forked from containers/podman
-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathnetworking_slirp4netns.go
106 lines (96 loc) · 3.28 KB
/
networking_slirp4netns.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
//go:build !remote && linux
package libpod
import (
"fmt"
"io"
"net"
"os"
"path/filepath"
"github.com/containers/common/libnetwork/slirp4netns"
"github.com/containers/common/libnetwork/types"
"github.com/containers/podman/v5/pkg/errorhandling"
"github.com/sirupsen/logrus"
)
// setupSlirp4netns can be called in rootful as well as in rootless
func (r *Runtime) setupSlirp4netns(ctr *Container, netns string) error {
ports := ctr.convertPortMappings()
if !ctr.config.PostConfigureNetNS {
var err error
ctr.rootlessSlirpSyncR, ctr.rootlessSlirpSyncW, err = os.Pipe()
if err != nil {
return fmt.Errorf("failed to create rootless network sync pipe: %w", err)
}
if len(ports) > 0 {
ctr.rootlessPortSyncR, ctr.rootlessPortSyncW, err = os.Pipe()
if err != nil {
return fmt.Errorf("failed to create rootless port sync pipe: %w", err)
}
}
}
defer errorhandling.CloseQuiet(ctr.rootlessSlirpSyncR)
if ctr.rootlessPortSyncR != nil {
defer errorhandling.CloseQuiet(ctr.rootlessPortSyncR)
}
res, err := slirp4netns.Setup(&slirp4netns.SetupOptions{
Config: r.config,
ContainerID: ctr.ID(),
Netns: netns,
Ports: ports,
ExtraOptions: ctr.config.NetworkOptions[slirp4netns.BinaryName],
Slirp4netnsExitPipeR: ctr.rootlessSlirpSyncR,
RootlessPortExitPipeR: ctr.rootlessPortSyncR,
})
if err != nil {
return err
}
ctr.slirp4netnsSubnet = res.Subnet
return nil
}
func (r *Runtime) setupRootlessPortMappingViaRLK(ctr *Container, netnsPath string, netStatus map[string]types.StatusBlock) error {
var err error
if !ctr.config.PostConfigureNetNS {
ctr.rootlessPortSyncR, ctr.rootlessPortSyncW, err = os.Pipe()
if err != nil {
return fmt.Errorf("failed to create rootless port sync pipe: %w", err)
}
}
defer errorhandling.CloseQuiet(ctr.rootlessPortSyncR)
return slirp4netns.SetupRootlessPortMappingViaRLK(&slirp4netns.SetupOptions{
Config: r.config,
ContainerID: ctr.ID(),
Netns: netnsPath,
Ports: ctr.convertPortMappings(),
RootlessPortExitPipeR: ctr.rootlessPortSyncR,
}, nil, netStatus)
}
// reloadRootlessRLKPortMapping will trigger a reload for the port mappings in the rootlessport process.
// This should only be called by network connect/disconnect and only as rootless.
func (c *Container) reloadRootlessRLKPortMapping() error {
if len(c.config.PortMappings) == 0 {
return nil
}
childIP := slirp4netns.GetRootlessPortChildIP(nil, c.state.NetworkStatus)
logrus.Debugf("reloading rootless ports for container %s, childIP is %s", c.config.ID, childIP)
conn, err := openUnixSocket(filepath.Join(c.runtime.config.Engine.TmpDir, "rp", c.config.ID))
if err != nil {
return fmt.Errorf("could not reload rootless port mappings, port forwarding may no longer work correctly: %w", err)
}
defer conn.Close()
enc := json.NewEncoder(conn)
err = enc.Encode(childIP)
if err != nil {
return fmt.Errorf("port reloading failed: %w", err)
}
b, err := io.ReadAll(conn)
if err != nil {
return fmt.Errorf("port reloading failed: %w", err)
}
data := string(b)
if data != "OK" {
return fmt.Errorf("port reloading failed: %s", data)
}
return nil
}
func getSlirp4netnsIP(subnet *net.IPNet) (*net.IP, error) {
return slirp4netns.GetIP(subnet)
}