udp.go 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283
  1. package udp
  2. import (
  3. "fmt"
  4. "encoding/json"
  5. "net"
  6. "os"
  7. "strings"
  8. "sync"
  9. "syscall"
  10. "github.com/coreos/rudder/Godeps/_workspace/src/github.com/docker/libcontainer/netlink"
  11. log "github.com/coreos/rudder/Godeps/_workspace/src/github.com/golang/glog"
  12. "github.com/coreos/rudder/backend"
  13. "github.com/coreos/rudder/pkg/ip"
  14. "github.com/coreos/rudder/pkg/task"
  15. "github.com/coreos/rudder/subnet"
  16. )
  17. const (
  18. encapOverhead = 28 // 20 bytes IP hdr + 8 bytes UDP hdr
  19. defaultPort = 8285
  20. )
  21. type UdpBackend struct {
  22. sm *subnet.SubnetManager
  23. rawCfg json.RawMessage
  24. cfg struct {
  25. Port int
  26. }
  27. ctl *os.File
  28. ctl2 *os.File
  29. tun *os.File
  30. conn *net.UDPConn
  31. mtu int
  32. tunNet ip.IP4Net
  33. stop chan bool
  34. wg sync.WaitGroup
  35. }
  36. func New(sm *subnet.SubnetManager, config json.RawMessage) backend.Backend {
  37. be := UdpBackend{
  38. sm: sm,
  39. rawCfg: config,
  40. stop: make(chan bool),
  41. }
  42. be.cfg.Port = defaultPort
  43. return &be
  44. }
  45. func (m *UdpBackend) Init(extIface *net.Interface, extIP net.IP, ipMasq bool) (ip.IP4Net, int, error) {
  46. // Parse our configuration
  47. if len(m.rawCfg) > 0 {
  48. if err := json.Unmarshal(m.rawCfg, &m.cfg); err != nil {
  49. return ip.IP4Net{}, 0, fmt.Errorf("Error decoding UDP backend config: %v", err)
  50. }
  51. }
  52. // Acquire the lease form subnet manager
  53. attrs := subnet.BaseAttrs{
  54. PublicIP: ip.FromIP(extIP),
  55. }
  56. sn, err := m.sm.AcquireLease(attrs.PublicIP, &attrs, m.stop)
  57. if err != nil {
  58. if err == task.ErrCanceled {
  59. return ip.IP4Net{}, 0, err
  60. } else {
  61. return ip.IP4Net{}, 0, fmt.Errorf("Failed to acquire lease: %s", err)
  62. }
  63. }
  64. // Tunnel's subnet is that of the whole overlay network (e.g. /16)
  65. // and not that of the individual host (e.g. /24)
  66. m.tunNet = ip.IP4Net{
  67. IP: sn.IP,
  68. PrefixLen: m.sm.GetConfig().Network.PrefixLen,
  69. }
  70. // TUN MTU will be smaller b/c of encap (IP+UDP hdrs)
  71. m.mtu = extIface.MTU - encapOverhead
  72. if err = m.initTun(ipMasq); err != nil {
  73. return ip.IP4Net{}, 0, err
  74. }
  75. m.conn, err = net.ListenUDP("udp4", &net.UDPAddr{Port: m.cfg.Port})
  76. if err != nil {
  77. return ip.IP4Net{}, 0, fmt.Errorf("Failed to start listening on UDP socket: %s", err)
  78. }
  79. m.ctl, m.ctl2, err = newCtlSockets()
  80. if err != nil {
  81. return ip.IP4Net{}, 0, fmt.Errorf("Failed to create control socket: %s", err)
  82. }
  83. return sn, m.mtu, nil
  84. }
  85. func (m *UdpBackend) Run() {
  86. // one for each goroutine below
  87. m.wg.Add(2)
  88. go func() {
  89. runCProxy(m.tun, m.conn, m.ctl2, m.tunNet.IP, m.mtu)
  90. m.wg.Done()
  91. }()
  92. go func() {
  93. m.sm.LeaseRenewer(m.stop)
  94. m.wg.Done()
  95. }()
  96. m.monitorEvents()
  97. m.wg.Wait()
  98. }
  99. func (m *UdpBackend) Stop() {
  100. if m.ctl != nil {
  101. stopProxy(m.ctl)
  102. }
  103. close(m.stop)
  104. }
  105. func (m *UdpBackend) Name() string {
  106. return "UDP"
  107. }
  108. func newCtlSockets() (*os.File, *os.File, error) {
  109. fds, err := syscall.Socketpair(syscall.AF_UNIX, syscall.SOCK_SEQPACKET, 0)
  110. if err != nil {
  111. return nil, nil, err
  112. }
  113. f1 := os.NewFile(uintptr(fds[0]), "ctl")
  114. f2 := os.NewFile(uintptr(fds[1]), "ctl")
  115. return f1, f2, nil
  116. }
  117. func (m *UdpBackend) initTun(ipMasq bool) error {
  118. var tunName string
  119. var err error
  120. m.tun, tunName, err = ip.OpenTun("rudder%d")
  121. if err != nil {
  122. log.Error("Failed to open TUN device: ", err)
  123. return err
  124. }
  125. err = configureIface(tunName, m.tunNet, m.mtu)
  126. if err != nil {
  127. return err
  128. }
  129. if ipMasq {
  130. err = setupIpMasq(m.tunNet.Network(), tunName)
  131. if err != nil {
  132. return err
  133. }
  134. }
  135. return nil
  136. }
  137. func configureIface(ifname string, ipn ip.IP4Net, mtu int) error {
  138. iface, err := net.InterfaceByName(ifname)
  139. if err != nil {
  140. log.Error("Failed to lookup interface ", ifname)
  141. return err
  142. }
  143. n := ipn.ToIPNet()
  144. err = netlink.NetworkLinkAddIp(iface, n.IP, n)
  145. if err != nil {
  146. log.Errorf("Failed to add IP address %s to %s: %s", n.IP, ifname, err)
  147. return err
  148. }
  149. err = netlink.NetworkSetMTU(iface, mtu)
  150. if err != nil {
  151. log.Errorf("Failed to set MTU for %s: ", ifname, err)
  152. return err
  153. }
  154. err = netlink.NetworkLinkUp(iface)
  155. if err != nil {
  156. log.Errorf("Failed to set interface %s to UP state: %s", ifname, err)
  157. return err
  158. }
  159. // explicitly add a route since there might be a route for a subnet already
  160. // installed by Docker and then it won't get auto added
  161. err = netlink.AddRoute(ipn.Network().String(), "", "", ifname)
  162. if err != nil && err != syscall.EEXIST {
  163. log.Errorf("Failed to add route (%s -> %s): ", ipn.Network().String(), ifname, err)
  164. return err
  165. }
  166. return nil
  167. }
  168. func setupIpMasq(ipn ip.IP4Net, iface string) error {
  169. ipt, err := ip.NewIPTables()
  170. if err != nil {
  171. log.Error("Failed to setup IP Masquerade. iptables was not found")
  172. return err
  173. }
  174. err = ipt.ClearChain("nat", "RUDDER")
  175. if err != nil {
  176. log.Error("Failed to create/clear RUDDER chain in NAT table: ", err)
  177. return err
  178. }
  179. rules := [][]string{
  180. // This rule makes sure we don't NAT traffic within overlay network (e.g. coming out of docker0)
  181. []string{ "RUDDER", "-d", ipn.String(), "-j", "ACCEPT" },
  182. // This rule makes sure we don't NAT multicast traffic within overlay network
  183. []string{ "RUDDER", "-d", "224.0.0.0/4", "-j", "ACCEPT" },
  184. // This rule will NAT everything originating from our overlay network and
  185. []string{ "RUDDER", "!", "-o", iface, "-j", "MASQUERADE" },
  186. // This rule will take everything coming from overlay and sent it to RUDDER chain
  187. []string{ "POSTROUTING", "-s", ipn.String(), "-j", "RUDDER" },
  188. }
  189. for _, args := range rules {
  190. log.Info("Adding iptables rule: ", strings.Join(args, " "))
  191. err = ipt.AppendUnique("nat", args...)
  192. if err != nil {
  193. log.Error("Failed to insert IP masquerade rule: ", err)
  194. return err
  195. }
  196. }
  197. return nil
  198. }
  199. func (m *UdpBackend) monitorEvents() {
  200. log.Info("Watching for new subnet leases")
  201. evts := make(chan subnet.EventBatch)
  202. m.wg.Add(1)
  203. go func() {
  204. m.sm.WatchLeases(evts, m.stop)
  205. m.wg.Done()
  206. }()
  207. for {
  208. select {
  209. case evtBatch := <-evts:
  210. for _, evt := range evtBatch {
  211. switch evt.Type {
  212. case subnet.SubnetAdded:
  213. log.Info("Subnet added: ", evt.Lease.Network)
  214. var attrs subnet.BaseAttrs
  215. if err := json.Unmarshal([]byte(evt.Lease.Data), &attrs); err != nil {
  216. log.Error("Error decoding subnet lease JSON: ", err)
  217. continue
  218. }
  219. setRoute(m.ctl, evt.Lease.Network, attrs.PublicIP, m.cfg.Port)
  220. case subnet.SubnetRemoved:
  221. log.Info("Subnet removed: ", evt.Lease.Network)
  222. removeRoute(m.ctl, evt.Lease.Network)
  223. default:
  224. log.Error("Internal error: unknown event type: ", int(evt.Type))
  225. }
  226. }
  227. case <-m.stop:
  228. return
  229. }
  230. }
  231. }