]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/network/networkd-manager.c
core: apply WorkingDirectory after enforce_user
[thirdparty/systemd.git] / src / network / networkd-manager.c
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
f579559b 2
091a364c 3#include <sys/socket.h>
bbf7c048 4#include <linux/if.h>
bce67bbe 5#include <linux/fib_rules.h>
0d536673 6#include <stdio_ext.h>
3bef724f 7
fc2f9534 8#include "sd-daemon.h"
07630cea 9#include "sd-netlink.h"
fc2f9534 10
b5efdb8a 11#include "alloc-util.h"
a97dcc12 12#include "bus-util.h"
07630cea 13#include "conf-parser.h"
a97dcc12 14#include "def.h"
482d1aeb 15#include "dns-domain.h"
3ffd4af2 16#include "fd-util.h"
0d39fa9c 17#include "fileio.h"
4f5f911e 18#include "local-addresses.h"
07630cea 19#include "netlink-util.h"
23f53b99 20#include "networkd-manager.h"
00616955 21#include "ordered-set.h"
07630cea
LP
22#include "path-util.h"
23#include "set.h"
07630cea 24#include "virt.h"
505f8da7 25
be660c37
AR
26/* use 8 MB for receive socket kernel queue. */
27#define RCVBUF_SIZE (8*1024*1024)
28
2ad8416d
ZJS
29const char* const network_dirs[] = {
30 "/etc/systemd/network",
31 "/run/systemd/network",
32 "/usr/lib/systemd/network",
349cc4a5 33#if HAVE_SPLIT_USR
2ad8416d
ZJS
34 "/lib/systemd/network",
35#endif
36 NULL};
37
11bf3cce
LP
38static int setup_default_address_pool(Manager *m) {
39 AddressPool *p;
40 int r;
41
42 assert(m);
43
44 /* Add in the well-known private address ranges. */
45
46 r = address_pool_new_from_string(m, &p, AF_INET6, "fc00::", 7);
47 if (r < 0)
48 return r;
49
50 r = address_pool_new_from_string(m, &p, AF_INET, "192.168.0.0", 16);
51 if (r < 0)
52 return r;
53
54 r = address_pool_new_from_string(m, &p, AF_INET, "172.16.0.0", 12);
55 if (r < 0)
56 return r;
57
58 r = address_pool_new_from_string(m, &p, AF_INET, "10.0.0.0", 8);
59 if (r < 0)
60 return r;
61
62 return 0;
63}
64
9c0a72f9
TG
65static int manager_reset_all(Manager *m) {
66 Link *link;
67 Iterator i;
68 int r;
69
70 assert(m);
71
72 HASHMAP_FOREACH(link, m->links, i) {
73 r = link_carrier_reset(link);
74 if (r < 0)
2f3cf1f9 75 log_link_warning_errno(link, r, "Could not reset carrier: %m");
9c0a72f9
TG
76 }
77
78 return 0;
79}
80
19070062 81static int match_prepare_for_sleep(sd_bus_message *message, void *userdata, sd_bus_error *ret_error) {
9c0a72f9
TG
82 Manager *m = userdata;
83 int b, r;
84
19070062 85 assert(message);
d7afd945 86 assert(m);
9c0a72f9
TG
87
88 r = sd_bus_message_read(message, "b", &b);
89 if (r < 0) {
90 log_debug_errno(r, "Failed to parse PrepareForSleep signal: %m");
91 return 0;
92 }
93
94 if (b)
95 return 0;
96
97 log_debug("Coming back from suspend, resetting all connections...");
98
e1694a75 99 (void) manager_reset_all(m);
9c0a72f9
TG
100
101 return 0;
102}
103
d7afd945
LP
104static int on_connected(sd_bus_message *message, void *userdata, sd_bus_error *ret_error) {
105 Manager *m = userdata;
9c0a72f9 106
d7afd945 107 assert(message);
9c0a72f9
TG
108 assert(m);
109
d7afd945
LP
110 /* Did we get a timezone or transient hostname from DHCP while D-Bus wasn't up yet? */
111 if (m->dynamic_hostname)
112 (void) manager_set_hostname(m, m->dynamic_hostname);
113 if (m->dynamic_timezone)
114 (void) manager_set_timezone(m, m->dynamic_timezone);
27dfc982
YW
115 if (m->links_requesting_uuid)
116 (void) manager_request_product_uuid(m, NULL);
9c0a72f9 117
d7afd945
LP
118 return 0;
119}
9c0a72f9 120
d7afd945
LP
121int manager_connect_bus(Manager *m) {
122 int r;
123
124 assert(m);
9c0a72f9 125
d7afd945 126 if (m->bus)
9c0a72f9 127 return 0;
7d6884b6 128
621e4509 129 r = bus_open_system_watch_bind_with_description(&m->bus, "bus-api-network");
9c0a72f9 130 if (r < 0)
d7afd945 131 return log_error_errno(r, "Failed to connect to bus: %m");
9c0a72f9 132
e331e246
TG
133 r = sd_bus_add_object_vtable(m->bus, NULL, "/org/freedesktop/network1", "org.freedesktop.network1.Manager", manager_vtable, m);
134 if (r < 0)
135 return log_error_errno(r, "Failed to add manager object vtable: %m");
136
137 r = sd_bus_add_fallback_vtable(m->bus, NULL, "/org/freedesktop/network1/link", "org.freedesktop.network1.Link", link_vtable, link_object_find, m);
138 if (r < 0)
139 return log_error_errno(r, "Failed to add link object vtable: %m");
140
141 r = sd_bus_add_node_enumerator(m->bus, NULL, "/org/freedesktop/network1/link", link_node_enumerator, m);
142 if (r < 0)
143 return log_error_errno(r, "Failed to add link enumerator: %m");
3175fcde
TG
144
145 r = sd_bus_add_fallback_vtable(m->bus, NULL, "/org/freedesktop/network1/network", "org.freedesktop.network1.Network", network_vtable, network_object_find, m);
146 if (r < 0)
147 return log_error_errno(r, "Failed to add network object vtable: %m");
148
149 r = sd_bus_add_node_enumerator(m->bus, NULL, "/org/freedesktop/network1/network", network_node_enumerator, m);
150 if (r < 0)
151 return log_error_errno(r, "Failed to add network enumerator: %m");
e331e246 152
696fc836 153 r = sd_bus_request_name_async(m->bus, NULL, "org.freedesktop.network1", 0, NULL, NULL);
e331e246 154 if (r < 0)
0c0b9306 155 return log_error_errno(r, "Failed to request name: %m");
e331e246
TG
156
157 r = sd_bus_attach_event(m->bus, m->event, 0);
158 if (r < 0)
159 return log_error_errno(r, "Failed to attach bus to event loop: %m");
160
d7afd945
LP
161 r = sd_bus_match_signal_async(
162 m->bus,
cad43595 163 NULL,
d7afd945
LP
164 "org.freedesktop.DBus.Local",
165 NULL,
166 "org.freedesktop.DBus.Local",
167 "Connected",
168 on_connected, NULL, m);
169 if (r < 0)
170 return log_error_errno(r, "Failed to request match on Connected signal: %m");
171
172 r = sd_bus_match_signal_async(
173 m->bus,
cad43595 174 NULL,
d7afd945
LP
175 "org.freedesktop.login1",
176 "/org/freedesktop/login1",
177 "org.freedesktop.login1.Manager",
178 "PrepareForSleep",
179 match_prepare_for_sleep, NULL, m);
180 if (r < 0)
181 log_warning_errno(r, "Failed to request match for PrepareForSleep, ignoring: %m");
7901cea1 182
9c0a72f9
TG
183 return 0;
184}
185
d2ebf952
YW
186static int manager_udev_process_link(sd_device_monitor *monitor, sd_device *device, void *userdata) {
187 Manager *m = userdata;
51517f9e 188 const char *action;
5fae368b
TG
189 Link *link = NULL;
190 int r, ifindex;
5544ee85 191
5fae368b
TG
192 assert(m);
193 assert(device);
5544ee85 194
51517f9e
YW
195 r = sd_device_get_property_value(device, "ACTION", &action);
196 if (r < 0 || !streq_ptr(action, "add"))
5fae368b 197 return 0;
5544ee85 198
51517f9e 199 r = sd_device_get_ifindex(device, &ifindex);
7606377e
YW
200 if (r < 0) {
201 log_debug_errno(r, "Ignoring udev ADD event for device without ifindex or with invalid ifindex: %m");
5fae368b 202 return 0;
5544ee85
TG
203 }
204
5fae368b 205 r = link_get(m, ifindex, &link);
d2ebf952
YW
206 if (r < 0) {
207 if (r != -ENODEV)
208 log_debug_errno(r, "Failed to get link from ifindex %i, ignoring: %m", ifindex);
5fae368b 209 return 0;
d2ebf952 210 }
02b59d57 211
d2ebf952 212 (void) link_initialized(link, device);
e1694a75 213
f579559b
TG
214 return 0;
215}
216
5fae368b
TG
217static int manager_connect_udev(Manager *m) {
218 int r;
f579559b 219
5fae368b
TG
220 /* udev does not initialize devices inside containers,
221 * so we rely on them being already initialized before
222 * entering the container */
75f86906 223 if (detect_container() > 0)
5fae368b 224 return 0;
f579559b 225
d2ebf952 226 r = sd_device_monitor_new(&m->device_monitor);
02b59d57 227 if (r < 0)
d2ebf952 228 return log_error_errno(r, "Failed to initialize device monitor: %m");
02b59d57 229
d2ebf952
YW
230 r = sd_device_monitor_filter_add_match_subsystem_devtype(m->device_monitor, "net", NULL);
231 if (r < 0)
232 return log_error_errno(r, "Could not add device monitor filter: %m");
505f8da7 233
d2ebf952 234 r = sd_device_monitor_attach_event(m->device_monitor, m->event, 0);
5fae368b 235 if (r < 0)
d2ebf952 236 return log_error_errno(r, "Failed to attach event to device monitor: %m");
505f8da7 237
d2ebf952 238 r = sd_device_monitor_start(m->device_monitor, manager_udev_process_link, m, "networkd-device-monitor");
505f8da7 239 if (r < 0)
d2ebf952 240 return log_error_errno(r, "Failed to start device monitor: %m");
11a7f229 241
505f8da7
TG
242 return 0;
243}
f579559b 244
1c8e710c
TG
245int manager_rtnl_process_route(sd_netlink *rtnl, sd_netlink_message *message, void *userdata) {
246 Manager *m = userdata;
247 Link *link = NULL;
248 uint16_t type;
249 uint32_t ifindex, priority = 0;
983226f3 250 unsigned char protocol, scope, tos, table, rt_type;
1c8e710c
TG
251 int family;
252 unsigned char dst_prefixlen, src_prefixlen;
253 union in_addr_union dst = {}, gw = {}, src = {}, prefsrc = {};
254 Route *route = NULL;
255 int r;
256
257 assert(rtnl);
258 assert(message);
259 assert(m);
260
261 if (sd_netlink_message_is_error(message)) {
262 r = sd_netlink_message_get_errno(message);
263 if (r < 0)
e1694a75 264 log_warning_errno(r, "rtnl: failed to receive route, ignoring: %m");
1c8e710c
TG
265
266 return 0;
267 }
268
269 r = sd_netlink_message_get_type(message, &type);
270 if (r < 0) {
e1694a75 271 log_warning_errno(r, "rtnl: could not get message type, ignoring: %m");
1c8e710c 272 return 0;
25a1bffc 273 } else if (!IN_SET(type, RTM_NEWROUTE, RTM_DELROUTE)) {
e1694a75 274 log_warning("rtnl: received unexpected message type when processing route, ignoring");
1c8e710c
TG
275 return 0;
276 }
277
278 r = sd_netlink_message_read_u32(message, RTA_OIF, &ifindex);
279 if (r == -ENODATA) {
280 log_debug("rtnl: received route without ifindex, ignoring");
281 return 0;
282 } else if (r < 0) {
283 log_warning_errno(r, "rtnl: could not get ifindex from route, ignoring: %m");
284 return 0;
285 } else if (ifindex <= 0) {
286 log_warning("rtnl: received route message with invalid ifindex, ignoring: %d", ifindex);
287 return 0;
288 } else {
289 r = link_get(m, ifindex, &link);
290 if (r < 0 || !link) {
291 /* when enumerating we might be out of sync, but we will
292 * get the route again, so just ignore it */
293 if (!m->enumerating)
294 log_warning("rtnl: received route for nonexistent link (%d), ignoring", ifindex);
295 return 0;
296 }
297 }
298
299 r = sd_rtnl_message_route_get_family(message, &family);
300 if (r < 0 || !IN_SET(family, AF_INET, AF_INET6)) {
e1694a75 301 log_link_warning(link, "rtnl: received address with invalid family, ignoring");
1c8e710c
TG
302 return 0;
303 }
304
305 r = sd_rtnl_message_route_get_protocol(message, &protocol);
306 if (r < 0) {
307 log_warning_errno(r, "rtnl: could not get route protocol: %m");
308 return 0;
309 }
310
311 switch (family) {
312 case AF_INET:
313 r = sd_netlink_message_read_in_addr(message, RTA_DST, &dst.in);
314 if (r < 0 && r != -ENODATA) {
315 log_link_warning_errno(link, r, "rtnl: received route without valid destination, ignoring: %m");
316 return 0;
317 }
318
319 r = sd_netlink_message_read_in_addr(message, RTA_GATEWAY, &gw.in);
320 if (r < 0 && r != -ENODATA) {
321 log_link_warning_errno(link, r, "rtnl: received route with invalid gateway, ignoring: %m");
322 return 0;
323 }
324
325 r = sd_netlink_message_read_in_addr(message, RTA_SRC, &src.in);
326 if (r < 0 && r != -ENODATA) {
327 log_link_warning_errno(link, r, "rtnl: received route with invalid source, ignoring: %m");
328 return 0;
329 }
330
331 r = sd_netlink_message_read_in_addr(message, RTA_PREFSRC, &prefsrc.in);
332 if (r < 0 && r != -ENODATA) {
333 log_link_warning_errno(link, r, "rtnl: received route with invalid preferred source, ignoring: %m");
334 return 0;
335 }
336
337 break;
338
339 case AF_INET6:
340 r = sd_netlink_message_read_in6_addr(message, RTA_DST, &dst.in6);
341 if (r < 0 && r != -ENODATA) {
342 log_link_warning_errno(link, r, "rtnl: received route without valid destination, ignoring: %m");
343 return 0;
344 }
345
346 r = sd_netlink_message_read_in6_addr(message, RTA_GATEWAY, &gw.in6);
347 if (r < 0 && r != -ENODATA) {
348 log_link_warning_errno(link, r, "rtnl: received route with invalid gateway, ignoring: %m");
349 return 0;
350 }
351
352 r = sd_netlink_message_read_in6_addr(message, RTA_SRC, &src.in6);
353 if (r < 0 && r != -ENODATA) {
354 log_link_warning_errno(link, r, "rtnl: received route with invalid source, ignoring: %m");
355 return 0;
356 }
357
358 r = sd_netlink_message_read_in6_addr(message, RTA_PREFSRC, &prefsrc.in6);
359 if (r < 0 && r != -ENODATA) {
360 log_link_warning_errno(link, r, "rtnl: received route with invalid preferred source, ignoring: %m");
361 return 0;
362 }
363
364 break;
365
366 default:
74dead34 367 assert_not_reached("Received unsupported address family");
1c8e710c
TG
368 return 0;
369 }
370
371 r = sd_rtnl_message_route_get_dst_prefixlen(message, &dst_prefixlen);
372 if (r < 0) {
373 log_link_warning_errno(link, r, "rtnl: received route with invalid destination prefixlen, ignoring: %m");
374 return 0;
375 }
376
377 r = sd_rtnl_message_route_get_src_prefixlen(message, &src_prefixlen);
378 if (r < 0) {
379 log_link_warning_errno(link, r, "rtnl: received route with invalid source prefixlen, ignoring: %m");
380 return 0;
381 }
382
383 r = sd_rtnl_message_route_get_scope(message, &scope);
384 if (r < 0) {
385 log_link_warning_errno(link, r, "rtnl: received route with invalid scope, ignoring: %m");
386 return 0;
387 }
388
389 r = sd_rtnl_message_route_get_tos(message, &tos);
390 if (r < 0) {
391 log_link_warning_errno(link, r, "rtnl: received route with invalid tos, ignoring: %m");
392 return 0;
393 }
394
983226f3
SS
395 r = sd_rtnl_message_route_get_type(message, &rt_type);
396 if (r < 0) {
397 log_link_warning_errno(link, r, "rtnl: received route with invalid type, ignoring: %m");
398 return 0;
399 }
400
1c8e710c
TG
401 r = sd_rtnl_message_route_get_table(message, &table);
402 if (r < 0) {
403 log_link_warning_errno(link, r, "rtnl: received route with invalid table, ignoring: %m");
404 return 0;
405 }
406
407 r = sd_netlink_message_read_u32(message, RTA_PRIORITY, &priority);
408 if (r < 0 && r != -ENODATA) {
409 log_link_warning_errno(link, r, "rtnl: received route with invalid priority, ignoring: %m");
410 return 0;
411 }
412
e1694a75 413 (void) route_get(link, family, &dst, dst_prefixlen, tos, priority, table, &route);
1c8e710c
TG
414
415 switch (type) {
416 case RTM_NEWROUTE:
417 if (!route) {
418 /* A route appeared that we did not request */
419 r = route_add_foreign(link, family, &dst, dst_prefixlen, tos, priority, table, &route);
e1694a75
YW
420 if (r < 0) {
421 log_link_warning_errno(link, r, "Failed to add route, ignoring: %m");
1c8e710c 422 return 0;
e1694a75 423 }
1c8e710c
TG
424 }
425
bbd15900 426 route_update(route, &src, src_prefixlen, &gw, &prefsrc, scope, protocol, rt_type);
1c8e710c
TG
427
428 break;
429
430 case RTM_DELROUTE:
b9642f41 431 route_free(route);
1c8e710c 432 break;
b9642f41 433
1c8e710c
TG
434 default:
435 assert_not_reached("Received invalid RTNL message type");
436 }
437
438 return 1;
439}
440
200a0868
TG
441int manager_rtnl_process_address(sd_netlink *rtnl, sd_netlink_message *message, void *userdata) {
442 Manager *m = userdata;
443 Link *link = NULL;
444 uint16_t type;
200a0868 445 unsigned char flags;
054f0db4
TG
446 int family;
447 unsigned char prefixlen;
448 unsigned char scope;
449 union in_addr_union in_addr;
450 struct ifa_cacheinfo cinfo;
451 Address *address = NULL;
200a0868
TG
452 char buf[INET6_ADDRSTRLEN], valid_buf[FORMAT_TIMESPAN_MAX];
453 const char *valid_str = NULL;
454 int r, ifindex;
455
456 assert(rtnl);
457 assert(message);
458 assert(m);
459
460 if (sd_netlink_message_is_error(message)) {
461 r = sd_netlink_message_get_errno(message);
462 if (r < 0)
e1694a75 463 log_warning_errno(r, "rtnl: failed to receive address, ignoring: %m");
200a0868
TG
464
465 return 0;
466 }
467
468 r = sd_netlink_message_get_type(message, &type);
469 if (r < 0) {
e1694a75 470 log_warning_errno(r, "rtnl: could not get message type, ignoring: %m");
200a0868 471 return 0;
25a1bffc 472 } else if (!IN_SET(type, RTM_NEWADDR, RTM_DELADDR)) {
e1694a75 473 log_warning("rtnl: received unexpected message type when processing address, ignoring");
200a0868
TG
474 return 0;
475 }
476
477 r = sd_rtnl_message_addr_get_ifindex(message, &ifindex);
478 if (r < 0) {
e1694a75 479 log_warning_errno(r, "rtnl: could not get ifindex from address, ignoring: %m");
200a0868
TG
480 return 0;
481 } else if (ifindex <= 0) {
e1694a75 482 log_warning("rtnl: received address message with invalid ifindex, ignoring: %d", ifindex);
200a0868
TG
483 return 0;
484 } else {
485 r = link_get(m, ifindex, &link);
486 if (r < 0 || !link) {
487 /* when enumerating we might be out of sync, but we will
488 * get the address again, so just ignore it */
489 if (!m->enumerating)
490 log_warning("rtnl: received address for nonexistent link (%d), ignoring", ifindex);
491 return 0;
492 }
493 }
494
054f0db4
TG
495 r = sd_rtnl_message_addr_get_family(message, &family);
496 if (r < 0 || !IN_SET(family, AF_INET, AF_INET6)) {
e1694a75 497 log_link_warning(link, "rtnl: received address with invalid family, ignoring");
200a0868
TG
498 return 0;
499 }
500
054f0db4 501 r = sd_rtnl_message_addr_get_prefixlen(message, &prefixlen);
200a0868
TG
502 if (r < 0) {
503 log_link_warning_errno(link, r, "rtnl: received address with invalid prefixlen, ignoring: %m");
504 return 0;
505 }
506
054f0db4 507 r = sd_rtnl_message_addr_get_scope(message, &scope);
200a0868
TG
508 if (r < 0) {
509 log_link_warning_errno(link, r, "rtnl: received address with invalid scope, ignoring: %m");
510 return 0;
511 }
512
513 r = sd_rtnl_message_addr_get_flags(message, &flags);
514 if (r < 0) {
515 log_link_warning_errno(link, r, "rtnl: received address with invalid flags, ignoring: %m");
516 return 0;
517 }
200a0868 518
054f0db4 519 switch (family) {
200a0868 520 case AF_INET:
054f0db4 521 r = sd_netlink_message_read_in_addr(message, IFA_LOCAL, &in_addr.in);
200a0868
TG
522 if (r < 0) {
523 log_link_warning_errno(link, r, "rtnl: received address without valid address, ignoring: %m");
524 return 0;
525 }
526
527 break;
528
529 case AF_INET6:
054f0db4 530 r = sd_netlink_message_read_in6_addr(message, IFA_ADDRESS, &in_addr.in6);
200a0868
TG
531 if (r < 0) {
532 log_link_warning_errno(link, r, "rtnl: received address without valid address, ignoring: %m");
533 return 0;
534 }
535
536 break;
537
538 default:
e1694a75 539 assert_not_reached("Received unsupported address family");
200a0868
TG
540 }
541
054f0db4 542 if (!inet_ntop(family, &in_addr, buf, INET6_ADDRSTRLEN)) {
e1694a75 543 log_link_warning(link, "Could not print address, ignoring");
200a0868
TG
544 return 0;
545 }
546
054f0db4 547 r = sd_netlink_message_read_cache_info(message, IFA_CACHEINFO, &cinfo);
e1694a75
YW
548 if (r < 0 && r != -ENODATA) {
549 log_link_warning_errno(link, r, "rtnl: cannot get IFA_CACHEINFO attribute, ignoring: %m");
550 return 0;
551 } else if (r >= 0) {
4058d339 552 if (cinfo.ifa_valid != CACHE_INFO_INFINITY_LIFE_TIME)
200a0868 553 valid_str = format_timespan(valid_buf, FORMAT_TIMESPAN_MAX,
054f0db4 554 cinfo.ifa_valid * USEC_PER_SEC,
200a0868
TG
555 USEC_PER_SEC);
556 }
557
e1694a75 558 (void) address_get(link, family, &in_addr, prefixlen, &address);
200a0868
TG
559
560 switch (type) {
561 case RTM_NEWADDR:
36c32f61 562 if (address)
4058d339 563 log_link_debug(link, "Updating address: %s/%u (valid %s%s)", buf, prefixlen,
87e4e28d 564 valid_str ? "for " : "forever", strempty(valid_str));
36c32f61 565 else {
adda1ed9
TG
566 /* An address appeared that we did not request */
567 r = address_add_foreign(link, family, &in_addr, prefixlen, &address);
cf1d700d 568 if (r < 0) {
e1694a75 569 log_link_warning_errno(link, r, "Failed to add address %s/%u, ignoring: %m", buf, prefixlen);
cf1d700d
TG
570 return 0;
571 } else
4058d339 572 log_link_debug(link, "Adding address: %s/%u (valid %s%s)", buf, prefixlen,
87e4e28d 573 valid_str ? "for " : "forever", strempty(valid_str));
200a0868
TG
574 }
575
e1694a75
YW
576 r = address_update(address, flags, scope, &cinfo);
577 if (r < 0) {
578 log_link_warning_errno(link, r, "Failed to update address %s/%u, ignoring: %m", buf, prefixlen);
579 return 0;
580 }
36c32f61 581
200a0868
TG
582 break;
583
584 case RTM_DELADDR:
585
054f0db4 586 if (address) {
4058d339 587 log_link_debug(link, "Removing address: %s/%u (valid %s%s)", buf, prefixlen,
87e4e28d 588 valid_str ? "for " : "forever", strempty(valid_str));
e1694a75 589 (void) address_drop(address);
200a0868 590 } else
e1694a75 591 log_link_warning(link, "Removing non-existent address: %s/%u (valid %s%s), ignoring", buf, prefixlen,
87e4e28d 592 valid_str ? "for " : "forever", strempty(valid_str));
200a0868
TG
593
594 break;
595 default:
596 assert_not_reached("Received invalid RTNL message type");
597 }
598
599 return 1;
600}
601
1c4baffc 602static int manager_rtnl_process_link(sd_netlink *rtnl, sd_netlink_message *message, void *userdata) {
505f8da7
TG
603 Manager *m = userdata;
604 Link *link = NULL;
4d473d5d 605 NetDev *netdev = NULL;
f2236469 606 uint16_t type;
ca4e095a 607 const char *name;
505f8da7 608 int r, ifindex;
f579559b 609
505f8da7
TG
610 assert(rtnl);
611 assert(message);
f579559b
TG
612 assert(m);
613
1c4baffc
TG
614 if (sd_netlink_message_is_error(message)) {
615 r = sd_netlink_message_get_errno(message);
45af44d4 616 if (r < 0)
e1694a75 617 log_warning_errno(r, "rtnl: Could not receive link, ignoring: %m");
45af44d4
TG
618
619 return 0;
620 }
621
1c4baffc 622 r = sd_netlink_message_get_type(message, &type);
f2236469 623 if (r < 0) {
e1694a75 624 log_warning_errno(r, "rtnl: Could not get message type, ignoring: %m");
f2236469 625 return 0;
25a1bffc 626 } else if (!IN_SET(type, RTM_NEWLINK, RTM_DELLINK)) {
e1694a75 627 log_warning("rtnl: Received unexpected message type when processing link, ignoring");
cdfee943 628 return 0;
f2236469
TG
629 }
630
505f8da7 631 r = sd_rtnl_message_link_get_ifindex(message, &ifindex);
45af44d4 632 if (r < 0) {
e1694a75 633 log_warning_errno(r, "rtnl: Could not get ifindex from link, ignoring: %m");
45af44d4
TG
634 return 0;
635 } else if (ifindex <= 0) {
e1694a75 636 log_warning("rtnl: received link message with invalid ifindex %d, ignoring", ifindex);
505f8da7 637 return 0;
a0db8e46 638 }
f579559b 639
1c4baffc 640 r = sd_netlink_message_read_string(message, IFLA_IFNAME, &name);
45af44d4 641 if (r < 0) {
e1694a75 642 log_warning_errno(r, "rtnl: Received link message without ifname, ignoring: %m");
4d473d5d 643 return 0;
a0db8e46
ZJS
644 }
645
646 (void) link_get(m, ifindex, &link);
647 (void) netdev_get(m, name, &netdev);
4d473d5d
TG
648
649 switch (type) {
650 case RTM_NEWLINK:
651 if (!link) {
652 /* link is new, so add it */
653 r = link_add(m, message, &link);
654 if (r < 0) {
e1694a75 655 log_warning_errno(r, "Could not add new link, ignoring: %m");
4d473d5d
TG
656 return 0;
657 }
658 }
659
660 if (netdev) {
661 /* netdev exists, so make sure the ifindex matches */
505f8da7
TG
662 r = netdev_set_ifindex(netdev, message);
663 if (r < 0) {
e1694a75 664 log_warning_errno(r, "Could not set ifindex on netdev, ignoring: %m");
505f8da7
TG
665 return 0;
666 }
667 }
e1202047 668
f2236469 669 r = link_update(link, message);
e1694a75
YW
670 if (r < 0) {
671 log_warning_errno(r, "Could not update link, ignoring: %m");
f2236469 672 return 0;
e1694a75 673 }
4d473d5d
TG
674
675 break;
676
677 case RTM_DELLINK:
678 link_drop(link);
679 netdev_drop(netdev);
680
681 break;
682
683 default:
684 assert_not_reached("Received invalid RTNL message type.");
f2236469 685 }
505f8da7
TG
686
687 return 1;
688}
689
bce67bbe
SS
690int manager_rtnl_process_rule(sd_netlink *rtnl, sd_netlink_message *message, void *userdata) {
691 uint8_t tos = 0, to_prefixlen = 0, from_prefixlen = 0;
36e6e28b 692 union in_addr_union to = {}, from = {};
bce67bbe 693 RoutingPolicyRule *rule = NULL;
bce67bbe 694 uint32_t fwmark = 0, table = 0;
eeab051b 695 const char *iif = NULL, *oif = NULL;
bce67bbe
SS
696 Manager *m = userdata;
697 uint16_t type;
698 int family;
699 int r;
700
701 assert(rtnl);
702 assert(message);
703 assert(m);
704
705 if (sd_netlink_message_is_error(message)) {
706 r = sd_netlink_message_get_errno(message);
707 if (r < 0)
e1694a75 708 log_warning_errno(r, "rtnl: failed to receive rule, ignoring: %m");
bce67bbe
SS
709
710 return 0;
711 }
712
713 r = sd_netlink_message_get_type(message, &type);
714 if (r < 0) {
e1694a75 715 log_warning_errno(r, "rtnl: could not get message type, ignoring: %m");
bce67bbe
SS
716 return 0;
717 } else if (!IN_SET(type, RTM_NEWRULE, RTM_DELRULE)) {
e1694a75 718 log_warning("rtnl: received unexpected message type '%u' when processing rule, ignoring", type);
bce67bbe
SS
719 return 0;
720 }
721
722 r = sd_rtnl_message_get_family(message, &family);
615ded62 723 if (r < 0) {
e1694a75 724 log_warning_errno(r, "rtnl: could not get rule family, ignoring: %m");
615ded62
YW
725 return 0;
726 } else if (!IN_SET(family, AF_INET, AF_INET6)) {
e1694a75 727 log_debug("rtnl: received address with invalid family %u, ignoring", family);
bce67bbe
SS
728 return 0;
729 }
730
731 switch (family) {
732 case AF_INET:
733 r = sd_netlink_message_read_in_addr(message, FRA_SRC, &from.in);
e1694a75
YW
734 if (r < 0 && r != -ENODATA) {
735 log_warning_errno(r, "rtnl: could not get FRA_SRC attribute, ignoring: %m");
736 return 0;
737 } else if (r >= 0) {
bce67bbe 738 r = sd_rtnl_message_routing_policy_rule_get_rtm_src_prefixlen(message, &from_prefixlen);
e1694a75 739 if (r < 0) {
3fe91079 740 log_warning_errno(r, "rtnl: failed to retrieve rule from prefix length, ignoring: %m");
e1694a75
YW
741 return 0;
742 }
bce67bbe
SS
743 }
744
745 r = sd_netlink_message_read_in_addr(message, FRA_DST, &to.in);
e1694a75
YW
746 if (r < 0 && r != -ENODATA) {
747 log_warning_errno(r, "rtnl: could not get FRA_DST attribute, ignoring: %m");
748 return 0;
749 } else if (r >= 0) {
bce67bbe 750 r = sd_rtnl_message_routing_policy_rule_get_rtm_dst_prefixlen(message, &to_prefixlen);
e1694a75 751 if (r < 0) {
3fe91079 752 log_warning_errno(r, "rtnl: failed to retrieve rule to prefix length, ignoring: %m");
e1694a75
YW
753 return 0;
754 }
bce67bbe
SS
755 }
756
757 break;
758
759 case AF_INET6:
760 r = sd_netlink_message_read_in6_addr(message, FRA_SRC, &from.in6);
e1694a75
YW
761 if (r < 0 && r != -ENODATA) {
762 log_warning_errno(r, "rtnl: could not get FRA_SRC attribute, ignoring: %m");
763 return 0;
764 } else if (r >= 0) {
bce67bbe 765 r = sd_rtnl_message_routing_policy_rule_get_rtm_src_prefixlen(message, &from_prefixlen);
e1694a75 766 if (r < 0) {
3fe91079 767 log_warning_errno(r, "rtnl: failed to retrieve rule from prefix length, ignoring: %m");
e1694a75
YW
768 return 0;
769 }
bce67bbe
SS
770 }
771
772 r = sd_netlink_message_read_in6_addr(message, FRA_DST, &to.in6);
e1694a75
YW
773 if (r < 0 && r != -ENODATA) {
774 log_warning_errno(r, "rtnl: could not get FRA_DST attribute, ignoring: %m");
775 return 0;
776 } else if (r >= 0) {
bce67bbe 777 r = sd_rtnl_message_routing_policy_rule_get_rtm_dst_prefixlen(message, &to_prefixlen);
e1694a75 778 if (r < 0) {
3fe91079 779 log_warning_errno(r, "rtnl: failed to retrieve rule to prefix length, ignoring: %m");
e1694a75
YW
780 return 0;
781 }
bce67bbe
SS
782 }
783
784 break;
785
786 default:
74dead34 787 assert_not_reached("Received unsupported address family");
bce67bbe
SS
788 }
789
790 if (from_prefixlen == 0 && to_prefixlen == 0)
791 return 0;
792
e1694a75
YW
793 r = sd_netlink_message_read_u32(message, FRA_FWMARK, &fwmark);
794 if (r < 0 && r != -ENODATA) {
795 log_warning_errno(r, "rtnl: could not get FRA_FWMARK attribute, ignoring: %m");
796 return 0;
797 }
798
799 r = sd_netlink_message_read_u32(message, FRA_TABLE, &table);
800 if (r < 0 && r != -ENODATA) {
801 log_warning_errno(r, "rtnl: could not get FRA_TABLE attribute, ignoring: %m");
802 return 0;
803 }
804
805 r = sd_rtnl_message_routing_policy_rule_get_tos(message, &tos);
806 if (r < 0 && r != -ENODATA) {
807 log_warning_errno(r, "rtnl: could not get ip rule TOS, ignoring: %m");
808 return 0;
809 }
810
eeab051b 811 r = sd_netlink_message_read_string(message, FRA_IIFNAME, &iif);
e1694a75
YW
812 if (r < 0 && r != -ENODATA) {
813 log_warning_errno(r, "rtnl: could not get FRA_IIFNAME attribute, ignoring: %m");
814 return 0;
815 }
816
eeab051b 817 r = sd_netlink_message_read_string(message, FRA_OIFNAME, &oif);
e1694a75
YW
818 if (r < 0 && r != -ENODATA) {
819 log_warning_errno(r, "rtnl: could not get FRA_OIFNAME attribute, ignoring: %m");
820 return 0;
821 }
bce67bbe 822
762e2659 823 (void) routing_policy_rule_get(m, family, &from, from_prefixlen, &to, to_prefixlen, tos, fwmark, table, iif, oif, &rule);
bce67bbe
SS
824
825 switch (type) {
826 case RTM_NEWRULE:
508f63b4 827 if (!rule) {
762e2659 828 r = routing_policy_rule_add_foreign(m, family, &from, from_prefixlen, &to, to_prefixlen, tos, fwmark, table, iif, oif, &rule);
bce67bbe 829 if (r < 0) {
e1694a75 830 log_warning_errno(r, "Could not add rule, ignoring: %m");
bce67bbe
SS
831 return 0;
832 }
833 }
834 break;
835 case RTM_DELRULE:
836 routing_policy_rule_free(rule);
837
838 break;
839
840 default:
841 assert_not_reached("Received invalid RTNL message type");
842 }
843
844 return 1;
845}
846
5fae368b
TG
847static int systemd_netlink_fd(void) {
848 int n, fd, rtnl_fd = -EINVAL;
849
850 n = sd_listen_fds(true);
851 if (n <= 0)
852 return -EINVAL;
853
854 for (fd = SD_LISTEN_FDS_START; fd < SD_LISTEN_FDS_START + n; fd ++) {
855 if (sd_is_socket(fd, AF_NETLINK, SOCK_RAW, -1) > 0) {
856 if (rtnl_fd >= 0)
857 return -EINVAL;
858
859 rtnl_fd = fd;
860 }
861 }
862
863 return rtnl_fd;
864}
865
05d0c2e3
JT
866static int manager_connect_genl(Manager *m) {
867 int r;
868
869 assert(m);
870
871 r = sd_genl_socket_open(&m->genl);
872 if (r < 0)
873 return r;
874
875 r = sd_netlink_inc_rcvbuf(m->genl, RCVBUF_SIZE);
876 if (r < 0)
877 return r;
878
879 r = sd_netlink_attach_event(m->genl, m->event, 0);
880 if (r < 0)
881 return r;
882
883 return 0;
884}
885
5fae368b
TG
886static int manager_connect_rtnl(Manager *m) {
887 int fd, r;
505f8da7
TG
888
889 assert(m);
505f8da7 890
5fae368b
TG
891 fd = systemd_netlink_fd();
892 if (fd < 0)
1c4baffc 893 r = sd_netlink_open(&m->rtnl);
5fae368b 894 else
1c4baffc 895 r = sd_netlink_open_fd(&m->rtnl, fd);
505f8da7
TG
896 if (r < 0)
897 return r;
898
1c4baffc 899 r = sd_netlink_inc_rcvbuf(m->rtnl, RCVBUF_SIZE);
f579559b 900 if (r < 0)
bf5332d2 901 return r;
f579559b 902
1c4baffc 903 r = sd_netlink_attach_event(m->rtnl, m->event, 0);
505f8da7
TG
904 if (r < 0)
905 return r;
f579559b 906
8190a388 907 r = sd_netlink_add_match(m->rtnl, NULL, RTM_NEWLINK, &manager_rtnl_process_link, NULL, m, "network-rtnl_process_link");
5fae368b
TG
908 if (r < 0)
909 return r;
505f8da7 910
8190a388 911 r = sd_netlink_add_match(m->rtnl, NULL, RTM_DELLINK, &manager_rtnl_process_link, NULL, m, "network-rtnl_process_link");
5fae368b
TG
912 if (r < 0)
913 return r;
45af44d4 914
8190a388 915 r = sd_netlink_add_match(m->rtnl, NULL, RTM_NEWADDR, &manager_rtnl_process_address, NULL, m, "network-rtnl_process_address");
5fae368b
TG
916 if (r < 0)
917 return r;
918
8190a388 919 r = sd_netlink_add_match(m->rtnl, NULL, RTM_DELADDR, &manager_rtnl_process_address, NULL, m, "network-rtnl_process_address");
5fae368b
TG
920 if (r < 0)
921 return r;
922
8190a388 923 r = sd_netlink_add_match(m->rtnl, NULL, RTM_NEWROUTE, &manager_rtnl_process_route, NULL, m, "network-rtnl_process_route");
1c8e710c
TG
924 if (r < 0)
925 return r;
926
8190a388 927 r = sd_netlink_add_match(m->rtnl, NULL, RTM_DELROUTE, &manager_rtnl_process_route, NULL, m, "network-rtnl_process_route");
1c8e710c
TG
928 if (r < 0)
929 return r;
930
8190a388 931 r = sd_netlink_add_match(m->rtnl, NULL, RTM_NEWRULE, &manager_rtnl_process_rule, NULL, m, "network-rtnl_process_rule");
bce67bbe
SS
932 if (r < 0)
933 return r;
934
8190a388 935 r = sd_netlink_add_match(m->rtnl, NULL, RTM_DELRULE, &manager_rtnl_process_rule, NULL, m, "network-rtnl_process_rule");
bce67bbe
SS
936 if (r < 0)
937 return r;
938
5fae368b 939 return 0;
45af44d4 940}
505f8da7 941
5512a963 942static int ordered_set_put_in_addr_data(OrderedSet *s, const struct in_addr_data *address) {
84de38c5
TG
943 char *p;
944 int r;
945
946 assert(s);
5512a963
LP
947 assert(address);
948
949 r = in_addr_to_string(address->family, &address->address, &p);
950 if (r < 0)
951 return r;
952
953 r = ordered_set_consume(s, p);
954 if (r == -EEXIST)
955 return 0;
956
957 return r;
958}
959
960static int ordered_set_put_in_addr_datav(OrderedSet *s, const struct in_addr_data *addresses, unsigned n) {
961 int r, c = 0;
962 unsigned i;
963
964 assert(s);
965 assert(addresses || n == 0);
966
967 for (i = 0; i < n; i++) {
968 r = ordered_set_put_in_addr_data(s, addresses+i);
969 if (r < 0)
970 return r;
971
972 c += r;
973 }
974
975 return c;
976}
977
978static int ordered_set_put_in4_addr(OrderedSet *s, const struct in_addr *address) {
979 char *p;
980 int r;
981
982 assert(s);
983 assert(address);
84de38c5
TG
984
985 r = in_addr_to_string(AF_INET, (const union in_addr_union*) address, &p);
986 if (r < 0)
987 return r;
988
00616955 989 r = ordered_set_consume(s, p);
84de38c5
TG
990 if (r == -EEXIST)
991 return 0;
992
993 return r;
994}
995
5512a963
LP
996static int ordered_set_put_in4_addrv(OrderedSet *s, const struct in_addr *addresses, unsigned n) {
997 int r, c = 0;
998 unsigned i;
84de38c5
TG
999
1000 assert(s);
5512a963 1001 assert(n == 0 || addresses);
84de38c5
TG
1002
1003 for (i = 0; i < n; i++) {
5512a963 1004 r = ordered_set_put_in4_addr(s, addresses+i);
84de38c5
TG
1005 if (r < 0)
1006 return r;
1007
1008 c += r;
1009 }
1010
1011 return c;
1012}
1013
00616955 1014static void print_string_set(FILE *f, const char *field, OrderedSet *s) {
84de38c5
TG
1015 bool space = false;
1016 Iterator i;
1017 char *p;
1018
00616955 1019 if (ordered_set_isempty(s))
84de38c5
TG
1020 return;
1021
0d536673 1022 fputs(field, f);
84de38c5 1023
d390f8ef
LP
1024 ORDERED_SET_FOREACH(p, s, i)
1025 fputs_with_space(f, p, NULL, &space);
1026
0d536673 1027 fputc('\n', f);
84de38c5
TG
1028}
1029
1030static int manager_save(Manager *m) {
00616955 1031 _cleanup_ordered_set_free_free_ OrderedSet *dns = NULL, *ntp = NULL, *search_domains = NULL, *route_domains = NULL;
84de38c5
TG
1032 Link *link;
1033 Iterator i;
1034 _cleanup_free_ char *temp_path = NULL;
1035 _cleanup_fclose_ FILE *f = NULL;
1036 LinkOperationalState operstate = LINK_OPERSTATE_OFF;
1037 const char *operstate_str;
1038 int r;
1039
1040 assert(m);
1041 assert(m->state_file);
1042
1043 /* We add all NTP and DNS server to a set, to filter out duplicates */
00616955 1044 dns = ordered_set_new(&string_hash_ops);
84de38c5
TG
1045 if (!dns)
1046 return -ENOMEM;
1047
00616955 1048 ntp = ordered_set_new(&string_hash_ops);
84de38c5
TG
1049 if (!ntp)
1050 return -ENOMEM;
1051
482d1aeb 1052 search_domains = ordered_set_new(&dns_name_hash_ops);
3df9bec5
LP
1053 if (!search_domains)
1054 return -ENOMEM;
1055
482d1aeb 1056 route_domains = ordered_set_new(&dns_name_hash_ops);
3df9bec5 1057 if (!route_domains)
84de38c5
TG
1058 return -ENOMEM;
1059
1060 HASHMAP_FOREACH(link, m->links, i) {
1061 if (link->flags & IFF_LOOPBACK)
1062 continue;
1063
1064 if (link->operstate > operstate)
1065 operstate = link->operstate;
1066
1067 if (!link->network)
1068 continue;
1069
1070 /* First add the static configured entries */
5512a963 1071 r = ordered_set_put_in_addr_datav(dns, link->network->dns, link->network->n_dns);
84de38c5
TG
1072 if (r < 0)
1073 return r;
1074
00616955 1075 r = ordered_set_put_strdupv(ntp, link->network->ntp);
84de38c5
TG
1076 if (r < 0)
1077 return r;
1078
00616955 1079 r = ordered_set_put_strdupv(search_domains, link->network->search_domains);
3df9bec5
LP
1080 if (r < 0)
1081 return r;
1082
00616955 1083 r = ordered_set_put_strdupv(route_domains, link->network->route_domains);
84de38c5
TG
1084 if (r < 0)
1085 return r;
1086
1087 if (!link->dhcp_lease)
1088 continue;
1089
1090 /* Secondly, add the entries acquired via DHCP */
27cb34f5 1091 if (link->network->dhcp_use_dns) {
84de38c5
TG
1092 const struct in_addr *addresses;
1093
1094 r = sd_dhcp_lease_get_dns(link->dhcp_lease, &addresses);
1095 if (r > 0) {
5512a963 1096 r = ordered_set_put_in4_addrv(dns, addresses, r);
84de38c5
TG
1097 if (r < 0)
1098 return r;
1099 } else if (r < 0 && r != -ENODATA)
1100 return r;
1101 }
1102
27cb34f5 1103 if (link->network->dhcp_use_ntp) {
84de38c5
TG
1104 const struct in_addr *addresses;
1105
1106 r = sd_dhcp_lease_get_ntp(link->dhcp_lease, &addresses);
1107 if (r > 0) {
5512a963 1108 r = ordered_set_put_in4_addrv(ntp, addresses, r);
84de38c5
TG
1109 if (r < 0)
1110 return r;
1111 } else if (r < 0 && r != -ENODATA)
1112 return r;
1113 }
1114
b2a81c0b 1115 if (link->network->dhcp_use_domains != DHCP_USE_DOMAINS_NO) {
84de38c5 1116 const char *domainname;
b85bc551 1117 char **domains = NULL;
84de38c5 1118
b85bc551 1119 OrderedSet *target_domains = (link->network->dhcp_use_domains == DHCP_USE_DOMAINS_YES) ? search_domains : route_domains;
84de38c5
TG
1120 r = sd_dhcp_lease_get_domainname(link->dhcp_lease, &domainname);
1121 if (r >= 0) {
b85bc551
DW
1122 r = ordered_set_put_strdup(target_domains, domainname);
1123 if (r < 0)
1124 return r;
1125 } else if (r != -ENODATA)
1126 return r;
b2a81c0b 1127
b85bc551
DW
1128 r = sd_dhcp_lease_get_search_domains(link->dhcp_lease, &domains);
1129 if (r >= 0) {
1130 r = ordered_set_put_strdupv(target_domains, domains);
84de38c5
TG
1131 if (r < 0)
1132 return r;
1133 } else if (r != -ENODATA)
1134 return r;
1135 }
1136 }
1137
1138 operstate_str = link_operstate_to_string(operstate);
1139 assert(operstate_str);
1140
1141 r = fopen_temporary(m->state_file, &f, &temp_path);
1142 if (r < 0)
1143 return r;
1144
0d536673 1145 (void) __fsetlocking(f, FSETLOCKING_BYCALLER);
5512a963 1146 (void) fchmod(fileno(f), 0644);
84de38c5
TG
1147
1148 fprintf(f,
1149 "# This is private data. Do not parse.\n"
1150 "OPER_STATE=%s\n", operstate_str);
1151
1152 print_string_set(f, "DNS=", dns);
1153 print_string_set(f, "NTP=", ntp);
3df9bec5
LP
1154 print_string_set(f, "DOMAINS=", search_domains);
1155 print_string_set(f, "ROUTE_DOMAINS=", route_domains);
84de38c5 1156
458d8ae3
ZJS
1157 r = routing_policy_serialize_rules(m->rules, f);
1158 if (r < 0)
1159 goto fail;
bce67bbe 1160
84de38c5
TG
1161 r = fflush_and_check(f);
1162 if (r < 0)
1163 goto fail;
1164
1165 if (rename(temp_path, m->state_file) < 0) {
1166 r = -errno;
1167 goto fail;
1168 }
1169
1170 if (m->operational_state != operstate) {
1171 m->operational_state = operstate;
1172 r = manager_send_changed(m, "OperationalState", NULL);
1173 if (r < 0)
1174 log_error_errno(r, "Could not emit changed OperationalState: %m");
1175 }
1176
1177 m->dirty = false;
1178
1179 return 0;
1180
1181fail:
1182 (void) unlink(m->state_file);
1183 (void) unlink(temp_path);
1184
1185 return log_error_errno(r, "Failed to save network state to %s: %m", m->state_file);
1186}
1187
1188static int manager_dirty_handler(sd_event_source *s, void *userdata) {
1189 Manager *m = userdata;
1190 Link *link;
1191 Iterator i;
1192 int r;
1193
1194 assert(m);
1195
1196 if (m->dirty)
1197 manager_save(m);
1198
1199 SET_FOREACH(link, m->dirty_links, i) {
1200 r = link_save(link);
1201 if (r >= 0)
1202 link_clean(link);
1203 }
1204
1205 return 1;
1206}
1207
e133b289
PF
1208Link *manager_dhcp6_prefix_get(Manager *m, struct in6_addr *addr) {
1209 assert_return(m, NULL);
1210 assert_return(m->dhcp6_prefixes, NULL);
1211 assert_return(addr, NULL);
1212
1213 return hashmap_get(m->dhcp6_prefixes, addr);
1214}
1215
c8ee637e 1216static int dhcp6_route_add_handler(sd_netlink *nl, sd_netlink_message *m, void *userdata) {
1046bf9b 1217 Link *link = userdata;
9f386c6d 1218 int r;
9f386c6d 1219
1046bf9b
YW
1220 assert(link);
1221
9f386c6d 1222 r = sd_netlink_message_get_errno(m);
e1d737ef 1223 if (r < 0 && r != -EEXIST)
1046bf9b 1224 log_link_debug_errno(link, r, "Received error adding DHCPv6 Prefix Delegation route: %m");
9f386c6d
PF
1225
1226 return 0;
1227}
1228
e133b289 1229int manager_dhcp6_prefix_add(Manager *m, struct in6_addr *addr, Link *link) {
9f386c6d
PF
1230 int r;
1231 Route *route;
e1d737ef 1232 _cleanup_free_ char *buf = NULL;
9f386c6d 1233
e133b289
PF
1234 assert_return(m, -EINVAL);
1235 assert_return(m->dhcp6_prefixes, -ENODATA);
1236 assert_return(addr, -EINVAL);
1237
9f386c6d
PF
1238 r = route_add(link, AF_INET6, (union in_addr_union *) addr, 64,
1239 0, 0, 0, &route);
1240 if (r < 0)
1241 return r;
1242
c8ee637e 1243 r = route_configure(route, link, dhcp6_route_add_handler);
9f386c6d
PF
1244 if (r < 0)
1245 return r;
1246
e1d737ef
PF
1247 (void) in_addr_to_string(AF_INET6, (union in_addr_union *) addr, &buf);
1248 log_link_debug(link, "Adding prefix route %s/64", strnull(buf));
1249
e133b289
PF
1250 return hashmap_put(m->dhcp6_prefixes, addr, link);
1251}
1252
c8ee637e 1253static int dhcp6_route_remove_handler(sd_netlink *nl, sd_netlink_message *m, void *userdata) {
1046bf9b 1254 Link *link = userdata;
9f386c6d 1255 int r;
9f386c6d 1256
1046bf9b
YW
1257 assert(link);
1258
9f386c6d 1259 r = sd_netlink_message_get_errno(m);
e1d737ef 1260 if (r < 0)
1046bf9b 1261 log_link_debug_errno(link, r, "Received error on DHCPv6 Prefix Delegation route removal: %m");
9f386c6d 1262
0ae286e6 1263 return 1;
9f386c6d
PF
1264}
1265
fdb20b7c 1266static int manager_dhcp6_prefix_remove(Manager *m, struct in6_addr *addr) {
e133b289 1267 Link *l;
9f386c6d
PF
1268 int r;
1269 Route *route;
e1d737ef 1270 _cleanup_free_ char *buf = NULL;
e133b289
PF
1271
1272 assert_return(m, -EINVAL);
1273 assert_return(m->dhcp6_prefixes, -ENODATA);
1274 assert_return(addr, -EINVAL);
1275
1276 l = hashmap_remove(m->dhcp6_prefixes, addr);
1277 if (!l)
1278 return -EINVAL;
1279
1280 (void) sd_radv_remove_prefix(l->radv, addr, 64);
9f386c6d
PF
1281 r = route_get(l, AF_INET6, (union in_addr_union *) addr, 64,
1282 0, 0, 0, &route);
e1d737ef
PF
1283 if (r < 0)
1284 return r;
1285
c8ee637e 1286 r = route_remove(route, l, dhcp6_route_remove_handler);
e1d737ef
PF
1287 if (r < 0)
1288 return r;
1289
1290 (void) in_addr_to_string(AF_INET6, (union in_addr_union *) addr, &buf);
1291 log_link_debug(l, "Removing prefix route %s/64", strnull(buf));
e133b289
PF
1292
1293 return 0;
1294}
1295
1296int manager_dhcp6_prefix_remove_all(Manager *m, Link *link) {
1297 Iterator i;
1298 Link *l;
1299 struct in6_addr *addr;
1300
1301 assert_return(m, -EINVAL);
b7d16a91 1302 assert_return(link, -EINVAL);
e133b289
PF
1303
1304 HASHMAP_FOREACH_KEY(l, addr, m->dhcp6_prefixes, i) {
1305 if (l != link)
1306 continue;
1307
9f386c6d 1308 (void) manager_dhcp6_prefix_remove(m, addr);
e133b289
PF
1309 }
1310
1311 return 0;
1312}
1313
1314static void dhcp6_prefixes_hash_func(const void *p, struct siphash *state) {
1315 const struct in6_addr *addr = p;
1316
1317 assert(p);
1318
1319 siphash24_compress(addr, sizeof(*addr), state);
1320}
1321
1322static int dhcp6_prefixes_compare_func(const void *_a, const void *_b) {
1323 const struct in6_addr *a = _a, *b = _b;
1324
aa18944d 1325 return memcmp(a, b, sizeof(*a));
e133b289
PF
1326}
1327
1328static const struct hash_ops dhcp6_prefixes_hash_ops = {
1329 .hash = dhcp6_prefixes_hash_func,
1330 .compare = dhcp6_prefixes_compare_func,
1331};
1332
3534a043 1333int manager_new(Manager **ret) {
8e766630 1334 _cleanup_(manager_freep) Manager *m = NULL;
45af44d4 1335 int r;
f579559b 1336
5fae368b
TG
1337 m = new0(Manager, 1);
1338 if (!m)
1339 return -ENOMEM;
45af44d4 1340
5fae368b
TG
1341 m->state_file = strdup("/run/systemd/netif/state");
1342 if (!m->state_file)
1343 return -ENOMEM;
1344
3534a043
YW
1345 r = sd_event_default(&m->event);
1346 if (r < 0)
1347 return r;
1348
05e21627
YW
1349 (void) sd_event_set_watchdog(m->event, true);
1350 (void) sd_event_add_signal(m->event, NULL, SIGTERM, NULL, NULL);
1351 (void) sd_event_add_signal(m->event, NULL, SIGINT, NULL, NULL);
5fae368b 1352
84de38c5
TG
1353 r = sd_event_add_post(m->event, NULL, manager_dirty_handler, m);
1354 if (r < 0)
1355 return r;
1356
5fae368b 1357 r = manager_connect_rtnl(m);
45af44d4
TG
1358 if (r < 0)
1359 return r;
1360
05d0c2e3
JT
1361 r = manager_connect_genl(m);
1362 if (r < 0)
1363 return r;
1364
5fae368b
TG
1365 r = manager_connect_udev(m);
1366 if (r < 0)
1367 return r;
45af44d4 1368
5fae368b
TG
1369 m->netdevs = hashmap_new(&string_hash_ops);
1370 if (!m->netdevs)
1371 return -ENOMEM;
f579559b 1372
5fae368b 1373 LIST_HEAD_INIT(m->networks);
f579559b 1374
05d0c2e3
JT
1375 r = sd_resolve_default(&m->resolve);
1376 if (r < 0)
1377 return r;
1378
1379 r = sd_resolve_attach_event(m->resolve, m->event, 0);
1380 if (r < 0)
1381 return r;
1382
5fae368b
TG
1383 r = setup_default_address_pool(m);
1384 if (r < 0)
1385 return r;
f579559b 1386
e133b289
PF
1387 m->dhcp6_prefixes = hashmap_new(&dhcp6_prefixes_hash_ops);
1388 if (!m->dhcp6_prefixes)
1389 return -ENOMEM;
1390
8341a5c3 1391 m->duid.type = DUID_TYPE_EN;
413708d1 1392
458d8ae3 1393 (void) routing_policy_load_rules(m->state_file, &m->rules_saved);
bce67bbe 1394
1cc6c93a 1395 *ret = TAKE_PTR(m);
f579559b 1396
f579559b
TG
1397 return 0;
1398}
1399
5fae368b
TG
1400void manager_free(Manager *m) {
1401 Network *network;
1402 NetDev *netdev;
1403 Link *link;
1404 AddressPool *pool;
f579559b 1405
5fae368b
TG
1406 if (!m)
1407 return;
505f8da7 1408
5fae368b 1409 free(m->state_file);
505f8da7 1410
1046bf9b
YW
1411 sd_netlink_unref(m->rtnl);
1412 sd_netlink_unref(m->genl);
1413
bce67bbe
SS
1414 while ((network = m->networks))
1415 network_free(network);
1416
e133b289 1417 while ((link = hashmap_first(m->dhcp6_prefixes)))
65dd5e31 1418 manager_dhcp6_prefix_remove_all(m, link);
e133b289
PF
1419 hashmap_free(m->dhcp6_prefixes);
1420
65dd5e31
PF
1421 while ((link = hashmap_first(m->links))) {
1422 if (link->dhcp6_client)
1423 (void) dhcp6_lease_pd_prefix_lost(link->dhcp6_client,
1424 link);
1425
1426 hashmap_remove(m->links, INT_TO_PTR(link->ifindex));
1427
5fae368b 1428 link_unref(link);
65dd5e31 1429 }
f579559b 1430
9bcb210e
YW
1431 set_free_with_destructor(m->dirty_links, link_unref);
1432 hashmap_free(m->links);
27dfc982
YW
1433 set_free(m->links_requesting_uuid);
1434 set_free(m->duids_requesting_uuid);
1435
dbffab87
TG
1436 hashmap_free(m->networks_by_name);
1437
5fae368b
TG
1438 while ((netdev = hashmap_first(m->netdevs)))
1439 netdev_unref(netdev);
1440 hashmap_free(m->netdevs);
1441
1442 while ((pool = m->address_pools))
1443 address_pool_free(pool);
1444
1b3194d8
YW
1445 set_free_with_destructor(m->rules, routing_policy_rule_free);
1446 set_free_with_destructor(m->rules_foreign, routing_policy_rule_free);
b921fcb2 1447 set_free_with_destructor(m->rules_saved, routing_policy_rule_free);
bce67bbe 1448
2f5b4a77 1449 sd_event_unref(m->event);
5fae368b 1450
05d0c2e3
JT
1451 sd_resolve_unref(m->resolve);
1452
d2ebf952 1453 sd_device_monitor_unref(m->device_monitor);
7d20d375
TG
1454
1455 sd_bus_unref(m->bus);
7d20d375 1456
7901cea1
MP
1457 free(m->dynamic_timezone);
1458 free(m->dynamic_hostname);
1459
5fae368b
TG
1460 free(m);
1461}
1462
b76d99d9 1463int manager_start(Manager *m) {
84de38c5
TG
1464 Link *link;
1465 Iterator i;
1466
a97dcc12
TG
1467 assert(m);
1468
84de38c5
TG
1469 /* The dirty handler will deal with future serialization, but the first one
1470 must be done explicitly. */
1471
1472 manager_save(m);
1473
1474 HASHMAP_FOREACH(link, m->links, i)
1475 link_save(link);
1476
b76d99d9 1477 return 0;
a97dcc12
TG
1478}
1479
5fae368b
TG
1480int manager_load_config(Manager *m) {
1481 int r;
1482
1483 /* update timestamp */
1484 paths_check_timestamp(network_dirs, &m->network_dirs_ts_usec, true);
1485
1486 r = netdev_load(m);
f579559b
TG
1487 if (r < 0)
1488 return r;
1489
5fae368b 1490 r = network_load(m);
9021bb9f
TG
1491 if (r < 0)
1492 return r;
1493
f579559b
TG
1494 return 0;
1495}
f882c247 1496
5fae368b
TG
1497bool manager_should_reload(Manager *m) {
1498 return paths_check_timestamp(network_dirs, &m->network_dirs_ts_usec, false);
1499}
1500
1501int manager_rtnl_enumerate_links(Manager *m) {
4afd3348 1502 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL, *reply = NULL;
1c4baffc 1503 sd_netlink_message *link;
f882c247
TG
1504 int r;
1505
5da8149f 1506 assert(m);
5fae368b 1507 assert(m->rtnl);
5da8149f 1508
5fae368b 1509 r = sd_rtnl_message_new_link(m->rtnl, &req, RTM_GETLINK, 0);
f882c247
TG
1510 if (r < 0)
1511 return r;
1512
1c4baffc 1513 r = sd_netlink_message_request_dump(req, true);
dd3efc09
TG
1514 if (r < 0)
1515 return r;
1516
1c4baffc 1517 r = sd_netlink_call(m->rtnl, req, 0, &reply);
f2236469
TG
1518 if (r < 0)
1519 return r;
1520
1c4baffc 1521 for (link = reply; link; link = sd_netlink_message_next(link)) {
5fae368b 1522 int k;
2e9f08ea 1523
6a24f148
TG
1524 m->enumerating = true;
1525
5fae368b
TG
1526 k = manager_rtnl_process_link(m->rtnl, link, m);
1527 if (k < 0)
1528 r = k;
6a24f148
TG
1529
1530 m->enumerating = false;
5fae368b 1531 }
2e9f08ea 1532
5fae368b 1533 return r;
f882c247 1534}
3bef724f 1535
5fae368b 1536int manager_rtnl_enumerate_addresses(Manager *m) {
4afd3348 1537 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL, *reply = NULL;
1c4baffc 1538 sd_netlink_message *addr;
1346b1f0
TG
1539 int r;
1540
5fae368b
TG
1541 assert(m);
1542 assert(m->rtnl);
bcbca829 1543
5fae368b
TG
1544 r = sd_rtnl_message_new_addr(m->rtnl, &req, RTM_GETADDR, 0, 0);
1545 if (r < 0)
1546 return r;
bcbca829 1547
1c4baffc 1548 r = sd_netlink_message_request_dump(req, true);
1346b1f0
TG
1549 if (r < 0)
1550 return r;
1551
1c4baffc 1552 r = sd_netlink_call(m->rtnl, req, 0, &reply);
5fae368b
TG
1553 if (r < 0)
1554 return r;
1555
1c4baffc 1556 for (addr = reply; addr; addr = sd_netlink_message_next(addr)) {
5fae368b
TG
1557 int k;
1558
6a24f148
TG
1559 m->enumerating = true;
1560
200a0868 1561 k = manager_rtnl_process_address(m->rtnl, addr, m);
5fae368b
TG
1562 if (k < 0)
1563 r = k;
6a24f148
TG
1564
1565 m->enumerating = false;
5fae368b
TG
1566 }
1567
1568 return r;
1346b1f0
TG
1569}
1570
1c8e710c 1571int manager_rtnl_enumerate_routes(Manager *m) {
4afd3348 1572 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL, *reply = NULL;
1c8e710c
TG
1573 sd_netlink_message *route;
1574 int r;
1575
1576 assert(m);
1577 assert(m->rtnl);
1578
1579 r = sd_rtnl_message_new_route(m->rtnl, &req, RTM_GETROUTE, 0, 0);
1580 if (r < 0)
1581 return r;
1582
1583 r = sd_netlink_message_request_dump(req, true);
1584 if (r < 0)
1585 return r;
1586
1587 r = sd_netlink_call(m->rtnl, req, 0, &reply);
1588 if (r < 0)
1589 return r;
1590
1591 for (route = reply; route; route = sd_netlink_message_next(route)) {
1592 int k;
1593
1594 m->enumerating = true;
1595
1596 k = manager_rtnl_process_route(m->rtnl, route, m);
1597 if (k < 0)
1598 r = k;
1599
1600 m->enumerating = false;
1601 }
1602
1603 return r;
1604}
1605
bce67bbe
SS
1606int manager_rtnl_enumerate_rules(Manager *m) {
1607 _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL, *reply = NULL;
1608 sd_netlink_message *rule;
1609 int r;
1610
1611 assert(m);
1612 assert(m->rtnl);
1613
1614 r = sd_rtnl_message_new_routing_policy_rule(m->rtnl, &req, RTM_GETRULE, 0);
1615 if (r < 0)
1616 return r;
1617
1618 r = sd_netlink_message_request_dump(req, true);
1619 if (r < 0)
1620 return r;
1621
1622 r = sd_netlink_call(m->rtnl, req, 0, &reply);
6acbbdd4
SS
1623 if (r < 0) {
1624 if (r == -EOPNOTSUPP) {
1625 log_debug("FIB Rules are not supported by the kernel. Ignoring.");
1626 return 0;
1627 }
1628
bce67bbe 1629 return r;
6acbbdd4 1630 }
bce67bbe
SS
1631
1632 for (rule = reply; rule; rule = sd_netlink_message_next(rule)) {
1633 int k;
1634
1635 m->enumerating = true;
1636
1637 k = manager_rtnl_process_rule(m->rtnl, rule, m);
1638 if (k < 0)
1639 r = k;
1640
1641 m->enumerating = false;
1642 }
1643
1644 return r;
1645}
1646
0dd25fb9 1647int manager_address_pool_acquire(Manager *m, int family, unsigned prefixlen, union in_addr_union *found) {
11bf3cce
LP
1648 AddressPool *p;
1649 int r;
1650
1651 assert(m);
1652 assert(prefixlen > 0);
1653 assert(found);
1654
1655 LIST_FOREACH(address_pools, p, m->address_pools) {
1656 if (p->family != family)
1657 continue;
1658
1659 r = address_pool_acquire(p, prefixlen, found);
1660 if (r != 0)
1661 return r;
1662 }
1663
1664 return 0;
1665}
4f5f911e
LP
1666
1667Link* manager_find_uplink(Manager *m, Link *exclude) {
1668 _cleanup_free_ struct local_address *gateways = NULL;
1669 int n, i;
1670
1671 assert(m);
1672
1673 /* Looks for a suitable "uplink", via black magic: an
1674 * interface that is up and where the default route with the
1675 * highest priority points to. */
1676
1677 n = local_gateways(m->rtnl, 0, AF_UNSPEC, &gateways);
1678 if (n < 0) {
1679 log_warning_errno(n, "Failed to determine list of default gateways: %m");
1680 return NULL;
1681 }
1682
1683 for (i = 0; i < n; i++) {
1684 Link *link;
1685
1686 link = hashmap_get(m->links, INT_TO_PTR(gateways[i].ifindex));
1687 if (!link) {
c2c940bd 1688 log_debug("Weird, found a gateway for a link we don't know. Ignoring.");
4f5f911e
LP
1689 continue;
1690 }
1691
1692 if (link == exclude)
1693 continue;
1694
1695 if (link->operstate < LINK_OPERSTATE_ROUTABLE)
1696 continue;
1697
1698 return link;
1699 }
1700
1701 return NULL;
1702}
84de38c5
TG
1703
1704void manager_dirty(Manager *manager) {
1705 assert(manager);
1706
1707 /* the serialized state in /run is no longer up-to-date */
1708 manager->dirty = true;
1709}
59eb33e0
MP
1710
1711static int set_hostname_handler(sd_bus_message *m, void *userdata, sd_bus_error *ret_error) {
1712 Manager *manager = userdata;
1713 const sd_bus_error *e;
1714
1715 assert(m);
1716 assert(manager);
1717
1718 e = sd_bus_message_get_error(m);
1719 if (e)
1720 log_warning_errno(sd_bus_error_get_errno(e), "Could not set hostname: %s", e->message);
1721
1722 return 1;
1723}
1724
1725int manager_set_hostname(Manager *m, const char *hostname) {
1726 int r;
1727
1728 log_debug("Setting transient hostname: '%s'", strna(hostname));
d7afd945 1729
7901cea1
MP
1730 if (free_and_strdup(&m->dynamic_hostname, hostname) < 0)
1731 return log_oom();
59eb33e0 1732
d7afd945 1733 if (!m->bus || sd_bus_is_ready(m->bus) <= 0) {
e0d95f03 1734 log_debug("Not connected to system bus, setting hostname later.");
59eb33e0
MP
1735 return 0;
1736 }
1737
1738 r = sd_bus_call_method_async(
1739 m->bus,
1740 NULL,
1741 "org.freedesktop.hostname1",
1742 "/org/freedesktop/hostname1",
1743 "org.freedesktop.hostname1",
1744 "SetHostname",
1745 set_hostname_handler,
1746 m,
1747 "sb",
1748 hostname,
1749 false);
1750
1751 if (r < 0)
1752 return log_error_errno(r, "Could not set transient hostname: %m");
1753
1754 return 0;
1755}
1756
1757static int set_timezone_handler(sd_bus_message *m, void *userdata, sd_bus_error *ret_error) {
1758 Manager *manager = userdata;
1759 const sd_bus_error *e;
1760
1761 assert(m);
1762 assert(manager);
1763
1764 e = sd_bus_message_get_error(m);
1765 if (e)
1766 log_warning_errno(sd_bus_error_get_errno(e), "Could not set timezone: %s", e->message);
1767
1768 return 1;
1769}
1770
1771int manager_set_timezone(Manager *m, const char *tz) {
1772 int r;
1773
1774 assert(m);
1775 assert(tz);
1776
1777 log_debug("Setting system timezone: '%s'", tz);
7901cea1
MP
1778 if (free_and_strdup(&m->dynamic_timezone, tz) < 0)
1779 return log_oom();
59eb33e0 1780
d7afd945 1781 if (!m->bus || sd_bus_is_ready(m->bus) <= 0) {
e0d95f03 1782 log_debug("Not connected to system bus, setting timezone later.");
59eb33e0
MP
1783 return 0;
1784 }
1785
1786 r = sd_bus_call_method_async(
1787 m->bus,
1788 NULL,
1789 "org.freedesktop.timedate1",
1790 "/org/freedesktop/timedate1",
1791 "org.freedesktop.timedate1",
1792 "SetTimezone",
1793 set_timezone_handler,
1794 m,
1795 "sb",
1796 tz,
1797 false);
1798 if (r < 0)
1799 return log_error_errno(r, "Could not set timezone: %m");
1800
1801 return 0;
1802}
27dfc982
YW
1803
1804int manager_request_product_uuid(Manager *m, Link *link) {
1805 int r;
1806
1807 assert(m);
1808
1809 if (m->has_product_uuid)
1810 return 0;
1811
1812 log_debug("Requesting product UUID");
1813
1814 if (link) {
1815 DUID *duid;
1816
1817 assert_se(duid = link_get_duid(link));
1818
1819 r = set_ensure_allocated(&m->links_requesting_uuid, NULL);
1820 if (r < 0)
1821 return log_oom();
1822
1823 r = set_ensure_allocated(&m->duids_requesting_uuid, NULL);
1824 if (r < 0)
1825 return log_oom();
1826
1827 r = set_put(m->links_requesting_uuid, link);
1828 if (r < 0)
1829 return log_oom();
1830
1831 r = set_put(m->duids_requesting_uuid, duid);
1832 if (r < 0)
1833 return log_oom();
1834 }
1835
1836 if (!m->bus || sd_bus_is_ready(m->bus) <= 0) {
1837 log_debug("Not connected to system bus, requesting product UUID later.");
1838 return 0;
1839 }
1840
1841 r = sd_bus_call_method_async(
1842 m->bus,
1843 NULL,
1844 "org.freedesktop.hostname1",
1845 "/org/freedesktop/hostname1",
1846 "org.freedesktop.hostname1",
1847 "GetProductUUID",
1848 get_product_uuid_handler,
1849 m,
1850 "b",
1851 false);
1852 if (r < 0)
1853 return log_warning_errno(r, "Failed to get product UUID: %m");
1854
1855 return 0;
1856}