blob: 6d16c6ec0e536cd7a35277246d35c3597dfdd288 [file] [log] [blame]
paul718e3742002-12-13 20:15:29 +00001/* BGP network related fucntions
2 Copyright (C) 1999 Kunihiro Ishiguro
3
4This file is part of GNU Zebra.
5
6GNU Zebra is free software; you can redistribute it and/or modify it
7under the terms of the GNU General Public License as published by the
8Free Software Foundation; either version 2, or (at your option) any
9later version.
10
11GNU Zebra is distributed in the hope that it will be useful, but
12WITHOUT ANY WARRANTY; without even the implied warranty of
13MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14General Public License for more details.
15
16You should have received a copy of the GNU General Public License
17along with GNU Zebra; see the file COPYING. If not, write to the Free
18Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
1902111-1307, USA. */
20
21#include <zebra.h>
22
23#include "thread.h"
24#include "sockunion.h"
Paul Jakma0df7c912008-07-21 21:02:49 +000025#include "sockopt.h"
paul718e3742002-12-13 20:15:29 +000026#include "memory.h"
27#include "log.h"
28#include "if.h"
29#include "prefix.h"
30#include "command.h"
pauledd7c242003-06-04 13:59:38 +000031#include "privs.h"
Paul Jakma0df7c912008-07-21 21:02:49 +000032#include "linklist.h"
paul718e3742002-12-13 20:15:29 +000033
34#include "bgpd/bgpd.h"
35#include "bgpd/bgp_fsm.h"
36#include "bgpd/bgp_attr.h"
37#include "bgpd/bgp_debug.h"
38#include "bgpd/bgp_network.h"
pauledd7c242003-06-04 13:59:38 +000039
40extern struct zebra_privs_t bgpd_privs;
41
paul718e3742002-12-13 20:15:29 +000042
Paul Jakma0df7c912008-07-21 21:02:49 +000043/*
44 * Set MD5 key for the socket, for the given IPv4 peer address.
45 * If the password is NULL or zero-length, the option will be disabled.
46 */
47static int
48bgp_md5_set_socket (int socket, union sockunion *su, const char *password)
49{
50 int ret = -1;
51 int en = ENOSYS;
52
53 assert (socket >= 0);
54
55#if HAVE_DECL_TCP_MD5SIG
56 ret = sockopt_tcp_signature (socket, su, password);
57 en = errno;
58#endif /* HAVE_TCP_MD5SIG */
59
60 if (ret < 0)
61 zlog (NULL, LOG_WARNING, "can't set TCP_MD5SIG option on socket %d: %s",
62 socket, safe_strerror (en));
63
64 return ret;
65}
66
67/* Helper for bgp_connect */
68static int
69bgp_md5_set_connect (int socket, union sockunion *su, const char *password)
70{
71 int ret = -1;
72
73#if HAVE_DECL_TCP_MD5SIG
74 if ( bgpd_privs.change (ZPRIVS_RAISE) )
75 {
76 zlog_err ("%s: could not raise privs", __func__);
77 return ret;
78 }
79
80 ret = bgp_md5_set_socket (socket, su, password);
81
82 if (bgpd_privs.change (ZPRIVS_LOWER) )
83 zlog_err ("%s: could not lower privs", __func__);
84#endif /* HAVE_TCP_MD5SIG */
85
86 return ret;
87}
88
89int
90bgp_md5_set (struct peer *peer)
91{
92 struct listnode *node;
93 int fret = 0, ret;
94 int *socket;
95
96 if ( bgpd_privs.change (ZPRIVS_RAISE) )
97 {
98 zlog_err ("%s: could not raise privs", __func__);
99 return -1;
100 }
101
102 /* Just set the password on the listen socket(s). Outbound connections
103 * are taken care of in bgp_connect() below.
104 */
105 for (ALL_LIST_ELEMENTS_RO(bm->listen_sockets, node, socket))
106 {
107 ret = bgp_md5_set_socket ((int )socket, &peer->su, peer->password);
108 if (ret < 0)
109 fret = ret;
110 }
111 if (bgpd_privs.change (ZPRIVS_LOWER) )
112 zlog_err ("%s: could not lower privs", __func__);
113
114 return fret;
115}
116
paul718e3742002-12-13 20:15:29 +0000117/* Accept bgp connection. */
118static int
119bgp_accept (struct thread *thread)
120{
121 int bgp_sock;
122 int accept_sock;
123 union sockunion su;
124 struct peer *peer;
pauleb821182004-05-01 08:44:08 +0000125 struct peer *peer1;
paul718e3742002-12-13 20:15:29 +0000126 struct bgp *bgp;
127 char buf[SU_ADDRSTRLEN];
128
129 /* Regiser accept thread. */
130 accept_sock = THREAD_FD (thread);
131 bgp = THREAD_ARG (thread);
132
133 if (accept_sock < 0)
134 {
135 zlog_err ("accept_sock is nevative value %d", accept_sock);
136 return -1;
137 }
138 thread_add_read (master, bgp_accept, bgp, accept_sock);
139
140 /* Accept client connection. */
141 bgp_sock = sockunion_accept (accept_sock, &su);
142 if (bgp_sock < 0)
143 {
ajs6099b3b2004-11-20 02:06:59 +0000144 zlog_err ("[Error] BGP socket accept failed (%s)", safe_strerror (errno));
paul718e3742002-12-13 20:15:29 +0000145 return -1;
146 }
147
148 if (BGP_DEBUG (events, EVENTS))
ajs478ba052004-12-08 20:41:23 +0000149 zlog_debug ("[Event] BGP connection from host %s", inet_sutop (&su, buf));
paul718e3742002-12-13 20:15:29 +0000150
151 /* Check remote IP address */
pauleb821182004-05-01 08:44:08 +0000152 peer1 = peer_lookup (bgp, &su);
153 if (! peer1 || peer1->status == Idle)
paul718e3742002-12-13 20:15:29 +0000154 {
155 if (BGP_DEBUG (events, EVENTS))
156 {
pauleb821182004-05-01 08:44:08 +0000157 if (! peer1)
ajs478ba052004-12-08 20:41:23 +0000158 zlog_debug ("[Event] BGP connection IP address %s is not configured",
paul718e3742002-12-13 20:15:29 +0000159 inet_sutop (&su, buf));
160 else
ajs478ba052004-12-08 20:41:23 +0000161 zlog_debug ("[Event] BGP connection IP address %s is Idle state",
paul718e3742002-12-13 20:15:29 +0000162 inet_sutop (&su, buf));
163 }
164 close (bgp_sock);
165 return -1;
166 }
167
168 /* In case of peer is EBGP, we should set TTL for this connection. */
pauleb821182004-05-01 08:44:08 +0000169 if (peer_sort (peer1) == BGP_PEER_EBGP)
170 sockopt_ttl (peer1->su.sa.sa_family, bgp_sock, peer1->ttl);
paul718e3742002-12-13 20:15:29 +0000171
172 if (! bgp)
pauleb821182004-05-01 08:44:08 +0000173 bgp = peer1->bgp;
paul718e3742002-12-13 20:15:29 +0000174
pauleb821182004-05-01 08:44:08 +0000175 /* Make dummy peer until read Open packet. */
176 if (BGP_DEBUG (events, EVENTS))
ajs478ba052004-12-08 20:41:23 +0000177 zlog_debug ("[Event] Make dummy peer structure until read Open packet");
pauleb821182004-05-01 08:44:08 +0000178
179 {
180 char buf[SU_ADDRSTRLEN + 1];
181
182 peer = peer_create_accept (bgp);
183 SET_FLAG (peer->sflags, PEER_STATUS_ACCEPT_PEER);
184 peer->su = su;
185 peer->fd = bgp_sock;
186 peer->status = Active;
187 peer->local_id = peer1->local_id;
188
189 /* Make peer's address string. */
190 sockunion2str (&su, buf, SU_ADDRSTRLEN);
paule83e2082005-05-19 02:12:25 +0000191 peer->host = XSTRDUP (MTYPE_BGP_PEER_HOST, buf);
pauleb821182004-05-01 08:44:08 +0000192 }
paul718e3742002-12-13 20:15:29 +0000193
194 BGP_EVENT_ADD (peer, TCP_connection_open);
195
196 return 0;
197}
198
199/* BGP socket bind. */
paul94f2b392005-06-28 12:44:16 +0000200static int
paul718e3742002-12-13 20:15:29 +0000201bgp_bind (struct peer *peer)
202{
203#ifdef SO_BINDTODEVICE
204 int ret;
205 struct ifreq ifreq;
206
207 if (! peer->ifname)
208 return 0;
209
210 strncpy ((char *)&ifreq.ifr_name, peer->ifname, sizeof (ifreq.ifr_name));
211
paul98f51632004-10-25 14:19:15 +0000212 if ( bgpd_privs.change (ZPRIVS_RAISE) )
213 zlog_err ("bgp_bind: could not raise privs");
214
pauleb821182004-05-01 08:44:08 +0000215 ret = setsockopt (peer->fd, SOL_SOCKET, SO_BINDTODEVICE,
paul718e3742002-12-13 20:15:29 +0000216 &ifreq, sizeof (ifreq));
paul98f51632004-10-25 14:19:15 +0000217
218 if (bgpd_privs.change (ZPRIVS_LOWER) )
219 zlog_err ("bgp_bind: could not lower privs");
220
paul718e3742002-12-13 20:15:29 +0000221 if (ret < 0)
222 {
223 zlog (peer->log, LOG_INFO, "bind to interface %s failed", peer->ifname);
224 return ret;
225 }
226#endif /* SO_BINDTODEVICE */
227 return 0;
228}
229
paul94f2b392005-06-28 12:44:16 +0000230static int
paul718e3742002-12-13 20:15:29 +0000231bgp_bind_address (int sock, struct in_addr *addr)
232{
233 int ret;
234 struct sockaddr_in local;
235
236 memset (&local, 0, sizeof (struct sockaddr_in));
237 local.sin_family = AF_INET;
Paul Jakma6f0e3f62007-05-10 02:38:51 +0000238#ifdef HAVE_STRUCT_SOCKADDR_IN_SIN_LEN
paul718e3742002-12-13 20:15:29 +0000239 local.sin_len = sizeof(struct sockaddr_in);
Paul Jakma6f0e3f62007-05-10 02:38:51 +0000240#endif /* HAVE_STRUCT_SOCKADDR_IN_SIN_LEN */
paul718e3742002-12-13 20:15:29 +0000241 memcpy (&local.sin_addr, addr, sizeof (struct in_addr));
242
pauledd7c242003-06-04 13:59:38 +0000243 if ( bgpd_privs.change (ZPRIVS_RAISE) )
244 zlog_err ("bgp_bind_address: could not raise privs");
245
paul718e3742002-12-13 20:15:29 +0000246 ret = bind (sock, (struct sockaddr *)&local, sizeof (struct sockaddr_in));
247 if (ret < 0)
248 ;
pauledd7c242003-06-04 13:59:38 +0000249
250 if (bgpd_privs.change (ZPRIVS_LOWER) )
251 zlog_err ("bgp_bind_address: could not lower privs");
252
paul718e3742002-12-13 20:15:29 +0000253 return 0;
254}
255
paul94f2b392005-06-28 12:44:16 +0000256static struct in_addr *
paul718e3742002-12-13 20:15:29 +0000257bgp_update_address (struct interface *ifp)
258{
259 struct prefix_ipv4 *p;
260 struct connected *connected;
hasso52dc7ee2004-09-23 19:18:23 +0000261 struct listnode *node;
paul718e3742002-12-13 20:15:29 +0000262
paul1eb8ef22005-04-07 07:30:20 +0000263 for (ALL_LIST_ELEMENTS_RO (ifp->connected, node, connected))
paul718e3742002-12-13 20:15:29 +0000264 {
paul718e3742002-12-13 20:15:29 +0000265 p = (struct prefix_ipv4 *) connected->address;
266
267 if (p->family == AF_INET)
268 return &p->prefix;
269 }
270 return NULL;
271}
272
273/* Update source selection. */
paul94f2b392005-06-28 12:44:16 +0000274static void
paul718e3742002-12-13 20:15:29 +0000275bgp_update_source (struct peer *peer)
276{
277 struct interface *ifp;
278 struct in_addr *addr;
279
280 /* Source is specified with interface name. */
281 if (peer->update_if)
282 {
283 ifp = if_lookup_by_name (peer->update_if);
284 if (! ifp)
285 return;
286
287 addr = bgp_update_address (ifp);
288 if (! addr)
289 return;
290
pauleb821182004-05-01 08:44:08 +0000291 bgp_bind_address (peer->fd, addr);
paul718e3742002-12-13 20:15:29 +0000292 }
293
294 /* Source is specified with IP address. */
295 if (peer->update_source)
pauleb821182004-05-01 08:44:08 +0000296 sockunion_bind (peer->fd, peer->update_source, 0, peer->update_source);
paul718e3742002-12-13 20:15:29 +0000297}
298
299/* BGP try to connect to the peer. */
300int
301bgp_connect (struct peer *peer)
302{
303 unsigned int ifindex = 0;
304
305 /* Make socket for the peer. */
pauleb821182004-05-01 08:44:08 +0000306 peer->fd = sockunion_socket (&peer->su);
307 if (peer->fd < 0)
paul718e3742002-12-13 20:15:29 +0000308 return -1;
309
310 /* If we can get socket for the peer, adjest TTL and make connection. */
311 if (peer_sort (peer) == BGP_PEER_EBGP)
pauleb821182004-05-01 08:44:08 +0000312 sockopt_ttl (peer->su.sa.sa_family, peer->fd, peer->ttl);
paul718e3742002-12-13 20:15:29 +0000313
pauleb821182004-05-01 08:44:08 +0000314 sockopt_reuseaddr (peer->fd);
315 sockopt_reuseport (peer->fd);
Paul Jakma0df7c912008-07-21 21:02:49 +0000316
Stephen Hemminger1423c802008-08-14 17:59:25 +0100317#ifdef IPTOS_PREC_INTERNETCONTROL
318 if (sockunion_family (&peer->su) == AF_INET)
319 setsockopt_ipv4_tos (peer->fd, IPTOS_PREC_INTERNETCONTROL);
320#endif
321
Paul Jakma0df7c912008-07-21 21:02:49 +0000322 if (peer->password)
323 bgp_md5_set_connect (peer->fd, &peer->su, peer->password);
paul718e3742002-12-13 20:15:29 +0000324
325 /* Bind socket. */
326 bgp_bind (peer);
327
328 /* Update source bind. */
329 bgp_update_source (peer);
330
331#ifdef HAVE_IPV6
332 if (peer->ifname)
333 ifindex = if_nametoindex (peer->ifname);
334#endif /* HAVE_IPV6 */
335
336 if (BGP_DEBUG (events, EVENTS))
ajs478ba052004-12-08 20:41:23 +0000337 plog_debug (peer->log, "%s [Event] Connect start to %s fd %d",
pauleb821182004-05-01 08:44:08 +0000338 peer->host, peer->host, peer->fd);
paul718e3742002-12-13 20:15:29 +0000339
340 /* Connect to the remote peer. */
pauleb821182004-05-01 08:44:08 +0000341 return sockunion_connect (peer->fd, &peer->su, htons (peer->port), ifindex);
paul718e3742002-12-13 20:15:29 +0000342}
343
344/* After TCP connection is established. Get local address and port. */
345void
346bgp_getsockname (struct peer *peer)
347{
348 if (peer->su_local)
349 {
paul22db9de2005-05-19 01:50:11 +0000350 sockunion_free (peer->su_local);
paul718e3742002-12-13 20:15:29 +0000351 peer->su_local = NULL;
352 }
353
354 if (peer->su_remote)
355 {
paul22db9de2005-05-19 01:50:11 +0000356 sockunion_free (peer->su_remote);
paul718e3742002-12-13 20:15:29 +0000357 peer->su_remote = NULL;
358 }
359
pauleb821182004-05-01 08:44:08 +0000360 peer->su_local = sockunion_getsockname (peer->fd);
361 peer->su_remote = sockunion_getpeername (peer->fd);
paul718e3742002-12-13 20:15:29 +0000362
363 bgp_nexthop_set (peer->su_local, peer->su_remote, &peer->nexthop, peer);
364}
365
366/* IPv6 supported version of BGP server socket setup. */
367#if defined (HAVE_IPV6) && ! defined (NRL)
368int
Paul Jakma3a02d1f2007-11-01 14:29:11 +0000369bgp_socket (struct bgp *bgp, unsigned short port, char *address)
paul718e3742002-12-13 20:15:29 +0000370{
gdt10d60ad2003-12-23 17:34:39 +0000371 int ret, en;
paul718e3742002-12-13 20:15:29 +0000372 struct addrinfo req;
373 struct addrinfo *ainfo;
374 struct addrinfo *ainfo_save;
375 int sock = 0;
376 char port_str[BUFSIZ];
377
378 memset (&req, 0, sizeof (struct addrinfo));
379
380 req.ai_flags = AI_PASSIVE;
381 req.ai_family = AF_UNSPEC;
382 req.ai_socktype = SOCK_STREAM;
Paul Jakma90b68762008-01-29 17:26:34 +0000383 snprintf (port_str, sizeof(port_str), "%d", port);
paul718e3742002-12-13 20:15:29 +0000384 port_str[sizeof (port_str) - 1] = '\0';
385
Paul Jakma3a02d1f2007-11-01 14:29:11 +0000386 ret = getaddrinfo (address, port_str, &req, &ainfo);
paul718e3742002-12-13 20:15:29 +0000387 if (ret != 0)
388 {
389 zlog_err ("getaddrinfo: %s", gai_strerror (ret));
390 return -1;
391 }
392
393 ainfo_save = ainfo;
394
395 do
396 {
397 if (ainfo->ai_family != AF_INET && ainfo->ai_family != AF_INET6)
398 continue;
399
400 sock = socket (ainfo->ai_family, ainfo->ai_socktype, ainfo->ai_protocol);
401 if (sock < 0)
402 {
ajs6099b3b2004-11-20 02:06:59 +0000403 zlog_err ("socket: %s", safe_strerror (errno));
paul718e3742002-12-13 20:15:29 +0000404 continue;
405 }
406
407 sockopt_reuseaddr (sock);
408 sockopt_reuseport (sock);
pauledd7c242003-06-04 13:59:38 +0000409
Stephen Hemminger1423c802008-08-14 17:59:25 +0100410#ifdef IPTOS_PREC_INTERNETCONTROL
411 if (ainfo->ai_family == AF_INET)
412 setsockopt_ipv4_tos (sock, IPTOS_PREC_INTERNETCONTROL);
413#endif
414
Stephen Hemmingere9a36702008-08-24 20:36:51 -0400415#ifdef IPV6_V6ONLY
416 /* Want only IPV6 on ipv6 socket (not mapped addresses) */
417 if (ainfo->ai_family == AF_INET6) {
418 int on = 1;
419 setsockopt (sock, IPPROTO_IPV6, IPV6_V6ONLY,
420 (void *) &on, sizeof (on));
421 }
422#endif
423
pauledd7c242003-06-04 13:59:38 +0000424 if (bgpd_privs.change (ZPRIVS_RAISE) )
425 zlog_err ("bgp_socket: could not raise privs");
paul718e3742002-12-13 20:15:29 +0000426
427 ret = bind (sock, ainfo->ai_addr, ainfo->ai_addrlen);
gdt10d60ad2003-12-23 17:34:39 +0000428 en = errno;
429 if (bgpd_privs.change (ZPRIVS_LOWER) )
430 zlog_err ("bgp_bind_address: could not lower privs");
431
paul718e3742002-12-13 20:15:29 +0000432 if (ret < 0)
433 {
ajs6099b3b2004-11-20 02:06:59 +0000434 zlog_err ("bind: %s", safe_strerror (en));
gdt10d60ad2003-12-23 17:34:39 +0000435 close(sock);
paul718e3742002-12-13 20:15:29 +0000436 continue;
437 }
pauledd7c242003-06-04 13:59:38 +0000438
paul718e3742002-12-13 20:15:29 +0000439 ret = listen (sock, 3);
440 if (ret < 0)
441 {
ajs6099b3b2004-11-20 02:06:59 +0000442 zlog_err ("listen: %s", safe_strerror (errno));
paul718e3742002-12-13 20:15:29 +0000443 close (sock);
444 continue;
445 }
Paul Jakma0df7c912008-07-21 21:02:49 +0000446
447 listnode_add (bm->listen_sockets, (void *)sock);
paul718e3742002-12-13 20:15:29 +0000448 thread_add_read (master, bgp_accept, bgp, sock);
449 }
450 while ((ainfo = ainfo->ai_next) != NULL);
451
452 freeaddrinfo (ainfo_save);
453
454 return sock;
455}
456#else
457/* Traditional IPv4 only version. */
458int
Paul Jakma3a02d1f2007-11-01 14:29:11 +0000459bgp_socket (struct bgp *bgp, unsigned short port, char *address)
paul718e3742002-12-13 20:15:29 +0000460{
461 int sock;
462 int socklen;
463 struct sockaddr_in sin;
hasso4a1a2712004-02-12 15:41:38 +0000464 int ret, en;
paul718e3742002-12-13 20:15:29 +0000465
466 sock = socket (AF_INET, SOCK_STREAM, 0);
467 if (sock < 0)
468 {
ajs6099b3b2004-11-20 02:06:59 +0000469 zlog_err ("socket: %s", safe_strerror (errno));
paul718e3742002-12-13 20:15:29 +0000470 return sock;
471 }
472
473 sockopt_reuseaddr (sock);
474 sockopt_reuseport (sock);
475
Stephen Hemminger1423c802008-08-14 17:59:25 +0100476#ifdef IPTOS_PREC_INTERNETCONTROL
477 setsockopt_ipv4_tos (sock, IPTOS_PREC_INTERNETCONTROL);
478#endif
479
paul718e3742002-12-13 20:15:29 +0000480 memset (&sin, 0, sizeof (struct sockaddr_in));
481
482 sin.sin_family = AF_INET;
483 sin.sin_port = htons (port);
484 socklen = sizeof (struct sockaddr_in);
Paul Jakma3a02d1f2007-11-01 14:29:11 +0000485
Paul Jakma90b68762008-01-29 17:26:34 +0000486 if (address && ((ret = inet_aton(address, &sin.sin_addr)) < 1))
Paul Jakma3a02d1f2007-11-01 14:29:11 +0000487 {
Paul Jakma90b68762008-01-29 17:26:34 +0000488 zlog_err("bgp_socket: could not parse ip address %s: %s",
489 address, safe_strerror (errno));
Paul Jakma3a02d1f2007-11-01 14:29:11 +0000490 return ret;
491 }
Paul Jakma6f0e3f62007-05-10 02:38:51 +0000492#ifdef HAVE_STRUCT_SOCKADDR_IN_SIN_LEN
paul718e3742002-12-13 20:15:29 +0000493 sin.sin_len = socklen;
Paul Jakma6f0e3f62007-05-10 02:38:51 +0000494#endif /* HAVE_STRUCT_SOCKADDR_IN_SIN_LEN */
paul718e3742002-12-13 20:15:29 +0000495
pauledd7c242003-06-04 13:59:38 +0000496 if ( bgpd_privs.change (ZPRIVS_RAISE) )
497 zlog_err ("bgp_socket: could not raise privs");
498
paul718e3742002-12-13 20:15:29 +0000499 ret = bind (sock, (struct sockaddr *) &sin, socklen);
gdt10d60ad2003-12-23 17:34:39 +0000500 en = errno;
501
502 if (bgpd_privs.change (ZPRIVS_LOWER) )
503 zlog_err ("bgp_socket: could not lower privs");
504
paul718e3742002-12-13 20:15:29 +0000505 if (ret < 0)
506 {
ajs6099b3b2004-11-20 02:06:59 +0000507 zlog_err ("bind: %s", safe_strerror (en));
paul718e3742002-12-13 20:15:29 +0000508 close (sock);
509 return ret;
510 }
pauledd7c242003-06-04 13:59:38 +0000511
paul718e3742002-12-13 20:15:29 +0000512 ret = listen (sock, 3);
513 if (ret < 0)
514 {
ajs6099b3b2004-11-20 02:06:59 +0000515 zlog_err ("listen: %s", safe_strerror (errno));
paul718e3742002-12-13 20:15:29 +0000516 close (sock);
517 return ret;
518 }
519
520 thread_add_read (bm->master, bgp_accept, bgp, sock);
521
522 return sock;
523}
524#endif /* HAVE_IPV6 && !NRL */