From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 412F21FF09F for ; Thu, 03 Sep 2026 06:26:22 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id DCA9321553; Thu, 03 Sep 2026 06:26:21 +0200 (CEST) Message-ID: <300969a6-16d1-487b-8f54-8548b9460380@proxmox.com> Date: Thu, 3 Sep 2026 06:26:14 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF To: pve-devel@lists.proxmox.com References: <20260902124739.750853-1-h.laimer@proxmox.com> From: Hannes Laimer Content-Language: en-US In-Reply-To: <20260902124739.750853-1-h.laimer@proxmox.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788409570131 X-SPAM-LEVEL: Spam detection results: 0 AWL -2.011 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLACK 3 Contains an URL listed in the URIBL blacklist [types.rs] Message-ID-Hash: ECJYHXWPLGNZB6XW4OGYRD2JFZEUDZG7 X-Message-ID-Hash: ECJYHXWPLGNZB6XW4OGYRD2JFZEUDZG7 X-MailFrom: h.laimer@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: just noticed a problem with this, I'll send another version soon. sorry for the noise On 2026-09-02 14:48, Hannes Laimer wrote: > Adds a second DHCP backend, `ebpf`, next to dnsmasq, selectable per > zone. It aims to replace dnsmasq eventually, for now it is a second > implementation, which keeps a migration simple. Every zone type can > enable DHCP through a dropdown selector, `dnsmasq` stays limited to > simple zones. > > The responder is a subsystem of `proxmox-ebpf` [1], Perl reaches it > through new pve-rs bindings (PVE::RS::SDN::Dhcp), so the pve-network > patches need the pve-rs of this series. > > Currently only supports DHCPv4, but adding v6 is very possible once we're happy > with the overall design. > > # How > An eBPF program on the ingress of every guest tap parses DHCP requests, > looks the client MAC up in a mac -> ip+options map and rewrites the > request into the reply in place, redirected back out of the tap. The > exchange never reaches the bridge. Everything else, including MACs > without a map entry, passes untouched, so attaching is a no-op for > unmanaged MACs. > > IPAM is the source of the assignments, the map is a per-node copy of > the records, kept current by: > - guest start / NIC hotplug / migration: add_dhcp_mapping already > fires here and pushes the MAC's record before the interface is > plugged, tap_plug then attaches the program. > - mapping create/update/delete through the API: the editing node > updates its own map and pokes the node running the guest to do the > same, detached from the request. Best effort, an unreachable node > catches up on its next apply or the guest's next start. > - SDN apply: refreshes the programs, drops the link pins of departed > guests and rebuilds the map from the current records. > - boot: maps start empty, every guest start seeds its own record. > > Changes made directly on an external IPAM service are not detectable > and the per-MAC answers are cached, so they are not picked up on apply > either, exactly like with dnsmasq today. > > The pve-network part applies on top of the separately posted patch > pushing ipam API mapping changes to the dhcp backend. Its first > patches are preparatory, no negative per-MAC cache entries and a > locked cache write, a lease time property on subnets, and asserting a > backend's availability only for zones using it. > > [1] https://lore.proxmox.com/pve-devel/8d63974f-0a73-480b-9407-c6bdc2d576d7@proxmox.com > > > proxmox-ebpf: > > Hannes Laimer (2): > dhcp: add per-tap responder BPF program > dhcp: add responder subsystem > > Cargo.toml | 5 + > debian/control | 6 +- > src/dhcp/bpf/dhcp.bpf.c | 324 +++++++++++++++++++ > src/dhcp/bpf/types.h | 25 ++ > src/dhcp/mod.rs | 288 +++++++++++++++++ > src/dhcp/types.rs | 53 ++++ > src/lib.rs | 3 + > src/subsystem.rs | 35 +++ > tests/dhcp.rs | 668 ++++++++++++++++++++++++++++++++++++++++ > 9 files changed, 1406 insertions(+), 1 deletion(-) > create mode 100644 src/dhcp/bpf/dhcp.bpf.c > create mode 100644 src/dhcp/bpf/types.h > create mode 100644 src/dhcp/mod.rs > create mode 100644 src/dhcp/types.rs > create mode 100644 tests/dhcp.rs > > > proxmox-perl-rs: > > Hannes Laimer (1): > pve-rs: sdn: add dhcp responder bindings > > pve-rs/Cargo.toml | 2 + > pve-rs/Makefile | 1 + > pve-rs/debian/control | 2 + > pve-rs/src/bindings/sdn/dhcp.rs | 91 +++++++++++++++++++++++++++++++++ > pve-rs/src/bindings/sdn/mod.rs | 1 + > 5 files changed, 97 insertions(+) > create mode 100644 pve-rs/src/bindings/sdn/dhcp.rs > > > pve-network: > > Hannes Laimer (8): > sdn: ipam: do not cache negative per-MAC answers, lock the write > sdn: subnets: add dhcp-lease-time property > sdn: dhcp: only assert a backend's availability for zones using it > sdn: dhcp: add ebpf plugin > sdn: zones: attach the dhcp responder on tap plug > sdn: dhcp: apply mapping edits on the node serving the guest > sdn: zones: offer dhcp on all zone types, keep dnsmasq simple-only > tests: cover the ebpf dhcp backend and ipam API mapping pushes > > src/PVE/API2/Network/SDN/Ips.pm | 5 +- > src/PVE/API2/Network/SDN/Nodes/Status.pm | 37 ++++- > src/PVE/API2/Network/SDN/Zones.pm | 8 +- > src/PVE/Network/SDN/Dhcp.pm | 87 ++++++++++- > src/PVE/Network/SDN/Dhcp/Ebpf.pm | 173 ++++++++++++++++++++++ > src/PVE/Network/SDN/Dhcp/Makefile | 2 +- > src/PVE/Network/SDN/Ipams.pm | 20 ++- > src/PVE/Network/SDN/SubnetPlugin.pm | 7 + > src/PVE/Network/SDN/Zones.pm | 4 + > src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 1 + > src/PVE/Network/SDN/Zones/FaucetPlugin.pm | 1 + > src/PVE/Network/SDN/Zones/QinQPlugin.pm | 7 + > src/PVE/Network/SDN/Zones/VlanPlugin.pm | 7 + > src/PVE/Network/SDN/Zones/VxlanPlugin.pm | 9 ++ > src/test/run_test_vnets_blackbox.pl | 147 ++++++++++++++++++ > 15 files changed, 502 insertions(+), 13 deletions(-) > create mode 100644 src/PVE/Network/SDN/Dhcp/Ebpf.pm > > > pve-manager: > > Hannes Laimer (1): > ui: sdn: dhcp backend selector on all zones, expose dhcp options > > www/manager6/sdn/SubnetEdit.js | 24 ++++++++++++++++++++++++ > www/manager6/sdn/zones/Base.js | 17 +++++++++++++++++ > www/manager6/sdn/zones/SimpleEdit.js | 11 ----------- > 3 files changed, 41 insertions(+), 11 deletions(-) > > > Summary over all repositories: > 32 files changed, 2046 insertions(+), 25 deletions(-) >