Compare commits

..

2 commits

Author SHA1 Message Date
d15454d35b
f-34: route: add test for route metadata #34
All checks were successful
Release Pipeline / set-release-target (push) Successful in 1s
Release Pipeline / upload-assets (agent.service, systemd/agent.service) (push) Successful in 3s
Release Pipeline / upload-assets (dnsmasq@.service, systemd/dnsmasq@.service) (push) Successful in 3s
Release Pipeline / upload-assets (metadata@.service, systemd/metadata@.service) (push) Successful in 3s
Release Pipeline / upload-assets (run-dnsmasq-in-netns.sh, scripts/run-dnsmasq-in-netns.sh) (push) Successful in 3s
Release Pipeline / build (agent, amd64, linux) (push) Successful in 0s
Release Pipeline / build (metadata, amd64, linux) (push) Successful in 0s
Release Pipeline / release (push) Successful in 11s
Release Pipeline / publish (push) Successful in 0s
Release Pipeline / build (push) Successful in 1m29s
Release Pipeline / checksums (push) Successful in 4s
Signed-off-by: GnomeZworc <nicolas.boufidjeline@g3e.fr>
2026-08-24 22:57:30 +02:00
a2170fff08
f-34: route: fix missing route for metadata #34
Signed-off-by: GnomeZworc <nicolas.boufidjeline@g3e.fr>
2026-08-24 22:57:03 +02:00
6 changed files with 126 additions and 29 deletions

View file

@ -55,7 +55,7 @@ func newConf(t *testing.T, cidr string) Config {
gw := net.ParseIP("192.168.1.1").To4()
return Config{
Network: network,
VPCGateway: gw,
InterfaceIP: net.ParseIP("192.168.1.254").To4(),
VPCRoute: vpcNet,
DefaultGateway: gw,
Name: "test",
@ -136,23 +136,19 @@ func TestGenerateConfig_VxlanEmitsNoRouterOption(t *testing.T) {
}
func TestGenerateConfig_ContainsVPCRoute(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
path, _, _ := GenerateConfig(conf)
content, _ := os.ReadFile(path)
if !strings.Contains(string(content), "dhcp-option=121,10.0.0.0/16,192.168.1.1") {
t.Errorf("dhcp-option=121 absente ou incorrecte :\n%s", content)
routes := route121(t, confLines(t, newConf(t, "192.168.1.0/29")))
if !strings.Contains(routes, "10.0.0.0/16,192.168.1.254") {
t.Errorf("route VPC absente, ou next-hop autre que l'interface_ip du subnet :\n%s", routes)
}
}
func TestGenerateConfig_NoVPCRoute(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
conf.VPCRoute = nil
path, _, _ := GenerateConfig(conf)
content, _ := os.ReadFile(path)
if strings.Contains(string(content), "dhcp-option=121,") {
t.Errorf("dhcp-option=121 présente alors que VPCRoute=nil :\n%s", content)
routes := route121(t, confLines(t, conf))
if strings.Contains(routes, "10.0.0.0/16") {
t.Errorf("route VPC présente alors que VPCRoute=nil :\n%s", routes)
}
}
@ -160,6 +156,7 @@ func TestGenerateConfig_ContainsDhcpRange(t *testing.T) {
_, network, _ := net.ParseCIDR("10.10.0.0/24")
conf := Config{
Network: network,
InterfaceIP: net.ParseIP("10.10.0.1").To4(),
Name: "vpc1",
ConfDir: t.TempDir(),
}
@ -205,6 +202,7 @@ func TestGenerateConfig_CreatesConfDir(t *testing.T) {
_, network, _ := net.ParseCIDR("10.0.0.0/30")
conf := Config{
Network: network,
InterfaceIP: net.ParseIP("10.0.0.1").To4(),
Name: "net",
ConfDir: dir,
}
@ -215,3 +213,79 @@ func TestGenerateConfig_CreatesConfDir(t *testing.T) {
t.Errorf("répertoire %q non créé", dir)
}
}
// --- option 121 : routes classless ---
func confLines(t *testing.T, c Config) string {
t.Helper()
path, _, err := GenerateConfig(c)
if err != nil {
t.Fatalf("GenerateConfig : %v", err)
}
content, err := os.ReadFile(path)
if err != nil {
t.Fatalf("lecture : %v", err)
}
return string(content)
}
func route121(t *testing.T, content string) string {
t.Helper()
for _, line := range strings.Split(content, "\n") {
if strings.HasPrefix(line, "dhcp-option=121,") {
return strings.TrimPrefix(line, "dhcp-option=121,")
}
}
t.Fatalf("aucune dhcp-option=121 dans :\n%s", content)
return ""
}
func TestGenerateConfig_AlwaysRoutesToMetadata(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
conf.VPCRoute = nil
conf.DefaultGateway = nil
routes := route121(t, confLines(t, conf))
if !strings.Contains(routes, "169.254.169.254/32,192.168.1.254") {
t.Errorf("sans route vers le serveur de métadonnées, cloud-init échoue et la VM n'est pas provisionnée :\n%s", routes)
}
}
func TestGenerateConfig_MetadataRouteEvenInBridgeMode(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
conf.VPCRoute = nil
routes := route121(t, confLines(t, conf))
if !strings.Contains(routes, "169.254.169.254/32") {
t.Errorf("le mode bridge a besoin de la même route :\n%s", routes)
}
}
func TestGenerateConfig_DefaultRouteAlsoInOption121(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
conf.VPCRoute = nil
routes := route121(t, confLines(t, conf))
if !strings.Contains(routes, "0.0.0.0/0,192.168.1.1") {
t.Errorf("RFC 3442 : un client qui lit l'option 121 ignore l'option 3, la route par défaut doit donc figurer dans la 121 :\n%s", routes)
}
}
func TestGenerateConfig_NoDefaultRouteMeansNoCatchAllInOption121(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
conf.DefaultGateway = nil
routes := route121(t, confLines(t, conf))
if strings.Contains(routes, "0.0.0.0/0") {
t.Errorf("aucune route par défaut demandée, la 121 ne doit pas en contenir :\n%s", routes)
}
}
func TestGenerateConfig_MissingInterfaceIPIsAnError(t *testing.T) {
conf := newConf(t, "192.168.1.0/29")
conf.InterfaceIP = nil
if _, _, err := GenerateConfig(conf); err == nil {
t.Error("sans interface_ip aucune route metadata n'est possible : il faut échouer, pas écrire une conf muette")
}
}

View file

@ -6,17 +6,20 @@ import (
"os"
"path/filepath"
"strings"
"git.g3e.fr/syonad/two/internal/metadata"
)
func GenerateConfig(c Config) (string, map[string]string, error) {
if c.InterfaceIP == nil {
return "", nil, fmt.Errorf("interface ip is required: guests would have no route to the metadata server")
}
mask := fmt.Sprintf("%d.%d.%d.%d", c.Network.Mask[0], c.Network.Mask[1], c.Network.Mask[2], c.Network.Mask[3])
var sb strings.Builder
fmt.Fprintf(&sb, "no-resolv\n")
fmt.Fprintf(&sb, "dhcp-range=%s,static,%s,12h\n", c.Network.IP.String(), mask)
if c.VPCRoute != nil {
fmt.Fprintf(&sb, "dhcp-option=121,%s,%s\n", c.VPCRoute.String(), c.VPCGateway.String())
}
fmt.Fprintf(&sb, "dhcp-option=121,%s\n", strings.Join(classlessRoutes(c), ","))
if c.DefaultGateway != nil {
fmt.Fprintf(&sb, "dhcp-option=3,%s\n", c.DefaultGateway.String())
} else {
@ -40,6 +43,19 @@ func GenerateConfig(c Config) (string, map[string]string, error) {
return outPath, entries, os.WriteFile(outPath, []byte(sb.String()), 0644)
}
func classlessRoutes(c Config) []string {
nextHop := c.InterfaceIP.String()
routes := []string{metadata.ServiceIP + "/32," + nextHop}
if c.VPCRoute != nil {
routes = append(routes, c.VPCRoute.String()+","+nextHop)
}
if c.DefaultGateway != nil {
routes = append(routes, "0.0.0.0/0,"+c.DefaultGateway.String())
}
return routes
}
func incrementIP(ip net.IP) {
for j := len(ip) - 1; j >= 0; j-- {
ip[j]++

View file

@ -8,9 +8,9 @@ const DefaultConfDir = "/etc/dnsmasq.d"
type Config struct {
Network *net.IPNet
VPCGateway net.IP // next-hop for VPCRoute (option 121)
VPCRoute *net.IPNet // if non-nil, emit dhcp-option=121,VPCRoute,VPCGateway
DefaultGateway net.IP // if non-nil, emit dhcp-option=3,DefaultGateway; if nil, emit a bare dhcp-option=3 to suppress the dnsmasq default
InterfaceIP net.IP // subnet gateway; next-hop for the metadata and VPC routes
VPCRoute *net.IPNet // if non-nil, routed via InterfaceIP in option 121
DefaultGateway net.IP // if non-nil, default route via option 3 and 0.0.0.0/0 in option 121
Name string
ConfDir string
}

View file

@ -3,6 +3,8 @@ package iptables
import (
"fmt"
"os/exec"
"git.g3e.fr/syonad/two/internal/metadata"
)
func addRule(args ...string) error {
@ -16,7 +18,7 @@ func deleteRule(args ...string) error {
func AddMetadataRedirect(vmIP, gatewayIP, metadataPort string) error {
if err := addRule("PREROUTING",
"-s", vmIP+"/32",
"-d", "169.254.169.254/32",
"-d", metadata.ServiceIP+"/32",
"-p", "tcp", "-m", "tcp",
"--dport", "80",
"-j", "DNAT",
@ -30,7 +32,7 @@ func AddMetadataRedirect(vmIP, gatewayIP, metadataPort string) error {
func DeleteMetadataRedirect(vmIP, gatewayIP, metadataPort string) error {
if err := deleteRule("PREROUTING",
"-s", vmIP+"/32",
"-d", "169.254.169.254/32",
"-d", metadata.ServiceIP+"/32",
"-p", "tcp", "-m", "tcp",
"--dport", "80",
"-j", "DNAT",

View file

@ -1,5 +1,10 @@
package metadata
// ServiceIP is the well-known address guests use to reach the metadata server.
// Traffic to it is DNATed to the subnet gateway by internal/iptables, and the
// route to it is advertised by internal/dhcp.
const ServiceIP = "169.254.169.254"
type NoCloudData struct {
MetaData string
UserData string

View file

@ -139,10 +139,10 @@ func startDHCP(db *badger.DB, subnetName string, d subnetData) error {
Network: d.cidr,
Name: d.vpc + "_" + d.bridge,
ConfDir: dhcp.DefaultConfDir,
InterfaceIP: d.interfaceIP,
}
switch d.mode {
case "vxlan":
conf.VPCGateway = d.interfaceIP
conf.VPCRoute = d.vpcCIDR
case "bridge":
if d.defaultRoute {