Find a file
Beniamino Galvani 0df304b790 Revert "platform: always reconfigure IP routes even if removed externally"
The change in behavior introduced by the patch departs from the policy
that NM had for long time of trying not to interfere with user
modifications. This seems a fundamental aspect of how NM works and
indeed we got already one report:

https://bugzilla.redhat.com/show_bug.cgi?id=2218866

of a user that was affected by the change. The specific case is about
routes from DHCP, but also static routes are affected. When a user
removes the route added by NM, NM now can add it back at any time.

Changing behavior is bad, it causes pain for users and for people who
need to support them. However, if the new behavior provides clear
advantages to users, that might be ok. This doesn't seem the case in
my opinion. Commit 7ca95cee describes a couple of scenarios:

> - kernel can automatically remove routes. For example, deleting an
>   IPv4 address that is the prefsrc of a route, will cause kernel to
>   delete that route. Sure, we may be unable to re-configure the
>   route at this moment, but we shouldn't remember indefinitely that
>   the route is supposed to be absent. Rather, we should re-add it
>   when possible

> - kernel is a pain with validating consistencies of routes. For
>   example, when a route has a nexthop gateway, then the gateway must
>   be onlink (directly reachable), or kernel refuses to add it with
>   "Nexthop has invalid gateway". Of course, when removing the onlink
>   route kernel is fine leaving the gateway route behind, which it
>   would otherwise refuse to add.
>   Anyway. Such interdependencies for when kernel rejects adding a
>   route with "Nexthop has invalid gateway" are non-trivial. We try
>   to work around that by always adding the necessary onlink
>   routes. See nm_l3_config_data_add_dependent_onlink_routes(). But
>   if the user externally removed the dependent onlink route, and
>   NetworkManager remembers to not re-adding it, then the efforts
>   from nm_l3_config_data_add_dependent_onlink_routes() are
>   ignored. This causes ripple effects and NetworkManager will also
>   be unable to add the nexthop route.

Kernel usually removes addresses as consequence of user actions. If
not (e.g. DHCP lease expiring) we have solutions in place for that to
re-add the route.

If the route removal is the consequence of a user action, then the
user must do something to undo it. For example, if the user removes an
address on the same interface, a route using the address as prefsrc
will be deleted. If the user wants it back, it must be re-added
manually together with the address; I don't see any problem with this.

The prefsrc address could be on another interface; in such case by
simply deactivating the connection providing the address, a dependent
route could be removed on another interface and never readded. This
doesn't look as a setup that anybody would use; in case we need to
support it, it is better to find alternative solutions.

So, my opinion is that the change in behavior potentially breaks many
users and doesn't bring clear advantages. Therefore, restore the old
behavior.

This reverts commit 7ca95cee15.

Revert conflicts:

- the following code was removed from _obj_states_sync_filter() in
  nm-l3cfg.c because the mechanism to set temporarily-unavailable
  routes was changed in 1feaf427d2
  ('platform: rework handling of failed routes during
  nm_platform_ip_route_sync()'), and so
  `os_temporary_not_available_timestamp_msec` no longer exists:

    if (obj_state->os_temporary_not_available_timestamp_msec > 0) {
        /* we currently try to configure this address (but failed earlier).
         * Definitely retry. */
        return TRUE;
    }
2023-07-25 19:30:15 +02:00
.gitlab gitlab: improve issue and merge-request templates 2023-06-27 09:51:46 +02:00
.gitlab-ci gitlab-ci: fix detection and handling of Ubuntu 18.04 2023-06-30 18:51:13 +02:00
contrib contrib: add "cloud-init", "firewalld", "nftables" to makerepo.sh script 2023-07-14 09:40:26 +02:00
data doc: update Documentation reference in NetworkManager-wait-online.service 2023-06-07 16:48:30 +02:00
docs docs: add daemon internal documentation 2023-06-27 14:29:18 +02:00
examples examples: support older libnm without NM.SettingOvsOtherConfig in "ovs-external-ids.py" 2023-02-16 10:17:48 +01:00
introspection settings: add "version-id" argument to Update2() D-Bus call 2023-06-26 10:35:36 +02:00
m4 build: enable "-Wcast-align" warning 2022-12-09 09:15:56 +01:00
man build,core: add a "main.migrate-ifcfg-rh" configuration option 2023-07-25 15:39:06 +02:00
po nmtui: replace occurrences of master/slave with controller/port in internal code 2023-07-25 14:22:25 +02:00
src Revert "platform: always reconfigure IP routes even if removed externally" 2023-07-25 19:30:15 +02:00
tools nm-in-container: add NetworkManager.service override 2023-06-30 15:44:05 +02:00
vapi all: add "link" setting 2023-03-02 16:51:16 +01:00
.clang-format glib-aux/prioq: rename NM_PRIOQ_FOREACH_ITEM() to nm_prioq_for_each() 2023-03-21 15:58:39 +01:00
.dir-locals.el misc: add toplevel .dir-locals file that tells Emacs to show trailing whitespace 2013-03-08 15:15:28 +01:00
.git-blame-ignore-revs clang-format: add reformatting commit to ".git-blame-ignore-revs" 2023-05-19 12:49:22 +02:00
.gitignore gitignore: ignore "po/.Makefile.patched" file 2022-10-31 09:20:53 +01:00
.gitlab-ci.yml gitlab-ci: fix detection and handling of Ubuntu 18.04 2023-06-30 18:51:13 +02:00
.mailmap mailmap: update Jordi's identity 2023-06-28 13:50:25 +02:00
.triage-policies.yml triage: only make stale issues/merge-requests with a label instead of autoclosing them 2023-05-08 11:04:50 +02:00
AUTHORS docs: fix typo in docs for upstream mailing list 2022-11-07 17:50:29 +01:00
autogen.sh build: stop relying on intltool for i18n 2022-06-27 13:40:09 +02:00
ChangeLog Changelog: update references to "main" branch 2021-04-01 22:30:20 +02:00
config-extra.h.meson build: remove duplicate and unused RUNDIR define 2019-05-17 21:24:18 +02:00
config-extra.h.mk build: regenerate config-extra.h if configure was re-run with different arguments 2019-09-25 15:55:37 +02:00
config.h.meson build,core: add a "main.migrate-ifcfg-rh" configuration option 2023-07-25 15:39:06 +02:00
configure.ac build,core: add a "main.migrate-ifcfg-rh" configuration option 2023-07-25 15:39:06 +02:00
CONTRIBUTING.md CONTRIBUTING: don't use signed-off-by in NetworkManager 2023-06-07 14:25:05 +02:00
COPYING COPYING: make sure we ship the relevant license texts 2019-09-10 11:10:52 +02:00
COPYING.GFDL COPYING: make sure we ship the relevant license texts 2019-09-10 11:10:52 +02:00
COPYING.LGPL COPYING: make sure we ship the relevant license texts 2019-09-10 11:10:52 +02:00
linker-script-binary.ver iface-helper/build: add linker version script 2016-10-13 21:33:33 +02:00
linker-script-devices.ver devices/build: use one linker-script-devices.ver for all device plugins 2016-10-13 21:36:06 +02:00
linker-script-settings.ver settings/build: add linker version script for settings plugins 2016-10-13 21:33:33 +02:00
lsan.suppressions tests/sanitizer: suppress leak in openssl 2020-05-14 12:03:24 +02:00
MAINTAINERS misc: update maintainers and authors 2016-04-21 13:39:03 -05:00
MAINTAINERS.md MAINTAINERS: how to merge merge requests 2023-06-07 14:25:05 +02:00
Makefile.am build,core: add a "main.migrate-ifcfg-rh" configuration option 2023-07-25 15:39:06 +02:00
Makefile.examples examples: add python example for reapply 2022-12-14 17:31:17 +01:00
Makefile.glib all: drop emacs file variables from source files 2019-06-11 10:04:00 +02:00
Makefile.vapigen build: fix make always re-making vapigen target 2016-10-21 18:46:03 +02:00
meson.build build,core: add a "main.migrate-ifcfg-rh" configuration option 2023-07-25 15:39:06 +02:00
meson_options.txt build,core: add a "main.migrate-ifcfg-rh" configuration option 2023-07-25 15:39:06 +02:00
NEWS keyfile: add a NetworkManager.conf option "keyfile.rename" 2023-06-29 14:05:27 +02:00
README.md doc: rename "README" to "README.md" 2022-03-21 17:19:47 +01:00
RELICENSE.md docs: fix typo in docs for upstream mailing list 2022-11-07 17:50:29 +01:00
TODO core/trivial: rename NM_SHUTDOWN_TIMEOUT_MS to NM_SHUTDOWN_TIMEOUT_MAX_MSEC 2022-02-24 09:38:52 +01:00
valgrind.suppressions all: goodbye libnm-glib 2019-04-16 15:52:27 +02:00


NetworkManager core daemon has moved to gitlab.freedesktop.org!

git clone https://gitlab.freedesktop.org/NetworkManager/NetworkManager.git


Networking that Just Works

NetworkManager attempts to keep an active network connection available at all times. The point of NetworkManager is to make networking configuration and setup as painless and automatic as possible. NetworkManager is intended to replace default route, replace other routes, set IP addresses, and in general configure networking as NM sees fit (with the possibility of manual override as necessary). In effect, the goal of NetworkManager is to make networking Just Work with a minimum of user hassle, but still allow customization and a high level of manual network control. If you have special needs, we'd like to hear about them, but understand that NetworkManager is not intended for every use-case.

NetworkManager will attempt to keep every network device in the system up and active, as long as the device is available for use (has a cable plugged in, the killswitch isn't turned on, etc). Network connections can be set to 'autoconnect', meaning that NetworkManager will make that connection active whenever it and the hardware is available.

"Settings services" store lists of user- or administrator-defined "connections", which contain all the settings and parameters required to connect to a specific network. NetworkManager will never activate a connection that is not in this list, or that the user has not directed NetworkManager to connect to.

How it works:

The NetworkManager daemon runs as a privileged service (since it must access and control hardware), but provides a D-Bus interface on the system bus to allow for fine-grained control of networking. NetworkManager does not store connections or settings, it is only the mechanism by which those connections are selected and activated.

To store pre-defined network connections, two separate services, the "system settings service" and the "user settings service" store connection information and provide these to NetworkManager, also via D-Bus. Each settings service can determine how and where it persistently stores the connection information; for example, the GNOME applet stores its configuration in GConf, and the system settings service stores its config in distro-specific formats, or in a distro- agnostic format, depending on user/administrator preference.

A variety of other system services are used by NetworkManager to provide network functionality: wpa_supplicant for wireless connections and 802.1x wired connections, pppd for PPP and mobile broadband connections, DHCP clients for dynamic IP addressing, dnsmasq for proxy nameserver and DHCP server functionality for internet connection sharing, and avahi-autoipd for IPv4 link-local addresses. Most communication with these daemons occurs, again, via D-Bus.

Why doesn't my network Just Work?

Driver problems are the #1 cause of why NetworkManager sometimes fails to connect to wireless networks. Often, the driver simply doesn't behave in a consistent manner, or is just plain buggy. NetworkManager supports only those drivers that are shipped with the upstream Linux kernel, because only those drivers can be easily fixed and debugged. ndiswrapper, vendor binary drivers, or other out-of-tree drivers may or may not work well with NetworkManager, precisely because they have not been vetted and improved by the open-source community, and because problems in these drivers usually cannot be fixed.

Sometimes, command-line tools like 'iwconfig' will work, but NetworkManager will fail. This is again often due to buggy drivers, because these drivers simply aren't expecting the dynamic requests that NetworkManager and wpa_supplicant make. Driver bugs should be filed in the bug tracker of the distribution being run, since often distributions customize their kernel and drivers.

Sometimes, it really is NetworkManager's fault. If you think that's the case, please file a bug at:

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/issues

Attaching NetworkManager debug logs from the journal (or wherever your distribution directs syslog's 'daemon' facility output, as /var/log/messages or /var/log/daemon.log) is often very helpful, and (if you can get) a working wpa_supplicant config file helps enormously. See the logging section of file contrib/fedora/rpm/NetworkManager.conf for how to enable debug logging in NetworkManager.