mirror of
https://github.com/vdsm/virtual-dsm.git
synced 2025-02-24 13:30:02 +08:00
Check NET_ADMIN flag
This commit is contained in:
parent
a6e53bae4b
commit
a2f33378cd
@ -25,7 +25,7 @@ configureDHCP() {
|
|||||||
NETWORK=$(ip -o route | grep "${VM_NET_DEV}" | grep -v default | awk '{print $1}')
|
NETWORK=$(ip -o route | grep "${VM_NET_DEV}" | grep -v default | awk '{print $1}')
|
||||||
IP=$(ip address show dev "${VM_NET_DEV}" | grep inet | awk '/inet / { print $2 }' | cut -f1 -d/)
|
IP=$(ip address show dev "${VM_NET_DEV}" | grep inet | awk '/inet / { print $2 }' | cut -f1 -d/)
|
||||||
|
|
||||||
ip l add link "${VM_NET_DEV}" "${VM_NET_VLAN}" type macvlan mode bridge
|
ip link add link "${VM_NET_DEV}" "${VM_NET_VLAN}" type macvlan mode bridge
|
||||||
ip address add "${IP}" dev "${VM_NET_VLAN}"
|
ip address add "${IP}" dev "${VM_NET_VLAN}"
|
||||||
ip link set dev "${VM_NET_VLAN}" up
|
ip link set dev "${VM_NET_VLAN}" up
|
||||||
|
|
||||||
@ -37,8 +37,8 @@ configureDHCP() {
|
|||||||
|
|
||||||
echo "INFO: Acquiring an IP address via DHCP using MAC address ${VM_NET_MAC}..."
|
echo "INFO: Acquiring an IP address via DHCP using MAC address ${VM_NET_MAC}..."
|
||||||
|
|
||||||
ip l add link "${VM_NET_DEV}" name "${VM_NET_TAP}" address "${VM_NET_MAC}" type macvtap mode bridge || true
|
ip link add link "${VM_NET_DEV}" name "${VM_NET_TAP}" address "${VM_NET_MAC}" type macvtap mode bridge || true
|
||||||
ip l set "${VM_NET_TAP}" up
|
ip link set "${VM_NET_TAP}" up
|
||||||
|
|
||||||
ip a flush "${VM_NET_DEV}"
|
ip a flush "${VM_NET_DEV}"
|
||||||
ip a flush "${VM_NET_TAP}"
|
ip a flush "${VM_NET_TAP}"
|
||||||
@ -51,7 +51,7 @@ configureDHCP() {
|
|||||||
echo "ERROR: Cannot acquire an IP address from the DHCP server" && exit 16
|
echo "ERROR: Cannot acquire an IP address from the DHCP server" && exit 16
|
||||||
fi
|
fi
|
||||||
|
|
||||||
ip a flush "${VM_NET_TAP}"
|
ip address flush "${VM_NET_TAP}"
|
||||||
|
|
||||||
TAP_NR=$(</sys/class/net/"${VM_NET_TAP}"/ifindex)
|
TAP_NR=$(</sys/class/net/"${VM_NET_TAP}"/ifindex)
|
||||||
TAP_PATH="/dev/tap${TAP_NR}"
|
TAP_PATH="/dev/tap${TAP_NR}"
|
||||||
@ -72,7 +72,7 @@ configureDHCP() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
if ! exec 30>>"$TAP_PATH"; then
|
if ! exec 30>>"$TAP_PATH"; then
|
||||||
echo -n "ERROR: Please add the following docker variables to your container: "
|
echo -n "ERROR: Please add the following docker settings to your container: "
|
||||||
echo "--device=/dev/vhost-net --device-cgroup-rule='c ${MAJOR}:* rwm'" && exit 21
|
echo "--device=/dev/vhost-net --device-cgroup-rule='c ${MAJOR}:* rwm'" && exit 21
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@ -83,8 +83,8 @@ configureDHCP() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
if ! exec 40>>/dev/vhost-net; then
|
if ! exec 40>>/dev/vhost-net; then
|
||||||
echo -n "ERROR: VHOST can not be found. Please add the following docker "
|
echo -n "ERROR: VHOST can not be found. Please add the following "
|
||||||
echo "variable to your container: --device=/dev/vhost-net" && exit 22
|
echo "docker setting to your container: --device=/dev/vhost-net" && exit 22
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Store IP for Docker healthcheck
|
# Store IP for Docker healthcheck
|
||||||
@ -98,7 +98,12 @@ configureNAT () {
|
|||||||
VM_NET_IP='20.20.20.21'
|
VM_NET_IP='20.20.20.21'
|
||||||
|
|
||||||
#Create bridge with static IP for the VM guest
|
#Create bridge with static IP for the VM guest
|
||||||
ip link add dev dockerbridge type bridge
|
|
||||||
|
if ! ip link add dev dockerbridge type bridge > /dev/null 2>&1 ; then
|
||||||
|
echo -n "ERROR: Capability NET_ADMIN has not been set. Please add the "
|
||||||
|
echo "following docker setting to your container: --cap-add NET_ADMIN" && exit 23
|
||||||
|
fi
|
||||||
|
|
||||||
ip addr add ${VM_NET_IP%.*}.1/24 broadcast ${VM_NET_IP%.*}.255 dev dockerbridge
|
ip addr add ${VM_NET_IP%.*}.1/24 broadcast ${VM_NET_IP%.*}.255 dev dockerbridge
|
||||||
ip link set dockerbridge up
|
ip link set dockerbridge up
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user