blob: 28b814f212524de3f8a31407ab5f34e8fe157b7d [file] [log] [blame]
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -07001/*
2 * Copyright (C) 2012 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
Sasha Levitskiy329c3b42012-07-30 16:11:23 -07008 * http://www.apache.org/licenses/LICENSE-2.0
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -07009 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Lorenzo Colitti37f2e372013-04-12 00:44:06 +090017#include <dirent.h>
Dan Albertaa1be2b2015-01-06 09:36:17 -080018#include <errno.h>
Elliott Hughes5f4938f2015-01-28 11:22:38 -080019#include <malloc.h>
Erik Klineb218a872016-07-04 09:57:18 +090020#include <sys/socket.h>
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -070021
Joel Scherpelz31e25992017-03-24 12:40:00 +090022#include <functional>
23
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -070024#define LOG_TAG "InterfaceController"
Elliott Hughesbbd56262015-12-04 15:45:10 -080025#include <android-base/file.h>
Joel Scherpelzde937962017-06-01 13:20:21 +090026#include <android-base/properties.h>
Elliott Hughesbbd56262015-12-04 15:45:10 -080027#include <android-base/stringprintf.h>
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -070028#include <cutils/log.h>
Lorenzo Colitti0ea8ff82014-10-28 00:15:07 +090029#include <logwrap/logwrap.h>
Erik Klinec296f092016-08-02 15:22:53 +090030#include <netutils/ifc.h>
Lorenzo Colitti70afde62013-03-04 17:58:40 +090031
Joel Scherpelzde937962017-06-01 13:20:21 +090032#include <android/net/INetd.h>
33#include <netdutils/Misc.h>
34#include <netdutils/Slice.h>
35#include <netdutils/Syscalls.h>
36
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -070037#include "InterfaceController.h"
Sreeram Ramachandrana4811802014-04-10 12:10:24 -070038#include "RouteController.h"
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -070039
Erik Klineb218a872016-07-04 09:57:18 +090040using android::base::ReadFileToString;
Joel Scherpelzde937962017-06-01 13:20:21 +090041using android::base::StringPrintf;
Dan Albert5407e142015-03-16 10:05:59 -070042using android::base::WriteStringToFile;
Joel Scherpelzde937962017-06-01 13:20:21 +090043using android::net::INetd;
Lorenzo Colitti7035f222017-02-13 18:29:00 +090044using android::net::RouteController;
Joel Scherpelzde937962017-06-01 13:20:21 +090045using android::netdutils::Status;
46using android::netdutils::StatusOr;
47using android::netdutils::makeSlice;
48using android::netdutils::sSyscalls;
49using android::netdutils::status::ok;
50using android::netdutils::statusFromErrno;
51using android::netdutils::toString;
Dan Albert5407e142015-03-16 10:05:59 -070052
Erik Klinee1da4842015-05-12 15:56:06 +090053namespace {
54
Lorenzo Colitti37f2e372013-04-12 00:44:06 +090055const char ipv6_proc_path[] = "/proc/sys/net/ipv6/conf";
56
Erik Kline145fd252015-05-12 15:58:49 +090057const char ipv4_neigh_conf_dir[] = "/proc/sys/net/ipv4/neigh";
58
59const char ipv6_neigh_conf_dir[] = "/proc/sys/net/ipv6/neigh";
60
Erik Klineb218a872016-07-04 09:57:18 +090061const char proc_net_path[] = "/proc/sys/net";
Dmitry Shmidt6d6c0e62013-06-11 16:18:06 -070062const char sys_net_path[] = "/sys/class/net";
63
Joel Scherpelz31e25992017-03-24 12:40:00 +090064constexpr int kRouteInfoMinPrefixLen = 48;
65
66// RFC 7421 prefix length.
67constexpr int kRouteInfoMaxPrefixLen = 64;
68
Joel Scherpelzde937962017-06-01 13:20:21 +090069// Property used to persist RFC 7217 stable secret. Protected by SELinux policy.
70const char kStableSecretProperty[] = "persist.netd.stable_secret";
71
72// RFC 7217 stable secret on linux is formatted as an IPv6 address.
73// This function uses 128 bits of high quality entropy to generate an
74// address for this purpose. This function should be not be called
75// frequently.
76StatusOr<std::string> randomIPv6Address() {
77 in6_addr addr = {};
78 const auto& sys = sSyscalls.get();
79 ASSIGN_OR_RETURN(auto fd, sys.open("/dev/random", O_RDONLY));
80 RETURN_IF_NOT_OK(sys.read(fd, makeSlice(addr)));
81 return toString(addr);
82}
83
Erik Klineb218a872016-07-04 09:57:18 +090084inline bool isNormalPathComponent(const char *component) {
85 return (strcmp(component, ".") != 0) &&
86 (strcmp(component, "..") != 0) &&
87 (strchr(component, '/') == nullptr);
88}
89
90inline bool isAddressFamilyPathComponent(const char *component) {
91 return strcmp(component, "ipv4") == 0 || strcmp(component, "ipv6") == 0;
92}
93
94inline bool isInterfaceName(const char *name) {
95 return isNormalPathComponent(name) &&
96 (strcmp(name, "default") != 0) &&
97 (strcmp(name, "all") != 0);
Erik Klinee1da4842015-05-12 15:56:06 +090098}
99
100int writeValueToPath(
101 const char* dirname, const char* subdirname, const char* basename,
102 const char* value) {
103 std::string path(StringPrintf("%s/%s/%s", dirname, subdirname, basename));
Erik Kline3f957772015-06-03 17:44:24 +0900104 return WriteStringToFile(value, path) ? 0 : -1;
Erik Klinee1da4842015-05-12 15:56:06 +0900105}
106
Joel Scherpelz31e25992017-03-24 12:40:00 +0900107// Run @fn on each interface as well as 'default' in the path @dirname.
108void forEachInterface(const std::string& dirname,
109 std::function<void(const std::string& path, const std::string& iface)> fn) {
110 // Run on default, which controls the behavior of any interfaces that are created in the future.
111 fn(dirname, "default");
112 DIR* dir = opendir(dirname.c_str());
Erik Klinee1da4842015-05-12 15:56:06 +0900113 if (!dir) {
Joel Scherpelz31e25992017-03-24 12:40:00 +0900114 ALOGE("Can't list %s: %s", dirname.c_str(), strerror(errno));
Erik Klinee1da4842015-05-12 15:56:06 +0900115 return;
116 }
Joel Scherpelz31e25992017-03-24 12:40:00 +0900117 while (true) {
118 const dirent *ent = readdir(dir);
119 if (!ent) {
120 break;
121 }
122 if ((ent->d_type != DT_DIR) || !isInterfaceName(ent->d_name)) {
Erik Klinee1da4842015-05-12 15:56:06 +0900123 continue;
124 }
Joel Scherpelz31e25992017-03-24 12:40:00 +0900125 fn(dirname, ent->d_name);
Erik Klinee1da4842015-05-12 15:56:06 +0900126 }
127 closedir(dir);
128}
129
Joel Scherpelz31e25992017-03-24 12:40:00 +0900130void setOnAllInterfaces(const char* dirname, const char* basename, const char* value) {
131 auto fn = [basename, value](const std::string& path, const std::string& iface) {
132 writeValueToPath(path.c_str(), iface.c_str(), basename, value);
133 };
134 forEachInterface(dirname, fn);
135}
136
Erik Kline7adf8d72015-07-28 18:51:01 +0900137void setIPv6UseOutgoingInterfaceAddrsOnly(const char *value) {
138 setOnAllInterfaces(ipv6_proc_path, "use_oif_addrs_only", value);
139}
140
Erik Klineb218a872016-07-04 09:57:18 +0900141std::string getParameterPathname(
142 const char *family, const char *which, const char *interface, const char *parameter) {
143 if (!isAddressFamilyPathComponent(family)) {
144 errno = EAFNOSUPPORT;
145 return "";
146 } else if (!isNormalPathComponent(which) ||
147 !isInterfaceName(interface) ||
148 !isNormalPathComponent(parameter)) {
149 errno = EINVAL;
150 return "";
151 }
152
153 return StringPrintf("%s/%s/%s/%s/%s", proc_net_path, family, which, interface, parameter);
154}
155
Joel Scherpelz31e25992017-03-24 12:40:00 +0900156void setAcceptIPv6RIO(int min, int max) {
157 auto fn = [min, max](const std::string& prefix, const std::string& iface) {
158 int rv = writeValueToPath(prefix.c_str(), iface.c_str(), "accept_ra_rt_info_min_plen",
159 std::to_string(min).c_str());
160 if (rv != 0) {
161 // Only update max_plen if the write to min_plen succeeded. This ordering will prevent
162 // RIOs from being accepted unless both min and max are written successfully.
163 return;
164 }
165 writeValueToPath(prefix.c_str(), iface.c_str(), "accept_ra_rt_info_max_plen",
166 std::to_string(max).c_str());
167 };
168 forEachInterface(ipv6_proc_path, fn);
169}
170
Joel Scherpelzde937962017-06-01 13:20:21 +0900171// Ideally this function would return StatusOr<std::string>, however
172// there is no safe value for dflt that will always differ from the
173// stored property. Bugs code could conceivably end up persisting the
174// reserved value resulting in surprising behavior.
175std::string getProperty(const std::string& key, const std::string& dflt) {
176 return android::base::GetProperty(key, dflt);
177};
178
179Status setProperty(const std::string& key, const std::string& val) {
Lorenzo Colitti516764f2017-07-10 19:13:23 +0900180 // SetProperty does not dependably set errno to a meaningful value. Use our own error code so
181 // callers don't get confused.
Joel Scherpelzde937962017-06-01 13:20:21 +0900182 return android::base::SetProperty(key, val)
183 ? ok
Lorenzo Colitti516764f2017-07-10 19:13:23 +0900184 : statusFromErrno(EREMOTEIO, "SetProperty failed, see libc logs");
Joel Scherpelzde937962017-06-01 13:20:21 +0900185};
186
187
Erik Klinee1da4842015-05-12 15:56:06 +0900188} // namespace
189
Joel Scherpelzde937962017-06-01 13:20:21 +0900190android::netdutils::Status InterfaceController::enableStablePrivacyAddresses(
191 const std::string& iface, GetPropertyFn getProperty, SetPropertyFn setProperty) {
192 const auto& sys = sSyscalls.get();
193 const std::string procTarget = std::string(ipv6_proc_path) + "/" + iface + "/stable_secret";
194 auto procFd = sys.open(procTarget, O_CLOEXEC | O_WRONLY);
195
196 // Devices with old kernels (typically < 4.4) don't support
197 // RFC 7217 stable privacy addresses.
198 if (equalToErrno(procFd, ENOENT)) {
199 return statusFromErrno(EOPNOTSUPP,
200 "Failed to open stable_secret. Assuming unsupported kernel version");
201 }
202
203 // If stable_secret exists but we can't open it, something strange is going on.
204 RETURN_IF_NOT_OK(procFd);
205
206 const char kUninitialized[] = "uninitialized";
207 const auto oldSecret = getProperty(kStableSecretProperty, kUninitialized);
208 std::string secret = oldSecret;
209
210 // Generate a new secret if no persistent property existed.
211 if (oldSecret == kUninitialized) {
212 ASSIGN_OR_RETURN(secret, randomIPv6Address());
213 }
214
215 // Ask the OS to generate SLAAC addresses on iface using secret.
216 RETURN_IF_NOT_OK(sys.write(procFd.value(), makeSlice(secret)));
217
218 // Don't persist an existing secret.
219 if (oldSecret != kUninitialized) {
220 return ok;
221 }
222
223 return setProperty(kStableSecretProperty, secret);
224}
225
Erik Kline2c5aaa12016-06-08 13:24:45 +0900226void InterfaceController::initializeAll() {
227 // Initial IPv6 settings.
228 // By default, accept_ra is set to 1 (accept RAs unless forwarding is on) on all interfaces.
229 // This causes RAs to work or not work based on whether forwarding is on, and causes routes
230 // learned from RAs to go away when forwarding is turned on. Make this behaviour predictable
231 // by always setting accept_ra to 2.
232 setAcceptRA("2");
Lorenzo Colitti37f2e372013-04-12 00:44:06 +0900233
Joel Scherpelz31e25992017-03-24 12:40:00 +0900234 // Accept RIOs with prefix length in the closed interval [48, 64].
235 setAcceptIPv6RIO(kRouteInfoMinPrefixLen, kRouteInfoMaxPrefixLen);
236
Erik Kline2c5aaa12016-06-08 13:24:45 +0900237 setAcceptRARouteTable(-RouteController::ROUTE_TABLE_OFFSET_FROM_INDEX);
Erik Kline59273ed2014-12-08 16:05:28 +0900238
Erik Kline2c5aaa12016-06-08 13:24:45 +0900239 // Enable optimistic DAD for IPv6 addresses on all interfaces.
240 setIPv6OptimisticMode("1");
Erik Kline145fd252015-05-12 15:58:49 +0900241
Erik Kline2c5aaa12016-06-08 13:24:45 +0900242 // Reduce the ARP/ND base reachable time from the default (30sec) to 15sec.
243 setBaseReachableTimeMs(15 * 1000);
Erik Kline7adf8d72015-07-28 18:51:01 +0900244
Erik Kline2c5aaa12016-06-08 13:24:45 +0900245 // When sending traffic via a given interface use only addresses configured
246 // on that interface as possible source addresses.
247 setIPv6UseOutgoingInterfaceAddrsOnly("1");
Dmitry Shmidt2eab1f72012-07-26 16:08:02 -0700248}
Lorenzo Colitti70afde62013-03-04 17:58:40 +0900249
Lorenzo Colitti70afde62013-03-04 17:58:40 +0900250int InterfaceController::setEnableIPv6(const char *interface, const int on) {
Erik Klinee1da4842015-05-12 15:56:06 +0900251 if (!isIfaceName(interface)) {
252 errno = ENOENT;
253 return -1;
254 }
255 // When disable_ipv6 changes from 1 to 0, the kernel starts autoconf.
256 // When disable_ipv6 changes from 0 to 1, the kernel clears all autoconf
257 // addresses and routes and disables IPv6 on the interface.
258 const char *disable_ipv6 = on ? "0" : "1";
259 return writeValueToPath(ipv6_proc_path, interface, "disable_ipv6", disable_ipv6);
Lorenzo Colitti70afde62013-03-04 17:58:40 +0900260}
261
Joel Scherpelzde937962017-06-01 13:20:21 +0900262// Changes to addrGenMode will not fully take effect until the next
263// time disable_ipv6 transitions from 1 to 0.
264Status InterfaceController::setIPv6AddrGenMode(const std::string& interface, int mode) {
265 if (!isIfaceName(interface)) {
266 return statusFromErrno(ENOENT, "invalid iface name: " + interface);
267 }
268
269 switch (mode) {
270 case INetd::IPV6_ADDR_GEN_MODE_EUI64:
271 // Ignore return value. If /proc/.../stable_secret is
272 // missing we're probably in EUI64 mode already.
273 writeValueToPath(ipv6_proc_path, interface.c_str(), "stable_secret", "");
274 break;
275 case INetd::IPV6_ADDR_GEN_MODE_STABLE_PRIVACY: {
276 return enableStablePrivacyAddresses(interface, getProperty, setProperty);
277 }
278 case INetd::IPV6_ADDR_GEN_MODE_NONE:
279 case INetd::IPV6_ADDR_GEN_MODE_RANDOM:
280 default:
281 return statusFromErrno(EOPNOTSUPP, "unsupported addrGenMode");
282 }
283
284 return ok;
285}
286
Erik Kline2c5aaa12016-06-08 13:24:45 +0900287int InterfaceController::setAcceptIPv6Ra(const char *interface, const int on) {
288 if (!isIfaceName(interface)) {
289 errno = ENOENT;
290 return -1;
291 }
292 // Because forwarding can be enabled even when tethering is off, we always
293 // use mode "2" (accept RAs, even if forwarding is enabled).
294 const char *accept_ra = on ? "2" : "0";
295 return writeValueToPath(ipv6_proc_path, interface, "accept_ra", accept_ra);
296}
297
298int InterfaceController::setAcceptIPv6Dad(const char *interface, const int on) {
299 if (!isIfaceName(interface)) {
300 errno = ENOENT;
301 return -1;
302 }
303 const char *accept_dad = on ? "1" : "0";
304 return writeValueToPath(ipv6_proc_path, interface, "accept_dad", accept_dad);
305}
306
Erik Kline59d8c482016-08-09 15:28:42 +0900307int InterfaceController::setIPv6DadTransmits(const char *interface, const char *value) {
308 if (!isIfaceName(interface)) {
309 errno = ENOENT;
310 return -1;
311 }
312 return writeValueToPath(ipv6_proc_path, interface, "dad_transmits", value);
313}
314
Lorenzo Colitti70afde62013-03-04 17:58:40 +0900315int InterfaceController::setIPv6PrivacyExtensions(const char *interface, const int on) {
Erik Klinee1da4842015-05-12 15:56:06 +0900316 if (!isIfaceName(interface)) {
317 errno = ENOENT;
318 return -1;
319 }
320 // 0: disable IPv6 privacy addresses
Joel Scherpelzde937962017-06-01 13:20:21 +0900321 // 2: enable IPv6 privacy addresses and prefer them over non-privacy ones.
Erik Klinee1da4842015-05-12 15:56:06 +0900322 return writeValueToPath(ipv6_proc_path, interface, "use_tempaddr", on ? "2" : "0");
Lorenzo Colitti70afde62013-03-04 17:58:40 +0900323}
Lorenzo Colitti37f2e372013-04-12 00:44:06 +0900324
Sreeram Ramachandrana4811802014-04-10 12:10:24 -0700325void InterfaceController::setAcceptRA(const char *value) {
Erik Klinee1da4842015-05-12 15:56:06 +0900326 setOnAllInterfaces(ipv6_proc_path, "accept_ra", value);
Sreeram Ramachandrana4811802014-04-10 12:10:24 -0700327}
328
Sreeram Ramachandrana01d6ef2014-04-10 19:37:59 -0700329// |tableOrOffset| is interpreted as:
Sreeram Ramachandrana4811802014-04-10 12:10:24 -0700330// If == 0: default. Routes go into RT6_TABLE_MAIN.
331// If > 0: user set. Routes go into the specified table.
332// If < 0: automatic. The absolute value is intepreted as an offset and added to the interface
333// ID to get the table. If it's set to -1000, routes from interface ID 5 will go into
334// table 1005, etc.
Sreeram Ramachandrana01d6ef2014-04-10 19:37:59 -0700335void InterfaceController::setAcceptRARouteTable(int tableOrOffset) {
Erik Klinee1da4842015-05-12 15:56:06 +0900336 std::string value(StringPrintf("%d", tableOrOffset));
337 setOnAllInterfaces(ipv6_proc_path, "accept_ra_rt_table", value.c_str());
Lorenzo Colitti37f2e372013-04-12 00:44:06 +0900338}
Dmitry Shmidt6d6c0e62013-06-11 16:18:06 -0700339
Dmitry Shmidt6d6c0e62013-06-11 16:18:06 -0700340int InterfaceController::setMtu(const char *interface, const char *mtu)
341{
Erik Klinee1da4842015-05-12 15:56:06 +0900342 if (!isIfaceName(interface)) {
343 errno = ENOENT;
344 return -1;
345 }
346 return writeValueToPath(sys_net_path, interface, "mtu", mtu);
Dmitry Shmidt6d6c0e62013-06-11 16:18:06 -0700347}
Erik Kline59273ed2014-12-08 16:05:28 +0900348
Erik Klinec296f092016-08-02 15:22:53 +0900349int InterfaceController::addAddress(const char *interface,
350 const char *addrString, int prefixLength) {
351 return ifc_add_address(interface, addrString, prefixLength);
352}
353
354int InterfaceController::delAddress(const char *interface,
355 const char *addrString, int prefixLength) {
356 return ifc_del_address(interface, addrString, prefixLength);
357}
358
Erik Klineb218a872016-07-04 09:57:18 +0900359int InterfaceController::getParameter(
360 const char *family, const char *which, const char *interface, const char *parameter,
361 std::string *value) {
362 const std::string path(getParameterPathname(family, which, interface, parameter));
363 if (path.empty()) {
364 return -errno;
365 }
366 return ReadFileToString(path, value) ? 0 : -errno;
367}
368
369int InterfaceController::setParameter(
370 const char *family, const char *which, const char *interface, const char *parameter,
371 const char *value) {
372 const std::string path(getParameterPathname(family, which, interface, parameter));
373 if (path.empty()) {
374 return -errno;
375 }
376 return WriteStringToFile(value, path) ? 0 : -errno;
377}
378
Erik Kline145fd252015-05-12 15:58:49 +0900379void InterfaceController::setBaseReachableTimeMs(unsigned int millis) {
380 std::string value(StringPrintf("%u", millis));
381 setOnAllInterfaces(ipv4_neigh_conf_dir, "base_reachable_time_ms", value.c_str());
382 setOnAllInterfaces(ipv6_neigh_conf_dir, "base_reachable_time_ms", value.c_str());
383}
384
Erik Kline59273ed2014-12-08 16:05:28 +0900385void InterfaceController::setIPv6OptimisticMode(const char *value) {
Erik Klinee1da4842015-05-12 15:56:06 +0900386 setOnAllInterfaces(ipv6_proc_path, "optimistic_dad", value);
387 setOnAllInterfaces(ipv6_proc_path, "use_optimistic", value);
Erik Kline59273ed2014-12-08 16:05:28 +0900388}