added cidr validation and made hook execs to command array with args
This commit is contained in:
parent
fd9f8fc1fd
commit
85a2e39a4b
6 changed files with 54 additions and 165 deletions
|
|
@ -7,6 +7,7 @@ import (
|
|||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"github.com/vishvananda/netlink"
|
||||
"gopkg.in/yaml.v2"
|
||||
)
|
||||
|
||||
|
|
@ -41,14 +42,20 @@ func Validate(c *Config) error {
|
|||
if len(c.VirtualIPs) == 0 {
|
||||
return errors.New("missing virtualIPs config")
|
||||
}
|
||||
if c.LeaderHook != "" {
|
||||
if !filepath.IsAbs(c.LeaderHook) {
|
||||
return errors.New("leaderHook path must be absolute")
|
||||
for _, vip := range c.VirtualIPs {
|
||||
_, err := netlink.ParseAddr(vip)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to parse CIDR virtualIP '%s': %w", vip, err)
|
||||
}
|
||||
}
|
||||
if c.FollowerHook != "" {
|
||||
if !filepath.IsAbs(c.FollowerHook) {
|
||||
return errors.New("followerHook path must be absolute")
|
||||
if len(c.LeaderHook) > 0 {
|
||||
if !filepath.IsAbs(c.LeaderHook[0]) {
|
||||
return errors.New("leaderHook executable path must be absolute")
|
||||
}
|
||||
}
|
||||
if len(c.FollowerHook) > 0 {
|
||||
if !filepath.IsAbs(c.FollowerHook[0]) {
|
||||
return errors.New("followerHook executable path must be absolute")
|
||||
}
|
||||
}
|
||||
raft := c.Cluster.Raft
|
||||
|
|
@ -116,8 +123,8 @@ type Config struct {
|
|||
VirtualIPs []string `yaml:"virtualIPs"`
|
||||
Interface string `yaml:"interface,omitempty"`
|
||||
Label string `yaml:"label,omitempty"`
|
||||
LeaderHook string `yaml:"leaderHook,omitempty"`
|
||||
FollowerHook string `yaml:"followerHook,omitempty"`
|
||||
LeaderHook []string `yaml:"leaderHook,omitempty"`
|
||||
FollowerHook []string `yaml:"followerHook,omitempty"`
|
||||
Cluster Cluster `yaml:"cluster"`
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -19,9 +19,9 @@ func NewVIPController(cfg *config.Config) (callbacks cluster.Callbacks, err erro
|
|||
callbacks = cluster.Callbacks{
|
||||
Leader: func(ctx context.Context, cc cluster.CallbackContext) {
|
||||
t := time.NewTicker(time.Second * 10)
|
||||
if cfg.LeaderHook != "" {
|
||||
if len(cfg.LeaderHook) > 0 {
|
||||
go func() {
|
||||
err := exec.CommandContext(ctx, cfg.LeaderHook).Run()
|
||||
err := exec.CommandContext(ctx, cfg.LeaderHook[0], cfg.LeaderHook[1:]...).Run()
|
||||
if err != nil {
|
||||
cc.Error(err, "error running hook", "leaderHook", cfg.LeaderHook)
|
||||
}
|
||||
|
|
@ -42,9 +42,9 @@ func NewVIPController(cfg *config.Config) (callbacks cluster.Callbacks, err erro
|
|||
},
|
||||
Follower: func(ctx context.Context, cc cluster.CallbackContext) {
|
||||
t := time.NewTicker(time.Second * 10)
|
||||
if cfg.FollowerHook != "" {
|
||||
if len(cfg.FollowerHook) > 0 {
|
||||
go func() {
|
||||
err := exec.CommandContext(ctx, cfg.FollowerHook).Run()
|
||||
err := exec.CommandContext(ctx, cfg.FollowerHook[0], cfg.FollowerHook[1:]...).Run()
|
||||
if err != nil {
|
||||
cc.Error(err, "error running hook", "followerHook", cfg.FollowerHook)
|
||||
}
|
||||
|
|
@ -52,8 +52,7 @@ func NewVIPController(cfg *config.Config) (callbacks cluster.Callbacks, err erro
|
|||
}
|
||||
for {
|
||||
cc.Info("following", "id", cc.ID())
|
||||
//TODO
|
||||
//deleteIPs(cc, n, cfg.VirtualIPs)
|
||||
deleteIPs(cc, n, cfg.VirtualIPs)
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
t.Stop()
|
||||
|
|
|
|||
|
|
@ -1,159 +1,30 @@
|
|||
// +build linux
|
||||
|
||||
// These syscalls are only supported on Linux, so this uses a build directive during compilation. Other OS's will use the arp_unsupported.go and receive an error
|
||||
|
||||
package vip
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/binary"
|
||||
"fmt"
|
||||
"net"
|
||||
"syscall"
|
||||
"unsafe"
|
||||
|
||||
"github.com/mdlayher/arp"
|
||||
"github.com/mdlayher/ethernet"
|
||||
)
|
||||
|
||||
const (
|
||||
opARPRequest = 1
|
||||
opARPReply = 2
|
||||
hwLen = 6
|
||||
)
|
||||
|
||||
var (
|
||||
ethernetBroadcast = net.HardwareAddr{0xff, 0xff, 0xff, 0xff, 0xff, 0xff}
|
||||
// arpRequest is used to flip between garp request or garp reply
|
||||
arpRequest = true
|
||||
)
|
||||
|
||||
func htons(p uint16) uint16 {
|
||||
var b [2]byte
|
||||
binary.BigEndian.PutUint16(b[:], p)
|
||||
return *(*uint16)(unsafe.Pointer(&b))
|
||||
}
|
||||
|
||||
// arpHeader specifies the header for an ARP message.
|
||||
type arpHeader struct {
|
||||
hardwareType uint16
|
||||
protocolType uint16
|
||||
hardwareAddressLength uint8
|
||||
protocolAddressLength uint8
|
||||
opcode uint16
|
||||
}
|
||||
|
||||
// arpMessage represents an ARP message.
|
||||
type arpMessage struct {
|
||||
arpHeader
|
||||
senderHardwareAddress []byte
|
||||
senderProtocolAddress []byte
|
||||
targetHardwareAddress []byte
|
||||
targetProtocolAddress []byte
|
||||
}
|
||||
|
||||
// bytes returns the wire representation of the ARP message.
|
||||
func (m *arpMessage) bytes() ([]byte, error) {
|
||||
buf := new(bytes.Buffer)
|
||||
|
||||
if err := binary.Write(buf, binary.BigEndian, m.arpHeader); err != nil {
|
||||
return nil, fmt.Errorf("binary write failed: %v", err)
|
||||
}
|
||||
buf.Write(m.senderHardwareAddress)
|
||||
buf.Write(m.senderProtocolAddress)
|
||||
buf.Write(m.targetHardwareAddress)
|
||||
buf.Write(m.targetProtocolAddress)
|
||||
|
||||
return buf.Bytes(), nil
|
||||
}
|
||||
|
||||
// gratuitousARP return a gARP request or gARP reply alternatively
|
||||
// because different devices may support either one of them
|
||||
func gratuitousARP(ip net.IP, mac net.HardwareAddr) (*arpMessage, error) {
|
||||
if ip.To4() == nil {
|
||||
return nil, fmt.Errorf("%q is not an IPv4 address", ip)
|
||||
}
|
||||
if len(mac) != hwLen {
|
||||
return nil, fmt.Errorf("%q is not an Ethernet MAC address", mac)
|
||||
}
|
||||
|
||||
m := &arpMessage{
|
||||
arpHeader: arpHeader{
|
||||
1, // Ethernet
|
||||
0x0800, // IPv4
|
||||
hwLen, // 48-bit MAC Address
|
||||
net.IPv4len, // 32-bit IPv4 Address
|
||||
opARPReply, // ARP Reply
|
||||
},
|
||||
}
|
||||
|
||||
// https://tools.ietf.org/html/rfc5944#section-4.6
|
||||
// In either case, the ARP Sender Hardware Address is
|
||||
// set to the link-layer address to which this cache entry should be
|
||||
// updated.
|
||||
m.senderHardwareAddress = mac
|
||||
|
||||
// When using an ARP Reply packet, the Target Hardware
|
||||
// Address is also set to the link-layer address to which this cache
|
||||
// entry should be updated (this field is not used in an ARP Request
|
||||
// packet).
|
||||
m.targetHardwareAddress = mac
|
||||
|
||||
// In either case, the ARP Sender Protocol Address and
|
||||
// ARP Target Protocol Address are both set to the IP address of the
|
||||
// cache entry to be updated,
|
||||
m.senderProtocolAddress = ip.To4()
|
||||
m.targetProtocolAddress = ip.To4()
|
||||
|
||||
// send arpRequest and arpReply alternatively
|
||||
arpRequest = !arpRequest
|
||||
if arpRequest {
|
||||
m.arpHeader.opcode = opARPRequest
|
||||
|
||||
// this field is not used in an ARP Request packet
|
||||
m.targetHardwareAddress = ethernetBroadcast
|
||||
}
|
||||
|
||||
return m, nil
|
||||
}
|
||||
|
||||
// sendARP sends the given ARP message via the specified interface.
|
||||
func sendARP(iface *net.Interface, m *arpMessage) error {
|
||||
fd, err := syscall.Socket(syscall.AF_PACKET, syscall.SOCK_DGRAM, int(htons(syscall.ETH_P_ARP)))
|
||||
func sendARP(ip net.IP, iface *net.Interface) error {
|
||||
c, err := arp.Dial(iface)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to get raw socket: %v", err)
|
||||
return err
|
||||
}
|
||||
defer syscall.Close(fd)
|
||||
|
||||
if err := syscall.BindToDevice(fd, iface.Name); err != nil {
|
||||
return fmt.Errorf("failed to bind to device: %v", err)
|
||||
for _, op := range []arp.Operation{arp.OperationRequest, arp.OperationReply} {
|
||||
pkt, err := arp.NewPacket(op, iface.HardwareAddr, ip, ethernet.Broadcast, ip)
|
||||
if err != nil {
|
||||
return fmt.Errorf("assembling %q gratuitous packet for %q: %s", op, ip, err)
|
||||
}
|
||||
if err = c.WriteTo(pkt, ethernet.Broadcast); err != nil {
|
||||
return fmt.Errorf("writing %q gratuitous packet for %q: %s", op, ip, err)
|
||||
}
|
||||
}
|
||||
|
||||
ll := syscall.SockaddrLinklayer{
|
||||
Protocol: htons(syscall.ETH_P_ARP),
|
||||
Ifindex: iface.Index,
|
||||
Pkttype: 0, // syscall.PACKET_HOST
|
||||
Hatype: m.hardwareType,
|
||||
Halen: m.hardwareAddressLength,
|
||||
}
|
||||
target := ethernetBroadcast
|
||||
for i := 0; i < len(target); i++ {
|
||||
ll.Addr[i] = target[i]
|
||||
}
|
||||
|
||||
b, err := m.bytes()
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to convert ARP message: %v", err)
|
||||
}
|
||||
|
||||
if err := syscall.Bind(fd, &ll); err != nil {
|
||||
return fmt.Errorf("failed to bind: %v", err)
|
||||
}
|
||||
if err := syscall.Sendto(fd, b, 0, &ll); err != nil {
|
||||
return fmt.Errorf("failed to send: %v", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// ARPSendGratuitous sends a gratuitous ARP message via the specified interface.
|
||||
func ARPSendGratuitous(cidr, iface string) error {
|
||||
i, err := net.InterfaceByName(iface)
|
||||
if err != nil {
|
||||
|
|
@ -163,11 +34,5 @@ func ARPSendGratuitous(cidr, iface string) error {
|
|||
if err != nil {
|
||||
return fmt.Errorf("failed to parse cidr: %s", cidr)
|
||||
}
|
||||
|
||||
//log.Infof("Broadcasting ARP update for %s (%s) via %s", address, iface.HardwareAddr, iface.Name)
|
||||
m, err := gratuitousARP(ip, i.HardwareAddr)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return sendARP(i, m)
|
||||
return sendARP(ip, i)
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue