setup_ipv6_linux.go 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109
  1. package bridge
  2. import (
  3. "context"
  4. "fmt"
  5. "net"
  6. "os"
  7. "github.com/containerd/log"
  8. "github.com/vishvananda/netlink"
  9. )
  10. // bridgeIPv6 is the default, link-local IPv6 address for the bridge (fe80::1/64)
  11. var bridgeIPv6 = &net.IPNet{IP: net.ParseIP("fe80::1"), Mask: net.CIDRMask(64, 128)}
  12. const (
  13. ipv6ForwardConfPerm = 0o644
  14. ipv6ForwardConfDefault = "/proc/sys/net/ipv6/conf/default/forwarding"
  15. ipv6ForwardConfAll = "/proc/sys/net/ipv6/conf/all/forwarding"
  16. )
  17. func setupBridgeIPv6(config *networkConfiguration, i *bridgeInterface) error {
  18. procFile := "/proc/sys/net/ipv6/conf/" + config.BridgeName + "/disable_ipv6"
  19. ipv6BridgeData, err := os.ReadFile(procFile)
  20. if err != nil {
  21. return fmt.Errorf("Cannot read IPv6 setup for bridge %v: %v", config.BridgeName, err)
  22. }
  23. // Enable IPv6 on the bridge only if it isn't already enabled
  24. if ipv6BridgeData[0] != '0' {
  25. if err := os.WriteFile(procFile, []byte{'0', '\n'}, ipv6ForwardConfPerm); err != nil {
  26. return fmt.Errorf("Unable to enable IPv6 addresses on bridge: %v", err)
  27. }
  28. }
  29. // Store bridge network and default gateway
  30. i.bridgeIPv6 = bridgeIPv6
  31. i.gatewayIPv6 = i.bridgeIPv6.IP
  32. if err := i.programIPv6Address(); err != nil {
  33. return err
  34. }
  35. if config.AddressIPv6 == nil {
  36. return nil
  37. }
  38. // Store the user specified bridge network and network gateway and program it
  39. i.bridgeIPv6 = config.AddressIPv6
  40. i.gatewayIPv6 = config.AddressIPv6.IP
  41. if err := i.programIPv6Address(); err != nil {
  42. return err
  43. }
  44. // Setting route to global IPv6 subnet
  45. log.G(context.TODO()).Debugf("Adding route to IPv6 network %s via device %s", config.AddressIPv6.String(), config.BridgeName)
  46. err = i.nlh.RouteAdd(&netlink.Route{
  47. Scope: netlink.SCOPE_UNIVERSE,
  48. LinkIndex: i.Link.Attrs().Index,
  49. Dst: config.AddressIPv6,
  50. })
  51. if err != nil && !os.IsExist(err) {
  52. log.G(context.TODO()).Errorf("Could not add route to IPv6 network %s via device %s: %s", config.AddressIPv6.String(), config.BridgeName, err)
  53. }
  54. return nil
  55. }
  56. func setupGatewayIPv6(config *networkConfiguration, i *bridgeInterface) error {
  57. if config.AddressIPv6 == nil {
  58. return &ErrInvalidContainerSubnet{}
  59. }
  60. if !config.AddressIPv6.Contains(config.DefaultGatewayIPv6) {
  61. return &ErrInvalidGateway{}
  62. }
  63. // Store requested default gateway
  64. i.gatewayIPv6 = config.DefaultGatewayIPv6
  65. return nil
  66. }
  67. func setupIPv6Forwarding(config *networkConfiguration, i *bridgeInterface) error {
  68. // Get current IPv6 default forwarding setup
  69. ipv6ForwardDataDefault, err := os.ReadFile(ipv6ForwardConfDefault)
  70. if err != nil {
  71. return fmt.Errorf("Cannot read IPv6 default forwarding setup: %v", err)
  72. }
  73. // Enable IPv6 default forwarding only if it is not already enabled
  74. if ipv6ForwardDataDefault[0] != '1' {
  75. if err := os.WriteFile(ipv6ForwardConfDefault, []byte{'1', '\n'}, ipv6ForwardConfPerm); err != nil {
  76. log.G(context.TODO()).Warnf("Unable to enable IPv6 default forwarding: %v", err)
  77. }
  78. }
  79. // Get current IPv6 all forwarding setup
  80. ipv6ForwardDataAll, err := os.ReadFile(ipv6ForwardConfAll)
  81. if err != nil {
  82. return fmt.Errorf("Cannot read IPv6 all forwarding setup: %v", err)
  83. }
  84. // Enable IPv6 all forwarding only if it is not already enabled
  85. if ipv6ForwardDataAll[0] != '1' {
  86. if err := os.WriteFile(ipv6ForwardConfAll, []byte{'1', '\n'}, ipv6ForwardConfPerm); err != nil {
  87. log.G(context.TODO()).Warnf("Unable to enable IPv6 all forwarding: %v", err)
  88. }
  89. }
  90. return nil
  91. }