blob: 2f6d1ab10d9bc6a8fd56f4916c5ee4293b9e329c [file] [log] [blame]
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +01001#!/bin/bash
2#
3# Licensed under the Apache License, Version 2.0 (the "License"); you may
4# not use this file except in compliance with the License. You may obtain
5# a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12# License for the specific language governing permissions and limitations
13# under the License.
14#
15
16# Global Sources
17# --------------
18
19# There are some ovs functions OVN depends on that must be sourced from
20# the ovs neutron plugins.
21source ${TOP_DIR}/lib/neutron_plugins/ovs_base
22source ${TOP_DIR}/lib/neutron_plugins/openvswitch_agent
23
24# Load devstack ovs base functions
25source $NEUTRON_DIR/devstack/lib/ovs
26
27
28# Defaults
29# --------
30
Slawek Kaplonski7ba26f52020-09-17 11:13:52 +020031Q_BUILD_OVS_FROM_GIT=$(trueorfalse True Q_BUILD_OVS_FROM_GIT)
32
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010033# Set variables for building OVN from source
34OVN_REPO=${OVN_REPO:-https://github.com/ovn-org/ovn.git}
35OVN_REPO_NAME=$(basename ${OVN_REPO} | cut -f1 -d'.')
36OVN_REPO_NAME=${OVN_REPO_NAME:-ovn}
37OVN_BRANCH=${OVN_BRANCH:-v20.06.1}
38# The commit removing OVN bits from the OVS tree, it is the commit that is not
39# present in OVN tree and is used to distinguish if OVN is part of OVS or not.
40# https://github.com/openvswitch/ovs/commit/05bf1dbb98b0635a51f75e268ef8aed27601401d
41OVN_SPLIT_HASH=05bf1dbb98b0635a51f75e268ef8aed27601401d
42
43if is_service_enabled tls-proxy; then
44 OVN_PROTO=ssl
45else
46 OVN_PROTO=tcp
47fi
48
49# How to connect to ovsdb-server hosting the OVN SB database.
50OVN_SB_REMOTE=${OVN_SB_REMOTE:-$OVN_PROTO:$SERVICE_HOST:6642}
51
52# How to connect to ovsdb-server hosting the OVN NB database
53OVN_NB_REMOTE=${OVN_NB_REMOTE:-$OVN_PROTO:$SERVICE_HOST:6641}
54
55# ml2/config for neutron_sync_mode
56OVN_NEUTRON_SYNC_MODE=${OVN_NEUTRON_SYNC_MODE:-log}
57
58# Configured DNS servers to be used with internal_dns extension, only
59# if the subnet DNS is not configured.
60OVN_DNS_SERVERS=${OVN_DNS_SERVERS:-8.8.8.8}
61
62# The type of OVN L3 Scheduler to use. The OVN L3 Scheduler determines the
63# hypervisor/chassis where a routers gateway should be hosted in OVN. The
64# default OVN L3 scheduler is leastloaded
65OVN_L3_SCHEDULER=${OVN_L3_SCHEDULER:-leastloaded}
66
67# A UUID to uniquely identify this system. If one is not specified, a random
68# one will be generated. A randomly generated UUID will be saved in a file
Slawek Kaplonski1ed276c2021-03-11 13:10:28 +010069# $OVS_SYSCONFDIR/system-id.conf (typically /etc/openvswitch/system-id.conf)
70# so that the same one will be re-used if you re-run DevStack or restart
71# Open vSwitch service.
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010072OVN_UUID=${OVN_UUID:-}
73
74# Whether or not to build the openvswitch kernel module from ovs. This is required
75# unless the distro kernel includes ovs+conntrack support.
76OVN_BUILD_MODULES=$(trueorfalse False OVN_BUILD_MODULES)
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +000077OVN_BUILD_FROM_SOURCE=$(trueorfalse False OVN_BUILD_FROM_SOURCE)
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +010078
79# Whether or not to install the ovs python module from ovs source. This can be
80# used to test and validate new ovs python features. This should only be used
81# for development purposes since the ovs python version is controlled by OpenStack
82# requirements.
83OVN_INSTALL_OVS_PYTHON_MODULE=$(trueorfalse False OVN_INSTALL_OVS_PYTHON_MODULE)
84
85# GENEVE overlay protocol overhead. Defaults to 38 bytes plus the IP version
86# overhead (20 bytes for IPv4 (default) or 40 bytes for IPv6) which is determined
87# based on the ML2 overlay_ip_version option. The ML2 framework will use this to
88# configure the MTU DHCP option.
89OVN_GENEVE_OVERHEAD=${OVN_GENEVE_OVERHEAD:-38}
90
91# The log level of the OVN databases (north and south)
92OVN_DBS_LOG_LEVEL=${OVN_DBS_LOG_LEVEL:-info}
93
94OVN_META_CONF=$NEUTRON_CONF_DIR/neutron_ovn_metadata_agent.ini
95OVN_META_DATA_HOST=${OVN_META_DATA_HOST:-$(ipv6_unquote $SERVICE_HOST)}
96
Lucas Alvares Gomes6ecfe672020-09-23 11:54:19 +010097export OVSDB_SERVER_LOCAL_HOST=$SERVICE_LOCAL_HOST
98if [[ "$SERVICE_IP_VERSION" == 6 ]]; then
99 OVSDB_SERVER_LOCAL_HOST=[$OVSDB_SERVER_LOCAL_HOST]
100fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100101
102OVN_IGMP_SNOOPING_ENABLE=$(trueorfalse False OVN_IGMP_SNOOPING_ENABLE)
103
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000104OVS_PREFIX=
105if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
106 OVS_PREFIX=/usr/local
107fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100108OVS_SBINDIR=$OVS_PREFIX/sbin
109OVS_BINDIR=$OVS_PREFIX/bin
110OVS_RUNDIR=$OVS_PREFIX/var/run/openvswitch
111OVS_SHAREDIR=$OVS_PREFIX/share/openvswitch
112OVS_SCRIPTDIR=$OVS_SHAREDIR/scripts
113OVS_DATADIR=$DATA_DIR/ovs
Rodolfo Alonso Hernandez30819e62021-03-22 07:14:50 +0000114OVS_SYSCONFDIR=${OVS_SYSCONFDIR:-$OVS_PREFIX/etc/openvswitch}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100115
116OVN_DATADIR=$DATA_DIR/ovn
117OVN_SHAREDIR=$OVS_PREFIX/share/ovn
118OVN_SCRIPTDIR=$OVN_SHAREDIR/scripts
119OVN_RUNDIR=$OVS_PREFIX/var/run/ovn
120
121NEUTRON_OVN_BIN_DIR=$(get_python_exec_prefix)
122NEUTRON_OVN_METADATA_BINARY="neutron-ovn-metadata-agent"
123
124STACK_GROUP="$( id --group --name "$STACK_USER" )"
125
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000126OVN_NORTHD_SERVICE=ovn-northd.service
127if is_ubuntu; then
128 # The ovn-central.service file on Ubuntu is responsible for starting
129 # ovn-northd and the OVN DBs (on CentOS this is done by ovn-northd.service)
130 OVN_NORTHD_SERVICE=ovn-central.service
131fi
132OVSDB_SERVER_SERVICE=ovsdb-server.service
133OVS_VSWITCHD_SERVICE=ovs-vswitchd.service
134OVN_CONTROLLER_SERVICE=ovn-controller.service
135OVN_CONTROLLER_VTEP_SERVICE=ovn-controller-vtep.service
136if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
137 OVSDB_SERVER_SERVICE=devstack@ovsdb-server.service
138 OVS_VSWITCHD_SERVICE=devstack@ovs-vswitchd.service
139 OVN_NORTHD_SERVICE=devstack@ovn-northd.service
140 OVN_CONTROLLER_SERVICE=devstack@ovn-controller.service
141 OVN_CONTROLLER_VTEP_SERVICE=devstack@ovn-controller-vtep.service
142fi
143
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100144# Defaults Overwrite
145# ------------------
146
147Q_ML2_PLUGIN_MECHANISM_DRIVERS=${Q_ML2_PLUGIN_MECHANISM_DRIVERS:-ovn,logger}
148Q_ML2_PLUGIN_TYPE_DRIVERS=${Q_ML2_PLUGIN_TYPE_DRIVERS:-local,flat,vlan,geneve}
149Q_ML2_TENANT_NETWORK_TYPE=${Q_ML2_TENANT_NETWORK_TYPE:-"geneve"}
150Q_ML2_PLUGIN_GENEVE_TYPE_OPTIONS=${Q_ML2_PLUGIN_GENEVE_TYPE_OPTIONS:-"vni_ranges=1:65536"}
Lucas Alvares Gomese7625fc2020-08-26 09:46:35 +0100151Q_ML2_PLUGIN_EXT_DRIVERS=${Q_ML2_PLUGIN_EXT_DRIVERS:-port_security,qos}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100152# this one allows empty:
153ML2_L3_PLUGIN=${ML2_L3_PLUGIN-"ovn-router"}
154
Flavio Fernandesa2273cc2021-02-06 16:23:36 -0500155Q_LOG_DRIVER_RATE_LIMIT=${Q_LOG_DRIVER_RATE_LIMIT:-100}
156Q_LOG_DRIVER_BURST_LIMIT=${Q_LOG_DRIVER_BURST_LIMIT:-25}
157Q_LOG_DRIVER_LOG_BASE=${Q_LOG_DRIVER_LOG_BASE:-acl_log_meter}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100158
159# Utility Functions
160# -----------------
161
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000162function wait_for_sock_file {
163 local count=0
164 while [ ! -S $1 ]; do
165 sleep 1
166 count=$((count+1))
167 if [ "$count" -gt 5 ]; then
168 die $LINENO "Socket $1 not found"
169 fi
170 done
171}
172
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100173function use_new_ovn_repository {
174 if [ -z "$is_new_ovn" ]; then
175 local ovs_repo_dir=$DEST/$OVS_REPO_NAME
176 if [ ! -d $ovs_repo_dir ]; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000177 git_timed clone $OVS_REPO $ovs_repo_dir
178 pushd $ovs_repo_dir
179 git checkout $OVS_BRANCH
180 popd
181 else
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100182 clone_repository $OVS_REPO $ovs_repo_dir $OVS_BRANCH
183 fi
184 # Check the split commit exists in the current branch
185 pushd $ovs_repo_dir
186 git log $OVS_BRANCH --pretty=format:"%H" | grep -q $OVN_SPLIT_HASH
187 is_new_ovn=$?
188 popd
189 fi
190 return $is_new_ovn
191}
192
193# NOTE(rtheis): Function copied from DevStack _neutron_ovs_base_setup_bridge
194# and _neutron_ovs_base_add_bridge with the call to neutron-ovs-cleanup
195# removed. The call is not relevant for OVN, as it is specific to the use
196# of Neutron's OVS agent and hangs when running stack.sh because
197# neutron-ovs-cleanup uses the OVSDB native interface.
198function ovn_base_setup_bridge {
199 local bridge=$1
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000200 local addbr_cmd="sudo ovs-vsctl --no-wait -- --may-exist add-br $bridge -- set bridge $bridge protocols=OpenFlow13,OpenFlow15"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100201
202 if [ "$OVS_DATAPATH_TYPE" != "system" ] ; then
203 addbr_cmd="$addbr_cmd -- set Bridge $bridge datapath_type=${OVS_DATAPATH_TYPE}"
204 fi
205
206 $addbr_cmd
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000207 sudo ovs-vsctl --no-wait br-set-external-id $bridge bridge-id $bridge
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100208}
209
210function _start_process {
211 $SYSTEMCTL daemon-reload
212 $SYSTEMCTL enable $1
213 $SYSTEMCTL restart $1
214}
215
216function _run_process {
217 local service=$1
218 local cmd="$2"
219 local stop_cmd="$3"
220 local group=$4
221 local user=${5:-$STACK_USER}
222
223 local systemd_service="devstack@$service.service"
224 local unit_file="$SYSTEMD_DIR/$systemd_service"
225 local environment="OVN_RUNDIR=$OVS_RUNDIR OVN_DBDIR=$OVN_DATADIR OVN_LOGDIR=$LOGDIR OVS_RUNDIR=$OVS_RUNDIR OVS_DBDIR=$OVS_DATADIR OVS_LOGDIR=$LOGDIR"
226
227 echo "Starting $service executed command": $cmd
228
229 write_user_unit_file $systemd_service "$cmd" "$group" "$user"
230 iniset -sudo $unit_file "Service" "Type" "forking"
231 iniset -sudo $unit_file "Service" "RemainAfterExit" "yes"
232 iniset -sudo $unit_file "Service" "KillMode" "mixed"
233 iniset -sudo $unit_file "Service" "LimitNOFILE" "65536"
234 iniset -sudo $unit_file "Service" "Environment" "$environment"
235 if [ -n "$stop_cmd" ]; then
236 iniset -sudo $unit_file "Service" "ExecStop" "$stop_cmd"
237 fi
238
239 _start_process $systemd_service
240
241 local testcmd="test -e $OVS_RUNDIR/$service.pid"
242 test_with_retry "$testcmd" "$service did not start" $SERVICE_TIMEOUT 1
243 sudo ovs-appctl -t $service vlog/set console:off syslog:info file:info
244}
245
246function clone_repository {
247 local repo=$1
248 local dir=$2
249 local branch=$3
250 # Set ERROR_ON_CLONE to false to avoid the need of having the
251 # repositories like OVN and OVS in the required_projects of the job
252 # definition.
253 ERROR_ON_CLONE=false git_clone $repo $dir $branch
254}
255
256function get_ext_gw_interface {
257 # Get ext_gw_interface depending on value of Q_USE_PUBLIC_VETH
258 # This function is copied directly from the devstack neutron-legacy script
259 if [[ "$Q_USE_PUBLIC_VETH" == "True" ]]; then
260 echo $Q_PUBLIC_VETH_EX
261 else
262 # Disable in-band as we are going to use local port
263 # to communicate with VMs
264 sudo ovs-vsctl set Bridge $PUBLIC_BRIDGE \
265 other_config:disable-in-band=true
266 echo $PUBLIC_BRIDGE
267 fi
268}
269
270function create_public_bridge {
271 # Create the public bridge that OVN will use
272 # This logic is based on the devstack neutron-legacy _neutron_configure_router_v4 and _v6
273 local ext_gw_ifc
274 ext_gw_ifc=$(get_ext_gw_interface)
275
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000276 sudo ovs-vsctl --may-exist add-br $ext_gw_ifc -- set bridge $ext_gw_ifc protocols=OpenFlow13,OpenFlow15
277 sudo ovs-vsctl set open . external-ids:ovn-bridge-mappings=$PHYSICAL_NETWORK:$ext_gw_ifc
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100278 if [ -n "$FLOATING_RANGE" ]; then
279 local cidr_len=${FLOATING_RANGE#*/}
Brian Haleyaf79a932021-03-15 12:20:42 -0400280 sudo ip addr replace $PUBLIC_NETWORK_GATEWAY/$cidr_len dev $ext_gw_ifc
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100281 fi
282
283 # Ensure IPv6 RAs are accepted on the interface with the default route.
284 # This is needed for neutron-based devstack clouds to work in
285 # IPv6-only clouds in the gate. Please do not remove this without
286 # talking to folks in Infra. This fix is based on a devstack fix for
287 # neutron L3 agent: https://review.openstack.org/#/c/359490/.
288 default_route_dev=$(ip route | grep ^default | awk '{print $5}')
289 sudo sysctl -w net.ipv6.conf.$default_route_dev.accept_ra=2
290
291 sudo sysctl -w net.ipv6.conf.all.forwarding=1
292 if [ -n "$IPV6_PUBLIC_RANGE" ]; then
293 local ipv6_cidr_len=${IPV6_PUBLIC_RANGE#*/}
Brian Haleyaf79a932021-03-15 12:20:42 -0400294 sudo ip -6 addr replace $IPV6_PUBLIC_NETWORK_GATEWAY/$ipv6_cidr_len dev $ext_gw_ifc
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100295 fi
296
297 sudo ip link set $ext_gw_ifc up
298}
299
300function _disable_libvirt_apparmor {
301 if ! sudo aa-status --enabled ; then
302 return 0
303 fi
304 # NOTE(arosen): This is used as a work around to allow newer versions
305 # of libvirt to work with ovs configured ports. See LP#1466631.
306 # requires the apparmor-utils
307 install_package apparmor-utils
308 # disables apparmor for libvirtd
309 sudo aa-complain /etc/apparmor.d/usr.sbin.libvirtd
310}
311
312
313# OVN compilation functions
314# -------------------------
315
316
317# compile_ovn() - Compile OVN from source and load needed modules
318# Accepts three parameters:
319# - first optional is False by default and means that
320# modules are built and installed.
321# - second optional parameter defines prefix for
322# ovn compilation
323# - third optional parameter defines localstatedir for
324# ovn single machine runtime
325function compile_ovn {
326 local build_modules=${1:-False}
327 local prefix=$2
328 local localstatedir=$3
329
330 if [ -n "$prefix" ]; then
331 prefix="--prefix=$prefix"
332 fi
333
334 if [ -n "$localstatedir" ]; then
335 localstatedir="--localstatedir=$localstatedir"
336 fi
337
338 clone_repository $OVN_REPO $DEST/$OVN_REPO_NAME $OVN_BRANCH
339 pushd $DEST/$OVN_REPO_NAME
340
341 if [ ! -f configure ] ; then
342 ./boot.sh
343 fi
344
345 if [ ! -f config.status ] || [ configure -nt config.status ] ; then
346 ./configure --with-ovs-source=$DEST/$OVS_REPO_NAME $prefix $localstatedir
347 fi
348 make -j$(($(nproc) + 1))
349 sudo make install
350 popd
351}
352
353
354# OVN Neutron driver functions
355# ----------------------------
356
357# OVN service sanity check
358function ovn_sanity_check {
359 if is_service_enabled q-agt neutron-agt; then
360 die $LINENO "The q-agt/neutron-agt service must be disabled with OVN."
361 elif is_service_enabled q-l3 neutron-l3; then
362 die $LINENO "The q-l3/neutron-l3 service must be disabled with OVN."
363 elif is_service_enabled q-svc neutron-api && [[ ! $Q_ML2_PLUGIN_MECHANISM_DRIVERS =~ "ovn" ]]; then
364 die $LINENO "OVN needs to be enabled in \$Q_ML2_PLUGIN_MECHANISM_DRIVERS"
365 elif is_service_enabled q-svc neutron-api && [[ ! $Q_ML2_PLUGIN_TYPE_DRIVERS =~ "geneve" ]]; then
366 die $LINENO "Geneve needs to be enabled in \$Q_ML2_PLUGIN_TYPE_DRIVERS to be used with OVN"
367 fi
368}
369
370# install_ovn() - Collect source and prepare
371function install_ovn {
Slawek Kaplonski7ba26f52020-09-17 11:13:52 +0200372 if [[ "$Q_BUILD_OVS_FROM_GIT" == "False" ]]; then
373 echo "Installation of OVS from source disabled."
374 return 0
375 fi
376
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100377 echo "Installing OVN and dependent packages"
378
379 # Check the OVN configuration
380 ovn_sanity_check
381
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100382 # Install tox, used to generate the config (see devstack/override-defaults)
383 pip_install tox
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100384
385 sudo mkdir -p $OVS_RUNDIR
386 sudo chown $(whoami) $OVS_RUNDIR
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000387 # NOTE(lucasagomes): To keep things simpler, let's reuse the same
388 # RUNDIR for both OVS and OVN. This way we avoid having to specify the
389 # --db option in the ovn-{n,s}bctl commands while playing with DevStack
390 sudo ln -s $OVS_RUNDIR $OVN_RUNDIR
391
392 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
393 # If OVS is already installed, remove it, because we're about to
394 # re-install it from source.
395 for package in openvswitch openvswitch-switch openvswitch-common; do
396 if is_package_installed $package ; then
397 uninstall_package $package
398 fi
399 done
400
401 remove_ovs_packages
402 sudo rm -f $OVS_RUNDIR/*
403
404 compile_ovs $OVN_BUILD_MODULES
405 if use_new_ovn_repository; then
406 compile_ovn $OVN_BUILD_MODULES
407 fi
408
409 sudo mkdir -p $OVS_PREFIX/var/log/openvswitch
410 sudo chown $(whoami) $OVS_PREFIX/var/log/openvswitch
411 sudo mkdir -p $OVS_PREFIX/var/log/ovn
412 sudo chown $(whoami) $OVS_PREFIX/var/log/ovn
413 else
414 fixup_ovn_centos
415 install_package $(get_packages openvswitch)
416 install_package $(get_packages ovn)
417 fi
418
419 # Ensure that the OVS commands are accessible in the PATH
420 export PATH=$OVS_BINDIR:$PATH
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100421
422 # Archive log files and create new
423 local log_archive_dir=$LOGDIR/archive
424 mkdir -p $log_archive_dir
425 for logfile in ovs-vswitchd.log ovn-northd.log ovn-controller.log ovn-controller-vtep.log ovs-vtep.log ovsdb-server.log ovsdb-server-nb.log ovsdb-server-sb.log; do
426 if [ -f "$LOGDIR/$logfile" ] ; then
427 mv "$LOGDIR/$logfile" "$log_archive_dir/$logfile.${CURRENT_LOG_TIME}"
428 fi
429 done
430
431 # Install ovsdbapp from source if requested
432 if use_library_from_git "ovsdbapp"; then
433 git_clone_by_name "ovsdbapp"
434 setup_dev_lib "ovsdbapp"
435 fi
436
437 # Install ovs python module from ovs source.
438 if [[ "$OVN_INSTALL_OVS_PYTHON_MODULE" == "True" ]]; then
439 sudo pip uninstall -y ovs
440 # Clone the OVS repository if it's not yet present
441 clone_repository $OVS_REPO $DEST/$OVS_REPO_NAME $OVS_BRANCH
442 sudo pip install -e $DEST/$OVS_REPO_NAME/python
443 fi
444}
445
446# filter_network_api_extensions() - Remove non-supported API extensions by
447# the OVN driver from the list of enabled API extensions
448function filter_network_api_extensions {
449 SUPPORTED_NETWORK_API_EXTENSIONS=$($PYTHON -c \
450 'from neutron.common.ovn import extensions ;\
451 print(",".join(extensions.ML2_SUPPORTED_API_EXTENSIONS))')
452 SUPPORTED_NETWORK_API_EXTENSIONS=$SUPPORTED_NETWORK_API_EXTENSIONS,$($PYTHON -c \
453 'from neutron.common.ovn import extensions ;\
454 print(",".join(extensions.ML2_SUPPORTED_API_EXTENSIONS_OVN_L3))')
455 if is_service_enabled q-qos neutron-qos ; then
456 SUPPORTED_NETWORK_API_EXTENSIONS="$SUPPORTED_NETWORK_API_EXTENSIONS,qos"
457 fi
458 NETWORK_API_EXTENSIONS=${NETWORK_API_EXTENSIONS:-$SUPPORTED_NETWORK_API_EXTENSIONS}
459 extensions=$(echo $NETWORK_API_EXTENSIONS | tr ', ' '\n' | sort -u)
460 supported_ext=$(echo $SUPPORTED_NETWORK_API_EXTENSIONS | tr ', ' '\n' | sort -u)
461 enabled_ext=$(comm -12 <(echo -e "$extensions") <(echo -e "$supported_ext"))
462 disabled_ext=$(comm -3 <(echo -e "$extensions") <(echo -e "$enabled_ext"))
463
464 # Log a message in case some extensions had to be disabled because
465 # they are not supported by the OVN driver
466 if [ ! -z "$disabled_ext" ]; then
467 _disabled=$(echo $disabled_ext | tr ' ' ',')
468 echo "The folling network API extensions have been disabled because they are not supported by OVN: $_disabled"
469 fi
470
471 # Export the final list of extensions that have been enabled and are
472 # supported by OVN
473 export NETWORK_API_EXTENSIONS=$(echo $enabled_ext | tr ' ' ',')
474}
475
476function configure_ovn_plugin {
477 echo "Configuring Neutron for OVN"
478
479 if is_service_enabled q-svc ; then
480 filter_network_api_extensions
481 populate_ml2_config /$Q_PLUGIN_CONF_FILE ml2_type_geneve max_header_size=$OVN_GENEVE_OVERHEAD
482 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_connection="$OVN_NB_REMOTE"
483 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_connection="$OVN_SB_REMOTE"
484 if is_service_enabled tls-proxy; then
485 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_ca_cert="$INT_CA_DIR/ca-chain.pem"
486 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_certificate="$INT_CA_DIR/$DEVSTACK_CERT_NAME.crt"
487 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_sb_private_key="$INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key"
488 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_ca_cert="$INT_CA_DIR/ca-chain.pem"
489 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_certificate="$INT_CA_DIR/$DEVSTACK_CERT_NAME.crt"
490 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_nb_private_key="$INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key"
491 fi
492 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn neutron_sync_mode="$OVN_NEUTRON_SYNC_MODE"
493 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_l3_scheduler="$OVN_L3_SCHEDULER"
494 populate_ml2_config /$Q_PLUGIN_CONF_FILE securitygroup enable_security_group="$Q_USE_SECGROUP"
495 inicomment /$Q_PLUGIN_CONF_FILE securitygroup firewall_driver
496
Flavio Fernandesa2273cc2021-02-06 16:23:36 -0500497 if is_service_enabled q-log neutron-log; then
498 populate_ml2_config /$Q_PLUGIN_CONF_FILE network_log rate_limit="$Q_LOG_DRIVER_RATE_LIMIT"
499 populate_ml2_config /$Q_PLUGIN_CONF_FILE network_log burst_limit="$Q_LOG_DRIVER_BURST_LIMIT"
500 inicomment /$Q_PLUGIN_CONF_FILE network_log local_output_log_base="$Q_LOG_DRIVER_LOG_BASE"
501 fi
502
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100503 if is_service_enabled q-ovn-metadata-agent; then
504 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_metadata_enabled=True
505 else
506 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn ovn_metadata_enabled=False
507 fi
508
509 if is_service_enabled q-dns neutron-dns ; then
510 iniset $NEUTRON_CONF DEFAULT dns_domain openstackgate.local
511 populate_ml2_config /$Q_PLUGIN_CONF_FILE ovn dns_servers="$OVN_DNS_SERVERS"
512 fi
513
514 iniset $NEUTRON_CONF ovs igmp_snooping_enable $OVN_IGMP_SNOOPING_ENABLE
515 fi
516
517 if is_service_enabled q-dhcp neutron-dhcp ; then
518 iniset $NEUTRON_CONF DEFAULT dhcp_agent_notification True
519 else
520 iniset $NEUTRON_CONF DEFAULT dhcp_agent_notification False
521 fi
522
523 if is_service_enabled n-api-meta ; then
524 if is_service_enabled q-ovn-metadata-agent ; then
525 iniset $NOVA_CONF neutron service_metadata_proxy True
526 fi
527 fi
528}
529
530function configure_ovn {
531 echo "Configuring OVN"
532
533 if [ -z "$OVN_UUID" ] ; then
Slawek Kaplonski1ed276c2021-03-11 13:10:28 +0100534 if [ -f $OVS_SYSCONFDIR/system-id.conf ]; then
535 OVN_UUID=$(cat $OVS_SYSCONFDIR/system-id.conf)
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100536 else
537 OVN_UUID=$(uuidgen)
Slawek Kaplonski1ed276c2021-03-11 13:10:28 +0100538 echo $OVN_UUID | sudo tee $OVS_SYSCONFDIR/system-id.conf
539 fi
540 else
541 local ovs_uuid
542 ovs_uuid=$(cat $OVS_SYSCONFDIR/system-id.conf)
543 if [ "$ovs_uuid" != $OVN_UUID ]; then
544 echo $OVN_UUID | sudo tee $OVS_SYSCONFDIR/system-id.conf
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100545 fi
546 fi
547
548 # Metadata
549 if is_service_enabled q-ovn-metadata-agent && is_service_enabled ovn-controller; then
550 sudo install -d -o $STACK_USER $NEUTRON_CONF_DIR
551
552 mkdir -p $NEUTRON_DIR/etc/neutron/plugins/ml2
553 (cd $NEUTRON_DIR && exec ./tools/generate_config_file_samples.sh)
554
555 cp $NEUTRON_DIR/etc/neutron_ovn_metadata_agent.ini.sample $OVN_META_CONF
556 configure_root_helper_options $OVN_META_CONF
557
558 iniset $OVN_META_CONF DEFAULT debug $ENABLE_DEBUG_LOG_LEVEL
559 iniset $OVN_META_CONF DEFAULT nova_metadata_host $OVN_META_DATA_HOST
560 iniset $OVN_META_CONF DEFAULT metadata_workers $API_WORKERS
561 iniset $OVN_META_CONF DEFAULT state_path $NEUTRON_STATE_PATH
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000562 iniset $OVN_META_CONF ovs ovsdb_connection tcp:$OVSDB_SERVER_LOCAL_HOST:6640
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100563 iniset $OVN_META_CONF ovn ovn_sb_connection $OVN_SB_REMOTE
564 if is_service_enabled tls-proxy; then
565 iniset $OVN_META_CONF ovn \
566 ovn_sb_ca_cert $INT_CA_DIR/ca-chain.pem
567 iniset $OVN_META_CONF ovn \
568 ovn_sb_certificate $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt
569 iniset $OVN_META_CONF ovn \
570 ovn_sb_private_key $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key
571 fi
572 fi
573}
574
575function init_ovn {
576 # clean up from previous (possibly aborted) runs
577 # create required data files
578
579 # Assumption: this is a dedicated test system and there is nothing important
580 # in the ovn, ovn-nb, or ovs databases. We're going to trash them and
581 # create new ones on each devstack run.
582
583 _disable_libvirt_apparmor
584
585 mkdir -p $OVN_DATADIR
586 mkdir -p $OVS_DATADIR
587
588 rm -f $OVS_DATADIR/*.db
589 rm -f $OVS_DATADIR/.*.db.~lock~
590 rm -f $OVN_DATADIR/*.db
591 rm -f $OVN_DATADIR/.*.db.~lock~
592}
593
594function _start_ovs {
595 echo "Starting OVS"
596 if is_service_enabled ovn-controller ovn-controller-vtep ovn-northd; then
597 # ovsdb-server and ovs-vswitchd are used privately in OVN as openvswitch service names.
598 enable_service ovsdb-server
599 enable_service ovs-vswitchd
600
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000601 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
602 if [ ! -f $OVS_DATADIR/conf.db ]; then
603 ovsdb-tool create $OVS_DATADIR/conf.db $OVS_SHAREDIR/vswitch.ovsschema
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100604 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100605
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000606 if is_service_enabled ovn-controller-vtep; then
607 if [ ! -f $OVS_DATADIR/vtep.db ]; then
608 ovsdb-tool create $OVS_DATADIR/vtep.db $OVS_SHAREDIR/vtep.ovsschema
609 fi
610 fi
611
612 local dbcmd="$OVS_SBINDIR/ovsdb-server --remote=punix:$OVS_RUNDIR/db.sock --remote=ptcp:6640:$OVSDB_SERVER_LOCAL_HOST --pidfile --detach --log-file"
613 dbcmd+=" --remote=db:Open_vSwitch,Open_vSwitch,manager_options"
614 if is_service_enabled ovn-controller-vtep; then
615 dbcmd+=" --remote=db:hardware_vtep,Global,managers $OVS_DATADIR/vtep.db"
616 fi
617 dbcmd+=" $OVS_DATADIR/conf.db"
618 _run_process ovsdb-server "$dbcmd"
619
620 # Note: ovn-controller will create and configure br-int once it is started.
621 # So, no need to create it now because nothing depends on that bridge here.
622 local ovscmd="$OVS_SBINDIR/ovs-vswitchd --log-file --pidfile --detach"
623 _run_process ovs-vswitchd "$ovscmd" "" "$STACK_GROUP" "root"
624 else
625 _start_process "$OVSDB_SERVER_SERVICE"
626 _start_process "$OVS_VSWITCHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100627 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100628
629 echo "Configuring OVSDB"
630 if is_service_enabled tls-proxy; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000631 sudo ovs-vsctl --no-wait set-ssl \
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100632 $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key \
633 $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt \
634 $INT_CA_DIR/ca-chain.pem
635 fi
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000636
637 sudo ovs-vsctl --no-wait set-manager ptcp:6640:$OVSDB_SERVER_LOCAL_HOST
638 sudo ovs-vsctl --no-wait set open_vswitch . system-type="devstack"
639 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:system-id="$OVN_UUID"
640 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-remote="$OVN_SB_REMOTE"
641 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-bridge="br-int"
642 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-encap-type="geneve"
643 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-encap-ip="$HOST_IP"
644 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:hostname="$LOCAL_HOSTNAME"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100645 # Select this chassis to host gateway routers
646 if [[ "$ENABLE_CHASSIS_AS_GW" == "True" ]]; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000647 sudo ovs-vsctl --no-wait set open_vswitch . external-ids:ovn-cms-options="enable-chassis-as-gw"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100648 fi
649
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100650 if is_provider_network || [[ $Q_USE_PROVIDERNET_FOR_PUBLIC == "True" ]]; then
651 ovn_base_setup_bridge $OVS_PHYSICAL_BRIDGE
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000652 sudo ovs-vsctl set open . external-ids:ovn-bridge-mappings=${PHYSICAL_NETWORK}:${OVS_PHYSICAL_BRIDGE}
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100653 fi
654
655 if is_service_enabled ovn-controller-vtep ; then
656 ovn_base_setup_bridge br-v
657 vtep-ctl add-ps br-v
658 vtep-ctl set Physical_Switch br-v tunnel_ips=$HOST_IP
659
660 enable_service ovs-vtep
661 local vtepcmd="$OVS_SCRIPTDIR/ovs-vtep --log-file --pidfile --detach br-v"
662 _run_process ovs-vtep "$vtepcmd" "" "$STACK_GROUP" "root"
663
664 vtep-ctl set-manager tcp:$HOST_IP:6640
665 fi
666 fi
667}
668
669function _start_ovn_services {
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000670 _start_process "$OVSDB_SERVER_SERVICE"
671 _start_process "$OVS_VSWITCHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100672
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100673 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000674 _start_process "$OVN_NORTHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100675 fi
676 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000677 _start_process "$OVN_CONTROLLER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100678 fi
679 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000680 _start_process "$OVN_CONTROLLER_VTEP_SERVICE"
681 fi
682 if is_service_enabled ovs-vtep ; then
683 _start_process "devstack@ovs-vtep.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100684 fi
685 if is_service_enabled q-ovn-metadata-agent; then
686 _start_process "devstack@q-ovn-metadata-agent.service"
687 fi
688}
689
690# start_ovn() - Start running processes, including screen
691function start_ovn {
692 echo "Starting OVN"
693
694 _start_ovs
695
696 local SCRIPTDIR=$OVN_SCRIPTDIR
697 if ! use_new_ovn_repository; then
698 SCRIPTDIR=$OVS_SCRIPTDIR
699 fi
700
701 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000702 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
703 local cmd="/bin/bash $SCRIPTDIR/ovn-ctl --no-monitor start_northd"
704 local stop_cmd="/bin/bash $SCRIPTDIR/ovn-ctl stop_northd"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100705
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000706 _run_process ovn-northd "$cmd" "$stop_cmd"
707 else
708 _start_process "$OVN_NORTHD_SERVICE"
709 fi
710
711 # Wait for the service to be ready
712 wait_for_sock_file $OVS_RUNDIR/ovnnb_db.sock
713 wait_for_sock_file $OVS_RUNDIR/ovnsb_db.sock
714
715 if is_service_enabled tls-proxy; then
716 sudo ovn-nbctl --db=unix:$OVS_RUNDIR/ovnnb_db.sock set-ssl $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt $INT_CA_DIR/ca-chain.pem
717 sudo ovn-sbctl --db=unix:$OVS_RUNDIR/ovnsb_db.sock set-ssl $INT_CA_DIR/private/$DEVSTACK_CERT_NAME.key $INT_CA_DIR/$DEVSTACK_CERT_NAME.crt $INT_CA_DIR/ca-chain.pem
718 fi
719 sudo ovn-nbctl --db=unix:$OVS_RUNDIR/ovnnb_db.sock set-connection p${OVN_PROTO}:6641:$SERVICE_LISTEN_ADDRESS -- set connection . inactivity_probe=60000
720 sudo ovn-sbctl --db=unix:$OVS_RUNDIR/ovnsb_db.sock set-connection p${OVN_PROTO}:6642:$SERVICE_LISTEN_ADDRESS -- set connection . inactivity_probe=60000
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100721 sudo ovs-appctl -t $OVS_RUNDIR/ovnnb_db.ctl vlog/set console:off syslog:$OVN_DBS_LOG_LEVEL file:$OVN_DBS_LOG_LEVEL
722 sudo ovs-appctl -t $OVS_RUNDIR/ovnsb_db.ctl vlog/set console:off syslog:$OVN_DBS_LOG_LEVEL file:$OVN_DBS_LOG_LEVEL
723 fi
724
725 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000726 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
727 local cmd="/bin/bash $SCRIPTDIR/ovn-ctl --no-monitor start_controller"
728 local stop_cmd="/bin/bash $SCRIPTDIR/ovn-ctl stop_controller"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100729
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000730 _run_process ovn-controller "$cmd" "$stop_cmd" "$STACK_GROUP" "root"
731 else
732 _start_process "$OVN_CONTROLLER_SERVICE"
733 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100734 fi
735
736 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000737 if [[ "$OVN_BUILD_FROM_SOURCE" == "True" ]]; then
738 local cmd="$OVS_BINDIR/ovn-controller-vtep --log-file --pidfile --detach --ovnsb-db=$OVN_SB_REMOTE"
739 _run_process ovn-controller-vtep "$cmd" "" "$STACK_GROUP" "root"
740 else
741 _start_process "$OVN_CONTROLLER_VTEP_SERVICE"
742 fi
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100743 fi
744
745 if is_service_enabled q-ovn-metadata-agent; then
746 run_process q-ovn-metadata-agent "$NEUTRON_OVN_BIN_DIR/$NEUTRON_OVN_METADATA_BINARY --config-file $OVN_META_CONF"
747 # Format logging
748 setup_logging $OVN_META_CONF
749 fi
750
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100751 _start_ovn_services
752}
753
754function _stop_ovs_dp {
755 sudo ovs-dpctl dump-dps | sudo xargs -n1 ovs-dpctl del-dp
756 modprobe -q -r vport_geneve vport_vxlan openvswitch || true
757}
758
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000759function _stop_process {
760 local service=$1
761 echo "Stopping process $service"
762 if $SYSTEMCTL is-enabled $service; then
763 $SYSTEMCTL stop $service
764 $SYSTEMCTL disable $service
765 fi
766}
767
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100768function stop_ovn {
769 if is_service_enabled q-ovn-metadata-agent; then
770 sudo pkill -9 -f haproxy || :
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000771 _stop_process "devstack@q-ovn-metadata-agent.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100772 fi
773 if is_service_enabled ovn-controller-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000774 _stop_process "$OVN_CONTROLLER_VTEP_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100775 fi
776 if is_service_enabled ovn-controller ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000777 _stop_process "$OVN_CONTROLLER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100778 fi
779 if is_service_enabled ovn-northd ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000780 _stop_process "$OVN_NORTHD_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100781 fi
782 if is_service_enabled ovs-vtep ; then
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000783 _stop_process "devstack@ovs-vtep.service"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100784 fi
785
Lucas Alvares Gomese651d9e2020-11-19 14:50:01 +0000786 _stop_process "$OVS_VSWITCHD_SERVICE"
787 _stop_process "$OVSDB_SERVER_SERVICE"
Lucas Alvares Gomes1d468d42020-06-09 14:35:52 +0100788
789 _stop_ovs_dp
790}
791
792function _cleanup {
793 local path=${1:-$DEST/$OVN_REPO_NAME}
794 pushd $path
795 cd $path
796 sudo make uninstall
797 sudo make distclean
798 popd
799}
800
801# cleanup_ovn() - Remove residual data files, anything left over from previous
802# runs that a clean run would need to clean up
803function cleanup_ovn {
804 local ovn_path=$DEST/$OVN_REPO_NAME
805 local ovs_path=$DEST/$OVS_REPO_NAME
806
807 if [ -d $ovn_path ]; then
808 _cleanup $ovn_path
809 fi
810
811 if [ -d $ovs_path ]; then
812 _cleanup $ovs_path
813 fi
814
815 sudo rm -f $OVN_RUNDIR
816}