1 /*-
2 * SPDX-License-Identifier: BSD-2-Clause
3 *
4 * Copyright (c) 2022 Alexander V. Chernikov <melifaro@FreeBSD.org>
5 *
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
8 * are met:
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in the
13 * documentation and/or other materials provided with the distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
19 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25 * SUCH DAMAGE.
26 */
27
28 #include <sys/cdefs.h>
29 #include "opt_inet.h"
30 #include "opt_inet6.h"
31 #include <sys/types.h>
32 #include <sys/malloc.h>
33 #include <sys/socket.h>
34 #include <sys/sockio.h>
35 #include <sys/syslog.h>
36 #include <sys/socketvar.h>
37
38 #include <net/ethernet.h>
39 #include <net/if.h>
40 #include <net/if_dl.h>
41 #include <net/if_media.h>
42 #include <net/if_var.h>
43 #include <net/if_clone.h>
44 #include <net/if_vlan_var.h>
45 #include <net/route.h>
46 #include <net/route/nhop.h>
47 #include <net/route/route_ctl.h>
48 #include <netlink/netlink.h>
49 #include <netlink/netlink_ctl.h>
50 #include <netlink/netlink_route.h>
51 #include <netlink/route/route_var.h>
52
53 #include <netinet6/scope6_var.h> /* scope deembedding */
54
55 #define DEBUG_MOD_NAME nl_iface_drivers
56 #define DEBUG_MAX_LEVEL LOG_DEBUG3
57 #include <netlink/netlink_debug.h>
58 _DECLARE_DEBUG(LOG_INFO);
59
60 /*
61 * Generic modification interface handler.
62 * Responsible for changing network stack interface attributes
63 * such as state, mtu or description.
64 */
65 int
_nl_modify_ifp_generic(struct ifnet * ifp,struct nl_parsed_link * lattrs,const struct nlattr_bmask * bm,struct nl_pstate * npt)66 _nl_modify_ifp_generic(struct ifnet *ifp, struct nl_parsed_link *lattrs,
67 const struct nlattr_bmask *bm, struct nl_pstate *npt)
68 {
69 int error;
70
71 if (lattrs->ifla_ifalias != NULL) {
72 if (!nlp_has_priv(npt->nlp, PRIV_NET_SETIFDESCR)) {
73 nlmsg_report_err_msg(npt, "Not enough privileges to set descr");
74 return (EPERM);
75 }
76 int len = strlen(lattrs->ifla_ifalias) + 1;
77 char *buf = if_allocdescr(len, M_WAITOK);
78
79 memcpy(buf, lattrs->ifla_ifalias, len);
80 if_setdescr(ifp, buf);
81 if_setlastchange(ifp);
82 }
83
84 if ((lattrs->ifi_change & IFF_UP) != 0 || lattrs->ifi_change == 0) {
85 /* Request to up or down the interface */
86 if (!nlp_has_priv(npt->nlp, PRIV_NET_SETIFFLAGS)) {
87 nlmsg_report_err_msg(npt, "Not enough privileges to set flags");
88 return (EPERM);
89 }
90 if (lattrs->ifi_flags & IFF_UP)
91 if_up(ifp);
92 else
93 if_down(ifp);
94 }
95
96 if (lattrs->ifla_mtu > 0) {
97 if (!nlp_has_priv(npt->nlp, PRIV_NET_SETIFMTU)) {
98 nlmsg_report_err_msg(npt, "Not enough privileges to set mtu");
99 return (EPERM);
100 }
101 struct ifreq ifr = { .ifr_mtu = lattrs->ifla_mtu };
102 error = ifhwioctl(SIOCSIFMTU, ifp, (char *)&ifr,
103 curthread);
104 if (error != 0) {
105 nlmsg_report_err_msg(npt, "Failed to set mtu");
106 return (error);
107 }
108 }
109
110 if ((lattrs->ifi_change & IFF_PROMISC) != 0 ||
111 lattrs->ifi_change == 0) {
112 /*
113 * When asking for IFF_PROMISC, set permanent flag instead
114 * (IFF_PPROMISC) as we have no way of doing promiscuity
115 * reference counting through ifpromisc(). Every call to this
116 * function either sets or unsets IFF_PROMISC, and ifi_change
117 * is usually set to 0xFFFFFFFF.
118 */
119 if (!nlp_has_priv(npt->nlp, PRIV_NET_SETIFFLAGS)) {
120 nlmsg_report_err_msg(npt, "Not enough privileges to set promisc");
121 return (EPERM);
122 }
123 if_setppromisc(ifp, (lattrs->ifi_flags & IFF_PROMISC) != 0);
124 }
125
126 if (lattrs->ifla_address != NULL) {
127 if (!nlp_has_priv(npt->nlp, PRIV_NET_SETIFMAC)) {
128 nlmsg_report_err_msg(npt,
129 "Not enough privileges to set IFLA_ADDRESS");
130 return (EPERM);
131 }
132 error = if_setlladdr(ifp,
133 NLA_DATA(lattrs->ifla_address),
134 NLA_DATA_LEN(lattrs->ifla_address));
135 if (error != 0) {
136 nlmsg_report_err_msg(npt,
137 "setting IFLA_ADDRESS failed with error code: %d",
138 error);
139 return (error);
140 }
141 }
142
143 return (0);
144 }
145
146 /*
147 * Saves the resulting ifindex and ifname to report them
148 * to userland along with the operation result.
149 * NLA format:
150 * NLMSGERR_ATTR_COOKIE(nested)
151 * IFLA_NEW_IFINDEX(u32)
152 * IFLA_IFNAME(string)
153 */
154 void
_nl_store_ifp_cookie(struct nl_pstate * npt,struct ifnet * ifp)155 _nl_store_ifp_cookie(struct nl_pstate *npt, struct ifnet *ifp)
156 {
157 int ifname_len = strlen(if_name(ifp));
158 uint32_t ifindex = (uint32_t)if_getindex(ifp);
159
160 int nla_len = sizeof(struct nlattr) * 3 +
161 sizeof(ifindex) + NL_ITEM_ALIGN(ifname_len + 1);
162 struct nlattr *nla_cookie = npt_alloc(npt, nla_len);
163
164 if (nla_cookie == NULL)
165 return;
166
167 /* Nested TLV */
168 nla_cookie->nla_len = nla_len;
169 nla_cookie->nla_type = NLMSGERR_ATTR_COOKIE;
170
171 struct nlattr *nla = nla_cookie + 1;
172 nla->nla_len = sizeof(struct nlattr) + sizeof(ifindex);
173 nla->nla_type = IFLA_NEW_IFINDEX;
174 memcpy(NLA_DATA(nla), &ifindex, sizeof(ifindex));
175
176 nla = NLA_NEXT(nla);
177 nla->nla_len = sizeof(struct nlattr) + ifname_len + 1;
178 nla->nla_type = IFLA_IFNAME;
179 strlcpy(NLA_DATA(nla), if_name(ifp), ifname_len + 1);
180
181 nlmsg_report_cookie(npt, nla_cookie);
182 }
183
184