2 This file is part of systemd.
4 Copyright 2014 Susant Sahani
6 systemd is free software; you can redistribute it and/or modify it
7 under the terms of the GNU Lesser General Public License as published by
8 the Free Software Foundation; either version 2.1 of the License, or
9 (at your option) any later version.
11 systemd is distributed in the hope that it will be useful, but
12 WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 Lesser General Public License for more details.
16 You should have received a copy of the GNU Lesser General Public License
17 along with systemd; If not, see <http://www.gnu.org/licenses/>.
20 #include <arpa/inet.h>
23 #include <linux/if_tunnel.h>
24 #include <linux/ip6_tunnel.h>
26 #include "sd-netlink.h"
28 #include "conf-parser.h"
30 #include "networkd-link.h"
31 #include "netdev/tunnel.h"
32 #include "parse-util.h"
33 #include "string-table.h"
34 #include "string-util.h"
37 #define DEFAULT_TNL_HOP_LIMIT 64
38 #define IP6_FLOWINFO_FLOWLABEL htobe32(0x000FFFFF)
40 static const char* const ip6tnl_mode_table
[_NETDEV_IP6_TNL_MODE_MAX
] = {
41 [NETDEV_IP6_TNL_MODE_IP6IP6
] = "ip6ip6",
42 [NETDEV_IP6_TNL_MODE_IPIP6
] = "ipip6",
43 [NETDEV_IP6_TNL_MODE_ANYIP6
] = "any",
46 DEFINE_STRING_TABLE_LOOKUP(ip6tnl_mode
, Ip6TnlMode
);
47 DEFINE_CONFIG_PARSE_ENUM(config_parse_ip6tnl_mode
, ip6tnl_mode
, Ip6TnlMode
, "Failed to parse ip6 tunnel Mode");
49 static int netdev_ipip_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
50 Tunnel
*t
= IPIP(netdev
);
56 assert(IN_SET(t
->family
, AF_INET
, AF_UNSPEC
));
59 r
= sd_netlink_message_append_u32(m
, IFLA_IPTUN_LINK
, link
->ifindex
);
61 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LINK attribute: %m");
65 r
= sd_netlink_message_append_in_addr(m
, IFLA_IPTUN_LOCAL
, &t
->local
.in
);
67 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LOCAL attribute: %m");
69 r
= sd_netlink_message_append_in_addr(m
, IFLA_IPTUN_REMOTE
, &t
->remote
.in
);
71 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_REMOTE attribute: %m");
73 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_TTL
, t
->ttl
);
75 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_TTL attribute: %m");
77 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_PMTUDISC
, t
->pmtudisc
);
79 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_PMTUDISC attribute: %m");
84 static int netdev_sit_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
85 Tunnel
*t
= SIT(netdev
);
91 assert(IN_SET(t
->family
, AF_INET
, AF_UNSPEC
));
94 r
= sd_netlink_message_append_u32(m
, IFLA_IPTUN_LINK
, link
->ifindex
);
96 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LINK attribute: %m");
100 r
= sd_netlink_message_append_in_addr(m
, IFLA_IPTUN_LOCAL
, &t
->local
.in
);
102 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LOCAL attribute: %m");
104 r
= sd_netlink_message_append_in_addr(m
, IFLA_IPTUN_REMOTE
, &t
->remote
.in
);
106 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_REMOTE attribute: %m");
108 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_TTL
, t
->ttl
);
110 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_TTL attribute: %m");
112 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_PMTUDISC
, t
->pmtudisc
);
114 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_PMTUDISC attribute: %m");
119 static int netdev_gre_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
125 if (netdev
->kind
== NETDEV_KIND_GRE
)
131 assert(IN_SET(t
->family
, AF_INET
, AF_UNSPEC
));
135 r
= sd_netlink_message_append_u32(m
, IFLA_GRE_LINK
, link
->ifindex
);
137 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_LINK attribute: %m");
140 r
= sd_netlink_message_append_in_addr(m
, IFLA_GRE_LOCAL
, &t
->local
.in
);
142 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_LOCAL attribute: %m");
144 r
= sd_netlink_message_append_in_addr(m
, IFLA_GRE_REMOTE
, &t
->remote
.in
);
146 log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_REMOTE attribute: %m");
148 r
= sd_netlink_message_append_u8(m
, IFLA_GRE_TTL
, t
->ttl
);
150 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_TTL attribute: %m");
152 r
= sd_netlink_message_append_u8(m
, IFLA_GRE_TOS
, t
->tos
);
154 log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_TOS attribute: %m");
156 r
= sd_netlink_message_append_u8(m
, IFLA_GRE_PMTUDISC
, t
->pmtudisc
);
158 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_PMTUDISC attribute: %m");
163 static int netdev_ip6gre_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
169 if (netdev
->kind
== NETDEV_KIND_IP6GRE
)
172 t
= IP6GRETAP(netdev
);
175 assert(t
->family
== AF_INET6
);
179 r
= sd_netlink_message_append_u32(m
, IFLA_GRE_LINK
, link
->ifindex
);
181 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_LINK attribute: %m");
184 r
= sd_netlink_message_append_in6_addr(m
, IFLA_GRE_LOCAL
, &t
->local
.in6
);
186 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_LOCAL attribute: %m");
188 r
= sd_netlink_message_append_in6_addr(m
, IFLA_GRE_REMOTE
, &t
->remote
.in6
);
190 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_REMOTE attribute: %m");
192 r
= sd_netlink_message_append_u8(m
, IFLA_GRE_TTL
, t
->ttl
);
194 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_TTL attribute: %m");
196 if (t
->ipv6_flowlabel
!= _NETDEV_IPV6_FLOWLABEL_INVALID
) {
197 r
= sd_netlink_message_append_u32(m
, IFLA_GRE_FLOWINFO
, t
->ipv6_flowlabel
);
199 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_FLOWINFO attribute: %m");
202 r
= sd_netlink_message_append_u32(m
, IFLA_GRE_FLAGS
, t
->flags
);
204 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_GRE_FLAGS attribute: %m");
209 static int netdev_vti_fill_message_key(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
216 if (netdev
->kind
== NETDEV_KIND_VTI
)
224 ikey
= okey
= htobe32(t
->key
);
226 ikey
= htobe32(t
->ikey
);
227 okey
= htobe32(t
->okey
);
230 r
= sd_netlink_message_append_u32(m
, IFLA_VTI_IKEY
, ikey
);
232 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_VTI_IKEY attribute: %m");
234 r
= sd_netlink_message_append_u32(m
, IFLA_VTI_OKEY
, okey
);
236 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_VTI_OKEY attribute: %m");
241 static int netdev_vti_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
242 Tunnel
*t
= VTI(netdev
);
248 assert(t
->family
== AF_INET
);
251 r
= sd_netlink_message_append_u32(m
, IFLA_VTI_LINK
, link
->ifindex
);
253 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LINK attribute: %m");
256 r
= netdev_vti_fill_message_key(netdev
, link
, m
);
260 r
= sd_netlink_message_append_in_addr(m
, IFLA_VTI_LOCAL
, &t
->local
.in
);
262 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LOCAL attribute: %m");
264 r
= sd_netlink_message_append_in_addr(m
, IFLA_VTI_REMOTE
, &t
->remote
.in
);
266 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_REMOTE attribute: %m");
271 static int netdev_vti6_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
272 Tunnel
*t
= VTI6(netdev
);
278 assert(t
->family
== AF_INET6
);
281 r
= sd_netlink_message_append_u32(m
, IFLA_VTI_LINK
, link
->ifindex
);
283 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LINK attribute: %m");
286 r
= netdev_vti_fill_message_key(netdev
, link
, m
);
290 r
= sd_netlink_message_append_in6_addr(m
, IFLA_VTI_LOCAL
, &t
->local
.in6
);
292 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LOCAL attribute: %m");
294 r
= sd_netlink_message_append_in6_addr(m
, IFLA_VTI_REMOTE
, &t
->remote
.in6
);
296 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_REMOTE attribute: %m");
301 static int netdev_ip6tnl_fill_message_create(NetDev
*netdev
, Link
*link
, sd_netlink_message
*m
) {
302 Tunnel
*t
= IP6TNL(netdev
);
309 assert(t
->family
== AF_INET6
);
312 r
= sd_netlink_message_append_u32(m
, IFLA_IPTUN_LINK
, link
->ifindex
);
314 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LINK attribute: %m");
317 r
= sd_netlink_message_append_in6_addr(m
, IFLA_IPTUN_LOCAL
, &t
->local
.in6
);
319 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_LOCAL attribute: %m");
321 r
= sd_netlink_message_append_in6_addr(m
, IFLA_IPTUN_REMOTE
, &t
->remote
.in6
);
323 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_REMOTE attribute: %m");
325 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_TTL
, t
->ttl
);
327 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_TTL attribute: %m");
329 if (t
->ipv6_flowlabel
!= _NETDEV_IPV6_FLOWLABEL_INVALID
) {
330 r
= sd_netlink_message_append_u32(m
, IFLA_IPTUN_FLOWINFO
, t
->ipv6_flowlabel
);
332 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_FLOWINFO attribute: %m");
336 t
->flags
|= IP6_TNL_F_RCV_DSCP_COPY
;
338 if (t
->encap_limit
!= IPV6_DEFAULT_TNL_ENCAP_LIMIT
) {
339 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_ENCAP_LIMIT
, t
->encap_limit
);
341 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_ENCAP_LIMIT attribute: %m");
344 r
= sd_netlink_message_append_u32(m
, IFLA_IPTUN_FLAGS
, t
->flags
);
346 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_FLAGS attribute: %m");
348 switch (t
->ip6tnl_mode
) {
349 case NETDEV_IP6_TNL_MODE_IP6IP6
:
350 proto
= IPPROTO_IPV6
;
352 case NETDEV_IP6_TNL_MODE_IPIP6
:
353 proto
= IPPROTO_IPIP
;
355 case NETDEV_IP6_TNL_MODE_ANYIP6
:
361 r
= sd_netlink_message_append_u8(m
, IFLA_IPTUN_PROTO
, proto
);
363 return log_netdev_error_errno(netdev
, r
, "Could not append IFLA_IPTUN_MODE attribute: %m");
368 static int netdev_tunnel_verify(NetDev
*netdev
, const char *filename
) {
374 switch (netdev
->kind
) {
375 case NETDEV_KIND_IPIP
:
378 case NETDEV_KIND_SIT
:
381 case NETDEV_KIND_GRE
:
384 case NETDEV_KIND_GRETAP
:
387 case NETDEV_KIND_IP6GRE
:
390 case NETDEV_KIND_IP6GRETAP
:
391 t
= IP6GRETAP(netdev
);
393 case NETDEV_KIND_VTI
:
396 case NETDEV_KIND_VTI6
:
399 case NETDEV_KIND_IP6TNL
:
403 assert_not_reached("Invalid tunnel kind");
408 if (!IN_SET(t
->family
, AF_INET
, AF_INET6
, AF_UNSPEC
)) {
409 log_netdev_error(netdev
,
410 "Tunnel with invalid address family configured in %s. Ignoring", filename
);
414 if (netdev
->kind
== NETDEV_KIND_VTI
&&
415 (t
->family
!= AF_INET
|| in_addr_is_null(t
->family
, &t
->local
))) {
416 log_netdev_error(netdev
,
417 "vti tunnel without a local IPv4 address configured in %s. Ignoring", filename
);
421 if (IN_SET(netdev
->kind
, NETDEV_KIND_VTI6
, NETDEV_KIND_IP6TNL
, NETDEV_KIND_IP6GRE
) &&
422 (t
->family
!= AF_INET6
|| in_addr_is_null(t
->family
, &t
->local
))) {
423 log_netdev_error(netdev
,
424 "vti6/ip6tnl/ip6gre tunnel without a local IPv6 address configured in %s. Ignoring", filename
);
428 if (netdev
->kind
== NETDEV_KIND_IP6TNL
&&
429 t
->ip6tnl_mode
== _NETDEV_IP6_TNL_MODE_INVALID
) {
430 log_netdev_error(netdev
,
431 "ip6tnl without mode configured in %s. Ignoring", filename
);
438 int config_parse_tunnel_address(const char *unit
,
439 const char *filename
,
442 unsigned section_line
,
448 Tunnel
*t
= userdata
;
449 union in_addr_union
*addr
= data
, buffer
;
457 /* This is used to parse addresses on both local and remote ends of the tunnel.
458 * Address families must match.
460 * "any" is a special value which means that the address is unspecified.
463 if (streq(rvalue
, "any")) {
464 *addr
= IN_ADDR_NULL
;
466 /* As a special case, if both the local and remote addresses are
467 * unspecified, also clear the address family.
469 if (t
->family
!= AF_UNSPEC
&&
470 in_addr_is_null(t
->family
, &t
->local
) &&
471 in_addr_is_null(t
->family
, &t
->remote
))
472 t
->family
= AF_UNSPEC
;
476 r
= in_addr_from_string_auto(rvalue
, &f
, &buffer
);
478 log_syntax(unit
, LOG_ERR
, filename
, line
, r
,
479 "Tunnel address \"%s\" invalid, ignoring assignment: %m", rvalue
);
483 if (t
->family
!= AF_UNSPEC
&& t
->family
!= f
) {
484 log_syntax(unit
, LOG_ERR
, filename
, line
, 0,
485 "Tunnel addresses incompatible, ignoring assignment: %s", rvalue
);
494 int config_parse_tunnel_key(const char *unit
,
495 const char *filename
,
498 unsigned section_line
,
504 union in_addr_union buffer
;
505 Tunnel
*t
= userdata
;
514 r
= in_addr_from_string(AF_INET
, rvalue
, &buffer
);
516 r
= safe_atou32(rvalue
, &k
);
518 log_syntax(unit
, LOG_ERR
, filename
, line
, 0, "Failed to parse tunnel key ignoring assignment: %s", rvalue
);
522 k
= be32toh(buffer
.in
.s_addr
);
524 if (streq(lvalue
, "Key"))
526 else if (streq(lvalue
, "InputKey"))
534 int config_parse_ipv6_flowlabel(const char* unit
,
535 const char *filename
,
538 unsigned section_line
,
544 IPv6FlowLabel
*ipv6_flowlabel
= data
;
545 Tunnel
*t
= userdata
;
552 assert(ipv6_flowlabel
);
554 if (streq(rvalue
, "inherit")) {
555 *ipv6_flowlabel
= IP6_FLOWINFO_FLOWLABEL
;
556 t
->flags
|= IP6_TNL_F_USE_ORIG_FLOWLABEL
;
558 r
= config_parse_int(unit
, filename
, line
, section
, section_line
, lvalue
, ltype
, rvalue
, &k
, userdata
);
563 log_syntax(unit
, LOG_ERR
, filename
, line
, 0, "Failed to parse IPv6 flowlabel option, ignoring: %s", rvalue
);
565 *ipv6_flowlabel
= htobe32(k
) & IP6_FLOWINFO_FLOWLABEL
;
566 t
->flags
&= ~IP6_TNL_F_USE_ORIG_FLOWLABEL
;
573 int config_parse_encap_limit(const char* unit
,
574 const char *filename
,
577 unsigned section_line
,
583 Tunnel
*t
= userdata
;
591 if (streq(rvalue
, "none"))
592 t
->flags
|= IP6_TNL_F_IGN_ENCAP_LIMIT
;
594 r
= safe_atoi(rvalue
, &k
);
596 log_syntax(unit
, LOG_ERR
, filename
, line
, r
, "Failed to parse Tunnel Encapsulation Limit option, ignoring: %s", rvalue
);
600 if (k
> 255 || k
< 0)
601 log_syntax(unit
, LOG_ERR
, filename
, line
, 0, "Invalid Tunnel Encapsulation value, ignoring: %d", k
);
604 t
->flags
&= ~IP6_TNL_F_IGN_ENCAP_LIMIT
;
611 static void ipip_init(NetDev
*n
) {
620 static void sit_init(NetDev
*n
) {
629 static void vti_init(NetDev
*n
) {
634 if (n
->kind
== NETDEV_KIND_VTI
)
644 static void gre_init(NetDev
*n
) {
649 if (n
->kind
== NETDEV_KIND_GRE
)
659 static void ip6gre_init(NetDev
*n
) {
664 if (n
->kind
== NETDEV_KIND_IP6GRE
)
671 t
->ttl
= DEFAULT_TNL_HOP_LIMIT
;
674 static void ip6tnl_init(NetDev
*n
) {
675 Tunnel
*t
= IP6TNL(n
);
680 t
->ttl
= DEFAULT_TNL_HOP_LIMIT
;
681 t
->encap_limit
= IPV6_DEFAULT_TNL_ENCAP_LIMIT
;
682 t
->ip6tnl_mode
= _NETDEV_IP6_TNL_MODE_INVALID
;
683 t
->ipv6_flowlabel
= _NETDEV_IPV6_FLOWLABEL_INVALID
;
686 const NetDevVTable ipip_vtable
= {
687 .object_size
= sizeof(Tunnel
),
689 .sections
= "Match\0NetDev\0Tunnel\0",
690 .fill_message_create
= netdev_ipip_fill_message_create
,
691 .create_type
= NETDEV_CREATE_STACKED
,
692 .config_verify
= netdev_tunnel_verify
,
695 const NetDevVTable sit_vtable
= {
696 .object_size
= sizeof(Tunnel
),
698 .sections
= "Match\0NetDev\0Tunnel\0",
699 .fill_message_create
= netdev_sit_fill_message_create
,
700 .create_type
= NETDEV_CREATE_STACKED
,
701 .config_verify
= netdev_tunnel_verify
,
704 const NetDevVTable vti_vtable
= {
705 .object_size
= sizeof(Tunnel
),
707 .sections
= "Match\0NetDev\0Tunnel\0",
708 .fill_message_create
= netdev_vti_fill_message_create
,
709 .create_type
= NETDEV_CREATE_STACKED
,
710 .config_verify
= netdev_tunnel_verify
,
713 const NetDevVTable vti6_vtable
= {
714 .object_size
= sizeof(Tunnel
),
716 .sections
= "Match\0NetDev\0Tunnel\0",
717 .fill_message_create
= netdev_vti6_fill_message_create
,
718 .create_type
= NETDEV_CREATE_STACKED
,
719 .config_verify
= netdev_tunnel_verify
,
722 const NetDevVTable gre_vtable
= {
723 .object_size
= sizeof(Tunnel
),
725 .sections
= "Match\0NetDev\0Tunnel\0",
726 .fill_message_create
= netdev_gre_fill_message_create
,
727 .create_type
= NETDEV_CREATE_STACKED
,
728 .config_verify
= netdev_tunnel_verify
,
731 const NetDevVTable gretap_vtable
= {
732 .object_size
= sizeof(Tunnel
),
734 .sections
= "Match\0NetDev\0Tunnel\0",
735 .fill_message_create
= netdev_gre_fill_message_create
,
736 .create_type
= NETDEV_CREATE_STACKED
,
737 .config_verify
= netdev_tunnel_verify
,
740 const NetDevVTable ip6gre_vtable
= {
741 .object_size
= sizeof(Tunnel
),
743 .sections
= "Match\0NetDev\0Tunnel\0",
744 .fill_message_create
= netdev_ip6gre_fill_message_create
,
745 .create_type
= NETDEV_CREATE_STACKED
,
746 .config_verify
= netdev_tunnel_verify
,
749 const NetDevVTable ip6gretap_vtable
= {
750 .object_size
= sizeof(Tunnel
),
752 .sections
= "Match\0NetDev\0Tunnel\0",
753 .fill_message_create
= netdev_ip6gre_fill_message_create
,
754 .create_type
= NETDEV_CREATE_STACKED
,
755 .config_verify
= netdev_tunnel_verify
,
758 const NetDevVTable ip6tnl_vtable
= {
759 .object_size
= sizeof(Tunnel
),
761 .sections
= "Match\0NetDev\0Tunnel\0",
762 .fill_message_create
= netdev_ip6tnl_fill_message_create
,
763 .create_type
= NETDEV_CREATE_STACKED
,
764 .config_verify
= netdev_tunnel_verify
,