]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/network/networkd-dhcp4.c
networkd: Add support for blacklisting servers
[thirdparty/systemd.git] / src / network / networkd-dhcp4.c
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
3c9b8860
TG
2
3#include <netinet/ether.h>
4#include <linux/if.h>
5
b5efdb8a 6#include "alloc-util.h"
958b66ea 7#include "hostname-util.h"
64b21ece 8#include "parse-util.h"
3c9b8860 9#include "network-internal.h"
23f53b99
TG
10#include "networkd-link.h"
11#include "networkd-manager.h"
12#include "networkd-network.h"
64b21ece
MV
13#include "string-util.h"
14#include "sysctl-util.h"
3c9b8860 15
302a796f 16static int dhcp4_route_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) {
3c9b8860
TG
17 int r;
18
19 assert(link);
6cf4a01c 20 assert(link->dhcp4_messages > 0);
3c9b8860 21
313cefa1 22 link->dhcp4_messages--;
3c9b8860 23
1c4baffc 24 r = sd_netlink_message_get_errno(m);
3c9b8860 25 if (r < 0 && r != -EEXIST) {
f6b8196f 26 log_link_error_errno(link, r, "Could not set DHCPv4 route: %m");
3c9b8860
TG
27 link_enter_failed(link);
28 }
29
6cf4a01c 30 if (link->dhcp4_messages == 0) {
3c9b8860 31 link->dhcp4_configured = true;
8012cd39 32 link_check_ready(link);
3c9b8860
TG
33 }
34
35 return 1;
36}
37
d6eac9bd
DW
38static int route_scope_from_address(const Route *route, const struct in_addr *self_addr) {
39 assert(route);
40 assert(self_addr);
41
42 if (in_addr_is_localhost(AF_INET, &route->dst) ||
43 (self_addr->s_addr && route->dst.in.s_addr == self_addr->s_addr))
44 return RT_SCOPE_HOST;
45 else if (in4_addr_is_null(&route->gw.in))
46 return RT_SCOPE_LINK;
47 else
48 return RT_SCOPE_UNIVERSE;
49}
50
3c9b8860 51static int link_set_dhcp_routes(Link *link) {
f8693fc7 52 _cleanup_free_ sd_dhcp_route **static_routes = NULL;
8cdc46e7 53 bool classless_route = false, static_route = false;
f8862395
TH
54 const struct in_addr *router;
55 struct in_addr address;
3c9b8860 56 int r, n, i;
fc1ba79d 57 uint32_t table;
3c9b8860
TG
58
59 assert(link);
0c9b15a3
AJ
60
61 if (!link->dhcp_lease) /* link went down while we configured the IP addresses? */
62 return 0;
63
64 if (!link->network) /* link went down while we configured the IP addresses? */
65 return 0;
964b26fe
SS
66
67 if (!link->network->dhcp_use_routes)
68 return 0;
3c9b8860 69
bdb9f580 70 table = link_get_dhcp_route_table(link);
fc1ba79d 71
b23aec0d
DW
72 r = sd_dhcp_lease_get_address(link->dhcp_lease, &address);
73 if (r < 0)
74 return log_link_warning_errno(link, r, "DHCP error: could not get address: %m");
75
5f04a209 76 n = sd_dhcp_lease_get_routes(link->dhcp_lease, &static_routes);
599c44e6
YW
77 if (n == -ENODATA)
78 log_link_debug_errno(link, n, "DHCP: No routes received from DHCP server: %m");
79 else if (n < 0)
8dc787d1 80 log_link_debug_errno(link, n, "DHCP error: could not get routes: %m");
5f04a209 81
8cdc46e7 82 for (i = 0; i < n; i++) {
3476951c
TH
83 switch (sd_dhcp_route_get_option(static_routes[i])) {
84 case SD_DHCP_OPTION_CLASSLESS_STATIC_ROUTE:
8cdc46e7 85 classless_route = true;
3476951c
TH
86 break;
87 case SD_DHCP_OPTION_STATIC_ROUTE:
8cdc46e7 88 static_route = true;
3476951c
TH
89 break;
90 }
8cdc46e7
SS
91 }
92
5f04a209 93 for (i = 0; i < n; i++) {
8e766630 94 _cleanup_(route_freep) Route *route = NULL;
5f04a209 95
8cdc46e7
SS
96 /* if the DHCP server returns both a Classless Static Routes option and a Static Routes option,
97 the DHCP client MUST ignore the Static Routes option. */
3476951c
TH
98 if (classless_route &&
99 sd_dhcp_route_get_option(static_routes[i]) != SD_DHCP_OPTION_CLASSLESS_STATIC_ROUTE)
8cdc46e7
SS
100 continue;
101
5f04a209
SS
102 r = route_new(&route);
103 if (r < 0)
104 return log_link_error_errno(link, r, "Could not allocate route: %m");
105
106 route->family = AF_INET;
107 route->protocol = RTPROT_DHCP;
108 assert_se(sd_dhcp_route_get_gateway(static_routes[i], &route->gw.in) >= 0);
109 assert_se(sd_dhcp_route_get_destination(static_routes[i], &route->dst.in) >= 0);
110 assert_se(sd_dhcp_route_get_destination_prefix_length(static_routes[i], &route->dst_prefixlen) >= 0);
111 route->priority = link->network->dhcp_route_metric;
112 route->table = table;
113 route->scope = route_scope_from_address(route, &address);
114
115 r = route_configure(route, link, dhcp4_route_handler);
116 if (r < 0)
117 return log_link_warning_errno(link, r, "Could not set host route: %m");
118
119 link->dhcp4_messages++;
120 }
121
f8862395 122 r = sd_dhcp_lease_get_router(link->dhcp_lease, &router);
825ace96
YW
123 if (IN_SET(r, 0, -ENODATA))
124 log_link_info(link, "DHCP: No gateway received from DHCP server.");
125 else if (r < 0)
444b0170 126 log_link_warning_errno(link, r, "DHCP error: could not get gateway: %m");
825ace96
YW
127 else if (in4_addr_is_null(&router[0]))
128 log_link_info(link, "DHCP: Received gateway is null.");
f6b8196f 129
5f04a209
SS
130 /* According to RFC 3442: If the DHCP server returns both a Classless Static Routes option and
131 a Router option, the DHCP client MUST ignore the Router option. */
8cdc46e7
SS
132 if (classless_route && static_route)
133 log_link_warning(link, "Classless static routes received from DHCP server: ignoring static-route option and router option");
134
f8862395 135 if (r > 0 && !classless_route && !in4_addr_is_null(&router[0])) {
860e636c 136 _cleanup_(route_freep) Route *route = NULL, *route_gw = NULL;
ed9e361a
TG
137
138 r = route_new(&route_gw);
f6b8196f
LP
139 if (r < 0)
140 return log_link_error_errno(link, r, "Could not allocate route: %m");
3c9b8860
TG
141
142 /* The dhcp netmask may mask out the gateway. Add an explicit
143 * route for the gw host so that we can route no matter the
144 * netmask or existing kernel route tables. */
145 route_gw->family = AF_INET;
f8862395 146 route_gw->dst.in = router[0];
3c9b8860 147 route_gw->dst_prefixlen = 32;
2ce40956 148 route_gw->prefsrc.in = address;
3c9b8860 149 route_gw->scope = RT_SCOPE_LINK;
ed9e361a 150 route_gw->protocol = RTPROT_DHCP;
86655331 151 route_gw->priority = link->network->dhcp_route_metric;
fc1ba79d 152 route_gw->table = table;
3c9b8860 153
483d099e 154 r = route_configure(route_gw, link, dhcp4_route_handler);
f6b8196f
LP
155 if (r < 0)
156 return log_link_warning_errno(link, r, "Could not set host route: %m");
3c9b8860 157
313cefa1 158 link->dhcp4_messages++;
3c9b8860 159
860e636c
YW
160 r = route_new(&route);
161 if (r < 0)
162 return log_link_error_errno(link, r, "Could not allocate route: %m");
163
3c9b8860 164 route->family = AF_INET;
f8862395 165 route->gw.in = router[0];
2ce40956 166 route->prefsrc.in = address;
860e636c 167 route->protocol = RTPROT_DHCP;
86655331 168 route->priority = link->network->dhcp_route_metric;
fc1ba79d 169 route->table = table;
3c9b8860 170
483d099e 171 r = route_configure(route, link, dhcp4_route_handler);
3c9b8860 172 if (r < 0) {
f6b8196f 173 log_link_warning_errno(link, r, "Could not set routes: %m");
3c9b8860
TG
174 link_enter_failed(link);
175 return r;
176 }
177
313cefa1 178 link->dhcp4_messages++;
3c9b8860
TG
179 }
180
3c9b8860
TG
181 return 0;
182}
183
184static int dhcp_lease_lost(Link *link) {
8e766630 185 _cleanup_(address_freep) Address *address = NULL;
f8862395 186 const struct in_addr *router;
3c9b8860
TG
187 struct in_addr addr;
188 struct in_addr netmask;
f414a269 189 unsigned prefixlen = 0;
3c9b8860
TG
190 int r;
191
192 assert(link);
193 assert(link->dhcp_lease);
194
79008bdd 195 log_link_warning(link, "DHCP lease lost");
3c9b8860 196
27cb34f5 197 if (link->network->dhcp_use_routes) {
f8693fc7 198 _cleanup_free_ sd_dhcp_route **routes = NULL;
3c9b8860
TG
199 int n, i;
200
201 n = sd_dhcp_lease_get_routes(link->dhcp_lease, &routes);
202 if (n >= 0) {
203 for (i = 0; i < n; i++) {
8e766630 204 _cleanup_(route_freep) Route *route = NULL;
3c9b8860 205
ed9e361a 206 r = route_new(&route);
3c9b8860
TG
207 if (r >= 0) {
208 route->family = AF_INET;
f8693fc7
BG
209 assert_se(sd_dhcp_route_get_gateway(routes[i], &route->gw.in) >= 0);
210 assert_se(sd_dhcp_route_get_destination(routes[i], &route->dst.in) >= 0);
211 assert_se(sd_dhcp_route_get_destination_prefix_length(routes[i], &route->dst_prefixlen) >= 0);
3c9b8860 212
4645ad47 213 route_remove(route, link, NULL);
3c9b8860
TG
214 }
215 }
216 }
3c9b8860 217
f8862395
TH
218 r = sd_dhcp_lease_get_router(link->dhcp_lease, &router);
219 if (r > 0 && !in4_addr_is_null(&router[0])) {
8e766630
LP
220 _cleanup_(route_freep) Route *route_gw = NULL;
221 _cleanup_(route_freep) Route *route = NULL;
3c9b8860 222
ed9e361a 223 r = route_new(&route_gw);
3c9b8860
TG
224 if (r >= 0) {
225 route_gw->family = AF_INET;
f8862395 226 route_gw->dst.in = router[0];
3c9b8860
TG
227 route_gw->dst_prefixlen = 32;
228 route_gw->scope = RT_SCOPE_LINK;
229
4645ad47 230 route_remove(route_gw, link, NULL);
3c9b8860
TG
231 }
232
ed9e361a 233 r = route_new(&route);
3c9b8860
TG
234 if (r >= 0) {
235 route->family = AF_INET;
f8862395 236 route->gw.in = router[0];
3c9b8860 237
4645ad47 238 route_remove(route, link, NULL);
3c9b8860
TG
239 }
240 }
b5799eeb 241 }
3c9b8860 242
b5799eeb
SS
243 r = address_new(&address);
244 if (r >= 0) {
f414a269
TG
245 r = sd_dhcp_lease_get_address(link->dhcp_lease, &addr);
246 if (r >= 0) {
247 r = sd_dhcp_lease_get_netmask(link->dhcp_lease, &netmask);
248 if (r >= 0)
5a941f5f 249 prefixlen = in4_addr_netmask_to_prefixlen(&netmask);
3c9b8860 250
f414a269
TG
251 address->family = AF_INET;
252 address->in_addr.in = addr;
253 address->prefixlen = prefixlen;
3c9b8860 254
63ae0569 255 address_remove(address, link, NULL);
f414a269 256 }
3c9b8860
TG
257 }
258
27cb34f5 259 if (link->network->dhcp_use_mtu) {
3c9b8860
TG
260 uint16_t mtu;
261
262 r = sd_dhcp_lease_get_mtu(link->dhcp_lease, &mtu);
263 if (r >= 0 && link->original_mtu != mtu) {
40288ece 264 r = link_set_mtu(link, link->original_mtu, true);
3c9b8860 265 if (r < 0) {
79008bdd 266 log_link_warning(link,
3c9b8860
TG
267 "DHCP error: could not reset MTU");
268 link_enter_failed(link);
269 return r;
270 }
271 }
272 }
273
27cb34f5 274 if (link->network->dhcp_use_hostname) {
3c9b8860
TG
275 const char *hostname = NULL;
276
27cb34f5
LP
277 if (link->network->dhcp_hostname)
278 hostname = link->network->dhcp_hostname;
dce391e7
LP
279 else
280 (void) sd_dhcp_lease_get_hostname(link->dhcp_lease, &hostname);
a7d0ef44 281
dce391e7
LP
282 if (hostname) {
283 /* If a hostname was set due to the lease, then unset it now. */
59eb33e0 284 r = manager_set_hostname(link->manager, NULL);
3c9b8860 285 if (r < 0)
dce391e7 286 log_link_warning_errno(link, r, "Failed to reset transient hostname: %m");
3c9b8860
TG
287 }
288 }
289
290 link->dhcp_lease = sd_dhcp_lease_unref(link->dhcp_lease);
6a3e5f6a 291 link_dirty(link);
3c9b8860
TG
292 link->dhcp4_configured = false;
293
294 return 0;
295}
296
302a796f 297static int dhcp4_address_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) {
3c9b8860
TG
298 int r;
299
300 assert(link);
301
1c4baffc 302 r = sd_netlink_message_get_errno(m);
3c9b8860 303 if (r < 0 && r != -EEXIST) {
f6b8196f 304 log_link_error_errno(link, r, "Could not set DHCPv4 address: %m");
3c9b8860 305 link_enter_failed(link);
45af44d4 306 } else if (r >= 0)
200a0868 307 manager_rtnl_process_address(rtnl, m, link->manager);
3c9b8860
TG
308
309 link_set_dhcp_routes(link);
310
b5799eeb
SS
311 /* Add back static routes since kernel removes while DHCPv4 address is removed from when lease expires */
312 link_request_set_routes(link);
313
223932c7
AH
314 if (link->dhcp4_messages == 0) {
315 link->dhcp4_configured = true;
316 link_check_ready(link);
317 }
318
3c9b8860
TG
319 return 1;
320}
321
322static int dhcp4_update_address(Link *link,
323 struct in_addr *address,
324 struct in_addr *netmask,
325 uint32_t lifetime) {
8e766630 326 _cleanup_(address_freep) Address *addr = NULL;
3c9b8860
TG
327 unsigned prefixlen;
328 int r;
329
330 assert(address);
331 assert(netmask);
332 assert(lifetime);
333
5a941f5f 334 prefixlen = in4_addr_netmask_to_prefixlen(netmask);
3c9b8860 335
f0213e37 336 r = address_new(&addr);
3c9b8860
TG
337 if (r < 0)
338 return r;
339
340 addr->family = AF_INET;
341 addr->in_addr.in.s_addr = address->s_addr;
342 addr->cinfo.ifa_prefered = lifetime;
343 addr->cinfo.ifa_valid = lifetime;
344 addr->prefixlen = prefixlen;
345 addr->broadcast.s_addr = address->s_addr | ~netmask->s_addr;
346
66669078
TG
347 /* allow reusing an existing address and simply update its lifetime
348 * in case it already exists */
483d099e 349 r = address_configure(addr, link, dhcp4_address_handler, true);
3c9b8860
TG
350 if (r < 0)
351 return r;
352
353 return 0;
354}
355
356static int dhcp_lease_renew(sd_dhcp_client *client, Link *link) {
357 sd_dhcp_lease *lease;
358 struct in_addr address;
359 struct in_addr netmask;
360 uint32_t lifetime = CACHE_INFO_INFINITY_LIFE_TIME;
361 int r;
362
363 assert(link);
364 assert(client);
365 assert(link->network);
366
367 r = sd_dhcp_client_get_lease(client, &lease);
f6b8196f
LP
368 if (r < 0)
369 return log_link_warning_errno(link, r, "DHCP error: no lease: %m");
3c9b8860
TG
370
371 sd_dhcp_lease_unref(link->dhcp_lease);
372 link->dhcp4_configured = false;
e6b18ffa 373 link->dhcp_lease = sd_dhcp_lease_ref(lease);
6a3e5f6a 374 link_dirty(link);
3c9b8860
TG
375
376 r = sd_dhcp_lease_get_address(lease, &address);
f6b8196f
LP
377 if (r < 0)
378 return log_link_warning_errno(link, r, "DHCP error: no address: %m");
3c9b8860
TG
379
380 r = sd_dhcp_lease_get_netmask(lease, &netmask);
f6b8196f
LP
381 if (r < 0)
382 return log_link_warning_errno(link, r, "DHCP error: no netmask: %m");
3c9b8860
TG
383
384 if (!link->network->dhcp_critical) {
f6b8196f
LP
385 r = sd_dhcp_lease_get_lifetime(link->dhcp_lease, &lifetime);
386 if (r < 0)
387 return log_link_warning_errno(link, r, "DHCP error: no lifetime: %m");
3c9b8860
TG
388 }
389
390 r = dhcp4_update_address(link, &address, &netmask, lifetime);
391 if (r < 0) {
f6b8196f 392 log_link_warning_errno(link, r, "Could not update IP address: %m");
3c9b8860
TG
393 link_enter_failed(link);
394 return r;
395 }
396
397 return 0;
398}
399
400static int dhcp_lease_acquired(sd_dhcp_client *client, Link *link) {
f8862395 401 const struct in_addr *router;
3c9b8860
TG
402 sd_dhcp_lease *lease;
403 struct in_addr address;
404 struct in_addr netmask;
3c9b8860
TG
405 unsigned prefixlen;
406 uint32_t lifetime = CACHE_INFO_INFINITY_LIFE_TIME;
407 int r;
408
409 assert(client);
410 assert(link);
411
412 r = sd_dhcp_client_get_lease(client, &lease);
f2341e0a 413 if (r < 0)
f6b8196f 414 return log_link_error_errno(link, r, "DHCP error: No lease: %m");
3c9b8860
TG
415
416 r = sd_dhcp_lease_get_address(lease, &address);
f2341e0a 417 if (r < 0)
f6b8196f 418 return log_link_error_errno(link, r, "DHCP error: No address: %m");
3c9b8860
TG
419
420 r = sd_dhcp_lease_get_netmask(lease, &netmask);
f2341e0a 421 if (r < 0)
f6b8196f 422 return log_link_error_errno(link, r, "DHCP error: No netmask: %m");
3c9b8860 423
5a941f5f 424 prefixlen = in4_addr_netmask_to_prefixlen(&netmask);
3c9b8860 425
f8862395 426 r = sd_dhcp_lease_get_router(lease, &router);
397d15fd 427 if (r < 0 && r != -ENODATA)
f6b8196f 428 return log_link_error_errno(link, r, "DHCP error: Could not get gateway: %m");
3c9b8860 429
f8862395 430 if (r > 0 && !in4_addr_is_null(&router[0]))
f2341e0a
LP
431 log_struct(LOG_INFO,
432 LOG_LINK_INTERFACE(link),
433 LOG_LINK_MESSAGE(link, "DHCPv4 address %u.%u.%u.%u/%u via %u.%u.%u.%u",
434 ADDRESS_FMT_VAL(address),
435 prefixlen,
f8862395 436 ADDRESS_FMT_VAL(router[0])),
f2341e0a
LP
437 "ADDRESS=%u.%u.%u.%u", ADDRESS_FMT_VAL(address),
438 "PREFIXLEN=%u", prefixlen,
f8862395 439 "GATEWAY=%u.%u.%u.%u", ADDRESS_FMT_VAL(router[0]));
3c9b8860 440 else
f2341e0a
LP
441 log_struct(LOG_INFO,
442 LOG_LINK_INTERFACE(link),
443 LOG_LINK_MESSAGE(link, "DHCPv4 address %u.%u.%u.%u/%u",
444 ADDRESS_FMT_VAL(address),
445 prefixlen),
446 "ADDRESS=%u.%u.%u.%u", ADDRESS_FMT_VAL(address),
a1230ff9 447 "PREFIXLEN=%u", prefixlen);
3c9b8860 448
e6b18ffa 449 link->dhcp_lease = sd_dhcp_lease_ref(lease);
6a3e5f6a 450 link_dirty(link);
3c9b8860 451
27cb34f5 452 if (link->network->dhcp_use_mtu) {
3c9b8860
TG
453 uint16_t mtu;
454
455 r = sd_dhcp_lease_get_mtu(lease, &mtu);
456 if (r >= 0) {
40288ece 457 r = link_set_mtu(link, mtu, true);
3c9b8860 458 if (r < 0)
f2341e0a 459 log_link_error_errno(link, r, "Failed to set MTU to %" PRIu16 ": %m", mtu);
3c9b8860
TG
460 }
461 }
462
27cb34f5 463 if (link->network->dhcp_use_hostname) {
2de2abad
LB
464 const char *dhcpname = NULL;
465 _cleanup_free_ char *hostname = NULL;
3c9b8860 466
27cb34f5 467 if (link->network->dhcp_hostname)
2de2abad 468 dhcpname = link->network->dhcp_hostname;
dce391e7 469 else
2de2abad
LB
470 (void) sd_dhcp_lease_get_hostname(lease, &dhcpname);
471
472 if (dhcpname) {
473 r = shorten_overlong(dhcpname, &hostname);
474 if (r < 0)
475 log_link_warning_errno(link, r, "Unable to shorten overlong DHCP hostname '%s', ignoring: %m", dhcpname);
476 if (r == 1)
5238e957 477 log_link_notice(link, "Overlong DHCP hostname received, shortened from '%s' to '%s'", dhcpname, hostname);
2de2abad 478 }
a7d0ef44 479
dce391e7 480 if (hostname) {
59eb33e0 481 r = manager_set_hostname(link->manager, hostname);
3c9b8860 482 if (r < 0)
f2341e0a 483 log_link_error_errno(link, r, "Failed to set transient hostname to '%s': %m", hostname);
3c9b8860
TG
484 }
485 }
486
27cb34f5 487 if (link->network->dhcp_use_timezone) {
21b80ad1
LP
488 const char *tz = NULL;
489
490 (void) sd_dhcp_lease_get_timezone(link->dhcp_lease, &tz);
491
492 if (tz) {
59eb33e0 493 r = manager_set_timezone(link->manager, tz);
21b80ad1
LP
494 if (r < 0)
495 log_link_error_errno(link, r, "Failed to set timezone to '%s': %m", tz);
496 }
497 }
498
3c9b8860 499 if (!link->network->dhcp_critical) {
f2341e0a 500 r = sd_dhcp_lease_get_lifetime(link->dhcp_lease, &lifetime);
fc95c359
YW
501 if (r < 0)
502 return log_link_warning_errno(link, r, "DHCP error: no lifetime: %m");
3c9b8860
TG
503 }
504
505 r = dhcp4_update_address(link, &address, &netmask, lifetime);
506 if (r < 0) {
f2341e0a 507 log_link_warning_errno(link, r, "Could not update IP address: %m");
3c9b8860
TG
508 link_enter_failed(link);
509 return r;
510 }
511
512 return 0;
513}
8bc17bb3 514
727b5734
SS
515static int dhcp_server_is_black_listed(Link *link, sd_dhcp_client *client) {
516 sd_dhcp_lease *lease;
517 struct in_addr addr;
518 int r;
519
520 assert(link);
521 assert(link->network);
522 assert(client);
523
524 r = sd_dhcp_client_get_lease(client, &lease);
525 if (r < 0)
526 return log_link_error_errno(link, r, "Failed to get DHCP lease: %m");
527
528 r = sd_dhcp_lease_get_server_identifier(lease, &addr);
529 if (r < 0)
530 return log_link_debug_errno(link, r, "Failed to get DHCP server ip address: %m");
531
532 if (set_contains(link->network->dhcp_black_listed_ip, UINT32_TO_PTR(addr.s_addr))) {
533 log_struct(LOG_DEBUG,
534 LOG_LINK_INTERFACE(link),
535 LOG_LINK_MESSAGE(link, "DHCPv4 ip '%u.%u.%u.%u' found in black listed ip addresses, ignoring offer",
536 ADDRESS_FMT_VAL(addr)));
537 return true;
538 }
539
540 return false;
541}
542
543static int dhcp4_handler(sd_dhcp_client *client, int event, void *userdata) {
3c9b8860
TG
544 Link *link = userdata;
545 int r = 0;
546
547 assert(link);
548 assert(link->network);
549 assert(link->manager);
550
551 if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER))
727b5734 552 return 0;
3c9b8860
TG
553
554 switch (event) {
03748142 555 case SD_DHCP_CLIENT_EVENT_STOP:
8bc17bb3
SS
556
557 if (link_ipv4ll_fallback_enabled(link)) {
558 assert(link->ipv4ll);
559
560 log_link_debug(link, "DHCP client is stopped. Acquiring IPv4 link-local address");
561
562 r = sd_ipv4ll_start(link->ipv4ll);
727b5734
SS
563 if (r < 0)
564 return log_link_warning_errno(link, r, "Could not acquire IPv4 link-local address: %m");
8bc17bb3
SS
565 }
566
567 _fallthrough_;
568 case SD_DHCP_CLIENT_EVENT_EXPIRED:
03748142 569 case SD_DHCP_CLIENT_EVENT_IP_CHANGE:
8bc17bb3 570
3c9b8860 571 if (link->network->dhcp_critical) {
f6b8196f 572 log_link_error(link, "DHCPv4 connection considered system critical, ignoring request to reconfigure it.");
727b5734 573 return 0;
3c9b8860
TG
574 }
575
576 if (link->dhcp_lease) {
577 r = dhcp_lease_lost(link);
578 if (r < 0) {
579 link_enter_failed(link);
727b5734 580 return r;
3c9b8860
TG
581 }
582 }
583
03748142 584 if (event == SD_DHCP_CLIENT_EVENT_IP_CHANGE) {
3c9b8860
TG
585 r = dhcp_lease_acquired(client, link);
586 if (r < 0) {
587 link_enter_failed(link);
727b5734 588 return r;
3c9b8860
TG
589 }
590 }
591
592 break;
03748142 593 case SD_DHCP_CLIENT_EVENT_RENEW:
3c9b8860
TG
594 r = dhcp_lease_renew(client, link);
595 if (r < 0) {
596 link_enter_failed(link);
727b5734 597 return r;
3c9b8860
TG
598 }
599 break;
03748142 600 case SD_DHCP_CLIENT_EVENT_IP_ACQUIRE:
3c9b8860
TG
601 r = dhcp_lease_acquired(client, link);
602 if (r < 0) {
603 link_enter_failed(link);
727b5734 604 return r;
3c9b8860
TG
605 }
606 break;
727b5734
SS
607 case SD_DHCP_CLIENT_EVENT_SELECTING:
608 r = dhcp_server_is_black_listed(link, client);
609 if (r < 0)
610 return r;
611 if (r != 0)
612 return -ENOMSG;
613 break;
3c9b8860
TG
614 default:
615 if (event < 0)
f6b8196f 616 log_link_warning_errno(link, event, "DHCP error: Client failed: %m");
3c9b8860 617 else
f6b8196f 618 log_link_warning(link, "DHCP unknown event: %i", event);
3c9b8860
TG
619 break;
620 }
621
727b5734 622 return 0;
3c9b8860
TG
623}
624
7192bb81
LP
625static int dhcp4_set_hostname(Link *link) {
626 _cleanup_free_ char *hostname = NULL;
627 const char *hn;
628 int r;
629
630 assert(link);
631
632 if (!link->network->dhcp_send_hostname)
633 hn = NULL;
634 else if (link->network->dhcp_hostname)
635 hn = link->network->dhcp_hostname;
636 else {
637 r = gethostname_strict(&hostname);
638 if (r < 0 && r != -ENXIO) /* ENXIO: no hostname set or hostname is "localhost" */
639 return r;
640
641 hn = hostname;
642 }
643
a8494759
YW
644 r = sd_dhcp_client_set_hostname(link->dhcp_client, hn);
645 if (r == -EINVAL && hostname)
646 /* Ignore error when the machine's hostname is not suitable to send in DHCP packet. */
647 log_link_warning_errno(link, r, "DHCP4 CLIENT: Failed to set hostname from kernel hostname, ignoring: %m");
648 else if (r < 0)
649 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set hostname: %m");
650
651 return 0;
7192bb81
LP
652}
653
64b21ece 654static bool promote_secondaries_enabled(const char *ifname) {
3f550c31
HV
655 _cleanup_free_ char *promote_secondaries_sysctl = NULL;
656 char *promote_secondaries_path;
64b21ece
MV
657 int r;
658
659 promote_secondaries_path = strjoina("net/ipv4/conf/", ifname, "/promote_secondaries");
660 r = sysctl_read(promote_secondaries_path, &promote_secondaries_sysctl);
661 if (r < 0) {
662 log_debug_errno(r, "Cannot read sysctl %s", promote_secondaries_path);
663 return false;
664 }
665
666 truncate_nl(promote_secondaries_sysctl);
667 r = parse_boolean(promote_secondaries_sysctl);
668 if (r < 0)
669 log_warning_errno(r, "Cannot parse sysctl %s with content %s as boolean", promote_secondaries_path, promote_secondaries_sysctl);
670 return r > 0;
671}
672
673/* dhcp4_set_promote_secondaries will ensure this interface has
674 * the "promote_secondaries" option in the kernel set. If this sysctl
675 * is not set DHCP will work only as long as the IP address does not
676 * changes between leases. The kernel will remove all secondary IP
677 * addresses of an interface otherwise. The way systemd-network works
678 * is that the new IP of a lease is added as a secondary IP and when
679 * the primary one expires it relies on the kernel to promote the
680 * secondary IP. See also https://github.com/systemd/systemd/issues/7163
681 */
682int dhcp4_set_promote_secondaries(Link *link) {
683 int r;
684
685 assert(link);
686 assert(link->network);
687 assert(link->network->dhcp & ADDRESS_FAMILY_IPV4);
688
689 /* check if the kernel has promote_secondaries enabled for our
690 * interface. If it is not globally enabled or enabled for the
691 * specific interface we must either enable it.
692 */
8e1a7253 693 if (!(promote_secondaries_enabled("all") || promote_secondaries_enabled(link->ifname))) {
64b21ece
MV
694 char *promote_secondaries_path = NULL;
695
696 log_link_debug(link, "promote_secondaries is unset, setting it");
697 promote_secondaries_path = strjoina("net/ipv4/conf/", link->ifname, "/promote_secondaries");
698 r = sysctl_write(promote_secondaries_path, "1");
699 if (r < 0)
700 log_link_warning_errno(link, r, "cannot set sysctl %s to 1", promote_secondaries_path);
701 return r > 0;
702 }
703
704 return 0;
705}
706
fff1f40c
YW
707int dhcp4_set_client_identifier(Link *link) {
708 int r;
709
710 assert(link);
711 assert(link->network);
712 assert(link->dhcp_client);
713
714 switch (link->network->dhcp_client_identifier) {
715 case DHCP_CLIENT_ID_DUID: {
0cf7c3fd 716 /* If configured, apply user specified DUID and IAID */
fff1f40c
YW
717 const DUID *duid = link_get_duid(link);
718
0cf7c3fd
YW
719 if (duid->type == DUID_TYPE_LLT && duid->raw_data_len == 0)
720 r = sd_dhcp_client_set_iaid_duid_llt(link->dhcp_client,
8217ed5e 721 link->network->iaid_set,
0cf7c3fd
YW
722 link->network->iaid,
723 duid->llt_time);
724 else
725 r = sd_dhcp_client_set_iaid_duid(link->dhcp_client,
8217ed5e 726 link->network->iaid_set,
0cf7c3fd
YW
727 link->network->iaid,
728 duid->type,
729 duid->raw_data_len > 0 ? duid->raw_data : NULL,
730 duid->raw_data_len);
fff1f40c 731 if (r < 0)
0cf7c3fd 732 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set IAID+DUID: %m");
fff1f40c
YW
733 break;
734 }
735 case DHCP_CLIENT_ID_DUID_ONLY: {
736 /* If configured, apply user specified DUID */
737 const DUID *duid = link_get_duid(link);
738
0cf7c3fd
YW
739 if (duid->type == DUID_TYPE_LLT && duid->raw_data_len == 0)
740 r = sd_dhcp_client_set_duid_llt(link->dhcp_client,
89b3fa66 741 duid->llt_time);
0cf7c3fd
YW
742 else
743 r = sd_dhcp_client_set_duid(link->dhcp_client,
744 duid->type,
745 duid->raw_data_len > 0 ? duid->raw_data : NULL,
746 duid->raw_data_len);
fff1f40c
YW
747 if (r < 0)
748 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set DUID: %m");
749 break;
750 }
751 case DHCP_CLIENT_ID_MAC:
752 r = sd_dhcp_client_set_client_id(link->dhcp_client,
753 ARPHRD_ETHER,
754 (const uint8_t *) &link->mac,
755 sizeof(link->mac));
756 if (r < 0)
757 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set client ID: %m");
758 break;
759 default:
760 assert_not_reached("Unknown client identifier type.");
761 }
762
763 return 0;
764}
765
3c9b8860
TG
766int dhcp4_configure(Link *link) {
767 int r;
768
769 assert(link);
770 assert(link->network);
e0ee46f2 771 assert(link->network->dhcp & ADDRESS_FAMILY_IPV4);
3c9b8860 772
0bc70f1d 773 if (!link->dhcp_client) {
db3d2358 774 r = sd_dhcp_client_new(&link->dhcp_client, link->network->dhcp_anonymize);
1f6860d9
YW
775 if (r == -ENOMEM)
776 return log_oom();
0bc70f1d 777 if (r < 0)
1f6860d9 778 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to create DHCP4 client: %m");
0bc70f1d 779 }
3c9b8860
TG
780
781 r = sd_dhcp_client_attach_event(link->dhcp_client, NULL, 0);
782 if (r < 0)
1f6860d9 783 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to attach event: %m");
3c9b8860 784
76253e73
DW
785 r = sd_dhcp_client_set_mac(link->dhcp_client,
786 (const uint8_t *) &link->mac,
787 sizeof (link->mac), ARPHRD_ETHER);
3c9b8860 788 if (r < 0)
1f6860d9 789 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set MAC address: %m");
3c9b8860 790
2f8e7633 791 r = sd_dhcp_client_set_ifindex(link->dhcp_client, link->ifindex);
3c9b8860 792 if (r < 0)
1f6860d9 793 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set ifindex: %m");
3c9b8860
TG
794
795 r = sd_dhcp_client_set_callback(link->dhcp_client, dhcp4_handler, link);
796 if (r < 0)
1f6860d9 797 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set callback: %m");
3c9b8860
TG
798
799 r = sd_dhcp_client_set_request_broadcast(link->dhcp_client,
800 link->network->dhcp_broadcast);
801 if (r < 0)
1f6860d9 802 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for broadcast: %m");
3c9b8860
TG
803
804 if (link->mtu) {
805 r = sd_dhcp_client_set_mtu(link->dhcp_client, link->mtu);
806 if (r < 0)
1f6860d9 807 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set MTU: %m");
3c9b8860
TG
808 }
809
27cb34f5 810 if (link->network->dhcp_use_mtu) {
39745a5a 811 r = sd_dhcp_client_set_request_option(link->dhcp_client,
22805d92 812 SD_DHCP_OPTION_INTERFACE_MTU);
39745a5a 813 if (r < 0)
1f6860d9 814 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for MTU: %m");
3c9b8860
TG
815 }
816
5e77a146 817 /* NOTE: even if this variable is called "use", it also "sends" PRL
818 * options, maybe there should be a different configuration variable
819 * to send or not route options?. */
28522b0d 820 /* NOTE: when using Anonymize=yes, routes PRL options are sent
821 * by default, so they don't need to be added here. */
5e77a146 822 if (link->network->dhcp_use_routes && !link->network->dhcp_anonymize) {
3c9b8860 823 r = sd_dhcp_client_set_request_option(link->dhcp_client,
22805d92 824 SD_DHCP_OPTION_STATIC_ROUTE);
3c9b8860 825 if (r < 0)
1f6860d9
YW
826 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for static route: %m");
827
3c9b8860 828 r = sd_dhcp_client_set_request_option(link->dhcp_client,
22805d92 829 SD_DHCP_OPTION_CLASSLESS_STATIC_ROUTE);
7d6884b6 830 if (r < 0)
1f6860d9 831 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for classless static route: %m");
3c9b8860
TG
832 }
833
ead36ce6 834 if (link->network->dhcp_use_ntp) {
835 r = sd_dhcp_client_set_request_option(link->dhcp_client, SD_DHCP_OPTION_NTP_SERVER);
836 if (r < 0)
1f6860d9 837 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for NTP server: %m");
ead36ce6 838 }
4b7b5abb 839
89573b37 840 if (link->network->dhcp_use_timezone) {
841 r = sd_dhcp_client_set_request_option(link->dhcp_client, SD_DHCP_OPTION_NEW_TZDB_TIMEZONE);
842 if (r < 0)
1f6860d9 843 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for timezone: %m");
89573b37 844 }
8eb9058d 845
7192bb81
LP
846 r = dhcp4_set_hostname(link);
847 if (r < 0)
a8494759 848 return r;
3c9b8860
TG
849
850 if (link->network->dhcp_vendor_class_identifier) {
851 r = sd_dhcp_client_set_vendor_class_identifier(link->dhcp_client,
852 link->network->dhcp_vendor_class_identifier);
853 if (r < 0)
1f6860d9 854 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set vendor class identifier: %m");
3c9b8860
TG
855 }
856
af1c0de0
SS
857 if (link->network->dhcp_user_class) {
858 r = sd_dhcp_client_set_user_class(link->dhcp_client, (const char **) link->network->dhcp_user_class);
859 if (r < 0)
1f6860d9 860 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set user class: %m");
af1c0de0
SS
861 }
862
9faed222
SS
863 if (link->network->dhcp_client_port) {
864 r = sd_dhcp_client_set_client_port(link->dhcp_client, link->network->dhcp_client_port);
865 if (r < 0)
1f6860d9 866 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set listen port: %m");
9faed222
SS
867 }
868
715cedfb
SS
869 if (link->network->dhcp_max_attempts > 0) {
870 r = sd_dhcp_client_set_max_attempts(link->dhcp_client, link->network->dhcp_max_attempts);
871 if (r < 0)
872 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set max attempts: %m");
873 }
874
fff1f40c 875 return dhcp4_set_client_identifier(link);
3c9b8860 876}