xref: /openbsd/sbin/dhclient/options.c (revision b414edd1)
1*b414edd1Skrw /*	$OpenBSD: options.c,v 1.94 2017/07/07 14:53:07 krw Exp $	*/
29a2590e5Sderaadt 
3e7eb2effShenning /* DHCP options parsing and reassembly. */
49a2590e5Sderaadt 
59a2590e5Sderaadt /*
69a2590e5Sderaadt  * Copyright (c) 1995, 1996, 1997, 1998 The Internet Software Consortium.
79a2590e5Sderaadt  * All rights reserved.
89a2590e5Sderaadt  *
99a2590e5Sderaadt  * Redistribution and use in source and binary forms, with or without
109a2590e5Sderaadt  * modification, are permitted provided that the following conditions
119a2590e5Sderaadt  * are met:
129a2590e5Sderaadt  *
139a2590e5Sderaadt  * 1. Redistributions of source code must retain the above copyright
149a2590e5Sderaadt  *    notice, this list of conditions and the following disclaimer.
159a2590e5Sderaadt  * 2. Redistributions in binary form must reproduce the above copyright
169a2590e5Sderaadt  *    notice, this list of conditions and the following disclaimer in the
179a2590e5Sderaadt  *    documentation and/or other materials provided with the distribution.
189a2590e5Sderaadt  * 3. Neither the name of The Internet Software Consortium nor the names
199a2590e5Sderaadt  *    of its contributors may be used to endorse or promote products derived
209a2590e5Sderaadt  *    from this software without specific prior written permission.
219a2590e5Sderaadt  *
229a2590e5Sderaadt  * THIS SOFTWARE IS PROVIDED BY THE INTERNET SOFTWARE CONSORTIUM AND
239a2590e5Sderaadt  * CONTRIBUTORS ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
249a2590e5Sderaadt  * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
259a2590e5Sderaadt  * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
269a2590e5Sderaadt  * DISCLAIMED.  IN NO EVENT SHALL THE INTERNET SOFTWARE CONSORTIUM OR
279a2590e5Sderaadt  * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
289a2590e5Sderaadt  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
299a2590e5Sderaadt  * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
309a2590e5Sderaadt  * USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
319a2590e5Sderaadt  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
329a2590e5Sderaadt  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
339a2590e5Sderaadt  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
349a2590e5Sderaadt  * SUCH DAMAGE.
359a2590e5Sderaadt  *
369a2590e5Sderaadt  * This software has been written for the Internet Software Consortium
379a2590e5Sderaadt  * by Ted Lemon <mellon@fugue.com> in cooperation with Vixie
389a2590e5Sderaadt  * Enterprises.  To learn more about the Internet Software Consortium,
399a2590e5Sderaadt  * see ``http://www.vix.com/isc''.  To learn more about Vixie
409a2590e5Sderaadt  * Enterprises, see ``http://www.vix.com''.
419a2590e5Sderaadt  */
429a2590e5Sderaadt 
43711cae1eSkrw #include <sys/queue.h>
44711cae1eSkrw #include <sys/socket.h>
459a2590e5Sderaadt 
46711cae1eSkrw #include <arpa/inet.h>
47711cae1eSkrw 
48711cae1eSkrw #include <net/if.h>
49711cae1eSkrw 
50711cae1eSkrw #include <netinet/in.h>
51711cae1eSkrw #include <netinet/if_ether.h>
52711cae1eSkrw 
53711cae1eSkrw #include <ctype.h>
54711cae1eSkrw #include <signal.h>
55711cae1eSkrw #include <stdio.h>
56711cae1eSkrw #include <stdlib.h>
57711cae1eSkrw #include <string.h>
588d2bd14bSkrw #include <vis.h>
598d2bd14bSkrw 
60711cae1eSkrw #include "dhcp.h"
61711cae1eSkrw #include "dhcpd.h"
62385a6373Skrw #include "log.h"
63711cae1eSkrw 
6402e02bd5Skrw int parse_option_buffer(struct option_data *, unsigned char *, int);
65968fe952Skrw int expand_search_domain_name(unsigned char *, size_t, int *, unsigned char *);
669a2590e5Sderaadt 
67c714dadcShenning /*
68c714dadcShenning  * Parse options out of the specified buffer, storing addresses of
6992018899Skrw  * option values in options. Return 0 if errors, 1 if not.
70c714dadcShenning  */
7102e02bd5Skrw int
724f062ee3Skrw parse_option_buffer(struct option_data *options, unsigned char *buffer,
734f062ee3Skrw     int length)
749a2590e5Sderaadt {
75285f06efSderaadt 	unsigned char *s, *t, *end = buffer + length;
76285f06efSderaadt 	int len, code;
779a2590e5Sderaadt 
789a2590e5Sderaadt 	for (s = buffer; *s != DHO_END && s < end; ) {
799a2590e5Sderaadt 		code = s[0];
809a2590e5Sderaadt 
819a2590e5Sderaadt 		/* Pad options don't have a length - just skip them. */
829a2590e5Sderaadt 		if (code == DHO_PAD) {
83f1e89499Shenning 			s++;
849a2590e5Sderaadt 			continue;
859a2590e5Sderaadt 		}
869a2590e5Sderaadt 
87c714dadcShenning 		/*
8899c003b1Skrw 		 * All options other than DHO_PAD and DHO_END have a one-byte
8999c003b1Skrw 		 * length field. It could be 0! Make sure that the length byte
9099c003b1Skrw 		 * is present, and all the data is available.
91c714dadcShenning 		 */
9299c003b1Skrw 		if (s + 1 < end) {
939a2590e5Sderaadt 			len = s[1];
9499c003b1Skrw 			if (s + 1 + len < end) {
9599c003b1Skrw 				; /* option data is all there. */
9699c003b1Skrw 			} else {
97385a6373Skrw 				log_warnx("option %s (%d) larger than buffer.",
98b6fc88b9Skrw 				    dhcp_options[code].name, len);
9902e02bd5Skrw 				return (0);
1009a2590e5Sderaadt 			}
10199c003b1Skrw 		} else {
102385a6373Skrw 			log_warnx("option %s has no length field.",
10399c003b1Skrw 			    dhcp_options[code].name);
10499c003b1Skrw 			return (0);
10599c003b1Skrw 		}
106df453039Skrw 
107df453039Skrw 		/*
108df453039Skrw 		 * Strip trailing NULs from ascii ('t') options. They
109df453039Skrw 		 * will be treated as DHO_PAD options. i.e. ignored. RFC 2132
110df453039Skrw 		 * says "Options containing NVT ASCII data SHOULD NOT include
111df453039Skrw 		 * a trailing NULL; however, the receiver of such options
112df453039Skrw 		 * MUST be prepared to delete trailing nulls if they exist."
113df453039Skrw 		 */
114df453039Skrw 		if (dhcp_options[code].format[0] == 't') {
11599c003b1Skrw 			while (len > 0 && s[len + 1] == '\0')
11699c003b1Skrw 				len--;
117df453039Skrw 		}
118df453039Skrw 
119c714dadcShenning 		/*
120c714dadcShenning 		 * If we haven't seen this option before, just make
121c714dadcShenning 		 * space for it and copy it there.
122c714dadcShenning 		 */
1234f062ee3Skrw 		if (!options[code].data) {
1248e916ab9Shenning 			if (!(t = calloc(1, len + 1)))
125385a6373Skrw 				fatalx("Can't allocate storage for option %s.",
1269a2590e5Sderaadt 				    dhcp_options[code].name);
127c714dadcShenning 			/*
128c714dadcShenning 			 * Copy and NUL-terminate the option (in case
129cff08477Sstevesk 			 * it's an ASCII string).
130c714dadcShenning 			 */
1319a2590e5Sderaadt 			memcpy(t, &s[2], len);
1329a2590e5Sderaadt 			t[len] = 0;
1334f062ee3Skrw 			options[code].len = len;
1344f062ee3Skrw 			options[code].data = t;
1359a2590e5Sderaadt 		} else {
136c714dadcShenning 			/*
137c714dadcShenning 			 * If it's a repeat, concatenate it to whatever
13892018899Skrw 			 * we last saw.
139c714dadcShenning 			 */
1404f062ee3Skrw 			t = calloc(1, len + options[code].len + 1);
1419a2590e5Sderaadt 			if (!t)
142385a6373Skrw 				fatalx("Can't expand storage for option %s.",
1439a2590e5Sderaadt 				    dhcp_options[code].name);
1444f062ee3Skrw 			memcpy(t, options[code].data, options[code].len);
1454f062ee3Skrw 			memcpy(t + options[code].len, &s[2], len);
1464f062ee3Skrw 			options[code].len += len;
1474f062ee3Skrw 			t[options[code].len] = 0;
1484f062ee3Skrw 			free(options[code].data);
1494f062ee3Skrw 			options[code].data = t;
1509a2590e5Sderaadt 		}
1519a2590e5Sderaadt 		s += len + 2;
1529a2590e5Sderaadt 	}
15302e02bd5Skrw 
15402e02bd5Skrw 	return (1);
1559a2590e5Sderaadt }
1569a2590e5Sderaadt 
157c714dadcShenning /*
158*b414edd1Skrw  * Pack as many options as fit in buflen bytes of buf. Return the
15996978980Skrw  * offset of the start of the last option copied. A caller can check
16096978980Skrw  * to see if it's DHO_END to decide if all the options were copied.
161c714dadcShenning  */
162c714dadcShenning int
163*b414edd1Skrw pack_options(unsigned char *buf, int buflen, struct option_data *options)
1649a2590e5Sderaadt {
16596978980Skrw 	int ix, incr, length, bufix, code, lastopt = -1;
1669a2590e5Sderaadt 
167736b0ed2Skrw 	memset(buf, 0, buflen);
1689a2590e5Sderaadt 
16996978980Skrw 	memcpy(buf, DHCP_OPTIONS_COOKIE, 4);
170d6a67f0fSkrw 	if (options[DHO_DHCP_MESSAGE_TYPE].data) {
171d6a67f0fSkrw 		memcpy(&buf[4], DHCP_OPTIONS_MESSAGE_TYPE, 3);
172d6a67f0fSkrw 		buf[6] = options[DHO_DHCP_MESSAGE_TYPE].data[0];
173d6a67f0fSkrw 		bufix = 7;
174d6a67f0fSkrw 	} else
17596978980Skrw 		bufix = 4;
1769a2590e5Sderaadt 
17796978980Skrw 	for (code = DHO_SUBNET_MASK; code < DHO_END; code++) {
178d6a67f0fSkrw 		if (!options[code].data || code == DHO_DHCP_MESSAGE_TYPE)
1799a2590e5Sderaadt 			continue;
1809a2590e5Sderaadt 
181d7d9bbf5Skrw 		length = options[code].len;
18296978980Skrw 		if (bufix + length + 2*((length+254)/255) >= buflen)
18396978980Skrw 			return (lastopt);
1849a2590e5Sderaadt 
18596978980Skrw 		lastopt = bufix;
1869a2590e5Sderaadt 		ix = 0;
1879a2590e5Sderaadt 
1889a2590e5Sderaadt 		while (length) {
18996978980Skrw 			incr = length > 255 ? 255 : length;
1909a2590e5Sderaadt 
19196978980Skrw 			buf[bufix++] = code;
19296978980Skrw 			buf[bufix++] = incr;
19396978980Skrw 			memcpy(buf + bufix, options[code].data + ix, incr);
1949a2590e5Sderaadt 
1959a2590e5Sderaadt 			length -= incr;
1969a2590e5Sderaadt 			ix += incr;
1976fc9f4f6Skrw 			bufix += incr;
1989a2590e5Sderaadt 		}
1999a2590e5Sderaadt 	}
20096978980Skrw 
20196978980Skrw 	if (bufix < buflen) {
20296978980Skrw 		buf[bufix] = DHO_END;
20396978980Skrw 		lastopt = bufix;
20496978980Skrw 	}
20596978980Skrw 
20696978980Skrw 	return (lastopt);
2079a2590e5Sderaadt }
2089a2590e5Sderaadt 
209c714dadcShenning /*
210482123e8Skrw  * Use vis() to encode characters of src and append encoded characters onto
211482123e8Skrw  * dst. Also encode ", ', $, ` and \, to ensure resulting strings can be
212482123e8Skrw  * represented as '"' delimited strings and safely passed to scripts. Surround
213482123e8Skrw  * result with double quotes if emit_punct is true.
214482123e8Skrw  */
215bee06f07Skrw char *
216bee06f07Skrw pretty_print_string(unsigned char *src, size_t srclen, int emit_punct)
217482123e8Skrw {
218bee06f07Skrw 	static char string[8196];
219482123e8Skrw 	char visbuf[5];
220482123e8Skrw 	unsigned char *origsrc = src;
221bee06f07Skrw 	size_t rslt = 0;
222482123e8Skrw 
223bee06f07Skrw 	memset(string, 0, sizeof(string));
224bee06f07Skrw 
225bee06f07Skrw 	if (emit_punct)
226bee06f07Skrw 		rslt = strlcat(string, "\"", sizeof(string));
227482123e8Skrw 
228482123e8Skrw 	for (; src < origsrc + srclen; src++) {
229482123e8Skrw 		if (*src && strchr("\"'$`\\", *src))
230642cc348Skrw 			vis(visbuf, *src, VIS_ALL | VIS_OCTAL, *src+1);
231642cc348Skrw 		else
232482123e8Skrw 			vis(visbuf, *src, VIS_OCTAL, *src+1);
233bee06f07Skrw 		rslt = strlcat(string, visbuf, sizeof(string));
234482123e8Skrw 	}
235482123e8Skrw 
236bee06f07Skrw 	if (emit_punct)
237bee06f07Skrw 		rslt = strlcat(string, "\"", sizeof(string));
238bee06f07Skrw 
239bee06f07Skrw 	if (rslt >= sizeof(string))
240bee06f07Skrw 		return (NULL);
241bee06f07Skrw 
242bee06f07Skrw 	return (string);
243482123e8Skrw }
244482123e8Skrw 
245482123e8Skrw /*
2465714f486Skrw  * Must special case *_CLASSLESS_* route options due to the variable size
2475714f486Skrw  * of the CIDR element in its CIA format.
2485714f486Skrw  */
249da2eb076Skrw char *
250da2eb076Skrw pretty_print_classless_routes(unsigned char *src, size_t srclen)
2515714f486Skrw {
252da2eb076Skrw 	static char string[8196];
253da2eb076Skrw 	char bitsbuf[5];	/* to hold "/nn " */
254da2eb076Skrw 	struct in_addr net, gateway;
255e0a6d2f1Skrw 	unsigned int bytes;
256e0a6d2f1Skrw 	int bits, rslt;
2575714f486Skrw 
258da2eb076Skrw 	memset(string, 0, sizeof(string));
259da2eb076Skrw 
260da2eb076Skrw 	while (srclen) {
2615714f486Skrw 		bits = *src;
2625714f486Skrw 		src++;
2635714f486Skrw 		srclen--;
264da2eb076Skrw 
2655714f486Skrw 		bytes = (bits + 7) / 8;
266da2eb076Skrw 		if (srclen < (bytes + sizeof(gateway.s_addr)) ||
267da2eb076Skrw 		    bytes > sizeof(net.s_addr))
268da2eb076Skrw 			return (NULL);
269da2eb076Skrw 		rslt = snprintf(bitsbuf, sizeof(bitsbuf), "/%d ", bits);
2701be0b429Skrw 		if (rslt == -1 || (unsigned int)rslt >= sizeof(bitsbuf))
271da2eb076Skrw 			return (NULL);
272da2eb076Skrw 
273da2eb076Skrw 		memset(&net, 0, sizeof(net));
274da2eb076Skrw 		memcpy(&net.s_addr, src, bytes);
2755714f486Skrw 		src += bytes;
2765714f486Skrw 		srclen -= bytes;
277da2eb076Skrw 
2785714f486Skrw 		memcpy(&gateway.s_addr, src, sizeof(gateway.s_addr));
2795714f486Skrw 		src += sizeof(gateway.s_addr);
2805714f486Skrw 		srclen -= sizeof(gateway.s_addr);
281da2eb076Skrw 
282da2eb076Skrw 		if (strlen(string) > 0)
283da2eb076Skrw 			strlcat(string, ", ", sizeof(string));
284da2eb076Skrw 		strlcat(string, inet_ntoa(net), sizeof(string));
285da2eb076Skrw 		strlcat(string, bitsbuf, sizeof(string));
2861be0b429Skrw 		if (strlcat(string, inet_ntoa(gateway), sizeof(string)) >=
2871be0b429Skrw 		    sizeof(string))
288da2eb076Skrw 			return (NULL);
2895714f486Skrw 	}
2905714f486Skrw 
291da2eb076Skrw 	return (string);
2925714f486Skrw }
2935714f486Skrw 
294968fe952Skrw int
295968fe952Skrw expand_search_domain_name(unsigned char *src, size_t srclen, int *offset,
296968fe952Skrw     unsigned char *domain_search)
297968fe952Skrw {
298e0a6d2f1Skrw 	unsigned int i;
299e0a6d2f1Skrw 	int domain_name_len, label_len, pointer, pointed_len;
300968fe952Skrw 	char *cursor;
301968fe952Skrw 
302968fe952Skrw 	cursor = domain_search + strlen(domain_search);
303968fe952Skrw 	domain_name_len = 0;
304968fe952Skrw 
305968fe952Skrw 	i = *offset;
306968fe952Skrw 	while (i <= srclen) {
307968fe952Skrw 		label_len = src[i];
308968fe952Skrw 		if (label_len == 0) {
309968fe952Skrw 			/*
310968fe952Skrw 			 * A zero-length label marks the end of this
311968fe952Skrw 			 * domain name.
312968fe952Skrw 			 */
313968fe952Skrw 			*offset = i + 1;
314968fe952Skrw 			return (domain_name_len);
315968fe952Skrw 		} else if (label_len & 0xC0) {
316968fe952Skrw 			/* This is a pointer to another list of labels. */
317968fe952Skrw 			if (i + 1 >= srclen) {
318968fe952Skrw 				/* The pointer is truncated. */
319385a6373Skrw 				log_warnx("Truncated pointer in DHCP Domain "
320968fe952Skrw 				    "Search option.");
321968fe952Skrw 				return (-1);
322968fe952Skrw 			}
323968fe952Skrw 
324968fe952Skrw 			pointer = ((label_len & ~(0xC0)) << 8) + src[i + 1];
325968fe952Skrw 			if (pointer >= *offset) {
326968fe952Skrw 				/*
327968fe952Skrw 				 * The pointer must indicates a prior
328968fe952Skrw 				 * occurance.
329968fe952Skrw 				 */
330385a6373Skrw 				log_warnx("Invalid forward pointer in DHCP "
331968fe952Skrw 				    "Domain Search option compression.");
332968fe952Skrw 				return (-1);
333968fe952Skrw 			}
334968fe952Skrw 
335968fe952Skrw 			pointed_len = expand_search_domain_name(src, srclen,
336968fe952Skrw 			    &pointer, domain_search);
337968fe952Skrw 			domain_name_len += pointed_len;
338968fe952Skrw 
339968fe952Skrw 			*offset = i + 2;
340968fe952Skrw 			return (domain_name_len);
341968fe952Skrw 		}
342968fe952Skrw 		if (i + label_len + 1 > srclen) {
343385a6373Skrw 			log_warnx("Truncated label in DHCP Domain Search "
344968fe952Skrw 			    "option.");
345968fe952Skrw 			return (-1);
346968fe952Skrw 		}
347968fe952Skrw 		/*
348968fe952Skrw 		 * Update the domain name length with the length of the
349968fe952Skrw 		 * current label, plus a trailing dot ('.').
350968fe952Skrw 		 */
351968fe952Skrw 		domain_name_len += label_len + 1;
352968fe952Skrw 
353968fe952Skrw 		if (strlen(domain_search) + domain_name_len >=
354968fe952Skrw 		    DHCP_DOMAIN_SEARCH_LEN) {
355385a6373Skrw 			log_warnx("Domain search list too long.");
356968fe952Skrw 			return (-1);
357968fe952Skrw 		}
358968fe952Skrw 
359968fe952Skrw 		/* Copy the label found. */
360968fe952Skrw 		memcpy(cursor, src + i + 1, label_len);
361968fe952Skrw 		cursor[label_len] = '.';
362968fe952Skrw 
363968fe952Skrw 		/* Move cursor. */
364968fe952Skrw 		i += label_len + 1;
365968fe952Skrw 		cursor += label_len + 1;
366968fe952Skrw 	}
367968fe952Skrw 
368385a6373Skrw 	log_warnx("Truncated DHCP Domain Search option.");
369968fe952Skrw 
370968fe952Skrw 	return (-1);
371968fe952Skrw }
372968fe952Skrw 
373968fe952Skrw /*
374968fe952Skrw  * Must special case DHO_DOMAIN_SEARCH because it is encoded as described
375968fe952Skrw  * in RFC 1035 section 4.1.4.
376968fe952Skrw  */
3774d36d16aSkrw char *
3784d36d16aSkrw pretty_print_domain_search(unsigned char *src, size_t srclen)
379968fe952Skrw {
3804d36d16aSkrw 	static char domain_search[DHCP_DOMAIN_SEARCH_LEN];
381e0a6d2f1Skrw 	unsigned int offset;
382e0a6d2f1Skrw 	int len, expanded_len, domains;
3834d36d16aSkrw 	unsigned char *cursor;
384968fe952Skrw 
3854d36d16aSkrw 	memset(domain_search, 0, sizeof(domain_search));
386968fe952Skrw 
387968fe952Skrw 	/* Compute expanded length. */
388968fe952Skrw 	expanded_len = len = 0;
389968fe952Skrw 	domains = 0;
390968fe952Skrw 	offset = 0;
391968fe952Skrw 	while (offset < srclen) {
392968fe952Skrw 		cursor = domain_search + strlen(domain_search);
393968fe952Skrw 		if (domain_search[0]) {
394968fe952Skrw 			*cursor = ' ';
395968fe952Skrw 			expanded_len++;
396968fe952Skrw 		}
397968fe952Skrw 		len = expand_search_domain_name(src, srclen, &offset,
398968fe952Skrw 		    domain_search);
3994d36d16aSkrw 		if (len == -1)
4004d36d16aSkrw 			return (NULL);
401968fe952Skrw 		domains++;
402968fe952Skrw 		expanded_len += len;
4034d36d16aSkrw 		if (domains > DHCP_DOMAIN_SEARCH_CNT)
4044d36d16aSkrw 			return (NULL);
405968fe952Skrw 	}
406968fe952Skrw 
4074d36d16aSkrw 	return (domain_search);
408968fe952Skrw }
409968fe952Skrw 
4105714f486Skrw /*
411c714dadcShenning  * Format the specified option so that a human can easily read it.
412c714dadcShenning  */
413c714dadcShenning char *
414acf4c28bSkrw pretty_print_option(unsigned int code, struct option_data *option,
415acf4c28bSkrw     int emit_punct)
4169a2590e5Sderaadt {
417bee06f07Skrw 	static char optbuf[8192]; /* XXX */
418285f06efSderaadt 	int hunksize = 0, numhunk = -1, numelem = 0;
419bee06f07Skrw 	char fmtbuf[32], *op = optbuf, *buf;
420285f06efSderaadt 	int i, j, k, opleft = sizeof(optbuf);
421acf4c28bSkrw 	unsigned char *data = option->data;
4229a2590e5Sderaadt 	unsigned char *dp = data;
423acf4c28bSkrw 	int len = option->len;
424f3a8c5fdSkrw 	int opcount = 0;
4259a2590e5Sderaadt 	struct in_addr foo;
4269a2590e5Sderaadt 	char comma;
427bce09e58Skrw 	int32_t int32val;
428bce09e58Skrw 	u_int32_t uint32val;
429bce09e58Skrw 	u_int16_t uint16val;
4309a2590e5Sderaadt 
4312f18daabSkrw 	memset(optbuf, 0, sizeof(optbuf));
4322f18daabSkrw 
4339a2590e5Sderaadt 	/* Code should be between 0 and 255. */
4342f18daabSkrw 	if (code > 255) {
435385a6373Skrw 		log_warnx("pretty_print_option: bad code %d", code);
4362f18daabSkrw 		goto done;
4372f18daabSkrw 	}
4389a2590e5Sderaadt 
439acf4c28bSkrw 	if (emit_punct)
4409a2590e5Sderaadt 		comma = ',';
4419a2590e5Sderaadt 	else
4429a2590e5Sderaadt 		comma = ' ';
4439a2590e5Sderaadt 
4445714f486Skrw 	/* Handle the princess class options with weirdo formats. */
4455714f486Skrw 	switch (code) {
4465714f486Skrw 	case DHO_CLASSLESS_STATIC_ROUTES:
4475714f486Skrw 	case DHO_CLASSLESS_MS_STATIC_ROUTES:
448da2eb076Skrw 		buf = pretty_print_classless_routes(dp, len);
449da2eb076Skrw 		if (buf == NULL)
4505714f486Skrw 			goto toobig;
451da2eb076Skrw 		strlcat(optbuf, buf, sizeof(optbuf));
4525714f486Skrw 		goto done;
4535714f486Skrw 	default:
4545714f486Skrw 		break;
4555714f486Skrw 	}
4565714f486Skrw 
4579a2590e5Sderaadt 	/* Figure out the size of the data. */
4589a2590e5Sderaadt 	for (i = 0; dhcp_options[code].format[i]; i++) {
4599a2590e5Sderaadt 		if (!numhunk) {
460833082e5Skrw 			log_warnx("%s: Excess information in format string: "
461833082e5Skrw 			    "%s", dhcp_options[code].name,
4629a2590e5Sderaadt 			    &(dhcp_options[code].format[i]));
4632f18daabSkrw 			goto done;
4649a2590e5Sderaadt 		}
4659a2590e5Sderaadt 		numelem++;
4669a2590e5Sderaadt 		fmtbuf[i] = dhcp_options[code].format[i];
4679a2590e5Sderaadt 		switch (dhcp_options[code].format[i]) {
4689a2590e5Sderaadt 		case 'A':
4699a2590e5Sderaadt 			--numelem;
4709a2590e5Sderaadt 			fmtbuf[i] = 0;
4719a2590e5Sderaadt 			numhunk = 0;
47229432cd9Sphessler 			if (hunksize == 0) {
473385a6373Skrw 				log_warnx("%s: no size indicator before A"
47429432cd9Sphessler 				    " in format string: %s",
47529432cd9Sphessler 				    dhcp_options[code].name,
47629432cd9Sphessler 				    dhcp_options[code].format);
4772f18daabSkrw 				goto done;
47829432cd9Sphessler 			}
4799a2590e5Sderaadt 			break;
4809a2590e5Sderaadt 		case 'X':
481c714dadcShenning 			for (k = 0; k < len; k++)
4829a2590e5Sderaadt 				if (!isascii(data[k]) ||
4839a2590e5Sderaadt 				    !isprint(data[k]))
4849a2590e5Sderaadt 					break;
485b54c879eShenning 			if (k == len) {
4869a2590e5Sderaadt 				fmtbuf[i] = 't';
4879a2590e5Sderaadt 				numhunk = -2;
4889a2590e5Sderaadt 			} else {
4899a2590e5Sderaadt 				hunksize++;
4909a2590e5Sderaadt 				comma = ':';
4919a2590e5Sderaadt 				numhunk = 0;
4929a2590e5Sderaadt 			}
4939a2590e5Sderaadt 			fmtbuf[i + 1] = 0;
4949a2590e5Sderaadt 			break;
4959a2590e5Sderaadt 		case 't':
4969a2590e5Sderaadt 			fmtbuf[i + 1] = 0;
4979a2590e5Sderaadt 			numhunk = -2;
4989a2590e5Sderaadt 			break;
4999a2590e5Sderaadt 		case 'I':
5009a2590e5Sderaadt 		case 'l':
5019a2590e5Sderaadt 		case 'L':
5029a2590e5Sderaadt 			hunksize += 4;
5039a2590e5Sderaadt 			break;
5049a2590e5Sderaadt 		case 'S':
5059a2590e5Sderaadt 			hunksize += 2;
5069a2590e5Sderaadt 			break;
5079a2590e5Sderaadt 		case 'B':
5089a2590e5Sderaadt 		case 'f':
5099a2590e5Sderaadt 			hunksize++;
5109a2590e5Sderaadt 			break;
5119a2590e5Sderaadt 		case 'e':
5129a2590e5Sderaadt 			break;
5139a2590e5Sderaadt 		default:
514385a6373Skrw 			log_warnx("%s: garbage in format string: %s",
5159a2590e5Sderaadt 			    dhcp_options[code].name,
5169a2590e5Sderaadt 			    &(dhcp_options[code].format[i]));
5172f18daabSkrw 			goto done;
5189a2590e5Sderaadt 		}
5199a2590e5Sderaadt 	}
5209a2590e5Sderaadt 
521d22f105fSkrw 	/* Check for too few bytes. */
5229a2590e5Sderaadt 	if (hunksize > len) {
523385a6373Skrw 		log_warnx("%s: expecting at least %d bytes; got %d",
524c714dadcShenning 		    dhcp_options[code].name, hunksize, len);
5252f18daabSkrw 		goto done;
5269a2590e5Sderaadt 	}
527d22f105fSkrw 	/* Check for too many bytes. */
5282f18daabSkrw 	if (numhunk == -1 && hunksize < len) {
529385a6373Skrw 		log_warnx("%s: expecting only %d bytes: got %d",
53028f2359aSkrw 		    dhcp_options[code].name, hunksize, len);
5312f18daabSkrw 		goto done;
5322f18daabSkrw 	}
5339a2590e5Sderaadt 
5349a2590e5Sderaadt 	/* If this is an array, compute its size. */
5359a2590e5Sderaadt 	if (!numhunk)
5369a2590e5Sderaadt 		numhunk = len / hunksize;
5379a2590e5Sderaadt 	/* See if we got an exact number of hunks. */
5382f18daabSkrw 	if (numhunk > 0 && numhunk * hunksize != len) {
539385a6373Skrw 		log_warnx("%s: expecting %d bytes: got %d",
5402f18daabSkrw 		    dhcp_options[code].name, numhunk * hunksize, len);
5412f18daabSkrw 		goto done;
5422f18daabSkrw 	}
5439a2590e5Sderaadt 
5449a2590e5Sderaadt 	/* A one-hunk array prints the same as a single hunk. */
5459a2590e5Sderaadt 	if (numhunk < 0)
5469a2590e5Sderaadt 		numhunk = 1;
5479a2590e5Sderaadt 
5489a2590e5Sderaadt 	/* Cycle through the array (or hunk) printing the data. */
5499a2590e5Sderaadt 	for (i = 0; i < numhunk; i++) {
5509a2590e5Sderaadt 		for (j = 0; j < numelem; j++) {
5519a2590e5Sderaadt 			switch (fmtbuf[j]) {
5529a2590e5Sderaadt 			case 't':
553bee06f07Skrw 				buf = pretty_print_string(dp, len, emit_punct);
554bee06f07Skrw 				if (buf == NULL)
555bee06f07Skrw 					opcount = -1;
556bee06f07Skrw 				else
557bee06f07Skrw 					opcount = strlcat(op, buf, opleft);
5589a2590e5Sderaadt 				break;
5599a2590e5Sderaadt 			case 'I':
560e95625edSkrw 				memcpy(&foo.s_addr, dp, sizeof(foo.s_addr));
561f3a8c5fdSkrw 				opcount = snprintf(op, opleft, "%s",
562f3a8c5fdSkrw 				    inet_ntoa(foo));
563e95625edSkrw 				dp += sizeof(foo.s_addr);
5649a2590e5Sderaadt 				break;
5659a2590e5Sderaadt 			case 'l':
566bce09e58Skrw 				memcpy(&int32val, dp, sizeof(int32val));
567bce09e58Skrw 				opcount = snprintf(op, opleft, "%d",
568bce09e58Skrw 				    ntohl(int32val));
569bce09e58Skrw 				dp += sizeof(int32val);
5709a2590e5Sderaadt 				break;
5719a2590e5Sderaadt 			case 'L':
572bce09e58Skrw 				memcpy(&uint32val, dp, sizeof(uint32val));
573bce09e58Skrw 				opcount = snprintf(op, opleft, "%u",
574bce09e58Skrw 				    ntohl(uint32val));
575bce09e58Skrw 				dp += sizeof(uint32val);
5769a2590e5Sderaadt 				break;
5779a2590e5Sderaadt 			case 'S':
578bce09e58Skrw 				memcpy(&uint16val, dp, sizeof(uint16val));
579bce09e58Skrw 				opcount = snprintf(op, opleft, "%hu",
580bce09e58Skrw 				    ntohs(uint16val));
581bce09e58Skrw 				dp += sizeof(uint16val);
5829a2590e5Sderaadt 				break;
5839a2590e5Sderaadt 			case 'B':
584221bd6c0Skrw 				opcount = snprintf(op, opleft, "%u", *dp);
585de3ca9dbSkrw 				dp++;
5869a2590e5Sderaadt 				break;
587920d03efSkrw 			case 'X':
588de3ca9dbSkrw 				opcount = snprintf(op, opleft, "%x", *dp);
589de3ca9dbSkrw 				dp++;
5909a2590e5Sderaadt 				break;
5919a2590e5Sderaadt 			case 'f':
592f3a8c5fdSkrw 				opcount = snprintf(op, opleft, "%s",
593f3a8c5fdSkrw 				    *dp ? "true" : "false");
594de3ca9dbSkrw 				dp++;
5959a2590e5Sderaadt 				break;
5969a2590e5Sderaadt 			default:
597833082e5Skrw 				log_warnx("Unexpected format code %c",
598833082e5Skrw 				    fmtbuf[j]);
5999a2590e5Sderaadt 				goto toobig;
600f3a8c5fdSkrw 			}
601f3a8c5fdSkrw 			if (opcount >= opleft || opcount == -1)
602f3a8c5fdSkrw 				goto toobig;
603f3a8c5fdSkrw 			opleft -= opcount;
604f3a8c5fdSkrw 			op += opcount;
6059a2590e5Sderaadt 			if (j + 1 < numelem && comma != ':') {
606f3a8c5fdSkrw 				opcount = snprintf(op, opleft, " ");
607f3a8c5fdSkrw 				if (opcount >= opleft || opcount == -1)
608f3a8c5fdSkrw 					goto toobig;
609f3a8c5fdSkrw 				opleft -= opcount;
610f3a8c5fdSkrw 				op += opcount;
6119a2590e5Sderaadt 			}
6129a2590e5Sderaadt 		}
6139a2590e5Sderaadt 		if (i + 1 < numhunk) {
614f3a8c5fdSkrw 			opcount = snprintf(op, opleft, "%c", comma);
615f3a8c5fdSkrw 			if (opcount >= opleft || opcount == -1)
6169a2590e5Sderaadt 				goto toobig;
617f3a8c5fdSkrw 			opleft -= opcount;
618f3a8c5fdSkrw 			op += opcount;
619f3a8c5fdSkrw 		}
6209a2590e5Sderaadt 	}
6212f18daabSkrw 
6222f18daabSkrw done:
623c714dadcShenning 	return (optbuf);
6242f18daabSkrw 
6259a2590e5Sderaadt toobig:
6262f18daabSkrw 	memset(optbuf, 0, sizeof(optbuf));
6272f18daabSkrw 	return (optbuf);
6289a2590e5Sderaadt }
6299a2590e5Sderaadt 
630*b414edd1Skrw struct option_data *
631*b414edd1Skrw unpack_options(struct dhcp_packet *packet)
6329a2590e5Sderaadt {
633*b414edd1Skrw 	static struct option_data options[256];
634*b414edd1Skrw 	int i;
6359a2590e5Sderaadt 
636*b414edd1Skrw 	for (i = 0; i < 256; i++) {
637*b414edd1Skrw 		free(options[i].data);
638*b414edd1Skrw 		options[i].data = NULL;
639*b414edd1Skrw 		options[i].len = 0;
640*b414edd1Skrw 	}
64102e02bd5Skrw 
64202e02bd5Skrw 	if (memcmp(&packet->options, DHCP_OPTIONS_COOKIE, 4) == 0) {
64302e02bd5Skrw 		/* Parse the BOOTP/DHCP options field. */
644*b414edd1Skrw 		parse_option_buffer(options, &packet->options[4],
645*b414edd1Skrw 		    sizeof(packet->options) - 4);
64602e02bd5Skrw 
647*b414edd1Skrw 		/* DHCP packets can also use overload areas for options. */
648*b414edd1Skrw 		if (options[DHO_DHCP_MESSAGE_TYPE].data &&
64902e02bd5Skrw 		    options[DHO_DHCP_OPTION_OVERLOAD].data) {
65002e02bd5Skrw 			if (options[DHO_DHCP_OPTION_OVERLOAD].data[0] & 1)
651*b414edd1Skrw 				parse_option_buffer(options,
65202e02bd5Skrw 				    (unsigned char *)packet->file,
65302e02bd5Skrw 				    sizeof(packet->file));
654*b414edd1Skrw 			if (options[DHO_DHCP_OPTION_OVERLOAD].data[0] & 2)
655*b414edd1Skrw 				parse_option_buffer(options,
65602e02bd5Skrw 				    (unsigned char *)packet->sname,
65702e02bd5Skrw 				    sizeof(packet->sname));
65802e02bd5Skrw 		}
65902e02bd5Skrw 	}
66002e02bd5Skrw 
661*b414edd1Skrw 	return options;
6629a2590e5Sderaadt }
663