Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 1 | // Copyright 2020 The Monogon Project Authors. |
| 2 | // |
| 3 | // SPDX-License-Identifier: Apache-2.0 |
| 4 | // |
| 5 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 6 | // you may not use this file except in compliance with the License. |
| 7 | // You may obtain a copy of the License at |
| 8 | // |
| 9 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 10 | // |
| 11 | // Unless required by applicable law or agreed to in writing, software |
| 12 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 13 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 14 | // See the License for the specific language governing permissions and |
| 15 | // limitations under the License. |
| 16 | |
| 17 | package network |
| 18 | |
| 19 | import ( |
| 20 | "context" |
| 21 | "fmt" |
Lorenz Brun | f042e6f | 2020-06-24 16:46:09 +0200 | [diff] [blame] | 22 | "io/ioutil" |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 23 | "net" |
| 24 | "os" |
| 25 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 26 | "github.com/vishvananda/netlink" |
| 27 | "go.uber.org/zap" |
| 28 | "golang.org/x/sys/unix" |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 29 | |
| 30 | "git.monogon.dev/source/nexantic.git/core/internal/common/supervisor" |
| 31 | "git.monogon.dev/source/nexantic.git/core/internal/network/dhcp" |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 32 | ) |
| 33 | |
| 34 | const ( |
| 35 | resolvConfPath = "/etc/resolv.conf" |
| 36 | resolvConfSwapPath = "/etc/resolv.conf.new" |
| 37 | ) |
| 38 | |
| 39 | type Service struct { |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 40 | config Config |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 41 | dhcp *dhcp.Client |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 42 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 43 | logger *zap.Logger |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 44 | } |
| 45 | |
| 46 | type Config struct { |
| 47 | } |
| 48 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 49 | func New(config Config) *Service { |
| 50 | return &Service{ |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 51 | config: config, |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 52 | dhcp: dhcp.New(), |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 53 | } |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 54 | } |
| 55 | |
| 56 | func setResolvconf(nameservers []net.IP, searchDomains []string) error { |
Leopold Schabel | 68c5875 | 2019-11-14 21:00:59 +0100 | [diff] [blame] | 57 | _ = os.Mkdir("/etc", 0755) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 58 | newResolvConf, err := os.Create(resolvConfSwapPath) |
| 59 | if err != nil { |
| 60 | return err |
| 61 | } |
| 62 | defer newResolvConf.Close() |
| 63 | defer os.Remove(resolvConfSwapPath) |
| 64 | for _, ns := range nameservers { |
| 65 | if _, err := newResolvConf.WriteString(fmt.Sprintf("nameserver %v\n", ns)); err != nil { |
| 66 | return err |
| 67 | } |
| 68 | } |
| 69 | for _, searchDomain := range searchDomains { |
| 70 | if _, err := newResolvConf.WriteString(fmt.Sprintf("search %v", searchDomain)); err != nil { |
| 71 | return err |
| 72 | } |
| 73 | } |
| 74 | newResolvConf.Close() |
| 75 | // Atomically swap in new config |
| 76 | return unix.Rename(resolvConfSwapPath, resolvConfPath) |
| 77 | } |
| 78 | |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 79 | func (s *Service) addNetworkRoutes(link netlink.Link, addr net.IPNet, gw net.IP) error { |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 80 | if err := netlink.AddrReplace(link, &netlink.Addr{IPNet: &addr}); err != nil { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 81 | return fmt.Errorf("failed to add DHCP address to network interface \"%v\": %w", link.Attrs().Name, err) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 82 | } |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 83 | |
| 84 | if gw.IsUnspecified() { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 85 | s.logger.Info("No default route set, only local network will be reachable", zap.String("local", addr.String())) |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 86 | return nil |
| 87 | } |
| 88 | |
| 89 | route := &netlink.Route{ |
Lorenz Brun | 45333b6 | 2019-11-11 15:26:27 +0100 | [diff] [blame] | 90 | Dst: &net.IPNet{IP: net.IPv4(0, 0, 0, 0), Mask: net.IPv4Mask(0, 0, 0, 0)}, |
| 91 | Gw: gw, |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 92 | Scope: netlink.SCOPE_UNIVERSE, |
Serge Bazanski | 1a5a667 | 2020-02-18 10:09:43 +0100 | [diff] [blame] | 93 | } |
| 94 | if err := netlink.RouteAdd(route); err != nil { |
| 95 | return fmt.Errorf("could not add default route: netlink.RouteAdd(%+v): %v", route, err) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 96 | } |
| 97 | return nil |
| 98 | } |
| 99 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 100 | func (s *Service) useInterface(ctx context.Context, iface netlink.Link) error { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 101 | err := supervisor.Run(ctx, "dhcp", s.dhcp.Run(iface)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 102 | if err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 103 | return err |
| 104 | } |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 105 | status, err := s.dhcp.Status(ctx, true) |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 106 | if err != nil { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 107 | return fmt.Errorf("could not get DHCP Status: %w", err) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 108 | } |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 109 | |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 110 | if err := setResolvconf(status.DNS, []string{}); err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 111 | s.logger.Warn("failed to set resolvconf", zap.Error(err)) |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 112 | } |
| 113 | |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 114 | if err := s.addNetworkRoutes(iface, status.Address, status.Gateway); err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 115 | s.logger.Warn("failed to add routes", zap.Error(err)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 116 | } |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 117 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 118 | return nil |
| 119 | } |
| 120 | |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 121 | // GetIP returns the current IP (and optionally waits for one to be assigned) |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 122 | func (s *Service) GetIP(ctx context.Context, wait bool) (*net.IP, error) { |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 123 | status, err := s.dhcp.Status(ctx, wait) |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 124 | if err != nil { |
| 125 | return nil, err |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 126 | } |
Lorenz Brun | 52f7f29 | 2020-06-24 16:42:02 +0200 | [diff] [blame] | 127 | return &status.Address.IP, nil |
Lorenz Brun | aa6b734 | 2019-12-12 02:55:02 +0100 | [diff] [blame] | 128 | } |
| 129 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 130 | func (s *Service) Run(ctx context.Context) error { |
| 131 | s.logger = supervisor.Logger(ctx) |
| 132 | s.logger.Info("Starting network service") |
| 133 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 134 | links, err := netlink.LinkList() |
| 135 | if err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 136 | s.logger.Fatal("Failed to list network links", zap.Error(err)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 137 | } |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 138 | |
Lorenz Brun | f042e6f | 2020-06-24 16:46:09 +0200 | [diff] [blame] | 139 | if err := ioutil.WriteFile("/proc/sys/net/ipv4/ip_forward", []byte("1\n"), 0644); err != nil { |
| 140 | s.logger.Panic("Failed to enable IPv4 forwarding", zap.Error(err)) |
| 141 | } |
| 142 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 143 | var ethernetLinks []netlink.Link |
| 144 | for _, link := range links { |
| 145 | attrs := link.Attrs() |
| 146 | if link.Type() == "device" && len(attrs.HardwareAddr) > 0 { |
| 147 | if len(attrs.HardwareAddr) == 6 { // Ethernet |
| 148 | if attrs.Flags&net.FlagUp != net.FlagUp { |
| 149 | netlink.LinkSetUp(link) // Attempt to take up all ethernet links |
| 150 | } |
| 151 | ethernetLinks = append(ethernetLinks, link) |
| 152 | } else { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 153 | s.logger.Info("Ignoring non-Ethernet interface", zap.String("interface", attrs.Name)) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 154 | } |
Lorenz Brun | 45333b6 | 2019-11-11 15:26:27 +0100 | [diff] [blame] | 155 | } else if link.Attrs().Name == "lo" { |
| 156 | if err := netlink.LinkSetUp(link); err != nil { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 157 | s.logger.Error("Failed to take up loopback interface", zap.Error(err)) |
Lorenz Brun | 45333b6 | 2019-11-11 15:26:27 +0100 | [diff] [blame] | 158 | } |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 159 | } |
| 160 | } |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 161 | if len(ethernetLinks) != 1 { |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 162 | s.logger.Warn("Network service needs exactly one link, bailing") |
| 163 | } else { |
| 164 | link := ethernetLinks[0] |
| 165 | if err := s.useInterface(ctx, link); err != nil { |
| 166 | return fmt.Errorf("failed to bring up link %s: %w", link.Attrs().Name, err) |
| 167 | } |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 168 | } |
Serge Bazanski | cdb8c78 | 2020-02-17 12:34:02 +0100 | [diff] [blame] | 169 | |
Serge Bazanski | b1b742f | 2020-03-24 13:58:19 +0100 | [diff] [blame] | 170 | supervisor.Signal(ctx, supervisor.SignalHealthy) |
| 171 | supervisor.Signal(ctx, supervisor.SignalDone) |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 172 | return nil |
| 173 | } |