diff options
author | dheerajpdsk <p.dheeraj.srujan.kumar@intel.com> | 2022-05-06 02:48:05 +0300 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-05-06 02:48:05 +0300 |
commit | ca8d06bc610af08c2d3efc487aa9519989b743e6 (patch) | |
tree | c557da2136640a8ce48439f19fe5f7071faffeca /meta-google/recipes-google/ncsi | |
parent | 7cf0c1cd0ce835d1833509b7b911e8a97380278b (diff) | |
parent | 18f97faa411078b95d042d207f5fff32bc8ece1d (diff) | |
download | openbmc-ca8d06bc610af08c2d3efc487aa9519989b743e6.tar.xz |
Update
Diffstat (limited to 'meta-google/recipes-google/ncsi')
6 files changed, 174 insertions, 44 deletions
diff --git a/meta-google/recipes-google/ncsi/files/25-gbmc-ncsi-clear-ip.sh.in b/meta-google/recipes-google/ncsi/files/25-gbmc-ncsi-clear-ip.sh.in new file mode 100644 index 000000000..e17a5e200 --- /dev/null +++ b/meta-google/recipes-google/ncsi/files/25-gbmc-ncsi-clear-ip.sh.in @@ -0,0 +1,26 @@ +# Copyright 2021 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +[ -z "${gbmc_ncsi_clear_ip-}" ] || exit + +source /usr/libexec/ncsid_lib.sh || exit + +gbmc_ncsi_clear_ip_hook() { + UpdateIP xyz.openbmc_project.Network '@NCSI_IF@' '0.0.0.0' '0' || true + UpdateIP xyz.openbmc_project.Network '@NCSI_IF@' '::' '0' || true +} + +GBMC_BR_DHCP_HOOKS+=(gbmc_ncsi_clear_ip_hook) + +gbmc_ncsi_clear_ip=1 diff --git a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-deprecated-ips.sh.in b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-deprecated-ips.sh.in new file mode 100644 index 000000000..9d9f7899e --- /dev/null +++ b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-deprecated-ips.sh.in @@ -0,0 +1,130 @@ +# Copyright 2021 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +[ -z "${gbmc_ncsi_br_deprecated_ips_lib-}" ] || return + +source /usr/share/network/lib.sh || exit + +gbmc_ncsi_br_deprecated_ips_init= +gbmc_ncsi_br_deprecated_ips_confip= +gbmc_ncsi_br_deprecated_ips_lastip= + +gbmc_ncsi_br_deprecated_ips_update() { + [ -n "$gbmc_ncsi_br_deprecated_ips_init" ] || return + [ "$gbmc_ncsi_br_deprecated_ips_confip" != "$gbmc_ncsi_br_deprecated_ips_lastip" ] || return + gbmc_ncsi_br_deprecated_ips_confip="$gbmc_ncsi_br_deprecated_ips_lastip" + + printf 'gBMC Bridge NCSI Deprecated Addrs: %s\n' \ + "${gbmc_ncsi_br_deprecated_ips_lastip:-(deleted)}" >&2 + + local contents= + local nfcontents= + if [ -n "$gbmc_ncsi_br_deprecated_ips_lastip" ]; then + local pfx_bytes=() + ip_to_bytes pfx_bytes "$gbmc_ncsi_br_deprecated_ips_lastip" + + local pfx="$(ip_bytes_to_str pfx_bytes)" + (( pfx_bytes[9] &= 0xf0 )) + local stateless_pfx="$(ip_bytes_to_str pfx_bytes)" + pfx_bytes[8]=0 + pfx_bytes[9]=0 + local host_pfx="$(ip_bytes_to_str pfx_bytes)" + read -r -d '' contents <<EOF +[Address] +Address=$pfx/128 +PreferredLifetime=0 +[Address] +Address=$stateless_pfx/128 +PreferredLifetime=0 +[Address] +Address=$host_pfx/128 +PreferredLifetime=0 +EOF + read -r -d '' nfcontents <<EOF +table inet filter { + chain ncsi_input { + ip6 saddr != $pfx/76 ip6 daddr $pfx/76 goto ncsi_gbmc_br_pub_input + } + chain ncsi_forward { + ip6 saddr != $pfx/76 ip6 daddr $pfx/76 accept + } +} +EOF + fi + + local file + for file in /run/systemd/network/{00,}-bmc-@NCSI_IF@.network.d/50-deprecated.conf; do + mkdir -p -m 755 "$(dirname "$file")" + if [ -z "$contents" ]; then + rm -f "$file" + else + printf '%s' "$contents" >"$file" + fi + done + + # Ensure that systemd-networkd performs a reconfiguration as it doesn't + # currently check the mtime of drop-in files. + touch -c /etc/systemd/network/*-bmc-@NCSI_IF@.network + + if [ "$(systemctl is-active systemd-networkd)" != 'inactive' ]; then + networkctl reload && networkctl reconfigure @NCSI_IF@ + fi + + local rfile=/run/nftables/40-gbmc-ncsi-br.rules + mkdir -p -m 755 "$(dirname "$rfile")" + if [ -z "$nfcontents" ]; then + rm -f "$rfile" + else + printf '%s' "$nfcontents" >"$rfile" + fi + systemctl reset-failed nftables && systemctl --no-block reload-or-restart nftables || true +} + +gbmc_ncsi_br_deprecated_ips_hook() { + if [ "$change" = 'init' ]; then + gbmc_ncsi_br_deprecated_ips_init=1 + gbmc_ip_monitor_defer + elif [ "$change" = 'defer' ]; then + gbmc_ncsi_br_deprecated_ips_update + elif [ "$change" = 'addr' -a "$intf" = 'gbmcbr' ] && + [ "$scope" = 'global' -a "$fam" = 'inet6' ]; then + local pfx_bytes=() + ip_to_bytes pfx_bytes "$ip" || return + # No ULA Addresses + if (( pfx_bytes[0] & 0xfe == 0xfc )); then + return + fi + # We only want to allow a <pfx>::fd0x address, where x>0 + if (( pfx_bytes[8] != 0xfd || pfx_bytes[9] & 0xf == 0 )); then + return + fi + for (( i = 10; i < 16; ++i )); do + if (( pfx_bytes[i] != 0 )); then + return + fi + done + if [ "$action" = 'add' -a "$ip" != "$gbmc_ncsi_br_deprecated_ips_lastip" ]; then + gbmc_ncsi_br_deprecated_ips_lastip="$ip" + gbmc_ip_monitor_defer + fi + if [ "$action" = 'del' -a "$ip" = "$gbmc_ncsi_br_deprecated_ips_lastip" ]; then + gbmc_ncsi_br_deprecated_ips_lastip= + gbmc_ip_monitor_defer + fi + fi +} + +GBMC_IP_MONITOR_HOOKS+=(gbmc_ncsi_br_deprecated_ips_hook) + +gbmc_ncsi_br_deprecated_ips_lib=1 diff --git a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-pub-addr.sh.in b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-pub-addr.sh.in index 5adc41328..793403348 100644 --- a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-pub-addr.sh.in +++ b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-br-pub-addr.sh.in @@ -63,6 +63,8 @@ Destination=$stateless_pfx/76 Type=unreachable Metric=1024 EOF + # Delete DHCP configured addresses if we have a host published address + rm -f /etc/systemd/network/{00,}-bmc-gbmcbr.network.d/50-public.conf fi local file diff --git a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-ip-from-ra.sh.in b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-ip-from-ra.sh.in index 80bd34f04..2788f7f19 100755 --- a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-ip-from-ra.sh.in +++ b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-ip-from-ra.sh.in @@ -41,6 +41,9 @@ set_net() { echo "Found prefix $pfx from $rtr" >&2 + # We no longer need NCSId if we are in this configuration + systemctl stop --no-block ncsid@"$NCSI_IF" || true + # Delete any stale IP Addresses from the primary interface as we won't use them UpdateIP xyz.openbmc_project.Network "$NCSI_IF" '0.0.0.0' '0' || true UpdateIP xyz.openbmc_project.Network "$NCSI_IF" '::' '0' || true @@ -70,7 +73,6 @@ EOF touch -c /lib/systemd/network/*-bmc-gbmcbr.network || true contents='[Network]'$'\n' - contents+="Address=$pfx/128"$'\n' contents+="Gateway=$rtr"$'\n' for file in /run/systemd/network/{00,}-bmc-"$NCSI_IF".network.d/49-public-ra.conf; do mkdir -p -m 755 "$(dirname "$file")" @@ -81,21 +83,6 @@ EOF if [ "$(systemctl is-active systemd-networkd)" != 'inactive' ]; then networkctl reload && networkctl reconfigure gbmcbr "$NCSI_IF" || true fi - - read -r -d '' contents <<EOF -table inet filter { - chain ncsi_input { - ip6 saddr != $pfx/76 ip6 daddr $pfx/76 goto ncsi_gbmc_br_pub_input - } - chain ncsi_forward { - ip6 saddr != $pfx/76 ip6 daddr $pfx/76 accept - } -} -EOF - rfile=/run/nftables/40-gbmc-ncsi-ra.rules - mkdir -p -m 755 "$(dirname "$rfile")" - printf '%s' "$contents" >"$rfile" - systemctl reset-failed nftables && systemctl --no-block restart nftables || true } w=60 diff --git a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-nft.sh.in b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-nft.sh.in index 7a630f5fe..074ec5785 100644 --- a/meta-google/recipes-google/ncsi/files/gbmc-ncsi-nft.sh.in +++ b/meta-google/recipes-google/ncsi/files/gbmc-ncsi-nft.sh.in @@ -35,45 +35,18 @@ gbmc_ncsi_nft_update() { fi local ip6="$gbmc_ncsi_nft_lastip6" - local pfx= if [ -n "$ip6" ]; then contents+=" ip6 daddr $ip6/128 goto ncsi_legacy_input"$'\n' - - local ip_bytes=() - ip_to_bytes ip_bytes "$ip6" - # If our address has enough spare bits for appending the BMC suffix - # then we add a rule that allows the BMC subnet. That is, we need a /64 - # as input. - local i - for (( i = 8; i < 16; i++ )); do - if (( ip_bytes[$i] != 0 )); then - ip_bytes=() - break - fi - done - if (( ${#ip_bytes[@]} != 0 )); then - ip_bytes[8]=0xfd - pfx="$(ip_bytes_to_str ip_bytes)" - contents+=" ip6 saddr != $pfx/76 ip6 daddr" - contents+=" $pfx/76 goto ncsi_gbmc_br_pub_input"$'\n' - fi fi contents+=' }'$'\n' - contents+=' chain ncsi_forward {'$'\n' - if [ -n "$pfx" ]; then - contents+=" ip6 saddr != $pfx/76 ip6 daddr $pfx/76 accept"$'\n' - fi - contents+=' }'$'\n' contents+='}'$'\n' local rfile=/run/nftables/40-gbmc-ncsi-in.rules mkdir -p -m 755 "$(dirname "$rfile")" printf '%s' "$contents" >"$rfile" - echo 'Restarting nftables' >&2 - systemctl reset-failed nftables - systemctl --no-block restart nftables + systemctl reset-failed nftables && systemctl --no-block reload-or-restart nftables || true } gbmc_ncsi_nft_hook() { diff --git a/meta-google/recipes-google/ncsi/gbmc-ncsi-config.bb b/meta-google/recipes-google/ncsi/gbmc-ncsi-config.bb index 10ef56a76..0312f0502 100644 --- a/meta-google/recipes-google/ncsi/gbmc-ncsi-config.bb +++ b/meta-google/recipes-google/ncsi/gbmc-ncsi-config.bb @@ -18,7 +18,9 @@ SRC_URI += " \ file://gbmc-ncsi-sslh.service \ file://gbmc-ncsi-nft.sh.in \ file://gbmc-ncsi-br-pub-addr.sh.in \ + file://gbmc-ncsi-br-deprecated-ips.sh.in \ file://gbmc-ncsi-set-nicenabled.service.in \ + file://25-gbmc-ncsi-clear-ip.sh.in \ " S = "${WORKDIR}" @@ -35,6 +37,7 @@ RDEPENDS:${PN} += " \ " FILES:${PN} += " \ + ${datadir}/gbmc-br-dhcp \ ${datadir}/gbmc-ip-monitor \ ${systemd_unitdir} \ " @@ -100,6 +103,15 @@ do_install:append() { sed "s,@NCSI_IF@,$if_name,g" ${WORKDIR}/gbmc-ncsi-br-pub-addr.sh.in \ >${WORKDIR}/gbmc-ncsi-br-pub-addr.sh install -m644 ${WORKDIR}/gbmc-ncsi-br-pub-addr.sh $mondir + sed "s,@NCSI_IF@,$if_name,g" ${WORKDIR}/gbmc-ncsi-br-deprecated-ips.sh.in \ + >${WORKDIR}/gbmc-ncsi-br-deprecated-ips.sh + install -m644 ${WORKDIR}/gbmc-ncsi-br-deprecated-ips.sh $mondir + + dhcpdir=${D}${datadir}/gbmc-br-dhcp/ + install -d -m0755 $dhcpdir + sed "s,@NCSI_IF@,$if_name,g" ${WORKDIR}/25-gbmc-ncsi-clear-ip.sh.in \ + >${WORKDIR}/25-gbmc-ncsi-clear-ip.sh + install -m644 ${WORKDIR}/25-gbmc-ncsi-clear-ip.sh $dhcpdir sed "s,@NCSI_IF@,$if_name,g" ${WORKDIR}/gbmc-ncsi-set-nicenabled.service.in \ >${D}${systemd_system_unitdir}/gbmc-ncsi-set-nicenabled.service |