From: Jakub Sitnicki <hidden> Date: 2016-10-28 12:32:38
The motivation for this series is to route ICMPv6 error messages
together with the flow they belong to when multipath routing is in
use. It intends to bring the ECMP routing in IPv6 stack on par with
IPv4.
This enables the use of tools that rely on ICMP error messages such as
traceroute and makes PMTU discovery work both ways. However, for it to
work IPv6 flow labels have to be same in both directions
(i.e. reflected) or need to be chosen in a manner that ensures that
the flow going in the opposite direction would actually be routed to a
given path.
Even though we generally don't expect this, as receiving and sending
IPv6 are free to choose flow labels at will, we make an assumption
here that the enitity in charge of configuring ECMP routing will also
be in control of the server hosts, and can set up flow label
reflection. However, if this is not the case, the patchset doesn't
make the situation worse.
One potential user of the changes here would be an anycast service
hosted behind an ECMP router(s).
Changes have been tested in a virtual setup with a topology as below:
Re1 --- Hs1
/
Hc --- Ri --- Rc
\
Re1 --- Hs2
Hc - client host
HsX - server host
Rc - core router
ReX - edge router
Ri - intermediate router
To test the changes, traceroute in UDP mode to the client host, with
flow label set, has been run from one of the server hosts. Full test
is available at [1].
-Jakub
[1] https://github.com/jsitnicki/tools/blob/master/net/tests/ecmp/test-ecmp-icmpv6-error-routing.sh
v1 -> v2:
- don't use "extern" in external function declaration in header file,
pointed out by David Miller;
- style change, put as many arguments as possible on the first line of
a function call, and align consecutive lines to the first argument,
pointed out by David Miller;
- expand the cover letter based on the feedback from David Miller and
Hannes Sowa;
Jakub Sitnicki (5):
ipv6: Fold rt6_info_hash_nhsfn() into its only caller
net: Extend struct flowi6 with multipath hash
ipv6: Use multipath hash from flow info if available
ipv6: Compute multipath hash for sent ICMP errors from offending
packet
ipv6: Compute multipath hash for forwarded ICMP errors from offending
packet
include/linux/icmpv6.h | 2 ++
include/net/flow.h | 1 +
net/ipv6/icmp.c | 21 +++++++++++++++++++++
net/ipv6/route.c | 40 +++++++++++++++++++++++++++++-----------
4 files changed, 53 insertions(+), 11 deletions(-)
--
2.7.4
From: Jakub Sitnicki <hidden> Date: 2016-10-28 12:32:40
Allow for functions that fill out the IPv6 flow info to also pass a hash
computed over the skb contents. The hash value will drive the multipath
routing decisions.
This is intended for special treatment of ICMPv6 errors, where we would
like to make a routing decision based on the flow identifying the
offending IPv6 datagram that triggered the error, rather than the flow
of the ICMP error itself.
Signed-off-by: Jakub Sitnicki <redacted>
Acked-by: Hannes Frederic Sowa <redacted>
---
include/net/flow.h | 1 +
1 file changed, 1 insertion(+)
From: Jakub Sitnicki <hidden> Date: 2016-10-28 12:32:41
Allow our callers to influence the choice of ECMP link by honoring the
hash passed together with the flow info. This will allow for special
treatment of ICMP errors which we would like to route over the same link
as the IP datagram that triggered the error.
Signed-off-by: Jakub Sitnicki <redacted>
Acked-by: Hannes Frederic Sowa <redacted>
---
net/ipv6/route.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
From: Jakub Sitnicki <hidden> Date: 2016-10-28 12:32:42
Commit 644d0e656958 ("ipv6 Use get_hash_from_flowi6 for rt6 hash") has
turned rt6_info_hash_nhsfn() into a one-liner, so it no longer makes
sense to keep it around.
Also the accompanying documentation comment has become outdated, so just
remove it altogether.
Signed-off-by: Jakub Sitnicki <redacted>
Acked-by: Hannes Frederic Sowa <redacted>
---
net/ipv6/route.c | 12 +-----------
1 file changed, 1 insertion(+), 11 deletions(-)
From: Jakub Sitnicki <hidden> Date: 2016-10-28 12:32:43
Improve debuggability with tools like traceroute and make PMTUD work in
setups that make use of ECMP routing by sending ICMP errors down the
same path as the offending packet would travel, if it was going in the
opposite direction.
There is a caveat, flows in both directions need use the same
label. Otherwise packets from flow in the opposite direction and ICMP
errors will not be routed over the same ECMP link.
Export the function for calculating the multipath hash so that we can
use it also on receive side, when forwarding ICMP errors.
v1 -> v2:
- don't use "extern" in external function declaration in header file,
pointed out by David Miller
Signed-off-by: Jakub Sitnicki <redacted>
Acked-by: Hannes Frederic Sowa <redacted>
---
include/linux/icmpv6.h | 2 ++
net/ipv6/icmp.c | 21 +++++++++++++++++++++
2 files changed, 23 insertions(+)
@@ -385,6 +385,26 @@ static struct dst_entry *icmpv6_route_lookup(struct net *net,returnERR_PTR(err);}+u32icmpv6_multipath_hash(conststructipv6hdr*iph)+{+structflowi6fl6;++/* Calculate the multipath hash from the offending IP datagram that+*triggeredtheICMPerror.Thesourceanddestinationaddressesare+*swappedaswedoourbesttoroutetheICMPmessagetogetherwiththe+*flowitbelongsto.However,flowsinbothdirectionshavetohave+*thesamelabel(e.g.byusingflowlabelreflection)foritto+*happen.+*/+memset(&fl6,0,sizeof(fl6));+fl6.daddr=iph->saddr;+fl6.saddr=iph->daddr;+fl6.flowlabel=ip6_flowinfo(iph);+fl6.flowi6_proto=iph->nexthdr;++returnget_hash_from_flowi6(&fl6);+}+/**SendanICMPmessageinresponsetoapacketinerror*/
From: Jakub Sitnicki <hidden> Date: 2016-10-28 12:32:44
Same as for the transmit path, let's do our best to ensure that received
ICMP errors that may be subject to forwarding will be routed the same
path as flow that triggered the error, if it was going in the opposite
direction.
v1 -> v2:
- style change, put as many arguments as possible on the first line of
a function call, and align consecutive lines to the first argument,
pointed out by David Miller
Signed-off-by: Jakub Sitnicki <redacted>
Acked-by: Hannes Frederic Sowa <redacted>
---
net/ipv6/route.c | 26 ++++++++++++++++++++++++++
1 file changed, 26 insertions(+)
@@ -1150,6 +1150,30 @@ struct dst_entry *ip6_route_input_lookup(struct net *net,}EXPORT_SYMBOL_GPL(ip6_route_input_lookup);+staticu32ip6_multipath_icmp_hash(conststructsk_buff*skb)+{+conststructicmp6hdr*icmph=icmp6_hdr(skb);+conststructipv6hdr*inner_iph;+structipv6hdr_inner_iph;++if(icmph->icmp6_type!=ICMPV6_DEST_UNREACH&&+icmph->icmp6_type!=ICMPV6_PKT_TOOBIG&&+icmph->icmp6_type!=ICMPV6_TIME_EXCEED&&+icmph->icmp6_type!=ICMPV6_PARAMPROB)+gotostandard_hash;++inner_iph=skb_header_pointer(skb,+skb_transport_offset(skb)+sizeof(*icmph),+sizeof(_inner_iph),&_inner_iph);+if(!inner_iph)+gotostandard_hash;++returnicmpv6_multipath_hash(inner_iph);++standard_hash:+return0;/* compute it later, if needed */+}+voidip6_route_input(structsk_buff*skb){conststructipv6hdr*iph=ipv6_hdr(skb);