1 package PVE
::Network
::SDN
::Zones
::Plugin
;
6 use PVE
::Tools
qw(run_command);
11 use PVE
::JSONSchema
qw(get_standard_option);
12 use base
qw(PVE::SectionConfig);
14 PVE
::Cluster
::cfs_register_file
(
16 sub { __PACKAGE__-
>parse_config(@_); },
17 sub { __PACKAGE__-
>write_config(@_); },
20 PVE
::JSONSchema
::register_standard_option
('pve-sdn-zone-id', {
21 description
=> "The SDN zone object identifier.",
22 type
=> 'string', format
=> 'pve-sdn-zone-id',
25 PVE
::JSONSchema
::register_format
('pve-sdn-zone-id', \
&parse_sdn_zone_id
);
26 sub parse_sdn_zone_id
{
27 my ($id, $noerr) = @_;
29 if ($id !~ m/^[a-z][a-z0-9]*[a-z0-9]$/i) {
30 return undef if $noerr;
31 die "zone ID '$id' contains illegal characters\n";
33 die "zone ID '$id' can't be more length than 8 characters\n" if length($id) > 8;
41 description
=> "Plugin type.",
42 type
=> 'string', format
=> 'pve-configid',
45 nodes
=> get_standard_option
('pve-node-list', { optional
=> 1 }),
46 zone
=> get_standard_option
('pve-sdn-zone-id', {
47 completion
=> \
&PVE
::Network
::SDN
::Zones
::complete_sdn_zone
,
51 description
=> "use a specific ipam",
61 sub parse_section_header
{
62 my ($class, $line) = @_;
64 if ($line =~ m/^(\S+):\s*(\S+)\s*$/) {
65 my ($type, $id) = (lc($1), $2);
66 my $errmsg = undef; # set if you want to skip whole section
67 eval { PVE
::JSONSchema
::pve_verify_configid
($type); };
69 my $config = {}; # to return additional attributes
70 return ($type, $id, $errmsg, $config);
76 my ($class, $type, $key, $value) = @_;
78 if ($key eq 'nodes' || $key eq 'exitnodes') {
81 foreach my $node (PVE
::Tools
::split_list
($value)) {
82 if (PVE
::JSONSchema
::pve_verify_node_name
($node)) {
94 my ($class, $type, $key, $value) = @_;
96 if ($key eq 'nodes' || $key eq 'exitnodes') {
97 return join(',', keys(%$value));
103 sub generate_sdn_config
{
104 my ($class, $plugin_config, $zoneid, $vnetid, $vnet, $controller, $controller_cfg, $subnet_cfg, $interfaces_config, $config) = @_;
106 die "please implement inside plugin";
109 sub generate_controller_config
{
110 my ($class, $plugin_config, $controller, $id, $uplinks, $config) = @_;
112 die "please implement inside plugin";
115 sub generate_controller_vnet_config
{
116 my ($class, $plugin_config, $controller, $zoneid, $vnetid, $config) = @_;
120 sub write_controller_config
{
121 my ($class, $plugin_config, $config) = @_;
123 die "please implement inside plugin";
126 sub controller_reload
{
129 die "please implement inside plugin";
133 my ($class, $zoneid, $vnet_cfg) = @_;
135 # verify that no vnet are associated to this zone
136 foreach my $id (keys %{$vnet_cfg->{ids
}}) {
137 my $vnet = $vnet_cfg->{ids
}->{$id};
138 die "zone $zoneid is used by vnet $id"
139 if ($vnet->{type
} eq 'vnet' && defined($vnet->{zone
}) && $vnet->{zone
} eq $zoneid);
144 my ($class, $zoneid, $zone_cfg, $controller_cfg) = @_;
146 # do nothing by default
149 sub vnet_update_hook
{
150 my ($class, $vnet_cfg, $vnetid, $zone_cfg) = @_;
152 # do nothing by default
156 sub parse_tag_number_or_range
{
157 my ($str, $max, $tag) = @_;
159 my @elements = split(/,/, $str);
163 die "extraneous commas in list\n" if $str ne join(',', @elements);
164 foreach my $item (@elements) {
165 if ($item =~ m/^([0-9]+)-([0-9]+)$/) {
167 my ($port1, $port2) = ($1, $2);
168 die "invalid port '$port1'\n" if $port1 > $max;
169 die "invalid port '$port2'\n" if $port2 > $max;
170 die "backwards range '$port1:$port2' not allowed, did you mean '$port2:$port1'?\n" if $port1 > $port2;
172 if ($tag && $tag >= $port1 && $tag <= $port2){
177 } elsif ($item =~ m/^([0-9]+)$/) {
180 die "invalid port '$port'\n" if $port > $max;
182 if ($tag && $tag == $port){
188 die "tag $tag is not allowed" if $tag && !$allowed;
190 return (scalar(@elements) > 1);
194 my ($class, $plugin_config, $zone, $vnetid, $vnet, $status) = @_;
199 my $ifaces = [ $vnetid ];
201 foreach my $iface (@{$ifaces}) {
202 if (!$status->{$iface}->{status
}) {
203 push @$err_msg, "missing $iface";
204 } elsif ($status->{$iface}->{status
} ne 'pass') {
205 push @$err_msg, "error $iface";
213 my ($class, $plugin_config, $vnet, $iface, $vnetid) = @_;
215 PVE
::Network
::tap_create
($iface, $vnetid);
219 my ($class, $plugin_config, $vnet, $veth, $vethpeer, $vnetid, $hwaddr) = @_;
221 PVE
::Network
::veth_create
($veth, $vethpeer, $vnetid, $hwaddr);
225 my ($class, $plugin_config, $vnet, $tag, $iface, $vnetid, $firewall, $trunks, $rate) = @_;
227 my $vlan_aware = PVE
::Tools
::file_read_firstline
("/sys/class/net/$vnetid/bridge/vlan_filtering");
228 die "vm vlans are not allowed on vnet $vnetid" if !$vlan_aware && ($tag || $trunks);
230 PVE
::Network
::tap_plug
($iface, $vnetid, $tag, $firewall, $trunks, $rate);
235 sub get_uplink_iface
{
236 my ($interfaces_config, $uplink) = @_;
239 foreach my $id (keys %{$interfaces_config->{ifaces
}}) {
240 my $interface = $interfaces_config->{ifaces
}->{$id};
241 if (my $iface_uplink = $interface->{'uplink-id'}) {
242 next if $iface_uplink ne $uplink;
243 if($interface->{type
} ne 'eth' && $interface->{type
} ne 'bond') {
244 warn "uplink $uplink is not a physical or bond interface";
251 #create a dummy uplink interface if no uplink found
253 warn "can't find uplink $uplink in physical interface";
254 $iface = "uplink${uplink}";
260 sub get_local_route_ip
{
264 my $interface = undef;
266 run_command
(['/sbin/ip', 'route', 'get', $targetip], outfunc
=> sub {
267 if ($_[0] =~ m/src ($PVE::Tools::IPRE)/) {
270 if ($_[0] =~ m/dev (\S+)/) {
275 return ($ip, $interface);
279 sub find_local_ip_interface_peers
{
280 my ($peers, $iface) = @_;
282 my $network_config = PVE
::INotify
::read_file
('interfaces');
283 my $ifaces = $network_config->{ifaces
};
285 #if iface is defined, return ip if exist (if not,try to find it on other ifaces)
287 my $ip = $ifaces->{$iface}->{address
};
288 return ($ip,$iface) if $ip;
291 #is a local ip member of peers list ?
292 foreach my $address (@{$peers}) {
293 while (my $interface = each %$ifaces) {
294 my $ip = $ifaces->{$interface}->{address
};
295 if ($ip && $ip eq $address) {
296 return ($ip, $interface);
301 #if peer is remote, find source with ip route
302 foreach my $address (@{$peers}) {
303 my ($ip, $interface) = get_local_route_ip
($address);
304 return ($ip, $interface);
311 die "can't find bridge $bridge" if !-d
"/sys/class/net/$bridge";
317 return PVE
::Tools
::file_read_firstline
("/sys/class/net/$bridge/bridge/vlan_filtering");
323 my $is_ovs = !-d
"/sys/class/net/$bridge/brif";
327 sub get_bridge_ifaces
{
330 my @bridge_ifaces = ();
331 my $dir = "/sys/class/net/$bridge/brif";
332 PVE
::Tools
::dir_glob_foreach
($dir, '(((eth|bond)\d+|en[^.]+)(\.\d+)?)', sub {
333 push @bridge_ifaces, $_[0];
336 return @bridge_ifaces;