xref: /freebsd/sbin/dhclient/dhclient.c (revision b537db698cd4bf459e6ba02beef3d3faea214837)
147c08596SBrooks Davis /*	$OpenBSD: dhclient.c,v 1.63 2005/02/06 17:10:13 krw Exp $	*/
247c08596SBrooks Davis 
38a16b7a1SPedro F. Giffuni /*-
48a16b7a1SPedro F. Giffuni  * SPDX-License-Identifier: BSD-3-Clause
58a16b7a1SPedro F. Giffuni  *
647c08596SBrooks Davis  * Copyright 2004 Henning Brauer <henning@openbsd.org>
747c08596SBrooks Davis  * Copyright (c) 1995, 1996, 1997, 1998, 1999
847c08596SBrooks Davis  * The Internet Software Consortium.    All rights reserved.
947c08596SBrooks Davis  *
1047c08596SBrooks Davis  * Redistribution and use in source and binary forms, with or without
1147c08596SBrooks Davis  * modification, are permitted provided that the following conditions
1247c08596SBrooks Davis  * are met:
1347c08596SBrooks Davis  *
1447c08596SBrooks Davis  * 1. Redistributions of source code must retain the above copyright
1547c08596SBrooks Davis  *    notice, this list of conditions and the following disclaimer.
1647c08596SBrooks Davis  * 2. Redistributions in binary form must reproduce the above copyright
1747c08596SBrooks Davis  *    notice, this list of conditions and the following disclaimer in the
1847c08596SBrooks Davis  *    documentation and/or other materials provided with the distribution.
1947c08596SBrooks Davis  * 3. Neither the name of The Internet Software Consortium nor the names
2047c08596SBrooks Davis  *    of its contributors may be used to endorse or promote products derived
2147c08596SBrooks Davis  *    from this software without specific prior written permission.
2247c08596SBrooks Davis  *
2347c08596SBrooks Davis  * THIS SOFTWARE IS PROVIDED BY THE INTERNET SOFTWARE CONSORTIUM AND
2447c08596SBrooks Davis  * CONTRIBUTORS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
2547c08596SBrooks Davis  * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
2647c08596SBrooks Davis  * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
2747c08596SBrooks Davis  * DISCLAIMED.  IN NO EVENT SHALL THE INTERNET SOFTWARE CONSORTIUM OR
2847c08596SBrooks Davis  * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
2947c08596SBrooks Davis  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
3047c08596SBrooks Davis  * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
3147c08596SBrooks Davis  * USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
3247c08596SBrooks Davis  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
3347c08596SBrooks Davis  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
3447c08596SBrooks Davis  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
3547c08596SBrooks Davis  * SUCH DAMAGE.
3647c08596SBrooks Davis  *
3747c08596SBrooks Davis  * This software has been written for the Internet Software Consortium
3847c08596SBrooks Davis  * by Ted Lemon <mellon@fugue.com> in cooperation with Vixie
3947c08596SBrooks Davis  * Enterprises.  To learn more about the Internet Software Consortium,
4047c08596SBrooks Davis  * see ``http://www.vix.com/isc''.  To learn more about Vixie
4147c08596SBrooks Davis  * Enterprises, see ``http://www.vix.com''.
4247c08596SBrooks Davis  *
4347c08596SBrooks Davis  * This client was substantially modified and enhanced by Elliot Poger
4447c08596SBrooks Davis  * for use on Linux while he was working on the MosquitoNet project at
4547c08596SBrooks Davis  * Stanford.
4647c08596SBrooks Davis  *
4747c08596SBrooks Davis  * The current version owes much to Elliot's Linux enhancements, but
4847c08596SBrooks Davis  * was substantially reorganized and partially rewritten by Ted Lemon
4947c08596SBrooks Davis  * so as to use the same networking framework that the Internet Software
5047c08596SBrooks Davis  * Consortium DHCP server uses.   Much system-specific configuration code
5147c08596SBrooks Davis  * was moved into a shell script so that as support for more operating
5247c08596SBrooks Davis  * systems is added, it will not be necessary to port and maintain
5347c08596SBrooks Davis  * system-specific configuration code to these operating systems - instead,
5447c08596SBrooks Davis  * the shell script can invoke the native tools to accomplish the same
5547c08596SBrooks Davis  * purpose.
5647c08596SBrooks Davis  */
5747c08596SBrooks Davis 
588794fdbbSBrooks Davis #include <sys/cdefs.h>
598794fdbbSBrooks Davis __FBSDID("$FreeBSD$");
608794fdbbSBrooks Davis 
6147c08596SBrooks Davis #include "dhcpd.h"
6247c08596SBrooks Davis #include "privsep.h"
6347c08596SBrooks Davis 
64b881b8beSRobert Watson #include <sys/capsicum.h>
65387016a5SConrad Meyer #include <sys/endian.h>
66de2c882fSPawel Jakub Dawidek 
677672a014SMariusz Zaborski #include <capsicum_helpers.h>
6871c6c44dSEitan Adler #include <libgen.h>
697672a014SMariusz Zaborski 
702b19b6fcSBrooks Davis #include <net80211/ieee80211_freebsd.h>
712b19b6fcSBrooks Davis 
7271c6c44dSEitan Adler 
732b19b6fcSBrooks Davis #ifndef _PATH_VAREMPTY
742b19b6fcSBrooks Davis #define	_PATH_VAREMPTY	"/var/empty"
752b19b6fcSBrooks Davis #endif
762b19b6fcSBrooks Davis 
7747c08596SBrooks Davis #define	PERIOD 0x2e
7847c08596SBrooks Davis #define	hyphenchar(c) ((c) == 0x2d)
7947c08596SBrooks Davis #define	bslashchar(c) ((c) == 0x5c)
8047c08596SBrooks Davis #define	periodchar(c) ((c) == PERIOD)
8147c08596SBrooks Davis #define	asterchar(c) ((c) == 0x2a)
8247c08596SBrooks Davis #define	alphachar(c) (((c) >= 0x41 && (c) <= 0x5a) || \
8347c08596SBrooks Davis 	    ((c) >= 0x61 && (c) <= 0x7a))
8447c08596SBrooks Davis #define	digitchar(c) ((c) >= 0x30 && (c) <= 0x39)
85f954ec0bSBrooks Davis #define	whitechar(c) ((c) == ' ' || (c) == '\t')
8647c08596SBrooks Davis 
8747c08596SBrooks Davis #define	borderchar(c) (alphachar(c) || digitchar(c))
8847c08596SBrooks Davis #define	middlechar(c) (borderchar(c) || hyphenchar(c))
8947c08596SBrooks Davis #define	domainchar(c) ((c) > 0x20 && (c) < 0x7f)
9047c08596SBrooks Davis 
9147c08596SBrooks Davis #define	CLIENT_PATH "PATH=/usr/bin:/usr/sbin:/bin:/sbin"
9247c08596SBrooks Davis 
93cb003dd9SMariusz Zaborski cap_channel_t *capsyslog;
94cb003dd9SMariusz Zaborski 
9547c08596SBrooks Davis time_t cur_time;
9671c6c44dSEitan Adler static time_t default_lease_time = 43200; /* 12 hours... */
9747c08596SBrooks Davis 
9879a1d195SAlan Somers const char *path_dhclient_conf = _PATH_DHCLIENT_CONF;
9947c08596SBrooks Davis char *path_dhclient_db = NULL;
10047c08596SBrooks Davis 
10147c08596SBrooks Davis int log_perror = 1;
10271c6c44dSEitan Adler static int privfd;
10371c6c44dSEitan Adler static int nullfd = -1;
10447c08596SBrooks Davis 
10571c6c44dSEitan Adler static char hostname[_POSIX_HOST_NAME_MAX + 1];
1060bbe8306SPawel Jakub Dawidek 
10771c6c44dSEitan Adler static struct iaddr iaddr_broadcast = { 4, { 255, 255, 255, 255 } };
10871c6c44dSEitan Adler static struct in_addr inaddr_any, inaddr_broadcast;
10947c08596SBrooks Davis 
11071c6c44dSEitan Adler static char *path_dhclient_pidfile;
11123f39c90SDag-Erling Smørgrav struct pidfh *pidfile;
11223f39c90SDag-Erling Smørgrav 
11347c08596SBrooks Davis /*
11447c08596SBrooks Davis  * ASSERT_STATE() does nothing now; it used to be
11547c08596SBrooks Davis  * assert (state_is == state_shouldbe).
11647c08596SBrooks Davis  */
11747c08596SBrooks Davis #define ASSERT_STATE(state_is, state_shouldbe) {}
11847c08596SBrooks Davis 
119223c44aeSNick Hibma /*
120223c44aeSNick Hibma  * We need to check that the expiry, renewal and rebind times are not beyond
121223c44aeSNick Hibma  * the end of time (~2038 when a 32-bit time_t is being used).
122223c44aeSNick Hibma  */
123223c44aeSNick Hibma #define TIME_MAX        ((((time_t) 1 << (sizeof(time_t) * CHAR_BIT - 2)) - 1) * 2 + 1)
12447c08596SBrooks Davis 
12547c08596SBrooks Davis int		log_priority;
12671c6c44dSEitan Adler static int		no_daemon;
12771c6c44dSEitan Adler static int		unknown_ok = 1;
12871c6c44dSEitan Adler static int		routefd;
12947c08596SBrooks Davis 
13047c08596SBrooks Davis struct interface_info	*ifi;
13147c08596SBrooks Davis 
13247c08596SBrooks Davis int		 findproto(char *, int);
13347c08596SBrooks Davis struct sockaddr	*get_ifa(char *, int);
13447c08596SBrooks Davis void		 routehandler(struct protocol *);
13547c08596SBrooks Davis void		 usage(void);
13647c08596SBrooks Davis int		 check_option(struct client_lease *l, int option);
1372fcc7370SEd Maste int		 check_classless_option(unsigned char *data, int len);
13879a1d195SAlan Somers int		 ipv4addrs(const char * buf);
13947c08596SBrooks Davis int		 res_hnok(const char *dn);
140f954ec0bSBrooks Davis int		 check_search(const char *srch);
14179a1d195SAlan Somers const char	*option_as_string(unsigned int code, unsigned char *data, int len);
14247c08596SBrooks Davis int		 fork_privchld(int, int);
14347c08596SBrooks Davis 
14447c08596SBrooks Davis #define	ROUNDUP(a) \
14547c08596SBrooks Davis 	    ((a) > 0 ? (1 + (((a) - 1) | (sizeof(long) - 1))) : sizeof(long))
14647c08596SBrooks Davis #define	ADVANCE(x, n) (x += ROUNDUP((n)->sa_len))
14747c08596SBrooks Davis 
148387016a5SConrad Meyer /* Minimum MTU is 68 as per RFC791, p. 24 */
149387016a5SConrad Meyer #define MIN_MTU 68
150387016a5SConrad Meyer 
1516964abefSBrian Somers static time_t	scripttime;
15247c08596SBrooks Davis 
15347c08596SBrooks Davis int
15447c08596SBrooks Davis findproto(char *cp, int n)
15547c08596SBrooks Davis {
15647c08596SBrooks Davis 	struct sockaddr *sa;
1575f28c51dSAlan Somers 	unsigned i;
15847c08596SBrooks Davis 
15947c08596SBrooks Davis 	if (n == 0)
16047c08596SBrooks Davis 		return -1;
16147c08596SBrooks Davis 	for (i = 1; i; i <<= 1) {
16247c08596SBrooks Davis 		if (i & n) {
16347c08596SBrooks Davis 			sa = (struct sockaddr *)cp;
16447c08596SBrooks Davis 			switch (i) {
16547c08596SBrooks Davis 			case RTA_IFA:
16647c08596SBrooks Davis 			case RTA_DST:
16747c08596SBrooks Davis 			case RTA_GATEWAY:
16847c08596SBrooks Davis 			case RTA_NETMASK:
16947c08596SBrooks Davis 				if (sa->sa_family == AF_INET)
17047c08596SBrooks Davis 					return AF_INET;
17147c08596SBrooks Davis 				if (sa->sa_family == AF_INET6)
17247c08596SBrooks Davis 					return AF_INET6;
17347c08596SBrooks Davis 				break;
17447c08596SBrooks Davis 			case RTA_IFP:
17547c08596SBrooks Davis 				break;
17647c08596SBrooks Davis 			}
17747c08596SBrooks Davis 			ADVANCE(cp, sa);
17847c08596SBrooks Davis 		}
17947c08596SBrooks Davis 	}
18047c08596SBrooks Davis 	return (-1);
18147c08596SBrooks Davis }
18247c08596SBrooks Davis 
18347c08596SBrooks Davis struct sockaddr *
18447c08596SBrooks Davis get_ifa(char *cp, int n)
18547c08596SBrooks Davis {
18647c08596SBrooks Davis 	struct sockaddr *sa;
1875f28c51dSAlan Somers 	unsigned i;
18847c08596SBrooks Davis 
18947c08596SBrooks Davis 	if (n == 0)
19047c08596SBrooks Davis 		return (NULL);
19147c08596SBrooks Davis 	for (i = 1; i; i <<= 1)
19247c08596SBrooks Davis 		if (i & n) {
19347c08596SBrooks Davis 			sa = (struct sockaddr *)cp;
19447c08596SBrooks Davis 			if (i == RTA_IFA)
19547c08596SBrooks Davis 				return (sa);
19647c08596SBrooks Davis 			ADVANCE(cp, sa);
19747c08596SBrooks Davis 		}
19847c08596SBrooks Davis 
19947c08596SBrooks Davis 	return (NULL);
20047c08596SBrooks Davis }
20161063e47SSam Leffler 
20271c6c44dSEitan Adler static struct iaddr defaddr = { .len = 4 };
20371c6c44dSEitan Adler static uint8_t curbssid[6];
20461063e47SSam Leffler 
20561063e47SSam Leffler static void
20661063e47SSam Leffler disassoc(void *arg)
20761063e47SSam Leffler {
20879a1d195SAlan Somers 	struct interface_info *_ifi = arg;
20961063e47SSam Leffler 
21061063e47SSam Leffler 	/*
21161063e47SSam Leffler 	 * Clear existing state.
21261063e47SSam Leffler 	 */
21379a1d195SAlan Somers 	if (_ifi->client->active != NULL) {
21461063e47SSam Leffler 		script_init("EXPIRE", NULL);
21561063e47SSam Leffler 		script_write_params("old_",
21679a1d195SAlan Somers 		    _ifi->client->active);
21779a1d195SAlan Somers 		if (_ifi->client->alias)
21861063e47SSam Leffler 			script_write_params("alias_",
21979a1d195SAlan Somers 				_ifi->client->alias);
22061063e47SSam Leffler 		script_go();
22161063e47SSam Leffler 	}
22279a1d195SAlan Somers 	_ifi->client->state = S_INIT;
22361063e47SSam Leffler }
22447c08596SBrooks Davis 
22547c08596SBrooks Davis void
22679a1d195SAlan Somers routehandler(struct protocol *p __unused)
22747c08596SBrooks Davis {
2286964abefSBrian Somers 	char msg[2048], *addr;
22947c08596SBrooks Davis 	struct rt_msghdr *rtm;
23047c08596SBrooks Davis 	struct if_msghdr *ifm;
23147c08596SBrooks Davis 	struct ifa_msghdr *ifam;
23247c08596SBrooks Davis 	struct if_announcemsghdr *ifan;
23361063e47SSam Leffler 	struct ieee80211_join_event *jev;
23447c08596SBrooks Davis 	struct client_lease *l;
23547c08596SBrooks Davis 	time_t t = time(NULL);
23679a1d195SAlan Somers 	struct sockaddr_in *sa;
23747c08596SBrooks Davis 	struct iaddr a;
23847c08596SBrooks Davis 	ssize_t n;
2390a26f858SJohn Baldwin 	int linkstat;
24047c08596SBrooks Davis 
24147c08596SBrooks Davis 	n = read(routefd, &msg, sizeof(msg));
24247c08596SBrooks Davis 	rtm = (struct rt_msghdr *)msg;
243afe6f835SAlan Somers 	if (n < (ssize_t)sizeof(rtm->rtm_msglen) ||
244afe6f835SAlan Somers 	    n < (ssize_t)rtm->rtm_msglen ||
24547c08596SBrooks Davis 	    rtm->rtm_version != RTM_VERSION)
24647c08596SBrooks Davis 		return;
24747c08596SBrooks Davis 
24847c08596SBrooks Davis 	switch (rtm->rtm_type) {
24947c08596SBrooks Davis 	case RTM_NEWADDR:
250dfad96eaSBrooks Davis 	case RTM_DELADDR:
25147c08596SBrooks Davis 		ifam = (struct ifa_msghdr *)rtm;
252dfad96eaSBrooks Davis 
25347c08596SBrooks Davis 		if (ifam->ifam_index != ifi->index)
25447c08596SBrooks Davis 			break;
25547c08596SBrooks Davis 		if (findproto((char *)(ifam + 1), ifam->ifam_addrs) != AF_INET)
25647c08596SBrooks Davis 			break;
257dfad96eaSBrooks Davis 		if (scripttime == 0 || t < scripttime + 10)
258dfad96eaSBrooks Davis 			break;
259dfad96eaSBrooks Davis 
26079a1d195SAlan Somers 		sa = (struct sockaddr_in*)get_ifa((char *)(ifam + 1), ifam->ifam_addrs);
26147c08596SBrooks Davis 		if (sa == NULL)
2626964abefSBrian Somers 			break;
26347c08596SBrooks Davis 
26447c08596SBrooks Davis 		if ((a.len = sizeof(struct in_addr)) > sizeof(a.iabuf))
26547c08596SBrooks Davis 			error("king bula sez: len mismatch");
26679a1d195SAlan Somers 		memcpy(a.iabuf, &sa->sin_addr, a.len);
26747c08596SBrooks Davis 		if (addr_eq(a, defaddr))
26847c08596SBrooks Davis 			break;
26947c08596SBrooks Davis 
27047c08596SBrooks Davis 		for (l = ifi->client->active; l != NULL; l = l->next)
27147c08596SBrooks Davis 			if (addr_eq(a, l->address))
27247c08596SBrooks Davis 				break;
27347c08596SBrooks Davis 
2746964abefSBrian Somers 		if (l == NULL)	/* added/deleted addr is not the one we set */
27547c08596SBrooks Davis 			break;
2766964abefSBrian Somers 
27779a1d195SAlan Somers 		addr = inet_ntoa(sa->sin_addr);
2786964abefSBrian Somers 		if (rtm->rtm_type == RTM_NEWADDR)  {
2796964abefSBrian Somers 			/*
2806964abefSBrian Somers 			 * XXX: If someone other than us adds our address,
2816964abefSBrian Somers 			 * should we assume they are taking over from us,
2826964abefSBrian Somers 			 * delete the lease record, and exit without modifying
2836964abefSBrian Somers 			 * the interface?
2846964abefSBrian Somers 			 */
2856964abefSBrian Somers 			warning("My address (%s) was re-added", addr);
2866964abefSBrian Somers 		} else {
2876964abefSBrian Somers 			warning("My address (%s) was deleted, dhclient exiting",
2886964abefSBrian Somers 			    addr);
28947c08596SBrooks Davis 			goto die;
2906964abefSBrian Somers 		}
2916964abefSBrian Somers 		break;
29247c08596SBrooks Davis 	case RTM_IFINFO:
29347c08596SBrooks Davis 		ifm = (struct if_msghdr *)rtm;
29447c08596SBrooks Davis 		if (ifm->ifm_index != ifi->index)
29547c08596SBrooks Davis 			break;
2966964abefSBrian Somers 		if ((rtm->rtm_flags & RTF_UP) == 0) {
2976964abefSBrian Somers 			warning("Interface %s is down, dhclient exiting",
2986964abefSBrian Somers 			    ifi->name);
29947c08596SBrooks Davis 			goto die;
3006964abefSBrian Somers 		}
3010a26f858SJohn Baldwin 		linkstat = interface_link_status(ifi->name);
3020a26f858SJohn Baldwin 		if (linkstat != ifi->linkstat) {
3030a26f858SJohn Baldwin 			debug("%s link state %s -> %s", ifi->name,
3040a26f858SJohn Baldwin 			    ifi->linkstat ? "up" : "down",
3050a26f858SJohn Baldwin 			    linkstat ? "up" : "down");
3060a26f858SJohn Baldwin 			ifi->linkstat = linkstat;
3070a26f858SJohn Baldwin 			if (linkstat)
3080a26f858SJohn Baldwin 				state_reboot(ifi);
30983f745b8SJohn Baldwin 		}
31047c08596SBrooks Davis 		break;
31147c08596SBrooks Davis 	case RTM_IFANNOUNCE:
31247c08596SBrooks Davis 		ifan = (struct if_announcemsghdr *)rtm;
31347c08596SBrooks Davis 		if (ifan->ifan_what == IFAN_DEPARTURE &&
3146964abefSBrian Somers 		    ifan->ifan_index == ifi->index) {
3156964abefSBrian Somers 			warning("Interface %s is gone, dhclient exiting",
3166964abefSBrian Somers 			    ifi->name);
31747c08596SBrooks Davis 			goto die;
3186964abefSBrian Somers 		}
31947c08596SBrooks Davis 		break;
3202b19b6fcSBrooks Davis 	case RTM_IEEE80211:
3212b19b6fcSBrooks Davis 		ifan = (struct if_announcemsghdr *)rtm;
3222b19b6fcSBrooks Davis 		if (ifan->ifan_index != ifi->index)
3232b19b6fcSBrooks Davis 			break;
3242b19b6fcSBrooks Davis 		switch (ifan->ifan_what) {
3252b19b6fcSBrooks Davis 		case RTM_IEEE80211_ASSOC:
326b35f2511SSam Leffler 		case RTM_IEEE80211_REASSOC:
3272b19b6fcSBrooks Davis 			/*
32861063e47SSam Leffler 			 * Use assoc/reassoc event to kick state machine
32961063e47SSam Leffler 			 * in case we roam.  Otherwise fall back to the
33061063e47SSam Leffler 			 * normal state machine just like a wired network.
3312b19b6fcSBrooks Davis 			 */
33261063e47SSam Leffler 			jev = (struct ieee80211_join_event *) &ifan[1];
33361063e47SSam Leffler 			if (memcmp(curbssid, jev->iev_addr, 6)) {
33461063e47SSam Leffler 				disassoc(ifi);
33561063e47SSam Leffler 				state_reboot(ifi);
33659eac186SBrooks Davis 			}
33761063e47SSam Leffler 			memcpy(curbssid, jev->iev_addr, 6);
3382b19b6fcSBrooks Davis 			break;
3392b19b6fcSBrooks Davis 		}
3402b19b6fcSBrooks Davis 		break;
34147c08596SBrooks Davis 	default:
34247c08596SBrooks Davis 		break;
34347c08596SBrooks Davis 	}
34447c08596SBrooks Davis 	return;
34547c08596SBrooks Davis 
34647c08596SBrooks Davis die:
34747c08596SBrooks Davis 	script_init("FAIL", NULL);
34847c08596SBrooks Davis 	if (ifi->client->alias)
34947c08596SBrooks Davis 		script_write_params("alias_", ifi->client->alias);
35047c08596SBrooks Davis 	script_go();
35123f39c90SDag-Erling Smørgrav 	if (pidfile != NULL)
35223f39c90SDag-Erling Smørgrav 		pidfile_remove(pidfile);
35347c08596SBrooks Davis 	exit(1);
35447c08596SBrooks Davis }
35547c08596SBrooks Davis 
356cb003dd9SMariusz Zaborski static void
357cb003dd9SMariusz Zaborski init_casper(void)
358cb003dd9SMariusz Zaborski {
359cb003dd9SMariusz Zaborski 	cap_channel_t		*casper;
360cb003dd9SMariusz Zaborski 
361cb003dd9SMariusz Zaborski 	casper = cap_init();
362cb003dd9SMariusz Zaborski 	if (casper == NULL)
363cb003dd9SMariusz Zaborski 		error("unable to start casper");
364cb003dd9SMariusz Zaborski 
365cb003dd9SMariusz Zaborski 	capsyslog = cap_service_open(casper, "system.syslog");
366cb003dd9SMariusz Zaborski 	cap_close(casper);
367cb003dd9SMariusz Zaborski 	if (capsyslog == NULL)
368cb003dd9SMariusz Zaborski 		error("unable to open system.syslog service");
369cb003dd9SMariusz Zaborski }
370cb003dd9SMariusz Zaborski 
37147c08596SBrooks Davis int
37247c08596SBrooks Davis main(int argc, char *argv[])
37347c08596SBrooks Davis {
37447c08596SBrooks Davis 	int			 ch, fd, quiet = 0, i = 0;
37547c08596SBrooks Davis 	int			 pipe_fd[2];
3762b19b6fcSBrooks Davis 	int			 immediate_daemon = 0;
37747c08596SBrooks Davis 	struct passwd		*pw;
37823f39c90SDag-Erling Smørgrav 	pid_t			 otherpid;
3797008be5bSPawel Jakub Dawidek 	cap_rights_t		 rights;
38047c08596SBrooks Davis 
381cb003dd9SMariusz Zaborski 	init_casper();
382cb003dd9SMariusz Zaborski 
38347c08596SBrooks Davis 	/* Initially, log errors to stderr as well as to syslogd. */
384*b537db69SEitan Adler 	cap_openlog(capsyslog, getprogname(), LOG_PID | LOG_NDELAY, DHCPD_LOG_FACILITY);
385cb003dd9SMariusz Zaborski 	cap_setlogmask(capsyslog, LOG_UPTO(LOG_DEBUG));
38647c08596SBrooks Davis 
38723f39c90SDag-Erling Smørgrav 	while ((ch = getopt(argc, argv, "bc:dl:p:qu")) != -1)
38847c08596SBrooks Davis 		switch (ch) {
3892b19b6fcSBrooks Davis 		case 'b':
3902b19b6fcSBrooks Davis 			immediate_daemon = 1;
3912b19b6fcSBrooks Davis 			break;
39247c08596SBrooks Davis 		case 'c':
39347c08596SBrooks Davis 			path_dhclient_conf = optarg;
39447c08596SBrooks Davis 			break;
39547c08596SBrooks Davis 		case 'd':
39647c08596SBrooks Davis 			no_daemon = 1;
39747c08596SBrooks Davis 			break;
39847c08596SBrooks Davis 		case 'l':
39947c08596SBrooks Davis 			path_dhclient_db = optarg;
40047c08596SBrooks Davis 			break;
40123f39c90SDag-Erling Smørgrav 		case 'p':
40223f39c90SDag-Erling Smørgrav 			path_dhclient_pidfile = optarg;
40323f39c90SDag-Erling Smørgrav 			break;
40447c08596SBrooks Davis 		case 'q':
40547c08596SBrooks Davis 			quiet = 1;
40647c08596SBrooks Davis 			break;
40747c08596SBrooks Davis 		case 'u':
40847c08596SBrooks Davis 			unknown_ok = 0;
40947c08596SBrooks Davis 			break;
41047c08596SBrooks Davis 		default:
41147c08596SBrooks Davis 			usage();
41247c08596SBrooks Davis 		}
41347c08596SBrooks Davis 
41447c08596SBrooks Davis 	argc -= optind;
41547c08596SBrooks Davis 	argv += optind;
41647c08596SBrooks Davis 
41747c08596SBrooks Davis 	if (argc != 1)
41847c08596SBrooks Davis 		usage();
41947c08596SBrooks Davis 
42023f39c90SDag-Erling Smørgrav 	if (path_dhclient_pidfile == NULL) {
42123f39c90SDag-Erling Smørgrav 		asprintf(&path_dhclient_pidfile,
42223f39c90SDag-Erling Smørgrav 		    "%sdhclient.%s.pid", _PATH_VARRUN, *argv);
42323f39c90SDag-Erling Smørgrav 		if (path_dhclient_pidfile == NULL)
42423f39c90SDag-Erling Smørgrav 			error("asprintf");
42523f39c90SDag-Erling Smørgrav 	}
42607561ab4SEitan Adler 	pidfile = pidfile_open(path_dhclient_pidfile, 0644, &otherpid);
42723f39c90SDag-Erling Smørgrav 	if (pidfile == NULL) {
42823f39c90SDag-Erling Smørgrav 		if (errno == EEXIST)
42923f39c90SDag-Erling Smørgrav 			error("dhclient already running, pid: %d.", otherpid);
43023f39c90SDag-Erling Smørgrav 		if (errno == EAGAIN)
43123f39c90SDag-Erling Smørgrav 			error("dhclient already running.");
43223f39c90SDag-Erling Smørgrav 		warning("Cannot open or create pidfile: %m");
43323f39c90SDag-Erling Smørgrav 	}
43423f39c90SDag-Erling Smørgrav 
43547c08596SBrooks Davis 	if ((ifi = calloc(1, sizeof(struct interface_info))) == NULL)
43647c08596SBrooks Davis 		error("calloc");
43747c08596SBrooks Davis 	if (strlcpy(ifi->name, argv[0], IFNAMSIZ) >= IFNAMSIZ)
43847c08596SBrooks Davis 		error("Interface name too long");
43947c08596SBrooks Davis 	if (path_dhclient_db == NULL && asprintf(&path_dhclient_db, "%s.%s",
44047c08596SBrooks Davis 	    _PATH_DHCLIENT_DB, ifi->name) == -1)
44147c08596SBrooks Davis 		error("asprintf");
44247c08596SBrooks Davis 
44347c08596SBrooks Davis 	if (quiet)
44447c08596SBrooks Davis 		log_perror = 0;
44547c08596SBrooks Davis 
44647c08596SBrooks Davis 	tzset();
44747c08596SBrooks Davis 	time(&cur_time);
44847c08596SBrooks Davis 
449ba019ae5SPawel Jakub Dawidek 	inaddr_broadcast.s_addr = INADDR_BROADCAST;
45047c08596SBrooks Davis 	inaddr_any.s_addr = INADDR_ANY;
45147c08596SBrooks Davis 
45247c08596SBrooks Davis 	read_client_conf();
45347c08596SBrooks Davis 
45423f39c90SDag-Erling Smørgrav 	/* The next bit is potentially very time-consuming, so write out
45523f39c90SDag-Erling Smørgrav 	   the pidfile right away.  We will write it out again with the
45623f39c90SDag-Erling Smørgrav 	   correct pid after daemonizing. */
45723f39c90SDag-Erling Smørgrav 	if (pidfile != NULL)
45823f39c90SDag-Erling Smørgrav 		pidfile_write(pidfile);
45923f39c90SDag-Erling Smørgrav 
46047c08596SBrooks Davis 	if (!interface_link_status(ifi->name)) {
46147c08596SBrooks Davis 		fprintf(stderr, "%s: no link ...", ifi->name);
46247c08596SBrooks Davis 		fflush(stderr);
46347c08596SBrooks Davis 		sleep(1);
46447c08596SBrooks Davis 		while (!interface_link_status(ifi->name)) {
46547c08596SBrooks Davis 			fprintf(stderr, ".");
46647c08596SBrooks Davis 			fflush(stderr);
46747c08596SBrooks Davis 			if (++i > 10) {
46847c08596SBrooks Davis 				fprintf(stderr, " giving up\n");
46947c08596SBrooks Davis 				exit(1);
47047c08596SBrooks Davis 			}
47147c08596SBrooks Davis 			sleep(1);
47247c08596SBrooks Davis 		}
47347c08596SBrooks Davis 		fprintf(stderr, " got link\n");
47447c08596SBrooks Davis 	}
4750a26f858SJohn Baldwin 	ifi->linkstat = 1;
47647c08596SBrooks Davis 
47747c08596SBrooks Davis 	if ((nullfd = open(_PATH_DEVNULL, O_RDWR, 0)) == -1)
47847c08596SBrooks Davis 		error("cannot open %s: %m", _PATH_DEVNULL);
47947c08596SBrooks Davis 
48047c08596SBrooks Davis 	if ((pw = getpwnam("_dhcp")) == NULL) {
48147c08596SBrooks Davis 		warning("no such user: _dhcp, falling back to \"nobody\"");
48247c08596SBrooks Davis 		if ((pw = getpwnam("nobody")) == NULL)
48347c08596SBrooks Davis 			error("no such user: nobody");
48447c08596SBrooks Davis 	}
48547c08596SBrooks Davis 
4860bbe8306SPawel Jakub Dawidek 	/*
4870bbe8306SPawel Jakub Dawidek 	 * Obtain hostname before entering capability mode - it won't be
4880bbe8306SPawel Jakub Dawidek 	 * possible then, as reading kern.hostname is not permitted.
4890bbe8306SPawel Jakub Dawidek 	 */
4900bbe8306SPawel Jakub Dawidek 	if (gethostname(hostname, sizeof(hostname)) < 0)
4910bbe8306SPawel Jakub Dawidek 		hostname[0] = '\0';
4920bbe8306SPawel Jakub Dawidek 
493374a8a32SPawel Jakub Dawidek 	priv_script_init("PREINIT", NULL);
494374a8a32SPawel Jakub Dawidek 	if (ifi->client->alias)
495374a8a32SPawel Jakub Dawidek 		priv_script_write_params("alias_", ifi->client->alias);
496374a8a32SPawel Jakub Dawidek 	priv_script_go();
497374a8a32SPawel Jakub Dawidek 
498235eb530SPawel Jakub Dawidek 	/* set up the interface */
499235eb530SPawel Jakub Dawidek 	discover_interfaces(ifi);
500235eb530SPawel Jakub Dawidek 
50147c08596SBrooks Davis 	if (pipe(pipe_fd) == -1)
50247c08596SBrooks Davis 		error("pipe");
50347c08596SBrooks Davis 
50447c08596SBrooks Davis 	fork_privchld(pipe_fd[0], pipe_fd[1]);
50547c08596SBrooks Davis 
506235eb530SPawel Jakub Dawidek 	close(ifi->ufdesc);
507235eb530SPawel Jakub Dawidek 	ifi->ufdesc = -1;
508235eb530SPawel Jakub Dawidek 	close(ifi->wfdesc);
509235eb530SPawel Jakub Dawidek 	ifi->wfdesc = -1;
510235eb530SPawel Jakub Dawidek 
51147c08596SBrooks Davis 	close(pipe_fd[0]);
51247c08596SBrooks Davis 	privfd = pipe_fd[1];
5137008be5bSPawel Jakub Dawidek 	cap_rights_init(&rights, CAP_READ, CAP_WRITE);
5147008be5bSPawel Jakub Dawidek 	if (cap_rights_limit(privfd, &rights) < 0 && errno != ENOSYS)
515de2c882fSPawel Jakub Dawidek 		error("can't limit private descriptor: %m");
51647c08596SBrooks Davis 
51747c08596SBrooks Davis 	if ((fd = open(path_dhclient_db, O_RDONLY|O_EXLOCK|O_CREAT, 0)) == -1)
51847c08596SBrooks Davis 		error("can't open and lock %s: %m", path_dhclient_db);
51947c08596SBrooks Davis 	read_client_leases();
52047c08596SBrooks Davis 	rewrite_client_leases();
52147c08596SBrooks Davis 	close(fd);
52247c08596SBrooks Davis 
52347c08596SBrooks Davis 	if ((routefd = socket(PF_ROUTE, SOCK_RAW, 0)) != -1)
52447c08596SBrooks Davis 		add_protocol("AF_ROUTE", routefd, routehandler, ifi);
525e374cef5SPawel Jakub Dawidek 	if (shutdown(routefd, SHUT_WR) < 0)
526e374cef5SPawel Jakub Dawidek 		error("can't shutdown route socket: %m");
527bb7a82acSChristian Brueffer 	cap_rights_init(&rights, CAP_EVENT, CAP_READ);
5287008be5bSPawel Jakub Dawidek 	if (cap_rights_limit(routefd, &rights) < 0 && errno != ENOSYS)
529f73ac8b9SPawel Jakub Dawidek 		error("can't limit route socket: %m");
53047c08596SBrooks Davis 
53147c08596SBrooks Davis 	if (chroot(_PATH_VAREMPTY) == -1)
53247c08596SBrooks Davis 		error("chroot");
53347c08596SBrooks Davis 	if (chdir("/") == -1)
53447c08596SBrooks Davis 		error("chdir(\"/\")");
53547c08596SBrooks Davis 
53647c08596SBrooks Davis 	if (setgroups(1, &pw->pw_gid) ||
53747c08596SBrooks Davis 	    setegid(pw->pw_gid) || setgid(pw->pw_gid) ||
53847c08596SBrooks Davis 	    seteuid(pw->pw_uid) || setuid(pw->pw_uid))
53947c08596SBrooks Davis 		error("can't drop privileges: %m");
54047c08596SBrooks Davis 
54147c08596SBrooks Davis 	endpwent();
54247c08596SBrooks Davis 
54347c08596SBrooks Davis 	setproctitle("%s", ifi->name);
54447c08596SBrooks Davis 
5457672a014SMariusz Zaborski 	if (caph_enter_casper() < 0)
5468da93e68SPawel Jakub Dawidek 		error("can't enter capability mode: %m");
5478da93e68SPawel Jakub Dawidek 
5482b19b6fcSBrooks Davis 	if (immediate_daemon)
5492b19b6fcSBrooks Davis 		go_daemon();
5502b19b6fcSBrooks Davis 
55147c08596SBrooks Davis 	ifi->client->state = S_INIT;
55247c08596SBrooks Davis 	state_reboot(ifi);
55347c08596SBrooks Davis 
55447c08596SBrooks Davis 	bootp_packet_handler = do_packet;
55547c08596SBrooks Davis 
55647c08596SBrooks Davis 	dispatch();
55747c08596SBrooks Davis 
55847c08596SBrooks Davis 	/* not reached */
55947c08596SBrooks Davis 	return (0);
56047c08596SBrooks Davis }
56147c08596SBrooks Davis 
56247c08596SBrooks Davis void
56347c08596SBrooks Davis usage(void)
56447c08596SBrooks Davis {
56547c08596SBrooks Davis 
566*b537db69SEitan Adler 	fprintf(stderr, "usage: %s [-bdqu] ", getprogname());
56747c08596SBrooks Davis 	fprintf(stderr, "[-c conffile] [-l leasefile] interface\n");
56847c08596SBrooks Davis 	exit(1);
56947c08596SBrooks Davis }
57047c08596SBrooks Davis 
57147c08596SBrooks Davis /*
57247c08596SBrooks Davis  * Individual States:
57347c08596SBrooks Davis  *
57447c08596SBrooks Davis  * Each routine is called from the dhclient_state_machine() in one of
57547c08596SBrooks Davis  * these conditions:
57647c08596SBrooks Davis  * -> entering INIT state
57747c08596SBrooks Davis  * -> recvpacket_flag == 0: timeout in this state
57847c08596SBrooks Davis  * -> otherwise: received a packet in this state
57947c08596SBrooks Davis  *
58047c08596SBrooks Davis  * Return conditions as handled by dhclient_state_machine():
58147c08596SBrooks Davis  * Returns 1, sendpacket_flag = 1: send packet, reset timer.
58247c08596SBrooks Davis  * Returns 1, sendpacket_flag = 0: just reset the timer (wait for a milestone).
58347c08596SBrooks Davis  * Returns 0: finish the nap which was interrupted for no good reason.
58447c08596SBrooks Davis  *
58547c08596SBrooks Davis  * Several per-interface variables are used to keep track of the process:
58647c08596SBrooks Davis  *   active_lease: the lease that is being used on the interface
58747c08596SBrooks Davis  *                 (null pointer if not configured yet).
58847c08596SBrooks Davis  *   offered_leases: leases corresponding to DHCPOFFER messages that have
58947c08596SBrooks Davis  *                   been sent to us by DHCP servers.
59047c08596SBrooks Davis  *   acked_leases: leases corresponding to DHCPACK messages that have been
59147c08596SBrooks Davis  *                 sent to us by DHCP servers.
59247c08596SBrooks Davis  *   sendpacket: DHCP packet we're trying to send.
59347c08596SBrooks Davis  *   destination: IP address to send sendpacket to
59447c08596SBrooks Davis  * In addition, there are several relevant per-lease variables.
59547c08596SBrooks Davis  *   T1_expiry, T2_expiry, lease_expiry: lease milestones
59647c08596SBrooks Davis  * In the active lease, these control the process of renewing the lease;
59747c08596SBrooks Davis  * In leases on the acked_leases list, this simply determines when we
59847c08596SBrooks Davis  * can no longer legitimately use the lease.
59947c08596SBrooks Davis  */
60047c08596SBrooks Davis 
60147c08596SBrooks Davis void
60247c08596SBrooks Davis state_reboot(void *ipp)
60347c08596SBrooks Davis {
60447c08596SBrooks Davis 	struct interface_info *ip = ipp;
60547c08596SBrooks Davis 
60647c08596SBrooks Davis 	/* If we don't remember an active lease, go straight to INIT. */
60747c08596SBrooks Davis 	if (!ip->client->active || ip->client->active->is_bootp) {
60847c08596SBrooks Davis 		state_init(ip);
60947c08596SBrooks Davis 		return;
61047c08596SBrooks Davis 	}
61147c08596SBrooks Davis 
61247c08596SBrooks Davis 	/* We are in the rebooting state. */
61347c08596SBrooks Davis 	ip->client->state = S_REBOOTING;
61447c08596SBrooks Davis 
61547c08596SBrooks Davis 	/* make_request doesn't initialize xid because it normally comes
61647c08596SBrooks Davis 	   from the DHCPDISCOVER, but we haven't sent a DHCPDISCOVER,
61747c08596SBrooks Davis 	   so pick an xid now. */
61847c08596SBrooks Davis 	ip->client->xid = arc4random();
61947c08596SBrooks Davis 
62047c08596SBrooks Davis 	/* Make a DHCPREQUEST packet, and set appropriate per-interface
62147c08596SBrooks Davis 	   flags. */
62247c08596SBrooks Davis 	make_request(ip, ip->client->active);
62347c08596SBrooks Davis 	ip->client->destination = iaddr_broadcast;
62447c08596SBrooks Davis 	ip->client->first_sending = cur_time;
62547c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
62647c08596SBrooks Davis 
62747c08596SBrooks Davis 	/* Zap the medium list... */
62847c08596SBrooks Davis 	ip->client->medium = NULL;
62947c08596SBrooks Davis 
63047c08596SBrooks Davis 	/* Send out the first DHCPREQUEST packet. */
63147c08596SBrooks Davis 	send_request(ip);
63247c08596SBrooks Davis }
63347c08596SBrooks Davis 
63447c08596SBrooks Davis /*
63547c08596SBrooks Davis  * Called when a lease has completely expired and we've
63647c08596SBrooks Davis  * been unable to renew it.
63747c08596SBrooks Davis  */
63847c08596SBrooks Davis void
63947c08596SBrooks Davis state_init(void *ipp)
64047c08596SBrooks Davis {
64147c08596SBrooks Davis 	struct interface_info *ip = ipp;
64247c08596SBrooks Davis 
64347c08596SBrooks Davis 	ASSERT_STATE(state, S_INIT);
64447c08596SBrooks Davis 
64547c08596SBrooks Davis 	/* Make a DHCPDISCOVER packet, and set appropriate per-interface
64647c08596SBrooks Davis 	   flags. */
64747c08596SBrooks Davis 	make_discover(ip, ip->client->active);
64847c08596SBrooks Davis 	ip->client->xid = ip->client->packet.xid;
64947c08596SBrooks Davis 	ip->client->destination = iaddr_broadcast;
65047c08596SBrooks Davis 	ip->client->state = S_SELECTING;
65147c08596SBrooks Davis 	ip->client->first_sending = cur_time;
65247c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
65347c08596SBrooks Davis 
65447c08596SBrooks Davis 	/* Add an immediate timeout to cause the first DHCPDISCOVER packet
65547c08596SBrooks Davis 	   to go out. */
65647c08596SBrooks Davis 	send_discover(ip);
65747c08596SBrooks Davis }
65847c08596SBrooks Davis 
65947c08596SBrooks Davis /*
66047c08596SBrooks Davis  * state_selecting is called when one or more DHCPOFFER packets
66147c08596SBrooks Davis  * have been received and a configurable period of time has passed.
66247c08596SBrooks Davis  */
66347c08596SBrooks Davis void
66447c08596SBrooks Davis state_selecting(void *ipp)
66547c08596SBrooks Davis {
66647c08596SBrooks Davis 	struct interface_info *ip = ipp;
66747c08596SBrooks Davis 	struct client_lease *lp, *next, *picked;
66847c08596SBrooks Davis 
66947c08596SBrooks Davis 	ASSERT_STATE(state, S_SELECTING);
67047c08596SBrooks Davis 
67147c08596SBrooks Davis 	/* Cancel state_selecting and send_discover timeouts, since either
67247c08596SBrooks Davis 	   one could have got us here. */
67347c08596SBrooks Davis 	cancel_timeout(state_selecting, ip);
67447c08596SBrooks Davis 	cancel_timeout(send_discover, ip);
67547c08596SBrooks Davis 
67647c08596SBrooks Davis 	/* We have received one or more DHCPOFFER packets.   Currently,
67747c08596SBrooks Davis 	   the only criterion by which we judge leases is whether or
67847c08596SBrooks Davis 	   not we get a response when we arp for them. */
67947c08596SBrooks Davis 	picked = NULL;
68047c08596SBrooks Davis 	for (lp = ip->client->offered_leases; lp; lp = next) {
68147c08596SBrooks Davis 		next = lp->next;
68247c08596SBrooks Davis 
68347c08596SBrooks Davis 		/* Check to see if we got an ARPREPLY for the address
68447c08596SBrooks Davis 		   in this particular lease. */
68547c08596SBrooks Davis 		if (!picked) {
68647c08596SBrooks Davis 			script_init("ARPCHECK", lp->medium);
68747c08596SBrooks Davis 			script_write_params("check_", lp);
68847c08596SBrooks Davis 
68947c08596SBrooks Davis 			/* If the ARPCHECK code detects another
69047c08596SBrooks Davis 			   machine using the offered address, it exits
69147c08596SBrooks Davis 			   nonzero.  We need to send a DHCPDECLINE and
69247c08596SBrooks Davis 			   toss the lease. */
69347c08596SBrooks Davis 			if (script_go()) {
69447c08596SBrooks Davis 				make_decline(ip, lp);
69547c08596SBrooks Davis 				send_decline(ip);
69647c08596SBrooks Davis 				goto freeit;
69747c08596SBrooks Davis 			}
69847c08596SBrooks Davis 			picked = lp;
69947c08596SBrooks Davis 			picked->next = NULL;
70047c08596SBrooks Davis 		} else {
70147c08596SBrooks Davis freeit:
70247c08596SBrooks Davis 			free_client_lease(lp);
70347c08596SBrooks Davis 		}
70447c08596SBrooks Davis 	}
70547c08596SBrooks Davis 	ip->client->offered_leases = NULL;
70647c08596SBrooks Davis 
70747c08596SBrooks Davis 	/* If we just tossed all the leases we were offered, go back
70847c08596SBrooks Davis 	   to square one. */
70947c08596SBrooks Davis 	if (!picked) {
71047c08596SBrooks Davis 		ip->client->state = S_INIT;
71147c08596SBrooks Davis 		state_init(ip);
71247c08596SBrooks Davis 		return;
71347c08596SBrooks Davis 	}
71447c08596SBrooks Davis 
71547c08596SBrooks Davis 	/* If it was a BOOTREPLY, we can just take the address right now. */
71647c08596SBrooks Davis 	if (!picked->options[DHO_DHCP_MESSAGE_TYPE].len) {
71747c08596SBrooks Davis 		ip->client->new = picked;
71847c08596SBrooks Davis 
71947c08596SBrooks Davis 		/* Make up some lease expiry times
72047c08596SBrooks Davis 		   XXX these should be configurable. */
72147c08596SBrooks Davis 		ip->client->new->expiry = cur_time + 12000;
72247c08596SBrooks Davis 		ip->client->new->renewal += cur_time + 8000;
72347c08596SBrooks Davis 		ip->client->new->rebind += cur_time + 10000;
72447c08596SBrooks Davis 
72547c08596SBrooks Davis 		ip->client->state = S_REQUESTING;
72647c08596SBrooks Davis 
72747c08596SBrooks Davis 		/* Bind to the address we received. */
72847c08596SBrooks Davis 		bind_lease(ip);
72947c08596SBrooks Davis 		return;
73047c08596SBrooks Davis 	}
73147c08596SBrooks Davis 
73247c08596SBrooks Davis 	/* Go to the REQUESTING state. */
73347c08596SBrooks Davis 	ip->client->destination = iaddr_broadcast;
73447c08596SBrooks Davis 	ip->client->state = S_REQUESTING;
73547c08596SBrooks Davis 	ip->client->first_sending = cur_time;
73647c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
73747c08596SBrooks Davis 
73847c08596SBrooks Davis 	/* Make a DHCPREQUEST packet from the lease we picked. */
73947c08596SBrooks Davis 	make_request(ip, picked);
74047c08596SBrooks Davis 	ip->client->xid = ip->client->packet.xid;
74147c08596SBrooks Davis 
74247c08596SBrooks Davis 	/* Toss the lease we picked - we'll get it back in a DHCPACK. */
74347c08596SBrooks Davis 	free_client_lease(picked);
74447c08596SBrooks Davis 
74547c08596SBrooks Davis 	/* Add an immediate timeout to send the first DHCPREQUEST packet. */
74647c08596SBrooks Davis 	send_request(ip);
74747c08596SBrooks Davis }
74847c08596SBrooks Davis 
74947c08596SBrooks Davis /* state_requesting is called when we receive a DHCPACK message after
75047c08596SBrooks Davis    having sent out one or more DHCPREQUEST packets. */
75147c08596SBrooks Davis 
75247c08596SBrooks Davis void
75347c08596SBrooks Davis dhcpack(struct packet *packet)
75447c08596SBrooks Davis {
75547c08596SBrooks Davis 	struct interface_info *ip = packet->interface;
75647c08596SBrooks Davis 	struct client_lease *lease;
75747c08596SBrooks Davis 
75847c08596SBrooks Davis 	/* If we're not receptive to an offer right now, or if the offer
75947c08596SBrooks Davis 	   has an unrecognizable transaction id, then just drop it. */
76047c08596SBrooks Davis 	if (packet->interface->client->xid != packet->raw->xid ||
76147c08596SBrooks Davis 	    (packet->interface->hw_address.hlen != packet->raw->hlen) ||
76247c08596SBrooks Davis 	    (memcmp(packet->interface->hw_address.haddr,
76347c08596SBrooks Davis 	    packet->raw->chaddr, packet->raw->hlen)))
76447c08596SBrooks Davis 		return;
76547c08596SBrooks Davis 
76647c08596SBrooks Davis 	if (ip->client->state != S_REBOOTING &&
76747c08596SBrooks Davis 	    ip->client->state != S_REQUESTING &&
76847c08596SBrooks Davis 	    ip->client->state != S_RENEWING &&
76947c08596SBrooks Davis 	    ip->client->state != S_REBINDING)
77047c08596SBrooks Davis 		return;
77147c08596SBrooks Davis 
77247c08596SBrooks Davis 	note("DHCPACK from %s", piaddr(packet->client_addr));
77347c08596SBrooks Davis 
77447c08596SBrooks Davis 	lease = packet_to_lease(packet);
77547c08596SBrooks Davis 	if (!lease) {
77647c08596SBrooks Davis 		note("packet_to_lease failed.");
77747c08596SBrooks Davis 		return;
77847c08596SBrooks Davis 	}
77947c08596SBrooks Davis 
78047c08596SBrooks Davis 	ip->client->new = lease;
78147c08596SBrooks Davis 
78247c08596SBrooks Davis 	/* Stop resending DHCPREQUEST. */
78347c08596SBrooks Davis 	cancel_timeout(send_request, ip);
78447c08596SBrooks Davis 
78547c08596SBrooks Davis 	/* Figure out the lease time. */
7861fb4382cSNick Hibma         if (ip->client->config->default_actions[DHO_DHCP_LEASE_TIME] ==
7871fb4382cSNick Hibma             ACTION_SUPERSEDE)
7881fb4382cSNick Hibma 		ip->client->new->expiry = getULong(
7891fb4382cSNick Hibma 		    ip->client->config->defaults[DHO_DHCP_LEASE_TIME].data);
7901fb4382cSNick Hibma         else if (ip->client->new->options[DHO_DHCP_LEASE_TIME].data)
79147c08596SBrooks Davis 		ip->client->new->expiry = getULong(
79247c08596SBrooks Davis 		    ip->client->new->options[DHO_DHCP_LEASE_TIME].data);
79347c08596SBrooks Davis 	else
79447c08596SBrooks Davis 		ip->client->new->expiry = default_lease_time;
79547c08596SBrooks Davis 	/* A number that looks negative here is really just very large,
796223c44aeSNick Hibma 	   because the lease expiry offset is unsigned. Also make sure that
797223c44aeSNick Hibma            the addition of cur_time below does not overflow (a 32 bit) time_t. */
798223c44aeSNick Hibma 	if (ip->client->new->expiry < 0 ||
799223c44aeSNick Hibma             ip->client->new->expiry > TIME_MAX - cur_time)
800223c44aeSNick Hibma 		ip->client->new->expiry = TIME_MAX - cur_time;
80147c08596SBrooks Davis 	/* XXX should be fixed by resetting the client state */
80247c08596SBrooks Davis 	if (ip->client->new->expiry < 60)
80347c08596SBrooks Davis 		ip->client->new->expiry = 60;
80447c08596SBrooks Davis 
805c13fa60cSNick Hibma         /* Unless overridden in the config, take the server-provided renewal
806223c44aeSNick Hibma          * time if there is one. Otherwise figure it out according to the spec.
807c13fa60cSNick Hibma          * Also make sure the renewal time does not exceed the expiry time.
808c13fa60cSNick Hibma          */
809c13fa60cSNick Hibma         if (ip->client->config->default_actions[DHO_DHCP_RENEWAL_TIME] ==
810c13fa60cSNick Hibma             ACTION_SUPERSEDE)
811c13fa60cSNick Hibma 		ip->client->new->renewal = getULong(
812c13fa60cSNick Hibma 		    ip->client->config->defaults[DHO_DHCP_RENEWAL_TIME].data);
813c13fa60cSNick Hibma         else if (ip->client->new->options[DHO_DHCP_RENEWAL_TIME].len)
81447c08596SBrooks Davis 		ip->client->new->renewal = getULong(
81547c08596SBrooks Davis 		    ip->client->new->options[DHO_DHCP_RENEWAL_TIME].data);
81647c08596SBrooks Davis 	else
81747c08596SBrooks Davis 		ip->client->new->renewal = ip->client->new->expiry / 2;
818223c44aeSNick Hibma         if (ip->client->new->renewal < 0 ||
819223c44aeSNick Hibma             ip->client->new->renewal > ip->client->new->expiry / 2)
820c13fa60cSNick Hibma                 ip->client->new->renewal = ip->client->new->expiry / 2;
82147c08596SBrooks Davis 
82247c08596SBrooks Davis 	/* Same deal with the rebind time. */
823c13fa60cSNick Hibma         if (ip->client->config->default_actions[DHO_DHCP_REBINDING_TIME] ==
824c13fa60cSNick Hibma             ACTION_SUPERSEDE)
825c13fa60cSNick Hibma 		ip->client->new->rebind = getULong(
826c13fa60cSNick Hibma 		    ip->client->config->defaults[DHO_DHCP_REBINDING_TIME].data);
827c13fa60cSNick Hibma         else if (ip->client->new->options[DHO_DHCP_REBINDING_TIME].len)
82847c08596SBrooks Davis 		ip->client->new->rebind = getULong(
82947c08596SBrooks Davis 		    ip->client->new->options[DHO_DHCP_REBINDING_TIME].data);
83047c08596SBrooks Davis 	else
831223c44aeSNick Hibma 		ip->client->new->rebind = ip->client->new->renewal / 4 * 7;
832223c44aeSNick Hibma 	if (ip->client->new->rebind < 0 ||
833223c44aeSNick Hibma             ip->client->new->rebind > ip->client->new->renewal / 4 * 7)
834223c44aeSNick Hibma                 ip->client->new->rebind = ip->client->new->renewal / 4 * 7;
83547c08596SBrooks Davis 
836223c44aeSNick Hibma         /* Convert the time offsets into seconds-since-the-epoch */
83747c08596SBrooks Davis         ip->client->new->expiry += cur_time;
83847c08596SBrooks Davis         ip->client->new->renewal += cur_time;
83947c08596SBrooks Davis         ip->client->new->rebind += cur_time;
84047c08596SBrooks Davis 
84147c08596SBrooks Davis 	bind_lease(ip);
84247c08596SBrooks Davis }
84347c08596SBrooks Davis 
84447c08596SBrooks Davis void
84547c08596SBrooks Davis bind_lease(struct interface_info *ip)
84647c08596SBrooks Davis {
847387016a5SConrad Meyer 	struct option_data *opt;
848387016a5SConrad Meyer 
84947c08596SBrooks Davis 	/* Remember the medium. */
85047c08596SBrooks Davis 	ip->client->new->medium = ip->client->medium;
85147c08596SBrooks Davis 
852387016a5SConrad Meyer 	opt = &ip->client->new->options[DHO_INTERFACE_MTU];
853387016a5SConrad Meyer 	if (opt->len == sizeof(u_int16_t)) {
854f93497feSConrad Meyer 		u_int16_t mtu = 0;
855f93497feSConrad Meyer 		bool supersede = (ip->client->config->default_actions[DHO_INTERFACE_MTU] ==
856f93497feSConrad Meyer 			ACTION_SUPERSEDE);
857f93497feSConrad Meyer 
858f93497feSConrad Meyer 		if (supersede)
859f93497feSConrad Meyer 			mtu = getUShort(ip->client->config->defaults[DHO_INTERFACE_MTU].data);
860387016a5SConrad Meyer 		else
861f93497feSConrad Meyer 			mtu = be16dec(opt->data);
862f93497feSConrad Meyer 
863f93497feSConrad Meyer 		if (mtu < MIN_MTU) {
864f93497feSConrad Meyer 			/* Treat 0 like a user intentionally doesn't want to change MTU and,
865f93497feSConrad Meyer 			 * therefore, warning is not needed */
866f93497feSConrad Meyer 			if (!supersede || mtu != 0)
867f93497feSConrad Meyer 				warning("mtu size %u < %d: ignored", (unsigned)mtu, MIN_MTU);
868f93497feSConrad Meyer 		} else {
869387016a5SConrad Meyer 			interface_set_mtu_unpriv(privfd, mtu);
870387016a5SConrad Meyer 		}
871f93497feSConrad Meyer 	}
872387016a5SConrad Meyer 
87347c08596SBrooks Davis 	/* Write out the new lease. */
87447c08596SBrooks Davis 	write_client_lease(ip, ip->client->new, 0);
87547c08596SBrooks Davis 
87647c08596SBrooks Davis 	/* Run the client script with the new parameters. */
87747c08596SBrooks Davis 	script_init((ip->client->state == S_REQUESTING ? "BOUND" :
87847c08596SBrooks Davis 	    (ip->client->state == S_RENEWING ? "RENEW" :
87947c08596SBrooks Davis 	    (ip->client->state == S_REBOOTING ? "REBOOT" : "REBIND"))),
88047c08596SBrooks Davis 	    ip->client->new->medium);
88147c08596SBrooks Davis 	if (ip->client->active && ip->client->state != S_REBOOTING)
88247c08596SBrooks Davis 		script_write_params("old_", ip->client->active);
88347c08596SBrooks Davis 	script_write_params("new_", ip->client->new);
88447c08596SBrooks Davis 	if (ip->client->alias)
88547c08596SBrooks Davis 		script_write_params("alias_", ip->client->alias);
88647c08596SBrooks Davis 	script_go();
88747c08596SBrooks Davis 
88847c08596SBrooks Davis 	/* Replace the old active lease with the new one. */
88947c08596SBrooks Davis 	if (ip->client->active)
89047c08596SBrooks Davis 		free_client_lease(ip->client->active);
89147c08596SBrooks Davis 	ip->client->active = ip->client->new;
89247c08596SBrooks Davis 	ip->client->new = NULL;
89347c08596SBrooks Davis 
89447c08596SBrooks Davis 	/* Set up a timeout to start the renewal process. */
89547c08596SBrooks Davis 	add_timeout(ip->client->active->renewal, state_bound, ip);
89647c08596SBrooks Davis 
89747c08596SBrooks Davis 	note("bound to %s -- renewal in %d seconds.",
89847c08596SBrooks Davis 	    piaddr(ip->client->active->address),
8999c13d9cdSBrooks Davis 	    (int)(ip->client->active->renewal - cur_time));
90047c08596SBrooks Davis 	ip->client->state = S_BOUND;
90147c08596SBrooks Davis 	reinitialize_interfaces();
90247c08596SBrooks Davis 	go_daemon();
90347c08596SBrooks Davis }
90447c08596SBrooks Davis 
90547c08596SBrooks Davis /*
90647c08596SBrooks Davis  * state_bound is called when we've successfully bound to a particular
90747c08596SBrooks Davis  * lease, but the renewal time on that lease has expired.   We are
90847c08596SBrooks Davis  * expected to unicast a DHCPREQUEST to the server that gave us our
90947c08596SBrooks Davis  * original lease.
91047c08596SBrooks Davis  */
91147c08596SBrooks Davis void
91247c08596SBrooks Davis state_bound(void *ipp)
91347c08596SBrooks Davis {
91447c08596SBrooks Davis 	struct interface_info *ip = ipp;
91547c08596SBrooks Davis 
91647c08596SBrooks Davis 	ASSERT_STATE(state, S_BOUND);
91747c08596SBrooks Davis 
91847c08596SBrooks Davis 	/* T1 has expired. */
91947c08596SBrooks Davis 	make_request(ip, ip->client->active);
92047c08596SBrooks Davis 	ip->client->xid = ip->client->packet.xid;
92147c08596SBrooks Davis 
92247c08596SBrooks Davis 	if (ip->client->active->options[DHO_DHCP_SERVER_IDENTIFIER].len == 4) {
92347c08596SBrooks Davis 		memcpy(ip->client->destination.iabuf, ip->client->active->
92447c08596SBrooks Davis 		    options[DHO_DHCP_SERVER_IDENTIFIER].data, 4);
92547c08596SBrooks Davis 		ip->client->destination.len = 4;
92647c08596SBrooks Davis 	} else
92747c08596SBrooks Davis 		ip->client->destination = iaddr_broadcast;
92847c08596SBrooks Davis 
92947c08596SBrooks Davis 	ip->client->first_sending = cur_time;
93047c08596SBrooks Davis 	ip->client->interval = ip->client->config->initial_interval;
93147c08596SBrooks Davis 	ip->client->state = S_RENEWING;
93247c08596SBrooks Davis 
93347c08596SBrooks Davis 	/* Send the first packet immediately. */
93447c08596SBrooks Davis 	send_request(ip);
93547c08596SBrooks Davis }
93647c08596SBrooks Davis 
93747c08596SBrooks Davis void
93847c08596SBrooks Davis bootp(struct packet *packet)
93947c08596SBrooks Davis {
94047c08596SBrooks Davis 	struct iaddrlist *ap;
94147c08596SBrooks Davis 
94247c08596SBrooks Davis 	if (packet->raw->op != BOOTREPLY)
94347c08596SBrooks Davis 		return;
94447c08596SBrooks Davis 
94547c08596SBrooks Davis 	/* If there's a reject list, make sure this packet's sender isn't
94647c08596SBrooks Davis 	   on it. */
94747c08596SBrooks Davis 	for (ap = packet->interface->client->config->reject_list;
94847c08596SBrooks Davis 	    ap; ap = ap->next) {
94947c08596SBrooks Davis 		if (addr_eq(packet->client_addr, ap->addr)) {
95047c08596SBrooks Davis 			note("BOOTREPLY from %s rejected.", piaddr(ap->addr));
95147c08596SBrooks Davis 			return;
95247c08596SBrooks Davis 		}
95347c08596SBrooks Davis 	}
95447c08596SBrooks Davis 	dhcpoffer(packet);
95547c08596SBrooks Davis }
95647c08596SBrooks Davis 
95747c08596SBrooks Davis void
95847c08596SBrooks Davis dhcp(struct packet *packet)
95947c08596SBrooks Davis {
96047c08596SBrooks Davis 	struct iaddrlist *ap;
96147c08596SBrooks Davis 	void (*handler)(struct packet *);
96279a1d195SAlan Somers 	const char *type;
96347c08596SBrooks Davis 
96447c08596SBrooks Davis 	switch (packet->packet_type) {
96547c08596SBrooks Davis 	case DHCPOFFER:
96647c08596SBrooks Davis 		handler = dhcpoffer;
96747c08596SBrooks Davis 		type = "DHCPOFFER";
96847c08596SBrooks Davis 		break;
96947c08596SBrooks Davis 	case DHCPNAK:
97047c08596SBrooks Davis 		handler = dhcpnak;
97147c08596SBrooks Davis 		type = "DHCPNACK";
97247c08596SBrooks Davis 		break;
97347c08596SBrooks Davis 	case DHCPACK:
97447c08596SBrooks Davis 		handler = dhcpack;
97547c08596SBrooks Davis 		type = "DHCPACK";
97647c08596SBrooks Davis 		break;
97747c08596SBrooks Davis 	default:
97847c08596SBrooks Davis 		return;
97947c08596SBrooks Davis 	}
98047c08596SBrooks Davis 
98147c08596SBrooks Davis 	/* If there's a reject list, make sure this packet's sender isn't
98247c08596SBrooks Davis 	   on it. */
98347c08596SBrooks Davis 	for (ap = packet->interface->client->config->reject_list;
98447c08596SBrooks Davis 	    ap; ap = ap->next) {
98547c08596SBrooks Davis 		if (addr_eq(packet->client_addr, ap->addr)) {
98647c08596SBrooks Davis 			note("%s from %s rejected.", type, piaddr(ap->addr));
98747c08596SBrooks Davis 			return;
98847c08596SBrooks Davis 		}
98947c08596SBrooks Davis 	}
99047c08596SBrooks Davis 	(*handler)(packet);
99147c08596SBrooks Davis }
99247c08596SBrooks Davis 
99347c08596SBrooks Davis void
99447c08596SBrooks Davis dhcpoffer(struct packet *packet)
99547c08596SBrooks Davis {
99647c08596SBrooks Davis 	struct interface_info *ip = packet->interface;
99747c08596SBrooks Davis 	struct client_lease *lease, *lp;
99847c08596SBrooks Davis 	int i;
99947c08596SBrooks Davis 	int arp_timeout_needed, stop_selecting;
100079a1d195SAlan Somers 	const char *name = packet->options[DHO_DHCP_MESSAGE_TYPE].len ?
100147c08596SBrooks Davis 	    "DHCPOFFER" : "BOOTREPLY";
100247c08596SBrooks Davis 
100347c08596SBrooks Davis 	/* If we're not receptive to an offer right now, or if the offer
100447c08596SBrooks Davis 	   has an unrecognizable transaction id, then just drop it. */
100547c08596SBrooks Davis 	if (ip->client->state != S_SELECTING ||
100647c08596SBrooks Davis 	    packet->interface->client->xid != packet->raw->xid ||
100747c08596SBrooks Davis 	    (packet->interface->hw_address.hlen != packet->raw->hlen) ||
100847c08596SBrooks Davis 	    (memcmp(packet->interface->hw_address.haddr,
100947c08596SBrooks Davis 	    packet->raw->chaddr, packet->raw->hlen)))
101047c08596SBrooks Davis 		return;
101147c08596SBrooks Davis 
101247c08596SBrooks Davis 	note("%s from %s", name, piaddr(packet->client_addr));
101347c08596SBrooks Davis 
101447c08596SBrooks Davis 
101547c08596SBrooks Davis 	/* If this lease doesn't supply the minimum required parameters,
101647c08596SBrooks Davis 	   blow it off. */
101747c08596SBrooks Davis 	for (i = 0; ip->client->config->required_options[i]; i++) {
101847c08596SBrooks Davis 		if (!packet->options[ip->client->config->
101947c08596SBrooks Davis 		    required_options[i]].len) {
102047c08596SBrooks Davis 			note("%s isn't satisfactory.", name);
102147c08596SBrooks Davis 			return;
102247c08596SBrooks Davis 		}
102347c08596SBrooks Davis 	}
102447c08596SBrooks Davis 
102547c08596SBrooks Davis 	/* If we've already seen this lease, don't record it again. */
102647c08596SBrooks Davis 	for (lease = ip->client->offered_leases;
102747c08596SBrooks Davis 	    lease; lease = lease->next) {
102847c08596SBrooks Davis 		if (lease->address.len == sizeof(packet->raw->yiaddr) &&
102947c08596SBrooks Davis 		    !memcmp(lease->address.iabuf,
103047c08596SBrooks Davis 		    &packet->raw->yiaddr, lease->address.len)) {
103147c08596SBrooks Davis 			debug("%s already seen.", name);
103247c08596SBrooks Davis 			return;
103347c08596SBrooks Davis 		}
103447c08596SBrooks Davis 	}
103547c08596SBrooks Davis 
103647c08596SBrooks Davis 	lease = packet_to_lease(packet);
103747c08596SBrooks Davis 	if (!lease) {
103847c08596SBrooks Davis 		note("packet_to_lease failed.");
103947c08596SBrooks Davis 		return;
104047c08596SBrooks Davis 	}
104147c08596SBrooks Davis 
104247c08596SBrooks Davis 	/* If this lease was acquired through a BOOTREPLY, record that
104347c08596SBrooks Davis 	   fact. */
104447c08596SBrooks Davis 	if (!packet->options[DHO_DHCP_MESSAGE_TYPE].len)
104547c08596SBrooks Davis 		lease->is_bootp = 1;
104647c08596SBrooks Davis 
104747c08596SBrooks Davis 	/* Record the medium under which this lease was offered. */
104847c08596SBrooks Davis 	lease->medium = ip->client->medium;
104947c08596SBrooks Davis 
105047c08596SBrooks Davis 	/* Send out an ARP Request for the offered IP address. */
105147c08596SBrooks Davis 	script_init("ARPSEND", lease->medium);
105247c08596SBrooks Davis 	script_write_params("check_", lease);
105347c08596SBrooks Davis 	/* If the script can't send an ARP request without waiting,
105447c08596SBrooks Davis 	   we'll be waiting when we do the ARPCHECK, so don't wait now. */
105547c08596SBrooks Davis 	if (script_go())
105647c08596SBrooks Davis 		arp_timeout_needed = 0;
105747c08596SBrooks Davis 	else
105847c08596SBrooks Davis 		arp_timeout_needed = 2;
105947c08596SBrooks Davis 
106047c08596SBrooks Davis 	/* Figure out when we're supposed to stop selecting. */
106147c08596SBrooks Davis 	stop_selecting =
106247c08596SBrooks Davis 	    ip->client->first_sending + ip->client->config->select_interval;
106347c08596SBrooks Davis 
106447c08596SBrooks Davis 	/* If this is the lease we asked for, put it at the head of the
106547c08596SBrooks Davis 	   list, and don't mess with the arp request timeout. */
106647c08596SBrooks Davis 	if (lease->address.len == ip->client->requested_address.len &&
106747c08596SBrooks Davis 	    !memcmp(lease->address.iabuf,
106847c08596SBrooks Davis 	    ip->client->requested_address.iabuf,
106947c08596SBrooks Davis 	    ip->client->requested_address.len)) {
107047c08596SBrooks Davis 		lease->next = ip->client->offered_leases;
107147c08596SBrooks Davis 		ip->client->offered_leases = lease;
107247c08596SBrooks Davis 	} else {
107347c08596SBrooks Davis 		/* If we already have an offer, and arping for this
107447c08596SBrooks Davis 		   offer would take us past the selection timeout,
107547c08596SBrooks Davis 		   then don't extend the timeout - just hope for the
107647c08596SBrooks Davis 		   best. */
107747c08596SBrooks Davis 		if (ip->client->offered_leases &&
107847c08596SBrooks Davis 		    (cur_time + arp_timeout_needed) > stop_selecting)
107947c08596SBrooks Davis 			arp_timeout_needed = 0;
108047c08596SBrooks Davis 
108147c08596SBrooks Davis 		/* Put the lease at the end of the list. */
108247c08596SBrooks Davis 		lease->next = NULL;
108347c08596SBrooks Davis 		if (!ip->client->offered_leases)
108447c08596SBrooks Davis 			ip->client->offered_leases = lease;
108547c08596SBrooks Davis 		else {
108647c08596SBrooks Davis 			for (lp = ip->client->offered_leases; lp->next;
108747c08596SBrooks Davis 			    lp = lp->next)
108847c08596SBrooks Davis 				;	/* nothing */
108947c08596SBrooks Davis 			lp->next = lease;
109047c08596SBrooks Davis 		}
109147c08596SBrooks Davis 	}
109247c08596SBrooks Davis 
109347c08596SBrooks Davis 	/* If we're supposed to stop selecting before we've had time
109447c08596SBrooks Davis 	   to wait for the ARPREPLY, add some delay to wait for
109547c08596SBrooks Davis 	   the ARPREPLY. */
109647c08596SBrooks Davis 	if (stop_selecting - cur_time < arp_timeout_needed)
109747c08596SBrooks Davis 		stop_selecting = cur_time + arp_timeout_needed;
109847c08596SBrooks Davis 
109947c08596SBrooks Davis 	/* If the selecting interval has expired, go immediately to
110047c08596SBrooks Davis 	   state_selecting().  Otherwise, time out into
110147c08596SBrooks Davis 	   state_selecting at the select interval. */
110247c08596SBrooks Davis 	if (stop_selecting <= 0)
110347c08596SBrooks Davis 		state_selecting(ip);
110447c08596SBrooks Davis 	else {
110547c08596SBrooks Davis 		add_timeout(stop_selecting, state_selecting, ip);
110647c08596SBrooks Davis 		cancel_timeout(send_discover, ip);
110747c08596SBrooks Davis 	}
110847c08596SBrooks Davis }
110947c08596SBrooks Davis 
111047c08596SBrooks Davis /* Allocate a client_lease structure and initialize it from the parameters
111147c08596SBrooks Davis    in the specified packet. */
111247c08596SBrooks Davis 
111347c08596SBrooks Davis struct client_lease *
111447c08596SBrooks Davis packet_to_lease(struct packet *packet)
111547c08596SBrooks Davis {
111647c08596SBrooks Davis 	struct client_lease *lease;
111747c08596SBrooks Davis 	int i;
111847c08596SBrooks Davis 
111947c08596SBrooks Davis 	lease = malloc(sizeof(struct client_lease));
112047c08596SBrooks Davis 
112147c08596SBrooks Davis 	if (!lease) {
112247c08596SBrooks Davis 		warning("dhcpoffer: no memory to record lease.");
112347c08596SBrooks Davis 		return (NULL);
112447c08596SBrooks Davis 	}
112547c08596SBrooks Davis 
112647c08596SBrooks Davis 	memset(lease, 0, sizeof(*lease));
112747c08596SBrooks Davis 
112847c08596SBrooks Davis 	/* Copy the lease options. */
112947c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
113047c08596SBrooks Davis 		if (packet->options[i].len) {
113147c08596SBrooks Davis 			lease->options[i].data =
113247c08596SBrooks Davis 			    malloc(packet->options[i].len + 1);
113347c08596SBrooks Davis 			if (!lease->options[i].data) {
113447c08596SBrooks Davis 				warning("dhcpoffer: no memory for option %d", i);
113547c08596SBrooks Davis 				free_client_lease(lease);
113647c08596SBrooks Davis 				return (NULL);
113747c08596SBrooks Davis 			} else {
113847c08596SBrooks Davis 				memcpy(lease->options[i].data,
113947c08596SBrooks Davis 				    packet->options[i].data,
114047c08596SBrooks Davis 				    packet->options[i].len);
114147c08596SBrooks Davis 				lease->options[i].len =
114247c08596SBrooks Davis 				    packet->options[i].len;
114347c08596SBrooks Davis 				lease->options[i].data[lease->options[i].len] =
114447c08596SBrooks Davis 				    0;
114547c08596SBrooks Davis 			}
114647c08596SBrooks Davis 			if (!check_option(lease,i)) {
114747c08596SBrooks Davis 				/* ignore a bogus lease offer */
114847c08596SBrooks Davis 				warning("Invalid lease option - ignoring offer");
114947c08596SBrooks Davis 				free_client_lease(lease);
115047c08596SBrooks Davis 				return (NULL);
115147c08596SBrooks Davis 			}
115247c08596SBrooks Davis 		}
115347c08596SBrooks Davis 	}
115447c08596SBrooks Davis 
115547c08596SBrooks Davis 	lease->address.len = sizeof(packet->raw->yiaddr);
115647c08596SBrooks Davis 	memcpy(lease->address.iabuf, &packet->raw->yiaddr, lease->address.len);
115747c08596SBrooks Davis 
1158d32438c3SBruce M Simpson 	lease->nextserver.len = sizeof(packet->raw->siaddr);
1159d32438c3SBruce M Simpson 	memcpy(lease->nextserver.iabuf, &packet->raw->siaddr, lease->nextserver.len);
1160d32438c3SBruce M Simpson 
1161acccb9aaSBrooks Davis 	/* If the server name was filled out, copy it.
1162acccb9aaSBrooks Davis 	   Do not attempt to validate the server name as a host name.
1163acccb9aaSBrooks Davis 	   RFC 2131 merely states that sname is NUL-terminated (which do
1164acccb9aaSBrooks Davis 	   do not assume) and that it is the server's host name.  Since
1165acccb9aaSBrooks Davis 	   the ISC client and server allow arbitrary characters, we do
1166acccb9aaSBrooks Davis 	   as well. */
116747c08596SBrooks Davis 	if ((!packet->options[DHO_DHCP_OPTION_OVERLOAD].len ||
116847c08596SBrooks Davis 	    !(packet->options[DHO_DHCP_OPTION_OVERLOAD].data[0] & 2)) &&
116947c08596SBrooks Davis 	    packet->raw->sname[0]) {
117047c08596SBrooks Davis 		lease->server_name = malloc(DHCP_SNAME_LEN + 1);
117147c08596SBrooks Davis 		if (!lease->server_name) {
117247c08596SBrooks Davis 			warning("dhcpoffer: no memory for server name.");
117347c08596SBrooks Davis 			free_client_lease(lease);
117447c08596SBrooks Davis 			return (NULL);
117547c08596SBrooks Davis 		}
117647c08596SBrooks Davis 		memcpy(lease->server_name, packet->raw->sname, DHCP_SNAME_LEN);
117747c08596SBrooks Davis 		lease->server_name[DHCP_SNAME_LEN]='\0';
117847c08596SBrooks Davis 	}
117947c08596SBrooks Davis 
118047c08596SBrooks Davis 	/* Ditto for the filename. */
118147c08596SBrooks Davis 	if ((!packet->options[DHO_DHCP_OPTION_OVERLOAD].len ||
118247c08596SBrooks Davis 	    !(packet->options[DHO_DHCP_OPTION_OVERLOAD].data[0] & 1)) &&
118347c08596SBrooks Davis 	    packet->raw->file[0]) {
118447c08596SBrooks Davis 		/* Don't count on the NUL terminator. */
118547c08596SBrooks Davis 		lease->filename = malloc(DHCP_FILE_LEN + 1);
118647c08596SBrooks Davis 		if (!lease->filename) {
118747c08596SBrooks Davis 			warning("dhcpoffer: no memory for filename.");
118847c08596SBrooks Davis 			free_client_lease(lease);
118947c08596SBrooks Davis 			return (NULL);
119047c08596SBrooks Davis 		}
119147c08596SBrooks Davis 		memcpy(lease->filename, packet->raw->file, DHCP_FILE_LEN);
119247c08596SBrooks Davis 		lease->filename[DHCP_FILE_LEN]='\0';
119347c08596SBrooks Davis 	}
119447c08596SBrooks Davis 	return lease;
119547c08596SBrooks Davis }
119647c08596SBrooks Davis 
119747c08596SBrooks Davis void
119847c08596SBrooks Davis dhcpnak(struct packet *packet)
119947c08596SBrooks Davis {
120047c08596SBrooks Davis 	struct interface_info *ip = packet->interface;
120147c08596SBrooks Davis 
120247c08596SBrooks Davis 	/* If we're not receptive to an offer right now, or if the offer
120347c08596SBrooks Davis 	   has an unrecognizable transaction id, then just drop it. */
120447c08596SBrooks Davis 	if (packet->interface->client->xid != packet->raw->xid ||
120547c08596SBrooks Davis 	    (packet->interface->hw_address.hlen != packet->raw->hlen) ||
120647c08596SBrooks Davis 	    (memcmp(packet->interface->hw_address.haddr,
120747c08596SBrooks Davis 	    packet->raw->chaddr, packet->raw->hlen)))
120847c08596SBrooks Davis 		return;
120947c08596SBrooks Davis 
121047c08596SBrooks Davis 	if (ip->client->state != S_REBOOTING &&
121147c08596SBrooks Davis 	    ip->client->state != S_REQUESTING &&
121247c08596SBrooks Davis 	    ip->client->state != S_RENEWING &&
121347c08596SBrooks Davis 	    ip->client->state != S_REBINDING)
121447c08596SBrooks Davis 		return;
121547c08596SBrooks Davis 
121647c08596SBrooks Davis 	note("DHCPNAK from %s", piaddr(packet->client_addr));
121747c08596SBrooks Davis 
121847c08596SBrooks Davis 	if (!ip->client->active) {
121947c08596SBrooks Davis 		note("DHCPNAK with no active lease.\n");
122047c08596SBrooks Davis 		return;
122147c08596SBrooks Davis 	}
122247c08596SBrooks Davis 
122347c08596SBrooks Davis 	free_client_lease(ip->client->active);
122447c08596SBrooks Davis 	ip->client->active = NULL;
122547c08596SBrooks Davis 
122647c08596SBrooks Davis 	/* Stop sending DHCPREQUEST packets... */
122747c08596SBrooks Davis 	cancel_timeout(send_request, ip);
122847c08596SBrooks Davis 
122947c08596SBrooks Davis 	ip->client->state = S_INIT;
123047c08596SBrooks Davis 	state_init(ip);
123147c08596SBrooks Davis }
123247c08596SBrooks Davis 
123347c08596SBrooks Davis /* Send out a DHCPDISCOVER packet, and set a timeout to send out another
123447c08596SBrooks Davis    one after the right interval has expired.  If we don't get an offer by
123547c08596SBrooks Davis    the time we reach the panic interval, call the panic function. */
123647c08596SBrooks Davis 
123747c08596SBrooks Davis void
123847c08596SBrooks Davis send_discover(void *ipp)
123947c08596SBrooks Davis {
124047c08596SBrooks Davis 	struct interface_info *ip = ipp;
124147c08596SBrooks Davis 	int interval, increase = 1;
124247c08596SBrooks Davis 
124347c08596SBrooks Davis 	/* Figure out how long it's been since we started transmitting. */
124447c08596SBrooks Davis 	interval = cur_time - ip->client->first_sending;
124547c08596SBrooks Davis 
124647c08596SBrooks Davis 	/* If we're past the panic timeout, call the script and tell it
124747c08596SBrooks Davis 	   we haven't found anything for this interface yet. */
124847c08596SBrooks Davis 	if (interval > ip->client->config->timeout) {
124947c08596SBrooks Davis 		state_panic(ip);
125047c08596SBrooks Davis 		return;
125147c08596SBrooks Davis 	}
125247c08596SBrooks Davis 
125347c08596SBrooks Davis 	/* If we're selecting media, try the whole list before doing
125447c08596SBrooks Davis 	   the exponential backoff, but if we've already received an
125547c08596SBrooks Davis 	   offer, stop looping, because we obviously have it right. */
125647c08596SBrooks Davis 	if (!ip->client->offered_leases &&
125747c08596SBrooks Davis 	    ip->client->config->media) {
125847c08596SBrooks Davis 		int fail = 0;
125947c08596SBrooks Davis again:
126047c08596SBrooks Davis 		if (ip->client->medium) {
126147c08596SBrooks Davis 			ip->client->medium = ip->client->medium->next;
126247c08596SBrooks Davis 			increase = 0;
126347c08596SBrooks Davis 		}
126447c08596SBrooks Davis 		if (!ip->client->medium) {
126547c08596SBrooks Davis 			if (fail)
126647c08596SBrooks Davis 				error("No valid media types for %s!", ip->name);
126747c08596SBrooks Davis 			ip->client->medium = ip->client->config->media;
126847c08596SBrooks Davis 			increase = 1;
126947c08596SBrooks Davis 		}
127047c08596SBrooks Davis 
127147c08596SBrooks Davis 		note("Trying medium \"%s\" %d", ip->client->medium->string,
127247c08596SBrooks Davis 		    increase);
127347c08596SBrooks Davis 		script_init("MEDIUM", ip->client->medium);
127447c08596SBrooks Davis 		if (script_go())
127547c08596SBrooks Davis 			goto again;
127647c08596SBrooks Davis 	}
127747c08596SBrooks Davis 
127847c08596SBrooks Davis 	/*
127947c08596SBrooks Davis 	 * If we're supposed to increase the interval, do so.  If it's
128047c08596SBrooks Davis 	 * currently zero (i.e., we haven't sent any packets yet), set
128147c08596SBrooks Davis 	 * it to one; otherwise, add to it a random number between zero
128247c08596SBrooks Davis 	 * and two times itself.  On average, this means that it will
128347c08596SBrooks Davis 	 * double with every transmission.
128447c08596SBrooks Davis 	 */
128547c08596SBrooks Davis 	if (increase) {
128647c08596SBrooks Davis 		if (!ip->client->interval)
128747c08596SBrooks Davis 			ip->client->interval =
128847c08596SBrooks Davis 			    ip->client->config->initial_interval;
128947c08596SBrooks Davis 		else {
129047c08596SBrooks Davis 			ip->client->interval += (arc4random() >> 2) %
129147c08596SBrooks Davis 			    (2 * ip->client->interval);
129247c08596SBrooks Davis 		}
129347c08596SBrooks Davis 
129447c08596SBrooks Davis 		/* Don't backoff past cutoff. */
129547c08596SBrooks Davis 		if (ip->client->interval >
129647c08596SBrooks Davis 		    ip->client->config->backoff_cutoff)
129747c08596SBrooks Davis 			ip->client->interval =
129847c08596SBrooks Davis 				((ip->client->config->backoff_cutoff / 2)
129947c08596SBrooks Davis 				 + ((arc4random() >> 2) %
130047c08596SBrooks Davis 				    ip->client->config->backoff_cutoff));
130147c08596SBrooks Davis 	} else if (!ip->client->interval)
130247c08596SBrooks Davis 		ip->client->interval =
130347c08596SBrooks Davis 			ip->client->config->initial_interval;
130447c08596SBrooks Davis 
130547c08596SBrooks Davis 	/* If the backoff would take us to the panic timeout, just use that
130647c08596SBrooks Davis 	   as the interval. */
130747c08596SBrooks Davis 	if (cur_time + ip->client->interval >
130847c08596SBrooks Davis 	    ip->client->first_sending + ip->client->config->timeout)
130947c08596SBrooks Davis 		ip->client->interval =
131047c08596SBrooks Davis 			(ip->client->first_sending +
131147c08596SBrooks Davis 			 ip->client->config->timeout) - cur_time + 1;
131247c08596SBrooks Davis 
131347c08596SBrooks Davis 	/* Record the number of seconds since we started sending. */
131447c08596SBrooks Davis 	if (interval < 65536)
131547c08596SBrooks Davis 		ip->client->packet.secs = htons(interval);
131647c08596SBrooks Davis 	else
131747c08596SBrooks Davis 		ip->client->packet.secs = htons(65535);
131847c08596SBrooks Davis 	ip->client->secs = ip->client->packet.secs;
131947c08596SBrooks Davis 
132047c08596SBrooks Davis 	note("DHCPDISCOVER on %s to %s port %d interval %d",
1321ba019ae5SPawel Jakub Dawidek 	    ip->name, inet_ntoa(inaddr_broadcast), REMOTE_PORT,
13229c13d9cdSBrooks Davis 	    (int)ip->client->interval);
132347c08596SBrooks Davis 
132447c08596SBrooks Davis 	/* Send out a packet. */
1325235eb530SPawel Jakub Dawidek 	send_packet_unpriv(privfd, &ip->client->packet,
1326235eb530SPawel Jakub Dawidek 	    ip->client->packet_length, inaddr_any, inaddr_broadcast);
132747c08596SBrooks Davis 
132847c08596SBrooks Davis 	add_timeout(cur_time + ip->client->interval, send_discover, ip);
132947c08596SBrooks Davis }
133047c08596SBrooks Davis 
133147c08596SBrooks Davis /*
133247c08596SBrooks Davis  * state_panic gets called if we haven't received any offers in a preset
133347c08596SBrooks Davis  * amount of time.   When this happens, we try to use existing leases
133447c08596SBrooks Davis  * that haven't yet expired, and failing that, we call the client script
133547c08596SBrooks Davis  * and hope it can do something.
133647c08596SBrooks Davis  */
133747c08596SBrooks Davis void
133847c08596SBrooks Davis state_panic(void *ipp)
133947c08596SBrooks Davis {
134047c08596SBrooks Davis 	struct interface_info *ip = ipp;
134147c08596SBrooks Davis 	struct client_lease *loop = ip->client->active;
134247c08596SBrooks Davis 	struct client_lease *lp;
134347c08596SBrooks Davis 
134447c08596SBrooks Davis 	note("No DHCPOFFERS received.");
134547c08596SBrooks Davis 
134647c08596SBrooks Davis 	/* We may not have an active lease, but we may have some
134747c08596SBrooks Davis 	   predefined leases that we can try. */
134847c08596SBrooks Davis 	if (!ip->client->active && ip->client->leases)
134947c08596SBrooks Davis 		goto activate_next;
135047c08596SBrooks Davis 
135147c08596SBrooks Davis 	/* Run through the list of leases and see if one can be used. */
135247c08596SBrooks Davis 	while (ip->client->active) {
135347c08596SBrooks Davis 		if (ip->client->active->expiry > cur_time) {
135447c08596SBrooks Davis 			note("Trying recorded lease %s",
135547c08596SBrooks Davis 			    piaddr(ip->client->active->address));
135647c08596SBrooks Davis 			/* Run the client script with the existing
135747c08596SBrooks Davis 			   parameters. */
135847c08596SBrooks Davis 			script_init("TIMEOUT",
135947c08596SBrooks Davis 			    ip->client->active->medium);
136047c08596SBrooks Davis 			script_write_params("new_", ip->client->active);
136147c08596SBrooks Davis 			if (ip->client->alias)
136247c08596SBrooks Davis 				script_write_params("alias_",
136347c08596SBrooks Davis 				    ip->client->alias);
136447c08596SBrooks Davis 
136547c08596SBrooks Davis 			/* If the old lease is still good and doesn't
136647c08596SBrooks Davis 			   yet need renewal, go into BOUND state and
136747c08596SBrooks Davis 			   timeout at the renewal time. */
136847c08596SBrooks Davis 			if (!script_go()) {
136947c08596SBrooks Davis 				if (cur_time <
137047c08596SBrooks Davis 				    ip->client->active->renewal) {
137147c08596SBrooks Davis 					ip->client->state = S_BOUND;
137247c08596SBrooks Davis 					note("bound: renewal in %d seconds.",
13739c13d9cdSBrooks Davis 					    (int)(ip->client->active->renewal -
13749c13d9cdSBrooks Davis 					    cur_time));
137547c08596SBrooks Davis 					add_timeout(
137647c08596SBrooks Davis 					    ip->client->active->renewal,
137747c08596SBrooks Davis 					    state_bound, ip);
137847c08596SBrooks Davis 				} else {
137947c08596SBrooks Davis 					ip->client->state = S_BOUND;
138047c08596SBrooks Davis 					note("bound: immediate renewal.");
138147c08596SBrooks Davis 					state_bound(ip);
138247c08596SBrooks Davis 				}
138347c08596SBrooks Davis 				reinitialize_interfaces();
138447c08596SBrooks Davis 				go_daemon();
138547c08596SBrooks Davis 				return;
138647c08596SBrooks Davis 			}
138747c08596SBrooks Davis 		}
138847c08596SBrooks Davis 
138947c08596SBrooks Davis 		/* If there are no other leases, give up. */
139047c08596SBrooks Davis 		if (!ip->client->leases) {
139147c08596SBrooks Davis 			ip->client->leases = ip->client->active;
139247c08596SBrooks Davis 			ip->client->active = NULL;
139347c08596SBrooks Davis 			break;
139447c08596SBrooks Davis 		}
139547c08596SBrooks Davis 
139647c08596SBrooks Davis activate_next:
139747c08596SBrooks Davis 		/* Otherwise, put the active lease at the end of the
139847c08596SBrooks Davis 		   lease list, and try another lease.. */
139947c08596SBrooks Davis 		for (lp = ip->client->leases; lp->next; lp = lp->next)
140047c08596SBrooks Davis 			;
140147c08596SBrooks Davis 		lp->next = ip->client->active;
140247c08596SBrooks Davis 		if (lp->next)
140347c08596SBrooks Davis 			lp->next->next = NULL;
140447c08596SBrooks Davis 		ip->client->active = ip->client->leases;
140547c08596SBrooks Davis 		ip->client->leases = ip->client->leases->next;
140647c08596SBrooks Davis 
140747c08596SBrooks Davis 		/* If we already tried this lease, we've exhausted the
140847c08596SBrooks Davis 		   set of leases, so we might as well give up for
140947c08596SBrooks Davis 		   now. */
141047c08596SBrooks Davis 		if (ip->client->active == loop)
141147c08596SBrooks Davis 			break;
141247c08596SBrooks Davis 		else if (!loop)
141347c08596SBrooks Davis 			loop = ip->client->active;
141447c08596SBrooks Davis 	}
141547c08596SBrooks Davis 
141647c08596SBrooks Davis 	/* No leases were available, or what was available didn't work, so
141747c08596SBrooks Davis 	   tell the shell script that we failed to allocate an address,
141847c08596SBrooks Davis 	   and try again later. */
141947c08596SBrooks Davis 	note("No working leases in persistent database - sleeping.\n");
142047c08596SBrooks Davis 	script_init("FAIL", NULL);
142147c08596SBrooks Davis 	if (ip->client->alias)
142247c08596SBrooks Davis 		script_write_params("alias_", ip->client->alias);
142347c08596SBrooks Davis 	script_go();
142447c08596SBrooks Davis 	ip->client->state = S_INIT;
142547c08596SBrooks Davis 	add_timeout(cur_time + ip->client->config->retry_interval, state_init,
142647c08596SBrooks Davis 	    ip);
142747c08596SBrooks Davis 	go_daemon();
142847c08596SBrooks Davis }
142947c08596SBrooks Davis 
143047c08596SBrooks Davis void
143147c08596SBrooks Davis send_request(void *ipp)
143247c08596SBrooks Davis {
143347c08596SBrooks Davis 	struct interface_info *ip = ipp;
1434ba019ae5SPawel Jakub Dawidek 	struct in_addr from, to;
143547c08596SBrooks Davis 	int interval;
143647c08596SBrooks Davis 
143747c08596SBrooks Davis 	/* Figure out how long it's been since we started transmitting. */
143847c08596SBrooks Davis 	interval = cur_time - ip->client->first_sending;
143947c08596SBrooks Davis 
144047c08596SBrooks Davis 	/* If we're in the INIT-REBOOT or REQUESTING state and we're
144147c08596SBrooks Davis 	   past the reboot timeout, go to INIT and see if we can
144247c08596SBrooks Davis 	   DISCOVER an address... */
144347c08596SBrooks Davis 	/* XXX In the INIT-REBOOT state, if we don't get an ACK, it
144447c08596SBrooks Davis 	   means either that we're on a network with no DHCP server,
144547c08596SBrooks Davis 	   or that our server is down.  In the latter case, assuming
144647c08596SBrooks Davis 	   that there is a backup DHCP server, DHCPDISCOVER will get
144747c08596SBrooks Davis 	   us a new address, but we could also have successfully
144847c08596SBrooks Davis 	   reused our old address.  In the former case, we're hosed
144947c08596SBrooks Davis 	   anyway.  This is not a win-prone situation. */
145047c08596SBrooks Davis 	if ((ip->client->state == S_REBOOTING ||
145147c08596SBrooks Davis 	    ip->client->state == S_REQUESTING) &&
145247c08596SBrooks Davis 	    interval > ip->client->config->reboot_timeout) {
145347c08596SBrooks Davis cancel:
145447c08596SBrooks Davis 		ip->client->state = S_INIT;
145547c08596SBrooks Davis 		cancel_timeout(send_request, ip);
145647c08596SBrooks Davis 		state_init(ip);
145747c08596SBrooks Davis 		return;
145847c08596SBrooks Davis 	}
145947c08596SBrooks Davis 
146047c08596SBrooks Davis 	/* If we're in the reboot state, make sure the media is set up
146147c08596SBrooks Davis 	   correctly. */
146247c08596SBrooks Davis 	if (ip->client->state == S_REBOOTING &&
146347c08596SBrooks Davis 	    !ip->client->medium &&
146447c08596SBrooks Davis 	    ip->client->active->medium ) {
146547c08596SBrooks Davis 		script_init("MEDIUM", ip->client->active->medium);
146647c08596SBrooks Davis 
146747c08596SBrooks Davis 		/* If the medium we chose won't fly, go to INIT state. */
146847c08596SBrooks Davis 		if (script_go())
146947c08596SBrooks Davis 			goto cancel;
147047c08596SBrooks Davis 
147147c08596SBrooks Davis 		/* Record the medium. */
147247c08596SBrooks Davis 		ip->client->medium = ip->client->active->medium;
147347c08596SBrooks Davis 	}
147447c08596SBrooks Davis 
147547c08596SBrooks Davis 	/* If the lease has expired, relinquish the address and go back
147647c08596SBrooks Davis 	   to the INIT state. */
147747c08596SBrooks Davis 	if (ip->client->state != S_REQUESTING &&
147847c08596SBrooks Davis 	    cur_time > ip->client->active->expiry) {
147947c08596SBrooks Davis 		/* Run the client script with the new parameters. */
148047c08596SBrooks Davis 		script_init("EXPIRE", NULL);
148147c08596SBrooks Davis 		script_write_params("old_", ip->client->active);
148247c08596SBrooks Davis 		if (ip->client->alias)
148347c08596SBrooks Davis 			script_write_params("alias_", ip->client->alias);
148447c08596SBrooks Davis 		script_go();
148547c08596SBrooks Davis 
148647c08596SBrooks Davis 		/* Now do a preinit on the interface so that we can
148747c08596SBrooks Davis 		   discover a new address. */
148847c08596SBrooks Davis 		script_init("PREINIT", NULL);
148947c08596SBrooks Davis 		if (ip->client->alias)
149047c08596SBrooks Davis 			script_write_params("alias_", ip->client->alias);
149147c08596SBrooks Davis 		script_go();
149247c08596SBrooks Davis 
149347c08596SBrooks Davis 		ip->client->state = S_INIT;
149447c08596SBrooks Davis 		state_init(ip);
149547c08596SBrooks Davis 		return;
149647c08596SBrooks Davis 	}
149747c08596SBrooks Davis 
149847c08596SBrooks Davis 	/* Do the exponential backoff... */
149947c08596SBrooks Davis 	if (!ip->client->interval)
150047c08596SBrooks Davis 		ip->client->interval = ip->client->config->initial_interval;
150147c08596SBrooks Davis 	else
150247c08596SBrooks Davis 		ip->client->interval += ((arc4random() >> 2) %
150347c08596SBrooks Davis 		    (2 * ip->client->interval));
150447c08596SBrooks Davis 
150547c08596SBrooks Davis 	/* Don't backoff past cutoff. */
150647c08596SBrooks Davis 	if (ip->client->interval >
150747c08596SBrooks Davis 	    ip->client->config->backoff_cutoff)
150847c08596SBrooks Davis 		ip->client->interval =
150947c08596SBrooks Davis 		    ((ip->client->config->backoff_cutoff / 2) +
151047c08596SBrooks Davis 		    ((arc4random() >> 2) % ip->client->interval));
151147c08596SBrooks Davis 
151247c08596SBrooks Davis 	/* If the backoff would take us to the expiry time, just set the
151347c08596SBrooks Davis 	   timeout to the expiry time. */
151447c08596SBrooks Davis 	if (ip->client->state != S_REQUESTING &&
151547c08596SBrooks Davis 	    cur_time + ip->client->interval >
151647c08596SBrooks Davis 	    ip->client->active->expiry)
151747c08596SBrooks Davis 		ip->client->interval =
151847c08596SBrooks Davis 		    ip->client->active->expiry - cur_time + 1;
151947c08596SBrooks Davis 
152047c08596SBrooks Davis 	/* If the lease T2 time has elapsed, or if we're not yet bound,
152147c08596SBrooks Davis 	   broadcast the DHCPREQUEST rather than unicasting. */
152247c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING ||
152347c08596SBrooks Davis 	    ip->client->state == S_REBOOTING ||
152447c08596SBrooks Davis 	    cur_time > ip->client->active->rebind)
1525ba019ae5SPawel Jakub Dawidek 		to.s_addr = INADDR_BROADCAST;
152647c08596SBrooks Davis 	else
1527ba019ae5SPawel Jakub Dawidek 		memcpy(&to.s_addr, ip->client->destination.iabuf,
1528ba019ae5SPawel Jakub Dawidek 		    sizeof(to.s_addr));
152947c08596SBrooks Davis 
15303acf1760SDavid Bright 	if (ip->client->state != S_REQUESTING &&
15313acf1760SDavid Bright 	    ip->client->state != S_REBOOTING)
153247c08596SBrooks Davis 		memcpy(&from, ip->client->active->address.iabuf,
153347c08596SBrooks Davis 		    sizeof(from));
153447c08596SBrooks Davis 	else
153547c08596SBrooks Davis 		from.s_addr = INADDR_ANY;
153647c08596SBrooks Davis 
153747c08596SBrooks Davis 	/* Record the number of seconds since we started sending. */
153847c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING)
153947c08596SBrooks Davis 		ip->client->packet.secs = ip->client->secs;
154047c08596SBrooks Davis 	else {
154147c08596SBrooks Davis 		if (interval < 65536)
154247c08596SBrooks Davis 			ip->client->packet.secs = htons(interval);
154347c08596SBrooks Davis 		else
154447c08596SBrooks Davis 			ip->client->packet.secs = htons(65535);
154547c08596SBrooks Davis 	}
154647c08596SBrooks Davis 
1547ba019ae5SPawel Jakub Dawidek 	note("DHCPREQUEST on %s to %s port %d", ip->name, inet_ntoa(to),
1548ba019ae5SPawel Jakub Dawidek 	    REMOTE_PORT);
154947c08596SBrooks Davis 
155047c08596SBrooks Davis 	/* Send out a packet. */
1551235eb530SPawel Jakub Dawidek 	send_packet_unpriv(privfd, &ip->client->packet,
1552235eb530SPawel Jakub Dawidek 	    ip->client->packet_length, from, to);
155347c08596SBrooks Davis 
155447c08596SBrooks Davis 	add_timeout(cur_time + ip->client->interval, send_request, ip);
155547c08596SBrooks Davis }
155647c08596SBrooks Davis 
155747c08596SBrooks Davis void
155847c08596SBrooks Davis send_decline(void *ipp)
155947c08596SBrooks Davis {
156047c08596SBrooks Davis 	struct interface_info *ip = ipp;
156147c08596SBrooks Davis 
156247c08596SBrooks Davis 	note("DHCPDECLINE on %s to %s port %d", ip->name,
1563ba019ae5SPawel Jakub Dawidek 	    inet_ntoa(inaddr_broadcast), REMOTE_PORT);
156447c08596SBrooks Davis 
156547c08596SBrooks Davis 	/* Send out a packet. */
1566235eb530SPawel Jakub Dawidek 	send_packet_unpriv(privfd, &ip->client->packet,
1567235eb530SPawel Jakub Dawidek 	    ip->client->packet_length, inaddr_any, inaddr_broadcast);
156847c08596SBrooks Davis }
156947c08596SBrooks Davis 
157047c08596SBrooks Davis void
157147c08596SBrooks Davis make_discover(struct interface_info *ip, struct client_lease *lease)
157247c08596SBrooks Davis {
157347c08596SBrooks Davis 	unsigned char discover = DHCPDISCOVER;
157447c08596SBrooks Davis 	struct tree_cache *options[256];
157547c08596SBrooks Davis 	struct tree_cache option_elements[256];
157647c08596SBrooks Davis 	int i;
157747c08596SBrooks Davis 
157847c08596SBrooks Davis 	memset(option_elements, 0, sizeof(option_elements));
157947c08596SBrooks Davis 	memset(options, 0, sizeof(options));
158047c08596SBrooks Davis 	memset(&ip->client->packet, 0, sizeof(ip->client->packet));
158147c08596SBrooks Davis 
158247c08596SBrooks Davis 	/* Set DHCP_MESSAGE_TYPE to DHCPDISCOVER */
158347c08596SBrooks Davis 	i = DHO_DHCP_MESSAGE_TYPE;
158447c08596SBrooks Davis 	options[i] = &option_elements[i];
158547c08596SBrooks Davis 	options[i]->value = &discover;
158647c08596SBrooks Davis 	options[i]->len = sizeof(discover);
158747c08596SBrooks Davis 	options[i]->buf_size = sizeof(discover);
158847c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
158947c08596SBrooks Davis 
159047c08596SBrooks Davis 	/* Request the options we want */
159147c08596SBrooks Davis 	i  = DHO_DHCP_PARAMETER_REQUEST_LIST;
159247c08596SBrooks Davis 	options[i] = &option_elements[i];
159347c08596SBrooks Davis 	options[i]->value = ip->client->config->requested_options;
159447c08596SBrooks Davis 	options[i]->len = ip->client->config->requested_option_count;
159547c08596SBrooks Davis 	options[i]->buf_size =
159647c08596SBrooks Davis 		ip->client->config->requested_option_count;
159747c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
159847c08596SBrooks Davis 
159947c08596SBrooks Davis 	/* If we had an address, try to get it again. */
160047c08596SBrooks Davis 	if (lease) {
160147c08596SBrooks Davis 		ip->client->requested_address = lease->address;
160247c08596SBrooks Davis 		i = DHO_DHCP_REQUESTED_ADDRESS;
160347c08596SBrooks Davis 		options[i] = &option_elements[i];
160447c08596SBrooks Davis 		options[i]->value = lease->address.iabuf;
160547c08596SBrooks Davis 		options[i]->len = lease->address.len;
160647c08596SBrooks Davis 		options[i]->buf_size = lease->address.len;
160747c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
160847c08596SBrooks Davis 	} else
160947c08596SBrooks Davis 		ip->client->requested_address.len = 0;
161047c08596SBrooks Davis 
161147c08596SBrooks Davis 	/* Send any options requested in the config file. */
161247c08596SBrooks Davis 	for (i = 0; i < 256; i++)
161347c08596SBrooks Davis 		if (!options[i] &&
161447c08596SBrooks Davis 		    ip->client->config->send_options[i].data) {
161547c08596SBrooks Davis 			options[i] = &option_elements[i];
161647c08596SBrooks Davis 			options[i]->value =
161747c08596SBrooks Davis 			    ip->client->config->send_options[i].data;
161847c08596SBrooks Davis 			options[i]->len =
161947c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
162047c08596SBrooks Davis 			options[i]->buf_size =
162147c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
162247c08596SBrooks Davis 			options[i]->timeout = 0xFFFFFFFF;
162347c08596SBrooks Davis 		}
162447c08596SBrooks Davis 
1625fcab8addSBrooks Davis 	/* send host name if not set via config file. */
1626fcab8addSBrooks Davis 	if (!options[DHO_HOST_NAME]) {
16270bbe8306SPawel Jakub Dawidek 		if (hostname[0] != '\0') {
1628fcab8addSBrooks Davis 			size_t len;
1629fcab8addSBrooks Davis 			char* posDot = strchr(hostname, '.');
1630fcab8addSBrooks Davis 			if (posDot != NULL)
1631fcab8addSBrooks Davis 				len = posDot - hostname;
1632fcab8addSBrooks Davis 			else
1633fcab8addSBrooks Davis 				len = strlen(hostname);
1634fcab8addSBrooks Davis 			options[DHO_HOST_NAME] = &option_elements[DHO_HOST_NAME];
1635fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->value = hostname;
1636fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->len = len;
1637fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->buf_size = len;
1638fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->timeout = 0xFFFFFFFF;
1639fcab8addSBrooks Davis 		}
1640fcab8addSBrooks Davis 	}
1641fcab8addSBrooks Davis 
1642fcab8addSBrooks Davis 	/* set unique client identifier */
1643fb0eab09SConrad Meyer 	char client_ident[sizeof(ip->hw_address.haddr) + 1];
1644fcab8addSBrooks Davis 	if (!options[DHO_DHCP_CLIENT_IDENTIFIER]) {
16454441bd73SConrad Meyer 		int hwlen = (ip->hw_address.hlen < sizeof(client_ident)-1) ?
16464441bd73SConrad Meyer 				ip->hw_address.hlen : sizeof(client_ident)-1;
16474441bd73SConrad Meyer 		client_ident[0] = ip->hw_address.htype;
16484441bd73SConrad Meyer 		memcpy(&client_ident[1], ip->hw_address.haddr, hwlen);
1649fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER] = &option_elements[DHO_DHCP_CLIENT_IDENTIFIER];
16504441bd73SConrad Meyer 		options[DHO_DHCP_CLIENT_IDENTIFIER]->value = client_ident;
16514441bd73SConrad Meyer 		options[DHO_DHCP_CLIENT_IDENTIFIER]->len = hwlen+1;
16524441bd73SConrad Meyer 		options[DHO_DHCP_CLIENT_IDENTIFIER]->buf_size = hwlen+1;
1653fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->timeout = 0xFFFFFFFF;
1654fcab8addSBrooks Davis 	}
1655fcab8addSBrooks Davis 
165647c08596SBrooks Davis 	/* Set up the option buffer... */
165747c08596SBrooks Davis 	ip->client->packet_length = cons_options(NULL, &ip->client->packet, 0,
165847c08596SBrooks Davis 	    options, 0, 0, 0, NULL, 0);
165947c08596SBrooks Davis 	if (ip->client->packet_length < BOOTP_MIN_LEN)
166047c08596SBrooks Davis 		ip->client->packet_length = BOOTP_MIN_LEN;
166147c08596SBrooks Davis 
166247c08596SBrooks Davis 	ip->client->packet.op = BOOTREQUEST;
166347c08596SBrooks Davis 	ip->client->packet.htype = ip->hw_address.htype;
166447c08596SBrooks Davis 	ip->client->packet.hlen = ip->hw_address.hlen;
166547c08596SBrooks Davis 	ip->client->packet.hops = 0;
166647c08596SBrooks Davis 	ip->client->packet.xid = arc4random();
166747c08596SBrooks Davis 	ip->client->packet.secs = 0; /* filled in by send_discover. */
166847c08596SBrooks Davis 	ip->client->packet.flags = 0;
166947c08596SBrooks Davis 
167047c08596SBrooks Davis 	memset(&(ip->client->packet.ciaddr),
167147c08596SBrooks Davis 	    0, sizeof(ip->client->packet.ciaddr));
167247c08596SBrooks Davis 	memset(&(ip->client->packet.yiaddr),
167347c08596SBrooks Davis 	    0, sizeof(ip->client->packet.yiaddr));
167447c08596SBrooks Davis 	memset(&(ip->client->packet.siaddr),
167547c08596SBrooks Davis 	    0, sizeof(ip->client->packet.siaddr));
167647c08596SBrooks Davis 	memset(&(ip->client->packet.giaddr),
167747c08596SBrooks Davis 	    0, sizeof(ip->client->packet.giaddr));
16784441bd73SConrad Meyer 	memcpy(ip->client->packet.chaddr,
16794441bd73SConrad Meyer 	    ip->hw_address.haddr, ip->hw_address.hlen);
168047c08596SBrooks Davis }
168147c08596SBrooks Davis 
168247c08596SBrooks Davis 
168347c08596SBrooks Davis void
168447c08596SBrooks Davis make_request(struct interface_info *ip, struct client_lease * lease)
168547c08596SBrooks Davis {
168647c08596SBrooks Davis 	unsigned char request = DHCPREQUEST;
168747c08596SBrooks Davis 	struct tree_cache *options[256];
168847c08596SBrooks Davis 	struct tree_cache option_elements[256];
168947c08596SBrooks Davis 	int i;
169047c08596SBrooks Davis 
169147c08596SBrooks Davis 	memset(options, 0, sizeof(options));
169247c08596SBrooks Davis 	memset(&ip->client->packet, 0, sizeof(ip->client->packet));
169347c08596SBrooks Davis 
169447c08596SBrooks Davis 	/* Set DHCP_MESSAGE_TYPE to DHCPREQUEST */
169547c08596SBrooks Davis 	i = DHO_DHCP_MESSAGE_TYPE;
169647c08596SBrooks Davis 	options[i] = &option_elements[i];
169747c08596SBrooks Davis 	options[i]->value = &request;
169847c08596SBrooks Davis 	options[i]->len = sizeof(request);
169947c08596SBrooks Davis 	options[i]->buf_size = sizeof(request);
170047c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
170147c08596SBrooks Davis 
170247c08596SBrooks Davis 	/* Request the options we want */
170347c08596SBrooks Davis 	i = DHO_DHCP_PARAMETER_REQUEST_LIST;
170447c08596SBrooks Davis 	options[i] = &option_elements[i];
170547c08596SBrooks Davis 	options[i]->value = ip->client->config->requested_options;
170647c08596SBrooks Davis 	options[i]->len = ip->client->config->requested_option_count;
170747c08596SBrooks Davis 	options[i]->buf_size =
170847c08596SBrooks Davis 		ip->client->config->requested_option_count;
170947c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
171047c08596SBrooks Davis 
171147c08596SBrooks Davis 	/* If we are requesting an address that hasn't yet been assigned
171247c08596SBrooks Davis 	   to us, use the DHCP Requested Address option. */
171347c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING) {
171447c08596SBrooks Davis 		/* Send back the server identifier... */
171547c08596SBrooks Davis 		i = DHO_DHCP_SERVER_IDENTIFIER;
171647c08596SBrooks Davis 		options[i] = &option_elements[i];
171747c08596SBrooks Davis 		options[i]->value = lease->options[i].data;
171847c08596SBrooks Davis 		options[i]->len = lease->options[i].len;
171947c08596SBrooks Davis 		options[i]->buf_size = lease->options[i].len;
172047c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
172147c08596SBrooks Davis 	}
172247c08596SBrooks Davis 	if (ip->client->state == S_REQUESTING ||
172347c08596SBrooks Davis 	    ip->client->state == S_REBOOTING) {
172447c08596SBrooks Davis 		ip->client->requested_address = lease->address;
172547c08596SBrooks Davis 		i = DHO_DHCP_REQUESTED_ADDRESS;
172647c08596SBrooks Davis 		options[i] = &option_elements[i];
172747c08596SBrooks Davis 		options[i]->value = lease->address.iabuf;
172847c08596SBrooks Davis 		options[i]->len = lease->address.len;
172947c08596SBrooks Davis 		options[i]->buf_size = lease->address.len;
173047c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
173147c08596SBrooks Davis 	} else
173247c08596SBrooks Davis 		ip->client->requested_address.len = 0;
173347c08596SBrooks Davis 
173447c08596SBrooks Davis 	/* Send any options requested in the config file. */
173547c08596SBrooks Davis 	for (i = 0; i < 256; i++)
173647c08596SBrooks Davis 		if (!options[i] &&
173747c08596SBrooks Davis 		    ip->client->config->send_options[i].data) {
173847c08596SBrooks Davis 			options[i] = &option_elements[i];
173947c08596SBrooks Davis 			options[i]->value =
174047c08596SBrooks Davis 			    ip->client->config->send_options[i].data;
174147c08596SBrooks Davis 			options[i]->len =
174247c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
174347c08596SBrooks Davis 			options[i]->buf_size =
174447c08596SBrooks Davis 			    ip->client->config->send_options[i].len;
174547c08596SBrooks Davis 			options[i]->timeout = 0xFFFFFFFF;
174647c08596SBrooks Davis 		}
174747c08596SBrooks Davis 
1748fcab8addSBrooks Davis 	/* send host name if not set via config file. */
1749fcab8addSBrooks Davis 	if (!options[DHO_HOST_NAME]) {
17500bbe8306SPawel Jakub Dawidek 		if (hostname[0] != '\0') {
1751fcab8addSBrooks Davis 			size_t len;
1752fcab8addSBrooks Davis 			char* posDot = strchr(hostname, '.');
1753fcab8addSBrooks Davis 			if (posDot != NULL)
1754fcab8addSBrooks Davis 				len = posDot - hostname;
1755fcab8addSBrooks Davis 			else
1756fcab8addSBrooks Davis 				len = strlen(hostname);
1757fcab8addSBrooks Davis 			options[DHO_HOST_NAME] = &option_elements[DHO_HOST_NAME];
1758fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->value = hostname;
1759fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->len = len;
1760fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->buf_size = len;
1761fcab8addSBrooks Davis 			options[DHO_HOST_NAME]->timeout = 0xFFFFFFFF;
1762fcab8addSBrooks Davis 		}
1763fcab8addSBrooks Davis 	}
1764fcab8addSBrooks Davis 
1765fcab8addSBrooks Davis 	/* set unique client identifier */
1766fcab8addSBrooks Davis 	char client_ident[sizeof(struct hardware)];
1767fcab8addSBrooks Davis 	if (!options[DHO_DHCP_CLIENT_IDENTIFIER]) {
1768fcab8addSBrooks Davis 		int hwlen = (ip->hw_address.hlen < sizeof(client_ident)-1) ?
1769fcab8addSBrooks Davis 				ip->hw_address.hlen : sizeof(client_ident)-1;
1770fcab8addSBrooks Davis 		client_ident[0] = ip->hw_address.htype;
1771fcab8addSBrooks Davis 		memcpy(&client_ident[1], ip->hw_address.haddr, hwlen);
1772fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER] = &option_elements[DHO_DHCP_CLIENT_IDENTIFIER];
1773fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->value = client_ident;
1774fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->len = hwlen+1;
1775fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->buf_size = hwlen+1;
1776fcab8addSBrooks Davis 		options[DHO_DHCP_CLIENT_IDENTIFIER]->timeout = 0xFFFFFFFF;
1777fcab8addSBrooks Davis 	}
1778fcab8addSBrooks Davis 
177947c08596SBrooks Davis 	/* Set up the option buffer... */
178047c08596SBrooks Davis 	ip->client->packet_length = cons_options(NULL, &ip->client->packet, 0,
178147c08596SBrooks Davis 	    options, 0, 0, 0, NULL, 0);
178247c08596SBrooks Davis 	if (ip->client->packet_length < BOOTP_MIN_LEN)
178347c08596SBrooks Davis 		ip->client->packet_length = BOOTP_MIN_LEN;
178447c08596SBrooks Davis 
178547c08596SBrooks Davis 	ip->client->packet.op = BOOTREQUEST;
178647c08596SBrooks Davis 	ip->client->packet.htype = ip->hw_address.htype;
178747c08596SBrooks Davis 	ip->client->packet.hlen = ip->hw_address.hlen;
178847c08596SBrooks Davis 	ip->client->packet.hops = 0;
178947c08596SBrooks Davis 	ip->client->packet.xid = ip->client->xid;
179047c08596SBrooks Davis 	ip->client->packet.secs = 0; /* Filled in by send_request. */
179147c08596SBrooks Davis 
179247c08596SBrooks Davis 	/* If we own the address we're requesting, put it in ciaddr;
179347c08596SBrooks Davis 	   otherwise set ciaddr to zero. */
179447c08596SBrooks Davis 	if (ip->client->state == S_BOUND ||
179547c08596SBrooks Davis 	    ip->client->state == S_RENEWING ||
179647c08596SBrooks Davis 	    ip->client->state == S_REBINDING) {
179747c08596SBrooks Davis 		memcpy(&ip->client->packet.ciaddr,
179847c08596SBrooks Davis 		    lease->address.iabuf, lease->address.len);
179947c08596SBrooks Davis 		ip->client->packet.flags = 0;
180047c08596SBrooks Davis 	} else {
180147c08596SBrooks Davis 		memset(&ip->client->packet.ciaddr, 0,
180247c08596SBrooks Davis 		    sizeof(ip->client->packet.ciaddr));
180347c08596SBrooks Davis 		ip->client->packet.flags = 0;
180447c08596SBrooks Davis 	}
180547c08596SBrooks Davis 
180647c08596SBrooks Davis 	memset(&ip->client->packet.yiaddr, 0,
180747c08596SBrooks Davis 	    sizeof(ip->client->packet.yiaddr));
180847c08596SBrooks Davis 	memset(&ip->client->packet.siaddr, 0,
180947c08596SBrooks Davis 	    sizeof(ip->client->packet.siaddr));
181047c08596SBrooks Davis 	memset(&ip->client->packet.giaddr, 0,
181147c08596SBrooks Davis 	    sizeof(ip->client->packet.giaddr));
181247c08596SBrooks Davis 	memcpy(ip->client->packet.chaddr,
181347c08596SBrooks Davis 	    ip->hw_address.haddr, ip->hw_address.hlen);
181447c08596SBrooks Davis }
181547c08596SBrooks Davis 
181647c08596SBrooks Davis void
181747c08596SBrooks Davis make_decline(struct interface_info *ip, struct client_lease *lease)
181847c08596SBrooks Davis {
181947c08596SBrooks Davis 	struct tree_cache *options[256], message_type_tree;
182047c08596SBrooks Davis 	struct tree_cache requested_address_tree;
182147c08596SBrooks Davis 	struct tree_cache server_id_tree, client_id_tree;
182247c08596SBrooks Davis 	unsigned char decline = DHCPDECLINE;
182347c08596SBrooks Davis 	int i;
182447c08596SBrooks Davis 
182547c08596SBrooks Davis 	memset(options, 0, sizeof(options));
182647c08596SBrooks Davis 	memset(&ip->client->packet, 0, sizeof(ip->client->packet));
182747c08596SBrooks Davis 
182847c08596SBrooks Davis 	/* Set DHCP_MESSAGE_TYPE to DHCPDECLINE */
182947c08596SBrooks Davis 	i = DHO_DHCP_MESSAGE_TYPE;
183047c08596SBrooks Davis 	options[i] = &message_type_tree;
183147c08596SBrooks Davis 	options[i]->value = &decline;
183247c08596SBrooks Davis 	options[i]->len = sizeof(decline);
183347c08596SBrooks Davis 	options[i]->buf_size = sizeof(decline);
183447c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
183547c08596SBrooks Davis 
183647c08596SBrooks Davis 	/* Send back the server identifier... */
183747c08596SBrooks Davis 	i = DHO_DHCP_SERVER_IDENTIFIER;
183847c08596SBrooks Davis 	options[i] = &server_id_tree;
183947c08596SBrooks Davis 	options[i]->value = lease->options[i].data;
184047c08596SBrooks Davis 	options[i]->len = lease->options[i].len;
184147c08596SBrooks Davis 	options[i]->buf_size = lease->options[i].len;
184247c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
184347c08596SBrooks Davis 
184447c08596SBrooks Davis 	/* Send back the address we're declining. */
184547c08596SBrooks Davis 	i = DHO_DHCP_REQUESTED_ADDRESS;
184647c08596SBrooks Davis 	options[i] = &requested_address_tree;
184747c08596SBrooks Davis 	options[i]->value = lease->address.iabuf;
184847c08596SBrooks Davis 	options[i]->len = lease->address.len;
184947c08596SBrooks Davis 	options[i]->buf_size = lease->address.len;
185047c08596SBrooks Davis 	options[i]->timeout = 0xFFFFFFFF;
185147c08596SBrooks Davis 
185247c08596SBrooks Davis 	/* Send the uid if the user supplied one. */
185347c08596SBrooks Davis 	i = DHO_DHCP_CLIENT_IDENTIFIER;
185447c08596SBrooks Davis 	if (ip->client->config->send_options[i].len) {
185547c08596SBrooks Davis 		options[i] = &client_id_tree;
185647c08596SBrooks Davis 		options[i]->value = ip->client->config->send_options[i].data;
185747c08596SBrooks Davis 		options[i]->len = ip->client->config->send_options[i].len;
185847c08596SBrooks Davis 		options[i]->buf_size = ip->client->config->send_options[i].len;
185947c08596SBrooks Davis 		options[i]->timeout = 0xFFFFFFFF;
186047c08596SBrooks Davis 	}
186147c08596SBrooks Davis 
186247c08596SBrooks Davis 
186347c08596SBrooks Davis 	/* Set up the option buffer... */
186447c08596SBrooks Davis 	ip->client->packet_length = cons_options(NULL, &ip->client->packet, 0,
186547c08596SBrooks Davis 	    options, 0, 0, 0, NULL, 0);
186647c08596SBrooks Davis 	if (ip->client->packet_length < BOOTP_MIN_LEN)
186747c08596SBrooks Davis 		ip->client->packet_length = BOOTP_MIN_LEN;
186847c08596SBrooks Davis 
186947c08596SBrooks Davis 	ip->client->packet.op = BOOTREQUEST;
187047c08596SBrooks Davis 	ip->client->packet.htype = ip->hw_address.htype;
187147c08596SBrooks Davis 	ip->client->packet.hlen = ip->hw_address.hlen;
187247c08596SBrooks Davis 	ip->client->packet.hops = 0;
187347c08596SBrooks Davis 	ip->client->packet.xid = ip->client->xid;
187447c08596SBrooks Davis 	ip->client->packet.secs = 0; /* Filled in by send_request. */
187547c08596SBrooks Davis 	ip->client->packet.flags = 0;
187647c08596SBrooks Davis 
187747c08596SBrooks Davis 	/* ciaddr must always be zero. */
187847c08596SBrooks Davis 	memset(&ip->client->packet.ciaddr, 0,
187947c08596SBrooks Davis 	    sizeof(ip->client->packet.ciaddr));
188047c08596SBrooks Davis 	memset(&ip->client->packet.yiaddr, 0,
188147c08596SBrooks Davis 	    sizeof(ip->client->packet.yiaddr));
188247c08596SBrooks Davis 	memset(&ip->client->packet.siaddr, 0,
188347c08596SBrooks Davis 	    sizeof(ip->client->packet.siaddr));
188447c08596SBrooks Davis 	memset(&ip->client->packet.giaddr, 0,
188547c08596SBrooks Davis 	    sizeof(ip->client->packet.giaddr));
188647c08596SBrooks Davis 	memcpy(ip->client->packet.chaddr,
188747c08596SBrooks Davis 	    ip->hw_address.haddr, ip->hw_address.hlen);
188847c08596SBrooks Davis }
188947c08596SBrooks Davis 
189047c08596SBrooks Davis void
189147c08596SBrooks Davis free_client_lease(struct client_lease *lease)
189247c08596SBrooks Davis {
189347c08596SBrooks Davis 	int i;
189447c08596SBrooks Davis 
189547c08596SBrooks Davis 	if (lease->server_name)
189647c08596SBrooks Davis 		free(lease->server_name);
189747c08596SBrooks Davis 	if (lease->filename)
189847c08596SBrooks Davis 		free(lease->filename);
189947c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
190047c08596SBrooks Davis 		if (lease->options[i].len)
190147c08596SBrooks Davis 			free(lease->options[i].data);
190247c08596SBrooks Davis 	}
190347c08596SBrooks Davis 	free(lease);
190447c08596SBrooks Davis }
190547c08596SBrooks Davis 
190671c6c44dSEitan Adler static FILE *leaseFile;
190747c08596SBrooks Davis 
190847c08596SBrooks Davis void
190947c08596SBrooks Davis rewrite_client_leases(void)
191047c08596SBrooks Davis {
191147c08596SBrooks Davis 	struct client_lease *lp;
19127008be5bSPawel Jakub Dawidek 	cap_rights_t rights;
191347c08596SBrooks Davis 
191447c08596SBrooks Davis 	if (!leaseFile) {
191547c08596SBrooks Davis 		leaseFile = fopen(path_dhclient_db, "w");
191647c08596SBrooks Davis 		if (!leaseFile)
191747c08596SBrooks Davis 			error("can't create %s: %m", path_dhclient_db);
191819342eeeSPatrick Kelsey 		cap_rights_init(&rights, CAP_FCNTL, CAP_FSTAT, CAP_FSYNC,
191919342eeeSPatrick Kelsey 		    CAP_FTRUNCATE, CAP_SEEK, CAP_WRITE);
19207008be5bSPawel Jakub Dawidek 		if (cap_rights_limit(fileno(leaseFile), &rights) < 0 &&
1921fe5c7163SPawel Jakub Dawidek 		    errno != ENOSYS) {
1922fe5c7163SPawel Jakub Dawidek 			error("can't limit lease descriptor: %m");
1923fe5c7163SPawel Jakub Dawidek 		}
192419342eeeSPatrick Kelsey 		if (cap_fcntls_limit(fileno(leaseFile), CAP_FCNTL_GETFL) < 0 &&
192519342eeeSPatrick Kelsey 		    errno != ENOSYS) {
192619342eeeSPatrick Kelsey 			error("can't limit lease descriptor fcntls: %m");
192719342eeeSPatrick Kelsey 		}
192847c08596SBrooks Davis 	} else {
192947c08596SBrooks Davis 		fflush(leaseFile);
193047c08596SBrooks Davis 		rewind(leaseFile);
193147c08596SBrooks Davis 	}
193247c08596SBrooks Davis 
193347c08596SBrooks Davis 	for (lp = ifi->client->leases; lp; lp = lp->next)
193447c08596SBrooks Davis 		write_client_lease(ifi, lp, 1);
193547c08596SBrooks Davis 	if (ifi->client->active)
193647c08596SBrooks Davis 		write_client_lease(ifi, ifi->client->active, 1);
193747c08596SBrooks Davis 
193847c08596SBrooks Davis 	fflush(leaseFile);
193947c08596SBrooks Davis 	ftruncate(fileno(leaseFile), ftello(leaseFile));
194047c08596SBrooks Davis 	fsync(fileno(leaseFile));
194147c08596SBrooks Davis }
194247c08596SBrooks Davis 
194347c08596SBrooks Davis void
194447c08596SBrooks Davis write_client_lease(struct interface_info *ip, struct client_lease *lease,
194547c08596SBrooks Davis     int rewrite)
194647c08596SBrooks Davis {
194747c08596SBrooks Davis 	static int leases_written;
194847c08596SBrooks Davis 	struct tm *t;
194947c08596SBrooks Davis 	int i;
195047c08596SBrooks Davis 
195147c08596SBrooks Davis 	if (!rewrite) {
195247c08596SBrooks Davis 		if (leases_written++ > 20) {
195347c08596SBrooks Davis 			rewrite_client_leases();
195447c08596SBrooks Davis 			leases_written = 0;
195547c08596SBrooks Davis 		}
195647c08596SBrooks Davis 	}
195747c08596SBrooks Davis 
195847c08596SBrooks Davis 	/* If the lease came from the config file, we don't need to stash
195947c08596SBrooks Davis 	   a copy in the lease database. */
196047c08596SBrooks Davis 	if (lease->is_static)
196147c08596SBrooks Davis 		return;
196247c08596SBrooks Davis 
196347c08596SBrooks Davis 	if (!leaseFile) {	/* XXX */
196447c08596SBrooks Davis 		leaseFile = fopen(path_dhclient_db, "w");
196547c08596SBrooks Davis 		if (!leaseFile)
196647c08596SBrooks Davis 			error("can't create %s: %m", path_dhclient_db);
196747c08596SBrooks Davis 	}
196847c08596SBrooks Davis 
196947c08596SBrooks Davis 	fprintf(leaseFile, "lease {\n");
197047c08596SBrooks Davis 	if (lease->is_bootp)
197147c08596SBrooks Davis 		fprintf(leaseFile, "  bootp;\n");
197247c08596SBrooks Davis 	fprintf(leaseFile, "  interface \"%s\";\n", ip->name);
197347c08596SBrooks Davis 	fprintf(leaseFile, "  fixed-address %s;\n", piaddr(lease->address));
1974d32438c3SBruce M Simpson 	if (lease->nextserver.len == sizeof(inaddr_any) &&
1975d32438c3SBruce M Simpson 	    0 != memcmp(lease->nextserver.iabuf, &inaddr_any,
1976d32438c3SBruce M Simpson 	    sizeof(inaddr_any)))
1977d32438c3SBruce M Simpson 		fprintf(leaseFile, "  next-server %s;\n",
1978d32438c3SBruce M Simpson 		    piaddr(lease->nextserver));
197947c08596SBrooks Davis 	if (lease->filename)
198047c08596SBrooks Davis 		fprintf(leaseFile, "  filename \"%s\";\n", lease->filename);
198147c08596SBrooks Davis 	if (lease->server_name)
198247c08596SBrooks Davis 		fprintf(leaseFile, "  server-name \"%s\";\n",
198347c08596SBrooks Davis 		    lease->server_name);
198447c08596SBrooks Davis 	if (lease->medium)
198547c08596SBrooks Davis 		fprintf(leaseFile, "  medium \"%s\";\n", lease->medium->string);
198647c08596SBrooks Davis 	for (i = 0; i < 256; i++)
198747c08596SBrooks Davis 		if (lease->options[i].len)
198847c08596SBrooks Davis 			fprintf(leaseFile, "  option %s %s;\n",
198947c08596SBrooks Davis 			    dhcp_options[i].name,
199047c08596SBrooks Davis 			    pretty_print_option(i, lease->options[i].data,
199147c08596SBrooks Davis 			    lease->options[i].len, 1, 1));
199247c08596SBrooks Davis 
199347c08596SBrooks Davis 	t = gmtime(&lease->renewal);
199447c08596SBrooks Davis 	fprintf(leaseFile, "  renew %d %d/%d/%d %02d:%02d:%02d;\n",
199547c08596SBrooks Davis 	    t->tm_wday, t->tm_year + 1900, t->tm_mon + 1, t->tm_mday,
199647c08596SBrooks Davis 	    t->tm_hour, t->tm_min, t->tm_sec);
199747c08596SBrooks Davis 	t = gmtime(&lease->rebind);
199847c08596SBrooks Davis 	fprintf(leaseFile, "  rebind %d %d/%d/%d %02d:%02d:%02d;\n",
199947c08596SBrooks Davis 	    t->tm_wday, t->tm_year + 1900, t->tm_mon + 1, t->tm_mday,
200047c08596SBrooks Davis 	    t->tm_hour, t->tm_min, t->tm_sec);
200147c08596SBrooks Davis 	t = gmtime(&lease->expiry);
200247c08596SBrooks Davis 	fprintf(leaseFile, "  expire %d %d/%d/%d %02d:%02d:%02d;\n",
200347c08596SBrooks Davis 	    t->tm_wday, t->tm_year + 1900, t->tm_mon + 1, t->tm_mday,
200447c08596SBrooks Davis 	    t->tm_hour, t->tm_min, t->tm_sec);
200547c08596SBrooks Davis 	fprintf(leaseFile, "}\n");
200647c08596SBrooks Davis 	fflush(leaseFile);
200747c08596SBrooks Davis }
200847c08596SBrooks Davis 
200947c08596SBrooks Davis void
201079a1d195SAlan Somers script_init(const char *reason, struct string_list *medium)
201147c08596SBrooks Davis {
201247c08596SBrooks Davis 	size_t		 len, mediumlen = 0;
201347c08596SBrooks Davis 	struct imsg_hdr	 hdr;
201447c08596SBrooks Davis 	struct buf	*buf;
201547c08596SBrooks Davis 	int		 errs;
201647c08596SBrooks Davis 
201747c08596SBrooks Davis 	if (medium != NULL && medium->string != NULL)
201847c08596SBrooks Davis 		mediumlen = strlen(medium->string);
201947c08596SBrooks Davis 
202047c08596SBrooks Davis 	hdr.code = IMSG_SCRIPT_INIT;
202147c08596SBrooks Davis 	hdr.len = sizeof(struct imsg_hdr) +
202247c08596SBrooks Davis 	    sizeof(size_t) + mediumlen +
202347c08596SBrooks Davis 	    sizeof(size_t) + strlen(reason);
202447c08596SBrooks Davis 
202547c08596SBrooks Davis 	if ((buf = buf_open(hdr.len)) == NULL)
202647c08596SBrooks Davis 		error("buf_open: %m");
202747c08596SBrooks Davis 
202847c08596SBrooks Davis 	errs = 0;
202947c08596SBrooks Davis 	errs += buf_add(buf, &hdr, sizeof(hdr));
203047c08596SBrooks Davis 	errs += buf_add(buf, &mediumlen, sizeof(mediumlen));
203147c08596SBrooks Davis 	if (mediumlen > 0)
203247c08596SBrooks Davis 		errs += buf_add(buf, medium->string, mediumlen);
203347c08596SBrooks Davis 	len = strlen(reason);
203447c08596SBrooks Davis 	errs += buf_add(buf, &len, sizeof(len));
203547c08596SBrooks Davis 	errs += buf_add(buf, reason, len);
203647c08596SBrooks Davis 
203747c08596SBrooks Davis 	if (errs)
203847c08596SBrooks Davis 		error("buf_add: %m");
203947c08596SBrooks Davis 
204047c08596SBrooks Davis 	if (buf_close(privfd, buf) == -1)
204147c08596SBrooks Davis 		error("buf_close: %m");
204247c08596SBrooks Davis }
204347c08596SBrooks Davis 
204447c08596SBrooks Davis void
204579a1d195SAlan Somers priv_script_init(const char *reason, char *medium)
204647c08596SBrooks Davis {
204747c08596SBrooks Davis 	struct interface_info *ip = ifi;
204847c08596SBrooks Davis 
204947c08596SBrooks Davis 	if (ip) {
205047c08596SBrooks Davis 		ip->client->scriptEnvsize = 100;
205147c08596SBrooks Davis 		if (ip->client->scriptEnv == NULL)
205247c08596SBrooks Davis 			ip->client->scriptEnv =
205347c08596SBrooks Davis 			    malloc(ip->client->scriptEnvsize * sizeof(char *));
205447c08596SBrooks Davis 		if (ip->client->scriptEnv == NULL)
205547c08596SBrooks Davis 			error("script_init: no memory for environment");
205647c08596SBrooks Davis 
205747c08596SBrooks Davis 		ip->client->scriptEnv[0] = strdup(CLIENT_PATH);
205847c08596SBrooks Davis 		if (ip->client->scriptEnv[0] == NULL)
205947c08596SBrooks Davis 			error("script_init: no memory for environment");
206047c08596SBrooks Davis 
206147c08596SBrooks Davis 		ip->client->scriptEnv[1] = NULL;
206247c08596SBrooks Davis 
206347c08596SBrooks Davis 		script_set_env(ip->client, "", "interface", ip->name);
206447c08596SBrooks Davis 
206547c08596SBrooks Davis 		if (medium)
206647c08596SBrooks Davis 			script_set_env(ip->client, "", "medium", medium);
206747c08596SBrooks Davis 
206847c08596SBrooks Davis 		script_set_env(ip->client, "", "reason", reason);
206947c08596SBrooks Davis 	}
207047c08596SBrooks Davis }
207147c08596SBrooks Davis 
207247c08596SBrooks Davis void
207379a1d195SAlan Somers priv_script_write_params(const char *prefix, struct client_lease *lease)
207447c08596SBrooks Davis {
207547c08596SBrooks Davis 	struct interface_info *ip = ifi;
207640767e22SBrooks Davis 	u_int8_t dbuf[1500], *dp = NULL;
2077afe6f835SAlan Somers 	int i;
2078afe6f835SAlan Somers 	size_t len;
207947c08596SBrooks Davis 	char tbuf[128];
208047c08596SBrooks Davis 
208147c08596SBrooks Davis 	script_set_env(ip->client, prefix, "ip_address",
208247c08596SBrooks Davis 	    piaddr(lease->address));
208347c08596SBrooks Davis 
208440767e22SBrooks Davis 	if (ip->client->config->default_actions[DHO_SUBNET_MASK] ==
208540767e22SBrooks Davis 	    ACTION_SUPERSEDE) {
208640767e22SBrooks Davis 		dp = ip->client->config->defaults[DHO_SUBNET_MASK].data;
208740767e22SBrooks Davis 		len = ip->client->config->defaults[DHO_SUBNET_MASK].len;
208840767e22SBrooks Davis 	} else {
208940767e22SBrooks Davis 		dp = lease->options[DHO_SUBNET_MASK].data;
209040767e22SBrooks Davis 		len = lease->options[DHO_SUBNET_MASK].len;
209140767e22SBrooks Davis 	}
209240767e22SBrooks Davis 	if (len && (len < sizeof(lease->address.iabuf))) {
209347c08596SBrooks Davis 		struct iaddr netmask, subnet, broadcast;
209447c08596SBrooks Davis 
209540767e22SBrooks Davis 		memcpy(netmask.iabuf, dp, len);
209640767e22SBrooks Davis 		netmask.len = len;
209747c08596SBrooks Davis 		subnet = subnet_number(lease->address, netmask);
209847c08596SBrooks Davis 		if (subnet.len) {
209947c08596SBrooks Davis 			script_set_env(ip->client, prefix, "network_number",
210047c08596SBrooks Davis 			    piaddr(subnet));
210147c08596SBrooks Davis 			if (!lease->options[DHO_BROADCAST_ADDRESS].len) {
210247c08596SBrooks Davis 				broadcast = broadcast_addr(subnet, netmask);
210347c08596SBrooks Davis 				if (broadcast.len)
210447c08596SBrooks Davis 					script_set_env(ip->client, prefix,
210547c08596SBrooks Davis 					    "broadcast_address",
210647c08596SBrooks Davis 					    piaddr(broadcast));
210747c08596SBrooks Davis 			}
210847c08596SBrooks Davis 		}
210947c08596SBrooks Davis 	}
211047c08596SBrooks Davis 
211147c08596SBrooks Davis 	if (lease->filename)
211247c08596SBrooks Davis 		script_set_env(ip->client, prefix, "filename", lease->filename);
211347c08596SBrooks Davis 	if (lease->server_name)
211447c08596SBrooks Davis 		script_set_env(ip->client, prefix, "server_name",
211547c08596SBrooks Davis 		    lease->server_name);
211647c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
211740767e22SBrooks Davis 		len = 0;
211847c08596SBrooks Davis 
211947c08596SBrooks Davis 		if (ip->client->config->defaults[i].len) {
212047c08596SBrooks Davis 			if (lease->options[i].len) {
212147c08596SBrooks Davis 				switch (
212247c08596SBrooks Davis 				    ip->client->config->default_actions[i]) {
212347c08596SBrooks Davis 				case ACTION_DEFAULT:
212447c08596SBrooks Davis 					dp = lease->options[i].data;
212547c08596SBrooks Davis 					len = lease->options[i].len;
212647c08596SBrooks Davis 					break;
212747c08596SBrooks Davis 				case ACTION_SUPERSEDE:
212847c08596SBrooks Davis supersede:
212947c08596SBrooks Davis 					dp = ip->client->
213047c08596SBrooks Davis 						config->defaults[i].data;
213147c08596SBrooks Davis 					len = ip->client->
213247c08596SBrooks Davis 						config->defaults[i].len;
213347c08596SBrooks Davis 					break;
213447c08596SBrooks Davis 				case ACTION_PREPEND:
213547c08596SBrooks Davis 					len = ip->client->
213647c08596SBrooks Davis 					    config->defaults[i].len +
213747c08596SBrooks Davis 					    lease->options[i].len;
2138043bcc8dSBrian Somers 					if (len >= sizeof(dbuf)) {
213947c08596SBrooks Davis 						warning("no space to %s %s",
214047c08596SBrooks Davis 						    "prepend option",
214147c08596SBrooks Davis 						    dhcp_options[i].name);
214247c08596SBrooks Davis 						goto supersede;
214347c08596SBrooks Davis 					}
214447c08596SBrooks Davis 					dp = dbuf;
214547c08596SBrooks Davis 					memcpy(dp,
214647c08596SBrooks Davis 						ip->client->
214747c08596SBrooks Davis 						config->defaults[i].data,
214847c08596SBrooks Davis 						ip->client->
214947c08596SBrooks Davis 						config->defaults[i].len);
215047c08596SBrooks Davis 					memcpy(dp + ip->client->
215147c08596SBrooks Davis 						config->defaults[i].len,
215247c08596SBrooks Davis 						lease->options[i].data,
215347c08596SBrooks Davis 						lease->options[i].len);
215447c08596SBrooks Davis 					dp[len] = '\0';
215547c08596SBrooks Davis 					break;
215647c08596SBrooks Davis 				case ACTION_APPEND:
2157043bcc8dSBrian Somers 					/*
2158043bcc8dSBrian Somers 					 * When we append, we assume that we're
2159043bcc8dSBrian Somers 					 * appending to text.  Some MS servers
2160043bcc8dSBrian Somers 					 * include a NUL byte at the end of
2161043bcc8dSBrian Somers 					 * the search string provided.
2162043bcc8dSBrian Somers 					 */
216347c08596SBrooks Davis 					len = ip->client->
216447c08596SBrooks Davis 					    config->defaults[i].len +
216547c08596SBrooks Davis 					    lease->options[i].len;
2166043bcc8dSBrian Somers 					if (len >= sizeof(dbuf)) {
216747c08596SBrooks Davis 						warning("no space to %s %s",
216847c08596SBrooks Davis 						    "append option",
216947c08596SBrooks Davis 						    dhcp_options[i].name);
217047c08596SBrooks Davis 						goto supersede;
217147c08596SBrooks Davis 					}
2172043bcc8dSBrian Somers 					memcpy(dbuf,
217347c08596SBrooks Davis 						lease->options[i].data,
217447c08596SBrooks Davis 						lease->options[i].len);
2175043bcc8dSBrian Somers 					for (dp = dbuf + lease->options[i].len;
2176043bcc8dSBrian Somers 					    dp > dbuf; dp--, len--)
2177043bcc8dSBrian Somers 						if (dp[-1] != '\0')
2178043bcc8dSBrian Somers 							break;
2179043bcc8dSBrian Somers 					memcpy(dp,
218047c08596SBrooks Davis 						ip->client->
218147c08596SBrooks Davis 						config->defaults[i].data,
218247c08596SBrooks Davis 						ip->client->
218347c08596SBrooks Davis 						config->defaults[i].len);
2184043bcc8dSBrian Somers 					dp = dbuf;
218547c08596SBrooks Davis 					dp[len] = '\0';
218647c08596SBrooks Davis 				}
218747c08596SBrooks Davis 			} else {
218847c08596SBrooks Davis 				dp = ip->client->
218947c08596SBrooks Davis 					config->defaults[i].data;
219047c08596SBrooks Davis 				len = ip->client->
219147c08596SBrooks Davis 					config->defaults[i].len;
219247c08596SBrooks Davis 			}
219347c08596SBrooks Davis 		} else if (lease->options[i].len) {
219447c08596SBrooks Davis 			len = lease->options[i].len;
219547c08596SBrooks Davis 			dp = lease->options[i].data;
219647c08596SBrooks Davis 		} else {
219747c08596SBrooks Davis 			len = 0;
219847c08596SBrooks Davis 		}
219947c08596SBrooks Davis 		if (len) {
220047c08596SBrooks Davis 			char name[256];
220147c08596SBrooks Davis 
220247c08596SBrooks Davis 			if (dhcp_option_ev_name(name, sizeof(name),
220347c08596SBrooks Davis 			    &dhcp_options[i]))
220447c08596SBrooks Davis 				script_set_env(ip->client, prefix, name,
220547c08596SBrooks Davis 				    pretty_print_option(i, dp, len, 0, 0));
220647c08596SBrooks Davis 		}
220747c08596SBrooks Davis 	}
220847c08596SBrooks Davis 	snprintf(tbuf, sizeof(tbuf), "%d", (int)lease->expiry);
220947c08596SBrooks Davis 	script_set_env(ip->client, prefix, "expiry", tbuf);
221047c08596SBrooks Davis }
221147c08596SBrooks Davis 
221247c08596SBrooks Davis void
221379a1d195SAlan Somers script_write_params(const char *prefix, struct client_lease *lease)
221447c08596SBrooks Davis {
221547c08596SBrooks Davis 	size_t		 fn_len = 0, sn_len = 0, pr_len = 0;
221647c08596SBrooks Davis 	struct imsg_hdr	 hdr;
221747c08596SBrooks Davis 	struct buf	*buf;
221847c08596SBrooks Davis 	int		 errs, i;
221947c08596SBrooks Davis 
222047c08596SBrooks Davis 	if (lease->filename != NULL)
222147c08596SBrooks Davis 		fn_len = strlen(lease->filename);
222247c08596SBrooks Davis 	if (lease->server_name != NULL)
222347c08596SBrooks Davis 		sn_len = strlen(lease->server_name);
222447c08596SBrooks Davis 	if (prefix != NULL)
222547c08596SBrooks Davis 		pr_len = strlen(prefix);
222647c08596SBrooks Davis 
222747c08596SBrooks Davis 	hdr.code = IMSG_SCRIPT_WRITE_PARAMS;
2228afe6f835SAlan Somers 	hdr.len = sizeof(hdr) + sizeof(*lease) +
2229afe6f835SAlan Somers 	    sizeof(fn_len) + fn_len + sizeof(sn_len) + sn_len +
2230afe6f835SAlan Somers 	    sizeof(pr_len) + pr_len;
223147c08596SBrooks Davis 
2232afe6f835SAlan Somers 	for (i = 0; i < 256; i++) {
2233afe6f835SAlan Somers 		hdr.len += sizeof(lease->options[i].len);
2234afe6f835SAlan Somers 		hdr.len += lease->options[i].len;
2235afe6f835SAlan Somers 	}
223647c08596SBrooks Davis 
223747c08596SBrooks Davis 	scripttime = time(NULL);
223847c08596SBrooks Davis 
223947c08596SBrooks Davis 	if ((buf = buf_open(hdr.len)) == NULL)
224047c08596SBrooks Davis 		error("buf_open: %m");
224147c08596SBrooks Davis 
224247c08596SBrooks Davis 	errs = 0;
224347c08596SBrooks Davis 	errs += buf_add(buf, &hdr, sizeof(hdr));
2244afe6f835SAlan Somers 	errs += buf_add(buf, lease, sizeof(*lease));
224547c08596SBrooks Davis 	errs += buf_add(buf, &fn_len, sizeof(fn_len));
224647c08596SBrooks Davis 	errs += buf_add(buf, lease->filename, fn_len);
224747c08596SBrooks Davis 	errs += buf_add(buf, &sn_len, sizeof(sn_len));
224847c08596SBrooks Davis 	errs += buf_add(buf, lease->server_name, sn_len);
224947c08596SBrooks Davis 	errs += buf_add(buf, &pr_len, sizeof(pr_len));
225047c08596SBrooks Davis 	errs += buf_add(buf, prefix, pr_len);
225147c08596SBrooks Davis 
225247c08596SBrooks Davis 	for (i = 0; i < 256; i++) {
225347c08596SBrooks Davis 		errs += buf_add(buf, &lease->options[i].len,
225447c08596SBrooks Davis 		    sizeof(lease->options[i].len));
225547c08596SBrooks Davis 		errs += buf_add(buf, lease->options[i].data,
225647c08596SBrooks Davis 		    lease->options[i].len);
225747c08596SBrooks Davis 	}
225847c08596SBrooks Davis 
225947c08596SBrooks Davis 	if (errs)
226047c08596SBrooks Davis 		error("buf_add: %m");
226147c08596SBrooks Davis 
226247c08596SBrooks Davis 	if (buf_close(privfd, buf) == -1)
226347c08596SBrooks Davis 		error("buf_close: %m");
226447c08596SBrooks Davis }
226547c08596SBrooks Davis 
226647c08596SBrooks Davis int
226747c08596SBrooks Davis script_go(void)
226847c08596SBrooks Davis {
226947c08596SBrooks Davis 	struct imsg_hdr	 hdr;
227047c08596SBrooks Davis 	struct buf	*buf;
227147c08596SBrooks Davis 	int		 ret;
227247c08596SBrooks Davis 
227347c08596SBrooks Davis 	hdr.code = IMSG_SCRIPT_GO;
227447c08596SBrooks Davis 	hdr.len = sizeof(struct imsg_hdr);
227547c08596SBrooks Davis 
227647c08596SBrooks Davis 	if ((buf = buf_open(hdr.len)) == NULL)
227747c08596SBrooks Davis 		error("buf_open: %m");
227847c08596SBrooks Davis 
227947c08596SBrooks Davis 	if (buf_add(buf, &hdr, sizeof(hdr)))
228047c08596SBrooks Davis 		error("buf_add: %m");
228147c08596SBrooks Davis 
228247c08596SBrooks Davis 	if (buf_close(privfd, buf) == -1)
228347c08596SBrooks Davis 		error("buf_close: %m");
228447c08596SBrooks Davis 
228547c08596SBrooks Davis 	bzero(&hdr, sizeof(hdr));
228647c08596SBrooks Davis 	buf_read(privfd, &hdr, sizeof(hdr));
228747c08596SBrooks Davis 	if (hdr.code != IMSG_SCRIPT_GO_RET)
228847c08596SBrooks Davis 		error("unexpected msg type %u", hdr.code);
228947c08596SBrooks Davis 	if (hdr.len != sizeof(hdr) + sizeof(int))
229047c08596SBrooks Davis 		error("received corrupted message");
229147c08596SBrooks Davis 	buf_read(privfd, &ret, sizeof(ret));
229247c08596SBrooks Davis 
22936964abefSBrian Somers 	scripttime = time(NULL);
22946964abefSBrian Somers 
229547c08596SBrooks Davis 	return (ret);
229647c08596SBrooks Davis }
229747c08596SBrooks Davis 
229847c08596SBrooks Davis int
229947c08596SBrooks Davis priv_script_go(void)
230047c08596SBrooks Davis {
230147c08596SBrooks Davis 	char *scriptName, *argv[2], **envp, *epp[3], reason[] = "REASON=NBI";
230247c08596SBrooks Davis 	static char client_path[] = CLIENT_PATH;
230347c08596SBrooks Davis 	struct interface_info *ip = ifi;
230447c08596SBrooks Davis 	int pid, wpid, wstatus;
230547c08596SBrooks Davis 
230647c08596SBrooks Davis 	scripttime = time(NULL);
230747c08596SBrooks Davis 
230847c08596SBrooks Davis 	if (ip) {
230947c08596SBrooks Davis 		scriptName = ip->client->config->script_name;
231047c08596SBrooks Davis 		envp = ip->client->scriptEnv;
231147c08596SBrooks Davis 	} else {
231247c08596SBrooks Davis 		scriptName = top_level_config.script_name;
231347c08596SBrooks Davis 		epp[0] = reason;
231447c08596SBrooks Davis 		epp[1] = client_path;
231547c08596SBrooks Davis 		epp[2] = NULL;
231647c08596SBrooks Davis 		envp = epp;
231747c08596SBrooks Davis 	}
231847c08596SBrooks Davis 
231947c08596SBrooks Davis 	argv[0] = scriptName;
232047c08596SBrooks Davis 	argv[1] = NULL;
232147c08596SBrooks Davis 
232247c08596SBrooks Davis 	pid = fork();
232347c08596SBrooks Davis 	if (pid < 0) {
232447c08596SBrooks Davis 		error("fork: %m");
232547c08596SBrooks Davis 		wstatus = 0;
232647c08596SBrooks Davis 	} else if (pid) {
232747c08596SBrooks Davis 		do {
232847c08596SBrooks Davis 			wpid = wait(&wstatus);
232947c08596SBrooks Davis 		} while (wpid != pid && wpid > 0);
233047c08596SBrooks Davis 		if (wpid < 0) {
233147c08596SBrooks Davis 			error("wait: %m");
233247c08596SBrooks Davis 			wstatus = 0;
233347c08596SBrooks Davis 		}
233447c08596SBrooks Davis 	} else {
233547c08596SBrooks Davis 		execve(scriptName, argv, envp);
233647c08596SBrooks Davis 		error("execve (%s, ...): %m", scriptName);
233747c08596SBrooks Davis 	}
233847c08596SBrooks Davis 
233947c08596SBrooks Davis 	if (ip)
234047c08596SBrooks Davis 		script_flush_env(ip->client);
234147c08596SBrooks Davis 
234247c08596SBrooks Davis 	return (wstatus & 0xff);
234347c08596SBrooks Davis }
234447c08596SBrooks Davis 
234547c08596SBrooks Davis void
234647c08596SBrooks Davis script_set_env(struct client_state *client, const char *prefix,
234747c08596SBrooks Davis     const char *name, const char *value)
234847c08596SBrooks Davis {
2349afe6f835SAlan Somers 	int i, namelen;
2350afe6f835SAlan Somers 	size_t j;
235147c08596SBrooks Davis 
2352dd09ce39SSepherosa Ziehau 	/* No `` or $() command substitution allowed in environment values! */
2353dd09ce39SSepherosa Ziehau 	for (j=0; j < strlen(value); j++)
2354dd09ce39SSepherosa Ziehau 		switch (value[j]) {
2355dd09ce39SSepherosa Ziehau 		case '`':
2356dd09ce39SSepherosa Ziehau 		case '$':
2357dd09ce39SSepherosa Ziehau 			warning("illegal character (%c) in value '%s'",
2358dd09ce39SSepherosa Ziehau 			    value[j], value);
2359dd09ce39SSepherosa Ziehau 			/* Ignore this option */
2360dd09ce39SSepherosa Ziehau 			return;
2361dd09ce39SSepherosa Ziehau 		}
2362dd09ce39SSepherosa Ziehau 
236347c08596SBrooks Davis 	namelen = strlen(name);
236447c08596SBrooks Davis 
236547c08596SBrooks Davis 	for (i = 0; client->scriptEnv[i]; i++)
236647c08596SBrooks Davis 		if (strncmp(client->scriptEnv[i], name, namelen) == 0 &&
236747c08596SBrooks Davis 		    client->scriptEnv[i][namelen] == '=')
236847c08596SBrooks Davis 			break;
236947c08596SBrooks Davis 
237047c08596SBrooks Davis 	if (client->scriptEnv[i])
237147c08596SBrooks Davis 		/* Reuse the slot. */
237247c08596SBrooks Davis 		free(client->scriptEnv[i]);
237347c08596SBrooks Davis 	else {
237447c08596SBrooks Davis 		/* New variable.  Expand if necessary. */
237547c08596SBrooks Davis 		if (i >= client->scriptEnvsize - 1) {
237647c08596SBrooks Davis 			char **newscriptEnv;
237747c08596SBrooks Davis 			int newscriptEnvsize = client->scriptEnvsize + 50;
237847c08596SBrooks Davis 
237947c08596SBrooks Davis 			newscriptEnv = realloc(client->scriptEnv,
238047c08596SBrooks Davis 			    newscriptEnvsize);
238147c08596SBrooks Davis 			if (newscriptEnv == NULL) {
238247c08596SBrooks Davis 				free(client->scriptEnv);
238347c08596SBrooks Davis 				client->scriptEnv = NULL;
238447c08596SBrooks Davis 				client->scriptEnvsize = 0;
238547c08596SBrooks Davis 				error("script_set_env: no memory for variable");
238647c08596SBrooks Davis 			}
238747c08596SBrooks Davis 			client->scriptEnv = newscriptEnv;
238847c08596SBrooks Davis 			client->scriptEnvsize = newscriptEnvsize;
238947c08596SBrooks Davis 		}
239047c08596SBrooks Davis 		/* need to set the NULL pointer at end of array beyond
239147c08596SBrooks Davis 		   the new slot. */
239247c08596SBrooks Davis 		client->scriptEnv[i + 1] = NULL;
239347c08596SBrooks Davis 	}
239447c08596SBrooks Davis 	/* Allocate space and format the variable in the appropriate slot. */
239547c08596SBrooks Davis 	client->scriptEnv[i] = malloc(strlen(prefix) + strlen(name) + 1 +
239647c08596SBrooks Davis 	    strlen(value) + 1);
239747c08596SBrooks Davis 	if (client->scriptEnv[i] == NULL)
239847c08596SBrooks Davis 		error("script_set_env: no memory for variable assignment");
239947c08596SBrooks Davis 	snprintf(client->scriptEnv[i], strlen(prefix) + strlen(name) +
240047c08596SBrooks Davis 	    1 + strlen(value) + 1, "%s%s=%s", prefix, name, value);
240147c08596SBrooks Davis }
240247c08596SBrooks Davis 
240347c08596SBrooks Davis void
240447c08596SBrooks Davis script_flush_env(struct client_state *client)
240547c08596SBrooks Davis {
240647c08596SBrooks Davis 	int i;
240747c08596SBrooks Davis 
240847c08596SBrooks Davis 	for (i = 0; client->scriptEnv[i]; i++) {
240947c08596SBrooks Davis 		free(client->scriptEnv[i]);
241047c08596SBrooks Davis 		client->scriptEnv[i] = NULL;
241147c08596SBrooks Davis 	}
241247c08596SBrooks Davis 	client->scriptEnvsize = 0;
241347c08596SBrooks Davis }
241447c08596SBrooks Davis 
241547c08596SBrooks Davis int
241647c08596SBrooks Davis dhcp_option_ev_name(char *buf, size_t buflen, struct option *option)
241747c08596SBrooks Davis {
2418afe6f835SAlan Somers 	size_t i;
241947c08596SBrooks Davis 
242047c08596SBrooks Davis 	for (i = 0; option->name[i]; i++) {
242147c08596SBrooks Davis 		if (i + 1 == buflen)
242247c08596SBrooks Davis 			return 0;
242347c08596SBrooks Davis 		if (option->name[i] == '-')
242447c08596SBrooks Davis 			buf[i] = '_';
242547c08596SBrooks Davis 		else
242647c08596SBrooks Davis 			buf[i] = option->name[i];
242747c08596SBrooks Davis 	}
242847c08596SBrooks Davis 
242947c08596SBrooks Davis 	buf[i] = 0;
243047c08596SBrooks Davis 	return 1;
243147c08596SBrooks Davis }
243247c08596SBrooks Davis 
243347c08596SBrooks Davis void
243447c08596SBrooks Davis go_daemon(void)
243547c08596SBrooks Davis {
243647c08596SBrooks Davis 	static int state = 0;
24377008be5bSPawel Jakub Dawidek 	cap_rights_t rights;
243847c08596SBrooks Davis 
243947c08596SBrooks Davis 	if (no_daemon || state)
244047c08596SBrooks Davis 		return;
244147c08596SBrooks Davis 
244247c08596SBrooks Davis 	state = 1;
244347c08596SBrooks Davis 
244447c08596SBrooks Davis 	/* Stop logging to stderr... */
244547c08596SBrooks Davis 	log_perror = 0;
244647c08596SBrooks Davis 
244731698405SMariusz Zaborski 	if (daemonfd(-1, nullfd) == -1)
244847c08596SBrooks Davis 		error("daemon");
244947c08596SBrooks Davis 
24507008be5bSPawel Jakub Dawidek 	cap_rights_init(&rights);
24517008be5bSPawel Jakub Dawidek 
24524c7a48b7SPawel Jakub Dawidek 	if (pidfile != NULL) {
245323f39c90SDag-Erling Smørgrav 		pidfile_write(pidfile);
24547008be5bSPawel Jakub Dawidek 		if (cap_rights_limit(pidfile_fileno(pidfile), &rights) < 0 &&
24554c7a48b7SPawel Jakub Dawidek 		    errno != ENOSYS) {
24564c7a48b7SPawel Jakub Dawidek 			error("can't limit pidfile descriptor: %m");
24574c7a48b7SPawel Jakub Dawidek 		}
24584c7a48b7SPawel Jakub Dawidek 	}
245923f39c90SDag-Erling Smørgrav 
246047c08596SBrooks Davis 	if (nullfd != -1) {
246147c08596SBrooks Davis 		close(nullfd);
246247c08596SBrooks Davis 		nullfd = -1;
246347c08596SBrooks Davis 	}
2464a6f38228SPawel Jakub Dawidek 
24657008be5bSPawel Jakub Dawidek 	if (cap_rights_limit(STDIN_FILENO, &rights) < 0 && errno != ENOSYS)
2466a6f38228SPawel Jakub Dawidek 		error("can't limit stdin: %m");
24677008be5bSPawel Jakub Dawidek 	cap_rights_init(&rights, CAP_WRITE);
24687008be5bSPawel Jakub Dawidek 	if (cap_rights_limit(STDOUT_FILENO, &rights) < 0 && errno != ENOSYS)
2469a6f38228SPawel Jakub Dawidek 		error("can't limit stdout: %m");
24707008be5bSPawel Jakub Dawidek 	if (cap_rights_limit(STDERR_FILENO, &rights) < 0 && errno != ENOSYS)
2471a6f38228SPawel Jakub Dawidek 		error("can't limit stderr: %m");
247247c08596SBrooks Davis }
247347c08596SBrooks Davis 
247447c08596SBrooks Davis int
247547c08596SBrooks Davis check_option(struct client_lease *l, int option)
247647c08596SBrooks Davis {
247779a1d195SAlan Somers 	const char *opbuf;
247879a1d195SAlan Somers 	const char *sbuf;
247947c08596SBrooks Davis 
248047c08596SBrooks Davis 	/* we use this, since this is what gets passed to dhclient-script */
248147c08596SBrooks Davis 
248247c08596SBrooks Davis 	opbuf = pretty_print_option(option, l->options[option].data,
248347c08596SBrooks Davis 	    l->options[option].len, 0, 0);
248447c08596SBrooks Davis 
248547c08596SBrooks Davis 	sbuf = option_as_string(option, l->options[option].data,
248647c08596SBrooks Davis 	    l->options[option].len);
248747c08596SBrooks Davis 
248847c08596SBrooks Davis 	switch (option) {
248947c08596SBrooks Davis 	case DHO_SUBNET_MASK:
249047c08596SBrooks Davis 	case DHO_TIME_SERVERS:
249147c08596SBrooks Davis 	case DHO_NAME_SERVERS:
249247c08596SBrooks Davis 	case DHO_ROUTERS:
249347c08596SBrooks Davis 	case DHO_DOMAIN_NAME_SERVERS:
249447c08596SBrooks Davis 	case DHO_LOG_SERVERS:
249547c08596SBrooks Davis 	case DHO_COOKIE_SERVERS:
249647c08596SBrooks Davis 	case DHO_LPR_SERVERS:
249747c08596SBrooks Davis 	case DHO_IMPRESS_SERVERS:
249847c08596SBrooks Davis 	case DHO_RESOURCE_LOCATION_SERVERS:
249947c08596SBrooks Davis 	case DHO_SWAP_SERVER:
250047c08596SBrooks Davis 	case DHO_BROADCAST_ADDRESS:
250147c08596SBrooks Davis 	case DHO_NIS_SERVERS:
250247c08596SBrooks Davis 	case DHO_NTP_SERVERS:
250347c08596SBrooks Davis 	case DHO_NETBIOS_NAME_SERVERS:
250447c08596SBrooks Davis 	case DHO_NETBIOS_DD_SERVER:
250547c08596SBrooks Davis 	case DHO_FONT_SERVERS:
250647c08596SBrooks Davis 	case DHO_DHCP_SERVER_IDENTIFIER:
250738e755fdSBrooks Davis 	case DHO_NISPLUS_SERVERS:
250838e755fdSBrooks Davis 	case DHO_MOBILE_IP_HOME_AGENT:
2509a36c0b6bSBrooks Davis 	case DHO_SMTP_SERVER:
2510a36c0b6bSBrooks Davis 	case DHO_POP_SERVER:
2511a36c0b6bSBrooks Davis 	case DHO_NNTP_SERVER:
2512a36c0b6bSBrooks Davis 	case DHO_WWW_SERVER:
2513a36c0b6bSBrooks Davis 	case DHO_FINGER_SERVER:
2514a36c0b6bSBrooks Davis 	case DHO_IRC_SERVER:
251538e755fdSBrooks Davis 	case DHO_STREETTALK_SERVER:
251638e755fdSBrooks Davis 	case DHO_STREETTALK_DA_SERVER:
251747c08596SBrooks Davis 		if (!ipv4addrs(opbuf)) {
251847c08596SBrooks Davis 			warning("Invalid IP address in option: %s", opbuf);
251947c08596SBrooks Davis 			return (0);
252047c08596SBrooks Davis 		}
252147c08596SBrooks Davis 		return (1)  ;
252247c08596SBrooks Davis 	case DHO_HOST_NAME:
252347c08596SBrooks Davis 	case DHO_NIS_DOMAIN:
252438e755fdSBrooks Davis 	case DHO_NISPLUS_DOMAIN:
252538e755fdSBrooks Davis 	case DHO_TFTP_SERVER_NAME:
252647c08596SBrooks Davis 		if (!res_hnok(sbuf)) {
252747c08596SBrooks Davis 			warning("Bogus Host Name option %d: %s (%s)", option,
252847c08596SBrooks Davis 			    sbuf, opbuf);
252982dbbc41SBrooks Davis 			l->options[option].len = 0;
253082dbbc41SBrooks Davis 			free(l->options[option].data);
253147c08596SBrooks Davis 		}
253247c08596SBrooks Davis 		return (1);
2533b388f1cbSBrooks Davis 	case DHO_DOMAIN_NAME:
2534409139f0SJean-Sébastien Pédron 	case DHO_DOMAIN_SEARCH:
2535f954ec0bSBrooks Davis 		if (!res_hnok(sbuf)) {
2536f954ec0bSBrooks Davis 			if (!check_search(sbuf)) {
2537f954ec0bSBrooks Davis 				warning("Bogus domain search list %d: %s (%s)",
2538f954ec0bSBrooks Davis 				    option, sbuf, opbuf);
253982dbbc41SBrooks Davis 				l->options[option].len = 0;
254082dbbc41SBrooks Davis 				free(l->options[option].data);
2541f954ec0bSBrooks Davis 			}
2542f954ec0bSBrooks Davis 		}
2543f954ec0bSBrooks Davis 		return (1);
254447c08596SBrooks Davis 	case DHO_PAD:
254547c08596SBrooks Davis 	case DHO_TIME_OFFSET:
254647c08596SBrooks Davis 	case DHO_BOOT_SIZE:
254747c08596SBrooks Davis 	case DHO_MERIT_DUMP:
254847c08596SBrooks Davis 	case DHO_ROOT_PATH:
254947c08596SBrooks Davis 	case DHO_EXTENSIONS_PATH:
255047c08596SBrooks Davis 	case DHO_IP_FORWARDING:
255147c08596SBrooks Davis 	case DHO_NON_LOCAL_SOURCE_ROUTING:
255247c08596SBrooks Davis 	case DHO_POLICY_FILTER:
255347c08596SBrooks Davis 	case DHO_MAX_DGRAM_REASSEMBLY:
255447c08596SBrooks Davis 	case DHO_DEFAULT_IP_TTL:
255547c08596SBrooks Davis 	case DHO_PATH_MTU_AGING_TIMEOUT:
255647c08596SBrooks Davis 	case DHO_PATH_MTU_PLATEAU_TABLE:
255747c08596SBrooks Davis 	case DHO_INTERFACE_MTU:
255847c08596SBrooks Davis 	case DHO_ALL_SUBNETS_LOCAL:
255947c08596SBrooks Davis 	case DHO_PERFORM_MASK_DISCOVERY:
256047c08596SBrooks Davis 	case DHO_MASK_SUPPLIER:
256147c08596SBrooks Davis 	case DHO_ROUTER_DISCOVERY:
256247c08596SBrooks Davis 	case DHO_ROUTER_SOLICITATION_ADDRESS:
256347c08596SBrooks Davis 	case DHO_STATIC_ROUTES:
256447c08596SBrooks Davis 	case DHO_TRAILER_ENCAPSULATION:
256547c08596SBrooks Davis 	case DHO_ARP_CACHE_TIMEOUT:
256647c08596SBrooks Davis 	case DHO_IEEE802_3_ENCAPSULATION:
256747c08596SBrooks Davis 	case DHO_DEFAULT_TCP_TTL:
256847c08596SBrooks Davis 	case DHO_TCP_KEEPALIVE_INTERVAL:
256947c08596SBrooks Davis 	case DHO_TCP_KEEPALIVE_GARBAGE:
257047c08596SBrooks Davis 	case DHO_VENDOR_ENCAPSULATED_OPTIONS:
257147c08596SBrooks Davis 	case DHO_NETBIOS_NODE_TYPE:
257247c08596SBrooks Davis 	case DHO_NETBIOS_SCOPE:
257347c08596SBrooks Davis 	case DHO_X_DISPLAY_MANAGER:
257447c08596SBrooks Davis 	case DHO_DHCP_REQUESTED_ADDRESS:
257547c08596SBrooks Davis 	case DHO_DHCP_LEASE_TIME:
257647c08596SBrooks Davis 	case DHO_DHCP_OPTION_OVERLOAD:
257747c08596SBrooks Davis 	case DHO_DHCP_MESSAGE_TYPE:
257847c08596SBrooks Davis 	case DHO_DHCP_PARAMETER_REQUEST_LIST:
257947c08596SBrooks Davis 	case DHO_DHCP_MESSAGE:
258047c08596SBrooks Davis 	case DHO_DHCP_MAX_MESSAGE_SIZE:
258147c08596SBrooks Davis 	case DHO_DHCP_RENEWAL_TIME:
258247c08596SBrooks Davis 	case DHO_DHCP_REBINDING_TIME:
258347c08596SBrooks Davis 	case DHO_DHCP_CLASS_IDENTIFIER:
258447c08596SBrooks Davis 	case DHO_DHCP_CLIENT_IDENTIFIER:
258538e755fdSBrooks Davis 	case DHO_BOOTFILE_NAME:
258647c08596SBrooks Davis 	case DHO_DHCP_USER_CLASS_ID:
258747c08596SBrooks Davis 	case DHO_END:
258847c08596SBrooks Davis 		return (1);
25892fcc7370SEd Maste 	case DHO_CLASSLESS_ROUTES:
25902fcc7370SEd Maste 		return (check_classless_option(l->options[option].data,
25912fcc7370SEd Maste 		    l->options[option].len));
259247c08596SBrooks Davis 	default:
259347c08596SBrooks Davis 		warning("unknown dhcp option value 0x%x", option);
259447c08596SBrooks Davis 		return (unknown_ok);
259547c08596SBrooks Davis 	}
259647c08596SBrooks Davis }
259747c08596SBrooks Davis 
25982fcc7370SEd Maste /* RFC 3442 The Classless Static Routes option checks */
25992fcc7370SEd Maste int
26002fcc7370SEd Maste check_classless_option(unsigned char *data, int len)
26012fcc7370SEd Maste {
26022fcc7370SEd Maste 	int i = 0;
26032fcc7370SEd Maste 	unsigned char width;
26042fcc7370SEd Maste 	in_addr_t addr, mask;
26052fcc7370SEd Maste 
26062fcc7370SEd Maste 	if (len < 5) {
26072fcc7370SEd Maste 		warning("Too small length: %d", len);
26082fcc7370SEd Maste 		return (0);
26092fcc7370SEd Maste 	}
26102fcc7370SEd Maste 	while(i < len) {
26112fcc7370SEd Maste 		width = data[i++];
26122fcc7370SEd Maste 		if (width == 0) {
26132fcc7370SEd Maste 			i += 4;
26142fcc7370SEd Maste 			continue;
26152fcc7370SEd Maste 		} else if (width < 9) {
26162fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24);
26172fcc7370SEd Maste 			i += 1;
26182fcc7370SEd Maste 		} else if (width < 17) {
26192fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24) +
26202fcc7370SEd Maste 				(in_addr_t)(data[i + 1]	<< 16);
26212fcc7370SEd Maste 			i += 2;
26222fcc7370SEd Maste 		} else if (width < 25) {
26232fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24) +
26242fcc7370SEd Maste 				(in_addr_t)(data[i + 1]	<< 16) +
26252fcc7370SEd Maste 				(in_addr_t)(data[i + 2]	<< 8);
26262fcc7370SEd Maste 			i += 3;
26272fcc7370SEd Maste 		} else if (width < 33) {
26282fcc7370SEd Maste 			addr =  (in_addr_t)(data[i]	<< 24) +
26292fcc7370SEd Maste 				(in_addr_t)(data[i + 1]	<< 16) +
26302fcc7370SEd Maste 				(in_addr_t)(data[i + 2]	<< 8)  +
26312fcc7370SEd Maste 				data[i + 3];
26322fcc7370SEd Maste 			i += 4;
26332fcc7370SEd Maste 		} else {
26342fcc7370SEd Maste 			warning("Incorrect subnet width: %d", width);
26352fcc7370SEd Maste 			return (0);
26362fcc7370SEd Maste 		}
26372fcc7370SEd Maste 		mask = (in_addr_t)(~0) << (32 - width);
26382fcc7370SEd Maste 		addr = ntohl(addr);
26392fcc7370SEd Maste 		mask = ntohl(mask);
26402fcc7370SEd Maste 
26412fcc7370SEd Maste 		/*
26422fcc7370SEd Maste 		 * From RFC 3442:
26432fcc7370SEd Maste 		 * ... After deriving a subnet number and subnet mask
26442fcc7370SEd Maste 		 * from each destination descriptor, the DHCP client
26452fcc7370SEd Maste 		 * MUST zero any bits in the subnet number where the
26462fcc7370SEd Maste 		 * corresponding bit in the mask is zero...
26472fcc7370SEd Maste 		 */
26482fcc7370SEd Maste 		if ((addr & mask) != addr) {
26492fcc7370SEd Maste 			addr &= mask;
26502fcc7370SEd Maste 			data[i - 1] = (unsigned char)(
26512fcc7370SEd Maste 				(addr >> (((32 - width)/8)*8)) & 0xFF);
26522fcc7370SEd Maste 		}
26532fcc7370SEd Maste 		i += 4;
26542fcc7370SEd Maste 	}
26552fcc7370SEd Maste 	if (i > len) {
26562fcc7370SEd Maste 		warning("Incorrect data length: %d (must be %d)", len, i);
26572fcc7370SEd Maste 		return (0);
26582fcc7370SEd Maste 	}
26592fcc7370SEd Maste 	return (1);
26602fcc7370SEd Maste }
26612fcc7370SEd Maste 
266247c08596SBrooks Davis int
266347c08596SBrooks Davis res_hnok(const char *dn)
266447c08596SBrooks Davis {
266547c08596SBrooks Davis 	int pch = PERIOD, ch = *dn++;
266647c08596SBrooks Davis 
266747c08596SBrooks Davis 	while (ch != '\0') {
266847c08596SBrooks Davis 		int nch = *dn++;
266947c08596SBrooks Davis 
267047c08596SBrooks Davis 		if (periodchar(ch)) {
267147c08596SBrooks Davis 			;
267247c08596SBrooks Davis 		} else if (periodchar(pch)) {
267347c08596SBrooks Davis 			if (!borderchar(ch))
267447c08596SBrooks Davis 				return (0);
267547c08596SBrooks Davis 		} else if (periodchar(nch) || nch == '\0') {
267647c08596SBrooks Davis 			if (!borderchar(ch))
267747c08596SBrooks Davis 				return (0);
267847c08596SBrooks Davis 		} else {
267947c08596SBrooks Davis 			if (!middlechar(ch))
268047c08596SBrooks Davis 				return (0);
268147c08596SBrooks Davis 		}
268247c08596SBrooks Davis 		pch = ch, ch = nch;
268347c08596SBrooks Davis 	}
268447c08596SBrooks Davis 	return (1);
268547c08596SBrooks Davis }
268647c08596SBrooks Davis 
2687f954ec0bSBrooks Davis int
2688f954ec0bSBrooks Davis check_search(const char *srch)
2689f954ec0bSBrooks Davis {
2690f954ec0bSBrooks Davis         int pch = PERIOD, ch = *srch++;
2691f954ec0bSBrooks Davis 	int domains = 1;
2692f954ec0bSBrooks Davis 
2693f954ec0bSBrooks Davis 	/* 256 char limit re resolv.conf(5) */
2694f954ec0bSBrooks Davis 	if (strlen(srch) > 256)
2695f954ec0bSBrooks Davis 		return (0);
2696f954ec0bSBrooks Davis 
2697f954ec0bSBrooks Davis 	while (whitechar(ch))
2698f954ec0bSBrooks Davis 		ch = *srch++;
2699f954ec0bSBrooks Davis 
2700f954ec0bSBrooks Davis         while (ch != '\0') {
2701f954ec0bSBrooks Davis                 int nch = *srch++;
2702f954ec0bSBrooks Davis 
2703f954ec0bSBrooks Davis                 if (periodchar(ch) || whitechar(ch)) {
2704f954ec0bSBrooks Davis                         ;
2705f954ec0bSBrooks Davis                 } else if (periodchar(pch)) {
2706f954ec0bSBrooks Davis                         if (!borderchar(ch))
2707f954ec0bSBrooks Davis                                 return (0);
2708f954ec0bSBrooks Davis                 } else if (periodchar(nch) || nch == '\0') {
2709f954ec0bSBrooks Davis                         if (!borderchar(ch))
2710f954ec0bSBrooks Davis                                 return (0);
2711f954ec0bSBrooks Davis                 } else {
2712f954ec0bSBrooks Davis                         if (!middlechar(ch))
2713f954ec0bSBrooks Davis                                 return (0);
2714f954ec0bSBrooks Davis                 }
2715f954ec0bSBrooks Davis 		if (!whitechar(ch)) {
2716f954ec0bSBrooks Davis 			pch = ch;
2717f954ec0bSBrooks Davis 		} else {
2718f954ec0bSBrooks Davis 			while (whitechar(nch)) {
2719f954ec0bSBrooks Davis 				nch = *srch++;
2720f954ec0bSBrooks Davis 			}
2721f954ec0bSBrooks Davis 			if (nch != '\0')
2722f954ec0bSBrooks Davis 				domains++;
2723f954ec0bSBrooks Davis 			pch = PERIOD;
2724f954ec0bSBrooks Davis 		}
2725f954ec0bSBrooks Davis 		ch = nch;
2726f954ec0bSBrooks Davis         }
2727f954ec0bSBrooks Davis 	/* 6 domain limit re resolv.conf(5) */
2728f954ec0bSBrooks Davis 	if (domains > 6)
2729f954ec0bSBrooks Davis 		return (0);
2730f954ec0bSBrooks Davis         return (1);
2731f954ec0bSBrooks Davis }
2732f954ec0bSBrooks Davis 
273347c08596SBrooks Davis /* Does buf consist only of dotted decimal ipv4 addrs?
273447c08596SBrooks Davis  * return how many if so,
273547c08596SBrooks Davis  * otherwise, return 0
273647c08596SBrooks Davis  */
273747c08596SBrooks Davis int
273879a1d195SAlan Somers ipv4addrs(const char * buf)
273947c08596SBrooks Davis {
274047c08596SBrooks Davis 	struct in_addr jnk;
274147c08596SBrooks Davis 	int count = 0;
274247c08596SBrooks Davis 
274347c08596SBrooks Davis 	while (inet_aton(buf, &jnk) == 1){
274447c08596SBrooks Davis 		count++;
274547c08596SBrooks Davis 		while (periodchar(*buf) || digitchar(*buf))
274647c08596SBrooks Davis 			buf++;
274747c08596SBrooks Davis 		if (*buf == '\0')
274847c08596SBrooks Davis 			return (count);
274947c08596SBrooks Davis 		while (*buf ==  ' ')
275047c08596SBrooks Davis 			buf++;
275147c08596SBrooks Davis 	}
275247c08596SBrooks Davis 	return (0);
275347c08596SBrooks Davis }
275447c08596SBrooks Davis 
275547c08596SBrooks Davis 
275679a1d195SAlan Somers const char *
275747c08596SBrooks Davis option_as_string(unsigned int code, unsigned char *data, int len)
275847c08596SBrooks Davis {
275947c08596SBrooks Davis 	static char optbuf[32768]; /* XXX */
276047c08596SBrooks Davis 	char *op = optbuf;
276147c08596SBrooks Davis 	int opleft = sizeof(optbuf);
276247c08596SBrooks Davis 	unsigned char *dp = data;
276347c08596SBrooks Davis 
276447c08596SBrooks Davis 	if (code > 255)
276547c08596SBrooks Davis 		error("option_as_string: bad code %d", code);
276647c08596SBrooks Davis 
276747c08596SBrooks Davis 	for (; dp < data + len; dp++) {
276847c08596SBrooks Davis 		if (!isascii(*dp) || !isprint(*dp)) {
276947c08596SBrooks Davis 			if (dp + 1 != data + len || *dp != 0) {
277047c08596SBrooks Davis 				snprintf(op, opleft, "\\%03o", *dp);
277147c08596SBrooks Davis 				op += 4;
277247c08596SBrooks Davis 				opleft -= 4;
277347c08596SBrooks Davis 			}
277447c08596SBrooks Davis 		} else if (*dp == '"' || *dp == '\'' || *dp == '$' ||
277547c08596SBrooks Davis 		    *dp == '`' || *dp == '\\') {
277647c08596SBrooks Davis 			*op++ = '\\';
277747c08596SBrooks Davis 			*op++ = *dp;
277847c08596SBrooks Davis 			opleft -= 2;
277947c08596SBrooks Davis 		} else {
278047c08596SBrooks Davis 			*op++ = *dp;
278147c08596SBrooks Davis 			opleft--;
278247c08596SBrooks Davis 		}
278347c08596SBrooks Davis 	}
278447c08596SBrooks Davis 	if (opleft < 1)
278547c08596SBrooks Davis 		goto toobig;
278647c08596SBrooks Davis 	*op = 0;
278747c08596SBrooks Davis 	return optbuf;
278847c08596SBrooks Davis toobig:
278947c08596SBrooks Davis 	warning("dhcp option too large");
279047c08596SBrooks Davis 	return "<error>";
279147c08596SBrooks Davis }
279247c08596SBrooks Davis 
279347c08596SBrooks Davis int
279447c08596SBrooks Davis fork_privchld(int fd, int fd2)
279547c08596SBrooks Davis {
279647c08596SBrooks Davis 	struct pollfd pfd[1];
279747c08596SBrooks Davis 	int nfds;
279847c08596SBrooks Davis 
279947c08596SBrooks Davis 	switch (fork()) {
280047c08596SBrooks Davis 	case -1:
280147c08596SBrooks Davis 		error("cannot fork");
280247c08596SBrooks Davis 	case 0:
280347c08596SBrooks Davis 		break;
280447c08596SBrooks Davis 	default:
280547c08596SBrooks Davis 		return (0);
280647c08596SBrooks Davis 	}
280747c08596SBrooks Davis 
280847c08596SBrooks Davis 	setproctitle("%s [priv]", ifi->name);
280947c08596SBrooks Davis 
281070892546SEd Schouten 	setsid();
281147c08596SBrooks Davis 	dup2(nullfd, STDIN_FILENO);
281247c08596SBrooks Davis 	dup2(nullfd, STDOUT_FILENO);
281347c08596SBrooks Davis 	dup2(nullfd, STDERR_FILENO);
281447c08596SBrooks Davis 	close(nullfd);
281547c08596SBrooks Davis 	close(fd2);
2816235eb530SPawel Jakub Dawidek 	close(ifi->rfdesc);
2817235eb530SPawel Jakub Dawidek 	ifi->rfdesc = -1;
281847c08596SBrooks Davis 
281947c08596SBrooks Davis 	for (;;) {
282047c08596SBrooks Davis 		pfd[0].fd = fd;
282147c08596SBrooks Davis 		pfd[0].events = POLLIN;
282247c08596SBrooks Davis 		if ((nfds = poll(pfd, 1, INFTIM)) == -1)
282347c08596SBrooks Davis 			if (errno != EINTR)
282447c08596SBrooks Davis 				error("poll error");
282547c08596SBrooks Davis 
282647c08596SBrooks Davis 		if (nfds == 0 || !(pfd[0].revents & POLLIN))
282747c08596SBrooks Davis 			continue;
282847c08596SBrooks Davis 
2829235eb530SPawel Jakub Dawidek 		dispatch_imsg(ifi, fd);
283047c08596SBrooks Davis 	}
283147c08596SBrooks Davis }
2832