blob: 315094c09d4eb2c8366460e7860af26663cdcfcb [file] [log] [blame]
Garrick Evansf0ab7132019-06-18 14:50:42 +09001// Copyright 2019 The Chromium OS Authors. All rights reserved.
2// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
Garrick Evans3388a032020-03-24 11:25:55 +09005#ifndef PATCHPANEL_DATAPATH_H_
6#define PATCHPANEL_DATAPATH_H_
Garrick Evansf0ab7132019-06-18 14:50:42 +09007
Hugo Benichie8758b52020-04-03 14:49:01 +09008#include <net/route.h>
Hugo Benichi33860d72020-07-09 16:34:01 +09009#include <sys/types.h>
Hugo Benichie8758b52020-04-03 14:49:01 +090010
Hugo Benichifcf81022020-12-04 11:01:37 +090011#include <iostream>
Hugo Benichi2a940542020-10-26 18:50:49 +090012#include <set>
Garrick Evansf0ab7132019-06-18 14:50:42 +090013#include <string>
Hugo Benichi2a940542020-10-26 18:50:49 +090014#include <vector>
Garrick Evansf0ab7132019-06-18 14:50:42 +090015
16#include <base/macros.h>
Hugo Benichi82ed5cf2020-09-08 21:30:22 +090017#include <gtest/gtest_prod.h> // for FRIEND_TEST
Garrick Evansf0ab7132019-06-18 14:50:42 +090018
Jason Jeremy Imana7273a32020-08-04 11:25:31 +090019#include "patchpanel/firewall.h"
Garrick Evans3388a032020-03-24 11:25:55 +090020#include "patchpanel/mac_address_generator.h"
21#include "patchpanel/minijailed_process_runner.h"
Hugo Benichi8d622b52020-08-13 15:24:12 +090022#include "patchpanel/routing_service.h"
Garrick Evans3388a032020-03-24 11:25:55 +090023#include "patchpanel/subnet.h"
Garrick Evansf0ab7132019-06-18 14:50:42 +090024
Garrick Evans3388a032020-03-24 11:25:55 +090025namespace patchpanel {
Garrick Evansf0ab7132019-06-18 14:50:42 +090026
Hugo Benichifcf81022020-12-04 11:01:37 +090027// Struct holding parameters for Datapath::StartRoutingNamespace requests.
28struct ConnectedNamespace {
29 // The pid of the client network namespace.
30 pid_t pid;
31 // The name attached to the client network namespace.
32 std::string netns_name;
Hugo Benichi93306e52020-12-04 16:08:00 +090033 // Source to which traffic from |host_ifname| will be attributed.
34 TrafficSource source;
Hugo Benichifcf81022020-12-04 11:01:37 +090035 // Name of the shill device for routing outbound traffic from the client
36 // namespace. Empty if outbound traffic should be forwarded to the highest
37 // priority network (physical or virtual).
38 std::string outbound_ifname;
Hugo Benichi93306e52020-12-04 16:08:00 +090039 // If |outbound_ifname| is empty and |route_on_vpn| is false, the traffic from
40 // the client namespace will be routed to the highest priority physical
41 // device. If |outbound_ifname| is empty and |route_on_vpn| is true, the
42 // traffic will be routed through VPN connections. If |outbound_ifname|
43 // specifies a valid physical device, |route_on_vpn| is ignored.
44 bool route_on_vpn;
Hugo Benichifcf81022020-12-04 11:01:37 +090045 // Name of the "local" veth device visible on the host namespace.
46 std::string host_ifname;
47 // Name of the "remote" veth device moved into the client namespace.
48 std::string peer_ifname;
49 // IPv4 subnet assigned to the client namespace.
50 std::unique_ptr<Subnet> peer_subnet;
51 // MAC address of the "remote" veth device.
52 MacAddress peer_mac_addr;
53};
54
55std::ostream& operator<<(std::ostream& stream,
56 const ConnectedNamespace& nsinfo);
57
Hugo Benichid82d8832020-08-14 10:05:03 +090058// Simple enum of bitmasks used for specifying a set of IP family values.
59enum IpFamily {
60 NONE = 0,
61 IPv4 = 1 << 0,
62 IPv6 = 1 << 1,
Taoyu Lia0727dc2020-09-24 19:54:59 +090063 Dual = IPv4 | IPv6, // (1 << 0) | (1 << 1);
Hugo Benichid82d8832020-08-14 10:05:03 +090064};
65
Taoyu Li90c13912019-11-26 17:56:54 +090066// cros lint will yell to force using int16/int64 instead of long here, however
67// note that unsigned long IS the correct signature for ioctl in Linux kernel -
68// it's 32 bits on 32-bit platform and 64 bits on 64-bit one.
69using ioctl_req_t = unsigned long;
70typedef int (*ioctl_t)(int, ioctl_req_t, ...);
Garrick Evansc7ae82c2019-09-04 16:25:10 +090071
Garrick Evans54861622019-07-19 09:05:09 +090072// Returns for given interface name the host name of a ARC veth pair.
Garrick Evans2f581a02020-05-11 10:43:35 +090073std::string ArcVethHostName(const std::string& ifname);
Garrick Evans54861622019-07-19 09:05:09 +090074
Garrick Evans8a067562020-05-11 12:47:30 +090075// Returns the ARC bridge interface name for the given interface.
76std::string ArcBridgeName(const std::string& ifname);
77
Garrick Evansf0ab7132019-06-18 14:50:42 +090078// ARC networking data path configuration utility.
Garrick Evans54861622019-07-19 09:05:09 +090079// IPV4 addresses are always specified in singular dotted-form (a.b.c.d)
80// (not in CIDR representation
Garrick Evansf0ab7132019-06-18 14:50:42 +090081class Datapath {
82 public:
Jason Jeremy Imana7273a32020-08-04 11:25:31 +090083 // |process_runner| and |firewall| must not be null; it is not owned.
84 Datapath(MinijailedProcessRunner* process_runner, Firewall* firewall);
Garrick Evansc7ae82c2019-09-04 16:25:10 +090085 // Provided for testing only.
Jason Jeremy Imana7273a32020-08-04 11:25:31 +090086 Datapath(MinijailedProcessRunner* process_runner,
87 Firewall* firewall,
88 ioctl_t ioctl_hook);
Qijiang Fan6bc59e12020-11-11 02:51:06 +090089 Datapath(const Datapath&) = delete;
90 Datapath& operator=(const Datapath&) = delete;
91
Garrick Evansf0ab7132019-06-18 14:50:42 +090092 virtual ~Datapath() = default;
93
Hugo Benichibf811c62020-09-07 17:30:45 +090094 // Start and stop the Datapath, creating or destroying the initial iptables
95 // setup needed for forwarding traffic from VMs and containers and for
96 // fwmark based routing.
97 virtual void Start();
98 virtual void Stop();
99
Hugo Benichi33860d72020-07-09 16:34:01 +0900100 // Attaches the name |netns_name| to a network namespace identified by
101 // |netns_pid|. If |netns_name| had already been created, it will be deleted
102 // first.
103 virtual bool NetnsAttachName(const std::string& netns_name, pid_t netns_pid);
104
105 // Deletes the name |netns_name| of a network namespace.
106 virtual bool NetnsDeleteName(const std::string& netns_name);
107
Garrick Evans8a949dc2019-07-18 16:17:53 +0900108 virtual bool AddBridge(const std::string& ifname,
Garrick Evans7a1a9ee2020-01-28 11:03:57 +0900109 uint32_t ipv4_addr,
110 uint32_t ipv4_prefix_len);
Garrick Evans8a949dc2019-07-18 16:17:53 +0900111 virtual void RemoveBridge(const std::string& ifname);
112
Garrick Evans621ed262019-11-13 12:28:43 +0900113 virtual bool AddToBridge(const std::string& br_ifname,
114 const std::string& ifname);
115
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900116 // Adds a new TAP device.
117 // |name| may be empty, in which case a default device name will be used;
118 // it may be a template (e.g. vmtap%d), in which case the kernel will
119 // generate the name; or it may be fully defined. In all cases, upon success,
120 // the function returns the actual name of the interface.
Garrick Evans621ed262019-11-13 12:28:43 +0900121 // |mac_addr| and |ipv4_addr| should be null if this interface will be later
122 // bridged.
Garrick Evans4f9f5572019-11-26 10:25:16 +0900123 // If |user| is empty, no owner will be set
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900124 virtual std::string AddTAP(const std::string& name,
Garrick Evans621ed262019-11-13 12:28:43 +0900125 const MacAddress* mac_addr,
126 const SubnetAddress* ipv4_addr,
Garrick Evans4f9f5572019-11-26 10:25:16 +0900127 const std::string& user);
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900128
129 // |ifname| must be the actual name of the interface.
130 virtual void RemoveTAP(const std::string& ifname);
131
132 // The following are iptables methods.
133 // When specified, |ipv4_addr| is always singlar dotted-form (a.b.c.d)
134 // IPv4 address (not a CIDR representation).
135
Hugo Benichi76675592020-04-08 14:29:57 +0900136 // Creates a virtual interface pair split across the current namespace and the
137 // namespace corresponding to |pid|, and set up the remote interface
138 // |peer_ifname| according // to the given parameters.
139 virtual bool ConnectVethPair(pid_t pid,
Hugo Benichi33860d72020-07-09 16:34:01 +0900140 const std::string& netns_name,
Hugo Benichi76675592020-04-08 14:29:57 +0900141 const std::string& veth_ifname,
142 const std::string& peer_ifname,
143 const MacAddress& remote_mac_addr,
144 uint32_t remote_ipv4_addr,
145 uint32_t remote_ipv4_prefix_len,
146 bool remote_multicast_flag);
147
Garrick Evans54861622019-07-19 09:05:09 +0900148 virtual void RemoveInterface(const std::string& ifname);
149
Hugo Benichi954bae62021-04-09 09:12:30 +0900150 // Create an OUTPUT DROP rule for any locally originated traffic
Hugo Benichi321f23b2020-09-25 15:42:05 +0900151 // whose src IPv4 matches |src_ip| and would exit |oif|. This is mainly used
152 // for dropping Chrome webRTC traffic incorrectly bound on ARC and other
153 // guests virtual interfaces (chromium:898210).
154 virtual bool AddSourceIPv4DropRule(const std::string& oif,
155 const std::string& src_ip);
Hugo Benichi321f23b2020-09-25 15:42:05 +0900156
Hugo Benichi7c342672020-09-08 09:18:14 +0900157 // Creates a virtual ethernet interface pair shared with the client namespace
Hugo Benichifcf81022020-12-04 11:01:37 +0900158 // of |nsinfo.pid| and sets up routing outside and inside the client namespace
159 // for connecting the client namespace to the network.
160 bool StartRoutingNamespace(const ConnectedNamespace& nsinfo);
Hugo Benichi7c342672020-09-08 09:18:14 +0900161 // Destroys the virtual ethernet interface, routing, and network namespace
Hugo Benichifcf81022020-12-04 11:01:37 +0900162 // name set for |nsinfo.netns_name| by StartRoutingNamespace. The default
163 // route set inside the |nsinfo.netns_name| by patchpanel is not destroyed and
164 // it is assumed the client will teardown the namespace.
165 void StopRoutingNamespace(const ConnectedNamespace& nsinfo);
Hugo Benichi7c342672020-09-08 09:18:14 +0900166
Hugo Benichi8d622b52020-08-13 15:24:12 +0900167 // Sets up IPv4 SNAT, IP forwarding, and traffic marking for the given
168 // virtual device |int_ifname| associated to |source|. if |ext_ifname| is
169 // empty, the device is implicitly routed through the highest priority
Hugo Benichibfc49112020-12-14 12:54:44 +0900170 // physical network when |route_on_vpn| is false, or through the highest
171 // priority logical network when |route_on_vpn| is true. If |ext_ifname| is
172 // defined, the device is routed to |ext_ifname| and |route_on_vpn| is
173 // ignored.
Hugo Benichi8d622b52020-08-13 15:24:12 +0900174 virtual void StartRoutingDevice(const std::string& ext_ifname,
175 const std::string& int_ifname,
176 uint32_t int_ipv4_addr,
Hugo Benichi93306e52020-12-04 16:08:00 +0900177 TrafficSource source,
178 bool route_on_vpn);
Hugo Benichi8d622b52020-08-13 15:24:12 +0900179
180 // Removes IPv4 iptables, IP forwarding, and traffic marking for the given
181 // virtual device |int_ifname|.
182 virtual void StopRoutingDevice(const std::string& ext_ifname,
183 const std::string& int_ifname,
184 uint32_t int_ipv4_addr,
Hugo Benichi93306e52020-12-04 16:08:00 +0900185 TrafficSource source,
186 bool route_on_vpn);
Hugo Benichi8d622b52020-08-13 15:24:12 +0900187
Hugo Benichi76be34a2020-08-26 22:35:54 +0900188 // Starts or stops marking conntrack entries routed to |ext_ifname| with its
189 // associated fwmark routing tag. Once a conntrack entry is marked with the
190 // fwmark routing tag of a external device, the connection will be pinned
191 // to that deviced if conntrack fwmark restore is set for the source.
192 virtual void StartConnectionPinning(const std::string& ext_ifname);
193 virtual void StopConnectionPinning(const std::string& ext_ifname);
Hugo Benichi2a940542020-10-26 18:50:49 +0900194 // Starts or stops VPN routing for:
195 // - Local sockets of binaries running under uids eligible to be routed
196 // through VPN connections. These uids are defined by |kLocalSourceTypes|
197 // in routing_service.h
198 // - Forwarded virtual devices tracking the default network.
199 virtual void StartVpnRouting(const std::string& vpn_ifname);
200 virtual void StopVpnRouting(const std::string& vpn_ifname);
Hugo Benichi76be34a2020-08-26 22:35:54 +0900201
Taoyu Li90c13912019-11-26 17:56:54 +0900202 // Methods supporting IPv6 configuration for ARC.
Garrick Evans664a82f2019-12-17 12:18:05 +0900203 virtual bool MaskInterfaceFlags(const std::string& ifname,
204 uint16_t on,
205 uint16_t off = 0);
Garrick Evans260ff302019-07-25 11:22:50 +0900206
Hugo Benichid82d8832020-08-14 10:05:03 +0900207 // Convenience functions for enabling or disabling IPv6 forwarding in both
208 // directions between a pair of interfaces
Taoyu Li90c13912019-11-26 17:56:54 +0900209 virtual bool AddIPv6Forwarding(const std::string& ifname1,
210 const std::string& ifname2);
211 virtual void RemoveIPv6Forwarding(const std::string& ifname1,
212 const std::string& ifname2);
213
Garrick Evans260ff302019-07-25 11:22:50 +0900214 virtual bool AddIPv6HostRoute(const std::string& ifname,
215 const std::string& ipv6_addr,
216 int ipv6_prefix_len);
217 virtual void RemoveIPv6HostRoute(const std::string& ifname,
218 const std::string& ipv6_addr,
219 int ipv6_prefix_len);
220
Taoyu Lia0727dc2020-09-24 19:54:59 +0900221 virtual bool AddIPv6Address(const std::string& ifname,
222 const std::string& ipv6_addr);
223 virtual void RemoveIPv6Address(const std::string& ifname,
224 const std::string& ipv6_addr);
Garrick Evans260ff302019-07-25 11:22:50 +0900225
Hugo Benichie8758b52020-04-03 14:49:01 +0900226 // Adds (or deletes) a route to direct to |gateway_addr| the traffic destined
227 // to the subnet defined by |addr| and |netmask|.
Garrick Evans3d97a392020-02-21 15:24:37 +0900228 virtual bool AddIPv4Route(uint32_t gateway_addr,
229 uint32_t addr,
230 uint32_t netmask);
Hugo Benichie8758b52020-04-03 14:49:01 +0900231 virtual bool DeleteIPv4Route(uint32_t gateway_addr,
232 uint32_t addr,
233 uint32_t netmask);
234 // Adds (or deletes) a route to direct to |ifname| the traffic destined to the
235 // subnet defined by |addr| and |netmask|.
236 virtual bool AddIPv4Route(const std::string& ifname,
237 uint32_t addr,
238 uint32_t netmask);
239 virtual bool DeleteIPv4Route(const std::string& ifname,
240 uint32_t addr,
241 uint32_t netmask);
Garrick Evans3d97a392020-02-21 15:24:37 +0900242
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900243 // Adds (or deletes) an iptables rule for ADB port forwarding.
244 virtual bool AddAdbPortForwardRule(const std::string& ifname);
245 virtual void DeleteAdbPortForwardRule(const std::string& ifname);
246
247 // Adds (or deletes) an iptables rule for ADB port access.
248 virtual bool AddAdbPortAccessRule(const std::string& ifname);
249 virtual void DeleteAdbPortAccessRule(const std::string& ifname);
250
Hugo Benichi1e0656f2021-02-15 15:43:38 +0900251 // Create (or delete) DNAT rules for redirecting DNS queries from system
252 // services to the nameservers of a particular physical networks. These
253 // DNAT rules are only applied if a VPN is connected and allows system
254 // services to resolve hostnames even if a VPN application configures DNS
255 // addresses only routable through the VPN (b/178331695).
256 // TODO(b/171157837) Replaces these rules with the system DNS proxy.
257 bool AddRedirectDnsRule(const std::string& ifname,
258 const std::string dns_ipv4_addr);
259 bool RemoveRedirectDnsRule(const std::string& ifname);
260
Hugo Benichiaf9d8a72020-08-26 13:28:13 +0900261 // Set or override the interface name to index mapping for |ifname|.
262 // Only used for testing.
263 void SetIfnameIndex(const std::string& ifname, int ifindex);
264
Hugo Benichif0f55562021-04-02 15:25:02 +0900265 // Add, remove, or flush chain |chain| in table |table|.
266 bool AddChain(IpFamily family,
267 const std::string& table,
268 const std::string& name);
269 bool RemoveChain(IpFamily family,
270 const std::string& table,
271 const std::string& name);
272 bool FlushChain(IpFamily family,
273 const std::string& table,
274 const std::string& name);
Hugo Benichicd27f4e2020-11-19 18:32:23 +0900275 // Manipulates a chain |chain| in table |table|.
276 bool ModifyChain(IpFamily family,
277 const std::string& table,
278 const std::string& op,
279 const std::string& chain,
280 bool log_failures = true);
Hugo Benichiddf00842020-11-20 10:24:08 +0900281 // Sends an iptables command for table |table|.
282 bool ModifyIptables(IpFamily family,
283 const std::string& table,
284 const std::vector<std::string>& argv,
285 bool log_failures = true);
Hugo Benichicd27f4e2020-11-19 18:32:23 +0900286
Garrick Evans260ff302019-07-25 11:22:50 +0900287 MinijailedProcessRunner& runner() const;
288
Garrick Evansf0ab7132019-06-18 14:50:42 +0900289 private:
Hugo Benichi91ee09f2020-12-03 22:24:22 +0900290 // Attempts to flush all built-in iptables chains used by patchpanel, and to
291 // delete all additionals chains created by patchpanel for routing. Traffic
292 // accounting chains are not deleted.
293 void ResetIptables();
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900294 // Creates a virtual interface pair.
295 bool AddVirtualInterfacePair(const std::string& netns_name,
296 const std::string& veth_ifname,
297 const std::string& peer_ifname);
298 // Sets the configuration of an interface.
299 bool ConfigureInterface(const std::string& ifname,
300 const MacAddress& mac_addr,
301 uint32_t ipv4_addr,
302 uint32_t ipv4_prefix_len,
303 bool up,
304 bool enable_multicast);
305 // Sets the link status.
306 bool ToggleInterface(const std::string& ifname, bool up);
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900307 // Create (or delete) pre-routing rules allowing direct ingress on |ifname|
308 // to guest destination |ipv4_addr|.
309 bool AddInboundIPv4DNAT(const std::string& ifname,
310 const std::string& ipv4_addr);
311 void RemoveInboundIPv4DNAT(const std::string& ifname,
312 const std::string& ipv4_addr);
Hugo Benichi1e0656f2021-02-15 15:43:38 +0900313 bool ModifyRedirectDnsDNATRule(const std::string& op,
314 const std::string& protocol,
315 const std::string& ifname,
316 const std::string& dns_ipv4_addr);
317 bool ModifyRedirectDnsJumpRule(const std::string& op);
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900318
Hugo Benichi3a9162b2020-09-09 15:47:40 +0900319 bool ModifyConnmarkSet(IpFamily family,
320 const std::string& chain,
321 const std::string& op,
Hugo Benichi3a9162b2020-09-09 15:47:40 +0900322 Fwmark mark,
323 Fwmark mask);
Hugo Benichiaf9d8a72020-08-26 13:28:13 +0900324 bool ModifyConnmarkRestore(IpFamily family,
325 const std::string& chain,
326 const std::string& op,
Hugo Benichi1af52392020-11-27 18:09:32 +0900327 const std::string& iif,
328 Fwmark mask);
329 bool ModifyConnmarkSave(IpFamily family,
330 const std::string& chain,
331 const std::string& op,
Hugo Benichi1af52392020-11-27 18:09:32 +0900332 Fwmark mask);
Hugo Benichi2a940542020-10-26 18:50:49 +0900333 bool ModifyFwmarkRoutingTag(const std::string& chain,
334 const std::string& op,
Hugo Benichid872d3d2021-03-29 10:20:53 +0900335 Fwmark routing_mark);
336 bool ModifyFwmarkSourceTag(const std::string& chain,
337 const std::string& op,
Hugo Benichi9be19b12020-08-14 15:33:40 +0900338 TrafficSource source);
Hugo Benichi3a9162b2020-09-09 15:47:40 +0900339 bool ModifyFwmarkDefaultLocalSourceTag(const std::string& op,
340 TrafficSource source);
341 bool ModifyFwmarkLocalSourceTag(const std::string& op,
342 const LocalSourceSpecs& source);
343 bool ModifyFwmark(IpFamily family,
344 const std::string& chain,
345 const std::string& op,
346 const std::string& iif,
347 const std::string& uid_name,
Hugo Benichi7e3b1fc2020-11-19 15:47:05 +0900348 uint32_t classid,
Hugo Benichi3a9162b2020-09-09 15:47:40 +0900349 Fwmark mark,
350 Fwmark mask,
351 bool log_failures = true);
Hugo Benichid82d8832020-08-14 10:05:03 +0900352 bool ModifyIpForwarding(IpFamily family,
353 const std::string& op,
354 const std::string& iif,
355 const std::string& oif,
356 bool log_failures = true);
Hugo Benichiff3cbcf2021-04-03 00:22:06 +0900357 bool ModifyJumpRule(IpFamily family,
358 const std::string& table,
359 const std::string& op,
360 const std::string& chain,
361 const std::string& target,
362 const std::string& iif,
363 const std::string& oif,
364 bool log_failures = true);
Hugo Benichi3ef370b2020-11-16 19:07:17 +0900365 bool ModifyFwmarkVpnJumpRule(const std::string& chain,
366 const std::string& op,
Hugo Benichi3ef370b2020-11-16 19:07:17 +0900367 Fwmark mark,
368 Fwmark mask);
Hugo Benichiaf9d8a72020-08-26 13:28:13 +0900369 bool ModifyRtentry(ioctl_req_t op, struct rtentry* route);
Hugo Benichi8c526e92021-03-25 14:59:59 +0900370 // Uses if_nametoindex to return the interface index of |ifname|. If |ifname|
371 // does not exist anymore, looks up the cache |if_nametoindex_|. It is
372 // incorrect to use this function in situations where the interface has been
373 // recreated and the older value must be recovered (b/183679000).
Hugo Benichiaf9d8a72020-08-26 13:28:13 +0900374 int FindIfIndex(const std::string& ifname);
Hugo Benichid82d8832020-08-14 10:05:03 +0900375
Garrick Evansf0ab7132019-06-18 14:50:42 +0900376 MinijailedProcessRunner* process_runner_;
Jason Jeremy Imana7273a32020-08-04 11:25:31 +0900377 Firewall* firewall_;
Garrick Evansc7ae82c2019-09-04 16:25:10 +0900378 ioctl_t ioctl_;
Garrick Evansf0ab7132019-06-18 14:50:42 +0900379
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900380 FRIEND_TEST(DatapathTest, AddInboundIPv4DNAT);
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900381 FRIEND_TEST(DatapathTest, AddVirtualInterfacePair);
382 FRIEND_TEST(DatapathTest, ConfigureInterface);
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900383 FRIEND_TEST(DatapathTest, RemoveInboundIPv4DNAT);
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900384 FRIEND_TEST(DatapathTest, RemoveOutboundIPv4SNATMark);
Hugo Benichi82ed5cf2020-09-08 21:30:22 +0900385 FRIEND_TEST(DatapathTest, ToggleInterface);
386
Hugo Benichiaf9d8a72020-08-26 13:28:13 +0900387 // A map used for remembering the interface index of an interface. This
388 // information is necessary when cleaning up iptables fwmark rules that
389 // directly references the interface index. When removing these rules on
390 // an RTM_DELLINK event, the interface index cannot be retrieved anymore.
391 // A new entry is only added when a new physical device appears, and entries
392 // are not removed.
393 // TODO(b/161507671) Rely on RoutingService to obtain this information once
394 // shill/routing_table.cc has been migrated to patchpanel.
395 std::map<std::string, int> if_nametoindex_;
Hugo Benichi1e0656f2021-02-15 15:43:38 +0900396
397 // A map used for tracking the primary IPv4 dns address associated to a given
398 // Shill Device known by its interface name. This is used for redirecting
399 // DNS queries of system services when a VPN is connected.
400 std::map<std::string, std::string> physical_dns_addresses_;
Garrick Evansf0ab7132019-06-18 14:50:42 +0900401};
402
Garrick Evans3388a032020-03-24 11:25:55 +0900403} // namespace patchpanel
Garrick Evansf0ab7132019-06-18 14:50:42 +0900404
Garrick Evans3388a032020-03-24 11:25:55 +0900405#endif // PATCHPANEL_DATAPATH_H_