From patchwork Thu Sep 24 17:58:18 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Thomas F Herbert X-Patchwork-Id: 522478 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from archives.nicira.com (unknown [IPv6:2600:3c00::f03c:91ff:fe6e:bdf7]) by ozlabs.org (Postfix) with ESMTP id 270A214027C for ; Fri, 25 Sep 2015 03:59:14 +1000 (AEST) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b=chNK3uAH; dkim-atps=neutral Received: from archives.nicira.com (localhost [127.0.0.1]) by archives.nicira.com (Postfix) with ESMTP id 9111922C3BB; Thu, 24 Sep 2015 10:59:10 -0700 (PDT) X-Original-To: dev@openvswitch.org Delivered-To: dev@openvswitch.org Received: from mx3v1.cudamail.com (mx3.cudamail.com [64.34.241.5]) by archives.nicira.com (Postfix) with ESMTPS id 93DBB22C3BB for ; Thu, 24 Sep 2015 10:59:09 -0700 (PDT) Received: from bar3.cudamail.com (bar1 [192.168.15.1]) by mx3v1.cudamail.com (Postfix) with ESMTP id 0CA7C618CB6 for ; Thu, 24 Sep 2015 11:59:09 -0600 (MDT) X-ASG-Debug-ID: 1443117548-03dd7b6567800f0001-byXFYA Received: from mx3-pf3.cudamail.com ([192.168.14.3]) by bar3.cudamail.com with ESMTP id l0klrK1tyEA0AyKO (version=TLSv1 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Thu, 24 Sep 2015 11:59:08 -0600 (MDT) X-Barracuda-Envelope-From: thomasfherbert@gmail.com X-Barracuda-RBL-Trusted-Forwarder: 192.168.14.3 Received: from unknown (HELO mail-qg0-f43.google.com) (209.85.192.43) by mx3-pf3.cudamail.com with ESMTPS (RC4-SHA encrypted); 24 Sep 2015 17:59:06 -0000 Received-SPF: pass (mx3-pf3.cudamail.com: SPF record at _netblocks.google.com designates 209.85.192.43 as permitted sender) X-Barracuda-Apparent-Source-IP: 209.85.192.43 X-Barracuda-RBL-IP: 209.85.192.43 Received: by qgev79 with SMTP id v79so50707301qge.0 for ; Thu, 24 Sep 2015 10:59:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=Pr6+AkLmHxjLBZr+kRypoKo5g25Hu0cdDGMpXmcVKTY=; b=chNK3uAHJ3I6hwZwYB4PGAl+gu4pvnzO9v1VNDlnxw7KAWRMWeZGe1BDbGKETTGlhe tSh/Is30fIuM/fr25ZdDrJjAw7p6v2aCmkvr+p21izUnW4IECdTfdbc11dqpQbw+VBC6 6nIFMnVqgFwn1iKU+27a8fzMy2BXWf8qjAZ6c/QdYcO1sKKqEB5teAP8O6Df/OUXQS3j 1ZPtajCRZqGBn+REBgalm0hPGTPsNBxh+6Nalt8pPVrg9StmerRty/7HVQhSjTG7/kTr zpUhjHT3pV4TUKHNGpgDOdVswfGjMCpRL+7lVpjaltX5jiJnAcKrX1uFZE8+22YOwWTa VS+A== X-Received: by 10.140.151.140 with SMTP id 134mr1376928qhx.49.1443117545928; Thu, 24 Sep 2015 10:59:05 -0700 (PDT) Received: from localhost.localdomain (pool-173-53-26-105.rcmdva.fios.verizon.net. [173.53.26.105]) by smtp.gmail.com with ESMTPSA id s90sm4923089qki.46.2015.09.24.10.59.05 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 24 Sep 2015 10:59:05 -0700 (PDT) X-CudaMail-Envelope-Sender: thomasfherbert@gmail.com From: Thomas F Herbert To: netdev@vger.kernel.org, pshelar@nicira.com X-CudaMail-MID: CM-V3-923052756 X-CudaMail-DTE: 092415 X-CudaMail-Originating-IP: 209.85.192.43 Date: Thu, 24 Sep 2015 13:58:18 -0400 X-ASG-Orig-Subj: [##CM-V3-923052756##][PATCH 3/3] 802.1AD: Flow handling, actions, vlan parsing and netlink attributes Message-Id: <1443117498-19123-4-git-send-email-thomasfherbert@gmail.com> X-Mailer: git-send-email 2.4.3 In-Reply-To: <1443117498-19123-1-git-send-email-thomasfherbert@gmail.com> References: <1443117498-19123-1-git-send-email-thomasfherbert@gmail.com> X-GBUdb-Analysis: 0, 209.85.192.43, Ugly c=0.382685 p=-0.414634 Source Normal X-MessageSniffer-Rules: 0-0-0-21642-c X-Barracuda-Connect: UNKNOWN[192.168.14.3] X-Barracuda-Start-Time: 1443117548 X-Barracuda-Encrypted: DHE-RSA-AES256-SHA X-Barracuda-URL: https://web.cudamail.com:443/cgi-mod/mark.cgi X-Virus-Scanned: by bsmtpd at cudamail.com X-Barracuda-BRTS-Status: 1 X-Barracuda-Spam-Score: 0.60 X-Barracuda-Spam-Status: No, SCORE=0.60 using per-user scores of TAG_LEVEL=3.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=3.0 tests=BSF_SC5_MJ1963, DKIM_SIGNED, RDNS_NONE X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.22863 Rule breakdown below pts rule name description ---- ---------------------- -------------------------------------------------- 0.00 DKIM_SIGNED Domain Keys Identified Mail: message has a signature 0.10 RDNS_NONE Delivered to trusted network by a host with no rDNS 0.50 BSF_SC5_MJ1963 Custom Rule MJ1963 Cc: dev@openvswitch.org, therbert@redhat.com Subject: [ovs-dev] [PATCH 3/3] 802.1AD: Flow handling, actions, vlan parsing and netlink attributes X-BeenThere: dev@openvswitch.org X-Mailman-Version: 2.1.16 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: dev-bounces@openvswitch.org Sender: "dev" Add support for 802.1ad including the ability to push and pop double tagged vlans. Add support for 802.1ad to netlink parsing and flow conversion. Uses double nested encap attributes to represent double tagged vlan. Inner TPID encoded along with ctci in nested attributes. Signed-off-by: Thomas F Herbert --- net/openvswitch/flow.c | 83 +++++++++++++++++---- net/openvswitch/flow.h | 5 ++ net/openvswitch/flow_netlink.c | 166 ++++++++++++++++++++++++++++++++++++++--- 3 files changed, 230 insertions(+), 24 deletions(-) diff --git a/net/openvswitch/flow.c b/net/openvswitch/flow.c index c8db44a..db58e47 100644 --- a/net/openvswitch/flow.c +++ b/net/openvswitch/flow.c @@ -305,21 +305,77 @@ static bool icmp6hdr_ok(struct sk_buff *skb) static int parse_vlan(struct sk_buff *skb, struct sw_flow_key *key) { struct qtag_prefix { - __be16 eth_type; /* ETH_P_8021Q */ + __be16 eth_type; /* ETH_P_8021Q or ETH_P_8021AD */ __be16 tci; }; - struct qtag_prefix *qp; + struct qtag_prefix *qp = (struct qtag_prefix *)skb->data; - if (unlikely(skb->len < sizeof(struct qtag_prefix) + sizeof(__be16))) + struct qinqtag_prefix { + __be16 eth_type; /* ETH_P_8021Q or ETH_P_8021AD */ + __be16 tci; + __be16 inner_tpid; /* ETH_P_8021Q */ + __be16 ctci; + }; + + if (likely(skb_vlan_tag_present(skb))) { + key->eth.tci = htons(skb->vlan_tci); + + /* Case where upstream + * processing has already stripped the outer vlan tag. + */ + if (unlikely(skb->vlan_proto == htons(ETH_P_8021AD))) { + if (unlikely(skb->len < sizeof(struct qtag_prefix) + + sizeof(__be16))) { + key->eth.tci = 0; + return 0; + } + + if (unlikely(!pskb_may_pull(skb, + sizeof(struct qtag_prefix) + + sizeof(__be16)))) + return -ENOMEM; + + key->eth.cvlan.ctci = + qp->tci | htons(VLAN_TAG_PRESENT); + key->eth.cvlan.c_tpid = qp->eth_type; + + __skb_pull(skb, sizeof(struct qtag_prefix)); + } return 0; + } - if (unlikely(!pskb_may_pull(skb, sizeof(struct qtag_prefix) + - sizeof(__be16)))) - return -ENOMEM; - qp = (struct qtag_prefix *) skb->data; - key->eth.tci = qp->tci | htons(VLAN_TAG_PRESENT); - __skb_pull(skb, sizeof(struct qtag_prefix)); + if (qp->eth_type == htons(ETH_P_8021AD)) { + struct qinqtag_prefix *qinqp = + (struct qinqtag_prefix *)skb->data; + + if (unlikely(skb->len < sizeof(struct qinqtag_prefix) + + sizeof(__be16))) + return 0; + + if (unlikely(!pskb_may_pull(skb, sizeof(struct qinqtag_prefix) + + sizeof(__be16)))) + return -ENOMEM; + key->eth.tci = qinqp->tci | htons(VLAN_TAG_PRESENT); + key->eth.cvlan.ctci = qinqp->ctci | htons(VLAN_TAG_PRESENT); + key->eth.cvlan.c_tpid = qinqp->inner_tpid; + + __skb_pull(skb, sizeof(struct qinqtag_prefix)); + + return 0; + } + if (qp->eth_type == htons(ETH_P_8021Q)) { + if (unlikely(skb->len < sizeof(struct qtag_prefix) + + sizeof(__be16))) + return -ENOMEM; + + if (unlikely(!pskb_may_pull(skb, sizeof(struct qtag_prefix) + + sizeof(__be16)))) + return 0; + key->eth.tci = qp->tci | htons(VLAN_TAG_PRESENT); + + __skb_pull(skb, sizeof(struct qtag_prefix)); + } return 0; } @@ -481,11 +537,10 @@ static int key_extract(struct sk_buff *skb, struct sw_flow_key *key) */ key->eth.tci = 0; - if (skb_vlan_tag_present(skb)) - key->eth.tci = htons(skb->vlan_tci); - else if (eth->h_proto == htons(ETH_P_8021Q)) - if (unlikely(parse_vlan(skb, key))) - return -ENOMEM; + key->eth.cvlan.ctci = 0; + key->eth.cvlan.c_tpid = 0; + if (unlikely(parse_vlan(skb, key))) + return -ENOMEM; key->eth.type = parse_ethertype(skb); if (unlikely(key->eth.type == htons(0))) diff --git a/net/openvswitch/flow.h b/net/openvswitch/flow.h index fe527d2..2c491e8 100644 --- a/net/openvswitch/flow.h +++ b/net/openvswitch/flow.h @@ -69,6 +69,11 @@ struct sw_flow_key { u8 src[ETH_ALEN]; /* Ethernet source address. */ u8 dst[ETH_ALEN]; /* Ethernet destination address. */ __be16 tci; /* 0 if no VLAN, VLAN_TAG_PRESENT set otherwise. */ + struct { + __be16 c_tpid; /* Vlan DL_type 802.1q or 802.1ad */ + __be16 ctci; /* 0 if no CVLAN, VLAN_TAG_PRESENT */ + /* set otherwise. */ + } cvlan; __be16 type; /* Ethernet frame type. */ } eth; union { diff --git a/net/openvswitch/flow_netlink.c b/net/openvswitch/flow_netlink.c index c92d6a2..5fe415d 100644 --- a/net/openvswitch/flow_netlink.c +++ b/net/openvswitch/flow_netlink.c @@ -811,6 +811,27 @@ static int metadata_from_nlattrs(struct net *net, struct sw_flow_match *match, return 0; } +static int cust_vlan_from_nlattrs(struct sw_flow_match *match, + const struct nlattr *a[], + bool is_mask, bool log) +{ + __be16 ctci = 0; + __be16 c_tpid = 0; + + ctci = nla_get_be16(a[OVS_KEY_ATTR_VLAN]); + if (!(ctci & htons(VLAN_TAG_PRESENT))) { + if (is_mask) + OVS_NLERR(log, "VLAN CTCI mask does not have exact match for VLAN_TAG_PRESENT bit."); + else + OVS_NLERR(log, "VLAN CTCI does not have VLAN_TAG_PRESENT bit set."); + return -EINVAL; + } + c_tpid = nla_get_be16(a[OVS_KEY_ATTR_ETHERTYPE]); + SW_FLOW_KEY_PUT(match, eth.cvlan.c_tpid, c_tpid, is_mask); + SW_FLOW_KEY_PUT(match, eth.cvlan.ctci, ctci, is_mask); + return 0; +} + static int ovs_key_from_nlattrs(struct net *net, struct sw_flow_match *match, u64 attrs, const struct nlattr **a, bool is_mask, bool log) @@ -1064,6 +1085,80 @@ static void mask_set_nlattr(struct nlattr *attr, u8 val) nlattr_set(attr, val, ovs_key_lens); } +static int parse_vlan_from_nlattrs(const struct nlattr **nla, + struct sw_flow_match *match, + u64 *key_attrs, bool *ie_valid, + const struct nlattr **a, bool is_mask, + bool log) +{ + int err; + const struct nlattr *encap; + + *ie_valid = false; + if (!is_mask) { + u64 v_attrs = 0; + + err = parse_flow_nlattrs(*nla, a, &v_attrs, log); + if (err) + return err; + /* Another encap attribute here indicates + * the presence of a double tagged vlan. + */ + if ((v_attrs & (1 << OVS_KEY_ATTR_ETHERTYPE)) && + eth_type_vlan(nla_get_be16(a[OVS_KEY_ATTR_ETHERTYPE]))) { + if (!((v_attrs & (1ULL << OVS_KEY_ATTR_VLAN)) && + (v_attrs & (1ULL << OVS_KEY_ATTR_ENCAP)))) { + OVS_NLERR(log, "Invalid Inner VLAN frame"); + return -EINVAL; + } + encap = a[OVS_KEY_ATTR_ENCAP]; + v_attrs &= ~(1 << OVS_KEY_ATTR_ENCAP); + + err = cust_vlan_from_nlattrs(match, a, is_mask, log); + if (err) + return err; + *ie_valid = true; + *nla = encap; + + /* Insure that tci key attribute isn't + * overwritten by encapsulated customer tci. + * Ethertype is cleared because it is c_tpid. + */ + v_attrs &= ~(1 << OVS_KEY_ATTR_VLAN); + v_attrs &= ~(1 << OVS_KEY_ATTR_ETHERTYPE); + } + *key_attrs |= v_attrs; + + } else { + u64 mask_v_attrs = 0; + + err = parse_flow_mask_nlattrs(*nla, a, &mask_v_attrs, log); + if (err) + return err; + + if (mask_v_attrs & 1 << OVS_KEY_ATTR_ENCAP) { + if (!*ie_valid) { + OVS_NLERR(log, "Encap mask attribute is set for non-CVLAN frame."); + err = -EINVAL; + return err; + } + encap = a[OVS_KEY_ATTR_ENCAP]; + mask_v_attrs &= ~(1 << OVS_KEY_ATTR_ENCAP); + + err = cust_vlan_from_nlattrs(match, a, is_mask, log); + if (err) + return err; + *nla = encap; + + mask_v_attrs &= ~(1ULL << OVS_KEY_ATTR_VLAN); + mask_v_attrs &= ~(1ULL << OVS_KEY_ATTR_ETHERTYPE); + } + + *key_attrs |= mask_v_attrs; + } + return 0; +} + /** * ovs_nla_get_match - parses Netlink attributes into a flow key and * mask. In case the 'mask' is NULL, the flow is treated as exact match @@ -1091,6 +1186,7 @@ int ovs_nla_get_match(struct net *net, struct sw_flow_match *match, u64 key_attrs = 0; u64 mask_attrs = 0; bool encap_valid = false; + bool i_encap_valid = false; int err; err = parse_flow_nlattrs(nla_key, a, &key_attrs, log); @@ -1099,11 +1195,11 @@ int ovs_nla_get_match(struct net *net, struct sw_flow_match *match, if ((key_attrs & (1 << OVS_KEY_ATTR_ETHERNET)) && (key_attrs & (1 << OVS_KEY_ATTR_ETHERTYPE)) && - (nla_get_be16(a[OVS_KEY_ATTR_ETHERTYPE]) == htons(ETH_P_8021Q))) { + eth_type_vlan(nla_get_be16(a[OVS_KEY_ATTR_ETHERTYPE]))) { __be16 tci; - if (!((key_attrs & (1 << OVS_KEY_ATTR_VLAN)) && - (key_attrs & (1 << OVS_KEY_ATTR_ENCAP)))) { + if (!((key_attrs & (1ULL << OVS_KEY_ATTR_VLAN)) && + (key_attrs & (1ULL << OVS_KEY_ATTR_ENCAP)))) { OVS_NLERR(log, "Invalid Vlan frame."); return -EINVAL; } @@ -1115,9 +1211,19 @@ int ovs_nla_get_match(struct net *net, struct sw_flow_match *match, encap_valid = true; if (tci & htons(VLAN_TAG_PRESENT)) { - err = parse_flow_nlattrs(encap, a, &key_attrs, log); + err = parse_vlan_from_nlattrs(&encap, match, &key_attrs, + &i_encap_valid, a, false, + log); if (err) return err; + + if (i_encap_valid) { + err = parse_flow_nlattrs(encap, a, + &key_attrs, + log); + if (err) + return err; + } } else if (!tci) { /* Corner case for truncated 802.1Q header. */ if (nla_len(encap)) { @@ -1188,10 +1294,21 @@ int ovs_nla_get_match(struct net *net, struct sw_flow_match *match, if (eth_type == htons(0xffff)) { mask_attrs &= ~(1 << OVS_KEY_ATTR_ETHERTYPE); encap = a[OVS_KEY_ATTR_ENCAP]; - err = parse_flow_mask_nlattrs(encap, a, - &mask_attrs, log); + err = parse_vlan_from_nlattrs(&encap, match, + &mask_attrs, + &i_encap_valid, + a, true, log); if (err) goto free_newmask; + + if (i_encap_valid) { + err = + parse_flow_mask_nlattrs(encap, a, + &mask_attrs, + log); + if (err) + goto free_newmask; + } } else { OVS_NLERR(log, "VLAN frames must have an exact match on the TPID (mask=%x).", ntohs(eth_type)); @@ -1320,6 +1437,7 @@ static int __ovs_nla_put_key(const struct sw_flow_key *swkey, { struct ovs_key_ethernet *eth_key; struct nlattr *nla, *encap; + struct nlattr *in_encap = NULL; if (nla_put_u32(skb, OVS_KEY_ATTR_RECIRC_ID, output->recirc_id)) goto nla_put_failure; @@ -1368,17 +1486,42 @@ static int __ovs_nla_put_key(const struct sw_flow_key *swkey, ether_addr_copy(eth_key->eth_src, output->eth.src); ether_addr_copy(eth_key->eth_dst, output->eth.dst); - if (swkey->eth.tci || swkey->eth.type == htons(ETH_P_8021Q)) { + if (swkey->eth.tci || eth_type_vlan(swkey->eth.type)) { __be16 eth_type; - eth_type = !is_mask ? htons(ETH_P_8021Q) : htons(0xffff); + + if (swkey->eth.cvlan.ctci || + eth_type_vlan(swkey->eth.cvlan.c_tpid)) + eth_type = !is_mask ? htons(ETH_P_8021AD) : + htons(0xffff); + else + eth_type = !is_mask ? htons(ETH_P_8021Q) : + htons(0xffff); + if (nla_put_be16(skb, OVS_KEY_ATTR_ETHERTYPE, eth_type) || nla_put_be16(skb, OVS_KEY_ATTR_VLAN, output->eth.tci)) goto nla_put_failure; encap = nla_nest_start(skb, OVS_KEY_ATTR_ENCAP); if (!swkey->eth.tci) goto unencap; - } else + if (swkey->eth.cvlan.ctci || eth_type_vlan(swkey->eth.type)) { + __be16 eth_type; + + /* Customer tci is nested but uses same key attribute. + */ + eth_type = !is_mask ? htons(ETH_P_8021Q) : + htons(0xffff); + if (nla_put_be16(skb, OVS_KEY_ATTR_ETHERTYPE, + eth_type) || + nla_put_be16(skb, OVS_KEY_ATTR_VLAN, + output->eth.cvlan.ctci)) + goto nla_put_failure; + in_encap = nla_nest_start(skb, OVS_KEY_ATTR_ENCAP); + if (!swkey->eth.cvlan.ctci) + goto unencap; + } + } else { encap = NULL; + } if (swkey->eth.type == htons(ETH_P_802_2)) { /* @@ -1525,6 +1668,8 @@ static int __ovs_nla_put_key(const struct sw_flow_key *swkey, unencap: if (encap) nla_nest_end(skb, encap); + if (in_encap) + nla_nest_end(skb, in_encap); return 0; @@ -2174,7 +2319,8 @@ static int __ovs_nla_copy_actions(struct net *net, const struct nlattr *attr, case OVS_ACTION_ATTR_PUSH_VLAN: vlan = nla_data(a); - if (vlan->vlan_tpid != htons(ETH_P_8021Q)) + if ((vlan->vlan_tpid != htons(ETH_P_8021Q)) && + (vlan->vlan_tpid != htons(ETH_P_8021AD))) return -EINVAL; if (!(vlan->vlan_tci & htons(VLAN_TAG_PRESENT))) return -EINVAL;