Flow table item unloading method and device, intelligent network card and computer readable storage medium
By introducing a priority policy table into the smart network card, the problem of timely uninstallation of key business flow items caused by hash conflicts is solved, ensuring the normal operation of key businesses, and realizing timely uninstallation and business priority guarantee in the case of hash conflicts.
Patent Information
- Application Number
- CN202410027885.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
In smart network cards, hash conflicts cause the flow table entries of key services to be unable to be uninstalled to the hardware flow table in time, affecting the normal operation of the service, especially when restarting or failure recovery.
Introduce a priority policy table to store the matching information of key services in advance. By judging whether the matching information of the flow table entry to be unloaded is in the priority policy table, if so, replace the conflicting flow table entry in the hardware flow table to ensure that the flow table entry of the key services can be uninstalled in a timely manner.
It effectively avoids the impact of hash conflict on key services, ensures the normal operation of key services under smart network card restart, failure recovery, etc., and does not affect the uninstallation process of the existing OVS-DPDK.
Smart Images

Figure CN120281591A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent network cards, and more specifically, to a method and apparatus for offloading flow table entries, an intelligent network card, and a computer-readable storage medium. Background Art
[0002] With the development of the current big data network, the network bandwidth is getting higher and higher, and the server network has almost reached its bottleneck; the intelligent network card network offloading technology has emerged to relieve the computing power of the server CPU; however, the intelligent network card will bear many network processing pressures; on the premise of coping with the current network offloading pressure, the current available on-board CPU multi-core processing is used to improve the intelligent network card offloading speed; by connecting an external memory device, the capacity specification of the hardware flow table is improved; but after the flow table capacity is increased, on the basis of the large capacity, the intelligent network card performs hash calculation based on the packet feature information, so hash conflicts are difficult to avoid.
[0003] The OVS (Open Virtual Switch) flow table offloading technology based on DPDK (Data Plane Development Kit) is a commonly used offloading technology for current intelligent network cards; although the flow table hash algorithms are different; but when the flow table capacity reaches a certain scale, hash conflicts will be a problem that must be faced; currently, under the limited hardware resources, it is impossible to integrate more complex hash algorithms to solve the current hash conflict problem; because the current logical resources have almost reached the limit; and the implementation cycle of replacing the hash algorithm is long. Due to the existence of hash conflicts, when there are hash conflicts between the flow tables of critical services and ordinary services, the prior art cannot ensure that the software flow tables of critical services are timely offloaded to the hardware flow tables, affecting the normal operation of critical services. Summary of the Invention
[0004] The purpose of the present invention is to provide a method and apparatus for offloading flow table entries, an intelligent network card, and a computer-readable storage medium, which can timely offload the flow tables of critical services to the hardware flow tables and ensure the normal operation of critical services.
[0005] The embodiments of the present invention can be implemented as follows:
[0006] In a first aspect, the present invention provides a method for offloading flow table entries, which is applied to an intelligent network card. The intelligent network card pre-stores a hardware flow table and a priority policy table, and the priority policy table includes matching information of flow table entries of pre-specified priority offloading services. The method includes:
[0007] Obtain the flow table entries to be offloaded;
[0008] If there is a conflicting flow entry in the hardware flow table that has a hash conflict with the flow entry to be offloaded, determine whether the matching information of the flow entry to be offloaded is in the priority policy table;
[0009] If the matching information of the flow entry to be offloaded is in the priority policy table, replace the conflicting flow entry with the flow entry to be offloaded.
[0010] In an alternative embodiment, the step of determining whether the matching information of the flow entry to be offloaded is in the priority policy table includes:
[0011] If there is matching information in the priority policy table that is the same as the matching information of the flow entry to be offloaded, determine that the matching information of the flow entry to be offloaded is in the priority policy table; otherwise, determine reverse matching information based on the matching information of the flow entry to be offloaded, where the forwarding direction represented by the reverse matching information is opposite to the forwarding direction represented by the matching information of the flow entry to be offloaded;
[0012] If there is matching information in the priority policy table that is the same as the reverse matching information, determine that the matching information of the flow entry to be offloaded is in the priority policy table;
[0013] If there is no matching information in the priority policy table that is the same as the matching information of the flow entry to be offloaded and there is no matching information in the priority policy table that is the same as the reverse matching information, determine that the matching information of the flow entry to be offloaded is not in the priority policy table.
[0014] In an alternative embodiment, the matching information of the flow entry to be offloaded includes source matching information and destination matching information for matching the source of a packet, and the step of determining reverse matching information based on the matching information of the flow entry to be offloaded includes:
[0015] Exchange the source matching information and the destination matching information, and use the exchanged matching information as the reverse matching information.
[0016] In an alternative embodiment, the method further includes:
[0017] If the matching information of the flow entry to be offloaded is not in the priority policy table, do not offload the flow entry to be offloaded.
[0018] In an alternative embodiment, the method further includes:
[0019] If there is no such conflicting flow entry in the hardware flow table, offload the flow entry to be offloaded to the hardware flow table.
[0020] In an alternative embodiment, the hardware flow table includes flow entries and their matching information, and the method further includes:
[0021] If the hash value of the matching information of a flow entry in the hardware flow table is the same as the hash value of the matching information of the flow entry to be offloaded, it is determined that there is a conflicting flow entry in the hardware flow table; otherwise, it is determined that there is no conflicting flow entry in the hardware flow table.
[0022] In an alternative embodiment, the step of obtaining the flow entry to be offloaded includes:
[0023] Obtain a packet to be forwarded;
[0024] If the packet to be forwarded does not match the hardware flow table, generate the flow entry to be offloaded according to the source matching information and destination matching information carried in the packet to be forwarded.
[0025] In a second aspect, the present invention provides a flow entry offloading device, which is applied to an intelligent network card. The intelligent network card pre-stores a hardware flow table and a priority policy table. The priority policy table includes the matching information of the flow entries for the pre-specified priority offloading services. The device includes:
[0026] An obtaining module, configured to obtain a flow entry to be offloaded;
[0027] A judging module, configured to judge whether the matching information of the flow entry to be offloaded is in the priority policy table if there is a conflicting flow entry in the flow entries of the hardware flow table that has a hash conflict with the flow entry to be offloaded;
[0028] A processing module, configured to replace the conflicting flow entry with the flow entry to be offloaded if the matching information of the flow entry to be offloaded is in the priority policy table.
[0029] In a third aspect, the present invention provides an intelligent network card, including a processor and a memory. The memory is used to store a program, and the processor is configured to implement the flow entry offloading method described in the first aspect when executing the program.
[0030] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the flow entry offloading method described in the first aspect is implemented.
[0031] When there is a hash conflict between the flow entries of the hardware flow table and the flow entry to be offloaded, the present invention determines whether the flow entry to be offloaded is a flow entry that needs to be offloaded preferentially through the priority policy table. If so, the conflicting flow entry in the hardware flow table is replaced with the flow entry to be offloaded, thereby ensuring that the flow entry to be offloaded can be offloaded in time and enabling the service corresponding to the flow entry to be offloaded to run normally. Description of the Drawings
[0032] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0033] Figure 1 It is an example diagram of the application scenario provided for this embodiment.
[0034] Figure 2 It is a block diagram example of the intelligent network card provided for this embodiment.
[0035] Figure 3 It is a flowchart example of the flow table entry offloading method provided for this embodiment.
[0036] Figure 4 It is a block diagram example of the flow table entry offloading device provided for this embodiment.
[0037] Icons: 10 - intelligent network card; 11 - processor; 12 - memory; 13 - bus; 20 - server; 30 - storage device; 100 - flow table entry offloading device; 110 - acquisition module; 120 - judgment module; 130 - processing module. Specific embodiments
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0039] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0040] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0041] In the description of the present invention, it should be noted that if terms such as "upper", "lower", "inner", "outer", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the invention product is usually placed during use. This is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention.
[0042] In addition, if terms such as "first", "second", etc. are only used for distinguishing descriptions, they cannot be understood as indicating or implying relative importance.
[0043] It should be noted that, without conflict, the features in the embodiments of the present invention can be combined with each other.
[0044] Please refer to Figure 1 and refer to Figure 1 , Figure 1 which is an example diagram of the application scenario provided for this embodiment. Figure 1 In [the figure], the intelligent network card 10 is installed on the server 20 and is communicatively connected to the server 20 through a bus. The intelligent network card 10 communicates with a remote storage device 30 through a network. The server 20 uses the intelligent network card 10 to store the data to be stored in the storage device 30.
[0045] The intelligent network card 10 is a network card with an independent computing unit that can complete specific infrastructure function operations. The intelligent network card 10 performs communication protocol conversion through software to communicate with the storage device 30. The intelligent network card 10 also performs storage protocol conversion through software to access the storage device 30, thereby providing the server 20 with the function of accessing the storage device 30.
[0046] The server 20 is usually a hardware device that has both the characteristics of a traditional physical server and the virtualization service function of cloud computing technology. It is the product of the combination of hardware and software advantages. The server 20 can provide an enterprise with a dedicated physical server on the cloud, providing excellent computing performance and data security for services such as core databases, key application systems, high-performance computing, and big data. This enables cloud service users to apply flexibly and use on demand.
[0047] The storage device 30 provides storage space for the server 20. The storage device 30 can be an independent storage server, or a storage array or a storage network, etc.
[0048] Based on Figure 1 , this embodiment provides Figure 1 a block diagram example of the intelligent network card 10 in [the figure]. Please refer to Figure 2 , Figure 2 which is a block diagram example of the intelligent network card 10 provided for this embodiment.Figure 2 In the figure, the smart network card 10 includes a processor 11, a memory 12, and a bus 13, and the processor 11 and the memory 12 are connected through the bus 13.
[0049] The processor 11 may be an integrated circuit chip having signal processing capabilities. In the implementation process, each step of the flow table item unloading method may be completed by an integrated logic circuit of hardware in the processor 11 or by instructions in the form of software. The above-mentioned processor 11 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
[0050] The memory 12 is used to store programs, such as the flow entry unloading device in the following embodiments. The flow entry unloading device 100 includes at least one software function module that can be stored in the memory 12 in the form of software or firmware or fixed in the smart network card 10. After receiving the execution instruction, the processor 11 executes the program to implement the flow entry unloading method disclosed in the above embodiment.
[0051] based on Figure 1 and Figure 2 Due to the high difficulty in developing the hardware logic resources of the smart network card 10 and the limited hardware logic resources, the capacity of the hardware flow table is also limited. The method of unloading the software flow table items to the hardware flow table through hash calculation will inevitably result in hash conflicts. When the smart network card 10 restarts, recovers from a fault, restarts the software, and other events occur, if the software flow table items of the key services that handle such events cannot be unloaded to the hardware flow table in time due to hash conflicts with the flow table items in the hardware flow table, it will affect the normal use of the smart network card 10, and further affect the normal operation of the services on the server 20.
[0052] In view of the above problems, one solution is to minimize the probability of hash collisions as much as possible, increase the probability that the software flow table entries corresponding to critical services are promptly offloaded to the hardware flow table, and reduce the risk of the intelligent network card 10 being affected during critical events. One way to reduce hash collisions is to vary the hash factor used in the hash algorithm to decrease the calculated probability of hash collisions. The optimization effect is relatively obvious. For example, for a hardware flow table with a capacity of 1M, the collision rate is less than 5%. Although this method largely alleviates the problems caused by hash collisions for most application scenarios, in some scenarios, it still cannot guarantee that the critical service packets of the intelligent network card 10 are immune to hash collisions. For example, when the intelligent network card 10 boots using a cloud disk, in addition to the service packets related to cloud disk booting, there will also be a large number of other service packets that need to be offloaded to the hardware flow table. If hash collisions occur during the offloading process, the service packets related to cloud disk booting will be affected, ultimately resulting in the unavailability of the cloud disk.
[0053] To eliminate the problem that the flow table entries corresponding to critical services cannot be promptly offloaded to the hardware flow table due to hash collisions, this embodiment adopts another approach. By introducing a priority policy table, it is ensured that the flow table entries corresponding to the matching information in the priority policy table can be promptly offloaded to the hardware flow table even during hash collisions, thereby ensuring that the priority offloading services corresponding to the flow table entries with the matching information in the priority policy table can also be properly processed during hash collisions. Pre-loading the matching information corresponding to the priority offloading services into the priority policy table can ensure that the priority offloading services are not affected by hash collisions. The following will describe it in detail.
[0054] Please refer to Figure 3 , Figure 3 which is a flowchart example of the flow table entry offloading method provided in this embodiment. This method is applied to the intelligent network card 10 in Figure 1 and Figure 2 and includes the following steps:
[0055] Step S101, obtain the flow table entry to be offloaded.
[0056] In this embodiment, the flow table entry to be offloaded is the flow table entry that misses the hardware flow table. A flow table entry usually includes matching information (match or key) and an execution action (action). The matching information usually includes packet characteristic information, and the packet characteristic information usually includes the source MAC address, source IP address, source port, destination MAC address, destination IP address, and destination port. The packets entering the intelligent network card 10 also include packet characteristic information. The packets and the flow table entries are matched through the matching information. When the matching is successful, the packets are processed according to the execution action corresponding to the successfully matched flow table entry.
[0057] Step S102: If there is a conflicting flow entry in the hardware flow table that has a hash conflict with the flow entry to be unloaded, determine whether the matching information of the flow entry to be unloaded is in the priority policy table.
[0058] In this embodiment, the intelligent network card 10 pre-stores a hardware flow table and a priority policy table. Since the hardware flow table is stored in the switching chip of the intelligent network card 10, its processing efficiency is higher than that of the software processing of the CPU of the intelligent network card 10. The matching information in the priority policy table is the matching information for forwarding packets of services that need to be processed preferentially, and the services that need to be processed preferentially can be critical services, emergency services, and other services specified to meet the needs of the application scenario.
[0059] In this embodiment, the conflicting flow entry is a flow entry in the hardware flow table that has a hash conflict with the flow entry to be unloaded. As an implementation, it can be that their matching information is different, but the hash results obtained after hashing are the same.
[0060] Step S103: If the matching information of the flow entry to be unloaded is in the priority policy table, replace the conflicting flow entry with the flow entry to be unloaded.
[0061] In this embodiment, if the matching information of the flow entry to be unloaded is in the priority policy table, it means that the flow entry to be unloaded needs to be unloaded preferentially, and its unloading priority is higher than that of the conflicting flow entry. Therefore, replacing the conflicting flow entry with the flow entry to be unloaded realizes the unloading of the flow entry to be unloaded. Otherwise, the flow entry to be unloaded can be temporarily not unloaded.
[0062] The above method provided in this embodiment determines whether the flow entry to be unloaded is a flow entry that needs to be unloaded preferentially through the priority policy table. If so, the conflicting flow entry in the hardware flow table is replaced with the flow entry to be unloaded, thereby ensuring that the flow entry to be unloaded can be unloaded in time and enabling the service corresponding to the flow entry to be unloaded to run normally.
[0063] In an alternative embodiment, since the communication of packets is usually two-way, that is, the packets can be sent from the intelligent network card 10 or received by the intelligent network card 10, and each flow entry includes matching information for matching. To more accurately determine whether the matching information of the flow entry to be unloaded is in the priority policy table, this embodiment provides an implementation:
[0064] If there is matching information in the priority policy table that is the same as the matching information of the flow entry to be unloaded, it is determined that the matching information of the flow entry to be unloaded is in the priority policy table. Otherwise, reverse matching information is determined according to the matching information of the flow entry to be unloaded, and the forwarding direction represented by the reverse matching information is opposite to the forwarding direction represented by the matching information of the flow entry to be unloaded;
[0065] If there is matching information in the priority policy table that is the same as the reverse matching information, it is determined that the matching information of the flow table entry to be unloaded exists in the priority policy table;
[0066] If there is no matching information in the priority policy table that is the same as the matching information of the flow table entry to be unloaded and there is no matching information in the priority policy table that is the same as the reverse matching information, it is determined that the matching information of the flow table entry to be unloaded does not exist in the priority policy table.
[0067] In this embodiment, the matching information is used to determine whether there is matching information in the priority policy table that has the same communication direction as the flow table entry to be unloaded and is successfully matched. That is, when both are for sending packets or both are for receiving packets, the matching information can be used for judgment. The reverse matching information is used to determine whether there is matching information in the priority policy table that has the opposite communication direction to the flow table entry to be unloaded and is successfully matched. That is, when one of them is for sending packets and the other is for receiving packets, the reverse matching information can be used for judgment.
[0068] In this embodiment, only when there is no matching information with the same matching information and no matching information with the same reverse matching information in the priority policy table, it is determined that the matching information of the flow table entry to be unloaded does not exist in the priority policy table.
[0069] In this embodiment, the matching information of the flow table entry to be unloaded includes source matching information and destination matching information for matching the source of the packet. This embodiment also provides an implementation method for determining the reverse matching information:
[0070] Exchange the source matching information and the destination matching information, and use the exchanged matching information as the reverse matching information.
[0071] As an implementation manner, the source matching information may include one or more of a source MAC address, a source IP address, and a source port, and the destination matching information may include one or more of a destination MAC address, a destination IP address, and a destination port. For example, if the matching information of the flow table entry to be unloaded is: source matching information (MAC1, IP1, PORT1), destination matching information (MAC2, IP2, PORT2), then its reverse matching information is: source matching information (MAC2, IP2, PORT2), destination matching information (MAC1, IP1, PORT1).
[0072] In an optional implementation manner, if the matching information of the flow table entry to be unloaded does not exist in the priority policy table, it means that the flow table entry to be unloaded is not to be unloaded in a timely manner. The processing method at this time is:
[0073] If the matching information of the flow table entry to be unloaded does not exist in the priority policy table, the flow table entry to be unloaded is not unloaded.
[0074] It should be noted that if the matching information of the flow entry to be unloaded is not in the priority policy table, not unloading the flow entry to be unloaded can be temporary. When the conflicting flow entry reaches the aging condition and is deleted from the hardware flow table, if there is no conflicting flow entry at this time, and if the flow entry to be unloaded still needs to be unloaded into the hardware flow table, then the flow entry to be unloaded can be unloaded into the hardware flow table.
[0075] In an alternative embodiment, if there is no conflicting flow entry in the hardware flow table, the processing method here is as follows:
[0076] If there is no conflicting flow entry in the hardware flow table, then unload the flow entry to be unloaded into the hardware flow table.
[0077] In an alternative embodiment, in order to determine whether there is a conflicting flow entry, the hash value of the matching information of each flow entry in the hardware flow table can be compared with the hash value of the matching information of the flow entry to be unloaded one by one. If there is a flow entry with the same hash value as the flow entry to be unloaded, it is determined that there is a conflicting flow entry; otherwise, it is determined that there is no conflicting flow entry. The implementation method is as follows:
[0078] If the hash value of the matching information of a flow entry in the hardware flow table is the same as the hash value of the matching information of the flow entry to be unloaded, it is determined that there is a conflicting flow entry in the hardware flow table; otherwise, it is determined that there is no conflicting flow entry in the hardware flow table.
[0079] In this embodiment, the flow entry to be unloaded is generated when the packet misses the hardware flow table. One way to obtain the flow entry to be unloaded is as follows: obtain the packet to be forwarded; if the packet to be forwarded misses the hardware flow table, then generate the flow entry to be unloaded according to the source matching information and destination matching information carried by the packet to be forwarded.
[0080] In this embodiment, generating the flow entry to be unloaded according to the source matching information and destination matching information carried by the packet to be forwarded usually means converting the source matching information and destination matching information into a form that conforms to the flow entry format. The source matching information and destination matching information have been described above and will not be elaborated here.
[0081] In this embodiment, in order to more clearly illustrate the difference between the method provided in this embodiment and the existing method, the existing flow entry unloading method is given first in this embodiment, and the steps are as follows:
[0082] (1) The intelligent network card 10 receives a packet. If the packet misses the hardware flow table, the ovs pmd thread (ovs polling thread) forwards and unloads the packet.
[0083] (2) The ovs pmd generates offload flow entries to be offloaded based on the missed packets, and hands the offload flow entries to the ovsoffload thread (ovs offload thread), and the ovs offload thread offloads the offload flow entries one by one;
[0084] (3) For each offload flow entry, the ovs offload thread uniformly calls the rte_flow interface of DPDK for processing;
[0085] (4) The rte_flow interface finally calls the hardware offload interface of the driver for processing;
[0086] (5) When the hardware offload interface is processing, after calculating the hash value with the offload flow entry, it judges whether there is a hash conflict. If there is a hash conflict, no offload processing is performed;
[0087] (6) If there is no hash conflict, the offload flow entry is offloaded to the hardware flow table.
[0088] Taking the critical service as the basic service as an example, if the flow entry corresponding to the basic service needs to be offloaded and a hash conflict occurs, the flow entry will not be offloaded in time, affecting the operation of the basic service.
[0089] The method provided in this embodiment is used to improve the above steps. A priority policy table configuration file is added. The priority policy table includes the packet feature information of the flow entries corresponding to the services that need to be guaranteed with priority. The priority policy table configuration file is stored in the smart network card 10 in JSON format, and a dynamic setting command is provided using the JSON library to make the priority policy table take effect dynamically. The offload process adds the offload processing after the hash conflict of the flow table offload. After a hash conflict occurs, the matching information in the priority policy table is read through JSON, and the matching information of the offload flow entry is compared with the matching information in the priority policy table; the above steps (1)-(4) remain unchanged. Starting from the following step (5), step (5) and the subsequent improved steps are as follows:
[0090] (5) When the hardware offload interface is performing offload processing, after calculating the hash value with the offload flow entry, it judges whether there is a hash conflict. If there is a hash conflict, the priority policy table in JSON file format is read using the JSON library;
[0091] (6) The matching information of the offload flow entry is judged whether it exists in the priority policy table by using the matching information or reverse matching information of the offload flow entry in this embodiment;
[0092] (7) If not, the offload flow entry is not offloaded;
[0093] (8) If it exists, delete the flow entry that has a hash conflict with the flow entry to be unloaded from the hardware flow table, and unload the flow entry to be unloaded into the hardware flow table.
[0094] Taking the reliable basic service with priority guarantee as an example, the matching information corresponding to the packets of the basic service is written into the priority policy table in advance. When the flow entry corresponding to the basic service needs to be unloaded, if a hash conflict occurs, since the matching information of the flow entry corresponding to the basic service is in the priority policy table, according to the improved method, it can be unloaded in time, ensuring the normal operation of the basic service.
[0095] To execute the corresponding steps in the above embodiments and each possible implementation manner, an implementation manner of a flow entry unloading device 100 is given below. Please refer to Figure 4 , Figure 4 The block diagram of the flow entry unloading device 100 provided by the embodiment of the present invention is shown. It should be noted that the basic principle and the technical effects generated by the flow entry unloading device 100 provided in this embodiment are the same as those in the above embodiments. For the sake of brief description, some parts of this embodiment are not mentioned.
[0096] The flow entry unloading device 100 is applied to a smart network card. The smart network card pre-stores a hardware flow table and a priority policy table. The priority policy table includes the matching information of the flow entries of the pre-specified priority unloading services. The flow entry unloading device 100 includes an acquisition module 110, a judgment module 120, and a processing module 130.
[0097] The acquisition module 110 is used to acquire the flow entry to be unloaded;
[0098] The judgment module 120 is used to judge whether the matching information of the flow entry to be unloaded is in the priority policy table if there is a conflicting flow entry in the flow entries of the hardware flow table that has a hash conflict with the flow entry to be unloaded;
[0099] The processing module 130 is used to replace the conflicting flow entry with the flow entry to be unloaded if the matching information of the flow entry to be unloaded is in the priority policy table.
[0100] In an optional implementation manner, the acquisition module 110 is specifically used to: acquire the packet to be forwarded; if the packet to be forwarded does not hit the hardware flow table, generate the flow entry to be unloaded according to the source matching information and the destination matching information carried by the packet to be forwarded.
[0101] In an alternative embodiment, the determination module 120 is further configured to: if there is matching information in the priority policy table that is the same as the matching information of the flow entry to be unloaded, determine that the matching information of the flow entry to be unloaded is in the priority policy table; otherwise, determine reverse matching information according to the matching information of the flow entry to be unloaded, where the forwarding direction represented by the reverse matching information is opposite to the forwarding direction represented by the matching information of the flow entry to be unloaded; if there is matching information in the priority policy table that is the same as the reverse matching information, determine that the matching information of the flow entry to be unloaded is in the priority policy table; if there is no matching information in the priority policy table that is the same as the matching information of the flow entry to be unloaded and there is no matching information in the priority policy table that is the same as the reverse matching information, determine that the matching information of the flow entry to be unloaded is not in the priority policy table.
[0102] In an alternative embodiment, the matching information of the flow entry to be unloaded includes source matching information and destination matching information for matching the source of the packet. When the determination module 120 is configured to determine reverse matching information according to the matching information of the flow entry to be unloaded, it is specifically configured to: exchange the source matching information and the destination matching information, and use the exchanged matching information as the reverse matching information.
[0103] In an alternative embodiment, the hardware flow table includes flow entries and their matching information. The determination module 120 is further configured to: if there is a hash value of the matching information of a flow entry in the hardware flow table that is the same as the hash value of the matching information of the flow entry to be unloaded, determine that there is a conflicting flow entry in the hardware flow table; otherwise, determine that there is no conflicting flow entry in the hardware flow table.
[0104] In an alternative embodiment, the processing module 130 is further configured to: if the matching information of the flow entry to be unloaded is not in the priority policy table, do not unload the flow entry to be unloaded.
[0105] In an alternative embodiment, the processing module 130 is further configured to: if there is no conflicting flow entry in the hardware flow table, unload the flow entry to be unloaded into the hardware flow table.
[0106] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the flow entry unloading method according to any one of the foregoing embodiments is implemented.
[0107] In summary, the embodiments of the present invention provide a flow entry offloading method, apparatus, intelligent network card, and computer-readable storage medium, which are applied to an intelligent network card. The intelligent network card pre-stores a hardware flow table and a priority policy table, and the priority policy table includes matching information of flow entries for preferentially offloading services specified in advance. The method includes: obtaining a flow entry to be offloaded; if there is a conflicting flow entry in the flow entries of the hardware flow table that has a hash conflict with the flow entry to be offloaded, determining whether the matching information of the flow entry to be offloaded is in the priority policy table; if the matching information of the flow entry to be offloaded is in the priority policy table, replacing the conflicting flow entry with the flow entry to be offloaded. Compared with the prior art, this embodiment has at least the following advantages: (1) determining whether the flow entry to be offloaded is a flow entry that needs to be offloaded preferentially through the priority policy table. If so, using the flow entry to be offloaded to replace the conflicting flow entry in the hardware flow table, thereby ensuring that the flow entry to be offloaded can be offloaded in a timely manner, enabling the service corresponding to the flow entry to be offloaded to run normally; (2) based on the actual business scenario, using the priority policy table to specify the service that can ensure preferential offloading in case of hash conflict during offloading, achieving business priority guarantee; (3) during the stages of intelligent network card restart, OVS-DPDK restart, and OVS-DPDK self-recovery from a fault, ensuring that its related services can be offloaded in a timely manner; thus ensuring the normal operation of the entire network card system; (4) minimally improving the original OVS-DPDK, maximizing the use of the original mechanism of OVS-DPDK, not affecting the aging and normal offloading process, and being able to achieve timely offloading of specified services; (5) using the matching information and reverse matching information to ensure the matching of messages in bidirectional communication when determining whether the flow entry to be offloaded is in the priority policy table, improving the accuracy and reasonableness of the matching.
[0108] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A flow table entry offloading method, characterized in that, Applied to a smart network card, the smart network card pre-stores a hardware flow table and a priority policy table, and the priority policy table includes matching information of flow table entries for preferentially offloading services specified in advance. The method includes: Obtain a flow table entry to be offloaded; If there is a conflicting flow table entry in the flow table entries of the hardware flow table that has a hash conflict with the flow table entry to be offloaded, determine whether the matching information of the flow table entry to be offloaded is in the priority policy table; If the matching information of the flow table entry to be offloaded is in the priority policy table, replace the conflicting flow table entry with the flow table entry to be offloaded.
2. The flow table entry offloading method according to claim 1, wherein The step of determining whether the matching information of the flow table entry to be offloaded is in the priority policy table includes: If there is matching information in the priority policy table that is the same as the matching information of the flow table entry to be offloaded, determine that the matching information of the flow table entry to be offloaded is in the priority policy table; otherwise, determine reverse matching information according to the matching information of the flow table entry to be offloaded, and the forwarding direction represented by the reverse matching information is opposite to the forwarding direction represented by the matching information of the flow table entry to be offloaded; If there is matching information in the priority policy table that is the same as the reverse matching information, determine that the matching information of the flow table entry to be offloaded is in the priority policy table; If there is no matching information in the priority policy table that is the same as the matching information of the flow table entry to be offloaded and there is no matching information in the priority policy table that is the same as the reverse matching information, determine that the matching information of the flow table entry to be offloaded is not in the priority policy table.
3. The flow table entry offloading method according to claim 2, characterized in that The matching information of the flow table entry to be offloaded includes source matching information and destination matching information for matching packets. The step of determining reverse matching information according to the matching information of the flow table entry to be offloaded includes: Exchange the source matching information and the destination matching information, and use the exchanged matching information as the reverse matching information.
4. The flow table entry offloading method according to claim 1, wherein The method further includes: If the matching information of the flow table entry to be offloaded is not in the priority policy table, do not offload the flow table entry to be offloaded.
5. The flow table entry offloading method according to claim 1, wherein The method further includes: If there is no such conflicting flow table entry in the hardware flow table, offload the flow table entry to be offloaded to the hardware flow table.
6. The flow table entry offloading method according to claim 1, characterized in that, The hardware flow table includes flow table entries and their matching information. The method further includes: If the hash value of the matching information of a flow table entry in the hardware flow table is the same as the hash value of the matching information of the flow table entry to be offloaded, determine that there is such a conflicting flow table entry in the hardware flow table; otherwise, determine that there is no such conflicting flow table entry in the hardware flow table.
7. The flow table entry offloading method according to claim 1, characterized in that The step of obtaining a flow table entry to be offloaded includes: Obtain a packet to be forwarded; If the packet to be forwarded does not hit the hardware flow table, generate the flow table entry to be offloaded according to the source matching information and destination matching information carried by the packet to be forwarded.
8. A flow table entry offloading device, characterized in that, Applied to a smart network card, the smart network card pre-stores a hardware flow table and a priority policy table, and the priority policy table includes matching information of flow table entries for preferentially offloading services specified in advance. The device includes: An obtaining module, configured to obtain a flow table entry to be offloaded; A judging module, configured to judge whether matching information of the flow entry to be unloaded is in the priority policy table if there is a conflicting flow entry in the flow entries of the hardware flow table that has a hash conflict with the flow entry to be unloaded; A processing module, configured to replace the conflicting flow entry with the flow entry to be unloaded if the matching information of the flow entry to be unloaded is in the priority policy table.
9. An intelligent network card, characterized in that, It includes a processor and a memory, the memory is used for storing a program, and the processor is used for implementing the flow entry unloading method according to any one of claims 1-7 when executing the program.
10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is executed by a processor, the flow entry unloading method according to any one of claims 1-7 is implemented.