X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=datapath%2Fvport-gre.c;h=5d5090c89a502376c30583e82a4bbdeb4254000c;hb=HEAD;hp=eb109035a3bfb55db1ab5535f4f6512e43a86358;hpb=b9298d3f825703063c9538aa37407da43e1e4781;p=sliver-openvswitch.git diff --git a/datapath/vport-gre.c b/datapath/vport-gre.c index eb109035a..5d5090c89 100644 --- a/datapath/vport-gre.c +++ b/datapath/vport-gre.c @@ -1,11 +1,23 @@ /* - * Copyright (c) 2010 Nicira Networks. - * Distributed under the terms of the GNU GPL version 2. + * Copyright (c) 2007-2012 Nicira, Inc. * - * Significant portions of this file may be copied from parts of the Linux - * kernel, by Linus Torvalds and others. + * This program is free software; you can redistribute it and/or + * modify it under the terms of version 2 of the GNU General Public + * License as published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + * General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA + * 02110-1301, USA */ +#include +#if IS_ENABLED(CONFIG_NET_IPGRE_DEMUX) #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt #include @@ -14,393 +26,355 @@ #include #include #include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include #include #include +#include +#include #include -#include "tunnel.h" +#include "datapath.h" #include "vport.h" -#include "vport-generic.h" - -/* - * The GRE header is composed of a series of sections: a base and then a variable - * number of options. - */ -#define GRE_HEADER_SECTION 4 - -struct gre_base_hdr { - __be16 flags; - __be16 protocol; -}; - -static int gre_hdr_len(const struct tnl_port_config *port_config) -{ - int len; - - len = GRE_HEADER_SECTION; - - if (port_config->flags & TNL_F_CSUM) - len += GRE_HEADER_SECTION; - - if (port_config->out_key || - port_config->flags & TNL_F_OUT_KEY_ACTION) - len += GRE_HEADER_SECTION; - - return len; -} /* Returns the least-significant 32 bits of a __be64. */ static __be32 be64_get_low32(__be64 x) { #ifdef __BIG_ENDIAN - return x; + return (__force __be32)x; #else - return x >> 32; + return (__force __be32)((__force u64)x >> 32); #endif } -static void gre_build_header(const struct vport *vport, - const struct tnl_mutable_config *mutable, - void *header) +static __be16 filter_tnl_flags(__be16 flags) { - struct gre_base_hdr *greh = header; - __be32 *options = (__be32 *)(greh + 1); - - greh->protocol = htons(ETH_P_TEB); - greh->flags = 0; - - if (mutable->port_config.flags & TNL_F_CSUM) { - greh->flags |= GRE_CSUM; - *options = 0; - options++; - } - - if (mutable->port_config.out_key || - mutable->port_config.flags & TNL_F_OUT_KEY_ACTION) - greh->flags |= GRE_KEY; - - if (mutable->port_config.out_key) - *options = be64_get_low32(mutable->port_config.out_key); + return flags & (TUNNEL_CSUM | TUNNEL_KEY); } -static struct sk_buff *gre_update_header(const struct vport *vport, - const struct tnl_mutable_config *mutable, - struct dst_entry *dst, - struct sk_buff *skb) +static struct sk_buff *__build_header(struct sk_buff *skb, + int tunnel_hlen, + __be32 seq, __be16 gre64_flag) { - __be32 *options = (__be32 *)(skb_network_header(skb) + mutable->tunnel_hlen - - GRE_HEADER_SECTION); + const struct ovs_key_ipv4_tunnel *tun_key = OVS_CB(skb)->tun_key; + struct tnl_ptk_info tpi; - /* Work backwards over the options so the checksum is last. */ - if (mutable->port_config.flags & TNL_F_OUT_KEY_ACTION) { - *options = be64_get_low32(OVS_CB(skb)->tun_id); - options--; - } + skb = gre_handle_offloads(skb, !!(tun_key->tun_flags & TUNNEL_CSUM)); + if (IS_ERR(skb)) + return NULL; - if (mutable->port_config.flags & TNL_F_CSUM) - *(__sum16 *)options = csum_fold(skb_checksum(skb, - skb_transport_offset(skb), - skb->len - skb_transport_offset(skb), - 0)); - /* - * Allow our local IP stack to fragment the outer packet even if the - * DF bit is set as a last resort. - */ - skb->local_df = 1; + tpi.flags = filter_tnl_flags(tun_key->tun_flags) | gre64_flag; + + tpi.proto = htons(ETH_P_TEB); + tpi.key = be64_get_low32(tun_key->tun_id); + tpi.seq = seq; + gre_build_header(skb, &tpi, tunnel_hlen); return skb; } -/* Zero-extends a __be32 into the least-significant 32 bits of a __be64. */ -static __be64 be32_extend_to_be64(__be32 x) +static __be64 key_to_tunnel_id(__be32 key, __be32 seq) { #ifdef __BIG_ENDIAN - return x; + return (__force __be64)((__force u64)seq << 32 | (__force u32)key); #else - return (__be64) x << 32; + return (__force __be64)((__force u64)key << 32 | (__force u32)seq); #endif } -static int parse_header(struct iphdr *iph, __be16 *flags, __be64 *key) +/* Called with rcu_read_lock and BH disabled. */ +static int gre_rcv(struct sk_buff *skb, + const struct tnl_ptk_info *tpi) { - /* IP and ICMP protocol handlers check that the IHL is valid. */ - struct gre_base_hdr *greh = (struct gre_base_hdr *)((u8 *)iph + (iph->ihl << 2)); - __be32 *options = (__be32 *)(greh + 1); - int hdr_len; - - *flags = greh->flags; - - if (unlikely(greh->flags & (GRE_VERSION | GRE_ROUTING))) - return -EINVAL; - - if (unlikely(greh->protocol != htons(ETH_P_TEB))) - return -EINVAL; - - hdr_len = GRE_HEADER_SECTION; - - if (greh->flags & GRE_CSUM) { - hdr_len += GRE_HEADER_SECTION; - options++; - } - - if (greh->flags & GRE_KEY) { - hdr_len += GRE_HEADER_SECTION; + struct ovs_key_ipv4_tunnel tun_key; + struct ovs_net *ovs_net; + struct vport *vport; + __be64 key; - *key = be32_extend_to_be64(*options); - options++; - } else - *key = 0; + ovs_net = net_generic(dev_net(skb->dev), ovs_net_id); + if ((tpi->flags & TUNNEL_KEY) && (tpi->flags & TUNNEL_SEQ)) + vport = rcu_dereference(ovs_net->vport_net.gre64_vport); + else + vport = rcu_dereference(ovs_net->vport_net.gre_vport); + if (unlikely(!vport)) + return PACKET_REJECT; - if (unlikely(greh->flags & GRE_SEQ)) - hdr_len += GRE_HEADER_SECTION; + key = key_to_tunnel_id(tpi->key, tpi->seq); + ovs_flow_tun_key_init(&tun_key, ip_hdr(skb), key, filter_tnl_flags(tpi->flags)); - return hdr_len; + ovs_vport_receive(vport, skb, &tun_key); + return PACKET_RCVD; } /* Called with rcu_read_lock and BH disabled. */ -static void gre_err(struct sk_buff *skb, u32 info) +static int gre_err(struct sk_buff *skb, u32 info, + const struct tnl_ptk_info *tpi) { + struct ovs_net *ovs_net; struct vport *vport; - const struct tnl_mutable_config *mutable; - const int type = icmp_hdr(skb)->type; - const int code = icmp_hdr(skb)->code; - int mtu = ntohs(icmp_hdr(skb)->un.frag.mtu); - - struct iphdr *iph; - __be16 flags; - __be64 key; - int tunnel_hdr_len, tot_hdr_len; - unsigned int orig_mac_header; - unsigned int orig_nw_header; - - if (type != ICMP_DEST_UNREACH || code != ICMP_FRAG_NEEDED) - return; - /* - * The mimimum size packet that we would actually be able to process: - * encapsulating IP header, minimum GRE header, Ethernet header, - * inner IPv4 header. - */ - if (!pskb_may_pull(skb, sizeof(struct iphdr) + GRE_HEADER_SECTION + - ETH_HLEN + sizeof(struct iphdr))) - return; - - iph = (struct iphdr *)skb->data; + ovs_net = net_generic(dev_net(skb->dev), ovs_net_id); + if ((tpi->flags & TUNNEL_KEY) && (tpi->flags & TUNNEL_SEQ)) + vport = rcu_dereference(ovs_net->vport_net.gre64_vport); + else + vport = rcu_dereference(ovs_net->vport_net.gre_vport); - tunnel_hdr_len = parse_header(iph, &flags, &key); - if (tunnel_hdr_len < 0) - return; + if (unlikely(!vport)) + return PACKET_REJECT; + else + return PACKET_RCVD; +} - vport = tnl_find_port(iph->saddr, iph->daddr, key, - TNL_T_PROTO_GRE | TNL_T_KEY_EITHER, &mutable); - if (!vport) - return; +static int __send(struct vport *vport, struct sk_buff *skb, + int tunnel_hlen, + __be32 seq, __be16 gre64_flag) +{ + struct rtable *rt; + int min_headroom; + __be16 df; + __be32 saddr; + int err; - /* - * Packets received by this function were previously sent by us, so - * any comparisons should be to the output values, not the input. - * However, it's not really worth it to have a hash table based on - * output keys (especially since ICMP error handling of tunneled packets - * isn't that reliable anyways). Therefore, we do a lookup based on the - * out key as if it were the in key and then check to see if the input - * and output keys are the same. - */ - if (mutable->port_config.in_key != mutable->port_config.out_key) - return; + /* Route lookup */ + saddr = OVS_CB(skb)->tun_key->ipv4_src; + rt = find_route(ovs_dp_get_net(vport->dp), + &saddr, + OVS_CB(skb)->tun_key->ipv4_dst, + IPPROTO_GRE, + OVS_CB(skb)->tun_key->ipv4_tos, + skb->mark); + if (IS_ERR(rt)) { + err = PTR_ERR(rt); + goto error; + } - if (!!(mutable->port_config.flags & TNL_F_IN_KEY_MATCH) != - !!(mutable->port_config.flags & TNL_F_OUT_KEY_ACTION)) - return; + min_headroom = LL_RESERVED_SPACE(rt_dst(rt).dev) + rt_dst(rt).header_len + + tunnel_hlen + sizeof(struct iphdr) + + (vlan_tx_tag_present(skb) ? VLAN_HLEN : 0); + + if (skb_headroom(skb) < min_headroom || skb_header_cloned(skb)) { + int head_delta = SKB_DATA_ALIGN(min_headroom - + skb_headroom(skb) + + 16); + err = pskb_expand_head(skb, max_t(int, head_delta, 0), + 0, GFP_ATOMIC); + if (unlikely(err)) + goto err_free_rt; + } - if ((mutable->port_config.flags & TNL_F_CSUM) && !(flags & GRE_CSUM)) - return; + if (vlan_tx_tag_present(skb)) { + if (unlikely(!__vlan_put_tag(skb, + skb->vlan_proto, + vlan_tx_tag_get(skb)))) { + err = -ENOMEM; + goto err_free_rt; + } + vlan_set_tci(skb, 0); + } - tunnel_hdr_len += iph->ihl << 2; + /* Push Tunnel header. */ + skb = __build_header(skb, tunnel_hlen, seq, gre64_flag); + if (unlikely(!skb)) { + err = 0; + goto err_free_rt; + } - orig_mac_header = skb_mac_header(skb) - skb->data; - orig_nw_header = skb_network_header(skb) - skb->data; - skb_set_mac_header(skb, tunnel_hdr_len); + df = OVS_CB(skb)->tun_key->tun_flags & TUNNEL_DONT_FRAGMENT ? + htons(IP_DF) : 0; - tot_hdr_len = tunnel_hdr_len + ETH_HLEN; + skb->local_df = 1; - skb->protocol = eth_hdr(skb)->h_proto; - if (skb->protocol == htons(ETH_P_8021Q)) { - tot_hdr_len += VLAN_HLEN; - skb->protocol = vlan_eth_hdr(skb)->h_vlan_encapsulated_proto; - } + return iptunnel_xmit(rt, skb, saddr, + OVS_CB(skb)->tun_key->ipv4_dst, IPPROTO_GRE, + OVS_CB(skb)->tun_key->ipv4_tos, + OVS_CB(skb)->tun_key->ipv4_ttl, df, false); +err_free_rt: + ip_rt_put(rt); +error: + return err; +} - skb_set_network_header(skb, tot_hdr_len); - mtu -= tot_hdr_len; +static struct gre_cisco_protocol gre_protocol = { + .handler = gre_rcv, + .err_handler = gre_err, + .priority = 1, +}; - if (skb->protocol == htons(ETH_P_IP)) - tot_hdr_len += sizeof(struct iphdr); -#if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE) - else if (skb->protocol == htons(ETH_P_IPV6)) - tot_hdr_len += sizeof(struct ipv6hdr); -#endif - else - goto out; +static int gre_ports; +static int gre_init(void) +{ + int err; - if (!pskb_may_pull(skb, tot_hdr_len)) - goto out; + gre_ports++; + if (gre_ports > 1) + return 0; - if (skb->protocol == htons(ETH_P_IP)) { - if (mtu < IP_MIN_MTU) { - if (ntohs(ip_hdr(skb)->tot_len) >= IP_MIN_MTU) - mtu = IP_MIN_MTU; - else - goto out; - } + err = gre_cisco_register(&gre_protocol); + if (err) + pr_warn("cannot register gre protocol handler\n"); - } -#if defined(CONFIG_IPV6) || defined(CONFIG_IPV6_MODULE) - else if (skb->protocol == htons(ETH_P_IPV6)) { - if (mtu < IPV6_MIN_MTU) { - unsigned int packet_length = sizeof(struct ipv6hdr) + - ntohs(ipv6_hdr(skb)->payload_len); - - if (packet_length >= IPV6_MIN_MTU - || ntohs(ipv6_hdr(skb)->payload_len) == 0) - mtu = IPV6_MIN_MTU; - else - goto out; - } - } -#endif + return err; +} - __skb_pull(skb, tunnel_hdr_len); - tnl_frag_needed(vport, mutable, skb, mtu, key); - __skb_push(skb, tunnel_hdr_len); +static void gre_exit(void) +{ + gre_ports--; + if (gre_ports > 0) + return; -out: - skb_set_mac_header(skb, orig_mac_header); - skb_set_network_header(skb, orig_nw_header); - skb->protocol = htons(ETH_P_IP); + gre_cisco_unregister(&gre_protocol); } -static bool check_checksum(struct sk_buff *skb) +static const char *gre_get_name(const struct vport *vport) { - struct iphdr *iph = ip_hdr(skb); - struct gre_base_hdr *greh = (struct gre_base_hdr *)(iph + 1); - __sum16 csum = 0; - - if (greh->flags & GRE_CSUM) { - switch (skb->ip_summed) { - case CHECKSUM_COMPLETE: - csum = csum_fold(skb->csum); - - if (!csum) - break; - /* Fall through. */ - - case CHECKSUM_NONE: - skb->csum = 0; - csum = __skb_checksum_complete(skb); - skb->ip_summed = CHECKSUM_COMPLETE; - break; - } - } - - return (csum == 0); + return vport_priv(vport); } -/* Called with rcu_read_lock and BH disabled. */ -static int gre_rcv(struct sk_buff *skb) +static struct vport *gre_create(const struct vport_parms *parms) { + struct net *net = ovs_dp_get_net(parms->dp); + struct ovs_net *ovs_net; struct vport *vport; - const struct tnl_mutable_config *mutable; - int hdr_len; - struct iphdr *iph; - __be16 flags; - __be64 key; - - if (unlikely(!pskb_may_pull(skb, sizeof(struct gre_base_hdr) + ETH_HLEN))) - goto error; + int err; - if (unlikely(!check_checksum(skb))) - goto error; + err = gre_init(); + if (err) + return ERR_PTR(err); - hdr_len = parse_header(ip_hdr(skb), &flags, &key); - if (unlikely(hdr_len < 0)) + ovs_net = net_generic(net, ovs_net_id); + if (ovsl_dereference(ovs_net->vport_net.gre_vport)) { + vport = ERR_PTR(-EEXIST); goto error; + } - if (unlikely(!pskb_may_pull(skb, hdr_len + ETH_HLEN))) + vport = ovs_vport_alloc(IFNAMSIZ, &ovs_gre_vport_ops, parms); + if (IS_ERR(vport)) goto error; - iph = ip_hdr(skb); - vport = tnl_find_port(iph->daddr, iph->saddr, key, - TNL_T_PROTO_GRE | TNL_T_KEY_EITHER, &mutable); - if (unlikely(!vport)) { - icmp_send(skb, ICMP_DEST_UNREACH, ICMP_PORT_UNREACH, 0); - goto error; - } + strncpy(vport_priv(vport), parms->name, IFNAMSIZ); + rcu_assign_pointer(ovs_net->vport_net.gre_vport, vport); + return vport; - if (mutable->port_config.flags & TNL_F_IN_KEY_MATCH) - OVS_CB(skb)->tun_id = key; - else - OVS_CB(skb)->tun_id = 0; +error: + gre_exit(); + return vport; +} - __skb_pull(skb, hdr_len); - skb_postpull_rcsum(skb, skb_transport_header(skb), hdr_len + ETH_HLEN); +static void gre_tnl_destroy(struct vport *vport) +{ + struct net *net = ovs_dp_get_net(vport->dp); + struct ovs_net *ovs_net; - tnl_rcv(vport, skb); - return 0; + ovs_net = net_generic(net, ovs_net_id); -error: - kfree_skb(skb); - return 0; + RCU_INIT_POINTER(ovs_net->vport_net.gre_vport, NULL); + ovs_vport_deferred_free(vport); + gre_exit(); } -static const struct tnl_ops gre_tnl_ops = { - .tunnel_type = TNL_T_PROTO_GRE, - .ipproto = IPPROTO_GRE, - .hdr_len = gre_hdr_len, - .build_header = gre_build_header, - .update_header = gre_update_header, -}; - -static struct vport *gre_create(const struct vport_parms *parms) +static int gre_send(struct vport *vport, struct sk_buff *skb) { - return tnl_create(parms, &gre_vport_ops, &gre_tnl_ops); + int hlen; + + if (unlikely(!OVS_CB(skb)->tun_key)) + return -EINVAL; + + hlen = ip_gre_calc_hlen(OVS_CB(skb)->tun_key->tun_flags); + + return __send(vport, skb, hlen, 0, 0); } -static const struct net_protocol gre_protocol_handlers = { - .handler = gre_rcv, - .err_handler = gre_err, +const struct vport_ops ovs_gre_vport_ops = { + .type = OVS_VPORT_TYPE_GRE, + .create = gre_create, + .destroy = gre_tnl_destroy, + .get_name = gre_get_name, + .send = gre_send, }; -static int gre_init(void) +/* GRE64 vport. */ +static struct vport *gre64_create(const struct vport_parms *parms) { + struct net *net = ovs_dp_get_net(parms->dp); + struct ovs_net *ovs_net; + struct vport *vport; int err; - err = inet_add_protocol(&gre_protocol_handlers, IPPROTO_GRE); + err = gre_init(); if (err) - pr_warn("cannot register gre protocol handler\n"); + return ERR_PTR(err); - return err; + ovs_net = net_generic(net, ovs_net_id); + if (ovsl_dereference(ovs_net->vport_net.gre64_vport)) { + vport = ERR_PTR(-EEXIST); + goto error; + } + + vport = ovs_vport_alloc(IFNAMSIZ, &ovs_gre64_vport_ops, parms); + if (IS_ERR(vport)) + goto error; + + strncpy(vport_priv(vport), parms->name, IFNAMSIZ); + rcu_assign_pointer(ovs_net->vport_net.gre64_vport, vport); + return vport; +error: + gre_exit(); + return vport; } -static void gre_exit(void) +static void gre64_tnl_destroy(struct vport *vport) { - inet_del_protocol(&gre_protocol_handlers, IPPROTO_GRE); + struct net *net = ovs_dp_get_net(vport->dp); + struct ovs_net *ovs_net; + + ovs_net = net_generic(net, ovs_net_id); + + rcu_assign_pointer(ovs_net->vport_net.gre64_vport, NULL); + ovs_vport_deferred_free(vport); + gre_exit(); } -const struct vport_ops gre_vport_ops = { - .type = "gre", - .flags = VPORT_F_GEN_STATS | VPORT_F_TUN_ID, - .init = gre_init, - .exit = gre_exit, - .create = gre_create, - .modify = tnl_modify, - .destroy = tnl_destroy, - .set_mtu = tnl_set_mtu, - .set_addr = tnl_set_addr, - .get_name = tnl_get_name, - .get_addr = tnl_get_addr, - .get_dev_flags = vport_gen_get_dev_flags, - .is_running = vport_gen_is_running, - .get_operstate = vport_gen_get_operstate, - .get_mtu = tnl_get_mtu, - .send = tnl_send, +static __be32 be64_get_high32(__be64 x) +{ +#ifdef __BIG_ENDIAN + return (__force __be32)((__force u64)x >> 32); +#else + return (__force __be32)x; +#endif +} + +static int gre64_send(struct vport *vport, struct sk_buff *skb) +{ + int hlen = GRE_HEADER_SECTION + /* GRE Hdr */ + GRE_HEADER_SECTION + /* GRE Key */ + GRE_HEADER_SECTION; /* GRE SEQ */ + __be32 seq; + + if (unlikely(!OVS_CB(skb)->tun_key)) + return -EINVAL; + + if (OVS_CB(skb)->tun_key->tun_flags & TUNNEL_CSUM) + hlen += GRE_HEADER_SECTION; + + seq = be64_get_high32(OVS_CB(skb)->tun_key->tun_id); + return __send(vport, skb, hlen, seq, (TUNNEL_KEY|TUNNEL_SEQ)); +} + +const struct vport_ops ovs_gre64_vport_ops = { + .type = OVS_VPORT_TYPE_GRE64, + .create = gre64_create, + .destroy = gre64_tnl_destroy, + .get_name = gre_get_name, + .send = gre64_send, }; +#endif