2017-11-18 17:09:20 +01:00
|
|
|
/* SPDX-License-Identifier: LGPL-2.1+ */
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2018-01-11 00:39:12 +01:00
|
|
|
#include <errno.h>
|
2016-04-29 04:52:04 +02:00
|
|
|
#include <fcntl.h>
|
2014-07-03 10:04:11 +02:00
|
|
|
#include <linux/if_tun.h>
|
2016-04-29 04:52:04 +02:00
|
|
|
#include <net/if.h>
|
2016-02-19 00:34:30 +01:00
|
|
|
#include <netinet/if_ether.h>
|
2016-04-29 04:52:04 +02:00
|
|
|
#include <sys/ioctl.h>
|
|
|
|
#include <sys/stat.h>
|
|
|
|
#include <sys/types.h>
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2015-10-27 03:01:06 +01:00
|
|
|
#include "alloc-util.h"
|
2015-10-25 13:14:12 +01:00
|
|
|
#include "fd-util.h"
|
2016-11-13 02:01:19 +01:00
|
|
|
#include "netdev/tuntap.h"
|
2015-10-25 22:32:30 +01:00
|
|
|
#include "user-util.h"
|
2014-07-03 10:04:11 +02:00
|
|
|
|
|
|
|
#define TUN_DEV "/dev/net/tun"
|
|
|
|
|
|
|
|
static int netdev_fill_tuntap_message(NetDev *netdev, struct ifreq *ifr) {
|
2014-07-16 13:17:10 +02:00
|
|
|
TunTap *t;
|
2014-07-03 10:04:11 +02:00
|
|
|
|
|
|
|
assert(netdev);
|
2014-07-16 13:17:10 +02:00
|
|
|
assert(netdev->ifname);
|
2014-07-03 10:04:11 +02:00
|
|
|
assert(ifr);
|
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
if (netdev->kind == NETDEV_KIND_TAP) {
|
|
|
|
t = TAP(netdev);
|
2014-07-03 10:04:11 +02:00
|
|
|
ifr->ifr_flags |= IFF_TAP;
|
2014-07-16 13:17:10 +02:00
|
|
|
} else {
|
|
|
|
t = TUN(netdev);
|
2014-07-03 11:37:05 +02:00
|
|
|
ifr->ifr_flags |= IFF_TUN;
|
2014-07-16 13:17:10 +02:00
|
|
|
}
|
2014-07-03 11:37:05 +02:00
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
if (!t->packet_info)
|
2014-07-03 10:04:11 +02:00
|
|
|
ifr->ifr_flags |= IFF_NO_PI;
|
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
if (t->one_queue)
|
2014-07-03 10:04:11 +02:00
|
|
|
ifr->ifr_flags |= IFF_ONE_QUEUE;
|
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
if (t->multi_queue)
|
2014-07-03 10:04:11 +02:00
|
|
|
ifr->ifr_flags |= IFF_MULTI_QUEUE;
|
|
|
|
|
2015-07-14 10:25:52 +02:00
|
|
|
if (t->vnet_hdr)
|
|
|
|
ifr->ifr_flags |= IFF_VNET_HDR;
|
|
|
|
|
2014-07-03 10:04:11 +02:00
|
|
|
strncpy(ifr->ifr_name, netdev->ifname, IFNAMSIZ-1);
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int netdev_tuntap_add(NetDev *netdev, struct ifreq *ifr) {
|
|
|
|
_cleanup_close_ int fd;
|
2014-07-16 13:17:10 +02:00
|
|
|
TunTap *t = NULL;
|
2014-07-03 10:04:11 +02:00
|
|
|
const char *user;
|
|
|
|
const char *group;
|
|
|
|
uid_t uid;
|
|
|
|
gid_t gid;
|
2014-09-06 22:06:58 +02:00
|
|
|
int r;
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
assert(netdev);
|
|
|
|
assert(ifr);
|
|
|
|
|
2018-08-02 19:10:01 +02:00
|
|
|
fd = open(TUN_DEV, O_RDWR|O_CLOEXEC);
|
2015-06-12 10:31:51 +02:00
|
|
|
if (fd < 0)
|
|
|
|
return log_netdev_error_errno(netdev, -errno, "Failed to open tun dev: %m");
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2018-06-25 19:01:16 +02:00
|
|
|
if (ioctl(fd, TUNSETIFF, ifr) < 0)
|
2015-06-12 10:31:51 +02:00
|
|
|
return log_netdev_error_errno(netdev, -errno, "TUNSETIFF failed on tun dev: %m");
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
if (netdev->kind == NETDEV_KIND_TAP)
|
|
|
|
t = TAP(netdev);
|
|
|
|
else
|
|
|
|
t = TUN(netdev);
|
|
|
|
|
|
|
|
assert(t);
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2016-02-23 18:52:52 +01:00
|
|
|
if (t->user_name) {
|
2014-07-16 13:17:10 +02:00
|
|
|
user = t->user_name;
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2018-08-02 18:36:47 +02:00
|
|
|
r = get_user_creds(&user, &uid, NULL, NULL, NULL, USER_CREDS_ALLOW_MISSING);
|
2015-06-12 10:31:51 +02:00
|
|
|
if (r < 0)
|
|
|
|
return log_netdev_error_errno(netdev, r, "Cannot resolve user name %s: %m", t->user_name);
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2018-06-25 19:01:16 +02:00
|
|
|
if (ioctl(fd, TUNSETOWNER, uid) < 0)
|
2015-06-12 10:31:51 +02:00
|
|
|
return log_netdev_error_errno(netdev, -errno, "TUNSETOWNER failed on tun dev: %m");
|
2014-07-03 10:04:11 +02:00
|
|
|
}
|
|
|
|
|
2015-04-21 01:26:59 +02:00
|
|
|
if (t->group_name) {
|
2014-07-16 13:17:10 +02:00
|
|
|
group = t->group_name;
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2018-08-02 18:36:47 +02:00
|
|
|
r = get_group_creds(&group, &gid, USER_CREDS_ALLOW_MISSING);
|
2015-06-12 10:31:51 +02:00
|
|
|
if (r < 0)
|
|
|
|
return log_netdev_error_errno(netdev, r, "Cannot resolve group name %s: %m", t->group_name);
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2018-06-25 19:01:16 +02:00
|
|
|
if (ioctl(fd, TUNSETGROUP, gid) < 0)
|
2015-06-12 10:31:51 +02:00
|
|
|
return log_netdev_error_errno(netdev, -errno, "TUNSETGROUP failed on tun dev: %m");
|
2014-07-03 10:04:11 +02:00
|
|
|
|
|
|
|
}
|
|
|
|
|
2018-06-25 19:01:16 +02:00
|
|
|
if (ioctl(fd, TUNSETPERSIST, 1) < 0)
|
2015-06-12 10:31:51 +02:00
|
|
|
return log_netdev_error_errno(netdev, -errno, "TUNSETPERSIST failed on tun dev: %m");
|
2014-07-03 10:04:11 +02:00
|
|
|
|
2014-09-06 22:06:58 +02:00
|
|
|
return 0;
|
2014-07-03 10:04:11 +02:00
|
|
|
}
|
|
|
|
|
2014-07-06 14:07:34 +02:00
|
|
|
static int netdev_create_tuntap(NetDev *netdev) {
|
2014-07-16 13:17:10 +02:00
|
|
|
struct ifreq ifr = {};
|
2014-07-03 10:04:11 +02:00
|
|
|
int r;
|
|
|
|
|
|
|
|
r = netdev_fill_tuntap_message(netdev, &ifr);
|
2016-02-23 18:52:52 +01:00
|
|
|
if (r < 0)
|
2014-07-03 10:04:11 +02:00
|
|
|
return r;
|
|
|
|
|
|
|
|
return netdev_tuntap_add(netdev, &ifr);
|
|
|
|
}
|
2014-07-06 14:07:34 +02:00
|
|
|
|
2014-07-16 13:17:10 +02:00
|
|
|
static void tuntap_done(NetDev *netdev) {
|
|
|
|
TunTap *t = NULL;
|
|
|
|
|
|
|
|
assert(netdev);
|
|
|
|
|
|
|
|
if (netdev->kind == NETDEV_KIND_TUN)
|
|
|
|
t = TUN(netdev);
|
|
|
|
else
|
|
|
|
t = TAP(netdev);
|
|
|
|
|
|
|
|
assert(t);
|
|
|
|
|
2015-09-08 18:43:11 +02:00
|
|
|
t->user_name = mfree(t->user_name);
|
|
|
|
t->group_name = mfree(t->group_name);
|
2014-07-16 13:17:10 +02:00
|
|
|
}
|
|
|
|
|
2014-08-18 12:29:45 +02:00
|
|
|
static int tuntap_verify(NetDev *netdev, const char *filename) {
|
|
|
|
assert(netdev);
|
|
|
|
|
2018-04-20 16:33:00 +02:00
|
|
|
if (netdev->mtu != 0)
|
2015-04-21 01:26:59 +02:00
|
|
|
log_netdev_warning(netdev, "MTU configured for %s, ignoring", netdev_kind_to_string(netdev->kind));
|
2014-08-18 12:29:45 +02:00
|
|
|
|
2015-04-21 01:26:59 +02:00
|
|
|
if (netdev->mac)
|
|
|
|
log_netdev_warning(netdev, "MAC configured for %s, ignoring", netdev_kind_to_string(netdev->kind));
|
2014-08-18 12:29:45 +02:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2014-07-06 14:07:34 +02:00
|
|
|
const NetDevVTable tun_vtable = {
|
2014-07-16 13:17:10 +02:00
|
|
|
.object_size = sizeof(TunTap),
|
|
|
|
.sections = "Match\0NetDev\0Tun\0",
|
2014-08-18 12:29:45 +02:00
|
|
|
.config_verify = tuntap_verify,
|
2014-07-16 13:17:10 +02:00
|
|
|
.done = tuntap_done,
|
2014-07-06 14:07:34 +02:00
|
|
|
.create = netdev_create_tuntap,
|
2014-07-16 13:17:10 +02:00
|
|
|
.create_type = NETDEV_CREATE_INDEPENDENT,
|
2014-07-06 14:07:34 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
const NetDevVTable tap_vtable = {
|
2014-07-16 13:17:10 +02:00
|
|
|
.object_size = sizeof(TunTap),
|
|
|
|
.sections = "Match\0NetDev\0Tap\0",
|
2014-08-18 12:29:45 +02:00
|
|
|
.config_verify = tuntap_verify,
|
2014-07-16 13:17:10 +02:00
|
|
|
.done = tuntap_done,
|
2014-07-06 14:07:34 +02:00
|
|
|
.create = netdev_create_tuntap,
|
2014-07-16 13:17:10 +02:00
|
|
|
.create_type = NETDEV_CREATE_INDEPENDENT,
|
2014-07-06 14:07:34 +02:00
|
|
|
};
|