examples/ipsec-secgw: integrate inbound SAD
[dpdk.git] / examples / ipsec-secgw / sp4.c
index d1dc64b..1dcec52 100644 (file)
 
 #define MAX_ACL_RULE_NUM       1024
 
+#define IPV4_DST_FROM_SP(acr) \
+               (rte_cpu_to_be_32((acr).field[DST_FIELD_IPV4].value.u32))
+
+#define IPV4_SRC_FROM_SP(acr) \
+               (rte_cpu_to_be_32((acr).field[SRC_FIELD_IPV4].value.u32))
+
+#define IPV4_DST_MASK_FROM_SP(acr) \
+               ((acr).field[DST_FIELD_IPV4].mask_range.u32)
+
+#define IPV4_SRC_MASK_FROM_SP(acr) \
+               ((acr).field[SRC_FIELD_IPV4].mask_range.u32)
+
 /*
  * Rule and trace formats definitions.
  */
@@ -99,6 +111,7 @@ parse_sp4_tokens(char **tokens, uint32_t n_tokens,
 
        uint32_t *ri = NULL; /* rule index */
        uint32_t ti = 0; /* token index */
+       uint32_t tv;
 
        uint32_t esp_p = 0;
        uint32_t protect_p = 0;
@@ -169,8 +182,12 @@ parse_sp4_tokens(char **tokens, uint32_t n_tokens,
                        if (status->status < 0)
                                return;
 
-                       rule_ipv4->data.userdata =
-                               PROTECT(atoi(tokens[ti]));
+                       tv = atoi(tokens[ti]);
+                       APP_CHECK(tv != DISCARD && tv != BYPASS, status,
+                               "invalid SPI: %s", tokens[ti]);
+                       if (status->status < 0)
+                               return;
+                       rule_ipv4->data.userdata = tv;
 
                        protect_p = 1;
                        continue;
@@ -472,6 +489,42 @@ acl4_init(const char *name, int32_t socketid, const struct acl4_rules *rules,
        return ctx;
 }
 
+/*
+ * check that for each rule it's SPI has a correspondent entry in SAD
+ */
+static int
+check_spi_value(struct sa_ctx *sa_ctx, int inbound)
+{
+       uint32_t i, num, spi;
+       int32_t spi_idx;
+       struct acl4_rules *acr;
+
+       if (inbound != 0) {
+               acr = acl4_rules_in;
+               num = nb_acl4_rules_in;
+       } else {
+               acr = acl4_rules_out;
+               num = nb_acl4_rules_out;
+       }
+
+       for (i = 0; i != num; i++) {
+               spi = acr[i].data.userdata;
+               if (spi != DISCARD && spi != BYPASS) {
+                       spi_idx = sa_spi_present(sa_ctx, spi, inbound);
+                       if (spi_idx < 0) {
+                               RTE_LOG(ERR, IPSEC,
+                                       "SPI %u is not present in SAD\n",
+                                       spi);
+                               return -ENOENT;
+                       }
+                       /* Update userdata with spi index */
+                       acr[i].data.userdata = spi_idx + 1;
+               }
+       }
+
+       return 0;
+}
+
 void
 sp4_init(struct socket_ctx *ctx, int32_t socket_id)
 {
@@ -488,6 +541,14 @@ sp4_init(struct socket_ctx *ctx, int32_t socket_id)
                rte_exit(EXIT_FAILURE, "Outbound SP DB for socket %u already "
                                "initialized\n", socket_id);
 
+       if (check_spi_value(ctx->sa_in, 1) < 0)
+               rte_exit(EXIT_FAILURE,
+                       "Inbound IPv4 SP DB has unmatched in SAD SPIs\n");
+
+       if (check_spi_value(ctx->sa_out, 0) < 0)
+               rte_exit(EXIT_FAILURE,
+                       "Outbound IPv4 SP DB has unmatched in SAD SPIs\n");
+
        if (nb_acl4_rules_in > 0) {
                name = "sp_ip4_in";
                ctx->sp_ip4_in = (struct sp_ctx *)acl4_init(name,
@@ -509,7 +570,8 @@ sp4_init(struct socket_ctx *ctx, int32_t socket_id)
  * Search though SP rules for given SPI.
  */
 int
-sp4_spi_present(uint32_t spi, int inbound)
+sp4_spi_present(uint32_t spi, int inbound, struct ip_addr ip_addr[2],
+                       uint32_t mask[2])
 {
        uint32_t i, num;
        const struct acl4_rules *acr;
@@ -523,8 +585,15 @@ sp4_spi_present(uint32_t spi, int inbound)
        }
 
        for (i = 0; i != num; i++) {
-               if (acr[i].data.userdata == PROTECT(spi))
+               if (acr[i].data.userdata == spi) {
+                       if (NULL != ip_addr && NULL != mask) {
+                               ip_addr[0].ip.ip4 = IPV4_SRC_FROM_SP(acr[i]);
+                               ip_addr[1].ip.ip4 = IPV4_DST_FROM_SP(acr[i]);
+                               mask[0] = IPV4_SRC_MASK_FROM_SP(acr[i]);
+                               mask[1] = IPV4_DST_MASK_FROM_SP(acr[i]);
+                       }
                        return i;
+               }
        }
 
        return -ENOENT;