blob: 439b084d299e4005f89d2d819a151c31422ba3c9 [file] [log] [blame]
Jian Li4f368e82018-07-02 14:22:22 +09001/*
2 * Copyright 2018-present Open Networking Foundation
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16package org.onosproject.openstackvtap.impl;
17
Jian Li614cb092018-07-03 22:41:42 +090018import com.google.common.collect.ImmutableList;
19import com.google.common.collect.ImmutableSet;
20import com.google.common.collect.Lists;
Jian Li26ef1302018-07-04 14:37:06 +090021import com.google.common.collect.Sets;
Jian Li26ef1302018-07-04 14:37:06 +090022import org.onlab.packet.IpAddress;
Jian Li614cb092018-07-03 22:41:42 +090023import org.onlab.packet.IpPrefix;
Jimo Jung14e87bf2018-09-03 16:28:13 +090024import org.onlab.util.Tools;
25import org.onosproject.cfg.ComponentConfigService;
Jian Li614cb092018-07-03 22:41:42 +090026import org.onosproject.cluster.ClusterService;
27import org.onosproject.cluster.LeadershipService;
28import org.onosproject.cluster.NodeId;
29import org.onosproject.core.ApplicationId;
30import org.onosproject.core.CoreService;
31import org.onosproject.core.GroupId;
Jian Li19f25262018-07-03 22:37:12 +090032import org.onosproject.event.AbstractListenerManager;
Jian Li26ef1302018-07-04 14:37:06 +090033import org.onosproject.net.Device;
Jian Li38e4d942018-07-03 22:19:16 +090034import org.onosproject.net.DeviceId;
Jian Li614cb092018-07-03 22:41:42 +090035import org.onosproject.net.Host;
36import org.onosproject.net.HostLocation;
Jimo Jung14e87bf2018-09-03 16:28:13 +090037import org.onosproject.net.Port;
Jian Li19f25262018-07-03 22:37:12 +090038import org.onosproject.net.PortNumber;
Jimo Jung14e87bf2018-09-03 16:28:13 +090039import org.onosproject.net.behaviour.DefaultTunnelDescription;
Jian Li614cb092018-07-03 22:41:42 +090040import org.onosproject.net.behaviour.ExtensionTreatmentResolver;
Jimo Jung14e87bf2018-09-03 16:28:13 +090041import org.onosproject.net.behaviour.InterfaceConfig;
42import org.onosproject.net.behaviour.TunnelDescription;
43import org.onosproject.net.behaviour.TunnelEndPoints;
44import org.onosproject.net.behaviour.TunnelKey;
Jian Li614cb092018-07-03 22:41:42 +090045import org.onosproject.net.device.DeviceEvent;
46import org.onosproject.net.device.DeviceListener;
47import org.onosproject.net.device.DeviceService;
Jian Li614cb092018-07-03 22:41:42 +090048import org.onosproject.net.flow.DefaultFlowRule;
49import org.onosproject.net.flow.DefaultTrafficSelector;
50import org.onosproject.net.flow.DefaultTrafficTreatment;
51import org.onosproject.net.flow.FlowRule;
52import org.onosproject.net.flow.FlowRuleOperations;
53import org.onosproject.net.flow.FlowRuleOperationsContext;
54import org.onosproject.net.flow.FlowRuleService;
55import org.onosproject.net.flow.TrafficSelector;
56import org.onosproject.net.flow.TrafficTreatment;
Jimo Jung14e87bf2018-09-03 16:28:13 +090057import org.onosproject.net.flow.instructions.ExtensionPropertyException;
Jian Li614cb092018-07-03 22:41:42 +090058import org.onosproject.net.flow.instructions.ExtensionTreatment;
Jian Li614cb092018-07-03 22:41:42 +090059import org.onosproject.net.group.DefaultGroupBucket;
60import org.onosproject.net.group.DefaultGroupDescription;
Jian Li614cb092018-07-03 22:41:42 +090061import org.onosproject.net.group.GroupBucket;
62import org.onosproject.net.group.GroupBuckets;
63import org.onosproject.net.group.GroupDescription;
Jian Li614cb092018-07-03 22:41:42 +090064import org.onosproject.net.group.GroupService;
65import org.onosproject.net.host.HostEvent;
66import org.onosproject.net.host.HostListener;
67import org.onosproject.net.host.HostService;
Jimo Jung14e87bf2018-09-03 16:28:13 +090068import org.onosproject.openstacknode.api.OpenstackNode;
Jian Li26ef1302018-07-04 14:37:06 +090069import org.onosproject.openstacknode.api.OpenstackNodeEvent;
70import org.onosproject.openstacknode.api.OpenstackNodeListener;
71import org.onosproject.openstacknode.api.OpenstackNodeService;
Jian Li38e4d942018-07-03 22:19:16 +090072import org.onosproject.openstackvtap.api.OpenstackVtap;
Jian Li26ef1302018-07-04 14:37:06 +090073import org.onosproject.openstackvtap.api.OpenstackVtap.Type;
Jian Li19f25262018-07-03 22:37:12 +090074import org.onosproject.openstackvtap.api.OpenstackVtapAdminService;
75import org.onosproject.openstackvtap.api.OpenstackVtapCriterion;
76import org.onosproject.openstackvtap.api.OpenstackVtapEvent;
Jian Li26ef1302018-07-04 14:37:06 +090077import org.onosproject.openstackvtap.api.OpenstackVtapId;
Jian Li38e4d942018-07-03 22:19:16 +090078import org.onosproject.openstackvtap.api.OpenstackVtapListener;
Jimo Jung14e87bf2018-09-03 16:28:13 +090079import org.onosproject.openstackvtap.api.OpenstackVtapNetwork;
80import org.onosproject.openstackvtap.api.OpenstackVtapNetwork.Mode;
Jian Li4f368e82018-07-02 14:22:22 +090081import org.onosproject.openstackvtap.api.OpenstackVtapService;
Jian Li614cb092018-07-03 22:41:42 +090082import org.onosproject.openstackvtap.api.OpenstackVtapStore;
83import org.onosproject.openstackvtap.api.OpenstackVtapStoreDelegate;
Jian Li614cb092018-07-03 22:41:42 +090084import org.osgi.service.component.ComponentContext;
Ray Milkeyd84f89b2018-08-17 14:54:17 -070085import org.osgi.service.component.annotations.Activate;
86import org.osgi.service.component.annotations.Component;
87import org.osgi.service.component.annotations.Deactivate;
Ray Milkeyd5425682018-10-23 10:21:33 -070088import org.osgi.service.component.annotations.Modified;
Ray Milkeyd84f89b2018-08-17 14:54:17 -070089import org.osgi.service.component.annotations.Reference;
90import org.osgi.service.component.annotations.ReferenceCardinality;
Jian Li614cb092018-07-03 22:41:42 +090091import org.slf4j.Logger;
Jian Li4f368e82018-07-02 14:22:22 +090092
Jimo Jung14e87bf2018-09-03 16:28:13 +090093import java.util.Dictionary;
Jian Li614cb092018-07-03 22:41:42 +090094import java.util.List;
95import java.util.Objects;
Jian Li38e4d942018-07-03 22:19:16 +090096import java.util.Set;
Jian Li614cb092018-07-03 22:41:42 +090097import java.util.concurrent.ScheduledExecutorService;
Jian Li614cb092018-07-03 22:41:42 +090098import java.util.stream.Collectors;
99import java.util.stream.StreamSupport;
100
101import static com.google.common.base.Preconditions.checkNotNull;
102import static java.util.concurrent.Executors.newSingleThreadScheduledExecutor;
103import static org.onlab.packet.Ethernet.TYPE_IPV4;
104import static org.onlab.packet.IPv4.PROTOCOL_ICMP;
105import static org.onlab.packet.IPv4.PROTOCOL_TCP;
106import static org.onlab.packet.IPv4.PROTOCOL_UDP;
107import static org.onlab.util.Tools.groupedThreads;
Jimo Jung14e87bf2018-09-03 16:28:13 +0900108import static org.onosproject.net.AnnotationKeys.PORT_NAME;
Jian Li26ef1302018-07-04 14:37:06 +0900109import static org.onosproject.net.flow.instructions.ExtensionTreatmentType.ExtensionTreatmentTypes.NICIRA_RESUBMIT_TABLE;
Jimo Jung14e87bf2018-09-03 16:28:13 +0900110import static org.onosproject.net.flow.instructions.ExtensionTreatmentType.ExtensionTreatmentTypes.NICIRA_SET_TUNNEL_DST;
Jian Li5c09e212018-10-24 18:23:58 +0900111import static org.onosproject.openstacknetworking.api.Constants.DHCP_TABLE;
Jian Li614cb092018-07-03 22:41:42 +0900112import static org.onosproject.openstacknetworking.api.Constants.FLAT_TABLE;
113import static org.onosproject.openstacknetworking.api.Constants.FORWARDING_TABLE;
114import static org.onosproject.openstacknetworking.api.Constants.VTAP_FLAT_OUTBOUND_GROUP_TABLE;
115import static org.onosproject.openstacknetworking.api.Constants.VTAP_FLAT_OUTBOUND_MIRROR_TABLE;
116import static org.onosproject.openstacknetworking.api.Constants.VTAP_FLAT_OUTBOUND_TABLE;
117import static org.onosproject.openstacknetworking.api.Constants.VTAP_INBOUND_GROUP_TABLE;
118import static org.onosproject.openstacknetworking.api.Constants.VTAP_INBOUND_MIRROR_TABLE;
119import static org.onosproject.openstacknetworking.api.Constants.VTAP_INBOUND_TABLE;
120import static org.onosproject.openstacknetworking.api.Constants.VTAP_OUTBOUND_GROUP_TABLE;
121import static org.onosproject.openstacknetworking.api.Constants.VTAP_OUTBOUND_MIRROR_TABLE;
122import static org.onosproject.openstacknetworking.api.Constants.VTAP_OUTBOUND_TABLE;
Jimo Jung14e87bf2018-09-03 16:28:13 +0900123import static org.onosproject.openstacknode.api.Constants.INTEGRATION_BRIDGE;
124import static org.onosproject.openstacknode.api.NodeState.COMPLETE;
Jian Li26ef1302018-07-04 14:37:06 +0900125import static org.onosproject.openstacknode.api.OpenstackNode.NodeType.COMPUTE;
Ray Milkey8e406512018-10-24 15:56:50 -0700126import static org.onosproject.openstackvtap.impl.OsgiPropertyConstants.TUNNEL_NICIRA;
127import static org.onosproject.openstackvtap.impl.OsgiPropertyConstants.TUNNEL_NICRA_DEFAULT;
Jimo Jung14e87bf2018-09-03 16:28:13 +0900128import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.containsIp;
129import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.dumpStackTrace;
Jian Li26ef1302018-07-04 14:37:06 +0900130import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.getGroupKey;
Jimo Jung14e87bf2018-09-03 16:28:13 +0900131import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.getTunnelName;
132import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.getTunnelType;
133import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.hostCompareIp;
134import static org.onosproject.openstackvtap.util.OpenstackVtapUtil.isValidHost;
Jian Li614cb092018-07-03 22:41:42 +0900135import static org.slf4j.LoggerFactory.getLogger;
Jian Li38e4d942018-07-03 22:19:16 +0900136
Jian Li4f368e82018-07-02 14:22:22 +0900137/**
Jimo Jung14e87bf2018-09-03 16:28:13 +0900138 * Provides implementation of the openstack vtap and openstack vtap network APIs.
Jian Li4f368e82018-07-02 14:22:22 +0900139 */
Ray Milkey8e406512018-10-24 15:56:50 -0700140@Component(
141 immediate = true,
142 service = { OpenstackVtapService.class, OpenstackVtapAdminService.class },
143 property = {
144 TUNNEL_NICIRA + ":Boolean=" + TUNNEL_NICRA_DEFAULT
145 }
146)
Jian Li19f25262018-07-03 22:37:12 +0900147public class OpenstackVtapManager
148 extends AbstractListenerManager<OpenstackVtapEvent, OpenstackVtapListener>
149 implements OpenstackVtapService, OpenstackVtapAdminService {
Jian Li4f368e82018-07-02 14:22:22 +0900150
Jian Li614cb092018-07-03 22:41:42 +0900151 private final Logger log = getLogger(getClass());
152
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700153 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900154 protected CoreService coreService;
155
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700156 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900157 protected ClusterService clusterService;
158
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700159 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900160 protected LeadershipService leadershipService;
161
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700162 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900163 protected FlowRuleService flowRuleService;
164
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700165 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900166 protected GroupService groupService;
167
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700168 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900169 protected DeviceService deviceService;
170
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700171 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jimo Jung14e87bf2018-09-03 16:28:13 +0900172 protected OpenstackNodeService osNodeService;
173
Ray Milkeyd5425682018-10-23 10:21:33 -0700174 @Reference(cardinality = ReferenceCardinality.MANDATORY)
175
Jian Li614cb092018-07-03 22:41:42 +0900176 protected HostService hostService;
177
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700178 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jian Li614cb092018-07-03 22:41:42 +0900179 protected OpenstackVtapStore store;
180
Ray Milkeyd84f89b2018-08-17 14:54:17 -0700181 @Reference(cardinality = ReferenceCardinality.MANDATORY)
Jimo Jung14e87bf2018-09-03 16:28:13 +0900182 protected ComponentConfigService componentConfigService;
183
Ray Milkey8e406512018-10-24 15:56:50 -0700184 /** Use nicra extension for tunneling. */
185 private boolean tunnelNicira = TUNNEL_NICRA_DEFAULT;
Jian Li26ef1302018-07-04 14:37:06 +0900186
Jian Li614cb092018-07-03 22:41:42 +0900187 public static final String APP_ID = "org.onosproject.openstackvtap";
Jimo Jung14e87bf2018-09-03 16:28:13 +0900188 public static final String VTAP_DESC_NULL = "vtap field %s cannot be null";
Jian Li614cb092018-07-03 22:41:42 +0900189
190 private static final int PRIORITY_VTAP_RULE = 50000;
Jimo Jung14e87bf2018-09-03 16:28:13 +0900191 private static final int PRIORITY_VTAP_OUTPUT_RULE = 1000;
192 private static final int PRIORITY_VTAP_OUTPUT_DROP = 0;
Jian Li614cb092018-07-03 22:41:42 +0900193
Jian Li5c09e212018-10-24 18:23:58 +0900194 private static final int INBOUND_NEXT_TABLE = DHCP_TABLE;
Jian Li614cb092018-07-03 22:41:42 +0900195 private static final int FLAT_OUTBOUND_NEXT_TABLE = FLAT_TABLE;
196 private static final int OUTBOUND_NEXT_TABLE = FORWARDING_TABLE;
197
Jimo Jung14e87bf2018-09-03 16:28:13 +0900198 private static final int[][] VTAP_TABLES = {
199 {VTAP_INBOUND_TABLE, VTAP_INBOUND_GROUP_TABLE,
200 INBOUND_NEXT_TABLE, VTAP_INBOUND_MIRROR_TABLE},
201 {VTAP_FLAT_OUTBOUND_TABLE, VTAP_FLAT_OUTBOUND_GROUP_TABLE,
202 FLAT_OUTBOUND_NEXT_TABLE, VTAP_FLAT_OUTBOUND_MIRROR_TABLE},
203 {VTAP_OUTBOUND_TABLE, VTAP_OUTBOUND_GROUP_TABLE,
204 OUTBOUND_NEXT_TABLE, VTAP_OUTBOUND_MIRROR_TABLE}};
205 private static final int VTAP_TABLE_INBOUND_IDX = 0;
206 private static final int VTAP_TABLE_FLAT_OUTBOUND_IDX = 1;
207 private static final int VTAP_TABLE_OUTBOUND_IDX = 2;
208 private static final int VTAP_TABLE_INPUT_IDX = 0;
209 private static final int VTAP_TABLE_GROUP_IDX = 1;
210 private static final int VTAP_TABLE_NEXT_IDX = 2;
211 private static final int VTAP_TABLE_OUTPUT_IDX = 3;
212
Jian Li311a9c92018-07-09 16:48:36 +0900213 private static final IpPrefix ARBITRARY_IP_PREFIX =
214 IpPrefix.valueOf(IpAddress.valueOf("0.0.0.0"), 0);
Jimo Jung14e87bf2018-09-03 16:28:13 +0900215 private static final String TABLE_EXTENSION = "table";
216 private static final String TUNNEL_DST_EXTENSION = "tunnelDst";
Jimo Jung14e87bf2018-09-03 16:28:13 +0900217
218 private static final int VTAP_NETWORK_KEY = 0;
Jian Li311a9c92018-07-09 16:48:36 +0900219
Jian Li614cb092018-07-03 22:41:42 +0900220 private final DeviceListener deviceListener = new InternalDeviceListener();
Jian Li26ef1302018-07-04 14:37:06 +0900221 private final OpenstackNodeListener osNodeListener = new InternalOpenstackNodeListener();
Jimo Jung14e87bf2018-09-03 16:28:13 +0900222 private final HostListener hostListener = new InternalHostListener();
Jian Li614cb092018-07-03 22:41:42 +0900223
224 private OpenstackVtapStoreDelegate delegate = new InternalStoreDelegate();
225
226 private ApplicationId appId;
227 private NodeId localNodeId;
228 private ScheduledExecutorService eventExecutor;
229
Jimo Jung14e87bf2018-09-03 16:28:13 +0900230 private final Object syncInterface = new Object(); // notification of tunnel interface
231 private static final int INTERFACE_MANIPULATION_TIMEOUT = 1000; // 1000msec
232 private static final int INTERFACE_MANIPULATION_RETRY = 10; // 10 times (totally 10sec)
Jian Li614cb092018-07-03 22:41:42 +0900233
234 @Activate
235 public void activate(ComponentContext context) {
236 appId = coreService.registerApplication(APP_ID);
237 localNodeId = clusterService.getLocalNode().id();
238 leadershipService.runForLeadership(appId.name());
Jimo Jung14e87bf2018-09-03 16:28:13 +0900239 componentConfigService.registerProperties(getClass());
Jian Li614cb092018-07-03 22:41:42 +0900240
241 eventExecutor = newSingleThreadScheduledExecutor(
242 groupedThreads(this.getClass().getSimpleName(), "event-handler", log));
243
244 store.setDelegate(delegate);
245 eventDispatcher.addSink(OpenstackVtapEvent.class, listenerRegistry);
246
247 deviceService.addListener(deviceListener);
Jian Li26ef1302018-07-04 14:37:06 +0900248 osNodeService.addListener(osNodeListener);
Jimo Jung14e87bf2018-09-03 16:28:13 +0900249 hostService.addListener(hostListener);
Jian Li26ef1302018-07-04 14:37:06 +0900250
Jimo Jung14e87bf2018-09-03 16:28:13 +0900251 initVtap();
Jian Li614cb092018-07-03 22:41:42 +0900252
Jimo Jung14e87bf2018-09-03 16:28:13 +0900253 log.info("Started");
Jian Li19f25262018-07-03 22:37:12 +0900254 }
255
Jian Li614cb092018-07-03 22:41:42 +0900256 @Deactivate
257 public void deactivate() {
Jimo Jung14e87bf2018-09-03 16:28:13 +0900258 clearVtap();
Jian Lib1ca1a22018-07-06 13:31:39 +0900259
Jian Li614cb092018-07-03 22:41:42 +0900260 hostService.removeListener(hostListener);
Jimo Jung14e87bf2018-09-03 16:28:13 +0900261 osNodeService.removeListener(osNodeListener);
Jian Li614cb092018-07-03 22:41:42 +0900262 deviceService.removeListener(deviceListener);
Jian Li19f25262018-07-03 22:37:12 +0900263
Jian Li614cb092018-07-03 22:41:42 +0900264 eventDispatcher.removeSink(OpenstackVtapEvent.class);
265 store.unsetDelegate(delegate);
Jian Li19f25262018-07-03 22:37:12 +0900266
Jian Li614cb092018-07-03 22:41:42 +0900267 eventExecutor.shutdown();
Jimo Jung14e87bf2018-09-03 16:28:13 +0900268
269 componentConfigService.unregisterProperties(getClass(), false);
Jian Li614cb092018-07-03 22:41:42 +0900270 leadershipService.withdraw(appId.name());
Jian Li19f25262018-07-03 22:37:12 +0900271
Jimo Jung14e87bf2018-09-03 16:28:13 +0900272 log.info("Stopped");
273 }
274
275 @Modified
276 protected void modified(ComponentContext context) {
277 Dictionary<?, ?> properties = context.getProperties();
278
279 boolean updatedTunnelNicira = Tools.isPropertyEnabled(properties, TUNNEL_NICIRA);
280 if (tunnelNicira != updatedTunnelNicira) {
281 if (Objects.equals(localNodeId, leadershipService.getLeader(appId.name()))) {
282 // Update the tunnel flow rule by reflecting the change.
283 osNodeService.completeNodes(COMPUTE)
284 .forEach(osNode -> applyVtapNetwork(getVtapNetwork(), osNode, false));
285 tunnelNicira = updatedTunnelNicira;
286 osNodeService.completeNodes(COMPUTE).stream()
287 .filter(osNode -> osNode.state() == COMPLETE)
288 .forEach(osNode -> applyVtapNetwork(getVtapNetwork(), osNode, true));
289 log.debug("Apply {} nicira extension for tunneling", tunnelNicira ? "enable" : "disable");
290 } else {
291 tunnelNicira = updatedTunnelNicira;
292 }
293 }
294
295 log.info("Modified");
296 }
297
298 /**
299 * Initializes the flow rules and group tables, tunneling interface for all completed compute nodes.
300 */
301 @Override
302 public void initVtap() {
303 if (Objects.equals(localNodeId, leadershipService.getLeader(appId.name()))) {
304 osNodeService.completeNodes(COMPUTE).stream()
305 .filter(osNode -> osNode.state() == COMPLETE)
306 .forEach(osNode -> initVtapForNode(osNode));
307 log.trace("{} flow rules, groups, tunnel interface are initialized", appId.name());
308 }
309 }
310
311 /**
312 * Clears the flow rules and group tables, tunneling interface for all compute nodes.
313 */
314 @Override
315 public void clearVtap() {
316 if (Objects.equals(localNodeId, leadershipService.getLeader(appId.name()))) {
317 osNodeService.completeNodes(COMPUTE).stream()
318 .forEach(osNode -> clearVtapForNode(osNode));
319 log.trace("{} flow rules, groups, tunnel interface are cleared", appId.name());
320 }
321 }
322
323 /**
324 * Purges all flow rules and group tables, tunneling interface for openstack vtap.
325 */
326 @Override
327 public void purgeVtap() {
328 // Remove all flow rules
329 flowRuleService.removeFlowRulesById(appId);
330
331 // Remove all groups and tunnel interfaces
332 osNodeService.completeNodes(COMPUTE).stream()
333 .filter(osNode -> osNode.state() == COMPLETE)
334 .forEach(osNode -> {
335 groupService.getGroups(osNode.intgBridge(), appId)
336 .forEach(group ->
337 groupService.removeGroup(osNode.intgBridge(), group.appCookie(), appId));
338
339 OpenstackVtapNetwork vtapNetwork = getVtapNetwork();
340 setTunnelInterface(osNode, vtapNetwork, false);
341 });
342
343 log.trace("{} all flow rules, groups, tunnel interface are purged", appId.name());
344 }
345
346 private void initVtapForNode(OpenstackNode osNode) {
347 // Make base vtap network
348 initVtapNetwork(osNode);
349
350 // Make vtap connections by OpenstackVtap config
351 getVtapsByDeviceId(osNode.intgBridge())
352 .forEach(vtap -> applyVtap(vtap, osNode, true));
353
354 // Make vtap networks by OpenstackVtapNetwork config
355 applyVtapNetwork(getVtapNetwork(), osNode, true);
356 }
357
358 private void clearVtapForNode(OpenstackNode osNode) {
359 // Clear vtap networks by OpenstackVtapNetwork config
360 applyVtapNetwork(getVtapNetwork(), osNode, false);
361
362 // Clear vtap connections by OpenstackVtap config
363 getVtapsByDeviceId(osNode.intgBridge())
364 .forEach(vtap -> applyVtap(vtap, osNode, false));
365
366 // Clear base vtap network
367 clearVtapNetwork(osNode);
368 }
369
370 /**
371 * Initializes vtap pipeline of the given device.
372 *
373 * @param osNode device identifier
374 */
375 private void initVtapNetwork(OpenstackNode osNode) {
376 // Create default output tables
377 for (int idx = 0; idx < VTAP_TABLES.length; idx++) {
378 setOutputTableForDrop(osNode.intgBridge(),
379 VTAP_TABLES[idx][VTAP_TABLE_OUTPUT_IDX], true);
380 }
381
382 // Create group tables
383 for (int idx = 0; idx < VTAP_TABLES.length; idx++) {
384 createGroupTable(osNode.intgBridge(),
385 VTAP_TABLES[idx][VTAP_TABLE_GROUP_IDX],
386 ImmutableList.of(VTAP_TABLES[idx][VTAP_TABLE_NEXT_IDX],
387 VTAP_TABLES[idx][VTAP_TABLE_OUTPUT_IDX]),
388 null);
389 }
390 }
391
392 /**
393 * Clear vtap pipeline of the given device.
394 *
395 * @param osNode device identifier
396 */
397 private void clearVtapNetwork(OpenstackNode osNode) {
398 // Clear group tables
399 for (int idx = 0; idx < VTAP_TABLES.length; idx++) {
400 removeGroupTable(osNode.intgBridge(),
401 VTAP_TABLES[idx][VTAP_TABLE_GROUP_IDX]);
402 }
403
404 // Clear default output tables
405 for (int idx = 0; idx < VTAP_TABLES.length; idx++) {
406 setOutputTableForDrop(osNode.intgBridge(),
407 VTAP_TABLES[idx][VTAP_TABLE_OUTPUT_IDX], false);
408 }
409 }
410
411 @Override
412 public OpenstackVtapNetwork getVtapNetwork() {
413 return store.getVtapNetwork(VTAP_NETWORK_KEY);
414 }
415
416 @Override
417 public OpenstackVtapNetwork createVtapNetwork(Mode mode, Integer networkId, IpAddress serverIp) {
418 checkNotNull(mode, VTAP_DESC_NULL, "mode");
419 checkNotNull(serverIp, VTAP_DESC_NULL, "serverIp");
420 DefaultOpenstackVtapNetwork vtapNetwork = DefaultOpenstackVtapNetwork.builder()
421 .mode(mode)
422 .networkId(networkId)
423 .serverIp(serverIp)
424 .build();
425 return store.createVtapNetwork(VTAP_NETWORK_KEY, vtapNetwork);
426 }
427
428 @Override
429 public OpenstackVtapNetwork updateVtapNetwork(OpenstackVtapNetwork description) {
430 checkNotNull(description, VTAP_DESC_NULL, "vtapNetwork");
431 return store.updateVtapNetwork(VTAP_NETWORK_KEY, description);
432 }
433
434 @Override
435 public OpenstackVtapNetwork removeVtapNetwork() {
436 return store.removeVtapNetwork(VTAP_NETWORK_KEY);
437 }
438
439 @Override
440 public Set<DeviceId> getVtapNetworkDevices() {
441 return store.getVtapNetworkDevices(VTAP_NETWORK_KEY);
Jian Li19f25262018-07-03 22:37:12 +0900442 }
443
444 @Override
445 public int getVtapCount(Type type) {
Jian Li614cb092018-07-03 22:41:42 +0900446 return store.getVtapCount(type);
Jian Li38e4d942018-07-03 22:19:16 +0900447 }
448
449 @Override
Jian Li19f25262018-07-03 22:37:12 +0900450 public Set<OpenstackVtap> getVtaps(Type type) {
Jian Li614cb092018-07-03 22:41:42 +0900451 return store.getVtaps(type);
Jian Li38e4d942018-07-03 22:19:16 +0900452 }
453
454 @Override
Jimo Jung14e87bf2018-09-03 16:28:13 +0900455 public OpenstackVtap getVtap(OpenstackVtapId vtapId) {
456 return store.getVtap(vtapId);
Jian Li38e4d942018-07-03 22:19:16 +0900457 }
458
459 @Override
Jimo Jung14e87bf2018-09-03 16:28:13 +0900460 public Set<OpenstackVtap> getVtapsByDeviceId(DeviceId deviceId) {
461 return store.getVtapsByDeviceId(deviceId);
Jian Li614cb092018-07-03 22:41:42 +0900462 }
463
Jian Li614cb092018-07-03 22:41:42 +0900464 @Override
Jimo Jung14e87bf2018-09-03 16:28:13 +0900465 public OpenstackVtap createVtap(Type type, OpenstackVtapCriterion vtapCriterion) {
466 checkNotNull(type, VTAP_DESC_NULL, "type");
467 checkNotNull(vtapCriterion, VTAP_DESC_NULL, "vtapCriterion");
Jian Li614cb092018-07-03 22:41:42 +0900468
469 Set<DeviceId> txDevices = type.isValid(Type.VTAP_TX) ?
Jimo Jung14e87bf2018-09-03 16:28:13 +0900470 getEdgeDevice(Type.VTAP_TX, vtapCriterion) : ImmutableSet.of();
Jian Li614cb092018-07-03 22:41:42 +0900471 Set<DeviceId> rxDevices = type.isValid(Type.VTAP_RX) ?
Jimo Jung14e87bf2018-09-03 16:28:13 +0900472 getEdgeDevice(Type.VTAP_RX, vtapCriterion) : ImmutableSet.of();
Jian Li614cb092018-07-03 22:41:42 +0900473
Jimo Jung14e87bf2018-09-03 16:28:13 +0900474 DefaultOpenstackVtap description = DefaultOpenstackVtap.builder()
475 .id(OpenstackVtapId.vtapId())
476 .type(type)
477 .vtapCriterion(vtapCriterion)
478 .txDeviceIds(txDevices)
479 .rxDeviceIds(rxDevices)
480 .build();
481 return store.createVtap(description);
Jian Li614cb092018-07-03 22:41:42 +0900482 }
483
484 @Override
Jimo Jung14e87bf2018-09-03 16:28:13 +0900485 public OpenstackVtap updateVtap(OpenstackVtap description) {
486 checkNotNull(description, VTAP_DESC_NULL, "vtap");
Jian Li614cb092018-07-03 22:41:42 +0900487
Jimo Jung14e87bf2018-09-03 16:28:13 +0900488 Set<DeviceId> txDevices = description.type().isValid(Type.VTAP_TX) ?
489 getEdgeDevice(Type.VTAP_TX, description.vtapCriterion()) : ImmutableSet.of();
490 Set<DeviceId> rxDevices = description.type().isValid(Type.VTAP_RX) ?
491 getEdgeDevice(Type.VTAP_RX, description.vtapCriterion()) : ImmutableSet.of();
Jian Li614cb092018-07-03 22:41:42 +0900492
Jimo Jung14e87bf2018-09-03 16:28:13 +0900493 DefaultOpenstackVtap vtap = DefaultOpenstackVtap.builder(description)
494 .txDeviceIds(txDevices)
495 .rxDeviceIds(rxDevices)
496 .build();
497 return store.updateVtap(vtap, true);
Jian Li614cb092018-07-03 22:41:42 +0900498 }
499
500 @Override
Jimo Jung14e87bf2018-09-03 16:28:13 +0900501 public OpenstackVtap removeVtap(OpenstackVtapId vtapId) {
502 return store.removeVtap(vtapId);
Jian Li614cb092018-07-03 22:41:42 +0900503 }
504
Jian Li26ef1302018-07-04 14:37:06 +0900505 /**
506 * Obtains the identifier set of edge device where the targeted host is located.
507 * Note that, in most of cases target host is attached to one device,
508 * however, in some cases, the host can be attached to multiple devices.
509 *
Jimo Jung14e87bf2018-09-03 16:28:13 +0900510 * @param type vtap type
511 * @param criterion vtap criterion
Jian Li26ef1302018-07-04 14:37:06 +0900512 * @return a collection of device identifiers
513 */
514 private Set<DeviceId> getEdgeDevice(Type type, OpenstackVtapCriterion criterion) {
515 Set<DeviceId> deviceIds = Sets.newConcurrentHashSet();
516 StreamSupport.stream(hostService.getHosts().spliterator(), true)
Jimo Jung14e87bf2018-09-03 16:28:13 +0900517 .filter(host -> isValidHost(host) &&
518 host.ipAddresses().stream().anyMatch(ip -> containsIp(type, criterion, ip)))
519 .forEach(host -> {
520 Set<DeviceId> hostDeviceIds =
521 host.locations().stream()
522 .map(HostLocation::deviceId)
523 .filter(deviceId -> Objects.nonNull(osNodeService.node(deviceId)))
524 .collect(Collectors.toSet());
525 deviceIds.addAll(hostDeviceIds);
526 });
Jian Li26ef1302018-07-04 14:37:06 +0900527 return deviceIds;
Jian Li614cb092018-07-03 22:41:42 +0900528 }
529
Jian Li26ef1302018-07-04 14:37:06 +0900530 /**
Jimo Jung14e87bf2018-09-03 16:28:13 +0900531 * Updates device list of vtaps with respect to the host changes.
Jian Li26ef1302018-07-04 14:37:06 +0900532 *
533 * @param newHost new host instance
534 * @param oldHost old host instance
535 */
Jimo Jung14e87bf2018-09-03 16:28:13 +0900536 private void updateHostbyType(Type type, Host newHost, Host oldHost) {
537 getVtaps(type).forEach(vtap -> {
538 IpPrefix prefix = (type == Type.VTAP_TX) ?
539 vtap.vtapCriterion().srcIpPrefix() :
540 vtap.vtapCriterion().dstIpPrefix();
541
542 int hostDiff = hostCompareIp(newHost, oldHost, prefix);
543 if (hostDiff < 0) {
544 oldHost.locations().stream()
545 .map(HostLocation::deviceId)
546 .forEach(deviceId ->
547 store.removeDeviceFromVtap(vtap.id(), type, deviceId));
548 } else if (hostDiff > 0) {
549 newHost.locations().stream()
550 .map(HostLocation::deviceId)
551 .filter(deviceId -> Objects.nonNull(osNodeService.node(deviceId)))
552 .forEach(deviceId ->
553 store.addDeviceToVtap(vtap.id(), type, deviceId));
554 }
555 });
556 }
557
Jian Li614cb092018-07-03 22:41:42 +0900558 private void updateHost(Host newHost, Host oldHost) {
Jimo Jung14e87bf2018-09-03 16:28:13 +0900559 // update devices for vtap tx
560 updateHostbyType(Type.VTAP_TX, newHost, oldHost);
Jian Li26ef1302018-07-04 14:37:06 +0900561
Jimo Jung14e87bf2018-09-03 16:28:13 +0900562 // update devices for vtap rx
563 updateHostbyType(Type.VTAP_RX, newHost, oldHost);
Jian Li614cb092018-07-03 22:41:42 +0900564 }
565
Jimo Jung14e87bf2018-09-03 16:28:13 +0900566 private void applyFlowRule(FlowRule flowRule, boolean install) {
567 FlowRuleOperations.Builder flowOpsBuilder = FlowRuleOperations.builder();
Jian Li614cb092018-07-03 22:41:42 +0900568
Jimo Jung14e87bf2018-09-03 16:28:13 +0900569 if (install) {
570 flowOpsBuilder.add(flowRule);
571 } else {
572 flowOpsBuilder.remove(flowRule);
Jian Li26ef1302018-07-04 14:37:06 +0900573 }
574
Jimo Jung14e87bf2018-09-03 16:28:13 +0900575 flowRuleService.apply(flowOpsBuilder.build(new FlowRuleOperationsContext() {
576 @Override
577 public void onSuccess(FlowRuleOperations ops) {
578 log.debug("Installed flow rules for vtap");
579 }
Jian Li26ef1302018-07-04 14:37:06 +0900580
Jimo Jung14e87bf2018-09-03 16:28:13 +0900581 @Override
582 public void onError(FlowRuleOperations ops) {
583 log.warn("Failed to install flow rules for vtap");
584 }
585 }));
Jian Li614cb092018-07-03 22:41:42 +0900586 }
587
Jimo Jung14e87bf2018-09-03 16:28:13 +0900588 private void connectTables(DeviceId deviceId,
589 int fromTable,
590 int toTableOrGroup, boolean isGroup,
591 OpenstackVtapCriterion vtapCriterion,
592 int rulePriority, boolean install) {
593 log.debug("Table Transition: table[{}] -> table/group[{}]", fromTable, toTableOrGroup);
Jian Li614cb092018-07-03 22:41:42 +0900594
595 TrafficSelector.Builder selectorBuilder = DefaultTrafficSelector.builder()
Jian Li311a9c92018-07-09 16:48:36 +0900596 .matchEthType(TYPE_IPV4);
Jian Li614cb092018-07-03 22:41:42 +0900597
Jian Li311a9c92018-07-09 16:48:36 +0900598 // if the IpPrefix is "0.0.0.0/0", we do not include such a match into the flow rule
Jimo Jung14e87bf2018-09-03 16:28:13 +0900599 if (!vtapCriterion.srcIpPrefix().equals(ARBITRARY_IP_PREFIX)) {
600 selectorBuilder.matchIPSrc(vtapCriterion.srcIpPrefix());
Jian Li311a9c92018-07-09 16:48:36 +0900601 }
602
Jimo Jung14e87bf2018-09-03 16:28:13 +0900603 if (!vtapCriterion.dstIpPrefix().equals(ARBITRARY_IP_PREFIX)) {
604 selectorBuilder.matchIPDst(vtapCriterion.dstIpPrefix());
Jian Li311a9c92018-07-09 16:48:36 +0900605 }
606
Jimo Jung14e87bf2018-09-03 16:28:13 +0900607 switch (vtapCriterion.ipProtocol()) {
Jian Li614cb092018-07-03 22:41:42 +0900608 case PROTOCOL_TCP:
Jimo Jung14e87bf2018-09-03 16:28:13 +0900609 selectorBuilder.matchIPProtocol(vtapCriterion.ipProtocol());
Jian Li26ef1302018-07-04 14:37:06 +0900610
611 // Add port match only if the port number is greater than zero
Jimo Jung14e87bf2018-09-03 16:28:13 +0900612 if (vtapCriterion.srcTpPort().toInt() > 0) {
613 selectorBuilder.matchTcpSrc(vtapCriterion.srcTpPort());
Jian Li614cb092018-07-03 22:41:42 +0900614 }
Jimo Jung14e87bf2018-09-03 16:28:13 +0900615 if (vtapCriterion.dstTpPort().toInt() > 0) {
616 selectorBuilder.matchTcpDst(vtapCriterion.dstTpPort());
Jian Li614cb092018-07-03 22:41:42 +0900617 }
618 break;
619 case PROTOCOL_UDP:
Jimo Jung14e87bf2018-09-03 16:28:13 +0900620 selectorBuilder.matchIPProtocol(vtapCriterion.ipProtocol());
Jian Li26ef1302018-07-04 14:37:06 +0900621
622 // Add port match only if the port number is greater than zero
Jimo Jung14e87bf2018-09-03 16:28:13 +0900623 if (vtapCriterion.srcTpPort().toInt() > 0) {
624 selectorBuilder.matchUdpSrc(vtapCriterion.srcTpPort());
Jian Li614cb092018-07-03 22:41:42 +0900625 }
Jimo Jung14e87bf2018-09-03 16:28:13 +0900626 if (vtapCriterion.dstTpPort().toInt() > 0) {
627 selectorBuilder.matchUdpDst(vtapCriterion.dstTpPort());
Jian Li614cb092018-07-03 22:41:42 +0900628 }
629 break;
630 case PROTOCOL_ICMP:
Jimo Jung14e87bf2018-09-03 16:28:13 +0900631 selectorBuilder.matchIPProtocol(vtapCriterion.ipProtocol());
Jian Li614cb092018-07-03 22:41:42 +0900632 break;
633 default:
634 break;
635 }
636
637 TrafficTreatment.Builder treatmentBuilder = DefaultTrafficTreatment.builder();
Jimo Jung14e87bf2018-09-03 16:28:13 +0900638 if (isGroup) {
639 treatmentBuilder.group(GroupId.valueOf(toTableOrGroup));
Jian Li614cb092018-07-03 22:41:42 +0900640 } else {
Jimo Jung14e87bf2018-09-03 16:28:13 +0900641 treatmentBuilder.transition(toTableOrGroup);
Jian Li614cb092018-07-03 22:41:42 +0900642 }
643
644 FlowRule flowRule = DefaultFlowRule.builder()
645 .forDevice(deviceId)
646 .withSelector(selectorBuilder.build())
647 .withTreatment(treatmentBuilder.build())
648 .withPriority(rulePriority)
649 .fromApp(appId)
650 .makePermanent()
651 .forTable(fromTable)
652 .build();
653
654 applyFlowRule(flowRule, install);
655 }
656
Jimo Jung14e87bf2018-09-03 16:28:13 +0900657 /**
658 * Creates/Removes a tunnel interface in a given openstack node by vtap network information.
659 *
660 * @param osNode openstack node
661 * @param vtapNetwork openstack vtap network for making
662 *
663 */
664 private boolean setTunnelInterface(OpenstackNode osNode,
665 OpenstackVtapNetwork vtapNetwork,
666 boolean install) {
667 String tunnelName = getTunnelName(vtapNetwork.mode());
668 if (tunnelName == null) {
669 return false;
Jian Li614cb092018-07-03 22:41:42 +0900670 }
Jimo Jung14e87bf2018-09-03 16:28:13 +0900671
672 if (!deviceService.isAvailable(osNode.ovsdb())) {
673 log.warn("Not available osNode {} ovs {}", osNode.hostname(), osNode.ovsdb());
674 return false;
675 }
676
677 if (install == isInterfaceEnabled(osNode.intgBridge(), tunnelName)) {
678 log.warn("Already {} {} interface on osNode ovs {}, bridge {}",
679 install ? "add" : "remove",
680 tunnelName, osNode.ovsdb(), osNode.intgBridge());
681 return true;
682 }
683
684 Device device = deviceService.getDevice(osNode.ovsdb());
685 if (device == null || !device.is(InterfaceConfig.class)) {
686 log.warn("Not able to get InterfaceConfig on osNode ovs {}", osNode.ovsdb());
687 return false;
688 }
689
690 InterfaceConfig ifaceConfig = device.as(InterfaceConfig.class);
691 if (install) {
692 TunnelDescription.Builder tunnelDesc = DefaultTunnelDescription.builder()
693 .deviceId(INTEGRATION_BRIDGE)
694 .ifaceName(tunnelName)
695 .type(getTunnelType(vtapNetwork.mode()))
696 .key((vtapNetwork.networkId() == 0) ? null : new TunnelKey<>(vtapNetwork.networkId()))
697 .remote(TunnelEndPoints.ipTunnelEndpoint(vtapNetwork.serverIp()));
698 if (!ifaceConfig.addTunnelMode(tunnelName, tunnelDesc.build())) {
699 log.error("Fail to create {} interface on osNode ovs {}", tunnelName, osNode.ovsdb());
700 return false;
701 }
702 } else {
703 if (!ifaceConfig.removeTunnelMode(tunnelName)) {
704 log.error("Fail to remove {} interface on osNode ovs {}", tunnelName, osNode.ovsdb());
705 return false;
706 }
707 }
708
709 // Wait for tunnel interface create/remove complete
710 synchronized (syncInterface) {
711 for (int i = 0; i < INTERFACE_MANIPULATION_RETRY; i++) {
712 try {
713 syncInterface.wait(INTERFACE_MANIPULATION_TIMEOUT);
714 if (install == isInterfaceEnabled(osNode.intgBridge(), tunnelName)) {
715 log.debug("Success to {} {} interface on osNode ovs {}, bridge {}",
716 install ? "add" : "remove",
717 tunnelName, osNode.ovsdb(), osNode.intgBridge());
718 return true;
719 }
720 } catch (InterruptedException e) {
721 break;
722 }
723 }
724 }
725 log.warn("Fail to {} {} interface on osNode ovs {}, bridge {}",
726 install ? "add" : "remove",
727 tunnelName, osNode.ovsdb(), osNode.intgBridge());
728 return false;
729 }
730
731 /**
732 * Checks whether a given network interface in a given openstack node is enabled or not.
733 *
734 * @param deviceId openstack node
735 * @param interfaceName network interface name
736 * @return true if the given interface is enabled, false otherwise
737 */
738 private boolean isInterfaceEnabled(DeviceId deviceId, String interfaceName) {
739 return deviceService.isAvailable(deviceId) &&
740 deviceService.getPorts(deviceId).parallelStream().anyMatch(port ->
741 Objects.equals(port.annotations().value(PORT_NAME), interfaceName) && port.isEnabled());
742 }
743
744 private PortNumber portNumber(DeviceId deviceId, String interfaceName) {
745 Port port = deviceService.getPorts(deviceId).stream()
746 .filter(p -> p.isEnabled() &&
747 Objects.equals(p.annotations().value(PORT_NAME), interfaceName))
748 .findAny().orElse(null);
749 return port != null ? port.number() : null;
750 }
751
752 private void setOutputTableForTunnel(DeviceId deviceId, int tableId,
753 PortNumber outPort, IpAddress serverIp,
754 boolean install) {
755 log.debug("setOutputTableForTunnel[{}]: deviceId={}, tableId={}, outPort={}, serverIp={}",
756 install ? "add" : "remove", deviceId, tableId, outPort, serverIp);
757
758 TrafficSelector.Builder selector = DefaultTrafficSelector.builder();
759 TrafficTreatment.Builder treatment = DefaultTrafficTreatment.builder()
760 .setOutput(outPort);
761
762 if (tunnelNicira) {
763 ExtensionTreatment extensionTreatment = buildTunnelExtension(deviceId, serverIp);
764 if (extensionTreatment == null) {
765 return;
766 }
767 treatment.extension(extensionTreatment, deviceId);
Jian Li614cb092018-07-03 22:41:42 +0900768 }
769
770 FlowRule flowRule = DefaultFlowRule.builder()
771 .forDevice(deviceId)
772 .withSelector(selector.build())
773 .withTreatment(treatment.build())
Jimo Jung14e87bf2018-09-03 16:28:13 +0900774 .withPriority(PRIORITY_VTAP_OUTPUT_RULE)
Jian Li614cb092018-07-03 22:41:42 +0900775 .makePermanent()
776 .forTable(tableId)
777 .fromApp(appId)
778 .build();
Jimo Jung14e87bf2018-09-03 16:28:13 +0900779
780 log.debug("setOutputTableForTunnel flowRule={}, install={}", flowRule, install);
781 applyFlowRule(flowRule, install);
Jian Li614cb092018-07-03 22:41:42 +0900782 }
783
Jimo Jung14e87bf2018-09-03 16:28:13 +0900784 private void setOutputTableForDrop(DeviceId deviceId, int tableId,
785 boolean install) {
786 TrafficSelector.Builder selector = DefaultTrafficSelector.builder();
787 TrafficTreatment.Builder treatment = DefaultTrafficTreatment.builder();
Jian Li614cb092018-07-03 22:41:42 +0900788
Jimo Jung14e87bf2018-09-03 16:28:13 +0900789 FlowRule flowRule = DefaultFlowRule.builder()
790 .forDevice(deviceId)
791 .withSelector(selector.build())
792 .withTreatment(treatment.build())
793 .withPriority(PRIORITY_VTAP_OUTPUT_DROP)
794 .makePermanent()
795 .forTable(tableId)
796 .fromApp(appId)
797 .build();
798 applyFlowRule(flowRule, install);
799 }
Jian Li614cb092018-07-03 22:41:42 +0900800
Jimo Jung14e87bf2018-09-03 16:28:13 +0900801 private void setOutputTable(DeviceId deviceId, Mode mode,
802 IpAddress serverIp, boolean install) {
803 log.debug("setOutputTable[{}]: deviceId={}, mode={}, serverIp={}",
804 install ? "add" : "remove", deviceId, mode, serverIp);
805
806 if (deviceId == null) {
807 return;
Jian Li614cb092018-07-03 22:41:42 +0900808 }
809
Jimo Jung14e87bf2018-09-03 16:28:13 +0900810 switch (mode) {
811 case GRE:
812 case VXLAN:
813 String tunnelName = getTunnelName(mode);
814 PortNumber vtapPort = portNumber(deviceId, tunnelName);
815 if (vtapPort != null) {
816 for (int idx = 0; idx < VTAP_TABLES.length; idx++) {
817 setOutputTableForTunnel(deviceId, VTAP_TABLES[idx][VTAP_TABLE_OUTPUT_IDX],
818 vtapPort, serverIp, install);
819 }
820 } else {
821 log.warn("Vtap tunnel port {} doesn't exist", tunnelName);
822 }
823 break;
824 default:
825 log.warn("Invalid vtap network mode {}", mode);
826 break;
827 }
828 }
829
830 /**
831 * Returns tunnel destination extension treatment object.
832 *
833 * @param deviceId device id to apply this treatment
834 * @param remoteIp tunnel destination ip address
835 * @return extension treatment
836 */
837 private ExtensionTreatment buildTunnelExtension(DeviceId deviceId, IpAddress remoteIp) {
838 Device device = deviceService.getDevice(deviceId);
839 if (device == null || !device.is(ExtensionTreatmentResolver.class)) {
840 log.warn("Nicira extension treatment is not supported");
841 return null;
842 }
843
844 ExtensionTreatmentResolver resolver = device.as(ExtensionTreatmentResolver.class);
845 ExtensionTreatment treatment =
846 resolver.getExtensionInstruction(NICIRA_SET_TUNNEL_DST.type());
847 try {
848 treatment.setPropertyValue(TUNNEL_DST_EXTENSION, remoteIp.getIp4Address());
849 return treatment;
850 } catch (ExtensionPropertyException e) {
851 log.error("Failed to set nicira tunnelDst extension treatment for {}", deviceId);
852 return null;
853 }
854 }
855
856 private ExtensionTreatment buildResubmitExtension(DeviceId deviceId, int tableId) {
857 Device device = deviceService.getDevice(deviceId);
858 if (device == null || !device.is(ExtensionTreatmentResolver.class)) {
859 log.warn("Nicira extension treatment is not supported");
860 return null;
861 }
862
863 ExtensionTreatmentResolver resolver = device.as(ExtensionTreatmentResolver.class);
864 ExtensionTreatment treatment =
865 resolver.getExtensionInstruction(NICIRA_RESUBMIT_TABLE.type());
866
867 try {
868 treatment.setPropertyValue(TABLE_EXTENSION, ((short) tableId));
869 return treatment;
870 } catch (ExtensionPropertyException e) {
871 log.error("Failed to set nicira resubmit extension treatment for {}", deviceId);
872 return null;
873 }
Jian Li614cb092018-07-03 22:41:42 +0900874 }
875
876 private void createGroupTable(DeviceId deviceId, int groupId,
877 List<Integer> tableIds, List<PortNumber> ports) {
878 List<GroupBucket> buckets = Lists.newArrayList();
Jimo Jung14e87bf2018-09-03 16:28:13 +0900879 if (tableIds != null) {
880 tableIds.forEach(tableId -> {
881 TrafficTreatment.Builder treatment = DefaultTrafficTreatment.builder()
882 .extension(buildResubmitExtension(deviceId, tableId), deviceId);
883 GroupBucket bucket = DefaultGroupBucket
884 .createAllGroupBucket(treatment.build());
885 buckets.add(bucket);
886 });
887 }
888 if (ports != null) {
889 ports.forEach(port -> {
890 TrafficTreatment.Builder treatment = DefaultTrafficTreatment.builder()
891 .setOutput(port);
892 GroupBucket bucket = DefaultGroupBucket
893 .createAllGroupBucket(treatment.build());
894 buckets.add(bucket);
895 });
896 }
Jian Li614cb092018-07-03 22:41:42 +0900897
898 GroupDescription groupDescription = new DefaultGroupDescription(deviceId,
899 GroupDescription.Type.ALL,
900 new GroupBuckets(buckets),
901 getGroupKey(groupId),
902 groupId,
903 appId);
904 groupService.addGroup(groupDescription);
905 }
906
Jimo Jung14e87bf2018-09-03 16:28:13 +0900907 private void removeGroupTable(DeviceId deviceId, int groupId) {
908 groupService.removeGroup(deviceId, getGroupKey(groupId), appId);
Jian Li26ef1302018-07-04 14:37:06 +0900909 }
910
Jimo Jung14e87bf2018-09-03 16:28:13 +0900911 /**
912 * Internal listener for device events.
913 */
Jian Li26ef1302018-07-04 14:37:06 +0900914 private class InternalDeviceListener implements DeviceListener {
Jian Li26ef1302018-07-04 14:37:06 +0900915
916 @Override
917 public void event(DeviceEvent event) {
918 DeviceEvent.Type type = event.type();
Jimo Jung14e87bf2018-09-03 16:28:13 +0900919 Device device = event.subject();
Jian Li26ef1302018-07-04 14:37:06 +0900920
921 switch (type) {
Jimo Jung14e87bf2018-09-03 16:28:13 +0900922 case PORT_ADDED:
923 case PORT_UPDATED:
924 case PORT_REMOVED:
925 String portName = event.port().annotations().value(PORT_NAME);
926 if (portName.equals(getTunnelName(Mode.GRE)) ||
927 portName.equals(getTunnelName(Mode.VXLAN))) {
928 log.trace("InternalDeviceListener type={}, host={}", type, device);
929 synchronized (syncInterface) {
930 try {
931 syncInterface.notifyAll();
932 } catch (IllegalMonitorStateException e) {
933 log.warn("Already syncInterface exited");
934 }
935 }
936 }
Jian Li26ef1302018-07-04 14:37:06 +0900937 break;
938 default:
939 break;
940 }
941 }
942 }
943
Jimo Jung14e87bf2018-09-03 16:28:13 +0900944 /**
945 * Internal listener for openstack node events.
946 */
947 private class InternalOpenstackNodeListener implements OpenstackNodeListener {
948
949 @Override
950 public boolean isRelevant(OpenstackNodeEvent event) {
951 // do not allow to proceed without leadership and compute node
952 NodeId leader = leadershipService.getLeader(appId.name());
953 OpenstackNode osNode = event.subject();
954
955 return Objects.equals(localNodeId, leader) && osNode.type() == COMPUTE;
956 }
957
958 @Override
959 public void event(OpenstackNodeEvent event) {
960 OpenstackNodeEvent.Type type = event.type();
961 OpenstackNode osNode = event.subject();
962 log.trace("InternalOpenstackNodeListener type={}, osNode={}", type, osNode);
963
964 eventExecutor.execute(() -> {
965 try {
966 switch (type) {
967 case OPENSTACK_NODE_COMPLETE:
968 initVtapForNode(osNode);
969 break;
970
971 case OPENSTACK_NODE_REMOVED:
972 clearVtapForNode(osNode);
973 break;
974
975 default:
976 break;
977 }
978 } catch (Exception e) {
979 dumpStackTrace(log, e);
980 }
981 });
982 }
983 }
984
985 /**
986 * Internal listener for host events.
987 */
Jian Li26ef1302018-07-04 14:37:06 +0900988 private class InternalHostListener implements HostListener {
Jimo Jung14e87bf2018-09-03 16:28:13 +0900989
Jian Li26ef1302018-07-04 14:37:06 +0900990 @Override
991 public boolean isRelevant(HostEvent event) {
Jimo Jung14e87bf2018-09-03 16:28:13 +0900992 Host host = event.subject();
993 if (!isValidHost(host)) {
994 log.debug("Invalid host detected, ignore it {}", host);
995 return false;
996 }
997
Jian Li26ef1302018-07-04 14:37:06 +0900998 // do not allow to proceed without leadership
999 NodeId leader = leadershipService.getLeader(appId.name());
1000 return Objects.equals(localNodeId, leader);
1001 }
1002
1003 @Override
1004 public void event(HostEvent event) {
1005 HostEvent.Type type = event.type();
1006 Host host = event.subject();
Jimo Jung14e87bf2018-09-03 16:28:13 +09001007 Host prevHost = event.prevSubject();
1008 log.trace("InternalHostListener {}: {} -> {}", type, prevHost, host);
Jian Li26ef1302018-07-04 14:37:06 +09001009
Jimo Jung14e87bf2018-09-03 16:28:13 +09001010 eventExecutor.execute(() -> {
1011 try {
1012 switch (event.type()) {
1013 case HOST_ADDED:
1014 updateHost(host, null);
1015 break;
Jian Li26ef1302018-07-04 14:37:06 +09001016
Jimo Jung14e87bf2018-09-03 16:28:13 +09001017 case HOST_REMOVED:
1018 updateHost(null, host);
1019 break;
Jian Li26ef1302018-07-04 14:37:06 +09001020
Jimo Jung14e87bf2018-09-03 16:28:13 +09001021 case HOST_MOVED:
1022 case HOST_UPDATED:
1023 updateHost(host, prevHost);
1024 break;
Jian Li26ef1302018-07-04 14:37:06 +09001025
Jimo Jung14e87bf2018-09-03 16:28:13 +09001026 default:
1027 break;
1028 }
1029 } catch (Exception e) {
1030 dumpStackTrace(log, e);
1031 }
1032 });
Jian Li26ef1302018-07-04 14:37:06 +09001033 }
1034 }
1035
1036 // Store delegate to re-post events emitted from the store.
1037 private class InternalStoreDelegate implements OpenstackVtapStoreDelegate {
Jimo Jung14e87bf2018-09-03 16:28:13 +09001038
Jian Li26ef1302018-07-04 14:37:06 +09001039 @Override
1040 public void notify(OpenstackVtapEvent event) {
1041 OpenstackVtapEvent.Type type = event.type();
Jimo Jung14e87bf2018-09-03 16:28:13 +09001042 log.trace("InternalStoreDelegate {}: {} -> {}", type, event.prevSubject(), event.subject());
Jian Li26ef1302018-07-04 14:37:06 +09001043
Jimo Jung14e87bf2018-09-03 16:28:13 +09001044 if (Objects.equals(localNodeId, leadershipService.getLeader(appId.name()))) {
1045 eventExecutor.execute(() -> {
1046 try {
1047 switch (type) {
1048 case VTAP_NETWORK_ADDED:
1049 case VTAP_NETWORK_UPDATED:
1050 case VTAP_NETWORK_REMOVED:
1051 // Update network
1052 updateVtapNetwork(event.openstackVtapNetwork(),
1053 event.prevOpenstackVtapNetwork());
1054 break;
Jian Li26ef1302018-07-04 14:37:06 +09001055
Jimo Jung14e87bf2018-09-03 16:28:13 +09001056 case VTAP_ADDED:
1057 case VTAP_UPDATED:
1058 case VTAP_REMOVED:
1059 // Update vtap rule
1060 updateVtap(event.openstackVtap(),
1061 event.prevOpenstackVtap());
1062 break;
Jian Li26ef1302018-07-04 14:37:06 +09001063
Jimo Jung14e87bf2018-09-03 16:28:13 +09001064 default:
1065 break;
1066 }
1067 } catch (Exception e) {
1068 dumpStackTrace(log, e);
1069 }
1070 });
Jian Li26ef1302018-07-04 14:37:06 +09001071 }
1072 post(event);
1073 }
Jian Li38e4d942018-07-03 22:19:16 +09001074 }
Jimo Jung14e87bf2018-09-03 16:28:13 +09001075
1076 private void applyVtap(OpenstackVtap vtap,
1077 OpenstackNode osNode,
1078 boolean install) {
1079 if (vtap == null || osNode == null) {
1080 return;
1081 }
1082
1083 log.debug("applyVtap vtap={}, osNode={}, install={}", vtap, osNode, install);
1084
1085 DeviceId deviceId = osNode.intgBridge();
1086 for (int idx = 0; idx < VTAP_TABLES.length; idx++) {
1087 if ((idx == VTAP_TABLE_INBOUND_IDX &&
1088 vtap.type().isValid(Type.VTAP_TX) &&
1089 vtap.txDeviceIds().contains(deviceId)) ||
1090 (idx != VTAP_TABLE_INBOUND_IDX &&
1091 vtap.type().isValid(Type.VTAP_RX) &&
1092 vtap.rxDeviceIds().contains(deviceId))) {
1093 connectTables(deviceId,
1094 VTAP_TABLES[idx][VTAP_TABLE_INPUT_IDX],
1095 VTAP_TABLES[idx][VTAP_TABLE_GROUP_IDX],
1096 true,
1097 vtap.vtapCriterion(), PRIORITY_VTAP_RULE, install);
1098 }
1099 }
1100 }
1101
1102 private void updateVtap(OpenstackVtap vtap,
1103 OpenstackVtap prevVtap) {
1104 if (Objects.equals(vtap, prevVtap)) {
1105 return;
1106 }
1107
1108 Set<DeviceId> prevTxDeviceIds = (prevVtap != null ? prevVtap.txDeviceIds() : ImmutableSet.of());
1109 Set<DeviceId> txDeviceIds = (vtap != null ? vtap.txDeviceIds() : ImmutableSet.of());
1110 Set<DeviceId> prevRxDeviceIds = (prevVtap != null ? prevVtap.rxDeviceIds() : ImmutableSet.of());
1111 Set<DeviceId> rxDeviceIds = (vtap != null ? vtap.rxDeviceIds() : ImmutableSet.of());
1112
1113 // Remake all vtap rule
1114 if (prevVtap != null) {
1115 Set<DeviceId> deviceIds = Sets.newHashSet();
1116 deviceIds.addAll(Sets.difference(prevTxDeviceIds, txDeviceIds));
1117 deviceIds.addAll(Sets.difference(prevRxDeviceIds, rxDeviceIds));
1118 deviceIds.stream()
1119 .map(deviceId -> osNodeService.node(deviceId))
1120 .filter(osNode -> Objects.nonNull(osNode) &&
1121 osNode.type() == COMPUTE)
1122 .forEach(osNode -> applyVtap(prevVtap, osNode, false));
1123 }
1124 if (vtap != null) {
1125 Set<DeviceId> deviceIds = Sets.newHashSet();
1126 deviceIds.addAll(Sets.difference(txDeviceIds, prevTxDeviceIds));
1127 deviceIds.addAll(Sets.difference(rxDeviceIds, prevRxDeviceIds));
1128 deviceIds.stream()
1129 .map(deviceId -> osNodeService.node(deviceId))
1130 .filter(osNode -> Objects.nonNull(osNode) &&
1131 osNode.type() == COMPUTE && osNode.state() == COMPLETE)
1132 .forEach(osNode -> applyVtap(vtap, osNode, true));
1133 }
1134 }
1135
1136 // create/remove tunnel interface and output table
1137 private boolean applyVtapNetwork(OpenstackVtapNetwork vtapNetwork,
1138 OpenstackNode osNode,
1139 boolean install) {
1140 if (vtapNetwork == null || osNode == null) {
1141 return false;
1142 }
1143
1144 if (install) {
1145 if (setTunnelInterface(osNode, vtapNetwork, true)) {
1146 setOutputTable(osNode.intgBridge(), vtapNetwork.mode(), vtapNetwork.serverIp(), true);
1147 store.addDeviceToVtapNetwork(VTAP_NETWORK_KEY, osNode.intgBridge());
1148 return true;
1149 }
1150 } else {
1151 Set<DeviceId> deviceIds = getVtapNetworkDevices();
1152 if (deviceIds != null && deviceIds.contains(osNode.intgBridge())) {
1153 store.removeDeviceFromVtapNetwork(VTAP_NETWORK_KEY, osNode.intgBridge());
1154 setOutputTable(osNode.intgBridge(), vtapNetwork.mode(), vtapNetwork.serverIp(), false);
1155 setTunnelInterface(osNode, vtapNetwork, false);
1156 return true;
1157 }
1158 }
1159 return false;
1160 }
1161
1162 private void updateVtapNetwork(OpenstackVtapNetwork network,
1163 OpenstackVtapNetwork prevNetwork) {
1164 // Remake all output tables
1165 if (prevNetwork != null) {
1166 osNodeService.completeNodes(COMPUTE)
1167 .forEach(osNode -> applyVtapNetwork(prevNetwork, osNode, false));
1168 }
1169 if (network != null) {
1170 osNodeService.completeNodes(COMPUTE).stream()
1171 .filter(osNode -> osNode.state() == COMPLETE)
1172 .forEach(osNode -> applyVtapNetwork(network, osNode, true));
1173 }
1174 }
1175
Jian Li4f368e82018-07-02 14:22:22 +09001176}