1*df69c215Sderaadt /* $OpenBSD: bpf.c,v 1.27 2019/06/28 13:32:50 deraadt Exp $ */
2540eaef7Sderaadt /* $NetBSD: bpf.c,v 1.5.2.1 1995/11/14 08:45:42 thorpej Exp $ */
3df930be7Sderaadt
4df930be7Sderaadt /*
5df930be7Sderaadt * Copyright (c) 1988, 1992 The University of Utah and the Center
6df930be7Sderaadt * for Software Science (CSS).
7df930be7Sderaadt * Copyright (c) 1992, 1993
8df930be7Sderaadt * The Regents of the University of California. All rights reserved.
9df930be7Sderaadt *
10df930be7Sderaadt * This code is derived from software contributed to Berkeley by
11df930be7Sderaadt * the Center for Software Science of the University of Utah Computer
12df930be7Sderaadt * Science Department. CSS requests users of this software to return
13df930be7Sderaadt * to css-dist@cs.utah.edu any improvements that they make and grant
14df930be7Sderaadt * CSS redistribution rights.
15df930be7Sderaadt *
16df930be7Sderaadt * Redistribution and use in source and binary forms, with or without
17df930be7Sderaadt * modification, are permitted provided that the following conditions
18df930be7Sderaadt * are met:
19df930be7Sderaadt * 1. Redistributions of source code must retain the above copyright
20df930be7Sderaadt * notice, this list of conditions and the following disclaimer.
21df930be7Sderaadt * 2. Redistributions in binary form must reproduce the above copyright
22df930be7Sderaadt * notice, this list of conditions and the following disclaimer in the
23df930be7Sderaadt * documentation and/or other materials provided with the distribution.
2429295d1cSmillert * 3. Neither the name of the University nor the names of its contributors
25df930be7Sderaadt * may be used to endorse or promote products derived from this software
26df930be7Sderaadt * without specific prior written permission.
27df930be7Sderaadt *
28df930be7Sderaadt * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
29df930be7Sderaadt * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
30df930be7Sderaadt * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
31df930be7Sderaadt * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
32df930be7Sderaadt * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
33df930be7Sderaadt * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
34df930be7Sderaadt * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
35df930be7Sderaadt * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
36df930be7Sderaadt * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
37df930be7Sderaadt * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
38df930be7Sderaadt * SUCH DAMAGE.
39df930be7Sderaadt *
40df930be7Sderaadt * from: @(#)bpf.c 8.1 (Berkeley) 6/4/93
41df930be7Sderaadt *
42df930be7Sderaadt * From: Utah Hdr: bpf.c 3.1 92/07/06
43df930be7Sderaadt * Author: Jeff Forys, University of Utah CSS
44df930be7Sderaadt */
45df930be7Sderaadt
46df930be7Sderaadt #include <sys/ioctl.h>
47df930be7Sderaadt #include <sys/socket.h>
48df930be7Sderaadt
49df930be7Sderaadt #include <net/if.h>
50df930be7Sderaadt #include <net/bpf.h>
51df930be7Sderaadt
52df930be7Sderaadt #include <ctype.h>
53df930be7Sderaadt #include <errno.h>
54df930be7Sderaadt #include <fcntl.h>
550fd3b650Smiod #include <stddef.h>
56df930be7Sderaadt #include <stdio.h>
57df930be7Sderaadt #include <stdlib.h>
58df930be7Sderaadt #include <string.h>
59df930be7Sderaadt #include <syslog.h>
60df930be7Sderaadt #include <unistd.h>
61a47b6461Sderaadt #include <limits.h>
62e24fa105Sitojun #include <ifaddrs.h>
63df930be7Sderaadt #include "defs.h"
64df930be7Sderaadt
65df930be7Sderaadt static int BpfFd = -1;
661c711ca7Sderaadt static unsigned int BpfLen = 0;
67df930be7Sderaadt static u_int8_t *BpfPkt = NULL;
68df930be7Sderaadt
69df930be7Sderaadt /*
70df930be7Sderaadt ** BpfOpen -- Open and initialize a BPF device.
71df930be7Sderaadt **
72df930be7Sderaadt ** Parameters:
73df930be7Sderaadt ** None.
74df930be7Sderaadt **
75df930be7Sderaadt ** Returns:
76b40ea22fSderaadt ** File descriptor of opened BPF device
77df930be7Sderaadt **
78df930be7Sderaadt ** Side Effects:
79df930be7Sderaadt ** If an error is encountered, the program terminates here.
80df930be7Sderaadt */
81df930be7Sderaadt int
BpfOpen(void)8239883a76Sderaadt BpfOpen(void)
83df930be7Sderaadt {
84df930be7Sderaadt struct ifreq ifr;
852abf9a0dSnatano int n;
86df930be7Sderaadt
877b08a90aSnatano if ((BpfFd = open("/dev/bpf", O_RDWR)) == -1) {
882abf9a0dSnatano syslog(LOG_ERR, "bpf: can't open device: %m");
89404b31ceSmiod DoExit();
90df930be7Sderaadt }
91df930be7Sderaadt
92df930be7Sderaadt /*
93df930be7Sderaadt * Set interface name for bpf device, get data link layer
94df930be7Sderaadt * type and make sure it's type Ethernet.
95df930be7Sderaadt */
96df930be7Sderaadt (void) strncpy(ifr.ifr_name, IntfName, sizeof(ifr.ifr_name));
97*df69c215Sderaadt if (ioctl(BpfFd, BIOCSETIF, (caddr_t)&ifr) == -1) {
98df930be7Sderaadt syslog(LOG_ERR, "bpf: ioctl(BIOCSETIF,%s): %m", IntfName);
99404b31ceSmiod DoExit();
100df930be7Sderaadt }
101df930be7Sderaadt
102df930be7Sderaadt /*
103df930be7Sderaadt * Make sure we are dealing with an Ethernet device.
104df930be7Sderaadt */
105*df69c215Sderaadt if (ioctl(BpfFd, BIOCGDLT, (caddr_t)&n) == -1) {
106df930be7Sderaadt syslog(LOG_ERR, "bpf: ioctl(BIOCGDLT): %m");
107404b31ceSmiod DoExit();
108df930be7Sderaadt }
109df930be7Sderaadt if (n != DLT_EN10MB) {
110df930be7Sderaadt syslog(LOG_ERR,"bpf: %s: data-link type %d unsupported",
111df930be7Sderaadt IntfName, n);
112404b31ceSmiod DoExit();
113df930be7Sderaadt }
114df930be7Sderaadt
115df930be7Sderaadt /*
116df930be7Sderaadt * On read(), return packets immediately (do not buffer them).
117df930be7Sderaadt */
118df930be7Sderaadt n = 1;
119*df69c215Sderaadt if (ioctl(BpfFd, BIOCIMMEDIATE, (caddr_t)&n) == -1) {
120df930be7Sderaadt syslog(LOG_ERR, "bpf: ioctl(BIOCIMMEDIATE): %m");
121404b31ceSmiod DoExit();
122df930be7Sderaadt }
123df930be7Sderaadt
124df930be7Sderaadt /*
125df930be7Sderaadt * Try to enable the chip/driver's multicast address filter to
126df930be7Sderaadt * grab our RMP address. If this fails, try promiscuous mode.
127df930be7Sderaadt * If this fails, there's no way we are going to get any RMP
128df930be7Sderaadt * packets so just exit here.
129df930be7Sderaadt */
130df930be7Sderaadt #ifdef MSG_EOR
131df930be7Sderaadt ifr.ifr_addr.sa_len = RMP_ADDRLEN + 2;
132df930be7Sderaadt #endif
133df930be7Sderaadt ifr.ifr_addr.sa_family = AF_UNSPEC;
134df930be7Sderaadt bcopy(&RmpMcastAddr[0], (char *)&ifr.ifr_addr.sa_data[0], RMP_ADDRLEN);
135*df69c215Sderaadt if (ioctl(BpfFd, SIOCADDMULTI, (caddr_t)&ifr) == -1) {
136df930be7Sderaadt syslog(LOG_WARNING,
137df930be7Sderaadt "bpf: can't add mcast addr (%m), setting promiscuous mode");
138df930be7Sderaadt
139*df69c215Sderaadt if (ioctl(BpfFd, BIOCPROMISC, (caddr_t)0) == -1) {
140df930be7Sderaadt syslog(LOG_ERR, "bpf: can't set promiscuous mode: %m");
141404b31ceSmiod DoExit();
142df930be7Sderaadt }
143df930be7Sderaadt }
144df930be7Sderaadt
145df930be7Sderaadt /*
146df930be7Sderaadt * Ask BPF how much buffer space it requires and allocate one.
147df930be7Sderaadt */
148*df69c215Sderaadt if (ioctl(BpfFd, BIOCGBLEN, (caddr_t)&BpfLen) == -1) {
149df930be7Sderaadt syslog(LOG_ERR, "bpf: ioctl(BIOCGBLEN): %m");
150404b31ceSmiod DoExit();
151df930be7Sderaadt }
152df930be7Sderaadt if (BpfPkt == NULL)
15335de856eSderaadt BpfPkt = malloc(BpfLen);
154df930be7Sderaadt
155df930be7Sderaadt if (BpfPkt == NULL) {
156df930be7Sderaadt syslog(LOG_ERR, "bpf: out of memory (%u bytes for bpfpkt)",
157df930be7Sderaadt BpfLen);
158404b31ceSmiod DoExit();
159df930be7Sderaadt }
160df930be7Sderaadt
161df930be7Sderaadt /*
162df930be7Sderaadt * Write a little program to snarf RMP Boot packets and stuff
163df930be7Sderaadt * it down BPF's throat (i.e. set up the packet filter).
164df930be7Sderaadt */
165df930be7Sderaadt {
1660fd3b650Smiod #define RMP(field) offsetof(struct rmp_packet, field)
167df930be7Sderaadt static struct bpf_insn bpf_insn[] = {
16819b188a7Scanacar /* make sure it is a 802.3 packet */
1690fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_hdr.len) },
17019b188a7Scanacar { BPF_JMP|BPF_JGE|BPF_K, 7, 0, 0x600 },
17119b188a7Scanacar
1720fd3b650Smiod { BPF_LD|BPF_B|BPF_ABS, 0, 0, RMP(hp_llc.dsap) },
173df930be7Sderaadt { BPF_JMP|BPF_JEQ|BPF_K, 0, 5, IEEE_DSAP_HP },
1740fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_llc.cntrl) },
175df930be7Sderaadt { BPF_JMP|BPF_JEQ|BPF_K, 0, 3, IEEE_CNTL_HP },
1760fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_llc.dxsap) },
177df930be7Sderaadt { BPF_JMP|BPF_JEQ|BPF_K, 0, 1, HPEXT_DXSAP },
178df930be7Sderaadt { BPF_RET|BPF_K, 0, 0, RMP_MAX_PACKET },
179df930be7Sderaadt { BPF_RET|BPF_K, 0, 0, 0x0 }
180df930be7Sderaadt };
18119b188a7Scanacar
18219b188a7Scanacar static struct bpf_insn bpf_wf_insn[] = {
18319b188a7Scanacar /* make sure it is a 802.3 packet */
1840fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_hdr.len) },
18519b188a7Scanacar { BPF_JMP|BPF_JGE|BPF_K, 12, 0, 0x600 },
18619b188a7Scanacar
18719b188a7Scanacar /* check the SNAP header */
1880fd3b650Smiod { BPF_LD|BPF_B|BPF_ABS, 0, 0, RMP(hp_llc.dsap) },
18919b188a7Scanacar { BPF_JMP|BPF_JEQ|BPF_K, 0, 10, IEEE_DSAP_HP },
1900fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_llc.cntrl) },
19119b188a7Scanacar { BPF_JMP|BPF_JEQ|BPF_K, 0, 8, IEEE_CNTL_HP },
19219b188a7Scanacar
1930fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_llc.sxsap) },
19419b188a7Scanacar { BPF_JMP|BPF_JEQ|BPF_K, 0, 6, HPEXT_DXSAP },
1950fd3b650Smiod { BPF_LD|BPF_H|BPF_ABS, 0, 0, RMP(hp_llc.dxsap) },
19619b188a7Scanacar { BPF_JMP|BPF_JEQ|BPF_K, 0, 4, HPEXT_SXSAP },
19719b188a7Scanacar
19819b188a7Scanacar /* check return type code */
19919b188a7Scanacar { BPF_LD|BPF_B|BPF_ABS, 0, 0,
2000fd3b650Smiod RMP(rmp_proto.rmp_raw.rmp_type) },
20119b188a7Scanacar { BPF_JMP|BPF_JEQ|BPF_K, 1, 0, RMP_BOOT_REPL },
20219b188a7Scanacar { BPF_JMP|BPF_JEQ|BPF_K, 0, 1, RMP_READ_REPL },
20319b188a7Scanacar
20419b188a7Scanacar { BPF_RET|BPF_K, 0, 0, RMP_MAX_PACKET },
20519b188a7Scanacar { BPF_RET|BPF_K, 0, 0, 0x0 }
20619b188a7Scanacar };
207df930be7Sderaadt #undef RMP
208df930be7Sderaadt static struct bpf_program bpf_pgm = {
209df930be7Sderaadt sizeof(bpf_insn)/sizeof(bpf_insn[0]), bpf_insn
210df930be7Sderaadt };
211df930be7Sderaadt
21219b188a7Scanacar static struct bpf_program bpf_w_pgm = {
21319b188a7Scanacar sizeof(bpf_wf_insn)/sizeof(bpf_wf_insn[0]), bpf_wf_insn
21419b188a7Scanacar };
21519b188a7Scanacar
216*df69c215Sderaadt if (ioctl(BpfFd, BIOCSETF, (caddr_t)&bpf_pgm) == -1) {
217df930be7Sderaadt syslog(LOG_ERR, "bpf: ioctl(BIOCSETF): %m");
218404b31ceSmiod DoExit();
219df930be7Sderaadt }
22019b188a7Scanacar
221*df69c215Sderaadt if (ioctl(BpfFd, BIOCSETWF, (caddr_t)&bpf_w_pgm) == -1) {
22219b188a7Scanacar syslog(LOG_ERR, "bpf: ioctl(BIOCSETWF): %m");
22319b188a7Scanacar DoExit();
22419b188a7Scanacar }
22519b188a7Scanacar
226*df69c215Sderaadt if (ioctl(BpfFd, BIOCLOCK) == -1) {
22719b188a7Scanacar syslog(LOG_ERR, "bpf: ioctl(BIOCLOCK): %m");
22819b188a7Scanacar DoExit();
22919b188a7Scanacar }
230df930be7Sderaadt }
231df930be7Sderaadt
232df930be7Sderaadt return(BpfFd);
233df930be7Sderaadt }
234df930be7Sderaadt
235df930be7Sderaadt /*
236df930be7Sderaadt ** BPF GetIntfName -- Return the name of a network interface attached to
237df930be7Sderaadt ** the system, or 0 if none can be found. The interface
238df930be7Sderaadt ** must be configured up; the lowest unit number is
239df930be7Sderaadt ** preferred; loopback is ignored.
240df930be7Sderaadt **
241df930be7Sderaadt ** Parameters:
242df930be7Sderaadt ** errmsg - if no network interface found, *errmsg explains why.
243df930be7Sderaadt **
244df930be7Sderaadt ** Returns:
245df930be7Sderaadt ** A (static) pointer to interface name, or NULL on error.
246df930be7Sderaadt **
247df930be7Sderaadt ** Side Effects:
248df930be7Sderaadt ** None.
249df930be7Sderaadt */
250df930be7Sderaadt char *
BpfGetIntfName(char ** errmsg)25139883a76Sderaadt BpfGetIntfName(char **errmsg)
252df930be7Sderaadt {
25375a39e5eSderaadt int minunit = 999, n;
254df930be7Sderaadt char *cp;
255a47b6461Sderaadt const char *errstr;
256e24fa105Sitojun static char device[IFNAMSIZ];
257df930be7Sderaadt static char errbuf[128] = "No Error!";
25875a39e5eSderaadt struct ifaddrs *ifap, *ifa, *mp = NULL;
259df930be7Sderaadt
260df930be7Sderaadt if (errmsg != NULL)
261df930be7Sderaadt *errmsg = errbuf;
262df930be7Sderaadt
263e24fa105Sitojun if (getifaddrs(&ifap) != 0) {
264e24fa105Sitojun (void) strlcpy(errbuf, "bpf: getifaddrs: %m", sizeof(errbuf));
265df930be7Sderaadt return(NULL);
266df930be7Sderaadt }
267df930be7Sderaadt
268e24fa105Sitojun for (ifa = ifap; ifa; ifa = ifa->ifa_next) {
269df930be7Sderaadt /*
270df930be7Sderaadt * If interface is down or this is the loopback interface,
271df930be7Sderaadt * ignore it.
272df930be7Sderaadt */
273e24fa105Sitojun if ((ifa->ifa_flags & IFF_UP) == 0 ||
274df930be7Sderaadt #ifdef IFF_LOOPBACK
275e24fa105Sitojun (ifa->ifa_flags & IFF_LOOPBACK))
276df930be7Sderaadt #else
277e24fa105Sitojun (strcmp(ifa->ifa_name, "lo0") == 0))
278df930be7Sderaadt #endif
279df930be7Sderaadt continue;
280df930be7Sderaadt
281c75478feSderaadt for (cp = ifa->ifa_name; !isdigit((unsigned char)*cp); ++cp)
282df930be7Sderaadt ;
283a47b6461Sderaadt n = strtonum(cp, 0, INT_MAX, &errstr);
284a47b6461Sderaadt if (errstr == NULL && n < minunit) {
285df930be7Sderaadt minunit = n;
286e24fa105Sitojun mp = ifa;
287df930be7Sderaadt }
288df930be7Sderaadt }
289df930be7Sderaadt
290df930be7Sderaadt if (mp == 0) {
2917dbc111bSmickey (void) strlcpy(errbuf, "bpf: no interfaces found",
2927dbc111bSmickey sizeof(errbuf));
29317ca6decSitojun freeifaddrs(ifap);
294df930be7Sderaadt return(NULL);
295df930be7Sderaadt }
296df930be7Sderaadt
297e24fa105Sitojun (void) strlcpy(device, mp->ifa_name, sizeof device);
298e24fa105Sitojun freeifaddrs(ifap);
299df930be7Sderaadt return(device);
300df930be7Sderaadt }
301df930be7Sderaadt
302df930be7Sderaadt /*
303df930be7Sderaadt ** BpfRead -- Read packets from a BPF device and fill in `rconn'.
304df930be7Sderaadt **
305df930be7Sderaadt ** Parameters:
306df930be7Sderaadt ** rconn - filled in with next packet.
307df930be7Sderaadt ** doread - is True if we can issue a read() syscall.
308df930be7Sderaadt **
309df930be7Sderaadt ** Returns:
310df930be7Sderaadt ** True if `rconn' contains a new packet, False otherwise.
311df930be7Sderaadt **
312df930be7Sderaadt ** Side Effects:
313df930be7Sderaadt ** None.
314df930be7Sderaadt */
315df930be7Sderaadt int
BpfRead(RMPCONN * rconn,int doread)31639883a76Sderaadt BpfRead(RMPCONN *rconn, int doread)
317df930be7Sderaadt {
3180ac0d02eSmpech int datlen, caplen, hdrlen;
319df930be7Sderaadt static u_int8_t *bp = NULL, *ep = NULL;
320df930be7Sderaadt int cc;
321df930be7Sderaadt
322df930be7Sderaadt /*
323df930be7Sderaadt * The read() may block, or it may return one or more packets.
324df930be7Sderaadt * We let the caller decide whether or not we can issue a read().
325df930be7Sderaadt */
326df930be7Sderaadt if (doread) {
327*df69c215Sderaadt if ((cc = read(BpfFd, (char *)BpfPkt, (int)BpfLen)) == -1) {
328df930be7Sderaadt syslog(LOG_ERR, "bpf: read: %m");
329df930be7Sderaadt return(0);
330df930be7Sderaadt } else {
331df930be7Sderaadt bp = BpfPkt;
332df930be7Sderaadt ep = BpfPkt + cc;
333df930be7Sderaadt }
334df930be7Sderaadt }
335df930be7Sderaadt
336df930be7Sderaadt #define bhp ((struct bpf_hdr *)bp)
337df930be7Sderaadt /*
338df930be7Sderaadt * If there is a new packet in the buffer, stuff it into `rconn'
339df930be7Sderaadt * and return a success indication.
340df930be7Sderaadt */
341df930be7Sderaadt if (bp < ep) {
342df930be7Sderaadt datlen = bhp->bh_datalen;
343df930be7Sderaadt caplen = bhp->bh_caplen;
344df930be7Sderaadt hdrlen = bhp->bh_hdrlen;
345df930be7Sderaadt
346df930be7Sderaadt if (caplen != datlen)
347df930be7Sderaadt syslog(LOG_ERR,
348df930be7Sderaadt "bpf: short packet dropped (%d of %d bytes)",
349df930be7Sderaadt caplen, datlen);
350df930be7Sderaadt else if (caplen > sizeof(struct rmp_packet))
351df930be7Sderaadt syslog(LOG_ERR, "bpf: large packet dropped (%d bytes)",
352df930be7Sderaadt caplen);
353df930be7Sderaadt else {
354540eaef7Sderaadt rconn->rmplen = caplen;
355376cf3acSnatano rconn->tstamp.tv_sec = bhp->bh_tstamp.tv_sec;
356376cf3acSnatano rconn->tstamp.tv_usec = bhp->bh_tstamp.tv_usec;
357df930be7Sderaadt bcopy((char *)bp + hdrlen, (char *)&rconn->rmp, caplen);
358df930be7Sderaadt }
359df930be7Sderaadt bp += BPF_WORDALIGN(caplen + hdrlen);
360df930be7Sderaadt return(1);
361df930be7Sderaadt }
362df930be7Sderaadt #undef bhp
363df930be7Sderaadt
364df930be7Sderaadt return(0);
365df930be7Sderaadt }
366df930be7Sderaadt
367df930be7Sderaadt /*
368df930be7Sderaadt ** BpfWrite -- Write packet to BPF device.
369df930be7Sderaadt **
370df930be7Sderaadt ** Parameters:
371df930be7Sderaadt ** rconn - packet to send.
372df930be7Sderaadt **
373df930be7Sderaadt ** Returns:
374df930be7Sderaadt ** True if write succeeded, False otherwise.
375df930be7Sderaadt **
376df930be7Sderaadt ** Side Effects:
377df930be7Sderaadt ** None.
378df930be7Sderaadt */
379df930be7Sderaadt int
BpfWrite(RMPCONN * rconn)38039883a76Sderaadt BpfWrite(RMPCONN *rconn)
381df930be7Sderaadt {
382*df69c215Sderaadt if (write(BpfFd, (char *)&rconn->rmp, rconn->rmplen) == -1) {
383df930be7Sderaadt syslog(LOG_ERR, "write: %s: %m", EnetStr(rconn));
384df930be7Sderaadt return(0);
385df930be7Sderaadt }
386df930be7Sderaadt
387df930be7Sderaadt return(1);
388df930be7Sderaadt }
389