Home | History | Annotate | Line # | Download | only in traceroute6
traceroute6.c revision 1.50
      1 /*	$NetBSD: traceroute6.c,v 1.50 2018/04/23 10:23:38 maxv Exp $	*/
      2 /*	$KAME: traceroute6.c,v 1.67 2004/01/25 03:24:39 itojun Exp $	*/
      3 
      4 /*
      5  * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
      6  * All rights reserved.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  * 1. Redistributions of source code must retain the above copyright
     12  *    notice, this list of conditions and the following disclaimer.
     13  * 2. Redistributions in binary form must reproduce the above copyright
     14  *    notice, this list of conditions and the following disclaimer in the
     15  *    documentation and/or other materials provided with the distribution.
     16  * 3. Neither the name of the project nor the names of its contributors
     17  *    may be used to endorse or promote products derived from this software
     18  *    without specific prior written permission.
     19  *
     20  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
     21  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     22  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     23  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
     24  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     25  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     26  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     27  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     28  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     29  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     30  * SUCH DAMAGE.
     31  */
     32 
     33 /*-
     34  * Copyright (c) 1990, 1993
     35  *	The Regents of the University of California.  All rights reserved.
     36  *
     37  * This code is derived from software contributed to Berkeley by
     38  * Van Jacobson.
     39  *
     40  * Redistribution and use in source and binary forms, with or without
     41  * modification, are permitted provided that the following conditions
     42  * are met:
     43  * 1. Redistributions of source code must retain the above copyright
     44  *    notice, this list of conditions and the following disclaimer.
     45  * 2. Redistributions in binary form must reproduce the above copyright
     46  *    notice, this list of conditions and the following disclaimer in the
     47  *    documentation and/or other materials provided with the distribution.
     48  * 3. Neither the name of the University nor the names of its contributors
     49  *    may be used to endorse or promote products derived from this software
     50  *    without specific prior written permission.
     51  *
     52  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     53  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     54  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     55  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     56  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     57  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     58  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     59  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     60  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     61  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     62  * SUCH DAMAGE.
     63  */
     64 
     65 #if 0
     66 #ifndef lint
     67 static char copyright[] =
     68 "@(#) Copyright (c) 1990, 1993\n\
     69 	The Regents of the University of California.  All rights reserved.\n";
     70 #endif /* not lint */
     71 
     72 #ifndef lint
     73 static char sccsid[] = "@(#)traceroute.c	8.1 (Berkeley) 6/6/93";
     74 #endif /* not lint */
     75 #else
     76 #include <sys/cdefs.h>
     77 #ifndef lint
     78 __RCSID("$NetBSD: traceroute6.c,v 1.50 2018/04/23 10:23:38 maxv Exp $");
     79 #endif
     80 #endif
     81 
     82 /*
     83  * traceroute host  - trace the route ip packets follow going to "host".
     84  *
     85  * Attempt to trace the route an ip packet would follow to some
     86  * internet host.  We find out intermediate hops by launching probe
     87  * packets with a small ttl (time to live) then listening for an
     88  * icmp "time exceeded" reply from a gateway.  We start our probes
     89  * with a ttl of one and increase by one until we get an icmp "port
     90  * unreachable" (which means we got to "host") or hit a max (which
     91  * defaults to 30 hops & can be changed with the -m flag).  Three
     92  * probes (change with -q flag) are sent at each ttl setting and a
     93  * line is printed showing the ttl, address of the gateway and
     94  * round trip time of each probe.  If the probe answers come from
     95  * different gateways, the address of each responding system will
     96  * be printed.  If there is no response within a 5 sec. timeout
     97  * interval (changed with the -w flag), a "*" is printed for that
     98  * probe.
     99  *
    100  * Probe packets are UDP format.  We don't want the destination
    101  * host to process them so the destination port is set to an
    102  * unlikely value (if some clod on the destination is using that
    103  * value, it can be changed with the -p flag).
    104  *
    105  * A sample use might be:
    106  *
    107  *     [yak 71]% traceroute nis.nsf.net.
    108  *     traceroute to nis.nsf.net (35.1.1.48), 30 hops max, 56 byte packet
    109  *      1  helios.ee.lbl.gov (128.3.112.1)  19 ms  19 ms  0 ms
    110  *      2  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  39 ms  19 ms
    111  *      3  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  39 ms  19 ms
    112  *      4  ccngw-ner-cc.Berkeley.EDU (128.32.136.23)  39 ms  40 ms  39 ms
    113  *      5  ccn-nerif22.Berkeley.EDU (128.32.168.22)  39 ms  39 ms  39 ms
    114  *      6  128.32.197.4 (128.32.197.4)  40 ms  59 ms  59 ms
    115  *      7  131.119.2.5 (131.119.2.5)  59 ms  59 ms  59 ms
    116  *      8  129.140.70.13 (129.140.70.13)  99 ms  99 ms  80 ms
    117  *      9  129.140.71.6 (129.140.71.6)  139 ms  239 ms  319 ms
    118  *     10  129.140.81.7 (129.140.81.7)  220 ms  199 ms  199 ms
    119  *     11  nic.merit.edu (35.1.1.48)  239 ms  239 ms  239 ms
    120  *
    121  * Note that lines 2 & 3 are the same.  This is due to a buggy
    122  * kernel on the 2nd hop system -- lbl-csam.arpa -- that forwards
    123  * packets with a zero ttl.
    124  *
    125  * A more interesting example is:
    126  *
    127  *     [yak 72]% traceroute allspice.lcs.mit.edu.
    128  *     traceroute to allspice.lcs.mit.edu (18.26.0.115), 30 hops max
    129  *      1  helios.ee.lbl.gov (128.3.112.1)  0 ms  0 ms  0 ms
    130  *      2  lilac-dmc.Berkeley.EDU (128.32.216.1)  19 ms  19 ms  19 ms
    131  *      3  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  19 ms  19 ms
    132  *      4  ccngw-ner-cc.Berkeley.EDU (128.32.136.23)  19 ms  39 ms  39 ms
    133  *      5  ccn-nerif22.Berkeley.EDU (128.32.168.22)  20 ms  39 ms  39 ms
    134  *      6  128.32.197.4 (128.32.197.4)  59 ms  119 ms  39 ms
    135  *      7  131.119.2.5 (131.119.2.5)  59 ms  59 ms  39 ms
    136  *      8  129.140.70.13 (129.140.70.13)  80 ms  79 ms  99 ms
    137  *      9  129.140.71.6 (129.140.71.6)  139 ms  139 ms  159 ms
    138  *     10  129.140.81.7 (129.140.81.7)  199 ms  180 ms  300 ms
    139  *     11  129.140.72.17 (129.140.72.17)  300 ms  239 ms  239 ms
    140  *     12  * * *
    141  *     13  128.121.54.72 (128.121.54.72)  259 ms  499 ms  279 ms
    142  *     14  * * *
    143  *     15  * * *
    144  *     16  * * *
    145  *     17  * * *
    146  *     18  ALLSPICE.LCS.MIT.EDU (18.26.0.115)  339 ms  279 ms  279 ms
    147  *
    148  * (I start to see why I'm having so much trouble with mail to
    149  * MIT.)  Note that the gateways 12, 14, 15, 16 & 17 hops away
    150  * either don't send ICMP "time exceeded" messages or send them
    151  * with a ttl too small to reach us.  14 - 17 are running the
    152  * MIT C Gateway code that doesn't send "time exceeded"s.  God
    153  * only knows what's going on with 12.
    154  *
    155  * The silent gateway 12 in the above may be the result of a bug in
    156  * the 4.[23]BSD network code (and its derivatives):  4.x (x <= 3)
    157  * sends an unreachable message using whatever ttl remains in the
    158  * original datagram.  Since, for gateways, the remaining ttl is
    159  * zero, the icmp "time exceeded" is guaranteed to not make it back
    160  * to us.  The behavior of this bug is slightly more interesting
    161  * when it appears on the destination system:
    162  *
    163  *      1  helios.ee.lbl.gov (128.3.112.1)  0 ms  0 ms  0 ms
    164  *      2  lilac-dmc.Berkeley.EDU (128.32.216.1)  39 ms  19 ms  39 ms
    165  *      3  lilac-dmc.Berkeley.EDU (128.32.216.1)  19 ms  39 ms  19 ms
    166  *      4  ccngw-ner-cc.Berkeley.EDU (128.32.136.23)  39 ms  40 ms  19 ms
    167  *      5  ccn-nerif35.Berkeley.EDU (128.32.168.35)  39 ms  39 ms  39 ms
    168  *      6  csgw.Berkeley.EDU (128.32.133.254)  39 ms  59 ms  39 ms
    169  *      7  * * *
    170  *      8  * * *
    171  *      9  * * *
    172  *     10  * * *
    173  *     11  * * *
    174  *     12  * * *
    175  *     13  rip.Berkeley.EDU (128.32.131.22)  59 ms !  39 ms !  39 ms !
    176  *
    177  * Notice that there are 12 "gateways" (13 is the final
    178  * destination) and exactly the last half of them are "missing".
    179  * What's really happening is that rip (a Sun-3 running Sun OS3.5)
    180  * is using the ttl from our arriving datagram as the ttl in its
    181  * icmp reply.  So, the reply will time out on the return path
    182  * (with no notice sent to anyone since icmp's aren't sent for
    183  * icmp's) until we probe with a ttl that's at least twice the path
    184  * length.  I.e., rip is really only 7 hops away.  A reply that
    185  * returns with a ttl of 1 is a clue this problem exists.
    186  * Traceroute prints a "!" after the time if the ttl is <= 1.
    187  * Since vendors ship a lot of obsolete (DEC's Ultrix, Sun 3.x) or
    188  * non-standard (HPUX) software, expect to see this problem
    189  * frequently and/or take care picking the target host of your
    190  * probes.
    191  *
    192  * Other possible annotations after the time are !H, !N, !P (got a host,
    193  * network or protocol unreachable, respectively), !S or !F (source
    194  * route failed or fragmentation needed -- neither of these should
    195  * ever occur and the associated gateway is busted if you see one).  If
    196  * almost all the probes result in some kind of unreachable, traceroute
    197  * will give up and exit.
    198  *
    199  * Notes
    200  * -----
    201  * This program must be run by root or be setuid.  (I suggest that
    202  * you *don't* make it setuid -- casual use could result in a lot
    203  * of unnecessary traffic on our poor, congested nets.)
    204  *
    205  * This program requires a kernel mod that does not appear in any
    206  * system available from Berkeley:  A raw ip socket using proto
    207  * IPPROTO_RAW must interpret the data sent as an ip datagram (as
    208  * opposed to data to be wrapped in a ip datagram).  See the README
    209  * file that came with the source to this program for a description
    210  * of the mods I made to /sys/netinet/raw_ip.c.  Your mileage may
    211  * vary.  But, again, ANY 4.x (x < 4) BSD KERNEL WILL HAVE TO BE
    212  * MODIFIED TO RUN THIS PROGRAM.
    213  *
    214  * The udp port usage may appear bizarre (well, ok, it is bizarre).
    215  * The problem is that an icmp message only contains 8 bytes of
    216  * data from the original datagram.  8 bytes is the size of a udp
    217  * header so, if we want to associate replies with the original
    218  * datagram, the necessary information must be encoded into the
    219  * udp header (the ip id could be used but there's no way to
    220  * interlock with the kernel's assignment of ip id's and, anyway,
    221  * it would have taken a lot more kernel hacking to allow this
    222  * code to set the ip id).  So, to allow two or more users to
    223  * use traceroute simultaneously, we use this task's pid as the
    224  * source port (the high bit is set to move the port number out
    225  * of the "likely" range).  To keep track of which probe is being
    226  * replied to (so times and/or hop counts don't get confused by a
    227  * reply that was delayed in transit), we increment the destination
    228  * port number before each probe.
    229  *
    230  * Don't use this as a coding example.  I was trying to find a
    231  * routing problem and this code sort-of popped out after 48 hours
    232  * without sleep.  I was amazed it ever compiled, much less ran.
    233  *
    234  * I stole the idea for this program from Steve Deering.  Since
    235  * the first release, I've learned that had I attended the right
    236  * IETF working group meetings, I also could have stolen it from Guy
    237  * Almes or Matt Mathis.  I don't know (or care) who came up with
    238  * the idea first.  I envy the originators' perspicacity and I'm
    239  * glad they didn't keep the idea a secret.
    240  *
    241  * Tim Seaver, Ken Adelman and C. Philip Wood provided bug fixes and/or
    242  * enhancements to the original distribution.
    243  *
    244  * I've hacked up a round-trip-route version of this that works by
    245  * sending a loose-source-routed udp datagram through the destination
    246  * back to yourself.  Unfortunately, SO many gateways botch source
    247  * routing, the thing is almost worthless.  Maybe one day...
    248  *
    249  *  -- Van Jacobson (van (at) helios.ee.lbl.gov)
    250  *     Tue Dec 20 03:50:13 PST 1988
    251  */
    252 
    253 #include <sys/param.h>
    254 #include <sys/time.h>
    255 #include <sys/socket.h>
    256 #include <sys/uio.h>
    257 #include <sys/file.h>
    258 #include <sys/ioctl.h>
    259 #include <sys/sysctl.h>
    260 
    261 #include <netinet/in.h>
    262 
    263 #include <arpa/inet.h>
    264 
    265 #include <netdb.h>
    266 #include <stdio.h>
    267 #include <err.h>
    268 #ifdef HAVE_POLL
    269 #include <poll.h>
    270 #endif
    271 #include <errno.h>
    272 #include <stdlib.h>
    273 #include <string.h>
    274 #include <unistd.h>
    275 
    276 #include <netinet/ip6.h>
    277 #include <netinet/icmp6.h>
    278 #include <netinet/udp.h>
    279 
    280 #ifdef IPSEC
    281 #include <net/route.h>
    282 #include <netipsec/ipsec.h>
    283 #endif
    284 
    285 #include "as.h"
    286 
    287 #define DUMMY_PORT 10010
    288 
    289 #define	MAXPACKET	65535	/* max ip packet size */
    290 
    291 #ifndef HAVE_GETIPNODEBYNAME
    292 #define getipnodebyname(x, y, z, u)	gethostbyname2((x), (y))
    293 #define freehostent(x)
    294 #endif
    295 
    296 /*
    297  * format of a (udp) probe packet.
    298  */
    299 struct tv32 {
    300 	u_int32_t tv32_sec;
    301 	u_int32_t tv32_usec;
    302 };
    303 
    304 struct opacket {
    305 	u_char seq;		/* sequence number of this packet */
    306 	u_char hops;		/* hop limit of the packet */
    307 	u_char pad[2];
    308 	struct tv32 tv;		/* time packet left */
    309 } __packed;
    310 
    311 static u_char	packet[512];		/* last inbound (icmp) packet */
    312 static struct opacket	*outpacket;	/* last output (udp) packet */
    313 
    314 static ssize_t	wait_for_reply(int, struct msghdr *);
    315 #ifdef IPSEC
    316 #ifdef IPSEC_POLICY_IPSEC
    317 static int	setpolicy(int so, const char *policy);
    318 #endif
    319 #endif
    320 static void send_probe(int, u_long);
    321 static struct udphdr *get_udphdr(struct ip6_hdr *, u_char *);
    322 static double deltaT(struct timeval *, struct timeval *);
    323 static const char *pr_type(int);
    324 static int packet_ok(struct msghdr *, ssize_t, int);
    325 static void print(struct msghdr *, int);
    326 static const char *inetname(struct sockaddr *);
    327 static void usage(void) __attribute__((__noreturn__));
    328 
    329 static int rcvsock;		/* receive (icmp) socket file descriptor */
    330 static int sndsock;		/* send (udp) socket file descriptor */
    331 
    332 static struct msghdr rcvmhdr;
    333 static struct iovec rcviov[2];
    334 static int rcvhlim;
    335 static struct in6_pktinfo *rcvpktinfo;
    336 
    337 static struct sockaddr_in6 Src, Dst, Rcv;
    338 static u_long datalen;			/* How much data */
    339 #define	ICMP6ECHOLEN	8
    340 
    341 static char *source;
    342 static char *hostname;
    343 
    344 static u_long nprobes = 3;
    345 static u_long first_hop = 1;
    346 static u_long max_hops = 30;
    347 static u_int16_t srcport;
    348 static u_int16_t port = 32768+666;/* start udp dest port # for probe packets */
    349 static u_int16_t ident;
    350 static int options;		/* socket options */
    351 static int verbose;
    352 static int waittime = 5;	/* time to wait for response (in seconds) */
    353 static int nflag;		/* print addresses numerically */
    354 static int useicmp;
    355 static int lflag;		/* print both numerical address & hostname */
    356 static int as_path;		/* print as numbers for each hop */
    357 static char *as_server = NULL;
    358 static void *asn;
    359 
    360 int
    361 main(int argc, char *argv[])
    362 {
    363 	int mib[4] = { CTL_NET, PF_INET6, IPPROTO_IPV6, IPV6CTL_DEFHLIM };
    364 	char hbuf[NI_MAXHOST], src0[NI_MAXHOST], *ep;
    365 	int ch, i, on = 1, seq, rcvcmsglen, error;
    366 	u_long minlen;
    367 	struct addrinfo hints, *res;
    368 	static u_char *rcvcmsgbuf;
    369 	u_long probe, hops, lport;
    370 	size_t size;
    371 
    372 	/*
    373 	 * Receive ICMP
    374 	 */
    375 	if ((rcvsock = socket(AF_INET6, SOCK_RAW, IPPROTO_ICMPV6)) < 0)
    376 		err(5, "socket(ICMPv6)");
    377 
    378 	/* revoke privs */
    379 	seteuid(getuid());
    380 	setuid(getuid());
    381 
    382 	size = sizeof(i);
    383 	(void) sysctl(mib, sizeof(mib)/sizeof(mib[0]), &i, &size, NULL, 0);
    384 	max_hops = i;
    385 
    386 	/* specify to tell receiving interface */
    387 	if (setsockopt(rcvsock, IPPROTO_IPV6, IPV6_RECVPKTINFO, &on,
    388 	    sizeof(on)) < 0)
    389 		err(1, "setsockopt(IPV6_RECVPKTINFO)");
    390 
    391 	/* specify to tell value of hoplimit field of received IP6 hdr */
    392 	if (setsockopt(rcvsock, IPPROTO_IPV6, IPV6_RECVHOPLIMIT, &on,
    393 	    sizeof(on)) < 0)
    394 		err(1, "setsockopt(IPV6_RECVHOPLIMIT)");
    395 
    396 	seq = 0;
    397 
    398 	while ((ch = getopt(argc, argv, "aA:df:Ilm:np:q:rs:w:v")) != -1)
    399 		switch (ch) {
    400 		case 'a':
    401 			as_path = 1;
    402 			break;
    403 		case 'A':
    404 			as_path = 1;
    405 			as_server = optarg;
    406 			break;
    407 		case 'd':
    408 			options |= SO_DEBUG;
    409 			break;
    410 		case 'f':
    411 			ep = NULL;
    412 			errno = 0;
    413 			first_hop = strtoul(optarg, &ep, 0);
    414 			if (errno || !*optarg || *ep|| first_hop > 255)
    415 				errx(1, "Invalid min hoplimit `%s'", optarg);
    416 			break;
    417 		case 'I':
    418 			useicmp++;
    419 			/* same as ping6 */
    420 			ident = htons(arc4random() & 0xffff);
    421 			break;
    422 		case 'l':
    423 			lflag++;
    424 			break;
    425 		case 'm':
    426 			ep = NULL;
    427 			errno = 0;
    428 			max_hops = strtoul(optarg, &ep, 0);
    429 			if (errno || !*optarg || *ep || max_hops > 255)
    430 				errx(1, "Invalid max hoplimit `%s'", optarg);
    431 			break;
    432 		case 'n':
    433 			nflag++;
    434 			break;
    435 		case 'p':
    436 			ep = NULL;
    437 			errno = 0;
    438 			lport = strtoul(optarg, &ep, 0);
    439 			if (errno || !*optarg || *ep)
    440 				errx(1, "Invalid port `%s'", optarg);
    441 			if (lport == 0 || lport != (lport & 0xffff))
    442 				errx(1, "Port `%s' out of range", optarg);
    443 			port = lport & 0xffff;
    444 			break;
    445 		case 'q':
    446 			ep = NULL;
    447 			errno = 0;
    448 			nprobes = strtoul(optarg, &ep, 0);
    449 			if (errno || !*optarg || *ep)
    450 				errx(1, "Invalid nprobes `%s'", optarg);
    451 			if (nprobes < 1)
    452 				errx(1, "nprobes `%s' must be > 0", optarg);
    453 			break;
    454 		case 'r':
    455 			options |= SO_DONTROUTE;
    456 			break;
    457 		case 's':
    458 			/*
    459 			 * set the ip source address of the outbound
    460 			 * probe (e.g., on a multi-homed host).
    461 			 */
    462 			source = optarg;
    463 			break;
    464 		case 'v':
    465 			verbose++;
    466 			break;
    467 		case 'w':
    468 			ep = NULL;
    469 			errno = 0;
    470 			waittime = strtoul(optarg, &ep, 0);
    471 			if (errno || !*optarg || *ep)
    472 				errx(1, "Invalid wait time `%s'", optarg);
    473 			if (waittime <= 1)
    474 				errx(1, "Wait `%s' must be > 1 sec", optarg);
    475 			break;
    476 		default:
    477 			usage();
    478 		}
    479 	argc -= optind;
    480 	argv += optind;
    481 
    482 	if (max_hops < first_hop)
    483 		errx(1, "max hoplimit `%lu' must be larger than "
    484 		    "first hoplimit `%lu'", max_hops, first_hop);
    485 
    486 	if (argc < 1 || argc > 2)
    487 		usage();
    488 
    489 #if 1
    490 	setvbuf(stdout, NULL, _IOLBF, BUFSIZ);
    491 #else
    492 	setlinebuf(stdout);
    493 #endif
    494 
    495 	memset(&hints, 0, sizeof(hints));
    496 	hints.ai_family = PF_INET6;
    497 	hints.ai_socktype = SOCK_RAW;
    498 	hints.ai_protocol = IPPROTO_ICMPV6;
    499 	hints.ai_flags = AI_CANONNAME;
    500 	error = getaddrinfo(*argv, NULL, &hints, &res);
    501 	if (error)
    502 		errx(1, "%s", gai_strerror(error));
    503 	if (res->ai_addrlen != sizeof(Dst))
    504 		errx(1, "size of sockaddr mismatch");
    505 	memcpy(&Dst, res->ai_addr, res->ai_addrlen);
    506 	hostname = res->ai_canonname ? strdup(res->ai_canonname) : *argv;
    507 	if (!hostname)
    508 		err(1, NULL);
    509 	if (res->ai_next) {
    510 		if (getnameinfo(res->ai_addr, res->ai_addrlen, hbuf,
    511 		    sizeof(hbuf), NULL, 0, NI_NUMERICHOST) != 0)
    512 			strlcpy(hbuf, "?", sizeof(hbuf));
    513 		warnx("`%s' has multiple addresses; using `%s'",
    514 		    hostname, hbuf);
    515 	}
    516 
    517 	if (*++argv) {
    518 		ep = NULL;
    519 		errno = 0;
    520 		datalen = strtoul(*argv, &ep, 0);
    521 		if (errno || *ep)
    522 			errx(1, "Invalid packet length `%s'", *argv);
    523 	}
    524 	if (useicmp)
    525 		minlen = ICMP6ECHOLEN + sizeof(struct tv32);
    526 	else
    527 		minlen = sizeof(struct opacket);
    528 	if (datalen < minlen)
    529 		datalen = minlen;
    530 	else if (datalen >= MAXPACKET)
    531 		errx(1, "Packet size must be %lu <= s < %lu",
    532 		    minlen, (u_long)MAXPACKET);
    533 	outpacket = (struct opacket *)malloc((unsigned)datalen);
    534 	if (!outpacket)
    535 		err(1, NULL);
    536 	memset(outpacket, 0, datalen);
    537 
    538 	/* initialize msghdr for receiving packets */
    539 	rcviov[0].iov_base = (caddr_t)packet;
    540 	rcviov[0].iov_len = sizeof(packet);
    541 	rcvmhdr.msg_name = (caddr_t)&Rcv;
    542 	rcvmhdr.msg_namelen = sizeof(Rcv);
    543 	rcvmhdr.msg_iov = rcviov;
    544 	rcvmhdr.msg_iovlen = 1;
    545 	rcvcmsglen = CMSG_SPACE(sizeof(struct in6_pktinfo)) +
    546 	    CMSG_SPACE(sizeof(int));
    547 	if ((rcvcmsgbuf = malloc(rcvcmsglen)) == NULL)
    548 		err(1, NULL);
    549 	rcvmhdr.msg_control = (caddr_t) rcvcmsgbuf;
    550 	rcvmhdr.msg_controllen = rcvcmsglen;
    551 
    552 	if (options & SO_DEBUG)
    553 		(void) setsockopt(rcvsock, SOL_SOCKET, SO_DEBUG,
    554 		    (char *)&on, sizeof(on));
    555 	if (options & SO_DONTROUTE)
    556 		(void) setsockopt(rcvsock, SOL_SOCKET, SO_DONTROUTE,
    557 		    (char *)&on, sizeof(on));
    558 #ifdef IPSEC
    559 #ifdef IPSEC_POLICY_IPSEC
    560 	/*
    561 	 * do not raise error even if setsockopt fails, kernel may have ipsec
    562 	 * turned off.
    563 	 */
    564 	if (setpolicy(rcvsock, "in bypass") < 0)
    565 		errx(1, "%s", ipsec_strerror());
    566 	if (setpolicy(rcvsock, "out bypass") < 0)
    567 		errx(1, "%s", ipsec_strerror());
    568 #else
    569     {
    570 	int level = IPSEC_LEVEL_NONE;
    571 
    572 	(void)setsockopt(rcvsock, IPPROTO_IPV6, IPV6_ESP_TRANS_LEVEL, &level,
    573 	    sizeof(level));
    574 	(void)setsockopt(rcvsock, IPPROTO_IPV6, IPV6_ESP_NETWORK_LEVEL, &level,
    575 	    sizeof(level));
    576 #ifdef IP_AUTH_TRANS_LEVEL
    577 	(void)setsockopt(rcvsock, IPPROTO_IPV6, IPV6_AUTH_TRANS_LEVEL, &level,
    578 	    sizeof(level));
    579 #else
    580 	(void)setsockopt(rcvsock, IPPROTO_IPV6, IPV6_AUTH_LEVEL, &level,
    581 	    sizeof(level));
    582 #endif
    583 #ifdef IP_AUTH_NETWORK_LEVEL
    584 	(void)setsockopt(rcvsock, IPPROTO_IPV6, IPV6_AUTH_NETWORK_LEVEL, &level,
    585 	    sizeof(level));
    586 #endif
    587     }
    588 #endif /*IPSEC_POLICY_IPSEC*/
    589 #endif /*IPSEC*/
    590 
    591 	/*
    592 	 * Send UDP or ICMP
    593 	 */
    594 	if (useicmp) {
    595 		sndsock = rcvsock;
    596 	} else {
    597 		if ((sndsock = socket(AF_INET6, SOCK_DGRAM, 0)) < 0)
    598 			err(5, "socket(SOCK_DGRAM)");
    599 	}
    600 #ifdef SO_SNDBUF
    601 	i = datalen;
    602 	if (setsockopt(sndsock, SOL_SOCKET, SO_SNDBUF, (char *)&i,
    603 	    sizeof(i)) < 0)
    604 		err(6, "setsockopt(SO_SNDBUF)");
    605 #endif /* SO_SNDBUF */
    606 	if (options & SO_DEBUG)
    607 		(void) setsockopt(sndsock, SOL_SOCKET, SO_DEBUG,
    608 		    (char *)&on, sizeof(on));
    609 	if (options & SO_DONTROUTE)
    610 		(void) setsockopt(sndsock, SOL_SOCKET, SO_DONTROUTE,
    611 		    (char *)&on, sizeof(on));
    612 
    613 #ifdef IPSEC
    614 #ifdef IPSEC_POLICY_IPSEC
    615 	/*
    616 	 * do not raise error even if setsockopt fails, kernel may have ipsec
    617 	 * turned off.
    618 	 */
    619 	if (setpolicy(sndsock, "in bypass") < 0)
    620 		errx(1, "%s", ipsec_strerror());
    621 	if (setpolicy(sndsock, "out bypass") < 0)
    622 		errx(1, "%s", ipsec_strerror());
    623 #else
    624     {
    625 	int level = IPSEC_LEVEL_BYPASS;
    626 
    627 	(void)setsockopt(sndsock, IPPROTO_IPV6, IPV6_ESP_TRANS_LEVEL, &level,
    628 	    sizeof(level));
    629 	(void)setsockopt(sndsock, IPPROTO_IPV6, IPV6_ESP_NETWORK_LEVEL, &level,
    630 	    sizeof(level));
    631 #ifdef IP_AUTH_TRANS_LEVEL
    632 	(void)setsockopt(sndsock, IPPROTO_IPV6, IPV6_AUTH_TRANS_LEVEL, &level,
    633 	    sizeof(level));
    634 #else
    635 	(void)setsockopt(sndsock, IPPROTO_IPV6, IPV6_AUTH_LEVEL, &level,
    636 	    sizeof(level));
    637 #endif
    638 #ifdef IP_AUTH_NETWORK_LEVEL
    639 	(void)setsockopt(sndsock, IPPROTO_IPV6, IPV6_AUTH_NETWORK_LEVEL, &level,
    640 	    sizeof(level));
    641 #endif
    642     }
    643 #endif /*IPSEC_POLICY_IPSEC*/
    644 #endif /*IPSEC*/
    645 
    646 	/*
    647 	 * Source selection
    648 	 */
    649 	memset(&Src, 0, sizeof(Src));
    650 	if (source) {
    651 		struct addrinfo hints0, *res0;
    652 		int error0;
    653 
    654 		memset(&hints0, 0, sizeof(hints0));
    655 		hints0.ai_family = AF_INET6;
    656 		hints0.ai_socktype = SOCK_DGRAM;	/*dummy*/
    657 		hints0.ai_flags = AI_NUMERICHOST;
    658 		error0 = getaddrinfo(source, "0", &hints0, &res0);
    659 		if (error0)
    660 			errx(1, "Cannot get address for `%s' (%s)", source,
    661 			    gai_strerror(error0));
    662 		if (res0->ai_addrlen > sizeof(Src))
    663 			errx(1, "Bad incompatible address length");
    664 		memcpy(&Src, res0->ai_addr, res0->ai_addrlen);
    665 		freeaddrinfo(res0);
    666 	} else {
    667 		struct sockaddr_in6 Nxt;
    668 		int dummy;
    669 		socklen_t len;
    670 
    671 		Nxt = Dst;
    672 		Nxt.sin6_port = htons(DUMMY_PORT);
    673 
    674 		if ((dummy = socket(AF_INET6, SOCK_DGRAM, 0)) < 0)
    675 			err(1, "socket");
    676 		if (connect(dummy, (struct sockaddr *)&Nxt, Nxt.sin6_len) < 0)
    677 			err(1, "connect");
    678 		len = sizeof(Src);
    679 		if (getsockname(dummy, (struct sockaddr *)&Src, &len) < 0)
    680 			err(1, "getsockname");
    681 		if ((error = getnameinfo((struct sockaddr *)&Src, Src.sin6_len,
    682 		    src0, sizeof(src0), NULL, 0, NI_NUMERICHOST)))
    683 			errx(1, "getnameinfo failed for source (%s)",
    684 			    gai_strerror(error));
    685 		source = src0;
    686 		close(dummy);
    687 	}
    688 
    689 	Src.sin6_port = htons(0);
    690 	if (bind(sndsock, (struct sockaddr *)&Src, Src.sin6_len) < 0)
    691 		err(1, "bind");
    692 
    693 	{
    694 		socklen_t len;
    695 
    696 		len = sizeof(Src);
    697 		if (getsockname(sndsock, (struct sockaddr *)&Src, &len) < 0)
    698 			err(1, "bind");
    699 		srcport = ntohs(Src.sin6_port);
    700 	}
    701 
    702 	if (as_path) {
    703 		asn = as_setup(as_server);
    704 		if (asn == NULL) {
    705 			warnx("as_setup failed, AS# lookups disabled");
    706 			(void)fflush(stderr);
    707 			as_path = 0;
    708 		}
    709 	 }
    710 
    711 	/*
    712 	 * Message to users
    713 	 */
    714 	if (getnameinfo((struct sockaddr *)&Dst, Dst.sin6_len, hbuf,
    715 	    sizeof(hbuf), NULL, 0, NI_NUMERICHOST))
    716 		strlcpy(hbuf, "(invalid)", sizeof(hbuf));
    717 	fprintf(stderr, "traceroute6");
    718 	fprintf(stderr, " to %s (%s)", hostname, hbuf);
    719 	if (source)
    720 		fprintf(stderr, " from %s", source);
    721 	fprintf(stderr, ", %lu hops max, %lu byte packets\n",
    722 	    max_hops, datalen);
    723 	(void) fflush(stderr);
    724 
    725 	if (first_hop > 1)
    726 		printf("Skipping %lu intermediate hops\n", first_hop - 1);
    727 
    728 	/*
    729 	 * Main loop
    730 	 */
    731 	for (hops = first_hop; hops <= max_hops; ++hops) {
    732 		struct in6_addr lastaddr;
    733 		int got_there = 0;
    734 		u_long unreachable = 0;
    735 
    736 		printf("%2lu ", hops);
    737 		memset(&lastaddr, 0, sizeof(lastaddr));
    738 		for (probe = 0; probe < nprobes; ++probe) {
    739 			int cc;
    740 			struct timeval t1, t2;
    741 
    742 			(void) gettimeofday(&t1, NULL);
    743 			if (!useicmp && htons((in_port_t)(port + seq + 1)) == 0)
    744 				seq++;
    745 			send_probe(++seq, hops);
    746 			while ((cc = wait_for_reply(rcvsock, &rcvmhdr))) {
    747 				(void) gettimeofday(&t2, NULL);
    748 				if ((i = packet_ok(&rcvmhdr, cc, seq))) {
    749 					if (!IN6_ARE_ADDR_EQUAL(&Rcv.sin6_addr,
    750 					    &lastaddr)) {
    751 						print(&rcvmhdr, cc);
    752 						lastaddr = Rcv.sin6_addr;
    753 					}
    754 					printf("  %g ms", deltaT(&t1, &t2));
    755 					switch (i - 1) {
    756 					case ICMP6_DST_UNREACH_NOROUTE:
    757 						++unreachable;
    758 						printf(" !N");
    759 						break;
    760 					case ICMP6_DST_UNREACH_ADMIN:
    761 						++unreachable;
    762 						printf(" !X");
    763 						break;
    764 					case ICMP6_DST_UNREACH_NOTNEIGHBOR:
    765 						++unreachable;
    766 						printf(" !S");
    767 						break;
    768 					case ICMP6_DST_UNREACH_ADDR:
    769 						++unreachable;
    770 						printf(" !H");
    771 						break;
    772 					case ICMP6_DST_UNREACH_NOPORT:
    773 						if (rcvhlim >= 0 &&
    774 						    rcvhlim <= 1)
    775 							printf(" !");
    776 						++got_there;
    777 						break;
    778 					}
    779 					break;
    780 				}
    781 			}
    782 			if (cc == 0)
    783 				printf(" *");
    784 			(void) fflush(stdout);
    785 		}
    786 		putchar('\n');
    787 		if (got_there ||
    788 		    (unreachable > 0 && unreachable >= ((nprobes + 1) / 2))) {
    789 			exit(0);
    790 		}
    791 	}
    792 
    793 	if (as_path)
    794 		as_shutdown(asn);
    795 
    796 	exit(0);
    797 }
    798 
    799 static ssize_t
    800 wait_for_reply(int sock, struct msghdr *mhdr)
    801 {
    802 #ifdef HAVE_POLL
    803 	struct pollfd pfd[1];
    804 	ssize_t cc = 0;
    805 
    806 	pfd[0].fd = sock;
    807 	pfd[0].events = POLLIN;
    808 	pfd[0].revents = 0;
    809 
    810 	if (poll(pfd, 1, waittime * 1000) > 0)
    811 		cc = recvmsg(rcvsock, mhdr, 0);
    812 
    813 	return cc;
    814 #else
    815 	fd_set *fdsp;
    816 	struct timeval wait;
    817 	ssize_t cc = 0;
    818 	int fdsn;
    819 
    820 	fdsn = howmany(sock + 1, NFDBITS) * sizeof(fd_mask);
    821 	if ((fdsp = (fd_set *)malloc(fdsn)) == NULL)
    822 		err(1, "malloc");
    823 	memset(fdsp, 0, fdsn);
    824 	FD_SET(sock, fdsp);
    825 	wait.tv_sec = waittime; wait.tv_usec = 0;
    826 
    827 	if (select(sock+1, fdsp, (fd_set *)0, (fd_set *)0, &wait) > 0)
    828 		cc = recvmsg(rcvsock, mhdr, 0);
    829 
    830 	free(fdsp);
    831 	return cc;
    832 #endif
    833 }
    834 
    835 #ifdef IPSEC
    836 #ifdef IPSEC_POLICY_IPSEC
    837 static int
    838 setpolicy(int so, const char *policy)
    839 {
    840 	char *buf;
    841 
    842 	buf = ipsec_set_policy(policy, strlen(policy));
    843 	if (buf == NULL) {
    844 		warnx("%s", ipsec_strerror());
    845 		return -1;
    846 	}
    847 	(void)setsockopt(so, IPPROTO_IPV6, IPV6_IPSEC_POLICY,
    848 	    buf, ipsec_get_policylen(buf));
    849 
    850 	free(buf);
    851 
    852 	return 0;
    853 }
    854 #endif
    855 #endif
    856 
    857 static void
    858 send_probe(int seq, u_long hops)
    859 {
    860 	struct timeval tv;
    861 	struct tv32 tv32;
    862 	int i;
    863 
    864 	i = hops;
    865 	if (setsockopt(sndsock, IPPROTO_IPV6, IPV6_UNICAST_HOPS,
    866 	    (char *)&i, sizeof(i)) < 0)
    867 		warn("setsockopt IPV6_UNICAST_HOPS");
    868 
    869 	Dst.sin6_port = htons(port + seq);
    870 	(void) gettimeofday(&tv, NULL);
    871 	tv32.tv32_sec = htonl(tv.tv_sec);
    872 	tv32.tv32_usec = htonl(tv.tv_usec);
    873 
    874 	if (useicmp) {
    875 		struct icmp6_hdr *icp = (struct icmp6_hdr *)outpacket;
    876 
    877 		icp->icmp6_type = ICMP6_ECHO_REQUEST;
    878 		icp->icmp6_code = 0;
    879 		icp->icmp6_cksum = 0;
    880 		icp->icmp6_id = ident;
    881 		icp->icmp6_seq = htons(seq);
    882 		memcpy(((u_int8_t *)outpacket + ICMP6ECHOLEN), &tv32,
    883 		    sizeof(tv32));
    884 	} else {
    885 		struct opacket *op = outpacket;
    886 
    887 		op->seq = seq;
    888 		op->hops = hops;
    889 		memcpy(&op->tv, &tv32, sizeof tv32);
    890 	}
    891 
    892 	i = sendto(sndsock, (char *)outpacket, datalen , 0,
    893 	    (struct sockaddr *)&Dst, Dst.sin6_len);
    894 	if (i < 0 || i != (int)datalen)  {
    895 		if (i < 0)
    896 			warnx("sendto");
    897 		printf("traceroute6: wrote %s %lu chars, ret=%d\n",
    898 		    hostname, datalen, i);
    899 		(void) fflush(stdout);
    900 	}
    901 }
    902 
    903 static double
    904 deltaT(struct timeval *t1p, struct timeval *t2p)
    905 {
    906 	double dt;
    907 
    908 	dt = (double)(t2p->tv_sec - t1p->tv_sec) * 1000.0 +
    909 	    (double)(t2p->tv_usec - t1p->tv_usec) / 1000.0;
    910 	return dt;
    911 }
    912 
    913 /*
    914  * Convert an ICMP "type" field to a printable string.
    915  */
    916 static const char *
    917 pr_type(int t0)
    918 {
    919 	u_char t = t0 & 0xff;
    920 	const char *cp;
    921 
    922 	switch (t) {
    923 	case ICMP6_DST_UNREACH:
    924 		cp = "Destination Unreachable";
    925 		break;
    926 	case ICMP6_PACKET_TOO_BIG:
    927 		cp = "Packet Too Big";
    928 		break;
    929 	case ICMP6_TIME_EXCEEDED:
    930 		cp = "Time Exceeded";
    931 		break;
    932 	case ICMP6_PARAM_PROB:
    933 		cp = "Parameter Problem";
    934 		break;
    935 	case ICMP6_ECHO_REQUEST:
    936 		cp = "Echo Request";
    937 		break;
    938 	case ICMP6_ECHO_REPLY:
    939 		cp = "Echo Reply";
    940 		break;
    941 	case ICMP6_MEMBERSHIP_QUERY:
    942 		cp = "Group Membership Query";
    943 		break;
    944 	case ICMP6_MEMBERSHIP_REPORT:
    945 		cp = "Group Membership Report";
    946 		break;
    947 	case ICMP6_MEMBERSHIP_REDUCTION:
    948 		cp = "Group Membership Reduction";
    949 		break;
    950 	case ND_ROUTER_SOLICIT:
    951 		cp = "Router Solicitation";
    952 		break;
    953 	case ND_ROUTER_ADVERT:
    954 		cp = "Router Advertisement";
    955 		break;
    956 	case ND_NEIGHBOR_SOLICIT:
    957 		cp = "Neighbor Solicitation";
    958 		break;
    959 	case ND_NEIGHBOR_ADVERT:
    960 		cp = "Neighbor Advertisement";
    961 		break;
    962 	case ND_REDIRECT:
    963 		cp = "Redirect";
    964 		break;
    965 	default:
    966 		cp = "Unknown";
    967 		break;
    968 	}
    969 	return cp;
    970 }
    971 
    972 static int
    973 packet_ok(struct msghdr *mhdr, ssize_t cc, int seq)
    974 {
    975 	struct icmp6_hdr *icp;
    976 	struct sockaddr_in6 *from = (struct sockaddr_in6 *)mhdr->msg_name;
    977 	u_char type, code;
    978 	char *buf = (char *)mhdr->msg_iov[0].iov_base;
    979 	struct cmsghdr *cm;
    980 	int *hlimp;
    981 	char hbuf[NI_MAXHOST];
    982 
    983 	if (cc < (ssize_t)sizeof(struct icmp6_hdr)) {
    984 		if (verbose) {
    985 			if (getnameinfo((struct sockaddr *)from, from->sin6_len,
    986 			    hbuf, sizeof(hbuf), NULL, 0, NI_NUMERICHOST) != 0)
    987 				strlcpy(hbuf, "invalid", sizeof(hbuf));
    988 			printf("data too short (%zd bytes) from %s\n", cc,
    989 			    hbuf);
    990 		}
    991 		return 0;
    992 	}
    993 	icp = (struct icmp6_hdr *)buf;
    994 
    995 	/* get optional information via advanced API */
    996 	rcvpktinfo = NULL;
    997 	hlimp = NULL;
    998 	for (cm = (struct cmsghdr *)CMSG_FIRSTHDR(mhdr); cm;
    999 	    cm = (struct cmsghdr *)CMSG_NXTHDR(mhdr, cm)) {
   1000 		if (cm->cmsg_level == IPPROTO_IPV6 &&
   1001 		    cm->cmsg_type == IPV6_PKTINFO &&
   1002 		    cm->cmsg_len ==
   1003 		    CMSG_LEN(sizeof(struct in6_pktinfo)))
   1004 			rcvpktinfo = (struct in6_pktinfo *)(CMSG_DATA(cm));
   1005 
   1006 		if (cm->cmsg_level == IPPROTO_IPV6 &&
   1007 		    cm->cmsg_type == IPV6_HOPLIMIT &&
   1008 		    cm->cmsg_len == CMSG_LEN(sizeof(int)))
   1009 			hlimp = (int *)CMSG_DATA(cm);
   1010 	}
   1011 	if (rcvpktinfo == NULL || hlimp == NULL) {
   1012 		warnx("failed to get received hop limit or packet info");
   1013 #if 0
   1014 		return 0;
   1015 #else
   1016 		rcvhlim = 0;	/*XXX*/
   1017 #endif
   1018 	}
   1019 	else
   1020 		rcvhlim = *hlimp;
   1021 
   1022 	type = icp->icmp6_type;
   1023 	code = icp->icmp6_code;
   1024 	if ((type == ICMP6_TIME_EXCEEDED && code == ICMP6_TIME_EXCEED_TRANSIT)
   1025 	    || type == ICMP6_DST_UNREACH) {
   1026 		struct ip6_hdr *hip;
   1027 		struct udphdr *up;
   1028 
   1029 		hip = (struct ip6_hdr *)(icp + 1);
   1030 		if ((up = get_udphdr(hip, (u_char *)(buf + cc))) == NULL) {
   1031 			if (verbose)
   1032 				warnx("failed to get upper layer header");
   1033 			return 0;
   1034 		}
   1035 		if (useicmp &&
   1036 		    ((struct icmp6_hdr *)up)->icmp6_id == ident &&
   1037 		    ((struct icmp6_hdr *)up)->icmp6_seq == htons(seq))
   1038 			return type == ICMP6_TIME_EXCEEDED ? -1 : code + 1;
   1039 		else if (!useicmp &&
   1040 		    up->uh_sport == htons(srcport) &&
   1041 		    up->uh_dport == htons(port + seq))
   1042 			return type == ICMP6_TIME_EXCEEDED ? -1 : code + 1;
   1043 	} else if (useicmp && type == ICMP6_ECHO_REPLY) {
   1044 		if (icp->icmp6_id == ident &&
   1045 		    icp->icmp6_seq == htons(seq))
   1046 			return ICMP6_DST_UNREACH_NOPORT + 1;
   1047 	}
   1048 	if (verbose) {
   1049 		char sbuf[NI_MAXHOST+1], dbuf[INET6_ADDRSTRLEN];
   1050 		u_int8_t *p;
   1051 		ssize_t i;
   1052 
   1053 		if (getnameinfo((struct sockaddr *)from, from->sin6_len,
   1054 		    sbuf, sizeof(sbuf), NULL, 0, NI_NUMERICHOST) != 0)
   1055 			strlcpy(sbuf, "invalid", sizeof(sbuf));
   1056 		printf("\n%zd bytes from %s to %s", cc, sbuf,
   1057 		    rcvpktinfo ? inet_ntop(AF_INET6, &rcvpktinfo->ipi6_addr,
   1058 		    dbuf, sizeof(dbuf)) : "?");
   1059 		printf(": icmp type %d (%s) code %d\n", type, pr_type(type),
   1060 		    icp->icmp6_code);
   1061 		p = (u_int8_t *)(icp + 1);
   1062 #define WIDTH	16
   1063 		for (i = 0; i < cc; i++) {
   1064 			if (i % WIDTH == 0)
   1065 				printf("%04zx:", i);
   1066 			if (i % 4 == 0)
   1067 				printf(" ");
   1068 			printf("%02x", p[i]);
   1069 			if (i % WIDTH == WIDTH - 1)
   1070 				printf("\n");
   1071 		}
   1072 		if (cc % WIDTH != 0)
   1073 			printf("\n");
   1074 	}
   1075 	return 0;
   1076 }
   1077 
   1078 /*
   1079  * Increment pointer until find the UDP or ICMP header.
   1080  */
   1081 static struct udphdr *
   1082 get_udphdr(struct ip6_hdr *ip6, u_char *lim)
   1083 {
   1084 	u_char *cp = (u_char *)ip6, nh;
   1085 	int hlen;
   1086 
   1087 	if (cp + sizeof(*ip6) >= lim)
   1088 		return NULL;
   1089 
   1090 	nh = ip6->ip6_nxt;
   1091 	cp += sizeof(struct ip6_hdr);
   1092 
   1093 	while (lim - cp >= 8) {
   1094 		switch (nh) {
   1095 		case IPPROTO_ESP:
   1096 		case IPPROTO_TCP:
   1097 			return NULL;
   1098 		case IPPROTO_ICMPV6:
   1099 			return useicmp ? (struct udphdr *)cp : NULL;
   1100 		case IPPROTO_UDP:
   1101 			return useicmp ? NULL : (struct udphdr *)cp;
   1102 		case IPPROTO_FRAGMENT:
   1103 			hlen = sizeof(struct ip6_frag);
   1104 			nh = ((struct ip6_frag *)cp)->ip6f_nxt;
   1105 			break;
   1106 		case IPPROTO_AH:
   1107 			hlen = (((struct ip6_ext *)cp)->ip6e_len + 2) << 2;
   1108 			nh = ((struct ip6_ext *)cp)->ip6e_nxt;
   1109 			break;
   1110 		default:
   1111 			hlen = (((struct ip6_ext *)cp)->ip6e_len + 1) << 3;
   1112 			nh = ((struct ip6_ext *)cp)->ip6e_nxt;
   1113 			break;
   1114 		}
   1115 
   1116 		cp += hlen;
   1117 	}
   1118 
   1119 	return NULL;
   1120 }
   1121 
   1122 static void
   1123 print(struct msghdr *mhdr, int cc)
   1124 {
   1125 	struct sockaddr_in6 *from = (struct sockaddr_in6 *)mhdr->msg_name;
   1126 	char hbuf[NI_MAXHOST];
   1127 
   1128 	if (getnameinfo((struct sockaddr *)from, from->sin6_len,
   1129 	    hbuf, sizeof(hbuf), NULL, 0, NI_NUMERICHOST) != 0)
   1130 		strlcpy(hbuf, "invalid", sizeof(hbuf));
   1131 	if (as_path)
   1132 		printf(" [AS%u]", as_lookup(asn, hbuf, AF_INET6));
   1133 	if (nflag)
   1134 		printf(" %s", hbuf);
   1135 	else if (lflag)
   1136 		printf(" %s (%s)", inetname((struct sockaddr *)from), hbuf);
   1137 	else
   1138 		printf(" %s", inetname((struct sockaddr *)from));
   1139 
   1140 	if (verbose) {
   1141 		printf(" %d bytes of data to %s", cc,
   1142 		    rcvpktinfo ?  inet_ntop(AF_INET6, &rcvpktinfo->ipi6_addr,
   1143 		    hbuf, sizeof(hbuf)) : "?");
   1144 	}
   1145 }
   1146 
   1147 /*
   1148  * Construct an Internet address representation.
   1149  * If the nflag has been supplied, give
   1150  * numeric value, otherwise try for symbolic name.
   1151  */
   1152 static const char *
   1153 inetname(struct sockaddr *sa)
   1154 {
   1155 	static char line[NI_MAXHOST], domain[MAXHOSTNAMELEN + 1];
   1156 	static int first = 1;
   1157 	char *cp;
   1158 
   1159 	if (first && !nflag) {
   1160 		first = 0;
   1161 		if (gethostname(domain, sizeof(domain)) == 0 &&
   1162 		    (cp = strchr(domain, '.')))
   1163 			(void) strlcpy(domain, cp + 1, sizeof(domain));
   1164 		else
   1165 			domain[0] = 0;
   1166 	}
   1167 	cp = NULL;
   1168 	if (!nflag) {
   1169 		if (getnameinfo(sa, sa->sa_len, line, sizeof(line), NULL, 0,
   1170 		    NI_NAMEREQD) == 0) {
   1171 			if ((cp = strchr(line, '.')) &&
   1172 			    !strcmp(cp + 1, domain))
   1173 				*cp = 0;
   1174 			cp = line;
   1175 		}
   1176 	}
   1177 	if (cp)
   1178 		return cp;
   1179 
   1180 	if (getnameinfo(sa, sa->sa_len, line, sizeof(line), NULL, 0,
   1181 	    NI_NUMERICHOST) != 0)
   1182 		strlcpy(line, "invalid", sizeof(line));
   1183 	return line;
   1184 }
   1185 
   1186 static void
   1187 usage(void)
   1188 {
   1189 
   1190 	fprintf(stderr,
   1191 "Usage: %s [-adIlnrv] [-A as_server] [-f firsthop] [-m hoplimit]\n"
   1192 "\t[-p port] [-q probes] [-s src] [-w waittime] target [datalen]\n",
   1193 	getprogname());
   1194 	exit(1);
   1195 }
   1196