2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 .
/usr
/lib
/network
/header-zone
24 HOOK_MANPAGE
="network-zone-bridge"
26 HOOK_SETTINGS
="HOOK ADDRESS STP STP_FORWARD_DELAY STP_HELLO STP_MAXAGE"
27 HOOK_SETTINGS
="${HOOK_SETTINGS} STP_PRIORITY MTU"
29 HOOK_PORT_SETTINGS
="COST PRIORITY"
33 DEFAULT_STP_FORWARD_DELAY
=0
36 DEFAULT_STP_PRIORITY
=512
38 hook_check_settings
() {
40 assert isset MTU
&& assert mtu_is_valid
"ethernet" "${MTU}"
42 # Spanning Tree Protocol
44 assert isinteger STP_HELLO
45 assert isinteger STP_FORWARD_DELAY
46 assert isinteger STP_PRIORITY
49 hook_parse_cmdline
() {
50 while [ $# -gt 0 ]; do
53 ADDRESS
="$(cli_get_val "${1}")"
55 if ! mac_is_valid
"${ADDRESS}"; then
56 error
"Invalid MAC address: ${ADDRESS}"
62 MTU
="$(cli_get_val "${1}")"
64 if ! mtu_is_valid
"ethernet" "${MTU}"; then
65 error
"Invalid MTU: ${MTU}"
71 STP
="$(cli_get_val "${1}")"
75 elif disabled STP
; then
78 error
"Invalid value for STP: ${STP}"
83 --stp-forward-delay=*)
84 STP_FORWARD_DELAY
="$(cli_get_val "${1}")"
86 if ! isinteger STP_FORWARD_DELAY
; then
87 error
"Invalid STP forwarding delay: ${STP_FORWARD_DELAY}"
93 STP_HELLO
="$(cli_get_val "${1}")"
95 if ! isinteger STP_HELLO
; then
96 error
"Invalid STP hello time: ${STP_HELLO}"
102 STP_MAXAGE
="$(cli_get_val "${1}")"
104 if ! isinteger STP_MAXAGE
; then
105 error
"Invalid STP max age: ${STP_MAXAGE}"
111 STP_PRIORITY
="$(cli_get_val "${1}")"
113 if ! isinteger STP_PRIORITY
; then
114 error
"Invalid STP priority: ${STP_PRIORITY}"
120 error
"Unknown argument: ${1}"
127 # Generate a random MAC address if the user passed none
128 if ! isset ADDRESS
; then
129 ADDRESS
="$(mac_generate)"
139 zone_settings_read
"${zone}"
141 # Create the bridge if it does not already exist.
142 if ! device_exists
"${zone}"; then
143 bridge_create
"${zone}" \
144 --address="${ADDRESS}" \
152 if isset STP_FORWARD_DELAY
; then
153 stp_bridge_set_forward_delay
"${zone}" "${STP_FORWARD_DELAY}"
156 if isset STP_HELLO
; then
157 stp_bridge_set_hello_time
"${zone}" "${STP_HELLO}"
160 if isset STP_MAXAGE
; then
161 stp_bridge_set_max_age
"${zone}" "${STP_MAXAGE}"
164 if isset STP_PRIORITY
; then
165 stp_bridge_set_priority
"${zone}" "${STP_PRIORITY}"
168 stp_disable
"${zone}"
171 device_set_up
"${zone}"
173 # XXX Currently, there is a bug (in the linux kernel?) that we need to
174 # set our bridges to promisc mode.
175 device_set_promisc
"${zone}" on
177 # Bring up all configurations
178 zone_configs_up
"${zone}"
187 if ! device_is_up
"${zone}"; then
188 warning
"Zone '${zone}' is not up"
192 # Stop all the configs.
193 zone_configs_down
"${zone}"
195 # Bring down all the ports.
196 zone_ports_down
"${zone}"
197 zone_ports_remove
"${zone}"
200 device_set_down
"${zone}"
201 bridge_delete
"${zone}"
210 # Print the default header.
211 cli_device_headline
"${zone}"
213 # Exit if zone is down
214 if ! zone_is_up
"${zone}"; then
219 cli_headline
2 "Spanning Tree Protocol information"
220 if stp_is_enabled
"${zone}"; then
221 cli_print_fmt1
2 "ID" "$(stp_bridge_get_id ${zone})"
222 cli_print_fmt1
2 "Priority" "$(stp_bridge_get_priority ${zone})"
224 if stp_bridge_is_root
${zone}; then
225 cli_print
2 "This bridge is root."
227 cli_print_fmt1
2 "Designated root" \
228 "$(stp_bridge_get_designated_root ${zone})"
229 cli_print_fmt1
2 "Root path cost" \
230 "$(stp_bridge_get_root_path_cost ${zone})"
234 # Topology information
235 cli_print_fmt1
2 "Topology changing" \
236 "$(stp_bridge_get_topology_change_detected ${zone})"
237 cli_print_fmt1
2 "Topology change time" \
238 "$(beautify_time $(stp_bridge_get_topology_change_timer ${zone}))"
239 cli_print_fmt1
2 "Topology change count" \
240 "$(stp_bridge_get_topology_change_count ${zone})"
243 cli_print
2 "Disabled"
247 cli_headline
2 "Ports"
248 zone_ports_status
"${zone}"
251 cli_headline
2 "Configurations"
252 zone_configs_cmd status
"${zone}"
262 case "$(hotplug_action)" in
264 # Attach all ports when zone is coming up
265 if hotplug_event_interface_is_zone
"${zone}"; then
268 for port
in $
(zone_get_ports
"${zone}"); do
269 log DEBUG
"Trying to attach port ${port} to ${zone}"
271 hook_port_up
"${zone}" "${port}"
274 # Handle ports of this zone that have just been added
275 elif hotplug_event_interface_is_port_of_zone
"${zone}"; then
276 # Attach the device if the parent bridge is up
277 if zone_is_active
"${zone}"; then
278 hook_port_up
"${zone}" "${INTERFACE}"
284 if hotplug_event_interface_is_zone
"${zone}"; then
285 # Bring down/destroy all ports
287 for port
in $
(zone_get_ports
"${zone}"); do
288 log DEBUG
"Trying to detach port ${port} from ${zone}"
290 hook_port_down
"${zone}" "${port}"
293 # Handle ports of this zone that have just been removed
294 elif hotplug_event_interface_is_port_of_zone
"${zone}"; then
295 hook_port_down
"${zone}" "${INTERFACE}"
300 exit ${EXIT_NOT_HANDLED}
307 hook_check_port_settings
() {
309 assert isinteger COST
312 if isset PRIORITY
; then
313 assert isinteger PRIORITY
318 # Excepting at least two arguments here
325 if zone_has_port
"${zone}" "${port}"; then
326 zone_port_settings_read
"${zone}" "${port}"
334 COST
="$(cli_get_val "${arg}")"
337 PRIORITY
="$(cli_get_val "${arg}")"
340 done <<< "$(args "$@
")"
342 if ! zone_port_settings_write
"${zone}" "${port}"; then
355 # Shut down the port (if possible)
358 if ! zone_port_settings_remove
"${zone}" "${port}"; then
366 hook_port_attach
"$@"
375 # Try bringing up the port if it has not been
377 # We will get here as soon as the port device has
378 # been created and will then connect it with the bridge.
379 if ! device_exists
"${port}"; then
380 port_create
"${port}"
385 # Read configuration values
386 zone_port_settings_read
"${zone}" "${port}" ${HOOK_PORT_SETTINGS}
388 # Make sure that the port is up
391 # Attach the port to the bridge
392 bridge_attach_device "${zone}" "${port}"
394 # Set STP configuration
396 stp_port_set_cost "${zone}" "${port}" "${COST}"
399 if isset PRIORITY; then
400 stp_port_set_priority "${zone}" "${port}" "${PRIORITY}"
412 if device_exists "${port}"; then
413 bridge_detach_device "${zone}" "${port}"
427 # Do nothing for devices which are not up and running.
428 device_exists "${port}" || exit ${EXIT_OK}
432 # Check if the device is down.
433 if ! device_is_up "${port}"; then
434 status="${MSG_DEVICE_STATUS_DOWN}"
436 # Check if the device has no carrier.
437 elif ! device_has_carrier "${port}"; then
438 status="${MSG_DEVICE_STATUS_NOCARRIER}"
440 # Check for STP information.
441 elif stp_is_enabled "${zone}"; then
442 local state="$
(stp_port_get_state
"${zone}" "${port}")"
443 state="MSG_STP_
${state}"
446 status="${status} - DSR: $(stp_port_get_designated_root "${zone}" "${port}")"
447 status
="${status} - Cost: $(stp_port_get_cost "${zone}" "${port}")"
449 status="${MSG_DEVICE_STATUS_UP}"
451 cli_statusline 3 "${port}" "${status}"