blob: ef1ff48a27852b4e85d346000c395282cefb2b80 [file] [log] [blame]
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +09001/*
2 * Copyright (C) 2017 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#ifndef NETD_SERVER_NETLINK_UTIL_H
18#define NETD_SERVER_NETLINK_UTIL_H
19
20#include <functional>
Lorenzo Colittif3e299a2017-02-14 17:24:28 +090021#include <linux/netlink.h>
22#include <linux/rtnetlink.h>
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090023
24#include "NetdConstants.h"
25
26namespace android {
27namespace net {
28
29const sockaddr_nl KERNEL_NLADDR = {AF_NETLINK, 0, 0, 0};
30
Lorenzo Colittif3e299a2017-02-14 17:24:28 +090031const uint16_t NETLINK_REQUEST_FLAGS = NLM_F_REQUEST | NLM_F_ACK;
Lorenzo Colitti5c437992017-11-28 01:26:02 +090032const uint16_t NETLINK_ROUTE_CREATE_FLAGS = NETLINK_REQUEST_FLAGS | NLM_F_CREATE | NLM_F_EXCL;
33// Don't create rules with NLM_F_EXCL, because operations such as changing network permissions rely
34// on make-before-break. The kernel did not complain about duplicate rules until ~4.9, at which
35// point it started returning EEXIST. See for example b/69607866 . We can't just ignore the EEXIST
36// because if we hit it, the rule was not created, but we will think it was, and we'll then trip up
37// trying to delete it.
38const uint16_t NETLINK_RULE_CREATE_FLAGS = NETLINK_REQUEST_FLAGS | NLM_F_CREATE;
Lorenzo Colittif3e299a2017-02-14 17:24:28 +090039const uint16_t NETLINK_DUMP_FLAGS = NLM_F_REQUEST | NLM_F_DUMP;
40
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090041// Generic code for processing netlink dumps.
42const int kNetlinkDumpBufferSize = 8192;
43typedef std::function<void(nlmsghdr *)> NetlinkDumpCallback;
Lorenzo Colittif3e299a2017-02-14 17:24:28 +090044typedef std::function<bool(nlmsghdr *)> NetlinkDumpFilter;
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090045
46// Opens an RTNetlink socket and connects it to the kernel.
Nathan Harold1a371532017-01-30 12:30:48 -080047WARN_UNUSED_RESULT int openNetlinkSocket(int protocol);
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090048
49// Receives a netlink ACK. Returns 0 if the command succeeded or negative errno if the command
50// failed or receiving the ACK failed.
51WARN_UNUSED_RESULT int recvNetlinkAck(int sock);
52
53// Sends a netlink request and possibly expects an ACK. The first element of iov should be null and
54// will be set to the netlink message headerheader. The subsequent elements are the contents of the
55// request.
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090056
57// Disable optimizations in ASan build.
58// ASan reports an out-of-bounds 32-bit(!) access in the first loop of the
59// function (over iov[]).
60#ifdef __clang__
61#if __has_feature(address_sanitizer)
62__attribute__((optnone))
63#endif
64#endif
65WARN_UNUSED_RESULT int sendNetlinkRequest(uint16_t action, uint16_t flags, iovec* iov, int iovlen,
Lorenzo Colittif3e299a2017-02-14 17:24:28 +090066 const NetlinkDumpCallback *callback);
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090067
68// Processes a netlink dump, passing every message to the specified |callback|.
69WARN_UNUSED_RESULT int processNetlinkDump(int sock, const NetlinkDumpCallback& callback);
70
Lorenzo Colittif3e299a2017-02-14 17:24:28 +090071// Flushes netlink objects that take an rtmsg structure (FIB rules, routes...). |getAction| and
72// |deleteAction| specify the netlink message types, e.g., RTM_GETRULE and RTM_DELRULE.
73// |shouldDelete| specifies whether a given object should be deleted or not. |what| is a
74// human-readable name for the objects being flushed, e.g. "rules".
75WARN_UNUSED_RESULT int rtNetlinkFlush(uint16_t getAction, uint16_t deleteAction,
76 const char *what, const NetlinkDumpFilter& shouldDelete);
77
78// Returns the value of the specific __u32 attribute, or 0 if the attribute was not present.
79uint32_t getRtmU32Attribute(const nlmsghdr *nlh, int attribute);
80
Lorenzo Colitti1ef549d2017-02-13 18:32:09 +090081} // namespace net
82} // namespace android
83
84#endif // NETD_SERVER_NETLINK_UTIL_H