X-Git-Url: https://git.tcpdump.org/tcpdump/blobdiff_plain/393b47892732e2e4c86e1560713dd8c4144ce0da..da20bc56d6100b5275d6f85c4a25bac1dab4e57e:/print-bootp.c diff --git a/print-bootp.c b/print-bootp.c index 7f42492d..737c5afc 100644 --- a/print-bootp.c +++ b/print-bootp.c @@ -17,20 +17,19 @@ * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED * WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. - * - * Format and print bootp packets. */ -#define NETDISSECT_REWORKED +/* \summary: BOOTP and IPv4 DHCP printer */ + #ifdef HAVE_CONFIG_H #include "config.h" #endif -#include +#include #include -#include "interface.h" +#include "netdissect.h" #include "addrtoname.h" #include "extract.h" @@ -195,6 +194,8 @@ struct bootp { /* RFC 3442 */ #define TAG_CLASSLESS_STATIC_RT ((uint8_t) 121) #define TAG_CLASSLESS_STA_RT_MS ((uint8_t) 249) +/* RFC 5859 - TFTP Server Address Option for DHCPv4 */ +#define TAG_TFTP_SERVER_ADDRESS ((uint8_t) 150) /* ftp://ftp.isi.edu/.../assignments/bootp-dhcp-extensions */ #define TAG_SLP_NAMING_AUTH ((uint8_t) 80) #define TAG_CLIENT_FQDN ((uint8_t) 81) @@ -211,8 +212,9 @@ struct bootp { #define TAG_CLIENT_GUID ((uint8_t) 97) #define TAG_LDAP_URL ((uint8_t) 95) #define TAG_6OVER4 ((uint8_t) 96) -#define TAG_PRINTER_NAME ((uint8_t) 100) -#define TAG_MDHCP_SERVER ((uint8_t) 101) +/* RFC 4833, TZ codes */ +#define TAG_TZ_PCODE ((uint8_t) 100) +#define TAG_TZ_TCODE ((uint8_t) 101) #define TAG_IPX_COMPAT ((uint8_t) 110) #define TAG_NETINFO_PARENT ((uint8_t) 112) #define TAG_NETINFO_PARENT_TAG ((uint8_t) 113) @@ -220,6 +222,7 @@ struct bootp { #define TAG_FAILOVER ((uint8_t) 115) #define TAG_EXTENDED_REQUEST ((uint8_t) 126) #define TAG_EXTENDED_OPTION ((uint8_t) 127) +#define TAG_MUDURL ((uint8_t) 161) /* DHCP Message types (values for TAG_DHCP_MESSAGE option) */ #define DHCPDISCOVER 1 @@ -290,6 +293,7 @@ bootp_print(netdissect_options *ndo, ND_PRINT((ndo, "BOOTP/DHCP, %s", tok2str(bootp_op_values, "unknown (0x%02x)", bp->bp_op))); + ND_TCHECK(bp->bp_hlen); if (bp->bp_htype == 1 && bp->bp_hlen == 6 && bp->bp_op == BOOTPREQUEST) { ND_TCHECK2(bp->bp_chaddr[0], 6); ND_PRINT((ndo, " from %s", etheraddr_string(ndo, bp->bp_chaddr))); @@ -313,34 +317,35 @@ bootp_print(netdissect_options *ndo, /* Only print interesting fields */ if (bp->bp_hops) ND_PRINT((ndo, ", hops %d", bp->bp_hops)); - if (EXTRACT_32BITS(&bp->bp_xid)) - ND_PRINT((ndo, ", xid 0x%x", EXTRACT_32BITS(&bp->bp_xid))); - if (EXTRACT_16BITS(&bp->bp_secs)) - ND_PRINT((ndo, ", secs %d", EXTRACT_16BITS(&bp->bp_secs))); + if (EXTRACT_BE_U_4(&bp->bp_xid)) + ND_PRINT((ndo, ", xid 0x%x", EXTRACT_BE_U_4(&bp->bp_xid))); + if (EXTRACT_BE_U_2(&bp->bp_secs)) + ND_PRINT((ndo, ", secs %d", EXTRACT_BE_U_2(&bp->bp_secs))); + ND_TCHECK(bp->bp_flags); ND_PRINT((ndo, ", Flags [%s]", - bittok2str(bootp_flag_values, "none", EXTRACT_16BITS(&bp->bp_flags)))); + bittok2str(bootp_flag_values, "none", EXTRACT_BE_U_2(&bp->bp_flags)))); if (ndo->ndo_vflag > 1) - ND_PRINT((ndo, " (0x%04x)", EXTRACT_16BITS(&bp->bp_flags))); + ND_PRINT((ndo, " (0x%04x)", EXTRACT_BE_U_2(&bp->bp_flags))); /* Client's ip address */ ND_TCHECK(bp->bp_ciaddr); - if (EXTRACT_32BITS(&bp->bp_ciaddr.s_addr)) + if (EXTRACT_BE_U_4(&bp->bp_ciaddr.s_addr)) ND_PRINT((ndo, "\n\t Client-IP %s", ipaddr_string(ndo, &bp->bp_ciaddr))); /* 'your' ip address (bootp client) */ ND_TCHECK(bp->bp_yiaddr); - if (EXTRACT_32BITS(&bp->bp_yiaddr.s_addr)) + if (EXTRACT_BE_U_4(&bp->bp_yiaddr.s_addr)) ND_PRINT((ndo, "\n\t Your-IP %s", ipaddr_string(ndo, &bp->bp_yiaddr))); /* Server's ip address */ ND_TCHECK(bp->bp_siaddr); - if (EXTRACT_32BITS(&bp->bp_siaddr.s_addr)) + if (EXTRACT_BE_U_4(&bp->bp_siaddr.s_addr)) ND_PRINT((ndo, "\n\t Server-IP %s", ipaddr_string(ndo, &bp->bp_siaddr))); /* Gateway's ip address */ ND_TCHECK(bp->bp_giaddr); - if (EXTRACT_32BITS(&bp->bp_giaddr.s_addr)) + if (EXTRACT_BE_U_4(&bp->bp_giaddr.s_addr)) ND_PRINT((ndo, "\n\t Gateway-IP %s", ipaddr_string(ndo, &bp->bp_giaddr))); /* Client's Ethernet address */ @@ -349,20 +354,22 @@ bootp_print(netdissect_options *ndo, ND_PRINT((ndo, "\n\t Client-Ethernet-Address %s", etheraddr_string(ndo, bp->bp_chaddr))); } - ND_TCHECK2(bp->bp_sname[0], 1); /* check first char only */ - if (*bp->bp_sname) { + ND_TCHECK_1(bp->bp_sname); /* check first char only */ + if (EXTRACT_U_1(bp->bp_sname)) { ND_PRINT((ndo, "\n\t sname \"")); - if (fn_print(ndo, bp->bp_sname, ndo->ndo_snapend)) { + if (fn_printztn(ndo, bp->bp_sname, (u_int)sizeof bp->bp_sname, + ndo->ndo_snapend)) { ND_PRINT((ndo, "\"")); ND_PRINT((ndo, "%s", tstr + 1)); return; } ND_PRINT((ndo, "\"")); } - ND_TCHECK2(bp->bp_file[0], 1); /* check first char only */ - if (*bp->bp_file) { + ND_TCHECK_1(bp->bp_file); /* check first char only */ + if (EXTRACT_U_1(bp->bp_file)) { ND_PRINT((ndo, "\n\t file \"")); - if (fn_print(ndo, bp->bp_file, ndo->ndo_snapend)) { + if (fn_printztn(ndo, bp->bp_file, (u_int)sizeof bp->bp_file, + ndo->ndo_snapend)) { ND_PRINT((ndo, "\"")); ND_PRINT((ndo, "%s", tstr + 1)); return; @@ -381,7 +388,7 @@ bootp_print(netdissect_options *ndo, else { uint32_t ul; - ul = EXTRACT_32BITS(&bp->bp_vend); + ul = EXTRACT_BE_U_4(&bp->bp_vend); if (ul != 0) ND_PRINT((ndo, "\n\t Vendor-#0x%x", ul)); } @@ -400,7 +407,7 @@ trunc: * s - short (16 bits) * b - period-seperated decimal bytes (variable length) * x - colon-seperated hex bytes (variable length) - * a - ascii string (variable length) + * a - ASCII string (variable length) * B - on/off (8 bits) * $ - special (explicit code to handle) */ @@ -418,7 +425,7 @@ static const struct tok tag2str[] = { { TAG_LPR_SERVER, "iLPR-Server" }, /* lpr server (RFC1179) */ { TAG_IMPRESS_SERVER, "iIM" }, /* impress servers (Imagen) */ { TAG_RLP_SERVER, "iRL" }, /* resource location (RFC887) */ - { TAG_HOSTNAME, "aHostname" }, /* ascii hostname */ + { TAG_HOSTNAME, "aHostname" }, /* ASCII hostname */ { TAG_BOOTSIZE, "sBS" }, /* 512 byte blocks */ { TAG_END, " END" }, /* RFC1497 tags */ @@ -500,6 +507,8 @@ static const struct tok tag2str[] = { /* RFC 3442 */ { TAG_CLASSLESS_STATIC_RT, "$Classless-Static-Route" }, { TAG_CLASSLESS_STA_RT_MS, "$Classless-Static-Route-Microsoft" }, +/* RFC 5859 - TFTP Server Address Option for DHCPv4 */ + { TAG_TFTP_SERVER_ADDRESS, "iTFTP-Server-Address" }, /* http://www.iana.org/assignments/bootp-dhcp-extensions/index.htm */ { TAG_SLP_NAMING_AUTH, "aSLP-NA" }, { TAG_CLIENT_FQDN, "$FQDN" }, @@ -516,13 +525,14 @@ static const struct tok tag2str[] = { { TAG_CLIENT_GUID, "bGUID" }, /* XXX 'b' */ { TAG_LDAP_URL, "aLDAP" }, { TAG_6OVER4, "i6o4" }, - { TAG_PRINTER_NAME, "aPRTR" }, - { TAG_MDHCP_SERVER, "bMDHCP" }, /* XXX 'b' */ + { TAG_TZ_PCODE, "aPOSIX-TZ" }, + { TAG_TZ_TCODE, "aTZ-Name" }, { TAG_IPX_COMPAT, "bIPX" }, /* XXX 'b' */ { TAG_NETINFO_PARENT, "iNI" }, { TAG_NETINFO_PARENT_TAG, "aNITAG" }, { TAG_URL, "aURL" }, { TAG_FAILOVER, "bFAIL" }, /* XXX 'b' */ + { TAG_MUDURL, "aMUD-URL" }, { 0, NULL } }; /* 2-byte extended tags */ @@ -597,19 +607,20 @@ rfc1048_print(netdissect_options *ndo, ND_PRINT((ndo, "\n\t Vendor-rfc1048 Extensions")); /* Step over magic cookie */ - ND_PRINT((ndo, "\n\t Magic Cookie 0x%08x", EXTRACT_32BITS(bp))); + ND_PRINT((ndo, "\n\t Magic Cookie 0x%08x", EXTRACT_BE_U_4(bp))); bp += sizeof(int32_t); /* Loop while we there is a tag left in the buffer */ - while (ND_TTEST2(*bp, 1)) { - tag = *bp++; + while (ND_TTEST_1(bp)) { + tag = EXTRACT_U_1(bp); + bp++; if (tag == TAG_PAD && ndo->ndo_vflag < 3) continue; if (tag == TAG_END && ndo->ndo_vflag < 3) return; if (tag == TAG_EXTENDED_OPTION) { - ND_TCHECK2(*(bp + 1), 2); - tag = EXTRACT_16BITS(bp + 1); + ND_TCHECK_2(bp + 1); + tag = EXTRACT_BE_U_2(bp + 1); /* XXX we don't know yet if the IANA will * preclude overlap of 1-byte and 2-byte spaces. * If not, we need to offset tag after this step. @@ -623,8 +634,9 @@ rfc1048_print(netdissect_options *ndo, len = 0; else { /* Get the length; check for truncation */ - ND_TCHECK2(*bp, 1); - len = *bp++; + ND_TCHECK_1(bp); + len = EXTRACT_U_1(bp); + bp++; } ND_PRINT((ndo, "\n\t %s Option %u, length %u%s", cp, tag, len, @@ -632,7 +644,8 @@ rfc1048_print(netdissect_options *ndo, if (tag == TAG_PAD && ndo->ndo_vflag > 2) { u_int ntag = 1; - while (ND_TTEST2(*bp, 1) && *bp == TAG_PAD) { + while (ND_TTEST_1(bp) && + EXTRACT_U_1(bp) == TAG_PAD) { bp++; ntag++; } @@ -646,7 +659,8 @@ rfc1048_print(netdissect_options *ndo, } if (tag == TAG_DHCP_MESSAGE && len == 1) { - uc = *bp++; + uc = EXTRACT_U_1(bp); + bp++; ND_PRINT((ndo, "%s", tok2str(dhcp_msg_values, "Unknown (%u)", uc))); continue; } @@ -654,7 +668,8 @@ rfc1048_print(netdissect_options *ndo, if (tag == TAG_PARM_REQUEST) { idx = 0; while (len-- > 0) { - uc = *bp++; + uc = EXTRACT_U_1(bp); + bp++; cp = tok2str(tag2str, "?Option %u", uc); if (idx % 4 == 0) ND_PRINT((ndo, "\n\t ")); @@ -670,7 +685,7 @@ rfc1048_print(netdissect_options *ndo, first = 1; while (len > 1) { len -= 2; - us = EXTRACT_16BITS(bp); + us = EXTRACT_BE_U_2(bp); bp += 2; cp = tok2str(xtag2str, "?xT%u", us); if (!first) @@ -695,7 +710,7 @@ rfc1048_print(netdissect_options *ndo, switch (c) { case 'a': - /* ascii strings */ + /* ASCII strings */ ND_PRINT((ndo, "\"")); if (fn_printn(ndo, bp, len, ndo->ndo_snapend)) { ND_PRINT((ndo, "\"")); @@ -713,7 +728,7 @@ rfc1048_print(netdissect_options *ndo, while (len >= sizeof(ul)) { if (!first) ND_PRINT((ndo, ",")); - ul = EXTRACT_32BITS(bp); + ul = EXTRACT_BE_U_4(bp); if (c == 'i') { ul = htonl(ul); ND_PRINT((ndo, "%s", ipaddr_string(ndo, &ul))); @@ -748,7 +763,7 @@ rfc1048_print(netdissect_options *ndo, while (len >= sizeof(us)) { if (!first) ND_PRINT((ndo, ",")); - us = EXTRACT_16BITS(bp); + us = EXTRACT_BE_U_2(bp); ND_PRINT((ndo, "%u", us)); bp += sizeof(us); len -= sizeof(us); @@ -759,9 +774,11 @@ rfc1048_print(netdissect_options *ndo, case 'B': /* boolean */ while (len > 0) { + uint8_t bool_value; if (!first) ND_PRINT((ndo, ",")); - switch (*bp) { + bool_value = EXTRACT_U_1(bp); + switch (bool_value) { case 0: ND_PRINT((ndo, "N")); break; @@ -769,7 +786,7 @@ rfc1048_print(netdissect_options *ndo, ND_PRINT((ndo, "Y")); break; default: - ND_PRINT((ndo, "%u?", *bp)); + ND_PRINT((ndo, "%u?", bool_value)); break; } ++bp; @@ -783,12 +800,14 @@ rfc1048_print(netdissect_options *ndo, default: /* Bytes */ while (len > 0) { + uint8_t byte_value; if (!first) ND_PRINT((ndo, c == 'x' ? ":" : ".")); + byte_value = EXTRACT_U_1(bp); if (c == 'x') - ND_PRINT((ndo, "%02x", *bp)); + ND_PRINT((ndo, "%02x", byte_value)); else - ND_PRINT((ndo, "%u", *bp)); + ND_PRINT((ndo, "%u", byte_value)); ++bp; --len; first = 0; @@ -805,7 +824,8 @@ rfc1048_print(netdissect_options *ndo, ND_PRINT((ndo, "ERROR: length < 1 bytes")); break; } - tag = *bp++; + tag = EXTRACT_U_1(bp); + ++bp; --len; ND_PRINT((ndo, "%s", tok2str(nbo2str, NULL, tag))); break; @@ -816,7 +836,8 @@ rfc1048_print(netdissect_options *ndo, ND_PRINT((ndo, "ERROR: length < 1 bytes")); break; } - tag = *bp++; + tag = EXTRACT_U_1(bp); + ++bp; --len; ND_PRINT((ndo, "%s", tok2str(oo2str, NULL, tag))); break; @@ -829,11 +850,11 @@ rfc1048_print(netdissect_options *ndo, len = 0; break; } - if (*bp) - ND_PRINT((ndo, "[%s] ", client_fqdn_flags(*bp))); + if (EXTRACT_U_1(bp)) + ND_PRINT((ndo, "[%s] ", client_fqdn_flags(EXTRACT_U_1(bp)))); bp++; - if (*bp || *(bp+1)) - ND_PRINT((ndo, "%u/%u ", *bp, *(bp+1))); + if (EXTRACT_U_1(bp) || EXTRACT_U_1(bp + 1)) + ND_PRINT((ndo, "%u/%u ", EXTRACT_U_1(bp), EXTRACT_U_1(bp + 1))); bp += 2; ND_PRINT((ndo, "\"")); if (fn_printn(ndo, bp, len - 3, ndo->ndo_snapend)) { @@ -847,14 +868,15 @@ rfc1048_print(netdissect_options *ndo, case TAG_CLIENT_ID: { - int type; + int type; /* this option should be at least 1 byte long */ if (len < 1) { ND_PRINT((ndo, "ERROR: length < 1 bytes")); break; } - type = *bp++; + type = EXTRACT_U_1(bp); + bp++; len--; if (type == 0) { ND_PRINT((ndo, "\"")); @@ -871,7 +893,7 @@ rfc1048_print(netdissect_options *ndo, while (len > 0) { if (!first) ND_PRINT((ndo, ":")); - ND_PRINT((ndo, "%02x", *bp)); + ND_PRINT((ndo, "%02x", EXTRACT_U_1(bp))); ++bp; --len; first = 0; @@ -882,8 +904,9 @@ rfc1048_print(netdissect_options *ndo, case TAG_AGENT_CIRCUIT: while (len >= 2) { - subopt = *bp++; - suboptlen = *bp++; + subopt = EXTRACT_U_1(bp); + suboptlen = EXTRACT_U_1(bp + 1); + bp += 2; len -= 2; if (suboptlen > len) { ND_PRINT((ndo, "\n\t %s SubOption %u, length %u: length goes past end of option", @@ -903,7 +926,8 @@ rfc1048_print(netdissect_options *ndo, case AGENT_SUBOPTION_CIRCUIT_ID: /* fall through */ case AGENT_SUBOPTION_REMOTE_ID: case AGENT_SUBOPTION_SUBSCRIBER_ID: - fn_printn(ndo, bp, suboptlen, NULL); + if (fn_printn(ndo, bp, suboptlen, ndo->ndo_snapend)) + goto trunc; break; default: @@ -930,7 +954,8 @@ rfc1048_print(netdissect_options *ndo, while (len > 0) { if (!first) ND_PRINT((ndo, ",")); - mask_width = *bp++; + mask_width = EXTRACT_U_1(bp); + bp++; len--; /* mask_width <= 32 */ if (mask_width > 32) { @@ -954,7 +979,8 @@ rfc1048_print(netdissect_options *ndo, for (i = 0; i < significant_octets ; i++) { if (i > 0) ND_PRINT((ndo, ".")); - ND_PRINT((ndo, "%d", *bp++)); + ND_PRINT((ndo, "%d", EXTRACT_U_1(bp))); + bp++; } for (i = significant_octets ; i < 4 ; i++) ND_PRINT((ndo, ".0")); @@ -981,7 +1007,8 @@ rfc1048_print(netdissect_options *ndo, break; } while (len > 0) { - suboptlen = *bp++; + suboptlen = EXTRACT_U_1(bp); + bp++; len--; ND_PRINT((ndo, "\n\t ")); ND_PRINT((ndo, "instance#%u: ", suboptnumber)); @@ -992,7 +1019,7 @@ rfc1048_print(netdissect_options *ndo, break; } if (len < suboptlen) { - ND_PRINT((ndo, "ERROR: malformed option")); + ND_PRINT((ndo, "ERROR: invalid option")); bp += len; len = 0; break;