]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/network/networkd.c
resolved: do not keep dns_server to dns_stream ref if tls connection failed (#9855)
[thirdparty/systemd.git] / src / network / networkd.c
1 /* SPDX-License-Identifier: LGPL-2.1+ */
2
3 #include "sd-daemon.h"
4 #include "sd-event.h"
5
6 #include "capability-util.h"
7 #include "networkd-conf.h"
8 #include "networkd-manager.h"
9 #include "signal-util.h"
10 #include "user-util.h"
11
12 int main(int argc, char *argv[]) {
13 _cleanup_(manager_freep) Manager *m = NULL;
14 const char *user = "systemd-network";
15 uid_t uid;
16 gid_t gid;
17 int r;
18
19 log_set_target(LOG_TARGET_AUTO);
20 log_parse_environment();
21 log_open();
22
23 umask(0022);
24
25 if (argc != 1) {
26 log_error("This program takes no arguments.");
27 r = -EINVAL;
28 goto out;
29 }
30
31 r = get_user_creds(&user, &uid, &gid, NULL, NULL);
32 if (r < 0) {
33 log_error_errno(r, "Cannot resolve user name %s: %m", user);
34 goto out;
35 }
36
37 /* Create runtime directory. This is not necessary when networkd is
38 * started with "RuntimeDirectory=systemd/netif", or after
39 * systemd-tmpfiles-setup.service. */
40 r = mkdir_safe_label("/run/systemd/netif", 0755, uid, gid, MKDIR_WARN_MODE);
41 if (r < 0)
42 log_warning_errno(r, "Could not create runtime directory: %m");
43
44 /* Drop privileges, but only if we have been started as root. If we are not running as root we assume all
45 * privileges are already dropped. */
46 if (geteuid() == 0) {
47 r = drop_privileges(uid, gid,
48 (1ULL << CAP_NET_ADMIN) |
49 (1ULL << CAP_NET_BIND_SERVICE) |
50 (1ULL << CAP_NET_BROADCAST) |
51 (1ULL << CAP_NET_RAW));
52 if (r < 0)
53 goto out;
54 }
55
56 /* Always create the directories people can create inotify watches in.
57 * It is necessary to create the following subdirectories after drop_privileges()
58 * to support old kernels not supporting AmbientCapabilities=. */
59 r = mkdir_safe_label("/run/systemd/netif/links", 0755, uid, gid, MKDIR_WARN_MODE);
60 if (r < 0)
61 log_warning_errno(r, "Could not create runtime directory 'links': %m");
62
63 r = mkdir_safe_label("/run/systemd/netif/leases", 0755, uid, gid, MKDIR_WARN_MODE);
64 if (r < 0)
65 log_warning_errno(r, "Could not create runtime directory 'leases': %m");
66
67 r = mkdir_safe_label("/run/systemd/netif/lldp", 0755, uid, gid, MKDIR_WARN_MODE);
68 if (r < 0)
69 log_warning_errno(r, "Could not create runtime directory 'lldp': %m");
70
71 assert_se(sigprocmask_many(SIG_BLOCK, NULL, SIGTERM, SIGINT, -1) >= 0);
72
73 r = manager_new(&m);
74 if (r < 0) {
75 log_error_errno(r, "Could not create manager: %m");
76 goto out;
77 }
78
79 r = manager_connect_bus(m);
80 if (r < 0) {
81 log_error_errno(r, "Could not connect to bus: %m");
82 goto out;
83 }
84
85 r = manager_parse_config_file(m);
86 if (r < 0)
87 log_warning_errno(r, "Failed to parse configuration file: %m");
88
89 r = manager_load_config(m);
90 if (r < 0) {
91 log_error_errno(r, "Could not load configuration files: %m");
92 goto out;
93 }
94
95 r = manager_rtnl_enumerate_links(m);
96 if (r < 0) {
97 log_error_errno(r, "Could not enumerate links: %m");
98 goto out;
99 }
100
101 r = manager_rtnl_enumerate_addresses(m);
102 if (r < 0) {
103 log_error_errno(r, "Could not enumerate addresses: %m");
104 goto out;
105 }
106
107 r = manager_rtnl_enumerate_routes(m);
108 if (r < 0) {
109 log_error_errno(r, "Could not enumerate routes: %m");
110 goto out;
111 }
112
113 r = manager_rtnl_enumerate_rules(m);
114 if (r < 0) {
115 log_error_errno(r, "Could not enumerate rules: %m");
116 goto out;
117 }
118
119 r = manager_start(m);
120 if (r < 0) {
121 log_error_errno(r, "Could not start manager: %m");
122 goto out;
123 }
124
125 log_info("Enumeration completed");
126
127 sd_notify(false,
128 "READY=1\n"
129 "STATUS=Processing requests...");
130
131 r = sd_event_loop(m->event);
132 if (r < 0) {
133 log_error_errno(r, "Event loop failed: %m");
134 goto out;
135 }
136 out:
137 sd_notify(false,
138 "STOPPING=1\n"
139 "STATUS=Shutting down...");
140
141 return r < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
142 }