1*a915386bSclaudio /* $OpenBSD: packet.c,v 1.17 2021/01/19 16:02:22 claudio Exp $ */
2ddeeec14Snorby
3ddeeec14Snorby /*
4ddeeec14Snorby * Copyright (c) 2006 Michele Marchetto <mydecay@openbeer.it>
5ddeeec14Snorby * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
6ddeeec14Snorby *
7ddeeec14Snorby * Permission to use, copy, modify, and distribute this software for any
8ddeeec14Snorby * purpose with or without fee is hereby granted, provided that the above
9ddeeec14Snorby * copyright notice and this permission notice appear in all copies.
10ddeeec14Snorby *
11ddeeec14Snorby * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12ddeeec14Snorby * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13ddeeec14Snorby * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14ddeeec14Snorby * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15ddeeec14Snorby * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16ddeeec14Snorby * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17ddeeec14Snorby * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18ddeeec14Snorby */
19ddeeec14Snorby
20ddeeec14Snorby #include <sys/types.h>
21ddeeec14Snorby #include <sys/socket.h>
22ddeeec14Snorby #include <sys/uio.h>
23ddeeec14Snorby
24ddeeec14Snorby #include <netinet/in.h>
25ddeeec14Snorby #include <netinet/ip.h>
26ddeeec14Snorby #include <netinet/udp.h>
27ddeeec14Snorby #include <arpa/inet.h>
28ddeeec14Snorby
29ddeeec14Snorby #include <net/if_dl.h>
30ddeeec14Snorby
31ddeeec14Snorby #include <errno.h>
32ddeeec14Snorby #include <event.h>
33ddeeec14Snorby #include <stdlib.h>
34ddeeec14Snorby #include <string.h>
35ddeeec14Snorby
36ddeeec14Snorby #include "ripd.h"
37ddeeec14Snorby #include "rip.h"
38ddeeec14Snorby #include "log.h"
39ddeeec14Snorby #include "ripe.h"
40ddeeec14Snorby
41ddeeec14Snorby int rip_hdr_sanity_check(struct rip_hdr *);
42ddeeec14Snorby struct iface *find_iface(struct ripd_conf *, unsigned int, struct in_addr);
43ddeeec14Snorby
44*a915386bSclaudio static u_int8_t *recv_buf;
45*a915386bSclaudio
46ddeeec14Snorby int
gen_rip_hdr(struct ibuf * buf,u_int8_t command)47e39620e5Snicm gen_rip_hdr(struct ibuf *buf, u_int8_t command)
48ddeeec14Snorby {
49ddeeec14Snorby struct rip_hdr rip_hdr;
50ddeeec14Snorby
51ddeeec14Snorby bzero(&rip_hdr, sizeof(rip_hdr));
52ddeeec14Snorby rip_hdr.version = RIP_VERSION;
53ddeeec14Snorby rip_hdr.command = command;
54ddeeec14Snorby
55e39620e5Snicm return (ibuf_add(buf, &rip_hdr, sizeof(rip_hdr)));
56ddeeec14Snorby }
57ddeeec14Snorby
58ddeeec14Snorby /* send and receive packets */
59ddeeec14Snorby int
send_packet(struct iface * iface,void * pkt,size_t len,struct sockaddr_in * dst)60ddeeec14Snorby send_packet(struct iface *iface, void *pkt, size_t len, struct sockaddr_in *dst)
61ddeeec14Snorby {
62ddeeec14Snorby /* set outgoing interface for multicast traffic */
63ddeeec14Snorby if (IN_MULTICAST(ntohl(dst->sin_addr.s_addr)))
64ddeeec14Snorby if (if_set_mcast(iface) == -1) {
65ddeeec14Snorby log_warn("send_packet: error setting multicast "
66ddeeec14Snorby "interface, %s", iface->name);
67ddeeec14Snorby return (-1);
68ddeeec14Snorby }
69ddeeec14Snorby
70ddeeec14Snorby if (sendto(iface->fd, pkt, len, 0,
71ddeeec14Snorby (struct sockaddr *)dst, sizeof(*dst)) == -1) {
72ddeeec14Snorby log_warn("send_packet: error sending packet on interface %s",
73ddeeec14Snorby iface->name);
74ddeeec14Snorby return (-1);
75ddeeec14Snorby }
76ddeeec14Snorby
77ddeeec14Snorby return (0);
78ddeeec14Snorby }
79ddeeec14Snorby
80ddeeec14Snorby void
recv_packet(int fd,short event,void * bula)81ddeeec14Snorby recv_packet(int fd, short event, void *bula)
82ddeeec14Snorby {
830827ab61Sderaadt union {
840827ab61Sderaadt struct cmsghdr hdr;
850827ab61Sderaadt char buf[CMSG_SPACE(sizeof(struct sockaddr_dl))];
860827ab61Sderaadt } cmsgbuf;
87ddeeec14Snorby struct sockaddr_in src;
88ddeeec14Snorby struct iovec iov;
89ddeeec14Snorby struct msghdr msg;
90ddeeec14Snorby struct cmsghdr *cmsg;
91ddeeec14Snorby struct sockaddr_dl *dst = NULL;
92ddeeec14Snorby struct nbr_failed *nbr_failed = NULL;
93ddeeec14Snorby struct ripd_conf *xconf = bula;
94ddeeec14Snorby struct iface *iface;
95ddeeec14Snorby struct rip_hdr *rip_hdr;
96ddeeec14Snorby struct nbr *nbr;
9787feb355Sclaudio u_int8_t *buf;
98ddeeec14Snorby ssize_t r;
99ddeeec14Snorby u_int16_t len, srcport;
100ddeeec14Snorby u_int32_t auth_crypt_num = 0;
101ddeeec14Snorby
102ddeeec14Snorby if (event != EV_READ)
103ddeeec14Snorby return;
104ddeeec14Snorby
105*a915386bSclaudio if (recv_buf == NULL)
106*a915386bSclaudio if ((recv_buf = malloc(READ_BUF_SIZE)) == NULL)
107*a915386bSclaudio fatal(__func__);
108*a915386bSclaudio
109ddeeec14Snorby /* setup buffer */
110ddeeec14Snorby bzero(&msg, sizeof(msg));
111*a915386bSclaudio iov.iov_base = buf = recv_buf;
112e4d7b1daSclaudio iov.iov_len = READ_BUF_SIZE;
113ddeeec14Snorby msg.msg_name = &src;
114ddeeec14Snorby msg.msg_namelen = sizeof(src);
115ddeeec14Snorby msg.msg_iov = &iov;
116ddeeec14Snorby msg.msg_iovlen = 1;
1170827ab61Sderaadt msg.msg_control = &cmsgbuf.buf;
118da15c7b9Sderaadt msg.msg_controllen = sizeof(cmsgbuf.buf);
119ddeeec14Snorby
120ddeeec14Snorby if ((r = recvmsg(fd, &msg, 0)) == -1) {
121ddeeec14Snorby if (errno != EINTR && errno != EAGAIN)
122ddeeec14Snorby log_debug("recv_packet: read error: %s",
123ddeeec14Snorby strerror(errno));
124ddeeec14Snorby return;
125ddeeec14Snorby }
126ddeeec14Snorby
127ddeeec14Snorby for (cmsg = CMSG_FIRSTHDR(&msg); cmsg != NULL;
128ddeeec14Snorby cmsg = CMSG_NXTHDR(&msg, cmsg)) {
129ddeeec14Snorby if (cmsg->cmsg_level == IPPROTO_IP &&
130ddeeec14Snorby cmsg->cmsg_type == IP_RECVIF) {
131ddeeec14Snorby dst = (struct sockaddr_dl *)CMSG_DATA(cmsg);
132ddeeec14Snorby break;
133ddeeec14Snorby }
134ddeeec14Snorby }
135ddeeec14Snorby
136ddeeec14Snorby if (dst == NULL)
137ddeeec14Snorby return;
138ddeeec14Snorby
139ddeeec14Snorby len = (u_int16_t)r;
140ddeeec14Snorby
141ddeeec14Snorby /* Check the packet is not from one of the local interfaces */
142ddeeec14Snorby LIST_FOREACH(iface, &xconf->iface_list, entry) {
143ddeeec14Snorby if (iface->addr.s_addr == src.sin_addr.s_addr)
144ddeeec14Snorby return;
145ddeeec14Snorby }
146ddeeec14Snorby
147ddeeec14Snorby /* find a matching interface */
148ddeeec14Snorby if ((iface = find_iface(xconf, dst->sdl_index, src.sin_addr)) == NULL) {
149ddeeec14Snorby log_debug("recv_packet: cannot find a matching interface");
150ddeeec14Snorby return;
151ddeeec14Snorby }
152ddeeec14Snorby
153ddeeec14Snorby srcport = ntohs(src.sin_port);
154ddeeec14Snorby
155ddeeec14Snorby /* RIP header sanity checks */
156ddeeec14Snorby if (len < RIP_HDR_LEN) {
157ddeeec14Snorby log_debug("recv_packet: bad packet size");
158ddeeec14Snorby return;
159ddeeec14Snorby }
160ddeeec14Snorby rip_hdr = (struct rip_hdr *)buf;
161ddeeec14Snorby
162ddeeec14Snorby if (rip_hdr_sanity_check(rip_hdr) == -1)
163ddeeec14Snorby return;
164ddeeec14Snorby
165ddeeec14Snorby nbr = nbr_find_ip(iface, src.sin_addr.s_addr);
166ddeeec14Snorby
167ddeeec14Snorby if (nbr == NULL && iface->auth_type == AUTH_CRYPT)
168ddeeec14Snorby nbr_failed = nbr_failed_find(iface, src.sin_addr.s_addr);
169ddeeec14Snorby
170ddeeec14Snorby /* switch RIP command */
171ddeeec14Snorby switch (rip_hdr->command) {
172ddeeec14Snorby case COMMAND_REQUEST:
173e3be6b29Smichele /* Requests don't create a real neighbor, just a temporary
174e3be6b29Smichele * one to build the response.
175e3be6b29Smichele */
176ddeeec14Snorby if ((msg.msg_flags & MSG_MCAST) == 0 && srcport == RIP_PORT)
177ddeeec14Snorby return;
178ddeeec14Snorby
179ddeeec14Snorby if (nbr == NULL) {
18063b45a5dSmichele nbr = nbr_new(src.sin_addr.s_addr, iface);
181ddeeec14Snorby nbr->addr = src.sin_addr;
182ddeeec14Snorby }
183ddeeec14Snorby nbr->port = srcport;
184ddeeec14Snorby nbr_fsm(nbr, NBR_EVT_REQUEST_RCVD);
185ddeeec14Snorby
186ddeeec14Snorby buf += RIP_HDR_LEN;
187ddeeec14Snorby len -= RIP_HDR_LEN;
188ddeeec14Snorby
189ddeeec14Snorby recv_request(iface, nbr, buf, len);
190ddeeec14Snorby break;
191ddeeec14Snorby case COMMAND_RESPONSE:
192ddeeec14Snorby if (srcport != RIP_PORT)
193ddeeec14Snorby return;
194ddeeec14Snorby
195ddeeec14Snorby if (auth_validate(&buf, &len, iface, nbr, nbr_failed,
196ddeeec14Snorby &auth_crypt_num)) {
197ddeeec14Snorby log_warnx("recv_packet: authentication error, "
198ddeeec14Snorby "interface %s", iface->name);
199ddeeec14Snorby return;
200ddeeec14Snorby }
201ddeeec14Snorby
202ddeeec14Snorby if (nbr == NULL) {
20363b45a5dSmichele nbr = nbr_new(src.sin_addr.s_addr, iface);
204ddeeec14Snorby if (nbr_failed != NULL)
205a4d2b8b2Smichele nbr_failed_delete(nbr_failed);
206ddeeec14Snorby nbr->addr = src.sin_addr;
207ddeeec14Snorby }
208ddeeec14Snorby nbr->auth_seq_num = auth_crypt_num;
209ddeeec14Snorby nbr_fsm(nbr, NBR_EVT_RESPONSE_RCVD);
210ddeeec14Snorby
211ddeeec14Snorby recv_response(iface, nbr, buf, len);
212ddeeec14Snorby break;
213ddeeec14Snorby default:
214ddeeec14Snorby log_debug("recv_packet: unknown RIP command, interface %s",
215ddeeec14Snorby iface->name);
216ddeeec14Snorby }
217ddeeec14Snorby }
218ddeeec14Snorby
219ddeeec14Snorby int
rip_hdr_sanity_check(struct rip_hdr * rip_hdr)220ddeeec14Snorby rip_hdr_sanity_check(struct rip_hdr *rip_hdr)
221ddeeec14Snorby {
222ddeeec14Snorby if (rip_hdr->version != RIP_VERSION) {
22311981efdSmcbride log_debug("rip_hdr_sanity_check: invalid RIP version %d",
224ddeeec14Snorby rip_hdr->version);
225ddeeec14Snorby return (-1);
226ddeeec14Snorby }
227ddeeec14Snorby
228ddeeec14Snorby return (0);
229ddeeec14Snorby }
230ddeeec14Snorby
231ddeeec14Snorby struct iface *
find_iface(struct ripd_conf * xconf,unsigned int ifindex,struct in_addr src)232ddeeec14Snorby find_iface(struct ripd_conf *xconf, unsigned int ifindex, struct in_addr src)
233ddeeec14Snorby {
234ddeeec14Snorby struct iface *iface = NULL;
235ddeeec14Snorby
236ddeeec14Snorby /* returned interface needs to be active */
237ddeeec14Snorby LIST_FOREACH(iface, &xconf->iface_list, entry) {
238f1ae8209Sjca if (ifindex == 0 || ifindex != iface->ifindex)
239f1ae8209Sjca continue;
240f1ae8209Sjca
241f1ae8209Sjca if (iface->passive)
242f1ae8209Sjca continue;
243f1ae8209Sjca
244f1ae8209Sjca if ((iface->addr.s_addr & iface->mask.s_addr) ==
245f1ae8209Sjca (src.s_addr & iface->mask.s_addr))
246f1ae8209Sjca return (iface);
247f1ae8209Sjca
248f1ae8209Sjca if (iface->dst.s_addr && iface->dst.s_addr == src.s_addr)
249ddeeec14Snorby return (iface);
250ddeeec14Snorby }
251ddeeec14Snorby
252ddeeec14Snorby return (NULL);
253ddeeec14Snorby }
254