1ca007d91SDag-Erling Smørgrav /*- 21de7b4b8SPedro F. Giffuni * SPDX-License-Identifier: BSD-2-Clause-FreeBSD 31de7b4b8SPedro F. Giffuni * 4fb2ad9d3SUlrich Spörlein * Copyright (c) 2002 Dag-Erling Coïdan Smørgrav 5ca007d91SDag-Erling Smørgrav * All rights reserved. 6ca007d91SDag-Erling Smørgrav * 7ca007d91SDag-Erling Smørgrav * Redistribution and use in source and binary forms, with or without 8ca007d91SDag-Erling Smørgrav * modification, are permitted provided that the following conditions 9ca007d91SDag-Erling Smørgrav * are met: 10ca007d91SDag-Erling Smørgrav * 1. Redistributions of source code must retain the above copyright 11ca007d91SDag-Erling Smørgrav * notice, this list of conditions and the following disclaimer 12ca007d91SDag-Erling Smørgrav * in this position and unchanged. 13ca007d91SDag-Erling Smørgrav * 2. Redistributions in binary form must reproduce the above copyright 14ca007d91SDag-Erling Smørgrav * notice, this list of conditions and the following disclaimer in the 15ca007d91SDag-Erling Smørgrav * documentation and/or other materials provided with the distribution. 16ca007d91SDag-Erling Smørgrav * 3. The name of the author may not be used to endorse or promote products 17ca007d91SDag-Erling Smørgrav * derived from this software without specific prior written permission. 18ca007d91SDag-Erling Smørgrav * 19ca007d91SDag-Erling Smørgrav * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 20ca007d91SDag-Erling Smørgrav * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 21ca007d91SDag-Erling Smørgrav * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 22ca007d91SDag-Erling Smørgrav * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 23ca007d91SDag-Erling Smørgrav * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 24ca007d91SDag-Erling Smørgrav * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 25ca007d91SDag-Erling Smørgrav * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 26ca007d91SDag-Erling Smørgrav * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 27ca007d91SDag-Erling Smørgrav * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 28ca007d91SDag-Erling Smørgrav * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 29ca007d91SDag-Erling Smørgrav */ 30ca007d91SDag-Erling Smørgrav 31ca007d91SDag-Erling Smørgrav #include <sys/cdefs.h> 32ca007d91SDag-Erling Smørgrav __FBSDID("$FreeBSD$"); 33ca007d91SDag-Erling Smørgrav 34ca007d91SDag-Erling Smørgrav #include <sys/param.h> 35f1cd4902SRyan Moeller #include <sys/file.h> 36ca007d91SDag-Erling Smørgrav #include <sys/socket.h> 37ca007d91SDag-Erling Smørgrav #include <sys/socketvar.h> 38ca007d91SDag-Erling Smørgrav #include <sys/sysctl.h> 39f1cd4902SRyan Moeller #include <sys/jail.h> 40ca007d91SDag-Erling Smørgrav #include <sys/user.h> 41ca007d91SDag-Erling Smørgrav 42ca007d91SDag-Erling Smørgrav #include <sys/un.h> 430e229f34SGleb Smirnoff #define _WANT_UNPCB 44ca007d91SDag-Erling Smørgrav #include <sys/unpcb.h> 45ca007d91SDag-Erling Smørgrav 4602bd9db0SDag-Erling Smørgrav #include <net/route.h> 4702bd9db0SDag-Erling Smørgrav 48ca007d91SDag-Erling Smørgrav #include <netinet/in.h> 49ca007d91SDag-Erling Smørgrav #include <netinet/in_pcb.h> 50d5b4aa90SMichael Tuexen #include <netinet/sctp.h> 51ca007d91SDag-Erling Smørgrav #include <netinet/tcp.h> 527a5642b3SDag-Erling Smørgrav #define TCPSTATES /* load state names */ 537a5642b3SDag-Erling Smørgrav #include <netinet/tcp_fsm.h> 54ca007d91SDag-Erling Smørgrav #include <netinet/tcp_seq.h> 55ca007d91SDag-Erling Smørgrav #include <netinet/tcp_var.h> 56ca007d91SDag-Erling Smørgrav #include <arpa/inet.h> 57ca007d91SDag-Erling Smørgrav 58c5a2d8c5SRyan Moeller #include <capsicum_helpers.h> 59ca007d91SDag-Erling Smørgrav #include <ctype.h> 60ca007d91SDag-Erling Smørgrav #include <err.h> 61ca007d91SDag-Erling Smørgrav #include <errno.h> 62de68a320SJamie Gritton #include <jail.h> 63ca007d91SDag-Erling Smørgrav #include <netdb.h> 64ca007d91SDag-Erling Smørgrav #include <pwd.h> 65ca007d91SDag-Erling Smørgrav #include <stdarg.h> 66ca007d91SDag-Erling Smørgrav #include <stdio.h> 67ca007d91SDag-Erling Smørgrav #include <stdlib.h> 68ca007d91SDag-Erling Smørgrav #include <string.h> 69ca007d91SDag-Erling Smørgrav #include <unistd.h> 70ca007d91SDag-Erling Smørgrav 71c5a2d8c5SRyan Moeller #include <libcasper.h> 72c5a2d8c5SRyan Moeller #include <casper/cap_net.h> 73c5a2d8c5SRyan Moeller #include <casper/cap_netdb.h> 747ad30f58SMariusz Zaborski #include <casper/cap_pwd.h> 75c5a2d8c5SRyan Moeller #include <casper/cap_sysctl.h> 76c5a2d8c5SRyan Moeller 77b8e20e2dSHiroki Sato #define sstosin(ss) ((struct sockaddr_in *)(ss)) 78b8e20e2dSHiroki Sato #define sstosin6(ss) ((struct sockaddr_in6 *)(ss)) 79b8e20e2dSHiroki Sato #define sstosun(ss) ((struct sockaddr_un *)(ss)) 80b8e20e2dSHiroki Sato #define sstosa(ss) ((struct sockaddr *)(ss)) 81b8e20e2dSHiroki Sato 82ca007d91SDag-Erling Smørgrav static int opt_4; /* Show IPv4 sockets */ 83ca007d91SDag-Erling Smørgrav static int opt_6; /* Show IPv6 sockets */ 842ac089d0SMichael Tuexen static int opt_C; /* Show congestion control */ 85ca007d91SDag-Erling Smørgrav static int opt_c; /* Show connected sockets */ 8600feaafdSAndrew Thompson static int opt_j; /* Show specified jail */ 879b6ca892SBruce M Simpson static int opt_L; /* Don't show IPv4 or IPv6 loopback sockets */ 88ca007d91SDag-Erling Smørgrav static int opt_l; /* Show listening sockets */ 89ccdd2b2bSAlexander Motin static int opt_n; /* Don't resolve UIDs to user names */ 90ee0afaa9SEmmanuel Vadot static int opt_q; /* Don't show header */ 91e5cccc35SMichael Tuexen static int opt_S; /* Show protocol stack if applicable */ 927a5642b3SDag-Erling Smørgrav static int opt_s; /* Show protocol state if applicable */ 9349b836f2SMichael Tuexen static int opt_U; /* Show remote UDP encapsulation port number */ 94ca007d91SDag-Erling Smørgrav static int opt_u; /* Show Unix domain sockets */ 95ca007d91SDag-Erling Smørgrav static int opt_v; /* Verbose mode */ 9683f60cb2SMichael Tuexen static int opt_w; /* Wide print area for addresses */ 97ca007d91SDag-Erling Smørgrav 981f3d67aaSGiorgos Keramidas /* 991f3d67aaSGiorgos Keramidas * Default protocols to use if no -P was defined. 1001f3d67aaSGiorgos Keramidas */ 101d5b4aa90SMichael Tuexen static const char *default_protos[] = {"sctp", "tcp", "udp", "divert" }; 102b8e20e2dSHiroki Sato static size_t default_numprotos = nitems(default_protos); 1031f3d67aaSGiorgos Keramidas 1041f3d67aaSGiorgos Keramidas static int *protos; /* protocols to use */ 1051f3d67aaSGiorgos Keramidas static size_t numprotos; /* allocated size of protos[] */ 1061f3d67aaSGiorgos Keramidas 107ca007d91SDag-Erling Smørgrav static int *ports; 108ca007d91SDag-Erling Smørgrav 109ca007d91SDag-Erling Smørgrav #define INT_BIT (sizeof(int)*CHAR_BIT) 110ca007d91SDag-Erling Smørgrav #define SET_PORT(p) do { ports[p / INT_BIT] |= 1 << (p % INT_BIT); } while (0) 111ca007d91SDag-Erling Smørgrav #define CHK_PORT(p) (ports[p / INT_BIT] & (1 << (p % INT_BIT))) 112ca007d91SDag-Erling Smørgrav 113e6f718c7SMichael Tuexen struct addr { 114e6f718c7SMichael Tuexen struct sockaddr_storage address; 11549b836f2SMichael Tuexen unsigned int encaps_port; 116e389705eSMichael Tuexen int state; 117e6f718c7SMichael Tuexen struct addr *next; 118e6f718c7SMichael Tuexen }; 119e6f718c7SMichael Tuexen 120ca007d91SDag-Erling Smørgrav struct sock { 121f38b68aeSBrooks Davis kvaddr_t socket; 122f38b68aeSBrooks Davis kvaddr_t pcb; 12361149f8dSJilles Tjoelker int shown; 124ca007d91SDag-Erling Smørgrav int vflag; 125ca007d91SDag-Erling Smørgrav int family; 126ca007d91SDag-Erling Smørgrav int proto; 1277a5642b3SDag-Erling Smørgrav int state; 128ca007d91SDag-Erling Smørgrav const char *protoname; 129e5cccc35SMichael Tuexen char stack[TCP_FUNCTION_NAME_LEN_MAX]; 1302ac089d0SMichael Tuexen char cc[TCP_CA_NAME_MAX]; 131e6f718c7SMichael Tuexen struct addr *laddr; 132e6f718c7SMichael Tuexen struct addr *faddr; 133ca007d91SDag-Erling Smørgrav struct sock *next; 134ca007d91SDag-Erling Smørgrav }; 135ca007d91SDag-Erling Smørgrav 136ca007d91SDag-Erling Smørgrav #define HASHSIZE 1009 137ca007d91SDag-Erling Smørgrav static struct sock *sockhash[HASHSIZE]; 138ca007d91SDag-Erling Smørgrav 139ca007d91SDag-Erling Smørgrav static struct xfile *xfiles; 140ca007d91SDag-Erling Smørgrav static int nxfiles; 141ca007d91SDag-Erling Smørgrav 142c5a2d8c5SRyan Moeller static cap_channel_t *capnet; 143c5a2d8c5SRyan Moeller static cap_channel_t *capnetdb; 144c5a2d8c5SRyan Moeller static cap_channel_t *capsysctl; 1457ad30f58SMariusz Zaborski static cap_channel_t *cappwd; 146c5a2d8c5SRyan Moeller 147ca007d91SDag-Erling Smørgrav static int 148ca007d91SDag-Erling Smørgrav xprintf(const char *fmt, ...) 149ca007d91SDag-Erling Smørgrav { 150ca007d91SDag-Erling Smørgrav va_list ap; 151ca007d91SDag-Erling Smørgrav int len; 152ca007d91SDag-Erling Smørgrav 153ca007d91SDag-Erling Smørgrav va_start(ap, fmt); 154ca007d91SDag-Erling Smørgrav len = vprintf(fmt, ap); 155ca007d91SDag-Erling Smørgrav va_end(ap); 156ca007d91SDag-Erling Smørgrav if (len < 0) 157ca007d91SDag-Erling Smørgrav err(1, "printf()"); 158ca007d91SDag-Erling Smørgrav return (len); 159ca007d91SDag-Erling Smørgrav } 160ca007d91SDag-Erling Smørgrav 1611f3d67aaSGiorgos Keramidas static int 1621f3d67aaSGiorgos Keramidas get_proto_type(const char *proto) 1631f3d67aaSGiorgos Keramidas { 1641f3d67aaSGiorgos Keramidas struct protoent *pent; 1651f3d67aaSGiorgos Keramidas 1661f3d67aaSGiorgos Keramidas if (strlen(proto) == 0) 1671f3d67aaSGiorgos Keramidas return (0); 168bfb5947bSMariusz Zaborski if (capnetdb != NULL) 169c5a2d8c5SRyan Moeller pent = cap_getprotobyname(capnetdb, proto); 170bfb5947bSMariusz Zaborski else 171bfb5947bSMariusz Zaborski pent = getprotobyname(proto); 1721f3d67aaSGiorgos Keramidas if (pent == NULL) { 173c5a2d8c5SRyan Moeller warn("cap_getprotobyname"); 1741f3d67aaSGiorgos Keramidas return (-1); 1751f3d67aaSGiorgos Keramidas } 1761f3d67aaSGiorgos Keramidas return (pent->p_proto); 1771f3d67aaSGiorgos Keramidas } 1781f3d67aaSGiorgos Keramidas 179b8e20e2dSHiroki Sato static void 180b8e20e2dSHiroki Sato init_protos(int num) 1811f3d67aaSGiorgos Keramidas { 1821f3d67aaSGiorgos Keramidas int proto_count = 0; 1831f3d67aaSGiorgos Keramidas 1841f3d67aaSGiorgos Keramidas if (num > 0) { 1851f3d67aaSGiorgos Keramidas proto_count = num; 1861f3d67aaSGiorgos Keramidas } else { 1871f3d67aaSGiorgos Keramidas /* Find the maximum number of possible protocols. */ 1881f3d67aaSGiorgos Keramidas while (getprotoent() != NULL) 1891f3d67aaSGiorgos Keramidas proto_count++; 1901f3d67aaSGiorgos Keramidas endprotoent(); 1911f3d67aaSGiorgos Keramidas } 1921f3d67aaSGiorgos Keramidas 1931f3d67aaSGiorgos Keramidas if ((protos = malloc(sizeof(int) * proto_count)) == NULL) 1941f3d67aaSGiorgos Keramidas err(1, "malloc"); 1951f3d67aaSGiorgos Keramidas numprotos = proto_count; 1961f3d67aaSGiorgos Keramidas } 1971f3d67aaSGiorgos Keramidas 1981f3d67aaSGiorgos Keramidas static int 1991f3d67aaSGiorgos Keramidas parse_protos(char *protospec) 2001f3d67aaSGiorgos Keramidas { 2011f3d67aaSGiorgos Keramidas char *prot; 2021f3d67aaSGiorgos Keramidas int proto_type, proto_index; 2031f3d67aaSGiorgos Keramidas 2041f3d67aaSGiorgos Keramidas if (protospec == NULL) 2051f3d67aaSGiorgos Keramidas return (-1); 2061f3d67aaSGiorgos Keramidas 2071f3d67aaSGiorgos Keramidas init_protos(0); 2081f3d67aaSGiorgos Keramidas proto_index = 0; 209b8e20e2dSHiroki Sato while ((prot = strsep(&protospec, ",")) != NULL) { 2101f3d67aaSGiorgos Keramidas if (strlen(prot) == 0) 2111f3d67aaSGiorgos Keramidas continue; 2121f3d67aaSGiorgos Keramidas proto_type = get_proto_type(prot); 2131f3d67aaSGiorgos Keramidas if (proto_type != -1) 2141f3d67aaSGiorgos Keramidas protos[proto_index++] = proto_type; 2151f3d67aaSGiorgos Keramidas } 2161f3d67aaSGiorgos Keramidas numprotos = proto_index; 2171f3d67aaSGiorgos Keramidas return (proto_index); 2181f3d67aaSGiorgos Keramidas } 2191f3d67aaSGiorgos Keramidas 220ca007d91SDag-Erling Smørgrav static void 221ca007d91SDag-Erling Smørgrav parse_ports(const char *portspec) 222ca007d91SDag-Erling Smørgrav { 223ca007d91SDag-Erling Smørgrav const char *p, *q; 224ca007d91SDag-Erling Smørgrav int port, end; 225ca007d91SDag-Erling Smørgrav 226ca007d91SDag-Erling Smørgrav if (ports == NULL) 2279efed1e6SRobert Drehmel if ((ports = calloc(65536 / INT_BIT, sizeof(int))) == NULL) 228ca007d91SDag-Erling Smørgrav err(1, "calloc()"); 229ca007d91SDag-Erling Smørgrav p = portspec; 230ca007d91SDag-Erling Smørgrav while (*p != '\0') { 231ca007d91SDag-Erling Smørgrav if (!isdigit(*p)) 232ca007d91SDag-Erling Smørgrav errx(1, "syntax error in port range"); 233ca007d91SDag-Erling Smørgrav for (q = p; *q != '\0' && isdigit(*q); ++q) 234ca007d91SDag-Erling Smørgrav /* nothing */ ; 235ca007d91SDag-Erling Smørgrav for (port = 0; p < q; ++p) 236ca007d91SDag-Erling Smørgrav port = port * 10 + digittoint(*p); 237ca007d91SDag-Erling Smørgrav if (port < 0 || port > 65535) 238ca007d91SDag-Erling Smørgrav errx(1, "invalid port number"); 239ca007d91SDag-Erling Smørgrav SET_PORT(port); 240ca007d91SDag-Erling Smørgrav switch (*p) { 241ca007d91SDag-Erling Smørgrav case '-': 242ca007d91SDag-Erling Smørgrav ++p; 243ca007d91SDag-Erling Smørgrav break; 244ca007d91SDag-Erling Smørgrav case ',': 245ca007d91SDag-Erling Smørgrav ++p; 246ca007d91SDag-Erling Smørgrav /* fall through */ 247ca007d91SDag-Erling Smørgrav case '\0': 248ca007d91SDag-Erling Smørgrav default: 249ca007d91SDag-Erling Smørgrav continue; 250ca007d91SDag-Erling Smørgrav } 251ca007d91SDag-Erling Smørgrav for (q = p; *q != '\0' && isdigit(*q); ++q) 252ca007d91SDag-Erling Smørgrav /* nothing */ ; 253ca007d91SDag-Erling Smørgrav for (end = 0; p < q; ++p) 254ca007d91SDag-Erling Smørgrav end = end * 10 + digittoint(*p); 255ca007d91SDag-Erling Smørgrav if (end < port || end > 65535) 256ca007d91SDag-Erling Smørgrav errx(1, "invalid port number"); 257ca007d91SDag-Erling Smørgrav while (port++ < end) 258ca007d91SDag-Erling Smørgrav SET_PORT(port); 259ca007d91SDag-Erling Smørgrav if (*p == ',') 260ca007d91SDag-Erling Smørgrav ++p; 261ca007d91SDag-Erling Smørgrav } 262ca007d91SDag-Erling Smørgrav } 263ca007d91SDag-Erling Smørgrav 264ca007d91SDag-Erling Smørgrav static void 265b8e20e2dSHiroki Sato sockaddr(struct sockaddr_storage *ss, int af, void *addr, int port) 266ca007d91SDag-Erling Smørgrav { 267ca007d91SDag-Erling Smørgrav struct sockaddr_in *sin4; 268ca007d91SDag-Erling Smørgrav struct sockaddr_in6 *sin6; 269ca007d91SDag-Erling Smørgrav 270b8e20e2dSHiroki Sato bzero(ss, sizeof(*ss)); 271ca007d91SDag-Erling Smørgrav switch (af) { 272ca007d91SDag-Erling Smørgrav case AF_INET: 273b8e20e2dSHiroki Sato sin4 = sstosin(ss); 274b8e20e2dSHiroki Sato sin4->sin_len = sizeof(*sin4); 275ca007d91SDag-Erling Smørgrav sin4->sin_family = af; 276ca007d91SDag-Erling Smørgrav sin4->sin_port = port; 277ca007d91SDag-Erling Smørgrav sin4->sin_addr = *(struct in_addr *)addr; 278ca007d91SDag-Erling Smørgrav break; 279ca007d91SDag-Erling Smørgrav case AF_INET6: 280b8e20e2dSHiroki Sato sin6 = sstosin6(ss); 281b8e20e2dSHiroki Sato sin6->sin6_len = sizeof(*sin6); 282ca007d91SDag-Erling Smørgrav sin6->sin6_family = af; 283ca007d91SDag-Erling Smørgrav sin6->sin6_port = port; 284ca007d91SDag-Erling Smørgrav sin6->sin6_addr = *(struct in6_addr *)addr; 285b8e20e2dSHiroki Sato #define s6_addr16 __u6_addr.__u6_addr16 286b8e20e2dSHiroki Sato if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr)) { 287b8e20e2dSHiroki Sato sin6->sin6_scope_id = 288b8e20e2dSHiroki Sato ntohs(sin6->sin6_addr.s6_addr16[1]); 289b8e20e2dSHiroki Sato sin6->sin6_addr.s6_addr16[1] = 0; 290b8e20e2dSHiroki Sato } 291ca007d91SDag-Erling Smørgrav break; 292ca007d91SDag-Erling Smørgrav default: 293ca007d91SDag-Erling Smørgrav abort(); 294ca007d91SDag-Erling Smørgrav } 295ca007d91SDag-Erling Smørgrav } 296ca007d91SDag-Erling Smørgrav 297ca007d91SDag-Erling Smørgrav static void 298bedcf91dSMichael Tuexen free_socket(struct sock *sock) 299bedcf91dSMichael Tuexen { 300bedcf91dSMichael Tuexen struct addr *cur, *next; 301bedcf91dSMichael Tuexen 302bedcf91dSMichael Tuexen cur = sock->laddr; 303bedcf91dSMichael Tuexen while (cur != NULL) { 304bedcf91dSMichael Tuexen next = cur->next; 305bedcf91dSMichael Tuexen free(cur); 306bedcf91dSMichael Tuexen cur = next; 307bedcf91dSMichael Tuexen } 308bedcf91dSMichael Tuexen cur = sock->faddr; 309bedcf91dSMichael Tuexen while (cur != NULL) { 310bedcf91dSMichael Tuexen next = cur->next; 311bedcf91dSMichael Tuexen free(cur); 312bedcf91dSMichael Tuexen cur = next; 313bedcf91dSMichael Tuexen } 314bedcf91dSMichael Tuexen free(sock); 315bedcf91dSMichael Tuexen } 316bedcf91dSMichael Tuexen 317bedcf91dSMichael Tuexen static void 318d5b4aa90SMichael Tuexen gather_sctp(void) 319d5b4aa90SMichael Tuexen { 320d5b4aa90SMichael Tuexen struct sock *sock; 321d5b4aa90SMichael Tuexen struct addr *laddr, *prev_laddr, *faddr, *prev_faddr; 322d5b4aa90SMichael Tuexen struct xsctp_inpcb *xinpcb; 323d5b4aa90SMichael Tuexen struct xsctp_tcb *xstcb; 324d5b4aa90SMichael Tuexen struct xsctp_raddr *xraddr; 325d5b4aa90SMichael Tuexen struct xsctp_laddr *xladdr; 326d5b4aa90SMichael Tuexen const char *varname; 327d5b4aa90SMichael Tuexen size_t len, offset; 328d5b4aa90SMichael Tuexen char *buf; 329d5b4aa90SMichael Tuexen int hash, vflag; 330d5b4aa90SMichael Tuexen int no_stcb, local_all_loopback, foreign_all_loopback; 331d5b4aa90SMichael Tuexen 332d5b4aa90SMichael Tuexen vflag = 0; 333d5b4aa90SMichael Tuexen if (opt_4) 334d5b4aa90SMichael Tuexen vflag |= INP_IPV4; 335d5b4aa90SMichael Tuexen if (opt_6) 336d5b4aa90SMichael Tuexen vflag |= INP_IPV6; 337d5b4aa90SMichael Tuexen 338d5b4aa90SMichael Tuexen varname = "net.inet.sctp.assoclist"; 339c5a2d8c5SRyan Moeller if (cap_sysctlbyname(capsysctl, varname, 0, &len, 0, 0) < 0) { 340d5b4aa90SMichael Tuexen if (errno != ENOENT) 341c5a2d8c5SRyan Moeller err(1, "cap_sysctlbyname()"); 342d5b4aa90SMichael Tuexen return; 343d5b4aa90SMichael Tuexen } 344d5b4aa90SMichael Tuexen if ((buf = (char *)malloc(len)) == NULL) { 345d5b4aa90SMichael Tuexen err(1, "malloc()"); 346d5b4aa90SMichael Tuexen return; 347d5b4aa90SMichael Tuexen } 348c5a2d8c5SRyan Moeller if (cap_sysctlbyname(capsysctl, varname, buf, &len, 0, 0) < 0) { 349c5a2d8c5SRyan Moeller err(1, "cap_sysctlbyname()"); 350d5b4aa90SMichael Tuexen free(buf); 351d5b4aa90SMichael Tuexen return; 352d5b4aa90SMichael Tuexen } 353d5b4aa90SMichael Tuexen xinpcb = (struct xsctp_inpcb *)(void *)buf; 354d5b4aa90SMichael Tuexen offset = sizeof(struct xsctp_inpcb); 355d5b4aa90SMichael Tuexen while ((offset < len) && (xinpcb->last == 0)) { 356d5b4aa90SMichael Tuexen if ((sock = calloc(1, sizeof *sock)) == NULL) 357d5b4aa90SMichael Tuexen err(1, "malloc()"); 358d5b4aa90SMichael Tuexen sock->socket = xinpcb->socket; 359d5b4aa90SMichael Tuexen sock->proto = IPPROTO_SCTP; 360d5b4aa90SMichael Tuexen sock->protoname = "sctp"; 361c1eb13c7SMichael Tuexen if (xinpcb->maxqlen == 0) 3626414db1bSMichael Tuexen sock->state = SCTP_CLOSED; 3636414db1bSMichael Tuexen else 3646414db1bSMichael Tuexen sock->state = SCTP_LISTEN; 365d5b4aa90SMichael Tuexen if (xinpcb->flags & SCTP_PCB_FLAGS_BOUND_V6) { 366d5b4aa90SMichael Tuexen sock->family = AF_INET6; 367edc9c7fcSMichael Tuexen /* 368edc9c7fcSMichael Tuexen * Currently there is no way to distinguish between 369edc9c7fcSMichael Tuexen * IPv6 only sockets or dual family sockets. 370edc9c7fcSMichael Tuexen * So mark it as dual socket. 371edc9c7fcSMichael Tuexen */ 372edc9c7fcSMichael Tuexen sock->vflag = INP_IPV6 | INP_IPV4; 373d5b4aa90SMichael Tuexen } else { 374d5b4aa90SMichael Tuexen sock->family = AF_INET; 375d5b4aa90SMichael Tuexen sock->vflag = INP_IPV4; 376d5b4aa90SMichael Tuexen } 377d5b4aa90SMichael Tuexen prev_laddr = NULL; 378d5b4aa90SMichael Tuexen local_all_loopback = 1; 379d5b4aa90SMichael Tuexen while (offset < len) { 380d5b4aa90SMichael Tuexen xladdr = (struct xsctp_laddr *)(void *)(buf + offset); 381d5b4aa90SMichael Tuexen offset += sizeof(struct xsctp_laddr); 382d5b4aa90SMichael Tuexen if (xladdr->last == 1) 383d5b4aa90SMichael Tuexen break; 384d5b4aa90SMichael Tuexen if ((laddr = calloc(1, sizeof(struct addr))) == NULL) 385d5b4aa90SMichael Tuexen err(1, "malloc()"); 386d5b4aa90SMichael Tuexen switch (xladdr->address.sa.sa_family) { 387d5b4aa90SMichael Tuexen case AF_INET: 388d5b4aa90SMichael Tuexen #define __IN_IS_ADDR_LOOPBACK(pina) \ 389d5b4aa90SMichael Tuexen ((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET) 39027569d01SRenato Botelho if (!__IN_IS_ADDR_LOOPBACK( 39127569d01SRenato Botelho &xladdr->address.sin.sin_addr)) 392d5b4aa90SMichael Tuexen local_all_loopback = 0; 393d5b4aa90SMichael Tuexen #undef __IN_IS_ADDR_LOOPBACK 39427569d01SRenato Botelho sockaddr(&laddr->address, AF_INET, 395d5b4aa90SMichael Tuexen &xladdr->address.sin.sin_addr, 396d5b4aa90SMichael Tuexen htons(xinpcb->local_port)); 397d5b4aa90SMichael Tuexen break; 398d5b4aa90SMichael Tuexen case AF_INET6: 39927569d01SRenato Botelho if (!IN6_IS_ADDR_LOOPBACK( 40027569d01SRenato Botelho &xladdr->address.sin6.sin6_addr)) 401d5b4aa90SMichael Tuexen local_all_loopback = 0; 40227569d01SRenato Botelho sockaddr(&laddr->address, AF_INET6, 403d5b4aa90SMichael Tuexen &xladdr->address.sin6.sin6_addr, 404d5b4aa90SMichael Tuexen htons(xinpcb->local_port)); 405d5b4aa90SMichael Tuexen break; 406d5b4aa90SMichael Tuexen default: 407463a577bSEitan Adler errx(1, "address family %d not supported", 408d5b4aa90SMichael Tuexen xladdr->address.sa.sa_family); 409d5b4aa90SMichael Tuexen } 410d5b4aa90SMichael Tuexen laddr->next = NULL; 411d5b4aa90SMichael Tuexen if (prev_laddr == NULL) 412d5b4aa90SMichael Tuexen sock->laddr = laddr; 413d5b4aa90SMichael Tuexen else 414d5b4aa90SMichael Tuexen prev_laddr->next = laddr; 415d5b4aa90SMichael Tuexen prev_laddr = laddr; 416d5b4aa90SMichael Tuexen } 417d5b4aa90SMichael Tuexen if (sock->laddr == NULL) { 41827569d01SRenato Botelho if ((sock->laddr = 41927569d01SRenato Botelho calloc(1, sizeof(struct addr))) == NULL) 420d5b4aa90SMichael Tuexen err(1, "malloc()"); 421d5b4aa90SMichael Tuexen sock->laddr->address.ss_family = sock->family; 422d5b4aa90SMichael Tuexen if (sock->family == AF_INET) 42327569d01SRenato Botelho sock->laddr->address.ss_len = 42427569d01SRenato Botelho sizeof(struct sockaddr_in); 425d5b4aa90SMichael Tuexen else 42627569d01SRenato Botelho sock->laddr->address.ss_len = 42727569d01SRenato Botelho sizeof(struct sockaddr_in6); 428d5b4aa90SMichael Tuexen local_all_loopback = 0; 429d5b4aa90SMichael Tuexen } 430d5b4aa90SMichael Tuexen if ((sock->faddr = calloc(1, sizeof(struct addr))) == NULL) 431d5b4aa90SMichael Tuexen err(1, "malloc()"); 432d5b4aa90SMichael Tuexen sock->faddr->address.ss_family = sock->family; 433d5b4aa90SMichael Tuexen if (sock->family == AF_INET) 43427569d01SRenato Botelho sock->faddr->address.ss_len = 43527569d01SRenato Botelho sizeof(struct sockaddr_in); 436d5b4aa90SMichael Tuexen else 43727569d01SRenato Botelho sock->faddr->address.ss_len = 43827569d01SRenato Botelho sizeof(struct sockaddr_in6); 439d5b4aa90SMichael Tuexen no_stcb = 1; 440d5b4aa90SMichael Tuexen while (offset < len) { 441d5b4aa90SMichael Tuexen xstcb = (struct xsctp_tcb *)(void *)(buf + offset); 442d5b4aa90SMichael Tuexen offset += sizeof(struct xsctp_tcb); 443bedcf91dSMichael Tuexen if (no_stcb) { 44427569d01SRenato Botelho if (opt_l && (sock->vflag & vflag) && 445d5b4aa90SMichael Tuexen (!opt_L || !local_all_loopback) && 446d5b4aa90SMichael Tuexen ((xinpcb->flags & SCTP_PCB_FLAGS_UDPTYPE) || 447d5b4aa90SMichael Tuexen (xstcb->last == 1))) { 44827569d01SRenato Botelho hash = (int)((uintptr_t)sock->socket % 44927569d01SRenato Botelho HASHSIZE); 450d5b4aa90SMichael Tuexen sock->next = sockhash[hash]; 451d5b4aa90SMichael Tuexen sockhash[hash] = sock; 452bedcf91dSMichael Tuexen } else { 453bedcf91dSMichael Tuexen free_socket(sock); 454bedcf91dSMichael Tuexen } 455d5b4aa90SMichael Tuexen } 456d5b4aa90SMichael Tuexen if (xstcb->last == 1) 457d5b4aa90SMichael Tuexen break; 458d5b4aa90SMichael Tuexen no_stcb = 0; 459d5b4aa90SMichael Tuexen if (opt_c) { 460d5b4aa90SMichael Tuexen if ((sock = calloc(1, sizeof *sock)) == NULL) 461d5b4aa90SMichael Tuexen err(1, "malloc()"); 462d5b4aa90SMichael Tuexen sock->socket = xinpcb->socket; 463d5b4aa90SMichael Tuexen sock->proto = IPPROTO_SCTP; 464d5b4aa90SMichael Tuexen sock->protoname = "sctp"; 4656414db1bSMichael Tuexen sock->state = (int)xstcb->state; 466d5b4aa90SMichael Tuexen if (xinpcb->flags & SCTP_PCB_FLAGS_BOUND_V6) { 467d5b4aa90SMichael Tuexen sock->family = AF_INET6; 468edc9c7fcSMichael Tuexen /* 469edc9c7fcSMichael Tuexen * Currently there is no way to distinguish 470edc9c7fcSMichael Tuexen * between IPv6 only sockets or dual family 471edc9c7fcSMichael Tuexen * sockets. So mark it as dual socket. 472edc9c7fcSMichael Tuexen */ 473edc9c7fcSMichael Tuexen sock->vflag = INP_IPV6 | INP_IPV4; 474d5b4aa90SMichael Tuexen } else { 475d5b4aa90SMichael Tuexen sock->family = AF_INET; 476d5b4aa90SMichael Tuexen sock->vflag = INP_IPV4; 477d5b4aa90SMichael Tuexen } 478d5b4aa90SMichael Tuexen } 479d5b4aa90SMichael Tuexen prev_laddr = NULL; 480d5b4aa90SMichael Tuexen local_all_loopback = 1; 481d5b4aa90SMichael Tuexen while (offset < len) { 48227569d01SRenato Botelho xladdr = (struct xsctp_laddr *)(void *)(buf + 48327569d01SRenato Botelho offset); 484d5b4aa90SMichael Tuexen offset += sizeof(struct xsctp_laddr); 485d5b4aa90SMichael Tuexen if (xladdr->last == 1) 486d5b4aa90SMichael Tuexen break; 487d5b4aa90SMichael Tuexen if (!opt_c) 488d5b4aa90SMichael Tuexen continue; 48927569d01SRenato Botelho laddr = calloc(1, sizeof(struct addr)); 49027569d01SRenato Botelho if (laddr == NULL) 491d5b4aa90SMichael Tuexen err(1, "malloc()"); 492d5b4aa90SMichael Tuexen switch (xladdr->address.sa.sa_family) { 493d5b4aa90SMichael Tuexen case AF_INET: 494d5b4aa90SMichael Tuexen #define __IN_IS_ADDR_LOOPBACK(pina) \ 495d5b4aa90SMichael Tuexen ((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET) 49627569d01SRenato Botelho if (!__IN_IS_ADDR_LOOPBACK( 49727569d01SRenato Botelho &xladdr->address.sin.sin_addr)) 498d5b4aa90SMichael Tuexen local_all_loopback = 0; 499d5b4aa90SMichael Tuexen #undef __IN_IS_ADDR_LOOPBACK 50027569d01SRenato Botelho sockaddr(&laddr->address, AF_INET, 501d5b4aa90SMichael Tuexen &xladdr->address.sin.sin_addr, 502d5b4aa90SMichael Tuexen htons(xstcb->local_port)); 503d5b4aa90SMichael Tuexen break; 504d5b4aa90SMichael Tuexen case AF_INET6: 50527569d01SRenato Botelho if (!IN6_IS_ADDR_LOOPBACK( 50627569d01SRenato Botelho &xladdr->address.sin6.sin6_addr)) 507d5b4aa90SMichael Tuexen local_all_loopback = 0; 50827569d01SRenato Botelho sockaddr(&laddr->address, AF_INET6, 509d5b4aa90SMichael Tuexen &xladdr->address.sin6.sin6_addr, 510d5b4aa90SMichael Tuexen htons(xstcb->local_port)); 511d5b4aa90SMichael Tuexen break; 512d5b4aa90SMichael Tuexen default: 51327569d01SRenato Botelho errx(1, 51427569d01SRenato Botelho "address family %d not supported", 515d5b4aa90SMichael Tuexen xladdr->address.sa.sa_family); 516d5b4aa90SMichael Tuexen } 517d5b4aa90SMichael Tuexen laddr->next = NULL; 518d5b4aa90SMichael Tuexen if (prev_laddr == NULL) 519d5b4aa90SMichael Tuexen sock->laddr = laddr; 520d5b4aa90SMichael Tuexen else 521d5b4aa90SMichael Tuexen prev_laddr->next = laddr; 522d5b4aa90SMichael Tuexen prev_laddr = laddr; 523d5b4aa90SMichael Tuexen } 524d5b4aa90SMichael Tuexen prev_faddr = NULL; 525d5b4aa90SMichael Tuexen foreign_all_loopback = 1; 526d5b4aa90SMichael Tuexen while (offset < len) { 52727569d01SRenato Botelho xraddr = (struct xsctp_raddr *)(void *)(buf + 52827569d01SRenato Botelho offset); 529d5b4aa90SMichael Tuexen offset += sizeof(struct xsctp_raddr); 530d5b4aa90SMichael Tuexen if (xraddr->last == 1) 531d5b4aa90SMichael Tuexen break; 532d5b4aa90SMichael Tuexen if (!opt_c) 533d5b4aa90SMichael Tuexen continue; 53427569d01SRenato Botelho faddr = calloc(1, sizeof(struct addr)); 53527569d01SRenato Botelho if (faddr == NULL) 536d5b4aa90SMichael Tuexen err(1, "malloc()"); 537d5b4aa90SMichael Tuexen switch (xraddr->address.sa.sa_family) { 538d5b4aa90SMichael Tuexen case AF_INET: 539d5b4aa90SMichael Tuexen #define __IN_IS_ADDR_LOOPBACK(pina) \ 540d5b4aa90SMichael Tuexen ((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET) 54127569d01SRenato Botelho if (!__IN_IS_ADDR_LOOPBACK( 54227569d01SRenato Botelho &xraddr->address.sin.sin_addr)) 543d5b4aa90SMichael Tuexen foreign_all_loopback = 0; 544d5b4aa90SMichael Tuexen #undef __IN_IS_ADDR_LOOPBACK 54527569d01SRenato Botelho sockaddr(&faddr->address, AF_INET, 546d5b4aa90SMichael Tuexen &xraddr->address.sin.sin_addr, 547d5b4aa90SMichael Tuexen htons(xstcb->remote_port)); 548d5b4aa90SMichael Tuexen break; 549d5b4aa90SMichael Tuexen case AF_INET6: 55027569d01SRenato Botelho if (!IN6_IS_ADDR_LOOPBACK( 55127569d01SRenato Botelho &xraddr->address.sin6.sin6_addr)) 552d5b4aa90SMichael Tuexen foreign_all_loopback = 0; 55327569d01SRenato Botelho sockaddr(&faddr->address, AF_INET6, 554d5b4aa90SMichael Tuexen &xraddr->address.sin6.sin6_addr, 555d5b4aa90SMichael Tuexen htons(xstcb->remote_port)); 556d5b4aa90SMichael Tuexen break; 557d5b4aa90SMichael Tuexen default: 55827569d01SRenato Botelho errx(1, 55927569d01SRenato Botelho "address family %d not supported", 560d5b4aa90SMichael Tuexen xraddr->address.sa.sa_family); 561d5b4aa90SMichael Tuexen } 56249b836f2SMichael Tuexen faddr->encaps_port = xraddr->encaps_port; 563e389705eSMichael Tuexen faddr->state = xraddr->state; 564d5b4aa90SMichael Tuexen faddr->next = NULL; 565d5b4aa90SMichael Tuexen if (prev_faddr == NULL) 566d5b4aa90SMichael Tuexen sock->faddr = faddr; 567d5b4aa90SMichael Tuexen else 568d5b4aa90SMichael Tuexen prev_faddr->next = faddr; 569d5b4aa90SMichael Tuexen prev_faddr = faddr; 570d5b4aa90SMichael Tuexen } 571bedcf91dSMichael Tuexen if (opt_c) { 572edc9c7fcSMichael Tuexen if ((sock->vflag & vflag) && 573edc9c7fcSMichael Tuexen (!opt_L || 57427569d01SRenato Botelho !(local_all_loopback || 57527569d01SRenato Botelho foreign_all_loopback))) { 57627569d01SRenato Botelho hash = (int)((uintptr_t)sock->socket % 57727569d01SRenato Botelho HASHSIZE); 578d5b4aa90SMichael Tuexen sock->next = sockhash[hash]; 579d5b4aa90SMichael Tuexen sockhash[hash] = sock; 580bedcf91dSMichael Tuexen } else { 581bedcf91dSMichael Tuexen free_socket(sock); 582bedcf91dSMichael Tuexen } 583d5b4aa90SMichael Tuexen } 584d5b4aa90SMichael Tuexen } 585d5b4aa90SMichael Tuexen xinpcb = (struct xsctp_inpcb *)(void *)(buf + offset); 586d5b4aa90SMichael Tuexen offset += sizeof(struct xsctp_inpcb); 587d5b4aa90SMichael Tuexen } 588d5b4aa90SMichael Tuexen free(buf); 589d5b4aa90SMichael Tuexen } 590d5b4aa90SMichael Tuexen 591d5b4aa90SMichael Tuexen static void 592ca007d91SDag-Erling Smørgrav gather_inet(int proto) 593ca007d91SDag-Erling Smørgrav { 594ca007d91SDag-Erling Smørgrav struct xinpgen *xig, *exig; 595ca007d91SDag-Erling Smørgrav struct xinpcb *xip; 596bf40d2caSGleb Smirnoff struct xtcpcb *xtp = NULL; 597ca007d91SDag-Erling Smørgrav struct xsocket *so; 598ca007d91SDag-Erling Smørgrav struct sock *sock; 599e6f718c7SMichael Tuexen struct addr *laddr, *faddr; 600ca007d91SDag-Erling Smørgrav const char *varname, *protoname; 601ca007d91SDag-Erling Smørgrav size_t len, bufsize; 602ca007d91SDag-Erling Smørgrav void *buf; 6036eb1d5baSMichael Tuexen int hash, retry, vflag; 604ca007d91SDag-Erling Smørgrav 6056eb1d5baSMichael Tuexen vflag = 0; 606ca007d91SDag-Erling Smørgrav if (opt_4) 607ca007d91SDag-Erling Smørgrav vflag |= INP_IPV4; 608ca007d91SDag-Erling Smørgrav if (opt_6) 609ca007d91SDag-Erling Smørgrav vflag |= INP_IPV6; 610ca007d91SDag-Erling Smørgrav 611ca007d91SDag-Erling Smørgrav switch (proto) { 612ca007d91SDag-Erling Smørgrav case IPPROTO_TCP: 613ca007d91SDag-Erling Smørgrav varname = "net.inet.tcp.pcblist"; 614ca007d91SDag-Erling Smørgrav protoname = "tcp"; 615ca007d91SDag-Erling Smørgrav break; 616ca007d91SDag-Erling Smørgrav case IPPROTO_UDP: 617ca007d91SDag-Erling Smørgrav varname = "net.inet.udp.pcblist"; 618ca007d91SDag-Erling Smørgrav protoname = "udp"; 619ca007d91SDag-Erling Smørgrav break; 6202cfbdf89SRuslan Ermilov case IPPROTO_DIVERT: 6212cfbdf89SRuslan Ermilov varname = "net.inet.divert.pcblist"; 6222cfbdf89SRuslan Ermilov protoname = "div"; 6232cfbdf89SRuslan Ermilov break; 624ca007d91SDag-Erling Smørgrav default: 6251f3d67aaSGiorgos Keramidas errx(1, "protocol %d not supported", proto); 626ca007d91SDag-Erling Smørgrav } 627ca007d91SDag-Erling Smørgrav 628ca007d91SDag-Erling Smørgrav buf = NULL; 629ca007d91SDag-Erling Smørgrav bufsize = 8192; 630ca007d91SDag-Erling Smørgrav retry = 5; 631ca007d91SDag-Erling Smørgrav do { 632ca007d91SDag-Erling Smørgrav for (;;) { 633ca007d91SDag-Erling Smørgrav if ((buf = realloc(buf, bufsize)) == NULL) 634ca007d91SDag-Erling Smørgrav err(1, "realloc()"); 635ca007d91SDag-Erling Smørgrav len = bufsize; 636c5a2d8c5SRyan Moeller if (cap_sysctlbyname(capsysctl, varname, buf, &len, 637c5a2d8c5SRyan Moeller NULL, 0) == 0) 638ca007d91SDag-Erling Smørgrav break; 6394b2a3d41SRuslan Ermilov if (errno == ENOENT) 6404b2a3d41SRuslan Ermilov goto out; 641003e7e49SMikolaj Golub if (errno != ENOMEM || len != bufsize) 642c5a2d8c5SRyan Moeller err(1, "cap_sysctlbyname()"); 643ca007d91SDag-Erling Smørgrav bufsize *= 2; 644ca007d91SDag-Erling Smørgrav } 645ca007d91SDag-Erling Smørgrav xig = (struct xinpgen *)buf; 6466dbe8d53SRobert Drehmel exig = (struct xinpgen *)(void *) 6476dbe8d53SRobert Drehmel ((char *)buf + len - sizeof *exig); 648ca007d91SDag-Erling Smørgrav if (xig->xig_len != sizeof *xig || 649ca007d91SDag-Erling Smørgrav exig->xig_len != sizeof *exig) 650ca007d91SDag-Erling Smørgrav errx(1, "struct xinpgen size mismatch"); 651ca007d91SDag-Erling Smørgrav } while (xig->xig_gen != exig->xig_gen && retry--); 652ca007d91SDag-Erling Smørgrav 653ca007d91SDag-Erling Smørgrav if (xig->xig_gen != exig->xig_gen && opt_v) 654ca007d91SDag-Erling Smørgrav warnx("warning: data may be inconsistent"); 655ca007d91SDag-Erling Smørgrav 656ca007d91SDag-Erling Smørgrav for (;;) { 6576dbe8d53SRobert Drehmel xig = (struct xinpgen *)(void *)((char *)xig + xig->xig_len); 658ca007d91SDag-Erling Smørgrav if (xig >= exig) 659ca007d91SDag-Erling Smørgrav break; 660ca007d91SDag-Erling Smørgrav switch (proto) { 661ca007d91SDag-Erling Smørgrav case IPPROTO_TCP: 662cc65eb4eSGleb Smirnoff xtp = (struct xtcpcb *)xig; 663cc65eb4eSGleb Smirnoff xip = &xtp->xt_inp; 664b8e20e2dSHiroki Sato if (xtp->xt_len != sizeof(*xtp)) { 665ca007d91SDag-Erling Smørgrav warnx("struct xtcpcb size mismatch"); 666ca007d91SDag-Erling Smørgrav goto out; 667ca007d91SDag-Erling Smørgrav } 668cc65eb4eSGleb Smirnoff protoname = xtp->t_flags & TF_TOE ? "toe" : "tcp"; 669ca007d91SDag-Erling Smørgrav break; 670ca007d91SDag-Erling Smørgrav case IPPROTO_UDP: 6712cfbdf89SRuslan Ermilov case IPPROTO_DIVERT: 672cc65eb4eSGleb Smirnoff xip = (struct xinpcb *)xig; 673b8e20e2dSHiroki Sato if (xip->xi_len != sizeof(*xip)) { 674ca007d91SDag-Erling Smørgrav warnx("struct xinpcb size mismatch"); 675ca007d91SDag-Erling Smørgrav goto out; 676ca007d91SDag-Erling Smørgrav } 677ca007d91SDag-Erling Smørgrav break; 678ca007d91SDag-Erling Smørgrav default: 6791f3d67aaSGiorgos Keramidas errx(1, "protocol %d not supported", proto); 680ca007d91SDag-Erling Smørgrav } 681cc65eb4eSGleb Smirnoff so = &xip->xi_socket; 682cc65eb4eSGleb Smirnoff if ((xip->inp_vflag & vflag) == 0) 683ca007d91SDag-Erling Smørgrav continue; 684cc65eb4eSGleb Smirnoff if (xip->inp_vflag & INP_IPV4) { 685cc65eb4eSGleb Smirnoff if ((xip->inp_fport == 0 && !opt_l) || 686cc65eb4eSGleb Smirnoff (xip->inp_fport != 0 && !opt_c)) 6871e6690e5SDag-Erling Smørgrav continue; 6889b6ca892SBruce M Simpson #define __IN_IS_ADDR_LOOPBACK(pina) \ 6899b6ca892SBruce M Simpson ((ntohl((pina)->s_addr) >> IN_CLASSA_NSHIFT) == IN_LOOPBACKNET) 6909b6ca892SBruce M Simpson if (opt_L && 691cc65eb4eSGleb Smirnoff (__IN_IS_ADDR_LOOPBACK(&xip->inp_faddr) || 692cc65eb4eSGleb Smirnoff __IN_IS_ADDR_LOOPBACK(&xip->inp_laddr))) 6939b6ca892SBruce M Simpson continue; 6949b6ca892SBruce M Simpson #undef __IN_IS_ADDR_LOOPBACK 695cc65eb4eSGleb Smirnoff } else if (xip->inp_vflag & INP_IPV6) { 696cc65eb4eSGleb Smirnoff if ((xip->inp_fport == 0 && !opt_l) || 697cc65eb4eSGleb Smirnoff (xip->inp_fport != 0 && !opt_c)) 6981e6690e5SDag-Erling Smørgrav continue; 6999b6ca892SBruce M Simpson if (opt_L && 700cc65eb4eSGleb Smirnoff (IN6_IS_ADDR_LOOPBACK(&xip->in6p_faddr) || 701cc65eb4eSGleb Smirnoff IN6_IS_ADDR_LOOPBACK(&xip->in6p_laddr))) 7029b6ca892SBruce M Simpson continue; 7031e6690e5SDag-Erling Smørgrav } else { 7041e6690e5SDag-Erling Smørgrav if (opt_v) 705cc65eb4eSGleb Smirnoff warnx("invalid vflag 0x%x", xip->inp_vflag); 7061e6690e5SDag-Erling Smørgrav continue; 7071e6690e5SDag-Erling Smørgrav } 708b8e20e2dSHiroki Sato if ((sock = calloc(1, sizeof(*sock))) == NULL) 709ca007d91SDag-Erling Smørgrav err(1, "malloc()"); 710e6f718c7SMichael Tuexen if ((laddr = calloc(1, sizeof *laddr)) == NULL) 711e6f718c7SMichael Tuexen err(1, "malloc()"); 712e6f718c7SMichael Tuexen if ((faddr = calloc(1, sizeof *faddr)) == NULL) 713e6f718c7SMichael Tuexen err(1, "malloc()"); 714ca007d91SDag-Erling Smørgrav sock->socket = so->xso_so; 715ca007d91SDag-Erling Smørgrav sock->proto = proto; 716cc65eb4eSGleb Smirnoff if (xip->inp_vflag & INP_IPV4) { 717ca007d91SDag-Erling Smørgrav sock->family = AF_INET; 718e6f718c7SMichael Tuexen sockaddr(&laddr->address, sock->family, 719cc65eb4eSGleb Smirnoff &xip->inp_laddr, xip->inp_lport); 720e6f718c7SMichael Tuexen sockaddr(&faddr->address, sock->family, 721cc65eb4eSGleb Smirnoff &xip->inp_faddr, xip->inp_fport); 722cc65eb4eSGleb Smirnoff } else if (xip->inp_vflag & INP_IPV6) { 723ca007d91SDag-Erling Smørgrav sock->family = AF_INET6; 724e6f718c7SMichael Tuexen sockaddr(&laddr->address, sock->family, 725cc65eb4eSGleb Smirnoff &xip->in6p_laddr, xip->inp_lport); 726e6f718c7SMichael Tuexen sockaddr(&faddr->address, sock->family, 727cc65eb4eSGleb Smirnoff &xip->in6p_faddr, xip->inp_fport); 728ca007d91SDag-Erling Smørgrav } 7299e644c23SMichael Tuexen if (proto == IPPROTO_TCP) 7309e644c23SMichael Tuexen faddr->encaps_port = xtp->xt_encaps_port; 731e6f718c7SMichael Tuexen laddr->next = NULL; 732e6f718c7SMichael Tuexen faddr->next = NULL; 733e6f718c7SMichael Tuexen sock->laddr = laddr; 734e6f718c7SMichael Tuexen sock->faddr = faddr; 735cc65eb4eSGleb Smirnoff sock->vflag = xip->inp_vflag; 736e5cccc35SMichael Tuexen if (proto == IPPROTO_TCP) { 737cc65eb4eSGleb Smirnoff sock->state = xtp->t_state; 738e5cccc35SMichael Tuexen memcpy(sock->stack, xtp->xt_stack, 739e5cccc35SMichael Tuexen TCP_FUNCTION_NAME_LEN_MAX); 7402ac089d0SMichael Tuexen memcpy(sock->cc, xtp->xt_cc, TCP_CA_NAME_MAX); 741e5cccc35SMichael Tuexen } 742ca007d91SDag-Erling Smørgrav sock->protoname = protoname; 743ca007d91SDag-Erling Smørgrav hash = (int)((uintptr_t)sock->socket % HASHSIZE); 744ca007d91SDag-Erling Smørgrav sock->next = sockhash[hash]; 745ca007d91SDag-Erling Smørgrav sockhash[hash] = sock; 746ca007d91SDag-Erling Smørgrav } 747ca007d91SDag-Erling Smørgrav out: 748ca007d91SDag-Erling Smørgrav free(buf); 749ca007d91SDag-Erling Smørgrav } 750ca007d91SDag-Erling Smørgrav 751ca007d91SDag-Erling Smørgrav static void 752ca007d91SDag-Erling Smørgrav gather_unix(int proto) 753ca007d91SDag-Erling Smørgrav { 754ca007d91SDag-Erling Smørgrav struct xunpgen *xug, *exug; 755ca007d91SDag-Erling Smørgrav struct xunpcb *xup; 756ca007d91SDag-Erling Smørgrav struct sock *sock; 757e6f718c7SMichael Tuexen struct addr *laddr, *faddr; 758ca007d91SDag-Erling Smørgrav const char *varname, *protoname; 759ca007d91SDag-Erling Smørgrav size_t len, bufsize; 760ca007d91SDag-Erling Smørgrav void *buf; 761ca007d91SDag-Erling Smørgrav int hash, retry; 762ca007d91SDag-Erling Smørgrav 763ca007d91SDag-Erling Smørgrav switch (proto) { 764ca007d91SDag-Erling Smørgrav case SOCK_STREAM: 765ca007d91SDag-Erling Smørgrav varname = "net.local.stream.pcblist"; 766ca007d91SDag-Erling Smørgrav protoname = "stream"; 767ca007d91SDag-Erling Smørgrav break; 768ca007d91SDag-Erling Smørgrav case SOCK_DGRAM: 769ca007d91SDag-Erling Smørgrav varname = "net.local.dgram.pcblist"; 770ca007d91SDag-Erling Smørgrav protoname = "dgram"; 771ca007d91SDag-Erling Smørgrav break; 772b8e20e2dSHiroki Sato case SOCK_SEQPACKET: 773b8e20e2dSHiroki Sato varname = "net.local.seqpacket.pcblist"; 774b8e20e2dSHiroki Sato protoname = "seqpac"; 775b8e20e2dSHiroki Sato break; 776ca007d91SDag-Erling Smørgrav default: 777ca007d91SDag-Erling Smørgrav abort(); 778ca007d91SDag-Erling Smørgrav } 779ca007d91SDag-Erling Smørgrav buf = NULL; 780ca007d91SDag-Erling Smørgrav bufsize = 8192; 781ca007d91SDag-Erling Smørgrav retry = 5; 782ca007d91SDag-Erling Smørgrav do { 783ca007d91SDag-Erling Smørgrav for (;;) { 784ca007d91SDag-Erling Smørgrav if ((buf = realloc(buf, bufsize)) == NULL) 785ca007d91SDag-Erling Smørgrav err(1, "realloc()"); 786ca007d91SDag-Erling Smørgrav len = bufsize; 787c5a2d8c5SRyan Moeller if (cap_sysctlbyname(capsysctl, varname, buf, &len, 788c5a2d8c5SRyan Moeller NULL, 0) == 0) 789ca007d91SDag-Erling Smørgrav break; 790003e7e49SMikolaj Golub if (errno != ENOMEM || len != bufsize) 791c5a2d8c5SRyan Moeller err(1, "cap_sysctlbyname()"); 792ca007d91SDag-Erling Smørgrav bufsize *= 2; 793ca007d91SDag-Erling Smørgrav } 794ca007d91SDag-Erling Smørgrav xug = (struct xunpgen *)buf; 7956dbe8d53SRobert Drehmel exug = (struct xunpgen *)(void *) 796b8e20e2dSHiroki Sato ((char *)buf + len - sizeof(*exug)); 797b8e20e2dSHiroki Sato if (xug->xug_len != sizeof(*xug) || 798b8e20e2dSHiroki Sato exug->xug_len != sizeof(*exug)) { 799ca007d91SDag-Erling Smørgrav warnx("struct xinpgen size mismatch"); 800ca007d91SDag-Erling Smørgrav goto out; 801ca007d91SDag-Erling Smørgrav } 802ca007d91SDag-Erling Smørgrav } while (xug->xug_gen != exug->xug_gen && retry--); 803ca007d91SDag-Erling Smørgrav 804ca007d91SDag-Erling Smørgrav if (xug->xug_gen != exug->xug_gen && opt_v) 805ca007d91SDag-Erling Smørgrav warnx("warning: data may be inconsistent"); 806ca007d91SDag-Erling Smørgrav 807ca007d91SDag-Erling Smørgrav for (;;) { 8086dbe8d53SRobert Drehmel xug = (struct xunpgen *)(void *)((char *)xug + xug->xug_len); 809ca007d91SDag-Erling Smørgrav if (xug >= exug) 810ca007d91SDag-Erling Smørgrav break; 811ca007d91SDag-Erling Smørgrav xup = (struct xunpcb *)xug; 812b8e20e2dSHiroki Sato if (xup->xu_len != sizeof(*xup)) { 813ca007d91SDag-Erling Smørgrav warnx("struct xunpcb size mismatch"); 814ca007d91SDag-Erling Smørgrav goto out; 815ca007d91SDag-Erling Smørgrav } 816f38b68aeSBrooks Davis if ((xup->unp_conn == 0 && !opt_l) || 817f38b68aeSBrooks Davis (xup->unp_conn != 0 && !opt_c)) 8181e6690e5SDag-Erling Smørgrav continue; 819b8e20e2dSHiroki Sato if ((sock = calloc(1, sizeof(*sock))) == NULL) 820ca007d91SDag-Erling Smørgrav err(1, "malloc()"); 821e6f718c7SMichael Tuexen if ((laddr = calloc(1, sizeof *laddr)) == NULL) 822e6f718c7SMichael Tuexen err(1, "malloc()"); 823e6f718c7SMichael Tuexen if ((faddr = calloc(1, sizeof *faddr)) == NULL) 824e6f718c7SMichael Tuexen err(1, "malloc()"); 825ca007d91SDag-Erling Smørgrav sock->socket = xup->xu_socket.xso_so; 826ca007d91SDag-Erling Smørgrav sock->pcb = xup->xu_unpp; 827ca007d91SDag-Erling Smørgrav sock->proto = proto; 828ca007d91SDag-Erling Smørgrav sock->family = AF_UNIX; 829ca007d91SDag-Erling Smørgrav sock->protoname = protoname; 8300e229f34SGleb Smirnoff if (xup->xu_addr.sun_family == AF_UNIX) 831e6f718c7SMichael Tuexen laddr->address = 8326dbe8d53SRobert Drehmel *(struct sockaddr_storage *)(void *)&xup->xu_addr; 833f38b68aeSBrooks Davis else if (xup->unp_conn != 0) 834f38b68aeSBrooks Davis *(kvaddr_t*)&(faddr->address) = xup->unp_conn; 835e6f718c7SMichael Tuexen laddr->next = NULL; 836e6f718c7SMichael Tuexen faddr->next = NULL; 837e6f718c7SMichael Tuexen sock->laddr = laddr; 838e6f718c7SMichael Tuexen sock->faddr = faddr; 839ca007d91SDag-Erling Smørgrav hash = (int)((uintptr_t)sock->socket % HASHSIZE); 840ca007d91SDag-Erling Smørgrav sock->next = sockhash[hash]; 841ca007d91SDag-Erling Smørgrav sockhash[hash] = sock; 842ca007d91SDag-Erling Smørgrav } 843ca007d91SDag-Erling Smørgrav out: 844ca007d91SDag-Erling Smørgrav free(buf); 845ca007d91SDag-Erling Smørgrav } 846ca007d91SDag-Erling Smørgrav 847ca007d91SDag-Erling Smørgrav static void 848ca007d91SDag-Erling Smørgrav getfiles(void) 849ca007d91SDag-Erling Smørgrav { 850003e7e49SMikolaj Golub size_t len, olen; 851ca007d91SDag-Erling Smørgrav 852b8e20e2dSHiroki Sato olen = len = sizeof(*xfiles); 853003e7e49SMikolaj Golub if ((xfiles = malloc(len)) == NULL) 854ca007d91SDag-Erling Smørgrav err(1, "malloc()"); 855c5a2d8c5SRyan Moeller while (cap_sysctlbyname(capsysctl, "kern.file", xfiles, &len, 0, 0) 856c5a2d8c5SRyan Moeller == -1) { 857003e7e49SMikolaj Golub if (errno != ENOMEM || len != olen) 858c5a2d8c5SRyan Moeller err(1, "cap_sysctlbyname()"); 859003e7e49SMikolaj Golub olen = len *= 2; 860ca007d91SDag-Erling Smørgrav if ((xfiles = realloc(xfiles, len)) == NULL) 861ca007d91SDag-Erling Smørgrav err(1, "realloc()"); 862ca007d91SDag-Erling Smørgrav } 863b8e20e2dSHiroki Sato if (len > 0 && xfiles->xf_size != sizeof(*xfiles)) 864ca007d91SDag-Erling Smørgrav errx(1, "struct xfile size mismatch"); 865b8e20e2dSHiroki Sato nxfiles = len / sizeof(*xfiles); 866ca007d91SDag-Erling Smørgrav } 867ca007d91SDag-Erling Smørgrav 868ca007d91SDag-Erling Smørgrav static int 869baa7f281SMichael Tuexen printaddr(struct sockaddr_storage *ss) 870ca007d91SDag-Erling Smørgrav { 871ca007d91SDag-Erling Smørgrav struct sockaddr_un *sun; 872b8e20e2dSHiroki Sato char addrstr[NI_MAXHOST] = { '\0', '\0' }; 873b8e20e2dSHiroki Sato int error, off, port = 0; 874ca007d91SDag-Erling Smørgrav 875baa7f281SMichael Tuexen switch (ss->ss_family) { 876ca007d91SDag-Erling Smørgrav case AF_INET: 877b8e20e2dSHiroki Sato if (inet_lnaof(sstosin(ss)->sin_addr) == INADDR_ANY) 878ca007d91SDag-Erling Smørgrav addrstr[0] = '*'; 879b8e20e2dSHiroki Sato port = ntohs(sstosin(ss)->sin_port); 880ca007d91SDag-Erling Smørgrav break; 881ca007d91SDag-Erling Smørgrav case AF_INET6: 882b8e20e2dSHiroki Sato if (IN6_IS_ADDR_UNSPECIFIED(&sstosin6(ss)->sin6_addr)) 883ca007d91SDag-Erling Smørgrav addrstr[0] = '*'; 884b8e20e2dSHiroki Sato port = ntohs(sstosin6(ss)->sin6_port); 885ca007d91SDag-Erling Smørgrav break; 886ca007d91SDag-Erling Smørgrav case AF_UNIX: 887b8e20e2dSHiroki Sato sun = sstosun(ss); 888ca007d91SDag-Erling Smørgrav off = (int)((char *)&sun->sun_path - (char *)sun); 889ca007d91SDag-Erling Smørgrav return (xprintf("%.*s", sun->sun_len - off, sun->sun_path)); 890ca007d91SDag-Erling Smørgrav } 891b8e20e2dSHiroki Sato if (addrstr[0] == '\0') { 892c5a2d8c5SRyan Moeller error = cap_getnameinfo(capnet, sstosa(ss), ss->ss_len, 893c5a2d8c5SRyan Moeller addrstr, sizeof(addrstr), NULL, 0, NI_NUMERICHOST); 894b8e20e2dSHiroki Sato if (error) 895c5a2d8c5SRyan Moeller errx(1, "cap_getnameinfo()"); 896b8e20e2dSHiroki Sato } 897ca007d91SDag-Erling Smørgrav if (port == 0) 898ca007d91SDag-Erling Smørgrav return xprintf("%s:*", addrstr); 899ca007d91SDag-Erling Smørgrav else 900ca007d91SDag-Erling Smørgrav return xprintf("%s:%d", addrstr, port); 901ca007d91SDag-Erling Smørgrav } 902ca007d91SDag-Erling Smørgrav 903ca007d91SDag-Erling Smørgrav static const char * 904ca007d91SDag-Erling Smørgrav getprocname(pid_t pid) 905ca007d91SDag-Erling Smørgrav { 906ca007d91SDag-Erling Smørgrav static struct kinfo_proc proc; 907ca007d91SDag-Erling Smørgrav size_t len; 908ca007d91SDag-Erling Smørgrav int mib[4]; 909ca007d91SDag-Erling Smørgrav 910ca007d91SDag-Erling Smørgrav mib[0] = CTL_KERN; 911ca007d91SDag-Erling Smørgrav mib[1] = KERN_PROC; 912ca007d91SDag-Erling Smørgrav mib[2] = KERN_PROC_PID; 913ca007d91SDag-Erling Smørgrav mib[3] = (int)pid; 914b8e20e2dSHiroki Sato len = sizeof(proc); 915c5a2d8c5SRyan Moeller if (cap_sysctl(capsysctl, mib, nitems(mib), &proc, &len, NULL, 0) 916c5a2d8c5SRyan Moeller == -1) { 91748c513e0SMaxim Konovalov /* Do not warn if the process exits before we get its name. */ 91848c513e0SMaxim Konovalov if (errno != ESRCH) 919c5a2d8c5SRyan Moeller warn("cap_sysctl()"); 920ca007d91SDag-Erling Smørgrav return ("??"); 921ca007d91SDag-Erling Smørgrav } 922f487a6a8SEd Maste return (proc.ki_comm); 923ca007d91SDag-Erling Smørgrav } 924ca007d91SDag-Erling Smørgrav 925ae94787dSMaxime Henrion static int 92600feaafdSAndrew Thompson getprocjid(pid_t pid) 92700feaafdSAndrew Thompson { 92800feaafdSAndrew Thompson static struct kinfo_proc proc; 92900feaafdSAndrew Thompson size_t len; 93000feaafdSAndrew Thompson int mib[4]; 93100feaafdSAndrew Thompson 93200feaafdSAndrew Thompson mib[0] = CTL_KERN; 93300feaafdSAndrew Thompson mib[1] = KERN_PROC; 93400feaafdSAndrew Thompson mib[2] = KERN_PROC_PID; 93500feaafdSAndrew Thompson mib[3] = (int)pid; 936b8e20e2dSHiroki Sato len = sizeof(proc); 937c5a2d8c5SRyan Moeller if (cap_sysctl(capsysctl, mib, nitems(mib), &proc, &len, NULL, 0) 938c5a2d8c5SRyan Moeller == -1) { 93900feaafdSAndrew Thompson /* Do not warn if the process exits before we get its jid. */ 94000feaafdSAndrew Thompson if (errno != ESRCH) 941c5a2d8c5SRyan Moeller warn("cap_sysctl()"); 94200feaafdSAndrew Thompson return (-1); 94300feaafdSAndrew Thompson } 94400feaafdSAndrew Thompson return (proc.ki_jid); 94500feaafdSAndrew Thompson } 94600feaafdSAndrew Thompson 94700feaafdSAndrew Thompson static int 948ae94787dSMaxime Henrion check_ports(struct sock *s) 949ae94787dSMaxime Henrion { 950ae94787dSMaxime Henrion int port; 951e6f718c7SMichael Tuexen struct addr *addr; 952ae94787dSMaxime Henrion 953ae94787dSMaxime Henrion if (ports == NULL) 954ae94787dSMaxime Henrion return (1); 955ae94787dSMaxime Henrion if ((s->family != AF_INET) && (s->family != AF_INET6)) 956ae94787dSMaxime Henrion return (1); 957e6f718c7SMichael Tuexen for (addr = s->laddr; addr != NULL; addr = addr->next) { 958b8e20e2dSHiroki Sato if (s->family == AF_INET) 959b8e20e2dSHiroki Sato port = ntohs(sstosin(&addr->address)->sin_port); 960ae94787dSMaxime Henrion else 961b8e20e2dSHiroki Sato port = ntohs(sstosin6(&addr->address)->sin6_port); 962ae94787dSMaxime Henrion if (CHK_PORT(port)) 963ae94787dSMaxime Henrion return (1); 964e6f718c7SMichael Tuexen } 965e6f718c7SMichael Tuexen for (addr = s->faddr; addr != NULL; addr = addr->next) { 966b8e20e2dSHiroki Sato if (s->family == AF_INET) 967b8e20e2dSHiroki Sato port = ntohs(sstosin(&addr->address)->sin_port); 968ae94787dSMaxime Henrion else 969b8e20e2dSHiroki Sato port = ntohs(sstosin6(&addr->address)->sin6_port); 970ae94787dSMaxime Henrion if (CHK_PORT(port)) 971ae94787dSMaxime Henrion return (1); 972e6f718c7SMichael Tuexen } 973ae94787dSMaxime Henrion return (0); 974ae94787dSMaxime Henrion } 975ae94787dSMaxime Henrion 9766414db1bSMichael Tuexen static const char * 977e389705eSMichael Tuexen sctp_conn_state(int state) 9786414db1bSMichael Tuexen { 9796414db1bSMichael Tuexen switch (state) { 9806414db1bSMichael Tuexen case SCTP_CLOSED: 9816414db1bSMichael Tuexen return "CLOSED"; 9826414db1bSMichael Tuexen break; 9836414db1bSMichael Tuexen case SCTP_BOUND: 9846414db1bSMichael Tuexen return "BOUND"; 9856414db1bSMichael Tuexen break; 9866414db1bSMichael Tuexen case SCTP_LISTEN: 9876414db1bSMichael Tuexen return "LISTEN"; 9886414db1bSMichael Tuexen break; 9896414db1bSMichael Tuexen case SCTP_COOKIE_WAIT: 9906414db1bSMichael Tuexen return "COOKIE_WAIT"; 9916414db1bSMichael Tuexen break; 9926414db1bSMichael Tuexen case SCTP_COOKIE_ECHOED: 9936414db1bSMichael Tuexen return "COOKIE_ECHOED"; 9946414db1bSMichael Tuexen break; 9956414db1bSMichael Tuexen case SCTP_ESTABLISHED: 9966414db1bSMichael Tuexen return "ESTABLISHED"; 9976414db1bSMichael Tuexen break; 9986414db1bSMichael Tuexen case SCTP_SHUTDOWN_SENT: 9996414db1bSMichael Tuexen return "SHUTDOWN_SENT"; 10006414db1bSMichael Tuexen break; 10016414db1bSMichael Tuexen case SCTP_SHUTDOWN_RECEIVED: 10026414db1bSMichael Tuexen return "SHUTDOWN_RECEIVED"; 10036414db1bSMichael Tuexen break; 10046414db1bSMichael Tuexen case SCTP_SHUTDOWN_ACK_SENT: 10056414db1bSMichael Tuexen return "SHUTDOWN_ACK_SENT"; 10066414db1bSMichael Tuexen break; 10076414db1bSMichael Tuexen case SCTP_SHUTDOWN_PENDING: 10086414db1bSMichael Tuexen return "SHUTDOWN_PENDING"; 10096414db1bSMichael Tuexen break; 10106414db1bSMichael Tuexen default: 10116414db1bSMichael Tuexen return "UNKNOWN"; 10126414db1bSMichael Tuexen break; 10136414db1bSMichael Tuexen } 10146414db1bSMichael Tuexen } 10156414db1bSMichael Tuexen 1016e389705eSMichael Tuexen static const char * 1017e389705eSMichael Tuexen sctp_path_state(int state) 1018e389705eSMichael Tuexen { 1019e389705eSMichael Tuexen switch (state) { 1020e389705eSMichael Tuexen case SCTP_UNCONFIRMED: 1021e389705eSMichael Tuexen return "UNCONFIRMED"; 1022e389705eSMichael Tuexen break; 1023e389705eSMichael Tuexen case SCTP_ACTIVE: 1024e389705eSMichael Tuexen return "ACTIVE"; 1025e389705eSMichael Tuexen break; 1026e389705eSMichael Tuexen case SCTP_INACTIVE: 1027e389705eSMichael Tuexen return "INACTIVE"; 1028e389705eSMichael Tuexen break; 1029e389705eSMichael Tuexen default: 1030e389705eSMichael Tuexen return "UNKNOWN"; 1031e389705eSMichael Tuexen break; 1032e389705eSMichael Tuexen } 1033e389705eSMichael Tuexen } 1034e389705eSMichael Tuexen 1035ca007d91SDag-Erling Smørgrav static void 103661149f8dSJilles Tjoelker displaysock(struct sock *s, int pos) 1037ca007d91SDag-Erling Smørgrav { 1038f38b68aeSBrooks Davis kvaddr_t p; 103949b836f2SMichael Tuexen int hash, first, offset; 1040e6f718c7SMichael Tuexen struct addr *laddr, *faddr; 104181091202SMichael Tuexen struct sock *s_tmp; 1042ca007d91SDag-Erling Smørgrav 1043ca007d91SDag-Erling Smørgrav while (pos < 29) 1044ca007d91SDag-Erling Smørgrav pos += xprintf(" "); 1045ca007d91SDag-Erling Smørgrav pos += xprintf("%s", s->protoname); 1046ca007d91SDag-Erling Smørgrav if (s->vflag & INP_IPV4) 1047ca007d91SDag-Erling Smørgrav pos += xprintf("4"); 1048ca007d91SDag-Erling Smørgrav if (s->vflag & INP_IPV6) 1049ca007d91SDag-Erling Smørgrav pos += xprintf("6"); 1050edc9c7fcSMichael Tuexen if (s->vflag & (INP_IPV4 | INP_IPV6)) 1051edc9c7fcSMichael Tuexen pos += xprintf(" "); 1052e6f718c7SMichael Tuexen laddr = s->laddr; 1053e6f718c7SMichael Tuexen faddr = s->faddr; 10544e13a5b0SMichael Tuexen first = 1; 1055e6f718c7SMichael Tuexen while (laddr != NULL || faddr != NULL) { 105683f60cb2SMichael Tuexen offset = 36; 105783f60cb2SMichael Tuexen while (pos < offset) 1058ca007d91SDag-Erling Smørgrav pos += xprintf(" "); 1059ca007d91SDag-Erling Smørgrav switch (s->family) { 1060ca007d91SDag-Erling Smørgrav case AF_INET: 1061ca007d91SDag-Erling Smørgrav case AF_INET6: 1062e6f718c7SMichael Tuexen if (laddr != NULL) { 1063e6f718c7SMichael Tuexen pos += printaddr(&laddr->address); 106409bbda21SMaxim Konovalov if (s->family == AF_INET6 && pos >= 58) 106509bbda21SMaxim Konovalov pos += xprintf(" "); 1066e6f718c7SMichael Tuexen } 106783f60cb2SMichael Tuexen offset += opt_w ? 46 : 22; 106883f60cb2SMichael Tuexen while (pos < offset) 1069ca007d91SDag-Erling Smørgrav pos += xprintf(" "); 1070e6f718c7SMichael Tuexen if (faddr != NULL) 1071e6f718c7SMichael Tuexen pos += printaddr(&faddr->address); 107283f60cb2SMichael Tuexen offset += opt_w ? 46 : 22; 1073ca007d91SDag-Erling Smørgrav break; 1074ca007d91SDag-Erling Smørgrav case AF_UNIX: 1075e6f718c7SMichael Tuexen if ((laddr == NULL) || (faddr == NULL)) 1076e6f718c7SMichael Tuexen errx(1, "laddr = %p or faddr = %p is NULL", 1077e6f718c7SMichael Tuexen (void *)laddr, (void *)faddr); 1078ca007d91SDag-Erling Smørgrav /* server */ 1079e6f718c7SMichael Tuexen if (laddr->address.ss_len > 0) { 1080e6f718c7SMichael Tuexen pos += printaddr(&laddr->address); 1081ca007d91SDag-Erling Smørgrav break; 1082ca007d91SDag-Erling Smørgrav } 1083ca007d91SDag-Erling Smørgrav /* client */ 1084f38b68aeSBrooks Davis p = *(kvaddr_t*)&(faddr->address); 1085f38b68aeSBrooks Davis if (p == 0) { 1086b4eb37c6SJohn-Mark Gurney pos += xprintf("(not connected)"); 108783f60cb2SMichael Tuexen offset += opt_w ? 92 : 44; 1088b4eb37c6SJohn-Mark Gurney break; 1089b4eb37c6SJohn-Mark Gurney } 1090b4eb37c6SJohn-Mark Gurney pos += xprintf("-> "); 1091ca007d91SDag-Erling Smørgrav for (hash = 0; hash < HASHSIZE; ++hash) { 109281091202SMichael Tuexen for (s_tmp = sockhash[hash]; 109381091202SMichael Tuexen s_tmp != NULL; 109481091202SMichael Tuexen s_tmp = s_tmp->next) 109581091202SMichael Tuexen if (s_tmp->pcb == p) 1096ca007d91SDag-Erling Smørgrav break; 109781091202SMichael Tuexen if (s_tmp != NULL) 1098ca007d91SDag-Erling Smørgrav break; 1099ca007d91SDag-Erling Smørgrav } 110027569d01SRenato Botelho if (s_tmp == NULL || s_tmp->laddr == NULL || 110181091202SMichael Tuexen s_tmp->laddr->address.ss_len == 0) 1102ca007d91SDag-Erling Smørgrav pos += xprintf("??"); 1103ca007d91SDag-Erling Smørgrav else 110481091202SMichael Tuexen pos += printaddr(&s_tmp->laddr->address); 110583f60cb2SMichael Tuexen offset += opt_w ? 92 : 44; 1106ca007d91SDag-Erling Smørgrav break; 1107ca007d91SDag-Erling Smørgrav default: 1108ca007d91SDag-Erling Smørgrav abort(); 1109ca007d91SDag-Erling Smørgrav } 111049b836f2SMichael Tuexen if (opt_U) { 111149b836f2SMichael Tuexen if (faddr != NULL && 11129e644c23SMichael Tuexen ((s->proto == IPPROTO_SCTP && 111349b836f2SMichael Tuexen s->state != SCTP_CLOSED && 111449b836f2SMichael Tuexen s->state != SCTP_BOUND && 11159e644c23SMichael Tuexen s->state != SCTP_LISTEN) || 11169e644c23SMichael Tuexen (s->proto == IPPROTO_TCP && 11179e644c23SMichael Tuexen s->state != TCPS_CLOSED && 11189e644c23SMichael Tuexen s->state != TCPS_LISTEN))) { 111949b836f2SMichael Tuexen while (pos < offset) 112049b836f2SMichael Tuexen pos += xprintf(" "); 112149b836f2SMichael Tuexen pos += xprintf("%u", 112249b836f2SMichael Tuexen ntohs(faddr->encaps_port)); 112349b836f2SMichael Tuexen } 112449b836f2SMichael Tuexen offset += 7; 112549b836f2SMichael Tuexen } 1126e389705eSMichael Tuexen if (opt_s) { 1127e389705eSMichael Tuexen if (faddr != NULL && 1128e389705eSMichael Tuexen s->proto == IPPROTO_SCTP && 1129e389705eSMichael Tuexen s->state != SCTP_CLOSED && 1130e389705eSMichael Tuexen s->state != SCTP_BOUND && 1131e389705eSMichael Tuexen s->state != SCTP_LISTEN) { 1132e389705eSMichael Tuexen while (pos < offset) 1133e389705eSMichael Tuexen pos += xprintf(" "); 1134e389705eSMichael Tuexen pos += xprintf("%s", 1135e389705eSMichael Tuexen sctp_path_state(faddr->state)); 1136e389705eSMichael Tuexen } 1137e389705eSMichael Tuexen offset += 13; 1138e389705eSMichael Tuexen } 1139e5cccc35SMichael Tuexen if (first) { 114049b836f2SMichael Tuexen if (opt_s) { 114149b836f2SMichael Tuexen if (s->proto == IPPROTO_SCTP || 114249b836f2SMichael Tuexen s->proto == IPPROTO_TCP) { 114349b836f2SMichael Tuexen while (pos < offset) 11444e13a5b0SMichael Tuexen pos += xprintf(" "); 11456414db1bSMichael Tuexen switch (s->proto) { 11466414db1bSMichael Tuexen case IPPROTO_SCTP: 1147e5cccc35SMichael Tuexen pos += xprintf("%s", 1148e389705eSMichael Tuexen sctp_conn_state(s->state)); 11496414db1bSMichael Tuexen break; 11506414db1bSMichael Tuexen case IPPROTO_TCP: 1151e5cccc35SMichael Tuexen if (s->state >= 0 && 1152e5cccc35SMichael Tuexen s->state < TCP_NSTATES) 115349b836f2SMichael Tuexen pos += xprintf("%s", 1154e5cccc35SMichael Tuexen tcpstates[s->state]); 11554e13a5b0SMichael Tuexen else 11564e13a5b0SMichael Tuexen pos += xprintf("?"); 11576414db1bSMichael Tuexen break; 11586414db1bSMichael Tuexen } 11594e13a5b0SMichael Tuexen } 116049b836f2SMichael Tuexen offset += 13; 116149b836f2SMichael Tuexen } 11622ac089d0SMichael Tuexen if (opt_S) { 11632ac089d0SMichael Tuexen if (s->proto == IPPROTO_TCP) { 116449b836f2SMichael Tuexen while (pos < offset) 1165e5cccc35SMichael Tuexen pos += xprintf(" "); 11662ac089d0SMichael Tuexen pos += xprintf("%.*s", 11672ac089d0SMichael Tuexen TCP_FUNCTION_NAME_LEN_MAX, 1168e5cccc35SMichael Tuexen s->stack); 1169e5cccc35SMichael Tuexen } 11702ac089d0SMichael Tuexen offset += TCP_FUNCTION_NAME_LEN_MAX + 1; 11712ac089d0SMichael Tuexen } 11722ac089d0SMichael Tuexen if (opt_C) { 11732ac089d0SMichael Tuexen if (s->proto == IPPROTO_TCP) { 11742ac089d0SMichael Tuexen while (pos < offset) 11752ac089d0SMichael Tuexen pos += xprintf(" "); 11762ac089d0SMichael Tuexen xprintf("%.*s", TCP_CA_NAME_MAX, s->cc); 11772ac089d0SMichael Tuexen } 11782ac089d0SMichael Tuexen offset += TCP_CA_NAME_MAX + 1; 11792ac089d0SMichael Tuexen } 1180e5cccc35SMichael Tuexen } 1181e6f718c7SMichael Tuexen if (laddr != NULL) 1182e6f718c7SMichael Tuexen laddr = laddr->next; 1183e6f718c7SMichael Tuexen if (faddr != NULL) 1184e6f718c7SMichael Tuexen faddr = faddr->next; 1185e6f718c7SMichael Tuexen if ((laddr != NULL) || (faddr != NULL)) { 1186e6f718c7SMichael Tuexen xprintf("\n"); 1187e6f718c7SMichael Tuexen pos = 0; 1188e6f718c7SMichael Tuexen } 11894e13a5b0SMichael Tuexen first = 0; 1190e6f718c7SMichael Tuexen } 11914e13a5b0SMichael Tuexen xprintf("\n"); 1192ca007d91SDag-Erling Smørgrav } 119361149f8dSJilles Tjoelker 119461149f8dSJilles Tjoelker static void 119561149f8dSJilles Tjoelker display(void) 119661149f8dSJilles Tjoelker { 119761149f8dSJilles Tjoelker struct passwd *pwd; 119861149f8dSJilles Tjoelker struct xfile *xf; 119961149f8dSJilles Tjoelker struct sock *s; 120061149f8dSJilles Tjoelker int hash, n, pos; 120161149f8dSJilles Tjoelker 1202ee0afaa9SEmmanuel Vadot if (opt_q != 1) { 120383f60cb2SMichael Tuexen printf("%-8s %-10s %-5s %-2s %-6s %-*s %-*s", 120461149f8dSJilles Tjoelker "USER", "COMMAND", "PID", "FD", "PROTO", 120583f60cb2SMichael Tuexen opt_w ? 45 : 21, "LOCAL ADDRESS", 120683f60cb2SMichael Tuexen opt_w ? 45 : 21, "FOREIGN ADDRESS"); 120749b836f2SMichael Tuexen if (opt_U) 120849b836f2SMichael Tuexen printf(" %-6s", "ENCAPS"); 1209e389705eSMichael Tuexen if (opt_s) { 1210e389705eSMichael Tuexen printf(" %-12s", "PATH STATE"); 1211e389705eSMichael Tuexen printf(" %-12s", "CONN STATE"); 1212e389705eSMichael Tuexen } 1213e5cccc35SMichael Tuexen if (opt_S) 12142ac089d0SMichael Tuexen printf(" %-*.*s", TCP_FUNCTION_NAME_LEN_MAX, 12152ac089d0SMichael Tuexen TCP_FUNCTION_NAME_LEN_MAX, "STACK"); 12162ac089d0SMichael Tuexen if (opt_C) 12172ac089d0SMichael Tuexen printf(" %-.*s", TCP_CA_NAME_MAX, "CC"); 12187a5642b3SDag-Erling Smørgrav printf("\n"); 1219ee0afaa9SEmmanuel Vadot } 12207ad30f58SMariusz Zaborski cap_setpassent(cappwd, 1); 122161149f8dSJilles Tjoelker for (xf = xfiles, n = 0; n < nxfiles; ++n, ++xf) { 1222f38b68aeSBrooks Davis if (xf->xf_data == 0) 122361149f8dSJilles Tjoelker continue; 122400feaafdSAndrew Thompson if (opt_j >= 0 && opt_j != getprocjid(xf->xf_pid)) 122500feaafdSAndrew Thompson continue; 122661149f8dSJilles Tjoelker hash = (int)((uintptr_t)xf->xf_data % HASHSIZE); 12277e80c6b0SMichael Tuexen for (s = sockhash[hash]; s != NULL; s = s->next) { 1228f38b68aeSBrooks Davis if (s->socket != xf->xf_data) 122961149f8dSJilles Tjoelker continue; 123061149f8dSJilles Tjoelker if (!check_ports(s)) 123161149f8dSJilles Tjoelker continue; 123261149f8dSJilles Tjoelker s->shown = 1; 123361149f8dSJilles Tjoelker pos = 0; 12347ad30f58SMariusz Zaborski if (opt_n || 12357ad30f58SMariusz Zaborski (pwd = cap_getpwuid(cappwd, xf->xf_uid)) == NULL) 123661149f8dSJilles Tjoelker pos += xprintf("%lu ", (u_long)xf->xf_uid); 123761149f8dSJilles Tjoelker else 123861149f8dSJilles Tjoelker pos += xprintf("%s ", pwd->pw_name); 123961149f8dSJilles Tjoelker while (pos < 9) 124061149f8dSJilles Tjoelker pos += xprintf(" "); 124161149f8dSJilles Tjoelker pos += xprintf("%.10s", getprocname(xf->xf_pid)); 124261149f8dSJilles Tjoelker while (pos < 20) 124361149f8dSJilles Tjoelker pos += xprintf(" "); 124461149f8dSJilles Tjoelker pos += xprintf("%lu ", (u_long)xf->xf_pid); 124561149f8dSJilles Tjoelker while (pos < 26) 124661149f8dSJilles Tjoelker pos += xprintf(" "); 124761149f8dSJilles Tjoelker pos += xprintf("%d ", xf->xf_fd); 124861149f8dSJilles Tjoelker displaysock(s, pos); 124961149f8dSJilles Tjoelker } 12507e80c6b0SMichael Tuexen } 125100feaafdSAndrew Thompson if (opt_j >= 0) 125200feaafdSAndrew Thompson return; 125361149f8dSJilles Tjoelker for (hash = 0; hash < HASHSIZE; hash++) { 125461149f8dSJilles Tjoelker for (s = sockhash[hash]; s != NULL; s = s->next) { 125561149f8dSJilles Tjoelker if (s->shown) 125661149f8dSJilles Tjoelker continue; 125761149f8dSJilles Tjoelker if (!check_ports(s)) 125861149f8dSJilles Tjoelker continue; 125961149f8dSJilles Tjoelker pos = 0; 126061149f8dSJilles Tjoelker pos += xprintf("%-8s %-10s %-5s %-2s ", 126161149f8dSJilles Tjoelker "?", "?", "?", "?"); 126261149f8dSJilles Tjoelker displaysock(s, pos); 126361149f8dSJilles Tjoelker } 126461149f8dSJilles Tjoelker } 1265ca007d91SDag-Erling Smørgrav } 1266ca007d91SDag-Erling Smørgrav 1267f1cd4902SRyan Moeller static int 1268f1cd4902SRyan Moeller set_default_protos(void) 12691f3d67aaSGiorgos Keramidas { 12701f3d67aaSGiorgos Keramidas struct protoent *prot; 12711f3d67aaSGiorgos Keramidas const char *pname; 12721f3d67aaSGiorgos Keramidas size_t pindex; 12731f3d67aaSGiorgos Keramidas 12741f3d67aaSGiorgos Keramidas init_protos(default_numprotos); 12751f3d67aaSGiorgos Keramidas 12761f3d67aaSGiorgos Keramidas for (pindex = 0; pindex < default_numprotos; pindex++) { 12771f3d67aaSGiorgos Keramidas pname = default_protos[pindex]; 1278c5a2d8c5SRyan Moeller prot = cap_getprotobyname(capnetdb, pname); 12791f3d67aaSGiorgos Keramidas if (prot == NULL) 1280c5a2d8c5SRyan Moeller err(1, "cap_getprotobyname: %s", pname); 12811f3d67aaSGiorgos Keramidas protos[pindex] = prot->p_proto; 12821f3d67aaSGiorgos Keramidas } 12831f3d67aaSGiorgos Keramidas numprotos = pindex; 12841f3d67aaSGiorgos Keramidas return (pindex); 12851f3d67aaSGiorgos Keramidas } 12861f3d67aaSGiorgos Keramidas 1287f1cd4902SRyan Moeller /* 1288f1cd4902SRyan Moeller * Return the vnet property of the jail, or -1 on error. 1289f1cd4902SRyan Moeller */ 1290f1cd4902SRyan Moeller static int 1291f1cd4902SRyan Moeller jail_getvnet(int jid) 1292f1cd4902SRyan Moeller { 1293f1cd4902SRyan Moeller struct iovec jiov[6]; 1294f1cd4902SRyan Moeller int vnet; 1295f1cd4902SRyan Moeller 1296f1cd4902SRyan Moeller vnet = -1; 1297f1cd4902SRyan Moeller jiov[0].iov_base = __DECONST(char *, "jid"); 1298f1cd4902SRyan Moeller jiov[0].iov_len = sizeof("jid"); 1299f1cd4902SRyan Moeller jiov[1].iov_base = &jid; 1300f1cd4902SRyan Moeller jiov[1].iov_len = sizeof(jid); 1301f1cd4902SRyan Moeller jiov[2].iov_base = __DECONST(char *, "vnet"); 1302f1cd4902SRyan Moeller jiov[2].iov_len = sizeof("vnet"); 1303f1cd4902SRyan Moeller jiov[3].iov_base = &vnet; 1304f1cd4902SRyan Moeller jiov[3].iov_len = sizeof(vnet); 1305f1cd4902SRyan Moeller jiov[4].iov_base = __DECONST(char *, "errmsg"); 1306f1cd4902SRyan Moeller jiov[4].iov_len = sizeof("errmsg"); 1307f1cd4902SRyan Moeller jiov[5].iov_base = jail_errmsg; 1308f1cd4902SRyan Moeller jiov[5].iov_len = JAIL_ERRMSGLEN; 1309f1cd4902SRyan Moeller jail_errmsg[0] = '\0'; 1310f1cd4902SRyan Moeller if (jail_get(jiov, nitems(jiov), 0) < 0) { 1311f1cd4902SRyan Moeller if (!jail_errmsg[0]) 1312f1cd4902SRyan Moeller snprintf(jail_errmsg, JAIL_ERRMSGLEN, 1313f1cd4902SRyan Moeller "jail_get: %s", strerror(errno)); 1314f1cd4902SRyan Moeller return (-1); 1315f1cd4902SRyan Moeller } 1316f1cd4902SRyan Moeller return (vnet); 1317f1cd4902SRyan Moeller } 1318f1cd4902SRyan Moeller 1319ca007d91SDag-Erling Smørgrav static void 1320ca007d91SDag-Erling Smørgrav usage(void) 1321ca007d91SDag-Erling Smørgrav { 13221f3d67aaSGiorgos Keramidas fprintf(stderr, 132383f60cb2SMichael Tuexen "usage: sockstat [-46cLlSsUuvw] [-j jid] [-p ports] [-P protocols]\n"); 1324ca007d91SDag-Erling Smørgrav exit(1); 1325ca007d91SDag-Erling Smørgrav } 1326ca007d91SDag-Erling Smørgrav 1327ca007d91SDag-Erling Smørgrav int 1328ca007d91SDag-Erling Smørgrav main(int argc, char *argv[]) 1329ca007d91SDag-Erling Smørgrav { 1330c5a2d8c5SRyan Moeller cap_channel_t *capcas; 1331c5a2d8c5SRyan Moeller cap_net_limit_t *limit; 13327ad30f58SMariusz Zaborski const char *pwdcmds[] = { "setpassent", "getpwuid" }; 13337ad30f58SMariusz Zaborski const char *pwdfields[] = { "pw_name" }; 13341f3d67aaSGiorgos Keramidas int protos_defined = -1; 13351f3d67aaSGiorgos Keramidas int o, i; 1336ca007d91SDag-Erling Smørgrav 133700feaafdSAndrew Thompson opt_j = -1; 1338ccdd2b2bSAlexander Motin while ((o = getopt(argc, argv, "46Ccj:Llnp:P:qSsUuvw")) != -1) 1339ca007d91SDag-Erling Smørgrav switch (o) { 1340ca007d91SDag-Erling Smørgrav case '4': 1341ca007d91SDag-Erling Smørgrav opt_4 = 1; 1342ca007d91SDag-Erling Smørgrav break; 1343ca007d91SDag-Erling Smørgrav case '6': 1344ca007d91SDag-Erling Smørgrav opt_6 = 1; 1345ca007d91SDag-Erling Smørgrav break; 13462ac089d0SMichael Tuexen case 'C': 13472ac089d0SMichael Tuexen opt_C = 1; 13482ac089d0SMichael Tuexen break; 1349ca007d91SDag-Erling Smørgrav case 'c': 1350ca007d91SDag-Erling Smørgrav opt_c = 1; 1351ca007d91SDag-Erling Smørgrav break; 135200feaafdSAndrew Thompson case 'j': 1353de68a320SJamie Gritton opt_j = jail_getid(optarg); 1354de68a320SJamie Gritton if (opt_j < 0) 1355*32723a3bSGleb Smirnoff errx(1, "jail_getid: %s", jail_errmsg); 135600feaafdSAndrew Thompson break; 13579b6ca892SBruce M Simpson case 'L': 13589b6ca892SBruce M Simpson opt_L = 1; 13599b6ca892SBruce M Simpson break; 1360ca007d91SDag-Erling Smørgrav case 'l': 1361ca007d91SDag-Erling Smørgrav opt_l = 1; 1362ca007d91SDag-Erling Smørgrav break; 1363ccdd2b2bSAlexander Motin case 'n': 1364ccdd2b2bSAlexander Motin opt_n = 1; 1365ccdd2b2bSAlexander Motin break; 1366ca007d91SDag-Erling Smørgrav case 'p': 1367ca007d91SDag-Erling Smørgrav parse_ports(optarg); 1368ca007d91SDag-Erling Smørgrav break; 13691f3d67aaSGiorgos Keramidas case 'P': 13701f3d67aaSGiorgos Keramidas protos_defined = parse_protos(optarg); 13711f3d67aaSGiorgos Keramidas break; 1372ee0afaa9SEmmanuel Vadot case 'q': 1373ee0afaa9SEmmanuel Vadot opt_q = 1; 137462de7037SEmmanuel Vadot break; 1375e5cccc35SMichael Tuexen case 'S': 1376e5cccc35SMichael Tuexen opt_S = 1; 1377e5cccc35SMichael Tuexen break; 13787a5642b3SDag-Erling Smørgrav case 's': 13797a5642b3SDag-Erling Smørgrav opt_s = 1; 13807a5642b3SDag-Erling Smørgrav break; 138149b836f2SMichael Tuexen case 'U': 138249b836f2SMichael Tuexen opt_U = 1; 138349b836f2SMichael Tuexen break; 1384ca007d91SDag-Erling Smørgrav case 'u': 1385ca007d91SDag-Erling Smørgrav opt_u = 1; 1386ca007d91SDag-Erling Smørgrav break; 1387ca007d91SDag-Erling Smørgrav case 'v': 1388ca007d91SDag-Erling Smørgrav ++opt_v; 1389ca007d91SDag-Erling Smørgrav break; 139083f60cb2SMichael Tuexen case 'w': 139183f60cb2SMichael Tuexen opt_w = 1; 139283f60cb2SMichael Tuexen break; 1393ca007d91SDag-Erling Smørgrav default: 1394ca007d91SDag-Erling Smørgrav usage(); 1395ca007d91SDag-Erling Smørgrav } 1396ca007d91SDag-Erling Smørgrav 1397ca007d91SDag-Erling Smørgrav argc -= optind; 1398ca007d91SDag-Erling Smørgrav argv += optind; 1399ca007d91SDag-Erling Smørgrav 1400ca007d91SDag-Erling Smørgrav if (argc > 0) 1401ca007d91SDag-Erling Smørgrav usage(); 1402ca007d91SDag-Erling Smørgrav 1403f1cd4902SRyan Moeller if (opt_j > 0) { 1404f1cd4902SRyan Moeller switch (jail_getvnet(opt_j)) { 1405f1cd4902SRyan Moeller case -1: 1406*32723a3bSGleb Smirnoff errx(2, "jail_getvnet: %s", jail_errmsg); 1407f1cd4902SRyan Moeller case JAIL_SYS_NEW: 1408f1cd4902SRyan Moeller if (jail_attach(opt_j) < 0) 1409ae37905bSRyan Moeller err(3, "jail_attach()"); 1410f1cd4902SRyan Moeller /* Set back to -1 for normal output in vnet jail. */ 1411f1cd4902SRyan Moeller opt_j = -1; 1412f1cd4902SRyan Moeller break; 1413f1cd4902SRyan Moeller default: 1414f1cd4902SRyan Moeller break; 1415f1cd4902SRyan Moeller } 1416f1cd4902SRyan Moeller } 1417f1cd4902SRyan Moeller 1418c5a2d8c5SRyan Moeller capcas = cap_init(); 1419c5a2d8c5SRyan Moeller if (capcas == NULL) 1420c5a2d8c5SRyan Moeller err(1, "Unable to contact Casper"); 1421c5a2d8c5SRyan Moeller if (caph_enter_casper() < 0) 1422c5a2d8c5SRyan Moeller err(1, "Unable to enter capability mode"); 1423c5a2d8c5SRyan Moeller capnet = cap_service_open(capcas, "system.net"); 1424c5a2d8c5SRyan Moeller if (capnet == NULL) 1425c5a2d8c5SRyan Moeller err(1, "Unable to open system.net service"); 1426c5a2d8c5SRyan Moeller capnetdb = cap_service_open(capcas, "system.netdb"); 1427c5a2d8c5SRyan Moeller if (capnetdb == NULL) 1428c5a2d8c5SRyan Moeller err(1, "Unable to open system.netdb service"); 1429c5a2d8c5SRyan Moeller capsysctl = cap_service_open(capcas, "system.sysctl"); 1430c5a2d8c5SRyan Moeller if (capsysctl == NULL) 1431c5a2d8c5SRyan Moeller err(1, "Unable to open system.sysctl service"); 14327ad30f58SMariusz Zaborski cappwd = cap_service_open(capcas, "system.pwd"); 14337ad30f58SMariusz Zaborski if (cappwd == NULL) 14347ad30f58SMariusz Zaborski err(1, "Unable to open system.pwd service"); 1435c5a2d8c5SRyan Moeller cap_close(capcas); 1436c5a2d8c5SRyan Moeller limit = cap_net_limit_init(capnet, CAPNET_ADDR2NAME); 1437c5a2d8c5SRyan Moeller if (limit == NULL) 1438c5a2d8c5SRyan Moeller err(1, "Unable to init cap_net limits"); 1439c5a2d8c5SRyan Moeller if (cap_net_limit(limit) < 0) 1440c5a2d8c5SRyan Moeller err(1, "Unable to apply limits"); 14417ad30f58SMariusz Zaborski if (cap_pwd_limit_cmds(cappwd, pwdcmds, nitems(pwdcmds)) < 0) 14427ad30f58SMariusz Zaborski err(1, "Unable to apply pwd commands limits"); 14437ad30f58SMariusz Zaborski if (cap_pwd_limit_fields(cappwd, pwdfields, nitems(pwdfields)) < 0) 14447ad30f58SMariusz Zaborski err(1, "Unable to apply pwd commands limits"); 1445c5a2d8c5SRyan Moeller 1446d2d77d2aSGiorgos Keramidas if ((!opt_4 && !opt_6) && protos_defined != -1) 14471f3d67aaSGiorgos Keramidas opt_4 = opt_6 = 1; 1448d2d77d2aSGiorgos Keramidas if (!opt_4 && !opt_6 && !opt_u) 1449d2d77d2aSGiorgos Keramidas opt_4 = opt_6 = opt_u = 1; 1450d2d77d2aSGiorgos Keramidas if ((opt_4 || opt_6) && protos_defined == -1) 1451d2d77d2aSGiorgos Keramidas protos_defined = set_default_protos(); 1452ca007d91SDag-Erling Smørgrav if (!opt_c && !opt_l) 1453ca007d91SDag-Erling Smørgrav opt_c = opt_l = 1; 1454ca007d91SDag-Erling Smørgrav 1455ca007d91SDag-Erling Smørgrav if (opt_4 || opt_6) { 14561f3d67aaSGiorgos Keramidas for (i = 0; i < protos_defined; i++) 1457d5b4aa90SMichael Tuexen if (protos[i] == IPPROTO_SCTP) 1458d5b4aa90SMichael Tuexen gather_sctp(); 1459d5b4aa90SMichael Tuexen else 14601f3d67aaSGiorgos Keramidas gather_inet(protos[i]); 1461ca007d91SDag-Erling Smørgrav } 14621f3d67aaSGiorgos Keramidas 14631f3d67aaSGiorgos Keramidas if (opt_u || (protos_defined == -1 && !opt_4 && !opt_6)) { 1464ca007d91SDag-Erling Smørgrav gather_unix(SOCK_STREAM); 1465ca007d91SDag-Erling Smørgrav gather_unix(SOCK_DGRAM); 1466b8e20e2dSHiroki Sato gather_unix(SOCK_SEQPACKET); 1467ca007d91SDag-Erling Smørgrav } 1468ca007d91SDag-Erling Smørgrav getfiles(); 1469ca007d91SDag-Erling Smørgrav display(); 1470ca007d91SDag-Erling Smørgrav exit(0); 1471ca007d91SDag-Erling Smørgrav } 1472