summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorStephen Hemminger <stephen.hemminger@vyatta.com>2008-09-23 15:50:41 -0700
committerStephen Hemminger <stephen.hemminger@vyatta.com>2008-09-23 15:50:41 -0700
commit6ab5a0589ac4f0359679edbd3982c130038dfc1d (patch)
treed549d305f5633a97237bc1fe986c179394c216b7
parent200fb453f43a3f0406c14b9003ca5a1e6f7587f4 (diff)
downloadvyatta-cfg-qos-6ab5a0589ac4f0359679edbd3982c130038dfc1d.tar.gz
vyatta-cfg-qos-6ab5a0589ac4f0359679edbd3982c130038dfc1d.zip
Add incoming traffic limiting to Qos
This adds support for Qos using incoming policing. It is accepts the syntax and processes commands, but is not fully debugged. Bugfix: 3664
-rw-r--r--Makefile.am1
-rw-r--r--scripts/VyattaQosMatch.pm10
-rw-r--r--scripts/VyattaQosTrafficLimiter.pm217
-rw-r--r--scripts/VyattaQosTrafficShaper.pm6
-rwxr-xr-xscripts/vyatta-qos.pl70
-rw-r--r--templates/interfaces/adsl/node.tag/pvc/node.tag/classical-ipoa/qos-policy/out/node.def2
-rw-r--r--templates/interfaces/adsl/node.tag/pvc/node.tag/pppoa/node.tag/qos-policy/out/node.def2
-rw-r--r--templates/interfaces/adsl/node.tag/pvc/node.tag/pppoe/node.tag/qos-policy/out/node.def2
-rw-r--r--templates/interfaces/ethernet/node.tag/qos-policy/in/node.def5
-rw-r--r--templates/interfaces/ethernet/node.tag/qos-policy/out/node.def4
-rw-r--r--templates/interfaces/ethernet/node.tag/vif/node.tag/qos-policy/out/node.def2
-rw-r--r--templates/interfaces/ethernet/pppoe/node.tag/qos-policy/out/node.def2
-rw-r--r--templates/interfaces/serial/node.tag/qos-policy/in/node.def5
-rw-r--r--templates/interfaces/serial/node.tag/qos-policy/out/node.def2
-rw-r--r--templates/qos-policy/traffic-limiter/node.def7
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.def6
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/bandwidth/node.def8
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/description/node.def2
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.def4
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/description/node.def2
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/address/node.def2
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/port/node.def3
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/dscp/node.def18
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/protocol/node.def17
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/address/node.def2
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/port/node.def3
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/vif/node.def5
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/class/node.tag/priority/node.def8
-rw-r--r--templates/qos-policy/traffic-limiter/node.tag/description/node.def2
29 files changed, 380 insertions, 39 deletions
diff --git a/Makefile.am b/Makefile.am
index 8df4236..0257672 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -10,6 +10,7 @@ share_perl5_DATA += scripts/VyattaQosTrafficShaper.pm
share_perl5_DATA += scripts/VyattaQosMatch.pm
share_perl5_DATA += scripts/VyattaQosRateLimiter.pm
share_perl5_DATA += scripts/VyattaQosDropTail.pm
+share_perl5_DATA += scripts/VyattaQosTrafficLimiter.pm
cpiop = find . ! -regex '\(.*~\|.*\.bak\|.*\.swp\|.*\#.*\#\)' -print0 | \
cpio -0pd
diff --git a/scripts/VyattaQosMatch.pm b/scripts/VyattaQosMatch.pm
index 0fedda2..9c9945d 100644
--- a/scripts/VyattaQosMatch.pm
+++ b/scripts/VyattaQosMatch.pm
@@ -56,7 +56,7 @@ sub _define {
}
sub filter {
- my ( $self, $out, $dev, $parent, $id, $dsmark ) = @_;
+ my ( $self, $out, $dev, $parent, $prio, $dsmark ) = @_;
my $ip = $self->{_ip};
my $indev = $self->{_dev};
my $vif = $self->{_vif};
@@ -69,14 +69,13 @@ sub filter {
# Special case for when dsmarking is used with ds matching
# original dscp is saved in tc_index
if (defined $dsmark && defined $ip && defined $$ip{dsfield}) {
- printf {$out} "filter add dev %s parent %x:0 protocol ip prio 1",
+ printf {$out} "filter add dev %s parent %x: protocol ip prio 1",
$dev, $parent;
- printf ${out} " handle %d tcindex classid %x:%x\n",
- $$ip{dsfield}, $parent, $id;
+ printf ${out} " handle %d tcindex", $$ip{dsfield};
return;
}
- printf {$out} "filter add dev %s parent %x:0 prio 1", $dev, $parent;
+ printf {$out} "filter add dev %s parent %x: prio %d", $dev, $parent, $prio;
if (defined $ip) {
print {$out} " protocol ip u32";
print {$out} " match ip dsfield $$ip{dsfield} 0xff"
@@ -98,5 +97,4 @@ sub filter {
print {$out} " match meta\(vlan mask 0xfff eq $vif\)"
if (defined $vif);
}
- printf {$out} " classid %x:%x\n", $parent, $id;
}
diff --git a/scripts/VyattaQosTrafficLimiter.pm b/scripts/VyattaQosTrafficLimiter.pm
new file mode 100644
index 0000000..4ffee85
--- /dev/null
+++ b/scripts/VyattaQosTrafficLimiter.pm
@@ -0,0 +1,217 @@
+# Traffic limiter
+# This is a rate limiter based on ingress qdisc
+#
+# **** License ****
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2 as
+# published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful, but
+# WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# General Public License for more details.
+#
+# This code was originally developed by Vyatta, Inc.
+# Portions created by Vyatta are Copyright (C) 2008 Vyatta, Inc.
+# All Rights Reserved.
+# **** End License ****
+
+{
+
+ package LimiterClass;
+ use strict;
+ require VyattaConfig;
+ use VyattaQosMatch;
+
+ my %fields = (
+ id => undef,
+ priority => undef,
+ rate => undef,
+ _match => undef,
+ );
+
+ sub new {
+ my ( $that, $config, $id ) = @_;
+ my $class = ref($that) || $that;
+ my $self = {%fields};
+
+ $self->{id} = $id;
+
+ bless $self, $class;
+ $self->_define($config);
+
+ return $self;
+ }
+
+ sub _define {
+ my ( $self, $config ) = @_;
+ my $level = $config->setLevel();
+ my @matches = ();
+
+ $self->{rate} = $config->returnValue("bandwidth");
+ defined $self->{rate} or die "$level bandwidth not defined\n";
+
+ $self->{priority} = $config->returnValue("priority");
+
+ foreach my $match ( $config->listNodes("match") ) {
+ $config->setLevel("$level match $match");
+ push @matches, new VyattaQosMatch($config);
+ }
+ $self->{_match} = \@matches;
+ }
+
+ sub matchRules {
+ my ($self) = @_;
+ my $matches = $self->{_match};
+ return @$matches;
+ }
+
+ sub _getPercentRate {
+ my ( $rate, $speed ) = @_;
+
+ if ( !defined $rate ) {
+ return; # leave rate undef
+ }
+
+ # Rate might be a percentage of speed
+ if ( $rate =~ /%$/ ) {
+ my $percent = substr( $rate, 0, length($rate) - 1 );
+ if ( $percent < 0 || $percent > 100 ) {
+ die "Invalid percentage bandwidth: $percent\n";
+ }
+
+ $rate = ( $percent * $speed ) / 100.;
+ }
+ else {
+ $rate = VyattaQosUtil::getRate($rate);
+ }
+
+ return $rate;
+ }
+
+}
+
+package VyattaQosTrafficLimiter;
+use strict;
+require VyattaConfig;
+use VyattaQosUtil;
+
+my %fields = (
+ _level => undef,
+ _classes => undef,
+);
+
+# new VyattaQosTrafficLimiter($config)
+# Create a new instance based on config information
+sub new {
+ my ( $that, $config, $name ) = @_;
+ my $self = {%fields};
+ my $class = ref($that) || $that;
+
+ bless $self, $class;
+ $self->_define($config);
+
+ return $self;
+}
+
+# Setup new instance.
+# Assumes caller has done $config->setLevel to "traffic-limiter $name"
+sub _define {
+ my ( $self, $config ) = @_;
+ my $level = $config->setLevel();
+ my @classes = ();
+
+ $self->{_level} = $level;
+
+ # make sure no clash of different types of tc filters
+ my %matchTypes = ();
+ foreach my $class ( $config->listNodes("class") ) {
+ foreach my $match ( $config->listNodes("class $class match") ) {
+ foreach my $type ( $config->listNodes("class $class match $match") )
+ {
+ $matchTypes{$type} = "$class match $match";
+ }
+ }
+ }
+
+ if ( scalar keys %matchTypes > 1 && $matchTypes{ip} ) {
+ print "Match type conflict:\n";
+ while ( my ( $type, $usage ) = each(%matchTypes) ) {
+ print " class $usage $type\n";
+ }
+ die "$level can not match on both ip and other types\n";
+ }
+
+ foreach my $id ( $config->listNodes("class") ) {
+ $config->setLevel("$level class $id");
+ push @classes, new LimiterClass( $config, $id );
+ }
+ $self->{_classes} = \@classes;
+}
+
+sub commands {
+ my ( $self, $out, $dev ) = @_;
+ my $classes = $self->{_classes};
+ my $parent = 0xffff;
+
+ printf {$out} "qdisc add dev %s handle %x: ingress\n", $dev, $parent;
+ foreach my $class (@$classes) {
+ my $id = $class->{id};
+ my $rate = $class->{rate};
+ my $priority = $class->{priority};
+
+ foreach my $match ( $class->matchRules() ) {
+ $match->filter( $out, $dev, $parent, $priority );
+ printf {$out} " police avrate %s drop flowid :%x\n", $rate, $id;
+ }
+ }
+}
+
+# Walk configuration tree and look for changed nodes
+# The configuration system should do this but doesn't do it right
+sub isChanged {
+ my ( $self, $name ) = @_;
+ my $config = new VyattaConfig;
+
+ $config->setLevel("qos-policy traffic-limiter $name");
+ my %classNodes = $config->listNodeStatus('class');
+ while ( my ( $class, $status ) = each %classNodes ) {
+ if ( $status ne 'static' ) {
+ return "class $class";
+ }
+
+ foreach my $attr ( 'bandwidth', 'burst', 'priority' ) {
+ if ( $config->isChanged("class $class $attr") ) {
+ return "class $class $attr";
+ }
+ }
+
+ my %matchNodes = $config->listNodeStatus("class $class match");
+ while ( my ( $match, $status ) = each %matchNodes ) {
+ my $level = "class $class match $match";
+ if ( $status ne 'static' ) {
+ return $level;
+ }
+
+ foreach my $parm (
+ 'vif',
+ 'interface',
+ 'ip dscp',
+ 'ip protocol',
+ 'ip source address',
+ 'ip destination address',
+ 'ip source port',
+ 'ip destination port'
+ )
+ {
+ if ( $config->isChanged("$level $parm") ) {
+ return "$level $parm";
+ }
+ }
+ }
+ }
+
+ return undef; # false
+}
+
+1;
diff --git a/scripts/VyattaQosTrafficShaper.pm b/scripts/VyattaQosTrafficShaper.pm
index ce4ea3f..5f9fe75 100644
--- a/scripts/VyattaQosTrafficShaper.pm
+++ b/scripts/VyattaQosTrafficShaper.pm
@@ -384,7 +384,8 @@ sub commands {
foreach my $class (@$classes) {
$class->dsmarkClass($out, 1, $dev);
foreach my $match ($class->matchRules()) {
- $match->filter($out, $dev, 1, $class->{id});
+ $match->filter($out, $dev, 1, 1);
+ printf {$out} " classid %x:%x\n", $parent, $class->{id};
}
}
@@ -401,7 +402,8 @@ sub commands {
$class->htbClass($out, $dev, $parent, $rate);
foreach my $match ($class->matchRules()) {
- $match->filter($out, $dev, $parent, $class->{id}, $class->{dsmark});
+ $match->filter($out, $dev, $parent, 1, $class->{dsmark});
+ printf {$out} " classid %x:%x\n", $parent, $class->{id};
}
}
}
diff --git a/scripts/vyatta-qos.pl b/scripts/vyatta-qos.pl
index 690894d..a2b1303 100755
--- a/scripts/vyatta-qos.pl
+++ b/scripts/vyatta-qos.pl
@@ -34,45 +34,65 @@ GetOptions(
"update-interface=s{3}" => \@updateInterface,
"delete-interface=s{2}" => \@deleteInterface,
- "list-policy" => \$listPolicy,
+ "list-policy=s" => \$listPolicy,
"delete-policy=s" => \$deletePolicy,
"create-policy=s{2}" => \@createPolicy,
);
-# class factory for policies
-# TODO use hierarcy (ie VyattaQos::TrafficShaper)
-# and reference to object, not string dynamic binding
my %policies = (
- 'traffic-shaper' => "VyattaQosTrafficShaper",
- 'fair-queue' => "VyattaQosFairQueue",
- 'rate-limit' => "VyattaQosRateLimiter",
- 'drop-tail' => "VyattaQosDropTail",
+ 'out' => {
+ 'traffic-shaper' => 'VyattaQosTrafficShaper',
+ 'fair-queue' => 'VyattaQosFairQueue',
+ 'rate-limit' => 'VyattaQosRateLimiter',
+ 'drop-tail' => 'VyattaQosDropTail',
+ },
+ 'in' => {
+ 'traffic-limiter' => 'VyattaQosTrafficLimiter',
+ }
);
+# class factory for policies
sub make_policy {
- my ($config, $type, $name) = @_;
- my $class = $policies{$type};
+ my ($config, $type, $name, $direction) = @_;
+ my $class;
+
+ if ($direction) {
+ $class = $policies{$direction}{$type};
+ } else {
+ foreach $direction (keys %policies) {
+ $class = $policies{$direction}{$type};
+ last if defined $class;
+ }
+ }
# This means template exists but we don't know what it is.
- defined $class or die "Unknown policy type $type";
+ if (! defined $class) {
+ foreach $direction (keys %policies) {
+ die "QoS policy $name is type $type and is only valid for $direction\n"
+ if defined $policies{$direction}{$type};
+ }
+ die "QoS policy $name has not been created\n";
+ }
my $location = "$class.pm";
require $location;
$config->setLevel("qos-policy $type $name");
- return $class->new($config, $name);
+ return $class->new($config, $name, $direction);
}
## list defined qos policy names
sub list_policy {
+ my $direction = shift;
my $config = new VyattaConfig;
my @nodes = ();
$config->setLevel('qos-policy');
foreach my $type ( $config->listNodes() ) {
- foreach my $name ( $config->listNodes($type) ) {
- push @nodes, $name;
- }
+ next if ! defined $policies{$direction}{$type};
+ foreach my $name ( $config->listNodes ) {
+ push @nodes, $name;
+ }
}
print join( ' ', @nodes ), "\n";
@@ -83,9 +103,15 @@ sub list_policy {
sub delete_interface {
my ($interface, $direction ) = @_;
- if ($direction eq "out" ) {
- # delete old qdisc - will give error if no policy in place
- qx(sudo /sbin/tc qdisc del dev "$interface" root 2>/dev/null);
+ for ($direction) {
+ # delete old qdisc - silence error if no qdisc loaded
+ if (/^out$/) {
+ qx(sudo /sbin/tc qdisc del dev "$interface" root 2>/dev/null);
+ } elsif (/^in$/) {
+ qx(sudo /sbin/tc qdisc del dev "$interface" parent ffff: 2>/dev/null);
+ } else {
+ die "bad direction $direction";
+ }
}
}
@@ -95,12 +121,10 @@ sub update_interface {
my ($interface, $direction, $name ) = @_;
my $config = new VyattaConfig;
- ( $direction eq "out" ) or die "Only out direction supported";
-
$config->setLevel('qos-policy');
foreach my $type ( $config->listNodes() ) {
if ( $config->exists("$type $name") ) {
- my $shaper = make_policy($config, $type, $name);
+ my $shaper = make_policy($config, $type, $name, $direction);
# Remove old policy
delete_interface($interface, $direction);
@@ -122,7 +146,7 @@ sub update_interface {
# replay commands to stdout
open $out, '>-';
- $shaper->commands($out, $interface);
+ $shaper->commands($out, $interface, $direction);
close $out;
die "TC command failed.";
}
@@ -272,7 +296,7 @@ if ($check) {
}
if ( $listPolicy ) {
- list_policy();
+ list_policy($listPolicy);
exit 0;
}
diff --git a/templates/interfaces/adsl/node.tag/pvc/node.tag/classical-ipoa/qos-policy/out/node.def b/templates/interfaces/adsl/node.tag/pvc/node.tag/classical-ipoa/qos-policy/out/node.def
index bf62f9e..b8c64de 100644
--- a/templates/interfaces/adsl/node.tag/pvc/node.tag/classical-ipoa/qos-policy/out/node.def
+++ b/templates/interfaces/adsl/node.tag/pvc/node.tag/classical-ipoa/qos-policy/out/node.def
@@ -1,5 +1,5 @@
type: txt
help: Set outbound QOS policy for specified ethernet interface
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface $VAR(../../../../@) $VAR(.) $VAR(@)
delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface $VAR(../../../../@) $VAR(.)
diff --git a/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoa/node.tag/qos-policy/out/node.def b/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoa/node.tag/qos-policy/out/node.def
index dfbb888..54a968a 100644
--- a/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoa/node.tag/qos-policy/out/node.def
+++ b/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoa/node.tag/qos-policy/out/node.def
@@ -1,5 +1,5 @@
type: txt
help: Set outbound QOS policy for specified ethernet interface
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface pppoa$VAR(../../@) $VAR(.) $VAR(@)
delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface pppoa$VAR(../../@) $VAR(.)
diff --git a/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoe/node.tag/qos-policy/out/node.def b/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoe/node.tag/qos-policy/out/node.def
index 213d298..b61939d 100644
--- a/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoe/node.tag/qos-policy/out/node.def
+++ b/templates/interfaces/adsl/node.tag/pvc/node.tag/pppoe/node.tag/qos-policy/out/node.def
@@ -1,5 +1,5 @@
type: txt
help: Set outbound QOS policy for specified ethernet interface
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface pppoe$VAR(../../@) $VAR(.) $VAR(@)
delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface pppoe$VAR(../../@) $VAR(.)
diff --git a/templates/interfaces/ethernet/node.tag/qos-policy/in/node.def b/templates/interfaces/ethernet/node.tag/qos-policy/in/node.def
new file mode 100644
index 0000000..41f812f
--- /dev/null
+++ b/templates/interfaces/ethernet/node.tag/qos-policy/in/node.def
@@ -0,0 +1,5 @@
+type: txt
+help: Set input QOS policy for specified ethernet interface
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy in
+update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface $VAR(../../@) $VAR(.) $VAR(@)
+delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface $VAR(../../@) $VAR(.)
diff --git a/templates/interfaces/ethernet/node.tag/qos-policy/out/node.def b/templates/interfaces/ethernet/node.tag/qos-policy/out/node.def
index b4246b0..0b3d91a 100644
--- a/templates/interfaces/ethernet/node.tag/qos-policy/out/node.def
+++ b/templates/interfaces/ethernet/node.tag/qos-policy/out/node.def
@@ -1,5 +1,5 @@
type: txt
-help: Set outbound QOS policy for specified ethernet interface
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+help: Set output QOS policy for specified ethernet interface
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface $VAR(../../@) $VAR(.) $VAR(@)
delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface $VAR(../../@) $VAR(.)
diff --git a/templates/interfaces/ethernet/node.tag/vif/node.tag/qos-policy/out/node.def b/templates/interfaces/ethernet/node.tag/vif/node.tag/qos-policy/out/node.def
index ba98afa..60f003a 100644
--- a/templates/interfaces/ethernet/node.tag/vif/node.tag/qos-policy/out/node.def
+++ b/templates/interfaces/ethernet/node.tag/vif/node.tag/qos-policy/out/node.def
@@ -1,6 +1,6 @@
type: txt
help: Set outbound QOS policy
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
create: sudo ip link set dev $VAR(../../../@).$VAR(../../@) txqueuelen 100
/opt/vyatta/sbin/vyatta-qos.pl \
--update-interface $VAR(../../../@).$VAR(../../@) $VAR(.) $VAR(@)
diff --git a/templates/interfaces/ethernet/pppoe/node.tag/qos-policy/out/node.def b/templates/interfaces/ethernet/pppoe/node.tag/qos-policy/out/node.def
index 213d298..98f001e 100644
--- a/templates/interfaces/ethernet/pppoe/node.tag/qos-policy/out/node.def
+++ b/templates/interfaces/ethernet/pppoe/node.tag/qos-policy/out/node.def
@@ -1,5 +1,5 @@
type: txt
help: Set outbound QOS policy for specified ethernet interface
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface pppoe$VAR(../../@) $VAR(.) $VAR(@)
delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface pppoe$VAR(../../@) $VAR(.)
diff --git a/templates/interfaces/serial/node.tag/qos-policy/in/node.def b/templates/interfaces/serial/node.tag/qos-policy/in/node.def
new file mode 100644
index 0000000..de04df8
--- /dev/null
+++ b/templates/interfaces/serial/node.tag/qos-policy/in/node.def
@@ -0,0 +1,5 @@
+type: txt
+help: Set inbound QOS policy for specified serial interface
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy in
+update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface $VAR(../../@) $VAR(.) $VAR(@)
+delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface $VAR(../../@) $VAR(.)
diff --git a/templates/interfaces/serial/node.tag/qos-policy/out/node.def b/templates/interfaces/serial/node.tag/qos-policy/out/node.def
index 0251a27..f654046 100644
--- a/templates/interfaces/serial/node.tag/qos-policy/out/node.def
+++ b/templates/interfaces/serial/node.tag/qos-policy/out/node.def
@@ -1,5 +1,5 @@
type: txt
help: Set outbound QOS policy for specified serial interface
-allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy
+allowed: /opt/vyatta/sbin/vyatta-qos.pl --list-policy out
update: /opt/vyatta/sbin/vyatta-qos.pl --update-interface $VAR(../../@) $VAR(.) $VAR(@)
delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-interface $VAR(../../@) $VAR(.)
diff --git a/templates/qos-policy/traffic-limiter/node.def b/templates/qos-policy/traffic-limiter/node.def
new file mode 100644
index 0000000..d760acb
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.def
@@ -0,0 +1,7 @@
+tag:
+type: txt
+help: Set traffic input limiting policy
+syntax:expression: pattern $VAR(@) "^[[:alnum:]][-_[:alnum:]]*$"
+ ; "only alpha-numeric policy name allowed"
+update: /opt/vyatta/sbin/vyatta-qos.pl --create-policy "$VAR(.)" "$VAR(@)"
+delete: /opt/vyatta/sbin/vyatta-qos.pl --delete-policy "$VAR(@)"
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.def
new file mode 100644
index 0000000..2a77af0
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.def
@@ -0,0 +1,6 @@
+tag:
+type: u32
+help: Set class handle
+syntax:expression: $VAR(@) >= 1 && $VAR(@) < 4096; "Class identifier must be between 1 and 4095"
+comp_help: possible completions
+ <1-4095> Class ID
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/bandwidth/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/bandwidth/node.def
new file mode 100644
index 0000000..a87dd30
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/bandwidth/node.def
@@ -0,0 +1,8 @@
+type: txt
+help: Set the traffic-limit used for this class
+syntax:expression: exec "/opt/vyatta/sbin/vyatta-qos-util.pl --rate \"$VAR(@)\""
+comp_help: Allowed values:
+ <number> Bandwidth in Kbps
+ <number><suffix> Value with scaling suffix
+ bits per sec (kbit, mbit, gbit)
+ bytes per sec (kbps, mbps, gbps)
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/description/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/description/node.def
new file mode 100644
index 0000000..d4241e7
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/description/node.def
@@ -0,0 +1,2 @@
+type: txt
+help: Set description for this traffic class
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.def
new file mode 100644
index 0000000..2a5d021
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.def
@@ -0,0 +1,4 @@
+tag:
+type: txt
+syntax:expression: pattern $VAR(@) "^[^-]" ; "Match queue name cannot start with \"-\""
+help: Set class matching rule name
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/description/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/description/node.def
new file mode 100644
index 0000000..a56c59c
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/description/node.def
@@ -0,0 +1,2 @@
+type: txt
+help: Set description for this match
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/address/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/address/node.def
new file mode 100644
index 0000000..ccd2d14
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/address/node.def
@@ -0,0 +1,2 @@
+type: ipv4net
+help: Set IP destination address for this match
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/port/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/port/node.def
new file mode 100644
index 0000000..561899c
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/destination/port/node.def
@@ -0,0 +1,3 @@
+type: u32
+help: Set IP destination port for this match
+syntax:expression: ($VAR(@) > 0 && $VAR(@) < 65536) ; "port must be between 1 and 65535"
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/dscp/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/dscp/node.def
new file mode 100644
index 0000000..a2059c1
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/dscp/node.def
@@ -0,0 +1,18 @@
+type: txt
+help: Set Differentiated Services Codepoint (DSCP, formerly known as TOS) value for this match
+syntax:expression: exec "/opt/vyatta/sbin/vyatta-qos-util.pl --dscp \"$VAR(@)\""
+allowed: awk '
+ /^#/ { next }
+ { printf "%s ", $2 }' </etc/iproute2/rt_dsfield
+comp_help: <0-63> Differentiated Services Codepoint (DSCP) value
+ default match DSCP (000000)
+ reliability match DSCP (000001)
+ throughput match DSCP (000010)
+ lowdelay match DSCP (000100)
+ priority match DSCP (001000)
+ immediate match DSCP (010000)
+ flash match DSCP (011000)
+ flash-override match DSCP (100000)
+ critical match DSCP (101000)
+ internet match DSCP (110000)
+ network match DSCP (111000)
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/protocol/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/protocol/node.def
new file mode 100644
index 0000000..6c76cad
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/protocol/node.def
@@ -0,0 +1,17 @@
+type: txt
+help: Set IP protocol name or number for this match
+syntax:expression: exec "/opt/vyatta/sbin/vyatta-qos-util.pl --protocol \"$VAR(@)\""
+allowed: awk '
+ /^#/ { next }
+ { printf "%s ", $1 }' </etc/protocols
+comp_help: <0-255> IP protocol value or name
+Common names:
+ icmp Internet Control Message Protocol
+ igmp Internet Group Management Protocol
+ ggp Gateway-Gateway protocol
+ tcp Transmission Control Protocol
+ egp Exterior Gateway Protocol
+ udp User Datagram Protocol
+ gre General Routing Encapsulation
+ ospf Open Shortest Path First IGP
+ sctp Stream Control Transmission Protocol
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/address/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/address/node.def
new file mode 100644
index 0000000..0bc690a
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/address/node.def
@@ -0,0 +1,2 @@
+type: ipv4net
+help: Set IP source address for this match
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/port/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/port/node.def
new file mode 100644
index 0000000..ecd96ab
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/ip/source/port/node.def
@@ -0,0 +1,3 @@
+type: u32
+help: Set IP source port for this match
+syntax:expression: ($VAR(@) > 0 && $VAR(@) < 65536) ; "port must be between 1 and 65535"
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/vif/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/vif/node.def
new file mode 100644
index 0000000..e22250d
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/match/node.tag/vif/node.def
@@ -0,0 +1,5 @@
+type: u32
+help: Set Virtual Local Area Network (VLAN) ID for this match
+syntax:expression: $VAR(@) >= 0 && $VAR(@) <= 4095; "VLAN ID must be between 0 and 4095"
+comp_help: possible completions:
+ <0-4095> Set VLAN ID
diff --git a/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/priority/node.def b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/priority/node.def
new file mode 100644
index 0000000..a99400d
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/class/node.tag/priority/node.def
@@ -0,0 +1,8 @@
+type: u32
+help: Set priority for rule evaluation
+default: 20
+syntax:expression: $VAR(@) >= 0 && $VAR(@) <= 20 ; \
+ "priority must be between 0 and 20"
+help: Priority value
+comp_help: Priority for traffic limiting evaluation
+ <0-20> (default 20)
diff --git a/templates/qos-policy/traffic-limiter/node.tag/description/node.def b/templates/qos-policy/traffic-limiter/node.tag/description/node.def
new file mode 100644
index 0000000..1e8e64f
--- /dev/null
+++ b/templates/qos-policy/traffic-limiter/node.tag/description/node.def
@@ -0,0 +1,2 @@
+type: txt
+help: Set description for this queuing policy