geneve: allow user to specify TTL for tunnel frames
[linux-2.6-block.git] / drivers / net / geneve.c
CommitLineData
2d07dc79
JL
1/*
2 * GENEVE: Generic Network Virtualization Encapsulation
3 *
4 * Copyright (c) 2015 Red Hat, Inc.
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License version 2 as
8 * published by the Free Software Foundation.
9 */
10
11#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
12
13#include <linux/kernel.h>
14#include <linux/module.h>
15#include <linux/netdevice.h>
16#include <linux/etherdevice.h>
17#include <linux/hash.h>
18#include <net/rtnetlink.h>
19#include <net/geneve.h>
20
21#define GENEVE_NETDEV_VER "0.6"
22
23#define GENEVE_UDP_PORT 6081
24
25#define GENEVE_N_VID (1u << 24)
26#define GENEVE_VID_MASK (GENEVE_N_VID - 1)
27
28#define VNI_HASH_BITS 10
29#define VNI_HASH_SIZE (1<<VNI_HASH_BITS)
30
31static bool log_ecn_error = true;
32module_param(log_ecn_error, bool, 0644);
33MODULE_PARM_DESC(log_ecn_error, "Log packets received with corrupted ECN");
34
35/* per-network namespace private data for this module */
36struct geneve_net {
37 struct list_head geneve_list;
38 struct hlist_head vni_list[VNI_HASH_SIZE];
39};
40
41/* Pseudo network device */
42struct geneve_dev {
43 struct hlist_node hlist; /* vni hash table */
44 struct net *net; /* netns for packet i/o */
45 struct net_device *dev; /* netdev for geneve tunnel */
46 struct geneve_sock *sock; /* socket used for geneve tunnel */
8760ce58
JL
47 u8 vni[3]; /* virtual network ID for tunnel */
48 u8 ttl; /* TTL override */
2d07dc79
JL
49 struct sockaddr_in remote; /* IPv4 address for link partner */
50 struct list_head next; /* geneve's per namespace list */
51};
52
53static int geneve_net_id;
54
55static inline __u32 geneve_net_vni_hash(u8 vni[3])
56{
57 __u32 vnid;
58
59 vnid = (vni[0] << 16) | (vni[1] << 8) | vni[2];
60 return hash_32(vnid, VNI_HASH_BITS);
61}
62
63/* geneve receive/decap routine */
64static void geneve_rx(struct geneve_sock *gs, struct sk_buff *skb)
65{
66 struct genevehdr *gnvh = geneve_hdr(skb);
67 struct geneve_dev *dummy, *geneve = NULL;
68 struct geneve_net *gn;
69 struct iphdr *iph = NULL;
70 struct pcpu_sw_netstats *stats;
71 struct hlist_head *vni_list_head;
72 int err = 0;
73 __u32 hash;
74
75 iph = ip_hdr(skb); /* Still outer IP header... */
76
77 gn = gs->rcv_data;
78
79 /* Find the device for this VNI */
80 hash = geneve_net_vni_hash(gnvh->vni);
81 vni_list_head = &gn->vni_list[hash];
82 hlist_for_each_entry_rcu(dummy, vni_list_head, hlist) {
83 if (!memcmp(gnvh->vni, dummy->vni, sizeof(dummy->vni)) &&
84 iph->saddr == dummy->remote.sin_addr.s_addr) {
85 geneve = dummy;
86 break;
87 }
88 }
89 if (!geneve)
90 goto drop;
91
92 /* Drop packets w/ critical options,
93 * since we don't support any...
94 */
95 if (gnvh->critical)
96 goto drop;
97
98 skb_reset_mac_header(skb);
99 skb_scrub_packet(skb, !net_eq(geneve->net, dev_net(geneve->dev)));
100 skb->protocol = eth_type_trans(skb, geneve->dev);
101 skb_postpull_rcsum(skb, eth_hdr(skb), ETH_HLEN);
102
103 /* Ignore packet loops (and multicast echo) */
104 if (ether_addr_equal(eth_hdr(skb)->h_source, geneve->dev->dev_addr))
105 goto drop;
106
107 skb_reset_network_header(skb);
108
109 iph = ip_hdr(skb); /* Now inner IP header... */
110 err = IP_ECN_decapsulate(iph, skb);
111
112 if (unlikely(err)) {
113 if (log_ecn_error)
114 net_info_ratelimited("non-ECT from %pI4 with TOS=%#x\n",
115 &iph->saddr, iph->tos);
116 if (err > 1) {
117 ++geneve->dev->stats.rx_frame_errors;
118 ++geneve->dev->stats.rx_errors;
119 goto drop;
120 }
121 }
122
123 stats = this_cpu_ptr(geneve->dev->tstats);
124 u64_stats_update_begin(&stats->syncp);
125 stats->rx_packets++;
126 stats->rx_bytes += skb->len;
127 u64_stats_update_end(&stats->syncp);
128
129 netif_rx(skb);
130
131 return;
132drop:
133 /* Consume bad packet */
134 kfree_skb(skb);
135}
136
137/* Setup stats when device is created */
138static int geneve_init(struct net_device *dev)
139{
140 dev->tstats = netdev_alloc_pcpu_stats(struct pcpu_sw_netstats);
141 if (!dev->tstats)
142 return -ENOMEM;
143
144 return 0;
145}
146
147static void geneve_uninit(struct net_device *dev)
148{
149 free_percpu(dev->tstats);
150}
151
152static int geneve_open(struct net_device *dev)
153{
154 struct geneve_dev *geneve = netdev_priv(dev);
155 struct net *net = geneve->net;
156 struct geneve_net *gn = net_generic(geneve->net, geneve_net_id);
157 struct geneve_sock *gs;
158
159 gs = geneve_sock_add(net, htons(GENEVE_UDP_PORT), geneve_rx, gn,
160 false, false);
161 if (IS_ERR(gs))
162 return PTR_ERR(gs);
163
164 geneve->sock = gs;
165
166 return 0;
167}
168
169static int geneve_stop(struct net_device *dev)
170{
171 struct geneve_dev *geneve = netdev_priv(dev);
172 struct geneve_sock *gs = geneve->sock;
173
174 geneve_sock_release(gs);
175
176 return 0;
177}
178
179static netdev_tx_t geneve_xmit(struct sk_buff *skb, struct net_device *dev)
180{
181 struct geneve_dev *geneve = netdev_priv(dev);
182 struct geneve_sock *gs = geneve->sock;
183 struct rtable *rt = NULL;
184 const struct iphdr *iip; /* interior IP header */
185 struct flowi4 fl4;
186 int err;
187 __be16 sport;
8760ce58 188 __u8 tos, ttl;
2d07dc79
JL
189
190 iip = ip_hdr(skb);
191
192 skb_reset_mac_header(skb);
193
194 /* TODO: port min/max limits should be configurable */
195 sport = udp_flow_src_port(dev_net(dev), skb, 0, 0, true);
196
197 memset(&fl4, 0, sizeof(fl4));
198 fl4.daddr = geneve->remote.sin_addr.s_addr;
199 rt = ip_route_output_key(geneve->net, &fl4);
200 if (IS_ERR(rt)) {
201 netdev_dbg(dev, "no route to %pI4\n", &fl4.daddr);
202 dev->stats.tx_carrier_errors++;
203 goto tx_error;
204 }
205 if (rt->dst.dev == dev) { /* is this necessary? */
206 netdev_dbg(dev, "circular route to %pI4\n", &fl4.daddr);
207 dev->stats.collisions++;
208 goto rt_tx_error;
209 }
210
8760ce58 211 /* TODO: tos should be configurable */
2d07dc79
JL
212
213 tos = ip_tunnel_ecn_encap(0, iip, skb);
214
8760ce58
JL
215 ttl = geneve->ttl;
216 if (!ttl && IN_MULTICAST(ntohl(fl4.daddr)))
2d07dc79
JL
217 ttl = 1;
218
219 ttl = ttl ? : ip4_dst_hoplimit(&rt->dst);
220
221 /* no need to handle local destination and encap bypass...yet... */
222
223 err = geneve_xmit_skb(gs, rt, skb, fl4.saddr, fl4.daddr,
224 tos, ttl, 0, sport, htons(GENEVE_UDP_PORT), 0,
225 geneve->vni, 0, NULL, false,
226 !net_eq(geneve->net, dev_net(geneve->dev)));
227 if (err < 0)
228 ip_rt_put(rt);
229
230 iptunnel_xmit_stats(err, &dev->stats, dev->tstats);
231
232 return NETDEV_TX_OK;
233
234rt_tx_error:
235 ip_rt_put(rt);
236tx_error:
237 dev->stats.tx_errors++;
238 dev_kfree_skb(skb);
239 return NETDEV_TX_OK;
240}
241
242static const struct net_device_ops geneve_netdev_ops = {
243 .ndo_init = geneve_init,
244 .ndo_uninit = geneve_uninit,
245 .ndo_open = geneve_open,
246 .ndo_stop = geneve_stop,
247 .ndo_start_xmit = geneve_xmit,
248 .ndo_get_stats64 = ip_tunnel_get_stats64,
249 .ndo_change_mtu = eth_change_mtu,
250 .ndo_validate_addr = eth_validate_addr,
251 .ndo_set_mac_address = eth_mac_addr,
252};
253
254static void geneve_get_drvinfo(struct net_device *dev,
255 struct ethtool_drvinfo *drvinfo)
256{
257 strlcpy(drvinfo->version, GENEVE_NETDEV_VER, sizeof(drvinfo->version));
258 strlcpy(drvinfo->driver, "geneve", sizeof(drvinfo->driver));
259}
260
261static const struct ethtool_ops geneve_ethtool_ops = {
262 .get_drvinfo = geneve_get_drvinfo,
263 .get_link = ethtool_op_get_link,
264};
265
266/* Info for udev, that this is a virtual tunnel endpoint */
267static struct device_type geneve_type = {
268 .name = "geneve",
269};
270
271/* Initialize the device structure. */
272static void geneve_setup(struct net_device *dev)
273{
274 ether_setup(dev);
275
276 dev->netdev_ops = &geneve_netdev_ops;
277 dev->ethtool_ops = &geneve_ethtool_ops;
278 dev->destructor = free_netdev;
279
280 SET_NETDEV_DEVTYPE(dev, &geneve_type);
281
282 dev->tx_queue_len = 0;
283 dev->features |= NETIF_F_LLTX;
284 dev->features |= NETIF_F_SG | NETIF_F_HW_CSUM;
285 dev->features |= NETIF_F_RXCSUM;
286 dev->features |= NETIF_F_GSO_SOFTWARE;
287
288 dev->vlan_features = dev->features;
289 dev->features |= NETIF_F_HW_VLAN_CTAG_TX | NETIF_F_HW_VLAN_STAG_TX;
290
291 dev->hw_features |= NETIF_F_SG | NETIF_F_HW_CSUM | NETIF_F_RXCSUM;
292 dev->hw_features |= NETIF_F_GSO_SOFTWARE;
293 dev->hw_features |= NETIF_F_HW_VLAN_CTAG_TX | NETIF_F_HW_VLAN_STAG_TX;
294
295 netif_keep_dst(dev);
296 dev->priv_flags |= IFF_LIVE_ADDR_CHANGE;
297}
298
299static const struct nla_policy geneve_policy[IFLA_GENEVE_MAX + 1] = {
300 [IFLA_GENEVE_ID] = { .type = NLA_U32 },
301 [IFLA_GENEVE_REMOTE] = { .len = FIELD_SIZEOF(struct iphdr, daddr) },
8760ce58 302 [IFLA_GENEVE_TTL] = { .type = NLA_U8 },
2d07dc79
JL
303};
304
305static int geneve_validate(struct nlattr *tb[], struct nlattr *data[])
306{
307 if (tb[IFLA_ADDRESS]) {
308 if (nla_len(tb[IFLA_ADDRESS]) != ETH_ALEN)
309 return -EINVAL;
310
311 if (!is_valid_ether_addr(nla_data(tb[IFLA_ADDRESS])))
312 return -EADDRNOTAVAIL;
313 }
314
315 if (!data)
316 return -EINVAL;
317
318 if (data[IFLA_GENEVE_ID]) {
319 __u32 vni = nla_get_u32(data[IFLA_GENEVE_ID]);
320
321 if (vni >= GENEVE_VID_MASK)
322 return -ERANGE;
323 }
324
325 return 0;
326}
327
328static int geneve_newlink(struct net *net, struct net_device *dev,
329 struct nlattr *tb[], struct nlattr *data[])
330{
331 struct geneve_net *gn = net_generic(net, geneve_net_id);
332 struct geneve_dev *dummy, *geneve = netdev_priv(dev);
333 struct hlist_head *vni_list_head;
334 struct sockaddr_in remote; /* IPv4 address for link partner */
335 __u32 vni, hash;
336 int err;
337
338 if (!data[IFLA_GENEVE_ID] || !data[IFLA_GENEVE_REMOTE])
339 return -EINVAL;
340
341 geneve->net = net;
342 geneve->dev = dev;
343
344 vni = nla_get_u32(data[IFLA_GENEVE_ID]);
345 geneve->vni[0] = (vni & 0x00ff0000) >> 16;
346 geneve->vni[1] = (vni & 0x0000ff00) >> 8;
347 geneve->vni[2] = vni & 0x000000ff;
348
349 geneve->remote.sin_addr.s_addr =
350 nla_get_in_addr(data[IFLA_GENEVE_REMOTE]);
351 if (IN_MULTICAST(ntohl(geneve->remote.sin_addr.s_addr)))
352 return -EINVAL;
353
354 remote = geneve->remote;
355 hash = geneve_net_vni_hash(geneve->vni);
356 vni_list_head = &gn->vni_list[hash];
357 hlist_for_each_entry_rcu(dummy, vni_list_head, hlist) {
358 if (!memcmp(geneve->vni, dummy->vni, sizeof(dummy->vni)) &&
359 !memcmp(&remote, &dummy->remote, sizeof(dummy->remote)))
360 return -EBUSY;
361 }
362
363 if (tb[IFLA_ADDRESS] == NULL)
364 eth_hw_addr_random(dev);
365
366 err = register_netdevice(dev);
367 if (err)
368 return err;
369
8760ce58
JL
370 if (data[IFLA_GENEVE_TTL])
371 geneve->ttl = nla_get_u8(data[IFLA_GENEVE_TTL]);
372
2d07dc79
JL
373 list_add(&geneve->next, &gn->geneve_list);
374
375 hlist_add_head_rcu(&geneve->hlist, &gn->vni_list[hash]);
376
377 return 0;
378}
379
380static void geneve_dellink(struct net_device *dev, struct list_head *head)
381{
382 struct geneve_dev *geneve = netdev_priv(dev);
383
384 if (!hlist_unhashed(&geneve->hlist))
385 hlist_del_rcu(&geneve->hlist);
386
387 list_del(&geneve->next);
388 unregister_netdevice_queue(dev, head);
389}
390
391static size_t geneve_get_size(const struct net_device *dev)
392{
393 return nla_total_size(sizeof(__u32)) + /* IFLA_GENEVE_ID */
394 nla_total_size(sizeof(struct in_addr)) + /* IFLA_GENEVE_REMOTE */
8760ce58 395 nla_total_size(sizeof(__u8)) + /* IFLA_GENEVE_TTL */
2d07dc79
JL
396 0;
397}
398
399static int geneve_fill_info(struct sk_buff *skb, const struct net_device *dev)
400{
401 struct geneve_dev *geneve = netdev_priv(dev);
402 __u32 vni;
403
404 vni = (geneve->vni[0] << 16) | (geneve->vni[1] << 8) | geneve->vni[2];
405 if (nla_put_u32(skb, IFLA_GENEVE_ID, vni))
406 goto nla_put_failure;
407
408 if (nla_put_in_addr(skb, IFLA_GENEVE_REMOTE,
409 geneve->remote.sin_addr.s_addr))
410 goto nla_put_failure;
411
8760ce58
JL
412 if (nla_put_u8(skb, IFLA_GENEVE_TTL, geneve->ttl))
413 goto nla_put_failure;
414
2d07dc79
JL
415 return 0;
416
417nla_put_failure:
418 return -EMSGSIZE;
419}
420
421static struct rtnl_link_ops geneve_link_ops __read_mostly = {
422 .kind = "geneve",
423 .maxtype = IFLA_GENEVE_MAX,
424 .policy = geneve_policy,
425 .priv_size = sizeof(struct geneve_dev),
426 .setup = geneve_setup,
427 .validate = geneve_validate,
428 .newlink = geneve_newlink,
429 .dellink = geneve_dellink,
430 .get_size = geneve_get_size,
431 .fill_info = geneve_fill_info,
432};
433
434static __net_init int geneve_init_net(struct net *net)
435{
436 struct geneve_net *gn = net_generic(net, geneve_net_id);
437 unsigned int h;
438
439 INIT_LIST_HEAD(&gn->geneve_list);
440
441 for (h = 0; h < VNI_HASH_SIZE; ++h)
442 INIT_HLIST_HEAD(&gn->vni_list[h]);
443
444 return 0;
445}
446
447static void __net_exit geneve_exit_net(struct net *net)
448{
449 struct geneve_net *gn = net_generic(net, geneve_net_id);
450 struct geneve_dev *geneve, *next;
451 struct net_device *dev, *aux;
452 LIST_HEAD(list);
453
454 rtnl_lock();
455
456 /* gather any geneve devices that were moved into this ns */
457 for_each_netdev_safe(net, dev, aux)
458 if (dev->rtnl_link_ops == &geneve_link_ops)
459 unregister_netdevice_queue(dev, &list);
460
461 /* now gather any other geneve devices that were created in this ns */
462 list_for_each_entry_safe(geneve, next, &gn->geneve_list, next) {
463 /* If geneve->dev is in the same netns, it was already added
464 * to the list by the previous loop.
465 */
466 if (!net_eq(dev_net(geneve->dev), net))
467 unregister_netdevice_queue(geneve->dev, &list);
468 }
469
470 /* unregister the devices gathered above */
471 unregister_netdevice_many(&list);
472 rtnl_unlock();
473}
474
475static struct pernet_operations geneve_net_ops = {
476 .init = geneve_init_net,
477 .exit = geneve_exit_net,
478 .id = &geneve_net_id,
479 .size = sizeof(struct geneve_net),
480};
481
482static int __init geneve_init_module(void)
483{
484 int rc;
485
486 rc = register_pernet_subsys(&geneve_net_ops);
487 if (rc)
488 goto out1;
489
490 rc = rtnl_link_register(&geneve_link_ops);
491 if (rc)
492 goto out2;
493
494 return 0;
495out2:
496 unregister_pernet_subsys(&geneve_net_ops);
497out1:
498 return rc;
499}
500late_initcall(geneve_init_module);
501
502static void __exit geneve_cleanup_module(void)
503{
504 rtnl_link_unregister(&geneve_link_ops);
505 unregister_pernet_subsys(&geneve_net_ops);
506}
507module_exit(geneve_cleanup_module);
508
509MODULE_LICENSE("GPL");
510MODULE_VERSION(GENEVE_NETDEV_VER);
511MODULE_AUTHOR("John W. Linville <linville@tuxdriver.com>");
512MODULE_DESCRIPTION("Interface driver for GENEVE encapsulated traffic");
513MODULE_ALIAS_RTNL_LINK("geneve");