2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
25 if device_exists
${device}; then
31 for d
in $
(devices_get_all
); do
32 if [ "$(device_get_address ${d})" = "${device}" ]; then
44 if mac_is_valid
${device}; then
49 if device_exists
${device}; then
50 device_get_address
${device}
57 # Check if the device exists
58 function device_exists
() {
61 # If device name was not found, exit.
62 [ -n "${device}" ] ||
return ${EXIT_ERROR}
64 [ -d "${SYS_CLASS_NET}/${device}" ]
67 # Check if the device is up
68 function device_is_up
() {
71 device_exists
${device} ||
return ${EXIT_ERROR}
73 ip link show
${device} 2>/dev
/null |
grep -qE "<.*UP.*>"
76 # Check if the device is a bonding device
77 function device_is_bonding
() {
78 [ -d "/sys/class/net/${1}/bonding" ]
81 # Check if the device bonded in a bonding device
82 function device_is_bonded
() {
84 for dev
in /sys
/class
/net
/*; do
86 [ -d "${dev}" ] ||
continue
88 # Continue if not a bonding device
89 device_is_bonding
"${dev##*/}" ||
continue
91 if grep -q "\<${1}\>" ${dev}/bonding
/slaves
; then
99 # Check if the device is a bridge
100 function device_is_bridge
() {
101 [ -d "/sys/class/net/${1}/bridge" ]
104 function device_is_bridge_attached
() {
107 [ -d "${SYS_CLASS_NET}/${device}/brport" ]
110 # Check if the device is a virtual device
111 function device_is_virtual
() {
114 [ -e "/proc/net/vlan/${device}" ]
117 # Check if the device has virtual devices
118 function device_has_virtuals
() {
121 if device_is_virtual
${device}; then
125 if [ ! -e "/proc/net/vlan/config" ]; then
128 grep -q "${1}$" /proc
/net
/vlan
/config
131 function device_is_vlan
() { # XXX Compat function
132 log DEBUG
"Deprecated function device_is_vlan() was used."
137 # Check if the device is a ppp device
138 function device_is_ppp
() {
141 ip link show
${device} 2>/dev
/null |
grep -qE "<.*POINTOPOINT.*>"
144 # Check if the device is a loopback device
145 function device_is_loopback
() {
146 local device
=$
(devicify
${1})
147 [ "${device}" = "lo" ]
150 # Check if the device is a physical network interface
151 function device_is_real
() {
154 device_is_loopback
${device} && \
157 device_is_bonding
${device} && \
160 device_is_bridge
${device} && \
163 device_is_ppp
${device} && \
166 device_is_virtual
${device} && \
172 # Get the device type
173 function device_get_type
() {
174 local device
=$
(devicify
${1})
176 if device_is_vlan
${device}; then
179 elif device_is_bonding
${device}; then
182 elif device_is_bridge
${device}; then
185 elif device_is_ppp
${device}; then
188 elif device_is_loopback
${device}; then
191 elif device_is_real
${device}; then
199 function device_get_address
() {
202 cat ${SYS_CLASS_NET}/${device}/address
2>/dev
/null
205 function device_set_address
() {
209 if ! device_exists
${device}; then
210 error
"Device '${device}' does not exist."
214 log INFO
"Setting address of '${device}' to '${addr}' - was $(device_get_address ${device})."
217 if device_is_up
${device}; then
218 device_set_down
${device}
222 ip link
set ${device} address
${addr}
225 if [ "${up}" = "1" ]; then
226 device_set_up
${device}
229 if [ "${ret}" != "0" ]; then
230 error_log
"Could not set address '${addr}' on device '${device}'."
236 function devices_get_all
() {
238 for device
in ${SYS_CLASS_NET}/*; do
239 echo "$(basename ${device})"
243 # Check if a device has a cable plugged in
244 function device_has_carrier
() {
245 local device
=$
(devicify
${1})
246 [ "$(<${SYS_CLASS_NET}/${device}/carrier)" = "1" ]
249 # Check if the device is free
250 function device_is_free
() {
254 # Check if the device is used
255 function device_is_used
() {
256 local device
=$
(devicify
${1})
258 device_has_virtuals
${device} && \
260 device_is_bonded
${device} && \
262 device_is_bridge_attached
${device} && \
268 # XXX to be removed I think
269 function device_get_free
() {
270 local destination
=${1}
272 # Replace + by a valid number
273 if grep -q "+$" <<<${destination}; then
275 destination
=$
(sed -e "s/+//" <<<$destination)
276 while [ "${number}" -le "100" ]; do
277 if ! device_exists
"${destination}${number}"; then
278 destination
="${destination}${number}"
281 number
=$
(($number + 1))
284 echo "${destination}"
287 function device_rename
() {
288 warning_log
"Called deprecated function 'device_rename'"
293 function device_hash
() {
296 macify
${device} |
tr -d ':'
299 # Give the device a new name
300 function device_set_name
() {
302 local destination
=$
(device_get_free
${2})
304 # Check if devices exists
305 if ! device_exists
${source} || device_exists
${destination}; then
310 if device_is_up
${source}; then
311 ip link
set ${source} down
315 ip link
set ${source} name
${destination}
317 if [ "${up}" = "1" ]; then
318 ip link
set ${destination} up
323 function device_set_up
() {
324 local device
=$
(devicify
${1})
326 # Do nothing if device is already up
327 device_is_up
${device} && return ${EXIT_OK}
329 device_set_parent_up
${device}
331 log DEBUG
"Setting up device '${device}'"
333 ip link
set ${device} up
336 function device_set_parent_up
() {
340 if device_is_virtual
${device}; then
341 parent
=$
(device_virtual_get_parent
${device})
343 device_is_up
${parent} && return ${EXIT_OK}
345 log DEBUG
"Setting up parent device '${parent}' of '${device}'"
347 device_set_up
${parent}
355 function device_set_down
() {
356 local device
=$
(devicify
${1})
360 if device_is_up
${device}; then
361 log DEBUG
"Tearing down device '${device}'"
363 ip link
set ${device} down
367 device_set_parent_down
${device}
372 function device_set_parent_down
() {
376 if device_is_virtual
${device}; then
377 parent
=$
(device_virtual_get_parent
${device})
379 device_is_up
${parent} ||
return ${EXIT_OK}
381 if device_is_free
${parent}; then
382 log DEBUG
"Tearing down parent device '${parent}' of '${device}'"
384 device_set_down
${parent}
391 function device_get_mtu
() {
394 if ! device_exists
${device}; then
395 error
"Device '${device}' does not exist."
399 cat ${SYS_CLASS_NET}/${device}/mtu
402 # Set mtu to a device
403 function device_set_mtu
() {
407 if ! device_exists
${device}; then
408 error
"Device '${device}' does not exist."
412 local oldmtu
=$
(device_get_mtu
${device})
414 if [ "${oldmtu}" = "${mtu}" ]; then
415 # No need to set mtu.
419 log INFO
"Setting mtu of '${device}' to '${mtu}' - was ${oldmtu}."
422 if device_is_up
${device}; then
423 device_set_down
${device}
427 ip link
set ${device} mtu
${mtu}
430 if [ "${up}" = "1" ]; then
431 device_set_up
${device}
434 if [ "${ret}" != "0" ]; then
435 error_log
"Could not set mtu '${mtu}' on device '${device}'."
441 function device_discover
() {
444 log INFO
"Running discovery process on device '${device}'."
447 for hook
in $
(hooks_get_all
); do
448 hook_exec
${hook} discover
${device}
452 function device_create_virtual
() {
453 log WARN
"Called deprecated function device_create_virtual"
454 device_virtual_create $@
457 function device_virtual_create
() {
458 local port
=$
(devicify
${1})
461 local newport
=${port}v
${vid}
463 if [ -z "${mac}" ]; then
467 log INFO
"Creating virtual device '${newport}' with address '${mac}'."
469 local oldport
=$
(device_virtual_get_by_parent_and_vid
${port} ${vid})
471 if device_exists
${oldport}; then
474 if [ "${oldport}" != "${newport}" ]; then
475 differences
="${differences} name"
477 if [ "$(device_get_address ${oldport})" != "${mac}" ]; then
478 differences
="${differences} address"
481 echo "differences: $differences"
483 if [ -n "${differences}" ]; then
484 if device_is_used
${oldport}; then
485 error_log
"There was a device '${oldport}' set up with VID '${vid}' and parent '${port}' which is used somewhere else. Cannot go on."
488 log DEBUG
"There is a device '${oldport}' but it not used, so we grab it to ourselves."
491 log DEBUG
"Device '${newport}' already exists and reflects our configuration. Go on."
493 device_set_up
${oldport}
498 log DEBUG
"Virtual device '${newport}' does not exist, yet."
500 vconfig set_name_type DEV_PLUS_VID_NO_PAD
>/dev
/null
501 vconfig add
${port} ${vid} >/dev
/null
503 if [ $?
-ne ${EXIT_OK} ]; then
504 error_log
"Could not create virtual device '${newport}'."
508 oldport
=$
(device_virtual_get_by_parent_and_vid
${port} ${vid})
512 assert device_exists
${oldport}
514 if ! device_exists
${oldport}; then
515 error
"Could not determine the created virtual device '${newport}'."
519 # The device is expected to be named like ${port}.${vid}
520 # and will be renamed to the virtual schema
521 device_set_name
${oldport} ${newport}
523 if [ $?
-ne ${EXIT_OK} ]; then
524 error_log
"Could not set name of virtual device '${newport}'."
528 assert device_exists
${newport}
530 # Setting new mac address
531 device_set_address
${newport} ${mac}
533 if [ $?
-ne ${EXIT_OK} ]; then
534 error_log
"Could not set address '${mac}' to virtual device '${newport}'."
538 # Bring up the new device
539 device_set_up
${newport}
544 function device_virtual_remove
() {
545 local device
=$
(devicify
${1})
547 log INFO
"Removing virtual device '${device}' with address '$(macify ${device})'."
549 device_set_down
${device}
551 vconfig rem
${device} >/dev
/null
553 if [ $?
-ne ${EXIT_OK} ]; then
554 error_log
"Could not remote virtual device '${newport}'."
561 function device_virtual_get_parent
() {
564 local parent
=$
(grep "^${device}" < /proc
/net
/vlan
/config |
awk '{ print $NF }')
566 if device_exists
${parent}; then
574 function device_virtual_get_by_parent_and_vid
() {
582 fgrep
'|' < /proc
/net
/vlan
/config |
tr -d '|' | \
583 while read v_port v_id v_parent
; do
584 if [ "${v_parent}" = "${parent}" ] && [ "${v_id}" = "${vid}" ]; then
593 function device_bonding_create
() {
597 [ -z "${mac}" ] && mac
=$
(mac_generate
)
599 log INFO
"Creating bonding device '${device}' (${mac})."
601 echo "+${device}" > /sys
/class
/net
/bonding_masters
602 device_set_address
${mac}
603 device_set_up
${device}
606 function device_bonding_remove
() {
607 local device
=$
(devicify
${1})
609 log INFO
"Remove bonding device '${device}'."
611 device_set_down
${device}
612 echo "-${device}" > /sys
/class
/net
/bonding_masters
615 function bonding_set_mode
() {
619 log INFO
"Setting bonding mode on '${device}' '${mode}'."
621 echo "${mode}" > /sys
/class
/net
/${device}/bonding
/mode
624 function bonding_enslave_device
() {
625 local device
=$
(devicify
${1})
626 local slave
=$
(devicify
${2})
629 log INFO
"Enslaving slave '${slave}' to '${device}'."
631 device_set_down
${slave}
632 echo "+${slave}" > /sys
/class
/net
/${device}/bonding
/slaves
635 function bridge_attach_device
() {
639 if ! device_exists
${bridge}; then
640 error
"Bridge '${bridge}' does not exist."
644 if ! device_exists
${device}; then
645 error
"Device '${device}' does not exist."
649 log INFO
"Attaching device '${device}' to bridge '${bridge}'."
651 # XXX device_set_up ${device} # Do we need this here?
653 brctl addif
${bridge} ${device}
656 function bridge_detach_device
() {
660 if ! device_exists
${bridge}; then
661 error
"Bridge '${bridge}' does not exist."
665 if ! device_exists
${device}; then
666 error
"Device '${device}' does not exist."
670 log INFO
"Detaching device '${device}' from bridge '${bridge}'."
672 brctl delif
${bridge} ${device}
674 device_set_down
${device}
677 function bridge_is_forwarding
() {
681 bridge_has_carrier
${zone} ||
return ${EXIT_ERROR}
684 while [ ${seconds} -gt 0 ]; do
685 for device
in ${SYS_CLASS_NET}/${zone}/brif
/*; do
686 [ -e "${device}/state" ] ||
continue
687 if [ "$(<${device}/state)" = "3" ]; then
692 seconds
=$
((${seconds} - 1))
698 function bridge_has_carrier
() {
701 local has_carrier
=${EXIT_ERROR}
704 for device
in ${SYS_CLASS_NET}/${zone}/brif
/*; do
705 device
=$
(basename ${device})
706 device_exists
${device} ||
continue
708 device_has_carrier
${device} && has_carrier
=${EXIT_OK}
711 return ${has_carrier}
714 function device_has_ipv4
() {
718 if ! device_exists
${device}; then
719 error
"Device '${device}' does not exist."
723 ip addr show
${device} |
grep -q -e "inet " -e "${addr}"