iprule: fix segfault (FS#1875)
[project/netifd.git] / iprule.c
1 /*
2 * netifd - network interface daemon
3 * Copyright (C) 2012 Felix Fietkau <nbd@openwrt.org>
4 * Copyright (C) 2013 Jo-Philipp Wich <jow@openwrt.org>
5 * Copyright (C) 2018 Alexander Couzens <lynxis@fe80.eu>
6 *
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License version 2
9 * as published by the Free Software Foundation
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 */
16 #include <string.h>
17 #include <stdlib.h>
18 #include <stdio.h>
19
20 #include <arpa/inet.h>
21
22 #include "netifd.h"
23 #include "device.h"
24 #include "interface.h"
25 #include "iprule.h"
26 #include "proto.h"
27 #include "ubus.h"
28 #include "system.h"
29
30 struct vlist_tree iprules;
31 static bool iprules_flushed = false;
32 static unsigned int iprules_counter[2];
33
34 enum {
35 RULE_INTERFACE_IN,
36 RULE_INTERFACE_OUT,
37 RULE_INVERT,
38 RULE_SRC,
39 RULE_DEST,
40 RULE_PRIORITY,
41 RULE_TOS,
42 RULE_FWMARK,
43 RULE_LOOKUP,
44 RULE_ACTION,
45 RULE_GOTO,
46 RULE_SUP_PREFIXLEN,
47 __RULE_MAX
48 };
49
50 static const struct blobmsg_policy rule_attr[__RULE_MAX] = {
51 [RULE_INTERFACE_IN] = { .name = "in", .type = BLOBMSG_TYPE_STRING },
52 [RULE_INTERFACE_OUT] = { .name = "out", .type = BLOBMSG_TYPE_STRING },
53 [RULE_INVERT] = { .name = "invert", .type = BLOBMSG_TYPE_BOOL },
54 [RULE_SRC] = { .name = "src", .type = BLOBMSG_TYPE_STRING },
55 [RULE_DEST] = { .name = "dest", .type = BLOBMSG_TYPE_STRING },
56 [RULE_PRIORITY] = { .name = "priority", .type = BLOBMSG_TYPE_INT32 },
57 [RULE_TOS] = { .name = "tos", .type = BLOBMSG_TYPE_INT32 },
58 [RULE_FWMARK] = { .name = "mark", .type = BLOBMSG_TYPE_STRING },
59 [RULE_LOOKUP] = { .name = "lookup", .type = BLOBMSG_TYPE_STRING },
60 [RULE_SUP_PREFIXLEN] = { .name = "suppress_prefixlength", .type = BLOBMSG_TYPE_INT32 },
61 [RULE_ACTION] = { .name = "action", .type = BLOBMSG_TYPE_STRING },
62 [RULE_GOTO] = { .name = "goto", .type = BLOBMSG_TYPE_INT32 },
63 };
64
65 const struct uci_blob_param_list rule_attr_list = {
66 .n_params = __RULE_MAX,
67 .params = rule_attr,
68 };
69
70 /* interface based rules are dynamic. */
71 static bool rule_ready(struct iprule *rule) {
72 if (rule->flags & IPRULE_OUT && !rule->out_dev[0])
73 return false;
74
75 if (rule->flags & IPRULE_IN && !rule->in_dev[0])
76 return false;
77
78 return true;
79 }
80
81 static bool
82 iprule_parse_mark(const char *mark, struct iprule *rule)
83 {
84 char *s, *e;
85 unsigned int n;
86
87 if ((s = strchr(mark, '/')) != NULL)
88 *s++ = 0;
89
90 n = strtoul(mark, &e, 0);
91
92 if (e == mark || *e)
93 return false;
94
95 rule->fwmark = n;
96 rule->flags |= IPRULE_FWMARK;
97
98 if (s) {
99 n = strtoul(s, &e, 0);
100
101 if (e == s || *e)
102 return false;
103
104 rule->fwmask = n;
105 rule->flags |= IPRULE_FWMASK;
106 }
107
108 return true;
109 }
110
111 /* called on interface changes of the incoming interface */
112 static void rule_in_cb(
113 struct interface_user *dep,
114 struct interface *iface,
115 enum interface_event ev)
116 {
117 struct iprule *rule = container_of(dep, struct iprule, in_iface_user);
118
119 switch (ev) {
120 case IFEV_UP:
121 if (!iface->l3_dev.dev)
122 break;
123 memcpy(rule->in_dev, iface->l3_dev.dev->ifname, sizeof(rule->in_dev));
124 if (rule_ready(rule))
125 system_add_iprule(rule);
126 break;
127 case IFEV_DOWN:
128 case IFEV_UP_FAILED:
129 case IFEV_FREE:
130 if (rule_ready(rule))
131 system_del_iprule(rule);
132 rule->in_dev[0] = 0;
133 break;
134 default:
135 break;
136 }
137 }
138
139 /* called on interface changes of the outgoing interface */
140 static void rule_out_cb(
141 struct interface_user *dep,
142 struct interface *iface,
143 enum interface_event ev)
144 {
145 struct iprule *rule = container_of(dep, struct iprule, out_iface_user);
146
147 switch (ev) {
148 case IFEV_UP:
149 if (!iface->l3_dev.dev)
150 break;
151 memcpy(rule->out_dev, iface->l3_dev.dev->ifname, sizeof(rule->out_dev));
152 if (rule_ready(rule))
153 system_add_iprule(rule);
154 break;
155 case IFEV_DOWN:
156 case IFEV_UP_FAILED:
157 case IFEV_FREE:
158 if (rule_ready(rule))
159 system_del_iprule(rule);
160 rule->out_dev[0] = 0;
161 break;
162 default:
163 break;
164 }
165 }
166
167 /* called on all interface events */
168 static void generic_interface_cb(
169 struct interface_user *dep,
170 struct interface *iface,
171 enum interface_event ev)
172 {
173 struct iprule *rule;
174
175 if (ev != IFEV_CREATE)
176 return;
177
178 /* add new interfaces to rules */
179 vlist_for_each_element(&iprules, rule, node) {
180 if (rule_ready(rule))
181 continue;
182
183 if ((rule->flags & IPRULE_OUT) && !strcmp(rule->out_iface, iface->name))
184 interface_add_user(&rule->out_iface_user, iface);
185
186 if ((rule->flags & IPRULE_IN) && !strcmp(rule->in_iface, iface->name))
187 interface_add_user(&rule->in_iface_user, iface);
188 }
189 }
190
191 struct interface_user generic_listener = {
192 .cb = generic_interface_cb
193 };
194
195 void
196 iprule_add(struct blob_attr *attr, bool v6)
197 {
198 struct blob_attr *tb[__RULE_MAX], *cur;
199 struct iprule *rule;
200 char *iface_name;
201 int af = v6 ? AF_INET6 : AF_INET;
202
203 blobmsg_parse(rule_attr, __RULE_MAX, tb, blobmsg_data(attr), blobmsg_data_len(attr));
204
205 rule = calloc(1, sizeof(*rule));
206 if (!rule)
207 return;
208
209 rule->flags = v6 ? IPRULE_INET6 : IPRULE_INET4;
210 rule->order = iprules_counter[rule->flags]++;
211
212 if ((cur = tb[RULE_INVERT]) != NULL)
213 rule->invert = blobmsg_get_bool(cur);
214
215 if ((cur = tb[RULE_INTERFACE_IN]) != NULL) {
216 iface_name = calloc(1, strlen(blobmsg_data(cur)) + 1);
217 rule->in_iface = strcpy(iface_name, blobmsg_data(cur));
218 rule->in_iface_user.cb = &rule_in_cb;
219 rule->flags |= IPRULE_IN;
220 }
221
222 if ((cur = tb[RULE_INTERFACE_OUT]) != NULL) {
223 iface_name = calloc(1, strlen(blobmsg_data(cur)) + 1);
224 rule->out_iface = strcpy(iface_name, blobmsg_data(cur));
225 rule->out_iface_user.cb = &rule_out_cb;
226 rule->flags |= IPRULE_OUT;
227 }
228
229 if ((cur = tb[RULE_SRC]) != NULL) {
230 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &rule->src_addr, &rule->src_mask)) {
231 DPRINTF("Failed to parse rule source: %s\n", (char *) blobmsg_data(cur));
232 goto error;
233 }
234 rule->flags |= IPRULE_SRC;
235 }
236
237 if ((cur = tb[RULE_DEST]) != NULL) {
238 if (!parse_ip_and_netmask(af, blobmsg_data(cur), &rule->dest_addr, &rule->dest_mask)) {
239 DPRINTF("Failed to parse rule destination: %s\n", (char *) blobmsg_data(cur));
240 goto error;
241 }
242 rule->flags |= IPRULE_DEST;
243 }
244
245 if ((cur = tb[RULE_PRIORITY]) != NULL) {
246 rule->priority = blobmsg_get_u32(cur);
247 rule->flags |= IPRULE_PRIORITY;
248 }
249
250 if ((cur = tb[RULE_TOS]) != NULL) {
251 if ((rule->tos = blobmsg_get_u32(cur)) > 255) {
252 DPRINTF("Invalid TOS value: %u\n", blobmsg_get_u32(cur));
253 goto error;
254 }
255 rule->flags |= IPRULE_TOS;
256 }
257
258 if ((cur = tb[RULE_FWMARK]) != NULL) {
259 if (!iprule_parse_mark(blobmsg_data(cur), rule)) {
260 DPRINTF("Failed to parse rule fwmark: %s\n", (char *) blobmsg_data(cur));
261 goto error;
262 }
263 /* flags set by iprule_parse_mark() */
264 }
265
266 if ((cur = tb[RULE_LOOKUP]) != NULL) {
267 if (!system_resolve_rt_table(blobmsg_data(cur), &rule->lookup)) {
268 DPRINTF("Failed to parse rule lookup table: %s\n", (char *) blobmsg_data(cur));
269 goto error;
270 }
271 rule->flags |= IPRULE_LOOKUP;
272 }
273
274 if ((cur = tb[RULE_SUP_PREFIXLEN]) != NULL) {
275 rule->sup_prefixlen = blobmsg_get_u32(cur);
276 rule->flags |= IPRULE_SUP_PREFIXLEN;
277 }
278
279 if ((cur = tb[RULE_ACTION]) != NULL) {
280 if (!system_resolve_iprule_action(blobmsg_data(cur), &rule->action)) {
281 DPRINTF("Failed to parse rule action: %s\n", (char *) blobmsg_data(cur));
282 goto error;
283 }
284 rule->flags |= IPRULE_ACTION;
285 }
286
287 if ((cur = tb[RULE_GOTO]) != NULL) {
288 rule->gotoid = blobmsg_get_u32(cur);
289 rule->flags |= IPRULE_GOTO;
290 }
291
292 vlist_add(&iprules, &rule->node, &rule->flags);
293 return;
294
295 error:
296 free(rule);
297 }
298
299 void
300 iprule_update_start(void)
301 {
302 if (!iprules_flushed) {
303 system_flush_iprules();
304 iprules_flushed = true;
305 }
306
307 iprules_counter[0] = 1;
308 iprules_counter[1] = 1;
309 vlist_update(&iprules);
310 }
311
312 void
313 iprule_update_complete(void)
314 {
315 vlist_flush(&iprules);
316 }
317
318
319 static int
320 rule_cmp(const void *k1, const void *k2, void *ptr)
321 {
322 return memcmp(k1, k2, sizeof(struct iprule)-offsetof(struct iprule, flags));
323 }
324
325 static void deregister_interfaces(struct iprule *rule)
326 {
327 if (rule->flags & IPRULE_IN && rule->in_iface_user.iface)
328 interface_remove_user(&rule->in_iface_user);
329
330 if (rule->flags & IPRULE_OUT && rule->out_iface_user.iface)
331 interface_remove_user(&rule->out_iface_user);
332 }
333
334 static void register_interfaces(struct iprule *rule)
335 {
336 struct interface *iface, *tmp;
337
338 if (rule->flags & IPRULE_IN) {
339 tmp = vlist_find(&interfaces, rule->in_iface, iface, node);
340 if (tmp)
341 interface_add_user(&rule->in_iface_user, tmp);
342 }
343 if (rule->flags & IPRULE_OUT) {
344 tmp = vlist_find(&interfaces, rule->out_iface, iface, node);
345 if (tmp)
346 interface_add_user(&rule->out_iface_user, tmp);
347 }
348 }
349
350 static void
351 iprule_update_rule(struct vlist_tree *tree,
352 struct vlist_node *node_new, struct vlist_node *node_old)
353 {
354 struct iprule *rule_old, *rule_new;
355
356 rule_old = container_of(node_old, struct iprule, node);
357 rule_new = container_of(node_new, struct iprule, node);
358
359 if (node_old) {
360 if (rule_ready(rule_old))
361 system_del_iprule(rule_old);
362
363 if (rule_old->flags & (IPRULE_IN | IPRULE_OUT))
364 deregister_interfaces(rule_old);
365
366 if (rule_old->in_iface)
367 free(rule_old->in_iface);
368
369 if (rule_old->out_iface)
370 free(rule_old->out_iface);
371
372 free(rule_old);
373 }
374
375 if (node_new) {
376 /* interface based rules calls system_add_iprule over the event cb */
377 if (rule_new->flags & (IPRULE_IN | IPRULE_OUT)) {
378 register_interfaces(rule_new);
379 } else {
380 system_add_iprule(rule_new);
381 }
382 }
383 }
384
385 static void __init
386 iprule_init_list(void)
387 {
388 vlist_init(&iprules, rule_cmp, iprule_update_rule);
389 interface_add_user(&generic_listener, NULL);
390 }