configure_linux.go 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168
  1. package sandbox
  2. import (
  3. "fmt"
  4. "net"
  5. "os"
  6. "runtime"
  7. "github.com/vishvananda/netlink"
  8. "github.com/vishvananda/netns"
  9. )
  10. func configureInterface(iface netlink.Link, settings *Interface) error {
  11. ifaceName := iface.Attrs().Name
  12. ifaceConfigurators := []struct {
  13. Fn func(netlink.Link, *Interface) error
  14. ErrMessage string
  15. }{
  16. {setInterfaceName, fmt.Sprintf("error renaming interface %q to %q", ifaceName, settings.DstName)},
  17. {setInterfaceIP, fmt.Sprintf("error setting interface %q IP to %q", ifaceName, settings.Address)},
  18. {setInterfaceIPv6, fmt.Sprintf("error setting interface %q IPv6 to %q", ifaceName, settings.AddressIPv6)},
  19. {setInterfaceRoutes, fmt.Sprintf("error setting interface %q routes to %q", ifaceName, settings.Routes)},
  20. }
  21. for _, config := range ifaceConfigurators {
  22. if err := config.Fn(iface, settings); err != nil {
  23. return fmt.Errorf("%s: %v", config.ErrMessage, err)
  24. }
  25. }
  26. return nil
  27. }
  28. func programGateway(path string, gw net.IP) error {
  29. runtime.LockOSThread()
  30. defer runtime.UnlockOSThread()
  31. origns, err := netns.Get()
  32. if err != nil {
  33. return err
  34. }
  35. defer origns.Close()
  36. f, err := os.OpenFile(path, os.O_RDONLY, 0)
  37. if err != nil {
  38. return fmt.Errorf("failed get network namespace %q: %v", path, err)
  39. }
  40. defer f.Close()
  41. nsFD := f.Fd()
  42. if err = netns.Set(netns.NsHandle(nsFD)); err != nil {
  43. return err
  44. }
  45. defer netns.Set(origns)
  46. gwRoutes, err := netlink.RouteGet(gw)
  47. if err != nil {
  48. return fmt.Errorf("route for the gateway could not be found: %v", err)
  49. }
  50. return netlink.RouteAdd(&netlink.Route{
  51. Scope: netlink.SCOPE_UNIVERSE,
  52. LinkIndex: gwRoutes[0].LinkIndex,
  53. Gw: gw,
  54. })
  55. }
  56. // Program a route in to the namespace routing table.
  57. func programRoute(path string, dest *net.IPNet, nh net.IP) error {
  58. runtime.LockOSThread()
  59. defer runtime.UnlockOSThread()
  60. origns, err := netns.Get()
  61. if err != nil {
  62. return err
  63. }
  64. defer origns.Close()
  65. f, err := os.OpenFile(path, os.O_RDONLY, 0)
  66. if err != nil {
  67. return fmt.Errorf("failed get network namespace %q: %v", path, err)
  68. }
  69. defer f.Close()
  70. nsFD := f.Fd()
  71. if err = netns.Set(netns.NsHandle(nsFD)); err != nil {
  72. return err
  73. }
  74. defer netns.Set(origns)
  75. gwRoutes, err := netlink.RouteGet(nh)
  76. if err != nil {
  77. return fmt.Errorf("route for the next hop could not be found: %v", err)
  78. }
  79. return netlink.RouteAdd(&netlink.Route{
  80. Scope: netlink.SCOPE_UNIVERSE,
  81. LinkIndex: gwRoutes[0].LinkIndex,
  82. Gw: gwRoutes[0].Gw,
  83. Dst: dest,
  84. })
  85. }
  86. // Delete a route from the namespace routing table.
  87. func removeRoute(path string, dest *net.IPNet, nh net.IP) error {
  88. runtime.LockOSThread()
  89. defer runtime.UnlockOSThread()
  90. origns, err := netns.Get()
  91. if err != nil {
  92. return err
  93. }
  94. defer origns.Close()
  95. f, err := os.OpenFile(path, os.O_RDONLY, 0)
  96. if err != nil {
  97. return fmt.Errorf("failed get network namespace %q: %v", path, err)
  98. }
  99. defer f.Close()
  100. nsFD := f.Fd()
  101. if err = netns.Set(netns.NsHandle(nsFD)); err != nil {
  102. return err
  103. }
  104. defer netns.Set(origns)
  105. gwRoutes, err := netlink.RouteGet(nh)
  106. if err != nil {
  107. return fmt.Errorf("route for the next hop could not be found: %v", err)
  108. }
  109. return netlink.RouteDel(&netlink.Route{
  110. Scope: netlink.SCOPE_UNIVERSE,
  111. LinkIndex: gwRoutes[0].LinkIndex,
  112. Gw: gwRoutes[0].Gw,
  113. Dst: dest,
  114. })
  115. }
  116. func setInterfaceIP(iface netlink.Link, settings *Interface) error {
  117. ipAddr := &netlink.Addr{IPNet: settings.Address, Label: ""}
  118. return netlink.AddrAdd(iface, ipAddr)
  119. }
  120. func setInterfaceIPv6(iface netlink.Link, settings *Interface) error {
  121. if settings.AddressIPv6 == nil {
  122. return nil
  123. }
  124. ipAddr := &netlink.Addr{IPNet: settings.AddressIPv6, Label: ""}
  125. return netlink.AddrAdd(iface, ipAddr)
  126. }
  127. func setInterfaceName(iface netlink.Link, settings *Interface) error {
  128. return netlink.LinkSetName(iface, settings.DstName)
  129. }
  130. func setInterfaceRoutes(iface netlink.Link, settings *Interface) error {
  131. for _, route := range settings.Routes {
  132. err := netlink.RouteAdd(&netlink.Route{
  133. Scope: netlink.SCOPE_UNIVERSE,
  134. LinkIndex: iface.Attrs().Index,
  135. Dst: route,
  136. })
  137. if err != nil {
  138. return err
  139. }
  140. }
  141. return nil
  142. }