Home | History | Annotate | Line # | Download | only in traceroute
traceroute.c revision 1.61
      1  1.61    itojun /*	$NetBSD: traceroute.c,v 1.61 2004/04/22 01:41:22 itojun Exp $	*/
      2   1.8     glass 
      3  1.18  christos /*
      4  1.18  christos  * Copyright (c) 1988, 1989, 1991, 1994, 1995, 1996, 1997
      5   1.3   mycroft  *	The Regents of the University of California.  All rights reserved.
      6   1.1       cgd  *
      7   1.1       cgd  * Redistribution and use in source and binary forms, with or without
      8  1.18  christos  * modification, are permitted provided that: (1) source code distributions
      9  1.18  christos  * retain the above copyright notice and this paragraph in its entirety, (2)
     10  1.18  christos  * distributions including binary code include the above copyright notice and
     11  1.18  christos  * this paragraph in its entirety in the documentation or other materials
     12  1.18  christos  * provided with the distribution, and (3) all advertising materials mentioning
     13  1.18  christos  * features or use of this software display the following acknowledgement:
     14  1.18  christos  * ``This product includes software developed by the University of California,
     15  1.18  christos  * Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
     16  1.18  christos  * the University nor the names of its contributors may be used to endorse
     17  1.18  christos  * or promote products derived from this software without specific prior
     18  1.18  christos  * written permission.
     19  1.18  christos  * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
     20  1.18  christos  * WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
     21  1.18  christos  * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
     22   1.1       cgd  */
     23   1.1       cgd 
     24  1.18  christos #include <sys/cdefs.h>
     25   1.1       cgd #ifndef lint
     26   1.8     glass #if 0
     27  1.18  christos static const char rcsid[] =
     28  1.18  christos     "@(#)Header: traceroute.c,v 1.49 97/06/13 02:30:23 leres Exp  (LBL)";
     29   1.8     glass #else
     30  1.18  christos __COPYRIGHT("@(#) Copyright (c) 1988, 1989, 1991, 1994, 1995, 1996, 1997\n\
     31  1.18  christos The Regents of the University of California.  All rights reserved.\n");
     32  1.61    itojun __RCSID("$NetBSD: traceroute.c,v 1.61 2004/04/22 01:41:22 itojun Exp $");
     33  1.18  christos #endif
     34   1.8     glass #endif
     35   1.1       cgd 
     36   1.1       cgd /*
     37   1.1       cgd  * traceroute host  - trace the route ip packets follow going to "host".
     38   1.1       cgd  *
     39   1.1       cgd  * Attempt to trace the route an ip packet would follow to some
     40   1.1       cgd  * internet host.  We find out intermediate hops by launching probe
     41   1.1       cgd  * packets with a small ttl (time to live) then listening for an
     42   1.1       cgd  * icmp "time exceeded" reply from a gateway.  We start our probes
     43   1.1       cgd  * with a ttl of one and increase by one until we get an icmp "port
     44   1.1       cgd  * unreachable" (which means we got to "host") or hit a max (which
     45   1.1       cgd  * defaults to 30 hops & can be changed with the -m flag).  Three
     46   1.1       cgd  * probes (change with -q flag) are sent at each ttl setting and a
     47   1.1       cgd  * line is printed showing the ttl, address of the gateway and
     48   1.1       cgd  * round trip time of each probe.  If the probe answers come from
     49   1.1       cgd  * different gateways, the address of each responding system will
     50   1.1       cgd  * be printed.  If there is no response within a 5 sec. timeout
     51   1.1       cgd  * interval (changed with the -w flag), a "*" is printed for that
     52   1.1       cgd  * probe.
     53   1.1       cgd  *
     54   1.1       cgd  * Probe packets are UDP format.  We don't want the destination
     55   1.1       cgd  * host to process them so the destination port is set to an
     56   1.1       cgd  * unlikely value (if some clod on the destination is using that
     57   1.1       cgd  * value, it can be changed with the -p flag).
     58   1.1       cgd  *
     59   1.1       cgd  * A sample use might be:
     60   1.1       cgd  *
     61   1.1       cgd  *     [yak 71]% traceroute nis.nsf.net.
     62   1.1       cgd  *     traceroute to nis.nsf.net (35.1.1.48), 30 hops max, 56 byte packet
     63   1.1       cgd  *      1  helios.ee.lbl.gov (128.3.112.1)  19 ms  19 ms  0 ms
     64   1.1       cgd  *      2  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  39 ms  19 ms
     65   1.1       cgd  *      3  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  39 ms  19 ms
     66   1.1       cgd  *      4  ccngw-ner-cc.Berkeley.EDU (128.32.136.23)  39 ms  40 ms  39 ms
     67   1.1       cgd  *      5  ccn-nerif22.Berkeley.EDU (128.32.168.22)  39 ms  39 ms  39 ms
     68   1.1       cgd  *      6  128.32.197.4 (128.32.197.4)  40 ms  59 ms  59 ms
     69   1.1       cgd  *      7  131.119.2.5 (131.119.2.5)  59 ms  59 ms  59 ms
     70   1.1       cgd  *      8  129.140.70.13 (129.140.70.13)  99 ms  99 ms  80 ms
     71   1.1       cgd  *      9  129.140.71.6 (129.140.71.6)  139 ms  239 ms  319 ms
     72   1.1       cgd  *     10  129.140.81.7 (129.140.81.7)  220 ms  199 ms  199 ms
     73   1.1       cgd  *     11  nic.merit.edu (35.1.1.48)  239 ms  239 ms  239 ms
     74   1.1       cgd  *
     75   1.1       cgd  * Note that lines 2 & 3 are the same.  This is due to a buggy
     76   1.1       cgd  * kernel on the 2nd hop system -- lbl-csam.arpa -- that forwards
     77   1.1       cgd  * packets with a zero ttl.
     78   1.1       cgd  *
     79   1.1       cgd  * A more interesting example is:
     80   1.1       cgd  *
     81   1.1       cgd  *     [yak 72]% traceroute allspice.lcs.mit.edu.
     82   1.1       cgd  *     traceroute to allspice.lcs.mit.edu (18.26.0.115), 30 hops max
     83   1.1       cgd  *      1  helios.ee.lbl.gov (128.3.112.1)  0 ms  0 ms  0 ms
     84   1.1       cgd  *      2  lilac-dmc.Berkeley.EDU (128.32.216.1)  19 ms  19 ms  19 ms
     85   1.1       cgd  *      3  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  19 ms  19 ms
     86   1.1       cgd  *      4  ccngw-ner-cc.Berkeley.EDU (128.32.136.23)  19 ms  39 ms  39 ms
     87   1.1       cgd  *      5  ccn-nerif22.Berkeley.EDU (128.32.168.22)  20 ms  39 ms  39 ms
     88   1.1       cgd  *      6  128.32.197.4 (128.32.197.4)  59 ms  119 ms  39 ms
     89   1.1       cgd  *      7  131.119.2.5 (131.119.2.5)  59 ms  59 ms  39 ms
     90   1.1       cgd  *      8  129.140.70.13 (129.140.70.13)  80 ms  79 ms  99 ms
     91   1.1       cgd  *      9  129.140.71.6 (129.140.71.6)  139 ms  139 ms  159 ms
     92   1.1       cgd  *     10  129.140.81.7 (129.140.81.7)  199 ms  180 ms  300 ms
     93   1.1       cgd  *     11  129.140.72.17 (129.140.72.17)  300 ms  239 ms  239 ms
     94   1.1       cgd  *     12  * * *
     95   1.1       cgd  *     13  128.121.54.72 (128.121.54.72)  259 ms  499 ms  279 ms
     96   1.1       cgd  *     14  * * *
     97   1.1       cgd  *     15  * * *
     98   1.1       cgd  *     16  * * *
     99   1.1       cgd  *     17  * * *
    100   1.1       cgd  *     18  ALLSPICE.LCS.MIT.EDU (18.26.0.115)  339 ms  279 ms  279 ms
    101   1.1       cgd  *
    102   1.1       cgd  * (I start to see why I'm having so much trouble with mail to
    103   1.1       cgd  * MIT.)  Note that the gateways 12, 14, 15, 16 & 17 hops away
    104   1.1       cgd  * either don't send ICMP "time exceeded" messages or send them
    105   1.1       cgd  * with a ttl too small to reach us.  14 - 17 are running the
    106   1.1       cgd  * MIT C Gateway code that doesn't send "time exceeded"s.  God
    107   1.1       cgd  * only knows what's going on with 12.
    108   1.1       cgd  *
    109   1.1       cgd  * The silent gateway 12 in the above may be the result of a bug in
    110   1.1       cgd  * the 4.[23]BSD network code (and its derivatives):  4.x (x <= 3)
    111   1.1       cgd  * sends an unreachable message using whatever ttl remains in the
    112   1.1       cgd  * original datagram.  Since, for gateways, the remaining ttl is
    113   1.1       cgd  * zero, the icmp "time exceeded" is guaranteed to not make it back
    114   1.1       cgd  * to us.  The behavior of this bug is slightly more interesting
    115   1.1       cgd  * when it appears on the destination system:
    116   1.1       cgd  *
    117   1.1       cgd  *      1  helios.ee.lbl.gov (128.3.112.1)  0 ms  0 ms  0 ms
    118   1.1       cgd  *      2  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  19 ms  39 ms
    119   1.1       cgd  *      3  lilac-dmc.Berkeley.EDU (128.32.216.1)  19 ms  39 ms  19 ms
    120   1.1       cgd  *      4  ccngw-ner-cc.Berkeley.EDU (128.32.136.23)  39 ms  40 ms  19 ms
    121   1.1       cgd  *      5  ccn-nerif35.Berkeley.EDU (128.32.168.35)  39 ms  39 ms  39 ms
    122   1.1       cgd  *      6  csgw.Berkeley.EDU (128.32.133.254)  39 ms  59 ms  39 ms
    123   1.1       cgd  *      7  * * *
    124   1.1       cgd  *      8  * * *
    125   1.1       cgd  *      9  * * *
    126   1.1       cgd  *     10  * * *
    127   1.1       cgd  *     11  * * *
    128   1.1       cgd  *     12  * * *
    129   1.1       cgd  *     13  rip.Berkeley.EDU (128.32.131.22)  59 ms !  39 ms !  39 ms !
    130   1.1       cgd  *
    131   1.1       cgd  * Notice that there are 12 "gateways" (13 is the final
    132   1.1       cgd  * destination) and exactly the last half of them are "missing".
    133   1.1       cgd  * What's really happening is that rip (a Sun-3 running Sun OS3.5)
    134   1.1       cgd  * is using the ttl from our arriving datagram as the ttl in its
    135   1.1       cgd  * icmp reply.  So, the reply will time out on the return path
    136   1.1       cgd  * (with no notice sent to anyone since icmp's aren't sent for
    137   1.1       cgd  * icmp's) until we probe with a ttl that's at least twice the path
    138   1.1       cgd  * length.  I.e., rip is really only 7 hops away.  A reply that
    139   1.1       cgd  * returns with a ttl of 1 is a clue this problem exists.
    140   1.1       cgd  * Traceroute prints a "!" after the time if the ttl is <= 1.
    141   1.1       cgd  * Since vendors ship a lot of obsolete (DEC's Ultrix, Sun 3.x) or
    142   1.1       cgd  * non-standard (HPUX) software, expect to see this problem
    143   1.1       cgd  * frequently and/or take care picking the target host of your
    144   1.1       cgd  * probes.
    145   1.1       cgd  *
    146   1.1       cgd  * Other possible annotations after the time are !H, !N, !P (got a host,
    147   1.1       cgd  * network or protocol unreachable, respectively), !S or !F (source
    148   1.1       cgd  * route failed or fragmentation needed -- neither of these should
    149   1.1       cgd  * ever occur and the associated gateway is busted if you see one).  If
    150   1.1       cgd  * almost all the probes result in some kind of unreachable, traceroute
    151   1.1       cgd  * will give up and exit.
    152   1.1       cgd  *
    153   1.1       cgd  * Notes
    154   1.1       cgd  * -----
    155   1.1       cgd  * This program must be run by root or be setuid.  (I suggest that
    156   1.1       cgd  * you *don't* make it setuid -- casual use could result in a lot
    157   1.1       cgd  * of unnecessary traffic on our poor, congested nets.)
    158   1.1       cgd  *
    159   1.1       cgd  * This program requires a kernel mod that does not appear in any
    160   1.1       cgd  * system available from Berkeley:  A raw ip socket using proto
    161   1.1       cgd  * IPPROTO_RAW must interpret the data sent as an ip datagram (as
    162   1.1       cgd  * opposed to data to be wrapped in a ip datagram).  See the README
    163   1.1       cgd  * file that came with the source to this program for a description
    164   1.1       cgd  * of the mods I made to /sys/netinet/raw_ip.c.  Your mileage may
    165   1.1       cgd  * vary.  But, again, ANY 4.x (x < 4) BSD KERNEL WILL HAVE TO BE
    166   1.1       cgd  * MODIFIED TO RUN THIS PROGRAM.
    167   1.1       cgd  *
    168   1.1       cgd  * The udp port usage may appear bizarre (well, ok, it is bizarre).
    169   1.1       cgd  * The problem is that an icmp message only contains 8 bytes of
    170   1.1       cgd  * data from the original datagram.  8 bytes is the size of a udp
    171   1.1       cgd  * header so, if we want to associate replies with the original
    172   1.1       cgd  * datagram, the necessary information must be encoded into the
    173   1.1       cgd  * udp header (the ip id could be used but there's no way to
    174   1.1       cgd  * interlock with the kernel's assignment of ip id's and, anyway,
    175   1.1       cgd  * it would have taken a lot more kernel hacking to allow this
    176   1.1       cgd  * code to set the ip id).  So, to allow two or more users to
    177   1.1       cgd  * use traceroute simultaneously, we use this task's pid as the
    178   1.1       cgd  * source port (the high bit is set to move the port number out
    179   1.1       cgd  * of the "likely" range).  To keep track of which probe is being
    180   1.1       cgd  * replied to (so times and/or hop counts don't get confused by a
    181   1.1       cgd  * reply that was delayed in transit), we increment the destination
    182   1.1       cgd  * port number before each probe.
    183   1.1       cgd  *
    184   1.1       cgd  * Don't use this as a coding example.  I was trying to find a
    185   1.1       cgd  * routing problem and this code sort-of popped out after 48 hours
    186   1.1       cgd  * without sleep.  I was amazed it ever compiled, much less ran.
    187   1.1       cgd  *
    188   1.1       cgd  * I stole the idea for this program from Steve Deering.  Since
    189   1.1       cgd  * the first release, I've learned that had I attended the right
    190   1.1       cgd  * IETF working group meetings, I also could have stolen it from Guy
    191   1.1       cgd  * Almes or Matt Mathis.  I don't know (or care) who came up with
    192   1.1       cgd  * the idea first.  I envy the originators' perspicacity and I'm
    193   1.1       cgd  * glad they didn't keep the idea a secret.
    194   1.1       cgd  *
    195   1.1       cgd  * Tim Seaver, Ken Adelman and C. Philip Wood provided bug fixes and/or
    196   1.1       cgd  * enhancements to the original distribution.
    197   1.1       cgd  *
    198   1.1       cgd  * I've hacked up a round-trip-route version of this that works by
    199   1.1       cgd  * sending a loose-source-routed udp datagram through the destination
    200   1.1       cgd  * back to yourself.  Unfortunately, SO many gateways botch source
    201   1.1       cgd  * routing, the thing is almost worthless.  Maybe one day...
    202   1.1       cgd  *
    203  1.18  christos  *  -- Van Jacobson (van (at) ee.lbl.gov)
    204   1.1       cgd  *     Tue Dec 20 03:50:13 PST 1988
    205   1.1       cgd  */
    206   1.1       cgd 
    207   1.1       cgd #include <sys/param.h>
    208   1.1       cgd #include <sys/file.h>
    209   1.1       cgd #include <sys/ioctl.h>
    210  1.18  christos #include <sys/socket.h>
    211  1.18  christos #include <sys/time.h>
    212  1.46    itojun #include <sys/sysctl.h>
    213   1.1       cgd 
    214   1.1       cgd #include <netinet/in_systm.h>
    215   1.1       cgd #include <netinet/in.h>
    216   1.1       cgd #include <netinet/ip.h>
    217  1.18  christos #include <netinet/ip_var.h>
    218   1.1       cgd #include <netinet/ip_icmp.h>
    219   1.1       cgd #include <netinet/udp.h>
    220  1.18  christos #include <netinet/udp_var.h>
    221   1.3   mycroft 
    222   1.3   mycroft #include <arpa/inet.h>
    223   1.3   mycroft 
    224   1.4   mycroft #include <ctype.h>
    225   1.4   mycroft #include <errno.h>
    226  1.18  christos #ifdef HAVE_MALLOC_H
    227  1.18  christos #include <malloc.h>
    228  1.18  christos #endif
    229  1.18  christos #include <memory.h>
    230   1.1       cgd #include <netdb.h>
    231   1.1       cgd #include <stdio.h>
    232   1.3   mycroft #include <stdlib.h>
    233   1.1       cgd #include <string.h>
    234   1.3   mycroft #include <unistd.h>
    235  1.55    itojun #include <poll.h>
    236  1.37    itojun #ifdef IPSEC
    237  1.37    itojun #include <net/route.h>
    238  1.37    itojun #include <netinet6/ipsec.h>
    239  1.37    itojun #endif
    240   1.1       cgd 
    241  1.18  christos #include "gnuc.h"
    242  1.18  christos #ifdef HAVE_OS_PROTO_H
    243  1.18  christos #include "os-proto.h"
    244  1.18  christos #endif
    245  1.18  christos 
    246  1.18  christos #include "ifaddrlist.h"
    247  1.44    atatat #include "as.h"
    248  1.18  christos 
    249  1.18  christos /* Maximum number of gateways (include room for one noop) */
    250  1.18  christos #define NGATEWAYS ((int)((MAX_IPOPTLEN - IPOPT_MINOFF - 1) / sizeof(u_int32_t)))
    251  1.18  christos 
    252  1.18  christos #ifndef MAXHOSTNAMELEN
    253  1.18  christos #define MAXHOSTNAMELEN	64
    254  1.18  christos #endif
    255  1.18  christos 
    256   1.1       cgd #define Fprintf (void)fprintf
    257   1.1       cgd #define Printf (void)printf
    258   1.1       cgd 
    259  1.18  christos /* Host name and address list */
    260  1.18  christos struct hostinfo {
    261  1.18  christos 	char *name;
    262  1.18  christos 	int n;
    263  1.18  christos 	u_int32_t *addrs;
    264  1.18  christos };
    265   1.4   mycroft 
    266  1.18  christos /* Data section of the probe packet */
    267  1.18  christos struct outdata {
    268   1.1       cgd 	u_char seq;		/* sequence number of this packet */
    269   1.1       cgd 	u_char ttl;		/* ttl packet left with */
    270   1.1       cgd 	struct timeval tv;	/* time packet left */
    271   1.1       cgd };
    272   1.1       cgd 
    273  1.18  christos u_char	packet[512];		/* last inbound (icmp) packet */
    274  1.18  christos 
    275  1.18  christos struct ip *outip;		/* last output (udp) packet */
    276  1.18  christos struct udphdr *outudp;		/* last output (udp) packet */
    277  1.21      ross void *outmark;			/* packed location of struct outdata */
    278  1.21      ross struct outdata outsetup;	/* setup and copy for alignment */
    279   1.4   mycroft 
    280  1.18  christos struct icmp *outicmp;		/* last output (icmp) packet */
    281   1.3   mycroft 
    282  1.18  christos /* loose source route gateway list (including room for final destination) */
    283  1.18  christos u_int32_t gwlist[NGATEWAYS + 1];
    284   1.1       cgd 
    285   1.1       cgd int s;				/* receive (icmp) socket file descriptor */
    286  1.18  christos int sndsock;			/* send (udp/icmp) socket file descriptor */
    287   1.1       cgd 
    288  1.18  christos struct sockaddr whereto;	/* Who to try to reach */
    289  1.18  christos struct sockaddr_in wherefrom;	/* Who we are */
    290  1.18  christos int packlen;			/* total length of packet */
    291  1.18  christos int minpacket;			/* min ip packet size */
    292  1.18  christos int maxpacket = 32 * 1024;	/* max ip packet size */
    293  1.38  sommerfe int printed_ttl = 0;
    294   1.1       cgd 
    295  1.18  christos char *prog;
    296  1.18  christos char *source;
    297   1.1       cgd char *hostname;
    298  1.18  christos char *device;
    299   1.1       cgd 
    300   1.1       cgd int nprobes = 3;
    301   1.1       cgd int max_ttl = 30;
    302  1.18  christos int first_ttl = 1;
    303  1.49    itojun u_int16_t ident;
    304  1.49    itojun in_port_t port = 32768 + 666;	/* start udp dest port # for probe packets */
    305  1.18  christos 
    306   1.1       cgd int options;			/* socket options */
    307   1.1       cgd int verbose;
    308   1.1       cgd int waittime = 5;		/* time to wait for response (in seconds) */
    309   1.1       cgd int nflag;			/* print addresses numerically */
    310   1.4   mycroft int dump;
    311  1.44    atatat int as_path;			/* print as numbers for each hop */
    312  1.44    atatat char *as_server = NULL;
    313  1.44    atatat void *asn;
    314  1.18  christos int useicmp;			/* use icmp echo instead of udp packets */
    315  1.18  christos #ifdef CANT_HACK_CKSUM
    316  1.18  christos int docksum = 0;		/* don't calculate checksums */
    317  1.18  christos #else
    318  1.18  christos int docksum = 1;		/* calculate checksums */
    319  1.18  christos #endif
    320  1.18  christos int optlen;			/* length of ip options */
    321  1.18  christos 
    322  1.24        is int mtus[] = {
    323  1.24        is         17914,
    324  1.24        is          8166,
    325  1.24        is          4464,
    326  1.24        is          4352,
    327  1.24        is          2048,
    328  1.24        is          2002,
    329  1.24        is          1536,
    330  1.24        is          1500,
    331  1.24        is          1492,
    332  1.38  sommerfe 	 1480,
    333  1.38  sommerfe 	 1280,
    334  1.24        is          1006,
    335  1.24        is           576,
    336  1.24        is           552,
    337  1.24        is           544,
    338  1.24        is           512,
    339  1.24        is           508,
    340  1.24        is           296,
    341  1.24        is            68,
    342  1.24        is             0
    343  1.24        is };
    344  1.24        is int *mtuptr = &mtus[0];
    345  1.24        is int mtudisc = 0;
    346  1.24        is int nextmtu;   /* from ICMP error, set by packet_ok(), might be 0 */
    347  1.24        is 
    348  1.18  christos extern int optind;
    349  1.18  christos extern int opterr;
    350  1.18  christos extern char *optarg;
    351  1.18  christos 
    352  1.18  christos /* Forwards */
    353  1.18  christos double	deltaT(struct timeval *, struct timeval *);
    354  1.18  christos void	freehostinfo(struct hostinfo *);
    355  1.18  christos void	getaddr(u_int32_t *, char *);
    356  1.18  christos struct	hostinfo *gethostinfo(char *);
    357  1.49    itojun u_int16_t in_cksum(u_int16_t *, int);
    358  1.49    itojun u_int16_t in_cksum2(u_int16_t, u_int16_t *, int);
    359  1.18  christos char	*inetname(struct in_addr);
    360  1.18  christos int	main(int, char **);
    361  1.18  christos int	packet_ok(u_char *, int, struct sockaddr_in *, int);
    362  1.18  christos char	*pr_type(u_char);
    363  1.18  christos void	print(u_char *, int, struct sockaddr_in *);
    364  1.38  sommerfe void	resize_packet(void);
    365  1.18  christos void	dump_packet(void);
    366  1.18  christos void	send_probe(int, int, struct timeval *);
    367  1.18  christos void	setsin(struct sockaddr_in *, u_int32_t);
    368  1.18  christos int	str2val(const char *, const char *, int, int);
    369  1.18  christos void	tvsub(struct timeval *, struct timeval *);
    370  1.18  christos __dead	void usage(void);
    371  1.18  christos int	wait_for_reply(int, struct sockaddr_in *, struct timeval *);
    372  1.24        is void	frag_err(void);
    373  1.26      tron int	find_local_ip(struct sockaddr_in *, struct sockaddr_in *);
    374  1.39    itojun #ifdef IPSEC
    375  1.39    itojun #ifdef IPSEC_POLICY_IPSEC
    376  1.39    itojun int	setpolicy(int so, char *policy);
    377  1.39    itojun #endif
    378  1.39    itojun #endif
    379   1.1       cgd 
    380   1.3   mycroft int
    381  1.18  christos main(int argc, char **argv)
    382  1.18  christos {
    383  1.50    itojun 	int op, code, n;
    384  1.50    itojun 	char *cp;
    385  1.50    itojun 	u_char *outp;
    386  1.50    itojun 	u_int32_t *ap;
    387  1.50    itojun 	struct sockaddr_in *from = &wherefrom;
    388  1.50    itojun 	struct sockaddr_in *to = (struct sockaddr_in *)&whereto;
    389  1.50    itojun 	struct hostinfo *hi;
    390  1.18  christos 	int on = 1;
    391  1.50    itojun 	int ttl, probe, i;
    392  1.50    itojun 	int seq = 0;
    393  1.18  christos 	int tos = 0, settos = 0, ttl_flag = 0;
    394  1.50    itojun 	int lsrr = 0;
    395  1.50    itojun 	u_int16_t off = 0;
    396  1.28       cjs 	struct ifaddrlist *al, *al2;
    397  1.18  christos 	char errbuf[132];
    398  1.46    itojun 	int mib[4] = { CTL_NET, PF_INET, IPPROTO_IP, IPCTL_DEFTTL };
    399  1.46    itojun 	size_t size = sizeof(max_ttl);
    400  1.46    itojun 
    401  1.46    itojun 	(void) sysctl(mib, sizeof(mib)/sizeof(mib[0]), &max_ttl, &size,
    402  1.46    itojun 	    NULL, 0);
    403  1.18  christos 
    404  1.18  christos 	if ((cp = strrchr(argv[0], '/')) != NULL)
    405  1.18  christos 		prog = cp + 1;
    406  1.18  christos 	else
    407  1.18  christos 		prog = argv[0];
    408  1.18  christos 
    409  1.18  christos 	opterr = 0;
    410  1.44    atatat 	while ((op = getopt(argc, argv, "aA:dDFPInlrvxf:g:i:m:p:q:s:t:w:")) != -1)
    411  1.18  christos 		switch (op) {
    412  1.18  christos 
    413  1.44    atatat 		case 'a':
    414  1.44    atatat 			as_path = 1;
    415  1.44    atatat 			break;
    416  1.44    atatat 
    417  1.44    atatat 		case 'A':
    418  1.44    atatat 			as_path = 1;
    419  1.44    atatat 			as_server = optarg;
    420  1.44    atatat 			break;
    421  1.44    atatat 
    422   1.1       cgd 		case 'd':
    423   1.1       cgd 			options |= SO_DEBUG;
    424   1.1       cgd 			break;
    425  1.18  christos 
    426   1.4   mycroft 		case 'D':
    427   1.4   mycroft 			dump = 1;
    428   1.4   mycroft 			break;
    429  1.18  christos 
    430  1.18  christos 		case 'f':
    431  1.18  christos 			first_ttl = str2val(optarg, "first ttl", 1, 255);
    432  1.18  christos 			break;
    433  1.18  christos 
    434  1.18  christos 		case 'F':
    435  1.18  christos 			off = IP_DF;
    436  1.18  christos 			break;
    437  1.18  christos 
    438   1.4   mycroft 		case 'g':
    439  1.18  christos 			if (lsrr >= NGATEWAYS) {
    440  1.18  christos 				Fprintf(stderr,
    441  1.18  christos 				    "%s: No more than %d gateways\n",
    442  1.18  christos 				    prog, NGATEWAYS);
    443  1.18  christos 				exit(1);
    444   1.4   mycroft 			}
    445  1.18  christos 			getaddr(gwlist + lsrr, optarg);
    446  1.18  christos 			++lsrr;
    447  1.18  christos 			break;
    448  1.18  christos 
    449  1.18  christos 		case 'i':
    450  1.18  christos 			device = optarg;
    451  1.18  christos 			break;
    452  1.18  christos 
    453  1.18  christos 		case 'I':
    454  1.18  christos 			++useicmp;
    455   1.4   mycroft 			break;
    456  1.18  christos 
    457  1.15   thorpej 		case 'l':
    458  1.18  christos 			++ttl_flag;
    459  1.15   thorpej 			break;
    460  1.18  christos 
    461   1.1       cgd 		case 'm':
    462  1.18  christos 			max_ttl = str2val(optarg, "max ttl", 1, 255);
    463   1.1       cgd 			break;
    464  1.18  christos 
    465   1.1       cgd 		case 'n':
    466  1.18  christos 			++nflag;
    467   1.1       cgd 			break;
    468  1.18  christos 
    469   1.1       cgd 		case 'p':
    470  1.18  christos 			port = str2val(optarg, "port", 1, -1);
    471   1.1       cgd 			break;
    472  1.18  christos 
    473   1.1       cgd 		case 'q':
    474  1.18  christos 			nprobes = str2val(optarg, "nprobes", 1, -1);
    475   1.1       cgd 			break;
    476  1.18  christos 
    477   1.1       cgd 		case 'r':
    478   1.1       cgd 			options |= SO_DONTROUTE;
    479   1.1       cgd 			break;
    480  1.18  christos 
    481   1.1       cgd 		case 's':
    482   1.1       cgd 			/*
    483   1.1       cgd 			 * set the ip source address of the outbound
    484   1.1       cgd 			 * probe (e.g., on a multi-homed host).
    485   1.1       cgd 			 */
    486   1.1       cgd 			source = optarg;
    487   1.1       cgd 			break;
    488  1.18  christos 
    489   1.1       cgd 		case 't':
    490  1.18  christos 			tos = str2val(optarg, "tos", 0, 255);
    491  1.18  christos 			++settos;
    492   1.1       cgd 			break;
    493  1.18  christos 
    494   1.1       cgd 		case 'v':
    495  1.18  christos 			++verbose;
    496   1.1       cgd 			break;
    497  1.18  christos 
    498  1.18  christos 		case 'x':
    499  1.18  christos 			docksum = (docksum == 0);
    500  1.18  christos 			break;
    501  1.18  christos 
    502   1.1       cgd 		case 'w':
    503  1.30  christos 			waittime = str2val(optarg, "wait time", 2, 24 * 3600);
    504   1.1       cgd 			break;
    505  1.18  christos 
    506  1.24        is 		case 'P':
    507  1.24        is 			off = IP_DF;
    508  1.24        is 			mtudisc = 1;
    509  1.24        is 			break;
    510  1.24        is 
    511   1.1       cgd 		default:
    512   1.1       cgd 			usage();
    513   1.1       cgd 		}
    514   1.1       cgd 
    515  1.18  christos 	if (first_ttl > max_ttl) {
    516  1.18  christos 		Fprintf(stderr,
    517  1.18  christos 		    "%s: first ttl (%d) may not be greater than max ttl (%d)\n",
    518  1.18  christos 		    prog, first_ttl, max_ttl);
    519  1.18  christos 		exit(1);
    520  1.18  christos 	}
    521  1.18  christos 
    522  1.18  christos 	if (!docksum)
    523  1.18  christos 		Fprintf(stderr, "%s: Warning: ckecksums disabled\n", prog);
    524  1.18  christos 
    525  1.18  christos 	if (lsrr > 0)
    526  1.18  christos 		optlen = (lsrr + 1) * sizeof(gwlist[0]);
    527  1.21      ross 	minpacket = sizeof(*outip) + sizeof(struct outdata) + optlen;
    528  1.18  christos 	if (useicmp)
    529  1.18  christos 		minpacket += 8;			/* XXX magic number */
    530  1.18  christos 	else
    531  1.18  christos 		minpacket += sizeof(*outudp);
    532  1.18  christos 	if (packlen == 0)
    533  1.18  christos 		packlen = minpacket;		/* minimum sized packet */
    534  1.18  christos 	else if (minpacket > packlen || packlen > maxpacket) {
    535  1.18  christos 		Fprintf(stderr, "%s: packet size must be %d <= s <= %d\n",
    536  1.18  christos 		    prog, minpacket, maxpacket);
    537  1.18  christos 		exit(1);
    538  1.18  christos 	}
    539  1.18  christos 
    540  1.24        is 	if (mtudisc)
    541  1.24        is 		packlen = *mtuptr++;
    542  1.24        is 
    543  1.18  christos 	/* Process destination and optional packet size */
    544  1.18  christos 	switch (argc - optind) {
    545  1.18  christos 
    546  1.18  christos 	case 2:
    547  1.18  christos 		packlen = str2val(argv[optind + 1],
    548  1.18  christos 		    "packet length", minpacket, -1);
    549  1.18  christos 		/* Fall through */
    550  1.18  christos 
    551  1.18  christos 	case 1:
    552  1.18  christos 		hostname = argv[optind];
    553  1.18  christos 		hi = gethostinfo(hostname);
    554  1.18  christos 		setsin(to, hi->addrs[0]);
    555  1.18  christos 		if (hi->n > 1)
    556  1.18  christos 			Fprintf(stderr,
    557  1.18  christos 		    "%s: Warning: %s has multiple addresses; using %s\n",
    558  1.18  christos 				prog, hostname, inet_ntoa(to->sin_addr));
    559  1.18  christos 		hostname = hi->name;
    560  1.18  christos 		hi->name = NULL;
    561  1.18  christos 		freehostinfo(hi);
    562  1.18  christos 		break;
    563  1.18  christos 
    564  1.18  christos 	default:
    565   1.1       cgd 		usage();
    566  1.18  christos 	}
    567   1.1       cgd 
    568  1.18  christos #ifdef HAVE_SETLINEBUF
    569   1.1       cgd 	setlinebuf (stdout);
    570  1.18  christos #else
    571  1.18  christos 	setvbuf(stdout, NULL, _IOLBF, 0);
    572  1.18  christos #endif
    573  1.18  christos 
    574  1.18  christos 	outip = (struct ip *)malloc((unsigned)packlen);
    575  1.18  christos 	if (outip == NULL) {
    576  1.18  christos 		Fprintf(stderr, "%s: malloc: %s\n", prog, strerror(errno));
    577  1.18  christos 		exit(1);
    578  1.18  christos 	}
    579  1.18  christos 	memset((char *)outip, 0, packlen);
    580   1.1       cgd 
    581  1.18  christos 	outip->ip_v = IPVERSION;
    582  1.18  christos 	if (settos)
    583  1.18  christos 		outip->ip_tos = tos;
    584  1.18  christos #ifdef BYTESWAP_IP_LEN
    585  1.18  christos 	outip->ip_len = htons(packlen);
    586  1.18  christos #else
    587  1.18  christos 	outip->ip_len = packlen;
    588  1.18  christos #endif
    589  1.18  christos 	outip->ip_off = off;
    590  1.18  christos 	outp = (u_char *)(outip + 1);
    591  1.18  christos #ifdef HAVE_RAW_OPTIONS
    592  1.18  christos 	if (lsrr > 0) {
    593  1.50    itojun 		u_char *optlist;
    594  1.18  christos 
    595  1.18  christos 		optlist = outp;
    596  1.18  christos 		outp += optlen;
    597  1.18  christos 
    598  1.18  christos 		/* final hop */
    599  1.18  christos 		gwlist[lsrr] = to->sin_addr.s_addr;
    600  1.18  christos 
    601  1.18  christos 		outip->ip_dst.s_addr = gwlist[0];
    602  1.18  christos 
    603  1.18  christos 		/* force 4 byte alignment */
    604  1.18  christos 		optlist[0] = IPOPT_NOP;
    605  1.18  christos 		/* loose source route option */
    606  1.18  christos 		optlist[1] = IPOPT_LSRR;
    607  1.18  christos 		i = lsrr * sizeof(gwlist[0]);
    608  1.18  christos 		optlist[2] = i + 3;
    609  1.18  christos 		/* Pointer to LSRR addresses */
    610  1.18  christos 		optlist[3] = IPOPT_MINOFF;
    611  1.18  christos 		memcpy(optlist + 4, gwlist + 1, i);
    612   1.4   mycroft 	} else
    613  1.18  christos #endif
    614  1.18  christos 		outip->ip_dst = to->sin_addr;
    615   1.1       cgd 
    616  1.18  christos 	outip->ip_hl = (outp - (u_char *)outip) >> 2;
    617  1.61    itojun 	ident = htons(arc4random() & 0xffff) | 0x8000;
    618  1.18  christos 	if (useicmp) {
    619  1.18  christos 		outip->ip_p = IPPROTO_ICMP;
    620  1.18  christos 
    621  1.18  christos 		outicmp = (struct icmp *)outp;
    622  1.18  christos 		outicmp->icmp_type = ICMP_ECHO;
    623  1.18  christos 		outicmp->icmp_id = htons(ident);
    624   1.1       cgd 
    625  1.21      ross 		outmark = outp + 8;	/* XXX magic number */
    626  1.18  christos 	} else {
    627  1.18  christos 		outip->ip_p = IPPROTO_UDP;
    628  1.18  christos 
    629  1.18  christos 		outudp = (struct udphdr *)outp;
    630  1.18  christos 		outudp->uh_sport = htons(ident);
    631  1.18  christos 		outudp->uh_ulen =
    632  1.49    itojun 		    htons((u_int16_t)(packlen - (sizeof(*outip) + optlen)));
    633  1.21      ross 		outmark = outudp + 1;
    634  1.18  christos 	}
    635  1.18  christos 
    636  1.47    itojun 	if ((s = socket(AF_INET, SOCK_RAW, IPPROTO_ICMP)) < 0) {
    637  1.18  christos 		Fprintf(stderr, "%s: icmp socket: %s\n", prog, strerror(errno));
    638  1.18  christos 		exit(1);
    639   1.1       cgd 	}
    640   1.1       cgd 	if (options & SO_DEBUG)
    641  1.18  christos 		(void)setsockopt(s, SOL_SOCKET, SO_DEBUG, (char *)&on,
    642  1.18  christos 		    sizeof(on));
    643  1.37    itojun #ifdef IPSEC
    644  1.37    itojun #ifdef IPSEC_POLICY_IPSEC
    645  1.37    itojun 	/*
    646  1.37    itojun 	 * do not raise error even if setsockopt fails, kernel may have ipsec
    647  1.37    itojun 	 * turned off.
    648  1.37    itojun 	 */
    649  1.39    itojun 	if (setpolicy(s, "in bypass") < 0)
    650  1.39    itojun 		exit(1);
    651  1.39    itojun 	if (setpolicy(s, "out bypass") < 0)
    652  1.37    itojun 		exit(1);
    653  1.37    itojun #else
    654  1.37    itojun     {
    655  1.37    itojun 	int level = IPSEC_LEVEL_AVAIL;
    656  1.37    itojun 
    657  1.37    itojun 	(void)setsockopt(s, IPPROTO_IP, IP_ESP_TRANS_LEVEL, &level,
    658  1.37    itojun 		sizeof(level));
    659  1.37    itojun 	(void)setsockopt(s, IPPROTO_IP, IP_ESP_NETWORK_LEVEL, &level,
    660  1.37    itojun 		sizeof(level));
    661  1.37    itojun #ifdef IP_AUTH_TRANS_LEVEL
    662  1.37    itojun 	(void)setsockopt(s, IPPROTO_IP, IP_AUTH_TRANS_LEVEL, &level,
    663  1.37    itojun 		sizeof(level));
    664  1.37    itojun #else
    665  1.37    itojun 	(void)setsockopt(s, IPPROTO_IP, IP_AUTH_LEVEL, &level,
    666  1.37    itojun 		sizeof(level));
    667  1.37    itojun #endif
    668  1.37    itojun #ifdef IP_AUTH_NETWORK_LEVEL
    669  1.37    itojun 	(void)setsockopt(s, IPPROTO_IP, IP_AUTH_NETWORK_LEVEL, &level,
    670  1.37    itojun 		sizeof(level));
    671  1.37    itojun #endif
    672  1.37    itojun     }
    673  1.37    itojun #endif /*IPSEC_POLICY_IPSEC*/
    674  1.37    itojun #endif /*IPSEC*/
    675  1.18  christos 
    676  1.18  christos #ifndef __hpux
    677  1.18  christos 	sndsock = socket(AF_INET, SOCK_RAW, IPPROTO_RAW);
    678  1.18  christos #else
    679  1.18  christos 	sndsock = socket(AF_INET, SOCK_RAW,
    680  1.18  christos 	    useicmp ? IPPROTO_ICMP : IPPROTO_UDP);
    681  1.18  christos #endif
    682  1.18  christos 	if (sndsock < 0) {
    683  1.18  christos 		Fprintf(stderr, "%s: raw socket: %s\n", prog, strerror(errno));
    684  1.18  christos 		exit(1);
    685  1.18  christos 	}
    686  1.37    itojun 
    687  1.37    itojun #ifdef IPSEC
    688  1.37    itojun #ifdef IPSEC_POLICY_IPSEC
    689  1.37    itojun 	/*
    690  1.37    itojun 	 * do not raise error even if setsockopt fails, kernel may have ipsec
    691  1.37    itojun 	 * turned off.
    692  1.37    itojun 	 */
    693  1.39    itojun 	if (setpolicy(sndsock, "in bypass") < 0)
    694  1.39    itojun 		exit(1);
    695  1.39    itojun 	if (setpolicy(sndsock, "out bypass") < 0)
    696  1.37    itojun 		exit(1);
    697  1.37    itojun #else
    698  1.37    itojun     {
    699  1.37    itojun 	int level = IPSEC_LEVEL_BYPASS;
    700  1.37    itojun 
    701  1.37    itojun 	(void)setsockopt(sndsock, IPPROTO_IP, IP_ESP_TRANS_LEVEL, &level,
    702  1.37    itojun 		sizeof(level));
    703  1.37    itojun 	(void)setsockopt(sndsock, IPPROTO_IP, IP_ESP_NETWORK_LEVEL, &level,
    704  1.37    itojun 		sizeof(level));
    705  1.37    itojun #ifdef IP_AUTH_TRANS_LEVEL
    706  1.37    itojun 	(void)setsockopt(sndsock, IPPROTO_IP, IP_AUTH_TRANS_LEVEL, &level,
    707  1.37    itojun 		sizeof(level));
    708  1.37    itojun #else
    709  1.37    itojun 	(void)setsockopt(sndsock, IPPROTO_IP, IP_AUTH_LEVEL, &level,
    710  1.37    itojun 		sizeof(level));
    711  1.37    itojun #endif
    712  1.37    itojun #ifdef IP_AUTH_NETWORK_LEVEL
    713  1.37    itojun 	(void)setsockopt(sndsock, IPPROTO_IP, IP_AUTH_NETWORK_LEVEL, &level,
    714  1.37    itojun 		sizeof(level));
    715  1.37    itojun #endif
    716  1.37    itojun     }
    717  1.37    itojun #endif /*IPSEC_POLICY_IPSEC*/
    718  1.37    itojun #endif /*IPSEC*/
    719   1.1       cgd 
    720  1.18  christos 	/* Revert to non-privileged user after opening sockets */
    721  1.18  christos 	setuid(getuid());
    722  1.18  christos 
    723  1.18  christos #if defined(IP_OPTIONS) && !defined(HAVE_RAW_OPTIONS)
    724  1.18  christos 	if (lsrr > 0) {
    725  1.18  christos 		u_char optlist[MAX_IPOPTLEN];
    726  1.18  christos 
    727  1.18  christos 		/* final hop */
    728  1.18  christos 		gwlist[lsrr] = to->sin_addr.s_addr;
    729  1.18  christos 		++lsrr;
    730  1.18  christos 
    731  1.18  christos 		/* force 4 byte alignment */
    732  1.18  christos 		optlist[0] = IPOPT_NOP;
    733  1.18  christos 		/* loose source route option */
    734  1.18  christos 		optlist[1] = IPOPT_LSRR;
    735  1.18  christos 		i = lsrr * sizeof(gwlist[0]);
    736  1.18  christos 		optlist[2] = i + 3;
    737  1.18  christos 		/* Pointer to LSRR addresses */
    738  1.18  christos 		optlist[3] = IPOPT_MINOFF;
    739  1.18  christos 		memcpy(optlist + 4, gwlist, i);
    740  1.18  christos 
    741  1.47    itojun 		if ((setsockopt(sndsock, IPPROTO_IP, IP_OPTIONS, optlist,
    742  1.18  christos 		    i + sizeof(gwlist[0]))) < 0) {
    743  1.18  christos 			Fprintf(stderr, "%s: IP_OPTIONS: %s\n",
    744  1.18  christos 			    prog, strerror(errno));
    745  1.18  christos 			exit(1);
    746  1.18  christos 		    }
    747  1.18  christos 	}
    748  1.18  christos #endif
    749   1.4   mycroft 
    750   1.1       cgd #ifdef SO_SNDBUF
    751  1.18  christos 	if (setsockopt(sndsock, SOL_SOCKET, SO_SNDBUF, (char *)&packlen,
    752  1.18  christos 	    sizeof(packlen)) < 0) {
    753  1.18  christos 		Fprintf(stderr, "%s: SO_SNDBUF: %s\n", prog, strerror(errno));
    754  1.18  christos 		exit(1);
    755  1.18  christos 	}
    756  1.18  christos #endif
    757   1.1       cgd #ifdef IP_HDRINCL
    758   1.1       cgd 	if (setsockopt(sndsock, IPPROTO_IP, IP_HDRINCL, (char *)&on,
    759  1.18  christos 	    sizeof(on)) < 0) {
    760  1.18  christos 		Fprintf(stderr, "%s: IP_HDRINCL: %s\n", prog, strerror(errno));
    761  1.18  christos 		exit(1);
    762  1.18  christos 	}
    763  1.18  christos #else
    764  1.18  christos #ifdef IP_TOS
    765  1.18  christos 	if (settos && setsockopt(sndsock, IPPROTO_IP, IP_TOS,
    766  1.18  christos 	    (char *)&tos, sizeof(tos)) < 0) {
    767  1.18  christos 		Fprintf(stderr, "%s: setsockopt tos %d: %s\n",
    768  1.18  christos 		    prog, tos, strerror(errno));
    769  1.18  christos 		exit(1);
    770  1.18  christos 	}
    771  1.18  christos #endif
    772  1.18  christos #endif
    773   1.1       cgd 	if (options & SO_DEBUG)
    774  1.18  christos 		(void)setsockopt(sndsock, SOL_SOCKET, SO_DEBUG, (char *)&on,
    775  1.18  christos 		    sizeof(on));
    776   1.1       cgd 	if (options & SO_DONTROUTE)
    777  1.18  christos 		(void)setsockopt(sndsock, SOL_SOCKET, SO_DONTROUTE, (char *)&on,
    778  1.18  christos 		    sizeof(on));
    779   1.1       cgd 
    780  1.18  christos 	/* Get the interface address list */
    781  1.22       mrg 	n = ifaddrlist(&al, errbuf, sizeof errbuf);
    782  1.28       cjs 	al2 = al;
    783  1.18  christos 	if (n < 0) {
    784  1.18  christos 		Fprintf(stderr, "%s: ifaddrlist: %s\n", prog, errbuf);
    785  1.18  christos 		exit(1);
    786  1.18  christos 	}
    787  1.18  christos 	if (n == 0) {
    788  1.18  christos 		Fprintf(stderr,
    789  1.18  christos 		    "%s: Can't find any network interfaces\n", prog);
    790  1.18  christos 		exit(1);
    791  1.18  christos 	}
    792  1.18  christos 
    793  1.18  christos 	/* Look for a specific device */
    794  1.18  christos 	if (device != NULL) {
    795  1.28       cjs 		for (i = n; i > 0; --i, ++al2)
    796  1.28       cjs 			if (strcmp(device, al2->device) == 0)
    797  1.18  christos 				break;
    798  1.18  christos 		if (i <= 0) {
    799  1.18  christos 			Fprintf(stderr, "%s: Can't find interface %s\n",
    800  1.18  christos 			    prog, device);
    801  1.18  christos 			exit(1);
    802  1.18  christos 		}
    803  1.18  christos 	}
    804  1.18  christos 
    805  1.18  christos 	/* Determine our source address */
    806  1.18  christos 	if (source == NULL) {
    807  1.18  christos 		/*
    808  1.18  christos 		 * If a device was specified, use the interface address.
    809  1.18  christos 		 * Otherwise, use the first interface found.
    810  1.18  christos 		 * Warn if there are more than one.
    811  1.18  christos 		 */
    812  1.28       cjs 		setsin(from, al2->addr);
    813  1.26      tron 		if (n > 1 && device == NULL && !find_local_ip(from, to)) {
    814  1.18  christos 			Fprintf(stderr,
    815  1.18  christos 		    "%s: Warning: Multiple interfaces found; using %s @ %s\n",
    816  1.28       cjs 			    prog, inet_ntoa(from->sin_addr), al2->device);
    817  1.18  christos 		}
    818  1.18  christos 	} else {
    819  1.18  christos 		hi = gethostinfo(source);
    820  1.18  christos 		source = hi->name;
    821  1.18  christos 		hi->name = NULL;
    822  1.18  christos 		if (device == NULL) {
    823  1.18  christos 			/*
    824  1.18  christos 			 * Use the first interface found.
    825  1.18  christos 			 * Warn if there are more than one.
    826  1.18  christos 			 */
    827  1.18  christos 			setsin(from, hi->addrs[0]);
    828  1.18  christos 			if (hi->n > 1)
    829  1.18  christos 				Fprintf(stderr,
    830  1.18  christos 			"%s: Warning: %s has multiple addresses; using %s\n",
    831  1.18  christos 				    prog, source, inet_ntoa(from->sin_addr));
    832  1.18  christos 		} else {
    833  1.18  christos 			/*
    834  1.18  christos 			 * Make sure the source specified matches the
    835  1.18  christos 			 * interface address.
    836  1.18  christos 			 */
    837  1.18  christos 			for (i = hi->n, ap = hi->addrs; i > 0; --i, ++ap)
    838  1.28       cjs 				if (*ap == al2->addr)
    839  1.18  christos 					break;
    840  1.18  christos 			if (i <= 0) {
    841  1.18  christos 				Fprintf(stderr,
    842  1.18  christos 				    "%s: %s is not on interface %s\n",
    843  1.18  christos 				    prog, source, device);
    844  1.18  christos 				exit(1);
    845  1.18  christos 			}
    846  1.18  christos 			setsin(from, *ap);
    847  1.18  christos 		}
    848  1.18  christos 		freehostinfo(hi);
    849  1.18  christos 	}
    850  1.28       cjs 
    851  1.28       cjs 	/*
    852  1.28       cjs 	 * If not root, make sure source address matches a local interface.
    853  1.28       cjs 	 * (The list of addresses produced by ifaddrlist() automatically
    854  1.28       cjs 	 * excludes interfaces that are marked down and/or loopback.)
    855  1.28       cjs 	 */
    856  1.28       cjs 	if (getuid())  {
    857  1.28       cjs 		al2 = al;
    858  1.28       cjs 		for (i = n; i > 0; --i, ++al2)
    859  1.28       cjs 			if (from->sin_addr.s_addr == al2->addr)
    860  1.28       cjs 			    break;
    861  1.28       cjs 		if (i <= 0) {
    862  1.28       cjs 			Fprintf(stderr, "%s: %s is not a valid local address "
    863  1.28       cjs 			    "and you are not superuser.\n", prog,
    864  1.28       cjs 			    inet_ntoa(from->sin_addr));
    865  1.28       cjs 			exit(1);
    866  1.28       cjs 		}
    867  1.28       cjs 	}
    868  1.28       cjs 
    869  1.18  christos 	outip->ip_src = from->sin_addr;
    870   1.1       cgd #ifndef IP_HDRINCL
    871  1.18  christos 	if (bind(sndsock, (struct sockaddr *)from, sizeof(*from)) < 0) {
    872  1.18  christos 		Fprintf(stderr, "%s: bind: %s\n",
    873  1.18  christos 		    prog, strerror(errno));
    874  1.18  christos 		exit (1);
    875   1.1       cgd 	}
    876  1.18  christos #endif
    877   1.1       cgd 
    878  1.44    atatat 	if (as_path) {
    879  1.44    atatat 		asn = as_setup(as_server);
    880  1.44    atatat 		if (asn == NULL) {
    881  1.44    atatat 			Fprintf(stderr, "%s: as_setup failed, AS# lookups disabled\n",
    882  1.44    atatat 				prog);
    883  1.44    atatat 			(void)fflush(stderr);
    884  1.44    atatat 			as_path = 0;
    885  1.44    atatat 		}
    886  1.44    atatat 	}
    887  1.44    atatat 
    888  1.14  explorer 	setuid(getuid());
    889  1.18  christos 	Fprintf(stderr, "%s to %s (%s)",
    890  1.18  christos 	    prog, hostname, inet_ntoa(to->sin_addr));
    891   1.1       cgd 	if (source)
    892   1.1       cgd 		Fprintf(stderr, " from %s", source);
    893  1.18  christos 	Fprintf(stderr, ", %d hops max, %d byte packets\n", max_ttl, packlen);
    894  1.18  christos 	(void)fflush(stderr);
    895   1.1       cgd 
    896  1.18  christos 	for (ttl = first_ttl; ttl <= max_ttl; ++ttl) {
    897  1.18  christos 		u_int32_t lastaddr = 0;
    898   1.1       cgd 		int got_there = 0;
    899   1.1       cgd 		int unreachable = 0;
    900   1.1       cgd 
    901  1.24        is again:
    902  1.38  sommerfe 		printed_ttl = 0;
    903   1.1       cgd 		for (probe = 0; probe < nprobes; ++probe) {
    904  1.50    itojun 			int cc;
    905   1.3   mycroft 			struct timeval t1, t2;
    906  1.50    itojun 			struct ip *ip;
    907  1.52    itojun 			(void)gettimeofday(&t1, NULL);
    908  1.18  christos 			send_probe(++seq, ttl, &t1);
    909  1.18  christos 			while ((cc = wait_for_reply(s, from, &t1)) != 0) {
    910  1.52    itojun 				(void)gettimeofday(&t2, NULL);
    911  1.12  explorer 				/*
    912  1.12  explorer 				 * Since we'll be receiving all ICMP
    913  1.12  explorer 				 * messages to this host above, we may
    914  1.12  explorer 				 * never end up with cc=0, so we need
    915  1.12  explorer 				 * an additional termination check.
    916  1.12  explorer 				 */
    917  1.12  explorer 				if (t2.tv_sec - t1.tv_sec > waittime) {
    918  1.13  explorer 					cc = 0;
    919  1.12  explorer 					break;
    920  1.12  explorer 				}
    921  1.18  christos 				i = packet_ok(packet, cc, from, seq);
    922  1.18  christos 				/* Skip short packet */
    923  1.18  christos 				if (i == 0)
    924  1.18  christos 					continue;
    925  1.18  christos 				if (from->sin_addr.s_addr != lastaddr) {
    926  1.18  christos 					print(packet, cc, from);
    927  1.18  christos 					lastaddr = from->sin_addr.s_addr;
    928  1.18  christos 				}
    929  1.18  christos 				ip = (struct ip *)packet;
    930  1.18  christos 				Printf("  %.3f ms", deltaT(&t1, &t2));
    931  1.18  christos 				if (ttl_flag)
    932  1.18  christos 					Printf(" (ttl = %d)", ip->ip_ttl);
    933  1.18  christos 				if (i == -2) {
    934   1.1       cgd #ifndef ARCHAIC
    935  1.18  christos 					if (ip->ip_ttl <= 1)
    936  1.18  christos 						Printf(" !");
    937  1.18  christos #endif
    938  1.18  christos 					++got_there;
    939   1.1       cgd 					break;
    940   1.1       cgd 				}
    941  1.24        is 
    942  1.18  christos 				/* time exceeded in transit */
    943  1.18  christos 				if (i == -1)
    944  1.18  christos 					break;
    945  1.18  christos 				code = i - 1;
    946  1.18  christos 				switch (code) {
    947  1.18  christos 
    948  1.18  christos 				case ICMP_UNREACH_PORT:
    949  1.18  christos #ifndef ARCHAIC
    950  1.18  christos 					if (ip->ip_ttl <= 1)
    951  1.18  christos 						Printf(" !");
    952  1.18  christos #endif
    953  1.18  christos 					++got_there;
    954  1.18  christos 					break;
    955  1.18  christos 
    956  1.18  christos 				case ICMP_UNREACH_NET:
    957  1.18  christos 					++unreachable;
    958  1.18  christos 					Printf(" !N");
    959  1.18  christos 					break;
    960  1.18  christos 
    961  1.18  christos 				case ICMP_UNREACH_HOST:
    962  1.18  christos 					++unreachable;
    963  1.18  christos 					Printf(" !H");
    964  1.18  christos 					break;
    965  1.18  christos 
    966  1.18  christos 				case ICMP_UNREACH_PROTOCOL:
    967  1.18  christos 					++got_there;
    968  1.18  christos 					Printf(" !P");
    969  1.18  christos 					break;
    970  1.18  christos 
    971  1.18  christos 				case ICMP_UNREACH_NEEDFRAG:
    972  1.24        is 					if (mtudisc) {
    973  1.24        is 						frag_err();
    974  1.24        is 						goto again;
    975  1.24        is 					} else {
    976  1.24        is 						++unreachable;
    977  1.24        is 						Printf(" !F");
    978  1.24        is 					}
    979  1.18  christos 					break;
    980  1.18  christos 
    981  1.18  christos 				case ICMP_UNREACH_SRCFAIL:
    982  1.18  christos 					++unreachable;
    983  1.18  christos 					Printf(" !S");
    984  1.18  christos 					break;
    985  1.18  christos 
    986  1.18  christos /* rfc1716 */
    987  1.18  christos #ifndef ICMP_UNREACH_FILTER_PROHIB
    988  1.18  christos #define ICMP_UNREACH_FILTER_PROHIB	13	/* admin prohibited filter */
    989  1.18  christos #endif
    990  1.18  christos 				case ICMP_UNREACH_FILTER_PROHIB:
    991  1.18  christos 					++unreachable;
    992  1.18  christos 					Printf(" !X");
    993  1.18  christos 					break;
    994  1.18  christos 
    995  1.18  christos 				default:
    996  1.18  christos 					++unreachable;
    997  1.18  christos 					Printf(" !<%d>", code);
    998  1.18  christos 					break;
    999  1.18  christos 				}
   1000  1.18  christos 				break;
   1001   1.1       cgd 			}
   1002   1.1       cgd 			if (cc == 0)
   1003   1.1       cgd 				Printf(" *");
   1004  1.18  christos 			(void)fflush(stdout);
   1005   1.1       cgd 		}
   1006   1.1       cgd 		putchar('\n');
   1007  1.18  christos 		if (got_there ||
   1008  1.36       kim 		    (unreachable > 0 && unreachable >= ((nprobes + 1) / 2)))
   1009  1.18  christos 			break;
   1010   1.1       cgd 	}
   1011  1.44    atatat 
   1012  1.44    atatat 	if (as_path)
   1013  1.44    atatat 		as_shutdown(asn);
   1014  1.44    atatat 
   1015  1.18  christos 	exit(0);
   1016   1.1       cgd }
   1017   1.1       cgd 
   1018   1.3   mycroft int
   1019  1.50    itojun wait_for_reply(int sock, struct sockaddr_in *fromp, struct timeval *tp)
   1020   1.1       cgd {
   1021  1.54   mycroft 	struct pollfd set[1];
   1022  1.18  christos 	struct timeval now, wait;
   1023  1.50    itojun 	int cc = 0;
   1024  1.18  christos 	int fromlen = sizeof(*fromp);
   1025  1.27       cjs 	int retval;
   1026   1.1       cgd 
   1027  1.54   mycroft 	set[0].fd = sock;
   1028  1.54   mycroft 	set[0].events = POLLIN;
   1029   1.1       cgd 
   1030  1.18  christos 	wait.tv_sec = tp->tv_sec + waittime;
   1031  1.18  christos 	wait.tv_usec = tp->tv_usec;
   1032  1.52    itojun 	(void)gettimeofday(&now, NULL);
   1033  1.18  christos 	tvsub(&wait, &now);
   1034  1.45      yamt 
   1035  1.45      yamt 	if (wait.tv_sec < 0) {
   1036  1.45      yamt 		wait.tv_sec = 0;
   1037  1.45      yamt 		wait.tv_usec = 0;
   1038  1.45      yamt 	}
   1039  1.18  christos 
   1040  1.54   mycroft 	retval = poll(set, 1, wait.tv_sec * 1000 + wait.tv_usec / 1000);
   1041  1.27       cjs 	if (retval < 0)  {
   1042  1.27       cjs 		/* If we continue, we probably just flood the remote host. */
   1043  1.27       cjs 		Fprintf(stderr, "%s: select: %s\n", prog, strerror(errno));
   1044  1.27       cjs 		exit(1);
   1045  1.27       cjs 	}
   1046  1.27       cjs 	if (retval > 0)  {
   1047  1.18  christos 		cc = recvfrom(s, (char *)packet, sizeof(packet), 0,
   1048  1.18  christos 			    (struct sockaddr *)fromp, &fromlen);
   1049  1.27       cjs 	}
   1050   1.1       cgd 
   1051   1.1       cgd 	return(cc);
   1052   1.1       cgd }
   1053   1.1       cgd 
   1054   1.4   mycroft void
   1055   1.4   mycroft dump_packet()
   1056   1.4   mycroft {
   1057   1.4   mycroft 	u_char *p;
   1058   1.4   mycroft 	int i;
   1059   1.4   mycroft 
   1060   1.4   mycroft 	Fprintf(stderr, "packet data:");
   1061  1.18  christos 
   1062  1.18  christos #ifdef __hpux
   1063  1.18  christos 	for (p = useicmp ? (u_char *)outicmp : (u_char *)outudp, i = 0; i <
   1064  1.18  christos 	    i < packlen - (sizeof(*outip) + optlen); i++)
   1065  1.18  christos #else
   1066  1.18  christos 	for (p = (u_char *)outip, i = 0; i < packlen; i++)
   1067  1.18  christos #endif
   1068  1.18  christos 	{
   1069   1.4   mycroft 		if ((i % 24) == 0)
   1070   1.4   mycroft 			Fprintf(stderr, "\n ");
   1071   1.4   mycroft 		Fprintf(stderr, " %02x", *p++);
   1072   1.4   mycroft 	}
   1073   1.4   mycroft 	Fprintf(stderr, "\n");
   1074   1.4   mycroft }
   1075   1.1       cgd 
   1076   1.3   mycroft void
   1077  1.50    itojun send_probe(int seq, int ttl, struct timeval *tp)
   1078  1.18  christos {
   1079  1.50    itojun 	int cc;
   1080  1.50    itojun 	struct udpiphdr * ui;
   1081  1.38  sommerfe 	int oldmtu = packlen;
   1082  1.18  christos 
   1083  1.24        is again:
   1084  1.24        is #ifdef BYTESWAP_IP_LEN
   1085  1.24        is 	outip->ip_len = htons(packlen);
   1086  1.24        is #else
   1087  1.24        is 	outip->ip_len = packlen;
   1088  1.24        is #endif
   1089  1.18  christos 	outip->ip_ttl = ttl;
   1090  1.18  christos #ifndef __hpux
   1091  1.18  christos 	outip->ip_id = htons(ident + seq);
   1092  1.18  christos #endif
   1093  1.18  christos 
   1094  1.18  christos 	/*
   1095  1.18  christos 	 * In most cases, the kernel will recalculate the ip checksum.
   1096  1.18  christos 	 * But we must do it anyway so that the udp checksum comes out
   1097  1.18  christos 	 * right.
   1098  1.18  christos 	 */
   1099  1.18  christos 	if (docksum) {
   1100  1.18  christos 		outip->ip_sum =
   1101  1.49    itojun 		    in_cksum((u_int16_t *)outip, sizeof(*outip) + optlen);
   1102  1.18  christos 		if (outip->ip_sum == 0)
   1103  1.18  christos 			outip->ip_sum = 0xffff;
   1104  1.18  christos 	}
   1105  1.18  christos 
   1106  1.18  christos 	/* Payload */
   1107  1.20      ross 	outsetup.seq = seq;
   1108  1.20      ross 	outsetup.ttl = ttl;
   1109  1.20      ross 	outsetup.tv  = *tp;
   1110  1.21      ross 	memcpy(outmark,&outsetup,sizeof(outsetup));
   1111  1.18  christos 
   1112  1.18  christos 	if (useicmp)
   1113  1.18  christos 		outicmp->icmp_seq = htons(seq);
   1114  1.18  christos 	else
   1115  1.18  christos 		outudp->uh_dport = htons(port + seq);
   1116  1.18  christos 
   1117  1.18  christos 	/* (We can only do the checksum if we know our ip address) */
   1118  1.18  christos 	if (docksum) {
   1119  1.18  christos 		if (useicmp) {
   1120  1.18  christos 			outicmp->icmp_cksum = 0;
   1121  1.49    itojun 			outicmp->icmp_cksum = in_cksum((u_int16_t *)outicmp,
   1122  1.18  christos 			    packlen - (sizeof(*outip) + optlen));
   1123  1.18  christos 			if (outicmp->icmp_cksum == 0)
   1124  1.18  christos 				outicmp->icmp_cksum = 0xffff;
   1125  1.18  christos 		} else {
   1126  1.49    itojun 			u_int16_t sum;
   1127  1.43      yamt 			struct {
   1128  1.43      yamt 				struct in_addr src;
   1129  1.43      yamt 				struct in_addr dst;
   1130  1.43      yamt 				u_int8_t zero;
   1131  1.43      yamt 				u_int8_t protocol;
   1132  1.43      yamt 				u_int16_t len;
   1133  1.43      yamt 			} __attribute__((__packed__)) phdr;
   1134  1.43      yamt 
   1135  1.43      yamt 			/* Checksum */
   1136  1.18  christos 			ui = (struct udpiphdr *)outip;
   1137  1.43      yamt 			memset(&phdr, 0, sizeof(phdr));
   1138  1.43      yamt 			phdr.src = ui->ui_src;
   1139  1.43      yamt 			phdr.dst = ((struct sockaddr_in *)&whereto)->sin_addr;
   1140  1.43      yamt 			phdr.protocol = ui->ui_pr;
   1141  1.43      yamt 			phdr.len = outudp->uh_ulen;
   1142  1.18  christos 			outudp->uh_sum = 0;
   1143  1.49    itojun 			sum = in_cksum2(0, (u_int16_t *)&phdr, sizeof(phdr));
   1144  1.49    itojun 			sum = in_cksum2(sum, (u_int16_t *)outudp, ntohs(outudp->uh_ulen));
   1145  1.48       scw 			sum = ~sum;	/** XXXSCW: Quell SuperH Compiler Bug */
   1146  1.48       scw 			outudp->uh_sum = sum;
   1147  1.18  christos 			if (outudp->uh_sum == 0)
   1148  1.18  christos 				outudp->uh_sum = 0xffff;
   1149  1.18  christos 		}
   1150  1.18  christos 	}
   1151   1.1       cgd 
   1152  1.18  christos 	/* XXX undocumented debugging hack */
   1153  1.18  christos 	if (verbose > 1) {
   1154  1.50    itojun 		const u_int16_t *sp;
   1155  1.50    itojun 		int nshorts, i;
   1156  1.18  christos 
   1157  1.49    itojun 		sp = (u_int16_t *)outip;
   1158  1.49    itojun 		nshorts = (u_int)packlen / sizeof(u_int16_t);
   1159  1.18  christos 		i = 0;
   1160  1.18  christos 		Printf("[ %d bytes", packlen);
   1161  1.18  christos 		while (--nshorts >= 0) {
   1162  1.18  christos 			if ((i++ % 8) == 0)
   1163  1.18  christos 				Printf("\n\t");
   1164  1.18  christos 			Printf(" %04x", ntohs(*sp++));
   1165  1.18  christos 		}
   1166  1.18  christos 		if (packlen & 1) {
   1167  1.18  christos 			if ((i % 8) == 0)
   1168  1.18  christos 				Printf("\n\t");
   1169  1.18  christos 			Printf(" %02x", *(u_char *)sp);
   1170  1.18  christos 		}
   1171  1.18  christos 		Printf("]\n");
   1172  1.18  christos 	}
   1173   1.1       cgd 
   1174  1.18  christos #if !defined(IP_HDRINCL) && defined(IP_TTL)
   1175  1.18  christos 	if (setsockopt(sndsock, IPPROTO_IP, IP_TTL,
   1176  1.18  christos 	    (char *)&ttl, sizeof(ttl)) < 0) {
   1177  1.18  christos 		Fprintf(stderr, "%s: setsockopt ttl %d: %s\n",
   1178  1.18  christos 		    prog, ttl, strerror(errno));
   1179  1.18  christos 		exit(1);
   1180  1.18  christos 	}
   1181  1.18  christos #endif
   1182   1.4   mycroft 	if (dump)
   1183   1.4   mycroft 		dump_packet();
   1184   1.4   mycroft 
   1185  1.18  christos #ifdef __hpux
   1186  1.18  christos 	cc = sendto(sndsock, useicmp ? (char *)outicmp : (char *)outudp,
   1187  1.18  christos 	    packlen - (sizeof(*outip) + optlen), 0, &whereto, sizeof(whereto));
   1188  1.18  christos 	if (cc > 0)
   1189  1.18  christos 		cc += sizeof(*outip) + optlen;
   1190  1.18  christos #else
   1191  1.18  christos 	cc = sendto(sndsock, (char *)outip,
   1192  1.18  christos 	    packlen, 0, &whereto, sizeof(whereto));
   1193  1.18  christos #endif
   1194  1.18  christos 	if (cc < 0 || cc != packlen)  {
   1195  1.25      ross 		if (cc < 0) {
   1196  1.24        is 			/*
   1197  1.24        is 			 * An errno of EMSGSIZE means we're writing too big a
   1198  1.38  sommerfe 			 * datagram for the interface.  We have to just
   1199  1.38  sommerfe 			 * decrease the packet size until we find one that
   1200  1.38  sommerfe 			 * works.
   1201  1.24        is 			 *
   1202  1.24        is 			 * XXX maybe we should try to read the outgoing if's
   1203  1.24        is 			 * mtu?
   1204  1.24        is 			 */
   1205  1.24        is 			if (errno == EMSGSIZE) {
   1206  1.24        is 				packlen = *mtuptr++;
   1207  1.38  sommerfe 				resize_packet();
   1208  1.24        is 				goto again;
   1209  1.24        is 			} else
   1210  1.24        is 				Fprintf(stderr, "%s: sendto: %s\n",
   1211  1.24        is 				    prog, strerror(errno));
   1212  1.25      ross 		}
   1213  1.24        is 
   1214  1.18  christos 		Printf("%s: wrote %s %d chars, ret=%d\n",
   1215  1.18  christos 		    prog, hostname, packlen, cc);
   1216  1.18  christos 		(void)fflush(stdout);
   1217   1.1       cgd 	}
   1218  1.38  sommerfe 	if (oldmtu != packlen) {
   1219  1.38  sommerfe 		Printf("message too big, "
   1220  1.38  sommerfe 		    "trying new MTU = %d\n", packlen);
   1221  1.38  sommerfe 		printed_ttl = 0;
   1222  1.38  sommerfe 	}
   1223  1.38  sommerfe 	if (!printed_ttl) {
   1224  1.38  sommerfe 		Printf("%2d ", ttl);
   1225  1.38  sommerfe 		printed_ttl = 1;
   1226  1.38  sommerfe 	}
   1227  1.38  sommerfe 
   1228   1.1       cgd }
   1229   1.1       cgd 
   1230   1.3   mycroft double
   1231  1.18  christos deltaT(struct timeval *t1p, struct timeval *t2p)
   1232   1.3   mycroft {
   1233  1.50    itojun 	double dt;
   1234   1.3   mycroft 
   1235   1.3   mycroft 	dt = (double)(t2p->tv_sec - t1p->tv_sec) * 1000.0 +
   1236   1.3   mycroft 	     (double)(t2p->tv_usec - t1p->tv_usec) / 1000.0;
   1237   1.3   mycroft 	return (dt);
   1238   1.1       cgd }
   1239   1.1       cgd 
   1240   1.1       cgd /*
   1241   1.1       cgd  * Convert an ICMP "type" field to a printable string.
   1242   1.1       cgd  */
   1243   1.1       cgd char *
   1244  1.50    itojun pr_type(u_char t)
   1245   1.1       cgd {
   1246   1.1       cgd 	static char *ttab[] = {
   1247   1.1       cgd 	"Echo Reply",	"ICMP 1",	"ICMP 2",	"Dest Unreachable",
   1248   1.1       cgd 	"Source Quench", "Redirect",	"ICMP 6",	"ICMP 7",
   1249   1.1       cgd 	"Echo",		"ICMP 9",	"ICMP 10",	"Time Exceeded",
   1250   1.1       cgd 	"Param Problem", "Timestamp",	"Timestamp Reply", "Info Request",
   1251   1.1       cgd 	"Info Reply"
   1252   1.1       cgd 	};
   1253   1.1       cgd 
   1254  1.18  christos 	if (t > 16)
   1255   1.1       cgd 		return("OUT-OF-RANGE");
   1256   1.1       cgd 
   1257   1.1       cgd 	return(ttab[t]);
   1258   1.1       cgd }
   1259   1.1       cgd 
   1260   1.3   mycroft int
   1261  1.50    itojun packet_ok(u_char *buf, int cc, struct sockaddr_in *from, int seq)
   1262   1.1       cgd {
   1263  1.50    itojun 	struct icmp *icp;
   1264  1.50    itojun 	u_char type, code;
   1265  1.50    itojun 	int hlen;
   1266   1.1       cgd #ifndef ARCHAIC
   1267  1.50    itojun 	struct ip *ip;
   1268   1.1       cgd 
   1269   1.1       cgd 	ip = (struct ip *) buf;
   1270   1.1       cgd 	hlen = ip->ip_hl << 2;
   1271   1.1       cgd 	if (cc < hlen + ICMP_MINLEN) {
   1272   1.1       cgd 		if (verbose)
   1273   1.1       cgd 			Printf("packet too short (%d bytes) from %s\n", cc,
   1274   1.1       cgd 				inet_ntoa(from->sin_addr));
   1275   1.1       cgd 		return (0);
   1276   1.1       cgd 	}
   1277   1.1       cgd 	cc -= hlen;
   1278   1.1       cgd 	icp = (struct icmp *)(buf + hlen);
   1279   1.1       cgd #else
   1280   1.1       cgd 	icp = (struct icmp *)buf;
   1281  1.18  christos #endif
   1282  1.18  christos 	type = icp->icmp_type;
   1283  1.18  christos 	code = icp->icmp_code;
   1284   1.1       cgd 	if ((type == ICMP_TIMXCEED && code == ICMP_TIMXCEED_INTRANS) ||
   1285  1.18  christos 	    type == ICMP_UNREACH || type == ICMP_ECHOREPLY) {
   1286  1.50    itojun 		struct ip *hip;
   1287  1.50    itojun 		struct udphdr *up;
   1288  1.50    itojun 		struct icmp *hicmp;
   1289   1.1       cgd 
   1290   1.1       cgd 		hip = &icp->icmp_ip;
   1291   1.1       cgd 		hlen = hip->ip_hl << 2;
   1292  1.24        is 
   1293  1.32        is 		nextmtu = ntohs(icp->icmp_nextmtu);	/* for frag_err() */
   1294  1.24        is 
   1295  1.18  christos 		if (useicmp) {
   1296  1.18  christos 			/* XXX */
   1297  1.18  christos 			if (type == ICMP_ECHOREPLY &&
   1298  1.18  christos 			    icp->icmp_id == htons(ident) &&
   1299  1.18  christos 			    icp->icmp_seq == htons(seq))
   1300  1.18  christos 				return (-2);
   1301  1.18  christos 
   1302  1.18  christos 			hicmp = (struct icmp *)((u_char *)hip + hlen);
   1303  1.18  christos 			/* XXX 8 is a magic number */
   1304  1.18  christos 			if (hlen + 8 <= cc &&
   1305  1.18  christos 			    hip->ip_p == IPPROTO_ICMP &&
   1306  1.18  christos 			    hicmp->icmp_id == htons(ident) &&
   1307  1.18  christos 			    hicmp->icmp_seq == htons(seq))
   1308  1.18  christos 				return (type == ICMP_TIMXCEED ? -1 : code + 1);
   1309  1.18  christos 		} else {
   1310  1.18  christos 			up = (struct udphdr *)((u_char *)hip + hlen);
   1311  1.18  christos 			/* XXX 8 is a magic number */
   1312  1.18  christos 			if (hlen + 12 <= cc &&
   1313  1.18  christos 			    hip->ip_p == IPPROTO_UDP &&
   1314  1.18  christos 			    up->uh_sport == htons(ident) &&
   1315  1.18  christos 			    up->uh_dport == htons(port + seq))
   1316  1.18  christos 				return (type == ICMP_TIMXCEED ? -1 : code + 1);
   1317  1.18  christos 		}
   1318   1.1       cgd 	}
   1319   1.1       cgd #ifndef ARCHAIC
   1320   1.1       cgd 	if (verbose) {
   1321  1.50    itojun 		int i;
   1322  1.18  christos 		u_int32_t *lp = (u_int32_t *)&icp->icmp_ip;
   1323   1.1       cgd 
   1324  1.18  christos 		Printf("\n%d bytes from %s to ", cc, inet_ntoa(from->sin_addr));
   1325  1.18  christos 		Printf("%s: icmp type %d (%s) code %d\n",
   1326  1.18  christos 		    inet_ntoa(ip->ip_dst), type, pr_type(type), icp->icmp_code);
   1327  1.18  christos 		for (i = 4; i < cc ; i += sizeof(*lp))
   1328  1.18  christos 			Printf("%2d: x%8.8x\n", i, *lp++);
   1329   1.1       cgd 	}
   1330  1.18  christos #endif
   1331   1.1       cgd 	return(0);
   1332   1.1       cgd }
   1333   1.1       cgd 
   1334  1.38  sommerfe void resize_packet(void)
   1335  1.38  sommerfe {
   1336  1.38  sommerfe 	if (useicmp) {
   1337  1.38  sommerfe 		outicmp->icmp_cksum = 0;
   1338  1.49    itojun 		outicmp->icmp_cksum = in_cksum((u_int16_t *)outicmp,
   1339  1.38  sommerfe 		    packlen - (sizeof(*outip) + optlen));
   1340  1.38  sommerfe 		if (outicmp->icmp_cksum == 0)
   1341  1.38  sommerfe 			outicmp->icmp_cksum = 0xffff;
   1342  1.38  sommerfe 	} else {
   1343  1.38  sommerfe 		outudp->uh_ulen =
   1344  1.49    itojun 		    htons((u_int16_t)(packlen - (sizeof(*outip) + optlen)));
   1345  1.38  sommerfe 	}
   1346  1.38  sommerfe }
   1347   1.1       cgd 
   1348   1.3   mycroft void
   1349  1.50    itojun print(u_char *buf, int cc, struct sockaddr_in *from)
   1350   1.1       cgd {
   1351  1.50    itojun 	struct ip *ip;
   1352  1.50    itojun 	int hlen;
   1353   1.1       cgd 
   1354   1.1       cgd 	ip = (struct ip *) buf;
   1355   1.1       cgd 	hlen = ip->ip_hl << 2;
   1356   1.1       cgd 	cc -= hlen;
   1357   1.1       cgd 
   1358  1.44    atatat 	if (as_path)
   1359  1.44    atatat 		Printf(" [AS%d]", as_lookup(asn, &from->sin_addr));
   1360  1.44    atatat 
   1361   1.1       cgd 	if (nflag)
   1362   1.1       cgd 		Printf(" %s", inet_ntoa(from->sin_addr));
   1363   1.1       cgd 	else
   1364   1.1       cgd 		Printf(" %s (%s)", inetname(from->sin_addr),
   1365  1.18  christos 		    inet_ntoa(from->sin_addr));
   1366   1.1       cgd 
   1367   1.1       cgd 	if (verbose)
   1368  1.18  christos 		Printf(" %d bytes to %s", cc, inet_ntoa (ip->ip_dst));
   1369   1.1       cgd }
   1370   1.1       cgd 
   1371  1.49    itojun u_int16_t
   1372  1.49    itojun in_cksum(u_int16_t *addr, int len)
   1373  1.43      yamt {
   1374  1.43      yamt 
   1375  1.43      yamt 	return ~in_cksum2(0, addr, len);
   1376  1.43      yamt }
   1377  1.43      yamt 
   1378   1.1       cgd /*
   1379   1.1       cgd  * Checksum routine for Internet Protocol family headers (C Version)
   1380   1.1       cgd  */
   1381  1.49    itojun u_int16_t
   1382  1.50    itojun in_cksum2(u_int16_t seed, u_int16_t *addr, int len)
   1383   1.1       cgd {
   1384  1.50    itojun 	int nleft = len;
   1385  1.50    itojun 	u_int16_t *w = addr;
   1386  1.51    itojun 	union {
   1387  1.51    itojun 		u_int16_t w;
   1388  1.51    itojun 		u_int8_t b[2];
   1389  1.51    itojun 	} answer;
   1390  1.50    itojun 	int32_t sum = seed;
   1391   1.1       cgd 
   1392   1.1       cgd 	/*
   1393   1.1       cgd 	 *  Our algorithm is simple, using a 32 bit accumulator (sum),
   1394   1.1       cgd 	 *  we add sequential 16 bit words to it, and at the end, fold
   1395   1.1       cgd 	 *  back all the carry bits from the top 16 bits into the lower
   1396   1.1       cgd 	 *  16 bits.
   1397   1.1       cgd 	 */
   1398   1.1       cgd 	while (nleft > 1)  {
   1399   1.1       cgd 		sum += *w++;
   1400   1.1       cgd 		nleft -= 2;
   1401   1.1       cgd 	}
   1402   1.1       cgd 
   1403   1.1       cgd 	/* mop up an odd byte, if necessary */
   1404  1.51    itojun 	if (nleft == 1) {
   1405  1.51    itojun 		answer.b[0] = *(u_char *)w;
   1406  1.51    itojun 		answer.b[1] = 0;
   1407  1.51    itojun 		sum += answer.w;
   1408  1.51    itojun 	}
   1409   1.1       cgd 
   1410   1.1       cgd 	/*
   1411   1.1       cgd 	 * add back carry outs from top 16 bits to low 16 bits
   1412   1.1       cgd 	 */
   1413   1.1       cgd 	sum = (sum >> 16) + (sum & 0xffff);	/* add hi 16 to low 16 */
   1414   1.1       cgd 	sum += (sum >> 16);			/* add carry */
   1415  1.51    itojun 	answer.w = sum;				/* truncate to 16 bits */
   1416  1.51    itojun 	return (answer.w);
   1417   1.1       cgd }
   1418  1.18  christos 
   1419  1.18  christos /*
   1420  1.18  christos  * Subtract 2 timeval structs:  out = out - in.
   1421  1.18  christos  * Out is assumed to be >= in.
   1422  1.18  christos  */
   1423  1.18  christos void
   1424  1.50    itojun tvsub(struct timeval *out, struct timeval *in)
   1425  1.18  christos {
   1426  1.18  christos 
   1427  1.18  christos 	if ((out->tv_usec -= in->tv_usec) < 0)   {
   1428  1.18  christos 		--out->tv_sec;
   1429  1.18  christos 		out->tv_usec += 1000000;
   1430  1.18  christos 	}
   1431  1.18  christos 	out->tv_sec -= in->tv_sec;
   1432  1.18  christos }
   1433   1.1       cgd 
   1434   1.1       cgd /*
   1435   1.1       cgd  * Construct an Internet address representation.
   1436   1.3   mycroft  * If the nflag has been supplied, give
   1437   1.1       cgd  * numeric value, otherwise try for symbolic name.
   1438   1.1       cgd  */
   1439   1.1       cgd char *
   1440  1.18  christos inetname(struct in_addr in)
   1441   1.1       cgd {
   1442  1.50    itojun 	char *cp;
   1443  1.50    itojun 	struct hostent *hp;
   1444   1.1       cgd 	static int first = 1;
   1445  1.18  christos 	static char domain[MAXHOSTNAMELEN + 1], line[MAXHOSTNAMELEN + 1];
   1446   1.1       cgd 
   1447   1.1       cgd 	if (first && !nflag) {
   1448  1.23       mrg 		int rv;
   1449  1.23       mrg 
   1450   1.1       cgd 		first = 0;
   1451  1.23       mrg 		rv = gethostname(domain, sizeof domain);
   1452  1.23       mrg 		if (rv == 0 && (cp = strchr(domain, '.')) != NULL) {
   1453  1.59    itojun 			(void)strlcpy(domain, cp + 1, sizeof(domain));
   1454  1.14  explorer 		} else
   1455  1.18  christos 			domain[0] = '\0';
   1456   1.1       cgd 	}
   1457   1.1       cgd 	if (!nflag && in.s_addr != INADDR_ANY) {
   1458  1.18  christos 		hp = gethostbyaddr((char *)&in, sizeof(in), AF_INET);
   1459  1.18  christos 		if (hp != NULL) {
   1460  1.18  christos 			if ((cp = strchr(hp->h_name, '.')) != NULL &&
   1461  1.18  christos 			    strcmp(cp + 1, domain) == 0)
   1462  1.18  christos 				*cp = '\0';
   1463  1.59    itojun 			(void)strlcpy(line, hp->h_name, sizeof(line));
   1464  1.18  christos 			return (line);
   1465   1.1       cgd 		}
   1466   1.1       cgd 	}
   1467  1.18  christos 	return (inet_ntoa(in));
   1468  1.18  christos }
   1469  1.18  christos 
   1470  1.18  christos struct hostinfo *
   1471  1.50    itojun gethostinfo(char *hostname)
   1472  1.18  christos {
   1473  1.50    itojun 	int n;
   1474  1.50    itojun 	struct hostent *hp;
   1475  1.50    itojun 	struct hostinfo *hi;
   1476  1.50    itojun 	char **p;
   1477  1.50    itojun 	u_int32_t *ap;
   1478  1.18  christos 	struct in_addr addr;
   1479  1.18  christos 
   1480  1.18  christos 	hi = calloc(1, sizeof(*hi));
   1481  1.18  christos 	if (hi == NULL) {
   1482  1.18  christos 		Fprintf(stderr, "%s: calloc %s\n", prog, strerror(errno));
   1483  1.18  christos 		exit(1);
   1484  1.18  christos 	}
   1485  1.18  christos 	if (inet_aton(hostname, &addr) != 0) {
   1486  1.40  sommerfe 		hi->name = strdup(hostname);
   1487  1.57    itojun 		if (!hi->name) {
   1488  1.57    itojun 			Fprintf(stderr, "%s: strdup %s\n", prog,
   1489  1.57    itojun 			    strerror(errno));
   1490  1.57    itojun 			exit(1);
   1491  1.57    itojun 		}
   1492  1.18  christos 		hi->n = 1;
   1493  1.18  christos 		hi->addrs = calloc(1, sizeof(hi->addrs[0]));
   1494  1.18  christos 		if (hi->addrs == NULL) {
   1495  1.18  christos 			Fprintf(stderr, "%s: calloc %s\n",
   1496  1.18  christos 			    prog, strerror(errno));
   1497  1.18  christos 			exit(1);
   1498  1.18  christos 		}
   1499  1.18  christos 		hi->addrs[0] = addr.s_addr;
   1500  1.18  christos 		return (hi);
   1501  1.18  christos 	}
   1502  1.18  christos 
   1503  1.18  christos 	hp = gethostbyname(hostname);
   1504  1.18  christos 	if (hp == NULL) {
   1505  1.18  christos 		Fprintf(stderr, "%s: unknown host %s\n", prog, hostname);
   1506  1.18  christos 		exit(1);
   1507  1.18  christos 	}
   1508  1.18  christos 	if (hp->h_addrtype != AF_INET || hp->h_length != 4) {
   1509  1.18  christos 		Fprintf(stderr, "%s: bad host %s\n", prog, hostname);
   1510  1.18  christos 		exit(1);
   1511  1.18  christos 	}
   1512  1.40  sommerfe 	hi->name = strdup(hp->h_name);
   1513  1.57    itojun 	if (!hi->name) {
   1514  1.57    itojun 		Fprintf(stderr, "%s: strdup %s\n", prog, strerror(errno));
   1515  1.57    itojun 		exit(1);
   1516  1.57    itojun 	}
   1517  1.18  christos 	for (n = 0, p = hp->h_addr_list; *p != NULL; ++n, ++p)
   1518  1.18  christos 		continue;
   1519  1.18  christos 	hi->n = n;
   1520  1.18  christos 	hi->addrs = calloc(n, sizeof(hi->addrs[0]));
   1521  1.18  christos 	if (hi->addrs == NULL) {
   1522  1.18  christos 		Fprintf(stderr, "%s: calloc %s\n", prog, strerror(errno));
   1523  1.18  christos 		exit(1);
   1524  1.18  christos 	}
   1525  1.18  christos 	for (ap = hi->addrs, p = hp->h_addr_list; *p != NULL; ++ap, ++p)
   1526  1.18  christos 		memcpy(ap, *p, sizeof(*ap));
   1527  1.18  christos 	return (hi);
   1528  1.18  christos }
   1529  1.18  christos 
   1530  1.18  christos void
   1531  1.50    itojun freehostinfo(struct hostinfo *hi)
   1532  1.18  christos {
   1533  1.18  christos 	if (hi->name != NULL) {
   1534  1.18  christos 		free(hi->name);
   1535  1.18  christos 		hi->name = NULL;
   1536   1.1       cgd 	}
   1537  1.18  christos 	free((char *)hi->addrs);
   1538  1.18  christos 	free((char *)hi);
   1539   1.1       cgd }
   1540   1.1       cgd 
   1541   1.3   mycroft void
   1542  1.50    itojun getaddr(u_int32_t *ap, char *hostname)
   1543  1.18  christos {
   1544  1.50    itojun 	struct hostinfo *hi;
   1545  1.18  christos 
   1546  1.18  christos 	hi = gethostinfo(hostname);
   1547  1.18  christos 	*ap = hi->addrs[0];
   1548  1.18  christos 	freehostinfo(hi);
   1549  1.18  christos }
   1550  1.18  christos 
   1551  1.18  christos void
   1552  1.50    itojun setsin(struct sockaddr_in *sin, u_int32_t addr)
   1553  1.18  christos {
   1554  1.18  christos 
   1555  1.18  christos 	memset(sin, 0, sizeof(*sin));
   1556  1.18  christos #ifdef HAVE_SOCKADDR_SA_LEN
   1557  1.18  christos 	sin->sin_len = sizeof(*sin);
   1558  1.18  christos #endif
   1559  1.18  christos 	sin->sin_family = AF_INET;
   1560  1.18  christos 	sin->sin_addr.s_addr = addr;
   1561  1.18  christos }
   1562  1.18  christos 
   1563  1.18  christos /* String to value with optional min and max. Handles decimal and hex. */
   1564  1.18  christos int
   1565  1.50    itojun str2val(const char *str, const char *what, int mi, int ma)
   1566   1.1       cgd {
   1567  1.50    itojun 	const char *cp;
   1568  1.56    itojun 	long val;
   1569  1.18  christos 	char *ep;
   1570  1.18  christos 
   1571  1.56    itojun 	errno = 0;
   1572  1.56    itojun 	ep = NULL;
   1573  1.18  christos 	if (str[0] == '0' && (str[1] == 'x' || str[1] == 'X')) {
   1574  1.18  christos 		cp = str + 2;
   1575  1.56    itojun 		val = strtol(cp, &ep, 16);
   1576  1.18  christos 	} else
   1577  1.56    itojun 		val = strtol(str, &ep, 10);
   1578  1.56    itojun 	if (errno || str[0] == '\0' || *ep != '\0') {
   1579  1.18  christos 		Fprintf(stderr, "%s: \"%s\" bad value for %s \n",
   1580  1.18  christos 		    prog, str, what);
   1581  1.18  christos 		exit(1);
   1582  1.18  christos 	}
   1583  1.18  christos 	if (val < mi && mi >= 0) {
   1584  1.18  christos 		if (mi == 0)
   1585  1.18  christos 			Fprintf(stderr, "%s: %s must be >= %d\n",
   1586  1.18  christos 			    prog, what, mi);
   1587  1.18  christos 		else
   1588  1.18  christos 			Fprintf(stderr, "%s: %s must be > %d\n",
   1589  1.18  christos 			    prog, what, mi - 1);
   1590  1.18  christos 		exit(1);
   1591  1.18  christos 	}
   1592  1.18  christos 	if (val > ma && ma >= 0) {
   1593  1.18  christos 		Fprintf(stderr, "%s: %s must be <= %d\n", prog, what, ma);
   1594  1.18  christos 		exit(1);
   1595  1.18  christos 	}
   1596  1.56    itojun 	return ((int)val);
   1597  1.18  christos }
   1598  1.18  christos 
   1599  1.18  christos __dead void
   1600  1.18  christos usage(void)
   1601  1.18  christos {
   1602  1.18  christos 	extern char version[];
   1603  1.18  christos 
   1604  1.18  christos 	Fprintf(stderr, "Version %s\n", version);
   1605  1.60      jmmv 	Fprintf(stderr, "usage: %s [-adDFPIlnrvx] [-g gateway] [-i iface] \
   1606  1.44    atatat [-f first_ttl]\n\t[-m max_ttl] [-p port] [-q nqueries] [-s src_addr] [-t tos]\n\t\
   1607  1.44    atatat [-w waittime] [-A as_server] host [packetlen]\n",
   1608  1.18  christos 	    prog);
   1609   1.5   mycroft 	exit(1);
   1610   1.5   mycroft }
   1611  1.24        is 
   1612  1.24        is /*
   1613  1.24        is  * Received ICMP unreachable (fragmentation required and DF set).
   1614  1.24        is  * If the ICMP error was from a "new" router, it'll contain the next-hop
   1615  1.24        is  * MTU that we should use next.  Otherwise we'll just keep going in the
   1616  1.24        is  * mtus[] table, trying until we hit a valid MTU.
   1617  1.24        is  */
   1618  1.24        is 
   1619  1.24        is 
   1620  1.24        is void
   1621  1.24        is frag_err()
   1622  1.24        is {
   1623  1.24        is         int i;
   1624  1.24        is 
   1625  1.35        is         if (nextmtu > 0 && nextmtu < packlen) {
   1626  1.34        is                 Printf("\nfragmentation required and DF set, "
   1627  1.34        is 		     "next hop MTU = %d\n",
   1628  1.24        is                         nextmtu);
   1629  1.24        is                 packlen = nextmtu;
   1630  1.24        is                 for (i = 0; mtus[i] > 0; i++) {
   1631  1.24        is                         if (mtus[i] < nextmtu) {
   1632  1.24        is                                 mtuptr = &mtus[i];    /* next one to try */
   1633  1.34        is                                 break;
   1634  1.24        is                         }
   1635  1.24        is                 }
   1636  1.24        is         } else {
   1637  1.35        is                 Printf("\nfragmentation required and DF set. ");
   1638  1.35        is 		if (nextmtu)
   1639  1.35        is 			Printf("\nBogus next hop MTU = %d > last MTU = %d. ",
   1640  1.35        is 			    nextmtu, packlen);
   1641  1.24        is                 packlen = *mtuptr++;
   1642  1.35        is 		Printf("Trying new MTU = %d\n", packlen);
   1643  1.24        is         }
   1644  1.38  sommerfe 	resize_packet();
   1645  1.24        is }
   1646  1.24        is 
   1647  1.26      tron int
   1648  1.26      tron find_local_ip(struct sockaddr_in *from, struct sockaddr_in *to)
   1649  1.26      tron {
   1650  1.26      tron 	int sock;
   1651  1.26      tron 	struct sockaddr_in help;
   1652  1.26      tron 	int help_len;
   1653  1.26      tron 
   1654  1.26      tron 	sock = socket(AF_INET, SOCK_DGRAM, 0);
   1655  1.26      tron 	if (sock < 0) return (0);
   1656  1.26      tron 
   1657  1.26      tron 	help.sin_family = AF_INET;
   1658  1.26      tron 	/*
   1659  1.26      tron 	 * At this point the port number doesn't matter
   1660  1.26      tron 	 * since it only has to be greater than zero.
   1661  1.26      tron 	 */
   1662  1.26      tron 	help.sin_port = 42;
   1663  1.26      tron 	help.sin_addr.s_addr = to->sin_addr.s_addr;
   1664  1.26      tron 	if (connect(sock, (struct sockaddr *)&help, sizeof(help)) < 0) {
   1665  1.26      tron 		(void)close(sock);
   1666  1.26      tron 		return (0);
   1667  1.26      tron 	}
   1668  1.26      tron 
   1669  1.26      tron 	help_len = sizeof(help);
   1670  1.26      tron 	if (getsockname(sock, (struct sockaddr *)&help, &help_len) < 0 ||
   1671  1.26      tron 	    help_len != sizeof(help) ||
   1672  1.26      tron 	    help.sin_addr.s_addr == INADDR_ANY) {
   1673  1.26      tron 		(void)close(sock);
   1674  1.26      tron 		return (0);
   1675  1.26      tron 	}
   1676  1.26      tron 
   1677  1.26      tron 	(void)close(sock);
   1678  1.26      tron 	setsin(from, help.sin_addr.s_addr);
   1679  1.26      tron 	return (1);
   1680  1.26      tron }
   1681  1.39    itojun 
   1682  1.39    itojun #ifdef IPSEC
   1683  1.39    itojun #ifdef IPSEC_POLICY_IPSEC
   1684  1.39    itojun int
   1685  1.39    itojun setpolicy(so, policy)
   1686  1.39    itojun 	int so;
   1687  1.39    itojun 	char *policy;
   1688  1.39    itojun {
   1689  1.39    itojun 	char *buf;
   1690  1.39    itojun 
   1691  1.39    itojun 	buf = ipsec_set_policy(policy, strlen(policy));
   1692  1.39    itojun 	if (buf == NULL) {
   1693  1.39    itojun 		Fprintf(stderr, "%s: %s\n", prog, ipsec_strerror());
   1694  1.39    itojun 		return -1;
   1695  1.39    itojun 	}
   1696  1.39    itojun 	(void)setsockopt(so, IPPROTO_IP, IP_IPSEC_POLICY,
   1697  1.39    itojun 		buf, ipsec_get_policylen(buf));
   1698  1.39    itojun 
   1699  1.39    itojun 	free(buf);
   1700  1.39    itojun 
   1701  1.39    itojun 	return 0;
   1702  1.39    itojun }
   1703  1.39    itojun #endif
   1704  1.39    itojun #endif
   1705  1.39    itojun 
   1706