zoukankan      html  css  js  c++  java
  • runv nslistener源码分析

    nslistener的作用实质上就是将新的namespace里的veth网卡的配置信息通过proxy进程传输出来,并且利用该信息对tap进行相同的配置,最终用tap模拟新的namespace里的veth,将流量导入虚拟机的tap网卡中。

    NetlinkUpdate的数据结构如下所示:

    // NetlinkUpdate tracks the change of network namespace
    type NetlinkUpdate struct {   // AddrUpdate is used to pass information back from AddrSubscribe()   Addr netlink.AddrUpdate   // RouteUpdate is used to pass information back from RouteSubscribe()   Route netlink.RouteUpdate   // Veth is used to pass information back from LinkSubscribe().   // Only support veth link at present   Veth *netlink.Veth   // UpdateType indicates which part of the netlink information has been changed.   UpdateType NetlinkUpdateType }

      

    ------------------------------------------------------------ nsListener 内-----------------------------------------------------------------------------------

    // runv/supervisor/hyperpod.go

    1、func createHyperPod(f factory.Factory, spec *specs.Spec, defaultCpus int, defaultMemory int) (*HyperPod, error)

    ...// create Listener process running in its one netns

    调用hp.startNsListener()

    // runv/supervisor/hyperpod.go

    2、func (hp *HyperPod) startNsListener() (err error)

    (1)、创建var parentPipe, childPipe *os.File

    (2)、调用`runv containerd-nslistener`命令

    (3)、调用enc := gob.NewEncoder(parentPipe)和dec := gob.NewDecoder(parentPipe)

    (4)、填充hp.nslistener{

      enc:  enc,

      dec:  dec,

      cmd:   cmd,

    }

    (5)、从dec中独到read == "init"则表示创建成功

    注:runv/supervisor/proxy/nslistener.go的init函数调用reexec.Register("containerd-nslistener", setupNsListener)函数,因此,`runv containerd-nslistener`命令本质上就是调用setupNsListener()函数

    // runv/supervisor/proxy/nslistener.go

    3、func setupNsListener()

    (1)、调用syscall.Unshare(syscall.CLONE_NEWNET) --> create own netns

    (2)、再通过childPipe将"init"传输给containerd--> notify containerd to execute prestart hooks

    (3)、after execute prestart hooks从childPipe中读到"init"再继续执行

    // Get network namespace info for the first time and send to the containerd

    (4)、调用routes, err := netlink.RouteList(nil, netlink.FAMILY_V4) --> get route info before link down

    (5)、调用infos := collectionInterfaceInfo() --> send interface info to containerd

    (6)、调用enc.Encode(intofs)和enc.Encode(routes)传输

    (7)、创建函数netNs2Containerd := func(netlinkUpdate supervisor.NetlinkUpdate) ->本质上就是将netlinkUpdate信息通过childPipe发送出去

    (8)、调用setupNetworkNsTrap(netNs2Containerd) --> keep collecting network namespace info and sending to the containerd

    // runv/supervisor/proxy/nslistener.go

    // 获取net ns中的veth网卡信息,传输出去,并且将其link down

    4、func collectionInterfaceInfo() []supervisor.InterfaceInfo

    (1)、调用links, err := netlink.LinkList()

    (2)、遍历links,当link.Type()为"veth"时,将信息填充添加到infos数组中,

    最后调用netlink.LinkSetDown(link)  --> set link down, tap device take over it

    // runv/supervisor/proxy/nslistener.go

    // This function should be put into the main process or somewhere that can be used to init the network namespace trap

    5、func setupNetworkNsTrap(netNs2Containerd func(supervisor.NetlinkUpdate))

    该函数主要用于获取links change event,addresses change event,route change event,然后将它们分别利用handleLink,handleAddr和handleRoute函数发送给containerd

    ......

    ------------------------------------------------------------------- containerd中 ----------------------------------------------------------------------------------

    6、func (c *Container) start(p *Process) error

    .....

    (1)、调用err = execPrestartHooks(c.Spec, state)

    (2)、调用c.ownPod.initPodNetwork(c)

    7、func execPrestartHooks(rt *specs.Spec, state *specs.State)

    遍历rt.Hooks.Prestart,调用execHook(hook, state)

    8、func (hp *HyperPod) initPodNetwork(c *Container) error

    (1)、当len(hp.Containers) > 1时,返回nil --> Only start first container will setup netns

    (2)、当len(c.Spec.Hooks.Prestart) == 0时,返回nil --> container has no prestart hooks, means no net for this container

    (3)、将listener赋值为hp.nslistener,调用listener.enc.Encode("init"),向nsListener发送收集信息的请求

    (4)、调用listener.dec.Decode(&info)和listener.dec.Decode(&route)收集ns的nic信息

    (5)、遍历infos,调用bridge,err := GetBridgeFromIndex(info.PeerIndex),nicId := strconv.Itoa(info.Index),并用它们填充获得conf := &api.InterfaceDescription{},最后调用hp.vm.AddNic(conf)

    (6)、调用hp.vm.AddRoute()

    (7)、调用go hp.nsListenerStrap()

    9、func (hp *HyperPod) nsListenerStrap()

    (1)、将listener赋值为hp.nslistener

    // Keep watching container network setting and then update vm/hyperstart

    (2)、从parentPipe中获取update信息(类型为NetlinkUpdate{}),再根据update.UpdateType,分别进行对应的操作

  • 相关阅读:
    微信小程序 阻止冒泡事件
    vant/weapp goodsaction 显示样式不正常问题
    微信小程序图表工具wxcharts
    webstorm 不识别 rpx 格式化出错
    小程序自定义 tabbar 以vant weapp 调试工具不显示,但是在真机显示
    小程序自定义 tabbar 以vant weapp为例
    TypeScript之环境搭建
    模块化打包工具webpack
    【纪中受难记】——Day2.感觉冤的慌
    计算机精英协会考核题 —— 第三题:斐波那契数
  • 原文地址:https://www.cnblogs.com/YaoDD/p/6231829.html
Copyright © 2011-2022 走看看