From: Hannes Laimer <h.laimer@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF
Date: Wed, 2 Sep 2026 14:47:27 +0200 [thread overview]
Message-ID: <20260902124739.750853-1-h.laimer@proxmox.com> (raw)
Adds a second DHCP backend, `ebpf`, next to dnsmasq, selectable per
zone. It aims to replace dnsmasq eventually, for now it is a second
implementation, which keeps a migration simple. Every zone type can
enable DHCP through a dropdown selector, `dnsmasq` stays limited to
simple zones.
The responder is a subsystem of `proxmox-ebpf` [1], Perl reaches it
through new pve-rs bindings (PVE::RS::SDN::Dhcp), so the pve-network
patches need the pve-rs of this series.
Currently only supports DHCPv4, but adding v6 is very possible once we're happy
with the overall design.
# How
An eBPF program on the ingress of every guest tap parses DHCP requests,
looks the client MAC up in a mac -> ip+options map and rewrites the
request into the reply in place, redirected back out of the tap. The
exchange never reaches the bridge. Everything else, including MACs
without a map entry, passes untouched, so attaching is a no-op for
unmanaged MACs.
IPAM is the source of the assignments, the map is a per-node copy of
the records, kept current by:
- guest start / NIC hotplug / migration: add_dhcp_mapping already
fires here and pushes the MAC's record before the interface is
plugged, tap_plug then attaches the program.
- mapping create/update/delete through the API: the editing node
updates its own map and pokes the node running the guest to do the
same, detached from the request. Best effort, an unreachable node
catches up on its next apply or the guest's next start.
- SDN apply: refreshes the programs, drops the link pins of departed
guests and rebuilds the map from the current records.
- boot: maps start empty, every guest start seeds its own record.
Changes made directly on an external IPAM service are not detectable
and the per-MAC answers are cached, so they are not picked up on apply
either, exactly like with dnsmasq today.
The pve-network part applies on top of the separately posted patch
pushing ipam API mapping changes to the dhcp backend. Its first
patches are preparatory, no negative per-MAC cache entries and a
locked cache write, a lease time property on subnets, and asserting a
backend's availability only for zones using it.
[1] https://lore.proxmox.com/pve-devel/8d63974f-0a73-480b-9407-c6bdc2d576d7@proxmox.com
proxmox-ebpf:
Hannes Laimer (2):
dhcp: add per-tap responder BPF program
dhcp: add responder subsystem
Cargo.toml | 5 +
debian/control | 6 +-
src/dhcp/bpf/dhcp.bpf.c | 324 +++++++++++++++++++
src/dhcp/bpf/types.h | 25 ++
src/dhcp/mod.rs | 288 +++++++++++++++++
src/dhcp/types.rs | 53 ++++
src/lib.rs | 3 +
src/subsystem.rs | 35 +++
tests/dhcp.rs | 668 ++++++++++++++++++++++++++++++++++++++++
9 files changed, 1406 insertions(+), 1 deletion(-)
create mode 100644 src/dhcp/bpf/dhcp.bpf.c
create mode 100644 src/dhcp/bpf/types.h
create mode 100644 src/dhcp/mod.rs
create mode 100644 src/dhcp/types.rs
create mode 100644 tests/dhcp.rs
proxmox-perl-rs:
Hannes Laimer (1):
pve-rs: sdn: add dhcp responder bindings
pve-rs/Cargo.toml | 2 +
pve-rs/Makefile | 1 +
pve-rs/debian/control | 2 +
pve-rs/src/bindings/sdn/dhcp.rs | 91 +++++++++++++++++++++++++++++++++
pve-rs/src/bindings/sdn/mod.rs | 1 +
5 files changed, 97 insertions(+)
create mode 100644 pve-rs/src/bindings/sdn/dhcp.rs
pve-network:
Hannes Laimer (8):
sdn: ipam: do not cache negative per-MAC answers, lock the write
sdn: subnets: add dhcp-lease-time property
sdn: dhcp: only assert a backend's availability for zones using it
sdn: dhcp: add ebpf plugin
sdn: zones: attach the dhcp responder on tap plug
sdn: dhcp: apply mapping edits on the node serving the guest
sdn: zones: offer dhcp on all zone types, keep dnsmasq simple-only
tests: cover the ebpf dhcp backend and ipam API mapping pushes
src/PVE/API2/Network/SDN/Ips.pm | 5 +-
src/PVE/API2/Network/SDN/Nodes/Status.pm | 37 ++++-
src/PVE/API2/Network/SDN/Zones.pm | 8 +-
src/PVE/Network/SDN/Dhcp.pm | 87 ++++++++++-
src/PVE/Network/SDN/Dhcp/Ebpf.pm | 173 ++++++++++++++++++++++
src/PVE/Network/SDN/Dhcp/Makefile | 2 +-
src/PVE/Network/SDN/Ipams.pm | 20 ++-
src/PVE/Network/SDN/SubnetPlugin.pm | 7 +
src/PVE/Network/SDN/Zones.pm | 4 +
src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 1 +
src/PVE/Network/SDN/Zones/FaucetPlugin.pm | 1 +
src/PVE/Network/SDN/Zones/QinQPlugin.pm | 7 +
src/PVE/Network/SDN/Zones/VlanPlugin.pm | 7 +
src/PVE/Network/SDN/Zones/VxlanPlugin.pm | 9 ++
src/test/run_test_vnets_blackbox.pl | 147 ++++++++++++++++++
15 files changed, 502 insertions(+), 13 deletions(-)
create mode 100644 src/PVE/Network/SDN/Dhcp/Ebpf.pm
pve-manager:
Hannes Laimer (1):
ui: sdn: dhcp backend selector on all zones, expose dhcp options
www/manager6/sdn/SubnetEdit.js | 24 ++++++++++++++++++++++++
www/manager6/sdn/zones/Base.js | 17 +++++++++++++++++
www/manager6/sdn/zones/SimpleEdit.js | 11 -----------
3 files changed, 41 insertions(+), 11 deletions(-)
Summary over all repositories:
32 files changed, 2046 insertions(+), 25 deletions(-)
--
Generated by murpp 0.12.0
next reply other threads:[~2026-09-02 12:47 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 12:47 Hannes Laimer [this message]
2026-09-02 12:47 ` [PATCH proxmox-ebpf 01/12] dhcp: add per-tap responder BPF program Hannes Laimer
2026-09-02 12:47 ` [PATCH proxmox-ebpf 02/12] dhcp: add responder subsystem Hannes Laimer
2026-09-02 12:47 ` [PATCH proxmox-perl-rs 03/12] pve-rs: sdn: add dhcp responder bindings Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 04/12] sdn: ipam: do not cache negative per-MAC answers, lock the write Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 05/12] sdn: subnets: add dhcp-lease-time property Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 06/12] sdn: dhcp: only assert a backend's availability for zones using it Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 07/12] sdn: dhcp: add ebpf plugin Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 08/12] sdn: zones: attach the dhcp responder on tap plug Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 09/12] sdn: dhcp: apply mapping edits on the node serving the guest Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 10/12] sdn: zones: offer dhcp on all zone types, keep dnsmasq simple-only Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 11/12] tests: cover the ebpf dhcp backend and ipam API mapping pushes Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-manager 12/12] ui: sdn: dhcp backend selector on all zones, expose dhcp options Hannes Laimer
2026-09-02 12:54 ` [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF Hannes Laimer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902124739.750853-1-h.laimer@proxmox.com \
--to=h.laimer@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox