Commit Graph
100 Commits
Author SHA1 Message Date
Michael Stapelberg a2ea8c2f95 cmd/dhcp4d: refactor for testing, add /lease/ test 2020-01-31 19:00:51 +01:00
Michael Stapelberg 4558cb61b4 dhcp4d: serve lease json data at /lease/<hostname> 2020-01-31 18:30:18 +01:00
Michael Stapelberg 3707ba290c dhcp4d: move http.HandleFunc into logic 2020-01-31 18:25:02 +01:00
Michael Stapelberg 41985d6378 dhcp4d: reduce lease period to 20 minutes
This forces devices to renew the lease more often, which is nice when you want
to tie home automation behavior to DHCP lease validity.
2020-01-31 18:23:50 +01:00
Michael Stapelberg e76886dab4 dhcp4d: protect leases with a mutex
The HTTP handler runs in a separate goroutine.
2020-01-31 18:23:19 +01:00
Michael Stapelberg 73bd5c6a50 dhcp6: T1 is now already a time.Duration
see https://github.com/insomniacslk/dhcp/pull/347
2020-01-03 08:06:17 +01:00
Michael Stapelberg 70edcab16b dns: return NXDOMAIN for DHCP leases once they expire 2019-09-07 19:27:12 +02:00
Michael Stapelberg fa82132962 dhcp4d: add HostnameOverride field
This can be used to permanently override a hostname, regardless of whether the
lease is static or not. We use a separate field because we want devices to be
able to change their hostname themselves, until we override it.
2019-08-30 09:06:21 +02:00
Michael Stapelberg 4cde5ec6fc dns: fix resolution of uppercase host names, add test 2019-08-07 18:18:51 +02:00
Michael Stapelberg 9fe38edec0 netconfig_test: force an order for IP address golden output 2019-08-07 18:13:52 +02:00
Michael Stapelberg 8fb81f90b1 dns: make more recent DHCP leases overwrite older ones
fixes #20
2019-07-20 12:23:48 +02:00
Michael Stapelberg 36995097b9 make local name resolution case-insensitive
fixes #34
2019-07-20 12:07:30 +02:00
Michael Stapelberg 975f05d7ac fix dhcp4d_test.go 2019-07-20 11:30:52 +02:00
Michael Stapelberg 323cc42b8e dhcp4d: polish status page, actually update it upon changes 2019-07-20 11:07:11 +02:00
Michael Stapelberg c602f1d6b6 dhcp4d: introduce -interface flag 2019-07-20 10:50:30 +02:00
Michael Stapelberg c211763b5d dhcp4d: indent leases.json for easier human editing 2019-07-20 10:49:53 +02:00
Michael Stapelberg c0067c5aa5 change diff order to -want +got
This is easier to read and consistent with how we do things at work.
2019-07-11 08:42:21 +02:00
Michael Stapelberg 414a7c025b use nft’s --numeric flag for stable output across 0.9.0 and 0.9.1
nftables 0.9.1 started printing e.g. “priority 0” as “priority filter”.
2019-07-11 08:39:08 +02:00
Michael Stapelberg 554d7fa8bf netconfig_test: fix goldens after nftables change
The nftables package started honoring the rule position (insert vs. append), and
it turns out our goldens have been wrong all along. Now the configured order
matches the golden order.
2019-07-11 08:28:33 +02:00
Michael Stapelberg fa91770b09 integration/dns: 8.8.8.8’s RDNS changed to dns.google. 2019-07-01 08:55:10 +02:00
Michael Stapelberg 373c83196d dhcp4: make interface and state directory configurable
This is useful for manual testing on separate interfaces.
2019-06-06 07:52:08 +02:00
Michael Stapelberg 54843950dd dhcp6: allow overriding hardwareaddr in test
This fixes the breakage introduced by commit
https://github.com/insomniacslk/dhcp/commit/8166b9a9db9b180c02622ebf3dcff01ff2b2e0a6
2019-04-29 19:16:19 +02:00
Michael Stapelberg 02741e8d28 travis: remove debugging statements 2019-04-29 19:09:08 +02:00
Michael Stapelberg 4a1d06f5f8 travis: list links/addresses for debugging 2019-04-29 19:02:39 +02:00
Michael Stapelberg ea8efe1978 log hardwareAddr for debugging travis 2019-04-29 19:02:39 +02:00
Michael Stapelberg 82b41d1cc3 travis: switch to go vet 2019-04-29 18:42:29 +02:00
Michael Stapelberg 844f528ed8 travis: enable IPv6 before running tests 2019-04-29 18:42:15 +02:00
Michael Stapelberg 1a65f972c6 dhcp6: only call net.InterfaceByName when client is constructed 2019-04-16 08:36:06 +02:00
Michael Stapelberg 3765287e97 dhcp4: use SetReadDeadline, not SetDeadline
fixes https://github.com/rtr7/router7/issues/25

related to https://github.com/mdlayher/raw/issues/42
2019-03-21 09:18:32 +01:00
Michael Stapelberg 7b1fcc9017 travis: use go1.12
https://github.com/mdlayher/raw/pull/40 requires go1.12
2019-03-03 16:36:25 +01:00
Michael Stapelberg 8906854211 fix compilation after https://github.com/mdlayher/netlink/pull/127 2019-03-03 16:09:20 +01:00
Michael Stapelberg 3dad1e9a23 dhcp4: use the configured (not the current) MAC address
This fixes a race where dhcp4 started before netconfigd had a chance to change
the hardware address on the uplink0 interface.

fiber7’s port security feature may result in an about hour-long internet outage
without this commit.
2019-02-19 09:39:16 +01:00
Michael Stapelberg 66942bd4f7 dns: steer traffic toward the most response upstream
There is not much of a difference between IPv4 and IPv6 on my fiber7 link, but
in other networks, there might well be.

For my connection, this commit results in hitting different upstreams all the
time because the list isn’t stable. But, this is the opposite of a problem: we
are spreading the DNS query load over all configured IPs, as good netizen do.
2019-02-19 09:37:38 +01:00
Michael Stapelberg a05f027765 dns: fallback only once, i.e. prefer the working server next time 2019-02-19 08:49:40 +01:00
Michael Stapelberg ccaf6ad452 dns: fallback to next upstream upon failure 2019-02-19 08:38:52 +01:00
Michael Stapelberg abeddabbb7 dhcp4d: restrict lease details page to internal IPs 2019-02-19 07:50:39 +01:00
Michael Stapelberg 13926217d9 oui_test: fix data race when overriding ouiURL 2019-01-06 18:07:59 +01:00
Michael Stapelberg 6320b6c3a7 dhcp4d: display MAC vendor of each lease’s HardwareAddr 2019-01-06 18:02:01 +01:00
Michael Stapelberg 8df6329209 use renameio to write files atomically 2019-01-06 15:25:33 +01:00
Michael Stapelberg f67d4ec93f radvd: load extra prefixes from /perm/radvd/prefixes.json 2019-01-06 15:12:22 +01:00
Michael Stapelberg bd8fc63b0e dns: implement per-DHCP-lease dyndns
The HTTP API is easy to use from the command line or from Go:

% curl --data "host=sub&ip=192.168.33.44" -4 http://router7:8053/dyndns
ok
% host sub.$(hostname)
sub.midna has address 192.168.33.44

This can be used in combination with https://github.com/gokrazy/gdns
2019-01-06 14:41:26 +01:00
Michael Stapelberg 92d995bf79 dns: return empty reply for non-A queries for DNS hostnames
instead of NXDOMAIN, which is incorrect
2019-01-01 17:21:50 +01:00
Michael Stapelberg c7be96ac2e dhcp4d: fix IP address comparison
AFAICT, this wasn’t actually a bug: canLease performs the correct check.
2019-01-01 10:45:03 +01:00
Michael Stapelberg 0d2e89cebf dhcp4d_test: fix message to match comparison 2019-01-01 10:44:03 +01:00
Michael Stapelberg b923f145a5 dhcp4d: don’t incorrectly _offer_ reused addresses
Turns out a5d9e03dd3 was not entirely sufficient:
even though reused addresses would not be handed out anymore, they would still
be offered, which results in the client not being able to obtain an address.
2019-01-01 10:41:29 +01:00
Michael Stapelberg ddcdd39737 dhcp4: drop last ack to restart with DISCOVER upon receiving NAK
fixes #13
2018-12-25 14:10:21 +01:00
Michael Stapelberg 725262d376 netconfig: use sysctl format for easier copy&paste 2018-12-25 14:08:14 +01:00
Michael Stapelberg 9012520052 diag: more informative error messages 2018-12-15 13:36:21 +01:00
Michael Stapelberg 5eaba2aa4d travis: switch to go 1.11 2018-12-15 12:49:34 +01:00
Michael Stapelberg a5d9e03dd3 dhcp4d: don’t incorrectly hand out reused addresses
fixes #18
2018-12-15 12:44:09 +01:00
Michael Stapelberg badee1eef8 netconfig_test: skip test if WireGuard is unavailable 2018-11-26 18:43:04 +01:00
Michael Stapelberg ec4f1f4dc5 netconfig: implement WireGuard support
To set up a tunnel, create a /perm/wireguard.json as illustrated in
netconfig_test.go, and don’t forget to adjust your /perm/interfaces.json with
the address configuration for the WireGuard tunnel.

Note that static routes cannot currently be configured, so the usefulness is
limited. If you have a use-case you’d like to see covered, please explain it in
https://github.com/rtr7/router7/issues/14
2018-11-26 18:29:03 +01:00
Michael Stapelberg b6a5227d49 netconfig_test: better diffs, refactor for clarity/brevity 2018-11-26 08:46:59 +01:00
Michael Stapelberg 127bdc466e netconfig_test: use ip -netns instead of ip netns exec ip 2018-11-26 08:32:38 +01:00
Michael Stapelberg df9a40557c dhcp4: correctly check errors from c.once 2018-11-21 08:41:24 +01:00
Michael Stapelberg bef7168112 dhcp4: resolve TODOs in comments 2018-11-21 08:41:07 +01:00
Michael Stapelberg 5b34daeb4e no-op cleanup: switch to dhcp4.LeaseFromACK 2018-11-21 08:23:57 +01:00
Michael Stapelberg 8c55c5ba44 dhcp4: switch to github.com/rtr7/dhcp4
All existing DHCPv4 packages I looked at were unappealing for one reason or
another, so we’re now using a little helper to glue github.com/google/gopacket
and github.com/mdlayher/raw together, which suffices for our use-case and gives
us more control.
2018-11-21 08:18:58 +01:00
Michael Stapelberg 30e9a6677b integration/dhcpv4: print unified line-wise diff
This is much more readable than the go-cmp Diff() output when dealing with
[]string lines.
2018-11-18 14:29:30 +01:00
Michael Stapelberg fac1bf231e netconfigd: notify dhcp4d to update its listeners 2018-10-29 18:14:01 +01:00
Michael Stapelberg 7d278289f0 captured: directly call NextPacket() to prevent hanging reads
Using Packets() spawns off a separate goroutine which calls NextPacket in a loop
until io.EOF is returned. This goroutine will stick around after Close()
returned, resulting in only the first wireshark connection working.
2018-10-23 09:56:07 +02:00
Michael Stapelberg d9f5d95812 dhcp4d: export number of non-expired DHCP leases 2018-10-23 08:49:29 +02:00
Michael Stapelberg 4288adec69 dns: don’t let clients override the hostname
fixes #11
2018-10-22 21:43:41 +02:00
Michael Stapelberg 0bbc1d923d refactor replayer code into pcapreplayer package 2018-10-22 21:04:35 +02:00
Michael Stapelberg e01a38ff78 commit debug statements 2018-10-22 18:58:40 +02:00
Michael Stapelberg 817fdc81f8 README: recommend to install all rtr7 tools 2018-10-22 18:58:40 +02:00
Michael Stapelberg 2e8e0daa0a implement TCP MSS clamping (for non-ethernet uplinks)
We didn’t have a need to clamp the TCP Maximum Segment Size (MSS) up until now,
because fiber7 uses an MTU of 1500.

Because Path MTU discovery is often broken on the internet, it’s best practice
to limit the Maximum Segment Size (MSS) of each TCP connection, achieving the
same effect (but only for TCP connections).

This change is beneficial when running router7 behind a non-ethernet uplink,
such as a Fritz!Box cable modem.

This has no adverse effect on fiber7: after clamping, the MSS is still 1440, as
without clamping.
2018-10-22 18:54:25 +02:00
Michael Stapelberg c037bf9c5f dhcp4d: fix panic when receiving unsupported requests 2018-10-22 18:39:25 +02:00
Michael Stapelberg 672134080f README: reference prometheus config + dashboard 2018-10-10 16:52:42 +02:00
Michael Stapelberg b725100d9c add prometheus configuration examples 2018-10-10 16:49:45 +02:00
Michael Stapelberg f606e70250 dhcp4d: respect broadcast bit
Mac’s Internet Recovery DHCP client requires broadcast responses and will ignore
unicast responses outright.
2018-10-07 17:36:00 +02:00
Michael Stapelberg f7638dfeaa netconfig_test: test updating port forwardings after installation
This uncovered an nftables issue:
https://github.com/google/nftables/commit/695079ebffbbd1e2f68b3e235977ceb42e21c182
2018-10-03 18:24:54 +02:00
Michael Stapelberg ea4ffa7bec OpenEthernet → NewEthernetHandle, remove kludge 2018-09-07 00:50:41 +02:00
Michael Stapelberg 447f1779e2 dhcp6: update for breaking upstream changes
see https://github.com/insomniacslk/dhcp/pull/81
2018-09-05 08:39:35 +02:00
Michael Stapelberg 4c4032d469 README: add radvd as consumer of dhcp6 lease file 2018-08-20 22:59:22 +02:00
Michael Stapelberg 14f1636bc0 travis: upgrade to xenial (Ubuntu 16.04)
Perhaps this will use a newer kernel with support for nftables stateful objects?
2018-08-10 09:37:25 +02:00
Michael Stapelberg b03596f1c5 nftables: use stateful object counters
This way, we can atomically get and reset them.

fixes https://github.com/rtr7/router7/issues/3
2018-08-08 23:15:21 +02:00
Michael Stapelberg ad779c3665 dhcp6: update for breaking upstream changes 2018-08-05 11:45:03 +02:00
Michael Stapelberg 5a5a748b9f dnsd: don’t serve expired leases
fixes #6
2018-08-05 11:30:58 +02:00
Michael Stapelberg daa14845ab netconfig: plug fd leak by closing the netlink handle
fixes #4
2018-07-22 23:07:23 +02:00
Michael Stapelberg c5e5a0eee0 radvd: gather details about the interface on SIGUSR1
The interface might have a new MAC address (if radvd was started before netconfigd).
2018-07-16 22:46:49 +02:00
Michael Stapelberg 49a59779f5 dhcp4d: don’t offer expired leases 2018-07-15 18:33:11 +02:00
Michael Stapelberg a9c7585eac README: add travis badge 2018-07-14 20:57:27 +02:00
Michael Stapelberg 4a85c51b9f add travis config 2018-07-14 20:53:24 +02:00
Michael Stapelberg 3282dc5675 netconfig: GetRule filtering is not supported by Linux 4.4.0 (trusty) 2018-07-14 20:53:15 +02:00
Michael Stapelberg ea10307b5d dhcpv4: replace hard-coded midna → os.Hostname() 2018-07-14 17:35:25 +02:00
Michael Stapelberg bfa16c559f dnsmasq: gracefully handle temporarily not existing ready files 2018-07-14 16:42:50 +02:00
Michael Stapelberg 3afe757a34 notify: gracefully handle vanishing processes 2018-07-14 16:36:51 +02:00
Michael Stapelberg 9e0f83a7cf integration tests: send ip netns add errors to stderr, too 2018-07-14 15:43:47 +02:00
Michael Stapelberg 9131e7a99c dhcp6: add missing err parameter 2018-07-14 15:17:12 +02:00
Michael Stapelberg 8da684cc8f README: add godoc badge 2018-07-14 15:14:42 +02:00
Michael Stapelberg b08f872a65 add go report card 2018-07-14 14:55:30 +02:00
Michael Stapelberg 25ceda02ec README: get router7 repo explicitly 2018-07-14 14:34:08 +02:00
Michael Stapelberg 6b73254a72 write README.md 2018-07-14 14:03:02 +02:00
Michael Stapelberg 9153805e69 randomd moved to github.com/gokrazy/gokrazy/cmd/randomd 2018-07-14 12:51:28 +02:00
Michael Stapelberg b347ed74c5 update import paths 2018-07-09 08:54:04 +02:00
Michael Stapelberg 984e8802f7 dhcp6: log XIDs when they differ
Encountering this message can be perfectly normal, e.g. in a high-availability
setup, where two DHCP servers answer to your requests.
2018-07-03 17:37:25 +02:00
Michael Stapelberg b05fd74006 dhcp4: increase timeout to 10s 2018-07-03 17:37:17 +02:00
Michael Stapelberg 88bf7d90eb dhcp6: delay at least 10s before attempts
Otherwise we might exceed fiber7’s firewall rules and get blacklisted.
2018-07-03 17:36:46 +02:00
Michael Stapelberg 86f5433cbb dhcp6: correctly clear previous error 2018-06-29 12:02:16 +02:00