2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 .
/usr
/lib
/network
/header-zone
24 HOOK_MANPAGE
="network-zone-bridge"
26 HOOK_SETTINGS
="HOOK ADDRESS STP STP_FORWARD_DELAY STP_HELLO STP_MAXAGE"
27 HOOK_SETTINGS
="${HOOK_SETTINGS} STP_PRIORITY MTU"
29 HOOK_PORT_SETTINGS
="COST PRIORITY"
39 hook_check_settings
() {
41 assert isset MTU
&& assert mtu_is_valid
"ethernet" "${MTU}"
43 # Spanning Tree Protocol
45 assert isinteger STP_HELLO
46 assert isinteger STP_FORWARD_DELAY
47 assert isinteger STP_PRIORITY
50 hook_parse_cmdline
() {
51 while [ $# -gt 0 ]; do
54 ADDRESS
="$(cli_get_val "${1}")"
56 if ! mac_is_valid
"${ADDRESS}"; then
57 error
"Invalid MAC address: ${ADDRESS}"
63 MTU
="$(cli_get_val "${1}")"
65 if ! mtu_is_valid
"ethernet" "${MTU}"; then
66 error
"Invalid MTU: ${MTU}"
72 STP
="$(cli_get_val "${1}")"
76 elif disabled STP
; then
79 error
"Invalid value for STP: ${STP}"
85 STP_HELLO
="$(cli_get_val "${1}")"
87 if ! isinteger STP_HELLO
; then
88 error
"Invalid STP hello time: ${STP_HELLO}"
93 --stp-forward-delay=*)
94 STP_FORWARD_DELAY
="$(cli_get_val "${1}")"
96 if ! isinteger STP_FORWARD_DELAY
; then
97 error
"Invalid STP forwarding delay: ${STP_FORWARD_DELAY}"
103 STP_PRIORITY
="$(cli_get_val "${1}")"
105 if ! isinteger STP_PRIORITY
; then
106 error
"Invalid STP priority: ${STP_PRIORITY}"
112 error
"Unknown argument: ${1}"
119 # Generate a random MAC address if the user passed no one
120 if isset ADDRESS
; then
121 ADDRESS
="$(mac_generate)"
131 zone_settings_read
"${zone}"
133 # Create the bridge if it does not already exist.
134 if ! device_exists
"${zone}"; then
135 bridge_create
"${zone}" \
136 --address="${ADDRESS}" \
144 if isset STP_FORWARD_DELAY
; then
145 stp_bridge_set_forward_delay
"${zone}" "${STP_FORWARD_DELAY}"
148 if isset STP_HELLO
; then
149 stp_bridge_set_hello_time
"${zone}" "${STP_HELLO}"
152 if isset STP_MAXAGE
; then
153 stp_bridge_set_max_age
"${zone}" "${STP_MAXAGE}"
156 if isset STP_PRIORITY
; then
157 stp_bridge_set_priority
"${zone}" "${STP_PRIORITY}"
160 stp_disable
"${zone}"
163 device_set_up
"${zone}"
165 # XXX Currently, there is a bug (in the linux kernel?) that we need to
166 # set our bridges to promisc mode.
167 device_set_promisc
"${zone}" on
169 # Bring up all configurations
170 zone_configs_up
"${zone}"
179 if ! device_is_up
"${zone}"; then
180 warning
"Zone '${zone}' is not up"
184 # Stop all the configs.
185 zone_configs_down
"${zone}"
187 # Bring down all the ports.
188 zone_ports_down
"${zone}"
189 zone_ports_remove
"${zone}"
192 device_set_down
"${zone}"
193 bridge_delete
"${zone}"
202 # Print the default header.
203 cli_device_headline
"${zone}"
205 # Exit if zone is down
206 if ! zone_is_up
"${zone}"; then
211 cli_headline
2 "Spanning Tree Protocol information"
212 if stp_is_enabled
"${zone}"; then
213 cli_print_fmt1
2 "ID" "$(stp_bridge_get_id ${zone})"
214 cli_print_fmt1
2 "Priority" "$(stp_bridge_get_priority ${zone})"
216 if stp_bridge_is_root
${zone}; then
217 cli_print
2 "This bridge is root."
219 cli_print_fmt1
2 "Designated root" \
220 "$(stp_bridge_get_designated_root ${zone})"
221 cli_print_fmt1
2 "Root path cost" \
222 "$(stp_bridge_get_root_path_cost ${zone})"
226 # Topology information
227 cli_print_fmt1
2 "Topology changing" \
228 "$(stp_bridge_get_topology_change_detected ${zone})"
229 cli_print_fmt1
2 "Topology change time" \
230 "$(beautify_time $(stp_bridge_get_topology_change_timer ${zone}))"
231 cli_print_fmt1
2 "Topology change count" \
232 "$(stp_bridge_get_topology_change_count ${zone})"
235 cli_print
2 "Disabled"
239 cli_headline
2 "Ports"
240 zone_ports_status
"${zone}"
243 cli_headline
2 "Configurations"
244 zone_configs_cmd status
"${zone}"
254 case "$(hotplug_action)" in
256 # Attach all ports when zone is coming up
257 if hotplug_event_interface_is_zone
"${zone}"; then
260 for port
in $
(zone_get_ports
"${zone}"); do
261 log DEBUG
"Trying to attach port ${port} to ${zone}"
263 hook_port_up
"${zone}" "${port}"
266 # Handle ports of this zone that have just been added
267 elif hotplug_event_interface_is_port_of_zone
"${zone}"; then
268 # Attach the device if the parent bridge is up
269 if zone_is_active
"${zone}"; then
270 hook_port_up
"${zone}" "${INTERFACE}"
276 if hotplug_event_interface_is_zone
"${zone}"; then
277 # Bring down/destroy all ports
279 for port
in $
(zone_get_ports
"${zone}"); do
280 log DEBUG
"Trying to detach port ${port} from ${zone}"
282 hook_port_down
"${zone}" "${port}"
285 # Handle ports of this zone that have just been removed
286 elif hotplug_event_interface_is_port_of_zone
"${zone}"; then
287 hook_port_down
"${zone}" "${INTERFACE}"
292 exit ${EXIT_NOT_HANDLED}
299 hook_check_port_settings
() {
301 assert isinteger COST
304 if isset PRIORITY
; then
305 assert isinteger PRIORITY
310 # Excepting at least two arguments here
317 if zone_has_port
"${zone}" "${port}"; then
318 zone_port_settings_read
"${zone}" "${port}"
326 COST
="$(cli_get_val "${arg}")"
329 PRIORITY
="$(cli_get_val "${arg}")"
332 done <<< "$(args "$@
")"
334 if ! zone_port_settings_write
"${zone}" "${port}"; then
347 # Shut down the port (if possible)
350 if ! zone_port_settings_remove
"${zone}" "${port}"; then
358 hook_port_attach
"$@"
367 # Try bringing up the port if it has not been
369 # We will get here as soon as the port device has
370 # been created and will then connect it with the bridge.
371 if ! device_exists
"${port}"; then
372 port_create
"${port}"
377 # Read configuration values
378 zone_port_settings_read
"${zone}" "${port}" ${HOOK_PORT_SETTINGS}
380 # Make sure that the port is up
383 # Attach the port to the bridge
384 bridge_attach_device "${zone}" "${port}"
386 # Set STP configuration
388 stp_port_set_cost "${zone}" "${port}" "${COST}"
391 if isset PRIORITY; then
392 stp_port_set_priority "${zone}" "${port}" "${PRIORITY}"
404 if device_exists "${port}"; then
405 bridge_detach_device "${zone}" "${port}"
419 # Do nothing for devices which are not up and running.
420 device_exists "${port}" || exit ${EXIT_OK}
424 # Check if the device is down.
425 if ! device_is_up "${port}"; then
426 status="${MSG_DEVICE_STATUS_DOWN}"
428 # Check if the device has no carrier.
429 elif ! device_has_carrier "${port}"; then
430 status="${MSG_DEVICE_STATUS_NOCARRIER}"
432 # Check for STP information.
433 elif stp_is_enabled "${zone}"; then
434 local state="$
(stp_port_get_state
"${zone}" "${port}")"
435 state="MSG_STP_
${state}"
438 status="${status} - DSR: $(stp_port_get_designated_root "${zone}" "${port}")"
439 status
="${status} - Cost: $(stp_port_get_cost "${zone}" "${port}")"
441 status="${MSG_DEVICE_STATUS_UP}"
443 cli_statusline 3 "${port}" "${status}"