]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/network/networkd-dhcp-server.c
alloc-util: add MALLOC_ELEMENTSOF() helper
[thirdparty/systemd.git] / src / network / networkd-dhcp-server.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
8fcf1d61 2
5ae0fb7f
YW
3#include <netinet/in.h>
4#include <linux/if_arp.h>
5#include <linux/if.h>
6
8fcf1d61
YW
7#include "sd-dhcp-server.h"
8
dd1d3060
MAL
9#include "fd-util.h"
10#include "fileio.h"
093e3533 11#include "networkd-address.h"
8fcf1d61 12#include "networkd-dhcp-server.h"
a95e9306 13#include "networkd-dhcp-server-bus.h"
8fcf1d61
YW
14#include "networkd-link.h"
15#include "networkd-manager.h"
16#include "networkd-network.h"
564ca984 17#include "parse-util.h"
dd1d3060 18#include "socket-netlink.h"
564ca984
SS
19#include "string-table.h"
20#include "string-util.h"
dd1d3060 21#include "strv.h"
8fcf1d61 22
5ae0fb7f
YW
23static bool link_dhcp4_server_enabled(Link *link) {
24 assert(link);
25
26 if (link->flags & IFF_LOOPBACK)
27 return false;
28
29 if (!link->network)
30 return false;
31
5ae0fb7f
YW
32 if (link->iftype == ARPHRD_CAN)
33 return false;
34
35 return link->network->dhcp_server;
36}
37
0017ba31
YW
38void network_adjust_dhcp_server(Network *network) {
39 assert(network);
40
41 if (!network->dhcp_server)
42 return;
43
44 if (network->bond) {
45 log_warning("%s: DHCPServer= is enabled for bond slave. Disabling DHCP server.",
46 network->filename);
47 network->dhcp_server = false;
48 return;
49 }
50
51 if (!in4_addr_is_set(&network->dhcp_server_address)) {
52 Address *address;
53 bool have = false;
54
55 ORDERED_HASHMAP_FOREACH(address, network->addresses_by_section) {
56 if (section_is_invalid(address->section))
57 continue;
58 if (address->family == AF_INET &&
59 !in4_addr_is_localhost(&address->in_addr.in) &&
60 in4_addr_is_null(&address->in_addr_peer.in)) {
61 have = true;
62 break;
63 }
64 }
65 if (!have) {
66 log_warning("%s: DHCPServer= is enabled, but no static address configured. "
67 "Disabling DHCP server.",
68 network->filename);
69 network->dhcp_server = false;
70 return;
71 }
72 }
73}
74
75static int link_find_dhcp_server_address(Link *link, Address **ret) {
8fcf1d61
YW
76 Address *address;
77
78 assert(link);
79 assert(link->network);
80
0017ba31
YW
81 /* If ServerAddress= is specified, then use the address. */
82 if (in4_addr_is_set(&link->network->dhcp_server_address))
83 return link_get_ipv4_address(link, &link->network->dhcp_server_address,
84 link->network->dhcp_server_address_prefixlen, ret);
8fcf1d61 85
0017ba31
YW
86 /* If not, then select one from static addresses. */
87 SET_FOREACH(address, link->static_addresses)
88 if (address->family == AF_INET &&
89 !in4_addr_is_localhost(&address->in_addr.in) &&
90 in4_addr_is_null(&address->in_addr_peer.in)) {
91 *ret = address;
92 return 0;
93 }
8fcf1d61 94
0017ba31 95 return -ENOENT;
8fcf1d61
YW
96}
97
2a71d57f
LP
98static int link_push_uplink_to_dhcp_server(
99 Link *link,
2324fd3a 100 sd_dhcp_lease_server_type_t what,
2a71d57f
LP
101 sd_dhcp_server *s) {
102
8fcf1d61
YW
103 _cleanup_free_ struct in_addr *addresses = NULL;
104 size_t n_addresses = 0, n_allocated = 0;
2a71d57f 105 bool use_dhcp_lease_data = true;
8fcf1d61 106
2a71d57f 107 assert(link);
8fcf1d61 108
2a71d57f
LP
109 if (!link->network)
110 return 0;
111 assert(link->network);
8fcf1d61 112
2a71d57f 113 log_link_debug(link, "Copying %s from link", dhcp_lease_server_type_to_string(what));
8fcf1d61 114
2a71d57f 115 switch (what) {
8fcf1d61 116
2a71d57f
LP
117 case SD_DHCP_LEASE_DNS:
118 /* For DNS we have a special case. We the data configured explicitly locally along with the
119 * data from the DHCP lease. */
8fcf1d61 120
2a71d57f
LP
121 for (unsigned i = 0; i < link->network->n_dns; i++) {
122 struct in_addr ia;
8fcf1d61 123
2a71d57f 124 /* Only look for IPv4 addresses */
e77bd3fd 125 if (link->network->dns[i]->family != AF_INET)
2a71d57f 126 continue;
8fcf1d61 127
e77bd3fd 128 ia = link->network->dns[i]->address.in;
2a71d57f
LP
129
130 /* Never propagate obviously borked data */
131 if (in4_addr_is_null(&ia) || in4_addr_is_localhost(&ia))
132 continue;
133
134 if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + 1))
8fcf1d61
YW
135 return log_oom();
136
2a71d57f 137 addresses[n_addresses++] = ia;
8fcf1d61 138 }
8fcf1d61 139
2a71d57f
LP
140 use_dhcp_lease_data = link->network->dhcp_use_dns;
141 break;
8fcf1d61 142
2a71d57f
LP
143 case SD_DHCP_LEASE_NTP: {
144 char **i;
8fcf1d61 145
2a71d57f
LP
146 /* For NTP things are similar, but for NTP hostnames can be configured too, which we cannot
147 * propagate via DHCP. Hence let's only propagate those which are IP addresses. */
284e8fd0 148
2a71d57f
LP
149 STRV_FOREACH(i, link->network->ntp) {
150 union in_addr_union ia;
284e8fd0 151
2a71d57f
LP
152 if (in_addr_from_string(AF_INET, *i, &ia) < 0)
153 continue;
284e8fd0 154
2a71d57f
LP
155 /* Never propagate obviously borked data */
156 if (in4_addr_is_null(&ia.in) || in4_addr_is_localhost(&ia.in))
157 continue;
284e8fd0 158
2a71d57f
LP
159 if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + 1))
160 return log_oom();
284e8fd0 161
2a71d57f
LP
162 addresses[n_addresses++] = ia.in;
163 }
284e8fd0 164
2a71d57f 165 use_dhcp_lease_data = link->network->dhcp_use_ntp;
24e6f458 166 break;
2a71d57f 167 }
284e8fd0 168
ddb82ec2 169 case SD_DHCP_LEASE_SIP:
2a71d57f
LP
170
171 /* For SIP we don't allow explicit, local configuration, but there's control whether to use the data */
172 use_dhcp_lease_data = link->network->dhcp_use_sip;
24e6f458 173 break;
284e8fd0 174
2a71d57f
LP
175 case SD_DHCP_LEASE_POP3:
176 case SD_DHCP_LEASE_SMTP:
ddb82ec2 177 case SD_DHCP_LEASE_LPR:
2a71d57f
LP
178 /* For the other server types we currently do not allow local configuration of server data,
179 * since there are typically no local consumers of the data. */
c4e585a3 180 break;
d361b373 181
24e6f458 182 default:
2a71d57f 183 assert_not_reached("Unexpected server type");
f6269fe7
SS
184 }
185
2a71d57f 186 if (use_dhcp_lease_data && link->dhcp_lease) {
24e6f458 187 const struct in_addr *da;
f6269fe7 188
a2706075 189 int n = sd_dhcp_lease_get_servers(link->dhcp_lease, what, &da);
f6269fe7 190 if (n > 0) {
f6269fe7
SS
191 if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + n))
192 return log_oom();
193
2a71d57f
LP
194 for (int j = 0; j < n; j++)
195 if (in4_addr_is_non_local(&da[j]))
196 addresses[n_addresses++] = da[j];
f6269fe7
SS
197 }
198 }
199
200 if (n_addresses <= 0)
201 return 0;
202
24e6f458 203 return sd_dhcp_server_set_servers(s, what, addresses, n_addresses);
299d578f
SS
204}
205
dd1d3060
MAL
206static int dhcp4_server_parse_dns_server_string_and_warn(Link *l, const char *string, struct in_addr **addresses, size_t *n_allocated, size_t *n_addresses) {
207 for (;;) {
208 _cleanup_free_ char *word = NULL, *server_name = NULL;
209 union in_addr_union address;
210 int family, r, ifindex = 0;
211
212 r = extract_first_word(&string, &word, NULL, 0);
213 if (r < 0)
214 return r;
215 if (r == 0)
216 break;
217
218 r = in_addr_ifindex_name_from_string_auto(word, &family, &address, &ifindex, &server_name);
219 if (r < 0) {
220 log_warning_errno(r, "Failed to parse DNS server address '%s', ignoring: %m", word);
221 continue;
222 }
223
224 /* Only look for IPv4 addresses */
225 if (family != AF_INET)
226 continue;
227
228 /* Never propagate obviously borked data */
229 if (in4_addr_is_null(&address.in) || in4_addr_is_localhost(&address.in))
230 continue;
231
232 if (!GREEDY_REALLOC(*addresses, *n_allocated, *n_addresses + 1))
233 return log_oom();
234
235 (*addresses)[(*n_addresses)++] = address.in;
236 }
237
238 return 0;
239}
240
241static int dhcp4_server_set_dns_from_resolve_conf(Link *link) {
242 _cleanup_free_ struct in_addr *addresses = NULL;
243 size_t n_addresses = 0, n_allocated = 0;
244 _cleanup_fclose_ FILE *f = NULL;
245 int n = 0, r;
246
247 f = fopen(PRIVATE_UPLINK_RESOLV_CONF, "re");
248 if (!f) {
249 if (errno == ENOENT)
250 return 0;
251
252 return log_warning_errno(errno, "Failed to open " PRIVATE_UPLINK_RESOLV_CONF ": %m");
253 }
254
255 for (;;) {
256 _cleanup_free_ char *line = NULL;
257 const char *a;
258 char *l;
259
260 r = read_line(f, LONG_LINE_MAX, &line);
261 if (r < 0)
262 return log_error_errno(r, "Failed to read " PRIVATE_UPLINK_RESOLV_CONF ": %m");
263 if (r == 0)
264 break;
265
266 n++;
267
268 l = strstrip(line);
269 if (IN_SET(*l, '#', ';', 0))
270 continue;
271
272 a = first_word(l, "nameserver");
273 if (!a)
274 continue;
275
276 r = dhcp4_server_parse_dns_server_string_and_warn(link, a, &addresses, &n_allocated, &n_addresses);
277 if (r < 0)
278 log_warning_errno(r, "Failed to parse DNS server address '%s', ignoring.", a);
279 }
280
281 if (n_addresses <= 0)
282 return 0;
283
284 return sd_dhcp_server_set_dns(link->dhcp_server, addresses, n_addresses);
285}
286
8fcf1d61 287int dhcp4_server_configure(Link *link) {
8fcf1d61 288 bool acquired_uplink = false;
461dbb2f 289 sd_dhcp_option *p;
564ca984
SS
290 Link *uplink = NULL;
291 Address *address;
11c38d3e 292 bool bind_to_interface;
8fcf1d61
YW
293 int r;
294
5ae0fb7f
YW
295 assert(link);
296
297 if (!link_dhcp4_server_enabled(link))
298 return 0;
299
300 if (!(link->flags & IFF_UP))
301 return 0;
302
303 if (!link->dhcp_server) {
304 r = sd_dhcp_server_new(&link->dhcp_server, link->ifindex);
305 if (r < 0)
306 return r;
307
308 r = sd_dhcp_server_attach_event(link->dhcp_server, link->manager->event, 0);
309 if (r < 0)
310 return r;
311 }
312
a95e9306
LK
313 r = sd_dhcp_server_set_callback(link->dhcp_server, dhcp_server_callback, link);
314 if (r < 0)
315 return log_link_warning_errno(link, r, "Failed to set callback for DHCPv4 server instance: %m");
316
0017ba31
YW
317 r = link_find_dhcp_server_address(link, &address);
318 if (r < 0)
319 return log_link_error_errno(link, r, "Failed to find suitable address for DHCPv4 server instance: %m");
8fcf1d61
YW
320
321 /* use the server address' subnet as the pool */
322 r = sd_dhcp_server_configure_pool(link->dhcp_server, &address->in_addr.in, address->prefixlen,
323 link->network->dhcp_server_pool_offset, link->network->dhcp_server_pool_size);
324 if (r < 0)
c00c3b64 325 return log_link_error_errno(link, r, "Failed to configure address pool for DHCPv4 server instance: %m");
8fcf1d61
YW
326
327 /* TODO:
328 r = sd_dhcp_server_set_router(link->dhcp_server, &main_address->in_addr.in);
329 if (r < 0)
330 return r;
331 */
332
333 if (link->network->dhcp_server_max_lease_time_usec > 0) {
334 r = sd_dhcp_server_set_max_lease_time(link->dhcp_server,
335 DIV_ROUND_UP(link->network->dhcp_server_max_lease_time_usec, USEC_PER_SEC));
336 if (r < 0)
c00c3b64 337 return log_link_error_errno(link, r, "Failed to set maximum lease time for DHCPv4 server instance: %m");
8fcf1d61
YW
338 }
339
340 if (link->network->dhcp_server_default_lease_time_usec > 0) {
341 r = sd_dhcp_server_set_default_lease_time(link->dhcp_server,
342 DIV_ROUND_UP(link->network->dhcp_server_default_lease_time_usec, USEC_PER_SEC));
343 if (r < 0)
c00c3b64 344 return log_link_error_errno(link, r, "Failed to set default lease time for DHCPv4 server instance: %m");
8fcf1d61
YW
345 }
346
2324fd3a 347 for (sd_dhcp_lease_server_type_t type = 0; type < _SD_DHCP_LEASE_SERVER_TYPE_MAX; type ++) {
2a71d57f
LP
348
349 if (!link->network->dhcp_server_emit[type].emit)
350 continue;
351
352 if (link->network->dhcp_server_emit[type].n_addresses > 0)
353 /* Explicitly specified servers to emit */
354 r = sd_dhcp_server_set_servers(
355 link->dhcp_server,
356 type,
357 link->network->dhcp_server_emit[type].addresses,
358 link->network->dhcp_server_emit[type].n_addresses);
359 else {
360 /* Emission is requested, but nothing explicitly configured. Let's find a suitable upling */
361 if (!acquired_uplink) {
362 uplink = manager_find_uplink(link->manager, link);
363 acquired_uplink = true;
364 }
365
366 if (uplink && uplink->network)
367 r = link_push_uplink_to_dhcp_server(uplink, type, link->dhcp_server);
368 else if (type == SD_DHCP_LEASE_DNS)
369 r = dhcp4_server_set_dns_from_resolve_conf(link);
24e6f458 370 else {
2a71d57f
LP
371 log_link_debug(link,
372 "Not emitting %s on link, couldn't find suitable uplink.",
373 dhcp_lease_server_type_to_string(type));
374 continue;
24e6f458 375 }
299d578f 376 }
284e8fd0 377
2a71d57f
LP
378 if (r < 0)
379 log_link_warning_errno(link, r,
380 "Failed to set %s for DHCP server, ignoring: %m",
381 dhcp_lease_server_type_to_string(type));
382 }
383
8fcf1d61
YW
384 r = sd_dhcp_server_set_emit_router(link->dhcp_server, link->network->dhcp_server_emit_router);
385 if (r < 0)
a0fa3ef7 386 return log_link_error_errno(link, r, "Failed to set router emission for DHCP server: %m");
8fcf1d61 387
c95df587
YA
388 r = sd_dhcp_server_set_relay_target(link->dhcp_server, &link->network->dhcp_server_relay_target);
389 if (r < 0)
390 return log_link_error_errno(link, r, "Failed to set relay target for DHCP server: %m");
391
11c38d3e
YA
392 bind_to_interface = sd_dhcp_server_is_in_relay_mode(link->dhcp_server) ? false : link->network->dhcp_server_bind_to_interface;
393 r = sd_dhcp_server_set_bind_to_interface(link->dhcp_server, bind_to_interface);
394 if (r < 0)
395 return log_link_error_errno(link, r, "Failed to set interface binding for DHCP server: %m");
396
397 r = sd_dhcp_server_set_relay_agent_information(link->dhcp_server, link->network->dhcp_server_relay_agent_circuit_id, link->network->dhcp_server_relay_agent_remote_id);
398 if (r < 0)
399 return log_link_error_errno(link, r, "Failed to set agent circuit/remote id for DHCP server: %m");
400
8fcf1d61
YW
401 if (link->network->dhcp_server_emit_timezone) {
402 _cleanup_free_ char *buffer = NULL;
7b5018ca 403 const char *tz = NULL;
8fcf1d61
YW
404
405 if (link->network->dhcp_server_timezone)
406 tz = link->network->dhcp_server_timezone;
407 else {
408 r = get_timezone(&buffer);
409 if (r < 0)
7b5018ca 410 log_link_warning_errno(link, r, "Failed to determine timezone, not sending timezone: %m");
411 else
412 tz = buffer;
8fcf1d61
YW
413 }
414
7b5018ca 415 if (tz) {
416 r = sd_dhcp_server_set_timezone(link->dhcp_server, tz);
417 if (r < 0)
418 return log_link_error_errno(link, r, "Failed to set timezone for DHCP server: %m");
419 }
8fcf1d61 420 }
564ca984 421
90e74a66 422 ORDERED_HASHMAP_FOREACH(p, link->network->dhcp_server_send_options) {
461dbb2f 423 r = sd_dhcp_server_add_option(link->dhcp_server, p);
564ca984
SS
424 if (r == -EEXIST)
425 continue;
426 if (r < 0)
c00c3b64 427 return log_link_error_errno(link, r, "Failed to set DHCPv4 option: %m");
564ca984
SS
428 }
429
90e74a66 430 ORDERED_HASHMAP_FOREACH(p, link->network->dhcp_server_send_vendor_options) {
7354900d
DW
431 r = sd_dhcp_server_add_vendor_option(link->dhcp_server, p);
432 if (r == -EEXIST)
433 continue;
434 if (r < 0)
435 return log_link_error_errno(link, r, "Failed to set DHCPv4 option: %m");
436 }
437
8fcf1d61
YW
438 if (!sd_dhcp_server_is_running(link->dhcp_server)) {
439 r = sd_dhcp_server_start(link->dhcp_server);
440 if (r < 0)
a0fa3ef7 441 return log_link_error_errno(link, r, "Could not start DHCPv4 server instance: %m");
5ae0fb7f
YW
442
443 log_link_debug(link, "Offering DHCPv4 leases");
8fcf1d61
YW
444 }
445
446 return 0;
447}
448
11c38d3e
YA
449int config_parse_dhcp_server_relay_agent_suboption(
450 const char *unit,
451 const char *filename,
452 unsigned line,
453 const char *section,
454 unsigned section_line,
455 const char *lvalue,
456 int ltype,
457 const char *rvalue,
458 void *data,
459 void *userdata) {
460
461 char **suboption_value = data;
462 char* p;
463
464 assert(filename);
465 assert(lvalue);
466 assert(rvalue);
467
11c38d3e
YA
468 if (isempty(rvalue)) {
469 *suboption_value = mfree(*suboption_value);
470 return 0;
471 }
472
473 p = startswith(rvalue, "string:");
474 if (!p) {
475 log_syntax(unit, LOG_WARNING, filename, line, 0,
476 "Failed to parse %s=%s'. Invalid format, ignoring.", lvalue, rvalue);
477 return 0;
478 }
479 return free_and_strdup(suboption_value, empty_to_null(p));
480}
481
2a71d57f 482int config_parse_dhcp_server_emit(
8fcf1d61
YW
483 const char *unit,
484 const char *filename,
485 unsigned line,
2a71d57f
LP
486 const char *section,
487 unsigned section_line,
8fcf1d61 488 const char *lvalue,
2a71d57f 489 int ltype,
8fcf1d61 490 const char *rvalue,
2a71d57f
LP
491 void *data,
492 void *userdata) {
8fcf1d61 493
2a71d57f
LP
494 NetworkDHCPServerEmitAddress *emit = data;
495
496 assert(emit);
8fcf1d61
YW
497 assert(rvalue);
498
c1997a5b 499 for (const char *p = rvalue;;) {
8fcf1d61
YW
500 _cleanup_free_ char *w = NULL;
501 union in_addr_union a;
c1997a5b 502 int r;
8fcf1d61
YW
503
504 r = extract_first_word(&p, &w, NULL, 0);
505 if (r == -ENOMEM)
506 return log_oom();
507 if (r < 0) {
d96edb2c 508 log_syntax(unit, LOG_WARNING, filename, line, r,
8fcf1d61
YW
509 "Failed to extract word, ignoring: %s", rvalue);
510 return 0;
511 }
512 if (r == 0)
c1997a5b 513 return 0;
8fcf1d61
YW
514
515 r = in_addr_from_string(AF_INET, w, &a);
516 if (r < 0) {
d96edb2c 517 log_syntax(unit, LOG_WARNING, filename, line, r,
c1997a5b 518 "Failed to parse %s= address '%s', ignoring: %m", lvalue, w);
8fcf1d61
YW
519 continue;
520 }
521
2a71d57f 522 struct in_addr *m = reallocarray(emit->addresses, emit->n_addresses + 1, sizeof(struct in_addr));
8fcf1d61
YW
523 if (!m)
524 return log_oom();
525
2a71d57f
LP
526 emit->addresses = m;
527 emit->addresses[emit->n_addresses++] = a.in;
8fcf1d61 528 }
8fcf1d61 529}
0017ba31
YW
530
531int config_parse_dhcp_server_address(
532 const char *unit,
533 const char *filename,
534 unsigned line,
535 const char *section,
536 unsigned section_line,
537 const char *lvalue,
538 int ltype,
539 const char *rvalue,
540 void *data,
541 void *userdata) {
542
543 Network *network = userdata;
544 union in_addr_union a;
545 unsigned char prefixlen;
546 int r;
547
548 assert(filename);
549 assert(lvalue);
550 assert(rvalue);
551
552 if (isempty(rvalue)) {
553 network->dhcp_server_address = (struct in_addr) {};
554 network->dhcp_server_address_prefixlen = 0;
555 return 0;
556 }
557
558 r = in_addr_prefix_from_string(rvalue, AF_INET, &a, &prefixlen);
559 if (r < 0) {
560 log_syntax(unit, LOG_WARNING, filename, line, r,
561 "Failed to parse %s=, ignoring assignment: %s", lvalue, rvalue);
562 return 0;
563 }
564 if (in4_addr_is_null(&a.in) || in4_addr_is_localhost(&a.in)) {
565 log_syntax(unit, LOG_WARNING, filename, line, 0,
566 "DHCP server address cannot be the ANY address or a localhost address, "
567 "ignoring assignment: %s", rvalue);
568 return 0;
569 }
570
571 network->dhcp_server_address = a.in;
572 network->dhcp_server_address_prefixlen = prefixlen;
573 return 0;
574}