]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/libsystemd-network/dhcp-network.c
tree-wide: use -EBADF more
[thirdparty/systemd.git] / src / libsystemd-network / dhcp-network.c
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2 /***
3 Copyright © 2013 Intel Corporation. All rights reserved.
4 ***/
5
6 #include <errno.h>
7 #include <net/ethernet.h>
8 #include <net/if.h>
9 #include <net/if_arp.h>
10 #include <stdio.h>
11 #include <string.h>
12 #include <linux/filter.h>
13 #include <linux/if_infiniband.h>
14 #include <linux/if_packet.h>
15
16 #include "dhcp-internal.h"
17 #include "fd-util.h"
18 #include "socket-util.h"
19 #include "unaligned.h"
20
21 static int _bind_raw_socket(
22 int ifindex,
23 union sockaddr_union *link,
24 uint32_t xid,
25 const struct hw_addr_data *hw_addr,
26 const struct hw_addr_data *bcast_addr,
27 uint16_t arp_type,
28 uint16_t port) {
29
30 assert(ifindex > 0);
31 assert(link);
32 assert(hw_addr);
33 assert(bcast_addr);
34 assert(IN_SET(arp_type, ARPHRD_ETHER, ARPHRD_INFINIBAND));
35
36 switch (arp_type) {
37 case ARPHRD_ETHER:
38 assert(hw_addr->length == ETH_ALEN);
39 assert(bcast_addr->length == ETH_ALEN);
40 break;
41 case ARPHRD_INFINIBAND:
42 assert(hw_addr->length == 0);
43 assert(bcast_addr->length == INFINIBAND_ALEN);
44 break;
45 default:
46 assert_not_reached();
47 }
48
49 struct sock_filter filter[] = {
50 BPF_STMT(BPF_LD + BPF_W + BPF_LEN, 0), /* A <- packet length */
51 BPF_JUMP(BPF_JMP + BPF_JGE + BPF_K, sizeof(DHCPPacket), 1, 0), /* packet >= DHCPPacket ? */
52 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
53 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.protocol)), /* A <- IP protocol */
54 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 1, 0), /* IP protocol == UDP ? */
55 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
56 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags */
57 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x20), /* A <- A & 0x20 (More Fragments bit) */
58 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
59 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
60 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, ip.frag_off)), /* A <- Flags + Fragment offset */
61 BPF_STMT(BPF_ALU + BPF_AND + BPF_K, 0x1fff), /* A <- A & 0x1fff (Fragment offset) */
62 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, 0, 1, 0), /* A == 0 ? */
63 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
64 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, udp.dest)), /* A <- UDP destination port */
65 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, port, 1, 0), /* UDP destination port == DHCP client port ? */
66 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
67 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.op)), /* A <- DHCP op */
68 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, BOOTREPLY, 1, 0), /* op == BOOTREPLY ? */
69 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
70 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.htype)), /* A <- DHCP header type */
71 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, arp_type, 1, 0), /* header type == arp_type ? */
72 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
73 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.xid)), /* A <- client identifier */
74 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, xid, 1, 0), /* client identifier == xid ? */
75 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
76 BPF_STMT(BPF_LD + BPF_B + BPF_ABS, offsetof(DHCPPacket, dhcp.hlen)), /* A <- MAC address length */
77 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, (uint8_t) hw_addr->length, 1, 0), /* address length == hw_addr->length ? */
78 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
79
80 /* We only support MAC address length to be either 0 or 6 (ETH_ALEN). Optionally
81 * compare chaddr for ETH_ALEN bytes. */
82 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETH_ALEN, 0, 8), /* A (the MAC address length) == ETH_ALEN ? */
83 BPF_STMT(BPF_LDX + BPF_IMM, unaligned_read_be32(hw_addr->bytes)), /* X <- 4 bytes of client's MAC */
84 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr)), /* A <- 4 bytes of MAC from dhcp.chaddr */
85 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_X, 0, 1, 0), /* A == X ? */
86 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
87 BPF_STMT(BPF_LDX + BPF_IMM, unaligned_read_be16(hw_addr->bytes + 4)), /* X <- remainder of client's MAC */
88 BPF_STMT(BPF_LD + BPF_H + BPF_ABS, offsetof(DHCPPacket, dhcp.chaddr) + 4), /* A <- remainder of MAC from dhcp.chaddr */
89 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_X, 0, 1, 0), /* A == X ? */
90 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
91
92 BPF_STMT(BPF_LD + BPF_W + BPF_ABS, offsetof(DHCPPacket, dhcp.magic)), /* A <- DHCP magic cookie */
93 BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, DHCP_MAGIC_COOKIE, 1, 0), /* cookie == DHCP magic cookie ? */
94 BPF_STMT(BPF_RET + BPF_K, 0), /* ignore */
95 BPF_STMT(BPF_RET + BPF_K, UINT32_MAX), /* accept */
96 };
97 struct sock_fprog fprog = {
98 .len = ELEMENTSOF(filter),
99 .filter = filter
100 };
101 _cleanup_close_ int s = -EBADF;
102 int r;
103
104 s = socket(AF_PACKET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
105 if (s < 0)
106 return -errno;
107
108 r = setsockopt_int(s, SOL_PACKET, PACKET_AUXDATA, true);
109 if (r < 0)
110 return r;
111
112 r = setsockopt(s, SOL_SOCKET, SO_ATTACH_FILTER, &fprog, sizeof(fprog));
113 if (r < 0)
114 return -errno;
115
116 link->ll = (struct sockaddr_ll) {
117 .sll_family = AF_PACKET,
118 .sll_protocol = htobe16(ETH_P_IP),
119 .sll_ifindex = ifindex,
120 .sll_hatype = htobe16(arp_type),
121 .sll_halen = bcast_addr->length,
122 };
123 /* We may overflow link->ll. link->ll_buffer ensures we have enough space. */
124 memcpy(link->ll.sll_addr, bcast_addr->bytes, bcast_addr->length);
125
126 r = bind(s, &link->sa, SOCKADDR_LL_LEN(link->ll));
127 if (r < 0)
128 return -errno;
129
130 return TAKE_FD(s);
131 }
132
133 int dhcp_network_bind_raw_socket(
134 int ifindex,
135 union sockaddr_union *link,
136 uint32_t xid,
137 const struct hw_addr_data *hw_addr,
138 const struct hw_addr_data *bcast_addr,
139 uint16_t arp_type,
140 uint16_t port) {
141
142 static struct hw_addr_data default_eth_bcast = {
143 .length = ETH_ALEN,
144 .ether = {{ 0xff, 0xff, 0xff, 0xff, 0xff, 0xff }},
145 }, default_ib_bcast = {
146 .length = INFINIBAND_ALEN,
147 .infiniband = {
148 0x00, 0xff, 0xff, 0xff, 0xff, 0x12, 0x40, 0x1b,
149 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
150 0xff, 0xff, 0xff, 0xff
151 },
152 };
153
154 assert(ifindex > 0);
155 assert(link);
156 assert(hw_addr);
157
158 switch (arp_type) {
159 case ARPHRD_ETHER:
160 return _bind_raw_socket(ifindex, link, xid,
161 hw_addr,
162 (bcast_addr && !hw_addr_is_null(bcast_addr)) ? bcast_addr : &default_eth_bcast,
163 arp_type, port);
164
165 case ARPHRD_INFINIBAND:
166 return _bind_raw_socket(ifindex, link, xid,
167 &HW_ADDR_NULL,
168 (bcast_addr && !hw_addr_is_null(bcast_addr)) ? bcast_addr : &default_ib_bcast,
169 arp_type, port);
170 default:
171 return -EINVAL;
172 }
173 }
174
175 int dhcp_network_bind_udp_socket(int ifindex, be32_t address, uint16_t port, int ip_service_type) {
176 union sockaddr_union src = {
177 .in.sin_family = AF_INET,
178 .in.sin_port = htobe16(port),
179 .in.sin_addr.s_addr = address,
180 };
181 _cleanup_close_ int s = -EBADF;
182 int r;
183
184 s = socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
185 if (s < 0)
186 return -errno;
187
188 if (ip_service_type >= 0)
189 r = setsockopt_int(s, IPPROTO_IP, IP_TOS, ip_service_type);
190 else
191 r = setsockopt_int(s, IPPROTO_IP, IP_TOS, IPTOS_CLASS_CS6);
192 if (r < 0)
193 return r;
194
195 r = setsockopt_int(s, SOL_SOCKET, SO_REUSEADDR, true);
196 if (r < 0)
197 return r;
198
199 if (ifindex > 0) {
200 r = socket_bind_to_ifindex(s, ifindex);
201 if (r < 0)
202 return r;
203 }
204
205 if (port == DHCP_PORT_SERVER) {
206 r = setsockopt_int(s, SOL_SOCKET, SO_BROADCAST, true);
207 if (r < 0)
208 return r;
209 if (address == INADDR_ANY) {
210 /* IP_PKTINFO filter should not be applied when packets are
211 allowed to enter/leave through the interface other than
212 DHCP server sits on(BindToInterface option). */
213 r = setsockopt_int(s, IPPROTO_IP, IP_PKTINFO, true);
214 if (r < 0)
215 return r;
216 }
217 } else {
218 r = setsockopt_int(s, IPPROTO_IP, IP_FREEBIND, true);
219 if (r < 0)
220 return r;
221 }
222
223 if (bind(s, &src.sa, sizeof(src.in)) < 0)
224 return -errno;
225
226 return TAKE_FD(s);
227 }
228
229 int dhcp_network_send_raw_socket(
230 int s,
231 const union sockaddr_union *link,
232 const void *packet,
233 size_t len) {
234
235 /* Do not add assert(s >= 0) here, as this is called in fuzz-dhcp-server, and in that case this
236 * function should fail with negative errno. */
237
238 assert(link);
239 assert(packet);
240 assert(len > 0);
241
242 if (sendto(s, packet, len, 0, &link->sa, SOCKADDR_LL_LEN(link->ll)) < 0)
243 return -errno;
244
245 return 0;
246 }
247
248 int dhcp_network_send_udp_socket(
249 int s,
250 be32_t address,
251 uint16_t port,
252 const void *packet,
253 size_t len) {
254
255 union sockaddr_union dest = {
256 .in.sin_family = AF_INET,
257 .in.sin_port = htobe16(port),
258 .in.sin_addr.s_addr = address,
259 };
260
261 assert(s >= 0);
262 assert(packet);
263 assert(len > 0);
264
265 if (sendto(s, packet, len, 0, &dest.sa, sizeof(dest.in)) < 0)
266 return -errno;
267
268 return 0;
269 }