/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to plugin-helpers/mandos-client-iprouteadddel.c

  • Committer: Teddy Hogeborn
  • Date: 2015-07-05 18:36:23 UTC
  • mto: This revision was merged to the branch mainline in revision 759.
  • Revision ID: teddy@recompile.se-20150705183623-k7yokhi0wpvs61iw
Add plugin for mandos-client to add and delete local routes.

* Makefile (LIBNL3_CFLAGS, LIBNL3_LIBS): New; add for netlink library.
  (PLUGIN_HELPERS): Add "plugin-helpers/mandos-client-iprouteadddel".
  (plugin-helpers/mandos-client-iprouteadddel): New.
* plugin-helpers/mandos-client-iprouteadddel.c: New.
* plugins.d/mandos_client (add_remove_local_route): Rename
                                                    "remove_arg" to
                                                    "delete_arg".  All
                                                    users changed.

Show diffs side-by-side

added added

removed removed

Lines of Context:
2
2
/* 
3
3
 * iprouteadddel - Add or delete direct route to a local IP address
4
4
 * 
5
 
 * Copyright © 2015-2018, 2021-2022 Teddy Hogeborn
6
 
 * Copyright © 2015-2018, 2021-2022 Björn Påhlsson
7
 
 * 
8
 
 * This file is part of Mandos.
9
 
 * 
10
 
 * Mandos is free software: you can redistribute it and/or modify it
11
 
 * under the terms of the GNU General Public License as published by
12
 
 * the Free Software Foundation, either version 3 of the License, or
13
 
 * (at your option) any later version.
14
 
 * 
15
 
 * Mandos is distributed in the hope that it will be useful, but
 
5
 * Copyright © 2015 Teddy Hogeborn
 
6
 * Copyright © 2015 Björn Påhlsson
 
7
 * 
 
8
 * This program is free software: you can redistribute it and/or
 
9
 * modify it under the terms of the GNU General Public License as
 
10
 * published by the Free Software Foundation, either version 3 of the
 
11
 * License, or (at your option) any later version.
 
12
 * 
 
13
 * This program is distributed in the hope that it will be useful, but
16
14
 * WITHOUT ANY WARRANTY; without even the implied warranty of
17
15
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
18
16
 * General Public License for more details.
19
17
 * 
20
18
 * You should have received a copy of the GNU General Public License
21
 
 * along with Mandos.  If not, see <http://www.gnu.org/licenses/>.
 
19
 * along with this program.  If not, see
 
20
 * <http://www.gnu.org/licenses/>.
22
21
 * 
23
22
 * Contact the authors at <mandos@recompile.se>.
24
23
 */
25
24
 
26
 
#define _GNU_SOURCE             /* program_invocation_short_name */
 
25
#define _GNU_SOURCE             /* asprintf(),
 
26
                                   program_invocation_short_name */
 
27
#include <iso646.h>             /* not, or, and */
27
28
#include <stdbool.h>            /* bool, false, true */
28
 
#include <argp.h>               /* argp_program_version,
29
 
                                   argp_program_bug_address,
30
 
                                   struct argp_option,
31
 
                                   struct argp_state, ARGP_KEY_ARG,
32
 
                                   argp_usage(), ARGP_KEY_END,
33
 
                                   ARGP_ERR_UNKNOWN, struct argp,
34
 
                                   argp_parse(), ARGP_IN_ORDER */
35
 
#include <errno.h>              /* errno,
36
 
                                   program_invocation_short_name,
37
 
                                   error_t, EINVAL, ENOMEM */
38
 
#include <stdio.h>              /* fprintf(), stderr, perror(), FILE,
39
 
                                   vfprintf() */
40
 
#include <stdarg.h>             /* va_list, va_start(), vfprintf() */
41
 
#include <stdlib.h>             /* EXIT_SUCCESS */
42
 
#include <netlink/netlink.h>    /* struct nl_addr, nl_addr_parse(),
43
 
                                   nl_geterror(),
44
 
                                   nl_addr_get_family(), NLM_F_EXCL,
45
 
                                   nl_addr_put() */
46
 
#include <stddef.h>             /* NULL */
47
 
#include <netlink/route/route.h>/* struct rtnl_route,
48
 
                                   struct rtnl_nexthop, NETLINK_ROUTE,
49
 
                                   rtnl_route_alloc(),
50
 
                                   rtnl_route_set_family(),
51
 
                                   rtnl_route_set_protocol(),
52
 
                                   RTPROT_BOOT,
53
 
                                   rtnl_route_set_scope(),
54
 
                                   RT_SCOPE_LINK,
55
 
                                   rtnl_route_set_type(), RTN_UNICAST,
56
 
                                   rtnl_route_set_dst(),
57
 
                                   rtnl_route_set_table(),
58
 
                                   RT_TABLE_MAIN,
59
 
                                   rtnl_route_nh_alloc(),
60
 
                                   rtnl_route_nh_set_ifindex(),
61
 
                                   rtnl_route_add_nexthop(),
62
 
                                   rtnl_route_add(),
63
 
                                   rtnl_route_delete(),
64
 
                                   rtnl_route_put(),
65
 
                                   rtnl_route_nh_free() */
66
 
#include <netlink/socket.h>     /* struct nl_sock, nl_socket_alloc(),
67
 
                                   nl_connect(), nl_socket_free() */
68
 
#include <strings.h>            /* strcasecmp() */
69
 
#include <sys/socket.h>         /* AF_UNSPEC, AF_INET6, AF_INET */
70
 
#include <sysexits.h>           /* EX_USAGE, EX_OSERR */
71
 
#include <netlink/route/link.h> /* struct rtnl_link,
72
 
                                   rtnl_link_get_kernel(),
73
 
                                   rtnl_link_get_ifindex(),
74
 
                                   rtnl_link_put() */
75
 
#include <netinet/in.h>         /* sa_family_t */
 
29
#include <stdio.h>              /* vfprintf(), stderr, stdout */
 
30
#include <stdarg.h>             /* va_list, va_start */
 
31
#include <errno.h>              /* perror(), errno,
 
32
                                   program_invocation_short_name */
 
33
#include <argp.h>               /* struct argp_option, error_t, struct
 
34
                                   argp_state, struct argp,
 
35
                                   argp_parse(), ARGP_KEY_ARG,
 
36
                                   ARGP_KEY_END, ARGP_ERR_UNKNOWN */
76
37
#include <inttypes.h>           /* PRIdMAX, intmax_t */
77
 
#include <stdint.h>             /* uint8_t */
 
38
#include <sysexits.h>           /* EX_OSERR */
78
39
 
 
40
/* #include <linux/netlink.h> */
 
41
/* #include <netlink/netlink.h> */
 
42
/* #include <netlink/socket.h> */
 
43
#include <netlink/netlink.h>
 
44
#include <netlink/socket.h>
 
45
#include <netlink/cache.h>
 
46
#include <netlink/route/link.h>  /* libnl xxx */
 
47
#include <netlink/route/route.h> /* libnl xxx */
79
48
 
80
49
bool debug = false;
81
50
const char *argp_program_version = "mandos-client-iprouteadddel " VERSION;
93
62
__attribute__((format (gnu_printf, 2, 3), nonnull))
94
63
int fprintf_plus(FILE *stream, const char *format, ...){
95
64
  va_list ap;
96
 
  va_start(ap, format);
 
65
  va_start (ap, format);
97
66
  
98
67
  fprintf(stream, "Mandos plugin helper %s: ",
99
68
          program_invocation_short_name);
239
208
  /* Create nexthop */
240
209
  nexthop = rtnl_route_nh_alloc();
241
210
  if(nexthop == NULL){
242
 
    fprintf_plus(stderr, "Failed to get netlink route nexthop\n");
 
211
    fprintf_plus(stderr, "Failed to get netlink route nexthop:\n");
243
212
    exitcode = EX_OSERR;
244
213
    goto end;
245
214
  }
251
220
  }
252
221
  /* Set interface index number on nexthop object */
253
222
  rtnl_route_nh_set_ifindex(nexthop, ifindex);
254
 
  /* Set route to use nexthop object */
 
223
  /* Set route tu use nexthop object */
255
224
  rtnl_route_add_nexthop(route, nexthop);
256
225
  /* Add or delete route? */
257
226
  if(arguments.add){