2 * netifd - network interface daemon
3 * Copyright (C) 2012 Felix Fietkau <nbd@openwrt.org>
4 * Copyright (C) 2013 Jo-Philipp Wich <jow@openwrt.org>
5 * Copyright (C) 2018 Alexander Couzens <lynxis@fe80.eu>
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License version 2
9 * as published by the Free Software Foundation
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
21 #include <arpa/inet.h>
25 #include "interface.h"
31 struct vlist_tree iprules;
32 static bool iprules_flushed = false;
33 static unsigned int iprules_counter[2];
51 static const struct blobmsg_policy rule_attr[__RULE_MAX] = {
52 [RULE_INTERFACE_IN] = { .name = "in", .type = BLOBMSG_TYPE_STRING },
53 [RULE_INTERFACE_OUT] = { .name = "out", .type = BLOBMSG_TYPE_STRING },
54 [RULE_INVERT] = { .name = "invert", .type = BLOBMSG_TYPE_BOOL },
55 [RULE_SRC] = { .name = "src", .type = BLOBMSG_TYPE_STRING },
56 [RULE_DEST] = { .name = "dest", .type = BLOBMSG_TYPE_STRING },
57 [RULE_PRIORITY] = { .name = "priority", .type = BLOBMSG_TYPE_INT32 },
58 [RULE_TOS] = { .name = "tos", .type = BLOBMSG_TYPE_INT32 },
59 [RULE_FWMARK] = { .name = "mark", .type = BLOBMSG_TYPE_STRING },
60 [RULE_LOOKUP] = { .name = "lookup", .type = BLOBMSG_TYPE_STRING },
61 [RULE_SUP_PREFIXLEN] = { .name = "suppress_prefixlength", .type = BLOBMSG_TYPE_INT32 },
62 [RULE_ACTION] = { .name = "action", .type = BLOBMSG_TYPE_STRING },
63 [RULE_GOTO] = { .name = "goto", .type = BLOBMSG_TYPE_INT32 },
66 const struct uci_blob_param_list rule_attr_list = {
67 .n_params = __RULE_MAX,
71 /* interface based rules are dynamic. */
72 static bool rule_ready(struct iprule *rule) {
73 if (rule->flags & IPRULE_OUT && rule->out_dev == NULL)
76 if (rule->flags & IPRULE_IN && rule->in_dev == NULL)
83 iprule_parse_mark(const char *mark, struct iprule *rule)
88 if ((s = strchr(mark, '/')) != NULL)
91 n = strtoul(mark, &e, 0);
97 rule->flags |= IPRULE_FWMARK;
100 n = strtoul(s, &e, 0);
106 rule->flags |= IPRULE_FWMASK;
112 /* called on interface changes of the incoming interface */
113 static void rule_in_cb(
114 struct interface_user *dep,
115 struct interface *iface,
116 enum interface_event ev)
118 struct iprule *rule = container_of(dep, struct iprule, in_iface_user);
122 if (!iface->l3_dev.dev)
124 memcpy(rule->in_dev, iface->l3_dev.dev->ifname, sizeof(rule->in_dev));
125 if (rule_ready(rule))
126 system_add_iprule(rule);
131 if (rule_ready(rule))
132 system_del_iprule(rule);
140 /* called on interface changes of the outgoing interface */
141 static void rule_out_cb(
142 struct interface_user *dep,
143 struct interface *iface,
144 enum interface_event ev)
146 struct iprule *rule = container_of(dep, struct iprule, out_iface_user);
150 if (!iface->l3_dev.dev)
152 memcpy(rule->out_dev, iface->l3_dev.dev->ifname, sizeof(rule->out_dev));
153 if (rule_ready(rule))
154 system_add_iprule(rule);
159 if (rule_ready(rule))
160 system_del_iprule(rule);
161 rule->out_dev[0] = 0;
168 /* called on all interface events */
169 static void generic_interface_cb(
170 struct interface_user *dep,
171 struct interface *iface,
172 enum interface_event ev)
176 if (ev != IFEV_CREATE)
179 /* add new interfaces to rules */
180 vlist_for_each_element(&iprules, rule, node) {
181 if (rule_ready(rule))
184 if (!strcmp(rule->out_iface, iface->name)) {
185 assert(!rule->out_dev);
186 memcpy(rule->out_dev, iface->l3_dev.dev->ifname, sizeof(rule->out_dev));
187 interface_add_user(&rule->out_iface_user, iface);
190 if (!strcmp(rule->in_iface, iface->name)) {
191 assert(!rule->in_dev);
192 memcpy(rule->in_dev, iface->l3_dev.dev->ifname, sizeof(rule->in_dev));
193 interface_add_user(&rule->in_iface_user, iface);
198 struct interface_user generic_listener = {
199 .cb = generic_interface_cb
203 iprule_add(struct blob_attr *attr, bool v6)
205 struct blob_attr *tb[__RULE_MAX], *cur;
208 int af = v6 ? AF_INET6 : AF_INET;
210 blobmsg_parse(rule_attr, __RULE_MAX, tb, blobmsg_data(attr), blobmsg_data_len(attr));
212 rule = calloc(1, sizeof(*rule));
216 rule->flags = v6 ? IPRULE_INET6 : IPRULE_INET4;
217 rule->order = iprules_counter[rule->flags]++;
219 if ((cur = tb[RULE_INVERT]) != NULL)
220 rule->invert = blobmsg_get_bool(cur);
222 if ((cur = tb[RULE_INTERFACE_IN]) != NULL) {
223 iface_name = calloc(1, strlen(blobmsg_data(cur)) + 1);
224 rule->in_iface = strcpy(iface_name, blobmsg_data(cur));
225 rule->in_iface_user.cb = &rule_in_cb;
226 rule->flags |= IPRULE_IN;
229 if ((cur = tb[RULE_INTERFACE_OUT]) != NULL) {
230 iface_name = calloc(1, strlen(blobmsg_data(cur)) + 1);
231 rule->out_iface = strcpy(iface_name, blobmsg_data(cur));
232 rule->out_iface_user.cb = &rule_out_cb;
233 rule->flags |= IPRULE_OUT;
236 if ((cur = tb[RULE_SRC]) != NULL) {
237 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &rule->src_addr, &rule->src_mask)) {
238 DPRINTF("Failed to parse rule source: %s\n", (char *) blobmsg_data(cur));
241 rule->flags |= IPRULE_SRC;
244 if ((cur = tb[RULE_DEST]) != NULL) {
245 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &rule->dest_addr, &rule->dest_mask)) {
246 DPRINTF("Failed to parse rule destination: %s\n", (char *) blobmsg_data(cur));
249 rule->flags |= IPRULE_DEST;
252 if ((cur = tb[RULE_PRIORITY]) != NULL) {
253 rule->priority = blobmsg_get_u32(cur);
254 rule->flags |= IPRULE_PRIORITY;
257 if ((cur = tb[RULE_TOS]) != NULL) {
258 if ((rule->tos = blobmsg_get_u32(cur)) > 255) {
259 DPRINTF("Invalid TOS value: %u\n", blobmsg_get_u32(cur));
262 rule->flags |= IPRULE_TOS;
265 if ((cur = tb[RULE_FWMARK]) != NULL) {
266 if (!iprule_parse_mark(blobmsg_data(cur), rule)) {
267 DPRINTF("Failed to parse rule fwmark: %s\n", (char *) blobmsg_data(cur));
270 /* flags set by iprule_parse_mark() */
273 if ((cur = tb[RULE_LOOKUP]) != NULL) {
274 if (!system_resolve_rt_table(blobmsg_data(cur), &rule->lookup)) {
275 DPRINTF("Failed to parse rule lookup table: %s\n", (char *) blobmsg_data(cur));
278 rule->flags |= IPRULE_LOOKUP;
281 if ((cur = tb[RULE_SUP_PREFIXLEN]) != NULL) {
282 rule->sup_prefixlen = blobmsg_get_u32(cur);
283 rule->flags |= IPRULE_SUP_PREFIXLEN;
286 if ((cur = tb[RULE_ACTION]) != NULL) {
287 if (!system_resolve_iprule_action(blobmsg_data(cur), &rule->action)) {
288 DPRINTF("Failed to parse rule action: %s\n", (char *) blobmsg_data(cur));
291 rule->flags |= IPRULE_ACTION;
294 if ((cur = tb[RULE_GOTO]) != NULL) {
295 rule->gotoid = blobmsg_get_u32(cur);
296 rule->flags |= IPRULE_GOTO;
299 vlist_add(&iprules, &rule->node, &rule->flags);
307 iprule_update_start(void)
309 if (!iprules_flushed) {
310 system_flush_iprules();
311 iprules_flushed = true;
314 iprules_counter[0] = 1;
315 iprules_counter[1] = 1;
316 vlist_update(&iprules);
320 iprule_update_complete(void)
322 vlist_flush(&iprules);
327 rule_cmp(const void *k1, const void *k2, void *ptr)
329 return memcmp(k1, k2, sizeof(struct iprule)-offsetof(struct iprule, flags));
332 static void deregister_interfaces(struct iprule *rule)
334 if (rule->flags & IPRULE_IN && rule->in_iface_user.iface)
335 interface_remove_user(&rule->in_iface_user);
337 if (rule->flags & IPRULE_OUT && rule->out_iface_user.iface)
338 interface_remove_user(&rule->out_iface_user);
341 static void register_interfaces(struct iprule *rule)
343 struct interface *iface, *tmp;
345 if (rule->flags & IPRULE_IN) {
346 tmp = vlist_find(&interfaces, rule->in_iface, iface, node);
348 interface_add_user(&rule->in_iface_user, tmp);
350 if (rule->flags & IPRULE_OUT) {
351 tmp = vlist_find(&interfaces, rule->out_iface, iface, node);
353 interface_add_user(&rule->out_iface_user, tmp);
358 iprule_update_rule(struct vlist_tree *tree,
359 struct vlist_node *node_new, struct vlist_node *node_old)
361 struct iprule *rule_old, *rule_new;
363 rule_old = container_of(node_old, struct iprule, node);
364 rule_new = container_of(node_new, struct iprule, node);
367 if (rule_ready(rule_old))
368 system_del_iprule(rule_old);
370 if (rule_old->flags & (IPRULE_IN | IPRULE_OUT))
371 deregister_interfaces(rule_old);
373 if (rule_old->in_iface)
374 free(rule_old->in_iface);
376 if (rule_old->out_iface)
377 free(rule_old->out_iface);
383 /* interface based rules calls system_add_iprule over the event cb */
384 if (rule_new->flags & (IPRULE_IN | IPRULE_OUT)) {
385 register_interfaces(rule_new);
387 system_add_iprule(rule_new);
393 iprule_init_list(void)
395 vlist_init(&iprules, rule_cmp, iprule_update_rule);
396 interface_add_user(&generic_listener, NULL);