]> The Tcpdump Group git mirrors - tcpdump/blobdiff - print-bootp.c
Do more bounds checking.
[tcpdump] / print-bootp.c
index 04f767ee1994703d0a601b2e93380ded9f69b509..c0077eeb23dbe30f7e085790ce5442c3d4f2f4ab 100644 (file)
  * Format and print bootp packets.
  */
 #ifndef lint
-static const char rcsid[] =
-    "@(#) $Header: /tcpdump/master/tcpdump/print-bootp.c,v 1.59 2001-07-04 21:18:12 fenner Exp $ (LBL)";
+static const char rcsid[] _U_ =
+    "@(#) $Header: /tcpdump/master/tcpdump/print-bootp.c,v 1.78.2.2 2005-05-06 04:19:39 guy Exp $ (LBL)";
 #endif
 
 #ifdef HAVE_CONFIG_H
 #include "config.h"
 #endif
 
-#include <sys/param.h>
-#include <sys/time.h>
-#include <sys/socket.h>
+#include <tcpdump-stdinc.h>
 
-struct mbuf;
-struct rtentry;
-
-#include <netinet/in.h>
-
-#include <ctype.h>
 #include <stdio.h>
 #include <string.h>
 
@@ -48,102 +40,100 @@ struct rtentry;
 #include "ether.h"
 #include "bootp.h"
 
-static void rfc1048_print(const u_char *, u_int);
-static void cmu_print(const u_char *, u_int);
+static void rfc1048_print(const u_char *);
+static void cmu_print(const u_char *);
 
 static char tstr[] = " [|bootp]";
 
+static const struct tok bootp_flag_values[] = {
+    { 0x8000,                   "Broadcast" },
+    { 0, NULL}
+};
+
+static const struct tok bootp_op_values[] = {
+    { BOOTPREQUEST,             "Request" },
+    { BOOTPREPLY,               "Reply" },
+    { 0, NULL}
+};
+
 /*
  * Print bootp requests
  */
 void
-bootp_print(register const u_char *cp, u_int length,
-           u_short sport, u_short dport)
+bootp_print(register const u_char *cp, u_int length)
 {
        register const struct bootp *bp;
-       static u_char vm_cmu[4] = VM_CMU;
-       static u_char vm_rfc1048[4] = VM_RFC1048;
+       static const u_char vm_cmu[4] = VM_CMU;
+       static const u_char vm_rfc1048[4] = VM_RFC1048;
 
-       bp = (struct bootp *)cp;
+       bp = (const struct bootp *)cp;
        TCHECK(bp->bp_op);
-       switch (bp->bp_op) {
-
-       case BOOTREQUEST:
-               /* Usually, a request goes from a client to a server */
-               if (sport != IPPORT_BOOTPC || dport != IPPORT_BOOTPS)
-                       printf(" (request)");
-               break;
-
-       case BOOTREPLY:
-               /* Usually, a reply goes from a server to a client */
-               if (sport != IPPORT_BOOTPS || dport != IPPORT_BOOTPC)
-                       printf(" (reply)");
-               break;
-
-       default:
-               printf(" bootp-#%d", bp->bp_op);
+
+        printf("BOOTP/DHCP, %s",
+              tok2str(bootp_op_values, "unknown (0x%02x)", bp->bp_op));
+
+       if (bp->bp_htype == 1 && bp->bp_hlen == 6 && bp->bp_op == BOOTPREQUEST) {
+               TCHECK2(bp->bp_chaddr[0], 6);
+               printf(" from %s", etheraddr_string(bp->bp_chaddr));
        }
 
+        printf(", length: %u", length);
+
+        if (!vflag)
+            return;
+
        TCHECK(bp->bp_secs);
 
        /* The usual hardware address type is 1 (10Mb Ethernet) */
        if (bp->bp_htype != 1)
-               printf(" htype-#%d", bp->bp_htype);
+               printf(", htype-#%d", bp->bp_htype);
 
        /* The usual length for 10Mb Ethernet address is 6 bytes */
        if (bp->bp_htype != 1 || bp->bp_hlen != 6)
-               printf(" hlen:%d", bp->bp_hlen);
+               printf(", hlen:%d", bp->bp_hlen);
 
        /* Only print interesting fields */
        if (bp->bp_hops)
-               printf(" hops:%d", bp->bp_hops);
+               printf(", hops:%d", bp->bp_hops);
        if (bp->bp_xid)
-               printf(" xid:0x%x", (u_int32_t)ntohl(bp->bp_xid));
+               printf(", xid:0x%x", EXTRACT_32BITS(&bp->bp_xid));
        if (bp->bp_secs)
-               printf(" secs:%d", ntohs(bp->bp_secs));
-       if (bp->bp_flags)
-               printf(" flags:0x%x", ntohs(bp->bp_flags));
+               printf(", secs:%d", EXTRACT_16BITS(&bp->bp_secs));
+
+       printf(", flags: [%s]",
+              bittok2str(bootp_flag_values, "none", EXTRACT_16BITS(&bp->bp_flags)));
+       if (vflag>1)
+         printf( " (0x%04x)", EXTRACT_16BITS(&bp->bp_flags));
 
        /* Client's ip address */
        TCHECK(bp->bp_ciaddr);
        if (bp->bp_ciaddr.s_addr)
-               printf(" C:%s", ipaddr_string(&bp->bp_ciaddr));
+               printf("\n\t  Client IP: %s", ipaddr_string(&bp->bp_ciaddr));
 
        /* 'your' ip address (bootp client) */
        TCHECK(bp->bp_yiaddr);
        if (bp->bp_yiaddr.s_addr)
-               printf(" Y:%s", ipaddr_string(&bp->bp_yiaddr));
+               printf("\n\t  Your IP: %s", ipaddr_string(&bp->bp_yiaddr));
 
        /* Server's ip address */
        TCHECK(bp->bp_siaddr);
        if (bp->bp_siaddr.s_addr)
-               printf(" S:%s", ipaddr_string(&bp->bp_siaddr));
+               printf("\n\t  Server IP: %s", ipaddr_string(&bp->bp_siaddr));
 
        /* Gateway's ip address */
        TCHECK(bp->bp_giaddr);
        if (bp->bp_giaddr.s_addr)
-               printf(" G:%s", ipaddr_string(&bp->bp_giaddr));
+               printf("\n\t  Gateway IP: %s", ipaddr_string(&bp->bp_giaddr));
 
        /* Client's Ethernet address */
        if (bp->bp_htype == 1 && bp->bp_hlen == 6) {
-               register const struct ether_header *eh;
-               register const char *e;
-
                TCHECK2(bp->bp_chaddr[0], 6);
-               eh = (struct ether_header *)packetp;
-               if (bp->bp_op == BOOTREQUEST)
-                       e = (const char *)ESRC(eh);
-               else if (bp->bp_op == BOOTREPLY)
-                       e = (const char *)EDST(eh);
-               else
-                       e = 0;
-               if (e == 0 || memcmp((char *)bp->bp_chaddr, e, 6) != 0)
-                       printf(" ether %s", etheraddr_string(bp->bp_chaddr));
+               printf("\n\t  Client Ethernet Address: %s", etheraddr_string(bp->bp_chaddr));
        }
 
        TCHECK2(bp->bp_sname[0], 1);            /* check first char only */
        if (*bp->bp_sname) {
-               printf(" sname \"");
+               printf("\n\t  sname \"");
                if (fn_print(bp->bp_sname, snapend)) {
                        putchar('"');
                        fputs(tstr + 1, stdout);
@@ -151,9 +141,9 @@ bootp_print(register const u_char *cp, u_int length,
                }
                putchar('"');
        }
-       TCHECK2(bp->bp_sname[0], 1);            /* check first char only */
+       TCHECK2(bp->bp_file[0], 1);             /* check first char only */
        if (*bp->bp_file) {
-               printf(" file \"");
+               printf("\n\t  file \"");
                if (fn_print(bp->bp_file, snapend)) {
                        putchar('"');
                        fputs(tstr + 1, stdout);
@@ -164,19 +154,18 @@ bootp_print(register const u_char *cp, u_int length,
 
        /* Decode the vendor buffer */
        TCHECK(bp->bp_vend[0]);
-       length -= sizeof(*bp) - sizeof(bp->bp_vend);
-       if (memcmp((char *)bp->bp_vend, (char *)vm_rfc1048,
+       if (memcmp((const char *)bp->bp_vend, vm_rfc1048,
                 sizeof(u_int32_t)) == 0)
-               rfc1048_print(bp->bp_vend, length);
-       else if (memcmp((char *)bp->bp_vend, (char *)vm_cmu,
+               rfc1048_print(bp->bp_vend);
+       else if (memcmp((const char *)bp->bp_vend, vm_cmu,
                      sizeof(u_int32_t)) == 0)
-               cmu_print(bp->bp_vend, length);
+               cmu_print(bp->bp_vend);
        else {
                u_int32_t ul;
 
                ul = EXTRACT_32BITS(&bp->bp_vend);
                if (ul != 0)
-                       printf("vend-#0x%x", ul);
+                       printf("\n\t  Vendor-#0x%x", ul);
        }
 
        return;
@@ -288,7 +277,7 @@ static struct tok tag2str[] = {
        { TAG_NS_SEARCH,        "sNSSEARCH" },  /* XXX 's' */
 /* RFC 3011 */
        { TAG_IP4_SUBNET_SELECT, "iSUBNET" },
-/* ftp://ftp.isi.edu/.../assignments/bootp-dhcp-extensions */
+/* http://www.iana.org/assignments/bootp-dhcp-extensions/index.htm */
        { TAG_USER_CLASS,       "aCLASS" },
        { TAG_SLP_NAMING_AUTH,  "aSLP-NA" },
        { TAG_CLIENT_FQDN,      "$FQDN" },
@@ -348,17 +337,18 @@ static struct tok arp2str[] = {
 };
 
 static void
-rfc1048_print(register const u_char *bp, register u_int length)
+rfc1048_print(register const u_char *bp)
 {
-       register u_char tag;
+       register u_int16_t tag;
        register u_int len, size;
        register const char *cp;
        register char c;
        int first;
        u_int32_t ul;
-       u_short us;
+       u_int16_t us;
+       u_int8_t uc;
 
-       printf(" vend-rfc1048");
+       printf("\n\t  Vendor-rfc1048:");
 
        /* Step over magic cookie */
        bp += sizeof(int32_t);
@@ -377,11 +367,11 @@ rfc1048_print(register const u_char *bp, register u_int length)
                         * preclude overlap of 1-byte and 2-byte spaces.
                         * If not, we need to offset tag after this step.
                         */
-                       cp = tok2str(xtag2str, "?xT%d", tag);
+                       cp = tok2str(xtag2str, "?xT%u", tag);
                } else
-                       cp = tok2str(tag2str, "?T%d", tag);
+                       cp = tok2str(tag2str, "?T%u", tag);
                c = *cp++;
-               printf(" %s:", cp);
+               printf("\n\t    %s:", cp);
 
                /* Get the length; check for truncation */
                if (bp + 1 >= snapend) {
@@ -390,13 +380,13 @@ rfc1048_print(register const u_char *bp, register u_int length)
                }
                len = *bp++;
                if (bp + len >= snapend) {
-                       fputs(tstr, stdout);
+                       printf("[|bootp %u]", len);
                        return;
                }
 
                if (tag == TAG_DHCP_MESSAGE && len == 1) {
-                       c = *bp++;
-                       switch (c) {
+                       uc = *bp++;
+                       switch (uc) {
                        case DHCPDISCOVER:      printf("DISCOVER");     break;
                        case DHCPOFFER:         printf("OFFER");        break;
                        case DHCPREQUEST:       printf("REQUEST");      break;
@@ -405,7 +395,7 @@ rfc1048_print(register const u_char *bp, register u_int length)
                        case DHCPNAK:           printf("NACK");         break;
                        case DHCPRELEASE:       printf("RELEASE");      break;
                        case DHCPINFORM:        printf("INFORM");       break;
-                       default:                printf("%u", c);        break;
+                       default:                printf("%u", uc);       break;
                        }
                        continue;
                }
@@ -413,8 +403,8 @@ rfc1048_print(register const u_char *bp, register u_int length)
                if (tag == TAG_PARM_REQUEST) {
                        first = 1;
                        while (len-- > 0) {
-                               c = *bp++;
-                               cp = tok2str(tag2str, "?T%d", c);
+                               uc = *bp++;
+                               cp = tok2str(tag2str, "?T%u", uc);
                                if (!first)
                                        putchar('+');
                                printf("%s", cp + 1);
@@ -426,9 +416,9 @@ rfc1048_print(register const u_char *bp, register u_int length)
                        first = 1;
                        while (len > 1) {
                                len -= 2;
-                               c = EXTRACT_16BITS(bp);
+                               us = EXTRACT_16BITS(bp);
                                bp += 2;
-                               cp = tok2str(xtag2str, "?xT%d", c);
+                               cp = tok2str(xtag2str, "?xT%u", us);
                                if (!first)
                                        putchar('+');
                                printf("%s", cp + 1);
@@ -454,7 +444,10 @@ rfc1048_print(register const u_char *bp, register u_int length)
                case 'a':
                        /* ascii strings */
                        putchar('"');
-                       (void)fn_printn(bp, size, NULL);
+                       if (fn_printn(bp, size, snapend)) {
+                               putchar('"');
+                               goto trunc;
+                       }
                        putchar('"');
                        bp += size;
                        size = 0;
@@ -486,10 +479,10 @@ rfc1048_print(register const u_char *bp, register u_int length)
                        while (size >= 2*sizeof(ul)) {
                                if (!first)
                                        putchar(',');
-                               memcpy((char *)&ul, (char *)bp, sizeof(ul));
+                               memcpy((char *)&ul, (const char *)bp, sizeof(ul));
                                printf("(%s:", ipaddr_string(&ul));
                                bp += sizeof(ul);
-                               memcpy((char *)&ul, (char *)bp, sizeof(ul));
+                               memcpy((char *)&ul, (const char *)bp, sizeof(ul));
                                printf("%s)", ipaddr_string(&ul));
                                bp += sizeof(ul);
                                size -= 2*sizeof(ul);
@@ -503,7 +496,7 @@ rfc1048_print(register const u_char *bp, register u_int length)
                                if (!first)
                                        putchar(',');
                                us = EXTRACT_16BITS(bp);
-                               printf("%d", us);
+                               printf("%u", us);
                                bp += sizeof(us);
                                size -= sizeof(us);
                                first = 0;
@@ -523,7 +516,7 @@ rfc1048_print(register const u_char *bp, register u_int length)
                                        putchar('Y');
                                        break;
                                default:
-                                       printf("%d?", *bp);
+                                       printf("%u?", *bp);
                                        break;
                                }
                                ++bp;
@@ -542,7 +535,7 @@ rfc1048_print(register const u_char *bp, register u_int length)
                                if (c == 'x')
                                        printf("%02x", *bp);
                                else
-                                       printf("%d", *bp);
+                                       printf("%u", *bp);
                                ++bp;
                                --size;
                                first = 0;
@@ -566,13 +559,21 @@ rfc1048_print(register const u_char *bp, register u_int length)
                                break;
 
                        case TAG_CLIENT_FQDN:
+                               /* option 81 should be at least 4 bytes long */
+                               if (len < 4)  {
+                                        printf("ERROR: options 81 len %u < 4 bytes", len);
+                                       break;
+                               }
                                if (*bp++)
                                        printf("[svrreg]");
                                if (*bp)
-                                       printf("%d/%d/", *bp, *(bp+1));
+                                       printf("%u/%u/", *bp, *(bp+1));
                                bp += 2;
                                putchar('"');
-                               (void)fn_printn(bp, size - 3, NULL);
+                               if (fn_printn(bp, size - 3, snapend)) {
+                                       putchar('"');
+                                       goto trunc;
+                               }
                                putchar('"');
                                bp += size - 3;
                                size = 0;
@@ -583,8 +584,13 @@ rfc1048_print(register const u_char *bp, register u_int length)
                                size--;
                                if (type == 0) {
                                        putchar('"');
-                                       (void)fn_printn(bp, size, NULL);  
+                                       if (fn_printn(bp, size, snapend)) {
+                                               putchar('"');
+                                               goto trunc;
+                                       }
                                        putchar('"');
+                                       bp += size;
+                                       size = 0;
                                        break;
                                } else {
                                        printf("[%s]", tok2str(arp2str, "type-%d", type));
@@ -601,7 +607,7 @@ rfc1048_print(register const u_char *bp, register u_int length)
                            }
 
                        default:
-                               printf("[unknown special tag %d, size %d]",
+                               printf("[unknown special tag %u, size %u]",
                                    tag, size);
                                bp += size;
                                size = 0;
@@ -610,8 +616,10 @@ rfc1048_print(register const u_char *bp, register u_int length)
                        break;
                }
                /* Data left over? */
-               if (size)
-                       printf("[len %d]", len);
+               if (size) {
+                       printf("[len %u]", len);
+                       bp += size;
+               }
        }
        return;
 trunc:
@@ -619,7 +627,7 @@ trunc:
 }
 
 static void
-cmu_print(register const u_char *bp, register u_int length)
+cmu_print(register const u_char *bp)
 {
        register const struct cmu_vend *cmu;
 
@@ -628,7 +636,7 @@ cmu_print(register const u_char *bp, register u_int length)
        printf(" %s:%s", s, ipaddr_string(&cmu->m.s_addr)); }
 
        printf(" vend-cmu");
-       cmu = (struct cmu_vend *)bp;
+       cmu = (const struct cmu_vend *)bp;
 
        /* Only print if there are unknown bits */
        TCHECK(cmu->v_flags);