2 * Copyright (c) 2015, 2016 VMware, Inc.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at:
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
17 #ifndef __OVS_CONNTRACK_H_
18 #define __OVS_CONNTRACK_H_ 1
29 #define OVS_DBG_MOD OVS_DBG_CONTRK
35 uint32_t ipv4_aligned
;
36 struct in6_addr ipv6_aligned
;
55 typedef enum CT_UPDATE_RES
{
62 /* Metadata mark for masked write to conntrack mark */
63 typedef struct MD_MARK
{
68 /* Metadata label for masked write to conntrack label. */
69 typedef struct MD_LABELS
{
70 struct ovs_key_ct_labels value
;
71 struct ovs_key_ct_labels mask
;
74 typedef enum _NAT_ACTION
{
76 NAT_ACTION_REVERSE
= 1 << 0,
77 NAT_ACTION_SRC
= 1 << 1,
78 NAT_ACTION_SRC_PORT
= 1 << 2,
79 NAT_ACTION_DST
= 1 << 3,
80 NAT_ACTION_DST_PORT
= 1 << 4,
83 typedef struct _OVS_CT_KEY
{
84 struct ct_endpoint src
;
85 struct ct_endpoint dst
;
91 } OVS_CT_KEY
, *POVS_CT_KEY
;
93 typedef struct _NAT_ACTION_INFO
{
94 struct ct_addr minAddr
;
95 struct ct_addr maxAddr
;
99 } NAT_ACTION_INFO
, *PNAT_ACTION_INFO
;
101 typedef struct OVS_CT_ENTRY
{
102 NDIS_SPIN_LOCK lock
; /* Protects OVS_CT_ENTRY. */
108 UINT64 timestampStart
;
109 struct ovs_key_ct_labels labels
;
110 NAT_ACTION_INFO natInfo
;
111 PVOID parent
; /* Points to main connection */
112 } OVS_CT_ENTRY
, *POVS_CT_ENTRY
;
114 typedef struct OVS_CT_REL_ENTRY
{
116 POVS_CT_ENTRY parent
;
119 } OVS_CT_REL_ENTRY
, *POVS_CT_REL_ENTRY
;
121 typedef struct _OVS_CT_THREAD_CTX
{
125 } OVS_CT_THREAD_CTX
, *POVS_CT_THREAD_CTX
;
127 typedef struct OvsConntrackKeyLookupCtx
{
133 } OvsConntrackKeyLookupCtx
;
135 /* Per zone strucuture. */
136 typedef struct _OVS_CT_ZONE_INFO
{
139 } OVS_CT_ZONE_INFO
, *POVS_CT_ZONE_INFO
;
141 typedef struct _OVS_CT_ZONE_LIMIT
{
145 } OVS_CT_ZONE_LIMIT
, *POVS_CT_ZONE_LIMIT
;
147 #define CT_MAX_ENTRIES 1 << 21
148 #define CT_HASH_TABLE_SIZE ((UINT32)1 << 10)
149 #define CT_HASH_TABLE_MASK (CT_HASH_TABLE_SIZE - 1)
150 #define CT_INTERVAL_SEC 10000000LL //1s
151 #define CT_ENTRY_TIMEOUT (2 * 60 * CT_INTERVAL_SEC) // 2m
152 #define CT_CLEANUP_INTERVAL (2 * 60 * CT_INTERVAL_SEC) // 2m
155 /* Given POINTER, the address of the given MEMBER in a STRUCT object, returns
156 the STRUCT object. */
157 #define CONTAINER_OF(POINTER, STRUCT, MEMBER) \
158 ((STRUCT *) (void *) ((char *) (POINTER) - \
159 offsetof (STRUCT, MEMBER)))
162 OvsConntrackUpdateExpiration(OVS_CT_ENTRY
*ctEntry
,
166 ctEntry
->expiration
= now
+ interval
;
170 OvsGetTcpHeader(PNET_BUFFER_LIST nbl
,
171 OVS_PACKET_HDR_INFO
*layers
,
173 UINT32
*tcpPayloadLen
)
177 VOID
*dest
= storage
;
179 ipHdr
= NdisGetDataBuffer(NET_BUFFER_LIST_FIRST_NB(nbl
),
180 layers
->l4Offset
+ sizeof(TCPHdr
),
181 NULL
, 1 /*no align*/, 0);
186 ipHdr
= (IPHdr
*)((PCHAR
)ipHdr
+ layers
->l3Offset
);
187 tcp
= (TCPHdr
*)((PCHAR
)ipHdr
+ ipHdr
->ihl
* 4);
188 if (tcp
->doff
* 4 >= sizeof *tcp
) {
189 NdisMoveMemory(dest
, tcp
, sizeof(TCPHdr
));
190 *tcpPayloadLen
= TCP_DATA_LENGTH(ipHdr
, tcp
);
197 VOID
OvsCleanupConntrack(VOID
);
198 NTSTATUS
OvsInitConntrack(POVS_SWITCH_CONTEXT context
);
200 NDIS_STATUS
OvsExecuteConntrackAction(OvsForwardingContext
*fwdCtx
,
203 BOOLEAN
OvsConntrackValidateTcpPacket(const TCPHdr
*tcp
);
204 BOOLEAN
OvsConntrackValidateIcmpPacket(const ICMPHdr
*icmp
);
205 OVS_CT_ENTRY
* OvsConntrackCreateTcpEntry(const TCPHdr
*tcp
,
207 UINT32 tcpPayloadLen
);
208 NDIS_STATUS
OvsCtMapTcpProtoInfoToNl(PNL_BUFFER nlBuf
,
209 OVS_CT_ENTRY
*conn_
);
210 OVS_CT_ENTRY
* OvsConntrackCreateOtherEntry(UINT64 now
);
211 OVS_CT_ENTRY
* OvsConntrackCreateIcmpEntry(UINT64 now
);
212 enum CT_UPDATE_RES
OvsConntrackUpdateTcpEntry(OVS_CT_ENTRY
* conn_
,
216 UINT32 tcpPayloadLen
);
217 enum CT_UPDATE_RES
OvsConntrackUpdateOtherEntry(OVS_CT_ENTRY
*conn_
,
220 enum CT_UPDATE_RES
OvsConntrackUpdateIcmpEntry(OVS_CT_ENTRY
* conn_
,
223 NTSTATUS
OvsCreateNlMsgFromCtEntry(POVS_CT_ENTRY entry
,
232 /* Tracking related connections */
233 NTSTATUS
OvsInitCtRelated(POVS_SWITCH_CONTEXT context
);
234 VOID
OvsCleanupCtRelated(VOID
);
235 NDIS_STATUS
OvsCtRelatedEntryCreate(UINT8 ipProto
,
242 POVS_CT_ENTRY parent
);
243 POVS_CT_ENTRY
OvsCtRelatedLookup(OVS_CT_KEY key
, UINT64 currentTime
);
245 NDIS_STATUS
OvsCtHandleFtp(PNET_BUFFER_LIST curNbl
,
247 OVS_PACKET_HDR_INFO
*layers
,
251 #endif /* __OVS_CONNTRACK_H_ */