network.go 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284
  1. // Copyright 2015 flannel authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package ipsec
  15. import (
  16. "fmt"
  17. "net"
  18. "strconv"
  19. "sync"
  20. "time"
  21. log "github.com/coreos/flannel/Godeps/_workspace/src/github.com/golang/glog"
  22. "github.com/coreos/flannel/Godeps/_workspace/src/github.com/vishvananda/netlink"
  23. "github.com/coreos/flannel/Godeps/_workspace/src/golang.org/x/net/context"
  24. "github.com/coreos/flannel/backend"
  25. "github.com/coreos/flannel/subnet"
  26. )
  27. const (
  28. /*
  29. New IP header (Tunnel Mode) : 20
  30. SPI (ESP Header) : 4
  31. Sequence (ESP Header) : 4
  32. ESP-AES IV : 16
  33. ESP-AES Pad : 0-15
  34. Pad length (ESP Trailer) : 1
  35. Next Header (ESP Trailer) : 1
  36. ESP-SHA-256 ICV : 16
  37. */
  38. ipsecOverhead = 77
  39. udpEncapOverhead = 8
  40. defaultReqID = 11
  41. )
  42. type network struct {
  43. backend.SimpleNetwork
  44. name string
  45. password string
  46. UDPEncap bool
  47. sm subnet.Manager
  48. iked *CharonIKEDaemon
  49. }
  50. func newNetwork(name string, sm subnet.Manager, extIface *backend.ExternalInterface, UDPEncap bool, password string, ikeDaemon *CharonIKEDaemon, l *subnet.Lease) (*network, error) {
  51. n := &network{
  52. SimpleNetwork: backend.SimpleNetwork{
  53. SubnetLease: l,
  54. ExtIface: extIface,
  55. },
  56. name: name,
  57. sm: sm,
  58. iked: ikeDaemon,
  59. password: password,
  60. UDPEncap: UDPEncap,
  61. }
  62. return n, nil
  63. }
  64. func (n *network) Run(ctx context.Context) {
  65. wg := sync.WaitGroup{}
  66. defer wg.Wait()
  67. wg.Add(1)
  68. go func() {
  69. log.Info("Starting charon \n")
  70. n.startIKEDaemon()
  71. log.Info("Charon daemon exited")
  72. wg.Done()
  73. }()
  74. log.Info("Watching for new subnet leases")
  75. evts := make(chan []subnet.Event)
  76. wg.Add(1)
  77. go func() {
  78. subnet.WatchLeases(ctx, n.sm, n.name, n.SubnetLease, evts)
  79. log.Info("WatchLeases exited")
  80. wg.Done()
  81. }()
  82. initialEvtsBatch := <-evts
  83. for {
  84. err := n.handleInitialSubnetEvents(initialEvtsBatch)
  85. if err == nil {
  86. break
  87. }
  88. log.Error(err, " Retrying")
  89. time.Sleep(time.Second)
  90. }
  91. for {
  92. select {
  93. case evtsBatch := <-evts:
  94. n.handleSubnetEvents(evtsBatch)
  95. case <-ctx.Done():
  96. return
  97. }
  98. }
  99. }
  100. func (n *network) handleInitialSubnetEvents(batch []subnet.Event) error {
  101. log.Infof("Handling initial subnet events \n")
  102. installedPolicies, err := GetIPSECPolicies()
  103. if err != nil {
  104. return fmt.Errorf("error getting ipsec policies: %v", err)
  105. }
  106. evtMarker := make([]bool, len(batch))
  107. policyMarker := make([]bool, len(installedPolicies))
  108. for k, evt := range batch {
  109. if evt.Lease.Attrs.BackendType != "ipsec" {
  110. log.Warningf("Ignoring non-ipsec subnet event type:%v", evt.Lease.Attrs.BackendType)
  111. evtMarker[k] = true
  112. continue
  113. }
  114. for j, policy := range installedPolicies {
  115. if (policy.Src.String() == n.SubnetLease.Subnet.ToIPNet().String()) && (policy.Dst.String() == evt.Lease.Subnet.ToIPNet().String()) {
  116. if policy.Dir != netlink.XFRM_DIR_OUT {
  117. continue
  118. }
  119. if (policy.Tmpls[0].Src.Equal(n.SubnetLease.Attrs.PublicIP.ToIP())) && (policy.Tmpls[0].Dst.Equal(evt.Lease.Attrs.PublicIP.ToIP())) {
  120. evtMarker[k] = true
  121. policyMarker[j] = true
  122. }
  123. }
  124. }
  125. }
  126. for k, marker := range evtMarker {
  127. if !marker {
  128. if err := n.AddIPSECPolicies(&batch[k].Lease, defaultReqID); err != nil {
  129. log.Errorf("error adding initial ipsec policy: %v", err)
  130. }
  131. }
  132. }
  133. for _, evt := range batch {
  134. if err := n.iked.LoadSharedKey(evt.Lease.Attrs.PublicIP.String(), n.password); err != nil {
  135. log.Errorf("error loading initial shared key: %v", err)
  136. }
  137. if err := n.iked.LoadConnection(n.SubnetLease, &evt.Lease, strconv.Itoa(defaultReqID), strconv.FormatBool(n.UDPEncap)); err != nil {
  138. log.Errorf("error loading initial connection into IKE daemon: %v", err)
  139. }
  140. }
  141. for j, marker := range policyMarker {
  142. if !marker {
  143. if installedPolicies[j].Dir != netlink.XFRM_DIR_OUT {
  144. continue
  145. }
  146. if err := n.DeleteIPSECPolicies(installedPolicies[j].Src, installedPolicies[j].Dst, installedPolicies[j].Tmpls[0].Src, installedPolicies[j].Tmpls[0].Dst, installedPolicies[j].Tmpls[0].Reqid); err != nil {
  147. log.Errorf("error deleting installed policy")
  148. }
  149. }
  150. }
  151. return nil
  152. }
  153. func (n *network) handleSubnetEvents(batch []subnet.Event) {
  154. for _, evt := range batch {
  155. switch evt.Type {
  156. case subnet.EventAdded:
  157. log.Info("Subnet added: ", evt.Lease.Subnet)
  158. if evt.Lease.Attrs.BackendType != "ipsec" {
  159. log.Warningf("Ignoring non-ipsec event: type: %v", evt.Lease.Attrs.BackendType)
  160. continue
  161. }
  162. if evt.Lease.Subnet.Equal(n.SubnetLease.Subnet) {
  163. log.Warningf("Ignoring own lease add event: %+v", evt.Lease)
  164. continue
  165. }
  166. if err := n.AddIPSECPolicies(&evt.Lease, defaultReqID); err != nil {
  167. log.Errorf("error adding ipsec policy: %v", err)
  168. }
  169. if err := n.iked.LoadSharedKey(evt.Lease.Attrs.PublicIP.String(), n.password); err != nil {
  170. log.Errorf("error loading shared key into IKE daemon: %v", err)
  171. }
  172. if err := n.iked.LoadConnection(n.SubnetLease, &evt.Lease, strconv.Itoa(defaultReqID), strconv.FormatBool(n.UDPEncap)); err != nil {
  173. log.Errorf("error loading connection into IKE daemon: %v", err)
  174. }
  175. case subnet.EventRemoved:
  176. log.Info("Subnet removed: ", evt.Lease.Subnet)
  177. if evt.Lease.Attrs.BackendType != "ipsec" {
  178. log.Warningf("Ignoring non-ipsec event: type: %v", evt.Lease.Attrs.BackendType)
  179. continue
  180. }
  181. if evt.Lease.Subnet.Equal(n.SubnetLease.Subnet) {
  182. log.Warningf("Ignoring own lease remove event: %+v", evt.Lease)
  183. continue
  184. }
  185. if err := n.iked.UnloadCharonConnection(n.SubnetLease, &evt.Lease); err != nil {
  186. log.Errorf("error unloading charon connections: %v", err)
  187. }
  188. if err := n.DeleteIPSECPolicies(n.SubnetLease.Subnet.ToIPNet(), evt.Lease.Subnet.ToIPNet(), n.SubnetLease.Attrs.PublicIP.ToIP(), evt.Lease.Attrs.PublicIP.ToIP(), defaultReqID); err != nil {
  189. log.Errorf("error deleting ipsec policies: %v", err)
  190. }
  191. }
  192. }
  193. }
  194. func (n *network) startIKEDaemon() {
  195. if err := n.iked.Run(); err != nil {
  196. log.Info("error starting IKE daemon: ", err)
  197. }
  198. }
  199. func (n *network) MTU() int {
  200. mtu := n.ExtIface.Iface.MTU - ipsecOverhead
  201. if n.UDPEncap {
  202. mtu -= udpEncapOverhead
  203. }
  204. return mtu
  205. }
  206. func (n *network) AddIPSECPolicies(remoteLease *subnet.Lease, reqID int) error {
  207. err := AddXFRMPolicy(n.SubnetLease, remoteLease, netlink.XFRM_DIR_OUT, reqID)
  208. if err != nil {
  209. return fmt.Errorf("error adding ipsec out policy: %v", err)
  210. }
  211. err = AddXFRMPolicy(remoteLease, n.SubnetLease, netlink.XFRM_DIR_IN, reqID)
  212. if err != nil {
  213. return fmt.Errorf("error adding ipsec in policy: %v", err)
  214. }
  215. err = AddXFRMPolicy(remoteLease, n.SubnetLease, netlink.XFRM_DIR_FWD, reqID)
  216. if err != nil {
  217. return fmt.Errorf("error adding ipsec fwd policy: %v", err)
  218. }
  219. return nil
  220. }
  221. func (n *network) DeleteIPSECPolicies(localSubnet, remoteSubnet *net.IPNet, localPublicIP, remotePublicIP net.IP, reqID int) error {
  222. err := DeleteXFRMPolicy(localSubnet, remoteSubnet, localPublicIP, remotePublicIP, netlink.XFRM_DIR_OUT, reqID)
  223. if err != nil {
  224. return fmt.Errorf("error deleting ipsec out policy: %v", err)
  225. }
  226. err = DeleteXFRMPolicy(remoteSubnet, localSubnet, remotePublicIP, localPublicIP, netlink.XFRM_DIR_IN, reqID)
  227. if err != nil {
  228. return fmt.Errorf("error deleting ipsec in policy: %v", err)
  229. }
  230. err = DeleteXFRMPolicy(remoteSubnet, localSubnet, remotePublicIP, localPublicIP, netlink.XFRM_DIR_FWD, reqID)
  231. if err != nil {
  232. return fmt.Errorf("error deleting ipsec fwd policy: %v", err)
  233. }
  234. return nil
  235. }