bpf.c revision 1.8 1 1.8 thorpej /* $NetBSD: bpf.c,v 1.8 1997/07/28 05:39:17 thorpej Exp $ */
2 1.3 thorpej
3 1.1 brezak /*
4 1.1 brezak * Copyright (c) 1988, 1992 The University of Utah and the Center
5 1.1 brezak * for Software Science (CSS).
6 1.1 brezak * Copyright (c) 1992, 1993
7 1.1 brezak * The Regents of the University of California. All rights reserved.
8 1.1 brezak *
9 1.1 brezak * This code is derived from software contributed to Berkeley by
10 1.1 brezak * the Center for Software Science of the University of Utah Computer
11 1.1 brezak * Science Department. CSS requests users of this software to return
12 1.1 brezak * to css-dist (at) cs.utah.edu any improvements that they make and grant
13 1.1 brezak * CSS redistribution rights.
14 1.1 brezak *
15 1.1 brezak * Redistribution and use in source and binary forms, with or without
16 1.1 brezak * modification, are permitted provided that the following conditions
17 1.1 brezak * are met:
18 1.1 brezak * 1. Redistributions of source code must retain the above copyright
19 1.1 brezak * notice, this list of conditions and the following disclaimer.
20 1.1 brezak * 2. Redistributions in binary form must reproduce the above copyright
21 1.1 brezak * notice, this list of conditions and the following disclaimer in the
22 1.1 brezak * documentation and/or other materials provided with the distribution.
23 1.1 brezak * 3. All advertising materials mentioning features or use of this software
24 1.1 brezak * must display the following acknowledgement:
25 1.1 brezak * This product includes software developed by the University of
26 1.1 brezak * California, Berkeley and its contributors.
27 1.1 brezak * 4. Neither the name of the University nor the names of its contributors
28 1.1 brezak * may be used to endorse or promote products derived from this software
29 1.1 brezak * without specific prior written permission.
30 1.1 brezak *
31 1.1 brezak * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
32 1.1 brezak * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
33 1.1 brezak * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
34 1.1 brezak * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
35 1.1 brezak * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
36 1.1 brezak * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
37 1.1 brezak * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
38 1.1 brezak * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
39 1.1 brezak * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
40 1.1 brezak * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
41 1.1 brezak * SUCH DAMAGE.
42 1.1 brezak *
43 1.2 brezak * from: @(#)bpf.c 8.1 (Berkeley) 6/4/93
44 1.1 brezak *
45 1.2 brezak * From: Utah Hdr: bpf.c 3.1 92/07/06
46 1.1 brezak * Author: Jeff Forys, University of Utah CSS
47 1.1 brezak */
48 1.1 brezak
49 1.8 thorpej #include <sys/cdefs.h>
50 1.1 brezak #ifndef lint
51 1.8 thorpej #if 0
52 1.8 thorpej static char sccsid[] = "@(#)bpf.c 8.1 (Berkeley) 6/4/93";
53 1.8 thorpej #else
54 1.8 thorpej __RCSID("$NetBSD: bpf.c,v 1.8 1997/07/28 05:39:17 thorpej Exp $");
55 1.8 thorpej #endif
56 1.1 brezak #endif /* not lint */
57 1.1 brezak
58 1.1 brezak #include <sys/param.h>
59 1.1 brezak #include <sys/ioctl.h>
60 1.1 brezak #include <sys/socket.h>
61 1.1 brezak
62 1.1 brezak #include <net/if.h>
63 1.1 brezak #include <net/bpf.h>
64 1.1 brezak
65 1.1 brezak #include <ctype.h>
66 1.1 brezak #include <errno.h>
67 1.1 brezak #include <fcntl.h>
68 1.1 brezak #include <stdio.h>
69 1.1 brezak #include <stdlib.h>
70 1.1 brezak #include <string.h>
71 1.1 brezak #include <syslog.h>
72 1.1 brezak #include <unistd.h>
73 1.1 brezak #include "defs.h"
74 1.1 brezak #include "pathnames.h"
75 1.1 brezak
76 1.1 brezak static int BpfFd = -1;
77 1.1 brezak static unsigned BpfLen = 0;
78 1.5 thorpej static u_int8_t *BpfPkt = NULL;
79 1.1 brezak
80 1.1 brezak /*
81 1.1 brezak ** BpfOpen -- Open and initialize a BPF device.
82 1.1 brezak **
83 1.1 brezak ** Parameters:
84 1.1 brezak ** None.
85 1.1 brezak **
86 1.1 brezak ** Returns:
87 1.1 brezak ** File descriptor of opened BPF device (for select() etc).
88 1.1 brezak **
89 1.1 brezak ** Side Effects:
90 1.1 brezak ** If an error is encountered, the program terminates here.
91 1.1 brezak */
92 1.1 brezak int
93 1.1 brezak BpfOpen()
94 1.1 brezak {
95 1.1 brezak struct ifreq ifr;
96 1.1 brezak char bpfdev[32];
97 1.1 brezak int n = 0;
98 1.1 brezak
99 1.1 brezak /*
100 1.1 brezak * Open the first available BPF device.
101 1.1 brezak */
102 1.1 brezak do {
103 1.1 brezak (void) sprintf(bpfdev, _PATH_BPF, n++);
104 1.1 brezak BpfFd = open(bpfdev, O_RDWR);
105 1.1 brezak } while (BpfFd < 0 && (errno == EBUSY || errno == EPERM));
106 1.1 brezak
107 1.1 brezak if (BpfFd < 0) {
108 1.1 brezak syslog(LOG_ERR, "bpf: no available devices: %m");
109 1.1 brezak Exit(0);
110 1.1 brezak }
111 1.1 brezak
112 1.1 brezak /*
113 1.1 brezak * Set interface name for bpf device, get data link layer
114 1.1 brezak * type and make sure it's type Ethernet.
115 1.1 brezak */
116 1.1 brezak (void) strncpy(ifr.ifr_name, IntfName, sizeof(ifr.ifr_name));
117 1.1 brezak if (ioctl(BpfFd, BIOCSETIF, (caddr_t)&ifr) < 0) {
118 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCSETIF,%s): %m", IntfName);
119 1.1 brezak Exit(0);
120 1.1 brezak }
121 1.1 brezak
122 1.1 brezak /*
123 1.1 brezak * Make sure we are dealing with an Ethernet device.
124 1.1 brezak */
125 1.1 brezak if (ioctl(BpfFd, BIOCGDLT, (caddr_t)&n) < 0) {
126 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCGDLT): %m");
127 1.1 brezak Exit(0);
128 1.1 brezak }
129 1.1 brezak if (n != DLT_EN10MB) {
130 1.1 brezak syslog(LOG_ERR,"bpf: %s: data-link type %d unsupported",
131 1.1 brezak IntfName, n);
132 1.1 brezak Exit(0);
133 1.1 brezak }
134 1.1 brezak
135 1.1 brezak /*
136 1.1 brezak * On read(), return packets immediately (do not buffer them).
137 1.1 brezak */
138 1.1 brezak n = 1;
139 1.1 brezak if (ioctl(BpfFd, BIOCIMMEDIATE, (caddr_t)&n) < 0) {
140 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCIMMEDIATE): %m");
141 1.1 brezak Exit(0);
142 1.1 brezak }
143 1.1 brezak
144 1.1 brezak /*
145 1.1 brezak * Try to enable the chip/driver's multicast address filter to
146 1.1 brezak * grab our RMP address. If this fails, try promiscuous mode.
147 1.1 brezak * If this fails, there's no way we are going to get any RMP
148 1.1 brezak * packets so just exit here.
149 1.1 brezak */
150 1.1 brezak #ifdef MSG_EOR
151 1.1 brezak ifr.ifr_addr.sa_len = RMP_ADDRLEN + 2;
152 1.1 brezak #endif
153 1.1 brezak ifr.ifr_addr.sa_family = AF_UNSPEC;
154 1.1 brezak bcopy(&RmpMcastAddr[0], (char *)&ifr.ifr_addr.sa_data[0], RMP_ADDRLEN);
155 1.7 thorpej if (ioctl(BpfFd, BIOCPROMISC, (caddr_t)0) < 0) {
156 1.7 thorpej syslog(LOG_ERR, "bpf: can't set promiscuous mode: %m");
157 1.7 thorpej Exit(0);
158 1.1 brezak }
159 1.1 brezak
160 1.1 brezak /*
161 1.1 brezak * Ask BPF how much buffer space it requires and allocate one.
162 1.1 brezak */
163 1.1 brezak if (ioctl(BpfFd, BIOCGBLEN, (caddr_t)&BpfLen) < 0) {
164 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCGBLEN): %m");
165 1.1 brezak Exit(0);
166 1.1 brezak }
167 1.1 brezak if (BpfPkt == NULL)
168 1.5 thorpej BpfPkt = (u_int8_t *)malloc(BpfLen);
169 1.1 brezak
170 1.1 brezak if (BpfPkt == NULL) {
171 1.1 brezak syslog(LOG_ERR, "bpf: out of memory (%u bytes for bpfpkt)",
172 1.1 brezak BpfLen);
173 1.1 brezak Exit(0);
174 1.1 brezak }
175 1.1 brezak
176 1.1 brezak /*
177 1.1 brezak * Write a little program to snarf RMP Boot packets and stuff
178 1.1 brezak * it down BPF's throat (i.e. set up the packet filter).
179 1.1 brezak */
180 1.1 brezak {
181 1.1 brezak #define RMP ((struct rmp_packet *)0)
182 1.1 brezak static struct bpf_insn bpf_insn[] = {
183 1.1 brezak { BPF_LD|BPF_B|BPF_ABS, 0, 0, (long)&RMP->hp_llc.dsap },
184 1.1 brezak { BPF_JMP|BPF_JEQ|BPF_K, 0, 5, IEEE_DSAP_HP },
185 1.1 brezak { BPF_LD|BPF_H|BPF_ABS, 0, 0, (long)&RMP->hp_llc.cntrl },
186 1.1 brezak { BPF_JMP|BPF_JEQ|BPF_K, 0, 3, IEEE_CNTL_HP },
187 1.1 brezak { BPF_LD|BPF_H|BPF_ABS, 0, 0, (long)&RMP->hp_llc.dxsap },
188 1.1 brezak { BPF_JMP|BPF_JEQ|BPF_K, 0, 1, HPEXT_DXSAP },
189 1.1 brezak { BPF_RET|BPF_K, 0, 0, RMP_MAX_PACKET },
190 1.1 brezak { BPF_RET|BPF_K, 0, 0, 0x0 }
191 1.1 brezak };
192 1.1 brezak #undef RMP
193 1.1 brezak static struct bpf_program bpf_pgm = {
194 1.1 brezak sizeof(bpf_insn)/sizeof(bpf_insn[0]), bpf_insn
195 1.1 brezak };
196 1.1 brezak
197 1.1 brezak if (ioctl(BpfFd, BIOCSETF, (caddr_t)&bpf_pgm) < 0) {
198 1.1 brezak syslog(LOG_ERR, "bpf: ioctl(BIOCSETF): %m");
199 1.1 brezak Exit(0);
200 1.1 brezak }
201 1.1 brezak }
202 1.1 brezak
203 1.1 brezak return(BpfFd);
204 1.1 brezak }
205 1.1 brezak
206 1.1 brezak /*
207 1.1 brezak ** BPF GetIntfName -- Return the name of a network interface attached to
208 1.1 brezak ** the system, or 0 if none can be found. The interface
209 1.1 brezak ** must be configured up; the lowest unit number is
210 1.1 brezak ** preferred; loopback is ignored.
211 1.1 brezak **
212 1.1 brezak ** Parameters:
213 1.1 brezak ** errmsg - if no network interface found, *errmsg explains why.
214 1.1 brezak **
215 1.1 brezak ** Returns:
216 1.1 brezak ** A (static) pointer to interface name, or NULL on error.
217 1.1 brezak **
218 1.1 brezak ** Side Effects:
219 1.1 brezak ** None.
220 1.1 brezak */
221 1.1 brezak char *
222 1.1 brezak BpfGetIntfName(errmsg)
223 1.1 brezak char **errmsg;
224 1.1 brezak {
225 1.1 brezak struct ifreq ibuf[8], *ifrp, *ifend, *mp;
226 1.1 brezak struct ifconf ifc;
227 1.1 brezak int fd;
228 1.1 brezak int minunit, n;
229 1.1 brezak char *cp;
230 1.1 brezak static char device[sizeof(ifrp->ifr_name)];
231 1.1 brezak static char errbuf[128] = "No Error!";
232 1.1 brezak
233 1.1 brezak if (errmsg != NULL)
234 1.1 brezak *errmsg = errbuf;
235 1.1 brezak
236 1.1 brezak if ((fd = socket(AF_INET, SOCK_DGRAM, 0)) < 0) {
237 1.1 brezak (void) strcpy(errbuf, "bpf: socket: %m");
238 1.1 brezak return(NULL);
239 1.1 brezak }
240 1.1 brezak ifc.ifc_len = sizeof ibuf;
241 1.1 brezak ifc.ifc_buf = (caddr_t)ibuf;
242 1.1 brezak
243 1.1 brezak #ifdef OSIOCGIFCONF
244 1.1 brezak if (ioctl(fd, OSIOCGIFCONF, (char *)&ifc) < 0 ||
245 1.1 brezak ifc.ifc_len < sizeof(struct ifreq)) {
246 1.1 brezak (void) strcpy(errbuf, "bpf: ioctl(OSIOCGIFCONF): %m");
247 1.1 brezak return(NULL);
248 1.1 brezak }
249 1.1 brezak #else
250 1.1 brezak if (ioctl(fd, SIOCGIFCONF, (char *)&ifc) < 0 ||
251 1.1 brezak ifc.ifc_len < sizeof(struct ifreq)) {
252 1.1 brezak (void) strcpy(errbuf, "bpf: ioctl(SIOCGIFCONF): %m");
253 1.1 brezak return(NULL);
254 1.1 brezak }
255 1.1 brezak #endif
256 1.1 brezak ifrp = ibuf;
257 1.1 brezak ifend = (struct ifreq *)((char *)ibuf + ifc.ifc_len);
258 1.1 brezak
259 1.1 brezak mp = 0;
260 1.1 brezak minunit = 666;
261 1.1 brezak for (; ifrp < ifend; ++ifrp) {
262 1.1 brezak if (ioctl(fd, SIOCGIFFLAGS, (char *)ifrp) < 0) {
263 1.1 brezak (void) strcpy(errbuf, "bpf: ioctl(SIOCGIFFLAGS): %m");
264 1.1 brezak return(NULL);
265 1.1 brezak }
266 1.1 brezak
267 1.1 brezak /*
268 1.1 brezak * If interface is down or this is the loopback interface,
269 1.1 brezak * ignore it.
270 1.1 brezak */
271 1.1 brezak if ((ifrp->ifr_flags & IFF_UP) == 0 ||
272 1.1 brezak #ifdef IFF_LOOPBACK
273 1.1 brezak (ifrp->ifr_flags & IFF_LOOPBACK))
274 1.1 brezak #else
275 1.1 brezak (strcmp(ifrp->ifr_name, "lo0") == 0))
276 1.1 brezak #endif
277 1.1 brezak continue;
278 1.1 brezak
279 1.1 brezak for (cp = ifrp->ifr_name; !isdigit(*cp); ++cp)
280 1.1 brezak ;
281 1.1 brezak n = atoi(cp);
282 1.1 brezak if (n < minunit) {
283 1.1 brezak minunit = n;
284 1.1 brezak mp = ifrp;
285 1.1 brezak }
286 1.1 brezak }
287 1.1 brezak
288 1.1 brezak (void) close(fd);
289 1.1 brezak if (mp == 0) {
290 1.1 brezak (void) strcpy(errbuf, "bpf: no interfaces found");
291 1.1 brezak return(NULL);
292 1.1 brezak }
293 1.1 brezak
294 1.1 brezak (void) strcpy(device, mp->ifr_name);
295 1.1 brezak return(device);
296 1.1 brezak }
297 1.1 brezak
298 1.1 brezak /*
299 1.1 brezak ** BpfRead -- Read packets from a BPF device and fill in `rconn'.
300 1.1 brezak **
301 1.1 brezak ** Parameters:
302 1.1 brezak ** rconn - filled in with next packet.
303 1.1 brezak ** doread - is True if we can issue a read() syscall.
304 1.1 brezak **
305 1.1 brezak ** Returns:
306 1.1 brezak ** True if `rconn' contains a new packet, False otherwise.
307 1.1 brezak **
308 1.1 brezak ** Side Effects:
309 1.1 brezak ** None.
310 1.1 brezak */
311 1.1 brezak int
312 1.1 brezak BpfRead(rconn, doread)
313 1.1 brezak RMPCONN *rconn;
314 1.1 brezak int doread;
315 1.1 brezak {
316 1.1 brezak register int datlen, caplen, hdrlen;
317 1.5 thorpej static u_int8_t *bp = NULL, *ep = NULL;
318 1.1 brezak int cc;
319 1.1 brezak
320 1.1 brezak /*
321 1.1 brezak * The read() may block, or it may return one or more packets.
322 1.1 brezak * We let the caller decide whether or not we can issue a read().
323 1.1 brezak */
324 1.1 brezak if (doread) {
325 1.1 brezak if ((cc = read(BpfFd, (char *)BpfPkt, (int)BpfLen)) < 0) {
326 1.1 brezak syslog(LOG_ERR, "bpf: read: %m");
327 1.1 brezak return(0);
328 1.1 brezak } else {
329 1.1 brezak bp = BpfPkt;
330 1.1 brezak ep = BpfPkt + cc;
331 1.1 brezak }
332 1.1 brezak }
333 1.1 brezak
334 1.1 brezak #define bhp ((struct bpf_hdr *)bp)
335 1.1 brezak /*
336 1.1 brezak * If there is a new packet in the buffer, stuff it into `rconn'
337 1.1 brezak * and return a success indication.
338 1.1 brezak */
339 1.1 brezak if (bp < ep) {
340 1.1 brezak datlen = bhp->bh_datalen;
341 1.1 brezak caplen = bhp->bh_caplen;
342 1.1 brezak hdrlen = bhp->bh_hdrlen;
343 1.1 brezak
344 1.1 brezak if (caplen != datlen)
345 1.1 brezak syslog(LOG_ERR,
346 1.1 brezak "bpf: short packet dropped (%d of %d bytes)",
347 1.1 brezak caplen, datlen);
348 1.1 brezak else if (caplen > sizeof(struct rmp_packet))
349 1.1 brezak syslog(LOG_ERR, "bpf: large packet dropped (%d bytes)",
350 1.1 brezak caplen);
351 1.1 brezak else {
352 1.6 thorpej rconn->rmplen = caplen;
353 1.1 brezak bcopy((char *)&bhp->bh_tstamp, (char *)&rconn->tstamp,
354 1.1 brezak sizeof(struct timeval));
355 1.1 brezak bcopy((char *)bp + hdrlen, (char *)&rconn->rmp, caplen);
356 1.1 brezak }
357 1.1 brezak bp += BPF_WORDALIGN(caplen + hdrlen);
358 1.1 brezak return(1);
359 1.1 brezak }
360 1.1 brezak #undef bhp
361 1.1 brezak
362 1.1 brezak return(0);
363 1.1 brezak }
364 1.1 brezak
365 1.1 brezak /*
366 1.1 brezak ** BpfWrite -- Write packet to BPF device.
367 1.1 brezak **
368 1.1 brezak ** Parameters:
369 1.1 brezak ** rconn - packet to send.
370 1.1 brezak **
371 1.1 brezak ** Returns:
372 1.1 brezak ** True if write succeeded, False otherwise.
373 1.1 brezak **
374 1.1 brezak ** Side Effects:
375 1.1 brezak ** None.
376 1.1 brezak */
377 1.1 brezak int
378 1.1 brezak BpfWrite(rconn)
379 1.1 brezak RMPCONN *rconn;
380 1.1 brezak {
381 1.6 thorpej if (write(BpfFd, (char *)&rconn->rmp, rconn->rmplen) < 0) {
382 1.1 brezak syslog(LOG_ERR, "write: %s: %m", EnetStr(rconn));
383 1.1 brezak return(0);
384 1.1 brezak }
385 1.1 brezak
386 1.1 brezak return(1);
387 1.1 brezak }
388 1.1 brezak
389 1.1 brezak /*
390 1.1 brezak ** BpfClose -- Close a BPF device.
391 1.1 brezak **
392 1.1 brezak ** Parameters:
393 1.1 brezak ** None.
394 1.1 brezak **
395 1.1 brezak ** Returns:
396 1.1 brezak ** Nothing.
397 1.1 brezak **
398 1.1 brezak ** Side Effects:
399 1.1 brezak ** None.
400 1.1 brezak */
401 1.1 brezak void
402 1.1 brezak BpfClose()
403 1.1 brezak {
404 1.1 brezak struct ifreq ifr;
405 1.1 brezak
406 1.1 brezak if (BpfPkt != NULL) {
407 1.1 brezak free((char *)BpfPkt);
408 1.1 brezak BpfPkt = NULL;
409 1.1 brezak }
410 1.1 brezak
411 1.1 brezak if (BpfFd == -1)
412 1.1 brezak return;
413 1.1 brezak
414 1.1 brezak #ifdef MSG_EOR
415 1.1 brezak ifr.ifr_addr.sa_len = RMP_ADDRLEN + 2;
416 1.1 brezak #endif
417 1.1 brezak ifr.ifr_addr.sa_family = AF_UNSPEC;
418 1.1 brezak bcopy(&RmpMcastAddr[0], (char *)&ifr.ifr_addr.sa_data[0], RMP_ADDRLEN);
419 1.1 brezak if (ioctl(BpfFd, SIOCDELMULTI, (caddr_t)&ifr) < 0)
420 1.1 brezak (void) ioctl(BpfFd, BIOCPROMISC, (caddr_t)0);
421 1.1 brezak
422 1.1 brezak (void) close(BpfFd);
423 1.1 brezak BpfFd = -1;
424 1.1 brezak }
425