setup_ipv6.go 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119
  1. package bridge
  2. import (
  3. "fmt"
  4. "io/ioutil"
  5. "net"
  6. "os"
  7. "github.com/Sirupsen/logrus"
  8. "github.com/docker/libnetwork/types"
  9. "github.com/vishvananda/netlink"
  10. )
  11. var bridgeIPv6 *net.IPNet
  12. const (
  13. bridgeIPv6Str = "fe80::1/64"
  14. ipv6ForwardConfPerm = 0644
  15. ipv6ForwardConfDefault = "/proc/sys/net/ipv6/conf/default/forwarding"
  16. ipv6ForwardConfAll = "/proc/sys/net/ipv6/conf/all/forwarding"
  17. )
  18. func init() {
  19. // We allow ourselves to panic in this special case because we indicate a
  20. // failure to parse a compile-time define constant.
  21. var err error
  22. if bridgeIPv6, err = types.ParseCIDR(bridgeIPv6Str); err != nil {
  23. panic(fmt.Sprintf("Cannot parse default bridge IPv6 address %q: %v", bridgeIPv6Str, err))
  24. }
  25. }
  26. func setupBridgeIPv6(config *networkConfiguration, i *bridgeInterface) error {
  27. procFile := "/proc/sys/net/ipv6/conf/" + config.BridgeName + "/disable_ipv6"
  28. ipv6BridgeData, err := ioutil.ReadFile(procFile)
  29. if err != nil {
  30. return fmt.Errorf("Cannot read IPv6 setup for bridge %v: %v", config.BridgeName, err)
  31. }
  32. // Enable IPv6 on the bridge only if it isn't already enabled
  33. if ipv6BridgeData[0] != '0' {
  34. if err := ioutil.WriteFile(procFile, []byte{'0', '\n'}, ipv6ForwardConfPerm); err != nil {
  35. return fmt.Errorf("Unable to enable IPv6 addresses on bridge: %v", err)
  36. }
  37. }
  38. // Store bridge network and default gateway
  39. i.bridgeIPv6 = bridgeIPv6
  40. i.gatewayIPv6 = i.bridgeIPv6.IP
  41. if err := i.programIPv6Address(); err != nil {
  42. return err
  43. }
  44. if config.AddressIPv6 == nil {
  45. return nil
  46. }
  47. // Store the user specified bridge network and network gateway and program it
  48. i.bridgeIPv6 = config.AddressIPv6
  49. i.gatewayIPv6 = config.AddressIPv6.IP
  50. if err := i.programIPv6Address(); err != nil {
  51. return err
  52. }
  53. // Setting route to global IPv6 subnet
  54. logrus.Debugf("Adding route to IPv6 network %s via device %s", config.AddressIPv6.String(), config.BridgeName)
  55. err = i.nlh.RouteAdd(&netlink.Route{
  56. Scope: netlink.SCOPE_UNIVERSE,
  57. LinkIndex: i.Link.Attrs().Index,
  58. Dst: config.AddressIPv6,
  59. })
  60. if err != nil && !os.IsExist(err) {
  61. logrus.Errorf("Could not add route to IPv6 network %s via device %s", config.AddressIPv6.String(), config.BridgeName)
  62. }
  63. return nil
  64. }
  65. func setupGatewayIPv6(config *networkConfiguration, i *bridgeInterface) error {
  66. if config.AddressIPv6 == nil {
  67. return &ErrInvalidContainerSubnet{}
  68. }
  69. if !config.AddressIPv6.Contains(config.DefaultGatewayIPv6) {
  70. return &ErrInvalidGateway{}
  71. }
  72. // Store requested default gateway
  73. i.gatewayIPv6 = config.DefaultGatewayIPv6
  74. return nil
  75. }
  76. func setupIPv6Forwarding(config *networkConfiguration, i *bridgeInterface) error {
  77. // Get current IPv6 default forwarding setup
  78. ipv6ForwardDataDefault, err := ioutil.ReadFile(ipv6ForwardConfDefault)
  79. if err != nil {
  80. return fmt.Errorf("Cannot read IPv6 default forwarding setup: %v", err)
  81. }
  82. // Enable IPv6 default forwarding only if it is not already enabled
  83. if ipv6ForwardDataDefault[0] != '1' {
  84. if err := ioutil.WriteFile(ipv6ForwardConfDefault, []byte{'1', '\n'}, ipv6ForwardConfPerm); err != nil {
  85. logrus.Warnf("Unable to enable IPv6 default forwarding: %v", err)
  86. }
  87. }
  88. // Get current IPv6 all forwarding setup
  89. ipv6ForwardDataAll, err := ioutil.ReadFile(ipv6ForwardConfAll)
  90. if err != nil {
  91. return fmt.Errorf("Cannot read IPv6 all forwarding setup: %v", err)
  92. }
  93. // Enable IPv6 all forwarding only if it is not already enabled
  94. if ipv6ForwardDataAll[0] != '1' {
  95. if err := ioutil.WriteFile(ipv6ForwardConfAll, []byte{'1', '\n'}, ipv6ForwardConfPerm); err != nil {
  96. logrus.Warnf("Unable to enable IPv6 all forwarding: %v", err)
  97. }
  98. }
  99. return nil
  100. }