github.com/tonistiigi/docker@v0.10.1-0.20240229224939-974013b0dc6a/libnetwork/drivers/bridge/setup_ipv4_linux.go (about)

     1  package bridge
     2  
     3  import (
     4  	"context"
     5  	"errors"
     6  	"fmt"
     7  	"net"
     8  	"os"
     9  	"path/filepath"
    10  
    11  	"github.com/containerd/log"
    12  	"github.com/docker/docker/libnetwork/types"
    13  	"github.com/vishvananda/netlink"
    14  )
    15  
    16  func selectIPv4Address(addresses []netlink.Addr, selector *net.IPNet) (netlink.Addr, error) {
    17  	if len(addresses) == 0 {
    18  		return netlink.Addr{}, errors.New("unable to select an address as the address pool is empty")
    19  	}
    20  	if selector != nil {
    21  		for _, addr := range addresses {
    22  			if selector.Contains(addr.IP) {
    23  				return addr, nil
    24  			}
    25  		}
    26  	}
    27  	return addresses[0], nil
    28  }
    29  
    30  func setupBridgeIPv4(config *networkConfiguration, i *bridgeInterface) error {
    31  	// TODO(aker): the bridge driver panics if its bridgeIPv4 field isn't set. Once bridge subnet and bridge IP address
    32  	//             are decoupled, we should assign it only when it's really needed.
    33  	i.bridgeIPv4 = config.AddressIPv4
    34  
    35  	if !config.InhibitIPv4 {
    36  		addrv4List, err := i.addresses(netlink.FAMILY_V4)
    37  		if err != nil {
    38  			return fmt.Errorf("failed to retrieve bridge interface addresses: %v", err)
    39  		}
    40  
    41  		addrv4, _ := selectIPv4Address(addrv4List, config.AddressIPv4)
    42  
    43  		if !types.CompareIPNet(addrv4.IPNet, config.AddressIPv4) {
    44  			if addrv4.IPNet != nil {
    45  				if err := i.nlh.AddrDel(i.Link, &addrv4); err != nil {
    46  					return fmt.Errorf("failed to remove current ip address from bridge: %v", err)
    47  				}
    48  			}
    49  			log.G(context.TODO()).Debugf("Assigning address to bridge interface %s: %s", config.BridgeName, config.AddressIPv4)
    50  			if err := i.nlh.AddrAdd(i.Link, &netlink.Addr{IPNet: config.AddressIPv4}); err != nil {
    51  				return &IPv4AddrAddError{IP: config.AddressIPv4, Err: err}
    52  			}
    53  		}
    54  	}
    55  
    56  	if !config.Internal {
    57  		// Store the default gateway
    58  		i.gatewayIPv4 = config.AddressIPv4.IP
    59  	}
    60  
    61  	return nil
    62  }
    63  
    64  func setupGatewayIPv4(config *networkConfiguration, i *bridgeInterface) error {
    65  	if !i.bridgeIPv4.Contains(config.DefaultGatewayIPv4) {
    66  		return &ErrInvalidGateway{}
    67  	}
    68  	if config.Internal {
    69  		return types.InvalidParameterErrorf("no gateway can be set on an internal bridge network")
    70  	}
    71  
    72  	// Store requested default gateway
    73  	i.gatewayIPv4 = config.DefaultGatewayIPv4
    74  
    75  	return nil
    76  }
    77  
    78  func setupLoopbackAddressesRouting(config *networkConfiguration, i *bridgeInterface) error {
    79  	sysPath := filepath.Join("/proc/sys/net/ipv4/conf", config.BridgeName, "route_localnet")
    80  	ipv4LoRoutingData, err := os.ReadFile(sysPath)
    81  	if err != nil {
    82  		return fmt.Errorf("Cannot read IPv4 local routing setup: %v", err)
    83  	}
    84  	// Enable loopback addresses routing only if it isn't already enabled
    85  	if ipv4LoRoutingData[0] != '1' {
    86  		if err := os.WriteFile(sysPath, []byte{'1', '\n'}, 0o644); err != nil {
    87  			return fmt.Errorf("Unable to enable local routing for hairpin mode: %v", err)
    88  		}
    89  	}
    90  	return nil
    91  }