xref: /dflybsd-src/contrib/dhcpcd/src/dhcp.c (revision 6a6d63c5317abf314a78f8c8300ef73c2bc0c39e)
18d36e1dfSRoy Marples /* SPDX-License-Identifier: BSD-2-Clause */
27827cba2SAaron LI /*
37827cba2SAaron LI  * dhcpcd - DHCP client daemon
480aa9461SRoy Marples  * Copyright (c) 2006-2023 Roy Marples <roy@marples.name>
57827cba2SAaron LI  * All rights reserved
67827cba2SAaron LI 
77827cba2SAaron LI  * Redistribution and use in source and binary forms, with or without
87827cba2SAaron LI  * modification, are permitted provided that the following conditions
97827cba2SAaron LI  * are met:
107827cba2SAaron LI  * 1. Redistributions of source code must retain the above copyright
117827cba2SAaron LI  *    notice, this list of conditions and the following disclaimer.
127827cba2SAaron LI  * 2. Redistributions in binary form must reproduce the above copyright
137827cba2SAaron LI  *    notice, this list of conditions and the following disclaimer in the
147827cba2SAaron LI  *    documentation and/or other materials provided with the distribution.
157827cba2SAaron LI  *
167827cba2SAaron LI  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
177827cba2SAaron LI  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
187827cba2SAaron LI  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
197827cba2SAaron LI  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
207827cba2SAaron LI  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
217827cba2SAaron LI  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
227827cba2SAaron LI  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
237827cba2SAaron LI  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
247827cba2SAaron LI  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
257827cba2SAaron LI  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
267827cba2SAaron LI  * SUCH DAMAGE.
277827cba2SAaron LI  */
287827cba2SAaron LI 
297827cba2SAaron LI #include <sys/param.h>
307827cba2SAaron LI #include <sys/socket.h>
317827cba2SAaron LI 
327827cba2SAaron LI #include <arpa/inet.h>
337827cba2SAaron LI #include <net/if.h>
347827cba2SAaron LI #include <net/route.h>
357827cba2SAaron LI #include <netinet/if_ether.h>
367827cba2SAaron LI #include <netinet/in_systm.h>
377827cba2SAaron LI #include <netinet/in.h>
387827cba2SAaron LI #include <netinet/ip.h>
397827cba2SAaron LI #define __FAVOR_BSD /* Nasty glibc hack so we can use BSD semantics for UDP */
407827cba2SAaron LI #include <netinet/udp.h>
417827cba2SAaron LI #undef __FAVOR_BSD
427827cba2SAaron LI 
43b9ccd228SRoy Marples #ifdef AF_LINK
44b9ccd228SRoy Marples #  include <net/if_dl.h>
45b9ccd228SRoy Marples #endif
46b9ccd228SRoy Marples 
477827cba2SAaron LI #include <assert.h>
487827cba2SAaron LI #include <ctype.h>
497827cba2SAaron LI #include <errno.h>
507827cba2SAaron LI #include <fcntl.h>
517827cba2SAaron LI #include <inttypes.h>
527827cba2SAaron LI #include <stdbool.h>
537827cba2SAaron LI #include <stddef.h>
548d36e1dfSRoy Marples #include <stdio.h>
557827cba2SAaron LI #include <stdlib.h>
567827cba2SAaron LI #include <string.h>
577827cba2SAaron LI #include <unistd.h>
586e63cc1fSRoy Marples #include <syslog.h>
597827cba2SAaron LI 
606e63cc1fSRoy Marples #define ELOOP_QUEUE	ELOOP_DHCP
617827cba2SAaron LI #include "config.h"
627827cba2SAaron LI #include "arp.h"
637827cba2SAaron LI #include "bpf.h"
647827cba2SAaron LI #include "common.h"
657827cba2SAaron LI #include "dhcp.h"
667827cba2SAaron LI #include "dhcpcd.h"
677827cba2SAaron LI #include "dhcp-common.h"
687827cba2SAaron LI #include "duid.h"
697827cba2SAaron LI #include "eloop.h"
707827cba2SAaron LI #include "if.h"
717827cba2SAaron LI #include "ipv4.h"
727827cba2SAaron LI #include "ipv4ll.h"
737827cba2SAaron LI #include "logerr.h"
746e63cc1fSRoy Marples #include "privsep.h"
757827cba2SAaron LI #include "sa.h"
767827cba2SAaron LI #include "script.h"
777827cba2SAaron LI 
787827cba2SAaron LI #define DAD		"Duplicate address detected"
797827cba2SAaron LI #define DHCP_MIN_LEASE	20
807827cba2SAaron LI 
817827cba2SAaron LI #define IPV4A		ADDRIPV4 | ARRAY
827827cba2SAaron LI #define IPV4R		ADDRIPV4 | REQUEST
837827cba2SAaron LI 
847827cba2SAaron LI /* We should define a maximum for the NAK exponential backoff */
857827cba2SAaron LI #define NAKOFF_MAX              60
867827cba2SAaron LI 
877827cba2SAaron LI #ifndef IPDEFTTL
887827cba2SAaron LI #define IPDEFTTL 64 /* RFC1340 */
897827cba2SAaron LI #endif
907827cba2SAaron LI 
918d36e1dfSRoy Marples /* Support older systems with different defines */
928d36e1dfSRoy Marples #if !defined(IP_RECVPKTINFO) && defined(IP_PKTINFO)
938d36e1dfSRoy Marples #define IP_RECVPKTINFO IP_PKTINFO
947827cba2SAaron LI #endif
957827cba2SAaron LI 
967827cba2SAaron LI /* Assert the correct structure size for on wire */
977827cba2SAaron LI __CTASSERT(sizeof(struct ip)		== 20);
987827cba2SAaron LI __CTASSERT(sizeof(struct udphdr)	== 8);
997827cba2SAaron LI __CTASSERT(sizeof(struct bootp)		== 300);
1007827cba2SAaron LI 
1017827cba2SAaron LI struct dhcp_op {
1027827cba2SAaron LI 	uint8_t value;
1037827cba2SAaron LI 	const char *name;
1047827cba2SAaron LI };
1057827cba2SAaron LI 
1067827cba2SAaron LI static const struct dhcp_op dhcp_ops[] = {
1077827cba2SAaron LI 	{ DHCP_DISCOVER,   "DISCOVER" },
1087827cba2SAaron LI 	{ DHCP_OFFER,      "OFFER" },
1097827cba2SAaron LI 	{ DHCP_REQUEST,    "REQUEST" },
1107827cba2SAaron LI 	{ DHCP_DECLINE,    "DECLINE" },
1117827cba2SAaron LI 	{ DHCP_ACK,        "ACK" },
1127827cba2SAaron LI 	{ DHCP_NAK,        "NAK" },
1137827cba2SAaron LI 	{ DHCP_RELEASE,    "RELEASE" },
1147827cba2SAaron LI 	{ DHCP_INFORM,     "INFORM" },
1157827cba2SAaron LI 	{ DHCP_FORCERENEW, "FORCERENEW"},
1167827cba2SAaron LI 	{ 0, NULL }
1177827cba2SAaron LI };
1187827cba2SAaron LI 
1197827cba2SAaron LI static const char * const dhcp_params[] = {
1207827cba2SAaron LI 	"ip_address",
1217827cba2SAaron LI 	"subnet_cidr",
1227827cba2SAaron LI 	"network_number",
1237827cba2SAaron LI 	"filename",
1247827cba2SAaron LI 	"server_name",
1257827cba2SAaron LI 	NULL
1267827cba2SAaron LI };
1277827cba2SAaron LI 
1287827cba2SAaron LI static int dhcp_openbpf(struct interface *);
1298d36e1dfSRoy Marples static void dhcp_start1(void *);
1308d36e1dfSRoy Marples #if defined(ARP) && (!defined(KERNEL_RFC5227) || defined(ARPING))
1318d36e1dfSRoy Marples static void dhcp_arp_found(struct arp_state *, const struct arp_msg *);
1327827cba2SAaron LI #endif
1337827cba2SAaron LI static void dhcp_handledhcp(struct interface *, struct bootp *, size_t,
1347827cba2SAaron LI     const struct in_addr *);
13580aa9461SRoy Marples static void dhcp_handleifudp(void *, unsigned short);
1367827cba2SAaron LI static int dhcp_initstate(struct interface *);
1377827cba2SAaron LI 
1387827cba2SAaron LI void
dhcp_printoptions(const struct dhcpcd_ctx * ctx,const struct dhcp_opt * opts,size_t opts_len)1397827cba2SAaron LI dhcp_printoptions(const struct dhcpcd_ctx *ctx,
1407827cba2SAaron LI     const struct dhcp_opt *opts, size_t opts_len)
1417827cba2SAaron LI {
1427827cba2SAaron LI 	const char * const *p;
1437827cba2SAaron LI 	size_t i, j;
1447827cba2SAaron LI 	const struct dhcp_opt *opt, *opt2;
1457827cba2SAaron LI 	int cols;
1467827cba2SAaron LI 
1477827cba2SAaron LI 	for (p = dhcp_params; *p; p++)
1487827cba2SAaron LI 		printf("    %s\n", *p);
1497827cba2SAaron LI 
1507827cba2SAaron LI 	for (i = 0, opt = ctx->dhcp_opts; i < ctx->dhcp_opts_len; i++, opt++) {
1517827cba2SAaron LI 		for (j = 0, opt2 = opts; j < opts_len; j++, opt2++)
1527827cba2SAaron LI 			if (opt->option == opt2->option)
1537827cba2SAaron LI 				break;
1547827cba2SAaron LI 		if (j == opts_len) {
1557827cba2SAaron LI 			cols = printf("%03d %s", opt->option, opt->var);
1567827cba2SAaron LI 			dhcp_print_option_encoding(opt, cols);
1577827cba2SAaron LI 		}
1587827cba2SAaron LI 	}
1597827cba2SAaron LI 	for (i = 0, opt = opts; i < opts_len; i++, opt++) {
1607827cba2SAaron LI 		cols = printf("%03d %s", opt->option, opt->var);
1617827cba2SAaron LI 		dhcp_print_option_encoding(opt, cols);
1627827cba2SAaron LI 	}
1637827cba2SAaron LI }
1647827cba2SAaron LI 
1657827cba2SAaron LI static const uint8_t *
get_option(struct dhcpcd_ctx * ctx,const struct bootp * bootp,size_t bootp_len,unsigned int opt,size_t * opt_len)1667827cba2SAaron LI get_option(struct dhcpcd_ctx *ctx,
1677827cba2SAaron LI     const struct bootp *bootp, size_t bootp_len,
1687827cba2SAaron LI     unsigned int opt, size_t *opt_len)
1697827cba2SAaron LI {
1707827cba2SAaron LI 	const uint8_t *p, *e;
1717827cba2SAaron LI 	uint8_t l, o, ol, overl, *bp;
1727827cba2SAaron LI 	const uint8_t *op;
1737827cba2SAaron LI 	size_t bl;
1747827cba2SAaron LI 
175ce6cc02eSRoy Marples 	if (bootp == NULL || bootp_len < DHCP_MIN_LEN) {
176ce6cc02eSRoy Marples 		errno = EINVAL;
177ce6cc02eSRoy Marples 		return NULL;
178ce6cc02eSRoy Marples 	}
179ce6cc02eSRoy Marples 
1807827cba2SAaron LI 	/* Check we have the magic cookie */
1817827cba2SAaron LI 	if (!IS_DHCP(bootp)) {
1827827cba2SAaron LI 		errno = ENOTSUP;
1837827cba2SAaron LI 		return NULL;
1847827cba2SAaron LI 	}
1857827cba2SAaron LI 
1867827cba2SAaron LI 	p = bootp->vend + 4; /* options after the 4 byte cookie */
1877827cba2SAaron LI 	e = (const uint8_t *)bootp + bootp_len;
1887827cba2SAaron LI 	ol = o = overl = 0;
1897827cba2SAaron LI 	bp = NULL;
1907827cba2SAaron LI 	op = NULL;
1917827cba2SAaron LI 	bl = 0;
1927827cba2SAaron LI 	while (p < e) {
1937827cba2SAaron LI 		o = *p++;
1947827cba2SAaron LI 		switch (o) {
1957827cba2SAaron LI 		case DHO_PAD:
1967827cba2SAaron LI 			/* No length to read */
1977827cba2SAaron LI 			continue;
1987827cba2SAaron LI 		case DHO_END:
1997827cba2SAaron LI 			if (overl & 1) {
2007827cba2SAaron LI 				/* bit 1 set means parse boot file */
2017827cba2SAaron LI 				overl = (uint8_t)(overl & ~1);
2027827cba2SAaron LI 				p = bootp->file;
2037827cba2SAaron LI 				e = p + sizeof(bootp->file);
2047827cba2SAaron LI 			} else if (overl & 2) {
2057827cba2SAaron LI 				/* bit 2 set means parse server name */
2067827cba2SAaron LI 				overl = (uint8_t)(overl & ~2);
2077827cba2SAaron LI 				p = bootp->sname;
2087827cba2SAaron LI 				e = p + sizeof(bootp->sname);
2097827cba2SAaron LI 			} else
2107827cba2SAaron LI 				goto exit;
2117827cba2SAaron LI 			/* No length to read */
2127827cba2SAaron LI 			continue;
2137827cba2SAaron LI 		}
2147827cba2SAaron LI 
2157827cba2SAaron LI 		/* Check we can read the length */
2167827cba2SAaron LI 		if (p == e) {
2177827cba2SAaron LI 			errno = EINVAL;
2187827cba2SAaron LI 			return NULL;
2197827cba2SAaron LI 		}
2207827cba2SAaron LI 		l = *p++;
2217827cba2SAaron LI 
2228d36e1dfSRoy Marples 		/* Check we can read the option data, if present */
2238d36e1dfSRoy Marples 		if (p + l > e) {
2248d36e1dfSRoy Marples 			errno = EINVAL;
2258d36e1dfSRoy Marples 			return NULL;
2268d36e1dfSRoy Marples 		}
2278d36e1dfSRoy Marples 
2287827cba2SAaron LI 		if (o == DHO_OPTSOVERLOADED) {
2297827cba2SAaron LI 			/* Ensure we only get this option once by setting
2307827cba2SAaron LI 			 * the last bit as well as the value.
2317827cba2SAaron LI 			 * This is valid because only the first two bits
2327827cba2SAaron LI 			 * actually mean anything in RFC2132 Section 9.3 */
2337827cba2SAaron LI 			if (l == 1 && !overl)
2347827cba2SAaron LI 				overl = 0x80 | p[0];
2357827cba2SAaron LI 		}
2367827cba2SAaron LI 
2377827cba2SAaron LI 		if (o == opt) {
2387827cba2SAaron LI 			if (op) {
2397827cba2SAaron LI 				/* We must concatonate the options. */
2407827cba2SAaron LI 				if (bl + l > ctx->opt_buffer_len) {
2417827cba2SAaron LI 					size_t pos;
2427827cba2SAaron LI 					uint8_t *nb;
2437827cba2SAaron LI 
2447827cba2SAaron LI 					if (bp)
2457827cba2SAaron LI 						pos = (size_t)
2467827cba2SAaron LI 						    (bp - ctx->opt_buffer);
2477827cba2SAaron LI 					else
2487827cba2SAaron LI 						pos = 0;
2497827cba2SAaron LI 					nb = realloc(ctx->opt_buffer, bl + l);
2507827cba2SAaron LI 					if (nb == NULL)
2517827cba2SAaron LI 						return NULL;
2527827cba2SAaron LI 					ctx->opt_buffer = nb;
2537827cba2SAaron LI 					ctx->opt_buffer_len = bl + l;
2547827cba2SAaron LI 					bp = ctx->opt_buffer + pos;
2557827cba2SAaron LI 				}
2567827cba2SAaron LI 				if (bp == NULL)
2577827cba2SAaron LI 					bp = ctx->opt_buffer;
2587827cba2SAaron LI 				memcpy(bp, op, ol);
2597827cba2SAaron LI 				bp += ol;
2607827cba2SAaron LI 			}
2617827cba2SAaron LI 			ol = l;
2627827cba2SAaron LI 			op = p;
2637827cba2SAaron LI 			bl += ol;
2647827cba2SAaron LI 		}
2657827cba2SAaron LI 		p += l;
2667827cba2SAaron LI 	}
2677827cba2SAaron LI 
2687827cba2SAaron LI exit:
2697827cba2SAaron LI 	if (opt_len)
2707827cba2SAaron LI 		*opt_len = bl;
2717827cba2SAaron LI 	if (bp) {
2727827cba2SAaron LI 		memcpy(bp, op, ol);
2737827cba2SAaron LI 		return (const uint8_t *)ctx->opt_buffer;
2747827cba2SAaron LI 	}
2757827cba2SAaron LI 	if (op)
2767827cba2SAaron LI 		return op;
2777827cba2SAaron LI 	errno = ENOENT;
2787827cba2SAaron LI 	return NULL;
2797827cba2SAaron LI }
2807827cba2SAaron LI 
2817827cba2SAaron LI static int
get_option_addr(struct dhcpcd_ctx * ctx,struct in_addr * a,const struct bootp * bootp,size_t bootp_len,uint8_t option)2827827cba2SAaron LI get_option_addr(struct dhcpcd_ctx *ctx,
2837827cba2SAaron LI     struct in_addr *a, const struct bootp *bootp, size_t bootp_len,
2847827cba2SAaron LI     uint8_t option)
2857827cba2SAaron LI {
2867827cba2SAaron LI 	const uint8_t *p;
2877827cba2SAaron LI 	size_t len;
2887827cba2SAaron LI 
2897827cba2SAaron LI 	p = get_option(ctx, bootp, bootp_len, option, &len);
2907827cba2SAaron LI 	if (!p || len < (ssize_t)sizeof(a->s_addr))
2917827cba2SAaron LI 		return -1;
2927827cba2SAaron LI 	memcpy(&a->s_addr, p, sizeof(a->s_addr));
2937827cba2SAaron LI 	return 0;
2947827cba2SAaron LI }
2957827cba2SAaron LI 
2967827cba2SAaron LI static int
get_option_uint32(struct dhcpcd_ctx * ctx,uint32_t * i,const struct bootp * bootp,size_t bootp_len,uint8_t option)2977827cba2SAaron LI get_option_uint32(struct dhcpcd_ctx *ctx,
2987827cba2SAaron LI     uint32_t *i, const struct bootp *bootp, size_t bootp_len, uint8_t option)
2997827cba2SAaron LI {
3007827cba2SAaron LI 	const uint8_t *p;
3017827cba2SAaron LI 	size_t len;
3027827cba2SAaron LI 	uint32_t d;
3037827cba2SAaron LI 
3047827cba2SAaron LI 	p = get_option(ctx, bootp, bootp_len, option, &len);
3057827cba2SAaron LI 	if (!p || len < (ssize_t)sizeof(d))
3067827cba2SAaron LI 		return -1;
3077827cba2SAaron LI 	memcpy(&d, p, sizeof(d));
3087827cba2SAaron LI 	if (i)
3097827cba2SAaron LI 		*i = ntohl(d);
3107827cba2SAaron LI 	return 0;
3117827cba2SAaron LI }
3127827cba2SAaron LI 
3137827cba2SAaron LI static int
get_option_uint16(struct dhcpcd_ctx * ctx,uint16_t * i,const struct bootp * bootp,size_t bootp_len,uint8_t option)3147827cba2SAaron LI get_option_uint16(struct dhcpcd_ctx *ctx,
3157827cba2SAaron LI     uint16_t *i, const struct bootp *bootp, size_t bootp_len, uint8_t option)
3167827cba2SAaron LI {
3177827cba2SAaron LI 	const uint8_t *p;
3187827cba2SAaron LI 	size_t len;
3197827cba2SAaron LI 	uint16_t d;
3207827cba2SAaron LI 
3217827cba2SAaron LI 	p = get_option(ctx, bootp, bootp_len, option, &len);
3227827cba2SAaron LI 	if (!p || len < (ssize_t)sizeof(d))
3237827cba2SAaron LI 		return -1;
3247827cba2SAaron LI 	memcpy(&d, p, sizeof(d));
3257827cba2SAaron LI 	if (i)
3267827cba2SAaron LI 		*i = ntohs(d);
3277827cba2SAaron LI 	return 0;
3287827cba2SAaron LI }
3297827cba2SAaron LI 
3307827cba2SAaron LI static int
get_option_uint8(struct dhcpcd_ctx * ctx,uint8_t * i,const struct bootp * bootp,size_t bootp_len,uint8_t option)3317827cba2SAaron LI get_option_uint8(struct dhcpcd_ctx *ctx,
3327827cba2SAaron LI     uint8_t *i, const struct bootp *bootp, size_t bootp_len, uint8_t option)
3337827cba2SAaron LI {
3347827cba2SAaron LI 	const uint8_t *p;
3357827cba2SAaron LI 	size_t len;
3367827cba2SAaron LI 
3377827cba2SAaron LI 	p = get_option(ctx, bootp, bootp_len, option, &len);
3387827cba2SAaron LI 	if (!p || len < (ssize_t)sizeof(*p))
3397827cba2SAaron LI 		return -1;
3407827cba2SAaron LI 	if (i)
3417827cba2SAaron LI 		*i = *(p);
3427827cba2SAaron LI 	return 0;
3437827cba2SAaron LI }
3447827cba2SAaron LI 
3457827cba2SAaron LI ssize_t
print_rfc3442(FILE * fp,const uint8_t * data,size_t data_len)3468d36e1dfSRoy Marples print_rfc3442(FILE *fp, const uint8_t *data, size_t data_len)
3477827cba2SAaron LI {
3488d36e1dfSRoy Marples 	const uint8_t *p = data, *e;
3498d36e1dfSRoy Marples 	size_t ocets;
3507827cba2SAaron LI 	uint8_t cidr;
3517827cba2SAaron LI 	struct in_addr addr;
3527827cba2SAaron LI 
3537827cba2SAaron LI 	/* Minimum is 5 -first is CIDR and a router length of 4 */
3548d36e1dfSRoy Marples 	if (data_len < 5) {
3557827cba2SAaron LI 		errno = EINVAL;
3567827cba2SAaron LI 		return -1;
3577827cba2SAaron LI 	}
3587827cba2SAaron LI 
3598d36e1dfSRoy Marples 	e = p + data_len;
3607827cba2SAaron LI 	while (p < e) {
3618d36e1dfSRoy Marples 		if (p != data) {
3628d36e1dfSRoy Marples 			if (fputc(' ', fp) == EOF)
3638d36e1dfSRoy Marples 				return -1;
3648d36e1dfSRoy Marples 		}
3657827cba2SAaron LI 		cidr = *p++;
3667827cba2SAaron LI 		if (cidr > 32) {
3677827cba2SAaron LI 			errno = EINVAL;
3687827cba2SAaron LI 			return -1;
3697827cba2SAaron LI 		}
3707827cba2SAaron LI 		ocets = (size_t)(cidr + 7) / NBBY;
3717827cba2SAaron LI 		if (p + 4 + ocets > e) {
3727827cba2SAaron LI 			errno = ERANGE;
3737827cba2SAaron LI 			return -1;
3747827cba2SAaron LI 		}
3757827cba2SAaron LI 		/* If we have ocets then we have a destination and netmask */
3767827cba2SAaron LI 		addr.s_addr = 0;
3778d36e1dfSRoy Marples 		if (ocets > 0) {
3787827cba2SAaron LI 			memcpy(&addr.s_addr, p, ocets);
3797827cba2SAaron LI 			p += ocets;
3808d36e1dfSRoy Marples 		}
3818d36e1dfSRoy Marples 		if (fprintf(fp, "%s/%d", inet_ntoa(addr), cidr) == -1)
3828d36e1dfSRoy Marples 			return -1;
3837827cba2SAaron LI 
3847827cba2SAaron LI 		/* Finally, snag the router */
3857827cba2SAaron LI 		memcpy(&addr.s_addr, p, 4);
3867827cba2SAaron LI 		p += 4;
3878d36e1dfSRoy Marples 		if (fprintf(fp, " %s", inet_ntoa(addr)) == -1)
3888d36e1dfSRoy Marples 			return -1;
3897827cba2SAaron LI 	}
3907827cba2SAaron LI 
3918d36e1dfSRoy Marples 	if (fputc('\0', fp) == EOF)
3928d36e1dfSRoy Marples 		return -1;
3938d36e1dfSRoy Marples 	return 1;
3947827cba2SAaron LI }
3957827cba2SAaron LI 
3967827cba2SAaron LI static int
decode_rfc3442_rt(rb_tree_t * routes,struct interface * ifp,const uint8_t * data,size_t dl)3978d36e1dfSRoy Marples decode_rfc3442_rt(rb_tree_t *routes, struct interface *ifp,
39880aa9461SRoy Marples     const uint8_t *data, size_t dl)
3997827cba2SAaron LI {
4007827cba2SAaron LI 	const uint8_t *p = data;
4017827cba2SAaron LI 	const uint8_t *e;
4027827cba2SAaron LI 	uint8_t cidr;
4037827cba2SAaron LI 	size_t ocets;
4047827cba2SAaron LI 	struct rt *rt = NULL;
4057827cba2SAaron LI 	struct in_addr dest, netmask, gateway;
4067827cba2SAaron LI 	int n;
4077827cba2SAaron LI 
4087827cba2SAaron LI 	/* Minimum is 5 -first is CIDR and a router length of 4 */
4097827cba2SAaron LI 	if (dl < 5) {
4107827cba2SAaron LI 		errno = EINVAL;
4117827cba2SAaron LI 		return -1;
4127827cba2SAaron LI 	}
4137827cba2SAaron LI 
4147827cba2SAaron LI 	n = 0;
4157827cba2SAaron LI 	e = p + dl;
4167827cba2SAaron LI 	while (p < e) {
4177827cba2SAaron LI 		cidr = *p++;
4187827cba2SAaron LI 		if (cidr > 32) {
4197827cba2SAaron LI 			errno = EINVAL;
4207827cba2SAaron LI 			return -1;
4217827cba2SAaron LI 		}
4227827cba2SAaron LI 
4237827cba2SAaron LI 		ocets = (size_t)(cidr + 7) / NBBY;
4247827cba2SAaron LI 		if (p + 4 + ocets > e) {
4257827cba2SAaron LI 			errno = ERANGE;
4267827cba2SAaron LI 			return -1;
4277827cba2SAaron LI 		}
4287827cba2SAaron LI 
4297827cba2SAaron LI 		if ((rt = rt_new(ifp)) == NULL)
4307827cba2SAaron LI 			return -1;
4317827cba2SAaron LI 
4327827cba2SAaron LI 		/* If we have ocets then we have a destination and netmask */
4337827cba2SAaron LI 		dest.s_addr = 0;
4347827cba2SAaron LI 		if (ocets > 0) {
4357827cba2SAaron LI 			memcpy(&dest.s_addr, p, ocets);
4367827cba2SAaron LI 			p += ocets;
4377827cba2SAaron LI 			netmask.s_addr = htonl(~0U << (32 - cidr));
4387827cba2SAaron LI 		} else
4397827cba2SAaron LI 			netmask.s_addr = 0;
4407827cba2SAaron LI 
4417827cba2SAaron LI 		/* Finally, snag the router */
4427827cba2SAaron LI 		memcpy(&gateway.s_addr, p, 4);
4437827cba2SAaron LI 		p += 4;
4447827cba2SAaron LI 
4458d36e1dfSRoy Marples 		if (netmask.s_addr == INADDR_BROADCAST)
4468d36e1dfSRoy Marples 			rt->rt_flags = RTF_HOST;
4477827cba2SAaron LI 
4487827cba2SAaron LI 		sa_in_init(&rt->rt_dest, &dest);
4497827cba2SAaron LI 		sa_in_init(&rt->rt_netmask, &netmask);
4507827cba2SAaron LI 		sa_in_init(&rt->rt_gateway, &gateway);
4518d36e1dfSRoy Marples 		if (rt_proto_add(routes, rt))
4528d36e1dfSRoy Marples 			n = 1;
4537827cba2SAaron LI 	}
4547827cba2SAaron LI 	return n;
4557827cba2SAaron LI }
4567827cba2SAaron LI 
4578d36e1dfSRoy Marples ssize_t
print_rfc3361(FILE * fp,const uint8_t * data,size_t dl)4588d36e1dfSRoy Marples print_rfc3361(FILE *fp, const uint8_t *data, size_t dl)
4597827cba2SAaron LI {
4607827cba2SAaron LI 	uint8_t enc;
4618d36e1dfSRoy Marples 	char sip[NS_MAXDNAME];
4627827cba2SAaron LI 	struct in_addr addr;
4637827cba2SAaron LI 
4647827cba2SAaron LI 	if (dl < 2) {
4657827cba2SAaron LI 		errno = EINVAL;
4667827cba2SAaron LI 		return 0;
4677827cba2SAaron LI 	}
4687827cba2SAaron LI 
4697827cba2SAaron LI 	enc = *data++;
4707827cba2SAaron LI 	dl--;
4717827cba2SAaron LI 	switch (enc) {
4727827cba2SAaron LI 	case 0:
4738d36e1dfSRoy Marples 		if (decode_rfc1035(sip, sizeof(sip), data, dl) == -1)
4748d36e1dfSRoy Marples 			return -1;
4758d36e1dfSRoy Marples 		if (efprintf(fp, "%s", sip) == -1)
4768d36e1dfSRoy Marples 			return -1;
4777827cba2SAaron LI 		break;
4787827cba2SAaron LI 	case 1:
479ce6cc02eSRoy Marples 		if (dl % 4 != 0) {
4807827cba2SAaron LI 			errno = EINVAL;
4817827cba2SAaron LI 			break;
4827827cba2SAaron LI 		}
4837827cba2SAaron LI 		addr.s_addr = INADDR_BROADCAST;
4848d36e1dfSRoy Marples 		for (;
4858d36e1dfSRoy Marples 		    dl != 0;
4868d36e1dfSRoy Marples 		    data += sizeof(addr.s_addr), dl -= sizeof(addr.s_addr))
4878d36e1dfSRoy Marples 		{
4887827cba2SAaron LI 			memcpy(&addr.s_addr, data, sizeof(addr.s_addr));
4898d36e1dfSRoy Marples 			if (fprintf(fp, "%s", inet_ntoa(addr)) == -1)
4908d36e1dfSRoy Marples 				return -1;
491d4fb1e02SRoy Marples 			if (dl != sizeof(addr.s_addr)) {
4928d36e1dfSRoy Marples 				if (fputc(' ', fp) == EOF)
4938d36e1dfSRoy Marples 					return -1;
4947827cba2SAaron LI 			}
4958d36e1dfSRoy Marples 		}
4968d36e1dfSRoy Marples 		if (fputc('\0', fp) == EOF)
4978d36e1dfSRoy Marples 			return -1;
4987827cba2SAaron LI 		break;
4997827cba2SAaron LI 	default:
5007827cba2SAaron LI 		errno = EINVAL;
5017827cba2SAaron LI 		return 0;
5027827cba2SAaron LI 	}
5037827cba2SAaron LI 
5048d36e1dfSRoy Marples 	return 1;
5057827cba2SAaron LI }
5067827cba2SAaron LI 
5077827cba2SAaron LI static char *
get_option_string(struct dhcpcd_ctx * ctx,const struct bootp * bootp,size_t bootp_len,uint8_t option)5087827cba2SAaron LI get_option_string(struct dhcpcd_ctx *ctx,
5097827cba2SAaron LI     const struct bootp *bootp, size_t bootp_len, uint8_t option)
5107827cba2SAaron LI {
5117827cba2SAaron LI 	size_t len;
5127827cba2SAaron LI 	const uint8_t *p;
5137827cba2SAaron LI 	char *s;
5147827cba2SAaron LI 
5157827cba2SAaron LI 	p = get_option(ctx, bootp, bootp_len, option, &len);
5167827cba2SAaron LI 	if (!p || len == 0 || *p == '\0')
5177827cba2SAaron LI 		return NULL;
5187827cba2SAaron LI 
5197827cba2SAaron LI 	s = malloc(sizeof(char) * (len + 1));
5207827cba2SAaron LI 	if (s) {
5217827cba2SAaron LI 		memcpy(s, p, len);
5227827cba2SAaron LI 		s[len] = '\0';
5237827cba2SAaron LI 	}
5247827cba2SAaron LI 	return s;
5257827cba2SAaron LI }
5267827cba2SAaron LI 
5277827cba2SAaron LI /* This calculates the netmask that we should use for static routes.
5287827cba2SAaron LI  * This IS different from the calculation used to calculate the netmask
5297827cba2SAaron LI  * for an interface address. */
5307827cba2SAaron LI static uint32_t
route_netmask(uint32_t ip_in)5317827cba2SAaron LI route_netmask(uint32_t ip_in)
5327827cba2SAaron LI {
5337827cba2SAaron LI 	/* used to be unsigned long - check if error */
5347827cba2SAaron LI 	uint32_t p = ntohl(ip_in);
5357827cba2SAaron LI 	uint32_t t;
5367827cba2SAaron LI 
5377827cba2SAaron LI 	if (IN_CLASSA(p))
5387827cba2SAaron LI 		t = ~IN_CLASSA_NET;
5397827cba2SAaron LI 	else {
5407827cba2SAaron LI 		if (IN_CLASSB(p))
5417827cba2SAaron LI 			t = ~IN_CLASSB_NET;
5427827cba2SAaron LI 		else {
5437827cba2SAaron LI 			if (IN_CLASSC(p))
5447827cba2SAaron LI 				t = ~IN_CLASSC_NET;
5457827cba2SAaron LI 			else
5467827cba2SAaron LI 				t = 0;
5477827cba2SAaron LI 		}
5487827cba2SAaron LI 	}
5497827cba2SAaron LI 
5507827cba2SAaron LI 	while (t & p)
5517827cba2SAaron LI 		t >>= 1;
5527827cba2SAaron LI 
5537827cba2SAaron LI 	return (htonl(~t));
5547827cba2SAaron LI }
5557827cba2SAaron LI 
5567827cba2SAaron LI /* We need to obey routing options.
5577827cba2SAaron LI  * If we have a CSR then we only use that.
5587827cba2SAaron LI  * Otherwise we add static routes and then routers. */
5597827cba2SAaron LI static int
get_option_routes(rb_tree_t * routes,struct interface * ifp,const struct bootp * bootp,size_t bootp_len)5608d36e1dfSRoy Marples get_option_routes(rb_tree_t *routes, struct interface *ifp,
5617827cba2SAaron LI     const struct bootp *bootp, size_t bootp_len)
5627827cba2SAaron LI {
5637827cba2SAaron LI 	struct if_options *ifo = ifp->options;
5647827cba2SAaron LI 	const uint8_t *p;
5657827cba2SAaron LI 	const uint8_t *e;
5667827cba2SAaron LI 	struct rt *rt = NULL;
5677827cba2SAaron LI 	struct in_addr dest, netmask, gateway;
5687827cba2SAaron LI 	size_t len;
5697827cba2SAaron LI 	const char *csr = "";
5707827cba2SAaron LI 	int n;
5717827cba2SAaron LI 
5727827cba2SAaron LI 	/* If we have CSR's then we MUST use these only */
5737827cba2SAaron LI 	if (!has_option_mask(ifo->nomask, DHO_CSR))
5747827cba2SAaron LI 		p = get_option(ifp->ctx, bootp, bootp_len, DHO_CSR, &len);
5757827cba2SAaron LI 	else
5767827cba2SAaron LI 		p = NULL;
5777827cba2SAaron LI 	/* Check for crappy MS option */
5787827cba2SAaron LI 	if (!p && !has_option_mask(ifo->nomask, DHO_MSCSR)) {
5797827cba2SAaron LI 		p = get_option(ifp->ctx, bootp, bootp_len, DHO_MSCSR, &len);
5807827cba2SAaron LI 		if (p)
5817827cba2SAaron LI 			csr = "MS ";
5827827cba2SAaron LI 	}
58380aa9461SRoy Marples 	if (p && (n = decode_rfc3442_rt(routes, ifp, p, len)) != -1) {
5847827cba2SAaron LI 		const struct dhcp_state *state;
5857827cba2SAaron LI 
5867827cba2SAaron LI 		state = D_CSTATE(ifp);
5877827cba2SAaron LI 		if (!(ifo->options & DHCPCD_CSR_WARNED) &&
5887827cba2SAaron LI 		    !(state->added & STATE_FAKE))
5897827cba2SAaron LI 		{
5907827cba2SAaron LI 			logdebugx("%s: using %sClassless Static Routes",
5917827cba2SAaron LI 			    ifp->name, csr);
5927827cba2SAaron LI 			ifo->options |= DHCPCD_CSR_WARNED;
5937827cba2SAaron LI 		}
5947827cba2SAaron LI 		return n;
5957827cba2SAaron LI 	}
5967827cba2SAaron LI 
5977827cba2SAaron LI 	n = 0;
5987827cba2SAaron LI 	/* OK, get our static routes first. */
5997827cba2SAaron LI 	if (!has_option_mask(ifo->nomask, DHO_STATICROUTE))
6007827cba2SAaron LI 		p = get_option(ifp->ctx, bootp, bootp_len,
6017827cba2SAaron LI 		    DHO_STATICROUTE, &len);
6027827cba2SAaron LI 	else
6037827cba2SAaron LI 		p = NULL;
6047827cba2SAaron LI 	/* RFC 2131 Section 5.8 states length MUST be in multiples of 8 */
6057827cba2SAaron LI 	if (p && len % 8 == 0) {
6067827cba2SAaron LI 		e = p + len;
6077827cba2SAaron LI 		while (p < e) {
6087827cba2SAaron LI 			memcpy(&dest.s_addr, p, sizeof(dest.s_addr));
6097827cba2SAaron LI 			p += 4;
6107827cba2SAaron LI 			memcpy(&gateway.s_addr, p, sizeof(gateway.s_addr));
6117827cba2SAaron LI 			p += 4;
6127827cba2SAaron LI 			/* RFC 2131 Section 5.8 states default route is
6137827cba2SAaron LI 			 * illegal */
6147827cba2SAaron LI 			if (gateway.s_addr == INADDR_ANY)
6157827cba2SAaron LI 				continue;
6167827cba2SAaron LI 			if ((rt = rt_new(ifp)) == NULL)
6177827cba2SAaron LI 				return -1;
6187827cba2SAaron LI 
6198d36e1dfSRoy Marples 			/* A on-link host route is normally set by having the
6207827cba2SAaron LI 			 * gateway match the destination or assigned address */
6217827cba2SAaron LI 			if (gateway.s_addr == dest.s_addr ||
6227827cba2SAaron LI 			     (gateway.s_addr == bootp->yiaddr ||
6237827cba2SAaron LI 			      gateway.s_addr == bootp->ciaddr))
6247827cba2SAaron LI 			{
6257827cba2SAaron LI 				gateway.s_addr = INADDR_ANY;
6267827cba2SAaron LI 				netmask.s_addr = INADDR_BROADCAST;
6277827cba2SAaron LI 			} else
6287827cba2SAaron LI 				netmask.s_addr = route_netmask(dest.s_addr);
6298d36e1dfSRoy Marples 			if (netmask.s_addr == INADDR_BROADCAST)
6308d36e1dfSRoy Marples 				rt->rt_flags = RTF_HOST;
6318d36e1dfSRoy Marples 
6327827cba2SAaron LI 			sa_in_init(&rt->rt_dest, &dest);
6337827cba2SAaron LI 			sa_in_init(&rt->rt_netmask, &netmask);
6347827cba2SAaron LI 			sa_in_init(&rt->rt_gateway, &gateway);
6358d36e1dfSRoy Marples 			if (rt_proto_add(routes, rt))
6367827cba2SAaron LI 				n++;
6377827cba2SAaron LI 		}
6387827cba2SAaron LI 	}
6397827cba2SAaron LI 
6407827cba2SAaron LI 	/* Now grab our routers */
6417827cba2SAaron LI 	if (!has_option_mask(ifo->nomask, DHO_ROUTER))
6427827cba2SAaron LI 		p = get_option(ifp->ctx, bootp, bootp_len, DHO_ROUTER, &len);
6437827cba2SAaron LI 	else
6447827cba2SAaron LI 		p = NULL;
6458d36e1dfSRoy Marples 	if (p && len % 4 == 0) {
6467827cba2SAaron LI 		e = p + len;
6477827cba2SAaron LI 		dest.s_addr = INADDR_ANY;
6487827cba2SAaron LI 		netmask.s_addr = INADDR_ANY;
6497827cba2SAaron LI 		while (p < e) {
6507827cba2SAaron LI 			if ((rt = rt_new(ifp)) == NULL)
6517827cba2SAaron LI 				return -1;
6527827cba2SAaron LI 			memcpy(&gateway.s_addr, p, sizeof(gateway.s_addr));
6537827cba2SAaron LI 			p += 4;
6547827cba2SAaron LI 			sa_in_init(&rt->rt_dest, &dest);
6557827cba2SAaron LI 			sa_in_init(&rt->rt_netmask, &netmask);
6567827cba2SAaron LI 			sa_in_init(&rt->rt_gateway, &gateway);
6578d36e1dfSRoy Marples 			if (rt_proto_add(routes, rt))
6587827cba2SAaron LI 				n++;
6597827cba2SAaron LI 		}
6607827cba2SAaron LI 	}
6617827cba2SAaron LI 
6627827cba2SAaron LI 	return n;
6637827cba2SAaron LI }
6647827cba2SAaron LI 
6657827cba2SAaron LI uint16_t
dhcp_get_mtu(const struct interface * ifp)6667827cba2SAaron LI dhcp_get_mtu(const struct interface *ifp)
6677827cba2SAaron LI {
6687827cba2SAaron LI 	const struct dhcp_state *state;
6697827cba2SAaron LI 	uint16_t mtu;
6707827cba2SAaron LI 
6717827cba2SAaron LI 	if (ifp->options->mtu)
6727827cba2SAaron LI 		return (uint16_t)ifp->options->mtu;
6737827cba2SAaron LI 	mtu = 0; /* bogus gcc warning */
6747827cba2SAaron LI 	if ((state = D_CSTATE(ifp)) == NULL ||
6757827cba2SAaron LI 	    has_option_mask(ifp->options->nomask, DHO_MTU) ||
6767827cba2SAaron LI 	    get_option_uint16(ifp->ctx, &mtu,
6777827cba2SAaron LI 			      state->new, state->new_len, DHO_MTU) == -1)
6787827cba2SAaron LI 		return 0;
6797827cba2SAaron LI 	return mtu;
6807827cba2SAaron LI }
6817827cba2SAaron LI 
6827827cba2SAaron LI /* Grab our routers from the DHCP message and apply any MTU value
6837827cba2SAaron LI  * the message contains */
6847827cba2SAaron LI int
dhcp_get_routes(rb_tree_t * routes,struct interface * ifp)6858d36e1dfSRoy Marples dhcp_get_routes(rb_tree_t *routes, struct interface *ifp)
6867827cba2SAaron LI {
6877827cba2SAaron LI 	const struct dhcp_state *state;
6887827cba2SAaron LI 
6897827cba2SAaron LI 	if ((state = D_CSTATE(ifp)) == NULL || !(state->added & STATE_ADDED))
6907827cba2SAaron LI 		return 0;
6917827cba2SAaron LI 	return get_option_routes(routes, ifp, state->new, state->new_len);
6927827cba2SAaron LI }
6937827cba2SAaron LI 
6947827cba2SAaron LI /* Assumes DHCP options */
6957827cba2SAaron LI static int
dhcp_message_add_addr(struct bootp * bootp,uint8_t type,struct in_addr addr)6967827cba2SAaron LI dhcp_message_add_addr(struct bootp *bootp,
6977827cba2SAaron LI     uint8_t type, struct in_addr addr)
6987827cba2SAaron LI {
6997827cba2SAaron LI 	uint8_t *p;
7007827cba2SAaron LI 	size_t len;
7017827cba2SAaron LI 
7027827cba2SAaron LI 	p = bootp->vend;
7037827cba2SAaron LI 	while (*p != DHO_END) {
7047827cba2SAaron LI 		p++;
7057827cba2SAaron LI 		p += *p + 1;
7067827cba2SAaron LI 	}
7077827cba2SAaron LI 
7087827cba2SAaron LI 	len = (size_t)(p - bootp->vend);
7097827cba2SAaron LI 	if (len + 6 > sizeof(bootp->vend)) {
7107827cba2SAaron LI 		errno = ENOMEM;
7117827cba2SAaron LI 		return -1;
7127827cba2SAaron LI 	}
7137827cba2SAaron LI 
7147827cba2SAaron LI 	*p++ = type;
7157827cba2SAaron LI 	*p++ = 4;
7167827cba2SAaron LI 	memcpy(p, &addr.s_addr, 4);
7177827cba2SAaron LI 	p += 4;
7187827cba2SAaron LI 	*p = DHO_END;
7197827cba2SAaron LI 	return 0;
7207827cba2SAaron LI }
7217827cba2SAaron LI 
7227827cba2SAaron LI static ssize_t
make_message(struct bootp ** bootpm,const struct interface * ifp,uint8_t type)7237827cba2SAaron LI make_message(struct bootp **bootpm, const struct interface *ifp, uint8_t type)
7247827cba2SAaron LI {
7257827cba2SAaron LI 	struct bootp *bootp;
7267827cba2SAaron LI 	uint8_t *lp, *p, *e;
7277827cba2SAaron LI 	uint8_t *n_params = NULL;
7287827cba2SAaron LI 	uint32_t ul;
7297827cba2SAaron LI 	uint16_t sz;
7307827cba2SAaron LI 	size_t len, i;
7317827cba2SAaron LI 	const struct dhcp_opt *opt;
7327827cba2SAaron LI 	struct if_options *ifo = ifp->options;
7337827cba2SAaron LI 	const struct dhcp_state *state = D_CSTATE(ifp);
7347827cba2SAaron LI 	const struct dhcp_lease *lease = &state->lease;
7357827cba2SAaron LI 	char hbuf[HOSTNAME_MAX_LEN + 1];
7367827cba2SAaron LI 	const char *hostname;
7377827cba2SAaron LI 	const struct vivco *vivco;
7387827cba2SAaron LI 	int mtu;
7397827cba2SAaron LI #ifdef AUTH
7407827cba2SAaron LI 	uint8_t *auth, auth_len;
7417827cba2SAaron LI #endif
7427827cba2SAaron LI 
7437827cba2SAaron LI 	if ((mtu = if_getmtu(ifp)) == -1)
7447827cba2SAaron LI 		logerr("%s: if_getmtu", ifp->name);
7457827cba2SAaron LI 	else if (mtu < MTU_MIN) {
7467827cba2SAaron LI 		if (if_setmtu(ifp, MTU_MIN) == -1)
7477827cba2SAaron LI 			logerr("%s: if_setmtu", ifp->name);
7487827cba2SAaron LI 		mtu = MTU_MIN;
7497827cba2SAaron LI 	}
7507827cba2SAaron LI 
7517827cba2SAaron LI 	if (ifo->options & DHCPCD_BOOTP)
7527827cba2SAaron LI 		bootp = calloc(1, sizeof (*bootp));
7537827cba2SAaron LI 	else
7547827cba2SAaron LI 		/* Make the maximal message we could send */
7557827cba2SAaron LI 		bootp = calloc(1, (size_t)(mtu - IP_UDP_SIZE));
7567827cba2SAaron LI 
7577827cba2SAaron LI 	if (bootp == NULL)
7587827cba2SAaron LI 		return -1;
7597827cba2SAaron LI 	*bootpm = bootp;
7607827cba2SAaron LI 
7617827cba2SAaron LI 	if (state->addr != NULL &&
7627827cba2SAaron LI 	    (type == DHCP_INFORM || type == DHCP_RELEASE ||
7637827cba2SAaron LI 	    (type == DHCP_REQUEST &&
7647827cba2SAaron LI 	    state->addr->mask.s_addr == lease->mask.s_addr &&
7657827cba2SAaron LI 	    (state->new == NULL || IS_DHCP(state->new)) &&
766b8b69544SRoy Marples 	    !(state->added & (STATE_FAKE | STATE_EXPIRED)))))
7677827cba2SAaron LI 		bootp->ciaddr = state->addr->addr.s_addr;
7687827cba2SAaron LI 
7697827cba2SAaron LI 	bootp->op = BOOTREQUEST;
770d4fb1e02SRoy Marples 	bootp->htype = (uint8_t)ifp->hwtype;
77180aa9461SRoy Marples 	if (ifp->hwlen != 0 && ifp->hwlen <= sizeof(bootp->chaddr)) {
7727827cba2SAaron LI 		bootp->hlen = (uint8_t)ifp->hwlen;
7737827cba2SAaron LI 		memcpy(&bootp->chaddr, &ifp->hwaddr, ifp->hwlen);
7747827cba2SAaron LI 	}
7757827cba2SAaron LI 
7767827cba2SAaron LI 	if (ifo->options & DHCPCD_BROADCAST &&
7777827cba2SAaron LI 	    bootp->ciaddr == 0 &&
7787827cba2SAaron LI 	    type != DHCP_DECLINE &&
7797827cba2SAaron LI 	    type != DHCP_RELEASE)
7807827cba2SAaron LI 		bootp->flags = htons(BROADCAST_FLAG);
7817827cba2SAaron LI 
7827827cba2SAaron LI 	if (type != DHCP_DECLINE && type != DHCP_RELEASE) {
7837827cba2SAaron LI 		struct timespec tv;
7846e63cc1fSRoy Marples 		unsigned long long secs;
7857827cba2SAaron LI 
7867827cba2SAaron LI 		clock_gettime(CLOCK_MONOTONIC, &tv);
7876e63cc1fSRoy Marples 		secs = eloop_timespec_diff(&tv, &state->started, NULL);
7886e63cc1fSRoy Marples 		if (secs > UINT16_MAX)
7897827cba2SAaron LI 			bootp->secs = htons((uint16_t)UINT16_MAX);
7907827cba2SAaron LI 		else
7916e63cc1fSRoy Marples 			bootp->secs = htons((uint16_t)secs);
7927827cba2SAaron LI 	}
7937827cba2SAaron LI 
7947827cba2SAaron LI 	bootp->xid = htonl(state->xid);
7957827cba2SAaron LI 
7967827cba2SAaron LI 	if (ifo->options & DHCPCD_BOOTP)
7977827cba2SAaron LI 		return sizeof(*bootp);
7987827cba2SAaron LI 
7997827cba2SAaron LI 	p = bootp->vend;
8007827cba2SAaron LI 	e = (uint8_t *)bootp + (mtu - IP_UDP_SIZE) - 1; /* -1 for DHO_END */
8017827cba2SAaron LI 
8027827cba2SAaron LI 	ul = htonl(MAGIC_COOKIE);
8037827cba2SAaron LI 	memcpy(p, &ul, sizeof(ul));
8047827cba2SAaron LI 	p += sizeof(ul);
8057827cba2SAaron LI 
8067827cba2SAaron LI #define AREA_LEFT	(size_t)(e - p)
8077827cba2SAaron LI #define AREA_FIT(s)	if ((s) > AREA_LEFT) goto toobig
8087827cba2SAaron LI #define AREA_CHECK(s)	if ((s) + 2UL > AREA_LEFT) goto toobig
8097827cba2SAaron LI #define PUT_ADDR(o, a)	do {		\
8107827cba2SAaron LI 	AREA_CHECK(4);			\
8117827cba2SAaron LI 	*p++ = (o);			\
8127827cba2SAaron LI 	*p++ = 4;			\
8137827cba2SAaron LI 	memcpy(p, &(a)->s_addr, 4);	\
8147827cba2SAaron LI 	p += 4;				\
8157827cba2SAaron LI } while (0 /* CONSTCOND */)
8167827cba2SAaron LI 
8176e63cc1fSRoy Marples 	/* Options are listed in numerical order as per RFC 7844 Section 3.1
8186e63cc1fSRoy Marples 	 * XXX: They should be randomised. */
8197827cba2SAaron LI 
8206e63cc1fSRoy Marples 	bool putip = false;
8217827cba2SAaron LI 	if (lease->addr.s_addr && lease->cookie == htonl(MAGIC_COOKIE)) {
8227827cba2SAaron LI 		if (type == DHCP_DECLINE ||
8237827cba2SAaron LI 		    (type == DHCP_REQUEST &&
8247827cba2SAaron LI 		    (state->addr == NULL ||
825b8b69544SRoy Marples 		    state->added & (STATE_FAKE | STATE_EXPIRED) ||
8267827cba2SAaron LI 		    lease->addr.s_addr != state->addr->addr.s_addr)))
8277827cba2SAaron LI 		{
8286e63cc1fSRoy Marples 			putip = true;
8297827cba2SAaron LI 			PUT_ADDR(DHO_IPADDRESS, &lease->addr);
8306e63cc1fSRoy Marples 		}
8317827cba2SAaron LI 	}
8327827cba2SAaron LI 
8336e63cc1fSRoy Marples 	AREA_CHECK(3);
8346e63cc1fSRoy Marples 	*p++ = DHO_MESSAGETYPE;
8356e63cc1fSRoy Marples 	*p++ = 1;
8366e63cc1fSRoy Marples 	*p++ = type;
8376e63cc1fSRoy Marples 
8386e63cc1fSRoy Marples 	if (lease->addr.s_addr && lease->cookie == htonl(MAGIC_COOKIE)) {
8396e63cc1fSRoy Marples 		if (type == DHCP_RELEASE || putip) {
8407827cba2SAaron LI 			if (lease->server.s_addr)
8417827cba2SAaron LI 				PUT_ADDR(DHO_SERVERID, &lease->server);
8427827cba2SAaron LI 		}
8437827cba2SAaron LI 	}
8447827cba2SAaron LI 
8457827cba2SAaron LI 	if (type == DHCP_DECLINE) {
8467827cba2SAaron LI 		len = strlen(DAD);
8477827cba2SAaron LI 		if (len > AREA_LEFT) {
8487827cba2SAaron LI 			*p++ = DHO_MESSAGE;
8497827cba2SAaron LI 			*p++ = (uint8_t)len;
8507827cba2SAaron LI 			memcpy(p, DAD, len);
8517827cba2SAaron LI 			p += len;
8527827cba2SAaron LI 		}
8537827cba2SAaron LI 	}
8547827cba2SAaron LI 
8556e63cc1fSRoy Marples #define	DHCP_DIR(type) ((type) == DHCP_DISCOVER || (type) == DHCP_INFORM || \
8566e63cc1fSRoy Marples     (type) == DHCP_REQUEST)
8576e63cc1fSRoy Marples 
8586e63cc1fSRoy Marples 	if (DHCP_DIR(type)) {
8596e63cc1fSRoy Marples 		/* vendor is already encoded correctly, so just add it */
8606e63cc1fSRoy Marples 		if (ifo->vendor[0]) {
8616e63cc1fSRoy Marples 			AREA_CHECK(ifo->vendor[0]);
8626e63cc1fSRoy Marples 			*p++ = DHO_VENDOR;
8636e63cc1fSRoy Marples 			memcpy(p, ifo->vendor, (size_t)ifo->vendor[0] + 1);
8646e63cc1fSRoy Marples 			p += ifo->vendor[0] + 1;
8656e63cc1fSRoy Marples 		}
8667827cba2SAaron LI 	}
8677827cba2SAaron LI 
8687827cba2SAaron LI 	if (type == DHCP_DISCOVER && ifo->options & DHCPCD_REQUEST)
8697827cba2SAaron LI 		PUT_ADDR(DHO_IPADDRESS, &ifo->req_addr);
8707827cba2SAaron LI 
8716e63cc1fSRoy Marples 	if (DHCP_DIR(type)) {
8727827cba2SAaron LI 		if (type != DHCP_INFORM) {
8737827cba2SAaron LI 			if (ifo->leasetime != 0) {
8747827cba2SAaron LI 				AREA_CHECK(4);
8757827cba2SAaron LI 				*p++ = DHO_LEASETIME;
8767827cba2SAaron LI 				*p++ = 4;
8777827cba2SAaron LI 				ul = htonl(ifo->leasetime);
8787827cba2SAaron LI 				memcpy(p, &ul, 4);
8797827cba2SAaron LI 				p += 4;
8807827cba2SAaron LI 			}
8817827cba2SAaron LI 		}
8827827cba2SAaron LI 
8836e63cc1fSRoy Marples 		AREA_CHECK(0);
8846e63cc1fSRoy Marples 		*p++ = DHO_PARAMETERREQUESTLIST;
8856e63cc1fSRoy Marples 		n_params = p;
8866e63cc1fSRoy Marples 		*p++ = 0;
8876e63cc1fSRoy Marples 		for (i = 0, opt = ifp->ctx->dhcp_opts;
8886e63cc1fSRoy Marples 		    i < ifp->ctx->dhcp_opts_len;
8896e63cc1fSRoy Marples 		    i++, opt++)
8906e63cc1fSRoy Marples 		{
8916e63cc1fSRoy Marples 			if (!DHC_REQOPT(opt, ifo->requestmask, ifo->nomask))
8926e63cc1fSRoy Marples 				continue;
8936e63cc1fSRoy Marples 			if (type == DHCP_INFORM &&
8946e63cc1fSRoy Marples 			    (opt->option == DHO_RENEWALTIME ||
8956e63cc1fSRoy Marples 				opt->option == DHO_REBINDTIME))
8966e63cc1fSRoy Marples 				continue;
8976e63cc1fSRoy Marples 			AREA_FIT(1);
8986e63cc1fSRoy Marples 			*p++ = (uint8_t)opt->option;
8996e63cc1fSRoy Marples 		}
9006e63cc1fSRoy Marples 		for (i = 0, opt = ifo->dhcp_override;
9016e63cc1fSRoy Marples 		    i < ifo->dhcp_override_len;
9026e63cc1fSRoy Marples 		    i++, opt++)
9036e63cc1fSRoy Marples 		{
9046e63cc1fSRoy Marples 			/* Check if added above */
9056e63cc1fSRoy Marples 			for (lp = n_params + 1; lp < p; lp++)
9066e63cc1fSRoy Marples 				if (*lp == (uint8_t)opt->option)
9076e63cc1fSRoy Marples 					break;
9086e63cc1fSRoy Marples 			if (lp < p)
9096e63cc1fSRoy Marples 				continue;
9106e63cc1fSRoy Marples 			if (!DHC_REQOPT(opt, ifo->requestmask, ifo->nomask))
9116e63cc1fSRoy Marples 				continue;
9126e63cc1fSRoy Marples 			if (type == DHCP_INFORM &&
9136e63cc1fSRoy Marples 			    (opt->option == DHO_RENEWALTIME ||
9146e63cc1fSRoy Marples 				opt->option == DHO_REBINDTIME))
9156e63cc1fSRoy Marples 				continue;
9166e63cc1fSRoy Marples 			AREA_FIT(1);
9176e63cc1fSRoy Marples 			*p++ = (uint8_t)opt->option;
9186e63cc1fSRoy Marples 		}
9196e63cc1fSRoy Marples 		*n_params = (uint8_t)(p - n_params - 1);
9206e63cc1fSRoy Marples 
9216e63cc1fSRoy Marples 		if (mtu != -1 &&
9226e63cc1fSRoy Marples 		    !(has_option_mask(ifo->nomask, DHO_MAXMESSAGESIZE)))
9236e63cc1fSRoy Marples 		{
9246e63cc1fSRoy Marples 			AREA_CHECK(2);
9256e63cc1fSRoy Marples 			*p++ = DHO_MAXMESSAGESIZE;
9266e63cc1fSRoy Marples 			*p++ = 2;
9276e63cc1fSRoy Marples 			sz = htons((uint16_t)(mtu - IP_UDP_SIZE));
9286e63cc1fSRoy Marples 			memcpy(p, &sz, 2);
9296e63cc1fSRoy Marples 			p += 2;
9306e63cc1fSRoy Marples 		}
9316e63cc1fSRoy Marples 
9326e63cc1fSRoy Marples 		if (ifo->userclass[0] &&
9336e63cc1fSRoy Marples 		    !has_option_mask(ifo->nomask, DHO_USERCLASS))
9346e63cc1fSRoy Marples 		{
9356e63cc1fSRoy Marples 			AREA_CHECK(ifo->userclass[0]);
9366e63cc1fSRoy Marples 			*p++ = DHO_USERCLASS;
9376e63cc1fSRoy Marples 			memcpy(p, ifo->userclass,
9386e63cc1fSRoy Marples 			    (size_t)ifo->userclass[0] + 1);
9396e63cc1fSRoy Marples 			p += ifo->userclass[0] + 1;
9406e63cc1fSRoy Marples 		}
9416e63cc1fSRoy Marples 	}
9426e63cc1fSRoy Marples 
9436e63cc1fSRoy Marples 	if (state->clientid) {
9446e63cc1fSRoy Marples 		AREA_CHECK(state->clientid[0]);
9456e63cc1fSRoy Marples 		*p++ = DHO_CLIENTID;
9466e63cc1fSRoy Marples 		memcpy(p, state->clientid, (size_t)state->clientid[0] + 1);
9476e63cc1fSRoy Marples 		p += state->clientid[0] + 1;
9486e63cc1fSRoy Marples 	}
9496e63cc1fSRoy Marples 
9506e63cc1fSRoy Marples 	if (DHCP_DIR(type) &&
9516e63cc1fSRoy Marples 	    !has_option_mask(ifo->nomask, DHO_VENDORCLASSID) &&
9526e63cc1fSRoy Marples 	    ifo->vendorclassid[0])
9536e63cc1fSRoy Marples 	{
9546e63cc1fSRoy Marples 		AREA_CHECK(ifo->vendorclassid[0]);
9556e63cc1fSRoy Marples 		*p++ = DHO_VENDORCLASSID;
9566e63cc1fSRoy Marples 		memcpy(p, ifo->vendorclassid, (size_t)ifo->vendorclassid[0]+1);
9576e63cc1fSRoy Marples 		p += ifo->vendorclassid[0] + 1;
9586e63cc1fSRoy Marples 	}
9596e63cc1fSRoy Marples 
9606e63cc1fSRoy Marples 	if (type == DHCP_DISCOVER &&
9616e63cc1fSRoy Marples 	    !(ifp->ctx->options & DHCPCD_TEST) &&
9626e63cc1fSRoy Marples 	    DHC_REQ(ifo->requestmask, ifo->nomask, DHO_RAPIDCOMMIT))
9636e63cc1fSRoy Marples 	{
9646e63cc1fSRoy Marples 		/* RFC 4039 Section 3 */
9656e63cc1fSRoy Marples 		AREA_CHECK(0);
9666e63cc1fSRoy Marples 		*p++ = DHO_RAPIDCOMMIT;
9676e63cc1fSRoy Marples 		*p++ = 0;
9686e63cc1fSRoy Marples 	}
9696e63cc1fSRoy Marples 
9706e63cc1fSRoy Marples 	if (DHCP_DIR(type)) {
9717827cba2SAaron LI 		hostname = dhcp_get_hostname(hbuf, sizeof(hbuf), ifo);
9727827cba2SAaron LI 
9737827cba2SAaron LI 		/*
9747827cba2SAaron LI 		 * RFC4702 3.1 States that if we send the Client FQDN option
9757827cba2SAaron LI 		 * then we MUST NOT also send the Host Name option.
9767827cba2SAaron LI 		 * Technically we could, but that is not RFC conformant and
9777827cba2SAaron LI 		 * also seems to break some DHCP server implemetations such as
9787827cba2SAaron LI 		 * Windows. On the other hand, ISC dhcpd is just as non RFC
9797827cba2SAaron LI 		 * conformant by not accepting a partially qualified FQDN.
9807827cba2SAaron LI 		 */
9817827cba2SAaron LI 		if (ifo->fqdn != FQDN_DISABLE) {
9827827cba2SAaron LI 			/* IETF DHC-FQDN option (81), RFC4702 */
9837827cba2SAaron LI 			i = 3;
9847827cba2SAaron LI 			if (hostname)
9857827cba2SAaron LI 				i += encode_rfc1035(hostname, NULL);
9867827cba2SAaron LI 			AREA_CHECK(i);
9877827cba2SAaron LI 			*p++ = DHO_FQDN;
9887827cba2SAaron LI 			*p++ = (uint8_t)i;
9897827cba2SAaron LI 			/*
9907827cba2SAaron LI 			 * Flags: 0000NEOS
9917827cba2SAaron LI 			 * S: 1 => Client requests Server to update
9927827cba2SAaron LI 			 *         a RR in DNS as well as PTR
9937827cba2SAaron LI 			 * O: 1 => Server indicates to client that
9947827cba2SAaron LI 			 *         DNS has been updated
9957827cba2SAaron LI 			 * E: 1 => Name data is DNS format
9967827cba2SAaron LI 			 * N: 1 => Client requests Server to not
9977827cba2SAaron LI 			 *         update DNS
9987827cba2SAaron LI 			 */
9997827cba2SAaron LI 			if (hostname)
10007827cba2SAaron LI 				*p++ = (uint8_t)((ifo->fqdn & 0x09) | 0x04);
10017827cba2SAaron LI 			else
10027827cba2SAaron LI 				*p++ = (FQDN_NONE & 0x09) | 0x04;
10037827cba2SAaron LI 			*p++ = 0; /* from server for PTR RR */
10047827cba2SAaron LI 			*p++ = 0; /* from server for A RR if S=1 */
10057827cba2SAaron LI 			if (hostname) {
10067827cba2SAaron LI 				i = encode_rfc1035(hostname, p);
10077827cba2SAaron LI 				p += i;
10087827cba2SAaron LI 			}
10097827cba2SAaron LI 		} else if (ifo->options & DHCPCD_HOSTNAME && hostname) {
10107827cba2SAaron LI 			len = strlen(hostname);
10117827cba2SAaron LI 			AREA_CHECK(len);
10127827cba2SAaron LI 			*p++ = DHO_HOSTNAME;
10137827cba2SAaron LI 			*p++ = (uint8_t)len;
10147827cba2SAaron LI 			memcpy(p, hostname, len);
10157827cba2SAaron LI 			p += len;
10167827cba2SAaron LI 		}
10177827cba2SAaron LI 	}
10187827cba2SAaron LI 
10197827cba2SAaron LI #ifdef AUTH
10207827cba2SAaron LI 	auth = NULL;	/* appease GCC */
10217827cba2SAaron LI 	auth_len = 0;
10227827cba2SAaron LI 	if (ifo->auth.options & DHCPCD_AUTH_SEND) {
1023acd7a309SRoy Marples 		ssize_t alen = dhcp_auth_encode(ifp->ctx, &ifo->auth,
10247827cba2SAaron LI 		    state->auth.token,
10257827cba2SAaron LI 		    NULL, 0, 4, type, NULL, 0);
10267827cba2SAaron LI 		if (alen != -1 && alen > UINT8_MAX) {
10277827cba2SAaron LI 			errno = ERANGE;
10287827cba2SAaron LI 			alen = -1;
10297827cba2SAaron LI 		}
10307827cba2SAaron LI 		if (alen == -1)
10317827cba2SAaron LI 			logerr("%s: dhcp_auth_encode", ifp->name);
10327827cba2SAaron LI 		else if (alen != 0) {
10337827cba2SAaron LI 			auth_len = (uint8_t)alen;
10347827cba2SAaron LI 			AREA_CHECK(auth_len);
10357827cba2SAaron LI 			*p++ = DHO_AUTHENTICATION;
10367827cba2SAaron LI 			*p++ = auth_len;
10377827cba2SAaron LI 			auth = p;
10387827cba2SAaron LI 			p += auth_len;
10397827cba2SAaron LI 		}
10407827cba2SAaron LI 	}
10417827cba2SAaron LI #endif
10427827cba2SAaron LI 
10436e63cc1fSRoy Marples 	/* RFC 2563 Auto Configure */
10446e63cc1fSRoy Marples 	if (type == DHCP_DISCOVER && ifo->options & DHCPCD_IPV4LL &&
10456e63cc1fSRoy Marples 	    !(has_option_mask(ifo->nomask, DHO_AUTOCONFIGURE)))
10466e63cc1fSRoy Marples 	{
10476e63cc1fSRoy Marples 		AREA_CHECK(1);
10486e63cc1fSRoy Marples 		*p++ = DHO_AUTOCONFIGURE;
10496e63cc1fSRoy Marples 		*p++ = 1;
10506e63cc1fSRoy Marples 		*p++ = 1;
10516e63cc1fSRoy Marples 	}
10526e63cc1fSRoy Marples 
10536e63cc1fSRoy Marples 	if (DHCP_DIR(type)) {
10546e63cc1fSRoy Marples 		if (ifo->mudurl[0]) {
10556e63cc1fSRoy Marples 		       AREA_CHECK(ifo->mudurl[0]);
10566e63cc1fSRoy Marples 		       *p++ = DHO_MUDURL;
10576e63cc1fSRoy Marples 		       memcpy(p, ifo->mudurl, (size_t)ifo->mudurl[0] + 1);
10586e63cc1fSRoy Marples 		       p += ifo->mudurl[0] + 1;
10596e63cc1fSRoy Marples 		}
10606e63cc1fSRoy Marples 
10616e63cc1fSRoy Marples 		if (ifo->vivco_len &&
10626e63cc1fSRoy Marples 		    !has_option_mask(ifo->nomask, DHO_VIVCO))
10636e63cc1fSRoy Marples 		{
10646e63cc1fSRoy Marples 			AREA_CHECK(sizeof(ul));
10656e63cc1fSRoy Marples 			*p++ = DHO_VIVCO;
10666e63cc1fSRoy Marples 			lp = p++;
10676e63cc1fSRoy Marples 			*lp = sizeof(ul);
10686e63cc1fSRoy Marples 			ul = htonl(ifo->vivco_en);
10696e63cc1fSRoy Marples 			memcpy(p, &ul, sizeof(ul));
10706e63cc1fSRoy Marples 			p += sizeof(ul);
10716e63cc1fSRoy Marples 			for (i = 0, vivco = ifo->vivco;
10726e63cc1fSRoy Marples 			    i < ifo->vivco_len;
10736e63cc1fSRoy Marples 			    i++, vivco++)
10746e63cc1fSRoy Marples 			{
10756e63cc1fSRoy Marples 				AREA_FIT(vivco->len);
10766e63cc1fSRoy Marples 				if (vivco->len + 2 + *lp > 255) {
10776e63cc1fSRoy Marples 					logerrx("%s: VIVCO option too big",
10786e63cc1fSRoy Marples 					    ifp->name);
10796e63cc1fSRoy Marples 					free(bootp);
10806e63cc1fSRoy Marples 					return -1;
10816e63cc1fSRoy Marples 				}
10826e63cc1fSRoy Marples 				*p++ = (uint8_t)vivco->len;
10836e63cc1fSRoy Marples 				memcpy(p, vivco->data, vivco->len);
10846e63cc1fSRoy Marples 				p += vivco->len;
10856e63cc1fSRoy Marples 				*lp = (uint8_t)(*lp + vivco->len + 1);
10866e63cc1fSRoy Marples 			}
10876e63cc1fSRoy Marples 		}
10886e63cc1fSRoy Marples 
10896e63cc1fSRoy Marples #ifdef AUTH
10906e63cc1fSRoy Marples 		if ((ifo->auth.options & DHCPCD_AUTH_SENDREQUIRE) !=
10916e63cc1fSRoy Marples 		    DHCPCD_AUTH_SENDREQUIRE &&
10926e63cc1fSRoy Marples 		    !has_option_mask(ifo->nomask, DHO_FORCERENEW_NONCE))
10936e63cc1fSRoy Marples 		{
10946e63cc1fSRoy Marples 			/* We support HMAC-MD5 */
10956e63cc1fSRoy Marples 			AREA_CHECK(1);
10966e63cc1fSRoy Marples 			*p++ = DHO_FORCERENEW_NONCE;
10976e63cc1fSRoy Marples 			*p++ = 1;
10986e63cc1fSRoy Marples 			*p++ = AUTH_ALG_HMAC_MD5;
10996e63cc1fSRoy Marples 		}
11006e63cc1fSRoy Marples #endif
11016e63cc1fSRoy Marples 	}
11026e63cc1fSRoy Marples 
11037827cba2SAaron LI 	*p++ = DHO_END;
11047827cba2SAaron LI 	len = (size_t)(p - (uint8_t *)bootp);
11057827cba2SAaron LI 
11067827cba2SAaron LI 	/* Pad out to the BOOTP message length.
11077827cba2SAaron LI 	 * Even if we send a DHCP packet with a variable length vendor area,
11087827cba2SAaron LI 	 * some servers / relay agents don't like packets smaller than
11097827cba2SAaron LI 	 * a BOOTP message which is fine because that's stipulated
11107827cba2SAaron LI 	 * in RFC1542 section 2.1. */
11117827cba2SAaron LI 	while (len < sizeof(*bootp)) {
11127827cba2SAaron LI 		*p++ = DHO_PAD;
11137827cba2SAaron LI 		len++;
11147827cba2SAaron LI 	}
11157827cba2SAaron LI 
11167827cba2SAaron LI #ifdef AUTH
11177827cba2SAaron LI 	if (ifo->auth.options & DHCPCD_AUTH_SEND && auth_len != 0)
1118acd7a309SRoy Marples 		dhcp_auth_encode(ifp->ctx, &ifo->auth, state->auth.token,
11197827cba2SAaron LI 		    (uint8_t *)bootp, len, 4, type, auth, auth_len);
11207827cba2SAaron LI #endif
11217827cba2SAaron LI 
11227827cba2SAaron LI 	return (ssize_t)len;
11237827cba2SAaron LI 
11247827cba2SAaron LI toobig:
11257827cba2SAaron LI 	logerrx("%s: DHCP message too big", ifp->name);
11267827cba2SAaron LI 	free(bootp);
11277827cba2SAaron LI 	return -1;
11287827cba2SAaron LI }
11297827cba2SAaron LI 
11307827cba2SAaron LI static size_t
read_lease(struct interface * ifp,struct bootp ** bootp)11317827cba2SAaron LI read_lease(struct interface *ifp, struct bootp **bootp)
11327827cba2SAaron LI {
1133d4fb1e02SRoy Marples 	union {
1134d4fb1e02SRoy Marples 		struct bootp bootp;
1135d4fb1e02SRoy Marples 		uint8_t buf[FRAMELEN_MAX];
1136d4fb1e02SRoy Marples 	} buf;
11377827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
1138d4fb1e02SRoy Marples 	ssize_t sbytes;
11397827cba2SAaron LI 	size_t bytes;
11407827cba2SAaron LI 	uint8_t type;
11417827cba2SAaron LI #ifdef AUTH
11427827cba2SAaron LI 	const uint8_t *auth;
11437827cba2SAaron LI 	size_t auth_len;
11447827cba2SAaron LI #endif
11457827cba2SAaron LI 
11467827cba2SAaron LI 	/* Safety */
11477827cba2SAaron LI 	*bootp = NULL;
11487827cba2SAaron LI 
11497827cba2SAaron LI 	if (state->leasefile[0] == '\0') {
11507827cba2SAaron LI 		logdebugx("reading standard input");
1151d4fb1e02SRoy Marples 		sbytes = read(fileno(stdin), buf.buf, sizeof(buf.buf));
1152d4fb1e02SRoy Marples 	} else {
1153a0d9933aSRoy Marples 		logdebugx("%s: reading lease: %s",
11547827cba2SAaron LI 		    ifp->name, state->leasefile);
1155d4fb1e02SRoy Marples 		sbytes = dhcp_readfile(ifp->ctx, state->leasefile,
1156d4fb1e02SRoy Marples 		    buf.buf, sizeof(buf.buf));
1157d4fb1e02SRoy Marples 	}
1158d4fb1e02SRoy Marples 	if (sbytes == -1) {
1159d4fb1e02SRoy Marples 		if (errno != ENOENT)
1160d4fb1e02SRoy Marples 			logerr("%s: %s", ifp->name, state->leasefile);
11617827cba2SAaron LI 		return 0;
1162d4fb1e02SRoy Marples 	}
1163d4fb1e02SRoy Marples 	bytes = (size_t)sbytes;
11647827cba2SAaron LI 
11657827cba2SAaron LI 	/* Ensure the packet is at lease BOOTP sized
11667827cba2SAaron LI 	 * with a vendor area of 4 octets
11677827cba2SAaron LI 	 * (it should be more, and our read packet enforces this so this
11687827cba2SAaron LI 	 * code should not be needed, but of course people could
11697827cba2SAaron LI 	 * scribble whatever in the stored lease file. */
1170ce6cc02eSRoy Marples 	if (bytes < DHCP_MIN_LEN) {
11717827cba2SAaron LI 		logerrx("%s: %s: truncated lease", ifp->name, __func__);
11727827cba2SAaron LI 		return 0;
11737827cba2SAaron LI 	}
11747827cba2SAaron LI 
11757827cba2SAaron LI 	if (ifp->ctx->options & DHCPCD_DUMPLEASE)
11767827cba2SAaron LI 		goto out;
11777827cba2SAaron LI 
11787827cba2SAaron LI 	/* We may have found a BOOTP server */
1179d4fb1e02SRoy Marples 	if (get_option_uint8(ifp->ctx, &type, &buf.bootp, bytes,
11807827cba2SAaron LI 	    DHO_MESSAGETYPE) == -1)
11817827cba2SAaron LI 		type = 0;
11827827cba2SAaron LI 
11837827cba2SAaron LI #ifdef AUTH
11847827cba2SAaron LI 	/* Authenticate the message */
1185d4fb1e02SRoy Marples 	auth = get_option(ifp->ctx, &buf.bootp, bytes,
11867827cba2SAaron LI 	    DHO_AUTHENTICATION, &auth_len);
11877827cba2SAaron LI 	if (auth) {
11887827cba2SAaron LI 		if (dhcp_auth_validate(&state->auth, &ifp->options->auth,
1189d4fb1e02SRoy Marples 		    &buf.bootp, bytes, 4, type, auth, auth_len) == NULL)
11907827cba2SAaron LI 		{
11917827cba2SAaron LI 			logerr("%s: authentication failed", ifp->name);
11927827cba2SAaron LI 			return 0;
11937827cba2SAaron LI 		}
11947827cba2SAaron LI 		if (state->auth.token)
11957827cba2SAaron LI 			logdebugx("%s: validated using 0x%08" PRIu32,
11967827cba2SAaron LI 			    ifp->name, state->auth.token->secretid);
11977827cba2SAaron LI 		else
11987827cba2SAaron LI 			logdebugx("%s: accepted reconfigure key", ifp->name);
11997827cba2SAaron LI 	} else if ((ifp->options->auth.options & DHCPCD_AUTH_SENDREQUIRE) ==
12007827cba2SAaron LI 	    DHCPCD_AUTH_SENDREQUIRE)
12017827cba2SAaron LI 	{
12027827cba2SAaron LI 		logerrx("%s: authentication now required", ifp->name);
12037827cba2SAaron LI 		return 0;
12047827cba2SAaron LI 	}
12057827cba2SAaron LI #endif
12067827cba2SAaron LI 
12077827cba2SAaron LI out:
1208d4fb1e02SRoy Marples 	*bootp = malloc(bytes);
1209d4fb1e02SRoy Marples 	if (*bootp == NULL) {
1210d4fb1e02SRoy Marples 		logerr(__func__);
1211d4fb1e02SRoy Marples 		return 0;
1212d4fb1e02SRoy Marples 	}
1213d4fb1e02SRoy Marples 	memcpy(*bootp, buf.buf, bytes);
12147827cba2SAaron LI 	return bytes;
12157827cba2SAaron LI }
12167827cba2SAaron LI 
12177827cba2SAaron LI static const struct dhcp_opt *
dhcp_getoverride(const struct if_options * ifo,unsigned int o)12187827cba2SAaron LI dhcp_getoverride(const struct if_options *ifo, unsigned int o)
12197827cba2SAaron LI {
12207827cba2SAaron LI 	size_t i;
12217827cba2SAaron LI 	const struct dhcp_opt *opt;
12227827cba2SAaron LI 
12237827cba2SAaron LI 	for (i = 0, opt = ifo->dhcp_override;
12247827cba2SAaron LI 	    i < ifo->dhcp_override_len;
12257827cba2SAaron LI 	    i++, opt++)
12267827cba2SAaron LI 	{
12277827cba2SAaron LI 		if (opt->option == o)
12287827cba2SAaron LI 			return opt;
12297827cba2SAaron LI 	}
12307827cba2SAaron LI 	return NULL;
12317827cba2SAaron LI }
12327827cba2SAaron LI 
12337827cba2SAaron LI static const uint8_t *
dhcp_getoption(struct dhcpcd_ctx * ctx,size_t * os,unsigned int * code,size_t * len,const uint8_t * od,size_t ol,struct dhcp_opt ** oopt)12347827cba2SAaron LI dhcp_getoption(struct dhcpcd_ctx *ctx,
12357827cba2SAaron LI     size_t *os, unsigned int *code, size_t *len,
12367827cba2SAaron LI     const uint8_t *od, size_t ol, struct dhcp_opt **oopt)
12377827cba2SAaron LI {
12387827cba2SAaron LI 	size_t i;
12397827cba2SAaron LI 	struct dhcp_opt *opt;
12407827cba2SAaron LI 
12417827cba2SAaron LI 	if (od) {
12427827cba2SAaron LI 		if (ol < 2) {
12437827cba2SAaron LI 			errno = EINVAL;
12447827cba2SAaron LI 			return NULL;
12457827cba2SAaron LI 		}
12467827cba2SAaron LI 		*os = 2; /* code + len */
12477827cba2SAaron LI 		*code = (unsigned int)*od++;
12487827cba2SAaron LI 		*len = (size_t)*od++;
12497827cba2SAaron LI 		if (*len > ol - *os) {
12507827cba2SAaron LI 			errno = ERANGE;
12517827cba2SAaron LI 			return NULL;
12527827cba2SAaron LI 		}
12537827cba2SAaron LI 	}
12547827cba2SAaron LI 
12557827cba2SAaron LI 	*oopt = NULL;
12567827cba2SAaron LI 	for (i = 0, opt = ctx->dhcp_opts; i < ctx->dhcp_opts_len; i++, opt++) {
12577827cba2SAaron LI 		if (opt->option == *code) {
12587827cba2SAaron LI 			*oopt = opt;
12597827cba2SAaron LI 			break;
12607827cba2SAaron LI 		}
12617827cba2SAaron LI 	}
12627827cba2SAaron LI 
12637827cba2SAaron LI 	return od;
12647827cba2SAaron LI }
12657827cba2SAaron LI 
12667827cba2SAaron LI ssize_t
dhcp_env(FILE * fenv,const char * prefix,const struct interface * ifp,const struct bootp * bootp,size_t bootp_len)12678d36e1dfSRoy Marples dhcp_env(FILE *fenv, const char *prefix, const struct interface *ifp,
12688d36e1dfSRoy Marples     const struct bootp *bootp, size_t bootp_len)
12697827cba2SAaron LI {
12707827cba2SAaron LI 	const struct if_options *ifo;
12717827cba2SAaron LI 	const uint8_t *p;
12727827cba2SAaron LI 	struct in_addr addr;
12737827cba2SAaron LI 	struct in_addr net;
12747827cba2SAaron LI 	struct in_addr brd;
12757827cba2SAaron LI 	struct dhcp_opt *opt, *vo;
12768d36e1dfSRoy Marples 	size_t i, pl;
12778d36e1dfSRoy Marples 	char safe[(BOOTP_FILE_LEN * 4) + 1];
12787827cba2SAaron LI 	uint8_t overl = 0;
12797827cba2SAaron LI 	uint32_t en;
12807827cba2SAaron LI 
12817827cba2SAaron LI 	ifo = ifp->options;
12827827cba2SAaron LI 	if (get_option_uint8(ifp->ctx, &overl, bootp, bootp_len,
12837827cba2SAaron LI 	    DHO_OPTSOVERLOADED) == -1)
12847827cba2SAaron LI 		overl = 0;
12857827cba2SAaron LI 
12867827cba2SAaron LI 	if (bootp->yiaddr || bootp->ciaddr) {
12877827cba2SAaron LI 		/* Set some useful variables that we derive from the DHCP
12887827cba2SAaron LI 		 * message but are not necessarily in the options */
12897827cba2SAaron LI 		addr.s_addr = bootp->yiaddr ? bootp->yiaddr : bootp->ciaddr;
12908d36e1dfSRoy Marples 		if (efprintf(fenv, "%s_ip_address=%s",
12918d36e1dfSRoy Marples 		    prefix, inet_ntoa(addr)) == -1)
12928d36e1dfSRoy Marples 			return -1;
12937827cba2SAaron LI 		if (get_option_addr(ifp->ctx, &net,
12948d36e1dfSRoy Marples 		    bootp, bootp_len, DHO_SUBNETMASK) == -1) {
12957827cba2SAaron LI 			net.s_addr = ipv4_getnetmask(addr.s_addr);
12968d36e1dfSRoy Marples 			if (efprintf(fenv, "%s_subnet_mask=%s",
12978d36e1dfSRoy Marples 			    prefix, inet_ntoa(net)) == -1)
12988d36e1dfSRoy Marples 				return -1;
12997827cba2SAaron LI 		}
13008d36e1dfSRoy Marples 		if (efprintf(fenv, "%s_subnet_cidr=%d",
13018d36e1dfSRoy Marples 		    prefix, inet_ntocidr(net))== -1)
13028d36e1dfSRoy Marples 			return -1;
13037827cba2SAaron LI 		if (get_option_addr(ifp->ctx, &brd,
13047827cba2SAaron LI 		    bootp, bootp_len, DHO_BROADCAST) == -1)
13057827cba2SAaron LI 		{
13067827cba2SAaron LI 			brd.s_addr = addr.s_addr | ~net.s_addr;
13078d36e1dfSRoy Marples 			if (efprintf(fenv, "%s_broadcast_address=%s",
13088d36e1dfSRoy Marples 			    prefix, inet_ntoa(brd)) == -1)
13098d36e1dfSRoy Marples 				return -1;
13107827cba2SAaron LI 		}
13117827cba2SAaron LI 		addr.s_addr = bootp->yiaddr & net.s_addr;
13128d36e1dfSRoy Marples 		if (efprintf(fenv, "%s_network_number=%s",
13138d36e1dfSRoy Marples 		    prefix, inet_ntoa(addr)) == -1)
13148d36e1dfSRoy Marples 			return -1;
13157827cba2SAaron LI 	}
13167827cba2SAaron LI 
13177827cba2SAaron LI 	if (*bootp->file && !(overl & 1)) {
13187827cba2SAaron LI 		print_string(safe, sizeof(safe), OT_STRING,
13197827cba2SAaron LI 		    bootp->file, sizeof(bootp->file));
13208d36e1dfSRoy Marples 		if (efprintf(fenv, "%s_filename=%s", prefix, safe) == -1)
13218d36e1dfSRoy Marples 			return -1;
13227827cba2SAaron LI 	}
13237827cba2SAaron LI 	if (*bootp->sname && !(overl & 2)) {
13247827cba2SAaron LI 		print_string(safe, sizeof(safe), OT_STRING | OT_DOMAIN,
13257827cba2SAaron LI 		    bootp->sname, sizeof(bootp->sname));
13268d36e1dfSRoy Marples 		if (efprintf(fenv, "%s_server_name=%s", prefix, safe) == -1)
13278d36e1dfSRoy Marples 			return -1;
13287827cba2SAaron LI 	}
13297827cba2SAaron LI 
13307827cba2SAaron LI 	/* Zero our indexes */
13317827cba2SAaron LI 	for (i = 0, opt = ifp->ctx->dhcp_opts;
13327827cba2SAaron LI 	    i < ifp->ctx->dhcp_opts_len;
13337827cba2SAaron LI 	    i++, opt++)
13347827cba2SAaron LI 		dhcp_zero_index(opt);
13357827cba2SAaron LI 	for (i = 0, opt = ifp->options->dhcp_override;
13367827cba2SAaron LI 	    i < ifp->options->dhcp_override_len;
13377827cba2SAaron LI 	    i++, opt++)
13387827cba2SAaron LI 		dhcp_zero_index(opt);
13397827cba2SAaron LI 	for (i = 0, opt = ifp->ctx->vivso;
13407827cba2SAaron LI 	    i < ifp->ctx->vivso_len;
13417827cba2SAaron LI 	    i++, opt++)
13427827cba2SAaron LI 		dhcp_zero_index(opt);
13437827cba2SAaron LI 
13447827cba2SAaron LI 	for (i = 0, opt = ifp->ctx->dhcp_opts;
13457827cba2SAaron LI 	    i < ifp->ctx->dhcp_opts_len;
13467827cba2SAaron LI 	    i++, opt++)
13477827cba2SAaron LI 	{
13487827cba2SAaron LI 		if (has_option_mask(ifo->nomask, opt->option))
13497827cba2SAaron LI 			continue;
13507827cba2SAaron LI 		if (dhcp_getoverride(ifo, opt->option))
13517827cba2SAaron LI 			continue;
13527827cba2SAaron LI 		p = get_option(ifp->ctx, bootp, bootp_len, opt->option, &pl);
13537827cba2SAaron LI 		if (p == NULL)
13547827cba2SAaron LI 			continue;
13558d36e1dfSRoy Marples 		dhcp_envoption(ifp->ctx, fenv, prefix, ifp->name,
13567827cba2SAaron LI 		    opt, dhcp_getoption, p, pl);
13577827cba2SAaron LI 
13587827cba2SAaron LI 		if (opt->option != DHO_VIVSO || pl <= (int)sizeof(uint32_t))
13597827cba2SAaron LI 			continue;
13607827cba2SAaron LI 		memcpy(&en, p, sizeof(en));
13617827cba2SAaron LI 		en = ntohl(en);
13627827cba2SAaron LI 		vo = vivso_find(en, ifp);
13637827cba2SAaron LI 		if (vo == NULL)
13647827cba2SAaron LI 			continue;
13657827cba2SAaron LI 		/* Skip over en + total size */
13667827cba2SAaron LI 		p += sizeof(en) + 1;
13677827cba2SAaron LI 		pl -= sizeof(en) + 1;
13688d36e1dfSRoy Marples 		dhcp_envoption(ifp->ctx, fenv, prefix, ifp->name,
13697827cba2SAaron LI 		    vo, dhcp_getoption, p, pl);
13707827cba2SAaron LI 	}
13717827cba2SAaron LI 
13727827cba2SAaron LI 	for (i = 0, opt = ifo->dhcp_override;
13737827cba2SAaron LI 	    i < ifo->dhcp_override_len;
13747827cba2SAaron LI 	    i++, opt++)
13757827cba2SAaron LI 	{
13767827cba2SAaron LI 		if (has_option_mask(ifo->nomask, opt->option))
13777827cba2SAaron LI 			continue;
13787827cba2SAaron LI 		p = get_option(ifp->ctx, bootp, bootp_len, opt->option, &pl);
13797827cba2SAaron LI 		if (p == NULL)
13807827cba2SAaron LI 			continue;
13818d36e1dfSRoy Marples 		dhcp_envoption(ifp->ctx, fenv, prefix, ifp->name,
13827827cba2SAaron LI 		    opt, dhcp_getoption, p, pl);
13837827cba2SAaron LI 	}
13847827cba2SAaron LI 
13858d36e1dfSRoy Marples 	return 1;
13867827cba2SAaron LI }
13877827cba2SAaron LI 
13887827cba2SAaron LI static void
get_lease(struct interface * ifp,struct dhcp_lease * lease,const struct bootp * bootp,size_t len)13897827cba2SAaron LI get_lease(struct interface *ifp,
13907827cba2SAaron LI     struct dhcp_lease *lease, const struct bootp *bootp, size_t len)
13917827cba2SAaron LI {
13927827cba2SAaron LI 	struct dhcpcd_ctx *ctx;
13937827cba2SAaron LI 
13947827cba2SAaron LI 	assert(bootp != NULL);
13957827cba2SAaron LI 
13967827cba2SAaron LI 	memcpy(&lease->cookie, bootp->vend, sizeof(lease->cookie));
13977827cba2SAaron LI 	/* BOOTP does not set yiaddr for replies when ciaddr is set. */
13987827cba2SAaron LI 	lease->addr.s_addr = bootp->yiaddr ? bootp->yiaddr : bootp->ciaddr;
13997827cba2SAaron LI 	ctx = ifp->ctx;
14007827cba2SAaron LI 	if (ifp->options->options & (DHCPCD_STATIC | DHCPCD_INFORM)) {
14017827cba2SAaron LI 		if (ifp->options->req_addr.s_addr != INADDR_ANY) {
14027827cba2SAaron LI 			lease->mask = ifp->options->req_mask;
14037827cba2SAaron LI 			if (ifp->options->req_brd.s_addr != INADDR_ANY)
14047827cba2SAaron LI 				lease->brd = ifp->options->req_brd;
14057827cba2SAaron LI 			else
14067827cba2SAaron LI 				lease->brd.s_addr =
14077827cba2SAaron LI 				    lease->addr.s_addr | ~lease->mask.s_addr;
14087827cba2SAaron LI 		} else {
14097827cba2SAaron LI 			const struct ipv4_addr *ia;
14107827cba2SAaron LI 
14117827cba2SAaron LI 			ia = ipv4_iffindaddr(ifp, &lease->addr, NULL);
14127827cba2SAaron LI 			assert(ia != NULL);
14137827cba2SAaron LI 			lease->mask = ia->mask;
14147827cba2SAaron LI 			lease->brd = ia->brd;
14157827cba2SAaron LI 		}
14167827cba2SAaron LI 	} else {
14177827cba2SAaron LI 		if (get_option_addr(ctx, &lease->mask, bootp, len,
14187827cba2SAaron LI 		    DHO_SUBNETMASK) == -1)
14197827cba2SAaron LI 			lease->mask.s_addr =
14207827cba2SAaron LI 			    ipv4_getnetmask(lease->addr.s_addr);
14217827cba2SAaron LI 		if (get_option_addr(ctx, &lease->brd, bootp, len,
14227827cba2SAaron LI 		    DHO_BROADCAST) == -1)
14237827cba2SAaron LI 			lease->brd.s_addr =
14247827cba2SAaron LI 			    lease->addr.s_addr | ~lease->mask.s_addr;
14257827cba2SAaron LI 	}
14267827cba2SAaron LI 	if (get_option_uint32(ctx, &lease->leasetime,
14277827cba2SAaron LI 	    bootp, len, DHO_LEASETIME) != 0)
14288d36e1dfSRoy Marples 		lease->leasetime = DHCP_INFINITE_LIFETIME;
14297827cba2SAaron LI 	if (get_option_uint32(ctx, &lease->renewaltime,
14307827cba2SAaron LI 	    bootp, len, DHO_RENEWALTIME) != 0)
14317827cba2SAaron LI 		lease->renewaltime = 0;
14327827cba2SAaron LI 	if (get_option_uint32(ctx, &lease->rebindtime,
14337827cba2SAaron LI 	    bootp, len, DHO_REBINDTIME) != 0)
14347827cba2SAaron LI 		lease->rebindtime = 0;
14357827cba2SAaron LI 	if (get_option_addr(ctx, &lease->server, bootp, len, DHO_SERVERID) != 0)
14367827cba2SAaron LI 		lease->server.s_addr = INADDR_ANY;
14377827cba2SAaron LI }
14387827cba2SAaron LI 
14397827cba2SAaron LI static const char *
get_dhcp_op(uint8_t type)14407827cba2SAaron LI get_dhcp_op(uint8_t type)
14417827cba2SAaron LI {
14427827cba2SAaron LI 	const struct dhcp_op *d;
14437827cba2SAaron LI 
14447827cba2SAaron LI 	for (d = dhcp_ops; d->name; d++)
14457827cba2SAaron LI 		if (d->value == type)
14467827cba2SAaron LI 			return d->name;
14477827cba2SAaron LI 	return NULL;
14487827cba2SAaron LI }
14497827cba2SAaron LI 
14507827cba2SAaron LI static void
dhcp_fallback(void * arg)14517827cba2SAaron LI dhcp_fallback(void *arg)
14527827cba2SAaron LI {
14537827cba2SAaron LI 	struct interface *iface;
14547827cba2SAaron LI 
14557827cba2SAaron LI 	iface = (struct interface *)arg;
14567827cba2SAaron LI 	dhcpcd_selectprofile(iface, iface->options->fallback);
14577827cba2SAaron LI 	dhcpcd_startinterface(iface);
14587827cba2SAaron LI }
14597827cba2SAaron LI 
14607827cba2SAaron LI static void
dhcp_new_xid(struct interface * ifp)14617827cba2SAaron LI dhcp_new_xid(struct interface *ifp)
14627827cba2SAaron LI {
14637827cba2SAaron LI 	struct dhcp_state *state;
14647827cba2SAaron LI 	const struct interface *ifp1;
14657827cba2SAaron LI 	const struct dhcp_state *state1;
14667827cba2SAaron LI 
14677827cba2SAaron LI 	state = D_STATE(ifp);
14687827cba2SAaron LI 	if (ifp->options->options & DHCPCD_XID_HWADDR &&
14697827cba2SAaron LI 	    ifp->hwlen >= sizeof(state->xid))
14707827cba2SAaron LI 		/* The lower bits are probably more unique on the network */
14717827cba2SAaron LI 		memcpy(&state->xid,
14727827cba2SAaron LI 		    (ifp->hwaddr + ifp->hwlen) - sizeof(state->xid),
14737827cba2SAaron LI 		    sizeof(state->xid));
14747827cba2SAaron LI 	else {
14757827cba2SAaron LI again:
14767827cba2SAaron LI 		state->xid = arc4random();
14777827cba2SAaron LI 	}
14787827cba2SAaron LI 
14797827cba2SAaron LI 	/* Ensure it's unique */
14807827cba2SAaron LI 	TAILQ_FOREACH(ifp1, ifp->ctx->ifaces, next) {
14817827cba2SAaron LI 		if (ifp == ifp1)
14827827cba2SAaron LI 			continue;
14837827cba2SAaron LI 		if ((state1 = D_CSTATE(ifp1)) == NULL)
14847827cba2SAaron LI 			continue;
14857827cba2SAaron LI 		if (state1->xid == state->xid)
14867827cba2SAaron LI 			break;
14877827cba2SAaron LI 	}
14887827cba2SAaron LI 	if (ifp1 != NULL) {
14897827cba2SAaron LI 		if (ifp->options->options & DHCPCD_XID_HWADDR &&
14907827cba2SAaron LI 		    ifp->hwlen >= sizeof(state->xid))
14917827cba2SAaron LI 		{
14927827cba2SAaron LI 			logerrx("%s: duplicate xid on %s",
14937827cba2SAaron LI 			    ifp->name, ifp1->name);
14947827cba2SAaron LI 			    return;
14957827cba2SAaron LI 		}
14967827cba2SAaron LI 		goto again;
14977827cba2SAaron LI 	}
14987827cba2SAaron LI 
14997827cba2SAaron LI 	/* We can't do this when sharing leases across interfaes */
15007827cba2SAaron LI #if 0
15017827cba2SAaron LI 	/* As the XID changes, re-apply the filter. */
15027827cba2SAaron LI 	if (state->bpf_fd != -1) {
15037827cba2SAaron LI 		if (bpf_bootp(ifp, state->bpf_fd) == -1)
15047827cba2SAaron LI 			logerr(__func__); /* try to continue */
15057827cba2SAaron LI 	}
15067827cba2SAaron LI #endif
15077827cba2SAaron LI }
15087827cba2SAaron LI 
150939994b17SRoy Marples static void
dhcp_closebpf(struct interface * ifp)151039994b17SRoy Marples dhcp_closebpf(struct interface *ifp)
15117827cba2SAaron LI {
15126e63cc1fSRoy Marples 	struct dhcpcd_ctx *ctx = ifp->ctx;
15137827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
15147827cba2SAaron LI 
15156e63cc1fSRoy Marples #ifdef PRIVSEP
151639994b17SRoy Marples 	if (IN_PRIVSEP_SE(ctx))
15176e63cc1fSRoy Marples 		ps_bpf_closebootp(ifp);
15186e63cc1fSRoy Marples #endif
15196e63cc1fSRoy Marples 
1520d4fb1e02SRoy Marples 	if (state->bpf != NULL) {
1521d4fb1e02SRoy Marples 		eloop_event_delete(ctx->eloop, state->bpf->bpf_fd);
1522d4fb1e02SRoy Marples 		bpf_close(state->bpf);
1523d4fb1e02SRoy Marples 		state->bpf = NULL;
15247827cba2SAaron LI 	}
152539994b17SRoy Marples }
152639994b17SRoy Marples 
152739994b17SRoy Marples static void
dhcp_closeinet(struct interface * ifp)152839994b17SRoy Marples dhcp_closeinet(struct interface *ifp)
152939994b17SRoy Marples {
153039994b17SRoy Marples 	struct dhcpcd_ctx *ctx = ifp->ctx;
153139994b17SRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
153239994b17SRoy Marples 
153339994b17SRoy Marples #ifdef PRIVSEP
153439994b17SRoy Marples 	if (IN_PRIVSEP_SE(ctx)) {
153539994b17SRoy Marples 		if (state->addr != NULL)
153639994b17SRoy Marples 			ps_inet_closebootp(state->addr);
153739994b17SRoy Marples 	}
153839994b17SRoy Marples #endif
153939994b17SRoy Marples 
1540d4fb1e02SRoy Marples 	if (state->udp_rfd != -1) {
1541d4fb1e02SRoy Marples 		eloop_event_delete(ctx->eloop, state->udp_rfd);
1542d4fb1e02SRoy Marples 		close(state->udp_rfd);
1543d4fb1e02SRoy Marples 		state->udp_rfd = -1;
15448d36e1dfSRoy Marples 	}
154539994b17SRoy Marples }
154639994b17SRoy Marples 
154739994b17SRoy Marples void
dhcp_close(struct interface * ifp)154839994b17SRoy Marples dhcp_close(struct interface *ifp)
154939994b17SRoy Marples {
155039994b17SRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
155139994b17SRoy Marples 
155239994b17SRoy Marples 	if (state == NULL)
155339994b17SRoy Marples 		return;
155439994b17SRoy Marples 
155539994b17SRoy Marples 	dhcp_closebpf(ifp);
155639994b17SRoy Marples 	dhcp_closeinet(ifp);
15577827cba2SAaron LI 
15587827cba2SAaron LI 	state->interval = 0;
15597827cba2SAaron LI }
15607827cba2SAaron LI 
15616e63cc1fSRoy Marples int
dhcp_openudp(struct in_addr * ia)1562ce6cc02eSRoy Marples dhcp_openudp(struct in_addr *ia)
15637827cba2SAaron LI {
15647827cba2SAaron LI 	int s;
15657827cba2SAaron LI 	struct sockaddr_in sin;
15667827cba2SAaron LI 	int n;
15677827cba2SAaron LI 
1568d4fb1e02SRoy Marples 	if ((s = xsocket(PF_INET, SOCK_DGRAM | SOCK_CXNB, IPPROTO_UDP)) == -1)
15697827cba2SAaron LI 		return -1;
15707827cba2SAaron LI 
15717827cba2SAaron LI 	n = 1;
15727827cba2SAaron LI 	if (setsockopt(s, SOL_SOCKET, SO_REUSEADDR, &n, sizeof(n)) == -1)
1573ce6cc02eSRoy Marples 		goto errexit;
1574b9ccd228SRoy Marples #ifdef IP_RECVIF
1575b9ccd228SRoy Marples 	if (setsockopt(s, IPPROTO_IP, IP_RECVIF, &n, sizeof(n)) == -1)
1576ce6cc02eSRoy Marples 		goto errexit;
1577b9ccd228SRoy Marples #else
15788d36e1dfSRoy Marples 	if (setsockopt(s, IPPROTO_IP, IP_RECVPKTINFO, &n, sizeof(n)) == -1)
1579ce6cc02eSRoy Marples 		goto errexit;
15808d36e1dfSRoy Marples #endif
1581d4fb1e02SRoy Marples #ifdef SO_RERROR
1582d4fb1e02SRoy Marples 	if (setsockopt(s, SOL_SOCKET, SO_RERROR, &n, sizeof(n)) == -1)
1583d4fb1e02SRoy Marples 		goto errexit;
1584d4fb1e02SRoy Marples #endif
1585d4fb1e02SRoy Marples 
15867827cba2SAaron LI 	memset(&sin, 0, sizeof(sin));
15877827cba2SAaron LI 	sin.sin_family = AF_INET;
15887827cba2SAaron LI 	sin.sin_port = htons(BOOTPC);
1589ce6cc02eSRoy Marples 	if (ia != NULL)
1590ce6cc02eSRoy Marples 		sin.sin_addr = *ia;
15917827cba2SAaron LI 	if (bind(s, (struct sockaddr *)&sin, sizeof(sin)) == -1)
1592ce6cc02eSRoy Marples 		goto errexit;
15937827cba2SAaron LI 
15947827cba2SAaron LI 	return s;
15957827cba2SAaron LI 
1596ce6cc02eSRoy Marples errexit:
15977827cba2SAaron LI 	close(s);
15987827cba2SAaron LI 	return -1;
15997827cba2SAaron LI }
16007827cba2SAaron LI 
16017827cba2SAaron LI static uint16_t
in_cksum(const void * data,size_t len,uint32_t * isum)16028d36e1dfSRoy Marples in_cksum(const void *data, size_t len, uint32_t *isum)
16037827cba2SAaron LI {
16048d36e1dfSRoy Marples 	const uint16_t *word = data;
16058d36e1dfSRoy Marples 	uint32_t sum = isum != NULL ? *isum : 0;
16067827cba2SAaron LI 
16078d36e1dfSRoy Marples 	for (; len > 1; len -= sizeof(*word))
16088d36e1dfSRoy Marples 		sum += *word++;
16097827cba2SAaron LI 
16107827cba2SAaron LI 	if (len == 1)
16118d36e1dfSRoy Marples 		sum += htons((uint16_t)(*(const uint8_t *)word << 8));
16128d36e1dfSRoy Marples 
16138d36e1dfSRoy Marples 	if (isum != NULL)
16148d36e1dfSRoy Marples 		*isum = sum;
16157827cba2SAaron LI 
16167827cba2SAaron LI 	sum = (sum >> 16) + (sum & 0xffff);
16177827cba2SAaron LI 	sum += (sum >> 16);
16187827cba2SAaron LI 
16198d36e1dfSRoy Marples 	return (uint16_t)~sum;
16207827cba2SAaron LI }
16217827cba2SAaron LI 
16227827cba2SAaron LI static struct bootp_pkt *
dhcp_makeudppacket(size_t * sz,const uint8_t * data,size_t length,struct in_addr source,struct in_addr dest)16237827cba2SAaron LI dhcp_makeudppacket(size_t *sz, const uint8_t *data, size_t length,
16247827cba2SAaron LI 	struct in_addr source, struct in_addr dest)
16257827cba2SAaron LI {
16267827cba2SAaron LI 	struct bootp_pkt *udpp;
16277827cba2SAaron LI 	struct ip *ip;
16287827cba2SAaron LI 	struct udphdr *udp;
16297827cba2SAaron LI 
16307827cba2SAaron LI 	if ((udpp = calloc(1, sizeof(*ip) + sizeof(*udp) + length)) == NULL)
16317827cba2SAaron LI 		return NULL;
16327827cba2SAaron LI 	ip = &udpp->ip;
16337827cba2SAaron LI 	udp = &udpp->udp;
16347827cba2SAaron LI 
16357827cba2SAaron LI 	/* OK, this is important :)
16367827cba2SAaron LI 	 * We copy the data to our packet and then create a small part of the
16377827cba2SAaron LI 	 * ip structure and an invalid ip_len (basically udp length).
16387827cba2SAaron LI 	 * We then fill the udp structure and put the checksum
16397827cba2SAaron LI 	 * of the whole packet into the udp checksum.
16407827cba2SAaron LI 	 * Finally we complete the ip structure and ip checksum.
16417827cba2SAaron LI 	 * If we don't do the ordering like so then the udp checksum will be
16427827cba2SAaron LI 	 * broken, so find another way of doing it! */
16437827cba2SAaron LI 
16447827cba2SAaron LI 	memcpy(&udpp->bootp, data, length);
16457827cba2SAaron LI 
16467827cba2SAaron LI 	ip->ip_p = IPPROTO_UDP;
16477827cba2SAaron LI 	ip->ip_src.s_addr = source.s_addr;
16487827cba2SAaron LI 	if (dest.s_addr == 0)
16497827cba2SAaron LI 		ip->ip_dst.s_addr = INADDR_BROADCAST;
16507827cba2SAaron LI 	else
16517827cba2SAaron LI 		ip->ip_dst.s_addr = dest.s_addr;
16527827cba2SAaron LI 
16537827cba2SAaron LI 	udp->uh_sport = htons(BOOTPC);
16547827cba2SAaron LI 	udp->uh_dport = htons(BOOTPS);
16557827cba2SAaron LI 	udp->uh_ulen = htons((uint16_t)(sizeof(*udp) + length));
16567827cba2SAaron LI 	ip->ip_len = udp->uh_ulen;
16578d36e1dfSRoy Marples 	udp->uh_sum = in_cksum(udpp, sizeof(*ip) + sizeof(*udp) + length, NULL);
16587827cba2SAaron LI 
16597827cba2SAaron LI 	ip->ip_v = IPVERSION;
16607827cba2SAaron LI 	ip->ip_hl = sizeof(*ip) >> 2;
16617827cba2SAaron LI 	ip->ip_id = (uint16_t)arc4random_uniform(UINT16_MAX);
16627827cba2SAaron LI 	ip->ip_ttl = IPDEFTTL;
16637827cba2SAaron LI 	ip->ip_len = htons((uint16_t)(sizeof(*ip) + sizeof(*udp) + length));
16648d36e1dfSRoy Marples 	ip->ip_sum = in_cksum(ip, sizeof(*ip), NULL);
16658d36e1dfSRoy Marples 	if (ip->ip_sum == 0)
16668d36e1dfSRoy Marples 		ip->ip_sum = 0xffff; /* RFC 768 */
16677827cba2SAaron LI 
16687827cba2SAaron LI 	*sz = sizeof(*ip) + sizeof(*udp) + length;
16697827cba2SAaron LI 	return udpp;
16707827cba2SAaron LI }
16717827cba2SAaron LI 
16727827cba2SAaron LI static ssize_t
dhcp_sendudp(struct interface * ifp,struct in_addr * to,void * data,size_t len)16737827cba2SAaron LI dhcp_sendudp(struct interface *ifp, struct in_addr *to, void *data, size_t len)
16747827cba2SAaron LI {
1675b9ccd228SRoy Marples 	struct sockaddr_in sin = {
1676b9ccd228SRoy Marples 		.sin_family = AF_INET,
1677b9ccd228SRoy Marples 		.sin_addr = *to,
1678b9ccd228SRoy Marples 		.sin_port = htons(BOOTPS),
1679b9ccd228SRoy Marples #ifdef HAVE_SA_LEN
1680b9ccd228SRoy Marples 		.sin_len = sizeof(sin),
1681b9ccd228SRoy Marples #endif
1682b9ccd228SRoy Marples 	};
1683d4fb1e02SRoy Marples 	struct udphdr udp = {
1684d4fb1e02SRoy Marples 	    .uh_sport = htons(BOOTPC),
1685d4fb1e02SRoy Marples 	    .uh_dport = htons(BOOTPS),
1686d4fb1e02SRoy Marples 	    .uh_ulen = htons((uint16_t)(sizeof(udp) + len)),
1687d4fb1e02SRoy Marples 	};
1688b9ccd228SRoy Marples 	struct iovec iov[] = {
1689d4fb1e02SRoy Marples 	    { .iov_base = &udp, .iov_len = sizeof(udp), },
1690d4fb1e02SRoy Marples 	    { .iov_base = data, .iov_len = len, },
1691b9ccd228SRoy Marples 	};
1692b9ccd228SRoy Marples 	struct msghdr msg = {
1693b9ccd228SRoy Marples 		.msg_name = (void *)&sin,
1694b9ccd228SRoy Marples 		.msg_namelen = sizeof(sin),
1695b9ccd228SRoy Marples 		.msg_iov = iov,
1696d4fb1e02SRoy Marples 		.msg_iovlen = __arraycount(iov),
1697b9ccd228SRoy Marples 	};
1698d4fb1e02SRoy Marples 	struct dhcpcd_ctx *ctx = ifp->ctx;
16997827cba2SAaron LI 
17006e63cc1fSRoy Marples #ifdef PRIVSEP
1701d4fb1e02SRoy Marples 	if (ctx->options & DHCPCD_PRIVSEP)
1702d4fb1e02SRoy Marples 		return ps_inet_sendbootp(ifp, &msg);
17036e63cc1fSRoy Marples #endif
1704d4fb1e02SRoy Marples 	return sendmsg(ctx->udp_wfd, &msg, 0);
17057827cba2SAaron LI }
17067827cba2SAaron LI 
17077827cba2SAaron LI static void
send_message(struct interface * ifp,uint8_t type,void (* callback)(void *))17087827cba2SAaron LI send_message(struct interface *ifp, uint8_t type,
17097827cba2SAaron LI     void (*callback)(void *))
17107827cba2SAaron LI {
17117827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
17127827cba2SAaron LI 	struct if_options *ifo = ifp->options;
17137827cba2SAaron LI 	struct bootp *bootp;
17147827cba2SAaron LI 	struct bootp_pkt *udp;
17157827cba2SAaron LI 	size_t len, ulen;
17167827cba2SAaron LI 	ssize_t r;
17177827cba2SAaron LI 	struct in_addr from, to;
17186e63cc1fSRoy Marples 	unsigned int RT;
17197827cba2SAaron LI 
17206e63cc1fSRoy Marples 	if (callback == NULL) {
17217827cba2SAaron LI 		/* No carrier? Don't bother sending the packet. */
172293ddca5eSRoy Marples 		if (!if_is_link_up(ifp))
17237827cba2SAaron LI 			return;
17247827cba2SAaron LI 		logdebugx("%s: sending %s with xid 0x%x",
17257827cba2SAaron LI 		    ifp->name,
17267827cba2SAaron LI 		    ifo->options & DHCPCD_BOOTP ? "BOOTP" : get_dhcp_op(type),
17277827cba2SAaron LI 		    state->xid);
17286e63cc1fSRoy Marples 		RT = 0; /* bogus gcc warning */
17297827cba2SAaron LI 	} else {
17307827cba2SAaron LI 		if (state->interval == 0)
17317827cba2SAaron LI 			state->interval = 4;
17327827cba2SAaron LI 		else {
17337827cba2SAaron LI 			state->interval *= 2;
17347827cba2SAaron LI 			if (state->interval > 64)
17357827cba2SAaron LI 				state->interval = 64;
17367827cba2SAaron LI 		}
17376e63cc1fSRoy Marples 		RT = (state->interval * MSEC_PER_SEC) +
17386e63cc1fSRoy Marples 		    (arc4random_uniform(MSEC_PER_SEC * 2) - MSEC_PER_SEC);
17397827cba2SAaron LI 		/* No carrier? Don't bother sending the packet.
17407827cba2SAaron LI 		 * However, we do need to advance the timeout. */
174193ddca5eSRoy Marples 		if (!if_is_link_up(ifp))
17427827cba2SAaron LI 			goto fail;
17437827cba2SAaron LI 		logdebugx("%s: sending %s (xid 0x%x), next in %0.1f seconds",
17447827cba2SAaron LI 		    ifp->name,
17457827cba2SAaron LI 		    ifo->options & DHCPCD_BOOTP ? "BOOTP" : get_dhcp_op(type),
17467827cba2SAaron LI 		    state->xid,
17476e63cc1fSRoy Marples 		    (float)RT / MSEC_PER_SEC);
17487827cba2SAaron LI 	}
17497827cba2SAaron LI 
17507827cba2SAaron LI 	r = make_message(&bootp, ifp, type);
17517827cba2SAaron LI 	if (r == -1)
17527827cba2SAaron LI 		goto fail;
17537827cba2SAaron LI 	len = (size_t)r;
17541b3b16a2SRoy Marples 
1755b8b69544SRoy Marples 	if (!(state->added & (STATE_FAKE | STATE_EXPIRED)) &&
1756ce6cc02eSRoy Marples 	    state->addr != NULL &&
1757ce6cc02eSRoy Marples 	    ipv4_iffindaddr(ifp, &state->lease.addr, NULL) != NULL)
17581b3b16a2SRoy Marples 		from.s_addr = state->lease.addr.s_addr;
17591b3b16a2SRoy Marples 	else
17601b3b16a2SRoy Marples 		from.s_addr = INADDR_ANY;
17611b3b16a2SRoy Marples 	if (from.s_addr != INADDR_ANY &&
17621b3b16a2SRoy Marples 	    state->lease.server.s_addr != INADDR_ANY)
17637827cba2SAaron LI 		to.s_addr = state->lease.server.s_addr;
17647827cba2SAaron LI 	else
17651b3b16a2SRoy Marples 		to.s_addr = INADDR_BROADCAST;
17667827cba2SAaron LI 
17671b3b16a2SRoy Marples 	/*
17681b3b16a2SRoy Marples 	 * If not listening on the unspecified address we can
17691b3b16a2SRoy Marples 	 * only receive broadcast messages via BPF.
17701b3b16a2SRoy Marples 	 * Sockets bound to an address cannot receive broadcast messages
17711b3b16a2SRoy Marples 	 * even if they are setup to send them.
17721b3b16a2SRoy Marples 	 * Broadcasting from UDP is only an optimisation for rebinding
17731b3b16a2SRoy Marples 	 * and on BSD, at least, is reliant on the subnet route being
1774ce6cc02eSRoy Marples 	 * correctly configured to receive the unicast reply.
17751b3b16a2SRoy Marples 	 * As such, we always broadcast and receive the reply to it via BPF.
17761b3b16a2SRoy Marples 	 * This also guarantees we have a DHCP server attached to the
17771b3b16a2SRoy Marples 	 * interface we want to configure because we can't dictate the
17781b3b16a2SRoy Marples 	 * interface via IP_PKTINFO unlike for IPv6.
17791b3b16a2SRoy Marples 	 */
1780d4fb1e02SRoy Marples 	if (to.s_addr != INADDR_BROADCAST) {
17817827cba2SAaron LI 		if (dhcp_sendudp(ifp, &to, bootp, len) != -1)
17827827cba2SAaron LI 			goto out;
17837827cba2SAaron LI 		logerr("%s: dhcp_sendudp", ifp->name);
17847827cba2SAaron LI 	}
17857827cba2SAaron LI 
17867827cba2SAaron LI 	if (dhcp_openbpf(ifp) == -1)
17877827cba2SAaron LI 		goto out;
17887827cba2SAaron LI 
17897827cba2SAaron LI 	udp = dhcp_makeudppacket(&ulen, (uint8_t *)bootp, len, from, to);
17907827cba2SAaron LI 	if (udp == NULL) {
17917827cba2SAaron LI 		logerr("%s: dhcp_makeudppacket", ifp->name);
17927827cba2SAaron LI 		r = 0;
17936e63cc1fSRoy Marples #ifdef PRIVSEP
17946e63cc1fSRoy Marples 	} else if (ifp->ctx->options & DHCPCD_PRIVSEP) {
17956e63cc1fSRoy Marples 		r = ps_bpf_sendbootp(ifp, udp, ulen);
17966e63cc1fSRoy Marples 		free(udp);
17976e63cc1fSRoy Marples #endif
17987827cba2SAaron LI 	} else {
1799d4fb1e02SRoy Marples 		r = bpf_send(state->bpf, ETHERTYPE_IP, udp, ulen);
18007827cba2SAaron LI 		free(udp);
18017827cba2SAaron LI 	}
18027827cba2SAaron LI 	/* If we failed to send a raw packet this normally means
18037827cba2SAaron LI 	 * we don't have the ability to work beneath the IP layer
18047827cba2SAaron LI 	 * for this interface.
18057827cba2SAaron LI 	 * As such we remove it from consideration without actually
18067827cba2SAaron LI 	 * stopping the interface. */
18077827cba2SAaron LI 	if (r == -1) {
1808b9ccd228SRoy Marples 		logerr("%s: bpf_send", ifp->name);
18097827cba2SAaron LI 		switch(errno) {
18107827cba2SAaron LI 		case ENETDOWN:
18117827cba2SAaron LI 		case ENETRESET:
18127827cba2SAaron LI 		case ENETUNREACH:
18137827cba2SAaron LI 		case ENOBUFS:
18147827cba2SAaron LI 			break;
18157827cba2SAaron LI 		default:
18167827cba2SAaron LI 			if (!(ifp->ctx->options & DHCPCD_TEST))
18177827cba2SAaron LI 				dhcp_drop(ifp, "FAIL");
18187827cba2SAaron LI 			eloop_timeout_delete(ifp->ctx->eloop,
18197827cba2SAaron LI 			    NULL, ifp);
18207827cba2SAaron LI 			callback = NULL;
18217827cba2SAaron LI 		}
18227827cba2SAaron LI 	}
18237827cba2SAaron LI 
18247827cba2SAaron LI out:
18257827cba2SAaron LI 	free(bootp);
18267827cba2SAaron LI 
18277827cba2SAaron LI fail:
18287827cba2SAaron LI 	/* Even if we fail to send a packet we should continue as we are
18297827cba2SAaron LI 	 * as our failure timeouts will change out codepath when needed. */
18306e63cc1fSRoy Marples 	if (callback != NULL)
18316e63cc1fSRoy Marples 		eloop_timeout_add_msec(ifp->ctx->eloop, RT, callback, ifp);
18327827cba2SAaron LI }
18337827cba2SAaron LI 
18347827cba2SAaron LI static void
send_inform(void * arg)18357827cba2SAaron LI send_inform(void *arg)
18367827cba2SAaron LI {
18377827cba2SAaron LI 
18387827cba2SAaron LI 	send_message((struct interface *)arg, DHCP_INFORM, send_inform);
18397827cba2SAaron LI }
18407827cba2SAaron LI 
18417827cba2SAaron LI static void
send_discover(void * arg)18427827cba2SAaron LI send_discover(void *arg)
18437827cba2SAaron LI {
18447827cba2SAaron LI 
18457827cba2SAaron LI 	send_message((struct interface *)arg, DHCP_DISCOVER, send_discover);
18467827cba2SAaron LI }
18477827cba2SAaron LI 
18487827cba2SAaron LI static void
send_request(void * arg)18497827cba2SAaron LI send_request(void *arg)
18507827cba2SAaron LI {
18517827cba2SAaron LI 
18527827cba2SAaron LI 	send_message((struct interface *)arg, DHCP_REQUEST, send_request);
18537827cba2SAaron LI }
18547827cba2SAaron LI 
18557827cba2SAaron LI static void
send_renew(void * arg)18567827cba2SAaron LI send_renew(void *arg)
18577827cba2SAaron LI {
18587827cba2SAaron LI 
18597827cba2SAaron LI 	send_message((struct interface *)arg, DHCP_REQUEST, send_renew);
18607827cba2SAaron LI }
18617827cba2SAaron LI 
18627827cba2SAaron LI static void
send_rebind(void * arg)18637827cba2SAaron LI send_rebind(void *arg)
18647827cba2SAaron LI {
18657827cba2SAaron LI 
18667827cba2SAaron LI 	send_message((struct interface *)arg, DHCP_REQUEST, send_rebind);
18677827cba2SAaron LI }
18687827cba2SAaron LI 
18697827cba2SAaron LI void
dhcp_discover(void * arg)18707827cba2SAaron LI dhcp_discover(void *arg)
18717827cba2SAaron LI {
18727827cba2SAaron LI 	struct interface *ifp = arg;
18737827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
18747827cba2SAaron LI 	struct if_options *ifo = ifp->options;
18757827cba2SAaron LI 
18767827cba2SAaron LI 	state->state = DHS_DISCOVER;
18777827cba2SAaron LI 	dhcp_new_xid(ifp);
18787827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
1879b8b69544SRoy Marples 	if (!(state->added & STATE_EXPIRED)) {
1880*54175cefSRoy Marples 		if (ifo->fallback && ifo->fallback_time)
18817827cba2SAaron LI 			eloop_timeout_add_sec(ifp->ctx->eloop,
1882*54175cefSRoy Marples 			    ifo->fallback_time, dhcp_fallback, ifp);
18837827cba2SAaron LI #ifdef IPV4LL
18847827cba2SAaron LI 		else if (ifo->options & DHCPCD_IPV4LL)
18857827cba2SAaron LI 			eloop_timeout_add_sec(ifp->ctx->eloop,
1886*54175cefSRoy Marples 			    ifo->ipv4ll_time, ipv4ll_start, ifp);
18877827cba2SAaron LI #endif
1888b8b69544SRoy Marples 	}
18897827cba2SAaron LI 	if (ifo->options & DHCPCD_REQUEST)
18907827cba2SAaron LI 		loginfox("%s: soliciting a DHCP lease (requesting %s)",
18917827cba2SAaron LI 		    ifp->name, inet_ntoa(ifo->req_addr));
18927827cba2SAaron LI 	else
18937827cba2SAaron LI 		loginfox("%s: soliciting a %s lease",
18947827cba2SAaron LI 		    ifp->name, ifo->options & DHCPCD_BOOTP ? "BOOTP" : "DHCP");
18957827cba2SAaron LI 	send_discover(ifp);
18967827cba2SAaron LI }
18977827cba2SAaron LI 
18987827cba2SAaron LI static void
dhcp_requestfailed(void * arg)18990b4c9755SRoy Marples dhcp_requestfailed(void *arg)
19000b4c9755SRoy Marples {
19010b4c9755SRoy Marples 	struct interface *ifp = arg;
19020b4c9755SRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
19030b4c9755SRoy Marples 
19040b4c9755SRoy Marples 	logwarnx("%s: failed to request the lease", ifp->name);
19050b4c9755SRoy Marples 	free(state->offer);
19060b4c9755SRoy Marples 	state->offer = NULL;
19070b4c9755SRoy Marples 	state->offer_len = 0;
19080b4c9755SRoy Marples 	state->interval = 0;
19090b4c9755SRoy Marples 	dhcp_discover(ifp);
19100b4c9755SRoy Marples }
19110b4c9755SRoy Marples 
19120b4c9755SRoy Marples static void
dhcp_request(void * arg)19137827cba2SAaron LI dhcp_request(void *arg)
19147827cba2SAaron LI {
19157827cba2SAaron LI 	struct interface *ifp = arg;
19167827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
1917*54175cefSRoy Marples 	struct if_options *ifo = ifp->options;
19187827cba2SAaron LI 
19197827cba2SAaron LI 	state->state = DHS_REQUEST;
19200b4c9755SRoy Marples 	// Handle the server being silent to our request.
1921*54175cefSRoy Marples 	if (ifo->request_time != 0)
1922*54175cefSRoy Marples 		eloop_timeout_add_sec(ifp->ctx->eloop, ifo->request_time,
19230b4c9755SRoy Marples 		    dhcp_requestfailed, ifp);
19247827cba2SAaron LI 	send_request(ifp);
19257827cba2SAaron LI }
19267827cba2SAaron LI 
19277827cba2SAaron LI static void
dhcp_expire(void * arg)19287827cba2SAaron LI dhcp_expire(void *arg)
19297827cba2SAaron LI {
19307827cba2SAaron LI 	struct interface *ifp = arg;
1931b8b69544SRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
19327827cba2SAaron LI 
19337827cba2SAaron LI 	if (ifp->options->options & DHCPCD_LASTLEASE_EXTEND) {
19348d36e1dfSRoy Marples 		logwarnx("%s: DHCP lease expired, extending lease", ifp->name);
1935b8b69544SRoy Marples 		state->added |= STATE_EXPIRED;
1936b8b69544SRoy Marples 	} else {
19378d36e1dfSRoy Marples 		logerrx("%s: DHCP lease expired", ifp->name);
1938b8b69544SRoy Marples 		dhcp_drop(ifp, "EXPIRE");
1939b8b69544SRoy Marples 		dhcp_unlink(ifp->ctx, state->leasefile);
1940b8b69544SRoy Marples 	}
1941b8b69544SRoy Marples 	state->interval = 0;
1942b8b69544SRoy Marples 	dhcp_discover(ifp);
19437827cba2SAaron LI }
19447827cba2SAaron LI 
19457827cba2SAaron LI #if defined(ARP) || defined(IN_IFF_DUPLICATED)
19467827cba2SAaron LI static void
dhcp_decline(struct interface * ifp)19477827cba2SAaron LI dhcp_decline(struct interface *ifp)
19487827cba2SAaron LI {
1949*54175cefSRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
19507827cba2SAaron LI 
1951*54175cefSRoy Marples 	// Set the expired state so we send over BPF as this could be
1952*54175cefSRoy Marples 	// an address defence failure.
1953*54175cefSRoy Marples 	state->added |= STATE_EXPIRED;
19547827cba2SAaron LI 	send_message(ifp, DHCP_DECLINE, NULL);
19557827cba2SAaron LI }
19567827cba2SAaron LI #endif
19577827cba2SAaron LI 
19587827cba2SAaron LI static void
dhcp_startrenew(void * arg)19597827cba2SAaron LI dhcp_startrenew(void *arg)
19607827cba2SAaron LI {
19617827cba2SAaron LI 	struct interface *ifp = arg;
19627827cba2SAaron LI 	struct dhcp_state *state;
19637827cba2SAaron LI 	struct dhcp_lease *lease;
19647827cba2SAaron LI 
19657827cba2SAaron LI 	if ((state = D_STATE(ifp)) == NULL)
19667827cba2SAaron LI 		return;
19677827cba2SAaron LI 
19687827cba2SAaron LI 	/* Only renew in the bound or renew states */
19697827cba2SAaron LI 	if (state->state != DHS_BOUND &&
19707827cba2SAaron LI 	    state->state != DHS_RENEW)
19717827cba2SAaron LI 		return;
19727827cba2SAaron LI 
19737827cba2SAaron LI 	/* Remove the timeout as the renew may have been forced. */
19747827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, dhcp_startrenew, ifp);
19757827cba2SAaron LI 
19767827cba2SAaron LI 	lease = &state->lease;
19777827cba2SAaron LI 	logdebugx("%s: renewing lease of %s", ifp->name,
19787827cba2SAaron LI 	    inet_ntoa(lease->addr));
19797827cba2SAaron LI 	state->state = DHS_RENEW;
19807827cba2SAaron LI 	dhcp_new_xid(ifp);
19817827cba2SAaron LI 	state->interval = 0;
19827827cba2SAaron LI 	send_renew(ifp);
19837827cba2SAaron LI }
19847827cba2SAaron LI 
19857827cba2SAaron LI void
dhcp_renew(struct interface * ifp)19867827cba2SAaron LI dhcp_renew(struct interface *ifp)
19877827cba2SAaron LI {
19887827cba2SAaron LI 
19897827cba2SAaron LI 	dhcp_startrenew(ifp);
19907827cba2SAaron LI }
19917827cba2SAaron LI 
19927827cba2SAaron LI static void
dhcp_rebind(void * arg)19937827cba2SAaron LI dhcp_rebind(void *arg)
19947827cba2SAaron LI {
19957827cba2SAaron LI 	struct interface *ifp = arg;
19967827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
19977827cba2SAaron LI 	struct dhcp_lease *lease = &state->lease;
19987827cba2SAaron LI 
19997827cba2SAaron LI 	logwarnx("%s: failed to renew DHCP, rebinding", ifp->name);
20007827cba2SAaron LI 	logdebugx("%s: expire in %"PRIu32" seconds",
20017827cba2SAaron LI 	    ifp->name, lease->leasetime - lease->rebindtime);
20027827cba2SAaron LI 	state->state = DHS_REBIND;
20037827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, send_renew, ifp);
20047827cba2SAaron LI 	state->lease.server.s_addr = INADDR_ANY;
20057827cba2SAaron LI 	state->interval = 0;
20067827cba2SAaron LI 	ifp->options->options &= ~(DHCPCD_CSR_WARNED |
20077827cba2SAaron LI 	    DHCPCD_ROUTER_HOST_ROUTE_WARNED);
20087827cba2SAaron LI 	send_rebind(ifp);
20097827cba2SAaron LI }
20107827cba2SAaron LI 
20118d36e1dfSRoy Marples #if defined(ARP) || defined(IN_IFF_DUPLICATED)
20127827cba2SAaron LI static void
dhcp_finish_dad(struct interface * ifp,struct in_addr * ia)20138d36e1dfSRoy Marples dhcp_finish_dad(struct interface *ifp, struct in_addr *ia)
20147827cba2SAaron LI {
20158d36e1dfSRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
20167827cba2SAaron LI 
201780aa9461SRoy Marples 	if (state->state == DHS_BOUND)
20187827cba2SAaron LI 		return;
20198d36e1dfSRoy Marples 	if (state->offer == NULL || state->offer->yiaddr != ia->s_addr)
20207827cba2SAaron LI 		return;
20217827cba2SAaron LI 
20228d36e1dfSRoy Marples 	logdebugx("%s: DAD completed for %s", ifp->name, inet_ntoa(*ia));
20238d36e1dfSRoy Marples 	if (!(ifp->options->options & DHCPCD_INFORM))
20247827cba2SAaron LI 		dhcp_bind(ifp);
20258d36e1dfSRoy Marples #ifndef IN_IFF_DUPLICATED
20267827cba2SAaron LI 	else {
20277827cba2SAaron LI 		struct bootp *bootp;
20287827cba2SAaron LI 		size_t len;
20297827cba2SAaron LI 
20307827cba2SAaron LI 		bootp = state->new;
20317827cba2SAaron LI 		len = state->new_len;
20327827cba2SAaron LI 		state->new = state->offer;
20337827cba2SAaron LI 		state->new_len = state->offer_len;
20347827cba2SAaron LI 		get_lease(ifp, &state->lease, state->new, state->new_len);
20358d36e1dfSRoy Marples 		ipv4_applyaddr(ifp);
20367827cba2SAaron LI 		state->new = bootp;
20377827cba2SAaron LI 		state->new_len = len;
20387827cba2SAaron LI 	}
20397827cba2SAaron LI #endif
20407827cba2SAaron LI 
20417827cba2SAaron LI #ifdef IPV4LL
20427827cba2SAaron LI 	/* Stop IPv4LL now we have a working DHCP address */
20430a68f8d2SRoy Marples 	if (!IN_LINKLOCAL(ntohl(ia->s_addr)))
20447827cba2SAaron LI 		ipv4ll_drop(ifp);
20457827cba2SAaron LI #endif
20467827cba2SAaron LI 
20478d36e1dfSRoy Marples 	if (ifp->options->options & DHCPCD_INFORM)
20487827cba2SAaron LI 		dhcp_inform(ifp);
20497827cba2SAaron LI }
20507827cba2SAaron LI 
20511b3b16a2SRoy Marples static bool
dhcp_addr_duplicated(struct interface * ifp,struct in_addr * ia)20528d36e1dfSRoy Marples dhcp_addr_duplicated(struct interface *ifp, struct in_addr *ia)
20538d36e1dfSRoy Marples {
20548d36e1dfSRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
20551b3b16a2SRoy Marples 	unsigned long long opts = ifp->options->options;
20561b3b16a2SRoy Marples 	struct dhcpcd_ctx *ctx = ifp->ctx;
20571b3b16a2SRoy Marples 	bool deleted = false;
20588d36e1dfSRoy Marples #ifdef IN_IFF_DUPLICATED
20598d36e1dfSRoy Marples 	struct ipv4_addr *iap;
20608d36e1dfSRoy Marples #endif
20618d36e1dfSRoy Marples 
20628d36e1dfSRoy Marples 	if ((state->offer == NULL || state->offer->yiaddr != ia->s_addr) &&
20638d36e1dfSRoy Marples 	    !IN_ARE_ADDR_EQUAL(ia, &state->lease.addr))
20641b3b16a2SRoy Marples 		return deleted;
20658d36e1dfSRoy Marples 
20668d36e1dfSRoy Marples 	/* RFC 2131 3.1.5, Client-server interaction */
20678d36e1dfSRoy Marples 	logerrx("%s: DAD detected %s", ifp->name, inet_ntoa(*ia));
2068d4fb1e02SRoy Marples 	dhcp_unlink(ifp->ctx, state->leasefile);
20691b3b16a2SRoy Marples 	if (!(opts & DHCPCD_STATIC) && !state->lease.frominfo)
20708d36e1dfSRoy Marples 		dhcp_decline(ifp);
20718d36e1dfSRoy Marples #ifdef IN_IFF_DUPLICATED
20721b3b16a2SRoy Marples 	if ((iap = ipv4_iffindaddr(ifp, ia, NULL)) != NULL) {
20738d36e1dfSRoy Marples 		ipv4_deladdr(iap, 0);
20741b3b16a2SRoy Marples 		deleted = true;
20751b3b16a2SRoy Marples 	}
20768d36e1dfSRoy Marples #endif
20771b3b16a2SRoy Marples 	eloop_timeout_delete(ctx->eloop, NULL, ifp);
20781b3b16a2SRoy Marples 	if (opts & (DHCPCD_STATIC | DHCPCD_INFORM)) {
20791b3b16a2SRoy Marples 		state->reason = "EXPIRE";
20801b3b16a2SRoy Marples 		script_runreason(ifp, state->reason);
20810a68f8d2SRoy Marples #define NOT_ONLY_SELF (DHCPCD_MANAGER | DHCPCD_IPV6RS | DHCPCD_DHCP6)
20821b3b16a2SRoy Marples 		if (!(ctx->options & NOT_ONLY_SELF))
20831b3b16a2SRoy Marples 			eloop_exit(ifp->ctx->eloop, EXIT_FAILURE);
20841b3b16a2SRoy Marples 		return deleted;
20851b3b16a2SRoy Marples 	}
20868d36e1dfSRoy Marples 	eloop_timeout_add_sec(ifp->ctx->eloop,
20878d36e1dfSRoy Marples 	    DHCP_RAND_MAX, dhcp_discover, ifp);
20881b3b16a2SRoy Marples 	return deleted;
20898d36e1dfSRoy Marples }
20908d36e1dfSRoy Marples #endif
20918d36e1dfSRoy Marples 
2092d4fb1e02SRoy Marples #ifdef ARP
2093d4fb1e02SRoy Marples #ifdef KERNEL_RFC5227
209439994b17SRoy Marples #ifdef ARPING
2095d4fb1e02SRoy Marples static void
dhcp_arp_announced(struct arp_state * state)2096d4fb1e02SRoy Marples dhcp_arp_announced(struct arp_state *state)
2097d4fb1e02SRoy Marples {
2098d4fb1e02SRoy Marples 
2099d4fb1e02SRoy Marples 	arp_free(state);
2100d4fb1e02SRoy Marples }
210139994b17SRoy Marples #endif
2102d4fb1e02SRoy Marples #else
2103d4fb1e02SRoy Marples static void
dhcp_arp_defend_failed(struct arp_state * astate)2104d4fb1e02SRoy Marples dhcp_arp_defend_failed(struct arp_state *astate)
2105d4fb1e02SRoy Marples {
2106d4fb1e02SRoy Marples 	struct interface *ifp = astate->iface;
2107*54175cefSRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
2108d4fb1e02SRoy Marples 
2109*54175cefSRoy Marples 	if (!(ifp->options->options & (DHCPCD_INFORM | DHCPCD_STATIC)))
2110*54175cefSRoy Marples 		dhcp_decline(ifp);
2111d4fb1e02SRoy Marples 	dhcp_drop(ifp, "EXPIRED");
2112*54175cefSRoy Marples 	dhcp_unlink(ifp->ctx, state->leasefile);
2113d4fb1e02SRoy Marples 	dhcp_start1(ifp);
2114d4fb1e02SRoy Marples }
2115d4fb1e02SRoy Marples #endif
2116d4fb1e02SRoy Marples 
2117d4fb1e02SRoy Marples #if !defined(KERNEL_RFC5227) || defined(ARPING)
2118d4fb1e02SRoy Marples static void dhcp_arp_not_found(struct arp_state *);
2119d4fb1e02SRoy Marples 
2120d4fb1e02SRoy Marples static struct arp_state *
dhcp_arp_new(struct interface * ifp,struct in_addr * addr)2121d4fb1e02SRoy Marples dhcp_arp_new(struct interface *ifp, struct in_addr *addr)
2122d4fb1e02SRoy Marples {
2123d4fb1e02SRoy Marples 	struct arp_state *astate;
2124d4fb1e02SRoy Marples 
2125d4fb1e02SRoy Marples 	astate = arp_new(ifp, addr);
2126d4fb1e02SRoy Marples 	if (astate == NULL)
2127d4fb1e02SRoy Marples 		return NULL;
2128d4fb1e02SRoy Marples 
2129d4fb1e02SRoy Marples 	astate->found_cb = dhcp_arp_found;
2130d4fb1e02SRoy Marples 	astate->not_found_cb = dhcp_arp_not_found;
2131d4fb1e02SRoy Marples #ifdef KERNEL_RFC5227
2132d4fb1e02SRoy Marples 	astate->announced_cb = dhcp_arp_announced;
2133d4fb1e02SRoy Marples #else
2134d4fb1e02SRoy Marples 	astate->announced_cb = NULL;
2135d4fb1e02SRoy Marples 	astate->defend_failed_cb = dhcp_arp_defend_failed;
2136d4fb1e02SRoy Marples #endif
2137d4fb1e02SRoy Marples 	return astate;
2138d4fb1e02SRoy Marples }
2139d4fb1e02SRoy Marples #endif
2140d4fb1e02SRoy Marples 
2141d4fb1e02SRoy Marples #ifdef ARPING
2142d4fb1e02SRoy Marples static int
dhcp_arping(struct interface * ifp)2143d4fb1e02SRoy Marples dhcp_arping(struct interface *ifp)
2144d4fb1e02SRoy Marples {
2145d4fb1e02SRoy Marples 	struct dhcp_state *state;
2146d4fb1e02SRoy Marples 	struct if_options *ifo;
2147d4fb1e02SRoy Marples 	struct arp_state *astate;
2148d4fb1e02SRoy Marples 	struct in_addr addr;
2149d4fb1e02SRoy Marples 
2150d4fb1e02SRoy Marples 	state = D_STATE(ifp);
2151d4fb1e02SRoy Marples 	ifo = ifp->options;
2152d4fb1e02SRoy Marples 
2153d4fb1e02SRoy Marples 	if (ifo->arping_len == 0 || state->arping_index > ifo->arping_len)
2154d4fb1e02SRoy Marples 		return 0;
2155d4fb1e02SRoy Marples 
2156d4fb1e02SRoy Marples 	if (state->arping_index + 1 == ifo->arping_len) {
2157d4fb1e02SRoy Marples 		state->arping_index++;
2158d4fb1e02SRoy Marples 		dhcpcd_startinterface(ifp);
2159d4fb1e02SRoy Marples 		return 1;
2160d4fb1e02SRoy Marples 	}
2161d4fb1e02SRoy Marples 
2162d4fb1e02SRoy Marples 	addr.s_addr = ifo->arping[++state->arping_index];
2163d4fb1e02SRoy Marples 	astate = dhcp_arp_new(ifp, &addr);
2164d4fb1e02SRoy Marples 	if (astate == NULL) {
2165d4fb1e02SRoy Marples 		logerr(__func__);
2166d4fb1e02SRoy Marples 		return -1;
2167d4fb1e02SRoy Marples 	}
2168d4fb1e02SRoy Marples 	arp_probe(astate);
2169d4fb1e02SRoy Marples 	return 1;
2170d4fb1e02SRoy Marples }
2171d4fb1e02SRoy Marples #endif
2172d4fb1e02SRoy Marples 
2173d4fb1e02SRoy Marples #if !defined(KERNEL_RFC5227) || defined(ARPING)
21748d36e1dfSRoy Marples static void
dhcp_arp_not_found(struct arp_state * astate)21758d36e1dfSRoy Marples dhcp_arp_not_found(struct arp_state *astate)
21767827cba2SAaron LI {
21777827cba2SAaron LI 	struct interface *ifp;
21787827cba2SAaron LI 
21797827cba2SAaron LI 	ifp = astate->iface;
21808d36e1dfSRoy Marples #ifdef ARPING
2181d4fb1e02SRoy Marples 	if (dhcp_arping(ifp) == 1) {
21828d36e1dfSRoy Marples 		arp_free(astate);
21838d36e1dfSRoy Marples 		return;
21848d36e1dfSRoy Marples 	}
21858d36e1dfSRoy Marples #endif
21868d36e1dfSRoy Marples 
21878d36e1dfSRoy Marples 	dhcp_finish_dad(ifp, &astate->addr);
21888d36e1dfSRoy Marples }
21898d36e1dfSRoy Marples 
21908d36e1dfSRoy Marples static void
dhcp_arp_found(struct arp_state * astate,const struct arp_msg * amsg)21918d36e1dfSRoy Marples dhcp_arp_found(struct arp_state *astate, const struct arp_msg *amsg)
21928d36e1dfSRoy Marples {
21938d36e1dfSRoy Marples 	struct in_addr addr;
21948d36e1dfSRoy Marples 	struct interface *ifp = astate->iface;
21958d36e1dfSRoy Marples #ifdef ARPING
21968d36e1dfSRoy Marples 	struct dhcp_state *state;
21978d36e1dfSRoy Marples 	struct if_options *ifo;
21988d36e1dfSRoy Marples 
21997827cba2SAaron LI 	state = D_STATE(ifp);
22007827cba2SAaron LI 
22017827cba2SAaron LI 	ifo = ifp->options;
22027827cba2SAaron LI 	if (state->arping_index != -1 &&
22037827cba2SAaron LI 	    state->arping_index < ifo->arping_len &&
22047827cba2SAaron LI 	    amsg &&
22057827cba2SAaron LI 	    amsg->sip.s_addr == ifo->arping[state->arping_index])
22067827cba2SAaron LI 	{
22077827cba2SAaron LI 		char buf[HWADDR_LEN * 3];
22087827cba2SAaron LI 
22097827cba2SAaron LI 		hwaddr_ntoa(amsg->sha, ifp->hwlen, buf, sizeof(buf));
22107827cba2SAaron LI 		if (dhcpcd_selectprofile(ifp, buf) == -1 &&
22118d36e1dfSRoy Marples 		    dhcpcd_selectprofile(ifp, inet_ntoa(amsg->sip)) == -1)
22127827cba2SAaron LI 		{
22137827cba2SAaron LI 			/* We didn't find a profile for this
22147827cba2SAaron LI 			 * address or hwaddr, so move to the next
22157827cba2SAaron LI 			 * arping profile */
22168d36e1dfSRoy Marples 			dhcp_arp_not_found(astate);
22177827cba2SAaron LI 			return;
22187827cba2SAaron LI 		}
22197827cba2SAaron LI 		arp_free(astate);
22207827cba2SAaron LI 		eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
22217827cba2SAaron LI 		dhcpcd_startinterface(ifp);
22227827cba2SAaron LI 		return;
22237827cba2SAaron LI 	}
22248d36e1dfSRoy Marples #else
22258d36e1dfSRoy Marples 	UNUSED(amsg);
22267827cba2SAaron LI #endif
22277827cba2SAaron LI 
22288d36e1dfSRoy Marples 	addr = astate->addr;
22297827cba2SAaron LI 	arp_free(astate);
22308d36e1dfSRoy Marples 	dhcp_addr_duplicated(ifp, &addr);
22317827cba2SAaron LI }
2232d4fb1e02SRoy Marples #endif
22337827cba2SAaron LI 
22348d36e1dfSRoy Marples #endif /* ARP */
22357827cba2SAaron LI 
22367827cba2SAaron LI void
dhcp_bind(struct interface * ifp)22377827cba2SAaron LI dhcp_bind(struct interface *ifp)
22387827cba2SAaron LI {
22398d36e1dfSRoy Marples 	struct dhcpcd_ctx *ctx = ifp->ctx;
22407827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
22417827cba2SAaron LI 	struct if_options *ifo = ifp->options;
22427827cba2SAaron LI 	struct dhcp_lease *lease = &state->lease;
22436e63cc1fSRoy Marples 	uint8_t old_state;
22447827cba2SAaron LI 
22457827cba2SAaron LI 	state->reason = NULL;
22467827cba2SAaron LI 	/* If we don't have an offer, we are re-binding a lease on preference,
22477827cba2SAaron LI 	 * normally when two interfaces have a lease matching IP addresses. */
22487827cba2SAaron LI 	if (state->offer) {
22497827cba2SAaron LI 		free(state->old);
22507827cba2SAaron LI 		state->old = state->new;
22517827cba2SAaron LI 		state->old_len = state->new_len;
22527827cba2SAaron LI 		state->new = state->offer;
22537827cba2SAaron LI 		state->new_len = state->offer_len;
22547827cba2SAaron LI 		state->offer = NULL;
22557827cba2SAaron LI 		state->offer_len = 0;
22567827cba2SAaron LI 	}
22577827cba2SAaron LI 	get_lease(ifp, lease, state->new, state->new_len);
22587827cba2SAaron LI 	if (ifo->options & DHCPCD_STATIC) {
22597827cba2SAaron LI 		loginfox("%s: using static address %s/%d",
22607827cba2SAaron LI 		    ifp->name, inet_ntoa(lease->addr),
22617827cba2SAaron LI 		    inet_ntocidr(lease->mask));
22628d36e1dfSRoy Marples 		lease->leasetime = DHCP_INFINITE_LIFETIME;
22637827cba2SAaron LI 		state->reason = "STATIC";
22647827cba2SAaron LI 	} else if (ifo->options & DHCPCD_INFORM) {
22657827cba2SAaron LI 		loginfox("%s: received approval for %s",
22667827cba2SAaron LI 		    ifp->name, inet_ntoa(lease->addr));
22678d36e1dfSRoy Marples 		lease->leasetime = DHCP_INFINITE_LIFETIME;
22687827cba2SAaron LI 		state->reason = "INFORM";
22697827cba2SAaron LI 	} else {
22707827cba2SAaron LI 		if (lease->frominfo)
22717827cba2SAaron LI 			state->reason = "TIMEOUT";
22728d36e1dfSRoy Marples 		if (lease->leasetime == DHCP_INFINITE_LIFETIME) {
22737827cba2SAaron LI 			lease->renewaltime =
22747827cba2SAaron LI 			    lease->rebindtime =
22757827cba2SAaron LI 			    lease->leasetime;
22767827cba2SAaron LI 			loginfox("%s: leased %s for infinity",
22777827cba2SAaron LI 			   ifp->name, inet_ntoa(lease->addr));
22787827cba2SAaron LI 		} else {
22797827cba2SAaron LI 			if (lease->leasetime < DHCP_MIN_LEASE) {
22807827cba2SAaron LI 				logwarnx("%s: minimum lease is %d seconds",
22817827cba2SAaron LI 				    ifp->name, DHCP_MIN_LEASE);
22827827cba2SAaron LI 				lease->leasetime = DHCP_MIN_LEASE;
22837827cba2SAaron LI 			}
22847827cba2SAaron LI 			if (lease->rebindtime == 0)
22857827cba2SAaron LI 				lease->rebindtime =
22867827cba2SAaron LI 				    (uint32_t)(lease->leasetime * T2);
22877827cba2SAaron LI 			else if (lease->rebindtime >= lease->leasetime) {
22887827cba2SAaron LI 				lease->rebindtime =
22897827cba2SAaron LI 				    (uint32_t)(lease->leasetime * T2);
22907827cba2SAaron LI 				logwarnx("%s: rebind time greater than lease "
22917827cba2SAaron LI 				    "time, forcing to %"PRIu32" seconds",
22927827cba2SAaron LI 				    ifp->name, lease->rebindtime);
22937827cba2SAaron LI 			}
22947827cba2SAaron LI 			if (lease->renewaltime == 0)
22957827cba2SAaron LI 				lease->renewaltime =
22967827cba2SAaron LI 				    (uint32_t)(lease->leasetime * T1);
22977827cba2SAaron LI 			else if (lease->renewaltime > lease->rebindtime) {
22987827cba2SAaron LI 				lease->renewaltime =
22997827cba2SAaron LI 				    (uint32_t)(lease->leasetime * T1);
23007827cba2SAaron LI 				logwarnx("%s: renewal time greater than "
23017827cba2SAaron LI 				    "rebind time, forcing to %"PRIu32" seconds",
23027827cba2SAaron LI 				    ifp->name, lease->renewaltime);
23037827cba2SAaron LI 			}
2304d4fb1e02SRoy Marples 			if (state->state == DHS_RENEW && state->addr &&
23057827cba2SAaron LI 			    lease->addr.s_addr == state->addr->addr.s_addr &&
23067827cba2SAaron LI 			    !(state->added & STATE_FAKE))
23077827cba2SAaron LI 				logdebugx("%s: leased %s for %"PRIu32" seconds",
23087827cba2SAaron LI 				    ifp->name, inet_ntoa(lease->addr),
23097827cba2SAaron LI 				    lease->leasetime);
23107827cba2SAaron LI 			else
23117827cba2SAaron LI 				loginfox("%s: leased %s for %"PRIu32" seconds",
23127827cba2SAaron LI 				    ifp->name, inet_ntoa(lease->addr),
23137827cba2SAaron LI 				    lease->leasetime);
23147827cba2SAaron LI 		}
23157827cba2SAaron LI 	}
23168d36e1dfSRoy Marples 	if (ctx->options & DHCPCD_TEST) {
23177827cba2SAaron LI 		state->reason = "TEST";
23187827cba2SAaron LI 		script_runreason(ifp, state->reason);
23198d36e1dfSRoy Marples 		eloop_exit(ctx->eloop, EXIT_SUCCESS);
23207827cba2SAaron LI 		return;
23217827cba2SAaron LI 	}
23227827cba2SAaron LI 	if (state->reason == NULL) {
2323b8b69544SRoy Marples 		if (state->old &&
2324b8b69544SRoy Marples 		    !(state->added & (STATE_FAKE | STATE_EXPIRED)))
2325b8b69544SRoy Marples 		{
23267827cba2SAaron LI 			if (state->old->yiaddr == state->new->yiaddr &&
23277827cba2SAaron LI 			    lease->server.s_addr &&
23287827cba2SAaron LI 			    state->state != DHS_REBIND)
23297827cba2SAaron LI 				state->reason = "RENEW";
23307827cba2SAaron LI 			else
23317827cba2SAaron LI 				state->reason = "REBIND";
23327827cba2SAaron LI 		} else if (state->state == DHS_REBOOT)
23337827cba2SAaron LI 			state->reason = "REBOOT";
23347827cba2SAaron LI 		else
23357827cba2SAaron LI 			state->reason = "BOUND";
23367827cba2SAaron LI 	}
23378d36e1dfSRoy Marples 	if (lease->leasetime == DHCP_INFINITE_LIFETIME)
23387827cba2SAaron LI 		lease->renewaltime = lease->rebindtime = lease->leasetime;
23397827cba2SAaron LI 	else {
23408d36e1dfSRoy Marples 		eloop_timeout_add_sec(ctx->eloop,
23416e63cc1fSRoy Marples 		    lease->renewaltime, dhcp_startrenew, ifp);
23428d36e1dfSRoy Marples 		eloop_timeout_add_sec(ctx->eloop,
23436e63cc1fSRoy Marples 		    lease->rebindtime, dhcp_rebind, ifp);
23448d36e1dfSRoy Marples 		eloop_timeout_add_sec(ctx->eloop,
23456e63cc1fSRoy Marples 		    lease->leasetime, dhcp_expire, ifp);
23467827cba2SAaron LI 		logdebugx("%s: renew in %"PRIu32" seconds, rebind in %"PRIu32
23477827cba2SAaron LI 		    " seconds",
23487827cba2SAaron LI 		    ifp->name, lease->renewaltime, lease->rebindtime);
23497827cba2SAaron LI 	}
23507827cba2SAaron LI 	state->state = DHS_BOUND;
23517827cba2SAaron LI 	if (!state->lease.frominfo &&
2352d4fb1e02SRoy Marples 	    !(ifo->options & (DHCPCD_INFORM | DHCPCD_STATIC))) {
2353a0d9933aSRoy Marples 		logdebugx("%s: writing lease: %s",
2354d4fb1e02SRoy Marples 		    ifp->name, state->leasefile);
2355d4fb1e02SRoy Marples 		if (dhcp_writefile(ifp->ctx, state->leasefile, 0640,
2356d4fb1e02SRoy Marples 		    state->new, state->new_len) == -1)
2357d4fb1e02SRoy Marples 			logerr("dhcp_writefile: %s", state->leasefile);
2358d4fb1e02SRoy Marples 	}
23597827cba2SAaron LI 
236039994b17SRoy Marples 	old_state = state->added;
236139994b17SRoy Marples 
2362b2927f2bSRoy Marples 	if (!(ifo->options & DHCPCD_CONFIGURE)) {
2363b2927f2bSRoy Marples 		struct ipv4_addr *ia;
2364b2927f2bSRoy Marples 
2365b2927f2bSRoy Marples 		script_runreason(ifp, state->reason);
2366b2927f2bSRoy Marples 		dhcpcd_daemonise(ifp->ctx);
2367b2927f2bSRoy Marples 
2368b2927f2bSRoy Marples 		/* We we are not configuring the address, we need to keep
2369b2927f2bSRoy Marples 		 * the BPF socket open if the address does not exist. */
2370b2927f2bSRoy Marples 		ia = ipv4_iffindaddr(ifp, &state->lease.addr, NULL);
2371b2927f2bSRoy Marples 		if (ia != NULL) {
2372b2927f2bSRoy Marples 			state->addr = ia;
2373b2927f2bSRoy Marples 			state->added = STATE_ADDED;
2374b2927f2bSRoy Marples 			dhcp_closebpf(ifp);
2375b2927f2bSRoy Marples 			goto openudp;
2376b2927f2bSRoy Marples 		}
2377b2927f2bSRoy Marples 		return;
2378b2927f2bSRoy Marples 	}
2379b2927f2bSRoy Marples 
238020329f2aSRoy Marples 	/* Add the address */
238120329f2aSRoy Marples 	if (ipv4_applyaddr(ifp) == NULL) {
238220329f2aSRoy Marples 		/* There was an error adding the address.
238320329f2aSRoy Marples 		 * If we are in oneshot, exit with a failure. */
238420329f2aSRoy Marples 		if (ctx->options & DHCPCD_ONESHOT) {
238520329f2aSRoy Marples 			loginfox("exiting due to oneshot");
238620329f2aSRoy Marples 			eloop_exit(ctx->eloop, EXIT_FAILURE);
238720329f2aSRoy Marples 		}
238820329f2aSRoy Marples 		return;
238920329f2aSRoy Marples 	}
239020329f2aSRoy Marples 
23918d36e1dfSRoy Marples 	/* Close the BPF filter as we can now receive DHCP messages
23928d36e1dfSRoy Marples 	 * on a UDP socket. */
239339994b17SRoy Marples 	dhcp_closebpf(ifp);
2394b9ccd228SRoy Marples 
2395b2927f2bSRoy Marples openudp:
23960a68f8d2SRoy Marples 	/* If not in manager mode, open an address specific socket. */
23970a68f8d2SRoy Marples 	if (ctx->options & DHCPCD_MANAGER ||
23980a68f8d2SRoy Marples 	    ifo->options & DHCPCD_STATIC ||
23996e63cc1fSRoy Marples 	    (state->old != NULL &&
24006e63cc1fSRoy Marples 	     state->old->yiaddr == state->new->yiaddr &&
24016e63cc1fSRoy Marples 	     old_state & STATE_ADDED && !(old_state & STATE_FAKE)))
2402b9ccd228SRoy Marples 		return;
24036e63cc1fSRoy Marples 
240439994b17SRoy Marples 	dhcp_closeinet(ifp);
24056e63cc1fSRoy Marples #ifdef PRIVSEP
24066e63cc1fSRoy Marples 	if (IN_PRIVSEP_SE(ctx)) {
24076e63cc1fSRoy Marples 		if (ps_inet_openbootp(state->addr) == -1)
24086e63cc1fSRoy Marples 		    logerr(__func__);
24096e63cc1fSRoy Marples 		return;
24106e63cc1fSRoy Marples 	}
24116e63cc1fSRoy Marples #endif
24126e63cc1fSRoy Marples 
2413d4fb1e02SRoy Marples 	state->udp_rfd = dhcp_openudp(&state->addr->addr);
2414d4fb1e02SRoy Marples 	if (state->udp_rfd == -1) {
24158d36e1dfSRoy Marples 		logerr(__func__);
24160a68f8d2SRoy Marples 		/* Address sharing without manager mode is not supported.
2417b9ccd228SRoy Marples 		 * It's also possible another DHCP client could be running,
2418b9ccd228SRoy Marples 		 * which is even worse.
24198d36e1dfSRoy Marples 		 * We still need to work, so re-open BPF. */
24208d36e1dfSRoy Marples 		dhcp_openbpf(ifp);
2421b9ccd228SRoy Marples 		return;
24228d36e1dfSRoy Marples 	}
242380aa9461SRoy Marples 	if (eloop_event_add(ctx->eloop, state->udp_rfd, ELE_READ,
242480aa9461SRoy Marples 	    dhcp_handleifudp, ifp) == -1)
242580aa9461SRoy Marples 		logerr("%s: eloop_event_add", __func__);
24267827cba2SAaron LI }
24277827cba2SAaron LI 
24287827cba2SAaron LI static size_t
dhcp_message_new(struct bootp ** bootp,const struct in_addr * addr,const struct in_addr * mask)24297827cba2SAaron LI dhcp_message_new(struct bootp **bootp,
24307827cba2SAaron LI     const struct in_addr *addr, const struct in_addr *mask)
24317827cba2SAaron LI {
24327827cba2SAaron LI 	uint8_t *p;
24337827cba2SAaron LI 	uint32_t cookie;
24347827cba2SAaron LI 
24357827cba2SAaron LI 	if ((*bootp = calloc(1, sizeof(**bootp))) == NULL)
24367827cba2SAaron LI 		return 0;
24377827cba2SAaron LI 
24387827cba2SAaron LI 	(*bootp)->yiaddr = addr->s_addr;
24397827cba2SAaron LI 	p = (*bootp)->vend;
24407827cba2SAaron LI 
24417827cba2SAaron LI 	cookie = htonl(MAGIC_COOKIE);
24427827cba2SAaron LI 	memcpy(p, &cookie, sizeof(cookie));
24437827cba2SAaron LI 	p += sizeof(cookie);
24447827cba2SAaron LI 
24457827cba2SAaron LI 	if (mask->s_addr != INADDR_ANY) {
24467827cba2SAaron LI 		*p++ = DHO_SUBNETMASK;
24477827cba2SAaron LI 		*p++ = sizeof(mask->s_addr);
24487827cba2SAaron LI 		memcpy(p, &mask->s_addr, sizeof(mask->s_addr));
24497827cba2SAaron LI 		p+= sizeof(mask->s_addr);
24507827cba2SAaron LI 	}
24517827cba2SAaron LI 
24527827cba2SAaron LI 	*p = DHO_END;
24537827cba2SAaron LI 	return sizeof(**bootp);
24547827cba2SAaron LI }
24557827cba2SAaron LI 
24568d36e1dfSRoy Marples #if defined(ARP) || defined(KERNEL_RFC5227)
24577827cba2SAaron LI static int
dhcp_arp_address(struct interface * ifp)24587827cba2SAaron LI dhcp_arp_address(struct interface *ifp)
24597827cba2SAaron LI {
24607827cba2SAaron LI 	struct dhcp_state *state;
24617827cba2SAaron LI 	struct in_addr addr;
24627827cba2SAaron LI 	struct ipv4_addr *ia;
24637827cba2SAaron LI 
24647827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
24657827cba2SAaron LI 
24667827cba2SAaron LI 	state = D_STATE(ifp);
24677827cba2SAaron LI 	addr.s_addr = state->offer->yiaddr == INADDR_ANY ?
24687827cba2SAaron LI 	    state->offer->ciaddr : state->offer->yiaddr;
24697827cba2SAaron LI 	/* If the interface already has the address configured
24707827cba2SAaron LI 	 * then we can't ARP for duplicate detection. */
24717827cba2SAaron LI 	ia = ipv4_iffindaddr(ifp, &addr, NULL);
24728d36e1dfSRoy Marples #ifdef IN_IFF_NOTUSEABLE
24737827cba2SAaron LI 	if (ia == NULL || ia->addr_flags & IN_IFF_NOTUSEABLE) {
24747827cba2SAaron LI 		state->state = DHS_PROBE;
24757827cba2SAaron LI 		if (ia == NULL) {
24767827cba2SAaron LI 			struct dhcp_lease l;
24777827cba2SAaron LI 
24787827cba2SAaron LI 			get_lease(ifp, &l, state->offer, state->offer_len);
24797827cba2SAaron LI 			/* Add the address now, let the kernel handle DAD. */
24808d36e1dfSRoy Marples 			ipv4_addaddr(ifp, &l.addr, &l.mask, &l.brd,
24818d36e1dfSRoy Marples 			    l.leasetime, l.rebindtime);
24821b3b16a2SRoy Marples 		} else if (ia->addr_flags & IN_IFF_DUPLICATED)
24831b3b16a2SRoy Marples 			dhcp_addr_duplicated(ifp, &ia->addr);
24841b3b16a2SRoy Marples 		else
24857827cba2SAaron LI 			loginfox("%s: waiting for DAD on %s",
24867827cba2SAaron LI 			    ifp->name, inet_ntoa(addr));
24877827cba2SAaron LI 		return 0;
24887827cba2SAaron LI 	}
24897827cba2SAaron LI #else
24908d36e1dfSRoy Marples 	if (!(ifp->flags & IFF_NOARP) &&
24916e63cc1fSRoy Marples 	    ifp->options->options & DHCPCD_ARP)
24928d36e1dfSRoy Marples 	{
24938d36e1dfSRoy Marples 		struct arp_state *astate;
24947827cba2SAaron LI 		struct dhcp_lease l;
24957827cba2SAaron LI 
24966e63cc1fSRoy Marples 		/* Even if the address exists, we need to defend it. */
24978d36e1dfSRoy Marples 		astate = dhcp_arp_new(ifp, &addr);
24988d36e1dfSRoy Marples 		if (astate == NULL)
24998d36e1dfSRoy Marples 			return -1;
25008d36e1dfSRoy Marples 
25016e63cc1fSRoy Marples 		if (ia == NULL) {
25027827cba2SAaron LI 			state->state = DHS_PROBE;
25037827cba2SAaron LI 			get_lease(ifp, &l, state->offer, state->offer_len);
25047827cba2SAaron LI 			loginfox("%s: probing address %s/%d",
25057827cba2SAaron LI 			    ifp->name, inet_ntoa(l.addr), inet_ntocidr(l.mask));
25067827cba2SAaron LI 			/* We need to handle DAD. */
25077827cba2SAaron LI 			arp_probe(astate);
25087827cba2SAaron LI 			return 0;
25097827cba2SAaron LI 		}
25106e63cc1fSRoy Marples 	}
25117827cba2SAaron LI #endif
25127827cba2SAaron LI 
25137827cba2SAaron LI 	return 1;
25147827cba2SAaron LI }
25157827cba2SAaron LI 
25167827cba2SAaron LI static void
dhcp_arp_bind(struct interface * ifp)25177827cba2SAaron LI dhcp_arp_bind(struct interface *ifp)
25187827cba2SAaron LI {
25197827cba2SAaron LI 
25208d36e1dfSRoy Marples 	if (ifp->ctx->options & DHCPCD_TEST ||
25218d36e1dfSRoy Marples 	    dhcp_arp_address(ifp) == 1)
25227827cba2SAaron LI 		dhcp_bind(ifp);
25237827cba2SAaron LI }
25247827cba2SAaron LI #endif
25257827cba2SAaron LI 
25267827cba2SAaron LI static void
dhcp_lastlease(void * arg)2527b8b69544SRoy Marples dhcp_lastlease(void *arg)
2528b8b69544SRoy Marples {
2529b8b69544SRoy Marples 	struct interface *ifp = arg;
2530b8b69544SRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
2531b8b69544SRoy Marples 
2532b8b69544SRoy Marples 	loginfox("%s: timed out contacting a DHCP server, using last lease",
2533b8b69544SRoy Marples 	    ifp->name);
2534b8b69544SRoy Marples #if defined(ARP) || defined(KERNEL_RFC5227)
2535b8b69544SRoy Marples 	dhcp_arp_bind(ifp);
2536b8b69544SRoy Marples #else
2537b8b69544SRoy Marples 	dhcp_bind(ifp);
2538b8b69544SRoy Marples #endif
2539b8b69544SRoy Marples 	/* Set expired here because dhcp_bind() -> ipv4_addaddr() will reset
2540b8b69544SRoy Marples 	 * state */
2541b8b69544SRoy Marples 	state->added |= STATE_EXPIRED;
2542b8b69544SRoy Marples 	state->interval = 0;
2543b8b69544SRoy Marples 	dhcp_discover(ifp);
2544b8b69544SRoy Marples }
2545b8b69544SRoy Marples 
2546b8b69544SRoy Marples static void
dhcp_static(struct interface * ifp)25477827cba2SAaron LI dhcp_static(struct interface *ifp)
25487827cba2SAaron LI {
25497827cba2SAaron LI 	struct if_options *ifo;
25507827cba2SAaron LI 	struct dhcp_state *state;
25517827cba2SAaron LI 	struct ipv4_addr *ia;
25527827cba2SAaron LI 
25537827cba2SAaron LI 	state = D_STATE(ifp);
25547827cba2SAaron LI 	ifo = ifp->options;
25557827cba2SAaron LI 
25567827cba2SAaron LI 	ia = NULL;
25577827cba2SAaron LI 	if (ifo->req_addr.s_addr == INADDR_ANY &&
25587827cba2SAaron LI 	    (ia = ipv4_iffindaddr(ifp, NULL, NULL)) == NULL)
25597827cba2SAaron LI 	{
25607827cba2SAaron LI 		loginfox("%s: waiting for 3rd party to "
25617827cba2SAaron LI 		    "configure IP address", ifp->name);
25627827cba2SAaron LI 		state->reason = "3RDPARTY";
25637827cba2SAaron LI 		script_runreason(ifp, state->reason);
25647827cba2SAaron LI 		return;
25657827cba2SAaron LI 	}
25667827cba2SAaron LI 
25677827cba2SAaron LI 	state->offer_len = dhcp_message_new(&state->offer,
25687827cba2SAaron LI 	    ia ? &ia->addr : &ifo->req_addr,
25697827cba2SAaron LI 	    ia ? &ia->mask : &ifo->req_mask);
25707827cba2SAaron LI 	if (state->offer_len)
25718d36e1dfSRoy Marples #if defined(ARP) || defined(KERNEL_RFC5227)
25727827cba2SAaron LI 		dhcp_arp_bind(ifp);
25737827cba2SAaron LI #else
25747827cba2SAaron LI 		dhcp_bind(ifp);
25757827cba2SAaron LI #endif
25767827cba2SAaron LI }
25777827cba2SAaron LI 
25787827cba2SAaron LI void
dhcp_inform(struct interface * ifp)25797827cba2SAaron LI dhcp_inform(struct interface *ifp)
25807827cba2SAaron LI {
25817827cba2SAaron LI 	struct dhcp_state *state;
25827827cba2SAaron LI 	struct if_options *ifo;
25837827cba2SAaron LI 	struct ipv4_addr *ia;
25847827cba2SAaron LI 
25857827cba2SAaron LI 	state = D_STATE(ifp);
25867827cba2SAaron LI 	ifo = ifp->options;
25877827cba2SAaron LI 
25887827cba2SAaron LI 	free(state->offer);
25897827cba2SAaron LI 	state->offer = NULL;
25907827cba2SAaron LI 	state->offer_len = 0;
25917827cba2SAaron LI 
25927827cba2SAaron LI 	if (ifo->req_addr.s_addr == INADDR_ANY) {
25937827cba2SAaron LI 		ia = ipv4_iffindaddr(ifp, NULL, NULL);
25947827cba2SAaron LI 		if (ia == NULL) {
25957827cba2SAaron LI 			loginfox("%s: waiting for 3rd party to "
25967827cba2SAaron LI 			    "configure IP address",
25977827cba2SAaron LI 			    ifp->name);
25987827cba2SAaron LI 			if (!(ifp->ctx->options & DHCPCD_TEST)) {
25997827cba2SAaron LI 				state->reason = "3RDPARTY";
26007827cba2SAaron LI 				script_runreason(ifp, state->reason);
26017827cba2SAaron LI 			}
26027827cba2SAaron LI 			return;
26037827cba2SAaron LI 		}
26047827cba2SAaron LI 	} else {
26057827cba2SAaron LI 		ia = ipv4_iffindaddr(ifp, &ifo->req_addr, &ifo->req_mask);
26067827cba2SAaron LI 		if (ia == NULL) {
26077827cba2SAaron LI 			if (ifp->ctx->options & DHCPCD_TEST) {
26087827cba2SAaron LI 				logerrx("%s: cannot add IP address in test mode",
26097827cba2SAaron LI 				    ifp->name);
26107827cba2SAaron LI 				return;
26117827cba2SAaron LI 			}
26127827cba2SAaron LI 			ia = ipv4_iffindaddr(ifp, &ifo->req_addr, NULL);
26137827cba2SAaron LI 			if (ia != NULL)
26147827cba2SAaron LI 				/* Netmask must be different, delete it. */
26157827cba2SAaron LI 				ipv4_deladdr(ia, 1);
26167827cba2SAaron LI 			state->offer_len = dhcp_message_new(&state->offer,
26177827cba2SAaron LI 			    &ifo->req_addr, &ifo->req_mask);
26187827cba2SAaron LI #ifdef ARP
2619ce6cc02eSRoy Marples 			if (dhcp_arp_address(ifp) != 1)
26207827cba2SAaron LI 				return;
26217827cba2SAaron LI #endif
26227827cba2SAaron LI 			ia = ipv4_iffindaddr(ifp,
26237827cba2SAaron LI 			    &ifo->req_addr, &ifo->req_mask);
26247827cba2SAaron LI 			assert(ia != NULL);
26257827cba2SAaron LI 		}
26267827cba2SAaron LI 	}
26277827cba2SAaron LI 
26280a68f8d2SRoy Marples 	state->state = DHS_INFORM;
26297827cba2SAaron LI 	state->addr = ia;
26307827cba2SAaron LI 	state->offer_len = dhcp_message_new(&state->offer,
26317827cba2SAaron LI 	    &ia->addr, &ia->mask);
26327827cba2SAaron LI 	if (state->offer_len) {
26337827cba2SAaron LI 		dhcp_new_xid(ifp);
26347827cba2SAaron LI 		get_lease(ifp, &state->lease, state->offer, state->offer_len);
26357827cba2SAaron LI 		send_inform(ifp);
26367827cba2SAaron LI 	}
26377827cba2SAaron LI }
26387827cba2SAaron LI 
26397827cba2SAaron LI void
dhcp_reboot_newopts(struct interface * ifp,unsigned long long oldopts)26407827cba2SAaron LI dhcp_reboot_newopts(struct interface *ifp, unsigned long long oldopts)
26417827cba2SAaron LI {
26427827cba2SAaron LI 	struct if_options *ifo;
26437827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
26447827cba2SAaron LI 
26457827cba2SAaron LI 	if (state == NULL || state->state == DHS_NONE)
26467827cba2SAaron LI 		return;
26477827cba2SAaron LI 	ifo = ifp->options;
26487827cba2SAaron LI 	if ((ifo->options & (DHCPCD_INFORM | DHCPCD_STATIC) &&
26497827cba2SAaron LI 		(state->addr == NULL ||
26507827cba2SAaron LI 		state->addr->addr.s_addr != ifo->req_addr.s_addr)) ||
26517827cba2SAaron LI 	    (oldopts & (DHCPCD_INFORM | DHCPCD_STATIC) &&
26527827cba2SAaron LI 		!(ifo->options & (DHCPCD_INFORM | DHCPCD_STATIC))))
26537827cba2SAaron LI 	{
26547827cba2SAaron LI 		dhcp_drop(ifp, "EXPIRE");
26557827cba2SAaron LI 	}
26567827cba2SAaron LI }
26577827cba2SAaron LI 
26587827cba2SAaron LI #ifdef ARP
26597827cba2SAaron LI static int
dhcp_activeaddr(const struct interface * ifp,const struct in_addr * addr)26607827cba2SAaron LI dhcp_activeaddr(const struct interface *ifp, const struct in_addr *addr)
26617827cba2SAaron LI {
26627827cba2SAaron LI 	const struct interface *ifp1;
26637827cba2SAaron LI 	const struct dhcp_state *state;
26647827cba2SAaron LI 
26657827cba2SAaron LI 	TAILQ_FOREACH(ifp1, ifp->ctx->ifaces, next) {
26667827cba2SAaron LI 		if (ifp1 == ifp)
26677827cba2SAaron LI 			continue;
26687827cba2SAaron LI 		if ((state = D_CSTATE(ifp1)) == NULL)
26697827cba2SAaron LI 			continue;
26707827cba2SAaron LI 		switch(state->state) {
26717827cba2SAaron LI 		case DHS_REBOOT:
26727827cba2SAaron LI 		case DHS_RENEW:
26737827cba2SAaron LI 		case DHS_REBIND:
26747827cba2SAaron LI 		case DHS_BOUND:
26757827cba2SAaron LI 		case DHS_INFORM:
26767827cba2SAaron LI 			break;
26777827cba2SAaron LI 		default:
26787827cba2SAaron LI 			continue;
26797827cba2SAaron LI 		}
26807827cba2SAaron LI 		if (state->lease.addr.s_addr == addr->s_addr)
26817827cba2SAaron LI 			return 1;
26827827cba2SAaron LI 	}
26837827cba2SAaron LI 	return 0;
26847827cba2SAaron LI }
26857827cba2SAaron LI #endif
26867827cba2SAaron LI 
26877827cba2SAaron LI static void
dhcp_reboot(struct interface * ifp)26887827cba2SAaron LI dhcp_reboot(struct interface *ifp)
26897827cba2SAaron LI {
26907827cba2SAaron LI 	struct if_options *ifo;
26917827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
26927827cba2SAaron LI #ifdef ARP
26937827cba2SAaron LI 	struct ipv4_addr *ia;
26947827cba2SAaron LI #endif
26957827cba2SAaron LI 
26967827cba2SAaron LI 	if (state == NULL || state->state == DHS_NONE)
26977827cba2SAaron LI 		return;
26987827cba2SAaron LI 	ifo = ifp->options;
26997827cba2SAaron LI 	state->state = DHS_REBOOT;
27007827cba2SAaron LI 	state->interval = 0;
27017827cba2SAaron LI 
270293ddca5eSRoy Marples 	if (ifo->options & DHCPCD_LINK && !if_is_link_up(ifp)) {
27037827cba2SAaron LI 		loginfox("%s: waiting for carrier", ifp->name);
27047827cba2SAaron LI 		return;
27057827cba2SAaron LI 	}
27067827cba2SAaron LI 	if (ifo->options & DHCPCD_STATIC) {
27077827cba2SAaron LI 		dhcp_static(ifp);
27087827cba2SAaron LI 		return;
27097827cba2SAaron LI 	}
27107827cba2SAaron LI 	if (ifo->options & DHCPCD_INFORM) {
27117827cba2SAaron LI 		loginfox("%s: informing address of %s",
27127827cba2SAaron LI 		    ifp->name, inet_ntoa(state->lease.addr));
27137827cba2SAaron LI 		dhcp_inform(ifp);
27147827cba2SAaron LI 		return;
27157827cba2SAaron LI 	}
27167827cba2SAaron LI 	if (ifo->reboot == 0 || state->offer == NULL) {
27177827cba2SAaron LI 		dhcp_discover(ifp);
27187827cba2SAaron LI 		return;
27197827cba2SAaron LI 	}
27207827cba2SAaron LI 	if (!IS_DHCP(state->offer))
27217827cba2SAaron LI 		return;
27227827cba2SAaron LI 
27237827cba2SAaron LI 	loginfox("%s: rebinding lease of %s",
27247827cba2SAaron LI 	    ifp->name, inet_ntoa(state->lease.addr));
27257827cba2SAaron LI 
27267827cba2SAaron LI #ifdef ARP
2727b9ccd228SRoy Marples #ifndef KERNEL_RFC5227
2728b9ccd228SRoy Marples 	/* Create the DHCP ARP state so we can defend it. */
2729b9ccd228SRoy Marples 	(void)dhcp_arp_new(ifp, &state->lease.addr);
2730b9ccd228SRoy Marples #endif
2731b9ccd228SRoy Marples 
27327827cba2SAaron LI 	/* If the address exists on the interface and no other interface
27337827cba2SAaron LI 	 * is currently using it then announce it to ensure this
27347827cba2SAaron LI 	 * interface gets the reply. */
27357827cba2SAaron LI 	ia = ipv4_iffindaddr(ifp, &state->lease.addr, NULL);
27367827cba2SAaron LI 	if (ia != NULL &&
27378d36e1dfSRoy Marples 	    !(ifp->ctx->options & DHCPCD_TEST) &&
27387827cba2SAaron LI #ifdef IN_IFF_NOTUSEABLE
27397827cba2SAaron LI 	    !(ia->addr_flags & IN_IFF_NOTUSEABLE) &&
27407827cba2SAaron LI #endif
27417827cba2SAaron LI 	    dhcp_activeaddr(ifp, &state->lease.addr) == 0)
27427827cba2SAaron LI 		arp_ifannounceaddr(ifp, &state->lease.addr);
27437827cba2SAaron LI #endif
27447827cba2SAaron LI 
27457827cba2SAaron LI 	dhcp_new_xid(ifp);
27467827cba2SAaron LI 	state->lease.server.s_addr = INADDR_ANY;
27477827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
27487827cba2SAaron LI 
27497827cba2SAaron LI #ifdef IPV4LL
27507827cba2SAaron LI 	/* Need to add this before dhcp_expire and friends. */
27517827cba2SAaron LI 	if (!ifo->fallback && ifo->options & DHCPCD_IPV4LL)
27527827cba2SAaron LI 		eloop_timeout_add_sec(ifp->ctx->eloop,
2753*54175cefSRoy Marples 		    ifo->ipv4ll_time, ipv4ll_start, ifp);
27547827cba2SAaron LI #endif
27557827cba2SAaron LI 
27567827cba2SAaron LI 	if (ifo->options & DHCPCD_LASTLEASE && state->lease.frominfo)
27577827cba2SAaron LI 		eloop_timeout_add_sec(ifp->ctx->eloop,
27587827cba2SAaron LI 		    ifo->reboot, dhcp_lastlease, ifp);
27597827cba2SAaron LI 	else if (!(ifo->options & DHCPCD_INFORM))
27607827cba2SAaron LI 		eloop_timeout_add_sec(ifp->ctx->eloop,
27617827cba2SAaron LI 		    ifo->reboot, dhcp_expire, ifp);
27627827cba2SAaron LI 
27637827cba2SAaron LI 	/* Don't bother ARP checking as the server could NAK us first.
27647827cba2SAaron LI 	 * Don't call dhcp_request as that would change the state */
27657827cba2SAaron LI 	send_request(ifp);
27667827cba2SAaron LI }
27677827cba2SAaron LI 
27687827cba2SAaron LI void
dhcp_drop(struct interface * ifp,const char * reason)27697827cba2SAaron LI dhcp_drop(struct interface *ifp, const char *reason)
27707827cba2SAaron LI {
277180aa9461SRoy Marples 	struct dhcp_state *state = D_STATE(ifp);
27727827cba2SAaron LI 
27737827cba2SAaron LI 	/* dhcp_start may just have been called and we don't yet have a state
27747827cba2SAaron LI 	 * but we do have a timeout, so punt it. */
27757827cba2SAaron LI 	if (state == NULL || state->state == DHS_NONE) {
27767827cba2SAaron LI 		eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
27777827cba2SAaron LI 		return;
27787827cba2SAaron LI 	}
27797827cba2SAaron LI 
27808d36e1dfSRoy Marples #ifdef ARP
27818d36e1dfSRoy Marples 	if (state->addr != NULL)
27828d36e1dfSRoy Marples 		arp_freeaddr(ifp, &state->addr->addr);
27838d36e1dfSRoy Marples #endif
27847827cba2SAaron LI #ifdef ARPING
27857827cba2SAaron LI 	state->arping_index = -1;
27867827cba2SAaron LI #endif
27878d36e1dfSRoy Marples 
27887827cba2SAaron LI 	if (ifp->options->options & DHCPCD_RELEASE &&
27897827cba2SAaron LI 	    !(ifp->options->options & DHCPCD_INFORM))
27907827cba2SAaron LI 	{
27917827cba2SAaron LI 		/* Failure to send the release may cause this function to
27927827cba2SAaron LI 		 * re-enter so guard by setting the state. */
27937827cba2SAaron LI 		if (state->state == DHS_RELEASE)
27947827cba2SAaron LI 			return;
27957827cba2SAaron LI 		state->state = DHS_RELEASE;
27967827cba2SAaron LI 
2797d4fb1e02SRoy Marples 		dhcp_unlink(ifp->ctx, state->leasefile);
279893ddca5eSRoy Marples 		if (if_is_link_up(ifp) &&
27997827cba2SAaron LI 		    state->new != NULL &&
28007827cba2SAaron LI 		    state->lease.server.s_addr != INADDR_ANY)
28017827cba2SAaron LI 		{
28027827cba2SAaron LI 			loginfox("%s: releasing lease of %s",
28037827cba2SAaron LI 			    ifp->name, inet_ntoa(state->lease.addr));
28047827cba2SAaron LI 			dhcp_new_xid(ifp);
28057827cba2SAaron LI 			send_message(ifp, DHCP_RELEASE, NULL);
28067827cba2SAaron LI 		}
28077827cba2SAaron LI 	}
2808acd7a309SRoy Marples #ifdef AUTH
2809acd7a309SRoy Marples 	else if (state->auth.reconf != NULL) {
2810acd7a309SRoy Marples 		/*
2811acd7a309SRoy Marples 		 * Drop the lease as the token may only be present
2812acd7a309SRoy Marples 		 * in the initial reply message and not subsequent
2813acd7a309SRoy Marples 		 * renewals.
2814acd7a309SRoy Marples 		 * If dhcpcd is restarted, the token is lost.
2815acd7a309SRoy Marples 		 * XXX persist this in another file?
2816acd7a309SRoy Marples 		 */
2817acd7a309SRoy Marples 		dhcp_unlink(ifp->ctx, state->leasefile);
2818acd7a309SRoy Marples 	}
2819acd7a309SRoy Marples #endif
28207827cba2SAaron LI 
28217827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
28227827cba2SAaron LI #ifdef AUTH
28237827cba2SAaron LI 	dhcp_auth_reset(&state->auth);
28247827cba2SAaron LI #endif
28257827cba2SAaron LI 
28267827cba2SAaron LI 	state->state = DHS_NONE;
28277827cba2SAaron LI 	free(state->offer);
28287827cba2SAaron LI 	state->offer = NULL;
28297827cba2SAaron LI 	state->offer_len = 0;
28307827cba2SAaron LI 	free(state->old);
28317827cba2SAaron LI 	state->old = state->new;
28327827cba2SAaron LI 	state->old_len = state->new_len;
28337827cba2SAaron LI 	state->new = NULL;
28347827cba2SAaron LI 	state->new_len = 0;
28357827cba2SAaron LI 	state->reason = reason;
2836b2927f2bSRoy Marples 	if (ifp->options->options & DHCPCD_CONFIGURE)
28377827cba2SAaron LI 		ipv4_applyaddr(ifp);
2838b2927f2bSRoy Marples 	else {
2839b2927f2bSRoy Marples 		state->addr = NULL;
2840b2927f2bSRoy Marples 		state->added = 0;
2841b2927f2bSRoy Marples 		script_runreason(ifp, state->reason);
2842b2927f2bSRoy Marples 	}
28437827cba2SAaron LI 	free(state->old);
28447827cba2SAaron LI 	state->old = NULL;
28457827cba2SAaron LI 	state->old_len = 0;
28467827cba2SAaron LI 	state->lease.addr.s_addr = 0;
28477827cba2SAaron LI 	ifp->options->options &= ~(DHCPCD_CSR_WARNED |
28487827cba2SAaron LI 	    DHCPCD_ROUTER_HOST_ROUTE_WARNED);
284980aa9461SRoy Marples 
285080aa9461SRoy Marples 	/* Close DHCP ports so a changed interface family is picked
285180aa9461SRoy Marples 	 * up by a new BPF state. */
285280aa9461SRoy Marples 	dhcp_close(ifp);
28537827cba2SAaron LI }
28547827cba2SAaron LI 
28557827cba2SAaron LI static int
blacklisted_ip(const struct if_options * ifo,in_addr_t addr)28567827cba2SAaron LI blacklisted_ip(const struct if_options *ifo, in_addr_t addr)
28577827cba2SAaron LI {
28587827cba2SAaron LI 	size_t i;
28597827cba2SAaron LI 
28607827cba2SAaron LI 	for (i = 0; i < ifo->blacklist_len; i += 2)
28617827cba2SAaron LI 		if (ifo->blacklist[i] == (addr & ifo->blacklist[i + 1]))
28627827cba2SAaron LI 			return 1;
28637827cba2SAaron LI 	return 0;
28647827cba2SAaron LI }
28657827cba2SAaron LI 
28667827cba2SAaron LI #define	WHTLST_NONE	0
28677827cba2SAaron LI #define	WHTLST_MATCH	1
28687827cba2SAaron LI #define WHTLST_NOMATCH	2
28697827cba2SAaron LI static unsigned int
whitelisted_ip(const struct if_options * ifo,in_addr_t addr)28707827cba2SAaron LI whitelisted_ip(const struct if_options *ifo, in_addr_t addr)
28717827cba2SAaron LI {
28727827cba2SAaron LI 	size_t i;
28737827cba2SAaron LI 
28747827cba2SAaron LI 	if (ifo->whitelist_len == 0)
28757827cba2SAaron LI 		return WHTLST_NONE;
28767827cba2SAaron LI 	for (i = 0; i < ifo->whitelist_len; i += 2)
28777827cba2SAaron LI 		if (ifo->whitelist[i] == (addr & ifo->whitelist[i + 1]))
28787827cba2SAaron LI 			return WHTLST_MATCH;
28797827cba2SAaron LI 	return WHTLST_NOMATCH;
28807827cba2SAaron LI }
28817827cba2SAaron LI 
28827827cba2SAaron LI static void
log_dhcp(int loglevel,const char * msg,const struct interface * ifp,const struct bootp * bootp,size_t bootp_len,const struct in_addr * from,int ad)28836e63cc1fSRoy Marples log_dhcp(int loglevel, const char *msg,
28847827cba2SAaron LI     const struct interface *ifp, const struct bootp *bootp, size_t bootp_len,
28857827cba2SAaron LI     const struct in_addr *from, int ad)
28867827cba2SAaron LI {
28877827cba2SAaron LI 	const char *tfrom;
28887827cba2SAaron LI 	char *a, sname[sizeof(bootp->sname) * 4];
28897827cba2SAaron LI 	struct in_addr addr;
28907827cba2SAaron LI 	int r;
28917827cba2SAaron LI 	uint8_t overl;
28927827cba2SAaron LI 
28937827cba2SAaron LI 	if (strcmp(msg, "NAK:") == 0) {
28947827cba2SAaron LI 		a = get_option_string(ifp->ctx, bootp, bootp_len, DHO_MESSAGE);
28957827cba2SAaron LI 		if (a) {
28967827cba2SAaron LI 			char *tmp;
28977827cba2SAaron LI 			size_t al, tmpl;
28987827cba2SAaron LI 
28997827cba2SAaron LI 			al = strlen(a);
29007827cba2SAaron LI 			tmpl = (al * 4) + 1;
29017827cba2SAaron LI 			tmp = malloc(tmpl);
29027827cba2SAaron LI 			if (tmp == NULL) {
29037827cba2SAaron LI 				logerr(__func__);
29047827cba2SAaron LI 				free(a);
29057827cba2SAaron LI 				return;
29067827cba2SAaron LI 			}
29077827cba2SAaron LI 			print_string(tmp, tmpl, OT_STRING, (uint8_t *)a, al);
29087827cba2SAaron LI 			free(a);
29097827cba2SAaron LI 			a = tmp;
29107827cba2SAaron LI 		}
29117827cba2SAaron LI 	} else if (ad && bootp->yiaddr != 0) {
29127827cba2SAaron LI 		addr.s_addr = bootp->yiaddr;
29137827cba2SAaron LI 		a = strdup(inet_ntoa(addr));
29147827cba2SAaron LI 		if (a == NULL) {
29157827cba2SAaron LI 			logerr(__func__);
29167827cba2SAaron LI 			return;
29177827cba2SAaron LI 		}
29187827cba2SAaron LI 	} else
29197827cba2SAaron LI 		a = NULL;
29207827cba2SAaron LI 
29217827cba2SAaron LI 	tfrom = "from";
29227827cba2SAaron LI 	r = get_option_addr(ifp->ctx, &addr, bootp, bootp_len, DHO_SERVERID);
29237827cba2SAaron LI 	if (get_option_uint8(ifp->ctx, &overl, bootp, bootp_len,
29247827cba2SAaron LI 	    DHO_OPTSOVERLOADED) == -1)
29257827cba2SAaron LI 		overl = 0;
29267827cba2SAaron LI 	if (bootp->sname[0] && r == 0 && !(overl & 2)) {
29277827cba2SAaron LI 		print_string(sname, sizeof(sname), OT_STRING | OT_DOMAIN,
29287827cba2SAaron LI 		    bootp->sname, sizeof(bootp->sname));
29297827cba2SAaron LI 		if (a == NULL)
2930a0d9933aSRoy Marples 			logmessage(loglevel, "%s: %s %s %s %s",
29317827cba2SAaron LI 			    ifp->name, msg, tfrom, inet_ntoa(addr), sname);
29327827cba2SAaron LI 		else
2933a0d9933aSRoy Marples 			logmessage(loglevel, "%s: %s %s %s %s %s",
29347827cba2SAaron LI 			    ifp->name, msg, a, tfrom, inet_ntoa(addr), sname);
29357827cba2SAaron LI 	} else {
29367827cba2SAaron LI 		if (r != 0) {
29377827cba2SAaron LI 			tfrom = "via";
29387827cba2SAaron LI 			addr = *from;
29397827cba2SAaron LI 		}
29407827cba2SAaron LI 		if (a == NULL)
29416e63cc1fSRoy Marples 			logmessage(loglevel, "%s: %s %s %s",
29427827cba2SAaron LI 			    ifp->name, msg, tfrom, inet_ntoa(addr));
29437827cba2SAaron LI 		else
29446e63cc1fSRoy Marples 			logmessage(loglevel, "%s: %s %s %s %s",
29457827cba2SAaron LI 			    ifp->name, msg, a, tfrom, inet_ntoa(addr));
29467827cba2SAaron LI 	}
29477827cba2SAaron LI 	free(a);
29487827cba2SAaron LI }
29497827cba2SAaron LI 
29507827cba2SAaron LI /* If we're sharing the same IP address with another interface on the
29517827cba2SAaron LI  * same network, we may receive the DHCP reply on the wrong interface.
29527827cba2SAaron LI  * Try and re-direct it here. */
29537827cba2SAaron LI static void
dhcp_redirect_dhcp(struct interface * ifp,struct bootp * bootp,size_t bootp_len,const struct in_addr * from)29547827cba2SAaron LI dhcp_redirect_dhcp(struct interface *ifp, struct bootp *bootp, size_t bootp_len,
29557827cba2SAaron LI     const struct in_addr *from)
29567827cba2SAaron LI {
29577827cba2SAaron LI 	struct interface *ifn;
29587827cba2SAaron LI 	const struct dhcp_state *state;
29597827cba2SAaron LI 	uint32_t xid;
29607827cba2SAaron LI 
29617827cba2SAaron LI 	xid = ntohl(bootp->xid);
29627827cba2SAaron LI 	TAILQ_FOREACH(ifn, ifp->ctx->ifaces, next) {
29636e63cc1fSRoy Marples 		if (ifn == ifp)
29646e63cc1fSRoy Marples 			continue;
29657827cba2SAaron LI 		state = D_CSTATE(ifn);
29667827cba2SAaron LI 		if (state == NULL || state->state == DHS_NONE)
29677827cba2SAaron LI 			continue;
29687827cba2SAaron LI 		if (state->xid != xid)
29697827cba2SAaron LI 			continue;
29707827cba2SAaron LI 		if (ifn->hwlen <= sizeof(bootp->chaddr) &&
29717827cba2SAaron LI 		    memcmp(bootp->chaddr, ifn->hwaddr, ifn->hwlen))
29727827cba2SAaron LI 			continue;
29737827cba2SAaron LI 		logdebugx("%s: redirecting DHCP message to %s",
29747827cba2SAaron LI 		    ifp->name, ifn->name);
29757827cba2SAaron LI 		dhcp_handledhcp(ifn, bootp, bootp_len, from);
29767827cba2SAaron LI 	}
29777827cba2SAaron LI }
29787827cba2SAaron LI 
29797827cba2SAaron LI static void
dhcp_handledhcp(struct interface * ifp,struct bootp * bootp,size_t bootp_len,const struct in_addr * from)29807827cba2SAaron LI dhcp_handledhcp(struct interface *ifp, struct bootp *bootp, size_t bootp_len,
29817827cba2SAaron LI     const struct in_addr *from)
29827827cba2SAaron LI {
29837827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
29847827cba2SAaron LI 	struct if_options *ifo = ifp->options;
29857827cba2SAaron LI 	struct dhcp_lease *lease = &state->lease;
29867827cba2SAaron LI 	uint8_t type, tmp;
29877827cba2SAaron LI 	struct in_addr addr;
29887827cba2SAaron LI 	unsigned int i;
29897827cba2SAaron LI 	char *msg;
29907827cba2SAaron LI 	bool bootp_copied;
299139994b17SRoy Marples 	uint32_t v6only_time = 0;
299239994b17SRoy Marples 	bool use_v6only = false;
29937827cba2SAaron LI #ifdef AUTH
29947827cba2SAaron LI 	const uint8_t *auth;
29957827cba2SAaron LI 	size_t auth_len;
29967827cba2SAaron LI #endif
29977827cba2SAaron LI #ifdef IN_IFF_DUPLICATED
29987827cba2SAaron LI 	struct ipv4_addr *ia;
29997827cba2SAaron LI #endif
30007827cba2SAaron LI 
30017827cba2SAaron LI #define LOGDHCP0(l, m) \
30027827cba2SAaron LI 	log_dhcp((l), (m), ifp, bootp, bootp_len, from, 0)
30037827cba2SAaron LI #define LOGDHCP(l, m) \
30047827cba2SAaron LI 	log_dhcp((l), (m), ifp, bootp, bootp_len, from, 1)
30057827cba2SAaron LI 
30061b3b16a2SRoy Marples #define IS_STATE_ACTIVE(s) ((s)-state != DHS_NONE && \
30071b3b16a2SRoy Marples 	(s)->state != DHS_INIT && (s)->state != DHS_BOUND)
30081b3b16a2SRoy Marples 
30097827cba2SAaron LI 	if (bootp->op != BOOTREPLY) {
30101b3b16a2SRoy Marples 		if (IS_STATE_ACTIVE(state))
30117827cba2SAaron LI 			logdebugx("%s: op (%d) is not BOOTREPLY",
30127827cba2SAaron LI 			    ifp->name, bootp->op);
30137827cba2SAaron LI 		return;
30147827cba2SAaron LI 	}
30157827cba2SAaron LI 
30167827cba2SAaron LI 	if (state->xid != ntohl(bootp->xid)) {
30171b3b16a2SRoy Marples 		if (IS_STATE_ACTIVE(state))
30187827cba2SAaron LI 			logdebugx("%s: wrong xid 0x%x (expecting 0x%x) from %s",
30197827cba2SAaron LI 			    ifp->name, ntohl(bootp->xid), state->xid,
30207827cba2SAaron LI 			    inet_ntoa(*from));
30217827cba2SAaron LI 		dhcp_redirect_dhcp(ifp, bootp, bootp_len, from);
30227827cba2SAaron LI 		return;
30237827cba2SAaron LI 	}
30247827cba2SAaron LI 
30257827cba2SAaron LI 	if (ifp->hwlen <= sizeof(bootp->chaddr) &&
30267827cba2SAaron LI 	    memcmp(bootp->chaddr, ifp->hwaddr, ifp->hwlen))
30277827cba2SAaron LI 	{
30281b3b16a2SRoy Marples 		if (IS_STATE_ACTIVE(state)) {
30297827cba2SAaron LI 			char buf[sizeof(bootp->chaddr) * 3];
30307827cba2SAaron LI 
30317827cba2SAaron LI 			logdebugx("%s: xid 0x%x is for hwaddr %s",
30327827cba2SAaron LI 			    ifp->name, ntohl(bootp->xid),
30337827cba2SAaron LI 			    hwaddr_ntoa(bootp->chaddr, sizeof(bootp->chaddr),
30347827cba2SAaron LI 				    buf, sizeof(buf)));
30351b3b16a2SRoy Marples 		}
30367827cba2SAaron LI 		dhcp_redirect_dhcp(ifp, bootp, bootp_len, from);
30377827cba2SAaron LI 		return;
30387827cba2SAaron LI 	}
30397827cba2SAaron LI 
30407827cba2SAaron LI 	if (!ifp->active)
30417827cba2SAaron LI 		return;
30427827cba2SAaron LI 
30437827cba2SAaron LI 	i = whitelisted_ip(ifp->options, from->s_addr);
30447827cba2SAaron LI 	switch (i) {
30457827cba2SAaron LI 	case WHTLST_NOMATCH:
30467827cba2SAaron LI 		logwarnx("%s: non whitelisted DHCP packet from %s",
30477827cba2SAaron LI 		    ifp->name, inet_ntoa(*from));
30487827cba2SAaron LI 		return;
30497827cba2SAaron LI 	case WHTLST_MATCH:
30507827cba2SAaron LI 		break;
30517827cba2SAaron LI 	case WHTLST_NONE:
30527827cba2SAaron LI 		if (blacklisted_ip(ifp->options, from->s_addr) == 1) {
30537827cba2SAaron LI 			logwarnx("%s: blacklisted DHCP packet from %s",
30547827cba2SAaron LI 			    ifp->name, inet_ntoa(*from));
30557827cba2SAaron LI 			return;
30567827cba2SAaron LI 		}
30577827cba2SAaron LI 	}
30587827cba2SAaron LI 
30597827cba2SAaron LI 	/* We may have found a BOOTP server */
30607827cba2SAaron LI 	if (get_option_uint8(ifp->ctx, &type,
30617827cba2SAaron LI 	    bootp, bootp_len, DHO_MESSAGETYPE) == -1)
30627827cba2SAaron LI 		type = 0;
30637827cba2SAaron LI 	else if (ifo->options & DHCPCD_BOOTP) {
30647827cba2SAaron LI 		logdebugx("%s: ignoring DHCP reply (expecting BOOTP)",
30657827cba2SAaron LI 		    ifp->name);
30667827cba2SAaron LI 		return;
30677827cba2SAaron LI 	}
30687827cba2SAaron LI 
30697827cba2SAaron LI #ifdef AUTH
30707827cba2SAaron LI 	/* Authenticate the message */
30717827cba2SAaron LI 	auth = get_option(ifp->ctx, bootp, bootp_len,
30727827cba2SAaron LI 	    DHO_AUTHENTICATION, &auth_len);
30737827cba2SAaron LI 	if (auth) {
30747827cba2SAaron LI 		if (dhcp_auth_validate(&state->auth, &ifo->auth,
30757827cba2SAaron LI 		    (uint8_t *)bootp, bootp_len, 4, type,
30767827cba2SAaron LI 		    auth, auth_len) == NULL)
30777827cba2SAaron LI 		{
30786e63cc1fSRoy Marples 			LOGDHCP0(LOG_ERR, "authentication failed");
30797827cba2SAaron LI 			return;
30807827cba2SAaron LI 		}
30817827cba2SAaron LI 		if (state->auth.token)
30827827cba2SAaron LI 			logdebugx("%s: validated using 0x%08" PRIu32,
30837827cba2SAaron LI 			    ifp->name, state->auth.token->secretid);
30847827cba2SAaron LI 		else
30857827cba2SAaron LI 			loginfox("%s: accepted reconfigure key", ifp->name);
30867827cba2SAaron LI 	} else if (ifo->auth.options & DHCPCD_AUTH_SEND) {
30877827cba2SAaron LI 		if (ifo->auth.options & DHCPCD_AUTH_REQUIRE) {
30886e63cc1fSRoy Marples 			LOGDHCP0(LOG_ERR, "no authentication");
30897827cba2SAaron LI 			return;
30907827cba2SAaron LI 		}
30916e63cc1fSRoy Marples 		LOGDHCP0(LOG_WARNING, "no authentication");
30927827cba2SAaron LI 	}
30937827cba2SAaron LI #endif
30947827cba2SAaron LI 
30957827cba2SAaron LI 	/* RFC 3203 */
30967827cba2SAaron LI 	if (type == DHCP_FORCERENEW) {
30977827cba2SAaron LI 		if (from->s_addr == INADDR_ANY ||
30987827cba2SAaron LI 		    from->s_addr == INADDR_BROADCAST)
30997827cba2SAaron LI 		{
31006e63cc1fSRoy Marples 			LOGDHCP(LOG_ERR, "discarding Force Renew");
31017827cba2SAaron LI 			return;
31027827cba2SAaron LI 		}
31037827cba2SAaron LI #ifdef AUTH
31047827cba2SAaron LI 		if (auth == NULL) {
31056e63cc1fSRoy Marples 			LOGDHCP(LOG_ERR, "unauthenticated Force Renew");
31067827cba2SAaron LI 			if (ifo->auth.options & DHCPCD_AUTH_REQUIRE)
31077827cba2SAaron LI 				return;
31087827cba2SAaron LI 		}
31097827cba2SAaron LI 		if (state->state != DHS_BOUND && state->state != DHS_INFORM) {
31106e63cc1fSRoy Marples 			LOGDHCP(LOG_DEBUG, "not bound, ignoring Force Renew");
31117827cba2SAaron LI 			return;
31127827cba2SAaron LI 		}
31136e63cc1fSRoy Marples 		LOGDHCP(LOG_INFO, "Force Renew from");
31147827cba2SAaron LI 		/* The rebind and expire timings are still the same, we just
31157827cba2SAaron LI 		 * enter the renew state early */
31167827cba2SAaron LI 		if (state->state == DHS_BOUND)
31177827cba2SAaron LI 			dhcp_renew(ifp);
31187827cba2SAaron LI 		else {
31197827cba2SAaron LI 			eloop_timeout_delete(ifp->ctx->eloop,
31207827cba2SAaron LI 			    send_inform, ifp);
31217827cba2SAaron LI 			dhcp_inform(ifp);
31227827cba2SAaron LI 		}
31237827cba2SAaron LI #else
31246e63cc1fSRoy Marples 		LOGDHCP(LOG_ERR, "unauthenticated Force Renew");
31257827cba2SAaron LI #endif
31267827cba2SAaron LI 		return;
31277827cba2SAaron LI 	}
31287827cba2SAaron LI 
31297827cba2SAaron LI 	if (state->state == DHS_BOUND) {
31306e63cc1fSRoy Marples 		LOGDHCP(LOG_DEBUG, "bound, ignoring");
31317827cba2SAaron LI 		return;
31327827cba2SAaron LI 	}
31337827cba2SAaron LI 
31347827cba2SAaron LI 	if (state->state == DHS_PROBE) {
31357827cba2SAaron LI 		/* Ignore any DHCP messages whilst probing a lease to bind. */
31366e63cc1fSRoy Marples 		LOGDHCP(LOG_DEBUG, "probing, ignoring");
31377827cba2SAaron LI 		return;
31387827cba2SAaron LI 	}
31397827cba2SAaron LI 
31407827cba2SAaron LI 	/* reset the message counter */
31417827cba2SAaron LI 	state->interval = 0;
31427827cba2SAaron LI 
31437827cba2SAaron LI 	/* Ensure that no reject options are present */
31447827cba2SAaron LI 	for (i = 1; i < 255; i++) {
31457827cba2SAaron LI 		if (has_option_mask(ifo->rejectmask, i) &&
31467827cba2SAaron LI 		    get_option_uint8(ifp->ctx, &tmp,
31477827cba2SAaron LI 		    bootp, bootp_len, (uint8_t)i) == 0)
31487827cba2SAaron LI 		{
31496e63cc1fSRoy Marples 			LOGDHCP(LOG_WARNING, "reject DHCP");
31507827cba2SAaron LI 			return;
31517827cba2SAaron LI 		}
31527827cba2SAaron LI 	}
31537827cba2SAaron LI 
31547827cba2SAaron LI 	if (type == DHCP_NAK) {
31557827cba2SAaron LI 		/* For NAK, only check if we require the ServerID */
31567827cba2SAaron LI 		if (has_option_mask(ifo->requiremask, DHO_SERVERID) &&
31577827cba2SAaron LI 		    get_option_addr(ifp->ctx, &addr,
31587827cba2SAaron LI 		    bootp, bootp_len, DHO_SERVERID) == -1)
31597827cba2SAaron LI 		{
31606e63cc1fSRoy Marples 			LOGDHCP(LOG_WARNING, "reject NAK");
31617827cba2SAaron LI 			return;
31627827cba2SAaron LI 		}
31637827cba2SAaron LI 
31647827cba2SAaron LI 		/* We should restart on a NAK */
31656e63cc1fSRoy Marples 		LOGDHCP(LOG_WARNING, "NAK:");
31667827cba2SAaron LI 		if ((msg = get_option_string(ifp->ctx,
31677827cba2SAaron LI 		    bootp, bootp_len, DHO_MESSAGE)))
31687827cba2SAaron LI 		{
31697827cba2SAaron LI 			logwarnx("%s: message: %s", ifp->name, msg);
31707827cba2SAaron LI 			free(msg);
31717827cba2SAaron LI 		}
31727827cba2SAaron LI 		if (state->state == DHS_INFORM) /* INFORM should not be NAKed */
31737827cba2SAaron LI 			return;
31747827cba2SAaron LI 		if (!(ifp->ctx->options & DHCPCD_TEST)) {
31757827cba2SAaron LI 			dhcp_drop(ifp, "NAK");
3176d4fb1e02SRoy Marples 			dhcp_unlink(ifp->ctx, state->leasefile);
31777827cba2SAaron LI 		}
31787827cba2SAaron LI 
31797827cba2SAaron LI 		/* If we constantly get NAKS then we should slowly back off */
31807827cba2SAaron LI 		eloop_timeout_add_sec(ifp->ctx->eloop,
31817827cba2SAaron LI 		    state->nakoff, dhcp_discover, ifp);
31827827cba2SAaron LI 		if (state->nakoff == 0)
31837827cba2SAaron LI 			state->nakoff = 1;
31847827cba2SAaron LI 		else {
31857827cba2SAaron LI 			state->nakoff *= 2;
31867827cba2SAaron LI 			if (state->nakoff > NAKOFF_MAX)
31877827cba2SAaron LI 				state->nakoff = NAKOFF_MAX;
31887827cba2SAaron LI 		}
31897827cba2SAaron LI 		return;
31907827cba2SAaron LI 	}
31917827cba2SAaron LI 
31927827cba2SAaron LI 	/* Ensure that all required options are present */
31937827cba2SAaron LI 	for (i = 1; i < 255; i++) {
31947827cba2SAaron LI 		if (has_option_mask(ifo->requiremask, i) &&
31957827cba2SAaron LI 		    get_option_uint8(ifp->ctx, &tmp,
31967827cba2SAaron LI 		    bootp, bootp_len, (uint8_t)i) != 0)
31977827cba2SAaron LI 		{
31987827cba2SAaron LI 			/* If we are BOOTP, then ignore the need for serverid.
31997827cba2SAaron LI 			 * To ignore BOOTP, require dhcp_message_type.
32007827cba2SAaron LI 			 * However, nothing really stops BOOTP from providing
32017827cba2SAaron LI 			 * DHCP style options as well so the above isn't
32027827cba2SAaron LI 			 * always true. */
32037827cba2SAaron LI 			if (type == 0 && i == DHO_SERVERID)
32047827cba2SAaron LI 				continue;
32056e63cc1fSRoy Marples 			LOGDHCP(LOG_WARNING, "reject DHCP");
32067827cba2SAaron LI 			return;
32077827cba2SAaron LI 		}
32087827cba2SAaron LI 	}
32097827cba2SAaron LI 
321039994b17SRoy Marples 	if (has_option_mask(ifo->requestmask, DHO_IPV6_PREFERRED_ONLY)) {
321139994b17SRoy Marples 		if (get_option_uint32(ifp->ctx, &v6only_time, bootp, bootp_len,
3212*54175cefSRoy Marples 		    DHO_IPV6_PREFERRED_ONLY) == 0 && (state->state == DHS_DISCOVER ||
3213*54175cefSRoy Marples 		    state->state == DHS_REBOOT || state->state == DHS_NONE))
321439994b17SRoy Marples 		{
321539994b17SRoy Marples 			char v6msg[128];
321639994b17SRoy Marples 
321739994b17SRoy Marples 			use_v6only = true;
321839994b17SRoy Marples 			if (v6only_time < MIN_V6ONLY_WAIT)
321939994b17SRoy Marples 				v6only_time = MIN_V6ONLY_WAIT;
322039994b17SRoy Marples 			snprintf(v6msg, sizeof(v6msg),
322139994b17SRoy Marples 			    "IPv6-Only Preferred received (%u seconds)",
322239994b17SRoy Marples 			    v6only_time);
322339994b17SRoy Marples 			LOGDHCP(LOG_INFO, v6msg);
322439994b17SRoy Marples 		}
322539994b17SRoy Marples 	}
322639994b17SRoy Marples 
32277827cba2SAaron LI 	/* DHCP Auto-Configure, RFC 2563 */
32287827cba2SAaron LI 	if (type == DHCP_OFFER && bootp->yiaddr == 0) {
32296e63cc1fSRoy Marples 		LOGDHCP(LOG_WARNING, "no address given");
32307827cba2SAaron LI 		if ((msg = get_option_string(ifp->ctx,
32317827cba2SAaron LI 		    bootp, bootp_len, DHO_MESSAGE)))
32327827cba2SAaron LI 		{
32337827cba2SAaron LI 			logwarnx("%s: message: %s", ifp->name, msg);
32347827cba2SAaron LI 			free(msg);
32357827cba2SAaron LI 		}
32367827cba2SAaron LI #ifdef IPV4LL
32377827cba2SAaron LI 		if (state->state == DHS_DISCOVER &&
32387827cba2SAaron LI 		    get_option_uint8(ifp->ctx, &tmp, bootp, bootp_len,
32397827cba2SAaron LI 		    DHO_AUTOCONFIGURE) == 0)
32407827cba2SAaron LI 		{
32417827cba2SAaron LI 			switch (tmp) {
32427827cba2SAaron LI 			case 0:
32436e63cc1fSRoy Marples 				LOGDHCP(LOG_WARNING, "IPv4LL disabled from");
32447827cba2SAaron LI 				ipv4ll_drop(ifp);
32457827cba2SAaron LI #ifdef ARP
32467827cba2SAaron LI 				arp_drop(ifp);
32477827cba2SAaron LI #endif
32487827cba2SAaron LI 				break;
32497827cba2SAaron LI 			case 1:
32506e63cc1fSRoy Marples 				LOGDHCP(LOG_WARNING, "IPv4LL enabled from");
32517827cba2SAaron LI 				ipv4ll_start(ifp);
32527827cba2SAaron LI 				break;
32537827cba2SAaron LI 			default:
32547827cba2SAaron LI 				logerrx("%s: unknown auto configuration "
32557827cba2SAaron LI 				    "option %d",
32567827cba2SAaron LI 				    ifp->name, tmp);
32577827cba2SAaron LI 				break;
32587827cba2SAaron LI 			}
32597827cba2SAaron LI 			eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
32607827cba2SAaron LI 			eloop_timeout_add_sec(ifp->ctx->eloop,
326139994b17SRoy Marples 			    use_v6only ? v6only_time : DHCP_MAX,
326239994b17SRoy Marples 			    dhcp_discover, ifp);
32637827cba2SAaron LI 		}
32647827cba2SAaron LI #endif
32657827cba2SAaron LI 		return;
32667827cba2SAaron LI 	}
32677827cba2SAaron LI 
326839994b17SRoy Marples 	if (use_v6only) {
326939994b17SRoy Marples 		dhcp_drop(ifp, "EXPIRE");
327039994b17SRoy Marples 		dhcp_unlink(ifp->ctx, state->leasefile);
327139994b17SRoy Marples 		eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
327239994b17SRoy Marples 		eloop_timeout_add_sec(ifp->ctx->eloop, v6only_time,
327339994b17SRoy Marples 		    dhcp_discover, ifp);
327439994b17SRoy Marples 		return;
327539994b17SRoy Marples 	}
327639994b17SRoy Marples 
32777827cba2SAaron LI 	/* Ensure that the address offered is valid */
32787827cba2SAaron LI 	if ((type == 0 || type == DHCP_OFFER || type == DHCP_ACK) &&
32797827cba2SAaron LI 	    (bootp->ciaddr == INADDR_ANY || bootp->ciaddr == INADDR_BROADCAST)
32807827cba2SAaron LI 	    &&
32817827cba2SAaron LI 	    (bootp->yiaddr == INADDR_ANY || bootp->yiaddr == INADDR_BROADCAST))
32827827cba2SAaron LI 	{
32836e63cc1fSRoy Marples 		LOGDHCP(LOG_WARNING, "reject invalid address");
32847827cba2SAaron LI 		return;
32857827cba2SAaron LI 	}
32867827cba2SAaron LI 
32877827cba2SAaron LI #ifdef IN_IFF_DUPLICATED
32887827cba2SAaron LI 	ia = ipv4_iffindaddr(ifp, &lease->addr, NULL);
32897827cba2SAaron LI 	if (ia && ia->addr_flags & IN_IFF_DUPLICATED) {
32906e63cc1fSRoy Marples 		LOGDHCP(LOG_WARNING, "declined duplicate address");
32917827cba2SAaron LI 		if (type)
32927827cba2SAaron LI 			dhcp_decline(ifp);
32937827cba2SAaron LI 		ipv4_deladdr(ia, 0);
32947827cba2SAaron LI 		eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
32957827cba2SAaron LI 		eloop_timeout_add_sec(ifp->ctx->eloop,
32967827cba2SAaron LI 		    DHCP_RAND_MAX, dhcp_discover, ifp);
32977827cba2SAaron LI 		return;
32987827cba2SAaron LI 	}
32997827cba2SAaron LI #endif
33007827cba2SAaron LI 
33017827cba2SAaron LI 	bootp_copied = false;
33027827cba2SAaron LI 	if ((type == 0 || type == DHCP_OFFER) && state->state == DHS_DISCOVER) {
33037827cba2SAaron LI 		lease->frominfo = 0;
33047827cba2SAaron LI 		lease->addr.s_addr = bootp->yiaddr;
33057827cba2SAaron LI 		memcpy(&lease->cookie, bootp->vend, sizeof(lease->cookie));
33067827cba2SAaron LI 		if (type == 0 ||
33077827cba2SAaron LI 		    get_option_addr(ifp->ctx,
33087827cba2SAaron LI 		    &lease->server, bootp, bootp_len, DHO_SERVERID) != 0)
33097827cba2SAaron LI 			lease->server.s_addr = INADDR_ANY;
33107827cba2SAaron LI 
33117827cba2SAaron LI 		/* Test for rapid commit in the OFFER */
33127827cba2SAaron LI 		if (!(ifp->ctx->options & DHCPCD_TEST) &&
33137827cba2SAaron LI 		    has_option_mask(ifo->requestmask, DHO_RAPIDCOMMIT) &&
33147827cba2SAaron LI 		    get_option(ifp->ctx, bootp, bootp_len,
33157827cba2SAaron LI 		    DHO_RAPIDCOMMIT, NULL))
33167827cba2SAaron LI 		{
33177827cba2SAaron LI 			state->state = DHS_REQUEST;
33187827cba2SAaron LI 			goto rapidcommit;
33197827cba2SAaron LI 		}
33207827cba2SAaron LI 
33216e63cc1fSRoy Marples 		LOGDHCP(LOG_INFO, "offered");
33227827cba2SAaron LI 		if (state->offer_len < bootp_len) {
33237827cba2SAaron LI 			free(state->offer);
33247827cba2SAaron LI 			if ((state->offer = malloc(bootp_len)) == NULL) {
33257827cba2SAaron LI 				logerr(__func__);
33267827cba2SAaron LI 				state->offer_len = 0;
33277827cba2SAaron LI 				return;
33287827cba2SAaron LI 			}
33297827cba2SAaron LI 		}
33307827cba2SAaron LI 		state->offer_len = bootp_len;
33317827cba2SAaron LI 		memcpy(state->offer, bootp, bootp_len);
33327827cba2SAaron LI 		bootp_copied = true;
33337827cba2SAaron LI 		if (ifp->ctx->options & DHCPCD_TEST) {
33347827cba2SAaron LI 			free(state->old);
33357827cba2SAaron LI 			state->old = state->new;
33367827cba2SAaron LI 			state->old_len = state->new_len;
33377827cba2SAaron LI 			state->new = state->offer;
33387827cba2SAaron LI 			state->new_len = state->offer_len;
33397827cba2SAaron LI 			state->offer = NULL;
33407827cba2SAaron LI 			state->offer_len = 0;
33417827cba2SAaron LI 			state->reason = "TEST";
33427827cba2SAaron LI 			script_runreason(ifp, state->reason);
33437827cba2SAaron LI 			eloop_exit(ifp->ctx->eloop, EXIT_SUCCESS);
33444f235d86SRoy Marples 			if (state->bpf)
3345d4fb1e02SRoy Marples 				state->bpf->bpf_flags |= BPF_EOF;
33467827cba2SAaron LI 			return;
33477827cba2SAaron LI 		}
33487827cba2SAaron LI 		eloop_timeout_delete(ifp->ctx->eloop, send_discover, ifp);
33497827cba2SAaron LI 		/* We don't request BOOTP addresses */
33507827cba2SAaron LI 		if (type) {
33517827cba2SAaron LI 			/* We used to ARP check here, but that seems to be in
33527827cba2SAaron LI 			 * violation of RFC2131 where it only describes
33537827cba2SAaron LI 			 * DECLINE after REQUEST.
33547827cba2SAaron LI 			 * It also seems that some MS DHCP servers actually
33557827cba2SAaron LI 			 * ignore DECLINE if no REQUEST, ie we decline a
33567827cba2SAaron LI 			 * DISCOVER. */
33577827cba2SAaron LI 			dhcp_request(ifp);
33587827cba2SAaron LI 			return;
33597827cba2SAaron LI 		}
33607827cba2SAaron LI 	}
33617827cba2SAaron LI 
33627827cba2SAaron LI 	if (type) {
33637827cba2SAaron LI 		if (type == DHCP_OFFER) {
33646e63cc1fSRoy Marples 			LOGDHCP(LOG_WARNING, "ignoring offer of");
33657827cba2SAaron LI 			return;
33667827cba2SAaron LI 		}
33677827cba2SAaron LI 
33687827cba2SAaron LI 		/* We should only be dealing with acks */
33697827cba2SAaron LI 		if (type != DHCP_ACK) {
33706e63cc1fSRoy Marples 			LOGDHCP(LOG_ERR, "not ACK or OFFER");
33717827cba2SAaron LI 			return;
33727827cba2SAaron LI 		}
33737827cba2SAaron LI 
33747827cba2SAaron LI 		if (state->state == DHS_DISCOVER) {
33757827cba2SAaron LI 			/* We only allow ACK of rapid commit DISCOVER. */
33767827cba2SAaron LI 			if (has_option_mask(ifo->requestmask,
33777827cba2SAaron LI 			    DHO_RAPIDCOMMIT) &&
33787827cba2SAaron LI 			    get_option(ifp->ctx, bootp, bootp_len,
33797827cba2SAaron LI 			    DHO_RAPIDCOMMIT, NULL))
33807827cba2SAaron LI 				state->state = DHS_REQUEST;
33817827cba2SAaron LI 			else {
33826e63cc1fSRoy Marples 				LOGDHCP(LOG_DEBUG, "ignoring ack of");
33837827cba2SAaron LI 				return;
33847827cba2SAaron LI 			}
33857827cba2SAaron LI 		}
33867827cba2SAaron LI 
33877827cba2SAaron LI rapidcommit:
33887827cba2SAaron LI 		if (!(ifo->options & DHCPCD_INFORM))
33896e63cc1fSRoy Marples 			LOGDHCP(LOG_DEBUG, "acknowledged");
33907827cba2SAaron LI 		else
33917827cba2SAaron LI 		    ifo->options &= ~DHCPCD_STATIC;
33927827cba2SAaron LI 	}
33937827cba2SAaron LI 
33947827cba2SAaron LI 	/* No NAK, so reset the backoff
33957827cba2SAaron LI 	 * We don't reset on an OFFER message because the server could
33967827cba2SAaron LI 	 * potentially NAK the REQUEST. */
33977827cba2SAaron LI 	state->nakoff = 0;
33987827cba2SAaron LI 
33997827cba2SAaron LI 	/* BOOTP could have already assigned this above. */
34007827cba2SAaron LI 	if (!bootp_copied) {
34017827cba2SAaron LI 		if (state->offer_len < bootp_len) {
34027827cba2SAaron LI 			free(state->offer);
34037827cba2SAaron LI 			if ((state->offer = malloc(bootp_len)) == NULL) {
34047827cba2SAaron LI 				logerr(__func__);
34057827cba2SAaron LI 				state->offer_len = 0;
34067827cba2SAaron LI 				return;
34077827cba2SAaron LI 			}
34087827cba2SAaron LI 		}
34097827cba2SAaron LI 		state->offer_len = bootp_len;
34107827cba2SAaron LI 		memcpy(state->offer, bootp, bootp_len);
34117827cba2SAaron LI 	}
34127827cba2SAaron LI 
34137827cba2SAaron LI 	lease->frominfo = 0;
34147827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, NULL, ifp);
34157827cba2SAaron LI 
34168d36e1dfSRoy Marples #if defined(ARP) || defined(KERNEL_RFC5227)
34177827cba2SAaron LI 	dhcp_arp_bind(ifp);
34187827cba2SAaron LI #else
34197827cba2SAaron LI 	dhcp_bind(ifp);
34207827cba2SAaron LI #endif
34217827cba2SAaron LI }
34227827cba2SAaron LI 
34237827cba2SAaron LI static void *
get_udp_data(void * packet,size_t * len)34248d36e1dfSRoy Marples get_udp_data(void *packet, size_t *len)
34257827cba2SAaron LI {
34268d36e1dfSRoy Marples 	const struct ip *ip = packet;
34278d36e1dfSRoy Marples 	size_t ip_hl = (size_t)ip->ip_hl * 4;
34288d36e1dfSRoy Marples 	char *p = packet;
34297827cba2SAaron LI 
34308d36e1dfSRoy Marples 	p += ip_hl + sizeof(struct udphdr);
34318d36e1dfSRoy Marples 	*len = (size_t)ntohs(ip->ip_len) - sizeof(struct udphdr) - ip_hl;
34328d36e1dfSRoy Marples 	return p;
34337827cba2SAaron LI }
34347827cba2SAaron LI 
34351b3b16a2SRoy Marples static bool
is_packet_udp_bootp(void * packet,size_t plen)34361b3b16a2SRoy Marples is_packet_udp_bootp(void *packet, size_t plen)
34371b3b16a2SRoy Marples {
34381b3b16a2SRoy Marples 	struct ip *ip = packet;
34391b3b16a2SRoy Marples 	size_t ip_hlen;
3440ce3872cbSRoy Marples 	struct udphdr udp;
34411b3b16a2SRoy Marples 
3442ce3872cbSRoy Marples 	if (plen < sizeof(*ip))
34431b3b16a2SRoy Marples 		return false;
34441b3b16a2SRoy Marples 
34451b3b16a2SRoy Marples 	if (ip->ip_v != IPVERSION || ip->ip_p != IPPROTO_UDP)
34461b3b16a2SRoy Marples 		return false;
34471b3b16a2SRoy Marples 
34481b3b16a2SRoy Marples 	/* Sanity. */
3449ce3872cbSRoy Marples 	if (ntohs(ip->ip_len) > plen)
34501b3b16a2SRoy Marples 		return false;
34511b3b16a2SRoy Marples 
34521b3b16a2SRoy Marples 	ip_hlen = (size_t)ip->ip_hl * 4;
3453ce3872cbSRoy Marples 	if (ip_hlen < sizeof(*ip))
3454ce3872cbSRoy Marples 		return false;
3455ce3872cbSRoy Marples 
34561b3b16a2SRoy Marples 	/* Check we have a UDP header and BOOTP. */
3457ce3872cbSRoy Marples 	if (ip_hlen + sizeof(udp) + offsetof(struct bootp, vend) > plen)
3458ce3872cbSRoy Marples 		return false;
3459ce3872cbSRoy Marples 
3460ce3872cbSRoy Marples 	/* Sanity. */
3461ce3872cbSRoy Marples 	memcpy(&udp, (char *)ip + ip_hlen, sizeof(udp));
3462ce3872cbSRoy Marples 	if (ntohs(udp.uh_ulen) < sizeof(udp))
3463ce3872cbSRoy Marples 		return false;
3464ce3872cbSRoy Marples 	if (ip_hlen + ntohs(udp.uh_ulen) > plen)
34651b3b16a2SRoy Marples 		return false;
34661b3b16a2SRoy Marples 
3467f3744ac9SRoy Marples 	/* Check it's to the right port. */
3468f3744ac9SRoy Marples 	if (udp.uh_dport != htons(BOOTPC))
34691b3b16a2SRoy Marples 		return false;
34701b3b16a2SRoy Marples 
34711b3b16a2SRoy Marples 	return true;
34721b3b16a2SRoy Marples }
34731b3b16a2SRoy Marples 
34741b3b16a2SRoy Marples /* Lengths have already been checked. */
34751b3b16a2SRoy Marples static bool
checksums_valid(void * packet,struct in_addr * from,unsigned int flags)34761b3b16a2SRoy Marples checksums_valid(void *packet,
34771b3b16a2SRoy Marples     struct in_addr *from, unsigned int flags)
34787827cba2SAaron LI {
34798d36e1dfSRoy Marples 	struct ip *ip = packet;
3480ce3872cbSRoy Marples 	union pip {
3481ce3872cbSRoy Marples 		struct ip ip;
3482b9ccd228SRoy Marples 		uint16_t w[sizeof(struct ip) / 2];
3483ce3872cbSRoy Marples 	} pip = {
3484d4fb1e02SRoy Marples 		.ip = {
3485d4fb1e02SRoy Marples 			.ip_p = IPPROTO_UDP,
3486d4fb1e02SRoy Marples 			.ip_src = ip->ip_src,
3487d4fb1e02SRoy Marples 			.ip_dst = ip->ip_dst,
3488d4fb1e02SRoy Marples 		}
34898d36e1dfSRoy Marples 	};
34908d36e1dfSRoy Marples 	size_t ip_hlen;
3491ce3872cbSRoy Marples 	struct udphdr udp;
3492ce3872cbSRoy Marples 	char *udpp, *uh_sump;
34938d36e1dfSRoy Marples 	uint32_t csum;
34947827cba2SAaron LI 
34958d36e1dfSRoy Marples 	if (from != NULL)
34968d36e1dfSRoy Marples 		from->s_addr = ip->ip_src.s_addr;
34978d36e1dfSRoy Marples 
34988d36e1dfSRoy Marples 	ip_hlen = (size_t)ip->ip_hl * 4;
34991b3b16a2SRoy Marples 	if (in_cksum(ip, ip_hlen, NULL) != 0)
35001b3b16a2SRoy Marples 		return false;
350112af092aSRoy Marples 
35021b3b16a2SRoy Marples 	if (flags & BPF_PARTIALCSUM)
3503ce3872cbSRoy Marples 		return true;
35047827cba2SAaron LI 
3505ce3872cbSRoy Marples 	udpp = (char *)ip + ip_hlen;
3506ce3872cbSRoy Marples 	memcpy(&udp, udpp, sizeof(udp));
3507ce3872cbSRoy Marples 	if (udp.uh_sum == 0)
3508ce3872cbSRoy Marples 		return true;
35097827cba2SAaron LI 
35108d36e1dfSRoy Marples 	/* UDP checksum is based on a pseudo IP header alongside
35118d36e1dfSRoy Marples 	 * the UDP header and payload. */
3512ce3872cbSRoy Marples 	pip.ip.ip_len = udp.uh_ulen;
35138d36e1dfSRoy Marples 	csum = 0;
3514ce3872cbSRoy Marples 
3515ce3872cbSRoy Marples 	/* Need to zero the UDP sum in the packet for the checksum to work. */
3516ce3872cbSRoy Marples 	uh_sump = udpp + offsetof(struct udphdr, uh_sum);
3517ce3872cbSRoy Marples 	memset(uh_sump, 0, sizeof(udp.uh_sum));
3518ce3872cbSRoy Marples 
3519b9ccd228SRoy Marples 	/* Checksum pseudo header and then UDP + payload. */
3520ce3872cbSRoy Marples 	in_cksum(pip.w, sizeof(pip.w), &csum);
3521ce3872cbSRoy Marples 	csum = in_cksum(udpp, ntohs(udp.uh_ulen), &csum);
3522ce3872cbSRoy Marples 
3523ce3872cbSRoy Marples #if 0	/* Not needed, just here for completeness. */
3524ce3872cbSRoy Marples 	/* Put the checksum back. */
3525ce3872cbSRoy Marples 	memcpy(uh_sump, &udp.uh_sum, sizeof(udp.uh_sum));
3526ce3872cbSRoy Marples #endif
3527ce3872cbSRoy Marples 
3528ce3872cbSRoy Marples 	return csum == udp.uh_sum;
35297827cba2SAaron LI }
35307827cba2SAaron LI 
35317827cba2SAaron LI static void
dhcp_handlebootp(struct interface * ifp,struct bootp * bootp,size_t len,struct in_addr * from)35328d36e1dfSRoy Marples dhcp_handlebootp(struct interface *ifp, struct bootp *bootp, size_t len,
35338d36e1dfSRoy Marples     struct in_addr *from)
35348d36e1dfSRoy Marples {
35358d36e1dfSRoy Marples 	size_t v;
35368d36e1dfSRoy Marples 
35376e63cc1fSRoy Marples 	/* Unlikely, but appeases sanitizers. */
35386e63cc1fSRoy Marples 	if (len > FRAMELEN_MAX) {
35396e63cc1fSRoy Marples 		logerrx("%s: packet exceeded frame length (%zu) from %s",
35406e63cc1fSRoy Marples 		    ifp->name, len, inet_ntoa(*from));
35416e63cc1fSRoy Marples 		return;
35426e63cc1fSRoy Marples 	}
35436e63cc1fSRoy Marples 
35448d36e1dfSRoy Marples 	/* To make our IS_DHCP macro easy, ensure the vendor
35458d36e1dfSRoy Marples 	 * area has at least 4 octets. */
35468d36e1dfSRoy Marples 	v = len - offsetof(struct bootp, vend);
35478d36e1dfSRoy Marples 	while (v < 4) {
35488d36e1dfSRoy Marples 		bootp->vend[v++] = '\0';
35498d36e1dfSRoy Marples 		len++;
35508d36e1dfSRoy Marples 	}
35518d36e1dfSRoy Marples 
35528d36e1dfSRoy Marples 	dhcp_handledhcp(ifp, bootp, len, from);
35538d36e1dfSRoy Marples }
35548d36e1dfSRoy Marples 
35556e63cc1fSRoy Marples void
dhcp_packet(struct interface * ifp,uint8_t * data,size_t len,unsigned int bpf_flags)3556d4fb1e02SRoy Marples dhcp_packet(struct interface *ifp, uint8_t *data, size_t len,
3557d4fb1e02SRoy Marples     unsigned int bpf_flags)
35587827cba2SAaron LI {
35597827cba2SAaron LI 	struct bootp *bootp;
35607827cba2SAaron LI 	struct in_addr from;
35617827cba2SAaron LI 	size_t udp_len;
35626e63cc1fSRoy Marples 	size_t fl = bpf_frame_header_len(ifp);
35636e63cc1fSRoy Marples #ifdef PRIVSEP
3564d4fb1e02SRoy Marples 	const struct dhcp_state *state = D_CSTATE(ifp);
3565d4fb1e02SRoy Marples 
3566a0d9933aSRoy Marples 	/* It's possible that an interface departs and arrives in short
3567a0d9933aSRoy Marples 	 * order to receive a BPF frame out of order.
3568a0d9933aSRoy Marples 	 * There is a similar check in ARP, but much lower down the stack.
3569a0d9933aSRoy Marples 	 * It's not needed for other inet protocols because we send the
3570a0d9933aSRoy Marples 	 * message as a whole and select the interface off that and then
3571a0d9933aSRoy Marples 	 * check state. BPF on the other hand is very interface
3572a0d9933aSRoy Marples 	 * specific and we do need this check. */
3573a0d9933aSRoy Marples 	if (state == NULL)
3574a0d9933aSRoy Marples 		return;
3575a0d9933aSRoy Marples 
35766e63cc1fSRoy Marples 	/* Ignore double reads */
35776e63cc1fSRoy Marples 	if (IN_PRIVSEP(ifp->ctx)) {
35786e63cc1fSRoy Marples 		switch (state->state) {
35796e63cc1fSRoy Marples 		case DHS_BOUND: /* FALLTHROUGH */
35806e63cc1fSRoy Marples 		case DHS_RENEW:
35816e63cc1fSRoy Marples 			return;
35826e63cc1fSRoy Marples 		default:
35836e63cc1fSRoy Marples 			break;
35846e63cc1fSRoy Marples 		}
35856e63cc1fSRoy Marples 	}
35866e63cc1fSRoy Marples #endif
35876e63cc1fSRoy Marples 
35886e63cc1fSRoy Marples 	/* Trim frame header */
35896e63cc1fSRoy Marples 	if (fl != 0) {
35906e63cc1fSRoy Marples 		if (len < fl) {
3591d4fb1e02SRoy Marples 			logerrx("%s: %s: short frame header %zu",
3592d4fb1e02SRoy Marples 			    __func__, ifp->name, len);
35936e63cc1fSRoy Marples 			return;
35946e63cc1fSRoy Marples 		}
35956e63cc1fSRoy Marples 		len -= fl;
35967a0236bfSRoy Marples 		/* Move the data to avoid alignment errors. */
35977a0236bfSRoy Marples 		memmove(data, data + fl, len);
35986e63cc1fSRoy Marples 	}
35997827cba2SAaron LI 
36001b3b16a2SRoy Marples 	/* Validate filter. */
36011b3b16a2SRoy Marples 	if (!is_packet_udp_bootp(data, len)) {
36021b3b16a2SRoy Marples #ifdef BPF_DEBUG
36031b3b16a2SRoy Marples 		logerrx("%s: DHCP BPF validation failure", ifp->name);
36041b3b16a2SRoy Marples #endif
36051b3b16a2SRoy Marples 		return;
36061b3b16a2SRoy Marples 	}
360712af092aSRoy Marples 
3608d4fb1e02SRoy Marples 	if (!checksums_valid(data, &from, bpf_flags)) {
36091b3b16a2SRoy Marples 		logerrx("%s: checksum failure from %s",
36101b3b16a2SRoy Marples 		    ifp->name, inet_ntoa(from));
36117827cba2SAaron LI 		return;
36127827cba2SAaron LI 	}
36137827cba2SAaron LI 
36147827cba2SAaron LI 	/*
36157827cba2SAaron LI 	 * DHCP has a variable option area rather than a fixed vendor area.
36167827cba2SAaron LI 	 * Because DHCP uses the BOOTP protocol it should still send BOOTP
36177827cba2SAaron LI 	 * sized packets to be RFC compliant.
36187827cba2SAaron LI 	 * However some servers send a truncated vendor area.
36197827cba2SAaron LI 	 * dhcpcd can work fine without the vendor area being sent.
36207827cba2SAaron LI 	 */
36217827cba2SAaron LI 	bootp = get_udp_data(data, &udp_len);
36228d36e1dfSRoy Marples 	dhcp_handlebootp(ifp, bootp, udp_len, &from);
36237827cba2SAaron LI }
36247827cba2SAaron LI 
36257827cba2SAaron LI static void
dhcp_readbpf(void * arg,unsigned short events)362680aa9461SRoy Marples dhcp_readbpf(void *arg, unsigned short events)
36277827cba2SAaron LI {
36287827cba2SAaron LI 	struct interface *ifp = arg;
36296e63cc1fSRoy Marples 	uint8_t buf[FRAMELEN_MAX];
36307827cba2SAaron LI 	ssize_t bytes;
36317827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
3632d4fb1e02SRoy Marples 	struct bpf *bpf = state->bpf;
36337827cba2SAaron LI 
363480aa9461SRoy Marples 	if (events != ELE_READ)
363580aa9461SRoy Marples 		logerrx("%s: unexpected event 0x%04x", __func__, events);
363680aa9461SRoy Marples 
3637d4fb1e02SRoy Marples 	bpf->bpf_flags &= ~BPF_EOF;
3638d4fb1e02SRoy Marples 	while (!(bpf->bpf_flags & BPF_EOF)) {
3639d4fb1e02SRoy Marples 		bytes = bpf_read(bpf, buf, sizeof(buf));
36407827cba2SAaron LI 		if (bytes == -1) {
36417827cba2SAaron LI 			if (state->state != DHS_NONE) {
36427827cba2SAaron LI 				logerr("%s: %s", __func__, ifp->name);
36437827cba2SAaron LI 				dhcp_close(ifp);
36447827cba2SAaron LI 			}
36457827cba2SAaron LI 			break;
36467827cba2SAaron LI 		}
3647d4fb1e02SRoy Marples 		dhcp_packet(ifp, buf, (size_t)bytes, bpf->bpf_flags);
36487827cba2SAaron LI 		/* Check we still have a state after processing. */
36497827cba2SAaron LI 		if ((state = D_STATE(ifp)) == NULL)
36507827cba2SAaron LI 			break;
3651d4fb1e02SRoy Marples 		if ((bpf = state->bpf) == NULL)
3652d4fb1e02SRoy Marples 			break;
36537827cba2SAaron LI 	}
36547827cba2SAaron LI }
36557827cba2SAaron LI 
36566e63cc1fSRoy Marples void
dhcp_recvmsg(struct dhcpcd_ctx * ctx,struct msghdr * msg)3657b9ccd228SRoy Marples dhcp_recvmsg(struct dhcpcd_ctx *ctx, struct msghdr *msg)
3658b9ccd228SRoy Marples {
3659b9ccd228SRoy Marples 	struct sockaddr_in *from = (struct sockaddr_in *)msg->msg_name;
3660b9ccd228SRoy Marples 	struct iovec *iov = &msg->msg_iov[0];
3661b9ccd228SRoy Marples 	struct interface *ifp;
3662b9ccd228SRoy Marples 	const struct dhcp_state *state;
3663b9ccd228SRoy Marples 
3664b9ccd228SRoy Marples 	ifp = if_findifpfromcmsg(ctx, msg, NULL);
3665b9ccd228SRoy Marples 	if (ifp == NULL) {
3666b9ccd228SRoy Marples 		logerr(__func__);
3667b9ccd228SRoy Marples 		return;
3668b9ccd228SRoy Marples 	}
3669*54175cefSRoy Marples 
3670*54175cefSRoy Marples 	if (iov->iov_len < offsetof(struct bootp, vend)) {
3671*54175cefSRoy Marples 		logerrx("%s: truncated packet (%zu) from %s",
3672*54175cefSRoy Marples 		    ifp->name, iov->iov_len, inet_ntoa(from->sin_addr));
3673*54175cefSRoy Marples 		return;
3674*54175cefSRoy Marples 	}
3675*54175cefSRoy Marples 
3676b9ccd228SRoy Marples 	state = D_CSTATE(ifp);
3677b9ccd228SRoy Marples 	if (state == NULL) {
36786e63cc1fSRoy Marples 		/* Try re-directing it to another interface. */
36796e63cc1fSRoy Marples 		dhcp_redirect_dhcp(ifp, (struct bootp *)iov->iov_base,
36806e63cc1fSRoy Marples 		    iov->iov_len, &from->sin_addr);
3681b9ccd228SRoy Marples 		return;
3682b9ccd228SRoy Marples 	}
3683b9ccd228SRoy Marples 
3684d4fb1e02SRoy Marples 	if (state->bpf != NULL) {
3685b9ccd228SRoy Marples 		/* Avoid a duplicate read if BPF is open for the interface. */
3686b9ccd228SRoy Marples 		return;
3687b9ccd228SRoy Marples 	}
36886e63cc1fSRoy Marples #ifdef PRIVSEP
36896e63cc1fSRoy Marples 	if (IN_PRIVSEP(ctx)) {
36906e63cc1fSRoy Marples 		switch (state->state) {
36916e63cc1fSRoy Marples 		case DHS_BOUND: /* FALLTHROUGH */
36926e63cc1fSRoy Marples 		case DHS_RENEW:
36936e63cc1fSRoy Marples 			break;
36946e63cc1fSRoy Marples 		default:
36956e63cc1fSRoy Marples 			/* Any other state we ignore it or will receive
36966e63cc1fSRoy Marples 			 * via BPF. */
36976e63cc1fSRoy Marples 			return;
36986e63cc1fSRoy Marples 		}
36996e63cc1fSRoy Marples 	}
37006e63cc1fSRoy Marples #endif
3701b9ccd228SRoy Marples 
3702d4fb1e02SRoy Marples 	dhcp_handlebootp(ifp, iov->iov_base, iov->iov_len,
3703b9ccd228SRoy Marples 	    &from->sin_addr);
3704b9ccd228SRoy Marples }
3705b9ccd228SRoy Marples 
3706b9ccd228SRoy Marples static void
dhcp_readudp(struct dhcpcd_ctx * ctx,struct interface * ifp,unsigned short events)370780aa9461SRoy Marples dhcp_readudp(struct dhcpcd_ctx *ctx, struct interface *ifp,
370880aa9461SRoy Marples     unsigned short events)
37098d36e1dfSRoy Marples {
37108d36e1dfSRoy Marples 	const struct dhcp_state *state;
37118d36e1dfSRoy Marples 	struct sockaddr_in from;
3712d4fb1e02SRoy Marples 	union {
3713d4fb1e02SRoy Marples 		struct bootp bootp;
3714d4fb1e02SRoy Marples 		uint8_t buf[10 * 1024]; /* Maximum MTU */
3715d4fb1e02SRoy Marples 	} iovbuf;
37168d36e1dfSRoy Marples 	struct iovec iov = {
3717d4fb1e02SRoy Marples 		.iov_base = iovbuf.buf,
3718d4fb1e02SRoy Marples 		.iov_len = sizeof(iovbuf.buf),
37198d36e1dfSRoy Marples 	};
37207a0236bfSRoy Marples 	union {
37217a0236bfSRoy Marples 		struct cmsghdr hdr;
3722b9ccd228SRoy Marples #ifdef IP_RECVIF
37237a0236bfSRoy Marples 		uint8_t buf[CMSG_SPACE(sizeof(struct sockaddr_dl))];
3724b9ccd228SRoy Marples #else
37257a0236bfSRoy Marples 		uint8_t buf[CMSG_SPACE(sizeof(struct in_pktinfo))];
37268d36e1dfSRoy Marples #endif
37277a0236bfSRoy Marples 	} cmsgbuf = { .buf = { 0 } };
37288d36e1dfSRoy Marples 	struct msghdr msg = {
37298d36e1dfSRoy Marples 	    .msg_name = &from, .msg_namelen = sizeof(from),
37308d36e1dfSRoy Marples 	    .msg_iov = &iov, .msg_iovlen = 1,
3731d4fb1e02SRoy Marples 	    .msg_control = cmsgbuf.buf, .msg_controllen = sizeof(cmsgbuf.buf),
37328d36e1dfSRoy Marples 	};
37338d36e1dfSRoy Marples 	int s;
37348d36e1dfSRoy Marples 	ssize_t bytes;
37358d36e1dfSRoy Marples 
373680aa9461SRoy Marples 	if (events != ELE_READ)
373780aa9461SRoy Marples 		logerrx("%s: unexpected event 0x%04x", __func__, events);
373880aa9461SRoy Marples 
37398d36e1dfSRoy Marples 	if (ifp != NULL) {
37408d36e1dfSRoy Marples 		state = D_CSTATE(ifp);
3741d4fb1e02SRoy Marples 		s = state->udp_rfd;
37428d36e1dfSRoy Marples 	} else
3743d4fb1e02SRoy Marples 		s = ctx->udp_rfd;
37448d36e1dfSRoy Marples 
37458d36e1dfSRoy Marples 	bytes = recvmsg(s, &msg, 0);
37468d36e1dfSRoy Marples 	if (bytes == -1) {
37478d36e1dfSRoy Marples 		logerr(__func__);
37488d36e1dfSRoy Marples 		return;
37498d36e1dfSRoy Marples 	}
37508d36e1dfSRoy Marples 
3751b9ccd228SRoy Marples 	iov.iov_len = (size_t)bytes;
3752b9ccd228SRoy Marples 	dhcp_recvmsg(ctx, &msg);
37538d36e1dfSRoy Marples }
37548d36e1dfSRoy Marples 
37558d36e1dfSRoy Marples static void
dhcp_handleudp(void * arg,unsigned short events)375680aa9461SRoy Marples dhcp_handleudp(void *arg, unsigned short events)
37577827cba2SAaron LI {
37588d36e1dfSRoy Marples 	struct dhcpcd_ctx *ctx = arg;
37597827cba2SAaron LI 
376080aa9461SRoy Marples 	dhcp_readudp(ctx, NULL, events);
37618d36e1dfSRoy Marples }
37627827cba2SAaron LI 
37638d36e1dfSRoy Marples static void
dhcp_handleifudp(void * arg,unsigned short events)376480aa9461SRoy Marples dhcp_handleifudp(void *arg, unsigned short events)
37658d36e1dfSRoy Marples {
37668d36e1dfSRoy Marples 	struct interface *ifp = arg;
37678d36e1dfSRoy Marples 
376880aa9461SRoy Marples 	dhcp_readudp(ifp->ctx, ifp, events);
37697827cba2SAaron LI }
3770b9ccd228SRoy Marples 
3771b9ccd228SRoy Marples static int
dhcp_openbpf(struct interface * ifp)37727827cba2SAaron LI dhcp_openbpf(struct interface *ifp)
37737827cba2SAaron LI {
37747827cba2SAaron LI 	struct dhcp_state *state;
37757827cba2SAaron LI 
37767827cba2SAaron LI 	state = D_STATE(ifp);
37776e63cc1fSRoy Marples 
37786e63cc1fSRoy Marples #ifdef PRIVSEP
37796e63cc1fSRoy Marples 	if (IN_PRIVSEP_SE(ifp->ctx)) {
37806e63cc1fSRoy Marples 		if (ps_bpf_openbootp(ifp) == -1) {
37816e63cc1fSRoy Marples 			logerr(__func__);
37826e63cc1fSRoy Marples 			return -1;
37836e63cc1fSRoy Marples 		}
37846e63cc1fSRoy Marples 		return 0;
37856e63cc1fSRoy Marples 	}
37866e63cc1fSRoy Marples #endif
37876e63cc1fSRoy Marples 
3788d4fb1e02SRoy Marples 	if (state->bpf != NULL)
37897827cba2SAaron LI 		return 0;
37907827cba2SAaron LI 
3791d4fb1e02SRoy Marples 	state->bpf = bpf_open(ifp, bpf_bootp, NULL);
3792d4fb1e02SRoy Marples 	if (state->bpf == NULL) {
37937827cba2SAaron LI 		if (errno == ENOENT) {
37947827cba2SAaron LI 			logerrx("%s not found", bpf_name);
37957827cba2SAaron LI 			/* May as well disable IPv4 entirely at
37967827cba2SAaron LI 			 * this point as we really need it. */
37977827cba2SAaron LI 			ifp->options->options &= ~DHCPCD_IPV4;
37987827cba2SAaron LI 		} else
37997827cba2SAaron LI 			logerr("%s: %s", __func__, ifp->name);
38007827cba2SAaron LI 		return -1;
38017827cba2SAaron LI 	}
38027827cba2SAaron LI 
380380aa9461SRoy Marples 	if (eloop_event_add(ifp->ctx->eloop, state->bpf->bpf_fd, ELE_READ,
380480aa9461SRoy Marples 	    dhcp_readbpf, ifp) == -1)
380580aa9461SRoy Marples 		logerr("%s: eloop_event_add", __func__);
38067827cba2SAaron LI 	return 0;
38077827cba2SAaron LI }
38087827cba2SAaron LI 
38097827cba2SAaron LI void
dhcp_free(struct interface * ifp)38107827cba2SAaron LI dhcp_free(struct interface *ifp)
38117827cba2SAaron LI {
38127827cba2SAaron LI 	struct dhcp_state *state = D_STATE(ifp);
38137827cba2SAaron LI 	struct dhcpcd_ctx *ctx;
38147827cba2SAaron LI 
38157827cba2SAaron LI 	dhcp_close(ifp);
38167827cba2SAaron LI #ifdef ARP
38177827cba2SAaron LI 	arp_drop(ifp);
38187827cba2SAaron LI #endif
38197827cba2SAaron LI 	if (state) {
38207827cba2SAaron LI 		state->state = DHS_NONE;
38217827cba2SAaron LI 		free(state->old);
38227827cba2SAaron LI 		free(state->new);
38237827cba2SAaron LI 		free(state->offer);
38247827cba2SAaron LI 		free(state->clientid);
38257827cba2SAaron LI 		free(state);
38267827cba2SAaron LI 	}
38277827cba2SAaron LI 
38287827cba2SAaron LI 	ctx = ifp->ctx;
38297827cba2SAaron LI 	/* If we don't have any more DHCP enabled interfaces,
38307827cba2SAaron LI 	 * close the global socket and release resources */
38317827cba2SAaron LI 	if (ctx->ifaces) {
38327827cba2SAaron LI 		TAILQ_FOREACH(ifp, ctx->ifaces, next) {
38337827cba2SAaron LI 			state = D_STATE(ifp);
38347827cba2SAaron LI 			if (state != NULL && state->state != DHS_NONE)
38357827cba2SAaron LI 				break;
38367827cba2SAaron LI 		}
38377827cba2SAaron LI 	}
38387827cba2SAaron LI 	if (ifp == NULL) {
3839d4fb1e02SRoy Marples 		if (ctx->udp_rfd != -1) {
3840d4fb1e02SRoy Marples 			eloop_event_delete(ctx->eloop, ctx->udp_rfd);
3841d4fb1e02SRoy Marples 			close(ctx->udp_rfd);
3842d4fb1e02SRoy Marples 			ctx->udp_rfd = -1;
3843d4fb1e02SRoy Marples 		}
3844d4fb1e02SRoy Marples 		if (ctx->udp_wfd != -1) {
3845d4fb1e02SRoy Marples 			close(ctx->udp_wfd);
3846d4fb1e02SRoy Marples 			ctx->udp_wfd = -1;
38477827cba2SAaron LI 		}
38487827cba2SAaron LI 
38497827cba2SAaron LI 		free(ctx->opt_buffer);
38507827cba2SAaron LI 		ctx->opt_buffer = NULL;
385180aa9461SRoy Marples 		ctx->opt_buffer_len = 0;
38527827cba2SAaron LI 	}
38537827cba2SAaron LI }
38547827cba2SAaron LI 
38557827cba2SAaron LI static int
dhcp_initstate(struct interface * ifp)38567827cba2SAaron LI dhcp_initstate(struct interface *ifp)
38577827cba2SAaron LI {
38587827cba2SAaron LI 	struct dhcp_state *state;
38597827cba2SAaron LI 
38607827cba2SAaron LI 	state = D_STATE(ifp);
38617827cba2SAaron LI 	if (state != NULL)
38627827cba2SAaron LI 		return 0;
38637827cba2SAaron LI 
38647827cba2SAaron LI 	ifp->if_data[IF_DATA_DHCP] = calloc(1, sizeof(*state));
38657827cba2SAaron LI 	state = D_STATE(ifp);
38667827cba2SAaron LI 	if (state == NULL)
38677827cba2SAaron LI 		return -1;
38687827cba2SAaron LI 
38697827cba2SAaron LI 	state->state = DHS_NONE;
38707827cba2SAaron LI 	/* 0 is a valid fd, so init to -1 */
3871d4fb1e02SRoy Marples 	state->udp_rfd = -1;
38727827cba2SAaron LI #ifdef ARPING
38737827cba2SAaron LI 	state->arping_index = -1;
38747827cba2SAaron LI #endif
38757827cba2SAaron LI 	return 1;
38767827cba2SAaron LI }
38777827cba2SAaron LI 
38787827cba2SAaron LI static int
dhcp_init(struct interface * ifp)38797827cba2SAaron LI dhcp_init(struct interface *ifp)
38807827cba2SAaron LI {
38817827cba2SAaron LI 	struct dhcp_state *state;
3882d4fb1e02SRoy Marples 	struct if_options *ifo;
38837827cba2SAaron LI 	uint8_t len;
38847827cba2SAaron LI 	char buf[(sizeof(ifo->clientid) - 1) * 3];
38857827cba2SAaron LI 
38868d36e1dfSRoy Marples 	if (dhcp_initstate(ifp) == -1)
38877827cba2SAaron LI 		return -1;
38887827cba2SAaron LI 
38897827cba2SAaron LI 	state = D_STATE(ifp);
38907827cba2SAaron LI 	state->state = DHS_INIT;
38917827cba2SAaron LI 	state->reason = "PREINIT";
38927827cba2SAaron LI 	state->nakoff = 0;
38937827cba2SAaron LI 	dhcp_set_leasefile(state->leasefile, sizeof(state->leasefile),
38947827cba2SAaron LI 	    AF_INET, ifp);
38957827cba2SAaron LI 
38967827cba2SAaron LI 	ifo = ifp->options;
38977827cba2SAaron LI 	/* We need to drop the leasefile so that dhcp_start
38987827cba2SAaron LI 	 * doesn't load it. */
38997827cba2SAaron LI 	if (ifo->options & DHCPCD_REQUEST)
3900d4fb1e02SRoy Marples 		dhcp_unlink(ifp->ctx, state->leasefile);
39017827cba2SAaron LI 
39027827cba2SAaron LI 	free(state->clientid);
39037827cba2SAaron LI 	state->clientid = NULL;
39047827cba2SAaron LI 
39056e63cc1fSRoy Marples 	if (ifo->options & DHCPCD_ANONYMOUS) {
39060aaf6155SRoy Marples 		/* Removing the option could show that we want anonymous.
39070aaf6155SRoy Marples 		 * As such keep it as it's already in the hwaddr field. */
39080aaf6155SRoy Marples 		goto make_clientid;
39096e63cc1fSRoy Marples 	} else if (*ifo->clientid) {
39107827cba2SAaron LI 		state->clientid = malloc((size_t)(ifo->clientid[0] + 1));
39117827cba2SAaron LI 		if (state->clientid == NULL)
39127827cba2SAaron LI 			goto eexit;
39137827cba2SAaron LI 		memcpy(state->clientid, ifo->clientid,
39147827cba2SAaron LI 		    (size_t)(ifo->clientid[0]) + 1);
39157827cba2SAaron LI 	} else if (ifo->options & DHCPCD_CLIENTID) {
39167827cba2SAaron LI 		if (ifo->options & DHCPCD_DUID) {
39177827cba2SAaron LI 			state->clientid = malloc(ifp->ctx->duid_len + 6);
39187827cba2SAaron LI 			if (state->clientid == NULL)
39197827cba2SAaron LI 				goto eexit;
39207827cba2SAaron LI 			state->clientid[0] =(uint8_t)(ifp->ctx->duid_len + 5);
39217827cba2SAaron LI 			state->clientid[1] = 255; /* RFC 4361 */
39227827cba2SAaron LI 			memcpy(state->clientid + 2, ifo->iaid, 4);
39237827cba2SAaron LI 			memcpy(state->clientid + 6, ifp->ctx->duid,
39247827cba2SAaron LI 			    ifp->ctx->duid_len);
39257827cba2SAaron LI 		} else {
39260aaf6155SRoy Marples make_clientid:
39277827cba2SAaron LI 			len = (uint8_t)(ifp->hwlen + 1);
39287827cba2SAaron LI 			state->clientid = malloc((size_t)len + 1);
39297827cba2SAaron LI 			if (state->clientid == NULL)
39307827cba2SAaron LI 				goto eexit;
39317827cba2SAaron LI 			state->clientid[0] = len;
3932d4fb1e02SRoy Marples 			state->clientid[1] = (uint8_t)ifp->hwtype;
39337827cba2SAaron LI 			memcpy(state->clientid + 2, ifp->hwaddr,
39347827cba2SAaron LI 			    ifp->hwlen);
39357827cba2SAaron LI 		}
39367827cba2SAaron LI 	}
39377827cba2SAaron LI 
39387827cba2SAaron LI 	if (ifo->options & DHCPCD_DUID)
39397827cba2SAaron LI 		/* Don't bother logging as DUID and IAID are reported
39407827cba2SAaron LI 		 * at device start. */
39417827cba2SAaron LI 		return 0;
39427827cba2SAaron LI 
3943d4fb1e02SRoy Marples 	if (ifo->options & DHCPCD_CLIENTID && state->clientid != NULL)
39447827cba2SAaron LI 		logdebugx("%s: using ClientID %s", ifp->name,
39457827cba2SAaron LI 		    hwaddr_ntoa(state->clientid + 1, state->clientid[0],
39467827cba2SAaron LI 			buf, sizeof(buf)));
39477827cba2SAaron LI 	else if (ifp->hwlen)
39487827cba2SAaron LI 		logdebugx("%s: using hwaddr %s", ifp->name,
39497827cba2SAaron LI 		    hwaddr_ntoa(ifp->hwaddr, ifp->hwlen, buf, sizeof(buf)));
39507827cba2SAaron LI 	return 0;
39517827cba2SAaron LI 
39527827cba2SAaron LI eexit:
39537827cba2SAaron LI 	logerr(__func__);
39547827cba2SAaron LI 	return -1;
39557827cba2SAaron LI }
39567827cba2SAaron LI 
39577827cba2SAaron LI static void
dhcp_start1(void * arg)39587827cba2SAaron LI dhcp_start1(void *arg)
39597827cba2SAaron LI {
39607827cba2SAaron LI 	struct interface *ifp = arg;
39618d36e1dfSRoy Marples 	struct dhcpcd_ctx *ctx = ifp->ctx;
39627827cba2SAaron LI 	struct if_options *ifo = ifp->options;
39637827cba2SAaron LI 	struct dhcp_state *state;
39647827cba2SAaron LI 	uint32_t l;
39657827cba2SAaron LI 	int nolease;
39667827cba2SAaron LI 
39677827cba2SAaron LI 	if (!(ifo->options & DHCPCD_IPV4))
39687827cba2SAaron LI 		return;
39697827cba2SAaron LI 
39707827cba2SAaron LI 	/* Listen on *.*.*.*:bootpc so that the kernel never sends an
39718d36e1dfSRoy Marples 	 * ICMP port unreachable message back to the DHCP server.
39720a68f8d2SRoy Marples 	 * Only do this in manager mode so we don't swallow messages
39738d36e1dfSRoy Marples 	 * for dhcpcd running on another interface. */
39740a68f8d2SRoy Marples 	if ((ctx->options & (DHCPCD_MANAGER|DHCPCD_PRIVSEP)) == DHCPCD_MANAGER
3975d4fb1e02SRoy Marples 	    && ctx->udp_rfd == -1)
39766e63cc1fSRoy Marples 	{
3977d4fb1e02SRoy Marples 		ctx->udp_rfd = dhcp_openudp(NULL);
3978d4fb1e02SRoy Marples 		if (ctx->udp_rfd == -1) {
39796e63cc1fSRoy Marples 			logerr(__func__);
39806e63cc1fSRoy Marples 			return;
3981b9ccd228SRoy Marples 		}
398280aa9461SRoy Marples 		if (eloop_event_add(ctx->eloop, ctx->udp_rfd, ELE_READ,
398380aa9461SRoy Marples 		    dhcp_handleudp, ctx) == -1)
398480aa9461SRoy Marples 			logerr("%s: eloop_event_add", __func__);
3985d4fb1e02SRoy Marples 	}
3986d4fb1e02SRoy Marples 	if (!IN_PRIVSEP(ctx) && ctx->udp_wfd == -1) {
3987d4fb1e02SRoy Marples 		ctx->udp_wfd = xsocket(PF_INET, SOCK_RAW|SOCK_CXNB,IPPROTO_UDP);
3988d4fb1e02SRoy Marples 		if (ctx->udp_wfd == -1) {
3989d4fb1e02SRoy Marples 			logerr(__func__);
3990d4fb1e02SRoy Marples 			return;
3991d4fb1e02SRoy Marples 		}
39927827cba2SAaron LI 	}
39937827cba2SAaron LI 
39947827cba2SAaron LI 	if (dhcp_init(ifp) == -1) {
39957827cba2SAaron LI 		logerr("%s: dhcp_init", ifp->name);
39967827cba2SAaron LI 		return;
39977827cba2SAaron LI 	}
39987827cba2SAaron LI 
39997827cba2SAaron LI 	state = D_STATE(ifp);
40007827cba2SAaron LI 	clock_gettime(CLOCK_MONOTONIC, &state->started);
40017827cba2SAaron LI 	state->interval = 0;
40027827cba2SAaron LI 	free(state->offer);
40037827cba2SAaron LI 	state->offer = NULL;
40047827cba2SAaron LI 	state->offer_len = 0;
40057827cba2SAaron LI 
40067827cba2SAaron LI #ifdef ARPING
40077827cba2SAaron LI 	if (ifo->arping_len && state->arping_index < ifo->arping_len) {
4008d4fb1e02SRoy Marples 		dhcp_arping(ifp);
40097827cba2SAaron LI 		return;
40107827cba2SAaron LI 	}
40117827cba2SAaron LI #endif
40127827cba2SAaron LI 
40137827cba2SAaron LI 	if (ifo->options & DHCPCD_STATIC) {
40147827cba2SAaron LI 		dhcp_static(ifp);
40157827cba2SAaron LI 		return;
40167827cba2SAaron LI 	}
40177827cba2SAaron LI 
40187827cba2SAaron LI 	if (ifo->options & DHCPCD_INFORM) {
40197827cba2SAaron LI 		dhcp_inform(ifp);
40207827cba2SAaron LI 		return;
40217827cba2SAaron LI 	}
40228d36e1dfSRoy Marples 
40237827cba2SAaron LI 	/* We don't want to read the old lease if we NAK an old test */
40247827cba2SAaron LI 	nolease = state->offer && ifp->ctx->options & DHCPCD_TEST;
40257827cba2SAaron LI 	if (!nolease && ifo->options & DHCPCD_DHCP) {
40267827cba2SAaron LI 		state->offer_len = read_lease(ifp, &state->offer);
40277827cba2SAaron LI 		/* Check the saved lease matches the type we want */
40287827cba2SAaron LI 		if (state->offer) {
40297827cba2SAaron LI #ifdef IN_IFF_DUPLICATED
40307827cba2SAaron LI 			struct in_addr addr;
40317827cba2SAaron LI 			struct ipv4_addr *ia;
40327827cba2SAaron LI 
40337827cba2SAaron LI 			addr.s_addr = state->offer->yiaddr;
40347827cba2SAaron LI 			ia = ipv4_iffindaddr(ifp, &addr, NULL);
40357827cba2SAaron LI #endif
40367827cba2SAaron LI 
40377827cba2SAaron LI 			if ((!IS_DHCP(state->offer) &&
40387827cba2SAaron LI 			    !(ifo->options & DHCPCD_BOOTP)) ||
40397827cba2SAaron LI #ifdef IN_IFF_DUPLICATED
40407827cba2SAaron LI 			    (ia && ia->addr_flags & IN_IFF_DUPLICATED) ||
40417827cba2SAaron LI #endif
40427827cba2SAaron LI 			    (IS_DHCP(state->offer) &&
40437827cba2SAaron LI 			    ifo->options & DHCPCD_BOOTP))
40447827cba2SAaron LI 			{
40457827cba2SAaron LI 				free(state->offer);
40467827cba2SAaron LI 				state->offer = NULL;
40477827cba2SAaron LI 				state->offer_len = 0;
40487827cba2SAaron LI 			}
40497827cba2SAaron LI 		}
40507827cba2SAaron LI 	}
40517827cba2SAaron LI 	if (state->offer) {
40527827cba2SAaron LI 		struct ipv4_addr *ia;
4053d4fb1e02SRoy Marples 		time_t mtime;
40547827cba2SAaron LI 
40557827cba2SAaron LI 		get_lease(ifp, &state->lease, state->offer, state->offer_len);
40567827cba2SAaron LI 		state->lease.frominfo = 1;
40577827cba2SAaron LI 		if (state->new == NULL &&
40587827cba2SAaron LI 		    (ia = ipv4_iffindaddr(ifp,
40597827cba2SAaron LI 		    &state->lease.addr, &state->lease.mask)) != NULL)
40607827cba2SAaron LI 		{
40617827cba2SAaron LI 			/* We still have the IP address from the last lease.
40627827cba2SAaron LI 			 * Fake add the address and routes from it so the lease
40637827cba2SAaron LI 			 * can be cleaned up. */
40647827cba2SAaron LI 			state->new = malloc(state->offer_len);
40657827cba2SAaron LI 			if (state->new) {
40667827cba2SAaron LI 				memcpy(state->new,
40677827cba2SAaron LI 				    state->offer, state->offer_len);
40687827cba2SAaron LI 				state->new_len = state->offer_len;
40697827cba2SAaron LI 				state->addr = ia;
40707827cba2SAaron LI 				state->added |= STATE_ADDED | STATE_FAKE;
40717827cba2SAaron LI 				rt_build(ifp->ctx, AF_INET);
40727827cba2SAaron LI 			} else
40737827cba2SAaron LI 				logerr(__func__);
40747827cba2SAaron LI 		}
40757827cba2SAaron LI 		if (!IS_DHCP(state->offer)) {
40767827cba2SAaron LI 			free(state->offer);
40777827cba2SAaron LI 			state->offer = NULL;
40787827cba2SAaron LI 			state->offer_len = 0;
40797827cba2SAaron LI 		} else if (!(ifo->options & DHCPCD_LASTLEASE_EXTEND) &&
40808d36e1dfSRoy Marples 		    state->lease.leasetime != DHCP_INFINITE_LIFETIME &&
4081d4fb1e02SRoy Marples 		    dhcp_filemtime(ifp->ctx, state->leasefile, &mtime) == 0)
40827827cba2SAaron LI 		{
40837827cba2SAaron LI 			time_t now;
40847827cba2SAaron LI 
40857827cba2SAaron LI 			/* Offset lease times and check expiry */
40867827cba2SAaron LI 			now = time(NULL);
40877827cba2SAaron LI 			if (now == -1 ||
4088d4fb1e02SRoy Marples 			    (time_t)state->lease.leasetime < now - mtime)
40897827cba2SAaron LI 			{
40907827cba2SAaron LI 				logdebugx("%s: discarding expired lease",
40917827cba2SAaron LI 				    ifp->name);
40927827cba2SAaron LI 				free(state->offer);
40937827cba2SAaron LI 				state->offer = NULL;
40947827cba2SAaron LI 				state->offer_len = 0;
40957827cba2SAaron LI 				state->lease.addr.s_addr = 0;
40967827cba2SAaron LI 				/* Technically we should discard the lease
40977827cba2SAaron LI 				 * as it's expired, just as DHCPv6 addresses
40987827cba2SAaron LI 				 * would be by the kernel.
40997827cba2SAaron LI 				 * However, this may violate POLA so
41007827cba2SAaron LI 				 * we currently leave it be.
41017827cba2SAaron LI 				 * If we get a totally different lease from
41027827cba2SAaron LI 				 * the DHCP server we'll drop it anyway, as
41037827cba2SAaron LI 				 * we will on any other event which would
41047827cba2SAaron LI 				 * trigger a lease drop.
41057827cba2SAaron LI 				 * This should only happen if dhcpcd stops
41067827cba2SAaron LI 				 * running and the lease expires before
41077827cba2SAaron LI 				 * dhcpcd starts again. */
41087827cba2SAaron LI #if 0
41097827cba2SAaron LI 				if (state->new)
41107827cba2SAaron LI 					dhcp_drop(ifp, "EXPIRE");
41117827cba2SAaron LI #endif
41127827cba2SAaron LI 			} else {
4113d4fb1e02SRoy Marples 				l = (uint32_t)(now - mtime);
41147827cba2SAaron LI 				state->lease.leasetime -= l;
41157827cba2SAaron LI 				state->lease.renewaltime -= l;
41167827cba2SAaron LI 				state->lease.rebindtime -= l;
41177827cba2SAaron LI 			}
41187827cba2SAaron LI 		}
41197827cba2SAaron LI 	}
41207827cba2SAaron LI 
41217827cba2SAaron LI #ifdef IPV4LL
41227827cba2SAaron LI 	if (!(ifo->options & DHCPCD_DHCP)) {
41237827cba2SAaron LI 		if (ifo->options & DHCPCD_IPV4LL)
41247827cba2SAaron LI 			ipv4ll_start(ifp);
41257827cba2SAaron LI 		return;
41267827cba2SAaron LI 	}
41277827cba2SAaron LI #endif
41287827cba2SAaron LI 
41296e63cc1fSRoy Marples 	if (state->offer == NULL ||
41306e63cc1fSRoy Marples 	    !IS_DHCP(state->offer) ||
41316e63cc1fSRoy Marples 	    ifo->options & DHCPCD_ANONYMOUS)
41327827cba2SAaron LI 		dhcp_discover(ifp);
41337827cba2SAaron LI 	else
41347827cba2SAaron LI 		dhcp_reboot(ifp);
41357827cba2SAaron LI }
41367827cba2SAaron LI 
41377827cba2SAaron LI void
dhcp_start(struct interface * ifp)41387827cba2SAaron LI dhcp_start(struct interface *ifp)
41397827cba2SAaron LI {
41406e63cc1fSRoy Marples 	unsigned int delay;
41417827cba2SAaron LI #ifdef ARPING
41427827cba2SAaron LI 	const struct dhcp_state *state;
41437827cba2SAaron LI #endif
41447827cba2SAaron LI 
41457827cba2SAaron LI 	if (!(ifp->options->options & DHCPCD_IPV4))
41467827cba2SAaron LI 		return;
41477827cba2SAaron LI 
41487827cba2SAaron LI 	/* If we haven't been given a netmask for our requested address,
41497827cba2SAaron LI 	 * set it now. */
41507827cba2SAaron LI 	if (ifp->options->req_addr.s_addr != INADDR_ANY &&
41517827cba2SAaron LI 	    ifp->options->req_mask.s_addr == INADDR_ANY)
41527827cba2SAaron LI 		ifp->options->req_mask.s_addr =
41537827cba2SAaron LI 		    ipv4_getnetmask(ifp->options->req_addr.s_addr);
41547827cba2SAaron LI 
41557827cba2SAaron LI 	/* If we haven't specified a ClientID and our hardware address
41567827cba2SAaron LI 	 * length is greater than BOOTP CHADDR then we enforce a ClientID
4157d4fb1e02SRoy Marples 	 * of the hardware address type and the hardware address.
41587827cba2SAaron LI 	 * If there is no hardware address and no ClientID set,
41597827cba2SAaron LI 	 * force a DUID based ClientID. */
41607827cba2SAaron LI 	if (ifp->hwlen > 16)
41617827cba2SAaron LI 		ifp->options->options |= DHCPCD_CLIENTID;
41627827cba2SAaron LI 	else if (ifp->hwlen == 0 && !(ifp->options->options & DHCPCD_CLIENTID))
41637827cba2SAaron LI 		ifp->options->options |= DHCPCD_CLIENTID | DHCPCD_DUID;
41647827cba2SAaron LI 
41657827cba2SAaron LI 	/* Firewire and InfiniBand interfaces require ClientID and
41667827cba2SAaron LI 	 * the broadcast option being set. */
4167d4fb1e02SRoy Marples 	switch (ifp->hwtype) {
41687827cba2SAaron LI 	case ARPHRD_IEEE1394:	/* FALLTHROUGH */
41697827cba2SAaron LI 	case ARPHRD_INFINIBAND:
41707827cba2SAaron LI 		ifp->options->options |= DHCPCD_CLIENTID | DHCPCD_BROADCAST;
41717827cba2SAaron LI 		break;
41727827cba2SAaron LI 	}
41737827cba2SAaron LI 
41747827cba2SAaron LI 	/* If we violate RFC2131 section 3.7 then require ARP
41757827cba2SAaron LI 	 * to detect if any other client wants our address. */
41767827cba2SAaron LI 	if (ifp->options->options & DHCPCD_LASTLEASE_EXTEND)
41777827cba2SAaron LI 		ifp->options->options |= DHCPCD_ARP;
41787827cba2SAaron LI 
41797827cba2SAaron LI 	/* No point in delaying a static configuration */
41807827cba2SAaron LI 	if (ifp->options->options & DHCPCD_STATIC ||
41817827cba2SAaron LI 	    !(ifp->options->options & DHCPCD_INITIAL_DELAY))
41827827cba2SAaron LI 	{
41837827cba2SAaron LI 		dhcp_start1(ifp);
41847827cba2SAaron LI 		return;
41857827cba2SAaron LI 	}
41867827cba2SAaron LI 
41877827cba2SAaron LI #ifdef ARPING
41887827cba2SAaron LI 	/* If we have arpinged then we have already delayed. */
41897827cba2SAaron LI 	state = D_CSTATE(ifp);
41907827cba2SAaron LI 	if (state != NULL && state->arping_index != -1) {
41917827cba2SAaron LI 		dhcp_start1(ifp);
41927827cba2SAaron LI 		return;
41937827cba2SAaron LI 	}
41947827cba2SAaron LI #endif
41956e63cc1fSRoy Marples 	delay = MSEC_PER_SEC +
41966e63cc1fSRoy Marples 		(arc4random_uniform(MSEC_PER_SEC * 2) - MSEC_PER_SEC);
41977827cba2SAaron LI 	logdebugx("%s: delaying IPv4 for %0.1f seconds",
41986e63cc1fSRoy Marples 	    ifp->name, (float)delay / MSEC_PER_SEC);
41997827cba2SAaron LI 
42006e63cc1fSRoy Marples 	eloop_timeout_add_msec(ifp->ctx->eloop, delay, dhcp_start1, ifp);
42017827cba2SAaron LI }
42027827cba2SAaron LI 
42037827cba2SAaron LI void
dhcp_abort(struct interface * ifp)42047827cba2SAaron LI dhcp_abort(struct interface *ifp)
42057827cba2SAaron LI {
42067827cba2SAaron LI 	struct dhcp_state *state;
42077827cba2SAaron LI 
42087827cba2SAaron LI 	state = D_STATE(ifp);
42097827cba2SAaron LI #ifdef ARPING
42107827cba2SAaron LI 	if (state != NULL)
42117827cba2SAaron LI 		state->arping_index = -1;
42127827cba2SAaron LI #endif
42137827cba2SAaron LI 
42147827cba2SAaron LI 	eloop_timeout_delete(ifp->ctx->eloop, dhcp_start1, ifp);
42157827cba2SAaron LI 
42167827cba2SAaron LI 	if (state != NULL && state->added) {
42177827cba2SAaron LI 		rt_build(ifp->ctx, AF_INET);
42187827cba2SAaron LI #ifdef ARP
4219d4fb1e02SRoy Marples 		if (ifp->options->options & DHCPCD_ARP)
42207827cba2SAaron LI 			arp_announceaddr(ifp->ctx, &state->addr->addr);
42217827cba2SAaron LI #endif
42227827cba2SAaron LI 	}
42237827cba2SAaron LI }
42247827cba2SAaron LI 
42251b3b16a2SRoy Marples struct ipv4_addr *
dhcp_handleifa(int cmd,struct ipv4_addr * ia,pid_t pid)42267827cba2SAaron LI dhcp_handleifa(int cmd, struct ipv4_addr *ia, pid_t pid)
42277827cba2SAaron LI {
42287827cba2SAaron LI 	struct interface *ifp;
42297827cba2SAaron LI 	struct dhcp_state *state;
42307827cba2SAaron LI 	struct if_options *ifo;
42317827cba2SAaron LI 	uint8_t i;
42327827cba2SAaron LI 
42337827cba2SAaron LI 	ifp = ia->iface;
42347827cba2SAaron LI 	state = D_STATE(ifp);
42357827cba2SAaron LI 	if (state == NULL || state->state == DHS_NONE)
42361b3b16a2SRoy Marples 		return ia;
42377827cba2SAaron LI 
42387827cba2SAaron LI 	if (cmd == RTM_DELADDR) {
42397827cba2SAaron LI 		if (state->addr == ia) {
42407827cba2SAaron LI 			loginfox("%s: pid %d deleted IP address %s",
42417827cba2SAaron LI 			    ifp->name, pid, ia->saddr);
42426e63cc1fSRoy Marples 			dhcp_close(ifp);
42437827cba2SAaron LI 			state->addr = NULL;
42447827cba2SAaron LI 			/* Don't clear the added state as we need
42457827cba2SAaron LI 			 * to drop the lease. */
42467827cba2SAaron LI 			dhcp_drop(ifp, "EXPIRE");
42477827cba2SAaron LI 			dhcp_start1(ifp);
4248b9ccd228SRoy Marples 			return ia;
42497827cba2SAaron LI 		}
42507827cba2SAaron LI 	}
42517827cba2SAaron LI 
42527827cba2SAaron LI 	if (cmd != RTM_NEWADDR)
42531b3b16a2SRoy Marples 		return ia;
42547827cba2SAaron LI 
42557827cba2SAaron LI #ifdef IN_IFF_NOTUSEABLE
42568d36e1dfSRoy Marples 	if (!(ia->addr_flags & IN_IFF_NOTUSEABLE))
42578d36e1dfSRoy Marples 		dhcp_finish_dad(ifp, &ia->addr);
42588d36e1dfSRoy Marples 	else if (ia->addr_flags & IN_IFF_DUPLICATED)
42591b3b16a2SRoy Marples 		return dhcp_addr_duplicated(ifp, &ia->addr) ? NULL : ia;
42607827cba2SAaron LI #endif
42617827cba2SAaron LI 
42627827cba2SAaron LI 	ifo = ifp->options;
4263b2927f2bSRoy Marples 
4264b2927f2bSRoy Marples #ifdef PRIVSEP
4265b2927f2bSRoy Marples 	if (IN_PRIVSEP_SE(ifp->ctx) &&
42660a68f8d2SRoy Marples 	    !(ifp->ctx->options & (DHCPCD_MANAGER | DHCPCD_CONFIGURE)) &&
4267b2927f2bSRoy Marples 	    IN_ARE_ADDR_EQUAL(&state->lease.addr, &ia->addr))
4268b2927f2bSRoy Marples 	{
4269b2927f2bSRoy Marples 		state->addr = ia;
4270b2927f2bSRoy Marples 		state->added = STATE_ADDED;
4271b2927f2bSRoy Marples 		dhcp_closebpf(ifp);
4272b2927f2bSRoy Marples 		if (ps_inet_openbootp(ia) == -1)
4273b2927f2bSRoy Marples 		    logerr(__func__);
4274b2927f2bSRoy Marples 	}
4275b2927f2bSRoy Marples #endif
4276b2927f2bSRoy Marples 
42770a68f8d2SRoy Marples 	/* If we have requested a specific address, return now.
42780a68f8d2SRoy Marples 	 * The below code is only for when inform or static has been
42790a68f8d2SRoy Marples 	 * requested without a specific address. */
42800a68f8d2SRoy Marples 	if (ifo->req_addr.s_addr != INADDR_ANY)
42810a68f8d2SRoy Marples 		return ia;
42820a68f8d2SRoy Marples 
42830a68f8d2SRoy Marples 	/* Only inform if we are NOT in the inform state or bound. */
42847827cba2SAaron LI 	if (ifo->options & DHCPCD_INFORM) {
42850a68f8d2SRoy Marples 		if (state->state != DHS_INFORM && state->state != DHS_BOUND)
42867827cba2SAaron LI 			dhcp_inform(ifp);
42871b3b16a2SRoy Marples 		return ia;
42887827cba2SAaron LI 	}
42897827cba2SAaron LI 
42900a68f8d2SRoy Marples 	/* Static and inform are mutually exclusive. If not static, return. */
42917827cba2SAaron LI 	if (!(ifo->options & DHCPCD_STATIC))
42921b3b16a2SRoy Marples 		return ia;
42937827cba2SAaron LI 
42947827cba2SAaron LI 	free(state->old);
42957827cba2SAaron LI 	state->old = state->new;
42967827cba2SAaron LI 	state->new_len = dhcp_message_new(&state->new, &ia->addr, &ia->mask);
42977827cba2SAaron LI 	if (state->new == NULL)
42981b3b16a2SRoy Marples 		return ia;
42990a68f8d2SRoy Marples 
43007827cba2SAaron LI 	if (ifp->flags & IFF_POINTOPOINT) {
43017827cba2SAaron LI 		for (i = 1; i < 255; i++)
43027827cba2SAaron LI 			if (i != DHO_ROUTER && has_option_mask(ifo->dstmask,i))
43037827cba2SAaron LI 				dhcp_message_add_addr(state->new, i, ia->brd);
43047827cba2SAaron LI 	}
43050a68f8d2SRoy Marples 
43067827cba2SAaron LI 	state->reason = "STATIC";
43077827cba2SAaron LI 	rt_build(ifp->ctx, AF_INET);
43087827cba2SAaron LI 	script_runreason(ifp, state->reason);
43091b3b16a2SRoy Marples 
43101b3b16a2SRoy Marples 	return ia;
43117827cba2SAaron LI }
4312d4fb1e02SRoy Marples 
4313d4fb1e02SRoy Marples #ifndef SMALL
4314d4fb1e02SRoy Marples int
dhcp_dump(struct interface * ifp)4315d4fb1e02SRoy Marples dhcp_dump(struct interface *ifp)
4316d4fb1e02SRoy Marples {
4317d4fb1e02SRoy Marples 	struct dhcp_state *state;
4318d4fb1e02SRoy Marples 
4319d4fb1e02SRoy Marples 	ifp->if_data[IF_DATA_DHCP] = state = calloc(1, sizeof(*state));
4320d4fb1e02SRoy Marples 	if (state == NULL) {
4321d4fb1e02SRoy Marples 		logerr(__func__);
4322d4fb1e02SRoy Marples 		return -1;
4323d4fb1e02SRoy Marples 	}
4324d4fb1e02SRoy Marples 	state->new_len = read_lease(ifp, &state->new);
4325d4fb1e02SRoy Marples 	if (state->new == NULL) {
4326d4fb1e02SRoy Marples 		logerr("read_lease");
4327d4fb1e02SRoy Marples 		return -1;
4328d4fb1e02SRoy Marples 	}
4329d4fb1e02SRoy Marples 	state->reason = "DUMP";
4330d4fb1e02SRoy Marples 	return script_runreason(ifp, state->reason);
4331d4fb1e02SRoy Marples }
4332d4fb1e02SRoy Marples #endif
4333