From patchwork Tue Nov 24 21:43:20 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Han Zhou X-Patchwork-Id: 548291 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from archives.nicira.com (unknown [IPv6:2600:3c00::f03c:91ff:fe6e:bdf7]) by ozlabs.org (Postfix) with ESMTP id EC3C51402C2 for ; Wed, 25 Nov 2015 08:43:34 +1100 (AEDT) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b=AlG4zhhn; dkim-atps=neutral Received: from archives.nicira.com (localhost [127.0.0.1]) by archives.nicira.com (Postfix) with ESMTP id 09F5D109E0; Tue, 24 Nov 2015 13:43:34 -0800 (PST) X-Original-To: dev@openvswitch.org Delivered-To: dev@openvswitch.org Received: from mx3v3.cudamail.com (mx3.cudamail.com [64.34.241.5]) by archives.nicira.com (Postfix) with ESMTPS id 388CB1063B for ; Tue, 24 Nov 2015 13:43:33 -0800 (PST) Received: from bar3.cudamail.com (localhost [127.0.0.1]) by mx3v3.cudamail.com (Postfix) with ESMTPS id C3740161DC5 for ; Tue, 24 Nov 2015 14:43:32 -0700 (MST) X-ASG-Debug-ID: 1448401412-03dd7b464534a2b0001-byXFYA Received: from mx3-pf3.cudamail.com ([192.168.14.3]) by bar3.cudamail.com with ESMTP id E6nrHqirpfWybYCX (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 24 Nov 2015 14:43:32 -0700 (MST) X-Barracuda-Envelope-From: zhouhan@gmail.com X-Barracuda-RBL-Trusted-Forwarder: 192.168.14.3 Received: from unknown (HELO mail-pa0-f53.google.com) (209.85.220.53) by mx3-pf3.cudamail.com with ESMTPS (RC4-SHA encrypted); 24 Nov 2015 21:46:21 -0000 Received-SPF: pass (mx3-pf3.cudamail.com: SPF record at _netblocks.google.com designates 209.85.220.53 as permitted sender) X-Barracuda-RBL-Trusted-Forwarder: 209.85.220.53 Received: by pacdm15 with SMTP id dm15so34120458pac.3 for ; Tue, 24 Nov 2015 13:43:31 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:cc:subject:date:message-id; bh=owA7mt/8I7JnbaFWOBt3g4rgD/RFVTzyf+0YThVDnbE=; b=AlG4zhhn+jXdAaATPaYdb3qIk76ONRFxi0ME9wneWp/bdrHSEziYWS2A6X3foKIfJJ Er080EuLT6NRg5s91dybJ49giMBf/b20eN7B1Lo51Xk3mF3PitQbteYK825gCoZER/1x 0eXHlvnIaI24XbaXvTQdPVntcEvmkHWs1UdAeq3Ovst3gbhprPa4loKpe+NNTP7BKs4s CPKafr6hOllmK8NYT+iMA56yhAH2f/Acv1V4oPcZb7wnqkmLmAgvkyjFIrSMFVh57mP1 CRzumAgXGocRklsKdY7ejScQ+3BvyU18B0maTjuQTh6XSh3Fl/XYCcFZiwF2RHT1gfFc zW7w== X-Received: by 10.67.7.101 with SMTP id db5mr1943154pad.53.1448401411419; Tue, 24 Nov 2015 13:43:31 -0800 (PST) Received: from localhost.localdomain.localdomain (c-50-185-229-130.hsd1.ca.comcast.net. [50.185.229.130]) by smtp.gmail.com with ESMTPSA id 9sm16297885pfn.51.2015.11.24.13.43.30 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 24 Nov 2015 13:43:30 -0800 (PST) X-CudaMail-Envelope-Sender: zhouhan@gmail.com X-Barracuda-Apparent-Source-IP: 50.185.229.130 From: Han Zhou To: dev@openvswitch.org X-CudaMail-MID: CM-V3-1123058619 X-CudaMail-DTE: 112415 X-CudaMail-Originating-IP: 209.85.220.53 Date: Tue, 24 Nov 2015 13:43:20 -0800 X-ASG-Orig-Subj: [##CM-V3-1123058619##][PATCH v3] ovn: support ARP response for known IPs Message-Id: <1448401400-13171-1-git-send-email-zhouhan@gmail.com> X-Mailer: git-send-email 2.1.0 X-GBUdb-Analysis: 0, 209.85.220.53, Ugly c=0.495056 p=-0.42623 Source Normal X-MessageSniffer-Rules: 0-0-0-7845-c X-Barracuda-Connect: UNKNOWN[192.168.14.3] X-Barracuda-Start-Time: 1448401412 X-Barracuda-Encrypted: DHE-RSA-AES256-SHA X-Barracuda-URL: https://web.cudamail.com:443/cgi-mod/mark.cgi X-Virus-Scanned: by bsmtpd at cudamail.com X-Barracuda-BRTS-Status: 1 X-Barracuda-Spam-Score: 0.60 X-Barracuda-Spam-Status: No, SCORE=0.60 using per-user scores of TAG_LEVEL=3.5 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=4.0 tests=BSF_SC5_MJ1963, DKIM_SIGNED, RDNS_NONE X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.24692 Rule breakdown below pts rule name description ---- ---------------------- -------------------------------------------------- 0.00 DKIM_SIGNED Domain Keys Identified Mail: message has a signature 0.10 RDNS_NONE Delivered to trusted network by a host with no rDNS 0.50 BSF_SC5_MJ1963 Custom Rule MJ1963 Subject: [ovs-dev] [PATCH v3] ovn: support ARP response for known IPs X-BeenThere: dev@openvswitch.org X-Mailman-Version: 2.1.16 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: dev-bounces@openvswitch.org Sender: "dev" For lswitch ports with known IPs, ARP is responded directly from local ovn-controller to avoid flooding. Signed-off-by: Han Zhou --- Notes: v1->v2: remove the extra arg of xasprintf() v2->v3: update ovn-northd.8.xml to describe the new flows ovn/northd/ovn-northd.8.xml | 18 ++++++++++++++++++ ovn/northd/ovn-northd.c | 38 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 56 insertions(+) diff --git a/ovn/northd/ovn-northd.8.xml b/ovn/northd/ovn-northd.8.xml index e7dec72..2cd2818 100644 --- a/ovn/northd/ovn-northd.8.xml +++ b/ovn/northd/ovn-northd.8.xml @@ -204,6 +204,24 @@
  • + Priority-150 flows that matches ARP requests to each known IP address + A of logical port P, and respond ARP replies + directly with corresponding Ethernet address E: +
    +eth.dst = eth.src;
    +eth.src = E;
    +arp.op = 2; /* ARP reply. */
    +arp.tha = arp.sha;
    +arp.sha = E;
    +arp.tpa = arp.spa;
    +arp.spa = A;
    +outport = P;
    +inport = ""; /* Allow sending out inport. */
    +output;
    +        
    +
  • + +
  • A priority-100 flow that outputs all packets with an Ethernet broadcast or multicast eth.dst to the MC_FLOOD multicast group, which ovn-northd populates with all diff --git a/ovn/northd/ovn-northd.c b/ovn/northd/ovn-northd.c index 8fe0c2c..ec13171 100644 --- a/ovn/northd/ovn-northd.c +++ b/ovn/northd/ovn-northd.c @@ -1151,6 +1151,44 @@ build_lswitch_flows(struct hmap *datapaths, struct hmap *ports, ds_destroy(&match); } + /* Ingress table 3: Destination lookup, ARP reply for known IPs. + * (priority 150). */ + HMAP_FOR_EACH (op, key_node, ports) { + if (!op->nbs) { + continue; + } + + for (size_t i = 0; i < op->nbs->n_addresses; i++) { + struct eth_addr ea; + ovs_be32 ip; + + if (ovs_scan(op->nbs->addresses[i], + ETH_ADDR_SCAN_FMT" "IP_SCAN_FMT, + ETH_ADDR_SCAN_ARGS(ea), IP_SCAN_ARGS(&ip))) { + char *match = xasprintf( + "arp.tpa == "IP_FMT" && arp.op == 1", IP_ARGS(ip)); + char *actions = xasprintf( + "eth.dst = eth.src; " + "eth.src = "ETH_ADDR_FMT"; " + "arp.op = 2; /* ARP reply */ " + "arp.tha = arp.sha; " + "arp.sha = "ETH_ADDR_FMT"; " + "arp.tpa = arp.spa; " + "arp.spa = "IP_FMT"; " + "outport = inport; " + "inport = \"\"; /* Allow sending out inport. */ " + "output;", + ETH_ADDR_ARGS(ea), + ETH_ADDR_ARGS(ea), + IP_ARGS(ip)); + ovn_lflow_add(lflows, op->od, S_SWITCH_IN_L2_LKUP, 150, + match, actions); + free(match); + free(actions); + } + } + } + /* Ingress table 3: Destination lookup, broadcast and multicast handling * (priority 100). */ HMAP_FOR_EACH (op, key_node, ports) {