]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/libsystemd-network/dhcp-network.c
sd-network: make socket filter programs static const where possible
[thirdparty/systemd.git] / src / libsystemd-network / dhcp-network.c
1 /***
2 This file is part of systemd.
3
4 Copyright (C) 2013 Intel Corporation. All rights reserved.
5
6 systemd is free software; you can redistribute it and/or modify it
7 under the terms of the GNU Lesser General Public License as published by
8 the Free Software Foundation; either version 2.1 of the License, or
9 (at your option) any later version.
10
11 systemd is distributed in the hope that it will be useful, but
12 WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 Lesser General Public License for more details.
15
16 You should have received a copy of the GNU Lesser General Public License
17 along with systemd; If not, see <http://www.gnu.org/licenses/>.
18 ***/
19
20 #include <errno.h>
21 #include <sys/types.h>
22 #include <sys/socket.h>
23 #include <string.h>
24 #include <linux/if_packet.h>
25 #include <net/ethernet.h>
26 #include <net/if_arp.h>
27 #include <stdio.h>
28 #include <unistd.h>
29 #include <linux/filter.h>
30
31 #include "socket-util.h"
32
33 #include "dhcp-internal.h"
34
35 int dhcp_network_bind_raw_socket(int ifindex, union sockaddr_union *link,
36 uint32_t xid, struct ether_addr mac_addr) {
37
38 struct sock_filter filter[] = {
39 BPF_STMT(BPF_LD + BPF_W + BPF_LEN, 0), /* A <- packet length */
40 BPF_JUMP(BPF_JMP + BPF_JGE + BPF_K, sizeof(DHCPPacket), 1, 0), /* packet >= DHCPPacket ? */
41 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
42 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.protocol)), /* A <- IP protocol */
43 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 1, 0), /* IP protocol == UDP ? */
44 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
45 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags */
46 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x20), /* A <- A & 0x20 (More Fragments bit) */
47 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
48 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
49 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags + Fragment offset */
50 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x1fff), /* A <- A & 0x1fff (Fragment offset) */
51 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
52 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
53 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, udp.dest)), /* A <- UDP destination port */
54 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, DHCP_PORT_CLIENT, 1, 0), /* UDP destination port == DHCP client port ? */
55 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
56 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.op)), /* A <- DHCP op */
57 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, BOOTREPLY, 1, 0), /* op == BOOTREPLY ? */
58 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
59 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.htype)), /* A <- DHCP header type */
60 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ARPHRD_ETHER, 1, 0), /* header type == ARPHRD_ETHER ? */
61 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
62 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.hlen)), /* A <- mac address length */
63 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETHER_ADDR_LEN, 1, 0), /* address length == ETHER_ADDR_LEN ? */
64 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
65 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.xid)), /* A <- client identifier */
66 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, xid, 1, 0), /* client identifier == xid ? */
67 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
68 BPF_STMT(BPF_LD + BPF_IMM, htobe32(*((unsigned int *) &mac_addr))), /* A <- 4 bytes of client's MAC */
69 BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */
70 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr)), /* A <- 4 bytes of MAC from dhcp.chaddr */
71 BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */
72 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
73 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
74 BPF_STMT(BPF_LD + BPF_IMM, htobe16(*((unsigned short *) (((char *) &mac_addr) + 4)))), /* A <- remainder of client's MAC */
75 BPF_STMT(BPF_MISC + BPF_TAX, 0), /* X <- A */
76 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr) + 4), /* A <- remainder of MAC from dhcp.chaddr */
77 BPF_STMT(BPF_ALU + BPF_XOR + BPF_X, 0), /* A xor X */
78 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
79 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
80 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.magic)), /* A <- DHCP magic cookie */
81 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, DHCP_MAGIC_COOKIE, 1, 0), /* cookie == DHCP magic cookie ? */
82 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
83 BPF_STMT(BPF_RET + BPF_K, 65535), /* return all */
84 };
85 struct sock_fprog fprog = {
86 .len = ELEMENTSOF(filter),
87 .filter = filter
88 };
89 _cleanup_close_ int s = -1;
90 int r, on = 1;
91
92 assert(ifindex > 0);
93 assert(link);
94
95 s = socket(AF_PACKET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
96 if (s < 0)
97 return -errno;
98
99 r = setsockopt(s, SOL_PACKET, PACKET_AUXDATA, &on, sizeof(on));
100 if (r < 0)
101 return -errno;
102
103 r = setsockopt(s, SOL_SOCKET, SO_ATTACH_FILTER, &fprog, sizeof(fprog));
104 if (r < 0)
105 return -errno;
106
107 link->ll.sll_family = AF_PACKET;
108 link->ll.sll_protocol = htons(ETH_P_IP);
109 link->ll.sll_ifindex = ifindex;
110 link->ll.sll_halen = ETH_ALEN;
111 memset(link->ll.sll_addr, 0xff, ETH_ALEN);
112
113 r = bind(s, &link->sa, sizeof(link->ll));
114 if (r < 0)
115 return -errno;
116
117 r = s;
118 s = -1;
119
120 return r;
121 }
122
123 int dhcp_network_bind_udp_socket(be32_t address, uint16_t port) {
124 union sockaddr_union src = {
125 .in.sin_family = AF_INET,
126 .in.sin_port = htobe16(port),
127 .in.sin_addr.s_addr = address,
128 };
129 _cleanup_close_ int s = -1;
130 int r, on = 1, tos = IPTOS_CLASS_CS6;
131
132 s = socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
133 if (s < 0)
134 return -errno;
135
136 r = setsockopt(s, IPPROTO_IP, IP_TOS, &tos, sizeof(tos));
137 if (r < 0)
138 return -errno;
139
140 r = setsockopt(s, SOL_SOCKET, SO_REUSEADDR, &on, sizeof(on));
141 if (r < 0)
142 return -errno;
143
144 if (address == INADDR_ANY) {
145 r = setsockopt(s, IPPROTO_IP, IP_PKTINFO, &on, sizeof(on));
146 if (r < 0)
147 return -errno;
148
149 r = setsockopt(s, SOL_SOCKET, SO_BROADCAST, &on, sizeof(on));
150 if (r < 0)
151 return -errno;
152 } else {
153 r = setsockopt(s, IPPROTO_IP, IP_FREEBIND, &on, sizeof(on));
154 if (r < 0)
155 return -errno;
156 }
157
158 r = bind(s, &src.sa, sizeof(src.in));
159 if (r < 0)
160 return -errno;
161
162 r = s;
163 s = -1;
164
165 return r;
166 }
167
168 int dhcp_network_send_raw_socket(int s, const union sockaddr_union *link,
169 const void *packet, size_t len) {
170 int r;
171
172 assert(link);
173 assert(packet);
174 assert(len);
175
176 r = sendto(s, packet, len, 0, &link->sa, sizeof(link->ll));
177 if (r < 0)
178 return -errno;
179
180 return 0;
181 }
182
183 int dhcp_network_send_udp_socket(int s, be32_t address, uint16_t port,
184 const void *packet, size_t len) {
185 union sockaddr_union dest = {
186 .in.sin_family = AF_INET,
187 .in.sin_port = htobe16(port),
188 .in.sin_addr.s_addr = address,
189 };
190 int r;
191
192 assert(s >= 0);
193 assert(packet);
194 assert(len);
195
196 r = sendto(s, packet, len, 0, &dest.sa, sizeof(dest.in));
197 if (r < 0)
198 return -errno;
199
200 return 0;
201 }