IFACE_ATTR_PROTO,
IFACE_ATTR_AUTO,
IFACE_ATTR_JAIL,
+ IFACE_ATTR_JAIL_IFNAME,
IFACE_ATTR_DEFAULTROUTE,
IFACE_ATTR_PEERDNS,
IFACE_ATTR_DNS,
[IFACE_ATTR_IFNAME] = { .name = "ifname", .type = BLOBMSG_TYPE_STRING },
[IFACE_ATTR_AUTO] = { .name = "auto", .type = BLOBMSG_TYPE_BOOL },
[IFACE_ATTR_JAIL] = { .name = "jail", .type = BLOBMSG_TYPE_STRING },
+ [IFACE_ATTR_JAIL_IFNAME] = { .name = "jail_ifname", .type = BLOBMSG_TYPE_STRING },
[IFACE_ATTR_DEFAULTROUTE] = { .name = "defaultroute", .type = BLOBMSG_TYPE_BOOL },
[IFACE_ATTR_PEERDNS] = { .name = "peerdns", .type = BLOBMSG_TYPE_BOOL },
[IFACE_ATTR_METRIC] = { .name = "metric", .type = BLOBMSG_TYPE_INT32 },
avl_delete(&interfaces.avl, &iface->node.avl);
if (iface->jail)
free(iface->jail);
+ if (iface->jail_ifname)
+ free(iface->jail_ifname);
free(iface);
}
iface->autostart = false;
}
+ iface->jail_ifname = NULL;
+ if ((cur = tb[IFACE_ATTR_JAIL_IFNAME]))
+ iface->jail_ifname = strdup(blobmsg_get_string(cur));
+
return iface;
}
if (!iface->jail || strcmp(iface->jail, jail))
continue;
- system_link_netns_move(iface->ifname, netns_fd);
+ system_link_netns_move(iface->ifname, netns_fd, iface->jail_ifname);
}
+ close(netns_fd);
+
pr = fork();
if (pr) {
waitpid(pr, &wstatus, WUNTRACED | WCONTINUED);
- close(netns_fd);
return;
}
+ /* child process */
+ netns_fd = system_netns_open(netns_pid);
+ if (netns_fd < 0)
+ return;
+
system_netns_set(netns_fd);
system_init();
vlist_for_each_element(&interfaces, iface, node) {
if (!iface->jail || strcmp(iface->jail, jail))
continue;
+ /*
+ * The interface has already been renamed and is inside target
+ * namespace, hence overwrite ifname with jail_ifname for
+ * interface_set_up().
+ * We are inside a fork which got it's own copy of the interfaces
+ * list, so we can mess with it :)
+ */
+ iface->ifname = iface->jail_ifname;
+ interface_do_reload(iface);
interface_set_up(iface);
}
+
+ close(netns_fd);
_exit(0);
}
struct interface *iface;
int netns_fd, root_netns;
int wstatus;
+ pid_t parent_pid = getpid();
pid_t pr = 0;
- netns_fd = system_netns_open(netns_pid);
- if (netns_fd < 0)
+ pr = fork();
+ if (pr) {
+ waitpid(pr, &wstatus, WUNTRACED | WCONTINUED);
return;
+ }
- root_netns = system_netns_open(getpid());
+ /* child process */
+ root_netns = system_netns_open(parent_pid);
if (root_netns < 0)
return;
- pr = fork();
- if (pr) {
- waitpid(pr, &wstatus, WUNTRACED | WCONTINUED);
- close(netns_fd);
- close(root_netns);
+ netns_fd = system_netns_open(netns_pid);
+ if (netns_fd < 0)
return;
- }
system_netns_set(netns_fd);
system_init();
continue;
interface_set_down(iface);
- system_link_netns_move(iface->ifname, root_netns);
+ system_link_netns_move(iface->jail_ifname, root_netns, iface->ifname);
}
+
+ close(root_netns);
+ close(netns_fd);
_exit(0);
}
if (if_old->jail)
if_old->autostart = false;
+ if (if_old->jail_ifname)
+ free(if_old->jail_ifname);
+
+ if_old->jail_ifname = if_new->jail_ifname;
+
if_old->ifname = if_new->ifname;
if_old->parent_ifname = if_new->parent_ifname;
if_old->dynamic = if_new->dynamic;
return system_bridge_if(bridge->ifname, dev, SIOCBRDELIF, NULL);
}
-int system_if_resolve(struct device *dev)
+static int system_ifname_resolve(const char *ifname)
{
struct ifreq ifr;
- strncpy(ifr.ifr_name, dev->ifname, sizeof(ifr.ifr_name) - 1);
+ strncpy(ifr.ifr_name, ifname, sizeof(ifr.ifr_name) - 1);
if (!ioctl(sock_ioctl, SIOCGIFINDEX, &ifr))
return ifr.ifr_ifindex;
else
return 0;
}
+int system_if_resolve(struct device *dev)
+{
+ return system_ifname_resolve(dev->ifname);
+}
+
static int system_if_flags(const char *ifname, unsigned add, unsigned rem)
{
struct ifreq ifr;
return -ENOMEM;
}
-int system_link_netns_move(const char *ifname, int netns_fd)
+int system_link_netns_move(const char *ifname, int netns_fd, const char *target_ifname)
{
struct nl_msg *msg;
struct ifinfomsg iim = {
.ifi_family = AF_UNSPEC,
- .ifi_index = 0,
};
+ iim.ifi_index = system_ifname_resolve(ifname);
msg = nlmsg_alloc_simple(RTM_NEWLINK, NLM_F_REQUEST);
if (!msg)
return -1;
nlmsg_append(msg, &iim, sizeof(iim), 0);
- nla_put_string(msg, IFLA_IFNAME, ifname);
+ if (target_ifname)
+ nla_put_string(msg, IFLA_IFNAME, target_ifname);
+
nla_put_u32(msg, IFLA_NET_NS_FD, netns_fd);
return system_rtnl_call(msg);
}