2021-05-01 12:45:37 +02:00
|
|
|
package iface
|
|
|
|
|
|
|
|
import (
|
2022-01-24 22:45:52 +01:00
|
|
|
"errors"
|
2022-09-05 02:03:16 +02:00
|
|
|
"golang.zx2c4.com/wireguard/conn"
|
2022-01-24 22:45:52 +01:00
|
|
|
"math"
|
|
|
|
"os"
|
|
|
|
"syscall"
|
|
|
|
|
2021-05-01 12:45:37 +02:00
|
|
|
log "github.com/sirupsen/logrus"
|
|
|
|
"github.com/vishvananda/netlink"
|
2022-01-24 22:45:52 +01:00
|
|
|
)
|
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
type NativeLink struct {
|
|
|
|
Link *netlink.Link
|
|
|
|
}
|
|
|
|
|
2022-07-02 12:02:17 +02:00
|
|
|
// WireguardModExists check if we can load wireguard mod (linux only)
|
2022-01-24 22:45:52 +01:00
|
|
|
func WireguardModExists() bool {
|
|
|
|
link := newWGLink("mustnotexist")
|
|
|
|
|
|
|
|
// We willingly try to create a device with an invalid
|
|
|
|
// MTU here as the validation of the MTU will be performed after
|
|
|
|
// the validation of the link kind and hence allows us to check
|
|
|
|
// for the existance of the wireguard module without actually
|
|
|
|
// creating a link.
|
|
|
|
//
|
|
|
|
// As a side-effect, this will also let the kernel lazy-load
|
|
|
|
// the wireguard module.
|
|
|
|
link.attrs.MTU = math.MaxInt
|
|
|
|
|
|
|
|
err := netlink.LinkAdd(link)
|
|
|
|
|
|
|
|
return errors.Is(err, syscall.EINVAL)
|
|
|
|
}
|
2022-09-05 02:03:16 +02:00
|
|
|
func (w *WGIface) CreateNew(bind conn.Bind) error {
|
2022-09-04 22:52:52 +02:00
|
|
|
w.mu.Lock()
|
|
|
|
defer w.mu.Unlock()
|
|
|
|
|
2022-09-05 02:03:16 +02:00
|
|
|
return w.createWithUserspaceNew(bind)
|
2022-09-04 22:52:52 +02:00
|
|
|
}
|
2022-01-24 22:45:52 +01:00
|
|
|
|
2022-06-04 19:41:01 +02:00
|
|
|
// Create creates a new Wireguard interface, sets a given IP and brings it up.
|
2021-06-18 13:01:43 +02:00
|
|
|
// Will reuse an existing one.
|
2022-01-17 14:01:58 +01:00
|
|
|
func (w *WGIface) Create() error {
|
2022-06-04 19:41:01 +02:00
|
|
|
w.mu.Lock()
|
|
|
|
defer w.mu.Unlock()
|
2021-06-18 13:01:43 +02:00
|
|
|
|
2022-09-04 22:52:52 +02:00
|
|
|
return w.createWithUserspace()
|
2021-06-18 13:01:43 +02:00
|
|
|
}
|
|
|
|
|
2022-06-04 19:41:01 +02:00
|
|
|
// createWithKernel Creates a new Wireguard interface using kernel Wireguard module.
|
2021-06-24 11:02:40 +02:00
|
|
|
// Works for Linux and offers much better network performance
|
2022-06-04 19:41:01 +02:00
|
|
|
func (w *WGIface) createWithKernel() error {
|
2021-06-24 11:02:40 +02:00
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
link := newWGLink(w.Name)
|
2021-06-24 11:02:40 +02:00
|
|
|
|
2021-08-26 18:04:19 +02:00
|
|
|
// check if interface exists
|
2022-01-17 14:01:58 +01:00
|
|
|
l, err := netlink.LinkByName(w.Name)
|
2021-08-26 18:04:19 +02:00
|
|
|
if err != nil {
|
|
|
|
switch err.(type) {
|
|
|
|
case netlink.LinkNotFoundError:
|
|
|
|
break
|
|
|
|
default:
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// remove if interface exists
|
|
|
|
if l != nil {
|
2022-01-17 14:01:58 +01:00
|
|
|
err = netlink.LinkDel(link)
|
2021-08-26 18:04:19 +02:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
log.Debugf("adding device: %s", w.Name)
|
|
|
|
err = netlink.LinkAdd(link)
|
2021-06-24 11:02:40 +02:00
|
|
|
if os.IsExist(err) {
|
2022-01-17 14:01:58 +01:00
|
|
|
log.Infof("interface %s already exists. Will reuse.", w.Name)
|
2021-06-24 11:02:40 +02:00
|
|
|
} else if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
w.Interface = link
|
|
|
|
|
|
|
|
err = w.assignAddr()
|
2021-06-24 11:02:40 +02:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// todo do a discovery
|
2022-01-17 14:01:58 +01:00
|
|
|
log.Debugf("setting MTU: %d interface: %s", w.MTU, w.Name)
|
|
|
|
err = netlink.LinkSetMTU(link, w.MTU)
|
2021-06-24 11:02:40 +02:00
|
|
|
if err != nil {
|
2022-01-17 14:01:58 +01:00
|
|
|
log.Errorf("error setting MTU on interface: %s", w.Name)
|
2021-06-24 11:02:40 +02:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
log.Debugf("bringing up interface: %s", w.Name)
|
|
|
|
err = netlink.LinkSetUp(link)
|
2021-06-24 11:02:40 +02:00
|
|
|
if err != nil {
|
2022-01-17 14:01:58 +01:00
|
|
|
log.Errorf("error bringing up interface: %s", w.Name)
|
2021-06-24 11:02:40 +02:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-06-18 13:01:43 +02:00
|
|
|
// assignAddr Adds IP address to the tunnel interface
|
2022-01-17 14:01:58 +01:00
|
|
|
func (w *WGIface) assignAddr() error {
|
|
|
|
link := newWGLink(w.Name)
|
2021-05-01 12:45:37 +02:00
|
|
|
|
2021-08-26 15:32:05 +02:00
|
|
|
//delete existing addresses
|
2022-01-17 14:01:58 +01:00
|
|
|
list, err := netlink.AddrList(link, 0)
|
2021-08-26 15:32:05 +02:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if len(list) > 0 {
|
|
|
|
for _, a := range list {
|
2022-01-17 14:01:58 +01:00
|
|
|
err = netlink.AddrDel(link, &a)
|
2021-08-26 15:32:05 +02:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-06-04 19:41:01 +02:00
|
|
|
log.Debugf("adding address %s to interface: %s", w.Address.String(), w.Name)
|
|
|
|
addr, _ := netlink.ParseAddr(w.Address.String())
|
2022-01-17 14:01:58 +01:00
|
|
|
err = netlink.AddrAdd(link, addr)
|
2021-05-01 12:45:37 +02:00
|
|
|
if os.IsExist(err) {
|
2022-06-04 19:41:01 +02:00
|
|
|
log.Infof("interface %s already has the address: %s", w.Name, w.Address.String())
|
2021-05-01 12:45:37 +02:00
|
|
|
} else if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
// On linux, the link must be brought up
|
2022-01-17 14:01:58 +01:00
|
|
|
err = netlink.LinkSetUp(link)
|
2021-05-01 12:45:37 +02:00
|
|
|
return err
|
|
|
|
}
|
2021-06-06 00:40:44 +02:00
|
|
|
|
|
|
|
type wgLink struct {
|
|
|
|
attrs *netlink.LinkAttrs
|
|
|
|
}
|
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
func newWGLink(name string) *wgLink {
|
|
|
|
attrs := netlink.NewLinkAttrs()
|
|
|
|
attrs.Name = name
|
|
|
|
|
|
|
|
return &wgLink{
|
|
|
|
attrs: &attrs,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-06-06 00:40:44 +02:00
|
|
|
// Attrs returns the Wireguard's default attributes
|
2022-01-17 14:01:58 +01:00
|
|
|
func (l *wgLink) Attrs() *netlink.LinkAttrs {
|
|
|
|
return l.attrs
|
2021-06-06 00:40:44 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
// Type returns the interface type
|
2022-01-17 14:01:58 +01:00
|
|
|
func (l *wgLink) Type() string {
|
2021-06-06 00:40:44 +02:00
|
|
|
return "wireguard"
|
|
|
|
}
|
2021-07-19 15:02:11 +02:00
|
|
|
|
2022-01-17 14:01:58 +01:00
|
|
|
// Close deletes the link interface
|
|
|
|
func (l *wgLink) Close() error {
|
|
|
|
return netlink.LinkDel(l)
|
2021-07-19 15:02:11 +02:00
|
|
|
}
|