Tobias Brunner
c005073d0b
kernel-interface: Add destination prefix to get_nexthop()
...
This allows to determine the next hop to reach a subnet, for instance, when
installing routes for shunt policies.
2014-06-19 14:33:40 +02:00
Tobias Brunner
7522fcffd2
kernel-pfroute: Let get_nexthop() default to destination address
2014-03-31 14:32:44 +02:00
Tobias Brunner
d347a130f5
libhydra: Use lib->ns instead of hydra->daemon
2014-02-12 14:34:32 +01:00
Tobias Brunner
822b22c96f
kernel-pfroute: Don't cache route entries if installation fails
2014-02-12 13:52:25 +01:00
Mathias Krause
45b80880f8
kernel-pfroute: Fix mixed up memset() call in get_route()
...
The retry code introduced in dc8b083 got the memset() arguments wrong.
Fix this to ensure the buffer gets zeroed, for real.
It probably doesn't matter as we do reset the message length on retry, so
the stale data shouldn't be seen by anyone.
Found-by: git grep 'memset\s*\([^,]*,\s*[^,]*,\s*0\s*\)'
2013-08-29 18:56:39 +02:00
Tobias Brunner
11f468533f
kernel-netlink,pfroute: Properly update address flag within ROAM_DELAY
...
77d4a02 and 55da01f only updated the address flag when a job was created,
which obviously had the same limitation as the old code.
Fixes #374 .
2013-08-12 12:08:23 +02:00
Tobias Brunner
55da01f348
kernel-pfroute: Implement roam event handling like in the kernel-netlink plugin
...
There was no proper locking and the issue regarding the address
flag also existed.
2013-08-12 12:03:48 +02:00
Martin Willi
46666dd3c1
kernel-pfroute: use watcher to receive kernel events
2013-07-18 16:00:30 +02:00
Tobias Brunner
fae4d67adc
kernel-pfroute: Ignore IP address changes if address is %any
2013-07-17 17:45:18 +02:00
Tobias Brunner
b308a97944
kernel-pfroute: Properly enumerate sockaddrs in interface messages
...
The ifa_msghdr and rt_msghdr structs are not compatible (at least not on
FreeBSD).
2013-07-17 17:45:18 +02:00
Tobias Brunner
5310f485d9
kernel-pfroute: Provide name of interfaces on which virtual IPs are installed
2013-07-17 17:45:18 +02:00
Tobias Brunner
e9c1ca0278
kernel-pfroute: Ignore virtual IPs in address map
...
As the virtual flag is set after the address has been added to the map,
we make sure we ignore virtual IPs when doing lookups.
2013-07-17 17:45:18 +02:00
Tobias Brunner
cb082d15ef
kernel-pfroute: Make sure source addresses are not virtual and usable
...
It seems we sometimes get the virtual IP as source (with
rightsubnet=0.0.0.0/0) even if the exclude route is already
installed. Might be a timing issue because shortly afterwards the
lookup seems to succeed.
2013-07-17 17:45:18 +02:00
Tobias Brunner
527663d6b6
kernel-pfroute: Don't report an error when trying to reinstall a route
2013-07-17 17:45:18 +02:00
Tobias Brunner
0745f846d0
kernel-pfroute: Reinstall routes on interface/address changes
2013-07-17 17:45:17 +02:00
Tobias Brunner
7b9c3fb41f
kernel-pfroute: Trigger a roam event if a new interface appears
2013-07-17 17:45:17 +02:00
Tobias Brunner
e50b20539b
kernel-pfroute: Use ref_get() to allocate sequence numbers
2013-07-17 17:45:17 +02:00
Tobias Brunner
baa6419ec1
kernel-pfroute: Make time that is waited for VIPs to appear configurable
...
One second might be too short for IPs to appear/disappear, especially on
virtualized hosts.
2013-07-17 17:45:17 +02:00
Tobias Brunner
dc8b083d9f
kernel-pfroute: Retry route lookup without source address on failure
...
The known source address might be gone resulting in an error, making
learning a new source address impossible.
2013-07-17 17:45:17 +02:00
Tobias Brunner
12488efa78
kernel-pfroute: Simplify route lookup after fixing sockaddr parsing
2013-06-21 17:03:22 +02:00
Tobias Brunner
4b3fea3d54
kernel-pfroute: Alignment of sockaddrs is not always the same
2013-06-21 17:03:22 +02:00
Tobias Brunner
aa33d2e6eb
kernel-pfroute: struct sockaddr arguments are 4 byte aligned
...
This was noticed on Mac OS X where, if the default route is returned,
RTA_NETMASK has sa_len set to 0, but skipping zero bytes to read the
next address makes no sense, of course. Using 0 for sa_len seems
a bit strange, in particular, because struct sockaddr has by definition
a minimum length of 16 bytes. But it seems FreeBSD actually does the
same.
2013-06-21 17:03:22 +02:00
Tobias Brunner
b0629f7d9b
kernel-pfroute: Improve route lookup depending on information we get back
...
Kernels don't provide the same information for all routes.
2013-06-21 17:03:22 +02:00
Tobias Brunner
1c697ff1c5
kernel-pfroute: Try to ensure we get a source address or interface name
2013-06-21 17:03:22 +02:00
Tobias Brunner
34b0ad0653
kernel-pfroute: Use DST as nexthop for host routes
...
These are created as cache/clone on Mac OS X.
2013-06-21 17:03:21 +02:00
Tobias Brunner
d6c17e96b2
kernel-pfroute: Implement get_source_addr()
2013-06-21 17:03:21 +02:00
Tobias Brunner
f58f8bf409
kernel-pfroute: Properly install routes with interface and gateway
2013-06-21 17:03:21 +02:00
Tobias Brunner
93e4df3761
kernel-pfroute: Activate TUN device before setting address
...
On FreeBSD, for some reason, we don't learn the interface is up
otherwise. Even though ifconfig lists it as up at the same time.
2013-06-21 17:03:21 +02:00
Tobias Brunner
554c4276a5
kernel-pfroute: Raise tun event when creating/destroying TUN devices for virtual IPs
2013-06-21 17:03:21 +02:00
Martin Willi
c9a323c1d9
kernel-pfroute: allow only one thread to do a route look up simultaneously
...
Otherwise we mess up the sequence number another thread is waiting for.
2013-05-06 17:01:13 +02:00
Martin Willi
580b768d03
kernel-pfroute: add a feature flag requesting "exclude" routes
...
If routes installed along with policies covering the peer address affect local
IKE/ESP packets, they won't get routed correctly. To work around this issue,
the kernel interface can install "exclude" routes for the IKE peer. Not all
networking backends require this workaround, hence we export a flag for it
if it is required.
2013-05-06 17:01:13 +02:00
Martin Willi
bd520193a4
kernel-pfroute: remove unused interface address refcounting
2013-05-06 17:01:13 +02:00
Martin Willi
77b6f19694
kernel-pfroute: mark IPs installed on tun device as virtual
2013-05-06 17:00:55 +02:00
Martin Willi
2a2d7a4dc8
kernel-pfroute: install virtual IPs using dedicated tun devices
2013-05-06 16:10:13 +02:00
Martin Willi
1a2a8bffed
kernel-interface: support enumeration of virtual-only IPs
2013-05-06 16:10:13 +02:00
Martin Willi
121783035c
kernel-pfroute: split /0 routes to avoid conflict with default route
2013-05-06 16:10:13 +02:00
Martin Willi
6e879a59fc
kernel-pfroute: rescan address list for an interface if its state changes
...
It seems that we don't get address notifications if the interface is down
on OS X.
2013-05-06 16:10:13 +02:00
Martin Willi
0fd409db77
kernel-pfroute: add newly appearing interfaces to the interface cache
2013-05-06 16:10:12 +02:00
Martin Willi
9bc342eae4
kernel-pfroute: implement get_nexthop()
2013-05-06 16:10:12 +02:00
Martin Willi
272bcac894
kernel-pfroute: install and uninstall routes
2013-05-06 16:10:12 +02:00
Martin Willi
3a7f4b5c8d
kernel-pfroute: collect replies received for our own queries
2013-05-06 16:10:12 +02:00
Martin Willi
b1c6b68e4c
kernel-pfroute: refactor PF_ROUTE message processing, use an enumerator
2013-05-06 16:10:12 +02:00
Martin Willi
9650bf3cc7
kernel-pfroute: use INIT() macro for allocations
2013-05-06 16:10:12 +02:00
Martin Willi
0e107f03ac
kernel-pfroute: use only a single PF_ROUTE socket for both events and queries
2013-05-06 16:10:12 +02:00
Martin Willi
e8002956c9
kernel-pfroute: fix length check when receiving PF_ROUTE messages
2013-05-06 16:10:12 +02:00
Martin Willi
d88597f0dd
Don't wait while removing external IPs used for load testing
2012-11-29 10:22:51 +01:00
Martin Willi
b185cdd16d
Install virtual IPs via interface name, and use an interface lookup where required
2012-11-29 10:22:51 +01:00
Martin Willi
50bd755871
Add an optional kernel-interface parameter to install IPs with a custom prefix
2012-11-29 10:22:51 +01:00
Tobias Brunner
f05b427265
Moved debug.[ch] to utils folder
2012-10-24 16:00:51 +02:00
Tobias Brunner
12642a6831
Moved data structures to new collections subfolder
2012-10-24 16:00:49 +02:00