2012-10-01 12:32:35 +00:00
|
|
|
|
2012-11-13 13:29:15 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-04-27 11:31:52 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-01-29 23:43:07 +00:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-28 21:43:22 +02:00
|
|
|
|
2013-08-19 11:23:07 -07:00
|
|
|
|
2016-02-09 22:07:29 -08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2013-09-02 10:06:52 +08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-27 11:31:53 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:41 -07:00
|
|
|
|
2013-04-27 11:31:53 +00:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
netns: make struct pernet_operations::id unsigned int
Make struct pernet_operations::id unsigned.
There are 2 reasons to do so:
1)
This field is really an index into an zero based array and
thus is unsigned entity. Using negative value is out-of-bound
access by definition.
2)
On x86_64 unsigned 32-bit data which are mixed with pointers
via array indexing or offsets added or subtracted to pointers
are preffered to signed 32-bit data.
"int" being used as an array index needs to be sign-extended
to 64-bit before being used.
void f(long *p, int i)
{
g(p[i]);
}
roughly translates to
movsx rsi, esi
mov rdi, [rsi+...]
call g
MOVSX is 3 byte instruction which isn't necessary if the variable is
unsigned because x86_64 is zero extending by default.
Now, there is net_generic() function which, you guessed it right, uses
"int" as an array index:
static inline void *net_generic(const struct net *net, int id)
{
...
ptr = ng->ptr[id - 1];
...
}
And this function is used a lot, so those sign extensions add up.
Patch snipes ~1730 bytes on allyesconfig kernel (without all junk
messing with code generation):
add/remove: 0/0 grow/shrink: 70/598 up/down: 396/-2126 (-1730)
Unfortunately some functions actually grow bigger.
This is a semmingly random artefact of code generation with register
allocator being used differently. gcc decides that some variable
needs to live in new r8+ registers and every access now requires REX
prefix. Or it is shifted into r12, so [r12+0] addressing mode has to be
used which is longer than [r8]
However, overall balance is in negative direction:
add/remove: 0/0 grow/shrink: 70/598 up/down: 396/-2126 (-1730)
function old new delta
nfsd4_lock 3886 3959 +73
tipc_link_build_proto_msg 1096 1140 +44
mac80211_hwsim_new_radio 2776 2808 +32
tipc_mon_rcv 1032 1058 +26
svcauth_gss_legacy_init 1413 1429 +16
tipc_bcbase_select_primary 379 392 +13
nfsd4_exchange_id 1247 1260 +13
nfsd4_setclientid_confirm 782 793 +11
...
put_client_renew_locked 494 480 -14
ip_set_sockfn_get 730 716 -14
geneve_sock_add 829 813 -16
nfsd4_sequence_done 721 703 -18
nlmclnt_lookup_host 708 686 -22
nfsd4_lockt 1085 1063 -22
nfs_get_client 1077 1050 -27
tcf_bpf_init 1106 1076 -30
nfsd4_encode_fattr 5997 5930 -67
Total: Before=154856051, After=154854321, chg -0.00%
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-11-17 04:58:21 +03:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2016-01-29 09:43:47 +08:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2015-07-21 10:44:06 +02:00
|
|
|
|
2017-06-02 03:24:08 +03:00
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2015-07-20 09:54:50 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:01 +02:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2015-03-29 16:59:26 +02:00
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:59:26 +02:00
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:59:26 +02:00
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:17:37 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-04 17:17:39 -07:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2013-08-04 17:17:39 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
|
|
|
|
|
2015-01-15 03:53:56 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2015-01-20 11:23:05 -08:00
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2014-11-13 14:43:08 -02:00
|
|
|
|
2015-08-20 13:56:28 +02:00
|
|
|
|
2015-01-20 11:23:05 -08:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-16 21:59:03 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-15 03:53:56 +01:00
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:41 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-03-10 16:30:24 +01:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
2014-07-26 00:38:59 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-01-20 15:15:47 +01:00
|
|
|
|
2015-01-26 14:10:53 +01:00
|
|
|
|
2016-09-01 21:53:44 -07:00
|
|
|
|
2015-01-20 15:15:47 +01:00
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2013-04-16 02:50:52 +00:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-16 22:09:00 +01:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-04-27 11:31:54 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2015-01-26 14:10:53 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:40 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-06-17 14:16:40 -07:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:40 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:47 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-17 06:39:07 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
hlist: drop the node parameter from iterators
I'm not sure why, but the hlist for each entry iterators were conceived
list_for_each_entry(pos, head, member)
The hlist ones were greedy and wanted an extra parameter:
hlist_for_each_entry(tpos, pos, head, member)
Why did they need an extra pos parameter? I'm not quite sure. Not only
they don't really need it, it also prevents the iterator from looking
exactly like the list iterator, which is unfortunate.
Besides the semantic patch, there was some manual work required:
- Fix up the actual hlist iterators in linux/list.h
- Fix up the declaration of other iterators based on the hlist ones.
- A very small amount of places were using the 'node' parameter, this
was modified to use 'obj->member' instead.
- Coccinelle didn't handle the hlist_for_each_entry_safe iterator
properly, so those had to be fixed up manually.
The semantic patch which is mostly the work of Peter Senna Tschudin is here:
@@
iterator name hlist_for_each_entry, hlist_for_each_entry_continue, hlist_for_each_entry_from, hlist_for_each_entry_rcu, hlist_for_each_entry_rcu_bh, hlist_for_each_entry_continue_rcu_bh, for_each_busy_worker, ax25_uid_for_each, ax25_for_each, inet_bind_bucket_for_each, sctp_for_each_hentry, sk_for_each, sk_for_each_rcu, sk_for_each_from, sk_for_each_safe, sk_for_each_bound, hlist_for_each_entry_safe, hlist_for_each_entry_continue_rcu, nr_neigh_for_each, nr_neigh_for_each_safe, nr_node_for_each, nr_node_for_each_safe, for_each_gfn_indirect_valid_sp, for_each_gfn_sp, for_each_host;
type T;
expression a,c,d,e;
identifier b;
statement S;
@@
-T b;
<+... when != b
(
hlist_for_each_entry(a,
- b,
c, d) S
|
hlist_for_each_entry_continue(a,
- b,
c) S
|
hlist_for_each_entry_from(a,
- b,
c) S
|
hlist_for_each_entry_rcu(a,
- b,
c, d) S
|
hlist_for_each_entry_rcu_bh(a,
- b,
c, d) S
|
hlist_for_each_entry_continue_rcu_bh(a,
- b,
c) S
|
for_each_busy_worker(a, c,
- b,
d) S
|
ax25_uid_for_each(a,
- b,
c) S
|
ax25_for_each(a,
- b,
c) S
|
inet_bind_bucket_for_each(a,
- b,
c) S
|
sctp_for_each_hentry(a,
- b,
c) S
|
sk_for_each(a,
- b,
c) S
|
sk_for_each_rcu(a,
- b,
c) S
|
sk_for_each_from
-(a, b)
+(a)
S
+ sk_for_each_from(a) S
|
sk_for_each_safe(a,
- b,
c, d) S
|
sk_for_each_bound(a,
- b,
c) S
|
hlist_for_each_entry_safe(a,
- b,
c, d, e) S
|
hlist_for_each_entry_continue_rcu(a,
- b,
c) S
|
nr_neigh_for_each(a,
- b,
c) S
|
nr_neigh_for_each_safe(a,
- b,
c, d) S
|
nr_node_for_each(a,
- b,
c) S
|
nr_node_for_each_safe(a,
- b,
c, d) S
|
- for_each_gfn_sp(a, c, d, b) S
+ for_each_gfn_sp(a, c, d) S
|
- for_each_gfn_indirect_valid_sp(a, c, d, b) S
+ for_each_gfn_indirect_valid_sp(a, c, d) S
|
for_each_host(a,
- b,
c) S
|
for_each_host_safe(a,
- b,
c, d) S
|
for_each_mesh_entry(a,
- b,
c, d) S
)
...+>
[akpm@linux-foundation.org: drop bogus change from net/ipv4/raw.c]
[akpm@linux-foundation.org: drop bogus hunk from net/ipv6/raw.c]
[akpm@linux-foundation.org: checkpatch fixes]
[akpm@linux-foundation.org: fix warnings]
[akpm@linux-foudnation.org: redo intrusive kvm changes]
Tested-by: Peter Senna Tschudin <peter.senna@gmail.com>
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Cc: Wu Fengguang <fengguang.wu@intel.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2013-02-27 17:06:00 -08:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-17 06:39:07 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-05-17 06:39:07 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-05-17 06:39:07 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:52 +03:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:52 +03:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2013-06-25 16:01:52 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-19 17:20:07 +02:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
|
|
|
|
|
2013-07-19 17:20:07 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-07-19 17:20:07 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:52 +03:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2013-06-25 16:01:52 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
|
|
|
|
|
2015-02-10 16:30:32 -08:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2015-08-19 17:07:32 -07:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
2015-08-19 17:07:32 -07:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2015-08-19 17:07:32 -07:00
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-05 08:22:53 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-12-30 19:10:15 -08:00
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
2016-04-05 08:22:53 -07:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2015-02-10 16:30:27 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2015-02-10 16:30:32 -08:00
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-19 17:07:32 -07:00
|
|
|
|
|
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
|
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-10-20 15:58:02 +02:00
|
|
|
|
2016-03-09 09:24:23 -08:00
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
2015-02-10 16:30:27 -08:00
|
|
|
|
2017-08-01 01:05:20 +09:00
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-05 08:22:53 -07:00
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
2016-05-03 16:10:21 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-12-30 19:10:15 -08:00
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2016-11-29 09:59:36 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-19 17:20:07 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-04-22 15:49:10 +08:00
|
|
|
|
2013-07-19 17:20:07 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-25 16:01:56 +03:00
|
|
|
|
|
|
|
|
|
2016-11-29 09:59:36 +08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-07-19 17:20:07 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2016-11-29 09:59:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-11 19:00:35 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-05-29 13:25:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-04-27 11:31:54 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-03-26 08:29:30 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2014-01-15 10:23:41 +08:00
|
|
|
|
2013-03-26 08:29:30 +00:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-11-28 14:34:15 +01:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:53 +03:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2014-04-01 09:23:01 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
2017-11-26 21:19:05 +08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-05-29 13:25:57 -04:00
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-06-25 16:01:54 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-10 07:01:58 -04:00
|
|
|
|
2016-08-30 21:56:45 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-08-30 21:56:45 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
hlist: drop the node parameter from iterators
I'm not sure why, but the hlist for each entry iterators were conceived
list_for_each_entry(pos, head, member)
The hlist ones were greedy and wanted an extra parameter:
hlist_for_each_entry(tpos, pos, head, member)
Why did they need an extra pos parameter? I'm not quite sure. Not only
they don't really need it, it also prevents the iterator from looking
exactly like the list iterator, which is unfortunate.
Besides the semantic patch, there was some manual work required:
- Fix up the actual hlist iterators in linux/list.h
- Fix up the declaration of other iterators based on the hlist ones.
- A very small amount of places were using the 'node' parameter, this
was modified to use 'obj->member' instead.
- Coccinelle didn't handle the hlist_for_each_entry_safe iterator
properly, so those had to be fixed up manually.
The semantic patch which is mostly the work of Peter Senna Tschudin is here:
@@
iterator name hlist_for_each_entry, hlist_for_each_entry_continue, hlist_for_each_entry_from, hlist_for_each_entry_rcu, hlist_for_each_entry_rcu_bh, hlist_for_each_entry_continue_rcu_bh, for_each_busy_worker, ax25_uid_for_each, ax25_for_each, inet_bind_bucket_for_each, sctp_for_each_hentry, sk_for_each, sk_for_each_rcu, sk_for_each_from, sk_for_each_safe, sk_for_each_bound, hlist_for_each_entry_safe, hlist_for_each_entry_continue_rcu, nr_neigh_for_each, nr_neigh_for_each_safe, nr_node_for_each, nr_node_for_each_safe, for_each_gfn_indirect_valid_sp, for_each_gfn_sp, for_each_host;
type T;
expression a,c,d,e;
identifier b;
statement S;
@@
-T b;
<+... when != b
(
hlist_for_each_entry(a,
- b,
c, d) S
|
hlist_for_each_entry_continue(a,
- b,
c) S
|
hlist_for_each_entry_from(a,
- b,
c) S
|
hlist_for_each_entry_rcu(a,
- b,
c, d) S
|
hlist_for_each_entry_rcu_bh(a,
- b,
c, d) S
|
hlist_for_each_entry_continue_rcu_bh(a,
- b,
c) S
|
for_each_busy_worker(a, c,
- b,
d) S
|
ax25_uid_for_each(a,
- b,
c) S
|
ax25_for_each(a,
- b,
c) S
|
inet_bind_bucket_for_each(a,
- b,
c) S
|
sctp_for_each_hentry(a,
- b,
c) S
|
sk_for_each(a,
- b,
c) S
|
sk_for_each_rcu(a,
- b,
c) S
|
sk_for_each_from
-(a, b)
+(a)
S
+ sk_for_each_from(a) S
|
sk_for_each_safe(a,
- b,
c, d) S
|
sk_for_each_bound(a,
- b,
c) S
|
hlist_for_each_entry_safe(a,
- b,
c, d, e) S
|
hlist_for_each_entry_continue_rcu(a,
- b,
c) S
|
nr_neigh_for_each(a,
- b,
c) S
|
nr_neigh_for_each_safe(a,
- b,
c, d) S
|
nr_node_for_each(a,
- b,
c) S
|
nr_node_for_each_safe(a,
- b,
c, d) S
|
- for_each_gfn_sp(a, c, d, b) S
+ for_each_gfn_sp(a, c, d) S
|
- for_each_gfn_indirect_valid_sp(a, c, d, b) S
+ for_each_gfn_indirect_valid_sp(a, c, d) S
|
for_each_host(a,
- b,
c) S
|
for_each_host_safe(a,
- b,
c, d) S
|
for_each_mesh_entry(a,
- b,
c, d) S
)
...+>
[akpm@linux-foundation.org: drop bogus change from net/ipv4/raw.c]
[akpm@linux-foundation.org: drop bogus hunk from net/ipv6/raw.c]
[akpm@linux-foundation.org: checkpatch fixes]
[akpm@linux-foundation.org: fix warnings]
[akpm@linux-foudnation.org: redo intrusive kvm changes]
Tested-by: Peter Senna Tschudin <peter.senna@gmail.com>
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Cc: Wu Fengguang <fengguang.wu@intel.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2013-02-27 17:06:00 -08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2016-08-30 21:56:45 -07:00
|
|
|
|
2015-08-10 23:39:09 +09:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-08-30 21:56:45 -07:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
|
|
|
|
|
2016-08-30 21:56:45 -07:00
|
|
|
|
2015-08-10 23:39:09 +09:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2016-08-30 21:56:45 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-04-02 11:17:58 +09:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-06-17 12:09:58 -07:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-08-04 17:17:39 -07:00
|
|
|
|
2013-06-17 14:16:12 -07:00
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
|
|
|
|
|
2013-06-17 12:09:58 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-11 16:32:50 -07:00
|
|
|
|
2013-06-17 12:09:58 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2015-02-07 03:17:31 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2014-04-22 15:01:30 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 12:09:57 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-17 12:09:57 -07:00
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-06-17 12:09:58 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2016-11-07 22:09:07 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-04 15:52:59 +03:00
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2017-07-04 15:52:59 +03:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
2013-12-10 16:37:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
2013-06-17 14:16:10 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-19 11:23:07 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
2017-07-04 15:52:59 +03:00
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2013-06-17 14:16:10 -07:00
|
|
|
|
2016-06-16 12:20:52 -07:00
|
|
|
|
2016-06-16 12:23:19 -07:00
|
|
|
|
|
|
|
|
|
2016-06-16 12:20:52 -07:00
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
|
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
2017-06-07 14:36:58 +03:00
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
|
|
|
|
|
2017-06-07 14:36:58 +03:00
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
|
|
|
|
|
2017-06-02 03:24:08 +03:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-09 12:46:23 +02:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-04-02 11:17:58 +09:00
|
|
|
|
2013-06-17 14:16:10 -07:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2015-03-20 10:26:21 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2013-07-18 08:40:15 -07:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2013-07-18 08:40:15 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2013-07-18 08:40:15 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2015-03-20 10:26:21 -03:00
|
|
|
|
2013-07-18 08:40:15 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2016-03-21 17:50:05 +01:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
2015-08-19 17:07:32 -07:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2016-03-21 17:50:05 +01:00
|
|
|
|
2016-02-16 21:58:59 +01:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2016-02-16 21:58:59 +01:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:59 +01:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
2016-02-23 18:02:55 +01:00
|
|
|
|
2016-02-23 18:02:59 +01:00
|
|
|
|
2016-02-16 21:59:00 +01:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
2016-02-23 18:02:59 +01:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:00 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:59 +01:00
|
|
|
|
2016-03-08 12:34:12 -05:00
|
|
|
|
2016-02-16 21:59:00 +01:00
|
|
|
|
2016-03-08 12:34:12 -05:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:00 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
2016-02-23 18:02:55 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:00 +01:00
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2016-04-11 17:06:08 +02:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-28 21:43:22 +02:00
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:56 +01:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2015-07-21 10:44:06 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
2015-07-21 10:44:06 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:56 +01:00
|
|
|
|
2015-07-21 10:44:06 +02:00
|
|
|
|
2016-02-23 18:02:57 +01:00
|
|
|
|
2015-12-07 16:29:08 +01:00
|
|
|
|
2016-02-23 18:02:56 +01:00
|
|
|
|
2015-07-21 10:44:06 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:56 +01:00
|
|
|
|
2015-07-21 10:44:06 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
2016-02-23 18:02:56 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:57 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-23 18:02:58 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-23 18:02:58 +01:00
|
|
|
|
2016-02-18 11:22:51 +01:00
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
2016-04-11 17:06:08 +02:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2016-02-23 18:02:58 +01:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2013-08-19 11:22:54 -07:00
|
|
|
|
2016-05-19 15:58:33 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
2016-02-16 21:59:02 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-05-19 15:58:33 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-16 21:59:02 +01:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-09-24 10:25:40 -07:00
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2016-02-18 11:22:51 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-18 11:22:51 +01:00
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
2016-02-23 18:02:59 +01:00
|
|
|
|
2016-02-18 19:19:29 +01:00
|
|
|
|
2015-08-26 23:46:50 -07:00
|
|
|
|
2016-09-08 16:23:45 +03:00
|
|
|
|
2015-08-26 23:46:50 -07:00
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-04 12:49:32 +02:00
|
|
|
|
2016-02-23 18:02:59 +01:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:59 +01:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
2016-02-16 21:59:01 +01:00
|
|
|
|
2015-01-08 12:31:18 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-04-02 11:17:58 +09:00
|
|
|
|
2015-01-08 12:31:18 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:02 +01:00
|
|
|
|
2015-01-08 12:31:18 -08:00
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
2016-05-13 10:48:42 +02:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:58 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-16 21:59:02 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-19 11:23:02 -07:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-03-18 12:32:29 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2014-08-22 21:34:16 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-04-02 11:00:06 +02:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-03 01:16:54 +00:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
2017-04-02 11:00:06 +02:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
2017-04-02 11:00:06 +02:00
|
|
|
|
|
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-03 01:16:54 +00:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-03 01:16:54 +00:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
networking: convert many more places to skb_put_zero()
There were many places that my previous spatch didn't find,
as pointed out by yuan linyu in various patches.
The following spatch found many more and also removes the
now unnecessary casts:
@@
identifier p, p2;
expression len;
expression skb;
type t, t2;
@@
(
-p = skb_put(skb, len);
+p = skb_put_zero(skb, len);
|
-p = (t)skb_put(skb, len);
+p = skb_put_zero(skb, len);
)
... when != p
(
p2 = (t2)p;
-memset(p2, 0, len);
|
-memset(p, 0, len);
)
@@
type t, t2;
identifier p, p2;
expression skb;
@@
t *p;
...
(
-p = skb_put(skb, sizeof(t));
+p = skb_put_zero(skb, sizeof(t));
|
-p = (t *)skb_put(skb, sizeof(t));
+p = skb_put_zero(skb, sizeof(t));
)
... when != p
(
p2 = (t2)p;
-memset(p2, 0, sizeof(*p));
|
-memset(p, 0, sizeof(*p));
)
@@
expression skb, len;
@@
-memset(skb_put(skb, len), 0, len);
+skb_put_zero(skb, len);
Apply it to the tree (with one manual fixup to keep the
comment in vxlan.c, which spatch removed.)
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2017-06-16 14:29:19 +02:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
2017-02-20 08:41:16 -08:00
|
|
|
|
2017-11-11 19:58:50 +08:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
2017-11-11 19:58:50 +08:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-04-02 11:00:06 +02:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
2014-08-22 21:34:16 +02:00
|
|
|
|
vxlan: fix nonfunctional neigh_reduce()
The VXLAN neigh_reduce() code is completely non-functional since
check-in. Specific errors:
1) The original code drops all packets with a multicast destination address,
even though neighbor solicitations are sent to the solicited-node
address, a multicast address. The code after this check was never run.
2) The neighbor table lookup used the IPv6 header destination, which is the
solicited node address, rather than the target address from the
neighbor solicitation. So neighbor lookups would always fail if it
got this far. Also for L3MISSes.
3) The code calls ndisc_send_na(), which does a send on the tunnel device.
The context for neigh_reduce() is the transmit path, vxlan_xmit(),
where the host or a bridge-attached neighbor is trying to transmit
a neighbor solicitation. To respond to it, the tunnel endpoint needs
to do a *receive* of the appropriate neighbor advertisement. Doing a
send, would only try to send the advertisement, encapsulated, to the
remote destinations in the fdb -- hosts that definitely did not do the
corresponding solicitation.
4) The code uses the tunnel endpoint IPv6 forwarding flag to determine the
isrouter flag in the advertisement. This has nothing to do with whether
or not the target is a router, and generally won't be set since the
tunnel endpoint is bridging, not routing, traffic.
The patch below creates a proxy neighbor advertisement to respond to
neighbor solicitions as intended, providing proper IPv6 support for neighbor
reduction.
Signed-off-by: David L Stevens <dlstevens@us.ibm.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-03-24 10:39:58 -04:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:34 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2014-08-22 21:34:16 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2013-08-31 13:44:34 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2013-08-31 13:44:34 +08:00
|
|
|
|
|
|
|
|
|
2014-08-22 21:34:16 +02:00
|
|
|
|
2013-08-31 13:44:34 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
drivers/net: Convert uses of compare_ether_addr to ether_addr_equal
Use the new bool function ether_addr_equal to add
some clarity and reduce the likelihood for misuse
of compare_ether_addr for sorting.
Done via cocci script: (and a little typing)
$ cat compare_ether_addr.cocci
@@
expression a,b;
@@
- !compare_ether_addr(a, b)
+ ether_addr_equal(a, b)
@@
expression a,b;
@@
- compare_ether_addr(a, b)
+ !ether_addr_equal(a, b)
@@
expression a,b;
@@
- !ether_addr_equal(a, b) == 0
+ ether_addr_equal(a, b)
@@
expression a,b;
@@
- !ether_addr_equal(a, b) != 0
+ !ether_addr_equal(a, b)
@@
expression a,b;
@@
- ether_addr_equal(a, b) == 0
+ !ether_addr_equal(a, b)
@@
expression a,b;
@@
- ether_addr_equal(a, b) != 0
+ ether_addr_equal(a, b)
@@
expression a,b;
@@
- !!ether_addr_equal(a, b)
+ ether_addr_equal(a, b)
Signed-off-by: Joe Perches <joe@perches.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2013-09-01 11:51:23 -07:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-20 11:23:05 -08:00
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-02-04 17:00:04 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-28 21:43:22 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:16 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:15 +01:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2015-01-20 11:23:05 -08:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-11 20:57:17 +00:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:52 -08:00
|
|
|
|
2013-08-19 11:23:22 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2013-08-19 11:23:22 -07:00
|
|
|
|
2016-04-14 15:33:37 -04:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2015-04-09 11:19:14 -07:00
|
|
|
|
networking: make skb_push & __skb_push return void pointers
It seems like a historic accident that these return unsigned char *,
and in many places that means casts are required, more often than not.
Make these functions return void * and remove all the casts across
the tree, adding a (u8 *) cast only where the unsigned char pointer
was used directly, all done with the following spatch:
@@
expression SKB, LEN;
typedef u8;
identifier fn = { skb_push, __skb_push, skb_push_rcsum };
@@
- *(fn(SKB, LEN))
+ *(u8 *)fn(SKB, LEN)
@@
expression E, SKB, LEN;
identifier fn = { skb_push, __skb_push, skb_push_rcsum };
type T;
@@
- E = ((T *)(fn(SKB, LEN)))
+ E = fn(SKB, LEN)
@@
expression SKB, LEN;
identifier fn = { skb_push, __skb_push, skb_push_rcsum };
@@
- fn(SKB, LEN)[0]
+ *(u8 *)fn(SKB, LEN)
Note that the last part there converts from push(...)[0] to the
more idiomatic *(u8 *)push(...).
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2017-06-16 14:29:23 +02:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
|
|
|
|
|
2013-08-19 11:23:17 -07:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-20 11:23:05 -08:00
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2015-12-24 14:34:54 -08:00
|
|
|
|
2013-08-19 11:23:17 -07:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
2017-01-11 15:18:53 +00:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2017-01-11 15:18:53 +00:00
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
2016-11-13 20:43:53 -08:00
|
|
|
|
2016-03-04 15:15:08 +01:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
2017-01-11 15:18:53 +00:00
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-04 15:15:08 +01:00
|
|
|
|
|
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2016-03-18 18:37:57 +01:00
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
2017-01-11 15:18:53 +00:00
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
2016-02-12 15:43:56 +01:00
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
2014-01-04 13:57:59 +08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2014-10-16 08:49:41 +08:00
|
|
|
|
|
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
2014-01-04 13:57:59 +08:00
|
|
|
|
|
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-06-19 10:03:59 +02:00
|
|
|
|
|
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-10-16 08:49:41 +08:00
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-10-16 08:49:41 +08:00
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
|
|
|
|
|
2014-10-16 08:49:41 +08:00
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-12 15:43:57 +01:00
|
|
|
|
2015-07-21 10:44:00 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2013-06-17 17:49:56 -07:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2016-02-02 18:09:15 +01:00
|
|
|
|
2016-02-02 18:09:16 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-08-20 13:56:25 +02:00
|
|
|
|
2015-07-21 10:44:00 +02:00
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2017-02-24 17:47:11 +00:00
|
|
|
|
2016-02-12 15:43:57 +01:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2015-08-20 13:56:30 +02:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
|
|
|
|
|
2015-08-20 13:56:30 +02:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:43:58 +02:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2016-02-12 15:43:57 +01:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
|
|
|
|
|
2015-08-20 13:56:30 +02:00
|
|
|
|
|
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2016-02-02 18:09:15 +01:00
|
|
|
|
2015-08-20 13:56:30 +02:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
|
|
|
|
|
2015-08-20 13:56:30 +02:00
|
|
|
|
2017-02-24 11:43:36 -08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2017-02-24 17:47:11 +00:00
|
|
|
|
2017-01-11 15:18:53 +00:00
|
|
|
|
2016-02-12 15:43:57 +01:00
|
|
|
|
2016-11-15 16:32:11 -05:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2016-11-15 16:32:11 -05:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2017-02-24 11:43:36 -08:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2016-02-19 11:26:31 -08:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2016-02-19 11:26:31 -08:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2017-12-18 14:20:56 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2018-01-25 19:03:03 +01:00
|
|
|
|
2017-12-18 14:20:56 +08:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2016-02-02 18:09:16 +01:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2016-02-02 18:09:16 +01:00
|
|
|
|
2017-02-24 17:47:11 +00:00
|
|
|
|
2016-02-02 18:09:16 +01:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2017-02-24 17:47:11 +00:00
|
|
|
|
2017-01-11 15:18:53 +00:00
|
|
|
|
bpf, vxlan, geneve, gre: fix usage of dst_cache on xmit
The assumptions from commit 0c1d70af924b ("net: use dst_cache for vxlan
device"), 468dfffcd762 ("geneve: add dst caching support") and 3c1cb4d2604c
("net/ipv4: add dst cache support for gre lwtunnels") on dst_cache usage
when ip_tunnel_info is used is unfortunately not always valid as assumed.
While it seems correct for ip_tunnel_info front-ends such as OVS, eBPF
however can fill in ip_tunnel_info for consumers like vxlan, geneve or gre
with different remote dsts, tos, etc, therefore they cannot be assumed as
packet independent.
Right now vxlan, geneve, gre would cache the dst for eBPF and every packet
would reuse the same entry that was first created on the initial route
lookup. eBPF doesn't store/cache the ip_tunnel_info, so each skb may have
a different one.
Fix it by adding a flag that checks the ip_tunnel_info. Also the !tos test
in vxlan needs to be handeled differently in this context as it is currently
inferred from ip_tunnel_info as well if present. ip_tunnel_dst_cache_usable()
helper is added for the three tunnel cases, which checks if we can use dst
cache.
Fixes: 0c1d70af924b ("net: use dst_cache for vxlan device")
Fixes: 468dfffcd762 ("geneve: add dst caching support")
Fixes: 3c1cb4d2604c ("net/ipv4: add dst cache support for gre lwtunnels")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Paolo Abeni <pabeni@redhat.com>
Acked-by: Hannes Frederic Sowa <hannes@stressinduktion.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-03-04 15:15:07 +01:00
|
|
|
|
2015-12-07 13:04:30 +01:00
|
|
|
|
2016-11-15 16:32:11 -05:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2013-04-02 12:31:52 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
|
|
|
|
|
2013-08-19 11:23:17 -07:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2017-02-24 11:43:36 -08:00
|
|
|
|
2016-11-13 20:43:56 -08:00
|
|
|
|
2016-01-20 16:22:47 -08:00
|
|
|
|
2017-12-18 14:20:56 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2018-01-25 19:03:03 +01:00
|
|
|
|
2017-12-18 14:20:56 +08:00
|
|
|
|
|
|
|
|
|
2016-03-04 15:15:08 +01:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2016-02-02 18:09:16 +01:00
|
|
|
|
|
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:57 -08:00
|
|
|
|
2017-02-24 17:47:11 +00:00
|
|
|
|
2016-08-05 17:45:36 -07:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2017-02-24 11:43:36 -08:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-02-24 11:43:36 -08:00
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-11-13 20:43:54 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-11-11 19:58:50 +08:00
|
|
|
|
2015-07-21 10:44:00 +02:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2017-11-11 19:58:50 +08:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2015-08-20 13:56:25 +02:00
|
|
|
|
2015-07-21 10:44:00 +02:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-05 14:47:11 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2016-04-05 14:47:11 +02:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
2017-11-11 19:58:50 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-04-02 11:00:06 +02:00
|
|
|
|
2013-08-31 13:44:36 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2016-04-05 14:47:11 +02:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2013-08-31 13:44:34 +08:00
|
|
|
|
|
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-04-19 00:36:26 +00:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-06 09:54:31 -08:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
2014-01-06 09:54:31 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2014-01-06 09:54:31 -08:00
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2014-01-06 09:54:31 -08:00
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2013-03-15 04:35:51 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-10-04 16:26:59 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-10-04 16:26:59 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-05-26 10:42:04 +03:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-23 20:44:33 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-03-27 15:46:41 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-05-26 10:42:04 +03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-02 03:24:08 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-02 03:24:08 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
|
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-02-13 11:46:28 -08:00
|
|
|
|
2013-03-25 14:49:46 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-31 22:59:52 -08:00
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-12-10 16:37:32 +08:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-08-25 20:22:35 -03:00
|
|
|
|
|
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-23 20:44:32 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-05-27 22:35:52 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-23 20:44:32 -08:00
|
|
|
|
|
|
|
|
|
2013-06-25 16:01:51 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-24 10:02:49 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-03-23 16:23:12 -03:00
|
|
|
|
2015-04-08 14:48:30 -07:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-23 20:44:32 -08:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
2013-12-18 00:21:08 +01:00
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
2013-12-18 00:21:08 +01:00
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-10 00:05:55 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-12-18 00:21:08 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-22 18:17:16 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:31 +01:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
2017-02-17 19:14:27 +01:00
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:31 +01:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:53 -08:00
|
|
|
|
2015-12-07 13:04:31 +01:00
|
|
|
|
|
|
|
|
|
2016-11-13 20:43:55 -08:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2017-02-17 19:14:27 +01:00
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:31 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-02-02 18:09:14 +01:00
|
|
|
|
|
|
|
|
|
2015-12-07 13:04:31 +01:00
|
|
|
|
2015-10-22 18:17:16 -07:00
|
|
|
|
|
|
|
|
|
2016-04-05 14:47:10 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-25 14:49:46 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-12-18 00:21:08 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-10-22 18:17:16 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-07-11 13:12:28 +02:00
|
|
|
|
2013-09-13 07:34:13 -07:00
|
|
|
|
2016-07-11 13:12:28 +02:00
|
|
|
|
2013-09-04 02:13:38 -07:00
|
|
|
|
2017-07-21 12:49:32 +02:00
|
|
|
|
2013-09-04 02:13:38 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-13 07:34:13 -07:00
|
|
|
|
2013-09-04 02:13:38 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-21 12:49:32 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-04 02:13:38 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-27 22:35:52 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-04-28 16:36:30 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
net: Fix inconsistent teardown and release of private netdev state.
Network devices can allocate reasources and private memory using
netdev_ops->ndo_init(). However, the release of these resources
can occur in one of two different places.
Either netdev_ops->ndo_uninit() or netdev->destructor().
The decision of which operation frees the resources depends upon
whether it is necessary for all netdev refs to be released before it
is safe to perform the freeing.
netdev_ops->ndo_uninit() presumably can occur right after the
NETDEV_UNREGISTER notifier completes and the unicast and multicast
address lists are flushed.
netdev->destructor(), on the other hand, does not run until the
netdev references all go away.
Further complicating the situation is that netdev->destructor()
almost universally does also a free_netdev().
This creates a problem for the logic in register_netdevice().
Because all callers of register_netdevice() manage the freeing
of the netdev, and invoke free_netdev(dev) if register_netdevice()
fails.
If netdev_ops->ndo_init() succeeds, but something else fails inside
of register_netdevice(), it does call ndo_ops->ndo_uninit(). But
it is not able to invoke netdev->destructor().
This is because netdev->destructor() will do a free_netdev() and
then the caller of register_netdevice() will do the same.
However, this means that the resources that would normally be released
by netdev->destructor() will not be.
Over the years drivers have added local hacks to deal with this, by
invoking their destructor parts by hand when register_netdevice()
fails.
Many drivers do not try to deal with this, and instead we have leaks.
Let's close this hole by formalizing the distinction between what
private things need to be freed up by netdev->destructor() and whether
the driver needs unregister_netdevice() to perform the free_netdev().
netdev->priv_destructor() performs all actions to free up the private
resources that used to be freed by netdev->destructor(), except for
free_netdev().
netdev->needs_free_netdev is a boolean that indicates whether
free_netdev() should be done at the end of unregister_netdevice().
Now, register_netdevice() can sanely release all resources after
ndo_ops->ndo_init() succeeds, by invoking both ndo_ops->ndo_uninit()
and netdev->priv_destructor().
And at the end of unregister_netdevice(), we invoke
netdev->priv_destructor() and optionally call free_netdev().
Signed-off-by: David S. Miller <davem@davemloft.net>
2017-05-08 12:52:56 -04:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-12-07 14:14:16 +00:00
|
|
|
|
2012-12-07 14:14:18 +00:00
|
|
|
|
2013-03-07 13:22:36 +00:00
|
|
|
|
2012-12-07 14:14:18 +00:00
|
|
|
|
2013-08-19 11:23:29 -07:00
|
|
|
|
2012-12-07 14:14:18 +00:00
|
|
|
|
2013-03-07 13:22:36 +00:00
|
|
|
|
2014-10-05 18:38:35 -07:00
|
|
|
|
2016-04-05 14:47:10 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-10-04 16:26:59 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-19 17:07:33 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-05 14:47:10 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
2016-04-28 16:36:30 +02:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-04-27 11:31:55 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-30 20:10:22 -07:00
|
|
|
|
2013-04-27 11:31:57 +00:00
|
|
|
|
2014-11-06 18:06:01 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2015-02-10 16:30:32 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-06-25 23:56:01 +02:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-06-27 14:42:43 +02:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-01-29 23:43:07 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
|
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-11-24 20:08:38 -08:00
|
|
|
|
2015-08-28 20:48:22 +02:00
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-10-28 14:01:48 +08:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-09-16 17:31:18 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2014-01-20 13:59:21 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-13 19:49:42 -07:00
|
|
|
|
2013-10-28 14:01:48 +08:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2013-11-01 13:09:43 +08:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2017-07-04 15:52:59 +03:00
|
|
|
|
2015-01-20 11:23:05 -08:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
|
|
|
|
|
2016-06-16 12:20:52 -07:00
|
|
|
|
2016-06-16 12:23:19 -07:00
|
|
|
|
|
|
|
|
|
2016-06-16 12:20:52 -07:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2016-04-05 08:22:53 -07:00
|
|
|
|
2014-09-16 17:31:18 -07:00
|
|
|
|
|
|
|
|
|
2016-02-23 18:02:58 +01:00
|
|
|
|
2014-09-16 17:31:18 -07:00
|
|
|
|
2016-04-05 08:22:53 -07:00
|
|
|
|
|
|
|
|
|
2014-09-16 17:31:18 -07:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
|
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2013-08-19 11:22:48 -07:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-07-04 15:52:59 +03:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2015-03-18 14:50:44 -03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2017-07-02 19:00:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:01 +02:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
|
|
|
|
|
2017-04-27 21:24:35 +02:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2016-10-28 09:59:15 -07:00
|
|
|
|
2017-04-27 21:24:35 +02:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2017-04-27 21:24:35 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
2017-04-27 21:24:35 +02:00
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-01-26 22:28:14 +01:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2016-09-02 13:37:12 +02:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2016-04-05 14:47:10 +02:00
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-17 16:11:11 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-17 16:11:11 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:53 +00:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:53 +00:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2012-11-13 13:10:59 +00:00
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-06-19 10:03:58 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2015-09-17 16:11:10 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-03-29 17:56:43 -07:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:04:00 +02:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-30 15:50:00 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-30 15:50:00 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
net: use core MTU range checking in core net infra
geneve:
- Merge __geneve_change_mtu back into geneve_change_mtu, set max_mtu
- This one isn't quite as straight-forward as others, could use some
closer inspection and testing
macvlan:
- set min/max_mtu
tun:
- set min/max_mtu, remove tun_net_change_mtu
vxlan:
- Merge __vxlan_change_mtu back into vxlan_change_mtu
- Set max_mtu to IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
- This one is also not as straight-forward and could use closer inspection
and testing from vxlan folks
bridge:
- set max_mtu of IP_MAX_MTU and retain dynamic MTU range checks in
change_mtu function
openvswitch:
- set min/max_mtu, remove internal_dev_change_mtu
- note: max_mtu wasn't checked previously, it's been set to 65535, which
is the largest possible size supported
sch_teql:
- set min/max_mtu (note: max_mtu previously unchecked, used max of 65535)
macsec:
- min_mtu = 0, max_mtu = 65535
macvlan:
- min_mtu = 0, max_mtu = 65535
ntb_netdev:
- min_mtu = 0, max_mtu = 65535
veth:
- min_mtu = 68, max_mtu = 65535
8021q:
- min_mtu = 0, max_mtu = 65535
CC: netdev@vger.kernel.org
CC: Nicolas Dichtel <nicolas.dichtel@6wind.com>
CC: Hannes Frederic Sowa <hannes@stressinduktion.org>
CC: Tom Herbert <tom@herbertland.com>
CC: Daniel Borkmann <daniel@iogearbox.net>
CC: Alexander Duyck <alexander.h.duyck@intel.com>
CC: Paolo Abeni <pabeni@redhat.com>
CC: Jiri Benc <jbenc@redhat.com>
CC: WANG Cong <xiyou.wangcong@gmail.com>
CC: Roopa Prabhu <roopa@cumulusnetworks.com>
CC: Pravin B Shelar <pshelar@ovn.org>
CC: Sabrina Dubroca <sd@queasysnail.net>
CC: Patrick McHardy <kaber@trash.net>
CC: Stephen Hemminger <stephen@networkplumber.org>
CC: Pravin Shelar <pshelar@nicira.com>
CC: Maxim Krasnyansky <maxk@qti.qualcomm.com>
Signed-off-by: Jarod Wilson <jarod@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-10-20 13:55:20 -04:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2017-12-14 20:20:00 +03:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan, gre, geneve: Set a large MTU on ovs-created tunnel devices
Prior to 4.3, openvswitch tunnel vports (vxlan, gre and geneve) could
transmit vxlan packets of any size, constrained only by the ability to
send out the resulting packets. 4.3 introduced netdevs corresponding
to tunnel vports. These netdevs have an MTU, which limits the size of
a packet that can be successfully encapsulated. The default MTU
values are low (1500 or less), which is awkwardly small in the context
of physical networks supporting jumbo frames, and leads to a
conspicuous change in behaviour for userspace.
Instead, set the MTU on openvswitch-created netdevs to be the relevant
maximum (i.e. the maximum IP packet size minus any relevant overhead),
effectively restoring the behaviour prior to 4.3.
Signed-off-by: David Wragg <david@weave.works>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-02-10 00:05:58 +00:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-24 13:50:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-06-19 10:03:55 +02:00
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2017-06-30 15:50:00 +02:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-03-13 16:24:03 +01:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
|
|
|
|
|
2017-03-13 16:24:03 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-03-13 16:24:03 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2015-10-16 16:36:00 -07:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2012-10-30 10:27:16 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2012-10-30 10:27:16 +00:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-07-30 20:10:22 -07:00
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-27 11:31:57 +00:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-25 23:55:59 +02:00
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2017-06-25 23:56:00 +02:00
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
2015-02-10 16:30:32 -08:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-05-27 10:49:11 +08:00
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-01-23 20:44:32 -08:00
|
|
|
|
|
|
|
|
|
2015-08-19 17:07:33 -07:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-04 22:51:07 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-16 02:50:52 +00:00
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2016-02-16 21:58:58 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
|
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-04-16 02:50:52 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-29 16:59:25 +02:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
2013-08-31 13:44:33 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
2016-03-09 03:00:03 +01:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2012-11-20 02:50:14 +00:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2015-08-04 22:51:07 -07:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2015-07-21 10:44:02 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2014-06-04 17:20:29 -07:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2015-01-12 17:00:38 -08:00
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2012-10-09 20:35:50 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
vxlan: Group Policy extension
Implements supports for the Group Policy VXLAN extension [0] to provide
a lightweight and simple security label mechanism across network peers
based on VXLAN. The security context and associated metadata is mapped
to/from skb->mark. This allows further mapping to a SELinux context
using SECMARK, to implement ACLs directly with nftables, iptables, OVS,
tc, etc.
The group membership is defined by the lower 16 bits of skb->mark, the
upper 16 bits are used for flags.
SELinux allows to manage label to secure local resources. However,
distributed applications require ACLs to implemented across hosts. This
is typically achieved by matching on L2-L4 fields to identify the
original sending host and process on the receiver. On top of that,
netlabel and specifically CIPSO [1] allow to map security contexts to
universal labels. However, netlabel and CIPSO are relatively complex.
This patch provides a lightweight alternative for overlay network
environments with a trusted underlay. No additional control protocol
is required.
Host 1: Host 2:
Group A Group B Group B Group A
+-----+ +-------------+ +-------+ +-----+
| lxc | | SELinux CTX | | httpd | | VM |
+--+--+ +--+----------+ +---+---+ +--+--+
\---+---/ \----+---/
| |
+---+---+ +---+---+
| vxlan | | vxlan |
+---+---+ +---+---+
+------------------------------+
Backwards compatibility:
A VXLAN-GBP socket can receive standard VXLAN frames and will assign
the default group 0x0000 to such frames. A Linux VXLAN socket will
drop VXLAN-GBP frames. The extension is therefore disabled by default
and needs to be specifically enabled:
ip link add [...] type vxlan [...] gbp
In a mixed environment with VXLAN and VXLAN-GBP sockets, the GBP socket
must run on a separate port number.
Examples:
iptables:
host1# iptables -I OUTPUT -m owner --uid-owner 101 -j MARK --set-mark 0x200
host2# iptables -I INPUT -m mark --mark 0x200 -j DROP
OVS:
# ovs-ofctl add-flow br0 'in_port=1,actions=load:0x200->NXM_NX_TUN_GBP_ID[],NORMAL'
# ovs-ofctl add-flow br0 'in_port=2,tun_gbp_id=0x200,actions=drop'
[0] https://tools.ietf.org/html/draft-smith-vxlan-group-policy
[1] http://lwn.net/Articles/204905/
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-01-15 03:53:55 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
vxlan: implement GPE
Implement VXLAN-GPE. Only COLLECT_METADATA is supported for now (it is
possible to support static configuration, too, if there is demand for it).
The GPE header parsing has to be moved before iptunnel_pull_header, as we
need to know the protocol.
v2: Removed what was called "L2 mode" in v1 of the patchset. Only "L3 mode"
(now called "raw mode") is added by this patch. This mode does not allow
Ethernet header to be encapsulated in VXLAN-GPE when using ip route to
specify the encapsulation, IP header is encapsulated instead. The patch
does support Ethernet to be encapsulated, though, using ETH_P_TEB in
skb->protocol. This will be utilized by other COLLECT_METADATA users
(openvswitch in particular).
If there is ever demand for Ethernet encapsulation with VXLAN-GPE using
ip route, it's easy to add a new flag switching the interface to
"Ethernet mode" (called "L2 mode" in v1 of this patchset). For now,
leave this out, it seems we don't need it.
Disallowed more flag combinations, especially RCO with GPE.
Added comment explaining that GBP and GPE cannot be set together.
Signed-off-by: Jiri Benc <jbenc@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2016-04-05 14:47:13 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-06-19 10:03:56 +02:00
|
|
|
|
2015-02-10 16:30:32 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-15 15:11:17 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-02-20 08:29:19 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-01-15 15:11:17 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2016-06-13 10:31:05 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-08-11 15:20:59 -07:00
|
|
|
|
2016-06-13 10:31:05 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-18 21:19:47 +02:00
|
|
|
|
|
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
|
|
|
|
|
net: vxlan: convert to act as a pernet subsystem
As per suggestion from Eric W. Biederman, vxlan should be using
{un,}register_pernet_subsys() instead of {un,}register_pernet_device()
to ensure the vxlan_net structure is initialized before and cleaned
up after all network devices in a given network namespace i.e. when
dealing with network notifiers. This is similarly handeled already in
commit 91e2ff3528ac ("net: Teach vlans to cleanup as a pernet subsystem")
and, thus, improves upon fd27e0d44a89 ("net: vxlan: do not use vxlan_net
before checking event type"). Just as in 91e2ff3528ac, we do not need
to explicitly handle deletion of vxlan devices as network namespace
exit calls dellink on all remaining virtual devices, and
rtnl_link_unregister() calls dellink on all outstanding devices in that
network namespace, so we can entirely drop the pernet exit operation
as well. Moreover, on vxlan module exit, rcu_barrier() is called by
netns since commit 3a765edadb28 ("netns: Add an explicit rcu_barrier
to unregister_pernet_{device|subsys}"), so this may be omitted. Tested
with various scenarios and works well on my side.
Suggested-by: Eric W. Biederman <ebiederm@xmission.com>
Cc: Jesse Brandeburg <jesse.brandeburg@intel.com>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-01-22 21:07:53 +01:00
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
2017-07-21 12:49:33 +02:00
|
|
|
|
|
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
2017-07-21 12:49:33 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-07-21 12:49:32 +02:00
|
|
|
|
2017-07-21 12:49:33 +02:00
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-18 21:19:47 +02:00
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-27 22:35:52 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
2013-06-17 14:16:11 -07:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2013-05-16 11:35:20 +00:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-12-16 17:54:49 +08:00
|
|
|
|
2014-04-24 10:02:49 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-11-12 22:28:10 +03:00
|
|
|
|
2014-04-24 10:02:49 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2017-12-16 17:54:49 +08:00
|
|
|
|
2014-04-24 10:02:49 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-08-19 17:07:33 -07:00
|
|
|
|
|
|
|
|
|
2017-12-16 17:54:49 +08:00
|
|
|
|
2015-08-19 17:07:33 -07:00
|
|
|
|
2014-04-24 10:02:49 +02:00
|
|
|
|
|
|
|
|
|
2017-11-12 22:28:10 +03:00
|
|
|
|
|
|
|
|
|
2014-04-24 10:02:49 +02:00
|
|
|
|
|
|
|
|
|
2017-12-16 17:54:49 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
2017-12-16 17:54:49 +08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
net: vxlan: convert to act as a pernet subsystem
As per suggestion from Eric W. Biederman, vxlan should be using
{un,}register_pernet_subsys() instead of {un,}register_pernet_device()
to ensure the vxlan_net structure is initialized before and cleaned
up after all network devices in a given network namespace i.e. when
dealing with network notifiers. This is similarly handeled already in
commit 91e2ff3528ac ("net: Teach vlans to cleanup as a pernet subsystem")
and, thus, improves upon fd27e0d44a89 ("net: vxlan: do not use vxlan_net
before checking event type"). Just as in 91e2ff3528ac, we do not need
to explicitly handle deletion of vxlan devices as network namespace
exit calls dellink on all remaining virtual devices, and
rtnl_link_unregister() calls dellink on all outstanding devices in that
network namespace, so we can entirely drop the pernet exit operation
as well. Moreover, on vxlan module exit, rcu_barrier() is called by
netns since commit 3a765edadb28 ("netns: Add an explicit rcu_barrier
to unregister_pernet_{device|subsys}"), so this may be omitted. Tested
with various scenarios and works well on my side.
Suggested-by: Eric W. Biederman <ebiederm@xmission.com>
Cc: Jesse Brandeburg <jesse.brandeburg@intel.com>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-01-22 21:07:53 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
net: vxlan: convert to act as a pernet subsystem
As per suggestion from Eric W. Biederman, vxlan should be using
{un,}register_pernet_subsys() instead of {un,}register_pernet_device()
to ensure the vxlan_net structure is initialized before and cleaned
up after all network devices in a given network namespace i.e. when
dealing with network notifiers. This is similarly handeled already in
commit 91e2ff3528ac ("net: Teach vlans to cleanup as a pernet subsystem")
and, thus, improves upon fd27e0d44a89 ("net: vxlan: do not use vxlan_net
before checking event type"). Just as in 91e2ff3528ac, we do not need
to explicitly handle deletion of vxlan devices as network namespace
exit calls dellink on all remaining virtual devices, and
rtnl_link_unregister() calls dellink on all outstanding devices in that
network namespace, so we can entirely drop the pernet exit operation
as well. Moreover, on vxlan module exit, rcu_barrier() is called by
netns since commit 3a765edadb28 ("netns: Add an explicit rcu_barrier
to unregister_pernet_{device|subsys}"), so this may be omitted. Tested
with various scenarios and works well on my side.
Suggested-by: Eric W. Biederman <ebiederm@xmission.com>
Cc: Jesse Brandeburg <jesse.brandeburg@intel.com>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-01-22 21:07:53 +01:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-27 22:35:53 +00:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-06-17 14:16:09 -07:00
|
|
|
|
2014-01-13 18:41:19 +01:00
|
|
|
|
net: vxlan: convert to act as a pernet subsystem
As per suggestion from Eric W. Biederman, vxlan should be using
{un,}register_pernet_subsys() instead of {un,}register_pernet_device()
to ensure the vxlan_net structure is initialized before and cleaned
up after all network devices in a given network namespace i.e. when
dealing with network notifiers. This is similarly handeled already in
commit 91e2ff3528ac ("net: Teach vlans to cleanup as a pernet subsystem")
and, thus, improves upon fd27e0d44a89 ("net: vxlan: do not use vxlan_net
before checking event type"). Just as in 91e2ff3528ac, we do not need
to explicitly handle deletion of vxlan devices as network namespace
exit calls dellink on all remaining virtual devices, and
rtnl_link_unregister() calls dellink on all outstanding devices in that
network namespace, so we can entirely drop the pernet exit operation
as well. Moreover, on vxlan module exit, rcu_barrier() is called by
netns since commit 3a765edadb28 ("netns: Add an explicit rcu_barrier
to unregister_pernet_{device|subsys}"), so this may be omitted. Tested
with various scenarios and works well on my side.
Suggested-by: Eric W. Biederman <ebiederm@xmission.com>
Cc: Jesse Brandeburg <jesse.brandeburg@intel.com>
Cc: Eric W. Biederman <ebiederm@xmission.com>
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2014-01-22 21:07:53 +01:00
|
|
|
|
|
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-27 11:31:52 +00:00
|
|
|
|
2014-01-17 11:00:33 -08:00
|
|
|
|
2012-10-01 12:32:35 +00:00
|
|
|
|