2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 .
/usr
/lib
/network
/header-zone
24 HOOK_MANPAGE
="network-zone-bridge"
26 HOOK_SETTINGS
="HOOK ADDRESS STP STP_FORWARD_DELAY STP_HELLO STP_MAXAGE"
27 HOOK_SETTINGS
="${HOOK_SETTINGS} STP_PRIORITY MTU"
29 HOOK_PORT_SETTINGS
="COST PRIORITY"
32 DEFAULT_STP_FORWARD_DELAY
=0
35 DEFAULT_STP_PRIORITY
=512
37 hook_check_settings
() {
39 assert isset MTU
&& assert mtu_is_valid
"ethernet" "${MTU}"
41 # Spanning Tree Protocol
43 assert isinteger STP_HELLO
44 assert isinteger STP_FORWARD_DELAY
45 assert isinteger STP_PRIORITY
48 hook_parse_cmdline
() {
49 while [ $# -gt 0 ]; do
52 ADDRESS
="$(cli_get_val "${1}")"
54 if ! mac_is_valid
"${ADDRESS}"; then
55 error
"Invalid MAC address: ${ADDRESS}"
61 MTU
="$(cli_get_val "${1}")"
63 if ! mtu_is_valid
"ethernet" "${MTU}"; then
64 error
"Invalid MTU: ${MTU}"
70 STP
="$(cli_get_val "${1}")"
74 elif disabled STP
; then
77 error
"Invalid value for STP: ${STP}"
82 --stp-forward-delay=*)
83 STP_FORWARD_DELAY
="$(cli_get_val "${1}")"
85 if ! isinteger STP_FORWARD_DELAY
; then
86 error
"Invalid STP forwarding delay: ${STP_FORWARD_DELAY}"
92 STP_HELLO
="$(cli_get_val "${1}")"
94 if ! isinteger STP_HELLO
; then
95 error
"Invalid STP hello time: ${STP_HELLO}"
101 STP_PRIORITY
="$(cli_get_val "${1}")"
103 if ! isinteger STP_PRIORITY
; then
104 error
"Invalid STP priority: ${STP_PRIORITY}"
110 error
"Unknown argument: ${1}"
117 # Generate a random MAC address if the user passed no one
118 if ! isset ADDRESS
; then
119 ADDRESS
="$(mac_generate)"
122 # Enable Spanning Tree Protocol by default
127 # Set all other defaults
137 zone_settings_read
"${zone}"
139 # Create the bridge if it does not already exist.
140 if ! device_exists
"${zone}"; then
141 bridge_create
"${zone}" \
142 --address="${ADDRESS}" \
150 if isset STP_FORWARD_DELAY
; then
151 stp_bridge_set_forward_delay
"${zone}" "${STP_FORWARD_DELAY}"
154 if isset STP_HELLO
; then
155 stp_bridge_set_hello_time
"${zone}" "${STP_HELLO}"
158 if isset STP_MAXAGE
; then
159 stp_bridge_set_max_age
"${zone}" "${STP_MAXAGE}"
162 if isset STP_PRIORITY
; then
163 stp_bridge_set_priority
"${zone}" "${STP_PRIORITY}"
166 stp_disable
"${zone}"
169 device_set_up
"${zone}"
171 # XXX Currently, there is a bug (in the linux kernel?) that we need to
172 # set our bridges to promisc mode.
173 device_set_promisc
"${zone}" on
175 # Bring up all configurations
176 zone_configs_up
"${zone}"
185 if ! device_is_up
"${zone}"; then
186 warning
"Zone '${zone}' is not up"
190 # Stop all the configs.
191 zone_configs_down
"${zone}"
193 # Bring down all the ports.
194 zone_ports_down
"${zone}"
195 zone_ports_remove
"${zone}"
198 device_set_down
"${zone}"
199 bridge_delete
"${zone}"
208 # Print the default header.
209 cli_device_headline
"${zone}"
211 # Exit if zone is down
212 if ! zone_is_up
"${zone}"; then
217 cli_headline
2 "Spanning Tree Protocol information"
218 if stp_is_enabled
"${zone}"; then
219 cli_print_fmt1
2 "ID" "$(stp_bridge_get_id ${zone})"
220 cli_print_fmt1
2 "Priority" "$(stp_bridge_get_priority ${zone})"
222 if stp_bridge_is_root
${zone}; then
223 cli_print
2 "This bridge is root."
225 cli_print_fmt1
2 "Designated root" \
226 "$(stp_bridge_get_designated_root ${zone})"
227 cli_print_fmt1
2 "Root path cost" \
228 "$(stp_bridge_get_root_path_cost ${zone})"
232 # Topology information
233 cli_print_fmt1
2 "Topology changing" \
234 "$(stp_bridge_get_topology_change_detected ${zone})"
235 cli_print_fmt1
2 "Topology change time" \
236 "$(beautify_time $(stp_bridge_get_topology_change_timer ${zone}))"
237 cli_print_fmt1
2 "Topology change count" \
238 "$(stp_bridge_get_topology_change_count ${zone})"
241 cli_print
2 "Disabled"
245 cli_headline
2 "Ports"
246 zone_ports_status
"${zone}"
249 cli_headline
2 "Configurations"
250 zone_configs_cmd status
"${zone}"
260 case "$(hotplug_action)" in
262 # Attach all ports when zone is coming up
263 if hotplug_event_interface_is_zone
"${zone}"; then
266 for port
in $
(zone_get_ports
"${zone}"); do
267 log DEBUG
"Trying to attach port ${port} to ${zone}"
269 hook_port_up
"${zone}" "${port}"
272 # Handle ports of this zone that have just been added
273 elif hotplug_event_interface_is_port_of_zone
"${zone}"; then
274 # Attach the device if the parent bridge is up
275 if zone_is_active
"${zone}"; then
276 hook_port_up
"${zone}" "${INTERFACE}"
282 if hotplug_event_interface_is_zone
"${zone}"; then
283 # Bring down/destroy all ports
285 for port
in $
(zone_get_ports
"${zone}"); do
286 log DEBUG
"Trying to detach port ${port} from ${zone}"
288 hook_port_down
"${zone}" "${port}"
291 # Handle ports of this zone that have just been removed
292 elif hotplug_event_interface_is_port_of_zone
"${zone}"; then
293 hook_port_down
"${zone}" "${INTERFACE}"
298 exit ${EXIT_NOT_HANDLED}
305 hook_check_port_settings
() {
307 assert isinteger COST
310 if isset PRIORITY
; then
311 assert isinteger PRIORITY
316 # Excepting at least two arguments here
323 if zone_has_port
"${zone}" "${port}"; then
324 zone_port_settings_read
"${zone}" "${port}"
332 COST
="$(cli_get_val "${arg}")"
335 PRIORITY
="$(cli_get_val "${arg}")"
338 done <<< "$(args "$@
")"
340 if ! zone_port_settings_write
"${zone}" "${port}"; then
353 # Shut down the port (if possible)
356 if ! zone_port_settings_remove
"${zone}" "${port}"; then
364 hook_port_attach
"$@"
373 # Try bringing up the port if it has not been
375 # We will get here as soon as the port device has
376 # been created and will then connect it with the bridge.
377 if ! device_exists
"${port}"; then
378 port_create
"${port}"
383 # Read configuration values
384 zone_port_settings_read
"${zone}" "${port}" ${HOOK_PORT_SETTINGS}
386 # Make sure that the port is up
389 # Attach the port to the bridge
390 bridge_attach_device "${zone}" "${port}"
392 # Set STP configuration
394 stp_port_set_cost "${zone}" "${port}" "${COST}"
397 if isset PRIORITY; then
398 stp_port_set_priority "${zone}" "${port}" "${PRIORITY}"
410 if device_exists "${port}"; then
411 bridge_detach_device "${zone}" "${port}"
425 # Do nothing for devices which are not up and running.
426 device_exists "${port}" || exit ${EXIT_OK}
430 # Check if the device is down.
431 if ! device_is_up "${port}"; then
432 status="${MSG_DEVICE_STATUS_DOWN}"
434 # Check if the device has no carrier.
435 elif ! device_has_carrier "${port}"; then
436 status="${MSG_DEVICE_STATUS_NOCARRIER}"
438 # Check for STP information.
439 elif stp_is_enabled "${zone}"; then
440 local state="$
(stp_port_get_state
"${zone}" "${port}")"
441 state="MSG_STP_
${state}"
444 status="${status} - DSR: $(stp_port_get_designated_root "${zone}" "${port}")"
445 status
="${status} - Cost: $(stp_port_get_cost "${zone}" "${port}")"
447 status="${MSG_DEVICE_STATUS_UP}"
449 cli_statusline 3 "${port}" "${status}"