summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorDamjan Marion <damarion@cisco.com>2020-07-16 00:48:55 +0200
committerDave Barach <openvpp@barachs.net>2020-07-16 12:07:20 +0000
commite5f0050c7a5d411f96af6401797529d58825e2af (patch)
tree0f23b08e73be807204cff9665176ea1b4efee3cf /src
parentcf86740a11650231bab4d14bc8d9288a91a22f16 (diff)
ip: optimize ip4_header_checksum
Type: improvement Change-Id: I67bacb90a3dd8a9bd7beb4975ad0fe344675b65f Signed-off-by: Damjan Marion <damarion@cisco.com>
Diffstat (limited to 'src')
-rw-r--r--src/vnet/ip/ip4_packet.h117
1 files changed, 55 insertions, 62 deletions
diff --git a/src/vnet/ip/ip4_packet.h b/src/vnet/ip/ip4_packet.h
index 362805c8529..9d63baecf88 100644
--- a/src/vnet/ip/ip4_packet.h
+++ b/src/vnet/ip/ip4_packet.h
@@ -83,52 +83,6 @@ typedef struct
ip4_address_t addr, mask;
} ip4_address_and_mask_t;
-/* If address is a valid netmask, return length of mask. */
-always_inline uword
-ip4_address_netmask_length (const ip4_address_t * a)
-{
- uword result = 0;
- uword i;
- for (i = 0; i < ARRAY_LEN (a->as_u8); i++)
- {
- switch (a->as_u8[i])
- {
- case 0xff:
- result += 8;
- break;
- case 0xfe:
- result += 7;
- goto done;
- case 0xfc:
- result += 6;
- goto done;
- case 0xf8:
- result += 5;
- goto done;
- case 0xf0:
- result += 4;
- goto done;
- case 0xe0:
- result += 3;
- goto done;
- case 0xc0:
- result += 2;
- goto done;
- case 0x80:
- result += 1;
- goto done;
- case 0x00:
- result += 0;
- goto done;
- default:
- /* Not a valid netmask mask. */
- return ~0;
- }
- }
-done:
- return result;
-}
-
typedef union
{
struct
@@ -246,22 +200,61 @@ ip4_next_header (ip4_header_t * i)
always_inline u16
ip4_header_checksum (ip4_header_t * i)
{
- u16 save, csum;
- ip_csum_t sum;
-
- save = i->checksum;
- i->checksum = 0;
- sum = ip_incremental_checksum (0, i, ip4_header_bytes (i));
- csum = ~ip_csum_fold (sum);
-
- i->checksum = save;
-
- /* Make checksum agree for special case where either
- 0 or 0xffff would give same 1s complement sum. */
- if (csum == 0 && save == 0xffff)
- csum = save;
-
- return csum;
+ u16 *iphdr = (u16 *) i;
+ u32 sum = 0;
+ int option_len = (i->ip_version_and_header_length & 0xf) - 5;
+
+ sum += clib_net_to_host_u16 (iphdr[0]);
+ sum += clib_net_to_host_u16 (iphdr[1]);
+ sum += clib_net_to_host_u16 (iphdr[2]);
+ sum += clib_net_to_host_u16 (iphdr[3]);
+ sum += clib_net_to_host_u16 (iphdr[4]);
+
+ sum += clib_net_to_host_u16 (iphdr[6]);
+ sum += clib_net_to_host_u16 (iphdr[7]);
+ sum += clib_net_to_host_u16 (iphdr[8]);
+ sum += clib_net_to_host_u16 (iphdr[9]);
+
+ if (PREDICT_FALSE (option_len > 0))
+ switch (option_len)
+ {
+ case 10:
+ sum += clib_net_to_host_u16 (iphdr[28]);
+ sum += clib_net_to_host_u16 (iphdr[29]);
+ case 9:
+ sum += clib_net_to_host_u16 (iphdr[26]);
+ sum += clib_net_to_host_u16 (iphdr[27]);
+ case 8:
+ sum += clib_net_to_host_u16 (iphdr[24]);
+ sum += clib_net_to_host_u16 (iphdr[25]);
+ case 7:
+ sum += clib_net_to_host_u16 (iphdr[22]);
+ sum += clib_net_to_host_u16 (iphdr[23]);
+ case 6:
+ sum += clib_net_to_host_u16 (iphdr[20]);
+ sum += clib_net_to_host_u16 (iphdr[21]);
+ case 5:
+ sum += clib_net_to_host_u16 (iphdr[18]);
+ sum += clib_net_to_host_u16 (iphdr[19]);
+ case 4:
+ sum += clib_net_to_host_u16 (iphdr[16]);
+ sum += clib_net_to_host_u16 (iphdr[17]);
+ case 3:
+ sum += clib_net_to_host_u16 (iphdr[14]);
+ sum += clib_net_to_host_u16 (iphdr[15]);
+ case 2:
+ sum += clib_net_to_host_u16 (iphdr[12]);
+ sum += clib_net_to_host_u16 (iphdr[13]);
+ case 1:
+ sum += clib_net_to_host_u16 (iphdr[10]);
+ sum += clib_net_to_host_u16 (iphdr[11]);
+ default:
+ break;
+ }
+
+ sum = ((u16) sum) + (sum >> 16);
+ sum = ((u16) sum) + (sum >> 16);
+ return clib_host_to_net_u16 (~((u16) sum));
}
always_inline void
02' href='#n102'>102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144
# Copyright (c) 2020 Cisco and/or its affiliates.
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at:
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

*** Settings ***
| Resource | resources/libraries/robot/shared/default.robot
| Resource | resources/libraries/robot/crypto/ipsec.robot
|
| Force Tags | 3_NODE_SINGLE_LINK_TOPO | PERFTEST | HW_ENV | SCALE | NDRPDR
| ... | IP4FWD | IPSEC | IPSECHW | IPSECTUN | NIC_Intel-X710 | TNL_1000
| ... | AES_128_CBC | HMAC_SHA_256 | HMAC | AES | DRV_VFIO_PCI
| ... | ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha
|
| Suite Setup | Setup suite single link | performance | ipsechw
| Suite Teardown | Tear down suite | performance
| Test Setup | Setup test | performance
| Test Teardown | Tear down test | performance
|
| Test Template | Local Template
|
| Documentation | *IPv4 IPsec tunnel mode performance test suite.*
|
| ... | *[Top] Network Topologies:* TG-DUT1-DUT2-TG 3-node circular topology
| ... | with single links between nodes.
| ... | *[Enc] Packet Encapsulations:* Eth-IPv4 on TG-DUTn,
| ... | Eth-IPv4-IPSec on DUT1-DUT2
| ... | *[Cfg] DUT configuration:* DUT1 and DUT2 are configured with multiple
| ... | IPsec tunnels between them. DUTs get IPv4 traffic from TG, encrypt it
| ... | and send to another DUT, where packets are decrypted and sent back to TG
| ... | *[Ver] TG verification:* TG finds and reports throughput NDR (Non Drop\
| ... | Rate) with zero packet loss tolerance and throughput PDR (Partial Drop\
| ... | Rate) with non-zero packet loss tolerance (LT) expressed in percentage\
| ... | of packets transmitted. NDR and PDR are discovered for different\
| ... | Ethernet L2 frame sizes using MLRsearch library.\
| ... | Test packets are generated by TG on
| ... | links to DUTs. TG traffic profile contains two L3 flow-groups
| ... | (flow-group per direction, number of flows per flow-group equals to
| ... | number of IPSec tunnels) with all packets
| ... | containing Ethernet header, IPv4 header with IP protocol=61 and
| ... | static payload. MAC addresses are matching MAC addresses of the TG
| ... | node interfaces. Incrementing of IP.dst (IPv4 destination address) field
| ... | is applied to both streams.
| ... | *[Ref] Applicable standard specifications:* RFC4303 and RFC2544.

*** Variables ***
| @{plugins_to_enable}= | dpdk_plugin.so | crypto_native_plugin.so
| ... | crypto_ipsecmb_plugin.so | crypto_openssl_plugin.so
| ${crypto_type}= | HW_DH895xcc
| ${nic_name}= | Intel-X710
| ${nic_driver}= | vfio-pci
| ${osi_layer}= | L3
| ${overhead}= | ${62}
| ${tg_if1_ip4}= | 192.168.10.2
| ${dut1_if1_ip4}= | 192.168.10.1
| ${dut1_if2_ip4}= | 100.0.0.1
| ${dut2_if1_ip4}= | 100.0.0.2
| ${dut2_if2_ip4}= | 192.168.20.1
| ${tg_if2_ip4}= | 192.168.20.2
| ${raddr_ip4}= | 20.0.0.0
| ${laddr_ip4}= | 10.0.0.0
| ${addr_range}= | ${24}
| ${n_tunnels}= | ${1000}
# Traffic profile:
| ${traffic_profile}= | trex-sl-3n-ethip4-ip4dst${n_tunnels}

*** Keywords ***
| Local Template
| | [Documentation]
| | ... | [Cfg] DUTs runs IPsec tunneling AES_128_CBC / HMAC_SHA_256 config.\
| | ... | Each DUT uses ${phy_cores} physical core(s) for worker threads.
| | ... | [Ver] Measure NDR and PDR values using MLRsearch algorithm.\
| |
| | ... | *Arguments:*
| | ... | - frame_size - Framesize in Bytes in integer or string (IMIX_v4_1).
| | ... | Type: integer, string
| | ... | - phy_cores - Number of physical cores. Type: integer
| | ... | - rxq - Number of RX queues, default value: ${None}. Type: integer
| |
| | [Arguments] | ${frame_size} | ${phy_cores} | ${rxq}=${None}
| |
| | Set Test Variable | \${frame_size}
| |
| | # These are enums (not strings) so they cannot be in Variables table.
| | ${encr_alg}= | Crypto Alg AES CBC 128
| | ${auth_alg}= | Integ Alg SHA 256 128
| |
| | Given Set Max Rate And Jumbo
| | And Add worker threads to all DUTs | ${phy_cores} | ${rxq}
| | And Pre-initialize layer driver | ${nic_driver}
| | And Apply startup configuration on all VPP DUTs
| | When Initialize layer driver | ${nic_driver}
| | And Initialize layer interface
| | And Initialize IPSec in 3-node circular topology
| | And VPP IPsec Add Multiple Tunnels
| | ... | ${nodes} | ${dut1_if2} | ${dut2_if1} | ${n_tunnels}
| | ... | ${encr_alg} | ${auth_alg} | ${dut1_if2_ip4} | ${dut2_if1_ip4}
| | ... | ${laddr_ip4} | ${raddr_ip4} | ${addr_range}
| | Then Find NDR and PDR intervals using optimized search

*** Test Cases ***
| tc01-64B-1c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | 64B | 1C
| | frame_size=${64} | phy_cores=${1}

| tc02-64B-2c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | 64B | 2C
| | frame_size=${64} | phy_cores=${2}

| tc03-64B-4c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | 64B | 4C
| | frame_size=${64} | phy_cores=${4}

| tc04-1518B-1c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | 1518B | 1C
| | frame_size=${1518} | phy_cores=${1}

| tc05-1518B-2c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | 1518B | 2C
| | frame_size=${1518} | phy_cores=${2}

| tc06-1518B-4c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | 1518B | 4C
| | frame_size=${1518} | phy_cores=${4}

| tc10-IMIX-1c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | IMIX | 1C
| | frame_size=IMIX_v4_1 | phy_cores=${1}

| tc11-IMIX-2c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | IMIX | 2C
| | frame_size=IMIX_v4_1 | phy_cores=${2}

| tc12-IMIX-4c-ethip4ipsec1000tnlhw-ip4base-policy-aes128cbc-hmac256sha-ndrpdr
| | [Tags] | IMIX | 4C
| | frame_size=IMIX_v4_1 | phy_cores=${4}