]>
Commit | Line | Data |
---|---|---|
53e1b683 | 1 | /* SPDX-License-Identifier: LGPL-2.1+ */ |
8b4a9693 | 2 | /*** |
810adae9 | 3 | Copyright © 2013 Intel Corporation. All rights reserved. |
8b4a9693 PF |
4 | ***/ |
5 | ||
6 | #include <errno.h> | |
8b4a9693 | 7 | #include <net/ethernet.h> |
3e7b9f76 | 8 | #include <net/if.h> |
7429b07f | 9 | #include <net/if_arp.h> |
8b4a9693 | 10 | #include <stdio.h> |
3ffd4af2 | 11 | #include <string.h> |
bc29e507 | 12 | #include <linux/filter.h> |
3ffd4af2 LP |
13 | #include <linux/if_infiniband.h> |
14 | #include <linux/if_packet.h> | |
8b4a9693 PF |
15 | |
16 | #include "dhcp-internal.h" | |
3ffd4af2 LP |
17 | #include "fd-util.h" |
18 | #include "socket-util.h" | |
f11cba74 | 19 | #include "unaligned.h" |
8b4a9693 | 20 | |
76253e73 | 21 | static int _bind_raw_socket(int ifindex, union sockaddr_union *link, |
14b66dbc | 22 | uint32_t xid, |
76253e73 | 23 | const uint8_t *bcast_addr, |
14b66dbc | 24 | size_t bcast_addr_len, |
76253e73 | 25 | const struct ether_addr *eth_mac, |
9faed222 SS |
26 | uint16_t arp_type, uint8_t dhcp_hlen, |
27 | uint16_t port) { | |
bc29e507 | 28 | struct sock_filter filter[] = { |
088b6ba2 LP |
29 | BPF_STMT(BPF_LD + BPF_W + BPF_LEN, 0), /* A <- packet length */ |
30 | BPF_JUMP(BPF_JMP + BPF_JGE + BPF_K, sizeof(DHCPPacket), 1, 0), /* packet >= DHCPPacket ? */ | |
31 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
32 | BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.protocol)), /* A <- IP protocol */ | |
33 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 1, 0), /* IP protocol == UDP ? */ | |
34 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
35 | BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags */ | |
36 | BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x20), /* A <- A & 0x20 (More Fragments bit) */ | |
37 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */ | |
38 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
39 | BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags + Fragment offset */ | |
40 | BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x1fff), /* A <- A & 0x1fff (Fragment offset) */ | |
41 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */ | |
42 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
43 | BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, udp.dest)), /* A <- UDP destination port */ | |
9faed222 | 44 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, port, 1, 0), /* UDP destination port == DHCP client port ? */ |
088b6ba2 LP |
45 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ |
46 | BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.op)), /* A <- DHCP op */ | |
47 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, BOOTREPLY, 1, 0), /* op == BOOTREPLY ? */ | |
48 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
49 | BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.htype)), /* A <- DHCP header type */ | |
76253e73 | 50 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, arp_type, 1, 0), /* header type == arp_type ? */ |
088b6ba2 | 51 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ |
088b6ba2 LP |
52 | BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.xid)), /* A <- client identifier */ |
53 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, xid, 1, 0), /* client identifier == xid ? */ | |
54 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
13f1fd03 TH |
55 | BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.hlen)), /* A <- MAC address length */ |
56 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, dhcp_hlen, 1, 0), /* address length == dhcp_hlen ? */ | |
57 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
58 | ||
59 | /* We only support MAC address length to be either 0 or 6 (ETH_ALEN). Optionally | |
60 | * compare chaddr for ETH_ALEN bytes. */ | |
61 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETH_ALEN, 0, 12), /* A (the MAC address length) == ETH_ALEN ? */ | |
f11cba74 | 62 | BPF_STMT(BPF_LD + BPF_IMM, unaligned_read_be32(ð_mac->ether_addr_octet[0])), /* A <- 4 bytes of client's MAC */ |
088b6ba2 LP |
63 | BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */ |
64 | BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr)), /* A <- 4 bytes of MAC from dhcp.chaddr */ | |
65 | BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */ | |
66 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */ | |
67 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
f11cba74 | 68 | BPF_STMT(BPF_LD + BPF_IMM, unaligned_read_be16(ð_mac->ether_addr_octet[4])), /* A <- remainder of client's MAC */ |
088b6ba2 LP |
69 | BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */ |
70 | BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr) + 4), /* A <- remainder of MAC from dhcp.chaddr */ | |
71 | BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */ | |
72 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */ | |
73 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
13f1fd03 | 74 | |
088b6ba2 LP |
75 | BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.magic)), /* A <- DHCP magic cookie */ |
76 | BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, DHCP_MAGIC_COOKIE, 1, 0), /* cookie == DHCP magic cookie ? */ | |
77 | BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */ | |
78 | BPF_STMT(BPF_RET + BPF_K, 65535), /* return all */ | |
bc29e507 TG |
79 | }; |
80 | struct sock_fprog fprog = { | |
088b6ba2 LP |
81 | .len = ELEMENTSOF(filter), |
82 | .filter = filter | |
bc29e507 | 83 | }; |
c3d2994b | 84 | _cleanup_close_ int s = -1; |
6d5e65f6 | 85 | int r; |
8b4a9693 | 86 | |
088b6ba2 | 87 | assert(ifindex > 0); |
23f30ed3 TG |
88 | assert(link); |
89 | ||
66a67eff | 90 | s = socket(AF_PACKET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0); |
8b4a9693 PF |
91 | if (s < 0) |
92 | return -errno; | |
93 | ||
2ff48e98 | 94 | r = setsockopt_int(s, SOL_PACKET, PACKET_AUXDATA, true); |
c3d2994b | 95 | if (r < 0) |
2ff48e98 | 96 | return r; |
c3d2994b TG |
97 | |
98 | r = setsockopt(s, SOL_SOCKET, SO_ATTACH_FILTER, &fprog, sizeof(fprog)); | |
99 | if (r < 0) | |
100 | return -errno; | |
101 | ||
b1f24b75 BG |
102 | link->ll = (struct sockaddr_ll) { |
103 | .sll_family = AF_PACKET, | |
104 | .sll_protocol = htobe16(ETH_P_IP), | |
105 | .sll_ifindex = ifindex, | |
106 | .sll_hatype = htobe16(arp_type), | |
14b66dbc | 107 | .sll_halen = bcast_addr_len, |
b1f24b75 | 108 | }; |
14b66dbc | 109 | memcpy(link->ll.sll_addr, bcast_addr, bcast_addr_len); |
8b4a9693 | 110 | |
b1f24b75 | 111 | r = bind(s, &link->sa, SOCKADDR_LL_LEN(link->ll)); |
c3d2994b | 112 | if (r < 0) |
bc29e507 | 113 | return -errno; |
bc29e507 | 114 | |
c10d6bdb | 115 | return TAKE_FD(s); |
8c00042c PF |
116 | } |
117 | ||
14b66dbc TR |
118 | int dhcp_network_bind_raw_socket(int ifindex, union sockaddr_union *link, uint32_t xid, |
119 | const uint8_t *mac_addr, size_t mac_addr_len, | |
120 | const uint8_t *bcast_addr, size_t bcast_addr_len, | |
121 | uint16_t arp_type, uint16_t port) { | |
76253e73 DW |
122 | static const uint8_t eth_bcast[] = { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }; |
123 | /* Default broadcast address for IPoIB */ | |
124 | static const uint8_t ib_bcast[] = { | |
125 | 0x00, 0xff, 0xff, 0xff, 0xff, 0x12, 0x40, 0x1b, | |
126 | 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, | |
127 | 0xff, 0xff, 0xff, 0xff | |
14b66dbc | 128 | }; |
76253e73 | 129 | struct ether_addr eth_mac = { { 0, 0, 0, 0, 0, 0 } }; |
14b66dbc TR |
130 | const uint8_t *default_bcast_addr; |
131 | size_t expected_bcast_addr_len; | |
76253e73 DW |
132 | uint8_t dhcp_hlen = 0; |
133 | ||
76253e73 DW |
134 | if (arp_type == ARPHRD_ETHER) { |
135 | assert_return(mac_addr_len == ETH_ALEN, -EINVAL); | |
136 | memcpy(ð_mac, mac_addr, ETH_ALEN); | |
76253e73 | 137 | dhcp_hlen = ETH_ALEN; |
14b66dbc TR |
138 | |
139 | default_bcast_addr = eth_bcast; | |
140 | expected_bcast_addr_len = ETH_ALEN; | |
76253e73 | 141 | } else if (arp_type == ARPHRD_INFINIBAND) { |
14b66dbc TR |
142 | default_bcast_addr = ib_bcast; |
143 | expected_bcast_addr_len = INFINIBAND_ALEN; | |
76253e73 DW |
144 | } else |
145 | return -EINVAL; | |
146 | ||
14b66dbc TR |
147 | if (bcast_addr && bcast_addr_len > 0) |
148 | assert_return(bcast_addr_len == expected_bcast_addr_len, -EINVAL); | |
149 | else { | |
150 | bcast_addr = default_bcast_addr; | |
151 | bcast_addr_len = expected_bcast_addr_len; | |
152 | } | |
153 | ||
154 | return _bind_raw_socket(ifindex, link, xid, bcast_addr, bcast_addr_len, | |
155 | ð_mac, arp_type, dhcp_hlen, port); | |
76253e73 DW |
156 | } |
157 | ||
afe42aef | 158 | int dhcp_network_bind_udp_socket(int ifindex, be32_t address, uint16_t port, int ip_service_type) { |
234fc2df PF |
159 | union sockaddr_union src = { |
160 | .in.sin_family = AF_INET, | |
080ab276 TG |
161 | .in.sin_port = htobe16(port), |
162 | .in.sin_addr.s_addr = address, | |
234fc2df | 163 | }; |
c3d2994b | 164 | _cleanup_close_ int s = -1; |
9e5b6496 | 165 | int r; |
234fc2df PF |
166 | |
167 | s = socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0); | |
168 | if (s < 0) | |
169 | return -errno; | |
170 | ||
afe42aef SC |
171 | if (ip_service_type >= 0) |
172 | r = setsockopt_int(s, IPPROTO_IP, IP_TOS, ip_service_type); | |
173 | else | |
174 | r = setsockopt_int(s, IPPROTO_IP, IP_TOS, IPTOS_CLASS_CS6); | |
175 | ||
c3d2994b | 176 | if (r < 0) |
9e5b6496 | 177 | return r; |
b44cd882 | 178 | |
2ff48e98 | 179 | r = setsockopt_int(s, SOL_SOCKET, SO_REUSEADDR, true); |
076adf01 | 180 | if (r < 0) |
2ff48e98 | 181 | return r; |
fef0e0f3 | 182 | |
3e7b9f76 | 183 | if (ifindex > 0) { |
953a02d1 | 184 | r = socket_bind_to_ifindex(s, ifindex); |
3e7b9f76 | 185 | if (r < 0) |
953a02d1 | 186 | return r; |
3e7b9f76 MK |
187 | } |
188 | ||
076adf01 | 189 | if (address == INADDR_ANY) { |
2ff48e98 | 190 | r = setsockopt_int(s, IPPROTO_IP, IP_PKTINFO, true); |
fef0e0f3 | 191 | if (r < 0) |
2ff48e98 | 192 | return r; |
d6bd972d | 193 | |
2ff48e98 | 194 | r = setsockopt_int(s, SOL_SOCKET, SO_BROADCAST, true); |
d6bd972d | 195 | if (r < 0) |
2ff48e98 | 196 | return r; |
3e7b9f76 | 197 | |
076adf01 | 198 | } else { |
2ff48e98 | 199 | r = setsockopt_int(s, IPPROTO_IP, IP_FREEBIND, true); |
076adf01 | 200 | if (r < 0) |
2ff48e98 | 201 | return r; |
fef0e0f3 | 202 | } |
85923f79 | 203 | |
c3d2994b TG |
204 | r = bind(s, &src.sa, sizeof(src.in)); |
205 | if (r < 0) | |
234fc2df | 206 | return -errno; |
234fc2df | 207 | |
c10d6bdb | 208 | return TAKE_FD(s); |
234fc2df PF |
209 | } |
210 | ||
8c00042c | 211 | int dhcp_network_send_raw_socket(int s, const union sockaddr_union *link, |
c3d2994b TG |
212 | const void *packet, size_t len) { |
213 | int r; | |
214 | ||
23f30ed3 TG |
215 | assert(link); |
216 | assert(packet); | |
217 | assert(len); | |
218 | ||
b1f24b75 | 219 | r = sendto(s, packet, len, 0, &link->sa, SOCKADDR_LL_LEN(link->ll)); |
c3d2994b | 220 | if (r < 0) |
1c8035a8 | 221 | return -errno; |
8b4a9693 | 222 | |
1c8035a8 | 223 | return 0; |
8b4a9693 | 224 | } |
234fc2df | 225 | |
080ab276 | 226 | int dhcp_network_send_udp_socket(int s, be32_t address, uint16_t port, |
c3d2994b | 227 | const void *packet, size_t len) { |
234fc2df PF |
228 | union sockaddr_union dest = { |
229 | .in.sin_family = AF_INET, | |
080ab276 TG |
230 | .in.sin_port = htobe16(port), |
231 | .in.sin_addr.s_addr = address, | |
234fc2df | 232 | }; |
c3d2994b TG |
233 | int r; |
234 | ||
235 | assert(s >= 0); | |
236 | assert(packet); | |
237 | assert(len); | |
234fc2df | 238 | |
c3d2994b TG |
239 | r = sendto(s, packet, len, 0, &dest.sa, sizeof(dest.in)); |
240 | if (r < 0) | |
234fc2df PF |
241 | return -errno; |
242 | ||
243 | return 0; | |
244 | } |