version 1.1.1.1, 2013/07/29 19:37:40
|
version 1.1.1.5, 2023/09/27 11:02:07
|
Line 1
|
Line 1
|
/* dnsmasq is Copyright (c) 2000-2013 Simon Kelley | /* dnsmasq is Copyright (c) 2000-2022 Simon Kelley |
|
|
This program is free software; you can redistribute it and/or modify |
This program is free software; you can redistribute it and/or modify |
it under the terms of the GNU General Public License as published by |
it under the terms of the GNU General Public License as published by |
Line 28
|
Line 28
|
|
|
struct ra_param { |
struct ra_param { |
time_t now; |
time_t now; |
int ind, managed, other, found_context, first; | int ind, managed, other, first, adv_router; |
char *if_name; |
char *if_name; |
struct dhcp_netid *tags; |
struct dhcp_netid *tags; |
struct in6_addr link_local, link_global; | struct in6_addr link_local, link_global, ula; |
unsigned int pref_time; | unsigned int glob_pref_time, link_pref_time, ula_pref_time, adv_interval, prio; |
| struct dhcp_context *found_context; |
}; |
}; |
|
|
struct search_param { |
struct search_param { |
time_t now; int iface; |
time_t now; int iface; |
|
char name[IF_NAMESIZE+1]; |
}; |
}; |
|
|
|
struct alias_param { |
|
int iface; |
|
struct dhcp_bridge *bridge; |
|
int num_alias_ifs; |
|
int max_alias_ifs; |
|
int *alias_ifs; |
|
}; |
|
|
static void send_ra(time_t now, int iface, char *iface_name, struct in6_addr *dest); |
static void send_ra(time_t now, int iface, char *iface_name, struct in6_addr *dest); |
|
static void send_ra_alias(time_t now, int iface, char *iface_name, struct in6_addr *dest, |
|
int send_iface); |
|
static int send_ra_to_aliases(int index, unsigned int type, char *mac, size_t maclen, void *parm); |
static int add_prefixes(struct in6_addr *local, int prefix, |
static int add_prefixes(struct in6_addr *local, int prefix, |
int scope, int if_index, int flags, |
int scope, int if_index, int flags, |
unsigned int preferred, unsigned int valid, void *vparam); |
unsigned int preferred, unsigned int valid, void *vparam); |
Line 47 static int iface_search(struct in6_addr *local, int p
|
Line 60 static int iface_search(struct in6_addr *local, int p
|
int scope, int if_index, int flags, |
int scope, int if_index, int flags, |
int prefered, int valid, void *vparam); |
int prefered, int valid, void *vparam); |
static int add_lla(int index, unsigned int type, char *mac, size_t maclen, void *parm); |
static int add_lla(int index, unsigned int type, char *mac, size_t maclen, void *parm); |
|
static void new_timeout(struct dhcp_context *context, char *iface_name, time_t now); |
|
static unsigned int calc_lifetime(struct ra_interface *ra); |
|
static unsigned int calc_interval(struct ra_interface *ra); |
|
static unsigned int calc_prio(struct ra_interface *ra); |
|
static struct ra_interface *find_iface_param(char *iface); |
|
|
static int hop_limit; |
static int hop_limit; |
|
|
Line 64 void ra_init(time_t now)
|
Line 82 void ra_init(time_t now)
|
/* ensure this is around even if we're not doing DHCPv6 */ |
/* ensure this is around even if we're not doing DHCPv6 */ |
expand_buf(&daemon->outpacket, sizeof(struct dhcp_packet)); |
expand_buf(&daemon->outpacket, sizeof(struct dhcp_packet)); |
|
|
/* See if we're guessing SLAAC addresses, if so we need to recieve ping replies */ | /* See if we're guessing SLAAC addresses, if so we need to receive ping replies */ |
for (context = daemon->dhcp6; context; context = context->next) |
for (context = daemon->dhcp6; context; context = context->next) |
if ((context->flags & CONTEXT_RA_NAME)) |
if ((context->flags & CONTEXT_RA_NAME)) |
break; |
break; |
|
|
|
/* Need ICMP6 socket for transmission for DHCPv6 even when not doing RA. */ |
|
|
ICMP6_FILTER_SETBLOCKALL(&filter); |
ICMP6_FILTER_SETBLOCKALL(&filter); |
ICMP6_FILTER_SETPASS(ND_ROUTER_SOLICIT, &filter); | if (daemon->doing_ra) |
if (context) | { |
ICMP6_FILTER_SETPASS(ICMP6_ECHO_REPLY, &filter); | ICMP6_FILTER_SETPASS(ND_ROUTER_SOLICIT, &filter); |
| if (context) |
| ICMP6_FILTER_SETPASS(ICMP6_ECHO_REPLY, &filter); |
| } |
|
|
if ((fd = socket(PF_INET6, SOCK_RAW, IPPROTO_ICMPV6)) == -1 || |
if ((fd = socket(PF_INET6, SOCK_RAW, IPPROTO_ICMPV6)) == -1 || |
getsockopt(fd, IPPROTO_IPV6, IPV6_UNICAST_HOPS, &hop_limit, &len) || |
getsockopt(fd, IPPROTO_IPV6, IPV6_UNICAST_HOPS, &hop_limit, &len) || |
Line 88 void ra_init(time_t now)
|
Line 111 void ra_init(time_t now)
|
|
|
daemon->icmp6fd = fd; |
daemon->icmp6fd = fd; |
|
|
ra_start_unsolicted(now, NULL); | if (daemon->doing_ra) |
| ra_start_unsolicited(now, NULL); |
} |
} |
|
|
void ra_start_unsolicted(time_t now, struct dhcp_context *context) | void ra_start_unsolicited(time_t now, struct dhcp_context *context) |
{ |
{ |
/* init timers so that we do ra's for some/all soon. some ra_times will end up zeroed |
/* init timers so that we do ra's for some/all soon. some ra_times will end up zeroed |
if it's not appropriate to advertise those contexts. |
if it's not appropriate to advertise those contexts. |
Line 99 void ra_start_unsolicted(time_t now, struct dhcp_conte
|
Line 123 void ra_start_unsolicted(time_t now, struct dhcp_conte
|
and pick up new interfaces */ |
and pick up new interfaces */ |
|
|
if (context) |
if (context) |
context->ra_short_period_start = context->ra_time = now; | { |
| context->ra_short_period_start = now; |
| /* start after 1 second to get logging right at startup. */ |
| context->ra_time = now + 1; |
| } |
else |
else |
for (context = daemon->dhcp6; context; context = context->next) |
for (context = daemon->dhcp6; context; context = context->next) |
if (!(context->flags & CONTEXT_TEMPLATE)) |
if (!(context->flags & CONTEXT_TEMPLATE)) |
Line 138 void icmp6_packet(time_t now)
|
Line 166 void icmp6_packet(time_t now)
|
return; |
return; |
|
|
packet = (unsigned char *)daemon->outpacket.iov_base; |
packet = (unsigned char *)daemon->outpacket.iov_base; |
| |
for (cmptr = CMSG_FIRSTHDR(&msg); cmptr; cmptr = CMSG_NXTHDR(&msg, cmptr)) |
for (cmptr = CMSG_FIRSTHDR(&msg); cmptr; cmptr = CMSG_NXTHDR(&msg, cmptr)) |
if (cmptr->cmsg_level == IPPROTO_IPV6 && cmptr->cmsg_type == daemon->v6pktinfo) |
if (cmptr->cmsg_level == IPPROTO_IPV6 && cmptr->cmsg_type == daemon->v6pktinfo) |
{ |
{ |
Line 163 void icmp6_packet(time_t now)
|
Line 191 void icmp6_packet(time_t now)
|
|
|
if (packet[1] != 0) |
if (packet[1] != 0) |
return; |
return; |
| |
if (packet[0] == ICMP6_ECHO_REPLY) |
if (packet[0] == ICMP6_ECHO_REPLY) |
lease_ping_reply(&from.sin6_addr, packet, interface); |
lease_ping_reply(&from.sin6_addr, packet, interface); |
else if (packet[0] == ND_ROUTER_SOLICIT) |
else if (packet[0] == ND_ROUTER_SOLICIT) |
{ |
{ |
char *mac = ""; |
char *mac = ""; |
|
struct dhcp_bridge *bridge, *alias; |
|
ssize_t rem; |
|
unsigned char *p; |
|
int opt_sz; |
|
|
|
#ifdef HAVE_DUMPFILE |
|
dump_packet_icmp(DUMP_RA, (void *)packet, sz, (union mysockaddr *)&from, NULL); |
|
#endif |
|
|
/* look for link-layer address option for logging */ |
/* look for link-layer address option for logging */ |
if (sz >= 16 && packet[8] == ICMP6_OPT_SOURCE_MAC && (packet[9] * 8) + 8 <= sz) | for (rem = sz - 8, p = &packet[8]; rem >= 2; rem -= opt_sz, p += opt_sz) |
{ |
{ |
print_mac(daemon->namebuff, &packet[10], (packet[9] * 8) - 2); | opt_sz = p[1] * 8; |
mac = daemon->namebuff; | |
| if (opt_sz == 0 || opt_sz > rem) |
| return; /* Bad packet */ |
| |
| if (p[0] == ICMP6_OPT_SOURCE_MAC && ((opt_sz - 2) * 3 - 1 < MAXDNAME)) |
| { |
| print_mac(daemon->namebuff, &p[2], opt_sz - 2); |
| mac = daemon->namebuff; |
| } |
} |
} |
| |
my_syslog(MS_DHCP | LOG_INFO, "RTR-SOLICIT(%s) %s", interface, mac); | if (!option_bool(OPT_QUIET_RA)) |
/* source address may not be valid in solicit request. */ | my_syslog(MS_DHCP | LOG_INFO, "RTR-SOLICIT(%s) %s", interface, mac); |
send_ra(now, if_index, interface, !IN6_IS_ADDR_UNSPECIFIED(&from.sin6_addr) ? &from.sin6_addr : NULL); | |
| /* If the incoming interface is an alias of some other one (as |
| specified by the --bridge-interface option), send an RA using |
| the context of the aliased interface. */ |
| for (bridge = daemon->bridges; bridge; bridge = bridge->next) |
| { |
| int bridge_index = if_nametoindex(bridge->iface); |
| if (bridge_index) |
| { |
| for (alias = bridge->alias; alias; alias = alias->next) |
| if (wildcard_matchn(alias->iface, interface, IF_NAMESIZE)) |
| { |
| /* Send an RA on if_index with information from |
| bridge_index. */ |
| send_ra_alias(now, bridge_index, bridge->iface, NULL, if_index); |
| break; |
| } |
| if (alias) |
| break; |
| } |
| } |
| |
| /* If the incoming interface wasn't an alias, send an RA using |
| the context of the incoming interface. */ |
| if (!bridge) |
| /* source address may not be valid in solicit request. */ |
| send_ra(now, if_index, interface, !IN6_IS_ADDR_UNSPECIFIED(&from.sin6_addr) ? &from.sin6_addr : NULL); |
} |
} |
} |
} |
|
|
static void send_ra(time_t now, int iface, char *iface_name, struct in6_addr *dest) | static void send_ra_alias(time_t now, int iface, char *iface_name, struct in6_addr *dest, int send_iface) |
{ |
{ |
struct ra_packet *ra; |
struct ra_packet *ra; |
struct ra_param parm; |
struct ra_param parm; |
struct ifreq ifr; |
|
struct sockaddr_in6 addr; |
struct sockaddr_in6 addr; |
struct dhcp_context *context; | struct dhcp_context *context, *tmp, **up; |
struct dhcp_netid iface_id; |
struct dhcp_netid iface_id; |
struct dhcp_opt *opt_cfg; |
struct dhcp_opt *opt_cfg; |
int done_dns = 0; | struct ra_interface *ra_param = find_iface_param(iface_name); |
| int done_dns = 0, old_prefix = 0, mtu = 0; |
| unsigned int min_pref_time; |
#ifdef HAVE_LINUX_NETWORK |
#ifdef HAVE_LINUX_NETWORK |
FILE *f; |
FILE *f; |
#endif |
#endif |
|
|
save_counter(0); |
|
ra = expand(sizeof(struct ra_packet)); |
|
|
|
ra->type = ND_ROUTER_ADVERT; |
|
ra->code = 0; |
|
ra->hop_limit = hop_limit; |
|
ra->flags = 0x00; |
|
ra->lifetime = htons(RA_INTERVAL * 3); /* AdvDefaultLifetime * 3 */ |
|
ra->reachable_time = 0; |
|
ra->retrans_time = 0; |
|
|
|
parm.ind = iface; |
parm.ind = iface; |
parm.managed = 0; |
parm.managed = 0; |
parm.other = 0; |
parm.other = 0; |
parm.found_context = 0; | parm.found_context = NULL; |
| parm.adv_router = 0; |
parm.if_name = iface_name; |
parm.if_name = iface_name; |
parm.first = 1; |
parm.first = 1; |
parm.now = now; |
parm.now = now; |
parm.pref_time = 0; | parm.glob_pref_time = parm.link_pref_time = parm.ula_pref_time = 0; |
| parm.adv_interval = calc_interval(ra_param); |
| parm.prio = calc_prio(ra_param); |
|
|
|
reset_counter(); |
|
|
|
if (!(ra = expand(sizeof(struct ra_packet)))) |
|
return; |
|
|
|
ra->type = ND_ROUTER_ADVERT; |
|
ra->code = 0; |
|
ra->hop_limit = hop_limit; |
|
ra->flags = parm.prio; |
|
ra->lifetime = htons(calc_lifetime(ra_param)); |
|
ra->reachable_time = 0; |
|
ra->retrans_time = 0; |
|
|
/* set tag with name == interface */ |
/* set tag with name == interface */ |
iface_id.net = iface_name; |
iface_id.net = iface_name; |
iface_id.next = NULL; |
iface_id.next = NULL; |
Line 228 static void send_ra(time_t now, int iface, char *iface
|
Line 304 static void send_ra(time_t now, int iface, char *iface
|
context->netid.next = &context->netid; |
context->netid.next = &context->netid; |
} |
} |
|
|
|
/* If no link-local address then we can't advertise since source address of |
|
advertisement must be link local address: RFC 4861 para 6.1.2. */ |
if (!iface_enumerate(AF_INET6, &parm, add_prefixes) || |
if (!iface_enumerate(AF_INET6, &parm, add_prefixes) || |
!parm.found_context) | parm.link_pref_time == 0) |
return; |
return; |
|
|
strncpy(ifr.ifr_name, iface_name, IF_NAMESIZE); | /* Find smallest preferred time within address classes, |
| to use as lifetime for options. This is a rather arbitrary choice. */ |
| min_pref_time = 0xffffffff; |
| if (parm.glob_pref_time != 0 && parm.glob_pref_time < min_pref_time) |
| min_pref_time = parm.glob_pref_time; |
| |
| if (parm.ula_pref_time != 0 && parm.ula_pref_time < min_pref_time) |
| min_pref_time = parm.ula_pref_time; |
|
|
#ifdef HAVE_LINUX_NETWORK | if (parm.link_pref_time != 0 && parm.link_pref_time < min_pref_time) |
/* Note that IPv6 MTU is not necessarilly the same as the IPv4 MTU | min_pref_time = parm.link_pref_time; |
available from SIOCGIFMTU */ | |
sprintf(daemon->namebuff, "/proc/sys/net/ipv6/conf/%s/mtu", iface_name); | /* Look for constructed contexts associated with addresses which have gone, |
if ((f = fopen(daemon->namebuff, "r"))) | and advertise them with preferred_time == 0 RFC 6204 4.3 L-13 */ |
| for (up = &daemon->dhcp6, context = daemon->dhcp6; context; context = tmp) |
{ |
{ |
if (fgets(daemon->namebuff, MAXDNAME, f)) | tmp = context->next; |
| |
| if (context->if_index == iface && (context->flags & CONTEXT_OLD)) |
{ |
{ |
put_opt6_char(ICMP6_OPT_MTU); | unsigned int old = difftime(now, context->address_lost_time); |
put_opt6_char(1); | |
put_opt6_short(0); | if (old > context->saved_valid) |
put_opt6_long(atoi(daemon->namebuff)); | { |
| /* We've advertised this enough, time to go */ |
| |
| /* If this context held the timeout, and there's another context in use |
| transfer the timeout there. */ |
| if (context->ra_time != 0 && parm.found_context && parm.found_context->ra_time == 0) |
| new_timeout(parm.found_context, iface_name, now); |
| |
| *up = context->next; |
| free(context); |
| } |
| else |
| { |
| struct prefix_opt *opt; |
| struct in6_addr local = context->start6; |
| int do_slaac = 0; |
| |
| old_prefix = 1; |
| |
| /* zero net part of address */ |
| setaddr6part(&local, addr6part(&local) & ~((context->prefix == 64) ? (u64)-1LL : (1LLU << (128 - context->prefix)) - 1LLU)); |
| |
| |
| if (context->flags & CONTEXT_RA) |
| { |
| do_slaac = 1; |
| if (context->flags & CONTEXT_DHCP) |
| { |
| parm.other = 1; |
| if (!(context->flags & CONTEXT_RA_STATELESS)) |
| parm.managed = 1; |
| } |
| } |
| else |
| { |
| /* don't do RA for non-ra-only unless --enable-ra is set */ |
| if (option_bool(OPT_RA)) |
| { |
| parm.managed = 1; |
| parm.other = 1; |
| } |
| } |
| |
| if ((opt = expand(sizeof(struct prefix_opt)))) |
| { |
| opt->type = ICMP6_OPT_PREFIX; |
| opt->len = 4; |
| opt->prefix_len = context->prefix; |
| /* autonomous only if we're not doing dhcp, set |
| "on-link" unless "off-link" was specified */ |
| opt->flags = (do_slaac ? 0x40 : 0) | |
| ((context->flags & CONTEXT_RA_OFF_LINK) ? 0 : 0x80); |
| opt->valid_lifetime = htonl(context->saved_valid - old); |
| opt->preferred_lifetime = htonl(0); |
| opt->reserved = 0; |
| opt->prefix = local; |
| |
| inet_ntop(AF_INET6, &local, daemon->addrbuff, ADDRSTRLEN); |
| if (!option_bool(OPT_QUIET_RA)) |
| my_syslog(MS_DHCP | LOG_INFO, "RTR-ADVERT(%s) %s old prefix", iface_name, daemon->addrbuff); |
| } |
| |
| up = &context->next; |
| } |
} |
} |
fclose(f); | else |
| up = &context->next; |
} |
} |
|
|
|
/* If we're advertising only old prefixes, set router lifetime to zero. */ |
|
if (old_prefix && !parm.found_context) |
|
ra->lifetime = htons(0); |
|
|
|
/* No prefixes to advertise. */ |
|
if (!old_prefix && !parm.found_context) |
|
return; |
|
|
|
/* If we're sending router address instead of prefix in at least on prefix, |
|
include the advertisement interval option. */ |
|
if (parm.adv_router) |
|
{ |
|
put_opt6_char(ICMP6_OPT_ADV_INTERVAL); |
|
put_opt6_char(1); |
|
put_opt6_short(0); |
|
/* interval value is in milliseconds */ |
|
put_opt6_long(1000 * calc_interval(find_iface_param(iface_name))); |
|
} |
|
|
|
/* Set the MTU from ra_param if any, an MTU of 0 mean automatic for linux, */ |
|
/* an MTU of -1 prevents the option from being sent. */ |
|
if (ra_param) |
|
mtu = ra_param->mtu; |
|
#ifdef HAVE_LINUX_NETWORK |
|
/* Note that IPv6 MTU is not necessarily the same as the IPv4 MTU |
|
available from SIOCGIFMTU */ |
|
if (mtu == 0) |
|
{ |
|
char *mtu_name = ra_param ? ra_param->mtu_name : NULL; |
|
sprintf(daemon->namebuff, "/proc/sys/net/ipv6/conf/%s/mtu", mtu_name ? mtu_name : iface_name); |
|
if ((f = fopen(daemon->namebuff, "r"))) |
|
{ |
|
if (fgets(daemon->namebuff, MAXDNAME, f)) |
|
mtu = atoi(daemon->namebuff); |
|
fclose(f); |
|
} |
|
} |
#endif |
#endif |
|
if (mtu > 0) |
|
{ |
|
put_opt6_char(ICMP6_OPT_MTU); |
|
put_opt6_char(1); |
|
put_opt6_short(0); |
|
put_opt6_long(mtu); |
|
} |
|
|
iface_enumerate(AF_LOCAL, &iface, add_lla); | iface_enumerate(AF_LOCAL, &send_iface, add_lla); |
|
|
/* RDNSS, RFC 6106, use relevant DHCP6 options */ |
/* RDNSS, RFC 6106, use relevant DHCP6 options */ |
(void)option_filter(parm.tags, NULL, daemon->dhcp_opts6); |
(void)option_filter(parm.tags, NULL, daemon->dhcp_opts6); |
Line 266 static void send_ra(time_t now, int iface, char *iface
|
Line 463 static void send_ra(time_t now, int iface, char *iface
|
|
|
if (opt_cfg->opt == OPTION6_DNS_SERVER) |
if (opt_cfg->opt == OPTION6_DNS_SERVER) |
{ |
{ |
struct in6_addr *a = (struct in6_addr *)opt_cfg->val; | struct in6_addr *a; |
| int len; |
|
|
done_dns = 1; |
done_dns = 1; |
|
|
if (opt_cfg->len == 0) |
if (opt_cfg->len == 0) |
continue; | continue; |
|
|
put_opt6_char(ICMP6_OPT_RDNSS); | /* reduce len for any addresses we can't substitute */ |
put_opt6_char((opt_cfg->len/8) + 1); | for (a = (struct in6_addr *)opt_cfg->val, len = opt_cfg->len, i = 0; |
put_opt6_short(0); | i < opt_cfg->len; i += IN6ADDRSZ, a++) |
put_opt6_long(RA_INTERVAL * 2); /* lifetime - twice RA retransmit */ | if ((IN6_IS_ADDR_UNSPECIFIED(a) && parm.glob_pref_time == 0) || |
/* zero means "self" */ | (IN6_IS_ADDR_ULA_ZERO(a) && parm.ula_pref_time == 0) || |
for (i = 0; i < opt_cfg->len; i += IN6ADDRSZ, a++) | (IN6_IS_ADDR_LINK_LOCAL_ZERO(a) && parm.link_pref_time == 0)) |
if (IN6_IS_ADDR_UNSPECIFIED(a)) | len -= IN6ADDRSZ; |
put_opt6(&parm.link_global, IN6ADDRSZ); | |
else | if (len != 0) |
put_opt6(a, IN6ADDRSZ); | { |
| put_opt6_char(ICMP6_OPT_RDNSS); |
| put_opt6_char((len/8) + 1); |
| put_opt6_short(0); |
| put_opt6_long(min_pref_time); |
| |
| for (a = (struct in6_addr *)opt_cfg->val, i = 0; i < opt_cfg->len; i += IN6ADDRSZ, a++) |
| if (IN6_IS_ADDR_UNSPECIFIED(a)) |
| { |
| if (parm.glob_pref_time != 0) |
| put_opt6(&parm.link_global, IN6ADDRSZ); |
| } |
| else if (IN6_IS_ADDR_ULA_ZERO(a)) |
| { |
| if (parm.ula_pref_time != 0) |
| put_opt6(&parm.ula, IN6ADDRSZ); |
| } |
| else if (IN6_IS_ADDR_LINK_LOCAL_ZERO(a)) |
| { |
| if (parm.link_pref_time != 0) |
| put_opt6(&parm.link_local, IN6ADDRSZ); |
| } |
| else |
| put_opt6(a, IN6ADDRSZ); |
| } |
} |
} |
|
|
if (opt_cfg->opt == OPTION6_DOMAIN_SEARCH && opt_cfg->len != 0) |
if (opt_cfg->opt == OPTION6_DOMAIN_SEARCH && opt_cfg->len != 0) |
Line 291 static void send_ra(time_t now, int iface, char *iface
|
Line 514 static void send_ra(time_t now, int iface, char *iface
|
put_opt6_char(ICMP6_OPT_DNSSL); |
put_opt6_char(ICMP6_OPT_DNSSL); |
put_opt6_char(len + 1); |
put_opt6_char(len + 1); |
put_opt6_short(0); |
put_opt6_short(0); |
put_opt6_long(1800); /* lifetime - twice RA retransmit */ | put_opt6_long(min_pref_time); |
put_opt6(opt_cfg->val, opt_cfg->len); |
put_opt6(opt_cfg->val, opt_cfg->len); |
|
|
/* pad */ |
/* pad */ |
Line 300 static void send_ra(time_t now, int iface, char *iface
|
Line 523 static void send_ra(time_t now, int iface, char *iface
|
} |
} |
} |
} |
|
|
if (!done_dns) | if (daemon->port == NAMESERVER_PORT && !done_dns && parm.link_pref_time != 0) |
{ |
{ |
/* default == us. */ | /* default == us, as long as we are supplying DNS service. */ |
put_opt6_char(ICMP6_OPT_RDNSS); |
put_opt6_char(ICMP6_OPT_RDNSS); |
put_opt6_char(3); |
put_opt6_char(3); |
put_opt6_short(0); |
put_opt6_short(0); |
put_opt6_long(RA_INTERVAL * 2); /* lifetime - twice RA retransmit */ | put_opt6_long(min_pref_time); |
put_opt6(&parm.link_global, IN6ADDRSZ); | put_opt6(&parm.link_local, IN6ADDRSZ); |
} |
} |
|
|
/* set managed bits unless we're providing only RA on this link */ |
/* set managed bits unless we're providing only RA on this link */ |
Line 331 static void send_ra(time_t now, int iface, char *iface
|
Line 554 static void send_ra(time_t now, int iface, char *iface
|
addr.sin6_scope_id = iface; |
addr.sin6_scope_id = iface; |
} |
} |
else |
else |
inet_pton(AF_INET6, ALL_NODES, &addr.sin6_addr); | { |
| inet_pton(AF_INET6, ALL_NODES, &addr.sin6_addr); |
| setsockopt(daemon->icmp6fd, IPPROTO_IPV6, IPV6_MULTICAST_IF, &send_iface, sizeof(send_iface)); |
| } |
|
|
send_from(daemon->icmp6fd, 0, daemon->outpacket.iov_base, save_counter(0), | #ifdef HAVE_DUMPFILE |
(union mysockaddr *)&addr, (struct all_addr *)&parm.link_local, iface); | { |
| struct sockaddr_in6 src; |
| src.sin6_family = AF_INET6; |
| src.sin6_addr = parm.link_local; |
| |
| dump_packet_icmp(DUMP_RA, (void *)daemon->outpacket.iov_base, save_counter(-1), (union mysockaddr *)&src, (union mysockaddr *)&addr); |
| } |
| #endif |
| |
| while (retry_send(sendto(daemon->icmp6fd, daemon->outpacket.iov_base, |
| save_counter(-1), 0, (struct sockaddr *)&addr, |
| sizeof(addr)))); |
|
|
} |
} |
|
|
|
static void send_ra(time_t now, int iface, char *iface_name, struct in6_addr *dest) |
|
{ |
|
/* Send an RA on the same interface that the RA content is based |
|
on. */ |
|
send_ra_alias(now, iface, iface_name, dest, iface); |
|
} |
|
|
static int add_prefixes(struct in6_addr *local, int prefix, |
static int add_prefixes(struct in6_addr *local, int prefix, |
int scope, int if_index, int flags, |
int scope, int if_index, int flags, |
unsigned int preferred, unsigned int valid, void *vparam) |
unsigned int preferred, unsigned int valid, void *vparam) |
Line 349 static int add_prefixes(struct in6_addr *local, int p
|
Line 593 static int add_prefixes(struct in6_addr *local, int p
|
if (if_index == param->ind) |
if (if_index == param->ind) |
{ |
{ |
if (IN6_IS_ADDR_LINKLOCAL(local)) |
if (IN6_IS_ADDR_LINKLOCAL(local)) |
param->link_local = *local; | { |
| /* Can there be more than one LL address? |
| Select the one with the longest preferred time |
| if there is. */ |
| if (preferred > param->link_pref_time) |
| { |
| param->link_pref_time = preferred; |
| param->link_local = *local; |
| } |
| } |
else if (!IN6_IS_ADDR_LOOPBACK(local) && |
else if (!IN6_IS_ADDR_LOOPBACK(local) && |
!IN6_IS_ADDR_MULTICAST(local)) |
!IN6_IS_ADDR_MULTICAST(local)) |
{ |
{ |
int do_prefix = 0; | int real_prefix = 0; |
int do_slaac = 0; |
int do_slaac = 0; |
int deprecate = 0; |
int deprecate = 0; |
int constructed = 0; |
int constructed = 0; |
|
int adv_router = 0; |
|
int off_link = 0; |
unsigned int time = 0xffffffff; |
unsigned int time = 0xffffffff; |
struct dhcp_context *context; |
struct dhcp_context *context; |
|
|
for (context = daemon->dhcp6; context; context = context->next) |
for (context = daemon->dhcp6; context; context = context->next) |
if (!(context->flags & CONTEXT_TEMPLATE) && | if (!(context->flags & (CONTEXT_TEMPLATE | CONTEXT_OLD)) && |
prefix == context->prefix && | prefix <= context->prefix && |
is_same_net6(local, &context->start6, prefix) && | is_same_net6(local, &context->start6, context->prefix) && |
is_same_net6(local, &context->end6, prefix)) | is_same_net6(local, &context->end6, context->prefix)) |
{ |
{ |
if ((context->flags & | context->saved_valid = valid; |
(CONTEXT_RA_ONLY | CONTEXT_RA_NAME | CONTEXT_RA_STATELESS))) | |
| if (context->flags & CONTEXT_RA) |
{ |
{ |
do_slaac = 1; |
do_slaac = 1; |
if (context->flags & CONTEXT_DHCP) |
if (context->flags & CONTEXT_DHCP) |
Line 385 static int add_prefixes(struct in6_addr *local, int p
|
Line 641 static int add_prefixes(struct in6_addr *local, int p
|
param->managed = 1; |
param->managed = 1; |
param->other = 1; |
param->other = 1; |
} |
} |
| |
/* find floor time, don't reduce below RA interval. */ | /* Configured to advertise router address, not prefix. See RFC 3775 7.2 |
if (time > context->lease_time) | In this case we do all addresses associated with a context, |
| hence the real_prefix setting here. */ |
| if (context->flags & CONTEXT_RA_ROUTER) |
{ |
{ |
|
adv_router = 1; |
|
param->adv_router = 1; |
|
real_prefix = context->prefix; |
|
} |
|
|
|
/* find floor time, don't reduce below 3 * RA interval. |
|
If the lease time has been left as default, don't |
|
use that as a floor. */ |
|
if ((context->flags & CONTEXT_SETLEASE) && |
|
time > context->lease_time) |
|
{ |
time = context->lease_time; |
time = context->lease_time; |
if (time < ((unsigned int)RA_INTERVAL)) | if (time < ((unsigned int)(3 * param->adv_interval))) |
time = RA_INTERVAL; | time = 3 * param->adv_interval; |
} |
} |
|
|
if (context->flags & CONTEXT_DEPRECATE) |
if (context->flags & CONTEXT_DEPRECATE) |
Line 411 static int add_prefixes(struct in6_addr *local, int p
|
Line 680 static int add_prefixes(struct in6_addr *local, int p
|
/* subsequent prefixes on the same interface |
/* subsequent prefixes on the same interface |
and subsequent instances of this prefix don't need timers. |
and subsequent instances of this prefix don't need timers. |
Be careful not to find the same prefix twice with different |
Be careful not to find the same prefix twice with different |
addresses. */ | addresses unless we're advertising the actual addresses. */ |
if (!(context->flags & CONTEXT_RA_DONE)) |
if (!(context->flags & CONTEXT_RA_DONE)) |
{ |
{ |
if (!param->first) |
if (!param->first) |
context->ra_time = 0; |
context->ra_time = 0; |
context->flags |= CONTEXT_RA_DONE; |
context->flags |= CONTEXT_RA_DONE; |
do_prefix = 1; | real_prefix = context->prefix; |
| off_link = (context->flags & CONTEXT_RA_OFF_LINK); |
} |
} |
|
|
param->first = 0; | param->first = 0; |
param->found_context = 1; | /* found_context is the _last_ one we found, so if there's |
| more than one, it's not the first. */ |
| param->found_context = context; |
} |
} |
|
|
/* configured time is ceiling */ |
/* configured time is ceiling */ |
Line 437 static int add_prefixes(struct in6_addr *local, int p
|
Line 709 static int add_prefixes(struct in6_addr *local, int p
|
/* configured time is ceiling */ |
/* configured time is ceiling */ |
if (!constructed || preferred > time) |
if (!constructed || preferred > time) |
preferred = time; |
preferred = time; |
| |
if (preferred > param->pref_time) | if (IN6_IS_ADDR_ULA(local)) |
{ |
{ |
param->pref_time = preferred; | if (preferred > param->ula_pref_time) |
param->link_global = *local; | { |
| param->ula_pref_time = preferred; |
| param->ula = *local; |
| } |
} |
} |
|
else |
|
{ |
|
if (preferred > param->glob_pref_time) |
|
{ |
|
param->glob_pref_time = preferred; |
|
param->link_global = *local; |
|
} |
|
} |
|
|
if (do_prefix) | if (real_prefix != 0) |
{ |
{ |
struct prefix_opt *opt; |
struct prefix_opt *opt; |
|
|
if ((opt = expand(sizeof(struct prefix_opt)))) |
if ((opt = expand(sizeof(struct prefix_opt)))) |
{ |
{ |
/* zero net part of address */ |
/* zero net part of address */ |
setaddr6part(local, addr6part(local) & ~((prefix == 64) ? (u64)-1LL : (1LLU << (128 - prefix)) - 1LLU)); | if (!adv_router) |
| setaddr6part(local, addr6part(local) & ~((real_prefix == 64) ? (u64)-1LL : (1LLU << (128 - real_prefix)) - 1LLU)); |
|
|
opt->type = ICMP6_OPT_PREFIX; |
opt->type = ICMP6_OPT_PREFIX; |
opt->len = 4; |
opt->len = 4; |
opt->prefix_len = prefix; | opt->prefix_len = real_prefix; |
/* autonomous only if we're not doing dhcp, always set "on-link" */ | /* autonomous only if we're not doing dhcp, set |
opt->flags = do_slaac ? 0xC0 : 0x80; | "on-link" unless "off-link" was specified */ |
| opt->flags = (off_link ? 0 : 0x80); |
| if (do_slaac) |
| opt->flags |= 0x40; |
| if (adv_router) |
| opt->flags |= 0x20; |
opt->valid_lifetime = htonl(valid); |
opt->valid_lifetime = htonl(valid); |
opt->preferred_lifetime = htonl(preferred); |
opt->preferred_lifetime = htonl(preferred); |
opt->reserved = 0; |
opt->reserved = 0; |
opt->prefix = *local; |
opt->prefix = *local; |
|
|
inet_ntop(AF_INET6, local, daemon->addrbuff, ADDRSTRLEN); |
inet_ntop(AF_INET6, local, daemon->addrbuff, ADDRSTRLEN); |
my_syslog(MS_DHCP | LOG_INFO, "RTR-ADVERT(%s) %s", param->if_name, daemon->addrbuff); | if (!option_bool(OPT_QUIET_RA)) |
| my_syslog(MS_DHCP | LOG_INFO, "RTR-ADVERT(%s) %s", param->if_name, daemon->addrbuff); |
} |
} |
} |
} |
} |
} |
Line 482 static int add_lla(int index, unsigned int type, char
|
Line 772 static int add_lla(int index, unsigned int type, char
|
add 7 to round up */ |
add 7 to round up */ |
int len = (maclen + 9) >> 3; |
int len = (maclen + 9) >> 3; |
unsigned char *p = expand(len << 3); |
unsigned char *p = expand(len << 3); |
|
if (!p) |
|
return 1; |
memset(p, 0, len << 3); |
memset(p, 0, len << 3); |
*p++ = ICMP6_OPT_SOURCE_MAC; |
*p++ = ICMP6_OPT_SOURCE_MAC; |
*p++ = len; |
*p++ = len; |
Line 498 time_t periodic_ra(time_t now)
|
Line 790 time_t periodic_ra(time_t now)
|
struct search_param param; |
struct search_param param; |
struct dhcp_context *context; |
struct dhcp_context *context; |
time_t next_event; |
time_t next_event; |
char interface[IF_NAMESIZE+1]; | struct alias_param aparam; |
| |
param.now = now; |
param.now = now; |
param.iface = 0; |
param.iface = 0; |
|
|
Line 520 time_t periodic_ra(time_t now)
|
Line 812 time_t periodic_ra(time_t now)
|
if (!context) |
if (!context) |
break; |
break; |
|
|
/* There's a context overdue, but we can't find an interface | if ((context->flags & CONTEXT_OLD) && |
associated with it, because it's for a subnet we dont | context->if_index != 0 && |
have an interface on. Probably we're doing DHCP on | indextoname(daemon->icmp6fd, context->if_index, param.name)) |
a remote subnet via a relay. Zero the timer, since we won't | { |
ever be able to send ra's and satistfy it. */ | /* A context for an old address. We'll not find the interface by |
if (iface_enumerate(AF_INET6, ¶m, iface_search)) | looking for addresses, but we know it anyway, since the context is |
| constructed */ |
| param.iface = context->if_index; |
| new_timeout(context, param.name, now); |
| } |
| else if (iface_enumerate(AF_INET6, ¶m, iface_search)) |
| /* There's a context overdue, but we can't find an interface |
| associated with it, because it's for a subnet we dont |
| have an interface on. Probably we're doing DHCP on |
| a remote subnet via a relay. Zero the timer, since we won't |
| ever be able to send ra's and satisfy it. */ |
context->ra_time = 0; |
context->ra_time = 0; |
else if (param.iface != 0 && | |
indextoname(daemon->icmp6fd, param.iface, interface) && | if (param.iface != 0 && |
iface_check(AF_LOCAL, NULL, interface, NULL)) | iface_check(AF_LOCAL, NULL, param.name, NULL)) |
{ |
{ |
struct iname *tmp; |
struct iname *tmp; |
for (tmp = daemon->dhcp_except; tmp; tmp = tmp->next) |
for (tmp = daemon->dhcp_except; tmp; tmp = tmp->next) |
if (tmp->name && wildcard_match(tmp->name, interface)) | if (tmp->name && wildcard_match(tmp->name, param.name)) |
break; |
break; |
if (!tmp) |
if (!tmp) |
send_ra(now, param.iface, interface, NULL); | { |
| send_ra(now, param.iface, param.name, NULL); |
| |
| /* Also send on all interfaces that are aliases of this |
| one. */ |
| for (aparam.bridge = daemon->bridges; |
| aparam.bridge; |
| aparam.bridge = aparam.bridge->next) |
| if ((int)if_nametoindex(aparam.bridge->iface) == param.iface) |
| { |
| /* Count the number of alias interfaces for this |
| 'bridge', by calling iface_enumerate with |
| send_ra_to_aliases and NULL alias_ifs. */ |
| aparam.iface = param.iface; |
| aparam.alias_ifs = NULL; |
| aparam.num_alias_ifs = 0; |
| iface_enumerate(AF_LOCAL, &aparam, send_ra_to_aliases); |
| my_syslog(MS_DHCP | LOG_INFO, "RTR-ADVERT(%s) %s => %d alias(es)", |
| param.name, daemon->addrbuff, aparam.num_alias_ifs); |
| |
| /* Allocate memory to store the alias interface |
| indices. */ |
| aparam.alias_ifs = (int *)whine_malloc(aparam.num_alias_ifs * |
| sizeof(int)); |
| if (aparam.alias_ifs) |
| { |
| /* Use iface_enumerate again to get the alias |
| interface indices, then send on each of |
| those. */ |
| aparam.max_alias_ifs = aparam.num_alias_ifs; |
| aparam.num_alias_ifs = 0; |
| iface_enumerate(AF_LOCAL, &aparam, send_ra_to_aliases); |
| for (; aparam.num_alias_ifs; aparam.num_alias_ifs--) |
| { |
| my_syslog(MS_DHCP | LOG_INFO, "RTR-ADVERT(%s) %s => i/f %d", |
| param.name, daemon->addrbuff, |
| aparam.alias_ifs[aparam.num_alias_ifs - 1]); |
| send_ra_alias(now, |
| param.iface, |
| param.name, |
| NULL, |
| aparam.alias_ifs[aparam.num_alias_ifs - 1]); |
| } |
| free(aparam.alias_ifs); |
| } |
| |
| /* The source interface can only appear in at most |
| one --bridge-interface. */ |
| break; |
| } |
| } |
} |
} |
} |
} |
return next_event; |
return next_event; |
} |
} |
| |
| static int send_ra_to_aliases(int index, unsigned int type, char *mac, size_t maclen, void *parm) |
| { |
| struct alias_param *aparam = (struct alias_param *)parm; |
| char ifrn_name[IFNAMSIZ]; |
| struct dhcp_bridge *alias; |
| |
| (void)type; |
| (void)mac; |
| (void)maclen; |
| |
| if (if_indextoname(index, ifrn_name)) |
| for (alias = aparam->bridge->alias; alias; alias = alias->next) |
| if (wildcard_matchn(alias->iface, ifrn_name, IFNAMSIZ)) |
| { |
| if (aparam->alias_ifs && (aparam->num_alias_ifs < aparam->max_alias_ifs)) |
| aparam->alias_ifs[aparam->num_alias_ifs] = index; |
| aparam->num_alias_ifs++; |
| } |
| |
| return 1; |
| } |
| |
static int iface_search(struct in6_addr *local, int prefix, |
static int iface_search(struct in6_addr *local, int prefix, |
int scope, int if_index, int flags, |
int scope, int if_index, int flags, |
int preferred, int valid, void *vparam) |
int preferred, int valid, void *vparam) |
{ |
{ |
struct search_param *param = vparam; |
struct search_param *param = vparam; |
struct dhcp_context *context; |
struct dhcp_context *context; |
| struct iname *tmp; |
| |
(void)scope; |
(void)scope; |
(void)preferred; |
(void)preferred; |
(void)valid; |
(void)valid; |
| |
| /* ignore interfaces we're not doing DHCP on. */ |
| if (!indextoname(daemon->icmp6fd, if_index, param->name) || |
| !iface_check(AF_LOCAL, NULL, param->name, NULL)) |
| return 1; |
| |
| for (tmp = daemon->dhcp_except; tmp; tmp = tmp->next) |
| if (tmp->name && wildcard_match(tmp->name, param->name)) |
| return 1; |
| |
for (context = daemon->dhcp6; context; context = context->next) |
for (context = daemon->dhcp6; context; context = context->next) |
if (!(context->flags & CONTEXT_TEMPLATE) && | if (!(context->flags & (CONTEXT_TEMPLATE | CONTEXT_OLD)) && |
prefix == context->prefix && | prefix <= context->prefix && |
is_same_net6(local, &context->start6, prefix) && | is_same_net6(local, &context->start6, context->prefix) && |
is_same_net6(local, &context->end6, prefix) && | is_same_net6(local, &context->end6, context->prefix) && |
context->ra_time != 0 && |
context->ra_time != 0 && |
difftime(context->ra_time, param->now) <= 0.0) |
difftime(context->ra_time, param->now) <= 0.0) |
{ |
{ |
/* found an interface that's overdue for RA determine new |
/* found an interface that's overdue for RA determine new |
timeout value and arrange for RA to be sent unless interface is |
timeout value and arrange for RA to be sent unless interface is |
still doing DAD.*/ |
still doing DAD.*/ |
|
|
if (!(flags & IFACE_TENTATIVE)) |
if (!(flags & IFACE_TENTATIVE)) |
param->iface = if_index; |
param->iface = if_index; |
|
|
if (difftime(param->now, context->ra_short_period_start) < 60.0) | new_timeout(context, param->name, param->now); |
/* range 5 - 20 */ | |
context->ra_time = param->now + 5 + (rand16()/4400); | |
else | |
/* range 3/4 - 1 times RA_INTERVAL */ | |
context->ra_time = param->now + (3 * RA_INTERVAL)/4 + ((RA_INTERVAL * (unsigned int)rand16()) >> 18); | |
|
|
/* zero timers for other contexts on the same subnet, so they don't timeout |
/* zero timers for other contexts on the same subnet, so they don't timeout |
independently */ |
independently */ |
for (context = context->next; context; context = context->next) |
for (context = context->next; context; context = context->next) |
if (prefix == context->prefix && | if (prefix <= context->prefix && |
is_same_net6(local, &context->start6, prefix) && | is_same_net6(local, &context->start6, context->prefix) && |
is_same_net6(local, &context->end6, prefix)) | is_same_net6(local, &context->end6, context->prefix)) |
context->ra_time = 0; |
context->ra_time = 0; |
|
|
return 0; /* found, abort */ |
return 0; /* found, abort */ |
Line 588 static int iface_search(struct in6_addr *local, int p
|
Line 966 static int iface_search(struct in6_addr *local, int p
|
|
|
return 1; /* keep searching */ |
return 1; /* keep searching */ |
} |
} |
|
|
|
static void new_timeout(struct dhcp_context *context, char *iface_name, time_t now) |
|
{ |
|
if (difftime(now, context->ra_short_period_start) < 60.0) |
|
/* range 5 - 20 */ |
|
context->ra_time = now + 5 + (rand16()/4400); |
|
else |
|
{ |
|
/* range 3/4 - 1 times MaxRtrAdvInterval */ |
|
unsigned int adv_interval = calc_interval(find_iface_param(iface_name)); |
|
context->ra_time = now + (3 * adv_interval)/4 + ((adv_interval * (unsigned int)rand16()) >> 18); |
|
} |
|
} |
|
|
|
static struct ra_interface *find_iface_param(char *iface) |
|
{ |
|
struct ra_interface *ra; |
|
|
|
for (ra = daemon->ra_interfaces; ra; ra = ra->next) |
|
if (wildcard_match(ra->name, iface)) |
|
return ra; |
|
|
|
return NULL; |
|
} |
|
|
|
static unsigned int calc_interval(struct ra_interface *ra) |
|
{ |
|
int interval = 600; |
|
|
|
if (ra && ra->interval != 0) |
|
{ |
|
interval = ra->interval; |
|
if (interval > 1800) |
|
interval = 1800; |
|
else if (interval < 4) |
|
interval = 4; |
|
} |
|
|
|
return (unsigned int)interval; |
|
} |
|
|
|
static unsigned int calc_lifetime(struct ra_interface *ra) |
|
{ |
|
int lifetime, interval = (int)calc_interval(ra); |
|
|
|
if (!ra || ra->lifetime == -1) /* not specified */ |
|
lifetime = 3 * interval; |
|
else |
|
{ |
|
lifetime = ra->lifetime; |
|
if (lifetime < interval && lifetime != 0) |
|
lifetime = interval; |
|
else if (lifetime > 9000) |
|
lifetime = 9000; |
|
} |
|
|
|
return (unsigned int)lifetime; |
|
} |
|
|
|
static unsigned int calc_prio(struct ra_interface *ra) |
|
{ |
|
if (ra) |
|
return ra->prio; |
|
|
|
return 0; |
|
} |
|
|
#endif |
#endif |