setup_ipv4_linux.go 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293
  1. package bridge
  2. import (
  3. "context"
  4. "errors"
  5. "fmt"
  6. "net"
  7. "os"
  8. "path/filepath"
  9. "github.com/containerd/log"
  10. "github.com/docker/docker/libnetwork/types"
  11. "github.com/vishvananda/netlink"
  12. )
  13. func selectIPv4Address(addresses []netlink.Addr, selector *net.IPNet) (netlink.Addr, error) {
  14. if len(addresses) == 0 {
  15. return netlink.Addr{}, errors.New("unable to select an address as the address pool is empty")
  16. }
  17. if selector != nil {
  18. for _, addr := range addresses {
  19. if selector.Contains(addr.IP) {
  20. return addr, nil
  21. }
  22. }
  23. }
  24. return addresses[0], nil
  25. }
  26. func setupBridgeIPv4(config *networkConfiguration, i *bridgeInterface) error {
  27. // TODO(aker): the bridge driver panics if its bridgeIPv4 field isn't set. Once bridge subnet and bridge IP address
  28. // are decoupled, we should assign it only when it's really needed.
  29. i.bridgeIPv4 = config.AddressIPv4
  30. if config.Internal {
  31. return nil
  32. }
  33. if !config.InhibitIPv4 {
  34. addrv4List, err := i.addresses(netlink.FAMILY_V4)
  35. if err != nil {
  36. return fmt.Errorf("failed to retrieve bridge interface addresses: %v", err)
  37. }
  38. addrv4, _ := selectIPv4Address(addrv4List, config.AddressIPv4)
  39. if !types.CompareIPNet(addrv4.IPNet, config.AddressIPv4) {
  40. if addrv4.IPNet != nil {
  41. if err := i.nlh.AddrDel(i.Link, &addrv4); err != nil {
  42. return fmt.Errorf("failed to remove current ip address from bridge: %v", err)
  43. }
  44. }
  45. log.G(context.TODO()).Debugf("Assigning address to bridge interface %s: %s", config.BridgeName, config.AddressIPv4)
  46. if err := i.nlh.AddrAdd(i.Link, &netlink.Addr{IPNet: config.AddressIPv4}); err != nil {
  47. return &IPv4AddrAddError{IP: config.AddressIPv4, Err: err}
  48. }
  49. }
  50. }
  51. // Store the default gateway
  52. i.gatewayIPv4 = config.AddressIPv4.IP
  53. return nil
  54. }
  55. func setupGatewayIPv4(config *networkConfiguration, i *bridgeInterface) error {
  56. if !i.bridgeIPv4.Contains(config.DefaultGatewayIPv4) {
  57. return &ErrInvalidGateway{}
  58. }
  59. if config.Internal {
  60. return types.InvalidParameterErrorf("no gateway can be set on an internal bridge network")
  61. }
  62. // Store requested default gateway
  63. i.gatewayIPv4 = config.DefaultGatewayIPv4
  64. return nil
  65. }
  66. func setupLoopbackAddressesRouting(config *networkConfiguration, i *bridgeInterface) error {
  67. sysPath := filepath.Join("/proc/sys/net/ipv4/conf", config.BridgeName, "route_localnet")
  68. ipv4LoRoutingData, err := os.ReadFile(sysPath)
  69. if err != nil {
  70. return fmt.Errorf("Cannot read IPv4 local routing setup: %v", err)
  71. }
  72. // Enable loopback addresses routing only if it isn't already enabled
  73. if ipv4LoRoutingData[0] != '1' {
  74. if err := os.WriteFile(sysPath, []byte{'1', '\n'}, 0o644); err != nil {
  75. return fmt.Errorf("Unable to enable local routing for hairpin mode: %v", err)
  76. }
  77. }
  78. return nil
  79. }