Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 1 | // Copyright 2019 The Chromium OS Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 5 | #ifndef PATCHPANEL_DATAPATH_H_ |
| 6 | #define PATCHPANEL_DATAPATH_H_ |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 7 | |
Hugo Benichi | e8758b5 | 2020-04-03 14:49:01 +0900 | [diff] [blame] | 8 | #include <net/route.h> |
| 9 | |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 10 | #include <string> |
| 11 | |
| 12 | #include <base/macros.h> |
| 13 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 14 | #include "patchpanel/mac_address_generator.h" |
| 15 | #include "patchpanel/minijailed_process_runner.h" |
| 16 | #include "patchpanel/subnet.h" |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 17 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 18 | namespace patchpanel { |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 19 | |
Taoyu Li | 90c1391 | 2019-11-26 17:56:54 +0900 | [diff] [blame] | 20 | // cros lint will yell to force using int16/int64 instead of long here, however |
| 21 | // note that unsigned long IS the correct signature for ioctl in Linux kernel - |
| 22 | // it's 32 bits on 32-bit platform and 64 bits on 64-bit one. |
| 23 | using ioctl_req_t = unsigned long; |
| 24 | typedef int (*ioctl_t)(int, ioctl_req_t, ...); |
Garrick Evans | c7ae82c | 2019-09-04 16:25:10 +0900 | [diff] [blame] | 25 | |
Garrick Evans | 5486162 | 2019-07-19 09:05:09 +0900 | [diff] [blame] | 26 | // Returns for given interface name the host name of a ARC veth pair. |
Garrick Evans | 2f581a0 | 2020-05-11 10:43:35 +0900 | [diff] [blame] | 27 | std::string ArcVethHostName(const std::string& ifname); |
Garrick Evans | 5486162 | 2019-07-19 09:05:09 +0900 | [diff] [blame] | 28 | |
Garrick Evans | 8a06756 | 2020-05-11 12:47:30 +0900 | [diff] [blame] | 29 | // Returns the ARC bridge interface name for the given interface. |
| 30 | std::string ArcBridgeName(const std::string& ifname); |
| 31 | |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 32 | // ARC networking data path configuration utility. |
Garrick Evans | 5486162 | 2019-07-19 09:05:09 +0900 | [diff] [blame] | 33 | // IPV4 addresses are always specified in singular dotted-form (a.b.c.d) |
| 34 | // (not in CIDR representation |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 35 | class Datapath { |
| 36 | public: |
| 37 | // |process_runner| must not be null; it is not owned. |
| 38 | explicit Datapath(MinijailedProcessRunner* process_runner); |
Garrick Evans | c7ae82c | 2019-09-04 16:25:10 +0900 | [diff] [blame] | 39 | // Provided for testing only. |
| 40 | Datapath(MinijailedProcessRunner* process_runner, ioctl_t ioctl_hook); |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 41 | virtual ~Datapath() = default; |
| 42 | |
Garrick Evans | 8a949dc | 2019-07-18 16:17:53 +0900 | [diff] [blame] | 43 | virtual bool AddBridge(const std::string& ifname, |
Garrick Evans | 7a1a9ee | 2020-01-28 11:03:57 +0900 | [diff] [blame] | 44 | uint32_t ipv4_addr, |
| 45 | uint32_t ipv4_prefix_len); |
Garrick Evans | 8a949dc | 2019-07-18 16:17:53 +0900 | [diff] [blame] | 46 | virtual void RemoveBridge(const std::string& ifname); |
| 47 | |
Garrick Evans | 621ed26 | 2019-11-13 12:28:43 +0900 | [diff] [blame] | 48 | virtual bool AddToBridge(const std::string& br_ifname, |
| 49 | const std::string& ifname); |
| 50 | |
Garrick Evans | c7ae82c | 2019-09-04 16:25:10 +0900 | [diff] [blame] | 51 | // Adds a new TAP device. |
| 52 | // |name| may be empty, in which case a default device name will be used; |
| 53 | // it may be a template (e.g. vmtap%d), in which case the kernel will |
| 54 | // generate the name; or it may be fully defined. In all cases, upon success, |
| 55 | // the function returns the actual name of the interface. |
Garrick Evans | 621ed26 | 2019-11-13 12:28:43 +0900 | [diff] [blame] | 56 | // |mac_addr| and |ipv4_addr| should be null if this interface will be later |
| 57 | // bridged. |
Garrick Evans | 4f9f557 | 2019-11-26 10:25:16 +0900 | [diff] [blame] | 58 | // If |user| is empty, no owner will be set |
Garrick Evans | c7ae82c | 2019-09-04 16:25:10 +0900 | [diff] [blame] | 59 | virtual std::string AddTAP(const std::string& name, |
Garrick Evans | 621ed26 | 2019-11-13 12:28:43 +0900 | [diff] [blame] | 60 | const MacAddress* mac_addr, |
| 61 | const SubnetAddress* ipv4_addr, |
Garrick Evans | 4f9f557 | 2019-11-26 10:25:16 +0900 | [diff] [blame] | 62 | const std::string& user); |
Garrick Evans | c7ae82c | 2019-09-04 16:25:10 +0900 | [diff] [blame] | 63 | |
| 64 | // |ifname| must be the actual name of the interface. |
| 65 | virtual void RemoveTAP(const std::string& ifname); |
| 66 | |
| 67 | // The following are iptables methods. |
| 68 | // When specified, |ipv4_addr| is always singlar dotted-form (a.b.c.d) |
| 69 | // IPv4 address (not a CIDR representation). |
| 70 | |
Hugo Benichi | 7667559 | 2020-04-08 14:29:57 +0900 | [diff] [blame] | 71 | // Creates a virtual interface pair split across the current namespace and the |
| 72 | // namespace corresponding to |pid|, and set up the remote interface |
| 73 | // |peer_ifname| according // to the given parameters. |
| 74 | virtual bool ConnectVethPair(pid_t pid, |
| 75 | const std::string& veth_ifname, |
| 76 | const std::string& peer_ifname, |
| 77 | const MacAddress& remote_mac_addr, |
| 78 | uint32_t remote_ipv4_addr, |
| 79 | uint32_t remote_ipv4_prefix_len, |
| 80 | bool remote_multicast_flag); |
| 81 | |
Garrick Evans | 2470caa | 2020-03-04 14:15:41 +0900 | [diff] [blame] | 82 | // Creates a virtual interface pair. |
| 83 | virtual bool AddVirtualInterfacePair(const std::string& veth_ifname, |
| 84 | const std::string& peer_ifname); |
| 85 | |
| 86 | // Sets the link status. |
| 87 | virtual bool ToggleInterface(const std::string& ifname, bool up); |
| 88 | |
| 89 | // Sets the configuration of an interface. |
| 90 | virtual bool ConfigureInterface(const std::string& ifname, |
| 91 | const MacAddress& mac_addr, |
| 92 | uint32_t ipv4_addr, |
| 93 | uint32_t ipv4_prefix_len, |
| 94 | bool up, |
| 95 | bool enable_multicast); |
| 96 | |
Garrick Evans | 5486162 | 2019-07-19 09:05:09 +0900 | [diff] [blame] | 97 | virtual void RemoveInterface(const std::string& ifname); |
| 98 | |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 99 | // Create (or flush and delete) pre-routing rules supporting legacy (ARC N) |
| 100 | // single networking DNAT configuration. |
| 101 | virtual bool AddLegacyIPv4DNAT(const std::string& ipv4_addr); |
| 102 | virtual void RemoveLegacyIPv4DNAT(); |
| 103 | |
Garrick Evans | 5486162 | 2019-07-19 09:05:09 +0900 | [diff] [blame] | 104 | // Enable ingress traffic from a specific physical device to the legacy |
| 105 | // single networkng DNAT configuration. |
| 106 | virtual bool AddLegacyIPv4InboundDNAT(const std::string& ifname); |
| 107 | virtual void RemoveLegacyIPv4InboundDNAT(); |
| 108 | |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 109 | // Create (or delete) pre-routing rules allowing direct ingress on |ifname| |
| 110 | // to guest desintation |ipv4_addr|. |
| 111 | virtual bool AddInboundIPv4DNAT(const std::string& ifname, |
| 112 | const std::string& ipv4_addr); |
| 113 | virtual void RemoveInboundIPv4DNAT(const std::string& ifname, |
| 114 | const std::string& ipv4_addr); |
| 115 | |
| 116 | // Create (or delete) a forwarding rule for |ifname|. |
| 117 | virtual bool AddOutboundIPv4(const std::string& ifname); |
| 118 | virtual void RemoveOutboundIPv4(const std::string& ifname); |
| 119 | |
Garrick Evans | d291af6 | 2020-05-25 10:39:06 +0900 | [diff] [blame^] | 120 | // Creates (or deletes) the forwarding and postrouting rules for SNAT |
| 121 | // fwmarked IPv4 traffic. |
| 122 | virtual bool AddSNATMarkRules(); |
| 123 | virtual void RemoveSNATMarkRules(); |
| 124 | |
Hugo Benichi | e8758b5 | 2020-04-03 14:49:01 +0900 | [diff] [blame] | 125 | // Create (or delete) a mangle PREROUTING rule for marking IPv4 traffic |
| 126 | // outgoing of |ifname| with the SNAT fwmark value 0x1. |
| 127 | // TODO(hugobenichi) Refer to RoutingService to obtain the fwmark value and |
| 128 | // add a fwmark mask in the generated rule. |
| 129 | virtual bool AddOutboundIPv4SNATMark(const std::string& ifname); |
| 130 | virtual void RemoveOutboundIPv4SNATMark(const std::string& ifname); |
| 131 | |
Garrick Evans | d291af6 | 2020-05-25 10:39:06 +0900 | [diff] [blame^] | 132 | // Create (or delete) a forward rule for established connections. |
| 133 | virtual bool AddForwardEstablishedRule(); |
| 134 | virtual void RemoveForwardEstablishedRule(); |
| 135 | |
Taoyu Li | 90c1391 | 2019-11-26 17:56:54 +0900 | [diff] [blame] | 136 | // Methods supporting IPv6 configuration for ARC. |
Garrick Evans | 664a82f | 2019-12-17 12:18:05 +0900 | [diff] [blame] | 137 | virtual bool MaskInterfaceFlags(const std::string& ifname, |
| 138 | uint16_t on, |
| 139 | uint16_t off = 0); |
Garrick Evans | 260ff30 | 2019-07-25 11:22:50 +0900 | [diff] [blame] | 140 | |
Taoyu Li | 90c1391 | 2019-11-26 17:56:54 +0900 | [diff] [blame] | 141 | virtual bool AddIPv6Forwarding(const std::string& ifname1, |
| 142 | const std::string& ifname2); |
| 143 | virtual void RemoveIPv6Forwarding(const std::string& ifname1, |
| 144 | const std::string& ifname2); |
| 145 | |
Garrick Evans | 260ff30 | 2019-07-25 11:22:50 +0900 | [diff] [blame] | 146 | virtual bool AddIPv6HostRoute(const std::string& ifname, |
| 147 | const std::string& ipv6_addr, |
| 148 | int ipv6_prefix_len); |
| 149 | virtual void RemoveIPv6HostRoute(const std::string& ifname, |
| 150 | const std::string& ipv6_addr, |
| 151 | int ipv6_prefix_len); |
| 152 | |
| 153 | virtual bool AddIPv6Neighbor(const std::string& ifname, |
| 154 | const std::string& ipv6_addr); |
| 155 | virtual void RemoveIPv6Neighbor(const std::string& ifname, |
| 156 | const std::string& ipv6_addr); |
| 157 | |
Hugo Benichi | e8758b5 | 2020-04-03 14:49:01 +0900 | [diff] [blame] | 158 | // Adds (or deletes) a route to direct to |gateway_addr| the traffic destined |
| 159 | // to the subnet defined by |addr| and |netmask|. |
Garrick Evans | 3d97a39 | 2020-02-21 15:24:37 +0900 | [diff] [blame] | 160 | virtual bool AddIPv4Route(uint32_t gateway_addr, |
| 161 | uint32_t addr, |
| 162 | uint32_t netmask); |
Hugo Benichi | e8758b5 | 2020-04-03 14:49:01 +0900 | [diff] [blame] | 163 | virtual bool DeleteIPv4Route(uint32_t gateway_addr, |
| 164 | uint32_t addr, |
| 165 | uint32_t netmask); |
| 166 | // Adds (or deletes) a route to direct to |ifname| the traffic destined to the |
| 167 | // subnet defined by |addr| and |netmask|. |
| 168 | virtual bool AddIPv4Route(const std::string& ifname, |
| 169 | uint32_t addr, |
| 170 | uint32_t netmask); |
| 171 | virtual bool DeleteIPv4Route(const std::string& ifname, |
| 172 | uint32_t addr, |
| 173 | uint32_t netmask); |
Garrick Evans | 3d97a39 | 2020-02-21 15:24:37 +0900 | [diff] [blame] | 174 | |
Garrick Evans | 260ff30 | 2019-07-25 11:22:50 +0900 | [diff] [blame] | 175 | MinijailedProcessRunner& runner() const; |
| 176 | |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 177 | private: |
| 178 | MinijailedProcessRunner* process_runner_; |
Garrick Evans | c7ae82c | 2019-09-04 16:25:10 +0900 | [diff] [blame] | 179 | ioctl_t ioctl_; |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 180 | |
Hugo Benichi | e8758b5 | 2020-04-03 14:49:01 +0900 | [diff] [blame] | 181 | bool ModifyRtentry(unsigned long op, struct rtentry* route); |
| 182 | |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 183 | DISALLOW_COPY_AND_ASSIGN(Datapath); |
| 184 | }; |
| 185 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 186 | } // namespace patchpanel |
Garrick Evans | f0ab713 | 2019-06-18 14:50:42 +0900 | [diff] [blame] | 187 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 188 | #endif // PATCHPANEL_DATAPATH_H_ |