common.sh: revert VNET function

This commit is contained in:
tschettervictor
2025-01-06 12:41:30 -07:00
committed by GitHub
parent e9ad74d000
commit a9bd2d55c1

View File

@@ -222,73 +222,46 @@ generate_static_mac() {
} }
generate_vnet_jail_netblock() { generate_vnet_jail_netblock() {
local jail_name="${1}" local jail_name="$1"
local use_unique_bridge="${2}" local use_unique_bridge="$2"
local external_interface="${3}" local external_interface="$3"
# setting this to 1 temprarily until we integrate the -M switch generate_static_mac "${jail_name}" "${external_interface}"
local static_mac=1 ## determine number of containers + 1
## determine number of interfaces + 1
## iterate num and grep all jail configs ## iterate num and grep all jail configs
## define uniq_epair ## define uniq_epair
local _epair_if_count="$(grep -Eos 'epair[1-9]+' ${bastille_jailsdir}/*/jail.conf | sort -u | wc -l | awk '{print $1}')" local jail_list="$(bastille list jails)"
local _vnet_if_count="$(grep -Eos 'bastille[1-9]+' ${bastille_jailsdir}/*/jail.conf | sort -u | wc -l | awk '{print $1}')" if [ -n "${jail_list}" ]; then
local epair_num_range=$((_epair_if_count + 1)) local list_jails_num="$(echo "${jail_list}" | wc -l | awk '{print $1}')"
local vnet_num_range=$((_vnet_if_count + 1)) local num_range=$((list_jails_num + 1))
if [ -n "${use_unique_bridge}" ]; then for _num in $(seq 0 "${num_range}"); do
if [ "${_epair_if_count}" -gt 0 ]; then if ! grep -q "e[0-9]b_bastille${_num}" "${bastille_jailsdir}"/*/jail.conf; then
for _num in $(seq 1 "${epair_num_range}"); do if ! grep -q "epair${_num}" "${bastille_jailsdir}"/*/jail.conf; then
if ! grep -osq "epair${_num}" ${bastille_jailsdir}/*/jail.conf; then local uniq_epair="bastille${_num}"
local uniq_epair_bridge="${_num}" local uniq_epair_bridge="${_num}"
break break
fi fi
done
else
local uniq_epair_bridge="1"
fi
else
if [ "${_vnet_if_count}" -gt 0 ]; then
for _num in $(seq 1 "${vnet_num_range}"); do
if ! grep -osq "bastillle${_num}" ${bastille_jailsdir}/*/jail.conf; then
local uniq_epair="bastille${_num}"
break
fi fi
done done
else else
local uniq_epair="bastille1" local uniq_epair="bastille0"
local uniq_epair_bridge="0"
fi fi
fi
## If BRIDGE is enabled, generate bridge config, else generate VNET config
if [ -n "${use_unique_bridge}" ]; then if [ -n "${use_unique_bridge}" ]; then
if [ -n "${static_mac}" ]; then ## generate bridge config
## Generate bridged VNET config with static MAC address
generate_static_mac "${jail_name}" "${external_interface}"
cat <<-EOF cat <<-EOF
vnet; vnet;
vnet.interface = epair${uniq_epair_bridge}b; vnet.interface = e${uniq_epair_bridge}b_${jail_name};
exec.prestart += "ifconfig epair${uniq_epair_bridge} create"; exec.prestart += "ifconfig epair${uniq_epair_bridge} create";
exec.prestart += "ifconfig ${external_interface} addm epair${uniq_epair_bridge}a"; exec.prestart += "ifconfig ${external_interface} addm epair${uniq_epair_bridge}a";
exec.prestart += "ifconfig epair${uniq_epair_bridge}a ether ${macaddr}a"; exec.prestart += "ifconfig epair${uniq_epair_bridge}a up name e${uniq_epair_bridge}a_${jail_name}";
exec.prestart += "ifconfig epair${uniq_epair_bridge}b ether ${macaddr}b"; exec.prestart += "ifconfig epair${uniq_epair_bridge}b up name e${uniq_epair_bridge}b_${jail_name}";
exec.prestart += "ifconfig epair${uniq_epair_bridge}a description \"vnet host interface for Bastille jail ${jail_name}\""; exec.prestart += "ifconfig e${uniq_epair_bridge}a_${jail_name} ether ${macaddr}a";
exec.poststop += "ifconfig ${external_interface} deletem epair${uniq_epair_bridge}a"; exec.prestart += "ifconfig e${uniq_epair_bridge}b_${jail_name} ether ${macaddr}b";
exec.poststop += "ifconfig epair${uniq_epair_bridge}a destroy"; exec.poststop += "ifconfig ${external_interface} deletem e${uniq_epair_bridge}a_${jail_name}";
exec.poststop += "ifconfig e${uniq_epair_bridge}a_${jail_name} destroy";
EOF EOF
else else
## Generate bridged VNET config without static MAC address ## generate config
cat <<-EOF
vnet;
vnet.interface = epair${uniq_epair_bridge}b;
exec.prestart += "ifconfig epair${uniq_epair_bridge} create";
exec.prestart += "ifconfig ${external_interface} addm epair${uniq_epair_bridge}a";
exec.prestart += "ifconfig epair${uniq_epair_bridge}a description \"vnet host interface for Bastille jail ${jail_name}\"";
exec.poststop += "ifconfig ${external_interface} deletem epair${uniq_epair_bridge}a";
exec.poststop += "ifconfig epair${uniq_epair_bridge}a destroy";
EOF
fi
else
if [ -n "${static_mac}" ]; then
## Generate VNET config with static MAC address
generate_static_mac "${jail_name}" "${external_interface}"
cat <<-EOF cat <<-EOF
vnet; vnet;
vnet.interface = e0b_${uniq_epair}; vnet.interface = e0b_${uniq_epair};
@@ -298,16 +271,6 @@ EOF
exec.prestart += "ifconfig e0a_${uniq_epair} description \"vnet host interface for Bastille jail ${jail_name}\""; exec.prestart += "ifconfig e0a_${uniq_epair} description \"vnet host interface for Bastille jail ${jail_name}\"";
exec.poststop += "jib destroy ${uniq_epair}"; exec.poststop += "jib destroy ${uniq_epair}";
EOF EOF
else
## Generate VNET config without static MAC address
cat <<-EOF
vnet;
vnet.interface = e0b_${uniq_epair};
exec.prestart += "jib addm ${uniq_epair} ${external_interface}";
exec.prestart += "ifconfig e0a_${uniq_epair} description \"vnet host interface for Bastille jail ${jail_name}\"";
exec.poststop += "jib destroy ${uniq_epair}";
EOF
fi
fi fi
} }