arplock.sh.in 2.22 KB
Newer Older
1 2 3 4 5 6 7 8
#!/bin/sh

# PROVIDE: arplock
# REQUIRE: netif
# BEFORE: pf ipfw routing
# KEYWORD: shutdown

#
9
# Copyright (c) 2012-2014 University of Utah and the Flux Group.
10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32
# 
# {{{EMULAB-LICENSE
# 
# This file is part of the Emulab network testbed software.
# 
# This file is free software: you can redistribute it and/or modify it
# under the terms of the GNU Affero General Public License as published by
# the Free Software Foundation, either version 3 of the License, or (at
# your option) any later version.
# 
# This file is distributed in the hope that it will be useful, but WITHOUT
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
# FITNESS FOR A PARTICULAR PURPOSE.  See the GNU Affero General Public
# License for more details.
# 
# You should have received a copy of the GNU Affero General Public License
# along with this file.  If not, see <http://www.gnu.org/licenses/>.
# 
# }}}
#

. /etc/emulab/paths.sh

33 34 35 36 37 38
#
# XXX allow a timeout on tmcc calls. Without timeout, ops/fs boot will hang
# if Emulab services (i.e., tmcd) are not running on boss.
# Set to zero for no timeout.
timo=5

39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59
if [ ! -x $BINDIR/fixarpinfo ]; then
    echo "*** fixarpinfo script missing, ARP lockdown not done"
    exit 0
fi

#
# XXX create some missing state if we are the ops node
#
if [ ! -r $BOOTDIR/controlif -a -x $BINDIR/findif ]; then
    iface=`$BINDIR/findif -i @USERNODE_IP@`
    if [ -n "$iface" ]; then
	echo $iface > $BOOTDIR/controlif
	echo @USERNODE_IP@ > $BOOTDIR/myip
    fi
fi

#
# ARP lockdown script. Has to run early, after network setup but before
# we start firing up daemons.
#
case "$1" in
60
start|faststart|quietstart|onestart|forcestart)
61
	echo "Setting up static ARP entries."
62
	$BINDIR/fixarpinfo -sv -t $timo >$LOGDIR/fixarpinfo.log 2>&1
63
	;;
64
restart|fastrestart|quietrestart|onerestart|forcerestart)
65
	echo "Updating static ARP entries."
66
	$BINDIR/fixarpinfo -uv -t $timo >$LOGDIR/fixarpinfo.log 2>&1
67
	;;
68
stop|faststop|quietstop|onestop|forcestop)
69
	echo "Removing static ARP entries."
70
	$BINDIR/fixarpinfo -cv -t $timo >$LOGDIR/fixarpinfo.log 2>&1
71 72 73
	;;
*)
	echo "Usage: `basename $0` {start|stop|restart}" >&2
74
	false
75 76
	;;
esac
77
stat=$?
78

79 80 81 82
if [ $timo -gt 0 -a $stat -eq 255 ]; then
    echo "WARNING: arpinfo call timed out; ARP not locked down!"
fi
exit $stat