+ n = self.findNIC(str(chaddr))
+ intf = self.find_interface_by_nic(n)
+ main_ip = ni.ifaddresses(config.xen.iface)[ni.AF_INET][0]['addr']
+ s.syslog(s.LOG_ERR, "Interface is %s" % (intf))
+ # Don't perform "other" actions if the machine isn't running
+ other_action = n.other_action if n.other_action and intf else ''
+ if other_action == 'renumber' or other_action == 'renumber_dhcp':
+ (n.ip, n.netmask, n.gateway, n.other_ip, n.other_netmask,
+ n.other_gateway) = (
+ n.other_ip, n.other_netmask, n.other_gateway, n.ip,
+ n.netmask, n.gateway)
+ other_action = n.other_action = 'dnat'
+ database.session.add(n)
+ database.session.flush()
+ if other_action == 'dnat':
+ # If the machine was booted in 'dnat' mode, then both
+ # routes were already added by the invirt-database script.
+ # If the machine was already on and has just been set to
+ # 'dnat' mode, we need to add the route for the 'other' IP.
+ # If the machine has just been 'renumbered' by us above,
+ # the IPs will be swapped and only the route for the main
+ # IP needs to be added. Just try adding both of them, and
+ # arp for whichever of them turns out to be new.
+ for parms in [(n.ip, n.gateway), (n.other_ip, n.other_gateway)]:
+ try:
+ p = Popen(['ip', 'route', 'add', parms[0], 'dev', intf, 'src', main_ip, 'metric', '2' if intf.startswith('vif') else '1'], stdout=PIPE, stderr=PIPE)
+ (out, err) = p.communicate()
+ if p.returncode == 0:
+ s.syslog(s.LOG_INFO, "Added route for IP %s to interface %s" % (parms[0], intf))
+ self.queue.put(parms)
+ sys.stderr.write(err)
+ sys.stdout.write(out)
+ except Exception as e:
+ s.syslog(s.LOG_ERR, "Could not add route for IP %s: %s" % (parms[0], e))
+ try:
+ # iptables will let you add the same rule again and again;
+ # let's not do that.
+ p = Popen(['iptables', '-t', 'nat', '-C', 'PREROUTING', '-d', n.other_ip, '-j', 'DNAT', '--to-destination', n.ip], stdout=PIPE, stderr=PIPE)
+ (out, err) = p.communicate()
+ sys.stderr.write(err)
+ sys.stdout.write(out)
+ if p.returncode != 0:
+ p2 = Popen(['iptables', '-t', 'nat', '-A', 'PREROUTING', '-d', n.other_ip, '-j', 'DNAT', '--to-destination', n.ip], stdout=PIPE, stderr=PIPE)
+ (out, err) = p2.communicate()
+ sys.stderr.write(err)
+ sys.stdout.write(out)
+ if p2.returncode == 0:
+ s.syslog(s.LOG_INFO, "Added DNAT for IP %s to %s" % (n.other_ip, n.ip))
+ else:
+ s.syslog(s.LOG_ERR, "Could not add DNAT for IP %s to %s" % (n.other_ip, n.ip))
+ except Exception as e:
+ s.syslog(s.LOG_ERR, "Could not check and/or add DNAT for IP %s to %s: %s" % (n.other_ip, n.ip, e))
+ if other_action == 'remove':
+ try:
+ p = Popen(['ip', 'route', 'del', n.other_ip, 'dev', intf, 'src', main_ip], stdout=PIPE, stderr=PIPE)
+ (out, err) = p.communicate()
+ sys.stderr.write(err)
+ sys.stderr.write(out)
+ if p.returncode == 0:
+ s.syslog(s.LOG_INFO, "Removed route for IP %s" % (n.other_ip))
+ else:
+ s.syslog(s.LOG_ERR, "Could not remove route for IP %s" % (n.other_ip))
+ except Exception as e:
+ s.syslog(s.LOG_ERR, "Could not run ip to remove route for IP %s: %s" % (n.other_ip, e))
+ try:
+ p = Popen(['iptables', '-t', 'nat', '-D', 'PREROUTING', '-d', n.other_ip, '-j', 'DNAT', '--to-destination', n.ip], stdout=PIPE, stderr=PIPE)
+ (out, err) = p.communicate()
+ sys.stderr.write(err)
+ sys.stdout.write(out)
+ if p.returncode == 0:
+ s.syslog(s.LOG_INFO, "Removed DNAT for IP %s" % (n.other_ip))
+ else:
+ s.syslog(s.LOG_ERR, "Could not remove DNAT for IP %s" % (n.other_ip))
+ except Exception as e:
+ s.syslog(s.LOG_ERR, "Could not run iptables to remove DNAT for IP %s: %s" % (n.other_ip, e))
+ n.other_ip = n.other_netmask = n.other_gateway = n.other_action = None
+ database.session.add(n)
+ database.session.flush()
+ # We went through the DISCOVER codepath already to populate some
+ # of the packet's parameters. If we renumbered the VM just above,
+ # the packet is set to offer them what they asked for - the old
+ # address. So, we'll send then a DHCPNACK and they'll come right
+ # back and be offered the new address. The code above won't be
+ # able to add duplicate routes, won't insert a duplicate DNAT,
+ # and won't ARP again because the routes will exist, so this won't
+ # incur much extra work.
+ if request != map(int, n.ip.split('.')):
+ return False