2 * Copyright (c) 2010, 2011, 2012, 2013 Nicira, Inc.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at:
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
19 #include "netdev-vport.h"
23 #include <sys/socket.h>
25 #include <sys/ioctl.h>
27 #include "byte-order.h"
34 #include "netdev-provider.h"
37 #include "route-table.h"
39 #include "socket-util.h"
42 VLOG_DEFINE_THIS_MODULE(netdev_vport
);
44 #define VXLAN_DST_PORT 4789
45 #define LISP_DST_PORT 4341
47 #define DEFAULT_TTL 64
49 struct netdev_dev_vport
{
50 struct netdev_dev netdev_dev
;
51 unsigned int change_seq
;
52 uint8_t etheraddr
[ETH_ADDR_LEN
];
53 struct netdev_stats stats
;
56 struct netdev_tunnel_config tnl_cfg
;
63 const char *dpif_port
;
64 struct netdev_class netdev_class
;
67 static int netdev_vport_create(const struct netdev_class
*, const char *,
68 struct netdev_dev
**);
69 static int get_patch_config(struct netdev_dev
*, struct smap
*args
);
70 static int get_tunnel_config(struct netdev_dev
*, struct smap
*args
);
71 static void netdev_vport_poll_notify(struct netdev_dev_vport
*);
74 is_vport_class(const struct netdev_class
*class)
76 return class->create
== netdev_vport_create
;
79 static const struct vport_class
*
80 vport_class_cast(const struct netdev_class
*class)
82 ovs_assert(is_vport_class(class));
83 return CONTAINER_OF(class, struct vport_class
, netdev_class
);
86 static struct netdev_dev_vport
*
87 netdev_dev_vport_cast(const struct netdev_dev
*netdev_dev
)
89 ovs_assert(is_vport_class(netdev_dev_get_class(netdev_dev
)));
90 return CONTAINER_OF(netdev_dev
, struct netdev_dev_vport
, netdev_dev
);
93 static struct netdev_dev_vport
*
94 netdev_vport_get_dev(const struct netdev
*netdev
)
96 return netdev_dev_vport_cast(netdev_get_dev(netdev
));
99 static const struct netdev_tunnel_config
*
100 get_netdev_tunnel_config(const struct netdev_dev
*netdev_dev
)
102 return &netdev_dev_vport_cast(netdev_dev
)->tnl_cfg
;
106 netdev_vport_is_patch(const struct netdev
*netdev
)
108 const struct netdev_dev
*dev
= netdev_get_dev(netdev
);
109 const struct netdev_class
*class = netdev_dev_get_class(dev
);
111 return class->get_config
== get_patch_config
;
115 netdev_vport_needs_dst_port(const struct netdev_dev
*dev
)
117 const struct netdev_class
*class = netdev_dev_get_class(dev
);
118 const char *type
= netdev_dev_get_type(dev
);
120 return (class->get_config
== get_tunnel_config
&&
121 (!strcmp("vxlan", type
) || !strcmp("lisp", type
)));
125 netdev_vport_get_dpif_port(const struct netdev
*netdev
)
127 const struct netdev_dev
*dev
= netdev_get_dev(netdev
);
128 const struct netdev_class
*class = netdev_dev_get_class(dev
);
129 const char *dpif_port
;
131 if (netdev_vport_needs_dst_port(dev
)) {
132 const struct netdev_dev_vport
*vport
= netdev_vport_get_dev(netdev
);
133 const char *type
= netdev_dev_get_type(dev
);
134 static char dpif_port_combined
[IFNAMSIZ
];
137 * Note: IFNAMSIZ is 16 bytes long. The maximum length of a VXLAN
138 * or LISP port name below is 15 or 14 bytes respectively. Still,
139 * assert here on the size of strlen(type) in case that changes
142 ovs_assert(strlen(type
) + 10 < IFNAMSIZ
);
143 snprintf(dpif_port_combined
, IFNAMSIZ
, "%s_sys_%d", type
,
144 ntohs(vport
->tnl_cfg
.dst_port
));
145 return dpif_port_combined
;
147 dpif_port
= (is_vport_class(class)
148 ? vport_class_cast(class)->dpif_port
152 return dpif_port
? dpif_port
: netdev_get_name(netdev
);
156 netdev_vport_create(const struct netdev_class
*netdev_class
, const char *name
,
157 struct netdev_dev
**netdev_devp
)
159 struct netdev_dev_vport
*dev
;
161 dev
= xzalloc(sizeof *dev
);
162 netdev_dev_init(&dev
->netdev_dev
, name
, netdev_class
);
164 eth_addr_random(dev
->etheraddr
);
166 *netdev_devp
= &dev
->netdev_dev
;
167 route_table_register();
173 netdev_vport_destroy(struct netdev_dev
*netdev_dev_
)
175 struct netdev_dev_vport
*netdev_dev
= netdev_dev_vport_cast(netdev_dev_
);
177 route_table_unregister();
178 free(netdev_dev
->peer
);
183 netdev_vport_open(struct netdev_dev
*netdev_dev
, struct netdev
**netdevp
)
185 *netdevp
= xmalloc(sizeof **netdevp
);
186 netdev_init(*netdevp
, netdev_dev
);
191 netdev_vport_close(struct netdev
*netdev
)
197 netdev_vport_set_etheraddr(struct netdev
*netdev
,
198 const uint8_t mac
[ETH_ADDR_LEN
])
200 struct netdev_dev_vport
*dev
= netdev_vport_get_dev(netdev
);
201 memcpy(dev
->etheraddr
, mac
, ETH_ADDR_LEN
);
202 netdev_vport_poll_notify(dev
);
207 netdev_vport_get_etheraddr(const struct netdev
*netdev
,
208 uint8_t mac
[ETH_ADDR_LEN
])
210 memcpy(mac
, netdev_vport_get_dev(netdev
)->etheraddr
, ETH_ADDR_LEN
);
215 tunnel_get_status(const struct netdev
*netdev
, struct smap
*smap
)
217 static char iface
[IFNAMSIZ
];
220 route
= netdev_vport_get_dev(netdev
)->tnl_cfg
.ip_dst
;
221 if (route_table_get_name(route
, iface
)) {
222 struct netdev
*egress_netdev
;
224 smap_add(smap
, "tunnel_egress_iface", iface
);
226 if (!netdev_open(iface
, "system", &egress_netdev
)) {
227 smap_add(smap
, "tunnel_egress_iface_carrier",
228 netdev_get_carrier(egress_netdev
) ? "up" : "down");
229 netdev_close(egress_netdev
);
237 netdev_vport_update_flags(struct netdev_dev
*netdev_dev OVS_UNUSED
,
238 enum netdev_flags off
, enum netdev_flags on OVS_UNUSED
,
239 enum netdev_flags
*old_flagsp
)
241 if (off
& (NETDEV_UP
| NETDEV_PROMISC
)) {
245 *old_flagsp
= NETDEV_UP
| NETDEV_PROMISC
;
250 netdev_vport_change_seq(const struct netdev
*netdev
)
252 return netdev_vport_get_dev(netdev
)->change_seq
;
256 netdev_vport_run(void)
262 netdev_vport_wait(void)
267 /* Helper functions. */
270 netdev_vport_poll_notify(struct netdev_dev_vport
*ndv
)
273 if (!ndv
->change_seq
) {
278 /* Code specific to tunnel types. */
281 parse_key(const struct smap
*args
, const char *name
,
282 bool *present
, bool *flow
)
289 s
= smap_get(args
, name
);
291 s
= smap_get(args
, "key");
299 if (!strcmp(s
, "flow")) {
303 return htonll(strtoull(s
, NULL
, 0));
308 set_tunnel_config(struct netdev_dev
*dev_
, const struct smap
*args
)
310 struct netdev_dev_vport
*dev
= netdev_dev_vport_cast(dev_
);
311 const char *name
= netdev_dev_get_name(dev_
);
312 const char *type
= netdev_dev_get_type(dev_
);
313 bool ipsec_mech_set
, needs_dst_port
, has_csum
;
314 struct netdev_tunnel_config tnl_cfg
;
315 struct smap_node
*node
;
317 has_csum
= strstr(type
, "gre");
318 ipsec_mech_set
= false;
319 memset(&tnl_cfg
, 0, sizeof tnl_cfg
);
321 needs_dst_port
= netdev_vport_needs_dst_port(dev_
);
322 tnl_cfg
.ipsec
= strstr(type
, "ipsec");
323 tnl_cfg
.dont_fragment
= true;
325 SMAP_FOR_EACH (node
, args
) {
326 if (!strcmp(node
->key
, "remote_ip")) {
327 struct in_addr in_addr
;
328 if (!strcmp(node
->value
, "flow")) {
329 tnl_cfg
.ip_dst_flow
= true;
330 tnl_cfg
.ip_dst
= htonl(0);
331 } else if (lookup_ip(node
->value
, &in_addr
)) {
332 VLOG_WARN("%s: bad %s 'remote_ip'", name
, type
);
333 } else if (ip_is_multicast(in_addr
.s_addr
)) {
334 VLOG_WARN("%s: multicast remote_ip="IP_FMT
" not allowed",
335 name
, IP_ARGS(in_addr
.s_addr
));
338 tnl_cfg
.ip_dst
= in_addr
.s_addr
;
340 } else if (!strcmp(node
->key
, "local_ip")) {
341 struct in_addr in_addr
;
342 if (!strcmp(node
->value
, "flow")) {
343 tnl_cfg
.ip_src_flow
= true;
344 tnl_cfg
.ip_src
= htonl(0);
345 } else if (lookup_ip(node
->value
, &in_addr
)) {
346 VLOG_WARN("%s: bad %s 'local_ip'", name
, type
);
348 tnl_cfg
.ip_src
= in_addr
.s_addr
;
350 } else if (!strcmp(node
->key
, "tos")) {
351 if (!strcmp(node
->value
, "inherit")) {
352 tnl_cfg
.tos_inherit
= true;
356 tos
= strtol(node
->value
, &endptr
, 0);
357 if (*endptr
== '\0' && tos
== (tos
& IP_DSCP_MASK
)) {
360 VLOG_WARN("%s: invalid TOS %s", name
, node
->value
);
363 } else if (!strcmp(node
->key
, "ttl")) {
364 if (!strcmp(node
->value
, "inherit")) {
365 tnl_cfg
.ttl_inherit
= true;
367 tnl_cfg
.ttl
= atoi(node
->value
);
369 } else if (!strcmp(node
->key
, "dst_port") && needs_dst_port
) {
370 tnl_cfg
.dst_port
= htons(atoi(node
->value
));
371 } else if (!strcmp(node
->key
, "csum") && has_csum
) {
372 if (!strcmp(node
->value
, "true")) {
375 } else if (!strcmp(node
->key
, "df_default")) {
376 if (!strcmp(node
->value
, "false")) {
377 tnl_cfg
.dont_fragment
= false;
379 } else if (!strcmp(node
->key
, "peer_cert") && tnl_cfg
.ipsec
) {
380 if (smap_get(args
, "certificate")) {
381 ipsec_mech_set
= true;
383 const char *use_ssl_cert
;
385 /* If the "use_ssl_cert" is true, then "certificate" and
386 * "private_key" will be pulled from the SSL table. The
387 * use of this option is strongly discouraged, since it
388 * will like be removed when multiple SSL configurations
389 * are supported by OVS.
391 use_ssl_cert
= smap_get(args
, "use_ssl_cert");
392 if (!use_ssl_cert
|| strcmp(use_ssl_cert
, "true")) {
393 VLOG_ERR("%s: 'peer_cert' requires 'certificate' argument",
397 ipsec_mech_set
= true;
399 } else if (!strcmp(node
->key
, "psk") && tnl_cfg
.ipsec
) {
400 ipsec_mech_set
= true;
401 } else if (tnl_cfg
.ipsec
402 && (!strcmp(node
->key
, "certificate")
403 || !strcmp(node
->key
, "private_key")
404 || !strcmp(node
->key
, "use_ssl_cert"))) {
405 /* Ignore options not used by the netdev. */
406 } else if (!strcmp(node
->key
, "key") ||
407 !strcmp(node
->key
, "in_key") ||
408 !strcmp(node
->key
, "out_key")) {
409 /* Handled separately below. */
411 VLOG_WARN("%s: unknown %s argument '%s'", name
, type
, node
->key
);
415 /* Add a default destination port for VXLAN if none specified. */
416 if (!strcmp(type
, "vxlan") && !tnl_cfg
.dst_port
) {
417 tnl_cfg
.dst_port
= htons(VXLAN_DST_PORT
);
420 /* Add a default destination port for LISP if none specified. */
421 if (!strcmp(type
, "lisp") && !tnl_cfg
.dst_port
) {
422 tnl_cfg
.dst_port
= htons(LISP_DST_PORT
);
426 static pid_t pid
= 0;
428 char *file_name
= xasprintf("%s/%s", ovs_rundir(),
429 "ovs-monitor-ipsec.pid");
430 pid
= read_pidfile(file_name
);
435 VLOG_ERR("%s: IPsec requires the ovs-monitor-ipsec daemon",
440 if (smap_get(args
, "peer_cert") && smap_get(args
, "psk")) {
441 VLOG_ERR("%s: cannot define both 'peer_cert' and 'psk'", name
);
445 if (!ipsec_mech_set
) {
446 VLOG_ERR("%s: IPsec requires an 'peer_cert' or psk' argument",
452 if (!tnl_cfg
.ip_dst
&& !tnl_cfg
.ip_dst_flow
) {
453 VLOG_ERR("%s: %s type requires valid 'remote_ip' argument",
457 if (tnl_cfg
.ip_src_flow
&& !tnl_cfg
.ip_dst_flow
) {
458 VLOG_ERR("%s: %s type requires 'remote_ip=flow' with 'local_ip=flow'",
463 tnl_cfg
.ttl
= DEFAULT_TTL
;
466 tnl_cfg
.in_key
= parse_key(args
, "in_key",
467 &tnl_cfg
.in_key_present
,
468 &tnl_cfg
.in_key_flow
);
470 tnl_cfg
.out_key
= parse_key(args
, "out_key",
471 &tnl_cfg
.out_key_present
,
472 &tnl_cfg
.out_key_flow
);
474 dev
->tnl_cfg
= tnl_cfg
;
475 netdev_vport_poll_notify(dev
);
481 get_tunnel_config(struct netdev_dev
*dev
, struct smap
*args
)
483 const struct netdev_tunnel_config
*tnl_cfg
=
484 &netdev_dev_vport_cast(dev
)->tnl_cfg
;
486 if (tnl_cfg
->ip_dst
) {
487 smap_add_format(args
, "remote_ip", IP_FMT
, IP_ARGS(tnl_cfg
->ip_dst
));
488 } else if (tnl_cfg
->ip_dst_flow
) {
489 smap_add(args
, "remote_ip", "flow");
492 if (tnl_cfg
->ip_src
) {
493 smap_add_format(args
, "local_ip", IP_FMT
, IP_ARGS(tnl_cfg
->ip_src
));
494 } else if (tnl_cfg
->ip_src_flow
) {
495 smap_add(args
, "local_ip", "flow");
498 if (tnl_cfg
->in_key_flow
&& tnl_cfg
->out_key_flow
) {
499 smap_add(args
, "key", "flow");
500 } else if (tnl_cfg
->in_key_present
&& tnl_cfg
->out_key_present
501 && tnl_cfg
->in_key
== tnl_cfg
->out_key
) {
502 smap_add_format(args
, "key", "%"PRIu64
, ntohll(tnl_cfg
->in_key
));
504 if (tnl_cfg
->in_key_flow
) {
505 smap_add(args
, "in_key", "flow");
506 } else if (tnl_cfg
->in_key_present
) {
507 smap_add_format(args
, "in_key", "%"PRIu64
,
508 ntohll(tnl_cfg
->in_key
));
511 if (tnl_cfg
->out_key_flow
) {
512 smap_add(args
, "out_key", "flow");
513 } else if (tnl_cfg
->out_key_present
) {
514 smap_add_format(args
, "out_key", "%"PRIu64
,
515 ntohll(tnl_cfg
->out_key
));
519 if (tnl_cfg
->ttl_inherit
) {
520 smap_add(args
, "ttl", "inherit");
521 } else if (tnl_cfg
->ttl
!= DEFAULT_TTL
) {
522 smap_add_format(args
, "ttl", "%"PRIu8
, tnl_cfg
->ttl
);
525 if (tnl_cfg
->tos_inherit
) {
526 smap_add(args
, "tos", "inherit");
527 } else if (tnl_cfg
->tos
) {
528 smap_add_format(args
, "tos", "0x%x", tnl_cfg
->tos
);
531 if (tnl_cfg
->dst_port
) {
532 uint16_t dst_port
= ntohs(tnl_cfg
->dst_port
);
533 const char *type
= netdev_dev_get_type(dev
);
535 if ((!strcmp("vxlan", type
) && dst_port
!= VXLAN_DST_PORT
) ||
536 (!strcmp("lisp", type
) && dst_port
!= LISP_DST_PORT
)) {
537 smap_add_format(args
, "dst_port", "%d", dst_port
);
542 smap_add(args
, "csum", "true");
545 if (!tnl_cfg
->dont_fragment
) {
546 smap_add(args
, "df_default", "false");
552 /* Code specific to patch ports. */
555 netdev_vport_patch_peer(const struct netdev
*netdev
)
557 return netdev_vport_is_patch(netdev
)
558 ? netdev_vport_get_dev(netdev
)->peer
563 netdev_vport_inc_rx(const struct netdev
*netdev
,
564 const struct dpif_flow_stats
*stats
)
566 if (is_vport_class(netdev_dev_get_class(netdev_get_dev(netdev
)))) {
567 struct netdev_dev_vport
*dev
= netdev_vport_get_dev(netdev
);
568 dev
->stats
.rx_packets
+= stats
->n_packets
;
569 dev
->stats
.rx_bytes
+= stats
->n_bytes
;
574 netdev_vport_inc_tx(const struct netdev
*netdev
,
575 const struct dpif_flow_stats
*stats
)
577 if (is_vport_class(netdev_dev_get_class(netdev_get_dev(netdev
)))) {
578 struct netdev_dev_vport
*dev
= netdev_vport_get_dev(netdev
);
579 dev
->stats
.tx_packets
+= stats
->n_packets
;
580 dev
->stats
.tx_bytes
+= stats
->n_bytes
;
585 get_patch_config(struct netdev_dev
*dev_
, struct smap
*args
)
587 struct netdev_dev_vport
*dev
= netdev_dev_vport_cast(dev_
);
590 smap_add(args
, "peer", dev
->peer
);
596 set_patch_config(struct netdev_dev
*dev_
, const struct smap
*args
)
598 struct netdev_dev_vport
*dev
= netdev_dev_vport_cast(dev_
);
599 const char *name
= netdev_dev_get_name(dev_
);
602 peer
= smap_get(args
, "peer");
604 VLOG_ERR("%s: patch type requires valid 'peer' argument", name
);
608 if (smap_count(args
) > 1) {
609 VLOG_ERR("%s: patch type takes only a 'peer' argument", name
);
613 if (!strcmp(name
, peer
)) {
614 VLOG_ERR("%s: patch peer must not be self", name
);
619 dev
->peer
= xstrdup(peer
);
625 get_stats(const struct netdev
*netdev
, struct netdev_stats
*stats
)
627 struct netdev_dev_vport
*dev
= netdev_vport_get_dev(netdev
);
628 memcpy(stats
, &dev
->stats
, sizeof *stats
);
632 #define VPORT_FUNCTIONS(GET_CONFIG, SET_CONFIG, \
633 GET_TUNNEL_CONFIG, GET_STATUS) \
638 netdev_vport_create, \
639 netdev_vport_destroy, \
645 netdev_vport_close, \
649 NULL, /* recv_wait */ \
653 NULL, /* send_wait */ \
655 netdev_vport_set_etheraddr, \
656 netdev_vport_get_etheraddr, \
657 NULL, /* get_mtu */ \
658 NULL, /* set_mtu */ \
659 NULL, /* get_ifindex */ \
660 NULL, /* get_carrier */ \
661 NULL, /* get_carrier_resets */ \
662 NULL, /* get_miimon */ \
664 NULL, /* set_stats */ \
666 NULL, /* get_features */ \
667 NULL, /* set_advertisements */ \
669 NULL, /* set_policing */ \
670 NULL, /* get_qos_types */ \
671 NULL, /* get_qos_capabilities */ \
672 NULL, /* get_qos */ \
673 NULL, /* set_qos */ \
674 NULL, /* get_queue */ \
675 NULL, /* set_queue */ \
676 NULL, /* delete_queue */ \
677 NULL, /* get_queue_stats */ \
678 NULL, /* dump_queues */ \
679 NULL, /* dump_queue_stats */ \
681 NULL, /* get_in4 */ \
682 NULL, /* set_in4 */ \
683 NULL, /* get_in6 */ \
684 NULL, /* add_router */ \
685 NULL, /* get_next_hop */ \
687 NULL, /* arp_lookup */ \
689 netdev_vport_update_flags, \
691 netdev_vport_change_seq
693 #define TUNNEL_CLASS(NAME, DPIF_PORT) \
695 { NAME, VPORT_FUNCTIONS(get_tunnel_config, \
697 get_netdev_tunnel_config, \
698 tunnel_get_status) }}
701 netdev_vport_tunnel_register(void)
703 static const struct vport_class vport_classes
[] = {
704 TUNNEL_CLASS("gre", "gre_system"),
705 TUNNEL_CLASS("ipsec_gre", "gre_system"),
706 TUNNEL_CLASS("gre64", "gre64_system"),
707 TUNNEL_CLASS("ipsec_gre64", "gre64_system"),
708 TUNNEL_CLASS("vxlan", "vxlan_system"),
709 TUNNEL_CLASS("lisp", "lisp_system")
714 for (i
= 0; i
< ARRAY_SIZE(vport_classes
); i
++) {
715 netdev_register_provider(&vport_classes
[i
].netdev_class
);
720 netdev_vport_patch_register(void)
722 static const struct vport_class patch_class
=
724 { "patch", VPORT_FUNCTIONS(get_patch_config
,
728 netdev_register_provider(&patch_class
.netdev_class
);