]> git.ipfire.org Git - thirdparty/iproute2.git/commitdiff
ip-link: add support for nolocalbypass in vxlan
authorVladimir Nikishkin <vladimir@nikishkin.pw>
Tue, 6 Jun 2023 02:32:02 +0000 (10:32 +0800)
committerDavid Ahern <dsahern@kernel.org>
Tue, 6 Jun 2023 14:30:55 +0000 (08:30 -0600)
Add userspace support for the [no]localbypass vxlan netlink
attribute. With localbypass on (default), the vxlan driver processes
the packets destined to the local machine by itself, bypassing the
userspace nework stack. With nolocalbypass the packets are always
forwarded to the userspace network stack, so userspace programs,
such as tcpdump have a chance to process them.

Signed-off-by: Vladimir Nikishkin <vladimir@nikishkin.pw>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Andrea Claudi <aclaudi@redhat.com>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Signed-off-by: David Ahern <dsahern@kernel.org>
ip/iplink_vxlan.c
man/man8/ip-link.8.in

index 3053cdb861d5112c2c522e7f5af869004863200e..7781d60bbb52fd4473ee89175bae0769af3c0bcb 100644 (file)
@@ -36,6 +36,7 @@ static const struct vxlan_bool_opt {
        { "udp_zero_csum6_rx", IFLA_VXLAN_UDP_ZERO_CSUM6_RX, false },
        { "remcsum_tx", IFLA_VXLAN_REMCSUM_TX,          false },
        { "remcsum_rx", IFLA_VXLAN_REMCSUM_RX,          false },
+       { "localbypass", IFLA_VXLAN_LOCALBYPASS,        true },
 };
 
 static void print_explain(FILE *f)
@@ -62,6 +63,7 @@ static void print_explain(FILE *f)
                "               [ [no]udp6zerocsumtx ]\n"
                "               [ [no]udp6zerocsumrx ]\n"
                "               [ [no]remcsumtx ] [ [no]remcsumrx ]\n"
+               "               [ [no]localbypass ]\n"
                "               [ [no]external ] [ gbp ] [ gpe ]\n"
                "               [ [no]vnifilter ]\n"
                "\n"
@@ -327,6 +329,14 @@ static int vxlan_parse_opt(struct link_util *lu, int argc, char **argv,
                        check_duparg(&attrs, IFLA_VXLAN_REMCSUM_RX,
                                     *argv, *argv);
                        addattr8(n, 1024, IFLA_VXLAN_REMCSUM_RX, 0);
+               } else if (strcmp(*argv, "localbypass") == 0) {
+                       check_duparg(&attrs, IFLA_VXLAN_LOCALBYPASS,
+                                    *argv, *argv);
+                       addattr8(n, 1024, IFLA_VXLAN_LOCALBYPASS, 1);
+               } else if (strcmp(*argv, "nolocalbypass") == 0) {
+                       check_duparg(&attrs, IFLA_VXLAN_LOCALBYPASS,
+                                    *argv, *argv);
+                       addattr8(n, 1024, IFLA_VXLAN_LOCALBYPASS, 0);
                } else if (!matches(*argv, "external")) {
                        check_duparg(&attrs, IFLA_VXLAN_COLLECT_METADATA,
                                     *argv, *argv);
index bf3605a9fa2ea106111836a71abdfdaccd48bf58..6a82ddc45adf4660f449bb0f9803efa76cf22be1 100644 (file)
@@ -634,6 +634,8 @@ the following additional arguments are supported:
 ] [
 .RB [ no ] udp6zerocsumrx
 ] [
+.RB [ no ] localbypass
+] [
 .BI ageing " SECONDS "
 ] [
 .BI maxaddress " NUMBER "
@@ -742,6 +744,14 @@ are entered into the VXLAN device forwarding database.
 .RB [ no ] udp6zerocsumrx
 - allow incoming UDP packets over IPv6 with zero checksum field.
 
+.sp
+.RB [ no ] localbypass
+- if FDB destination is local, with nolocalbypass set, forward encapsulated
+packets to the userspace network stack. If there is a userspace process
+listening for these packets, it will have a chance to process them. If
+localbypass is active (default), bypass the kernel network stack and
+inject the packets into the target VXLAN device, assuming one exists.
+
 .sp
 .BI ageing " SECONDS"
 - specifies the lifetime in seconds of FDB entries learnt by the kernel.