X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=lib%2Fnetdev-vport.c;h=d85d528454b46201675ff252ab022482bd914217;hb=f613a0d72c521ca3a4eeb2c29ac523f6fdf72667;hp=55662890f86a4ca4ea94936924311df5339c9d1c;hpb=b9298d3f825703063c9538aa37407da43e1e4781;p=sliver-openvswitch.git diff --git a/lib/netdev-vport.c b/lib/netdev-vport.c index 55662890f..d85d52845 100644 --- a/lib/netdev-vport.c +++ b/lib/netdev-vport.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2010 Nicira Networks. + * Copyright (c) 2010, 2011 Nicira Networks. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -20,30 +20,40 @@ #include #include +#include +#include #include #include #include "byte-order.h" +#include "daemon.h" +#include "dirs.h" +#include "dpif-linux.h" +#include "hash.h" +#include "hmap.h" #include "list.h" +#include "netdev-linux.h" #include "netdev-provider.h" +#include "netlink.h" +#include "netlink-notifier.h" +#include "netlink-socket.h" +#include "ofpbuf.h" #include "openvswitch/datapath-protocol.h" #include "openvswitch/tunnel.h" #include "packets.h" +#include "route-table.h" #include "shash.h" #include "socket-util.h" #include "vlog.h" VLOG_DEFINE_THIS_MODULE(netdev_vport); -struct netdev_vport_notifier { - struct netdev_notifier notifier; - struct list list_node; - struct shash_node *shash_node; -}; - struct netdev_dev_vport { struct netdev_dev netdev_dev; - uint64_t config[VPORT_CONFIG_SIZE / 8]; + struct ofpbuf *options; + int dp_ifindex; /* -1 if unknown. */ + uint32_t port_no; /* UINT32_MAX if unknown. */ + unsigned int change_seq; }; struct netdev_vport { @@ -51,20 +61,25 @@ struct netdev_vport { }; struct vport_class { + enum ovs_vport_type type; struct netdev_class netdev_class; - int (*parse_config)(const struct netdev_dev *, const struct shash *args, - void *config); + int (*parse_config)(const char *name, const char *type, + const struct shash *args, struct ofpbuf *options); + int (*unparse_config)(const char *name, const char *type, + const struct nlattr *options, size_t options_len, + struct shash *args); }; -static struct shash netdev_vport_notifiers = - SHASH_INITIALIZER(&netdev_vport_notifiers); - static struct vlog_rate_limit rl = VLOG_RATE_LIMIT_INIT(5, 20); -static int netdev_vport_do_ioctl(int cmd, void *arg); static int netdev_vport_create(const struct netdev_class *, const char *, - const struct shash *, struct netdev_dev **); + struct netdev_dev **); static void netdev_vport_poll_notify(const struct netdev *); +static int tnl_port_config_from_nlattr(const struct nlattr *options, + size_t options_len, + struct nlattr *a[OVS_TUNNEL_ATTR_MAX + 1]); + +static const char *netdev_vport_get_tnl_iface(const struct netdev *netdev); static bool is_vport_class(const struct netdev_class *class) @@ -94,39 +109,86 @@ netdev_vport_cast(const struct netdev *netdev) return CONTAINER_OF(netdev, struct netdev_vport, netdev); } -/* If 'netdev' is a vport netdev, copies its kernel configuration into - * 'config'. Otherwise leaves 'config' untouched. */ -void -netdev_vport_get_config(const struct netdev *netdev, void *config) +/* If 'netdev' is a vport netdev, returns an ofpbuf that contains Netlink + * options to include in OVS_VPORT_ATTR_OPTIONS for configuring that vport. + * Otherwise returns NULL. */ +const struct ofpbuf * +netdev_vport_get_options(const struct netdev *netdev) +{ + const struct netdev_dev *dev = netdev_get_dev(netdev); + + return (is_vport_class(netdev_dev_get_class(dev)) + ? netdev_dev_vport_cast(dev)->options + : NULL); +} + +enum ovs_vport_type +netdev_vport_get_vport_type(const struct netdev *netdev) { const struct netdev_dev *dev = netdev_get_dev(netdev); + const struct netdev_class *class = netdev_dev_get_class(dev); + + return (is_vport_class(class) ? vport_class_cast(class)->type + : class == &netdev_internal_class ? OVS_VPORT_TYPE_INTERNAL + : class == &netdev_linux_class ? OVS_VPORT_TYPE_NETDEV + : OVS_VPORT_TYPE_UNSPEC); +} + +const char * +netdev_vport_get_netdev_type(const struct dpif_linux_vport *vport) +{ + struct nlattr *a[OVS_TUNNEL_ATTR_MAX + 1]; - if (is_vport_class(netdev_dev_get_class(dev))) { - const struct netdev_dev_vport *vport = netdev_dev_vport_cast(dev); - memcpy(config, vport->config, VPORT_CONFIG_SIZE); + switch (vport->type) { + case OVS_VPORT_TYPE_UNSPEC: + break; + + case OVS_VPORT_TYPE_NETDEV: + return "system"; + + case OVS_VPORT_TYPE_INTERNAL: + return "internal"; + + case OVS_VPORT_TYPE_PATCH: + return "patch"; + + case OVS_VPORT_TYPE_GRE: + if (tnl_port_config_from_nlattr(vport->options, vport->options_len, + a)) { + break; + } + return (nl_attr_get_u32(a[OVS_TUNNEL_ATTR_FLAGS]) & TNL_F_IPSEC + ? "ipsec_gre" : "gre"); + + case OVS_VPORT_TYPE_CAPWAP: + return "capwap"; + + case __OVS_VPORT_TYPE_MAX: + break; } + + VLOG_WARN_RL(&rl, "dp%d: port `%s' has unsupported type %u", + vport->dp_ifindex, vport->name, (unsigned int) vport->type); + return "unknown"; } static int netdev_vport_create(const struct netdev_class *netdev_class, const char *name, - const struct shash *args, struct netdev_dev **netdev_devp) { - const struct vport_class *vport_class = vport_class_cast(netdev_class); struct netdev_dev_vport *dev; - int error; dev = xmalloc(sizeof *dev); - *netdev_devp = &dev->netdev_dev; netdev_dev_init(&dev->netdev_dev, name, netdev_class); + dev->options = NULL; + dev->dp_ifindex = -1; + dev->port_no = UINT32_MAX; + dev->change_seq = 1; - memset(dev->config, 0, sizeof dev->config); - error = vport_class->parse_config(&dev->netdev_dev, args, dev->config); + *netdev_devp = &dev->netdev_dev; + route_table_register(); - if (error) { - netdev_dev_uninit(&dev->netdev_dev, true); - } - return error; + return 0; } static void @@ -134,12 +196,12 @@ netdev_vport_destroy(struct netdev_dev *netdev_dev_) { struct netdev_dev_vport *netdev_dev = netdev_dev_vport_cast(netdev_dev_); + route_table_unregister(); free(netdev_dev); } static int -netdev_vport_open(struct netdev_dev *netdev_dev_, int ethertype OVS_UNUSED, - struct netdev **netdevp) +netdev_vport_open(struct netdev_dev *netdev_dev_, struct netdev **netdevp) { struct netdev_vport *netdev; @@ -158,123 +220,204 @@ netdev_vport_close(struct netdev *netdev_) } static int -netdev_vport_reconfigure(struct netdev_dev *dev_, - const struct shash *args) +netdev_vport_get_config(struct netdev_dev *dev_, struct shash *args) +{ + const struct netdev_class *netdev_class = netdev_dev_get_class(dev_); + const struct vport_class *vport_class = vport_class_cast(netdev_class); + struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); + const char *name = netdev_dev_get_name(dev_); + int error; + + if (!dev->options) { + struct dpif_linux_vport reply; + struct ofpbuf *buf; + + error = dpif_linux_vport_get(name, &reply, &buf); + if (error) { + VLOG_ERR_RL(&rl, "%s: vport query failed (%s)", + name, strerror(error)); + return error; + } + + dev->options = ofpbuf_clone_data(reply.options, reply.options_len); + dev->dp_ifindex = reply.dp_ifindex; + dev->port_no = reply.port_no; + ofpbuf_delete(buf); + } + + error = vport_class->unparse_config(name, netdev_class->type, + dev->options->data, + dev->options->size, + args); + if (error) { + VLOG_ERR_RL(&rl, "%s: failed to parse kernel config (%s)", + name, strerror(error)); + } + return error; +} + +static int +netdev_vport_set_config(struct netdev_dev *dev_, const struct shash *args) { const struct netdev_class *netdev_class = netdev_dev_get_class(dev_); const struct vport_class *vport_class = vport_class_cast(netdev_class); struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); - struct odp_port port; + const char *name = netdev_dev_get_name(dev_); + struct ofpbuf *options; int error; - memset(&port, 0, sizeof port); - strncpy(port.devname, netdev_dev_get_name(dev_), sizeof port.devname); - strncpy(port.type, netdev_dev_get_type(dev_), sizeof port.type); - error = vport_class->parse_config(dev_, args, port.config); - if (!error && memcmp(port.config, dev->config, sizeof dev->config)) { - error = netdev_vport_do_ioctl(ODP_VPORT_MOD, &port); + options = ofpbuf_new(64); + error = vport_class->parse_config(name, netdev_dev_get_type(dev_), + args, options); + if (!error + && (!dev->options + || options->size != dev->options->size + || memcmp(options->data, dev->options->data, options->size))) { + struct dpif_linux_vport vport; + + dpif_linux_vport_init(&vport); + vport.cmd = OVS_VPORT_CMD_SET; + vport.name = name; + vport.options = options->data; + vport.options_len = options->size; + error = dpif_linux_vport_transact(&vport, NULL, NULL); if (!error || error == ENODEV) { /* Either reconfiguration succeeded or this vport is not installed * in the kernel (e.g. it hasn't been added to a dpif yet with * dpif_port_add()). */ - memcpy(dev->config, port.config, sizeof dev->config); + ofpbuf_delete(dev->options); + dev->options = options; + options = NULL; + error = 0; } } + ofpbuf_delete(options); + return error; } static int -netdev_vport_set_etheraddr(struct netdev *netdev, - const uint8_t mac[ETH_ADDR_LEN]) +netdev_vport_send(struct netdev *netdev, const void *data, size_t size) { - struct odp_vport_ether vport_ether; - int err; - - ovs_strlcpy(vport_ether.devname, netdev_get_name(netdev), - sizeof vport_ether.devname); - - memcpy(vport_ether.ether_addr, mac, ETH_ADDR_LEN); + struct netdev_dev *dev_ = netdev_get_dev(netdev); + struct netdev_dev_vport *dev = netdev_dev_vport_cast(dev_); - err = netdev_vport_do_ioctl(ODP_VPORT_ETHER_SET, &vport_ether); - if (err) { - return err; + if (dev->dp_ifindex == -1) { + const char *name = netdev_get_name(netdev); + struct dpif_linux_vport reply; + struct ofpbuf *buf; + int error; + + error = dpif_linux_vport_get(name, &reply, &buf); + if (error) { + VLOG_ERR_RL(&rl, "%s: failed to query vport for send (%s)", + name, strerror(error)); + return error; + } + dev->dp_ifindex = reply.dp_ifindex; + dev->port_no = reply.port_no; + ofpbuf_delete(buf); } - netdev_vport_poll_notify(netdev); - return 0; + return dpif_linux_vport_send(dev->dp_ifindex, dev->port_no, data, size); } static int -netdev_vport_get_etheraddr(const struct netdev *netdev, - uint8_t mac[ETH_ADDR_LEN]) +netdev_vport_set_etheraddr(struct netdev *netdev, + const uint8_t mac[ETH_ADDR_LEN]) { - struct odp_vport_ether vport_ether; - int err; + struct dpif_linux_vport vport; + int error; - ovs_strlcpy(vport_ether.devname, netdev_get_name(netdev), - sizeof vport_ether.devname); + dpif_linux_vport_init(&vport); + vport.cmd = OVS_VPORT_CMD_SET; + vport.name = netdev_get_name(netdev); + vport.address = mac; - err = netdev_vport_do_ioctl(ODP_VPORT_ETHER_GET, &vport_ether); - if (err) { - return err; + error = dpif_linux_vport_transact(&vport, NULL, NULL); + if (!error) { + netdev_vport_poll_notify(netdev); } - - memcpy(mac, vport_ether.ether_addr, ETH_ADDR_LEN); - return 0; + return error; } static int -netdev_vport_get_mtu(const struct netdev *netdev, int *mtup) +netdev_vport_get_etheraddr(const struct netdev *netdev, + uint8_t mac[ETH_ADDR_LEN]) { - struct odp_vport_mtu vport_mtu; - int err; - - ovs_strlcpy(vport_mtu.devname, netdev_get_name(netdev), - sizeof vport_mtu.devname); + struct dpif_linux_vport reply; + struct ofpbuf *buf; + int error; - err = netdev_vport_do_ioctl(ODP_VPORT_MTU_GET, &vport_mtu); - if (err) { - return err; + error = dpif_linux_vport_get(netdev_get_name(netdev), &reply, &buf); + if (!error) { + if (reply.address) { + memcpy(mac, reply.address, ETH_ADDR_LEN); + } else { + error = EOPNOTSUPP; + } + ofpbuf_delete(buf); } + return error; +} - *mtup = vport_mtu.mtu; - return 0; +#define COPY_OVS_STATS \ + dst->rx_packets = src->rx_packets; \ + dst->tx_packets = src->tx_packets; \ + dst->rx_bytes = src->rx_bytes; \ + dst->tx_bytes = src->tx_bytes; \ + dst->rx_errors = src->rx_errors; \ + dst->tx_errors = src->tx_errors; \ + dst->rx_dropped = src->rx_dropped; \ + dst->tx_dropped = src->tx_dropped; + +/* Copies 'src' into 'dst', performing format conversion in the process. */ +static void +netdev_stats_from_ovs_vport_stats(struct netdev_stats *dst, + const struct ovs_vport_stats *src) +{ + COPY_OVS_STATS + dst->multicast = 0; + dst->collisions = 0; + dst->rx_length_errors = 0; + dst->rx_over_errors = 0; + dst->rx_crc_errors = 0; + dst->rx_frame_errors = 0; + dst->rx_fifo_errors = 0; + dst->rx_missed_errors = 0; + dst->tx_aborted_errors = 0; + dst->tx_carrier_errors = 0; + dst->tx_fifo_errors = 0; + dst->tx_heartbeat_errors = 0; + dst->tx_window_errors = 0; +} + +/* Copies 'src' into 'dst', performing format conversion in the process. */ +static void +netdev_stats_to_ovs_vport_stats(struct ovs_vport_stats *dst, + const struct netdev_stats *src) +{ + COPY_OVS_STATS } int netdev_vport_get_stats(const struct netdev *netdev, struct netdev_stats *stats) { - const char *name = netdev_get_name(netdev); - struct odp_vport_stats_req ovsr; - int err; + struct dpif_linux_vport reply; + struct ofpbuf *buf; + int error; - ovs_strlcpy(ovsr.devname, name, sizeof ovsr.devname); - err = netdev_vport_do_ioctl(ODP_VPORT_STATS_GET, &ovsr); - if (err) { - return err; - } - - stats->rx_packets = ovsr.stats.rx_packets; - stats->tx_packets = ovsr.stats.tx_packets; - stats->rx_bytes = ovsr.stats.rx_bytes; - stats->tx_bytes = ovsr.stats.tx_bytes; - stats->rx_errors = ovsr.stats.rx_errors; - stats->tx_errors = ovsr.stats.tx_errors; - stats->rx_dropped = ovsr.stats.rx_dropped; - stats->tx_dropped = ovsr.stats.tx_dropped; - stats->multicast = ovsr.stats.multicast; - stats->collisions = ovsr.stats.collisions; - stats->rx_length_errors = ovsr.stats.rx_length_errors; - stats->rx_over_errors = ovsr.stats.rx_over_errors; - stats->rx_crc_errors = ovsr.stats.rx_crc_errors; - stats->rx_frame_errors = ovsr.stats.rx_frame_errors; - stats->rx_fifo_errors = ovsr.stats.rx_fifo_errors; - stats->rx_missed_errors = ovsr.stats.rx_missed_errors; - stats->tx_aborted_errors = ovsr.stats.tx_aborted_errors; - stats->tx_carrier_errors = ovsr.stats.tx_carrier_errors; - stats->tx_fifo_errors = ovsr.stats.tx_fifo_errors; - stats->tx_heartbeat_errors = ovsr.stats.tx_heartbeat_errors; - stats->tx_window_errors = ovsr.stats.tx_window_errors; + error = dpif_linux_vport_get(netdev_get_name(netdev), &reply, &buf); + if (error) { + return error; + } else if (!reply.stats) { + ofpbuf_delete(buf); + return EOPNOTSUPP; + } + + netdev_stats_from_ovs_vport_stats(stats, reply.stats); + + ofpbuf_delete(buf); return 0; } @@ -282,34 +425,18 @@ netdev_vport_get_stats(const struct netdev *netdev, struct netdev_stats *stats) int netdev_vport_set_stats(struct netdev *netdev, const struct netdev_stats *stats) { - struct odp_vport_stats_req ovsr; + struct ovs_vport_stats rtnl_stats; + struct dpif_linux_vport vport; int err; - ovs_strlcpy(ovsr.devname, netdev_get_name(netdev), sizeof ovsr.devname); - - ovsr.stats.rx_packets = stats->rx_packets; - ovsr.stats.tx_packets = stats->tx_packets; - ovsr.stats.rx_bytes = stats->rx_bytes; - ovsr.stats.tx_bytes = stats->tx_bytes; - ovsr.stats.rx_errors = stats->rx_errors; - ovsr.stats.tx_errors = stats->tx_errors; - ovsr.stats.rx_dropped = stats->rx_dropped; - ovsr.stats.tx_dropped = stats->tx_dropped; - ovsr.stats.multicast = stats->multicast; - ovsr.stats.collisions = stats->collisions; - ovsr.stats.rx_length_errors = stats->rx_length_errors; - ovsr.stats.rx_over_errors = stats->rx_over_errors; - ovsr.stats.rx_crc_errors = stats->rx_crc_errors; - ovsr.stats.rx_frame_errors = stats->rx_frame_errors; - ovsr.stats.rx_fifo_errors = stats->rx_fifo_errors; - ovsr.stats.rx_missed_errors = stats->rx_missed_errors; - ovsr.stats.tx_aborted_errors = stats->tx_aborted_errors; - ovsr.stats.tx_carrier_errors = stats->tx_carrier_errors; - ovsr.stats.tx_fifo_errors = stats->tx_fifo_errors; - ovsr.stats.tx_heartbeat_errors = stats->tx_heartbeat_errors; - ovsr.stats.tx_window_errors = stats->tx_window_errors; - - err = netdev_vport_do_ioctl(ODP_VPORT_STATS_SET, &ovsr); + netdev_stats_to_ovs_vport_stats(&rtnl_stats, stats); + + dpif_linux_vport_init(&vport); + vport.cmd = OVS_VPORT_CMD_SET; + vport.name = netdev_get_name(netdev); + vport.stats = &rtnl_stats; + + err = dpif_linux_vport_transact(&vport, NULL, NULL); /* If the vport layer doesn't know about the device, that doesn't mean it * doesn't exist (after all were able to open it when netdev_open() was @@ -322,6 +449,27 @@ netdev_vport_set_stats(struct netdev *netdev, const struct netdev_stats *stats) return err; } +static int +netdev_vport_get_status(const struct netdev *netdev, struct shash *sh) +{ + const char *iface = netdev_vport_get_tnl_iface(netdev); + + if (iface) { + struct netdev *egress_netdev; + + shash_add(sh, "tunnel_egress_iface", xstrdup(iface)); + + if (!netdev_open(iface, "system", &egress_netdev)) { + shash_add(sh, "tunnel_egress_iface_carrier", + xstrdup(netdev_get_carrier(egress_netdev) + ? "up" : "down")); + netdev_close(egress_netdev); + } + } + + return 0; +} + static int netdev_vport_update_flags(struct netdev *netdev OVS_UNUSED, enum netdev_flags off, enum netdev_flags on OVS_UNUSED, @@ -335,113 +483,105 @@ netdev_vport_update_flags(struct netdev *netdev OVS_UNUSED, return 0; } -static char * -make_poll_name(const struct netdev *netdev) +static unsigned int +netdev_vport_change_seq(const struct netdev *netdev) { - return xasprintf("%s:%s", netdev_get_type(netdev), netdev_get_name(netdev)); + return netdev_dev_vport_cast(netdev_get_dev(netdev))->change_seq; } -static int -netdev_vport_poll_add(struct netdev *netdev, - void (*cb)(struct netdev_notifier *), void *aux, - struct netdev_notifier **notifierp) -{ - char *poll_name = make_poll_name(netdev); - struct netdev_vport_notifier *notifier; - struct list *list; - struct shash_node *shash_node; - - shash_node = shash_find_data(&netdev_vport_notifiers, poll_name); - if (!shash_node) { - list = xmalloc(sizeof *list); - list_init(list); - shash_node = shash_add(&netdev_vport_notifiers, poll_name, list); - } else { - list = shash_node->data; - } - - notifier = xmalloc(sizeof *notifier); - netdev_notifier_init(¬ifier->notifier, netdev, cb, aux); - list_push_back(list, ¬ifier->list_node); - notifier->shash_node = shash_node; - - *notifierp = ¬ifier->notifier; - free(poll_name); - - return 0; +static void +netdev_vport_run(void) +{ + route_table_run(); } static void -netdev_vport_poll_remove(struct netdev_notifier *notifier_) +netdev_vport_wait(void) { - struct netdev_vport_notifier *notifier = - CONTAINER_OF(notifier_, struct netdev_vport_notifier, notifier); - - struct list *list; + route_table_wait(); +} + +/* get_tnl_iface() implementation. */ +static const char * +netdev_vport_get_tnl_iface(const struct netdev *netdev) +{ + struct nlattr *a[OVS_TUNNEL_ATTR_MAX + 1]; + ovs_be32 route; + struct netdev_dev_vport *ndv; + static char name[IFNAMSIZ]; + + ndv = netdev_dev_vport_cast(netdev_get_dev(netdev)); + if (tnl_port_config_from_nlattr(ndv->options->data, ndv->options->size, + a)) { + return NULL; + } + route = nl_attr_get_be32(a[OVS_TUNNEL_ATTR_DST_IPV4]); - list = list_remove(¬ifier->list_node); - if (list_is_empty(list)) { - shash_delete(&netdev_vport_notifiers, notifier->shash_node); - free(list); + if (route_table_get_name(route, name)) { + return name; } - free(notifier); + return NULL; } /* Helper functions. */ -static int -netdev_vport_do_ioctl(int cmd, void *arg) +static void +netdev_vport_poll_notify(const struct netdev *netdev) { - static int ioctl_fd = -1; + struct netdev_dev_vport *ndv; - if (ioctl_fd < 0) { - ioctl_fd = open("/dev/net/dp0", O_RDONLY | O_NONBLOCK); - if (ioctl_fd < 0) { - VLOG_ERR_RL(&rl, "failed to open ioctl fd: %s", strerror(errno)); - return errno; - } - } + ndv = netdev_dev_vport_cast(netdev_get_dev(netdev)); - return ioctl(ioctl_fd, cmd, arg) ? errno : 0; + ndv->change_seq++; + if (!ndv->change_seq) { + ndv->change_seq++; + } } + +/* Code specific to individual vport types. */ static void -netdev_vport_poll_notify(const struct netdev *netdev) +set_key(const struct shash *args, const char *name, uint16_t type, + struct ofpbuf *options) { - char *poll_name = make_poll_name(netdev); - struct list *list = shash_find_data(&netdev_vport_notifiers, - poll_name); - - if (list) { - struct netdev_vport_notifier *notifier; + const char *s; - LIST_FOR_EACH (notifier, list_node, list) { - struct netdev_notifier *n = ¬ifier->notifier; - n->cb(n); + s = shash_find_data(args, name); + if (!s) { + s = shash_find_data(args, "key"); + if (!s) { + s = "0"; } } - free(poll_name); + if (!strcmp(s, "flow")) { + /* This is the default if no attribute is present. */ + } else { + nl_msg_put_be64(options, type, htonll(strtoull(s, NULL, 0))); + } } - -/* Code specific to individual vport types. */ static int -parse_tunnel_config(const struct netdev_dev *dev, const struct shash *args, - void *configp) +parse_tunnel_config(const char *name, const char *type, + const struct shash *args, struct ofpbuf *options) { - const char *name = netdev_dev_get_name(dev); - const char *type = netdev_dev_get_type(dev); - bool is_gre = !strcmp(type, "gre"); - struct tnl_port_config config; + bool is_gre = false; + bool is_ipsec = false; struct shash_node *node; - bool ipsec_ip_set = false; bool ipsec_mech_set = false; - - memset(&config, 0, sizeof config); - config.flags |= TNL_F_PMTUD; - config.flags |= TNL_F_HDR_CACHE; + ovs_be32 daddr = htonl(0); + uint32_t flags; + + flags = TNL_F_DF_DEFAULT | TNL_F_PMTUD | TNL_F_HDR_CACHE; + if (!strcmp(type, "gre")) { + is_gre = true; + } else if (!strcmp(type, "ipsec_gre")) { + is_gre = true; + is_ipsec = true; + flags |= TNL_F_IPSEC; + flags &= ~TNL_F_HDR_CACHE; + } SHASH_FOR_EACH (node, args) { if (!strcmp(node->name, "remote_ip")) { @@ -449,147 +589,319 @@ parse_tunnel_config(const struct netdev_dev *dev, const struct shash *args, if (lookup_ip(node->data, &in_addr)) { VLOG_WARN("%s: bad %s 'remote_ip'", name, type); } else { - config.daddr = in_addr.s_addr; + daddr = in_addr.s_addr; } } else if (!strcmp(node->name, "local_ip")) { struct in_addr in_addr; if (lookup_ip(node->data, &in_addr)) { VLOG_WARN("%s: bad %s 'local_ip'", name, type); } else { - config.saddr = in_addr.s_addr; - } - } else if (!strcmp(node->name, "key") && is_gre) { - if (!strcmp(node->data, "flow")) { - config.flags |= TNL_F_IN_KEY_MATCH; - config.flags |= TNL_F_OUT_KEY_ACTION; - } else { - uint64_t key = strtoull(node->data, NULL, 0); - config.out_key = config.in_key = htonll(key); - } - } else if (!strcmp(node->name, "in_key") && is_gre) { - if (!strcmp(node->data, "flow")) { - config.flags |= TNL_F_IN_KEY_MATCH; - } else { - config.in_key = htonll(strtoull(node->data, NULL, 0)); - } - } else if (!strcmp(node->name, "out_key") && is_gre) { - if (!strcmp(node->data, "flow")) { - config.flags |= TNL_F_OUT_KEY_ACTION; - } else { - config.out_key = htonll(strtoull(node->data, NULL, 0)); + nl_msg_put_be32(options, OVS_TUNNEL_ATTR_SRC_IPV4, + in_addr.s_addr); } } else if (!strcmp(node->name, "tos")) { if (!strcmp(node->data, "inherit")) { - config.flags |= TNL_F_TOS_INHERIT; + flags |= TNL_F_TOS_INHERIT; } else { - config.tos = atoi(node->data); + nl_msg_put_u8(options, OVS_TUNNEL_ATTR_TOS, atoi(node->data)); } } else if (!strcmp(node->name, "ttl")) { if (!strcmp(node->data, "inherit")) { - config.flags |= TNL_F_TTL_INHERIT; + flags |= TNL_F_TTL_INHERIT; } else { - config.ttl = atoi(node->data); + nl_msg_put_u8(options, OVS_TUNNEL_ATTR_TTL, atoi(node->data)); } } else if (!strcmp(node->name, "csum") && is_gre) { if (!strcmp(node->data, "true")) { - config.flags |= TNL_F_CSUM; + flags |= TNL_F_CSUM; + } + } else if (!strcmp(node->name, "df_inherit")) { + if (!strcmp(node->data, "true")) { + flags |= TNL_F_DF_INHERIT; + } + } else if (!strcmp(node->name, "df_default")) { + if (!strcmp(node->data, "false")) { + flags &= ~TNL_F_DF_DEFAULT; } } else if (!strcmp(node->name, "pmtud")) { if (!strcmp(node->data, "false")) { - config.flags &= ~TNL_F_PMTUD; + flags &= ~TNL_F_PMTUD; } } else if (!strcmp(node->name, "header_cache")) { if (!strcmp(node->data, "false")) { - config.flags &= ~TNL_F_HDR_CACHE; + flags &= ~TNL_F_HDR_CACHE; } - } else if (!strcmp(node->name, "ipsec_local_ip")) { - ipsec_ip_set = true; - } else if (!strcmp(node->name, "ipsec_cert") - || !strcmp(node->name, "ipsec_psk")) { + } else if (!strcmp(node->name, "peer_cert") && is_ipsec) { + if (shash_find(args, "certificate")) { + ipsec_mech_set = true; + } else { + const char *use_ssl_cert; + + /* If the "use_ssl_cert" is true, then "certificate" and + * "private_key" will be pulled from the SSL table. The + * use of this option is strongly discouraged, since it + * will like be removed when multiple SSL configurations + * are supported by OVS. + */ + use_ssl_cert = shash_find_data(args, "use_ssl_cert"); + if (!use_ssl_cert || strcmp(use_ssl_cert, "true")) { + VLOG_ERR("%s: 'peer_cert' requires 'certificate' argument", + name); + return EINVAL; + } + ipsec_mech_set = true; + } + } else if (!strcmp(node->name, "psk") && is_ipsec) { ipsec_mech_set = true; + } else if (is_ipsec + && (!strcmp(node->name, "certificate") + || !strcmp(node->name, "private_key") + || !strcmp(node->name, "use_ssl_cert"))) { + /* Ignore options not used by the netdev. */ + } else if (!strcmp(node->name, "key") || + !strcmp(node->name, "in_key") || + !strcmp(node->name, "out_key")) { + /* Handled separately below. */ } else { - VLOG_WARN("%s: unknown %s argument '%s'", - name, type, node->name); + VLOG_WARN("%s: unknown %s argument '%s'", name, type, node->name); + } + } + + if (is_ipsec) { + char *file_name = xasprintf("%s/%s", ovs_rundir(), + "ovs-monitor-ipsec.pid"); + pid_t pid = read_pidfile(file_name); + free(file_name); + if (pid < 0) { + VLOG_ERR("%s: IPsec requires the ovs-monitor-ipsec daemon", + name); + return EINVAL; + } + + if (shash_find(args, "peer_cert") && shash_find(args, "psk")) { + VLOG_ERR("%s: cannot define both 'peer_cert' and 'psk'", name); + return EINVAL; + } + + if (!ipsec_mech_set) { + VLOG_ERR("%s: IPsec requires an 'peer_cert' or psk' argument", + name); + return EINVAL; } } - /* IPsec doesn't work when header caching is enabled. Disable it if the - * IPsec local IP address and authentication mechanism have been defined. */ - if (ipsec_ip_set && ipsec_mech_set) { - VLOG_INFO("%s: header caching disabled due to use of IPsec", name); - config.flags &= ~TNL_F_HDR_CACHE; + set_key(args, "in_key", OVS_TUNNEL_ATTR_IN_KEY, options); + set_key(args, "out_key", OVS_TUNNEL_ATTR_OUT_KEY, options); + + if (!daddr) { + VLOG_ERR("%s: %s type requires valid 'remote_ip' argument", + name, type); + return EINVAL; } + nl_msg_put_be32(options, OVS_TUNNEL_ATTR_DST_IPV4, daddr); + + nl_msg_put_u32(options, OVS_TUNNEL_ATTR_FLAGS, flags); + + return 0; +} + +static int +tnl_port_config_from_nlattr(const struct nlattr *options, size_t options_len, + struct nlattr *a[OVS_TUNNEL_ATTR_MAX + 1]) +{ + static const struct nl_policy ovs_tunnel_policy[] = { + [OVS_TUNNEL_ATTR_FLAGS] = { .type = NL_A_U32 }, + [OVS_TUNNEL_ATTR_DST_IPV4] = { .type = NL_A_BE32 }, + [OVS_TUNNEL_ATTR_SRC_IPV4] = { .type = NL_A_BE32, .optional = true }, + [OVS_TUNNEL_ATTR_IN_KEY] = { .type = NL_A_BE64, .optional = true }, + [OVS_TUNNEL_ATTR_OUT_KEY] = { .type = NL_A_BE64, .optional = true }, + [OVS_TUNNEL_ATTR_TOS] = { .type = NL_A_U8, .optional = true }, + [OVS_TUNNEL_ATTR_TTL] = { .type = NL_A_U8, .optional = true }, + }; + struct ofpbuf buf; - if (!config.daddr) { - VLOG_WARN("%s: %s type requires valid 'remote_ip' argument", - name, type); + ofpbuf_use_const(&buf, options, options_len); + if (!nl_policy_parse(&buf, 0, ovs_tunnel_policy, + a, ARRAY_SIZE(ovs_tunnel_policy))) { return EINVAL; } + return 0; +} + +static uint64_t +get_be64_or_zero(const struct nlattr *a) +{ + return a ? ntohll(nl_attr_get_be64(a)) : 0; +} + +static int +unparse_tunnel_config(const char *name OVS_UNUSED, const char *type OVS_UNUSED, + const struct nlattr *options, size_t options_len, + struct shash *args) +{ + struct nlattr *a[OVS_TUNNEL_ATTR_MAX + 1]; + ovs_be32 daddr; + uint32_t flags; + int error; + + error = tnl_port_config_from_nlattr(options, options_len, a); + if (error) { + return error; + } + + flags = nl_attr_get_u32(a[OVS_TUNNEL_ATTR_FLAGS]); + if (!(flags & TNL_F_HDR_CACHE) == !(flags & TNL_F_IPSEC)) { + smap_add(args, "header_cache", + flags & TNL_F_HDR_CACHE ? "true" : "false"); + } + + daddr = nl_attr_get_be32(a[OVS_TUNNEL_ATTR_DST_IPV4]); + shash_add(args, "remote_ip", xasprintf(IP_FMT, IP_ARGS(&daddr))); + + if (a[OVS_TUNNEL_ATTR_SRC_IPV4]) { + ovs_be32 saddr = nl_attr_get_be32(a[OVS_TUNNEL_ATTR_SRC_IPV4]); + shash_add(args, "local_ip", xasprintf(IP_FMT, IP_ARGS(&saddr))); + } + + if (!a[OVS_TUNNEL_ATTR_IN_KEY] && !a[OVS_TUNNEL_ATTR_OUT_KEY]) { + smap_add(args, "key", "flow"); + } else { + uint64_t in_key = get_be64_or_zero(a[OVS_TUNNEL_ATTR_IN_KEY]); + uint64_t out_key = get_be64_or_zero(a[OVS_TUNNEL_ATTR_OUT_KEY]); + + if (in_key && in_key == out_key) { + shash_add(args, "key", xasprintf("%"PRIu64, in_key)); + } else { + if (!a[OVS_TUNNEL_ATTR_IN_KEY]) { + smap_add(args, "in_key", "flow"); + } else if (in_key) { + shash_add(args, "in_key", xasprintf("%"PRIu64, in_key)); + } + + if (!a[OVS_TUNNEL_ATTR_OUT_KEY]) { + smap_add(args, "out_key", "flow"); + } else if (out_key) { + shash_add(args, "out_key", xasprintf("%"PRIu64, out_key)); + } + } + } + + if (flags & TNL_F_TTL_INHERIT) { + smap_add(args, "tos", "inherit"); + } else if (a[OVS_TUNNEL_ATTR_TTL]) { + int ttl = nl_attr_get_u8(a[OVS_TUNNEL_ATTR_TTL]); + shash_add(args, "tos", xasprintf("%d", ttl)); + } + + if (flags & TNL_F_TOS_INHERIT) { + smap_add(args, "tos", "inherit"); + } else if (a[OVS_TUNNEL_ATTR_TOS]) { + int tos = nl_attr_get_u8(a[OVS_TUNNEL_ATTR_TOS]); + shash_add(args, "tos", xasprintf("%d", tos)); + } + + if (flags & TNL_F_CSUM) { + smap_add(args, "csum", "true"); + } + if (flags & TNL_F_DF_INHERIT) { + smap_add(args, "df_inherit", "true"); + } + if (!(flags & TNL_F_DF_DEFAULT)) { + smap_add(args, "df_default", "false"); + } + if (!(flags & TNL_F_PMTUD)) { + smap_add(args, "pmtud", "false"); + } - BUILD_ASSERT(sizeof config <= VPORT_CONFIG_SIZE); - memcpy(configp, &config, sizeof config); return 0; } static int -parse_patch_config(const struct netdev_dev *dev, const struct shash *args, - void *configp) +parse_patch_config(const char *name, const char *type OVS_UNUSED, + const struct shash *args, struct ofpbuf *options) { - const char *name = netdev_dev_get_name(dev); const char *peer; peer = shash_find_data(args, "peer"); if (!peer) { - VLOG_WARN("%s: patch type requires valid 'peer' argument", name); + VLOG_ERR("%s: patch type requires valid 'peer' argument", name); return EINVAL; } if (shash_count(args) > 1) { - VLOG_WARN("%s: patch type takes only a 'peer' argument", name); + VLOG_ERR("%s: patch type takes only a 'peer' argument", name); return EINVAL; } - if (strlen(peer) >= MIN(IFNAMSIZ, VPORT_CONFIG_SIZE)) { - VLOG_WARN("%s: patch 'peer' arg too long", name); + if (strlen(peer) >= IFNAMSIZ) { + VLOG_ERR("%s: patch 'peer' arg too long", name); return EINVAL; } if (!strcmp(name, peer)) { - VLOG_WARN("%s: patch peer must not be self", name); + VLOG_ERR("%s: patch peer must not be self", name); return EINVAL; } - strncpy(configp, peer, VPORT_CONFIG_SIZE); + nl_msg_put_string(options, OVS_PATCH_ATTR_PEER, peer); + + return 0; +} + +static int +unparse_patch_config(const char *name OVS_UNUSED, const char *type OVS_UNUSED, + const struct nlattr *options, size_t options_len, + struct shash *args) +{ + static const struct nl_policy ovs_patch_policy[] = { + [OVS_PATCH_ATTR_PEER] = { .type = NL_A_STRING, + .max_len = IFNAMSIZ, + .optional = false } + }; + + struct nlattr *a[ARRAY_SIZE(ovs_patch_policy)]; + struct ofpbuf buf; + ofpbuf_use_const(&buf, options, options_len); + if (!nl_policy_parse(&buf, 0, ovs_patch_policy, + a, ARRAY_SIZE(ovs_patch_policy))) { + return EINVAL; + } + + smap_add(args, "peer", nl_attr_get_string(a[OVS_PATCH_ATTR_PEER])); return 0; } -#define VPORT_FUNCTIONS \ - NULL, /* init */ \ - NULL, /* run */ \ - NULL, /* wait */ \ +#define VPORT_FUNCTIONS(GET_STATUS) \ + NULL, \ + netdev_vport_run, \ + netdev_vport_wait, \ \ netdev_vport_create, \ netdev_vport_destroy, \ - netdev_vport_reconfigure, \ + netdev_vport_get_config, \ + netdev_vport_set_config, \ \ netdev_vport_open, \ netdev_vport_close, \ \ NULL, /* enumerate */ \ \ + NULL, /* listen */ \ NULL, /* recv */ \ NULL, /* recv_wait */ \ NULL, /* drain */ \ \ - NULL, /* send */ \ + netdev_vport_send, /* send */ \ NULL, /* send_wait */ \ \ netdev_vport_set_etheraddr, \ netdev_vport_get_etheraddr, \ - netdev_vport_get_mtu, \ + NULL, /* get_mtu */ \ + NULL, /* set_mtu */ \ NULL, /* get_ifindex */ \ NULL, /* get_carrier */ \ + NULL, /* get_miimon */ \ netdev_vport_get_stats, \ netdev_vport_set_stats, \ \ @@ -614,20 +926,32 @@ parse_patch_config(const struct netdev_dev *dev, const struct shash *args, NULL, /* get_in6 */ \ NULL, /* add_router */ \ NULL, /* get_next_hop */ \ + GET_STATUS, \ NULL, /* arp_lookup */ \ \ netdev_vport_update_flags, \ \ - netdev_vport_poll_add, \ - netdev_vport_poll_remove, + netdev_vport_change_seq void netdev_vport_register(void) { static const struct vport_class vport_classes[] = { - { { "gre", VPORT_FUNCTIONS }, parse_tunnel_config }, - { { "capwap", VPORT_FUNCTIONS }, parse_tunnel_config }, - { { "patch", VPORT_FUNCTIONS }, parse_patch_config } + { OVS_VPORT_TYPE_GRE, + { "gre", VPORT_FUNCTIONS(netdev_vport_get_status) }, + parse_tunnel_config, unparse_tunnel_config }, + + { OVS_VPORT_TYPE_GRE, + { "ipsec_gre", VPORT_FUNCTIONS(netdev_vport_get_status) }, + parse_tunnel_config, unparse_tunnel_config }, + + { OVS_VPORT_TYPE_CAPWAP, + { "capwap", VPORT_FUNCTIONS(netdev_vport_get_status) }, + parse_tunnel_config, unparse_tunnel_config }, + + { OVS_VPORT_TYPE_PATCH, + { "patch", VPORT_FUNCTIONS(NULL) }, + parse_patch_config, unparse_patch_config } }; int i;