From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 7897E90937 for ; Tue, 2 Apr 2024 19:16:37 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id D034FA6ED for ; Tue, 2 Apr 2024 19:16:35 +0200 (CEST) Received: from lana.proxmox.com (unknown [94.136.29.99]) by firstgate.proxmox.com (Proxmox) with ESMTP for ; Tue, 2 Apr 2024 19:16:32 +0200 (CEST) Received: by lana.proxmox.com (Postfix, from userid 10043) id D5A6A2C33F9; Tue, 2 Apr 2024 19:16:30 +0200 (CEST) From: Stefan Hanreich To: pve-devel@lists.proxmox.com Cc: Stefan Hanreich , Wolfgang Bumiller Date: Tue, 2 Apr 2024 19:15:58 +0200 Message-Id: <20240402171629.536804-7-s.hanreich@proxmox.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240402171629.536804-1-s.hanreich@proxmox.com> References: <20240402171629.536804-1-s.hanreich@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL -0.337 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 0.793 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Subject: [pve-devel] [PATCH proxmox-firewall 06/37] config: host: add helpers for host network configuration X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Apr 2024 17:16:37 -0000 Currently the helpers for obtaining the host network configuration panic on error, which could be avoided by the use of OnceLock::get_or_init, but this method is currently only available in nightly versions. Generally, if there is a problem with obtaining a hostname for the current node then something else is probably already quite broken, so I would deem it acceptable for now, same goes for obtaining the current network configuration. Co-authored-by: Wolfgang Bumiller Signed-off-by: Stefan Hanreich --- proxmox-ve-config/Cargo.toml | 1 + proxmox-ve-config/src/host/mod.rs | 1 + proxmox-ve-config/src/host/utils.rs | 97 +++++++++++++++++++++++++++++ proxmox-ve-config/src/lib.rs | 1 + 4 files changed, 100 insertions(+) create mode 100644 proxmox-ve-config/src/host/mod.rs create mode 100644 proxmox-ve-config/src/host/utils.rs diff --git a/proxmox-ve-config/Cargo.toml b/proxmox-ve-config/Cargo.toml index 7bb391e..480eb58 100644 --- a/proxmox-ve-config/Cargo.toml +++ b/proxmox-ve-config/Cargo.toml @@ -13,6 +13,7 @@ license = "AGPL-3" [dependencies] log = "0.4" anyhow = "1" +nix = "0.26" serde = { version = "1", features = [ "derive" ] } serde_json = "1" diff --git a/proxmox-ve-config/src/host/mod.rs b/proxmox-ve-config/src/host/mod.rs new file mode 100644 index 0000000..b5614dd --- /dev/null +++ b/proxmox-ve-config/src/host/mod.rs @@ -0,0 +1 @@ +pub mod utils; diff --git a/proxmox-ve-config/src/host/utils.rs b/proxmox-ve-config/src/host/utils.rs new file mode 100644 index 0000000..1636f95 --- /dev/null +++ b/proxmox-ve-config/src/host/utils.rs @@ -0,0 +1,97 @@ +use std::net::{IpAddr, ToSocketAddrs}; +use std::sync::OnceLock; + +use crate::firewall::types::Cidr; + +use nix::sys::socket::{AddressFamily, SockaddrLike}; + +pub fn hostname() -> &'static str { + static HOSTNAME: OnceLock = OnceLock::new(); + + // We should rather use get_or_try_init to avoid needing to panic + // but it is currently experimental + HOSTNAME.get_or_init(|| { + use nix::libc::{c_char, gethostname, sysconf, _SC_HOST_NAME_MAX}; + use std::ffi::CStr; + + let max_len = unsafe { sysconf(_SC_HOST_NAME_MAX) } as usize + 1; + let mut buffer = vec![0; max_len]; + + let ret = unsafe { gethostname(buffer.as_mut_ptr() as *mut c_char, buffer.len()) }; + + if ret != 0 { + // failing to get the hostname means something is *really* off + panic!("gethostname failed with returncode {ret}"); + } + + let c_str = CStr::from_bytes_until_nul(&buffer).expect("buffer contains a NUL byte"); + + String::from_utf8_lossy(c_str.to_bytes()).to_string() + }) +} + +pub fn host_ips() -> &'static [IpAddr] { + static IP_ADDRESSES: OnceLock> = OnceLock::new(); + + // We should rather use get_or_try_init to avoid needing to panic + // but it is currently experimental + IP_ADDRESSES.get_or_init(|| { + let hostname = hostname(); + + format!("{hostname}:0") + .to_socket_addrs() + .expect("local hostname is resolvable") + .map(|addr| addr.ip()) + .collect() + }) +} + +pub fn network_interface_cidrs() -> &'static [Cidr] { + static INTERFACES: OnceLock> = OnceLock::new(); + + // We should rather use get_or_try_init to avoid needing to panic + // but it is currently experimental + INTERFACES.get_or_init(|| { + use nix::ifaddrs::getifaddrs; + + let mut cidrs = Vec::new(); + + let interfaces = getifaddrs().expect("should be able to query network interfaces"); + + for interface in interfaces { + if let (Some(address), Some(netmask)) = (interface.address, interface.netmask) { + match (address.family(), netmask.family()) { + (Some(AddressFamily::Inet), Some(AddressFamily::Inet)) => { + let address = address.as_sockaddr_in().expect("is an IPv4 address").ip(); + + let netmask = netmask + .as_sockaddr_in() + .expect("is an IPv4 address") + .ip() + .count_ones() + .try_into() + .expect("count_ones of u32 is < u8_max"); + + cidrs.push(Cidr::new_v4(address, netmask).expect("netmask is valid")); + } + (Some(AddressFamily::Inet6), Some(AddressFamily::Inet6)) => { + let address = address.as_sockaddr_in6().expect("is an IPv6 address").ip(); + + let netmask_address = + netmask.as_sockaddr_in6().expect("is an IPv6 address").ip(); + + let netmask = u128::from_be_bytes(netmask_address.octets()) + .count_ones() + .try_into() + .expect("count_ones of u128 is < u8_max"); + + cidrs.push(Cidr::new_v6(address, netmask).expect("netmask is valid")); + } + _ => continue, + } + } + } + + cidrs + }) +} diff --git a/proxmox-ve-config/src/lib.rs b/proxmox-ve-config/src/lib.rs index a0734b8..2bf9352 100644 --- a/proxmox-ve-config/src/lib.rs +++ b/proxmox-ve-config/src/lib.rs @@ -1 +1,2 @@ pub mod firewall; +pub mod host; -- 2.39.2