From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id D74521FF0A7 for ; Wed, 02 Sep 2026 14:47:45 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 3D7E021302; Wed, 02 Sep 2026 14:47:45 +0200 (CEST) From: Hannes Laimer To: pve-devel@lists.proxmox.com Subject: [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF Date: Wed, 2 Sep 2026 14:47:27 +0200 Message-ID: <20260902124739.750853-1-h.laimer@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788353256312 X-SPAM-LEVEL: Spam detection results: 0 AWL -0.824 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLACK 3 Contains an URL listed in the URIBL blacklist [types.rs] Message-ID-Hash: DR6ZFBZTQSGGRYDQJLBWC3TS3CTFQZBC X-Message-ID-Hash: DR6ZFBZTQSGGRYDQJLBWC3TS3CTFQZBC X-MailFrom: h.laimer@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Adds a second DHCP backend, `ebpf`, next to dnsmasq, selectable per zone. It aims to replace dnsmasq eventually, for now it is a second implementation, which keeps a migration simple. Every zone type can enable DHCP through a dropdown selector, `dnsmasq` stays limited to simple zones. The responder is a subsystem of `proxmox-ebpf` [1], Perl reaches it through new pve-rs bindings (PVE::RS::SDN::Dhcp), so the pve-network patches need the pve-rs of this series. Currently only supports DHCPv4, but adding v6 is very possible once we're happy with the overall design. # How An eBPF program on the ingress of every guest tap parses DHCP requests, looks the client MAC up in a mac -> ip+options map and rewrites the request into the reply in place, redirected back out of the tap. The exchange never reaches the bridge. Everything else, including MACs without a map entry, passes untouched, so attaching is a no-op for unmanaged MACs. IPAM is the source of the assignments, the map is a per-node copy of the records, kept current by: - guest start / NIC hotplug / migration: add_dhcp_mapping already fires here and pushes the MAC's record before the interface is plugged, tap_plug then attaches the program. - mapping create/update/delete through the API: the editing node updates its own map and pokes the node running the guest to do the same, detached from the request. Best effort, an unreachable node catches up on its next apply or the guest's next start. - SDN apply: refreshes the programs, drops the link pins of departed guests and rebuilds the map from the current records. - boot: maps start empty, every guest start seeds its own record. Changes made directly on an external IPAM service are not detectable and the per-MAC answers are cached, so they are not picked up on apply either, exactly like with dnsmasq today. The pve-network part applies on top of the separately posted patch pushing ipam API mapping changes to the dhcp backend. Its first patches are preparatory, no negative per-MAC cache entries and a locked cache write, a lease time property on subnets, and asserting a backend's availability only for zones using it. [1] https://lore.proxmox.com/pve-devel/8d63974f-0a73-480b-9407-c6bdc2d576d7@proxmox.com proxmox-ebpf: Hannes Laimer (2): dhcp: add per-tap responder BPF program dhcp: add responder subsystem Cargo.toml | 5 + debian/control | 6 +- src/dhcp/bpf/dhcp.bpf.c | 324 +++++++++++++++++++ src/dhcp/bpf/types.h | 25 ++ src/dhcp/mod.rs | 288 +++++++++++++++++ src/dhcp/types.rs | 53 ++++ src/lib.rs | 3 + src/subsystem.rs | 35 +++ tests/dhcp.rs | 668 ++++++++++++++++++++++++++++++++++++++++ 9 files changed, 1406 insertions(+), 1 deletion(-) create mode 100644 src/dhcp/bpf/dhcp.bpf.c create mode 100644 src/dhcp/bpf/types.h create mode 100644 src/dhcp/mod.rs create mode 100644 src/dhcp/types.rs create mode 100644 tests/dhcp.rs proxmox-perl-rs: Hannes Laimer (1): pve-rs: sdn: add dhcp responder bindings pve-rs/Cargo.toml | 2 + pve-rs/Makefile | 1 + pve-rs/debian/control | 2 + pve-rs/src/bindings/sdn/dhcp.rs | 91 +++++++++++++++++++++++++++++++++ pve-rs/src/bindings/sdn/mod.rs | 1 + 5 files changed, 97 insertions(+) create mode 100644 pve-rs/src/bindings/sdn/dhcp.rs pve-network: Hannes Laimer (8): sdn: ipam: do not cache negative per-MAC answers, lock the write sdn: subnets: add dhcp-lease-time property sdn: dhcp: only assert a backend's availability for zones using it sdn: dhcp: add ebpf plugin sdn: zones: attach the dhcp responder on tap plug sdn: dhcp: apply mapping edits on the node serving the guest sdn: zones: offer dhcp on all zone types, keep dnsmasq simple-only tests: cover the ebpf dhcp backend and ipam API mapping pushes src/PVE/API2/Network/SDN/Ips.pm | 5 +- src/PVE/API2/Network/SDN/Nodes/Status.pm | 37 ++++- src/PVE/API2/Network/SDN/Zones.pm | 8 +- src/PVE/Network/SDN/Dhcp.pm | 87 ++++++++++- src/PVE/Network/SDN/Dhcp/Ebpf.pm | 173 ++++++++++++++++++++++ src/PVE/Network/SDN/Dhcp/Makefile | 2 +- src/PVE/Network/SDN/Ipams.pm | 20 ++- src/PVE/Network/SDN/SubnetPlugin.pm | 7 + src/PVE/Network/SDN/Zones.pm | 4 + src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 1 + src/PVE/Network/SDN/Zones/FaucetPlugin.pm | 1 + src/PVE/Network/SDN/Zones/QinQPlugin.pm | 7 + src/PVE/Network/SDN/Zones/VlanPlugin.pm | 7 + src/PVE/Network/SDN/Zones/VxlanPlugin.pm | 9 ++ src/test/run_test_vnets_blackbox.pl | 147 ++++++++++++++++++ 15 files changed, 502 insertions(+), 13 deletions(-) create mode 100644 src/PVE/Network/SDN/Dhcp/Ebpf.pm pve-manager: Hannes Laimer (1): ui: sdn: dhcp backend selector on all zones, expose dhcp options www/manager6/sdn/SubnetEdit.js | 24 ++++++++++++++++++++++++ www/manager6/sdn/zones/Base.js | 17 +++++++++++++++++ www/manager6/sdn/zones/SimpleEdit.js | 11 ----------- 3 files changed, 41 insertions(+), 11 deletions(-) Summary over all repositories: 32 files changed, 2046 insertions(+), 25 deletions(-) -- Generated by murpp 0.12.0