xref: /freebsd/crypto/heimdal/lib/krb5/addr_families.c (revision b52b9d56d4e96089873a75f9e29062eec19fabba)
1 /*
2  * Copyright (c) 1997-2001 Kungliga Tekniska H�gskolan
3  * (Royal Institute of Technology, Stockholm, Sweden).
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  *
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  *
13  * 2. Redistributions in binary form must reproduce the above copyright
14  *    notice, this list of conditions and the following disclaimer in the
15  *    documentation and/or other materials provided with the distribution.
16  *
17  * 3. Neither the name of the Institute nor the names of its contributors
18  *    may be used to endorse or promote products derived from this software
19  *    without specific prior written permission.
20  *
21  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  */
33 
34 #include "krb5_locl.h"
35 
36 RCSID("$Id: addr_families.c,v 1.32 2001/09/03 19:53:51 assar Exp $");
37 
38 struct addr_operations {
39     int af;
40     krb5_address_type atype;
41     size_t max_sockaddr_size;
42     krb5_error_code (*sockaddr2addr)(const struct sockaddr *, krb5_address *);
43     krb5_error_code (*sockaddr2port)(const struct sockaddr *, int16_t *);
44     void (*addr2sockaddr)(const krb5_address *, struct sockaddr *,
45 			  int *sa_size, int port);
46     void (*h_addr2sockaddr)(const char *, struct sockaddr *, int *, int);
47     krb5_error_code (*h_addr2addr)(const char *, krb5_address *);
48     krb5_boolean (*uninteresting)(const struct sockaddr *);
49     void (*anyaddr)(struct sockaddr *, int *, int);
50     int (*print_addr)(const krb5_address *, char *, size_t);
51     int (*parse_addr)(krb5_context, const char*, krb5_address *);
52     int (*order_addr)(krb5_context, const krb5_address*, const krb5_address*);
53     int (*free_addr)(krb5_context, krb5_address*);
54     int (*copy_addr)(krb5_context, const krb5_address*, krb5_address*);
55 };
56 
57 /*
58  * AF_INET - aka IPv4 implementation
59  */
60 
61 static krb5_error_code
62 ipv4_sockaddr2addr (const struct sockaddr *sa, krb5_address *a)
63 {
64     const struct sockaddr_in *sin = (const struct sockaddr_in *)sa;
65     unsigned char buf[4];
66 
67     a->addr_type = KRB5_ADDRESS_INET;
68     memcpy (buf, &sin->sin_addr, 4);
69     return krb5_data_copy(&a->address, buf, 4);
70 }
71 
72 static krb5_error_code
73 ipv4_sockaddr2port (const struct sockaddr *sa, int16_t *port)
74 {
75     const struct sockaddr_in *sin = (const struct sockaddr_in *)sa;
76 
77     *port = sin->sin_port;
78     return 0;
79 }
80 
81 static void
82 ipv4_addr2sockaddr (const krb5_address *a,
83 		    struct sockaddr *sa,
84 		    int *sa_size,
85 		    int port)
86 {
87     struct sockaddr_in *sin = (struct sockaddr_in *)sa;
88 
89     memset (sin, 0, sizeof(*sin));
90     sin->sin_family = AF_INET;
91     memcpy (&sin->sin_addr, a->address.data, 4);
92     sin->sin_port = port;
93     *sa_size = sizeof(*sin);
94 }
95 
96 static void
97 ipv4_h_addr2sockaddr(const char *addr,
98 		     struct sockaddr *sa, int *sa_size, int port)
99 {
100     struct sockaddr_in *sin = (struct sockaddr_in *)sa;
101 
102     memset (sin, 0, sizeof(*sin));
103     *sa_size = sizeof(*sin);
104     sin->sin_family = AF_INET;
105     sin->sin_port   = port;
106     sin->sin_addr   = *((const struct in_addr *)addr);
107 }
108 
109 static krb5_error_code
110 ipv4_h_addr2addr (const char *addr,
111 		  krb5_address *a)
112 {
113     unsigned char buf[4];
114 
115     a->addr_type = KRB5_ADDRESS_INET;
116     memcpy(buf, addr, 4);
117     return krb5_data_copy(&a->address, buf, 4);
118 }
119 
120 /*
121  * Are there any addresses that should be considered `uninteresting'?
122  */
123 
124 static krb5_boolean
125 ipv4_uninteresting (const struct sockaddr *sa)
126 {
127     const struct sockaddr_in *sin = (const struct sockaddr_in *)sa;
128 
129     if (sin->sin_addr.s_addr == INADDR_ANY)
130 	return TRUE;
131 
132     return FALSE;
133 }
134 
135 static void
136 ipv4_anyaddr (struct sockaddr *sa, int *sa_size, int port)
137 {
138     struct sockaddr_in *sin = (struct sockaddr_in *)sa;
139 
140     memset (sin, 0, sizeof(*sin));
141     *sa_size = sizeof(*sin);
142     sin->sin_family = AF_INET;
143     sin->sin_port   = port;
144     sin->sin_addr.s_addr = INADDR_ANY;
145 }
146 
147 static int
148 ipv4_print_addr (const krb5_address *addr, char *str, size_t len)
149 {
150     struct in_addr ia;
151 
152     memcpy (&ia, addr->address.data, 4);
153 
154     return snprintf (str, len, "IPv4:%s", inet_ntoa(ia));
155 }
156 
157 static int
158 ipv4_parse_addr (krb5_context context, const char *address, krb5_address *addr)
159 {
160     const char *p;
161     struct in_addr a;
162 
163     p = strchr(address, ':');
164     if(p) {
165 	p++;
166 	if(strncasecmp(address, "ip:", p - address) != 0 &&
167 	   strncasecmp(address, "ip4:", p - address) != 0 &&
168 	   strncasecmp(address, "ipv4:", p - address) != 0 &&
169 	   strncasecmp(address, "inet:", p - address) != 0)
170 	    return -1;
171     } else
172 	p = address;
173 #ifdef HAVE_INET_ATON
174     if(inet_aton(p, &a) == 0)
175 	return -1;
176 #elif defined(HAVE_INET_ADDR)
177     a.s_addr = inet_addr(p);
178     if(a.s_addr == INADDR_NONE)
179 	return -1;
180 #else
181     return -1;
182 #endif
183     addr->addr_type = KRB5_ADDRESS_INET;
184     if(krb5_data_alloc(&addr->address, 4) != 0)
185 	return -1;
186     _krb5_put_int(addr->address.data, ntohl(a.s_addr), addr->address.length);
187     return 0;
188 }
189 
190 /*
191  * AF_INET6 - aka IPv6 implementation
192  */
193 
194 #ifdef HAVE_IPV6
195 
196 static krb5_error_code
197 ipv6_sockaddr2addr (const struct sockaddr *sa, krb5_address *a)
198 {
199     const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
200 
201     if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
202 	unsigned char buf[4];
203 
204 	a->addr_type      = KRB5_ADDRESS_INET;
205 #ifndef IN6_ADDR_V6_TO_V4
206 #ifdef IN6_EXTRACT_V4ADDR
207 #define IN6_ADDR_V6_TO_V4(x) (&IN6_EXTRACT_V4ADDR(x))
208 #else
209 #define IN6_ADDR_V6_TO_V4(x) ((const struct in_addr *)&(x)->s6_addr[12])
210 #endif
211 #endif
212 	memcpy (buf, IN6_ADDR_V6_TO_V4(&sin6->sin6_addr), 4);
213 	return krb5_data_copy(&a->address, buf, 4);
214     } else {
215 	a->addr_type = KRB5_ADDRESS_INET6;
216 	return krb5_data_copy(&a->address,
217 			      &sin6->sin6_addr,
218 			      sizeof(sin6->sin6_addr));
219     }
220 }
221 
222 static krb5_error_code
223 ipv6_sockaddr2port (const struct sockaddr *sa, int16_t *port)
224 {
225     const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
226 
227     *port = sin6->sin6_port;
228     return 0;
229 }
230 
231 static void
232 ipv6_addr2sockaddr (const krb5_address *a,
233 		    struct sockaddr *sa,
234 		    int *sa_size,
235 		    int port)
236 {
237     struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)sa;
238 
239     memset (sin6, 0, sizeof(*sin6));
240     sin6->sin6_family = AF_INET6;
241     memcpy (&sin6->sin6_addr, a->address.data, sizeof(sin6->sin6_addr));
242     sin6->sin6_port = port;
243     *sa_size = sizeof(*sin6);
244 }
245 
246 static void
247 ipv6_h_addr2sockaddr(const char *addr,
248 		     struct sockaddr *sa,
249 		     int *sa_size,
250 		     int port)
251 {
252     struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)sa;
253 
254     memset (sin6, 0, sizeof(*sin6));
255     *sa_size = sizeof(*sin6);
256     sin6->sin6_family = AF_INET6;
257     sin6->sin6_port   = port;
258     sin6->sin6_addr   = *((const struct in6_addr *)addr);
259 }
260 
261 static krb5_error_code
262 ipv6_h_addr2addr (const char *addr,
263 		  krb5_address *a)
264 {
265     a->addr_type = KRB5_ADDRESS_INET6;
266     return krb5_data_copy(&a->address, addr, sizeof(struct in6_addr));
267 }
268 
269 /*
270  *
271  */
272 
273 static krb5_boolean
274 ipv6_uninteresting (const struct sockaddr *sa)
275 {
276     const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
277     const struct in6_addr *in6 = (const struct in6_addr *)&sin6->sin6_addr;
278 
279     return
280 	IN6_IS_ADDR_LINKLOCAL(in6)
281 	|| IN6_IS_ADDR_V4COMPAT(in6);
282 }
283 
284 static void
285 ipv6_anyaddr (struct sockaddr *sa, int *sa_size, int port)
286 {
287     struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)sa;
288 
289     memset (sin6, 0, sizeof(*sin6));
290     *sa_size = sizeof(*sin6);
291     sin6->sin6_family = AF_INET6;
292     sin6->sin6_port   = port;
293     sin6->sin6_addr   = in6addr_any;
294 }
295 
296 static int
297 ipv6_print_addr (const krb5_address *addr, char *str, size_t len)
298 {
299     char buf[128], buf2[3];
300 #ifdef HAVE_INET_NTOP
301     if(inet_ntop(AF_INET6, addr->address.data, buf, sizeof(buf)) == NULL)
302 #endif
303 	{
304 	    /* XXX this is pretty ugly, but better than abort() */
305 	    int i;
306 	    unsigned char *p = addr->address.data;
307 	    buf[0] = '\0';
308 	    for(i = 0; i < addr->address.length; i++) {
309 		snprintf(buf2, sizeof(buf2), "%02x", p[i]);
310 		if(i > 0 && (i & 1) == 0)
311 		    strlcat(buf, ":", sizeof(buf));
312 		strlcat(buf, buf2, sizeof(buf));
313 	    }
314 	}
315     return snprintf(str, len, "IPv6:%s", buf);
316 }
317 
318 static int
319 ipv6_parse_addr (krb5_context context, const char *address, krb5_address *addr)
320 {
321     int ret;
322     struct in6_addr in6;
323     const char *p;
324 
325     p = strchr(address, ':');
326     if(p) {
327 	p++;
328 	if(strncasecmp(address, "ip6:", p - address) == 0 ||
329 	   strncasecmp(address, "ipv6:", p - address) == 0 ||
330 	   strncasecmp(address, "inet6:", p - address) == 0)
331 	    address = p;
332     }
333 
334     ret = inet_pton(AF_INET6, address, &in6.s6_addr);
335     if(ret == 1) {
336 	addr->addr_type = KRB5_ADDRESS_INET6;
337 	ret = krb5_data_alloc(&addr->address, sizeof(in6.s6_addr));
338 	if (ret)
339 	    return -1;
340 	memcpy(addr->address.data, in6.s6_addr, sizeof(in6.s6_addr));
341 	return 0;
342     }
343     return -1;
344 }
345 
346 #endif /* IPv6 */
347 
348 /*
349  * table
350  */
351 
352 #define KRB5_ADDRESS_ARANGE	(-100)
353 
354 struct arange {
355     krb5_address low;
356     krb5_address high;
357 };
358 
359 static int
360 arange_parse_addr (krb5_context context,
361 			  const char *address, krb5_address *addr)
362 {
363     char buf[1024];
364     krb5_addresses low, high;
365     struct arange *a;
366     krb5_error_code ret;
367 
368     if(strncasecmp(address, "RANGE:", 6) != 0)
369 	return -1;
370 
371     address += 6;
372 
373     /* should handle netmasks */
374     strsep_copy(&address, "-", buf, sizeof(buf));
375     ret = krb5_parse_address(context, buf, &low);
376     if(ret)
377 	return ret;
378     if(low.len != 1) {
379 	krb5_free_addresses(context, &low);
380 	return -1;
381     }
382 
383     strsep_copy(&address, "-", buf, sizeof(buf));
384     ret = krb5_parse_address(context, buf, &high);
385     if(ret) {
386 	krb5_free_addresses(context, &low);
387 	return ret;
388     }
389 
390     if(high.len != 1 || high.val[0].addr_type != low.val[0].addr_type) {
391 	krb5_free_addresses(context, &low);
392 	krb5_free_addresses(context, &high);
393 	return -1;
394     }
395 
396     krb5_data_alloc(&addr->address, sizeof(*a));
397     addr->addr_type = KRB5_ADDRESS_ARANGE;
398     a = addr->address.data;
399 
400     if(krb5_address_order(context, &low.val[0], &high.val[0]) < 0) {
401 	a->low = low.val[0];
402 	a->high = high.val[0];
403     } else {
404 	a->low = high.val[0];
405 	a->high = low.val[0];
406     }
407     return 0;
408 }
409 
410 static int
411 arange_free (krb5_context context, krb5_address *addr)
412 {
413     struct arange *a;
414     a = addr->address.data;
415     krb5_free_address(context, &a->low);
416     krb5_free_address(context, &a->high);
417     return 0;
418 }
419 
420 
421 static int
422 arange_copy (krb5_context context, const krb5_address *inaddr,
423 	     krb5_address *outaddr)
424 {
425     krb5_error_code ret;
426     struct arange *i, *o;
427 
428     outaddr->addr_type = KRB5_ADDRESS_ARANGE;
429     ret = krb5_data_alloc(&outaddr->address, sizeof(*o));
430     if(ret)
431 	return ret;
432     i = inaddr->address.data;
433     o = outaddr->address.data;
434     ret = krb5_copy_address(context, &i->low, &o->low);
435     if(ret) {
436 	krb5_data_free(&outaddr->address);
437 	return ret;
438     }
439     ret = krb5_copy_address(context, &i->high, &o->high);
440     if(ret) {
441 	krb5_free_address(context, &o->low);
442 	krb5_data_free(&outaddr->address);
443 	return ret;
444     }
445     return 0;
446 }
447 
448 static int
449 arange_print_addr (const krb5_address *addr, char *str, size_t len)
450 {
451     struct arange *a;
452     krb5_error_code ret;
453     size_t l, ret_len = 0;
454 
455     a = addr->address.data;
456 
457     l = strlcpy(str, "RANGE:", len);
458     ret_len += l;
459 
460     ret = krb5_print_address (&a->low, str + ret_len, len - ret_len, &l);
461     ret_len += l;
462 
463     l = strlcat(str, "-", len);
464     ret_len += l;
465 
466     ret = krb5_print_address (&a->high, str + ret_len, len - ret_len, &l);
467     ret_len += l;
468 
469     return ret_len;
470 }
471 
472 static int
473 arange_order_addr(krb5_context context,
474 			 const krb5_address *addr1,
475 			 const krb5_address *addr2)
476 {
477     int tmp1, tmp2, sign;
478     struct arange *a;
479     const krb5_address *a2;
480 
481     if(addr1->addr_type == KRB5_ADDRESS_ARANGE) {
482 	a = addr1->address.data;
483 	a2 = addr2;
484 	sign = 1;
485     } else if(addr2->addr_type == KRB5_ADDRESS_ARANGE) {
486 	a = addr2->address.data;
487 	a2 = addr1;
488 	sign = -1;
489     } else
490 	abort();
491 
492     if(a2->addr_type == KRB5_ADDRESS_ARANGE) {
493 	struct arange *b = a2->address.data;
494 	tmp1 = krb5_address_order(context, &a->low, &b->low);
495 	if(tmp1 != 0)
496 	    return sign * tmp1;
497 	return sign * krb5_address_order(context, &a->high, &b->high);
498     } else if(a2->addr_type == a->low.addr_type) {
499 	tmp1 = krb5_address_order(context, &a->low, a2);
500 	if(tmp1 > 0)
501 	    return sign;
502 	tmp2 = krb5_address_order(context, &a->high, a2);
503 	if(tmp2 < 0)
504 	    return -sign;
505 	return 0;
506     } else {
507 	return sign * (addr1->addr_type - addr2->addr_type);
508     }
509 }
510 
511 static struct addr_operations at[] = {
512     {AF_INET,	KRB5_ADDRESS_INET, sizeof(struct sockaddr_in),
513      ipv4_sockaddr2addr,
514      ipv4_sockaddr2port,
515      ipv4_addr2sockaddr,
516      ipv4_h_addr2sockaddr,
517      ipv4_h_addr2addr,
518      ipv4_uninteresting, ipv4_anyaddr, ipv4_print_addr, ipv4_parse_addr},
519 #ifdef HAVE_IPV6
520     {AF_INET6,	KRB5_ADDRESS_INET6, sizeof(struct sockaddr_in6),
521      ipv6_sockaddr2addr,
522      ipv6_sockaddr2port,
523      ipv6_addr2sockaddr,
524      ipv6_h_addr2sockaddr,
525      ipv6_h_addr2addr,
526      ipv6_uninteresting, ipv6_anyaddr, ipv6_print_addr, ipv6_parse_addr} ,
527 #endif
528     {KRB5_ADDRESS_ADDRPORT, KRB5_ADDRESS_ADDRPORT, 0,
529      NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL },
530     /* fake address type */
531     {KRB5_ADDRESS_ARANGE, KRB5_ADDRESS_ARANGE, sizeof(struct arange),
532      NULL, NULL, NULL, NULL, NULL, NULL, NULL,
533      arange_print_addr, arange_parse_addr,
534      arange_order_addr, arange_free, arange_copy }
535 };
536 
537 static int num_addrs = sizeof(at) / sizeof(at[0]);
538 
539 static size_t max_sockaddr_size = 0;
540 
541 /*
542  * generic functions
543  */
544 
545 static struct addr_operations *
546 find_af(int af)
547 {
548     struct addr_operations *a;
549 
550     for (a = at; a < at + num_addrs; ++a)
551 	if (af == a->af)
552 	    return a;
553     return NULL;
554 }
555 
556 static struct addr_operations *
557 find_atype(int atype)
558 {
559     struct addr_operations *a;
560 
561     for (a = at; a < at + num_addrs; ++a)
562 	if (atype == a->atype)
563 	    return a;
564     return NULL;
565 }
566 
567 krb5_error_code
568 krb5_sockaddr2address (krb5_context context,
569 		       const struct sockaddr *sa, krb5_address *addr)
570 {
571     struct addr_operations *a = find_af(sa->sa_family);
572     if (a == NULL) {
573 	krb5_set_error_string (context, "Address family %d not supported",
574 			       sa->sa_family);
575 	return KRB5_PROG_ATYPE_NOSUPP;
576     }
577     return (*a->sockaddr2addr)(sa, addr);
578 }
579 
580 krb5_error_code
581 krb5_sockaddr2port (krb5_context context,
582 		    const struct sockaddr *sa, int16_t *port)
583 {
584     struct addr_operations *a = find_af(sa->sa_family);
585     if (a == NULL) {
586 	krb5_set_error_string (context, "Address family %d not supported",
587 			       sa->sa_family);
588 	return KRB5_PROG_ATYPE_NOSUPP;
589     }
590     return (*a->sockaddr2port)(sa, port);
591 }
592 
593 krb5_error_code
594 krb5_addr2sockaddr (krb5_context context,
595 		    const krb5_address *addr,
596 		    struct sockaddr *sa,
597 		    int *sa_size,
598 		    int port)
599 {
600     struct addr_operations *a = find_atype(addr->addr_type);
601 
602     if (a == NULL) {
603 	krb5_set_error_string (context, "Address type %d not supported",
604 			       addr->addr_type);
605 	return KRB5_PROG_ATYPE_NOSUPP;
606     }
607     if (a->addr2sockaddr == NULL) {
608 	krb5_set_error_string (context, "Can't convert address type %d to sockaddr",
609 			       addr->addr_type);
610 	return KRB5_PROG_ATYPE_NOSUPP;
611     }
612     (*a->addr2sockaddr)(addr, sa, sa_size, port);
613     return 0;
614 }
615 
616 size_t
617 krb5_max_sockaddr_size (void)
618 {
619     if (max_sockaddr_size == 0) {
620 	struct addr_operations *a;
621 
622 	for(a = at; a < at + num_addrs; ++a)
623 	    max_sockaddr_size = max(max_sockaddr_size, a->max_sockaddr_size);
624     }
625     return max_sockaddr_size;
626 }
627 
628 krb5_boolean
629 krb5_sockaddr_uninteresting(const struct sockaddr *sa)
630 {
631     struct addr_operations *a = find_af(sa->sa_family);
632     if (a == NULL || a->uninteresting == NULL)
633 	return TRUE;
634     return (*a->uninteresting)(sa);
635 }
636 
637 krb5_error_code
638 krb5_h_addr2sockaddr (krb5_context context,
639 		      int af,
640 		      const char *addr, struct sockaddr *sa, int *sa_size,
641 		      int port)
642 {
643     struct addr_operations *a = find_af(af);
644     if (a == NULL) {
645 	krb5_set_error_string (context, "Address family %d not supported", af);
646 	return KRB5_PROG_ATYPE_NOSUPP;
647     }
648     (*a->h_addr2sockaddr)(addr, sa, sa_size, port);
649     return 0;
650 }
651 
652 krb5_error_code
653 krb5_h_addr2addr (krb5_context context,
654 		  int af,
655 		  const char *haddr, krb5_address *addr)
656 {
657     struct addr_operations *a = find_af(af);
658     if (a == NULL) {
659 	krb5_set_error_string (context, "Address family %d not supported", af);
660 	return KRB5_PROG_ATYPE_NOSUPP;
661     }
662     return (*a->h_addr2addr)(haddr, addr);
663 }
664 
665 krb5_error_code
666 krb5_anyaddr (krb5_context context,
667 	      int af,
668 	      struct sockaddr *sa,
669 	      int *sa_size,
670 	      int port)
671 {
672     struct addr_operations *a = find_af (af);
673 
674     if (a == NULL) {
675 	krb5_set_error_string (context, "Address family %d not supported", af);
676 	return KRB5_PROG_ATYPE_NOSUPP;
677     }
678 
679     (*a->anyaddr)(sa, sa_size, port);
680     return 0;
681 }
682 
683 krb5_error_code
684 krb5_print_address (const krb5_address *addr,
685 		    char *str, size_t len, size_t *ret_len)
686 {
687     struct addr_operations *a = find_atype(addr->addr_type);
688 
689     if (a == NULL) {
690 	char *s;
691 	int l;
692 	int i;
693 
694 	s = str;
695 	l = snprintf(s, len, "TYPE_%d:", addr->addr_type);
696 	if (l < 0)
697 	    return EINVAL;
698 	s += l;
699 	len -= l;
700 	for(i = 0; i < addr->address.length; i++) {
701 	    l = snprintf(s, len, "%02x", ((char*)addr->address.data)[i]);
702 	    if (l < 0)
703 		return EINVAL;
704 	    len -= l;
705 	    s += l;
706 	}
707 	*ret_len = s - str;
708 	return 0;
709     }
710     *ret_len = (*a->print_addr)(addr, str, len);
711     return 0;
712 }
713 
714 krb5_error_code
715 krb5_parse_address(krb5_context context,
716 		   const char *string,
717 		   krb5_addresses *addresses)
718 {
719     int i, n;
720     struct addrinfo *ai, *a;
721     int error;
722     int save_errno;
723 
724     for(i = 0; i < num_addrs; i++) {
725 	if(at[i].parse_addr) {
726 	    krb5_address a;
727 	    if((*at[i].parse_addr)(context, string, &a) == 0) {
728 		ALLOC_SEQ(addresses, 1);
729 		addresses->val[0] = a;
730 		return 0;
731 	    }
732 	}
733     }
734 
735     error = getaddrinfo (string, NULL, NULL, &ai);
736     if (error) {
737 	save_errno = errno;
738 	krb5_set_error_string (context, "%s: %s", string, gai_strerror(error));
739 	return krb5_eai_to_heim_errno(error, save_errno);
740     }
741 
742     n = 0;
743     for (a = ai; a != NULL; a = a->ai_next)
744 	++n;
745 
746     ALLOC_SEQ(addresses, n);
747 
748     for (a = ai, i = 0; a != NULL; a = a->ai_next, ++i) {
749 	krb5_sockaddr2address (context, ai->ai_addr, &addresses->val[i]);
750     }
751     freeaddrinfo (ai);
752     return 0;
753 }
754 
755 int
756 krb5_address_order(krb5_context context,
757 		   const krb5_address *addr1,
758 		   const krb5_address *addr2)
759 {
760     /* this sucks; what if both addresses have order functions, which
761        should we call? this works for now, though */
762     struct addr_operations *a;
763     a = find_atype(addr1->addr_type);
764     if(a == NULL) {
765 	krb5_set_error_string (context, "Address family %d not supported",
766 			       addr1->addr_type);
767 	return KRB5_PROG_ATYPE_NOSUPP;
768     }
769     if(a->order_addr != NULL)
770 	return (*a->order_addr)(context, addr1, addr2);
771     a = find_atype(addr2->addr_type);
772     if(a == NULL) {
773 	krb5_set_error_string (context, "Address family %d not supported",
774 			       addr2->addr_type);
775 	return KRB5_PROG_ATYPE_NOSUPP;
776     }
777     if(a->order_addr != NULL)
778 	return (*a->order_addr)(context, addr1, addr2);
779 
780     if(addr1->addr_type != addr2->addr_type)
781 	return addr1->addr_type - addr2->addr_type;
782     if(addr1->address.length != addr2->address.length)
783 	return addr1->address.length - addr2->address.length;
784     return memcmp (addr1->address.data,
785 		   addr2->address.data,
786 		   addr1->address.length);
787 }
788 
789 krb5_boolean
790 krb5_address_compare(krb5_context context,
791 		     const krb5_address *addr1,
792 		     const krb5_address *addr2)
793 {
794     return krb5_address_order (context, addr1, addr2) == 0;
795 }
796 
797 krb5_boolean
798 krb5_address_search(krb5_context context,
799 		    const krb5_address *addr,
800 		    const krb5_addresses *addrlist)
801 {
802     int i;
803 
804     for (i = 0; i < addrlist->len; ++i)
805 	if (krb5_address_compare (context, addr, &addrlist->val[i]))
806 	    return TRUE;
807     return FALSE;
808 }
809 
810 krb5_error_code
811 krb5_free_address(krb5_context context,
812 		  krb5_address *address)
813 {
814     struct addr_operations *a = find_af (address->addr_type);
815     if(a != NULL && a->free_addr != NULL)
816 	return (*a->free_addr)(context, address);
817     krb5_data_free (&address->address);
818     return 0;
819 }
820 
821 krb5_error_code
822 krb5_free_addresses(krb5_context context,
823 		    krb5_addresses *addresses)
824 {
825     int i;
826     for(i = 0; i < addresses->len; i++)
827 	krb5_free_address(context, &addresses->val[i]);
828     free(addresses->val);
829     return 0;
830 }
831 
832 krb5_error_code
833 krb5_copy_address(krb5_context context,
834 		  const krb5_address *inaddr,
835 		  krb5_address *outaddr)
836 {
837     struct addr_operations *a = find_af (inaddr->addr_type);
838     if(a != NULL && a->copy_addr != NULL)
839 	return (*a->copy_addr)(context, inaddr, outaddr);
840     return copy_HostAddress(inaddr, outaddr);
841 }
842 
843 krb5_error_code
844 krb5_copy_addresses(krb5_context context,
845 		    const krb5_addresses *inaddr,
846 		    krb5_addresses *outaddr)
847 {
848     int i;
849     ALLOC_SEQ(outaddr, inaddr->len);
850     if(inaddr->len > 0 && outaddr->val == NULL)
851 	return ENOMEM;
852     for(i = 0; i < inaddr->len; i++)
853 	krb5_copy_address(context, &inaddr->val[i], &outaddr->val[i]);
854     return 0;
855 }
856 
857 krb5_error_code
858 krb5_append_addresses(krb5_context context,
859 		      krb5_addresses *dest,
860 		      const krb5_addresses *source)
861 {
862     krb5_address *tmp;
863     krb5_error_code ret;
864     int i;
865     if(source->len > 0) {
866 	tmp = realloc(dest->val, (dest->len + source->len) * sizeof(*tmp));
867 	if(tmp == NULL) {
868 	    krb5_set_error_string(context, "realloc: out of memory");
869 	    return ENOMEM;
870 	}
871 	dest->val = tmp;
872 	for(i = 0; i < source->len; i++) {
873 	    /* skip duplicates */
874 	    if(krb5_address_search(context, &source->val[i], dest))
875 		continue;
876 	    ret = krb5_copy_address(context,
877 				    &source->val[i],
878 				    &dest->val[dest->len]);
879 	    if(ret)
880 		return ret;
881 	    dest->len++;
882 	}
883     }
884     return 0;
885 }
886 
887 /*
888  * Create an address of type KRB5_ADDRESS_ADDRPORT from (addr, port)
889  */
890 
891 krb5_error_code
892 krb5_make_addrport (krb5_context context,
893 		    krb5_address **res, const krb5_address *addr, int16_t port)
894 {
895     krb5_error_code ret;
896     size_t len = addr->address.length + 2 + 4 * 4;
897     u_char *p;
898 
899     *res = malloc (sizeof(**res));
900     if (*res == NULL) {
901 	krb5_set_error_string(context, "malloc: out of memory");
902 	return ENOMEM;
903     }
904     (*res)->addr_type = KRB5_ADDRESS_ADDRPORT;
905     ret = krb5_data_alloc (&(*res)->address, len);
906     if (ret) {
907 	krb5_set_error_string(context, "malloc: out of memory");
908 	free (*res);
909 	return ret;
910     }
911     p = (*res)->address.data;
912     *p++ = 0;
913     *p++ = 0;
914     *p++ = (addr->addr_type     ) & 0xFF;
915     *p++ = (addr->addr_type >> 8) & 0xFF;
916 
917     *p++ = (addr->address.length      ) & 0xFF;
918     *p++ = (addr->address.length >>  8) & 0xFF;
919     *p++ = (addr->address.length >> 16) & 0xFF;
920     *p++ = (addr->address.length >> 24) & 0xFF;
921 
922     memcpy (p, addr->address.data, addr->address.length);
923     p += addr->address.length;
924 
925     *p++ = 0;
926     *p++ = 0;
927     *p++ = (KRB5_ADDRESS_IPPORT     ) & 0xFF;
928     *p++ = (KRB5_ADDRESS_IPPORT >> 8) & 0xFF;
929 
930     *p++ = (2      ) & 0xFF;
931     *p++ = (2 >>  8) & 0xFF;
932     *p++ = (2 >> 16) & 0xFF;
933     *p++ = (2 >> 24) & 0xFF;
934 
935     memcpy (p, &port, 2);
936     p += 2;
937 
938     return 0;
939 }
940