1 /* 2 * netifd - network interface daemon 3 * Copyright (C) 2012 Felix Fietkau <nbd@openwrt.org> 4 * Copyright (C) 2012 Steven Barth <steven@midlink.org> 5 * 6 * This program is free software; you can redistribute it and/or modify 7 * it under the terms of the GNU General Public License version 2 8 * as published by the Free Software Foundation 9 * 10 * This program is distributed in the hope that it will be useful, 11 * but WITHOUT ANY WARRANTY; without even the implied warranty of 12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 13 * GNU General Public License for more details. 14 */ 15 #include <string.h> 16 #include <stdlib.h> 17 #include <stdio.h> 18 #include <libgen.h> 19 #include <sys/stat.h> 20 21 #include <limits.h> 22 #include <arpa/inet.h> 23 #include <netinet/in.h> 24 25 #include "netifd.h" 26 #include "device.h" 27 #include "interface.h" 28 #include "interface-ip.h" 29 #include "proto.h" 30 #include "ubus.h" 31 #include "system.h" 32 33 enum { 34 ROUTE_INTERFACE, 35 ROUTE_TARGET, 36 ROUTE_MASK, 37 ROUTE_GATEWAY, 38 ROUTE_METRIC, 39 ROUTE_MTU, 40 ROUTE_VALID, 41 ROUTE_TABLE, 42 ROUTE_SOURCE, 43 ROUTE_ONLINK, 44 ROUTE_TYPE, 45 ROUTE_PROTO, 46 ROUTE_DISABLED, 47 __ROUTE_MAX 48 }; 49 50 static const struct blobmsg_policy route_attr[__ROUTE_MAX] = { 51 [ROUTE_INTERFACE] = { .name = "interface", .type = BLOBMSG_TYPE_STRING }, 52 [ROUTE_TARGET] = { .name = "target", .type = BLOBMSG_TYPE_STRING }, 53 [ROUTE_MASK] = { .name = "netmask", .type = BLOBMSG_TYPE_STRING }, 54 [ROUTE_GATEWAY] = { .name = "gateway", .type = BLOBMSG_TYPE_STRING }, 55 [ROUTE_METRIC] = { .name = "metric", .type = BLOBMSG_TYPE_INT32 }, 56 [ROUTE_MTU] = { .name = "mtu", .type = BLOBMSG_TYPE_INT32 }, 57 [ROUTE_TABLE] = { .name = "table", .type = BLOBMSG_TYPE_STRING }, 58 [ROUTE_VALID] = { .name = "valid", .type = BLOBMSG_TYPE_INT32 }, 59 [ROUTE_SOURCE] = { .name = "source", .type = BLOBMSG_TYPE_STRING }, 60 [ROUTE_ONLINK] = { .name = "onlink", .type = BLOBMSG_TYPE_BOOL }, 61 [ROUTE_TYPE] = { .name = "type", .type = BLOBMSG_TYPE_STRING }, 62 [ROUTE_PROTO] = { .name = "proto", .type = BLOBMSG_TYPE_STRING }, 63 [ROUTE_DISABLED] = { .name = "disabled", .type = BLOBMSG_TYPE_BOOL }, 64 }; 65 66 const struct uci_blob_param_list route_attr_list = { 67 .n_params = __ROUTE_MAX, 68 .params = route_attr, 69 }; 70 71 enum { 72 NEIGHBOR_INTERFACE, 73 NEIGHBOR_ADDRESS, 74 NEIGHBOR_MAC, 75 NEIGHBOR_PROXY, 76 NEIGHBOR_ROUTER, 77 __NEIGHBOR_MAX 78 }; 79 80 static const struct blobmsg_policy neighbor_attr[__NEIGHBOR_MAX]={ 81 [NEIGHBOR_INTERFACE]= { .name = "interface", .type = BLOBMSG_TYPE_STRING}, 82 [NEIGHBOR_ADDRESS]= { .name = "ipaddr", .type = BLOBMSG_TYPE_STRING}, 83 [NEIGHBOR_MAC]= { .name = "mac", .type = BLOBMSG_TYPE_STRING}, 84 [NEIGHBOR_PROXY]= { .name = "proxy", .type = BLOBMSG_TYPE_BOOL}, 85 [NEIGHBOR_ROUTER]= {.name = "router", .type = BLOBMSG_TYPE_BOOL}, 86 }; 87 88 const struct uci_blob_param_list neighbor_attr_list = { 89 .n_params = __NEIGHBOR_MAX, 90 .params = neighbor_attr, 91 }; 92 93 94 struct list_head prefixes = LIST_HEAD_INIT(prefixes); 95 static struct device_prefix *ula_prefix = NULL; 96 static struct uloop_timeout valid_until_timeout; 97 98 99 static void 100 clear_if_addr(union if_addr *a, int mask) 101 { 102 size_t m_bytes = (mask + 7) / 8; 103 uint8_t m_clear = (1 << (m_bytes * 8 - mask)) - 1; 104 uint8_t *p = (uint8_t *) a; 105 106 if (m_bytes < sizeof(*a)) 107 memset(p + m_bytes, 0, sizeof(*a) - m_bytes); 108 109 if (m_bytes) 110 p[m_bytes - 1] &= ~m_clear; 111 } 112 113 static bool 114 addr_is_offlink(struct device *dev, struct device_addr *addr) 115 { 116 /* 117 * The offlink mechanism (suppress the kernel connected route and add an 118 * unreachable prefix route as a loop guard) only makes sense on shared 119 * segments. A point-to-point link has a single peer and no loop risk, so 120 * the kernel connected route is the correct way to reach the prefix there. 121 * 122 * Query the device state live rather than caching it: this is only called 123 * while applying an address to a device that is already up, so the flag is 124 * guaranteed to be available, with none of the ordering races a cached 125 * value would introduce. 126 */ 127 return (addr->flags & DEVADDR_OFFLINK) && 128 !(dev && system_if_is_point_to_point(dev)); 129 } 130 131 static bool 132 match_if_addr(union if_addr *a1, union if_addr *a2, int mask) 133 { 134 union if_addr *p1, *p2; 135 136 p1 = alloca(sizeof(*a1)); 137 p2 = alloca(sizeof(*a2)); 138 139 memcpy(p1, a1, sizeof(*a1)); 140 clear_if_addr(p1, mask); 141 memcpy(p2, a2, sizeof(*a2)); 142 clear_if_addr(p2, mask); 143 144 return !memcmp(p1, p2, sizeof(*p1)); 145 } 146 147 static int set_ip_source_policy(bool add, bool v6, unsigned int priority, 148 const union if_addr *addr, uint8_t mask, unsigned int table, 149 struct interface *in_iface, const char *action, bool src) 150 { 151 struct iprule rule = { 152 .flags = IPRULE_PRIORITY, 153 .priority = priority 154 }; 155 156 if (addr) { 157 if (src) { 158 rule.flags |= IPRULE_SRC; 159 rule.src_addr = *addr; 160 rule.src_mask = mask; 161 } else { 162 rule.flags |= IPRULE_DEST; 163 rule.dest_addr = *addr; 164 rule.dest_mask = mask; 165 } 166 } 167 168 if (table) { 169 rule.flags |= IPRULE_LOOKUP; 170 rule.lookup = table; 171 172 if (!rule.lookup) 173 return 0; 174 } else if (action) { 175 rule.flags |= IPRULE_ACTION; 176 system_resolve_iprule_action(action, &rule.action); 177 } 178 179 if (in_iface && in_iface->l3_dev.dev) { 180 rule.flags |= IPRULE_IN; 181 strcpy(rule.in_dev, in_iface->l3_dev.dev->ifname); 182 } 183 184 rule.flags |= (v6) ? IPRULE_INET6 : IPRULE_INET4; 185 186 return (add) ? system_add_iprule(&rule) : system_del_iprule(&rule); 187 } 188 189 static int set_ip_lo_policy(bool add, bool v6, struct interface *iface) 190 { 191 struct iprule rule = { 192 .flags = IPRULE_IN | IPRULE_LOOKUP | IPRULE_PRIORITY, 193 .priority = IPRULE_PRIORITY_NW + iface->l3_dev.dev->ifindex, 194 .lookup = (v6) ? iface->ip6table : iface->ip4table, 195 .in_dev = "lo" 196 }; 197 198 if (!rule.lookup) 199 return 0; 200 201 rule.flags |= (v6) ? IPRULE_INET6 : IPRULE_INET4; 202 203 return (add) ? system_add_iprule(&rule) : system_del_iprule(&rule); 204 } 205 206 static bool 207 __find_ip_addr_target(struct interface_ip_settings *ip, union if_addr *a, bool v6) 208 { 209 struct device_addr *addr; 210 211 vlist_for_each_element(&ip->addr, addr, node) { 212 if (!addr->enabled) 213 continue; 214 215 if (v6 != ((addr->flags & DEVADDR_FAMILY) == DEVADDR_INET6)) 216 continue; 217 218 if (((addr->flags & DEVADDR_FAMILY) == DEVADDR_INET4) && 219 addr->point_to_point && a->in.s_addr == addr->point_to_point) 220 return true; 221 222 /* Handle offlink addresses correctly */ 223 unsigned int mask = addr->mask; 224 if ((addr->flags & DEVADDR_FAMILY) == DEVADDR_INET6 && 225 (addr->flags & DEVADDR_OFFLINK)) 226 mask = 128; 227 228 if (!match_if_addr(&addr->addr, a, mask)) 229 continue; 230 231 return true; 232 } 233 234 return false; 235 } 236 237 static void 238 __find_ip_route_target(struct interface_ip_settings *ip, union if_addr *a, 239 bool v6, struct device_route **res) 240 { 241 struct device_route *route; 242 243 vlist_for_each_element(&ip->route, route, node) { 244 if (!route->enabled) 245 continue; 246 247 if (v6 != ((route->flags & DEVADDR_FAMILY) == DEVADDR_INET6)) 248 continue; 249 250 if (!match_if_addr(&route->addr, a, route->mask)) 251 continue; 252 253 if (route->flags & DEVROUTE_TABLE) 254 continue; 255 256 if (!*res || route->mask > (*res)->mask || 257 ((route->mask == (*res)->mask) && (route->flags & DEVROUTE_METRIC) 258 && (route->metric < (*res)->metric))) 259 *res = route; 260 } 261 } 262 263 static bool 264 interface_ip_find_addr_target(struct interface *iface, union if_addr *a, bool v6) 265 { 266 return __find_ip_addr_target(&iface->proto_ip, a, v6) || 267 __find_ip_addr_target(&iface->config_ip, a, v6); 268 } 269 270 static void 271 interface_ip_find_route_target(struct interface *iface, union if_addr *a, 272 bool v6, struct device_route **route) 273 { 274 __find_ip_route_target(&iface->proto_ip, a, v6, route); 275 __find_ip_route_target(&iface->config_ip, a, v6, route); 276 } 277 278 struct interface * 279 interface_ip_add_target_route(union if_addr *addr, bool v6, struct interface *iface, 280 bool exclude) 281 { 282 struct device_route *route, *r_next = NULL; 283 bool defaultroute_target = false; 284 union if_addr addr_zero; 285 int addrsize = v6 ? sizeof(addr->in6) : sizeof(addr->in); 286 struct interface *exclude_iface = NULL; 287 288 if (exclude) { 289 exclude_iface = iface; 290 iface = NULL; 291 } 292 293 memset(&addr_zero, 0, sizeof(addr_zero)); 294 if (memcmp(&addr_zero, addr, addrsize) == 0) 295 defaultroute_target = true; 296 297 if (iface) { 298 /* look for locally addressable target first */ 299 if (interface_ip_find_addr_target(iface, addr, v6)) 300 return iface; 301 302 /* do not stop at the first route, let the lookup compare 303 * masks to find the best match */ 304 interface_ip_find_route_target(iface, addr, v6, &r_next); 305 } else { 306 vlist_for_each_element(&interfaces, iface, node) { 307 if (iface == exclude_iface) 308 continue; 309 310 /* look for locally addressable target first */ 311 if (interface_ip_find_addr_target(iface, addr, v6)) 312 return iface; 313 314 /* do not stop at the first route, let the lookup compare 315 * masks to find the best match */ 316 interface_ip_find_route_target(iface, addr, v6, &r_next); 317 } 318 } 319 320 if (!r_next) 321 return NULL; 322 323 iface = r_next->iface; 324 if (defaultroute_target) 325 return iface; 326 327 route = calloc(1, sizeof(*route)); 328 if (!route) 329 return NULL; 330 331 route->flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 332 route->mask = v6 ? 128 : 32; 333 memcpy(&route->addr, addr, addrsize); 334 memcpy(&route->nexthop, &r_next->nexthop, sizeof(route->nexthop)); 335 route->mtu = r_next->mtu; 336 route->metric = r_next->metric; 337 route->table = r_next->table; 338 route->valid_until = r_next->valid_until; 339 route->iface = iface; 340 vlist_add(&iface->host_routes, &route->node, route); 341 342 return iface; 343 } 344 345 static void 346 interface_set_route_info(struct interface *iface, struct device_route *route) 347 { 348 bool v6 = ((route->flags & DEVADDR_FAMILY) == DEVADDR_INET6); 349 350 if (!iface) 351 return; 352 353 if (!(route->flags & DEVROUTE_METRIC)) 354 route->metric = iface->metric; 355 356 if (!(route->flags & DEVROUTE_TABLE)) { 357 route->table = (v6) ? iface->ip6table : iface->ip4table; 358 if (route->table) 359 route->flags |= DEVROUTE_SRCTABLE; 360 } 361 } 362 363 void 364 interface_ip_add_neighbor(struct interface *iface, struct blob_attr *attr, bool v6) 365 { 366 struct interface_ip_settings *ip; 367 struct blob_attr *tb[__NEIGHBOR_MAX], *cur; 368 struct device_neighbor *neighbor; 369 int af = v6 ? AF_INET6: AF_INET; 370 struct ether_addr *ea; 371 372 blobmsg_parse_attr(neighbor_attr, __NEIGHBOR_MAX, tb, attr); 373 374 if (!iface) { 375 if ((cur = tb[NEIGHBOR_INTERFACE]) == NULL) 376 return; 377 378 iface = vlist_find(&interfaces, blobmsg_data(cur), iface, node); 379 380 if (!iface) 381 return; 382 383 ip = &iface->config_ip; 384 } else 385 ip = &iface->proto_ip; 386 387 neighbor = calloc(1,sizeof(*neighbor)); 388 if (!neighbor) 389 return; 390 391 neighbor->flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 392 393 if ((cur = tb[NEIGHBOR_ADDRESS]) != NULL){ 394 if (!inet_pton(af, blobmsg_data(cur), &neighbor->addr)) 395 goto error; 396 } else 397 goto error; 398 399 if ((cur = tb[NEIGHBOR_MAC]) != NULL) { 400 neighbor->flags |= DEVNEIGH_MAC; 401 ea = ether_aton(blobmsg_data(cur)); 402 if (!ea) 403 goto error; 404 405 memcpy(neighbor->macaddr, ea, 6); 406 } 407 408 if ((cur = tb[NEIGHBOR_PROXY]) != NULL) 409 neighbor->proxy = blobmsg_get_bool(cur); 410 411 if ((cur = tb[NEIGHBOR_ROUTER]) != NULL) 412 neighbor->router = blobmsg_get_bool(cur); 413 414 vlist_add(&ip->neighbor, &neighbor->node, neighbor); 415 return; 416 417 error: 418 free(neighbor); 419 } 420 421 void 422 interface_ip_add_route(struct interface *iface, struct blob_attr *attr, bool v6) 423 { 424 struct interface_ip_settings *ip; 425 struct blob_attr *tb[__ROUTE_MAX], *cur; 426 struct device_route *route; 427 int af = v6 ? AF_INET6 : AF_INET; 428 bool no_device = false; 429 430 blobmsg_parse_attr(route_attr, __ROUTE_MAX, tb, attr); 431 432 if ((cur = tb[ROUTE_DISABLED]) != NULL && blobmsg_get_bool(cur)) 433 return; 434 435 if (!iface) { 436 if ((cur = tb[ROUTE_INTERFACE]) == NULL) { 437 iface = vlist_find(&interfaces, "loopback", iface, node); 438 no_device = true; 439 } else { 440 iface = vlist_find(&interfaces, blobmsg_data(cur), iface, node); 441 } 442 443 if (!iface) 444 return; 445 446 ip = &iface->config_ip; 447 } else { 448 ip = &iface->proto_ip; 449 } 450 451 route = calloc(1, sizeof(*route)); 452 if (!route) 453 return; 454 455 route->flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 456 route->mask = v6 ? 128 : 32; 457 if ((cur = tb[ROUTE_MASK]) != NULL) { 458 route->mask = parse_netmask_string(blobmsg_data(cur), v6); 459 if (route->mask > (v6 ? 128 : 32)) 460 goto error; 461 } 462 463 if ((cur = tb[ROUTE_TARGET]) != NULL) { 464 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &route->addr, &route->mask)) { 465 D(INTERFACE, "Failed to parse route target: %s", (char *) blobmsg_data(cur)); 466 goto error; 467 } 468 469 /* Mask out IPv4 host bits to avoid "Invalid prefix for given prefix length" */ 470 if (af == AF_INET && route->mask < 32) 471 clear_if_addr(&route->addr, route->mask); 472 } 473 474 if ((cur = tb[ROUTE_GATEWAY]) != NULL) { 475 if (!inet_pton(af, blobmsg_data(cur), &route->nexthop)) { 476 D(INTERFACE, "Failed to parse route gateway: %s", (char *) blobmsg_data(cur)); 477 goto error; 478 } 479 } 480 481 if ((cur = tb[ROUTE_METRIC]) != NULL) { 482 route->metric = blobmsg_get_u32(cur); 483 route->flags |= DEVROUTE_METRIC; 484 } 485 486 if ((cur = tb[ROUTE_MTU]) != NULL) { 487 route->mtu = blobmsg_get_u32(cur); 488 route->flags |= DEVROUTE_MTU; 489 } 490 491 /* Use source-based routing */ 492 if ((cur = tb[ROUTE_SOURCE]) != NULL) { 493 char *saveptr, *source = alloca(blobmsg_data_len(cur)); 494 memcpy(source, blobmsg_data(cur), blobmsg_data_len(cur)); 495 496 const char *addr = strtok_r(source, "/", &saveptr); 497 const char *mask = strtok_r(NULL, "/", &saveptr); 498 499 if (!addr || inet_pton(af, addr, &route->source) < 1) { 500 D(INTERFACE, "Failed to parse route source: %s", addr ? addr : "NULL"); 501 goto error; 502 } 503 504 if (mask) { 505 char *e; 506 507 route->sourcemask = strtoul(mask, &e, 10); 508 if (e == mask || *e || 509 route->sourcemask > ((af == AF_INET6) ? 128 : 32)) { 510 D(INTERFACE, "Invalid route source mask: %s", mask); 511 goto error; 512 } 513 } else { 514 route->sourcemask = (af == AF_INET6) ? 128 : 32; 515 } 516 } 517 518 if ((cur = tb[ROUTE_ONLINK]) != NULL && blobmsg_get_bool(cur)) 519 route->flags |= DEVROUTE_ONLINK; 520 521 if ((cur = tb[ROUTE_TABLE]) != NULL) { 522 if (!system_resolve_rt_table(blobmsg_data(cur), &route->table)) { 523 D(INTERFACE, "Failed to resolve routing table: %s", (char *) blobmsg_data(cur)); 524 goto error; 525 } 526 527 /* only set the table flag if not using the main (default) table */ 528 if (system_is_default_rt_table(route->table)) 529 route->table = 0; 530 531 if (route->table) 532 route->flags |= DEVROUTE_TABLE; 533 } 534 535 if ((cur = tb[ROUTE_VALID]) != NULL) { 536 int64_t valid = blobmsg_get_u32(cur); 537 int64_t valid_until = valid + (int64_t)system_get_rtime(); 538 if (valid_until <= LONG_MAX && valid != 0xffffffffLL) /* Catch overflow */ 539 route->valid_until = valid_until; 540 } 541 542 if ((cur = tb[ROUTE_TYPE]) != NULL) { 543 if (!system_resolve_rt_type(blobmsg_data(cur), &route->type)) { 544 D(INTERFACE, "Failed to resolve routing type: %s", (char *) blobmsg_data(cur)); 545 goto error; 546 } 547 route->flags |= DEVROUTE_TYPE; 548 } 549 550 if ((cur = tb[ROUTE_PROTO]) != NULL) { 551 if (!system_resolve_rt_proto(blobmsg_data(cur), &route->proto)) { 552 D(INTERFACE, "Failed to resolve proto type: %s", (char *) blobmsg_data(cur)); 553 goto error; 554 } 555 route->flags |= DEVROUTE_PROTO; 556 } 557 558 if (no_device) 559 route->flags |= DEVROUTE_NODEV; 560 else 561 interface_set_route_info(iface, route); 562 563 vlist_add(&ip->route, &route->node, route); 564 return; 565 566 error: 567 free(route); 568 } 569 570 static int 571 addr_cmp(const void *k1, const void *k2, void *ptr) 572 { 573 const struct device_addr *a1 = k1; 574 const struct device_addr *a2 = k2; 575 const int cmp_offset = offsetof(struct device_addr, flags); 576 const int cmp_size = sizeof(struct device_addr) - cmp_offset; 577 578 if (a1->index != a2->index) 579 return a1->index - a2->index; 580 return memcmp(k1+cmp_offset, k2+cmp_offset, cmp_size); 581 } 582 583 /* 584 * Look for a current node covering the same kernel address (the kernel 585 * matches addresses by family, local address and prefix length only) 586 */ 587 static struct device_addr * 588 interface_addr_find_current(struct vlist_tree *tree, struct device_addr *a_old) 589 { 590 struct device_addr *a; 591 592 if (tree->version == -1) 593 return NULL; 594 595 vlist_for_each_element(tree, a, node) { 596 if (a == a_old || a->node.version != tree->version) 597 continue; 598 599 if ((a->flags & DEVADDR_FAMILY) != (a_old->flags & DEVADDR_FAMILY) || 600 a->mask != a_old->mask || 601 memcmp(&a->addr, &a_old->addr, sizeof(a->addr))) 602 continue; 603 604 return a; 605 } 606 607 return NULL; 608 } 609 610 static int 611 neighbor_cmp(const void *k1, const void *k2, void *ptr) 612 { 613 const struct device_neighbor *n1 = k1, *n2 = k2; 614 615 return memcmp(&n1->addr, &n2->addr, sizeof(n2->addr)); 616 } 617 618 static int 619 route_cmp(const void *k1, const void *k2, void *ptr) 620 { 621 const struct device_route *r1 = k1, *r2 = k2; 622 623 if (r1->mask != r2->mask) 624 return r2->mask - r1->mask; 625 626 if (r1->metric != r2->metric) 627 return r1->metric - r2->metric; 628 629 if (r1->flags != r2->flags) 630 return r2->flags - r1->flags; 631 632 if (r1->sourcemask != r2->sourcemask) 633 return r1->sourcemask - r2->sourcemask; 634 635 if (r1->table != r2->table) 636 return r1->table - r2->table; 637 638 int maskcmp = memcmp(&r1->source, &r2->source, sizeof(r1->source)); 639 if (maskcmp) 640 return maskcmp; 641 642 return memcmp(&r1->addr, &r2->addr, sizeof(r1->addr)); 643 } 644 645 static int 646 prefix_cmp(const void *k1, const void *k2, void *ptr) 647 { 648 return memcmp(k1, k2, offsetof(struct device_prefix, pclass) - 649 offsetof(struct device_prefix, addr)); 650 } 651 652 static void 653 interface_handle_subnet_route(struct interface *iface, struct device_addr *addr, bool add) 654 { 655 struct device *dev = iface->l3_dev.dev; 656 struct device_route *r = &addr->subnet; 657 658 if (addr_is_offlink(dev, addr)) 659 return; 660 661 if (!add) { 662 if (!addr->subnet.iface) 663 return; 664 665 system_del_route(dev, r); 666 memset(r, 0, sizeof(*r)); 667 return; 668 } 669 670 r->iface = iface; 671 r->flags = addr->flags; 672 r->mask = addr->mask; 673 memcpy(&r->addr, &addr->addr, sizeof(r->addr)); 674 clear_if_addr(&r->addr, r->mask); 675 676 if (!system_resolve_rt_proto("kernel", &r->proto)) 677 return; 678 679 r->flags |= DEVROUTE_PROTO; 680 system_del_route(dev, r); 681 682 r->flags &= ~DEVROUTE_PROTO; 683 interface_set_route_info(iface, r); 684 685 system_add_route(dev, r); 686 } 687 688 static void 689 interface_add_addr_rules(struct device_addr *addr, bool enabled) 690 { 691 bool v6 = (addr->flags & DEVADDR_FAMILY) == DEVADDR_INET6; 692 693 set_ip_source_policy(enabled, v6, IPRULE_PRIORITY_ADDR, &addr->addr, 694 (v6) ? 128 : 32, addr->policy_table, NULL, NULL, 695 true); 696 set_ip_source_policy(enabled, v6, IPRULE_PRIORITY_ADDR_MASK, 697 &addr->addr, addr->mask, addr->policy_table, NULL, 698 NULL, false); 699 } 700 701 static void 702 interface_update_proto_addr(struct vlist_tree *tree, 703 struct vlist_node *node_new, 704 struct vlist_node *node_old) 705 { 706 struct interface_ip_settings *ip; 707 struct interface *iface; 708 struct device *dev; 709 struct device_addr *a_new = NULL, *a_old = NULL; 710 bool replace = false; 711 bool keep = false; 712 713 ip = container_of(tree, struct interface_ip_settings, addr); 714 iface = ip->iface; 715 dev = iface->l3_dev.dev; 716 717 if (!node_new || !node_old) 718 iface->updated |= IUF_ADDRESS; 719 720 if (node_new) { 721 a_new = container_of(node_new, struct device_addr, node); 722 723 if ((a_new->flags & DEVADDR_FAMILY) == DEVADDR_INET4 && 724 !a_new->broadcast) { 725 726 /* /31 and /32 addressing need 255.255.255.255 727 * as broadcast address. */ 728 if (a_new->mask >= 31) { 729 a_new->broadcast = (uint32_t) ~0; 730 } else { 731 uint32_t mask = ~0; 732 uint32_t *a = (uint32_t *) &a_new->addr; 733 734 mask >>= a_new->mask; 735 a_new->broadcast = *a | htonl(mask); 736 } 737 } 738 } 739 740 if (node_old) 741 a_old = container_of(node_old, struct device_addr, node); 742 743 if (a_new && a_old) { 744 keep = true; 745 746 if (a_old->flags != a_new->flags || a_old->failed) 747 keep = false; 748 749 if (a_old->valid_until != a_new->valid_until || 750 a_old->preferred_until != a_new->preferred_until) 751 replace = true; 752 753 if (((a_new->flags & DEVADDR_FAMILY) == DEVADDR_INET4) && 754 (a_new->broadcast != a_old->broadcast || 755 a_new->point_to_point != a_old->point_to_point)) 756 keep = false; 757 } 758 759 if (node_old) { 760 bool v6 = (a_old->flags & DEVADDR_FAMILY) == DEVADDR_INET6; 761 762 /* 763 * The same address re-announced under a different list index 764 * is a different vlist node whose add path already ran, so 765 * the flush of the stale node must not touch the kernel 766 * state owned by the surviving node 767 */ 768 struct device_addr *a_kept = NULL; 769 770 if (!node_new) 771 a_kept = interface_addr_find_current(tree, a_old); 772 773 if (a_old->enabled && !keep) { 774 /* 775 * This is needed for source routing to work correctly. If a device 776 * has two connections to a network using the same subnet, adding 777 * only the network-rule will cause packets to be routed through the 778 * first matching network (source IP matches both masks) 779 */ 780 if (a_old->policy_table) 781 interface_add_addr_rules(a_old, false); 782 783 if (!(a_old->flags & DEVADDR_EXTERNAL)) { 784 if (!a_kept || !a_kept->subnet.iface) 785 interface_handle_subnet_route(iface, a_old, false); 786 787 if (!a_kept) 788 system_del_address(dev, a_old); 789 790 if (!(a_kept && addr_is_offlink(dev, a_kept)) && 791 addr_is_offlink(dev, a_old) && (a_old->mask < (v6 ? 128 : 32))) { 792 struct device_route route; 793 794 memset(&route, 0, sizeof(route)); 795 route.flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 796 route.metric = INT32_MAX; 797 route.mask = a_old->mask; 798 route.addr = a_old->addr; 799 800 clear_if_addr(&route.addr, route.mask); 801 802 /* Delete null-route */ 803 system_del_route(NULL, &route); 804 } 805 806 } 807 } 808 809 /* 810 * Keep the subnet route state so it can be deleted later. With 811 * replace set the add path rebuilds it instead, and the copied 812 * metric would poison the metric-agnostic delete of the 813 * kernel-created prefix route there 814 */ 815 if (keep && !replace) 816 a_new->subnet = a_old->subnet; 817 818 free(a_old->pclass); 819 free(a_old); 820 } 821 822 if (node_new) { 823 bool v6 = (a_new->flags & DEVADDR_FAMILY) == DEVADDR_INET6; 824 825 a_new->enabled = true; 826 a_new->policy_table = (v6) ? iface->ip6table : iface->ip4table; 827 828 if (!keep || replace) { 829 if (!(a_new->flags & DEVADDR_EXTERNAL)) { 830 if (system_add_address(dev, a_new)) 831 a_new->failed = true; 832 833 if (iface->metric || a_new->policy_table) 834 interface_handle_subnet_route(iface, a_new, true); 835 } 836 837 if (!keep) { 838 if (!(a_new->flags & DEVADDR_EXTERNAL) && 839 addr_is_offlink(dev, a_new) && 840 (a_new->mask < (v6 ? 128 : 32))) { 841 struct device_route route; 842 843 memset(&route, 0, sizeof(route)); 844 route.flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 845 route.metric = INT32_MAX; 846 route.mask = a_new->mask; 847 route.addr = a_new->addr; 848 849 clear_if_addr(&route.addr, route.mask); 850 851 /* 852 * In case off link is specifed as address property 853 * add null-route to avoid routing loops 854 */ 855 system_add_route(NULL, &route); 856 } 857 858 if (a_new->policy_table) 859 interface_add_addr_rules(a_new, true); 860 } 861 } 862 } 863 } 864 865 static bool 866 enable_route(struct interface_ip_settings *ip, struct device_route *route) 867 { 868 if (ip->no_defaultroute && !route->mask) 869 return false; 870 871 return ip->enabled; 872 } 873 874 static void 875 interface_update_proto_neighbor(struct vlist_tree *tree, 876 struct vlist_node * node_new, 877 struct vlist_node *node_old) 878 { 879 struct device *dev; 880 struct device_neighbor *neighbor_old, *neighbor_new; 881 struct interface_ip_settings *ip; 882 bool keep = false; 883 884 ip = container_of(tree, struct interface_ip_settings, neighbor); 885 dev = ip->iface->l3_dev.dev; 886 887 neighbor_old = container_of(node_old, struct device_neighbor, node); 888 neighbor_new = container_of(node_new, struct device_neighbor, node); 889 890 if (node_old && node_new) { 891 keep = (!memcmp(neighbor_old->macaddr, neighbor_new->macaddr, sizeof(neighbor_old->macaddr)) && 892 (neighbor_old->proxy == neighbor_new->proxy) && 893 (neighbor_old->router == neighbor_new->router)); 894 } 895 896 if (node_old) { 897 if (!keep && neighbor_old->enabled) 898 system_del_neighbor(dev, neighbor_old); 899 900 free(neighbor_old); 901 } 902 903 if (node_new) { 904 if (!keep && ip->enabled) 905 if (system_add_neighbor(dev, neighbor_new)) 906 neighbor_new->failed = true; 907 908 neighbor_new->enabled = ip->enabled; 909 } 910 } 911 912 static void 913 __interface_update_route(struct interface_ip_settings *ip, 914 struct vlist_node *node_new, 915 struct vlist_node *node_old) 916 { 917 struct interface *iface = ip->iface; 918 struct device *dev; 919 struct device_route *route_old, *route_new; 920 bool keep = false; 921 922 dev = iface->l3_dev.dev; 923 924 if (!node_new || !node_old) 925 iface->updated |= IUF_ROUTE; 926 927 route_old = container_of(node_old, struct device_route, node); 928 route_new = container_of(node_new, struct device_route, node); 929 930 if (node_old && node_new) 931 keep = !memcmp(&route_old->nexthop, &route_new->nexthop, sizeof(route_old->nexthop)) && 932 (route_old->mtu == route_new->mtu) && (route_old->type == route_new->type) && 933 (route_old->proto == route_new->proto) && !route_old->failed; 934 935 if (node_old) { 936 if (!(route_old->flags & DEVADDR_EXTERNAL) && route_old->enabled && !keep) 937 system_del_route(dev, route_old); 938 939 free(route_old); 940 } 941 942 if (node_new) { 943 bool _enabled = enable_route(ip, route_new); 944 945 if (!(route_new->flags & DEVADDR_EXTERNAL) && !keep && _enabled) 946 if (system_add_route(dev, route_new)) 947 route_new->failed = true; 948 949 route_new->iface = iface; 950 route_new->enabled = _enabled; 951 } 952 } 953 954 static void 955 interface_update_proto_route(struct vlist_tree *tree, 956 struct vlist_node *node_new, 957 struct vlist_node *node_old) 958 { 959 struct interface_ip_settings *ip; 960 961 ip = container_of(tree, struct interface_ip_settings, route); 962 __interface_update_route(ip, node_new, node_old); 963 } 964 965 static void 966 interface_update_host_route(struct vlist_tree *tree, 967 struct vlist_node *node_new, 968 struct vlist_node *node_old) 969 { 970 struct interface *iface; 971 972 iface = container_of(tree, struct interface, host_routes); 973 __interface_update_route(&iface->proto_ip, node_new, node_old); 974 } 975 976 static void 977 random_ifaceid(struct in6_addr *addr) 978 { 979 static bool initialized = false; 980 struct timeval t; 981 982 if (!initialized) { 983 long int seed = 0; 984 gettimeofday(&t, NULL); 985 seed = t.tv_sec ^ t.tv_usec ^ getpid(); 986 srand48(seed); 987 initialized = true; 988 } 989 addr->s6_addr32[2] = (uint32_t)mrand48(); 990 addr->s6_addr32[3] = (uint32_t)mrand48(); 991 } 992 993 static bool 994 eui64_ifaceid(struct interface *iface, struct in6_addr *addr) 995 { 996 struct device_settings st; 997 998 device_merge_settings(iface->l3_dev.dev, &st); 999 1000 if (!(st.flags & DEV_OPT_MACADDR)) 1001 return false; 1002 1003 /* get mac address */ 1004 uint8_t *ifaceid = addr->s6_addr + 8; 1005 memcpy(ifaceid, st.macaddr, 3); 1006 memcpy(ifaceid + 5, st.macaddr + 3, 3); 1007 ifaceid[3] = 0xff; 1008 ifaceid[4] = 0xfe; 1009 ifaceid[0] ^= 0x02; 1010 1011 return true; 1012 } 1013 1014 static bool 1015 generate_ifaceid(struct interface *iface, struct in6_addr *addr) 1016 { 1017 bool ret = true; 1018 1019 /* generate new iface id */ 1020 switch (iface->assignment_iface_id_selection) { 1021 case IFID_FIXED: 1022 /* fixed */ 1023 /* copy host part from assignment_fixed_iface_id */ 1024 memcpy(addr->s6_addr + 8, iface->assignment_fixed_iface_id.s6_addr + 8, 8); 1025 break; 1026 case IFID_RANDOM: 1027 /* randomize last 64 bits */ 1028 random_ifaceid(addr); 1029 break; 1030 case IFID_EUI64: 1031 /* eui64 */ 1032 ret = eui64_ifaceid(iface, addr); 1033 break; 1034 default: 1035 ret = false; 1036 break; 1037 } 1038 return ret; 1039 } 1040 1041 static void 1042 interface_set_prefix_address(struct device_prefix_assignment *assignment, 1043 const struct device_prefix *prefix, struct interface *iface, bool add) 1044 { 1045 const struct interface *uplink = prefix->iface; 1046 if (!iface->l3_dev.dev) 1047 return; 1048 1049 struct device *l3_downlink = iface->l3_dev.dev; 1050 1051 struct device_addr addr; 1052 struct device_route route; 1053 memset(&addr, 0, sizeof(addr)); 1054 memset(&route, 0, sizeof(route)); 1055 1056 addr.addr.in6 = assignment->addr; 1057 addr.mask = assignment->length; 1058 addr.flags = DEVADDR_INET6; 1059 addr.preferred_until = prefix->preferred_until; 1060 addr.valid_until = prefix->valid_until; 1061 1062 route.flags = DEVADDR_INET6; 1063 route.mask = addr.mask < 64 ? 64 : addr.mask; 1064 route.addr = addr.addr; 1065 1066 if (!add && assignment->enabled) { 1067 time_t now = system_get_rtime(); 1068 1069 if (addr.valid_until && addr.valid_until - 1 <= now) { 1070 addr.valid_until = 0; 1071 addr.preferred_until = 0; 1072 } else { 1073 /* Address is still valid; pass its ownership to kernel (see L-14 RFC 7084). */ 1074 addr.preferred_until = now; 1075 1076 if (!addr.valid_until || addr.valid_until > now + 7200) 1077 addr.valid_until = now + 7200; 1078 } 1079 1080 if (iface->ip6table) 1081 set_ip_source_policy(false, true, IPRULE_PRIORITY_ADDR_MASK, &addr.addr, 1082 addr.mask < 64 ? 64 : addr.mask, iface->ip6table, NULL, NULL, false); 1083 1084 if (prefix->iface) { 1085 if (prefix->iface->ip6table) 1086 set_ip_source_policy(false, true, IPRULE_PRIORITY_NW, &addr.addr, 1087 addr.mask, prefix->iface->ip6table, iface, NULL, true); 1088 1089 set_ip_source_policy(false, true, IPRULE_PRIORITY_REJECT, &addr.addr, 1090 addr.mask, 0, iface, "unreachable", true); 1091 } 1092 1093 clear_if_addr(&route.addr, route.mask); 1094 interface_set_route_info(iface, &route); 1095 1096 system_del_route(l3_downlink, &route); 1097 if (addr.valid_until) 1098 system_add_address(l3_downlink, &addr); 1099 else 1100 system_del_address(l3_downlink, &addr); 1101 1102 assignment->addr = in6addr_any; 1103 assignment->enabled = false; 1104 } else if (add && (iface->state == IFS_UP || iface->state == IFS_SETUP)) { 1105 if (IN6_IS_ADDR_UNSPECIFIED(&addr.addr.in6)) { 1106 addr.addr.in6 = prefix->addr; 1107 addr.addr.in6.s6_addr32[1] |= htonl(assignment->assigned); 1108 if (!generate_ifaceid(iface, &addr.addr.in6)) 1109 return; 1110 1111 assignment->addr = addr.addr.in6; 1112 route.addr = addr.addr; 1113 } 1114 1115 addr.flags |= DEVADDR_OFFLINK; 1116 if (system_add_address(l3_downlink, &addr)) 1117 return; 1118 1119 if (!assignment->enabled) { 1120 if (iface->ip6table) 1121 set_ip_source_policy(true, true, IPRULE_PRIORITY_ADDR_MASK, &addr.addr, 1122 addr.mask < 64 ? 64 : addr.mask, iface->ip6table, NULL, NULL, false); 1123 1124 if (prefix->iface) { 1125 set_ip_source_policy(true, true, IPRULE_PRIORITY_REJECT, &addr.addr, 1126 addr.mask, 0, iface, "unreachable", true); 1127 1128 if (prefix->iface->ip6table) 1129 set_ip_source_policy(true, true, IPRULE_PRIORITY_NW, &addr.addr, 1130 addr.mask, prefix->iface->ip6table, iface, NULL, true); 1131 } 1132 } 1133 1134 clear_if_addr(&route.addr, route.mask); 1135 interface_set_route_info(iface, &route); 1136 1137 system_add_route(l3_downlink, &route); 1138 1139 if (uplink && uplink->l3_dev.dev && !(l3_downlink->settings.flags & DEV_OPT_MTU6)) { 1140 int mtu = system_update_ipv6_mtu(uplink->l3_dev.dev, 0); 1141 int mtu_old = system_update_ipv6_mtu(l3_downlink, 0); 1142 1143 if (mtu > 0 && mtu_old != mtu) { 1144 if (system_update_ipv6_mtu(l3_downlink, mtu) < 0 && mtu < mtu_old) 1145 netifd_log_message(L_WARNING, "Failed to set IPv6 mtu to %d " 1146 "on interface '%s'\n", mtu, iface->name); 1147 } 1148 } 1149 1150 assignment->enabled = true; 1151 } 1152 } 1153 1154 /* 1155 * Size of a sub-prefix in /64 units, saturated to the representable 1156 * assignment space: prefixes shorter than /34 exceed the int32_t offset 1157 * range used for assignments 1158 */ 1159 static int32_t prefix_assignment_space(uint8_t length) 1160 { 1161 if (length < 34) 1162 return INT32_MAX; 1163 1164 return 1 << (64 - length); 1165 } 1166 1167 static bool interface_prefix_assign(struct list_head *list, 1168 struct device_prefix_assignment *assign) 1169 { 1170 int32_t asize = (1 << (64 - assign->length)) - 1; 1171 int64_t current = 0; 1172 struct device_prefix_assignment *c; 1173 1174 list_for_each_entry(c, list, head) { 1175 if (assign->assigned != -1) { 1176 if (assign->assigned >= current && assign->assigned + (int64_t)asize < c->assigned) { 1177 list_add_tail(&assign->head, &c->head); 1178 return true; 1179 } 1180 } else if (assign->assigned == -1) { 1181 current = (current + asize) & ~(int64_t)asize; 1182 if (current + asize < c->assigned) { 1183 assign->assigned = current; 1184 list_add_tail(&assign->head, &c->head); 1185 return true; 1186 } 1187 } 1188 current = (int64_t)c->assigned + prefix_assignment_space(c->length); 1189 } 1190 return false; 1191 } 1192 1193 /* 1194 * Sorting of assignment entries: 1195 * Primary on assignment length: smallest assignment first 1196 * Secondary on assignment weight: highest weight first 1197 * Finally alphabetical order of interface names 1198 */ 1199 static int prefix_assignment_cmp(const void *k1, const void *k2, void *ptr) 1200 { 1201 const struct device_prefix_assignment *a1 = k1, *a2 = k2; 1202 1203 if (a1->length != a2->length) 1204 return a1->length - a2->length; 1205 1206 if (a1->weight != a2->weight) 1207 return a2->weight - a1->weight; 1208 1209 return strcmp(a1->name, a2->name); 1210 } 1211 1212 static void interface_update_prefix_assignments(struct device_prefix *prefix, bool setup) 1213 { 1214 struct device_prefix_assignment *c; 1215 struct interface *iface; 1216 1217 /* Delete all assignments */ 1218 while (!list_empty(&prefix->assignments)) { 1219 c = list_first_entry(&prefix->assignments, 1220 struct device_prefix_assignment, head); 1221 if ((iface = vlist_find(&interfaces, c->name, iface, node))) 1222 interface_set_prefix_address(c, prefix, iface, false); 1223 list_del(&c->head); 1224 free(c); 1225 } 1226 1227 if (!setup) 1228 return; 1229 1230 /* End-of-assignment sentinel */ 1231 c = malloc(sizeof(*c) + 1); 1232 if (!c) 1233 return; 1234 1235 c->assigned = prefix_assignment_space(prefix->length); 1236 c->length = 64; 1237 c->name[0] = 0; 1238 c->addr = in6addr_any; 1239 list_add(&c->head, &prefix->assignments); 1240 1241 /* Excluded prefix */ 1242 if (prefix->excl_length > 0) { 1243 const char name[] = "!excluded"; 1244 c = malloc(sizeof(*c) + sizeof(name)); 1245 if (c) { 1246 int32_t mask = prefix_assignment_space(prefix->length); 1247 1248 if (mask != INT32_MAX) 1249 mask -= 1; 1250 1251 c->assigned = ntohl(prefix->excl_addr.s6_addr32[1]) & mask; 1252 c->length = prefix->excl_length; 1253 c->addr = in6addr_any; 1254 memcpy(c->name, name, sizeof(name)); 1255 list_add(&c->head, &prefix->assignments); 1256 } 1257 } 1258 1259 bool assigned_any = false; 1260 struct { 1261 struct avl_node node; 1262 } *entry, *n_entry; 1263 struct avl_tree assign_later; 1264 1265 avl_init(&assign_later, prefix_assignment_cmp, false, NULL); 1266 1267 vlist_for_each_element(&interfaces, iface, node) { 1268 if (iface->assignment_length < 48 || 1269 iface->assignment_length > 64) 1270 continue; 1271 1272 /* Test whether there is a matching class */ 1273 if (!list_empty(&iface->assignment_classes)) { 1274 bool found = false; 1275 1276 struct interface_assignment_class *c; 1277 list_for_each_entry(c, &iface->assignment_classes, head) { 1278 if (!strcmp(c->name, prefix->pclass)) { 1279 found = true; 1280 break; 1281 } 1282 } 1283 1284 if (!found) 1285 continue; 1286 } 1287 1288 size_t namelen = strlen(iface->name) + 1; 1289 c = malloc(sizeof(*c) + namelen); 1290 if (!c) 1291 continue; 1292 1293 c->length = iface->assignment_length; 1294 c->assigned = iface->assignment_hint; 1295 c->weight = iface->assignment_weight; 1296 c->addr = in6addr_any; 1297 c->enabled = false; 1298 memcpy(c->name, iface->name, namelen); 1299 1300 /* First process all custom assignments, put all others in later-list */ 1301 if (c->assigned == -1 || !interface_prefix_assign(&prefix->assignments, c)) { 1302 if (c->assigned != -1) { 1303 c->assigned = -1; 1304 netifd_log_message(L_WARNING, "Failed to assign requested subprefix " 1305 "of size %hhu for %s, trying other\n", c->length, c->name); 1306 } 1307 1308 entry = calloc(1, sizeof(*entry)); 1309 if (!entry) { 1310 free(c); 1311 continue; 1312 } 1313 1314 entry->node.key = c; 1315 avl_insert(&assign_later, &entry->node); 1316 } 1317 1318 if (c->assigned != -1) 1319 assigned_any = true; 1320 } 1321 1322 /* Then try to assign all other + failed custom assignments */ 1323 avl_for_each_element_safe(&assign_later, entry, node, n_entry) { 1324 bool assigned = false; 1325 1326 c = (struct device_prefix_assignment *)entry->node.key; 1327 avl_delete(&assign_later, &entry->node); 1328 1329 do { 1330 assigned = interface_prefix_assign(&prefix->assignments, c); 1331 } while (!assigned && ++c->length <= 64); 1332 1333 if (!assigned) { 1334 netifd_log_message(L_WARNING, "Failed to assign subprefix " 1335 "of size %hhu for %s\n", c->length, c->name); 1336 free(c); 1337 } else 1338 assigned_any = true; 1339 1340 free(entry); 1341 } 1342 1343 list_for_each_entry(c, &prefix->assignments, head) 1344 if ((iface = vlist_find(&interfaces, c->name, iface, node))) 1345 interface_set_prefix_address(c, prefix, iface, true); 1346 1347 if (!assigned_any) 1348 netifd_log_message(L_WARNING, "You have delegated IPv6-prefixes but haven't assigned them " 1349 "to any interface. Did you forget to set option ip6assign on your lan-interfaces?"); 1350 } 1351 1352 1353 void interface_refresh_assignments(bool hint) 1354 { 1355 static bool refresh = false; 1356 if (!hint && refresh) { 1357 struct device_prefix *p; 1358 time_t now = system_get_rtime(); 1359 1360 list_for_each_entry(p, &prefixes, head) { 1361 bool valid = !(p->valid_until && p->valid_until - 1 <= now); 1362 1363 interface_update_prefix_assignments(p, valid); 1364 } 1365 } 1366 refresh = hint; 1367 } 1368 1369 void interface_update_prefix_delegation(struct interface_ip_settings *ip) 1370 { 1371 struct device_prefix *prefix; 1372 time_t now = system_get_rtime(); 1373 1374 vlist_for_each_element(&ip->prefix, prefix, node) { 1375 bool valid = !(prefix->valid_until && prefix->valid_until - 1 <= now); 1376 1377 interface_update_prefix_assignments(prefix, !ip->no_delegation && valid); 1378 1379 if (ip->no_delegation) { 1380 if (prefix->head.next) 1381 list_del(&prefix->head); 1382 } else 1383 list_add(&prefix->head, &prefixes); 1384 } 1385 } 1386 1387 static void 1388 interface_update_prefix(struct vlist_tree *tree, 1389 struct vlist_node *node_new, 1390 struct vlist_node *node_old) 1391 { 1392 struct device_prefix *prefix_old, *prefix_new; 1393 prefix_old = container_of(node_old, struct device_prefix, node); 1394 prefix_new = container_of(node_new, struct device_prefix, node); 1395 1396 struct interface_ip_settings *ip = container_of(tree, struct interface_ip_settings, prefix); 1397 if (tree && (!node_new || !node_old)) 1398 ip->iface->updated |= IUF_PREFIX; 1399 1400 struct device_route route; 1401 memset(&route, 0, sizeof(route)); 1402 route.flags = DEVADDR_INET6; 1403 route.metric = INT32_MAX; 1404 route.mask = (node_new) ? prefix_new->length : prefix_old->length; 1405 route.addr.in6 = (node_new) ? prefix_new->addr : prefix_old->addr; 1406 1407 struct device_prefix_assignment *c; 1408 struct interface *iface; 1409 bool new_valid = node_new && !(prefix_new->valid_until && prefix_new->valid_until - 1 <= system_get_rtime()); 1410 1411 if (node_old && node_new) { 1412 /* Move assignments and refresh addresses to update valid times */ 1413 list_splice(&prefix_old->assignments, &prefix_new->assignments); 1414 1415 list_for_each_entry(c, &prefix_new->assignments, head) 1416 if ((iface = vlist_find(&interfaces, c->name, iface, node))) 1417 interface_set_prefix_address(c, prefix_new, iface, new_valid); 1418 1419 if (prefix_new->preferred_until != prefix_old->preferred_until || 1420 prefix_new->valid_until != prefix_old->valid_until) 1421 ip->iface->updated |= IUF_PREFIX; 1422 } else if (node_new) { 1423 /* Set null-route to avoid routing loops */ 1424 system_add_route(NULL, &route); 1425 1426 if (!prefix_new->iface || !prefix_new->iface->proto_ip.no_delegation) 1427 interface_update_prefix_assignments(prefix_new, new_valid); 1428 } else if (node_old) { 1429 /* Remove null-route */ 1430 interface_update_prefix_assignments(prefix_old, false); 1431 system_del_route(NULL, &route); 1432 } 1433 1434 if (node_old) { 1435 if (prefix_old->head.next) 1436 list_del(&prefix_old->head); 1437 free(prefix_old); 1438 } 1439 1440 if (node_new && (!prefix_new->iface || !prefix_new->iface->proto_ip.no_delegation)) 1441 list_add(&prefix_new->head, &prefixes); 1442 1443 } 1444 1445 struct device_prefix* 1446 interface_ip_add_device_prefix(struct interface *iface, struct in6_addr *addr, 1447 uint8_t length, time_t valid_until, time_t preferred_until, 1448 struct in6_addr *excl_addr, uint8_t excl_length, const char *pclass) 1449 { 1450 union if_addr a = { .in6 = *addr }; 1451 1452 if (!pclass) 1453 pclass = (iface) ? iface->name : "local"; 1454 1455 struct device_prefix *prefix = calloc(1, sizeof(*prefix) + strlen(pclass) + 1); 1456 if (!prefix) 1457 return NULL; 1458 1459 clear_if_addr(&a, length); 1460 1461 prefix->length = length; 1462 prefix->addr = a.in6; 1463 prefix->preferred_until = preferred_until; 1464 prefix->valid_until = valid_until; 1465 prefix->iface = iface; 1466 INIT_LIST_HEAD(&prefix->assignments); 1467 1468 if (excl_addr) { 1469 prefix->excl_addr = *excl_addr; 1470 prefix->excl_length = excl_length; 1471 } 1472 1473 strcpy(prefix->pclass, pclass); 1474 1475 if (iface) 1476 vlist_add(&iface->proto_ip.prefix, &prefix->node, &prefix->addr); 1477 else 1478 interface_update_prefix(NULL, &prefix->node, NULL); 1479 1480 return prefix; 1481 } 1482 1483 void 1484 interface_ip_set_ula_prefix(const char *prefix) 1485 { 1486 char buf[INET6_ADDRSTRLEN + 4] = {0}, *saveptr; 1487 char *prefixaddr, *prefixlen; 1488 struct in6_addr addr; 1489 int length; 1490 1491 if (prefix) 1492 strncpy(buf, prefix, sizeof(buf) - 1); 1493 prefixaddr = strtok_r(buf, "/", &saveptr); 1494 1495 if (!prefixaddr || inet_pton(AF_INET6, prefixaddr, &addr) < 1) 1496 goto invalid; 1497 1498 prefixlen = strtok_r(NULL, ",", &saveptr); 1499 if (!prefixlen || (length = atoi(prefixlen)) < 1 || length > 64) 1500 goto invalid; 1501 1502 if (!ula_prefix || !IN6_ARE_ADDR_EQUAL(&addr, &ula_prefix->addr) || 1503 ula_prefix->length != length) { 1504 if (ula_prefix) 1505 interface_update_prefix(NULL, NULL, &ula_prefix->node); 1506 1507 ula_prefix = interface_ip_add_device_prefix(NULL, &addr, length, 1508 0, 0, NULL, 0, NULL); 1509 } 1510 1511 return; 1512 1513 invalid: 1514 if (ula_prefix) { 1515 interface_update_prefix(NULL, NULL, &ula_prefix->node); 1516 ula_prefix = NULL; 1517 } 1518 } 1519 1520 static void 1521 interface_add_dns_server(struct interface_ip_settings *ip, const char *str) 1522 { 1523 struct dns_server *s; 1524 1525 s = calloc(1, sizeof(*s)); 1526 if (!s) 1527 return; 1528 1529 s->af = AF_INET; 1530 if (inet_pton(s->af, str, &s->addr.in)) 1531 goto add; 1532 1533 s->af = AF_INET6; 1534 if (inet_pton(s->af, str, &s->addr.in6)) 1535 goto add; 1536 1537 free(s); 1538 return; 1539 1540 add: 1541 D(INTERFACE, "Add IPv%c DNS server: %s", 1542 s->af == AF_INET6 ? '6' : '4', str); 1543 vlist_simple_add(&ip->dns_servers, &s->node); 1544 } 1545 1546 void 1547 interface_add_dns_server_list(struct interface_ip_settings *ip, struct blob_attr *list) 1548 { 1549 struct blob_attr *cur; 1550 size_t rem; 1551 1552 blobmsg_for_each_attr(cur, list, rem) { 1553 if (blobmsg_type(cur) != BLOBMSG_TYPE_STRING) 1554 continue; 1555 1556 if (!blobmsg_check_attr(cur, false)) 1557 continue; 1558 1559 interface_add_dns_server(ip, blobmsg_data(cur)); 1560 } 1561 } 1562 1563 static void 1564 interface_add_dns_search_domain(struct interface_ip_settings *ip, const char *str) 1565 { 1566 struct dns_search_domain *s; 1567 int len = strlen(str); 1568 1569 s = calloc(1, sizeof(*s) + len + 1); 1570 if (!s) 1571 return; 1572 1573 D(INTERFACE, "Add DNS search domain: %s", str); 1574 memcpy(s->name, str, len); 1575 vlist_simple_add(&ip->dns_search, &s->node); 1576 } 1577 1578 void 1579 interface_add_dns_search_list(struct interface_ip_settings *ip, struct blob_attr *list) 1580 { 1581 struct blob_attr *cur; 1582 size_t rem; 1583 1584 blobmsg_for_each_attr(cur, list, rem) { 1585 if (blobmsg_type(cur) != BLOBMSG_TYPE_STRING) 1586 continue; 1587 1588 if (!blobmsg_check_attr(cur, false)) 1589 continue; 1590 1591 interface_add_dns_search_domain(ip, blobmsg_data(cur)); 1592 } 1593 } 1594 1595 static void 1596 write_resolv_conf_entries(FILE *f, struct interface_ip_settings *ip, const char *dev) 1597 { 1598 struct dns_server *s; 1599 struct dns_search_domain *d; 1600 const char *str; 1601 char buf[INET6_ADDRSTRLEN]; 1602 1603 vlist_simple_for_each_element(&ip->dns_servers, s, node) { 1604 str = inet_ntop(s->af, &s->addr, buf, sizeof(buf)); 1605 if (!str) 1606 continue; 1607 1608 if (s->af == AF_INET6 && IN6_IS_ADDR_LINKLOCAL(&s->addr.in6)) 1609 fprintf(f, "nameserver %s%%%s\n", str, dev); 1610 else 1611 fprintf(f, "nameserver %s\n", str); 1612 } 1613 1614 vlist_simple_for_each_element(&ip->dns_search, d, node) { 1615 fprintf(f, "search %s\n", d->name); 1616 } 1617 } 1618 1619 /* Sorting of interface resolver entries : */ 1620 /* Primary on interface dns_metric : lowest metric first */ 1621 /* Secondary on interface metric : lowest metric first */ 1622 /* Finally alphabetical order of interface names */ 1623 static int resolv_conf_iface_cmp(const void *k1, const void *k2, void *ptr) 1624 { 1625 const struct interface *iface1 = k1, *iface2 = k2; 1626 1627 if (iface1->dns_metric != iface2->dns_metric) 1628 return iface1->dns_metric - iface2->dns_metric; 1629 1630 if (iface1->metric != iface2->metric) 1631 return iface1->metric - iface2->metric; 1632 1633 return strcmp(iface1->name, iface2->name); 1634 } 1635 1636 static void 1637 __interface_write_dns_entries(FILE *f, const char *jail) 1638 { 1639 struct interface *iface; 1640 struct { 1641 struct avl_node node; 1642 } *entry, *n_entry; 1643 struct avl_tree resolv_conf_iface_entries; 1644 1645 avl_init(&resolv_conf_iface_entries, resolv_conf_iface_cmp, false, NULL); 1646 1647 vlist_for_each_element(&interfaces, iface, node) { 1648 if (iface->state != IFS_UP) 1649 continue; 1650 1651 if (jail && (!iface->jail || strcmp(jail, iface->jail))) 1652 continue; 1653 1654 if (vlist_simple_empty(&iface->proto_ip.dns_search) && 1655 vlist_simple_empty(&iface->proto_ip.dns_servers) && 1656 vlist_simple_empty(&iface->config_ip.dns_search) && 1657 vlist_simple_empty(&iface->config_ip.dns_servers)) 1658 continue; 1659 1660 entry = calloc(1, sizeof(*entry)); 1661 if (!entry) 1662 continue; 1663 1664 entry->node.key = iface; 1665 avl_insert(&resolv_conf_iface_entries, &entry->node); 1666 } 1667 1668 avl_for_each_element(&resolv_conf_iface_entries, entry, node) { 1669 iface = (struct interface *)entry->node.key; 1670 struct device *dev = iface->l3_dev.dev; 1671 1672 fprintf(f, "# Interface %s\n", iface->name); 1673 1674 write_resolv_conf_entries(f, &iface->config_ip, dev->ifname); 1675 1676 if (!iface->proto_ip.no_dns) 1677 write_resolv_conf_entries(f, &iface->proto_ip, dev->ifname); 1678 } 1679 1680 avl_remove_all_elements(&resolv_conf_iface_entries, entry, node, n_entry) 1681 free(entry); 1682 } 1683 1684 void 1685 interface_write_resolv_conf(const char *jail) 1686 { 1687 size_t plen = (jail ? strlen(jail) + 1 : 0 ) + 1688 (strlen(resolv_conf) >= strlen(DEFAULT_RESOLV_CONF) ? 1689 strlen(resolv_conf) : strlen(DEFAULT_RESOLV_CONF) ) + 1; 1690 char *path = alloca(plen); 1691 char *dpath = alloca(plen); 1692 char *tmppath = alloca(plen + 4); 1693 FILE *f; 1694 uint32_t crcold, crcnew; 1695 1696 if (jail) { 1697 sprintf(path, "/tmp/resolv.conf-%s.d/resolv.conf.auto", jail); 1698 strcpy(dpath, path); 1699 dpath = dirname(dpath); 1700 mkdir(dpath, 0755); 1701 } else { 1702 strcpy(path, resolv_conf); 1703 } 1704 1705 sprintf(tmppath, "%s.tmp", path); 1706 unlink(tmppath); 1707 f = fopen(tmppath, "w+"); 1708 if (!f) { 1709 D(INTERFACE, "Failed to open %s for writing", path); 1710 return; 1711 } 1712 1713 __interface_write_dns_entries(f, jail); 1714 1715 fflush(f); 1716 rewind(f); 1717 crcnew = crc32_file(f); 1718 fclose(f); 1719 1720 crcold = crcnew + 1; 1721 f = fopen(path, "r"); 1722 if (f) { 1723 crcold = crc32_file(f); 1724 fclose(f); 1725 } 1726 1727 if (crcold == crcnew) { 1728 unlink(tmppath); 1729 } else if (rename(tmppath, path) < 0) { 1730 D(INTERFACE, "Failed to replace %s", path); 1731 unlink(tmppath); 1732 } 1733 } 1734 1735 static void 1736 interface_ip_set_route_enabled(struct interface_ip_settings *ip, 1737 struct device_route *route, bool enabled) 1738 { 1739 struct device *dev = ip->iface->l3_dev.dev; 1740 1741 if (route->flags & DEVADDR_EXTERNAL) 1742 return; 1743 1744 if (!enable_route(ip, route)) 1745 enabled = false; 1746 1747 if (route->enabled == enabled) 1748 return; 1749 1750 if (enabled) { 1751 interface_set_route_info(ip->iface, route); 1752 1753 if (system_add_route(dev, route)) 1754 route->failed = true; 1755 } else 1756 system_del_route(dev, route); 1757 1758 route->enabled = enabled; 1759 } 1760 1761 void interface_ip_set_enabled(struct interface_ip_settings *ip, bool enabled) 1762 { 1763 struct device_addr *addr; 1764 struct device_route *route; 1765 struct device_neighbor *neighbor; 1766 struct device *dev; 1767 struct interface *iface; 1768 1769 ip->enabled = enabled; 1770 iface = ip->iface; 1771 dev = iface->l3_dev.dev; 1772 if (!dev) 1773 return; 1774 1775 vlist_for_each_element(&ip->addr, addr, node) { 1776 bool v6 = ((addr->flags & DEVADDR_FAMILY) == DEVADDR_INET6) ? true : false; 1777 1778 if (addr->flags & DEVADDR_EXTERNAL) 1779 continue; 1780 1781 if (addr->enabled == enabled) 1782 continue; 1783 1784 if (enabled) { 1785 system_add_address(dev, addr); 1786 1787 addr->policy_table = (v6) ? iface->ip6table : iface->ip4table; 1788 if (iface->metric || addr->policy_table) 1789 interface_handle_subnet_route(iface, addr, true); 1790 1791 if (addr_is_offlink(dev, addr) && (addr->mask < (v6 ? 128 : 32))) { 1792 struct device_route route; 1793 1794 memset(&route, 0, sizeof(route)); 1795 route.flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 1796 route.metric = INT32_MAX; 1797 route.mask = addr->mask; 1798 route.addr = addr->addr; 1799 1800 clear_if_addr(&route.addr, route.mask); 1801 1802 /* 1803 * In case off link is specifed as address property 1804 * add null-route to avoid routing loops 1805 */ 1806 system_add_route(NULL, &route); 1807 } 1808 1809 if (addr->policy_table) 1810 interface_add_addr_rules(addr, true); 1811 } else { 1812 interface_handle_subnet_route(iface, addr, false); 1813 system_del_address(dev, addr); 1814 1815 if (addr_is_offlink(dev, addr) && (addr->mask < (v6 ? 128 : 32))) { 1816 struct device_route route; 1817 1818 memset(&route, 0, sizeof(route)); 1819 route.flags = v6 ? DEVADDR_INET6 : DEVADDR_INET4; 1820 route.metric = INT32_MAX; 1821 route.mask = addr->mask; 1822 route.addr = addr->addr; 1823 1824 clear_if_addr(&route.addr, route.mask); 1825 1826 /* Delete null-route */ 1827 system_del_route(NULL, &route); 1828 } 1829 1830 if (addr->policy_table) 1831 interface_add_addr_rules(addr, false); 1832 } 1833 addr->enabled = enabled; 1834 } 1835 1836 vlist_for_each_element(&ip->route, route, node) 1837 interface_ip_set_route_enabled(ip, route, enabled); 1838 if (ip == &iface->proto_ip) 1839 vlist_for_each_element(&iface->host_routes, route, node) 1840 interface_ip_set_route_enabled(ip, route, enabled); 1841 1842 vlist_for_each_element(&ip->neighbor, neighbor, node) { 1843 if (neighbor->enabled == enabled) 1844 continue; 1845 1846 if (enabled) { 1847 if(system_add_neighbor(dev, neighbor)) 1848 neighbor->failed = true; 1849 } else 1850 system_del_neighbor(dev, neighbor); 1851 1852 neighbor->enabled = enabled; 1853 } 1854 1855 struct device_prefix *c; 1856 struct device_prefix_assignment *a; 1857 list_for_each_entry(c, &prefixes, head) 1858 list_for_each_entry(a, &c->assignments, head) 1859 if (!strcmp(a->name, ip->iface->name)) 1860 interface_set_prefix_address(a, c, ip->iface, enabled); 1861 1862 if (ip->iface->policy_rules_set != enabled && 1863 ip->iface->l3_dev.dev) { 1864 if (ip->iface->l3_dev.dev->settings.ipv6) { 1865 set_ip_lo_policy(enabled, true, ip->iface); 1866 set_ip_source_policy(enabled, true, IPRULE_PRIORITY_REJECT + ip->iface->l3_dev.dev->ifindex, 1867 NULL, 0, 0, ip->iface, "failed_policy", true); 1868 } 1869 set_ip_lo_policy(enabled, false, ip->iface); 1870 1871 ip->iface->policy_rules_set = enabled; 1872 } 1873 } 1874 1875 void 1876 interface_ip_update_start(struct interface_ip_settings *ip) 1877 { 1878 if (ip != &ip->iface->config_ip) { 1879 vlist_simple_update(&ip->dns_servers); 1880 vlist_simple_update(&ip->dns_search); 1881 } 1882 vlist_update(&ip->route); 1883 vlist_update(&ip->addr); 1884 vlist_update(&ip->prefix); 1885 vlist_update(&ip->neighbor); 1886 } 1887 1888 static void 1889 interface_host_routes_refresh(struct interface *iface) 1890 { 1891 struct device_route *route, *tmp, *r_next, *r_new; 1892 1893 vlist_for_each_element_safe(&iface->host_routes, route, node, tmp) { 1894 bool v6 = (route->flags & DEVADDR_FAMILY) == DEVADDR_INET6; 1895 1896 r_next = NULL; 1897 interface_ip_find_route_target(iface, &route->addr, v6, &r_next); 1898 if (!r_next) { 1899 vlist_delete(&iface->host_routes, &route->node); 1900 continue; 1901 } 1902 1903 if (!memcmp(&route->nexthop, &r_next->nexthop, sizeof(route->nexthop)) && 1904 route->mtu == r_next->mtu && route->metric == r_next->metric && 1905 route->table == r_next->table) { 1906 route->valid_until = r_next->valid_until; 1907 continue; 1908 } 1909 1910 r_new = calloc(1, sizeof(*r_new)); 1911 if (!r_new) 1912 continue; 1913 1914 r_new->flags = route->flags; 1915 r_new->mask = route->mask; 1916 memcpy(&r_new->addr, &route->addr, sizeof(r_new->addr)); 1917 memcpy(&r_new->nexthop, &r_next->nexthop, sizeof(r_new->nexthop)); 1918 r_new->mtu = r_next->mtu; 1919 r_new->metric = r_next->metric; 1920 r_new->table = r_next->table; 1921 r_new->valid_until = r_next->valid_until; 1922 r_new->iface = iface; 1923 1924 /* metric/table are part of the vlist key; a changed key means 1925 * the old node is not replaced by the add below */ 1926 if (route_cmp(r_new, route, NULL)) 1927 vlist_delete(&iface->host_routes, &route->node); 1928 1929 vlist_add(&iface->host_routes, &r_new->node, r_new); 1930 } 1931 } 1932 1933 void 1934 interface_ip_update_complete(struct interface_ip_settings *ip) 1935 { 1936 vlist_simple_flush(&ip->dns_servers); 1937 vlist_simple_flush(&ip->dns_search); 1938 vlist_flush(&ip->route); 1939 vlist_flush(&ip->addr); 1940 vlist_flush(&ip->prefix); 1941 vlist_flush(&ip->neighbor); 1942 1943 if (ip == &ip->iface->proto_ip) 1944 interface_host_routes_refresh(ip->iface); 1945 1946 interface_write_resolv_conf(ip->iface->jail); 1947 } 1948 1949 void 1950 interface_ip_flush(struct interface_ip_settings *ip) 1951 { 1952 if (ip == &ip->iface->proto_ip) 1953 vlist_flush_all(&ip->iface->host_routes); 1954 vlist_simple_flush_all(&ip->dns_servers); 1955 vlist_simple_flush_all(&ip->dns_search); 1956 vlist_flush_all(&ip->route); 1957 vlist_flush_all(&ip->addr); 1958 vlist_flush_all(&ip->neighbor); 1959 vlist_flush_all(&ip->prefix); 1960 } 1961 1962 static void 1963 __interface_ip_init(struct interface_ip_settings *ip, struct interface *iface) 1964 { 1965 ip->iface = iface; 1966 ip->enabled = true; 1967 vlist_simple_init(&ip->dns_search, struct dns_search_domain, node); 1968 vlist_simple_init(&ip->dns_servers, struct dns_server, node); 1969 vlist_init(&ip->route, route_cmp, interface_update_proto_route); 1970 vlist_init(&ip->neighbor, neighbor_cmp, interface_update_proto_neighbor); 1971 vlist_init(&ip->addr, addr_cmp, interface_update_proto_addr); 1972 vlist_init(&ip->prefix, prefix_cmp, interface_update_prefix); 1973 } 1974 1975 void 1976 interface_ip_init(struct interface *iface) 1977 { 1978 __interface_ip_init(&iface->proto_ip, iface); 1979 __interface_ip_init(&iface->config_ip, iface); 1980 vlist_init(&iface->host_routes, route_cmp, interface_update_host_route); 1981 } 1982 1983 static void 1984 interface_ip_valid_until_handler(struct uloop_timeout *t) 1985 { 1986 time_t now = system_get_rtime(); 1987 struct interface *iface; 1988 vlist_for_each_element(&interfaces, iface, node) { 1989 if (iface->state != IFS_UP) 1990 continue; 1991 1992 struct device_addr *addr, *addrp; 1993 struct device_route *route, *routep; 1994 struct device_prefix *pref, *prefp; 1995 1996 vlist_for_each_element_safe(&iface->proto_ip.addr, addr, node, addrp) 1997 if (addr->valid_until && addr->valid_until < now) 1998 vlist_delete(&iface->proto_ip.addr, &addr->node); 1999 2000 vlist_for_each_element_safe(&iface->proto_ip.route, route, node, routep) 2001 if (route->valid_until && route->valid_until < now) 2002 vlist_delete(&iface->proto_ip.route, &route->node); 2003 2004 vlist_for_each_element_safe(&iface->config_ip.route, route, node, routep) 2005 if (route->valid_until && route->valid_until < now) 2006 vlist_delete(&iface->config_ip.route, &route->node); 2007 2008 vlist_for_each_element_safe(&iface->host_routes, route, node, routep) 2009 if (route->valid_until && route->valid_until < now) 2010 vlist_delete(&iface->host_routes, &route->node); 2011 2012 vlist_for_each_element_safe(&iface->proto_ip.prefix, pref, node, prefp) 2013 if (pref->valid_until && pref->valid_until < now) 2014 vlist_delete(&iface->proto_ip.prefix, &pref->node); 2015 2016 } 2017 2018 uloop_timeout_set(t, 1000); 2019 } 2020 2021 static void __init 2022 interface_ip_init_worker(void) 2023 { 2024 valid_until_timeout.cb = interface_ip_valid_until_handler; 2025 uloop_timeout_set(&valid_until_timeout, 1000); 2026 } 2027
This page was automatically generated by LXR 0.3.1. • OpenWrt