]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/network/networkd-dhcp4.c
networkd: Add support for blacklisting servers
[thirdparty/systemd.git] / src / network / networkd-dhcp4.c
1 /* SPDX-License-Identifier: LGPL-2.1+ */
2
3 #include <netinet/ether.h>
4 #include <linux/if.h>
5
6 #include "alloc-util.h"
7 #include "hostname-util.h"
8 #include "parse-util.h"
9 #include "network-internal.h"
10 #include "networkd-link.h"
11 #include "networkd-manager.h"
12 #include "networkd-network.h"
13 #include "string-util.h"
14 #include "sysctl-util.h"
15
16 static int dhcp4_route_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) {
17 int r;
18
19 assert(link);
20 assert(link->dhcp4_messages > 0);
21
22 link->dhcp4_messages--;
23
24 r = sd_netlink_message_get_errno(m);
25 if (r < 0 && r != -EEXIST) {
26 log_link_error_errno(link, r, "Could not set DHCPv4 route: %m");
27 link_enter_failed(link);
28 }
29
30 if (link->dhcp4_messages == 0) {
31 link->dhcp4_configured = true;
32 link_check_ready(link);
33 }
34
35 return 1;
36 }
37
38 static int route_scope_from_address(const Route *route, const struct in_addr *self_addr) {
39 assert(route);
40 assert(self_addr);
41
42 if (in_addr_is_localhost(AF_INET, &route->dst) ||
43 (self_addr->s_addr && route->dst.in.s_addr == self_addr->s_addr))
44 return RT_SCOPE_HOST;
45 else if (in4_addr_is_null(&route->gw.in))
46 return RT_SCOPE_LINK;
47 else
48 return RT_SCOPE_UNIVERSE;
49 }
50
51 static int link_set_dhcp_routes(Link *link) {
52 _cleanup_free_ sd_dhcp_route **static_routes = NULL;
53 bool classless_route = false, static_route = false;
54 const struct in_addr *router;
55 struct in_addr address;
56 int r, n, i;
57 uint32_t table;
58
59 assert(link);
60
61 if (!link->dhcp_lease) /* link went down while we configured the IP addresses? */
62 return 0;
63
64 if (!link->network) /* link went down while we configured the IP addresses? */
65 return 0;
66
67 if (!link->network->dhcp_use_routes)
68 return 0;
69
70 table = link_get_dhcp_route_table(link);
71
72 r = sd_dhcp_lease_get_address(link->dhcp_lease, &address);
73 if (r < 0)
74 return log_link_warning_errno(link, r, "DHCP error: could not get address: %m");
75
76 n = sd_dhcp_lease_get_routes(link->dhcp_lease, &static_routes);
77 if (n == -ENODATA)
78 log_link_debug_errno(link, n, "DHCP: No routes received from DHCP server: %m");
79 else if (n < 0)
80 log_link_debug_errno(link, n, "DHCP error: could not get routes: %m");
81
82 for (i = 0; i < n; i++) {
83 switch (sd_dhcp_route_get_option(static_routes[i])) {
84 case SD_DHCP_OPTION_CLASSLESS_STATIC_ROUTE:
85 classless_route = true;
86 break;
87 case SD_DHCP_OPTION_STATIC_ROUTE:
88 static_route = true;
89 break;
90 }
91 }
92
93 for (i = 0; i < n; i++) {
94 _cleanup_(route_freep) Route *route = NULL;
95
96 /* if the DHCP server returns both a Classless Static Routes option and a Static Routes option,
97 the DHCP client MUST ignore the Static Routes option. */
98 if (classless_route &&
99 sd_dhcp_route_get_option(static_routes[i]) != SD_DHCP_OPTION_CLASSLESS_STATIC_ROUTE)
100 continue;
101
102 r = route_new(&route);
103 if (r < 0)
104 return log_link_error_errno(link, r, "Could not allocate route: %m");
105
106 route->family = AF_INET;
107 route->protocol = RTPROT_DHCP;
108 assert_se(sd_dhcp_route_get_gateway(static_routes[i], &route->gw.in) >= 0);
109 assert_se(sd_dhcp_route_get_destination(static_routes[i], &route->dst.in) >= 0);
110 assert_se(sd_dhcp_route_get_destination_prefix_length(static_routes[i], &route->dst_prefixlen) >= 0);
111 route->priority = link->network->dhcp_route_metric;
112 route->table = table;
113 route->scope = route_scope_from_address(route, &address);
114
115 r = route_configure(route, link, dhcp4_route_handler);
116 if (r < 0)
117 return log_link_warning_errno(link, r, "Could not set host route: %m");
118
119 link->dhcp4_messages++;
120 }
121
122 r = sd_dhcp_lease_get_router(link->dhcp_lease, &router);
123 if (IN_SET(r, 0, -ENODATA))
124 log_link_info(link, "DHCP: No gateway received from DHCP server.");
125 else if (r < 0)
126 log_link_warning_errno(link, r, "DHCP error: could not get gateway: %m");
127 else if (in4_addr_is_null(&router[0]))
128 log_link_info(link, "DHCP: Received gateway is null.");
129
130 /* According to RFC 3442: If the DHCP server returns both a Classless Static Routes option and
131 a Router option, the DHCP client MUST ignore the Router option. */
132 if (classless_route && static_route)
133 log_link_warning(link, "Classless static routes received from DHCP server: ignoring static-route option and router option");
134
135 if (r > 0 && !classless_route && !in4_addr_is_null(&router[0])) {
136 _cleanup_(route_freep) Route *route = NULL, *route_gw = NULL;
137
138 r = route_new(&route_gw);
139 if (r < 0)
140 return log_link_error_errno(link, r, "Could not allocate route: %m");
141
142 /* The dhcp netmask may mask out the gateway. Add an explicit
143 * route for the gw host so that we can route no matter the
144 * netmask or existing kernel route tables. */
145 route_gw->family = AF_INET;
146 route_gw->dst.in = router[0];
147 route_gw->dst_prefixlen = 32;
148 route_gw->prefsrc.in = address;
149 route_gw->scope = RT_SCOPE_LINK;
150 route_gw->protocol = RTPROT_DHCP;
151 route_gw->priority = link->network->dhcp_route_metric;
152 route_gw->table = table;
153
154 r = route_configure(route_gw, link, dhcp4_route_handler);
155 if (r < 0)
156 return log_link_warning_errno(link, r, "Could not set host route: %m");
157
158 link->dhcp4_messages++;
159
160 r = route_new(&route);
161 if (r < 0)
162 return log_link_error_errno(link, r, "Could not allocate route: %m");
163
164 route->family = AF_INET;
165 route->gw.in = router[0];
166 route->prefsrc.in = address;
167 route->protocol = RTPROT_DHCP;
168 route->priority = link->network->dhcp_route_metric;
169 route->table = table;
170
171 r = route_configure(route, link, dhcp4_route_handler);
172 if (r < 0) {
173 log_link_warning_errno(link, r, "Could not set routes: %m");
174 link_enter_failed(link);
175 return r;
176 }
177
178 link->dhcp4_messages++;
179 }
180
181 return 0;
182 }
183
184 static int dhcp_lease_lost(Link *link) {
185 _cleanup_(address_freep) Address *address = NULL;
186 const struct in_addr *router;
187 struct in_addr addr;
188 struct in_addr netmask;
189 unsigned prefixlen = 0;
190 int r;
191
192 assert(link);
193 assert(link->dhcp_lease);
194
195 log_link_warning(link, "DHCP lease lost");
196
197 if (link->network->dhcp_use_routes) {
198 _cleanup_free_ sd_dhcp_route **routes = NULL;
199 int n, i;
200
201 n = sd_dhcp_lease_get_routes(link->dhcp_lease, &routes);
202 if (n >= 0) {
203 for (i = 0; i < n; i++) {
204 _cleanup_(route_freep) Route *route = NULL;
205
206 r = route_new(&route);
207 if (r >= 0) {
208 route->family = AF_INET;
209 assert_se(sd_dhcp_route_get_gateway(routes[i], &route->gw.in) >= 0);
210 assert_se(sd_dhcp_route_get_destination(routes[i], &route->dst.in) >= 0);
211 assert_se(sd_dhcp_route_get_destination_prefix_length(routes[i], &route->dst_prefixlen) >= 0);
212
213 route_remove(route, link, NULL);
214 }
215 }
216 }
217
218 r = sd_dhcp_lease_get_router(link->dhcp_lease, &router);
219 if (r > 0 && !in4_addr_is_null(&router[0])) {
220 _cleanup_(route_freep) Route *route_gw = NULL;
221 _cleanup_(route_freep) Route *route = NULL;
222
223 r = route_new(&route_gw);
224 if (r >= 0) {
225 route_gw->family = AF_INET;
226 route_gw->dst.in = router[0];
227 route_gw->dst_prefixlen = 32;
228 route_gw->scope = RT_SCOPE_LINK;
229
230 route_remove(route_gw, link, NULL);
231 }
232
233 r = route_new(&route);
234 if (r >= 0) {
235 route->family = AF_INET;
236 route->gw.in = router[0];
237
238 route_remove(route, link, NULL);
239 }
240 }
241 }
242
243 r = address_new(&address);
244 if (r >= 0) {
245 r = sd_dhcp_lease_get_address(link->dhcp_lease, &addr);
246 if (r >= 0) {
247 r = sd_dhcp_lease_get_netmask(link->dhcp_lease, &netmask);
248 if (r >= 0)
249 prefixlen = in4_addr_netmask_to_prefixlen(&netmask);
250
251 address->family = AF_INET;
252 address->in_addr.in = addr;
253 address->prefixlen = prefixlen;
254
255 address_remove(address, link, NULL);
256 }
257 }
258
259 if (link->network->dhcp_use_mtu) {
260 uint16_t mtu;
261
262 r = sd_dhcp_lease_get_mtu(link->dhcp_lease, &mtu);
263 if (r >= 0 && link->original_mtu != mtu) {
264 r = link_set_mtu(link, link->original_mtu, true);
265 if (r < 0) {
266 log_link_warning(link,
267 "DHCP error: could not reset MTU");
268 link_enter_failed(link);
269 return r;
270 }
271 }
272 }
273
274 if (link->network->dhcp_use_hostname) {
275 const char *hostname = NULL;
276
277 if (link->network->dhcp_hostname)
278 hostname = link->network->dhcp_hostname;
279 else
280 (void) sd_dhcp_lease_get_hostname(link->dhcp_lease, &hostname);
281
282 if (hostname) {
283 /* If a hostname was set due to the lease, then unset it now. */
284 r = manager_set_hostname(link->manager, NULL);
285 if (r < 0)
286 log_link_warning_errno(link, r, "Failed to reset transient hostname: %m");
287 }
288 }
289
290 link->dhcp_lease = sd_dhcp_lease_unref(link->dhcp_lease);
291 link_dirty(link);
292 link->dhcp4_configured = false;
293
294 return 0;
295 }
296
297 static int dhcp4_address_handler(sd_netlink *rtnl, sd_netlink_message *m, Link *link) {
298 int r;
299
300 assert(link);
301
302 r = sd_netlink_message_get_errno(m);
303 if (r < 0 && r != -EEXIST) {
304 log_link_error_errno(link, r, "Could not set DHCPv4 address: %m");
305 link_enter_failed(link);
306 } else if (r >= 0)
307 manager_rtnl_process_address(rtnl, m, link->manager);
308
309 link_set_dhcp_routes(link);
310
311 /* Add back static routes since kernel removes while DHCPv4 address is removed from when lease expires */
312 link_request_set_routes(link);
313
314 if (link->dhcp4_messages == 0) {
315 link->dhcp4_configured = true;
316 link_check_ready(link);
317 }
318
319 return 1;
320 }
321
322 static int dhcp4_update_address(Link *link,
323 struct in_addr *address,
324 struct in_addr *netmask,
325 uint32_t lifetime) {
326 _cleanup_(address_freep) Address *addr = NULL;
327 unsigned prefixlen;
328 int r;
329
330 assert(address);
331 assert(netmask);
332 assert(lifetime);
333
334 prefixlen = in4_addr_netmask_to_prefixlen(netmask);
335
336 r = address_new(&addr);
337 if (r < 0)
338 return r;
339
340 addr->family = AF_INET;
341 addr->in_addr.in.s_addr = address->s_addr;
342 addr->cinfo.ifa_prefered = lifetime;
343 addr->cinfo.ifa_valid = lifetime;
344 addr->prefixlen = prefixlen;
345 addr->broadcast.s_addr = address->s_addr | ~netmask->s_addr;
346
347 /* allow reusing an existing address and simply update its lifetime
348 * in case it already exists */
349 r = address_configure(addr, link, dhcp4_address_handler, true);
350 if (r < 0)
351 return r;
352
353 return 0;
354 }
355
356 static int dhcp_lease_renew(sd_dhcp_client *client, Link *link) {
357 sd_dhcp_lease *lease;
358 struct in_addr address;
359 struct in_addr netmask;
360 uint32_t lifetime = CACHE_INFO_INFINITY_LIFE_TIME;
361 int r;
362
363 assert(link);
364 assert(client);
365 assert(link->network);
366
367 r = sd_dhcp_client_get_lease(client, &lease);
368 if (r < 0)
369 return log_link_warning_errno(link, r, "DHCP error: no lease: %m");
370
371 sd_dhcp_lease_unref(link->dhcp_lease);
372 link->dhcp4_configured = false;
373 link->dhcp_lease = sd_dhcp_lease_ref(lease);
374 link_dirty(link);
375
376 r = sd_dhcp_lease_get_address(lease, &address);
377 if (r < 0)
378 return log_link_warning_errno(link, r, "DHCP error: no address: %m");
379
380 r = sd_dhcp_lease_get_netmask(lease, &netmask);
381 if (r < 0)
382 return log_link_warning_errno(link, r, "DHCP error: no netmask: %m");
383
384 if (!link->network->dhcp_critical) {
385 r = sd_dhcp_lease_get_lifetime(link->dhcp_lease, &lifetime);
386 if (r < 0)
387 return log_link_warning_errno(link, r, "DHCP error: no lifetime: %m");
388 }
389
390 r = dhcp4_update_address(link, &address, &netmask, lifetime);
391 if (r < 0) {
392 log_link_warning_errno(link, r, "Could not update IP address: %m");
393 link_enter_failed(link);
394 return r;
395 }
396
397 return 0;
398 }
399
400 static int dhcp_lease_acquired(sd_dhcp_client *client, Link *link) {
401 const struct in_addr *router;
402 sd_dhcp_lease *lease;
403 struct in_addr address;
404 struct in_addr netmask;
405 unsigned prefixlen;
406 uint32_t lifetime = CACHE_INFO_INFINITY_LIFE_TIME;
407 int r;
408
409 assert(client);
410 assert(link);
411
412 r = sd_dhcp_client_get_lease(client, &lease);
413 if (r < 0)
414 return log_link_error_errno(link, r, "DHCP error: No lease: %m");
415
416 r = sd_dhcp_lease_get_address(lease, &address);
417 if (r < 0)
418 return log_link_error_errno(link, r, "DHCP error: No address: %m");
419
420 r = sd_dhcp_lease_get_netmask(lease, &netmask);
421 if (r < 0)
422 return log_link_error_errno(link, r, "DHCP error: No netmask: %m");
423
424 prefixlen = in4_addr_netmask_to_prefixlen(&netmask);
425
426 r = sd_dhcp_lease_get_router(lease, &router);
427 if (r < 0 && r != -ENODATA)
428 return log_link_error_errno(link, r, "DHCP error: Could not get gateway: %m");
429
430 if (r > 0 && !in4_addr_is_null(&router[0]))
431 log_struct(LOG_INFO,
432 LOG_LINK_INTERFACE(link),
433 LOG_LINK_MESSAGE(link, "DHCPv4 address %u.%u.%u.%u/%u via %u.%u.%u.%u",
434 ADDRESS_FMT_VAL(address),
435 prefixlen,
436 ADDRESS_FMT_VAL(router[0])),
437 "ADDRESS=%u.%u.%u.%u", ADDRESS_FMT_VAL(address),
438 "PREFIXLEN=%u", prefixlen,
439 "GATEWAY=%u.%u.%u.%u", ADDRESS_FMT_VAL(router[0]));
440 else
441 log_struct(LOG_INFO,
442 LOG_LINK_INTERFACE(link),
443 LOG_LINK_MESSAGE(link, "DHCPv4 address %u.%u.%u.%u/%u",
444 ADDRESS_FMT_VAL(address),
445 prefixlen),
446 "ADDRESS=%u.%u.%u.%u", ADDRESS_FMT_VAL(address),
447 "PREFIXLEN=%u", prefixlen);
448
449 link->dhcp_lease = sd_dhcp_lease_ref(lease);
450 link_dirty(link);
451
452 if (link->network->dhcp_use_mtu) {
453 uint16_t mtu;
454
455 r = sd_dhcp_lease_get_mtu(lease, &mtu);
456 if (r >= 0) {
457 r = link_set_mtu(link, mtu, true);
458 if (r < 0)
459 log_link_error_errno(link, r, "Failed to set MTU to %" PRIu16 ": %m", mtu);
460 }
461 }
462
463 if (link->network->dhcp_use_hostname) {
464 const char *dhcpname = NULL;
465 _cleanup_free_ char *hostname = NULL;
466
467 if (link->network->dhcp_hostname)
468 dhcpname = link->network->dhcp_hostname;
469 else
470 (void) sd_dhcp_lease_get_hostname(lease, &dhcpname);
471
472 if (dhcpname) {
473 r = shorten_overlong(dhcpname, &hostname);
474 if (r < 0)
475 log_link_warning_errno(link, r, "Unable to shorten overlong DHCP hostname '%s', ignoring: %m", dhcpname);
476 if (r == 1)
477 log_link_notice(link, "Overlong DHCP hostname received, shortened from '%s' to '%s'", dhcpname, hostname);
478 }
479
480 if (hostname) {
481 r = manager_set_hostname(link->manager, hostname);
482 if (r < 0)
483 log_link_error_errno(link, r, "Failed to set transient hostname to '%s': %m", hostname);
484 }
485 }
486
487 if (link->network->dhcp_use_timezone) {
488 const char *tz = NULL;
489
490 (void) sd_dhcp_lease_get_timezone(link->dhcp_lease, &tz);
491
492 if (tz) {
493 r = manager_set_timezone(link->manager, tz);
494 if (r < 0)
495 log_link_error_errno(link, r, "Failed to set timezone to '%s': %m", tz);
496 }
497 }
498
499 if (!link->network->dhcp_critical) {
500 r = sd_dhcp_lease_get_lifetime(link->dhcp_lease, &lifetime);
501 if (r < 0)
502 return log_link_warning_errno(link, r, "DHCP error: no lifetime: %m");
503 }
504
505 r = dhcp4_update_address(link, &address, &netmask, lifetime);
506 if (r < 0) {
507 log_link_warning_errno(link, r, "Could not update IP address: %m");
508 link_enter_failed(link);
509 return r;
510 }
511
512 return 0;
513 }
514
515 static int dhcp_server_is_black_listed(Link *link, sd_dhcp_client *client) {
516 sd_dhcp_lease *lease;
517 struct in_addr addr;
518 int r;
519
520 assert(link);
521 assert(link->network);
522 assert(client);
523
524 r = sd_dhcp_client_get_lease(client, &lease);
525 if (r < 0)
526 return log_link_error_errno(link, r, "Failed to get DHCP lease: %m");
527
528 r = sd_dhcp_lease_get_server_identifier(lease, &addr);
529 if (r < 0)
530 return log_link_debug_errno(link, r, "Failed to get DHCP server ip address: %m");
531
532 if (set_contains(link->network->dhcp_black_listed_ip, UINT32_TO_PTR(addr.s_addr))) {
533 log_struct(LOG_DEBUG,
534 LOG_LINK_INTERFACE(link),
535 LOG_LINK_MESSAGE(link, "DHCPv4 ip '%u.%u.%u.%u' found in black listed ip addresses, ignoring offer",
536 ADDRESS_FMT_VAL(addr)));
537 return true;
538 }
539
540 return false;
541 }
542
543 static int dhcp4_handler(sd_dhcp_client *client, int event, void *userdata) {
544 Link *link = userdata;
545 int r = 0;
546
547 assert(link);
548 assert(link->network);
549 assert(link->manager);
550
551 if (IN_SET(link->state, LINK_STATE_FAILED, LINK_STATE_LINGER))
552 return 0;
553
554 switch (event) {
555 case SD_DHCP_CLIENT_EVENT_STOP:
556
557 if (link_ipv4ll_fallback_enabled(link)) {
558 assert(link->ipv4ll);
559
560 log_link_debug(link, "DHCP client is stopped. Acquiring IPv4 link-local address");
561
562 r = sd_ipv4ll_start(link->ipv4ll);
563 if (r < 0)
564 return log_link_warning_errno(link, r, "Could not acquire IPv4 link-local address: %m");
565 }
566
567 _fallthrough_;
568 case SD_DHCP_CLIENT_EVENT_EXPIRED:
569 case SD_DHCP_CLIENT_EVENT_IP_CHANGE:
570
571 if (link->network->dhcp_critical) {
572 log_link_error(link, "DHCPv4 connection considered system critical, ignoring request to reconfigure it.");
573 return 0;
574 }
575
576 if (link->dhcp_lease) {
577 r = dhcp_lease_lost(link);
578 if (r < 0) {
579 link_enter_failed(link);
580 return r;
581 }
582 }
583
584 if (event == SD_DHCP_CLIENT_EVENT_IP_CHANGE) {
585 r = dhcp_lease_acquired(client, link);
586 if (r < 0) {
587 link_enter_failed(link);
588 return r;
589 }
590 }
591
592 break;
593 case SD_DHCP_CLIENT_EVENT_RENEW:
594 r = dhcp_lease_renew(client, link);
595 if (r < 0) {
596 link_enter_failed(link);
597 return r;
598 }
599 break;
600 case SD_DHCP_CLIENT_EVENT_IP_ACQUIRE:
601 r = dhcp_lease_acquired(client, link);
602 if (r < 0) {
603 link_enter_failed(link);
604 return r;
605 }
606 break;
607 case SD_DHCP_CLIENT_EVENT_SELECTING:
608 r = dhcp_server_is_black_listed(link, client);
609 if (r < 0)
610 return r;
611 if (r != 0)
612 return -ENOMSG;
613 break;
614 default:
615 if (event < 0)
616 log_link_warning_errno(link, event, "DHCP error: Client failed: %m");
617 else
618 log_link_warning(link, "DHCP unknown event: %i", event);
619 break;
620 }
621
622 return 0;
623 }
624
625 static int dhcp4_set_hostname(Link *link) {
626 _cleanup_free_ char *hostname = NULL;
627 const char *hn;
628 int r;
629
630 assert(link);
631
632 if (!link->network->dhcp_send_hostname)
633 hn = NULL;
634 else if (link->network->dhcp_hostname)
635 hn = link->network->dhcp_hostname;
636 else {
637 r = gethostname_strict(&hostname);
638 if (r < 0 && r != -ENXIO) /* ENXIO: no hostname set or hostname is "localhost" */
639 return r;
640
641 hn = hostname;
642 }
643
644 r = sd_dhcp_client_set_hostname(link->dhcp_client, hn);
645 if (r == -EINVAL && hostname)
646 /* Ignore error when the machine's hostname is not suitable to send in DHCP packet. */
647 log_link_warning_errno(link, r, "DHCP4 CLIENT: Failed to set hostname from kernel hostname, ignoring: %m");
648 else if (r < 0)
649 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set hostname: %m");
650
651 return 0;
652 }
653
654 static bool promote_secondaries_enabled(const char *ifname) {
655 _cleanup_free_ char *promote_secondaries_sysctl = NULL;
656 char *promote_secondaries_path;
657 int r;
658
659 promote_secondaries_path = strjoina("net/ipv4/conf/", ifname, "/promote_secondaries");
660 r = sysctl_read(promote_secondaries_path, &promote_secondaries_sysctl);
661 if (r < 0) {
662 log_debug_errno(r, "Cannot read sysctl %s", promote_secondaries_path);
663 return false;
664 }
665
666 truncate_nl(promote_secondaries_sysctl);
667 r = parse_boolean(promote_secondaries_sysctl);
668 if (r < 0)
669 log_warning_errno(r, "Cannot parse sysctl %s with content %s as boolean", promote_secondaries_path, promote_secondaries_sysctl);
670 return r > 0;
671 }
672
673 /* dhcp4_set_promote_secondaries will ensure this interface has
674 * the "promote_secondaries" option in the kernel set. If this sysctl
675 * is not set DHCP will work only as long as the IP address does not
676 * changes between leases. The kernel will remove all secondary IP
677 * addresses of an interface otherwise. The way systemd-network works
678 * is that the new IP of a lease is added as a secondary IP and when
679 * the primary one expires it relies on the kernel to promote the
680 * secondary IP. See also https://github.com/systemd/systemd/issues/7163
681 */
682 int dhcp4_set_promote_secondaries(Link *link) {
683 int r;
684
685 assert(link);
686 assert(link->network);
687 assert(link->network->dhcp & ADDRESS_FAMILY_IPV4);
688
689 /* check if the kernel has promote_secondaries enabled for our
690 * interface. If it is not globally enabled or enabled for the
691 * specific interface we must either enable it.
692 */
693 if (!(promote_secondaries_enabled("all") || promote_secondaries_enabled(link->ifname))) {
694 char *promote_secondaries_path = NULL;
695
696 log_link_debug(link, "promote_secondaries is unset, setting it");
697 promote_secondaries_path = strjoina("net/ipv4/conf/", link->ifname, "/promote_secondaries");
698 r = sysctl_write(promote_secondaries_path, "1");
699 if (r < 0)
700 log_link_warning_errno(link, r, "cannot set sysctl %s to 1", promote_secondaries_path);
701 return r > 0;
702 }
703
704 return 0;
705 }
706
707 int dhcp4_set_client_identifier(Link *link) {
708 int r;
709
710 assert(link);
711 assert(link->network);
712 assert(link->dhcp_client);
713
714 switch (link->network->dhcp_client_identifier) {
715 case DHCP_CLIENT_ID_DUID: {
716 /* If configured, apply user specified DUID and IAID */
717 const DUID *duid = link_get_duid(link);
718
719 if (duid->type == DUID_TYPE_LLT && duid->raw_data_len == 0)
720 r = sd_dhcp_client_set_iaid_duid_llt(link->dhcp_client,
721 link->network->iaid_set,
722 link->network->iaid,
723 duid->llt_time);
724 else
725 r = sd_dhcp_client_set_iaid_duid(link->dhcp_client,
726 link->network->iaid_set,
727 link->network->iaid,
728 duid->type,
729 duid->raw_data_len > 0 ? duid->raw_data : NULL,
730 duid->raw_data_len);
731 if (r < 0)
732 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set IAID+DUID: %m");
733 break;
734 }
735 case DHCP_CLIENT_ID_DUID_ONLY: {
736 /* If configured, apply user specified DUID */
737 const DUID *duid = link_get_duid(link);
738
739 if (duid->type == DUID_TYPE_LLT && duid->raw_data_len == 0)
740 r = sd_dhcp_client_set_duid_llt(link->dhcp_client,
741 duid->llt_time);
742 else
743 r = sd_dhcp_client_set_duid(link->dhcp_client,
744 duid->type,
745 duid->raw_data_len > 0 ? duid->raw_data : NULL,
746 duid->raw_data_len);
747 if (r < 0)
748 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set DUID: %m");
749 break;
750 }
751 case DHCP_CLIENT_ID_MAC:
752 r = sd_dhcp_client_set_client_id(link->dhcp_client,
753 ARPHRD_ETHER,
754 (const uint8_t *) &link->mac,
755 sizeof(link->mac));
756 if (r < 0)
757 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set client ID: %m");
758 break;
759 default:
760 assert_not_reached("Unknown client identifier type.");
761 }
762
763 return 0;
764 }
765
766 int dhcp4_configure(Link *link) {
767 int r;
768
769 assert(link);
770 assert(link->network);
771 assert(link->network->dhcp & ADDRESS_FAMILY_IPV4);
772
773 if (!link->dhcp_client) {
774 r = sd_dhcp_client_new(&link->dhcp_client, link->network->dhcp_anonymize);
775 if (r == -ENOMEM)
776 return log_oom();
777 if (r < 0)
778 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to create DHCP4 client: %m");
779 }
780
781 r = sd_dhcp_client_attach_event(link->dhcp_client, NULL, 0);
782 if (r < 0)
783 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to attach event: %m");
784
785 r = sd_dhcp_client_set_mac(link->dhcp_client,
786 (const uint8_t *) &link->mac,
787 sizeof (link->mac), ARPHRD_ETHER);
788 if (r < 0)
789 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set MAC address: %m");
790
791 r = sd_dhcp_client_set_ifindex(link->dhcp_client, link->ifindex);
792 if (r < 0)
793 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set ifindex: %m");
794
795 r = sd_dhcp_client_set_callback(link->dhcp_client, dhcp4_handler, link);
796 if (r < 0)
797 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set callback: %m");
798
799 r = sd_dhcp_client_set_request_broadcast(link->dhcp_client,
800 link->network->dhcp_broadcast);
801 if (r < 0)
802 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for broadcast: %m");
803
804 if (link->mtu) {
805 r = sd_dhcp_client_set_mtu(link->dhcp_client, link->mtu);
806 if (r < 0)
807 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set MTU: %m");
808 }
809
810 if (link->network->dhcp_use_mtu) {
811 r = sd_dhcp_client_set_request_option(link->dhcp_client,
812 SD_DHCP_OPTION_INTERFACE_MTU);
813 if (r < 0)
814 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for MTU: %m");
815 }
816
817 /* NOTE: even if this variable is called "use", it also "sends" PRL
818 * options, maybe there should be a different configuration variable
819 * to send or not route options?. */
820 /* NOTE: when using Anonymize=yes, routes PRL options are sent
821 * by default, so they don't need to be added here. */
822 if (link->network->dhcp_use_routes && !link->network->dhcp_anonymize) {
823 r = sd_dhcp_client_set_request_option(link->dhcp_client,
824 SD_DHCP_OPTION_STATIC_ROUTE);
825 if (r < 0)
826 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for static route: %m");
827
828 r = sd_dhcp_client_set_request_option(link->dhcp_client,
829 SD_DHCP_OPTION_CLASSLESS_STATIC_ROUTE);
830 if (r < 0)
831 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for classless static route: %m");
832 }
833
834 if (link->network->dhcp_use_ntp) {
835 r = sd_dhcp_client_set_request_option(link->dhcp_client, SD_DHCP_OPTION_NTP_SERVER);
836 if (r < 0)
837 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for NTP server: %m");
838 }
839
840 if (link->network->dhcp_use_timezone) {
841 r = sd_dhcp_client_set_request_option(link->dhcp_client, SD_DHCP_OPTION_NEW_TZDB_TIMEZONE);
842 if (r < 0)
843 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set request flag for timezone: %m");
844 }
845
846 r = dhcp4_set_hostname(link);
847 if (r < 0)
848 return r;
849
850 if (link->network->dhcp_vendor_class_identifier) {
851 r = sd_dhcp_client_set_vendor_class_identifier(link->dhcp_client,
852 link->network->dhcp_vendor_class_identifier);
853 if (r < 0)
854 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set vendor class identifier: %m");
855 }
856
857 if (link->network->dhcp_user_class) {
858 r = sd_dhcp_client_set_user_class(link->dhcp_client, (const char **) link->network->dhcp_user_class);
859 if (r < 0)
860 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set user class: %m");
861 }
862
863 if (link->network->dhcp_client_port) {
864 r = sd_dhcp_client_set_client_port(link->dhcp_client, link->network->dhcp_client_port);
865 if (r < 0)
866 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set listen port: %m");
867 }
868
869 if (link->network->dhcp_max_attempts > 0) {
870 r = sd_dhcp_client_set_max_attempts(link->dhcp_client, link->network->dhcp_max_attempts);
871 if (r < 0)
872 return log_link_error_errno(link, r, "DHCP4 CLIENT: Failed to set max attempts: %m");
873 }
874
875 return dhcp4_set_client_identifier(link);
876 }