2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 declare -A DEVICE_LINK_SPEEDS
=(
29 [10000BaseT-Full
]=0x1000
35 for device
in $
(list_directory
${SYS_CLASS_NET}); do
36 if device_exists
"${device}"; then
44 # List all serial devices
48 # Check if the device exists
52 # If device name was not found, exit.
53 [ -n "${device}" ] ||
return ${EXIT_ERROR}
55 # Check for a normal network device.
56 [ -d "${SYS_CLASS_NET}/${device}" ] && return ${EXIT_OK}
58 # If the check above did not find a result,
60 phy_exists "${device}" && return ${EXIT_OK}
62 # If the check above did not find a result,
63 # we check for serial devices.
64 serial_exists ${device}
67 device_matches_pattern() {
74 pattern="^
${pattern//N/[[:digit:]]+}$
"
76 [[ ${device} =~ ${pattern} ]] \
77 && return ${EXIT_TRUE} || return ${EXIT_FALSE}
84 # Nothing to do, it device does not exist.
85 device_exists ${device} || return ${EXIT_OK}
87 # Shut down device before we delete it
88 device_set_down "${device}"
91 cmd_quiet ip link delete ${device}
94 if [ ${ret} -ne ${EXIT_OK} ]; then
95 log ERROR "device
: Could not delete device
'${device}': ${ret}"
106 local flags=$(__device_get_file ${device} flags)
108 if [[ "$
(( ${flags} & ${flag} ))" -eq 0 ]]; then
115 # Check if the device is up
119 device_exists ${device} || return ${EXIT_ERROR}
121 device_has_flag ${device} 0x1
124 device_ifindex_to_name() {
128 local device device_idx
129 for device in $(list_directory "${SYS_CLASS_NET}"); do
130 device_idx=$(device_get_ifindex ${device})
132 if [ "${device_idx}" = "${idx}" ]; then
141 device_get_ifindex() {
145 local path="${SYS_CLASS_NET}/${1}/ifindex
"
147 # Check if file can be read.
148 [ -r "${path}" ] || return ${EXIT_ERROR}
153 device_get_driver() {
157 get_driver_from_path "${SYS_CLASS_NET}/${device}/device
/driver
/module
"
160 # Check if the device is a bonding device
161 device_is_bonding() {
162 [ -d "/sys
/class
/net
/${1}/bonding
" ]
165 # Check if the device bonded in a bonding device
169 [ -d "${SYS_CLASS_NET}/${device}/bonding_slave
" ]
172 # Check if the device is a bridge
174 [ -d "/sys
/class
/net
/${1}/bridge
" ]
177 device_is_bridge_attached() {
179 [ -d "${SYS_CLASS_NET}/${device}/brport
" ]
182 device_is_wireless_monitor() {
186 device_is_wireless "${device}" && \
187 device_matches_pattern "${device}" "${PORT_PATTERN_WIRELESS_MONITOR}"
190 device_is_wireless_adhoc() {
194 device_is_wireless "${device}" && \
195 device_matches_pattern "${device}" "${PORT_PATTERN_WIRELESS_ADHOC}"
198 device_get_bridge() {
202 # Check if device is attached to a bridge.
203 device_is_bridge_attached ${device} || return ${EXIT_ERROR}
205 local ifindex_path="${SYS_CLASS_NET}/${device}/brport
/bridge
/ifindex
"
206 [ -r "${ifindex_path}" ] || return ${EXIT_ERROR}
208 local ifindex=$(<${ifindex_path})
211 device_ifindex_to_name ${ifindex}
214 # Check if the device is a vlan device
219 [ -e "${PROC_NET_VLAN}/${device}" ]
222 # Check if the device has vlan devices
227 if device_is_vlan ${device}; then
231 local vlans=$(device_get_vlans ${device})
232 [ -n "${vlans}" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
239 # If no 8021q module has been loaded into the kernel,
240 # we cannot do anything.
241 [ -r "${PROC_NET_VLAN_CONFIG}" ] ||
return ${EXIT_OK}
243 local dev spacer1 id spacer2 parent
244 while read dev spacer1 id spacer2 parent
; do
245 [ "${parent}" = "${device}" ] ||
continue
248 done < ${PROC_NET_VLAN_CONFIG}
251 # Check if the device is a ppp device
255 local type=$
(__device_get_file
${device} type)
257 [ "${type}" = "512" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
260 # Check if the device is a pointopoint device.
264 device_has_flag ${device} 0x10
267 # Check if the device is a loopback device
268 device_is_loopback() {
271 [ "${device}" = "lo
" ]
274 # Check if the device is a dummy device
275 # This is the worst possible check, but all I could come up with
279 [[ ${device} =~ ^dummy[0-9]+$ ]]
285 [[ ${device} =~ ^ipsec\- ]]
288 # Check if the device is a wireless device
289 device_is_wireless() {
292 [ -d "${SYS_CLASS_NET}/${device}/phy80211
" ]
298 local type=$(__device_get_file ${device} type)
300 [ "${type}" = "768" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
306 local type=$
(__device_get_file
${device} type)
308 [ "${type}" = "769" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
314 if device_is_wireless "${device}"; then
315 print "$
(<${SYS_CLASS_NET}/${device}/phy80211
/name
)"
330 # Returns true if a device is a tun device
334 [ -e "${SYS_CLASS_NET}/${device}/tun_flags
" ]
337 # Check if the device is a physical network interface
338 device_is_ethernet() {
341 device_is_ethernet_compatible "${device}" || \
344 device_is_loopback ${device} && \
347 device_is_bonding ${device} && \
350 device_is_bridge ${device} && \
353 device_is_ppp ${device} && \
356 device_is_vlan ${device} && \
359 device_is_dummy ${device} && \
362 device_is_tun ${device} && \
368 # Get the device type
372 # If the device does not exist (happens on udev remove events),
373 # we do not bother to run all checks.
374 if ! device_exists "${device}"; then
377 elif device_is_vlan ${device}; then
380 elif device_is_bonding ${device}; then
383 elif device_is_bridge ${device}; then
386 elif device_is_ppp ${device}; then
389 elif device_is_loopback ${device}; then
392 elif device_is_wireless_adhoc ${device}; then
393 echo "wireless-adhoc
"
395 elif device_is_wireless ${device}; then
398 elif device_is_dummy ${device}; then
401 elif device_is_tun ${device}; then
404 elif device_is_ethernet ${device}; then
407 elif device_is_serial ${device}; then
410 elif device_is_phy ${device}; then
414 echo "$
(device_tunnel_get_type
"${device}")"
418 # This function just checks the types a ip-tunnel device usually have
419 # so when we know that the device is an ip-tunnel device we save time
420 device_tunnel_get_type() {
423 # If the device does not exist (happens on udev remove events),
424 # we do not bother to run all checks.
425 if ! device_exists "${device}"; then
428 elif device_is_vti ${device}; then
431 elif device_is_vti6 ${device}; then
439 device_is_ethernet_compatible() {
442 # /sys/class/net/*/type must equal 1 for ethernet compatible devices
443 local type="$
(__device_get_file
"${device}" "type")"
444 [[ "${type}" = "1" ]]
447 device_get_status() {
451 local status=${STATUS_DOWN}
453 if device_is_up ${device}; then
456 if ! device_has_carrier ${device}; then
457 status=${STATUS_NOCARRIER}
464 device_get_address() {
467 cat ${SYS_CLASS_NET}/${device}/address 2>/dev/null
470 device_set_address() {
476 if ! device_exists "${device}"; then
477 error "Device
'${device}' does not exist.
"
481 # Do nothing if the address has not changed
482 local old_addr="$
(device_get_address
"${device}")"
483 if [ -n "${old_addr}" -a "${addr}" = "${old_addr}" ]; then
487 log DEBUG "Setting address of
'${device}' from '${old_addr}' to '${addr}'"
490 if device_is_up "${device}"; then
491 device_set_down "${device}"
495 ip link set "${device}" address "${addr}"
498 if [ "${up}" = "1" ]; then
499 device_set_up "${device}"
502 if [ "${ret}" != "0" ]; then
503 error_log "Could not
set address
'${addr}' on device
'${device}'"
511 for device in $(list_directory "${SYS_CLASS_NET}"); do
512 # bonding_masters is no device
513 [ "${device}" = "bonding_masters
" ] && continue
521 # Check if a device has a cable plugged in
522 device_has_carrier() {
526 local carrier=$(__device_get_file ${device} carrier)
527 [ "${carrier}" = "1" ]
530 device_is_promisc() {
533 device_has_flag ${device} 0x200
536 device_set_promisc() {
540 assert device_exists ${device}
542 assert isoneof state on off
544 ip link set ${device} promisc ${state}
547 # Check if the device is free
549 ! device_is_used "$@
"
552 # Check if the device is used
556 device_has_vlans ${device} && \
558 device_is_bonded ${device} && \
560 device_is_bridge_attached ${device} && \
566 # Give the device a new name
569 local destination=${2}
571 # Check if devices exists
572 if ! device_exists ${source} || device_exists ${destination}; then
577 if device_is_up ${source}; then
578 ip link set ${source} down
582 ip link set ${source} name ${destination}
584 if [ "${up}" = "1" ]; then
585 ip link set ${destination} up
589 device_set_master() {
596 if ! cmd ip link set "${device}" master "${master}"; then
597 log ERROR "Could not
set master
${master} for device
${device}"
604 device_remove_master() {
608 if ! cmd ip link set "${device}" nomaster; then
609 log ERROR "Could not remove master
for device
${device}"
622 # Do nothing if device is already up
623 device_is_up ${device} && return ${EXIT_OK}
625 log INFO "Bringing up
${device}"
627 device_set_parent_up ${device}
628 if ! cmd ip link set ${device} up; then
633 if interrupt_use_smp_affinity; then
634 device_auto_configure_smp_affinity ${device}
640 device_set_parent_up() {
644 if device_is_vlan ${device}; then
645 parent=$(vlan_get_parent ${device})
647 device_is_up ${parent} && return ${EXIT_OK}
649 log DEBUG "Setting up parent device
'${parent}' of
'${device}'"
651 device_set_up ${parent}
665 if device_is_up ${device}; then
666 log INFO "Bringing down
${device}"
668 cmd ip link set ${device} down
672 device_set_parent_down ${device}
677 device_set_parent_down() {
681 if device_is_vlan ${device}; then
682 parent=$(vlan_get_parent ${device})
684 device_is_up ${parent} || return ${EXIT_OK}
686 if device_is_free ${parent}; then
687 log DEBUG "Tearing down parent device
'${parent}' of
'${device}'"
689 device_set_down ${parent}
699 # Return an error if the device does not exist
700 device_exists ${device} || return ${EXIT_ERROR}
702 echo $(<${SYS_CLASS_NET}/${device}/mtu)
705 # Set mtu to a device
710 assert device_exists ${device}
712 # Handle bridges differently
713 if device_is_bridge ${device}; then
715 for port in $(bridge_get_members ${device}); do
716 device_set_mtu ${port} ${mtu}
720 log INFO "Setting MTU of
${device} to
${mtu}"
723 if device_is_up ${device}; then
724 device_set_down ${device}
729 if ! cmd ip link set ${device} mtu ${mtu}; then
732 log ERROR "Could not
set MTU
${mtu} on
${device}"
735 if [ "${up}" = "1" ]; then
736 device_set_up ${device}
742 device_adjust_mtu() {
746 local other_device="${2}"
748 local mtu="$
(device_get_mtu
"${other_device}")"
749 device_set_mtu "${device}" "${mtu}"
755 log INFO "Running discovery process on device
'${device}'.
"
758 for hook in $(hook_zone_get_all); do
759 hook_zone_exec ${hook} discover ${device}
768 # Flash for ten seconds by default
772 local background="false
"
781 seconds="$
(cli_get_val
"${arg}")"
784 done <<< "$
(args
"$@")"
786 assert isinteger seconds
788 if ! device_exists "${device}"; then
789 log ERROR "Cannot identify device
${device}: Does not exist
"
793 if ! device_is_ethernet "${device}"; then
794 log DEBUG "Cannot identify device
${device}: Not an ethernet device
"
795 return ${EXIT_NOT_SUPPORTED}
798 log DEBUG "Identifying device
${device}"
800 local command="ethtool
--identify ${device} ${seconds}"
803 if enabled background; then
804 cmd_background "${command}"
806 cmd_quiet "${command}"
818 assert device_exists ${device}
820 # IPv6 addresses must be fully imploded
821 local protocol=$(ip_detect_protocol ${addr})
822 case "${protocol}" in
824 addr=$(ipv6_format "${addr}")
828 list_match ${addr} $(device_get_addresses ${device})
831 device_get_addresses() {
834 assert device_exists ${device}
839 ip addr show ${device} | \
840 while read prot addr line; do
841 [ "${prot:0:4}" = "inet
" ] && echo "${addr}"
845 __device_get_file() {
849 fread "${SYS_CLASS_NET}/${device}/${file}"
852 __device_set_file() {
859 fappend "${SYS_CLASS_NET}/${device}/${file}" "${value}"
862 device_get_rx_bytes() {
865 __device_get_file ${device} statistics/rx_bytes
868 device_get_tx_bytes() {
871 __device_get_file ${device} statistics/tx_bytes
874 device_get_rx_packets() {
877 __device_get_file ${device} statistics/rx_packets
880 device_get_tx_packets() {
883 __device_get_file ${device} statistics/tx_packets
886 device_get_rx_errors() {
889 __device_get_file ${device} statistics/rx_errors
892 device_get_tx_errors() {
895 __device_get_file ${device} statistics/tx_errors
898 device_advertise_link_speeds() {
904 # Advertised modes in hex
909 local m="${DEVICE_LINK_SPEEDS[${mode}]}"
911 advertise="$
(( advertise | m
))"
915 # If nothing was selected, we reset and enable everything
916 if [ ${advertise} -eq 0 ]; then
920 # Enable auto-negotiation
921 cmd_quiet ethtool --change "${device}" autoneg on
923 # Set advertised link speeds
924 if ! cmd_quiet ethtool --change "${device}" advertise "0x$
(hex
"${advertise}")"; then
925 log ERROR "Could not
set link modes of
${device}: $@
"
929 log DEBUG "Set device link modes of
${device} to $@
"
936 local speed=$(__device_get_file ${device} speed)
938 # Exit for no output (i.e. no link detected)
939 isset speed || return ${EXIT_ERROR}
941 # Don't return anything for negative values
942 [ ${speed} -lt 0 ] && return ${EXIT_ERROR}
947 device_get_duplex() {
950 local duplex=$(__device_get_file ${device} duplex)
962 device_get_link_string() {
968 local speed="$
(device_get_speed
"${device}")"
970 list_append s "${speed} MBit
/s
"
973 local duplex="$
(device_get_duplex
"${device}")"
974 if isset duplex; then
975 list_append s "${duplex} duplex
"
981 device_auto_configure_smp_affinity() {
986 if lock_acquire "smp-affinity
" 60; then
987 device_set_smp_affinity ${device} auto
989 lock_release "smp-affinity
"
993 device_set_smp_affinity() {
999 # mode can be auto which will automatically try to find
1000 # the least busy processor, or an integer for the desired
1001 # processor that should handle this device
1003 local num_processors=$(system_get_processors)
1005 if [ "${mode}" = "auto
" ]; then
1006 local processor=$(interrupt_choose_least_busy_processor)
1008 assert isinteger mode
1009 local processor=${mode}
1011 if [ ${processor} -gt ${num_processors} ]; then
1012 log ERROR "Processor
${processor} does not exist
"
1013 return ${EXIT_ERROR}
1017 local interrupts=$(interrupts_for_device ${device})
1018 if ! isset interrupts; then
1019 log DEBUG "${device} has no interrupts. Not changing SMP affinity
"
1025 for interrupt in ${interrupts}; do
1026 interrupt_set_smp_affinity ${interrupt} ${processor}
1029 # Find all queues and assign them to the next processor
1031 for queue in $(device_get_queues ${device}); do
1033 # Only handle receive queues
1035 for interrupt in $(interrupts_for_device_queue ${device} ${queue}); do
1036 interrupt_set_smp_affinity ${interrupt} ${processor}
1039 device_queue_set_smp_affinity ${device} ${queue} ${processor}
1048 # Get the next available processor if in auto mode
1049 [ "${mode}" = "auto
" ] && processor=$(system_get_next_processor ${processor})
1055 device_get_queues() {
1060 list_directory "${SYS_CLASS_NET}/${device}/queues
"
1063 device_supports_multiqueue() {
1066 local num_queues=$(device_num_queues ${device})
1068 if isset num_queues && [ ${num_queues} -gt 2 ]; then
1072 return ${EXIT_FALSE}
1075 device_num_queues() {
1079 isset type && assert isoneof type rx tx
1084 for q in $(device_get_queues ${device}); do
1085 case "${type},${q}" in
1101 device_queue_get_smp_affinity() {
1107 local path="${SYS_CLASS_NET}/${device}/queues/${queue}"
1111 path="${path}/rps_cpus
"
1114 path="${path}/xps_cpus
"
1117 assert [ -r "${path}" ]
1119 __bitmap_to_processor_ids $(<${path})
1122 device_queue_set_smp_affinity() {
1127 local processor=${3}
1129 local path="${SYS_CLASS_NET}/${device}/queues/${queue}/rps_cpus
"
1130 assert [ -w "${path}" ]
1132 log DEBUG "Setting SMP affinity of
${device} (${queue}) to processor ${processor}"
1134 __processor_id_to_bitmap ${processor} > ${path}
1137 # Tries to find a device which has the given IP address assigned
1138 device_get_by_assigned_ip_address() {
1145 # Read the first line of ip addr show to
1146 read -r device <<< $(ip addr show to "${ip}")
1148 # If we did not found a device we return with ${EXIT_ERROR}
1149 if ! isset device; then
1150 return ${EXIT_ERROR}
1153 # We get something like:
1154 # 3: upl0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
1155 # and we want upl0 so we take the second word and removing the :
1164 device_get_by_mac_address() {
1171 for device in $(device_list); do
1172 if [ "${mac}" = "$
(device_get_address
${device})" ]; then
1178 # We could not found a port to the given mac address so we return exit error
1179 return ${EXIT_ERROR}