1 /* SPDX-License-Identifier: LGPL-2.1+ */
3 #include <sys/socket.h>
5 #include <linux/fib_rules.h>
9 #include "sd-netlink.h"
11 #include "alloc-util.h"
13 #include "conf-parser.h"
15 #include "device-util.h"
16 #include "dns-domain.h"
19 #include "local-addresses.h"
20 #include "netlink-util.h"
21 #include "networkd-manager.h"
22 #include "ordered-set.h"
23 #include "path-util.h"
26 #include "tmpfile-util.h"
29 /* use 8 MB for receive socket kernel queue. */
30 #define RCVBUF_SIZE (8*1024*1024)
32 const char* const network_dirs
[] = {
33 "/etc/systemd/network",
34 "/run/systemd/network",
35 "/usr/lib/systemd/network",
37 "/lib/systemd/network",
41 static int setup_default_address_pool(Manager
*m
) {
47 /* Add in the well-known private address ranges. */
49 r
= address_pool_new_from_string(m
, &p
, AF_INET6
, "fc00::", 7);
53 r
= address_pool_new_from_string(m
, &p
, AF_INET
, "192.168.0.0", 16);
57 r
= address_pool_new_from_string(m
, &p
, AF_INET
, "172.16.0.0", 12);
61 r
= address_pool_new_from_string(m
, &p
, AF_INET
, "10.0.0.0", 8);
68 static int manager_reset_all(Manager
*m
) {
75 HASHMAP_FOREACH(link
, m
->links
, i
) {
76 r
= link_carrier_reset(link
);
78 log_link_warning_errno(link
, r
, "Could not reset carrier: %m");
84 static int match_prepare_for_sleep(sd_bus_message
*message
, void *userdata
, sd_bus_error
*ret_error
) {
85 Manager
*m
= userdata
;
91 r
= sd_bus_message_read(message
, "b", &b
);
93 log_debug_errno(r
, "Failed to parse PrepareForSleep signal: %m");
100 log_debug("Coming back from suspend, resetting all connections...");
102 (void) manager_reset_all(m
);
107 static int on_connected(sd_bus_message
*message
, void *userdata
, sd_bus_error
*ret_error
) {
108 Manager
*m
= userdata
;
113 /* Did we get a timezone or transient hostname from DHCP while D-Bus wasn't up yet? */
114 if (m
->dynamic_hostname
)
115 (void) manager_set_hostname(m
, m
->dynamic_hostname
);
116 if (m
->dynamic_timezone
)
117 (void) manager_set_timezone(m
, m
->dynamic_timezone
);
118 if (m
->links_requesting_uuid
)
119 (void) manager_request_product_uuid(m
, NULL
);
124 int manager_connect_bus(Manager
*m
) {
132 r
= bus_open_system_watch_bind_with_description(&m
->bus
, "bus-api-network");
134 return log_error_errno(r
, "Failed to connect to bus: %m");
136 r
= sd_bus_add_object_vtable(m
->bus
, NULL
, "/org/freedesktop/network1", "org.freedesktop.network1.Manager", manager_vtable
, m
);
138 return log_error_errno(r
, "Failed to add manager object vtable: %m");
140 r
= sd_bus_add_fallback_vtable(m
->bus
, NULL
, "/org/freedesktop/network1/link", "org.freedesktop.network1.Link", link_vtable
, link_object_find
, m
);
142 return log_error_errno(r
, "Failed to add link object vtable: %m");
144 r
= sd_bus_add_node_enumerator(m
->bus
, NULL
, "/org/freedesktop/network1/link", link_node_enumerator
, m
);
146 return log_error_errno(r
, "Failed to add link enumerator: %m");
148 r
= sd_bus_add_fallback_vtable(m
->bus
, NULL
, "/org/freedesktop/network1/network", "org.freedesktop.network1.Network", network_vtable
, network_object_find
, m
);
150 return log_error_errno(r
, "Failed to add network object vtable: %m");
152 r
= sd_bus_add_node_enumerator(m
->bus
, NULL
, "/org/freedesktop/network1/network", network_node_enumerator
, m
);
154 return log_error_errno(r
, "Failed to add network enumerator: %m");
156 r
= sd_bus_request_name_async(m
->bus
, NULL
, "org.freedesktop.network1", 0, NULL
, NULL
);
158 return log_error_errno(r
, "Failed to request name: %m");
160 r
= sd_bus_attach_event(m
->bus
, m
->event
, 0);
162 return log_error_errno(r
, "Failed to attach bus to event loop: %m");
164 r
= sd_bus_match_signal_async(
167 "org.freedesktop.DBus.Local",
169 "org.freedesktop.DBus.Local",
171 on_connected
, NULL
, m
);
173 return log_error_errno(r
, "Failed to request match on Connected signal: %m");
175 r
= sd_bus_match_signal_async(
178 "org.freedesktop.login1",
179 "/org/freedesktop/login1",
180 "org.freedesktop.login1.Manager",
182 match_prepare_for_sleep
, NULL
, m
);
184 log_warning_errno(r
, "Failed to request match for PrepareForSleep, ignoring: %m");
189 static int manager_udev_process_link(sd_device_monitor
*monitor
, sd_device
*device
, void *userdata
) {
190 Manager
*m
= userdata
;
198 r
= sd_device_get_property_value(device
, "ACTION", &action
);
200 log_device_debug_errno(device
, r
, "Failed to get 'ACTION' property, ignoring device: %m");
204 if (!STR_IN_SET(action
, "add", "change")) {
205 log_device_debug(device
, "Ignoring udev %s event for device.", action
);
209 r
= sd_device_get_ifindex(device
, &ifindex
);
211 log_device_debug_errno(device
, r
, "Ignoring udev ADD event for device without ifindex or with invalid ifindex: %m");
215 r
= link_get(m
, ifindex
, &link
);
218 log_debug_errno(r
, "Failed to get link from ifindex %i, ignoring: %m", ifindex
);
222 (void) link_initialized(link
, device
);
227 static int manager_connect_udev(Manager
*m
) {
230 /* udev does not initialize devices inside containers,
231 * so we rely on them being already initialized before
232 * entering the container */
233 if (detect_container() > 0)
236 r
= sd_device_monitor_new(&m
->device_monitor
);
238 return log_error_errno(r
, "Failed to initialize device monitor: %m");
240 r
= sd_device_monitor_filter_add_match_subsystem_devtype(m
->device_monitor
, "net", NULL
);
242 return log_error_errno(r
, "Could not add device monitor filter: %m");
244 r
= sd_device_monitor_attach_event(m
->device_monitor
, m
->event
);
246 return log_error_errno(r
, "Failed to attach event to device monitor: %m");
248 r
= sd_device_monitor_start(m
->device_monitor
, manager_udev_process_link
, m
);
250 return log_error_errno(r
, "Failed to start device monitor: %m");
255 int manager_rtnl_process_route(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
256 Manager
*m
= userdata
;
259 uint32_t ifindex
, priority
= 0;
260 unsigned char protocol
, scope
, tos
, table
, rt_type
;
262 unsigned char dst_prefixlen
, src_prefixlen
;
263 union in_addr_union dst
= {}, gw
= {}, src
= {}, prefsrc
= {};
271 if (sd_netlink_message_is_error(message
)) {
272 r
= sd_netlink_message_get_errno(message
);
274 log_warning_errno(r
, "rtnl: failed to receive route, ignoring: %m");
279 r
= sd_netlink_message_get_type(message
, &type
);
281 log_warning_errno(r
, "rtnl: could not get message type, ignoring: %m");
283 } else if (!IN_SET(type
, RTM_NEWROUTE
, RTM_DELROUTE
)) {
284 log_warning("rtnl: received unexpected message type when processing route, ignoring");
288 r
= sd_netlink_message_read_u32(message
, RTA_OIF
, &ifindex
);
290 log_debug("rtnl: received route without ifindex, ignoring");
293 log_warning_errno(r
, "rtnl: could not get ifindex from route, ignoring: %m");
295 } else if (ifindex
<= 0) {
296 log_warning("rtnl: received route message with invalid ifindex, ignoring: %d", ifindex
);
299 r
= link_get(m
, ifindex
, &link
);
300 if (r
< 0 || !link
) {
301 /* when enumerating we might be out of sync, but we will
302 * get the route again, so just ignore it */
304 log_warning("rtnl: received route for nonexistent link (%d), ignoring", ifindex
);
309 r
= sd_rtnl_message_route_get_family(message
, &family
);
310 if (r
< 0 || !IN_SET(family
, AF_INET
, AF_INET6
)) {
311 log_link_warning(link
, "rtnl: received address with invalid family, ignoring");
315 r
= sd_rtnl_message_route_get_protocol(message
, &protocol
);
317 log_warning_errno(r
, "rtnl: could not get route protocol: %m");
323 r
= sd_netlink_message_read_in_addr(message
, RTA_DST
, &dst
.in
);
324 if (r
< 0 && r
!= -ENODATA
) {
325 log_link_warning_errno(link
, r
, "rtnl: received route without valid destination, ignoring: %m");
329 r
= sd_netlink_message_read_in_addr(message
, RTA_GATEWAY
, &gw
.in
);
330 if (r
< 0 && r
!= -ENODATA
) {
331 log_link_warning_errno(link
, r
, "rtnl: received route with invalid gateway, ignoring: %m");
335 r
= sd_netlink_message_read_in_addr(message
, RTA_SRC
, &src
.in
);
336 if (r
< 0 && r
!= -ENODATA
) {
337 log_link_warning_errno(link
, r
, "rtnl: received route with invalid source, ignoring: %m");
341 r
= sd_netlink_message_read_in_addr(message
, RTA_PREFSRC
, &prefsrc
.in
);
342 if (r
< 0 && r
!= -ENODATA
) {
343 log_link_warning_errno(link
, r
, "rtnl: received route with invalid preferred source, ignoring: %m");
350 r
= sd_netlink_message_read_in6_addr(message
, RTA_DST
, &dst
.in6
);
351 if (r
< 0 && r
!= -ENODATA
) {
352 log_link_warning_errno(link
, r
, "rtnl: received route without valid destination, ignoring: %m");
356 r
= sd_netlink_message_read_in6_addr(message
, RTA_GATEWAY
, &gw
.in6
);
357 if (r
< 0 && r
!= -ENODATA
) {
358 log_link_warning_errno(link
, r
, "rtnl: received route with invalid gateway, ignoring: %m");
362 r
= sd_netlink_message_read_in6_addr(message
, RTA_SRC
, &src
.in6
);
363 if (r
< 0 && r
!= -ENODATA
) {
364 log_link_warning_errno(link
, r
, "rtnl: received route with invalid source, ignoring: %m");
368 r
= sd_netlink_message_read_in6_addr(message
, RTA_PREFSRC
, &prefsrc
.in6
);
369 if (r
< 0 && r
!= -ENODATA
) {
370 log_link_warning_errno(link
, r
, "rtnl: received route with invalid preferred source, ignoring: %m");
377 assert_not_reached("Received unsupported address family");
381 r
= sd_rtnl_message_route_get_dst_prefixlen(message
, &dst_prefixlen
);
383 log_link_warning_errno(link
, r
, "rtnl: received route with invalid destination prefixlen, ignoring: %m");
387 r
= sd_rtnl_message_route_get_src_prefixlen(message
, &src_prefixlen
);
389 log_link_warning_errno(link
, r
, "rtnl: received route with invalid source prefixlen, ignoring: %m");
393 r
= sd_rtnl_message_route_get_scope(message
, &scope
);
395 log_link_warning_errno(link
, r
, "rtnl: received route with invalid scope, ignoring: %m");
399 r
= sd_rtnl_message_route_get_tos(message
, &tos
);
401 log_link_warning_errno(link
, r
, "rtnl: received route with invalid tos, ignoring: %m");
405 r
= sd_rtnl_message_route_get_type(message
, &rt_type
);
407 log_link_warning_errno(link
, r
, "rtnl: received route with invalid type, ignoring: %m");
411 r
= sd_rtnl_message_route_get_table(message
, &table
);
413 log_link_warning_errno(link
, r
, "rtnl: received route with invalid table, ignoring: %m");
417 r
= sd_netlink_message_read_u32(message
, RTA_PRIORITY
, &priority
);
418 if (r
< 0 && r
!= -ENODATA
) {
419 log_link_warning_errno(link
, r
, "rtnl: received route with invalid priority, ignoring: %m");
423 (void) route_get(link
, family
, &dst
, dst_prefixlen
, tos
, priority
, table
, &route
);
428 /* A route appeared that we did not request */
429 r
= route_add_foreign(link
, family
, &dst
, dst_prefixlen
, tos
, priority
, table
, &route
);
431 log_link_warning_errno(link
, r
, "Failed to add route, ignoring: %m");
436 route_update(route
, &src
, src_prefixlen
, &gw
, &prefsrc
, scope
, protocol
, rt_type
);
445 assert_not_reached("Received invalid RTNL message type");
451 int manager_rtnl_process_address(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
452 Manager
*m
= userdata
;
457 unsigned char prefixlen
;
459 union in_addr_union in_addr
;
460 struct ifa_cacheinfo cinfo
;
461 Address
*address
= NULL
;
462 char buf
[INET6_ADDRSTRLEN
], valid_buf
[FORMAT_TIMESPAN_MAX
];
463 const char *valid_str
= NULL
;
470 if (sd_netlink_message_is_error(message
)) {
471 r
= sd_netlink_message_get_errno(message
);
473 log_warning_errno(r
, "rtnl: failed to receive address, ignoring: %m");
478 r
= sd_netlink_message_get_type(message
, &type
);
480 log_warning_errno(r
, "rtnl: could not get message type, ignoring: %m");
482 } else if (!IN_SET(type
, RTM_NEWADDR
, RTM_DELADDR
)) {
483 log_warning("rtnl: received unexpected message type when processing address, ignoring");
487 r
= sd_rtnl_message_addr_get_ifindex(message
, &ifindex
);
489 log_warning_errno(r
, "rtnl: could not get ifindex from address, ignoring: %m");
491 } else if (ifindex
<= 0) {
492 log_warning("rtnl: received address message with invalid ifindex, ignoring: %d", ifindex
);
495 r
= link_get(m
, ifindex
, &link
);
496 if (r
< 0 || !link
) {
497 /* when enumerating we might be out of sync, but we will
498 * get the address again, so just ignore it */
500 log_warning("rtnl: received address for nonexistent link (%d), ignoring", ifindex
);
505 r
= sd_rtnl_message_addr_get_family(message
, &family
);
506 if (r
< 0 || !IN_SET(family
, AF_INET
, AF_INET6
)) {
507 log_link_warning(link
, "rtnl: received address with invalid family, ignoring");
511 r
= sd_rtnl_message_addr_get_prefixlen(message
, &prefixlen
);
513 log_link_warning_errno(link
, r
, "rtnl: received address with invalid prefixlen, ignoring: %m");
517 r
= sd_rtnl_message_addr_get_scope(message
, &scope
);
519 log_link_warning_errno(link
, r
, "rtnl: received address with invalid scope, ignoring: %m");
523 r
= sd_rtnl_message_addr_get_flags(message
, &flags
);
525 log_link_warning_errno(link
, r
, "rtnl: received address with invalid flags, ignoring: %m");
531 r
= sd_netlink_message_read_in_addr(message
, IFA_LOCAL
, &in_addr
.in
);
533 log_link_warning_errno(link
, r
, "rtnl: received address without valid address, ignoring: %m");
540 r
= sd_netlink_message_read_in6_addr(message
, IFA_ADDRESS
, &in_addr
.in6
);
542 log_link_warning_errno(link
, r
, "rtnl: received address without valid address, ignoring: %m");
549 assert_not_reached("Received unsupported address family");
552 if (!inet_ntop(family
, &in_addr
, buf
, INET6_ADDRSTRLEN
)) {
553 log_link_warning(link
, "Could not print address, ignoring");
557 r
= sd_netlink_message_read_cache_info(message
, IFA_CACHEINFO
, &cinfo
);
558 if (r
< 0 && r
!= -ENODATA
) {
559 log_link_warning_errno(link
, r
, "rtnl: cannot get IFA_CACHEINFO attribute, ignoring: %m");
562 if (cinfo
.ifa_valid
!= CACHE_INFO_INFINITY_LIFE_TIME
)
563 valid_str
= format_timespan(valid_buf
, FORMAT_TIMESPAN_MAX
,
564 cinfo
.ifa_valid
* USEC_PER_SEC
,
568 (void) address_get(link
, family
, &in_addr
, prefixlen
, &address
);
573 log_link_debug(link
, "Updating address: %s/%u (valid %s%s)", buf
, prefixlen
,
574 valid_str
? "for " : "forever", strempty(valid_str
));
576 /* An address appeared that we did not request */
577 r
= address_add_foreign(link
, family
, &in_addr
, prefixlen
, &address
);
579 log_link_warning_errno(link
, r
, "Failed to add address %s/%u, ignoring: %m", buf
, prefixlen
);
582 log_link_debug(link
, "Adding address: %s/%u (valid %s%s)", buf
, prefixlen
,
583 valid_str
? "for " : "forever", strempty(valid_str
));
586 r
= address_update(address
, flags
, scope
, &cinfo
);
588 log_link_warning_errno(link
, r
, "Failed to update address %s/%u, ignoring: %m", buf
, prefixlen
);
597 log_link_debug(link
, "Removing address: %s/%u (valid %s%s)", buf
, prefixlen
,
598 valid_str
? "for " : "forever", strempty(valid_str
));
599 (void) address_drop(address
);
601 log_link_warning(link
, "Removing non-existent address: %s/%u (valid %s%s), ignoring", buf
, prefixlen
,
602 valid_str
? "for " : "forever", strempty(valid_str
));
606 assert_not_reached("Received invalid RTNL message type");
612 static int manager_rtnl_process_link(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
613 Manager
*m
= userdata
;
615 NetDev
*netdev
= NULL
;
624 if (sd_netlink_message_is_error(message
)) {
625 r
= sd_netlink_message_get_errno(message
);
627 log_warning_errno(r
, "rtnl: Could not receive link, ignoring: %m");
632 r
= sd_netlink_message_get_type(message
, &type
);
634 log_warning_errno(r
, "rtnl: Could not get message type, ignoring: %m");
636 } else if (!IN_SET(type
, RTM_NEWLINK
, RTM_DELLINK
)) {
637 log_warning("rtnl: Received unexpected message type when processing link, ignoring");
641 r
= sd_rtnl_message_link_get_ifindex(message
, &ifindex
);
643 log_warning_errno(r
, "rtnl: Could not get ifindex from link, ignoring: %m");
645 } else if (ifindex
<= 0) {
646 log_warning("rtnl: received link message with invalid ifindex %d, ignoring", ifindex
);
650 r
= sd_netlink_message_read_string(message
, IFLA_IFNAME
, &name
);
652 log_warning_errno(r
, "rtnl: Received link message without ifname, ignoring: %m");
656 (void) link_get(m
, ifindex
, &link
);
657 (void) netdev_get(m
, name
, &netdev
);
662 /* link is new, so add it */
663 r
= link_add(m
, message
, &link
);
665 log_warning_errno(r
, "Could not add new link, ignoring: %m");
671 /* netdev exists, so make sure the ifindex matches */
672 r
= netdev_set_ifindex(netdev
, message
);
674 log_warning_errno(r
, "Could not set ifindex on netdev, ignoring: %m");
679 r
= link_update(link
, message
);
681 log_warning_errno(r
, "Could not update link, ignoring: %m");
694 assert_not_reached("Received invalid RTNL message type.");
700 int manager_rtnl_process_rule(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
701 uint8_t tos
= 0, to_prefixlen
= 0, from_prefixlen
= 0, protocol
= 0;
702 struct fib_rule_port_range sport
= {}, dport
= {};
703 union in_addr_union to
= {}, from
= {};
704 RoutingPolicyRule
*rule
= NULL
;
705 uint32_t fwmark
= 0, table
= 0;
706 const char *iif
= NULL
, *oif
= NULL
;
707 Manager
*m
= userdata
;
716 if (sd_netlink_message_is_error(message
)) {
717 r
= sd_netlink_message_get_errno(message
);
719 log_warning_errno(r
, "rtnl: failed to receive rule, ignoring: %m");
724 r
= sd_netlink_message_get_type(message
, &type
);
726 log_warning_errno(r
, "rtnl: could not get message type, ignoring: %m");
728 } else if (!IN_SET(type
, RTM_NEWRULE
, RTM_DELRULE
)) {
729 log_warning("rtnl: received unexpected message type '%u' when processing rule, ignoring", type
);
733 r
= sd_rtnl_message_get_family(message
, &family
);
735 log_warning_errno(r
, "rtnl: could not get rule family, ignoring: %m");
737 } else if (!IN_SET(family
, AF_INET
, AF_INET6
)) {
738 log_debug("rtnl: received address with invalid family %u, ignoring", family
);
744 r
= sd_netlink_message_read_in_addr(message
, FRA_SRC
, &from
.in
);
745 if (r
< 0 && r
!= -ENODATA
) {
746 log_warning_errno(r
, "rtnl: could not get FRA_SRC attribute, ignoring: %m");
749 r
= sd_rtnl_message_routing_policy_rule_get_rtm_src_prefixlen(message
, &from_prefixlen
);
751 log_warning_errno(r
, "rtnl: failed to retrieve rule from prefix length, ignoring: %m");
756 r
= sd_netlink_message_read_in_addr(message
, FRA_DST
, &to
.in
);
757 if (r
< 0 && r
!= -ENODATA
) {
758 log_warning_errno(r
, "rtnl: could not get FRA_DST attribute, ignoring: %m");
761 r
= sd_rtnl_message_routing_policy_rule_get_rtm_dst_prefixlen(message
, &to_prefixlen
);
763 log_warning_errno(r
, "rtnl: failed to retrieve rule to prefix length, ignoring: %m");
771 r
= sd_netlink_message_read_in6_addr(message
, FRA_SRC
, &from
.in6
);
772 if (r
< 0 && r
!= -ENODATA
) {
773 log_warning_errno(r
, "rtnl: could not get FRA_SRC attribute, ignoring: %m");
776 r
= sd_rtnl_message_routing_policy_rule_get_rtm_src_prefixlen(message
, &from_prefixlen
);
778 log_warning_errno(r
, "rtnl: failed to retrieve rule from prefix length, ignoring: %m");
783 r
= sd_netlink_message_read_in6_addr(message
, FRA_DST
, &to
.in6
);
784 if (r
< 0 && r
!= -ENODATA
) {
785 log_warning_errno(r
, "rtnl: could not get FRA_DST attribute, ignoring: %m");
788 r
= sd_rtnl_message_routing_policy_rule_get_rtm_dst_prefixlen(message
, &to_prefixlen
);
790 log_warning_errno(r
, "rtnl: failed to retrieve rule to prefix length, ignoring: %m");
798 assert_not_reached("Received unsupported address family");
801 if (from_prefixlen
== 0 && to_prefixlen
== 0)
804 r
= sd_netlink_message_read_u32(message
, FRA_FWMARK
, &fwmark
);
805 if (r
< 0 && r
!= -ENODATA
) {
806 log_warning_errno(r
, "rtnl: could not get FRA_FWMARK attribute, ignoring: %m");
810 r
= sd_netlink_message_read_u32(message
, FRA_TABLE
, &table
);
811 if (r
< 0 && r
!= -ENODATA
) {
812 log_warning_errno(r
, "rtnl: could not get FRA_TABLE attribute, ignoring: %m");
816 r
= sd_rtnl_message_routing_policy_rule_get_tos(message
, &tos
);
817 if (r
< 0 && r
!= -ENODATA
) {
818 log_warning_errno(r
, "rtnl: could not get ip rule TOS, ignoring: %m");
822 r
= sd_netlink_message_read_string(message
, FRA_IIFNAME
, &iif
);
823 if (r
< 0 && r
!= -ENODATA
) {
824 log_warning_errno(r
, "rtnl: could not get FRA_IIFNAME attribute, ignoring: %m");
828 r
= sd_netlink_message_read_string(message
, FRA_OIFNAME
, &oif
);
829 if (r
< 0 && r
!= -ENODATA
) {
830 log_warning_errno(r
, "rtnl: could not get FRA_OIFNAME attribute, ignoring: %m");
834 r
= sd_netlink_message_read_u8(message
, FRA_IP_PROTO
, &protocol
);
835 if (r
< 0 && r
!= -ENODATA
) {
836 log_warning_errno(r
, "rtnl: could not get FRA_IP_PROTO attribute, ignoring: %m");
840 r
= sd_netlink_message_read(message
, FRA_SPORT_RANGE
, sizeof(sport
), (void *) &sport
);
841 if (r
< 0 && r
!= -ENODATA
) {
842 log_warning_errno(r
, "rtnl: could not get FRA_SPORT_RANGE attribute, ignoring: %m");
846 r
= sd_netlink_message_read(message
, FRA_DPORT_RANGE
, sizeof(dport
), (void *) &dport
);
847 if (r
< 0 && r
!= -ENODATA
) {
848 log_warning_errno(r
, "rtnl: could not get FRA_DPORT_RANGE attribute, ignoring: %m");
852 (void) routing_policy_rule_get(m
, family
, &from
, from_prefixlen
, &to
, to_prefixlen
, tos
, fwmark
, table
, iif
, oif
, protocol
, &sport
, &dport
, &rule
);
857 r
= routing_policy_rule_add_foreign(m
, family
, &from
, from_prefixlen
, &to
, to_prefixlen
, tos
, fwmark
, table
, iif
, oif
, protocol
, &sport
, &dport
, &rule
);
859 log_warning_errno(r
, "Could not add rule, ignoring: %m");
865 routing_policy_rule_free(rule
);
870 assert_not_reached("Received invalid RTNL message type");
876 static int systemd_netlink_fd(void) {
877 int n
, fd
, rtnl_fd
= -EINVAL
;
879 n
= sd_listen_fds(true);
883 for (fd
= SD_LISTEN_FDS_START
; fd
< SD_LISTEN_FDS_START
+ n
; fd
++) {
884 if (sd_is_socket(fd
, AF_NETLINK
, SOCK_RAW
, -1) > 0) {
895 static int manager_connect_genl(Manager
*m
) {
900 r
= sd_genl_socket_open(&m
->genl
);
904 r
= sd_netlink_inc_rcvbuf(m
->genl
, RCVBUF_SIZE
);
908 r
= sd_netlink_attach_event(m
->genl
, m
->event
, 0);
915 static int manager_connect_rtnl(Manager
*m
) {
920 fd
= systemd_netlink_fd();
922 r
= sd_netlink_open(&m
->rtnl
);
924 r
= sd_netlink_open_fd(&m
->rtnl
, fd
);
928 r
= sd_netlink_inc_rcvbuf(m
->rtnl
, RCVBUF_SIZE
);
932 r
= sd_netlink_attach_event(m
->rtnl
, m
->event
, 0);
936 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_NEWLINK
, &manager_rtnl_process_link
, NULL
, m
, "network-rtnl_process_link");
940 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_DELLINK
, &manager_rtnl_process_link
, NULL
, m
, "network-rtnl_process_link");
944 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_NEWADDR
, &manager_rtnl_process_address
, NULL
, m
, "network-rtnl_process_address");
948 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_DELADDR
, &manager_rtnl_process_address
, NULL
, m
, "network-rtnl_process_address");
952 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_NEWROUTE
, &manager_rtnl_process_route
, NULL
, m
, "network-rtnl_process_route");
956 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_DELROUTE
, &manager_rtnl_process_route
, NULL
, m
, "network-rtnl_process_route");
960 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_NEWRULE
, &manager_rtnl_process_rule
, NULL
, m
, "network-rtnl_process_rule");
964 r
= sd_netlink_add_match(m
->rtnl
, NULL
, RTM_DELRULE
, &manager_rtnl_process_rule
, NULL
, m
, "network-rtnl_process_rule");
971 static int ordered_set_put_in_addr_data(OrderedSet
*s
, const struct in_addr_data
*address
) {
978 r
= in_addr_to_string(address
->family
, &address
->address
, &p
);
982 r
= ordered_set_consume(s
, p
);
989 static int ordered_set_put_in_addr_datav(OrderedSet
*s
, const struct in_addr_data
*addresses
, unsigned n
) {
994 assert(addresses
|| n
== 0);
996 for (i
= 0; i
< n
; i
++) {
997 r
= ordered_set_put_in_addr_data(s
, addresses
+i
);
1007 static int ordered_set_put_in4_addr(OrderedSet
*s
, const struct in_addr
*address
) {
1014 r
= in_addr_to_string(AF_INET
, (const union in_addr_union
*) address
, &p
);
1018 r
= ordered_set_consume(s
, p
);
1025 static int ordered_set_put_in4_addrv(OrderedSet
*s
, const struct in_addr
*addresses
, unsigned n
) {
1030 assert(n
== 0 || addresses
);
1032 for (i
= 0; i
< n
; i
++) {
1033 r
= ordered_set_put_in4_addr(s
, addresses
+i
);
1043 static void print_string_set(FILE *f
, const char *field
, OrderedSet
*s
) {
1048 if (ordered_set_isempty(s
))
1053 ORDERED_SET_FOREACH(p
, s
, i
)
1054 fputs_with_space(f
, p
, NULL
, &space
);
1059 static int manager_save(Manager
*m
) {
1060 _cleanup_ordered_set_free_free_ OrderedSet
*dns
= NULL
, *ntp
= NULL
, *search_domains
= NULL
, *route_domains
= NULL
;
1063 _cleanup_free_
char *temp_path
= NULL
;
1064 _cleanup_fclose_
FILE *f
= NULL
;
1065 LinkOperationalState operstate
= LINK_OPERSTATE_OFF
;
1066 const char *operstate_str
;
1070 assert(m
->state_file
);
1072 /* We add all NTP and DNS server to a set, to filter out duplicates */
1073 dns
= ordered_set_new(&string_hash_ops
);
1077 ntp
= ordered_set_new(&string_hash_ops
);
1081 search_domains
= ordered_set_new(&dns_name_hash_ops
);
1082 if (!search_domains
)
1085 route_domains
= ordered_set_new(&dns_name_hash_ops
);
1089 HASHMAP_FOREACH(link
, m
->links
, i
) {
1090 if (link
->flags
& IFF_LOOPBACK
)
1093 if (link
->operstate
> operstate
)
1094 operstate
= link
->operstate
;
1099 /* First add the static configured entries */
1100 r
= ordered_set_put_in_addr_datav(dns
, link
->network
->dns
, link
->network
->n_dns
);
1104 r
= ordered_set_put_strdupv(ntp
, link
->network
->ntp
);
1108 r
= ordered_set_put_strdupv(search_domains
, link
->network
->search_domains
);
1112 r
= ordered_set_put_strdupv(route_domains
, link
->network
->route_domains
);
1116 if (!link
->dhcp_lease
)
1119 /* Secondly, add the entries acquired via DHCP */
1120 if (link
->network
->dhcp_use_dns
) {
1121 const struct in_addr
*addresses
;
1123 r
= sd_dhcp_lease_get_dns(link
->dhcp_lease
, &addresses
);
1125 r
= ordered_set_put_in4_addrv(dns
, addresses
, r
);
1128 } else if (r
< 0 && r
!= -ENODATA
)
1132 if (link
->network
->dhcp_use_ntp
) {
1133 const struct in_addr
*addresses
;
1135 r
= sd_dhcp_lease_get_ntp(link
->dhcp_lease
, &addresses
);
1137 r
= ordered_set_put_in4_addrv(ntp
, addresses
, r
);
1140 } else if (r
< 0 && r
!= -ENODATA
)
1144 if (link
->network
->dhcp_use_domains
!= DHCP_USE_DOMAINS_NO
) {
1145 const char *domainname
;
1146 char **domains
= NULL
;
1148 OrderedSet
*target_domains
= (link
->network
->dhcp_use_domains
== DHCP_USE_DOMAINS_YES
) ? search_domains
: route_domains
;
1149 r
= sd_dhcp_lease_get_domainname(link
->dhcp_lease
, &domainname
);
1151 r
= ordered_set_put_strdup(target_domains
, domainname
);
1154 } else if (r
!= -ENODATA
)
1157 r
= sd_dhcp_lease_get_search_domains(link
->dhcp_lease
, &domains
);
1159 r
= ordered_set_put_strdupv(target_domains
, domains
);
1162 } else if (r
!= -ENODATA
)
1167 operstate_str
= link_operstate_to_string(operstate
);
1168 assert(operstate_str
);
1170 r
= fopen_temporary(m
->state_file
, &f
, &temp_path
);
1174 (void) __fsetlocking(f
, FSETLOCKING_BYCALLER
);
1175 (void) fchmod(fileno(f
), 0644);
1178 "# This is private data. Do not parse.\n"
1179 "OPER_STATE=%s\n", operstate_str
);
1181 print_string_set(f
, "DNS=", dns
);
1182 print_string_set(f
, "NTP=", ntp
);
1183 print_string_set(f
, "DOMAINS=", search_domains
);
1184 print_string_set(f
, "ROUTE_DOMAINS=", route_domains
);
1186 r
= routing_policy_serialize_rules(m
->rules
, f
);
1190 r
= fflush_and_check(f
);
1194 if (rename(temp_path
, m
->state_file
) < 0) {
1199 if (m
->operational_state
!= operstate
) {
1200 m
->operational_state
= operstate
;
1201 r
= manager_send_changed(m
, "OperationalState", NULL
);
1203 log_error_errno(r
, "Could not emit changed OperationalState: %m");
1211 (void) unlink(m
->state_file
);
1212 (void) unlink(temp_path
);
1214 return log_error_errno(r
, "Failed to save network state to %s: %m", m
->state_file
);
1217 static int manager_dirty_handler(sd_event_source
*s
, void *userdata
) {
1218 Manager
*m
= userdata
;
1227 SET_FOREACH(link
, m
->dirty_links
, i
)
1228 if (link_save(link
) >= 0)
1234 Link
*manager_dhcp6_prefix_get(Manager
*m
, struct in6_addr
*addr
) {
1235 assert_return(m
, NULL
);
1236 assert_return(addr
, NULL
);
1238 return hashmap_get(m
->dhcp6_prefixes
, addr
);
1241 static int dhcp6_route_add_handler(sd_netlink
*nl
, sd_netlink_message
*m
, Link
*link
) {
1246 r
= sd_netlink_message_get_errno(m
);
1247 if (r
< 0 && r
!= -EEXIST
)
1248 log_link_debug_errno(link
, r
, "Received error adding DHCPv6 Prefix Delegation route: %m");
1253 static void dhcp6_prefixes_hash_func(const struct in6_addr
*addr
, struct siphash
*state
) {
1256 siphash24_compress(addr
, sizeof(*addr
), state
);
1259 static int dhcp6_prefixes_compare_func(const struct in6_addr
*a
, const struct in6_addr
*b
) {
1260 return memcmp(a
, b
, sizeof(*a
));
1263 DEFINE_PRIVATE_HASH_OPS(dhcp6_prefixes_hash_ops
, struct in6_addr
, dhcp6_prefixes_hash_func
, dhcp6_prefixes_compare_func
);
1265 int manager_dhcp6_prefix_add(Manager
*m
, struct in6_addr
*addr
, Link
*link
) {
1266 _cleanup_free_
char *buf
= NULL
;
1270 assert_return(m
, -EINVAL
);
1271 assert_return(addr
, -EINVAL
);
1273 r
= route_add(link
, AF_INET6
, (union in_addr_union
*) addr
, 64,
1278 r
= route_configure(route
, link
, dhcp6_route_add_handler
);
1282 (void) in_addr_to_string(AF_INET6
, (union in_addr_union
*) addr
, &buf
);
1283 log_link_debug(link
, "Adding prefix route %s/64", strnull(buf
));
1285 r
= hashmap_ensure_allocated(&m
->dhcp6_prefixes
, &dhcp6_prefixes_hash_ops
);
1289 return hashmap_put(m
->dhcp6_prefixes
, addr
, link
);
1292 static int dhcp6_route_remove_handler(sd_netlink
*nl
, sd_netlink_message
*m
, Link
*link
) {
1297 r
= sd_netlink_message_get_errno(m
);
1299 log_link_debug_errno(link
, r
, "Received error on DHCPv6 Prefix Delegation route removal: %m");
1304 static int manager_dhcp6_prefix_remove(Manager
*m
, struct in6_addr
*addr
) {
1305 _cleanup_free_
char *buf
= NULL
;
1310 assert_return(m
, -EINVAL
);
1311 assert_return(addr
, -EINVAL
);
1313 l
= hashmap_remove(m
->dhcp6_prefixes
, addr
);
1317 (void) sd_radv_remove_prefix(l
->radv
, addr
, 64);
1318 r
= route_get(l
, AF_INET6
, (union in_addr_union
*) addr
, 64,
1323 r
= route_remove(route
, l
, dhcp6_route_remove_handler
);
1327 (void) in_addr_to_string(AF_INET6
, (union in_addr_union
*) addr
, &buf
);
1328 log_link_debug(l
, "Removing prefix route %s/64", strnull(buf
));
1333 int manager_dhcp6_prefix_remove_all(Manager
*m
, Link
*link
) {
1334 struct in6_addr
*addr
;
1338 assert_return(m
, -EINVAL
);
1339 assert_return(link
, -EINVAL
);
1341 HASHMAP_FOREACH_KEY(l
, addr
, m
->dhcp6_prefixes
, i
) {
1345 (void) manager_dhcp6_prefix_remove(m
, addr
);
1351 int manager_new(Manager
**ret
) {
1352 _cleanup_(manager_freep
) Manager
*m
= NULL
;
1355 m
= new0(Manager
, 1);
1359 m
->state_file
= strdup("/run/systemd/netif/state");
1363 r
= sd_event_default(&m
->event
);
1367 (void) sd_event_set_watchdog(m
->event
, true);
1368 (void) sd_event_add_signal(m
->event
, NULL
, SIGTERM
, NULL
, NULL
);
1369 (void) sd_event_add_signal(m
->event
, NULL
, SIGINT
, NULL
, NULL
);
1371 r
= sd_event_add_post(m
->event
, NULL
, manager_dirty_handler
, m
);
1375 r
= manager_connect_rtnl(m
);
1379 r
= manager_connect_genl(m
);
1383 r
= manager_connect_udev(m
);
1387 LIST_HEAD_INIT(m
->networks
);
1389 r
= sd_resolve_default(&m
->resolve
);
1393 r
= sd_resolve_attach_event(m
->resolve
, m
->event
, 0);
1397 r
= setup_default_address_pool(m
);
1401 m
->duid
.type
= DUID_TYPE_EN
;
1403 (void) routing_policy_load_rules(m
->state_file
, &m
->rules_saved
);
1410 void manager_free(Manager
*m
) {
1418 free(m
->state_file
);
1420 sd_netlink_unref(m
->rtnl
);
1421 sd_netlink_unref(m
->genl
);
1422 sd_resolve_unref(m
->resolve
);
1424 while ((network
= m
->networks
))
1425 network_free(network
);
1427 while ((link
= hashmap_first(m
->dhcp6_prefixes
)))
1428 manager_dhcp6_prefix_remove_all(m
, link
);
1429 hashmap_free(m
->dhcp6_prefixes
);
1431 while ((link
= hashmap_steal_first(m
->links
))) {
1432 if (link
->dhcp6_client
)
1433 (void) dhcp6_lease_pd_prefix_lost(link
->dhcp6_client
, link
);
1437 m
->dirty_links
= set_free_with_destructor(m
->dirty_links
, link_unref
);
1438 m
->links
= hashmap_free(m
->links
);
1439 m
->links_requesting_uuid
= set_free(m
->links_requesting_uuid
);
1440 set_free(m
->duids_requesting_uuid
);
1442 hashmap_free(m
->networks_by_name
);
1444 m
->netdevs
= hashmap_free_with_destructor(m
->netdevs
, netdev_unref
);
1446 while ((pool
= m
->address_pools
))
1447 address_pool_free(pool
);
1449 /* routing_policy_rule_free() access m->rules and m->rules_foreign.
1450 * So, it is necessary to set NULL after the sets are freed. */
1451 m
->rules
= set_free_with_destructor(m
->rules
, routing_policy_rule_free
);
1452 m
->rules_foreign
= set_free_with_destructor(m
->rules_foreign
, routing_policy_rule_free
);
1453 set_free_with_destructor(m
->rules_saved
, routing_policy_rule_free
);
1455 sd_event_unref(m
->event
);
1457 sd_device_monitor_unref(m
->device_monitor
);
1459 sd_bus_unref(m
->bus
);
1461 free(m
->dynamic_timezone
);
1462 free(m
->dynamic_hostname
);
1467 int manager_start(Manager
*m
) {
1473 /* The dirty handler will deal with future serialization, but the first one
1474 must be done explicitly. */
1478 HASHMAP_FOREACH(link
, m
->links
, i
)
1484 int manager_load_config(Manager
*m
) {
1487 /* update timestamp */
1488 paths_check_timestamp(network_dirs
, &m
->network_dirs_ts_usec
, true);
1494 r
= network_load(m
);
1501 bool manager_should_reload(Manager
*m
) {
1502 return paths_check_timestamp(network_dirs
, &m
->network_dirs_ts_usec
, false);
1505 int manager_rtnl_enumerate_links(Manager
*m
) {
1506 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1507 sd_netlink_message
*link
;
1513 r
= sd_rtnl_message_new_link(m
->rtnl
, &req
, RTM_GETLINK
, 0);
1517 r
= sd_netlink_message_request_dump(req
, true);
1521 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1525 for (link
= reply
; link
; link
= sd_netlink_message_next(link
)) {
1528 m
->enumerating
= true;
1530 k
= manager_rtnl_process_link(m
->rtnl
, link
, m
);
1534 m
->enumerating
= false;
1540 int manager_rtnl_enumerate_addresses(Manager
*m
) {
1541 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1542 sd_netlink_message
*addr
;
1548 r
= sd_rtnl_message_new_addr(m
->rtnl
, &req
, RTM_GETADDR
, 0, 0);
1552 r
= sd_netlink_message_request_dump(req
, true);
1556 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1560 for (addr
= reply
; addr
; addr
= sd_netlink_message_next(addr
)) {
1563 m
->enumerating
= true;
1565 k
= manager_rtnl_process_address(m
->rtnl
, addr
, m
);
1569 m
->enumerating
= false;
1575 int manager_rtnl_enumerate_routes(Manager
*m
) {
1576 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1577 sd_netlink_message
*route
;
1583 r
= sd_rtnl_message_new_route(m
->rtnl
, &req
, RTM_GETROUTE
, 0, 0);
1587 r
= sd_netlink_message_request_dump(req
, true);
1591 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1595 for (route
= reply
; route
; route
= sd_netlink_message_next(route
)) {
1598 m
->enumerating
= true;
1600 k
= manager_rtnl_process_route(m
->rtnl
, route
, m
);
1604 m
->enumerating
= false;
1610 int manager_rtnl_enumerate_rules(Manager
*m
) {
1611 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1612 sd_netlink_message
*rule
;
1618 r
= sd_rtnl_message_new_routing_policy_rule(m
->rtnl
, &req
, RTM_GETRULE
, 0);
1622 r
= sd_netlink_message_request_dump(req
, true);
1626 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1628 if (r
== -EOPNOTSUPP
) {
1629 log_debug("FIB Rules are not supported by the kernel. Ignoring.");
1636 for (rule
= reply
; rule
; rule
= sd_netlink_message_next(rule
)) {
1639 m
->enumerating
= true;
1641 k
= manager_rtnl_process_rule(m
->rtnl
, rule
, m
);
1645 m
->enumerating
= false;
1651 int manager_address_pool_acquire(Manager
*m
, int family
, unsigned prefixlen
, union in_addr_union
*found
) {
1656 assert(prefixlen
> 0);
1659 LIST_FOREACH(address_pools
, p
, m
->address_pools
) {
1660 if (p
->family
!= family
)
1663 r
= address_pool_acquire(p
, prefixlen
, found
);
1671 Link
* manager_find_uplink(Manager
*m
, Link
*exclude
) {
1672 _cleanup_free_
struct local_address
*gateways
= NULL
;
1677 /* Looks for a suitable "uplink", via black magic: an
1678 * interface that is up and where the default route with the
1679 * highest priority points to. */
1681 n
= local_gateways(m
->rtnl
, 0, AF_UNSPEC
, &gateways
);
1683 log_warning_errno(n
, "Failed to determine list of default gateways: %m");
1687 for (i
= 0; i
< n
; i
++) {
1690 link
= hashmap_get(m
->links
, INT_TO_PTR(gateways
[i
].ifindex
));
1692 log_debug("Weird, found a gateway for a link we don't know. Ignoring.");
1696 if (link
== exclude
)
1699 if (link
->operstate
< LINK_OPERSTATE_ROUTABLE
)
1708 void manager_dirty(Manager
*manager
) {
1711 /* the serialized state in /run is no longer up-to-date */
1712 manager
->dirty
= true;
1715 static int set_hostname_handler(sd_bus_message
*m
, void *userdata
, sd_bus_error
*ret_error
) {
1716 Manager
*manager
= userdata
;
1717 const sd_bus_error
*e
;
1722 e
= sd_bus_message_get_error(m
);
1724 log_warning_errno(sd_bus_error_get_errno(e
), "Could not set hostname: %s", e
->message
);
1729 int manager_set_hostname(Manager
*m
, const char *hostname
) {
1732 log_debug("Setting transient hostname: '%s'", strna(hostname
));
1734 if (free_and_strdup(&m
->dynamic_hostname
, hostname
) < 0)
1737 if (!m
->bus
|| sd_bus_is_ready(m
->bus
) <= 0) {
1738 log_debug("Not connected to system bus, setting hostname later.");
1742 r
= sd_bus_call_method_async(
1745 "org.freedesktop.hostname1",
1746 "/org/freedesktop/hostname1",
1747 "org.freedesktop.hostname1",
1749 set_hostname_handler
,
1756 return log_error_errno(r
, "Could not set transient hostname: %m");
1761 static int set_timezone_handler(sd_bus_message
*m
, void *userdata
, sd_bus_error
*ret_error
) {
1762 Manager
*manager
= userdata
;
1763 const sd_bus_error
*e
;
1768 e
= sd_bus_message_get_error(m
);
1770 log_warning_errno(sd_bus_error_get_errno(e
), "Could not set timezone: %s", e
->message
);
1775 int manager_set_timezone(Manager
*m
, const char *tz
) {
1781 log_debug("Setting system timezone: '%s'", tz
);
1782 if (free_and_strdup(&m
->dynamic_timezone
, tz
) < 0)
1785 if (!m
->bus
|| sd_bus_is_ready(m
->bus
) <= 0) {
1786 log_debug("Not connected to system bus, setting timezone later.");
1790 r
= sd_bus_call_method_async(
1793 "org.freedesktop.timedate1",
1794 "/org/freedesktop/timedate1",
1795 "org.freedesktop.timedate1",
1797 set_timezone_handler
,
1803 return log_error_errno(r
, "Could not set timezone: %m");
1808 int manager_request_product_uuid(Manager
*m
, Link
*link
) {
1813 if (m
->has_product_uuid
)
1816 log_debug("Requesting product UUID");
1821 assert_se(duid
= link_get_duid(link
));
1823 r
= set_ensure_allocated(&m
->links_requesting_uuid
, NULL
);
1827 r
= set_ensure_allocated(&m
->duids_requesting_uuid
, NULL
);
1831 r
= set_put(m
->links_requesting_uuid
, link
);
1835 r
= set_put(m
->duids_requesting_uuid
, duid
);
1840 if (!m
->bus
|| sd_bus_is_ready(m
->bus
) <= 0) {
1841 log_debug("Not connected to system bus, requesting product UUID later.");
1845 r
= sd_bus_call_method_async(
1848 "org.freedesktop.hostname1",
1849 "/org/freedesktop/hostname1",
1850 "org.freedesktop.hostname1",
1852 get_product_uuid_handler
,
1857 return log_warning_errno(r
, "Failed to get product UUID: %m");