2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
25 if device_exists
${device}; then
31 for d
in $
(devices_get_all
); do
32 if [ "$(device_get_address ${d})" = "${device}" ]; then
44 if mac_is_valid
${device}; then
49 if device_exists
${device}; then
50 device_get_address
${device}
57 # Check if the device exists
58 function device_exists
() {
61 # If device name was not found, exit.
62 [ -n "${device}" ] ||
return ${EXIT_ERROR}
64 [ -d "${SYS_CLASS_NET}/${device}" ]
67 # Check if the device is up
68 function device_is_up
() {
71 device_exists
${device} ||
return ${EXIT_ERROR}
73 ip link show
${device} 2>/dev
/null |
grep -qE "<.*UP.*>"
76 # Check if the device is a bonding device
77 function device_is_bonding
() {
78 [ -d "/sys/class/net/${1}/bonding" ]
81 # Check if the device bonded in a bonding device
82 function device_is_bonded
() {
84 for dev
in /sys
/class
/net
/*; do
86 [ -d "${dev}" ] ||
continue
88 # Continue if not a bonding device
89 device_is_bonding
"${dev##*/}" ||
continue
91 if grep -q "\<${1}\>" ${dev}/bonding
/slaves
; then
99 # Check if the device is a bridge
100 function device_is_bridge
() {
101 [ -d "/sys/class/net/${1}/bridge" ]
104 # Check if the device is a virtual device
105 function device_is_virtual
() {
108 [ -e "/proc/net/vlan/${device}" ]
111 # Check if the device has virtual devices
112 function device_has_virtuals
() {
115 if device_is_virtual
${device}; then
119 if [ ! -e "/proc/net/vlan/config" ]; then
122 grep -q "${1}$" /proc
/net
/vlan
/config
125 function device_is_vlan
() { # XXX Compat function
126 log DEBUG
"Deprecated function device_is_vlan() was used."
131 # Check if the device is a ppp device
132 function device_is_ppp
() {
135 ip link show
${device} 2>/dev
/null |
grep -qE "<.*POINTOPOINT.*>"
138 # Check if the device is a loopback device
139 function device_is_loopback
() {
140 local device
=$
(devicify
${1})
141 [ "${device}" = "lo" ]
144 # Check if the device is a physical network interface
145 function device_is_real
() {
148 device_is_loopback
${device} && \
151 device_is_bonding
${device} && \
154 device_is_bridge
${device} && \
157 device_is_ppp
${device} && \
160 device_is_virtual
${device} && \
166 # Get the device type
167 function device_get_type
() {
168 local device
=$
(devicify
${1})
170 if device_is_vlan
${device}; then
173 elif device_is_bonding
${device}; then
176 elif device_is_bridge
${device}; then
179 elif device_is_ppp
${device}; then
182 elif device_is_loopback
${device}; then
185 elif device_is_real
${device}; then
193 function device_get_address
() {
196 cat ${SYS_CLASS_NET}/${device}/address
2>/dev
/null
199 function device_set_address
() {
203 if ! device_exists
${device}; then
204 error
"Device '${device}' does not exist."
208 log INFO
"Setting address of '${device}' to '${addr}' - was $(device_get_address ${device})."
211 if device_is_up
${device}; then
212 device_set_down
${device}
216 ip link
set ${device} address
${addr}
219 if [ "${up}" = "1" ]; then
220 device_set_up
${device}
223 if [ "${ret}" != "0" ]; then
224 error_log
"Could not set address '${addr}' on device '${device}'."
230 function devices_get_all
() {
232 for device
in ${SYS_CLASS_NET}/*; do
233 echo "$(basename ${device})"
237 # Check if a device has a cable plugged in
238 function device_has_carrier
() {
239 local device
=$
(devicify
${1})
240 [ "$(<${SYS_CLASS_NET}/${device}/carrier)" = "1" ]
243 # Check if the device is free
244 function device_is_free
() {
247 device_is_used
${device} && \
253 # Check if the device is used
254 function device_is_used
() {
255 local device
=$
(devicify
${1})
257 device_has_virtuals
${device} && \
259 device_is_bonded
${device} && \
265 # XXX to be removed I think
266 function device_get_free
() {
267 local destination
=${1}
269 # Replace + by a valid number
270 if grep -q "+$" <<<${destination}; then
272 destination
=$
(sed -e "s/+//" <<<$destination)
273 while [ "${number}" -le "100" ]; do
274 if ! device_exists
"${destination}${number}"; then
275 destination
="${destination}${number}"
278 number
=$
(($number + 1))
281 echo "${destination}"
284 function device_rename
() {
285 warning_log
"Called deprecated function 'device_rename'"
290 function device_hash
() {
293 macify
${device} |
tr -d ':'
296 # Give the device a new name
297 function device_set_name
() {
299 local destination
=$
(device_get_free
${2})
301 # Check if devices exists
302 if ! device_exists
${source} || device_exists
${destination}; then
307 if device_is_up
${source}; then
308 ip link
set ${source} down
312 ip link
set ${source} name
${destination}
314 if [ "${up}" = "1" ]; then
315 ip link
set ${destination} up
320 function device_set_up
() {
321 local device
=$
(devicify
${1})
323 # Do nothing if device is already up
324 device_is_up
${device} && return ${EXIT_OK}
326 log DEBUG
"Setting up device $@"
327 ip link
set ${device} up
331 function device_set_down
() {
332 local device
=$
(devicify
${1})
334 # Do nothing if device is not up
335 device_is_up
${device} ||
return ${EXIT_OK}
337 log DEBUG
"Tearing down device $@"
338 ip link
set ${device} down
341 # Set new address to a device
342 function device_set_mac
() {
343 warning_log
"Called deprecated function 'device_set_mac'"
345 device_set_address $@
348 function device_get_mtu
() {
351 if ! device_exists
${device}; then
352 error
"Device '${device}' does not exist."
356 cat ${SYS_CLASS_NET}/${device}/mtu
359 # Set mtu to a device
360 function device_set_mtu
() {
364 if ! device_exists
${device}; then
365 error
"Device '${device}' does not exist."
369 local oldmtu
=$
(device_get_mtu
${device})
371 if [ "${oldmtu}" = "${mtu}" ]; then
372 # No need to set mtu.
376 log INFO
"Setting mtu of '${device}' to '${mtu}' - was ${oldmtu}."
379 if device_is_up
${device}; then
380 device_set_down
${device}
384 ip link
set ${device} mtu
${mtu}
387 if [ "${up}" = "1" ]; then
388 device_set_up
${device}
391 if [ "${ret}" != "0" ]; then
392 error_log
"Could not set mtu '${mtu}' on device '${device}'."
398 function device_discover
() {
401 log INFO
"Running discovery process on device '${device}'."
404 for hook
in $
(hooks_get_all
); do
405 hook_exec
${hook} discover
${device}
409 function device_create_virtual
() {
410 log WARN
"Called deprecated function device_create_virtual"
411 device_virtual_create $@
414 function device_virtual_create
() {
415 local port
=$
(devicify
${1})
418 local newport
=${port}v
${vid}
420 if [ -z "${mac}" ]; then
424 log INFO
"Creating virtual device '${newport}' with address '${mac}'."
426 local oldport
=$
(device_virtual_get_by_parent_and_vid
${port} ${vid})
428 if device_exists
${oldport}; then
431 if [ "${oldport}" != "${newport}" ]; then
432 differences
="${differences} name"
434 if [ "$(device_get_address ${oldport})" != "${mac}" ]; then
435 differences
="${differences} address"
438 echo "differences: $differences"
440 if [ -n "${differences}" ]; then
441 if device_is_used
${oldport}; then
442 error_log
"There was a device '${oldport}' set up with VID '${vid}' and parent '${port}' which is used somewhere else. Cannot go on."
445 log DEBUG
"There is a device '${oldport}' but it not used, so we grab it to ourselves."
448 log DEBUG
"Device '${newport}' already exists and reflects our configuration. Go on."
450 device_set_up
${oldport}
455 log DEBUG
"Virtual device '${newport}' does not exist, yet."
457 vconfig set_name_type DEV_PLUS_VID_NO_PAD
>/dev
/null
458 vconfig add
${port} ${vid} >/dev
/null
460 if [ $?
-ne ${EXIT_OK} ]; then
461 error_log
"Could not create virtual device '${newport}'."
465 oldport
=$
(device_virtual_get_by_parent_and_vid
${port} ${vid})
469 assert device_exists
${oldport}
471 if ! device_exists
${oldport}; then
472 error
"Could not determine the created virtual device '${newport}'."
476 # The device is expected to be named like ${port}.${vid}
477 # and will be renamed to the virtual schema
478 device_set_name
${oldport} ${newport}
480 if [ $?
-ne ${EXIT_OK} ]; then
481 error_log
"Could not set name of virtual device '${newport}'."
485 assert device_exists
${newport}
487 # Setting new mac address
488 device_set_address
${newport} ${mac}
490 if [ $?
-ne ${EXIT_OK} ]; then
491 error_log
"Could not set address '${mac}' to virtual device '${newport}'."
495 # Bring up the new device
496 device_set_up
${newport}
501 function device_virtual_remove
() {
502 local device
=$
(devicify
${1})
504 log INFO
"Removing virtual device '${device}' with address '$(macify ${devive})'."
506 device_set_down
${device}
508 vconfig rem
${device} >/dev
/null
510 if [ $?
-ne ${EXIT_OK} ]; then
511 error_log
"Could not remote virtual device '${newport}'."
518 function device_virtual_get_by_parent_and_vid
() {
526 fgrep
'|' < /proc
/net
/vlan
/config |
tr -d '|' | \
527 while read v_port v_id v_parent
; do
528 if [ "${v_parent}" = "${parent}" ] && [ "${v_id}" = "${vid}" ]; then
537 function device_bonding_create
() {
541 [ -z "${mac}" ] && mac
=$
(mac_generate
)
543 log INFO
"Creating bonding device '${device}' (${mac})."
545 echo "+${device}" > /sys
/class
/net
/bonding_masters
546 device_set_mac
${mac}
547 device_set_up
${device}
550 function device_bonding_remove
() {
551 local device
=$
(devicify
${1})
553 log INFO
"Remove bonding device '${device}'."
555 device_set_down
${device}
556 echo "-${device}" > /sys
/class
/net
/bonding_masters
559 function bonding_set_mode
() {
563 log INFO
"Setting bonding mode on '${device}' '${mode}'."
565 echo "${mode}" > /sys
/class
/net
/${device}/bonding
/mode
568 function bonding_enslave_device
() {
569 local device
=$
(devicify
${1})
570 local slave
=$
(devicify
${2})
573 log INFO
"Enslaving slave '${slave}' to '${device}'."
575 device_set_down
${slave}
576 echo "+${slave}" > /sys
/class
/net
/${device}/bonding
/slaves
579 function bridge_attach_device
() {
583 if ! device_exists
${bridge}; then
584 error
"Bridge '${bridge}' does not exist."
588 if ! device_exists
${device}; then
589 error
"Device '${device}' does not exist."
593 log INFO
"Attaching device '${device}' to bridge '${bridge}'."
595 # XXX device_set_up ${device} # Do we need this here?
597 brctl addif
${bridge} ${device}
600 function bridge_detach_device
() {
604 if ! device_exists
${bridge}; then
605 error
"Bridge '${bridge}' does not exist."
609 if ! device_exists
${device}; then
610 error
"Device '${device}' does not exist."
614 log INFO
"Detaching device '${device}' from bridge '${bridge}'."
616 brctl delif
${bridge} ${device}
618 device_set_down
${device}
621 function bridge_is_forwarding
() {
625 bridge_has_carrier
${zone} ||
return ${EXIT_ERROR}
628 while [ ${seconds} -gt 0 ]; do
629 for device
in ${SYS_CLASS_NET}/${zone}/brif
/*; do
630 [ -e "${device}/state" ] ||
continue
631 if [ "$(<${device}/state)" = "3" ]; then
636 seconds
=$
((${seconds} - 1))
642 function bridge_has_carrier
() {
645 local has_carrier
=${EXIT_ERROR}
648 for device
in ${SYS_CLASS_NET}/${zone}/brif
/*; do
649 device
=$
(basename ${device})
650 device_exists
${device} ||
continue
652 device_has_carrier
${device} && has_carrier
=${EXIT_OK}
655 return ${has_carrier}
658 function device_has_ipv4
() {
662 if ! device_exists
${device}; then
663 error
"Device '${device}' does not exist."
667 ip addr show
${device} |
grep -q -e "inet " -e "${addr}"