diff --git a/nixos/modules/virtualisation/openvswitch.nix b/nixos/modules/virtualisation/openvswitch.nix index 4e75d1677955..085de6b61c7f 100644 --- a/nixos/modules/virtualisation/openvswitch.nix +++ b/nixos/modules/virtualisation/openvswitch.nix @@ -64,9 +64,22 @@ in boot.extraModulePackages = [ cfg.package ]; + systemd.sockets.ovsdb = { + description = "Open_vSwitch Database Socket"; + wantedBy = [ "sockets.target" ]; + before = [ "ovsdb.service" ]; + socketConfig = { + ListenStream = "${runDir}/db.sock"; + Service = "ovsdb.service"; + SocketMode = "0770"; + }; + }; + systemd.services.ovsdb = { description = "Open_vSwitch Database Server"; wantedBy = [ "multi-user.target" ]; + requires = [ "ovsdb.socket" ]; + after = [ "ovsdb.socket" ]; path = [ cfg.package ]; restartTriggers = [ db @@ -95,7 +108,7 @@ in serviceConfig = { ExecStart = '' ${cfg.package}/bin/ovsdb-server \ - --remote=punix:${runDir}/db.sock \ + --remote=pfd:3 \ --private-key=db:Open_vSwitch,SSL,private_key \ --certificate=db:Open_vSwitch,SSL,certificate \ --bootstrap-ca-cert=db:Open_vSwitch,SSL,ca_cert \ @@ -105,6 +118,7 @@ in /var/db/openvswitch/conf.db ''; Restart = "always"; + RestartMode = "direct"; RestartSec = 3; PIDFile = "/run/openvswitch/ovsdb.pid"; # Use service type 'forking' to correctly determine when ovsdb-server is ready. @@ -118,8 +132,8 @@ in systemd.services.ovs-vswitchd = { description = "Open_vSwitch Daemon"; wantedBy = [ "multi-user.target" ]; - bindsTo = [ "ovsdb.service" ]; - after = [ "ovsdb.service" ]; + requires = [ "ovsdb.socket" ]; + after = [ "ovsdb.socket" ]; path = [ cfg.package ]; serviceConfig = { ExecStart = '' @@ -131,6 +145,7 @@ in # Use service type 'forking' to correctly determine when vswitchd is ready. Type = "forking"; Restart = "always"; + RestartMode = "direct"; RestartSec = 3; }; }; diff --git a/nixos/tests/openvswitch.nix b/nixos/tests/openvswitch.nix index cd725ccb4071..a6296c2a36a2 100644 --- a/nixos/tests/openvswitch.nix +++ b/nixos/tests/openvswitch.nix @@ -58,5 +58,27 @@ node1.wait_until_succeeds("ping -c1 10.0.0.2", timeout=30) node2.wait_until_succeeds("ping -c1 10.0.0.1", timeout=30) + + with subtest("Restarting ovsdb preserves OpenFlow flows"): + ovs_ofctl = "ovs-ofctl -O OpenFlow13" + marker_cookie = "0x5eed" + + def check_marker_flow(): + node1.succeed( + f"{ovs_ofctl} dump-flows vs0 | grep -q 'cookie={marker_cookie}'" + ) + + node1.succeed( + f"{ovs_ofctl} add-flow vs0 " + f"'cookie={marker_cookie},priority=100,ip,nw_src=192.0.2.1,actions=drop'" + ) + check_marker_flow() + + node1.succeed("systemctl restart ovsdb.service") + node1.wait_for_unit("ovsdb.service") + node1.wait_for_unit("ovs-vswitchd.service") + node1.wait_for_unit("vs0-netdev.service") + + check_marker_flow() ''; } diff --git a/pkgs/by-name/op/openvswitch/package.nix b/pkgs/by-name/op/openvswitch/package.nix index 37f67274fad0..db5aca0d872c 100644 --- a/pkgs/by-name/op/openvswitch/package.nix +++ b/pkgs/by-name/op/openvswitch/package.nix @@ -31,13 +31,13 @@ stdenv.mkDerivation (finalAttrs: { pname = if withDPDK then "openvswitch-dpdk" else "openvswitch"; - version = "3.7.1"; + version = "4.0.0"; src = fetchFromGitHub { owner = "openvswitch"; repo = "ovs"; tag = "v${finalAttrs.version}"; - hash = "sha256-3FQjV4BZZpn7Loiu9Xm30cCqzkU1HgJ3sAc+I6D8OvQ="; + hash = "sha256-+WjpNJkM3AztBY1gPO6RdujGi86GDTjskJyDK16/9Dc="; }; outputs = [ @@ -110,13 +110,9 @@ stdenv.mkDerivation (finalAttrs: { installShellCompletion utilities/ovs-vsctl-bashcomp.bash mkdir -p $tools/{bin,share/openvswitch/scripts} - mv $out/share/openvswitch/bugtool-plugins $tools/share/openvswitch - mv $out/share/openvswitch/scripts/ovs-{bugtool*,check-dead-ifs,monitor-ipsec,vtep} $tools/share/openvswitch/scripts + mv $out/share/openvswitch/scripts/ovs-{check-dead-ifs,monitor-ipsec,vtep} $tools/share/openvswitch/scripts mv $out/share/openvswitch/scripts/usdt $tools/share/openvswitch/scripts - mv $out/bin/ovs-{bugtool,dpctl-top,l3ping,parse-backtrace,pcap,tcpdump,tcpundump,test,vlan-test} $tools/bin - - wrapProgram $tools/bin/ovs-l3ping \ - --prefix PYTHONPATH : $out/share/openvswitch/python + mv $out/bin/ovs-{dpctl-top,pcap,tcpdump,tcpundump} $tools/bin wrapProgram $tools/bin/ovs-tcpdump \ --prefix PATH : ${lib.makeBinPath [ tcpdump ]} \ @@ -143,7 +139,10 @@ stdenv.mkDerivation (finalAttrs: { pyparsing pytest setuptools - ]); + tftpy + ]) + # pyftpdlib depends on pysendfile extension, which cannot be static + ++ lib.optionals (!stdenv.hostPlatform.isStatic) [ python3.pkgs.pyftpdlib ]; passthru = { tests = {