Fix potential buffer overflow in entry_to_env
[odhcp6c.git] / src / script.c
1 /**
2  * Copyright (C) 2012-2014 Steven Barth <steven@midlink.org>
3  *
4  * This program is free software; you can redistribute it and/or modify
5  * it under the terms of the GNU General Public License v2 as published by
6  * the Free Software Foundation.
7  *
8  * This program is distributed in the hope that it will be useful,
9  * but WITHOUT ANY WARRANTY; without even the implied warranty of
10  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
11  * GNU General Public License for more details.
12  *
13  */
14
15 #include <stdio.h>
16 #include <netdb.h>
17 #include <resolv.h>
18 #include <stdlib.h>
19 #include <string.h>
20 #include <syslog.h>
21 #include <signal.h>
22 #include <unistd.h>
23 #include <inttypes.h>
24 #include <arpa/inet.h>
25 #include <sys/wait.h>
26 #include <netinet/in.h>
27
28 #include "odhcp6c.h"
29
30 static const char hexdigits[] = "0123456789abcdef";
31 static const int8_t hexvals[] = {
32     -1, -1, -1, -1, -1, -1, -1, -1, -1, -2, -2, -1, -1, -2, -1, -1,
33     -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
34     -2, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
35      0,  1,  2,  3,  4,  5,  6,  7,  8,  9, -1, -1, -1, -1, -1, -1,
36     -1, 10, 11, 12, 13, 14, 15, -1, -1, -1, -1, -1, -1, -1, -1, -1,
37     -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
38     -1, 10, 11, 12, 13, 14, 15, -1, -1, -1, -1, -1, -1, -1, -1, -1,
39     -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
40 };
41
42
43 static char action[16] = "";
44 static char *argv[4] = {NULL, NULL, action, NULL};
45 static volatile pid_t running = 0;
46 static time_t started;
47
48
49 static void script_sighandle(int signal)
50 {
51         if (signal == SIGCHLD) {
52                 pid_t child;
53                 while ((child = waitpid(-1, NULL, WNOHANG)) > 0)
54                         if (running == child)
55                                 running = 0;
56         }
57 }
58
59 int script_init(const char *path, const char *ifname)
60 {
61         argv[0] = (char*)path;
62         argv[1] = (char*)ifname;
63         signal(SIGCHLD, script_sighandle);
64         return 0;
65 }
66
67
68 ssize_t script_unhexlify(uint8_t *dst, size_t len, const char *src)
69 {
70         size_t c;
71         for (c = 0; c < len && src[0] && src[1]; ++c) {
72                 int8_t x = (int8_t)*src++;
73                 int8_t y = (int8_t)*src++;
74                 if (x < 0 || (x = hexvals[x]) < 0
75                                 || y < 0 || (y = hexvals[y]) < 0)
76                         return -1;
77                 dst[c] = x << 4 | y;
78                 while (((int8_t)*src) < 0 ||
79                                 (*src && hexvals[(uint8_t)*src] < 0))
80                         src++;
81         }
82
83         return c;
84 }
85
86
87 static void script_hexlify(char *dst, const uint8_t *src, size_t len) {
88         for (size_t i = 0; i < len; ++i) {
89                 *dst++ = hexdigits[src[i] >> 4];
90                 *dst++ = hexdigits[src[i] & 0x0f];
91         }
92         *dst = 0;
93 }
94
95
96 static void ipv6_to_env(const char *name,
97                 const struct in6_addr *addr, size_t cnt)
98 {
99         size_t buf_len = strlen(name);
100         char *buf = realloc(NULL, cnt * INET6_ADDRSTRLEN + buf_len + 2);
101         memcpy(buf, name, buf_len);
102         buf[buf_len++] = '=';
103         for (size_t i = 0; i < cnt; ++i) {
104                 inet_ntop(AF_INET6, &addr[i], &buf[buf_len], INET6_ADDRSTRLEN);
105                 buf_len += strlen(&buf[buf_len]);
106                 buf[buf_len++] = ' ';
107         }
108         buf[buf_len - 1] = '\0';
109         putenv(buf);
110 }
111
112
113 static void fqdn_to_env(const char *name, const uint8_t *fqdn, size_t len)
114 {
115         size_t buf_len = strlen(name);
116         size_t buf_size = len + buf_len + 2;
117         const uint8_t *fqdn_end = fqdn + len;
118         char *buf = realloc(NULL, len + buf_len + 2);
119         memcpy(buf, name, buf_len);
120         buf[buf_len++] = '=';
121         while (fqdn < fqdn_end) {
122                 int l = dn_expand(fqdn, fqdn_end, fqdn, &buf[buf_len], buf_size - buf_len);
123                 if (l <= 0)
124                         break;
125                 fqdn += l;
126                 buf_len += strlen(&buf[buf_len]);
127                 buf[buf_len++] = ' ';
128         }
129         buf[buf_len - 1] = '\0';
130         putenv(buf);
131 }
132
133 static void bin_to_env(uint8_t *opts, size_t len)
134 {
135         uint8_t *oend = opts + len, *odata;
136         uint16_t otype, olen;
137         dhcpv6_for_each_option(opts, oend, otype, olen, odata) {
138                 char *buf = realloc(NULL, 14 + (olen * 2));
139                 size_t buf_len = 0;
140
141                 snprintf(buf, 14, "OPTION_%hu=", otype);
142                 buf_len += strlen(buf);
143
144                 script_hexlify(&buf[buf_len], odata, olen);
145                 putenv(buf);
146         }
147 }
148
149 enum entry_type {
150         ENTRY_ADDRESS,
151         ENTRY_HOST,
152         ENTRY_ROUTE,
153         ENTRY_PREFIX
154 };
155
156 static void entry_to_env(const char *name, const void *data, size_t len, enum entry_type type)
157 {
158         size_t buf_len = strlen(name);
159         const struct odhcp6c_entry *e = data;
160         // Worst case: ENTRY_PREFIX with iaid != 1 and exclusion
161         const size_t max_entry_len = (INET6_ADDRSTRLEN-1 + 5 + 22 + 15 + 10 +
162                                       INET6_ADDRSTRLEN-1 + 11 + 1);
163         char *buf = realloc(NULL, buf_len + 2 + (len / sizeof(*e)) * max_entry_len);
164         memcpy(buf, name, buf_len);
165         buf[buf_len++] = '=';
166
167         for (size_t i = 0; i < len / sizeof(*e); ++i) {
168                 inet_ntop(AF_INET6, &e[i].target, &buf[buf_len], INET6_ADDRSTRLEN);
169                 buf_len += strlen(&buf[buf_len]);
170                 if (type != ENTRY_HOST) {
171                         snprintf(&buf[buf_len], 6, "/%"PRIu16, e[i].length);
172                         buf += strlen(&buf[buf_len]);
173                         if (type == ENTRY_ROUTE) {
174                                 buf[buf_len++] = ',';
175                                 if (!IN6_IS_ADDR_UNSPECIFIED(&e[i].router)) {
176                                         inet_ntop(AF_INET6, &e[i].router, &buf[buf_len], INET6_ADDRSTRLEN);
177                                         buf_len += strlen(&buf[buf_len]);
178                                 }
179                                 snprintf(&buf[buf_len], 23, ",%u,%u", e[i].valid, e[i].priority);
180                                 buf += strlen(&buf[buf_len]);
181                         } else {
182                                 snprintf(&buf[buf_len], 23, ",%u,%u", e[i].preferred, e[i].valid);
183                                 buf += strlen(&buf[buf_len]);
184                         }
185
186                         if (type == ENTRY_PREFIX && ntohl(e[i].iaid) != 1) {
187                                 snprintf(&buf[buf_len], 16, ",class=%08x", ntohl(e[i].iaid));
188                                 buf += strlen(&buf[buf_len]);
189                         }
190
191                         if (type == ENTRY_PREFIX && e[i].priority) {
192                                 // priority and router are abused for prefix exclusion
193                                 snprintf(&buf[buf_len], 11, ",excluded=");
194                                 buf_len += strlen(&buf[buf_len]);
195                                 inet_ntop(AF_INET6, &e[i].router, &buf[buf_len], INET6_ADDRSTRLEN);
196                                 buf_len += strlen(&buf[buf_len]);
197                                 snprintf(&buf[buf_len], 12, "/%u", e[i].priority);
198                                 buf_len += strlen(&buf[buf_len]);
199                         }
200                 }
201                 buf[buf_len++] = ' ';
202         }
203
204         buf[buf_len - 1] = '\0';
205         putenv(buf);
206 }
207
208
209 static void search_to_env(const char *name, const uint8_t *start, size_t len)
210 {
211         size_t buf_len = strlen(name);
212         char *buf = realloc(NULL, buf_len + 2 + len);
213         char *c = mempcpy(buf, name, buf_len);
214         *c++ = '=';
215
216         for (struct odhcp6c_entry *e = (struct odhcp6c_entry*)start;
217                                 (uint8_t*)e < &start[len] && &e->auxtarget[e->auxlen] <= &start[len];
218                                 e = (struct odhcp6c_entry*)(&e->auxtarget[e->auxlen])) {
219                 c = mempcpy(c, e->auxtarget, e->auxlen);
220                 *c++ = ' ';
221         }
222
223         c[-1] = '\0';
224         putenv(buf);
225 }
226
227
228 static void int_to_env(const char *name, int value)
229 {
230         size_t len = 12 + strlen(name);
231         char *buf = realloc(NULL, len);
232         snprintf(buf, len, "%s=%d", name, value);
233         putenv(buf);
234 }
235
236
237 static void s46_to_env_portparams(const uint8_t *data, size_t len, FILE *fp)
238 {
239         uint8_t *odata;
240         uint16_t otype, olen;
241         dhcpv6_for_each_option(data, &data[len], otype, olen, odata) {
242                 if (otype == DHCPV6_OPT_S46_PORTPARAMS &&
243                                 olen == sizeof(struct dhcpv6_s46_portparams)) {
244                         struct dhcpv6_s46_portparams *params = (void*)odata;
245                         fprintf(fp, "offset=%d,psidlen=%d,psid=%d,",
246                                         params->offset, params->psid_len, ntohs(params->psid));
247                 }
248         }
249 }
250
251
252 static void s46_to_env(enum odhcp6c_state state, const uint8_t *data, size_t len)
253 {
254         const char *name = (state == STATE_S46_MAPE) ? "MAPE" :
255                         (state == STATE_S46_MAPT) ? "MAPT" : "LW4O6";
256
257         if (len == 0)
258                 return;
259
260         char *str;
261         size_t strsize;
262
263         FILE *fp = open_memstream(&str, &strsize);
264         fputs(name, fp);
265         fputc('=', fp);
266
267         const char *type = (state == STATE_S46_MAPE) ? "map-e" :
268                         (state == STATE_S46_MAPT) ? "map-t" : "lw4o6";
269
270         uint8_t *odata;
271         uint16_t otype, olen;
272         dhcpv6_for_each_option(data, &data[len], otype, olen, odata) {
273                 struct dhcpv6_s46_rule *rule = (struct dhcpv6_s46_rule*)odata;
274                 struct dhcpv6_s46_v4v6bind *bind = (struct dhcpv6_s46_v4v6bind*)odata;
275
276                 if (state != STATE_S46_LW && otype == DHCPV6_OPT_S46_RULE &&
277                                 olen >= sizeof(struct dhcpv6_s46_rule)) {
278                         char buf4[INET_ADDRSTRLEN];
279                         char buf6[INET6_ADDRSTRLEN];
280                         struct in6_addr in6 = IN6ADDR_ANY_INIT;
281
282                         size_t prefix6len = rule->prefix6_len;
283                         prefix6len = (prefix6len % 8 == 0) ? prefix6len / 8 : prefix6len / 8 + 1;
284
285                         if (olen < sizeof(struct dhcpv6_s46_rule) + prefix6len)
286                                 continue;
287
288                         memcpy(&in6, rule->ipv6_prefix, prefix6len);
289
290                         inet_ntop(AF_INET, &rule->ipv4_prefix, buf4, sizeof(buf4));
291                         inet_ntop(AF_INET6, &in6, buf6, sizeof(buf6));
292
293                         if (rule->flags & 1)
294                                 fputs("fmr,", fp);
295
296                         fprintf(fp, "type=%s,ealen=%d,prefix4len=%d,prefix6len=%d,ipv4prefix=%s,ipv6prefix=%s,",
297                                         type, rule->ea_len, rule->prefix4_len, rule->prefix6_len, buf4, buf6);
298
299                         s46_to_env_portparams(&rule->ipv6_prefix[prefix6len],
300                                         olen - sizeof(*rule) - prefix6len, fp);
301
302                         dhcpv6_for_each_option(data, &data[len], otype, olen, odata) {
303                                 if (state != STATE_S46_MAPT && otype == DHCPV6_OPT_S46_BR &&
304                                                 olen == sizeof(struct in6_addr)) {
305                                         inet_ntop(AF_INET6, odata, buf6, sizeof(buf6));
306                                         fprintf(fp, "br=%s,", buf6);
307                                 } else if (state == STATE_S46_MAPT && otype == DHCPV6_OPT_S46_DMR &&
308                                                 olen >= sizeof(struct dhcpv6_s46_dmr)) {
309                                         struct dhcpv6_s46_dmr *dmr = (struct dhcpv6_s46_dmr*)odata;
310                                         memset(&in6, 0, sizeof(in6));
311                                         size_t prefix6len = dmr->dmr_prefix6_len;
312                                         prefix6len = (prefix6len % 8 == 0) ? prefix6len / 8 : prefix6len / 8 + 1;
313
314                                         if (olen < sizeof(struct dhcpv6_s46_dmr) + prefix6len)
315                                                 continue;
316
317                                         memcpy(&in6, dmr->dmr_ipv6_prefix, prefix6len);
318                                         inet_ntop(AF_INET6, &in6, buf6, sizeof(buf6));
319                                         fprintf(fp, "dmr=%s/%d,", buf6, dmr->dmr_prefix6_len);
320                                 }
321                         }
322
323                         fputc(' ', fp);
324                 } else if (state == STATE_S46_LW && otype == DHCPV6_OPT_S46_V4V6BIND &&
325                                 olen >= sizeof(struct dhcpv6_s46_v4v6bind)) {
326                         char buf4[INET_ADDRSTRLEN];
327                         char buf6[INET6_ADDRSTRLEN];
328                         struct in6_addr in6 = IN6ADDR_ANY_INIT;
329
330                         size_t prefix6len = bind->bindprefix6_len;
331                         prefix6len = (prefix6len % 8 == 0) ? prefix6len / 8 : prefix6len / 8 + 1;
332
333                         if (olen < sizeof(struct dhcpv6_s46_v4v6bind) + prefix6len)
334                                 continue;
335
336                         memcpy(&in6, bind->bind_ipv6_prefix, prefix6len);
337
338                         inet_ntop(AF_INET, &bind->ipv4_address, buf4, sizeof(buf4));
339                         inet_ntop(AF_INET6, &in6, buf6, sizeof(buf6));
340
341                         fprintf(fp, "type=%s,prefix4len=32,prefix6len=%d,ipv4prefix=%s,ipv6prefix=%s,",
342                                         type, bind->bindprefix6_len, buf4, buf6);
343
344                         s46_to_env_portparams(&bind->bind_ipv6_prefix[prefix6len],
345                                         olen - sizeof(*bind) - prefix6len, fp);
346
347                         dhcpv6_for_each_option(data, &data[len], otype, olen, odata) {
348                                 if (otype == DHCPV6_OPT_S46_BR && olen == sizeof(struct in6_addr)) {
349                                         inet_ntop(AF_INET6, odata, buf6, sizeof(buf6));
350                                         fprintf(fp, "br=%s,", buf6);
351                                 }
352                         }
353
354                         fputc(' ', fp);
355                 }
356         }
357
358         fclose(fp);
359         putenv(str);
360 }
361
362
363 void script_call(const char *status, int delay, bool resume)
364 {
365         time_t now = odhcp6c_get_milli_time() / 1000;
366         bool running_script = false;
367
368         if (running) {
369                 kill(running, SIGTERM);
370                 delay -= now - started;
371                 running_script = true;
372         }
373
374         if (resume || !running_script || !action[0])
375                 strncpy(action, status, sizeof(action) - 1);
376
377         pid_t pid = fork();
378         if (pid > 0) {
379                 running = pid;
380                 started = now;
381
382                 if (!resume)
383                         action[0] = 0;
384         } else if (pid == 0) {
385                 size_t dns_len, search_len, custom_len, sntp_ip_len, ntp_ip_len, ntp_dns_len;
386                 size_t sip_ip_len, sip_fqdn_len, aftr_name_len, cer_len, addr_len;
387                 size_t s46_mapt_len, s46_mape_len, s46_lw_len, passthru_len;
388
389                 signal(SIGTERM, SIG_DFL);
390                 if (delay > 0) {
391                         sleep(delay);
392                         odhcp6c_expire();
393                 }
394
395                 struct in6_addr *addr = odhcp6c_get_state(STATE_SERVER_ADDR, &addr_len);
396                 struct in6_addr *dns = odhcp6c_get_state(STATE_DNS, &dns_len);
397                 uint8_t *search = odhcp6c_get_state(STATE_SEARCH, &search_len);
398                 uint8_t *custom = odhcp6c_get_state(STATE_CUSTOM_OPTS, &custom_len);
399                 struct in6_addr *sntp = odhcp6c_get_state(STATE_SNTP_IP, &sntp_ip_len);
400                 struct in6_addr *ntp = odhcp6c_get_state(STATE_NTP_IP, &ntp_ip_len);
401                 uint8_t *ntp_dns = odhcp6c_get_state(STATE_NTP_FQDN, &ntp_dns_len);
402                 struct in6_addr *sip = odhcp6c_get_state(STATE_SIP_IP, &sip_ip_len);
403                 uint8_t *sip_fqdn = odhcp6c_get_state(STATE_SIP_FQDN, &sip_fqdn_len);
404                 uint8_t *aftr_name = odhcp6c_get_state(STATE_AFTR_NAME, &aftr_name_len);
405                 struct in6_addr *cer = odhcp6c_get_state(STATE_CER, &cer_len);
406                 uint8_t *s46_mapt = odhcp6c_get_state(STATE_S46_MAPT, &s46_mapt_len);
407                 uint8_t *s46_mape = odhcp6c_get_state(STATE_S46_MAPE, &s46_mape_len);
408                 uint8_t *s46_lw = odhcp6c_get_state(STATE_S46_LW, &s46_lw_len);
409                 uint8_t *passthru = odhcp6c_get_state(STATE_PASSTHRU, &passthru_len);
410
411                 size_t prefix_len, address_len, ra_pref_len,
412                         ra_route_len, ra_dns_len, ra_search_len;
413                 uint8_t *prefix = odhcp6c_get_state(STATE_IA_PD, &prefix_len);
414                 uint8_t *address = odhcp6c_get_state(STATE_IA_NA, &address_len);
415                 uint8_t *ra_pref = odhcp6c_get_state(STATE_RA_PREFIX, &ra_pref_len);
416                 uint8_t *ra_route = odhcp6c_get_state(STATE_RA_ROUTE, &ra_route_len);
417                 uint8_t *ra_dns = odhcp6c_get_state(STATE_RA_DNS, &ra_dns_len);
418                 uint8_t *ra_search = odhcp6c_get_state(STATE_RA_SEARCH, &ra_search_len);
419
420                 ipv6_to_env("SERVER", addr, addr_len / sizeof(*addr));
421                 ipv6_to_env("RDNSS", dns, dns_len / sizeof(*dns));
422                 ipv6_to_env("SNTP_IP", sntp, sntp_ip_len / sizeof(*sntp));
423                 ipv6_to_env("NTP_IP", ntp, ntp_ip_len / sizeof(*ntp));
424                 fqdn_to_env("NTP_FQDN", ntp_dns, ntp_dns_len);
425                 ipv6_to_env("SIP_IP", sip, sip_ip_len / sizeof(*sip));
426                 fqdn_to_env("DOMAINS", search, search_len);
427                 fqdn_to_env("SIP_DOMAIN", sip_fqdn, sip_fqdn_len);
428                 fqdn_to_env("AFTR", aftr_name, aftr_name_len);
429                 ipv6_to_env("CER", cer, cer_len / sizeof(*cer));
430                 s46_to_env(STATE_S46_MAPE, s46_mape, s46_mape_len);
431                 s46_to_env(STATE_S46_MAPT, s46_mapt, s46_mapt_len);
432                 s46_to_env(STATE_S46_LW, s46_lw, s46_lw_len);
433                 bin_to_env(custom, custom_len);
434
435                 if (odhcp6c_is_bound()) {
436                         entry_to_env("PREFIXES", prefix, prefix_len, ENTRY_PREFIX);
437                         entry_to_env("ADDRESSES", address, address_len, ENTRY_ADDRESS);
438                 }
439
440                 entry_to_env("RA_ADDRESSES", ra_pref, ra_pref_len, ENTRY_ADDRESS);
441                 entry_to_env("RA_ROUTES", ra_route, ra_route_len, ENTRY_ROUTE);
442                 entry_to_env("RA_DNS", ra_dns, ra_dns_len, ENTRY_HOST);
443                 search_to_env("RA_DOMAINS", ra_search, ra_search_len);
444
445                 int_to_env("RA_HOPLIMIT", ra_conf_hoplimit(0));
446                 int_to_env("RA_MTU", ra_conf_mtu(0));
447                 int_to_env("RA_REACHABLE", ra_conf_reachable(0));
448                 int_to_env("RA_RETRANSMIT", ra_conf_retransmit(0));
449
450                 char *buf = malloc(10 + passthru_len * 2);
451                 strncpy(buf, "PASSTHRU=", 10);
452                 script_hexlify(&buf[9], passthru, passthru_len);
453                 putenv(buf);
454
455                 execv(argv[0], argv);
456                 _exit(128);
457         }
458 }