udp.go 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282
  1. package udp
  2. import (
  3. "fmt"
  4. "encoding/json"
  5. "net"
  6. "os"
  7. "strings"
  8. "sync"
  9. "syscall"
  10. "github.com/coreos/rudder/Godeps/_workspace/src/github.com/docker/libcontainer/netlink"
  11. log "github.com/coreos/rudder/Godeps/_workspace/src/github.com/golang/glog"
  12. "github.com/coreos/rudder/backend"
  13. "github.com/coreos/rudder/pkg/ip"
  14. "github.com/coreos/rudder/pkg/task"
  15. "github.com/coreos/rudder/subnet"
  16. )
  17. const (
  18. encapOverhead = 28 // 20 bytes IP hdr + 8 bytes UDP hdr
  19. defaultPort = 8285
  20. )
  21. type UdpBackend struct {
  22. sm *subnet.SubnetManager
  23. rawCfg json.RawMessage
  24. cfg struct {
  25. Port int
  26. }
  27. ctl *os.File
  28. ctl2 *os.File
  29. tun *os.File
  30. conn *net.UDPConn
  31. mtu int
  32. tunNet ip.IP4Net
  33. stop chan bool
  34. wg sync.WaitGroup
  35. }
  36. func New(sm *subnet.SubnetManager, config json.RawMessage) backend.Backend {
  37. be := UdpBackend{
  38. sm: sm,
  39. rawCfg: config,
  40. stop: make(chan bool),
  41. }
  42. be.cfg.Port = defaultPort
  43. return &be
  44. }
  45. func (m *UdpBackend) Init(extIface *net.Interface, extIP net.IP, ipMasq bool) (*backend.SubnetDef, error) {
  46. // Parse our configuration
  47. if len(m.rawCfg) > 0 {
  48. if err := json.Unmarshal(m.rawCfg, &m.cfg); err != nil {
  49. return nil, fmt.Errorf("error decoding UDP backend config: %v", err)
  50. }
  51. }
  52. // Acquire the lease form subnet manager
  53. attrs := subnet.BaseAttrs{
  54. PublicIP: ip.FromIP(extIP),
  55. }
  56. sn, err := m.sm.AcquireLease(attrs.PublicIP, &attrs, m.stop)
  57. if err != nil {
  58. if err == task.ErrCanceled {
  59. return nil, err
  60. } else {
  61. return nil, fmt.Errorf("failed to acquire lease: %v", err)
  62. }
  63. }
  64. // Tunnel's subnet is that of the whole overlay network (e.g. /16)
  65. // and not that of the individual host (e.g. /24)
  66. m.tunNet = ip.IP4Net{
  67. IP: sn.IP,
  68. PrefixLen: m.sm.GetConfig().Network.PrefixLen,
  69. }
  70. // TUN MTU will be smaller b/c of encap (IP+UDP hdrs)
  71. m.mtu = extIface.MTU - encapOverhead
  72. if err = m.initTun(ipMasq); err != nil {
  73. return nil, err
  74. }
  75. m.conn, err = net.ListenUDP("udp4", &net.UDPAddr{Port: m.cfg.Port})
  76. if err != nil {
  77. return nil, fmt.Errorf("failed to start listening on UDP socket: %v", err)
  78. }
  79. m.ctl, m.ctl2, err = newCtlSockets()
  80. if err != nil {
  81. return nil, fmt.Errorf("failed to create control socket: %v", err)
  82. }
  83. return &backend.SubnetDef{
  84. Net: sn,
  85. MTU: m.mtu,
  86. }, nil
  87. }
  88. func (m *UdpBackend) Run() {
  89. // one for each goroutine below
  90. m.wg.Add(2)
  91. go func() {
  92. runCProxy(m.tun, m.conn, m.ctl2, m.tunNet.IP, m.mtu)
  93. m.wg.Done()
  94. }()
  95. go func() {
  96. m.sm.LeaseRenewer(m.stop)
  97. m.wg.Done()
  98. }()
  99. m.monitorEvents()
  100. m.wg.Wait()
  101. }
  102. func (m *UdpBackend) Stop() {
  103. if m.ctl != nil {
  104. stopProxy(m.ctl)
  105. }
  106. close(m.stop)
  107. }
  108. func (m *UdpBackend) Name() string {
  109. return "UDP"
  110. }
  111. func newCtlSockets() (*os.File, *os.File, error) {
  112. fds, err := syscall.Socketpair(syscall.AF_UNIX, syscall.SOCK_SEQPACKET, 0)
  113. if err != nil {
  114. return nil, nil, err
  115. }
  116. f1 := os.NewFile(uintptr(fds[0]), "ctl")
  117. f2 := os.NewFile(uintptr(fds[1]), "ctl")
  118. return f1, f2, nil
  119. }
  120. func (m *UdpBackend) initTun(ipMasq bool) error {
  121. var tunName string
  122. var err error
  123. m.tun, tunName, err = ip.OpenTun("rudder%d")
  124. if err != nil {
  125. return fmt.Errorf("Failed to open TUN device: %v", err)
  126. }
  127. err = configureIface(tunName, m.tunNet, m.mtu)
  128. if err != nil {
  129. return err
  130. }
  131. if ipMasq {
  132. err = setupIpMasq(m.tunNet.Network(), tunName)
  133. if err != nil {
  134. return err
  135. }
  136. }
  137. return nil
  138. }
  139. func configureIface(ifname string, ipn ip.IP4Net, mtu int) error {
  140. iface, err := net.InterfaceByName(ifname)
  141. if err != nil {
  142. return fmt.Errorf("failed to lookup interface %v", ifname)
  143. }
  144. n := ipn.ToIPNet()
  145. err = netlink.NetworkLinkAddIp(iface, n.IP, n)
  146. if err != nil {
  147. return fmt.Errorf("failed to add IP address %v to %v: %v", n.IP, ifname, err)
  148. }
  149. err = netlink.NetworkSetMTU(iface, mtu)
  150. if err != nil {
  151. return fmt.Errorf("failed to set MTU for %v: %v", ifname, err)
  152. }
  153. err = netlink.NetworkLinkUp(iface)
  154. if err != nil {
  155. return fmt.Errorf("failed to set interface %v to UP state: %v", ifname, err)
  156. }
  157. // explicitly add a route since there might be a route for a subnet already
  158. // installed by Docker and then it won't get auto added
  159. err = netlink.AddRoute(ipn.Network().String(), "", "", ifname)
  160. if err != nil && err != syscall.EEXIST {
  161. return fmt.Errorf("Failed to add route (%v -> %v): %v", ipn.Network().String(), ifname, err)
  162. }
  163. return nil
  164. }
  165. func setupIpMasq(ipn ip.IP4Net, iface string) error {
  166. ipt, err := ip.NewIPTables()
  167. if err != nil {
  168. return fmt.Errorf("failed to setup IP Masquerade. iptables was not found")
  169. }
  170. err = ipt.ClearChain("nat", "RUDDER")
  171. if err != nil {
  172. return fmt.Errorf("Failed to create/clear RUDDER chain in NAT table: %v", err)
  173. }
  174. rules := [][]string{
  175. // This rule makes sure we don't NAT traffic within overlay network (e.g. coming out of docker0)
  176. []string{ "RUDDER", "-d", ipn.String(), "-j", "ACCEPT" },
  177. // This rule makes sure we don't NAT multicast traffic within overlay network
  178. []string{ "RUDDER", "-d", "224.0.0.0/4", "-j", "ACCEPT" },
  179. // This rule will NAT everything originating from our overlay network and
  180. []string{ "RUDDER", "!", "-o", iface, "-j", "MASQUERADE" },
  181. // This rule will take everything coming from overlay and sent it to RUDDER chain
  182. []string{ "POSTROUTING", "-s", ipn.String(), "-j", "RUDDER" },
  183. }
  184. for _, args := range rules {
  185. log.Info("Adding iptables rule: ", strings.Join(args, " "))
  186. err = ipt.AppendUnique("nat", args...)
  187. if err != nil {
  188. return fmt.Errorf("Failed to insert IP masquerade rule: %v", err)
  189. }
  190. }
  191. return nil
  192. }
  193. func (m *UdpBackend) monitorEvents() {
  194. log.Info("Watching for new subnet leases")
  195. evts := make(chan subnet.EventBatch)
  196. m.wg.Add(1)
  197. go func() {
  198. m.sm.WatchLeases(evts, m.stop)
  199. m.wg.Done()
  200. }()
  201. for {
  202. select {
  203. case evtBatch := <-evts:
  204. m.processSubnetEvents(evtBatch)
  205. case <-m.stop:
  206. return
  207. }
  208. }
  209. }
  210. func (m *UdpBackend) processSubnetEvents(batch subnet.EventBatch) {
  211. for _, evt := range batch {
  212. switch evt.Type {
  213. case subnet.SubnetAdded:
  214. log.Info("Subnet added: ", evt.Lease.Network)
  215. var attrs subnet.BaseAttrs
  216. if err := json.Unmarshal([]byte(evt.Lease.Data), &attrs); err != nil {
  217. log.Error("Error decoding subnet lease JSON: ", err)
  218. continue
  219. }
  220. setRoute(m.ctl, evt.Lease.Network, attrs.PublicIP, m.cfg.Port)
  221. case subnet.SubnetRemoved:
  222. log.Info("Subnet removed: ", evt.Lease.Network)
  223. removeRoute(m.ctl, evt.Lease.Network)
  224. default:
  225. log.Error("Internal error: unknown event type: ", int(evt.Type))
  226. }
  227. }
  228. }