From patchwork Fri Aug 25 22:51:14 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Yi-Hung Wei X-Patchwork-Id: 806055 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=openvswitch.org (client-ip=140.211.169.12; helo=mail.linuxfoundation.org; envelope-from=ovs-dev-bounces@openvswitch.org; receiver=) Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="daAaUES/"; dkim-atps=neutral Received: from mail.linuxfoundation.org (mail.linuxfoundation.org [140.211.169.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3xfGgC5PDjz9t43 for ; Sat, 26 Aug 2017 08:53:59 +1000 (AEST) Received: from mail.linux-foundation.org (localhost [127.0.0.1]) by mail.linuxfoundation.org (Postfix) with ESMTP id D1CC1B59; Fri, 25 Aug 2017 22:51:40 +0000 (UTC) X-Original-To: dev@openvswitch.org Delivered-To: ovs-dev@mail.linuxfoundation.org Received: from smtp1.linuxfoundation.org (smtp1.linux-foundation.org [172.17.192.35]) by mail.linuxfoundation.org (Postfix) with ESMTPS id E571AACC for ; Fri, 25 Aug 2017 22:51:34 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.7.6 Received: from mail-pg0-f66.google.com (mail-pg0-f66.google.com [74.125.83.66]) by smtp1.linuxfoundation.org (Postfix) with ESMTPS id 8B16687 for ; Fri, 25 Aug 2017 22:51:34 +0000 (UTC) Received: by mail-pg0-f66.google.com with SMTP id q16so1570471pgc.0 for ; Fri, 25 Aug 2017 15:51:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=K1CHy538iVrR99FFCGnjNED3g333Q90PbeZyTuM6yqc=; b=daAaUES/7HtSwAuF5Ss7373N95ei6j0Ok1YzqeKVrwb0zrsyO3x8yysfxQvFyXQZ+u 4rEs1cGOOKO0J1u1um+oTlV2/Fch8kS8/d0BwuH6sfMLqV4FJb2OacySk2XzHIKVDo8I iKGxAW6+ruRH3yQxxvUgvAzRkthrpq9ML+4ZupmfYYjWdWuJQrfGuPI5JWy7ciKRW02g rOeg7/B8g/tEaWswvabA+qoc4AvvwweSbGOjA0z5ywBbEQodGYLLdk8yeEv3cGoesfQs FWQv9JGZIXzAiXITpKUvx6DjM9EZ6tNil0I3SYBpHsedInW+wst6UA2Ns7o1+Vn5euyk B1YA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=K1CHy538iVrR99FFCGnjNED3g333Q90PbeZyTuM6yqc=; b=kwkaq6/dEa9+pb03hRm0UYOkpwSBmm0P7xlbga65zBfMlb3leMHW/7Vm3bFqOMV1v1 zTJV/oGtONuFDvT7GBPnWV0do57jcbZ/4acS7Wf80bnouWYbcZK29UEXtezCYQXHL8BM /VKpIGva3RQ7O6VJ4g6P0T8VOHTc1mDgcBNHdVIM/+4iENEmlZR7dZhqTY9XnkvL+OLc I+VIZGl+fj6yWkVdiQLoO4J1GEr+yc8cj4tx8LqdEDwxskGGh7Z8sFzw4lOWAjOW+iTu jQpmnImQ5Az9equtM9IWKxgW3Hr8JFgbqhMmIzivwWNX0z9i0l1Q2oCdUYFx/53Woxdc rAEQ== X-Gm-Message-State: AHYfb5jBdakm/mVEvulJksqnLqNP/7Mm8GYUrR4drt4hBjRaP/jqrfcb 2GmBY0s5L0k4+C92A+c= X-Received: by 10.84.218.131 with SMTP id r3mr5148pli.235.1503701493877; Fri, 25 Aug 2017 15:51:33 -0700 (PDT) Received: from vm-01.vmware.com ([208.91.2.1]) by smtp.gmail.com with ESMTPSA id b68sm12678154pfd.33.2017.08.25.15.51.33 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 25 Aug 2017 15:51:33 -0700 (PDT) From: Yi-Hung Wei To: dev@openvswitch.org Date: Fri, 25 Aug 2017 15:51:14 -0700 Message-Id: <1503701479-43894-5-git-send-email-yihung.wei@gmail.com> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1503701479-43894-1-git-send-email-yihung.wei@gmail.com> References: <1503701479-43894-1-git-send-email-yihung.wei@gmail.com> X-Spam-Status: No, score=0.4 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE,RCVD_IN_SORBS_SPAM autolearn=disabled version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on smtp1.linux-foundation.org Subject: [ovs-dev] [PATCH 4/9] ofproto/trace: Query ct_state for conntrack recirc from DP X-BeenThere: ovs-dev@openvswitch.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: ovs-dev-bounces@openvswitch.org Errors-To: ovs-dev-bounces@openvswitch.org Instead of using fixed default conntrack state 'trk|new' in ofproto/trace for conntrack recirculation, this patch queries the conntrack state from datapath using ct_dpif_get_info(). Signed-off-by: Yi-Hung Wei --- lib/ct-dpif.c | 42 ++++++++++++++++++++++++++++++++++++++ lib/ct-dpif.h | 2 ++ ofproto/ofproto-dpif-trace.c | 48 ++++++++++++++++++++++++++++++++++---------- 3 files changed, 81 insertions(+), 11 deletions(-) diff --git a/lib/ct-dpif.c b/lib/ct-dpif.c index 3e6f4cbe9be2..91388dd6681b 100644 --- a/lib/ct-dpif.c +++ b/lib/ct-dpif.c @@ -442,3 +442,45 @@ ct_dpif_format_tcp_stat(struct ds * ds, int tcp_state, int conn_per_state) ds_put_cstr(ds, "]"); ds_put_format(ds, "=%u", conn_per_state); } + +/* Converts a given 'flow' to conntrack 'tuple'. Returns true if the + * conversion is valid. Returns false and reports error in 'ds', if + * the type of the connection is not supported. */ +bool +ct_dpif_flow_to_tuple(struct flow *flow, struct ct_dpif_tuple *tuple, + struct ds *ds) +{ + memset(tuple, 0, sizeof *tuple); + + if (flow->dl_type == htons(ETH_TYPE_IP)) { + tuple->l3_type = AF_INET; + memcpy(&tuple->src.in, &flow->nw_src, sizeof tuple->src.in); + memcpy(&tuple->dst.in, &flow->nw_dst, sizeof tuple->dst.in); + } else if (flow->dl_type == htons(ETH_TYPE_IPV6)) { + tuple->l3_type = AF_INET6; + memcpy(&tuple->src.in6, &flow->ipv6_src, sizeof tuple->src.in6); + memcpy(&tuple->dst.in6, &flow->ipv6_dst, sizeof tuple->dst.in6); + } else { + ds_put_format(ds, + "Failed to convert flow to conntrack tuple " + "(Unsupported dl_type: %"PRIu16").", + ntohs(flow->dl_type)); + return false; + } + + tuple->ip_proto = flow->nw_proto; + + /* Conntrack does support ICMP, however, we can not get ICMP id + * from 'flow'. */ + if (flow->nw_proto == IPPROTO_TCP || flow->nw_proto == IPPROTO_UDP) { + tuple->src_port = flow->tp_src; + tuple->dst_port = flow->tp_dst; + } else { + ds_put_format(ds, + "Failed to convert flow to conntrack tuple " + "(Unsupported ip_proto: %"PRIu8").", flow->nw_proto); + return false; + } + + return true; +} diff --git a/lib/ct-dpif.h b/lib/ct-dpif.h index 0c82fb022f2b..f4ca07b5e776 100644 --- a/lib/ct-dpif.h +++ b/lib/ct-dpif.h @@ -17,6 +17,7 @@ #ifndef CT_DPIF_H #define CT_DPIF_H +#include "flow.h" #include "openvswitch/types.h" #include "packets.h" @@ -209,5 +210,6 @@ void ct_dpif_format_entry(const struct ct_dpif_entry *, struct ds *, void ct_dpif_format_tuple(struct ds *, const struct ct_dpif_tuple *); uint8_t ct_dpif_coalesce_tcp_state(uint8_t state); void ct_dpif_format_tcp_stat(struct ds *, int, int); +bool ct_dpif_flow_to_tuple(struct flow *, struct ct_dpif_tuple *, struct ds *); #endif /* CT_DPIF_H */ diff --git a/ofproto/ofproto-dpif-trace.c b/ofproto/ofproto-dpif-trace.c index c3c929520a2d..a86cf211803e 100644 --- a/ofproto/ofproto-dpif-trace.c +++ b/ofproto/ofproto-dpif-trace.c @@ -18,7 +18,9 @@ #include "ofproto-dpif-trace.h" +#include #include "conntrack.h" +#include "ct-dpif.h" #include "dpif.h" #include "ofproto-dpif-xlate.h" #include "openvswitch/ofp-parse.h" @@ -645,20 +647,44 @@ ofproto_trace(struct ofproto_dpif *ofproto, const struct flow *flow, recirc_node->recirc_id); if (recirc_node->type == OFT_RECIRC_CONNTRACK) { - uint32_t ct_state; + struct ct_dpif_info ct_info; + memset(&ct_info, 0, sizeof(ct_info)); + if (ovs_list_is_empty(next_ct_states)) { - ct_state = CS_TRACKED | CS_NEW; - ds_put_cstr(output, " - resume conntrack with default " - "ct_state=trk|new (use --ct-next to customize)"); + struct ds errs = DS_EMPTY_INITIALIZER; + struct ct_dpif_tuple tuple; + int err, indent_size; + + indent_size = 14 + recirc_node->recirc_id / 16; + ds_put_cstr(output, " - resume conntrack with conntrack info" + "from datapath\n"); + ds_put_char_multiple(output, ' ', indent_size); + + if (ct_dpif_flow_to_tuple(&recirc_node->flow, &tuple, &errs)) { + err = ct_dpif_get_info(ofproto->backer->dpif, &tuple, + recirc_node->flow.ct_zone, + &ct_info); + if (err) { + ds_put_format(&errs, "%s", ovs_strerror(err)); + } + } + + if (errs.length) { + ct_info.ct_state = CS_TRACKED | CS_NEW; + ds_put_format(output, "Failed to query ct_state from " + "datapath (%s).\n", ds_cstr(&errs)); + ds_put_char_multiple(output, ' ', indent_size); + ds_put_format(output, "Use default ct_state = trk|new."); + } else { + ct_dpif_format_info(&ct_info, output); + } + ds_put_format(output, " (use --ct-next to customize)"); + ds_destroy(&errs); } else { - oftrace_pop_ct_state(next_ct_states, &ct_state); - struct ds s = DS_EMPTY_INITIALIZER; - format_flags(&s, ct_state_to_string, ct_state, '|'); - ds_put_format(output, " - resume conntrack with ct_state=%s", - ds_cstr(&s)); - ds_destroy(&s); + oftrace_pop_ct_state(next_ct_states, &ct_info.ct_state); + ct_dpif_format_info(&ct_info, output); } - recirc_node->flow.ct_state = ct_state; + recirc_node->flow.ct_state = ct_info.ct_state; } ds_put_char(output, '\n'); ds_put_char_multiple(output, '=', 79);