]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/libsystemd-network/dhcp-network.c
dhcp: rebreak function arguments
[thirdparty/systemd.git] / src / libsystemd-network / dhcp-network.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
8b4a9693 2/***
810adae9 3 Copyright © 2013 Intel Corporation. All rights reserved.
8b4a9693
PF
4***/
5
6#include <errno.h>
8b4a9693 7#include <net/ethernet.h>
3e7b9f76 8#include <net/if.h>
7429b07f 9#include <net/if_arp.h>
8b4a9693 10#include <stdio.h>
3ffd4af2 11#include <string.h>
bc29e507 12#include <linux/filter.h>
3ffd4af2
LP
13#include <linux/if_infiniband.h>
14#include <linux/if_packet.h>
8b4a9693
PF
15
16#include "dhcp-internal.h"
3ffd4af2
LP
17#include "fd-util.h"
18#include "socket-util.h"
f11cba74 19#include "unaligned.h"
8b4a9693 20
76253e73 21static int _bind_raw_socket(int ifindex, union sockaddr_union *link,
14b66dbc 22 uint32_t xid,
76253e73 23 const uint8_t *bcast_addr,
14b66dbc 24 size_t bcast_addr_len,
76253e73 25 const struct ether_addr *eth_mac,
9faed222
SS
26 uint16_t arp_type, uint8_t dhcp_hlen,
27 uint16_t port) {
bc29e507 28 struct sock_filter filter[] = {
088b6ba2
LP
29 BPF_STMT(BPF_LD + BPF_W + BPF_LEN, 0), /* A <- packet length */
30 BPF_JUMP(BPF_JMP + BPF_JGE + BPF_K, sizeof(DHCPPacket), 1, 0), /* packet >= DHCPPacket ? */
31 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
32 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.protocol)), /* A <- IP protocol */
33 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 1, 0), /* IP protocol == UDP ? */
34 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
35 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags */
36 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x20), /* A <- A & 0x20 (More Fragments bit) */
37 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
38 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
39 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags + Fragment offset */
40 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x1fff), /* A <- A & 0x1fff (Fragment offset) */
41 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
42 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
43 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, udp.dest)), /* A <- UDP destination port */
9faed222 44 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, port, 1, 0), /* UDP destination port == DHCP client port ? */
088b6ba2
LP
45 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
46 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.op)), /* A <- DHCP op */
47 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, BOOTREPLY, 1, 0), /* op == BOOTREPLY ? */
48 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
49 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.htype)), /* A <- DHCP header type */
76253e73 50 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, arp_type, 1, 0), /* header type == arp_type ? */
088b6ba2 51 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
088b6ba2
LP
52 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.xid)), /* A <- client identifier */
53 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, xid, 1, 0), /* client identifier == xid ? */
54 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
13f1fd03
TH
55 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.hlen)), /* A <- MAC address length */
56 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, dhcp_hlen, 1, 0), /* address length == dhcp_hlen ? */
57 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
58
59 /* We only support MAC address length to be either 0 or 6 (ETH_ALEN). Optionally
60 * compare chaddr for ETH_ALEN bytes. */
61 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETH_ALEN, 0, 12), /* A (the MAC address length) == ETH_ALEN ? */
f11cba74 62 BPF_STMT(BPF_LD + BPF_IMM, unaligned_read_be32(&eth_mac->ether_addr_octet[0])), /* A <- 4 bytes of client's MAC */
088b6ba2
LP
63 BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */
64 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr)), /* A <- 4 bytes of MAC from dhcp.chaddr */
65 BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */
66 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
67 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
f11cba74 68 BPF_STMT(BPF_LD + BPF_IMM, unaligned_read_be16(&eth_mac->ether_addr_octet[4])), /* A <- remainder of client's MAC */
088b6ba2
LP
69 BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */
70 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr) + 4), /* A <- remainder of MAC from dhcp.chaddr */
71 BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */
72 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
73 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
13f1fd03 74
088b6ba2
LP
75 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.magic)), /* A <- DHCP magic cookie */
76 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, DHCP_MAGIC_COOKIE, 1, 0), /* cookie == DHCP magic cookie ? */
77 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
78 BPF_STMT(BPF_RET + BPF_K, 65535), /* return all */
bc29e507
TG
79 };
80 struct sock_fprog fprog = {
088b6ba2
LP
81 .len = ELEMENTSOF(filter),
82 .filter = filter
bc29e507 83 };
c3d2994b 84 _cleanup_close_ int s = -1;
6d5e65f6 85 int r;
8b4a9693 86
088b6ba2 87 assert(ifindex > 0);
23f30ed3
TG
88 assert(link);
89
66a67eff 90 s = socket(AF_PACKET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
8b4a9693
PF
91 if (s < 0)
92 return -errno;
93
2ff48e98 94 r = setsockopt_int(s, SOL_PACKET, PACKET_AUXDATA, true);
c3d2994b 95 if (r < 0)
2ff48e98 96 return r;
c3d2994b
TG
97
98 r = setsockopt(s, SOL_SOCKET, SO_ATTACH_FILTER, &fprog, sizeof(fprog));
99 if (r < 0)
100 return -errno;
101
b1f24b75
BG
102 link->ll = (struct sockaddr_ll) {
103 .sll_family = AF_PACKET,
104 .sll_protocol = htobe16(ETH_P_IP),
105 .sll_ifindex = ifindex,
106 .sll_hatype = htobe16(arp_type),
14b66dbc 107 .sll_halen = bcast_addr_len,
b1f24b75 108 };
b5c474f6 109 memcpy(link->ll.sll_addr, bcast_addr, bcast_addr_len); /* We may overflow link->ll. link->ll_buffer ensures we have enough space. */
8b4a9693 110
b1f24b75 111 r = bind(s, &link->sa, SOCKADDR_LL_LEN(link->ll));
c3d2994b 112 if (r < 0)
bc29e507 113 return -errno;
bc29e507 114
c10d6bdb 115 return TAKE_FD(s);
8c00042c
PF
116}
117
155943b2
YW
118int dhcp_network_bind_raw_socket(
119 int ifindex,
120 union sockaddr_union *link,
121 uint32_t xid,
122 const uint8_t *mac_addr,
123 size_t mac_addr_len,
124 const uint8_t *bcast_addr,
125 size_t bcast_addr_len,
126 uint16_t arp_type,
127 uint16_t port) {
128
76253e73
DW
129 static const uint8_t eth_bcast[] = { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF };
130 /* Default broadcast address for IPoIB */
131 static const uint8_t ib_bcast[] = {
132 0x00, 0xff, 0xff, 0xff, 0xff, 0x12, 0x40, 0x1b,
133 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
134 0xff, 0xff, 0xff, 0xff
14b66dbc 135 };
76253e73 136 struct ether_addr eth_mac = { { 0, 0, 0, 0, 0, 0 } };
14b66dbc
TR
137 const uint8_t *default_bcast_addr;
138 size_t expected_bcast_addr_len;
76253e73
DW
139 uint8_t dhcp_hlen = 0;
140
76253e73
DW
141 if (arp_type == ARPHRD_ETHER) {
142 assert_return(mac_addr_len == ETH_ALEN, -EINVAL);
143 memcpy(&eth_mac, mac_addr, ETH_ALEN);
76253e73 144 dhcp_hlen = ETH_ALEN;
14b66dbc
TR
145
146 default_bcast_addr = eth_bcast;
147 expected_bcast_addr_len = ETH_ALEN;
76253e73 148 } else if (arp_type == ARPHRD_INFINIBAND) {
14b66dbc
TR
149 default_bcast_addr = ib_bcast;
150 expected_bcast_addr_len = INFINIBAND_ALEN;
76253e73
DW
151 } else
152 return -EINVAL;
153
14b66dbc
TR
154 if (bcast_addr && bcast_addr_len > 0)
155 assert_return(bcast_addr_len == expected_bcast_addr_len, -EINVAL);
156 else {
157 bcast_addr = default_bcast_addr;
158 bcast_addr_len = expected_bcast_addr_len;
159 }
160
161 return _bind_raw_socket(ifindex, link, xid, bcast_addr, bcast_addr_len,
162 &eth_mac, arp_type, dhcp_hlen, port);
76253e73
DW
163}
164
afe42aef 165int dhcp_network_bind_udp_socket(int ifindex, be32_t address, uint16_t port, int ip_service_type) {
234fc2df
PF
166 union sockaddr_union src = {
167 .in.sin_family = AF_INET,
080ab276
TG
168 .in.sin_port = htobe16(port),
169 .in.sin_addr.s_addr = address,
234fc2df 170 };
c3d2994b 171 _cleanup_close_ int s = -1;
9e5b6496 172 int r;
234fc2df
PF
173
174 s = socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
175 if (s < 0)
176 return -errno;
177
afe42aef
SC
178 if (ip_service_type >= 0)
179 r = setsockopt_int(s, IPPROTO_IP, IP_TOS, ip_service_type);
180 else
181 r = setsockopt_int(s, IPPROTO_IP, IP_TOS, IPTOS_CLASS_CS6);
c3d2994b 182 if (r < 0)
9e5b6496 183 return r;
b44cd882 184
2ff48e98 185 r = setsockopt_int(s, SOL_SOCKET, SO_REUSEADDR, true);
076adf01 186 if (r < 0)
2ff48e98 187 return r;
fef0e0f3 188
3e7b9f76 189 if (ifindex > 0) {
953a02d1 190 r = socket_bind_to_ifindex(s, ifindex);
3e7b9f76 191 if (r < 0)
953a02d1 192 return r;
3e7b9f76
MK
193 }
194
21b6b87e 195 if (port == DHCP_PORT_SERVER) {
2ff48e98 196 r = setsockopt_int(s, SOL_SOCKET, SO_BROADCAST, true);
d6bd972d 197 if (r < 0)
2ff48e98 198 return r;
21b6b87e
YA
199 if (address == INADDR_ANY) {
200 /* IP_PKTINFO filter should not be applied when packets are
201 allowed to enter/leave through the interface other than
202 DHCP server sits on(BindToInterface option). */
203 r = setsockopt_int(s, IPPROTO_IP, IP_PKTINFO, true);
204 if (r < 0)
205 return r;
206 }
076adf01 207 } else {
2ff48e98 208 r = setsockopt_int(s, IPPROTO_IP, IP_FREEBIND, true);
076adf01 209 if (r < 0)
2ff48e98 210 return r;
fef0e0f3 211 }
85923f79 212
d70c7813 213 if (bind(s, &src.sa, sizeof(src.in)) < 0)
234fc2df 214 return -errno;
234fc2df 215
c10d6bdb 216 return TAKE_FD(s);
234fc2df
PF
217}
218
155943b2
YW
219int dhcp_network_send_raw_socket(
220 int s,
221 const union sockaddr_union *link,
222 const void *packet,
223 size_t len) {
c3d2994b 224
b8319d74
YW
225 /* Do not add assert(s >= 0) here, as this is called in fuzz-dhcp-server, and in that case this
226 * function should fail with negative errno. */
227
23f30ed3
TG
228 assert(link);
229 assert(packet);
b8319d74 230 assert(len > 0);
23f30ed3 231
d70c7813 232 if (sendto(s, packet, len, 0, &link->sa, SOCKADDR_LL_LEN(link->ll)) < 0)
1c8035a8 233 return -errno;
8b4a9693 234
1c8035a8 235 return 0;
8b4a9693 236}
234fc2df 237
155943b2
YW
238int dhcp_network_send_udp_socket(
239 int s,
240 be32_t address,
241 uint16_t port,
242 const void *packet,
243 size_t len) {
244
234fc2df
PF
245 union sockaddr_union dest = {
246 .in.sin_family = AF_INET,
080ab276
TG
247 .in.sin_port = htobe16(port),
248 .in.sin_addr.s_addr = address,
234fc2df 249 };
c3d2994b
TG
250
251 assert(s >= 0);
252 assert(packet);
b8319d74 253 assert(len > 0);
234fc2df 254
d70c7813 255 if (sendto(s, packet, len, 0, &dest.sa, sizeof(dest.in)) < 0)
234fc2df
PF
256 return -errno;
257
258 return 0;
259}