]> git.proxmox.com Git - mirror_iproute2.git/log
mirror_iproute2.git
7 years agoman: ip-link: Specify min/max values for bridge slave priority and cost
Phil Sutter [Tue, 4 Apr 2017 15:08:43 +0000 (17:08 +0200)]
man: ip-link: Specify min/max values for bridge slave priority and cost

The values are parsed as u16/u32, but kernel limits allowed values.

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agoip: link: Add missing link type help texts
Phil Sutter [Tue, 28 Mar 2017 21:19:39 +0000 (23:19 +0200)]
ip: link: Add missing link type help texts

These are basically stubs: The types which lacked their own help text
simply don't accept any options (yet). Still it might be a bit confusing
to users if they are presented with the generic 'ip link' help text
instead of something saying there are no type specific options.

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agoip: link: Unify link type help functions a bit
Phil Sutter [Tue, 28 Mar 2017 21:19:38 +0000 (23:19 +0200)]
ip: link: Unify link type help functions a bit

Take help function in iplink_bridge.c as an example and make other link
types' help functions similar:

* Use a single fprintf() call (if possible).
* Don't state a full command line, just "... type OPTIONS".
* Put every option in it's own line, align options by column.
* List mandatory options first.

link_veth.c is intentionally left untouched because it's 'peer' option
eats all kinds of generic link options and the help text points this out
without duplicating all the options there again.

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agoip: link: macvlan: Add newline to help output
Phil Sutter [Tue, 28 Mar 2017 21:19:37 +0000 (23:19 +0200)]
ip: link: macvlan: Add newline to help output

A newline between synopsis and variable definition looks nice and is
consistent with others.

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agoip: link: bond: Fix whitespace in help text
Phil Sutter [Tue, 28 Mar 2017 21:19:36 +0000 (23:19 +0200)]
ip: link: bond: Fix whitespace in help text

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agoman: ip-link.8: document bridge options
Sabrina Dubroca [Tue, 28 Mar 2017 15:56:48 +0000 (17:56 +0200)]
man: ip-link.8: document bridge options

Signed-off-by: Phil Sutter <phil@nwl.cc>
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
7 years agotc: print skbedit action when dumping actions.
Roman Mashak [Wed, 22 Mar 2017 18:00:31 +0000 (14:00 -0400)]
tc: print skbedit action when dumping actions.

Signed-off-by: Roman Mashak <mrv@mojatatu.com>
7 years agoman: fix man page warnings
Alexander Alemayhu [Sun, 26 Mar 2017 19:11:14 +0000 (21:11 +0200)]
man: fix man page warnings

While generating PDFs from the man pages, I saw the warning below from
several files. Compared the tc-matchall.8 with bridge.8 and used .RI
instead of .R. It should have no effect on the man page rendering.

    `R' is a string (producing the registered sign), not a macro.

Signed-off-by: Alexander Alemayhu <alexander@alemayhu.com>
7 years agoupdate headers from 4.11-rc3
Stephen Hemminger [Mon, 20 Mar 2017 17:16:46 +0000 (10:16 -0700)]
update headers from 4.11-rc3

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agovxlan: use preferred address family when neither group or remote is specified
Vincent Bernat [Thu, 9 Mar 2017 20:05:42 +0000 (21:05 +0100)]
vxlan: use preferred address family when neither group or remote is specified

When neither group or remote is specified (or if they are specified with
the any address), nothing is sent to the kernel. In this case, the
kernel defaults to IPv4. This makes impossible to use IPv6 with
unspecified unicast remote ("bridge fdb add" will return
EAFNOTSUPPORT).

If the user specifies a preferred address family (eg, "ip -6 link add"),
then send either IFLA_VXLAN_GROUP or IFLA_VXLAN_GROUP6 to enforce the
use of the appropriate family.

Signed-off-by: Vincent Bernat <vincent@bernat.im>
7 years agoip route: Add missing space between nexthop and via for mpls multipath routes
David Ahern [Fri, 17 Mar 2017 23:39:14 +0000 (16:39 -0700)]
ip route: Add missing space between nexthop and via for mpls multipath routes

MPLS multipath routes are missing a space between 'nexthop' and 'via':

$ ip -net ns1 -f mpls ro ls
100
nexthopvia inet 172.16.2.2  dev virt12
nexthopvia inet 172.16.3.2  dev br0

Add it.

Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoman: add examples to ip.8
Alexander Alemayhu [Sun, 12 Mar 2017 20:41:16 +0000 (21:41 +0100)]
man: add examples to ip.8

Having some examples in the top level man page might make it a little bit easier
for new users to get started. Reused some words / sentences from the existing
man pages.

Suggested-by: 積丹尼 Dan Jacobson <jidanni@jidanni.org>
Signed-off-by: Alexander Alemayhu <alexander@alemayhu.com>
7 years agoupdate headers from 4.11-rc2
Stephen Hemminger [Mon, 13 Mar 2017 15:30:39 +0000 (08:30 -0700)]
update headers from 4.11-rc2

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoman: Fix formatting of vrf parameter of ip-link show command
Robert Shearman [Thu, 9 Mar 2017 12:56:14 +0000 (12:56 +0000)]
man: Fix formatting of vrf parameter of ip-link show command

Add missing opening " [" for the vrf parameter.

Signed-off-by: Robert Shearman <rshearma@brocade.com>
7 years agopie: remove always false condition
Stephen Hemminger [Fri, 10 Mar 2017 16:56:51 +0000 (08:56 -0800)]
pie: remove always false condition

When built with GCC warnings enabled:
q_pie.c: In function ‘pie_parse_opt’:
q_pie.c:78:38: warning: comparison of unsigned expression < 0 is always false [-Wtype-limits]
        (alpha > ALPHA_MAX) || (alpha < ALPHA_MIN)) {
                                      ^
q_pie.c:85:35: warning: comparison of unsigned expression < 0 is always false [-Wtype-limits]
        (beta > BETA_MAX) || (beta < BETA_MIN)) {
                                   ^

This is because MIN is 0 and unsigned number can never be less than 0.
Therefore just remove the _MIN values.

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoiplink: add support for afstats subcommand
Robert Shearman [Thu, 9 Mar 2017 12:43:36 +0000 (12:43 +0000)]
iplink: add support for afstats subcommand

Add support for new afstats subcommand. This uses the new
IFLA_STATS_AF_SPEC attribute of RTM_GETSTATS messages to show
per-device, AF-specific stats. At the moment the kernel only supports
MPLS AF stats, so that is all that's implemented here.

The print_num function is exposed from ipaddress.c to be used for
printing the new stats so that the human-readable option, if set, can
be respected.

Example of use:

    $ ./ip/ip -f mpls link afstats dev eth1
    3: eth1
        mpls:
            RX: bytes  packets  errors  dropped  noroute
            9016       98       0       0        0
            TX: bytes  packets  errors  dropped
            7232       113      0       0

Signed-off-by: Robert Shearman <rshearma@brocade.com>
7 years agoman: ss.8: Add missing protocols to description of -A
Phil Sutter [Thu, 9 Mar 2017 16:07:33 +0000 (17:07 +0100)]
man: ss.8: Add missing protocols to description of -A

The list was missing dccp and sctp protocols.

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agodevlink: Add json and pretty options to help and man
Roi Dayan [Mon, 6 Mar 2017 09:06:18 +0000 (11:06 +0200)]
devlink: Add json and pretty options to help and man

While at it also fixed missing double dash for long opts.

Signed-off-by: Roi Dayan <roid@mellanox.com>
Acked-by: Jiri Pirko <jiri@mellanox.com>
7 years agobpf: test for valid type in bpf_get_work_dir
Daniel Borkmann [Mon, 6 Mar 2017 12:06:00 +0000 (13:06 +0100)]
bpf: test for valid type in bpf_get_work_dir

Jan-Erik reported an assertion in bpf_prog_to_subdir() failed where
type was BPF_PROG_TYPE_UNSPEC, which is only used in bpf_init_env()
to auto-mount and cache the bpf fs mount point.

Therefore, make sure when bpf_init_env() is called multiple times
(f.e. eBPF classifier with eBPF action attached) and bpf_mnt_cached
is set already that the type is also valid. In bpf_init_env(), we're
only interested in the mount point and not a type-specific subdir.

Fixes: e42256699cac ("bpf: make tc's bpf loader generic and move into lib")
Reported-by: Jan-Erik Rediger <janerik@rediger.net>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
7 years agocolor: use "light" colors for dark background
Petr Vorel [Wed, 1 Mar 2017 20:52:33 +0000 (21:52 +0100)]
color: use "light" colors for dark background

COLORFGBG environment variable is used to detect dark background.

Idea and a bit of code is borrowed from Vim, thanks.

Signed-off-by: Petr Vorel <pvorel@suse.cz>
Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agobpf: remove unnecessary cast
Stephen Hemminger [Fri, 24 Feb 2017 23:24:42 +0000 (15:24 -0800)]
bpf: remove unnecessary cast

No need to cast RTA_DATA

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agotc: use rta_getattr_u32
Stephen Hemminger [Fri, 24 Feb 2017 23:24:05 +0000 (15:24 -0800)]
tc: use rta_getattr_u32

Don't cast RTA_DATA use newish accessors.

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoxfrm: remove unnecessary casts
Stephen Hemminger [Fri, 24 Feb 2017 23:22:42 +0000 (15:22 -0800)]
xfrm: remove unnecessary casts

Since RTA_DATA() returns void * no need to cast it.

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoiproute2: tc: introduce build dependency on libnetlink
Jiri Kosina [Fri, 24 Feb 2017 17:28:54 +0000 (18:28 +0100)]
iproute2: tc: introduce build dependency on libnetlink

Rebuilding libnetlink doesn't trigger rebuild of tc, which is wrong
(especially so for builds where libnetlink.a gets statically linked into
tc). Fix that by introducing an explicit dependency.

Signed-off-by: Jiri Kosina <jkosina@suse.cz>
7 years agonetlink route attribute cleanup
Stephen Hemminger [Fri, 24 Feb 2017 16:56:38 +0000 (08:56 -0800)]
netlink route attribute cleanup

Use the new helper functions rta_getattr_u* instead of direct
cast of RTA_DATA().  Where RTA_DATA() is a structure, then remove
the unnecessary cast since RTA_DATA() is void *

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years ago{f,m}_bpf: dump tag over insns
Daniel Borkmann [Thu, 23 Feb 2017 12:07:14 +0000 (13:07 +0100)]
{f,m}_bpf: dump tag over insns

We already export TCA_BPF_TAG resp. TCA_ACT_BPF_TAG from kernel commit
f1f7714ea51c ("bpf: rework prog_digest into prog_tag"), thus also dump
it when filter/actions are shown.

Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
7 years agotc: flower: Fix parsing ip address
Roi Dayan [Wed, 22 Feb 2017 14:05:01 +0000 (16:05 +0200)]
tc: flower: Fix parsing ip address

Fix order of arguments when passed to __flower_parse_ip_addr.

Fixes: ("f888f4e20534 tc: flower: Support matching ARP")
Signed-off-by: Roi Dayan <roid@mellanox.com>
Reviewed-by: Paul Blakey <paulb@mellanox.com>
Reviewed-by: Simon Horman <simon.horman@netronome.com>
7 years agoip: Add support for MPLS netconf
David Ahern [Tue, 21 Feb 2017 17:23:31 +0000 (09:23 -0800)]
ip: Add support for MPLS netconf

Add support for MPLS netconf to ip monitor and ip netconf commands.
Changes to header files not included as those are typically pulled
in my a header sync with the kernel.

Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoUpdate headers based on 4.11 merge window
Stephen Hemminger [Thu, 23 Feb 2017 16:58:11 +0000 (08:58 -0800)]
Update headers based on 4.11 merge window

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoupdate headers from net-next
Stephen Hemminger [Mon, 20 Feb 2017 16:53:50 +0000 (08:53 -0800)]
update headers from net-next

updated sctp.h

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoadd missing iplink_xstats.c
Stephen Hemminger [Mon, 20 Feb 2017 16:53:25 +0000 (08:53 -0800)]
add missing iplink_xstats.c

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Mon, 20 Feb 2017 16:51:22 +0000 (08:51 -0800)]
Merge branch 'master' into net-next

7 years agov4.10.0
Stephen Hemminger [Mon, 20 Feb 2017 16:47:52 +0000 (08:47 -0800)]
v4.10.0

7 years agodevlink: use DEVLINK_CMD_ESWITCH_* instead of DEVLINK_CMD_ESWITCH_MODE_*
Jiri Pirko [Sun, 19 Feb 2017 14:37:06 +0000 (15:37 +0100)]
devlink: use DEVLINK_CMD_ESWITCH_* instead of DEVLINK_CMD_ESWITCH_MODE_*

Sync with kernel and don't use the obsolete enum values.

Signed-off-by: Jiri Pirko <jiri@mellanox.com>
7 years agoiplink: bridge_slave: add support for displaying xstats
Nikolay Aleksandrov [Wed, 15 Feb 2017 14:23:13 +0000 (15:23 +0100)]
iplink: bridge_slave: add support for displaying xstats

This patch adds support to the bridge_slave link type for displaying
xstats by reusing the previously added bridge xstats callbacks.

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
7 years agoiplink: bridge: add support for displaying xstats
Nikolay Aleksandrov [Wed, 15 Feb 2017 14:23:12 +0000 (15:23 +0100)]
iplink: bridge: add support for displaying xstats

Add support for the new parse/print_ifla_xstats callbacks and use them to
print the per-bridge multicast stats.
Example:
$ ip link xstats type bridge
br0
                    IGMP queries:
                      RX: v1 0 v2 0 v3 0
                      TX: v1 0 v2 0 v3 0
                    IGMP reports:
                      RX: v1 0 v2 0 v3 0
                      TX: v1 0 v2 0 v3 0
                    IGMP leaves: RX: 0 TX: 0
                    IGMP parse errors: 0
                    MLD queries:
                      RX: v1 0 v2 0
                      TX: v1 0 v2 0
                    MLD reports:
                      RX: v1 0 v2 0
                      TX: v1 0 v2 0
                    MLD leaves: RX: 0 TX: 0
                    MLD parse errors: 0

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
7 years agoiplink: add support for xstats subcommand
Nikolay Aleksandrov [Sun, 19 Feb 2017 00:35:32 +0000 (16:35 -0800)]
iplink: add support for xstats subcommand

This patch adds support for a new xstats link subcommand which uses the
specified link type's new parse/print_ifla_xstats callbacks to display
extended statistics.

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Sun, 19 Feb 2017 00:32:16 +0000 (16:32 -0800)]
Merge branch 'master' into net-next

7 years agodevlink: Call dl_free in early exit case
Leon Romanovsky [Tue, 14 Feb 2017 05:29:38 +0000 (07:29 +0200)]
devlink: Call dl_free in early exit case

Prior to parsing command options, the devlink tool allocates memory
to store results. In case of early exit (wrong parameters or version
check), this memory wasn't freed.

Signed-off-by: Leon Romanovsky <leonro@mellanox.com>
Acked-by: Jiri Pirko <jiri@mellanox.com>
7 years agoman page: add page for skbmod action
Lucas Bates [Fri, 10 Feb 2017 23:28:54 +0000 (18:28 -0500)]
man page: add page for skbmod action

Signed-off-by: Lucas Bates <lucasb@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Roman Mashak <mrv@mojatatu.com>
Reviewed-by: Simon Horman <simon.horman@netronome.com>
7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Sun, 19 Feb 2017 00:21:20 +0000 (16:21 -0800)]
Merge branch 'master' into net-next

7 years agoutils: hex2mem get rid of unnecessary goto
Stephen Hemminger [Sun, 19 Feb 2017 00:17:43 +0000 (16:17 -0800)]
utils: hex2mem get rid of unnecessary goto

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Sun, 19 Feb 2017 00:07:32 +0000 (16:07 -0800)]
Merge branch 'master' into net-next

7 years agoupdate headers from 4.10-rc8
Stephen Hemminger [Sun, 19 Feb 2017 00:05:37 +0000 (16:05 -0800)]
update headers from 4.10-rc8

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoMerge branch 'merge-4.10' of /tmp/iproute2
Stephen Hemminger [Sun, 19 Feb 2017 00:04:25 +0000 (16:04 -0800)]
Merge branch 'merge-4.10' of /tmp/iproute2

7 years agoMerge branch 'merge-4.10' into next-merge
Stephen Hemminger [Fri, 17 Feb 2017 23:34:24 +0000 (15:34 -0800)]
Merge branch 'merge-4.10' into next-merge

7 years agoip vrf: Detect invalid vrf name in pids command
David Ahern [Thu, 16 Feb 2017 16:58:58 +0000 (08:58 -0800)]
ip vrf: Detect invalid vrf name in pids command

Verify VRF name is valid before attempting to read cgroups files.

Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoip vrf: Handle VRF nesting in namespace
David Ahern [Thu, 16 Feb 2017 16:58:57 +0000 (08:58 -0800)]
ip vrf: Handle VRF nesting in namespace

Since cgroups are not namespace aware, the directory heirarchy used by
ip vrf should account for network namespaces. In this case, change the
path from CGRP/BASE/vrf/NAME to CGRP/BASE/NETNS/vrf/NAME where CGRP is
the cgroup2 mount path, BASE in any base heirarchy inherited before VRF
is applied and NAME is the VRF name.

The intent is as follows: a user logs into the box into some namespace
with a name known to iproute2. Some other policy may have put the
process into a BASE heirarchy. From there the user executes a task in
a VRF and in doing so the task heirarchy becomes CGRP/BASE/NETNS/vrf/NAME.
The namespace level is omitted for the default namespace.

Reported-by: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoip netns: refactor netns_identify
David Ahern [Thu, 16 Feb 2017 16:58:56 +0000 (08:58 -0800)]
ip netns: refactor netns_identify

Move guts of netns_identify into a standalone function that returns
the netns name in a given buffer.

Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoip vrf: Handle vrf in a cgroup hierarchy
David Ahern [Thu, 16 Feb 2017 16:58:55 +0000 (08:58 -0800)]
ip vrf: Handle vrf in a cgroup hierarchy

Add support for VRF in a pre-existing hierarchy. For example, if the
current process is running in CGRP/foo/bar, the 'ip vrf exec NAME CMD'
should run CMD in the cgroup CGRP/foo/bar/vrf/NAME.

When listing process ids in a VRF, search for the directory vrf/NAME
regardless of base path (foo/bar/vrf/NAME and vrf/NAME) are still
running against the same vrf NAME.

Reported-by: Andy Lutomirski <luto@amacapital.net>
Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoMerge branch 'merge-4.10' into next-merge
Stephen Hemminger [Fri, 17 Feb 2017 23:32:28 +0000 (15:32 -0800)]
Merge branch 'merge-4.10' into next-merge

7 years agotc: flower: support masked ICMP code and type match
Simon Horman [Thu, 9 Feb 2017 13:49:01 +0000 (14:49 +0100)]
tc: flower: support masked ICMP code and type match

Extend ICMP code and type match to support masks.

Also add missing documentation to synopsis in manpage.

tc qdisc add dev eth0 ingress
tc filter add dev eth0 protocol ipv6 parent ffff: flower \
indev eth0 ip_proto icmpv6 type 128/240 code 0 action drop

Signed-off-by: Simon Horman <simon.horman@netronome.com>
7 years agotc: flower: provide generic masked u8 print helper
Simon Horman [Thu, 9 Feb 2017 13:49:00 +0000 (14:49 +0100)]
tc: flower: provide generic masked u8 print helper

Provide generic masked u8 print helper and use it to print arp operations.

Also:
* Make name parameter of arp op print helper const.
* Consistently use __u8 rather than uint8_t, in keeping with the
  pervasive style in the file.

Signed-off-by: Simon Horman <simon.horman@netronome.com>
7 years agotc: flower: provide generic masked u8 parser helper
Simon Horman [Thu, 9 Feb 2017 13:48:59 +0000 (14:48 +0100)]
tc: flower: provide generic masked u8 parser helper

Provide generic masked u8 paser helper and use it to parse arp operations.

Also consistently use __u8 rather than uint8_t, in keeping with the
pervasive style in the file.

Signed-off-by: Simon Horman <simon.horman@netronome.com>
7 years agoupdate headers from net-next
Stephen Hemminger [Fri, 17 Feb 2017 23:30:50 +0000 (15:30 -0800)]
update headers from net-next

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoMerge branch 'master' into next-merge
Stephen Hemminger [Fri, 17 Feb 2017 23:29:24 +0000 (15:29 -0800)]
Merge branch 'master' into next-merge

7 years agotestsuite: search for kernel config in /boot
Asbjørn Sloth Tønnesen [Wed, 15 Feb 2017 21:26:42 +0000 (21:26 +0000)]
testsuite: search for kernel config in /boot

Add support for finding the kernel config in Debian
and derivatives.

Signed-off-by: Asbjørn Sloth Tønnesen <asbjorn@asbjorn.st>
7 years agotestsuite: refactor kernel config search
Asbjørn Sloth Tønnesen [Wed, 15 Feb 2017 21:26:41 +0000 (21:26 +0000)]
testsuite: refactor kernel config search

Signed-off-by: Asbjørn Sloth Tønnesen <asbjorn@asbjorn.st>
7 years agotc: matchall: Print skip flags when dumping a filter
Or Gerlitz [Thu, 9 Feb 2017 13:10:14 +0000 (15:10 +0200)]
tc: matchall: Print skip flags when dumping a filter

Print the skip flags when we dump a filter.

Signed-off-by: Or Gerlitz <ogerlitz@mellanox.com>
Acked by: Yotam Gigi <yotamg@mellanox.com>
Reviewed-by: Simon Horman <simon.horman@netronome.com>
7 years agoip route: Make name of protocol 0 consistent
David Ahern [Mon, 13 Feb 2017 20:21:53 +0000 (12:21 -0800)]
ip route: Make name of protocol 0 consistent

iproute2 can inconsistently show the name of protocol 0 if a route with
a custom protocol is added. For example:
  dsa@cartman:~$ ip -6 ro ls table all | egrep 'proto none|proto unspec'
  local ::1 dev lo  table local  proto none  metric 0  pref medium
  local fe80::225:90ff:fecb:1c18 dev lo  table local  proto none  metric 0  pref medium
  local fe80::92e2:baff:fe5c:da5d dev lo  table local  proto none  metric 0  pref medium

protocol 0 is pretty printed as "none". Add a route with a custom protocol:
  dsa@cartman:~$ sudo ip -6 ro add  2001:db8:200::1/128 dev eth0 proto 123

And now display has switched from "none" to "unspec":
  dsa@cartman:~$ ip -6 ro ls table all | egrep 'proto none|proto unspec'
  local ::1 dev lo  table local  proto unspec  metric 0  pref medium
  local fe80::225:90ff:fecb:1c18 dev lo  table local  proto unspec  metric 0  pref medium
  local fe80::92e2:baff:fe5c:da5d dev lo  table local  proto unspec  metric 0  pref medium

The rt_protos file has the id to name mapping as "unspec" while
rtnl_rtprot_tab[0] has "none". The presence of a custom protocol id
triggers reading the rt_protos file and overwriting the string in
rtnl_rtprot_tab. All of this is logic from 2004 and earlier.

Update rtnl_rtprot_tab to "unspec" to match the enum value.

Signed-off-by: David Ahern <dsa@cumulusnetworks.com>
7 years agoman: ip-link.8: Document bridge_slave fdb_flush option
Hangbin Liu [Thu, 9 Feb 2017 01:27:35 +0000 (09:27 +0800)]
man: ip-link.8: Document bridge_slave fdb_flush option

Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
7 years agotestsuite: Search kernel config in modules dir also
Phil Sutter [Thu, 9 Feb 2017 10:50:55 +0000 (11:50 +0100)]
testsuite: Search kernel config in modules dir also

At least in Fedora there is no /proc/config.gz but instead
/lib/modules/`uname -r`/config, so use that as a fallback.

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agotestsuite: Generate nlmsg blob at runtime
Phil Sutter [Thu, 9 Feb 2017 10:50:54 +0000 (11:50 +0100)]
testsuite: Generate nlmsg blob at runtime

Since netlink messages are in host byte order, shipping a pre-generated
nlmsg blob won't suffice on systems with different endianness. Therefore
generate the blob at runtime, so it's content fits the hosts endianness.

Note that the generated message will contain only a single interface
featuring two VFs instead of the full list before. Yet this is
sufficient, as it triggers the crash with iproute versions prior to
commit 8c29ae7cc2494 ("ip link: Fix crash on older kernels when show VF
dev").

Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agotc: flower: Update documentation to indicate ARP takes IPv4 prefixes
Simon Horman [Wed, 8 Feb 2017 12:01:04 +0000 (13:01 +0100)]
tc: flower: Update documentation to indicate ARP takes IPv4 prefixes

Unlike other PREFIXes documented in the usage for tc flower, which accept
both IPv4 and IPv6 prefixes, arp_sip and arp_tip only accepts IPv4
prefixes.

Signed-off-by: Simon Horman <simon.horman@netronome.com>
7 years agotc: flower: use correct type when calling flower_icmp_attr_type
Simon Horman [Wed, 8 Feb 2017 12:04:31 +0000 (13:04 +0100)]
tc: flower: use correct type when calling flower_icmp_attr_type

Use enum flower_icmp_field rather than bool as type of third parameter
when calling flower_icmp_attr_type.

Fixes: eb3b5696f163 ("tc: flower: support matching on ICMP type and code")
Signed-off-by: Simon Horman <simon.horman@netronome.com>
7 years agoman: ip-link.8: Document bridge_slave fdb_flush option
Hangbin Liu [Wed, 8 Feb 2017 08:02:20 +0000 (16:02 +0800)]
man: ip-link.8: Document bridge_slave fdb_flush option

Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
7 years agotc: add missing sample file
Stephen Hemminger [Tue, 7 Feb 2017 19:53:24 +0000 (11:53 -0800)]
tc: add missing sample file

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoupdate headers from bridge tunnel metadata
Stephen Hemminger [Tue, 7 Feb 2017 19:52:21 +0000 (11:52 -0800)]
update headers from bridge tunnel metadata

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agotc: bash-completion: Add support for matchall
Yotam Gigi [Tue, 7 Feb 2017 13:50:52 +0000 (15:50 +0200)]
tc: bash-completion: Add support for matchall

Add support for the matchall classifier and its parameters.

Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: bash-completion: Add support for filter actions
Yotam Gigi [Tue, 7 Feb 2017 13:50:51 +0000 (15:50 +0200)]
tc: bash-completion: Add support for filter actions

Previously, the autocomplete routine did not complete actions after a
filter keyword, for example:

$ tc filter add dev eth0 u32 [...] action <TAB>

did not suggest the actions list, and:

$ tc filter add dev eth0 u32 [...] action mirred <TAB>

did not suggest the specific mirred parameters. Add the support for this
kind of completion by adding the _tc_filter_action_options routine and
invoking it from inside _tc_filter_options.

Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: bash-completion: Make the *_KIND variables global
Yotam Gigi [Tue, 7 Feb 2017 13:50:50 +0000 (15:50 +0200)]
tc: bash-completion: Make the *_KIND variables global

The QDISC_KIND, FILTER_KIND, ACTION_KIND variables may be used by other
routines, thus make them global variables.

Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: bash-completion: Prepare action autocomplete to support several actions
Yotam Gigi [Tue, 7 Feb 2017 13:50:49 +0000 (15:50 +0200)]
tc: bash-completion: Prepare action autocomplete to support several actions

The action autocomplete routine (_tc_action_options) currently does not
support several actions statements in one tc command line as it uses the
_tc_once_attr and _tc_one_from_list.

For example, in that case:

$ tc filter add dev eth0 handle ffff: u32 [...]  \
   action sample group 5 rate 12   \
   action sample <TAB>

the _tc_once_attr function, when invoked with "group rate" will not
suggest those as they already exist on the command line.

Fix the function to use the _from variant, thus allowing each action
autocomplete start from the action keyword, and not from the beginning of
the command line.

Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: bash-completion: Add the _from variant to _tc_one* funcs
Yotam Gigi [Tue, 7 Feb 2017 13:50:48 +0000 (15:50 +0200)]
tc: bash-completion: Add the _from variant to _tc_one* funcs

The _tc_one_of_list and _tc_once_attr functions simplfy the bash
completion task by validating each attr exist only once on the command
line.

For example, for the command line:

$ a b c d e

and the call to _tc_once_attr with "a f g", the function will suggest
"f g" as "a" existed in the command line in args 0.

Add the _from variant to those functions, which allows having the command
line option once from a specified index. In the previous example, calling
_tc_once_attr with 4 and "a f g" will suggest "a f g".

Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: man: matchall: Update examples to include sample
Yotam Gigi [Sun, 5 Feb 2017 07:58:54 +0000 (09:58 +0200)]
tc: man: matchall: Update examples to include sample

Add an example of packet sampling to the tc-matchall man page examples
section. The example uses the matchall classifier and the sample action to
create packet sampling on a port.

Reviewed-by: Jiri Pirko <jiri@mellanox.com>
Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: man: Add man entry for the tc-sample action
Yotam Gigi [Mon, 6 Feb 2017 22:23:21 +0000 (14:23 -0800)]
tc: man: Add man entry for the tc-sample action

In addition to general information about the tc action, the man entry
contains common usage examples and information about the tlv fields packed
within each sampled packet.

Reviewed-by: Jiri Pirko <jiri@mellanox.com>
Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agotc: Add support for the sample tc action
Yotam Gigi [Sun, 5 Feb 2017 07:58:52 +0000 (09:58 +0200)]
tc: Add support for the sample tc action

The sample tc action allows sampling packets matching a classifier. It
peeks randomly packets, and samples them using the psample netlink
channel. The user can specify the psample group, which the packet will be
sampled to, the sampling rate and the packet truncation (to save
kernel-user traffic).

The sampled packets contain informative metadata, for example, the input
interface and the original packet length.

The action syntax:
tc filter add [...] \
action sample rate <RATE> group <GROUP> [trunc <SIZE>]
[...]

Where:
  RATE := The sampling rate which is the ratio of packets observed at the
  data source to the samples generated
  GROUP := the psample module sampling group
  SIZE := optional truncation size

An example for a common usecase of the sample tc action: to sample ingress
traffic from interface eth1, one may use the commands:

tc qdisc add dev eth1 handle ffff: ingress

tc filter add dev eth1 parent ffff: \
       matchall action sample rate 12 group 4

Where the first command adds an ingress qdisc and the second starts
sampling randomly with an average of one sampled packet per 12 packets
on dev eth1 to psample group 4.

Reviewed-by: Jiri Pirko <jiri@mellanox.com>
Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Mon, 6 Feb 2017 22:13:27 +0000 (14:13 -0800)]
Merge branch 'master' into net-next

7 years agotcp: header file update
Stephen Hemminger [Mon, 6 Feb 2017 22:08:07 +0000 (14:08 -0800)]
tcp: header file update

Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Mon, 6 Feb 2017 22:07:13 +0000 (14:07 -0800)]
Merge branch 'master' into net-next

7 years agoman: ip-route.8: Fix 'expires' indenting
Phil Sutter [Thu, 2 Feb 2017 15:22:56 +0000 (16:22 +0100)]
man: ip-route.8: Fix 'expires' indenting

Descriptions of each route sub-command's arguments are enclosed in
.RS/.RE pairs. For 'replace' sub-command, '.RE' was incorrectly put
before the last argument ('expires').

Fixes: 3fbe7ca847367 ("iproute2: ip-route.8.in: Add expires option for ip route")
Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agoss: print tcpi_rcv_mss and tcpi_advmss
Eric Dumazet [Thu, 2 Feb 2017 13:47:27 +0000 (05:47 -0800)]
ss: print tcpi_rcv_mss and tcpi_advmss

tcpi_rcv_mss and tcpi_advmss tcp info fields were not yet reported
by ss.

While adding GRO support to packetdrill, I found this was useful.

Signed-off-by: Eric Dumazet <edumazet@google.com>
7 years agoip: HSR: Fix cut and paste error
Ralf Baechle [Mon, 6 Feb 2017 20:47:35 +0000 (21:47 +0100)]
ip: HSR: Fix cut and paste error

Fixes: 5c0aec93a516 ("ip: Add HSR support")
Signed-off-by: Ralf Baechle <ralf@linux-mips.org>
7 years agoifstat: Add xstat to ifstat man page
Nogah Frankel [Thu, 26 Jan 2017 12:44:41 +0000 (14:44 +0200)]
ifstat: Add xstat to ifstat man page

Add documentation about the extended statistics to the ifstat man page.
Add ifstat man age to the man8 Makefile

Signed-off-by: Nogah Frankel <nogahf@mellanox.com>
Reviewed-by: Jiri Pirko <jiri@mellanox.com>
7 years agoifstat: Add "sw only" extended statistics to ifstat
Nogah Frankel [Thu, 26 Jan 2017 12:44:40 +0000 (14:44 +0200)]
ifstat: Add "sw only" extended statistics to ifstat

Add support for extended statistics of SW only type, for counting only the
packets that went via the cpu. (useful for systems with forward
offloading). It reads it from filter type IFLA_STATS_LINK_OFFLOAD_XSTATS
and sub type IFLA_OFFLOAD_XSTATS_CPU_HIT.

It is under the name 'cpu_hits'
(or any shorten of it as 'cpu' or simply 'c')

For example:
ifstat -x c

Signed-off-by: Nogah Frankel <nogahf@mellanox.com>
Reviewed-by: Jiri Pirko <jiri@mellanox.com>
7 years agoifstat: Add extended statistics to ifstat
Nogah Frankel [Thu, 26 Jan 2017 12:44:39 +0000 (14:44 +0200)]
ifstat: Add extended statistics to ifstat

Extended stats are part of the RTM_GETSTATS method. This patch adds them
to ifstat.
While extended stats can come in many forms, we support only the
rtnl_link_stats64 struct for them (which is the 64 bits version of struct
rtnl_link_stats).
We support stats in the main nesting level, or one lower.
The extension can be called by its name or any shorten of it. If there is
more than one matched, the first one will be picked.

To get the extended stats the flag -x <stats type> is used.

Signed-off-by: Nogah Frankel <nogahf@mellanox.com>
Reviewed-by: Jiri Pirko <jiri@mellanox.com>
7 years agoifstat: Includes reorder
Nogah Frankel [Thu, 26 Jan 2017 12:44:38 +0000 (14:44 +0200)]
ifstat: Includes reorder

Reorder the includes in misc/ifstat.c to match convention.

Signed-off-by: Nogah Frankel <nogahf@mellanox.com>
Reviewed-by: Jiri Pirko <jiri@mellanox.com>
7 years agotc: man: matchall: Fix example indentation
Yotam Gigi [Tue, 31 Jan 2017 09:47:47 +0000 (11:47 +0200)]
tc: man: matchall: Fix example indentation

The man page contains two examples, which have different indentation. Fix
the indentation of the two examples to match.

Reviewed-by: Jiri Pirko <jiri@mellanox.com>
Signed-off-by: Yotam Gigi <yotamg@mellanox.com>
7 years agoupdate kernel headers from net-next
Stephen Hemminger [Mon, 30 Jan 2017 04:31:31 +0000 (20:31 -0800)]
update kernel headers from net-next

7 years agoMerge branch 'master' into net-next
Stephen Hemminger [Mon, 30 Jan 2017 04:30:05 +0000 (20:30 -0800)]
Merge branch 'master' into net-next

7 years agotc: distinguish Add/Replace action operations.
Roman Mashak [Sun, 22 Jan 2017 13:55:33 +0000 (08:55 -0500)]
tc: distinguish Add/Replace action operations.

Signed-off-by: Roman Mashak <mrv@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Acked-by: Phil Sutter <phil@nwl.cc>
7 years agoman: tc-csum.8: Fix example
Phil Sutter [Sat, 28 Jan 2017 11:59:10 +0000 (12:59 +0100)]
man: tc-csum.8: Fix example

This fixes two issues with the provided example:

- Add missing 'dev' keyword to second command.
- Use a real IPv4 address instead of a bogus hex value since that will
  be rejected by get_addr_ipv4().

Fixes: dbfb17a67f9c7 ("man: tc-csum.8: Add an example")
Reported-by: Davide Caratti <dcaratti@redhat.com>
Signed-off-by: Phil Sutter <phil@nwl.cc>
7 years agof_flower: don't set TCA_FLOWER_KEY_ETH_TYPE for "protocol all"
Benjamin LaHaise [Fri, 20 Jan 2017 19:07:38 +0000 (14:07 -0500)]
f_flower: don't set TCA_FLOWER_KEY_ETH_TYPE for "protocol all"

v2 - update to address changes in 00697ca19ae3e1118f2af82c3b41ac4335fe918b.

When using the tc flower filter, rules marked with "protocol all" do not
actually match all packets.  This is due to a bug in f_flower.c that passes
in ETH_P_ALL in the TCA_FLOWER_KEY_ETH_TYPE attribute when adding a rule.
Fix this by omitting TCA_FLOWER_KEY_ETH_TYPE if the protocol is set to
ETH_P_ALL.

Fixes: 488b41d020fb ("tc: flower no need to specify the ethertype")
Cc: Jamal Hadi Salim <jhs@mojatatu.com>
Signed-off-by: Benjamin LaHaise <benjamin.lahaise@netronome.com>
Signed-off-by: Benjamin LaHaise <bcrl@kvack.org>
Reviewed-by: Roi Dayan <roid@mellanox.com>
7 years agotc: flower: Refactor matching flags to be more user friendly
Paul Blakey [Fri, 20 Jan 2017 18:36:45 +0000 (10:36 -0800)]
tc: flower: Refactor matching flags to be more user friendly

Instead of "magic numbers" we can now specify each flag
by name. Prefix of "no"  (e.g nofrag) unsets the flag,
otherwise it wil be set.

Example:
    # add a flower filter that will drop fragmented packets
    tc filter add dev ens4f0 protocol ip parent ffff: \
            flower \
            src_mac e4:1d:2d:fd:8b:01 \
            dst_mac e4:1d:2d:fd:8b:02 \
            indev ens4f0 \
            ip_flags frag \
    action drop

    # add a flower filter that will drop non-fragmented packets
    tc filter add dev ens4f0 protocol ip parent ffff: \
            flower \
            src_mac e4:1d:2d:fd:8b:01 \
            dst_mac e4:1d:2d:fd:8b:02 \
            indev ens4f0 \
            ip_flags nofrag \
    action drop

Fixes: 22a8f019891c ('tc: flower: support matching flags')
Signed-off-by: Paul Blakey <paulb@mellanox.com>
Reviewed-by: Roi Dayan <roid@mellanox.com>
Reviewed-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
7 years agoiplink: bridge_slave: add support for IFLA_BRPORT_FLUSH
Hangbin Liu [Wed, 18 Jan 2017 06:36:45 +0000 (14:36 +0800)]
iplink: bridge_slave: add support for IFLA_BRPORT_FLUSH

This patch implements support for the IFLA_BRPORT_FLUSH attribute
in iproute2 so it can flush bridge slave's fdb dynamic entries.

Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
Reviewed-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
7 years agoiplink: bridge: add support for IFLA_BR_MCAST_MLD_VERSION
Hangbin Liu [Wed, 18 Jan 2017 06:12:51 +0000 (14:12 +0800)]
iplink: bridge: add support for IFLA_BR_MCAST_MLD_VERSION

This patch implements support for the IFLA_BR_MCAST_MLD_VERSION
attribute in iproute2 so it can change the mcast mld version.

Reviewed-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
7 years agoiplink: bridge: add support for IFLA_BR_MCAST_IGMP_VERSION
Hangbin Liu [Wed, 18 Jan 2017 06:12:50 +0000 (14:12 +0800)]
iplink: bridge: add support for IFLA_BR_MCAST_IGMP_VERSION

This patch implements support for the IFLA_BR_MCAST_IGMP_VERSION
attribute in iproute2 so it can change the mcast igmp version.

Reviewed-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
7 years agoiplink: bridge: add support for IFLA_BR_MCAST_STATS_ENABLED
Hangbin Liu [Wed, 18 Jan 2017 06:12:49 +0000 (14:12 +0800)]
iplink: bridge: add support for IFLA_BR_MCAST_STATS_ENABLED

This patch implements support for the IFLA_BR_MCAST_STATS_ENABLED
attribute in iproute2 so it can enable/disable mcast stats accounting.

Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
Reviewed-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
7 years agoiplink: bridge: add support for IFLA_BR_VLAN_STATS_ENABLED
Hangbin Liu [Wed, 18 Jan 2017 06:12:48 +0000 (14:12 +0800)]
iplink: bridge: add support for IFLA_BR_VLAN_STATS_ENABLED

This patch implements support for the IFLA_BR_VLAN_STATS_ENABLED
attribute in iproute2 so it can enable/disable vlan stats accounting.

Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
Reviewed-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
7 years agoiplink: bridge: add support for IFLA_BR_FDB_FLUSH
Hangbin Liu [Wed, 18 Jan 2017 06:12:47 +0000 (14:12 +0800)]
iplink: bridge: add support for IFLA_BR_FDB_FLUSH

This patch implements support for the IFLA_BR_FDB_FLUSH attribute
in iproute2 so it can flush bridge fdb dynamic entries.

Reviewed-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: Hangbin Liu <liuhangbin@gmail.com>
7 years agoipmroute: add support for RTNH_F_UNRESOLVED
Nikolay Aleksandrov [Fri, 20 Jan 2017 14:15:21 +0000 (15:15 +0100)]
ipmroute: add support for RTNH_F_UNRESOLVED

This patch adds a new field that is printed in the end of the line which
denotes the real entry state. Before this patch an entry's IIF could
disappear and it would look like an unresolved one (iif = unresolved):
(3.0.16.1, 225.11.16.1)          Iif: unresolved

with no way to really distinguish it from an unresolved entry.
After the patch if the dumped entry has RTNH_F_UNRESOLVED set we get:
(3.0.16.1, 225.11.16.1)          Iif: unresolved  State: unresolved

for unresolved entries and:
(0.0.0.0, 225.11.11.11)          Iif: eth4       Oifs: eth3  State: resolved

for resolved entries after the OIF list. Note that "State:" has ':' in
it so it cannot be mistaken for an interface name.

And for the example above, we'd get:
(0.0.0.0, 225.11.11.11)          Iif: unresolved     State: resolved

Also when dumping all routes via ip route show table all,
 it will show up as:
multicast 225.11.16.1/32 from 3.0.16.1/32 table default proto 17 unresolved

Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>