xref: /f-stack/dpdk/examples/ipsec-secgw/rt.c (revision d30ea906)
1*d30ea906Sjfb8856606 /* SPDX-License-Identifier: BSD-3-Clause
2*d30ea906Sjfb8856606  * Copyright(c) 2016 Intel Corporation
3a9643ea8Slogwang  */
4a9643ea8Slogwang 
5a9643ea8Slogwang /*
6a9643ea8Slogwang  * Routing Table (RT)
7a9643ea8Slogwang  */
8a9643ea8Slogwang #include <sys/types.h>
9a9643ea8Slogwang #include <rte_lpm.h>
10a9643ea8Slogwang #include <rte_lpm6.h>
11a9643ea8Slogwang #include <rte_errno.h>
12a9643ea8Slogwang #include <rte_ip.h>
13a9643ea8Slogwang 
14a9643ea8Slogwang #include "ipsec.h"
152bfe3f2eSlogwang #include "parser.h"
16a9643ea8Slogwang 
17a9643ea8Slogwang #define RT_IPV4_MAX_RULES	1024
18a9643ea8Slogwang #define RT_IPV6_MAX_RULES	1024
19a9643ea8Slogwang 
20a9643ea8Slogwang struct ip4_route {
21a9643ea8Slogwang 	uint32_t ip;
22a9643ea8Slogwang 	uint8_t depth;
23a9643ea8Slogwang 	uint8_t if_out;
24a9643ea8Slogwang };
25a9643ea8Slogwang 
26a9643ea8Slogwang struct ip6_route {
27a9643ea8Slogwang 	uint8_t ip[16];
28a9643ea8Slogwang 	uint8_t depth;
29a9643ea8Slogwang 	uint8_t if_out;
30a9643ea8Slogwang };
31a9643ea8Slogwang 
322bfe3f2eSlogwang struct ip4_route rt_ip4[RT_IPV4_MAX_RULES];
332bfe3f2eSlogwang uint32_t nb_rt_ip4;
34a9643ea8Slogwang 
352bfe3f2eSlogwang struct ip6_route rt_ip6[RT_IPV4_MAX_RULES];
362bfe3f2eSlogwang uint32_t nb_rt_ip6;
37a9643ea8Slogwang 
38a9643ea8Slogwang void
parse_rt_tokens(char ** tokens,uint32_t n_tokens,struct parse_status * status)392bfe3f2eSlogwang parse_rt_tokens(char **tokens, uint32_t n_tokens,
402bfe3f2eSlogwang 	struct parse_status *status)
412bfe3f2eSlogwang {
422bfe3f2eSlogwang 	uint32_t ti;
432bfe3f2eSlogwang 	uint32_t *n_rts = NULL;
442bfe3f2eSlogwang 	struct ip4_route *route_ipv4 = NULL;
452bfe3f2eSlogwang 	struct ip6_route *route_ipv6 = NULL;
462bfe3f2eSlogwang 
472bfe3f2eSlogwang 	if (strcmp(tokens[0], "ipv4") == 0) {
482bfe3f2eSlogwang 		n_rts = &nb_rt_ip4;
492bfe3f2eSlogwang 		route_ipv4 = &rt_ip4[*n_rts];
502bfe3f2eSlogwang 
512bfe3f2eSlogwang 		APP_CHECK(*n_rts <= RT_IPV4_MAX_RULES - 1, status,
522bfe3f2eSlogwang 			"too many rt rules, abort insertion\n");
532bfe3f2eSlogwang 		if (status->status < 0)
542bfe3f2eSlogwang 			return;
552bfe3f2eSlogwang 
562bfe3f2eSlogwang 	} else if (strcmp(tokens[0], "ipv6") == 0) {
572bfe3f2eSlogwang 		n_rts = &nb_rt_ip6;
582bfe3f2eSlogwang 		route_ipv6 = &rt_ip6[*n_rts];
592bfe3f2eSlogwang 
602bfe3f2eSlogwang 		APP_CHECK(*n_rts <= RT_IPV6_MAX_RULES - 1, status,
612bfe3f2eSlogwang 			"too many rt rules, abort insertion\n");
622bfe3f2eSlogwang 		if (status->status < 0)
632bfe3f2eSlogwang 			return;
642bfe3f2eSlogwang 	} else {
652bfe3f2eSlogwang 		APP_CHECK(0, status, "unrecognized input \"%s\"",
662bfe3f2eSlogwang 			tokens[0]);
672bfe3f2eSlogwang 		return;
682bfe3f2eSlogwang 	}
692bfe3f2eSlogwang 
702bfe3f2eSlogwang 	for (ti = 1; ti < n_tokens; ti++) {
712bfe3f2eSlogwang 		if (strcmp(tokens[ti], "dst") == 0) {
722bfe3f2eSlogwang 			INCREMENT_TOKEN_INDEX(ti, n_tokens, status);
732bfe3f2eSlogwang 			if (status->status < 0)
742bfe3f2eSlogwang 				return;
752bfe3f2eSlogwang 
762bfe3f2eSlogwang 			if (route_ipv4 != NULL) {
772bfe3f2eSlogwang 				struct in_addr ip;
782bfe3f2eSlogwang 				uint32_t depth = 0;
792bfe3f2eSlogwang 
802bfe3f2eSlogwang 				APP_CHECK(parse_ipv4_addr(tokens[ti],
812bfe3f2eSlogwang 					&ip, &depth) == 0, status,
822bfe3f2eSlogwang 					"unrecognized input \"%s\", "
832bfe3f2eSlogwang 					"expect valid ipv4 addr",
842bfe3f2eSlogwang 					tokens[ti]);
852bfe3f2eSlogwang 				if (status->status < 0)
862bfe3f2eSlogwang 					return;
872bfe3f2eSlogwang 				route_ipv4->ip = rte_bswap32(
882bfe3f2eSlogwang 					(uint32_t)ip.s_addr);
892bfe3f2eSlogwang 				route_ipv4->depth = (uint8_t)depth;
902bfe3f2eSlogwang 			} else {
912bfe3f2eSlogwang 				struct in6_addr ip;
922bfe3f2eSlogwang 				uint32_t depth;
932bfe3f2eSlogwang 
942bfe3f2eSlogwang 				APP_CHECK(parse_ipv6_addr(tokens[ti],
952bfe3f2eSlogwang 					&ip, &depth) == 0, status,
962bfe3f2eSlogwang 					"unrecognized input \"%s\", "
972bfe3f2eSlogwang 					"expect valid ipv6 address",
982bfe3f2eSlogwang 					tokens[ti]);
992bfe3f2eSlogwang 				if (status->status < 0)
1002bfe3f2eSlogwang 					return;
1012bfe3f2eSlogwang 				memcpy(route_ipv6->ip, ip.s6_addr, 16);
1022bfe3f2eSlogwang 				route_ipv6->depth = (uint8_t)depth;
1032bfe3f2eSlogwang 			}
1042bfe3f2eSlogwang 		}
1052bfe3f2eSlogwang 
1062bfe3f2eSlogwang 		if (strcmp(tokens[ti], "port") == 0) {
1072bfe3f2eSlogwang 			INCREMENT_TOKEN_INDEX(ti, n_tokens, status);
1082bfe3f2eSlogwang 			if (status->status < 0)
1092bfe3f2eSlogwang 				return;
1102bfe3f2eSlogwang 			APP_CHECK_TOKEN_IS_NUM(tokens, ti, status);
1112bfe3f2eSlogwang 			if (status->status < 0)
1122bfe3f2eSlogwang 				return;
1132bfe3f2eSlogwang 			if (route_ipv4 != NULL)
1142bfe3f2eSlogwang 				route_ipv4->if_out = atoi(tokens[ti]);
1152bfe3f2eSlogwang 			else
1162bfe3f2eSlogwang 				route_ipv6->if_out = atoi(tokens[ti]);
1172bfe3f2eSlogwang 		}
1182bfe3f2eSlogwang 	}
1192bfe3f2eSlogwang 
1202bfe3f2eSlogwang 	*n_rts = *n_rts + 1;
1212bfe3f2eSlogwang }
1222bfe3f2eSlogwang 
1232bfe3f2eSlogwang void
rt_init(struct socket_ctx * ctx,int32_t socket_id)1242bfe3f2eSlogwang rt_init(struct socket_ctx *ctx, int32_t socket_id)
125a9643ea8Slogwang {
126a9643ea8Slogwang 	char name[PATH_MAX];
127a9643ea8Slogwang 	uint32_t i;
128a9643ea8Slogwang 	int32_t ret;
129a9643ea8Slogwang 	struct rte_lpm *lpm;
130a9643ea8Slogwang 	struct rte_lpm6 *lpm6;
131a9643ea8Slogwang 	char a, b, c, d;
132a9643ea8Slogwang 	struct rte_lpm_config conf = { 0 };
133a9643ea8Slogwang 	struct rte_lpm6_config conf6 = { 0 };
134a9643ea8Slogwang 
135a9643ea8Slogwang 	if (ctx == NULL)
136a9643ea8Slogwang 		rte_exit(EXIT_FAILURE, "NULL context.\n");
137a9643ea8Slogwang 
138a9643ea8Slogwang 	if (ctx->rt_ip4 != NULL)
139a9643ea8Slogwang 		rte_exit(EXIT_FAILURE, "IPv4 Routing Table for socket %u "
140a9643ea8Slogwang 			"already initialized\n", socket_id);
141a9643ea8Slogwang 
142a9643ea8Slogwang 	if (ctx->rt_ip6 != NULL)
143a9643ea8Slogwang 		rte_exit(EXIT_FAILURE, "IPv6 Routing Table for socket %u "
144a9643ea8Slogwang 			"already initialized\n", socket_id);
145a9643ea8Slogwang 
1462bfe3f2eSlogwang 	if (nb_rt_ip4 == 0 && nb_rt_ip6 == 0)
1472bfe3f2eSlogwang 		RTE_LOG(WARNING, IPSEC, "No Routing rule specified\n");
1482bfe3f2eSlogwang 
149a9643ea8Slogwang 	printf("Creating IPv4 Routing Table (RT) context with %u max routes\n",
150a9643ea8Slogwang 			RT_IPV4_MAX_RULES);
151a9643ea8Slogwang 
152a9643ea8Slogwang 	/* create the LPM table */
153a9643ea8Slogwang 	snprintf(name, sizeof(name), "%s_%u", "rt_ip4", socket_id);
154a9643ea8Slogwang 	conf.max_rules = RT_IPV4_MAX_RULES;
155a9643ea8Slogwang 	conf.number_tbl8s = RTE_LPM_TBL8_NUM_ENTRIES;
156a9643ea8Slogwang 	lpm = rte_lpm_create(name, socket_id, &conf);
157a9643ea8Slogwang 	if (lpm == NULL)
158a9643ea8Slogwang 		rte_exit(EXIT_FAILURE, "Unable to create %s LPM table "
159a9643ea8Slogwang 			"on socket %d\n", name, socket_id);
160a9643ea8Slogwang 
161a9643ea8Slogwang 	/* populate the LPM table */
1622bfe3f2eSlogwang 	for (i = 0; i < nb_rt_ip4; i++) {
1632bfe3f2eSlogwang 		ret = rte_lpm_add(lpm, rt_ip4[i].ip, rt_ip4[i].depth,
1642bfe3f2eSlogwang 			rt_ip4[i].if_out);
165a9643ea8Slogwang 		if (ret < 0)
166a9643ea8Slogwang 			rte_exit(EXIT_FAILURE, "Fail to add entry num %u to %s "
167a9643ea8Slogwang 				"LPM table on socket %d\n", i, name, socket_id);
168a9643ea8Slogwang 
1692bfe3f2eSlogwang 		uint32_t_to_char(rt_ip4[i].ip, &a, &b, &c, &d);
170a9643ea8Slogwang 		printf("LPM: Adding route %hhu.%hhu.%hhu.%hhu/%hhu (%hhu)\n",
1712bfe3f2eSlogwang 				a, b, c, d, rt_ip4[i].depth,
1722bfe3f2eSlogwang 				rt_ip4[i].if_out);
173a9643ea8Slogwang 	}
174a9643ea8Slogwang 
175a9643ea8Slogwang 	snprintf(name, sizeof(name), "%s_%u", "rt_ip6", socket_id);
176a9643ea8Slogwang 	conf6.max_rules = RT_IPV6_MAX_RULES;
177a9643ea8Slogwang 	conf6.number_tbl8s = RTE_LPM_TBL8_NUM_ENTRIES;
178a9643ea8Slogwang 	lpm6 = rte_lpm6_create(name, socket_id, &conf6);
179a9643ea8Slogwang 	if (lpm6 == NULL)
180a9643ea8Slogwang 		rte_exit(EXIT_FAILURE, "Unable to create %s LPM table "
181a9643ea8Slogwang 			"on socket %d\n", name, socket_id);
182a9643ea8Slogwang 
183a9643ea8Slogwang 	/* populate the LPM table */
1842bfe3f2eSlogwang 	for (i = 0; i < nb_rt_ip6; i++) {
1852bfe3f2eSlogwang 		ret = rte_lpm6_add(lpm6, rt_ip6[i].ip, rt_ip6[i].depth,
1862bfe3f2eSlogwang 				rt_ip6[i].if_out);
187a9643ea8Slogwang 		if (ret < 0)
188a9643ea8Slogwang 			rte_exit(EXIT_FAILURE, "Fail to add entry num %u to %s "
189a9643ea8Slogwang 				"LPM table on socket %d\n", i, name, socket_id);
190a9643ea8Slogwang 
191a9643ea8Slogwang 		printf("LPM6: Adding route "
192a9643ea8Slogwang 			" %hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx/%hhx (%hhx)\n",
1932bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[0] << 8) | rt_ip6[i].ip[1]),
1942bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[2] << 8) | rt_ip6[i].ip[3]),
1952bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[4] << 8) | rt_ip6[i].ip[5]),
1962bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[6] << 8) | rt_ip6[i].ip[7]),
1972bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[8] << 8) | rt_ip6[i].ip[9]),
1982bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[10] << 8) | rt_ip6[i].ip[11]),
1992bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[12] << 8) | rt_ip6[i].ip[13]),
2002bfe3f2eSlogwang 			(uint16_t)((rt_ip6[i].ip[14] << 8) | rt_ip6[i].ip[15]),
2012bfe3f2eSlogwang 			rt_ip6[i].depth, rt_ip6[i].if_out);
202a9643ea8Slogwang 	}
203a9643ea8Slogwang 
204a9643ea8Slogwang 	ctx->rt_ip4 = (struct rt_ctx *)lpm;
205a9643ea8Slogwang 	ctx->rt_ip6 = (struct rt_ctx *)lpm6;
206a9643ea8Slogwang }
207