]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/libsystemd-network/dhcp-network.c
socket-util: tighten socket_address_verify() checks a bit
[thirdparty/systemd.git] / src / libsystemd-network / dhcp-network.c
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
8b4a9693 2/***
810adae9 3 Copyright © 2013 Intel Corporation. All rights reserved.
8b4a9693
PF
4***/
5
6#include <errno.h>
8b4a9693 7#include <net/ethernet.h>
3e7b9f76 8#include <net/if.h>
7429b07f 9#include <net/if_arp.h>
8b4a9693 10#include <stdio.h>
3ffd4af2
LP
11#include <string.h>
12#include <sys/socket.h>
bc29e507 13#include <linux/filter.h>
3ffd4af2
LP
14#include <linux/if_infiniband.h>
15#include <linux/if_packet.h>
8b4a9693
PF
16
17#include "dhcp-internal.h"
3ffd4af2
LP
18#include "fd-util.h"
19#include "socket-util.h"
f11cba74 20#include "unaligned.h"
8b4a9693 21
76253e73
DW
22static int _bind_raw_socket(int ifindex, union sockaddr_union *link,
23 uint32_t xid, const uint8_t *mac_addr,
24 size_t mac_addr_len,
25 const uint8_t *bcast_addr,
26 const struct ether_addr *eth_mac,
9faed222
SS
27 uint16_t arp_type, uint8_t dhcp_hlen,
28 uint16_t port) {
bc29e507 29 struct sock_filter filter[] = {
088b6ba2
LP
30 BPF_STMT(BPF_LD + BPF_W + BPF_LEN, 0), /* A <- packet length */
31 BPF_JUMP(BPF_JMP + BPF_JGE + BPF_K, sizeof(DHCPPacket), 1, 0), /* packet >= DHCPPacket ? */
32 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
33 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.protocol)), /* A <- IP protocol */
34 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 1, 0), /* IP protocol == UDP ? */
35 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
36 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags */
37 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x20), /* A <- A & 0x20 (More Fragments bit) */
38 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
39 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
40 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags + Fragment offset */
41 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x1fff), /* A <- A & 0x1fff (Fragment offset) */
42 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
43 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
44 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, udp.dest)), /* A <- UDP destination port */
9faed222 45 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, port, 1, 0), /* UDP destination port == DHCP client port ? */
088b6ba2
LP
46 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
47 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.op)), /* A <- DHCP op */
48 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, BOOTREPLY, 1, 0), /* op == BOOTREPLY ? */
49 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
50 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.htype)), /* A <- DHCP header type */
76253e73 51 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, arp_type, 1, 0), /* header type == arp_type ? */
088b6ba2 52 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
e2acdb6b 53 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.hlen)), /* A <- MAC address length */
76253e73 54 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, dhcp_hlen, 1, 0), /* address length == dhcp_hlen ? */
088b6ba2
LP
55 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
56 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.xid)), /* A <- client identifier */
57 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, xid, 1, 0), /* client identifier == xid ? */
58 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
f11cba74 59 BPF_STMT(BPF_LD + BPF_IMM, unaligned_read_be32(&eth_mac->ether_addr_octet[0])), /* A <- 4 bytes of client's MAC */
088b6ba2
LP
60 BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */
61 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr)), /* A <- 4 bytes of MAC from dhcp.chaddr */
62 BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */
63 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
64 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
f11cba74 65 BPF_STMT(BPF_LD + BPF_IMM, unaligned_read_be16(&eth_mac->ether_addr_octet[4])), /* A <- remainder of client's MAC */
088b6ba2
LP
66 BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */
67 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr) + 4), /* A <- remainder of MAC from dhcp.chaddr */
68 BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */
69 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
70 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
71 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.magic)), /* A <- DHCP magic cookie */
72 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, DHCP_MAGIC_COOKIE, 1, 0), /* cookie == DHCP magic cookie ? */
73 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
74 BPF_STMT(BPF_RET + BPF_K, 65535), /* return all */
bc29e507
TG
75 };
76 struct sock_fprog fprog = {
088b6ba2
LP
77 .len = ELEMENTSOF(filter),
78 .filter = filter
bc29e507 79 };
c3d2994b 80 _cleanup_close_ int s = -1;
fef0e0f3 81 int r, on = 1;
8b4a9693 82
088b6ba2 83 assert(ifindex > 0);
23f30ed3
TG
84 assert(link);
85
66a67eff 86 s = socket(AF_PACKET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
8b4a9693
PF
87 if (s < 0)
88 return -errno;
89
088b6ba2 90 r = setsockopt(s, SOL_PACKET, PACKET_AUXDATA, &on, sizeof(on));
c3d2994b
TG
91 if (r < 0)
92 return -errno;
93
94 r = setsockopt(s, SOL_SOCKET, SO_ATTACH_FILTER, &fprog, sizeof(fprog));
95 if (r < 0)
96 return -errno;
97
b1f24b75
BG
98 link->ll = (struct sockaddr_ll) {
99 .sll_family = AF_PACKET,
100 .sll_protocol = htobe16(ETH_P_IP),
101 .sll_ifindex = ifindex,
102 .sll_hatype = htobe16(arp_type),
103 .sll_halen = mac_addr_len,
104 };
76253e73 105 memcpy(link->ll.sll_addr, bcast_addr, mac_addr_len);
8b4a9693 106
b1f24b75 107 r = bind(s, &link->sa, SOCKADDR_LL_LEN(link->ll));
c3d2994b 108 if (r < 0)
bc29e507 109 return -errno;
bc29e507 110
c10d6bdb 111 return TAKE_FD(s);
8c00042c
PF
112}
113
76253e73
DW
114int dhcp_network_bind_raw_socket(int ifindex, union sockaddr_union *link,
115 uint32_t xid, const uint8_t *mac_addr,
9faed222
SS
116 size_t mac_addr_len, uint16_t arp_type,
117 uint16_t port) {
76253e73
DW
118 static const uint8_t eth_bcast[] = { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF };
119 /* Default broadcast address for IPoIB */
120 static const uint8_t ib_bcast[] = {
121 0x00, 0xff, 0xff, 0xff, 0xff, 0x12, 0x40, 0x1b,
122 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
123 0xff, 0xff, 0xff, 0xff
124 };
125 struct ether_addr eth_mac = { { 0, 0, 0, 0, 0, 0 } };
126 const uint8_t *bcast_addr = NULL;
127 uint8_t dhcp_hlen = 0;
128
76253e73
DW
129 if (arp_type == ARPHRD_ETHER) {
130 assert_return(mac_addr_len == ETH_ALEN, -EINVAL);
131 memcpy(&eth_mac, mac_addr, ETH_ALEN);
132 bcast_addr = eth_bcast;
133 dhcp_hlen = ETH_ALEN;
134 } else if (arp_type == ARPHRD_INFINIBAND) {
135 assert_return(mac_addr_len == INFINIBAND_ALEN, -EINVAL);
136 bcast_addr = ib_bcast;
137 } else
138 return -EINVAL;
139
140 return _bind_raw_socket(ifindex, link, xid, mac_addr, mac_addr_len,
9faed222 141 bcast_addr, &eth_mac, arp_type, dhcp_hlen, port);
76253e73
DW
142}
143
3e7b9f76 144int dhcp_network_bind_udp_socket(int ifindex, be32_t address, uint16_t port) {
234fc2df
PF
145 union sockaddr_union src = {
146 .in.sin_family = AF_INET,
080ab276
TG
147 .in.sin_port = htobe16(port),
148 .in.sin_addr.s_addr = address,
234fc2df 149 };
c3d2994b 150 _cleanup_close_ int s = -1;
3e7b9f76 151 char ifname[IF_NAMESIZE] = "";
076adf01 152 int r, on = 1, tos = IPTOS_CLASS_CS6;
234fc2df
PF
153
154 s = socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
155 if (s < 0)
156 return -errno;
157
c3d2994b
TG
158 r = setsockopt(s, IPPROTO_IP, IP_TOS, &tos, sizeof(tos));
159 if (r < 0)
85923f79 160 return -errno;
b44cd882 161
076adf01
TG
162 r = setsockopt(s, SOL_SOCKET, SO_REUSEADDR, &on, sizeof(on));
163 if (r < 0)
164 return -errno;
fef0e0f3 165
3e7b9f76
MK
166 if (ifindex > 0) {
167 if (if_indextoname(ifindex, ifname) == 0)
168 return -errno;
169
170 r = setsockopt(s, SOL_SOCKET, SO_BINDTODEVICE, ifname, strlen(ifname));
171 if (r < 0)
172 return -errno;
173 }
174
076adf01 175 if (address == INADDR_ANY) {
fef0e0f3
TG
176 r = setsockopt(s, IPPROTO_IP, IP_PKTINFO, &on, sizeof(on));
177 if (r < 0)
178 return -errno;
d6bd972d
TG
179
180 r = setsockopt(s, SOL_SOCKET, SO_BROADCAST, &on, sizeof(on));
181 if (r < 0)
182 return -errno;
3e7b9f76 183
076adf01
TG
184 } else {
185 r = setsockopt(s, IPPROTO_IP, IP_FREEBIND, &on, sizeof(on));
186 if (r < 0)
187 return -errno;
fef0e0f3 188 }
85923f79 189
c3d2994b
TG
190 r = bind(s, &src.sa, sizeof(src.in));
191 if (r < 0)
234fc2df 192 return -errno;
234fc2df 193
c10d6bdb 194 return TAKE_FD(s);
234fc2df
PF
195}
196
8c00042c 197int dhcp_network_send_raw_socket(int s, const union sockaddr_union *link,
c3d2994b
TG
198 const void *packet, size_t len) {
199 int r;
200
23f30ed3
TG
201 assert(link);
202 assert(packet);
203 assert(len);
204
b1f24b75 205 r = sendto(s, packet, len, 0, &link->sa, SOCKADDR_LL_LEN(link->ll));
c3d2994b 206 if (r < 0)
1c8035a8 207 return -errno;
8b4a9693 208
1c8035a8 209 return 0;
8b4a9693 210}
234fc2df 211
080ab276 212int dhcp_network_send_udp_socket(int s, be32_t address, uint16_t port,
c3d2994b 213 const void *packet, size_t len) {
234fc2df
PF
214 union sockaddr_union dest = {
215 .in.sin_family = AF_INET,
080ab276
TG
216 .in.sin_port = htobe16(port),
217 .in.sin_addr.s_addr = address,
234fc2df 218 };
c3d2994b
TG
219 int r;
220
221 assert(s >= 0);
222 assert(packet);
223 assert(len);
234fc2df 224
c3d2994b
TG
225 r = sendto(s, packet, len, 0, &dest.sa, sizeof(dest.in));
226 if (r < 0)
234fc2df
PF
227 return -errno;
228
229 return 0;
230}