Bug Summary

File:build-scan/../src/nspawn/nspawn-network.c
Warning:line 647, column 25
Potential leak of memory pointed to by 'b'

Annotated Source Code

Press '?' to see keyboard shortcuts

clang -cc1 -cc1 -triple x86_64-unknown-linux-gnu -analyze -disable-free -disable-llvm-verifier -discard-value-names -main-file-name nspawn-network.c -analyzer-store=region -analyzer-opt-analyze-nested-blocks -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -mrelocation-model pic -pic-level 2 -fhalf-no-semantic-interposition -mframe-pointer=all -relaxed-aliasing -menable-no-infs -menable-no-nans -menable-unsafe-fp-math -fno-signed-zeros -mreassociate -freciprocal-math -fdenormal-fp-math=preserve-sign,preserve-sign -ffp-contract=fast -fno-rounding-math -ffast-math -ffinite-math-only -mconstructor-aliases -munwind-tables -target-cpu x86-64 -tune-cpu generic -fno-split-dwarf-inlining -debugger-tuning=gdb -resource-dir /usr/lib64/clang/12.0.0 -include config.h -I src/nspawn/libnspawn-core.a.p -I src/nspawn -I ../src/nspawn -I src/basic -I ../src/basic -I src/shared -I ../src/shared -I src/systemd -I ../src/systemd -I src/journal -I ../src/journal -I src/journal-remote -I ../src/journal-remote -I src/resolve -I ../src/resolve -I src/timesync -I ../src/timesync -I ../src/time-wait-sync -I src/login -I ../src/login -I src/udev -I ../src/udev -I src/libudev -I ../src/libudev -I src/core -I ../src/core -I ../src/libsystemd/sd-bus -I ../src/libsystemd/sd-device -I ../src/libsystemd/sd-hwdb -I ../src/libsystemd/sd-id128 -I ../src/libsystemd/sd-netlink -I ../src/libsystemd/sd-network -I src/libsystemd-network -I ../src/libsystemd-network -I . -I .. -D _FILE_OFFSET_BITS=64 -internal-isystem /usr/local/include -internal-isystem /usr/lib64/clang/12.0.0/include -internal-externc-isystem /include -internal-externc-isystem /usr/include -Wwrite-strings -Wno-unused-parameter -Wno-missing-field-initializers -Wno-unused-result -Wno-format-signedness -Wno-error=nonnull -std=gnu99 -fconst-strings -fdebug-compilation-dir /home/mrc0mmand/repos/@redhat-plumbers/systemd-rhel8/build-scan -ferror-limit 19 -fvisibility hidden -stack-protector 2 -fgnuc-version=4.2.1 -fcolor-diagnostics -analyzer-output=html -faddrsig -o /tmp/scan-build-2021-07-16-221226-1465241-1 -x c ../src/nspawn/nspawn-network.c
1/* SPDX-License-Identifier: LGPL-2.1+ */
2
3#include <linux1/veth.h>
4#include <net/if.h>
5#include <sys/file.h>
6
7#include "libudev.h"
8#include "sd-id128.h"
9#include "sd-netlink.h"
10
11#include "alloc-util.h"
12#include "ether-addr-util.h"
13#include "lockfile-util.h"
14#include "netlink-util.h"
15#include "nspawn-network.h"
16#include "siphash24.h"
17#include "socket-util.h"
18#include "stat-util.h"
19#include "string-util.h"
20#include "udev-util.h"
21#include "util.h"
22
23#define HOST_HASH_KEY((const sd_id128_t) { .bytes = { 0x1a, 0x37, 0x6f, 0xc7, 0x46
, 0xec, 0x45, 0x0b, 0xad, 0xa3, 0xd5, 0x31, 0x06, 0x60, 0x5d,
0xb1 }})
SD_ID128_MAKE(1a,37,6f,c7,46,ec,45,0b,ad,a3,d5,31,06,60,5d,b1)((const sd_id128_t) { .bytes = { 0x1a, 0x37, 0x6f, 0xc7, 0x46
, 0xec, 0x45, 0x0b, 0xad, 0xa3, 0xd5, 0x31, 0x06, 0x60, 0x5d,
0xb1 }})
24#define CONTAINER_HASH_KEY((const sd_id128_t) { .bytes = { 0xc3, 0xc4, 0xf9, 0x19, 0xb5
, 0x57, 0xb2, 0x1c, 0xe6, 0xcf, 0x14, 0x27, 0x03, 0x9c, 0xee,
0xa2 }})
SD_ID128_MAKE(c3,c4,f9,19,b5,57,b2,1c,e6,cf,14,27,03,9c,ee,a2)((const sd_id128_t) { .bytes = { 0xc3, 0xc4, 0xf9, 0x19, 0xb5
, 0x57, 0xb2, 0x1c, 0xe6, 0xcf, 0x14, 0x27, 0x03, 0x9c, 0xee,
0xa2 }})
25#define VETH_EXTRA_HOST_HASH_KEY((const sd_id128_t) { .bytes = { 0x48, 0xc7, 0xf6, 0xb7, 0xea
, 0x9d, 0x4c, 0x9e, 0xb7, 0x28, 0xd4, 0xde, 0x91, 0xd5, 0xbf,
0x66 }})
SD_ID128_MAKE(48,c7,f6,b7,ea,9d,4c,9e,b7,28,d4,de,91,d5,bf,66)((const sd_id128_t) { .bytes = { 0x48, 0xc7, 0xf6, 0xb7, 0xea
, 0x9d, 0x4c, 0x9e, 0xb7, 0x28, 0xd4, 0xde, 0x91, 0xd5, 0xbf,
0x66 }})
26#define VETH_EXTRA_CONTAINER_HASH_KEY((const sd_id128_t) { .bytes = { 0xaf, 0x50, 0x17, 0x61, 0xce
, 0xf9, 0x4d, 0x35, 0x84, 0x0d, 0x2b, 0x20, 0x54, 0xbe, 0xce,
0x59 }})
SD_ID128_MAKE(af,50,17,61,ce,f9,4d,35,84,0d,2b,20,54,be,ce,59)((const sd_id128_t) { .bytes = { 0xaf, 0x50, 0x17, 0x61, 0xce
, 0xf9, 0x4d, 0x35, 0x84, 0x0d, 0x2b, 0x20, 0x54, 0xbe, 0xce,
0x59 }})
27#define MACVLAN_HASH_KEY((const sd_id128_t) { .bytes = { 0x00, 0x13, 0x6d, 0xbc, 0x66
, 0x83, 0x44, 0x81, 0xbb, 0x0c, 0xf9, 0x51, 0x1f, 0x24, 0xa6,
0x6f }})
SD_ID128_MAKE(00,13,6d,bc,66,83,44,81,bb,0c,f9,51,1f,24,a6,6f)((const sd_id128_t) { .bytes = { 0x00, 0x13, 0x6d, 0xbc, 0x66
, 0x83, 0x44, 0x81, 0xbb, 0x0c, 0xf9, 0x51, 0x1f, 0x24, 0xa6,
0x6f }})
28
29static int remove_one_link(sd_netlink *rtnl, const char *name) {
30 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
31 int r;
32
33 if (isempty(name))
34 return 0;
35
36 r = sd_rtnl_message_new_link(rtnl, &m, RTM_DELLINKRTM_DELLINK, 0);
37 if (r < 0)
38 return log_error_errno(r, "Failed to allocate netlink message: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 38, __func__, "Failed to allocate netlink message: %m"
) : -abs(_e); })
;
39
40 r = sd_netlink_message_append_string(m, IFLA_IFNAME, name);
41 if (r < 0)
42 return log_error_errno(r, "Failed to add netlink interface name: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 42, __func__, "Failed to add netlink interface name: %m"
) : -abs(_e); })
;
43
44 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
45 if (r == -ENODEV19) /* Already gone */
46 return 0;
47 if (r < 0)
48 return log_error_errno(r, "Failed to remove interface %s: %m", name)({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 48, __func__, "Failed to remove interface %s: %m"
, name) : -abs(_e); })
;
49
50 return 1;
51}
52
53static int generate_mac(
54 const char *machine_name,
55 struct ether_addr *mac,
56 sd_id128_t hash_key,
57 uint64_t idx) {
58
59 uint64_t result;
60 size_t l, sz;
61 uint8_t *v, *i;
62 int r;
63
64 l = strlen(machine_name);
65 sz = sizeof(sd_id128_t) + l;
66 if (idx > 0)
67 sz += sizeof(idx);
68
69 v = alloca(sz)__builtin_alloca (sz);
70
71 /* fetch some persistent data unique to the host */
72 r = sd_id128_get_machine((sd_id128_t*) v);
73 if (r < 0)
74 return r;
75
76 /* combine with some data unique (on this host) to this
77 * container instance */
78 i = mempcpy(v + sizeof(sd_id128_t), machine_name, l);
79 if (idx > 0) {
80 idx = htole64(idx)__uint64_identity (idx);
81 memcpy(i, &idx, sizeof(idx));
82 }
83
84 /* Let's hash the host machine ID plus the container name. We
85 * use a fixed, but originally randomly created hash key here. */
86 result = htole64(siphash24(v, sz, hash_key.bytes))__uint64_identity (siphash24(v, sz, hash_key.bytes));
87
88 assert_cc(ETH_ALEN <= sizeof(result))GCC diagnostic push ; GCC diagnostic ignored "-Wdeclaration-after-statement"
; struct _assert_struct_1 { char x[(6 <= sizeof(result)) ?
0 : -1]; }; GCC diagnostic pop
;
89 memcpy(mac->ether_addr_octet, &result, ETH_ALEN6);
90
91 /* see eth_random_addr in the kernel */
92 mac->ether_addr_octet[0] &= 0xfe; /* clear multicast bit */
93 mac->ether_addr_octet[0] |= 0x02; /* set local assignment bit (IEEE802) */
94
95 return 0;
96}
97
98static int add_veth(
99 sd_netlink *rtnl,
100 pid_t pid,
101 const char *ifname_host,
102 const struct ether_addr *mac_host,
103 const char *ifname_container,
104 const struct ether_addr *mac_container) {
105
106 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
107 int r;
108
109 assert(rtnl)do { if ((__builtin_expect(!!(!(rtnl)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("rtnl"), "../src/nspawn/nspawn-network.c"
, 109, __PRETTY_FUNCTION__); } while (0)
;
110 assert(ifname_host)do { if ((__builtin_expect(!!(!(ifname_host)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("ifname_host"), "../src/nspawn/nspawn-network.c"
, 110, __PRETTY_FUNCTION__); } while (0)
;
111 assert(mac_host)do { if ((__builtin_expect(!!(!(mac_host)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("mac_host"), "../src/nspawn/nspawn-network.c"
, 111, __PRETTY_FUNCTION__); } while (0)
;
112 assert(ifname_container)do { if ((__builtin_expect(!!(!(ifname_container)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("ifname_container"), "../src/nspawn/nspawn-network.c"
, 112, __PRETTY_FUNCTION__); } while (0)
;
113 assert(mac_container)do { if ((__builtin_expect(!!(!(mac_container)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("mac_container"), "../src/nspawn/nspawn-network.c"
, 113, __PRETTY_FUNCTION__); } while (0)
;
114
115 r = sd_rtnl_message_new_link(rtnl, &m, RTM_NEWLINKRTM_NEWLINK, 0);
116 if (r < 0)
117 return log_error_errno(r, "Failed to allocate netlink message: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 117, __func__, "Failed to allocate netlink message: %m"
) : -abs(_e); })
;
118
119 r = sd_netlink_message_append_string(m, IFLA_IFNAME, ifname_host);
120 if (r < 0)
121 return log_error_errno(r, "Failed to add netlink interface name: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 121, __func__, "Failed to add netlink interface name: %m"
) : -abs(_e); })
;
122
123 r = sd_netlink_message_append_ether_addr(m, IFLA_ADDRESS, mac_host);
124 if (r < 0)
125 return log_error_errno(r, "Failed to add netlink MAC address: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 125, __func__, "Failed to add netlink MAC address: %m"
) : -abs(_e); })
;
126
127 r = sd_netlink_message_open_container(m, IFLA_LINKINFOIFLA_LINKINFO);
128 if (r < 0)
129 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 129, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
130
131 r = sd_netlink_message_open_container_union(m, IFLA_INFO_DATA, "veth");
132 if (r < 0)
133 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 133, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
134
135 r = sd_netlink_message_open_container(m, VETH_INFO_PEER);
136 if (r < 0)
137 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 137, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
138
139 r = sd_netlink_message_append_string(m, IFLA_IFNAME, ifname_container);
140 if (r < 0)
141 return log_error_errno(r, "Failed to add netlink interface name: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 141, __func__, "Failed to add netlink interface name: %m"
) : -abs(_e); })
;
142
143 r = sd_netlink_message_append_ether_addr(m, IFLA_ADDRESS, mac_container);
144 if (r < 0)
145 return log_error_errno(r, "Failed to add netlink MAC address: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 145, __func__, "Failed to add netlink MAC address: %m"
) : -abs(_e); })
;
146
147 r = sd_netlink_message_append_u32(m, IFLA_NET_NS_PID, pid);
148 if (r < 0)
149 return log_error_errno(r, "Failed to add netlink namespace field: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 149, __func__, "Failed to add netlink namespace field: %m"
) : -abs(_e); })
;
150
151 r = sd_netlink_message_close_container(m);
152 if (r < 0)
153 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 153, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
154
155 r = sd_netlink_message_close_container(m);
156 if (r < 0)
157 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 157, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
158
159 r = sd_netlink_message_close_container(m);
160 if (r < 0)
161 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 161, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
162
163 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
164 if (r < 0)
165 return log_error_errno(r, "Failed to add new veth interfaces (%s:%s): %m", ifname_host, ifname_container)({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 165, __func__, "Failed to add new veth interfaces (%s:%s): %m"
, ifname_host, ifname_container) : -abs(_e); })
;
166
167 return 0;
168}
169
170int setup_veth(const char *machine_name,
171 pid_t pid,
172 char iface_name[IFNAMSIZ16],
173 bool_Bool bridge) {
174
175 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
176 struct ether_addr mac_host, mac_container;
177 int r, i;
178
179 assert(machine_name)do { if ((__builtin_expect(!!(!(machine_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("machine_name"), "../src/nspawn/nspawn-network.c"
, 179, __PRETTY_FUNCTION__); } while (0)
;
180 assert(pid > 0)do { if ((__builtin_expect(!!(!(pid > 0)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("pid > 0"), "../src/nspawn/nspawn-network.c"
, 180, __PRETTY_FUNCTION__); } while (0)
;
181 assert(iface_name)do { if ((__builtin_expect(!!(!(iface_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("iface_name"), "../src/nspawn/nspawn-network.c"
, 181, __PRETTY_FUNCTION__); } while (0)
;
182
183 /* Use two different interface name prefixes depending whether
184 * we are in bridge mode or not. */
185 snprintf(iface_name, IFNAMSIZ16 - 1, "%s-%s",
186 bridge ? "vb" : "ve", machine_name);
187
188 r = generate_mac(machine_name, &mac_container, CONTAINER_HASH_KEY((const sd_id128_t) { .bytes = { 0xc3, 0xc4, 0xf9, 0x19, 0xb5
, 0x57, 0xb2, 0x1c, 0xe6, 0xcf, 0x14, 0x27, 0x03, 0x9c, 0xee,
0xa2 }})
, 0);
189 if (r < 0)
190 return log_error_errno(r, "Failed to generate predictable MAC address for container side: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 190, __func__, "Failed to generate predictable MAC address for container side: %m"
) : -abs(_e); })
;
191
192 r = generate_mac(machine_name, &mac_host, HOST_HASH_KEY((const sd_id128_t) { .bytes = { 0x1a, 0x37, 0x6f, 0xc7, 0x46
, 0xec, 0x45, 0x0b, 0xad, 0xa3, 0xd5, 0x31, 0x06, 0x60, 0x5d,
0xb1 }})
, 0);
193 if (r < 0)
194 return log_error_errno(r, "Failed to generate predictable MAC address for host side: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 194, __func__, "Failed to generate predictable MAC address for host side: %m"
) : -abs(_e); })
;
195
196 r = sd_netlink_open(&rtnl);
197 if (r < 0)
198 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 198, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
199
200 r = add_veth(rtnl, pid, iface_name, &mac_host, "host0", &mac_container);
201 if (r < 0)
202 return r;
203
204 i = (int) if_nametoindex(iface_name);
205 if (i <= 0)
206 return log_error_errno(errno, "Failed to resolve interface %s: %m", iface_name)({ int _level = ((3)), _e = (((*__errno_location ()))), _realm
= (LOG_REALM_SYSTEMD); (log_get_max_level_realm(_realm) >=
((_level) & 0x07)) ? log_internal_realm(((_realm) <<
10 | (_level)), _e, "../src/nspawn/nspawn-network.c", 206, __func__
, "Failed to resolve interface %s: %m", iface_name) : -abs(_e
); })
;
207
208 return i;
209}
210
211int setup_veth_extra(
212 const char *machine_name,
213 pid_t pid,
214 char **pairs) {
215
216 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
217 uint64_t idx = 0;
218 char **a, **b;
219 int r;
220
221 assert(machine_name)do { if ((__builtin_expect(!!(!(machine_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("machine_name"), "../src/nspawn/nspawn-network.c"
, 221, __PRETTY_FUNCTION__); } while (0)
;
222 assert(pid > 0)do { if ((__builtin_expect(!!(!(pid > 0)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("pid > 0"), "../src/nspawn/nspawn-network.c"
, 222, __PRETTY_FUNCTION__); } while (0)
;
223
224 if (strv_isempty(pairs))
225 return 0;
226
227 r = sd_netlink_open(&rtnl);
228 if (r < 0)
229 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 229, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
230
231 STRV_FOREACH_PAIR(a, b, pairs)for ((a) = (pairs), (b) = (a+1); (a) && *(a) &&
*(b); (a) += 2, (b) = (a + 1))
{
232 struct ether_addr mac_host, mac_container;
233
234 r = generate_mac(machine_name, &mac_container, VETH_EXTRA_CONTAINER_HASH_KEY((const sd_id128_t) { .bytes = { 0xaf, 0x50, 0x17, 0x61, 0xce
, 0xf9, 0x4d, 0x35, 0x84, 0x0d, 0x2b, 0x20, 0x54, 0xbe, 0xce,
0x59 }})
, idx);
235 if (r < 0)
236 return log_error_errno(r, "Failed to generate predictable MAC address for container side of extra veth link: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 236, __func__, "Failed to generate predictable MAC address for container side of extra veth link: %m"
) : -abs(_e); })
;
237
238 r = generate_mac(machine_name, &mac_host, VETH_EXTRA_HOST_HASH_KEY((const sd_id128_t) { .bytes = { 0x48, 0xc7, 0xf6, 0xb7, 0xea
, 0x9d, 0x4c, 0x9e, 0xb7, 0x28, 0xd4, 0xde, 0x91, 0xd5, 0xbf,
0x66 }})
, idx);
239 if (r < 0)
240 return log_error_errno(r, "Failed to generate predictable MAC address for container side of extra veth link: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 240, __func__, "Failed to generate predictable MAC address for container side of extra veth link: %m"
) : -abs(_e); })
;
241
242 r = add_veth(rtnl, pid, *a, &mac_host, *b, &mac_container);
243 if (r < 0)
244 return r;
245
246 idx++;
247 }
248
249 return 0;
250}
251
252static int join_bridge(sd_netlink *rtnl, const char *veth_name, const char *bridge_name) {
253 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
254 int r, bridge_ifi;
255
256 assert(rtnl)do { if ((__builtin_expect(!!(!(rtnl)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("rtnl"), "../src/nspawn/nspawn-network.c"
, 256, __PRETTY_FUNCTION__); } while (0)
;
257 assert(veth_name)do { if ((__builtin_expect(!!(!(veth_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("veth_name"), "../src/nspawn/nspawn-network.c"
, 257, __PRETTY_FUNCTION__); } while (0)
;
258 assert(bridge_name)do { if ((__builtin_expect(!!(!(bridge_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("bridge_name"), "../src/nspawn/nspawn-network.c"
, 258, __PRETTY_FUNCTION__); } while (0)
;
259
260 bridge_ifi = (int) if_nametoindex(bridge_name);
261 if (bridge_ifi <= 0)
262 return -errno(*__errno_location ());
263
264 r = sd_rtnl_message_new_link(rtnl, &m, RTM_SETLINKRTM_SETLINK, 0);
265 if (r < 0)
266 return r;
267
268 r = sd_rtnl_message_link_set_flags(m, IFF_UPIFF_UP, IFF_UPIFF_UP);
269 if (r < 0)
270 return r;
271
272 r = sd_netlink_message_append_string(m, IFLA_IFNAME, veth_name);
273 if (r < 0)
274 return r;
275
276 r = sd_netlink_message_append_u32(m, IFLA_MASTERIFLA_MASTER, bridge_ifi);
277 if (r < 0)
278 return r;
279
280 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
281 if (r < 0)
282 return r;
283
284 return bridge_ifi;
285}
286
287static int create_bridge(sd_netlink *rtnl, const char *bridge_name) {
288 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
289 int r;
290
291 r = sd_rtnl_message_new_link(rtnl, &m, RTM_NEWLINKRTM_NEWLINK, 0);
292 if (r < 0)
293 return r;
294
295 r = sd_netlink_message_append_string(m, IFLA_IFNAME, bridge_name);
296 if (r < 0)
297 return r;
298
299 r = sd_netlink_message_open_container(m, IFLA_LINKINFOIFLA_LINKINFO);
300 if (r < 0)
301 return r;
302
303 r = sd_netlink_message_open_container_union(m, IFLA_INFO_DATA, "bridge");
304 if (r < 0)
305 return r;
306
307 r = sd_netlink_message_close_container(m);
308 if (r < 0)
309 return r;
310
311 r = sd_netlink_message_close_container(m);
312 if (r < 0)
313 return r;
314
315 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
316 if (r < 0)
317 return r;
318
319 return 0;
320}
321
322int setup_bridge(const char *veth_name, const char *bridge_name, bool_Bool create) {
323 _cleanup_(release_lock_file)__attribute__((cleanup(release_lock_file))) LockFile bridge_lock = LOCK_FILE_INIT{ .fd = -1, .path = ((void*)0) };
324 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
325 int r, bridge_ifi;
326 unsigned n = 0;
327
328 assert(veth_name)do { if ((__builtin_expect(!!(!(veth_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("veth_name"), "../src/nspawn/nspawn-network.c"
, 328, __PRETTY_FUNCTION__); } while (0)
;
329 assert(bridge_name)do { if ((__builtin_expect(!!(!(bridge_name)),0))) log_assert_failed_realm
(LOG_REALM_SYSTEMD, ("bridge_name"), "../src/nspawn/nspawn-network.c"
, 329, __PRETTY_FUNCTION__); } while (0)
;
330
331 r = sd_netlink_open(&rtnl);
332 if (r < 0)
333 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 333, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
334
335 if (create) {
336 /* We take a system-wide lock here, so that we can safely check whether there's still a member in the
337 * bridge before removing it, without risking interference from other nspawn instances. */
338
339 r = make_lock_file("/run/systemd/nspawn-network-zone", LOCK_EX2, &bridge_lock);
340 if (r < 0)
341 return log_error_errno(r, "Failed to take network zone lock: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 341, __func__, "Failed to take network zone lock: %m"
) : -abs(_e); })
;
342 }
343
344 for (;;) {
345 bridge_ifi = join_bridge(rtnl, veth_name, bridge_name);
346 if (bridge_ifi >= 0)
347 return bridge_ifi;
348 if (bridge_ifi != -ENODEV19 || !create || n > 10)
349 return log_error_errno(bridge_ifi, "Failed to add interface %s to bridge %s: %m", veth_name, bridge_name)({ int _level = ((3)), _e = ((bridge_ifi)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 349, __func__, "Failed to add interface %s to bridge %s: %m"
, veth_name, bridge_name) : -abs(_e); })
;
350
351 /* Count attempts, so that we don't enter an endless loop here. */
352 n++;
353
354 /* The bridge doesn't exist yet. Let's create it */
355 r = create_bridge(rtnl, bridge_name);
356 if (r < 0)
357 return log_error_errno(r, "Failed to create bridge interface %s: %m", bridge_name)({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 357, __func__, "Failed to create bridge interface %s: %m"
, bridge_name) : -abs(_e); })
;
358
359 /* Try again, now that the bridge exists */
360 }
361}
362
363int remove_bridge(const char *bridge_name) {
364 _cleanup_(release_lock_file)__attribute__((cleanup(release_lock_file))) LockFile bridge_lock = LOCK_FILE_INIT{ .fd = -1, .path = ((void*)0) };
365 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
366 const char *path;
367 int r;
368
369 /* Removes the specified bridge, but only if it is currently empty */
370
371 if (isempty(bridge_name))
372 return 0;
373
374 r = make_lock_file("/run/systemd/nspawn-network-zone", LOCK_EX2, &bridge_lock);
375 if (r < 0)
376 return log_error_errno(r, "Failed to take network zone lock: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 376, __func__, "Failed to take network zone lock: %m"
) : -abs(_e); })
;
377
378 path = strjoina("/sys/class/net/", bridge_name, "/brif")({ const char *_appendees_[] = { "/sys/class/net/", bridge_name
, "/brif" }; char *_d_, *_p_; size_t _len_ = 0; size_t _i_; for
(_i_ = 0; _i_ < __extension__ (__builtin_choose_expr( !__builtin_types_compatible_p
(typeof(_appendees_), typeof(&*(_appendees_))), sizeof(_appendees_
)/sizeof((_appendees_)[0]), ((void)0))) && _appendees_
[_i_]; _i_++) _len_ += strlen(_appendees_[_i_]); _p_ = _d_ = __builtin_alloca
(_len_ + 1); for (_i_ = 0; _i_ < __extension__ (__builtin_choose_expr
( !__builtin_types_compatible_p(typeof(_appendees_), typeof(&
*(_appendees_))), sizeof(_appendees_)/sizeof((_appendees_)[0]
), ((void)0))) && _appendees_[_i_]; _i_++) _p_ = stpcpy
(_p_, _appendees_[_i_]); *_p_ = 0; _d_; })
;
379
380 r = dir_is_empty(path);
381 if (r == -ENOENT2) /* Already gone? */
382 return 0;
383 if (r < 0)
384 return log_error_errno(r, "Can't detect if bridge %s is empty: %m", bridge_name)({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 384, __func__, "Can't detect if bridge %s is empty: %m"
, bridge_name) : -abs(_e); })
;
385 if (r == 0) /* Still populated, leave it around */
386 return 0;
387
388 r = sd_netlink_open(&rtnl);
389 if (r < 0)
390 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 390, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
391
392 return remove_one_link(rtnl, bridge_name);
393}
394
395static int parse_interface(struct udev *udev, const char *name) {
396 _cleanup_(udev_device_unrefp)__attribute__((cleanup(udev_device_unrefp))) struct udev_device *d = NULL((void*)0);
397 char ifi_str[2 + DECIMAL_STR_MAX(int)(2+(sizeof(int) <= 1 ? 3 : sizeof(int) <= 2 ? 5 : sizeof
(int) <= 4 ? 10 : sizeof(int) <= 8 ? 20 : sizeof(int[-2
*(sizeof(int) > 8)])))
];
398 int ifi;
399
400 ifi = (int) if_nametoindex(name);
401 if (ifi <= 0)
402 return log_error_errno(errno, "Failed to resolve interface %s: %m", name)({ int _level = ((3)), _e = (((*__errno_location ()))), _realm
= (LOG_REALM_SYSTEMD); (log_get_max_level_realm(_realm) >=
((_level) & 0x07)) ? log_internal_realm(((_realm) <<
10 | (_level)), _e, "../src/nspawn/nspawn-network.c", 402, __func__
, "Failed to resolve interface %s: %m", name) : -abs(_e); })
;
403
404 sprintf(ifi_str, "n%i", ifi);
405 d = udev_device_new_from_device_id(udev, ifi_str);
406 if (!d)
407 return log_error_errno(errno, "Failed to get udev device for interface %s: %m", name)({ int _level = ((3)), _e = (((*__errno_location ()))), _realm
= (LOG_REALM_SYSTEMD); (log_get_max_level_realm(_realm) >=
((_level) & 0x07)) ? log_internal_realm(((_realm) <<
10 | (_level)), _e, "../src/nspawn/nspawn-network.c", 407, __func__
, "Failed to get udev device for interface %s: %m", name) : -
abs(_e); })
;
408
409 if (udev_device_get_is_initialized(d) <= 0) {
410 log_error("Network interface %s is not initialized yet.", name)({ int _level = (((3))), _e = ((0)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 410, __func__, "Network interface %s is not initialized yet."
, name) : -abs(_e); })
;
411 return -EBUSY16;
412 }
413
414 return ifi;
415}
416
417int move_network_interfaces(pid_t pid, char **ifaces) {
418 _cleanup_(udev_unrefp)__attribute__((cleanup(udev_unrefp))) struct udev *udev = NULL((void*)0);
419 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
420 char **i;
421 int r;
422
423 if (strv_isempty(ifaces))
424 return 0;
425
426 r = sd_netlink_open(&rtnl);
427 if (r < 0)
428 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 428, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
429
430 udev = udev_new();
431 if (!udev) {
432 log_error("Failed to connect to udev.")({ int _level = (((3))), _e = ((0)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 432, __func__, "Failed to connect to udev."
) : -abs(_e); })
;
433 return -ENOMEM12;
434 }
435
436 STRV_FOREACH(i, ifaces)for ((i) = (ifaces); (i) && *(i); (i)++) {
437 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
438 int ifi;
439
440 ifi = parse_interface(udev, *i);
441 if (ifi < 0)
442 return ifi;
443
444 r = sd_rtnl_message_new_link(rtnl, &m, RTM_SETLINKRTM_SETLINK, ifi);
445 if (r < 0)
446 return log_error_errno(r, "Failed to allocate netlink message: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 446, __func__, "Failed to allocate netlink message: %m"
) : -abs(_e); })
;
447
448 r = sd_netlink_message_append_u32(m, IFLA_NET_NS_PID, pid);
449 if (r < 0)
450 return log_error_errno(r, "Failed to append namespace PID to netlink message: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 450, __func__, "Failed to append namespace PID to netlink message: %m"
) : -abs(_e); })
;
451
452 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
453 if (r < 0)
454 return log_error_errno(r, "Failed to move interface %s to namespace: %m", *i)({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 454, __func__, "Failed to move interface %s to namespace: %m"
, *i) : -abs(_e); })
;
455 }
456
457 return 0;
458}
459
460int setup_macvlan(const char *machine_name, pid_t pid, char **ifaces) {
461 _cleanup_(udev_unrefp)__attribute__((cleanup(udev_unrefp))) struct udev *udev = NULL((void*)0);
462 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
463 unsigned idx = 0;
464 char **i;
465 int r;
466
467 if (strv_isempty(ifaces))
468 return 0;
469
470 r = sd_netlink_open(&rtnl);
471 if (r < 0)
472 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 472, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
473
474 udev = udev_new();
475 if (!udev) {
476 log_error("Failed to connect to udev.")({ int _level = (((3))), _e = ((0)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 476, __func__, "Failed to connect to udev."
) : -abs(_e); })
;
477 return -ENOMEM12;
478 }
479
480 STRV_FOREACH(i, ifaces)for ((i) = (ifaces); (i) && *(i); (i)++) {
481 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
482 _cleanup_free___attribute__((cleanup(freep))) char *n = NULL((void*)0);
483 struct ether_addr mac;
484 int ifi;
485
486 ifi = parse_interface(udev, *i);
487 if (ifi < 0)
488 return ifi;
489
490 r = generate_mac(machine_name, &mac, MACVLAN_HASH_KEY((const sd_id128_t) { .bytes = { 0x00, 0x13, 0x6d, 0xbc, 0x66
, 0x83, 0x44, 0x81, 0xbb, 0x0c, 0xf9, 0x51, 0x1f, 0x24, 0xa6,
0x6f }})
, idx++);
491 if (r < 0)
492 return log_error_errno(r, "Failed to create MACVLAN MAC address: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 492, __func__, "Failed to create MACVLAN MAC address: %m"
) : -abs(_e); })
;
493
494 r = sd_rtnl_message_new_link(rtnl, &m, RTM_NEWLINKRTM_NEWLINK, 0);
495 if (r < 0)
496 return log_error_errno(r, "Failed to allocate netlink message: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 496, __func__, "Failed to allocate netlink message: %m"
) : -abs(_e); })
;
497
498 r = sd_netlink_message_append_u32(m, IFLA_LINK, ifi);
499 if (r < 0)
500 return log_error_errno(r, "Failed to add netlink interface index: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 500, __func__, "Failed to add netlink interface index: %m"
) : -abs(_e); })
;
501
502 n = strappend("mv-", *i);
503 if (!n)
504 return log_oom()log_oom_internal(LOG_REALM_SYSTEMD, "../src/nspawn/nspawn-network.c"
, 504, __func__)
;
505
506 strshorten(n, IFNAMSIZ16-1);
507
508 r = sd_netlink_message_append_string(m, IFLA_IFNAME, n);
509 if (r < 0)
510 return log_error_errno(r, "Failed to add netlink interface name: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 510, __func__, "Failed to add netlink interface name: %m"
) : -abs(_e); })
;
511
512 r = sd_netlink_message_append_ether_addr(m, IFLA_ADDRESS, &mac);
513 if (r < 0)
514 return log_error_errno(r, "Failed to add netlink MAC address: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 514, __func__, "Failed to add netlink MAC address: %m"
) : -abs(_e); })
;
515
516 r = sd_netlink_message_append_u32(m, IFLA_NET_NS_PID, pid);
517 if (r < 0)
518 return log_error_errno(r, "Failed to add netlink namespace field: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 518, __func__, "Failed to add netlink namespace field: %m"
) : -abs(_e); })
;
519
520 r = sd_netlink_message_open_container(m, IFLA_LINKINFOIFLA_LINKINFO);
521 if (r < 0)
522 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 522, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
523
524 r = sd_netlink_message_open_container_union(m, IFLA_INFO_DATA, "macvlan");
525 if (r < 0)
526 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 526, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
527
528 r = sd_netlink_message_append_u32(m, IFLA_MACVLAN_MODE, MACVLAN_MODE_BRIDGE);
529 if (r < 0)
530 return log_error_errno(r, "Failed to append macvlan mode: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 530, __func__, "Failed to append macvlan mode: %m"
) : -abs(_e); })
;
531
532 r = sd_netlink_message_close_container(m);
533 if (r < 0)
534 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 534, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
535
536 r = sd_netlink_message_close_container(m);
537 if (r < 0)
538 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 538, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
539
540 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
541 if (r < 0)
542 return log_error_errno(r, "Failed to add new macvlan interfaces: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 542, __func__, "Failed to add new macvlan interfaces: %m"
) : -abs(_e); })
;
543 }
544
545 return 0;
546}
547
548int setup_ipvlan(const char *machine_name, pid_t pid, char **ifaces) {
549 _cleanup_(udev_unrefp)__attribute__((cleanup(udev_unrefp))) struct udev *udev = NULL((void*)0);
550 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
551 char **i;
552 int r;
553
554 if (strv_isempty(ifaces))
555 return 0;
556
557 r = sd_netlink_open(&rtnl);
558 if (r < 0)
559 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 559, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
560
561 udev = udev_new();
562 if (!udev) {
563 log_error("Failed to connect to udev.")({ int _level = (((3))), _e = ((0)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 563, __func__, "Failed to connect to udev."
) : -abs(_e); })
;
564 return -ENOMEM12;
565 }
566
567 STRV_FOREACH(i, ifaces)for ((i) = (ifaces); (i) && *(i); (i)++) {
568 _cleanup_(sd_netlink_message_unrefp)__attribute__((cleanup(sd_netlink_message_unrefp))) sd_netlink_message *m = NULL((void*)0);
569 _cleanup_free___attribute__((cleanup(freep))) char *n = NULL((void*)0);
570 int ifi;
571
572 ifi = parse_interface(udev, *i);
573 if (ifi < 0)
574 return ifi;
575
576 r = sd_rtnl_message_new_link(rtnl, &m, RTM_NEWLINKRTM_NEWLINK, 0);
577 if (r < 0)
578 return log_error_errno(r, "Failed to allocate netlink message: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 578, __func__, "Failed to allocate netlink message: %m"
) : -abs(_e); })
;
579
580 r = sd_netlink_message_append_u32(m, IFLA_LINK, ifi);
581 if (r < 0)
582 return log_error_errno(r, "Failed to add netlink interface index: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 582, __func__, "Failed to add netlink interface index: %m"
) : -abs(_e); })
;
583
584 n = strappend("iv-", *i);
585 if (!n)
586 return log_oom()log_oom_internal(LOG_REALM_SYSTEMD, "../src/nspawn/nspawn-network.c"
, 586, __func__)
;
587
588 strshorten(n, IFNAMSIZ16-1);
589
590 r = sd_netlink_message_append_string(m, IFLA_IFNAME, n);
591 if (r < 0)
592 return log_error_errno(r, "Failed to add netlink interface name: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 592, __func__, "Failed to add netlink interface name: %m"
) : -abs(_e); })
;
593
594 r = sd_netlink_message_append_u32(m, IFLA_NET_NS_PID, pid);
595 if (r < 0)
596 return log_error_errno(r, "Failed to add netlink namespace field: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 596, __func__, "Failed to add netlink namespace field: %m"
) : -abs(_e); })
;
597
598 r = sd_netlink_message_open_container(m, IFLA_LINKINFOIFLA_LINKINFO);
599 if (r < 0)
600 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 600, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
601
602 r = sd_netlink_message_open_container_union(m, IFLA_INFO_DATA, "ipvlan");
603 if (r < 0)
604 return log_error_errno(r, "Failed to open netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 604, __func__, "Failed to open netlink container: %m"
) : -abs(_e); })
;
605
606 r = sd_netlink_message_append_u16(m, IFLA_IPVLAN_MODE, IPVLAN_MODE_L2);
607 if (r < 0)
608 return log_error_errno(r, "Failed to add ipvlan mode: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 608, __func__, "Failed to add ipvlan mode: %m"
) : -abs(_e); })
;
609
610 r = sd_netlink_message_close_container(m);
611 if (r < 0)
612 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 612, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
613
614 r = sd_netlink_message_close_container(m);
615 if (r < 0)
616 return log_error_errno(r, "Failed to close netlink container: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 616, __func__, "Failed to close netlink container: %m"
) : -abs(_e); })
;
617
618 r = sd_netlink_call(rtnl, m, 0, NULL((void*)0));
619 if (r < 0)
620 return log_error_errno(r, "Failed to add new ipvlan interfaces: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 620, __func__, "Failed to add new ipvlan interfaces: %m"
) : -abs(_e); })
;
621 }
622
623 return 0;
624}
625
626int veth_extra_parse(char ***l, const char *p) {
627 _cleanup_free___attribute__((cleanup(freep))) char *a = NULL((void*)0), *b = NULL((void*)0);
628 int r;
629
630 r = extract_first_word(&p, &a, ":", EXTRACT_DONT_COALESCE_SEPARATORS);
631 if (r < 0)
1
Assuming 'r' is >= 0
2
Taking false branch
632 return r;
633 if (r == 0 || !ifname_valid(a))
3
Assuming 'r' is not equal to 0
4
Assuming the condition is false
5
Taking false branch
634 return -EINVAL22;
635
636 r = extract_first_word(&p, &b, ":", EXTRACT_DONT_COALESCE_SEPARATORS);
637 if (r < 0)
6
Assuming 'r' is >= 0
7
Taking false branch
638 return r;
639 if (r == 0 || !ifname_valid(b)) {
8
Assuming 'r' is equal to 0
640 free(b);
641 b = strdup(a);
9
Memory is allocated
642 if (!b)
10
Assuming 'b' is non-null
11
Taking false branch
643 return -ENOMEM12;
644 }
645
646 if (p)
12
Assuming 'p' is non-null
13
Taking true branch
647 return -EINVAL22;
14
Potential leak of memory pointed to by 'b'
648
649 r = strv_push_pair(l, a, b);
650 if (r < 0)
651 return -ENOMEM12;
652
653 a = b = NULL((void*)0);
654 return 0;
655}
656
657int remove_veth_links(const char *primary, char **pairs) {
658 _cleanup_(sd_netlink_unrefp)__attribute__((cleanup(sd_netlink_unrefp))) sd_netlink *rtnl = NULL((void*)0);
659 char **a, **b;
660 int r;
661
662 /* In some cases the kernel might pin the veth links between host and container even after the namespace
663 * died. Hence, let's better remove them explicitly too. */
664
665 if (isempty(primary) && strv_isempty(pairs))
666 return 0;
667
668 r = sd_netlink_open(&rtnl);
669 if (r < 0)
670 return log_error_errno(r, "Failed to connect to netlink: %m")({ int _level = ((3)), _e = ((r)), _realm = (LOG_REALM_SYSTEMD
); (log_get_max_level_realm(_realm) >= ((_level) & 0x07
)) ? log_internal_realm(((_realm) << 10 | (_level)), _e
, "../src/nspawn/nspawn-network.c", 670, __func__, "Failed to connect to netlink: %m"
) : -abs(_e); })
;
671
672 remove_one_link(rtnl, primary);
673
674 STRV_FOREACH_PAIR(a, b, pairs)for ((a) = (pairs), (b) = (a+1); (a) && *(a) &&
*(b); (a) += 2, (b) = (a + 1))
675 remove_one_link(rtnl, *a);
676
677 return 0;
678}