aboutsummaryrefslogtreecommitdiffstats
path: root/src/vnet/ip/ip_api.c
AgeCommit message (Expand)AuthorFilesLines
2020-05-05api: ip: add IP_ROUTE_LOOKUP APIChristian Hopps1-0/+57
2020-05-04misc: binary api fuzz test fixesDave Barach1-2/+3
2020-04-24ip: Setting the Link-Local address from the API enables IPv6 on theNeale Ranns1-2/+2
2020-04-14urpf: Unicast reverse Path Forwarding (plugin)Neale Ranns1-33/+0
2019-12-17ip: Protocol Independent IP NeighborsNeale Ranns1-1341/+37
2019-12-10api: multiple connections per processDave Barach1-1/+1
2019-12-04ip: populate ip_reassembly_get_reply correctlyMatthew Smith1-3/+4
2019-11-26fib: Table ReplaceNeale Ranns1-117/+73
2019-10-06ip: Fix IP unnumbered dump of one interfaceNeale Ranns1-1/+1
2019-09-26ip: add shallow virtual reassembly functionalityKlement Sekera1-33/+101
2019-09-25ip: refactor reassemblyKlement Sekera1-19/+25
2019-09-23ip: fix memory leak in ip_dump handlerMatthew Smith1-0/+2
2019-09-16api: autogenerate api trace print/endianOle Troan1-0/+1
2019-08-08api: vppapitrace JSON/API trace converterOle Troan1-1/+1
2019-07-03fib: allow route delete with no paths and multipath=0 to remove theNeale Ranns1-10/+5
2019-06-18fib: fib api updatesNeale Ranns1-803/+253
2019-06-06IP-Punt-redirect: allow the use of a FIB path to describe how toNeale Ranns1-44/+47
2019-06-03ARP: add feature arcNeale Ranns1-17/+6
2019-05-22stats: support multiple works for error countersOle Troan1-24/+0
2019-05-20reassembly: prevent long chain attackKlement Sekera1-0/+3
2019-04-10API: Fix shared memory only action handlers.Ole Troan1-5/+4
2019-04-08fixing typosJim Thompson1-2/+2
2019-01-30Use IP and MAC API types for neighborsNeale Ranns1-142/+183
2019-01-25IP6 FIB: walk table for dump (VPP-1553)Neale Ranns1-12/+7
2019-01-23IP route local and connectedNeale Ranns1-2/+9
2019-01-07VOM: mroutesNeale Ranns1-4/+6
2018-12-20FIB: encode the label stack in the FIB path during table dumpNeale Ranns1-0/+2
2018-12-18MFIB: recurse resolution through an MFIB entryNeale Ranns1-20/+20
2018-12-01ip_reassembly_enable_disable reply handler name is changed.Chore1-1/+1
2018-11-29api: ip_source_check_interface_add_del api is added.Chore1-0/+32
2018-11-29VPP-1507: Added binary api to dump configured ip_punt_redirectPavel Kotucek1-19/+92
2018-11-12IPv6: Make link-local configurable per-interface (VPP-1446)Juraj Sloboda1-34/+0
2018-10-23c11 safe string handling supportDave Barach1-24/+24
2018-10-17IP Route add/del API is MP safeNeale Ranns1-0/+6
2018-10-12ip: add container proxy dump API (VPP-1364)Matus Fabian1-0/+49
2018-10-04MFIB-API: when programming an (S,G) fix the grp-lenNeale Ranns1-0/+4
2018-10-01Add adjacency counters to the stats segmentNeale Ranns1-2/+9
2018-10-01mroute routers in the stats segmentNeale Ranns1-22/+39
2018-09-28stats: Split stat_segment and stats code in preparation for deprecation.Ole Troan1-1/+0
2018-09-20Route counters in the stats segmentNeale Ranns1-48/+70
2018-09-13IP-neighbor: add and delete internal APINeale Ranns1-32/+15
2018-09-07IP route update fix when multipath and drop setNeale Ranns1-20/+14
2018-07-30FIB: return entry prefix by const reference to avoid the copyNeale Ranns1-10/+10
2018-07-27Fix memory leak in processing of ICMPv6 RA event (VPP-1360)Juraj Sloboda1-1/+2
2018-06-20Fix sw-if-index display error.Brant Lin1-2/+2
2018-06-14Use unicast DMAC for IP neighbor pool refresh probesJohn Lo1-2/+2
2018-06-08Add reaper functions to want events APIs (VPP-1304)Neale Ranns1-1/+126
2018-05-25ARP proxy dumpsNeale Ranns1-6/+94
2018-05-18IP unnumbered dumpNeale Ranns1-0/+69
2018-05-18IP address dump - don't send subnets for unnumbered interfacesNeale Ranns1-4/+6
self.acl_tbl_idx.get(key), self.build_ip_match(src_ip=self.pg0.remote_ip4)) self.input_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_dst_ip(self): """ Destination IP iACL test Test scenario for basic IP ACL with destination IP - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with destination IP address. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with destination IP pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes) self.pg0.add_stream(pkts) key = 'ip_dst' self.create_classify_table(key, self.build_ip_mask(dst_ip='ffffffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(dst_ip=self.pg1.remote_ip4)) self.input_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_src_dst_ip(self): """ Source and destination IP iACL test Test scenario for basic IP ACL with source and destination IP - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with source and destination IP addresses. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with source and destination IP pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes) self.pg0.add_stream(pkts) key = 'ip' self.create_classify_table( key, self.build_ip_mask(src_ip='ffffffff', dst_ip='ffffffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(src_ip=self.pg0.remote_ip4, dst_ip=self.pg1.remote_ip4)) self.input_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") class TestClassifierUDP(TestClassifier): """ Classifier UDP proto Test Case """ @classmethod def setUpClass(cls): super(TestClassifierUDP, cls).setUpClass() @classmethod def tearDownClass(cls): super(TestClassifierUDP, cls).tearDownClass() def test_iacl_proto_udp(self): """ UDP protocol iACL test Test scenario for basic protocol ACL with UDP protocol - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with UDP IP protocol. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with UDP protocol pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes) self.pg0.add_stream(pkts) key = 'proto_udp' self.create_classify_table(key, self.build_ip_mask(proto='ff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_UDP)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_proto_udp_sport(self): """ UDP source port iACL test Test scenario for basic protocol ACL with UDP and sport - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with UDP IP protocol and defined sport. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with UDP and sport sport = 38 pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, UDP(sport=sport, dport=5678)) self.pg0.add_stream(pkts) key = 'proto_udp_sport' self.create_classify_table( key, self.build_ip_mask(proto='ff', src_port='ffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_UDP, src_port=sport)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_proto_udp_dport(self): """ UDP destination port iACL test Test scenario for basic protocol ACL with UDP and dport - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with UDP IP protocol and defined dport. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with UDP and dport dport = 427 pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, UDP(sport=1234, dport=dport)) self.pg0.add_stream(pkts) key = 'proto_udp_dport' self.create_classify_table( key, self.build_ip_mask(proto='ff', dst_port='ffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_UDP, dst_port=dport)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_proto_udp_sport_dport(self): """ UDP source and destination ports iACL test Test scenario for basic protocol ACL with UDP and sport and dport - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with UDP IP protocol and defined sport and dport. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with UDP and sport and dport sport = 13720 dport = 9080 pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, UDP(sport=sport, dport=dport)) self.pg0.add_stream(pkts) key = 'proto_udp_ports' self.create_classify_table( key, self.build_ip_mask(proto='ff', src_port='ffff', dst_port='ffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_UDP, src_port=sport, dst_port=dport)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") class TestClassifierTCP(TestClassifier): """ Classifier TCP proto Test Case """ @classmethod def setUpClass(cls): super(TestClassifierTCP, cls).setUpClass() @classmethod def tearDownClass(cls): super(TestClassifierTCP, cls).tearDownClass() def test_iacl_proto_tcp(self): """ TCP protocol iACL test Test scenario for basic protocol ACL with TCP protocol - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with TCP IP protocol. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with TCP protocol pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, TCP(sport=1234, dport=5678)) self.pg0.add_stream(pkts) key = 'proto_tcp' self.create_classify_table(key, self.build_ip_mask(proto='ff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_TCP)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts, TCP) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_proto_tcp_sport(self): """ TCP source port iACL test Test scenario for basic protocol ACL with TCP and sport - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with TCP IP protocol and defined sport. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with TCP and sport sport = 38 pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, TCP(sport=sport, dport=5678)) self.pg0.add_stream(pkts) key = 'proto_tcp_sport' self.create_classify_table( key, self.build_ip_mask(proto='ff', src_port='ffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_TCP, src_port=sport)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts, TCP) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_proto_tcp_dport(self): """ TCP destination port iACL test Test scenario for basic protocol ACL with TCP and dport - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with TCP IP protocol and defined dport. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with TCP and dport dport = 427 pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, TCP(sport=1234, dport=dport)) self.pg0.add_stream(pkts) key = 'proto_tcp_sport' self.create_classify_table( key, self.build_ip_mask(proto='ff', dst_port='ffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_TCP, dst_port=dport)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts, TCP) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") def test_iacl_proto_tcp_sport_dport(self): """ TCP source and destination ports iACL test Test scenario for basic protocol ACL with TCP and sport and dport - Create IPv4 stream for pg0 -> pg1 interface. - Create iACL with TCP IP protocol and defined sport and dport. - Send and verify received packets on pg1 interface. """ # Basic iACL testing with TCP and sport and dport sport = 13720 dport = 9080 pkts = self.create_stream(self.pg0, self.pg1, self.pg_if_packet_sizes, TCP(sport=sport, dport=dport)) self.pg0.add_stream(pkts) key = 'proto_tcp_ports' self.create_classify_table( key, self.build_ip_mask(proto='ff', src_port='ffff', dst_port='ffff')) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(proto=socket.IPPROTO_TCP, src_port=sport, dst_port=dport)) self.input_acl_set_interface( self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg1.get_capture(len(pkts)) self.verify_capture(self.pg1, pkts, TCP) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") class TestClassifierIPOut(TestClassifier): """ Classifier output IP Test Case """ @classmethod def setUpClass(cls): super(TestClassifierIPOut, cls).setUpClass() @classmethod def tearDownClass(cls): super(TestClassifierIPOut, cls).tearDownClass() def test_acl_ip_out(self): """ Output IP ACL test Test scenario for basic IP ACL with source IP - Create IPv4 stream for pg1 -> pg0 interface. - Create ACL with source IP address. - Send and verify received packets on pg0 interface. """ # Basic oACL testing with source IP pkts = self.create_stream(self.pg1, self.pg0, self.pg_if_packet_sizes) self.pg1.add_stream(pkts) key = 'ip_out' self.create_classify_table( key, self.build_ip_mask(src_ip='ffffffff'), data_offset=0) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(src_ip=self.pg1.remote_ip4)) self.output_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg0.get_capture(len(pkts)) self.verify_capture(self.pg0, pkts) self.pg1.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") class TestClassifierMAC(TestClassifier): """ Classifier MAC Test Case """ @classmethod def setUpClass(cls): super(TestClassifierMAC, cls).setUpClass() @classmethod def tearDownClass(cls): super(TestClassifierMAC, cls).tearDownClass() def test_acl_mac(self): """ MAC ACL test Test scenario for basic MAC ACL with source MAC - Create IPv4 stream for pg0 -> pg2 interface. - Create ACL with source MAC address. - Send and verify received packets on pg2 interface. """ # Basic iACL testing with source MAC pkts = self.create_stream(self.pg0, self.pg2, self.pg_if_packet_sizes) self.pg0.add_stream(pkts) key = 'mac' self.create_classify_table( key, self.build_mac_mask(src_mac='ffffffffffff'), data_offset=-14) self.create_classify_session( self.acl_tbl_idx.get(key), self.build_mac_match(src_mac=self.pg0.remote_mac)) self.input_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key)) self.acl_active_table = key self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg2.get_capture(len(pkts)) self.verify_capture(self.pg2, pkts) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg1.assert_nothing_captured(remark="packets forwarded") self.pg3.assert_nothing_captured(remark="packets forwarded") class TestClassifierPBR(TestClassifier): """ Classifier PBR Test Case """ @classmethod def setUpClass(cls): super(TestClassifierPBR, cls).setUpClass() @classmethod def tearDownClass(cls): super(TestClassifierPBR, cls).tearDownClass() def test_acl_pbr(self): """ IP PBR test Test scenario for PBR with source IP - Create IPv4 stream for pg0 -> pg3 interface. - Configure PBR fib entry for packet forwarding. - Send and verify received packets on pg3 interface. """ # PBR testing with source IP pkts = self.create_stream(self.pg0, self.pg3, self.pg_if_packet_sizes) self.pg0.add_stream(pkts) key = 'pbr' self.create_classify_table(key, self.build_ip_mask(src_ip='ffffffff')) pbr_option = 1 # this will create the VRF/table in which we will insert the route self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(src_ip=self.pg0.remote_ip4), pbr_option, self.pbr_vrfid) self.assertTrue(self.verify_vrf(self.pbr_vrfid)) r = VppIpRoute(self, self.pg3.local_ip4, 24, [VppRoutePath(self.pg3.remote_ip4, INVALID_INDEX)], table_id=self.pbr_vrfid) r.add_vpp_config() self.input_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key)) self.pg_enable_capture(self.pg_interfaces) self.pg_start() pkts = self.pg3.get_capture(len(pkts)) self.verify_capture(self.pg3, pkts) self.input_acl_set_interface(self.pg0, self.acl_tbl_idx.get(key), 0) self.pg0.assert_nothing_captured(remark="packets forwarded") self.pg1.assert_nothing_captured(remark="packets forwarded") self.pg2.assert_nothing_captured(remark="packets forwarded") # remove the classify session and the route r.remove_vpp_config() self.create_classify_session( self.acl_tbl_idx.get(key), self.build_ip_match(src_ip=self.pg0.remote_ip4), pbr_option, self.pbr_vrfid, is_add=0) # and the table should be gone. self.assertFalse(self.verify_vrf(self.pbr_vrfid)) if __name__ == '__main__': unittest.main(testRunner=VppTestRunner)