Mirror image flow table offloading method, device and medium
By generating a multicast replication group to represent the mirror flow table members, the problem of high resource consumption in multi-export mirror flow table offloading is solved, efficient mirror message forwarding is achieved, and the hardware offloading requirements of different numbers of mirror flow tables are adapted.
Patent Information
- Application Number
- CN202411722209.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-11-28
AI Technical Summary
The existing technology faces the problems of a large number of actions, flow table unloading failure and high resource consumption during the multi-export mirror flow table unloading process, resulting in low mirror message forwarding efficiency.
By generating a multicast replication group to represent the mirrored flow table members, a mirroring relationship is established between the reference flow table and the multicast replication group. The multicast replication function is used to implement the mirrored flow table function, reducing the number of action fields. The reference flow table and multicast replication group are then offloaded to the packet forwarding hardware.
It significantly reduces resource consumption in data movement, editing, and verification operations, improves mirror message forwarding efficiency, and adapts to hardware offload requirements for various numbers of mirror flow tables.
Smart Images

Figure CN119603312B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, and particularly relates to a mirror flow table offloading method, device and medium. BACKGROUND
[0002] With the development of cloud computing network, big data, artificial intelligence and other technologies, extensive business needs are generated, which leads to rapid growth of data centers and dramatic increase of data traffic. Therefore, high-performance business forwarding needs to be achieved. Sometimes, multiple egress mirrors need to be provided and hardware acceleration offloading technology is used to offload multiple egress mirror flow tables to special hardware. However, in the prior art, considering that various editing actions and verifications need to be performed in the message forwarding process, when offloading mirror flow tables for multiple egress mirror message forwarding, problems such as a large number of actions, flow table offloading failure and the like are faced. In addition, a flow table with a large number of editing actions may be faced, which may consume a large amount of resources to achieve data movement and verification operations, and is not conducive to improving the forwarding efficiency of mirror messages.
[0003] Therefore, the present application provides a mirror flow table offloading method, device and medium, which can flexibly adapt to the hardware offloading needs of various numbers of mirror flow tables, not only can greatly save the resource consumption of data movement, editing actions and verification operations, but also can effectively improve the forwarding efficiency of mirror messages. SUMMARY
[0004] In a first aspect, the present application provides a mirror flow table offloading method. The mirror flow table offloading method comprises: determining a reference flow table and at least one mirror flow table having a first mirroring relationship with the reference flow table, wherein the reference flow table defines at least one message editing action, and each of the at least one mirror flow table defines, on the basis of the at least one message editing action defined by the reference flow table, a message editing action to be executed based on the first mirroring relationship; generating a multicast replication group to represent all members in the at least one mirror flow table, constructing a second mirroring relationship between the reference flow table and the multicast replication group based on the first mirroring relationship between the reference flow table and the at least one mirror flow table, wherein the multicast replication group defines, on the basis of the at least one message editing action defined by the reference flow table, a message editing action to be executed based on the second mirroring relationship, so as to use the multicast replication function of the multicast replication group to achieve the mirror flow table function of all members in the at least one mirror flow table; and offloading the reference flow table and the multicast replication group to message forwarding hardware.
[0005] Through the first aspect of the present application, the hardware offloading needs of various numbers of mirror flow tables can be flexibly adapted, not only can the resource consumption of data movement, editing actions and verification operations be greatly saved, but also the forwarding efficiency of mirror messages can be effectively improved.
[0006] In a possible implementation of the first aspect of the present application, the at least one packet editing action defined by the reference flow table comprises performing packet field modification on one or more of a source network protocol address, a source machine physical address, a source port, a destination network protocol address, a destination machine physical address, and a destination port.
[0007] In a possible implementation of the first aspect of the present application, the packet editing action defined by each of the at least one mirror flow table comprises, on the basis of the at least one packet editing action defined by the reference flow table, performing packet field modification on one or more of a source network protocol address, a source machine physical address, a source port, a destination network protocol address, a destination machine physical address, and a destination port based on the first mirror relationship.
[0008] In a possible implementation of the first aspect of the present application, the number of times of the packet editing action defined by each of the at least one mirror flow table is the same as the number of times of the at least one packet editing action defined by the reference flow table.
[0009] In a possible implementation of the first aspect of the present application, the number of times of the packet editing action defined by the multicast replication group is the same as the number of times of the at least one packet editing action defined by the reference flow table.
[0010] In a possible implementation of the first aspect of the present application, the reference flow table defines that a checksum calculation is performed once after each of the at least one packet editing action defined by the reference flow table is completed.
[0011] In a possible implementation of the first aspect of the present application, each of the at least one mirror flow table defines that a checksum calculation is performed once after each of the packet editing action defined by the mirror flow table is completed.
[0012] In a possible implementation of the first aspect of the present application, the number of times of the checksum calculation defined by each of the at least one mirror flow table is the same as the number of times of the checksum calculation defined by the reference flow table.
[0013] In a possible implementation of the first aspect of the present application, the multicast replication group defines that a checksum calculation is performed once after each of the packet editing action defined by the multicast replication group is completed, and the number of times of the checksum calculation defined by the multicast replication group is the same as the number of times of the checksum calculation defined by the reference flow table.
[0014] In a possible implementation of the first aspect of the application, the reference flow table is used for forwarding message traffic from a first virtual function of a first physical function to a second virtual function of the first physical function, and the at least one mirror flow table is used for performing message field modification and checksum calculation on original messages from the first virtual function of the first physical function to the second virtual function of the first physical function, so as to realize mirror message forwarding to other virtual functions of the first physical function except the first virtual function and the second virtual function.
[0015] In a second aspect, the embodiments of the present application further provide a computer device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method according to any one of the implementation manners of any one of the above aspects when executing the computer program.
[0016] In a third aspect, the embodiments of the present application further provide a computer readable storage medium, which stores computer instructions, and the computer instructions make the computer device execute the method according to any one of the implementation manners of any one of the above aspects when the computer instructions are executed on the computer device.
[0017] In a fourth aspect, the embodiments of the present application further provide a computer program product, which comprises instructions stored on a computer readable storage medium, and the instructions make the computer device execute the method according to any one of the implementation manners of any one of the above aspects when the instructions are executed on the computer device. BRIEF DESCRIPTION OF DRAWINGS
[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0019] Figure 1 A flowchart of a mirror flow table offloading method provided by the embodiments of the present application;
[0020] Figure 2 A schematic diagram of a virtual switch provided by the embodiments of the present application;
[0021] Figure 3 A structural schematic diagram of a computer device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0022] The embodiments of the present application will be further described in detail below with reference to the drawings.
[0023] It should be understood that in the description of the present application, "at least one" means one or more, and "multiple" means two or more. In addition, the words "first", "second", and the like, unless otherwise specified, are only used to distinguish the description purpose, and cannot be understood as indicating or implying relative importance, nor can it be understood as indicating or implying order.
[0024] Figure 1 A flowchart of a mirror flow table offloading method provided for an embodiment of the present application. As shown in the figure, the mirror flow table offloading method comprises the following steps. Figure 1
[0025] Step S101: Determine a reference flow table and at least one mirror flow table having a first mirroring relationship with the reference flow table, wherein the reference flow table defines at least one packet editing action, and each of the at least one mirror flow table defines, on the basis of the at least one packet editing action defined by the reference flow table, packet editing action based on the first mirroring relationship.
[0026] Step S103: Generate a multicast replication group to represent all members in the at least one mirror flow table, and construct a second mirroring relationship between the reference flow table and the multicast replication group based on the first mirroring relationship between the reference flow table and the at least one mirror flow table, wherein the multicast replication group defines, on the basis of the at least one packet editing action defined by the reference flow table, packet editing action based on the second mirroring relationship, so as to use the multicast replication function of the multicast replication group to realize the mirror flow table function of all members in the at least one mirror flow table.
[0027] Step S105: Offload the reference flow table and the multicast replication group to packet forwarding hardware.
[0028] Figure 1 The illustrated mirror flow table offloading method can be applied to the technical fields of cloud computing networks, big data, artificial intelligence and the like, can meet high-performance service forwarding requirements, especially can meet multi-outlet mirror message forwarding and mirror flow table offloading, can flexibly adapt to hardware offloading requirements of various numbers of mirror flow tables, can better combine virtual switches and other virtualization products and services to meet traffic forwarding requirements between ingress ports and egress ports, and in the case of a large number of hardware offloaded mirror flow tables, can still maintain low resource occupation through optimized design of message field modification and verification operations, and in the face of a large number of message editing actions, can still save resources and improve resource utilization through optimized design of mirror flow table function implementation process, flexibly adapt to hardware offloading requirements of various numbers of mirror flow tables, not only can greatly save resource consumption of data movement, editing actions and verification operations, but also can effectively improve mirror message forwarding efficiency. Details are described below.
[0029] Reference Figure 1 In step S101, a reference flow table and at least one mirror flow table having a first mirroring relationship with the reference flow table are determined, wherein the reference flow table defines at least one message editing action, and each of the at least one mirror flow table defines, on the basis of the at least one message editing action defined by the reference flow table, a message editing action that is executed based on the first mirroring relationship. Here, the reference flow table is used for message forwarding from one port to another port, and the data format of the reference flow table defines various information such as source network protocol address, source machine physical address, source port, destination port, etc. Depending on the specific message encapsulation format and communication protocol specification, modification can be made to the combination of multiple different fields, so that message forwarding from one port to another port can be achieved. Based on the reference flow table, there can be one or more mirror flow tables having a first mirroring relationship with the reference flow table. The data format of each of these mirror flow tables also defines modification of the combination of multiple fields. For example, the data format of the reference flow table defines modification of the source network protocol address, the source machine physical address, the source port, and the destination port, and the data format of the mirror flow table can also require modification of the source network protocol address, the source machine physical address, the source port, and the destination port. Considering that the number of mirror flow tables to be offloaded is difficult to determine in advance, and the number and complexity of message editing actions defined by the reference flow table are also difficult to determine, if the reference flow table and the mirror flow table having a mirroring relationship are integrated into one flow table for hardware offloading, a large amount of resources may be required to store the action field, and a large number of field modification operations and checksum calculation operations may be caused.
[0030] For example, assume that the reference flow table is from pf1vf1 to pf1vf2, and then the mirror flow table is to forward the mirror packet to pf1vf3, pf1vf4, pf1vf5, pf1vf6, pf1vf7, pf1vf8, totally six mirror packets. Here, pf1vf1, pf1vf2, pf1vf3, pf1vf4, pf1vf5, pf1vf6, pf1vf7, pf1vf8 are used to represent the first virtual function pf1vf1, the second virtual function pf1vf2, until the eighth virtual function pf1vf8 of the first physical function pf1 respectively. Here, assume that the following flow table defines the packet editing actions in the packet forwarding process for the original packet and the mirror packet:
[0031] "Key: smac=11:22:33:44:55:66, dmac=99:88:77:66:55:44, sip=1.1.1.1, dip=1.1.1.2, sport=1000, dport=2000; inport=pf1vf1_rep; action=mod_sip=2.2.2.1, mod_smac=66:55:44:33:22:11, mod_sport=3000, mod_dport=4000, pf1vf2_rep, pf1vf3_rep, pf1vf4_rep, pf1vf5_rep, pf1vf6_rep, pf1vf7_rep, pf1vf8_rep".
[0032] Here, Key indicates a key field, in which smac is a source machine physical address, dmac is a destination machine physical address, sip is a source network protocol address, dip is a destination network protocol address, sport is a source port, dport is a destination port, and inport is an in port. Action indicates an action field, in which the action field defines packet field modification on sip, i.e., the source network protocol address, packet field modification on smac, i.e., the source machine physical address, packet field modification on sport, i.e., the source port, and packet field modification on dport, i.e., the destination port. In addition, the flow table above also shows that, on the basis of the four action fields defined by the flow table, i.e., packet field modification on the source network protocol address, the source machine physical address, the source port, and the destination port in turn, a total of six mirror packets, i.e., "pf1vf2_rep, pf1vf3_rep, pf1vf4_rep, pf1vf5_rep, pf1vf6_rep, pf1vf7_rep, pf1vf8_rep," are faced with. Each mirror packet needs to perform packet field modification on the source network protocol address, the source machine physical address, the source port, and the destination port in turn. Therefore, the original packet from pf1vf1 to pf1vf2 and the six mirror packets that exist in the mirror relationship, a total of seven packets, need to perform a total of 7 times 4, i.e., 28 times of packet field modification. Moreover, the original packet and the mirror packet need to perform a total of 28 times of checksum calculation after each packet field modification and checksum calculation, which means that a total of 56 times of packet field modification and checksum calculation need to be performed.
[0033] It can be seen that when the number of image flow tables to be offloaded further increases, for example, from six image flow tables to 100 image flow tables, if the reference flow table and the image flow tables having the image relationship are all integrated into one flow table for hardware offloading, it means that the number of times of data modification and checksum calculation needs to be increased greatly, which is not conducive to improving the performance of the network card. In addition, when the number of packet editing actions defined by the reference flow table further increases, the data length of the action field that needs to be occupied will further increase. In the above example, a total of 11 action fields are used. When 16 or more action fields need to be used, it may cause the maximum data length of the flow table entry to be exceeded, thereby causing the flow table offloading to fail. In addition, the data specification for the image flow table is generally limited. Therefore, when there are many cloud devices, all the data specifications allocated to the image flow table may be used up, causing the excess data service demand to be unable to be met by the dedicated hardware, but only by packet soft switching, which is also not conducive to improving the performance of the network card. Therefore, with the increase in the scale of the image packets and the egress ports having the image relationship, the action field of the comprehensive flow table will increase, so as to exceed the upper limit of the design, thereby being unable to be stored and offloaded to the hardware. Moreover, the number of flow table actions to be performed will also increase, which is not conducive to improving the performance of the network card.
[0034] With reference to the foregoing Figure 1 On the basis of step S101, that is, after determining the reference flow table and the at least one image flow table having the first image relationship with the reference flow table, step S103 is performed to generate a multicast replication group to represent all members in the at least one image flow table, and to construct a second image relationship between the reference flow table and the multicast replication group on the basis of the first image relationship between the reference flow table and the at least one image flow table. The multicast replication group defines that, on the basis of the at least one packet editing action defined by the reference flow table, a packet editing action is performed on the basis of the second image relationship, so as to use the multicast replication function of the multicast replication group to realize the image flow table function of all members in the at least one image flow table. In this way, the multicast replication group is used to represent all members in the at least one image flow table, which effectively replaces the forwarding of all egress ports and image packets having the image relationship. Only one flow table action needs to be performed, that is, forwarding to the multicast replication group, and only one packet field modification and checksum calculation needs to be performed, that is, using the multicast replication group as a representative of all image packets. For example, taking the above flow table defining the packet editing action in the process of packet forwarding of the original packet and the image packet as a reference, the following is the definition of the corresponding multicast replication group:
[0035] "Key: smac=11:22:33:44:55:66, dmac=99:88:77:66:55:44, sip=1.1.1.1, dip=1.1.1.2, sport=1000, dport=2000; inport=pf1vf1_rep; action=mod_sip=2.2.2.1, mod_smac=66:55:44:33:22:11, mod_sport=3000, mod_dport=4000, mcc_index=1".
[0036] Here, Key indicates a key field, in which smac is a source machine physical address, dmac is a destination machine physical address, sip is a source network protocol address, dip is a destination network protocol address, sport is a source port, dport is a destination port, and inport is an ingress port. Action indicates an action field, in which the action field defines packet field modification on sip, i.e., the source network protocol address, packet field modification on smac, i.e., the source machine physical address, packet field modification on sport, i.e., the source port, and packet field modification on dport, i.e., the destination port. The multicast replication group above also defines an identifier of the multicast replication group, i.e., mcc_index. It can be seen that the multicast replication group represents all members in the at least one mirror flow table, and a second mirror relationship between the reference flow table and the multicast replication group is constructed based on the first mirror relationship between the reference flow table and the at least one mirror flow table. In this way, the multicast replication group defines that packet editing actions are performed based on the second mirror relationship on the basis of the at least one packet editing action defined by the reference flow table, so as to implement mirror flow table functions of all members in the at least one mirror flow table by using multicast replication functions of the multicast replication group. It can be seen that 4 times of packet field modification and 4 times of checksum calculation are required for the original packet each time packet forwarding is performed, and relatively, 4 times of packet field modification and 4 times of checksum calculation are required for the multicast replication group. Therefore, 8 times of packet field modification and 8 times of checksum calculation are required in total by using the generated multicast replication group to replace the mirror flow table, and 16 times of packet field modification and checksum calculation are cumulatively performed. Moreover, because the multicast replication group effectively replaces all egress ports and mirror packet forwarding in the mirror relationship, the number of action fields required is greatly reduced, and the multicast replication group uses 5 action fields. Moreover, by introducing the multicast replication group, only one time of packet editing action and checksum calculation is performed on the original packet, and the edited packet can be directly copied by using multicast replication functions of the multicast replication group. By combining ports and mirror actions in a flow table to obtain a multicast replication group and assigning an index, i.e., an identifier of the multicast replication group, i.e., mcc_index, the number of various mirror flow tables to be offloaded and the number of packet editing actions defined by various reference flow tables and the complexity of various mirror action combinations can all be integrated into an action of one multicast replication group, and the number of action fields is greatly reduced.
[0037] With reference to the foregoing Figure 1After step S103, step S105 is performed to unload the reference flow table and the multicast replication group to the packet forwarding hardware. In this way, by combining the ports and mirror actions in the flow table to obtain the multicast replication group, no matter how many ports and mirror actions are, they can be integrated into the action of one multicast replication group, greatly reducing the number of action fields, and effectively avoiding the failure of flow table unloading due to too many action fields exceeding the maximum data length of the flow table entry. In addition, the multicast replication group specification can be used, and there is no need to allocate a flow table specification for the mirror flow table, which can save flow table resources, and can flexibly adapt to the hardware unloading needs of various numbers of mirror flow tables. When the number of egress ports increases or decreases, the flow table content does not need to be changed, and the multicast replication group can still represent all members in the mirror flow table and use the multicast replication function to realize the mirror flow table function of all members, which is beneficial to improve the performance of the network card. In addition, by introducing the multicast replication group, only one packet editing action and checksum calculation is performed on the original packet, and the edited packet can be directly copied by the multicast replication function of the multicast replication group to adapt to the number of mirror flow tables to be unloaded and the number of packet editing actions defined by the reference flow table and the complexity of mirror action combination. Not only can the resource consumption of data movement, editing action and checksum operation be greatly saved, but also the forwarding efficiency of the mirror packet can be effectively improved.
[0038] Figure 2 A schematic diagram of a virtual switch is provided for the embodiments of the present application. As shown in the figure, Figure 2 The virtual switch 201 has a plurality of ports, which are used for traffic forwarding between virtual functions under physical functions. Among them, the ports include a first virtual function 211 of a first physical function, a second virtual function 212 of the first physical function, a third virtual function 213 of the first physical function, and a fourth virtual function 214 of the first physical function. Referring to Figure 1 The mirror flow table unloading method, the reference flow table is used for packet traffic forwarding from the first virtual function 211 of the first physical function to the second virtual function 212 of the first physical function, and the at least one mirror flow table is used for packet field modification and checksum calculation on the original packet from the first virtual function 211 of the first physical function to the second virtual function 212 of the first physical function, so as to realize mirror packet forwarding to other virtual functions of the first physical function except the first virtual function and the second virtual function, i.e. the third virtual function 213 of the first physical function and the fourth virtual function 214 of the first physical function. In this way, flexible adaptation to the hardware unloading needs of various numbers of mirror flow tables is realized, which can greatly save the resource consumption of data movement, editing action and checksum operation, and effectively improve the forwarding efficiency of the mirror packet.
[0039] ReferenceFigure 1 and Figure 2 In a possible implementation, the at least one packet editing action defined by the reference flow table includes performing packet field modification on one or more of a source network protocol address, a source machine physical address, a source port, a destination network protocol address, a destination machine physical address, and a destination port. In this way, various communication protocol specifications, user requirements, and flow table forwarding requirements of service flows can be flexibly adapted.
[0040] In some embodiments, the packet editing action defined by each of the at least one mirror flow table includes, on the basis of the at least one packet editing action defined by the reference flow table, performing packet field modification on one or more of a source network protocol address, a source machine physical address, a source port, a destination network protocol address, a destination machine physical address, and a destination port based on the first mirror relationship. In this way, packet forwarding and hardware offloading requirements of various mirror flow tables can be flexibly adapted.
[0041] In some embodiments, the number of times of the packet editing action defined by each of the at least one mirror flow table is the same as the number of times of the at least one packet editing action defined by the reference flow table. In this way, by introducing the multicast replication group, the number of mirror flow tables to be offloaded and the number of packet editing actions defined by the reference flow table and the complexity of mirror action combination can be adapted, which not only can greatly save resource consumption of data movement, editing action, and verification operation, but also can effectively improve the forwarding efficiency of mirror packets.
[0042] In some embodiments, the number of times of the packet editing action defined by the multicast replication group is the same as the number of times of the at least one packet editing action defined by the reference flow table. In this way, by introducing the multicast replication group, only one packet editing action and verification and calculation are performed on the original packet, and the edited packet can be directly replicated by the multicast replication function of the multicast replication group, which can adapt the number of mirror flow tables to be offloaded and the number of packet editing actions defined by the reference flow table and the complexity of mirror action combination, which not only can greatly save resource consumption of data movement, editing action, and verification operation, but also can effectively improve the forwarding efficiency of mirror packets.
[0043] In a possible implementation, the reference flow table defines that verification and calculation are performed once after each of the at least one packet editing action defined by the reference flow table is completed. In this way, verification and calculation of various packet data formats and protocol specifications can be adapted.
[0044] In some embodiments, each of the at least one mirror flow table defines that a checksum calculation is performed once after each packet editing action defined by the mirror flow table is completed. In this way, the mirror flow table and the checksum operation of the mirror packet can be adapted.
[0045] In some embodiments, the number of times of performing the checksum calculation defined by each of the at least one mirror flow table is the same as the number of times of performing the checksum calculation defined by the reference flow table. In this way, the multicast replication group specification can be adopted without allocating a flow table specification for the mirror flow table, so that the flow table resource can be saved, the hardware offloading requirement of various numbers of mirror flow tables can be flexibly adapted, when the number of egress ports increases or decreases, the flow table content does not need to be changed, the multicast replication group can still represent all members of the mirror flow table, and the multicast replication function can be used to implement the mirror flow table function of all members, which is beneficial to improve the network card performance. In addition, by introducing the multicast replication group, only one packet editing action and checksum calculation are performed on the original packet, and then the edited packet can be copied by the multicast replication function of the multicast replication group, so that the number of mirror flow tables to be offloaded, the number of packet editing actions defined by the reference flow table, and the complexity of the mirror action combination can be adapted. Not only the resource consumption of data movement, editing action, and checksum operation can be greatly saved, but also the forwarding efficiency of the mirror packet can be effectively improved.
[0046] In some embodiments, the multicast replication group defines that a checksum calculation is performed once after each packet editing action defined by the multicast replication group is completed, and the number of times of performing the checksum calculation defined by the multicast replication group is the same as the number of times of performing the checksum calculation defined by the reference flow table. In this way, the multicast replication group specification can be adopted without allocating a flow table specification for the mirror flow table, so that the flow table resource can be saved, the hardware offloading requirement of various numbers of mirror flow tables can be flexibly adapted, when the number of egress ports increases or decreases, the flow table content does not need to be changed, the multicast replication group can still represent all members of the mirror flow table, and the multicast replication function can be used to implement the mirror flow table function of all members, which is beneficial to improve the network card performance. In addition, by introducing the multicast replication group, only one packet editing action and checksum calculation are performed on the original packet, and then the edited packet can be copied by the multicast replication function of the multicast replication group, so that the number of mirror flow tables to be offloaded, the number of packet editing actions defined by the reference flow table, and the complexity of the mirror action combination can be adapted. Not only the resource consumption of data movement, editing action, and checksum operation can be greatly saved, but also the forwarding efficiency of the mirror packet can be effectively improved.
[0047] In a possible implementation, the reference flow table is used for forwarding a packet flow from a first virtual function of a first physical function to a second virtual function of the first physical function, and the at least one mirror flow table is used for performing packet field modification and checksum calculation on an original packet from the first virtual function of the first physical function to the second virtual function of the first physical function, so as to realize mirror packet forwarding to other virtual functions of the first physical function except the first virtual function and the second virtual function. In this way, the hardware offloading requirement of flexibly adapting various numbers of mirror flow tables is realized, not only the resource consumption of data movement, editing actions and checksum operations can be greatly saved, but also the forwarding efficiency of mirror packets can be effectively improved.
[0048] Figure 3 is a structural schematic diagram of a computing device provided by an embodiment of the present application. The computing device 300 includes one or more processors 310, a communication interface 320, and a memory 330. The processor 310, the communication interface 320, and the memory 330 are connected to each other through a bus 340. Optionally, the computing device 300 can further include an input / output interface 350 connected with an input / output device for receiving parameters set by a user and the like. The computing device 300 can be used to implement part or all of the functions of the device embodiments or system embodiments of the above-described embodiments of the present application; the processor 310 can also be used to implement part or all of the operation steps of the above-described method embodiments of the present application. For example, the specific implementation of the computing device 300 performing various operations can refer to the specific details in the above-described embodiments, such as the processor 310 being used to perform part or all of the steps in the above-described method embodiments or part or all of the operations in the above-described method embodiments. For another example, in the embodiments of the present application, the computing device 300 can be used to implement part or all of the functions of one or more components in the above-described device embodiments, in addition, the communication interface 320 can be specifically used for communication functions necessary for implementing the functions of these devices, components, and the like, and the processor 310 can be specifically used for processing functions necessary for implementing the functions of these devices, components, and the like.
[0049] It should be understood that, Figure 3 The computing device 300 can include one or more processors 310, and the plurality of processors 310 can cooperatively provide processing capability in a parallel connection manner, a serial connection manner, a serial-parallel connection manner, or any connection manner, or the plurality of processors 310 can constitute a processor sequence or a processor array, or the plurality of processors 310 can be divided into a main processor and an auxiliary processor, or the plurality of processors 310 can have different architectures, such as using a heterogeneous computing architecture. In addition, Figure 3The illustrated computing device 300, related structural and functional descriptions are exemplary and non-limiting. In some example embodiments, the computing device 300 can include more or less components, or combinations of components, or have different arrangements of components than shown. Figure 3 The illustrated computing device 300, related structural and functional descriptions are exemplary and non-limiting. In some example embodiments, the computing device 300 can include more or less components, or combinations of components, or have different arrangements of components than shown.
[0050] The processor 310 can have various specific implementations. For example, the processor 310 can include one or more combinations of a central processing unit (CPU), a graphics processing unit (GPU), a neural-network processing unit (NPU), a tensor processing unit (TPU), a data processing unit (DPU), or the like, and the embodiments of the present application are not limited in this regard. The processor 310 can also be a single core processor or a multiple core processor. The processor 310 can be a combination of a CPU and a hardware chip. The hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 310 can also be implemented by a logic device with built-in processing logic, such as an FPGA or a digital signal processor (DSP), etc. The communication interface 320 can be a wired interface or a wireless interface, used for communication with other modules or devices. The wired interface can be an Ethernet interface, a local interconnect network (LIN), etc., and the wireless interface can be a cellular network interface or a wireless local area network interface, etc.
[0051] The memory 330 can be a non-volatile memory, for example, a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically EPROM (EEPROM), or a flash memory. The memory 330 can also be a volatile memory, which can be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM can be used, for example, a static RAM (SRAM), a dynamic RAM (DRAM), a synchronous DRAM (SDRAM), a double data rate SDRAM (DDR SDRAM), an enhanced SDRAM (ESDRAM), a synchlink DRAM (SLDRAM), and a direct rambus RAM (DR RAM). The memory 330 can also be used for storing programs codes and data to facilitate the processor 310 to invoke the program codes stored in the memory 330 to execute a portion or all of the procedures of the above method embodiments, or to execute the related functions of the above device embodiments. Moreover, the computing device 300 can contain more or less components, or have different configurations of components, than those shown in the drawings. Figure 3 More or less components can be used, or different configurations of components can be used.
[0052] The bus 340 can be a peripheral component interconnect express (PCIe) bus, or an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. The bus 340 can be divided into an address bus, a data bus, a control bus, etc. In addition to including a data bus, the bus 340 can also include a power bus, a control bus, a status signal bus, etc. However, for the sake of clarity,Figure 3 Only one bus or bus type is used in the figure, but it is understood that the computer system 1000 can use multiple buses, bus types, and / or other bus configurations, combinations, and / or variations thereof.
[0053] The method and device provided by the embodiments of the present application are based on the same inventive concept, and the embodiments, implementation manners, examples, or implementation modes of the method and device are similar in principle for solving problems, and thus the embodiments, implementation manners, examples, or implementation modes of the method and device can be referred to each other, and the repeated parts will not be described herein. The embodiments of the present application further provide a system including a plurality of computing devices, and the structure of each computing device can refer to the structure of the computing device described above. The functions or operations that can be implemented by the system can refer to the specific implementation steps in the above method embodiments and / or the specific functions described in the above device embodiments, and will not be described herein.
[0054] The embodiments of the present application further provide a computer readable storage medium, and the computer readable storage medium stores computer instructions, and when the computer instructions run on a computer device (such as one or more processors), the method steps in the above method embodiments can be implemented. The specific implementation of the processor of the computer readable storage medium in executing the above method steps can refer to the specific operations described in the above method embodiments and / or the specific functions described in the above device embodiments, and will not be described herein.
[0055] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, apparatus, or computer program product. Embodiments of the present application can be implemented in hardware, software, firmware, or any combination thereof. Embodiments of the present application can be implemented in software and / or firmware to operate on a computer or other programmable processing device, which can be a general purpose computer, a special purpose computer, a computer network, or other programmable processing device to produce a machine, such that the computer program product, when loaded and / or executed on the computer or other programmable processing device, can implement processes or functions described herein. Such computer program product can be a computer- readable storage medium having computer readable program code embodied therein, which causes a computer to function in a particular manner, such that the computer
[0056] The computer program instructions can also be loaded onto a computer, other programmable processing device, or network device to cause a series of operations to be performed on the computer, other programmable processing device, or network device to produce a computer implemented process such that the instructions which execute on the computer or other programmable processing device implement the functions / acts specified in the flowchart and / or block diagram block or blocks. Figure 1 The flowchart and / or block diagram in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present application. In this regard, each flowchart and / or block diagram can represent a method, module, and / or portion of code which comprises one or more executable instructions implemented in computer readable program code to be executed by a processor system, such as a general purpose computer, special purpose computer, embedded processor, or Figure 1 The flowchart and / or block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present application. In this regard, each flowchart and / or block diagram can represent a method, module, and / or portion of code which comprises one or more executable instructions implemented in computer readable program code to be executed by a processor system, such as a general purpose computer, special purpose computer, embedded processor, or Figure 1one or more processes and / or functions specified in the flow block or blocks Figure 1 one or more processes and / or functions specified in the flow block or blocks Figure 1 one or more processes and / or functions specified in the flow block or blocks Figure 1 one or more processes and / or functions specified in the flow block or blocks
[0057] In the above embodiments, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments. Obviously, those skilled in the art can make various modifications and variations to the embodiments of the present application without departing from the spirit and scope of the embodiments of the present application. The steps in the method of the embodiments of the present application can be adjusted, combined or deleted in sequence according to actual needs; the modules in the system of the embodiments of the present application can be divided, combined or deleted according to actual needs. If these modifications and variations of the embodiments of the present application belong to the scope of the claims of the present application and the equivalent technologies thereof, the present application also intends to include these modifications and variations.
Claims
1. A method for unloading a mirror stream table, characterized in that: The mirror stream table unloading method includes: Determining a reference flow table and at least one mirrored flow table having a first mirroring relationship with the reference flow table, wherein the reference flow table defines at least one message editing action, and the at least one mirrored flow table each defines, based on the at least one message editing action defined in the reference flow table, performing the message editing action based on the first mirroring relationship; generating a multicast replication group to represent all members of the at least one mirrored flow table, and establishing a second mirroring relationship between the reference flow table and the multicast replication group based on the first mirroring relationship between the reference flow table and the at least one mirrored flow table, wherein the multicast replication group defines, based on the at least one message editing action defined in the reference flow table, a message editing action to be performed based on the second mirroring relationship, so as to implement a mirrored flow table function for all members of the at least one mirrored flow table using the multicast replication function of the multicast replication group; The reference flow table and the multicast replication group are uninstalled to the message forwarding hardware.
2. The image stream table unloading method according to claim 1, characterized in that: The at least one message editing action defined in the reference flow table includes performing message field modification on one or more of the source network protocol address, source machine physical address, source port, destination network protocol address, destination machine physical address, and destination port.
3. The mirror stream table unloading method according to claim 2, characterized in that: The message editing action defined in each of the at least one mirror flow tables includes, based on the at least one message editing action defined in the reference flow table and based on the first mirroring relationship, performing message field modification on one or more of the source network protocol address, the source machine physical address, the source port, the destination network protocol address, the destination machine physical address, and the destination port.
4. The mirror stream table unloading method according to claim 3, characterized in that: The number of packet editing actions defined in each of the at least one mirrored flow table is the same as the number of the at least one packet editing action defined in the reference flow table.
5. The mirror stream table unloading method according to claim 2, characterized in that: The number of packet editing actions defined by the multicast replication group is the same as the number of the at least one packet editing action defined by the reference flow table.
6. The image stream table unloading method according to claim 1, characterized in that: The reference flow table defines that a checksum calculation is performed once after each of the at least one packet editing action defined in the reference flow table is completed.
7. The mirror stream table unloading method according to claim 6, characterized in that: Each of the at least one mirror flow table defines that a checksum calculation is performed after each message editing action defined in the mirror flow table is completed.
8. The mirror stream table unloading method according to claim 7, characterized in that: The number of times the checksum calculation is performed defined in each of the at least one mirror flow table is the same as the number of times the checksum calculation is performed defined in the reference flow table.
9. The mirror stream table unloading method according to claim 6, characterized in that: The multicast replication group defines that a checksum calculation is performed after each message editing action defined in the multicast replication group is completed, and the number of checksum calculations defined by the multicast replication group is the same as the number of checksum calculations defined by the reference flow table.
10. The image stream table unloading method according to claim 1, characterized in that: The reference flow table is used to forward message traffic from the first virtual function of the first physical function to the second virtual function of the first physical function, and the at least one mirror flow table is used to modify message fields and perform checksum calculations on the original message from the first virtual function of the first physical function to the second virtual function of the first physical function, so as to realize forwarding of the mirror message to other virtual functions of the first physical function except the first virtual function and the second virtual function.
11. A device, characterized in that The device comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 10 when executing the computer program.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, which, when executed on a computer device, cause the computer device to perform the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Flow table hardware unloading method, equipment and medium
CN115150328A
Multicast traffic replication method based on hardware unloading and related device
CN116366534A