public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [pve-devel] [PATCH proxmox-perl-rs 07/10] pve-rs: fabrics: add function to get l2vpn and l3vpn routes for evpn
Date: Thu, 30 Oct 2025 16:48:22 +0100	[thread overview]
Message-ID: <20251030154851.540408-16-s.hanreich@proxmox.com> (raw)
In-Reply-To: <20251030154851.540408-1-s.hanreich@proxmox.com>

From: Gabriel Goller <g.goller@proxmox.com>

Add functions to get the l3vpn and l2vpn routes from frr so that we can
display them in the ui in the evpn zone content view. L3vpn route
retrieval is quite easy, we just get the routes that are in a specific
vrf (the vrf of the zone) (we could do this with iproute2, but we use
vtysh so that we can get all nexthops). For l2vpn we could also use
`bridge fdb`, but then we don't get the VNI and the ip address
associated to the l2vpn route distributed by EVPN. In order to get all
the information we show all the type2 routes that EVPN receives and get
the mac and ip address of them. We also filter by installed and bestpath
so we only display the installed and best routes.

Signed-off-by: Gabriel Goller <g.goller@proxmox.com>
Signed-off-by: Stefan Hanreich <s.hanreich@proxmox.com>
---
 pve-rs/src/bindings/sdn/fabrics.rs | 53 ++++++++++++++++-
 pve-rs/src/sdn/status.rs           | 93 +++++++++++++++++++++++++++++-
 2 files changed, 144 insertions(+), 2 deletions(-)

diff --git a/pve-rs/src/bindings/sdn/fabrics.rs b/pve-rs/src/bindings/sdn/fabrics.rs
index dcd5bcc..a1f056d 100644
--- a/pve-rs/src/bindings/sdn/fabrics.rs
+++ b/pve-rs/src/bindings/sdn/fabrics.rs
@@ -12,7 +12,7 @@ pub mod pve_rs_sdn_fabrics {
     use std::process::Command;
     use std::sync::Mutex;
 
-    use anyhow::{Context, Error};
+    use anyhow::{Context, Error, format_err};
     use openssl::hash::{MessageDigest, hash};
     use serde::{Deserialize, Serialize};
 
@@ -22,6 +22,7 @@ pub mod pve_rs_sdn_fabrics {
     use proxmox_section_config::typed::SectionConfigData;
     use proxmox_ve_config::common::valid::{Valid, Validatable};
 
+    use proxmox_ve_config::sdn::config::{SdnConfig, ZoneConfig};
     use proxmox_ve_config::sdn::fabric::section_config::Section;
     use proxmox_ve_config::sdn::fabric::section_config::fabric::{
         Fabric as ConfigFabric, FabricId,
@@ -662,4 +663,54 @@ pub mod pve_rs_sdn_fabrics {
 
         status::get_status(config, route_status)
     }
+
+    /// Get all the L3 routes for the passed zone.
+    ///
+    /// Every zone has a vrf named `vrf_{zone}`. Show all the L3 (IP) routes on the VRF of the
+    /// zone.
+    #[export]
+    fn l3vpn_routes(zone: String) -> Result<status::L3VPNRoutes, Error> {
+        let command = format!("vtysh -c 'show ip route vrf vrf_{zone} json'");
+        let l3vpn_routes_string =
+            String::from_utf8(Command::new("sh").args(["-c", &command]).output()?.stdout)?;
+        let l3vpn_routes: proxmox_frr::de::Routes = if l3vpn_routes_string.is_empty() {
+            proxmox_frr::de::Routes::default()
+        } else {
+            serde_json::from_str(&l3vpn_routes_string)
+                .with_context(|| "error parsing l3vpn routes")?
+        };
+
+        status::get_l3vpn_routes(&format!("vrf_{zone}"), l3vpn_routes)
+    }
+
+    /// Get all the L2 routes for the passed vnet.
+    ///
+    /// When using VXLAN the vnet "stores" the L2 routes in it's FDB. The best way to retrieve them
+    /// with additional metadata is to query FRR. Use the `show bgp l2vpn evpn route` command.
+    /// To filter by vnet, get the VNI of the vnet from the config and use it in the command.
+    #[export]
+    fn l2vpn_routes(vnet: String) -> Result<status::L2VPNRoutes, Error> {
+        // read config to get the vni of the vnet
+        let raw_config = std::fs::read_to_string("/etc/pve/sdn/.running-config")?;
+        let running_config: proxmox_ve_config::sdn::config::RunningConfig =
+            serde_json::from_str(&raw_config)?;
+        let parsed_config = SdnConfig::try_from(running_config)?;
+
+        let vni = parsed_config
+            .zones()
+            .flat_map(ZoneConfig::vnets)
+            .find(|vnet_config| vnet_config.name().as_ref() == vnet)
+            .ok_or_else(|| format_err!("could not find vnet {vnet}"))?
+            .tag()
+            .ok_or_else(|| format_err!("vnet {vnet} has no tag"))?;
+
+        let command = format!("vtysh -c 'show bgp l2vpn evpn route vni {vni} type 2 json'");
+        let l2vpn_routes_string =
+            String::from_utf8(Command::new("sh").args(["-c", &command]).output()?.stdout)?;
+
+        let routes = serde_json::from_str(&l2vpn_routes_string)
+            .with_context(|| "error parsing l2vpn routes")?;
+
+        status::get_l2vpn_routes(routes)
+    }
 }
diff --git a/pve-rs/src/sdn/status.rs b/pve-rs/src/sdn/status.rs
index c04a0c1..0c9dc0f 100644
--- a/pve-rs/src/sdn/status.rs
+++ b/pve-rs/src/sdn/status.rs
@@ -1,6 +1,8 @@
 use std::collections::{BTreeMap, HashMap, HashSet};
+use std::net::IpAddr;
 
-use proxmox_section_config::typed::SectionConfigData;
+use proxmox_network_types::ip_address::Cidr;
+use proxmox_network_types::mac_address::MacAddress;
 use serde::{Deserialize, Serialize};
 
 use proxmox_frr::de::{self};
@@ -138,3 +140,92 @@ pub fn get_status(
 
     Ok(stats)
 }
+/// Common for nexthops, they can be either a interface name or a ip addr
+#[derive(Debug, Serialize)]
+#[serde(untagged)]
+pub enum IpAddrOrInterfaceName {
+    /// IpAddr
+    IpAddr(IpAddr),
+    /// Interface Name
+    InterfaceName(String),
+}
+
+/// One L3VPN route
+#[derive(Debug, Serialize)]
+pub struct L3VPNRoute {
+    ip: Cidr,
+    protocol: String,
+    metric: i32,
+    nexthops: Vec<IpAddrOrInterfaceName>,
+}
+
+/// All L3VPN routes of a zone
+#[derive(Debug, Serialize)]
+pub struct L3VPNRoutes(Vec<L3VPNRoute>);
+
+/// Convert parsed routes from frr into l3vpn routes, this means we need to match against the vrf
+/// name of the zone.
+pub fn get_l3vpn_routes(vrf: &str, routes: de::Routes) -> Result<L3VPNRoutes, anyhow::Error> {
+    let mut result = Vec::new();
+    for (prefix, routes) in routes.0 {
+        for route in routes {
+            if route.vrf_name == vrf && route.installed.unwrap_or_default() {
+                result.push(L3VPNRoute {
+                    ip: prefix,
+                    metric: route.metric,
+                    protocol: route.protocol,
+                    nexthops: route
+                        .nexthops
+                        .into_iter()
+                        .filter_map(|nh| {
+                            if nh.duplicate.unwrap_or_default() {
+                                return None;
+                            }
+
+                            nh.ip.map(IpAddrOrInterfaceName::IpAddr).or_else(|| {
+                                nh.interface_name.map(IpAddrOrInterfaceName::InterfaceName)
+                            })
+                        })
+                        .collect(),
+                });
+            }
+        }
+    }
+    Ok(L3VPNRoutes(result))
+}
+
+/// One L2VPN route
+#[derive(Debug, Serialize)]
+pub struct L2VPNRoute {
+    mac: MacAddress,
+    ip: IpAddr,
+    nexthop: IpAddr,
+}
+
+/// All L2VPN routes of a specific vnet
+#[derive(Debug, Serialize)]
+pub struct L2VPNRoutes(Vec<L2VPNRoute>);
+
+/// Convert the parsed frr evpn struct into an array of structured L2VPN routes
+pub fn get_l2vpn_routes(routes: de::evpn::Routes) -> Result<L2VPNRoutes, anyhow::Error> {
+    let mut result = Vec::new();
+    for route in routes.0.values() {
+        if let de::evpn::Entry::Route(r) = route {
+            r.paths.iter().flatten().for_each(|path| {
+                if path.bestpath.unwrap_or_default() {
+                    if let (Some(mac), Some(ip), Some(nh)) =
+                        (path.mac, path.ip, path.nexthops.first())
+                    {
+                        result.push(L2VPNRoute {
+                            mac,
+                            ip,
+                            nexthop: nh.ip,
+                        });
+                    }
+                }
+            });
+        }
+    }
+
+    Ok(L2VPNRoutes(result))
+}
-- 
2.47.3


_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel


  parent reply	other threads:[~2025-10-30 15:51 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-10-30 15:48 [pve-devel] [PATCH common/manager/network/proxmox{-ve-rs, -perl-rs} 00/35] Improve status reporting for SDN / networking Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-common 1/2] iproute2: add helper for detecting bridge members Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-common 2/2] iproute2: add helper for querying vlan information Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 1/6] frr: make room for deserialization structs Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 2/6] frr: add deserialization types for openfabric and ospf Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 3/6] ve-config: add helper function to iterate over all nodes in all fabrics Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 4/6] ve-config: add optional tag property to vnet Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 5/6] frr: fix some route deserialization types Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 6/6] frr: add deserialization types for EVPN Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 01/10] pve-rs: firewall: cargo: fmt Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 02/10] pve-rs: firewall: add missing documentation comments Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 03/10] pve-rs: cargo: bump proxmox-apt and proxmox-ve-config versions Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 04/10] pve-rs: fabrics: update proxmox-frr import path Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 05/10] pve-rs: fabrics: fix clippy lint warnings Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 06/10] pve-rs: fabrics: add function to get status of fabric Stefan Hanreich
2025-10-30 15:48 ` Stefan Hanreich [this message]
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 08/10] pve-rs: fabrics: add function to get routes learned by a fabric Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 09/10] pve-rs: fabrics: add function to get the interfaces used for " Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 10/10] pve-rs: fabrics: add function to get the neighbors " Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 1/9] refactor: rework api module structure for the /nodes/{node}/sdn subdir Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 2/9] fabrics: add fabrics status to SDN::status function Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 3/9] sdn: status: add zone type to sdn resource Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 4/9] api: nodes: fabrics: add endpoint for querying route status Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 5/9] api: nodes: fabrics: add endpoint for querying neighbor information Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 6/9] api: nodes: fabrics: add endpoint for querying interface status Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 7/9] api: nodes: zones: add bridge status Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 8/9] api: nodes: zones: add ip vrf endpoint for evpn zones Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 9/9] api: nodes: vnets: add mac-vrf endpoint for evpn vnets Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 1/8] api: nodes: use new status module for sdn subdirectory Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 2/8] refactor: ui: sdn browser: parametrize zone content panel Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 3/8] pvestatd: add network resource to status reporting Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 4/8] pvestatd: sdn: adapt to changes in " Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 5/8] ui: resource tree: add network resource Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 6/8] ui: sdn browser: Add ip-vrf panel for evpn zones Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 7/8] ui: sdn browser: add mac vrf panel Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 8/8] ui: sdn browser: add zone bridge view Stefan Hanreich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251030154851.540408-16-s.hanreich@proxmox.com \
    --to=s.hanreich@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal