setup_ipv4.go 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136
  1. package bridge
  2. import (
  3. "fmt"
  4. "io/ioutil"
  5. "net"
  6. "path/filepath"
  7. log "github.com/Sirupsen/logrus"
  8. "github.com/docker/libnetwork/netutils"
  9. "github.com/vishvananda/netlink"
  10. )
  11. var bridgeNetworks []*net.IPNet
  12. func init() {
  13. // Here we don't follow the convention of using the 1st IP of the range for the gateway.
  14. // This is to use the same gateway IPs as the /24 ranges, which predate the /16 ranges.
  15. // In theory this shouldn't matter - in practice there's bound to be a few scripts relying
  16. // on the internal addressing or other stupid things like that.
  17. // They shouldn't, but hey, let's not break them unless we really have to.
  18. for _, addr := range []string{
  19. "172.17.42.1/16", // Don't use 172.16.0.0/16, it conflicts with EC2 DNS 172.16.0.23
  20. "10.0.42.1/16", // Don't even try using the entire /8, that's too intrusive
  21. "10.1.42.1/16",
  22. "10.42.42.1/16",
  23. "172.16.42.1/24",
  24. "172.16.43.1/24",
  25. "172.16.44.1/24",
  26. "10.0.42.1/24",
  27. "10.0.43.1/24",
  28. "192.168.42.1/24",
  29. "192.168.43.1/24",
  30. "192.168.44.1/24",
  31. } {
  32. ip, net, err := net.ParseCIDR(addr)
  33. if err != nil {
  34. log.Errorf("Failed to parse address %s", addr)
  35. continue
  36. }
  37. net.IP = ip.To4()
  38. bridgeNetworks = append(bridgeNetworks, net)
  39. }
  40. }
  41. func setupBridgeIPv4(config *NetworkConfiguration, i *bridgeInterface) error {
  42. addrv4, _, err := i.addresses()
  43. if err != nil {
  44. return err
  45. }
  46. // Check if we have an IP address already on the bridge.
  47. if addrv4.IPNet != nil {
  48. // Make sure to store bridge network and default gateway before getting out.
  49. i.bridgeIPv4 = addrv4.IPNet
  50. i.gatewayIPv4 = addrv4.IPNet.IP
  51. return nil
  52. }
  53. // Do not try to configure IPv4 on a non-default bridge unless you are
  54. // specifically asked to do so.
  55. if config.BridgeName != DefaultBridgeName && !config.AllowNonDefaultBridge {
  56. return NonDefaultBridgeExistError(config.BridgeName)
  57. }
  58. bridgeIPv4, err := electBridgeIPv4(config)
  59. if err != nil {
  60. return err
  61. }
  62. log.Debugf("Creating bridge interface %q with network %s", config.BridgeName, bridgeIPv4)
  63. if err := netlink.AddrAdd(i.Link, &netlink.Addr{IPNet: bridgeIPv4}); err != nil {
  64. return &IPv4AddrAddError{IP: bridgeIPv4, Err: err}
  65. }
  66. // Store bridge network and default gateway
  67. i.bridgeIPv4 = bridgeIPv4
  68. i.gatewayIPv4 = i.bridgeIPv4.IP
  69. return nil
  70. }
  71. func allocateBridgeIP(config *NetworkConfiguration, i *bridgeInterface) error {
  72. ipAllocator.RequestIP(i.bridgeIPv4, i.bridgeIPv4.IP)
  73. return nil
  74. }
  75. func electBridgeIPv4(config *NetworkConfiguration) (*net.IPNet, error) {
  76. // Use the requested IPv4 CIDR when available.
  77. if config.AddressIPv4 != nil {
  78. return config.AddressIPv4, nil
  79. }
  80. // We don't check for an error here, because we don't really care if we
  81. // can't read /etc/resolv.conf. So instead we skip the append if resolvConf
  82. // is nil. It either doesn't exist, or we can't read it for some reason.
  83. nameservers := []string{}
  84. if resolvConf, _ := readResolvConf(); resolvConf != nil {
  85. nameservers = append(nameservers, getNameserversAsCIDR(resolvConf)...)
  86. }
  87. // Try to automatically elect appropriate bridge IPv4 settings.
  88. for _, n := range bridgeNetworks {
  89. if err := netutils.CheckNameserverOverlaps(nameservers, n); err == nil {
  90. if err := netutils.CheckRouteOverlaps(n); err == nil {
  91. return n, nil
  92. }
  93. }
  94. }
  95. return nil, IPv4AddrRangeError(config.BridgeName)
  96. }
  97. func setupGatewayIPv4(config *NetworkConfiguration, i *bridgeInterface) error {
  98. if !i.bridgeIPv4.Contains(config.DefaultGatewayIPv4) {
  99. return &ErrInvalidGateway{}
  100. }
  101. if _, err := ipAllocator.RequestIP(i.bridgeIPv4, config.DefaultGatewayIPv4); err != nil {
  102. return err
  103. }
  104. // Store requested default gateway
  105. i.gatewayIPv4 = config.DefaultGatewayIPv4
  106. return nil
  107. }
  108. func setupLoopbackAdressesRouting(config *NetworkConfiguration, i *bridgeInterface) error {
  109. // Enable loopback adresses routing
  110. sysPath := filepath.Join("/proc/sys/net/ipv4/conf", config.BridgeName, "route_localnet")
  111. if err := ioutil.WriteFile(sysPath, []byte{'1', '\n'}, 0644); err != nil {
  112. return fmt.Errorf("Unable to enable local routing for hairpin mode: %v", err)
  113. }
  114. return nil
  115. }