2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
27 for device
in $
(list_directory
${SYS_CLASS_NET}); do
28 list_append_one devices
"${device}"
32 list_append devices $
(phy_list
)
34 # Add all serial devices
35 list_append devices $
(serial_list
)
37 # Return a sorted result
41 # Check if the device exists
45 # If device name was not found, exit.
46 [ -n "${device}" ] ||
return ${EXIT_ERROR}
48 # Check for a normal network device.
49 [ -d "${SYS_CLASS_NET}/${device}" ] && return ${EXIT_OK}
51 # If the check above did not find a result,
53 phy_exists "${device}" && return ${EXIT_OK}
55 # If the check above did not find a result,
56 # we check for serial devices.
57 serial_exists ${device}
60 device_matches_pattern() {
67 pattern="^
${pattern//N/[[:digit:]]+}$
"
69 [[ ${device} =~ ${pattern} ]] \
70 && return ${EXIT_TRUE} || return ${EXIT_FALSE}
77 # Nothing to do, it device does not exist.
78 device_exists ${device} || return ${EXIT_OK}
80 # Shut down device before we delete it
81 device_set_down "${device}"
84 cmd_quiet ip link delete ${device}
87 if [ ${ret} -ne ${EXIT_OK} ]; then
88 log ERROR "device
: Could not delete device
'${device}': ${ret}"
99 local flags=$(__device_get_file ${device} flags)
101 if [[ "$
(( ${flags} & ${flag} ))" -eq 0 ]]; then
108 # Check if the device is up
112 device_exists ${device} || return ${EXIT_ERROR}
114 device_has_flag ${device} 0x1
117 device_ifindex_to_name() {
121 local device device_idx
122 for device in $(list_directory "${SYS_CLASS_NET}"); do
123 device_idx=$(device_get_ifindex ${device})
125 if [ "${device_idx}" = "${idx}" ]; then
134 device_get_ifindex() {
138 local path="${SYS_CLASS_NET}/${1}/ifindex
"
140 # Check if file can be read.
141 [ -r "${path}" ] || return ${EXIT_ERROR}
146 # Check if the device is a bonding device
147 device_is_bonding() {
148 [ -d "/sys
/class
/net
/${1}/bonding
" ]
151 # Check if the device bonded in a bonding device
155 [ -d "${SYS_CLASS_NET}/${device}/bonding_slave
" ]
158 # Check if the device is a bridge
160 [ -d "/sys
/class
/net
/${1}/bridge
" ]
163 device_is_bridge_attached() {
165 [ -d "${SYS_CLASS_NET}/${device}/brport
" ]
168 device_is_wireless_monitor() {
172 device_is_wireless "${device}" && \
173 device_matches_pattern "${device}" "${PORT_PATTERN_WIRELESS_MONITOR}"
176 device_is_wireless_adhoc() {
180 device_is_wireless "${device}" && \
181 device_matches_pattern "${device}" "${PORT_PATTERN_WIRELESS_ADHOC}"
184 device_get_bridge() {
188 # Check if device is attached to a bridge.
189 device_is_bridge_attached ${device} || return ${EXIT_ERROR}
191 local ifindex_path="${SYS_CLASS_NET}/${device}/brport
/bridge
/ifindex
"
192 [ -r "${ifindex_path}" ] || return ${EXIT_ERROR}
194 local ifindex=$(<${ifindex_path})
197 device_ifindex_to_name ${ifindex}
200 # Check if the device is a vlan device
205 [ -e "${PROC_NET_VLAN}/${device}" ]
208 # Check if the device has vlan devices
213 if device_is_vlan ${device}; then
217 local vlans=$(device_get_vlans ${device})
218 [ -n "${vlans}" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
225 # If no 8021q module has been loaded into the kernel,
226 # we cannot do anything.
227 [ -r "${PROC_NET_VLAN_CONFIG}" ] ||
return ${EXIT_OK}
229 local dev spacer1 id spacer2 parent
230 while read dev spacer1 id spacer2 parent
; do
231 [ "${parent}" = "${device}" ] ||
continue
234 done < ${PROC_NET_VLAN_CONFIG}
237 # Check if the device is a ppp device
241 local type=$
(__device_get_file
${device} type)
243 [ "${type}" = "512" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
246 # Check if the device is a pointopoint device.
250 device_has_flag ${device} 0x10
253 # Check if the device is a loopback device
254 device_is_loopback() {
257 [ "${device}" = "lo
" ]
260 # Check if the device is a dummy device
261 # This is the worst possible check, but all I could come up with
265 [[ ${device} =~ ^dummy[0-9]+$ ]]
271 [[ ${device} =~ ^ipsec\- ]]
274 # Check if the device is a wireless device
275 device_is_wireless() {
278 [ -d "${SYS_CLASS_NET}/${device}/phy80211
" ]
284 local type=$(__device_get_file ${device} type)
286 [ "${type}" = "768" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
292 local type=$
(__device_get_file
${device} type)
294 [ "${type}" = "769" ] && return ${EXIT_OK} || return ${EXIT_ERROR}
300 if device_is_wireless "${device}"; then
301 print "$
(<${SYS_CLASS_NET}/${device}/phy80211
/name
)"
316 # Returns true if a device is a tun device
320 [ -e "${SYS_CLASS_NET}/${device}/tun_flags
" ]
323 # Check if the device is a physical network interface
324 device_is_ethernet() {
327 device_is_ethernet_compatible "${device}" || \
330 device_is_loopback ${device} && \
333 device_is_bonding ${device} && \
336 device_is_bridge ${device} && \
339 device_is_ppp ${device} && \
342 device_is_vlan ${device} && \
345 device_is_dummy ${device} && \
348 device_is_tun ${device} && \
354 # Get the device type
358 # If the device does not exist (happens on udev remove events),
359 # we do not bother to run all checks.
360 if ! device_exists "${device}"; then
363 elif device_is_vlan ${device}; then
366 elif device_is_bonding ${device}; then
369 elif device_is_bridge ${device}; then
372 elif device_is_ppp ${device}; then
375 elif device_is_loopback ${device}; then
378 elif device_is_wireless_adhoc ${device}; then
379 echo "wireless-adhoc
"
381 elif device_is_wireless ${device}; then
384 elif device_is_dummy ${device}; then
387 elif device_is_tun ${device}; then
390 elif device_is_ethernet ${device}; then
393 elif device_is_serial ${device}; then
396 elif device_is_phy ${device}; then
400 echo "$
(device_tunnel_get_type
"${device}")"
404 # This function just checks the types a ip-tunnel device usually have
405 # so when we know that the device is an ip-tunnel device we save time
406 device_tunnel_get_type() {
409 # If the device does not exist (happens on udev remove events),
410 # we do not bother to run all checks.
411 if ! device_exists "${device}"; then
414 elif device_is_vti ${device}; then
417 elif device_is_vti6 ${device}; then
425 device_is_ethernet_compatible() {
428 # /sys/class/net/*/type must equal 1 for ethernet compatible devices
429 local type="$
(__device_get_file
"${device}" "type")"
430 [[ "${type}" = "1" ]]
433 device_get_status() {
437 local status=${STATUS_DOWN}
439 if device_is_up ${device}; then
442 if ! device_has_carrier ${device}; then
443 status=${STATUS_NOCARRIER}
450 device_get_address() {
453 cat ${SYS_CLASS_NET}/${device}/address 2>/dev/null
456 device_set_address() {
462 if ! device_exists "${device}"; then
463 error "Device
'${device}' does not exist.
"
467 # Do nothing if the address has not changed
468 local old_addr="$
(device_get_address
"${device}")"
469 if [ -n "${old_addr}" -a "${addr}" = "${old_addr}" ]; then
473 log DEBUG "Setting address of
'${device}' from '${old_addr}' to '${addr}'"
476 if device_is_up "${device}"; then
477 device_set_down "${device}"
481 ip link set "${device}" address "${addr}"
484 if [ "${up}" = "1" ]; then
485 device_set_up "${device}"
488 if [ "${ret}" != "0" ]; then
489 error_log "Could not
set address
'${addr}' on device
'${device}'"
497 for device in $(list_directory "${SYS_CLASS_NET}"); do
498 # bonding_masters is no device
499 [ "${device}" = "bonding_masters
" ] && continue
507 # Check if a device has a cable plugged in
508 device_has_carrier() {
512 local carrier=$(__device_get_file ${device} carrier)
513 [ "${carrier}" = "1" ]
516 device_is_promisc() {
519 device_has_flag ${device} 0x200
522 device_set_promisc() {
526 assert device_exists ${device}
528 assert isoneof state on off
530 ip link set ${device} promisc ${state}
533 # Check if the device is free
535 ! device_is_used "$@
"
538 # Check if the device is used
542 device_has_vlans ${device} && \
544 device_is_bonded ${device} && \
546 device_is_bridge_attached ${device} && \
552 # Give the device a new name
555 local destination=${2}
557 # Check if devices exists
558 if ! device_exists ${source} || device_exists ${destination}; then
563 if device_is_up ${source}; then
564 ip link set ${source} down
568 ip link set ${source} name ${destination}
570 if [ "${up}" = "1" ]; then
571 ip link set ${destination} up
575 device_set_master() {
582 if ! cmd ip link set "${device}" master "${master}"; then
583 log ERROR "Could not
set master
${master} for device
${device}"
590 device_remove_master() {
594 if ! cmd ip link set "${device}" nomaster; then
595 log ERROR "Could not remove master
for device
${device}"
608 # Do nothing if device is already up
609 device_is_up ${device} && return ${EXIT_OK}
611 log INFO "Bringing up
${device}"
613 device_set_parent_up ${device}
614 if ! cmd ip link set ${device} up; then
619 if interrupt_use_smp_affinity; then
620 device_auto_configure_smp_affinity ${device}
626 device_set_parent_up() {
630 if device_is_vlan ${device}; then
631 parent=$(vlan_get_parent ${device})
633 device_is_up ${parent} && return ${EXIT_OK}
635 log DEBUG "Setting up parent device
'${parent}' of
'${device}'"
637 device_set_up ${parent}
651 if device_is_up ${device}; then
652 log INFO "Bringing down
${device}"
654 cmd ip link set ${device} down
658 device_set_parent_down ${device}
663 device_set_parent_down() {
667 if device_is_vlan ${device}; then
668 parent=$(vlan_get_parent ${device})
670 device_is_up ${parent} || return ${EXIT_OK}
672 if device_is_free ${parent}; then
673 log DEBUG "Tearing down parent device
'${parent}' of
'${device}'"
675 device_set_down ${parent}
685 # Return an error if the device does not exist
686 device_exists ${device} || return ${EXIT_ERROR}
688 echo $(<${SYS_CLASS_NET}/${device}/mtu)
691 # Set mtu to a device
696 assert device_exists ${device}
698 # Handle bridges differently
699 if device_is_bridge ${device}; then
701 for port in $(bridge_get_members ${device}); do
702 device_set_mtu ${port} ${mtu}
706 log INFO "Setting MTU of
${device} to
${mtu}"
709 if device_is_up ${device}; then
710 device_set_down ${device}
715 if ! cmd ip link set ${device} mtu ${mtu}; then
718 log ERROR "Could not
set MTU
${mtu} on
${device}"
721 if [ "${up}" = "1" ]; then
722 device_set_up ${device}
728 device_adjust_mtu() {
732 local other_device="${2}"
734 local mtu="$
(device_get_mtu
"${other_device}")"
735 device_set_mtu "${device}" "${mtu}"
741 log INFO "Running discovery process on device
'${device}'.
"
744 for hook in $(hook_zone_get_all); do
745 hook_zone_exec ${hook} discover ${device}
754 # Flash for ten seconds by default
758 local background="false
"
767 seconds="$
(cli_get_val
"${arg}")"
770 done <<< "$
(args
"$@")"
772 assert isinteger seconds
774 if ! device_exists "${device}"; then
775 log ERROR "Cannot identify device
${device}: Does not exist
"
779 if ! device_is_ethernet "${device}"; then
780 log DEBUG "Cannot identify device
${device}: Not an ethernet device
"
781 return ${EXIT_NOT_SUPPORTED}
784 log DEBUG "Identifying device
${device}"
786 local command="ethtool
--identify ${device} ${seconds}"
789 if enabled background; then
790 cmd_background "${command}"
792 cmd_quiet "${command}"
804 assert device_exists ${device}
806 # IPv6 addresses must be fully imploded
807 local protocol=$(ip_detect_protocol ${addr})
808 case "${protocol}" in
810 addr=$(ipv6_format "${addr}")
814 list_match ${addr} $(device_get_addresses ${device})
817 device_get_addresses() {
820 assert device_exists ${device}
825 ip addr show ${device} | \
826 while read prot addr line; do
827 [ "${prot:0:4}" = "inet
" ] && echo "${addr}"
831 __device_get_file() {
835 fread "${SYS_CLASS_NET}/${device}/${file}"
838 __device_set_file() {
845 fappend "${SYS_CLASS_NET}/${device}/${file}" "${value}"
848 device_get_rx_bytes() {
851 __device_get_file ${device} statistics/rx_bytes
854 device_get_tx_bytes() {
857 __device_get_file ${device} statistics/tx_bytes
860 device_get_rx_packets() {
863 __device_get_file ${device} statistics/rx_packets
866 device_get_tx_packets() {
869 __device_get_file ${device} statistics/tx_packets
872 device_get_rx_errors() {
875 __device_get_file ${device} statistics/rx_errors
878 device_get_tx_errors() {
881 __device_get_file ${device} statistics/tx_errors
887 local speed=$(__device_get_file ${device} speed)
889 # Exit for no output (i.e. no link detected)
890 isset speed || return ${EXIT_ERROR}
892 # Don't return anything for negative values
893 [ ${speed} -lt 0 ] && return ${EXIT_ERROR}
903 assert isinteger speed
905 if ! cmd_quiet ethtool --change "${device}" speed "${speed}"; then
906 log ERROR "Could not
set speed of
${device} to
${speed} MBit
/s
"
910 log DEBUG "Set speed of
${device} to
${speed} MBit
/s
"
915 device_get_duplex() {
918 local duplex=$(__device_get_file ${device} duplex)
930 device_get_link_string() {
936 local speed="$
(device_get_speed
"${device}")"
938 list_append s "${speed} MBit
/s
"
941 local duplex="$
(device_get_duplex
"${device}")"
942 if isset duplex; then
943 list_append s "${duplex} duplex
"
949 device_auto_configure_smp_affinity() {
954 if lock_acquire "smp-affinity
" 60; then
955 device_set_smp_affinity ${device} auto
957 lock_release "smp-affinity
"
961 device_set_smp_affinity() {
967 # mode can be auto which will automatically try to find
968 # the least busy processor, or an integer for the desired
969 # processor that should handle this device
971 local num_processors=$(system_get_processors)
973 if [ "${mode}" = "auto
" ]; then
974 local processor=$(interrupt_choose_least_busy_processor)
976 assert isinteger mode
977 local processor=${mode}
979 if [ ${processor} -gt ${num_processors} ]; then
980 log ERROR "Processor
${processor} does not exist
"
985 local interrupts=$(interrupts_for_device ${device})
986 if ! isset interrupts; then
987 log DEBUG "${device} has no interrupts. Not changing SMP affinity
"
993 for interrupt in ${interrupts}; do
994 interrupt_set_smp_affinity ${interrupt} ${processor}
997 # Find all queues and assign them to the next processor
999 for queue in $(device_get_queues ${device}); do
1001 # Only handle receive queues
1003 for interrupt in $(interrupts_for_device_queue ${device} ${queue}); do
1004 interrupt_set_smp_affinity ${interrupt} ${processor}
1007 device_queue_set_smp_affinity ${device} ${queue} ${processor}
1016 # Get the next available processor if in auto mode
1017 [ "${mode}" = "auto
" ] && processor=$(system_get_next_processor ${processor})
1023 device_get_queues() {
1028 list_directory "${SYS_CLASS_NET}/${device}/queues
"
1031 device_supports_multiqueue() {
1034 local num_queues=$(device_num_queues ${device})
1036 if isset num_queues && [ ${num_queues} -gt 2 ]; then
1040 return ${EXIT_FALSE}
1043 device_num_queues() {
1047 isset type && assert isoneof type rx tx
1052 for q in $(device_get_queues ${device}); do
1053 case "${type},${q}" in
1069 device_queue_get_smp_affinity() {
1075 local path="${SYS_CLASS_NET}/${device}/queues/${queue}"
1079 path="${path}/rps_cpus
"
1082 path="${path}/xps_cpus
"
1085 assert [ -r "${path}" ]
1087 __bitmap_to_processor_ids $(<${path})
1090 device_queue_set_smp_affinity() {
1095 local processor=${3}
1097 local path="${SYS_CLASS_NET}/${device}/queues/${queue}/rps_cpus
"
1098 assert [ -w "${path}" ]
1100 log DEBUG "Setting SMP affinity of
${device} (${queue}) to processor ${processor}"
1102 __processor_id_to_bitmap ${processor} > ${path}
1105 # Tries to find a device which has the given IP address assigned
1106 device_get_by_assigned_ip_address() {
1113 # Read the first line of ip addr show to
1114 read -r device <<< $(ip addr show to "${ip}")
1116 # If we did not found a device we return with ${EXIT_ERROR}
1117 if ! isset device; then
1118 return ${EXIT_ERROR}
1121 # We get something like:
1122 # 3: upl0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
1123 # and we want upl0 so we take the second word and removing the :
1132 device_get_by_mac_address() {
1139 for device in $(device_list); do
1140 if [ "${mac}" = "$
(device_get_address
${device})" ]; then
1146 # We could not found a port to the given mac address so we return exit error
1147 return ${EXIT_ERROR}