xref: /freebsd/usr.sbin/ppp/command.c (revision 78704ef45793e56c8e064611c05c9bb8a0067e9f)
1 /*-
2  * Copyright (c) 1996 - 2001 Brian Somers <brian@Awfulhak.org>
3  *          based on work by Toshiharu OHNO <tony-o@iij.ad.jp>
4  *                           Internet Initiative Japan, Inc (IIJ)
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  *
28  * $FreeBSD$
29  */
30 
31 #include <sys/param.h>
32 #include <netinet/in_systm.h>
33 #include <netinet/in.h>
34 #include <netinet/ip.h>
35 #include <arpa/inet.h>
36 #include <sys/socket.h>
37 #include <net/route.h>
38 #include <netdb.h>
39 #include <sys/un.h>
40 
41 #include <ctype.h>
42 #include <errno.h>
43 #include <fcntl.h>
44 #include <paths.h>
45 #include <stdarg.h>
46 #include <stdio.h>
47 #include <stdlib.h>
48 #include <string.h>
49 #include <sys/wait.h>
50 #include <termios.h>
51 #include <unistd.h>
52 
53 #ifndef NONAT
54 #ifdef LOCALNAT
55 #include "alias.h"
56 #else
57 #include <alias.h>
58 #endif
59 #endif
60 
61 #include "layer.h"
62 #include "defs.h"
63 #include "command.h"
64 #include "mbuf.h"
65 #include "log.h"
66 #include "timer.h"
67 #include "fsm.h"
68 #include "iplist.h"
69 #include "throughput.h"
70 #include "slcompress.h"
71 #include "lqr.h"
72 #include "hdlc.h"
73 #include "lcp.h"
74 #include "ncpaddr.h"
75 #include "ipcp.h"
76 #ifndef NONAT
77 #include "nat_cmd.h"
78 #endif
79 #include "systems.h"
80 #include "filter.h"
81 #include "descriptor.h"
82 #include "main.h"
83 #include "route.h"
84 #include "ccp.h"
85 #include "auth.h"
86 #include "async.h"
87 #include "link.h"
88 #include "physical.h"
89 #include "mp.h"
90 #ifndef NORADIUS
91 #include "radius.h"
92 #endif
93 #include "ipv6cp.h"
94 #include "ncp.h"
95 #include "bundle.h"
96 #include "server.h"
97 #include "prompt.h"
98 #include "chat.h"
99 #include "chap.h"
100 #include "cbcp.h"
101 #include "datalink.h"
102 #include "iface.h"
103 #include "id.h"
104 #include "probe.h"
105 
106 /* ``set'' values */
107 #define	VAR_AUTHKEY	0
108 #define	VAR_DIAL	1
109 #define	VAR_LOGIN	2
110 #define	VAR_AUTHNAME	3
111 #define	VAR_AUTOLOAD	4
112 #define	VAR_WINSIZE	5
113 #define	VAR_DEVICE	6
114 #define	VAR_ACCMAP	7
115 #define	VAR_MRRU	8
116 #define	VAR_MRU		9
117 #define	VAR_MTU		10
118 #define	VAR_OPENMODE	11
119 #define	VAR_PHONE	12
120 #define	VAR_HANGUP	13
121 #define	VAR_IDLETIMEOUT	14
122 #define	VAR_LQRPERIOD	15
123 #define	VAR_LCPRETRY	16
124 #define	VAR_CHAPRETRY	17
125 #define	VAR_PAPRETRY	18
126 #define	VAR_CCPRETRY	19
127 #define	VAR_IPCPRETRY	20
128 #define	VAR_DNS		21
129 #define	VAR_NBNS	22
130 #define	VAR_MODE	23
131 #define	VAR_CALLBACK	24
132 #define	VAR_CBCP	25
133 #define	VAR_CHOKED	26
134 #define	VAR_SENDPIPE	27
135 #define	VAR_RECVPIPE	28
136 #define	VAR_RADIUS	29
137 #define	VAR_CD		30
138 #define	VAR_PARITY	31
139 #define VAR_CRTSCTS	32
140 #define VAR_URGENTPORTS	33
141 #define	VAR_LOGOUT	34
142 #define	VAR_IFQUEUE	35
143 #define	VAR_MPPE	36
144 #define	VAR_IPV6CPRETRY	37
145 
146 /* ``accept|deny|disable|enable'' masks */
147 #define NEG_HISMASK (1)
148 #define NEG_MYMASK (2)
149 
150 /* ``accept|deny|disable|enable'' values */
151 #define NEG_ACFCOMP	40
152 #define NEG_CHAP05	41
153 #define NEG_CHAP80	42
154 #define NEG_CHAP80LM	43
155 #define NEG_DEFLATE	44
156 #define NEG_DNS		45
157 #define NEG_ENDDISC	46
158 #define NEG_LQR		47
159 #define NEG_PAP		48
160 #define NEG_PPPDDEFLATE	49
161 #define NEG_PRED1	50
162 #define NEG_PROTOCOMP	51
163 #define NEG_SHORTSEQ	52
164 #define NEG_VJCOMP	53
165 #define NEG_MPPE	54
166 #define NEG_CHAP81	55
167 
168 const char Version[] = "3.1";
169 
170 static int ShowCommand(struct cmdargs const *);
171 static int TerminalCommand(struct cmdargs const *);
172 static int QuitCommand(struct cmdargs const *);
173 static int OpenCommand(struct cmdargs const *);
174 static int CloseCommand(struct cmdargs const *);
175 static int DownCommand(struct cmdargs const *);
176 static int SetCommand(struct cmdargs const *);
177 static int LinkCommand(struct cmdargs const *);
178 static int AddCommand(struct cmdargs const *);
179 static int DeleteCommand(struct cmdargs const *);
180 static int NegotiateCommand(struct cmdargs const *);
181 static int ClearCommand(struct cmdargs const *);
182 static int RunListCommand(struct cmdargs const *);
183 static int IfaceAddCommand(struct cmdargs const *);
184 static int IfaceDeleteCommand(struct cmdargs const *);
185 static int IfaceClearCommand(struct cmdargs const *);
186 static int SetProcTitle(struct cmdargs const *);
187 #ifndef NONAT
188 static int NatEnable(struct cmdargs const *);
189 static int NatOption(struct cmdargs const *);
190 #endif
191 
192 static const char *
193 showcx(struct cmdtab const *cmd)
194 {
195   if (cmd->lauth & LOCAL_CX)
196     return "(c)";
197   else if (cmd->lauth & LOCAL_CX_OPT)
198     return "(o)";
199 
200   return "";
201 }
202 
203 static int
204 HelpCommand(struct cmdargs const *arg)
205 {
206   struct cmdtab const *cmd;
207   int n, cmax, dmax, cols, cxlen;
208   const char *cx;
209 
210   if (!arg->prompt) {
211     log_Printf(LogWARN, "help: Cannot help without a prompt\n");
212     return 0;
213   }
214 
215   if (arg->argc > arg->argn) {
216     for (cmd = arg->cmdtab; cmd->name || cmd->alias; cmd++)
217       if ((cmd->lauth & arg->prompt->auth) &&
218           ((cmd->name && !strcasecmp(cmd->name, arg->argv[arg->argn])) ||
219            (cmd->alias && !strcasecmp(cmd->alias, arg->argv[arg->argn])))) {
220 	prompt_Printf(arg->prompt, "%s %s\n", cmd->syntax, showcx(cmd));
221 	return 0;
222       }
223     return -1;
224   }
225 
226   cmax = dmax = 0;
227   for (cmd = arg->cmdtab; cmd->func; cmd++)
228     if (cmd->name && (cmd->lauth & arg->prompt->auth)) {
229       if ((n = strlen(cmd->name) + strlen(showcx(cmd))) > cmax)
230         cmax = n;
231       if ((n = strlen(cmd->helpmes)) > dmax)
232         dmax = n;
233     }
234 
235   cols = 80 / (dmax + cmax + 3);
236   n = 0;
237   prompt_Printf(arg->prompt, "(o) = Optional context,"
238                 " (c) = Context required\n");
239   for (cmd = arg->cmdtab; cmd->func; cmd++)
240     if (cmd->name && (cmd->lauth & arg->prompt->auth)) {
241       cx = showcx(cmd);
242       cxlen = cmax - strlen(cmd->name);
243       if (n % cols != 0)
244         prompt_Printf(arg->prompt, " ");
245       prompt_Printf(arg->prompt, "%s%-*.*s: %-*.*s",
246               cmd->name, cxlen, cxlen, cx, dmax, dmax, cmd->helpmes);
247       if (++n % cols == 0)
248         prompt_Printf(arg->prompt, "\n");
249     }
250   if (n % cols != 0)
251     prompt_Printf(arg->prompt, "\n");
252 
253   return 0;
254 }
255 
256 static int
257 IdentCommand(struct cmdargs const *arg)
258 {
259   Concatinate(arg->cx->physical->link.lcp.cfg.ident,
260               sizeof arg->cx->physical->link.lcp.cfg.ident,
261               arg->argc - arg->argn, arg->argv + arg->argn);
262   return 0;
263 }
264 
265 static int
266 SendIdentification(struct cmdargs const *arg)
267 {
268   if (arg->cx->state < DATALINK_LCP) {
269     log_Printf(LogWARN, "sendident: link has not reached LCP\n");
270     return 2;
271   }
272   return lcp_SendIdentification(&arg->cx->physical->link.lcp) ? 0 : 1;
273 }
274 
275 static int
276 CloneCommand(struct cmdargs const *arg)
277 {
278   char namelist[LINE_LEN];
279   char *name;
280   int f;
281 
282   if (arg->argc == arg->argn)
283     return -1;
284 
285   namelist[sizeof namelist - 1] = '\0';
286   for (f = arg->argn; f < arg->argc; f++) {
287     strncpy(namelist, arg->argv[f], sizeof namelist - 1);
288     for(name = strtok(namelist, ", "); name; name = strtok(NULL,", "))
289       bundle_DatalinkClone(arg->bundle, arg->cx, name);
290   }
291 
292   return 0;
293 }
294 
295 static int
296 RemoveCommand(struct cmdargs const *arg)
297 {
298   if (arg->argc != arg->argn)
299     return -1;
300 
301   if (arg->cx->state != DATALINK_CLOSED) {
302     log_Printf(LogWARN, "remove: Cannot delete links that aren't closed\n");
303     return 2;
304   }
305 
306   bundle_DatalinkRemove(arg->bundle, arg->cx);
307   return 0;
308 }
309 
310 static int
311 RenameCommand(struct cmdargs const *arg)
312 {
313   if (arg->argc != arg->argn + 1)
314     return -1;
315 
316   if (bundle_RenameDatalink(arg->bundle, arg->cx, arg->argv[arg->argn]))
317     return 0;
318 
319   log_Printf(LogWARN, "%s -> %s: target name already exists\n",
320              arg->cx->name, arg->argv[arg->argn]);
321   return 1;
322 }
323 
324 static int
325 LoadCommand(struct cmdargs const *arg)
326 {
327   const char *err;
328   int n, mode;
329 
330   mode = arg->bundle->phys_type.all;
331 
332   if (arg->argn < arg->argc) {
333     for (n = arg->argn; n < arg->argc; n++)
334       if ((err = system_IsValid(arg->argv[n], arg->prompt, mode)) != NULL) {
335         log_Printf(LogWARN, "%s: %s\n", arg->argv[n], err);
336         return 1;
337       }
338 
339     for (n = arg->argn; n < arg->argc; n++) {
340       bundle_SetLabel(arg->bundle, arg->argv[arg->argc - 1]);
341       system_Select(arg->bundle, arg->argv[n], CONFFILE, arg->prompt, arg->cx);
342     }
343     bundle_SetLabel(arg->bundle, arg->argv[arg->argc - 1]);
344   } else if ((err = system_IsValid("default", arg->prompt, mode)) != NULL) {
345     log_Printf(LogWARN, "default: %s\n", err);
346     return 1;
347   } else {
348     bundle_SetLabel(arg->bundle, "default");
349     system_Select(arg->bundle, "default", CONFFILE, arg->prompt, arg->cx);
350     bundle_SetLabel(arg->bundle, "default");
351   }
352 
353   return 0;
354 }
355 
356 static int
357 LogCommand(struct cmdargs const *arg)
358 {
359   char buf[LINE_LEN];
360 
361   if (arg->argn < arg->argc) {
362     char *argv[MAXARGS];
363     int argc = arg->argc - arg->argn;
364 
365     if (argc >= sizeof argv / sizeof argv[0]) {
366       argc = sizeof argv / sizeof argv[0] - 1;
367       log_Printf(LogWARN, "Truncating log command to %d args\n", argc);
368     }
369     command_Expand(argv, argc, arg->argv + arg->argn, arg->bundle, 1, getpid());
370     Concatinate(buf, sizeof buf, argc, (const char *const *)argv);
371     log_Printf(LogLOG, "%s\n", buf);
372     command_Free(argc, argv);
373     return 0;
374   }
375 
376   return -1;
377 }
378 
379 static int
380 SaveCommand(struct cmdargs const *arg)
381 {
382   log_Printf(LogWARN, "save command is not yet implemented.\n");
383   return 1;
384 }
385 
386 static int
387 DialCommand(struct cmdargs const *arg)
388 {
389   int res;
390 
391   if ((arg->cx && !(arg->cx->physical->type & (PHYS_INTERACTIVE|PHYS_AUTO)))
392       || (!arg->cx &&
393           (arg->bundle->phys_type.all & ~(PHYS_INTERACTIVE|PHYS_AUTO)))) {
394     log_Printf(LogWARN, "Manual dial is only available for auto and"
395               " interactive links\n");
396     return 1;
397   }
398 
399   if (arg->argc > arg->argn && (res = LoadCommand(arg)) != 0)
400     return res;
401 
402   bundle_Open(arg->bundle, arg->cx ? arg->cx->name : NULL, PHYS_ALL, 1);
403 
404   return 0;
405 }
406 
407 #define isinword(ch) (isalnum(ch) || (ch) == '_')
408 
409 static char *
410 strstrword(char *big, const char *little)
411 {
412   /* Get the first occurance of the word ``little'' in ``big'' */
413   char *pos;
414   int len;
415 
416   pos = big;
417   len = strlen(little);
418 
419   while ((pos = strstr(pos, little)) != NULL)
420     if ((pos != big && isinword(pos[-1])) || isinword(pos[len]))
421       pos++;
422     else if (pos != big && pos[-1] == '\\')
423       memmove(pos - 1, pos, strlen(pos) + 1);
424     else
425       break;
426 
427   return pos;
428 }
429 
430 static char *
431 subst(char *tgt, const char *oldstr, const char *newstr)
432 {
433   /* tgt is a malloc()d area... realloc() as necessary */
434   char *word, *ntgt;
435   int ltgt, loldstr, lnewstr, pos;
436 
437   if ((word = strstrword(tgt, oldstr)) == NULL)
438     return tgt;
439 
440   ltgt = strlen(tgt) + 1;
441   loldstr = strlen(oldstr);
442   lnewstr = strlen(newstr);
443   do {
444     pos = word - tgt;
445     if (loldstr > lnewstr)
446       bcopy(word + loldstr, word + lnewstr, ltgt - pos - loldstr);
447     if (loldstr != lnewstr) {
448       ntgt = realloc(tgt, ltgt += lnewstr - loldstr);
449       if (ntgt == NULL)
450         break;			/* Oh wonderful ! */
451       word = ntgt + pos;
452       tgt = ntgt;
453     }
454     if (lnewstr > loldstr)
455       bcopy(word + loldstr, word + lnewstr, ltgt - pos - loldstr);
456     bcopy(newstr, word, lnewstr);
457   } while ((word = strstrword(word, oldstr)));
458 
459   return tgt;
460 }
461 
462 static char *
463 substip(char *tgt, const char *oldstr, struct in_addr ip)
464 {
465   return subst(tgt, oldstr, inet_ntoa(ip));
466 }
467 
468 static char *
469 substlong(char *tgt, const char *oldstr, long l)
470 {
471   char buf[23];
472 
473   snprintf(buf, sizeof buf, "%ld", l);
474 
475   return subst(tgt, oldstr, buf);
476 }
477 
478 static char *
479 substull(char *tgt, const char *oldstr, unsigned long long ull)
480 {
481   char buf[21];
482 
483   snprintf(buf, sizeof buf, "%llu", ull);
484 
485   return subst(tgt, oldstr, buf);
486 }
487 
488 
489 #ifndef NOINET6
490 static char *
491 substipv6(char *tgt, const char *oldstr, const struct ncpaddr *ip)
492 {
493     return subst(tgt, oldstr, ncpaddr_ntoa(ip));
494 }
495 #endif
496 
497 void
498 command_Expand(char **nargv, int argc, char const *const *oargv,
499                struct bundle *bundle, int inc0, pid_t pid)
500 {
501   int arg, secs;
502   char uptime[20];
503   unsigned long long oin, oout, pin, pout;
504 
505   if (inc0)
506     arg = 0;		/* Start at arg 0 */
507   else {
508     nargv[0] = strdup(oargv[0]);
509     arg = 1;
510   }
511 
512   secs = bundle_Uptime(bundle);
513   snprintf(uptime, sizeof uptime, "%d:%02d:%02d",
514            secs / 3600, (secs / 60) % 60, secs % 60);
515   oin = bundle->ncp.ipcp.throughput.OctetsIn;
516   oout = bundle->ncp.ipcp.throughput.OctetsOut;
517   pin = bundle->ncp.ipcp.throughput.PacketsIn;
518   pout = bundle->ncp.ipcp.throughput.PacketsOut;
519 #ifndef NOINET6
520   oin += bundle->ncp.ipv6cp.throughput.OctetsIn;
521   oout += bundle->ncp.ipv6cp.throughput.OctetsOut;
522   pin += bundle->ncp.ipv6cp.throughput.PacketsIn;
523   pout += bundle->ncp.ipv6cp.throughput.PacketsOut;
524 #endif
525 
526   for (; arg < argc; arg++) {
527     nargv[arg] = strdup(oargv[arg]);
528     nargv[arg] = subst(nargv[arg], "AUTHNAME", bundle->cfg.auth.name);
529     nargv[arg] = subst(nargv[arg], "COMPILATIONDATE", __DATE__);
530     nargv[arg] = substip(nargv[arg], "DNS0", bundle->ncp.ipcp.ns.dns[0]);
531     nargv[arg] = substip(nargv[arg], "DNS1", bundle->ncp.ipcp.ns.dns[1]);
532     nargv[arg] = subst(nargv[arg], "ENDDISC",
533                        mp_Enddisc(bundle->ncp.mp.cfg.enddisc.class,
534                                   bundle->ncp.mp.cfg.enddisc.address,
535                                   bundle->ncp.mp.cfg.enddisc.len));
536     nargv[arg] = substip(nargv[arg], "HISADDR", bundle->ncp.ipcp.peer_ip);
537 #ifndef NOINET6
538     nargv[arg] = substipv6(nargv[arg], "HISADDR6", &bundle->ncp.ipv6cp.hisaddr);
539 #endif
540     nargv[arg] = subst(nargv[arg], "INTERFACE", bundle->iface->name);
541     nargv[arg] = substull(nargv[arg], "IPOCTETSIN",
542                           bundle->ncp.ipcp.throughput.OctetsIn);
543     nargv[arg] = substull(nargv[arg], "IPOCTETSOUT",
544                           bundle->ncp.ipcp.throughput.OctetsOut);
545     nargv[arg] = substull(nargv[arg], "IPPACKETSIN",
546                           bundle->ncp.ipcp.throughput.PacketsIn);
547     nargv[arg] = substull(nargv[arg], "IPPACKETSOUT",
548                           bundle->ncp.ipcp.throughput.PacketsOut);
549 #ifndef NOINET6
550     nargv[arg] = substull(nargv[arg], "IPV6OCTETSIN",
551                           bundle->ncp.ipv6cp.throughput.OctetsIn);
552     nargv[arg] = substull(nargv[arg], "IPV6OCTETSOUT",
553                           bundle->ncp.ipv6cp.throughput.OctetsOut);
554     nargv[arg] = substull(nargv[arg], "IPV6PACKETSIN",
555                           bundle->ncp.ipv6cp.throughput.PacketsIn);
556     nargv[arg] = substull(nargv[arg], "IPV6PACKETSOUT",
557                           bundle->ncp.ipv6cp.throughput.PacketsOut);
558 #endif
559     nargv[arg] = subst(nargv[arg], "LABEL", bundle_GetLabel(bundle));
560     nargv[arg] = substip(nargv[arg], "MYADDR", bundle->ncp.ipcp.my_ip);
561 #ifndef NOINET6
562     nargv[arg] = substipv6(nargv[arg], "MYADDR6", &bundle->ncp.ipv6cp.myaddr);
563 #endif
564     nargv[arg] = substull(nargv[arg], "OCTETSIN", oin);
565     nargv[arg] = substull(nargv[arg], "OCTETSOUT", oout);
566     nargv[arg] = substull(nargv[arg], "PACKETSIN", pin);
567     nargv[arg] = substull(nargv[arg], "PACKETSOUT", pout);
568     nargv[arg] = subst(nargv[arg], "PEER_ENDDISC",
569                        mp_Enddisc(bundle->ncp.mp.peer.enddisc.class,
570                                   bundle->ncp.mp.peer.enddisc.address,
571                                   bundle->ncp.mp.peer.enddisc.len));
572     nargv[arg] = substlong(nargv[arg], "PROCESSID", pid);
573     if (server.cfg.port)
574       nargv[arg] = substlong(nargv[arg], "SOCKNAME", server.cfg.port);
575     else
576       nargv[arg] = subst(nargv[arg], "SOCKNAME", server.cfg.sockname);
577     nargv[arg] = subst(nargv[arg], "UPTIME", uptime);
578     nargv[arg] = subst(nargv[arg], "USER", bundle->ncp.mp.peer.authname);
579     nargv[arg] = subst(nargv[arg], "VERSION", Version);
580   }
581   nargv[arg] = NULL;
582 }
583 
584 void
585 command_Free(int argc, char **argv)
586 {
587   while (argc) {
588     free(*argv);
589     argc--;
590     argv++;
591   }
592 }
593 
594 static int
595 ShellCommand(struct cmdargs const *arg, int bg)
596 {
597   const char *shell;
598   pid_t shpid, pid;
599 
600 #ifdef SHELL_ONLY_INTERACTIVELY
601   /* we're only allowed to shell when we run ppp interactively */
602   if (arg->prompt && arg->prompt->owner) {
603     log_Printf(LogWARN, "Can't start a shell from a network connection\n");
604     return 1;
605   }
606 #endif
607 
608   if (arg->argc == arg->argn) {
609     if (!arg->prompt) {
610       log_Printf(LogWARN, "Can't start an interactive shell from"
611                 " a config file\n");
612       return 1;
613     } else if (arg->prompt->owner) {
614       log_Printf(LogWARN, "Can't start an interactive shell from"
615                 " a socket connection\n");
616       return 1;
617     } else if (bg) {
618       log_Printf(LogWARN, "Can only start an interactive shell in"
619 		" the foreground mode\n");
620       return 1;
621     }
622   }
623 
624   pid = getpid();
625   if ((shpid = fork()) == 0) {
626     int i, fd;
627 
628     if ((shell = getenv("SHELL")) == 0)
629       shell = _PATH_BSHELL;
630 
631     timer_TermService();
632 
633     if (arg->prompt)
634       fd = arg->prompt->fd_out;
635     else if ((fd = open(_PATH_DEVNULL, O_RDWR)) == -1) {
636       log_Printf(LogALERT, "Failed to open %s: %s\n",
637                 _PATH_DEVNULL, strerror(errno));
638       exit(1);
639     }
640     dup2(fd, STDIN_FILENO);
641     dup2(fd, STDOUT_FILENO);
642     dup2(fd, STDERR_FILENO);
643     for (i = getdtablesize(); i > STDERR_FILENO; i--)
644       fcntl(i, F_SETFD, 1);
645 
646 #ifndef NOSUID
647     setuid(ID0realuid());
648 #endif
649     if (arg->argc > arg->argn) {
650       /* substitute pseudo args */
651       char *argv[MAXARGS];
652       int argc = arg->argc - arg->argn;
653 
654       if (argc >= sizeof argv / sizeof argv[0]) {
655         argc = sizeof argv / sizeof argv[0] - 1;
656         log_Printf(LogWARN, "Truncating shell command to %d args\n", argc);
657       }
658       command_Expand(argv, argc, arg->argv + arg->argn, arg->bundle, 0, pid);
659       if (bg) {
660 	pid_t p;
661 
662 	p = getpid();
663 	if (daemon(1, 1) == -1) {
664 	  log_Printf(LogERROR, "%ld: daemon: %s\n", (long)p, strerror(errno));
665 	  exit(1);
666 	}
667       } else if (arg->prompt)
668         printf("ppp: Pausing until %s finishes\n", arg->argv[arg->argn]);
669       execvp(argv[0], argv);
670     } else {
671       if (arg->prompt)
672         printf("ppp: Pausing until %s finishes\n", shell);
673       prompt_TtyOldMode(arg->prompt);
674       execl(shell, shell, (char *)NULL);
675     }
676 
677     log_Printf(LogWARN, "exec() of %s failed: %s\n",
678               arg->argc > arg->argn ? arg->argv[arg->argn] : shell,
679               strerror(errno));
680     _exit(255);
681   }
682 
683   if (shpid == (pid_t)-1)
684     log_Printf(LogERROR, "Fork failed: %s\n", strerror(errno));
685   else {
686     int status;
687     waitpid(shpid, &status, 0);
688   }
689 
690   if (arg->prompt && !arg->prompt->owner)
691     prompt_TtyCommandMode(arg->prompt);
692 
693   return 0;
694 }
695 
696 static int
697 BgShellCommand(struct cmdargs const *arg)
698 {
699   if (arg->argc == arg->argn)
700     return -1;
701   return ShellCommand(arg, 1);
702 }
703 
704 static int
705 FgShellCommand(struct cmdargs const *arg)
706 {
707   return ShellCommand(arg, 0);
708 }
709 
710 static int
711 ResolvCommand(struct cmdargs const *arg)
712 {
713   if (arg->argc == arg->argn + 1) {
714     if (!strcasecmp(arg->argv[arg->argn], "reload"))
715       ipcp_LoadDNS(&arg->bundle->ncp.ipcp);
716     else if (!strcasecmp(arg->argv[arg->argn], "restore"))
717       ipcp_RestoreDNS(&arg->bundle->ncp.ipcp);
718     else if (!strcasecmp(arg->argv[arg->argn], "rewrite"))
719       ipcp_WriteDNS(&arg->bundle->ncp.ipcp);
720     else if (!strcasecmp(arg->argv[arg->argn], "readonly"))
721       arg->bundle->ncp.ipcp.ns.writable = 0;
722     else if (!strcasecmp(arg->argv[arg->argn], "writable"))
723       arg->bundle->ncp.ipcp.ns.writable = 1;
724     else
725       return -1;
726 
727     return 0;
728   }
729 
730   return -1;
731 }
732 
733 #ifndef NONAT
734 static struct cmdtab const NatCommands[] =
735 {
736   {"addr", NULL, nat_RedirectAddr, LOCAL_AUTH,
737    "static address translation", "nat addr [addr_local addr_alias]"},
738   {"deny_incoming", NULL, NatOption, LOCAL_AUTH,
739    "stop incoming connections", "nat deny_incoming yes|no",
740    (const void *) PKT_ALIAS_DENY_INCOMING},
741   {"enable", NULL, NatEnable, LOCAL_AUTH,
742    "enable NAT", "nat enable yes|no"},
743   {"log", NULL, NatOption, LOCAL_AUTH,
744    "log NAT link creation", "nat log yes|no",
745    (const void *) PKT_ALIAS_LOG},
746   {"port", NULL, nat_RedirectPort, LOCAL_AUTH, "port redirection",
747    "nat port proto localaddr:port[-port] aliasport[-aliasport]"},
748   {"proto", NULL, nat_RedirectProto, LOCAL_AUTH, "protocol redirection",
749    "nat proto proto localIP [publicIP [remoteIP]]"},
750   {"proxy", NULL, nat_ProxyRule, LOCAL_AUTH,
751    "proxy control", "nat proxy server host[:port] ..."},
752 #ifndef NO_FW_PUNCH
753   {"punch_fw", NULL, nat_PunchFW, LOCAL_AUTH,
754    "firewall control", "nat punch_fw [base count]"},
755 #endif
756   {"same_ports", NULL, NatOption, LOCAL_AUTH,
757    "try to leave port numbers unchanged", "nat same_ports yes|no",
758    (const void *) PKT_ALIAS_SAME_PORTS},
759   {"target", NULL, nat_SetTarget, LOCAL_AUTH,
760    "Default address for incoming connections", "nat target addr" },
761   {"unregistered_only", NULL, NatOption, LOCAL_AUTH,
762    "translate unregistered (private) IP address space only",
763    "nat unregistered_only yes|no",
764    (const void *) PKT_ALIAS_UNREGISTERED_ONLY},
765   {"use_sockets", NULL, NatOption, LOCAL_AUTH,
766    "allocate host sockets", "nat use_sockets yes|no",
767    (const void *) PKT_ALIAS_USE_SOCKETS},
768   {"help", "?", HelpCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
769    "Display this message", "nat help|? [command]", NatCommands},
770   {NULL, NULL, NULL},
771 };
772 #endif
773 
774 static struct cmdtab const AllowCommands[] = {
775   {"modes", "mode", AllowModes, LOCAL_AUTH,
776   "Only allow certain ppp modes", "allow modes mode..."},
777   {"users", "user", AllowUsers, LOCAL_AUTH,
778   "Only allow ppp access to certain users", "allow users logname..."},
779   {"help", "?", HelpCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
780   "Display this message", "allow help|? [command]", AllowCommands},
781   {NULL, NULL, NULL},
782 };
783 
784 static struct cmdtab const IfaceCommands[] =
785 {
786   {"add", NULL, IfaceAddCommand, LOCAL_AUTH,
787    "Add iface address", "iface add addr[/bits| mask] peer", NULL},
788   {NULL, "add!", IfaceAddCommand, LOCAL_AUTH,
789    "Add or change an iface address", "iface add! addr[/bits| mask] peer",
790    (void *)1},
791   {"clear", NULL, IfaceClearCommand, LOCAL_AUTH,
792    "Clear iface address(es)", "iface clear [INET | INET6]"},
793   {"delete", "rm", IfaceDeleteCommand, LOCAL_AUTH,
794    "Delete iface address", "iface delete addr", NULL},
795   {NULL, "rm!", IfaceDeleteCommand, LOCAL_AUTH,
796    "Delete iface address", "iface delete addr", (void *)1},
797   {NULL, "delete!", IfaceDeleteCommand, LOCAL_AUTH,
798    "Delete iface address", "iface delete addr", (void *)1},
799   {"show", NULL, iface_Show, LOCAL_AUTH,
800    "Show iface address(es)", "iface show"},
801   {"help", "?", HelpCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
802    "Display this message", "nat help|? [command]", IfaceCommands},
803   {NULL, NULL, NULL},
804 };
805 
806 static struct cmdtab const Commands[] = {
807   {"accept", NULL, NegotiateCommand, LOCAL_AUTH | LOCAL_CX_OPT,
808   "accept option request", "accept option .."},
809   {"add", NULL, AddCommand, LOCAL_AUTH,
810   "add route", "add dest mask gateway", NULL},
811   {NULL, "add!", AddCommand, LOCAL_AUTH,
812   "add or change route", "add! dest mask gateway", (void *)1},
813   {"allow", "auth", RunListCommand, LOCAL_AUTH,
814   "Allow ppp access", "allow users|modes ....", AllowCommands},
815   {"bg", "!bg", BgShellCommand, LOCAL_AUTH,
816   "Run a background command", "[!]bg command"},
817   {"clear", NULL, ClearCommand, LOCAL_AUTH | LOCAL_CX_OPT,
818   "Clear throughput statistics",
819   "clear ipcp|ipv6cp|physical [current|overall|peak]..."},
820   {"clone", NULL, CloneCommand, LOCAL_AUTH | LOCAL_CX,
821   "Clone a link", "clone newname..."},
822   {"close", NULL, CloseCommand, LOCAL_AUTH | LOCAL_CX_OPT,
823   "Close an FSM", "close [lcp|ccp]"},
824   {"delete", NULL, DeleteCommand, LOCAL_AUTH,
825   "delete route", "delete dest", NULL},
826   {NULL, "delete!", DeleteCommand, LOCAL_AUTH,
827   "delete a route if it exists", "delete! dest", (void *)1},
828   {"deny", NULL, NegotiateCommand, LOCAL_AUTH | LOCAL_CX_OPT,
829   "Deny option request", "deny option .."},
830   {"dial", "call", DialCommand, LOCAL_AUTH | LOCAL_CX_OPT,
831   "Dial and login", "dial|call [system ...]", NULL},
832   {"disable", NULL, NegotiateCommand, LOCAL_AUTH | LOCAL_CX_OPT,
833   "Disable option", "disable option .."},
834   {"down", NULL, DownCommand, LOCAL_AUTH | LOCAL_CX_OPT,
835   "Generate a down event", "down [ccp|lcp]"},
836   {"enable", NULL, NegotiateCommand, LOCAL_AUTH | LOCAL_CX_OPT,
837   "Enable option", "enable option .."},
838   {"ident", NULL, IdentCommand, LOCAL_AUTH | LOCAL_CX,
839   "Set the link identity", "ident text..."},
840   {"iface", "interface", RunListCommand, LOCAL_AUTH,
841   "interface control", "iface option ...", IfaceCommands},
842   {"link", "datalink", LinkCommand, LOCAL_AUTH,
843   "Link specific commands", "link name command ..."},
844   {"load", NULL, LoadCommand, LOCAL_AUTH | LOCAL_CX_OPT,
845   "Load settings", "load [system ...]"},
846   {"log", NULL, LogCommand, LOCAL_AUTH | LOCAL_CX_OPT,
847   "log information", "log word ..."},
848 #ifndef NONAT
849   {"nat", "alias", RunListCommand, LOCAL_AUTH,
850   "NAT control", "nat option yes|no", NatCommands},
851 #endif
852   {"open", NULL, OpenCommand, LOCAL_AUTH | LOCAL_CX_OPT,
853   "Open an FSM", "open! [lcp|ccp|ipcp]", (void *)1},
854   {"passwd", NULL, PasswdCommand, LOCAL_NO_AUTH,
855   "Password for manipulation", "passwd LocalPassword"},
856   {"quit", "bye", QuitCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
857   "Quit PPP program", "quit|bye [all]"},
858   {"remove", "rm", RemoveCommand, LOCAL_AUTH | LOCAL_CX,
859   "Remove a link", "remove"},
860   {"rename", "mv", RenameCommand, LOCAL_AUTH | LOCAL_CX,
861   "Rename a link", "rename name"},
862   {"resolv", NULL, ResolvCommand, LOCAL_AUTH,
863   "Manipulate resolv.conf", "resolv readonly|reload|restore|rewrite|writable"},
864   {"save", NULL, SaveCommand, LOCAL_AUTH,
865   "Save settings", "save"},
866   {"sendident", NULL, SendIdentification, LOCAL_AUTH | LOCAL_CX,
867   "Transmit the link identity", "sendident"},
868   {"set", "setup", SetCommand, LOCAL_AUTH | LOCAL_CX_OPT,
869   "Set parameters", "set[up] var value"},
870   {"shell", "!", FgShellCommand, LOCAL_AUTH,
871   "Run a subshell", "shell|! [sh command]"},
872   {"show", NULL, ShowCommand, LOCAL_AUTH | LOCAL_CX_OPT,
873   "Show status and stats", "show var"},
874   {"term", NULL, TerminalCommand, LOCAL_AUTH | LOCAL_CX,
875   "Enter terminal mode", "term"},
876   {"help", "?", HelpCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
877   "Display this message", "help|? [command]", Commands},
878   {NULL, NULL, NULL},
879 };
880 
881 static int
882 ShowEscape(struct cmdargs const *arg)
883 {
884   if (arg->cx->physical->async.cfg.EscMap[32]) {
885     int code, bit;
886     const char *sep = "";
887 
888     for (code = 0; code < 32; code++)
889       if (arg->cx->physical->async.cfg.EscMap[code])
890 	for (bit = 0; bit < 8; bit++)
891 	  if (arg->cx->physical->async.cfg.EscMap[code] & (1 << bit)) {
892 	    prompt_Printf(arg->prompt, "%s0x%02x", sep, (code << 3) + bit);
893             sep = ", ";
894           }
895     prompt_Printf(arg->prompt, "\n");
896   }
897   return 0;
898 }
899 
900 static int
901 ShowTimerList(struct cmdargs const *arg)
902 {
903   timer_Show(0, arg->prompt);
904   return 0;
905 }
906 
907 static int
908 ShowStopped(struct cmdargs const *arg)
909 {
910   prompt_Printf(arg->prompt, " Stopped Timer:  LCP: ");
911   if (!arg->cx->physical->link.lcp.fsm.StoppedTimer.load)
912     prompt_Printf(arg->prompt, "Disabled");
913   else
914     prompt_Printf(arg->prompt, "%ld secs",
915                   arg->cx->physical->link.lcp.fsm.StoppedTimer.load / SECTICKS);
916 
917   prompt_Printf(arg->prompt, ", CCP: ");
918   if (!arg->cx->physical->link.ccp.fsm.StoppedTimer.load)
919     prompt_Printf(arg->prompt, "Disabled");
920   else
921     prompt_Printf(arg->prompt, "%ld secs",
922                   arg->cx->physical->link.ccp.fsm.StoppedTimer.load / SECTICKS);
923 
924   prompt_Printf(arg->prompt, "\n");
925 
926   return 0;
927 }
928 
929 static int
930 ShowVersion(struct cmdargs const *arg)
931 {
932   prompt_Printf(arg->prompt, "PPP Version %s - %s\n", Version, __DATE__);
933   return 0;
934 }
935 
936 static int
937 ShowProtocolStats(struct cmdargs const *arg)
938 {
939   struct link *l = command_ChooseLink(arg);
940 
941   prompt_Printf(arg->prompt, "%s:\n", l->name);
942   link_ReportProtocolStatus(l, arg->prompt);
943   return 0;
944 }
945 
946 static struct cmdtab const ShowCommands[] = {
947   {"bundle", NULL, bundle_ShowStatus, LOCAL_AUTH,
948   "bundle details", "show bundle"},
949   {"ccp", NULL, ccp_ReportStatus, LOCAL_AUTH | LOCAL_CX_OPT,
950   "CCP status", "show cpp"},
951   {"compress", NULL, sl_Show, LOCAL_AUTH,
952   "VJ compression stats", "show compress"},
953   {"escape", NULL, ShowEscape, LOCAL_AUTH | LOCAL_CX,
954   "escape characters", "show escape"},
955   {"filter", NULL, filter_Show, LOCAL_AUTH,
956   "packet filters", "show filter [in|out|dial|alive]"},
957   {"hdlc", NULL, hdlc_ReportStatus, LOCAL_AUTH | LOCAL_CX,
958   "HDLC errors", "show hdlc"},
959   {"iface", "interface", iface_Show, LOCAL_AUTH,
960   "Interface status", "show iface"},
961   {"ipcp", NULL, ipcp_Show, LOCAL_AUTH,
962   "IPCP status", "show ipcp"},
963 #ifndef NOINET6
964   {"ipv6cp", NULL, ipv6cp_Show, LOCAL_AUTH,
965   "IPV6CP status", "show ipv6cp"},
966 #endif
967   {"layers", NULL, link_ShowLayers, LOCAL_AUTH | LOCAL_CX_OPT,
968   "Protocol layers", "show layers"},
969   {"lcp", NULL, lcp_ReportStatus, LOCAL_AUTH | LOCAL_CX,
970   "LCP status", "show lcp"},
971   {"link", "datalink", datalink_Show, LOCAL_AUTH | LOCAL_CX,
972   "(high-level) link info", "show link"},
973   {"links", NULL, bundle_ShowLinks, LOCAL_AUTH,
974   "available link names", "show links"},
975   {"log", NULL, log_ShowLevel, LOCAL_AUTH,
976   "log levels", "show log"},
977   {"mem", NULL, mbuf_Show, LOCAL_AUTH,
978   "mbuf allocations", "show mem"},
979   {"ncp", NULL, ncp_Show, LOCAL_AUTH,
980   "NCP status", "show ncp"},
981   {"physical", NULL, physical_ShowStatus, LOCAL_AUTH | LOCAL_CX,
982   "(low-level) link info", "show physical"},
983   {"mp", "multilink", mp_ShowStatus, LOCAL_AUTH,
984   "multilink setup", "show mp"},
985   {"proto", NULL, ShowProtocolStats, LOCAL_AUTH | LOCAL_CX_OPT,
986   "protocol summary", "show proto"},
987   {"route", NULL, route_Show, LOCAL_AUTH,
988   "routing table", "show route"},
989   {"stopped", NULL, ShowStopped, LOCAL_AUTH | LOCAL_CX,
990   "STOPPED timeout", "show stopped"},
991   {"timers", NULL, ShowTimerList, LOCAL_AUTH,
992   "alarm timers", "show timers"},
993   {"version", NULL, ShowVersion, LOCAL_NO_AUTH | LOCAL_AUTH,
994   "version string", "show version"},
995   {"who", NULL, log_ShowWho, LOCAL_AUTH,
996   "client list", "show who"},
997   {"help", "?", HelpCommand, LOCAL_NO_AUTH | LOCAL_AUTH,
998   "Display this message", "show help|? [command]", ShowCommands},
999   {NULL, NULL, NULL},
1000 };
1001 
1002 static struct cmdtab const *
1003 FindCommand(struct cmdtab const *cmds, const char *str, int *pmatch)
1004 {
1005   int nmatch;
1006   int len;
1007   struct cmdtab const *found;
1008 
1009   found = NULL;
1010   len = strlen(str);
1011   nmatch = 0;
1012   while (cmds->func) {
1013     if (cmds->name && strncasecmp(str, cmds->name, len) == 0) {
1014       if (cmds->name[len] == '\0') {
1015 	*pmatch = 1;
1016 	return cmds;
1017       }
1018       nmatch++;
1019       found = cmds;
1020     } else if (cmds->alias && strncasecmp(str, cmds->alias, len) == 0) {
1021       if (cmds->alias[len] == '\0') {
1022 	*pmatch = 1;
1023 	return cmds;
1024       }
1025       nmatch++;
1026       found = cmds;
1027     }
1028     cmds++;
1029   }
1030   *pmatch = nmatch;
1031   return found;
1032 }
1033 
1034 static const char *
1035 mkPrefix(int argc, char const *const *argv, char *tgt, int sz)
1036 {
1037   int f, tlen, len;
1038 
1039   tlen = 0;
1040   for (f = 0; f < argc && tlen < sz - 2; f++) {
1041     if (f)
1042       tgt[tlen++] = ' ';
1043     len = strlen(argv[f]);
1044     if (len > sz - tlen - 1)
1045       len = sz - tlen - 1;
1046     strncpy(tgt+tlen, argv[f], len);
1047     tlen += len;
1048   }
1049   tgt[tlen] = '\0';
1050   return tgt;
1051 }
1052 
1053 static int
1054 FindExec(struct bundle *bundle, struct cmdtab const *cmds, int argc, int argn,
1055          char const *const *argv, struct prompt *prompt, struct datalink *cx)
1056 {
1057   struct cmdtab const *cmd;
1058   int val = 1;
1059   int nmatch;
1060   struct cmdargs arg;
1061   char prefix[100];
1062 
1063   cmd = FindCommand(cmds, argv[argn], &nmatch);
1064   if (nmatch > 1)
1065     log_Printf(LogWARN, "%s: Ambiguous command\n",
1066               mkPrefix(argn+1, argv, prefix, sizeof prefix));
1067   else if (cmd && (!prompt || (cmd->lauth & prompt->auth))) {
1068     if ((cmd->lauth & LOCAL_CX) && !cx)
1069       /* We've got no context, but we require it */
1070       cx = bundle2datalink(bundle, NULL);
1071 
1072     if ((cmd->lauth & LOCAL_CX) && !cx)
1073       log_Printf(LogWARN, "%s: No context (use the `link' command)\n",
1074                 mkPrefix(argn+1, argv, prefix, sizeof prefix));
1075     else {
1076       if (cx && !(cmd->lauth & (LOCAL_CX|LOCAL_CX_OPT))) {
1077         log_Printf(LogWARN, "%s: Redundant context (%s) ignored\n",
1078                   mkPrefix(argn+1, argv, prefix, sizeof prefix), cx->name);
1079         cx = NULL;
1080       }
1081       arg.cmdtab = cmds;
1082       arg.cmd = cmd;
1083       arg.argc = argc;
1084       arg.argn = argn+1;
1085       arg.argv = argv;
1086       arg.bundle = bundle;
1087       arg.cx = cx;
1088       arg.prompt = prompt;
1089       val = (*cmd->func) (&arg);
1090     }
1091   } else
1092     log_Printf(LogWARN, "%s: Invalid command\n",
1093               mkPrefix(argn+1, argv, prefix, sizeof prefix));
1094 
1095   if (val == -1)
1096     log_Printf(LogWARN, "usage: %s\n", cmd->syntax);
1097   else if (val)
1098     log_Printf(LogWARN, "%s: Failed %d\n",
1099               mkPrefix(argn+1, argv, prefix, sizeof prefix), val);
1100 
1101   return val;
1102 }
1103 
1104 int
1105 command_Expand_Interpret(char *buff, int nb, char *argv[MAXARGS], int offset)
1106 {
1107   char buff2[LINE_LEN-offset];
1108 
1109   InterpretArg(buff, buff2);
1110   strncpy(buff, buff2, LINE_LEN - offset - 1);
1111   buff[LINE_LEN - offset - 1] = '\0';
1112 
1113   return command_Interpret(buff, nb, argv);
1114 }
1115 
1116 int
1117 command_Interpret(char *buff, int nb, char *argv[MAXARGS])
1118 {
1119   char *cp;
1120 
1121   if (nb > 0) {
1122     cp = buff + strcspn(buff, "\r\n");
1123     if (cp)
1124       *cp = '\0';
1125     return MakeArgs(buff, argv, MAXARGS, PARSE_REDUCE);
1126   }
1127   return 0;
1128 }
1129 
1130 static int
1131 arghidden(int argc, char const *const *argv, int n)
1132 {
1133   /* Is arg n of the given command to be hidden from the log ? */
1134 
1135   /* set authkey xxxxx */
1136   /* set key xxxxx */
1137   if (n == 2 && !strncasecmp(argv[0], "se", 2) &&
1138       (!strncasecmp(argv[1], "authk", 5) || !strncasecmp(argv[1], "ke", 2)))
1139     return 1;
1140 
1141   /* passwd xxxxx */
1142   if (n == 1 && !strncasecmp(argv[0], "p", 1))
1143     return 1;
1144 
1145   /* set server port xxxxx .... */
1146   if (n == 3 && !strncasecmp(argv[0], "se", 2) &&
1147       !strncasecmp(argv[1], "se", 2))
1148     return 1;
1149 
1150   return 0;
1151 }
1152 
1153 void
1154 command_Run(struct bundle *bundle, int argc, char const *const *argv,
1155            struct prompt *prompt, const char *label, struct datalink *cx)
1156 {
1157   if (argc > 0) {
1158     if (log_IsKept(LogCOMMAND)) {
1159       char buf[LINE_LEN];
1160       int f, n;
1161 
1162       if (label) {
1163         strncpy(buf, label, sizeof buf - 3);
1164         buf[sizeof buf - 3] = '\0';
1165         strcat(buf, ": ");
1166         n = strlen(buf);
1167       } else {
1168         *buf = '\0';
1169         n = 0;
1170       }
1171       buf[sizeof buf - 1] = '\0';	/* In case we run out of room in buf */
1172 
1173       for (f = 0; f < argc; f++) {
1174         if (n < sizeof buf - 1 && f)
1175           buf[n++] = ' ';
1176         if (arghidden(argc, argv, f))
1177           strncpy(buf+n, "********", sizeof buf - n - 1);
1178         else
1179           strncpy(buf+n, argv[f], sizeof buf - n - 1);
1180         n += strlen(buf+n);
1181       }
1182       log_Printf(LogCOMMAND, "%s\n", buf);
1183     }
1184     FindExec(bundle, Commands, argc, 0, argv, prompt, cx);
1185   }
1186 }
1187 
1188 int
1189 command_Decode(struct bundle *bundle, char *buff, int nb, struct prompt *prompt,
1190               const char *label)
1191 {
1192   int argc;
1193   char *argv[MAXARGS];
1194 
1195   if ((argc = command_Expand_Interpret(buff, nb, argv, 0)) < 0)
1196     return 0;
1197 
1198   command_Run(bundle, argc, (char const *const *)argv, prompt, label, NULL);
1199   return 1;
1200 }
1201 
1202 static int
1203 ShowCommand(struct cmdargs const *arg)
1204 {
1205   if (!arg->prompt)
1206     log_Printf(LogWARN, "show: Cannot show without a prompt\n");
1207   else if (arg->argc > arg->argn)
1208     FindExec(arg->bundle, ShowCommands, arg->argc, arg->argn, arg->argv,
1209              arg->prompt, arg->cx);
1210   else
1211     prompt_Printf(arg->prompt, "Use ``show ?'' to get a list.\n");
1212 
1213   return 0;
1214 }
1215 
1216 static int
1217 TerminalCommand(struct cmdargs const *arg)
1218 {
1219   if (!arg->prompt) {
1220     log_Printf(LogWARN, "term: Need a prompt\n");
1221     return 1;
1222   }
1223 
1224   if (arg->cx->physical->link.lcp.fsm.state > ST_CLOSED) {
1225     prompt_Printf(arg->prompt, "LCP state is [%s]\n",
1226                   State2Nam(arg->cx->physical->link.lcp.fsm.state));
1227     return 1;
1228   }
1229 
1230   datalink_Up(arg->cx, 0, 0);
1231   prompt_TtyTermMode(arg->prompt, arg->cx);
1232   return 0;
1233 }
1234 
1235 static int
1236 QuitCommand(struct cmdargs const *arg)
1237 {
1238   if (!arg->prompt || prompt_IsController(arg->prompt) ||
1239       (arg->argc > arg->argn && !strcasecmp(arg->argv[arg->argn], "all") &&
1240        (arg->prompt->auth & LOCAL_AUTH)))
1241     Cleanup(EX_NORMAL);
1242   if (arg->prompt)
1243     prompt_Destroy(arg->prompt, 1);
1244 
1245   return 0;
1246 }
1247 
1248 static int
1249 OpenCommand(struct cmdargs const *arg)
1250 {
1251   if (arg->argc == arg->argn)
1252     bundle_Open(arg->bundle, arg->cx ? arg->cx->name : NULL, PHYS_ALL, 1);
1253   else if (arg->argc == arg->argn + 1) {
1254     if (!strcasecmp(arg->argv[arg->argn], "lcp")) {
1255       struct datalink *cx = arg->cx ?
1256         arg->cx : bundle2datalink(arg->bundle, NULL);
1257       if (cx) {
1258         if (cx->physical->link.lcp.fsm.state == ST_OPENED)
1259           fsm_Reopen(&cx->physical->link.lcp.fsm);
1260         else
1261           bundle_Open(arg->bundle, cx->name, PHYS_ALL, 1);
1262       } else
1263         log_Printf(LogWARN, "open lcp: You must specify a link\n");
1264     } else if (!strcasecmp(arg->argv[arg->argn], "ccp")) {
1265       struct fsm *fp;
1266 
1267       fp = &command_ChooseLink(arg)->ccp.fsm;
1268       if (fp->link->lcp.fsm.state != ST_OPENED)
1269         log_Printf(LogWARN, "open: LCP must be open before opening CCP\n");
1270       else if (fp->state == ST_OPENED)
1271         fsm_Reopen(fp);
1272       else {
1273         fp->open_mode = 0;	/* Not passive any more */
1274         if (fp->state == ST_STOPPED) {
1275           fsm_Down(fp);
1276           fsm_Up(fp);
1277         } else {
1278           fsm_Up(fp);
1279           fsm_Open(fp);
1280         }
1281       }
1282     } else if (!strcasecmp(arg->argv[arg->argn], "ipcp")) {
1283       if (arg->cx)
1284         log_Printf(LogWARN, "open ipcp: You need not specify a link\n");
1285       if (arg->bundle->ncp.ipcp.fsm.state == ST_OPENED)
1286         fsm_Reopen(&arg->bundle->ncp.ipcp.fsm);
1287       else
1288         bundle_Open(arg->bundle, NULL, PHYS_ALL, 1);
1289     } else
1290       return -1;
1291   } else
1292     return -1;
1293 
1294   return 0;
1295 }
1296 
1297 static int
1298 CloseCommand(struct cmdargs const *arg)
1299 {
1300   if (arg->argc == arg->argn)
1301     bundle_Close(arg->bundle, arg->cx ? arg->cx->name : NULL, CLOSE_STAYDOWN);
1302   else if (arg->argc == arg->argn + 1) {
1303     if (!strcasecmp(arg->argv[arg->argn], "lcp"))
1304       bundle_Close(arg->bundle, arg->cx ? arg->cx->name : NULL, CLOSE_LCP);
1305     else if (!strcasecmp(arg->argv[arg->argn], "ccp") ||
1306              !strcasecmp(arg->argv[arg->argn], "ccp!")) {
1307       struct fsm *fp;
1308 
1309       fp = &command_ChooseLink(arg)->ccp.fsm;
1310       if (fp->state == ST_OPENED) {
1311         fsm_Close(fp);
1312         if (arg->argv[arg->argn][3] == '!')
1313           fp->open_mode = 0;		/* Stay ST_CLOSED */
1314         else
1315           fp->open_mode = OPEN_PASSIVE;	/* Wait for the peer to start */
1316       }
1317     } else
1318       return -1;
1319   } else
1320     return -1;
1321 
1322   return 0;
1323 }
1324 
1325 static int
1326 DownCommand(struct cmdargs const *arg)
1327 {
1328   if (arg->argc == arg->argn) {
1329       if (arg->cx)
1330         datalink_Down(arg->cx, CLOSE_STAYDOWN);
1331       else
1332         bundle_Down(arg->bundle, CLOSE_STAYDOWN);
1333   } else if (arg->argc == arg->argn + 1) {
1334     if (!strcasecmp(arg->argv[arg->argn], "lcp")) {
1335       if (arg->cx)
1336         datalink_Down(arg->cx, CLOSE_LCP);
1337       else
1338         bundle_Down(arg->bundle, CLOSE_LCP);
1339     } else if (!strcasecmp(arg->argv[arg->argn], "ccp")) {
1340       struct fsm *fp = arg->cx ? &arg->cx->physical->link.ccp.fsm :
1341                                  &arg->bundle->ncp.mp.link.ccp.fsm;
1342       fsm2initial(fp);
1343     } else
1344       return -1;
1345   } else
1346     return -1;
1347 
1348   return 0;
1349 }
1350 
1351 static int
1352 SetModemSpeed(struct cmdargs const *arg)
1353 {
1354   long speed;
1355   char *end;
1356 
1357   if (arg->argc > arg->argn && *arg->argv[arg->argn]) {
1358     if (arg->argc > arg->argn+1) {
1359       log_Printf(LogWARN, "SetModemSpeed: Too many arguments\n");
1360       return -1;
1361     }
1362     if (strcasecmp(arg->argv[arg->argn], "sync") == 0) {
1363       physical_SetSync(arg->cx->physical);
1364       return 0;
1365     }
1366     end = NULL;
1367     speed = strtol(arg->argv[arg->argn], &end, 10);
1368     if (*end) {
1369       log_Printf(LogWARN, "SetModemSpeed: Bad argument \"%s\"",
1370                 arg->argv[arg->argn]);
1371       return -1;
1372     }
1373     if (physical_SetSpeed(arg->cx->physical, speed))
1374       return 0;
1375     log_Printf(LogWARN, "%s: Invalid speed\n", arg->argv[arg->argn]);
1376   } else
1377     log_Printf(LogWARN, "SetModemSpeed: No speed specified\n");
1378 
1379   return -1;
1380 }
1381 
1382 static int
1383 SetStoppedTimeout(struct cmdargs const *arg)
1384 {
1385   struct link *l = &arg->cx->physical->link;
1386 
1387   l->lcp.fsm.StoppedTimer.load = 0;
1388   l->ccp.fsm.StoppedTimer.load = 0;
1389   if (arg->argc <= arg->argn+2) {
1390     if (arg->argc > arg->argn) {
1391       l->lcp.fsm.StoppedTimer.load = atoi(arg->argv[arg->argn]) * SECTICKS;
1392       if (arg->argc > arg->argn+1)
1393         l->ccp.fsm.StoppedTimer.load = atoi(arg->argv[arg->argn+1]) * SECTICKS;
1394     }
1395     return 0;
1396   }
1397   return -1;
1398 }
1399 
1400 static int
1401 SetServer(struct cmdargs const *arg)
1402 {
1403   int res = -1;
1404 
1405   if (arg->argc > arg->argn && arg->argc < arg->argn+4) {
1406     const char *port, *passwd, *mask;
1407     int mlen;
1408 
1409     /* What's what ? */
1410     port = arg->argv[arg->argn];
1411     if (arg->argc == arg->argn + 2) {
1412       passwd = arg->argv[arg->argn+1];
1413       mask = NULL;
1414     } else if (arg->argc == arg->argn + 3) {
1415       passwd = arg->argv[arg->argn+1];
1416       mask = arg->argv[arg->argn+2];
1417       mlen = strlen(mask);
1418       if (mlen == 0 || mlen > 4 || strspn(mask, "01234567") != mlen ||
1419           (mlen == 4 && *mask != '0')) {
1420         log_Printf(LogWARN, "%s %s: %s: Invalid mask\n",
1421                    arg->argv[arg->argn - 2], arg->argv[arg->argn - 1], mask);
1422         return -1;
1423       }
1424     } else if (arg->argc != arg->argn + 1)
1425       return -1;
1426     else if (strcasecmp(port, "none") == 0) {
1427       if (server_Clear(arg->bundle))
1428         log_Printf(LogPHASE, "Disabled server socket\n");
1429       return 0;
1430     } else if (strcasecmp(port, "open") == 0) {
1431       switch (server_Reopen(arg->bundle)) {
1432         case SERVER_OK:
1433           return 0;
1434         case SERVER_FAILED:
1435           log_Printf(LogWARN, "Failed to reopen server port\n");
1436           return 1;
1437         case SERVER_UNSET:
1438           log_Printf(LogWARN, "Cannot reopen unset server socket\n");
1439           return 1;
1440         default:
1441           break;
1442       }
1443       return -1;
1444     } else if (strcasecmp(port, "closed") == 0) {
1445       if (server_Close(arg->bundle))
1446         log_Printf(LogPHASE, "Closed server socket\n");
1447       else
1448         log_Printf(LogWARN, "Server socket not open\n");
1449 
1450       return 0;
1451     } else
1452       return -1;
1453 
1454     strncpy(server.cfg.passwd, passwd, sizeof server.cfg.passwd - 1);
1455     server.cfg.passwd[sizeof server.cfg.passwd - 1] = '\0';
1456 
1457     if (*port == '/') {
1458       mode_t imask;
1459       char *ptr, name[LINE_LEN + 12];
1460 
1461       if (mask == NULL)
1462         imask = (mode_t)-1;
1463       else for (imask = mlen = 0; mask[mlen]; mlen++)
1464         imask = (imask * 8) + mask[mlen] - '0';
1465 
1466       ptr = strstr(port, "%d");
1467       if (ptr) {
1468         snprintf(name, sizeof name, "%.*s%d%s",
1469                  (int)(ptr - port), port, arg->bundle->unit, ptr + 2);
1470         port = name;
1471       }
1472       res = server_LocalOpen(arg->bundle, port, imask);
1473     } else {
1474       int iport, add = 0;
1475 
1476       if (mask != NULL)
1477         return -1;
1478 
1479       if (*port == '+') {
1480         port++;
1481         add = 1;
1482       }
1483       if (strspn(port, "0123456789") != strlen(port)) {
1484         struct servent *s;
1485 
1486         if ((s = getservbyname(port, "tcp")) == NULL) {
1487 	  iport = 0;
1488 	  log_Printf(LogWARN, "%s: Invalid port or service\n", port);
1489 	} else
1490 	  iport = ntohs(s->s_port);
1491       } else
1492         iport = atoi(port);
1493 
1494       if (iport) {
1495         if (add)
1496           iport += arg->bundle->unit;
1497         res = server_TcpOpen(arg->bundle, iport);
1498       } else
1499         res = -1;
1500     }
1501   }
1502 
1503   return res;
1504 }
1505 
1506 static int
1507 SetEscape(struct cmdargs const *arg)
1508 {
1509   int code;
1510   int argc = arg->argc - arg->argn;
1511   char const *const *argv = arg->argv + arg->argn;
1512 
1513   for (code = 0; code < 33; code++)
1514     arg->cx->physical->async.cfg.EscMap[code] = 0;
1515 
1516   while (argc-- > 0) {
1517     sscanf(*argv++, "%x", &code);
1518     code &= 0xff;
1519     arg->cx->physical->async.cfg.EscMap[code >> 3] |= (1 << (code & 7));
1520     arg->cx->physical->async.cfg.EscMap[32] = 1;
1521   }
1522   return 0;
1523 }
1524 
1525 static int
1526 SetInterfaceAddr(struct cmdargs const *arg)
1527 {
1528   struct ncp *ncp = &arg->bundle->ncp;
1529   struct ncpaddr ncpaddr;
1530   const char *hisaddr;
1531 
1532   if (arg->argc > arg->argn + 4)
1533     return -1;
1534 
1535   hisaddr = NULL;
1536   memset(&ncp->ipcp.cfg.my_range, '\0', sizeof ncp->ipcp.cfg.my_range);
1537   memset(&ncp->ipcp.cfg.peer_range, '\0', sizeof ncp->ipcp.cfg.peer_range);
1538   ncp->ipcp.cfg.HaveTriggerAddress = 0;
1539   ncp->ipcp.cfg.netmask.s_addr = INADDR_ANY;
1540   iplist_reset(&ncp->ipcp.cfg.peer_list);
1541 
1542   if (arg->argc > arg->argn) {
1543     if (!ncprange_aton(&ncp->ipcp.cfg.my_range, ncp, arg->argv[arg->argn]))
1544       return 1;
1545     if (arg->argc > arg->argn+1) {
1546       hisaddr = arg->argv[arg->argn+1];
1547       if (arg->argc > arg->argn+2) {
1548         ncp->ipcp.ifmask = ncp->ipcp.cfg.netmask =
1549           GetIpAddr(arg->argv[arg->argn+2]);
1550 	if (arg->argc > arg->argn+3) {
1551 	  ncp->ipcp.cfg.TriggerAddress = GetIpAddr(arg->argv[arg->argn+3]);
1552 	  ncp->ipcp.cfg.HaveTriggerAddress = 1;
1553 	}
1554       }
1555     }
1556   }
1557 
1558   /* 0.0.0.0 means any address (0 bits) */
1559   ncpaddr_getip4(&ncpaddr, &ncp->ipcp.my_ip);
1560   ncprange_getaddr(&ncp->ipcp.cfg.my_range, &ncpaddr);
1561   if (ncp->ipcp.my_ip.s_addr == INADDR_ANY)
1562     ncprange_setwidth(&ncp->ipcp.cfg.my_range, 0);
1563   bundle_AdjustFilters(arg->bundle, &ncpaddr, NULL);
1564 
1565   if (hisaddr && !ipcp_UseHisaddr(arg->bundle, hisaddr,
1566                                   arg->bundle->phys_type.all & PHYS_AUTO))
1567     return 4;
1568 
1569   return 0;
1570 }
1571 
1572 static int
1573 SetRetry(int argc, char const *const *argv, u_int *timeout, u_int *maxreq,
1574           u_int *maxtrm, int def)
1575 {
1576   if (argc == 0) {
1577     *timeout = DEF_FSMRETRY;
1578     *maxreq = def;
1579     if (maxtrm != NULL)
1580       *maxtrm = def;
1581   } else {
1582     long l = atol(argv[0]);
1583 
1584     if (l < MIN_FSMRETRY) {
1585       log_Printf(LogWARN, "%ld: Invalid FSM retry period - min %d\n",
1586                  l, MIN_FSMRETRY);
1587       return 1;
1588     } else
1589       *timeout = l;
1590 
1591     if (argc > 1) {
1592       l = atol(argv[1]);
1593       if (l < 1) {
1594         log_Printf(LogWARN, "%ld: Invalid FSM REQ tries - changed to 1\n", l);
1595         l = 1;
1596       }
1597       *maxreq = l;
1598 
1599       if (argc > 2 && maxtrm != NULL) {
1600         l = atol(argv[2]);
1601         if (l < 1) {
1602           log_Printf(LogWARN, "%ld: Invalid FSM TRM tries - changed to 1\n", l);
1603           l = 1;
1604         }
1605         *maxtrm = l;
1606       }
1607     }
1608   }
1609 
1610   return 0;
1611 }
1612 
1613 static int
1614 SetVariable(struct cmdargs const *arg)
1615 {
1616   long long_val, param = (long)arg->cmd->args;
1617   int mode, dummyint, f, first, res;
1618   u_short *change;
1619   const char *argp;
1620   struct datalink *cx = arg->cx;	/* LOCAL_CX uses this */
1621   struct link *l = command_ChooseLink(arg);	/* LOCAL_CX_OPT uses this */
1622   struct in_addr *ipaddr;
1623   struct ncpaddr ncpaddr[2];
1624 
1625   if (arg->argc > arg->argn)
1626     argp = arg->argv[arg->argn];
1627   else
1628     argp = "";
1629 
1630   res = 0;
1631 
1632   if ((arg->cmd->lauth & LOCAL_CX) && !cx) {
1633     log_Printf(LogWARN, "set %s: No context (use the `link' command)\n",
1634               arg->cmd->name);
1635     return 1;
1636   } else if (cx && !(arg->cmd->lauth & (LOCAL_CX|LOCAL_CX_OPT))) {
1637     log_Printf(LogWARN, "set %s: Redundant context (%s) ignored\n",
1638               arg->cmd->name, cx->name);
1639     cx = NULL;
1640   }
1641 
1642   switch (param) {
1643   case VAR_AUTHKEY:
1644     strncpy(arg->bundle->cfg.auth.key, argp,
1645             sizeof arg->bundle->cfg.auth.key - 1);
1646     arg->bundle->cfg.auth.key[sizeof arg->bundle->cfg.auth.key - 1] = '\0';
1647     break;
1648 
1649   case VAR_AUTHNAME:
1650     switch (bundle_Phase(arg->bundle)) {
1651       default:
1652         log_Printf(LogWARN, "Altering authname while at phase %s\n",
1653                    bundle_PhaseName(arg->bundle));
1654         /* drop through */
1655       case PHASE_DEAD:
1656       case PHASE_ESTABLISH:
1657         strncpy(arg->bundle->cfg.auth.name, argp,
1658                 sizeof arg->bundle->cfg.auth.name - 1);
1659         arg->bundle->cfg.auth.name[sizeof arg->bundle->cfg.auth.name-1] = '\0';
1660         break;
1661     }
1662     break;
1663 
1664   case VAR_AUTOLOAD:
1665     if (arg->argc == arg->argn + 3) {
1666       int v1, v2, v3;
1667       char *end;
1668 
1669       v1 = strtol(arg->argv[arg->argn], &end, 0);
1670       if (v1 < 0 || *end) {
1671         log_Printf(LogWARN, "autoload: %s: Invalid min percentage\n",
1672                    arg->argv[arg->argn]);
1673         res = 1;
1674         break;
1675       }
1676 
1677       v2 = strtol(arg->argv[arg->argn + 1], &end, 0);
1678       if (v2 < 0 || *end) {
1679         log_Printf(LogWARN, "autoload: %s: Invalid max percentage\n",
1680                    arg->argv[arg->argn + 1]);
1681         res = 1;
1682         break;
1683       }
1684       if (v2 < v1) {
1685         v3 = v1;
1686         v1 = v2;
1687         v2 = v3;
1688       }
1689 
1690       v3 = strtol(arg->argv[arg->argn + 2], &end, 0);
1691       if (v3 <= 0 || *end) {
1692         log_Printf(LogWARN, "autoload: %s: Invalid throughput period\n",
1693                    arg->argv[arg->argn + 2]);
1694         res = 1;
1695         break;
1696       }
1697 
1698       arg->bundle->ncp.mp.cfg.autoload.min = v1;
1699       arg->bundle->ncp.mp.cfg.autoload.max = v2;
1700       arg->bundle->ncp.mp.cfg.autoload.period = v3;
1701       mp_RestartAutoloadTimer(&arg->bundle->ncp.mp);
1702     } else {
1703       log_Printf(LogWARN, "Set autoload requires three arguments\n");
1704       res = 1;
1705     }
1706     break;
1707 
1708   case VAR_DIAL:
1709     strncpy(cx->cfg.script.dial, argp, sizeof cx->cfg.script.dial - 1);
1710     cx->cfg.script.dial[sizeof cx->cfg.script.dial - 1] = '\0';
1711     break;
1712 
1713   case VAR_LOGIN:
1714     strncpy(cx->cfg.script.login, argp, sizeof cx->cfg.script.login - 1);
1715     cx->cfg.script.login[sizeof cx->cfg.script.login - 1] = '\0';
1716     break;
1717 
1718   case VAR_WINSIZE:
1719     if (arg->argc > arg->argn) {
1720       l->ccp.cfg.deflate.out.winsize = atoi(arg->argv[arg->argn]);
1721       if (l->ccp.cfg.deflate.out.winsize < 8 ||
1722           l->ccp.cfg.deflate.out.winsize > 15) {
1723           log_Printf(LogWARN, "%d: Invalid outgoing window size\n",
1724                     l->ccp.cfg.deflate.out.winsize);
1725           l->ccp.cfg.deflate.out.winsize = 15;
1726       }
1727       if (arg->argc > arg->argn+1) {
1728         l->ccp.cfg.deflate.in.winsize = atoi(arg->argv[arg->argn+1]);
1729         if (l->ccp.cfg.deflate.in.winsize < 8 ||
1730             l->ccp.cfg.deflate.in.winsize > 15) {
1731             log_Printf(LogWARN, "%d: Invalid incoming window size\n",
1732                       l->ccp.cfg.deflate.in.winsize);
1733             l->ccp.cfg.deflate.in.winsize = 15;
1734         }
1735       } else
1736         l->ccp.cfg.deflate.in.winsize = 0;
1737     } else {
1738       log_Printf(LogWARN, "No window size specified\n");
1739       res = 1;
1740     }
1741     break;
1742 
1743 #ifndef NODES
1744   case VAR_MPPE:
1745     if (arg->argc > arg->argn + 2) {
1746       res = -1;
1747       break;
1748     }
1749 
1750     if (arg->argc == arg->argn) {
1751       l->ccp.cfg.mppe.keybits = 0;
1752       l->ccp.cfg.mppe.state = MPPE_ANYSTATE;
1753       l->ccp.cfg.mppe.required = 0;
1754       break;
1755     }
1756 
1757     if (!strcmp(argp, "*"))
1758       long_val = 0;
1759     else {
1760       long_val = atol(argp);
1761       if (long_val != 40 && long_val != 56 && long_val != 128) {
1762         log_Printf(LogWARN, "%s: Invalid bits value\n", argp);
1763         res = -1;
1764         break;
1765       }
1766     }
1767 
1768     if (arg->argc == arg->argn + 2) {
1769       if (!strcmp(arg->argv[arg->argn + 1], "*"))
1770         l->ccp.cfg.mppe.state = MPPE_ANYSTATE;
1771       else if (!strcasecmp(arg->argv[arg->argn + 1], "stateless"))
1772         l->ccp.cfg.mppe.state = MPPE_STATELESS;
1773       else if (!strcasecmp(arg->argv[arg->argn + 1], "stateful"))
1774         l->ccp.cfg.mppe.state = MPPE_STATEFUL;
1775       else {
1776         log_Printf(LogWARN, "%s: Invalid state value\n",
1777                    arg->argv[arg->argn + 1]);
1778         res = -1;
1779         break;
1780       }
1781     } else
1782       l->ccp.cfg.mppe.state = MPPE_ANYSTATE;
1783     l->ccp.cfg.mppe.keybits = long_val;
1784     l->ccp.cfg.mppe.required = 1;
1785     break;
1786 #endif
1787 
1788   case VAR_DEVICE:
1789     physical_SetDeviceList(cx->physical, arg->argc - arg->argn,
1790                            arg->argv + arg->argn);
1791     break;
1792 
1793   case VAR_ACCMAP:
1794     if (arg->argc > arg->argn) {
1795       u_long ulong_val;
1796       sscanf(argp, "%lx", &ulong_val);
1797       cx->physical->link.lcp.cfg.accmap = (u_int32_t)ulong_val;
1798     } else {
1799       log_Printf(LogWARN, "No accmap specified\n");
1800       res = 1;
1801     }
1802     break;
1803 
1804   case VAR_MODE:
1805     mode = Nam2mode(argp);
1806     if (mode == PHYS_NONE || mode == PHYS_ALL) {
1807       log_Printf(LogWARN, "%s: Invalid mode\n", argp);
1808       res = -1;
1809       break;
1810     }
1811     bundle_SetMode(arg->bundle, cx, mode);
1812     break;
1813 
1814   case VAR_MRRU:
1815     switch (bundle_Phase(arg->bundle)) {
1816       case PHASE_DEAD:
1817         break;
1818       case PHASE_ESTABLISH:
1819         /* Make sure none of our links are DATALINK_LCP or greater */
1820         if (bundle_HighestState(arg->bundle) >= DATALINK_LCP) {
1821           log_Printf(LogWARN, "mrru: Only changable before LCP negotiations\n");
1822           res = 1;
1823           break;
1824         }
1825         break;
1826       default:
1827         log_Printf(LogWARN, "mrru: Only changable at phase DEAD/ESTABLISH\n");
1828         res = 1;
1829         break;
1830     }
1831     if (res != 0)
1832       break;
1833     long_val = atol(argp);
1834     if (long_val && long_val < MIN_MRU) {
1835       log_Printf(LogWARN, "MRRU %ld: too small - min %d\n", long_val, MIN_MRU);
1836       res = 1;
1837       break;
1838     } else if (long_val > MAX_MRU) {
1839       log_Printf(LogWARN, "MRRU %ld: too big - max %d\n", long_val, MAX_MRU);
1840       res = 1;
1841       break;
1842     } else
1843       arg->bundle->ncp.mp.cfg.mrru = long_val;
1844     break;
1845 
1846   case VAR_MRU:
1847     long_val = 0;	/* silence gcc */
1848     change = NULL;	/* silence gcc */
1849     switch(arg->argc - arg->argn) {
1850     case 1:
1851       if (argp[strspn(argp, "0123456789")] != '\0') {
1852         res = -1;
1853         break;
1854       }
1855       /*FALLTHRU*/
1856     case 0:
1857       long_val = atol(argp);
1858       change = &l->lcp.cfg.mru;
1859       if (long_val > l->lcp.cfg.max_mru) {
1860         log_Printf(LogWARN, "MRU %ld: too large - max set to %d\n", long_val,
1861                    l->lcp.cfg.max_mru);
1862         res = 1;
1863         break;
1864       }
1865       break;
1866     case 2:
1867       if (strcasecmp(argp, "max") && strcasecmp(argp, "maximum")) {
1868         res = -1;
1869         break;
1870       }
1871       long_val = atol(arg->argv[arg->argn + 1]);
1872       change = &l->lcp.cfg.max_mru;
1873       if (long_val > MAX_MRU) {
1874         log_Printf(LogWARN, "MRU %ld: too large - maximum is %d\n", long_val,
1875                    MAX_MRU);
1876         res = 1;
1877         break;
1878       }
1879       break;
1880     default:
1881       res = -1;
1882       break;
1883     }
1884     if (res != 0)
1885       break;
1886 
1887     if (long_val == 0)
1888       *change = 0;
1889     else if (long_val < MIN_MRU) {
1890       log_Printf(LogWARN, "MRU %ld: too small - min %d\n", long_val, MIN_MRU);
1891       res = 1;
1892       break;
1893     } else if (long_val > MAX_MRU) {
1894       log_Printf(LogWARN, "MRU %ld: too big - max %d\n", long_val, MAX_MRU);
1895       res = 1;
1896       break;
1897     } else
1898       *change = long_val;
1899     if (l->lcp.cfg.mru > *change)
1900       l->lcp.cfg.mru = *change;
1901     break;
1902 
1903   case VAR_MTU:
1904     long_val = 0;	/* silence gcc */
1905     change = NULL;	/* silence gcc */
1906     switch(arg->argc - arg->argn) {
1907     case 1:
1908       if (argp[strspn(argp, "0123456789")] != '\0') {
1909         res = -1;
1910         break;
1911       }
1912       /*FALLTHRU*/
1913     case 0:
1914       long_val = atol(argp);
1915       change = &l->lcp.cfg.mtu;
1916       if (long_val > l->lcp.cfg.max_mtu) {
1917         log_Printf(LogWARN, "MTU %ld: too large - max set to %d\n", long_val,
1918                    l->lcp.cfg.max_mtu);
1919         res = 1;
1920         break;
1921       }
1922       break;
1923     case 2:
1924       if (strcasecmp(argp, "max") && strcasecmp(argp, "maximum")) {
1925         res = -1;
1926         break;
1927       }
1928       long_val = atol(arg->argv[arg->argn + 1]);
1929       change = &l->lcp.cfg.max_mtu;
1930       if (long_val > MAX_MTU) {
1931         log_Printf(LogWARN, "MTU %ld: too large - maximum is %d\n", long_val,
1932                    MAX_MTU);
1933         res = 1;
1934         break;
1935       }
1936       break;
1937     default:
1938       res = -1;
1939       break;
1940     }
1941 
1942     if (res != 0)
1943       break;
1944 
1945     if (long_val && long_val < MIN_MTU) {
1946       log_Printf(LogWARN, "MTU %ld: too small - min %d\n", long_val, MIN_MTU);
1947       res = 1;
1948       break;
1949     } else if (long_val > MAX_MTU) {
1950       log_Printf(LogWARN, "MTU %ld: too big - max %d\n", long_val, MAX_MTU);
1951       res = 1;
1952       break;
1953     } else
1954       *change = long_val;
1955     if (l->lcp.cfg.mtu > *change)
1956       l->lcp.cfg.mtu = *change;
1957     break;
1958 
1959   case VAR_OPENMODE:
1960     if (strcasecmp(argp, "active") == 0)
1961       cx->physical->link.lcp.cfg.openmode = arg->argc > arg->argn+1 ?
1962         atoi(arg->argv[arg->argn+1]) : 1;
1963     else if (strcasecmp(argp, "passive") == 0)
1964       cx->physical->link.lcp.cfg.openmode = OPEN_PASSIVE;
1965     else {
1966       log_Printf(LogWARN, "%s: Invalid openmode\n", argp);
1967       res = 1;
1968     }
1969     break;
1970 
1971   case VAR_PHONE:
1972     strncpy(cx->cfg.phone.list, argp, sizeof cx->cfg.phone.list - 1);
1973     cx->cfg.phone.list[sizeof cx->cfg.phone.list - 1] = '\0';
1974     cx->phone.alt = cx->phone.next = NULL;
1975     break;
1976 
1977   case VAR_HANGUP:
1978     strncpy(cx->cfg.script.hangup, argp, sizeof cx->cfg.script.hangup - 1);
1979     cx->cfg.script.hangup[sizeof cx->cfg.script.hangup - 1] = '\0';
1980     break;
1981 
1982   case VAR_IFQUEUE:
1983     long_val = atol(argp);
1984     arg->bundle->cfg.ifqueue = long_val < 0 ? 0 : long_val;
1985     break;
1986 
1987   case VAR_LOGOUT:
1988     strncpy(cx->cfg.script.logout, argp, sizeof cx->cfg.script.logout - 1);
1989     cx->cfg.script.logout[sizeof cx->cfg.script.logout - 1] = '\0';
1990     break;
1991 
1992   case VAR_IDLETIMEOUT:
1993     if (arg->argc > arg->argn+2) {
1994       log_Printf(LogWARN, "Too many idle timeout values\n");
1995       res = 1;
1996     } else if (arg->argc == arg->argn) {
1997       log_Printf(LogWARN, "Too few idle timeout values\n");
1998       res = 1;
1999     } else {
2000       int timeout, min;
2001 
2002       timeout = atoi(argp);
2003       min = arg->argc == arg->argn + 2 ? atoi(arg->argv[arg->argn + 1]) : -1;
2004       bundle_SetIdleTimer(arg->bundle, timeout, min);
2005     }
2006     break;
2007 
2008   case VAR_LQRPERIOD:
2009     long_val = atol(argp);
2010     if (long_val < MIN_LQRPERIOD) {
2011       log_Printf(LogWARN, "%ld: Invalid lqr period - min %d\n",
2012                  long_val, MIN_LQRPERIOD);
2013       res = 1;
2014     } else
2015       l->lcp.cfg.lqrperiod = long_val;
2016     break;
2017 
2018   case VAR_LCPRETRY:
2019     res = SetRetry(arg->argc - arg->argn, arg->argv + arg->argn,
2020                    &cx->physical->link.lcp.cfg.fsm.timeout,
2021                    &cx->physical->link.lcp.cfg.fsm.maxreq,
2022                    &cx->physical->link.lcp.cfg.fsm.maxtrm, DEF_FSMTRIES);
2023     break;
2024 
2025   case VAR_CHAPRETRY:
2026     res = SetRetry(arg->argc - arg->argn, arg->argv + arg->argn,
2027                    &cx->chap.auth.cfg.fsm.timeout,
2028                    &cx->chap.auth.cfg.fsm.maxreq, NULL, DEF_FSMAUTHTRIES);
2029     break;
2030 
2031   case VAR_PAPRETRY:
2032     res = SetRetry(arg->argc - arg->argn, arg->argv + arg->argn,
2033                    &cx->pap.cfg.fsm.timeout, &cx->pap.cfg.fsm.maxreq,
2034                    NULL, DEF_FSMAUTHTRIES);
2035     break;
2036 
2037   case VAR_CCPRETRY:
2038     res = SetRetry(arg->argc - arg->argn, arg->argv + arg->argn,
2039                    &l->ccp.cfg.fsm.timeout, &l->ccp.cfg.fsm.maxreq,
2040                    &l->ccp.cfg.fsm.maxtrm, DEF_FSMTRIES);
2041     break;
2042 
2043   case VAR_IPCPRETRY:
2044     res = SetRetry(arg->argc - arg->argn, arg->argv + arg->argn,
2045                    &arg->bundle->ncp.ipcp.cfg.fsm.timeout,
2046                    &arg->bundle->ncp.ipcp.cfg.fsm.maxreq,
2047                    &arg->bundle->ncp.ipcp.cfg.fsm.maxtrm, DEF_FSMTRIES);
2048     break;
2049 
2050 #ifndef NOINET6
2051   case VAR_IPV6CPRETRY:
2052     res = SetRetry(arg->argc - arg->argn, arg->argv + arg->argn,
2053                    &arg->bundle->ncp.ipv6cp.cfg.fsm.timeout,
2054                    &arg->bundle->ncp.ipv6cp.cfg.fsm.maxreq,
2055                    &arg->bundle->ncp.ipv6cp.cfg.fsm.maxtrm, DEF_FSMTRIES);
2056     break;
2057 #endif
2058 
2059   case VAR_NBNS:
2060   case VAR_DNS:
2061     if (param == VAR_DNS) {
2062       ipaddr = arg->bundle->ncp.ipcp.cfg.ns.dns;
2063       ipaddr[0].s_addr = ipaddr[1].s_addr = INADDR_NONE;
2064     } else {
2065       ipaddr = arg->bundle->ncp.ipcp.cfg.ns.nbns;
2066       ipaddr[0].s_addr = ipaddr[1].s_addr = INADDR_ANY;
2067     }
2068 
2069     if (arg->argc > arg->argn) {
2070       ncpaddr_aton(ncpaddr, &arg->bundle->ncp, arg->argv[arg->argn]);
2071       if (!ncpaddr_getip4(ncpaddr, ipaddr))
2072         return -1;
2073       if (arg->argc > arg->argn+1) {
2074         ncpaddr_aton(ncpaddr + 1, &arg->bundle->ncp, arg->argv[arg->argn + 1]);
2075         if (!ncpaddr_getip4(ncpaddr + 1, ipaddr + 1))
2076           return -1;
2077       }
2078 
2079       if (ipaddr[0].s_addr == INADDR_ANY) {
2080         ipaddr[0] = ipaddr[1];
2081         ipaddr[1].s_addr = INADDR_ANY;
2082       }
2083       if (ipaddr[0].s_addr == INADDR_NONE) {
2084         ipaddr[0] = ipaddr[1];
2085         ipaddr[1].s_addr = INADDR_NONE;
2086       }
2087     }
2088     break;
2089 
2090   case VAR_CALLBACK:
2091     cx->cfg.callback.opmask = 0;
2092     for (dummyint = arg->argn; dummyint < arg->argc; dummyint++) {
2093       if (!strcasecmp(arg->argv[dummyint], "auth"))
2094         cx->cfg.callback.opmask |= CALLBACK_BIT(CALLBACK_AUTH);
2095       else if (!strcasecmp(arg->argv[dummyint], "cbcp"))
2096         cx->cfg.callback.opmask |= CALLBACK_BIT(CALLBACK_CBCP);
2097       else if (!strcasecmp(arg->argv[dummyint], "e.164")) {
2098         if (dummyint == arg->argc - 1)
2099           log_Printf(LogWARN, "No E.164 arg (E.164 ignored) !\n");
2100         else {
2101           cx->cfg.callback.opmask |= CALLBACK_BIT(CALLBACK_E164);
2102           strncpy(cx->cfg.callback.msg, arg->argv[++dummyint],
2103                   sizeof cx->cfg.callback.msg - 1);
2104           cx->cfg.callback.msg[sizeof cx->cfg.callback.msg - 1] = '\0';
2105         }
2106       } else if (!strcasecmp(arg->argv[dummyint], "none"))
2107         cx->cfg.callback.opmask |= CALLBACK_BIT(CALLBACK_NONE);
2108       else {
2109         res = -1;
2110         break;
2111       }
2112     }
2113     if (cx->cfg.callback.opmask == CALLBACK_BIT(CALLBACK_NONE))
2114       cx->cfg.callback.opmask = 0;
2115     break;
2116 
2117   case VAR_CBCP:
2118     cx->cfg.cbcp.delay = 0;
2119     *cx->cfg.cbcp.phone = '\0';
2120     cx->cfg.cbcp.fsmretry = DEF_FSMRETRY;
2121     if (arg->argc > arg->argn) {
2122       strncpy(cx->cfg.cbcp.phone, arg->argv[arg->argn],
2123               sizeof cx->cfg.cbcp.phone - 1);
2124       cx->cfg.cbcp.phone[sizeof cx->cfg.cbcp.phone - 1] = '\0';
2125       if (arg->argc > arg->argn + 1) {
2126         cx->cfg.cbcp.delay = atoi(arg->argv[arg->argn + 1]);
2127         if (arg->argc > arg->argn + 2) {
2128           long_val = atol(arg->argv[arg->argn + 2]);
2129           if (long_val < MIN_FSMRETRY)
2130             log_Printf(LogWARN, "%ld: Invalid CBCP FSM retry period - min %d\n",
2131                        long_val, MIN_FSMRETRY);
2132           else
2133             cx->cfg.cbcp.fsmretry = long_val;
2134         }
2135       }
2136     }
2137     break;
2138 
2139   case VAR_CHOKED:
2140     arg->bundle->cfg.choked.timeout = atoi(argp);
2141     if (arg->bundle->cfg.choked.timeout <= 0)
2142       arg->bundle->cfg.choked.timeout = CHOKED_TIMEOUT;
2143     break;
2144 
2145   case VAR_SENDPIPE:
2146     long_val = atol(argp);
2147     arg->bundle->ncp.cfg.sendpipe = long_val;
2148     break;
2149 
2150   case VAR_RECVPIPE:
2151     long_val = atol(argp);
2152     arg->bundle->ncp.cfg.recvpipe = long_val;
2153     break;
2154 
2155 #ifndef NORADIUS
2156   case VAR_RADIUS:
2157     if (!*argp)
2158       *arg->bundle->radius.cfg.file = '\0';
2159     else if (access(argp, R_OK)) {
2160       log_Printf(LogWARN, "%s: %s\n", argp, strerror(errno));
2161       res = 1;
2162       break;
2163     } else {
2164       strncpy(arg->bundle->radius.cfg.file, argp,
2165               sizeof arg->bundle->radius.cfg.file - 1);
2166       arg->bundle->radius.cfg.file
2167         [sizeof arg->bundle->radius.cfg.file - 1] = '\0';
2168     }
2169     break;
2170 #endif
2171 
2172   case VAR_CD:
2173     if (*argp) {
2174       if (strcasecmp(argp, "off")) {
2175         long_val = atol(argp);
2176         if (long_val < 0)
2177           long_val = 0;
2178         cx->physical->cfg.cd.delay = long_val;
2179         cx->physical->cfg.cd.necessity = argp[strlen(argp)-1] == '!' ?
2180           CD_REQUIRED : CD_VARIABLE;
2181       } else
2182         cx->physical->cfg.cd.necessity = CD_NOTREQUIRED;
2183     } else {
2184       cx->physical->cfg.cd.delay = 0;
2185       cx->physical->cfg.cd.necessity = CD_DEFAULT;
2186     }
2187     break;
2188 
2189   case VAR_PARITY:
2190     if (arg->argc == arg->argn + 1)
2191       res = physical_SetParity(arg->cx->physical, argp);
2192     else {
2193       log_Printf(LogWARN, "Parity value must be odd, even or none\n");
2194       res = 1;
2195     }
2196     break;
2197 
2198   case VAR_CRTSCTS:
2199     if (strcasecmp(argp, "on") == 0)
2200       physical_SetRtsCts(arg->cx->physical, 1);
2201     else if (strcasecmp(argp, "off") == 0)
2202       physical_SetRtsCts(arg->cx->physical, 0);
2203     else {
2204       log_Printf(LogWARN, "RTS/CTS value must be on or off\n");
2205       res = 1;
2206     }
2207     break;
2208 
2209   case VAR_URGENTPORTS:
2210     if (arg->argn == arg->argc) {
2211       ncp_SetUrgentTOS(&arg->bundle->ncp);
2212       ncp_ClearUrgentTcpPorts(&arg->bundle->ncp);
2213       ncp_ClearUrgentUdpPorts(&arg->bundle->ncp);
2214     } else if (!strcasecmp(arg->argv[arg->argn], "udp")) {
2215       ncp_SetUrgentTOS(&arg->bundle->ncp);
2216       if (arg->argn == arg->argc - 1)
2217         ncp_ClearUrgentUdpPorts(&arg->bundle->ncp);
2218       else for (f = arg->argn + 1; f < arg->argc; f++)
2219         if (*arg->argv[f] == '+')
2220           ncp_AddUrgentUdpPort(&arg->bundle->ncp, atoi(arg->argv[f] + 1));
2221         else if (*arg->argv[f] == '-')
2222           ncp_RemoveUrgentUdpPort(&arg->bundle->ncp, atoi(arg->argv[f] + 1));
2223         else {
2224           if (f == arg->argn)
2225             ncp_ClearUrgentUdpPorts(&arg->bundle->ncp);
2226           ncp_AddUrgentUdpPort(&arg->bundle->ncp, atoi(arg->argv[f]));
2227         }
2228     } else if (arg->argn == arg->argc - 1 &&
2229                !strcasecmp(arg->argv[arg->argn], "none")) {
2230       ncp_ClearUrgentTcpPorts(&arg->bundle->ncp);
2231       ncp_ClearUrgentUdpPorts(&arg->bundle->ncp);
2232       ncp_ClearUrgentTOS(&arg->bundle->ncp);
2233     } else {
2234       ncp_SetUrgentTOS(&arg->bundle->ncp);
2235       first = arg->argn;
2236       if (!strcasecmp(arg->argv[first], "tcp") && ++first == arg->argc)
2237         ncp_ClearUrgentTcpPorts(&arg->bundle->ncp);
2238 
2239       for (f = first; f < arg->argc; f++)
2240         if (*arg->argv[f] == '+')
2241           ncp_AddUrgentTcpPort(&arg->bundle->ncp, atoi(arg->argv[f] + 1));
2242         else if (*arg->argv[f] == '-')
2243           ncp_RemoveUrgentTcpPort(&arg->bundle->ncp, atoi(arg->argv[f] + 1));
2244         else {
2245           if (f == first)
2246             ncp_ClearUrgentTcpPorts(&arg->bundle->ncp);
2247           ncp_AddUrgentTcpPort(&arg->bundle->ncp, atoi(arg->argv[f]));
2248         }
2249     }
2250     break;
2251   }
2252 
2253   return res;
2254 }
2255 
2256 static struct cmdtab const SetCommands[] = {
2257   {"accmap", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2258   "accmap value", "set accmap hex-value", (const void *)VAR_ACCMAP},
2259   {"authkey", "key", SetVariable, LOCAL_AUTH,
2260   "authentication key", "set authkey|key key", (const void *)VAR_AUTHKEY},
2261   {"authname", NULL, SetVariable, LOCAL_AUTH,
2262   "authentication name", "set authname name", (const void *)VAR_AUTHNAME},
2263   {"autoload", NULL, SetVariable, LOCAL_AUTH,
2264   "auto link [de]activation", "set autoload maxtime maxload mintime minload",
2265   (const void *)VAR_AUTOLOAD},
2266   {"bandwidth", NULL, mp_SetDatalinkBandwidth, LOCAL_AUTH | LOCAL_CX,
2267   "datalink bandwidth", "set bandwidth value"},
2268   {"callback", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2269   "callback control", "set callback [none|auth|cbcp|"
2270   "E.164 *|number[,number]...]...", (const void *)VAR_CALLBACK},
2271   {"cbcp", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2272   "CBCP control", "set cbcp [*|phone[,phone...] [delay [timeout]]]",
2273   (const void *)VAR_CBCP},
2274   {"ccpretry", "ccpretries", SetVariable, LOCAL_AUTH | LOCAL_CX_OPT,
2275    "CCP retries", "set ccpretry value [attempts]", (const void *)VAR_CCPRETRY},
2276   {"cd", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX, "Carrier delay requirement",
2277    "set cd value[!]", (const void *)VAR_CD},
2278   {"chapretry", "chapretries", SetVariable, LOCAL_AUTH | LOCAL_CX,
2279    "CHAP retries", "set chapretry value [attempts]",
2280    (const void *)VAR_CHAPRETRY},
2281   {"choked", NULL, SetVariable, LOCAL_AUTH,
2282   "choked timeout", "set choked [secs]", (const void *)VAR_CHOKED},
2283   {"ctsrts", "crtscts", SetVariable, LOCAL_AUTH | LOCAL_CX,
2284    "Use hardware flow control", "set ctsrts [on|off]",
2285    (const char *)VAR_CRTSCTS},
2286   {"deflate", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX_OPT,
2287   "deflate window sizes", "set deflate out-winsize in-winsize",
2288   (const void *) VAR_WINSIZE},
2289 #ifndef NODES
2290   {"mppe", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX_OPT,
2291   "MPPE key size and state", "set mppe [40|56|128|* [stateful|stateless|*]]",
2292   (const void *) VAR_MPPE},
2293 #endif
2294   {"device", "line", SetVariable, LOCAL_AUTH | LOCAL_CX,
2295   "physical device name", "set device|line device-name[,device-name]",
2296   (const void *) VAR_DEVICE},
2297   {"dial", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2298   "dialing script", "set dial chat-script", (const void *) VAR_DIAL},
2299   {"dns", NULL, SetVariable, LOCAL_AUTH, "Domain Name Server",
2300   "set dns pri-addr [sec-addr]", (const void *)VAR_DNS},
2301   {"enddisc", NULL, mp_SetEnddisc, LOCAL_AUTH,
2302   "Endpoint Discriminator", "set enddisc [IP|magic|label|psn value]"},
2303   {"escape", NULL, SetEscape, LOCAL_AUTH | LOCAL_CX,
2304   "escape characters", "set escape hex-digit ..."},
2305   {"filter", NULL, filter_Set, LOCAL_AUTH,
2306   "packet filters", "set filter alive|dial|in|out rule-no permit|deny "
2307   "[src_addr[/width]] [dst_addr[/width]] [proto "
2308   "[src [lt|eq|gt port]] [dst [lt|eq|gt port]] [estab] [syn] [finrst]]"},
2309   {"hangup", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2310   "hangup script", "set hangup chat-script", (const void *) VAR_HANGUP},
2311   {"ifaddr", NULL, SetInterfaceAddr, LOCAL_AUTH, "destination address",
2312   "set ifaddr [src-addr [dst-addr [netmask [trg-addr]]]]"},
2313   {"ifqueue", NULL, SetVariable, LOCAL_AUTH, "interface queue",
2314   "set ifqueue packets", (const void *)VAR_IFQUEUE},
2315   {"ipcpretry", "ipcpretries", SetVariable, LOCAL_AUTH, "IPCP retries",
2316    "set ipcpretry value [attempts]", (const void *)VAR_IPCPRETRY},
2317   {"ipv6cpretry", "ipv6cpretries", SetVariable, LOCAL_AUTH, "IPV6CP retries",
2318    "set ipv6cpretry value [attempts]", (const void *)VAR_IPV6CPRETRY},
2319   {"lcpretry", "lcpretries", SetVariable, LOCAL_AUTH | LOCAL_CX, "LCP retries",
2320    "set lcpretry value [attempts]", (const void *)VAR_LCPRETRY},
2321   {"log", NULL, log_SetLevel, LOCAL_AUTH, "log level",
2322   "set log [local] [+|-]all|async|cbcp|ccp|chat|command|connect|debug|dns|hdlc|"
2323   "id0|ipcp|lcp|lqm|phase|physical|sync|tcp/ip|timer|tun..."},
2324   {"login", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2325   "login script", "set login chat-script", (const void *) VAR_LOGIN},
2326   {"logout", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2327   "logout script", "set logout chat-script", (const void *) VAR_LOGOUT},
2328   {"lqrperiod", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX_OPT,
2329   "LQR period", "set lqrperiod value", (const void *)VAR_LQRPERIOD},
2330   {"mode", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX, "mode value",
2331   "set mode interactive|auto|ddial|background", (const void *)VAR_MODE},
2332   {"mrru", NULL, SetVariable, LOCAL_AUTH, "MRRU value",
2333   "set mrru value", (const void *)VAR_MRRU},
2334   {"mru", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2335   "MRU value", "set mru [max[imum]] [value]", (const void *)VAR_MRU},
2336   {"mtu", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX,
2337   "interface MTU value", "set mtu [max[imum]] [value]", (const void *)VAR_MTU},
2338   {"nbns", NULL, SetVariable, LOCAL_AUTH, "NetBIOS Name Server",
2339   "set nbns pri-addr [sec-addr]", (const void *)VAR_NBNS},
2340   {"openmode", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX, "open mode",
2341   "set openmode active|passive [secs]", (const void *)VAR_OPENMODE},
2342   {"papretry", "papretries", SetVariable, LOCAL_AUTH | LOCAL_CX, "PAP retries",
2343    "set papretry value [attempts]", (const void *)VAR_PAPRETRY},
2344   {"parity", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX, "serial parity",
2345    "set parity [odd|even|none]", (const void *)VAR_PARITY},
2346   {"phone", NULL, SetVariable, LOCAL_AUTH | LOCAL_CX, "telephone number(s)",
2347   "set phone phone1[:phone2[...]]", (const void *)VAR_PHONE},
2348   {"proctitle", "title", SetProcTitle, LOCAL_AUTH,
2349   "Process title", "set proctitle [value]"},
2350 #ifndef NORADIUS
2351   {"radius", NULL, SetVariable, LOCAL_AUTH,
2352   "RADIUS Config", "set radius cfgfile", (const void *)VAR_RADIUS},
2353 #endif
2354   {"reconnect", NULL, datalink_SetReconnect, LOCAL_AUTH | LOCAL_CX,
2355   "Reconnect timeout", "set reconnect value ntries"},
2356   {"recvpipe", NULL, SetVariable, LOCAL_AUTH,
2357   "RECVPIPE value", "set recvpipe value", (const void *)VAR_RECVPIPE},
2358   {"redial", NULL, datalink_SetRedial, LOCAL_AUTH | LOCAL_CX,
2359   "Redial timeout", "set redial secs[+inc[-incmax]][.next] [attempts]"},
2360   {"sendpipe", NULL, SetVariable, LOCAL_AUTH,
2361   "SENDPIPE value", "set sendpipe value", (const void *)VAR_SENDPIPE},
2362   {"server", "socket", SetServer, LOCAL_AUTH, "diagnostic port",
2363   "set server|socket TcpPort|LocalName|none|open|closed [password [mask]]"},
2364   {"speed", NULL, SetModemSpeed, LOCAL_AUTH | LOCAL_CX,
2365   "physical speed", "set speed value|sync"},
2366   {"stopped", NULL, SetStoppedTimeout, LOCAL_AUTH | LOCAL_CX,
2367   "STOPPED timeouts", "set stopped [LCPseconds [CCPseconds]]"},
2368   {"timeout", NULL, SetVariable, LOCAL_AUTH, "Idle timeout",
2369   "set timeout idletime", (const void *)VAR_IDLETIMEOUT},
2370   {"urgent", NULL, SetVariable, LOCAL_AUTH, "urgent ports",
2371   "set urgent [tcp|udp] [+|-]port...", (const void *)VAR_URGENTPORTS},
2372   {"vj", NULL, ipcp_vjset, LOCAL_AUTH,
2373   "vj values", "set vj slots|slotcomp [value]"},
2374   {"help", "?", HelpCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
2375   "Display this message", "set help|? [command]", SetCommands},
2376   {NULL, NULL, NULL},
2377 };
2378 
2379 static int
2380 SetCommand(struct cmdargs const *arg)
2381 {
2382   if (arg->argc > arg->argn)
2383     FindExec(arg->bundle, SetCommands, arg->argc, arg->argn, arg->argv,
2384              arg->prompt, arg->cx);
2385   else if (arg->prompt)
2386     prompt_Printf(arg->prompt, "Use `set ?' to get a list or `set ? <var>' for"
2387 	          " syntax help.\n");
2388   else
2389     log_Printf(LogWARN, "set command must have arguments\n");
2390 
2391   return 0;
2392 }
2393 
2394 static int
2395 AddCommand(struct cmdargs const *arg)
2396 {
2397   struct ncpaddr gw;
2398   struct ncprange dest;
2399   struct in_addr host;
2400   int dest_default, gw_arg, addrs;
2401 
2402   if (arg->argc != arg->argn+3 && arg->argc != arg->argn+2)
2403     return -1;
2404 
2405   addrs = 0;
2406   dest_default = 0;
2407   if (arg->argc == arg->argn + 2) {
2408     if (!strcasecmp(arg->argv[arg->argn], "default"))
2409       dest_default = 1;
2410     else {
2411       if (!ncprange_aton(&dest, &arg->bundle->ncp, arg->argv[arg->argn]))
2412         return -1;
2413       if (!strncasecmp(arg->argv[arg->argn], "MYADDR", 6))
2414         addrs = ROUTE_DSTMYADDR;
2415       else if (!strncasecmp(arg->argv[arg->argn], "MYADDR6", 7))
2416         addrs = ROUTE_DSTMYADDR6;
2417       else if (!strncasecmp(arg->argv[arg->argn], "HISADDR", 7))
2418         addrs = ROUTE_DSTHISADDR;
2419       else if (!strncasecmp(arg->argv[arg->argn], "HISADDR6", 8))
2420         addrs = ROUTE_DSTHISADDR6;
2421       else if (!strncasecmp(arg->argv[arg->argn], "DNS0", 4))
2422         addrs = ROUTE_DSTDNS0;
2423       else if (!strncasecmp(arg->argv[arg->argn], "DNS1", 4))
2424         addrs = ROUTE_DSTDNS1;
2425     }
2426     gw_arg = 1;
2427   } else {
2428     if (strcasecmp(arg->argv[arg->argn], "MYADDR") == 0) {
2429       addrs = ROUTE_DSTMYADDR;
2430       host = arg->bundle->ncp.ipcp.my_ip;
2431     } else if (strcasecmp(arg->argv[arg->argn], "HISADDR") == 0) {
2432       addrs = ROUTE_DSTHISADDR;
2433       host = arg->bundle->ncp.ipcp.peer_ip;
2434     } else if (strcasecmp(arg->argv[arg->argn], "DNS0") == 0) {
2435       addrs = ROUTE_DSTDNS0;
2436       host = arg->bundle->ncp.ipcp.ns.dns[0];
2437     } else if (strcasecmp(arg->argv[arg->argn], "DNS1") == 0) {
2438       addrs = ROUTE_DSTDNS1;
2439       host = arg->bundle->ncp.ipcp.ns.dns[1];
2440     } else {
2441       host = GetIpAddr(arg->argv[arg->argn]);
2442       if (host.s_addr == INADDR_NONE) {
2443         log_Printf(LogWARN, "%s: Invalid destination address\n",
2444                    arg->argv[arg->argn]);
2445         return -1;
2446       }
2447     }
2448     ncprange_setip4(&dest, host, GetIpAddr(arg->argv[arg->argn + 1]));
2449     gw_arg = 2;
2450   }
2451 
2452   if (strcasecmp(arg->argv[arg->argn + gw_arg], "HISADDR") == 0) {
2453     ncpaddr_setip4(&gw, arg->bundle->ncp.ipcp.peer_ip);
2454     addrs |= ROUTE_GWHISADDR;
2455 #ifndef NOINET6
2456   } else if (strcasecmp(arg->argv[arg->argn + gw_arg], "HISADDR6") == 0) {
2457     ncpaddr_copy(&gw, &arg->bundle->ncp.ipv6cp.hisaddr);
2458     addrs |= ROUTE_GWHISADDR6;
2459 #endif
2460   } else {
2461     if (!ncpaddr_aton(&gw, &arg->bundle->ncp, arg->argv[arg->argn + gw_arg])) {
2462       log_Printf(LogWARN, "%s: Invalid gateway address\n",
2463                  arg->argv[arg->argn + gw_arg]);
2464       return -1;
2465     }
2466   }
2467 
2468   if (dest_default)
2469     ncprange_setdefault(&dest, ncpaddr_family(&gw));
2470 
2471   if (rt_Set(arg->bundle, RTM_ADD, &dest, &gw, arg->cmd->args ? 1 : 0,
2472              ((addrs & ROUTE_GWHISADDR) || (addrs & ROUTE_GWHISADDR6)) ? 1 : 0)
2473       && addrs != ROUTE_STATIC)
2474     route_Add(&arg->bundle->ncp.route, addrs, &dest, &gw);
2475 
2476   return 0;
2477 }
2478 
2479 static int
2480 DeleteCommand(struct cmdargs const *arg)
2481 {
2482   struct ncprange dest;
2483   int addrs;
2484 
2485   if (arg->argc == arg->argn+1) {
2486     if(strcasecmp(arg->argv[arg->argn], "all") == 0) {
2487       route_IfDelete(arg->bundle, 0);
2488       route_DeleteAll(&arg->bundle->ncp.route);
2489     } else {
2490       addrs = 0;
2491       if (strcasecmp(arg->argv[arg->argn], "MYADDR") == 0) {
2492         ncprange_setip4host(&dest, arg->bundle->ncp.ipcp.my_ip);
2493         addrs = ROUTE_DSTMYADDR;
2494 #ifndef NOINET6
2495       } else if (strcasecmp(arg->argv[arg->argn], "MYADDR6") == 0) {
2496         ncprange_sethost(&dest, &arg->bundle->ncp.ipv6cp.myaddr);
2497         addrs = ROUTE_DSTMYADDR6;
2498 #endif
2499       } else if (strcasecmp(arg->argv[arg->argn], "HISADDR") == 0) {
2500         ncprange_setip4host(&dest, arg->bundle->ncp.ipcp.peer_ip);
2501         addrs = ROUTE_DSTHISADDR;
2502 #ifndef NOINET6
2503       } else if (strcasecmp(arg->argv[arg->argn], "HISADDR6") == 0) {
2504         ncprange_sethost(&dest, &arg->bundle->ncp.ipv6cp.hisaddr);
2505         addrs = ROUTE_DSTHISADDR6;
2506 #endif
2507       } else if (strcasecmp(arg->argv[arg->argn], "DNS0") == 0) {
2508         ncprange_setip4host(&dest, arg->bundle->ncp.ipcp.ns.dns[0]);
2509         addrs = ROUTE_DSTDNS0;
2510       } else if (strcasecmp(arg->argv[arg->argn], "DNS1") == 0) {
2511         ncprange_setip4host(&dest, arg->bundle->ncp.ipcp.ns.dns[1]);
2512         addrs = ROUTE_DSTDNS1;
2513       } else {
2514         ncprange_aton(&dest, &arg->bundle->ncp, arg->argv[arg->argn]);
2515         addrs = ROUTE_STATIC;
2516       }
2517       rt_Set(arg->bundle, RTM_DELETE, &dest, NULL, arg->cmd->args ? 1 : 0, 0);
2518       route_Delete(&arg->bundle->ncp.route, addrs, &dest);
2519     }
2520   } else
2521     return -1;
2522 
2523   return 0;
2524 }
2525 
2526 #ifndef NONAT
2527 static int
2528 NatEnable(struct cmdargs const *arg)
2529 {
2530   if (arg->argc == arg->argn+1) {
2531     if (strcasecmp(arg->argv[arg->argn], "yes") == 0) {
2532       if (!arg->bundle->NatEnabled) {
2533         if (arg->bundle->ncp.ipcp.fsm.state == ST_OPENED)
2534           PacketAliasSetAddress(arg->bundle->ncp.ipcp.my_ip);
2535         arg->bundle->NatEnabled = 1;
2536       }
2537       return 0;
2538     } else if (strcasecmp(arg->argv[arg->argn], "no") == 0) {
2539       arg->bundle->NatEnabled = 0;
2540       arg->bundle->cfg.opt &= ~OPT_IFACEALIAS;
2541       /* Don't iface_Clear() - there may be manually configured addresses */
2542       return 0;
2543     }
2544   }
2545 
2546   return -1;
2547 }
2548 
2549 
2550 static int
2551 NatOption(struct cmdargs const *arg)
2552 {
2553   long param = (long)arg->cmd->args;
2554 
2555   if (arg->argc == arg->argn+1) {
2556     if (strcasecmp(arg->argv[arg->argn], "yes") == 0) {
2557       if (arg->bundle->NatEnabled) {
2558 	PacketAliasSetMode(param, param);
2559 	return 0;
2560       }
2561       log_Printf(LogWARN, "nat not enabled\n");
2562     } else if (strcmp(arg->argv[arg->argn], "no") == 0) {
2563       if (arg->bundle->NatEnabled) {
2564 	PacketAliasSetMode(0, param);
2565 	return 0;
2566       }
2567       log_Printf(LogWARN, "nat not enabled\n");
2568     }
2569   }
2570   return -1;
2571 }
2572 #endif /* #ifndef NONAT */
2573 
2574 static int
2575 LinkCommand(struct cmdargs const *arg)
2576 {
2577   if (arg->argc > arg->argn+1) {
2578     char namelist[LINE_LEN];
2579     struct datalink *cx;
2580     char *name;
2581     int result = 0;
2582 
2583     if (!strcmp(arg->argv[arg->argn], "*")) {
2584       struct datalink *dl;
2585 
2586       cx = arg->bundle->links;
2587       while (cx) {
2588         /* Watch it, the command could be a ``remove'' */
2589         dl = cx->next;
2590         FindExec(arg->bundle, Commands, arg->argc, arg->argn+1, arg->argv,
2591                  arg->prompt, cx);
2592         for (cx = arg->bundle->links; cx; cx = cx->next)
2593           if (cx == dl)
2594             break;		/* Pointer's still valid ! */
2595       }
2596     } else {
2597       strncpy(namelist, arg->argv[arg->argn], sizeof namelist - 1);
2598       namelist[sizeof namelist - 1] = '\0';
2599       for(name = strtok(namelist, ", "); name; name = strtok(NULL,", "))
2600         if (!bundle2datalink(arg->bundle, name)) {
2601           log_Printf(LogWARN, "link: %s: Invalid link name\n", name);
2602           return 1;
2603         }
2604 
2605       strncpy(namelist, arg->argv[arg->argn], sizeof namelist - 1);
2606       namelist[sizeof namelist - 1] = '\0';
2607       for(name = strtok(namelist, ", "); name; name = strtok(NULL,", ")) {
2608         cx = bundle2datalink(arg->bundle, name);
2609         if (cx)
2610           FindExec(arg->bundle, Commands, arg->argc, arg->argn+1, arg->argv,
2611                    arg->prompt, cx);
2612         else {
2613           log_Printf(LogWARN, "link: %s: Invalidated link name !\n", name);
2614           result++;
2615         }
2616       }
2617     }
2618     return result;
2619   }
2620 
2621   log_Printf(LogWARN, "usage: %s\n", arg->cmd->syntax);
2622   return 2;
2623 }
2624 
2625 struct link *
2626 command_ChooseLink(struct cmdargs const *arg)
2627 {
2628   if (arg->cx)
2629     return &arg->cx->physical->link;
2630   else if (!arg->bundle->ncp.mp.cfg.mrru) {
2631     struct datalink *dl = bundle2datalink(arg->bundle, NULL);
2632     if (dl)
2633       return &dl->physical->link;
2634   }
2635   return &arg->bundle->ncp.mp.link;
2636 }
2637 
2638 static const char *
2639 ident_cmd(const char *cmd, unsigned *keep, unsigned *add)
2640 {
2641   const char *result;
2642 
2643   switch (*cmd) {
2644     case 'A':
2645     case 'a':
2646       result = "accept";
2647       *keep = NEG_MYMASK;
2648       *add = NEG_ACCEPTED;
2649       break;
2650     case 'D':
2651     case 'd':
2652       switch (cmd[1]) {
2653         case 'E':
2654         case 'e':
2655           result = "deny";
2656           *keep = NEG_MYMASK;
2657           *add = 0;
2658           break;
2659         case 'I':
2660         case 'i':
2661           result = "disable";
2662           *keep = NEG_HISMASK;
2663           *add = 0;
2664           break;
2665         default:
2666           return NULL;
2667       }
2668       break;
2669     case 'E':
2670     case 'e':
2671       result = "enable";
2672       *keep = NEG_HISMASK;
2673       *add = NEG_ENABLED;
2674       break;
2675     default:
2676       return NULL;
2677   }
2678 
2679   return result;
2680 }
2681 
2682 static int
2683 OptSet(struct cmdargs const *arg)
2684 {
2685   int bit = (int)(long)arg->cmd->args;
2686   unsigned keep;			/* Keep these bits */
2687   unsigned add;				/* Add these bits */
2688 
2689   if (ident_cmd(arg->argv[arg->argn - 2], &keep, &add) == NULL)
2690     return 1;
2691 
2692 #ifndef NOINET6
2693   if (add == NEG_ENABLED && bit == OPT_IPV6CP && !probe.ipv6_available) {
2694     log_Printf(LogWARN, "IPv6 is not available on this machine\n");
2695     return 1;
2696   }
2697 #endif
2698 
2699   if (add)
2700     arg->bundle->cfg.opt |= bit;
2701   else
2702     arg->bundle->cfg.opt &= ~bit;
2703 
2704   return 0;
2705 }
2706 
2707 static int
2708 IfaceAliasOptSet(struct cmdargs const *arg)
2709 {
2710   unsigned save = arg->bundle->cfg.opt;
2711   int result = OptSet(arg);
2712 
2713   if (result == 0)
2714     if (Enabled(arg->bundle, OPT_IFACEALIAS) && !arg->bundle->NatEnabled) {
2715       arg->bundle->cfg.opt = save;
2716       log_Printf(LogWARN, "Cannot enable iface-alias without NAT\n");
2717       result = 2;
2718     }
2719 
2720   return result;
2721 }
2722 
2723 static int
2724 NegotiateSet(struct cmdargs const *arg)
2725 {
2726   long param = (long)arg->cmd->args;
2727   struct link *l = command_ChooseLink(arg);	/* LOCAL_CX_OPT uses this */
2728   struct datalink *cx = arg->cx;	/* LOCAL_CX uses this */
2729   const char *cmd;
2730   unsigned keep;			/* Keep these bits */
2731   unsigned add;				/* Add these bits */
2732 
2733   if ((cmd = ident_cmd(arg->argv[arg->argn-2], &keep, &add)) == NULL)
2734     return 1;
2735 
2736   if ((arg->cmd->lauth & LOCAL_CX) && !cx) {
2737     log_Printf(LogWARN, "%s %s: No context (use the `link' command)\n",
2738               cmd, arg->cmd->name);
2739     return 2;
2740   } else if (cx && !(arg->cmd->lauth & (LOCAL_CX|LOCAL_CX_OPT))) {
2741     log_Printf(LogWARN, "%s %s: Redundant context (%s) ignored\n",
2742               cmd, arg->cmd->name, cx->name);
2743     cx = NULL;
2744   }
2745 
2746   switch (param) {
2747     case NEG_ACFCOMP:
2748       cx->physical->link.lcp.cfg.acfcomp &= keep;
2749       cx->physical->link.lcp.cfg.acfcomp |= add;
2750       break;
2751     case NEG_CHAP05:
2752       cx->physical->link.lcp.cfg.chap05 &= keep;
2753       cx->physical->link.lcp.cfg.chap05 |= add;
2754       break;
2755 #ifndef NODES
2756     case NEG_CHAP80:
2757       cx->physical->link.lcp.cfg.chap80nt &= keep;
2758       cx->physical->link.lcp.cfg.chap80nt |= add;
2759       break;
2760     case NEG_CHAP80LM:
2761       cx->physical->link.lcp.cfg.chap80lm &= keep;
2762       cx->physical->link.lcp.cfg.chap80lm |= add;
2763       break;
2764     case NEG_CHAP81:
2765       cx->physical->link.lcp.cfg.chap81 &= keep;
2766       cx->physical->link.lcp.cfg.chap81 |= add;
2767       break;
2768     case NEG_MPPE:
2769       l->ccp.cfg.neg[CCP_NEG_MPPE] &= keep;
2770       l->ccp.cfg.neg[CCP_NEG_MPPE] |= add;
2771       break;
2772 #endif
2773     case NEG_DEFLATE:
2774       l->ccp.cfg.neg[CCP_NEG_DEFLATE] &= keep;
2775       l->ccp.cfg.neg[CCP_NEG_DEFLATE] |= add;
2776       break;
2777     case NEG_DNS:
2778       arg->bundle->ncp.ipcp.cfg.ns.dns_neg &= keep;
2779       arg->bundle->ncp.ipcp.cfg.ns.dns_neg |= add;
2780       break;
2781     case NEG_ENDDISC:
2782       arg->bundle->ncp.mp.cfg.negenddisc &= keep;
2783       arg->bundle->ncp.mp.cfg.negenddisc |= add;
2784       break;
2785     case NEG_LQR:
2786       cx->physical->link.lcp.cfg.lqr &= keep;
2787       cx->physical->link.lcp.cfg.lqr |= add;
2788       break;
2789     case NEG_PAP:
2790       cx->physical->link.lcp.cfg.pap &= keep;
2791       cx->physical->link.lcp.cfg.pap |= add;
2792       break;
2793     case NEG_PPPDDEFLATE:
2794       l->ccp.cfg.neg[CCP_NEG_DEFLATE24] &= keep;
2795       l->ccp.cfg.neg[CCP_NEG_DEFLATE24] |= add;
2796       break;
2797     case NEG_PRED1:
2798       l->ccp.cfg.neg[CCP_NEG_PRED1] &= keep;
2799       l->ccp.cfg.neg[CCP_NEG_PRED1] |= add;
2800       break;
2801     case NEG_PROTOCOMP:
2802       cx->physical->link.lcp.cfg.protocomp &= keep;
2803       cx->physical->link.lcp.cfg.protocomp |= add;
2804       break;
2805     case NEG_SHORTSEQ:
2806       switch (bundle_Phase(arg->bundle)) {
2807         case PHASE_DEAD:
2808           break;
2809         case PHASE_ESTABLISH:
2810           /* Make sure none of our links are DATALINK_LCP or greater */
2811           if (bundle_HighestState(arg->bundle) >= DATALINK_LCP) {
2812             log_Printf(LogWARN, "shortseq: Only changable before"
2813                        " LCP negotiations\n");
2814             return 1;
2815           }
2816           break;
2817         default:
2818           log_Printf(LogWARN, "shortseq: Only changable at phase"
2819                      " DEAD/ESTABLISH\n");
2820           return 1;
2821       }
2822       arg->bundle->ncp.mp.cfg.shortseq &= keep;
2823       arg->bundle->ncp.mp.cfg.shortseq |= add;
2824       break;
2825     case NEG_VJCOMP:
2826       arg->bundle->ncp.ipcp.cfg.vj.neg &= keep;
2827       arg->bundle->ncp.ipcp.cfg.vj.neg |= add;
2828       break;
2829   }
2830 
2831   return 0;
2832 }
2833 
2834 static struct cmdtab const NegotiateCommands[] = {
2835   {"filter-decapsulation", NULL, OptSet, LOCAL_AUTH,
2836   "filter on PPPoUDP payloads", "disable|enable",
2837   (const void *)OPT_FILTERDECAP},
2838   {"idcheck", NULL, OptSet, LOCAL_AUTH, "Check FSM reply ids",
2839   "disable|enable", (const void *)OPT_IDCHECK},
2840   {"iface-alias", NULL, IfaceAliasOptSet, LOCAL_AUTH,
2841   "retain interface addresses", "disable|enable",
2842   (const void *)OPT_IFACEALIAS},
2843 #ifndef NOINET6
2844   {"ipcp", NULL, OptSet, LOCAL_AUTH, "IP Network Control Protocol",
2845   "disable|enable", (const void *)OPT_IPCP},
2846   {"ipv6cp", NULL, OptSet, LOCAL_AUTH, "IPv6 Network Control Protocol",
2847   "disable|enable", (const void *)OPT_IPV6CP},
2848 #endif
2849   {"keep-session", NULL, OptSet, LOCAL_AUTH, "Retain device session leader",
2850   "disable|enable", (const void *)OPT_KEEPSESSION},
2851   {"loopback", NULL, OptSet, LOCAL_AUTH, "Loop packets for local iface",
2852   "disable|enable", (const void *)OPT_LOOPBACK},
2853   {"passwdauth", NULL, OptSet, LOCAL_AUTH, "Use passwd file",
2854   "disable|enable", (const void *)OPT_PASSWDAUTH},
2855   {"proxy", NULL, OptSet, LOCAL_AUTH, "Create a proxy ARP entry",
2856   "disable|enable", (const void *)OPT_PROXY},
2857   {"proxyall", NULL, OptSet, LOCAL_AUTH, "Proxy ARP for all remote hosts",
2858   "disable|enable", (const void *)OPT_PROXYALL},
2859   {"sroutes", NULL, OptSet, LOCAL_AUTH, "Use sticky routes",
2860   "disable|enable", (const void *)OPT_SROUTES},
2861   {"tcpmssfixup", "mssfixup", OptSet, LOCAL_AUTH, "Modify MSS options",
2862   "disable|enable", (const void *)OPT_TCPMSSFIXUP},
2863   {"throughput", NULL, OptSet, LOCAL_AUTH, "Rolling throughput",
2864   "disable|enable", (const void *)OPT_THROUGHPUT},
2865   {"utmp", NULL, OptSet, LOCAL_AUTH, "Log connections in utmp",
2866   "disable|enable", (const void *)OPT_UTMP},
2867 
2868 #ifndef NOINET6
2869 #define OPT_MAX 13	/* accept/deny allowed below and not above */
2870 #else
2871 #define OPT_MAX 11
2872 #endif
2873 
2874   {"acfcomp", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2875   "Address & Control field compression", "accept|deny|disable|enable",
2876   (const void *)NEG_ACFCOMP},
2877   {"chap", "chap05", NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2878   "Challenge Handshake Authentication Protocol", "accept|deny|disable|enable",
2879   (const void *)NEG_CHAP05},
2880 #ifndef NODES
2881   {"mschap", "chap80nt", NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2882   "Microsoft (NT) CHAP", "accept|deny|disable|enable",
2883   (const void *)NEG_CHAP80},
2884   {"LANMan", "chap80lm", NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2885   "Microsoft (NT) CHAP", "accept|deny|disable|enable",
2886   (const void *)NEG_CHAP80LM},
2887   {"mschapv2", "chap81", NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2888   "Microsoft CHAP v2", "accept|deny|disable|enable",
2889   (const void *)NEG_CHAP81},
2890   {"mppe", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX_OPT,
2891   "MPPE encryption", "accept|deny|disable|enable",
2892   (const void *)NEG_MPPE},
2893 #endif
2894   {"deflate", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX_OPT,
2895   "Deflate compression", "accept|deny|disable|enable",
2896   (const void *)NEG_DEFLATE},
2897   {"deflate24", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX_OPT,
2898   "Deflate (type 24) compression", "accept|deny|disable|enable",
2899   (const void *)NEG_PPPDDEFLATE},
2900   {"dns", NULL, NegotiateSet, LOCAL_AUTH,
2901   "DNS specification", "accept|deny|disable|enable", (const void *)NEG_DNS},
2902   {"enddisc", NULL, NegotiateSet, LOCAL_AUTH, "ENDDISC negotiation",
2903   "accept|deny|disable|enable", (const void *)NEG_ENDDISC},
2904   {"lqr", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2905   "Link Quality Reports", "accept|deny|disable|enable",
2906   (const void *)NEG_LQR},
2907   {"pap", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2908   "Password Authentication protocol", "accept|deny|disable|enable",
2909   (const void *)NEG_PAP},
2910   {"pred1", "predictor1", NegotiateSet, LOCAL_AUTH | LOCAL_CX_OPT,
2911   "Predictor 1 compression", "accept|deny|disable|enable",
2912   (const void *)NEG_PRED1},
2913   {"protocomp", NULL, NegotiateSet, LOCAL_AUTH | LOCAL_CX,
2914   "Protocol field compression", "accept|deny|disable|enable",
2915   (const void *)NEG_PROTOCOMP},
2916   {"shortseq", NULL, NegotiateSet, LOCAL_AUTH,
2917   "MP Short Sequence Numbers", "accept|deny|disable|enable",
2918   (const void *)NEG_SHORTSEQ},
2919   {"vjcomp", NULL, NegotiateSet, LOCAL_AUTH,
2920   "Van Jacobson header compression", "accept|deny|disable|enable",
2921   (const void *)NEG_VJCOMP},
2922   {"help", "?", HelpCommand, LOCAL_AUTH | LOCAL_NO_AUTH,
2923   "Display this message", "accept|deny|disable|enable help|? [value]",
2924   NegotiateCommands},
2925   {NULL, NULL, NULL},
2926 };
2927 
2928 static int
2929 NegotiateCommand(struct cmdargs const *arg)
2930 {
2931   if (arg->argc > arg->argn) {
2932     char const *argv[3];
2933     unsigned keep, add;
2934     int n;
2935 
2936     if ((argv[0] = ident_cmd(arg->argv[arg->argn-1], &keep, &add)) == NULL)
2937       return -1;
2938     argv[2] = NULL;
2939 
2940     for (n = arg->argn; n < arg->argc; n++) {
2941       argv[1] = arg->argv[n];
2942       FindExec(arg->bundle, NegotiateCommands + (keep == NEG_HISMASK ?
2943                0 : OPT_MAX), 2, 1, argv, arg->prompt, arg->cx);
2944     }
2945   } else if (arg->prompt)
2946     prompt_Printf(arg->prompt, "Use `%s ?' to get a list.\n",
2947 	    arg->argv[arg->argn-1]);
2948   else
2949     log_Printf(LogWARN, "%s command must have arguments\n",
2950               arg->argv[arg->argn] );
2951 
2952   return 0;
2953 }
2954 
2955 const char *
2956 command_ShowNegval(unsigned val)
2957 {
2958   switch (val&3) {
2959     case 1: return "disabled & accepted";
2960     case 2: return "enabled & denied";
2961     case 3: return "enabled & accepted";
2962   }
2963   return "disabled & denied";
2964 }
2965 
2966 static int
2967 ClearCommand(struct cmdargs const *arg)
2968 {
2969   struct pppThroughput *t;
2970   struct datalink *cx;
2971   int i, clear_type;
2972 
2973   if (arg->argc < arg->argn + 1)
2974     return -1;
2975 
2976   if (strcasecmp(arg->argv[arg->argn], "physical") == 0) {
2977     cx = arg->cx;
2978     if (!cx)
2979       cx = bundle2datalink(arg->bundle, NULL);
2980     if (!cx) {
2981       log_Printf(LogWARN, "A link must be specified for ``clear physical''\n");
2982       return 1;
2983     }
2984     t = &cx->physical->link.stats.total;
2985   } else if (strcasecmp(arg->argv[arg->argn], "ipcp") == 0)
2986     t = &arg->bundle->ncp.ipcp.throughput;
2987 #ifndef NOINET6
2988   else if (strcasecmp(arg->argv[arg->argn], "ipv6cp") == 0)
2989     t = &arg->bundle->ncp.ipv6cp.throughput;
2990 #endif
2991   else
2992     return -1;
2993 
2994   if (arg->argc > arg->argn + 1) {
2995     clear_type = 0;
2996     for (i = arg->argn + 1; i < arg->argc; i++)
2997       if (strcasecmp(arg->argv[i], "overall") == 0)
2998         clear_type |= THROUGHPUT_OVERALL;
2999       else if (strcasecmp(arg->argv[i], "current") == 0)
3000         clear_type |= THROUGHPUT_CURRENT;
3001       else if (strcasecmp(arg->argv[i], "peak") == 0)
3002         clear_type |= THROUGHPUT_PEAK;
3003       else
3004         return -1;
3005   } else
3006     clear_type = THROUGHPUT_ALL;
3007 
3008   throughput_clear(t, clear_type, arg->prompt);
3009   return 0;
3010 }
3011 
3012 static int
3013 RunListCommand(struct cmdargs const *arg)
3014 {
3015   const char *cmd = arg->argc ? arg->argv[arg->argc - 1] : "???";
3016 
3017 #ifndef NONAT
3018   if (arg->cmd->args == NatCommands &&
3019       tolower(*arg->argv[arg->argn - 1]) == 'a') {
3020     if (arg->prompt)
3021       prompt_Printf(arg->prompt, "The alias command is deprecated\n");
3022     else
3023       log_Printf(LogWARN, "The alias command is deprecated\n");
3024   }
3025 #endif
3026 
3027   if (arg->argc > arg->argn)
3028     FindExec(arg->bundle, arg->cmd->args, arg->argc, arg->argn, arg->argv,
3029              arg->prompt, arg->cx);
3030   else if (arg->prompt)
3031     prompt_Printf(arg->prompt, "Use `%s help' to get a list or `%s help"
3032                   " <option>' for syntax help.\n", cmd, cmd);
3033   else
3034     log_Printf(LogWARN, "%s command must have arguments\n", cmd);
3035 
3036   return 0;
3037 }
3038 
3039 static int
3040 IfaceAddCommand(struct cmdargs const *arg)
3041 {
3042   struct ncpaddr peer, addr;
3043   struct ncprange ifa;
3044   struct in_addr mask;
3045   int n, how;
3046 
3047   if (arg->argc == arg->argn + 1) {
3048     if (!ncprange_aton(&ifa, NULL, arg->argv[arg->argn]))
3049       return -1;
3050     ncpaddr_init(&peer);
3051   } else {
3052     if (arg->argc == arg->argn + 2) {
3053       if (!ncprange_aton(&ifa, NULL, arg->argv[arg->argn]))
3054         return -1;
3055       n = 1;
3056     } else if (arg->argc == arg->argn + 3) {
3057       if (!ncpaddr_aton(&addr, NULL, arg->argv[arg->argn]))
3058         return -1;
3059       if (ncpaddr_family(&addr) != AF_INET)
3060         return -1;
3061       ncprange_sethost(&ifa, &addr);
3062       if (!ncpaddr_aton(&addr, NULL, arg->argv[arg->argn + 1]))
3063         return -1;
3064       if (!ncpaddr_getip4(&addr, &mask))
3065         return -1;
3066       if (!ncprange_setip4mask(&ifa, mask))
3067         return -1;
3068       n = 2;
3069     } else
3070       return -1;
3071 
3072     if (!ncpaddr_aton(&peer, NULL, arg->argv[arg->argn + n]))
3073       return -1;
3074 
3075     if (ncprange_family(&ifa) != ncpaddr_family(&peer)) {
3076       log_Printf(LogWARN, "IfaceAddCommand: src and dst address families"
3077                  " differ\n");
3078       return -1;
3079     }
3080   }
3081 
3082   how = IFACE_ADD_LAST;
3083   if (arg->cmd->args)
3084     how |= IFACE_FORCE_ADD;
3085 
3086   return !iface_Add(arg->bundle->iface, &arg->bundle->ncp, &ifa, &peer, how);
3087 }
3088 
3089 static int
3090 IfaceDeleteCommand(struct cmdargs const *arg)
3091 {
3092   struct ncpaddr ifa;
3093   struct in_addr ifa4;
3094   int ok;
3095 
3096   if (arg->argc != arg->argn + 1)
3097     return -1;
3098 
3099   if (!ncpaddr_aton(&ifa, NULL, arg->argv[arg->argn]))
3100     return -1;
3101 
3102   if (arg->bundle->ncp.ipcp.fsm.state == ST_OPENED &&
3103       ncpaddr_getip4(&ifa, &ifa4) &&
3104       arg->bundle->ncp.ipcp.my_ip.s_addr == ifa4.s_addr) {
3105     log_Printf(LogWARN, "%s: Cannot remove active interface address\n",
3106                ncpaddr_ntoa(&ifa));
3107     return 1;
3108   }
3109 
3110   ok = iface_Delete(arg->bundle->iface, &arg->bundle->ncp, &ifa);
3111   if (!ok) {
3112     if (arg->cmd->args)
3113       ok = 1;
3114     else if (arg->prompt)
3115       prompt_Printf(arg->prompt, "%s: No such interface address\n",
3116                     ncpaddr_ntoa(&ifa));
3117     else
3118       log_Printf(LogWARN, "%s: No such interface address\n",
3119                  ncpaddr_ntoa(&ifa));
3120   }
3121 
3122   return !ok;
3123 }
3124 
3125 static int
3126 IfaceClearCommand(struct cmdargs const *arg)
3127 {
3128   int family, how;
3129 
3130   family = 0;
3131   if (arg->argc == arg->argn + 1) {
3132     if (strcasecmp(arg->argv[arg->argn], "inet") == 0)
3133       family = AF_INET;
3134 #ifndef NOINET6
3135     else if (strcasecmp(arg->argv[arg->argn], "inet6") == 0)
3136       family = AF_INET6;
3137 #endif
3138     else
3139       return -1;
3140   } else if (arg->argc != arg->argn)
3141     return -1;
3142 
3143   how = arg->bundle->ncp.ipcp.fsm.state == ST_OPENED ||
3144         arg->bundle->phys_type.all & PHYS_AUTO ?
3145         IFACE_CLEAR_ALIASES : IFACE_CLEAR_ALL;
3146   iface_Clear(arg->bundle->iface, &arg->bundle->ncp, family, how);
3147 
3148   return 0;
3149 }
3150 
3151 static int
3152 SetProcTitle(struct cmdargs const *arg)
3153 {
3154   static char title[LINE_LEN];
3155   char *argv[MAXARGS];
3156   int argc = arg->argc - arg->argn;
3157 
3158   if (arg->argc == arg->argn) {
3159     SetTitle(NULL);
3160     return 0;
3161   }
3162 
3163   if (argc >= sizeof argv / sizeof argv[0]) {
3164     argc = sizeof argv / sizeof argv[0] - 1;
3165     log_Printf(LogWARN, "Truncating proc title to %d args\n", argc);
3166   }
3167   command_Expand(argv, argc, arg->argv + arg->argn, arg->bundle, 1, getpid());
3168   Concatinate(title, sizeof title, argc, (const char *const *)argv);
3169   SetTitle(title);
3170   command_Free(argc, argv);
3171 
3172   return 0;
3173 }
3174