Commit graph

23914 commits

Author SHA1 Message Date
Beniamino Galvani
bfece9d4fc dhcp: nettools: fix parsing of search domains option
'first' was never modified and so the dot was never added.

Fixes: 6adade6f21 ('dhcp: add nettools dhcp4 client')

https://bugzilla.redhat.com/show_bug.cgi?id=1783981
(cherry picked from commit 9aa00a8a14)
(cherry picked from commit ea22135384)
2019-12-17 14:36:23 +01:00
Thomas Haller
f200573a95 all: fix wrong "gs_free GError *" declarations
This is a bug and leads either to a leak or a crash.

(cherry picked from commit 4a3ca7115a)
(cherry picked from commit 809d70ee64)
2019-12-16 17:46:59 +01:00
Thomas Haller
00cf235a7a checkpatch: catch "gs_free GError *" declations
(cherry picked from commit ec0adbfaf0)
(cherry picked from commit 2fa4827eb9)
2019-12-16 17:46:10 +01:00
Beniamino Galvani
a3ed90bdbc device: don't reapply IP configuration if the ifindex is missing
Assertions will fail in ip_config_merge_and_apply() if the device
doesn't have an ifindex. Reproducible with:

 $ nmcli connection add type ovs-bridge ifname ovs0 ipv4.method disabled ipv6.method disabled
 Connection 'ovs-bridge-ovs0' (1d5e794b-10ad-4b2b-aa7c-5ca7e34b0a55) successfully added

 $ nmcli device reapply ovs0
 Error: Reapplying connection to device '(null)' (/org/freedesktop/NetworkManager/Devices/16) failed: Remote peer disconnected

 $ journalctl -u NetworkManager -e
 ...
 NetworkManager[73824]: nm_ip4_config_add_dependent_routes: assertion 'ifindex > 0' failed
 systemd[1]: NetworkManager.service: Main process exited, code=dumped, status=5/TRAP
 ...

(cherry picked from commit 6d6e1402dc)
(cherry picked from commit f1d4853927)
2019-12-14 21:08:27 +01:00
Beniamino Galvani
65d37a3bfa ovs: check state before starting ip configuration after link change
When the link becomes available, check that the device is in the
ip-config state before starting ip configuration. Also, reset the
'waiting_for_interface' flag when the device deactivates.

https://bugzilla.redhat.com/show_bug.cgi?id=1781165
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/358
(cherry picked from commit 0738c10445)
(cherry picked from commit 3381299562)
2019-12-14 21:08:26 +01:00
Beniamino Galvani
74649429df manager: forbid autoactivation of parent when it is blocked by user request
If a device is being autoactivated and requires a parent that is
blocked due to user request, the autoactivation attempt should fail
because NM shouldn't overrule the user decision.

https://bugzilla.redhat.com/show_bug.cgi?id=1765566
(cherry picked from commit f2dbf8fbc0)
(cherry picked from commit 61d431a9e8)
2019-12-11 13:55:32 +01:00
Beniamino Galvani
269deeebf8 merge: branch 'bg/mtu-reapply-rh1779162'
https://bugzilla.redhat.com/show_bug.cgi?id=1779162
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/356
(cherry picked from commit ce2cceef83)
(cherry picked from commit 73a2557a6f)
2019-12-11 13:54:49 +01:00
Beniamino Galvani
0064401e35 device: always allow reapply of MTU from wired setting
Many device types take the MTU value from the wired setting; usually
they don't implement the can_reapply_change() method and so the MTU
can't be changed with the Reapply() API.

Instead of implementing the method for all such devices to support the
same property (adding a lot of duplicated code), add a check in
NMDevice to allow the reapply of MTU when we recognize that the device
uses the MTU from the wired setting.

Device types can still decide to implement can_reapply_change() and
support whatever properties they want, even from the wired setting.

(cherry picked from commit 9339d3310e)
(cherry picked from commit 1191eba15a)
2019-12-11 13:54:35 +01:00
Beniamino Galvani
4134023a29 infiniband: allow reapply of MTU
(cherry picked from commit ceeefa82c5)
(cherry picked from commit 1aedf60244)
2019-12-11 13:54:32 +01:00
Thomas Haller
ee032f79df settings: assert that we don't leak error variable in impl_settings_load_connections()
(cherry picked from commit e0569ee575)
(cherry picked from commit 7e8a5d98e3)
2019-12-09 09:55:51 +01:00
Thomas Haller
aa545d5b58 settings: fix use after free in keyfile's load_connections()
Fixes: d35d3c468a ('settings: rework tracking settings connections and settings plugins')
(cherry picked from commit eb642fecdf)
(cherry picked from commit 6d37f690ad)
2019-12-09 09:55:49 +01:00
Beniamino Galvani
8274cc1353 device: don't transition assumed devices to FAILED before ACTIVATED
If the activation of an assumed device fails, we first set the device
state to FAILED and then to ACTIVATED. In the FAILED state, the active
connection transitions to DEACTIVATED and clears its device pointer;
hence we end up with an inconsistent state which causes assertion
failures in other parts of the code (for example, get_best_ip_config()
assumes that the device of the best active connection is not NULL).

Don't first transition to FAILED and then to ACTIVATED, just set the
latter.

https://bugzilla.redhat.com/show_bug.cgi?id=1737774
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/351
(cherry picked from commit 93e9010b75)
(cherry picked from commit 366b90db87)
2019-12-05 17:14:31 +01:00
Beniamino Galvani
80bb91d8e6 manager: don't activate device if the parent is missing
In multiple places we currently proceed to creating a virtual device
even if the connection specifies a parent device which is
missing. This can be easily reproduced with:

  nmcli con add type vxlan ifname vxlan1 \
                vxlan.parent not-exists \
                id 43 remote 172.25.1.1

which creates a vxlan1 interface without activating any
connection. Add a check to prevent this.

https://bugzilla.redhat.com/show_bug.cgi?id=1774074
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/344
(cherry picked from commit a73efb059f)
2019-11-29 11:13:27 +01:00
Beniamino Galvani
6c8f42fdd1 systemd: use busctl instead of dbus-send
While dbus-send may not be installed, busctl is shipped with systemd
and so it should be always available.

(cherry picked from commit a2e6e7f2a9)
2019-11-29 10:49:08 +01:00
Thomas Haller
37c571a72a dispatcher: use free() to free memory allocated with malloc()
In practice, nowadays g_free() is the same as free(), so there is no
difference. However, we still should not mix the two and use free()
for data that was allocated with malloc() -- in this case, the memory
was allocated by libc's realpath().

(cherry picked from commit 3ade6dacfc)
2019-11-27 12:05:24 +01:00
Thomas Haller
467296ed17 dispatcher: fix detection of no-wait dispatcher scripts
While at it, use NM_STR_HAS_SUFFIX() with the string literal.

Fixes: 35a428f168 ('dispatcher: look for the scripts in /usr/lib as well')
(cherry picked from commit 1c2889faee)
2019-11-27 12:05:23 +01:00
Lubomir Rintel
cbecc4318c release: bump version to 1.20.9 (development) 2019-11-25 14:22:57 +01:00
Lubomir Rintel
4ef92efc07 release: bump version to 1.20.8 2019-11-25 13:58:32 +01:00
Lubomir Rintel
d437d58ebc release: update NEWS 2019-11-25 13:58:32 +01:00
Thomas Haller
962297f908 gitlab-ci: run tests on extra distributions only manually
For the moment, we use docker images from dockerhub, which require
a lot of extra overhead to prepare and install the test environment.
This should be improved, by using more suitable container images.

Anyway, for now to alleviate the pressure on the freedesktop gitlab
infrastructure, disable most test to only run manually.

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/issues/241#note_282521
(cherry picked from commit b733d477e8)
2019-11-22 14:41:06 +01:00
Thomas Haller
725141c07a gitlab-ci: use Fedora 30 to build documentation and archived tarball
(cherry picked from commit 339df56887)
2019-11-22 14:41:05 +01:00
Thomas Haller
361251989f ifcfg: merge branch 'th/ifcfg-8021x-system-ca-certs'
(cherry picked from commit c1dca47619)
2019-11-22 14:40:32 +01:00
Thomas Haller
b67983c387 ifcfg: various cleanup in ifcfg writer
svUnsetValue (ifcfg, KEY);
    if (condition)
         svSetValue* (ifcfg, KEY, ...);

is not good. It requires first clearing the value, before setting
it again.

Various cleanup to fix such uses.

(cherry picked from commit 5028206ec4)
2019-11-22 14:40:32 +01:00
Thomas Haller
d0572b6602 ifcfg: add support for "802-1x.system-ca-certs" setting
(cherry picked from commit 2a4fb75d3b)
2019-11-22 14:40:32 +01:00
Thomas Haller
f449ace2f1 ifcfg: add svSetValueBoolean_cond_true() helper
(cherry picked from commit 87af96a9d6)
2019-11-22 14:40:32 +01:00
Beniamino Galvani
8e2ad6f0c3 ethernet: wait for carrier before starting supplicant
After we set link parameters (auto-negotiation, speed, duplex) in
stage1, the carrier can go down for several seconds because the
Ethernet PHY needs to renegotiate the link. Wait that carrier goes up
before starting the supplicant or the EAPoL start packet can be lost
causing an authentication failure.

https://bugzilla.redhat.com/show_bug.cgi?id=1759797
(cherry picked from commit 838e5b87c2)
2019-11-21 10:22:47 +01:00
Beniamino Galvani
5a8ea69209 device: check for disconnected state before activating NMActRequest
When a new activation request comes and the device is currently
activated, we move the device state to 'deactivating' and wait that it
reaches 'disconnected' before starting the new activation request.

In the meantime, a carrier change could happen but still we have to
wait that device finishes any pending deactivation.

https://bugzilla.redhat.com/show_bug.cgi?id=1772960

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/339
(cherry picked from commit 4b4f18e77b)
2019-11-21 10:10:06 +01:00
Beniamino Galvani
b366234a3a ovs: allow changing mac address of bridges and interfaces
Allow changing the cloned MAC address for OVS bridges and
interfaces. The MAC address set on the bridge is propagated by ovs to
the local interface (the one with the same name as the bridge), while
all other internal interfaces use the address defined in the interface
connection.

https://bugzilla.redhat.com/show_bug.cgi?id=1763734
https://bugzilla.redhat.com/show_bug.cgi?id=1740557

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/321
(cherry picked from commit 101e65d2bb)
2019-11-20 11:12:12 +01:00
Beniamino Galvani
ad17cfff24 ovs: fix memory leak
(cherry picked from commit 508c7679cf)
2019-11-20 11:10:53 +01:00
Beniamino Galvani
a5667952db build: meson: fix dependency to gdbus generated headers
libnm has a dependency on 'libnmdbus_dep', which contains 'link_with:
libnmdbus'. This however only enforces that libnm is linked after the
libnmdbus static library is built; it doesn't give any guarantees
about the compilation phase.

We need to make libnm compilation depend on the generated header
files. The output of 'gnome.gdbus_codegen' is an array with the header
file in the second position; use it to add a proper
dependency. Unfortunately this works only with meson >= 0.46.

In the future libnm will no longer use gdbus generated code and this
dependency will not be needed anymore.

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/issues/286
(cherry picked from commit a59a8aa033)
2019-11-20 10:22:27 +01:00
Thomas Haller
8b4f7a9eb6 libnm: fix annotation for out arguments of nm_bridge_vlan_get_vid_range()
Workaround:

def br_get_vid_range(bridge_vlan):
    try:
        (is_range, vid_start, vid_end) = bridge_vlan.get_vid_range()
    except TypeError as e:
        s = bridge_vlan.to_str()
        s = s.split(' ', 1)
        s = s[0]
        s = s.split('-', 2)
        vid_start = int(s[0])
        if len(s) == 2:
            vid_end = int(s[1])
        else:
            vid_end = vid_start
        is_range = (vid_start == vid_end)
    return (vid_start, vid_end)

Fixes: da204257b1 ('all: support bridge vlan ranges')
(cherry picked from commit c68c199eda)
2019-11-19 16:17:57 +01:00
Lubomir Rintel
e51a4ae806 initrd/tests: put the bootif=no next to the other bootif tests
A cosmetical improvement.

(cherry picked from commit cdfa3d3428)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
964f8aab6d dracut/cmdline: don't combine BOOTIF with on with a name or a MAC address
This fixes the dracut test suite.

(cherry picked from commit 45548bc670)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
82283a50b3 utils: make nm_utils_hwaddr_matches() accept NULL
This essentially aligns the implementation with the documentation.

It is also rather useful, since it allows us to use the value returned
by nm_setting_wired_get_mac_address() directly, and that one can indeed
be NULL.

(cherry picked from commit 62919bab43)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
d240c14478 initrd/cmdline: split add_conn() from get_conn()
No change in behavior. Will be useful when we'll want to unconditionally
add new connection without the matching behavior.

(cherry picked from commit e1a068e93c)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
b03a632c3d initrd: don't overwrite just any connection's name with bootdev= argument
It is really not clear what the user could have meant by specifying a
bootdev= argument, and we deal with it just by ensuring a device with
that name whould come up.

We therefore pick a default connection if there's one (that is a
conneciton that we create if the device name is unspecified, as in
"ip=auto"), otherwise we create a new one.

(cherry picked from commit 30f8154319)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
d7101d8342 initrd: default bridge name to br0 as opposed to bridge0
For compatibility. The dracut.cmdline(7) manual says:

  Bridge without parameters assumes bridge=br0:eth0

(cherry picked from commit f581756af6)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
e19138b94c manager: assume DHCP if we see a lease on taking over an initramfs connection
In general, we aren't really able to tell, but when we see a lease file
we're pretty sure that DHCP is what was going on.

https://bugzilla.redhat.com/show_bug.cgi?id=1771792
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/335

Fixes: f2fe6c03ee ('manager: don't treat the initramfs-configured DHCP connections as generated')
(cherry picked from commit 7a84388a9b)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
3a133e2826 dhcp/nettools: add siaddr to lease options
This is so that we end up with a next-server option analogous to what
dhclient helper sends us. Dracut uses this for networked boots.

(cherry picked from commit c1104a5cc2)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
435dcc3dc6 n-dhcp4/lease: expose the server IP address
This is useful for network booting.

https://github.com/nettools/n-dhcp4/pull/7
(cherry picked from commit edda3d3606)
2019-11-18 13:44:06 +01:00
Lubomir Rintel
68841b76a6 systemd: add siaddr to lease options
This is so that we end up with a next-server option analogous to what
dhclient helper sends us. Dracut uses this for networked boots.

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/329
(cherry picked from commit e475ac7567)
2019-11-18 13:44:06 +01:00
Frank Deng
e1acd336bb utils: alow matching ipv6 new method 'disable'
Make nm_utils_match_connection() match 'ignore' connections with
connections that are generated to have ipv6.method of 'disable'.
Perhaps the ipv6 was disabled globally.

[lkundrak@v3.sk: commit message fixup]

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/336
(cherry picked from commit 87c9583282)
2019-11-18 13:44:06 +01:00
Beniamino Galvani
b35fb49a28 merge: branch 'bg/ipv6-accept-ra-rh1734470'
https://bugzilla.redhat.com/show_bug.cgi?id=1734470

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/247
(cherry picked from commit 6cf28fe2c0)
2019-11-15 16:18:30 +01:00
Beniamino Galvani
d1c7c381e4 ipv6: disable kernel handling of RAs (accept_ra)
With accept_ra set to 1, kernel sends its own router solicitation
messages and parses the advertisements. This duplicates what NM
already does in userspace and has unwanted consequences like [1] and
[2].

The only reason why accept_ra was re-enabled in the past was to apply
RA parameters like ReachableTime and RetransTimer [3]; but now NM
supports them and so accept_ra can be turned off again.

Also, note that previously the option was set in
addrconf6_start_with_link_ready(), and so this was done only when the
method was 'auto'. Instead, now we clear it for all methods except
'ignore'.

[1] https://mail.gnome.org/archives/networkmanager-list/2019-June/msg00027.html
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1734470
[3] https://bugzilla.redhat.com/show_bug.cgi?id=1068673

(cherry picked from commit 5a534529e2)
2019-11-15 16:17:41 +01:00
Beniamino Galvani
08fdea122d ipv6: set neighbor parameters from RAs
IPv6 router advertisement messages contain the following parameters
(RFC 4861):

 - Reachable time: 32-bit unsigned integer.  The time, in
   milliseconds, that a node assumes a neighbor is reachable after
   having received a reachability confirmation.  Used by the Neighbor
   Unreachability Detection algorithm.  A value of zero means
   unspecified (by this router).

 - Retrans Timer: 32-bit unsigned integer.  The time, in milliseconds,
   between retransmitted Neighbor Solicitation messages.  Used by
   address resolution and the Neighbor Unreachability Detection
   algorithm.   A value of zero means unspecified (by this router).

Currently NM ignores them; however, since it leaves accept_ra=1, the
kernel parses RAs and applies those parameters for us [1].

In the next commit kernel handling of RAs will be disabled, so let NM
set those neighbor-related parameters.

[1] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/net/ipv6/ndisc.c?h=v5.2#n1353

(cherry picked from commit 5f0c6f8d3b)
2019-11-15 16:17:33 +01:00
Beniamino Galvani
188911ae7d device: merge branch 'bg/parent-mtu-rh1723690-part1'
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/merge_requests/273
(cherry picked from commit facfc94744)
2019-11-11 10:58:21 +01:00
Beniamino Galvani
49857ed279 device: fix setting MTU from connection when limited by parent
We try to set only one time the MTU from the connection to not
interfere with manual user changes.

If at some point the parent interface changes temporarily MTU to a
lower value (for example, because the connection was reactivated), the
kernel will also lower the MTU on child interface and we will not
update it ever again.

Add a workaround to this. If we detect that the MTU we want to set
from connection is higher that the allowed one, go into a state where
we follow the parent MTU until it is possible to set again the desired
MTU. This is a bit ugly, but I can't think of any nicer way to do it.

https://bugzilla.redhat.com/show_bug.cgi?id=1751079
(cherry picked from commit ec28f5b343)
2019-11-11 10:56:43 +01:00
Beniamino Galvani
9133ba9003 macvlan: update MTU according to parent's one
(cherry picked from commit 4875745bc0)
2019-11-11 10:56:42 +01:00
Beniamino Galvani
c58ce8945d macsec: update MTU according to parent's one
A MACsec connection doesn't have an ordering dependency with its
parent connection and so it's possible that the parent gets activated
later and sets a greater MTU than the original one.

It is reasonable and useful to keep the MACsec MTU configured by
default as the maximum allowed by the parent interface, that is the
parent MTU minus the encapsulation overhead (32). The user can of
course override this by setting an explicit value in the
connection. We already do something similar for VLANs.

https://bugzilla.redhat.com/show_bug.cgi?id=1723690
(cherry picked from commit 438a0a9ad5)
2019-11-11 10:56:39 +01:00
Beniamino Galvani
73597864bb device: introduce generic function to inherit MTU from parent
Introduce a generic function to set a MTU based on parent's one. Also
define a device-specific @mtu_parent_delta value that specifies the
difference from parent MTU that should be set by default. For VLAN it
is zero but other interface types (for example MACsec) require a
positive value due to encapsulation overhead.

(cherry picked from commit 5cf57f4522)
2019-11-11 10:56:36 +01:00