]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/network/netdev/vxlan.c
Don't open /var journals in volatile mode when runtime_journal==NULL
[thirdparty/systemd.git] / src / network / netdev / vxlan.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
326cb406 2
326cb406
SS
3#include <net/if.h>
4
85a8eeee 5#include "conf-parser.h"
ea0288d1 6#include "alloc-util.h"
634f0f98 7#include "extract-word.h"
1189c00a 8#include "string-table.h"
d35e5d37
SS
9#include "string-util.h"
10#include "strv.h"
ea0288d1 11#include "parse-util.h"
737f1405 12#include "vxlan.h"
326cb406 13
1189c00a
SS
14static const char* const df_table[_NETDEV_VXLAN_DF_MAX] = {
15 [NETDEV_VXLAN_DF_NO] = "no",
16 [NETDEV_VXLAN_DF_YES] = "yes",
17 [NETDEV_VXLAN_DF_INHERIT] = "inherit",
18};
19
20DEFINE_STRING_TABLE_LOOKUP_WITH_BOOLEAN(df, VxLanDF, NETDEV_VXLAN_DF_YES);
21DEFINE_CONFIG_PARSE_ENUM(config_parse_df, df, VxLanDF, "Failed to parse VXLAN IPDoNotFragment= setting");
22
1c4baffc 23static int netdev_vxlan_fill_message_create(NetDev *netdev, Link *link, sd_netlink_message *m) {
c2353b2f 24 VxLan *v;
326cb406
SS
25 int r;
26
3be1d7e0 27 assert(netdev);
326cb406
SS
28 assert(m);
29
c2353b2f
SS
30 v = VXLAN(netdev);
31
32 assert(v);
326cb406 33
6f213e4a
SS
34 if (v->vni <= VXLAN_VID_MAX) {
35 r = sd_netlink_message_append_u32(m, IFLA_VXLAN_ID, v->vni);
f545680e
SS
36 if (r < 0)
37 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_ID attribute: %m");
326cb406
SS
38 }
39
94876904 40 if (in_addr_is_set(v->group_family, &v->group)) {
7c9b2690
SS
41 if (v->group_family == AF_INET)
42 r = sd_netlink_message_append_in_addr(m, IFLA_VXLAN_GROUP, &v->group.in);
d35e5d37 43 else
7c9b2690 44 r = sd_netlink_message_append_in6_addr(m, IFLA_VXLAN_GROUP6, &v->group.in6);
d35e5d37
SS
45 if (r < 0)
46 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_GROUP attribute: %m");
94876904 47 } else if (in_addr_is_set(v->remote_family, &v->remote)) {
fc1d9c7b
SS
48 if (v->remote_family == AF_INET)
49 r = sd_netlink_message_append_in_addr(m, IFLA_VXLAN_GROUP, &v->remote.in);
50 else
51 r = sd_netlink_message_append_in6_addr(m, IFLA_VXLAN_GROUP6, &v->remote.in6);
52 if (r < 0)
53 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_GROUP attribute: %m");
d35e5d37
SS
54 }
55
94876904 56 if (in_addr_is_set(v->local_family, &v->local)) {
d35e5d37
SS
57 if (v->local_family == AF_INET)
58 r = sd_netlink_message_append_in_addr(m, IFLA_VXLAN_LOCAL, &v->local.in);
59 else
60 r = sd_netlink_message_append_in6_addr(m, IFLA_VXLAN_LOCAL6, &v->local.in6);
d35e5d37
SS
61 if (r < 0)
62 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_LOCAL attribute: %m");
d35e5d37 63 }
326cb406 64
a9b8450b 65 r = sd_netlink_message_append_u32(m, IFLA_VXLAN_LINK, link ? link->ifindex : 0);
f545680e
SS
66 if (r < 0)
67 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_LINK attribute: %m");
326cb406 68
f4a8ca32
SS
69 if (v->inherit) {
70 r = sd_netlink_message_append_flag(m, IFLA_VXLAN_TTL_INHERIT);
71 if (r < 0)
72 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_TTL_INHERIT attribute: %m");
73 } else {
1c4baffc 74 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_TTL, v->ttl);
f545680e
SS
75 if (r < 0)
76 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_TTL attribute: %m");
326cb406
SS
77 }
78
7b3b9822 79 if (v->tos != 0) {
1c4baffc 80 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_TOS, v->tos);
f545680e
SS
81 if (r < 0)
82 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_TOS attribute: %m");
326cb406
SS
83 }
84
1c4baffc 85 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_LEARNING, v->learning);
f545680e
SS
86 if (r < 0)
87 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_LEARNING attribute: %m");
326cb406 88
1c4baffc 89 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_RSC, v->route_short_circuit);
f545680e
SS
90 if (r < 0)
91 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_RSC attribute: %m");
85a8eeee 92
1c4baffc 93 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_PROXY, v->arp_proxy);
f545680e
SS
94 if (r < 0)
95 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_PROXY attribute: %m");
85a8eeee 96
1c4baffc 97 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_L2MISS, v->l2miss);
f545680e
SS
98 if (r < 0)
99 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_L2MISS attribute: %m");
85a8eeee 100
1c4baffc 101 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_L3MISS, v->l3miss);
f545680e
SS
102 if (r < 0)
103 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_L3MISS attribute: %m");
85a8eeee 104
7b3b9822 105 if (v->fdb_ageing != 0) {
1c4baffc 106 r = sd_netlink_message_append_u32(m, IFLA_VXLAN_AGEING, v->fdb_ageing / USEC_PER_SEC);
f545680e
SS
107 if (r < 0)
108 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_AGEING attribute: %m");
85a8eeee
SS
109 }
110
7b3b9822 111 if (v->max_fdb != 0) {
3dbcf579
SS
112 r = sd_netlink_message_append_u32(m, IFLA_VXLAN_LIMIT, v->max_fdb);
113 if (r < 0)
114 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_LIMIT attribute: %m");
115 }
116
1c4baffc 117 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_UDP_CSUM, v->udpcsum);
f545680e
SS
118 if (r < 0)
119 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_UDP_CSUM attribute: %m");
cffacc74 120
1c4baffc 121 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_UDP_ZERO_CSUM6_TX, v->udp6zerocsumtx);
f545680e
SS
122 if (r < 0)
123 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_UDP_ZERO_CSUM6_TX attribute: %m");
cffacc74 124
1c4baffc 125 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_UDP_ZERO_CSUM6_RX, v->udp6zerocsumrx);
f545680e
SS
126 if (r < 0)
127 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_UDP_ZERO_CSUM6_RX attribute: %m");
cffacc74 128
16441027
SS
129 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_REMCSUM_TX, v->remote_csum_tx);
130 if (r < 0)
131 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_REMCSUM_TX attribute: %m");
132
133 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_REMCSUM_RX, v->remote_csum_rx);
134 if (r < 0)
135 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_REMCSUM_RX attribute: %m");
136
ea0288d1
SS
137 r = sd_netlink_message_append_u16(m, IFLA_VXLAN_PORT, htobe16(v->dest_port));
138 if (r < 0)
139 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_PORT attribute: %m");
140
173a6e29 141 if (v->port_range.low != 0 || v->port_range.high != 0) {
ea0288d1
SS
142 struct ifla_vxlan_port_range port_range;
143
144 port_range.low = htobe16(v->port_range.low);
145 port_range.high = htobe16(v->port_range.high);
146
147 r = sd_netlink_message_append_data(m, IFLA_VXLAN_PORT_RANGE, &port_range, sizeof(port_range));
148 if (r < 0)
149 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_PORT_RANGE attribute: %m");
150 }
151
d8653945
SS
152 r = sd_netlink_message_append_u32(m, IFLA_VXLAN_LABEL, htobe32(v->flow_label));
153 if (r < 0)
154 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_LABEL attribute: %m");
155
ea84fd5c
SS
156 if (v->group_policy) {
157 r = sd_netlink_message_append_flag(m, IFLA_VXLAN_GBP);
158 if (r < 0)
159 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_GBP attribute: %m");
160 }
161
4cc0fd75
SS
162 if (v->generic_protocol_extension) {
163 r = sd_netlink_message_append_flag(m, IFLA_VXLAN_GPE);
164 if (r < 0)
165 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_GPE attribute: %m");
166 }
167
1189c00a
SS
168 if (v->df != _NETDEV_VXLAN_DF_INVALID) {
169 r = sd_netlink_message_append_u8(m, IFLA_VXLAN_DF, v->df);
170 if (r < 0)
171 return log_netdev_error_errno(netdev, r, "Could not append IFLA_VXLAN_DF attribute: %m");
172 }
173
326cb406
SS
174 return r;
175}
176
d35e5d37
SS
177int config_parse_vxlan_address(const char *unit,
178 const char *filename,
179 unsigned line,
180 const char *section,
181 unsigned section_line,
182 const char *lvalue,
183 int ltype,
184 const char *rvalue,
185 void *data,
186 void *userdata) {
85a8eeee
SS
187 VxLan *v = userdata;
188 union in_addr_union *addr = data, buffer;
189 int r, f;
190
191 assert(filename);
192 assert(lvalue);
193 assert(rvalue);
194 assert(data);
195
196 r = in_addr_from_string_auto(rvalue, &f, &buffer);
197 if (r < 0) {
d96edb2c 198 log_syntax(unit, LOG_WARNING, filename, line, r, "vxlan '%s' address is invalid, ignoring assignment: %s", lvalue, rvalue);
85a8eeee
SS
199 return 0;
200 }
201
d35e5d37
SS
202 r = in_addr_is_multicast(f, &buffer);
203
bf443be9 204 if (streq(lvalue, "Group")) {
d35e5d37 205 if (r <= 0) {
d96edb2c 206 log_syntax(unit, LOG_WARNING, filename, line, 0, "vxlan %s invalid multicast address, ignoring assignment: %s", lvalue, rvalue);
d35e5d37
SS
207 return 0;
208 }
209
83cb24ac 210 v->group_family = f;
d35e5d37
SS
211 } else {
212 if (r > 0) {
d96edb2c 213 log_syntax(unit, LOG_WARNING, filename, line, 0, "vxlan %s cannot be a multicast address, ignoring assignment: %s", lvalue, rvalue);
d35e5d37
SS
214 return 0;
215 }
216
bf443be9
SS
217 if (streq(lvalue, "Remote"))
218 v->remote_family = f;
219 else
220 v->local_family = f;
85a8eeee
SS
221 }
222
85a8eeee
SS
223 *addr = buffer;
224
225 return 0;
226}
227
ea0288d1
SS
228int config_parse_port_range(const char *unit,
229 const char *filename,
230 unsigned line,
231 const char *section,
232 unsigned section_line,
233 const char *lvalue,
234 int ltype,
235 const char *rvalue,
236 void *data,
237 void *userdata) {
ea0288d1 238 VxLan *v = userdata;
173a6e29 239 uint16_t low, high;
ea0288d1
SS
240 int r;
241
242 assert(filename);
243 assert(lvalue);
244 assert(rvalue);
245 assert(data);
246
173a6e29 247 r = parse_ip_port_range(rvalue, &low, &high);
ea0288d1 248 if (r < 0) {
d96edb2c 249 log_syntax(unit, LOG_WARNING, filename, line, r,
173a6e29 250 "Failed to parse VXLAN port range '%s'. Port should be greater than 0 and less than 65535.", rvalue);
ea0288d1
SS
251 return 0;
252 }
253
254 v->port_range.low = low;
255 v->port_range.high = high;
256
257 return 0;
258}
259
d8653945
SS
260int config_parse_flow_label(const char *unit,
261 const char *filename,
262 unsigned line,
263 const char *section,
264 unsigned section_line,
265 const char *lvalue,
266 int ltype,
267 const char *rvalue,
268 void *data,
269 void *userdata) {
270 VxLan *v = userdata;
271 unsigned f;
272 int r;
273
274 assert(filename);
275 assert(lvalue);
276 assert(rvalue);
277 assert(data);
278
279 r = safe_atou(rvalue, &f);
280 if (r < 0) {
d96edb2c 281 log_syntax(unit, LOG_WARNING, filename, line, r, "Failed to parse VXLAN flow label '%s'.", rvalue);
d8653945
SS
282 return 0;
283 }
284
285 if (f & ~VXLAN_FLOW_LABEL_MAX_MASK) {
d96edb2c 286 log_syntax(unit, LOG_WARNING, filename, line, r,
d8653945
SS
287 "VXLAN flow label '%s' not valid. Flow label range should be [0-1048575].", rvalue);
288 return 0;
289 }
290
291 v->flow_label = f;
292
293 return 0;
294}
295
f4a8ca32
SS
296int config_parse_vxlan_ttl(const char *unit,
297 const char *filename,
298 unsigned line,
299 const char *section,
300 unsigned section_line,
301 const char *lvalue,
302 int ltype,
303 const char *rvalue,
304 void *data,
305 void *userdata) {
306 VxLan *v = userdata;
307 unsigned f;
308 int r;
309
310 assert(filename);
311 assert(lvalue);
312 assert(rvalue);
313 assert(data);
314
315 if (streq(rvalue, "inherit"))
316 v->inherit = true;
317 else {
318 r = safe_atou(rvalue, &f);
319 if (r < 0) {
d96edb2c 320 log_syntax(unit, LOG_WARNING, filename, line, r,
f4a8ca32
SS
321 "Failed to parse VXLAN TTL '%s', ignoring assignment: %m", rvalue);
322 return 0;
323 }
324
325 if (f > 255) {
d96edb2c 326 log_syntax(unit, LOG_WARNING, filename, line, 0,
f4a8ca32
SS
327 "Invalid VXLAN TTL '%s'. TTL must be <= 255. Ignoring assignment.", rvalue);
328 return 0;
329 }
330
331 v->ttl = f;
332 }
333
334 return 0;
335}
336
3be1d7e0 337static int netdev_vxlan_verify(NetDev *netdev, const char *filename) {
aa9f1140
TG
338 VxLan *v = VXLAN(netdev);
339
326cb406 340 assert(netdev);
aa9f1140 341 assert(v);
3be1d7e0 342 assert(filename);
326cb406 343
76fbd4d7
SS
344 if (v->vni > VXLAN_VID_MAX)
345 return log_netdev_warning_errno(netdev, SYNTHETIC_ERRNO(EINVAL),
346 "%s: VXLAN without valid VNI (or VXLAN Segment ID) configured. Ignoring.",
347 filename);
348
349 if (v->ttl > 255)
350 return log_netdev_warning_errno(netdev, SYNTHETIC_ERRNO(EINVAL),
351 "%s: VXLAN TTL must be <= 255. Ignoring.",
352 filename);
326cb406 353
1c8b0ecc
SS
354 if (!v->dest_port && v->generic_protocol_extension)
355 v->dest_port = 4790;
356
94876904 357 if (in_addr_is_set(v->group_family, &v->group) && in_addr_is_set(v->remote_family, &v->remote))
fc1d9c7b
SS
358 return log_netdev_warning_errno(netdev, SYNTHETIC_ERRNO(EINVAL),
359 "%s: VXLAN both 'Group=' and 'Remote=' cannot be specified. Ignoring.",
360 filename);
361
326cb406
SS
362 return 0;
363}
3be1d7e0 364
aa9f1140 365static void vxlan_init(NetDev *netdev) {
c2353b2f 366 VxLan *v;
aa9f1140
TG
367
368 assert(netdev);
c2353b2f
SS
369
370 v = VXLAN(netdev);
371
aa9f1140
TG
372 assert(v);
373
6f213e4a 374 v->vni = VXLAN_VID_MAX + 1;
1189c00a 375 v->df = _NETDEV_VXLAN_DF_INVALID;
aa9f1140 376 v->learning = true;
cffacc74
SS
377 v->udpcsum = false;
378 v->udp6zerocsumtx = false;
379 v->udp6zerocsumrx = false;
aa9f1140
TG
380}
381
3be1d7e0 382const NetDevVTable vxlan_vtable = {
aa9f1140
TG
383 .object_size = sizeof(VxLan),
384 .init = vxlan_init,
130b812f 385 .sections = NETDEV_COMMON_SECTIONS "VXLAN\0",
aa9f1140
TG
386 .fill_message_create = netdev_vxlan_fill_message_create,
387 .create_type = NETDEV_CREATE_STACKED,
3be1d7e0 388 .config_verify = netdev_vxlan_verify,
daf0f8ca 389 .generate_mac = true,
3be1d7e0 390};