]>
Commit | Line | Data |
---|---|---|
dba3c1d3 PG |
1 | /* BGP FlowSpec VTY |
2 | * Copyright (C) 2018 6WIND | |
3 | * | |
4 | * FRRouting is free software; you can redistribute it and/or modify it | |
5 | * under the terms of the GNU General Public License as published by the | |
6 | * Free Software Foundation; either version 2, or (at your option) any | |
7 | * later version. | |
8 | * | |
9 | * FRRouting is distributed in the hope that it will be useful, but | |
10 | * WITHOUT ANY WARRANTY; without even the implied warranty of | |
11 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
12 | * General Public License for more details. | |
13 | * | |
14 | * You should have received a copy of the GNU General Public License along | |
15 | * with this program; see the file COPYING; if not, write to the Free Software | |
16 | * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA | |
17 | */ | |
18 | ||
19 | #include <zebra.h> | |
20 | #include "command.h" | |
21 | ||
22 | #include "bgpd/bgpd.h" | |
23 | #include "bgpd/bgp_table.h" | |
24 | #include "bgpd/bgp_attr.h" | |
25 | #include "bgpd/bgp_ecommunity.h" | |
26 | #include "bgpd/bgp_vty.h" | |
27 | #include "bgpd/bgp_route.h" | |
28 | #include "bgpd/bgp_aspath.h" | |
29 | #include "bgpd/bgp_flowspec.h" | |
30 | #include "bgpd/bgp_flowspec_util.h" | |
31 | #include "bgpd/bgp_flowspec_private.h" | |
268e1b9b | 32 | #include "bgpd/bgp_debug.h" |
b588b642 | 33 | #include "bgpd/bgp_pbr.h" |
dba3c1d3 PG |
34 | |
35 | /* Local Structures and variables declarations | |
36 | * This code block hosts the struct declared that host the flowspec rules | |
37 | * as well as some structure used to convert to stringx | |
38 | */ | |
39 | ||
40 | static const struct message bgp_flowspec_display_large[] = { | |
41 | {FLOWSPEC_DEST_PREFIX, "Destination Address"}, | |
42 | {FLOWSPEC_SRC_PREFIX, "Source Address"}, | |
43 | {FLOWSPEC_IP_PROTOCOL, "IP Protocol"}, | |
44 | {FLOWSPEC_PORT, "Port"}, | |
45 | {FLOWSPEC_DEST_PORT, "Destination Port"}, | |
46 | {FLOWSPEC_SRC_PORT, "Source Port"}, | |
47 | {FLOWSPEC_ICMP_TYPE, "ICMP Type"}, | |
48 | {FLOWSPEC_ICMP_CODE, "ICMP Code"}, | |
49 | {FLOWSPEC_TCP_FLAGS, "TCP Flags"}, | |
50 | {FLOWSPEC_PKT_LEN, "Packet Length"}, | |
51 | {FLOWSPEC_DSCP, "DSCP field"}, | |
52 | {FLOWSPEC_FRAGMENT, "Packet Fragment"}, | |
40881800 | 53 | {FLOWSPEC_FLOW_LABEL, "Packet Flow Label"}, |
dba3c1d3 PG |
54 | {0} |
55 | }; | |
56 | ||
57 | static const struct message bgp_flowspec_display_min[] = { | |
58 | {FLOWSPEC_DEST_PREFIX, "to"}, | |
59 | {FLOWSPEC_SRC_PREFIX, "from"}, | |
60 | {FLOWSPEC_IP_PROTOCOL, "proto"}, | |
61 | {FLOWSPEC_PORT, "port"}, | |
62 | {FLOWSPEC_DEST_PORT, "dstp"}, | |
63 | {FLOWSPEC_SRC_PORT, "srcp"}, | |
64 | {FLOWSPEC_ICMP_TYPE, "type"}, | |
65 | {FLOWSPEC_ICMP_CODE, "code"}, | |
01ffd28b | 66 | {FLOWSPEC_TCP_FLAGS, "tcp"}, |
dba3c1d3 PG |
67 | {FLOWSPEC_PKT_LEN, "pktlen"}, |
68 | {FLOWSPEC_DSCP, "dscp"}, | |
69 | {FLOWSPEC_FRAGMENT, "pktfrag"}, | |
40881800 | 70 | {FLOWSPEC_FLOW_LABEL, "flwlbl"}, |
dba3c1d3 PG |
71 | {0} |
72 | }; | |
73 | ||
362a06e3 PG |
74 | #define FS_STRING_UPDATE(count, ptr, format, remaining_len) do { \ |
75 | int _len_written; \ | |
76 | \ | |
77 | if (((format) == NLRI_STRING_FORMAT_DEBUG) && (count)) {\ | |
78 | _len_written = snprintf((ptr), (remaining_len), \ | |
79 | ", "); \ | |
80 | (remaining_len) -= _len_written; \ | |
81 | (ptr) += _len_written; \ | |
82 | } else if (((format) == NLRI_STRING_FORMAT_MIN) \ | |
83 | && (count)) { \ | |
84 | _len_written = snprintf((ptr), (remaining_len), \ | |
85 | " "); \ | |
86 | (remaining_len) -= _len_written; \ | |
87 | (ptr) += _len_written; \ | |
88 | } \ | |
89 | count++; \ | |
dba3c1d3 PG |
90 | } while (0) |
91 | ||
362a06e3 PG |
92 | /* Parse FLOWSPEC NLRI |
93 | * passed return_string string has assumed length | |
94 | * BGP_FLOWSPEC_STRING_DISPLAY_MAX | |
95 | */ | |
dba3c1d3 | 96 | void bgp_fs_nlri_get_string(unsigned char *nlri_content, size_t len, |
d33fc23b | 97 | char *return_string, int format, |
1840384b PG |
98 | json_object *json_path, |
99 | afi_t afi) | |
dba3c1d3 PG |
100 | { |
101 | uint32_t offset = 0; | |
102 | int type; | |
103 | int ret = 0, error = 0; | |
104 | char *ptr = return_string; | |
105 | char local_string[BGP_FLOWSPEC_STRING_DISPLAY_MAX]; | |
106 | int count = 0; | |
107 | char extra[2] = ""; | |
108 | char pre_extra[2] = ""; | |
109 | const struct message *bgp_flowspec_display; | |
d33fc23b | 110 | enum bgp_flowspec_util_nlri_t type_util; |
362a06e3 PG |
111 | int len_string = BGP_FLOWSPEC_STRING_DISPLAY_MAX; |
112 | int len_written; | |
dba3c1d3 PG |
113 | |
114 | if (format == NLRI_STRING_FORMAT_LARGE) { | |
115 | snprintf(pre_extra, sizeof(pre_extra), "\t"); | |
116 | snprintf(extra, sizeof(extra), "\n"); | |
117 | bgp_flowspec_display = bgp_flowspec_display_large; | |
118 | } else | |
119 | bgp_flowspec_display = bgp_flowspec_display_min; | |
d33fc23b PG |
120 | /* if needed. type_util can be set to other values */ |
121 | type_util = BGP_FLOWSPEC_RETURN_STRING; | |
dba3c1d3 PG |
122 | error = 0; |
123 | while (offset < len-1 && error >= 0) { | |
124 | type = nlri_content[offset]; | |
125 | offset++; | |
126 | switch (type) { | |
127 | case FLOWSPEC_DEST_PREFIX: | |
128 | case FLOWSPEC_SRC_PREFIX: | |
129 | ret = bgp_flowspec_ip_address( | |
d33fc23b | 130 | type_util, |
dba3c1d3 PG |
131 | nlri_content+offset, |
132 | len - offset, | |
1840384b | 133 | local_string, &error, |
9cec4121 | 134 | afi, NULL); |
dba3c1d3 PG |
135 | if (ret <= 0) |
136 | break; | |
d33fc23b PG |
137 | if (json_path) { |
138 | json_object_string_add(json_path, | |
139 | lookup_msg(bgp_flowspec_display, type, ""), | |
140 | local_string); | |
141 | break; | |
142 | } | |
362a06e3 PG |
143 | FS_STRING_UPDATE(count, ptr, format, len_string); |
144 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
145 | pre_extra, | |
146 | lookup_msg(bgp_flowspec_display, | |
147 | type, ""), | |
148 | local_string, extra); | |
149 | len_string -= len_written; | |
150 | ptr += len_written; | |
dba3c1d3 | 151 | break; |
40881800 | 152 | case FLOWSPEC_FLOW_LABEL: |
dba3c1d3 PG |
153 | case FLOWSPEC_IP_PROTOCOL: |
154 | case FLOWSPEC_PORT: | |
155 | case FLOWSPEC_DEST_PORT: | |
156 | case FLOWSPEC_SRC_PORT: | |
157 | case FLOWSPEC_ICMP_TYPE: | |
158 | case FLOWSPEC_ICMP_CODE: | |
d33fc23b | 159 | ret = bgp_flowspec_op_decode(type_util, |
dba3c1d3 PG |
160 | nlri_content+offset, |
161 | len - offset, | |
162 | local_string, &error); | |
163 | if (ret <= 0) | |
164 | break; | |
d33fc23b PG |
165 | if (json_path) { |
166 | json_object_string_add(json_path, | |
167 | lookup_msg(bgp_flowspec_display, type, ""), | |
168 | local_string); | |
169 | break; | |
170 | } | |
362a06e3 PG |
171 | FS_STRING_UPDATE(count, ptr, format, len_string); |
172 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
173 | pre_extra, | |
174 | lookup_msg(bgp_flowspec_display, | |
175 | type, ""), | |
dba3c1d3 | 176 | local_string, extra); |
362a06e3 PG |
177 | len_string -= len_written; |
178 | ptr += len_written; | |
dba3c1d3 PG |
179 | break; |
180 | case FLOWSPEC_TCP_FLAGS: | |
588ec356 | 181 | ret = bgp_flowspec_bitmask_decode( |
d33fc23b | 182 | type_util, |
dba3c1d3 PG |
183 | nlri_content+offset, |
184 | len - offset, | |
185 | local_string, &error); | |
186 | if (ret <= 0) | |
187 | break; | |
d33fc23b PG |
188 | if (json_path) { |
189 | json_object_string_add(json_path, | |
362a06e3 PG |
190 | lookup_msg(bgp_flowspec_display, |
191 | type, ""), | |
d33fc23b PG |
192 | local_string); |
193 | break; | |
194 | } | |
362a06e3 PG |
195 | FS_STRING_UPDATE(count, ptr, format, len_string); |
196 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
197 | pre_extra, | |
198 | lookup_msg(bgp_flowspec_display, | |
199 | type, ""), | |
200 | local_string, extra); | |
201 | len_string -= len_written; | |
202 | ptr += len_written; | |
dba3c1d3 PG |
203 | break; |
204 | case FLOWSPEC_PKT_LEN: | |
205 | case FLOWSPEC_DSCP: | |
206 | ret = bgp_flowspec_op_decode( | |
d33fc23b | 207 | type_util, |
dba3c1d3 PG |
208 | nlri_content + offset, |
209 | len - offset, local_string, | |
210 | &error); | |
211 | if (ret <= 0) | |
212 | break; | |
d33fc23b PG |
213 | if (json_path) { |
214 | json_object_string_add(json_path, | |
215 | lookup_msg(bgp_flowspec_display, type, ""), | |
216 | local_string); | |
217 | break; | |
218 | } | |
362a06e3 PG |
219 | FS_STRING_UPDATE(count, ptr, format, len_string); |
220 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
221 | pre_extra, | |
222 | lookup_msg(bgp_flowspec_display, | |
223 | type, ""), | |
dba3c1d3 | 224 | local_string, extra); |
362a06e3 PG |
225 | len_string -= len_written; |
226 | ptr += len_written; | |
dba3c1d3 PG |
227 | break; |
228 | case FLOWSPEC_FRAGMENT: | |
588ec356 PG |
229 | ret = bgp_flowspec_bitmask_decode( |
230 | type_util, | |
231 | nlri_content+offset, | |
232 | len - offset, | |
233 | local_string, &error); | |
dba3c1d3 PG |
234 | if (ret <= 0) |
235 | break; | |
d33fc23b PG |
236 | if (json_path) { |
237 | json_object_string_add(json_path, | |
238 | lookup_msg(bgp_flowspec_display, | |
239 | type, ""), | |
240 | local_string); | |
241 | break; | |
242 | } | |
362a06e3 PG |
243 | FS_STRING_UPDATE(count, ptr, format, len_string); |
244 | len_written = snprintf(ptr, len_string, "%s%s %s%s", | |
245 | pre_extra, | |
246 | lookup_msg(bgp_flowspec_display, | |
247 | type, ""), | |
248 | local_string, extra); | |
249 | len_string -= len_written; | |
250 | ptr += len_written; | |
dba3c1d3 PG |
251 | break; |
252 | default: | |
253 | error = -1; | |
254 | break; | |
255 | } | |
256 | offset += ret; | |
257 | } | |
258 | } | |
259 | ||
bd494ec5 | 260 | void route_vty_out_flowspec(struct vty *vty, const struct prefix *p, |
9b6d8fcf | 261 | struct bgp_path_info *path, int display, |
4b7e6066 | 262 | json_object *json_paths) |
dba3c1d3 PG |
263 | { |
264 | struct attr *attr; | |
265 | char return_string[BGP_FLOWSPEC_STRING_DISPLAY_MAX]; | |
c6423c31 | 266 | char *s1 = NULL, *s2 = NULL; |
d33fc23b PG |
267 | json_object *json_nlri_path = NULL; |
268 | json_object *json_ecom_path = NULL; | |
269 | json_object *json_time_path = NULL; | |
270 | char timebuf[BGP_UPTIME_LEN]; | |
7de5a4d9 | 271 | struct ecommunity *ipv6_ecomm = NULL; |
dba3c1d3 | 272 | |
c24ceb89 PG |
273 | if (p == NULL || p->family != AF_FLOWSPEC) |
274 | return; | |
275 | if (json_paths) { | |
276 | if (display == NLRI_STRING_FORMAT_JSON) | |
277 | json_nlri_path = json_object_new_object(); | |
278 | else | |
279 | json_nlri_path = json_paths; | |
dba3c1d3 | 280 | } |
c24ceb89 PG |
281 | if (display == NLRI_STRING_FORMAT_LARGE && path) |
282 | vty_out(vty, "BGP flowspec entry: (flags 0x%x)\n", | |
283 | path->flags); | |
284 | bgp_fs_nlri_get_string((unsigned char *) | |
285 | p->u.prefix_flowspec.ptr, | |
286 | p->u.prefix_flowspec.prefixlen, | |
287 | return_string, | |
288 | display, | |
289 | json_nlri_path, | |
290 | family2afi(p->u.prefix_flowspec | |
291 | .family)); | |
292 | if (display == NLRI_STRING_FORMAT_LARGE) | |
293 | vty_out(vty, "%s", return_string); | |
294 | else if (display == NLRI_STRING_FORMAT_DEBUG) | |
295 | vty_out(vty, "%s", return_string); | |
296 | else if (display == NLRI_STRING_FORMAT_MIN) | |
297 | vty_out(vty, " %-30s", return_string); | |
298 | else if (json_paths && display == NLRI_STRING_FORMAT_JSON) | |
299 | json_object_array_add(json_paths, json_nlri_path); | |
9b6d8fcf | 300 | if (!path) |
dba3c1d3 | 301 | return; |
d04ac434 | 302 | |
7de5a4d9 DA |
303 | if (path->attr) |
304 | ipv6_ecomm = bgp_attr_get_ipv6_ecommunity(path->attr); | |
305 | ||
d04ac434 | 306 | if (path->attr && (path->attr->ecommunity || ipv6_ecomm)) { |
dba3c1d3 | 307 | /* Print attribute */ |
9b6d8fcf | 308 | attr = path->attr; |
9a659715 | 309 | if (attr->ecommunity) |
c6423c31 | 310 | s1 = ecommunity_ecom2str(attr->ecommunity, |
9a659715 | 311 | ECOMMUNITY_FORMAT_ROUTE_MAP, 0); |
d04ac434 DS |
312 | if (ipv6_ecomm) |
313 | s2 = ecommunity_ecom2str( | |
314 | ipv6_ecomm, ECOMMUNITY_FORMAT_ROUTE_MAP, 0); | |
c6423c31 | 315 | if (!s1 && !s2) |
dba3c1d3 PG |
316 | return; |
317 | if (display == NLRI_STRING_FORMAT_LARGE) | |
c6423c31 PG |
318 | vty_out(vty, "\t%s%s%s\n", s1 ? s1 : "", |
319 | s2 && s1 ? " " : "", s2 ? s2 : ""); | |
d33fc23b | 320 | else if (display == NLRI_STRING_FORMAT_MIN) |
c6423c31 | 321 | vty_out(vty, "%s%s", s1 ? s1 : "", s2 ? s2 : ""); |
d33fc23b PG |
322 | else if (json_paths) { |
323 | json_ecom_path = json_object_new_object(); | |
c6423c31 | 324 | if (s1) |
9a659715 | 325 | json_object_string_add(json_ecom_path, |
c6423c31 | 326 | "ecomlist", s1); |
9a659715 PG |
327 | if (s2) |
328 | json_object_string_add(json_ecom_path, | |
329 | "ecom6list", s2); | |
d33fc23b PG |
330 | if (display == NLRI_STRING_FORMAT_JSON) |
331 | json_object_array_add(json_paths, | |
332 | json_ecom_path); | |
333 | } | |
f01e580f PG |
334 | if (display == NLRI_STRING_FORMAT_LARGE) { |
335 | char local_buff[INET6_ADDRSTRLEN]; | |
336 | ||
337 | local_buff[0] = '\0'; | |
3a6290bd DA |
338 | if (p->u.prefix_flowspec.family == AF_INET |
339 | && attr->nexthop.s_addr != INADDR_ANY) | |
f01e580f PG |
340 | inet_ntop(AF_INET, |
341 | &attr->nexthop.s_addr, | |
342 | local_buff, | |
343 | INET6_ADDRSTRLEN); | |
344 | else if (p->u.prefix_flowspec.family == AF_INET6 && | |
345 | attr->mp_nexthop_len != 0 && | |
346 | attr->mp_nexthop_len != BGP_ATTR_NHLEN_IPV4 && | |
347 | attr->mp_nexthop_len != BGP_ATTR_NHLEN_VPNV4) | |
348 | inet_ntop(AF_INET6, | |
349 | &attr->mp_nexthop_global, | |
350 | local_buff, | |
351 | INET6_ADDRSTRLEN); | |
352 | if (local_buff[0] != '\0') | |
353 | vty_out(vty, "\tNLRI NH %s\n", | |
354 | local_buff); | |
355 | } | |
c6423c31 PG |
356 | XFREE(MTYPE_ECOMMUNITY_STR, s1); |
357 | XFREE(MTYPE_ECOMMUNITY_STR, s2); | |
dba3c1d3 | 358 | } |
9b6d8fcf | 359 | peer_uptime(path->uptime, timebuf, BGP_UPTIME_LEN, 0, NULL); |
b588b642 PG |
360 | if (display == NLRI_STRING_FORMAT_LARGE) { |
361 | vty_out(vty, "\treceived for %8s\n", timebuf); | |
362 | } else if (json_paths) { | |
d33fc23b PG |
363 | json_time_path = json_object_new_object(); |
364 | json_object_string_add(json_time_path, | |
365 | "time", timebuf); | |
366 | if (display == NLRI_STRING_FORMAT_JSON) | |
367 | json_object_array_add(json_paths, json_time_path); | |
dba3c1d3 | 368 | } |
b588b642 | 369 | if (display == NLRI_STRING_FORMAT_LARGE) { |
18ee8310 | 370 | struct bgp_path_info_extra *extra = |
9b6d8fcf | 371 | bgp_path_info_extra_get(path); |
3e3708cb | 372 | bool list_began = false; |
dba3c1d3 | 373 | |
3e3708cb | 374 | if (extra->bgp_fs_pbr && listcount(extra->bgp_fs_pbr)) { |
c26edcda | 375 | struct listnode *node; |
b588b642 PG |
376 | struct bgp_pbr_match_entry *bpme; |
377 | struct bgp_pbr_match *bpm; | |
c26edcda | 378 | struct list *list_bpm; |
b588b642 | 379 | |
c26edcda | 380 | list_bpm = list_new(); |
ce3c0614 | 381 | vty_out(vty, "\tinstalled in PBR"); |
c26edcda PG |
382 | for (ALL_LIST_ELEMENTS_RO(extra->bgp_fs_pbr, |
383 | node, bpme)) { | |
384 | bpm = bpme->backpointer; | |
385 | if (listnode_lookup(list_bpm, bpm)) | |
386 | continue; | |
387 | listnode_add(list_bpm, bpm); | |
503d1ec6 | 388 | if (!list_began) { |
c26edcda | 389 | vty_out(vty, " ("); |
503d1ec6 PG |
390 | list_began = true; |
391 | } else | |
c26edcda PG |
392 | vty_out(vty, ", "); |
393 | vty_out(vty, "%s", bpm->ipset_name); | |
c26edcda | 394 | } |
3e3708cb PG |
395 | list_delete(&list_bpm); |
396 | } | |
397 | if (extra->bgp_fs_iprule && listcount(extra->bgp_fs_iprule)) { | |
398 | struct listnode *node; | |
399 | struct bgp_pbr_rule *bpr; | |
400 | ||
401 | if (!list_began) | |
402 | vty_out(vty, "\tinstalled in PBR"); | |
ce3c0614 PG |
403 | for (ALL_LIST_ELEMENTS_RO(extra->bgp_fs_iprule, |
404 | node, bpr)) { | |
405 | if (!bpr->action) | |
406 | continue; | |
407 | if (!list_began) { | |
408 | vty_out(vty, " ("); | |
409 | list_began = true; | |
410 | } else | |
411 | vty_out(vty, ", "); | |
412 | vty_out(vty, "-ipv4-rule %d action lookup %u-", | |
413 | bpr->priority, | |
414 | bpr->action->table_id); | |
415 | } | |
3e3708cb | 416 | } |
026b0e3b PG |
417 | if (list_began) |
418 | vty_out(vty, ")\n"); | |
419 | else | |
b588b642 PG |
420 | vty_out(vty, "\tnot installed in PBR\n"); |
421 | } | |
dba3c1d3 PG |
422 | } |
423 | ||
424 | int bgp_show_table_flowspec(struct vty *vty, struct bgp *bgp, afi_t afi, | |
425 | struct bgp_table *table, enum bgp_show_type type, | |
088f1098 DS |
426 | void *output_arg, bool use_json, int is_last, |
427 | unsigned long *output_cum, unsigned long *total_cum) | |
dba3c1d3 | 428 | { |
40381db7 | 429 | struct bgp_path_info *pi; |
9bcb3eef | 430 | struct bgp_dest *dest; |
dba3c1d3 PG |
431 | unsigned long total_count = 0; |
432 | json_object *json_paths = NULL; | |
d33fc23b | 433 | int display = NLRI_STRING_FORMAT_LARGE; |
dba3c1d3 PG |
434 | |
435 | if (type != bgp_show_type_detail) | |
436 | return CMD_SUCCESS; | |
437 | ||
9bcb3eef DS |
438 | for (dest = bgp_table_top(table); dest; dest = bgp_route_next(dest)) { |
439 | pi = bgp_dest_get_bgp_path_info(dest); | |
6f94b685 | 440 | if (pi == NULL) |
dba3c1d3 | 441 | continue; |
d33fc23b PG |
442 | if (use_json) { |
443 | json_paths = json_object_new_array(); | |
444 | display = NLRI_STRING_FORMAT_JSON; | |
445 | } | |
6f94b685 | 446 | for (; pi; pi = pi->next) { |
dba3c1d3 | 447 | total_count++; |
9bcb3eef DS |
448 | route_vty_out_flowspec(vty, bgp_dest_get_prefix(dest), |
449 | pi, display, json_paths); | |
dba3c1d3 | 450 | } |
d33fc23b | 451 | if (use_json) { |
75eeda93 | 452 | vty_json(vty, json_paths); |
d33fc23b PG |
453 | json_paths = NULL; |
454 | } | |
dba3c1d3 | 455 | } |
d33fc23b | 456 | if (total_count && !use_json) |
dba3c1d3 PG |
457 | vty_out(vty, |
458 | "\nDisplayed %ld flowspec entries\n", | |
459 | total_count); | |
460 | return CMD_SUCCESS; | |
461 | } | |
462 | ||
268e1b9b PG |
463 | DEFUN (debug_bgp_flowspec, |
464 | debug_bgp_flowspec_cmd, | |
465 | "debug bgp flowspec", | |
466 | DEBUG_STR | |
467 | BGP_STR | |
468 | "BGP allow flowspec debugging entries\n") | |
469 | { | |
470 | if (vty->node == CONFIG_NODE) | |
471 | DEBUG_ON(flowspec, FLOWSPEC); | |
472 | else { | |
473 | TERM_DEBUG_ON(flowspec, FLOWSPEC); | |
474 | vty_out(vty, "BGP flowspec debugging is on\n"); | |
475 | } | |
476 | return CMD_SUCCESS; | |
477 | } | |
478 | ||
479 | DEFUN (no_debug_bgp_flowspec, | |
480 | no_debug_bgp_flowspec_cmd, | |
481 | "no debug bgp flowspec", | |
482 | NO_STR | |
483 | DEBUG_STR | |
484 | BGP_STR | |
485 | "BGP allow flowspec debugging entries\n") | |
486 | { | |
487 | if (vty->node == CONFIG_NODE) | |
488 | DEBUG_OFF(flowspec, FLOWSPEC); | |
489 | else { | |
490 | TERM_DEBUG_OFF(flowspec, FLOWSPEC); | |
491 | vty_out(vty, "BGP flowspec debugging is off\n"); | |
492 | } | |
493 | return CMD_SUCCESS; | |
494 | } | |
495 | ||
4762c213 PG |
496 | int bgp_fs_config_write_pbr(struct vty *vty, struct bgp *bgp, |
497 | afi_t afi, safi_t safi) | |
498 | { | |
499 | struct bgp_pbr_interface *pbr_if; | |
500 | bool declare_node = false; | |
501 | struct bgp_pbr_config *bgp_pbr_cfg = bgp->bgp_pbr_cfg; | |
502 | struct bgp_pbr_interface_head *head; | |
503 | bool bgp_pbr_interface_any; | |
504 | ||
8f242187 | 505 | if (!bgp_pbr_cfg || safi != SAFI_FLOWSPEC) |
4762c213 | 506 | return 0; |
8f242187 PG |
507 | if (afi == AFI_IP) { |
508 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv4); | |
509 | bgp_pbr_interface_any = bgp_pbr_cfg->pbr_interface_any_ipv4; | |
510 | } else if (afi == AFI_IP6) { | |
511 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv6); | |
512 | bgp_pbr_interface_any = bgp_pbr_cfg->pbr_interface_any_ipv6; | |
513 | } else { | |
514 | return 0; | |
515 | } | |
4762c213 PG |
516 | if (!RB_EMPTY(bgp_pbr_interface_head, head) || |
517 | !bgp_pbr_interface_any) | |
518 | declare_node = true; | |
519 | RB_FOREACH (pbr_if, bgp_pbr_interface_head, head) { | |
520 | vty_out(vty, " local-install %s\n", pbr_if->name); | |
521 | } | |
4762c213 PG |
522 | return declare_node ? 1 : 0; |
523 | } | |
524 | ||
525 | static int bgp_fs_local_install_interface(struct bgp *bgp, | |
8f242187 PG |
526 | const char *no, const char *ifname, |
527 | afi_t afi) | |
4762c213 PG |
528 | { |
529 | struct bgp_pbr_interface *pbr_if; | |
530 | struct bgp_pbr_config *bgp_pbr_cfg = bgp->bgp_pbr_cfg; | |
531 | struct bgp_pbr_interface_head *head; | |
532 | bool *bgp_pbr_interface_any; | |
533 | ||
534 | if (!bgp_pbr_cfg) | |
535 | return CMD_SUCCESS; | |
8f242187 PG |
536 | if (afi == AFI_IP) { |
537 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv4); | |
538 | bgp_pbr_interface_any = &(bgp_pbr_cfg->pbr_interface_any_ipv4); | |
539 | } else { | |
540 | head = &(bgp_pbr_cfg->ifaces_by_name_ipv6); | |
541 | bgp_pbr_interface_any = &(bgp_pbr_cfg->pbr_interface_any_ipv6); | |
542 | } | |
4762c213 PG |
543 | if (no) { |
544 | if (!ifname) { | |
545 | if (*bgp_pbr_interface_any) { | |
546 | *bgp_pbr_interface_any = false; | |
547 | /* remove all other interface list */ | |
8f242187 | 548 | bgp_pbr_reset(bgp, afi); |
4762c213 PG |
549 | } |
550 | return CMD_SUCCESS; | |
551 | } | |
552 | pbr_if = bgp_pbr_interface_lookup(ifname, head); | |
553 | if (!pbr_if) | |
554 | return CMD_SUCCESS; | |
555 | RB_REMOVE(bgp_pbr_interface_head, head, pbr_if); | |
556 | return CMD_SUCCESS; | |
557 | } | |
558 | if (ifname) { | |
559 | pbr_if = bgp_pbr_interface_lookup(ifname, head); | |
560 | if (pbr_if) | |
561 | return CMD_SUCCESS; | |
562 | pbr_if = XCALLOC(MTYPE_TMP, | |
563 | sizeof(struct bgp_pbr_interface)); | |
564 | strlcpy(pbr_if->name, ifname, INTERFACE_NAMSIZ); | |
565 | RB_INSERT(bgp_pbr_interface_head, head, pbr_if); | |
566 | *bgp_pbr_interface_any = false; | |
567 | } else { | |
568 | /* set to default */ | |
569 | if (!*bgp_pbr_interface_any) { | |
570 | /* remove all other interface list | |
571 | */ | |
8f242187 | 572 | bgp_pbr_reset(bgp, afi); |
4762c213 PG |
573 | *bgp_pbr_interface_any = true; |
574 | } | |
575 | } | |
576 | return CMD_SUCCESS; | |
577 | } | |
578 | ||
579 | DEFUN (bgp_fs_local_install_ifname, | |
580 | bgp_fs_local_install_ifname_cmd, | |
581 | "[no] local-install INTERFACE", | |
582 | NO_STR | |
583 | "Apply local policy routing\n" | |
584 | "Interface name\n") | |
585 | { | |
586 | struct bgp *bgp = VTY_GET_CONTEXT(bgp); | |
587 | int idx = 0; | |
36de6e0e | 588 | const char *no = strmatch(argv[0]->text, "no") ? "no" : NULL; |
4762c213 PG |
589 | char *ifname = argv_find(argv, argc, "INTERFACE", &idx) ? |
590 | argv[idx]->arg : NULL; | |
591 | ||
8f242187 PG |
592 | return bgp_fs_local_install_interface(bgp, no, ifname, |
593 | bgp_node_afi(vty)); | |
4762c213 PG |
594 | } |
595 | ||
088f1098 DS |
596 | extern int bgp_flowspec_display_match_per_ip(afi_t afi, struct bgp_table *rib, |
597 | struct prefix *match, | |
598 | int prefix_check, struct vty *vty, | |
599 | bool use_json, | |
600 | json_object *json_paths) | |
63a0b7a9 | 601 | { |
9bcb3eef | 602 | struct bgp_dest *dest; |
b54892e0 | 603 | const struct prefix *prefix; |
63a0b7a9 PG |
604 | int display = 0; |
605 | ||
9bcb3eef DS |
606 | for (dest = bgp_table_top(rib); dest; dest = bgp_route_next(dest)) { |
607 | prefix = bgp_dest_get_prefix(dest); | |
63a0b7a9 PG |
608 | |
609 | if (prefix->family != AF_FLOWSPEC) | |
610 | continue; | |
611 | ||
612 | if (bgp_flowspec_contains_prefix(prefix, match, prefix_check)) { | |
6f94b685 | 613 | route_vty_out_flowspec( |
9bcb3eef | 614 | vty, prefix, bgp_dest_get_bgp_path_info(dest), |
6f94b685 DS |
615 | use_json ? NLRI_STRING_FORMAT_JSON |
616 | : NLRI_STRING_FORMAT_LARGE, | |
617 | json_paths); | |
63a0b7a9 PG |
618 | display++; |
619 | } | |
620 | } | |
621 | return display; | |
622 | } | |
623 | ||
dba3c1d3 PG |
624 | void bgp_flowspec_vty_init(void) |
625 | { | |
268e1b9b PG |
626 | install_element(ENABLE_NODE, &debug_bgp_flowspec_cmd); |
627 | install_element(CONFIG_NODE, &debug_bgp_flowspec_cmd); | |
628 | install_element(ENABLE_NODE, &no_debug_bgp_flowspec_cmd); | |
629 | install_element(CONFIG_NODE, &no_debug_bgp_flowspec_cmd); | |
4762c213 | 630 | install_element(BGP_FLOWSPECV4_NODE, &bgp_fs_local_install_ifname_cmd); |
8f242187 | 631 | install_element(BGP_FLOWSPECV6_NODE, &bgp_fs_local_install_ifname_cmd); |
dba3c1d3 | 632 | } |