1 /* SPDX-License-Identifier: LGPL-2.1+ */
3 Copyright © 2013 Tom Gundersen <teg@jklm.no>
6 #include <sys/socket.h>
8 #include <linux/fib_rules.h>
11 #include "sd-daemon.h"
12 #include "sd-netlink.h"
14 #include "alloc-util.h"
16 #include "conf-parser.h"
18 #include "dns-domain.h"
21 #include "libudev-private.h"
22 #include "local-addresses.h"
23 #include "netlink-util.h"
24 #include "networkd-manager.h"
25 #include "ordered-set.h"
26 #include "path-util.h"
28 #include "udev-util.h"
31 /* use 8 MB for receive socket kernel queue. */
32 #define RCVBUF_SIZE (8*1024*1024)
34 const char* const network_dirs
[] = {
35 "/etc/systemd/network",
36 "/run/systemd/network",
37 "/usr/lib/systemd/network",
39 "/lib/systemd/network",
43 static int setup_default_address_pool(Manager
*m
) {
49 /* Add in the well-known private address ranges. */
51 r
= address_pool_new_from_string(m
, &p
, AF_INET6
, "fc00::", 7);
55 r
= address_pool_new_from_string(m
, &p
, AF_INET
, "192.168.0.0", 16);
59 r
= address_pool_new_from_string(m
, &p
, AF_INET
, "172.16.0.0", 12);
63 r
= address_pool_new_from_string(m
, &p
, AF_INET
, "10.0.0.0", 8);
70 static int manager_reset_all(Manager
*m
) {
77 HASHMAP_FOREACH(link
, m
->links
, i
) {
78 r
= link_carrier_reset(link
);
80 log_link_warning_errno(link
, r
, "Could not reset carrier: %m");
86 static int match_prepare_for_sleep(sd_bus_message
*message
, void *userdata
, sd_bus_error
*ret_error
) {
87 Manager
*m
= userdata
;
93 r
= sd_bus_message_read(message
, "b", &b
);
95 log_debug_errno(r
, "Failed to parse PrepareForSleep signal: %m");
102 log_debug("Coming back from suspend, resetting all connections...");
104 (void) manager_reset_all(m
);
109 static int on_connected(sd_bus_message
*message
, void *userdata
, sd_bus_error
*ret_error
) {
110 Manager
*m
= userdata
;
115 /* Did we get a timezone or transient hostname from DHCP while D-Bus wasn't up yet? */
116 if (m
->dynamic_hostname
)
117 (void) manager_set_hostname(m
, m
->dynamic_hostname
);
118 if (m
->dynamic_timezone
)
119 (void) manager_set_timezone(m
, m
->dynamic_timezone
);
124 int manager_connect_bus(Manager
*m
) {
132 r
= bus_open_system_watch_bind_with_description(&m
->bus
, "bus-api-network");
134 return log_error_errno(r
, "Failed to connect to bus: %m");
136 r
= sd_bus_add_object_vtable(m
->bus
, NULL
, "/org/freedesktop/network1", "org.freedesktop.network1.Manager", manager_vtable
, m
);
138 return log_error_errno(r
, "Failed to add manager object vtable: %m");
140 r
= sd_bus_add_fallback_vtable(m
->bus
, NULL
, "/org/freedesktop/network1/link", "org.freedesktop.network1.Link", link_vtable
, link_object_find
, m
);
142 return log_error_errno(r
, "Failed to add link object vtable: %m");
144 r
= sd_bus_add_node_enumerator(m
->bus
, NULL
, "/org/freedesktop/network1/link", link_node_enumerator
, m
);
146 return log_error_errno(r
, "Failed to add link enumerator: %m");
148 r
= sd_bus_add_fallback_vtable(m
->bus
, NULL
, "/org/freedesktop/network1/network", "org.freedesktop.network1.Network", network_vtable
, network_object_find
, m
);
150 return log_error_errno(r
, "Failed to add network object vtable: %m");
152 r
= sd_bus_add_node_enumerator(m
->bus
, NULL
, "/org/freedesktop/network1/network", network_node_enumerator
, m
);
154 return log_error_errno(r
, "Failed to add network enumerator: %m");
156 r
= bus_request_name_async_may_reload_dbus(m
->bus
, NULL
, "org.freedesktop.network1", 0, NULL
);
158 return log_error_errno(r
, "Failed to request name: %m");
160 r
= sd_bus_attach_event(m
->bus
, m
->event
, 0);
162 return log_error_errno(r
, "Failed to attach bus to event loop: %m");
164 r
= sd_bus_match_signal_async(
167 "org.freedesktop.DBus.Local",
169 "org.freedesktop.DBus.Local",
171 on_connected
, NULL
, m
);
173 return log_error_errno(r
, "Failed to request match on Connected signal: %m");
175 r
= sd_bus_match_signal_async(
177 &m
->prepare_for_sleep_slot
,
178 "org.freedesktop.login1",
179 "/org/freedesktop/login1",
180 "org.freedesktop.login1.Manager",
182 match_prepare_for_sleep
, NULL
, m
);
184 log_warning_errno(r
, "Failed to request match for PrepareForSleep, ignoring: %m");
189 static int manager_udev_process_link(Manager
*m
, struct udev_device
*device
) {
196 if (!streq_ptr(udev_device_get_action(device
), "add"))
199 ifindex
= udev_device_get_ifindex(device
);
201 log_debug("Ignoring udev ADD event for device with invalid ifindex");
205 r
= link_get(m
, ifindex
, &link
);
211 r
= link_initialized(link
, device
);
218 static int manager_dispatch_link_udev(sd_event_source
*source
, int fd
, uint32_t revents
, void *userdata
) {
219 Manager
*m
= userdata
;
220 struct udev_monitor
*monitor
= m
->udev_monitor
;
221 _cleanup_(udev_device_unrefp
) struct udev_device
*device
= NULL
;
223 device
= udev_monitor_receive_device(monitor
);
227 (void) manager_udev_process_link(m
, device
);
232 static int manager_connect_udev(Manager
*m
) {
235 /* udev does not initialize devices inside containers,
236 * so we rely on them being already initialized before
237 * entering the container */
238 if (detect_container() > 0)
241 m
->udev
= udev_new();
245 m
->udev_monitor
= udev_monitor_new_from_netlink(m
->udev
, "udev");
246 if (!m
->udev_monitor
)
249 r
= udev_monitor_filter_add_match_subsystem_devtype(m
->udev_monitor
, "net", NULL
);
251 return log_error_errno(r
, "Could not add udev monitor filter: %m");
253 r
= udev_monitor_enable_receiving(m
->udev_monitor
);
255 log_error("Could not enable udev monitor");
259 r
= sd_event_add_io(m
->event
,
260 &m
->udev_event_source
,
261 udev_monitor_get_fd(m
->udev_monitor
),
262 EPOLLIN
, manager_dispatch_link_udev
,
267 r
= sd_event_source_set_description(m
->udev_event_source
, "networkd-udev");
274 int manager_rtnl_process_route(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
275 Manager
*m
= userdata
;
278 uint32_t ifindex
, priority
= 0;
279 unsigned char protocol
, scope
, tos
, table
, rt_type
;
281 unsigned char dst_prefixlen
, src_prefixlen
;
282 union in_addr_union dst
= {}, gw
= {}, src
= {}, prefsrc
= {};
290 if (sd_netlink_message_is_error(message
)) {
291 r
= sd_netlink_message_get_errno(message
);
293 log_warning_errno(r
, "rtnl: failed to receive route, ignoring: %m");
298 r
= sd_netlink_message_get_type(message
, &type
);
300 log_warning_errno(r
, "rtnl: could not get message type, ignoring: %m");
302 } else if (!IN_SET(type
, RTM_NEWROUTE
, RTM_DELROUTE
)) {
303 log_warning("rtnl: received unexpected message type when processing route, ignoring");
307 r
= sd_netlink_message_read_u32(message
, RTA_OIF
, &ifindex
);
309 log_debug("rtnl: received route without ifindex, ignoring");
312 log_warning_errno(r
, "rtnl: could not get ifindex from route, ignoring: %m");
314 } else if (ifindex
<= 0) {
315 log_warning("rtnl: received route message with invalid ifindex, ignoring: %d", ifindex
);
318 r
= link_get(m
, ifindex
, &link
);
319 if (r
< 0 || !link
) {
320 /* when enumerating we might be out of sync, but we will
321 * get the route again, so just ignore it */
323 log_warning("rtnl: received route for nonexistent link (%d), ignoring", ifindex
);
328 r
= sd_rtnl_message_route_get_family(message
, &family
);
329 if (r
< 0 || !IN_SET(family
, AF_INET
, AF_INET6
)) {
330 log_link_warning(link
, "rtnl: received address with invalid family, ignoring");
334 r
= sd_rtnl_message_route_get_protocol(message
, &protocol
);
336 log_warning_errno(r
, "rtnl: could not get route protocol: %m");
342 r
= sd_netlink_message_read_in_addr(message
, RTA_DST
, &dst
.in
);
343 if (r
< 0 && r
!= -ENODATA
) {
344 log_link_warning_errno(link
, r
, "rtnl: received route without valid destination, ignoring: %m");
348 r
= sd_netlink_message_read_in_addr(message
, RTA_GATEWAY
, &gw
.in
);
349 if (r
< 0 && r
!= -ENODATA
) {
350 log_link_warning_errno(link
, r
, "rtnl: received route with invalid gateway, ignoring: %m");
354 r
= sd_netlink_message_read_in_addr(message
, RTA_SRC
, &src
.in
);
355 if (r
< 0 && r
!= -ENODATA
) {
356 log_link_warning_errno(link
, r
, "rtnl: received route with invalid source, ignoring: %m");
360 r
= sd_netlink_message_read_in_addr(message
, RTA_PREFSRC
, &prefsrc
.in
);
361 if (r
< 0 && r
!= -ENODATA
) {
362 log_link_warning_errno(link
, r
, "rtnl: received route with invalid preferred source, ignoring: %m");
369 r
= sd_netlink_message_read_in6_addr(message
, RTA_DST
, &dst
.in6
);
370 if (r
< 0 && r
!= -ENODATA
) {
371 log_link_warning_errno(link
, r
, "rtnl: received route without valid destination, ignoring: %m");
375 r
= sd_netlink_message_read_in6_addr(message
, RTA_GATEWAY
, &gw
.in6
);
376 if (r
< 0 && r
!= -ENODATA
) {
377 log_link_warning_errno(link
, r
, "rtnl: received route with invalid gateway, ignoring: %m");
381 r
= sd_netlink_message_read_in6_addr(message
, RTA_SRC
, &src
.in6
);
382 if (r
< 0 && r
!= -ENODATA
) {
383 log_link_warning_errno(link
, r
, "rtnl: received route with invalid source, ignoring: %m");
387 r
= sd_netlink_message_read_in6_addr(message
, RTA_PREFSRC
, &prefsrc
.in6
);
388 if (r
< 0 && r
!= -ENODATA
) {
389 log_link_warning_errno(link
, r
, "rtnl: received route with invalid preferred source, ignoring: %m");
396 assert_not_reached("Received unsupported address family");
400 r
= sd_rtnl_message_route_get_dst_prefixlen(message
, &dst_prefixlen
);
402 log_link_warning_errno(link
, r
, "rtnl: received route with invalid destination prefixlen, ignoring: %m");
406 r
= sd_rtnl_message_route_get_src_prefixlen(message
, &src_prefixlen
);
408 log_link_warning_errno(link
, r
, "rtnl: received route with invalid source prefixlen, ignoring: %m");
412 r
= sd_rtnl_message_route_get_scope(message
, &scope
);
414 log_link_warning_errno(link
, r
, "rtnl: received route with invalid scope, ignoring: %m");
418 r
= sd_rtnl_message_route_get_tos(message
, &tos
);
420 log_link_warning_errno(link
, r
, "rtnl: received route with invalid tos, ignoring: %m");
424 r
= sd_rtnl_message_route_get_type(message
, &rt_type
);
426 log_link_warning_errno(link
, r
, "rtnl: received route with invalid type, ignoring: %m");
430 r
= sd_rtnl_message_route_get_table(message
, &table
);
432 log_link_warning_errno(link
, r
, "rtnl: received route with invalid table, ignoring: %m");
436 r
= sd_netlink_message_read_u32(message
, RTA_PRIORITY
, &priority
);
437 if (r
< 0 && r
!= -ENODATA
) {
438 log_link_warning_errno(link
, r
, "rtnl: received route with invalid priority, ignoring: %m");
442 (void) route_get(link
, family
, &dst
, dst_prefixlen
, tos
, priority
, table
, &route
);
447 /* A route appeared that we did not request */
448 r
= route_add_foreign(link
, family
, &dst
, dst_prefixlen
, tos
, priority
, table
, &route
);
450 log_link_warning_errno(link
, r
, "Failed to add route, ignoring: %m");
455 route_update(route
, &src
, src_prefixlen
, &gw
, &prefsrc
, scope
, protocol
, rt_type
);
464 assert_not_reached("Received invalid RTNL message type");
470 int manager_rtnl_process_address(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
471 Manager
*m
= userdata
;
476 unsigned char prefixlen
;
478 union in_addr_union in_addr
;
479 struct ifa_cacheinfo cinfo
;
480 Address
*address
= NULL
;
481 char buf
[INET6_ADDRSTRLEN
], valid_buf
[FORMAT_TIMESPAN_MAX
];
482 const char *valid_str
= NULL
;
489 if (sd_netlink_message_is_error(message
)) {
490 r
= sd_netlink_message_get_errno(message
);
492 log_warning_errno(r
, "rtnl: failed to receive address, ignoring: %m");
497 r
= sd_netlink_message_get_type(message
, &type
);
499 log_warning_errno(r
, "rtnl: could not get message type, ignoring: %m");
501 } else if (!IN_SET(type
, RTM_NEWADDR
, RTM_DELADDR
)) {
502 log_warning("rtnl: received unexpected message type when processing address, ignoring");
506 r
= sd_rtnl_message_addr_get_ifindex(message
, &ifindex
);
508 log_warning_errno(r
, "rtnl: could not get ifindex from address, ignoring: %m");
510 } else if (ifindex
<= 0) {
511 log_warning("rtnl: received address message with invalid ifindex, ignoring: %d", ifindex
);
514 r
= link_get(m
, ifindex
, &link
);
515 if (r
< 0 || !link
) {
516 /* when enumerating we might be out of sync, but we will
517 * get the address again, so just ignore it */
519 log_warning("rtnl: received address for nonexistent link (%d), ignoring", ifindex
);
524 r
= sd_rtnl_message_addr_get_family(message
, &family
);
525 if (r
< 0 || !IN_SET(family
, AF_INET
, AF_INET6
)) {
526 log_link_warning(link
, "rtnl: received address with invalid family, ignoring");
530 r
= sd_rtnl_message_addr_get_prefixlen(message
, &prefixlen
);
532 log_link_warning_errno(link
, r
, "rtnl: received address with invalid prefixlen, ignoring: %m");
536 r
= sd_rtnl_message_addr_get_scope(message
, &scope
);
538 log_link_warning_errno(link
, r
, "rtnl: received address with invalid scope, ignoring: %m");
542 r
= sd_rtnl_message_addr_get_flags(message
, &flags
);
544 log_link_warning_errno(link
, r
, "rtnl: received address with invalid flags, ignoring: %m");
550 r
= sd_netlink_message_read_in_addr(message
, IFA_LOCAL
, &in_addr
.in
);
552 log_link_warning_errno(link
, r
, "rtnl: received address without valid address, ignoring: %m");
559 r
= sd_netlink_message_read_in6_addr(message
, IFA_ADDRESS
, &in_addr
.in6
);
561 log_link_warning_errno(link
, r
, "rtnl: received address without valid address, ignoring: %m");
568 assert_not_reached("Received unsupported address family");
571 if (!inet_ntop(family
, &in_addr
, buf
, INET6_ADDRSTRLEN
)) {
572 log_link_warning(link
, "Could not print address, ignoring");
576 r
= sd_netlink_message_read_cache_info(message
, IFA_CACHEINFO
, &cinfo
);
577 if (r
< 0 && r
!= -ENODATA
) {
578 log_link_warning_errno(link
, r
, "rtnl: cannot get IFA_CACHEINFO attribute, ignoring: %m");
581 if (cinfo
.ifa_valid
!= CACHE_INFO_INFINITY_LIFE_TIME
)
582 valid_str
= format_timespan(valid_buf
, FORMAT_TIMESPAN_MAX
,
583 cinfo
.ifa_valid
* USEC_PER_SEC
,
587 (void) address_get(link
, family
, &in_addr
, prefixlen
, &address
);
592 log_link_debug(link
, "Updating address: %s/%u (valid %s%s)", buf
, prefixlen
,
593 valid_str
? "for " : "forever", strempty(valid_str
));
595 /* An address appeared that we did not request */
596 r
= address_add_foreign(link
, family
, &in_addr
, prefixlen
, &address
);
598 log_link_warning_errno(link
, r
, "Failed to add address %s/%u, ignoring: %m", buf
, prefixlen
);
601 log_link_debug(link
, "Adding address: %s/%u (valid %s%s)", buf
, prefixlen
,
602 valid_str
? "for " : "forever", strempty(valid_str
));
605 r
= address_update(address
, flags
, scope
, &cinfo
);
607 log_link_warning_errno(link
, r
, "Failed to update address %s/%u, ignoring: %m", buf
, prefixlen
);
616 log_link_debug(link
, "Removing address: %s/%u (valid %s%s)", buf
, prefixlen
,
617 valid_str
? "for " : "forever", strempty(valid_str
));
618 (void) address_drop(address
);
620 log_link_warning(link
, "Removing non-existent address: %s/%u (valid %s%s), ignoring", buf
, prefixlen
,
621 valid_str
? "for " : "forever", strempty(valid_str
));
625 assert_not_reached("Received invalid RTNL message type");
631 static int manager_rtnl_process_link(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
632 Manager
*m
= userdata
;
634 NetDev
*netdev
= NULL
;
643 if (sd_netlink_message_is_error(message
)) {
644 r
= sd_netlink_message_get_errno(message
);
646 log_warning_errno(r
, "rtnl: Could not receive link, ignoring: %m");
651 r
= sd_netlink_message_get_type(message
, &type
);
653 log_warning_errno(r
, "rtnl: Could not get message type, ignoring: %m");
655 } else if (!IN_SET(type
, RTM_NEWLINK
, RTM_DELLINK
)) {
656 log_warning("rtnl: Received unexpected message type when processing link, ignoring");
660 r
= sd_rtnl_message_link_get_ifindex(message
, &ifindex
);
662 log_warning_errno(r
, "rtnl: Could not get ifindex from link, ignoring: %m");
664 } else if (ifindex
<= 0) {
665 log_warning("rtnl: received link message with invalid ifindex %d, ignoring", ifindex
);
669 r
= sd_netlink_message_read_string(message
, IFLA_IFNAME
, &name
);
671 log_warning_errno(r
, "rtnl: Received link message without ifname, ignoring: %m");
675 (void) link_get(m
, ifindex
, &link
);
676 (void) netdev_get(m
, name
, &netdev
);
681 /* link is new, so add it */
682 r
= link_add(m
, message
, &link
);
684 log_warning_errno(r
, "Could not add new link, ignoring: %m");
690 /* netdev exists, so make sure the ifindex matches */
691 r
= netdev_set_ifindex(netdev
, message
);
693 log_warning_errno(r
, "Could not set ifindex on netdev, ignoring: %m");
698 r
= link_update(link
, message
);
700 log_warning_errno(r
, "Could not update link, ignoring: %m");
713 assert_not_reached("Received invalid RTNL message type.");
719 int manager_rtnl_process_rule(sd_netlink
*rtnl
, sd_netlink_message
*message
, void *userdata
) {
720 uint8_t tos
= 0, to_prefixlen
= 0, from_prefixlen
= 0;
721 union in_addr_union to
= {}, from
= {};
722 RoutingPolicyRule
*rule
= NULL
;
723 uint32_t fwmark
= 0, table
= 0;
724 char *iif
= NULL
, *oif
= NULL
;
725 Manager
*m
= userdata
;
734 if (sd_netlink_message_is_error(message
)) {
735 r
= sd_netlink_message_get_errno(message
);
737 log_warning_errno(r
, "rtnl: failed to receive rule, ignoring: %m");
742 r
= sd_netlink_message_get_type(message
, &type
);
744 log_warning_errno(r
, "rtnl: could not get message type, ignoring: %m");
746 } else if (!IN_SET(type
, RTM_NEWRULE
, RTM_DELRULE
)) {
747 log_warning("rtnl: received unexpected message type '%u' when processing rule, ignoring", type
);
751 r
= sd_rtnl_message_get_family(message
, &family
);
753 log_warning_errno(r
, "rtnl: could not get rule family, ignoring: %m");
755 } else if (!IN_SET(family
, AF_INET
, AF_INET6
)) {
756 log_debug("rtnl: received address with invalid family %u, ignoring", family
);
762 r
= sd_netlink_message_read_in_addr(message
, FRA_SRC
, &from
.in
);
763 if (r
< 0 && r
!= -ENODATA
) {
764 log_warning_errno(r
, "rtnl: could not get FRA_SRC attribute, ignoring: %m");
767 r
= sd_rtnl_message_routing_policy_rule_get_rtm_src_prefixlen(message
, &from_prefixlen
);
769 log_warning_errno(r
, "rtnl: failed to retrive rule from prefix length, ignoring: %m");
774 r
= sd_netlink_message_read_in_addr(message
, FRA_DST
, &to
.in
);
775 if (r
< 0 && r
!= -ENODATA
) {
776 log_warning_errno(r
, "rtnl: could not get FRA_DST attribute, ignoring: %m");
779 r
= sd_rtnl_message_routing_policy_rule_get_rtm_dst_prefixlen(message
, &to_prefixlen
);
781 log_warning_errno(r
, "rtnl: failed to retrive rule to prefix length, ignoring: %m");
789 r
= sd_netlink_message_read_in6_addr(message
, FRA_SRC
, &from
.in6
);
790 if (r
< 0 && r
!= -ENODATA
) {
791 log_warning_errno(r
, "rtnl: could not get FRA_SRC attribute, ignoring: %m");
794 r
= sd_rtnl_message_routing_policy_rule_get_rtm_src_prefixlen(message
, &from_prefixlen
);
796 log_warning_errno(r
, "rtnl: failed to retrive rule from prefix length, ignoring: %m");
801 r
= sd_netlink_message_read_in6_addr(message
, FRA_DST
, &to
.in6
);
802 if (r
< 0 && r
!= -ENODATA
) {
803 log_warning_errno(r
, "rtnl: could not get FRA_DST attribute, ignoring: %m");
806 r
= sd_rtnl_message_routing_policy_rule_get_rtm_dst_prefixlen(message
, &to_prefixlen
);
808 log_warning_errno(r
, "rtnl: failed to retrive rule to prefix length, ignoring: %m");
816 assert_not_reached("Received unsupported address family");
819 if (from_prefixlen
== 0 && to_prefixlen
== 0)
822 r
= sd_netlink_message_read_u32(message
, FRA_FWMARK
, &fwmark
);
823 if (r
< 0 && r
!= -ENODATA
) {
824 log_warning_errno(r
, "rtnl: could not get FRA_FWMARK attribute, ignoring: %m");
828 r
= sd_netlink_message_read_u32(message
, FRA_TABLE
, &table
);
829 if (r
< 0 && r
!= -ENODATA
) {
830 log_warning_errno(r
, "rtnl: could not get FRA_TABLE attribute, ignoring: %m");
834 r
= sd_rtnl_message_routing_policy_rule_get_tos(message
, &tos
);
835 if (r
< 0 && r
!= -ENODATA
) {
836 log_warning_errno(r
, "rtnl: could not get ip rule TOS, ignoring: %m");
840 r
= sd_netlink_message_read_string(message
, FRA_IIFNAME
, (const char **) &iif
);
841 if (r
< 0 && r
!= -ENODATA
) {
842 log_warning_errno(r
, "rtnl: could not get FRA_IIFNAME attribute, ignoring: %m");
846 r
= sd_netlink_message_read_string(message
, FRA_OIFNAME
, (const char **) &oif
);
847 if (r
< 0 && r
!= -ENODATA
) {
848 log_warning_errno(r
, "rtnl: could not get FRA_OIFNAME attribute, ignoring: %m");
852 (void) routing_policy_rule_get(m
, family
, &from
, from_prefixlen
, &to
, to_prefixlen
, tos
, fwmark
, table
, iif
, oif
, &rule
);
857 r
= routing_policy_rule_add_foreign(m
, family
, &from
, from_prefixlen
, &to
, to_prefixlen
, tos
, fwmark
, table
, iif
, oif
, &rule
);
859 log_warning_errno(r
, "Could not add rule, ignoring: %m");
865 routing_policy_rule_free(rule
);
870 assert_not_reached("Received invalid RTNL message type");
876 static int systemd_netlink_fd(void) {
877 int n
, fd
, rtnl_fd
= -EINVAL
;
879 n
= sd_listen_fds(true);
883 for (fd
= SD_LISTEN_FDS_START
; fd
< SD_LISTEN_FDS_START
+ n
; fd
++) {
884 if (sd_is_socket(fd
, AF_NETLINK
, SOCK_RAW
, -1) > 0) {
895 static int manager_connect_genl(Manager
*m
) {
900 r
= sd_genl_socket_open(&m
->genl
);
904 r
= sd_netlink_inc_rcvbuf(m
->genl
, RCVBUF_SIZE
);
908 r
= sd_netlink_attach_event(m
->genl
, m
->event
, 0);
915 static int manager_connect_rtnl(Manager
*m
) {
920 fd
= systemd_netlink_fd();
922 r
= sd_netlink_open(&m
->rtnl
);
924 r
= sd_netlink_open_fd(&m
->rtnl
, fd
);
928 r
= sd_netlink_inc_rcvbuf(m
->rtnl
, RCVBUF_SIZE
);
932 r
= sd_netlink_attach_event(m
->rtnl
, m
->event
, 0);
936 r
= sd_netlink_add_match(m
->rtnl
, RTM_NEWLINK
, &manager_rtnl_process_link
, m
);
940 r
= sd_netlink_add_match(m
->rtnl
, RTM_DELLINK
, &manager_rtnl_process_link
, m
);
944 r
= sd_netlink_add_match(m
->rtnl
, RTM_NEWADDR
, &manager_rtnl_process_address
, m
);
948 r
= sd_netlink_add_match(m
->rtnl
, RTM_DELADDR
, &manager_rtnl_process_address
, m
);
952 r
= sd_netlink_add_match(m
->rtnl
, RTM_NEWROUTE
, &manager_rtnl_process_route
, m
);
956 r
= sd_netlink_add_match(m
->rtnl
, RTM_DELROUTE
, &manager_rtnl_process_route
, m
);
960 r
= sd_netlink_add_match(m
->rtnl
, RTM_NEWRULE
, &manager_rtnl_process_rule
, m
);
964 r
= sd_netlink_add_match(m
->rtnl
, RTM_DELRULE
, &manager_rtnl_process_rule
, m
);
971 static int ordered_set_put_in_addr_data(OrderedSet
*s
, const struct in_addr_data
*address
) {
978 r
= in_addr_to_string(address
->family
, &address
->address
, &p
);
982 r
= ordered_set_consume(s
, p
);
989 static int ordered_set_put_in_addr_datav(OrderedSet
*s
, const struct in_addr_data
*addresses
, unsigned n
) {
994 assert(addresses
|| n
== 0);
996 for (i
= 0; i
< n
; i
++) {
997 r
= ordered_set_put_in_addr_data(s
, addresses
+i
);
1007 static int ordered_set_put_in4_addr(OrderedSet
*s
, const struct in_addr
*address
) {
1014 r
= in_addr_to_string(AF_INET
, (const union in_addr_union
*) address
, &p
);
1018 r
= ordered_set_consume(s
, p
);
1025 static int ordered_set_put_in4_addrv(OrderedSet
*s
, const struct in_addr
*addresses
, unsigned n
) {
1030 assert(n
== 0 || addresses
);
1032 for (i
= 0; i
< n
; i
++) {
1033 r
= ordered_set_put_in4_addr(s
, addresses
+i
);
1043 static void print_string_set(FILE *f
, const char *field
, OrderedSet
*s
) {
1048 if (ordered_set_isempty(s
))
1053 ORDERED_SET_FOREACH(p
, s
, i
)
1054 fputs_with_space(f
, p
, NULL
, &space
);
1059 static int manager_save(Manager
*m
) {
1060 _cleanup_ordered_set_free_free_ OrderedSet
*dns
= NULL
, *ntp
= NULL
, *search_domains
= NULL
, *route_domains
= NULL
;
1063 _cleanup_free_
char *temp_path
= NULL
;
1064 _cleanup_fclose_
FILE *f
= NULL
;
1065 LinkOperationalState operstate
= LINK_OPERSTATE_OFF
;
1066 const char *operstate_str
;
1070 assert(m
->state_file
);
1072 /* We add all NTP and DNS server to a set, to filter out duplicates */
1073 dns
= ordered_set_new(&string_hash_ops
);
1077 ntp
= ordered_set_new(&string_hash_ops
);
1081 search_domains
= ordered_set_new(&dns_name_hash_ops
);
1082 if (!search_domains
)
1085 route_domains
= ordered_set_new(&dns_name_hash_ops
);
1089 HASHMAP_FOREACH(link
, m
->links
, i
) {
1090 if (link
->flags
& IFF_LOOPBACK
)
1093 if (link
->operstate
> operstate
)
1094 operstate
= link
->operstate
;
1099 /* First add the static configured entries */
1100 r
= ordered_set_put_in_addr_datav(dns
, link
->network
->dns
, link
->network
->n_dns
);
1104 r
= ordered_set_put_strdupv(ntp
, link
->network
->ntp
);
1108 r
= ordered_set_put_strdupv(search_domains
, link
->network
->search_domains
);
1112 r
= ordered_set_put_strdupv(route_domains
, link
->network
->route_domains
);
1116 if (!link
->dhcp_lease
)
1119 /* Secondly, add the entries acquired via DHCP */
1120 if (link
->network
->dhcp_use_dns
) {
1121 const struct in_addr
*addresses
;
1123 r
= sd_dhcp_lease_get_dns(link
->dhcp_lease
, &addresses
);
1125 r
= ordered_set_put_in4_addrv(dns
, addresses
, r
);
1128 } else if (r
< 0 && r
!= -ENODATA
)
1132 if (link
->network
->dhcp_use_ntp
) {
1133 const struct in_addr
*addresses
;
1135 r
= sd_dhcp_lease_get_ntp(link
->dhcp_lease
, &addresses
);
1137 r
= ordered_set_put_in4_addrv(ntp
, addresses
, r
);
1140 } else if (r
< 0 && r
!= -ENODATA
)
1144 if (link
->network
->dhcp_use_domains
!= DHCP_USE_DOMAINS_NO
) {
1145 const char *domainname
;
1146 char **domains
= NULL
;
1148 OrderedSet
*target_domains
= (link
->network
->dhcp_use_domains
== DHCP_USE_DOMAINS_YES
) ? search_domains
: route_domains
;
1149 r
= sd_dhcp_lease_get_domainname(link
->dhcp_lease
, &domainname
);
1151 r
= ordered_set_put_strdup(target_domains
, domainname
);
1154 } else if (r
!= -ENODATA
)
1157 r
= sd_dhcp_lease_get_search_domains(link
->dhcp_lease
, &domains
);
1159 r
= ordered_set_put_strdupv(target_domains
, domains
);
1162 } else if (r
!= -ENODATA
)
1167 operstate_str
= link_operstate_to_string(operstate
);
1168 assert(operstate_str
);
1170 r
= fopen_temporary(m
->state_file
, &f
, &temp_path
);
1174 (void) __fsetlocking(f
, FSETLOCKING_BYCALLER
);
1175 (void) fchmod(fileno(f
), 0644);
1178 "# This is private data. Do not parse.\n"
1179 "OPER_STATE=%s\n", operstate_str
);
1181 print_string_set(f
, "DNS=", dns
);
1182 print_string_set(f
, "NTP=", ntp
);
1183 print_string_set(f
, "DOMAINS=", search_domains
);
1184 print_string_set(f
, "ROUTE_DOMAINS=", route_domains
);
1186 r
= routing_policy_serialize_rules(m
->rules
, f
);
1190 r
= fflush_and_check(f
);
1194 if (rename(temp_path
, m
->state_file
) < 0) {
1199 if (m
->operational_state
!= operstate
) {
1200 m
->operational_state
= operstate
;
1201 r
= manager_send_changed(m
, "OperationalState", NULL
);
1203 log_error_errno(r
, "Could not emit changed OperationalState: %m");
1211 (void) unlink(m
->state_file
);
1212 (void) unlink(temp_path
);
1214 return log_error_errno(r
, "Failed to save network state to %s: %m", m
->state_file
);
1217 static int manager_dirty_handler(sd_event_source
*s
, void *userdata
) {
1218 Manager
*m
= userdata
;
1228 SET_FOREACH(link
, m
->dirty_links
, i
) {
1229 r
= link_save(link
);
1237 Link
*manager_dhcp6_prefix_get(Manager
*m
, struct in6_addr
*addr
) {
1238 assert_return(m
, NULL
);
1239 assert_return(m
->dhcp6_prefixes
, NULL
);
1240 assert_return(addr
, NULL
);
1242 return hashmap_get(m
->dhcp6_prefixes
, addr
);
1245 static int dhcp6_route_add_callback(sd_netlink
*nl
, sd_netlink_message
*m
,
1249 union in_addr_union prefix
;
1250 _cleanup_free_
char *buf
= NULL
;
1252 r
= sd_netlink_message_get_errno(m
);
1254 log_link_debug_errno(l
, r
, "Received error adding DHCPv6 Prefix Delegation route: %m");
1258 r
= sd_netlink_message_read_in6_addr(m
, RTA_DST
, &prefix
.in6
);
1260 log_link_debug_errno(l
, r
, "Could not read IPv6 address from DHCPv6 Prefix Delegation while adding route: %m");
1264 (void) in_addr_to_string(AF_INET6
, &prefix
, &buf
);
1265 log_link_debug(l
, "Added DHCPv6 Prefix Deleagtion route %s/64",
1271 int manager_dhcp6_prefix_add(Manager
*m
, struct in6_addr
*addr
, Link
*link
) {
1275 assert_return(m
, -EINVAL
);
1276 assert_return(m
->dhcp6_prefixes
, -ENODATA
);
1277 assert_return(addr
, -EINVAL
);
1279 r
= route_add(link
, AF_INET6
, (union in_addr_union
*) addr
, 64,
1284 r
= route_configure(route
, link
, dhcp6_route_add_callback
);
1288 return hashmap_put(m
->dhcp6_prefixes
, addr
, link
);
1291 static int dhcp6_route_remove_callback(sd_netlink
*nl
, sd_netlink_message
*m
,
1295 union in_addr_union prefix
;
1296 _cleanup_free_
char *buf
= NULL
;
1298 r
= sd_netlink_message_get_errno(m
);
1300 log_link_debug_errno(l
, r
, "Received error on DHCPv6 Prefix Delegation route removal: %m");
1304 r
= sd_netlink_message_read_in6_addr(m
, RTA_DST
, &prefix
.in6
);
1306 log_link_debug_errno(l
, r
, "Could not read IPv6 address from DHCPv6 Prefix Delegation while removing route: %m");
1310 (void) in_addr_to_string(AF_INET6
, &prefix
, &buf
);
1311 log_link_debug(l
, "Removed DHCPv6 Prefix Delegation route %s/64",
1317 int manager_dhcp6_prefix_remove(Manager
*m
, struct in6_addr
*addr
) {
1322 assert_return(m
, -EINVAL
);
1323 assert_return(m
->dhcp6_prefixes
, -ENODATA
);
1324 assert_return(addr
, -EINVAL
);
1326 l
= hashmap_remove(m
->dhcp6_prefixes
, addr
);
1330 (void) sd_radv_remove_prefix(l
->radv
, addr
, 64);
1331 r
= route_get(l
, AF_INET6
, (union in_addr_union
*) addr
, 64,
1334 (void) route_remove(route
, l
, dhcp6_route_remove_callback
);
1339 int manager_dhcp6_prefix_remove_all(Manager
*m
, Link
*link
) {
1342 struct in6_addr
*addr
;
1344 assert_return(m
, -EINVAL
);
1345 assert_return(link
, -EINVAL
);
1347 HASHMAP_FOREACH_KEY(l
, addr
, m
->dhcp6_prefixes
, i
) {
1351 (void) manager_dhcp6_prefix_remove(m
, addr
);
1357 static void dhcp6_prefixes_hash_func(const void *p
, struct siphash
*state
) {
1358 const struct in6_addr
*addr
= p
;
1362 siphash24_compress(addr
, sizeof(*addr
), state
);
1365 static int dhcp6_prefixes_compare_func(const void *_a
, const void *_b
) {
1366 const struct in6_addr
*a
= _a
, *b
= _b
;
1368 return memcmp(a
, b
, sizeof(*a
));
1371 static const struct hash_ops dhcp6_prefixes_hash_ops
= {
1372 .hash
= dhcp6_prefixes_hash_func
,
1373 .compare
= dhcp6_prefixes_compare_func
,
1376 int manager_new(Manager
**ret
, sd_event
*event
) {
1377 _cleanup_(manager_freep
) Manager
*m
= NULL
;
1380 m
= new0(Manager
, 1);
1384 m
->state_file
= strdup("/run/systemd/netif/state");
1388 m
->event
= sd_event_ref(event
);
1390 r
= sd_event_add_post(m
->event
, NULL
, manager_dirty_handler
, m
);
1394 r
= manager_connect_rtnl(m
);
1398 r
= manager_connect_genl(m
);
1402 r
= manager_connect_udev(m
);
1406 m
->netdevs
= hashmap_new(&string_hash_ops
);
1410 LIST_HEAD_INIT(m
->networks
);
1412 r
= sd_resolve_default(&m
->resolve
);
1416 r
= sd_resolve_attach_event(m
->resolve
, m
->event
, 0);
1420 r
= setup_default_address_pool(m
);
1424 m
->dhcp6_prefixes
= hashmap_new(&dhcp6_prefixes_hash_ops
);
1425 if (!m
->dhcp6_prefixes
)
1428 m
->duid
.type
= DUID_TYPE_EN
;
1430 (void) routing_policy_load_rules(m
->state_file
, &m
->rules_saved
);
1437 void manager_free(Manager
*m
) {
1446 free(m
->state_file
);
1448 while ((network
= m
->networks
))
1449 network_free(network
);
1451 while ((link
= hashmap_first(m
->dhcp6_prefixes
)))
1453 hashmap_free(m
->dhcp6_prefixes
);
1455 while ((link
= hashmap_first(m
->links
)))
1457 hashmap_free(m
->links
);
1459 hashmap_free(m
->networks_by_name
);
1461 while ((netdev
= hashmap_first(m
->netdevs
)))
1462 netdev_unref(netdev
);
1463 hashmap_free(m
->netdevs
);
1465 while ((pool
= m
->address_pools
))
1466 address_pool_free(pool
);
1469 set_free(m
->rules_foreign
);
1471 set_free_with_destructor(m
->rules_saved
, routing_policy_rule_free
);
1473 sd_netlink_unref(m
->rtnl
);
1474 sd_event_unref(m
->event
);
1476 sd_resolve_unref(m
->resolve
);
1478 sd_event_source_unref(m
->udev_event_source
);
1479 udev_monitor_unref(m
->udev_monitor
);
1480 udev_unref(m
->udev
);
1482 sd_bus_unref(m
->bus
);
1483 sd_bus_slot_unref(m
->prepare_for_sleep_slot
);
1484 sd_bus_slot_unref(m
->connected_slot
);
1486 free(m
->dynamic_timezone
);
1487 free(m
->dynamic_hostname
);
1492 int manager_start(Manager
*m
) {
1498 /* The dirty handler will deal with future serialization, but the first one
1499 must be done explicitly. */
1503 HASHMAP_FOREACH(link
, m
->links
, i
)
1509 int manager_load_config(Manager
*m
) {
1512 /* update timestamp */
1513 paths_check_timestamp(network_dirs
, &m
->network_dirs_ts_usec
, true);
1519 r
= network_load(m
);
1526 bool manager_should_reload(Manager
*m
) {
1527 return paths_check_timestamp(network_dirs
, &m
->network_dirs_ts_usec
, false);
1530 int manager_rtnl_enumerate_links(Manager
*m
) {
1531 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1532 sd_netlink_message
*link
;
1538 r
= sd_rtnl_message_new_link(m
->rtnl
, &req
, RTM_GETLINK
, 0);
1542 r
= sd_netlink_message_request_dump(req
, true);
1546 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1550 for (link
= reply
; link
; link
= sd_netlink_message_next(link
)) {
1553 m
->enumerating
= true;
1555 k
= manager_rtnl_process_link(m
->rtnl
, link
, m
);
1559 m
->enumerating
= false;
1565 int manager_rtnl_enumerate_addresses(Manager
*m
) {
1566 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1567 sd_netlink_message
*addr
;
1573 r
= sd_rtnl_message_new_addr(m
->rtnl
, &req
, RTM_GETADDR
, 0, 0);
1577 r
= sd_netlink_message_request_dump(req
, true);
1581 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1585 for (addr
= reply
; addr
; addr
= sd_netlink_message_next(addr
)) {
1588 m
->enumerating
= true;
1590 k
= manager_rtnl_process_address(m
->rtnl
, addr
, m
);
1594 m
->enumerating
= false;
1600 int manager_rtnl_enumerate_routes(Manager
*m
) {
1601 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1602 sd_netlink_message
*route
;
1608 r
= sd_rtnl_message_new_route(m
->rtnl
, &req
, RTM_GETROUTE
, 0, 0);
1612 r
= sd_netlink_message_request_dump(req
, true);
1616 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1620 for (route
= reply
; route
; route
= sd_netlink_message_next(route
)) {
1623 m
->enumerating
= true;
1625 k
= manager_rtnl_process_route(m
->rtnl
, route
, m
);
1629 m
->enumerating
= false;
1635 int manager_rtnl_enumerate_rules(Manager
*m
) {
1636 _cleanup_(sd_netlink_message_unrefp
) sd_netlink_message
*req
= NULL
, *reply
= NULL
;
1637 sd_netlink_message
*rule
;
1643 r
= sd_rtnl_message_new_routing_policy_rule(m
->rtnl
, &req
, RTM_GETRULE
, 0);
1647 r
= sd_netlink_message_request_dump(req
, true);
1651 r
= sd_netlink_call(m
->rtnl
, req
, 0, &reply
);
1653 if (r
== -EOPNOTSUPP
) {
1654 log_debug("FIB Rules are not supported by the kernel. Ignoring.");
1661 for (rule
= reply
; rule
; rule
= sd_netlink_message_next(rule
)) {
1664 m
->enumerating
= true;
1666 k
= manager_rtnl_process_rule(m
->rtnl
, rule
, m
);
1670 m
->enumerating
= false;
1676 int manager_address_pool_acquire(Manager
*m
, int family
, unsigned prefixlen
, union in_addr_union
*found
) {
1681 assert(prefixlen
> 0);
1684 LIST_FOREACH(address_pools
, p
, m
->address_pools
) {
1685 if (p
->family
!= family
)
1688 r
= address_pool_acquire(p
, prefixlen
, found
);
1696 Link
* manager_find_uplink(Manager
*m
, Link
*exclude
) {
1697 _cleanup_free_
struct local_address
*gateways
= NULL
;
1702 /* Looks for a suitable "uplink", via black magic: an
1703 * interface that is up and where the default route with the
1704 * highest priority points to. */
1706 n
= local_gateways(m
->rtnl
, 0, AF_UNSPEC
, &gateways
);
1708 log_warning_errno(n
, "Failed to determine list of default gateways: %m");
1712 for (i
= 0; i
< n
; i
++) {
1715 link
= hashmap_get(m
->links
, INT_TO_PTR(gateways
[i
].ifindex
));
1717 log_debug("Weird, found a gateway for a link we don't know. Ignoring.");
1721 if (link
== exclude
)
1724 if (link
->operstate
< LINK_OPERSTATE_ROUTABLE
)
1733 void manager_dirty(Manager
*manager
) {
1736 /* the serialized state in /run is no longer up-to-date */
1737 manager
->dirty
= true;
1740 static int set_hostname_handler(sd_bus_message
*m
, void *userdata
, sd_bus_error
*ret_error
) {
1741 Manager
*manager
= userdata
;
1742 const sd_bus_error
*e
;
1747 e
= sd_bus_message_get_error(m
);
1749 log_warning_errno(sd_bus_error_get_errno(e
), "Could not set hostname: %s", e
->message
);
1754 int manager_set_hostname(Manager
*m
, const char *hostname
) {
1757 log_debug("Setting transient hostname: '%s'", strna(hostname
));
1759 if (free_and_strdup(&m
->dynamic_hostname
, hostname
) < 0)
1762 if (!m
->bus
|| sd_bus_is_ready(m
->bus
) <= 0) {
1763 log_info("Not connected to system bus, not setting hostname.");
1767 r
= sd_bus_call_method_async(
1770 "org.freedesktop.hostname1",
1771 "/org/freedesktop/hostname1",
1772 "org.freedesktop.hostname1",
1774 set_hostname_handler
,
1781 return log_error_errno(r
, "Could not set transient hostname: %m");
1786 static int set_timezone_handler(sd_bus_message
*m
, void *userdata
, sd_bus_error
*ret_error
) {
1787 Manager
*manager
= userdata
;
1788 const sd_bus_error
*e
;
1793 e
= sd_bus_message_get_error(m
);
1795 log_warning_errno(sd_bus_error_get_errno(e
), "Could not set timezone: %s", e
->message
);
1800 int manager_set_timezone(Manager
*m
, const char *tz
) {
1806 log_debug("Setting system timezone: '%s'", tz
);
1807 if (free_and_strdup(&m
->dynamic_timezone
, tz
) < 0)
1810 if (!m
->bus
|| sd_bus_is_ready(m
->bus
) <= 0) {
1811 log_info("Not connected to system bus, not setting timezone.");
1815 r
= sd_bus_call_method_async(
1818 "org.freedesktop.timedate1",
1819 "/org/freedesktop/timedate1",
1820 "org.freedesktop.timedate1",
1822 set_timezone_handler
,
1828 return log_error_errno(r
, "Could not set timezone: %m");