xref: /dpdk/examples/ipsec-secgw/rt.c (revision 3998e2a0)
1*3998e2a0SBruce Richardson /* SPDX-License-Identifier: BSD-3-Clause
2*3998e2a0SBruce Richardson  * Copyright(c) 2016 Intel Corporation
3d299106eSSergio Gonzalez Monroy  */
4d299106eSSergio Gonzalez Monroy 
5d299106eSSergio Gonzalez Monroy /*
6d299106eSSergio Gonzalez Monroy  * Routing Table (RT)
7d299106eSSergio Gonzalez Monroy  */
855d4c775SDaniel Mrzyglod #include <sys/types.h>
9d299106eSSergio Gonzalez Monroy #include <rte_lpm.h>
10906257e9SSergio Gonzalez Monroy #include <rte_lpm6.h>
11d299106eSSergio Gonzalez Monroy #include <rte_errno.h>
12906257e9SSergio Gonzalez Monroy #include <rte_ip.h>
13d299106eSSergio Gonzalez Monroy 
14d299106eSSergio Gonzalez Monroy #include "ipsec.h"
150d547ed0SFan Zhang #include "parser.h"
16d299106eSSergio Gonzalez Monroy 
17906257e9SSergio Gonzalez Monroy #define RT_IPV4_MAX_RULES	1024
18906257e9SSergio Gonzalez Monroy #define RT_IPV6_MAX_RULES	1024
19d299106eSSergio Gonzalez Monroy 
20906257e9SSergio Gonzalez Monroy struct ip4_route {
21d299106eSSergio Gonzalez Monroy 	uint32_t ip;
22d299106eSSergio Gonzalez Monroy 	uint8_t depth;
23d299106eSSergio Gonzalez Monroy 	uint8_t if_out;
24d299106eSSergio Gonzalez Monroy };
25d299106eSSergio Gonzalez Monroy 
26906257e9SSergio Gonzalez Monroy struct ip6_route {
27906257e9SSergio Gonzalez Monroy 	uint8_t ip[16];
28906257e9SSergio Gonzalez Monroy 	uint8_t depth;
29906257e9SSergio Gonzalez Monroy 	uint8_t if_out;
30d299106eSSergio Gonzalez Monroy };
31d299106eSSergio Gonzalez Monroy 
320d547ed0SFan Zhang struct ip4_route rt_ip4[RT_IPV4_MAX_RULES];
330d547ed0SFan Zhang uint32_t nb_rt_ip4;
34d299106eSSergio Gonzalez Monroy 
350d547ed0SFan Zhang struct ip6_route rt_ip6[RT_IPV4_MAX_RULES];
360d547ed0SFan Zhang uint32_t nb_rt_ip6;
37d299106eSSergio Gonzalez Monroy 
38d299106eSSergio Gonzalez Monroy void
parse_rt_tokens(char ** tokens,uint32_t n_tokens,struct parse_status * status)390d547ed0SFan Zhang parse_rt_tokens(char **tokens, uint32_t n_tokens,
400d547ed0SFan Zhang 	struct parse_status *status)
410d547ed0SFan Zhang {
420d547ed0SFan Zhang 	uint32_t ti;
430d547ed0SFan Zhang 	uint32_t *n_rts = NULL;
440d547ed0SFan Zhang 	struct ip4_route *route_ipv4 = NULL;
450d547ed0SFan Zhang 	struct ip6_route *route_ipv6 = NULL;
460d547ed0SFan Zhang 
470d547ed0SFan Zhang 	if (strcmp(tokens[0], "ipv4") == 0) {
480d547ed0SFan Zhang 		n_rts = &nb_rt_ip4;
490d547ed0SFan Zhang 		route_ipv4 = &rt_ip4[*n_rts];
500d547ed0SFan Zhang 
510d547ed0SFan Zhang 		APP_CHECK(*n_rts <= RT_IPV4_MAX_RULES - 1, status,
520d547ed0SFan Zhang 			"too many rt rules, abort insertion\n");
530d547ed0SFan Zhang 		if (status->status < 0)
540d547ed0SFan Zhang 			return;
550d547ed0SFan Zhang 
560d547ed0SFan Zhang 	} else if (strcmp(tokens[0], "ipv6") == 0) {
570d547ed0SFan Zhang 		n_rts = &nb_rt_ip6;
580d547ed0SFan Zhang 		route_ipv6 = &rt_ip6[*n_rts];
590d547ed0SFan Zhang 
600d547ed0SFan Zhang 		APP_CHECK(*n_rts <= RT_IPV6_MAX_RULES - 1, status,
610d547ed0SFan Zhang 			"too many rt rules, abort insertion\n");
620d547ed0SFan Zhang 		if (status->status < 0)
630d547ed0SFan Zhang 			return;
640d547ed0SFan Zhang 	} else {
650d547ed0SFan Zhang 		APP_CHECK(0, status, "unrecognized input \"%s\"",
660d547ed0SFan Zhang 			tokens[0]);
670d547ed0SFan Zhang 		return;
680d547ed0SFan Zhang 	}
690d547ed0SFan Zhang 
700d547ed0SFan Zhang 	for (ti = 1; ti < n_tokens; ti++) {
710d547ed0SFan Zhang 		if (strcmp(tokens[ti], "dst") == 0) {
720d547ed0SFan Zhang 			INCREMENT_TOKEN_INDEX(ti, n_tokens, status);
730d547ed0SFan Zhang 			if (status->status < 0)
740d547ed0SFan Zhang 				return;
750d547ed0SFan Zhang 
760d547ed0SFan Zhang 			if (route_ipv4 != NULL) {
770d547ed0SFan Zhang 				struct in_addr ip;
780d547ed0SFan Zhang 				uint32_t depth = 0;
790d547ed0SFan Zhang 
800d547ed0SFan Zhang 				APP_CHECK(parse_ipv4_addr(tokens[ti],
810d547ed0SFan Zhang 					&ip, &depth) == 0, status,
820d547ed0SFan Zhang 					"unrecognized input \"%s\", "
830d547ed0SFan Zhang 					"expect valid ipv4 addr",
840d547ed0SFan Zhang 					tokens[ti]);
850d547ed0SFan Zhang 				if (status->status < 0)
860d547ed0SFan Zhang 					return;
870d547ed0SFan Zhang 				route_ipv4->ip = rte_bswap32(
880d547ed0SFan Zhang 					(uint32_t)ip.s_addr);
890d547ed0SFan Zhang 				route_ipv4->depth = (uint8_t)depth;
900d547ed0SFan Zhang 			} else {
910d547ed0SFan Zhang 				struct in6_addr ip;
920d547ed0SFan Zhang 				uint32_t depth;
930d547ed0SFan Zhang 
940d547ed0SFan Zhang 				APP_CHECK(parse_ipv6_addr(tokens[ti],
950d547ed0SFan Zhang 					&ip, &depth) == 0, status,
960d547ed0SFan Zhang 					"unrecognized input \"%s\", "
970d547ed0SFan Zhang 					"expect valid ipv6 address",
980d547ed0SFan Zhang 					tokens[ti]);
990d547ed0SFan Zhang 				if (status->status < 0)
1000d547ed0SFan Zhang 					return;
1010d547ed0SFan Zhang 				memcpy(route_ipv6->ip, ip.s6_addr, 16);
1020d547ed0SFan Zhang 				route_ipv6->depth = (uint8_t)depth;
1030d547ed0SFan Zhang 			}
1040d547ed0SFan Zhang 		}
1050d547ed0SFan Zhang 
1060d547ed0SFan Zhang 		if (strcmp(tokens[ti], "port") == 0) {
1070d547ed0SFan Zhang 			INCREMENT_TOKEN_INDEX(ti, n_tokens, status);
1080d547ed0SFan Zhang 			if (status->status < 0)
1090d547ed0SFan Zhang 				return;
1100d547ed0SFan Zhang 			APP_CHECK_TOKEN_IS_NUM(tokens, ti, status);
1110d547ed0SFan Zhang 			if (status->status < 0)
1120d547ed0SFan Zhang 				return;
1130d547ed0SFan Zhang 			if (route_ipv4 != NULL)
1140d547ed0SFan Zhang 				route_ipv4->if_out = atoi(tokens[ti]);
1150d547ed0SFan Zhang 			else
1160d547ed0SFan Zhang 				route_ipv6->if_out = atoi(tokens[ti]);
1170d547ed0SFan Zhang 		}
1180d547ed0SFan Zhang 	}
1190d547ed0SFan Zhang 
1200d547ed0SFan Zhang 	*n_rts = *n_rts + 1;
1210d547ed0SFan Zhang }
1220d547ed0SFan Zhang 
1230d547ed0SFan Zhang void
rt_init(struct socket_ctx * ctx,int32_t socket_id)1240d547ed0SFan Zhang rt_init(struct socket_ctx *ctx, int32_t socket_id)
125d299106eSSergio Gonzalez Monroy {
126d299106eSSergio Gonzalez Monroy 	char name[PATH_MAX];
127906257e9SSergio Gonzalez Monroy 	uint32_t i;
128906257e9SSergio Gonzalez Monroy 	int32_t ret;
129d299106eSSergio Gonzalez Monroy 	struct rte_lpm *lpm;
130906257e9SSergio Gonzalez Monroy 	struct rte_lpm6 *lpm6;
131d299106eSSergio Gonzalez Monroy 	char a, b, c, d;
132d299106eSSergio Gonzalez Monroy 	struct rte_lpm_config conf = { 0 };
133906257e9SSergio Gonzalez Monroy 	struct rte_lpm6_config conf6 = { 0 };
134d299106eSSergio Gonzalez Monroy 
135d299106eSSergio Gonzalez Monroy 	if (ctx == NULL)
136d299106eSSergio Gonzalez Monroy 		rte_exit(EXIT_FAILURE, "NULL context.\n");
137d299106eSSergio Gonzalez Monroy 
138906257e9SSergio Gonzalez Monroy 	if (ctx->rt_ip4 != NULL)
139906257e9SSergio Gonzalez Monroy 		rte_exit(EXIT_FAILURE, "IPv4 Routing Table for socket %u "
140906257e9SSergio Gonzalez Monroy 			"already initialized\n", socket_id);
141d299106eSSergio Gonzalez Monroy 
142906257e9SSergio Gonzalez Monroy 	if (ctx->rt_ip6 != NULL)
143906257e9SSergio Gonzalez Monroy 		rte_exit(EXIT_FAILURE, "IPv6 Routing Table for socket %u "
144906257e9SSergio Gonzalez Monroy 			"already initialized\n", socket_id);
145906257e9SSergio Gonzalez Monroy 
1460d547ed0SFan Zhang 	if (nb_rt_ip4 == 0 && nb_rt_ip6 == 0)
1470d547ed0SFan Zhang 		RTE_LOG(WARNING, IPSEC, "No Routing rule specified\n");
1480d547ed0SFan Zhang 
149906257e9SSergio Gonzalez Monroy 	printf("Creating IPv4 Routing Table (RT) context with %u max routes\n",
150d299106eSSergio Gonzalez Monroy 			RT_IPV4_MAX_RULES);
151d299106eSSergio Gonzalez Monroy 
152d299106eSSergio Gonzalez Monroy 	/* create the LPM table */
153906257e9SSergio Gonzalez Monroy 	snprintf(name, sizeof(name), "%s_%u", "rt_ip4", socket_id);
154d299106eSSergio Gonzalez Monroy 	conf.max_rules = RT_IPV4_MAX_RULES;
155d299106eSSergio Gonzalez Monroy 	conf.number_tbl8s = RTE_LPM_TBL8_NUM_ENTRIES;
156d299106eSSergio Gonzalez Monroy 	lpm = rte_lpm_create(name, socket_id, &conf);
157d299106eSSergio Gonzalez Monroy 	if (lpm == NULL)
158906257e9SSergio Gonzalez Monroy 		rte_exit(EXIT_FAILURE, "Unable to create %s LPM table "
159906257e9SSergio Gonzalez Monroy 			"on socket %d\n", name, socket_id);
160d299106eSSergio Gonzalez Monroy 
161d299106eSSergio Gonzalez Monroy 	/* populate the LPM table */
1620d547ed0SFan Zhang 	for (i = 0; i < nb_rt_ip4; i++) {
1630d547ed0SFan Zhang 		ret = rte_lpm_add(lpm, rt_ip4[i].ip, rt_ip4[i].depth,
1640d547ed0SFan Zhang 			rt_ip4[i].if_out);
165d299106eSSergio Gonzalez Monroy 		if (ret < 0)
166906257e9SSergio Gonzalez Monroy 			rte_exit(EXIT_FAILURE, "Fail to add entry num %u to %s "
167906257e9SSergio Gonzalez Monroy 				"LPM table on socket %d\n", i, name, socket_id);
168d299106eSSergio Gonzalez Monroy 
1690d547ed0SFan Zhang 		uint32_t_to_char(rt_ip4[i].ip, &a, &b, &c, &d);
170d299106eSSergio Gonzalez Monroy 		printf("LPM: Adding route %hhu.%hhu.%hhu.%hhu/%hhu (%hhu)\n",
1710d547ed0SFan Zhang 				a, b, c, d, rt_ip4[i].depth,
1720d547ed0SFan Zhang 				rt_ip4[i].if_out);
173d299106eSSergio Gonzalez Monroy 	}
174d299106eSSergio Gonzalez Monroy 
175906257e9SSergio Gonzalez Monroy 	snprintf(name, sizeof(name), "%s_%u", "rt_ip6", socket_id);
176906257e9SSergio Gonzalez Monroy 	conf6.max_rules = RT_IPV6_MAX_RULES;
177906257e9SSergio Gonzalez Monroy 	conf6.number_tbl8s = RTE_LPM_TBL8_NUM_ENTRIES;
178906257e9SSergio Gonzalez Monroy 	lpm6 = rte_lpm6_create(name, socket_id, &conf6);
179906257e9SSergio Gonzalez Monroy 	if (lpm6 == NULL)
180906257e9SSergio Gonzalez Monroy 		rte_exit(EXIT_FAILURE, "Unable to create %s LPM table "
181906257e9SSergio Gonzalez Monroy 			"on socket %d\n", name, socket_id);
182906257e9SSergio Gonzalez Monroy 
183906257e9SSergio Gonzalez Monroy 	/* populate the LPM table */
1840d547ed0SFan Zhang 	for (i = 0; i < nb_rt_ip6; i++) {
1850d547ed0SFan Zhang 		ret = rte_lpm6_add(lpm6, rt_ip6[i].ip, rt_ip6[i].depth,
1860d547ed0SFan Zhang 				rt_ip6[i].if_out);
187906257e9SSergio Gonzalez Monroy 		if (ret < 0)
188906257e9SSergio Gonzalez Monroy 			rte_exit(EXIT_FAILURE, "Fail to add entry num %u to %s "
189906257e9SSergio Gonzalez Monroy 				"LPM table on socket %d\n", i, name, socket_id);
190906257e9SSergio Gonzalez Monroy 
191906257e9SSergio Gonzalez Monroy 		printf("LPM6: Adding route "
192906257e9SSergio Gonzalez Monroy 			" %hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx/%hhx (%hhx)\n",
1930d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[0] << 8) | rt_ip6[i].ip[1]),
1940d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[2] << 8) | rt_ip6[i].ip[3]),
1950d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[4] << 8) | rt_ip6[i].ip[5]),
1960d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[6] << 8) | rt_ip6[i].ip[7]),
1970d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[8] << 8) | rt_ip6[i].ip[9]),
1980d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[10] << 8) | rt_ip6[i].ip[11]),
1990d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[12] << 8) | rt_ip6[i].ip[13]),
2000d547ed0SFan Zhang 			(uint16_t)((rt_ip6[i].ip[14] << 8) | rt_ip6[i].ip[15]),
2010d547ed0SFan Zhang 			rt_ip6[i].depth, rt_ip6[i].if_out);
202906257e9SSergio Gonzalez Monroy 	}
203906257e9SSergio Gonzalez Monroy 
204906257e9SSergio Gonzalez Monroy 	ctx->rt_ip4 = (struct rt_ctx *)lpm;
205906257e9SSergio Gonzalez Monroy 	ctx->rt_ip6 = (struct rt_ctx *)lpm6;
206d299106eSSergio Gonzalez Monroy }
207