2 # Copyright (C) 2013 Nicira, Inc. All Rights Reserved.
4 # Licensed under the Apache License, Version 2.0 (the "License");
5 # you may not use this file except in compliance with the License.
6 # You may obtain a copy of the License at:
8 # http://www.apache.org/licenses/LICENSE-2.0
10 # Unless required by applicable law or agreed to in writing, software
11 # distributed under the License is distributed on an "AS IS" BASIS,
12 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 # See the License for the specific language governing permissions and
14 # limitations under the License.
17 # - Doesn't support multicast other than "unknown-dst"
30 import ovs.unixctl.server
38 __pychecker__ = 'no-reuseattr' # Remove in pychecker >= 0.8.19.
39 vlog = ovs.vlog.Vlog("ovs-vtep")
49 bfd_bridge = "vtep_bfd"
53 def call_prog(prog, args_list):
54 cmd = [prog, "-vconsole:off"] + args_list
55 output = subprocess.Popen(cmd, stdout=subprocess.PIPE).communicate()
56 if len(output) == 0 or output[0] is None:
59 output = output[0].strip()
64 return call_prog("ovs-vsctl", shlex.split(args))
68 return call_prog("ovs-ofctl", shlex.split(args))
72 return call_prog("vtep-ctl", shlex.split(args))
75 def unixctl_exit(conn, unused_argv, unused_aux):
81 class Logical_Switch(object):
82 def __init__(self, ls_name):
86 self.short_name = "vtep_ls" + str(ls_count)
87 vlog.info("creating lswitch %s (%s)" % (self.name, self.short_name))
90 self.local_macs = set()
92 self.unknown_dsts = set()
97 vlog.info("destroying lswitch %s" % self.name)
100 column = vtep_ctl("--columns=tunnel_key find logical_switch "
101 "name=%s" % self.name)
102 tunnel_key = column.partition(":")[2].strip()
103 if tunnel_key and isinstance(eval(tunnel_key), types.IntType):
104 self.tunnel_key = tunnel_key
105 vlog.info("using tunnel key %s in %s"
106 % (self.tunnel_key, self.name))
109 vlog.warn("invalid tunnel key for %s, using 0" % self.name)
112 ovs_vsctl("--may-exist add-br %s -- set Bridge %s datapath_type=%s"
113 % (self.short_name, self.short_name, ps_type))
115 ovs_vsctl("--may-exist add-br %s" % self.short_name)
117 ovs_vsctl("br-set-external-id %s vtep_logical_switch true"
119 ovs_vsctl("br-set-external-id %s logical_switch_name %s"
120 % (self.short_name, self.name))
122 vtep_ctl("clear-local-macs %s" % self.name)
123 vtep_ctl("add-mcast-local %s unknown-dst %s" % (self.name, Tunnel_Ip))
125 ovs_ofctl("del-flows %s" % self.short_name)
126 ovs_ofctl("add-flow %s priority=0,action=drop" % self.short_name)
128 def cleanup_ls(self):
129 for port_no, tun_name, remote_ip in self.tunnels.itervalues():
132 def update_flood(self):
133 flood_ports = self.ports.values()
135 # Traffic flowing from one 'unknown-dst' should not be flooded to
136 # port belonging to another 'unknown-dst'.
137 for tunnel in self.unknown_dsts:
138 port_no = self.tunnels[tunnel][0]
139 ovs_ofctl("add-flow %s table=1,priority=1,in_port=%s,action=%s"
140 % (self.short_name, port_no, ",".join(flood_ports)))
142 # Traffic coming from a VTEP physical port should only be flooded to
143 # one 'unknown-dst' and to all other physical ports that belong to that
144 # VTEP device and this logical switch.
145 for tunnel in self.unknown_dsts:
146 port_no = self.tunnels[tunnel][0]
147 flood_ports.append(port_no)
150 ovs_ofctl("add-flow %s table=1,priority=0,action=%s"
151 % (self.short_name, ",".join(flood_ports)))
153 def add_lbinding(self, lbinding):
154 vlog.info("adding %s binding to %s" % (lbinding, self.name))
155 port_no = ovs_vsctl("get Interface %s ofport" % lbinding)
156 self.ports[lbinding] = port_no
157 ovs_ofctl("add-flow %s in_port=%s,action=learn(table=1,"
158 "priority=1000,idle_timeout=15,cookie=0x5000,"
159 "NXM_OF_ETH_DST[]=NXM_OF_ETH_SRC[],"
160 "output:NXM_OF_IN_PORT[]),resubmit(,1)"
161 % (self.short_name, port_no))
165 def del_lbinding(self, lbinding):
166 vlog.info("removing %s binding from %s" % (lbinding, self.name))
167 port_no = self.ports[lbinding]
168 ovs_ofctl("del-flows %s in_port=%s" % (self.short_name, port_no))
169 del self.ports[lbinding]
172 def add_tunnel(self, tunnel):
174 vlog.info("adding tunnel %s" % tunnel)
175 encap, ip = tunnel.split("/")
177 if encap != "vxlan_over_ipv4":
178 vlog.warn("unsupported tunnel format %s" % encap)
182 tun_name = "vx" + str(tun_id)
184 ovs_vsctl("add-port %s %s -- set Interface %s type=vxlan "
185 "options:key=%s options:remote_ip=%s"
186 % (self.short_name, tun_name, tun_name, self.tunnel_key, ip))
189 port_no = ovs_vsctl("get Interface %s ofport" % tun_name)
193 vlog.warn("couldn't create tunnel %s" % tunnel)
194 ovs_vsctl("del-port %s %s" % (self.short_name, tun_name))
197 # Give the system a moment to allocate the port number
200 self.tunnels[tunnel] = (port_no, tun_name, ip)
204 ovs_ofctl("add-flow %s table=0,priority=1000,in_port=%s,"
205 "actions=resubmit(,1)"
206 % (self.short_name, port_no))
208 def del_tunnel(self, tunnel):
209 vlog.info("removing tunnel %s" % tunnel)
211 port_no, tun_name, remote_ip = self.tunnels[tunnel]
212 ovs_ofctl("del-flows %s table=0,in_port=%s"
213 % (self.short_name, port_no))
214 ovs_vsctl("del-port %s %s" % (self.short_name, tun_name))
218 del self.tunnels[tunnel]
220 def update_local_macs(self):
221 flows = ovs_ofctl("dump-flows %s cookie=0x5000/-1,table=1"
222 % self.short_name).splitlines()
225 mac = re.split(r'.*dl_dst=(.*) .*', f)
229 for mac in macs.difference(self.local_macs):
230 vlog.info("adding local ucast %s to %s" % (mac, self.name))
231 vtep_ctl("add-ucast-local %s %s %s" % (self.name, mac, Tunnel_Ip))
233 for mac in self.local_macs.difference(macs):
234 vlog.info("removing local ucast %s from %s" % (mac, self.name))
235 vtep_ctl("del-ucast-local %s %s" % (self.name, mac))
237 self.local_macs = macs
239 def add_remote_mac(self, mac, tunnel):
240 port_no = self.tunnels.get(tunnel, (0, ""))[0]
244 ovs_ofctl("add-flow %s table=1,priority=1000,dl_dst=%s,action=%s"
245 % (self.short_name, mac, port_no))
247 def del_remote_mac(self, mac):
248 ovs_ofctl("del-flows %s table=1,dl_dst=%s" % (self.short_name, mac))
250 def update_remote_macs(self):
256 mac_list = vtep_ctl("list-remote-macs %s" % self.name).splitlines()
257 for line in mac_list:
258 if (line.find("mcast-mac-remote") != -1):
262 entry = re.split(r' (.*) -> (.*)', line)
267 remote_macs[entry[1]] = entry[2]
269 if entry[1] != "unknown-dst":
272 unknown_dsts.add(entry[2])
274 tunnels.add(entry[2])
276 old_tunnels = set(self.tunnels.keys())
278 for tunnel in tunnels.difference(old_tunnels):
279 self.add_tunnel(tunnel)
281 for tunnel in old_tunnels.difference(tunnels):
282 self.del_tunnel(tunnel)
284 for mac in remote_macs.keys():
285 if (self.remote_macs.get(mac) != remote_macs[mac]):
286 self.add_remote_mac(mac, remote_macs[mac])
288 for mac in self.remote_macs.keys():
289 if mac not in remote_macs:
290 self.del_remote_mac(mac)
292 self.remote_macs = remote_macs
294 if (self.unknown_dsts != unknown_dsts):
295 self.unknown_dsts = unknown_dsts
298 def update_stats(self):
299 # Map Open_vSwitch's "interface:statistics" to columns of
300 # vtep's logical_binding_stats. Since we are using the 'interface' from
301 # the logical switch to collect stats, packets transmitted from it
302 # is received in the physical switch and vice versa.
303 stats_map = {'tx_packets': 'packets_to_local',
304 'tx_bytes': 'bytes_to_local',
305 'rx_packets': 'packets_from_local',
306 'rx_bytes': 'bytes_from_local'}
308 # Go through all the logical switch's interfaces that end with "-l"
309 # and copy the statistics to logical_binding_stats.
310 for interface in self.ports.iterkeys():
311 if not interface.endswith("-l"):
313 # Physical ports can have a '-' as part of its name.
314 vlan, remainder = interface.split("-", 1)
315 pp_name, logical = remainder.rsplit("-", 1)
316 uuid = vtep_ctl("get physical_port %s vlan_stats:%s"
321 for (mapfrom, mapto) in stats_map.iteritems():
322 value = ovs_vsctl("get interface %s statistics:%s"
323 % (interface, mapfrom)).strip('"')
324 vtep_ctl("set logical_binding_stats %s %s=%s"
325 % (uuid, mapto, value))
328 self.update_local_macs()
329 self.update_remote_macs()
333 def get_vtep_tunnel(remote_ip):
334 # Get the physical_locator record for the local tunnel end point.
335 column = vtep_ctl("--columns=_uuid find physical_locator "
336 "dst_ip=%s" % Tunnel_Ip)
337 local = column.partition(":")[2].strip()
339 return (None, None, None)
341 # Get the physical_locator record for the remote tunnel end point.
342 column = vtep_ctl("--columns=_uuid find physical_locator "
343 "dst_ip=%s" % remote_ip)
344 remote = column.partition(":")[2].strip()
346 return (None, None, None)
348 column = vtep_ctl("--columns=_uuid find tunnel "
349 "local=%s remote=%s" % (local, remote))
350 tunnel = column.partition(":")[2].strip()
352 return (local, remote, tunnel)
355 def create_vtep_tunnel(remote_ip):
356 local, remote, tunnel = get_vtep_tunnel(remote_ip)
357 if not local or not remote:
361 vlog.info("creating tunnel record in vtep for remote_ip:%s"
363 tunnel = vtep_ctl("add physical_switch %s tunnels @tun -- "
364 "--id=@tun create Tunnel local=%s remote=%s"
365 % (ps_name, local, remote))
369 def destroy_vtep_tunnel(remote_ip):
370 local, remote, tunnel = get_vtep_tunnel(remote_ip)
372 vlog.info("destroying tunnel record in vtep for remote_ip:%s"
374 vtep_ctl("remove physical_switch %s tunnels %s "
375 "-- --if-exists destroy tunnel %s"
376 % (ps_name, tunnel, tunnel))
379 def add_bfd(remote_ip):
380 # The VTEP emulator creates one OVS bridge for every logical switch.
381 # Multiple logical switches can have multiple OVS tunnels to the
382 # same machine (with different tunnel ids). But VTEP schema expects
383 # a single BFD session between two physical locators. Therefore
384 # create a separate bridge ('bfd_bridge') and create a single OVS tunnel
385 # between two phsyical locators (using reference counter).
386 if remote_ip in bfd_ref:
387 bfd_ref[remote_ip] += 1
390 vlog.info("adding bfd tunnel for remote_ip:%s" % remote_ip)
392 port_name = "bfd" + remote_ip
393 # Don't enable BFD yet. Enabling or disabling BFD is based on
394 # the controller setting a value in VTEP DB's tunnel record.
395 ovs_vsctl("--may-exist add-port %s %s "
396 " -- set Interface %s type=vxlan options:remote_ip=%s"
397 % (bfd_bridge, port_name, port_name, remote_ip))
398 bfd_ref[remote_ip] = 1
400 # Ideally, we should create a 'tunnel' record in the VTEP DB here.
401 # To create a 'tunnel' record, we need 2 entries in 'physical_locator'
402 # table (one for local and one for remote). But, 'physical_locator'
403 # can be created/destroyed asynchronously when the remote controller
404 # adds/removes entries in Ucast_Macs_Remote table. To prevent race
405 # conditions, pass the responsibility of creating a 'tunnel' record
406 # to run_bfd() which runs more often.
409 def del_bfd(remote_ip):
410 if remote_ip in bfd_ref:
411 if bfd_ref[remote_ip] == 1:
412 port_name = "bfd" + remote_ip
413 vlog.info("deleting bfd tunnel for remote_ip:%s" % remote_ip)
414 ovs_vsctl("--if-exists del-port %s" % port_name)
415 destroy_vtep_tunnel(remote_ip)
416 del bfd_ref[remote_ip]
418 bfd_ref[remote_ip] -= 1
422 bfd_ports = ovs_vsctl("list-ports %s" % bfd_bridge).split()
423 for port in bfd_ports:
424 remote_ip = ovs_vsctl("get interface %s options:remote_ip" % port)
425 tunnel = create_vtep_tunnel(remote_ip)
429 bfd_params_default = {'bfd_params:enable': 'false',
430 'bfd_params:min_rx': 1000,
431 'bfd_params:min_tx': 100,
432 'bfd_params:decay_min_rx': 0,
433 'bfd_params:cpath_down': 'false',
434 'bfd_params:check_tnl_key': 'false'}
435 bfd_params_values = {}
437 for key, default in bfd_params_default.iteritems():
438 column = vtep_ctl("--if-exists get tunnel %s %s"
441 bfd_params_values[key] = default
443 bfd_params_values[key] = column
445 for key, value in bfd_params_values.iteritems():
446 new_key = key.replace('_params', '')
447 ovs_vsctl("set interface %s %s=%s" % (port, new_key, value))
449 bfd_status = ['bfd_status:state', 'bfd_status:forwarding',
450 'bfd_status:diagnostic', 'bfd_status:remote_state',
451 'bfd_status:remote_diagnostic']
452 for key in bfd_status:
453 value = ovs_vsctl("--if-exists get interface %s %s" % (port, key))
455 vtep_ctl("set tunnel %s %s=%s" % (tunnel, key, value))
457 new_key = key.replace('bfd_status:', '')
458 vtep_ctl("remove tunnel %s bfd_status %s" % (tunnel, new_key))
460 vtep_ctl("set tunnel %s bfd_status:enabled=%s"
461 % (tunnel, bfd_params_values['bfd_params:enable']))
463 # Add the defaults as described in VTEP schema to make it explicit.
464 bfd_lconf_default = {'bfd_config_local:bfd_dst_ip': '169.254.1.0',
465 'bfd_config_local:bfd_dst_mac':
467 for key, value in bfd_lconf_default.iteritems():
468 vtep_ctl("set tunnel %s %s=%s" % (tunnel, key, value))
470 # bfd_config_remote options from VTEP DB should be populated to
471 # corresponding OVS DB values.
472 bfd_dst_ip = vtep_ctl("--if-exists get tunnel %s "
473 "bfd_config_remote:bfd_dst_ip" % (tunnel))
475 bfd_dst_ip = "169.254.1.1"
477 bfd_dst_mac = vtep_ctl("--if-exists get tunnel %s "
478 "bfd_config_remote:bfd_dst_mac" % (tunnel))
480 bfd_dst_mac = "00:23:20:00:00:01"
482 ovs_vsctl("set interface %s bfd:bfd_dst_ip=%s "
483 "bfd:bfd_remote_dst_mac=%s bfd:bfd_local_dst_mac=%s"
485 bfd_lconf_default['bfd_config_local:bfd_dst_mac'],
489 def add_binding(binding, ls):
490 vlog.info("adding binding %s" % binding)
492 vlan, pp_name = binding.split("-", 1)
493 pbinding = binding + "-p"
494 lbinding = binding + "-l"
496 # Create a patch port that connects the VLAN+port to the lswitch.
497 # Do them as two separate calls so if one side already exists, the
498 # other side is created.
499 ovs_vsctl("add-port %s %s "
500 " -- set Interface %s type=patch options:peer=%s"
501 % (ps_name, pbinding, pbinding, lbinding))
502 ovs_vsctl("add-port %s %s "
503 " -- set Interface %s type=patch options:peer=%s"
504 % (ls.short_name, lbinding, lbinding, pbinding))
506 port_no = ovs_vsctl("get Interface %s ofport" % pp_name)
507 patch_no = ovs_vsctl("get Interface %s ofport" % pbinding)
508 vlan_ = vlan.lstrip('0')
510 ovs_ofctl("add-flow %s in_port=%s,dl_vlan=%s,action=strip_vlan,%s"
511 % (ps_name, port_no, vlan_, patch_no))
512 ovs_ofctl("add-flow %s in_port=%s,action=mod_vlan_vid:%s,%s"
513 % (ps_name, patch_no, vlan_, port_no))
515 ovs_ofctl("add-flow %s in_port=%s,action=%s"
516 % (ps_name, port_no, patch_no))
517 ovs_ofctl("add-flow %s in_port=%s,action=%s"
518 % (ps_name, patch_no, port_no))
520 # Create a logical_bindings_stats record.
523 vtep_ctl("set physical_port %s vlan_stats:%s=@stats -- "
524 "--id=@stats create logical_binding_stats packets_from_local=0"
527 ls.add_lbinding(lbinding)
528 Bindings[binding] = ls.name
531 def del_binding(binding, ls):
532 vlog.info("removing binding %s" % binding)
534 vlan, pp_name = binding.split("-", 1)
535 pbinding = binding + "-p"
536 lbinding = binding + "-l"
538 port_no = ovs_vsctl("get Interface %s ofport" % pp_name)
539 patch_no = ovs_vsctl("get Interface %s ofport" % pbinding)
540 vlan_ = vlan.lstrip('0')
542 ovs_ofctl("del-flows %s in_port=%s,dl_vlan=%s"
543 % (ps_name, port_no, vlan_))
544 ovs_ofctl("del-flows %s in_port=%s" % (ps_name, patch_no))
546 ovs_ofctl("del-flows %s in_port=%s" % (ps_name, port_no))
547 ovs_ofctl("del-flows %s in_port=%s" % (ps_name, patch_no))
549 ls.del_lbinding(lbinding)
551 # Destroy the patch port that connects the VLAN+port to the lswitch
552 ovs_vsctl("del-port %s %s -- del-port %s %s"
553 % (ps_name, pbinding, ls.short_name, lbinding))
555 # Remove the record that links vlan with stats in logical_binding_stats.
556 vtep_ctl("remove physical_port %s vlan_stats %s" % (pp_name, vlan))
558 del Bindings[binding]
561 def handle_physical():
562 # Gather physical ports except the patch ports we created
563 ovs_ports = ovs_vsctl("list-ports %s" % ps_name).split()
564 ovs_port_set = set([port for port in ovs_ports if port[-2:] != "-p"])
566 vtep_pp_set = set(vtep_ctl("list-ports %s" % ps_name).split())
568 for pp_name in ovs_port_set.difference(vtep_pp_set):
569 vlog.info("adding %s to %s" % (pp_name, ps_name))
570 vtep_ctl("add-port %s %s" % (ps_name, pp_name))
572 for pp_name in vtep_pp_set.difference(ovs_port_set):
573 vlog.info("deleting %s from %s" % (pp_name, ps_name))
574 vtep_ctl("del-port %s %s" % (ps_name, pp_name))
577 for pp_name in vtep_pp_set:
578 binding_set = set(vtep_ctl("list-bindings %s %s"
579 % (ps_name, pp_name)).splitlines())
581 for b in binding_set:
582 vlan, ls_name = b.split()
583 if ls_name not in Lswitches:
584 Lswitches[ls_name] = Logical_Switch(ls_name)
586 binding = "%s-%s" % (vlan, pp_name)
587 ls = Lswitches[ls_name]
588 new_bindings.add(binding)
590 if binding in Bindings:
591 if Bindings[binding] == ls_name:
594 del_binding(binding, Lswitches[Bindings[binding]])
596 add_binding(binding, ls)
598 dead_bindings = set(Bindings.keys()).difference(new_bindings)
599 for binding in dead_bindings:
600 ls_name = Bindings[binding]
601 ls = Lswitches[ls_name]
603 del_binding(binding, ls)
605 if not len(ls.ports):
607 ovs_vsctl("del-br %s" % Lswitches[ls_name].short_name)
608 vtep_ctl("clear-local-macs %s" % Lswitches[ls_name].name)
609 del Lswitches[ls_name]
613 br_list = ovs_vsctl("list-br").split()
614 if (ps_name not in br_list):
615 ovs.util.ovs_fatal(0, "couldn't find OVS bridge %s" % ps_name, vlog)
618 ps_type = ovs_vsctl("get Bridge %s datapath_type" % ps_name).strip('"')
620 call_prog("vtep-ctl", ["set", "physical_switch", ps_name,
621 'description="OVS VTEP Emulator"'])
623 tunnel_ips = vtep_ctl("get physical_switch %s tunnel_ips"
624 % ps_name).strip('[]"').split(", ")
625 if len(tunnel_ips) != 1 or not tunnel_ips[0]:
626 ovs.util.ovs_fatal(0, "exactly one 'tunnel_ips' should be set", vlog)
629 Tunnel_Ip = tunnel_ips[0]
631 ovs_ofctl("del-flows %s" % ps_name)
633 # Remove any logical bridges from the previous run
635 if ovs_vsctl("br-get-external-id %s vtep_logical_switch"
637 # Remove the remote side of any logical switch
638 ovs_ports = ovs_vsctl("list-ports %s" % br).split()
639 for port in ovs_ports:
640 port_type = ovs_vsctl("get Interface %s type"
642 if port_type != "patch":
645 peer = ovs_vsctl("get Interface %s options:peer"
648 ovs_vsctl("del-port %s" % peer)
650 ovs_vsctl("del-br %s" % br)
653 bfd_ports = ovs_vsctl("list-ports %s" % bfd_bridge).split()
654 for port in bfd_ports:
655 remote_ip = ovs_vsctl("get interface %s options:remote_ip"
657 destroy_vtep_tunnel(remote_ip)
659 ovs_vsctl("del-br %s" % br)
662 ovs_vsctl("add-br %s -- set Bridge %s datapath_type=%s"
663 % (bfd_bridge, bfd_bridge, ps_type))
665 ovs_vsctl("add-br %s" % bfd_bridge)
667 # Remove local-mac entries from the previous run. Otherwise, if a vlan
668 # binding is removed while the emulator is *not* running, the corresponding
669 # local-mac entries are never cleaned up.
670 vtep_ls = set(vtep_ctl("list-ls").split())
671 for ls_name in vtep_ls:
672 vtep_ctl("clear-local-macs %s" % ls_name)
676 parser = argparse.ArgumentParser()
677 parser.add_argument("ps_name", metavar="PS-NAME",
678 help="Name of physical switch.")
679 parser.add_argument("--root-prefix", metavar="DIR",
680 help="Use DIR as alternate root directory"
682 parser.add_argument("--version", action="version",
683 version="%s %s" % (ovs.util.PROGRAM_NAME, VERSION))
685 ovs.vlog.add_args(parser)
686 ovs.daemon.add_args(parser)
687 args = parser.parse_args()
688 ovs.vlog.handle_args(args)
689 ovs.daemon.handle_args(args)
693 root_prefix = args.root_prefix
696 ps_name = args.ps_name
698 ovs.daemon.daemonize()
700 ovs.unixctl.command_register("exit", "", 0, 0, unixctl_exit, None)
701 error, unixctl = ovs.unixctl.server.UnixctlServer.create(None,
704 ovs.util.ovs_fatal(error, "could not create unixctl server", vlog)
715 for ls_name, ls in Lswitches.items():
720 poller = ovs.poller.Poller()
722 poller.timer_wait(1000)
727 if __name__ == '__main__':
731 # Let system.exit() calls complete normally
734 vlog.exception("traceback")
735 sys.exit(ovs.daemon.RESTART_EXIT_CODE)