configure_linux.go 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. package sandbox
  2. import (
  3. "fmt"
  4. "net"
  5. "os"
  6. "runtime"
  7. "github.com/vishvananda/netlink"
  8. "github.com/vishvananda/netns"
  9. )
  10. func configureInterface(iface netlink.Link, settings *Interface) error {
  11. ifaceName := iface.Attrs().Name
  12. ifaceConfigurators := []struct {
  13. Fn func(netlink.Link, *Interface) error
  14. ErrMessage string
  15. }{
  16. {setInterfaceName, fmt.Sprintf("error renaming interface %q to %q", ifaceName, settings.DstName)},
  17. {setInterfaceIP, fmt.Sprintf("error setting interface %q IP to %q", ifaceName, settings.Address)},
  18. {setInterfaceIPv6, fmt.Sprintf("error setting interface %q IPv6 to %q", ifaceName, settings.AddressIPv6)},
  19. {setInterfaceRoutes, fmt.Sprintf("error setting interface %q routes to %q", ifaceName, settings.Routes)},
  20. }
  21. for _, config := range ifaceConfigurators {
  22. if err := config.Fn(iface, settings); err != nil {
  23. return fmt.Errorf("%s: %v", config.ErrMessage, err)
  24. }
  25. }
  26. return nil
  27. }
  28. func programGateway(path string, gw net.IP, isAdd bool) error {
  29. runtime.LockOSThread()
  30. defer runtime.UnlockOSThread()
  31. origns, err := netns.Get()
  32. if err != nil {
  33. return err
  34. }
  35. defer origns.Close()
  36. f, err := os.OpenFile(path, os.O_RDONLY, 0)
  37. if err != nil {
  38. return fmt.Errorf("failed get network namespace %q: %v", path, err)
  39. }
  40. defer f.Close()
  41. nsFD := f.Fd()
  42. if err = netns.Set(netns.NsHandle(nsFD)); err != nil {
  43. return err
  44. }
  45. defer netns.Set(origns)
  46. gwRoutes, err := netlink.RouteGet(gw)
  47. if err != nil {
  48. return fmt.Errorf("route for the gateway could not be found: %v", err)
  49. }
  50. if isAdd {
  51. return netlink.RouteAdd(&netlink.Route{
  52. Scope: netlink.SCOPE_UNIVERSE,
  53. LinkIndex: gwRoutes[0].LinkIndex,
  54. Gw: gw,
  55. })
  56. }
  57. return netlink.RouteDel(&netlink.Route{
  58. Scope: netlink.SCOPE_UNIVERSE,
  59. LinkIndex: gwRoutes[0].LinkIndex,
  60. Gw: gw,
  61. })
  62. }
  63. // Program a route in to the namespace routing table.
  64. func programRoute(path string, dest *net.IPNet, nh net.IP) error {
  65. runtime.LockOSThread()
  66. defer runtime.UnlockOSThread()
  67. origns, err := netns.Get()
  68. if err != nil {
  69. return err
  70. }
  71. defer origns.Close()
  72. f, err := os.OpenFile(path, os.O_RDONLY, 0)
  73. if err != nil {
  74. return fmt.Errorf("failed get network namespace %q: %v", path, err)
  75. }
  76. defer f.Close()
  77. nsFD := f.Fd()
  78. if err = netns.Set(netns.NsHandle(nsFD)); err != nil {
  79. return err
  80. }
  81. defer netns.Set(origns)
  82. gwRoutes, err := netlink.RouteGet(nh)
  83. if err != nil {
  84. return fmt.Errorf("route for the next hop could not be found: %v", err)
  85. }
  86. return netlink.RouteAdd(&netlink.Route{
  87. Scope: netlink.SCOPE_UNIVERSE,
  88. LinkIndex: gwRoutes[0].LinkIndex,
  89. Gw: gwRoutes[0].Gw,
  90. Dst: dest,
  91. })
  92. }
  93. // Delete a route from the namespace routing table.
  94. func removeRoute(path string, dest *net.IPNet, nh net.IP) error {
  95. runtime.LockOSThread()
  96. defer runtime.UnlockOSThread()
  97. origns, err := netns.Get()
  98. if err != nil {
  99. return err
  100. }
  101. defer origns.Close()
  102. f, err := os.OpenFile(path, os.O_RDONLY, 0)
  103. if err != nil {
  104. return fmt.Errorf("failed get network namespace %q: %v", path, err)
  105. }
  106. defer f.Close()
  107. nsFD := f.Fd()
  108. if err = netns.Set(netns.NsHandle(nsFD)); err != nil {
  109. return err
  110. }
  111. defer netns.Set(origns)
  112. gwRoutes, err := netlink.RouteGet(nh)
  113. if err != nil {
  114. return fmt.Errorf("route for the next hop could not be found: %v", err)
  115. }
  116. return netlink.RouteDel(&netlink.Route{
  117. Scope: netlink.SCOPE_UNIVERSE,
  118. LinkIndex: gwRoutes[0].LinkIndex,
  119. Gw: gwRoutes[0].Gw,
  120. Dst: dest,
  121. })
  122. }
  123. func setInterfaceIP(iface netlink.Link, settings *Interface) error {
  124. ipAddr := &netlink.Addr{IPNet: settings.Address, Label: ""}
  125. return netlink.AddrAdd(iface, ipAddr)
  126. }
  127. func setInterfaceIPv6(iface netlink.Link, settings *Interface) error {
  128. if settings.AddressIPv6 == nil {
  129. return nil
  130. }
  131. ipAddr := &netlink.Addr{IPNet: settings.AddressIPv6, Label: ""}
  132. return netlink.AddrAdd(iface, ipAddr)
  133. }
  134. func setInterfaceName(iface netlink.Link, settings *Interface) error {
  135. return netlink.LinkSetName(iface, settings.DstName)
  136. }
  137. func setInterfaceRoutes(iface netlink.Link, settings *Interface) error {
  138. for _, route := range settings.Routes {
  139. err := netlink.RouteAdd(&netlink.Route{
  140. Scope: netlink.SCOPE_LINK,
  141. LinkIndex: iface.Attrs().Index,
  142. Dst: route,
  143. })
  144. if err != nil {
  145. return err
  146. }
  147. }
  148. return nil
  149. }