blob: ea716db39f2eb42ba457e86c6d16c6d0a7aec8a4 [file] [log] [blame]
Hyunsun Moon44aac662017-02-18 02:07:01 +09001/*
2 * Copyright 2016-present Open Networking Laboratory
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16package org.onosproject.openstacknetworking.impl;
17
18import com.google.common.base.Strings;
19import com.google.common.collect.Maps;
20import org.apache.felix.scr.annotations.Activate;
21import org.apache.felix.scr.annotations.Component;
22import org.apache.felix.scr.annotations.Deactivate;
23import org.apache.felix.scr.annotations.Reference;
24import org.apache.felix.scr.annotations.ReferenceCardinality;
25import org.onlab.packet.Ethernet;
26import org.onlab.packet.ICMP;
27import org.onlab.packet.IPv4;
28import org.onlab.packet.IpAddress;
29import org.onlab.packet.MacAddress;
30import org.onosproject.core.ApplicationId;
31import org.onosproject.core.CoreService;
32import org.onosproject.mastership.MastershipService;
33import org.onosproject.net.DeviceId;
34import org.onosproject.net.flow.DefaultTrafficSelector;
35import org.onosproject.net.flow.DefaultTrafficTreatment;
36import org.onosproject.net.flow.TrafficSelector;
37import org.onosproject.net.flow.TrafficTreatment;
38import org.onosproject.net.packet.DefaultOutboundPacket;
39import org.onosproject.net.packet.InboundPacket;
40import org.onosproject.net.packet.OutboundPacket;
41import org.onosproject.net.packet.PacketContext;
42import org.onosproject.net.packet.PacketPriority;
43import org.onosproject.net.packet.PacketProcessor;
44import org.onosproject.net.packet.PacketService;
45import org.onosproject.openstacknetworking.api.Constants;
46import org.onosproject.openstacknetworking.api.InstancePort;
47import org.onosproject.openstacknetworking.api.InstancePortService;
48import org.onosproject.openstacknetworking.api.OpenstackRouterService;
49import org.onosproject.openstacknetworking.api.OpenstackNetworkService;
50import org.onosproject.openstacknode.OpenstackNode;
51import org.onosproject.openstacknode.OpenstackNodeEvent;
52import org.onosproject.openstacknode.OpenstackNodeListener;
53import org.onosproject.openstacknode.OpenstackNodeService;
Hyunsun Moon44aac662017-02-18 02:07:01 +090054import org.openstack4j.model.network.ExternalGateway;
55import org.openstack4j.model.network.IP;
56import org.openstack4j.model.network.Port;
57import org.openstack4j.model.network.Router;
58import org.openstack4j.model.network.RouterInterface;
59import org.openstack4j.model.network.Subnet;
60import org.slf4j.Logger;
61
62import java.nio.ByteBuffer;
63import java.util.Map;
64import java.util.Objects;
65import java.util.Optional;
66import java.util.Set;
67import java.util.concurrent.ExecutorService;
68import java.util.stream.Collectors;
69
70import static java.util.concurrent.Executors.newSingleThreadExecutor;
71import static org.onlab.util.Tools.groupedThreads;
72import static org.onosproject.openstacknetworking.api.Constants.*;
73import static org.onosproject.openstacknode.OpenstackNodeService.NodeType.GATEWAY;
74import static org.slf4j.LoggerFactory.getLogger;
75
76
77/**
78 * Handles ICMP packet received from a gateway node.
79 * For a request for virtual network subnet gateway, it generates fake ICMP reply.
80 * For a request for the external network, it does source NAT with the public IP and
81 * forward the request to the external only if the requested virtual subnet has
82 * external connectivity.
83 */
84@Component(immediate = true)
85public class OpenstackRoutingIcmpHandler {
86
87 protected final Logger log = getLogger(getClass());
88
89 private static final String ERR_REQ = "Failed to handle ICMP request: ";
90
91 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
92 protected CoreService coreService;
93
94 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
95 protected PacketService packetService;
96
97 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
98 protected MastershipService mastershipService;
99
100 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
Hyunsun Moon44aac662017-02-18 02:07:01 +0900101 protected OpenstackNodeService osNodeService;
102
103 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
104 protected InstancePortService instancePortService;
105
106 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
107 protected OpenstackNetworkService osNetworkService;
108
109 @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY)
110 protected OpenstackRouterService osRouterService;
111
112 private final ExecutorService eventExecutor = newSingleThreadExecutor(
113 groupedThreads(this.getClass().getSimpleName(), "event-handler", log));
114 private final InternalPacketProcessor packetProcessor = new InternalPacketProcessor();
115 private final InternalNodeListener nodeListener = new InternalNodeListener();
116 private final Map<String, InstancePort> icmpInfoMap = Maps.newHashMap();
117
118 private ApplicationId appId;
119
120 @Activate
121 protected void activate() {
122 appId = coreService.registerApplication(OPENSTACK_NETWORKING_APP_ID);
123 packetService.addProcessor(packetProcessor, PacketProcessor.director(1));
124 osNodeService.addListener(nodeListener);
125 requestPacket(appId);
126
127 log.info("Started");
128 }
129
130 @Deactivate
131 protected void deactivate() {
132 packetService.removeProcessor(packetProcessor);
133 osNodeService.removeListener(nodeListener);
134 eventExecutor.shutdown();
135
136 log.info("Stopped");
137 }
138
139 private void requestPacket(ApplicationId appId) {
140 TrafficSelector icmpSelector = DefaultTrafficSelector.builder()
141 .matchEthType(Ethernet.TYPE_IPV4)
142 .matchIPProtocol(IPv4.PROTOCOL_ICMP)
143 .build();
144
daniel parke49eb382017-04-05 16:48:28 +0900145 osNodeService.gatewayDeviceIds().forEach(gateway -> {
Hyunsun Moon44aac662017-02-18 02:07:01 +0900146 packetService.requestPackets(
147 icmpSelector,
148 PacketPriority.CONTROL,
149 appId,
150 Optional.of(gateway));
151 log.debug("Requested ICMP packet to {}", gateway);
152 });
153 }
154
155 private void processIcmpPacket(PacketContext context, Ethernet ethernet) {
156 IPv4 ipPacket = (IPv4) ethernet.getPayload();
157 ICMP icmp = (ICMP) ipPacket.getPayload();
158 log.trace("Processing ICMP packet source MAC:{}, source IP:{}," +
159 "dest MAC:{}, dest IP:{}",
160 ethernet.getSourceMAC(),
161 IpAddress.valueOf(ipPacket.getSourceAddress()),
162 ethernet.getDestinationMAC(),
163 IpAddress.valueOf(ipPacket.getDestinationAddress()));
164
165 switch (icmp.getIcmpType()) {
166 case ICMP.TYPE_ECHO_REQUEST:
167 handleEchoRequest(
168 context.inPacket().receivedFrom().deviceId(),
169 ethernet.getSourceMAC(),
170 ipPacket,
171 icmp);
172 context.block();
173 break;
174 case ICMP.TYPE_ECHO_REPLY:
175 handleEchoReply(ipPacket, icmp);
176 context.block();
177 break;
178 default:
179 break;
180 }
181 }
182
183 private void handleEchoRequest(DeviceId srcDevice, MacAddress srcMac, IPv4 ipPacket,
184 ICMP icmp) {
185 InstancePort instPort = instancePortService.instancePort(srcMac);
186 if (instPort == null) {
187 log.trace(ERR_REQ + "unknown source host(MAC:{})", srcMac);
188 return;
189 }
190
191 IpAddress srcIp = IpAddress.valueOf(ipPacket.getSourceAddress());
192 Subnet srcSubnet = getSourceSubnet(instPort, srcIp);
193 if (srcSubnet == null) {
194 log.trace(ERR_REQ + "unknown source subnet(IP:{})", srcIp);
195 return;
196 }
197 if (Strings.isNullOrEmpty(srcSubnet.getGateway())) {
198 log.trace(ERR_REQ + "source subnet(ID:{}, CIDR:{}) has no gateway",
199 srcSubnet.getId(), srcSubnet.getCidr());
200 return;
201 }
202
203 if (isForSubnetGateway(IpAddress.valueOf(ipPacket.getDestinationAddress()),
204 srcSubnet)) {
205 // this is a request for the subnet gateway
206 processRequestForGateway(ipPacket, instPort);
207 } else {
208 // this is a request for the external network
209 IpAddress externalIp = getExternalIp(srcSubnet);
210 if (externalIp == null) {
211 return;
212 }
213 log.debug("1");
214 sendRequestForExternal(ipPacket, srcDevice, externalIp);
215 log.debug("2");
216 String icmpInfoKey = String.valueOf(getIcmpId(icmp))
217 .concat(String.valueOf(externalIp.getIp4Address().toInt()))
218 .concat(String.valueOf(ipPacket.getDestinationAddress()));
219 icmpInfoMap.putIfAbsent(icmpInfoKey, instPort);
220 }
221 }
222
223 private void handleEchoReply(IPv4 ipPacket, ICMP icmp) {
224 String icmpInfoKey = String.valueOf(getIcmpId(icmp))
225 .concat(String.valueOf(ipPacket.getDestinationAddress()))
226 .concat(String.valueOf(ipPacket.getSourceAddress()));
227
228 processReplyFromExternal(ipPacket, icmpInfoMap.get(icmpInfoKey));
229 icmpInfoMap.remove(icmpInfoKey);
230 }
231
232 private Subnet getSourceSubnet(InstancePort instance, IpAddress srcIp) {
233 Port osPort = osNetworkService.port(instance.portId());
234 IP fixedIp = osPort.getFixedIps().stream()
235 .filter(ip -> IpAddress.valueOf(ip.getIpAddress()).equals(srcIp))
236 .findAny().orElse(null);
237 if (fixedIp == null) {
238 return null;
239 }
240 return osNetworkService.subnet(fixedIp.getSubnetId());
241 }
242
243 private boolean isForSubnetGateway(IpAddress dstIp, Subnet srcSubnet) {
244 RouterInterface osRouterIface = osRouterService.routerInterfaces().stream()
245 .filter(i -> Objects.equals(i.getSubnetId(), srcSubnet.getId()))
246 .findAny().orElse(null);
247 if (osRouterIface == null) {
248 log.trace(ERR_REQ + "source subnet(ID:{}, CIDR:{}) has no router",
249 srcSubnet.getId(), srcSubnet.getCidr());
250 return false;
251 }
252
253 Router osRouter = osRouterService.router(osRouterIface.getId());
254 Set<IpAddress> routableGateways = osRouterService.routerInterfaces(osRouter.getId())
255 .stream()
256 .map(iface -> osNetworkService.subnet(iface.getSubnetId()).getGateway())
257 .map(IpAddress::valueOf)
258 .collect(Collectors.toSet());
259
260 return routableGateways.contains(dstIp);
261 }
262
263 private IpAddress getExternalIp(Subnet srcSubnet) {
264 RouterInterface osRouterIface = osRouterService.routerInterfaces().stream()
265 .filter(i -> Objects.equals(i.getSubnetId(), srcSubnet.getId()))
266 .findAny().orElse(null);
267 if (osRouterIface == null) {
268 final String error = String.format(ERR_REQ +
269 "subnet(ID:%s, CIDR:%s) is not connected to any router",
270 srcSubnet.getId(), srcSubnet.getCidr());
271 throw new IllegalStateException(error);
272 }
273
274 Router osRouter = osRouterService.router(osRouterIface.getId());
275 if (osRouter.getExternalGatewayInfo() == null) {
276 final String error = String.format(ERR_REQ +
277 "router(ID:%s, name:%s) does not have external gateway",
278 osRouter.getId(), osRouter.getName());
279 throw new IllegalStateException(error);
280 }
281
282 // TODO fix openstack4j for ExternalGateway provides external fixed IP list
283 ExternalGateway exGatewayInfo = osRouter.getExternalGatewayInfo();
284 Port exGatewayPort = osNetworkService.ports(exGatewayInfo.getNetworkId())
285 .stream()
286 .filter(port -> Objects.equals(port.getDeviceId(), osRouter.getId()))
287 .findAny().orElse(null);
288 if (exGatewayPort == null) {
289 final String error = String.format(ERR_REQ +
290 "no external gateway port for router (ID:%s, name:%s)",
291 osRouter.getId(), osRouter.getName());
292 throw new IllegalStateException(error);
293 }
294
295 return IpAddress.valueOf(exGatewayPort.getFixedIps().stream()
296 .findFirst().get().getIpAddress());
297 }
298
299 private void processRequestForGateway(IPv4 ipPacket, InstancePort instPort) {
300 ICMP icmpReq = (ICMP) ipPacket.getPayload();
301 icmpReq.setChecksum((short) 0);
302 icmpReq.setIcmpType(ICMP.TYPE_ECHO_REPLY).resetChecksum();
303
304 int destinationAddress = ipPacket.getSourceAddress();
305
306 ipPacket.setSourceAddress(ipPacket.getDestinationAddress())
307 .setDestinationAddress(destinationAddress)
308 .resetChecksum();
309
310 ipPacket.setPayload(icmpReq);
311 Ethernet icmpReply = new Ethernet();
312 icmpReply.setEtherType(Ethernet.TYPE_IPV4)
313 .setSourceMACAddress(Constants.DEFAULT_GATEWAY_MAC)
314 .setDestinationMACAddress(instPort.macAddress())
315 .setPayload(ipPacket);
316
317 sendReply(icmpReply, instPort);
318 }
319
320 private void sendRequestForExternal(IPv4 ipPacket, DeviceId srcDevice, IpAddress srcNatIp) {
321 ICMP icmpReq = (ICMP) ipPacket.getPayload();
322 icmpReq.resetChecksum();
323 ipPacket.setSourceAddress(srcNatIp.getIp4Address().toInt()).resetChecksum();
324 ipPacket.setPayload(icmpReq);
325
326 Ethernet icmpRequestEth = new Ethernet();
327 icmpRequestEth.setEtherType(Ethernet.TYPE_IPV4)
328 .setSourceMACAddress(DEFAULT_GATEWAY_MAC)
329 .setDestinationMACAddress(DEFAULT_EXTERNAL_ROUTER_MAC)
330 .setPayload(ipPacket);
331
332 TrafficTreatment treatment = DefaultTrafficTreatment.builder()
daniel parke49eb382017-04-05 16:48:28 +0900333 .setOutput(osNodeService.externalPort(srcDevice).get())
Hyunsun Moon44aac662017-02-18 02:07:01 +0900334 .build();
335
336 OutboundPacket packet = new DefaultOutboundPacket(
337 srcDevice,
338 treatment,
339 ByteBuffer.wrap(icmpRequestEth.serialize()));
340
341 packetService.emit(packet);
342 }
343
344 private void processReplyFromExternal(IPv4 ipPacket, InstancePort instPort) {
345 ICMP icmpReply = (ICMP) ipPacket.getPayload();
346 icmpReply.resetChecksum();
347
348 ipPacket.setDestinationAddress(instPort.ipAddress().getIp4Address().toInt())
349 .resetChecksum();
350 ipPacket.setPayload(icmpReply);
351
352 Ethernet icmpResponseEth = new Ethernet();
353 icmpResponseEth.setEtherType(Ethernet.TYPE_IPV4)
354 .setSourceMACAddress(Constants.DEFAULT_GATEWAY_MAC)
355 .setDestinationMACAddress(instPort.macAddress())
356 .setPayload(ipPacket);
357
358 sendReply(icmpResponseEth, instPort);
359 }
360
361 private void sendReply(Ethernet icmpReply, InstancePort instPort) {
362 TrafficTreatment treatment = DefaultTrafficTreatment.builder()
363 .setOutput(instPort.portNumber())
364 .build();
365
366 OutboundPacket packet = new DefaultOutboundPacket(
367 instPort.deviceId(),
368 treatment,
369 ByteBuffer.wrap(icmpReply.serialize()));
370
371 packetService.emit(packet);
372 }
373
374 private short getIcmpId(ICMP icmp) {
375 return ByteBuffer.wrap(icmp.serialize(), 4, 2).getShort();
376 }
377
378 private class InternalPacketProcessor implements PacketProcessor {
379
380 @Override
381 public void process(PacketContext context) {
382 if (context.isHandled()) {
383 return;
daniel parke49eb382017-04-05 16:48:28 +0900384 } else if (!osNodeService.gatewayDeviceIds().contains(
Hyunsun Moon44aac662017-02-18 02:07:01 +0900385 context.inPacket().receivedFrom().deviceId())) {
386 // return if the packet is not from gateway nodes
387 return;
388 }
389
390 InboundPacket pkt = context.inPacket();
391 Ethernet ethernet = pkt.parsed();
392 if (ethernet == null || ethernet.getEtherType() == Ethernet.TYPE_ARP) {
393 return;
394 }
395
396 IPv4 iPacket = (IPv4) ethernet.getPayload();
397 if (iPacket.getProtocol() == IPv4.PROTOCOL_ICMP) {
398 eventExecutor.execute(() -> processIcmpPacket(context, ethernet));
399 }
400 }
401 }
402
403 private class InternalNodeListener implements OpenstackNodeListener {
404
405 @Override
406 public boolean isRelevant(OpenstackNodeEvent event) {
407 // do not proceed without mastership
408 OpenstackNode osNode = event.subject();
409 return mastershipService.isLocalMaster(osNode.intBridge());
410 }
411
412 @Override
413 public void event(OpenstackNodeEvent event) {
414 OpenstackNode osNode = event.subject();
415
416 switch (event.type()) {
417 case COMPLETE:
418 if (osNode.type() == GATEWAY) {
419 log.info("GATEWAY node {} detected", osNode.hostname());
420 eventExecutor.execute(() -> {
Hyunsun Moon44aac662017-02-18 02:07:01 +0900421 requestPacket(appId);
422 });
423 }
424 break;
425 case INIT:
426 case DEVICE_CREATED:
427 case INCOMPLETE:
428 default:
429 break;
430 }
431 }
432 }
433}