]>
Commit | Line | Data |
---|---|---|
1 | /* SPDX-License-Identifier: LGPL-2.1+ */ | |
2 | ||
3 | #include <netinet/in.h> | |
4 | #include <linux/if.h> | |
5 | #include <unistd.h> | |
6 | ||
7 | #include "alloc-util.h" | |
8 | #include "bus-util.h" | |
9 | #include "dhcp-identifier.h" | |
10 | #include "dhcp-lease-internal.h" | |
11 | #include "env-file.h" | |
12 | #include "fd-util.h" | |
13 | #include "fileio.h" | |
14 | #include "missing_network.h" | |
15 | #include "netdev/vrf.h" | |
16 | #include "netlink-util.h" | |
17 | #include "network-internal.h" | |
18 | #include "networkd-can.h" | |
19 | #include "networkd-ipv6-proxy-ndp.h" | |
20 | #include "networkd-lldp-tx.h" | |
21 | #include "networkd-manager.h" | |
22 | #include "networkd-ndisc.h" | |
23 | #include "networkd-neighbor.h" | |
24 | #include "networkd-radv.h" | |
25 | #include "networkd-routing-policy-rule.h" | |
26 | #include "set.h" | |
27 | #include "socket-util.h" | |
28 | #include "stdio-util.h" | |
29 | #include "string-table.h" | |
30 | #include "strv.h" | |
31 | #include "sysctl-util.h" | |
32 | #include "tmpfile-util.h" | |
33 | #include "udev-util.h" | |
34 | #include "util.h" | |
35 | #include "virt.h" | |
36 | ||
37 | uint32_t link_get_vrf_table(Link *link) { | |
38 | return link->network->vrf ? VRF(link->network->vrf)->table : RT_TABLE_MAIN; | |
39 | } | |
40 | ||
41 | uint32_t link_get_dhcp_route_table(Link *link) { | |
42 | /* When the interface is part of an VRF use the VRFs routing table, unless | |
43 | * another table is explicitly specified. */ | |
44 | if (link->network->dhcp_route_table_set) | |
45 | return link->network->dhcp_route_table; | |
46 | return link_get_vrf_table(link); | |
47 | } | |
48 | ||
49 | uint32_t link_get_ipv6_accept_ra_route_table(Link *link) { | |
50 | if (link->network->ipv6_accept_ra_route_table_set) | |
51 | return link->network->ipv6_accept_ra_route_table; | |
52 | return link_get_vrf_table(link); | |
53 | } | |
54 | ||
55 | DUID* link_get_duid(Link *link) { | |
56 | if (link->network->duid.type != _DUID_TYPE_INVALID) | |
57 | return &link->network->duid; | |
58 | else | |
59 | return &link->manager->duid; | |
60 | } | |
61 | ||
62 | static bool link_dhcp6_enabled(Link *link) { | |
63 | assert(link); | |
64 | ||
65 | if (!socket_ipv6_is_supported()) | |
66 | return false; | |
67 | ||
68 | if (link->flags & IFF_LOOPBACK) | |
69 | return false; | |
70 | ||
71 | if (!link->network) | |
72 | return false; | |
73 | ||
74 | if (link->network->bond) | |
75 | return false; | |
76 | ||
77 | if (manager_sysctl_ipv6_enabled(link->manager) == 0) | |
78 | return false; | |
79 | ||
80 | return link->network->dhcp & ADDRESS_FAMILY_IPV6; | |
81 | } | |
82 | ||
83 | static bool link_dhcp4_enabled(Link *link) { | |
84 | assert(link); | |
85 | ||
86 | if (link->flags & IFF_LOOPBACK) | |
87 | return false; | |
88 | ||
89 | if (!link->network) | |
90 | return false; | |
91 | ||
92 | if (link->network->bond) | |
93 | return false; | |
94 | ||
95 | return link->network->dhcp & ADDRESS_FAMILY_IPV4; | |
96 | } | |
97 | ||
98 | static bool link_dhcp4_server_enabled(Link *link) { | |
99 | assert(link); | |
100 | ||
101 | if (link->flags & IFF_LOOPBACK) | |
102 | return false; | |
103 | ||
104 | if (!link->network) | |
105 | return false; | |
106 | ||
107 | if (link->network->bond) | |
108 | return false; | |
109 | ||
110 | return link->network->dhcp_server; | |
111 | } | |
112 | ||
113 | bool link_ipv4ll_enabled(Link *link) { | |
114 | assert(link); | |
115 | ||
116 | if (link->flags & IFF_LOOPBACK) | |
117 | return false; | |
118 | ||
119 | if (!link->network) | |
120 | return false; | |
121 | ||
122 | if (STRPTR_IN_SET(link->kind, "vrf", "wireguard")) | |
123 | return false; | |
124 | ||
125 | if (link->network->bond) | |
126 | return false; | |
127 | ||
128 | return link->network->link_local & ADDRESS_FAMILY_IPV4; | |
129 | } | |
130 | ||
131 | bool link_ipv4ll_fallback_enabled(Link *link) { | |
132 | assert(link); | |
133 | ||
134 | if (link->flags & IFF_LOOPBACK) | |
135 | return false; | |
136 | ||
137 | if (!link->network) | |
138 | return false; | |
139 | ||
140 | if (STRPTR_IN_SET(link->kind, "vrf", "wireguard")) | |
141 | return false; | |
142 | ||
143 | if (link->network->bond) | |
144 | return false; | |
145 | ||
146 | return link->network->link_local & ADDRESS_FAMILY_FALLBACK_IPV4; | |
147 | } | |
148 | ||
149 | static bool link_ipv6ll_enabled(Link *link) { | |
150 | assert(link); | |
151 | ||
152 | if (!socket_ipv6_is_supported()) | |
153 | return false; | |
154 | ||
155 | if (link->flags & IFF_LOOPBACK) | |
156 | return false; | |
157 | ||
158 | if (!link->network) | |
159 | return false; | |
160 | ||
161 | if (STRPTR_IN_SET(link->kind, "vrf", "wireguard")) | |
162 | return false; | |
163 | ||
164 | if (link->network->bond) | |
165 | return false; | |
166 | ||
167 | if (manager_sysctl_ipv6_enabled(link->manager) == 0) | |
168 | return false; | |
169 | ||
170 | return link->network->link_local & ADDRESS_FAMILY_IPV6; | |
171 | } | |
172 | ||
173 | static bool link_ipv6_enabled(Link *link) { | |
174 | assert(link); | |
175 | ||
176 | if (!socket_ipv6_is_supported()) | |
177 | return false; | |
178 | ||
179 | if (link->network->bond) | |
180 | return false; | |
181 | ||
182 | if (manager_sysctl_ipv6_enabled(link->manager) == 0) | |
183 | return false; | |
184 | ||
185 | /* DHCPv6 client will not be started if no IPv6 link-local address is configured. */ | |
186 | return link_ipv6ll_enabled(link) || network_has_static_ipv6_addresses(link->network); | |
187 | } | |
188 | ||
189 | static bool link_radv_enabled(Link *link) { | |
190 | assert(link); | |
191 | ||
192 | if (!link_ipv6ll_enabled(link)) | |
193 | return false; | |
194 | ||
195 | return link->network->router_prefix_delegation != RADV_PREFIX_DELEGATION_NONE; | |
196 | } | |
197 | ||
198 | static bool link_ipv4_forward_enabled(Link *link) { | |
199 | assert(link); | |
200 | ||
201 | if (link->flags & IFF_LOOPBACK) | |
202 | return false; | |
203 | ||
204 | if (!link->network) | |
205 | return false; | |
206 | ||
207 | if (link->network->ip_forward == _ADDRESS_FAMILY_BOOLEAN_INVALID) | |
208 | return false; | |
209 | ||
210 | return link->network->ip_forward & ADDRESS_FAMILY_IPV4; | |
211 | } | |
212 | ||
213 | static bool link_ipv6_forward_enabled(Link *link) { | |
214 | assert(link); | |
215 | ||
216 | if (!socket_ipv6_is_supported()) | |
217 | return false; | |
218 | ||
219 | if (link->flags & IFF_LOOPBACK) | |
220 | return false; | |
221 | ||
222 | if (!link->network) | |
223 | return false; | |
224 | ||
225 | if (link->network->ip_forward == _ADDRESS_FAMILY_BOOLEAN_INVALID) | |
226 | return false; | |
227 | ||
228 | if (manager_sysctl_ipv6_enabled(link->manager) == 0) | |
229 | return false; | |
230 | ||
231 | return link->network->ip_forward & ADDRESS_FAMILY_IPV6; | |
232 | } | |
233 | ||
234 | static bool link_proxy_arp_enabled(Link *link) { | |
235 | assert(link); | |
236 | ||
237 | if (link->flags & IFF_LOOPBACK) | |
238 | return false; | |
239 | ||
240 | if (!link->network) | |
241 | return false; | |
242 | ||
243 | if (link->network->proxy_arp < 0) | |
244 | return false; | |
245 | ||
246 | return true; | |
247 | } | |
248 | ||
249 | static bool link_ipv6_accept_ra_enabled(Link *link) { | |
250 | assert(link); | |
251 | ||
252 | if (!socket_ipv6_is_supported()) | |
253 | return false; | |
254 | ||
255 | if (link->flags & IFF_LOOPBACK) | |
256 | return false; | |
257 | ||
258 | if (!link->network) | |
259 | return false; | |
260 | ||
261 | if (!link_ipv6ll_enabled(link)) | |
262 | return false; | |
263 | ||
264 | /* If unset use system default (enabled if local forwarding is disabled. | |
265 | * disabled if local forwarding is enabled). | |
266 | * If set, ignore or enforce RA independent of local forwarding state. | |
267 | */ | |
268 | if (link->network->ipv6_accept_ra < 0) | |
269 | /* default to accept RA if ip_forward is disabled and ignore RA if ip_forward is enabled */ | |
270 | return !link_ipv6_forward_enabled(link); | |
271 | else if (link->network->ipv6_accept_ra > 0) | |
272 | /* accept RA even if ip_forward is enabled */ | |
273 | return true; | |
274 | else | |
275 | /* ignore RA */ | |
276 | return false; | |
277 | } | |
278 | ||
279 | static IPv6PrivacyExtensions link_ipv6_privacy_extensions(Link *link) { | |
280 | assert(link); | |
281 | ||
282 | if (!socket_ipv6_is_supported()) | |
283 | return _IPV6_PRIVACY_EXTENSIONS_INVALID; | |
284 | ||
285 | if (link->flags & IFF_LOOPBACK) | |
286 | return _IPV6_PRIVACY_EXTENSIONS_INVALID; | |
287 | ||
288 | if (!link->network) | |
289 | return _IPV6_PRIVACY_EXTENSIONS_INVALID; | |
290 | ||
291 | return link->network->ipv6_privacy_extensions; | |
292 | } | |
293 | ||
294 | static int link_enable_ipv6(Link *link) { | |
295 | bool disabled; | |
296 | int r; | |
297 | ||
298 | if (link->flags & IFF_LOOPBACK) | |
299 | return 0; | |
300 | ||
301 | disabled = !link_ipv6_enabled(link); | |
302 | ||
303 | r = sysctl_write_ip_property_boolean(AF_INET6, link->ifname, "disable_ipv6", disabled); | |
304 | if (r < 0) | |
305 | log_link_warning_errno(link, r, "Cannot %s IPv6: %m", enable_disable(!disabled)); | |
306 | else | |
307 | log_link_info(link, "IPv6 successfully %sd", enable_disable(!disabled)); | |
308 | ||
309 | return 0; | |
310 | } | |
311 | ||
312 | static bool link_is_enslaved(Link *link) { | |
313 | if (link->flags & IFF_SLAVE) | |
314 | /* Even if the link is not managed by networkd, honor IFF_SLAVE flag. */ | |
315 | return true; | |
316 | ||
317 | if (!link->enslaved_raw) | |
318 | return false; | |
319 | ||
320 | if (!link->network) | |
321 | return false; | |
322 | ||
323 | if (link->network->bridge) | |
324 | /* TODO: support the case when link is not managed by networkd. */ | |
325 | return true; | |
326 | ||
327 | return false; | |
328 | } | |
329 | ||
330 | static void link_update_master_operstate(Link *link, NetDev *netdev) { | |
331 | Link *master; | |
332 | ||
333 | if (!netdev) | |
334 | return; | |
335 | ||
336 | if (link_get(link->manager, netdev->ifindex, &master) < 0) | |
337 | return; | |
338 | ||
339 | link_update_operstate(master, true); | |
340 | } | |
341 | ||
342 | void link_update_operstate(Link *link, bool also_update_master) { | |
343 | LinkOperationalState operstate; | |
344 | Iterator i; | |
345 | ||
346 | assert(link); | |
347 | ||
348 | if (link->kernel_operstate == IF_OPER_DORMANT) | |
349 | operstate = LINK_OPERSTATE_DORMANT; | |
350 | else if (link_has_carrier(link)) { | |
351 | Address *address; | |
352 | uint8_t scope = RT_SCOPE_NOWHERE; | |
353 | ||
354 | /* if we have carrier, check what addresses we have */ | |
355 | SET_FOREACH(address, link->addresses, i) { | |
356 | if (!address_is_ready(address)) | |
357 | continue; | |
358 | ||
359 | if (address->scope < scope) | |
360 | scope = address->scope; | |
361 | } | |
362 | ||
363 | /* for operstate we also take foreign addresses into account */ | |
364 | SET_FOREACH(address, link->addresses_foreign, i) { | |
365 | if (!address_is_ready(address)) | |
366 | continue; | |
367 | ||
368 | if (address->scope < scope) | |
369 | scope = address->scope; | |
370 | } | |
371 | ||
372 | if (scope < RT_SCOPE_SITE) | |
373 | /* universally accessible addresses found */ | |
374 | operstate = LINK_OPERSTATE_ROUTABLE; | |
375 | else if (scope < RT_SCOPE_HOST) | |
376 | /* only link or site local addresses found */ | |
377 | operstate = LINK_OPERSTATE_DEGRADED; | |
378 | else | |
379 | /* no useful addresses found */ | |
380 | operstate = LINK_OPERSTATE_CARRIER; | |
381 | } else if (link->flags & IFF_UP) | |
382 | operstate = LINK_OPERSTATE_NO_CARRIER; | |
383 | else | |
384 | operstate = LINK_OPERSTATE_OFF; | |
385 | ||
386 | if (IN_SET(operstate, LINK_OPERSTATE_DEGRADED, LINK_OPERSTATE_CARRIER) && | |
387 | link_is_enslaved(link)) | |
388 | operstate = LINK_OPERSTATE_ENSLAVED; | |
389 | ||
390 | if (operstate >= LINK_OPERSTATE_CARRIER) { | |
391 | Link *slave; | |
392 | ||
393 | SET_FOREACH(slave, link->slaves, i) { | |
394 | link_update_operstate(slave, false); | |
395 | ||
396 | if (slave->operstate < LINK_OPERSTATE_CARRIER) | |
397 | operstate = LINK_OPERSTATE_DEGRADED_CARRIER; | |
398 | } | |
399 | } | |
400 | ||
401 | if (link->operstate != operstate) { | |
402 | link->operstate = operstate; | |
403 | link_send_changed(link, "OperationalState", NULL); | |
404 | link_dirty(link); | |
405 | } | |
406 | ||
407 | if (also_update_master && link->network) { | |
408 | link_update_master_operstate(link, link->network->bond); | |
409 | link_update_master_operstate(link, link->network->bridge); | |
410 | } | |
411 | } | |
412 | ||
413 | #define FLAG_STRING(string, flag, old, new) \ | |
414 | (((old ^ new) & flag) \ | |
415 | ? ((old & flag) ? (" -" string) : (" +" string)) \ | |
416 | : "") | |
417 | ||
418 | static int link_update_flags(Link *link, sd_netlink_message *m) { | |
419 | unsigned flags, unknown_flags_added, unknown_flags_removed, unknown_flags; | |
420 | uint8_t operstate; | |
421 | int r; | |
422 | ||
423 | assert(link); | |
424 | ||
425 | r = sd_rtnl_message_link_get_flags(m, &flags); | |
426 | if (r < 0) | |
427 | return log_link_warning_errno(link, r, "Could not get link flags: %m"); | |
428 | ||
429 | r = sd_netlink_message_read_u8(m, IFLA_OPERSTATE, &operstate); | |
430 | if (r < 0) | |
431 | /* if we got a message without operstate, take it to mean | |
432 | the state was unchanged */ | |
433 | operstate = link->kernel_operstate; | |
434 | ||
435 | if ((link->flags == flags) && (link->kernel_operstate == operstate)) | |
436 | return 0; | |
437 | ||
438 | if (link->flags != flags) { | |
439 | log_link_debug(link, "Flags change:%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s", | |
440 | FLAG_STRING("LOOPBACK", IFF_LOOPBACK, link->flags, flags), | |
441 | FLAG_STRING("MASTER", IFF_MASTER, link->flags, flags), | |
442 | FLAG_STRING("SLAVE", IFF_SLAVE, link->flags, flags), | |
443 | FLAG_STRING("UP", IFF_UP, link->flags, flags), | |
444 | FLAG_STRING("DORMANT", IFF_DORMANT, link->flags, flags), | |
445 | FLAG_STRING("LOWER_UP", IFF_LOWER_UP, link->flags, flags), | |
446 | FLAG_STRING("RUNNING", IFF_RUNNING, link->flags, flags), | |
447 | FLAG_STRING("MULTICAST", IFF_MULTICAST, link->flags, flags), | |
448 | FLAG_STRING("BROADCAST", IFF_BROADCAST, link->flags, flags), | |
449 | FLAG_STRING("POINTOPOINT", IFF_POINTOPOINT, link->flags, flags), | |
450 | FLAG_STRING("PROMISC", IFF_PROMISC, link->flags, flags), | |
451 | FLAG_STRING("ALLMULTI", IFF_ALLMULTI, link->flags, flags), | |
452 | FLAG_STRING("PORTSEL", IFF_PORTSEL, link->flags, flags), | |
453 | FLAG_STRING("AUTOMEDIA", IFF_AUTOMEDIA, link->flags, flags), | |
454 | FLAG_STRING("DYNAMIC", IFF_DYNAMIC, link->flags, flags), | |
455 | FLAG_STRING("NOARP", IFF_NOARP, link->flags, flags), | |
456 | FLAG_STRING("NOTRAILERS", IFF_NOTRAILERS, link->flags, flags), | |
457 | FLAG_STRING("DEBUG", IFF_DEBUG, link->flags, flags), | |
458 | FLAG_STRING("ECHO", IFF_ECHO, link->flags, flags)); | |
459 | ||
460 | unknown_flags = ~(IFF_LOOPBACK | IFF_MASTER | IFF_SLAVE | IFF_UP | | |
461 | IFF_DORMANT | IFF_LOWER_UP | IFF_RUNNING | | |
462 | IFF_MULTICAST | IFF_BROADCAST | IFF_POINTOPOINT | | |
463 | IFF_PROMISC | IFF_ALLMULTI | IFF_PORTSEL | | |
464 | IFF_AUTOMEDIA | IFF_DYNAMIC | IFF_NOARP | | |
465 | IFF_NOTRAILERS | IFF_DEBUG | IFF_ECHO); | |
466 | unknown_flags_added = ((link->flags ^ flags) & flags & unknown_flags); | |
467 | unknown_flags_removed = ((link->flags ^ flags) & link->flags & unknown_flags); | |
468 | ||
469 | /* link flags are currently at most 18 bits, let's align to | |
470 | * printing 20 */ | |
471 | if (unknown_flags_added) | |
472 | log_link_debug(link, | |
473 | "Unknown link flags gained: %#.5x (ignoring)", | |
474 | unknown_flags_added); | |
475 | ||
476 | if (unknown_flags_removed) | |
477 | log_link_debug(link, | |
478 | "Unknown link flags lost: %#.5x (ignoring)", | |
479 | unknown_flags_removed); | |
480 | } | |
481 | ||
482 | link->flags = flags; | |
483 | link->kernel_operstate = operstate; | |
484 | ||
485 | link_update_operstate(link, true); | |
486 | ||
487 | return 0; | |
488 | } | |
489 | ||
490 | static int link_new(Manager *manager, sd_netlink_message *message, Link **ret) { | |
491 | _cleanup_(link_unrefp) Link *link = NULL; | |
492 | uint16_t type; | |
493 | const char *ifname, *kind = NULL; | |
494 | int r, ifindex; | |
495 | unsigned short iftype; | |
496 | ||
497 | assert(manager); | |
498 | assert(message); | |
499 | assert(ret); | |
500 | ||
501 | /* check for link kind */ | |
502 | r = sd_netlink_message_enter_container(message, IFLA_LINKINFO); | |
503 | if (r == 0) { | |
504 | (void) sd_netlink_message_read_string(message, IFLA_INFO_KIND, &kind); | |
505 | r = sd_netlink_message_exit_container(message); | |
506 | if (r < 0) | |
507 | return r; | |
508 | } | |
509 | ||
510 | r = sd_netlink_message_get_type(message, &type); | |
511 | if (r < 0) | |
512 | return r; | |
513 | else if (type != RTM_NEWLINK) | |
514 | return -EINVAL; | |
515 | ||
516 | r = sd_rtnl_message_link_get_ifindex(message, &ifindex); | |
517 | if (r < 0) | |
518 | return r; | |
519 | else if (ifindex <= 0) | |
520 | return -EINVAL; | |
521 | ||
522 | r = sd_rtnl_message_link_get_type(message, &iftype); | |
523 | if (r < 0) | |
524 | return r; | |
525 | ||
526 | r = sd_netlink_message_read_string(message, IFLA_IFNAME, &ifname); | |
527 | if (r < 0) | |
528 | return r; | |
529 | ||
530 | link = new(Link, 1); | |
531 | if (!link) | |
532 | return -ENOMEM; | |
533 | ||
534 | *link = (Link) { | |
535 | .n_ref = 1, | |
536 | .manager = manager, | |
537 | .state = LINK_STATE_PENDING, | |
538 | .rtnl_extended_attrs = true, | |
539 | .ifindex = ifindex, | |
540 | .iftype = iftype, | |
541 | }; | |
542 | ||
543 | link->ifname = strdup(ifname); | |
544 | if (!link->ifname) | |
545 | return -ENOMEM; | |
546 | ||
547 | if (kind) { | |
548 | link->kind = strdup(kind); | |
549 | if (!link->kind) | |
550 | return -ENOMEM; | |
551 | } | |
552 | ||
553 | r = sd_netlink_message_read_u32(message, IFLA_MASTER, (uint32_t *)&link->master_ifindex); | |
554 | if (r < 0) | |
555 | log_link_debug_errno(link, r, "New device has no master, continuing without"); | |
556 | ||
557 | r = sd_netlink_message_read_ether_addr(message, IFLA_ADDRESS, &link->mac); | |
558 | if (r < 0) | |
559 | log_link_debug_errno(link, r, "MAC address not found for new device, continuing without"); | |
560 | ||
561 | if (asprintf(&link->state_file, "/run/systemd/netif/links/%d", link->ifindex) < 0) | |
562 | return -ENOMEM; | |
563 | ||
564 | if (asprintf(&link->lease_file, "/run/systemd/netif/leases/%d", link->ifindex) < 0) | |
565 | return -ENOMEM; | |
566 | ||
567 | if (asprintf(&link->lldp_file, "/run/systemd/netif/lldp/%d", link->ifindex) < 0) | |
568 | return -ENOMEM; | |
569 | ||
570 | r = hashmap_ensure_allocated(&manager->links, NULL); | |
571 | if (r < 0) | |
572 | return r; | |
573 | ||
574 | r = hashmap_put(manager->links, INT_TO_PTR(link->ifindex), link); | |
575 | if (r < 0) | |
576 | return r; | |
577 | ||
578 | r = link_update_flags(link, message); | |
579 | if (r < 0) | |
580 | return r; | |
581 | ||
582 | *ret = TAKE_PTR(link); | |
583 | ||
584 | return 0; | |
585 | } | |
586 | ||
587 | static Link *link_free(Link *link) { | |
588 | Address *address; | |
589 | ||
590 | assert(link); | |
591 | ||
592 | link->routes = set_free_with_destructor(link->routes, route_free); | |
593 | link->routes_foreign = set_free_with_destructor(link->routes_foreign, route_free); | |
594 | ||
595 | link->addresses = set_free_with_destructor(link->addresses, address_free); | |
596 | link->addresses_foreign = set_free_with_destructor(link->addresses_foreign, address_free); | |
597 | ||
598 | while ((address = link->pool_addresses)) { | |
599 | LIST_REMOVE(addresses, link->pool_addresses, address); | |
600 | address_free(address); | |
601 | } | |
602 | ||
603 | sd_dhcp_server_unref(link->dhcp_server); | |
604 | sd_dhcp_client_unref(link->dhcp_client); | |
605 | sd_dhcp_lease_unref(link->dhcp_lease); | |
606 | ||
607 | link_lldp_emit_stop(link); | |
608 | ||
609 | free(link->lease_file); | |
610 | ||
611 | sd_lldp_unref(link->lldp); | |
612 | free(link->lldp_file); | |
613 | ||
614 | ndisc_flush(link); | |
615 | ||
616 | sd_ipv4ll_unref(link->ipv4ll); | |
617 | sd_dhcp6_client_unref(link->dhcp6_client); | |
618 | sd_ndisc_unref(link->ndisc); | |
619 | sd_radv_unref(link->radv); | |
620 | ||
621 | free(link->ifname); | |
622 | free(link->kind); | |
623 | ||
624 | (void) unlink(link->state_file); | |
625 | free(link->state_file); | |
626 | ||
627 | sd_device_unref(link->sd_device); | |
628 | ||
629 | hashmap_free(link->bound_to_links); | |
630 | hashmap_free(link->bound_by_links); | |
631 | ||
632 | set_free_with_destructor(link->slaves, link_unref); | |
633 | ||
634 | network_unref(link->network); | |
635 | ||
636 | return mfree(link); | |
637 | } | |
638 | ||
639 | DEFINE_TRIVIAL_REF_UNREF_FUNC(Link, link, link_free); | |
640 | ||
641 | int link_get(Manager *m, int ifindex, Link **ret) { | |
642 | Link *link; | |
643 | ||
644 | assert(m); | |
645 | assert(ifindex); | |
646 | assert(ret); | |
647 | ||
648 | link = hashmap_get(m->links, INT_TO_PTR(ifindex)); | |
649 | if (!link) | |
650 | return -ENODEV; | |
651 | ||
652 | *ret = link; | |
653 | ||
654 | return 0; | |
655 | } | |
656 | ||
657 | static void link_set_state(Link *link, LinkState state) { | |
658 | assert(link); | |
659 | ||
660 | if (link->state == state) | |
661 | return; | |
662 | ||
663 | log_link_debug(link, "State changed: %s -> %s", | |
664 | link_state_to_string(link->state), | |
665 | link_state_to_string(state)); | |
666 | ||
667 | link->state = state; | |
668 | ||
669 | link_send_changed(link, "AdministrativeState", NULL); | |
670 | } | |
671 | ||
672 | static void link_enter_unmanaged(Link *link) { | |
673 | assert(link); | |
674 | ||
675 | log_link_debug(link, "Unmanaged"); | |
676 | ||
677 | link_set_state(link, LINK_STATE_UNMANAGED); | |
678 | ||
679 | link_dirty(link); | |
680 | } | |
681 | ||
682 | int link_stop_clients(Link *link) { | |
683 | int r = 0, k; | |
684 | ||
685 | assert(link); | |
686 | assert(link->manager); | |
687 | assert(link->manager->event); | |
688 | ||
689 | if (link->dhcp_client) { | |
690 | k = sd_dhcp_client_stop(link->dhcp_client); | |
691 | if (k < 0) | |
692 | r = log_link_warning_errno(link, k, "Could not stop DHCPv4 client: %m"); | |
693 | } | |
694 | ||
695 | if (link->ipv4ll) { | |
696 | k = sd_ipv4ll_stop(link->ipv4ll); | |
697 | if (k < 0) | |
698 | r = log_link_warning_errno(link, k, "Could not stop IPv4 link-local: %m"); | |
699 | } | |
700 | ||
701 | if (link->dhcp6_client) { | |
702 | k = sd_dhcp6_client_stop(link->dhcp6_client); | |
703 | if (k < 0) | |
704 | r = log_link_warning_errno(link, k, "Could not stop DHCPv6 client: %m"); | |
705 | } | |
706 | ||
707 | if (link->ndisc) { | |
708 | k = sd_ndisc_stop(link->ndisc); | |
709 | if (k < 0) | |
710 | r = log_link_warning_errno(link, k, "Could not stop IPv6 Router Discovery: %m"); | |
711 | } | |
712 | ||
713 | if (link->radv) { | |
714 | k = sd_radv_stop(link->radv); | |
715 | if (k < 0) | |
716 | r = log_link_warning_errno(link, k, "Could not stop IPv6 Router Advertisement: %m"); | |
717 | } | |
718 | ||
719 | link_lldp_emit_stop(link); | |
720 | return r; | |
721 | } | |
722 | ||
723 | void link_enter_failed(Link *link) { | |
724 | assert(link); | |
725 | ||
726 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
727 | return; | |
728 | ||
729 | log_link_warning(link, "Failed"); | |
730 | ||
731 | link_set_state(link, LINK_STATE_FAILED); | |
732 | ||
733 | link_stop_clients(link); | |
734 | ||
735 | link_dirty(link); | |
736 | } | |
737 | ||
738 | static Address* link_find_dhcp_server_address(Link *link) { | |
739 | Address *address; | |
740 | ||
741 | assert(link); | |
742 | assert(link->network); | |
743 | ||
744 | /* The first statically configured address if there is any */ | |
745 | LIST_FOREACH(addresses, address, link->network->static_addresses) { | |
746 | ||
747 | if (address->family != AF_INET) | |
748 | continue; | |
749 | ||
750 | if (in_addr_is_null(address->family, &address->in_addr)) | |
751 | continue; | |
752 | ||
753 | return address; | |
754 | } | |
755 | ||
756 | /* If that didn't work, find a suitable address we got from the pool */ | |
757 | LIST_FOREACH(addresses, address, link->pool_addresses) { | |
758 | if (address->family != AF_INET) | |
759 | continue; | |
760 | ||
761 | return address; | |
762 | } | |
763 | ||
764 | return NULL; | |
765 | } | |
766 | ||
767 | static int link_join_netdevs_after_configured(Link *link) { | |
768 | NetDev *netdev; | |
769 | Iterator i; | |
770 | int r; | |
771 | ||
772 | HASHMAP_FOREACH(netdev, link->network->stacked_netdevs, i) { | |
773 | if (netdev->ifindex > 0) | |
774 | /* Assume already enslaved. */ | |
775 | continue; | |
776 | ||
777 | if (netdev_get_create_type(netdev) != NETDEV_CREATE_AFTER_CONFIGURED) | |
778 | continue; | |
779 | ||
780 | log_struct(LOG_DEBUG, | |
781 | LOG_LINK_INTERFACE(link), | |
782 | LOG_NETDEV_INTERFACE(netdev), | |
783 | LOG_LINK_MESSAGE(link, "Enslaving by '%s'", netdev->ifname)); | |
784 | ||
785 | r = netdev_join(netdev, link, NULL); | |
786 | if (r < 0) | |
787 | return log_struct_errno(LOG_WARNING, r, | |
788 | LOG_LINK_INTERFACE(link), | |
789 | LOG_NETDEV_INTERFACE(netdev), | |
790 | LOG_LINK_MESSAGE(link, "Could not join netdev '%s': %m", netdev->ifname)); | |
791 | } | |
792 | ||
793 | return 0; | |
794 | } | |
795 | ||
796 | static void link_enter_configured(Link *link) { | |
797 | assert(link); | |
798 | assert(link->network); | |
799 | ||
800 | if (link->state != LINK_STATE_CONFIGURING) | |
801 | return; | |
802 | ||
803 | log_link_info(link, "Configured"); | |
804 | ||
805 | link_set_state(link, LINK_STATE_CONFIGURED); | |
806 | ||
807 | (void) link_join_netdevs_after_configured(link); | |
808 | ||
809 | link_dirty(link); | |
810 | } | |
811 | ||
812 | static int link_request_set_routing_policy_rule(Link *link) { | |
813 | RoutingPolicyRule *rule, *rrule = NULL; | |
814 | int r; | |
815 | ||
816 | assert(link); | |
817 | assert(link->network); | |
818 | ||
819 | link_set_state(link, LINK_STATE_CONFIGURING); | |
820 | link->routing_policy_rules_configured = false; | |
821 | ||
822 | LIST_FOREACH(rules, rule, link->network->rules) { | |
823 | r = routing_policy_rule_get(link->manager, rule->family, &rule->from, rule->from_prefixlen, &rule->to, | |
824 | rule->to_prefixlen, rule->tos, rule->fwmark, rule->table, rule->iif, rule->oif, | |
825 | rule->protocol, &rule->sport, &rule->dport, &rrule); | |
826 | if (r == 0) { | |
827 | (void) routing_policy_rule_make_local(link->manager, rrule); | |
828 | continue; | |
829 | } | |
830 | ||
831 | r = routing_policy_rule_configure(rule, link, NULL, false); | |
832 | if (r < 0) { | |
833 | log_link_warning_errno(link, r, "Could not set routing policy rules: %m"); | |
834 | link_enter_failed(link); | |
835 | return r; | |
836 | } | |
837 | ||
838 | link->routing_policy_rule_messages++; | |
839 | } | |
840 | ||
841 | routing_policy_rule_purge(link->manager, link); | |
842 | if (link->routing_policy_rule_messages == 0) { | |
843 | link->routing_policy_rules_configured = true; | |
844 | link_check_ready(link); | |
845 | } else | |
846 | log_link_debug(link, "Setting routing policy rules"); | |
847 | ||
848 | return 0; | |
849 | } | |
850 | ||
851 | static int route_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
852 | int r; | |
853 | ||
854 | assert(link); | |
855 | assert(link->route_messages > 0); | |
856 | assert(IN_SET(link->state, LINK_STATE_CONFIGURING, | |
857 | LINK_STATE_FAILED, LINK_STATE_LINGER)); | |
858 | ||
859 | link->route_messages--; | |
860 | ||
861 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
862 | return 1; | |
863 | ||
864 | r = sd_netlink_message_get_errno(m); | |
865 | if (r < 0 && r != -EEXIST) | |
866 | log_link_warning_errno(link, r, "Could not set route: %m"); | |
867 | ||
868 | if (link->route_messages == 0) { | |
869 | log_link_debug(link, "Routes set"); | |
870 | link->static_routes_configured = true; | |
871 | link_check_ready(link); | |
872 | } | |
873 | ||
874 | return 1; | |
875 | } | |
876 | ||
877 | int link_request_set_routes(Link *link) { | |
878 | enum { | |
879 | PHASE_NON_GATEWAY, /* First phase: Routes without a gateway */ | |
880 | PHASE_GATEWAY, /* Second phase: Routes with a gateway */ | |
881 | _PHASE_MAX | |
882 | } phase; | |
883 | Route *rt; | |
884 | int r; | |
885 | ||
886 | assert(link); | |
887 | assert(link->network); | |
888 | assert(link->addresses_configured); | |
889 | assert(link->address_messages == 0); | |
890 | assert(link->state != _LINK_STATE_INVALID); | |
891 | ||
892 | link_set_state(link, LINK_STATE_CONFIGURING); | |
893 | link->static_routes_configured = false; | |
894 | ||
895 | r = link_request_set_routing_policy_rule(link); | |
896 | if (r < 0) | |
897 | return r; | |
898 | ||
899 | /* First add the routes that enable us to talk to gateways, then add in the others that need a gateway. */ | |
900 | for (phase = 0; phase < _PHASE_MAX; phase++) | |
901 | LIST_FOREACH(routes, rt, link->network->static_routes) { | |
902 | ||
903 | if (in_addr_is_null(rt->family, &rt->gw) != (phase == PHASE_NON_GATEWAY)) | |
904 | continue; | |
905 | ||
906 | r = route_configure(rt, link, route_handler); | |
907 | if (r < 0) { | |
908 | log_link_warning_errno(link, r, "Could not set routes: %m"); | |
909 | link_enter_failed(link); | |
910 | return r; | |
911 | } | |
912 | ||
913 | link->route_messages++; | |
914 | } | |
915 | ||
916 | if (link->route_messages == 0) { | |
917 | link->static_routes_configured = true; | |
918 | link_check_ready(link); | |
919 | } else | |
920 | log_link_debug(link, "Setting routes"); | |
921 | ||
922 | return 0; | |
923 | } | |
924 | ||
925 | void link_check_ready(Link *link) { | |
926 | Address *a; | |
927 | Iterator i; | |
928 | ||
929 | assert(link); | |
930 | ||
931 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
932 | return; | |
933 | ||
934 | if (!link->network) | |
935 | return; | |
936 | ||
937 | if (!link->addresses_configured) | |
938 | return; | |
939 | ||
940 | if (!link->neighbors_configured) | |
941 | return; | |
942 | ||
943 | SET_FOREACH(a, link->addresses, i) | |
944 | if (!address_is_ready(a)) | |
945 | return; | |
946 | ||
947 | if (!link->addresses_ready) { | |
948 | link->addresses_ready = true; | |
949 | link_request_set_routes(link); | |
950 | } | |
951 | ||
952 | if (!link->static_routes_configured) | |
953 | return; | |
954 | ||
955 | if (!link->routing_policy_rules_configured) | |
956 | return; | |
957 | ||
958 | if (link_ipv4ll_enabled(link) && !(link->ipv4ll_address && link->ipv4ll_route)) | |
959 | return; | |
960 | ||
961 | if (link_ipv6ll_enabled(link) && | |
962 | in_addr_is_null(AF_INET6, (const union in_addr_union*) &link->ipv6ll_address)) | |
963 | return; | |
964 | ||
965 | if ((link_dhcp4_enabled(link) || link_dhcp6_enabled(link)) && | |
966 | !(link->dhcp4_configured || link->dhcp6_configured) && | |
967 | !(link_ipv4ll_fallback_enabled(link) && link->ipv4ll_address && link->ipv4ll_route)) | |
968 | /* When DHCP is enabled, at least one protocol must provide an address, or | |
969 | * an IPv4ll fallback address must be configured. */ | |
970 | return; | |
971 | ||
972 | if (link_ipv6_accept_ra_enabled(link) && !link->ndisc_configured) | |
973 | return; | |
974 | ||
975 | if (link->state != LINK_STATE_CONFIGURED) | |
976 | link_enter_configured(link); | |
977 | ||
978 | return; | |
979 | } | |
980 | ||
981 | static int link_request_set_neighbors(Link *link) { | |
982 | Neighbor *neighbor; | |
983 | int r; | |
984 | ||
985 | assert(link); | |
986 | assert(link->network); | |
987 | assert(link->state != _LINK_STATE_INVALID); | |
988 | ||
989 | link_set_state(link, LINK_STATE_CONFIGURING); | |
990 | link->neighbors_configured = false; | |
991 | ||
992 | LIST_FOREACH(neighbors, neighbor, link->network->neighbors) { | |
993 | r = neighbor_configure(neighbor, link, NULL); | |
994 | if (r < 0) { | |
995 | log_link_warning_errno(link, r, "Could not set neighbor: %m"); | |
996 | link_enter_failed(link); | |
997 | return r; | |
998 | } | |
999 | } | |
1000 | ||
1001 | if (link->neighbor_messages == 0) { | |
1002 | link->neighbors_configured = true; | |
1003 | link_check_ready(link); | |
1004 | } else | |
1005 | log_link_debug(link, "Setting neighbors"); | |
1006 | ||
1007 | return 0; | |
1008 | } | |
1009 | ||
1010 | static int address_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1011 | int r; | |
1012 | ||
1013 | assert(rtnl); | |
1014 | assert(m); | |
1015 | assert(link); | |
1016 | assert(link->ifname); | |
1017 | assert(link->address_messages > 0); | |
1018 | assert(IN_SET(link->state, LINK_STATE_CONFIGURING, | |
1019 | LINK_STATE_FAILED, LINK_STATE_LINGER)); | |
1020 | ||
1021 | link->address_messages--; | |
1022 | ||
1023 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1024 | return 1; | |
1025 | ||
1026 | r = sd_netlink_message_get_errno(m); | |
1027 | if (r < 0 && r != -EEXIST) | |
1028 | log_link_warning_errno(link, r, "could not set address: %m"); | |
1029 | else if (r >= 0) | |
1030 | manager_rtnl_process_address(rtnl, m, link->manager); | |
1031 | ||
1032 | if (link->address_messages == 0) { | |
1033 | log_link_debug(link, "Addresses set"); | |
1034 | link->addresses_configured = true; | |
1035 | link_check_ready(link); | |
1036 | } | |
1037 | ||
1038 | return 1; | |
1039 | } | |
1040 | ||
1041 | static int link_push_uplink_dns_to_dhcp_server(Link *link, sd_dhcp_server *s) { | |
1042 | _cleanup_free_ struct in_addr *addresses = NULL; | |
1043 | size_t n_addresses = 0, n_allocated = 0; | |
1044 | unsigned i; | |
1045 | ||
1046 | log_debug("Copying DNS server information from %s", link->ifname); | |
1047 | ||
1048 | if (!link->network) | |
1049 | return 0; | |
1050 | ||
1051 | for (i = 0; i < link->network->n_dns; i++) { | |
1052 | struct in_addr ia; | |
1053 | ||
1054 | /* Only look for IPv4 addresses */ | |
1055 | if (link->network->dns[i].family != AF_INET) | |
1056 | continue; | |
1057 | ||
1058 | ia = link->network->dns[i].address.in; | |
1059 | ||
1060 | /* Never propagate obviously borked data */ | |
1061 | if (in4_addr_is_null(&ia) || in4_addr_is_localhost(&ia)) | |
1062 | continue; | |
1063 | ||
1064 | if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + 1)) | |
1065 | return log_oom(); | |
1066 | ||
1067 | addresses[n_addresses++] = ia; | |
1068 | } | |
1069 | ||
1070 | if (link->network->dhcp_use_dns && link->dhcp_lease) { | |
1071 | const struct in_addr *da = NULL; | |
1072 | int j, n; | |
1073 | ||
1074 | n = sd_dhcp_lease_get_dns(link->dhcp_lease, &da); | |
1075 | if (n > 0) { | |
1076 | ||
1077 | if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + n)) | |
1078 | return log_oom(); | |
1079 | ||
1080 | for (j = 0; j < n; j++) | |
1081 | if (in4_addr_is_non_local(&da[j])) | |
1082 | addresses[n_addresses++] = da[j]; | |
1083 | } | |
1084 | } | |
1085 | ||
1086 | if (n_addresses <= 0) | |
1087 | return 0; | |
1088 | ||
1089 | return sd_dhcp_server_set_dns(s, addresses, n_addresses); | |
1090 | } | |
1091 | ||
1092 | static int link_push_uplink_ntp_to_dhcp_server(Link *link, sd_dhcp_server *s) { | |
1093 | _cleanup_free_ struct in_addr *addresses = NULL; | |
1094 | size_t n_addresses = 0, n_allocated = 0; | |
1095 | char **a; | |
1096 | ||
1097 | if (!link->network) | |
1098 | return 0; | |
1099 | ||
1100 | log_debug("Copying NTP server information from %s", link->ifname); | |
1101 | ||
1102 | STRV_FOREACH(a, link->network->ntp) { | |
1103 | union in_addr_union ia; | |
1104 | ||
1105 | /* Only look for IPv4 addresses */ | |
1106 | if (in_addr_from_string(AF_INET, *a, &ia) <= 0) | |
1107 | continue; | |
1108 | ||
1109 | /* Never propagate obviously borked data */ | |
1110 | if (in4_addr_is_null(&ia.in) || in4_addr_is_localhost(&ia.in)) | |
1111 | continue; | |
1112 | ||
1113 | if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + 1)) | |
1114 | return log_oom(); | |
1115 | ||
1116 | addresses[n_addresses++] = ia.in; | |
1117 | } | |
1118 | ||
1119 | if (link->network->dhcp_use_ntp && link->dhcp_lease) { | |
1120 | const struct in_addr *da = NULL; | |
1121 | int j, n; | |
1122 | ||
1123 | n = sd_dhcp_lease_get_ntp(link->dhcp_lease, &da); | |
1124 | if (n > 0) { | |
1125 | ||
1126 | if (!GREEDY_REALLOC(addresses, n_allocated, n_addresses + n)) | |
1127 | return log_oom(); | |
1128 | ||
1129 | for (j = 0; j < n; j++) | |
1130 | if (in4_addr_is_non_local(&da[j])) | |
1131 | addresses[n_addresses++] = da[j]; | |
1132 | } | |
1133 | } | |
1134 | ||
1135 | if (n_addresses <= 0) | |
1136 | return 0; | |
1137 | ||
1138 | return sd_dhcp_server_set_ntp(s, addresses, n_addresses); | |
1139 | } | |
1140 | ||
1141 | static int link_set_bridge_fdb(Link *link) { | |
1142 | FdbEntry *fdb_entry; | |
1143 | int r; | |
1144 | ||
1145 | LIST_FOREACH(static_fdb_entries, fdb_entry, link->network->static_fdb_entries) { | |
1146 | r = fdb_entry_configure(link, fdb_entry); | |
1147 | if (r < 0) | |
1148 | return log_link_error_errno(link, r, "Failed to add MAC entry to static MAC table: %m"); | |
1149 | } | |
1150 | ||
1151 | return 0; | |
1152 | } | |
1153 | ||
1154 | static int link_request_set_addresses(Link *link) { | |
1155 | AddressLabel *label; | |
1156 | Address *ad; | |
1157 | int r; | |
1158 | ||
1159 | assert(link); | |
1160 | assert(link->network); | |
1161 | assert(link->state != _LINK_STATE_INVALID); | |
1162 | ||
1163 | link_set_state(link, LINK_STATE_CONFIGURING); | |
1164 | ||
1165 | /* Reset all *_configured flags we are configuring. */ | |
1166 | link->addresses_configured = false; | |
1167 | link->addresses_ready = false; | |
1168 | link->neighbors_configured = false; | |
1169 | link->static_routes_configured = false; | |
1170 | link->routing_policy_rules_configured = false; | |
1171 | ||
1172 | r = link_set_bridge_fdb(link); | |
1173 | if (r < 0) | |
1174 | return r; | |
1175 | ||
1176 | r = link_request_set_neighbors(link); | |
1177 | if (r < 0) | |
1178 | return r; | |
1179 | ||
1180 | LIST_FOREACH(addresses, ad, link->network->static_addresses) { | |
1181 | bool update; | |
1182 | ||
1183 | update = address_get(link, ad->family, &ad->in_addr, ad->prefixlen, NULL) > 0; | |
1184 | ||
1185 | r = address_configure(ad, link, address_handler, update); | |
1186 | if (r < 0) { | |
1187 | log_link_warning_errno(link, r, "Could not set addresses: %m"); | |
1188 | link_enter_failed(link); | |
1189 | return r; | |
1190 | } | |
1191 | ||
1192 | link->address_messages++; | |
1193 | } | |
1194 | ||
1195 | LIST_FOREACH(labels, label, link->network->address_labels) { | |
1196 | r = address_label_configure(label, link, NULL, false); | |
1197 | if (r < 0) { | |
1198 | log_link_warning_errno(link, r, "Could not set address label: %m"); | |
1199 | link_enter_failed(link); | |
1200 | return r; | |
1201 | } | |
1202 | ||
1203 | link->address_label_messages++; | |
1204 | } | |
1205 | ||
1206 | /* now that we can figure out a default address for the dhcp server, | |
1207 | start it */ | |
1208 | if (link_dhcp4_server_enabled(link) && (link->flags & IFF_UP)) { | |
1209 | Address *address; | |
1210 | Link *uplink = NULL; | |
1211 | bool acquired_uplink = false; | |
1212 | ||
1213 | address = link_find_dhcp_server_address(link); | |
1214 | if (!address) { | |
1215 | log_link_warning(link, "Failed to find suitable address for DHCPv4 server instance."); | |
1216 | link_enter_failed(link); | |
1217 | return 0; | |
1218 | } | |
1219 | ||
1220 | /* use the server address' subnet as the pool */ | |
1221 | r = sd_dhcp_server_configure_pool(link->dhcp_server, &address->in_addr.in, address->prefixlen, | |
1222 | link->network->dhcp_server_pool_offset, link->network->dhcp_server_pool_size); | |
1223 | if (r < 0) | |
1224 | return r; | |
1225 | ||
1226 | /* TODO: | |
1227 | r = sd_dhcp_server_set_router(link->dhcp_server, | |
1228 | &main_address->in_addr.in); | |
1229 | if (r < 0) | |
1230 | return r; | |
1231 | */ | |
1232 | ||
1233 | if (link->network->dhcp_server_max_lease_time_usec > 0) { | |
1234 | r = sd_dhcp_server_set_max_lease_time( | |
1235 | link->dhcp_server, | |
1236 | DIV_ROUND_UP(link->network->dhcp_server_max_lease_time_usec, USEC_PER_SEC)); | |
1237 | if (r < 0) | |
1238 | return r; | |
1239 | } | |
1240 | ||
1241 | if (link->network->dhcp_server_default_lease_time_usec > 0) { | |
1242 | r = sd_dhcp_server_set_default_lease_time( | |
1243 | link->dhcp_server, | |
1244 | DIV_ROUND_UP(link->network->dhcp_server_default_lease_time_usec, USEC_PER_SEC)); | |
1245 | if (r < 0) | |
1246 | return r; | |
1247 | } | |
1248 | ||
1249 | if (link->network->dhcp_server_emit_dns) { | |
1250 | ||
1251 | if (link->network->n_dhcp_server_dns > 0) | |
1252 | r = sd_dhcp_server_set_dns(link->dhcp_server, link->network->dhcp_server_dns, link->network->n_dhcp_server_dns); | |
1253 | else { | |
1254 | uplink = manager_find_uplink(link->manager, link); | |
1255 | acquired_uplink = true; | |
1256 | ||
1257 | if (!uplink) { | |
1258 | log_link_debug(link, "Not emitting DNS server information on link, couldn't find suitable uplink."); | |
1259 | r = 0; | |
1260 | } else | |
1261 | r = link_push_uplink_dns_to_dhcp_server(uplink, link->dhcp_server); | |
1262 | } | |
1263 | if (r < 0) | |
1264 | log_link_warning_errno(link, r, "Failed to set DNS server for DHCP server, ignoring: %m"); | |
1265 | } | |
1266 | ||
1267 | if (link->network->dhcp_server_emit_ntp) { | |
1268 | ||
1269 | if (link->network->n_dhcp_server_ntp > 0) | |
1270 | r = sd_dhcp_server_set_ntp(link->dhcp_server, link->network->dhcp_server_ntp, link->network->n_dhcp_server_ntp); | |
1271 | else { | |
1272 | if (!acquired_uplink) | |
1273 | uplink = manager_find_uplink(link->manager, link); | |
1274 | ||
1275 | if (!uplink) { | |
1276 | log_link_debug(link, "Not emitting NTP server information on link, couldn't find suitable uplink."); | |
1277 | r = 0; | |
1278 | } else | |
1279 | r = link_push_uplink_ntp_to_dhcp_server(uplink, link->dhcp_server); | |
1280 | ||
1281 | } | |
1282 | if (r < 0) | |
1283 | log_link_warning_errno(link, r, "Failed to set NTP server for DHCP server, ignoring: %m"); | |
1284 | } | |
1285 | ||
1286 | r = sd_dhcp_server_set_emit_router(link->dhcp_server, link->network->dhcp_server_emit_router); | |
1287 | if (r < 0) | |
1288 | return log_link_warning_errno(link, r, "Failed to set router emission for DHCP server: %m"); | |
1289 | ||
1290 | if (link->network->dhcp_server_emit_timezone) { | |
1291 | _cleanup_free_ char *buffer = NULL; | |
1292 | const char *tz = NULL; | |
1293 | ||
1294 | if (link->network->dhcp_server_timezone) | |
1295 | tz = link->network->dhcp_server_timezone; | |
1296 | else { | |
1297 | r = get_timezone(&buffer); | |
1298 | if (r < 0) | |
1299 | log_warning_errno(r, "Failed to determine timezone: %m"); | |
1300 | else | |
1301 | tz = buffer; | |
1302 | } | |
1303 | ||
1304 | if (tz) { | |
1305 | r = sd_dhcp_server_set_timezone(link->dhcp_server, tz); | |
1306 | if (r < 0) | |
1307 | return r; | |
1308 | } | |
1309 | } | |
1310 | if (!sd_dhcp_server_is_running(link->dhcp_server)) { | |
1311 | r = sd_dhcp_server_start(link->dhcp_server); | |
1312 | if (r < 0) { | |
1313 | log_link_warning_errno(link, r, "Could not start DHCPv4 server instance: %m"); | |
1314 | ||
1315 | link_enter_failed(link); | |
1316 | ||
1317 | return 0; | |
1318 | } | |
1319 | } | |
1320 | ||
1321 | log_link_debug(link, "Offering DHCPv4 leases"); | |
1322 | } | |
1323 | ||
1324 | if (link->address_messages == 0) { | |
1325 | link->addresses_configured = true; | |
1326 | link_check_ready(link); | |
1327 | } else | |
1328 | log_link_debug(link, "Setting addresses"); | |
1329 | ||
1330 | return 0; | |
1331 | } | |
1332 | ||
1333 | static int link_set_bridge_vlan(Link *link) { | |
1334 | int r = 0; | |
1335 | ||
1336 | r = br_vlan_configure(link, link->network->pvid, link->network->br_vid_bitmap, link->network->br_untagged_bitmap); | |
1337 | if (r < 0) | |
1338 | log_link_error_errno(link, r, "Failed to assign VLANs to bridge port: %m"); | |
1339 | ||
1340 | return r; | |
1341 | } | |
1342 | ||
1343 | static int link_set_proxy_arp(Link *link) { | |
1344 | int r; | |
1345 | ||
1346 | if (!link_proxy_arp_enabled(link)) | |
1347 | return 0; | |
1348 | ||
1349 | r = sysctl_write_ip_property_boolean(AF_INET, link->ifname, "proxy_arp", link->network->proxy_arp > 0); | |
1350 | if (r < 0) | |
1351 | log_link_warning_errno(link, r, "Cannot configure proxy ARP for interface: %m"); | |
1352 | ||
1353 | return 0; | |
1354 | } | |
1355 | ||
1356 | static int link_set_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1357 | int r; | |
1358 | ||
1359 | assert(link); | |
1360 | ||
1361 | log_link_debug(link, "Set link"); | |
1362 | ||
1363 | r = sd_netlink_message_get_errno(m); | |
1364 | if (r < 0 && r != -EEXIST) { | |
1365 | log_link_error_errno(link, r, "Could not join netdev: %m"); | |
1366 | link_enter_failed(link); | |
1367 | } | |
1368 | ||
1369 | return 1; | |
1370 | } | |
1371 | ||
1372 | static int link_configure_after_setting_mtu(Link *link); | |
1373 | ||
1374 | static int set_mtu_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1375 | int r; | |
1376 | ||
1377 | assert(m); | |
1378 | assert(link); | |
1379 | assert(link->ifname); | |
1380 | ||
1381 | link->setting_mtu = false; | |
1382 | ||
1383 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1384 | return 1; | |
1385 | ||
1386 | r = sd_netlink_message_get_errno(m); | |
1387 | if (r < 0) { | |
1388 | log_link_warning_errno(link, r, "Could not set MTU: %m"); | |
1389 | return 1; | |
1390 | } | |
1391 | ||
1392 | log_link_debug(link, "Setting MTU done."); | |
1393 | ||
1394 | if (link->state == LINK_STATE_INITIALIZED) | |
1395 | (void) link_configure_after_setting_mtu(link); | |
1396 | ||
1397 | return 1; | |
1398 | } | |
1399 | ||
1400 | int link_set_mtu(Link *link, uint32_t mtu, bool force) { | |
1401 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1402 | int r; | |
1403 | ||
1404 | assert(link); | |
1405 | assert(link->manager); | |
1406 | assert(link->manager->rtnl); | |
1407 | ||
1408 | if (mtu == 0 || link->setting_mtu) | |
1409 | return 0; | |
1410 | ||
1411 | if (force ? link->mtu == mtu : link->mtu >= mtu) | |
1412 | return 0; | |
1413 | ||
1414 | log_link_debug(link, "Setting MTU: %" PRIu32, mtu); | |
1415 | ||
1416 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_SETLINK, link->ifindex); | |
1417 | if (r < 0) | |
1418 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
1419 | ||
1420 | /* If IPv6 not configured (no static IPv6 address and IPv6LL autoconfiguration is disabled) | |
1421 | * for this interface, then disable IPv6 else enable it. */ | |
1422 | (void) link_enable_ipv6(link); | |
1423 | ||
1424 | /* IPv6 protocol requires a minimum MTU of IPV6_MTU_MIN(1280) bytes | |
1425 | * on the interface. Bump up MTU bytes to IPV6_MTU_MIN. */ | |
1426 | if (link_ipv6_enabled(link) && mtu < IPV6_MIN_MTU) { | |
1427 | ||
1428 | log_link_warning(link, "Bumping MTU to " STRINGIFY(IPV6_MIN_MTU) ", as " | |
1429 | "IPv6 is requested and requires a minimum MTU of " STRINGIFY(IPV6_MIN_MTU) " bytes: %m"); | |
1430 | ||
1431 | mtu = IPV6_MIN_MTU; | |
1432 | } | |
1433 | ||
1434 | r = sd_netlink_message_append_u32(req, IFLA_MTU, mtu); | |
1435 | if (r < 0) | |
1436 | return log_link_error_errno(link, r, "Could not append MTU: %m"); | |
1437 | ||
1438 | r = netlink_call_async(link->manager->rtnl, NULL, req, set_mtu_handler, | |
1439 | link_netlink_destroy_callback, link); | |
1440 | if (r < 0) | |
1441 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
1442 | ||
1443 | link_ref(link); | |
1444 | link->setting_mtu = true; | |
1445 | ||
1446 | return 0; | |
1447 | } | |
1448 | ||
1449 | static int set_flags_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1450 | int r; | |
1451 | ||
1452 | assert(m); | |
1453 | assert(link); | |
1454 | assert(link->ifname); | |
1455 | ||
1456 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1457 | return 1; | |
1458 | ||
1459 | r = sd_netlink_message_get_errno(m); | |
1460 | if (r < 0) | |
1461 | log_link_warning_errno(link, r, "Could not set link flags: %m"); | |
1462 | ||
1463 | return 1; | |
1464 | } | |
1465 | ||
1466 | static int link_set_flags(Link *link) { | |
1467 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1468 | unsigned ifi_change = 0; | |
1469 | unsigned ifi_flags = 0; | |
1470 | int r; | |
1471 | ||
1472 | assert(link); | |
1473 | assert(link->manager); | |
1474 | assert(link->manager->rtnl); | |
1475 | ||
1476 | if (link->flags & IFF_LOOPBACK) | |
1477 | return 0; | |
1478 | ||
1479 | if (!link->network) | |
1480 | return 0; | |
1481 | ||
1482 | if (link->network->arp < 0 && link->network->multicast < 0 && link->network->allmulticast < 0) | |
1483 | return 0; | |
1484 | ||
1485 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_SETLINK, link->ifindex); | |
1486 | if (r < 0) | |
1487 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
1488 | ||
1489 | if (link->network->arp >= 0) { | |
1490 | ifi_change |= IFF_NOARP; | |
1491 | SET_FLAG(ifi_flags, IFF_NOARP, link->network->arp == 0); | |
1492 | } | |
1493 | ||
1494 | if (link->network->multicast >= 0) { | |
1495 | ifi_change |= IFF_MULTICAST; | |
1496 | SET_FLAG(ifi_flags, IFF_MULTICAST, link->network->multicast); | |
1497 | } | |
1498 | ||
1499 | if (link->network->allmulticast >= 0) { | |
1500 | ifi_change |= IFF_ALLMULTI; | |
1501 | SET_FLAG(ifi_flags, IFF_ALLMULTI, link->network->allmulticast); | |
1502 | } | |
1503 | ||
1504 | r = sd_rtnl_message_link_set_flags(req, ifi_flags, ifi_change); | |
1505 | if (r < 0) | |
1506 | return log_link_error_errno(link, r, "Could not set link flags: %m"); | |
1507 | ||
1508 | r = netlink_call_async(link->manager->rtnl, NULL, req, set_flags_handler, | |
1509 | link_netlink_destroy_callback, link); | |
1510 | if (r < 0) | |
1511 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
1512 | ||
1513 | link_ref(link); | |
1514 | ||
1515 | return 0; | |
1516 | } | |
1517 | ||
1518 | static int link_set_bridge(Link *link) { | |
1519 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1520 | int r; | |
1521 | ||
1522 | assert(link); | |
1523 | assert(link->network); | |
1524 | ||
1525 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_SETLINK, link->ifindex); | |
1526 | if (r < 0) | |
1527 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
1528 | ||
1529 | r = sd_rtnl_message_link_set_family(req, PF_BRIDGE); | |
1530 | if (r < 0) | |
1531 | return log_link_error_errno(link, r, "Could not set message family: %m"); | |
1532 | ||
1533 | r = sd_netlink_message_open_container(req, IFLA_PROTINFO); | |
1534 | if (r < 0) | |
1535 | return log_link_error_errno(link, r, "Could not append IFLA_PROTINFO attribute: %m"); | |
1536 | ||
1537 | if (link->network->use_bpdu >= 0) { | |
1538 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_GUARD, link->network->use_bpdu); | |
1539 | if (r < 0) | |
1540 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_GUARD attribute: %m"); | |
1541 | } | |
1542 | ||
1543 | if (link->network->hairpin >= 0) { | |
1544 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MODE, link->network->hairpin); | |
1545 | if (r < 0) | |
1546 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MODE attribute: %m"); | |
1547 | } | |
1548 | ||
1549 | if (link->network->fast_leave >= 0) { | |
1550 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_FAST_LEAVE, link->network->fast_leave); | |
1551 | if (r < 0) | |
1552 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_FAST_LEAVE attribute: %m"); | |
1553 | } | |
1554 | ||
1555 | if (link->network->allow_port_to_be_root >= 0) { | |
1556 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_PROTECT, link->network->allow_port_to_be_root); | |
1557 | if (r < 0) | |
1558 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PROTECT attribute: %m"); | |
1559 | } | |
1560 | ||
1561 | if (link->network->unicast_flood >= 0) { | |
1562 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_UNICAST_FLOOD, link->network->unicast_flood); | |
1563 | if (r < 0) | |
1564 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_UNICAST_FLOOD attribute: %m"); | |
1565 | } | |
1566 | ||
1567 | if (link->network->multicast_flood >= 0) { | |
1568 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MCAST_FLOOD, link->network->multicast_flood); | |
1569 | if (r < 0) | |
1570 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MCAST_FLOOD attribute: %m"); | |
1571 | } | |
1572 | ||
1573 | if (link->network->multicast_to_unicast >= 0) { | |
1574 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MCAST_TO_UCAST, link->network->multicast_to_unicast); | |
1575 | if (r < 0) | |
1576 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MCAST_TO_UCAST attribute: %m"); | |
1577 | } | |
1578 | ||
1579 | if (link->network->neighbor_suppression >= 0) { | |
1580 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_NEIGH_SUPPRESS, link->network->neighbor_suppression); | |
1581 | if (r < 0) | |
1582 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_NEIGH_SUPPRESS attribute: %m"); | |
1583 | } | |
1584 | ||
1585 | if (link->network->learning >= 0) { | |
1586 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_LEARNING, link->network->learning); | |
1587 | if (r < 0) | |
1588 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_LEARNING attribute: %m"); | |
1589 | } | |
1590 | ||
1591 | if (link->network->bridge_proxy_arp >= 0) { | |
1592 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_PROXYARP, link->network->bridge_proxy_arp); | |
1593 | if (r < 0) | |
1594 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PROXYARP attribute: %m"); | |
1595 | } | |
1596 | ||
1597 | if (link->network->bridge_proxy_arp_wifi >= 0) { | |
1598 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_PROXYARP_WIFI, link->network->bridge_proxy_arp_wifi); | |
1599 | if (r < 0) | |
1600 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PROXYARP_WIFI attribute: %m"); | |
1601 | } | |
1602 | ||
1603 | if (link->network->cost != 0) { | |
1604 | r = sd_netlink_message_append_u32(req, IFLA_BRPORT_COST, link->network->cost); | |
1605 | if (r < 0) | |
1606 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_COST attribute: %m"); | |
1607 | } | |
1608 | ||
1609 | if (link->network->priority != LINK_BRIDGE_PORT_PRIORITY_INVALID) { | |
1610 | r = sd_netlink_message_append_u16(req, IFLA_BRPORT_PRIORITY, link->network->priority); | |
1611 | if (r < 0) | |
1612 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_PRIORITY attribute: %m"); | |
1613 | } | |
1614 | ||
1615 | if (link->network->multicast_router != _MULTICAST_ROUTER_INVALID) { | |
1616 | r = sd_netlink_message_append_u8(req, IFLA_BRPORT_MULTICAST_ROUTER, link->network->multicast_router); | |
1617 | if (r < 0) | |
1618 | return log_link_error_errno(link, r, "Could not append IFLA_BRPORT_MULTICAST_ROUTER attribute: %m"); | |
1619 | } | |
1620 | ||
1621 | r = sd_netlink_message_close_container(req); | |
1622 | if (r < 0) | |
1623 | return log_link_error_errno(link, r, "Could not append IFLA_LINKINFO attribute: %m"); | |
1624 | ||
1625 | r = netlink_call_async(link->manager->rtnl, NULL, req, link_set_handler, | |
1626 | link_netlink_destroy_callback, link); | |
1627 | if (r < 0) | |
1628 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
1629 | ||
1630 | link_ref(link); | |
1631 | ||
1632 | return r; | |
1633 | } | |
1634 | ||
1635 | static int link_set_bond_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1636 | int r; | |
1637 | ||
1638 | assert(m); | |
1639 | assert(link); | |
1640 | assert(link->ifname); | |
1641 | ||
1642 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1643 | return 1; | |
1644 | ||
1645 | r = sd_netlink_message_get_errno(m); | |
1646 | if (r < 0) { | |
1647 | log_link_warning_errno(link, r, "Could not set bonding interface: %m"); | |
1648 | return 1; | |
1649 | } | |
1650 | ||
1651 | return 1; | |
1652 | } | |
1653 | ||
1654 | static int link_set_bond(Link *link) { | |
1655 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1656 | int r; | |
1657 | ||
1658 | assert(link); | |
1659 | assert(link->network); | |
1660 | ||
1661 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_NEWLINK, link->network->bond->ifindex); | |
1662 | if (r < 0) | |
1663 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
1664 | ||
1665 | r = sd_netlink_message_set_flags(req, NLM_F_REQUEST | NLM_F_ACK); | |
1666 | if (r < 0) | |
1667 | return log_link_error_errno(link, r, "Could not set netlink flags: %m"); | |
1668 | ||
1669 | r = sd_netlink_message_open_container(req, IFLA_LINKINFO); | |
1670 | if (r < 0) | |
1671 | return log_link_error_errno(link, r, "Could not append IFLA_PROTINFO attribute: %m"); | |
1672 | ||
1673 | r = sd_netlink_message_open_container_union(req, IFLA_INFO_DATA, "bond"); | |
1674 | if (r < 0) | |
1675 | return log_link_error_errno(link, r, "Could not append IFLA_INFO_DATA attribute: %m"); | |
1676 | ||
1677 | if (link->network->active_slave) { | |
1678 | r = sd_netlink_message_append_u32(req, IFLA_BOND_ACTIVE_SLAVE, link->ifindex); | |
1679 | if (r < 0) | |
1680 | return log_link_error_errno(link, r, "Could not append IFLA_BOND_ACTIVE_SLAVE attribute: %m"); | |
1681 | } | |
1682 | ||
1683 | if (link->network->primary_slave) { | |
1684 | r = sd_netlink_message_append_u32(req, IFLA_BOND_PRIMARY, link->ifindex); | |
1685 | if (r < 0) | |
1686 | return log_link_error_errno(link, r, "Could not append IFLA_BOND_PRIMARY attribute: %m"); | |
1687 | } | |
1688 | ||
1689 | r = sd_netlink_message_close_container(req); | |
1690 | if (r < 0) | |
1691 | return log_link_error_errno(link, r, "Could not append IFLA_LINKINFO attribute: %m"); | |
1692 | ||
1693 | r = sd_netlink_message_close_container(req); | |
1694 | if (r < 0) | |
1695 | return log_link_error_errno(link, r, "Could not append IFLA_INFO_DATA attribute: %m"); | |
1696 | ||
1697 | r = netlink_call_async(link->manager->rtnl, NULL, req, link_set_bond_handler, | |
1698 | link_netlink_destroy_callback, link); | |
1699 | if (r < 0) | |
1700 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
1701 | ||
1702 | link_ref(link); | |
1703 | ||
1704 | return r; | |
1705 | } | |
1706 | ||
1707 | static int link_acquire_ipv6_conf(Link *link) { | |
1708 | int r; | |
1709 | ||
1710 | assert(link); | |
1711 | ||
1712 | if (link_ipv6_accept_ra_enabled(link)) { | |
1713 | assert(link->ndisc); | |
1714 | ||
1715 | log_link_debug(link, "Discovering IPv6 routers"); | |
1716 | ||
1717 | r = sd_ndisc_start(link->ndisc); | |
1718 | if (r < 0 && r != -EBUSY) | |
1719 | return log_link_warning_errno(link, r, "Could not start IPv6 Router Discovery: %m"); | |
1720 | } | |
1721 | ||
1722 | if (link_radv_enabled(link)) { | |
1723 | assert(link->radv); | |
1724 | assert(in_addr_is_link_local(AF_INET6, (const union in_addr_union*)&link->ipv6ll_address) > 0); | |
1725 | ||
1726 | log_link_debug(link, "Starting IPv6 Router Advertisements"); | |
1727 | ||
1728 | r = sd_radv_start(link->radv); | |
1729 | if (r < 0 && r != -EBUSY) | |
1730 | return log_link_warning_errno(link, r, "Could not start IPv6 Router Advertisement: %m"); | |
1731 | } | |
1732 | ||
1733 | (void) dhcp6_request_prefix_delegation(link); | |
1734 | ||
1735 | return 0; | |
1736 | } | |
1737 | ||
1738 | static int link_acquire_ipv4_conf(Link *link) { | |
1739 | int r; | |
1740 | ||
1741 | assert(link); | |
1742 | assert(link->manager); | |
1743 | assert(link->manager->event); | |
1744 | ||
1745 | if (link_ipv4ll_enabled(link)) { | |
1746 | assert(link->ipv4ll); | |
1747 | ||
1748 | log_link_debug(link, "Acquiring IPv4 link-local address"); | |
1749 | ||
1750 | r = sd_ipv4ll_start(link->ipv4ll); | |
1751 | if (r < 0) | |
1752 | return log_link_warning_errno(link, r, "Could not acquire IPv4 link-local address: %m"); | |
1753 | } | |
1754 | ||
1755 | if (link_dhcp4_enabled(link)) { | |
1756 | assert(link->dhcp_client); | |
1757 | ||
1758 | log_link_debug(link, "Acquiring DHCPv4 lease"); | |
1759 | ||
1760 | r = sd_dhcp_client_start(link->dhcp_client); | |
1761 | if (r < 0) | |
1762 | return log_link_warning_errno(link, r, "Could not acquire DHCPv4 lease: %m"); | |
1763 | } | |
1764 | ||
1765 | return 0; | |
1766 | } | |
1767 | ||
1768 | static int link_acquire_conf(Link *link) { | |
1769 | int r; | |
1770 | ||
1771 | assert(link); | |
1772 | ||
1773 | r = link_acquire_ipv4_conf(link); | |
1774 | if (r < 0) | |
1775 | return r; | |
1776 | ||
1777 | if (!in_addr_is_null(AF_INET6, (const union in_addr_union*) &link->ipv6ll_address)) { | |
1778 | r = link_acquire_ipv6_conf(link); | |
1779 | if (r < 0) | |
1780 | return r; | |
1781 | } | |
1782 | ||
1783 | if (link_lldp_emit_enabled(link)) { | |
1784 | r = link_lldp_emit_start(link); | |
1785 | if (r < 0) | |
1786 | return log_link_warning_errno(link, r, "Failed to start LLDP transmission: %m"); | |
1787 | } | |
1788 | ||
1789 | return 0; | |
1790 | } | |
1791 | ||
1792 | bool link_has_carrier(Link *link) { | |
1793 | /* see Documentation/networking/operstates.txt in the kernel sources */ | |
1794 | ||
1795 | if (link->kernel_operstate == IF_OPER_UP) | |
1796 | return true; | |
1797 | ||
1798 | if (link->kernel_operstate == IF_OPER_UNKNOWN) | |
1799 | /* operstate may not be implemented, so fall back to flags */ | |
1800 | if ((link->flags & IFF_LOWER_UP) && !(link->flags & IFF_DORMANT)) | |
1801 | return true; | |
1802 | ||
1803 | return false; | |
1804 | } | |
1805 | ||
1806 | static int link_address_genmode_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1807 | int r; | |
1808 | ||
1809 | assert(link); | |
1810 | ||
1811 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1812 | return 1; | |
1813 | ||
1814 | r = sd_netlink_message_get_errno(m); | |
1815 | if (r < 0) | |
1816 | log_link_warning_errno(link, r, "Could not set address genmode for interface: %m"); | |
1817 | ||
1818 | return 1; | |
1819 | } | |
1820 | ||
1821 | static int link_configure_addrgen_mode(Link *link) { | |
1822 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1823 | uint8_t ipv6ll_mode; | |
1824 | int r; | |
1825 | ||
1826 | assert(link); | |
1827 | assert(link->network); | |
1828 | assert(link->manager); | |
1829 | assert(link->manager->rtnl); | |
1830 | ||
1831 | log_link_debug(link, "Setting address genmode for link"); | |
1832 | ||
1833 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_SETLINK, link->ifindex); | |
1834 | if (r < 0) | |
1835 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
1836 | ||
1837 | r = sd_netlink_message_open_container(req, IFLA_AF_SPEC); | |
1838 | if (r < 0) | |
1839 | return log_link_error_errno(link, r, "Could not open IFLA_AF_SPEC container: %m"); | |
1840 | ||
1841 | r = sd_netlink_message_open_container(req, AF_INET6); | |
1842 | if (r < 0) | |
1843 | return log_link_error_errno(link, r, "Could not open AF_INET6 container: %m"); | |
1844 | ||
1845 | if (!link_ipv6ll_enabled(link)) | |
1846 | ipv6ll_mode = IN6_ADDR_GEN_MODE_NONE; | |
1847 | else if (sysctl_read_ip_property(AF_INET6, link->ifname, "stable_secret", NULL) < 0) | |
1848 | /* The file may not exist. And event if it exists, when stable_secret is unset, | |
1849 | * reading the file fails with EIO. */ | |
1850 | ipv6ll_mode = IN6_ADDR_GEN_MODE_EUI64; | |
1851 | else | |
1852 | ipv6ll_mode = IN6_ADDR_GEN_MODE_STABLE_PRIVACY; | |
1853 | ||
1854 | r = sd_netlink_message_append_u8(req, IFLA_INET6_ADDR_GEN_MODE, ipv6ll_mode); | |
1855 | if (r < 0) | |
1856 | return log_link_error_errno(link, r, "Could not append IFLA_INET6_ADDR_GEN_MODE: %m"); | |
1857 | ||
1858 | r = sd_netlink_message_close_container(req); | |
1859 | if (r < 0) | |
1860 | return log_link_error_errno(link, r, "Could not close AF_INET6 container: %m"); | |
1861 | ||
1862 | r = sd_netlink_message_close_container(req); | |
1863 | if (r < 0) | |
1864 | return log_link_error_errno(link, r, "Could not close IFLA_AF_SPEC container: %m"); | |
1865 | ||
1866 | r = netlink_call_async(link->manager->rtnl, NULL, req, link_address_genmode_handler, | |
1867 | link_netlink_destroy_callback, link); | |
1868 | if (r < 0) | |
1869 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
1870 | ||
1871 | link_ref(link); | |
1872 | ||
1873 | return 0; | |
1874 | } | |
1875 | ||
1876 | static int link_up_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1877 | int r; | |
1878 | ||
1879 | assert(link); | |
1880 | ||
1881 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1882 | return 1; | |
1883 | ||
1884 | r = sd_netlink_message_get_errno(m); | |
1885 | if (r < 0) | |
1886 | /* we warn but don't fail the link, as it may be brought up later */ | |
1887 | log_link_warning_errno(link, r, "Could not bring up interface: %m"); | |
1888 | ||
1889 | return 1; | |
1890 | } | |
1891 | ||
1892 | static int link_up(Link *link) { | |
1893 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1894 | int r; | |
1895 | ||
1896 | assert(link); | |
1897 | assert(link->network); | |
1898 | assert(link->manager); | |
1899 | assert(link->manager->rtnl); | |
1900 | ||
1901 | log_link_debug(link, "Bringing link up"); | |
1902 | ||
1903 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_SETLINK, link->ifindex); | |
1904 | if (r < 0) | |
1905 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
1906 | ||
1907 | /* set it free if not enslaved with networkd */ | |
1908 | if (!link->network->bridge && !link->network->bond && !link->network->vrf) { | |
1909 | r = sd_netlink_message_append_u32(req, IFLA_MASTER, 0); | |
1910 | if (r < 0) | |
1911 | return log_link_error_errno(link, r, "Could not append IFLA_MASTER attribute: %m"); | |
1912 | } | |
1913 | ||
1914 | r = sd_rtnl_message_link_set_flags(req, IFF_UP, IFF_UP); | |
1915 | if (r < 0) | |
1916 | return log_link_error_errno(link, r, "Could not set link flags: %m"); | |
1917 | ||
1918 | if (link->network->mac) { | |
1919 | r = sd_netlink_message_append_ether_addr(req, IFLA_ADDRESS, link->network->mac); | |
1920 | if (r < 0) | |
1921 | return log_link_error_errno(link, r, "Could not set MAC address: %m"); | |
1922 | } | |
1923 | ||
1924 | if (link_ipv6_enabled(link)) { | |
1925 | uint8_t ipv6ll_mode; | |
1926 | ||
1927 | r = sd_netlink_message_open_container(req, IFLA_AF_SPEC); | |
1928 | if (r < 0) | |
1929 | return log_link_error_errno(link, r, "Could not open IFLA_AF_SPEC container: %m"); | |
1930 | ||
1931 | /* if the kernel lacks ipv6 support setting IFF_UP fails if any ipv6 options are passed */ | |
1932 | r = sd_netlink_message_open_container(req, AF_INET6); | |
1933 | if (r < 0) | |
1934 | return log_link_error_errno(link, r, "Could not open AF_INET6 container: %m"); | |
1935 | ||
1936 | if (!in_addr_is_null(AF_INET6, &link->network->ipv6_token)) { | |
1937 | r = sd_netlink_message_append_in6_addr(req, IFLA_INET6_TOKEN, &link->network->ipv6_token.in6); | |
1938 | if (r < 0) | |
1939 | return log_link_error_errno(link, r, "Could not append IFLA_INET6_TOKEN: %m"); | |
1940 | } | |
1941 | ||
1942 | if (!link_ipv6ll_enabled(link)) | |
1943 | ipv6ll_mode = IN6_ADDR_GEN_MODE_NONE; | |
1944 | else if (sysctl_read_ip_property(AF_INET6, link->ifname, "stable_secret", NULL) < 0) | |
1945 | /* The file may not exist. And event if it exists, when stable_secret is unset, | |
1946 | * reading the file fails with EIO. */ | |
1947 | ipv6ll_mode = IN6_ADDR_GEN_MODE_EUI64; | |
1948 | else | |
1949 | ipv6ll_mode = IN6_ADDR_GEN_MODE_STABLE_PRIVACY; | |
1950 | ||
1951 | r = sd_netlink_message_append_u8(req, IFLA_INET6_ADDR_GEN_MODE, ipv6ll_mode); | |
1952 | if (r < 0) | |
1953 | return log_link_error_errno(link, r, "Could not append IFLA_INET6_ADDR_GEN_MODE: %m"); | |
1954 | ||
1955 | r = sd_netlink_message_close_container(req); | |
1956 | if (r < 0) | |
1957 | return log_link_error_errno(link, r, "Could not close AF_INET6 container: %m"); | |
1958 | ||
1959 | r = sd_netlink_message_close_container(req); | |
1960 | if (r < 0) | |
1961 | return log_link_error_errno(link, r, "Could not close IFLA_AF_SPEC container: %m"); | |
1962 | } | |
1963 | ||
1964 | r = netlink_call_async(link->manager->rtnl, NULL, req, link_up_handler, | |
1965 | link_netlink_destroy_callback, link); | |
1966 | if (r < 0) | |
1967 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
1968 | ||
1969 | link_ref(link); | |
1970 | ||
1971 | return 0; | |
1972 | } | |
1973 | ||
1974 | static int link_down_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
1975 | int r; | |
1976 | ||
1977 | assert(link); | |
1978 | ||
1979 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
1980 | return 1; | |
1981 | ||
1982 | r = sd_netlink_message_get_errno(m); | |
1983 | if (r < 0) | |
1984 | log_link_warning_errno(link, r, "Could not bring down interface: %m"); | |
1985 | ||
1986 | return 1; | |
1987 | } | |
1988 | ||
1989 | int link_down(Link *link, link_netlink_message_handler_t callback) { | |
1990 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
1991 | int r; | |
1992 | ||
1993 | assert(link); | |
1994 | assert(link->manager); | |
1995 | assert(link->manager->rtnl); | |
1996 | ||
1997 | log_link_debug(link, "Bringing link down"); | |
1998 | ||
1999 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, | |
2000 | RTM_SETLINK, link->ifindex); | |
2001 | if (r < 0) | |
2002 | return log_link_error_errno(link, r, "Could not allocate RTM_SETLINK message: %m"); | |
2003 | ||
2004 | r = sd_rtnl_message_link_set_flags(req, 0, IFF_UP); | |
2005 | if (r < 0) | |
2006 | return log_link_error_errno(link, r, "Could not set link flags: %m"); | |
2007 | ||
2008 | r = netlink_call_async(link->manager->rtnl, NULL, req, | |
2009 | callback ?: link_down_handler, | |
2010 | link_netlink_destroy_callback, link); | |
2011 | if (r < 0) | |
2012 | return log_link_error_errno(link, r, "Could not send rtnetlink message: %m"); | |
2013 | ||
2014 | link_ref(link); | |
2015 | ||
2016 | return 0; | |
2017 | } | |
2018 | ||
2019 | static int link_handle_bound_to_list(Link *link) { | |
2020 | Link *l; | |
2021 | Iterator i; | |
2022 | int r; | |
2023 | bool required_up = false; | |
2024 | bool link_is_up = false; | |
2025 | ||
2026 | assert(link); | |
2027 | ||
2028 | if (hashmap_isempty(link->bound_to_links)) | |
2029 | return 0; | |
2030 | ||
2031 | if (link->flags & IFF_UP) | |
2032 | link_is_up = true; | |
2033 | ||
2034 | HASHMAP_FOREACH (l, link->bound_to_links, i) | |
2035 | if (link_has_carrier(l)) { | |
2036 | required_up = true; | |
2037 | break; | |
2038 | } | |
2039 | ||
2040 | if (!required_up && link_is_up) { | |
2041 | r = link_down(link, NULL); | |
2042 | if (r < 0) | |
2043 | return r; | |
2044 | } else if (required_up && !link_is_up) { | |
2045 | r = link_up(link); | |
2046 | if (r < 0) | |
2047 | return r; | |
2048 | } | |
2049 | ||
2050 | return 0; | |
2051 | } | |
2052 | ||
2053 | static int link_handle_bound_by_list(Link *link) { | |
2054 | Iterator i; | |
2055 | Link *l; | |
2056 | int r; | |
2057 | ||
2058 | assert(link); | |
2059 | ||
2060 | if (hashmap_isempty(link->bound_by_links)) | |
2061 | return 0; | |
2062 | ||
2063 | HASHMAP_FOREACH (l, link->bound_by_links, i) { | |
2064 | r = link_handle_bound_to_list(l); | |
2065 | if (r < 0) | |
2066 | return r; | |
2067 | } | |
2068 | ||
2069 | return 0; | |
2070 | } | |
2071 | ||
2072 | static int link_put_carrier(Link *link, Link *carrier, Hashmap **h) { | |
2073 | int r; | |
2074 | ||
2075 | assert(link); | |
2076 | assert(carrier); | |
2077 | ||
2078 | if (link == carrier) | |
2079 | return 0; | |
2080 | ||
2081 | if (hashmap_get(*h, INT_TO_PTR(carrier->ifindex))) | |
2082 | return 0; | |
2083 | ||
2084 | r = hashmap_ensure_allocated(h, NULL); | |
2085 | if (r < 0) | |
2086 | return r; | |
2087 | ||
2088 | r = hashmap_put(*h, INT_TO_PTR(carrier->ifindex), carrier); | |
2089 | if (r < 0) | |
2090 | return r; | |
2091 | ||
2092 | return 0; | |
2093 | } | |
2094 | ||
2095 | static int link_new_bound_by_list(Link *link) { | |
2096 | Manager *m; | |
2097 | Link *carrier; | |
2098 | Iterator i; | |
2099 | int r; | |
2100 | bool list_updated = false; | |
2101 | ||
2102 | assert(link); | |
2103 | assert(link->manager); | |
2104 | ||
2105 | m = link->manager; | |
2106 | ||
2107 | HASHMAP_FOREACH(carrier, m->links, i) { | |
2108 | if (!carrier->network) | |
2109 | continue; | |
2110 | ||
2111 | if (strv_isempty(carrier->network->bind_carrier)) | |
2112 | continue; | |
2113 | ||
2114 | if (strv_fnmatch(carrier->network->bind_carrier, link->ifname, 0)) { | |
2115 | r = link_put_carrier(link, carrier, &link->bound_by_links); | |
2116 | if (r < 0) | |
2117 | return r; | |
2118 | ||
2119 | list_updated = true; | |
2120 | } | |
2121 | } | |
2122 | ||
2123 | if (list_updated) | |
2124 | link_dirty(link); | |
2125 | ||
2126 | HASHMAP_FOREACH(carrier, link->bound_by_links, i) { | |
2127 | r = link_put_carrier(carrier, link, &carrier->bound_to_links); | |
2128 | if (r < 0) | |
2129 | return r; | |
2130 | ||
2131 | link_dirty(carrier); | |
2132 | } | |
2133 | ||
2134 | return 0; | |
2135 | } | |
2136 | ||
2137 | static int link_new_bound_to_list(Link *link) { | |
2138 | Manager *m; | |
2139 | Link *carrier; | |
2140 | Iterator i; | |
2141 | int r; | |
2142 | bool list_updated = false; | |
2143 | ||
2144 | assert(link); | |
2145 | assert(link->manager); | |
2146 | ||
2147 | if (!link->network) | |
2148 | return 0; | |
2149 | ||
2150 | if (strv_isempty(link->network->bind_carrier)) | |
2151 | return 0; | |
2152 | ||
2153 | m = link->manager; | |
2154 | ||
2155 | HASHMAP_FOREACH (carrier, m->links, i) { | |
2156 | if (strv_fnmatch(link->network->bind_carrier, carrier->ifname, 0)) { | |
2157 | r = link_put_carrier(link, carrier, &link->bound_to_links); | |
2158 | if (r < 0) | |
2159 | return r; | |
2160 | ||
2161 | list_updated = true; | |
2162 | } | |
2163 | } | |
2164 | ||
2165 | if (list_updated) | |
2166 | link_dirty(link); | |
2167 | ||
2168 | HASHMAP_FOREACH (carrier, link->bound_to_links, i) { | |
2169 | r = link_put_carrier(carrier, link, &carrier->bound_by_links); | |
2170 | if (r < 0) | |
2171 | return r; | |
2172 | ||
2173 | link_dirty(carrier); | |
2174 | } | |
2175 | ||
2176 | return 0; | |
2177 | } | |
2178 | ||
2179 | static int link_new_carrier_maps(Link *link) { | |
2180 | int r; | |
2181 | ||
2182 | r = link_new_bound_by_list(link); | |
2183 | if (r < 0) | |
2184 | return r; | |
2185 | ||
2186 | r = link_handle_bound_by_list(link); | |
2187 | if (r < 0) | |
2188 | return r; | |
2189 | ||
2190 | r = link_new_bound_to_list(link); | |
2191 | if (r < 0) | |
2192 | return r; | |
2193 | ||
2194 | r = link_handle_bound_to_list(link); | |
2195 | if (r < 0) | |
2196 | return r; | |
2197 | ||
2198 | return 0; | |
2199 | } | |
2200 | ||
2201 | static void link_free_bound_to_list(Link *link) { | |
2202 | Link *bound_to; | |
2203 | Iterator i; | |
2204 | ||
2205 | HASHMAP_FOREACH (bound_to, link->bound_to_links, i) { | |
2206 | hashmap_remove(link->bound_to_links, INT_TO_PTR(bound_to->ifindex)); | |
2207 | ||
2208 | if (hashmap_remove(bound_to->bound_by_links, INT_TO_PTR(link->ifindex))) | |
2209 | link_dirty(bound_to); | |
2210 | } | |
2211 | ||
2212 | return; | |
2213 | } | |
2214 | ||
2215 | static void link_free_bound_by_list(Link *link) { | |
2216 | Link *bound_by; | |
2217 | Iterator i; | |
2218 | ||
2219 | HASHMAP_FOREACH (bound_by, link->bound_by_links, i) { | |
2220 | hashmap_remove(link->bound_by_links, INT_TO_PTR(bound_by->ifindex)); | |
2221 | ||
2222 | if (hashmap_remove(bound_by->bound_to_links, INT_TO_PTR(link->ifindex))) { | |
2223 | link_dirty(bound_by); | |
2224 | link_handle_bound_to_list(bound_by); | |
2225 | } | |
2226 | } | |
2227 | ||
2228 | return; | |
2229 | } | |
2230 | ||
2231 | static void link_free_carrier_maps(Link *link) { | |
2232 | bool list_updated = false; | |
2233 | ||
2234 | assert(link); | |
2235 | ||
2236 | if (!hashmap_isempty(link->bound_to_links)) { | |
2237 | link_free_bound_to_list(link); | |
2238 | list_updated = true; | |
2239 | } | |
2240 | ||
2241 | if (!hashmap_isempty(link->bound_by_links)) { | |
2242 | link_free_bound_by_list(link); | |
2243 | list_updated = true; | |
2244 | } | |
2245 | ||
2246 | if (list_updated) | |
2247 | link_dirty(link); | |
2248 | ||
2249 | return; | |
2250 | } | |
2251 | ||
2252 | static int link_append_to_master(Link *link, NetDev *netdev) { | |
2253 | Link *master; | |
2254 | int r; | |
2255 | ||
2256 | assert(link); | |
2257 | assert(netdev); | |
2258 | ||
2259 | r = link_get(link->manager, netdev->ifindex, &master); | |
2260 | if (r < 0) | |
2261 | return r; | |
2262 | ||
2263 | r = set_ensure_allocated(&master->slaves, NULL); | |
2264 | if (r < 0) | |
2265 | return r; | |
2266 | ||
2267 | r = set_put(master->slaves, link); | |
2268 | if (r < 0) | |
2269 | return r; | |
2270 | ||
2271 | link_ref(link); | |
2272 | return 0; | |
2273 | } | |
2274 | ||
2275 | static void link_drop_from_master(Link *link, NetDev *netdev) { | |
2276 | Link *master; | |
2277 | ||
2278 | assert(link); | |
2279 | ||
2280 | if (!link->manager || !netdev) | |
2281 | return; | |
2282 | ||
2283 | if (link_get(link->manager, netdev->ifindex, &master) < 0) | |
2284 | return; | |
2285 | ||
2286 | link_unref(set_remove(master->slaves, link)); | |
2287 | } | |
2288 | ||
2289 | static void link_detach_from_manager(Link *link) { | |
2290 | if (!link || !link->manager) | |
2291 | return; | |
2292 | ||
2293 | link_unref(set_remove(link->manager->links_requesting_uuid, link)); | |
2294 | link_clean(link); | |
2295 | ||
2296 | /* The following must be called at last. */ | |
2297 | assert_se(hashmap_remove(link->manager->links, INT_TO_PTR(link->ifindex)) == link); | |
2298 | link_unref(link); | |
2299 | } | |
2300 | ||
2301 | void link_drop(Link *link) { | |
2302 | if (!link || link->state == LINK_STATE_LINGER) | |
2303 | return; | |
2304 | ||
2305 | link_set_state(link, LINK_STATE_LINGER); | |
2306 | ||
2307 | link_free_carrier_maps(link); | |
2308 | ||
2309 | if (link->network) { | |
2310 | link_drop_from_master(link, link->network->bridge); | |
2311 | link_drop_from_master(link, link->network->bond); | |
2312 | } | |
2313 | ||
2314 | log_link_debug(link, "Link removed"); | |
2315 | ||
2316 | (void) unlink(link->state_file); | |
2317 | link_detach_from_manager(link); | |
2318 | } | |
2319 | ||
2320 | static int link_joined(Link *link) { | |
2321 | int r; | |
2322 | ||
2323 | assert(link); | |
2324 | assert(link->network); | |
2325 | ||
2326 | if (!hashmap_isempty(link->bound_to_links)) { | |
2327 | r = link_handle_bound_to_list(link); | |
2328 | if (r < 0) | |
2329 | return r; | |
2330 | } else if (!(link->flags & IFF_UP)) { | |
2331 | r = link_up(link); | |
2332 | if (r < 0) { | |
2333 | link_enter_failed(link); | |
2334 | return r; | |
2335 | } | |
2336 | } | |
2337 | ||
2338 | if (link->network->bridge) { | |
2339 | r = link_set_bridge(link); | |
2340 | if (r < 0) | |
2341 | log_link_error_errno(link, r, "Could not set bridge message: %m"); | |
2342 | ||
2343 | r = link_append_to_master(link, link->network->bridge); | |
2344 | if (r < 0) | |
2345 | log_link_error_errno(link, r, "Failed to add to bridge master's slave list: %m"); | |
2346 | } | |
2347 | ||
2348 | if (link->network->bond) { | |
2349 | r = link_set_bond(link); | |
2350 | if (r < 0) | |
2351 | log_link_error_errno(link, r, "Could not set bond message: %m"); | |
2352 | ||
2353 | r = link_append_to_master(link, link->network->bond); | |
2354 | if (r < 0) | |
2355 | log_link_error_errno(link, r, "Failed to add to bond master's slave list: %m"); | |
2356 | } | |
2357 | ||
2358 | if (link->network->use_br_vlan && | |
2359 | (link->network->bridge || streq_ptr("bridge", link->kind))) { | |
2360 | r = link_set_bridge_vlan(link); | |
2361 | if (r < 0) | |
2362 | log_link_error_errno(link, r, "Could not set bridge vlan: %m"); | |
2363 | } | |
2364 | ||
2365 | /* Skip setting up addresses until it gets carrier, | |
2366 | or it would try to set addresses twice, | |
2367 | which is bad for non-idempotent steps. */ | |
2368 | if (!link_has_carrier(link) && !link->network->configure_without_carrier) | |
2369 | return 0; | |
2370 | ||
2371 | return link_request_set_addresses(link); | |
2372 | } | |
2373 | ||
2374 | static int netdev_join_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
2375 | int r; | |
2376 | ||
2377 | assert(link); | |
2378 | assert(link->network); | |
2379 | assert(link->enslaving > 0); | |
2380 | assert(!link->enslaved_raw); | |
2381 | ||
2382 | link->enslaving--; | |
2383 | ||
2384 | if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER)) | |
2385 | return 1; | |
2386 | ||
2387 | r = sd_netlink_message_get_errno(m); | |
2388 | if (r < 0 && r != -EEXIST) { | |
2389 | log_link_error_errno(link, r, "Could not join netdev: %m"); | |
2390 | link_enter_failed(link); | |
2391 | return 1; | |
2392 | } else | |
2393 | log_link_debug(link, "Joined netdev"); | |
2394 | ||
2395 | if (link->enslaving == 0) { | |
2396 | link->enslaved_raw = true; | |
2397 | link_joined(link); | |
2398 | } | |
2399 | ||
2400 | return 1; | |
2401 | } | |
2402 | ||
2403 | static int link_enter_join_netdev(Link *link) { | |
2404 | NetDev *netdev; | |
2405 | Iterator i; | |
2406 | int r; | |
2407 | ||
2408 | assert(link); | |
2409 | assert(link->network); | |
2410 | assert(link->state == LINK_STATE_INITIALIZED); | |
2411 | ||
2412 | link_set_state(link, LINK_STATE_CONFIGURING); | |
2413 | ||
2414 | link_dirty(link); | |
2415 | link->enslaving = 0; | |
2416 | link->enslaved_raw = false; | |
2417 | ||
2418 | if (link->network->bond) { | |
2419 | if (link->network->bond->state == NETDEV_STATE_READY && | |
2420 | link->network->bond->ifindex == link->master_ifindex) | |
2421 | return link_joined(link); | |
2422 | ||
2423 | log_struct(LOG_DEBUG, | |
2424 | LOG_LINK_INTERFACE(link), | |
2425 | LOG_NETDEV_INTERFACE(link->network->bond), | |
2426 | LOG_LINK_MESSAGE(link, "Enslaving by '%s'", link->network->bond->ifname)); | |
2427 | ||
2428 | link->enslaving++; | |
2429 | ||
2430 | r = netdev_join(link->network->bond, link, netdev_join_handler); | |
2431 | if (r < 0) { | |
2432 | log_struct_errno(LOG_WARNING, r, | |
2433 | LOG_LINK_INTERFACE(link), | |
2434 | LOG_NETDEV_INTERFACE(link->network->bond), | |
2435 | LOG_LINK_MESSAGE(link, "Could not join netdev '%s': %m", link->network->bond->ifname)); | |
2436 | link_enter_failed(link); | |
2437 | return r; | |
2438 | } | |
2439 | } | |
2440 | ||
2441 | if (link->network->bridge) { | |
2442 | log_struct(LOG_DEBUG, | |
2443 | LOG_LINK_INTERFACE(link), | |
2444 | LOG_NETDEV_INTERFACE(link->network->bridge), | |
2445 | LOG_LINK_MESSAGE(link, "Enslaving by '%s'", link->network->bridge->ifname)); | |
2446 | ||
2447 | link->enslaving++; | |
2448 | ||
2449 | r = netdev_join(link->network->bridge, link, netdev_join_handler); | |
2450 | if (r < 0) { | |
2451 | log_struct_errno(LOG_WARNING, r, | |
2452 | LOG_LINK_INTERFACE(link), | |
2453 | LOG_NETDEV_INTERFACE(link->network->bridge), | |
2454 | LOG_LINK_MESSAGE(link, "Could not join netdev '%s': %m", link->network->bridge->ifname)); | |
2455 | link_enter_failed(link); | |
2456 | return r; | |
2457 | } | |
2458 | } | |
2459 | ||
2460 | if (link->network->vrf) { | |
2461 | log_struct(LOG_DEBUG, | |
2462 | LOG_LINK_INTERFACE(link), | |
2463 | LOG_NETDEV_INTERFACE(link->network->vrf), | |
2464 | LOG_LINK_MESSAGE(link, "Enslaving by '%s'", link->network->vrf->ifname)); | |
2465 | ||
2466 | link->enslaving++; | |
2467 | ||
2468 | r = netdev_join(link->network->vrf, link, netdev_join_handler); | |
2469 | if (r < 0) { | |
2470 | log_struct_errno(LOG_WARNING, r, | |
2471 | LOG_LINK_INTERFACE(link), | |
2472 | LOG_NETDEV_INTERFACE(link->network->vrf), | |
2473 | LOG_LINK_MESSAGE(link, "Could not join netdev '%s': %m", link->network->vrf->ifname)); | |
2474 | link_enter_failed(link); | |
2475 | return r; | |
2476 | } | |
2477 | } | |
2478 | ||
2479 | HASHMAP_FOREACH(netdev, link->network->stacked_netdevs, i) { | |
2480 | ||
2481 | if (netdev->ifindex > 0) | |
2482 | /* Assume already enslaved. */ | |
2483 | continue; | |
2484 | ||
2485 | if (netdev_get_create_type(netdev) != NETDEV_CREATE_STACKED) | |
2486 | continue; | |
2487 | ||
2488 | log_struct(LOG_DEBUG, | |
2489 | LOG_LINK_INTERFACE(link), | |
2490 | LOG_NETDEV_INTERFACE(netdev), | |
2491 | LOG_LINK_MESSAGE(link, "Enslaving by '%s'", netdev->ifname)); | |
2492 | ||
2493 | link->enslaving++; | |
2494 | ||
2495 | r = netdev_join(netdev, link, netdev_join_handler); | |
2496 | if (r < 0) { | |
2497 | log_struct_errno(LOG_WARNING, r, | |
2498 | LOG_LINK_INTERFACE(link), | |
2499 | LOG_NETDEV_INTERFACE(netdev), | |
2500 | LOG_LINK_MESSAGE(link, "Could not join netdev '%s': %m", netdev->ifname)); | |
2501 | link_enter_failed(link); | |
2502 | return r; | |
2503 | } | |
2504 | } | |
2505 | ||
2506 | if (link->enslaving == 0) | |
2507 | return link_joined(link); | |
2508 | ||
2509 | return 0; | |
2510 | } | |
2511 | ||
2512 | static int link_set_ipv4_forward(Link *link) { | |
2513 | int r; | |
2514 | ||
2515 | if (!link_ipv4_forward_enabled(link)) | |
2516 | return 0; | |
2517 | ||
2518 | /* We propagate the forwarding flag from one interface to the | |
2519 | * global setting one way. This means: as long as at least one | |
2520 | * interface was configured at any time that had IP forwarding | |
2521 | * enabled the setting will stay on for good. We do this | |
2522 | * primarily to keep IPv4 and IPv6 packet forwarding behaviour | |
2523 | * somewhat in sync (see below). */ | |
2524 | ||
2525 | r = sysctl_write_ip_property(AF_INET, NULL, "ip_forward", "1"); | |
2526 | if (r < 0) | |
2527 | log_link_warning_errno(link, r, "Cannot turn on IPv4 packet forwarding, ignoring: %m"); | |
2528 | ||
2529 | return 0; | |
2530 | } | |
2531 | ||
2532 | static int link_set_ipv6_forward(Link *link) { | |
2533 | int r; | |
2534 | ||
2535 | if (!link_ipv6_forward_enabled(link)) | |
2536 | return 0; | |
2537 | ||
2538 | /* On Linux, the IPv6 stack does not know a per-interface | |
2539 | * packet forwarding setting: either packet forwarding is on | |
2540 | * for all, or off for all. We hence don't bother with a | |
2541 | * per-interface setting, but simply propagate the interface | |
2542 | * flag, if it is set, to the global flag, one-way. Note that | |
2543 | * while IPv4 would allow a per-interface flag, we expose the | |
2544 | * same behaviour there and also propagate the setting from | |
2545 | * one to all, to keep things simple (see above). */ | |
2546 | ||
2547 | r = sysctl_write_ip_property(AF_INET6, "all", "forwarding", "1"); | |
2548 | if (r < 0) | |
2549 | log_link_warning_errno(link, r, "Cannot configure IPv6 packet forwarding, ignoring: %m"); | |
2550 | ||
2551 | return 0; | |
2552 | } | |
2553 | ||
2554 | static int link_set_ipv6_privacy_extensions(Link *link) { | |
2555 | IPv6PrivacyExtensions s; | |
2556 | int r; | |
2557 | ||
2558 | s = link_ipv6_privacy_extensions(link); | |
2559 | if (s < 0) | |
2560 | return 0; | |
2561 | ||
2562 | r = sysctl_write_ip_property_int(AF_INET6, link->ifname, "use_tempaddr", (int) link->network->ipv6_privacy_extensions); | |
2563 | if (r < 0) | |
2564 | log_link_warning_errno(link, r, "Cannot configure IPv6 privacy extension for interface: %m"); | |
2565 | ||
2566 | return 0; | |
2567 | } | |
2568 | ||
2569 | static int link_set_ipv6_accept_ra(Link *link) { | |
2570 | int r; | |
2571 | ||
2572 | /* Make this a NOP if IPv6 is not available */ | |
2573 | if (!socket_ipv6_is_supported()) | |
2574 | return 0; | |
2575 | ||
2576 | if (link->flags & IFF_LOOPBACK) | |
2577 | return 0; | |
2578 | ||
2579 | if (!link->network) | |
2580 | return 0; | |
2581 | ||
2582 | r = sysctl_write_ip_property(AF_INET6, link->ifname, "accept_ra", "0"); | |
2583 | if (r < 0) | |
2584 | log_link_warning_errno(link, r, "Cannot disable kernel IPv6 accept_ra for interface: %m"); | |
2585 | ||
2586 | return 0; | |
2587 | } | |
2588 | ||
2589 | static int link_set_ipv6_dad_transmits(Link *link) { | |
2590 | int r; | |
2591 | ||
2592 | /* Make this a NOP if IPv6 is not available */ | |
2593 | if (!socket_ipv6_is_supported()) | |
2594 | return 0; | |
2595 | ||
2596 | if (link->flags & IFF_LOOPBACK) | |
2597 | return 0; | |
2598 | ||
2599 | if (!link->network) | |
2600 | return 0; | |
2601 | ||
2602 | if (link->network->ipv6_dad_transmits < 0) | |
2603 | return 0; | |
2604 | ||
2605 | r = sysctl_write_ip_property_int(AF_INET6, link->ifname, "dad_transmits", link->network->ipv6_dad_transmits); | |
2606 | if (r < 0) | |
2607 | log_link_warning_errno(link, r, "Cannot set IPv6 dad transmits for interface: %m"); | |
2608 | ||
2609 | return 0; | |
2610 | } | |
2611 | ||
2612 | static int link_set_ipv6_hop_limit(Link *link) { | |
2613 | int r; | |
2614 | ||
2615 | /* Make this a NOP if IPv6 is not available */ | |
2616 | if (!socket_ipv6_is_supported()) | |
2617 | return 0; | |
2618 | ||
2619 | if (link->flags & IFF_LOOPBACK) | |
2620 | return 0; | |
2621 | ||
2622 | if (!link->network) | |
2623 | return 0; | |
2624 | ||
2625 | if (link->network->ipv6_hop_limit < 0) | |
2626 | return 0; | |
2627 | ||
2628 | r = sysctl_write_ip_property_int(AF_INET6, link->ifname, "hop_limit", link->network->ipv6_hop_limit); | |
2629 | if (r < 0) | |
2630 | log_link_warning_errno(link, r, "Cannot set IPv6 hop limit for interface: %m"); | |
2631 | ||
2632 | return 0; | |
2633 | } | |
2634 | ||
2635 | static int link_set_ipv6_mtu(Link *link) { | |
2636 | int r; | |
2637 | ||
2638 | /* Make this a NOP if IPv6 is not available */ | |
2639 | if (!socket_ipv6_is_supported()) | |
2640 | return 0; | |
2641 | ||
2642 | if (link->flags & IFF_LOOPBACK) | |
2643 | return 0; | |
2644 | ||
2645 | if (link->network->ipv6_mtu == 0) | |
2646 | return 0; | |
2647 | ||
2648 | r = sysctl_write_ip_property_uint32(AF_INET6, link->ifname, "mtu", link->network->ipv6_mtu); | |
2649 | if (r < 0) | |
2650 | log_link_warning_errno(link, r, "Cannot set IPv6 MTU for interface: %m"); | |
2651 | ||
2652 | return 0; | |
2653 | } | |
2654 | ||
2655 | static bool link_is_static_address_configured(Link *link, Address *address) { | |
2656 | Address *net_address; | |
2657 | ||
2658 | assert(link); | |
2659 | assert(address); | |
2660 | ||
2661 | if (!link->network) | |
2662 | return false; | |
2663 | ||
2664 | LIST_FOREACH(addresses, net_address, link->network->static_addresses) | |
2665 | if (address_equal(net_address, address)) | |
2666 | return true; | |
2667 | ||
2668 | return false; | |
2669 | } | |
2670 | ||
2671 | static bool link_is_static_route_configured(Link *link, Route *route) { | |
2672 | Route *net_route; | |
2673 | ||
2674 | assert(link); | |
2675 | assert(route); | |
2676 | ||
2677 | if (!link->network) | |
2678 | return false; | |
2679 | ||
2680 | LIST_FOREACH(routes, net_route, link->network->static_routes) | |
2681 | if (route_equal(net_route, route)) | |
2682 | return true; | |
2683 | ||
2684 | return false; | |
2685 | } | |
2686 | ||
2687 | static int link_drop_foreign_config(Link *link) { | |
2688 | Address *address; | |
2689 | Route *route; | |
2690 | Iterator i; | |
2691 | int r; | |
2692 | ||
2693 | SET_FOREACH(address, link->addresses_foreign, i) { | |
2694 | /* we consider IPv6LL addresses to be managed by the kernel */ | |
2695 | if (address->family == AF_INET6 && in_addr_is_link_local(AF_INET6, &address->in_addr) == 1) | |
2696 | continue; | |
2697 | ||
2698 | if (link_is_static_address_configured(link, address)) { | |
2699 | r = address_add(link, address->family, &address->in_addr, address->prefixlen, NULL); | |
2700 | if (r < 0) | |
2701 | return log_link_error_errno(link, r, "Failed to add address: %m"); | |
2702 | } else { | |
2703 | r = address_remove(address, link, NULL); | |
2704 | if (r < 0) | |
2705 | return r; | |
2706 | } | |
2707 | } | |
2708 | ||
2709 | SET_FOREACH(route, link->routes_foreign, i) { | |
2710 | /* do not touch routes managed by the kernel */ | |
2711 | if (route->protocol == RTPROT_KERNEL) | |
2712 | continue; | |
2713 | ||
2714 | if (link_is_static_route_configured(link, route)) { | |
2715 | r = route_add(link, route->family, &route->dst, route->dst_prefixlen, route->tos, route->priority, route->table, NULL); | |
2716 | if (r < 0) | |
2717 | return r; | |
2718 | } else { | |
2719 | r = route_remove(route, link, NULL); | |
2720 | if (r < 0) | |
2721 | return r; | |
2722 | } | |
2723 | } | |
2724 | ||
2725 | return 0; | |
2726 | } | |
2727 | ||
2728 | static int link_drop_config(Link *link) { | |
2729 | Address *address, *pool_address; | |
2730 | Route *route; | |
2731 | Iterator i; | |
2732 | int r; | |
2733 | ||
2734 | SET_FOREACH(address, link->addresses, i) { | |
2735 | /* we consider IPv6LL addresses to be managed by the kernel */ | |
2736 | if (address->family == AF_INET6 && in_addr_is_link_local(AF_INET6, &address->in_addr) == 1) | |
2737 | continue; | |
2738 | ||
2739 | r = address_remove(address, link, NULL); | |
2740 | if (r < 0) | |
2741 | return r; | |
2742 | ||
2743 | /* If this address came from an address pool, clean up the pool */ | |
2744 | LIST_FOREACH(addresses, pool_address, link->pool_addresses) { | |
2745 | if (address_equal(address, pool_address)) { | |
2746 | LIST_REMOVE(addresses, link->pool_addresses, pool_address); | |
2747 | address_free(pool_address); | |
2748 | break; | |
2749 | } | |
2750 | } | |
2751 | } | |
2752 | ||
2753 | SET_FOREACH(route, link->routes, i) { | |
2754 | /* do not touch routes managed by the kernel */ | |
2755 | if (route->protocol == RTPROT_KERNEL) | |
2756 | continue; | |
2757 | ||
2758 | r = route_remove(route, link, NULL); | |
2759 | if (r < 0) | |
2760 | return r; | |
2761 | } | |
2762 | ||
2763 | ndisc_flush(link); | |
2764 | ||
2765 | return 0; | |
2766 | } | |
2767 | ||
2768 | static int link_configure(Link *link) { | |
2769 | int r; | |
2770 | ||
2771 | assert(link); | |
2772 | assert(link->network); | |
2773 | assert(link->state == LINK_STATE_INITIALIZED); | |
2774 | ||
2775 | if (STRPTR_IN_SET(link->kind, "can", "vcan")) | |
2776 | return link_configure_can(link); | |
2777 | ||
2778 | /* Drop foreign config, but ignore loopback or critical devices. | |
2779 | * We do not want to remove loopback address or addresses used for root NFS. */ | |
2780 | if (!(link->flags & IFF_LOOPBACK) && !(link->network->dhcp_critical)) { | |
2781 | r = link_drop_foreign_config(link); | |
2782 | if (r < 0) | |
2783 | return r; | |
2784 | } | |
2785 | ||
2786 | r = link_set_proxy_arp(link); | |
2787 | if (r < 0) | |
2788 | return r; | |
2789 | ||
2790 | r = ipv6_proxy_ndp_addresses_configure(link); | |
2791 | if (r < 0) | |
2792 | return r; | |
2793 | ||
2794 | r = link_set_ipv4_forward(link); | |
2795 | if (r < 0) | |
2796 | return r; | |
2797 | ||
2798 | r = link_set_ipv6_forward(link); | |
2799 | if (r < 0) | |
2800 | return r; | |
2801 | ||
2802 | r = link_set_ipv6_privacy_extensions(link); | |
2803 | if (r < 0) | |
2804 | return r; | |
2805 | ||
2806 | r = link_set_ipv6_accept_ra(link); | |
2807 | if (r < 0) | |
2808 | return r; | |
2809 | ||
2810 | r = link_set_ipv6_dad_transmits(link); | |
2811 | if (r < 0) | |
2812 | return r; | |
2813 | ||
2814 | r = link_set_ipv6_hop_limit(link); | |
2815 | if (r < 0) | |
2816 | return r; | |
2817 | ||
2818 | r = link_set_flags(link); | |
2819 | if (r < 0) | |
2820 | return r; | |
2821 | ||
2822 | r = link_set_ipv6_mtu(link); | |
2823 | if (r < 0) | |
2824 | return r; | |
2825 | ||
2826 | if (link_ipv4ll_enabled(link) || link_ipv4ll_fallback_enabled(link)) { | |
2827 | r = ipv4ll_configure(link); | |
2828 | if (r < 0) | |
2829 | return r; | |
2830 | } | |
2831 | ||
2832 | if (link_dhcp4_enabled(link)) { | |
2833 | r = dhcp4_set_promote_secondaries(link); | |
2834 | if (r < 0) | |
2835 | return r; | |
2836 | ||
2837 | r = dhcp4_configure(link); | |
2838 | if (r < 0) | |
2839 | return r; | |
2840 | } | |
2841 | ||
2842 | if (link_dhcp4_server_enabled(link)) { | |
2843 | r = sd_dhcp_server_new(&link->dhcp_server, link->ifindex); | |
2844 | if (r < 0) | |
2845 | return r; | |
2846 | ||
2847 | r = sd_dhcp_server_attach_event(link->dhcp_server, NULL, 0); | |
2848 | if (r < 0) | |
2849 | return r; | |
2850 | } | |
2851 | ||
2852 | if (link_dhcp6_enabled(link) || | |
2853 | link_ipv6_accept_ra_enabled(link)) { | |
2854 | r = dhcp6_configure(link); | |
2855 | if (r < 0) | |
2856 | return r; | |
2857 | } | |
2858 | ||
2859 | if (link_ipv6_accept_ra_enabled(link)) { | |
2860 | r = ndisc_configure(link); | |
2861 | if (r < 0) | |
2862 | return r; | |
2863 | } | |
2864 | ||
2865 | if (link_radv_enabled(link)) { | |
2866 | r = radv_configure(link); | |
2867 | if (r < 0) | |
2868 | return r; | |
2869 | } | |
2870 | ||
2871 | if (link_lldp_rx_enabled(link)) { | |
2872 | r = link_lldp_rx_configure(link); | |
2873 | if (r < 0) | |
2874 | return r; | |
2875 | } | |
2876 | ||
2877 | r = link_set_mtu(link, link->network->mtu, link->network->mtu_is_set); | |
2878 | if (r < 0) | |
2879 | return r; | |
2880 | ||
2881 | if (socket_ipv6_is_supported()) { | |
2882 | r = link_configure_addrgen_mode(link); | |
2883 | if (r < 0) | |
2884 | return r; | |
2885 | } | |
2886 | ||
2887 | return link_configure_after_setting_mtu(link); | |
2888 | } | |
2889 | ||
2890 | static int link_configure_after_setting_mtu(Link *link) { | |
2891 | int r; | |
2892 | ||
2893 | assert(link); | |
2894 | assert(link->network); | |
2895 | assert(link->state == LINK_STATE_INITIALIZED); | |
2896 | ||
2897 | if (link->setting_mtu) | |
2898 | return 0; | |
2899 | ||
2900 | if (link_has_carrier(link) || link->network->configure_without_carrier) { | |
2901 | r = link_acquire_conf(link); | |
2902 | if (r < 0) | |
2903 | return r; | |
2904 | } | |
2905 | ||
2906 | return link_enter_join_netdev(link); | |
2907 | } | |
2908 | ||
2909 | static int duid_set_uuid(DUID *duid, sd_id128_t uuid) { | |
2910 | assert(duid); | |
2911 | ||
2912 | if (duid->raw_data_len > 0) | |
2913 | return 0; | |
2914 | ||
2915 | if (duid->type != DUID_TYPE_UUID) | |
2916 | return -EINVAL; | |
2917 | ||
2918 | memcpy(&duid->raw_data, &uuid, sizeof(sd_id128_t)); | |
2919 | duid->raw_data_len = sizeof(sd_id128_t); | |
2920 | ||
2921 | return 1; | |
2922 | } | |
2923 | ||
2924 | int get_product_uuid_handler(sd_bus_message *m, void *userdata, sd_bus_error *ret_error) { | |
2925 | Manager *manager = userdata; | |
2926 | const sd_bus_error *e; | |
2927 | const void *a; | |
2928 | size_t sz; | |
2929 | DUID *duid; | |
2930 | Link *link; | |
2931 | int r; | |
2932 | ||
2933 | assert(m); | |
2934 | assert(manager); | |
2935 | ||
2936 | e = sd_bus_message_get_error(m); | |
2937 | if (e) { | |
2938 | log_error_errno(sd_bus_error_get_errno(e), | |
2939 | "Could not get product UUID. Falling back to use machine-app-specific ID as DUID-UUID: %s", | |
2940 | e->message); | |
2941 | goto configure; | |
2942 | } | |
2943 | ||
2944 | r = sd_bus_message_read_array(m, 'y', &a, &sz); | |
2945 | if (r < 0) | |
2946 | goto configure; | |
2947 | ||
2948 | if (sz != sizeof(sd_id128_t)) { | |
2949 | log_error("Invalid product UUID. Falling back to use machine-app-specific ID as DUID-UUID."); | |
2950 | goto configure; | |
2951 | } | |
2952 | ||
2953 | memcpy(&manager->product_uuid, a, sz); | |
2954 | while ((duid = set_steal_first(manager->duids_requesting_uuid))) | |
2955 | (void) duid_set_uuid(duid, manager->product_uuid); | |
2956 | ||
2957 | manager->duids_requesting_uuid = set_free(manager->duids_requesting_uuid); | |
2958 | ||
2959 | configure: | |
2960 | while ((link = set_steal_first(manager->links_requesting_uuid))) { | |
2961 | r = link_configure(link); | |
2962 | if (r < 0) | |
2963 | log_link_error_errno(link, r, "Failed to configure link: %m"); | |
2964 | } | |
2965 | ||
2966 | manager->links_requesting_uuid = set_free(manager->links_requesting_uuid); | |
2967 | ||
2968 | /* To avoid calling GetProductUUID() bus method so frequently, set the flag below | |
2969 | * even if the method fails. */ | |
2970 | manager->has_product_uuid = true; | |
2971 | ||
2972 | return 1; | |
2973 | } | |
2974 | ||
2975 | static bool link_requires_uuid(Link *link) { | |
2976 | const DUID *duid; | |
2977 | ||
2978 | assert(link); | |
2979 | assert(link->manager); | |
2980 | assert(link->network); | |
2981 | ||
2982 | duid = link_get_duid(link); | |
2983 | if (duid->type != DUID_TYPE_UUID || duid->raw_data_len != 0) | |
2984 | return false; | |
2985 | ||
2986 | if (link_dhcp4_enabled(link) && IN_SET(link->network->dhcp_client_identifier, DHCP_CLIENT_ID_DUID, DHCP_CLIENT_ID_DUID_ONLY)) | |
2987 | return true; | |
2988 | ||
2989 | if (link_dhcp6_enabled(link) || link_ipv6_accept_ra_enabled(link)) | |
2990 | return true; | |
2991 | ||
2992 | return false; | |
2993 | } | |
2994 | ||
2995 | static int link_configure_duid(Link *link) { | |
2996 | Manager *m; | |
2997 | DUID *duid; | |
2998 | int r; | |
2999 | ||
3000 | assert(link); | |
3001 | assert(link->manager); | |
3002 | assert(link->network); | |
3003 | ||
3004 | m = link->manager; | |
3005 | duid = link_get_duid(link); | |
3006 | ||
3007 | if (!link_requires_uuid(link)) | |
3008 | return 1; | |
3009 | ||
3010 | if (m->has_product_uuid) { | |
3011 | (void) duid_set_uuid(duid, m->product_uuid); | |
3012 | return 1; | |
3013 | } | |
3014 | ||
3015 | if (!m->links_requesting_uuid) { | |
3016 | r = manager_request_product_uuid(m, link); | |
3017 | if (r < 0) { | |
3018 | if (r == -ENOMEM) | |
3019 | return r; | |
3020 | ||
3021 | log_link_warning_errno(link, r, | |
3022 | "Failed to get product UUID. Falling back to use machine-app-specific ID as DUID-UUID: %m"); | |
3023 | return 1; | |
3024 | } | |
3025 | } else { | |
3026 | r = set_put(m->links_requesting_uuid, link); | |
3027 | if (r < 0) | |
3028 | return log_oom(); | |
3029 | ||
3030 | r = set_put(m->duids_requesting_uuid, duid); | |
3031 | if (r < 0) | |
3032 | return log_oom(); | |
3033 | } | |
3034 | ||
3035 | return 0; | |
3036 | } | |
3037 | ||
3038 | static int link_initialized_and_synced(Link *link) { | |
3039 | Network *network; | |
3040 | int r; | |
3041 | ||
3042 | assert(link); | |
3043 | assert(link->ifname); | |
3044 | assert(link->manager); | |
3045 | ||
3046 | /* We may get called either from the asynchronous netlink callback, | |
3047 | * or directly for link_add() if running in a container. See link_add(). */ | |
3048 | if (!IN_SET(link->state, LINK_STATE_PENDING, LINK_STATE_INITIALIZED)) | |
3049 | return 0; | |
3050 | ||
3051 | log_link_debug(link, "Link state is up-to-date"); | |
3052 | link_set_state(link, LINK_STATE_INITIALIZED); | |
3053 | ||
3054 | r = link_new_bound_by_list(link); | |
3055 | if (r < 0) | |
3056 | return r; | |
3057 | ||
3058 | r = link_handle_bound_by_list(link); | |
3059 | if (r < 0) | |
3060 | return r; | |
3061 | ||
3062 | if (!link->network) { | |
3063 | r = network_get(link->manager, link->sd_device, link->ifname, | |
3064 | &link->mac, &network); | |
3065 | if (r == -ENOENT) { | |
3066 | link_enter_unmanaged(link); | |
3067 | return 0; | |
3068 | } else if (r == 0 && network->unmanaged) { | |
3069 | link_enter_unmanaged(link); | |
3070 | return 0; | |
3071 | } else if (r < 0) | |
3072 | return r; | |
3073 | ||
3074 | if (link->flags & IFF_LOOPBACK) { | |
3075 | if (network->link_local != ADDRESS_FAMILY_NO) | |
3076 | log_link_debug(link, "Ignoring link-local autoconfiguration for loopback link"); | |
3077 | ||
3078 | if (network->dhcp != ADDRESS_FAMILY_NO) | |
3079 | log_link_debug(link, "Ignoring DHCP clients for loopback link"); | |
3080 | ||
3081 | if (network->dhcp_server) | |
3082 | log_link_debug(link, "Ignoring DHCP server for loopback link"); | |
3083 | } | |
3084 | ||
3085 | r = network_apply(network, link); | |
3086 | if (r < 0) | |
3087 | return r; | |
3088 | } | |
3089 | ||
3090 | r = link_new_bound_to_list(link); | |
3091 | if (r < 0) | |
3092 | return r; | |
3093 | ||
3094 | /* link_configure_duid() returns 0 if it requests product UUID. In that case, | |
3095 | * link_configure() is called later asynchronously. */ | |
3096 | r = link_configure_duid(link); | |
3097 | if (r <= 0) | |
3098 | return r; | |
3099 | ||
3100 | r = link_configure(link); | |
3101 | if (r < 0) | |
3102 | return r; | |
3103 | ||
3104 | return 0; | |
3105 | } | |
3106 | ||
3107 | static int link_initialized_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) { | |
3108 | (void) link_initialized_and_synced(link); | |
3109 | return 1; | |
3110 | } | |
3111 | ||
3112 | int link_initialized(Link *link, sd_device *device) { | |
3113 | _cleanup_(sd_netlink_message_unrefp) sd_netlink_message *req = NULL; | |
3114 | int r; | |
3115 | ||
3116 | assert(link); | |
3117 | assert(link->manager); | |
3118 | assert(link->manager->rtnl); | |
3119 | assert(device); | |
3120 | ||
3121 | if (link->state != LINK_STATE_PENDING) | |
3122 | return 0; | |
3123 | ||
3124 | if (link->sd_device) | |
3125 | return 0; | |
3126 | ||
3127 | log_link_debug(link, "udev initialized link"); | |
3128 | link_set_state(link, LINK_STATE_INITIALIZED); | |
3129 | ||
3130 | link->sd_device = sd_device_ref(device); | |
3131 | ||
3132 | /* udev has initialized the link, but we don't know if we have yet | |
3133 | * processed the NEWLINK messages with the latest state. Do a GETLINK, | |
3134 | * when it returns we know that the pending NEWLINKs have already been | |
3135 | * processed and that we are up-to-date */ | |
3136 | ||
3137 | r = sd_rtnl_message_new_link(link->manager->rtnl, &req, RTM_GETLINK, | |
3138 | link->ifindex); | |
3139 | if (r < 0) | |
3140 | return r; | |
3141 | ||
3142 | r = netlink_call_async(link->manager->rtnl, NULL, req, link_initialized_handler, | |
3143 | link_netlink_destroy_callback, link); | |
3144 | if (r < 0) | |
3145 | return r; | |
3146 | ||
3147 | link_ref(link); | |
3148 | ||
3149 | return 0; | |
3150 | } | |
3151 | ||
3152 | static int link_load(Link *link) { | |
3153 | _cleanup_free_ char *network_file = NULL, | |
3154 | *addresses = NULL, | |
3155 | *routes = NULL, | |
3156 | *dhcp4_address = NULL, | |
3157 | *ipv4ll_address = NULL; | |
3158 | union in_addr_union address; | |
3159 | union in_addr_union route_dst; | |
3160 | const char *p; | |
3161 | int r; | |
3162 | ||
3163 | assert(link); | |
3164 | ||
3165 | r = parse_env_file(NULL, link->state_file, | |
3166 | "NETWORK_FILE", &network_file, | |
3167 | "ADDRESSES", &addresses, | |
3168 | "ROUTES", &routes, | |
3169 | "DHCP4_ADDRESS", &dhcp4_address, | |
3170 | "IPV4LL_ADDRESS", &ipv4ll_address); | |
3171 | if (r < 0 && r != -ENOENT) | |
3172 | return log_link_error_errno(link, r, "Failed to read %s: %m", link->state_file); | |
3173 | ||
3174 | if (network_file) { | |
3175 | Network *network; | |
3176 | char *suffix; | |
3177 | ||
3178 | /* drop suffix */ | |
3179 | suffix = strrchr(network_file, '.'); | |
3180 | if (!suffix) { | |
3181 | log_link_debug(link, "Failed to get network name from %s", network_file); | |
3182 | goto network_file_fail; | |
3183 | } | |
3184 | *suffix = '\0'; | |
3185 | ||
3186 | r = network_get_by_name(link->manager, basename(network_file), &network); | |
3187 | if (r < 0) { | |
3188 | log_link_debug_errno(link, r, "Failed to get network %s: %m", basename(network_file)); | |
3189 | goto network_file_fail; | |
3190 | } | |
3191 | ||
3192 | r = network_apply(network, link); | |
3193 | if (r < 0) | |
3194 | return log_link_error_errno(link, r, "Failed to apply network %s: %m", basename(network_file)); | |
3195 | } | |
3196 | ||
3197 | network_file_fail: | |
3198 | ||
3199 | if (addresses) { | |
3200 | p = addresses; | |
3201 | ||
3202 | for (;;) { | |
3203 | _cleanup_free_ char *address_str = NULL; | |
3204 | char *prefixlen_str; | |
3205 | int family; | |
3206 | unsigned char prefixlen; | |
3207 | ||
3208 | r = extract_first_word(&p, &address_str, NULL, 0); | |
3209 | if (r < 0) { | |
3210 | log_link_debug_errno(link, r, "Failed to extract next address string: %m"); | |
3211 | continue; | |
3212 | } | |
3213 | if (r == 0) | |
3214 | break; | |
3215 | ||
3216 | prefixlen_str = strchr(address_str, '/'); | |
3217 | if (!prefixlen_str) { | |
3218 | log_link_debug(link, "Failed to parse address and prefix length %s", address_str); | |
3219 | continue; | |
3220 | } | |
3221 | ||
3222 | *prefixlen_str++ = '\0'; | |
3223 | ||
3224 | r = sscanf(prefixlen_str, "%hhu", &prefixlen); | |
3225 | if (r != 1) { | |
3226 | log_link_error(link, "Failed to parse prefixlen %s", prefixlen_str); | |
3227 | continue; | |
3228 | } | |
3229 | ||
3230 | r = in_addr_from_string_auto(address_str, &family, &address); | |
3231 | if (r < 0) { | |
3232 | log_link_debug_errno(link, r, "Failed to parse address %s: %m", address_str); | |
3233 | continue; | |
3234 | } | |
3235 | ||
3236 | r = address_add(link, family, &address, prefixlen, NULL); | |
3237 | if (r < 0) | |
3238 | return log_link_error_errno(link, r, "Failed to add address: %m"); | |
3239 | } | |
3240 | } | |
3241 | ||
3242 | if (routes) { | |
3243 | p = routes; | |
3244 | ||
3245 | for (;;) { | |
3246 | Route *route; | |
3247 | _cleanup_free_ char *route_str = NULL; | |
3248 | _cleanup_(sd_event_source_unrefp) sd_event_source *expire = NULL; | |
3249 | usec_t lifetime; | |
3250 | char *prefixlen_str; | |
3251 | int family; | |
3252 | unsigned char prefixlen, tos, table; | |
3253 | uint32_t priority; | |
3254 | ||
3255 | r = extract_first_word(&p, &route_str, NULL, 0); | |
3256 | if (r < 0) { | |
3257 | log_link_debug_errno(link, r, "Failed to extract next route string: %m"); | |
3258 | continue; | |
3259 | } | |
3260 | if (r == 0) | |
3261 | break; | |
3262 | ||
3263 | prefixlen_str = strchr(route_str, '/'); | |
3264 | if (!prefixlen_str) { | |
3265 | log_link_debug(link, "Failed to parse route %s", route_str); | |
3266 | continue; | |
3267 | } | |
3268 | ||
3269 | *prefixlen_str++ = '\0'; | |
3270 | ||
3271 | r = sscanf(prefixlen_str, "%hhu/%hhu/%"SCNu32"/%hhu/"USEC_FMT, &prefixlen, &tos, &priority, &table, &lifetime); | |
3272 | if (r != 5) { | |
3273 | log_link_debug(link, | |
3274 | "Failed to parse destination prefix length, tos, priority, table or expiration %s", | |
3275 | prefixlen_str); | |
3276 | continue; | |
3277 | } | |
3278 | ||
3279 | r = in_addr_from_string_auto(route_str, &family, &route_dst); | |
3280 | if (r < 0) { | |
3281 | log_link_debug_errno(link, r, "Failed to parse route destination %s: %m", route_str); | |
3282 | continue; | |
3283 | } | |
3284 | ||
3285 | r = route_add(link, family, &route_dst, prefixlen, tos, priority, table, &route); | |
3286 | if (r < 0) | |
3287 | return log_link_error_errno(link, r, "Failed to add route: %m"); | |
3288 | ||
3289 | if (lifetime != USEC_INFINITY && !kernel_route_expiration_supported()) { | |
3290 | r = sd_event_add_time(link->manager->event, &expire, clock_boottime_or_monotonic(), lifetime, | |
3291 | 0, route_expire_handler, route); | |
3292 | if (r < 0) | |
3293 | log_link_warning_errno(link, r, "Could not arm route expiration handler: %m"); | |
3294 | } | |
3295 | ||
3296 | route->lifetime = lifetime; | |
3297 | sd_event_source_unref(route->expire); | |
3298 | route->expire = TAKE_PTR(expire); | |
3299 | } | |
3300 | } | |
3301 | ||
3302 | if (dhcp4_address) { | |
3303 | r = in_addr_from_string(AF_INET, dhcp4_address, &address); | |
3304 | if (r < 0) { | |
3305 | log_link_debug_errno(link, r, "Failed to parse DHCPv4 address %s: %m", dhcp4_address); | |
3306 | goto dhcp4_address_fail; | |
3307 | } | |
3308 | ||
3309 | r = sd_dhcp_client_new(&link->dhcp_client, link->network ? link->network->dhcp_anonymize : 0); | |
3310 | if (r < 0) | |
3311 | return log_link_error_errno(link, r, "Failed to create DHCPv4 client: %m"); | |
3312 | ||
3313 | r = sd_dhcp_client_set_request_address(link->dhcp_client, &address.in); | |
3314 | if (r < 0) | |
3315 | return log_link_error_errno(link, r, "Failed to set initial DHCPv4 address %s: %m", dhcp4_address); | |
3316 | } | |
3317 | ||
3318 | dhcp4_address_fail: | |
3319 | ||
3320 | if (ipv4ll_address) { | |
3321 | r = in_addr_from_string(AF_INET, ipv4ll_address, &address); | |
3322 | if (r < 0) { | |
3323 | log_link_debug_errno(link, r, "Failed to parse IPv4LL address %s: %m", ipv4ll_address); | |
3324 | goto ipv4ll_address_fail; | |
3325 | } | |
3326 | ||
3327 | r = sd_ipv4ll_new(&link->ipv4ll); | |
3328 | if (r < 0) | |
3329 | return log_link_error_errno(link, r, "Failed to create IPv4LL client: %m"); | |
3330 | ||
3331 | r = sd_ipv4ll_set_address(link->ipv4ll, &address.in); | |
3332 | if (r < 0) | |
3333 | return log_link_error_errno(link, r, "Failed to set initial IPv4LL address %s: %m", ipv4ll_address); | |
3334 | } | |
3335 | ||
3336 | ipv4ll_address_fail: | |
3337 | ||
3338 | return 0; | |
3339 | } | |
3340 | ||
3341 | int link_add(Manager *m, sd_netlink_message *message, Link **ret) { | |
3342 | _cleanup_(sd_device_unrefp) sd_device *device = NULL; | |
3343 | char ifindex_str[2 + DECIMAL_STR_MAX(int)]; | |
3344 | Link *link; | |
3345 | int r; | |
3346 | ||
3347 | assert(m); | |
3348 | assert(m->rtnl); | |
3349 | assert(message); | |
3350 | assert(ret); | |
3351 | ||
3352 | r = link_new(m, message, ret); | |
3353 | if (r < 0) | |
3354 | return r; | |
3355 | ||
3356 | link = *ret; | |
3357 | ||
3358 | log_link_debug(link, "Link %d added", link->ifindex); | |
3359 | ||
3360 | r = link_load(link); | |
3361 | if (r < 0) | |
3362 | return r; | |
3363 | ||
3364 | if (detect_container() <= 0) { | |
3365 | /* not in a container, udev will be around */ | |
3366 | sprintf(ifindex_str, "n%d", link->ifindex); | |
3367 | r = sd_device_new_from_device_id(&device, ifindex_str); | |
3368 | if (r < 0) { | |
3369 | log_link_warning_errno(link, r, "Could not find device: %m"); | |
3370 | goto failed; | |
3371 | } | |
3372 | ||
3373 | r = sd_device_get_is_initialized(device); | |
3374 | if (r < 0) { | |
3375 | log_link_warning_errno(link, r, "Could not determine whether the device is initialized or not: %m"); | |
3376 | goto failed; | |
3377 | } | |
3378 | if (r == 0) { | |
3379 | /* not yet ready */ | |
3380 | log_link_debug(link, "link pending udev initialization..."); | |
3381 | return 0; | |
3382 | } | |
3383 | ||
3384 | r = device_is_renaming(device); | |
3385 | if (r < 0) { | |
3386 | log_link_warning_errno(link, r, "Failed to determine the device is renamed or not: %m"); | |
3387 | goto failed; | |
3388 | } | |
3389 | if (r > 0) { | |
3390 | log_link_debug(link, "Interface is under renaming, pending initialization."); | |
3391 | return 0; | |
3392 | } | |
3393 | ||
3394 | r = link_initialized(link, device); | |
3395 | if (r < 0) | |
3396 | goto failed; | |
3397 | } else { | |
3398 | r = link_initialized_and_synced(link); | |
3399 | if (r < 0) | |
3400 | goto failed; | |
3401 | } | |
3402 | ||
3403 | return 0; | |
3404 | failed: | |
3405 | link_enter_failed(link); | |
3406 | return r; | |
3407 | } | |
3408 | ||
3409 | int link_ipv6ll_gained(Link *link, const struct in6_addr *address) { | |
3410 | int r; | |
3411 | ||
3412 | assert(link); | |
3413 | ||
3414 | log_link_info(link, "Gained IPv6LL"); | |
3415 | ||
3416 | link->ipv6ll_address = *address; | |
3417 | link_check_ready(link); | |
3418 | ||
3419 | if (IN_SET(link->state, LINK_STATE_CONFIGURING, LINK_STATE_CONFIGURED)) { | |
3420 | r = link_acquire_ipv6_conf(link); | |
3421 | if (r < 0) { | |
3422 | link_enter_failed(link); | |
3423 | return r; | |
3424 | } | |
3425 | } | |
3426 | ||
3427 | return 0; | |
3428 | } | |
3429 | ||
3430 | static int link_carrier_gained(Link *link) { | |
3431 | int r; | |
3432 | ||
3433 | assert(link); | |
3434 | ||
3435 | if (IN_SET(link->state, LINK_STATE_CONFIGURING, LINK_STATE_CONFIGURED)) { | |
3436 | r = link_acquire_conf(link); | |
3437 | if (r < 0) { | |
3438 | link_enter_failed(link); | |
3439 | return r; | |
3440 | } | |
3441 | ||
3442 | r = link_request_set_addresses(link); | |
3443 | if (r < 0) | |
3444 | return r; | |
3445 | } | |
3446 | ||
3447 | r = link_handle_bound_by_list(link); | |
3448 | if (r < 0) | |
3449 | return r; | |
3450 | ||
3451 | return 0; | |
3452 | } | |
3453 | ||
3454 | static int link_carrier_lost(Link *link) { | |
3455 | int r; | |
3456 | ||
3457 | assert(link); | |
3458 | ||
3459 | if (link->network && link->network->ignore_carrier_loss) | |
3460 | return 0; | |
3461 | ||
3462 | /* Some devices reset itself while setting the MTU. This causes the DHCP client fall into a loop. | |
3463 | * setting_mtu keep track whether the device got reset because of setting MTU and does not drop the | |
3464 | * configuration and stop the clients as well. */ | |
3465 | if (link->setting_mtu) | |
3466 | return 0; | |
3467 | ||
3468 | r = link_stop_clients(link); | |
3469 | if (r < 0) { | |
3470 | link_enter_failed(link); | |
3471 | return r; | |
3472 | } | |
3473 | ||
3474 | if (link_dhcp4_server_enabled(link)) | |
3475 | (void) sd_dhcp_server_stop(link->dhcp_server); | |
3476 | ||
3477 | r = link_drop_config(link); | |
3478 | if (r < 0) | |
3479 | return r; | |
3480 | ||
3481 | if (!IN_SET(link->state, LINK_STATE_UNMANAGED, LINK_STATE_PENDING)) { | |
3482 | log_link_debug(link, "State is %s, dropping config", link_state_to_string(link->state)); | |
3483 | r = link_drop_foreign_config(link); | |
3484 | if (r < 0) | |
3485 | return r; | |
3486 | } | |
3487 | ||
3488 | r = link_handle_bound_by_list(link); | |
3489 | if (r < 0) | |
3490 | return r; | |
3491 | ||
3492 | return 0; | |
3493 | } | |
3494 | ||
3495 | int link_carrier_reset(Link *link) { | |
3496 | int r; | |
3497 | ||
3498 | assert(link); | |
3499 | ||
3500 | if (link_has_carrier(link)) { | |
3501 | r = link_carrier_lost(link); | |
3502 | if (r < 0) | |
3503 | return r; | |
3504 | ||
3505 | r = link_carrier_gained(link); | |
3506 | if (r < 0) | |
3507 | return r; | |
3508 | ||
3509 | log_link_info(link, "Reset carrier"); | |
3510 | } | |
3511 | ||
3512 | return 0; | |
3513 | } | |
3514 | ||
3515 | int link_update(Link *link, sd_netlink_message *m) { | |
3516 | struct ether_addr mac; | |
3517 | const char *ifname; | |
3518 | uint32_t mtu; | |
3519 | bool had_carrier, carrier_gained, carrier_lost; | |
3520 | int r; | |
3521 | ||
3522 | assert(link); | |
3523 | assert(link->ifname); | |
3524 | assert(m); | |
3525 | ||
3526 | if (link->state == LINK_STATE_LINGER) { | |
3527 | log_link_info(link, "Link re-added"); | |
3528 | link_set_state(link, LINK_STATE_CONFIGURING); | |
3529 | ||
3530 | r = link_new_carrier_maps(link); | |
3531 | if (r < 0) | |
3532 | return r; | |
3533 | } | |
3534 | ||
3535 | r = sd_netlink_message_read_string(m, IFLA_IFNAME, &ifname); | |
3536 | if (r >= 0 && !streq(ifname, link->ifname)) { | |
3537 | Manager *manager = link->manager; | |
3538 | ||
3539 | log_link_info(link, "Interface name change detected, %s has been renamed to %s.", link->ifname, ifname); | |
3540 | ||
3541 | link_drop(link); | |
3542 | r = link_add(manager, m, &link); | |
3543 | if (r < 0) | |
3544 | return r; | |
3545 | } | |
3546 | ||
3547 | r = sd_netlink_message_read_u32(m, IFLA_MTU, &mtu); | |
3548 | if (r >= 0 && mtu > 0) { | |
3549 | link->mtu = mtu; | |
3550 | if (link->original_mtu == 0) { | |
3551 | link->original_mtu = mtu; | |
3552 | log_link_debug(link, "Saved original MTU: %" PRIu32, link->original_mtu); | |
3553 | } | |
3554 | ||
3555 | if (link->dhcp_client) { | |
3556 | r = sd_dhcp_client_set_mtu(link->dhcp_client, | |
3557 | link->mtu); | |
3558 | if (r < 0) | |
3559 | return log_link_warning_errno(link, r, "Could not update MTU in DHCP client: %m"); | |
3560 | } | |
3561 | ||
3562 | if (link->radv) { | |
3563 | r = sd_radv_set_mtu(link->radv, link->mtu); | |
3564 | if (r < 0) | |
3565 | return log_link_warning_errno(link, r, "Could not set MTU for Router Advertisement: %m"); | |
3566 | } | |
3567 | } | |
3568 | ||
3569 | /* The kernel may broadcast NEWLINK messages without the MAC address | |
3570 | set, simply ignore them. */ | |
3571 | r = sd_netlink_message_read_ether_addr(m, IFLA_ADDRESS, &mac); | |
3572 | if (r >= 0) { | |
3573 | if (memcmp(link->mac.ether_addr_octet, mac.ether_addr_octet, | |
3574 | ETH_ALEN)) { | |
3575 | ||
3576 | memcpy(link->mac.ether_addr_octet, mac.ether_addr_octet, | |
3577 | ETH_ALEN); | |
3578 | ||
3579 | log_link_debug(link, "MAC address: " | |
3580 | "%02hhx:%02hhx:%02hhx:%02hhx:%02hhx:%02hhx", | |
3581 | mac.ether_addr_octet[0], | |
3582 | mac.ether_addr_octet[1], | |
3583 | mac.ether_addr_octet[2], | |
3584 | mac.ether_addr_octet[3], | |
3585 | mac.ether_addr_octet[4], | |
3586 | mac.ether_addr_octet[5]); | |
3587 | ||
3588 | if (link->ipv4ll) { | |
3589 | r = sd_ipv4ll_set_mac(link->ipv4ll, &link->mac); | |
3590 | if (r < 0) | |
3591 | return log_link_warning_errno(link, r, "Could not update MAC address in IPv4LL client: %m"); | |
3592 | } | |
3593 | ||
3594 | if (link->dhcp_client) { | |
3595 | r = sd_dhcp_client_set_mac(link->dhcp_client, | |
3596 | (const uint8_t *) &link->mac, | |
3597 | sizeof (link->mac), | |
3598 | ARPHRD_ETHER); | |
3599 | if (r < 0) | |
3600 | return log_link_warning_errno(link, r, "Could not update MAC address in DHCP client: %m"); | |
3601 | ||
3602 | r = dhcp4_set_client_identifier(link); | |
3603 | if (r < 0) | |
3604 | return r; | |
3605 | } | |
3606 | ||
3607 | if (link->dhcp6_client) { | |
3608 | const DUID* duid = link_get_duid(link); | |
3609 | ||
3610 | r = sd_dhcp6_client_set_mac(link->dhcp6_client, | |
3611 | (const uint8_t *) &link->mac, | |
3612 | sizeof (link->mac), | |
3613 | ARPHRD_ETHER); | |
3614 | if (r < 0) | |
3615 | return log_link_warning_errno(link, r, "Could not update MAC address in DHCPv6 client: %m"); | |
3616 | ||
3617 | if (link->network->iaid_set) { | |
3618 | r = sd_dhcp6_client_set_iaid(link->dhcp6_client, | |
3619 | link->network->iaid); | |
3620 | if (r < 0) | |
3621 | return log_link_warning_errno(link, r, "Could not update DHCPv6 IAID: %m"); | |
3622 | } | |
3623 | ||
3624 | r = sd_dhcp6_client_set_duid(link->dhcp6_client, | |
3625 | duid->type, | |
3626 | duid->raw_data_len > 0 ? duid->raw_data : NULL, | |
3627 | duid->raw_data_len); | |
3628 | if (r < 0) | |
3629 | return log_link_warning_errno(link, r, "Could not update DHCPv6 DUID: %m"); | |
3630 | } | |
3631 | ||
3632 | if (link->radv) { | |
3633 | r = sd_radv_set_mac(link->radv, &link->mac); | |
3634 | if (r < 0) | |
3635 | return log_link_warning_errno(link, r, "Could not update MAC for Router Advertisement: %m"); | |
3636 | } | |
3637 | ||
3638 | if (link->ndisc) { | |
3639 | r = sd_ndisc_set_mac(link->ndisc, &link->mac); | |
3640 | if (r < 0) | |
3641 | return log_link_warning_errno(link, r, "Could not update MAC for ndisc: %m"); | |
3642 | } | |
3643 | } | |
3644 | } | |
3645 | ||
3646 | had_carrier = link_has_carrier(link); | |
3647 | ||
3648 | r = link_update_flags(link, m); | |
3649 | if (r < 0) | |
3650 | return r; | |
3651 | ||
3652 | r = link_update_lldp(link); | |
3653 | if (r < 0) | |
3654 | return r; | |
3655 | ||
3656 | carrier_gained = !had_carrier && link_has_carrier(link); | |
3657 | carrier_lost = had_carrier && !link_has_carrier(link); | |
3658 | ||
3659 | if (carrier_gained) { | |
3660 | log_link_info(link, "Gained carrier"); | |
3661 | ||
3662 | r = link_carrier_gained(link); | |
3663 | if (r < 0) | |
3664 | return r; | |
3665 | } else if (carrier_lost) { | |
3666 | log_link_info(link, "Lost carrier"); | |
3667 | ||
3668 | r = link_carrier_lost(link); | |
3669 | if (r < 0) | |
3670 | return r; | |
3671 | } | |
3672 | ||
3673 | return 0; | |
3674 | } | |
3675 | ||
3676 | static void print_link_hashmap(FILE *f, const char *prefix, Hashmap* h) { | |
3677 | bool space = false; | |
3678 | Iterator i; | |
3679 | Link *link; | |
3680 | ||
3681 | assert(f); | |
3682 | assert(prefix); | |
3683 | ||
3684 | if (hashmap_isempty(h)) | |
3685 | return; | |
3686 | ||
3687 | fputs(prefix, f); | |
3688 | HASHMAP_FOREACH(link, h, i) { | |
3689 | if (space) | |
3690 | fputc(' ', f); | |
3691 | ||
3692 | fprintf(f, "%i", link->ifindex); | |
3693 | space = true; | |
3694 | } | |
3695 | ||
3696 | fputc('\n', f); | |
3697 | } | |
3698 | ||
3699 | int link_save(Link *link) { | |
3700 | _cleanup_free_ char *temp_path = NULL; | |
3701 | _cleanup_fclose_ FILE *f = NULL; | |
3702 | const char *admin_state, *oper_state; | |
3703 | Address *a; | |
3704 | Route *route; | |
3705 | Iterator i; | |
3706 | int r; | |
3707 | ||
3708 | assert(link); | |
3709 | assert(link->state_file); | |
3710 | assert(link->lease_file); | |
3711 | assert(link->manager); | |
3712 | ||
3713 | if (link->state == LINK_STATE_LINGER) { | |
3714 | (void) unlink(link->state_file); | |
3715 | return 0; | |
3716 | } | |
3717 | ||
3718 | link_lldp_save(link); | |
3719 | ||
3720 | admin_state = link_state_to_string(link->state); | |
3721 | assert(admin_state); | |
3722 | ||
3723 | oper_state = link_operstate_to_string(link->operstate); | |
3724 | assert(oper_state); | |
3725 | ||
3726 | r = fopen_temporary(link->state_file, &f, &temp_path); | |
3727 | if (r < 0) | |
3728 | goto fail; | |
3729 | ||
3730 | (void) fchmod(fileno(f), 0644); | |
3731 | ||
3732 | fprintf(f, | |
3733 | "# This is private data. Do not parse.\n" | |
3734 | "ADMIN_STATE=%s\n" | |
3735 | "OPER_STATE=%s\n", | |
3736 | admin_state, oper_state); | |
3737 | ||
3738 | if (link->network) { | |
3739 | bool space; | |
3740 | sd_dhcp6_lease *dhcp6_lease = NULL; | |
3741 | const char *dhcp_domainname = NULL; | |
3742 | char **dhcp6_domains = NULL; | |
3743 | char **dhcp_domains = NULL; | |
3744 | unsigned j; | |
3745 | ||
3746 | fprintf(f, "REQUIRED_FOR_ONLINE=%s\n", | |
3747 | yes_no(link->network->required_for_online)); | |
3748 | ||
3749 | fprintf(f, "REQUIRED_OPER_STATE_FOR_ONLINE=%s\n", | |
3750 | strempty(link_operstate_to_string(link->network->required_operstate_for_online))); | |
3751 | ||
3752 | if (link->dhcp6_client) { | |
3753 | r = sd_dhcp6_client_get_lease(link->dhcp6_client, &dhcp6_lease); | |
3754 | if (r < 0 && r != -ENOMSG) | |
3755 | log_link_debug(link, "No DHCPv6 lease"); | |
3756 | } | |
3757 | ||
3758 | fprintf(f, "NETWORK_FILE=%s\n", link->network->filename); | |
3759 | ||
3760 | fputs("DNS=", f); | |
3761 | space = false; | |
3762 | ||
3763 | for (j = 0; j < link->network->n_dns; j++) { | |
3764 | _cleanup_free_ char *b = NULL; | |
3765 | ||
3766 | r = in_addr_to_string(link->network->dns[j].family, | |
3767 | &link->network->dns[j].address, &b); | |
3768 | if (r < 0) { | |
3769 | log_debug_errno(r, "Failed to format address, ignoring: %m"); | |
3770 | continue; | |
3771 | } | |
3772 | ||
3773 | if (space) | |
3774 | fputc(' ', f); | |
3775 | fputs(b, f); | |
3776 | space = true; | |
3777 | } | |
3778 | ||
3779 | if (link->network->dhcp_use_dns && | |
3780 | link->dhcp_lease) { | |
3781 | const struct in_addr *addresses; | |
3782 | ||
3783 | r = sd_dhcp_lease_get_dns(link->dhcp_lease, &addresses); | |
3784 | if (r > 0) | |
3785 | if (serialize_in_addrs(f, addresses, r, space, in4_addr_is_non_local) > 0) | |
3786 | space = true; | |
3787 | } | |
3788 | ||
3789 | if (link->network->dhcp_use_dns && dhcp6_lease) { | |
3790 | struct in6_addr *in6_addrs; | |
3791 | ||
3792 | r = sd_dhcp6_lease_get_dns(dhcp6_lease, &in6_addrs); | |
3793 | if (r > 0) { | |
3794 | if (space) | |
3795 | fputc(' ', f); | |
3796 | serialize_in6_addrs(f, in6_addrs, r); | |
3797 | space = true; | |
3798 | } | |
3799 | } | |
3800 | ||
3801 | /* Make sure to flush out old entries before we use the NDISC data */ | |
3802 | ndisc_vacuum(link); | |
3803 | ||
3804 | if (link->network->ipv6_accept_ra_use_dns && link->ndisc_rdnss) { | |
3805 | NDiscRDNSS *dd; | |
3806 | ||
3807 | SET_FOREACH(dd, link->ndisc_rdnss, i) { | |
3808 | if (space) | |
3809 | fputc(' ', f); | |
3810 | ||
3811 | serialize_in6_addrs(f, &dd->address, 1); | |
3812 | space = true; | |
3813 | } | |
3814 | } | |
3815 | ||
3816 | fputc('\n', f); | |
3817 | ||
3818 | fputs("NTP=", f); | |
3819 | space = false; | |
3820 | fputstrv(f, link->network->ntp, NULL, &space); | |
3821 | ||
3822 | if (link->network->dhcp_use_ntp && | |
3823 | link->dhcp_lease) { | |
3824 | const struct in_addr *addresses; | |
3825 | ||
3826 | r = sd_dhcp_lease_get_ntp(link->dhcp_lease, &addresses); | |
3827 | if (r > 0) | |
3828 | if (serialize_in_addrs(f, addresses, r, space, in4_addr_is_non_local) > 0) | |
3829 | space = true; | |
3830 | } | |
3831 | ||
3832 | if (link->network->dhcp_use_ntp && dhcp6_lease) { | |
3833 | struct in6_addr *in6_addrs; | |
3834 | char **hosts; | |
3835 | ||
3836 | r = sd_dhcp6_lease_get_ntp_addrs(dhcp6_lease, | |
3837 | &in6_addrs); | |
3838 | if (r > 0) { | |
3839 | if (space) | |
3840 | fputc(' ', f); | |
3841 | serialize_in6_addrs(f, in6_addrs, r); | |
3842 | space = true; | |
3843 | } | |
3844 | ||
3845 | r = sd_dhcp6_lease_get_ntp_fqdn(dhcp6_lease, &hosts); | |
3846 | if (r > 0) | |
3847 | fputstrv(f, hosts, NULL, &space); | |
3848 | } | |
3849 | ||
3850 | fputc('\n', f); | |
3851 | ||
3852 | if (link->network->dhcp_use_domains != DHCP_USE_DOMAINS_NO) { | |
3853 | if (link->dhcp_lease) { | |
3854 | (void) sd_dhcp_lease_get_domainname(link->dhcp_lease, &dhcp_domainname); | |
3855 | (void) sd_dhcp_lease_get_search_domains(link->dhcp_lease, &dhcp_domains); | |
3856 | } | |
3857 | if (dhcp6_lease) | |
3858 | (void) sd_dhcp6_lease_get_domains(dhcp6_lease, &dhcp6_domains); | |
3859 | } | |
3860 | ||
3861 | ordered_set_print(f, "DOMAINS=", link->network->search_domains); | |
3862 | ||
3863 | if (link->network->dhcp_use_domains == DHCP_USE_DOMAINS_YES) { | |
3864 | NDiscDNSSL *dd; | |
3865 | ||
3866 | if (dhcp_domainname) | |
3867 | fputs_with_space(f, dhcp_domainname, NULL, &space); | |
3868 | if (dhcp_domains) | |
3869 | fputstrv(f, dhcp_domains, NULL, &space); | |
3870 | if (dhcp6_domains) | |
3871 | fputstrv(f, dhcp6_domains, NULL, &space); | |
3872 | ||
3873 | SET_FOREACH(dd, link->ndisc_dnssl, i) | |
3874 | fputs_with_space(f, NDISC_DNSSL_DOMAIN(dd), NULL, &space); | |
3875 | } | |
3876 | ||
3877 | fputc('\n', f); | |
3878 | ||
3879 | ordered_set_print(f, "ROUTE_DOMAINS=", link->network->route_domains); | |
3880 | ||
3881 | if (link->network->dhcp_use_domains == DHCP_USE_DOMAINS_ROUTE) { | |
3882 | NDiscDNSSL *dd; | |
3883 | ||
3884 | if (dhcp_domainname) | |
3885 | fputs_with_space(f, dhcp_domainname, NULL, &space); | |
3886 | if (dhcp_domains) | |
3887 | fputstrv(f, dhcp_domains, NULL, &space); | |
3888 | if (dhcp6_domains) | |
3889 | fputstrv(f, dhcp6_domains, NULL, &space); | |
3890 | ||
3891 | SET_FOREACH(dd, link->ndisc_dnssl, i) | |
3892 | fputs_with_space(f, NDISC_DNSSL_DOMAIN(dd), NULL, &space); | |
3893 | } | |
3894 | ||
3895 | fputc('\n', f); | |
3896 | ||
3897 | fprintf(f, "LLMNR=%s\n", | |
3898 | resolve_support_to_string(link->network->llmnr)); | |
3899 | fprintf(f, "MDNS=%s\n", | |
3900 | resolve_support_to_string(link->network->mdns)); | |
3901 | if (link->network->dns_default_route >= 0) | |
3902 | fprintf(f, "DNS_DEFAULT_ROUTE=%s\n", yes_no(link->network->dns_default_route)); | |
3903 | ||
3904 | if (link->network->dns_over_tls_mode != _DNS_OVER_TLS_MODE_INVALID) | |
3905 | fprintf(f, "DNS_OVER_TLS=%s\n", | |
3906 | dns_over_tls_mode_to_string(link->network->dns_over_tls_mode)); | |
3907 | ||
3908 | if (link->network->dnssec_mode != _DNSSEC_MODE_INVALID) | |
3909 | fprintf(f, "DNSSEC=%s\n", | |
3910 | dnssec_mode_to_string(link->network->dnssec_mode)); | |
3911 | ||
3912 | if (!set_isempty(link->network->dnssec_negative_trust_anchors)) { | |
3913 | const char *n; | |
3914 | ||
3915 | fputs("DNSSEC_NTA=", f); | |
3916 | space = false; | |
3917 | SET_FOREACH(n, link->network->dnssec_negative_trust_anchors, i) | |
3918 | fputs_with_space(f, n, NULL, &space); | |
3919 | fputc('\n', f); | |
3920 | } | |
3921 | ||
3922 | fputs("ADDRESSES=", f); | |
3923 | space = false; | |
3924 | SET_FOREACH(a, link->addresses, i) { | |
3925 | _cleanup_free_ char *address_str = NULL; | |
3926 | ||
3927 | r = in_addr_to_string(a->family, &a->in_addr, &address_str); | |
3928 | if (r < 0) | |
3929 | goto fail; | |
3930 | ||
3931 | fprintf(f, "%s%s/%u", space ? " " : "", address_str, a->prefixlen); | |
3932 | space = true; | |
3933 | } | |
3934 | fputc('\n', f); | |
3935 | ||
3936 | fputs("ROUTES=", f); | |
3937 | space = false; | |
3938 | SET_FOREACH(route, link->routes, i) { | |
3939 | _cleanup_free_ char *route_str = NULL; | |
3940 | ||
3941 | r = in_addr_to_string(route->family, &route->dst, &route_str); | |
3942 | if (r < 0) | |
3943 | goto fail; | |
3944 | ||
3945 | fprintf(f, "%s%s/%hhu/%hhu/%"PRIu32"/%"PRIu32"/"USEC_FMT, | |
3946 | space ? " " : "", route_str, | |
3947 | route->dst_prefixlen, route->tos, route->priority, route->table, route->lifetime); | |
3948 | space = true; | |
3949 | } | |
3950 | ||
3951 | fputc('\n', f); | |
3952 | } | |
3953 | ||
3954 | print_link_hashmap(f, "CARRIER_BOUND_TO=", link->bound_to_links); | |
3955 | print_link_hashmap(f, "CARRIER_BOUND_BY=", link->bound_by_links); | |
3956 | ||
3957 | if (link->dhcp_lease) { | |
3958 | struct in_addr address; | |
3959 | const char *tz = NULL; | |
3960 | ||
3961 | assert(link->network); | |
3962 | ||
3963 | r = sd_dhcp_lease_get_timezone(link->dhcp_lease, &tz); | |
3964 | if (r >= 0) | |
3965 | fprintf(f, "TIMEZONE=%s\n", tz); | |
3966 | ||
3967 | r = sd_dhcp_lease_get_address(link->dhcp_lease, &address); | |
3968 | if (r >= 0) { | |
3969 | fputs("DHCP4_ADDRESS=", f); | |
3970 | serialize_in_addrs(f, &address, 1, false, NULL); | |
3971 | fputc('\n', f); | |
3972 | } | |
3973 | ||
3974 | r = dhcp_lease_save(link->dhcp_lease, link->lease_file); | |
3975 | if (r < 0) | |
3976 | goto fail; | |
3977 | ||
3978 | fprintf(f, | |
3979 | "DHCP_LEASE=%s\n", | |
3980 | link->lease_file); | |
3981 | } else | |
3982 | (void) unlink(link->lease_file); | |
3983 | ||
3984 | if (link->ipv4ll) { | |
3985 | struct in_addr address; | |
3986 | ||
3987 | r = sd_ipv4ll_get_address(link->ipv4ll, &address); | |
3988 | if (r >= 0) { | |
3989 | fputs("IPV4LL_ADDRESS=", f); | |
3990 | serialize_in_addrs(f, &address, 1, false, NULL); | |
3991 | fputc('\n', f); | |
3992 | } | |
3993 | } | |
3994 | ||
3995 | r = fflush_and_check(f); | |
3996 | if (r < 0) | |
3997 | goto fail; | |
3998 | ||
3999 | if (rename(temp_path, link->state_file) < 0) { | |
4000 | r = -errno; | |
4001 | goto fail; | |
4002 | } | |
4003 | ||
4004 | return 0; | |
4005 | ||
4006 | fail: | |
4007 | (void) unlink(link->state_file); | |
4008 | if (temp_path) | |
4009 | (void) unlink(temp_path); | |
4010 | ||
4011 | return log_link_error_errno(link, r, "Failed to save link data to %s: %m", link->state_file); | |
4012 | } | |
4013 | ||
4014 | /* The serialized state in /run is no longer up-to-date. */ | |
4015 | void link_dirty(Link *link) { | |
4016 | int r; | |
4017 | ||
4018 | assert(link); | |
4019 | ||
4020 | /* mark manager dirty as link is dirty */ | |
4021 | manager_dirty(link->manager); | |
4022 | ||
4023 | r = set_ensure_allocated(&link->manager->dirty_links, NULL); | |
4024 | if (r < 0) | |
4025 | /* allocation errors are ignored */ | |
4026 | return; | |
4027 | ||
4028 | r = set_put(link->manager->dirty_links, link); | |
4029 | if (r <= 0) | |
4030 | /* don't take another ref if the link was already dirty */ | |
4031 | return; | |
4032 | ||
4033 | link_ref(link); | |
4034 | } | |
4035 | ||
4036 | /* The serialized state in /run is up-to-date */ | |
4037 | void link_clean(Link *link) { | |
4038 | assert(link); | |
4039 | assert(link->manager); | |
4040 | ||
4041 | link_unref(set_remove(link->manager->dirty_links, link)); | |
4042 | } | |
4043 | ||
4044 | static const char* const link_state_table[_LINK_STATE_MAX] = { | |
4045 | [LINK_STATE_PENDING] = "pending", | |
4046 | [LINK_STATE_INITIALIZED] = "initialized", | |
4047 | [LINK_STATE_CONFIGURING] = "configuring", | |
4048 | [LINK_STATE_CONFIGURED] = "configured", | |
4049 | [LINK_STATE_UNMANAGED] = "unmanaged", | |
4050 | [LINK_STATE_FAILED] = "failed", | |
4051 | [LINK_STATE_LINGER] = "linger", | |
4052 | }; | |
4053 | ||
4054 | DEFINE_STRING_TABLE_LOOKUP(link_state, LinkState); |