1 /* 2 * Copyright (C) 2002 WIDE Project. 3 * All rights reserved. 4 * 5 * Redistribution and use in source and binary forms, with or without 6 * modification, are permitted provided that the following conditions 7 * are met: 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 3. Neither the name of the project nor the names of its contributors 14 * may be used to endorse or promote products derived from this software 15 * without specific prior written permission. 16 * 17 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND 18 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 19 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 20 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE 21 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 22 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 23 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 24 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 25 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 26 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 27 * SUCH DAMAGE. 28 */ 29 30 #include <sys/cdefs.h> 31 #ifndef lint 32 __RCSID("$NetBSD: print-mobility.c,v 1.11 2026/03/19 00:05:13 christos Exp $"); 33 #endif 34 35 /* \summary: IPv6 mobility printer */ 36 /* RFC 6275 */ 37 38 #include <config.h> 39 40 #include "netdissect-stdinc.h" 41 42 #define ND_LONGJMP_FROM_TCHECK 43 #include "netdissect.h" 44 #include "addrtoname.h" 45 #include "extract.h" 46 47 #include "ip6.h" 48 49 /* Mobility header */ 50 struct ip6_mobility { 51 nd_uint8_t ip6m_pproto; /* following payload protocol (for PG) */ 52 nd_uint8_t ip6m_len; /* length in units of 8 octets */ 53 nd_uint8_t ip6m_type; /* message type */ 54 nd_uint8_t reserved; /* reserved */ 55 nd_uint16_t ip6m_cksum; /* sum of IPv6 pseudo-header and MH */ 56 union { 57 nd_uint16_t ip6m_un_data16[1]; /* type-specific field */ 58 nd_uint8_t ip6m_un_data8[2]; /* type-specific field */ 59 } ip6m_dataun; 60 }; 61 62 #define ip6m_data16 ip6m_dataun.ip6m_un_data16 63 #define ip6m_data8 ip6m_dataun.ip6m_un_data8 64 65 #define IP6M_MINLEN 8 66 67 /* https://www.iana.org/assignments/mobility-parameters/mobility-parameters.xhtml */ 68 69 /* message type */ 70 #define IP6M_BINDING_REQUEST 0 /* Binding Refresh Request */ 71 #define IP6M_HOME_TEST_INIT 1 /* Home Test Init */ 72 #define IP6M_CAREOF_TEST_INIT 2 /* Care-of Test Init */ 73 #define IP6M_HOME_TEST 3 /* Home Test */ 74 #define IP6M_CAREOF_TEST 4 /* Care-of Test */ 75 #define IP6M_BINDING_UPDATE 5 /* Binding Update */ 76 #define IP6M_BINDING_ACK 6 /* Binding Acknowledgement */ 77 #define IP6M_BINDING_ERROR 7 /* Binding Error */ 78 #define IP6M_MAX 7 79 80 static const struct tok ip6m_str[] = { 81 { IP6M_BINDING_REQUEST, "BRR" }, 82 { IP6M_HOME_TEST_INIT, "HoTI" }, 83 { IP6M_CAREOF_TEST_INIT, "CoTI" }, 84 { IP6M_HOME_TEST, "HoT" }, 85 { IP6M_CAREOF_TEST, "CoT" }, 86 { IP6M_BINDING_UPDATE, "BU" }, 87 { IP6M_BINDING_ACK, "BA" }, 88 { IP6M_BINDING_ERROR, "BE" }, 89 { 0, NULL } 90 }; 91 92 static const unsigned ip6m_hdrlen[IP6M_MAX + 1] = { 93 IP6M_MINLEN, /* IP6M_BINDING_REQUEST */ 94 IP6M_MINLEN + 8, /* IP6M_HOME_TEST_INIT */ 95 IP6M_MINLEN + 8, /* IP6M_CAREOF_TEST_INIT */ 96 IP6M_MINLEN + 16, /* IP6M_HOME_TEST */ 97 IP6M_MINLEN + 16, /* IP6M_CAREOF_TEST */ 98 IP6M_MINLEN + 8, /* IP6M_BINDING_UPDATE */ 99 IP6M_MINLEN + 8, /* IP6M_BINDING_ACK */ 100 IP6M_MINLEN + 16, /* IP6M_BINDING_ERROR */ 101 }; 102 103 /* Mobility Header Options */ 104 #define IP6MOPT_MINLEN 2 105 #define IP6MOPT_PAD1 0x0 /* Pad1 */ 106 #define IP6MOPT_PADN 0x1 /* PadN */ 107 #define IP6MOPT_REFRESH 0x2 /* Binding Refresh Advice */ 108 #define IP6MOPT_REFRESH_MINLEN 4 109 #define IP6MOPT_ALTCOA 0x3 /* Alternate Care-of Address */ 110 #define IP6MOPT_ALTCOA_MINLEN 18 111 #define IP6MOPT_NONCEID 0x4 /* Nonce Indices */ 112 #define IP6MOPT_NONCEID_MINLEN 6 113 #define IP6MOPT_AUTH 0x5 /* Binding Authorization Data */ 114 #define IP6MOPT_AUTH_MINLEN 12 115 116 static const struct tok ip6m_binding_update_bits [] = { 117 { 0x08, "A" }, 118 { 0x04, "H" }, 119 { 0x02, "L" }, 120 { 0x01, "K" }, 121 { 0, NULL } 122 }; 123 124 static int 125 mobility_opt_print(netdissect_options *ndo, 126 const u_char *bp, const unsigned len) 127 { 128 unsigned i, opttype, optlen; 129 130 for (i = 0; i < len; i += optlen) { 131 opttype = GET_U_1(bp + i); 132 if (opttype == IP6MOPT_PAD1) 133 optlen = 1; 134 else { 135 ND_ICHECKMSG_U("remaining length", (u_int)(len - i), <, 136 IP6MOPT_MINLEN); 137 optlen = GET_U_1(bp + i + 1) + 2; 138 } 139 ND_ICHECKMSG_U("remaining length", (u_int)(len - i), <, optlen); 140 ND_TCHECK_LEN(bp + i, optlen); 141 142 switch (opttype) { 143 case IP6MOPT_PAD1: 144 ND_PRINT("(pad1)"); 145 break; 146 case IP6MOPT_PADN: 147 ND_PRINT("(padn)"); 148 break; 149 case IP6MOPT_REFRESH: 150 ND_PRINT("(refresh: "); 151 ND_ICHECKMSG_U("remaining length", (u_int)(len - i), <, 152 IP6MOPT_REFRESH_MINLEN); 153 /* units of 4 secs */ 154 ND_PRINT("%u)", GET_BE_U_2(bp + i + 2) << 2); 155 break; 156 case IP6MOPT_ALTCOA: 157 ND_PRINT("(alt-CoA: "); 158 ND_ICHECKMSG_U("remaining length", (u_int)(len - i), <, 159 IP6MOPT_ALTCOA_MINLEN); 160 ND_PRINT("%s)", GET_IP6ADDR_STRING(bp + i + 2)); 161 break; 162 case IP6MOPT_NONCEID: 163 ND_PRINT("(ni: "); 164 ND_ICHECKMSG_U("remaining length", (u_int)(len - i), <, 165 IP6MOPT_NONCEID_MINLEN); 166 ND_PRINT("ho=0x%04x co=0x%04x)", 167 GET_BE_U_2(bp + i + 2), 168 GET_BE_U_2(bp + i + 4)); 169 break; 170 case IP6MOPT_AUTH: 171 ND_PRINT("(auth)"); 172 ND_ICHECKMSG_U("remaining length", (u_int)(len - i), <, 173 IP6MOPT_AUTH_MINLEN); 174 break; 175 default: 176 ND_PRINT("(unknown: "); 177 ND_PRINT("type-#%u len=%u)", opttype, optlen - 2); 178 break; 179 } 180 } 181 return 0; 182 183 invalid: 184 return 1; 185 } 186 187 /* 188 * Mobility Header 189 */ 190 int 191 mobility_print(netdissect_options *ndo, 192 const u_char *bp, const u_char *bp2 _U_) 193 { 194 const struct ip6_mobility *mh; 195 unsigned mhlen, hlen; 196 uint8_t pproto, type; 197 198 ndo->ndo_protocol = "mobility"; 199 nd_print_protocol(ndo); 200 ND_PRINT(": "); 201 mh = (const struct ip6_mobility *)bp; 202 203 pproto = GET_U_1(mh->ip6m_pproto); 204 if (pproto != IPPROTO_NONE) 205 ND_PRINT("(payload protocol %u should be %u) ", pproto, 206 IPPROTO_NONE); 207 208 mhlen = (GET_U_1(mh->ip6m_len) + 1) << 3; 209 210 /* XXX ip6m_cksum */ 211 212 type = GET_U_1(mh->ip6m_type); 213 ND_PRINT("%s", tok2str(ip6m_str, "type-#%u", type)); 214 if (type <= IP6M_MAX && mhlen < ip6m_hdrlen[type]) { 215 ND_PRINT(" (header length %u < %u)", mhlen, ip6m_hdrlen[type]); 216 goto invalid; 217 } 218 switch (type) { 219 case IP6M_BINDING_REQUEST: 220 hlen = IP6M_MINLEN; 221 break; 222 case IP6M_HOME_TEST_INIT: 223 case IP6M_CAREOF_TEST_INIT: 224 hlen = IP6M_MINLEN; 225 if (ndo->ndo_vflag) { 226 ND_PRINT(" %s Init Cookie=%08x:%08x", 227 type == IP6M_HOME_TEST_INIT ? "Home" : "Care-of", 228 GET_BE_U_4(bp + hlen), 229 GET_BE_U_4(bp + hlen + 4)); 230 } 231 hlen += 8; 232 break; 233 case IP6M_HOME_TEST: 234 case IP6M_CAREOF_TEST: 235 ND_PRINT(" nonce id=0x%x", GET_BE_U_2(mh->ip6m_data16[0])); 236 hlen = IP6M_MINLEN; 237 if (ndo->ndo_vflag) { 238 ND_PRINT(" %s Init Cookie=%08x:%08x", 239 type == IP6M_HOME_TEST ? "Home" : "Care-of", 240 GET_BE_U_4(bp + hlen), 241 GET_BE_U_4(bp + hlen + 4)); 242 } 243 hlen += 8; 244 if (ndo->ndo_vflag) { 245 ND_PRINT(" %s Keygen Token=%08x:%08x", 246 type == IP6M_HOME_TEST ? "Home" : "Care-of", 247 GET_BE_U_4(bp + hlen), 248 GET_BE_U_4(bp + hlen + 4)); 249 } 250 hlen += 8; 251 break; 252 case IP6M_BINDING_UPDATE: 253 { 254 int bits; 255 ND_PRINT(" seq#=%u", GET_BE_U_2(mh->ip6m_data16[0])); 256 hlen = IP6M_MINLEN; 257 bits = (GET_U_1(bp + hlen) & 0xf0) >> 4; 258 if (bits) { 259 ND_PRINT(" "); 260 ND_PRINT("%s", 261 bittok2str_nosep(ip6m_binding_update_bits, 262 "bits-#0x%x", bits)); 263 } 264 /* Reserved (4bits) */ 265 hlen += 1; 266 /* Reserved (8bits) */ 267 hlen += 1; 268 /* units of 4 secs */ 269 ND_PRINT(" lifetime=%u", GET_BE_U_2(bp + hlen) << 2); 270 hlen += 2; 271 break; 272 } 273 case IP6M_BINDING_ACK: 274 ND_PRINT(" status=%u", GET_U_1(mh->ip6m_data8[0])); 275 if (GET_U_1(mh->ip6m_data8[1]) & 0x80) 276 ND_PRINT(" K"); 277 /* Reserved (7bits) */ 278 hlen = IP6M_MINLEN; 279 ND_PRINT(" seq#=%u", GET_BE_U_2(bp + hlen)); 280 hlen += 2; 281 /* units of 4 secs */ 282 ND_PRINT(" lifetime=%u", GET_BE_U_2(bp + hlen) << 2); 283 hlen += 2; 284 break; 285 case IP6M_BINDING_ERROR: 286 ND_PRINT(" status=%u", GET_U_1(mh->ip6m_data8[0])); 287 /* Reserved */ 288 hlen = IP6M_MINLEN; 289 ND_PRINT(" homeaddr %s", GET_IP6ADDR_STRING(bp + hlen)); 290 hlen += 16; 291 break; 292 default: 293 ND_PRINT(" len=%u", GET_U_1(mh->ip6m_len)); 294 return(mhlen); 295 break; 296 } 297 if (ndo->ndo_vflag) 298 if (mobility_opt_print(ndo, bp + hlen, mhlen - hlen)) 299 goto invalid; 300 301 return(mhlen); 302 303 invalid: 304 nd_print_invalid(ndo); 305 return(-1); 306 } 307