X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=lib%2Fnetdev-vport.c;h=4aa8bb04c114fde4f48b534507739aae73a75b4e;hb=e892d5ffb5749c0534fecd903e3e6a76819f1346;hp=f3985e9d23184b78ae97f62d33459257dbf529e0;hpb=ea83a2fcd0d31246ece7bdea4c54e162f432e81c;p=sliver-openvswitch.git diff --git a/lib/netdev-vport.c b/lib/netdev-vport.c index f3985e9d2..4aa8bb04c 100644 --- a/lib/netdev-vport.c +++ b/lib/netdev-vport.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2010 Nicira Networks. + * Copyright (c) 2010, 2011, 2012, 2013 Nicira, Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -21,85 +21,56 @@ #include #include #include -#include #include #include #include "byte-order.h" +#include "daemon.h" +#include "dirs.h" +#include "dpif.h" #include "hash.h" #include "hmap.h" #include "list.h" #include "netdev-provider.h" -#include "netlink.h" -#include "netlink-socket.h" #include "ofpbuf.h" -#include "openvswitch/datapath-protocol.h" -#include "openvswitch/tunnel.h" #include "packets.h" -#include "rtnetlink.h" -#include "rtnetlink-route.h" -#include "rtnetlink-link.h" +#include "route-table.h" #include "shash.h" #include "socket-util.h" #include "vlog.h" VLOG_DEFINE_THIS_MODULE(netdev_vport); -static struct hmap name_map; -static struct hmap route_map; -static struct rtnetlink_notifier netdev_vport_link_notifier; -static struct rtnetlink_notifier netdev_vport_route_notifier; +/* Default to the OTV port, per the VXLAN IETF draft. */ +#define VXLAN_DST_PORT 8472 -struct route_node { - struct hmap_node node; /* Node in route_map. */ - int rta_oif; /* Egress interface index. */ - uint32_t rta_dst; /* Destination address in host byte order. */ - unsigned char rtm_dst_len; /* Destination address length. */ -}; - -struct name_node { - struct hmap_node node; /* Node in name_map. */ - uint32_t ifi_index; /* Kernel interface index. */ +#define LISP_DST_PORT 4341 - char ifname[IFNAMSIZ]; /* Interface name. */ -}; - -struct netdev_vport_notifier { - struct netdev_notifier notifier; - struct list list_node; - struct shash_node *shash_node; -}; +#define DEFAULT_TTL 64 struct netdev_dev_vport { struct netdev_dev netdev_dev; - uint64_t config[VPORT_CONFIG_SIZE / 8]; -}; + unsigned int change_seq; + uint8_t etheraddr[ETH_ADDR_LEN]; + struct netdev_stats stats; + + /* Tunnels. */ + struct netdev_tunnel_config tnl_cfg; -struct netdev_vport { - struct netdev netdev; + /* Patch Ports. */ + char *peer; }; struct vport_class { + const char *dpif_port; struct netdev_class netdev_class; - int (*parse_config)(const struct netdev_dev *, const struct shash *args, - void *config); }; -static struct shash netdev_vport_notifiers = - SHASH_INITIALIZER(&netdev_vport_notifiers); - -static struct vlog_rate_limit rl = VLOG_RATE_LIMIT_INIT(5, 20); - -static int netdev_vport_do_ioctl(int cmd, void *arg); static int netdev_vport_create(const struct netdev_class *, const char *, - const struct shash *, struct netdev_dev **); -static void netdev_vport_poll_notify(const struct netdev *); - -static void netdev_vport_tnl_iface_init(void); -static void netdev_vport_route_change(const struct rtnetlink_route_change *, - void *); -static void netdev_vport_link_change(const struct rtnetlink_link_change *, - void *); + struct netdev_dev **); +static int get_patch_config(struct netdev_dev *, struct smap *args); +static int get_tunnel_config(struct netdev_dev *, struct smap *args); +static void netdev_vport_poll_notify(struct netdev_dev_vport *); static bool is_vport_class(const struct netdev_class *class) @@ -110,65 +81,94 @@ is_vport_class(const struct netdev_class *class) static const struct vport_class * vport_class_cast(const struct netdev_class *class) { - assert(is_vport_class(class)); + ovs_assert(is_vport_class(class)); return CONTAINER_OF(class, struct vport_class, netdev_class); } static struct netdev_dev_vport * netdev_dev_vport_cast(const struct netdev_dev *netdev_dev) { - assert(is_vport_class(netdev_dev_get_class(netdev_dev))); + ovs_assert(is_vport_class(netdev_dev_get_class(netdev_dev))); return CONTAINER_OF(netdev_dev, struct netdev_dev_vport, netdev_dev); } -static struct netdev_vport * -netdev_vport_cast(const struct netdev *netdev) +static struct netdev_dev_vport * +netdev_vport_get_dev(const struct netdev *netdev) { - struct netdev_dev *netdev_dev = netdev_get_dev(netdev); - assert(is_vport_class(netdev_dev_get_class(netdev_dev))); - return CONTAINER_OF(netdev, struct netdev_vport, netdev); + return netdev_dev_vport_cast(netdev_get_dev(netdev)); } -/* If 'netdev' is a vport netdev, copies its kernel configuration into - * 'config'. Otherwise leaves 'config' untouched. */ -void -netdev_vport_get_config(const struct netdev *netdev, void *config) +static const struct netdev_tunnel_config * +get_netdev_tunnel_config(const struct netdev_dev *netdev_dev) +{ + return &netdev_dev_vport_cast(netdev_dev)->tnl_cfg; +} + +bool +netdev_vport_is_patch(const struct netdev *netdev) { const struct netdev_dev *dev = netdev_get_dev(netdev); + const struct netdev_class *class = netdev_dev_get_class(dev); - if (is_vport_class(netdev_dev_get_class(dev))) { - const struct netdev_dev_vport *vport = netdev_dev_vport_cast(dev); - memcpy(config, vport->config, VPORT_CONFIG_SIZE); - } + return class->get_config == get_patch_config; } -static int -netdev_vport_init(void) +static bool +netdev_vport_needs_dst_port(const struct netdev_dev *dev) { - netdev_vport_tnl_iface_init(); - return 0; + const struct netdev_class *class = netdev_dev_get_class(dev); + const char *type = netdev_dev_get_type(dev); + + return (class->get_config == get_tunnel_config && + (!strcmp("vxlan", type) || !strcmp("lisp", type))); +} + +const char * +netdev_vport_get_dpif_port(const struct netdev *netdev) +{ + const struct netdev_dev *dev = netdev_get_dev(netdev); + const struct netdev_class *class = netdev_dev_get_class(dev); + const char *dpif_port; + + if (netdev_vport_needs_dst_port(dev)) { + const struct netdev_dev_vport *vport = netdev_vport_get_dev(netdev); + const char *type = netdev_dev_get_type(dev); + static char dpif_port_combined[IFNAMSIZ]; + + /* + * Note: IFNAMSIZ is 16 bytes long. The maximum length of a VXLAN + * or LISP port name below is 15 or 14 bytes respectively. Still, + * assert here on the size of strlen(type) in case that changes + * in the future. + */ + ovs_assert(strlen(type) + 10 < IFNAMSIZ); + snprintf(dpif_port_combined, IFNAMSIZ, "%s_sys_%d", type, + ntohs(vport->tnl_cfg.dst_port)); + return dpif_port_combined; + } else { + dpif_port = (is_vport_class(class) + ? vport_class_cast(class)->dpif_port + : NULL); + } + + return dpif_port ? dpif_port : netdev_get_name(netdev); } static int netdev_vport_create(const struct netdev_class *netdev_class, const char *name, - const struct shash *args, struct netdev_dev **netdev_devp) { - const struct vport_class *vport_class = vport_class_cast(netdev_class); struct netdev_dev_vport *dev; - int error; - dev = xmalloc(sizeof *dev); - *netdev_devp = &dev->netdev_dev; + dev = xzalloc(sizeof *dev); netdev_dev_init(&dev->netdev_dev, name, netdev_class); + dev->change_seq = 1; + eth_addr_random(dev->etheraddr); - memset(dev->config, 0, sizeof dev->config); - error = vport_class->parse_config(&dev->netdev_dev, args, dev->config); + *netdev_devp = &dev->netdev_dev; + route_table_register(); - if (error) { - netdev_dev_uninit(&dev->netdev_dev, true); - } - return error; + return 0; } static void @@ -176,73 +176,32 @@ netdev_vport_destroy(struct netdev_dev *netdev_dev_) { struct netdev_dev_vport *netdev_dev = netdev_dev_vport_cast(netdev_dev_); + route_table_unregister(); + free(netdev_dev->peer); free(netdev_dev); } static int -netdev_vport_open(struct netdev_dev *netdev_dev_, int ethertype OVS_UNUSED, - struct netdev **netdevp) +netdev_vport_open(struct netdev_dev *netdev_dev, struct netdev **netdevp) { - struct netdev_vport *netdev; - - netdev = xmalloc(sizeof *netdev); - netdev_init(&netdev->netdev, netdev_dev_); - - *netdevp = &netdev->netdev; + *netdevp = xmalloc(sizeof **netdevp); + netdev_init(*netdevp, netdev_dev); return 0; } static void -netdev_vport_close(struct netdev *netdev_) +netdev_vport_close(struct netdev *netdev) { - struct netdev_vport *netdev = netdev_vport_cast(netdev_); free(netdev); } -static int -netdev_vport_reconfigure(struct netdev_dev *dev_, - const struct shash *args) -{ - const struct netdev_class *netdev_class = netdev_dev_get_class(dev_); - const struct vport_class *vport_class = vport_class_cast(netdev_class); - struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); - struct odp_port port; - int error; - - memset(&port, 0, sizeof port); - strncpy(port.devname, netdev_dev_get_name(dev_), sizeof port.devname); - strncpy(port.type, netdev_dev_get_type(dev_), sizeof port.type); - error = vport_class->parse_config(dev_, args, port.config); - if (!error && memcmp(port.config, dev->config, sizeof dev->config)) { - error = netdev_vport_do_ioctl(ODP_VPORT_MOD, &port); - if (!error || error == ENODEV) { - /* Either reconfiguration succeeded or this vport is not installed - * in the kernel (e.g. it hasn't been added to a dpif yet with - * dpif_port_add()). */ - memcpy(dev->config, port.config, sizeof dev->config); - } - } - return error; -} - static int netdev_vport_set_etheraddr(struct netdev *netdev, const uint8_t mac[ETH_ADDR_LEN]) { - struct odp_vport_ether vport_ether; - int err; - - ovs_strlcpy(vport_ether.devname, netdev_get_name(netdev), - sizeof vport_ether.devname); - - memcpy(vport_ether.ether_addr, mac, ETH_ADDR_LEN); - - err = netdev_vport_do_ioctl(ODP_VPORT_ETHER_SET, &vport_ether); - if (err) { - return err; - } - - netdev_vport_poll_notify(netdev); + struct netdev_dev_vport *dev = netdev_vport_get_dev(netdev); + memcpy(dev->etheraddr, mac, ETH_ADDR_LEN); + netdev_vport_poll_notify(dev); return 0; } @@ -250,120 +209,32 @@ static int netdev_vport_get_etheraddr(const struct netdev *netdev, uint8_t mac[ETH_ADDR_LEN]) { - struct odp_vport_ether vport_ether; - int err; - - ovs_strlcpy(vport_ether.devname, netdev_get_name(netdev), - sizeof vport_ether.devname); - - err = netdev_vport_do_ioctl(ODP_VPORT_ETHER_GET, &vport_ether); - if (err) { - return err; - } - - memcpy(mac, vport_ether.ether_addr, ETH_ADDR_LEN); + memcpy(mac, netdev_vport_get_dev(netdev)->etheraddr, ETH_ADDR_LEN); return 0; } static int -netdev_vport_get_mtu(const struct netdev *netdev, int *mtup) +tunnel_get_status(const struct netdev *netdev, struct smap *smap) { - struct odp_vport_mtu vport_mtu; - int err; + static char iface[IFNAMSIZ]; + ovs_be32 route; - ovs_strlcpy(vport_mtu.devname, netdev_get_name(netdev), - sizeof vport_mtu.devname); + route = netdev_vport_get_dev(netdev)->tnl_cfg.ip_dst; + if (route_table_get_name(route, iface)) { + struct netdev *egress_netdev; - err = netdev_vport_do_ioctl(ODP_VPORT_MTU_GET, &vport_mtu); - if (err) { - return err; - } + smap_add(smap, "tunnel_egress_iface", iface); - *mtup = vport_mtu.mtu; - return 0; -} - -int -netdev_vport_get_stats(const struct netdev *netdev, struct netdev_stats *stats) -{ - const char *name = netdev_get_name(netdev); - struct odp_vport_stats_req ovsr; - int err; - - ovs_strlcpy(ovsr.devname, name, sizeof ovsr.devname); - err = netdev_vport_do_ioctl(ODP_VPORT_STATS_GET, &ovsr); - if (err) { - return err; + if (!netdev_open(iface, "system", &egress_netdev)) { + smap_add(smap, "tunnel_egress_iface_carrier", + netdev_get_carrier(egress_netdev) ? "up" : "down"); + netdev_close(egress_netdev); + } } - stats->rx_packets = ovsr.stats.rx_packets; - stats->tx_packets = ovsr.stats.tx_packets; - stats->rx_bytes = ovsr.stats.rx_bytes; - stats->tx_bytes = ovsr.stats.tx_bytes; - stats->rx_errors = ovsr.stats.rx_errors; - stats->tx_errors = ovsr.stats.tx_errors; - stats->rx_dropped = ovsr.stats.rx_dropped; - stats->tx_dropped = ovsr.stats.tx_dropped; - stats->multicast = ovsr.stats.multicast; - stats->collisions = ovsr.stats.collisions; - stats->rx_length_errors = ovsr.stats.rx_length_errors; - stats->rx_over_errors = ovsr.stats.rx_over_errors; - stats->rx_crc_errors = ovsr.stats.rx_crc_errors; - stats->rx_frame_errors = ovsr.stats.rx_frame_errors; - stats->rx_fifo_errors = ovsr.stats.rx_fifo_errors; - stats->rx_missed_errors = ovsr.stats.rx_missed_errors; - stats->tx_aborted_errors = ovsr.stats.tx_aborted_errors; - stats->tx_carrier_errors = ovsr.stats.tx_carrier_errors; - stats->tx_fifo_errors = ovsr.stats.tx_fifo_errors; - stats->tx_heartbeat_errors = ovsr.stats.tx_heartbeat_errors; - stats->tx_window_errors = ovsr.stats.tx_window_errors; - return 0; } -int -netdev_vport_set_stats(struct netdev *netdev, const struct netdev_stats *stats) -{ - struct odp_vport_stats_req ovsr; - int err; - - ovs_strlcpy(ovsr.devname, netdev_get_name(netdev), sizeof ovsr.devname); - - ovsr.stats.rx_packets = stats->rx_packets; - ovsr.stats.tx_packets = stats->tx_packets; - ovsr.stats.rx_bytes = stats->rx_bytes; - ovsr.stats.tx_bytes = stats->tx_bytes; - ovsr.stats.rx_errors = stats->rx_errors; - ovsr.stats.tx_errors = stats->tx_errors; - ovsr.stats.rx_dropped = stats->rx_dropped; - ovsr.stats.tx_dropped = stats->tx_dropped; - ovsr.stats.multicast = stats->multicast; - ovsr.stats.collisions = stats->collisions; - ovsr.stats.rx_length_errors = stats->rx_length_errors; - ovsr.stats.rx_over_errors = stats->rx_over_errors; - ovsr.stats.rx_crc_errors = stats->rx_crc_errors; - ovsr.stats.rx_frame_errors = stats->rx_frame_errors; - ovsr.stats.rx_fifo_errors = stats->rx_fifo_errors; - ovsr.stats.rx_missed_errors = stats->rx_missed_errors; - ovsr.stats.tx_aborted_errors = stats->tx_aborted_errors; - ovsr.stats.tx_carrier_errors = stats->tx_carrier_errors; - ovsr.stats.tx_fifo_errors = stats->tx_fifo_errors; - ovsr.stats.tx_heartbeat_errors = stats->tx_heartbeat_errors; - ovsr.stats.tx_window_errors = stats->tx_window_errors; - - err = netdev_vport_do_ioctl(ODP_VPORT_STATS_SET, &ovsr); - - /* If the vport layer doesn't know about the device, that doesn't mean it - * doesn't exist (after all were able to open it when netdev_open() was - * called), it just means that it isn't attached and we'll be getting - * stats a different way. */ - if (err == ENODEV) { - err = EOPNOTSUPP; - } - - return err; -} - static int netdev_vport_update_flags(struct netdev *netdev OVS_UNUSED, enum netdev_flags off, enum netdev_flags on OVS_UNUSED, @@ -377,567 +248,390 @@ netdev_vport_update_flags(struct netdev *netdev OVS_UNUSED, return 0; } -static char * -make_poll_name(const struct netdev *netdev) -{ - return xasprintf("%s:%s", netdev_get_type(netdev), netdev_get_name(netdev)); -} - -static int -netdev_vport_poll_add(struct netdev *netdev, - void (*cb)(struct netdev_notifier *), void *aux, - struct netdev_notifier **notifierp) +static unsigned int +netdev_vport_change_seq(const struct netdev *netdev) { - char *poll_name = make_poll_name(netdev); - struct netdev_vport_notifier *notifier; - struct list *list; - struct shash_node *shash_node; - - shash_node = shash_find_data(&netdev_vport_notifiers, poll_name); - if (!shash_node) { - list = xmalloc(sizeof *list); - list_init(list); - shash_node = shash_add(&netdev_vport_notifiers, poll_name, list); - } else { - list = shash_node->data; - } - - notifier = xmalloc(sizeof *notifier); - netdev_notifier_init(¬ifier->notifier, netdev, cb, aux); - list_push_back(list, ¬ifier->list_node); - notifier->shash_node = shash_node; - - *notifierp = ¬ifier->notifier; - free(poll_name); - - return 0; + return netdev_vport_get_dev(netdev)->change_seq; } static void -netdev_vport_poll_remove(struct netdev_notifier *notifier_) +netdev_vport_run(void) { - struct netdev_vport_notifier *notifier = - CONTAINER_OF(notifier_, struct netdev_vport_notifier, notifier); - - struct list *list; - - list = list_remove(¬ifier->list_node); - if (list_is_empty(list)) { - shash_delete(&netdev_vport_notifiers, notifier->shash_node); - free(list); - } - - free(notifier); + route_table_run(); } static void -netdev_vport_run(void) +netdev_vport_wait(void) { - rtnetlink_link_notifier_run(); - rtnetlink_route_notifier_run(); + route_table_wait(); } + +/* Helper functions. */ static void -netdev_vport_wait(void) +netdev_vport_poll_notify(struct netdev_dev_vport *ndv) { - rtnetlink_link_notifier_wait(); - rtnetlink_route_notifier_wait(); + ndv->change_seq++; + if (!ndv->change_seq) { + ndv->change_seq++; + } } -/* get_tnl_iface() implementation. */ +/* Code specific to tunnel types. */ -static struct name_node * -name_node_lookup(int ifi_index) +static ovs_be64 +parse_key(const struct smap *args, const char *name, + bool *present, bool *flow) { - struct name_node *nn; + const char *s; + + *present = false; + *flow = false; - HMAP_FOR_EACH_WITH_HASH(nn, node, hash_int(ifi_index, 0), &name_map) { - if (nn->ifi_index == ifi_index) { - return nn; + s = smap_get(args, name); + if (!s) { + s = smap_get(args, "key"); + if (!s) { + return 0; } } - return NULL; -} + *present = true; -static struct route_node * -route_node_lookup(int rta_oif, uint32_t rta_dst, unsigned char rtm_dst_len) -{ - uint32_t hash; - struct route_node *rn; - - hash = hash_3words(rta_oif, rta_dst, rtm_dst_len); - HMAP_FOR_EACH_WITH_HASH(rn, node, hash, &route_map) { - if (rn->rta_oif == rn->rta_oif && - rn->rta_dst == rn->rta_dst && - rn->rtm_dst_len == rn->rtm_dst_len) { - return rn; - } + if (!strcmp(s, "flow")) { + *flow = true; + return 0; + } else { + return htonll(strtoull(s, NULL, 0)); } - - return NULL; } -/* Resets the name or route map depending on the value of 'is_name'. Clears - * the appropriate map, makes an rtnetlink dump request, and calls the change - * callback for each reply from the kernel. One should probably use - * netdev_vport_reset_routes or netdev_vport_reset_names instead. */ static int -netdev_vport_reset_name_else_route(bool is_name) +set_tunnel_config(struct netdev_dev *dev_, const struct smap *args) { - int error; - int nlmsg_type; - struct nl_dump dump; - struct rtgenmsg *rtmsg; - struct ofpbuf request, reply; - static struct nl_sock *rtnl_sock; - - if (is_name) { - struct name_node *nn, *nn_next; - - HMAP_FOR_EACH_SAFE(nn, nn_next, node, &name_map) { - hmap_remove(&name_map, &nn->node); - free(nn); - } - } else { - struct route_node *rn, *rn_next; + struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); + const char *name = netdev_dev_get_name(dev_); + const char *type = netdev_dev_get_type(dev_); + bool ipsec_mech_set, needs_dst_port, has_csum; + struct netdev_tunnel_config tnl_cfg; + struct smap_node *node; + + has_csum = strstr(type, "gre"); + ipsec_mech_set = false; + memset(&tnl_cfg, 0, sizeof tnl_cfg); + + needs_dst_port = netdev_vport_needs_dst_port(dev_); + tnl_cfg.ipsec = strstr(type, "ipsec"); + tnl_cfg.dont_fragment = true; + + SMAP_FOR_EACH (node, args) { + if (!strcmp(node->key, "remote_ip")) { + struct in_addr in_addr; + if (lookup_ip(node->value, &in_addr)) { + VLOG_WARN("%s: bad %s 'remote_ip'", name, type); + } else if (ip_is_multicast(in_addr.s_addr)) { + VLOG_WARN("%s: multicast remote_ip="IP_FMT" not allowed", + name, IP_ARGS(in_addr.s_addr)); + return EINVAL; + } else { + tnl_cfg.ip_dst = in_addr.s_addr; + } + } else if (!strcmp(node->key, "local_ip")) { + struct in_addr in_addr; + if (lookup_ip(node->value, &in_addr)) { + VLOG_WARN("%s: bad %s 'local_ip'", name, type); + } else { + tnl_cfg.ip_src = in_addr.s_addr; + } + } else if (!strcmp(node->key, "tos")) { + if (!strcmp(node->value, "inherit")) { + tnl_cfg.tos_inherit = true; + } else { + char *endptr; + int tos; + tos = strtol(node->value, &endptr, 0); + if (*endptr == '\0' && tos == (tos & IP_DSCP_MASK)) { + tnl_cfg.tos = tos; + } else { + VLOG_WARN("%s: invalid TOS %s", name, node->value); + } + } + } else if (!strcmp(node->key, "ttl")) { + if (!strcmp(node->value, "inherit")) { + tnl_cfg.ttl_inherit = true; + } else { + tnl_cfg.ttl = atoi(node->value); + } + } else if (!strcmp(node->key, "dst_port") && needs_dst_port) { + tnl_cfg.dst_port = htons(atoi(node->value)); + } else if (!strcmp(node->key, "csum") && has_csum) { + if (!strcmp(node->value, "true")) { + tnl_cfg.csum = true; + } + } else if (!strcmp(node->key, "df_default")) { + if (!strcmp(node->value, "false")) { + tnl_cfg.dont_fragment = false; + } + } else if (!strcmp(node->key, "peer_cert") && tnl_cfg.ipsec) { + if (smap_get(args, "certificate")) { + ipsec_mech_set = true; + } else { + const char *use_ssl_cert; - HMAP_FOR_EACH_SAFE(rn, rn_next, node, &route_map) { - hmap_remove(&route_map, &rn->node); - free(rn); + /* If the "use_ssl_cert" is true, then "certificate" and + * "private_key" will be pulled from the SSL table. The + * use of this option is strongly discouraged, since it + * will like be removed when multiple SSL configurations + * are supported by OVS. + */ + use_ssl_cert = smap_get(args, "use_ssl_cert"); + if (!use_ssl_cert || strcmp(use_ssl_cert, "true")) { + VLOG_ERR("%s: 'peer_cert' requires 'certificate' argument", + name); + return EINVAL; + } + ipsec_mech_set = true; + } + } else if (!strcmp(node->key, "psk") && tnl_cfg.ipsec) { + ipsec_mech_set = true; + } else if (tnl_cfg.ipsec + && (!strcmp(node->key, "certificate") + || !strcmp(node->key, "private_key") + || !strcmp(node->key, "use_ssl_cert"))) { + /* Ignore options not used by the netdev. */ + } else if (!strcmp(node->key, "key") || + !strcmp(node->key, "in_key") || + !strcmp(node->key, "out_key")) { + /* Handled separately below. */ + } else { + VLOG_WARN("%s: unknown %s argument '%s'", name, type, node->key); } } - error = nl_sock_create(NETLINK_ROUTE, 0, 0, 0, &rtnl_sock); - if (error) { - VLOG_WARN_RL(&rl, "Failed to create NETLINK_ROUTE socket"); - return error; + /* Add a default destination port for VXLAN if none specified. */ + if (!strcmp(type, "vxlan") && !tnl_cfg.dst_port) { + tnl_cfg.dst_port = htons(VXLAN_DST_PORT); } - ofpbuf_init(&request, 0); - - nlmsg_type = is_name ? RTM_GETLINK : RTM_GETROUTE; - nl_msg_put_nlmsghdr(&request, sizeof *rtmsg, nlmsg_type, NLM_F_REQUEST); - - rtmsg = ofpbuf_put_zeros(&request, sizeof *rtmsg); - rtmsg->rtgen_family = AF_INET; + /* Add a default destination port for LISP if none specified. */ + if (!strcmp(type, "lisp") && !tnl_cfg.dst_port) { + tnl_cfg.dst_port = htons(LISP_DST_PORT); + } - nl_dump_start(&dump, rtnl_sock, &request); + if (tnl_cfg.ipsec) { + static pid_t pid = 0; + if (pid <= 0) { + char *file_name = xasprintf("%s/%s", ovs_rundir(), + "ovs-monitor-ipsec.pid"); + pid = read_pidfile(file_name); + free(file_name); + } - while (nl_dump_next(&dump, &reply)) { - if (is_name) { - struct rtnetlink_link_change change; + if (pid < 0) { + VLOG_ERR("%s: IPsec requires the ovs-monitor-ipsec daemon", + name); + return EINVAL; + } - if (rtnetlink_link_parse(&reply, &change)) { - netdev_vport_link_change(&change, NULL); - } - } else { - struct rtnetlink_route_change change; + if (smap_get(args, "peer_cert") && smap_get(args, "psk")) { + VLOG_ERR("%s: cannot define both 'peer_cert' and 'psk'", name); + return EINVAL; + } - if (rtnetlink_route_parse(&reply, &change)) { - netdev_vport_route_change(&change, NULL); - } + if (!ipsec_mech_set) { + VLOG_ERR("%s: IPsec requires an 'peer_cert' or psk' argument", + name); + return EINVAL; } } - error = nl_dump_done(&dump); - nl_sock_destroy(rtnl_sock); + if (!tnl_cfg.ip_dst) { + VLOG_ERR("%s: %s type requires valid 'remote_ip' argument", + name, type); + return EINVAL; + } + if (!tnl_cfg.ttl) { + tnl_cfg.ttl = DEFAULT_TTL; + } - return error; -} + tnl_cfg.in_key = parse_key(args, "in_key", + &tnl_cfg.in_key_present, + &tnl_cfg.in_key_flow); -static int -netdev_vport_reset_routes(void) -{ - return netdev_vport_reset_name_else_route(false); -} + tnl_cfg.out_key = parse_key(args, "out_key", + &tnl_cfg.out_key_present, + &tnl_cfg.out_key_flow); -static int -netdev_vport_reset_names(void) -{ - return netdev_vport_reset_name_else_route(true); + dev->tnl_cfg = tnl_cfg; + netdev_vport_poll_notify(dev); + + return 0; } -static void -netdev_vport_route_change(const struct rtnetlink_route_change *change, - void *aux OVS_UNUSED) +static int +get_tunnel_config(struct netdev_dev *dev, struct smap *args) { + const struct netdev_tunnel_config *tnl_cfg = + &netdev_dev_vport_cast(dev)->tnl_cfg; - if (!change) { - netdev_vport_reset_routes(); - } else if (change->nlmsg_type == RTM_NEWROUTE) { - uint32_t hash; - struct route_node *rn; - - if (route_node_lookup(change->rta_oif, change->rta_dst, - change->rtm_dst_len)) { - return; - } - - rn = xzalloc(sizeof *rn); - rn->rta_oif = change->rta_oif; - rn->rta_dst = change->rta_dst; - rn->rtm_dst_len = change->rtm_dst_len; - - hash = hash_3words(rn->rta_oif, rn->rta_dst, rn->rtm_dst_len); - hmap_insert(&route_map, &rn->node, hash); - } else if (change->nlmsg_type == RTM_DELROUTE) { - struct route_node *rn; - - rn = route_node_lookup(change->rta_oif, change->rta_dst, - change->rtm_dst_len); - - if (rn) { - hmap_remove(&route_map, &rn->node); - free(rn); - } - } else { - VLOG_WARN_RL(&rl, "Received unexpected rtnetlink message type %d", - change->nlmsg_type); + if (tnl_cfg->ip_dst) { + smap_add_format(args, "remote_ip", IP_FMT, IP_ARGS(tnl_cfg->ip_dst)); } -} -static void -netdev_vport_link_change(const struct rtnetlink_link_change *change, - void *aux OVS_UNUSED) -{ - - if (!change) { - netdev_vport_reset_names(); - } else if (change->nlmsg_type == RTM_NEWLINK) { - struct name_node *nn; + if (tnl_cfg->ip_src) { + smap_add_format(args, "local_ip", IP_FMT, IP_ARGS(tnl_cfg->ip_src)); + } - if (name_node_lookup(change->ifi_index)) { - return; + if (tnl_cfg->in_key_flow && tnl_cfg->out_key_flow) { + smap_add(args, "key", "flow"); + } else if (tnl_cfg->in_key_present && tnl_cfg->out_key_present + && tnl_cfg->in_key == tnl_cfg->out_key) { + smap_add_format(args, "key", "%"PRIu64, ntohll(tnl_cfg->in_key)); + } else { + if (tnl_cfg->in_key_flow) { + smap_add(args, "in_key", "flow"); + } else if (tnl_cfg->in_key_present) { + smap_add_format(args, "in_key", "%"PRIu64, + ntohll(tnl_cfg->in_key)); } - nn = xzalloc(sizeof *nn); - nn->ifi_index = change->ifi_index; - - strncpy(nn->ifname, change->ifname, IFNAMSIZ); - nn->ifname[IFNAMSIZ - 1] = '\0'; - - hmap_insert(&name_map, &nn->node, hash_int(nn->ifi_index, 0)); - } else if (change->nlmsg_type == RTM_DELLINK) { - struct name_node *nn; - - nn = name_node_lookup(change->ifi_index); - - if (nn) { - hmap_remove(&name_map, &nn->node); - free(nn); + if (tnl_cfg->out_key_flow) { + smap_add(args, "out_key", "flow"); + } else if (tnl_cfg->out_key_present) { + smap_add_format(args, "out_key", "%"PRIu64, + ntohll(tnl_cfg->out_key)); } - - /* Link deletions do not result in all of the RTM_DELROUTE messages one - * would expect. For now, go ahead and reset route_map whenever a link - * is deleted. */ - netdev_vport_reset_routes(); - } else { - VLOG_WARN_RL(&rl, "Received unexpected rtnetlink message type %d", - change->nlmsg_type); } -} -static void -netdev_vport_tnl_iface_init(void) -{ - static bool tnl_iface_is_init = false; - - if (!tnl_iface_is_init) { - hmap_init(&name_map); - hmap_init(&route_map); - - rtnetlink_link_notifier_register(&netdev_vport_link_notifier, - netdev_vport_link_change, NULL); - - rtnetlink_route_notifier_register(&netdev_vport_route_notifier, - netdev_vport_route_change, NULL); + if (tnl_cfg->ttl_inherit) { + smap_add(args, "ttl", "inherit"); + } else if (tnl_cfg->ttl != DEFAULT_TTL) { + smap_add_format(args, "ttl", "%"PRIu8, tnl_cfg->ttl); + } - netdev_vport_reset_names(); - netdev_vport_reset_routes(); - tnl_iface_is_init = true; + if (tnl_cfg->tos_inherit) { + smap_add(args, "tos", "inherit"); + } else if (tnl_cfg->tos) { + smap_add_format(args, "tos", "0x%x", tnl_cfg->tos); } -} -static const char * -netdev_vport_get_tnl_iface(const struct netdev *netdev) -{ - int dst_len; - uint32_t route; - struct netdev_dev_vport *ndv; - struct tnl_port_config *config; - struct route_node *rn, *rn_def, *rn_iter; - - ndv = netdev_dev_vport_cast(netdev_get_dev(netdev)); - config = (struct tnl_port_config *) ndv->config; - route = ntohl(config->daddr); - - dst_len = 0; - rn = NULL; - rn_def = NULL; - - HMAP_FOR_EACH(rn_iter, node, &route_map) { - if (rn_iter->rtm_dst_len == 0 && rn_iter->rta_dst == 0) { - /* Default route. */ - rn_def = rn_iter; - } else if (rn_iter->rtm_dst_len > dst_len) { - uint32_t mask = 0xffffffff << (32 - rn_iter->rtm_dst_len); - if ((route & mask) == (rn_iter->rta_dst & mask)) { - rn = rn_iter; - dst_len = rn_iter->rtm_dst_len; - } + if (tnl_cfg->dst_port) { + uint16_t dst_port = ntohs(tnl_cfg->dst_port); + const char *type = netdev_dev_get_type(dev); + + if ((!strcmp("vxlan", type) && dst_port != VXLAN_DST_PORT) || + (!strcmp("lisp", type) && dst_port != LISP_DST_PORT)) { + smap_add_format(args, "dst_port", "%d", dst_port); } } - if (!rn) { - rn = rn_def; + if (tnl_cfg->csum) { + smap_add(args, "csum", "true"); } - if (rn) { - uint32_t hash; - struct name_node *nn; - - hash = hash_int(rn->rta_oif, 0); - HMAP_FOR_EACH_WITH_HASH(nn, node, hash, &name_map) { - if (nn->ifi_index == rn->rta_oif) { - return nn->ifname; - } - } + if (!tnl_cfg->dont_fragment) { + smap_add(args, "df_default", "false"); } - return NULL; + return 0; } -/* Helper functions. */ +/* Code specific to patch ports. */ -static int -netdev_vport_do_ioctl(int cmd, void *arg) +const char * +netdev_vport_patch_peer(const struct netdev *netdev) { - static int ioctl_fd = -1; + return netdev_vport_is_patch(netdev) + ? netdev_vport_get_dev(netdev)->peer + : NULL; +} - if (ioctl_fd < 0) { - ioctl_fd = open("/dev/net/dp0", O_RDONLY | O_NONBLOCK); - if (ioctl_fd < 0) { - VLOG_ERR_RL(&rl, "failed to open ioctl fd: %s", strerror(errno)); - return errno; - } +void +netdev_vport_inc_rx(const struct netdev *netdev, + const struct dpif_flow_stats *stats) +{ + if (is_vport_class(netdev_dev_get_class(netdev_get_dev(netdev)))) { + struct netdev_dev_vport *dev = netdev_vport_get_dev(netdev); + dev->stats.rx_packets += stats->n_packets; + dev->stats.rx_bytes += stats->n_bytes; } - - return ioctl(ioctl_fd, cmd, arg) ? errno : 0; } -static void -netdev_vport_poll_notify(const struct netdev *netdev) +void +netdev_vport_inc_tx(const struct netdev *netdev, + const struct dpif_flow_stats *stats) { - char *poll_name = make_poll_name(netdev); - struct list *list = shash_find_data(&netdev_vport_notifiers, - poll_name); - - if (list) { - struct netdev_vport_notifier *notifier; - - LIST_FOR_EACH (notifier, list_node, list) { - struct netdev_notifier *n = ¬ifier->notifier; - n->cb(n); - } + if (is_vport_class(netdev_dev_get_class(netdev_get_dev(netdev)))) { + struct netdev_dev_vport *dev = netdev_vport_get_dev(netdev); + dev->stats.tx_packets += stats->n_packets; + dev->stats.tx_bytes += stats->n_bytes; } - - free(poll_name); } - -/* Code specific to individual vport types. */ static int -parse_tunnel_config(const struct netdev_dev *dev, const struct shash *args, - void *configp) +get_patch_config(struct netdev_dev *dev_, struct smap *args) { - const char *name = netdev_dev_get_name(dev); - const char *type = netdev_dev_get_type(dev); - bool is_gre = false; - bool is_ipsec = false; - struct tnl_port_config config; - struct shash_node *node; - bool ipsec_mech_set = false; - - memset(&config, 0, sizeof config); - config.flags |= TNL_F_PMTUD; - config.flags |= TNL_F_HDR_CACHE; - - if (!strcmp(type, "gre")) { - is_gre = true; - } else if (!strcmp(type, "ipsec_gre")) { - is_gre = true; - is_ipsec = true; - - config.flags |= TNL_F_IPSEC; - - /* IPsec doesn't work when header caching is enabled. */ - config.flags &= ~TNL_F_HDR_CACHE; - } - - SHASH_FOR_EACH (node, args) { - if (!strcmp(node->name, "remote_ip")) { - struct in_addr in_addr; - if (lookup_ip(node->data, &in_addr)) { - VLOG_WARN("%s: bad %s 'remote_ip'", name, type); - } else { - config.daddr = in_addr.s_addr; - } - } else if (!strcmp(node->name, "local_ip")) { - struct in_addr in_addr; - if (lookup_ip(node->data, &in_addr)) { - VLOG_WARN("%s: bad %s 'local_ip'", name, type); - } else { - config.saddr = in_addr.s_addr; - } - } else if (!strcmp(node->name, "key") && is_gre) { - if (!strcmp(node->data, "flow")) { - config.flags |= TNL_F_IN_KEY_MATCH; - config.flags |= TNL_F_OUT_KEY_ACTION; - } else { - uint64_t key = strtoull(node->data, NULL, 0); - config.out_key = config.in_key = htonll(key); - } - } else if (!strcmp(node->name, "in_key") && is_gre) { - if (!strcmp(node->data, "flow")) { - config.flags |= TNL_F_IN_KEY_MATCH; - } else { - config.in_key = htonll(strtoull(node->data, NULL, 0)); - } - } else if (!strcmp(node->name, "out_key") && is_gre) { - if (!strcmp(node->data, "flow")) { - config.flags |= TNL_F_OUT_KEY_ACTION; - } else { - config.out_key = htonll(strtoull(node->data, NULL, 0)); - } - } else if (!strcmp(node->name, "tos")) { - if (!strcmp(node->data, "inherit")) { - config.flags |= TNL_F_TOS_INHERIT; - } else { - config.tos = atoi(node->data); - } - } else if (!strcmp(node->name, "ttl")) { - if (!strcmp(node->data, "inherit")) { - config.flags |= TNL_F_TTL_INHERIT; - } else { - config.ttl = atoi(node->data); - } - } else if (!strcmp(node->name, "csum") && is_gre) { - if (!strcmp(node->data, "true")) { - config.flags |= TNL_F_CSUM; - } - } else if (!strcmp(node->name, "pmtud")) { - if (!strcmp(node->data, "false")) { - config.flags &= ~TNL_F_PMTUD; - } - } else if (!strcmp(node->name, "header_cache")) { - if (!strcmp(node->data, "false")) { - config.flags &= ~TNL_F_HDR_CACHE; - } - } else if (!strcmp(node->name, "peer_cert") && is_ipsec) { - if (shash_find(args, "certificate")) { - ipsec_mech_set = true; - } else { - const char *use_ssl_cert; - - /* If the "use_ssl_cert" is true, then "certificate" and - * "private_key" will be pulled from the SSL table. The - * use of this option is strongly discouraged, since it - * will like be removed when multiple SSL configurations - * are supported by OVS. - */ - use_ssl_cert = shash_find_data(args, "use_ssl_cert"); - if (!use_ssl_cert || strcmp(use_ssl_cert, "true")) { - VLOG_WARN("%s: 'peer_cert' requires 'certificate' argument", - name); - return EINVAL; - } - ipsec_mech_set = true; - } - } else if (!strcmp(node->name, "psk") && is_ipsec) { - ipsec_mech_set = true; - } else if (is_ipsec - && (!strcmp(node->name, "certificate") - || !strcmp(node->name, "private_key") - || !strcmp(node->name, "use_ssl_cert"))) { - /* Ignore options not used by the netdev. */ - } else { - VLOG_WARN("%s: unknown %s argument '%s'", - name, type, node->name); - } - } - - if (is_ipsec) { - if (shash_find(args, "peer_cert") && shash_find(args, "psk")) { - VLOG_WARN("%s: cannot define both 'peer_cert' and 'psk'", name); - return EINVAL; - } + struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); - if (!ipsec_mech_set) { - VLOG_WARN("%s: IPsec requires an 'peer_cert' or psk' argument", - name); - return EINVAL; - } + if (dev->peer) { + smap_add(args, "peer", dev->peer); } - - if (!config.daddr) { - VLOG_WARN("%s: %s type requires valid 'remote_ip' argument", - name, type); - return EINVAL; - } - - BUILD_ASSERT(sizeof config <= VPORT_CONFIG_SIZE); - memcpy(configp, &config, sizeof config); return 0; } static int -parse_patch_config(const struct netdev_dev *dev, const struct shash *args, - void *configp) +set_patch_config(struct netdev_dev *dev_, const struct smap *args) { - const char *name = netdev_dev_get_name(dev); + struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); + const char *name = netdev_dev_get_name(dev_); const char *peer; - peer = shash_find_data(args, "peer"); + peer = smap_get(args, "peer"); if (!peer) { - VLOG_WARN("%s: patch type requires valid 'peer' argument", name); - return EINVAL; - } - - if (shash_count(args) > 1) { - VLOG_WARN("%s: patch type takes only a 'peer' argument", name); + VLOG_ERR("%s: patch type requires valid 'peer' argument", name); return EINVAL; } - if (strlen(peer) >= MIN(IFNAMSIZ, VPORT_CONFIG_SIZE)) { - VLOG_WARN("%s: patch 'peer' arg too long", name); + if (smap_count(args) > 1) { + VLOG_ERR("%s: patch type takes only a 'peer' argument", name); return EINVAL; } if (!strcmp(name, peer)) { - VLOG_WARN("%s: patch peer must not be self", name); + VLOG_ERR("%s: patch peer must not be self", name); return EINVAL; } - strncpy(configp, peer, VPORT_CONFIG_SIZE); + free(dev->peer); + dev->peer = xstrdup(peer); + + return 0; +} +static int +get_stats(const struct netdev *netdev, struct netdev_stats *stats) +{ + struct netdev_dev_vport *dev = netdev_vport_get_dev(netdev); + memcpy(stats, &dev->stats, sizeof *stats); return 0; } -#define VPORT_FUNCTIONS(TNL_IFACE) \ - netdev_vport_init, \ +#define VPORT_FUNCTIONS(GET_CONFIG, SET_CONFIG, \ + GET_TUNNEL_CONFIG, GET_STATUS) \ + NULL, \ netdev_vport_run, \ netdev_vport_wait, \ \ netdev_vport_create, \ netdev_vport_destroy, \ - netdev_vport_reconfigure, \ + GET_CONFIG, \ + SET_CONFIG, \ + GET_TUNNEL_CONFIG, \ \ netdev_vport_open, \ netdev_vport_close, \ \ - NULL, /* enumerate */ \ - \ + NULL, /* listen */ \ NULL, /* recv */ \ NULL, /* recv_wait */ \ NULL, /* drain */ \ @@ -947,15 +641,17 @@ parse_patch_config(const struct netdev_dev *dev, const struct shash *args, \ netdev_vport_set_etheraddr, \ netdev_vport_get_etheraddr, \ - netdev_vport_get_mtu, \ + NULL, /* get_mtu */ \ + NULL, /* set_mtu */ \ NULL, /* get_ifindex */ \ NULL, /* get_carrier */ \ - netdev_vport_get_stats, \ - netdev_vport_set_stats, \ + NULL, /* get_carrier_resets */ \ + NULL, /* get_miimon */ \ + get_stats, \ + NULL, /* set_stats */ \ \ NULL, /* get_features */ \ NULL, /* set_advertisements */ \ - NULL, /* get_vlan_vid */ \ \ NULL, /* set_policing */ \ NULL, /* get_qos_types */ \ @@ -974,25 +670,30 @@ parse_patch_config(const struct netdev_dev *dev, const struct shash *args, NULL, /* get_in6 */ \ NULL, /* add_router */ \ NULL, /* get_next_hop */ \ - TNL_IFACE, \ + GET_STATUS, \ NULL, /* arp_lookup */ \ \ netdev_vport_update_flags, \ \ - netdev_vport_poll_add, \ - netdev_vport_poll_remove, + netdev_vport_change_seq + +#define TUNNEL_CLASS(NAME, DPIF_PORT) \ + { DPIF_PORT, \ + { NAME, VPORT_FUNCTIONS(get_tunnel_config, \ + set_tunnel_config, \ + get_netdev_tunnel_config, \ + tunnel_get_status) }} void -netdev_vport_register(void) +netdev_vport_tunnel_register(void) { static const struct vport_class vport_classes[] = { - { { "gre", VPORT_FUNCTIONS(netdev_vport_get_tnl_iface) }, - parse_tunnel_config }, - { { "ipsec_gre", VPORT_FUNCTIONS(netdev_vport_get_tnl_iface) }, - parse_tunnel_config }, - { { "capwap", VPORT_FUNCTIONS(netdev_vport_get_tnl_iface) }, - parse_tunnel_config }, - { { "patch", VPORT_FUNCTIONS(NULL) }, parse_patch_config } + TUNNEL_CLASS("gre", "gre_system"), + TUNNEL_CLASS("ipsec_gre", "gre_system"), + TUNNEL_CLASS("gre64", "gre64_system"), + TUNNEL_CLASS("ipsec_gre64", "gre64_system"), + TUNNEL_CLASS("vxlan", "vxlan_system"), + TUNNEL_CLASS("lisp", "lisp_system") }; int i; @@ -1001,3 +702,15 @@ netdev_vport_register(void) netdev_register_provider(&vport_classes[i].netdev_class); } } + +void +netdev_vport_patch_register(void) +{ + static const struct vport_class patch_class = + { NULL, + { "patch", VPORT_FUNCTIONS(get_patch_config, + set_patch_config, + NULL, + NULL) }}; + netdev_register_provider(&patch_class.netdev_class); +}