]> git.proxmox.com Git - pve-network.git/blob - PVE/Network/SDN/Zones/QinQPlugin.pm
bridge-disable-mac-learning : use $opts for tap_plug
[pve-network.git] / PVE / Network / SDN / Zones / QinQPlugin.pm
1 package PVE::Network::SDN::Zones::QinQPlugin;
2
3 use strict;
4 use warnings;
5
6 use PVE::Exception qw(raise raise_param_exc);
7
8 use PVE::Network::SDN::Zones::Plugin;
9
10 use base('PVE::Network::SDN::Zones::Plugin');
11
12 sub type {
13 return 'qinq';
14 }
15
16 sub properties {
17 return {
18 tag => {
19 type => 'integer',
20 minimum => 0,
21 description => "Service-VLAN Tag",
22 },
23 mtu => {
24 type => 'integer',
25 description => "MTU",
26 optional => 1,
27 },
28 'vlan-protocol' => {
29 type => 'string',
30 enum => ['802.1q', '802.1ad'],
31 default => '802.1q',
32 optional => 1,
33 }
34 };
35 }
36
37 sub options {
38 return {
39 nodes => { optional => 1},
40 'tag' => { optional => 0 },
41 'bridge' => { optional => 0 },
42 'bridge-disable-mac-learning' => { optional => 1 },
43 'mtu' => { optional => 1 },
44 'vlan-protocol' => { optional => 1 },
45 dns => { optional => 1 },
46 reversedns => { optional => 1 },
47 dnszone => { optional => 1 },
48 ipam => { optional => 1 },
49 };
50 }
51
52 # Plugin implementation
53 sub generate_sdn_config {
54 my ($class, $plugin_config, $zoneid, $vnetid, $vnet, $controller, $controller_cfg, $subnet_cfg, $interfaces_config, $config) = @_;
55
56 my ($bridge, $mtu, $stag) = $plugin_config->@{'bridge', 'mtu', 'tag'};
57 my $vlanprotocol = $plugin_config->{'vlan-protocol'};
58
59 PVE::Network::SDN::Zones::Plugin::find_bridge($bridge);
60
61 my $vlan_aware = PVE::Network::SDN::Zones::Plugin::is_vlanaware($bridge);
62 my $is_ovs = PVE::Network::SDN::Zones::Plugin::is_ovs($bridge);
63
64 my @iface_config = ();
65 my $zone_notag_uplink = "ln_${zoneid}";
66 my $zone_notag_uplinkpeer = "pr_${zoneid}";
67 my $zone = "z_${zoneid}";
68
69 my $vnet_bridge_ports = "";
70 if (my $ctag = $vnet->{tag}) {
71 $vnet_bridge_ports = "$zone.$ctag";
72 } else {
73 $vnet_bridge_ports = $zone_notag_uplinkpeer;
74 }
75
76 my $zone_bridge_ports = "";
77 if ($is_ovs) {
78 # ovs--->ovsintport(dot1q-tunnel tag)------->vlanawarebrige-----(tag)--->vnet
79
80 $vlanprotocol = "802.1q" if !$vlanprotocol;
81 my $svlan_iface = "sv_".$zoneid;
82
83 # ovs dot1q-tunnel port
84 @iface_config = ();
85 push @iface_config, "ovs_type OVSIntPort";
86 push @iface_config, "ovs_bridge $bridge";
87 push @iface_config, "ovs_mtu $mtu" if $mtu;
88 push @iface_config, "ovs_options vlan_mode=dot1q-tunnel tag=$stag other_config:qinq-ethtype=$vlanprotocol";
89 push(@{$config->{$svlan_iface}}, @iface_config) if !$config->{$svlan_iface};
90
91 # redefine main ovs bridge, ifupdown2 will merge ovs_ports
92 @{$config->{$bridge}}[0] = "ovs_ports" if !@{$config->{$bridge}}[0];
93 my @ovs_ports = split / / , @{$config->{$bridge}}[0];
94 @{$config->{$bridge}}[0] .= " $svlan_iface" if !grep( $_ eq $svlan_iface, @ovs_ports );
95
96 $zone_bridge_ports = $svlan_iface;
97
98 } elsif ($vlan_aware) {
99 # VLAN_aware_brige-(tag)----->vlanwarebridge-(tag)----->vnet
100
101 if ($vlanprotocol) {
102 @iface_config = ();
103 push @iface_config, "bridge-vlan-protocol $vlanprotocol";
104 push(@{$config->{$bridge}}, @iface_config) if !$config->{$bridge};
105 }
106
107 $zone_bridge_ports = "$bridge.$stag";
108
109 } else {
110 # eth--->eth.x(svlan)----->vlanwarebridge-(tag)----->vnet---->vnet
111
112 my @bridge_ifaces = PVE::Network::SDN::Zones::Plugin::get_bridge_ifaces($bridge);
113
114 for my $bridge_iface (@bridge_ifaces) {
115 # use named vlan interface to avoid too long names
116 my $svlan_iface = "sv_$zoneid";
117
118 # svlan
119 @iface_config = ();
120 push @iface_config, "vlan-raw-device $bridge_iface";
121 push @iface_config, "vlan-id $stag";
122 push @iface_config, "vlan-protocol $vlanprotocol" if $vlanprotocol;
123 push(@{$config->{$svlan_iface}}, @iface_config) if !$config->{$svlan_iface};
124
125 $zone_bridge_ports = $svlan_iface;
126 last;
127 }
128 }
129
130 # veth peer for notag vnet
131 @iface_config = ();
132 push @iface_config, "link-type veth";
133 push @iface_config, "veth-peer-name $zone_notag_uplinkpeer";
134 push(@{$config->{$zone_notag_uplink}}, @iface_config) if !$config->{$zone_notag_uplink};
135
136 @iface_config = ();
137 push @iface_config, "link-type veth";
138 push @iface_config, "veth-peer-name $zone_notag_uplink";
139 push(@{$config->{$zone_notag_uplinkpeer}}, @iface_config) if !$config->{$zone_notag_uplinkpeer};
140
141 # zone vlan aware bridge
142 @iface_config = ();
143 push @iface_config, "mtu $mtu" if $mtu;
144 push @iface_config, "bridge-stp off";
145 push @iface_config, "bridge-ports $zone_bridge_ports $zone_notag_uplink";
146 push @iface_config, "bridge-fd 0";
147 push @iface_config, "bridge-vlan-aware yes";
148 push @iface_config, "bridge-vids 2-4094";
149 push(@{$config->{$zone}}, @iface_config) if !$config->{$zone};
150
151 # vnet bridge
152 @iface_config = ();
153 push @iface_config, "bridge_ports $vnet_bridge_ports";
154 push @iface_config, "bridge_stp off";
155 push @iface_config, "bridge_fd 0";
156 if($vnet->{vlanaware}) {
157 push @iface_config, "bridge-vlan-aware yes";
158 push @iface_config, "bridge-vids 2-4094";
159 }
160 push @iface_config, "mtu $mtu" if $mtu;
161 push @iface_config, "alias $vnet->{alias}" if $vnet->{alias};
162 push(@{$config->{$vnetid}}, @iface_config) if !$config->{$vnetid};
163 }
164
165 sub status {
166 my ($class, $plugin_config, $zone, $vnetid, $vnet, $status) = @_;
167
168 my $bridge = $plugin_config->{bridge};
169 my $err_msg = [];
170
171 if (!-d "/sys/class/net/$bridge") {
172 push @$err_msg, "missing $bridge";
173 return $err_msg;
174 }
175
176 my $vlan_aware = PVE::Network::SDN::Zones::Plugin::is_vlanaware($bridge);
177
178 my $tag = $vnet->{tag};
179 my $vnet_uplink = "ln_".$vnetid;
180 my $vnet_uplinkpeer = "pr_".$vnetid;
181 my $zone_notag_uplink = "ln_".$zone;
182 my $zone_notag_uplinkpeer = "pr_".$zone;
183 my $zonebridge = "z_$zone";
184
185 # ifaces to check
186 my $ifaces = [ $vnetid, $bridge ];
187
188 push @$ifaces, $zonebridge;
189 push @$ifaces, $zone_notag_uplink;
190 push @$ifaces, $zone_notag_uplinkpeer;
191
192 if (!$vlan_aware) {
193 my $svlan_iface = "sv_$zone";
194 push @$ifaces, $svlan_iface;
195 }
196
197 foreach my $iface (@{$ifaces}) {
198 if (!$status->{$iface}->{status}) {
199 push @$err_msg, "missing $iface";
200 } elsif ($status->{$iface}->{status} ne 'pass') {
201 push @$err_msg, "error $iface";
202 }
203 }
204 return $err_msg;
205 }
206
207 sub vnet_update_hook {
208 my ($class, $vnet_cfg, $vnetid, $zone_cfg) = @_;
209
210 my $vnet = $vnet_cfg->{ids}->{$vnetid};
211
212 my $tag = $vnet->{tag};
213 raise_param_exc({ tag => "VLAN tag maximal value is 4096" }) if $tag && $tag > 4096;
214
215 # verify that tag is not already defined in another vnet on same zone
216 for my $id (sort keys %{$vnet_cfg->{ids}}) {
217 next if $id eq $vnetid;
218 my $other_vnet = $vnet_cfg->{ids}->{$id};
219 next if $vnet->{zone} ne $other_vnet->{zone};
220 my $other_tag = $other_vnet->{tag};
221 if ($tag) {
222 raise_param_exc({ tag => "tag $tag already exist in zone $vnet->{zone} vnet $id"})
223 if $other_tag && $tag eq $other_tag;
224 } else {
225 raise_param_exc({ tag => "tag-less vnet already exists in zone $vnet->{zone} vnet $id"})
226 if !$other_tag;
227 }
228 }
229 }
230
231 1;
232
233