]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/libsystemd-network/sd-radv.c
sd-radv: use ICMP6Packet and sd_ndisc_router_solicit
[thirdparty/systemd.git] / src / libsystemd-network / sd-radv.c
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2 /***
3 Copyright © 2017 Intel Corporation. All rights reserved.
4 ***/
5
6 #include <netinet/icmp6.h>
7 #include <netinet/in.h>
8 #include <arpa/inet.h>
9
10 #include "sd-radv.h"
11
12 #include "alloc-util.h"
13 #include "dns-domain.h"
14 #include "ether-addr-util.h"
15 #include "event-util.h"
16 #include "fd-util.h"
17 #include "icmp6-util.h"
18 #include "in-addr-util.h"
19 #include "iovec-util.h"
20 #include "macro.h"
21 #include "memory-util.h"
22 #include "ndisc-router-solicit-internal.h"
23 #include "network-common.h"
24 #include "radv-internal.h"
25 #include "random-util.h"
26 #include "socket-util.h"
27 #include "string-util.h"
28 #include "strv.h"
29 #include "unaligned.h"
30
31 int sd_radv_new(sd_radv **ret) {
32 _cleanup_(sd_radv_unrefp) sd_radv *ra = NULL;
33
34 assert_return(ret, -EINVAL);
35
36 ra = new(sd_radv, 1);
37 if (!ra)
38 return -ENOMEM;
39
40 *ra = (sd_radv) {
41 .n_ref = 1,
42 .fd = -EBADF,
43 .lifetime_usec = RADV_DEFAULT_ROUTER_LIFETIME_USEC,
44 };
45
46 *ret = TAKE_PTR(ra);
47
48 return 0;
49 }
50
51 int sd_radv_attach_event(sd_radv *ra, sd_event *event, int64_t priority) {
52 int r;
53
54 assert_return(ra, -EINVAL);
55 assert_return(!ra->event, -EBUSY);
56
57 if (event)
58 ra->event = sd_event_ref(event);
59 else {
60 r = sd_event_default(&ra->event);
61 if (r < 0)
62 return 0;
63 }
64
65 ra->event_priority = priority;
66
67 return 0;
68 }
69
70 int sd_radv_detach_event(sd_radv *ra) {
71
72 assert_return(ra, -EINVAL);
73
74 ra->event = sd_event_unref(ra->event);
75 return 0;
76 }
77
78 sd_event *sd_radv_get_event(sd_radv *ra) {
79 assert_return(ra, NULL);
80
81 return ra->event;
82 }
83
84 int sd_radv_is_running(sd_radv *ra) {
85 if (!ra)
86 return false;
87
88 return ra->state != RADV_STATE_IDLE;
89 }
90
91 static void radv_reset(sd_radv *ra) {
92 assert(ra);
93
94 (void) event_source_disable(ra->timeout_event_source);
95
96 ra->recv_event_source = sd_event_source_disable_unref(ra->recv_event_source);
97
98 ra->ra_sent = 0;
99 }
100
101 static sd_radv *radv_free(sd_radv *ra) {
102 if (!ra)
103 return NULL;
104
105 LIST_CLEAR(prefix, ra->prefixes, sd_radv_prefix_unref);
106 LIST_CLEAR(prefix, ra->route_prefixes, sd_radv_route_prefix_unref);
107 LIST_CLEAR(prefix, ra->pref64_prefixes, sd_radv_pref64_prefix_unref);
108
109 free(ra->rdnss);
110 free(ra->dnssl);
111
112 radv_reset(ra);
113
114 sd_event_source_unref(ra->timeout_event_source);
115 sd_radv_detach_event(ra);
116
117 ra->fd = safe_close(ra->fd);
118 free(ra->ifname);
119
120 return mfree(ra);
121 }
122
123 DEFINE_PUBLIC_TRIVIAL_REF_UNREF_FUNC(sd_radv, sd_radv, radv_free);
124
125 static bool router_lifetime_is_valid(usec_t lifetime_usec) {
126 assert_cc(RADV_MAX_ROUTER_LIFETIME_USEC <= UINT16_MAX * USEC_PER_SEC);
127 return lifetime_usec == 0 ||
128 (lifetime_usec >= RADV_MIN_ROUTER_LIFETIME_USEC &&
129 lifetime_usec <= RADV_MAX_ROUTER_LIFETIME_USEC);
130 }
131
132 static int radv_send_router(sd_radv *ra, const struct in6_addr *dst, usec_t lifetime_usec) {
133 assert(ra);
134 assert(router_lifetime_is_valid(lifetime_usec));
135
136 struct sockaddr_in6 dst_addr = {
137 .sin6_family = AF_INET6,
138 .sin6_addr = IN6_ADDR_ALL_NODES_MULTICAST,
139 };
140 struct nd_router_advert adv = {
141 .nd_ra_type = ND_ROUTER_ADVERT,
142 .nd_ra_router_lifetime = usec_to_be16_sec(lifetime_usec),
143 .nd_ra_retransmit = usec_to_be32_msec(ra->retransmit_usec),
144 };
145 struct {
146 struct nd_opt_hdr opthdr;
147 struct ether_addr slladdr;
148 } _packed_ opt_mac = {
149 .opthdr = {
150 .nd_opt_type = ND_OPT_SOURCE_LINKADDR,
151 .nd_opt_len = DIV_ROUND_UP(sizeof(struct nd_opt_hdr) + sizeof(struct ether_addr), 8),
152 },
153 .slladdr = ra->mac_addr,
154 };
155 struct nd_opt_mtu opt_mtu = {
156 .nd_opt_mtu_type = ND_OPT_MTU,
157 .nd_opt_mtu_len = 1,
158 .nd_opt_mtu_mtu = htobe32(ra->mtu),
159 };
160 /* Reserve iov space for RA header, linkaddr, MTU, N prefixes, N routes, N pref64 prefixes, RDNSS,
161 * DNSSL, and home agent. */
162 struct iovec iov[6 + ra->n_prefixes + ra->n_route_prefixes + ra->n_pref64_prefixes];
163 struct msghdr msg = {
164 .msg_name = &dst_addr,
165 .msg_namelen = sizeof(dst_addr),
166 .msg_iov = iov,
167 };
168 usec_t time_now;
169 int r;
170
171 r = sd_event_now(ra->event, CLOCK_BOOTTIME, &time_now);
172 if (r < 0)
173 return r;
174
175 if (dst && in6_addr_is_set(dst))
176 dst_addr.sin6_addr = *dst;
177
178 /* The nd_ra_curhoplimit and nd_ra_flags_reserved fields cannot specified with nd_ra_router_lifetime
179 * simultaneously in the structured initializer in the above. */
180 adv.nd_ra_curhoplimit = ra->hop_limit;
181 adv.nd_ra_flags_reserved = ra->flags;
182 iov[msg.msg_iovlen++] = IOVEC_MAKE(&adv, sizeof(adv));
183
184 /* MAC address is optional, either because the link does not use L2 addresses or load sharing is
185 * desired. See RFC 4861, Section 4.2. */
186 if (!ether_addr_is_null(&ra->mac_addr))
187 iov[msg.msg_iovlen++] = IOVEC_MAKE(&opt_mac, sizeof(opt_mac));
188
189 if (ra->mtu > 0)
190 iov[msg.msg_iovlen++] = IOVEC_MAKE(&opt_mtu, sizeof(opt_mtu));
191
192 LIST_FOREACH(prefix, p, ra->prefixes) {
193 usec_t lifetime_valid_usec, lifetime_preferred_usec;
194
195 lifetime_valid_usec = MIN(usec_sub_unsigned(p->valid_until, time_now),
196 p->lifetime_valid_usec);
197
198 lifetime_preferred_usec = MIN3(usec_sub_unsigned(p->preferred_until, time_now),
199 p->lifetime_preferred_usec,
200 lifetime_valid_usec);
201
202 p->opt.lifetime_valid = usec_to_be32_sec(lifetime_valid_usec);
203 p->opt.lifetime_preferred = usec_to_be32_sec(lifetime_preferred_usec);
204
205 iov[msg.msg_iovlen++] = IOVEC_MAKE(&p->opt, sizeof(p->opt));
206 }
207
208 LIST_FOREACH(prefix, rt, ra->route_prefixes) {
209 rt->opt.lifetime = usec_to_be32_sec(MIN(usec_sub_unsigned(rt->valid_until, time_now),
210 rt->lifetime_usec));
211
212 iov[msg.msg_iovlen++] = IOVEC_MAKE(&rt->opt, sizeof(rt->opt));
213 }
214
215 LIST_FOREACH(prefix, p, ra->pref64_prefixes)
216 iov[msg.msg_iovlen++] = IOVEC_MAKE(&p->opt, sizeof(p->opt));
217
218 if (ra->rdnss)
219 iov[msg.msg_iovlen++] = IOVEC_MAKE(ra->rdnss, ra->rdnss->length * 8);
220
221 if (ra->dnssl)
222 iov[msg.msg_iovlen++] = IOVEC_MAKE(ra->dnssl, ra->dnssl->length * 8);
223
224 if (FLAGS_SET(ra->flags, ND_RA_FLAG_HOME_AGENT)) {
225 ra->home_agent.nd_opt_home_agent_info_type = ND_OPT_HOME_AGENT_INFO;
226 ra->home_agent.nd_opt_home_agent_info_len = 1;
227
228 /* 0 means to place the current Router Lifetime value */
229 if (ra->home_agent.nd_opt_home_agent_info_lifetime == 0)
230 ra->home_agent.nd_opt_home_agent_info_lifetime = adv.nd_ra_router_lifetime;
231
232 iov[msg.msg_iovlen++] = IOVEC_MAKE(&ra->home_agent, sizeof(ra->home_agent));
233 }
234
235 if (sendmsg(ra->fd, &msg, 0) < 0)
236 return -errno;
237
238 return 0;
239 }
240
241 static int radv_process_packet(sd_radv *ra, ICMP6Packet *packet) {
242 int r;
243
244 assert(ra);
245 assert(packet);
246
247 if (icmp6_packet_get_type(packet) != ND_ROUTER_SOLICIT)
248 return log_radv_errno(ra, SYNTHETIC_ERRNO(EBADMSG), "Received ICMP6 packet with unexpected type, ignoring.");
249
250 _cleanup_(sd_ndisc_router_solicit_unrefp) sd_ndisc_router_solicit *rs = NULL;
251 rs = ndisc_router_solicit_new(packet);
252 if (!rs)
253 return log_oom_debug();
254
255 r = ndisc_router_solicit_parse(ra, rs);
256 if (r < 0)
257 return r;
258
259 struct in6_addr src = {};
260 r = sd_ndisc_router_solicit_get_sender_address(rs, &src);
261 if (r < 0 && r != -ENODATA) /* null address is allowed */
262 return log_radv_errno(ra, r, "Failed to get sender address of RS, ignoring: %m");
263
264 r = radv_send_router(ra, &src, ra->lifetime_usec);
265 if (r < 0)
266 return log_radv_errno(ra, r, "Unable to send solicited Router Advertisement to %s, ignoring: %m", IN6_ADDR_TO_STRING(&src));
267
268 log_radv(ra, "Sent solicited Router Advertisement to %s.", IN6_ADDR_TO_STRING(&src));
269 return 0;
270 }
271
272 static int radv_recv(sd_event_source *s, int fd, uint32_t revents, void *userdata) {
273 _cleanup_(icmp6_packet_unrefp) ICMP6Packet *packet = NULL;
274 sd_radv *ra = ASSERT_PTR(userdata);
275 int r;
276
277 assert(fd >= 0);
278
279 r = icmp6_packet_receive(fd, &packet);
280 if (r < 0) {
281 log_radv_errno(ra, r, "Failed to receive ICMPv6 packet, ignoring: %m");
282 return 0;
283 }
284
285 (void) radv_process_packet(ra, packet);
286 return 0;
287 }
288
289 static int radv_timeout(sd_event_source *s, uint64_t usec, void *userdata) {
290 usec_t min_timeout, max_timeout, time_now, timeout;
291 sd_radv *ra = ASSERT_PTR(userdata);
292 int r;
293
294 assert(s);
295 assert(ra->event);
296 assert(router_lifetime_is_valid(ra->lifetime_usec));
297
298 r = sd_event_now(ra->event, CLOCK_BOOTTIME, &time_now);
299 if (r < 0)
300 goto fail;
301
302 r = radv_send_router(ra, NULL, ra->lifetime_usec);
303 if (r < 0)
304 log_radv_errno(ra, r, "Unable to send Router Advertisement, ignoring: %m");
305
306 /* RFC 4861, Section 6.2.4, sending initial Router Advertisements */
307 if (ra->ra_sent < RADV_MAX_INITIAL_RTR_ADVERTISEMENTS)
308 max_timeout = RADV_MAX_INITIAL_RTR_ADVERT_INTERVAL_USEC;
309 else
310 max_timeout = RADV_DEFAULT_MAX_TIMEOUT_USEC;
311
312 /* RFC 4861, Section 6.2.1, lifetime must be at least MaxRtrAdvInterval,
313 * so lower the interval here */
314 if (ra->lifetime_usec > 0)
315 max_timeout = MIN(max_timeout, ra->lifetime_usec);
316
317 if (max_timeout >= 9 * USEC_PER_SEC)
318 min_timeout = max_timeout / 3;
319 else
320 min_timeout = max_timeout * 3 / 4;
321
322 /* RFC 4861, Section 6.2.1.
323 * MaxRtrAdvInterval MUST be no less than 4 seconds and no greater than 1800 seconds.
324 * MinRtrAdvInterval MUST be no less than 3 seconds and no greater than .75 * MaxRtrAdvInterval. */
325 assert(max_timeout >= RADV_MIN_MAX_TIMEOUT_USEC);
326 assert(max_timeout <= RADV_MAX_MAX_TIMEOUT_USEC);
327 assert(min_timeout >= RADV_MIN_MIN_TIMEOUT_USEC);
328 assert(min_timeout <= max_timeout * 3 / 4);
329
330 timeout = min_timeout + random_u64_range(max_timeout - min_timeout);
331 log_radv(ra, "Next Router Advertisement in %s", FORMAT_TIMESPAN(timeout, USEC_PER_SEC));
332
333 r = event_reset_time(ra->event, &ra->timeout_event_source,
334 CLOCK_BOOTTIME,
335 usec_add(time_now, timeout), MSEC_PER_SEC,
336 radv_timeout, ra,
337 ra->event_priority, "radv-timeout", true);
338 if (r < 0)
339 goto fail;
340
341 ra->ra_sent++;
342
343 return 0;
344
345 fail:
346 sd_radv_stop(ra);
347
348 return 0;
349 }
350
351 int sd_radv_stop(sd_radv *ra) {
352 int r;
353
354 if (!ra)
355 return 0;
356
357 if (ra->state == RADV_STATE_IDLE)
358 return 0;
359
360 log_radv(ra, "Stopping IPv6 Router Advertisement daemon");
361
362 /* RFC 4861, Section 6.2.5:
363 * the router SHOULD transmit one or more (but not more than MAX_FINAL_RTR_ADVERTISEMENTS) final
364 * multicast Router Advertisements on the interface with a Router Lifetime field of zero. */
365 r = radv_send_router(ra, NULL, 0);
366 if (r < 0)
367 log_radv_errno(ra, r, "Unable to send last Router Advertisement with router lifetime set to zero, ignoring: %m");
368
369 radv_reset(ra);
370 ra->fd = safe_close(ra->fd);
371 ra->state = RADV_STATE_IDLE;
372
373 return 0;
374 }
375
376 static int radv_setup_recv_event(sd_radv *ra) {
377 int r;
378
379 assert(ra);
380 assert(ra->event);
381 assert(ra->ifindex > 0);
382
383 _cleanup_close_ int fd = -EBADF;
384 fd = icmp6_bind(ra->ifindex, /* is_router = */ true);
385 if (fd < 0)
386 return fd;
387
388 _cleanup_(sd_event_source_unrefp) sd_event_source *s = NULL;
389 r = sd_event_add_io(ra->event, &s, fd, EPOLLIN, radv_recv, ra);
390 if (r < 0)
391 return r;
392
393 r = sd_event_source_set_priority(s, ra->event_priority);
394 if (r < 0)
395 return r;
396
397 (void) sd_event_source_set_description(s, "radv-receive-message");
398
399 ra->fd = TAKE_FD(fd);
400 ra->recv_event_source = TAKE_PTR(s);
401 return 0;
402 }
403
404 int sd_radv_start(sd_radv *ra) {
405 int r;
406
407 assert_return(ra, -EINVAL);
408 assert_return(ra->event, -EINVAL);
409 assert_return(ra->ifindex > 0, -EINVAL);
410
411 if (ra->state != RADV_STATE_IDLE)
412 return 0;
413
414 r = radv_setup_recv_event(ra);
415 if (r < 0)
416 goto fail;
417
418 r = event_reset_time(ra->event, &ra->timeout_event_source,
419 CLOCK_BOOTTIME,
420 0, 0,
421 radv_timeout, ra,
422 ra->event_priority, "radv-timeout", true);
423 if (r < 0)
424 goto fail;
425
426 ra->state = RADV_STATE_ADVERTISING;
427
428 log_radv(ra, "Started IPv6 Router Advertisement daemon");
429
430 return 0;
431
432 fail:
433 radv_reset(ra);
434
435 return r;
436 }
437
438 int sd_radv_set_ifindex(sd_radv *ra, int ifindex) {
439 assert_return(ra, -EINVAL);
440 assert_return(ifindex > 0, -EINVAL);
441
442 if (ra->state != RADV_STATE_IDLE)
443 return -EBUSY;
444
445 ra->ifindex = ifindex;
446
447 return 0;
448 }
449
450 int sd_radv_set_ifname(sd_radv *ra, const char *ifname) {
451 assert_return(ra, -EINVAL);
452 assert_return(ifname, -EINVAL);
453
454 if (!ifname_valid_full(ifname, IFNAME_VALID_ALTERNATIVE))
455 return -EINVAL;
456
457 return free_and_strdup(&ra->ifname, ifname);
458 }
459
460 int sd_radv_get_ifname(sd_radv *ra, const char **ret) {
461 int r;
462
463 assert_return(ra, -EINVAL);
464
465 r = get_ifname(ra->ifindex, &ra->ifname);
466 if (r < 0)
467 return r;
468
469 if (ret)
470 *ret = ra->ifname;
471
472 return 0;
473 }
474
475 int sd_radv_set_mac(sd_radv *ra, const struct ether_addr *mac_addr) {
476 assert_return(ra, -EINVAL);
477
478 if (ra->state != RADV_STATE_IDLE)
479 return -EBUSY;
480
481 if (mac_addr)
482 ra->mac_addr = *mac_addr;
483 else
484 zero(ra->mac_addr);
485
486 return 0;
487 }
488
489 int sd_radv_set_mtu(sd_radv *ra, uint32_t mtu) {
490 assert_return(ra, -EINVAL);
491 assert_return(mtu >= 1280, -EINVAL);
492
493 ra->mtu = mtu;
494
495 return 0;
496 }
497
498 int sd_radv_set_hop_limit(sd_radv *ra, uint8_t hop_limit) {
499 assert_return(ra, -EINVAL);
500
501 if (ra->state != RADV_STATE_IDLE)
502 return -EBUSY;
503
504 ra->hop_limit = hop_limit;
505
506 return 0;
507 }
508
509 int sd_radv_set_retransmit(sd_radv *ra, uint64_t usec) {
510 assert_return(ra, -EINVAL);
511
512 if (ra->state != RADV_STATE_IDLE)
513 return -EBUSY;
514
515 if (usec > RADV_MAX_RETRANSMIT_USEC)
516 return -EINVAL;
517
518 ra->retransmit_usec = usec;
519 return 0;
520 }
521
522 int sd_radv_set_router_lifetime(sd_radv *ra, uint64_t usec) {
523 assert_return(ra, -EINVAL);
524
525 if (ra->state != RADV_STATE_IDLE)
526 return -EBUSY;
527
528 if (!router_lifetime_is_valid(usec))
529 return -EINVAL;
530
531 /* RFC 4191, Section 2.2, "...If the Router Lifetime is zero, the preference value MUST be set
532 * to (00) by the sender..." */
533 if (usec == 0 &&
534 (ra->flags & (0x3 << 3)) != (SD_NDISC_PREFERENCE_MEDIUM << 3))
535 return -EINVAL;
536
537 ra->lifetime_usec = usec;
538 return 0;
539 }
540
541 int sd_radv_set_managed_information(sd_radv *ra, int managed) {
542 assert_return(ra, -EINVAL);
543
544 if (ra->state != RADV_STATE_IDLE)
545 return -EBUSY;
546
547 SET_FLAG(ra->flags, ND_RA_FLAG_MANAGED, managed);
548
549 return 0;
550 }
551
552 int sd_radv_set_other_information(sd_radv *ra, int other) {
553 assert_return(ra, -EINVAL);
554
555 if (ra->state != RADV_STATE_IDLE)
556 return -EBUSY;
557
558 SET_FLAG(ra->flags, ND_RA_FLAG_OTHER, other);
559
560 return 0;
561 }
562
563 int sd_radv_set_preference(sd_radv *ra, unsigned preference) {
564 assert_return(ra, -EINVAL);
565 assert_return(IN_SET(preference,
566 SD_NDISC_PREFERENCE_LOW,
567 SD_NDISC_PREFERENCE_MEDIUM,
568 SD_NDISC_PREFERENCE_HIGH), -EINVAL);
569
570 /* RFC 4191, Section 2.2, "...If the Router Lifetime is zero, the preference value MUST be set
571 * to (00) by the sender..." */
572 if (ra->lifetime_usec == 0 && preference != SD_NDISC_PREFERENCE_MEDIUM)
573 return -EINVAL;
574
575 ra->flags = (ra->flags & ~(0x3 << 3)) | (preference << 3);
576
577 return 0;
578 }
579
580 int sd_radv_set_home_agent_information(sd_radv *ra, int home_agent) {
581 assert_return(ra, -EINVAL);
582
583 if (ra->state != RADV_STATE_IDLE)
584 return -EBUSY;
585
586 SET_FLAG(ra->flags, ND_RA_FLAG_HOME_AGENT, home_agent);
587
588 return 0;
589 }
590
591 int sd_radv_set_home_agent_preference(sd_radv *ra, uint16_t preference) {
592 assert_return(ra, -EINVAL);
593
594 if (ra->state != RADV_STATE_IDLE)
595 return -EBUSY;
596
597 ra->home_agent.nd_opt_home_agent_info_preference = htobe16(preference);
598
599 return 0;
600 }
601
602 int sd_radv_set_home_agent_lifetime(sd_radv *ra, uint64_t lifetime_usec) {
603 assert_return(ra, -EINVAL);
604
605 if (ra->state != RADV_STATE_IDLE)
606 return -EBUSY;
607
608 if (lifetime_usec > RADV_HOME_AGENT_MAX_LIFETIME_USEC)
609 return -EINVAL;
610
611 ra->home_agent.nd_opt_home_agent_info_lifetime = usec_to_be16_sec(lifetime_usec);
612 return 0;
613 }
614
615 int sd_radv_add_prefix(sd_radv *ra, sd_radv_prefix *p) {
616 sd_radv_prefix *found = NULL;
617 int r;
618
619 assert_return(ra, -EINVAL);
620 assert_return(p, -EINVAL);
621
622 /* Refuse prefixes that don't have a prefix set */
623 if (in6_addr_is_null(&p->opt.in6_addr))
624 return -ENOEXEC;
625
626 const char *addr_p = IN6_ADDR_PREFIX_TO_STRING(&p->opt.in6_addr, p->opt.prefixlen);
627
628 LIST_FOREACH(prefix, cur, ra->prefixes) {
629 r = in_addr_prefix_intersect(AF_INET6,
630 (const union in_addr_union*) &cur->opt.in6_addr,
631 cur->opt.prefixlen,
632 (const union in_addr_union*) &p->opt.in6_addr,
633 p->opt.prefixlen);
634 if (r < 0)
635 return r;
636 if (r == 0)
637 continue;
638
639 if (cur->opt.prefixlen == p->opt.prefixlen) {
640 found = cur;
641 break;
642 }
643
644 return log_radv_errno(ra, SYNTHETIC_ERRNO(EEXIST),
645 "IPv6 prefix %s conflicts with %s, ignoring.",
646 addr_p,
647 IN6_ADDR_PREFIX_TO_STRING(&cur->opt.in6_addr, cur->opt.prefixlen));
648 }
649
650 if (found) {
651 /* p and cur may be equivalent. First increment the reference counter. */
652 sd_radv_prefix_ref(p);
653
654 /* Then, remove the old entry. */
655 LIST_REMOVE(prefix, ra->prefixes, found);
656 sd_radv_prefix_unref(found);
657
658 /* Finally, add the new entry. */
659 LIST_APPEND(prefix, ra->prefixes, p);
660
661 log_radv(ra, "Updated/replaced IPv6 prefix %s (preferred: %s, valid: %s)",
662 addr_p,
663 FORMAT_TIMESPAN(p->lifetime_preferred_usec, USEC_PER_SEC),
664 FORMAT_TIMESPAN(p->lifetime_valid_usec, USEC_PER_SEC));
665 } else {
666 /* The prefix is new. Let's simply add it. */
667
668 sd_radv_prefix_ref(p);
669 LIST_APPEND(prefix, ra->prefixes, p);
670 ra->n_prefixes++;
671
672 log_radv(ra, "Added prefix %s", addr_p);
673 }
674
675 if (ra->state == RADV_STATE_IDLE)
676 return 0;
677
678 if (ra->ra_sent == 0)
679 return 0;
680
681 /* If RAs have already been sent, send an RA immediately to announce the newly-added prefix */
682 r = radv_send_router(ra, NULL, ra->lifetime_usec);
683 if (r < 0)
684 log_radv_errno(ra, r, "Unable to send Router Advertisement for added prefix %s, ignoring: %m", addr_p);
685 else
686 log_radv(ra, "Sent Router Advertisement for added/updated prefix %s.", addr_p);
687
688 return 0;
689 }
690
691 void sd_radv_remove_prefix(
692 sd_radv *ra,
693 const struct in6_addr *prefix,
694 unsigned char prefixlen) {
695
696 if (!ra)
697 return;
698
699 if (!prefix)
700 return;
701
702 LIST_FOREACH(prefix, cur, ra->prefixes) {
703 if (prefixlen != cur->opt.prefixlen)
704 continue;
705
706 if (!in6_addr_equal(prefix, &cur->opt.in6_addr))
707 continue;
708
709 LIST_REMOVE(prefix, ra->prefixes, cur);
710 ra->n_prefixes--;
711 sd_radv_prefix_unref(cur);
712 return;
713 }
714 }
715
716 int sd_radv_add_route_prefix(sd_radv *ra, sd_radv_route_prefix *p) {
717 sd_radv_route_prefix *found = NULL;
718 int r;
719
720 assert_return(ra, -EINVAL);
721 assert_return(p, -EINVAL);
722
723 const char *addr_p = IN6_ADDR_PREFIX_TO_STRING(&p->opt.in6_addr, p->opt.prefixlen);
724
725 LIST_FOREACH(prefix, cur, ra->route_prefixes) {
726 r = in_addr_prefix_intersect(AF_INET6,
727 (const union in_addr_union*) &cur->opt.in6_addr,
728 cur->opt.prefixlen,
729 (const union in_addr_union*) &p->opt.in6_addr,
730 p->opt.prefixlen);
731 if (r < 0)
732 return r;
733 if (r == 0)
734 continue;
735
736 if (cur->opt.prefixlen == p->opt.prefixlen) {
737 found = cur;
738 break;
739 }
740
741 return log_radv_errno(ra, SYNTHETIC_ERRNO(EEXIST),
742 "IPv6 route prefix %s conflicts with %s, ignoring.",
743 addr_p,
744 IN6_ADDR_PREFIX_TO_STRING(&cur->opt.in6_addr, cur->opt.prefixlen));
745 }
746
747 if (found) {
748 /* p and cur may be equivalent. First increment the reference counter. */
749 sd_radv_route_prefix_ref(p);
750
751 /* Then, remove the old entry. */
752 LIST_REMOVE(prefix, ra->route_prefixes, found);
753 sd_radv_route_prefix_unref(found);
754
755 /* Finally, add the new entry. */
756 LIST_APPEND(prefix, ra->route_prefixes, p);
757
758 log_radv(ra, "Updated/replaced IPv6 route prefix %s (lifetime: %s)",
759 strna(addr_p),
760 FORMAT_TIMESPAN(p->lifetime_usec, USEC_PER_SEC));
761 } else {
762 /* The route prefix is new. Let's simply add it. */
763
764 sd_radv_route_prefix_ref(p);
765 LIST_APPEND(prefix, ra->route_prefixes, p);
766 ra->n_route_prefixes++;
767
768 log_radv(ra, "Added route prefix %s", strna(addr_p));
769 }
770
771 if (ra->state == RADV_STATE_IDLE)
772 return 0;
773
774 if (ra->ra_sent == 0)
775 return 0;
776
777 /* If RAs have already been sent, send an RA immediately to announce the newly-added route prefix */
778 r = radv_send_router(ra, NULL, ra->lifetime_usec);
779 if (r < 0)
780 log_radv_errno(ra, r, "Unable to send Router Advertisement for added route prefix %s, ignoring: %m",
781 strna(addr_p));
782 else
783 log_radv(ra, "Sent Router Advertisement for added route prefix %s.", strna(addr_p));
784
785 return 0;
786 }
787
788 int sd_radv_add_pref64_prefix(sd_radv *ra, sd_radv_pref64_prefix *p) {
789 sd_radv_pref64_prefix *found = NULL;
790 int r;
791
792 assert_return(ra, -EINVAL);
793 assert_return(p, -EINVAL);
794
795 const char *addr_p = IN6_ADDR_PREFIX_TO_STRING(&p->in6_addr, p->prefixlen);
796
797 LIST_FOREACH(prefix, cur, ra->pref64_prefixes) {
798 r = in_addr_prefix_intersect(AF_INET6,
799 (const union in_addr_union*) &cur->in6_addr,
800 cur->prefixlen,
801 (const union in_addr_union*) &p->in6_addr,
802 p->prefixlen);
803 if (r < 0)
804 return r;
805 if (r == 0)
806 continue;
807
808 if (cur->prefixlen == p->prefixlen) {
809 found = cur;
810 break;
811 }
812
813 return log_radv_errno(ra, SYNTHETIC_ERRNO(EEXIST),
814 "IPv6 PREF64 prefix %s conflicts with %s, ignoring.",
815 addr_p,
816 IN6_ADDR_PREFIX_TO_STRING(&cur->in6_addr, cur->prefixlen));
817 }
818
819 if (found) {
820 /* p and cur may be equivalent. First increment the reference counter. */
821 sd_radv_pref64_prefix_ref(p);
822
823 /* Then, remove the old entry. */
824 LIST_REMOVE(prefix, ra->pref64_prefixes, found);
825 sd_radv_pref64_prefix_unref(found);
826
827 /* Finally, add the new entry. */
828 LIST_APPEND(prefix, ra->pref64_prefixes, p);
829
830 log_radv(ra, "Updated/replaced IPv6 PREF64 prefix %s (lifetime: %s)",
831 strna(addr_p),
832 FORMAT_TIMESPAN(p->lifetime_usec, USEC_PER_SEC));
833 } else {
834 /* The route prefix is new. Let's simply add it. */
835
836 sd_radv_pref64_prefix_ref(p);
837 LIST_APPEND(prefix, ra->pref64_prefixes, p);
838 ra->n_pref64_prefixes++;
839
840 log_radv(ra, "Added PREF64 prefix %s", strna(addr_p));
841 }
842
843 if (ra->state == RADV_STATE_IDLE)
844 return 0;
845
846 if (ra->ra_sent == 0)
847 return 0;
848
849 /* If RAs have already been sent, send an RA immediately to announce the newly-added route prefix */
850 r = radv_send_router(ra, NULL, ra->lifetime_usec);
851 if (r < 0)
852 log_radv_errno(ra, r, "Unable to send Router Advertisement for added PREF64 prefix %s, ignoring: %m",
853 strna(addr_p));
854 else
855 log_radv(ra, "Sent Router Advertisement for added PREF64 prefix %s.", strna(addr_p));
856
857 return 0;
858 }
859
860 int sd_radv_set_rdnss(
861 sd_radv *ra,
862 uint64_t lifetime_usec,
863 const struct in6_addr *dns,
864 size_t n_dns) {
865
866 _cleanup_free_ struct sd_radv_opt_dns *opt_rdnss = NULL;
867 size_t len;
868
869 assert_return(ra, -EINVAL);
870 assert_return(n_dns < 128, -EINVAL);
871
872 if (lifetime_usec > RADV_RDNSS_MAX_LIFETIME_USEC)
873 return -EINVAL;
874
875 if (!dns || n_dns == 0) {
876 ra->rdnss = mfree(ra->rdnss);
877 ra->n_rdnss = 0;
878
879 return 0;
880 }
881
882 len = sizeof(struct sd_radv_opt_dns) + sizeof(struct in6_addr) * n_dns;
883
884 opt_rdnss = malloc0(len);
885 if (!opt_rdnss)
886 return -ENOMEM;
887
888 opt_rdnss->type = RADV_OPT_RDNSS;
889 opt_rdnss->length = len / 8;
890 opt_rdnss->lifetime = usec_to_be32_sec(lifetime_usec);
891
892 memcpy(opt_rdnss + 1, dns, n_dns * sizeof(struct in6_addr));
893
894 free_and_replace(ra->rdnss, opt_rdnss);
895
896 ra->n_rdnss = n_dns;
897
898 return 0;
899 }
900
901 int sd_radv_set_dnssl(
902 sd_radv *ra,
903 uint64_t lifetime_usec,
904 char **search_list) {
905
906 _cleanup_free_ struct sd_radv_opt_dns *opt_dnssl = NULL;
907 size_t len = 0;
908 uint8_t *p;
909
910 assert_return(ra, -EINVAL);
911
912 if (lifetime_usec > RADV_DNSSL_MAX_LIFETIME_USEC)
913 return -EINVAL;
914
915 if (strv_isempty(search_list)) {
916 ra->dnssl = mfree(ra->dnssl);
917 return 0;
918 }
919
920 STRV_FOREACH(s, search_list)
921 len += strlen(*s) + 2;
922
923 len = (sizeof(struct sd_radv_opt_dns) + len + 7) & ~0x7;
924
925 opt_dnssl = malloc0(len);
926 if (!opt_dnssl)
927 return -ENOMEM;
928
929 opt_dnssl->type = RADV_OPT_DNSSL;
930 opt_dnssl->length = len / 8;
931 opt_dnssl->lifetime = usec_to_be32_sec(lifetime_usec);
932
933 p = (uint8_t *)(opt_dnssl + 1);
934 len -= sizeof(struct sd_radv_opt_dns);
935
936 STRV_FOREACH(s, search_list) {
937 int r;
938
939 r = dns_name_to_wire_format(*s, p, len, false);
940 if (r < 0)
941 return r;
942
943 if (len < (size_t)r)
944 return -ENOBUFS;
945
946 p += r;
947 len -= r;
948 }
949
950 free_and_replace(ra->dnssl, opt_dnssl);
951
952 return 0;
953 }
954
955 int sd_radv_prefix_new(sd_radv_prefix **ret) {
956 sd_radv_prefix *p;
957
958 assert_return(ret, -EINVAL);
959
960 p = new(sd_radv_prefix, 1);
961 if (!p)
962 return -ENOMEM;
963
964 *p = (sd_radv_prefix) {
965 .n_ref = 1,
966
967 .opt.type = ND_OPT_PREFIX_INFORMATION,
968 .opt.length = (sizeof(p->opt) - 1)/8 + 1,
969 .opt.prefixlen = 64,
970
971 /* RFC 4861, Section 6.2.1 */
972 .opt.flags = ND_OPT_PI_FLAG_ONLINK|ND_OPT_PI_FLAG_AUTO,
973
974 .lifetime_valid_usec = RADV_DEFAULT_VALID_LIFETIME_USEC,
975 .lifetime_preferred_usec = RADV_DEFAULT_PREFERRED_LIFETIME_USEC,
976 .valid_until = USEC_INFINITY,
977 .preferred_until = USEC_INFINITY,
978 };
979
980 *ret = p;
981 return 0;
982 }
983
984 DEFINE_PUBLIC_TRIVIAL_REF_UNREF_FUNC(sd_radv_prefix, sd_radv_prefix, mfree);
985
986 int sd_radv_prefix_set_prefix(
987 sd_radv_prefix *p,
988 const struct in6_addr *in6_addr,
989 unsigned char prefixlen) {
990
991 assert_return(p, -EINVAL);
992 assert_return(in6_addr, -EINVAL);
993
994 if (prefixlen < 3 || prefixlen > 128)
995 return -EINVAL;
996
997 if (prefixlen > 64)
998 /* unusual but allowed, log it */
999 log_radv(NULL, "Unusual prefix length %d greater than 64", prefixlen);
1000
1001 p->opt.in6_addr = *in6_addr;
1002 p->opt.prefixlen = prefixlen;
1003
1004 return 0;
1005 }
1006
1007 int sd_radv_prefix_get_prefix(
1008 sd_radv_prefix *p,
1009 struct in6_addr *ret_in6_addr,
1010 unsigned char *ret_prefixlen) {
1011
1012 assert_return(p, -EINVAL);
1013 assert_return(ret_in6_addr, -EINVAL);
1014 assert_return(ret_prefixlen, -EINVAL);
1015
1016 *ret_in6_addr = p->opt.in6_addr;
1017 *ret_prefixlen = p->opt.prefixlen;
1018
1019 return 0;
1020 }
1021
1022 int sd_radv_prefix_set_onlink(sd_radv_prefix *p, int onlink) {
1023 assert_return(p, -EINVAL);
1024
1025 SET_FLAG(p->opt.flags, ND_OPT_PI_FLAG_ONLINK, onlink);
1026
1027 return 0;
1028 }
1029
1030 int sd_radv_prefix_set_address_autoconfiguration(sd_radv_prefix *p, int address_autoconfiguration) {
1031 assert_return(p, -EINVAL);
1032
1033 SET_FLAG(p->opt.flags, ND_OPT_PI_FLAG_AUTO, address_autoconfiguration);
1034
1035 return 0;
1036 }
1037
1038 int sd_radv_prefix_set_valid_lifetime(sd_radv_prefix *p, uint64_t lifetime_usec, uint64_t valid_until) {
1039 assert_return(p, -EINVAL);
1040
1041 p->lifetime_valid_usec = lifetime_usec;
1042 p->valid_until = valid_until;
1043
1044 return 0;
1045 }
1046
1047 int sd_radv_prefix_set_preferred_lifetime(sd_radv_prefix *p, uint64_t lifetime_usec, uint64_t valid_until) {
1048 assert_return(p, -EINVAL);
1049
1050 p->lifetime_preferred_usec = lifetime_usec;
1051 p->preferred_until = valid_until;
1052
1053 return 0;
1054 }
1055
1056 int sd_radv_route_prefix_new(sd_radv_route_prefix **ret) {
1057 sd_radv_route_prefix *p;
1058
1059 assert_return(ret, -EINVAL);
1060
1061 p = new(sd_radv_route_prefix, 1);
1062 if (!p)
1063 return -ENOMEM;
1064
1065 *p = (sd_radv_route_prefix) {
1066 .n_ref = 1,
1067
1068 .opt.type = RADV_OPT_ROUTE_INFORMATION,
1069 .opt.length = DIV_ROUND_UP(sizeof(p->opt), 8),
1070 .opt.prefixlen = 64,
1071
1072 .lifetime_usec = RADV_DEFAULT_VALID_LIFETIME_USEC,
1073 .valid_until = USEC_INFINITY,
1074 };
1075
1076 *ret = p;
1077 return 0;
1078 }
1079
1080 DEFINE_PUBLIC_TRIVIAL_REF_UNREF_FUNC(sd_radv_route_prefix, sd_radv_route_prefix, mfree);
1081
1082 int sd_radv_route_prefix_set_prefix(
1083 sd_radv_route_prefix *p,
1084 const struct in6_addr *in6_addr,
1085 unsigned char prefixlen) {
1086
1087 assert_return(p, -EINVAL);
1088 assert_return(in6_addr, -EINVAL);
1089
1090 if (prefixlen > 128)
1091 return -EINVAL;
1092
1093 if (prefixlen > 64)
1094 /* unusual but allowed, log it */
1095 log_radv(NULL, "Unusual prefix length %u greater than 64", prefixlen);
1096
1097 p->opt.in6_addr = *in6_addr;
1098 p->opt.prefixlen = prefixlen;
1099
1100 return 0;
1101 }
1102
1103 int sd_radv_route_prefix_set_lifetime(sd_radv_route_prefix *p, uint64_t lifetime_usec, uint64_t valid_until) {
1104 assert_return(p, -EINVAL);
1105
1106 p->lifetime_usec = lifetime_usec;
1107 p->valid_until = valid_until;
1108
1109 return 0;
1110 }
1111
1112 int sd_radv_pref64_prefix_new(sd_radv_pref64_prefix **ret) {
1113 sd_radv_pref64_prefix *p;
1114
1115 assert_return(ret, -EINVAL);
1116
1117 p = new(sd_radv_pref64_prefix, 1);
1118 if (!p)
1119 return -ENOMEM;
1120
1121 *p = (sd_radv_pref64_prefix) {
1122 .n_ref = 1,
1123
1124 .opt.type = RADV_OPT_PREF64,
1125 .opt.length = 2,
1126 };
1127
1128 *ret = p;
1129 return 0;
1130 }
1131
1132 DEFINE_PUBLIC_TRIVIAL_REF_UNREF_FUNC(sd_radv_pref64_prefix, sd_radv_pref64_prefix, mfree);
1133
1134 int sd_radv_pref64_prefix_set_prefix(
1135 sd_radv_pref64_prefix *p,
1136 const struct in6_addr *prefix,
1137 uint8_t prefixlen,
1138 uint64_t lifetime_usec) {
1139
1140 uint16_t pref64_lifetime;
1141 uint8_t prefixlen_code;
1142 int r;
1143
1144 assert_return(p, -EINVAL);
1145 assert_return(prefix, -EINVAL);
1146
1147 r = pref64_prefix_length_to_plc(prefixlen, &prefixlen_code);
1148 if (r < 0)
1149 return log_radv_errno(NULL, r,
1150 "Unsupported PREF64 prefix length %u. Valid lengths are 32, 40, 48, 56, 64 and 96", prefixlen);
1151
1152 if (lifetime_usec > PREF64_MAX_LIFETIME_USEC)
1153 return -EINVAL;
1154
1155 /* RFC 8781 - 4.1 rounding up lifetime to multiply of 8 */
1156 pref64_lifetime = DIV_ROUND_UP(lifetime_usec, 8 * USEC_PER_SEC) << 3;
1157 pref64_lifetime |= prefixlen_code;
1158
1159 unaligned_write_be16(&p->opt.lifetime_and_plc, pref64_lifetime);
1160 memcpy(&p->opt.prefix, prefix, sizeof(p->opt.prefix));
1161
1162 p->in6_addr = *prefix;
1163 p->prefixlen = prefixlen;
1164
1165 return 0;
1166 }