public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Hannes Laimer <h.laimer@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: Re: [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF
Date: Wed, 2 Sep 2026 14:54:18 +0200	[thread overview]
Message-ID: <57c14cbd-363f-4600-af70-a73700bc9d65@proxmox.com> (raw)
In-Reply-To: <20260902124739.750853-1-h.laimer@proxmox.com>

On 2026-09-02 14:48, Hannes Laimer wrote:
> Adds a second DHCP backend, `ebpf`, next to dnsmasq, selectable per
> zone. It aims to replace dnsmasq eventually, for now it is a second
> implementation, which keeps a migration simple. Every zone type can
> enable DHCP through a dropdown selector, `dnsmasq` stays limited to
> simple zones.
> 
> The responder is a subsystem of `proxmox-ebpf` [1], Perl reaches it
> through new pve-rs bindings (PVE::RS::SDN::Dhcp), so the pve-network
> patches need the pve-rs of this series.
> 
> Currently only supports DHCPv4, but adding v6 is very possible once we're happy
> with the overall design.
> 
> # How
> An eBPF program on the ingress of every guest tap parses DHCP requests,
> looks the client MAC up in a mac -> ip+options map and rewrites the
> request into the reply in place, redirected back out of the tap. The
> exchange never reaches the bridge. Everything else, including MACs
> without a map entry, passes untouched, so attaching is a no-op for
> unmanaged MACs.
> 
> IPAM is the source of the assignments, the map is a per-node copy of
> the records, kept current by:
>  - guest start / NIC hotplug / migration: add_dhcp_mapping already
>    fires here and pushes the MAC's record before the interface is
>    plugged, tap_plug then attaches the program.
>  - mapping create/update/delete through the API: the editing node
>    updates its own map and pokes the node running the guest to do the
>    same, detached from the request. Best effort, an unreachable node
>    catches up on its next apply or the guest's next start.
>  - SDN apply: refreshes the programs, drops the link pins of departed
>    guests and rebuilds the map from the current records.
>  - boot: maps start empty, every guest start seeds its own record.
> 
> Changes made directly on an external IPAM service are not detectable
> and the per-MAC answers are cached, so they are not picked up on apply
> either, exactly like with dnsmasq today.
> 
> The pve-network part applies on top of the separately posted patch
> pushing ipam API mapping changes to the dhcp backend. Its first
> patches are preparatory, no negative per-MAC cache entries and a
> locked cache write, a lease time property on subnets, and asserting a
> backend's availability only for zones using it.

oops, did not send that yet, it's [2]

> 
> [1] https://lore.proxmox.com/pve-devel/8d63974f-0a73-480b-9407-c6bdc2d576d7@proxmox.com

[2]
https://lore.proxmox.com/pve-devel/20260902125357.757029-1-h.laimer@proxmox.com/T/#u

> 
> 
> proxmox-ebpf:
> 
> Hannes Laimer (2):
>   dhcp: add per-tap responder BPF program
>   dhcp: add responder subsystem
> 
>  Cargo.toml              |   5 +
>  debian/control          |   6 +-
>  src/dhcp/bpf/dhcp.bpf.c | 324 +++++++++++++++++++
>  src/dhcp/bpf/types.h    |  25 ++
>  src/dhcp/mod.rs         | 288 +++++++++++++++++
>  src/dhcp/types.rs       |  53 ++++
>  src/lib.rs              |   3 +
>  src/subsystem.rs        |  35 +++
>  tests/dhcp.rs           | 668 ++++++++++++++++++++++++++++++++++++++++
>  9 files changed, 1406 insertions(+), 1 deletion(-)
>  create mode 100644 src/dhcp/bpf/dhcp.bpf.c
>  create mode 100644 src/dhcp/bpf/types.h
>  create mode 100644 src/dhcp/mod.rs
>  create mode 100644 src/dhcp/types.rs
>  create mode 100644 tests/dhcp.rs
> 
> 
> proxmox-perl-rs:
> 
> Hannes Laimer (1):
>   pve-rs: sdn: add dhcp responder bindings
> 
>  pve-rs/Cargo.toml               |  2 +
>  pve-rs/Makefile                 |  1 +
>  pve-rs/debian/control           |  2 +
>  pve-rs/src/bindings/sdn/dhcp.rs | 91 +++++++++++++++++++++++++++++++++
>  pve-rs/src/bindings/sdn/mod.rs  |  1 +
>  5 files changed, 97 insertions(+)
>  create mode 100644 pve-rs/src/bindings/sdn/dhcp.rs
> 
> 
> pve-network:
> 
> Hannes Laimer (8):
>   sdn: ipam: do not cache negative per-MAC answers, lock the write
>   sdn: subnets: add dhcp-lease-time property
>   sdn: dhcp: only assert a backend's availability for zones using it
>   sdn: dhcp: add ebpf plugin
>   sdn: zones: attach the dhcp responder on tap plug
>   sdn: dhcp: apply mapping edits on the node serving the guest
>   sdn: zones: offer dhcp on all zone types, keep dnsmasq simple-only
>   tests: cover the ebpf dhcp backend and ipam API mapping pushes
> 
>  src/PVE/API2/Network/SDN/Ips.pm           |   5 +-
>  src/PVE/API2/Network/SDN/Nodes/Status.pm  |  37 ++++-
>  src/PVE/API2/Network/SDN/Zones.pm         |   8 +-
>  src/PVE/Network/SDN/Dhcp.pm               |  87 ++++++++++-
>  src/PVE/Network/SDN/Dhcp/Ebpf.pm          | 173 ++++++++++++++++++++++
>  src/PVE/Network/SDN/Dhcp/Makefile         |   2 +-
>  src/PVE/Network/SDN/Ipams.pm              |  20 ++-
>  src/PVE/Network/SDN/SubnetPlugin.pm       |   7 +
>  src/PVE/Network/SDN/Zones.pm              |   4 +
>  src/PVE/Network/SDN/Zones/EvpnPlugin.pm   |   1 +
>  src/PVE/Network/SDN/Zones/FaucetPlugin.pm |   1 +
>  src/PVE/Network/SDN/Zones/QinQPlugin.pm   |   7 +
>  src/PVE/Network/SDN/Zones/VlanPlugin.pm   |   7 +
>  src/PVE/Network/SDN/Zones/VxlanPlugin.pm  |   9 ++
>  src/test/run_test_vnets_blackbox.pl       | 147 ++++++++++++++++++
>  15 files changed, 502 insertions(+), 13 deletions(-)
>  create mode 100644 src/PVE/Network/SDN/Dhcp/Ebpf.pm
> 
> 
> pve-manager:
> 
> Hannes Laimer (1):
>   ui: sdn: dhcp backend selector on all zones, expose dhcp options
> 
>  www/manager6/sdn/SubnetEdit.js       | 24 ++++++++++++++++++++++++
>  www/manager6/sdn/zones/Base.js       | 17 +++++++++++++++++
>  www/manager6/sdn/zones/SimpleEdit.js | 11 -----------
>  3 files changed, 41 insertions(+), 11 deletions(-)
> 
> 
> Summary over all repositories:
>   32 files changed, 2046 insertions(+), 25 deletions(-)
> 





  parent reply	other threads:[~2026-09-02 12:54 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 12:47 [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF Hannes Laimer
2026-09-02 12:47 ` [PATCH proxmox-ebpf 01/12] dhcp: add per-tap responder BPF program Hannes Laimer
2026-09-02 12:47 ` [PATCH proxmox-ebpf 02/12] dhcp: add responder subsystem Hannes Laimer
2026-09-02 12:47 ` [PATCH proxmox-perl-rs 03/12] pve-rs: sdn: add dhcp responder bindings Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 04/12] sdn: ipam: do not cache negative per-MAC answers, lock the write Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 05/12] sdn: subnets: add dhcp-lease-time property Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 06/12] sdn: dhcp: only assert a backend's availability for zones using it Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 07/12] sdn: dhcp: add ebpf plugin Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 08/12] sdn: zones: attach the dhcp responder on tap plug Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 09/12] sdn: dhcp: apply mapping edits on the node serving the guest Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 10/12] sdn: zones: offer dhcp on all zone types, keep dnsmasq simple-only Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-network 11/12] tests: cover the ebpf dhcp backend and ipam API mapping pushes Hannes Laimer
2026-09-02 12:47 ` [PATCH pve-manager 12/12] ui: sdn: dhcp backend selector on all zones, expose dhcp options Hannes Laimer
2026-09-02 12:54 ` Hannes Laimer [this message]
2026-09-03  4:26 ` [RFC manager/network/proxmox{-ebpf,-perl-rs} 00/12] sdn: implement DHCP for all zones using eBPF Hannes Laimer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=57c14cbd-363f-4600-af70-a73700bc9d65@proxmox.com \
    --to=h.laimer@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal