f-46: dhcp: add the dhcp binary, its unit and its wrapper #46
All checks were successful
Release Pipeline / set-release-target (push) Successful in 1s
Release Pipeline / upload-assets (agent.service, systemd/agent.service) (push) Successful in 3s
Release Pipeline / upload-assets (dhcp@.service, systemd/dhcp@.service) (push) Successful in 3s
Release Pipeline / upload-assets (dnsmasq@.service, systemd/dnsmasq@.service) (push) Successful in 3s
Release Pipeline / upload-assets (metadata@.service, systemd/metadata@.service) (push) Successful in 3s
Release Pipeline / upload-assets (run-dhcp-in-netns.sh, scripts/run-dhcp-in-netns.sh) (push) Successful in 3s
Release Pipeline / upload-assets (run-dnsmasq-in-netns.sh, scripts/run-dnsmasq-in-netns.sh) (push) Successful in 3s
Release Pipeline / build (metadata, amd64, linux) (push) Successful in 0s
Release Pipeline / build (agent, amd64, linux) (push) Successful in 0s
Release Pipeline / build (dhcp, amd64, linux) (push) Successful in 0s
Release Pipeline / checksums (push) Successful in 4s
Release Pipeline / release (push) Successful in 11s
Release Pipeline / build (push) Successful in 1m5s
Release Pipeline / publish (push) Successful in 0s

cmd/dhcp reçoit quatre paramètres en clair — interface, state, socket, conf —
sur le modèle de dnsmasq. Il ne compose aucun chemin, ne découpe aucun nom
composite et ignore le netns dans lequel il tourne : seul le wrapper en a besoin,
pour y entrer.

La boucle de lecture UDP est écrite à la main plutôt que confiée à
server4.Serve, qui lance une goroutine par datagramme sans borne et ne pose
aucun recover. Elle traite en ligne, réutilise un tampon de 1500 octets et pose
un recover par datagramme. NewIPv4UDPConn est conservé pour le SO_BROADCAST et
le bind à l'interface. Une réponse destinée à un client sans adresse part en
broadcast.

dhcp.run_dir n'est pas une clé de configuration : le wrapper code /run/two/dhcp
en dur et le Go utilise dhcpapi.DefaultRunDir, comme dhcp.DefaultConfDir pour
dnsmasq. Un test lit le script et vérifie que les deux s'accordent.

Le défaut dhcp.backend reste dnsmasq : un agent.yml de 0.1.0 se comporte comme
avant. deploy.sh et le pipeline publient le binaire, l'unit et le script.

La boucle est testée sur une vraie socket UDP en loopback. Neuf mutations, dont
une qui a révélé que le recover n'était couvert par rien.

Signed-off-by: GnomeZworc <nicolas.boufidjeline@g3e.fr>
This commit is contained in:
GnomeZworc 2026-08-31 19:48:50 +02:00
commit e00f456610
Signed by: nicolas.boufideline
GPG key ID: 4406BBBF8845D632
13 changed files with 579 additions and 2 deletions

View file

@ -0,0 +1,29 @@
package dhcpapi
import (
"path/filepath"
)
const (
DefaultRunDir = "/run/two/dhcp"
SocketExt = ".sock"
StateExt = ".state"
UnitExt = ".service"
UnitName = "dhcp@"
)
func Instance(vpc, bridge string) string {
return vpc + "_" + bridge
}
func Unit(instance string) string {
return UnitName + instance + UnitExt
}
func SocketPath(runDir, instance string) string {
return filepath.Join(runDir, instance+SocketExt)
}
func StatePath(runDir, instance string) string {
return filepath.Join(runDir, instance+StateExt)
}

View file

@ -0,0 +1,69 @@
package dhcpapi
import (
"os"
"strings"
"testing"
)
func TestInstance_JoinsVPCAndBridge(t *testing.T) {
if got := Instance("vp-admin", "br-000001"); got != "vp-admin_br-000001" {
t.Errorf("Instance = %s, want vp-admin_br-000001", got)
}
}
func TestUnit_NamesTheTemplatedService(t *testing.T) {
if got := Unit(Instance("vp-admin", "br-000001")); got != "dhcp@vp-admin_br-000001.service" {
t.Errorf("Unit = %s", got)
}
}
func TestSocketPath_SitsUnderTheRunDir(t *testing.T) {
got := SocketPath(DefaultRunDir, Instance("vp-admin", "br-000001"))
if got != "/run/two/dhcp/vp-admin_br-000001.sock" {
t.Errorf("SocketPath = %s", got)
}
}
func TestStatePath_SitsUnderTheRunDir(t *testing.T) {
got := StatePath(DefaultRunDir, Instance("vp-admin", "br-000001"))
if got != "/run/two/dhcp/vp-admin_br-000001.state" {
t.Errorf("StatePath = %s", got)
}
}
func TestPaths_NameTheVPCSoAListingIsReadable(t *testing.T) {
got := SocketPath(DefaultRunDir, Instance("vp-admin", "br-000001"))
if !strings.Contains(got, "vp-admin") {
t.Errorf("path = %s, want the vpc visible when listing the run dir", got)
}
}
func TestPaths_DistinguishTwoSubnetsOfTheSameVPC(t *testing.T) {
a := SocketPath(DefaultRunDir, Instance("vp-admin", "br-000001"))
b := SocketPath(DefaultRunDir, Instance("vp-admin", "br-000002"))
if a == b {
t.Error("two subnets must not share a control socket")
}
}
func TestSocketPath_StaysUnderTheUnixPathLimit(t *testing.T) {
got := SocketPath(DefaultRunDir, Instance("vp-000000", "br-000000"))
if len(got) > 100 {
t.Errorf("socket path is %d bytes (%s): sun_path caps at 104 on darwin and 108 on linux", len(got), got)
}
}
func TestDefaultRunDir_MatchesTheWrapperScript(t *testing.T) {
const script = "../../../scripts/run-dhcp-in-netns.sh"
raw, err := os.ReadFile(script)
if err != nil {
t.Fatalf("read %s: %v", script, err)
}
want := `RUN_DIR="` + DefaultRunDir + `"`
if !strings.Contains(string(raw), want) {
t.Errorf("%s does not set %s: the agent would talk to a socket the server never creates", script, want)
}
}