]>
Commit | Line | Data |
---|---|---|
98bf1607 | 1 | /* |
7dc4e69c | 2 | * Copyright(c) 2009-2010,2013-2014 by Internet Systems Consortium, Inc.("ISC") |
98bf1607 SR |
3 | * |
4 | * Permission to use, copy, modify, and distribute this software for any | |
5 | * purpose with or without fee is hereby granted, provided that the above | |
6 | * copyright notice and this permission notice appear in all copies. | |
7 | * | |
8 | * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES | |
9 | * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF | |
10 | * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR | |
11 | * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES | |
12 | * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN | |
13 | * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT | |
14 | * OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. | |
15 | * | |
16 | * Internet Systems Consortium, Inc. | |
17 | * 950 Charter Street | |
18 | * Redwood City, CA 94063 | |
19 | * <info@isc.org> | |
20 | * http://www.isc.org/ | |
21 | * | |
22 | */ | |
23 | ||
24 | /*Trying to figure out what we need to define to get things to work. | |
25 | It looks like we want/need the export library but need the fdwatchcommand | |
26 | which may be a problem */ | |
27 | ||
28 | #include "dhcpd.h" | |
29 | ||
3ac2a573 | 30 | #include <sys/time.h> |
47e8308d | 31 | #include <signal.h> |
3ac2a573 | 32 | |
98bf1607 | 33 | dhcp_context_t dhcp_gbl_ctx; |
0895c955 | 34 | int shutdown_signal = 0; |
98bf1607 | 35 | |
e54ff84f SR |
36 | #if defined (NSUPDATE) |
37 | ||
38 | /* This routine will open up the /etc/resolv.conf file and | |
39 | * send any nameservers it finds to the DNS client code. | |
40 | * It may be moved to be part of the dns client code instead | |
41 | * of being in the DHCP code | |
42 | */ | |
43 | isc_result_t | |
44 | dhcp_dns_client_setservers(void) | |
45 | { | |
46 | isc_result_t result; | |
47 | irs_resconf_t *resconf = NULL; | |
48 | isc_sockaddrlist_t *nameservers; | |
49 | isc_sockaddr_t *sa; | |
50 | ||
51 | result = irs_resconf_load(dhcp_gbl_ctx.mctx, _PATH_RESOLV_CONF, | |
52 | &resconf); | |
22ceb8bb | 53 | if (result != ISC_R_SUCCESS && result != ISC_R_FILENOTFOUND) { |
e54ff84f SR |
54 | log_error("irs_resconf_load failed: %d.", result); |
55 | return (result); | |
56 | } | |
57 | ||
58 | nameservers = irs_resconf_getnameservers(resconf); | |
59 | ||
60 | /* Initialize port numbers */ | |
61 | for (sa = ISC_LIST_HEAD(*nameservers); | |
62 | sa != NULL; | |
63 | sa = ISC_LIST_NEXT(sa, link)) { | |
64 | switch (sa->type.sa.sa_family) { | |
65 | case AF_INET: | |
66 | sa->type.sin.sin_port = htons(NS_DEFAULTPORT); | |
67 | break; | |
68 | case AF_INET6: | |
69 | sa->type.sin6.sin6_port = htons(NS_DEFAULTPORT); | |
70 | break; | |
71 | default: | |
72 | break; | |
73 | } | |
74 | } | |
75 | ||
76 | result = dns_client_setservers(dhcp_gbl_ctx.dnsclient, | |
77 | dns_rdataclass_in, | |
78 | NULL, nameservers); | |
79 | if (result != ISC_R_SUCCESS) { | |
80 | log_error("dns_client_setservers failed: %d.", | |
81 | result); | |
82 | } | |
83 | return (result); | |
84 | } | |
85 | #endif | |
86 | ||
98bf1607 SR |
87 | void |
88 | isclib_cleanup(void) | |
89 | { | |
90 | #if defined (NSUPDATE) | |
91 | if (dhcp_gbl_ctx.dnsclient != NULL) | |
92 | dns_client_destroy((dns_client_t **)&dhcp_gbl_ctx.dnsclient); | |
93 | #endif | |
94 | ||
95 | if (dhcp_gbl_ctx.task != NULL) { | |
98bf1607 SR |
96 | isc_task_shutdown(dhcp_gbl_ctx.task); |
97 | isc_task_detach(&dhcp_gbl_ctx.task); | |
98 | } | |
99 | ||
100 | if (dhcp_gbl_ctx.timermgr != NULL) | |
101 | isc_timermgr_destroy(&dhcp_gbl_ctx.timermgr); | |
102 | ||
103 | if (dhcp_gbl_ctx.socketmgr != NULL) | |
104 | isc_socketmgr_destroy(&dhcp_gbl_ctx.socketmgr); | |
105 | ||
106 | if (dhcp_gbl_ctx.taskmgr != NULL) | |
107 | isc_taskmgr_destroy(&dhcp_gbl_ctx.taskmgr); | |
108 | ||
109 | if (dhcp_gbl_ctx.actx_started != ISC_FALSE) { | |
110 | isc_app_ctxfinish(dhcp_gbl_ctx.actx); | |
111 | dhcp_gbl_ctx.actx_started = ISC_FALSE; | |
112 | } | |
113 | ||
114 | if (dhcp_gbl_ctx.actx != NULL) | |
115 | isc_appctx_destroy(&dhcp_gbl_ctx.actx); | |
116 | ||
117 | if (dhcp_gbl_ctx.mctx != NULL) | |
118 | isc_mem_detach(&dhcp_gbl_ctx.mctx); | |
119 | ||
120 | return; | |
121 | } | |
122 | ||
6067cd48 TM |
123 | /* Installs a handler for a signal using sigaction */ |
124 | static void | |
125 | handle_signal(int sig, void (*handler)(int)) { | |
126 | struct sigaction sa; | |
127 | ||
128 | memset(&sa, 0, sizeof(sa)); | |
129 | sa.sa_handler = handler; | |
130 | sigfillset(&sa.sa_mask); | |
131 | if (sigaction(sig, &sa, NULL) != 0) { | |
132 | log_debug("handle_signal() failed for signal %d error: %s", | |
133 | sig, strerror(errno)); | |
134 | } | |
135 | } | |
136 | ||
98bf1607 | 137 | isc_result_t |
61ef216b SR |
138 | dhcp_context_create(int flags, |
139 | struct in_addr *local4, | |
140 | struct in6_addr *local6) { | |
98bf1607 SR |
141 | isc_result_t result; |
142 | ||
61ef216b SR |
143 | if ((flags & DHCP_CONTEXT_PRE_DB) != 0) { |
144 | /* | |
145 | * Set up the error messages, this isn't the right place | |
146 | * for this call but it is convienent for now. | |
147 | */ | |
148 | result = dhcp_result_register(); | |
149 | if (result != ISC_R_SUCCESS) { | |
150 | log_fatal("register_table() %s: %u", "failed", result); | |
151 | } | |
98bf1607 | 152 | |
61ef216b | 153 | memset(&dhcp_gbl_ctx, 0, sizeof (dhcp_gbl_ctx)); |
98bf1607 | 154 | |
61ef216b | 155 | isc_lib_register(); |
98bf1607 | 156 | |
61ef216b SR |
157 | /* get the current time for use as the random seed */ |
158 | gettimeofday(&cur_tv, (struct timezone *)0); | |
159 | isc_random_seed(cur_tv.tv_sec); | |
98bf1607 | 160 | |
158a34fb SR |
161 | /* we need to create the memory context before |
162 | * the lib inits in case we aren't doing NSUPDATE | |
163 | * in which case dst needs a memory context | |
164 | */ | |
165 | result = isc_mem_create(0, 0, &dhcp_gbl_ctx.mctx); | |
166 | if (result != ISC_R_SUCCESS) | |
167 | goto cleanup; | |
168 | ||
169 | ||
98bf1607 | 170 | #if defined (NSUPDATE) |
61ef216b SR |
171 | result = dns_lib_init(); |
172 | if (result != ISC_R_SUCCESS) | |
173 | goto cleanup; | |
174 | #else | |
175 | /* The dst library is inited as part of dns_lib_init, we don't | |
176 | * need it if NSUPDATE is enabled */ | |
177 | result = dst_lib_init(dhcp_gbl_ctx.mctx, NULL, 0); | |
178 | if (result != ISC_R_SUCCESS) | |
179 | goto cleanup; | |
98bf1607 | 180 | |
61ef216b | 181 | #endif |
61ef216b SR |
182 | |
183 | result = isc_appctx_create(dhcp_gbl_ctx.mctx, | |
184 | &dhcp_gbl_ctx.actx); | |
185 | if (result != ISC_R_SUCCESS) | |
186 | goto cleanup; | |
187 | ||
188 | result = isc_app_ctxstart(dhcp_gbl_ctx.actx); | |
189 | if (result != ISC_R_SUCCESS) | |
190 | return (result); | |
191 | dhcp_gbl_ctx.actx_started = ISC_TRUE; | |
192 | ||
6067cd48 TM |
193 | /* Not all OSs support suppressing SIGPIPE through socket |
194 | * options, so set the sigal action to be ignore. This allows | |
195 | * broken connections to fail gracefully with EPIPE on writes */ | |
196 | handle_signal(SIGPIPE, SIG_IGN); | |
197 | ||
61ef216b SR |
198 | result = isc_taskmgr_createinctx(dhcp_gbl_ctx.mctx, |
199 | dhcp_gbl_ctx.actx, | |
200 | 1, 0, | |
201 | &dhcp_gbl_ctx.taskmgr); | |
202 | if (result != ISC_R_SUCCESS) | |
203 | goto cleanup; | |
204 | ||
205 | result = isc_socketmgr_createinctx(dhcp_gbl_ctx.mctx, | |
206 | dhcp_gbl_ctx.actx, | |
207 | &dhcp_gbl_ctx.socketmgr); | |
208 | if (result != ISC_R_SUCCESS) | |
209 | goto cleanup; | |
210 | ||
211 | result = isc_timermgr_createinctx(dhcp_gbl_ctx.mctx, | |
212 | dhcp_gbl_ctx.actx, | |
213 | &dhcp_gbl_ctx.timermgr); | |
214 | if (result != ISC_R_SUCCESS) | |
215 | goto cleanup; | |
216 | ||
217 | result = isc_task_create(dhcp_gbl_ctx.taskmgr, 0, &dhcp_gbl_ctx.task); | |
218 | if (result != ISC_R_SUCCESS) | |
219 | goto cleanup; | |
220 | } | |
98bf1607 SR |
221 | |
222 | #if defined (NSUPDATE) | |
61ef216b SR |
223 | if ((flags & DHCP_CONTEXT_POST_DB) != 0) { |
224 | isc_sockaddr_t localaddr4, *localaddr4_ptr = NULL; | |
225 | isc_sockaddr_t localaddr6, *localaddr6_ptr = NULL; | |
226 | if (local4 != NULL) { | |
227 | isc_sockaddr_fromin(&localaddr4, local4, 0); | |
228 | localaddr4_ptr = &localaddr4; | |
229 | } | |
230 | if (local6 != NULL) { | |
231 | isc_sockaddr_fromin6(&localaddr6, local6, 0); | |
232 | localaddr6_ptr = &localaddr6; | |
233 | } | |
98bf1607 | 234 | |
61ef216b SR |
235 | result = dns_client_createx2(dhcp_gbl_ctx.mctx, |
236 | dhcp_gbl_ctx.actx, | |
237 | dhcp_gbl_ctx.taskmgr, | |
238 | dhcp_gbl_ctx.socketmgr, | |
239 | dhcp_gbl_ctx.timermgr, | |
240 | 0, | |
241 | &dhcp_gbl_ctx.dnsclient, | |
242 | localaddr4_ptr, | |
243 | localaddr6_ptr); | |
244 | if (result != ISC_R_SUCCESS) | |
245 | goto cleanup; | |
246 | ||
0ab4a716 SR |
247 | /* |
248 | * If we can't set up the servers we may not be able to | |
249 | * do DDNS but we should continue to try and perform | |
250 | * our basic functions and let the user sort it out. | |
251 | */ | |
61ef216b | 252 | result = dhcp_dns_client_setservers(); |
0ab4a716 SR |
253 | if (result != ISC_R_SUCCESS) { |
254 | log_error("Unable to set resolver from resolv.conf; " | |
255 | "startup continuing but DDNS support " | |
256 | "may be affected"); | |
257 | } | |
61ef216b | 258 | } |
98bf1607 | 259 | #endif |
61ef216b | 260 | |
98bf1607 SR |
261 | return(ISC_R_SUCCESS); |
262 | ||
263 | cleanup: | |
d122accf SR |
264 | /* |
265 | * Currently we don't try and cleanup, just return an error | |
266 | * expecting that our caller will log the error and exit. | |
267 | */ | |
98bf1607 SR |
268 | |
269 | return(result); | |
270 | } | |
271 | ||
f4bc8261 SR |
272 | /* |
273 | * Convert a string name into the proper structure for the isc routines | |
274 | * | |
275 | * Previously we allowed names without a trailing '.' however the current | |
276 | * dns and dst code requires the names to end in a period. If the | |
277 | * name doesn't have a trailing period add one as part of creating | |
278 | * the dns name. | |
279 | */ | |
280 | ||
98bf1607 SR |
281 | isc_result_t |
282 | dhcp_isc_name(unsigned char *namestr, | |
283 | dns_fixedname_t *namefix, | |
284 | dns_name_t **name) | |
285 | { | |
286 | size_t namelen; | |
287 | isc_buffer_t b; | |
288 | isc_result_t result; | |
f4bc8261 | 289 | |
98bf1607 SR |
290 | namelen = strlen((char *)namestr); |
291 | isc_buffer_init(&b, namestr, namelen); | |
292 | isc_buffer_add(&b, namelen); | |
293 | dns_fixedname_init(namefix); | |
294 | *name = dns_fixedname_name(namefix); | |
f4bc8261 | 295 | result = dns_name_fromtext(*name, &b, dns_rootname, 0, NULL); |
98bf1607 SR |
296 | isc_buffer_invalidate(&b); |
297 | return(result); | |
298 | } | |
299 | ||
300 | isc_result_t | |
301 | isclib_make_dst_key(char *inname, | |
302 | char *algorithm, | |
303 | unsigned char *secret, | |
304 | int length, | |
305 | dst_key_t **dstkey) | |
306 | { | |
307 | isc_result_t result; | |
308 | dns_name_t *name; | |
309 | dns_fixedname_t name0; | |
310 | isc_buffer_t b; | |
3ffc07de | 311 | unsigned int algorithm_code; |
98bf1607 SR |
312 | |
313 | isc_buffer_init(&b, secret, length); | |
314 | isc_buffer_add(&b, length); | |
315 | ||
3ffc07de TM |
316 | if (strcasecmp(algorithm, DHCP_HMAC_MD5_NAME) == 0) { |
317 | algorithm_code = DST_ALG_HMACMD5; | |
318 | } else if (strcasecmp(algorithm, DHCP_HMAC_SHA1_NAME) == 0) { | |
319 | algorithm_code = DST_ALG_HMACSHA1; | |
320 | } else if (strcasecmp(algorithm, DHCP_HMAC_SHA224_NAME) == 0) { | |
321 | algorithm_code = DST_ALG_HMACSHA224; | |
322 | } else if (strcasecmp(algorithm, DHCP_HMAC_SHA256_NAME) == 0) { | |
323 | algorithm_code = DST_ALG_HMACSHA256; | |
324 | } else if (strcasecmp(algorithm, DHCP_HMAC_SHA384_NAME) == 0) { | |
325 | algorithm_code = DST_ALG_HMACSHA384; | |
326 | } else if (strcasecmp(algorithm, DHCP_HMAC_SHA512_NAME) == 0) { | |
327 | algorithm_code = DST_ALG_HMACSHA512; | |
328 | } else { | |
98bf1607 SR |
329 | return(DHCP_R_INVALIDARG); |
330 | } | |
331 | ||
f4bc8261 | 332 | result = dhcp_isc_name((unsigned char *)inname, &name0, &name); |
98bf1607 SR |
333 | if (result != ISC_R_SUCCESS) { |
334 | return(result); | |
335 | } | |
336 | ||
3ffc07de | 337 | return(dst_key_frombuffer(name, algorithm_code, DNS_KEYOWNER_ENTITY, |
98bf1607 SR |
338 | DNS_KEYPROTO_DNSSEC, dns_rdataclass_in, |
339 | &b, dhcp_gbl_ctx.mctx, dstkey)); | |
340 | } | |
341 | ||
47e8308d SR |
342 | /** |
343 | * signal handler that initiates server shutdown | |
344 | * | |
345 | * @param signal signal code that we received | |
346 | */ | |
347 | void dhcp_signal_handler(int signal) { | |
348 | isc_appctx_t *ctx = dhcp_gbl_ctx.actx; | |
0895c955 SR |
349 | int prev = shutdown_signal; |
350 | ||
351 | if (prev != 0) { | |
352 | /* Already in shutdown. */ | |
353 | return; | |
354 | } | |
355 | /* Possible race but does it matter? */ | |
356 | shutdown_signal = signal; | |
357 | ||
358 | /* Use reload (aka suspend) for easier dispatch() reenter. */ | |
359 | if (ctx && ctx->methods && ctx->methods->ctxsuspend) { | |
360 | (void) isc_app_ctxsuspend(ctx); | |
47e8308d SR |
361 | } |
362 | } |