From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2.migadu.com ([2001:41d0:403:58f0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms8.migadu.com with LMTPS id uMPZMVjmr2X1DgAAe85BDQ:P1 (envelope-from ) for ; Tue, 23 Jan 2024 17:16:25 +0100 Received: from aspmx1.migadu.com ([2001:41d0:403:58f0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2.migadu.com with LMTPS id uMPZMVjmr2X1DgAAe85BDQ (envelope-from ) for ; Tue, 23 Jan 2024 17:16:24 +0100 X-Envelope-To: larch@yhetil.org Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=soeren-tempel.net header.s=opensmtpd header.b="uKOQuTV/"; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=fail reason="SPF not aligned (relaxed)" header.from=soeren-tempel.net (policy=none) ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1706026584; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:dkim-signature; bh=FBkVxX9DhpxY7X8L8Y/WXaHkqP7d3CnQOY8GdsDfwzM=; b=SwOzECW8te7vIIKJ4LB8cUju1DdTbYxdAz4YXMtdL/3G95BEFfIrWBbvUUu7k/78kzIoDj v07UP5TRFlos1bOOL5xr8iqNOdG3UpWF/GxvthKlRtmilJ0L+lUnilp/NWPo1wf5ZTAJPn tbqmwomZVuE9q2CyFH5nIIiMxXb+Ie7t5aXaE2F/Up5jwGgGuCEXHrqO15gaVXlxxoVlFk deR0pqJnL/BWegkel0ikBWrxpg6ucmKuSmEE1uVo9Xx+J/X7fAbMq59vOO6FbGsgS0utB1 4DK5BJmTXDULZzDlgDf3H9X/+1qPNXlJEIf1Eibr00pf3jGK3ttD+NXlrynKyw== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=soeren-tempel.net header.s=opensmtpd header.b="uKOQuTV/"; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org"; dmarc=fail reason="SPF not aligned (relaxed)" header.from=soeren-tempel.net (policy=none) ARC-Seal: i=1; s=key1; d=yhetil.org; t=1706026584; a=rsa-sha256; cv=none; b=GvKMnsw8ij/6Ib1TAMkd0sMW//3236ZepK+KVcm//6OGU0rlfs0IzPXQaD9uZt8RcbYL4p ZUsP78GujuH4dvwwJOjwt2HEr8pqTWZtaKtrH/ZNTsLAMqd/HilTiyLLrCZd5x+LtDzZwq b7TfbXSLZrKx5s9VVjWRnpciRuGw+vDeuwlxSJT8R5oE0WxASVNNv5nwNSiVWy2O+nQKmy VQeW5SabTQCec9g7RXd6QQphzNM+qafws2JQ/dsvUsaQ9CrTCQ8CKFtiKAzapqnB6TIF97 4vMjc3gcK8hXLYi9SWAu9n3l9lAwMAC4ryz3oa8thJzV3PSiUBHVH9Eg36J72w== Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 9DE8D3C720 for ; Tue, 23 Jan 2024 17:16:24 +0100 (CET) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1rSJRf-00039Z-Ef; Tue, 23 Jan 2024 11:16:15 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rSJRO-00036P-6b for guix-patches@gnu.org; Tue, 23 Jan 2024 11:15:58 -0500 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1rSJRN-00077Z-QQ for guix-patches@gnu.org; Tue, 23 Jan 2024 11:15:57 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1rSJRS-00032I-Fe for guix-patches@gnu.org; Tue, 23 Jan 2024 11:16:02 -0500 X-Loop: help-debbugs@gnu.org Subject: [bug#68675] [PATCH] services: dhcp: Support the dhcpcd implementation. Resent-From: soeren@soeren-tempel.net Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Tue, 23 Jan 2024 16:16:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 68675 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 68675@debbugs.gnu.org Received: via spool by 68675-submit@debbugs.gnu.org id=B68675.170602652311581 (code B ref 68675); Tue, 23 Jan 2024 16:16:02 +0000 Received: (at 68675) by debbugs.gnu.org; 23 Jan 2024 16:15:23 +0000 Received: from localhost ([127.0.0.1]:43833 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1rSJQo-00030j-Ty for submit@debbugs.gnu.org; Tue, 23 Jan 2024 11:15:23 -0500 Received: from magnesium.8pit.net ([45.76.88.171]:32325) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1rSJQj-00030B-Cf; Tue, 23 Jan 2024 11:15:18 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; s=opensmtpd; bh=wvHlj9PHrj 9/m2osIm/SRuthX1y/0oGY2Y7OedtfoAk=; h=references:in-reply-to:date: subject:to:from; d=soeren-tempel.net; b=uKOQuTV/kOqGMdr8EVsXc8YZYbiLtc O7pNmFYIz1NN5/MPbafne/e4vyxO+lgT1l1AN3eXjkbGVKjzFdlXeBEnp9KPehUMMxoLTJ PUbfd+/6NFk7uKl42mfN0C/ss9uLiKCilWAh2L8XRgHyzIIRZ9KcPQF5ZORap87cN9JxYJ w= Received: from localhost (dynamic-2a02-3102-49da-001b-1300-cfa0-a067-980d.310.pool.telefonica.de [2a02:3102:49da:1b:1300:cfa0:a067:980d]) by magnesium.8pit.net (OpenSMTPD) with ESMTPSA id c4e14895 (TLSv1.3:TLS_AES_256_GCM_SHA384:256:YES); Tue, 23 Jan 2024 17:15:11 +0100 (CET) From: soeren@soeren-tempel.net Date: Tue, 23 Jan 2024 17:14:56 +0100 Message-ID: <68f1b45a7f8ced9bb57c661c0e7afa5136b5c673.1706026000.git.soeren@soeren-tempel.net> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: guix-patches-bounces+larch=yhetil.org@gnu.org X-Migadu-Flow: FLOW_IN X-Migadu-Country: US X-Migadu-Spam-Score: 3.34 X-Migadu-Queue-Id: 9DE8D3C720 X-Spam-Score: 3.34 X-Migadu-Scanner: mx11.migadu.com X-TUID: weNEvlaz9Tbq From: Sören Tempel Prior to this commit, the isc-dhcp implementation was the only DHCP implementation supported by dhcp-client-shepherd-service. This is problematic as the ISC implementation has reached end-of-life in 2022(!). As a first step to migrate away from isc-dhcp, this commit adds support for dhcpcd to dhcp-client-shepherd-service. Currently, it has to be enabled explicitly via the package field of the dhcp-client-configuration. In the future, it is intended to become the default to migrate away from isc-dhcp. See also: https://issues.guix.gnu.org/68619 * gnu/services/networking.scm (dhcp-client-shepherd-service): Add support for the dhcpcd client implementation. * gnu/services/networking.scm (dhcp-client-account-service): New procedure. * gnu/services/networking.scm (dhcp-client-service-type): Add optional account-service-type extensions (needed for dhcpcd). Signed-off-by: Sören Tempel --- gnu/services/networking.scm | 84 ++++++++++++++++++++++++++----------- 1 file changed, 60 insertions(+), 24 deletions(-) diff --git a/gnu/services/networking.scm b/gnu/services/networking.scm index 495d049728..3621e2bda2 100644 --- a/gnu/services/networking.scm +++ b/gnu/services/networking.scm @@ -316,25 +316,21 @@ (define-record-type* (define dhcp-client-shepherd-service (match-lambda ((? dhcp-client-configuration? config) - (let ((package (dhcp-client-configuration-package config)) - (requirement (dhcp-client-configuration-shepherd-requirement config)) - (provision (dhcp-client-configuration-shepherd-provision config)) - (interfaces (dhcp-client-configuration-interfaces config)) - (pid-file "/var/run/dhclient.pid")) + (let* ((package (dhcp-client-configuration-package config)) + (client-name (package-name package)) + (requirement (dhcp-client-configuration-shepherd-requirement config)) + (provision (dhcp-client-configuration-shepherd-provision config)) + (interfaces (dhcp-client-configuration-interfaces config))) (list (shepherd-service (documentation "Set up networking via DHCP.") (requirement `(user-processes udev ,@requirement)) (provision provision) - ;; XXX: Running with '-nw' ("no wait") avoids blocking for a minute when - ;; networking is unavailable, but also means that the interface is not up - ;; yet when 'start' completes. To wait for the interface to be ready, one - ;; should instead monitor udev events. (start #~(lambda _ - (define dhclient - (string-append #$package "/sbin/dhclient")) + (use-modules (ice-9 popen) + (ice-9 rdelim)) - ;; When invoked without any arguments, 'dhclient' discovers all + ;; When invoked without any arguments, the client discovers all ;; non-loopback interfaces *that are up*. However, the relevant ;; interfaces are typically down at this point. Thus we perform ;; our own interface discovery here. @@ -355,17 +351,40 @@ (define dhcp-client-shepherd-service (_ #~'#$interfaces)))) - (false-if-exception (delete-file #$pid-file)) - (let ((pid (fork+exec-command - ;; By default dhclient uses a - ;; pre-standardization implementation of - ;; DDNS, which is incompatable with - ;; non-ISC DHCP servers; thus, pass '-I'. - ;; . - (cons* dhclient "-nw" "-I" - "-pf" #$pid-file ifaces)))) - (and (zero? (cdr (waitpid pid))) - (read-pid-file #$pid-file))))) + ;; Returns the execution configuration for the DHCP client + ;; selected by the package field of dhcp-client-configuration. + ;; The configuration is a pair of pidfile and execution command + ;; where the latter is a list. + (define exec-config + (case (string->symbol #$client-name) + ((isc-dhcp) + (let ((pid-file "/var/run/dhclient.pid")) + (cons + (cons* (string-append #$package "/sbin/dhclient") + "-nw" "-I" "-pf" pid-file ifaces) + pid-file))) + ((dhcpcd) + ;; For dhcpcd, the utilized pid-file depends on the + ;; command-line arguments. If multiple interfaces are + ;; given, a different pid-file is returned. Hence, we + ;; consult dhcpcd itself to determine the pid-file. + (let* ((cmd (string-append #$package "/sbin/dhcpcd")) + (arg (cons* cmd "-b" ifaces))) + (cons arg + (let* ((pipe (string-join (append arg '("-P")) " ")) + (port (open-input-pipe pipe)) + (path (read-line port))) + (close-pipe port) + path)))) + (else + (error (G_ "unknown 'package' value in dhcp-client-configuration"))))) + + (let ((pid-file (cdr exec-config)) + (exec-cmd (car exec-config))) + (false-if-exception (delete-file pid-file)) + (let ((pid (fork+exec-command exec-cmd))) + (and (zero? (cdr (waitpid pid))) + (read-pid-file pid-file)))))) (stop #~(make-kill-destructor)))))) (package (warning (G_ "'dhcp-client' service now expects a \ @@ -377,10 +396,27 @@ (define dhcp-client-shepherd-service (dhcp-client-configuration (package package)))))) +(define (dhcp-client-account-service config) + (let ((package (dhcp-client-configuration-package config))) + ;; Contrary to other DHCP clients (e.g. dhclient), dhcpcd supports + ;; privilege separation. Hence, we need to create an account here. + (if (string=? "dhcpcd" (package-name package)) + (list (user-group (name "dhcpcd") (system? #t)) + (user-account + (name "dhcpcd") + (group "dhcpcd") + (system? #t) + (comment "dhcpcd daemon user") + (home-directory "/var/empty") + (shell "/run/current-system/profile/sbin/nologin"))) + '()))) + (define dhcp-client-service-type (service-type (name 'dhcp-client) (extensions - (list (service-extension shepherd-root-service-type + (list (service-extension account-service-type + dhcp-client-account-service) + (service-extension shepherd-root-service-type dhcp-client-shepherd-service))) (default-value (dhcp-client-configuration)) (description "Run @command{dhcp}, a Dynamic Host Configuration