udp.go 6.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277
  1. package udp
  2. import (
  3. "fmt"
  4. "encoding/json"
  5. "net"
  6. "os"
  7. "strings"
  8. "sync"
  9. "syscall"
  10. "github.com/coreos/flannel/Godeps/_workspace/src/github.com/vishvananda/netlink"
  11. log "github.com/coreos/flannel/Godeps/_workspace/src/github.com/golang/glog"
  12. "github.com/coreos/flannel/backend"
  13. "github.com/coreos/flannel/pkg/ip"
  14. "github.com/coreos/flannel/pkg/task"
  15. "github.com/coreos/flannel/subnet"
  16. )
  17. const (
  18. encapOverhead = 28 // 20 bytes IP hdr + 8 bytes UDP hdr
  19. defaultPort = 8285
  20. )
  21. type UdpBackend struct {
  22. sm *subnet.SubnetManager
  23. rawCfg json.RawMessage
  24. cfg struct {
  25. Port int
  26. }
  27. ctl *os.File
  28. ctl2 *os.File
  29. tun *os.File
  30. conn *net.UDPConn
  31. mtu int
  32. tunNet ip.IP4Net
  33. stop chan bool
  34. wg sync.WaitGroup
  35. }
  36. func New(sm *subnet.SubnetManager, config json.RawMessage) backend.Backend {
  37. be := UdpBackend{
  38. sm: sm,
  39. rawCfg: config,
  40. stop: make(chan bool),
  41. }
  42. be.cfg.Port = defaultPort
  43. return &be
  44. }
  45. func (m *UdpBackend) Init(extIface *net.Interface, extIP net.IP, ipMasq bool) (*backend.SubnetDef, error) {
  46. // Parse our configuration
  47. if len(m.rawCfg) > 0 {
  48. if err := json.Unmarshal(m.rawCfg, &m.cfg); err != nil {
  49. return nil, fmt.Errorf("error decoding UDP backend config: %v", err)
  50. }
  51. }
  52. // Acquire the lease form subnet manager
  53. attrs := subnet.LeaseAttrs{
  54. PublicIP: ip.FromIP(extIP),
  55. }
  56. sn, err := m.sm.AcquireLease(&attrs, m.stop)
  57. if err != nil {
  58. if err == task.ErrCanceled {
  59. return nil, err
  60. } else {
  61. return nil, fmt.Errorf("failed to acquire lease: %v", err)
  62. }
  63. }
  64. // Tunnel's subnet is that of the whole overlay network (e.g. /16)
  65. // and not that of the individual host (e.g. /24)
  66. m.tunNet = ip.IP4Net{
  67. IP: sn.IP,
  68. PrefixLen: m.sm.GetConfig().Network.PrefixLen,
  69. }
  70. // TUN MTU will be smaller b/c of encap (IP+UDP hdrs)
  71. m.mtu = extIface.MTU - encapOverhead
  72. if err = m.initTun(ipMasq); err != nil {
  73. return nil, err
  74. }
  75. m.conn, err = net.ListenUDP("udp4", &net.UDPAddr{Port: m.cfg.Port})
  76. if err != nil {
  77. return nil, fmt.Errorf("failed to start listening on UDP socket: %v", err)
  78. }
  79. m.ctl, m.ctl2, err = newCtlSockets()
  80. if err != nil {
  81. return nil, fmt.Errorf("failed to create control socket: %v", err)
  82. }
  83. return &backend.SubnetDef{
  84. Net: sn,
  85. MTU: m.mtu,
  86. }, nil
  87. }
  88. func (m *UdpBackend) Run() {
  89. // one for each goroutine below
  90. m.wg.Add(2)
  91. go func() {
  92. runCProxy(m.tun, m.conn, m.ctl2, m.tunNet.IP, m.mtu)
  93. m.wg.Done()
  94. }()
  95. go func() {
  96. m.sm.LeaseRenewer(m.stop)
  97. m.wg.Done()
  98. }()
  99. m.monitorEvents()
  100. m.wg.Wait()
  101. }
  102. func (m *UdpBackend) Stop() {
  103. if m.ctl != nil {
  104. stopProxy(m.ctl)
  105. }
  106. close(m.stop)
  107. }
  108. func (m *UdpBackend) Name() string {
  109. return "UDP"
  110. }
  111. func newCtlSockets() (*os.File, *os.File, error) {
  112. fds, err := syscall.Socketpair(syscall.AF_UNIX, syscall.SOCK_SEQPACKET, 0)
  113. if err != nil {
  114. return nil, nil, err
  115. }
  116. f1 := os.NewFile(uintptr(fds[0]), "ctl")
  117. f2 := os.NewFile(uintptr(fds[1]), "ctl")
  118. return f1, f2, nil
  119. }
  120. func (m *UdpBackend) initTun(ipMasq bool) error {
  121. var tunName string
  122. var err error
  123. m.tun, tunName, err = ip.OpenTun("flannel%d")
  124. if err != nil {
  125. return fmt.Errorf("Failed to open TUN device: %v", err)
  126. }
  127. err = configureIface(tunName, m.tunNet, m.mtu)
  128. if err != nil {
  129. return err
  130. }
  131. if ipMasq {
  132. err = setupIpMasq(m.tunNet.Network(), tunName)
  133. if err != nil {
  134. return err
  135. }
  136. }
  137. return nil
  138. }
  139. func configureIface(ifname string, ipn ip.IP4Net, mtu int) error {
  140. iface, err := netlink.LinkByName(ifname)
  141. if err != nil {
  142. return fmt.Errorf("failed to lookup interface %v", ifname)
  143. }
  144. err = netlink.AddrAdd(iface, &netlink.Addr{ipn.ToIPNet(), ""})
  145. if err != nil {
  146. return fmt.Errorf("failed to add IP address %v to %v: %v", ipn.String(), ifname, err)
  147. }
  148. err = netlink.LinkSetMTU(iface, mtu)
  149. if err != nil {
  150. return fmt.Errorf("failed to set MTU for %v: %v", ifname, err)
  151. }
  152. err = netlink.LinkSetUp(iface)
  153. if err != nil {
  154. return fmt.Errorf("failed to set interface %v to UP state: %v", ifname, err)
  155. }
  156. // explicitly add a route since there might be a route for a subnet already
  157. // installed by Docker and then it won't get auto added
  158. err = netlink.RouteAdd(&netlink.Route{
  159. LinkIndex: iface.Attrs().Index,
  160. Scope: netlink.SCOPE_UNIVERSE,
  161. Dst: ipn.Network().ToIPNet(),
  162. })
  163. if err != nil && err != syscall.EEXIST {
  164. return fmt.Errorf("Failed to add route (%v -> %v): %v", ipn.Network().String(), ifname, err)
  165. }
  166. return nil
  167. }
  168. func setupIpMasq(ipn ip.IP4Net, iface string) error {
  169. ipt, err := ip.NewIPTables()
  170. if err != nil {
  171. return fmt.Errorf("failed to setup IP Masquerade. iptables was not found")
  172. }
  173. err = ipt.ClearChain("nat", "FLANNEL")
  174. if err != nil {
  175. return fmt.Errorf("Failed to create/clear FLANNEL chain in NAT table: %v", err)
  176. }
  177. rules := [][]string{
  178. // This rule makes sure we don't NAT traffic within overlay network (e.g. coming out of docker0)
  179. []string{"FLANNEL", "-d", ipn.String(), "-j", "ACCEPT"},
  180. // This rule makes sure we don't NAT multicast traffic within overlay network
  181. []string{"FLANNEL", "-d", "224.0.0.0/4", "-j", "ACCEPT"}, // This rule will NAT everything originating from our overlay network and
  182. []string{"FLANNEL", "!", "-o", iface, "-j", "MASQUERADE"},
  183. // This rule will take everything coming from overlay and sent it to FLANNEL chain
  184. []string{"POSTROUTING", "-s", ipn.String(), "-j", "FLANNEL"},
  185. }
  186. for _, args := range rules {
  187. log.Info("Adding iptables rule: ", strings.Join(args, " "))
  188. err = ipt.AppendUnique("nat", args...)
  189. if err != nil {
  190. return fmt.Errorf("Failed to insert IP masquerade rule: %v", err)
  191. }
  192. }
  193. return nil
  194. }
  195. func (m *UdpBackend) monitorEvents() {
  196. log.Info("Watching for new subnet leases")
  197. evts := make(chan subnet.EventBatch)
  198. m.wg.Add(1)
  199. go func() {
  200. m.sm.WatchLeases(evts, m.stop)
  201. m.wg.Done()
  202. }()
  203. for {
  204. select {
  205. case evtBatch := <-evts:
  206. m.processSubnetEvents(evtBatch)
  207. case <-m.stop:
  208. return
  209. }
  210. }
  211. }
  212. func (m *UdpBackend) processSubnetEvents(batch subnet.EventBatch) {
  213. for _, evt := range batch {
  214. switch evt.Type {
  215. case subnet.SubnetAdded:
  216. log.Info("Subnet added: ", evt.Lease.Network)
  217. setRoute(m.ctl, evt.Lease.Network, evt.Lease.Attrs.PublicIP, m.cfg.Port)
  218. case subnet.SubnetRemoved:
  219. log.Info("Subnet removed: ", evt.Lease.Network)
  220. removeRoute(m.ctl, evt.Lease.Network)
  221. default:
  222. log.Error("Internal error: unknown event type: ", int(evt.Type))
  223. }
  224. }
  225. }