xref: /freebsd/sbin/dhclient/dhclient.c (revision 461ccb55d50ccf1b5bcfe1310fe32d72f8b0ecdd)
147c08596SBrooks Davis /*	$OpenBSD: dhclient.c,v 1.63 2005/02/06 17:10:13 krw Exp $	*/
247c08596SBrooks Davis 
38a16b7a1SPedro F. Giffuni /*-
48a16b7a1SPedro F. Giffuni  * SPDX-License-Identifier: BSD-3-Clause
58a16b7a1SPedro F. Giffuni  *
647c08596SBrooks Davis  * Copyright 2004 Henning Brauer <henning@openbsd.org>
747c08596SBrooks Davis  * Copyright (c) 1995, 1996, 1997, 1998, 1999
847c08596SBrooks Davis  * The Internet Software Consortium.    All rights reserved.
947c08596SBrooks Davis  *
1047c08596SBrooks Davis  * Redistribution and use in source and binary forms, with or without
1147c08596SBrooks Davis  * modification, are permitted provided that the following conditions
1247c08596SBrooks Davis  * are met:
1347c08596SBrooks Davis  *
1447c08596SBrooks Davis  * 1. Redistributions of source code must retain the above copyright
1547c08596SBrooks Davis  *    notice, this list of conditions and the following disclaimer.
1647c08596SBrooks Davis  * 2. Redistributions in binary form must reproduce the above copyright
1747c08596SBrooks Davis  *    notice, this list of conditions and the following disclaimer in the
1847c08596SBrooks Davis  *    documentation and/or other materials provided with the distribution.
1947c08596SBrooks Davis  * 3. Neither the name of The Internet Software Consortium nor the names
2047c08596SBrooks Davis  *    of its contributors may be used to endorse or promote products derived
2147c08596SBrooks Davis  *    from this software without specific prior written permission.
2247c08596SBrooks Davis  *
2347c08596SBrooks Davis  * THIS SOFTWARE IS PROVIDED BY THE INTERNET SOFTWARE CONSORTIUM AND
2447c08596SBrooks Davis  * CONTRIBUTORS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
2547c08596SBrooks Davis  * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
2647c08596SBrooks Davis  * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
2747c08596SBrooks Davis  * DISCLAIMED.  IN NO EVENT SHALL THE INTERNET SOFTWARE CONSORTIUM OR
2847c08596SBrooks Davis  * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
2947c08596SBrooks Davis  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
3047c08596SBrooks Davis  * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
3147c08596SBrooks Davis  * USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
3247c08596SBrooks Davis  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
3347c08596SBrooks Davis  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
3447c08596SBrooks Davis  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
3547c08596SBrooks Davis  * SUCH DAMAGE.
3647c08596SBrooks Davis  *
3747c08596SBrooks Davis  * This software has been written for the Internet Software Consortium
3847c08596SBrooks Davis  * by Ted Lemon <mellon@fugue.com> in cooperation with Vixie
3947c08596SBrooks Davis  * Enterprises.  To learn more about the Internet Software Consortium,
4047c08596SBrooks Davis  * see ``http://www.vix.com/isc''.  To learn more about Vixie
4147c08596SBrooks Davis  * Enterprises, see ``http://www.vix.com''.
4247c08596SBrooks Davis  *
4347c08596SBrooks Davis  * This client was substantially modified and enhanced by Elliot Poger
4447c08596SBrooks Davis  * for use on Linux while he was working on the MosquitoNet project at
4547c08596SBrooks Davis  * Stanford.
4647c08596SBrooks Davis  *
4747c08596SBrooks Davis  * The current version owes much to Elliot's Linux enhancements, but
4847c08596SBrooks Davis  * was substantially reorganized and partially rewritten by Ted Lemon
4947c08596SBrooks Davis  * so as to use the same networking framework that the Internet Software
5047c08596SBrooks Davis  * Consortium DHCP server uses.   Much system-specific configuration code
5147c08596SBrooks Davis  * was moved into a shell script so that as support for more operating
5247c08596SBrooks Davis  * systems is added, it will not be necessary to port and maintain
5347c08596SBrooks Davis  * system-specific configuration code to these operating systems - instead,
5447c08596SBrooks Davis  * the shell script can invoke the native tools to accomplish the same
5547c08596SBrooks Davis  * purpose.
5647c08596SBrooks Davis  */
5747c08596SBrooks Davis 
588794fdbbSBrooks Davis #include <sys/cdefs.h>
598794fdbbSBrooks Davis __FBSDID("$FreeBSD$");
608794fdbbSBrooks Davis 
6147c08596SBrooks Davis #include "dhcpd.h"
6247c08596SBrooks Davis #include "privsep.h"
6347c08596SBrooks Davis 
64b881b8beSRobert Watson #include <sys/capsicum.h>
65387016a5SConrad Meyer #include <sys/endian.h>
66de2c882fSPawel Jakub Dawidek 
677672a014SMariusz Zaborski #include <capsicum_helpers.h>
6871c6c44dSEitan Adler #include <libgen.h>
697672a014SMariusz Zaborski 
702b19b6fcSBrooks Davis #include <net80211/ieee80211_freebsd.h>
712b19b6fcSBrooks Davis 
7271c6c44dSEitan Adler 
732b19b6fcSBrooks Davis #ifndef _PATH_VAREMPTY
742b19b6fcSBrooks Davis #define	_PATH_VAREMPTY	"/var/empty"
752b19b6fcSBrooks Davis #endif
762b19b6fcSBrooks Davis 
7747c08596SBrooks Davis #define	PERIOD 0x2e
7847c08596SBrooks Davis #define	hyphenchar(c) ((c) == 0x2d)
7947c08596SBrooks Davis #define	bslashchar(c) ((c) == 0x5c)
8047c08596SBrooks Davis #define	periodchar(c) ((c) == PERIOD)
8147c08596SBrooks Davis #define	asterchar(c) ((c) == 0x2a)
8247c08596SBrooks Davis #define	alphachar(c) (((c) >= 0x41 && (c) <= 0x5a) || \
8347c08596SBrooks Davis 	    ((c) >= 0x61 && (c) <= 0x7a))
8447c08596SBrooks Davis #define	digitchar(c) ((c) >= 0x30 && (c) <= 0x39)
85f954ec0bSBrooks Davis #define	whitechar(c) ((c) == ' ' || (c) == '\t')
8647c08596SBrooks Davis 
8747c08596SBrooks Davis #define	borderchar(c) (alphachar(c) || digitchar(c))
8847c08596SBrooks Davis #define	middlechar(c) (borderchar(c) || hyphenchar(c))
8947c08596SBrooks Davis #define	domainchar(c) ((c) > 0x20 && (c) < 0x7f)
9047c08596SBrooks Davis 
9147c08596SBrooks Davis #define	CLIENT_PATH "PATH=/usr/bin:/usr/sbin:/bin:/sbin"
9247c08596SBrooks Davis 
93cb003dd9SMariusz Zaborski cap_channel_t *capsyslog;
94cb003dd9SMariusz Zaborski 
9547c08596SBrooks Davis time_t cur_time;
9671c6c44dSEitan Adler static time_t default_lease_time = 43200; /* 12 hours... */
9747c08596SBrooks Davis 
9879a1d195SAlan Somers const char *path_dhclient_conf = _PATH_DHCLIENT_CONF;
9947c08596SBrooks Davis char *path_dhclient_db = NULL;
10047c08596SBrooks Davis 
10147c08596SBrooks Davis int log_perror = 1;
10271c6c44dSEitan Adler static int privfd;
10371c6c44dSEitan Adler static int nullfd = -1;
10447c08596SBrooks Davis 
10571c6c44dSEitan Adler static char hostname[_POSIX_HOST_NAME_MAX + 1];
1060bbe8306SPawel Jakub Dawidek 
10771c6c44dSEitan Adler static struct iaddr iaddr_broadcast = { 4, { 255, 255, 255, 255 } };
10871c6c44dSEitan Adler static struct in_addr inaddr_any, inaddr_broadcast;
10947c08596SBrooks Davis 
11071c6c44dSEitan Adler static char *path_dhclient_pidfile;
11123f39c90SDag-Erling Smørgrav struct pidfh *pidfile;
11223f39c90SDag-Erling Smørgrav 
11347c08596SBrooks Davis /*
11447c08596SBrooks Davis  * ASSERT_STATE() does nothing now; it used to be
11547c08596SBrooks Davis  * assert (state_is == state_shouldbe).
11647c08596SBrooks Davis  */
11747c08596SBrooks Davis #define ASSERT_STATE(state_is, state_shouldbe) {}
11847c08596SBrooks Davis 
119223c44aeSNick Hibma /*
120223c44aeSNick Hibma  * We need to check that the expiry, renewal and rebind times are not beyond
121223c44aeSNick Hibma  * the end of time (~2038 when a 32-bit time_t is being used).
122223c44aeSNick Hibma  */
123223c44aeSNick Hibma #define TIME_MAX        ((((time_t) 1 << (sizeof(time_t) * CHAR_BIT - 2)) - 1) * 2 + 1)
12447c08596SBrooks Davis 
12547c08596SBrooks Davis int		log_priority;
12671c6c44dSEitan Adler static int		no_daemon;
12771c6c44dSEitan Adler static int		unknown_ok = 1;
12871c6c44dSEitan Adler static int		routefd;
12947c08596SBrooks Davis 
13047c08596SBrooks Davis struct interface_info	*ifi;
13147c08596SBrooks Davis 
13247c08596SBrooks Davis int		 findproto(char *, int);
13347c08596SBrooks Davis struct sockaddr	*get_ifa(char *, int);
13447c08596SBrooks Davis void		 routehandler(struct protocol *);
13547c08596SBrooks Davis void		 usage(void);
13647c08596SBrooks Davis int		 check_option(struct client_lease *l, int option);
1372fcc7370SEd Maste int		 check_classless_option(unsigned char *data, int len);
13879a1d195SAlan Somers int		 ipv4addrs(const char * buf);
13947c08596SBrooks Davis int		 res_hnok(const char *dn);
140f954ec0bSBrooks Davis int		 check_search(const char *srch);
14179a1d195SAlan Somers const char	*option_as_string(unsigned int code, unsigned char *data, int len);
14247c08596SBrooks Davis int		 fork_privchld(int, int);
14347c08596SBrooks Davis 
14447c08596SBrooks Davis #define	ROUNDUP(a) \
14547c08596SBrooks Davis 	    ((a) > 0 ? (1 + (((a) - 1) | (sizeof(long) - 1))) : sizeof(long))
14647c08596SBrooks Davis #define	ADVANCE(x, n) (x += ROUNDUP((n)->sa_len))
14747c08596SBrooks Davis 
148387016a5SConrad Meyer /* Minimum MTU is 68 as per RFC791, p. 24 */
149387016a5SConrad Meyer #define MIN_MTU 68
150387016a5SConrad Meyer 
1516964abefSBrian Somers static time_t	scripttime;
15247c08596SBrooks Davis 
15347c08596SBrooks Davis int
15447c08596SBrooks Davis findproto(char *cp, int n)
15547c08596SBrooks Davis {
15647c08596SBrooks Davis 	struct sockaddr *sa;
1575f28c51dSAlan Somers 	unsigned i;
15847c08596SBrooks Davis 
15947c08596SBrooks Davis 	if (n == 0)
16047c08596SBrooks Davis 		return -1;
16147c08596SBrooks Davis 	for (i = 1; i; i <<= 1) {
16247c08596SBrooks Davis 		if (i & n) {
16347c08596SBrooks Davis 			sa = (struct sockaddr *)cp;
16447c08596SBrooks Davis 			switch (i) {
16547c08596SBrooks Davis 			case RTA_IFA:
16647c08596SBrooks Davis 			case RTA_DST:
16747c08596SBrooks Davis 			case RTA_GATEWAY:
16847c08596SBrooks Davis 			case RTA_NETMASK:
16947c08596SBrooks Davis 				if (sa->sa_family == AF_INET)
17047c08596SBrooks Davis 					return AF_INET;
17147c08596SBrooks Davis 				if (sa->sa_family == AF_INET6)
17247c08596SBrooks Davis 					return AF_INET6;
17347c08596SBrooks Davis 				break;
17447c08596SBrooks Davis 			case RTA_IFP:
17547c08596SBrooks Davis 				break;
17647c08596SBrooks Davis 			}
17747c08596SBrooks Davis 			ADVANCE(cp, sa);
17847c08596SBrooks Davis 		}
17947c08596SBrooks Davis 	}
18047c08596SBrooks Davis 	return (-1);
18147c08596SBrooks Davis }
18247c08596SBrooks Davis 
18347c08596SBrooks Davis struct sockaddr *
18447c08596SBrooks Davis get_ifa(char *cp, int n)
18547c08596SBrooks Davis {
18647c08596SBrooks Davis 	struct sockaddr *sa;
1875f28c51dSAlan Somers 	unsigned i;
18847c08596SBrooks Davis 
18947c08596SBrooks Davis 	if (n == 0)
19047c08596SBrooks Davis 		return (NULL);
19147c08596SBrooks Davis 	for (i = 1; i; i <<= 1)
19247c08596SBrooks Davis 		if (i & n) {
19347c08596SBrooks Davis 			sa = (struct sockaddr *)cp;
19447c08596SBrooks Davis 			if (i == RTA_IFA)
19547c08596SBrooks Davis 				return (sa);
19647c08596SBrooks Davis 			ADVANCE(cp, sa);
19747c08596SBrooks Davis 		}
19847c08596SBrooks Davis 
19947c08596SBrooks Davis 	return (NULL);
20047c08596SBrooks Davis }
20161063e47SSam Leffler 
20271c6c44dSEitan Adler static struct iaddr defaddr = { .len = 4 };
20371c6c44dSEitan Adler static uint8_t curbssid[6];
20461063e47SSam Leffler 
20561063e47SSam Leffler static void
20661063e47SSam Leffler disassoc(void *arg)
20761063e47SSam Leffler {
20879a1d195SAlan Somers 	struct interface_info *_ifi = arg;
20961063e47SSam Leffler 
21061063e47SSam Leffler 	/*
21161063e47SSam Leffler 	 * Clear existing state.
21261063e47SSam Leffler 	 */
21379a1d195SAlan Somers 	if (_ifi->client->active != NULL) {
21461063e47SSam Leffler 		script_init("EXPIRE", NULL);
21561063e47SSam Leffler 		script_write_params("old_",
21679a1d195SAlan Somers 		    _ifi->client->active);
21779a1d195SAlan Somers 		if (_ifi->client->alias)
21861063e47SSam Leffler 			script_write_params("alias_",
21979a1d195SAlan Somers 				_ifi->client->alias);
22061063e47SSam Leffler 		script_go();
22161063e47SSam Leffler 	}
22279a1d195SAlan Somers 	_ifi->client->state = S_INIT;
22361063e47SSam Leffler }
22447c08596SBrooks Davis 
22547c08596SBrooks Davis void
22679a1d195SAlan Somers routehandler(struct protocol *p __unused)
22747c08596SBrooks Davis {
2286964abefSBrian Somers 	char msg[2048], *addr;
22947c08596SBrooks Davis 	struct rt_msghdr *rtm;
23047c08596SBrooks Davis 	struct if_msghdr *ifm;
23147c08596SBrooks Davis 	struct ifa_msghdr *ifam;
23247c08596SBrooks Davis 	struct if_announcemsghdr *ifan;
23361063e47SSam Leffler 	struct ieee80211_join_event *jev;
23447c08596SBrooks Davis 	struct client_lease *l;
23547c08596SBrooks Davis 	time_t t = time(NULL);
23679a1d195SAlan Somers 	struct sockaddr_in *sa;
23747c08596SBrooks Davis 	struct iaddr a;
23847c08596SBrooks Davis 	ssize_t n;
2390a26f858SJohn Baldwin 	int linkstat;
24047c08596SBrooks Davis 
24147c08596SBrooks Davis 	n = read(routefd, &msg, sizeof(msg));
24247c08596SBrooks Davis 	rtm = (struct rt_msghdr *)msg;
243afe6f835SAlan Somers 	if (n < (ssize_t)sizeof(rtm->rtm_msglen) ||
244afe6f835SAlan Somers 	    n < (ssize_t)rtm->rtm_msglen ||
24547c08596SBrooks Davis 	    rtm->rtm_version != RTM_VERSION)
24647c08596SBrooks Davis 		return;
24747c08596SBrooks Davis 
24847c08596SBrooks Davis 	switch (rtm->rtm_type) {
24947c08596SBrooks Davis 	case RTM_NEWADDR:
250dfad96eaSBrooks Davis 	case RTM_DELADDR:
25147c08596SBrooks Davis 		ifam = (struct ifa_msghdr *)rtm;
252dfad96eaSBrooks Davis 
25347c08596SBrooks Davis 		if (ifam->ifam_index != ifi->index)
25447c08596SBrooks Davis 			break;
25547c08596SBrooks Davis 		if (findproto((char *)(ifam + 1), ifam->ifam_addrs) != AF_INET)
25647c08596SBrooks Davis 			break;
257dfad96eaSBrooks Davis 		if (scripttime == 0 || t < scripttime + 10)
258dfad96eaSBrooks Davis 			break;
259dfad96eaSBrooks Davis 
26079a1d195SAlan Somers 		sa = (struct sockaddr_in*)get_ifa((char *)(ifam + 1), ifam->ifam_addrs);
26147c08596SBrooks Davis 		if (sa == NULL)
2626964abefSBrian Somers 			break;
26347c08596SBrooks Davis 
26447c08596SBrooks Davis 		if ((a.len = sizeof(struct in_addr)) > sizeof(a.iabuf))
26547c08596SBrooks Davis 			error("king bula sez: len mismatch");
26679a1d195SAlan Somers 		memcpy(a.iabuf, &sa->sin_addr, a.len);
26747c08596SBrooks Davis 		if (addr_eq(a, defaddr))
26847c08596SBrooks Davis 			break;
26947c08596SBrooks Davis 
27047c08596SBrooks Davis 		for (l = ifi->client->active; l != NULL; l = l->next)
27147c08596SBrooks Davis 			if (addr_eq(a, l->address))
27247c08596SBrooks Davis 				break;
27347c08596SBrooks Davis 
2746964abefSBrian Somers 		if (l == NULL)	/* added/deleted addr is not the one we set */
27547c08596SBrooks Davis 			break;
2766964abefSBrian Somers 
27779a1d195SAlan Somers 		addr = inet_ntoa(sa->sin_addr);
2786964abefSBrian Somers 		if (rtm->rtm_type == RTM_NEWADDR)  {
2796964abefSBrian Somers 			/*
2806964abefSBrian Somers 			 * XXX: If someone other than us adds our address,
2816964abefSBrian Somers 			 * should we assume they are taking over from us,
2826964abefSBrian Somers 			 * delete the lease record, and exit without modifying
2836964abefSBrian Somers 			 * the interface?
2846964abefSBrian Somers 			 */
2856964abefSBrian Somers 			warning("My address (%s) was re-added", addr);
2866964abefSBrian Somers 		} else {
2876964abefSBrian Somers 			warning("My address (%s) was deleted, dhclient exiting",
2886964abefSBrian Somers 			    addr);
28947c08596SBrooks Davis 			goto die;
2906964abefSBrian Somers 		}
2916964abefSBrian Somers 		break;
29247c08596SBrooks Davis 	case RTM_IFINFO:
29347c08596SBrooks Davis 		ifm = (struct if_msghdr *)rtm;
29447c08596SBrooks Davis 		if (ifm->ifm_index != ifi->index)
29547c08596SBrooks Davis 			break;
2966964abefSBrian Somers 		if ((rtm->rtm_flags & RTF_UP) == 0) {
2976964abefSBrian Somers 			warning("Interface %s is down, dhclient exiting",
2986964abefSBrian Somers 			    ifi->name);
29947c08596SBrooks Davis 			goto die;
3006964abefSBrian Somers 		}
3010a26f858SJohn Baldwin 		linkstat = interface_link_status(ifi->name);
3020a26f858SJohn Baldwin 		if (linkstat != ifi->linkstat) {
3030a26f858SJohn Baldwin 			debug("%s link state %s -> %s", ifi->name,
3040a26f858SJohn Baldwin 			    ifi->linkstat ? "up" : "down",
3050a26f858SJohn Baldwin 			    linkstat ? "up" : "down");
3060a26f858SJohn Baldwin 			ifi->linkstat = linkstat;
3070a26f858SJohn Baldwin 			if (linkstat)
3080a26f858SJohn Baldwin 				state_reboot(ifi);
30983f745b8SJohn Baldwin 		}
31047c08596SBrooks Davis 		break;
31147c08596SBrooks Davis 	case RTM_IFANNOUNCE:
31247c08596SBrooks Davis 		ifan = (struct if_announcemsghdr *)rtm;
31347c08596SBrooks Davis 		if (ifan->ifan_what == IFAN_DEPARTURE &&
3146964abefSBrian Somers 		    ifan->ifan_index == ifi->index) {
3156964abefSBrian Somers 			warning("Interface %s is gone, dhclient exiting",
3166964abefSBrian Somers 			    ifi->name);
31747c08596SBrooks Davis 			goto die;
3186964abefSBrian Somers 		}
31947c08596SBrooks Davis 		break;
3202b19b6fcSBrooks Davis 	case RTM_IEEE80211:
3212b19b6fcSBrooks Davis 		ifan = (struct if_announcemsghdr *)rtm;
3222b19b6fcSBrooks Davis 		if (ifan->ifan_index != ifi->index)
3232b19b6fcSBrooks Davis 			break;
3242b19b6fcSBrooks Davis 		switch (ifan->ifan_what) {
3252b19b6fcSBrooks Davis 		case RTM_IEEE80211_ASSOC:
326b35f2511SSam Leffler 		case RTM_IEEE80211_REASSOC:
3272b19b6fcSBrooks Davis 			/*
32861063e47SSam Leffler 			 * Use assoc/reassoc event to kick state machine
32961063e47SSam Leffler 			 * in case we roam.  Otherwise fall back to the
33061063e47SSam Leffler 			 * normal state machine just like a wired network.
3312b19b6fcSBrooks Davis 			 */
33261063e47SSam Leffler 			jev = (struct ieee80211_join_event *) &ifan[1];
33361063e47SSam Leffler 			if (memcmp(curbssid, jev->iev_addr, 6)) {
33461063e47SSam Leffler 				disassoc(ifi);
33561063e47SSam Leffler 				state_reboot(ifi);
33659eac186SBrooks Davis 			}
33761063e47SSam Leffler 			memcpy(curbssid, jev->iev_addr, 6);
3382b19b6fcSBrooks Davis 			break;
3392b19b6fcSBrooks Davis 		}
3402b19b6fcSBrooks Davis 		break;
34147c08596SBrooks Davis 	default:
34247c08596SBrooks Davis 		break;
34347c08596SBrooks Davis 	}
34447c08596SBrooks Davis 	return;
34547c08596SBrooks Davis 
34647c08596SBrooks Davis die:
34747c08596SBrooks Davis 	script_init("FAIL", NULL);
34847c08596SBrooks Davis 	if (ifi->client->alias)
34947c08596SBrooks Davis 		script_write_params("alias_", ifi->client->alias);
35047c08596SBrooks Davis 	script_go();
35123f39c90SDag-Erling Smørgrav 	if (pidfile != NULL)
35223f39c90SDag-Erling Smørgrav 		pidfile_remove(pidfile);
35347c08596SBrooks Davis 	exit(1);
35447c08596SBrooks Davis }
35547c08596SBrooks Davis 
356cb003dd9SMariusz Zaborski static void
357cb003dd9SMariusz Zaborski init_casper(void)
358cb003dd9SMariusz Zaborski {
359cb003dd9SMariusz Zaborski 	cap_channel_t		*casper;
360cb003dd9SMariusz Zaborski 
361cb003dd9SMariusz Zaborski 	casper = cap_init();
362cb003dd9SMariusz Zaborski 	if (casper == NULL)
363cb003dd9SMariusz Zaborski 		error("unable to start casper");
364cb003dd9SMariusz Zaborski 
365cb003dd9SMariusz Zaborski 	capsyslog = cap_service_open(casper, "system.syslog");
366cb003dd9SMariusz Zaborski 	cap_close(casper);
367cb003dd9SMariusz Zaborski 	if (capsyslog == NULL)
368cb003dd9SMariusz Zaborski 		error("unable to open system.syslog service");
369cb003dd9SMariusz Zaborski }
370cb003dd9SMariusz Zaborski 
37147c08596SBrooks Davis int
37247c08596SBrooks Davis main(int argc, char *argv[])
37347c08596SBrooks Davis {
374976e1003SMark Johnston 	u_int			 capmode;
37547c08596SBrooks Davis 	int			 ch, fd, quiet = 0, i = 0;
37647c08596SBrooks Davis 	int			 pipe_fd[2];
3772b19b6fcSBrooks Davis 	int			 immediate_daemon = 0;
37847c08596SBrooks Davis 	struct passwd		*pw;
37923f39c90SDag-Erling Smørgrav 	pid_t			 otherpid;
3807008be5bSPawel Jakub Dawidek 	cap_rights_t		 rights;
38147c08596SBrooks Davis 
382cb003dd9SMariusz Zaborski 	init_casper();
383cb003dd9SMariusz Zaborski 
38447c08596SBrooks Davis 	/* Initially, log errors to stderr as well as to syslogd. */
385b537db69SEitan Adler 	cap_openlog(capsyslog, getprogname(), LOG_PID | LOG_NDELAY, DHCPD_LOG_FACILITY);
386cb003dd9SMariusz Zaborski 	cap_setlogmask(capsyslog, LOG_UPTO(LOG_DEBUG));
38747c08596SBrooks Davis 
38823f39c90SDag-Erling Smørgrav 	while ((ch = getopt(argc, argv, "bc:dl:p:qu")) != -1)
38947c08596SBrooks Davis 		switch (ch) {
3902b19b6fcSBrooks Davis 		case 'b':
3912b19b6fcSBrooks Davis 			immediate_daemon = 1;
3922b19b6fcSBrooks Davis 			break;
39347c08596SBrooks Davis 		case 'c':
39447c08596SBrooks Davis 			path_dhclient_conf = optarg;
39547c08596SBrooks Davis 			break;
39647c08596SBrooks Davis 		case 'd':
39747c08596SBrooks Davis 			no_daemon = 1;
39847c08596SBrooks Davis 			break;
39947c08596SBrooks Davis 		case 'l':
40047c08596SBrooks Davis 			path_dhclient_db = optarg;
40147c08596SBrooks Davis 			break;
40223f39c90SDag-Erling Smørgrav 		case 'p':
40323f39c90SDag-Erling Smørgrav 			path_dhclient_pidfile = optarg;
40423f39c90SDag-Erling Smørgrav 			break;
40547c08596SBrooks Davis 		case 'q':
40647c08596SBrooks Davis 			quiet = 1;
40747c08596SBrooks Davis 			break;
40847c08596SBrooks Davis 		case 'u':
40947c08596SBrooks Davis 			unknown_ok = 0;
41047c08596SBrooks Davis 			break;
41147c08596SBrooks Davis 		default:
41247c08596SBrooks Davis 			usage();
41347c08596SBrooks Davis 		}
41447c08596SBrooks Davis 
41547c08596SBrooks Davis 	argc -= optind;
41647c08596SBrooks Davis 	argv += optind;
41747c08596SBrooks Davis 
41847c08596SBrooks Davis 	if (argc != 1)
41947c08596SBrooks Davis 		usage();
42047c08596SBrooks Davis 
42123f39c90SDag-Erling Smørgrav 	if (path_dhclient_pidfile == NULL) {
42223f39c90SDag-Erling Smørgrav 		asprintf(&path_dhclient_pidfile,
423976e1003SMark Johnston 		    "%s/dhclient/dhclient.%s.pid", _PATH_VARRUN, *argv);
42423f39c90SDag-Erling Smørgrav 		if (path_dhclient_pidfile == NULL)
42523f39c90SDag-Erling Smørgrav 			error("asprintf");
42623f39c90SDag-Erling Smørgrav 	}
42707561ab4SEitan Adler 	pidfile = pidfile_open(path_dhclient_pidfile, 0644, &otherpid);
42823f39c90SDag-Erling Smørgrav 	if (pidfile == NULL) {
42923f39c90SDag-Erling Smørgrav 		if (errno == EEXIST)
43023f39c90SDag-Erling Smørgrav 			error("dhclient already running, pid: %d.", otherpid);
43123f39c90SDag-Erling Smørgrav 		if (errno == EAGAIN)
43223f39c90SDag-Erling Smørgrav 			error("dhclient already running.");
43323f39c90SDag-Erling Smørgrav 		warning("Cannot open or create pidfile: %m");
43423f39c90SDag-Erling Smørgrav 	}
43523f39c90SDag-Erling Smørgrav 
43647c08596SBrooks Davis 	if ((ifi = calloc(1, sizeof(struct interface_info))) == NULL)
43747c08596SBrooks Davis 		error("calloc");
43847c08596SBrooks Davis 	if (strlcpy(ifi->name, argv[0], IFNAMSIZ) >= IFNAMSIZ)
43947c08596SBrooks Davis 		error("Interface name too long");
44047c08596SBrooks Davis 	if (path_dhclient_db == NULL && asprintf(&path_dhclient_db, "%s.%s",
44147c08596SBrooks Davis 	    _PATH_DHCLIENT_DB, ifi->name) == -1)
44247c08596SBrooks Davis 		error("asprintf");
44347c08596SBrooks Davis 
44447c08596SBrooks Davis 	if (quiet)
44547c08596SBrooks Davis 		log_perror = 0;
44647c08596SBrooks Davis 
44747c08596SBrooks Davis 	tzset();
44847c08596SBrooks Davis 	time(&cur_time);
44947c08596SBrooks Davis 
450ba019ae5SPawel Jakub Dawidek 	inaddr_broadcast.s_addr = INADDR_BROADCAST;
45147c08596SBrooks Davis 	inaddr_any.s_addr = INADDR_ANY;
45247c08596SBrooks Davis 
45347c08596SBrooks Davis 	read_client_conf();
45447c08596SBrooks Davis 
45523f39c90SDag-Erling Smørgrav 	/* The next bit is potentially very time-consuming, so write out
45623f39c90SDag-Erling Smørgrav 	   the pidfile right away.  We will write it out again with the
45723f39c90SDag-Erling Smørgrav 	   correct pid after daemonizing. */
45823f39c90SDag-Erling Smørgrav 	if (pidfile != NULL)
45923f39c90SDag-Erling Smørgrav 		pidfile_write(pidfile);
46023f39c90SDag-Erling Smørgrav 
46147c08596SBrooks Davis 	if (!interface_link_status(ifi->name)) {
46247c08596SBrooks Davis 		fprintf(stderr, "%s: no link ...", ifi->name);
46347c08596SBrooks Davis 		fflush(stderr);
46447c08596SBrooks Davis 		sleep(1);
46547c08596SBrooks Davis 		while (!interface_link_status(ifi->name)) {
46647c08596SBrooks Davis 			fprintf(stderr, ".");
46747c08596SBrooks Davis 			fflush(stderr);
46847c08596SBrooks Davis 			if (++i > 10) {
46947c08596SBrooks Davis 				fprintf(stderr, " giving up\n");
47047c08596SBrooks Davis 				exit(1);
47147c08596SBrooks Davis 			}
47247c08596SBrooks Davis 			sleep(1);
47347c08596SBrooks Davis 		}
47447c08596SBrooks Davis 		fprintf(stderr, " got link\n");
47547c08596SBrooks Davis 	}
4760a26f858SJohn Baldwin 	ifi->linkstat = 1;
47747c08596SBrooks Davis 
47847c08596SBrooks Davis 	if ((nullfd = open(_PATH_DEVNULL, O_RDWR, 0)) == -1)
47947c08596SBrooks Davis 		error("cannot open %s: %m", _PATH_DEVNULL);
48047c08596SBrooks Davis 
48147c08596SBrooks Davis 	if ((pw = getpwnam("_dhcp")) == NULL) {
48247c08596SBrooks Davis 		warning("no such user: _dhcp, falling back to \"nobody\"");
48347c08596SBrooks Davis 		if ((pw = getpwnam("nobody")) == NULL)
48447c08596SBrooks Davis 			error("no such user: nobody");
48547c08596SBrooks Davis 	}
48647c08596SBrooks Davis 
4870bbe8306SPawel Jakub Dawidek 	/*
4880bbe8306SPawel Jakub Dawidek 	 * Obtain hostname before entering capability mode - it won't be
4890bbe8306SPawel Jakub Dawidek 	 * possible then, as reading kern.hostname is not permitted.
4900bbe8306SPawel Jakub Dawidek 	 */
4910bbe8306SPawel Jakub Dawidek 	if (gethostname(hostname, sizeof(hostname)) < 0)
4920bbe8306SPawel Jakub Dawidek 		hostname[0] = '\0';
4930bbe8306SPawel Jakub Dawidek 
494374a8a32SPawel Jakub Dawidek 	priv_script_init("PREINIT", NULL);
495374a8a32SPawel Jakub Dawidek 	if (ifi->client->alias)
496374a8a32SPawel Jakub Dawidek 		priv_script_write_params("alias_", ifi->client->alias);
497374a8a32SPawel Jakub Dawidek 	priv_script_go();
498374a8a32SPawel Jakub Dawidek 
499235eb530SPawel Jakub Dawidek 	/* set up the interface */
500235eb530SPawel Jakub Dawidek 	discover_interfaces(ifi);
501235eb530SPawel Jakub Dawidek 
50247c08596SBrooks Davis 	if (pipe(pipe_fd) == -1)
50347c08596SBrooks Davis 		error("pipe");
50447c08596SBrooks Davis 
50547c08596SBrooks Davis 	fork_privchld(pipe_fd[0], pipe_fd[1]);
50647c08596SBrooks Davis 
507235eb530SPawel Jakub Dawidek 	close(ifi->ufdesc);
508235eb530SPawel Jakub Dawidek 	ifi->ufdesc = -1;
509235eb530SPawel Jakub Dawidek 	close(ifi->wfdesc);
510235eb530SPawel Jakub Dawidek 	ifi->wfdesc = -1;
511235eb530SPawel Jakub Dawidek 
51247c08596SBrooks Davis 	close(pipe_fd[0]);
51347c08596SBrooks Davis 	privfd = pipe_fd[1];
5147008be5bSPawel Jakub Dawidek 	cap_rights_init(&rights, CAP_READ, CAP_WRITE);
515377421dfSMariusz Zaborski 	if (caph_rights_limit(privfd, &rights) < 0)
516de2c882fSPawel Jakub Dawidek 		error("can't limit private descriptor: %m");
51747c08596SBrooks Davis 
51847c08596SBrooks Davis 	if ((fd = open(path_dhclient_db, O_RDONLY|O_EXLOCK|O_CREAT, 0)) == -1)
51947c08596SBrooks Davis 		error("can't open and lock %s: %m", path_dhclient_db);
52047c08596SBrooks Davis 	read_client_leases();
52147c08596SBrooks Davis 	rewrite_client_leases();
52247c08596SBrooks Davis 	close(fd);
52347c08596SBrooks Davis 
52447c08596SBrooks Davis 	if ((routefd = socket(PF_ROUTE, SOCK_RAW, 0)) != -1)
52547c08596SBrooks Davis 		add_protocol("AF_ROUTE", routefd, routehandler, ifi);
526e374cef5SPawel Jakub Dawidek 	if (shutdown(routefd, SHUT_WR) < 0)
527e374cef5SPawel Jakub Dawidek 		error("can't shutdown route socket: %m");
528bb7a82acSChristian Brueffer 	cap_rights_init(&rights, CAP_EVENT, CAP_READ);
529377421dfSMariusz Zaborski 	if (caph_rights_limit(routefd, &rights) < 0)
530f73ac8b9SPawel Jakub Dawidek 		error("can't limit route socket: %m");
53147c08596SBrooks Davis 
53247c08596SBrooks Davis 	endpwent();
53347c08596SBrooks Davis 
53447c08596SBrooks Davis 	setproctitle("%s", ifi->name);
53547c08596SBrooks Davis 
53617cfcf1dSMark Johnston 	/* setgroups(2) is not permitted in capability mode. */
53717cfcf1dSMark Johnston 	if (setgroups(1, &pw->pw_gid) != 0)
53817cfcf1dSMark Johnston 		error("can't restrict groups: %m");
53917cfcf1dSMark Johnston 
5407672a014SMariusz Zaborski 	if (caph_enter_casper() < 0)
5418da93e68SPawel Jakub Dawidek 		error("can't enter capability mode: %m");
5428da93e68SPawel Jakub Dawidek 
543976e1003SMark Johnston 	/*
54417cfcf1dSMark Johnston 	 * If we are not in capability mode (i.e., Capsicum or libcasper is
54517cfcf1dSMark Johnston 	 * disabled), try to restrict filesystem access.  This will fail if
54617cfcf1dSMark Johnston 	 * kern.chroot_allow_open_directories is 0 or the process is jailed.
547976e1003SMark Johnston 	 */
548976e1003SMark Johnston 	if (cap_getmode(&capmode) < 0 || capmode == 0) {
549976e1003SMark Johnston 		if (chroot(_PATH_VAREMPTY) == -1)
550976e1003SMark Johnston 			error("chroot");
551976e1003SMark Johnston 		if (chdir("/") == -1)
552976e1003SMark Johnston 			error("chdir(\"/\")");
553976e1003SMark Johnston 	}
554976e1003SMark Johnston 
55517cfcf1dSMark Johnston 	if (setegid(pw->pw_gid) || setgid(pw->pw_gid) ||
55617cfcf1dSMark Johnston 	    seteuid(pw->pw_uid) || setuid(pw->pw_uid))
55717cfcf1dSMark Johnston 		error("can't drop privileges: %m");
55817cfcf1dSMark Johnston 
5592b19b6fcSBrooks Davis 	if (immediate_daemon)
5602b19b6fcSBrooks Davis 		go_daemon();
5612b19b6fcSBrooks Davis 
56247c08596SBrooks Davis 	ifi->client->state = S_INIT;
56347c08596SBrooks Davis 	state_reboot(ifi);
56447c08596SBrooks Davis 
56547c08596SBrooks Davis 	bootp_packet_handler = do_packet;
56647c08596SBrooks Davis 
56747c08596SBrooks Davis 	dispatch();
56847c08596SBrooks Davis 
56947c08596SBrooks Davis 	/* not reached */
57047c08596SBrooks Davis 	return (0);
57147c08596SBrooks Davis }
57247c08596SBrooks Davis 
57347c08596SBrooks Davis void
57447c08596SBrooks Davis usage(void)
57547c08596SBrooks Davis {
57647c08596SBrooks Davis 
577b537db69SEitan Adler 	fprintf(stderr, "usage: %s [-bdqu] ", getprogname());
57847c08596SBrooks Davis 	fprintf(stderr, "[-c conffile] [-l leasefile] interface\n");
57947c08596SBrooks Davis 	exit(1);
58047c08596SBrooks Davis }
58147c08596SBrooks Davis 
58247c08596SBrooks Davis /*
58347c08596SBrooks Davis  * Individual States:
58447c08596SBrooks Davis  *
58547c08596SBrooks Davis  * Each routine is called from the dhclient_state_machine() in one of
58647c08596SBrooks Davis  * these conditions:
58747c08596SBrooks Davis  * -> entering INIT state
58847c08596SBrooks Davis  * -> recvpacket_flag == 0: timeout in this state
58947c08596SBrooks Davis  * -> otherwise: received a packet in this state
59047c08596SBrooks Davis  *
59147c08596SBrooks Davis  * Return conditions as handled by dhclient_state_machine():
59247c08596SBrooks Davis  * Returns 1, sendpacket_flag = 1: send packet, reset timer.
59347c08596SBrooks Davis  * Returns 1, sendpacket_flag = 0: just reset the timer (wait for a milestone).
59447c08596SBrooks Davis  * Returns 0: finish the nap which was interrupted for no good reason.
59547c08596SBrooks Davis  *
59647c08596SBrooks Davis  * Several per-interface variables are used to keep track of the process:
59747c08596SBrooks Davis  *   active_lease: the lease that is being used on the interface
59847c08596SBrooks Davis  *                 (null pointer if not configured yet).
59947c08596SBrooks Davis  *   offered_leases: leases corresponding to DHCPOFFER messages that have
60047c08596SBrooks Davis  *                   been sent to us by DHCP servers.
60147c08596SBrooks Davis  *   acked_leases: leases corresponding to DHCPACK messages that have been
60247c08596SBrooks Davis  *                 sent to us by DHCP servers.
60347c08596SBrooks Davis  *   sendpacket: DHCP packet we're trying to send.
60447c08596SBrooks Davis  *   destination: IP address to send sendpacket to
60547c08596SBrooks Davis  * In addition, there are several relevant per-lease variables.
60647c08596SBrooks Davis  *   T1_expiry, T2_expiry, lease_expiry: lease milestones
60747c08596SBrooks Davis  * In the active lease, these control the process of renewing the lease;
60847c08596SBrooks Davis  * In leases on the acked_leases list, this simply determines when we
60947c08596SBrooks Davis  * can no longer legitimately use the lease.
61047c08596SBrooks Davis  */
61147c08596SBrooks Davis 
61247c08596SBrooks Davis void
61347c08596SBrooks Davis state_reboot(void *ipp)
61447c08596SBrooks Davis {
61547c08596SBrooks Davis 	struct interface_info *ip = ipp;
61647c08596SBrooks Davis 
61747c08596SBrooks Davis 	/* If we don't remember an active lease, go straight to INIT. */
61847c08596SBrooks Davis 	if (!ip->client->active || ip->client->active->is_bootp) {
61947c08596SBrooks Davis 		state_init(ip);
62047c08596SBrooks Davis 		return;
62147c08596SBrooks Davis 	}
62247c08596SBrooks Davis 
62347c08596SBrooks Davis 	/* We are in the rebooting state. */
62447c08596SBrooks Davis 	ip->client->state = S_REBOOTING;
62547c08596SBrooks Davis 
62647c08596SBrooks Davis 	/* make_request doesn't initialize xid because it normally comes
62747c08596SBrooks Davis 	   from the DHCPDISCOVER, but we haven't sent a DHCPDISCOVER,
62847c08596SBrooks Davis 	   so pick an xid now. */
62947c08596SBrooks Davis 	ip->client->xid = arc4random();
63047c08596SBrooks Davis 
63147c08596SBrooks Davis 	/* Make a DHCPREQUEST packet, and set appropriate per-interface
63247c08596SBrooks Davis 	   flags. */
63347c08596SBrooks Davis 	make_request(ip, ip->client->active);
63447c08596SBrooks Davis 	ip->client->destination = iaddr_broadcast;
63547c08596SBrooks Davis 	ip->client->first_sending = cur_time;
63647c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
63747c08596SBrooks Davis 
63847c08596SBrooks Davis 	/* Zap the medium list... */
63947c08596SBrooks Davis 	ip->client->medium = NULL;
64047c08596SBrooks Davis 
64147c08596SBrooks Davis 	/* Send out the first DHCPREQUEST packet. */
64247c08596SBrooks Davis 	send_request(ip);
64347c08596SBrooks Davis }
64447c08596SBrooks Davis 
64547c08596SBrooks Davis /*
64647c08596SBrooks Davis  * Called when a lease has completely expired and we've
64747c08596SBrooks Davis  * been unable to renew it.
64847c08596SBrooks Davis  */
64947c08596SBrooks Davis void
65047c08596SBrooks Davis state_init(void *ipp)
65147c08596SBrooks Davis {
65247c08596SBrooks Davis 	struct interface_info *ip = ipp;
65347c08596SBrooks Davis 
65447c08596SBrooks Davis 	ASSERT_STATE(state, S_INIT);
65547c08596SBrooks Davis 
65647c08596SBrooks Davis 	/* Make a DHCPDISCOVER packet, and set appropriate per-interface
65747c08596SBrooks Davis 	   flags. */
65847c08596SBrooks Davis 	make_discover(ip, ip->client->active);
65947c08596SBrooks Davis 	ip->client->xid = ip->client->packet.xid;
66047c08596SBrooks Davis 	ip->client->destination = iaddr_broadcast;
66147c08596SBrooks Davis 	ip->client->state = S_SELECTING;
66247c08596SBrooks Davis 	ip->client->first_sending = cur_time;
66347c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
66447c08596SBrooks Davis 
66547c08596SBrooks Davis 	/* Add an immediate timeout to cause the first DHCPDISCOVER packet
66647c08596SBrooks Davis 	   to go out. */
66747c08596SBrooks Davis 	send_discover(ip);
66847c08596SBrooks Davis }
66947c08596SBrooks Davis 
67047c08596SBrooks Davis /*
67147c08596SBrooks Davis  * state_selecting is called when one or more DHCPOFFER packets
67247c08596SBrooks Davis  * have been received and a configurable period of time has passed.
67347c08596SBrooks Davis  */
67447c08596SBrooks Davis void
67547c08596SBrooks Davis state_selecting(void *ipp)
67647c08596SBrooks Davis {
67747c08596SBrooks Davis 	struct interface_info *ip = ipp;
67847c08596SBrooks Davis 	struct client_lease *lp, *next, *picked;
67947c08596SBrooks Davis 
68047c08596SBrooks Davis 	ASSERT_STATE(state, S_SELECTING);
68147c08596SBrooks Davis 
68247c08596SBrooks Davis 	/* Cancel state_selecting and send_discover timeouts, since either
68347c08596SBrooks Davis 	   one could have got us here. */
68447c08596SBrooks Davis 	cancel_timeout(state_selecting, ip);
68547c08596SBrooks Davis 	cancel_timeout(send_discover, ip);
68647c08596SBrooks Davis 
68747c08596SBrooks Davis 	/* We have received one or more DHCPOFFER packets.   Currently,
68847c08596SBrooks Davis 	   the only criterion by which we judge leases is whether or
68947c08596SBrooks Davis 	   not we get a response when we arp for them. */
69047c08596SBrooks Davis 	picked = NULL;
69147c08596SBrooks Davis 	for (lp = ip->client->offered_leases; lp; lp = next) {
69247c08596SBrooks Davis 		next = lp->next;
69347c08596SBrooks Davis 
69447c08596SBrooks Davis 		/* Check to see if we got an ARPREPLY for the address
69547c08596SBrooks Davis 		   in this particular lease. */
69647c08596SBrooks Davis 		if (!picked) {
69747c08596SBrooks Davis 			script_init("ARPCHECK", lp->medium);
69847c08596SBrooks Davis 			script_write_params("check_", lp);
69947c08596SBrooks Davis 
70047c08596SBrooks Davis 			/* If the ARPCHECK code detects another
70147c08596SBrooks Davis 			   machine using the offered address, it exits
70247c08596SBrooks Davis 			   nonzero.  We need to send a DHCPDECLINE and
70347c08596SBrooks Davis 			   toss the lease. */
70447c08596SBrooks Davis 			if (script_go()) {
70547c08596SBrooks Davis 				make_decline(ip, lp);
70647c08596SBrooks Davis 				send_decline(ip);
70747c08596SBrooks Davis 				goto freeit;
70847c08596SBrooks Davis 			}
70947c08596SBrooks Davis 			picked = lp;
71047c08596SBrooks Davis 			picked->next = NULL;
71147c08596SBrooks Davis 		} else {
71247c08596SBrooks Davis freeit:
71347c08596SBrooks Davis 			free_client_lease(lp);
71447c08596SBrooks Davis 		}
71547c08596SBrooks Davis 	}
71647c08596SBrooks Davis 	ip->client->offered_leases = NULL;
71747c08596SBrooks Davis 
71847c08596SBrooks Davis 	/* If we just tossed all the leases we were offered, go back
71947c08596SBrooks Davis 	   to square one. */
72047c08596SBrooks Davis 	if (!picked) {
72147c08596SBrooks Davis 		ip->client->state = S_INIT;
72247c08596SBrooks Davis 		state_init(ip);
72347c08596SBrooks Davis 		return;
72447c08596SBrooks Davis 	}
72547c08596SBrooks Davis 
72647c08596SBrooks Davis 	/* If it was a BOOTREPLY, we can just take the address right now. */
72747c08596SBrooks Davis 	if (!picked->options[DHO_DHCP_MESSAGE_TYPE].len) {
72847c08596SBrooks Davis 		ip->client->new = picked;
72947c08596SBrooks Davis 
73047c08596SBrooks Davis 		/* Make up some lease expiry times
73147c08596SBrooks Davis 		   XXX these should be configurable. */
73247c08596SBrooks Davis 		ip->client->new->expiry = cur_time + 12000;
73347c08596SBrooks Davis 		ip->client->new->renewal += cur_time + 8000;
73447c08596SBrooks Davis 		ip->client->new->rebind += cur_time + 10000;
73547c08596SBrooks Davis 
73647c08596SBrooks Davis 		ip->client->state = S_REQUESTING;
73747c08596SBrooks Davis 
73847c08596SBrooks Davis 		/* Bind to the address we received. */
73947c08596SBrooks Davis 		bind_lease(ip);
74047c08596SBrooks Davis 		return;
74147c08596SBrooks Davis 	}
74247c08596SBrooks Davis 
74347c08596SBrooks Davis 	/* Go to the REQUESTING state. */
74447c08596SBrooks Davis 	ip->client->destination = iaddr_broadcast;
74547c08596SBrooks Davis 	ip->client->state = S_REQUESTING;
74647c08596SBrooks Davis 	ip->client->first_sending = cur_time;
74747c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
74847c08596SBrooks Davis 
74947c08596SBrooks Davis 	/* Make a DHCPREQUEST packet from the lease we picked. */
75047c08596SBrooks Davis 	make_request(ip, picked);
75147c08596SBrooks Davis 	ip->client->xid = ip->client->packet.xid;
75247c08596SBrooks Davis 
75347c08596SBrooks Davis 	/* Toss the lease we picked - we'll get it back in a DHCPACK. */
75447c08596SBrooks Davis 	free_client_lease(picked);
75547c08596SBrooks Davis 
75647c08596SBrooks Davis 	/* Add an immediate timeout to send the first DHCPREQUEST packet. */
75747c08596SBrooks Davis 	send_request(ip);
75847c08596SBrooks Davis }
75947c08596SBrooks Davis 
76047c08596SBrooks Davis /* state_requesting is called when we receive a DHCPACK message after
76147c08596SBrooks Davis    having sent out one or more DHCPREQUEST packets. */
76247c08596SBrooks Davis 
76347c08596SBrooks Davis void
76447c08596SBrooks Davis dhcpack(struct packet *packet)
76547c08596SBrooks Davis {
76647c08596SBrooks Davis 	struct interface_info *ip = packet->interface;
76747c08596SBrooks Davis 	struct client_lease *lease;
76847c08596SBrooks Davis 
76947c08596SBrooks Davis 	/* If we're not receptive to an offer right now, or if the offer
77047c08596SBrooks Davis 	   has an unrecognizable transaction id, then just drop it. */
77147c08596SBrooks Davis 	if (packet->interface->client->xid != packet->raw->xid ||
77247c08596SBrooks Davis 	    (packet->interface->hw_address.hlen != packet->raw->hlen) ||
77347c08596SBrooks Davis 	    (memcmp(packet->interface->hw_address.haddr,
77447c08596SBrooks Davis 	    packet->raw->chaddr, packet->raw->hlen)))
77547c08596SBrooks Davis 		return;
77647c08596SBrooks Davis 
77747c08596SBrooks Davis 	if (ip->client->state != S_REBOOTING &&
77847c08596SBrooks Davis 	    ip->client->state != S_REQUESTING &&
77947c08596SBrooks Davis 	    ip->client->state != S_RENEWING &&
78047c08596SBrooks Davis 	    ip->client->state != S_REBINDING)
78147c08596SBrooks Davis 		return;
78247c08596SBrooks Davis 
78347c08596SBrooks Davis 	note("DHCPACK from %s", piaddr(packet->client_addr));
78447c08596SBrooks Davis 
78547c08596SBrooks Davis 	lease = packet_to_lease(packet);
78647c08596SBrooks Davis 	if (!lease) {
78747c08596SBrooks Davis 		note("packet_to_lease failed.");
78847c08596SBrooks Davis 		return;
78947c08596SBrooks Davis 	}
79047c08596SBrooks Davis 
79147c08596SBrooks Davis 	ip->client->new = lease;
79247c08596SBrooks Davis 
79347c08596SBrooks Davis 	/* Stop resending DHCPREQUEST. */
79447c08596SBrooks Davis 	cancel_timeout(send_request, ip);
79547c08596SBrooks Davis 
79647c08596SBrooks Davis 	/* Figure out the lease time. */
7971fb4382cSNick Hibma         if (ip->client->config->default_actions[DHO_DHCP_LEASE_TIME] ==
7981fb4382cSNick Hibma             ACTION_SUPERSEDE)
7991fb4382cSNick Hibma 		ip->client->new->expiry = getULong(
8001fb4382cSNick Hibma 		    ip->client->config->defaults[DHO_DHCP_LEASE_TIME].data);
8013492caf5SHans Petter Selasky         else if (ip->client->new->options[DHO_DHCP_LEASE_TIME].len >= 4)
80247c08596SBrooks Davis 		ip->client->new->expiry = getULong(
80347c08596SBrooks Davis 		    ip->client->new->options[DHO_DHCP_LEASE_TIME].data);
80447c08596SBrooks Davis 	else
80547c08596SBrooks Davis 		ip->client->new->expiry = default_lease_time;
80647c08596SBrooks Davis 	/* A number that looks negative here is really just very large,
807223c44aeSNick Hibma 	   because the lease expiry offset is unsigned. Also make sure that
808223c44aeSNick Hibma            the addition of cur_time below does not overflow (a 32 bit) time_t. */
809223c44aeSNick Hibma 	if (ip->client->new->expiry < 0 ||
810223c44aeSNick Hibma             ip->client->new->expiry > TIME_MAX - cur_time)
811223c44aeSNick Hibma 		ip->client->new->expiry = TIME_MAX - cur_time;
81247c08596SBrooks Davis 	/* XXX should be fixed by resetting the client state */
81347c08596SBrooks Davis 	if (ip->client->new->expiry < 60)
81447c08596SBrooks Davis 		ip->client->new->expiry = 60;
81547c08596SBrooks Davis 
816c13fa60cSNick Hibma         /* Unless overridden in the config, take the server-provided renewal
817223c44aeSNick Hibma          * time if there is one. Otherwise figure it out according to the spec.
818c13fa60cSNick Hibma          * Also make sure the renewal time does not exceed the expiry time.
819c13fa60cSNick Hibma          */
820c13fa60cSNick Hibma         if (ip->client->config->default_actions[DHO_DHCP_RENEWAL_TIME] ==
821c13fa60cSNick Hibma             ACTION_SUPERSEDE)
822c13fa60cSNick Hibma 		ip->client->new->renewal = getULong(
823c13fa60cSNick Hibma 		    ip->client->config->defaults[DHO_DHCP_RENEWAL_TIME].data);
8243492caf5SHans Petter Selasky         else if (ip->client->new->options[DHO_DHCP_RENEWAL_TIME].len >= 4)
82547c08596SBrooks Davis 		ip->client->new->renewal = getULong(
82647c08596SBrooks Davis 		    ip->client->new->options[DHO_DHCP_RENEWAL_TIME].data);
82747c08596SBrooks Davis 	else
82847c08596SBrooks Davis 		ip->client->new->renewal = ip->client->new->expiry / 2;
829223c44aeSNick Hibma         if (ip->client->new->renewal < 0 ||
830223c44aeSNick Hibma             ip->client->new->renewal > ip->client->new->expiry / 2)
831c13fa60cSNick Hibma                 ip->client->new->renewal = ip->client->new->expiry / 2;
83247c08596SBrooks Davis 
83347c08596SBrooks Davis 	/* Same deal with the rebind time. */
834c13fa60cSNick Hibma         if (ip->client->config->default_actions[DHO_DHCP_REBINDING_TIME] ==
835c13fa60cSNick Hibma             ACTION_SUPERSEDE)
836c13fa60cSNick Hibma 		ip->client->new->rebind = getULong(
837c13fa60cSNick Hibma 		    ip->client->config->defaults[DHO_DHCP_REBINDING_TIME].data);
8383492caf5SHans Petter Selasky         else if (ip->client->new->options[DHO_DHCP_REBINDING_TIME].len >= 4)
83947c08596SBrooks Davis 		ip->client->new->rebind = getULong(
84047c08596SBrooks Davis 		    ip->client->new->options[DHO_DHCP_REBINDING_TIME].data);
84147c08596SBrooks Davis 	else
842223c44aeSNick Hibma 		ip->client->new->rebind = ip->client->new->renewal / 4 * 7;
843223c44aeSNick Hibma 	if (ip->client->new->rebind < 0 ||
844223c44aeSNick Hibma             ip->client->new->rebind > ip->client->new->renewal / 4 * 7)
845223c44aeSNick Hibma                 ip->client->new->rebind = ip->client->new->renewal / 4 * 7;
84647c08596SBrooks Davis 
847223c44aeSNick Hibma         /* Convert the time offsets into seconds-since-the-epoch */
84847c08596SBrooks Davis         ip->client->new->expiry += cur_time;
84947c08596SBrooks Davis         ip->client->new->renewal += cur_time;
85047c08596SBrooks Davis         ip->client->new->rebind += cur_time;
85147c08596SBrooks Davis 
85247c08596SBrooks Davis 	bind_lease(ip);
85347c08596SBrooks Davis }
85447c08596SBrooks Davis 
85547c08596SBrooks Davis void
85647c08596SBrooks Davis bind_lease(struct interface_info *ip)
85747c08596SBrooks Davis {
858387016a5SConrad Meyer 	struct option_data *opt;
859387016a5SConrad Meyer 
86047c08596SBrooks Davis 	/* Remember the medium. */
86147c08596SBrooks Davis 	ip->client->new->medium = ip->client->medium;
86247c08596SBrooks Davis 
863387016a5SConrad Meyer 	opt = &ip->client->new->options[DHO_INTERFACE_MTU];
864387016a5SConrad Meyer 	if (opt->len == sizeof(u_int16_t)) {
865f93497feSConrad Meyer 		u_int16_t mtu = 0;
866221e5d2dSMaxim Sobolev 		u_int16_t old_mtu = 0;
867f93497feSConrad Meyer 		bool supersede = (ip->client->config->default_actions[DHO_INTERFACE_MTU] ==
868f93497feSConrad Meyer 			ACTION_SUPERSEDE);
869f93497feSConrad Meyer 
870f93497feSConrad Meyer 		if (supersede)
871f93497feSConrad Meyer 			mtu = getUShort(ip->client->config->defaults[DHO_INTERFACE_MTU].data);
872387016a5SConrad Meyer 		else
873f93497feSConrad Meyer 			mtu = be16dec(opt->data);
874f93497feSConrad Meyer 
875221e5d2dSMaxim Sobolev 		if (ip->client->active) {
876221e5d2dSMaxim Sobolev 			opt = &ip->client->active->options[DHO_INTERFACE_MTU];
877221e5d2dSMaxim Sobolev 			if (opt->len == sizeof(u_int16_t)) {
878221e5d2dSMaxim Sobolev 				old_mtu = be16dec(opt->data);
879221e5d2dSMaxim Sobolev 			}
880221e5d2dSMaxim Sobolev 		}
881221e5d2dSMaxim Sobolev 
882f93497feSConrad Meyer 		if (mtu < MIN_MTU) {
883f93497feSConrad Meyer 			/* Treat 0 like a user intentionally doesn't want to change MTU and,
884f93497feSConrad Meyer 			 * therefore, warning is not needed */
885f93497feSConrad Meyer 			if (!supersede || mtu != 0)
886f93497feSConrad Meyer 				warning("mtu size %u < %d: ignored", (unsigned)mtu, MIN_MTU);
887221e5d2dSMaxim Sobolev 		} else if (ip->client->state != S_RENEWING || mtu != old_mtu) {
888387016a5SConrad Meyer 			interface_set_mtu_unpriv(privfd, mtu);
889387016a5SConrad Meyer 		}
890f93497feSConrad Meyer 	}
891387016a5SConrad Meyer 
89247c08596SBrooks Davis 	/* Write out the new lease. */
89347c08596SBrooks Davis 	write_client_lease(ip, ip->client->new, 0);
89447c08596SBrooks Davis 
89547c08596SBrooks Davis 	/* Run the client script with the new parameters. */
89647c08596SBrooks Davis 	script_init((ip->client->state == S_REQUESTING ? "BOUND" :
89747c08596SBrooks Davis 	    (ip->client->state == S_RENEWING ? "RENEW" :
89847c08596SBrooks Davis 	    (ip->client->state == S_REBOOTING ? "REBOOT" : "REBIND"))),
89947c08596SBrooks Davis 	    ip->client->new->medium);
90047c08596SBrooks Davis 	if (ip->client->active && ip->client->state != S_REBOOTING)
90147c08596SBrooks Davis 		script_write_params("old_", ip->client->active);
90247c08596SBrooks Davis 	script_write_params("new_", ip->client->new);
90347c08596SBrooks Davis 	if (ip->client->alias)
90447c08596SBrooks Davis 		script_write_params("alias_", ip->client->alias);
90547c08596SBrooks Davis 	script_go();
90647c08596SBrooks Davis 
90747c08596SBrooks Davis 	/* Replace the old active lease with the new one. */
90847c08596SBrooks Davis 	if (ip->client->active)
90947c08596SBrooks Davis 		free_client_lease(ip->client->active);
91047c08596SBrooks Davis 	ip->client->active = ip->client->new;
91147c08596SBrooks Davis 	ip->client->new = NULL;
91247c08596SBrooks Davis 
91347c08596SBrooks Davis 	/* Set up a timeout to start the renewal process. */
91447c08596SBrooks Davis 	add_timeout(ip->client->active->renewal, state_bound, ip);
91547c08596SBrooks Davis 
91647c08596SBrooks Davis 	note("bound to %s -- renewal in %d seconds.",
91747c08596SBrooks Davis 	    piaddr(ip->client->active->address),
9189c13d9cdSBrooks Davis 	    (int)(ip->client->active->renewal - cur_time));
91947c08596SBrooks Davis 	ip->client->state = S_BOUND;
92047c08596SBrooks Davis 	reinitialize_interfaces();
92147c08596SBrooks Davis 	go_daemon();
92247c08596SBrooks Davis }
92347c08596SBrooks Davis 
92447c08596SBrooks Davis /*
92547c08596SBrooks Davis  * state_bound is called when we've successfully bound to a particular
92647c08596SBrooks Davis  * lease, but the renewal time on that lease has expired.   We are
92747c08596SBrooks Davis  * expected to unicast a DHCPREQUEST to the server that gave us our
92847c08596SBrooks Davis  * original lease.
92947c08596SBrooks Davis  */
93047c08596SBrooks Davis void
93147c08596SBrooks Davis state_bound(void *ipp)
93247c08596SBrooks Davis {
93347c08596SBrooks Davis 	struct interface_info *ip = ipp;
9340a539a0fSFabian Kurtz 	u_int8_t *dp = NULL;
9350a539a0fSFabian Kurtz 	int len;
93647c08596SBrooks Davis 
93747c08596SBrooks Davis 	ASSERT_STATE(state, S_BOUND);
93847c08596SBrooks Davis 
93947c08596SBrooks Davis 	/* T1 has expired. */
94047c08596SBrooks Davis 	make_request(ip, ip->client->active);
94147c08596SBrooks Davis 	ip->client->xid = ip->client->packet.xid;
94247c08596SBrooks Davis 
9430a539a0fSFabian Kurtz 	if (ip->client->config->default_actions[DHO_DHCP_SERVER_IDENTIFIER] ==
9440a539a0fSFabian Kurtz 	    ACTION_SUPERSEDE) {
9450a539a0fSFabian Kurtz 		dp = ip->client->config->defaults[DHO_DHCP_SERVER_IDENTIFIER].data;
9460a539a0fSFabian Kurtz 		len = ip->client->config->defaults[DHO_DHCP_SERVER_IDENTIFIER].len;
9470a539a0fSFabian Kurtz 	} else {
9480a539a0fSFabian Kurtz 		dp = ip->client->active->options[DHO_DHCP_SERVER_IDENTIFIER].data;
9490a539a0fSFabian Kurtz 		len = ip->client->active->options[DHO_DHCP_SERVER_IDENTIFIER].len;
9500a539a0fSFabian Kurtz 	}
9510a539a0fSFabian Kurtz 	if (len == 4) {
9520a539a0fSFabian Kurtz 		memcpy(ip->client->destination.iabuf, dp, len);
9530a539a0fSFabian Kurtz 		ip->client->destination.len = len;
95447c08596SBrooks Davis 	} else
95547c08596SBrooks Davis 		ip->client->destination = iaddr_broadcast;
95647c08596SBrooks Davis 
95747c08596SBrooks Davis 	ip->client->first_sending = cur_time;
95847c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
95947c08596SBrooks Davis 	ip->client->state = S_RENEWING;
96047c08596SBrooks Davis 
96147c08596SBrooks Davis 	/* Send the first packet immediately. */
96247c08596SBrooks Davis 	send_request(ip);
96347c08596SBrooks Davis }
96447c08596SBrooks Davis 
96547c08596SBrooks Davis void
96647c08596SBrooks Davis bootp(struct packet *packet)
96747c08596SBrooks Davis {
96847c08596SBrooks Davis 	struct iaddrlist *ap;
96947c08596SBrooks Davis 
97047c08596SBrooks Davis 	if (packet->raw->op != BOOTREPLY)
97147c08596SBrooks Davis 		return;
97247c08596SBrooks Davis 
97347c08596SBrooks Davis 	/* If there's a reject list, make sure this packet's sender isn't
97447c08596SBrooks Davis 	   on it. */
97547c08596SBrooks Davis 	for (ap = packet->interface->client->config->reject_list;
97647c08596SBrooks Davis 	    ap; ap = ap->next) {
97747c08596SBrooks Davis 		if (addr_eq(packet->client_addr, ap->addr)) {
97847c08596SBrooks Davis 			note("BOOTREPLY from %s rejected.", piaddr(ap->addr));
97947c08596SBrooks Davis 			return;
98047c08596SBrooks Davis 		}
98147c08596SBrooks Davis 	}
98247c08596SBrooks Davis 	dhcpoffer(packet);
98347c08596SBrooks Davis }
98447c08596SBrooks Davis 
98547c08596SBrooks Davis void
98647c08596SBrooks Davis dhcp(struct packet *packet)
98747c08596SBrooks Davis {
98847c08596SBrooks Davis 	struct iaddrlist *ap;
98947c08596SBrooks Davis 	void (*handler)(struct packet *);
99079a1d195SAlan Somers 	const char *type;
99147c08596SBrooks Davis 
99247c08596SBrooks Davis 	switch (packet->packet_type) {
99347c08596SBrooks Davis 	case DHCPOFFER:
99447c08596SBrooks Davis 		handler = dhcpoffer;
99547c08596SBrooks Davis 		type = "DHCPOFFER";
99647c08596SBrooks Davis 		break;
99747c08596SBrooks Davis 	case DHCPNAK:
99847c08596SBrooks Davis 		handler = dhcpnak;
99947c08596SBrooks Davis 		type = "DHCPNACK";
100047c08596SBrooks Davis 		break;
100147c08596SBrooks Davis 	case DHCPACK:
100247c08596SBrooks Davis 		handler = dhcpack;
100347c08596SBrooks Davis 		type = "DHCPACK";
100447c08596SBrooks Davis 		break;
100547c08596SBrooks Davis 	default:
100647c08596SBrooks Davis 		return;
100747c08596SBrooks Davis 	}
100847c08596SBrooks Davis 
100947c08596SBrooks Davis 	/* If there's a reject list, make sure this packet's sender isn't
101047c08596SBrooks Davis 	   on it. */
101147c08596SBrooks Davis 	for (ap = packet->interface->client->config->reject_list;
101247c08596SBrooks Davis 	    ap; ap = ap->next) {
101347c08596SBrooks Davis 		if (addr_eq(packet->client_addr, ap->addr)) {
101447c08596SBrooks Davis 			note("%s from %s rejected.", type, piaddr(ap->addr));
101547c08596SBrooks Davis 			return;
101647c08596SBrooks Davis 		}
101747c08596SBrooks Davis 	}
101847c08596SBrooks Davis 	(*handler)(packet);
101947c08596SBrooks Davis }
102047c08596SBrooks Davis 
102147c08596SBrooks Davis void
102247c08596SBrooks Davis dhcpoffer(struct packet *packet)
102347c08596SBrooks Davis {
102447c08596SBrooks Davis 	struct interface_info *ip = packet->interface;
102547c08596SBrooks Davis 	struct client_lease *lease, *lp;
102647c08596SBrooks Davis 	int i;
102747c08596SBrooks Davis 	int arp_timeout_needed, stop_selecting;
102879a1d195SAlan Somers 	const char *name = packet->options[DHO_DHCP_MESSAGE_TYPE].len ?
102947c08596SBrooks Davis 	    "DHCPOFFER" : "BOOTREPLY";
103047c08596SBrooks Davis 
103147c08596SBrooks Davis 	/* If we're not receptive to an offer right now, or if the offer
103247c08596SBrooks Davis 	   has an unrecognizable transaction id, then just drop it. */
103347c08596SBrooks Davis 	if (ip->client->state != S_SELECTING ||
103447c08596SBrooks Davis 	    packet->interface->client->xid != packet->raw->xid ||
103547c08596SBrooks Davis 	    (packet->interface->hw_address.hlen != packet->raw->hlen) ||
103647c08596SBrooks Davis 	    (memcmp(packet->interface->hw_address.haddr,
103747c08596SBrooks Davis 	    packet->raw->chaddr, packet->raw->hlen)))
103847c08596SBrooks Davis 		return;
103947c08596SBrooks Davis 
104047c08596SBrooks Davis 	note("%s from %s", name, piaddr(packet->client_addr));
104147c08596SBrooks Davis 
104247c08596SBrooks Davis 	/* If this lease doesn't supply the minimum required parameters,
104347c08596SBrooks Davis 	   blow it off. */
104447c08596SBrooks Davis 	for (i = 0; ip->client->config->required_options[i]; i++) {
104547c08596SBrooks Davis 		if (!packet->options[ip->client->config->
104647c08596SBrooks Davis 		    required_options[i]].len) {
104747c08596SBrooks Davis 			note("%s isn't satisfactory.", name);
104847c08596SBrooks Davis 			return;
104947c08596SBrooks Davis 		}
105047c08596SBrooks Davis 	}
105147c08596SBrooks Davis 
105247c08596SBrooks Davis 	/* If we've already seen this lease, don't record it again. */
105347c08596SBrooks Davis 	for (lease = ip->client->offered_leases;
105447c08596SBrooks Davis 	    lease; lease = lease->next) {
105547c08596SBrooks Davis 		if (lease->address.len == sizeof(packet->raw->yiaddr) &&
105647c08596SBrooks Davis 		    !memcmp(lease->address.iabuf,
105747c08596SBrooks Davis 		    &packet->raw->yiaddr, lease->address.len)) {
105847c08596SBrooks Davis 			debug("%s already seen.", name);
105947c08596SBrooks Davis 			return;
106047c08596SBrooks Davis 		}
106147c08596SBrooks Davis 	}
106247c08596SBrooks Davis 
106347c08596SBrooks Davis 	lease = packet_to_lease(packet);
106447c08596SBrooks Davis 	if (!lease) {
106547c08596SBrooks Davis 		note("packet_to_lease failed.");
106647c08596SBrooks Davis 		return;
106747c08596SBrooks Davis 	}
106847c08596SBrooks Davis 
106947c08596SBrooks Davis 	/* If this lease was acquired through a BOOTREPLY, record that
107047c08596SBrooks Davis 	   fact. */
107147c08596SBrooks Davis 	if (!packet->options[DHO_DHCP_MESSAGE_TYPE].len)
107247c08596SBrooks Davis 		lease->is_bootp = 1;
107347c08596SBrooks Davis 
107447c08596SBrooks Davis 	/* Record the medium under which this lease was offered. */
107547c08596SBrooks Davis 	lease->medium = ip->client->medium;
107647c08596SBrooks Davis 
107747c08596SBrooks Davis 	/* Send out an ARP Request for the offered IP address. */
107847c08596SBrooks Davis 	script_init("ARPSEND", lease->medium);
107947c08596SBrooks Davis 	script_write_params("check_", lease);
108047c08596SBrooks Davis 	/* If the script can't send an ARP request without waiting,
108147c08596SBrooks Davis 	   we'll be waiting when we do the ARPCHECK, so don't wait now. */
108247c08596SBrooks Davis 	if (script_go())
108347c08596SBrooks Davis 		arp_timeout_needed = 0;
108447c08596SBrooks Davis 	else
108547c08596SBrooks Davis 		arp_timeout_needed = 2;
108647c08596SBrooks Davis 
108747c08596SBrooks Davis 	/* Figure out when we're supposed to stop selecting. */
108847c08596SBrooks Davis 	stop_selecting =
108947c08596SBrooks Davis 	    ip->client->first_sending + ip->client->config->select_interval;
109047c08596SBrooks Davis 
109147c08596SBrooks Davis 	/* If this is the lease we asked for, put it at the head of the
109247c08596SBrooks Davis 	   list, and don't mess with the arp request timeout. */
109347c08596SBrooks Davis 	if (lease->address.len == ip->client->requested_address.len &&
109447c08596SBrooks Davis 	    !memcmp(lease->address.iabuf,
109547c08596SBrooks Davis 	    ip->client->requested_address.iabuf,
109647c08596SBrooks Davis 	    ip->client->requested_address.len)) {
109747c08596SBrooks Davis 		lease->next = ip->client->offered_leases;
109847c08596SBrooks Davis 		ip->client->offered_leases = lease;
109947c08596SBrooks Davis 	} else {
110047c08596SBrooks Davis 		/* If we already have an offer, and arping for this
110147c08596SBrooks Davis 		   offer would take us past the selection timeout,
110247c08596SBrooks Davis 		   then don't extend the timeout - just hope for the
110347c08596SBrooks Davis 		   best. */
110447c08596SBrooks Davis 		if (ip->client->offered_leases &&
110547c08596SBrooks Davis 		    (cur_time + arp_timeout_needed) > stop_selecting)
110647c08596SBrooks Davis 			arp_timeout_needed = 0;
110747c08596SBrooks Davis 
110847c08596SBrooks Davis 		/* Put the lease at the end of the list. */
110947c08596SBrooks Davis 		lease->next = NULL;
111047c08596SBrooks Davis 		if (!ip->client->offered_leases)
111147c08596SBrooks Davis 			ip->client->offered_leases = lease;
111247c08596SBrooks Davis 		else {
111347c08596SBrooks Davis 			for (lp = ip->client->offered_leases; lp->next;
111447c08596SBrooks Davis 			    lp = lp->next)
111547c08596SBrooks Davis 				;	/* nothing */
111647c08596SBrooks Davis 			lp->next = lease;
111747c08596SBrooks Davis 		}
111847c08596SBrooks Davis 	}
111947c08596SBrooks Davis 
112047c08596SBrooks Davis 	/* If we're supposed to stop selecting before we've had time
112147c08596SBrooks Davis 	   to wait for the ARPREPLY, add some delay to wait for
112247c08596SBrooks Davis 	   the ARPREPLY. */
112347c08596SBrooks Davis 	if (stop_selecting - cur_time < arp_timeout_needed)
112447c08596SBrooks Davis 		stop_selecting = cur_time + arp_timeout_needed;
112547c08596SBrooks Davis 
112647c08596SBrooks Davis 	/* If the selecting interval has expired, go immediately to
112747c08596SBrooks Davis 	   state_selecting().  Otherwise, time out into
112847c08596SBrooks Davis 	   state_selecting at the select interval. */
112947c08596SBrooks Davis 	if (stop_selecting <= 0)
113047c08596SBrooks Davis 		state_selecting(ip);
113147c08596SBrooks Davis 	else {
113247c08596SBrooks Davis 		add_timeout(stop_selecting, state_selecting, ip);
113347c08596SBrooks Davis 		cancel_timeout(send_discover, ip);
113447c08596SBrooks Davis 	}
113547c08596SBrooks Davis }
113647c08596SBrooks Davis 
113747c08596SBrooks Davis /* Allocate a client_lease structure and initialize it from the parameters
113847c08596SBrooks Davis    in the specified packet. */
113947c08596SBrooks Davis 
114047c08596SBrooks Davis struct client_lease *
114147c08596SBrooks Davis packet_to_lease(struct packet *packet)
114247c08596SBrooks Davis {
1143*461ccb55SRob Norris 	struct interface_info *ip = packet->interface;
114447c08596SBrooks Davis 	struct client_lease *lease;
1145*461ccb55SRob Norris 	int i, j;
114647c08596SBrooks Davis 
114747c08596SBrooks Davis 	lease = malloc(sizeof(struct client_lease));
114847c08596SBrooks Davis 
114947c08596SBrooks Davis 	if (!lease) {
115047c08596SBrooks Davis 		warning("dhcpoffer: no memory to record lease.");
115147c08596SBrooks Davis 		return (NULL);
115247c08596SBrooks Davis 	}
115347c08596SBrooks Davis 
115447c08596SBrooks Davis 	memset(lease, 0, sizeof(*lease));
115547c08596SBrooks Davis 
115647c08596SBrooks Davis 	/* Copy the lease options. */
115747c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
115847c08596SBrooks Davis 		if (packet->options[i].len) {
1159*461ccb55SRob Norris 			int ignored = 0;
1160*461ccb55SRob Norris 			for (j = 0; ip->client->config->ignored_options[j]; j++)
1161*461ccb55SRob Norris 				if (i ==
1162*461ccb55SRob Norris 				    ip->client->config->ignored_options[j]) {
1163*461ccb55SRob Norris 					ignored = 1;
1164*461ccb55SRob Norris 					break;
1165*461ccb55SRob Norris 				}
1166*461ccb55SRob Norris 			if (ignored)
1167*461ccb55SRob Norris 			    continue;
116847c08596SBrooks Davis 			lease->options[i].data =
116947c08596SBrooks Davis 			    malloc(packet->options[i].len + 1);
117047c08596SBrooks Davis 			if (!lease->options[i].data) {
117147c08596SBrooks Davis 				warning("dhcpoffer: no memory for option %d", i);
117247c08596SBrooks Davis 				free_client_lease(lease);
117347c08596SBrooks Davis 				return (NULL);
117447c08596SBrooks Davis 			} else {
117547c08596SBrooks Davis 				memcpy(lease->options[i].data,
117647c08596SBrooks Davis 				    packet->options[i].data,
117747c08596SBrooks Davis 				    packet->options[i].len);
117847c08596SBrooks Davis 				lease->options[i].len =
117947c08596SBrooks Davis 				    packet->options[i].len;
118047c08596SBrooks Davis 				lease->options[i].data[lease->options[i].len] =
118147c08596SBrooks Davis 				    0;
118247c08596SBrooks Davis 			}
118347c08596SBrooks Davis 			if (!check_option(lease,i)) {
118447c08596SBrooks Davis 				/* ignore a bogus lease offer */
118547c08596SBrooks Davis 				warning("Invalid lease option - ignoring offer");
118647c08596SBrooks Davis 				free_client_lease(lease);
118747c08596SBrooks Davis 				return (NULL);
118847c08596SBrooks Davis 			}
118947c08596SBrooks Davis 		}
119047c08596SBrooks Davis 	}
119147c08596SBrooks Davis 
119247c08596SBrooks Davis 	lease->address.len = sizeof(packet->raw->yiaddr);
119347c08596SBrooks Davis 	memcpy(lease->address.iabuf, &packet->raw->yiaddr, lease->address.len);
119447c08596SBrooks Davis 
1195d32438c3SBruce M Simpson 	lease->nextserver.len = sizeof(packet->raw->siaddr);
1196d32438c3SBruce M Simpson 	memcpy(lease->nextserver.iabuf, &packet->raw->siaddr, lease->nextserver.len);
1197d32438c3SBruce M Simpson 
1198acccb9aaSBrooks Davis 	/* If the server name was filled out, copy it.
1199acccb9aaSBrooks Davis 	   Do not attempt to validate the server name as a host name.
1200acccb9aaSBrooks Davis 	   RFC 2131 merely states that sname is NUL-terminated (which do
1201acccb9aaSBrooks Davis 	   do not assume) and that it is the server's host name.  Since
1202acccb9aaSBrooks Davis 	   the ISC client and server allow arbitrary characters, we do
1203acccb9aaSBrooks Davis 	   as well. */
120447c08596SBrooks Davis 	if ((!packet->options[DHO_DHCP_OPTION_OVERLOAD].len ||
120547c08596SBrooks Davis 	    !(packet->options[DHO_DHCP_OPTION_OVERLOAD].data[0] & 2)) &&
120647c08596SBrooks Davis 	    packet->raw->sname[0]) {
120747c08596SBrooks Davis 		lease->server_name = malloc(DHCP_SNAME_LEN + 1);
120847c08596SBrooks Davis 		if (!lease->server_name) {
120947c08596SBrooks Davis 			warning("dhcpoffer: no memory for server name.");
121047c08596SBrooks Davis 			free_client_lease(lease);
121147c08596SBrooks Davis 			return (NULL);
121247c08596SBrooks Davis 		}
121347c08596SBrooks Davis 		memcpy(lease->server_name, packet->raw->sname, DHCP_SNAME_LEN);
121447c08596SBrooks Davis 		lease->server_name[DHCP_SNAME_LEN]='\0';
121547c08596SBrooks Davis 	}
121647c08596SBrooks Davis 
121747c08596SBrooks Davis 	/* Ditto for the filename. */
121847c08596SBrooks Davis 	if ((!packet->options[DHO_DHCP_OPTION_OVERLOAD].len ||
121947c08596SBrooks Davis 	    !(packet->options[DHO_DHCP_OPTION_OVERLOAD].data[0] & 1)) &&
122047c08596SBrooks Davis 	    packet->raw->file[0]) {
122147c08596SBrooks Davis 		/* Don't count on the NUL terminator. */
122247c08596SBrooks Davis 		lease->filename = malloc(DHCP_FILE_LEN + 1);
122347c08596SBrooks Davis 		if (!lease->filename) {
122447c08596SBrooks Davis 			warning("dhcpoffer: no memory for filename.");
122547c08596SBrooks Davis 			free_client_lease(lease);
122647c08596SBrooks Davis 			return (NULL);
122747c08596SBrooks Davis 		}
122847c08596SBrooks Davis 		memcpy(lease->filename, packet->raw->file, DHCP_FILE_LEN);
122947c08596SBrooks Davis 		lease->filename[DHCP_FILE_LEN]='\0';
123047c08596SBrooks Davis 	}
123147c08596SBrooks Davis 	return lease;
123247c08596SBrooks Davis }
123347c08596SBrooks Davis 
123447c08596SBrooks Davis void
123547c08596SBrooks Davis dhcpnak(struct packet *packet)
123647c08596SBrooks Davis {
123747c08596SBrooks Davis 	struct interface_info *ip = packet->interface;
123847c08596SBrooks Davis 
123947c08596SBrooks Davis 	/* If we're not receptive to an offer right now, or if the offer
124047c08596SBrooks Davis 	   has an unrecognizable transaction id, then just drop it. */
124147c08596SBrooks Davis 	if (packet->interface->client->xid != packet->raw->xid ||
124247c08596SBrooks Davis 	    (packet->interface->hw_address.hlen != packet->raw->hlen) ||
124347c08596SBrooks Davis 	    (memcmp(packet->interface->hw_address.haddr,
124447c08596SBrooks Davis 	    packet->raw->chaddr, packet->raw->hlen)))
124547c08596SBrooks Davis 		return;
124647c08596SBrooks Davis 
124747c08596SBrooks Davis 	if (ip->client->state != S_REBOOTING &&
124847c08596SBrooks Davis 	    ip->client->state != S_REQUESTING &&
124947c08596SBrooks Davis 	    ip->client->state != S_RENEWING &&
125047c08596SBrooks Davis 	    ip->client->state != S_REBINDING)
125147c08596SBrooks Davis 		return;
125247c08596SBrooks Davis 
125347c08596SBrooks Davis 	note("DHCPNAK from %s", piaddr(packet->client_addr));
125447c08596SBrooks Davis 
125547c08596SBrooks Davis 	if (!ip->client->active) {
125647c08596SBrooks Davis 		note("DHCPNAK with no active lease.\n");
125747c08596SBrooks Davis 		return;
125847c08596SBrooks Davis 	}
125947c08596SBrooks Davis 
126047c08596SBrooks Davis 	free_client_lease(ip->client->active);
126147c08596SBrooks Davis 	ip->client->active = NULL;
126247c08596SBrooks Davis 
126347c08596SBrooks Davis 	/* Stop sending DHCPREQUEST packets... */
126447c08596SBrooks Davis 	cancel_timeout(send_request, ip);
126547c08596SBrooks Davis 
126647c08596SBrooks Davis 	ip->client->state = S_INIT;
126747c08596SBrooks Davis 	state_init(ip);
126847c08596SBrooks Davis }
126947c08596SBrooks Davis 
127047c08596SBrooks Davis /* Send out a DHCPDISCOVER packet, and set a timeout to send out another
127147c08596SBrooks Davis    one after the right interval has expired.  If we don't get an offer by
127247c08596SBrooks Davis    the time we reach the panic interval, call the panic function. */
127347c08596SBrooks Davis 
127447c08596SBrooks Davis void
127547c08596SBrooks Davis send_discover(void *ipp)
127647c08596SBrooks Davis {
127747c08596SBrooks Davis 	struct interface_info *ip = ipp;
127847c08596SBrooks Davis 	int interval, increase = 1;
127947c08596SBrooks Davis 
128047c08596SBrooks Davis 	/* Figure out how long it's been since we started transmitting. */
128147c08596SBrooks Davis 	interval = cur_time - ip->client->first_sending;
128247c08596SBrooks Davis 
128347c08596SBrooks Davis 	/* If we're past the panic timeout, call the script and tell it
128447c08596SBrooks Davis 	   we haven't found anything for this interface yet. */
128547c08596SBrooks Davis 	if (interval > ip->client->config->timeout) {
128647c08596SBrooks Davis 		state_panic(ip);
128747c08596SBrooks Davis 		return;
128847c08596SBrooks Davis 	}
128947c08596SBrooks Davis 
129047c08596SBrooks Davis 	/* If we're selecting media, try the whole list before doing
129147c08596SBrooks Davis 	   the exponential backoff, but if we've already received an
129247c08596SBrooks Davis 	   offer, stop looping, because we obviously have it right. */
129347c08596SBrooks Davis 	if (!ip->client->offered_leases &&
129447c08596SBrooks Davis 	    ip->client->config->media) {
129547c08596SBrooks Davis 		int fail = 0;
129647c08596SBrooks Davis again:
129747c08596SBrooks Davis 		if (ip->client->medium) {
129847c08596SBrooks Davis 			ip->client->medium = ip->client->medium->next;
129947c08596SBrooks Davis 			increase = 0;
130047c08596SBrooks Davis 		}
130147c08596SBrooks Davis 		if (!ip->client->medium) {
130247c08596SBrooks Davis 			if (fail)
130347c08596SBrooks Davis 				error("No valid media types for %s!", ip->name);
130447c08596SBrooks Davis 			ip->client->medium = ip->client->config->media;
130547c08596SBrooks Davis 			increase = 1;
130647c08596SBrooks Davis 		}
130747c08596SBrooks Davis 
130847c08596SBrooks Davis 		note("Trying medium \"%s\" %d", ip->client->medium->string,
130947c08596SBrooks Davis 		    increase);
131047c08596SBrooks Davis 		script_init("MEDIUM", ip->client->medium);
131147c08596SBrooks Davis 		if (script_go())
131247c08596SBrooks Davis 			goto again;
131347c08596SBrooks Davis 	}
131447c08596SBrooks Davis 
131547c08596SBrooks Davis 	/*
131647c08596SBrooks Davis 	 * If we're supposed to increase the interval, do so.  If it's
131747c08596SBrooks Davis 	 * currently zero (i.e., we haven't sent any packets yet), set
131847c08596SBrooks Davis 	 * it to one; otherwise, add to it a random number between zero
131947c08596SBrooks Davis 	 * and two times itself.  On average, this means that it will
132047c08596SBrooks Davis 	 * double with every transmission.
132147c08596SBrooks Davis 	 */
132247c08596SBrooks Davis 	if (increase) {
132347c08596SBrooks Davis 		if (!ip->client->interval)
132447c08596SBrooks Davis 			ip->client->interval =
132547c08596SBrooks Davis 			    ip->client->config->initial_interval;
132647c08596SBrooks Davis 		else {
132747c08596SBrooks Davis 			ip->client->interval += (arc4random() >> 2) %
132847c08596SBrooks Davis 			    (2 * ip->client->interval);
132947c08596SBrooks Davis 		}
133047c08596SBrooks Davis 
133147c08596SBrooks Davis 		/* Don't backoff past cutoff. */
133247c08596SBrooks Davis 		if (ip->client->interval >
133347c08596SBrooks Davis 		    ip->client->config->backoff_cutoff)
133447c08596SBrooks Davis 			ip->client->interval =
133547c08596SBrooks Davis 				((ip->client->config->backoff_cutoff / 2)
133647c08596SBrooks Davis 				 + ((arc4random() >> 2) %
133747c08596SBrooks Davis 				    ip->client->config->backoff_cutoff));
133847c08596SBrooks Davis 	} else if (!ip->client->interval)
133947c08596SBrooks Davis 		ip->client->interval =
134047c08596SBrooks Davis 			ip->client->config->initial_interval;
134147c08596SBrooks Davis 
134247c08596SBrooks Davis 	/* If the backoff would take us to the panic timeout, just use that
134347c08596SBrooks Davis 	   as the interval. */
134447c08596SBrooks Davis 	if (cur_time + ip->client->interval >
134547c08596SBrooks Davis 	    ip->client->first_sending + ip->client->config->timeout)
134647c08596SBrooks Davis 		ip->client->interval =
134747c08596SBrooks Davis 			(ip->client->first_sending +
134847c08596SBrooks Davis 			 ip->client->config->timeout) - cur_time + 1;
134947c08596SBrooks Davis 
135047c08596SBrooks Davis 	/* Record the number of seconds since we started sending. */
135147c08596SBrooks Davis 	if (interval < 65536)
135247c08596SBrooks Davis 		ip->client->packet.secs = htons(interval);
135347c08596SBrooks Davis 	else
135447c08596SBrooks Davis 		ip->client->packet.secs = htons(65535);
135547c08596SBrooks Davis 	ip->client->secs = ip->client->packet.secs;
135647c08596SBrooks Davis 
135747c08596SBrooks Davis 	note("DHCPDISCOVER on %s to %s port %d interval %d",
1358ba019ae5SPawel Jakub Dawidek 	    ip->name, inet_ntoa(inaddr_broadcast), REMOTE_PORT,
13599c13d9cdSBrooks Davis 	    (int)ip->client->interval);
136047c08596SBrooks Davis 
136147c08596SBrooks Davis 	/* Send out a packet. */
1362235eb530SPawel Jakub Dawidek 	send_packet_unpriv(privfd, &ip->client->packet,
1363235eb530SPawel Jakub Dawidek 	    ip->client->packet_length, inaddr_any, inaddr_broadcast);
136447c08596SBrooks Davis 
136547c08596SBrooks Davis 	add_timeout(cur_time + ip->client->interval, send_discover, ip);
136647c08596SBrooks Davis }
136747c08596SBrooks Davis 
136847c08596SBrooks Davis /*
136947c08596SBrooks Davis  * state_panic gets called if we haven't received any offers in a preset
137047c08596SBrooks Davis  * amount of time.   When this happens, we try to use existing leases
137147c08596SBrooks Davis  * that haven't yet expired, and failing that, we call the client script
137247c08596SBrooks Davis  * and hope it can do something.
137347c08596SBrooks Davis  */
137447c08596SBrooks Davis void
137547c08596SBrooks Davis state_panic(void *ipp)
137647c08596SBrooks Davis {
137747c08596SBrooks Davis 	struct interface_info *ip = ipp;
137847c08596SBrooks Davis 	struct client_lease *loop = ip->client->active;
137947c08596SBrooks Davis 	struct client_lease *lp;
138047c08596SBrooks Davis 
138147c08596SBrooks Davis 	note("No DHCPOFFERS received.");
138247c08596SBrooks Davis 
138347c08596SBrooks Davis 	/* We may not have an active lease, but we may have some
138447c08596SBrooks Davis 	   predefined leases that we can try. */
138547c08596SBrooks Davis 	if (!ip->client->active && ip->client->leases)
138647c08596SBrooks Davis 		goto activate_next;
138747c08596SBrooks Davis 
138847c08596SBrooks Davis 	/* Run through the list of leases and see if one can be used. */
138947c08596SBrooks Davis 	while (ip->client->active) {
139047c08596SBrooks Davis 		if (ip->client->active->expiry > cur_time) {
139147c08596SBrooks Davis 			note("Trying recorded lease %s",
139247c08596SBrooks Davis 			    piaddr(ip->client->active->address));
139347c08596SBrooks Davis 			/* Run the client script with the existing
139447c08596SBrooks Davis 			   parameters. */
139547c08596SBrooks Davis 			script_init("TIMEOUT",
139647c08596SBrooks Davis 			    ip->client->active->medium);
139747c08596SBrooks Davis 			script_write_params("new_", ip->client->active);
139847c08596SBrooks Davis 			if (ip->client->alias)
139947c08596SBrooks Davis 				script_write_params("alias_",
140047c08596SBrooks Davis 				    ip->client->alias);
140147c08596SBrooks Davis 
140247c08596SBrooks Davis 			/* If the old lease is still good and doesn't
140347c08596SBrooks Davis 			   yet need renewal, go into BOUND state and
140447c08596SBrooks Davis 			   timeout at the renewal time. */
140547c08596SBrooks Davis 			if (!script_go()) {
140647c08596SBrooks Davis 				if (cur_time <
140747c08596SBrooks Davis 				    ip->client->active->renewal) {
140847c08596SBrooks Davis 					ip->client->state = S_BOUND;
140947c08596SBrooks Davis 					note("bound: renewal in %d seconds.",
14109c13d9cdSBrooks Davis 					    (int)(ip->client->active->renewal -
14119c13d9cdSBrooks Davis 					    cur_time));
141247c08596SBrooks Davis 					add_timeout(
141347c08596SBrooks Davis 					    ip->client->active->renewal,
141447c08596SBrooks Davis 					    state_bound, ip);
141547c08596SBrooks Davis 				} else {
141647c08596SBrooks Davis 					ip->client->state = S_BOUND;
141747c08596SBrooks Davis 					note("bound: immediate renewal.");
141847c08596SBrooks Davis 					state_bound(ip);
141947c08596SBrooks Davis 				}
142047c08596SBrooks Davis 				reinitialize_interfaces();
142147c08596SBrooks Davis 				go_daemon();
142247c08596SBrooks Davis 				return;
142347c08596SBrooks Davis 			}
142447c08596SBrooks Davis 		}
142547c08596SBrooks Davis 
142647c08596SBrooks Davis 		/* If there are no other leases, give up. */
142747c08596SBrooks Davis 		if (!ip->client->leases) {
142847c08596SBrooks Davis 			ip->client->leases = ip->client->active;
142947c08596SBrooks Davis 			ip->client->active = NULL;
143047c08596SBrooks Davis 			break;
143147c08596SBrooks Davis 		}
143247c08596SBrooks Davis 
143347c08596SBrooks Davis activate_next:
143447c08596SBrooks Davis 		/* Otherwise, put the active lease at the end of the
143547c08596SBrooks Davis 		   lease list, and try another lease.. */
143647c08596SBrooks Davis 		for (lp = ip->client->leases; lp->next; lp = lp->next)
143747c08596SBrooks Davis 			;
143847c08596SBrooks Davis 		lp->next = ip->client->active;
143947c08596SBrooks Davis 		if (lp->next)
144047c08596SBrooks Davis 			lp->next->next = NULL;
144147c08596SBrooks Davis 		ip->client->active = ip->client->leases;
144247c08596SBrooks Davis 		ip->client->leases = ip->client->leases->next;
144347c08596SBrooks Davis 
144447c08596SBrooks Davis 		/* If we already tried this lease, we've exhausted the
144547c08596SBrooks Davis 		   set of leases, so we might as well give up for
144647c08596SBrooks Davis 		   now. */
144747c08596SBrooks Davis 		if (ip->client->active == loop)
144847c08596SBrooks Davis 			break;
144947c08596SBrooks Davis 		else if (!loop)
145047c08596SBrooks Davis 			loop = ip->client->active;
145147c08596SBrooks Davis 	}
145247c08596SBrooks Davis 
145347c08596SBrooks Davis 	/* No leases were available, or what was available didn't work, so
145447c08596SBrooks Davis 	   tell the shell script that we failed to allocate an address,
145547c08596SBrooks Davis 	   and try again later. */
145647c08596SBrooks Davis 	note("No working leases in persistent database - sleeping.\n");
145747c08596SBrooks Davis 	script_init("FAIL", NULL);
145847c08596SBrooks Davis 	if (ip->client->alias)
145947c08596SBrooks Davis 		script_write_params("alias_", ip->client->alias);
146047c08596SBrooks Davis 	script_go();
146147c08596SBrooks Davis 	ip->client->state = S_INIT;
146247c08596SBrooks Davis 	add_timeout(cur_time + ip->client->config->retry_interval, state_init,
146347c08596SBrooks Davis 	    ip);
146447c08596SBrooks Davis 	go_daemon();
146547c08596SBrooks Davis }
146647c08596SBrooks Davis 
146747c08596SBrooks Davis void
146847c08596SBrooks Davis send_request(void *ipp)
146947c08596SBrooks Davis {
147047c08596SBrooks Davis 	struct interface_info *ip = ipp;
1471ba019ae5SPawel Jakub Dawidek 	struct in_addr from, to;
147247c08596SBrooks Davis 	int interval;
147347c08596SBrooks Davis 
147447c08596SBrooks Davis 	/* Figure out how long it's been since we started transmitting. */
147547c08596SBrooks Davis 	interval = cur_time - ip->client->first_sending;
147647c08596SBrooks Davis 
147747c08596SBrooks Davis 	/* If we're in the INIT-REBOOT or REQUESTING state and we're
147847c08596SBrooks Davis 	   past the reboot timeout, go to INIT and see if we can
147947c08596SBrooks Davis 	   DISCOVER an address... */
148047c08596SBrooks Davis 	/* XXX In the INIT-REBOOT state, if we don't get an ACK, it
148147c08596SBrooks Davis 	   means either that we're on a network with no DHCP server,
148247c08596SBrooks Davis 	   or that our server is down.  In the latter case, assuming
148347c08596SBrooks Davis 	   that there is a backup DHCP server, DHCPDISCOVER will get
148447c08596SBrooks Davis 	   us a new address, but we could also have successfully
148547c08596SBrooks Davis 	   reused our old address.  In the former case, we're hosed
148647c08596SBrooks Davis 	   anyway.  This is not a win-prone situation. */
148747c08596SBrooks Davis 	if ((ip->client->state == S_REBOOTING ||
148847c08596SBrooks Davis 	    ip->client->state == S_REQUESTING) &&
148947c08596SBrooks Davis 	    interval > ip->client->config->reboot_timeout) {
149047c08596SBrooks Davis cancel:
149147c08596SBrooks Davis 		ip->client->state = S_INIT;
149247c08596SBrooks Davis 		cancel_timeout(send_request, ip);
149347c08596SBrooks Davis 		state_init(ip);
149447c08596SBrooks Davis 		return;
149547c08596SBrooks Davis 	}
149647c08596SBrooks Davis 
149747c08596SBrooks Davis 	/* If we're in the reboot state, make sure the media is set up
149847c08596SBrooks Davis 	   correctly. */
149947c08596SBrooks Davis 	if (ip->client->state == S_REBOOTING &&
150047c08596SBrooks Davis 	    !ip->client->medium &&
150147c08596SBrooks Davis 	    ip->client->active->medium ) {
150247c08596SBrooks Davis 		script_init("MEDIUM", ip->client->active->medium);
150347c08596SBrooks Davis 
150447c08596SBrooks Davis 		/* If the medium we chose won't fly, go to INIT state. */
150547c08596SBrooks Davis 		if (script_go())
150647c08596SBrooks Davis 			goto cancel;
150747c08596SBrooks Davis 
150847c08596SBrooks Davis 		/* Record the medium. */
150947c08596SBrooks Davis 		ip->client->medium = ip->client->active->medium;
151047c08596SBrooks Davis 	}
151147c08596SBrooks Davis 
151247c08596SBrooks Davis 	/* If the lease has expired, relinquish the address and go back
151347c08596SBrooks Davis 	   to the INIT state. */
151447c08596SBrooks Davis 	if (ip->client->state != S_REQUESTING &&
151547c08596SBrooks Davis 	    cur_time > ip->client->active->expiry) {
151647c08596SBrooks Davis 		/* Run the client script with the new parameters. */
151747c08596SBrooks Davis 		script_init("EXPIRE", NULL);
151847c08596SBrooks Davis 		script_write_params("old_", ip->client->active);
151947c08596SBrooks Davis 		if (ip->client->alias)
152047c08596SBrooks Davis 			script_write_params("alias_", ip->client->alias);
152147c08596SBrooks Davis 		script_go();
152247c08596SBrooks Davis 
152347c08596SBrooks Davis 		/* Now do a preinit on the interface so that we can
152447c08596SBrooks Davis 		   discover a new address. */
152547c08596SBrooks Davis 		script_init("PREINIT", NULL);
152647c08596SBrooks Davis 		if (ip->client->alias)
152747c08596SBrooks Davis 			script_write_params("alias_", ip->client->alias);
152847c08596SBrooks Davis 		script_go();
152947c08596SBrooks Davis 
153047c08596SBrooks Davis 		ip->client->state = S_INIT;
153147c08596SBrooks Davis 		state_init(ip);
153247c08596SBrooks Davis 		return;
153347c08596SBrooks Davis 	}
153447c08596SBrooks Davis 
153547c08596SBrooks Davis 	/* Do the exponential backoff... */
153647c08596SBrooks Davis 	if (!ip->client->interval)
153747c08596SBrooks Davis 		ip->client->interval = ip->client->config->initial_interval;
153847c08596SBrooks Davis 	else
153947c08596SBrooks Davis 		ip->client->interval += ((arc4random() >> 2) %
154047c08596SBrooks Davis 		    (2 * ip->client->interval));
154147c08596SBrooks Davis 
154247c08596SBrooks Davis 	/* Don't backoff past cutoff. */
154347c08596SBrooks Davis 	if (ip->client->interval >
154447c08596SBrooks Davis 	    ip->client->config->backoff_cutoff)
154547c08596SBrooks Davis 		ip->client->interval =
154647c08596SBrooks Davis 		    ((ip->client->config->backoff_cutoff / 2) +
154747c08596SBrooks Davis 		    ((arc4random() >> 2) % ip->client->interval));
154847c08596SBrooks Davis 
154947c08596SBrooks Davis 	/* If the backoff would take us to the expiry time, just set the
155047c08596SBrooks Davis 	   timeout to the expiry time. */
155147c08596SBrooks Davis 	if (ip->client->state != S_REQUESTING &&
155247c08596SBrooks Davis 	    cur_time + ip->client->interval >
155347c08596SBrooks Davis 	    ip->client->active->expiry)
155447c08596SBrooks Davis 		ip->client->interval =
155547c08596SBrooks Davis 		    ip->client->active->expiry - cur_time + 1;
155647c08596SBrooks Davis 
155747c08596SBrooks Davis 	/* If the lease T2 time has elapsed, or if we're not yet bound,
155847c08596SBrooks Davis 	   broadcast the DHCPREQUEST rather than unicasting. */
155947c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING ||
156047c08596SBrooks Davis 	    ip->client->state == S_REBOOTING ||
156147c08596SBrooks Davis 	    cur_time > ip->client->active->rebind)
1562ba019ae5SPawel Jakub Dawidek 		to.s_addr = INADDR_BROADCAST;
156347c08596SBrooks Davis 	else
1564ba019ae5SPawel Jakub Dawidek 		memcpy(&to.s_addr, ip->client->destination.iabuf,
1565ba019ae5SPawel Jakub Dawidek 		    sizeof(to.s_addr));
156647c08596SBrooks Davis 
15673acf1760SDavid Bright 	if (ip->client->state != S_REQUESTING &&
15683acf1760SDavid Bright 	    ip->client->state != S_REBOOTING)
156947c08596SBrooks Davis 		memcpy(&from, ip->client->active->address.iabuf,
157047c08596SBrooks Davis 		    sizeof(from));
157147c08596SBrooks Davis 	else
157247c08596SBrooks Davis 		from.s_addr = INADDR_ANY;
157347c08596SBrooks Davis 
157447c08596SBrooks Davis 	/* Record the number of seconds since we started sending. */
157547c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING)
157647c08596SBrooks Davis 		ip->client->packet.secs = ip->client->secs;
157747c08596SBrooks Davis 	else {
157847c08596SBrooks Davis 		if (interval < 65536)
157947c08596SBrooks Davis 			ip->client->packet.secs = htons(interval);
158047c08596SBrooks Davis 		else
158147c08596SBrooks Davis 			ip->client->packet.secs = htons(65535);
158247c08596SBrooks Davis 	}
158347c08596SBrooks Davis 
1584ba019ae5SPawel Jakub Dawidek 	note("DHCPREQUEST on %s to %s port %d", ip->name, inet_ntoa(to),
1585ba019ae5SPawel Jakub Dawidek 	    REMOTE_PORT);
158647c08596SBrooks Davis 
158747c08596SBrooks Davis 	/* Send out a packet. */
1588235eb530SPawel Jakub Dawidek 	send_packet_unpriv(privfd, &ip->client->packet,
1589235eb530SPawel Jakub Dawidek 	    ip->client->packet_length, from, to);
159047c08596SBrooks Davis 
159147c08596SBrooks Davis 	add_timeout(cur_time + ip->client->interval, send_request, ip);
159247c08596SBrooks Davis }
159347c08596SBrooks Davis 
159447c08596SBrooks Davis void
159547c08596SBrooks Davis send_decline(void *ipp)
159647c08596SBrooks Davis {
159747c08596SBrooks Davis 	struct interface_info *ip = ipp;
159847c08596SBrooks Davis 
159947c08596SBrooks Davis 	note("DHCPDECLINE on %s to %s port %d", ip->name,
1600ba019ae5SPawel Jakub Dawidek 	    inet_ntoa(inaddr_broadcast), REMOTE_PORT);
160147c08596SBrooks Davis 
160247c08596SBrooks Davis 	/* Send out a packet. */
1603235eb530SPawel Jakub Dawidek 	send_packet_unpriv(privfd, &ip->client->packet,
1604235eb530SPawel Jakub Dawidek 	    ip->client->packet_length, inaddr_any, inaddr_broadcast);
160547c08596SBrooks Davis }
160647c08596SBrooks Davis 
160747c08596SBrooks Davis void
160847c08596SBrooks Davis make_discover(struct interface_info *ip, struct client_lease *lease)
160947c08596SBrooks Davis {
161047c08596SBrooks Davis 	unsigned char discover = DHCPDISCOVER;
161147c08596SBrooks Davis 	struct tree_cache *options[256];
161247c08596SBrooks Davis 	struct tree_cache option_elements[256];
161347c08596SBrooks Davis 	int i;
161447c08596SBrooks Davis 
161547c08596SBrooks Davis 	memset(option_elements, 0, sizeof(option_elements));
161647c08596SBrooks Davis 	memset(options, 0, sizeof(options));
161747c08596SBrooks Davis 	memset(&ip->client->packet, 0, sizeof(ip->client->packet));
161847c08596SBrooks Davis 
161947c08596SBrooks Davis 	/* Set DHCP_MESSAGE_TYPE to DHCPDISCOVER */
162047c08596SBrooks Davis 	i = DHO_DHCP_MESSAGE_TYPE;
162147c08596SBrooks Davis 	options[i] = &option_elements[i];
162247c08596SBrooks Davis 	options[i]->value = &discover;
162347c08596SBrooks Davis 	options[i]->len = sizeof(discover);
162447c08596SBrooks Davis 	options[i]->buf_size = sizeof(discover);
162547c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
162647c08596SBrooks Davis 
162747c08596SBrooks Davis 	/* Request the options we want */
162847c08596SBrooks Davis 	i  = DHO_DHCP_PARAMETER_REQUEST_LIST;
162947c08596SBrooks Davis 	options[i] = &option_elements[i];
163047c08596SBrooks Davis 	options[i]->value = ip->client->config->requested_options;
163147c08596SBrooks Davis 	options[i]->len = ip->client->config->requested_option_count;
163247c08596SBrooks Davis 	options[i]->buf_size =
163347c08596SBrooks Davis 		ip->client->config->requested_option_count;
163447c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
163547c08596SBrooks Davis 
163647c08596SBrooks Davis 	/* If we had an address, try to get it again. */
163747c08596SBrooks Davis 	if (lease) {
163847c08596SBrooks Davis 		ip->client->requested_address = lease->address;
163947c08596SBrooks Davis 		i = DHO_DHCP_REQUESTED_ADDRESS;
164047c08596SBrooks Davis 		options[i] = &option_elements[i];
164147c08596SBrooks Davis 		options[i]->value = lease->address.iabuf;
164247c08596SBrooks Davis 		options[i]->len = lease->address.len;
164347c08596SBrooks Davis 		options[i]->buf_size = lease->address.len;
164447c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
164547c08596SBrooks Davis 	} else
164647c08596SBrooks Davis 		ip->client->requested_address.len = 0;
164747c08596SBrooks Davis 
164847c08596SBrooks Davis 	/* Send any options requested in the config file. */
164947c08596SBrooks Davis 	for (i = 0; i < 256; i++)
165047c08596SBrooks Davis 		if (!options[i] &&
165147c08596SBrooks Davis 		    ip->client->config->send_options[i].data) {
165247c08596SBrooks Davis 			options[i] = &option_elements[i];
165347c08596SBrooks Davis 			options[i]->value =
165447c08596SBrooks Davis 			    ip->client->config->send_options[i].data;
165547c08596SBrooks Davis 			options[i]->len =
165647c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
165747c08596SBrooks Davis 			options[i]->buf_size =
165847c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
165947c08596SBrooks Davis 			options[i]->timeout = 0xFFFFFFFF;
166047c08596SBrooks Davis 		}
166147c08596SBrooks Davis 
1662fcab8addSBrooks Davis 	/* send host name if not set via config file. */
1663fcab8addSBrooks Davis 	if (!options[DHO_HOST_NAME]) {
16640bbe8306SPawel Jakub Dawidek 		if (hostname[0] != '\0') {
1665fcab8addSBrooks Davis 			size_t len;
1666fcab8addSBrooks Davis 			char* posDot = strchr(hostname, '.');
1667fcab8addSBrooks Davis 			if (posDot != NULL)
1668fcab8addSBrooks Davis 				len = posDot - hostname;
1669fcab8addSBrooks Davis 			else
1670fcab8addSBrooks Davis 				len = strlen(hostname);
1671fcab8addSBrooks Davis 			options[DHO_HOST_NAME] = &option_elements[DHO_HOST_NAME];
1672fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->value = hostname;
1673fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->len = len;
1674fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->buf_size = len;
1675fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->timeout = 0xFFFFFFFF;
1676fcab8addSBrooks Davis 		}
1677fcab8addSBrooks Davis 	}
1678fcab8addSBrooks Davis 
1679fcab8addSBrooks Davis 	/* set unique client identifier */
1680fb0eab09SConrad Meyer 	char client_ident[sizeof(ip->hw_address.haddr) + 1];
1681fcab8addSBrooks Davis 	if (!options[DHO_DHCP_CLIENT_IDENTIFIER]) {
16824441bd73SConrad Meyer 		int hwlen = (ip->hw_address.hlen < sizeof(client_ident)-1) ?
16834441bd73SConrad Meyer 				ip->hw_address.hlen : sizeof(client_ident)-1;
16844441bd73SConrad Meyer 		client_ident[0] = ip->hw_address.htype;
16854441bd73SConrad Meyer 		memcpy(&client_ident[1], ip->hw_address.haddr, hwlen);
1686fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER] = &option_elements[DHO_DHCP_CLIENT_IDENTIFIER];
16874441bd73SConrad Meyer 		options[DHO_DHCP_CLIENT_IDENTIFIER]->value = client_ident;
16884441bd73SConrad Meyer 		options[DHO_DHCP_CLIENT_IDENTIFIER]->len = hwlen+1;
16894441bd73SConrad Meyer 		options[DHO_DHCP_CLIENT_IDENTIFIER]->buf_size = hwlen+1;
1690fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->timeout = 0xFFFFFFFF;
1691fcab8addSBrooks Davis 	}
1692fcab8addSBrooks Davis 
169347c08596SBrooks Davis 	/* Set up the option buffer... */
169447c08596SBrooks Davis 	ip->client->packet_length = cons_options(NULL, &ip->client->packet, 0,
169547c08596SBrooks Davis 	    options, 0, 0, 0, NULL, 0);
169647c08596SBrooks Davis 	if (ip->client->packet_length < BOOTP_MIN_LEN)
169747c08596SBrooks Davis 		ip->client->packet_length = BOOTP_MIN_LEN;
169847c08596SBrooks Davis 
169947c08596SBrooks Davis 	ip->client->packet.op = BOOTREQUEST;
170047c08596SBrooks Davis 	ip->client->packet.htype = ip->hw_address.htype;
170147c08596SBrooks Davis 	ip->client->packet.hlen = ip->hw_address.hlen;
170247c08596SBrooks Davis 	ip->client->packet.hops = 0;
170347c08596SBrooks Davis 	ip->client->packet.xid = arc4random();
170447c08596SBrooks Davis 	ip->client->packet.secs = 0; /* filled in by send_discover. */
170547c08596SBrooks Davis 	ip->client->packet.flags = 0;
170647c08596SBrooks Davis 
170747c08596SBrooks Davis 	memset(&(ip->client->packet.ciaddr),
170847c08596SBrooks Davis 	    0, sizeof(ip->client->packet.ciaddr));
170947c08596SBrooks Davis 	memset(&(ip->client->packet.yiaddr),
171047c08596SBrooks Davis 	    0, sizeof(ip->client->packet.yiaddr));
171147c08596SBrooks Davis 	memset(&(ip->client->packet.siaddr),
171247c08596SBrooks Davis 	    0, sizeof(ip->client->packet.siaddr));
171347c08596SBrooks Davis 	memset(&(ip->client->packet.giaddr),
171447c08596SBrooks Davis 	    0, sizeof(ip->client->packet.giaddr));
17154441bd73SConrad Meyer 	memcpy(ip->client->packet.chaddr,
17164441bd73SConrad Meyer 	    ip->hw_address.haddr, ip->hw_address.hlen);
171747c08596SBrooks Davis }
171847c08596SBrooks Davis 
171947c08596SBrooks Davis 
172047c08596SBrooks Davis void
172147c08596SBrooks Davis make_request(struct interface_info *ip, struct client_lease * lease)
172247c08596SBrooks Davis {
172347c08596SBrooks Davis 	unsigned char request = DHCPREQUEST;
172447c08596SBrooks Davis 	struct tree_cache *options[256];
172547c08596SBrooks Davis 	struct tree_cache option_elements[256];
172647c08596SBrooks Davis 	int i;
172747c08596SBrooks Davis 
172847c08596SBrooks Davis 	memset(options, 0, sizeof(options));
172947c08596SBrooks Davis 	memset(&ip->client->packet, 0, sizeof(ip->client->packet));
173047c08596SBrooks Davis 
173147c08596SBrooks Davis 	/* Set DHCP_MESSAGE_TYPE to DHCPREQUEST */
173247c08596SBrooks Davis 	i = DHO_DHCP_MESSAGE_TYPE;
173347c08596SBrooks Davis 	options[i] = &option_elements[i];
173447c08596SBrooks Davis 	options[i]->value = &request;
173547c08596SBrooks Davis 	options[i]->len = sizeof(request);
173647c08596SBrooks Davis 	options[i]->buf_size = sizeof(request);
173747c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
173847c08596SBrooks Davis 
173947c08596SBrooks Davis 	/* Request the options we want */
174047c08596SBrooks Davis 	i = DHO_DHCP_PARAMETER_REQUEST_LIST;
174147c08596SBrooks Davis 	options[i] = &option_elements[i];
174247c08596SBrooks Davis 	options[i]->value = ip->client->config->requested_options;
174347c08596SBrooks Davis 	options[i]->len = ip->client->config->requested_option_count;
174447c08596SBrooks Davis 	options[i]->buf_size =
174547c08596SBrooks Davis 		ip->client->config->requested_option_count;
174647c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
174747c08596SBrooks Davis 
174847c08596SBrooks Davis 	/* If we are requesting an address that hasn't yet been assigned
174947c08596SBrooks Davis 	   to us, use the DHCP Requested Address option. */
175047c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING) {
175147c08596SBrooks Davis 		/* Send back the server identifier... */
175247c08596SBrooks Davis 		i = DHO_DHCP_SERVER_IDENTIFIER;
175347c08596SBrooks Davis 		options[i] = &option_elements[i];
175447c08596SBrooks Davis 		options[i]->value = lease->options[i].data;
175547c08596SBrooks Davis 		options[i]->len = lease->options[i].len;
175647c08596SBrooks Davis 		options[i]->buf_size = lease->options[i].len;
175747c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
175847c08596SBrooks Davis 	}
175947c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING ||
176047c08596SBrooks Davis 	    ip->client->state == S_REBOOTING) {
176147c08596SBrooks Davis 		ip->client->requested_address = lease->address;
176247c08596SBrooks Davis 		i = DHO_DHCP_REQUESTED_ADDRESS;
176347c08596SBrooks Davis 		options[i] = &option_elements[i];
176447c08596SBrooks Davis 		options[i]->value = lease->address.iabuf;
176547c08596SBrooks Davis 		options[i]->len = lease->address.len;
176647c08596SBrooks Davis 		options[i]->buf_size = lease->address.len;
176747c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
176847c08596SBrooks Davis 	} else
176947c08596SBrooks Davis 		ip->client->requested_address.len = 0;
177047c08596SBrooks Davis 
177147c08596SBrooks Davis 	/* Send any options requested in the config file. */
177247c08596SBrooks Davis 	for (i = 0; i < 256; i++)
177347c08596SBrooks Davis 		if (!options[i] &&
177447c08596SBrooks Davis 		    ip->client->config->send_options[i].data) {
177547c08596SBrooks Davis 			options[i] = &option_elements[i];
177647c08596SBrooks Davis 			options[i]->value =
177747c08596SBrooks Davis 			    ip->client->config->send_options[i].data;
177847c08596SBrooks Davis 			options[i]->len =
177947c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
178047c08596SBrooks Davis 			options[i]->buf_size =
178147c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
178247c08596SBrooks Davis 			options[i]->timeout = 0xFFFFFFFF;
178347c08596SBrooks Davis 		}
178447c08596SBrooks Davis 
1785fcab8addSBrooks Davis 	/* send host name if not set via config file. */
1786fcab8addSBrooks Davis 	if (!options[DHO_HOST_NAME]) {
17870bbe8306SPawel Jakub Dawidek 		if (hostname[0] != '\0') {
1788fcab8addSBrooks Davis 			size_t len;
1789fcab8addSBrooks Davis 			char* posDot = strchr(hostname, '.');
1790fcab8addSBrooks Davis 			if (posDot != NULL)
1791fcab8addSBrooks Davis 				len = posDot - hostname;
1792fcab8addSBrooks Davis 			else
1793fcab8addSBrooks Davis 				len = strlen(hostname);
1794fcab8addSBrooks Davis 			options[DHO_HOST_NAME] = &option_elements[DHO_HOST_NAME];
1795fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->value = hostname;
1796fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->len = len;
1797fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->buf_size = len;
1798fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->timeout = 0xFFFFFFFF;
1799fcab8addSBrooks Davis 		}
1800fcab8addSBrooks Davis 	}
1801fcab8addSBrooks Davis 
1802fcab8addSBrooks Davis 	/* set unique client identifier */
180374aed808SConrad Meyer 	char client_ident[sizeof(ip->hw_address.haddr) + 1];
1804fcab8addSBrooks Davis 	if (!options[DHO_DHCP_CLIENT_IDENTIFIER]) {
1805fcab8addSBrooks Davis 		int hwlen = (ip->hw_address.hlen < sizeof(client_ident)-1) ?
1806fcab8addSBrooks Davis 				ip->hw_address.hlen : sizeof(client_ident)-1;
1807fcab8addSBrooks Davis 		client_ident[0] = ip->hw_address.htype;
1808fcab8addSBrooks Davis 		memcpy(&client_ident[1], ip->hw_address.haddr, hwlen);
1809fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER] = &option_elements[DHO_DHCP_CLIENT_IDENTIFIER];
1810fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->value = client_ident;
1811fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->len = hwlen+1;
1812fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->buf_size = hwlen+1;
1813fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->timeout = 0xFFFFFFFF;
1814fcab8addSBrooks Davis 	}
1815fcab8addSBrooks Davis 
181647c08596SBrooks Davis 	/* Set up the option buffer... */
181747c08596SBrooks Davis 	ip->client->packet_length = cons_options(NULL, &ip->client->packet, 0,
181847c08596SBrooks Davis 	    options, 0, 0, 0, NULL, 0);
181947c08596SBrooks Davis 	if (ip->client->packet_length < BOOTP_MIN_LEN)
182047c08596SBrooks Davis 		ip->client->packet_length = BOOTP_MIN_LEN;
182147c08596SBrooks Davis 
182247c08596SBrooks Davis 	ip->client->packet.op = BOOTREQUEST;
182347c08596SBrooks Davis 	ip->client->packet.htype = ip->hw_address.htype;
182447c08596SBrooks Davis 	ip->client->packet.hlen = ip->hw_address.hlen;
182547c08596SBrooks Davis 	ip->client->packet.hops = 0;
182647c08596SBrooks Davis 	ip->client->packet.xid = ip->client->xid;
182747c08596SBrooks Davis 	ip->client->packet.secs = 0; /* Filled in by send_request. */
182847c08596SBrooks Davis 
182947c08596SBrooks Davis 	/* If we own the address we're requesting, put it in ciaddr;
183047c08596SBrooks Davis 	   otherwise set ciaddr to zero. */
183147c08596SBrooks Davis 	if (ip->client->state == S_BOUND ||
183247c08596SBrooks Davis 	    ip->client->state == S_RENEWING ||
183347c08596SBrooks Davis 	    ip->client->state == S_REBINDING) {
183447c08596SBrooks Davis 		memcpy(&ip->client->packet.ciaddr,
183547c08596SBrooks Davis 		    lease->address.iabuf, lease->address.len);
183647c08596SBrooks Davis 		ip->client->packet.flags = 0;
183747c08596SBrooks Davis 	} else {
183847c08596SBrooks Davis 		memset(&ip->client->packet.ciaddr, 0,
183947c08596SBrooks Davis 		    sizeof(ip->client->packet.ciaddr));
184047c08596SBrooks Davis 		ip->client->packet.flags = 0;
184147c08596SBrooks Davis 	}
184247c08596SBrooks Davis 
184347c08596SBrooks Davis 	memset(&ip->client->packet.yiaddr, 0,
184447c08596SBrooks Davis 	    sizeof(ip->client->packet.yiaddr));
184547c08596SBrooks Davis 	memset(&ip->client->packet.siaddr, 0,
184647c08596SBrooks Davis 	    sizeof(ip->client->packet.siaddr));
184747c08596SBrooks Davis 	memset(&ip->client->packet.giaddr, 0,
184847c08596SBrooks Davis 	    sizeof(ip->client->packet.giaddr));
184947c08596SBrooks Davis 	memcpy(ip->client->packet.chaddr,
185047c08596SBrooks Davis 	    ip->hw_address.haddr, ip->hw_address.hlen);
185147c08596SBrooks Davis }
185247c08596SBrooks Davis 
185347c08596SBrooks Davis void
185447c08596SBrooks Davis make_decline(struct interface_info *ip, struct client_lease *lease)
185547c08596SBrooks Davis {
185647c08596SBrooks Davis 	struct tree_cache *options[256], message_type_tree;
185747c08596SBrooks Davis 	struct tree_cache requested_address_tree;
185847c08596SBrooks Davis 	struct tree_cache server_id_tree, client_id_tree;
185947c08596SBrooks Davis 	unsigned char decline = DHCPDECLINE;
186047c08596SBrooks Davis 	int i;
186147c08596SBrooks Davis 
186247c08596SBrooks Davis 	memset(options, 0, sizeof(options));
186347c08596SBrooks Davis 	memset(&ip->client->packet, 0, sizeof(ip->client->packet));
186447c08596SBrooks Davis 
186547c08596SBrooks Davis 	/* Set DHCP_MESSAGE_TYPE to DHCPDECLINE */
186647c08596SBrooks Davis 	i = DHO_DHCP_MESSAGE_TYPE;
186747c08596SBrooks Davis 	options[i] = &message_type_tree;
186847c08596SBrooks Davis 	options[i]->value = &decline;
186947c08596SBrooks Davis 	options[i]->len = sizeof(decline);
187047c08596SBrooks Davis 	options[i]->buf_size = sizeof(decline);
187147c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
187247c08596SBrooks Davis 
187347c08596SBrooks Davis 	/* Send back the server identifier... */
187447c08596SBrooks Davis 	i = DHO_DHCP_SERVER_IDENTIFIER;
187547c08596SBrooks Davis 	options[i] = &server_id_tree;
187647c08596SBrooks Davis 	options[i]->value = lease->options[i].data;
187747c08596SBrooks Davis 	options[i]->len = lease->options[i].len;
187847c08596SBrooks Davis 	options[i]->buf_size = lease->options[i].len;
187947c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
188047c08596SBrooks Davis 
188147c08596SBrooks Davis 	/* Send back the address we're declining. */
188247c08596SBrooks Davis 	i = DHO_DHCP_REQUESTED_ADDRESS;
188347c08596SBrooks Davis 	options[i] = &requested_address_tree;
188447c08596SBrooks Davis 	options[i]->value = lease->address.iabuf;
188547c08596SBrooks Davis 	options[i]->len = lease->address.len;
188647c08596SBrooks Davis 	options[i]->buf_size = lease->address.len;
188747c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
188847c08596SBrooks Davis 
188947c08596SBrooks Davis 	/* Send the uid if the user supplied one. */
189047c08596SBrooks Davis 	i = DHO_DHCP_CLIENT_IDENTIFIER;
189147c08596SBrooks Davis 	if (ip->client->config->send_options[i].len) {
189247c08596SBrooks Davis 		options[i] = &client_id_tree;
189347c08596SBrooks Davis 		options[i]->value = ip->client->config->send_options[i].data;
189447c08596SBrooks Davis 		options[i]->len = ip->client->config->send_options[i].len;
189547c08596SBrooks Davis 		options[i]->buf_size = ip->client->config->send_options[i].len;
189647c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
189747c08596SBrooks Davis 	}
189847c08596SBrooks Davis 
189947c08596SBrooks Davis 
190047c08596SBrooks Davis 	/* Set up the option buffer... */
190147c08596SBrooks Davis 	ip->client->packet_length = cons_options(NULL, &ip->client->packet, 0,
190247c08596SBrooks Davis 	    options, 0, 0, 0, NULL, 0);
190347c08596SBrooks Davis 	if (ip->client->packet_length < BOOTP_MIN_LEN)
190447c08596SBrooks Davis 		ip->client->packet_length = BOOTP_MIN_LEN;
190547c08596SBrooks Davis 
190647c08596SBrooks Davis 	ip->client->packet.op = BOOTREQUEST;
190747c08596SBrooks Davis 	ip->client->packet.htype = ip->hw_address.htype;
190847c08596SBrooks Davis 	ip->client->packet.hlen = ip->hw_address.hlen;
190947c08596SBrooks Davis 	ip->client->packet.hops = 0;
191047c08596SBrooks Davis 	ip->client->packet.xid = ip->client->xid;
191147c08596SBrooks Davis 	ip->client->packet.secs = 0; /* Filled in by send_request. */
191247c08596SBrooks Davis 	ip->client->packet.flags = 0;
191347c08596SBrooks Davis 
191447c08596SBrooks Davis 	/* ciaddr must always be zero. */
191547c08596SBrooks Davis 	memset(&ip->client->packet.ciaddr, 0,
191647c08596SBrooks Davis 	    sizeof(ip->client->packet.ciaddr));
191747c08596SBrooks Davis 	memset(&ip->client->packet.yiaddr, 0,
191847c08596SBrooks Davis 	    sizeof(ip->client->packet.yiaddr));
191947c08596SBrooks Davis 	memset(&ip->client->packet.siaddr, 0,
192047c08596SBrooks Davis 	    sizeof(ip->client->packet.siaddr));
192147c08596SBrooks Davis 	memset(&ip->client->packet.giaddr, 0,
192247c08596SBrooks Davis 	    sizeof(ip->client->packet.giaddr));
192347c08596SBrooks Davis 	memcpy(ip->client->packet.chaddr,
192447c08596SBrooks Davis 	    ip->hw_address.haddr, ip->hw_address.hlen);
192547c08596SBrooks Davis }
192647c08596SBrooks Davis 
192747c08596SBrooks Davis void
192847c08596SBrooks Davis free_client_lease(struct client_lease *lease)
192947c08596SBrooks Davis {
193047c08596SBrooks Davis 	int i;
193147c08596SBrooks Davis 
193247c08596SBrooks Davis 	if (lease->server_name)
193347c08596SBrooks Davis 		free(lease->server_name);
193447c08596SBrooks Davis 	if (lease->filename)
193547c08596SBrooks Davis 		free(lease->filename);
193647c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
193747c08596SBrooks Davis 		if (lease->options[i].len)
193847c08596SBrooks Davis 			free(lease->options[i].data);
193947c08596SBrooks Davis 	}
194047c08596SBrooks Davis 	free(lease);
194147c08596SBrooks Davis }
194247c08596SBrooks Davis 
194371c6c44dSEitan Adler static FILE *leaseFile;
194447c08596SBrooks Davis 
194547c08596SBrooks Davis void
194647c08596SBrooks Davis rewrite_client_leases(void)
194747c08596SBrooks Davis {
194847c08596SBrooks Davis 	struct client_lease *lp;
19497008be5bSPawel Jakub Dawidek 	cap_rights_t rights;
195047c08596SBrooks Davis 
195147c08596SBrooks Davis 	if (!leaseFile) {
195247c08596SBrooks Davis 		leaseFile = fopen(path_dhclient_db, "w");
195347c08596SBrooks Davis 		if (!leaseFile)
195447c08596SBrooks Davis 			error("can't create %s: %m", path_dhclient_db);
195519342eeeSPatrick Kelsey 		cap_rights_init(&rights, CAP_FCNTL, CAP_FSTAT, CAP_FSYNC,
195619342eeeSPatrick Kelsey 		    CAP_FTRUNCATE, CAP_SEEK, CAP_WRITE);
1957377421dfSMariusz Zaborski 		if (caph_rights_limit(fileno(leaseFile), &rights) < 0) {
1958fe5c7163SPawel Jakub Dawidek 			error("can't limit lease descriptor: %m");
1959fe5c7163SPawel Jakub Dawidek 		}
1960377421dfSMariusz Zaborski 		if (caph_fcntls_limit(fileno(leaseFile), CAP_FCNTL_GETFL) < 0) {
196119342eeeSPatrick Kelsey 			error("can't limit lease descriptor fcntls: %m");
196219342eeeSPatrick Kelsey 		}
196347c08596SBrooks Davis 	} else {
196447c08596SBrooks Davis 		fflush(leaseFile);
196547c08596SBrooks Davis 		rewind(leaseFile);
196647c08596SBrooks Davis 	}
196747c08596SBrooks Davis 
196847c08596SBrooks Davis 	for (lp = ifi->client->leases; lp; lp = lp->next)
196947c08596SBrooks Davis 		write_client_lease(ifi, lp, 1);
197047c08596SBrooks Davis 	if (ifi->client->active)
197147c08596SBrooks Davis 		write_client_lease(ifi, ifi->client->active, 1);
197247c08596SBrooks Davis 
197347c08596SBrooks Davis 	fflush(leaseFile);
197447c08596SBrooks Davis 	ftruncate(fileno(leaseFile), ftello(leaseFile));
197547c08596SBrooks Davis 	fsync(fileno(leaseFile));
197647c08596SBrooks Davis }
197747c08596SBrooks Davis 
197847c08596SBrooks Davis void
197947c08596SBrooks Davis write_client_lease(struct interface_info *ip, struct client_lease *lease,
198047c08596SBrooks Davis     int rewrite)
198147c08596SBrooks Davis {
198247c08596SBrooks Davis 	static int leases_written;
198347c08596SBrooks Davis 	struct tm *t;
198447c08596SBrooks Davis 	int i;
198547c08596SBrooks Davis 
198647c08596SBrooks Davis 	if (!rewrite) {
198747c08596SBrooks Davis 		if (leases_written++ > 20) {
198847c08596SBrooks Davis 			rewrite_client_leases();
198947c08596SBrooks Davis 			leases_written = 0;
199047c08596SBrooks Davis 		}
199147c08596SBrooks Davis 	}
199247c08596SBrooks Davis 
199347c08596SBrooks Davis 	/* If the lease came from the config file, we don't need to stash
199447c08596SBrooks Davis 	   a copy in the lease database. */
199547c08596SBrooks Davis 	if (lease->is_static)
199647c08596SBrooks Davis 		return;
199747c08596SBrooks Davis 
199847c08596SBrooks Davis 	if (!leaseFile) {	/* XXX */
199947c08596SBrooks Davis 		leaseFile = fopen(path_dhclient_db, "w");
200047c08596SBrooks Davis 		if (!leaseFile)
200147c08596SBrooks Davis 			error("can't create %s: %m", path_dhclient_db);
200247c08596SBrooks Davis 	}
200347c08596SBrooks Davis 
200447c08596SBrooks Davis 	fprintf(leaseFile, "lease {\n");
200547c08596SBrooks Davis 	if (lease->is_bootp)
200647c08596SBrooks Davis 		fprintf(leaseFile, "  bootp;\n");
200747c08596SBrooks Davis 	fprintf(leaseFile, "  interface \"%s\";\n", ip->name);
200847c08596SBrooks Davis 	fprintf(leaseFile, "  fixed-address %s;\n", piaddr(lease->address));
2009d32438c3SBruce M Simpson 	if (lease->nextserver.len == sizeof(inaddr_any) &&
2010d32438c3SBruce M Simpson 	    0 != memcmp(lease->nextserver.iabuf, &inaddr_any,
2011d32438c3SBruce M Simpson 	    sizeof(inaddr_any)))
2012d32438c3SBruce M Simpson 		fprintf(leaseFile, "  next-server %s;\n",
2013d32438c3SBruce M Simpson 		    piaddr(lease->nextserver));
201447c08596SBrooks Davis 	if (lease->filename)
201547c08596SBrooks Davis 		fprintf(leaseFile, "  filename \"%s\";\n", lease->filename);
201647c08596SBrooks Davis 	if (lease->server_name)
201747c08596SBrooks Davis 		fprintf(leaseFile, "  server-name \"%s\";\n",
201847c08596SBrooks Davis 		    lease->server_name);
201947c08596SBrooks Davis 	if (lease->medium)
202047c08596SBrooks Davis 		fprintf(leaseFile, "  medium \"%s\";\n", lease->medium->string);
202147c08596SBrooks Davis 	for (i = 0; i < 256; i++)
202247c08596SBrooks Davis 		if (lease->options[i].len)
202347c08596SBrooks Davis 			fprintf(leaseFile, "  option %s %s;\n",
202447c08596SBrooks Davis 			    dhcp_options[i].name,
202547c08596SBrooks Davis 			    pretty_print_option(i, lease->options[i].data,
202647c08596SBrooks Davis 			    lease->options[i].len, 1, 1));
202747c08596SBrooks Davis 
202847c08596SBrooks Davis 	t = gmtime(&lease->renewal);
202947c08596SBrooks Davis 	fprintf(leaseFile, "  renew %d %d/%d/%d %02d:%02d:%02d;\n",
203047c08596SBrooks Davis 	    t->tm_wday, t->tm_year + 1900, t->tm_mon + 1, t->tm_mday,
203147c08596SBrooks Davis 	    t->tm_hour, t->tm_min, t->tm_sec);
203247c08596SBrooks Davis 	t = gmtime(&lease->rebind);
203347c08596SBrooks Davis 	fprintf(leaseFile, "  rebind %d %d/%d/%d %02d:%02d:%02d;\n",
203447c08596SBrooks Davis 	    t->tm_wday, t->tm_year + 1900, t->tm_mon + 1, t->tm_mday,
203547c08596SBrooks Davis 	    t->tm_hour, t->tm_min, t->tm_sec);
203647c08596SBrooks Davis 	t = gmtime(&lease->expiry);
203747c08596SBrooks Davis 	fprintf(leaseFile, "  expire %d %d/%d/%d %02d:%02d:%02d;\n",
203847c08596SBrooks Davis 	    t->tm_wday, t->tm_year + 1900, t->tm_mon + 1, t->tm_mday,
203947c08596SBrooks Davis 	    t->tm_hour, t->tm_min, t->tm_sec);
204047c08596SBrooks Davis 	fprintf(leaseFile, "}\n");
204147c08596SBrooks Davis 	fflush(leaseFile);
204247c08596SBrooks Davis }
204347c08596SBrooks Davis 
204447c08596SBrooks Davis void
204579a1d195SAlan Somers script_init(const char *reason, struct string_list *medium)
204647c08596SBrooks Davis {
204747c08596SBrooks Davis 	size_t		 len, mediumlen = 0;
204847c08596SBrooks Davis 	struct imsg_hdr	 hdr;
204947c08596SBrooks Davis 	struct buf	*buf;
205047c08596SBrooks Davis 	int		 errs;
205147c08596SBrooks Davis 
205247c08596SBrooks Davis 	if (medium != NULL && medium->string != NULL)
205347c08596SBrooks Davis 		mediumlen = strlen(medium->string);
205447c08596SBrooks Davis 
205547c08596SBrooks Davis 	hdr.code = IMSG_SCRIPT_INIT;
205647c08596SBrooks Davis 	hdr.len = sizeof(struct imsg_hdr) +
205747c08596SBrooks Davis 	    sizeof(size_t) + mediumlen +
205847c08596SBrooks Davis 	    sizeof(size_t) + strlen(reason);
205947c08596SBrooks Davis 
206047c08596SBrooks Davis 	if ((buf = buf_open(hdr.len)) == NULL)
206147c08596SBrooks Davis 		error("buf_open: %m");
206247c08596SBrooks Davis 
206347c08596SBrooks Davis 	errs = 0;
206447c08596SBrooks Davis 	errs += buf_add(buf, &hdr, sizeof(hdr));
206547c08596SBrooks Davis 	errs += buf_add(buf, &mediumlen, sizeof(mediumlen));
206647c08596SBrooks Davis 	if (mediumlen > 0)
206747c08596SBrooks Davis 		errs += buf_add(buf, medium->string, mediumlen);
206847c08596SBrooks Davis 	len = strlen(reason);
206947c08596SBrooks Davis 	errs += buf_add(buf, &len, sizeof(len));
207047c08596SBrooks Davis 	errs += buf_add(buf, reason, len);
207147c08596SBrooks Davis 
207247c08596SBrooks Davis 	if (errs)
207347c08596SBrooks Davis 		error("buf_add: %m");
207447c08596SBrooks Davis 
207547c08596SBrooks Davis 	if (buf_close(privfd, buf) == -1)
207647c08596SBrooks Davis 		error("buf_close: %m");
207747c08596SBrooks Davis }
207847c08596SBrooks Davis 
207947c08596SBrooks Davis void
208079a1d195SAlan Somers priv_script_init(const char *reason, char *medium)
208147c08596SBrooks Davis {
208247c08596SBrooks Davis 	struct interface_info *ip = ifi;
208347c08596SBrooks Davis 
208447c08596SBrooks Davis 	if (ip) {
208547c08596SBrooks Davis 		ip->client->scriptEnvsize = 100;
208647c08596SBrooks Davis 		if (ip->client->scriptEnv == NULL)
208747c08596SBrooks Davis 			ip->client->scriptEnv =
208847c08596SBrooks Davis 			    malloc(ip->client->scriptEnvsize * sizeof(char *));
208947c08596SBrooks Davis 		if (ip->client->scriptEnv == NULL)
209047c08596SBrooks Davis 			error("script_init: no memory for environment");
209147c08596SBrooks Davis 
209247c08596SBrooks Davis 		ip->client->scriptEnv[0] = strdup(CLIENT_PATH);
209347c08596SBrooks Davis 		if (ip->client->scriptEnv[0] == NULL)
209447c08596SBrooks Davis 			error("script_init: no memory for environment");
209547c08596SBrooks Davis 
209647c08596SBrooks Davis 		ip->client->scriptEnv[1] = NULL;
209747c08596SBrooks Davis 
209847c08596SBrooks Davis 		script_set_env(ip->client, "", "interface", ip->name);
209947c08596SBrooks Davis 
210047c08596SBrooks Davis 		if (medium)
210147c08596SBrooks Davis 			script_set_env(ip->client, "", "medium", medium);
210247c08596SBrooks Davis 
210347c08596SBrooks Davis 		script_set_env(ip->client, "", "reason", reason);
210447c08596SBrooks Davis 	}
210547c08596SBrooks Davis }
210647c08596SBrooks Davis 
210747c08596SBrooks Davis void
210879a1d195SAlan Somers priv_script_write_params(const char *prefix, struct client_lease *lease)
210947c08596SBrooks Davis {
211047c08596SBrooks Davis 	struct interface_info *ip = ifi;
211140767e22SBrooks Davis 	u_int8_t dbuf[1500], *dp = NULL;
2112afe6f835SAlan Somers 	int i;
2113afe6f835SAlan Somers 	size_t len;
211447c08596SBrooks Davis 	char tbuf[128];
211547c08596SBrooks Davis 
211647c08596SBrooks Davis 	script_set_env(ip->client, prefix, "ip_address",
211747c08596SBrooks Davis 	    piaddr(lease->address));
211847c08596SBrooks Davis 
211940767e22SBrooks Davis 	if (ip->client->config->default_actions[DHO_SUBNET_MASK] ==
212040767e22SBrooks Davis 	    ACTION_SUPERSEDE) {
212140767e22SBrooks Davis 		dp = ip->client->config->defaults[DHO_SUBNET_MASK].data;
212240767e22SBrooks Davis 		len = ip->client->config->defaults[DHO_SUBNET_MASK].len;
212340767e22SBrooks Davis 	} else {
212440767e22SBrooks Davis 		dp = lease->options[DHO_SUBNET_MASK].data;
212540767e22SBrooks Davis 		len = lease->options[DHO_SUBNET_MASK].len;
212640767e22SBrooks Davis 	}
212740767e22SBrooks Davis 	if (len && (len < sizeof(lease->address.iabuf))) {
212847c08596SBrooks Davis 		struct iaddr netmask, subnet, broadcast;
212947c08596SBrooks Davis 
213040767e22SBrooks Davis 		memcpy(netmask.iabuf, dp, len);
213140767e22SBrooks Davis 		netmask.len = len;
213247c08596SBrooks Davis 		subnet = subnet_number(lease->address, netmask);
213347c08596SBrooks Davis 		if (subnet.len) {
213447c08596SBrooks Davis 			script_set_env(ip->client, prefix, "network_number",
213547c08596SBrooks Davis 			    piaddr(subnet));
213647c08596SBrooks Davis 			if (!lease->options[DHO_BROADCAST_ADDRESS].len) {
213747c08596SBrooks Davis 				broadcast = broadcast_addr(subnet, netmask);
213847c08596SBrooks Davis 				if (broadcast.len)
213947c08596SBrooks Davis 					script_set_env(ip->client, prefix,
214047c08596SBrooks Davis 					    "broadcast_address",
214147c08596SBrooks Davis 					    piaddr(broadcast));
214247c08596SBrooks Davis 			}
214347c08596SBrooks Davis 		}
214447c08596SBrooks Davis 	}
214547c08596SBrooks Davis 
214647c08596SBrooks Davis 	if (lease->filename)
214747c08596SBrooks Davis 		script_set_env(ip->client, prefix, "filename", lease->filename);
214847c08596SBrooks Davis 	if (lease->server_name)
214947c08596SBrooks Davis 		script_set_env(ip->client, prefix, "server_name",
215047c08596SBrooks Davis 		    lease->server_name);
215147c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
215240767e22SBrooks Davis 		len = 0;
215347c08596SBrooks Davis 
215447c08596SBrooks Davis 		if (ip->client->config->defaults[i].len) {
215547c08596SBrooks Davis 			if (lease->options[i].len) {
215647c08596SBrooks Davis 				switch (
215747c08596SBrooks Davis 				    ip->client->config->default_actions[i]) {
215847c08596SBrooks Davis 				case ACTION_DEFAULT:
215947c08596SBrooks Davis 					dp = lease->options[i].data;
216047c08596SBrooks Davis 					len = lease->options[i].len;
216147c08596SBrooks Davis 					break;
216247c08596SBrooks Davis 				case ACTION_SUPERSEDE:
216347c08596SBrooks Davis supersede:
216447c08596SBrooks Davis 					dp = ip->client->
216547c08596SBrooks Davis 						config->defaults[i].data;
216647c08596SBrooks Davis 					len = ip->client->
216747c08596SBrooks Davis 						config->defaults[i].len;
216847c08596SBrooks Davis 					break;
216947c08596SBrooks Davis 				case ACTION_PREPEND:
217047c08596SBrooks Davis 					len = ip->client->
217147c08596SBrooks Davis 					    config->defaults[i].len +
217247c08596SBrooks Davis 					    lease->options[i].len;
2173043bcc8dSBrian Somers 					if (len >= sizeof(dbuf)) {
217447c08596SBrooks Davis 						warning("no space to %s %s",
217547c08596SBrooks Davis 						    "prepend option",
217647c08596SBrooks Davis 						    dhcp_options[i].name);
217747c08596SBrooks Davis 						goto supersede;
217847c08596SBrooks Davis 					}
217947c08596SBrooks Davis 					dp = dbuf;
218047c08596SBrooks Davis 					memcpy(dp,
218147c08596SBrooks Davis 						ip->client->
218247c08596SBrooks Davis 						config->defaults[i].data,
218347c08596SBrooks Davis 						ip->client->
218447c08596SBrooks Davis 						config->defaults[i].len);
218547c08596SBrooks Davis 					memcpy(dp + ip->client->
218647c08596SBrooks Davis 						config->defaults[i].len,
218747c08596SBrooks Davis 						lease->options[i].data,
218847c08596SBrooks Davis 						lease->options[i].len);
218947c08596SBrooks Davis 					dp[len] = '\0';
219047c08596SBrooks Davis 					break;
219147c08596SBrooks Davis 				case ACTION_APPEND:
2192043bcc8dSBrian Somers 					/*
2193043bcc8dSBrian Somers 					 * When we append, we assume that we're
2194043bcc8dSBrian Somers 					 * appending to text.  Some MS servers
2195043bcc8dSBrian Somers 					 * include a NUL byte at the end of
2196043bcc8dSBrian Somers 					 * the search string provided.
2197043bcc8dSBrian Somers 					 */
219847c08596SBrooks Davis 					len = ip->client->
219947c08596SBrooks Davis 					    config->defaults[i].len +
220047c08596SBrooks Davis 					    lease->options[i].len;
2201043bcc8dSBrian Somers 					if (len >= sizeof(dbuf)) {
220247c08596SBrooks Davis 						warning("no space to %s %s",
220347c08596SBrooks Davis 						    "append option",
220447c08596SBrooks Davis 						    dhcp_options[i].name);
220547c08596SBrooks Davis 						goto supersede;
220647c08596SBrooks Davis 					}
2207043bcc8dSBrian Somers 					memcpy(dbuf,
220847c08596SBrooks Davis 						lease->options[i].data,
220947c08596SBrooks Davis 						lease->options[i].len);
2210043bcc8dSBrian Somers 					for (dp = dbuf + lease->options[i].len;
2211043bcc8dSBrian Somers 					    dp > dbuf; dp--, len--)
2212043bcc8dSBrian Somers 						if (dp[-1] != '\0')
2213043bcc8dSBrian Somers 							break;
2214043bcc8dSBrian Somers 					memcpy(dp,
221547c08596SBrooks Davis 						ip->client->
221647c08596SBrooks Davis 						config->defaults[i].data,
221747c08596SBrooks Davis 						ip->client->
221847c08596SBrooks Davis 						config->defaults[i].len);
2219043bcc8dSBrian Somers 					dp = dbuf;
222047c08596SBrooks Davis 					dp[len] = '\0';
222147c08596SBrooks Davis 				}
222247c08596SBrooks Davis 			} else {
222347c08596SBrooks Davis 				dp = ip->client->
222447c08596SBrooks Davis 					config->defaults[i].data;
222547c08596SBrooks Davis 				len = ip->client->
222647c08596SBrooks Davis 					config->defaults[i].len;
222747c08596SBrooks Davis 			}
222847c08596SBrooks Davis 		} else if (lease->options[i].len) {
222947c08596SBrooks Davis 			len = lease->options[i].len;
223047c08596SBrooks Davis 			dp = lease->options[i].data;
223147c08596SBrooks Davis 		} else {
223247c08596SBrooks Davis 			len = 0;
223347c08596SBrooks Davis 		}
223447c08596SBrooks Davis 		if (len) {
223547c08596SBrooks Davis 			char name[256];
223647c08596SBrooks Davis 
223747c08596SBrooks Davis 			if (dhcp_option_ev_name(name, sizeof(name),
223847c08596SBrooks Davis 			    &dhcp_options[i]))
223947c08596SBrooks Davis 				script_set_env(ip->client, prefix, name,
224047c08596SBrooks Davis 				    pretty_print_option(i, dp, len, 0, 0));
224147c08596SBrooks Davis 		}
224247c08596SBrooks Davis 	}
224347c08596SBrooks Davis 	snprintf(tbuf, sizeof(tbuf), "%d", (int)lease->expiry);
224447c08596SBrooks Davis 	script_set_env(ip->client, prefix, "expiry", tbuf);
224547c08596SBrooks Davis }
224647c08596SBrooks Davis 
224747c08596SBrooks Davis void
224879a1d195SAlan Somers script_write_params(const char *prefix, struct client_lease *lease)
224947c08596SBrooks Davis {
225047c08596SBrooks Davis 	size_t		 fn_len = 0, sn_len = 0, pr_len = 0;
225147c08596SBrooks Davis 	struct imsg_hdr	 hdr;
225247c08596SBrooks Davis 	struct buf	*buf;
225347c08596SBrooks Davis 	int		 errs, i;
225447c08596SBrooks Davis 
225547c08596SBrooks Davis 	if (lease->filename != NULL)
225647c08596SBrooks Davis 		fn_len = strlen(lease->filename);
225747c08596SBrooks Davis 	if (lease->server_name != NULL)
225847c08596SBrooks Davis 		sn_len = strlen(lease->server_name);
225947c08596SBrooks Davis 	if (prefix != NULL)
226047c08596SBrooks Davis 		pr_len = strlen(prefix);
226147c08596SBrooks Davis 
226247c08596SBrooks Davis 	hdr.code = IMSG_SCRIPT_WRITE_PARAMS;
2263afe6f835SAlan Somers 	hdr.len = sizeof(hdr) + sizeof(*lease) +
2264afe6f835SAlan Somers 	    sizeof(fn_len) + fn_len + sizeof(sn_len) + sn_len +
2265afe6f835SAlan Somers 	    sizeof(pr_len) + pr_len;
226647c08596SBrooks Davis 
2267afe6f835SAlan Somers 	for (i = 0; i < 256; i++) {
2268afe6f835SAlan Somers 		hdr.len += sizeof(lease->options[i].len);
2269afe6f835SAlan Somers 		hdr.len += lease->options[i].len;
2270afe6f835SAlan Somers 	}
227147c08596SBrooks Davis 
227247c08596SBrooks Davis 	scripttime = time(NULL);
227347c08596SBrooks Davis 
227447c08596SBrooks Davis 	if ((buf = buf_open(hdr.len)) == NULL)
227547c08596SBrooks Davis 		error("buf_open: %m");
227647c08596SBrooks Davis 
227747c08596SBrooks Davis 	errs = 0;
227847c08596SBrooks Davis 	errs += buf_add(buf, &hdr, sizeof(hdr));
2279afe6f835SAlan Somers 	errs += buf_add(buf, lease, sizeof(*lease));
228047c08596SBrooks Davis 	errs += buf_add(buf, &fn_len, sizeof(fn_len));
228147c08596SBrooks Davis 	errs += buf_add(buf, lease->filename, fn_len);
228247c08596SBrooks Davis 	errs += buf_add(buf, &sn_len, sizeof(sn_len));
228347c08596SBrooks Davis 	errs += buf_add(buf, lease->server_name, sn_len);
228447c08596SBrooks Davis 	errs += buf_add(buf, &pr_len, sizeof(pr_len));
228547c08596SBrooks Davis 	errs += buf_add(buf, prefix, pr_len);
228647c08596SBrooks Davis 
228747c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
228847c08596SBrooks Davis 		errs += buf_add(buf, &lease->options[i].len,
228947c08596SBrooks Davis 		    sizeof(lease->options[i].len));
229047c08596SBrooks Davis 		errs += buf_add(buf, lease->options[i].data,
229147c08596SBrooks Davis 		    lease->options[i].len);
229247c08596SBrooks Davis 	}
229347c08596SBrooks Davis 
229447c08596SBrooks Davis 	if (errs)
229547c08596SBrooks Davis 		error("buf_add: %m");
229647c08596SBrooks Davis 
229747c08596SBrooks Davis 	if (buf_close(privfd, buf) == -1)
229847c08596SBrooks Davis 		error("buf_close: %m");
229947c08596SBrooks Davis }
230047c08596SBrooks Davis 
230147c08596SBrooks Davis int
230247c08596SBrooks Davis script_go(void)
230347c08596SBrooks Davis {
230447c08596SBrooks Davis 	struct imsg_hdr	 hdr;
230547c08596SBrooks Davis 	struct buf	*buf;
230647c08596SBrooks Davis 	int		 ret;
230747c08596SBrooks Davis 
230847c08596SBrooks Davis 	hdr.code = IMSG_SCRIPT_GO;
230947c08596SBrooks Davis 	hdr.len = sizeof(struct imsg_hdr);
231047c08596SBrooks Davis 
231147c08596SBrooks Davis 	if ((buf = buf_open(hdr.len)) == NULL)
231247c08596SBrooks Davis 		error("buf_open: %m");
231347c08596SBrooks Davis 
231447c08596SBrooks Davis 	if (buf_add(buf, &hdr, sizeof(hdr)))
231547c08596SBrooks Davis 		error("buf_add: %m");
231647c08596SBrooks Davis 
231747c08596SBrooks Davis 	if (buf_close(privfd, buf) == -1)
231847c08596SBrooks Davis 		error("buf_close: %m");
231947c08596SBrooks Davis 
232047c08596SBrooks Davis 	bzero(&hdr, sizeof(hdr));
232147c08596SBrooks Davis 	buf_read(privfd, &hdr, sizeof(hdr));
232247c08596SBrooks Davis 	if (hdr.code != IMSG_SCRIPT_GO_RET)
232347c08596SBrooks Davis 		error("unexpected msg type %u", hdr.code);
232447c08596SBrooks Davis 	if (hdr.len != sizeof(hdr) + sizeof(int))
232547c08596SBrooks Davis 		error("received corrupted message");
232647c08596SBrooks Davis 	buf_read(privfd, &ret, sizeof(ret));
232747c08596SBrooks Davis 
23286964abefSBrian Somers 	scripttime = time(NULL);
23296964abefSBrian Somers 
233047c08596SBrooks Davis 	return (ret);
233147c08596SBrooks Davis }
233247c08596SBrooks Davis 
233347c08596SBrooks Davis int
233447c08596SBrooks Davis priv_script_go(void)
233547c08596SBrooks Davis {
233647c08596SBrooks Davis 	char *scriptName, *argv[2], **envp, *epp[3], reason[] = "REASON=NBI";
233747c08596SBrooks Davis 	static char client_path[] = CLIENT_PATH;
233847c08596SBrooks Davis 	struct interface_info *ip = ifi;
233947c08596SBrooks Davis 	int pid, wpid, wstatus;
234047c08596SBrooks Davis 
234147c08596SBrooks Davis 	scripttime = time(NULL);
234247c08596SBrooks Davis 
234347c08596SBrooks Davis 	if (ip) {
234447c08596SBrooks Davis 		scriptName = ip->client->config->script_name;
234547c08596SBrooks Davis 		envp = ip->client->scriptEnv;
234647c08596SBrooks Davis 	} else {
234747c08596SBrooks Davis 		scriptName = top_level_config.script_name;
234847c08596SBrooks Davis 		epp[0] = reason;
234947c08596SBrooks Davis 		epp[1] = client_path;
235047c08596SBrooks Davis 		epp[2] = NULL;
235147c08596SBrooks Davis 		envp = epp;
235247c08596SBrooks Davis 	}
235347c08596SBrooks Davis 
235447c08596SBrooks Davis 	argv[0] = scriptName;
235547c08596SBrooks Davis 	argv[1] = NULL;
235647c08596SBrooks Davis 
235747c08596SBrooks Davis 	pid = fork();
235847c08596SBrooks Davis 	if (pid < 0) {
235947c08596SBrooks Davis 		error("fork: %m");
236047c08596SBrooks Davis 		wstatus = 0;
236147c08596SBrooks Davis 	} else if (pid) {
236247c08596SBrooks Davis 		do {
236347c08596SBrooks Davis 			wpid = wait(&wstatus);
236447c08596SBrooks Davis 		} while (wpid != pid && wpid > 0);
236547c08596SBrooks Davis 		if (wpid < 0) {
236647c08596SBrooks Davis 			error("wait: %m");
236747c08596SBrooks Davis 			wstatus = 0;
236847c08596SBrooks Davis 		}
236947c08596SBrooks Davis 	} else {
237047c08596SBrooks Davis 		execve(scriptName, argv, envp);
237147c08596SBrooks Davis 		error("execve (%s, ...): %m", scriptName);
237247c08596SBrooks Davis 	}
237347c08596SBrooks Davis 
237447c08596SBrooks Davis 	if (ip)
237547c08596SBrooks Davis 		script_flush_env(ip->client);
237647c08596SBrooks Davis 
23773b08e0fcSJilles Tjoelker 	return (WIFEXITED(wstatus) ?
23783b08e0fcSJilles Tjoelker 	    WEXITSTATUS(wstatus) : 128 + WTERMSIG(wstatus));
237947c08596SBrooks Davis }
238047c08596SBrooks Davis 
238147c08596SBrooks Davis void
238247c08596SBrooks Davis script_set_env(struct client_state *client, const char *prefix,
238347c08596SBrooks Davis     const char *name, const char *value)
238447c08596SBrooks Davis {
2385afe6f835SAlan Somers 	int i, namelen;
2386afe6f835SAlan Somers 	size_t j;
238747c08596SBrooks Davis 
2388dd09ce39SSepherosa Ziehau 	/* No `` or $() command substitution allowed in environment values! */
2389dd09ce39SSepherosa Ziehau 	for (j=0; j < strlen(value); j++)
2390dd09ce39SSepherosa Ziehau 		switch (value[j]) {
2391dd09ce39SSepherosa Ziehau 		case '`':
2392dd09ce39SSepherosa Ziehau 		case '$':
2393dd09ce39SSepherosa Ziehau 			warning("illegal character (%c) in value '%s'",
2394dd09ce39SSepherosa Ziehau 			    value[j], value);
2395dd09ce39SSepherosa Ziehau 			/* Ignore this option */
2396dd09ce39SSepherosa Ziehau 			return;
2397dd09ce39SSepherosa Ziehau 		}
2398dd09ce39SSepherosa Ziehau 
239947c08596SBrooks Davis 	namelen = strlen(name);
240047c08596SBrooks Davis 
240147c08596SBrooks Davis 	for (i = 0; client->scriptEnv[i]; i++)
240247c08596SBrooks Davis 		if (strncmp(client->scriptEnv[i], name, namelen) == 0 &&
240347c08596SBrooks Davis 		    client->scriptEnv[i][namelen] == '=')
240447c08596SBrooks Davis 			break;
240547c08596SBrooks Davis 
240647c08596SBrooks Davis 	if (client->scriptEnv[i])
240747c08596SBrooks Davis 		/* Reuse the slot. */
240847c08596SBrooks Davis 		free(client->scriptEnv[i]);
240947c08596SBrooks Davis 	else {
241047c08596SBrooks Davis 		/* New variable.  Expand if necessary. */
241147c08596SBrooks Davis 		if (i >= client->scriptEnvsize - 1) {
241247c08596SBrooks Davis 			char **newscriptEnv;
241347c08596SBrooks Davis 			int newscriptEnvsize = client->scriptEnvsize + 50;
241447c08596SBrooks Davis 
241547c08596SBrooks Davis 			newscriptEnv = realloc(client->scriptEnv,
241647c08596SBrooks Davis 			    newscriptEnvsize);
241747c08596SBrooks Davis 			if (newscriptEnv == NULL) {
241847c08596SBrooks Davis 				free(client->scriptEnv);
241947c08596SBrooks Davis 				client->scriptEnv = NULL;
242047c08596SBrooks Davis 				client->scriptEnvsize = 0;
242147c08596SBrooks Davis 				error("script_set_env: no memory for variable");
242247c08596SBrooks Davis 			}
242347c08596SBrooks Davis 			client->scriptEnv = newscriptEnv;
242447c08596SBrooks Davis 			client->scriptEnvsize = newscriptEnvsize;
242547c08596SBrooks Davis 		}
242647c08596SBrooks Davis 		/* need to set the NULL pointer at end of array beyond
242747c08596SBrooks Davis 		   the new slot. */
242847c08596SBrooks Davis 		client->scriptEnv[i + 1] = NULL;
242947c08596SBrooks Davis 	}
243047c08596SBrooks Davis 	/* Allocate space and format the variable in the appropriate slot. */
243147c08596SBrooks Davis 	client->scriptEnv[i] = malloc(strlen(prefix) + strlen(name) + 1 +
243247c08596SBrooks Davis 	    strlen(value) + 1);
243347c08596SBrooks Davis 	if (client->scriptEnv[i] == NULL)
243447c08596SBrooks Davis 		error("script_set_env: no memory for variable assignment");
243547c08596SBrooks Davis 	snprintf(client->scriptEnv[i], strlen(prefix) + strlen(name) +
243647c08596SBrooks Davis 	    1 + strlen(value) + 1, "%s%s=%s", prefix, name, value);
243747c08596SBrooks Davis }
243847c08596SBrooks Davis 
243947c08596SBrooks Davis void
244047c08596SBrooks Davis script_flush_env(struct client_state *client)
244147c08596SBrooks Davis {
244247c08596SBrooks Davis 	int i;
244347c08596SBrooks Davis 
244447c08596SBrooks Davis 	for (i = 0; client->scriptEnv[i]; i++) {
244547c08596SBrooks Davis 		free(client->scriptEnv[i]);
244647c08596SBrooks Davis 		client->scriptEnv[i] = NULL;
244747c08596SBrooks Davis 	}
244847c08596SBrooks Davis 	client->scriptEnvsize = 0;
244947c08596SBrooks Davis }
245047c08596SBrooks Davis 
245147c08596SBrooks Davis int
245247c08596SBrooks Davis dhcp_option_ev_name(char *buf, size_t buflen, struct option *option)
245347c08596SBrooks Davis {
2454afe6f835SAlan Somers 	size_t i;
245547c08596SBrooks Davis 
245647c08596SBrooks Davis 	for (i = 0; option->name[i]; i++) {
245747c08596SBrooks Davis 		if (i + 1 == buflen)
245847c08596SBrooks Davis 			return 0;
245947c08596SBrooks Davis 		if (option->name[i] == '-')
246047c08596SBrooks Davis 			buf[i] = '_';
246147c08596SBrooks Davis 		else
246247c08596SBrooks Davis 			buf[i] = option->name[i];
246347c08596SBrooks Davis 	}
246447c08596SBrooks Davis 
246547c08596SBrooks Davis 	buf[i] = 0;
246647c08596SBrooks Davis 	return 1;
246747c08596SBrooks Davis }
246847c08596SBrooks Davis 
246947c08596SBrooks Davis void
247047c08596SBrooks Davis go_daemon(void)
247147c08596SBrooks Davis {
247247c08596SBrooks Davis 	static int state = 0;
24737008be5bSPawel Jakub Dawidek 	cap_rights_t rights;
247447c08596SBrooks Davis 
247547c08596SBrooks Davis 	if (no_daemon || state)
247647c08596SBrooks Davis 		return;
247747c08596SBrooks Davis 
247847c08596SBrooks Davis 	state = 1;
247947c08596SBrooks Davis 
248047c08596SBrooks Davis 	/* Stop logging to stderr... */
248147c08596SBrooks Davis 	log_perror = 0;
248247c08596SBrooks Davis 
248331698405SMariusz Zaborski 	if (daemonfd(-1, nullfd) == -1)
248447c08596SBrooks Davis 		error("daemon");
248547c08596SBrooks Davis 
24867008be5bSPawel Jakub Dawidek 	cap_rights_init(&rights);
24877008be5bSPawel Jakub Dawidek 
2488377421dfSMariusz Zaborski 	if (pidfile != NULL) {
248923f39c90SDag-Erling Smørgrav 		pidfile_write(pidfile);
249023f39c90SDag-Erling Smørgrav 
2491377421dfSMariusz Zaborski 		if (caph_rights_limit(pidfile_fileno(pidfile), &rights) < 0)
2492377421dfSMariusz Zaborski 			error("can't limit pidfile descriptor: %m");
2493377421dfSMariusz Zaborski 	}
2494377421dfSMariusz Zaborski 
249547c08596SBrooks Davis 	if (nullfd != -1) {
249647c08596SBrooks Davis 		close(nullfd);
249747c08596SBrooks Davis 		nullfd = -1;
249847c08596SBrooks Davis 	}
2499a6f38228SPawel Jakub Dawidek 
2500377421dfSMariusz Zaborski 	if (caph_rights_limit(STDIN_FILENO, &rights) < 0)
2501a6f38228SPawel Jakub Dawidek 		error("can't limit stdin: %m");
25027008be5bSPawel Jakub Dawidek 	cap_rights_init(&rights, CAP_WRITE);
2503377421dfSMariusz Zaborski 	if (caph_rights_limit(STDOUT_FILENO, &rights) < 0)
2504a6f38228SPawel Jakub Dawidek 		error("can't limit stdout: %m");
2505377421dfSMariusz Zaborski 	if (caph_rights_limit(STDERR_FILENO, &rights) < 0)
2506a6f38228SPawel Jakub Dawidek 		error("can't limit stderr: %m");
250747c08596SBrooks Davis }
250847c08596SBrooks Davis 
250947c08596SBrooks Davis int
251047c08596SBrooks Davis check_option(struct client_lease *l, int option)
251147c08596SBrooks Davis {
251279a1d195SAlan Somers 	const char *opbuf;
251379a1d195SAlan Somers 	const char *sbuf;
251447c08596SBrooks Davis 
251547c08596SBrooks Davis 	/* we use this, since this is what gets passed to dhclient-script */
251647c08596SBrooks Davis 
251747c08596SBrooks Davis 	opbuf = pretty_print_option(option, l->options[option].data,
251847c08596SBrooks Davis 	    l->options[option].len, 0, 0);
251947c08596SBrooks Davis 
252047c08596SBrooks Davis 	sbuf = option_as_string(option, l->options[option].data,
252147c08596SBrooks Davis 	    l->options[option].len);
252247c08596SBrooks Davis 
252347c08596SBrooks Davis 	switch (option) {
252447c08596SBrooks Davis 	case DHO_SUBNET_MASK:
252547c08596SBrooks Davis 	case DHO_TIME_SERVERS:
252647c08596SBrooks Davis 	case DHO_NAME_SERVERS:
252747c08596SBrooks Davis 	case DHO_ROUTERS:
252847c08596SBrooks Davis 	case DHO_DOMAIN_NAME_SERVERS:
252947c08596SBrooks Davis 	case DHO_LOG_SERVERS:
253047c08596SBrooks Davis 	case DHO_COOKIE_SERVERS:
253147c08596SBrooks Davis 	case DHO_LPR_SERVERS:
253247c08596SBrooks Davis 	case DHO_IMPRESS_SERVERS:
253347c08596SBrooks Davis 	case DHO_RESOURCE_LOCATION_SERVERS:
253447c08596SBrooks Davis 	case DHO_SWAP_SERVER:
253547c08596SBrooks Davis 	case DHO_BROADCAST_ADDRESS:
253647c08596SBrooks Davis 	case DHO_NIS_SERVERS:
253747c08596SBrooks Davis 	case DHO_NTP_SERVERS:
253847c08596SBrooks Davis 	case DHO_NETBIOS_NAME_SERVERS:
253947c08596SBrooks Davis 	case DHO_NETBIOS_DD_SERVER:
254047c08596SBrooks Davis 	case DHO_FONT_SERVERS:
254147c08596SBrooks Davis 	case DHO_DHCP_SERVER_IDENTIFIER:
254238e755fdSBrooks Davis 	case DHO_NISPLUS_SERVERS:
254338e755fdSBrooks Davis 	case DHO_MOBILE_IP_HOME_AGENT:
2544a36c0b6bSBrooks Davis 	case DHO_SMTP_SERVER:
2545a36c0b6bSBrooks Davis 	case DHO_POP_SERVER:
2546a36c0b6bSBrooks Davis 	case DHO_NNTP_SERVER:
2547a36c0b6bSBrooks Davis 	case DHO_WWW_SERVER:
2548a36c0b6bSBrooks Davis 	case DHO_FINGER_SERVER:
2549a36c0b6bSBrooks Davis 	case DHO_IRC_SERVER:
255038e755fdSBrooks Davis 	case DHO_STREETTALK_SERVER:
255138e755fdSBrooks Davis 	case DHO_STREETTALK_DA_SERVER:
255247c08596SBrooks Davis 		if (!ipv4addrs(opbuf)) {
255347c08596SBrooks Davis 			warning("Invalid IP address in option: %s", opbuf);
255447c08596SBrooks Davis 			return (0);
255547c08596SBrooks Davis 		}
255647c08596SBrooks Davis 		return (1)  ;
255747c08596SBrooks Davis 	case DHO_HOST_NAME:
255847c08596SBrooks Davis 	case DHO_NIS_DOMAIN:
255938e755fdSBrooks Davis 	case DHO_NISPLUS_DOMAIN:
256038e755fdSBrooks Davis 	case DHO_TFTP_SERVER_NAME:
256147c08596SBrooks Davis 		if (!res_hnok(sbuf)) {
256247c08596SBrooks Davis 			warning("Bogus Host Name option %d: %s (%s)", option,
256347c08596SBrooks Davis 			    sbuf, opbuf);
256482dbbc41SBrooks Davis 			l->options[option].len = 0;
256582dbbc41SBrooks Davis 			free(l->options[option].data);
256647c08596SBrooks Davis 		}
256747c08596SBrooks Davis 		return (1);
2568b388f1cbSBrooks Davis 	case DHO_DOMAIN_NAME:
2569409139f0SJean-Sébastien Pédron 	case DHO_DOMAIN_SEARCH:
2570f954ec0bSBrooks Davis 		if (!res_hnok(sbuf)) {
2571f954ec0bSBrooks Davis 			if (!check_search(sbuf)) {
2572f954ec0bSBrooks Davis 				warning("Bogus domain search list %d: %s (%s)",
2573f954ec0bSBrooks Davis 				    option, sbuf, opbuf);
257482dbbc41SBrooks Davis 				l->options[option].len = 0;
257582dbbc41SBrooks Davis 				free(l->options[option].data);
2576f954ec0bSBrooks Davis 			}
2577f954ec0bSBrooks Davis 		}
2578f954ec0bSBrooks Davis 		return (1);
257947c08596SBrooks Davis 	case DHO_PAD:
258047c08596SBrooks Davis 	case DHO_TIME_OFFSET:
258147c08596SBrooks Davis 	case DHO_BOOT_SIZE:
258247c08596SBrooks Davis 	case DHO_MERIT_DUMP:
258347c08596SBrooks Davis 	case DHO_ROOT_PATH:
258447c08596SBrooks Davis 	case DHO_EXTENSIONS_PATH:
258547c08596SBrooks Davis 	case DHO_IP_FORWARDING:
258647c08596SBrooks Davis 	case DHO_NON_LOCAL_SOURCE_ROUTING:
258747c08596SBrooks Davis 	case DHO_POLICY_FILTER:
258847c08596SBrooks Davis 	case DHO_MAX_DGRAM_REASSEMBLY:
258947c08596SBrooks Davis 	case DHO_DEFAULT_IP_TTL:
259047c08596SBrooks Davis 	case DHO_PATH_MTU_AGING_TIMEOUT:
259147c08596SBrooks Davis 	case DHO_PATH_MTU_PLATEAU_TABLE:
259247c08596SBrooks Davis 	case DHO_INTERFACE_MTU:
259347c08596SBrooks Davis 	case DHO_ALL_SUBNETS_LOCAL:
259447c08596SBrooks Davis 	case DHO_PERFORM_MASK_DISCOVERY:
259547c08596SBrooks Davis 	case DHO_MASK_SUPPLIER:
259647c08596SBrooks Davis 	case DHO_ROUTER_DISCOVERY:
259747c08596SBrooks Davis 	case DHO_ROUTER_SOLICITATION_ADDRESS:
259847c08596SBrooks Davis 	case DHO_STATIC_ROUTES:
259947c08596SBrooks Davis 	case DHO_TRAILER_ENCAPSULATION:
260047c08596SBrooks Davis 	case DHO_ARP_CACHE_TIMEOUT:
260147c08596SBrooks Davis 	case DHO_IEEE802_3_ENCAPSULATION:
260247c08596SBrooks Davis 	case DHO_DEFAULT_TCP_TTL:
260347c08596SBrooks Davis 	case DHO_TCP_KEEPALIVE_INTERVAL:
260447c08596SBrooks Davis 	case DHO_TCP_KEEPALIVE_GARBAGE:
260547c08596SBrooks Davis 	case DHO_VENDOR_ENCAPSULATED_OPTIONS:
260647c08596SBrooks Davis 	case DHO_NETBIOS_NODE_TYPE:
260747c08596SBrooks Davis 	case DHO_NETBIOS_SCOPE:
260847c08596SBrooks Davis 	case DHO_X_DISPLAY_MANAGER:
260947c08596SBrooks Davis 	case DHO_DHCP_REQUESTED_ADDRESS:
261047c08596SBrooks Davis 	case DHO_DHCP_LEASE_TIME:
261147c08596SBrooks Davis 	case DHO_DHCP_OPTION_OVERLOAD:
261247c08596SBrooks Davis 	case DHO_DHCP_MESSAGE_TYPE:
261347c08596SBrooks Davis 	case DHO_DHCP_PARAMETER_REQUEST_LIST:
261447c08596SBrooks Davis 	case DHO_DHCP_MESSAGE:
261547c08596SBrooks Davis 	case DHO_DHCP_MAX_MESSAGE_SIZE:
261647c08596SBrooks Davis 	case DHO_DHCP_RENEWAL_TIME:
261747c08596SBrooks Davis 	case DHO_DHCP_REBINDING_TIME:
261847c08596SBrooks Davis 	case DHO_DHCP_CLASS_IDENTIFIER:
261947c08596SBrooks Davis 	case DHO_DHCP_CLIENT_IDENTIFIER:
262038e755fdSBrooks Davis 	case DHO_BOOTFILE_NAME:
262147c08596SBrooks Davis 	case DHO_DHCP_USER_CLASS_ID:
2622130cfcf3SDave Cottlehuber 	case DHO_URL:
262347c08596SBrooks Davis 	case DHO_END:
262447c08596SBrooks Davis 		return (1);
26252fcc7370SEd Maste 	case DHO_CLASSLESS_ROUTES:
26262fcc7370SEd Maste 		return (check_classless_option(l->options[option].data,
26272fcc7370SEd Maste 		    l->options[option].len));
262847c08596SBrooks Davis 	default:
262947c08596SBrooks Davis 		warning("unknown dhcp option value 0x%x", option);
263047c08596SBrooks Davis 		return (unknown_ok);
263147c08596SBrooks Davis 	}
263247c08596SBrooks Davis }
263347c08596SBrooks Davis 
26342fcc7370SEd Maste /* RFC 3442 The Classless Static Routes option checks */
26352fcc7370SEd Maste int
26362fcc7370SEd Maste check_classless_option(unsigned char *data, int len)
26372fcc7370SEd Maste {
26382fcc7370SEd Maste 	int i = 0;
26392fcc7370SEd Maste 	unsigned char width;
26402fcc7370SEd Maste 	in_addr_t addr, mask;
26412fcc7370SEd Maste 
26422fcc7370SEd Maste 	if (len < 5) {
26432fcc7370SEd Maste 		warning("Too small length: %d", len);
26442fcc7370SEd Maste 		return (0);
26452fcc7370SEd Maste 	}
26462fcc7370SEd Maste 	while(i < len) {
26472fcc7370SEd Maste 		width = data[i++];
26482fcc7370SEd Maste 		if (width == 0) {
26492fcc7370SEd Maste 			i += 4;
26502fcc7370SEd Maste 			continue;
26512fcc7370SEd Maste 		} else if (width < 9) {
26522fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24);
26532fcc7370SEd Maste 			i += 1;
26542fcc7370SEd Maste 		} else if (width < 17) {
26552fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24) +
26562fcc7370SEd Maste 				(in_addr_t)(data[i + 1]	<< 16);
26572fcc7370SEd Maste 			i += 2;
26582fcc7370SEd Maste 		} else if (width < 25) {
26592fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24) +
26602fcc7370SEd Maste 				(in_addr_t)(data[i + 1]	<< 16) +
26612fcc7370SEd Maste 				(in_addr_t)(data[i + 2]	<< 8);
26622fcc7370SEd Maste 			i += 3;
26632fcc7370SEd Maste 		} else if (width < 33) {
26642fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24) +
26652fcc7370SEd Maste 				(in_addr_t)(data[i + 1]	<< 16) +
26662fcc7370SEd Maste 				(in_addr_t)(data[i + 2]	<< 8)  +
26672fcc7370SEd Maste 				data[i + 3];
26682fcc7370SEd Maste 			i += 4;
26692fcc7370SEd Maste 		} else {
26702fcc7370SEd Maste 			warning("Incorrect subnet width: %d", width);
26712fcc7370SEd Maste 			return (0);
26722fcc7370SEd Maste 		}
26732fcc7370SEd Maste 		mask = (in_addr_t)(~0) << (32 - width);
26742fcc7370SEd Maste 		addr = ntohl(addr);
26752fcc7370SEd Maste 		mask = ntohl(mask);
26762fcc7370SEd Maste 
26772fcc7370SEd Maste 		/*
26782fcc7370SEd Maste 		 * From RFC 3442:
26792fcc7370SEd Maste 		 * ... After deriving a subnet number and subnet mask
26802fcc7370SEd Maste 		 * from each destination descriptor, the DHCP client
26812fcc7370SEd Maste 		 * MUST zero any bits in the subnet number where the
26822fcc7370SEd Maste 		 * corresponding bit in the mask is zero...
26832fcc7370SEd Maste 		 */
26842fcc7370SEd Maste 		if ((addr & mask) != addr) {
26852fcc7370SEd Maste 			addr &= mask;
26862fcc7370SEd Maste 			data[i - 1] = (unsigned char)(
26872fcc7370SEd Maste 				(addr >> (((32 - width)/8)*8)) & 0xFF);
26882fcc7370SEd Maste 		}
26892fcc7370SEd Maste 		i += 4;
26902fcc7370SEd Maste 	}
26912fcc7370SEd Maste 	if (i > len) {
26922fcc7370SEd Maste 		warning("Incorrect data length: %d (must be %d)", len, i);
26932fcc7370SEd Maste 		return (0);
26942fcc7370SEd Maste 	}
26952fcc7370SEd Maste 	return (1);
26962fcc7370SEd Maste }
26972fcc7370SEd Maste 
269847c08596SBrooks Davis int
269947c08596SBrooks Davis res_hnok(const char *dn)
270047c08596SBrooks Davis {
270147c08596SBrooks Davis 	int pch = PERIOD, ch = *dn++;
270247c08596SBrooks Davis 
270347c08596SBrooks Davis 	while (ch != '\0') {
270447c08596SBrooks Davis 		int nch = *dn++;
270547c08596SBrooks Davis 
270647c08596SBrooks Davis 		if (periodchar(ch)) {
270747c08596SBrooks Davis 			;
270847c08596SBrooks Davis 		} else if (periodchar(pch)) {
270947c08596SBrooks Davis 			if (!borderchar(ch))
271047c08596SBrooks Davis 				return (0);
271147c08596SBrooks Davis 		} else if (periodchar(nch) || nch == '\0') {
271247c08596SBrooks Davis 			if (!borderchar(ch))
271347c08596SBrooks Davis 				return (0);
271447c08596SBrooks Davis 		} else {
271547c08596SBrooks Davis 			if (!middlechar(ch))
271647c08596SBrooks Davis 				return (0);
271747c08596SBrooks Davis 		}
271847c08596SBrooks Davis 		pch = ch, ch = nch;
271947c08596SBrooks Davis 	}
272047c08596SBrooks Davis 	return (1);
272147c08596SBrooks Davis }
272247c08596SBrooks Davis 
2723f954ec0bSBrooks Davis int
2724f954ec0bSBrooks Davis check_search(const char *srch)
2725f954ec0bSBrooks Davis {
2726f954ec0bSBrooks Davis         int pch = PERIOD, ch = *srch++;
2727f954ec0bSBrooks Davis 	int domains = 1;
2728f954ec0bSBrooks Davis 
2729f954ec0bSBrooks Davis 	/* 256 char limit re resolv.conf(5) */
2730f954ec0bSBrooks Davis 	if (strlen(srch) > 256)
2731f954ec0bSBrooks Davis 		return (0);
2732f954ec0bSBrooks Davis 
2733f954ec0bSBrooks Davis 	while (whitechar(ch))
2734f954ec0bSBrooks Davis 		ch = *srch++;
2735f954ec0bSBrooks Davis 
2736f954ec0bSBrooks Davis         while (ch != '\0') {
2737f954ec0bSBrooks Davis                 int nch = *srch++;
2738f954ec0bSBrooks Davis 
2739f954ec0bSBrooks Davis                 if (periodchar(ch) || whitechar(ch)) {
2740f954ec0bSBrooks Davis                         ;
2741f954ec0bSBrooks Davis                 } else if (periodchar(pch)) {
2742f954ec0bSBrooks Davis                         if (!borderchar(ch))
2743f954ec0bSBrooks Davis                                 return (0);
2744f954ec0bSBrooks Davis                 } else if (periodchar(nch) || nch == '\0') {
2745f954ec0bSBrooks Davis                         if (!borderchar(ch))
2746f954ec0bSBrooks Davis                                 return (0);
2747f954ec0bSBrooks Davis                 } else {
2748f954ec0bSBrooks Davis                         if (!middlechar(ch))
2749f954ec0bSBrooks Davis                                 return (0);
2750f954ec0bSBrooks Davis                 }
2751f954ec0bSBrooks Davis 		if (!whitechar(ch)) {
2752f954ec0bSBrooks Davis 			pch = ch;
2753f954ec0bSBrooks Davis 		} else {
2754f954ec0bSBrooks Davis 			while (whitechar(nch)) {
2755f954ec0bSBrooks Davis 				nch = *srch++;
2756f954ec0bSBrooks Davis 			}
2757f954ec0bSBrooks Davis 			if (nch != '\0')
2758f954ec0bSBrooks Davis 				domains++;
2759f954ec0bSBrooks Davis 			pch = PERIOD;
2760f954ec0bSBrooks Davis 		}
2761f954ec0bSBrooks Davis 		ch = nch;
2762f954ec0bSBrooks Davis         }
2763f954ec0bSBrooks Davis 	/* 6 domain limit re resolv.conf(5) */
2764f954ec0bSBrooks Davis 	if (domains > 6)
2765f954ec0bSBrooks Davis 		return (0);
2766f954ec0bSBrooks Davis         return (1);
2767f954ec0bSBrooks Davis }
2768f954ec0bSBrooks Davis 
276947c08596SBrooks Davis /* Does buf consist only of dotted decimal ipv4 addrs?
277047c08596SBrooks Davis  * return how many if so,
277147c08596SBrooks Davis  * otherwise, return 0
277247c08596SBrooks Davis  */
277347c08596SBrooks Davis int
277479a1d195SAlan Somers ipv4addrs(const char * buf)
277547c08596SBrooks Davis {
277647c08596SBrooks Davis 	struct in_addr jnk;
277747c08596SBrooks Davis 	int count = 0;
277847c08596SBrooks Davis 
277947c08596SBrooks Davis 	while (inet_aton(buf, &jnk) == 1){
278047c08596SBrooks Davis 		count++;
278147c08596SBrooks Davis 		while (periodchar(*buf) || digitchar(*buf))
278247c08596SBrooks Davis 			buf++;
278347c08596SBrooks Davis 		if (*buf == '\0')
278447c08596SBrooks Davis 			return (count);
278547c08596SBrooks Davis 		while (*buf ==  ' ')
278647c08596SBrooks Davis 			buf++;
278747c08596SBrooks Davis 	}
278847c08596SBrooks Davis 	return (0);
278947c08596SBrooks Davis }
279047c08596SBrooks Davis 
279147c08596SBrooks Davis 
279279a1d195SAlan Somers const char *
279347c08596SBrooks Davis option_as_string(unsigned int code, unsigned char *data, int len)
279447c08596SBrooks Davis {
279547c08596SBrooks Davis 	static char optbuf[32768]; /* XXX */
279647c08596SBrooks Davis 	char *op = optbuf;
279747c08596SBrooks Davis 	int opleft = sizeof(optbuf);
279847c08596SBrooks Davis 	unsigned char *dp = data;
279947c08596SBrooks Davis 
280047c08596SBrooks Davis 	if (code > 255)
280147c08596SBrooks Davis 		error("option_as_string: bad code %d", code);
280247c08596SBrooks Davis 
280347c08596SBrooks Davis 	for (; dp < data + len; dp++) {
280447c08596SBrooks Davis 		if (!isascii(*dp) || !isprint(*dp)) {
280547c08596SBrooks Davis 			if (dp + 1 != data + len || *dp != 0) {
280647c08596SBrooks Davis 				snprintf(op, opleft, "\\%03o", *dp);
280747c08596SBrooks Davis 				op += 4;
280847c08596SBrooks Davis 				opleft -= 4;
280947c08596SBrooks Davis 			}
281047c08596SBrooks Davis 		} else if (*dp == '"' || *dp == '\'' || *dp == '$' ||
281147c08596SBrooks Davis 		    *dp == '`' || *dp == '\\') {
281247c08596SBrooks Davis 			*op++ = '\\';
281347c08596SBrooks Davis 			*op++ = *dp;
281447c08596SBrooks Davis 			opleft -= 2;
281547c08596SBrooks Davis 		} else {
281647c08596SBrooks Davis 			*op++ = *dp;
281747c08596SBrooks Davis 			opleft--;
281847c08596SBrooks Davis 		}
281947c08596SBrooks Davis 	}
282047c08596SBrooks Davis 	if (opleft < 1)
282147c08596SBrooks Davis 		goto toobig;
282247c08596SBrooks Davis 	*op = 0;
282347c08596SBrooks Davis 	return optbuf;
282447c08596SBrooks Davis toobig:
282547c08596SBrooks Davis 	warning("dhcp option too large");
282647c08596SBrooks Davis 	return "<error>";
282747c08596SBrooks Davis }
282847c08596SBrooks Davis 
282947c08596SBrooks Davis int
283047c08596SBrooks Davis fork_privchld(int fd, int fd2)
283147c08596SBrooks Davis {
283247c08596SBrooks Davis 	struct pollfd pfd[1];
283347c08596SBrooks Davis 	int nfds;
283447c08596SBrooks Davis 
283547c08596SBrooks Davis 	switch (fork()) {
283647c08596SBrooks Davis 	case -1:
283747c08596SBrooks Davis 		error("cannot fork");
283847c08596SBrooks Davis 	case 0:
283947c08596SBrooks Davis 		break;
284047c08596SBrooks Davis 	default:
284147c08596SBrooks Davis 		return (0);
284247c08596SBrooks Davis 	}
284347c08596SBrooks Davis 
284447c08596SBrooks Davis 	setproctitle("%s [priv]", ifi->name);
284547c08596SBrooks Davis 
284670892546SEd Schouten 	setsid();
284747c08596SBrooks Davis 	dup2(nullfd, STDIN_FILENO);
284847c08596SBrooks Davis 	dup2(nullfd, STDOUT_FILENO);
284947c08596SBrooks Davis 	dup2(nullfd, STDERR_FILENO);
285047c08596SBrooks Davis 	close(nullfd);
285147c08596SBrooks Davis 	close(fd2);
2852235eb530SPawel Jakub Dawidek 	close(ifi->rfdesc);
2853235eb530SPawel Jakub Dawidek 	ifi->rfdesc = -1;
285447c08596SBrooks Davis 
285547c08596SBrooks Davis 	for (;;) {
285647c08596SBrooks Davis 		pfd[0].fd = fd;
285747c08596SBrooks Davis 		pfd[0].events = POLLIN;
285847c08596SBrooks Davis 		if ((nfds = poll(pfd, 1, INFTIM)) == -1)
285947c08596SBrooks Davis 			if (errno != EINTR)
286047c08596SBrooks Davis 				error("poll error");
286147c08596SBrooks Davis 
286247c08596SBrooks Davis 		if (nfds == 0 || !(pfd[0].revents & POLLIN))
286347c08596SBrooks Davis 			continue;
286447c08596SBrooks Davis 
2865235eb530SPawel Jakub Dawidek 		dispatch_imsg(ifi, fd);
286647c08596SBrooks Davis 	}
286747c08596SBrooks Davis }
2868