Ben Pfaff [Fri, 21 Nov 2008 18:48:00 +0000 (10:48 -0800)]
Don't rate-limit packet_ins from flows that the controller set up.
Ben Pfaff [Thu, 20 Nov 2008 18:10:59 +0000 (10:10 -0800)]
Prevent accidentally passing an integer value to IP_ARGS.
Ben Pfaff [Thu, 20 Nov 2008 18:07:22 +0000 (10:07 -0800)]
Fix printing of IP addresses in ofp_print_action().
IP_ARGS takes a pointer, not a raw IP address.
Thanks to kk yap for reporting the problem.
Ben Pfaff [Thu, 20 Nov 2008 17:53:27 +0000 (09:53 -0800)]
Use "%zu" to print size_t, not "%"PRIu16.
Ben Pfaff [Thu, 13 Nov 2008 20:48:02 +0000 (12:48 -0800)]
Copy skbs when we save them.
Ben Pfaff [Thu, 13 Nov 2008 20:50:03 +0000 (12:50 -0800)]
Simplify code for constructing skb in recv_packet_out().
Ben Pfaff [Thu, 13 Nov 2008 19:29:20 +0000 (11:29 -0800)]
Fix double-free: NF_HOOK sometimes frees the sk_buff passed in.
NF_HOOK is supposed to *always* consume the sk_buff passed in, either
internally or through the okfn argument. We assumed that it never
consumed its sk_buff, which was OK in the case where it called okfn,
since our okfn (snat_pre_route_finish) never freed its sk_buff, but
not when one of the netfilter hooks dropped or stole the packet, because
then we'd assume that it still existed and free it a second time.
The other users of NF_HOOK in this file, in snat_skb() and
snat_skb_finish(), do not need to be fixed because they always pass a
copy of their sk_buff argument to NF_HOOK and expect it to be freed.
Ben Pfaff [Thu, 13 Nov 2008 18:26:15 +0000 (10:26 -0800)]
No need to test argument of kfree_skb() for non-null.
Ben Pfaff [Thu, 13 Nov 2008 18:25:06 +0000 (10:25 -0800)]
Never free an skb that has been passed to genlmsg_reply().
genlmsg_reply() always consumes its argument, not just in the success case.
Ben Pfaff [Thu, 13 Nov 2008 20:44:35 +0000 (12:44 -0800)]
Pull arp header before grabbing the pointer to it.
Ben Pfaff [Wed, 12 Nov 2008 22:42:51 +0000 (14:42 -0800)]
Pull data into headers properly, and checksum ICMP replies correctly.
Ben Pfaff [Wed, 12 Nov 2008 00:51:56 +0000 (16:51 -0800)]
Reset mac header in flow_extract(), because it might initially be null.
__alloc_skb() sets the mac header to null, and not all call chains
reset it.
Ben Pfaff [Wed, 12 Nov 2008 00:18:32 +0000 (16:18 -0800)]
Use skb_copy_bits() to copy data that might not be pulled into headers.
Ben Pfaff [Tue, 11 Nov 2008 23:41:04 +0000 (15:41 -0800)]
Verify in fwd_port_input() that 'skb' has no destructor.
Ben Pfaff [Tue, 11 Nov 2008 23:40:48 +0000 (15:40 -0800)]
Verify in execute_actions() that 'skb' is not shared.
Ben Pfaff [Tue, 11 Nov 2008 23:40:28 +0000 (15:40 -0800)]
Fix datapath make_writable() function.
- We weren't necessarily pulling enough into the headers in the non-shared
case, since the IP header by itself can be longer than 40 bytes.
- The skb is guaranteed not to have a destructor at this point.
Ben Pfaff [Tue, 11 Nov 2008 23:35:26 +0000 (15:35 -0800)]
Make datapath's flow_extract() properly pull data into the headers.
Otherwise we might be reading headers that aren't really there.
Ben Pfaff [Tue, 11 Nov 2008 23:48:08 +0000 (15:48 -0800)]
Add comment.
Ben Pfaff [Tue, 11 Nov 2008 02:26:25 +0000 (18:26 -0800)]
Don't oops in dp_output_control() for skbs with null ->dev.
This shouldn't ordinarily happen, since normal packets are received from
a real device, but some packets can be spontaneously generated within
the switch and thus have null ->dev. (Possibly that is itself a bug
that we should track down; not sure.)
Ben Pfaff [Tue, 11 Nov 2008 22:03:31 +0000 (14:03 -0800)]
Verify in fwd_port_input() that we are not passed packets that are shared.
Ben Pfaff [Tue, 11 Nov 2008 21:57:07 +0000 (13:57 -0800)]
When a packet arrives via bridging, clone it if it is shared.
Otherwise we will mangle the packet for anyone who came before us
(e.g. tcpdump via AF_PACKET).
Ben Pfaff [Tue, 11 Nov 2008 04:56:13 +0000 (20:56 -0800)]
Make sure that do_port_input() always puts a MAC header on packets.
Prompted by persistent oopses on packets received by e1000e, in which
skb_mac_header() for the packet always returned null.
Ben Pfaff [Tue, 11 Nov 2008 21:33:24 +0000 (13:33 -0800)]
In handle_arp_snat() and snat_pre_route() pull enough payload into the headers.
There is no guarantee that the device put any data at all into the header.
The e1000 device, for example, appears to not put any data into the header
when the packet is longer than its configured copybreak value, which is
256 bytes by default. So we need to do it ourselves.
Ben Pfaff [Tue, 11 Nov 2008 20:58:52 +0000 (12:58 -0800)]
In update_mapping(), update m->hw_addr unconditionally.
There is no benefit to comparing it first, since we already know that that
cache line will be dirtied by the assignment to m->used.
Ben Pfaff [Tue, 11 Nov 2008 20:52:24 +0000 (12:52 -0800)]
Factor common SNAT code into new functions.
Ben Pfaff [Tue, 11 Nov 2008 21:01:12 +0000 (13:01 -0800)]
Make snat_skb() skb argument const.
After all, it doesn't modify it.
Ben Pfaff [Tue, 11 Nov 2008 04:06:45 +0000 (20:06 -0800)]
Don't process packets in NAT that aren't destined for us.
This time for sure!
Ben Pfaff [Tue, 11 Nov 2008 22:08:41 +0000 (14:08 -0800)]
Orphan and clone packets transmitted on dp_dev (proper fix for bug #478).
We need to orphan packets transmitted on dp_dev so that any socket that
the packets came from is no longer charged for them. If we don't do
this, then the sk_buff will be destructed eventually, but it is
harder to predict when.
We need to clone packets because we are sticking them on
&dp_dev->xmit_queue, which is done by modifying the sk_buff, which we
can only do if it is not shared.
Ben Pfaff [Wed, 12 Nov 2008 22:58:44 +0000 (14:58 -0800)]
Always compile openflow modules with debug information.
Ben Pfaff [Tue, 11 Nov 2008 20:13:49 +0000 (12:13 -0800)]
Check kmalloc() return value.
Ben Pfaff [Tue, 11 Nov 2008 20:11:31 +0000 (12:11 -0800)]
Fix typo: = should be ==
Ben Pfaff [Tue, 11 Nov 2008 01:45:23 +0000 (17:45 -0800)]
Stopgap fix for bug #478, where kernel panics on SNAT to input port.
Ben Pfaff [Mon, 10 Nov 2008 21:56:11 +0000 (13:56 -0800)]
Fix " is running" and " is not running" messages from openflow-switch init.d
With the "secchan" name in there it makes a lot more sense!
Ben Pfaff [Mon, 10 Nov 2008 18:43:18 +0000 (10:43 -0800)]
Make openflow-switch depend on dmidecode, procps instead of acpi-support.
acpi-support pulls in a lot of stuff we really don't want or need, such
as various X11-related stuff. Being more specific reduces our
dependencies.
Ben Pfaff [Mon, 10 Nov 2008 18:10:02 +0000 (10:10 -0800)]
Add build number to kernel modules built via Debian packaging.
Ben Pfaff [Fri, 7 Nov 2008 01:26:42 +0000 (17:26 -0800)]
Add --with-build-number configure argument and support in debian/rules.
Justin Pettit [Thu, 6 Nov 2008 20:42:07 +0000 (12:42 -0800)]
Add --monitor flag to default init scripts for secchan.
Ben Pfaff [Thu, 6 Nov 2008 18:25:08 +0000 (10:25 -0800)]
New package openflow-dbg for debugging symbols for the rest of OpenFlow.
Ben Pfaff [Thu, 6 Nov 2008 18:07:41 +0000 (10:07 -0800)]
Fix typo in code to set core limit that broke the openflow-switch init script.
Ben Pfaff [Wed, 5 Nov 2008 23:47:44 +0000 (15:47 -0800)]
Add openflow-switch settings for the limit on core files.
Ben Pfaff [Wed, 5 Nov 2008 23:46:25 +0000 (15:46 -0800)]
Add new Debian package "corekeeper" to centralize and reap core files.
Justin Pettit [Wed, 5 Nov 2008 23:24:29 +0000 (15:24 -0800)]
Rename switchmon to switchui.
Ben Pfaff [Wed, 5 Nov 2008 22:07:15 +0000 (14:07 -0800)]
Ignore openflow-monitor and openflow-wdt build directories.
Justin Pettit [Wed, 5 Nov 2008 21:01:05 +0000 (13:01 -0800)]
Add dist_sbin_SCRIPTS make target.
Justin Pettit [Wed, 5 Nov 2008 21:00:45 +0000 (13:00 -0800)]
Have git ignore the monitor and wdt packaging links.
Ben Pfaff [Wed, 5 Nov 2008 18:22:41 +0000 (10:22 -0800)]
When a new OpenFlow kernel module package is installed, restart the switch.
This helps to ensure that the secchan and the kernel module are exactly
the same version.
Ben Pfaff [Wed, 5 Nov 2008 18:20:04 +0000 (10:20 -0800)]
Unload kernel module when stopping switch, in Debian init scripts.
This way, we have a better chance at ensuring that the secchan and the
kernel module are exactly the same version.
Ben Pfaff [Wed, 5 Nov 2008 18:08:47 +0000 (10:08 -0800)]
Add required "subst" script to EXTRA_DIST.
Ben Pfaff [Wed, 5 Nov 2008 18:04:31 +0000 (10:04 -0800)]
Move "update" remote command from base secchan into Debian packaging.
The update command only works with Debian anyway, so there's no point
in installing it elsewhere.
Ben Pfaff [Wed, 5 Nov 2008 18:03:49 +0000 (10:03 -0800)]
New switch remote command for setting configuration parameters.
Ben Pfaff [Wed, 5 Nov 2008 18:03:07 +0000 (10:03 -0800)]
Make ofp-switch-setup preserve config variables that it does not set itself.
Before, it would delete them. This probably kept ofp-switch-setup from
working at all given the changes in openflow-switch.default. Now, it
should do better (but it has not been tested).
Ben Pfaff [Wed, 5 Nov 2008 00:45:21 +0000 (16:45 -0800)]
Add "execute" to dpctl usage message.
Ben Pfaff [Wed, 5 Nov 2008 00:13:42 +0000 (16:13 -0800)]
Fix openflow-switch log rotation.
The vlogconf command syntax was wrong. The pidfile also didn't contain
the right pid (which was fixed in the previous commit).
Ben Pfaff [Wed, 5 Nov 2008 00:11:17 +0000 (16:11 -0800)]
Create vlog sockets after daemonizing, so that pidfiles can be used.
Otherwise, pidfiles contain the process ID of the process that forked
and exited, so that "vlogconf --target <program.pid>" will fail.
Justin Pettit [Tue, 4 Nov 2008 23:01:37 +0000 (15:01 -0800)]
Dump more detailed information about system state from get-logs.
Ben Pfaff [Tue, 4 Nov 2008 22:26:38 +0000 (14:26 -0800)]
Use "set -e" command instead of "#! /bin/sh -e" magic.
Otherwise, running the script through an explicit shell invocation, such
as "sh -x <script>" for debugging, will fail to set -e and therefore the
script's behavior will change.
Ben Pfaff [Tue, 4 Nov 2008 22:24:18 +0000 (14:24 -0800)]
Add missing dependency on openssl to openflow-pki.
Otherwise the ofp-pki script cannot execute it.
Ben Pfaff [Tue, 4 Nov 2008 22:10:00 +0000 (14:10 -0800)]
Add build number to datapath version and --version output from programs.
Ben Pfaff [Tue, 4 Nov 2008 17:34:26 +0000 (09:34 -0800)]
In reboot script, send SIGUSR1 to ofp-switchmon to make it display "Rebooting".
Ben Pfaff [Tue, 4 Nov 2008 01:04:22 +0000 (17:04 -0800)]
Call VLOG_WARN before send_child_message(), to get correct errno value.
Otherwise we end up with nonsense like "failed to stat...: Success" in
the log.
Ben Pfaff [Tue, 4 Nov 2008 01:03:22 +0000 (17:03 -0800)]
Fix location of installed commands.
Ben Pfaff [Tue, 4 Nov 2008 00:26:51 +0000 (16:26 -0800)]
Pass --enable-snat to configure for datapath module also.
Ben Pfaff [Mon, 3 Nov 2008 18:45:38 +0000 (10:45 -0800)]
Make COMMANDS option in openflow-switch defaults file work.
The setting was being accidentally ignored, so commands like "reboot", etc.
would not work at all.
Ben Pfaff [Fri, 31 Oct 2008 21:14:22 +0000 (14:14 -0700)]
Add libncurses5-dev as build dependency for openflow.
Ben Pfaff [Fri, 31 Oct 2008 20:43:33 +0000 (13:43 -0700)]
Implement log rotation in openflow-switch.
Ben Pfaff [Fri, 31 Oct 2008 20:34:35 +0000 (13:34 -0700)]
Make secchan log to file by default.
Ben Pfaff [Fri, 31 Oct 2008 20:33:13 +0000 (13:33 -0700)]
Add /var/log/openflow directory to openflow-common.
This ensures that every system with OpenFlow packages will have this
directory available for logging.
Ben Pfaff [Fri, 31 Oct 2008 20:31:42 +0000 (13:31 -0700)]
Send openssl output to logfile on "ofp-pki self-sign" also.
Ben Pfaff [Fri, 31 Oct 2008 20:51:24 +0000 (13:51 -0700)]
Don't make ofp-pki --log option relative to log directory.
That behavior may have made sense, but it was too surprising.
Ben Pfaff [Fri, 31 Oct 2008 20:50:33 +0000 (13:50 -0700)]
Put ofp-pki logfile in log directory instead of in pki directory.
This should fix problems with trying to log on a machine that doesn't have
openflow-pki installed (because such machines didn't have the pki
directory). Every machine needs the log directory.
Ben Pfaff [Fri, 31 Oct 2008 19:11:31 +0000 (12:11 -0700)]
Fix openflow-datapath-source bugs added in "Simplify debian/rules..." commit.
Ben Pfaff [Fri, 31 Oct 2008 18:24:11 +0000 (11:24 -0700)]
Add settings for switch netmask and gateway for in-band mode to init script.
Previously we supported setting a switch IP address but not those
parameters, which are obviously required also.
Ben Pfaff [Fri, 31 Oct 2008 17:42:59 +0000 (10:42 -0700)]
Add extension hooks to debian/rules.
Ben Pfaff [Fri, 31 Oct 2008 17:40:59 +0000 (10:40 -0700)]
Move ofp-switch-config into new package openflow-switch-config.
This reduces the openflow-switch package's number of dependencies, making
it easier to install.
Ben Pfaff [Fri, 31 Oct 2008 17:07:43 +0000 (10:07 -0700)]
Improve the error message when vconn gets an unexpected version.
Ben Pfaff [Fri, 31 Oct 2008 15:56:51 +0000 (08:56 -0700)]
In openflow-switch init script, correct secchan option name.
Ben Pfaff [Fri, 31 Oct 2008 15:56:03 +0000 (08:56 -0700)]
In openflow-switch init script, do not re-load openflow_mod if already loaded.
Ben Pfaff [Fri, 31 Oct 2008 00:23:06 +0000 (17:23 -0700)]
Ignore openflow-pki-server directory.
Ben Pfaff [Fri, 31 Oct 2008 00:22:26 +0000 (17:22 -0700)]
Add missing header file to datapath/Modules.mk.
This fixes the generated Debian openflow-datapath-source package.
Justin Pettit [Thu, 30 Oct 2008 23:23:27 +0000 (16:23 -0700)]
Pull configuration information from DMI.
Pull configuration information from DMI when available. In its current form,
it will only use DMI information set by Nicira. Otherwise, it will use default
values. This change also makes DPIDs the same as the MAC address of the
local OpenFlow device.
Ben Pfaff [Thu, 30 Oct 2008 17:38:03 +0000 (10:38 -0700)]
Fix vconn_transact() bug introduced in commit
65ac65a6d2,
"Improve the command interface so that it sends back acks or errors."
Oops. That was dumb.
Thanks to Justin for reporting the problem.
Ben Pfaff [Thu, 30 Oct 2008 17:24:36 +0000 (10:24 -0700)]
Simplify debian/rules by adding new openflow-datapath-source.install file.
Ben Pfaff [Thu, 30 Oct 2008 17:24:02 +0000 (10:24 -0700)]
Break HTTP parts of openflow-pki package into new openflow-pki-server package.
Ben Pfaff [Wed, 29 Oct 2008 23:19:43 +0000 (16:19 -0700)]
Fix support for out-of-band control in Debian switch init script.
Not tested.
Ben Pfaff [Wed, 29 Oct 2008 22:15:45 +0000 (15:15 -0700)]
Move exported headers to include/openflow, private headers to lib/.
This makes it easier to install the headers, or to use them directly from
another software package with -I$(openflow)/include, without invading
the top-level include file namespace.
Ben Pfaff [Wed, 29 Oct 2008 20:46:54 +0000 (13:46 -0700)]
New function netdev_set_etheraddr().
Ben Pfaff [Wed, 29 Oct 2008 20:46:34 +0000 (13:46 -0700)]
Fix parsing of logging options in OpenFlow controller.
Oops.
Ben Pfaff [Wed, 29 Oct 2008 18:27:57 +0000 (11:27 -0700)]
Add "self-sign" command to ofp-pki.
Ben Pfaff [Wed, 29 Oct 2008 17:30:36 +0000 (10:30 -0700)]
Fix typo in manpage.
Ben Pfaff [Tue, 28 Oct 2008 19:46:18 +0000 (12:46 -0700)]
Improve the command interface so that it sends back acks or errors.
Ben Pfaff [Mon, 27 Oct 2008 23:37:00 +0000 (16:37 -0700)]
Delete ununsed file Make.vars.
Ben Pfaff [Mon, 27 Oct 2008 22:13:11 +0000 (15:13 -0700)]
Add a warning when secchan is invoked with a controller specified as the datapath.
Ben Pfaff [Mon, 27 Oct 2008 19:55:55 +0000 (12:55 -0700)]
Add Nicira extension for remote command execution.
Ben Pfaff [Fri, 24 Oct 2008 21:25:10 +0000 (14:25 -0700)]
Change the secchan "hook" mechanism to be easier to add new callbacks.
Ben Pfaff [Fri, 24 Oct 2008 21:19:26 +0000 (14:19 -0700)]
Fix typo in default switch config.
Justin Pettit [Sat, 25 Oct 2008 20:29:17 +0000 (13:29 -0700)]
Fix leaking of flows when output action validation fails.
Thanks to Brandon Heller for catching this.
Justin Pettit [Sat, 25 Oct 2008 00:24:06 +0000 (17:24 -0700)]
Fix leaking of flows when output action validation fails.
When action validation fails from a flow add, the flow would be leaked. This
caused the kmem cache (which handles allocating flow entries) to be unhappy
when we try to unload the OpenFlow module.
Thanks to Brandon Heller for catching this.
Ben Pfaff [Fri, 24 Oct 2008 16:43:44 +0000 (09:43 -0700)]
Break secchan into multiple files, to make it more maintainable.
Ben Pfaff [Thu, 23 Oct 2008 21:22:49 +0000 (14:22 -0700)]
Controller need not run as root now that we don't use a port below 1024.
Ben Pfaff [Thu, 23 Oct 2008 21:03:44 +0000 (14:03 -0700)]
Update manpages to mention new --log-file option.
Move vlog option descriptions into a separate file lib/vlog.man that
is substituted into manpages.
Get rid of individual rules for substituting most files in favor of
a single suffix rule. Unfortunately this loses the (Emacs-specific)
read-only markings but it simplifies the makefiles.