From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=ASAIYn3m; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 2A26A5A0653 for ; Mon, 15 Dec 2025 02:55:01 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1765763700; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=U27wdMfOmkPuI0PCRhHdufdpUtk3zWt/VYVG1xtN/Pc=; b=ASAIYn3mSY8ktWxR6+EYJV2p33wJ87IB6dqpRiNrcLwqlG89k5eXJ19fIKdkulQ6owFSvy wX/HN6rRwxu4QVGXJpOBGeh8eeDA9fRDbJpP6u8xofdJTlDG+evn9QnxoIwWeAcBl+Wu64 S8XbGSN5EeAsTW5xycYDSWIY1rNMlvQ= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-605-3ErxHC4rPhWWOzzUNKSixw-1; Sun, 14 Dec 2025 20:54:56 -0500 X-MC-Unique: 3ErxHC4rPhWWOzzUNKSixw-1 X-Mimecast-MFC-AGG-ID: 3ErxHC4rPhWWOzzUNKSixw_1765763696 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0CFB618002C1; Mon, 15 Dec 2025 01:54:56 +0000 (UTC) Received: from jmaloy-thinkpadp16vgen1.rmtcaqc.csb (unknown [10.22.88.123]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 34E1030001A2; Mon, 15 Dec 2025 01:54:55 +0000 (UTC) From: Jon Maloy To: sbrivio@redhat.com, dgibson@redhat.com, david@gibson.dropbear.id.au, jmaloy@redhat.com, passt-dev@passt.top Subject: [RFC 10/12] netlink: Add host-side route monitoring and propagation Date: Sun, 14 Dec 2025 20:54:39 -0500 Message-ID: <20251215015441.887736-11-jmaloy@redhat.com> In-Reply-To: <20251215015441.887736-1-jmaloy@redhat.com> References: <20251215015441.887736-1-jmaloy@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: uSNbBHCvKLaBhI1b069p4A0nfUphvcFGjLL-n0JuXgM_1765763696 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit content-type: text/plain; charset="US-ASCII"; x-default=true Message-ID-Hash: MN3B763BM5OXKI7C7YN5U5N7CRNTM72O X-Message-ID-Hash: MN3B763BM5OXKI7C7YN5U5N7CRNTM72O X-MailFrom: jmaloy@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: We extend host-side netlink monitoring to also track default route changes on the template interface and propagate them to the namespace. - Subscribe to RTMGRP_IPV4_ROUTE and RTMGRP_IPV6_ROUTE groups on the host-side netlink socket - Handle RTM_NEWROUTE/RTM_DELROUTE events for default routes. - Support late binding via routes: if no template interface is bound yet, adopt the interface in question when a default route appears on it. - When a default route is added, set guest_gw/our_tap_addr and propagate the route to the namespace via nl_route_set_def() - When a default route is removed, clear guest_gw/our_tap_addr Signed-off-by: Jon Maloy --- netlink.c | 100 ++++++++++++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 97 insertions(+), 3 deletions(-) diff --git a/netlink.c b/netlink.c index 583ada8..d049239 100644 --- a/netlink.c +++ b/netlink.c @@ -199,7 +199,7 @@ static bool nl_addr6_add(struct ctx *c, const struct in6_addr *addr, idx = c->ip6.addr_count++; c->ip6.addrs[idx].addr = *addr; c->ip6.addrs[idx].prefix_len = prefix_len; - c->ip6.addrs[idxyes].permanent = 0; + c->ip6.addrs[idx].permanent = 0; return true; } @@ -254,7 +254,7 @@ static bool nl_addr6_del(struct ctx *c, const struct in6_addr *addr) } /** - * nl_linkaddr_host_msg_read() - Handle host-side link/addr changes + * nl_linkaddr_host_msg_read() - Handle host-side link/addr/route changes * @c: Execution context * @nh: Netlink message header * @@ -420,6 +420,99 @@ static void nl_linkaddr_host_msg_read(struct ctx *c, const struct nlmsghdr *nh) } return; } + + if (nh->nlmsg_type == RTM_NEWROUTE || nh->nlmsg_type == RTM_DELROUTE) { + bool is_new = (nh->nlmsg_type == RTM_NEWROUTE); + const struct rtmsg *rtm = NLMSG_DATA(nh); + struct rtattr *rta = RTM_RTA(rtm); + size_t na = RTM_PAYLOAD(nh); + unsigned int template_ifi; + char ifname[IFNAMSIZ]; + unsigned int oif = 0; + void *gw = NULL; + bool is_default; + bool is_match; + bool unbound; + + /* Only interested in default routes */ + if (rtm->rtm_dst_len != 0) + return; + + for (; RTA_OK(rta, na); rta = RTA_NEXT(rta, na)) { + if (rta->rta_type == RTA_GATEWAY) + gw = RTA_DATA(rta); + else if (rta->rta_type == RTA_OIF) + oif = *(unsigned int *)RTA_DATA(rta); + } + + if (!gw || !oif) + return; + + /* Get interface name for late binding check */ + if (!if_indextoname(oif, ifname)) + return; + + /* Check for late binding conditions */ + is_default = !strcmp(c->pasta_ifn, pasta_default_ifn); + is_match = !strcmp(ifname, c->pasta_ifn); + + if (rtm->rtm_family == AF_INET) + template_ifi = c->ifi4; + else if (rtm->rtm_family == AF_INET6) + template_ifi = c->ifi6; + else + return; + + unbound = (rtm->rtm_family == AF_INET) ? + (int)c->ifi4 <= 0 : (int)c->ifi6 <= 0; + + if (unbound && (is_default || is_match)) { + debug("Late binding (route): using %s as %s template", + ifname, + rtm->rtm_family == AF_INET ? "IPv4" : "IPv6"); + + if (rtm->rtm_family == AF_INET) { + c->ifi4 = oif; + template_ifi = c->ifi4; + } else { + c->ifi6 = oif; + template_ifi = c->ifi6; + } + + if (is_default) + snprintf(c->pasta_ifn, sizeof(c->pasta_ifn), + "%s", ifname); + } + + if (oif != template_ifi) + return; + + if (rtm->rtm_family == AF_INET) { + char buf[INET_ADDRSTRLEN]; + + if (!is_new) { + c->ip4.guest_gw = (struct in_addr){ 0 }; + c->ip4.our_tap_addr = (struct in_addr){ 0 }; + return; + } + c->ip4.guest_gw = *(struct in_addr *)gw; + c->ip4.our_tap_addr = c->ip4.guest_gw; + nl_route_set_def(nl_sock_ns, c->pasta_ifi, AF_INET, gw); + inet_ntop(AF_INET, &c->ip4.guest_gw, buf, sizeof(buf)); + debug("Set IPv4 default route via %s", buf); + } else if (rtm->rtm_family == AF_INET6) { + char buf[INET6_ADDRSTRLEN]; + + if (!is_new) { + c->ip6.guest_gw = (struct in6_addr){ 0 }; + return; + } + c->ip6.guest_gw = *(struct in6_addr *)gw; + nl_route_set_def(nl_sock_ns, c->pasta_ifi, AF_INET6, gw); + inet_ntop(AF_INET6, &c->ip6.guest_gw, buf, sizeof(buf)); + debug("Set IPv6 default route via %s", buf); + } + } } /** @@ -676,7 +769,8 @@ static int nl_linkaddr_init_do(void *arg) static int nl_linkaddr_host_init_do(void *arg) { struct sockaddr_nl addr = { .nl_family = AF_NETLINK, - .nl_groups = RTMGRP_LINK | RTMGRP_IPV4_IFADDR | RTMGRP_IPV6_IFADDR }; + .nl_groups = RTMGRP_LINK | RTMGRP_IPV4_IFADDR | RTMGRP_IPV6_IFADDR | + RTMGRP_IPV4_ROUTE | RTMGRP_IPV6_ROUTE }; (void)arg; -- 2.51.1