bpf.c revision 1.12 1 1.12 itojun /* $NetBSD: bpf.c,v 1.12 2003/05/15 14:50:50 itojun Exp $ */
2 1.3 thorpej
3 1.1 brezak /*
4 1.1 brezak * Copyright (c) 1988, 1992 The University of Utah and the Center
5 1.1 brezak * for Software Science (CSS).
6 1.1 brezak * Copyright (c) 1992, 1993
7 1.1 brezak * The Regents of the University of California. All rights reserved.
8 1.1 brezak *
9 1.1 brezak * This code is derived from software contributed to Berkeley by
10 1.1 brezak * the Center for Software Science of the University of Utah Computer
11 1.1 brezak * Science Department. CSS requests users of this software to return
12 1.1 brezak * to css-dist (at) cs.utah.edu any improvements that they make and grant
13 1.1 brezak * CSS redistribution rights.
14 1.1 brezak *
15 1.1 brezak * Redistribution and use in source and binary forms, with or without
16 1.1 brezak * modification, are permitted provided that the following conditions
17 1.1 brezak * are met:
18 1.1 brezak * 1. Redistributions of source code must retain the above copyright
19 1.1 brezak * notice, this list of conditions and the following disclaimer.
20 1.1 brezak * 2. Redistributions in binary form must reproduce the above copyright
21 1.1 brezak * notice, this list of conditions and the following disclaimer in the
22 1.1 brezak * documentation and/or other materials provided with the distribution.
23 1.1 brezak * 3. All advertising materials mentioning features or use of this software
24 1.1 brezak * must display the following acknowledgement:
25 1.1 brezak * This product includes software developed by the University of
26 1.1 brezak * California, Berkeley and its contributors.
27 1.1 brezak * 4. Neither the name of the University nor the names of its contributors
28 1.1 brezak * may be used to endorse or promote products derived from this software
29 1.1 brezak * without specific prior written permission.
30 1.1 brezak *
31 1.1 brezak * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
32 1.1 brezak * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
33 1.1 brezak * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
34 1.1 brezak * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
35 1.1 brezak * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
36 1.1 brezak * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
37 1.1 brezak * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
38 1.1 brezak * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
39 1.1 brezak * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
40 1.1 brezak * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
41 1.1 brezak * SUCH DAMAGE.
42 1.1 brezak *
43 1.2 brezak * from: @(#)bpf.c 8.1 (Berkeley) 6/4/93
44 1.1 brezak *
45 1.2 brezak * From: Utah Hdr: bpf.c 3.1 92/07/06
46 1.1 brezak * Author: Jeff Forys, University of Utah CSS
47 1.1 brezak */
48 1.1 brezak
49 1.8 thorpej #include <sys/cdefs.h>
50 1.1 brezak #ifndef lint
51 1.8 thorpej #if 0
52 1.8 thorpej static char sccsid[] = "@(#)bpf.c 8.1 (Berkeley) 6/4/93";
53 1.8 thorpej #else
54 1.12 itojun __RCSID("$NetBSD: bpf.c,v 1.12 2003/05/15 14:50:50 itojun Exp $");
55 1.8 thorpej #endif
56 1.1 brezak #endif /* not lint */
57 1.1 brezak
58 1.1 brezak #include <sys/param.h>
59 1.1 brezak #include <sys/ioctl.h>
60 1.1 brezak #include <sys/socket.h>
61 1.1 brezak
62 1.1 brezak #include <net/if.h>
63 1.1 brezak #include <net/bpf.h>
64 1.1 brezak
65 1.1 brezak #include <ctype.h>
66 1.1 brezak #include <errno.h>
67 1.1 brezak #include <fcntl.h>
68 1.1 brezak #include <stdio.h>
69 1.1 brezak #include <stdlib.h>
70 1.1 brezak #include <string.h>
71 1.1 brezak #include <syslog.h>
72 1.1 brezak #include <unistd.h>
73 1.10 itojun #include <ifaddrs.h>
74 1.1 brezak #include "defs.h"
75 1.1 brezak #include "pathnames.h"
76 1.1 brezak
77 1.1 brezak static int BpfFd = -1;
78 1.1 brezak static unsigned BpfLen = 0;
79 1.5 thorpej static u_int8_t *BpfPkt = NULL;
80 1.1 brezak
81 1.1 brezak /*
82 1.1 brezak ** BpfOpen -- Open and initialize a BPF device.
83 1.1 brezak **
84 1.1 brezak ** Parameters:
85 1.1 brezak ** None.
86 1.1 brezak **
87 1.1 brezak ** Returns:
88 1.1 brezak ** File descriptor of opened BPF device (for select() etc).
89 1.1 brezak **
90 1.1 brezak ** Side Effects:
91 1.1 brezak ** If an error is encountered, the program terminates here.
92 1.1 brezak */
93 1.1 brezak int
94 1.1 brezak BpfOpen()
95 1.1 brezak {
96 1.1 brezak struct ifreq ifr;
97 1.1 brezak char bpfdev[32];
98 1.1 brezak int n = 0;
99 1.1 brezak
100 1.1 brezak /*
101 1.1 brezak * Open the first available BPF device.
102 1.1 brezak */
103 1.1 brezak do {
104 1.1 brezak (void) sprintf(bpfdev, _PATH_BPF, n++);
105 1.1 brezak BpfFd = open(bpfdev, O_RDWR);
106 1.1 brezak } while (BpfFd < 0 && (errno == EBUSY || errno == EPERM));
107 1.1 brezak
108 1.1 brezak if (BpfFd < 0) {
109 1.1 brezak syslog(LOG_ERR, "bpf: no available devices: %m");
110 1.1 brezak Exit(0);
111 1.1 brezak }
112 1.1 brezak
113 1.1 brezak /*
114 1.1 brezak * Set interface name for bpf device, get data link layer
115 1.1 brezak * type and make sure it's type Ethernet.
116 1.1 brezak */
117 1.1 brezak (void) strncpy(ifr.ifr_name, IntfName, sizeof(ifr.ifr_name));
118 1.1 brezak if (ioctl(BpfFd, BIOCSETIF, (caddr_t)&ifr) < 0) {
119 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCSETIF,%s): %m", IntfName);
120 1.1 brezak Exit(0);
121 1.1 brezak }
122 1.1 brezak
123 1.1 brezak /*
124 1.1 brezak * Make sure we are dealing with an Ethernet device.
125 1.1 brezak */
126 1.1 brezak if (ioctl(BpfFd, BIOCGDLT, (caddr_t)&n) < 0) {
127 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCGDLT): %m");
128 1.1 brezak Exit(0);
129 1.1 brezak }
130 1.1 brezak if (n != DLT_EN10MB) {
131 1.1 brezak syslog(LOG_ERR,"bpf: %s: data-link type %d unsupported",
132 1.1 brezak IntfName, n);
133 1.1 brezak Exit(0);
134 1.1 brezak }
135 1.1 brezak
136 1.1 brezak /*
137 1.1 brezak * On read(), return packets immediately (do not buffer them).
138 1.1 brezak */
139 1.1 brezak n = 1;
140 1.1 brezak if (ioctl(BpfFd, BIOCIMMEDIATE, (caddr_t)&n) < 0) {
141 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCIMMEDIATE): %m");
142 1.1 brezak Exit(0);
143 1.1 brezak }
144 1.1 brezak
145 1.1 brezak /*
146 1.1 brezak * Try to enable the chip/driver's multicast address filter to
147 1.1 brezak * grab our RMP address. If this fails, try promiscuous mode.
148 1.1 brezak * If this fails, there's no way we are going to get any RMP
149 1.1 brezak * packets so just exit here.
150 1.1 brezak */
151 1.1 brezak #ifdef MSG_EOR
152 1.1 brezak ifr.ifr_addr.sa_len = RMP_ADDRLEN + 2;
153 1.1 brezak #endif
154 1.1 brezak ifr.ifr_addr.sa_family = AF_UNSPEC;
155 1.9 lukem memmove((char *)&ifr.ifr_addr.sa_data[0], &RmpMcastAddr[0],
156 1.9 lukem RMP_ADDRLEN);
157 1.7 thorpej if (ioctl(BpfFd, BIOCPROMISC, (caddr_t)0) < 0) {
158 1.7 thorpej syslog(LOG_ERR, "bpf: can't set promiscuous mode: %m");
159 1.7 thorpej Exit(0);
160 1.1 brezak }
161 1.1 brezak
162 1.1 brezak /*
163 1.1 brezak * Ask BPF how much buffer space it requires and allocate one.
164 1.1 brezak */
165 1.1 brezak if (ioctl(BpfFd, BIOCGBLEN, (caddr_t)&BpfLen) < 0) {
166 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCGBLEN): %m");
167 1.1 brezak Exit(0);
168 1.1 brezak }
169 1.1 brezak if (BpfPkt == NULL)
170 1.5 thorpej BpfPkt = (u_int8_t *)malloc(BpfLen);
171 1.1 brezak
172 1.1 brezak if (BpfPkt == NULL) {
173 1.1 brezak syslog(LOG_ERR, "bpf: out of memory (%u bytes for bpfpkt)",
174 1.1 brezak BpfLen);
175 1.1 brezak Exit(0);
176 1.1 brezak }
177 1.1 brezak
178 1.1 brezak /*
179 1.1 brezak * Write a little program to snarf RMP Boot packets and stuff
180 1.1 brezak * it down BPF's throat (i.e. set up the packet filter).
181 1.1 brezak */
182 1.1 brezak {
183 1.1 brezak #define RMP ((struct rmp_packet *)0)
184 1.1 brezak static struct bpf_insn bpf_insn[] = {
185 1.1 brezak { BPF_LD|BPF_B|BPF_ABS, 0, 0, (long)&RMP->hp_llc.dsap },
186 1.1 brezak { BPF_JMP|BPF_JEQ|BPF_K, 0, 5, IEEE_DSAP_HP },
187 1.1 brezak { BPF_LD|BPF_H|BPF_ABS, 0, 0, (long)&RMP->hp_llc.cntrl },
188 1.1 brezak { BPF_JMP|BPF_JEQ|BPF_K, 0, 3, IEEE_CNTL_HP },
189 1.1 brezak { BPF_LD|BPF_H|BPF_ABS, 0, 0, (long)&RMP->hp_llc.dxsap },
190 1.1 brezak { BPF_JMP|BPF_JEQ|BPF_K, 0, 1, HPEXT_DXSAP },
191 1.1 brezak { BPF_RET|BPF_K, 0, 0, RMP_MAX_PACKET },
192 1.1 brezak { BPF_RET|BPF_K, 0, 0, 0x0 }
193 1.1 brezak };
194 1.1 brezak #undef RMP
195 1.1 brezak static struct bpf_program bpf_pgm = {
196 1.1 brezak sizeof(bpf_insn)/sizeof(bpf_insn[0]), bpf_insn
197 1.1 brezak };
198 1.1 brezak
199 1.1 brezak if (ioctl(BpfFd, BIOCSETF, (caddr_t)&bpf_pgm) < 0) {
200 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCSETF): %m");
201 1.1 brezak Exit(0);
202 1.1 brezak }
203 1.1 brezak }
204 1.1 brezak
205 1.1 brezak return(BpfFd);
206 1.1 brezak }
207 1.1 brezak
208 1.1 brezak /*
209 1.1 brezak ** BPF GetIntfName -- Return the name of a network interface attached to
210 1.1 brezak ** the system, or 0 if none can be found. The interface
211 1.1 brezak ** must be configured up; the lowest unit number is
212 1.1 brezak ** preferred; loopback is ignored.
213 1.1 brezak **
214 1.1 brezak ** Parameters:
215 1.1 brezak ** errmsg - if no network interface found, *errmsg explains why.
216 1.1 brezak **
217 1.1 brezak ** Returns:
218 1.1 brezak ** A (static) pointer to interface name, or NULL on error.
219 1.1 brezak **
220 1.1 brezak ** Side Effects:
221 1.1 brezak ** None.
222 1.1 brezak */
223 1.1 brezak char *
224 1.1 brezak BpfGetIntfName(errmsg)
225 1.1 brezak char **errmsg;
226 1.1 brezak {
227 1.10 itojun struct ifaddrs *ifap, *ifa, *p;
228 1.10 itojun int minunit, n;
229 1.10 itojun char *cp;
230 1.10 itojun static char device[IFNAMSIZ + 1];
231 1.10 itojun static char errbuf[128] = "No Error!";
232 1.11 lukem
233 1.11 lukem if (errmsg != NULL)
234 1.11 lukem *errmsg = errbuf;
235 1.10 itojun
236 1.10 itojun if (getifaddrs(&ifap) != 0) {
237 1.10 itojun (void) strcpy(errbuf, "bpf: getifaddrs: %m");
238 1.10 itojun return(NULL);
239 1.10 itojun }
240 1.10 itojun
241 1.10 itojun p = NULL;
242 1.10 itojun minunit = 666;
243 1.10 itojun for (ifa = ifap; ifa; ifa = ifa->ifa_next) {
244 1.10 itojun /*
245 1.10 itojun * If interface is down or this is the loopback interface,
246 1.10 itojun * ignore it.
247 1.10 itojun */
248 1.10 itojun if ((ifa->ifa_flags & IFF_UP) == 0 ||
249 1.10 itojun #ifdef IFF_LOOPBACK
250 1.10 itojun (ifa->ifa_flags & IFF_LOOPBACK))
251 1.10 itojun #else
252 1.10 itojun (strcmp(ifa->ifa_name, "lo0") == 0))
253 1.10 itojun #endif
254 1.10 itojun continue;
255 1.10 itojun
256 1.10 itojun for (cp = ifa->ifa_name; !isdigit(*cp); ++cp)
257 1.10 itojun ;
258 1.10 itojun n = atoi(cp);
259 1.10 itojun if (n < minunit) {
260 1.10 itojun minunit = n;
261 1.10 itojun p = ifa;
262 1.10 itojun }
263 1.10 itojun }
264 1.10 itojun if (p == NULL) {
265 1.10 itojun (void) strcpy(errbuf, "bpf: no interfaces found");
266 1.10 itojun freeifaddrs(ifap);
267 1.10 itojun return(NULL);
268 1.10 itojun }
269 1.10 itojun
270 1.10 itojun (void) strncpy(device, p->ifa_name, sizeof(device));
271 1.10 itojun device[sizeof(device) - 1] = '\0';
272 1.10 itojun freeifaddrs(ifap);
273 1.10 itojun return(device);
274 1.1 brezak }
275 1.1 brezak
276 1.1 brezak /*
277 1.1 brezak ** BpfRead -- Read packets from a BPF device and fill in `rconn'.
278 1.1 brezak **
279 1.1 brezak ** Parameters:
280 1.1 brezak ** rconn - filled in with next packet.
281 1.1 brezak ** doread - is True if we can issue a read() syscall.
282 1.1 brezak **
283 1.1 brezak ** Returns:
284 1.1 brezak ** True if `rconn' contains a new packet, False otherwise.
285 1.1 brezak **
286 1.1 brezak ** Side Effects:
287 1.1 brezak ** None.
288 1.1 brezak */
289 1.1 brezak int
290 1.1 brezak BpfRead(rconn, doread)
291 1.1 brezak RMPCONN *rconn;
292 1.1 brezak int doread;
293 1.1 brezak {
294 1.9 lukem int datlen, caplen, hdrlen;
295 1.5 thorpej static u_int8_t *bp = NULL, *ep = NULL;
296 1.1 brezak int cc;
297 1.1 brezak
298 1.1 brezak /*
299 1.1 brezak * The read() may block, or it may return one or more packets.
300 1.1 brezak * We let the caller decide whether or not we can issue a read().
301 1.1 brezak */
302 1.1 brezak if (doread) {
303 1.1 brezak if ((cc = read(BpfFd, (char *)BpfPkt, (int)BpfLen)) < 0) {
304 1.1 brezak syslog(LOG_ERR, "bpf: read: %m");
305 1.1 brezak return(0);
306 1.1 brezak } else {
307 1.1 brezak bp = BpfPkt;
308 1.1 brezak ep = BpfPkt + cc;
309 1.1 brezak }
310 1.1 brezak }
311 1.1 brezak
312 1.1 brezak #define bhp ((struct bpf_hdr *)bp)
313 1.1 brezak /*
314 1.1 brezak * If there is a new packet in the buffer, stuff it into `rconn'
315 1.1 brezak * and return a success indication.
316 1.1 brezak */
317 1.1 brezak if (bp < ep) {
318 1.1 brezak datlen = bhp->bh_datalen;
319 1.1 brezak caplen = bhp->bh_caplen;
320 1.1 brezak hdrlen = bhp->bh_hdrlen;
321 1.1 brezak
322 1.1 brezak if (caplen != datlen)
323 1.1 brezak syslog(LOG_ERR,
324 1.1 brezak "bpf: short packet dropped (%d of %d bytes)",
325 1.1 brezak caplen, datlen);
326 1.1 brezak else if (caplen > sizeof(struct rmp_packet))
327 1.1 brezak syslog(LOG_ERR, "bpf: large packet dropped (%d bytes)",
328 1.1 brezak caplen);
329 1.1 brezak else {
330 1.6 thorpej rconn->rmplen = caplen;
331 1.9 lukem memmove((char *)&rconn->tstamp, (char *)&bhp->bh_tstamp,
332 1.9 lukem sizeof(struct timeval));
333 1.9 lukem memmove((char *)&rconn->rmp, (char *)bp + hdrlen,
334 1.9 lukem caplen);
335 1.1 brezak }
336 1.1 brezak bp += BPF_WORDALIGN(caplen + hdrlen);
337 1.1 brezak return(1);
338 1.1 brezak }
339 1.1 brezak #undef bhp
340 1.1 brezak
341 1.1 brezak return(0);
342 1.1 brezak }
343 1.1 brezak
344 1.1 brezak /*
345 1.1 brezak ** BpfWrite -- Write packet to BPF device.
346 1.1 brezak **
347 1.1 brezak ** Parameters:
348 1.1 brezak ** rconn - packet to send.
349 1.1 brezak **
350 1.1 brezak ** Returns:
351 1.1 brezak ** True if write succeeded, False otherwise.
352 1.1 brezak **
353 1.1 brezak ** Side Effects:
354 1.1 brezak ** None.
355 1.1 brezak */
356 1.1 brezak int
357 1.1 brezak BpfWrite(rconn)
358 1.1 brezak RMPCONN *rconn;
359 1.1 brezak {
360 1.6 thorpej if (write(BpfFd, (char *)&rconn->rmp, rconn->rmplen) < 0) {
361 1.1 brezak syslog(LOG_ERR, "write: %s: %m", EnetStr(rconn));
362 1.1 brezak return(0);
363 1.1 brezak }
364 1.1 brezak
365 1.1 brezak return(1);
366 1.1 brezak }
367 1.1 brezak
368 1.1 brezak /*
369 1.1 brezak ** BpfClose -- Close a BPF device.
370 1.1 brezak **
371 1.1 brezak ** Parameters:
372 1.1 brezak ** None.
373 1.1 brezak **
374 1.1 brezak ** Returns:
375 1.1 brezak ** Nothing.
376 1.1 brezak **
377 1.1 brezak ** Side Effects:
378 1.1 brezak ** None.
379 1.1 brezak */
380 1.1 brezak void
381 1.1 brezak BpfClose()
382 1.1 brezak {
383 1.1 brezak struct ifreq ifr;
384 1.1 brezak
385 1.1 brezak if (BpfPkt != NULL) {
386 1.1 brezak free((char *)BpfPkt);
387 1.1 brezak BpfPkt = NULL;
388 1.1 brezak }
389 1.1 brezak
390 1.1 brezak if (BpfFd == -1)
391 1.1 brezak return;
392 1.1 brezak
393 1.1 brezak #ifdef MSG_EOR
394 1.1 brezak ifr.ifr_addr.sa_len = RMP_ADDRLEN + 2;
395 1.1 brezak #endif
396 1.1 brezak ifr.ifr_addr.sa_family = AF_UNSPEC;
397 1.9 lukem memmove((char *)&ifr.ifr_addr.sa_data[0], &RmpMcastAddr[0],
398 1.9 lukem RMP_ADDRLEN);
399 1.1 brezak if (ioctl(BpfFd, SIOCDELMULTI, (caddr_t)&ifr) < 0)
400 1.1 brezak (void) ioctl(BpfFd, BIOCPROMISC, (caddr_t)0);
401 1.1 brezak
402 1.1 brezak (void) close(BpfFd);
403 1.1 brezak BpfFd = -1;
404 1.1 brezak }
405