fou_linux.go 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. //go:build linux
  2. // +build linux
  3. package netlink
  4. import (
  5. "encoding/binary"
  6. "errors"
  7. "log"
  8. "net"
  9. "github.com/vishvananda/netlink/nl"
  10. "golang.org/x/sys/unix"
  11. )
  12. const (
  13. FOU_GENL_NAME = "fou"
  14. )
  15. const (
  16. FOU_CMD_UNSPEC uint8 = iota
  17. FOU_CMD_ADD
  18. FOU_CMD_DEL
  19. FOU_CMD_GET
  20. FOU_CMD_MAX = FOU_CMD_GET
  21. )
  22. const (
  23. FOU_ATTR_UNSPEC = iota
  24. FOU_ATTR_PORT
  25. FOU_ATTR_AF
  26. FOU_ATTR_IPPROTO
  27. FOU_ATTR_TYPE
  28. FOU_ATTR_REMCSUM_NOPARTIAL
  29. FOU_ATTR_LOCAL_V4
  30. FOU_ATTR_LOCAL_V6
  31. FOU_ATTR_PEER_V4
  32. FOU_ATTR_PEER_V6
  33. FOU_ATTR_PEER_PORT
  34. FOU_ATTR_IFINDEX
  35. FOU_ATTR_MAX = FOU_ATTR_REMCSUM_NOPARTIAL
  36. )
  37. const (
  38. FOU_ENCAP_UNSPEC = iota
  39. FOU_ENCAP_DIRECT
  40. FOU_ENCAP_GUE
  41. FOU_ENCAP_MAX = FOU_ENCAP_GUE
  42. )
  43. var fouFamilyId int
  44. func FouFamilyId() (int, error) {
  45. if fouFamilyId != 0 {
  46. return fouFamilyId, nil
  47. }
  48. fam, err := GenlFamilyGet(FOU_GENL_NAME)
  49. if err != nil {
  50. return -1, err
  51. }
  52. fouFamilyId = int(fam.ID)
  53. return fouFamilyId, nil
  54. }
  55. func FouAdd(f Fou) error {
  56. return pkgHandle.FouAdd(f)
  57. }
  58. func (h *Handle) FouAdd(f Fou) error {
  59. fam_id, err := FouFamilyId()
  60. if err != nil {
  61. return err
  62. }
  63. // setting ip protocol conflicts with encapsulation type GUE
  64. if f.EncapType == FOU_ENCAP_GUE && f.Protocol != 0 {
  65. return errors.New("GUE encapsulation doesn't specify an IP protocol")
  66. }
  67. req := h.newNetlinkRequest(fam_id, unix.NLM_F_ACK)
  68. // int to byte for port
  69. bp := make([]byte, 2)
  70. binary.BigEndian.PutUint16(bp[0:2], uint16(f.Port))
  71. attrs := []*nl.RtAttr{
  72. nl.NewRtAttr(FOU_ATTR_PORT, bp),
  73. nl.NewRtAttr(FOU_ATTR_TYPE, []byte{uint8(f.EncapType)}),
  74. nl.NewRtAttr(FOU_ATTR_AF, []byte{uint8(f.Family)}),
  75. nl.NewRtAttr(FOU_ATTR_IPPROTO, []byte{uint8(f.Protocol)}),
  76. }
  77. raw := []byte{FOU_CMD_ADD, 1, 0, 0}
  78. for _, a := range attrs {
  79. raw = append(raw, a.Serialize()...)
  80. }
  81. req.AddRawData(raw)
  82. _, err = req.Execute(unix.NETLINK_GENERIC, 0)
  83. return err
  84. }
  85. func FouDel(f Fou) error {
  86. return pkgHandle.FouDel(f)
  87. }
  88. func (h *Handle) FouDel(f Fou) error {
  89. fam_id, err := FouFamilyId()
  90. if err != nil {
  91. return err
  92. }
  93. req := h.newNetlinkRequest(fam_id, unix.NLM_F_ACK)
  94. // int to byte for port
  95. bp := make([]byte, 2)
  96. binary.BigEndian.PutUint16(bp[0:2], uint16(f.Port))
  97. attrs := []*nl.RtAttr{
  98. nl.NewRtAttr(FOU_ATTR_PORT, bp),
  99. nl.NewRtAttr(FOU_ATTR_AF, []byte{uint8(f.Family)}),
  100. }
  101. raw := []byte{FOU_CMD_DEL, 1, 0, 0}
  102. for _, a := range attrs {
  103. raw = append(raw, a.Serialize()...)
  104. }
  105. req.AddRawData(raw)
  106. _, err = req.Execute(unix.NETLINK_GENERIC, 0)
  107. if err != nil {
  108. return err
  109. }
  110. return nil
  111. }
  112. // If the returned error is [ErrDumpInterrupted], results may be inconsistent
  113. // or incomplete.
  114. func FouList(fam int) ([]Fou, error) {
  115. return pkgHandle.FouList(fam)
  116. }
  117. // If the returned error is [ErrDumpInterrupted], results may be inconsistent
  118. // or incomplete.
  119. func (h *Handle) FouList(fam int) ([]Fou, error) {
  120. fam_id, err := FouFamilyId()
  121. if err != nil {
  122. return nil, err
  123. }
  124. req := h.newNetlinkRequest(fam_id, unix.NLM_F_DUMP)
  125. attrs := []*nl.RtAttr{
  126. nl.NewRtAttr(FOU_ATTR_AF, []byte{uint8(fam)}),
  127. }
  128. raw := []byte{FOU_CMD_GET, 1, 0, 0}
  129. for _, a := range attrs {
  130. raw = append(raw, a.Serialize()...)
  131. }
  132. req.AddRawData(raw)
  133. msgs, executeErr := req.Execute(unix.NETLINK_GENERIC, 0)
  134. if executeErr != nil && !errors.Is(err, ErrDumpInterrupted) {
  135. return nil, executeErr
  136. }
  137. fous := make([]Fou, 0, len(msgs))
  138. for _, m := range msgs {
  139. f, err := deserializeFouMsg(m)
  140. if err != nil {
  141. return fous, err
  142. }
  143. fous = append(fous, f)
  144. }
  145. return fous, executeErr
  146. }
  147. func deserializeFouMsg(msg []byte) (Fou, error) {
  148. fou := Fou{}
  149. for attr := range nl.ParseAttributes(msg[4:]) {
  150. switch attr.Type {
  151. case FOU_ATTR_AF:
  152. fou.Family = int(attr.Value[0])
  153. case FOU_ATTR_PORT:
  154. fou.Port = int(networkOrder.Uint16(attr.Value))
  155. case FOU_ATTR_IPPROTO:
  156. fou.Protocol = int(attr.Value[0])
  157. case FOU_ATTR_TYPE:
  158. fou.EncapType = int(attr.Value[0])
  159. case FOU_ATTR_LOCAL_V4, FOU_ATTR_LOCAL_V6:
  160. fou.Local = net.IP(attr.Value)
  161. case FOU_ATTR_PEER_V4, FOU_ATTR_PEER_V6:
  162. fou.Peer = net.IP(attr.Value)
  163. case FOU_ATTR_PEER_PORT:
  164. fou.PeerPort = int(networkOrder.Uint16(attr.Value))
  165. case FOU_ATTR_IFINDEX:
  166. fou.IfIndex = int(native.Uint16(attr.Value))
  167. default:
  168. log.Printf("unknown fou attribute from kernel: %+v %v", attr, attr.Type&nl.NLA_TYPE_MASK)
  169. }
  170. }
  171. return fou, nil
  172. }