AltraMayor / AltraMayor/gatekeeper

Support running Gatekeeper and Grantor on KVM

未关闭
#464 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
C
星标
1.6k
派生
252
PR 合并指标
30 天内没有已合并 PR

描述

While running Gatekeeper on KVM, a couple of issues have been identified.

The following log entry is likely the biggest issue here since it means that Gatekeeper is not properly parsing packets.
`GATEKEEPER: l2: gk: invalid Ethernet field or frame not Ethernet II:38`
The current L2 implementation in Gatekeeper doesn't support alternatives to Ethernet II.

IPv6 multicast addresses in the format `0x33-33-mm-mm-mm-mm` are not being properly handled. Log entry example:
```
GATEKEEPER: acl: a packet failed to match any ACL rules, the whole packet is dumped below:
dump mbuf at 0x10f09c040, iova=5769c0d0, buf_len=2176
pkt_len=90, ol_flags=0, nb_segs=1, in_port=1
segment at 0x10f09c040, data=0x10f09c150, data_len=90
Dump data at [0x10f09c150], len=90
00000000: 33 33 00 00 00 16 FE 54 00 4B 73 5F 86 DD 60 00 | 33.....T.Ks_..`.
00000010: 00 00 00 24 00 01 00 00 00 00 00 00 00 00 00 00 | ...$............
00000020: 00 00 00 00 00 00 FF 02 00 00 00 00 00 00 00 00 | ................
00000030: 00 00 00 00 00 16 3A 00 05 02 00 00 01 00 8F 00 | ......:.........
00000040: FB DF 00 00 00 01 04 00 00 00 FF 02 00 00 00 00 | ................
00000050: 00 00 00 00 00 01 FF 4B 73 5F | .......Ks_
```
Information about these multicast addresses can be found in the article [Mapping IPv6 Multicast Addresses to Ethernet Addresses](https://flylib.com/books/en/2.223.1.44/1/). One has to investigate if Gatekeeper has to do something with these packets or just silently dropping them.

See [this Gatekeeper log](https://github.com/AltraMayor/gatekeeper/files/6266772/gatekeeper_2021_04_05_19_36.log) for examples of the issues described above.

Supporting KVM will enable Gatekeeper to be deployed on more cloud providers and be an easier alternative to test Gatekeeper.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。