Ben Pfaff [Mon, 27 Oct 2008 22:13:11 +0000 (15:13 -0700)]
Add a warning when secchan is invoked with a controller specified as the datapath.
Ben Pfaff [Mon, 27 Oct 2008 19:55:55 +0000 (12:55 -0700)]
Add Nicira extension for remote command execution.
Ben Pfaff [Fri, 24 Oct 2008 21:25:10 +0000 (14:25 -0700)]
Change the secchan "hook" mechanism to be easier to add new callbacks.
Ben Pfaff [Fri, 24 Oct 2008 21:19:26 +0000 (14:19 -0700)]
Fix typo in default switch config.
Justin Pettit [Sat, 25 Oct 2008 20:29:17 +0000 (13:29 -0700)]
Fix leaking of flows when output action validation fails.
Thanks to Brandon Heller for catching this.
Justin Pettit [Sat, 25 Oct 2008 00:24:06 +0000 (17:24 -0700)]
Fix leaking of flows when output action validation fails.
When action validation fails from a flow add, the flow would be leaked. This
caused the kmem cache (which handles allocating flow entries) to be unhappy
when we try to unload the OpenFlow module.
Thanks to Brandon Heller for catching this.
Ben Pfaff [Fri, 24 Oct 2008 16:43:44 +0000 (09:43 -0700)]
Break secchan into multiple files, to make it more maintainable.
Ben Pfaff [Thu, 23 Oct 2008 21:22:49 +0000 (14:22 -0700)]
Controller need not run as root now that we don't use a port below 1024.
Ben Pfaff [Thu, 23 Oct 2008 21:03:44 +0000 (14:03 -0700)]
Update manpages to mention new --log-file option.
Move vlog option descriptions into a separate file lib/vlog.man that
is substituted into manpages.
Get rid of individual rules for substituting most files in favor of
a single suffix rule. Unfortunately this loses the (Emacs-specific)
read-only markings but it simplifies the makefiles.
Ben Pfaff [Thu, 23 Oct 2008 17:45:39 +0000 (10:45 -0700)]
vlog: Add ability to log to an arbitrary file, and following related changes:
* New command-line options for configuring log files, hence:
- Centralized vlog usage messages.
* New vlogconf action for reopening log files.
* New vlogconf support for specifying a target by pidfile.
Ben Pfaff [Thu, 23 Oct 2008 19:42:18 +0000 (12:42 -0700)]
Create rundir, logdir, pkidir at install time.
Ben Pfaff [Wed, 22 Oct 2008 21:53:25 +0000 (14:53 -0700)]
Make pkidir, rundir, logdir modifiable from "configure" command line.
Make "make" behave properly when these are changed by re-running
"configure", by putting their definitions into a generated file that
depends on Makefile.
Ben Pfaff [Thu, 23 Oct 2008 21:07:01 +0000 (14:07 -0700)]
Introduce logdir (typically /var/log/openflow, by default /usr/local/var/log/openflow).
Ben Pfaff [Wed, 22 Oct 2008 20:50:03 +0000 (13:50 -0700)]
vlog: Avoid calling any function if nothing will be logged.
Ben Pfaff [Thu, 23 Oct 2008 18:08:23 +0000 (11:08 -0700)]
Make the format of vlog messages user-configurable.
Ben Pfaff [Wed, 15 Oct 2008 21:35:13 +0000 (14:35 -0700)]
New functions xvasprintf() and strlcpy() and macro va_copy().
Ben Pfaff [Wed, 15 Oct 2008 21:34:14 +0000 (14:34 -0700)]
New functions ds_put_uninit(), ds_put_char_multiple().
Ben Pfaff [Wed, 22 Oct 2008 21:38:22 +0000 (14:38 -0700)]
Consistently use AM_CPPFLAGS, not AM_CFLAGS, for -D and -I options.
Ben Pfaff [Wed, 22 Oct 2008 21:58:08 +0000 (14:58 -0700)]
Enable SNAT in Debian packages.
Ben Pfaff [Wed, 22 Oct 2008 20:54:44 +0000 (13:54 -0700)]
Avoid making Emacs think that this file contains a local variable list.
Ben Pfaff [Wed, 22 Oct 2008 20:27:03 +0000 (13:27 -0700)]
Add support for bootstrapping the CA certificate to the Debian packaging.
Ben Pfaff [Wed, 22 Oct 2008 21:37:07 +0000 (14:37 -0700)]
No need to pass -DVERSION=... to C compiler: Autoconf puts it into config.h.
Ben Pfaff [Wed, 22 Oct 2008 22:42:16 +0000 (15:42 -0700)]
Make it possible to open more than one vlog client socket at a time.
Justin Pettit [Thu, 23 Oct 2008 00:17:50 +0000 (17:17 -0700)]
Switch default OpenFlow port from 975 and 976 to 6633.
Justin Pettit [Wed, 22 Oct 2008 00:16:28 +0000 (17:16 -0700)]
Fix crash when SNAT support is built and traffic is in-band.
In order to make netfilter happy, we have to create a fake routing table
entry. Unfortunately, the kernel really doesn't like this when it actually
needs to make use of it. This code now removes the link between the packet
and the fake routing entry when the packet is being sent to a local port.
Ben Pfaff [Tue, 21 Oct 2008 23:31:50 +0000 (16:31 -0700)]
Add support for packaging openflowext.
Ben Pfaff [Fri, 17 Oct 2008 23:15:34 +0000 (16:15 -0700)]
Avoid leaving Makefile.am and configure.ac slightly modified by boot.sh.
(This turned out to be more annoying than I expected.)
Ben Pfaff [Fri, 17 Oct 2008 17:12:17 +0000 (10:12 -0700)]
Add missing Debian package dependency.
openflow-pki needs ofp-pki, which is openflow-common.
Thanks to Teemu for reporting the problem.
Ben Pfaff [Fri, 17 Oct 2008 17:07:21 +0000 (10:07 -0700)]
Modify Makefile.am and configure.ac only if they actually change.
Touching them unnecessarily causes Git to think they changed even if
their contents are the same.
Ben Pfaff [Fri, 17 Oct 2008 16:52:37 +0000 (09:52 -0700)]
Fix lib/dhparams.c build failure fallout from earlier build system changes.
Ben Pfaff [Thu, 16 Oct 2008 23:16:36 +0000 (16:16 -0700)]
Centralize daemon option processing and usage.
Ben Pfaff [Thu, 16 Oct 2008 22:54:52 +0000 (15:54 -0700)]
Fix boot.sh behavior when OpenFlow extensions are not available.
Ben Pfaff [Wed, 15 Oct 2008 21:35:52 +0000 (14:35 -0700)]
Delete trailing whitespace in vlog-socket.c
Ben Pfaff [Thu, 16 Oct 2008 20:48:09 +0000 (13:48 -0700)]
Hardcode path to tcpdump as /usr/sbin/tcpdump.
Otherwise it won't be found when run as non-root because such users
typically don't have /usr/sbin in $PATH. (We use tcpdump in a fashion
that doesn't require root privilege.)
Ben Pfaff [Wed, 15 Oct 2008 21:11:12 +0000 (14:11 -0700)]
Fix typo in manpage.
Ben Pfaff [Thu, 16 Oct 2008 18:11:59 +0000 (11:11 -0700)]
Revamp build system to make it easier to integrate openflowext.
Ben Pfaff [Wed, 15 Oct 2008 22:46:48 +0000 (15:46 -0700)]
secchan: Make sure fail-open doesn't drop the first messages from connection.
Fail-open mode is entered or left in a secchan "periodic" callback, which
may not be called immediately after the connection to the controller
actually comes up. This can cause the fail-open local-packet CB to
locally handle messages from the datapath and drop them, causing the
controller to think that it's being ignore and drop the connection.
Thanks to Dan for raising the issue.
Ben Pfaff [Tue, 14 Oct 2008 23:48:47 +0000 (16:48 -0700)]
Rework STP implementation in controller.
Before, we tried to use the port configuration bits to implement STP; e.g.
if a port was in LISTEN state we turned off sending and receiving frame
other than BPDUs. Unfortunately this interacts very badly with in-band
control: when the switch connects to the controller, it can be connected
to the controller over a port that is not in FORWARD, and so then the
controller disabled that port, and the connection eventually dropped when
an echo request/reply failed to get through.
Now, we implement STP by querying the flows on the switch and killing
off the ones that STP does not allow. This works much better because,
although we still kill off the in-band control connection, the in-band
hook in secchan is then able to resurrect it.
--no-stp is still the default since this has not been tested very much.
Ben Pfaff [Tue, 14 Oct 2008 23:11:06 +0000 (16:11 -0700)]
Set DHCP maximum retransmission timeout to 3 seconds in secchan.
This should help discovery complete faster, especially with hops across
multiple OpenFlow switches to the controller.
Ben Pfaff [Tue, 14 Oct 2008 23:08:36 +0000 (16:08 -0700)]
dhcp-client: Log DHCP messages at higher priority.
Logging DHCP messages sent or received with priority DBG made it hard
to see what was happening. So log them at priority WARN, but also make
them less verbose at that level since seeing the whole message is not
too useful most of the time.
Ben Pfaff [Tue, 14 Oct 2008 22:51:26 +0000 (15:51 -0700)]
dhcp-client: Fix computation of timeouts.
The "min_timeout" variable maintained by the DHCP client is measured
in seconds from the time the state was entered, but dhclient_wait()
was interpreting it as seconds from now. This made the DHCP client wait
much longer than necessary in some cases.
Ben Pfaff [Tue, 14 Oct 2008 21:29:03 +0000 (14:29 -0700)]
secchan: Log switch datapath id at startup.
Ben Pfaff [Tue, 14 Oct 2008 19:50:03 +0000 (12:50 -0700)]
New routine ofpbuf_put_zeros() to simplify a common code sequence.
Ben Pfaff [Tue, 14 Oct 2008 20:29:49 +0000 (13:29 -0700)]
secchan: Remove unhelpful STP-related log message.
Ben Pfaff [Tue, 14 Oct 2008 20:10:48 +0000 (13:10 -0700)]
secchan: Increase max number of local_cbs to accommodate STP.
Ben Pfaff [Tue, 14 Oct 2008 17:53:27 +0000 (10:53 -0700)]
Support up to 0xff00 ports in OpenFlow, without changing the implemented max.
Ben Pfaff [Tue, 14 Oct 2008 16:56:14 +0000 (09:56 -0700)]
No problum any more.
Justin Pettit [Tue, 14 Oct 2008 07:08:05 +0000 (00:08 -0700)]
Conditionally leave out a few more things if "--enable-snat" isn't used.
Justin Pettit [Tue, 14 Oct 2008 06:45:29 +0000 (23:45 -0700)]
Remove unnecessary check for validity when dereferencing an array.
Thanks to Masa et al. for pointing this out.
Justin Pettit [Tue, 14 Oct 2008 06:37:46 +0000 (23:37 -0700)]
Fix dereference of previously freed data.
Thanks to Masa et al. for catching this.
Justin Pettit [Tue, 14 Oct 2008 00:49:34 +0000 (17:49 -0700)]
Return error message when a flow can't be added due to full tables.
When a flow cannot be added to any tables because they are full, send
a message with type OFPET_FLOW_MOD_FAILED and code OFPFMFC_ALL_TABLES_FULL.
Justin Pettit [Mon, 13 Oct 2008 22:45:07 +0000 (15:45 -0700)]
Allow SNAT to build on older (2.6.15) and new (2.6.26) kernels.
Justin Pettit [Mon, 13 Oct 2008 21:43:29 +0000 (14:43 -0700)]
When sending error messages, set the length properly.
Ben Pfaff [Mon, 13 Oct 2008 20:56:26 +0000 (13:56 -0700)]
rconn: Never report being in failure mode while connected.
Change
e10dfcf35, "rconn: Be pickier about what constitutes a successful
connection," caused rconn to consider the connection to have failed even
when we are actually connected until one of several message types was
received. Unfortunately, that meant that "fail open" would intercept and
discard all messages sent by the controller until one of those messages
was received. Thus, the controller would never receive a reply to its
feature_request, assume that the connection was busted, and disconnect.
This happened forever, of course.
Fixes bug #242.
Thanks to Reid for reporting this and Dan for help in diagnosis.
Ben Pfaff [Mon, 13 Oct 2008 20:51:50 +0000 (13:51 -0700)]
rconn: Improve log message when peer closes connection.
Justin Pettit [Sun, 12 Oct 2008 07:46:52 +0000 (00:46 -0700)]
Remove OFPT_TABLE reference.
Justin Pettit [Sat, 11 Oct 2008 07:30:02 +0000 (00:30 -0700)]
Add support for Source-NAT to Linux 2.6 datapaths.
To enable SNAT, run configure with the "--enable-snat" flag. This has
only been tested with the 2.6.23 kernel...more diverse testing will follow.
Documentation and a cleaner build setup will also be in a future check-in.
Justin Pettit [Fri, 10 Oct 2008 22:06:43 +0000 (15:06 -0700)]
Free sk_buffs with kfree_skb() instead of just kfree().
Ben Pfaff [Fri, 10 Oct 2008 17:13:12 +0000 (10:13 -0700)]
rconn: Be pickier about what constitutes a successful connection.
When secchan is configured to "fail open" after failing to connect to
a controller for a period of time, it needs a heuristic for what
constitutes a successful connection. Until now, that heuristic was
simply that when it received an OpenFlow message from the controller
(any OpenFlow message), it considered the connection successful.
However, this is no longer good enough, because NOX performs
admission control on connections after sending a number of OpenFlow
messages, in particular after doing OpenFlow version negotiation and
requesting the switch features (and receiving the reply). Thus, this
commit adjusts the heuristic by only considering certain OpenFlow
messages to demonstrate that admission control checks have passed and
thus that the connection should be considered successful.
As a fallback, any connection that persists for 30 seconds or longer is
also considered successful.
An alternate and complementary approach (that this commit does not
implement) would be to use an OpenFlow error message to indicate why
the connection is closing.
Fixes bug #239.
Ben Pfaff [Fri, 10 Oct 2008 16:56:13 +0000 (09:56 -0700)]
Fix inaccurate log message.
Ben Pfaff [Thu, 9 Oct 2008 22:52:17 +0000 (15:52 -0700)]
Update documentation to talk about userspace datapath.
Ben Pfaff [Thu, 9 Oct 2008 18:13:09 +0000 (11:13 -0700)]
Remove secchan dependence on Netlink for connecting to the datapath.
Ben Pfaff [Wed, 8 Oct 2008 21:24:18 +0000 (14:24 -0700)]
Make rconn_disconnect() a no-op if already disconnected.
Ben Pfaff [Wed, 8 Oct 2008 21:11:08 +0000 (14:11 -0700)]
New function stp_set_bridge_id() to change the bridge ID of a running STP.
Ben Pfaff [Wed, 8 Oct 2008 21:09:37 +0000 (14:09 -0700)]
New function dhclient_get_netdev().
Ben Pfaff [Wed, 8 Oct 2008 21:09:18 +0000 (14:09 -0700)]
Implement dhclient_destroy().
This function has always been prototyped in dhcp-client.h, but it had
no users and never got implemented.
Ben Pfaff [Tue, 7 Oct 2008 17:08:45 +0000 (10:08 -0700)]
Add support for TAP virtual network devices in netdev.
Ben Pfaff [Mon, 6 Oct 2008 23:25:56 +0000 (16:25 -0700)]
Fix use-after-free error.
rconn_destroy() decrements the n_queued counters that are set up by
rconn_send(), so we need to destroy the rconn before we destroy anything
that used it.
(This system is more error-prone than I imagined.)
Justin Pettit [Mon, 6 Oct 2008 22:51:06 +0000 (15:51 -0700)]
Unconditionally set skb->dev in dp_set_origin.
If an invalid port index was used in dp_set_origin, the value of skb->dev
was left unchanged. This change causes skb->dev to be set to NULL in those
circumstances. This makes Packet Out and Add Flow messages that use a
buffer id behave like Packet Out without a buffer id.
Justin Pettit [Mon, 6 Oct 2008 22:14:52 +0000 (15:14 -0700)]
Properly set in_port in skb for Flow Mod messages.
When a buffer id is placed in a Flow Mod message, the actions are expected to
be executed against the referenced packet. The kernel implementation was
not setting the input device to what the controller was telling it to use.
Thanks to Natasha for catching this.
Ben Pfaff [Mon, 6 Oct 2008 16:38:05 +0000 (09:38 -0700)]
In ofp_packet_to_string(), make tcpdump print Ethernet headers also.
Ben Pfaff [Fri, 3 Oct 2008 22:10:31 +0000 (15:10 -0700)]
Add explanatory comment to make_unix_socket().
Ben Pfaff [Mon, 6 Oct 2008 16:49:15 +0000 (09:49 -0700)]
No longer necessary to obtain Ethernet header in netdev_send().
Ben Pfaff [Thu, 2 Oct 2008 21:31:29 +0000 (14:31 -0700)]
New function get_unix_name_len() to simplify code.
Ben Pfaff [Tue, 30 Sep 2008 19:26:12 +0000 (12:26 -0700)]
Make ofp_error() preserve the value of errno.
Ben Pfaff [Mon, 6 Oct 2008 16:37:42 +0000 (09:37 -0700)]
Random Ethernet addresses should be private and should not be multicast.
Ben Pfaff [Wed, 1 Oct 2008 18:41:29 +0000 (11:41 -0700)]
Fix typo in comment.
Ben Pfaff [Tue, 30 Sep 2008 23:50:54 +0000 (16:50 -0700)]
Fix typo in comment.
Justin Pettit [Fri, 3 Oct 2008 23:44:13 +0000 (16:44 -0700)]
Add support for vendor-defined and variable-length actions.
Allow vendors to define their own actions. Actions were originally fixed-
length, which was a bit constraining. Actions now contain a length field,
which gives them more flexibility.
Justin Pettit [Tue, 30 Sep 2008 21:19:47 +0000 (14:19 -0700)]
Properly allocate flow action blocks in user-space switch.
The user-space switch was allocating blocks to hold actions in flows that
did not include the action header.
Justin Pettit [Fri, 26 Sep 2008 22:28:41 +0000 (15:28 -0700)]
Show OpenFlow wire version when pretty printing features reply.
This allows easy detection of version number with "dpctl show".
Justin Pettit [Fri, 26 Sep 2008 21:58:17 +0000 (14:58 -0700)]
Remove kernel datapath unit tests.
The tests haven't been seeing much love and are suffering from bit-rot at
this point. We're removing them, since we have other ways to test at
this point.
Justin Pettit [Fri, 26 Sep 2008 20:20:29 +0000 (13:20 -0700)]
Added missing header file.
Justin Pettit [Thu, 25 Sep 2008 22:00:23 +0000 (15:00 -0700)]
Modify VLAN actions to support setting both VID and priority.
Stripping VLANs is now done through the OFPAT_STRIP_VLAN action (i.e., you
don't specify a magic value in the generirc VLAN action). Also, it is now
possible to modify the priority bits associated with the VLAN tag through
the OFPAT_SET_VLAN_PCP action. The OFPAT_SET_DL_VLAN has been renamed to
OFPAT_SET_VLAN_VID.
Ben Pfaff [Wed, 24 Sep 2008 21:09:00 +0000 (14:09 -0700)]
Remove unused, obsolete attributes from OpenFlow netlink protocol.
Ben Pfaff [Wed, 24 Sep 2008 19:43:23 +0000 (12:43 -0700)]
Fix typo in comment.
Ben Pfaff [Wed, 24 Sep 2008 16:44:08 +0000 (09:44 -0700)]
Avoid assertion failure connecting to unsupported remove OpenFlow host.
After increasing the length of an OpenFlow buffer, we need to update the
length in the OpenFlow header.
Ben Pfaff [Tue, 23 Sep 2008 22:47:03 +0000 (15:47 -0700)]
Disable STP in secchan by default (but let --stp enable it).
Justin Pettit [Tue, 23 Sep 2008 22:34:49 +0000 (15:34 -0700)]
Initial checkin of OpenFlow specification LaTeX source.
This version of the specification does not reflect the current checked in
version of OpenFlow. Checkins that follow should bring them in-line. The
TeX version of the spec was produced by Brandon Heller.
Ben Pfaff [Tue, 23 Sep 2008 18:24:30 +0000 (11:24 -0700)]
stp: Turn off STP on ports that are disabled or have no link.
Fixes a problem that a port that is disabled via "ifconfig down" does
not come back up properly when it is brought back up again with "ifconfig
up", if STP is enabled.
Justin Pettit [Tue, 23 Sep 2008 18:22:03 +0000 (11:22 -0700)]
Cleanup printing of ofp_port_mod a bit.
Ben Pfaff [Tue, 23 Sep 2008 16:51:00 +0000 (09:51 -0700)]
stp: Increase hello time to 2 seconds.
An STP advertisement is sent after every expiry of the hello timer, so
this reduces STP advertisements to once every 2 seconds.
Once a second seemed like too often.
Suggested by Justin.
Justin Pettit [Tue, 23 Sep 2008 01:01:39 +0000 (18:01 -0700)]
Make sure to set 'port_no' in ofp_port_mod messages.
Justin Pettit [Tue, 23 Sep 2008 00:59:50 +0000 (17:59 -0700)]
First cut of pretty printer of ofp_port_mod messages.
Justin Pettit [Tue, 23 Sep 2008 00:48:06 +0000 (17:48 -0700)]
Fix some old references to OFPPFL_ in comments.
Justin Pettit [Mon, 22 Sep 2008 22:18:22 +0000 (15:18 -0700)]
Modify OpenFlow commands related to ports to be more expressive.
This new OpenFlow message format provides a cleaner interface and greater
detail and control over ports. It is now possible to see what features
the switch's port is currently configured as having, what it's advertising,
and what it's capable of handling. It is also possible to return the
features advertised by the port's peer.
Ben Pfaff [Sat, 20 Sep 2008 00:03:24 +0000 (17:03 -0700)]
Drop port_watcher support for editing ports.
This was only needed for STP, which doesn't need it anymore.
Ben Pfaff [Sat, 20 Sep 2008 00:02:30 +0000 (17:02 -0700)]
Get rid of per-port STP implemented bits, by reducing OFPP_MAX to 255.
802.1D Spanning Tree Protocol supports a maximum of 255 ports per bridge,
but OpenFlow supported 256, so 1 port had to not implement STP. This
gets rid of the problem by reducing the maximum number of ports to 255.
Justin Pettit [Fri, 19 Sep 2008 23:10:12 +0000 (16:10 -0700)]
Use device notifier in Linux kernel switch for detecting port status changes.
To report on link status and whether a port is administratively enabled or
disabled, the reference switches poll. This change uses the Linux kernel's
device notification system, so that polling isn't necessary.
Ben Pfaff [Fri, 19 Sep 2008 22:37:53 +0000 (15:37 -0700)]
Add the ability to disable the STP implementation.