Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 1 | // Copyright 2020 The Monogon Project Authors. |
| 2 | // |
| 3 | // SPDX-License-Identifier: Apache-2.0 |
| 4 | // |
| 5 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 6 | // you may not use this file except in compliance with the License. |
| 7 | // You may obtain a copy of the License at |
| 8 | // |
| 9 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 10 | // |
| 11 | // Unless required by applicable law or agreed to in writing, software |
| 12 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 13 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 14 | // See the License for the specific language governing permissions and |
| 15 | // limitations under the License. |
| 16 | |
| 17 | package network |
| 18 | |
| 19 | import ( |
| 20 | "context" |
| 21 | "fmt" |
Lorenz Brun | f042e6f | 2020-06-24 16:46:09 +0200 | [diff] [blame] | 22 | "io/ioutil" |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 23 | "net" |
| 24 | "os" |
| 25 | |
Lorenz Brun | b682ba5 | 2020-07-08 14:51:36 +0200 | [diff] [blame] | 26 | "github.com/google/nftables" |
| 27 | "github.com/google/nftables/expr" |
| 28 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 29 | "github.com/vishvananda/netlink" |
| 30 | "go.uber.org/zap" |
| 31 | "golang.org/x/sys/unix" |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 32 | |
| 33 | "git.monogon.dev/source/nexantic.git/core/internal/common/supervisor" |
| 34 | "git.monogon.dev/source/nexantic.git/core/internal/network/dhcp" |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 35 | ) |
| 36 | |
| 37 | const ( |
| 38 | resolvConfPath = "/etc/resolv.conf" |
| 39 | resolvConfSwapPath = "/etc/resolv.conf.new" |
| 40 | ) |
| 41 | |
| 42 | type Service struct { |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 43 | config Config |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 44 | dhcp *dhcp.Client |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 45 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 46 | logger *zap.Logger |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 47 | } |
| 48 | |
| 49 | type Config struct { |
| 50 | } |
| 51 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 52 | func New(config Config) *Service { |
| 53 | return &Service{ |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 54 | config: config, |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 55 | dhcp: dhcp.New(), |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 56 | } |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 57 | } |
| 58 | |
| 59 | func setResolvconf(nameservers []net.IP, searchDomains []string) error { |
Leopold Schabel | 68c5875 | 2019-11-14 21:00:59 +0100 | [diff] [blame] | 60 | _ = os.Mkdir("/etc", 0755) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 61 | newResolvConf, err := os.Create(resolvConfSwapPath) |
| 62 | if err != nil { |
| 63 | return err |
| 64 | } |
| 65 | defer newResolvConf.Close() |
| 66 | defer os.Remove(resolvConfSwapPath) |
| 67 | for _, ns := range nameservers { |
| 68 | if _, err := newResolvConf.WriteString(fmt.Sprintf("nameserver %v\n", ns)); err != nil { |
| 69 | return err |
| 70 | } |
| 71 | } |
| 72 | for _, searchDomain := range searchDomains { |
| 73 | if _, err := newResolvConf.WriteString(fmt.Sprintf("search %v", searchDomain)); err != nil { |
| 74 | return err |
| 75 | } |
| 76 | } |
| 77 | newResolvConf.Close() |
| 78 | // Atomically swap in new config |
| 79 | return unix.Rename(resolvConfSwapPath, resolvConfPath) |
| 80 | } |
| 81 | |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 82 | func (s *Service) addNetworkRoutes(link netlink.Link, addr net.IPNet, gw net.IP) error { |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 83 | if err := netlink.AddrReplace(link, &netlink.Addr{IPNet: &addr}); err != nil { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 84 | return fmt.Errorf("failed to add DHCP address to network interface \"%v\": %w", link.Attrs().Name, err) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 85 | } |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 86 | |
| 87 | if gw.IsUnspecified() { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 88 | s.logger.Info("No default route set, only local network will be reachable", zap.String("local", addr.String())) |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 89 | return nil |
| 90 | } |
| 91 | |
| 92 | route := &netlink.Route{ |
Lorenz Brun | 45333b6 | 2019-11-11 15:26:27 +0100 | [diff] [blame] | 93 | Dst: &net.IPNet{IP: net.IPv4(0, 0, 0, 0), Mask: net.IPv4Mask(0, 0, 0, 0)}, |
| 94 | Gw: gw, |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 95 | Scope: netlink.SCOPE_UNIVERSE, |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 96 | } |
| 97 | if err := netlink.RouteAdd(route); err != nil { |
| 98 | return fmt.Errorf("could not add default route: netlink.RouteAdd(%+v): %v", route, err) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 99 | } |
| 100 | return nil |
| 101 | } |
| 102 | |
Lorenz Brun | b682ba5 | 2020-07-08 14:51:36 +0200 | [diff] [blame] | 103 | // nfifname converts an interface name into 16 bytes padded with zeroes (for nftables) |
| 104 | func nfifname(n string) []byte { |
| 105 | b := make([]byte, 16) |
| 106 | copy(b, []byte(n+"\x00")) |
| 107 | return b |
| 108 | } |
| 109 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 110 | func (s *Service) useInterface(ctx context.Context, iface netlink.Link) error { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 111 | err := supervisor.Run(ctx, "dhcp", s.dhcp.Run(iface)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 112 | if err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 113 | return err |
| 114 | } |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 115 | status, err := s.dhcp.Status(ctx, true) |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 116 | if err != nil { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 117 | return fmt.Errorf("could not get DHCP Status: %w", err) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 118 | } |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 119 | |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 120 | if err := setResolvconf(status.DNS, []string{}); err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 121 | s.logger.Warn("failed to set resolvconf", zap.Error(err)) |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 122 | } |
| 123 | |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 124 | if err := s.addNetworkRoutes(iface, status.Address, status.Gateway); err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 125 | s.logger.Warn("failed to add routes", zap.Error(err)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 126 | } |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 127 | |
Lorenz Brun | b682ba5 | 2020-07-08 14:51:36 +0200 | [diff] [blame] | 128 | c := nftables.Conn{} |
| 129 | |
| 130 | nat := c.AddTable(&nftables.Table{ |
| 131 | Family: nftables.TableFamilyIPv4, |
| 132 | Name: "nat", |
| 133 | }) |
| 134 | |
| 135 | postrouting := c.AddChain(&nftables.Chain{ |
| 136 | Name: "postrouting", |
| 137 | Hooknum: nftables.ChainHookPostrouting, |
| 138 | Priority: nftables.ChainPriorityNATSource, |
| 139 | Table: nat, |
| 140 | Type: nftables.ChainTypeNAT, |
| 141 | }) |
| 142 | |
| 143 | // Masquerade/SNAT all traffic going out of the external interface |
| 144 | c.AddRule(&nftables.Rule{ |
| 145 | Table: nat, |
| 146 | Chain: postrouting, |
| 147 | Exprs: []expr.Any{ |
| 148 | &expr.Meta{Key: expr.MetaKeyOIFNAME, Register: 1}, |
| 149 | &expr.Cmp{ |
| 150 | Op: expr.CmpOpEq, |
| 151 | Register: 1, |
| 152 | Data: nfifname(iface.Attrs().Name), |
| 153 | }, |
| 154 | &expr.Masq{}, |
| 155 | }, |
| 156 | }) |
| 157 | |
| 158 | if err := c.Flush(); err != nil { |
| 159 | panic(err) |
| 160 | } |
| 161 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 162 | return nil |
| 163 | } |
| 164 | |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 165 | // GetIP returns the current IP (and optionally waits for one to be assigned) |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 166 | func (s *Service) GetIP(ctx context.Context, wait bool) (*net.IP, error) { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 167 | status, err := s.dhcp.Status(ctx, wait) |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 168 | if err != nil { |
| 169 | return nil, err |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 170 | } |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 171 | return &status.Address.IP, nil |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 172 | } |
| 173 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 174 | func (s *Service) Run(ctx context.Context) error { |
| 175 | s.logger = supervisor.Logger(ctx) |
| 176 | s.logger.Info("Starting network service") |
| 177 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 178 | links, err := netlink.LinkList() |
| 179 | if err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 180 | s.logger.Fatal("Failed to list network links", zap.Error(err)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 181 | } |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 182 | |
Lorenz Brun | f042e6f | 2020-06-24 16:46:09 +0200 | [diff] [blame] | 183 | if err := ioutil.WriteFile("/proc/sys/net/ipv4/ip_forward", []byte("1\n"), 0644); err != nil { |
| 184 | s.logger.Panic("Failed to enable IPv4 forwarding", zap.Error(err)) |
| 185 | } |
| 186 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 187 | var ethernetLinks []netlink.Link |
| 188 | for _, link := range links { |
| 189 | attrs := link.Attrs() |
| 190 | if link.Type() == "device" && len(attrs.HardwareAddr) > 0 { |
| 191 | if len(attrs.HardwareAddr) == 6 { // Ethernet |
| 192 | if attrs.Flags&net.FlagUp != net.FlagUp { |
| 193 | netlink.LinkSetUp(link) // Attempt to take up all ethernet links |
| 194 | } |
| 195 | ethernetLinks = append(ethernetLinks, link) |
| 196 | } else { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 197 | s.logger.Info("Ignoring non-Ethernet interface", zap.String("interface", attrs.Name)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 198 | } |
Lorenz Brun | 45333b6 | 2019-11-11 15:26:27 +0100 | [diff] [blame] | 199 | } else if link.Attrs().Name == "lo" { |
| 200 | if err := netlink.LinkSetUp(link); err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 201 | s.logger.Error("Failed to take up loopback interface", zap.Error(err)) |
Lorenz Brun | 45333b6 | 2019-11-11 15:26:27 +0100 | [diff] [blame] | 202 | } |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 203 | } |
| 204 | } |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 205 | if len(ethernetLinks) != 1 { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 206 | s.logger.Warn("Network service needs exactly one link, bailing") |
| 207 | } else { |
| 208 | link := ethernetLinks[0] |
| 209 | if err := s.useInterface(ctx, link); err != nil { |
| 210 | return fmt.Errorf("failed to bring up link %s: %w", link.Attrs().Name, err) |
| 211 | } |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 212 | } |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 213 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 214 | supervisor.Signal(ctx, supervisor.SignalHealthy) |
| 215 | supervisor.Signal(ctx, supervisor.SignalDone) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 216 | return nil |
| 217 | } |