iprule: rework interface based rules to handle dynamic interfaces
[oweals/netifd.git] / iprule.c
1 /*
2  * netifd - network interface daemon
3  * Copyright (C) 2012 Felix Fietkau <nbd@openwrt.org>
4  * Copyright (C) 2013 Jo-Philipp Wich <jow@openwrt.org>
5  * Copyright (C) 2018 Alexander Couzens <lynxis@fe80.eu>
6  *
7  * This program is free software; you can redistribute it and/or modify
8  * it under the terms of the GNU General Public License version 2
9  * as published by the Free Software Foundation
10  *
11  * This program is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  * GNU General Public License for more details.
15  */
16 #include <assert.h>
17 #include <string.h>
18 #include <stdlib.h>
19 #include <stdio.h>
20
21 #include <arpa/inet.h>
22
23 #include "netifd.h"
24 #include "device.h"
25 #include "interface.h"
26 #include "iprule.h"
27 #include "proto.h"
28 #include "ubus.h"
29 #include "system.h"
30
31 struct vlist_tree iprules;
32 static bool iprules_flushed = false;
33 static unsigned int iprules_counter[2];
34
35 enum {
36         RULE_INTERFACE_IN,
37         RULE_INTERFACE_OUT,
38         RULE_INVERT,
39         RULE_SRC,
40         RULE_DEST,
41         RULE_PRIORITY,
42         RULE_TOS,
43         RULE_FWMARK,
44         RULE_LOOKUP,
45         RULE_ACTION,
46         RULE_GOTO,
47         RULE_SUP_PREFIXLEN,
48         __RULE_MAX
49 };
50
51 static const struct blobmsg_policy rule_attr[__RULE_MAX] = {
52         [RULE_INTERFACE_IN] = { .name = "in", .type = BLOBMSG_TYPE_STRING },
53         [RULE_INTERFACE_OUT] = { .name = "out", .type = BLOBMSG_TYPE_STRING },
54         [RULE_INVERT] = { .name = "invert", .type = BLOBMSG_TYPE_BOOL },
55         [RULE_SRC] = { .name = "src", .type = BLOBMSG_TYPE_STRING },
56         [RULE_DEST] = { .name = "dest", .type = BLOBMSG_TYPE_STRING },
57         [RULE_PRIORITY] = { .name = "priority", .type = BLOBMSG_TYPE_INT32 },
58         [RULE_TOS] = { .name = "tos", .type = BLOBMSG_TYPE_INT32 },
59         [RULE_FWMARK] = { .name = "mark", .type = BLOBMSG_TYPE_STRING },
60         [RULE_LOOKUP] = { .name = "lookup", .type = BLOBMSG_TYPE_STRING },
61         [RULE_SUP_PREFIXLEN] = { .name = "suppress_prefixlength", .type = BLOBMSG_TYPE_INT32 },
62         [RULE_ACTION] = { .name = "action", .type = BLOBMSG_TYPE_STRING },
63         [RULE_GOTO]   = { .name = "goto", .type = BLOBMSG_TYPE_INT32 },
64 };
65
66 const struct uci_blob_param_list rule_attr_list = {
67         .n_params = __RULE_MAX,
68         .params = rule_attr,
69 };
70
71 /* interface based rules are dynamic. */
72 static bool rule_ready(struct iprule *rule) {
73         if (rule->flags & IPRULE_OUT && rule->out_dev == NULL)
74                 return false;
75
76         if (rule->flags & IPRULE_IN && rule->in_dev == NULL)
77                 return false;
78
79         return true;
80 }
81
82 static bool
83 iprule_parse_mark(const char *mark, struct iprule *rule)
84 {
85         char *s, *e;
86         unsigned int n;
87
88         if ((s = strchr(mark, '/')) != NULL)
89                 *s++ = 0;
90
91         n = strtoul(mark, &e, 0);
92
93         if (e == mark || *e)
94                 return false;
95
96         rule->fwmark = n;
97         rule->flags |= IPRULE_FWMARK;
98
99         if (s) {
100                 n = strtoul(s, &e, 0);
101
102                 if (e == s || *e)
103                         return false;
104
105                 rule->fwmask = n;
106                 rule->flags |= IPRULE_FWMASK;
107         }
108
109         return true;
110 }
111
112 /* called on interface changes of the incoming interface */
113 static void rule_in_cb(
114                 struct interface_user *dep,
115                 struct interface *iface,
116                 enum interface_event ev)
117 {
118         struct iprule *rule = container_of(dep, struct iprule, in_iface_user);
119
120         switch (ev) {
121         case IFEV_UP:
122                 if (!iface->l3_dev.dev)
123                         break;
124                 memcpy(rule->in_dev, iface->l3_dev.dev->ifname, sizeof(rule->in_dev));
125                 if (rule_ready(rule))
126                         system_add_iprule(rule);
127                 break;
128         case IFEV_DOWN:
129         case IFEV_UP_FAILED:
130         case IFEV_FREE:
131                 if (rule_ready(rule))
132                         system_del_iprule(rule);
133                 rule->in_dev[0] = 0;
134                 break;
135         default:
136                 break;
137         }
138 }
139
140 /* called on interface changes of the outgoing interface */
141 static void rule_out_cb(
142                 struct interface_user *dep,
143                 struct interface *iface,
144                 enum interface_event ev)
145 {
146         struct iprule *rule = container_of(dep, struct iprule, out_iface_user);
147
148         switch (ev) {
149         case IFEV_UP:
150                 if (!iface->l3_dev.dev)
151                         break;
152                 memcpy(rule->out_dev, iface->l3_dev.dev->ifname, sizeof(rule->out_dev));
153                 if (rule_ready(rule))
154                         system_add_iprule(rule);
155                 break;
156         case IFEV_DOWN:
157         case IFEV_UP_FAILED:
158         case IFEV_FREE:
159                 if (rule_ready(rule))
160                         system_del_iprule(rule);
161                 rule->out_dev[0] = 0;
162                 break;
163         default:
164                 break;
165         }
166 }
167
168 /* called on all interface events */
169 static void generic_interface_cb(
170                 struct interface_user *dep,
171                 struct interface *iface,
172                 enum interface_event ev)
173 {
174         struct iprule *rule;
175
176         if (ev != IFEV_CREATE)
177                 return;
178
179         /* add new interfaces to rules */
180         vlist_for_each_element(&iprules, rule, node) {
181                 if (rule_ready(rule))
182                         continue;
183
184                 if (!strcmp(rule->out_iface, iface->name)) {
185                         assert(!rule->out_dev);
186                         memcpy(rule->out_dev, iface->l3_dev.dev->ifname, sizeof(rule->out_dev));
187                         interface_add_user(&rule->out_iface_user, iface);
188                 }
189
190                 if (!strcmp(rule->in_iface, iface->name)) {
191                         assert(!rule->in_dev);
192                         memcpy(rule->in_dev, iface->l3_dev.dev->ifname, sizeof(rule->in_dev));
193                         interface_add_user(&rule->in_iface_user, iface);
194                 }
195         }
196 }
197
198 struct interface_user generic_listener = {
199         .cb = generic_interface_cb
200 };
201
202 void
203 iprule_add(struct blob_attr *attr, bool v6)
204 {
205         struct blob_attr *tb[__RULE_MAX], *cur;
206         struct iprule *rule;
207         char *iface_name;
208         int af = v6 ? AF_INET6 : AF_INET;
209
210         blobmsg_parse(rule_attr, __RULE_MAX, tb, blobmsg_data(attr), blobmsg_data_len(attr));
211
212         rule = calloc(1, sizeof(*rule));
213         if (!rule)
214                 return;
215
216         rule->flags = v6 ? IPRULE_INET6 : IPRULE_INET4;
217         rule->order = iprules_counter[rule->flags]++;
218
219         if ((cur = tb[RULE_INVERT]) != NULL)
220                 rule->invert = blobmsg_get_bool(cur);
221
222         if ((cur = tb[RULE_INTERFACE_IN]) != NULL) {
223                 iface_name = calloc(1, strlen(blobmsg_data(cur)) + 1);
224                 rule->in_iface = strcpy(iface_name, blobmsg_data(cur));
225                 rule->in_iface_user.cb = &rule_in_cb;
226                 rule->flags |= IPRULE_IN;
227         }
228
229         if ((cur = tb[RULE_INTERFACE_OUT]) != NULL) {
230                 iface_name = calloc(1, strlen(blobmsg_data(cur)) + 1);
231                 rule->out_iface = strcpy(iface_name, blobmsg_data(cur));
232                 rule->out_iface_user.cb = &rule_out_cb;
233                 rule->flags |= IPRULE_OUT;
234         }
235
236         if ((cur = tb[RULE_SRC]) != NULL) {
237                 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &rule->src_addr, &rule->src_mask)) {
238                         DPRINTF("Failed to parse rule source: %s\n", (char *) blobmsg_data(cur));
239                         goto error;
240                 }
241                 rule->flags |= IPRULE_SRC;
242         }
243
244         if ((cur = tb[RULE_DEST]) != NULL) {
245                 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &rule->dest_addr, &rule->dest_mask)) {
246                         DPRINTF("Failed to parse rule destination: %s\n", (char *) blobmsg_data(cur));
247                         goto error;
248                 }
249                 rule->flags |= IPRULE_DEST;
250         }
251
252         if ((cur = tb[RULE_PRIORITY]) != NULL) {
253                 rule->priority = blobmsg_get_u32(cur);
254                 rule->flags |= IPRULE_PRIORITY;
255         }
256
257         if ((cur = tb[RULE_TOS]) != NULL) {
258                 if ((rule->tos = blobmsg_get_u32(cur)) > 255) {
259                         DPRINTF("Invalid TOS value: %u\n", blobmsg_get_u32(cur));
260                         goto error;
261                 }
262                 rule->flags |= IPRULE_TOS;
263         }
264
265         if ((cur = tb[RULE_FWMARK]) != NULL) {
266                 if (!iprule_parse_mark(blobmsg_data(cur), rule)) {
267                         DPRINTF("Failed to parse rule fwmark: %s\n", (char *) blobmsg_data(cur));
268                         goto error;
269                 }
270                 /* flags set by iprule_parse_mark() */
271         }
272
273         if ((cur = tb[RULE_LOOKUP]) != NULL) {
274                 if (!system_resolve_rt_table(blobmsg_data(cur), &rule->lookup)) {
275                         DPRINTF("Failed to parse rule lookup table: %s\n", (char *) blobmsg_data(cur));
276                         goto error;
277                 }
278                 rule->flags |= IPRULE_LOOKUP;
279         }
280
281         if ((cur = tb[RULE_SUP_PREFIXLEN]) != NULL) {
282                 rule->sup_prefixlen = blobmsg_get_u32(cur);
283                 rule->flags |= IPRULE_SUP_PREFIXLEN;
284         }
285
286         if ((cur = tb[RULE_ACTION]) != NULL) {
287                 if (!system_resolve_iprule_action(blobmsg_data(cur), &rule->action)) {
288                         DPRINTF("Failed to parse rule action: %s\n", (char *) blobmsg_data(cur));
289                         goto error;
290                 }
291                 rule->flags |= IPRULE_ACTION;
292         }
293
294         if ((cur = tb[RULE_GOTO]) != NULL) {
295                 rule->gotoid = blobmsg_get_u32(cur);
296                 rule->flags |= IPRULE_GOTO;
297         }
298
299         vlist_add(&iprules, &rule->node, &rule->flags);
300         return;
301
302 error:
303         free(rule);
304 }
305
306 void
307 iprule_update_start(void)
308 {
309         if (!iprules_flushed) {
310                 system_flush_iprules();
311                 iprules_flushed = true;
312         }
313
314         iprules_counter[0] = 1;
315         iprules_counter[1] = 1;
316         vlist_update(&iprules);
317 }
318
319 void
320 iprule_update_complete(void)
321 {
322         vlist_flush(&iprules);
323 }
324
325
326 static int
327 rule_cmp(const void *k1, const void *k2, void *ptr)
328 {
329         return memcmp(k1, k2, sizeof(struct iprule)-offsetof(struct iprule, flags));
330 }
331
332 static void deregister_interfaces(struct iprule *rule)
333 {
334         if (rule->flags & IPRULE_IN && rule->in_iface_user.iface)
335                 interface_remove_user(&rule->in_iface_user);
336
337         if (rule->flags & IPRULE_OUT && rule->out_iface_user.iface)
338                 interface_remove_user(&rule->out_iface_user);
339 }
340
341 static void register_interfaces(struct iprule *rule)
342 {
343         struct interface *iface, *tmp;
344
345         if (rule->flags & IPRULE_IN) {
346                 tmp = vlist_find(&interfaces, rule->in_iface, iface, node);
347                 if (tmp)
348                         interface_add_user(&rule->in_iface_user, tmp);
349         }
350         if (rule->flags & IPRULE_OUT) {
351                 tmp = vlist_find(&interfaces, rule->out_iface, iface, node);
352                 if (tmp)
353                         interface_add_user(&rule->out_iface_user, tmp);
354         }
355 }
356
357 static void
358 iprule_update_rule(struct vlist_tree *tree,
359                         struct vlist_node *node_new, struct vlist_node *node_old)
360 {
361         struct iprule *rule_old, *rule_new;
362
363         rule_old = container_of(node_old, struct iprule, node);
364         rule_new = container_of(node_new, struct iprule, node);
365
366         if (node_old) {
367                 if (rule_ready(rule_old))
368                         system_del_iprule(rule_old);
369
370                 if (rule_old->flags & (IPRULE_IN | IPRULE_OUT))
371                         deregister_interfaces(rule_old);
372
373                 if (rule_old->in_iface)
374                         free(rule_old->in_iface);
375
376                 if (rule_old->out_iface)
377                         free(rule_old->out_iface);
378
379                 free(rule_old);
380         }
381
382         if (node_new) {
383                 /* interface based rules calls system_add_iprule over the event cb */
384                 if (rule_new->flags & (IPRULE_IN | IPRULE_OUT)) {
385                         register_interfaces(rule_new);
386                 } else {
387                         system_add_iprule(rule_new);
388                 }
389         }
390 }
391
392 static void __init
393 iprule_init_list(void)
394 {
395         vlist_init(&iprules, rule_cmp, iprule_update_rule);
396         interface_add_user(&generic_listener, NULL);
397 }