From b2d36784ac6689e323017a6adb9fc284aae01e13 Mon Sep 17 00:00:00 2001 From: Zachary Leaf Date: Tue, 27 Jul 2021 05:18:47 -0500 Subject: ipsec: move startup config to common file The ipsec startup.conf config currently exists in ipsec_tun.c. This is because currently the only ipsec{...} options are tunnel related. This patch moves the ipsec config to a common file (ipsec.c) for future extensibility/addition of non-tunnel related config options. Type: refactor Signed-off-by: Zachary Leaf Change-Id: I1569dd7948334fd2cc28523ccc6791a22dea8d32 --- src/vnet/ipsec/ipsec.c | 51 +++++++++++++++++++++++++++++++++++++++++++++ src/vnet/ipsec/ipsec_tun.c | 52 +--------------------------------------------- src/vnet/ipsec/ipsec_tun.h | 3 +++ 3 files changed, 55 insertions(+), 51 deletions(-) (limited to 'src') diff --git a/src/vnet/ipsec/ipsec.c b/src/vnet/ipsec/ipsec.c index 74713458b14..d154b519ecb 100644 --- a/src/vnet/ipsec/ipsec.c +++ b/src/vnet/ipsec/ipsec.c @@ -24,6 +24,7 @@ #include #include #include +#include ipsec_main_t ipsec_main; esp_async_post_next_t esp_encrypt_async_next; @@ -549,6 +550,56 @@ ipsec_init (vlib_main_t * vm) VLIB_INIT_FUNCTION (ipsec_init); +static clib_error_t * +ipsec_config (vlib_main_t *vm, unformat_input_t *input) +{ + unformat_input_t sub_input; + + while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT) + { + if (unformat (input, "ip4 %U", unformat_vlib_cli_sub_input, &sub_input)) + { + uword table_size = ~0; + u32 n_buckets = ~0; + + while (unformat_check_input (&sub_input) != UNFORMAT_END_OF_INPUT) + { + if (unformat (&sub_input, "num-buckets %u", &n_buckets)) + ; + else + return clib_error_return (0, "unknown input `%U'", + format_unformat_error, &sub_input); + } + + ipsec_tun_table_init (AF_IP4, table_size, n_buckets); + } + else if (unformat (input, "ip6 %U", unformat_vlib_cli_sub_input, + &sub_input)) + { + uword table_size = ~0; + u32 n_buckets = ~0; + + while (unformat_check_input (&sub_input) != UNFORMAT_END_OF_INPUT) + { + if (unformat (&sub_input, "num-buckets %u", &n_buckets)) + ; + else + return clib_error_return (0, "unknown input `%U'", + format_unformat_error, &sub_input); + } + + ipsec_tun_table_init (AF_IP6, table_size, n_buckets); + } + else + return clib_error_return (0, "unknown input `%U'", + format_unformat_error, input); + } + + return 0; +} + +VLIB_CONFIG_FUNCTION (ipsec_config, "ipsec"); + /* * fd.io coding-style-patch-verification: ON * diff --git a/src/vnet/ipsec/ipsec_tun.c b/src/vnet/ipsec/ipsec_tun.c index 0b6ec0ea33e..58f9efefdc4 100644 --- a/src/vnet/ipsec/ipsec_tun.c +++ b/src/vnet/ipsec/ipsec_tun.c @@ -925,7 +925,7 @@ const static teib_vft_t ipsec_tun_teib_vft = { .nv_deleted = ipsec_tun_teib_entry_deleted, }; -static void +void ipsec_tun_table_init (ip_address_family_t af, uword table_size, u32 n_buckets) { ipsec_main_t *im; @@ -979,56 +979,6 @@ ipsec_tunnel_protect_init (vlib_main_t *vm) VLIB_INIT_FUNCTION (ipsec_tunnel_protect_init); -static clib_error_t * -ipsec_config (vlib_main_t * vm, unformat_input_t * input) -{ - unformat_input_t sub_input; - - while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT) - { - if (unformat (input, "ip4 %U", unformat_vlib_cli_sub_input, &sub_input)) - { - uword table_size = ~0; - u32 n_buckets = ~0; - - while (unformat_check_input (&sub_input) != UNFORMAT_END_OF_INPUT) - { - if (unformat (&sub_input, "num-buckets %u", &n_buckets)) - ; - else - return clib_error_return (0, "unknown input `%U'", - format_unformat_error, &sub_input); - } - - ipsec_tun_table_init (AF_IP4, table_size, n_buckets); - } - else if (unformat (input, "ip6 %U", unformat_vlib_cli_sub_input, - &sub_input)) - { - uword table_size = ~0; - u32 n_buckets = ~0; - - while (unformat_check_input (&sub_input) != UNFORMAT_END_OF_INPUT) - { - if (unformat (&sub_input, "num-buckets %u", &n_buckets)) - ; - else - return clib_error_return (0, "unknown input `%U'", - format_unformat_error, &sub_input); - } - - ipsec_tun_table_init (AF_IP6, table_size, n_buckets); - } - else - return clib_error_return (0, "unknown input `%U'", - format_unformat_error, input); - } - - return 0; -} - -VLIB_CONFIG_FUNCTION (ipsec_config, "ipsec"); - /* * fd.io coding-style-patch-verification: ON * diff --git a/src/vnet/ipsec/ipsec_tun.h b/src/vnet/ipsec/ipsec_tun.h index c79fb902dec..f452fa4354c 100644 --- a/src/vnet/ipsec/ipsec_tun.h +++ b/src/vnet/ipsec/ipsec_tun.h @@ -163,6 +163,9 @@ extern u8 *format_ipsec_tun_protect_index (u8 * s, va_list * args); extern void ipsec_tun_register_nodes (ip_address_family_t af); extern void ipsec_tun_unregister_nodes (ip_address_family_t af); +extern void ipsec_tun_table_init (ip_address_family_t af, uword table_size, + u32 n_buckets); + /* * DP API */ -- cgit 1.2.3-korg