definition: nat44_ed_classify.c:27
CLIB_UNUSED
#define CLIB_UNUSED(x)
Definition: clib.h:90
vnet_buffer
#define vnet_buffer(b)
Definition: buffer.h:441
NAT_NEXT_IN2OUT_ED_FAST_PATH
@ NAT_NEXT_IN2OUT_ED_FAST_PATH
Definition: nat44_ed.h:77
VLIB_NODE_FLAG_TRACE
#define VLIB_NODE_FLAG_TRACE
Definition: node.h:291
PREDICT_FALSE
#define PREDICT_FALSE(x)
Definition: clib.h:124
NAT_NEXT_OUT2IN_ED_FAST_PATH
@ NAT_NEXT_OUT2IN_ED_FAST_PATH
Definition: nat44_ed.h:81
vnet_feature_next
static_always_inline void vnet_feature_next(u32 *next0, vlib_buffer_t *b0)
Definition: feature.h:322
nat44_classify_next_t
nat44_classify_next_t
Definition: nat44_ed_classify.c:40
vlib_frame_vector_args
static void * vlib_frame_vector_args(vlib_frame_t *f)
Get pointer to frame vector data.
Definition: node_funcs.h:301
uword
u64 uword
Definition: types.h:112
nat44_handoff_classify_node
vlib_node_registration_t nat44_handoff_classify_node
(constructor) VLIB_REGISTER_NODE (nat44_handoff_classify_node)
Definition: nat44_ed_classify.c:348
nat44_ed_classify_node_fn_inline
static uword nat44_ed_classify_node_fn_inline(vlib_main_t *vm, vlib_node_runtime_t *node, vlib_frame_t *frame)
Definition: nat44_ed_classify.c:177
NAT44_CLASSIFY_N_NEXT
@ NAT44_CLASSIFY_N_NEXT
Definition: nat44_ed_classify.c:45
vlib_main_t::thread_index
u32 thread_index
Definition: main.h:215
init_ed_k
static void init_ed_k(clib_bihash_kv_16_8_t *kv, ip4_address_t l_addr, u16 l_port, ip4_address_t r_addr, u16 r_port, u32 fib_index, u8 proto)
Definition: nat44_ed_inlines.h:122
vlib_node_increment_counter
static void vlib_node_increment_counter(vlib_main_t *vm, u32 node_index, u32 counter_index, u64 increment)
Definition: node_funcs.h:1244
nat44_classify_trace_t::next_in2out
u8 next_in2out
Definition: nat44_ed_classify.c:50
FIB_PROTOCOL_IP4
@ FIB_PROTOCOL_IP4
Definition: fib_types.h:36
snat_main_s
Definition: nat44_ed.h:513
snat_main_per_thread_data_t::sessions
snat_session_t * sessions
Definition: nat44_ed.h:471
vlib_node_registration_t
struct _vlib_node_registration vlib_node_registration_t
ip4_header_t::dst_address
ip4_address_t dst_address
Definition: ip4_packet.h:125
vlib_validate_buffer_enqueue_x1
#define vlib_validate_buffer_enqueue_x1(vm, node, next_index, to_next, n_left_to_next, bi0, next0)
Finish enqueueing one buffer forward in the graph.
Definition: buffer_node.h:224
ip4_header_t::src_address
ip4_address_t src_address
Definition: ip4_packet.h:125
nat44_ed_inlines.h
clib_bihash_kv_16_8_t
Definition: bihash_16_8.h:40
format
description fragment has unexpected format
Definition: map.api:433
ASSERT
#define ASSERT(truth)
Definition: error_bootstrap.h:69
vlib_put_next_frame
vlib_put_next_frame(vm, node, next_index, 0)
fib_table_get_index_for_sw_if_index
u32 fib_table_get_index_for_sw_if_index(fib_protocol_t proto, u32 sw_if_index)
Get the index of the FIB bound to the interface.
Definition: fib_table.c:1003
clib_bihash_kv_16_8_t::key
u64 key[2]
Definition: bihash_16_8.h:42
u32
unsigned int u32
Definition: types.h:88
nat44_classify_trace_t
Definition: nat44_ed_classify.c:48
vec_foreach
#define vec_foreach(var, vec)
Vector iterator.
Definition: vec_bootstrap.h:213
nat44_ed.h
clib_bihash_kv_8_8_t
8 octet key, 8 octet key value pair
Definition: bihash_8_8.h:41
pool_elts
static uword pool_elts(void *v)
Number of active elements in a pool.
Definition: pool.h:127
ip4_fib.h
NAT44_CLASSIFY_NEXT_IN2OUT
@ NAT44_CLASSIFY_NEXT_IN2OUT
Definition: nat44_ed_classify.c:42
vlib_main_t
Definition: main.h:102
snat_main
snat_main_t snat_main
Definition: nat44_ed.c:41
vlib_node_t
Definition: node.h:247
NAT_NEXT_OUT2IN_CLASSIFY
@ NAT_NEXT_OUT2IN_CLASSIFY
Definition: nat44_ed.h:84
vlib_add_trace
void * vlib_add_trace(vlib_main_t *vm, vlib_node_runtime_t *r, vlib_buffer_t *b, u32 n_data_bytes)
Definition: trace.c:628
u8
unsigned char u8
Definition: types.h:56
vlib_buffer_get_current
static void * vlib_buffer_get_current(vlib_buffer_t *b)
Get pointer to current data to process.
Definition: buffer.h:257
ip
vl_api_address_t ip
Definition: l2.api:558
NAT44_CLASSIFY_N_ERROR
@ NAT44_CLASSIFY_N_ERROR
Definition: nat44_ed_classify.c:37
snat_static_mapping_t::external_addr
ip4_address_t external_addr
Definition: nat44_ed.h:420
NAT44_CLASSIFY_NEXT_OUT2IN
@ NAT44_CLASSIFY_NEXT_OUT2IN
Definition: nat44_ed_classify.c:43
snat_static_mapping_t
Definition: nat44_ed.h:413
snat_address_t::addr
ip4_address_t addr
Definition: nat44_ed.h:357
vnet.h
snat_main_per_thread_data_t
Definition: nat44_ed.h:468
vlib_node_runtime_t
Definition: node.h:454
from
from
Definition: nat44_ei_hairpinning.c:415
nat44_classify_trace_t::cached
u8 cached
Definition: nat44_ed_classify.c:51
vlib_get_next_frame
#define vlib_get_next_frame(vm, node, next_index, vectors, n_vectors_left)
Get pointer to next frame vector data by (vlib_node_runtime_t, next_index).
Definition: node_funcs.h:395
init_nat_k
static void init_nat_k(clib_bihash_kv_8_8_t *kv, ip4_address_t addr, u16 port, u32 fib_index, nat_protocol_t proto)
Definition: nat44_ei_inlines.h:56
n_left_from
n_left_from
Definition: nat44_ei_hairpinning.c:416
type
vl_api_fib_path_type_t type
Definition: fib_types.api:123
ip4_header_t::protocol
u8 protocol
Definition: ip4_packet.h:115
vlib_buffer_t::flags
u32 flags
buffer flags: VLIB_BUFFER_FREE_LIST_INDEX_MASK: bits used to store free list index,...
Definition: buffer.h:133
vlib_buffer_t
VLIB buffer representation.
Definition: buffer.h:111
VLIB_REGISTER_NODE
#define VLIB_REGISTER_NODE(x,...)
Definition: node.h:169