]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/network/netdev/bridge.c
Merge pull request #13870 from irtimmer/check_ip_gnutls
[thirdparty/systemd.git] / src / network / netdev / bridge.c
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
6235b3de 2
540eb5f0 3#include <net/if.h>
6235b3de 4
6235b3de 5#include "missing.h"
540eb5f0 6#include "netlink-util.h"
441e9ae4 7#include "netdev/bridge.h"
9a81f119 8#include "network-internal.h"
23f53b99 9#include "networkd-manager.h"
8e2cb51c 10#include "string-table.h"
0d6c68eb 11#include "vlan-util.h"
540eb5f0 12
8e2cb51c
YW
13static const char* const multicast_router_table[_MULTICAST_ROUTER_MAX] = {
14 [MULTICAST_ROUTER_NONE] = "no",
15 [MULTICAST_ROUTER_TEMPORARY_QUERY] = "query",
16 [MULTICAST_ROUTER_PERMANENT] = "permanent",
17 [MULTICAST_ROUTER_TEMPORARY] = "temporary",
18};
19
20DEFINE_STRING_TABLE_LOOKUP_WITH_BOOLEAN(multicast_router, MulticastRouter, _MULTICAST_ROUTER_INVALID);
21DEFINE_CONFIG_PARSE_ENUM(config_parse_multicast_router, multicast_router, MulticastRouter,
22 "Failed to parse bridge multicast router setting");
23
5238e957 24/* callback for bridge netdev's parameter set */
302a796f 25static int netdev_bridge_set_handler(sd_netlink *rtnl, sd_netlink_message *m, NetDev *netdev) {
540eb5f0
SS
26 int r;
27
28 assert(netdev);
29 assert(m);
30
31 r = sd_netlink_message_get_errno(m);
32 if (r < 0) {
33 log_netdev_warning_errno(netdev, r, "Bridge parameters could not be set: %m");
34 return 1;
35 }
36
82936769 37 log_netdev_debug(netdev, "Bridge parameters set success");
540eb5f0
SS
38
39 return 1;
40}
41
42static int netdev_bridge_post_create(NetDev *netdev, Link *link, sd_netlink_message *m) {
4afd3348 43 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL;
540eb5f0
SS
44 Bridge *b;
45 int r;
46
47 assert(netdev);
48
49 b = BRIDGE(netdev);
50
51 assert(b);
52
53 r = sd_rtnl_message_new_link(netdev->manager->rtnl, &req, RTM_NEWLINK, netdev->ifindex);
54 if (r < 0)
55 return log_netdev_error_errno(netdev, r, "Could not allocate RTM_SETLINK message: %m");
56
57 r = sd_netlink_message_set_flags(req, NLM_F_REQUEST | NLM_F_ACK);
58 if (r < 0)
59 return log_link_error_errno(link, r, "Could not set netlink flags: %m");
60
61 r = sd_netlink_message_open_container(req, IFLA_LINKINFO);
62 if (r < 0)
15cdaeee 63 return log_netdev_error_errno(netdev, r, "Could not append IFLA_LINKINFO attribute: %m");
540eb5f0
SS
64
65 r = sd_netlink_message_open_container_union(req, IFLA_INFO_DATA, netdev_kind_to_string(netdev->kind));
66 if (r < 0)
67 return log_netdev_error_errno(netdev, r, "Could not append IFLA_INFO_DATA attribute: %m");
68
1a14863e 69 /* convert to jiffes */
730389b6 70 if (b->forward_delay != USEC_INFINITY) {
1a14863e 71 r = sd_netlink_message_append_u32(req, IFLA_BR_FORWARD_DELAY, usec_to_jiffies(b->forward_delay));
540eb5f0
SS
72 if (r < 0)
73 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_FORWARD_DELAY attribute: %m");
74 }
75
76 if (b->hello_time > 0) {
1a14863e 77 r = sd_netlink_message_append_u32(req, IFLA_BR_HELLO_TIME, usec_to_jiffies(b->hello_time));
540eb5f0
SS
78 if (r < 0)
79 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_HELLO_TIME attribute: %m");
80 }
81
82 if (b->max_age > 0) {
1a14863e 83 r = sd_netlink_message_append_u32(req, IFLA_BR_MAX_AGE, usec_to_jiffies(b->max_age));
540eb5f0
SS
84 if (r < 0)
85 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_MAX_AGE attribute: %m");
86 }
87
0da81203 88 if (b->ageing_time != USEC_INFINITY) {
c7440e74
TJ
89 r = sd_netlink_message_append_u32(req, IFLA_BR_AGEING_TIME, usec_to_jiffies(b->ageing_time));
90 if (r < 0)
91 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_AGEING_TIME attribute: %m");
92 }
93
94 if (b->priority > 0) {
95 r = sd_netlink_message_append_u16(req, IFLA_BR_PRIORITY, b->priority);
96 if (r < 0)
97 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_PRIORITY attribute: %m");
98 }
99
c4819961
JC
100 if (b->group_fwd_mask > 0) {
101 r = sd_netlink_message_append_u16(req, IFLA_BR_GROUP_FWD_MASK, b->group_fwd_mask);
102 if (r < 0)
103 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_GROUP_FWD_MASK attribute: %m");
104 }
105
0d6c68eb 106 if (b->default_pvid != VLANID_INVALID) {
c7440e74
TJ
107 r = sd_netlink_message_append_u16(req, IFLA_BR_VLAN_DEFAULT_PVID, b->default_pvid);
108 if (r < 0)
109 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_VLAN_DEFAULT_PVID attribute: %m");
110 }
111
3fef7a3f
SS
112 if (b->mcast_querier >= 0) {
113 r = sd_netlink_message_append_u8(req, IFLA_BR_MCAST_QUERIER, b->mcast_querier);
114 if (r < 0)
115 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_MCAST_QUERIER attribute: %m");
116 }
117
6df6d898
SS
118 if (b->mcast_snooping >= 0) {
119 r = sd_netlink_message_append_u8(req, IFLA_BR_MCAST_SNOOPING, b->mcast_snooping);
120 if (r < 0)
121 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_MCAST_SNOOPING attribute: %m");
122 }
123
c6f8d17d
TJ
124 if (b->vlan_filtering >= 0) {
125 r = sd_netlink_message_append_u8(req, IFLA_BR_VLAN_FILTERING, b->vlan_filtering);
126 if (r < 0)
127 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_VLAN_FILTERING attribute: %m");
128 }
129
b760a9af
SS
130 if (b->stp >= 0) {
131 r = sd_netlink_message_append_u32(req, IFLA_BR_STP_STATE, b->stp);
132 if (r < 0)
133 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_STP_STATE attribute: %m");
134 }
135
afa51e2d
SS
136 if (b->igmp_version > 0) {
137 r = sd_netlink_message_append_u8(req, IFLA_BR_MCAST_IGMP_VERSION, b->igmp_version);
138 if (r < 0)
139 return log_netdev_error_errno(netdev, r, "Could not append IFLA_BR_MCAST_IGMP_VERSION attribute: %m");
140 }
141
540eb5f0
SS
142 r = sd_netlink_message_close_container(req);
143 if (r < 0)
144 return log_netdev_error_errno(netdev, r, "Could not append IFLA_LINKINFO attribute: %m");
145
146 r = sd_netlink_message_close_container(req);
147 if (r < 0)
148 return log_netdev_error_errno(netdev, r, "Could not append IFLA_INFO_DATA attribute: %m");
149
302a796f
YW
150 r = netlink_call_async(netdev->manager->rtnl, NULL, req, netdev_bridge_set_handler,
151 netdev_destroy_callback, netdev);
540eb5f0
SS
152 if (r < 0)
153 return log_netdev_error_errno(netdev, r, "Could not send rtnetlink message: %m");
154
155 netdev_ref(netdev);
156
157 return r;
158}
6235b3de 159
9a81f119
YW
160static int link_set_bridge_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) {
161 int r;
162
163 assert(m);
164 assert(link);
165 assert(link->ifname);
166
167 if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER))
168 return 1;
169
170 r = sd_netlink_message_get_errno(m);
171 if (r < 0) {
172 log_link_warning_errno(link, r, "Could not set bridge interface: %m");
173 return 1;
174 }
175
176 return 1;
177}
178
179int link_set_bridge(Link *link) {
180 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL;
181 int r;
182
183 assert(link);
184 assert(link->network);
185
186 r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_SETLINK, link->ifindex);
187 if (r < 0)
188 return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m");
189
190 r = sd_rtnl_message_link_set_family(req, PF_BRIDGE);
191 if (r < 0)
192 return log_link_error_errno(link, r, "Could not set message family: %m");
193
194 r = sd_netlink_message_open_container(req, IFLA_PROTINFO);
195 if (r < 0)
196 return log_link_error_errno(link, r, "Could not append IFLA_PROTINFO attribute: %m");
197
198 if (link->network->use_bpdu >= 0) {
199 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_GUARD, link->network->use_bpdu);
200 if (r < 0)
201 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_GUARD attribute: %m");
202 }
203
204 if (link->network->hairpin >= 0) {
205 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MODE, link->network->hairpin);
206 if (r < 0)
207 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MODE attribute: %m");
208 }
209
210 if (link->network->fast_leave >= 0) {
211 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_FAST_LEAVE, link->network->fast_leave);
212 if (r < 0)
213 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_FAST_LEAVE attribute: %m");
214 }
215
216 if (link->network->allow_port_to_be_root >= 0) {
217 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_PROTECT, link->network->allow_port_to_be_root);
218 if (r < 0)
219 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PROTECT attribute: %m");
220 }
221
222 if (link->network->unicast_flood >= 0) {
223 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_UNICAST_FLOOD, link->network->unicast_flood);
224 if (r < 0)
225 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_UNICAST_FLOOD attribute: %m");
226 }
227
228 if (link->network->multicast_flood >= 0) {
229 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MCAST_FLOOD, link->network->multicast_flood);
230 if (r < 0)
231 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MCAST_FLOOD attribute: %m");
232 }
233
234 if (link->network->multicast_to_unicast >= 0) {
235 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MCAST_TO_UCAST, link->network->multicast_to_unicast);
236 if (r < 0)
237 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MCAST_TO_UCAST attribute: %m");
238 }
239
240 if (link->network->neighbor_suppression >= 0) {
241 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_NEIGH_SUPPRESS, link->network->neighbor_suppression);
242 if (r < 0)
243 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_NEIGH_SUPPRESS attribute: %m");
244 }
245
246 if (link->network->learning >= 0) {
247 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_LEARNING, link->network->learning);
248 if (r < 0)
249 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_LEARNING attribute: %m");
250 }
251
252 if (link->network->bridge_proxy_arp >= 0) {
253 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_PROXYARP, link->network->bridge_proxy_arp);
254 if (r < 0)
255 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PROXYARP attribute: %m");
256 }
257
258 if (link->network->bridge_proxy_arp_wifi >= 0) {
259 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_PROXYARP_WIFI, link->network->bridge_proxy_arp_wifi);
260 if (r < 0)
261 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PROXYARP_WIFI attribute: %m");
262 }
263
264 if (link->network->cost != 0) {
265 r = sd_netlink_message_append_u32(req, IFLA_BRPORT_COST, link->network->cost);
266 if (r < 0)
267 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_COST attribute: %m");
268 }
269
270 if (link->network->priority != LINK_BRIDGE_PORT_PRIORITY_INVALID) {
271 r = sd_netlink_message_append_u16(req, IFLA_BRPORT_PRIORITY, link->network->priority);
272 if (r < 0)
273 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PRIORITY attribute: %m");
274 }
275
276 if (link->network->multicast_router != _MULTICAST_ROUTER_INVALID) {
277 r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MULTICAST_ROUTER, link->network->multicast_router);
278 if (r < 0)
279 return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MULTICAST_ROUTER attribute: %m");
280 }
281
282 r = sd_netlink_message_close_container(req);
283 if (r < 0)
284 return log_link_error_errno(link, r, "Could not append IFLA_LINKINFO attribute: %m");
285
286 r = netlink_call_async(link->manager->rtnl, NULL, req, link_set_bridge_handler,
287 link_netlink_destroy_callback, link);
288 if (r < 0)
289 return log_link_error_errno(link, r, "Could not send rtnetlink message: %m");
290
291 link_ref(link);
292
293 return r;
294}
295
afa51e2d
SS
296int config_parse_bridge_igmp_version(
297 const char *unit,
298 const char *filename,
299 unsigned line,
300 const char *section,
301 unsigned section_line,
302 const char *lvalue,
303 int ltype,
304 const char *rvalue,
305 void *data,
306 void *userdata) {
307
308 Bridge *b = userdata;
309 uint8_t u;
310 int r;
311
312 assert(filename);
313 assert(lvalue);
314 assert(rvalue);
315 assert(data);
316
317 if (isempty(rvalue)) {
318 b->igmp_version = 0; /* 0 means unset. */
319 return 0;
320 }
321
322 r = safe_atou8(rvalue, &u);
323 if (r < 0) {
324 log_syntax(unit, LOG_ERR, filename, line, r,
b738530b 325 "Failed to parse bridge's multicast IGMP version number '%s', ignoring assignment: %m",
afa51e2d
SS
326 rvalue);
327 return 0;
328 }
329 if (!IN_SET(u, 2, 3)) {
330 log_syntax(unit, LOG_ERR, filename, line, 0,
b738530b 331 "Invalid bridge's multicast IGMP version number '%s', ignoring assignment.", rvalue);
afa51e2d
SS
332 return 0;
333 }
334
335 b->igmp_version = u;
336
337 return 0;
338}
339
3fef7a3f
SS
340static void bridge_init(NetDev *n) {
341 Bridge *b;
342
343 b = BRIDGE(n);
344
345 assert(b);
346
347 b->mcast_querier = -1;
6df6d898 348 b->mcast_snooping = -1;
c6f8d17d 349 b->vlan_filtering = -1;
b760a9af 350 b->stp = -1;
0d6c68eb 351 b->default_pvid = VLANID_INVALID;
730389b6 352 b->forward_delay = USEC_INFINITY;
0da81203 353 b->ageing_time = USEC_INFINITY;
3fef7a3f
SS
354}
355
3be1d7e0 356const NetDevVTable bridge_vtable = {
aa9f1140 357 .object_size = sizeof(Bridge),
3fef7a3f 358 .init = bridge_init,
540eb5f0
SS
359 .sections = "Match\0NetDev\0Bridge\0",
360 .post_create = netdev_bridge_post_create,
aa9f1140 361 .create_type = NETDEV_CREATE_MASTER,
3be1d7e0 362};