2 * Copyright (c) 2010, 2011, 2012, 2013 Nicira, Inc.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at:
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
19 #include "netdev-vport.h"
23 #include <sys/socket.h>
25 #include <sys/ioctl.h>
27 #include "byte-order.h"
34 #include "netdev-provider.h"
37 #include "route-table.h"
39 #include "socket-util.h"
42 VLOG_DEFINE_THIS_MODULE(netdev_vport);
44 #define VXLAN_DST_PORT 4789
45 #define LISP_DST_PORT 4341
47 #define DEFAULT_TTL 64
51 unsigned int change_seq;
52 uint8_t etheraddr[ETH_ADDR_LEN];
53 struct netdev_stats stats;
56 struct netdev_tunnel_config tnl_cfg;
63 const char *dpif_port;
64 struct netdev_class netdev_class;
67 static int netdev_vport_construct(struct netdev *);
68 static int get_patch_config(const struct netdev *, struct smap *args);
69 static int get_tunnel_config(const struct netdev *, struct smap *args);
70 static void netdev_vport_poll_notify(struct netdev_vport *);
73 is_vport_class(const struct netdev_class *class)
75 return class->construct == netdev_vport_construct;
78 static const struct vport_class *
79 vport_class_cast(const struct netdev_class *class)
81 ovs_assert(is_vport_class(class));
82 return CONTAINER_OF(class, struct vport_class, netdev_class);
85 static struct netdev_vport *
86 netdev_vport_cast(const struct netdev *netdev)
88 ovs_assert(is_vport_class(netdev_get_class(netdev)));
89 return CONTAINER_OF(netdev, struct netdev_vport, up);
92 static const struct netdev_tunnel_config *
93 get_netdev_tunnel_config(const struct netdev *netdev)
95 return &netdev_vport_cast(netdev)->tnl_cfg;
99 netdev_vport_is_patch(const struct netdev *netdev)
101 const struct netdev_class *class = netdev_get_class(netdev);
103 return class->get_config == get_patch_config;
107 netdev_vport_needs_dst_port(const struct netdev *dev)
109 const struct netdev_class *class = netdev_get_class(dev);
110 const char *type = netdev_get_type(dev);
112 return (class->get_config == get_tunnel_config &&
113 (!strcmp("vxlan", type) || !strcmp("lisp", type)));
117 netdev_vport_class_get_dpif_port(const struct netdev_class *class)
119 return is_vport_class(class) ? vport_class_cast(class)->dpif_port : NULL;
123 netdev_vport_get_dpif_port(const struct netdev *netdev,
124 char namebuf[], size_t bufsize)
126 if (netdev_vport_needs_dst_port(netdev)) {
127 const struct netdev_vport *vport = netdev_vport_cast(netdev);
128 const char *type = netdev_get_type(netdev);
131 * Note: IFNAMSIZ is 16 bytes long. The maximum length of a VXLAN
132 * or LISP port name below is 15 or 14 bytes respectively. Still,
133 * assert here on the size of strlen(type) in case that changes
136 BUILD_ASSERT(NETDEV_VPORT_NAME_BUFSIZE >= IFNAMSIZ);
137 ovs_assert(strlen(type) + 10 < IFNAMSIZ);
138 snprintf(namebuf, bufsize, "%s_sys_%d", type,
139 ntohs(vport->tnl_cfg.dst_port));
142 const struct netdev_class *class = netdev_get_class(netdev);
143 const char *dpif_port = netdev_vport_class_get_dpif_port(class);
144 return dpif_port ? dpif_port : netdev_get_name(netdev);
149 netdev_vport_get_dpif_port_strdup(const struct netdev *netdev)
151 char namebuf[NETDEV_VPORT_NAME_BUFSIZE];
153 return xstrdup(netdev_vport_get_dpif_port(netdev, namebuf,
157 static struct netdev *
158 netdev_vport_alloc(void)
160 struct netdev_vport *netdev = xzalloc(sizeof *netdev);
165 netdev_vport_construct(struct netdev *netdev_)
167 struct netdev_vport *netdev = netdev_vport_cast(netdev_);
169 netdev->change_seq = 1;
170 eth_addr_random(netdev->etheraddr);
172 route_table_register();
178 netdev_vport_destruct(struct netdev *netdev_)
180 struct netdev_vport *netdev = netdev_vport_cast(netdev_);
182 route_table_unregister();
187 netdev_vport_dealloc(struct netdev *netdev_)
189 struct netdev_vport *netdev = netdev_vport_cast(netdev_);
194 netdev_vport_set_etheraddr(struct netdev *netdev_,
195 const uint8_t mac[ETH_ADDR_LEN])
197 struct netdev_vport *netdev = netdev_vport_cast(netdev_);
198 memcpy(netdev->etheraddr, mac, ETH_ADDR_LEN);
199 netdev_vport_poll_notify(netdev);
204 netdev_vport_get_etheraddr(const struct netdev *netdev,
205 uint8_t mac[ETH_ADDR_LEN])
207 memcpy(mac, netdev_vport_cast(netdev)->etheraddr, ETH_ADDR_LEN);
212 tunnel_get_status(const struct netdev *netdev, struct smap *smap)
214 char iface[IFNAMSIZ];
217 route = netdev_vport_cast(netdev)->tnl_cfg.ip_dst;
218 if (route_table_get_name(route, iface)) {
219 struct netdev *egress_netdev;
221 smap_add(smap, "tunnel_egress_iface", iface);
223 if (!netdev_open(iface, "system", &egress_netdev)) {
224 smap_add(smap, "tunnel_egress_iface_carrier",
225 netdev_get_carrier(egress_netdev) ? "up" : "down");
226 netdev_close(egress_netdev);
234 netdev_vport_update_flags(struct netdev *netdev OVS_UNUSED,
235 enum netdev_flags off,
236 enum netdev_flags on OVS_UNUSED,
237 enum netdev_flags *old_flagsp)
239 if (off & (NETDEV_UP | NETDEV_PROMISC)) {
243 *old_flagsp = NETDEV_UP | NETDEV_PROMISC;
248 netdev_vport_change_seq(const struct netdev *netdev)
250 return netdev_vport_cast(netdev)->change_seq;
254 netdev_vport_run(void)
260 netdev_vport_wait(void)
265 /* Helper functions. */
268 netdev_vport_poll_notify(struct netdev_vport *ndv)
271 if (!ndv->change_seq) {
276 /* Code specific to tunnel types. */
279 parse_key(const struct smap *args, const char *name,
280 bool *present, bool *flow)
287 s = smap_get(args, name);
289 s = smap_get(args, "key");
297 if (!strcmp(s, "flow")) {
301 return htonll(strtoull(s, NULL, 0));
306 set_tunnel_config(struct netdev *dev_, const struct smap *args)
308 struct netdev_vport *dev = netdev_vport_cast(dev_);
309 const char *name = netdev_get_name(dev_);
310 const char *type = netdev_get_type(dev_);
311 bool ipsec_mech_set, needs_dst_port, has_csum;
312 struct netdev_tunnel_config tnl_cfg;
313 struct smap_node *node;
315 has_csum = strstr(type, "gre");
316 ipsec_mech_set = false;
317 memset(&tnl_cfg, 0, sizeof tnl_cfg);
319 needs_dst_port = netdev_vport_needs_dst_port(dev_);
320 tnl_cfg.ipsec = strstr(type, "ipsec");
321 tnl_cfg.dont_fragment = true;
323 SMAP_FOR_EACH (node, args) {
324 if (!strcmp(node->key, "remote_ip")) {
325 struct in_addr in_addr;
326 if (!strcmp(node->value, "flow")) {
327 tnl_cfg.ip_dst_flow = true;
328 tnl_cfg.ip_dst = htonl(0);
329 } else if (lookup_ip(node->value, &in_addr)) {
330 VLOG_WARN("%s: bad %s 'remote_ip'", name, type);
331 } else if (ip_is_multicast(in_addr.s_addr)) {
332 VLOG_WARN("%s: multicast remote_ip="IP_FMT" not allowed",
333 name, IP_ARGS(in_addr.s_addr));
336 tnl_cfg.ip_dst = in_addr.s_addr;
338 } else if (!strcmp(node->key, "local_ip")) {
339 struct in_addr in_addr;
340 if (!strcmp(node->value, "flow")) {
341 tnl_cfg.ip_src_flow = true;
342 tnl_cfg.ip_src = htonl(0);
343 } else if (lookup_ip(node->value, &in_addr)) {
344 VLOG_WARN("%s: bad %s 'local_ip'", name, type);
346 tnl_cfg.ip_src = in_addr.s_addr;
348 } else if (!strcmp(node->key, "tos")) {
349 if (!strcmp(node->value, "inherit")) {
350 tnl_cfg.tos_inherit = true;
354 tos = strtol(node->value, &endptr, 0);
355 if (*endptr == '\0' && tos == (tos & IP_DSCP_MASK)) {
358 VLOG_WARN("%s: invalid TOS %s", name, node->value);
361 } else if (!strcmp(node->key, "ttl")) {
362 if (!strcmp(node->value, "inherit")) {
363 tnl_cfg.ttl_inherit = true;
365 tnl_cfg.ttl = atoi(node->value);
367 } else if (!strcmp(node->key, "dst_port") && needs_dst_port) {
368 tnl_cfg.dst_port = htons(atoi(node->value));
369 } else if (!strcmp(node->key, "csum") && has_csum) {
370 if (!strcmp(node->value, "true")) {
373 } else if (!strcmp(node->key, "df_default")) {
374 if (!strcmp(node->value, "false")) {
375 tnl_cfg.dont_fragment = false;
377 } else if (!strcmp(node->key, "peer_cert") && tnl_cfg.ipsec) {
378 if (smap_get(args, "certificate")) {
379 ipsec_mech_set = true;
381 const char *use_ssl_cert;
383 /* If the "use_ssl_cert" is true, then "certificate" and
384 * "private_key" will be pulled from the SSL table. The
385 * use of this option is strongly discouraged, since it
386 * will like be removed when multiple SSL configurations
387 * are supported by OVS.
389 use_ssl_cert = smap_get(args, "use_ssl_cert");
390 if (!use_ssl_cert || strcmp(use_ssl_cert, "true")) {
391 VLOG_ERR("%s: 'peer_cert' requires 'certificate' argument",
395 ipsec_mech_set = true;
397 } else if (!strcmp(node->key, "psk") && tnl_cfg.ipsec) {
398 ipsec_mech_set = true;
399 } else if (tnl_cfg.ipsec
400 && (!strcmp(node->key, "certificate")
401 || !strcmp(node->key, "private_key")
402 || !strcmp(node->key, "use_ssl_cert"))) {
403 /* Ignore options not used by the netdev. */
404 } else if (!strcmp(node->key, "key") ||
405 !strcmp(node->key, "in_key") ||
406 !strcmp(node->key, "out_key")) {
407 /* Handled separately below. */
409 VLOG_WARN("%s: unknown %s argument '%s'", name, type, node->key);
413 /* Add a default destination port for VXLAN if none specified. */
414 if (!strcmp(type, "vxlan") && !tnl_cfg.dst_port) {
415 tnl_cfg.dst_port = htons(VXLAN_DST_PORT);
418 /* Add a default destination port for LISP if none specified. */
419 if (!strcmp(type, "lisp") && !tnl_cfg.dst_port) {
420 tnl_cfg.dst_port = htons(LISP_DST_PORT);
424 static struct ovs_mutex mutex = OVS_MUTEX_INITIALIZER;
425 static pid_t pid = 0;
427 ovs_mutex_lock(&mutex);
429 char *file_name = xasprintf("%s/%s", ovs_rundir(),
430 "ovs-monitor-ipsec.pid");
431 pid = read_pidfile(file_name);
434 ovs_mutex_unlock(&mutex);
437 VLOG_ERR("%s: IPsec requires the ovs-monitor-ipsec daemon",
442 if (smap_get(args, "peer_cert") && smap_get(args, "psk")) {
443 VLOG_ERR("%s: cannot define both 'peer_cert' and 'psk'", name);
447 if (!ipsec_mech_set) {
448 VLOG_ERR("%s: IPsec requires an 'peer_cert' or psk' argument",
454 if (!tnl_cfg.ip_dst && !tnl_cfg.ip_dst_flow) {
455 VLOG_ERR("%s: %s type requires valid 'remote_ip' argument",
459 if (tnl_cfg.ip_src_flow && !tnl_cfg.ip_dst_flow) {
460 VLOG_ERR("%s: %s type requires 'remote_ip=flow' with 'local_ip=flow'",
465 tnl_cfg.ttl = DEFAULT_TTL;
468 tnl_cfg.in_key = parse_key(args, "in_key",
469 &tnl_cfg.in_key_present,
470 &tnl_cfg.in_key_flow);
472 tnl_cfg.out_key = parse_key(args, "out_key",
473 &tnl_cfg.out_key_present,
474 &tnl_cfg.out_key_flow);
476 dev->tnl_cfg = tnl_cfg;
477 netdev_vport_poll_notify(dev);
483 get_tunnel_config(const struct netdev *dev, struct smap *args)
485 const struct netdev_tunnel_config *tnl_cfg =
486 &netdev_vport_cast(dev)->tnl_cfg;
488 if (tnl_cfg->ip_dst) {
489 smap_add_format(args, "remote_ip", IP_FMT, IP_ARGS(tnl_cfg->ip_dst));
490 } else if (tnl_cfg->ip_dst_flow) {
491 smap_add(args, "remote_ip", "flow");
494 if (tnl_cfg->ip_src) {
495 smap_add_format(args, "local_ip", IP_FMT, IP_ARGS(tnl_cfg->ip_src));
496 } else if (tnl_cfg->ip_src_flow) {
497 smap_add(args, "local_ip", "flow");
500 if (tnl_cfg->in_key_flow && tnl_cfg->out_key_flow) {
501 smap_add(args, "key", "flow");
502 } else if (tnl_cfg->in_key_present && tnl_cfg->out_key_present
503 && tnl_cfg->in_key == tnl_cfg->out_key) {
504 smap_add_format(args, "key", "%"PRIu64, ntohll(tnl_cfg->in_key));
506 if (tnl_cfg->in_key_flow) {
507 smap_add(args, "in_key", "flow");
508 } else if (tnl_cfg->in_key_present) {
509 smap_add_format(args, "in_key", "%"PRIu64,
510 ntohll(tnl_cfg->in_key));
513 if (tnl_cfg->out_key_flow) {
514 smap_add(args, "out_key", "flow");
515 } else if (tnl_cfg->out_key_present) {
516 smap_add_format(args, "out_key", "%"PRIu64,
517 ntohll(tnl_cfg->out_key));
521 if (tnl_cfg->ttl_inherit) {
522 smap_add(args, "ttl", "inherit");
523 } else if (tnl_cfg->ttl != DEFAULT_TTL) {
524 smap_add_format(args, "ttl", "%"PRIu8, tnl_cfg->ttl);
527 if (tnl_cfg->tos_inherit) {
528 smap_add(args, "tos", "inherit");
529 } else if (tnl_cfg->tos) {
530 smap_add_format(args, "tos", "0x%x", tnl_cfg->tos);
533 if (tnl_cfg->dst_port) {
534 uint16_t dst_port = ntohs(tnl_cfg->dst_port);
535 const char *type = netdev_get_type(dev);
537 if ((!strcmp("vxlan", type) && dst_port != VXLAN_DST_PORT) ||
538 (!strcmp("lisp", type) && dst_port != LISP_DST_PORT)) {
539 smap_add_format(args, "dst_port", "%d", dst_port);
544 smap_add(args, "csum", "true");
547 if (!tnl_cfg->dont_fragment) {
548 smap_add(args, "df_default", "false");
554 /* Code specific to patch ports. */
557 netdev_vport_patch_peer(const struct netdev *netdev)
559 return (netdev_vport_is_patch(netdev)
560 ? netdev_vport_cast(netdev)->peer
565 netdev_vport_inc_rx(const struct netdev *netdev,
566 const struct dpif_flow_stats *stats)
568 if (is_vport_class(netdev_get_class(netdev))) {
569 struct netdev_vport *dev = netdev_vport_cast(netdev);
570 dev->stats.rx_packets += stats->n_packets;
571 dev->stats.rx_bytes += stats->n_bytes;
576 netdev_vport_inc_tx(const struct netdev *netdev,
577 const struct dpif_flow_stats *stats)
579 if (is_vport_class(netdev_get_class(netdev))) {
580 struct netdev_vport *dev = netdev_vport_cast(netdev);
581 dev->stats.tx_packets += stats->n_packets;
582 dev->stats.tx_bytes += stats->n_bytes;
587 get_patch_config(const struct netdev *dev_, struct smap *args)
589 struct netdev_vport *dev = netdev_vport_cast(dev_);
592 smap_add(args, "peer", dev->peer);
598 set_patch_config(struct netdev *dev_, const struct smap *args)
600 struct netdev_vport *dev = netdev_vport_cast(dev_);
601 const char *name = netdev_get_name(dev_);
604 peer = smap_get(args, "peer");
606 VLOG_ERR("%s: patch type requires valid 'peer' argument", name);
610 if (smap_count(args) > 1) {
611 VLOG_ERR("%s: patch type takes only a 'peer' argument", name);
615 if (!strcmp(name, peer)) {
616 VLOG_ERR("%s: patch peer must not be self", name);
621 dev->peer = xstrdup(peer);
622 netdev_vport_poll_notify(dev);
627 get_stats(const struct netdev *netdev, struct netdev_stats *stats)
629 struct netdev_vport *dev = netdev_vport_cast(netdev);
630 memcpy(stats, &dev->stats, sizeof *stats);
634 #define VPORT_FUNCTIONS(GET_CONFIG, SET_CONFIG, \
635 GET_TUNNEL_CONFIG, GET_STATUS) \
640 netdev_vport_alloc, \
641 netdev_vport_construct, \
642 netdev_vport_destruct, \
643 netdev_vport_dealloc, \
649 NULL, /* send_wait */ \
651 netdev_vport_set_etheraddr, \
652 netdev_vport_get_etheraddr, \
653 NULL, /* get_mtu */ \
654 NULL, /* set_mtu */ \
655 NULL, /* get_ifindex */ \
656 NULL, /* get_carrier */ \
657 NULL, /* get_carrier_resets */ \
658 NULL, /* get_miimon */ \
660 NULL, /* set_stats */ \
662 NULL, /* get_features */ \
663 NULL, /* set_advertisements */ \
665 NULL, /* set_policing */ \
666 NULL, /* get_qos_types */ \
667 NULL, /* get_qos_capabilities */ \
668 NULL, /* get_qos */ \
669 NULL, /* set_qos */ \
670 NULL, /* get_queue */ \
671 NULL, /* set_queue */ \
672 NULL, /* delete_queue */ \
673 NULL, /* get_queue_stats */ \
674 NULL, /* dump_queues */ \
675 NULL, /* dump_queue_stats */ \
677 NULL, /* get_in4 */ \
678 NULL, /* set_in4 */ \
679 NULL, /* get_in6 */ \
680 NULL, /* add_router */ \
681 NULL, /* get_next_hop */ \
683 NULL, /* arp_lookup */ \
685 netdev_vport_update_flags, \
687 netdev_vport_change_seq, \
689 NULL, /* rx_alloc */ \
690 NULL, /* rx_construct */ \
691 NULL, /* rx_destruct */ \
692 NULL, /* rx_dealloc */ \
693 NULL, /* rx_recv */ \
694 NULL, /* rx_wait */ \
697 #define TUNNEL_CLASS(NAME, DPIF_PORT) \
699 { NAME, VPORT_FUNCTIONS(get_tunnel_config, \
701 get_netdev_tunnel_config, \
702 tunnel_get_status) }}
705 netdev_vport_tunnel_register(void)
707 static const struct vport_class vport_classes[] = {
708 TUNNEL_CLASS("gre", "gre_system"),
709 TUNNEL_CLASS("ipsec_gre", "gre_system"),
710 TUNNEL_CLASS("gre64", "gre64_system"),
711 TUNNEL_CLASS("ipsec_gre64", "gre64_system"),
712 TUNNEL_CLASS("vxlan", "vxlan_system"),
713 TUNNEL_CLASS("lisp", "lisp_system")
721 for (i = 0; i < ARRAY_SIZE(vport_classes); i++) {
722 netdev_register_provider(&vport_classes[i].netdev_class);
728 netdev_vport_patch_register(void)
730 static const struct vport_class patch_class =
732 { "patch", VPORT_FUNCTIONS(get_patch_config,
736 netdev_register_provider(&patch_class.netdev_class);