Virtual machine mac address learning method, apparatus, device, medium and product

By maintaining the port upload status list in the distributed controller and recording the MAC address upload status information of each virtual machine port, the stability problem of the OVN cluster in the virtual machine abnormal scenario is solved, and the stability of the OVN cluster and efficient MAC address management are achieved.

CN120614324BActive Publication Date: 2025-10-17JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511073386.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-10-17
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

In abnormal scenarios such as virtual machine program anomalies or malicious attacks, the virtual machine may generate a large number of packets with different source MAC addresses in a short period of time, causing the host machine to frequently process upload requests, which spread to the OVN cluster, causing the cluster to be unable to process normal requests or even crash.

Method used

By maintaining a port upload status list in the distributed controller, recording the MAC address upload status information of each virtual machine port, and determining whether to learn and upload the source MAC address to the southbound database based on the updated status information, the upload of massive invalid MAC addresses is limited, avoiding database overload and cluster crash.

Benefits of technology

It effectively reduces the pressure on the OVN cluster, prevents database overload and cluster crash, and ensures the stability of the OVN cluster.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614324B_ABST
    Figure CN120614324B_ABST
Patent Text Reader

Abstract

The application discloses a virtual machine MAC address learning method and device, equipment, medium and product, relates to the technical field of cloud computing, and is applied to a distributed controller. The method comprises the following steps: acquiring a source MAC address reported by a virtual switch and determining a target virtual machine port bound with the source MAC address; wherein a virtual machine on a host machine sends a network message through the target virtual machine port, and the network message carries the source MAC address; acquiring current reporting state information of the target virtual machine port from a preset port reporting state list, and updating the current reporting state information based on the source MAC address to obtain updated reporting state information; wherein the port reporting state list is used for recording reporting state information of each virtual machine port about the MAC address; and determining whether to learn the source MAC address and whether to allow the source MAC address to be reported to a southbound database based on the updated reporting state. The application can guarantee the stability of an OVN cluster.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cloud computing, and particularly relates to a virtual machine MAC address learning method, device, equipment, medium and product. BACKGROUND

[0002] In a cloud platform, a source MAC (Media Access Control Address) address needs to be encapsulated when a virtual machine communicates. When interfacing with an OVN (Open Virtual Network), a specified MAC address is usually assigned to the virtual machine by the OVN, and the virtual machine needs to encapsulate a packet according to the address, otherwise the packet will be discarded.

[0003] For virtual machines with special business needs, such as high-availability businesses, the OVN provides a mechanism that allows the source MAC to be flexibly changed. The OVN uploads the learned MAC table item to the OVN southbound database FDB (Forwarding Database Table) table and synchronizes it to other nodes by issuing a learning flow table on the host where the virtual machine is located. The OVN has a FDB table aging function, and each virtual machine only records 1-2 FDB data under normal business.

[0004] However, in abnormal scenarios such as virtual machine program exceptions and malicious attacks, the virtual machine may generate millions of packets with different source MAC addresses in a short period of time, causing the host where the virtual machine is located to frequently process upload requests and upload a large number of MAC table items to the OVN southbound database, and then spread to the entire OVN cluster, causing the cluster to be unable to process normal requests or even crash.

[0005] In summary, in the virtual machine MAC address learning process, how to ensure the stability of the OVN cluster is a problem to be solved at present. SUMMARY

[0006] Therefore, the purpose of the present application is to provide a MAC address learning method, device, equipment, medium and product, which can ensure the stability of the OVN cluster in the virtual machine MAC address learning process. The specific scheme is as follows:

[0007] In a first aspect, the present application discloses a virtual machine MAC address learning method applied to a distributed controller, the distributed controller being deployed on a host, and at least one virtual machine being run on the host, and the method comprising:

[0008] obtaining a source MAC address reported by a virtual switch and determining a target virtual machine port bound to the source MAC address; wherein the virtual machine on the host sends a network packet through the target virtual machine port, and the network packet carries the source MAC address;

[0009] obtaining current advertisement state information of the target virtual machine port from a preset port advertisement state list, and updating the current advertisement state information based on the source MAC address to obtain updated advertisement state information; wherein the port advertisement state list is used to record advertisement state information of each virtual machine port with respect to MAC addresses;

[0010] determining whether to learn the source MAC address and whether to allow the source MAC address to be advertised to the southbound database based on the updated advertisement state.

[0011] Optionally, the advertisement state information recorded in the port advertisement state list includes a port identifier, a start time stamp of a current statistical period, a number of learned MAC addresses in the current statistical period, a last-learned MAC address, a current port advertisement state, and a cumulative number of times of continuously entering an advertisement state inhibition state.

[0012] Optionally, before the updating of the current advertisement state information based on the source MAC address to obtain the updated advertisement state information, the method further includes:

[0013] obtaining the last-learned MAC address in the current advertisement state information;

[0014] determining whether the last-learned MAC address is consistent with the source MAC address;

[0015] if the last-learned MAC address is consistent with the source MAC address, then prohibiting the updating of the current advertisement state information based on the source MAC address to obtain the updated advertisement state information;

[0016] if the last-learned MAC address is not consistent with the source MAC address, then allowing the updating of the current advertisement state information based on the source MAC address to obtain the updated advertisement state information.

[0017] Optionally, in the updating of the current advertisement state information based on the source MAC address to obtain the updated advertisement state information, the method further includes:

[0018] performing an addition operation on the number of learned MAC addresses to obtain an updated number of learned MAC addresses, determining a preset threshold corresponding to the current port advertisement state, and updating the current port advertisement state according to a comparison result of the updated number of learned MAC addresses and the preset threshold to obtain an updated port advertisement state;

[0019] updating the last-learned MAC address to the source MAC address.

[0020] Optionally, the current port learning state and the updated port learning state are any one of a learning state, a local storage state, a suppression state and an isolation state; the learning state indicates that the distributed controller is allowed to learn MAC addresses and the distributed controller is allowed to upload the MAC addresses to the southbound database; the local storage state indicates that the distributed controller is allowed to learn MAC addresses and the distributed controller is not allowed to upload the MAC addresses to the southbound database; the suppression state indicates that the distributed controller is not allowed to learn MAC addresses and the network packet is forwarded according to a default flow table rule; and the isolation state indicates that the distributed controller is not allowed to learn MAC addresses and the network packet corresponding to the MAC address not learned is discarded.

[0021] Optionally, the preset threshold corresponding to the current port learning state is determined, including:

[0022] If the current port learning state is the learning state, the preset threshold corresponding to the current port learning state is a first threshold; the first threshold is a maximum number of MAC addresses allowed to be learned in a preset statistical period.

[0023] Correspondingly, the current port learning state is updated according to the comparison result of the updated MAC address quantity and the preset threshold to obtain an updated port learning state, including:

[0024] If the updated MAC address quantity is greater than the first threshold, the current port learning state is updated from the learning state to the local storage state.

[0025] If the updated MAC address quantity is not greater than the first threshold, the current port learning state is kept unchanged.

[0026] Optionally, the preset threshold corresponding to the current port learning state is determined, including:

[0027] If the current port learning state is the local storage state, the preset threshold corresponding to the current port learning state is a second threshold; the second threshold is a product of a maximum number of MAC addresses allowed to be learned in a preset statistical period and a target multiple.

[0028] Correspondingly, the current port learning state is updated according to the comparison result of the updated MAC address quantity and the preset threshold to obtain an updated port learning state, including:

[0029] If the updated MAC address quantity is greater than the second threshold, the current port learning state is updated from the local storage state to the suppression state.

[0030] If the updated MAC address quantity is not greater than the second threshold, the current port learning state is kept unchanged.

[0031] Optionally, the preset threshold corresponding to the current port-up state is determined, comprising:

[0032] If the current port-up state is the suppression port-up state, the corresponding preset threshold is a third threshold; wherein the third threshold is a target limit number of times of continuously entering the suppression port-up state;

[0033] Correspondingly, the current port-up state is updated according to the comparison result of the updated MAC address quantity and the preset threshold to obtain an updated port-up state, comprising:

[0034] If the updated MAC address quantity is greater than the second threshold, the cumulative number of times is incremented by one to obtain an updated cumulative number of times;

[0035] It is judged whether the updated cumulative number of times is greater than the third threshold;

[0036] If yes, the current port-up state is updated from the suppression port-up state to the isolation state;

[0037] If no, the current port-up state is kept unchanged as the suppression port-up state.

[0038] Optionally, in the process of obtaining the current port-up state information of the target virtual machine port from the preset port-up state list, further comprising:

[0039] If the port-up state information of the target virtual machine port is not recorded in the port-up state list, the target port-up state information of the target virtual machine port is added in the port-up state list; wherein in the target port-up state information, the current port-up state is initialized as the allowed port-up state, and the starting timestamp of the current statistical period is initialized as the current timestamp;

[0040] If the current port-up state information of the target virtual machine port is recorded in the port-up state list, and the starting timestamp of the current statistical period in the current port-up state information is a zero value, the starting timestamp is updated as the current timestamp.

[0041] Optionally, based on the updated port-up state, it is determined whether to learn the source MAC address and whether to allow the learned source MAC address to be uploaded to the southbound database, comprising:

[0042] If the updated port-up state is the allowed port-up state, it is determined to learn the source MAC address, and the learned source MAC address is allowed to be uploaded to the southbound database;

[0043] If the updated port-up state is the local storage state, it is determined to learn the source MAC address, and the learned source MAC address is not allowed to be uploaded to the southbound database;

[0044] If the updated sending state is the suppression sending state or the isolation state, the source MAC address is not allowed to be learned, and the source MAC address is not allowed to be sent to the southbound database.

[0045] Optionally, the virtual machine MAC address learning method further comprises:

[0046] If the updated sending state is the permission sending state, a target flow table sent by the southbound database is acquired, so as to forward the network packet based on the target flow table;

[0047] If the updated sending state is the local storage state, the source MAC address is added to a preset MAC list to be configured to the local, and a local cache flow table of the target virtual machine port is generated, so as to forward the network packet based on the local cache flow table;

[0048] If the updated sending state is the suppression sending state, a suppression sending flow table of the target virtual machine port is sent, so as to forward the network packet based on the suppression sending flow table; the suppression sending flow table is used to control the distributed controller not to learn a new MAC address, and forward the network packet based on an existing flow table; the existing flow table is any one of the target flow table, the local cache flow table or a default flow table, the target flow table and the local cache flow table are used to forward the network packet of the known MAC address, and the default flow table is used to forward the network packet of the unknown MAC address;

[0049] If the updated sending state is the isolation state, an isolation flow table of the target virtual machine port is sent, so as to forward the network packet based on the suppression sending flow table; the isolation flow table is used to control the distributed controller not to learn a new MAC address, discard the network packet of the unknown MAC address, and forward the network packet of the known MAC address based on the target flow table and the local cache flow table.

[0050] Optionally, the priority of the isolation flow table is higher than the priority of the suppression sending flow table, the priority of the suppression sending flow table is higher than the priority of the target flow table and the local cache flow table, and the priority of the target flow table is the same as the priority of the local cache flow table.

[0051] Optionally, the virtual machine MAC address learning method further comprises:

[0052] The port sending state list is traversed, so as to calculate the cumulative record time of each virtual machine port based on the start time stamp of the current statistical period of each virtual machine port;

[0053] It is judged whether the cumulative record time of any virtual machine port exceeds a target rolling period;

[0054] If yes, a target cleaning operation is performed on the sending state information corresponding to any virtual machine port;

[0055] If not, then re-jump to the step of traversing the port uplink state list.

[0056] Optionally, the cumulative record time of each virtual machine port is calculated based on a start timestamp of a current statistics period of each virtual machine port, including:

[0057] The start timestamp of the current statistics period of each virtual machine port is obtained.

[0058] The cumulative record time is determined based on a difference between the current timestamp and the start timestamp.

[0059] Optionally, when the current port uplink state of any virtual machine port is the allowed uplink state, the local storage state or the suppressed uplink state, the target rolling period is a first rolling period, and the first rolling period is a single preset statistics period.

[0060] Correspondingly, the target cleaning operation is performed on the uplink state information corresponding to any virtual machine port, including:

[0061] If any virtual machine port is in the allowed uplink state in the first rolling period, the uplink state information of any virtual machine port is removed from the port uplink state list.

[0062] If any virtual machine port is in the local storage state in the first rolling period, the local cache flow table corresponding to any virtual machine port is removed, and the uplink state information of any virtual machine port is removed from the port uplink state list.

[0063] If any virtual machine port is in the suppressed uplink state in the first rolling period, the local cache flow table and the suppressed uplink flow table corresponding to any virtual machine port are removed, and it is determined whether the current state is updated to the isolation state, if not, the current port uplink state of any virtual machine port is updated to the allowed uplink state in the port uplink state list.

[0064] Optionally, when the current port uplink state of any virtual machine port is the isolation state, the target rolling period is a second rolling period, and the second rolling period is a target multiple of the preset statistics period.

[0065] Correspondingly, the target cleaning operation is performed on the uplink state information corresponding to any virtual machine port, including:

[0066] If any virtual machine port is in the isolation state in the second rolling period, the isolation flow table corresponding to any virtual machine port is removed, and the uplink state information of any virtual machine port is removed from the port uplink state list.

[0067] In a second aspect, the present application discloses a virtual machine MAC address learning device, applied to a distributed controller, the distributed controller being deployed on a host computer, the host computer running at least one virtual machine, the device comprising:

[0068] an information determining module, configured to acquire a source MAC address reported by a virtual switch and determine a target virtual machine port bound to the source MAC address; wherein the virtual machine on the host computer sends a network packet through the target virtual machine port, and the network packet carries the source MAC address;

[0069] an updating module, configured to acquire current reporting state information of the target virtual machine port from a preset port reporting state list and update the current reporting state information based on the source MAC address to obtain updated reporting state information; wherein the port reporting state list is used to record reporting state information of each virtual machine port about the MAC address;

[0070] a learning module, configured to determine whether to learn the source MAC address and whether to allow the source MAC address to be reported to a southbound database based on the updated reporting state.

[0071] In a third aspect, the present application discloses an electronic device, comprising:

[0072] a memory, configured to save a computer program;

[0073] a processor, configured to execute the computer program to implement the steps of the virtual machine MAC address learning method disclosed above.

[0074] In a fourth aspect, the present application discloses a computer readable storage medium, configured to store a computer program; wherein the computer program is executed by a processor to implement the steps of the virtual machine MAC address learning method disclosed above.

[0075] In a fifth aspect, the present application discloses a computer program product, comprising a computer program / instruction, which is executed by a processor to implement the steps of the virtual machine MAC address learning method disclosed above.

[0076] It can be seen that the distributed controller acquires the source MAC address reported by the virtual switch, and determines the target virtual machine port to which the source MAC address is bound; the virtual machine on the host machine sends a network packet through the target virtual machine port, and the network packet carries the source MAC address; the current reporting state information of the target virtual machine port is acquired from the preset port reporting state list, and the current reporting state information is updated based on the source MAC address to obtain updated reporting state information; the port reporting state list is used to record the reporting state information of each virtual machine port about the MAC address; whether to learn the source MAC address and whether to allow the source MAC address to be reported to the southbound database are determined based on the updated reporting state.

[0077] Beneficial effects: The distributed controller in the present application is deployed on a host machine, and at least one virtual machine runs on the host machine. When the virtual machine running on the host machine needs to communicate, it sends a network packet through its target virtual machine port, and the network packet carries a source MAC address. Moreover, the network packet sent by the virtual machine passes through a virtual switch. If the source MAC address has not been learned, the virtual switch will report the source MAC address to the distributed controller. After acquiring the reported source MAC address, the distributed controller will first determine the target virtual machine port to which the source MAC address is bound, and acquire the current reporting state information of the target virtual machine port from the preset port reporting state list. It can be understood that the port reporting state list is used to record the reporting state information of each virtual machine port about the MAC address, that is, the present application establishes a port reporting state list, and records each virtual machine port in the list independently to ensure that the MAC address reporting behavior of each virtual machine port is independently and accurately counted, and different virtual machine ports do not affect each other. Further, the present application updates the current reporting state information based on the source MAC address to obtain updated reporting state information, so as to determine whether to learn the source MAC address and whether to allow the source MAC address to be reported to the southbound database based on the updated reporting state. That is, the present application maintains the reporting state information of each virtual machine port. Compared with the traditional scheme in which the distributed controller directly reports the source MAC address to the southbound database, the present application needs to determine whether the distributed controller can currently learn the source MAC address based on the reporting state information, and whether to report the source MAC address to the southbound database, so as to reduce the pressure on the OVN cluster through this limiting method, avoid database overload and cluster collapse caused by a large number of invalid MAC addresses, and ensure the stability of the OVN cluster. BRIEF DESCRIPTION OF DRAWINGS

[0078] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description only constitute part of the embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of the provided drawings.

[0079] Figure 1 A flow chart of a virtual machine MAC address learning method disclosed by the present application;

[0080] Figure 2 A state machine schematic diagram disclosed by the present application;

[0081] Figure 3 A cleaning flow chart of a port sending state list disclosed by the present application;

[0082] Figure 4 A virtual machine MAC address learning device structure schematic diagram disclosed by the present application;

[0083] Figure 5 A structure diagram of an electronic device disclosed by the present application. DETAILED DESCRIPTION

[0084] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments only constitute part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort fall within the scope of protection of the present application.

[0085] In abnormal scenarios such as virtual machine program exceptions and malicious attacks, the virtual machine may generate millions of different source MAC address packets in a short time, causing the host machine to frequently process upload requests and upload a large number of MAC table items to the OVN southbound database, and then spread to the entire OVN cluster, thereby causing the cluster to be unable to process normal requests or even crash. Therefore, the embodiments of the present application disclose a MAC address learning method, device, equipment, medium and product, which can ensure the stability of the OVN cluster in the virtual machine MAC address learning process.

[0086] Referring to Figure 1 The embodiments of the present application disclose a virtual machine MAC address learning method, applied to a distributed controller, the distributed controller being deployed on a host machine, and at least one virtual machine running on the host machine, the method comprising:

[0087] Step S11: obtaining a source MAC address reported by the virtual switch and determining a target virtual machine port to which the source MAC address is bound; wherein the virtual machine on the host machine sends a network packet through the target virtual machine port, and the network packet carries the source MAC address.

[0088] In this embodiment, the distributed controller in the application is deployed on a host machine, and at least one virtual machine runs on the host machine. When the virtual machine running on the host machine needs to communicate, it sends a network packet through its target virtual machine port, and the network packet carries a source MAC address. Moreover, the network packet sent by the virtual machine passes through a virtual switch. If the source MAC address has not been learned, the virtual switch will report the source MAC address to the distributed controller. The virtual switch is specifically an Open vSwitch (OVS). After obtaining the reported source MAC address, the distributed controller will first determine the target virtual machine port to which the source MAC address is bound.

[0089] It should be noted that the virtual machine can be bound to multiple virtual network cards, and each virtual network card of the virtual machine corresponds to a unique virtual machine port in the OVN.

[0090] Step S12: obtaining current reporting state information of the target virtual machine port from a preset port reporting state list, and updating the current reporting state information based on the source MAC address to obtain updated reporting state information; wherein the port reporting state list is used to record reporting state information of each virtual machine port about MAC addresses.

[0091] In this embodiment, the current reporting state information of the target virtual machine port is obtained from the preset port reporting state list. It can be understood that the port reporting state list is used to record reporting state information of each virtual machine port about MAC addresses, that is, the application establishes a port reporting state list, and records each virtual machine port in the list to ensure that the MAC address reporting behavior of each virtual machine port is independently and accurately counted, and different virtual machine ports do not affect each other. Further, the current reporting state information is updated based on the source MAC address to obtain updated reporting state information.

[0092] The reporting state information recorded in the port reporting state list includes a port identifier, a start timestamp of a current statistical period, a number of learned MAC addresses in the current statistical period, a last learned MAC address, a current port reporting state, and a cumulative number of times of entering a continuous reporting suppression state. It can be understood that the port reporting state list is a data structure maintained internally by the distributed controller, which is usually stored in the form of a Hash Map or a linked list in the code. The data structure can be as follows:

[0093]

[0094] Further, it should be noted that before updating the current reporting state information based on the source MAC address to obtain the updated reporting state information, it further includes: obtaining the last learned MAC address in the current reporting state information; judging whether the last learned MAC address is consistent with the source MAC address; if consistent, prohibiting the step of updating the current reporting state information based on the source MAC address to obtain the updated reporting state information; if inconsistent, allowing the step of updating the current reporting state information based on the source MAC address to obtain the updated reporting state information.

[0095] That is, after obtaining the current reporting state information of the target virtual machine port from the port reporting state list, the embodiment judges whether the last learned MAC address in the current reporting state information is consistent with the source MAC address currently reported by the virtual switch, if the two are consistent, no processing is performed, if inconsistent, the step of updating the current reporting state information based on the source MAC address to obtain the updated reporting state information is allowed to be performed. It can be understood that when the virtual machine frequently sends messages of the same MAC address in a short time, for example, repeated reporting caused by high concurrency business, the distributed controller will detect that the currently reported source MAC address is consistent with the last_mac recorded by the port, in this case, the current reporting state information of the target virtual machine port is no longer updated, thereby avoiding the high count caused by repeated statistics of the same MAC address, preventing the high flow of normal business from being misjudged as abnormal MAC change, while reducing unnecessary processing overhead and improving the efficiency of the controller.

[0096] Step S13: determining whether to learn the source MAC address and whether to allow the source MAC address to be reported to the southbound database based on the updated reporting state.

[0097] In the embodiment, the distributed controller determines whether to learn the source MAC address and whether to allow the source MAC address to be reported to the southbound database based on the updated reporting state. That is, the present application maintains the reporting state information of each virtual machine port, compared with the traditional scheme in which the distributed controller directly reports the source MAC address to the southbound database, the present application needs to determine whether the distributed controller can currently learn the source MAC address based on the reporting state information, and determine whether to report the source MAC address to the southbound database, thereby reducing the pressure on the OVN cluster through this limiting method, avoiding the database overload and cluster collapse caused by a large number of invalid MAC addresses, and ensuring the stability of the OVN cluster.

[0098] In addition, it should be noted that the above step process is mainly executed by the pinctrl_handler thread in the distributed controller. That is, the virtual switch reports the source MAC address to the pinctrl_handler thread in the distributed controller after checking the new source MAC address, and the subsequent process is executed by the pinctrl_handler thread to determine whether to learn the source MAC address and whether to allow the source MAC address to be uploaded to the southbound database.

[0099] It can be seen that the distributed controller in the present application is deployed on a host, and at least one virtual machine runs on the host. When the virtual machine running on the host needs to communicate, it sends a network packet through its target virtual machine port, and the network packet carries a source MAC address. Moreover, the network packet sent by the virtual machine passes through the virtual switch. If the source MAC address has not been learned, the virtual switch will report the source MAC address to the distributed controller. After obtaining the reported source MAC address, the distributed controller will first determine the target virtual machine port bound to the source MAC address, and obtain the current upload state information of the target virtual machine port from the preset port upload state list. It can be understood that the port upload state list is used to record the upload state information of each virtual machine port about the MAC address, that is, the present application establishes a port upload state list, and records each virtual machine port in the list to ensure that the MAC address upload behavior of each virtual machine port is independently and accurately counted, and different virtual machine ports do not affect each other. Further, the present application updates the current upload state information based on the source MAC address to obtain updated upload state information, so as to determine whether to learn the source MAC address and whether to allow the source MAC address to be uploaded to the southbound database based on the updated upload state. That is, by maintaining the upload state information of each virtual machine port, compared with the traditional scheme in which the distributed controller directly uploads the source MAC address to the southbound database, the present application needs to determine whether the distributed controller can currently learn the source MAC address based on the upload state information, and whether to upload the source MAC address to the southbound database, thereby reducing the pressure on the OVN cluster through this limiting method, avoiding database overload and cluster collapse caused by a large number of invalid MAC addresses, and ensuring the stability of the OVN cluster.

[0100] On the basis of the foregoing embodiments, the application specifically discloses an updating process of the state information of the upper sending, wherein in the process of updating the current state information of the upper sending based on the source MAC address to obtain the updated state information of the upper sending, the following steps are included: performing a plus operation on the number of the learned MAC addresses to obtain the updated number of the MAC addresses, and determining a preset threshold corresponding to the current port state of the upper sending, so as to update the current port state of the upper sending according to the comparison result of the updated number of the MAC addresses and the preset threshold to obtain the updated port state of the upper sending; and updating the last learned MAC address to the source MAC address.

[0101] It can be understood that if the source MAC address is inconsistent with the last learned MAC address, the current state information of the upper sending needs to be updated based on the source MAC address, and the specific updating process mainly involves performing a plus operation on the number of the learned MAC addresses to obtain the updated number of the MAC addresses, i.e. count+1, and updating the last learned MAC address last_mac to the source MAC address. Further, the preset threshold corresponding to the current port state of the upper sending also needs to be determined, so as to update the current port state of the upper sending according to the comparison result of the updated number of the MAC addresses and the preset threshold to obtain the updated port state of the upper sending.

[0102] The current port state of the upper sending and the updated port state of the upper sending are any one of an allowed state of the upper sending, a local storage state, a blocked state of the upper sending and an isolation state. The allowed state of the upper sending, i.e. PUT_STAT_INIT, is used to represent that the distributed controller is allowed to learn the MAC address and the distributed controller is allowed to send the MAC address to the southbound database; the local storage state, i.e. PUT_STAT_LOCAL, is used to represent that the distributed controller is allowed to learn the MAC address and the distributed controller is not allowed to send the MAC address to the southbound database; the blocked state of the upper sending, i.e. PUT_STAT_BLOCKED, is used to represent that the distributed controller is not allowed to learn the MAC address and the network packet is forwarded according to the default flow table rule, i.e. all network packets are normally forwarded; and the isolation state, i.e. PUT_STAT_ISOLATION, is used to represent that the distributed controller is not allowed to learn the MAC address and the network packet corresponding to the MAC address not learned is discarded, and the network packet is forwarded only by the learned MAC address. It can be understood that when the distributed controller is not allowed to learn the MAC address, the distributed controller naturally will not send the learned MAC address to the southbound database since the distributed controller does not learn the MAC address. The data structure of the port state of the upper sending is as follows:

[0103] enum put_stat_type {

[0104] PUT_STAT_INIT,

[0105] PUT_STAT_LOCAL,

[0106] PUT_STAT_BLOCKED,

[0107] PUT_STAT_ISOLATION,

[0108] }.

[0109] It should be further pointed out that the embodiments of the present application allow the user to set the suppression parameter according to the host level. That is, the suppression parameter is set in the external_ids field of Open_vSwitch of the local ovsdb-server of the host. The suppression parameter specifically includes: (1) suppression period: fdb_put_limit_period, that is, the time period for counting the number of learned MAC addresses; (2) limit value: fdb_put_limit_value, that is, if the number of learned MAC addresses exceeds the value within the suppression period, the data is not allowed to be uploaded to the OVN southbound database; (3) blocking multiple: fdb_put_block_times, that is, if the number of uploads to the distributed controller exceeds how many times the limit value within the suppression period, the upload to the distributed controller is no longer allowed.

[0110] Specifically, in the first specific implementation, determining the preset threshold corresponding to the current port upload state comprises: if the current port upload state is the allowed upload state, the corresponding preset threshold is the first threshold; wherein the first threshold is the maximum number of MAC addresses allowed to be learned within a preset statistical period; and correspondingly, updating the current port upload state according to the comparison result of the updated MAC address number and the preset threshold to obtain an updated port upload state comprises: if the updated MAC address number is greater than the first threshold, updating the current port upload state from the allowed upload state to the local storage state; and if the updated MAC address number is not greater than the first threshold, keeping the current port upload state unchanged as the allowed upload state. That is, when the current port upload state is the allowed upload state, the corresponding preset threshold is the maximum number of MAC addresses allowed to be learned within a preset statistical period, wherein the preset statistical period is the above-mentioned suppression period, and the first threshold is actually the above-mentioned limit value fdb_put_limit_value. Therefore, if the updated MAC address number is greater than the first threshold fdb_put_limit_value, the current port upload state is updated from the allowed upload state to the local storage state, otherwise the current port upload state is kept unchanged as the allowed upload state.

[0111] In the second specific implementation, determining the preset threshold corresponding to the current port-up state comprises: if the current port-up state is the local storage state, the corresponding preset threshold is the second threshold; wherein the second threshold is the product between the maximum number of MAC addresses allowed to learn in a preset statistical period and a target multiple; and correspondingly, updating the current port-up state according to the comparison result of the updated MAC address quantity and the preset threshold to obtain an updated port-up state comprises: if the updated MAC address quantity is greater than the second threshold, updating the current port-up state from the local storage state to the suppression-up state; and if the updated MAC address quantity is not greater than the second threshold, keeping the current port-up state unchanged as the local storage state. That is, when the current port-up state is the local storage state, the corresponding preset threshold is the product between the maximum number of MAC addresses allowed to learn in a preset statistical period and a target multiple, wherein the maximum number of MAC addresses is the limit value fdb_put_limit_value and the target multiple is the suppression multiple fdb_put_block_times, and thus the second threshold is fdb_put_limit_value x fdb_put_block_times. Therefore, if the updated MAC address quantity is greater than the second threshold, the current port-up state is updated from the local storage state to the suppression-up state, otherwise the current port-up state is kept unchanged as the local storage state.

[0112] In the third specific implementation, determining the preset threshold corresponding to the current port-up state comprises: if the current port-up state is the suppression-up state, the corresponding preset threshold is the third threshold; wherein the third threshold is a target limit number of times of entering the suppression-up state continuously; and correspondingly, updating the current port-up state according to the comparison result of the updated MAC address quantity and the preset threshold to obtain an updated port-up state comprises: if the updated MAC address quantity is greater than the second threshold, performing a plus operation on the accumulated number of times to obtain an updated accumulated number of times; judging whether the updated accumulated number of times is greater than the third threshold; if yes, updating the current port-up state from the suppression-up state to the isolation state; and if no, keeping the current port-up state unchanged as the suppression-up state. That is, when the current port-up state is the suppression-up state, the corresponding preset threshold is the target limit number of times of entering the suppression-up state continuously, which is assumed to be t, that is, entering the suppression-up state in t continuous statistical periods. Therefore, if the updated MAC address quantity is greater than the second threshold, performing a plus operation on the accumulated number of times to obtain an updated accumulated number of times, and if the updated accumulated number of times is greater than the third threshold, updating the current port-up state from the suppression-up state to the isolation state, otherwise keeping the current port-up state unchanged as the suppression-up state.

[0113] Specifically, Figure 2The state machine disclosed in the application shows that the first threshold value is v1=fdb_put_limit_value, the second threshold value is v2=fdb_put_limit_valuexfdb_put_block_times, the initialization state of the port sending state is the allowed sending state, the port sending state is updated from the allowed sending state to the local storage state when the number of learned MAC addresses in the suppression period exceeds the threshold value v1, the port sending state is updated from the local storage state to the suppressed sending state when the number of learned MAC addresses in the suppression period exceeds the threshold value v2, and the port sending state is updated from the suppressed sending state to the isolation state when the port sending state enters the suppressed sending state for t consecutive periods. Assuming that fdb_put_limit_period=60, fdb_put_limit_value=100, and fdb_put_block_times=5, when the number of MAC addresses learned by a virtual machine port in 60 s is less than 100, the distributed controller is allowed to continue learning and send the learning result to the OVN southbound database; if the number of MAC addresses learned in 60 s is greater than 100 and less than or equal to 500 (100x5), the part of addresses greater than 100 will not be sent to the OVN southbound database, and when the number of learned addresses is greater than 500, the distributed controller will no longer learn the MAC addresses of the virtual machine and will forward network packets according to the default flow table rule; when the port sending state is the suppressed sending state for 300 s, i.e., 5 consecutive periods, the packets of unknown MAC addresses of the virtual machine will no longer be forwarded. It should be noted that the application embodiment allocates the state machine according to the virtual machine port, and different virtual machines and different ports do not affect each other.

[0114] In addition, in the process of obtaining the current sending state information of the target virtual machine port from the preset port sending state list, the following steps are further included: if the sending state information of the target virtual machine port is not recorded in the port sending state list, the target sending state information of the target virtual machine port is added in the port sending state list; wherein, in the target sending state information, the current port sending state is initialized as the allowed sending state, and the starting timestamp of the current statistical period is initialized as the current timestamp; if the current sending state information of the target virtual machine port is recorded in the port sending state list, and the starting timestamp of the current statistical period in the current sending state information is a zero value, the starting timestamp is updated as the current timestamp.

[0115] It can be understood that when the above state information of the target virtual machine port is looked up from the port up state list, the following two cases can occur. The first case is that the up state information of the target virtual machine port is not recorded in the port up state list, at this time, the target up state information of the target virtual machine port is added in the port up state list, and it should be pointed out that the current port up state needs to be initialized to the allowed up state in the target up state information, and the start timestamp of the current statistical period is initialized to the current timestamp. The second case is that although the current up state information of the target virtual machine port is recorded in the port up state list, the start timestamp of the current statistical period in the current up state information is zero, at this time, the start timestamp needs to be updated to the current timestamp.

[0116] In the specific embodiment, determining whether to learn the source MAC address and whether to allow the source MAC address to be uploaded to the southbound database based on the updated up state includes: if the updated up state is the allowed up state, determining to learn the source MAC address and allowing the learned source MAC address to be uploaded to the southbound database; if the updated up state is the local storage state, determining to learn the source MAC address and not allowing the learned source MAC address to be uploaded to the southbound database; and if the updated up state is the suppressed up state or the isolated state, not allowing the source MAC address to be learned and not allowing the source MAC address to be uploaded to the southbound database. That is, after the current up state information is updated based on the source MAC address to obtain updated up state information, it is necessary to determine whether the distributed controller needs to learn the source MAC address and whether the learned source MAC address is allowed to be uploaded to the southbound database according to the updated up state information.

[0117] Specifically, if the updated up state is the allowed up state, the distributed controller needs to learn the source MAC address and upload the learned source MAC address to the southbound database; if the updated up state is the local storage state, the distributed controller needs to learn the source MAC address, but does not allow the learned source MAC address to be uploaded to the southbound database; and if the updated up state is the suppressed up state or the isolated state, the distributed controller does not learn the source MAC address, and the source MAC address is not uploaded to the southbound database.

[0118] Further, the application further discloses a flow table forwarding rule for a network message in different port sending states. Specifically, if the updated sending state is the allowed sending state, a target flow table issued by the southbound database is acquired, so as to forward the network message based on the target flow table; if the updated sending state is the local storage state, a source MAC address is added to a preset MAC list to be configured to the local, and a local cache flow table of the target virtual machine port is generated, so as to forward the network message based on the local cache flow table; if the updated sending state is the inhibited sending state, an inhibited sending flow table of the target virtual machine port is issued, so as to forward the network message based on the inhibited sending flow table; wherein the inhibited sending flow table is used for controlling the distributed controller not to learn a new MAC address, and forwarding the network message based on an existing flow table; the existing flow table is any one of the target flow table, the local cache flow table or a default flow table, the target flow table and the local cache flow table are used for forwarding a network message of a known MAC address, and the default flow table is used for forwarding a network message of an unknown MAC address; if the updated sending state is the isolation state, an isolation flow table of the target virtual machine port is issued, so as to forward the network message based on the inhibited sending flow table; wherein the isolation flow table is used for controlling the distributed controller not to learn a new MAC address, discarding a network message of an unknown MAC address, and forwarding a network message of a known MAC address based on the target flow table and the local cache flow table.

[0119] When the updated sending state is the allowed sending state, the network message is forwarded based on the target flow table issued by the southbound database, and the type of the target flow table is OPTABLE_LOOKUP_FDB, in the specific implementation, by matching the dp_key, the port_key and the MAC address, the fast forwarding of the message is ensured. In this case, the subsequent network message of the same MAC address can be directly matched with the target flow table, and repeated learning is not needed. And the southbound database synchronizes the MAC address, and issues the flow table to all related hosts, so that cross-host communication can also be realized, that is, the MAC address can also be recognized by other hosts, and global reachability is ensured.

[0120] When the update post-state is the local storage state, the source MAC address is added to a preset MAC list to be configured to the local, and then the local cache flow table of the target virtual machine port is generated by traversing the preset MAC list, so as to forward the network packet based on the local cache flow table. It should be noted that the local cache flow table is only effective in the local host and is not synchronized to other nodes, avoiding the overload of the southbound database. Subsequently, when the network packet with the same MAC address is sent again in the local host, it can be quickly forwarded based on the local cache flow table. The type of the local cache flow table is OPTABLE_LOOKUP_FDB, and the matching rule is also to match the dp_key, port_key and MAC address, so as to ensure the fast forwarding of the packet, and the designed flow table cookie id is composed of the dp_key and port_key of the port, facilitating the addition and identification and deletion.

[0121] When the update post-state is the suppression post-state, the suppression post-flow table of the target virtual machine port is issued, so as to forward the network packet based on the suppression post-flow table; wherein the suppression post-flow table is used to control the distributed controller not to learn new MAC addresses, that is, to directly ignore the reporting event and forward the network packet based on the existing flow table. The existing flow table is any one of the target flow table, the local cache flow table or the default flow table, the target flow table and the local cache flow table are used to forward the network packet with the known MAC address, and the default flow table is used to forward the network packet with the unknown MAC address. That is, the MAC address that has been learned can still match the target flow table, the local cache flow table and other OPTABLE_LOOKUP_FDB flow tables for normal forwarding, and the packet with the MAC address that has not been learned is forwarded according to the default flow table. The default flow table can adopt the broadcast / flooding mode, that is, the OVS will flood the packet with the unknown destination MAC to all ports, which is similar to the behavior of the traditional switch, so as to try not to lose the packet, but the performance is low. The type of the suppression post-flow table is OPTABLE_PUT_FDB, and the matching rule is: dp_key of the port, port_key of the port, reg0=0 / 0x800 (meaning matching new MAC address); the designed flow table cookie id is composed of the dp_key and port_key of the port, facilitating the addition and identification and deletion.

[0122] When the update upper sending state is the isolation state, the isolation flow table of the target virtual machine port is issued, so as to forward the network packet based on the suppression upper sending flow table; wherein, the isolation flow table is used to control the distributed controller not to learn new MAC address, discard all network packets of unknown MAC address, completely prevent MAC flooding attack, and forward the network packet of known MAC address based on the target flow table and the local cache flow table, that is, under the suppression upper sending flow table rule, only the learned MAC address is allowed to pass. The type of the isolation flow table is OPTABLE_PUT_FDB, the matching rule is: dp_key of the port, port_key of the port, reg0=0 / 0x800 (meaning matching new MAC address); the designed flow table cookieid is composed of dp_key of the port+port_key, which is convenient for adding and identifying deletion.

[0123] It should be further pointed out that the priority of the isolation flow table is higher than that of the suppression upper sending flow table, the priority of the suppression upper sending flow table is higher than that of the target flow table and the local cache flow table, and the priority of the target flow table and the local cache flow table is the same. Among them, the priority of the target flow table and the local cache flow table is 100, the priority of the suppression upper sending flow table is 110, the effect of suppressing upper sending is realized; the priority of the isolation flow table is 120, and the action is DROP, realizing the flow isolation. In the specific implementation process, the high-priority flow table covers the low-priority flow table rule, and ensures strict isolation.

[0124] It can be seen that the application discloses a scheme for realizing cluster stability guarantee of frequent source MAC address conversion of virtual machine in OVN, which records the upper sending state information of the port and hierarchical control, ensures that all flows of virtual machine without MAC address conversion are normal, ensures that all flows of virtual machine with small amount of MAC address conversion are normal, ensures that all flows of virtual machine with more MAC address conversion can be normally forwarded, and the performance is not affected, and at the same time, the cluster is not affected by the MAC conversion; when there is virtual machine with frequent MAC address conversion, the OVN cluster is stable. That is, through the above scheme, the virtual machine flow forwarding of different upper sending requirements can be ensured to be normal, and the OVN cluster stability is not affected, in addition, the local storage MAC address scheme is designed, which ensures that the network packet can still be forwarded at high speed without sending the southbound database, reduces the frequent sending, and the specific scheme of flow table suppression isolation is designed, which ensures that the original flow table process is not affected, and the compatibility is strong.

[0125] Referring to Figure 3As shown, the embodiments of the present application also disclose periodic cleaning and state updating logic for the port-up state, which is executed by the main loop pinctrl_run thread of the distributed controller, and the core purpose is to dynamically adjust the port-up state according to a time period, to ensure the timeliness of the suppression strategy and resource release, and to ensure that normal services are not affected while abnormal traffic is suppressed. Specifically, the periodic cleaning and state updating logic comprises the following steps:

[0126] Step S21: Traversing the port-up state list to calculate the cumulative record time of each virtual machine port based on the start timestamp of the current statistical period of each virtual machine port.

[0127] In the embodiments, the port-up state list is traversed to check the states of all monitored virtual machine ports, and the cumulative record time of each virtual machine port is calculated based on the start timestamp of the current statistical period of each virtual machine port.

[0128] In the specific embodiments, the cumulative record time of each virtual machine port is calculated based on the start timestamp of the current statistical period of each virtual machine port, which comprises: obtaining the start timestamp of the current statistical period of each virtual machine port; and determining the cumulative record time based on the difference between the current timestamp and the start timestamp. That is, the cumulative record time of each virtual machine port is calculated by subtracting the start timestamp of the current statistical period from the current timestamp.

[0129] Step S22: Determining whether the cumulative record time of any virtual machine port exceeds a target rolling period.

[0130] In the embodiments, the cumulative record time of any virtual machine port is compared with the target rolling period to determine whether the cumulative record time exceeds the target rolling period.

[0131] Step S23: If yes, performing a target cleaning operation on the port-up state information corresponding to the virtual machine port.

[0132] In the embodiments, if the cumulative record time exceeds the target rolling period, the target cleaning operation is performed on the port-up state information corresponding to the virtual machine port.

[0133] Step S24: If no, returning to the step of traversing the port-up state list.

[0134] In the embodiments, if the cumulative record time does not exceed the target rolling period, the step of traversing the port-up state list is returned to.

[0135] Firstly, it should be pointed out that the target rolling period includes a first rolling period and a second rolling period, wherein the first rolling period is a single preset statistical period, i.e., the aforementioned suppression period fdb_put_limit_period, denoted as p1, and the second rolling period is a target multiple of the preset statistical period, i.e., fdb_put_limit_periodxfdb_put_block_times, denoted as p2. It can be understood that the present application performs different cleaning or updating operations when the cumulative record time of the different port sending states exceeds the target rolling period, such as shown in the following table. Figure 2

[0136] In a specific embodiment, when the current port sending state of any virtual machine port is the allowed sending state, the local storage state or the suppressed sending state, the target rolling period is the first rolling period, and the first rolling period is a single preset statistical period. Correspondingly, the target cleaning operation is performed on the sending state information corresponding to any virtual machine port, including: if any virtual machine port is in the allowed sending state within the first rolling period, the sending state information of any virtual machine port is removed from the port sending state list; if any virtual machine port is in the local storage state within the first rolling period, the local cache flow table corresponding to any virtual machine port is removed, and the sending state information of any virtual machine port is removed from the port sending state list; and if any virtual machine port is in the suppressed sending state within the first rolling period, the local cache flow table and the suppressed sending flow table corresponding to any virtual machine port are removed, and it is determined whether the current state is updated to the isolation state. If not, the current port sending state of any virtual machine port is updated to the allowed sending state in the port sending state list.

[0137] Specifically, if a certain virtual machine port is in the allowed sending state at the beginning of the first rolling period, and is still in the allowed sending state after the cumulative record time exceeds the first rolling period, it indicates that the virtual machine port is normal, and the monitoring is directly removed without the need to continue tracking, thereby releasing resources. In this case, the sending state information of the virtual machine port is directly removed from the port sending state list.

[0138] If a certain virtual machine port is in the local storage state at the beginning of the first rolling period, and is still in the local storage state after the cumulative record time exceeds the first rolling period, the local cache flow table corresponding to any virtual machine port is removed, and the sending state information of any virtual machine port is removed from the port sending state list. After that, the virtual machine port returns to the initialization state, and the MAC learning quantity is re-counted in the next rolling period.

[0139] ​If a virtual machine port is in the suppressed state at the beginning of the first rolling period, and still in the suppressed state after the cumulative record time exceeds the first rolling period, the local cache flow table and the suppressed flow table corresponding to any virtual machine port are removed, the blocked_times in the port state information is updated to blocked_times+1, and it is determined whether the blocked_times reaches the fdb_put_block_times. If the blocked_times reaches the fdb_put_block_times, the port state is updated to the isolated state, and the isolated flow table is issued. If the blocked_times does not reach the fdb_put_block_times, the current port state of any virtual machine port in the port state list is updated to the allowed state, and the monitor_time is reset to 0. That is, the cumulative number of times of continuously entering the suppressed state is used to determine whether to upgrade to a more stringent isolation strategy. If the threshold is not reached, the state is reset to avoid excessive suppression of normal traffic.

[0140] In another specific embodiment, when the current port state of any virtual machine port is in the isolated state, the target rolling period is the second rolling period, and the second rolling period is a target multiple of the preset statistical period. Correspondingly, the target cleaning operation is performed on the state information of any virtual machine port, including: if any virtual machine port is in the isolated state in the second rolling period, the isolated flow table corresponding to any virtual machine port is removed, and the state information of any virtual machine port in the port state list is removed.

[0141] If a virtual machine port is in the isolated state at the beginning of the second rolling period, and still in the isolated state after the cumulative record time exceeds the first rolling period, the isolated flow table corresponding to the virtual machine port is removed, and the state information of the virtual machine port in the port state list is removed. It can be understood that the isolated state is the final suppression state, and the isolation needs to be released after timeout to avoid long-term blocking of possibly recovered normal traffic.

[0142] Referring to Figure 4 As shown in the figure, the embodiment of the application discloses a virtual machine MAC address learning device applied to a distributed controller, the distributed controller is deployed on a host, and at least one virtual machine runs on the host. The device comprises:

[0143] An information determination module 11 is configured to acquire a source MAC address reported by a virtual switch and determine a target virtual machine port bound to the source MAC address. The virtual machine on the host sends a network packet through the target virtual machine port, and the network packet carries the source MAC address.

[0144] The updating module 12 is configured to obtain current upsend state information of the target virtual machine port from a preset port upsend state list, and update the current upsend state information based on the source MAC address to obtain updated upsend state information.

[0145] The learning module 13 is configured to determine whether to learn the source MAC address and whether to allow the source MAC address to be upsent to the southbound database based on the updated upsend state.

[0146] The distributed controller in the present application is deployed on a host, and at least one virtual machine runs on the host. When the virtual machine running on the host needs to communicate, it sends a network packet through its target virtual machine port, and the network packet carries a source MAC address. Moreover, the network packet sent by the virtual machine passes through a virtual switch. If the source MAC address has not been learned, the virtual switch will report the source MAC address to the distributed controller. After obtaining the reported source MAC address, the distributed controller will first determine the target virtual machine port bound to the source MAC address, and obtain the current upsend state information of the target virtual machine port from a preset port upsend state list. It can be understood that the port upsend state list is used to record the upsend state information of each virtual machine port about the MAC address, that is, the present application establishes a port upsend state list, and records each virtual machine port in the list independently to ensure that the MAC address upsend behavior of each virtual machine port is independently and accurately counted, and different virtual machine ports do not affect each other. Further, the present application updates the current upsend state information based on the source MAC address to obtain updated upsend state information, so as to determine whether to learn the source MAC address and whether to allow the source MAC address to be upsent to the southbound database based on the updated upsend state. That is, by maintaining the upsend state information of each virtual machine port, compared with the traditional scheme in which the distributed controller directly upsend the source MAC address to the southbound database, the present application needs to determine whether the distributed controller can currently learn the source MAC address based on the upsend state information, and determine whether to upsend the source MAC address to the southbound database, so as to reduce the pressure on the OVN cluster by this limiting method, avoid database overload and cluster collapse caused by a large number of invalid MAC addresses, and ensure the stability of the OVN cluster.

[0147] Since the embodiments of the device part correspond to the above-mentioned embodiments, the embodiments of the device part are described with reference to the embodiments of the above-mentioned method part, and will not be described here.

[0148] Figure 5A structural schematic diagram of an electronic device is provided in the embodiments of the present application. Specifically, it can include at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is configured to store a computer program, which is loaded and executed by the processor 21 to implement the related steps in the virtual machine MAC address learning method performed by the electronic device disclosed in any of the preceding embodiments.

[0149] In the embodiments, the power supply 23 is configured to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 is capable of creating a data transmission channel between the electronic device 20 and external devices, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the present application, which is not limited specifically herein; the input / output interface 25 is configured to obtain external input data or output data to the outside world, and the specific interface type can be selected according to the specific application needs, which is not limited specifically herein.

[0150] The processor 21 can include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one of a hardware form of a DSP (Digital Signal Processing), an FPGA (Field-Programmable Gate Array), and a PLA (Programmable Logic Array). The processor 21 can also include a main processor and a coprocessor. The main processor is a processor for processing data in a wake-up state, also known as a CPU (Central Processing Unit). The coprocessor is a low-power processor for processing data in a standby state. In some embodiments, the processor 21 can be integrated with a GPU (Graphics Processing Unit) that is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 can also include an AI (Artificial Intelligence) processor for processing machine learning-related computing operations.

[0151] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, or an optical disk, etc. The resources stored thereon include an operating system 221, a computer program 222, and data 223, etc. The storage mode can be temporary storage or permanent storage.

[0152] The operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, so as to realize the operation and processing of the processor 21 on the mass data 223 in the memory 22, and can be Windows, Unix, Linux, etc. The computer program 222 can further include a computer program capable of completing other specific work in addition to the computer program capable of completing the virtual machine MAC address learning method executed by the electronic device 20 disclosed in any of the foregoing embodiments. The data 223 can include data transmitted by an external device received by the electronic device, and can also include data collected by the self input / output interface 25, etc.

[0153] Further, the embodiment of the present application further discloses a computer readable storage medium, the storage medium stores a computer program, and the computer program is loaded and executed by a processor to realize the steps of the virtual machine MAC address learning method disclosed in any of the foregoing embodiments.

[0154] The embodiment of the present application further discloses a computer program product, including computer programs / instructions, which are executed by a processor to realize the steps of the virtual machine MAC address learning method disclosed in any of the foregoing embodiments.

[0155] Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the related parts can be referred to the method part.

[0156] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or combination of the two. In order to clearly show the interchangeability of hardware and software, the components and steps of each example have been described in the above description. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0157] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in Random Access Memory (RAM), flash memory, Read-Only Memory (ROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, hard disk can be used as a storage medium.

[0158] Finally, it should be noted that the terms "first" and "second", and the like, are used herein only to distinguish one entity or action from another, but do not necessarily require or imply any actual such relationship or order between such entities or actions. Also, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element preceded by "comprises... a" does not, without more limitations, foreclose the existence of additional identical elements in the process, method, article, or apparatus that includes the recited element.

[0159] The above describes in detail a MAC address learning method, device, equipment, medium and product provided by the present application. The principles and implementation manners of the present application are described by using specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manner and application range can be changed. In summary, the content of the specification should not be understood as a limitation of the present application.

Claims

1. A method for learning a virtual machine MAC address, characterized in that: Applied to a distributed controller, the distributed controller is deployed on a host machine, and at least one virtual machine is running on the host machine, the method includes: Obtaining a source MAC address reported by the virtual switch and determining a target virtual machine port bound to the source MAC address; wherein the virtual machine on the host machine sends a network message through the target virtual machine port, and the network message carries the source MAC address; Obtaining current upload status information of the target virtual machine port from a preset port upload status list, and updating the current upload status information based on the source MAC address to obtain updated upload status information; wherein the port upload status list is used to record the upload status information of each virtual machine port regarding the MAC address; Determine whether to learn the source MAC address and whether to allow the source MAC address to be uploaded to the southbound database based on the updated upload status; The port upload status list records the upload status information including the port identifier, the start timestamp of the current statistical period, the number of learned MAC addresses in the current statistical period, the last learned MAC address, the current port upload status, and the cumulative number of consecutive entries into the suppression upload status.

2. The virtual machine MAC address learning method according to claim 1, characterized in that: Before updating the current status information sent up based on the source MAC address to obtain updated status information sent up, the method further includes: Obtain the last learned MAC address in the currently uploaded status information; Determine whether the last learned MAC address is consistent with the source MAC address; If they are consistent, prohibiting the step of updating the current uploaded state information based on the source MAC address to obtain updated uploaded state information; If they are inconsistent, the step of updating the current uploaded state information based on the source MAC address to obtain updated uploaded state information is allowed to be executed.

3. The virtual machine MAC address learning method according to claim 1, characterized in that: The process of updating the current uploading status information based on the source MAC address to obtain updated uploading status information includes: performing an increment operation on the number of learned MAC addresses to obtain an updated number of MAC addresses, and determining a preset threshold value corresponding to the current port upload state, so as to update the current port upload state according to a comparison result of the updated number of MAC addresses and the preset threshold value to obtain an updated port upload state; The last learned MAC address is updated as the source MAC address.

4. The virtual machine MAC address learning method according to claim 3, characterized in that: The current port uploading state and the updated port uploading state are both any one of the states of allowed uploading state, local storage state, suppressed uploading state and isolated state; wherein, the allowed uploading state indicates that the distributed controller is allowed to learn MAC addresses and is allowed to upload MAC addresses to the southbound database; the local storage state indicates that the distributed controller is allowed to learn MAC addresses and is not allowed to upload MAC addresses to the southbound database; the suppressed uploading state indicates that the distributed controller is not allowed to learn MAC addresses and forwards network packets according to the default flow table rules; the isolated state indicates that the distributed controller is not allowed to learn MAC addresses and discards network packets corresponding to MAC addresses that have not been learned.

5. The virtual machine MAC address learning method according to claim 4, characterized in that: The determining of a preset threshold corresponding to the current port sending state includes: If the current port sending state is the sending state allowed, the corresponding preset threshold is the first threshold; wherein the first threshold is the maximum number of MAC addresses allowed to be learned within the preset statistical period; Correspondingly, updating the current port sending state according to the comparison result of the updated MAC address number with the preset threshold to obtain the updated port sending state includes: If the number of the updated MAC addresses is greater than the first threshold, updating the current port upload state from the upload-allowed state to the local storage state; If the updated MAC address quantity is not greater than the first threshold, the current port sending state is kept unchanged as the sending-allowed state.

6. The virtual machine MAC address learning method according to claim 4, characterized in that: The determining of a preset threshold corresponding to the current port sending state includes: If the current port uploading state is the local storage state, the corresponding preset threshold is the second threshold; wherein the second threshold is the product of the maximum number of MAC addresses allowed to be learned within the preset statistical period and the target multiple; Correspondingly, updating the current port sending state according to the comparison result of the updated MAC address number with the preset threshold to obtain the updated port sending state includes: If the number of the updated MAC addresses is greater than the second threshold, updating the current port sending state from the local storage state to the suppression sending state; If the updated MAC address quantity is not greater than the second threshold, the current port sending state is kept unchanged as the local storage state.

7. The virtual machine MAC address learning method according to claim 6, characterized in that: The determining of a preset threshold corresponding to the current port sending state includes: If the current port sending state is the suppression sending state, the corresponding preset threshold is the third threshold; wherein the third threshold is the target limit number of consecutive entering the suppression sending state; Correspondingly, updating the current port sending state according to the comparison result of the updated MAC address number with the preset threshold to obtain the updated port sending state includes: If the updated number of MAC addresses is greater than the second threshold, adding one to the cumulative number to obtain the updated cumulative number; Determining whether the cumulative number of updates is greater than the third threshold; If yes, then updating the current port sending state from the suppression sending state to the isolation state; If not, the current port sending state is kept as the sending suppression state.

8. The virtual machine MAC address learning method according to claim 4, characterized in that: The process of obtaining the current sending status information of the target virtual machine port from the preset port sending status list further includes: If the port upload status list does not record the upload status information of the target virtual machine port, then add the target upload status information of the target virtual machine port to the port upload status list; wherein, in the target upload status information, the current port upload status is initialized to the upload-allowed status, and the start timestamp of the current statistical period is initialized to the current timestamp; If the port upload status list records the current upload status information of the target virtual machine port, and the start timestamp of the current statistical period in the current upload status information is zero, the start timestamp is updated to the current timestamp.

9. The virtual machine MAC address learning method according to claim 4, characterized in that: The determining, based on the updated upload status, whether to learn the source MAC address and whether to allow the source MAC address to be uploaded to the southbound database includes: If the updated upload state is the upload allowed state, determining to learn the source MAC address and allowing the learned source MAC address to be uploaded to the southbound database; If the updated upload state is the local storage state, determining to learn the source MAC address and not allowing the learned source MAC address to be uploaded to the southbound database; If the updated upload state is the upload suppression state or the isolation state, the source MAC address is not allowed to be learned, and the source MAC address is not allowed to be uploaded to the southbound database.

10. The virtual machine MAC address learning method according to claim 4, characterized in that: Also includes: If the updated upload state is an upload-allowed state, obtaining a target flow table sent by the southbound database, so as to forward the network message based on the target flow table; If the updated upload state is a local storage state, the source MAC address is added to a preset MAC list to be configured locally, and a local cache flow table of the target virtual machine port is generated to forward the network message based on the local cache flow table; If the updated sending state is the suppression sending state, the suppression sending flow table of the target virtual machine port is issued so as to forward the network message based on the suppression sending flow table; wherein the suppression sending flow table is used to control the distributed controller not to learn new MAC addresses and forward the network message based on the existing flow table; the existing flow table is any one of the target flow table, the local cache flow table or the default flow table, the target flow table and the local cache flow table are used to forward network messages with known MAC addresses, and the default flow table is used to forward network messages with unknown MAC addresses; If the updated upstream status is an isolated status, the isolation flow table of the target virtual machine port is sent down to forward the network message based on the suppression upstream flow table; wherein, the isolation flow table is used to control the distributed controller not to learn new MAC addresses, discard network messages with unknown MAC addresses, and forward network messages with known MAC addresses based on the target flow table and the local cache flow table.

11. The virtual machine MAC address learning method according to claim 10, characterized in that: The priority of the isolation flow table is higher than the priority of the suppression flow table, and the priority of the suppression flow table is higher than the priority of the target flow table and the local cache flow table; the priority of the target flow table is the same as the priority of the local cache flow table.

12. The virtual machine MAC address learning method according to claim 10, characterized in that: Also includes: Traversing the port status list to calculate the cumulative recording time of each virtual machine port based on the start timestamp of the current statistical period of each virtual machine port; Determine whether the cumulative recording time of any virtual machine port exceeds the target rolling period; If it exceeds, performing a target cleanup operation on the uploaded status information corresponding to any virtual machine port; If not, jump back to the step of traversing the port status list.

13. The virtual machine MAC address learning method according to claim 12, characterized in that: The calculating of the accumulated recording time of each virtual machine port based on the start timestamp of the current statistical period of each virtual machine port includes: Get the start timestamp of the current statistical period for each virtual machine port; The accumulated recording time is determined based on the difference between the current timestamp and the start timestamp.

14. The virtual machine MAC address learning method according to claim 12, characterized in that: When the current port sending state of any virtual machine port is the sending-allowed state, the local storage state, or the sending-suppressed state, the target rolling period is the first rolling period, and the first rolling period is a single preset statistical period; Accordingly, performing a target cleanup operation on the uploaded status information corresponding to any virtual machine port includes: If any of the virtual machine ports is in the allowed upload state within the first rolling period, removing the upload state information of any of the virtual machine ports from the port upload state list; If any of the virtual machine ports is in the local storage state within the first rolling period, removing the local cache flow table corresponding to the any of the virtual machine ports, and removing the uploading state information of the any of the virtual machine ports from the port uploading state list; If any of the virtual machine ports is in the suppressed upload state within the first rolling period, the local cache flow table and the suppressed upload flow table corresponding to the any virtual machine port are removed, and it is determined whether the current state is updated to the isolated state. If not, the current port upload state of the any virtual machine port is updated to the allowed upload state in the port upload state list.

15. The virtual machine MAC address learning method according to claim 12, characterized in that: When the current port sending state of any virtual machine port is an isolated state, the target rolling period is a second rolling period, and the second rolling period is a target multiple of the preset statistical period; Accordingly, performing a target cleanup operation on the uploaded status information corresponding to any virtual machine port includes: If any of the virtual machine ports is in an isolated state within the second rolling period, the isolation flow table corresponding to the any of the virtual machine ports is removed, and the sending state information of the any of the virtual machine ports is removed from the port sending state list.

16. A virtual machine MAC address learning device, characterized in that: Applied to a distributed controller, the distributed controller is deployed on a host machine, and at least one virtual machine runs on the host machine, the device includes: An information determination module is configured to obtain a source MAC address reported by a virtual switch and determine a target virtual machine port bound to the source MAC address; wherein the virtual machine on the host machine sends a network message through the target virtual machine port, and the network message carries the source MAC address; an updating module, configured to obtain current upload status information of the target virtual machine port from a preset port upload status list, and update the current upload status information based on the source MAC address to obtain updated upload status information; wherein the port upload status list is used to record the upload status information of the MAC address of each virtual machine port; A learning module, configured to determine whether to learn the source MAC address and whether to allow the source MAC address to be uploaded to the southbound database based on the updated upload status; The port upload status list records the upload status information including the port identifier, the start timestamp of the current statistical period, the number of learned MAC addresses in the current statistical period, the last learned MAC address, the current port upload status, and the cumulative number of consecutive entries into the suppression upload status.

17. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the steps of the virtual machine MAC address learning method according to any one of claims 1 to 15.

18. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the steps of the virtual machine MAC address learning method according to any one of claims 1 to 15 are implemented.

19. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the virtual machine MAC address learning method according to any one of claims 1 to 15 are implemented.

Citation Information

Patent Citations

  • Method and system for processing virtual network messages based on virtual machine

    CN101605084A

  • Virtual machine management method and device and network equipment

    CN102025535A