#include <sys/types.h>
#include <sys/ioctl.h>
#include <sys/socket.h>
#include <net/bpf.h>
#include <net/if.h>
#include <netinet/in.h>
#include <netinet/if_ether.h>
#include <errno.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include "dhcp.h"
#include "dhcpd.h"
#include "log.h"
int
if_register_bpf(struct interface_info *info)
{
int sock;
if ((sock = open("/dev/bpf", O_RDWR)) == -1)
fatal("Can't open bpf device");
if (ioctl(sock, BIOCSETIF, &info->ifr) == -1)
fatal("Can't attach interface %s to bpf device", info->name);
return (sock);
}
void
if_register_send(struct interface_info *info)
{
info->wfdesc = info->rfdesc;
}
struct bpf_insn dhcp_bpf_sfilter[] = {
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 12),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETHERTYPE_IP, 0, 8),
BPF_STMT(BPF_LD + BPF_B + BPF_ABS, 23),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 0, 6),
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 20),
BPF_JUMP(BPF_JMP + BPF_JSET + BPF_K, 0x1fff, 4, 0),
BPF_STMT(BPF_LDX + BPF_B + BPF_MSH, 14),
BPF_STMT(BPF_LD + BPF_H + BPF_IND, 16),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, CLIENT_PORT, 0, 1),
BPF_STMT(BPF_RET+BPF_K, (u_int)-1),
BPF_STMT(BPF_RET+BPF_K, 0),
};
int dhcp_bpf_sfilter_len = sizeof(dhcp_bpf_sfilter) / sizeof(struct bpf_insn);
struct bpf_insn dhcp_bpf_filter[] = {
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 12),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETHERTYPE_IP, 0, 8),
BPF_STMT(BPF_LD + BPF_B + BPF_ABS, 23),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 0, 6),
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 20),
BPF_JUMP(BPF_JMP + BPF_JSET + BPF_K, 0x1fff, 4, 0),
BPF_STMT(BPF_LDX + BPF_B + BPF_MSH, 14),
BPF_STMT(BPF_LD + BPF_H + BPF_IND, 16),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, SERVER_PORT, 0, 1),
BPF_STMT(BPF_RET+BPF_K, (u_int)-1),
BPF_STMT(BPF_RET+BPF_K, 0),
};
int dhcp_bpf_filter_len = sizeof(dhcp_bpf_filter) / sizeof(struct bpf_insn);
struct bpf_insn dhcp_bpf_efilter[] = {
BPF_STMT(BPF_LD + BPF_W + BPF_ABS, 0),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, AF_INET << 24, 0, 10),
BPF_STMT(BPF_LD + BPF_B + BPF_ABS, 21),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_IPIP, 0, 8),
BPF_STMT(BPF_LD + BPF_B + BPF_ABS, 41),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 0, 6),
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 38),
BPF_JUMP(BPF_JMP + BPF_JSET + BPF_K, 0x1fff, 4, 0),
BPF_STMT(BPF_LDX + BPF_B + BPF_MSH, 32),
BPF_STMT(BPF_LD + BPF_H + BPF_IND, 34),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, SERVER_PORT, 0, 1),
BPF_STMT(BPF_RET+BPF_K, (u_int)-1),
BPF_STMT(BPF_RET+BPF_K, 0),
};
int dhcp_bpf_efilter_len = sizeof(dhcp_bpf_efilter) / sizeof(struct bpf_insn);
struct bpf_insn dhcp_bpf_swfilter[] = {
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 12),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETHERTYPE_IP, 0, 8),
BPF_STMT(BPF_LD + BPF_B + BPF_ABS, 23),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 0, 6),
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 20),
BPF_JUMP(BPF_JMP + BPF_JSET + BPF_K, 0x1fff, 4, 0),
BPF_STMT(BPF_LDX + BPF_B + BPF_MSH, 14),
BPF_STMT(BPF_LD + BPF_H + BPF_IND, 14),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, CLIENT_PORT, 0, 1),
BPF_STMT(BPF_RET+BPF_K, (u_int)-1),
BPF_STMT(BPF_RET+BPF_K, 0),
};
int dhcp_bpf_swfilter_len = sizeof(dhcp_bpf_swfilter) /
sizeof(struct bpf_insn);
struct bpf_insn dhcp_bpf_wfilter[] = {
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 12),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, ETHERTYPE_IP, 0, 8),
BPF_STMT(BPF_LD + BPF_B + BPF_ABS, 23),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 0, 6),
BPF_STMT(BPF_LD + BPF_H + BPF_ABS, 20),
BPF_JUMP(BPF_JMP + BPF_JSET + BPF_K, 0x1fff, 4, 0),
BPF_STMT(BPF_LDX + BPF_B + BPF_MSH, 14),
BPF_STMT(BPF_LD + BPF_H + BPF_IND, 14),
BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, SERVER_PORT, 0, 1),
BPF_STMT(BPF_RET+BPF_K, (u_int)-1),
BPF_STMT(BPF_RET+BPF_K, 0),
};
int dhcp_bpf_wfilter_len = sizeof(dhcp_bpf_wfilter) / sizeof(struct bpf_insn);
void
if_register_receive(struct interface_info *info, int isserver)
{
struct bpf_version v;
struct bpf_program p;
int flag = 1, sz, cmplt = 0;
info->rfdesc = if_register_bpf(info);
if (ioctl(info->rfdesc, BIOCVERSION, &v) == -1)
fatal("Can't get BPF version");
if (v.bv_major != BPF_MAJOR_VERSION ||
v.bv_minor < BPF_MINOR_VERSION)
fatalx("Kernel BPF version out of range - recompile dhcpd!");
if (ioctl(info->rfdesc, BIOCIMMEDIATE, &flag) == -1)
fatal("Can't set immediate mode on bpf device");
if (ioctl(info->rfdesc, BIOCSHDRCMPLT, &cmplt) == -1)
fatal("Can't set header complete flag on bpf device");
if (ioctl(info->rfdesc, BIOCGBLEN, &sz) == -1)
fatal("Can't get bpf buffer length");
info->rbuf_max = sz;
info->rbuf = malloc(info->rbuf_max);
if (!info->rbuf)
fatalx("Can't allocate %lu bytes for bpf input buffer.",
(unsigned long)info->rbuf_max);
info->rbuf_offset = 0;
info->rbuf_len = 0;
if (isserver) {
p.bf_len = dhcp_bpf_sfilter_len;
p.bf_insns = dhcp_bpf_sfilter;
} else if (info->hw_address.htype == HTYPE_IPSEC_TUNNEL) {
p.bf_len = dhcp_bpf_efilter_len;
p.bf_insns = dhcp_bpf_efilter;
} else {
p.bf_len = dhcp_bpf_filter_len;
p.bf_insns = dhcp_bpf_filter;
}
if (ioctl(info->rfdesc, BIOCSETF, &p) == -1)
fatal("Can't install packet filter program");
if (isserver) {
p.bf_len = dhcp_bpf_swfilter_len;
p.bf_insns = dhcp_bpf_swfilter;
} else {
p.bf_len = dhcp_bpf_wfilter_len;
p.bf_insns = dhcp_bpf_wfilter;
}
if (ioctl(info->rfdesc, BIOCSETWF, &p) == -1)
fatal("Can't install write filter program");
if (ioctl(info->rfdesc, BIOCLOCK) == -1)
fatal("Failed to lock bpf descriptor");
}
ssize_t
send_packet(struct interface_info *interface,
struct dhcp_packet *raw, size_t len, struct packet_ctx *pc)
{
unsigned char buf[256];
struct iovec iov[2];
ssize_t bufp;
int result;
result = -1;
if (interface->hw_address.htype == HTYPE_IPSEC_TUNNEL) {
socklen_t slen = pc->pc_dst.ss_len;
result = sendto(server_fd, raw, len, 0,
(struct sockaddr *)&pc->pc_dst, slen);
goto done;
}
if ((bufp = assemble_hw_header(buf, sizeof(buf), 0, pc,
interface->hw_address.htype)) == -1)
goto done;
if ((bufp = assemble_udp_ip_header(buf, sizeof(buf), bufp, pc,
(unsigned char *)raw, len)) == -1)
goto done;
iov[0].iov_base = (char *)buf;
iov[0].iov_len = bufp;
iov[1].iov_base = (char *)raw;
iov[1].iov_len = len;
result = writev(interface->wfdesc, iov, 2);
done:
if (result == -1)
log_warn("send_packet");
return (result);
}
ssize_t
receive_packet(struct interface_info *interface, unsigned char *buf,
size_t len, struct packet_ctx *pc)
{
int length = 0;
ssize_t offset = 0;
struct bpf_hdr hdr;
do {
if (interface->rbuf_offset == interface->rbuf_len) {
length = read(interface->rfdesc, interface->rbuf,
interface->rbuf_max);
if (length <= 0)
return (length);
interface->rbuf_offset = 0;
interface->rbuf_len = length;
}
if (interface->rbuf_len - interface->rbuf_offset <
sizeof(hdr)) {
interface->rbuf_offset = interface->rbuf_len;
continue;
}
memcpy(&hdr, &interface->rbuf[interface->rbuf_offset],
sizeof(hdr));
if (interface->rbuf_offset + hdr.bh_hdrlen + hdr.bh_caplen >
interface->rbuf_len) {
interface->rbuf_offset = interface->rbuf_len;
continue;
}
if (hdr.bh_caplen != hdr.bh_datalen) {
interface->rbuf_offset += hdr.bh_hdrlen =
hdr.bh_caplen;
continue;
}
interface->rbuf_offset += hdr.bh_hdrlen;
offset = decode_hw_header(interface->rbuf,
interface->rbuf_len, interface->rbuf_offset, pc,
interface->hw_address.htype);
if (offset < 0) {
interface->rbuf_offset += hdr.bh_caplen;
continue;
}
offset = decode_udp_ip_header(interface->rbuf,
interface->rbuf_len, offset, pc, hdr.bh_csumflags);
if (offset < 0) {
interface->rbuf_offset += hdr.bh_caplen;
continue;
}
hdr.bh_caplen -= offset - interface->rbuf_offset;
interface->rbuf_offset = offset;
if (hdr.bh_caplen > len) {
interface->rbuf_offset += hdr.bh_caplen;
continue;
}
memcpy(buf, interface->rbuf + interface->rbuf_offset,
hdr.bh_caplen);
interface->rbuf_offset += hdr.bh_caplen;
return (hdr.bh_caplen);
} while (!length);
return (0);
}