diff options
author | Dave Barach <dave@barachs.net> | 2019-03-06 11:14:03 -0500 |
---|---|---|
committer | Florin Coras <florin.coras@gmail.com> | 2019-03-06 17:19:22 +0000 |
commit | a55df1081762b4e40698ef7d9196551851be646a (patch) | |
tree | eb1867e1de1fc78d18da9067d04423dfdb199cd1 /src/plugins/ct6/ct6_test.c | |
parent | e275bed64d12009726fcf43943f1684195cd1e5d (diff) |
ipv6 connection tracking plugin
A security feature: drop unsolicited global unicast traffic.
Change-Id: I421da7d52e08b7acf40c62a1f6e2a6caac349e7e
Signed-off-by: Dave Barach <dave@barachs.net>
Diffstat (limited to 'src/plugins/ct6/ct6_test.c')
-rw-r--r-- | src/plugins/ct6/ct6_test.c | 202 |
1 files changed, 202 insertions, 0 deletions
diff --git a/src/plugins/ct6/ct6_test.c b/src/plugins/ct6/ct6_test.c new file mode 100644 index 00000000000..507620eaf0b --- /dev/null +++ b/src/plugins/ct6/ct6_test.c @@ -0,0 +1,202 @@ +/* + * ct6.c - skeleton vpp-api-test plug-in + * + * Copyright (c) <current-year> <your-organization> + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at: + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +#include <vat/vat.h> +#include <vlibapi/api.h> +#include <vlibmemory/api.h> +#include <vppinfra/error.h> + +uword unformat_sw_if_index (unformat_input_t * input, va_list * args); + +/* Declare message IDs */ +#include <ct6/ct6_msg_enum.h> + +/* define message structures */ +#define vl_typedefs +#include <ct6/ct6_all_api_h.h> +#undef vl_typedefs + +/* declare message handlers for each api */ + +#define vl_endianfun /* define message structures */ +#include <ct6/ct6_all_api_h.h> +#undef vl_endianfun + +/* instantiate all the print functions we know about */ +#define vl_print(handle, ...) +#define vl_printfun +#include <ct6/ct6_all_api_h.h> +#undef vl_printfun + +/* Get the API version number. */ +#define vl_api_version(n,v) static u32 api_version=(v); +#include <ct6/ct6_all_api_h.h> +#undef vl_api_version + + +typedef struct +{ + /* API message ID base */ + u16 msg_id_base; + vat_main_t *vat_main; +} ct6_test_main_t; + +ct6_test_main_t ct6_test_main; + +#define __plugin_msg_base ct6_test_main.msg_id_base +#include <vlibapi/vat_helper_macros.h> + +#define foreach_standard_reply_retval_handler \ +_(ct6_enable_disable_reply) + +#define _(n) \ + static void vl_api_##n##_t_handler \ + (vl_api_##n##_t * mp) \ + { \ + vat_main_t * vam = ct6_test_main.vat_main; \ + i32 retval = ntohl(mp->retval); \ + if (vam->async_mode) { \ + vam->async_errors += (retval < 0); \ + } else { \ + vam->retval = retval; \ + vam->result_ready = 1; \ + } \ + } +foreach_standard_reply_retval_handler; +#undef _ + +/* + * Table of message reply handlers, must include boilerplate handlers + * we just generated + */ +#define foreach_vpe_api_reply_msg \ +_(CT6_ENABLE_DISABLE_REPLY, ct6_enable_disable_reply) + + +static int +api_ct6_enable_disable (vat_main_t * vam) +{ + unformat_input_t *i = vam->input; + int enable_disable = 1; + u32 sw_if_index = ~0; + vl_api_ct6_enable_disable_t *mp; + u32 inside = ~0; + int ret; + + /* Parse args required to build the message */ + while (unformat_check_input (i) != UNFORMAT_END_OF_INPUT) + { + if (unformat (i, "%U", unformat_sw_if_index, vam, &sw_if_index)) + ; + else if (unformat (i, "sw_if_index %d", &sw_if_index)) + ; + else if (unformat (i, "disable")) + enable_disable = 0; + else if (unformat (i, "inside") || unformat (i, "in")) + inside = 1; + else if (unformat (i, "outside") || unformat (i, "out")) + inside = 0; + else + break; + } + + if (inside == ~0) + { + errmsg ("must specify inside or outside"); + return -99; + } + + if (sw_if_index == ~0) + { + errmsg ("missing interface name / explicit sw_if_index number \n"); + return -99; + } + + /* Construct the API message */ + M (CT6_ENABLE_DISABLE, mp); + mp->sw_if_index = ntohl (sw_if_index); + mp->enable_disable = enable_disable; + mp->is_inside = (u8) inside; + + /* send it... */ + S (mp); + + /* Wait for a reply... */ + W (ret); + return ret; +} + +/* + * List of messages that the api test plugin sends, + * and that the data plane plugin processes + */ +#define foreach_vpe_api_msg \ +_(ct6_enable_disable, "<intfc> [disable]") + +static void +ct6_api_hookup (vat_main_t * vam) +{ + ct6_test_main_t *ctmp = &ct6_test_main; + /* Hook up handlers for replies from the data plane plug-in */ +#define _(N,n) \ + vl_msg_api_set_handlers((VL_API_##N + ctmp->msg_id_base), \ + #n, \ + vl_api_##n##_t_handler, \ + vl_noop_handler, \ + vl_api_##n##_t_endian, \ + vl_api_##n##_t_print, \ + sizeof(vl_api_##n##_t), 1); + foreach_vpe_api_reply_msg; +#undef _ + + /* API messages we can send */ +#define _(n,h) hash_set_mem (vam->function_by_name, #n, api_##n); + foreach_vpe_api_msg; +#undef _ + + /* Help strings */ +#define _(n,h) hash_set_mem (vam->help_by_name, #n, h); + foreach_vpe_api_msg; +#undef _ +} + +clib_error_t * +vat_plugin_register (vat_main_t * vam) +{ + ct6_test_main_t *ctmp = &ct6_test_main; + u8 *name; + + ctmp->vat_main = vam; + + /* Ask the vpp engine for the first assigned message-id */ + name = format (0, "ct6_%08x%c", api_version, 0); + ctmp->msg_id_base = vl_client_get_first_plugin_msg_id ((char *) name); + + if (ctmp->msg_id_base != (u16) ~ 0) + ct6_api_hookup (vam); + + vec_free (name); + + return 0; +} + +/* + * fd.io coding-style-patch-verification: ON + * + * Local Variables: + * eval: (c-set-style "gnu") + * End: + */ |