1b528cefcSMark Murray /*
2*ae771770SStanislav Sedov * Copyright (c) 1997 - 2002 Kungliga Tekniska Högskolan
3b528cefcSMark Murray * (Royal Institute of Technology, Stockholm, Sweden).
4b528cefcSMark Murray * All rights reserved.
5b528cefcSMark Murray *
6b528cefcSMark Murray * Redistribution and use in source and binary forms, with or without
7b528cefcSMark Murray * modification, are permitted provided that the following conditions
8b528cefcSMark Murray * are met:
9b528cefcSMark Murray *
10b528cefcSMark Murray * 1. Redistributions of source code must retain the above copyright
11b528cefcSMark Murray * notice, this list of conditions and the following disclaimer.
12b528cefcSMark Murray *
13b528cefcSMark Murray * 2. Redistributions in binary form must reproduce the above copyright
14b528cefcSMark Murray * notice, this list of conditions and the following disclaimer in the
15b528cefcSMark Murray * documentation and/or other materials provided with the distribution.
16b528cefcSMark Murray *
17b528cefcSMark Murray * 3. Neither the name of the Institute nor the names of its contributors
18b528cefcSMark Murray * may be used to endorse or promote products derived from this software
19b528cefcSMark Murray * without specific prior written permission.
20b528cefcSMark Murray *
21b528cefcSMark Murray * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22b528cefcSMark Murray * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23b528cefcSMark Murray * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24b528cefcSMark Murray * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25b528cefcSMark Murray * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26b528cefcSMark Murray * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27b528cefcSMark Murray * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28b528cefcSMark Murray * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29b528cefcSMark Murray * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30b528cefcSMark Murray * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31b528cefcSMark Murray * SUCH DAMAGE.
32b528cefcSMark Murray */
33b528cefcSMark Murray
34b528cefcSMark Murray #include "krb5_locl.h"
35b528cefcSMark Murray
36b528cefcSMark Murray #ifdef __osf__
37b528cefcSMark Murray /* hate */
38b528cefcSMark Murray struct rtentry;
39b528cefcSMark Murray struct mbuf;
40b528cefcSMark Murray #endif
41b528cefcSMark Murray #ifdef HAVE_NET_IF_H
42b528cefcSMark Murray #include <net/if.h>
43b528cefcSMark Murray #endif
445e9cd1aeSAssar Westerlund #include <ifaddrs.h>
45b528cefcSMark Murray
46b528cefcSMark Murray static krb5_error_code
gethostname_fallback(krb5_context context,krb5_addresses * res)47adb0ddaeSAssar Westerlund gethostname_fallback (krb5_context context, krb5_addresses *res)
48b528cefcSMark Murray {
49adb0ddaeSAssar Westerlund krb5_error_code ret;
50b528cefcSMark Murray char hostname[MAXHOSTNAMELEN];
51b528cefcSMark Murray struct hostent *hostent;
52b528cefcSMark Murray
53adb0ddaeSAssar Westerlund if (gethostname (hostname, sizeof(hostname))) {
54adb0ddaeSAssar Westerlund ret = errno;
55*ae771770SStanislav Sedov krb5_set_error_message(context, ret, "gethostname: %s", strerror(ret));
56adb0ddaeSAssar Westerlund return ret;
57adb0ddaeSAssar Westerlund }
58b528cefcSMark Murray hostent = roken_gethostbyname (hostname);
59adb0ddaeSAssar Westerlund if (hostent == NULL) {
60adb0ddaeSAssar Westerlund ret = errno;
61*ae771770SStanislav Sedov krb5_set_error_message (context, ret, "gethostbyname %s: %s",
62adb0ddaeSAssar Westerlund hostname, strerror(ret));
63adb0ddaeSAssar Westerlund return ret;
64adb0ddaeSAssar Westerlund }
65b528cefcSMark Murray res->len = 1;
66b528cefcSMark Murray res->val = malloc (sizeof(*res->val));
67adb0ddaeSAssar Westerlund if (res->val == NULL) {
68*ae771770SStanislav Sedov krb5_set_error_message(context, ENOMEM, N_("malloc: out of memory", ""));
69b528cefcSMark Murray return ENOMEM;
70adb0ddaeSAssar Westerlund }
71b528cefcSMark Murray res->val[0].addr_type = hostent->h_addrtype;
72b528cefcSMark Murray res->val[0].address.data = NULL;
73b528cefcSMark Murray res->val[0].address.length = 0;
74adb0ddaeSAssar Westerlund ret = krb5_data_copy (&res->val[0].address,
75b528cefcSMark Murray hostent->h_addr,
76b528cefcSMark Murray hostent->h_length);
77adb0ddaeSAssar Westerlund if (ret) {
78b528cefcSMark Murray free (res->val);
79adb0ddaeSAssar Westerlund return ret;
80b528cefcSMark Murray }
81b528cefcSMark Murray return 0;
82b528cefcSMark Murray }
83b528cefcSMark Murray
84b528cefcSMark Murray enum {
85*ae771770SStanislav Sedov LOOP = 1, /* do include loopback addrs */
86*ae771770SStanislav Sedov LOOP_IF_NONE = 2, /* include loopback addrs if no others */
87b528cefcSMark Murray EXTRA_ADDRESSES = 4, /* include extra addresses */
88b528cefcSMark Murray SCAN_INTERFACES = 8 /* scan interfaces for addresses */
89b528cefcSMark Murray };
90b528cefcSMark Murray
91b528cefcSMark Murray /*
92b528cefcSMark Murray * Try to figure out the addresses of all configured interfaces with a
93b528cefcSMark Murray * lot of magic ioctls.
94b528cefcSMark Murray */
95b528cefcSMark Murray
96b528cefcSMark Murray static krb5_error_code
find_all_addresses(krb5_context context,krb5_addresses * res,int flags)975e9cd1aeSAssar Westerlund find_all_addresses (krb5_context context, krb5_addresses *res, int flags)
98b528cefcSMark Murray {
99b528cefcSMark Murray struct sockaddr sa_zero;
1005e9cd1aeSAssar Westerlund struct ifaddrs *ifa0, *ifa;
1015e9cd1aeSAssar Westerlund krb5_error_code ret = ENXIO;
102*ae771770SStanislav Sedov unsigned int num, idx;
1034137ff4cSJacques Vidrine krb5_addresses ignore_addresses;
104b528cefcSMark Murray
105adb0ddaeSAssar Westerlund if (getifaddrs(&ifa0) == -1) {
106adb0ddaeSAssar Westerlund ret = errno;
107*ae771770SStanislav Sedov krb5_set_error_message(context, ret, "getifaddrs: %s", strerror(ret));
108adb0ddaeSAssar Westerlund return (ret);
109adb0ddaeSAssar Westerlund }
1105e9cd1aeSAssar Westerlund
111b528cefcSMark Murray memset(&sa_zero, 0, sizeof(sa_zero));
112b528cefcSMark Murray
1135e9cd1aeSAssar Westerlund /* First, count all the ifaddrs. */
1145e9cd1aeSAssar Westerlund for (ifa = ifa0, num = 0; ifa != NULL; ifa = ifa->ifa_next, num++)
1155e9cd1aeSAssar Westerlund /* nothing */;
116b528cefcSMark Murray
1175e9cd1aeSAssar Westerlund if (num == 0) {
1185e9cd1aeSAssar Westerlund freeifaddrs(ifa0);
119*ae771770SStanislav Sedov krb5_set_error_message(context, ENXIO, N_("no addresses found", ""));
1205e9cd1aeSAssar Westerlund return (ENXIO);
121b528cefcSMark Murray }
122b528cefcSMark Murray
1234137ff4cSJacques Vidrine if (flags & EXTRA_ADDRESSES) {
1244137ff4cSJacques Vidrine /* we'll remove the addresses we don't care about */
1254137ff4cSJacques Vidrine ret = krb5_get_ignore_addresses(context, &ignore_addresses);
1264137ff4cSJacques Vidrine if(ret)
1274137ff4cSJacques Vidrine return ret;
1284137ff4cSJacques Vidrine }
1294137ff4cSJacques Vidrine
1305e9cd1aeSAssar Westerlund /* Allocate storage for them. */
131b528cefcSMark Murray res->val = calloc(num, sizeof(*res->val));
132b528cefcSMark Murray if (res->val == NULL) {
1334137ff4cSJacques Vidrine krb5_free_addresses(context, &ignore_addresses);
1345e9cd1aeSAssar Westerlund freeifaddrs(ifa0);
135*ae771770SStanislav Sedov krb5_set_error_message(context, ENOMEM, N_("malloc: out of memory", ""));
136*ae771770SStanislav Sedov return ENOMEM;
137b528cefcSMark Murray }
138b528cefcSMark Murray
1395e9cd1aeSAssar Westerlund /* Now traverse the list. */
1405e9cd1aeSAssar Westerlund for (ifa = ifa0, idx = 0; ifa != NULL; ifa = ifa->ifa_next) {
1415e9cd1aeSAssar Westerlund if ((ifa->ifa_flags & IFF_UP) == 0)
1425e9cd1aeSAssar Westerlund continue;
143bbd80c28SJacques Vidrine if (ifa->ifa_addr == NULL)
144bbd80c28SJacques Vidrine continue;
1455e9cd1aeSAssar Westerlund if (memcmp(ifa->ifa_addr, &sa_zero, sizeof(sa_zero)) == 0)
1465e9cd1aeSAssar Westerlund continue;
1475e9cd1aeSAssar Westerlund if (krb5_sockaddr_uninteresting(ifa->ifa_addr))
1485e9cd1aeSAssar Westerlund continue;
149*ae771770SStanislav Sedov if (krb5_sockaddr_is_loopback(ifa->ifa_addr) && (flags & LOOP) == 0)
1505e9cd1aeSAssar Westerlund /* We'll deal with the LOOP_IF_NONE case later. */
1515e9cd1aeSAssar Westerlund continue;
152b528cefcSMark Murray
153adb0ddaeSAssar Westerlund ret = krb5_sockaddr2address(context, ifa->ifa_addr, &res->val[idx]);
1545e9cd1aeSAssar Westerlund if (ret) {
1555e9cd1aeSAssar Westerlund /*
1565e9cd1aeSAssar Westerlund * The most likely error here is going to be "Program
1575e9cd1aeSAssar Westerlund * lacks support for address type". This is no big
1585e9cd1aeSAssar Westerlund * deal -- just continue, and we'll listen on the
1595e9cd1aeSAssar Westerlund * addresses who's type we *do* support.
1605e9cd1aeSAssar Westerlund */
161b528cefcSMark Murray continue;
1625e9cd1aeSAssar Westerlund }
1634137ff4cSJacques Vidrine /* possibly skip this address? */
1644137ff4cSJacques Vidrine if((flags & EXTRA_ADDRESSES) &&
1654137ff4cSJacques Vidrine krb5_address_search(context, &res->val[idx], &ignore_addresses)) {
1664137ff4cSJacques Vidrine krb5_free_address(context, &res->val[idx]);
1674137ff4cSJacques Vidrine flags &= ~LOOP_IF_NONE; /* we actually found an address,
1684137ff4cSJacques Vidrine so don't add any loop-back
1694137ff4cSJacques Vidrine addresses */
1704137ff4cSJacques Vidrine continue;
1714137ff4cSJacques Vidrine }
1724137ff4cSJacques Vidrine
1735e9cd1aeSAssar Westerlund idx++;
1745e9cd1aeSAssar Westerlund }
1755e9cd1aeSAssar Westerlund
1765e9cd1aeSAssar Westerlund /*
1775e9cd1aeSAssar Westerlund * If no addresses were found, and LOOP_IF_NONE is set, then find
1785e9cd1aeSAssar Westerlund * the loopback addresses and add them to our list.
1795e9cd1aeSAssar Westerlund */
1805e9cd1aeSAssar Westerlund if ((flags & LOOP_IF_NONE) != 0 && idx == 0) {
1815e9cd1aeSAssar Westerlund for (ifa = ifa0; ifa != NULL; ifa = ifa->ifa_next) {
1825e9cd1aeSAssar Westerlund if ((ifa->ifa_flags & IFF_UP) == 0)
183b528cefcSMark Murray continue;
184bbd80c28SJacques Vidrine if (ifa->ifa_addr == NULL)
185bbd80c28SJacques Vidrine continue;
1865e9cd1aeSAssar Westerlund if (memcmp(ifa->ifa_addr, &sa_zero, sizeof(sa_zero)) == 0)
1875e9cd1aeSAssar Westerlund continue;
1885e9cd1aeSAssar Westerlund if (krb5_sockaddr_uninteresting(ifa->ifa_addr))
189b528cefcSMark Murray continue;
190*ae771770SStanislav Sedov if (!krb5_sockaddr_is_loopback(ifa->ifa_addr))
191*ae771770SStanislav Sedov continue;
192*ae771770SStanislav Sedov if ((ifa->ifa_flags & IFF_LOOPBACK) == 0)
193*ae771770SStanislav Sedov /* Presumably loopback addrs are only used on loopback ifs! */
194*ae771770SStanislav Sedov continue;
195adb0ddaeSAssar Westerlund ret = krb5_sockaddr2address(context,
196adb0ddaeSAssar Westerlund ifa->ifa_addr, &res->val[idx]);
197*ae771770SStanislav Sedov if (ret)
198*ae771770SStanislav Sedov continue; /* We don't consider this failure fatal */
1994137ff4cSJacques Vidrine if((flags & EXTRA_ADDRESSES) &&
2004137ff4cSJacques Vidrine krb5_address_search(context, &res->val[idx],
2014137ff4cSJacques Vidrine &ignore_addresses)) {
2024137ff4cSJacques Vidrine krb5_free_address(context, &res->val[idx]);
2034137ff4cSJacques Vidrine continue;
2044137ff4cSJacques Vidrine }
2055e9cd1aeSAssar Westerlund idx++;
2065e9cd1aeSAssar Westerlund }
2075e9cd1aeSAssar Westerlund }
2085e9cd1aeSAssar Westerlund
2094137ff4cSJacques Vidrine if (flags & EXTRA_ADDRESSES)
2104137ff4cSJacques Vidrine krb5_free_addresses(context, &ignore_addresses);
2115e9cd1aeSAssar Westerlund freeifaddrs(ifa0);
212*ae771770SStanislav Sedov if (ret) {
213b528cefcSMark Murray free(res->val);
214*ae771770SStanislav Sedov res->val = NULL;
215*ae771770SStanislav Sedov } else
2165e9cd1aeSAssar Westerlund res->len = idx; /* Now a count. */
2175e9cd1aeSAssar Westerlund return (ret);
218b528cefcSMark Murray }
219b528cefcSMark Murray
220b528cefcSMark Murray static krb5_error_code
get_addrs_int(krb5_context context,krb5_addresses * res,int flags)221b528cefcSMark Murray get_addrs_int (krb5_context context, krb5_addresses *res, int flags)
222b528cefcSMark Murray {
223b528cefcSMark Murray krb5_error_code ret = -1;
224b528cefcSMark Murray
225*ae771770SStanislav Sedov res->len = 0;
226*ae771770SStanislav Sedov res->val = NULL;
227*ae771770SStanislav Sedov
228b528cefcSMark Murray if (flags & SCAN_INTERFACES) {
2295e9cd1aeSAssar Westerlund ret = find_all_addresses (context, res, flags);
230b528cefcSMark Murray if(ret || res->len == 0)
231adb0ddaeSAssar Westerlund ret = gethostname_fallback (context, res);
2328373020dSJacques Vidrine } else {
233b528cefcSMark Murray ret = 0;
2348373020dSJacques Vidrine }
235b528cefcSMark Murray
236b528cefcSMark Murray if(ret == 0 && (flags & EXTRA_ADDRESSES)) {
237b528cefcSMark Murray krb5_addresses a;
2384137ff4cSJacques Vidrine /* append user specified addresses */
239b528cefcSMark Murray ret = krb5_get_extra_addresses(context, &a);
240b528cefcSMark Murray if(ret) {
241b528cefcSMark Murray krb5_free_addresses(context, res);
242b528cefcSMark Murray return ret;
243b528cefcSMark Murray }
244b528cefcSMark Murray ret = krb5_append_addresses(context, res, &a);
245b528cefcSMark Murray if(ret) {
246b528cefcSMark Murray krb5_free_addresses(context, res);
247b528cefcSMark Murray return ret;
248b528cefcSMark Murray }
249b528cefcSMark Murray krb5_free_addresses(context, &a);
250b528cefcSMark Murray }
2514137ff4cSJacques Vidrine if(res->len == 0) {
2524137ff4cSJacques Vidrine free(res->val);
2534137ff4cSJacques Vidrine res->val = NULL;
2544137ff4cSJacques Vidrine }
255b528cefcSMark Murray return ret;
256b528cefcSMark Murray }
257b528cefcSMark Murray
258b528cefcSMark Murray /*
259b528cefcSMark Murray * Try to get all addresses, but return the one corresponding to
260b528cefcSMark Murray * `hostname' if we fail.
261b528cefcSMark Murray *
262b528cefcSMark Murray * Only include loopback address if there are no other.
263b528cefcSMark Murray */
264b528cefcSMark Murray
265*ae771770SStanislav Sedov KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
krb5_get_all_client_addrs(krb5_context context,krb5_addresses * res)266b528cefcSMark Murray krb5_get_all_client_addrs (krb5_context context, krb5_addresses *res)
267b528cefcSMark Murray {
268b528cefcSMark Murray int flags = LOOP_IF_NONE | EXTRA_ADDRESSES;
269b528cefcSMark Murray
270b528cefcSMark Murray if (context->scan_interfaces)
271b528cefcSMark Murray flags |= SCAN_INTERFACES;
272b528cefcSMark Murray
273b528cefcSMark Murray return get_addrs_int (context, res, flags);
274b528cefcSMark Murray }
275b528cefcSMark Murray
276b528cefcSMark Murray /*
277b528cefcSMark Murray * Try to get all local addresses that a server should listen to.
278b528cefcSMark Murray * If that fails, we return the address corresponding to `hostname'.
279b528cefcSMark Murray */
280b528cefcSMark Murray
281*ae771770SStanislav Sedov KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
krb5_get_all_server_addrs(krb5_context context,krb5_addresses * res)282b528cefcSMark Murray krb5_get_all_server_addrs (krb5_context context, krb5_addresses *res)
283b528cefcSMark Murray {
284b528cefcSMark Murray return get_addrs_int (context, res, LOOP | SCAN_INTERFACES);
285b528cefcSMark Murray }
286