DHCPv4: send DHCPNAK if requested addr != leased addr
[project/odhcpd.git] / src / dhcpv6.c
index 8f8f435..c2bb1c1 100644 (file)
@@ -84,12 +84,10 @@ int setup_dhcpv6_interface(struct interface *iface, bool enable)
 
                struct ipv6_mreq relay = {ALL_DHCPV6_RELAYS, iface->ifindex};
                struct ipv6_mreq server = {ALL_DHCPV6_SERVERS, iface->ifindex};
-               setsockopt(iface->dhcpv6_event.uloop.fd, IPPROTO_IPV6,
-                               IPV6_ADD_MEMBERSHIP, &relay, sizeof(relay));
+               setsockopt(sock, IPPROTO_IPV6, IPV6_ADD_MEMBERSHIP, &relay, sizeof(relay));
 
                if (iface->dhcpv6 == RELAYD_SERVER)
-                       setsockopt(iface->dhcpv6_event.uloop.fd, IPPROTO_IPV6,
-                                       IPV6_ADD_MEMBERSHIP, &server, sizeof(server));
+                       setsockopt(sock, IPPROTO_IPV6, IPV6_ADD_MEMBERSHIP, &server, sizeof(server));
 
                iface->dhcpv6_event.uloop.fd = sock;
                iface->dhcpv6_event.handle_dgram = handle_dhcpv6;
@@ -99,21 +97,35 @@ int setup_dhcpv6_interface(struct interface *iface, bool enable)
        return setup_dhcpv6_ia_interface(iface, enable);
 }
 
+enum {
+       IOV_NESTED = 0,
+       IOV_DEST,
+       IOV_DNS,
+       IOV_DNS_ADDR,
+       IOV_SEARCH,
+       IOV_SEARCH_DOMAIN,
+       IOV_PDBUF,
+#define        IOV_REFRESH IOV_PDBUF
+       IOV_CERID,
+       IOV_DHCPV6_RAW,
+       IOV_RELAY_MSG,
+       IOV_TOTAL
+};
 
 static void handle_nested_message(uint8_t *data, size_t len,
-               uint8_t **opts, uint8_t **end, struct iovec iov[6])
+               uint8_t **opts, uint8_t **end, struct iovec iov[IOV_TOTAL - 1])
 {
        struct dhcpv6_relay_header *hdr = (struct dhcpv6_relay_header*)data;
-       if (iov[0].iov_base == NULL) {
-               iov[0].iov_base = data;
-               iov[0].iov_len = len;
+       if (iov[IOV_NESTED].iov_base == NULL) {
+               iov[IOV_NESTED].iov_base = data;
+               iov[IOV_NESTED].iov_len = len;
        }
 
        if (len < sizeof(struct dhcpv6_client_header))
                return;
 
        if (hdr->msg_type != DHCPV6_MSG_RELAY_FORW) {
-               iov[0].iov_len = data - (uint8_t*)iov[0].iov_base;
+               iov[IOV_NESTED].iov_len = data - (uint8_t*)iov[IOV_NESTED].iov_base;
                struct dhcpv6_client_header *hdr = (void*)data;
                *opts = (uint8_t*)&hdr[1];
                *end = data + len;
@@ -124,9 +136,9 @@ static void handle_nested_message(uint8_t *data, size_t len,
        uint8_t *odata;
        dhcpv6_for_each_option(hdr->options, data + len, otype, olen, odata) {
                if (otype == DHCPV6_OPT_RELAY_MSG) {
-                       iov[7].iov_base = odata + olen;
-                       iov[7].iov_len = (((uint8_t*)iov[0].iov_base) + iov[0].iov_len)
-                                       - (odata + olen);
+                       iov[IOV_RELAY_MSG].iov_base = odata + olen;
+                       iov[IOV_RELAY_MSG].iov_len = (((uint8_t*)iov[IOV_NESTED].iov_base) + 
+                                       iov[IOV_NESTED].iov_len) - (odata + olen);
                        handle_nested_message(odata, olen, opts, end, iov);
                        return;
                }
@@ -175,6 +187,9 @@ static void handle_client_request(void *addr, void *data, size_t len,
                uint16_t duid_type;
                uint16_t hardware_type;
                uint8_t mac[6];
+               uint16_t solmaxrt_type;
+               uint16_t solmaxrt_length;
+               uint32_t solmaxrt_value;
                uint16_t clientid_type;
                uint16_t clientid_length;
                uint8_t clientid_buf[130];
@@ -184,6 +199,9 @@ static void handle_client_request(void *addr, void *data, size_t len,
                .serverid_length = htons(10),
                .duid_type = htons(3),
                .hardware_type = htons(1),
+               .solmaxrt_type = htons(DHCPV6_OPT_SOL_MAX_RT),
+               .solmaxrt_length = htons(4),
+               .solmaxrt_value = htonl(60),
                .clientid_type = htons(DHCPV6_OPT_CLIENTID),
                .clientid_buf = {0}
        };
@@ -238,16 +256,28 @@ static void handle_client_request(void *addr, void *data, size_t len,
        } search = {htons(DHCPV6_OPT_DNS_DOMAIN), htons(search_len)};
 
 
+       struct dhcpv6_cer_id cerid = {
+#ifdef EXT_CER_ID
+               .type = htons(EXT_CER_ID),
+#endif
+               .len = htons(36),
+               .addr = iface->dhcpv6_pd_cer,
+       };
+
 
        uint8_t pdbuf[512];
-       struct iovec iov[] = {{NULL, 0},
-                       {&dest, (uint8_t*)&dest.clientid_type - (uint8_t*)&dest},
-                       {&dns, (dns_cnt) ? sizeof(dns) : 0},
-                       {dns_addr, dns_cnt * sizeof(*dns_addr)},
-                       {&search, (search_len) ? sizeof(search) : 0},
-                       {search_domain, search_len},
-                       {pdbuf, 0},
-                       {NULL, 0}};
+       struct iovec iov[IOV_TOTAL] = {
+               [IOV_NESTED] = {NULL, 0},
+               [IOV_DEST] = {&dest, (uint8_t*)&dest.clientid_type - (uint8_t*)&dest},
+               [IOV_DNS] = {&dns, (dns_cnt) ? sizeof(dns) : 0},
+               [IOV_DNS_ADDR] = {dns_addr, dns_cnt * sizeof(*dns_addr)},
+               [IOV_SEARCH] = {&search, (search_len) ? sizeof(search) : 0},
+               [IOV_SEARCH_DOMAIN] = {search_domain, search_len},
+               [IOV_PDBUF] = {pdbuf, 0},
+               [IOV_CERID] = {&cerid, 0},
+               [IOV_DHCPV6_RAW] = {iface->dhcpv6_raw, iface->dhcpv6_raw_len},
+               [IOV_RELAY_MSG] = {NULL, 0}
+       };
 
        uint8_t *opts = (uint8_t*)&hdr[1], *opts_end = (uint8_t*)data + len;
        if (hdr->msg_type == DHCPV6_MSG_RELAY_FORW)
@@ -261,8 +291,8 @@ static void handle_client_request(void *addr, void *data, size_t len,
        if (opts[-4] == DHCPV6_MSG_SOLICIT) {
                dest.msg_type = DHCPV6_MSG_ADVERTISE;
        } else if (opts[-4] == DHCPV6_MSG_INFORMATION_REQUEST) {
-               iov[6].iov_base = &refresh;
-               iov[6].iov_len = sizeof(refresh);
+               iov[IOV_REFRESH].iov_base = &refresh;
+               iov[IOV_REFRESH].iov_len = sizeof(refresh);
        }
 
        // Go through options and find what we need
@@ -272,24 +302,48 @@ static void handle_client_request(void *addr, void *data, size_t len,
                if (otype == DHCPV6_OPT_CLIENTID && olen <= 130) {
                        dest.clientid_length = htons(olen);
                        memcpy(dest.clientid_buf, odata, olen);
-                       iov[1].iov_len += 4 + olen;
+                       iov[IOV_DEST].iov_len += 4 + olen;
                } else if (otype == DHCPV6_OPT_SERVERID) {
                        if (olen != ntohs(dest.serverid_length) ||
                                        memcmp(odata, &dest.duid_type, olen))
                                return; // Not for us
+               } else if (iface->filter_class && otype == DHCPV6_OPT_USER_CLASS) {
+                       uint8_t *c = odata, *cend = &odata[olen];
+                       for (; &c[2] <= cend && &c[2 + (c[0] << 8) + c[1]] <= cend; c = &c[2 + (c[0] << 8) + c[1]]) {
+                               size_t elen = strlen(iface->filter_class);
+                               if (((((size_t)c[0]) << 8) | c[1]) == elen && !memcmp(&c[2], iface->filter_class, elen))
+                                       return; // Ignore from homenet
+                       }
+               } else if (otype == DHCPV6_OPT_IA_PD) {
+#ifdef EXT_CER_ID
+                       iov[IOV_CERID].iov_len = sizeof(cerid);
+
+                       if (IN6_IS_ADDR_UNSPECIFIED(&cerid.addr)) {
+                               struct odhcpd_ipaddr addrs[32];
+                               ssize_t len = odhcpd_get_interface_addresses(0, addrs,
+                                               sizeof(addrs) / sizeof(*addrs));
+
+                               for (ssize_t i = 0; i < len; ++i)
+                                       if (IN6_IS_ADDR_UNSPECIFIED(&cerid.addr)
+                                                       || memcmp(&addrs[i].addr, &cerid.addr, sizeof(cerid.addr)) < 0)
+                                               cerid.addr = addrs[i].addr;
+                       }
+#endif
                }
        }
 
        if (opts[-4] != DHCPV6_MSG_INFORMATION_REQUEST) {
-               iov[6].iov_len = dhcpv6_handle_ia(pdbuf, sizeof(pdbuf), iface, addr, &opts[-4], opts_end);
-               if (iov[6].iov_len == 0 && opts[-4] == DHCPV6_MSG_REBIND)
+               ssize_t ialen = dhcpv6_handle_ia(pdbuf, sizeof(pdbuf), iface, addr, &opts[-4], opts_end);
+               iov[IOV_PDBUF].iov_len = ialen;
+               if (ialen < 0 || (ialen == 0 && (opts[-4] == DHCPV6_MSG_REBIND || opts[-4] == DHCPV6_MSG_CONFIRM)))
                        return;
        }
 
-       if (iov[0].iov_len > 0) // Update length
-               update_nested_message(data, len, iov[1].iov_len + iov[2].iov_len +
-                               iov[3].iov_len + iov[4].iov_len + iov[5].iov_len +
-                               iov[6].iov_len - (4 + opts_end - opts));
+       if (iov[IOV_NESTED].iov_len > 0) // Update length
+               update_nested_message(data, len, iov[IOV_DEST].iov_len + iov[IOV_DNS].iov_len +
+                               iov[IOV_DNS_ADDR].iov_len + iov[IOV_SEARCH].iov_len +
+                               iov[IOV_SEARCH_DOMAIN].iov_len + iov[IOV_PDBUF].iov_len +
+                               iov[IOV_CERID].iov_len + iov[IOV_DHCPV6_RAW].iov_len - (4 + opts_end - opts));
 
        odhcpd_send(iface->dhcpv6_event.uloop.fd, addr, iov, ARRAY_SIZE(iov), iface);
 }