1*0f99c42cSderaadt /* $OpenBSD: portmap.c,v 1.25 2002/07/15 23:47:57 deraadt Exp $ */ 2456a2117Smillert 3df930be7Sderaadt /*- 49d791f75Sderaadt * Copyright (c) 1996, 1997 Theo de Raadt (OpenBSD). All rights reserved. 5df930be7Sderaadt * Copyright (c) 1990 The Regents of the University of California. 6df930be7Sderaadt * All rights reserved. 7df930be7Sderaadt * 8df930be7Sderaadt * Redistribution and use in source and binary forms, with or without 9df930be7Sderaadt * modification, are permitted provided that the following conditions 10df930be7Sderaadt * are met: 11df930be7Sderaadt * 1. Redistributions of source code must retain the above copyright 12df930be7Sderaadt * notice, this list of conditions and the following disclaimer. 13df930be7Sderaadt * 2. Redistributions in binary form must reproduce the above copyright 14df930be7Sderaadt * notice, this list of conditions and the following disclaimer in the 15df930be7Sderaadt * documentation and/or other materials provided with the distribution. 16df930be7Sderaadt * 3. All advertising materials mentioning features or use of this software 17df930be7Sderaadt * must display the following acknowledgement: 18df930be7Sderaadt * This product includes software developed by the University of 19df930be7Sderaadt * California, Berkeley and its contributors. 20df930be7Sderaadt * 4. Neither the name of the University nor the names of its contributors 21df930be7Sderaadt * may be used to endorse or promote products derived from this software 22df930be7Sderaadt * without specific prior written permission. 23df930be7Sderaadt * 24df930be7Sderaadt * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 25df930be7Sderaadt * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 26df930be7Sderaadt * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 27df930be7Sderaadt * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 28df930be7Sderaadt * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 29df930be7Sderaadt * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 30df930be7Sderaadt * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 31df930be7Sderaadt * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 32df930be7Sderaadt * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 33df930be7Sderaadt * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 34df930be7Sderaadt * SUCH DAMAGE. 35df930be7Sderaadt */ 36df930be7Sderaadt 37df930be7Sderaadt #ifndef lint 38df930be7Sderaadt char copyright[] = 39df930be7Sderaadt "@(#) Copyright (c) 1990 The Regents of the University of California.\n\ 40df930be7Sderaadt All rights reserved.\n"; 41df930be7Sderaadt #endif /* not lint */ 42df930be7Sderaadt 43df930be7Sderaadt #ifndef lint 44456a2117Smillert #if 0 45456a2117Smillert static char sccsid[] = "from: @(#)portmap.c 5.4 (Berkeley) 4/19/91"; 46456a2117Smillert #else 47*0f99c42cSderaadt static char rcsid[] = "$OpenBSD: portmap.c,v 1.25 2002/07/15 23:47:57 deraadt Exp $"; 48456a2117Smillert #endif 49df930be7Sderaadt #endif /* not lint */ 50df930be7Sderaadt 51df930be7Sderaadt /* 52df930be7Sderaadt @(#)portmap.c 2.3 88/08/11 4.0 RPCSRC 53df930be7Sderaadt static char sccsid[] = "@(#)portmap.c 1.32 87/08/06 Copyr 1984 Sun Micro"; 54df930be7Sderaadt */ 55df930be7Sderaadt 56df930be7Sderaadt /* 57df930be7Sderaadt * portmap.c, Implements the program,version to port number mapping for 58df930be7Sderaadt * rpc. 59df930be7Sderaadt */ 60df930be7Sderaadt 61df930be7Sderaadt /* 62df930be7Sderaadt * Sun RPC is a product of Sun Microsystems, Inc. and is provided for 63df930be7Sderaadt * unrestricted use provided that this legend is included on all tape 64df930be7Sderaadt * media and as a part of the software program in whole or part. Users 65df930be7Sderaadt * may copy or modify Sun RPC without charge, but are not authorized 66df930be7Sderaadt * to license or distribute it to anyone else except as part of a product or 67df930be7Sderaadt * program developed by the user. 68df930be7Sderaadt * 69df930be7Sderaadt * SUN RPC IS PROVIDED AS IS WITH NO WARRANTIES OF ANY KIND INCLUDING THE 70df930be7Sderaadt * WARRANTIES OF DESIGN, MERCHANTIBILITY AND FITNESS FOR A PARTICULAR 71df930be7Sderaadt * PURPOSE, OR ARISING FROM A COURSE OF DEALING, USAGE OR TRADE PRACTICE. 72df930be7Sderaadt * 73df930be7Sderaadt * Sun RPC is provided with no support and without any obligation on the 74df930be7Sderaadt * part of Sun Microsystems, Inc. to assist in its use, correction, 75df930be7Sderaadt * modification or enhancement. 76df930be7Sderaadt * 77df930be7Sderaadt * SUN MICROSYSTEMS, INC. SHALL HAVE NO LIABILITY WITH RESPECT TO THE 78df930be7Sderaadt * INFRINGEMENT OF COPYRIGHTS, TRADE SECRETS OR ANY PATENTS BY SUN RPC 79df930be7Sderaadt * OR ANY PART THEREOF. 80df930be7Sderaadt * 81df930be7Sderaadt * In no event will Sun Microsystems, Inc. be liable for any lost revenue 82df930be7Sderaadt * or profits or other special, indirect and consequential damages, even if 83df930be7Sderaadt * Sun has been advised of the possibility of such damages. 84df930be7Sderaadt * 85df930be7Sderaadt * Sun Microsystems, Inc. 86df930be7Sderaadt * 2550 Garcia Avenue 87df930be7Sderaadt * Mountain View, California 94043 88df930be7Sderaadt */ 89df930be7Sderaadt 90df930be7Sderaadt #include <rpc/rpc.h> 91df930be7Sderaadt #include <rpc/pmap_prot.h> 92df930be7Sderaadt #include <stdio.h> 93df930be7Sderaadt #include <stdlib.h> 94df930be7Sderaadt #include <string.h> 95df930be7Sderaadt #include <syslog.h> 96df930be7Sderaadt #include <unistd.h> 97df930be7Sderaadt #include <netdb.h> 9846aa5dceSderaadt #include <pwd.h> 99df930be7Sderaadt #include <sys/socket.h> 100df930be7Sderaadt #include <sys/ioctl.h> 101df930be7Sderaadt #include <sys/wait.h> 102df930be7Sderaadt #include <sys/signal.h> 103df930be7Sderaadt #include <sys/resource.h> 10477baebbfSderaadt #include <rpcsvc/nfs_prot.h> 105d91d7659Sderaadt #include <arpa/inet.h> 106df930be7Sderaadt 107c72b5b24Smillert void reg_service(struct svc_req *, SVCXPRT *); 108c72b5b24Smillert void reap(void); 109c72b5b24Smillert void callit(struct svc_req *, SVCXPRT *); 110c72b5b24Smillert int check_callit(struct sockaddr_in *, u_long, u_long, u_long); 111df930be7Sderaadt 112df930be7Sderaadt struct pmaplist *pmaplist; 113df930be7Sderaadt int debugging = 0; 114df930be7Sderaadt extern int errno; 115df930be7Sderaadt 11677baebbfSderaadt SVCXPRT *ludpxprt, *ltcpxprt; 11777baebbfSderaadt 118d91d7659Sderaadt int 11946aa5dceSderaadt main(int argc, char *argv[]) 120df930be7Sderaadt { 12146aa5dceSderaadt int sock, lsock, c, on = 1, len = sizeof(struct sockaddr_in); 12277baebbfSderaadt struct sockaddr_in addr, laddr; 1230ac0d02eSmpech struct pmaplist *pml; 124*0f99c42cSderaadt struct passwd *pw; 12546aa5dceSderaadt SVCXPRT *xprt; 126df930be7Sderaadt 12772799b18Smillert while ((c = getopt(argc, argv, "d")) != -1) { 128df930be7Sderaadt switch (c) { 129df930be7Sderaadt 130df930be7Sderaadt case 'd': 131df930be7Sderaadt debugging = 1; 132df930be7Sderaadt break; 133df930be7Sderaadt 134df930be7Sderaadt default: 135df930be7Sderaadt (void) fprintf(stderr, "usage: %s [-d]\n", argv[0]); 136df930be7Sderaadt exit(1); 137df930be7Sderaadt } 138df930be7Sderaadt } 139df930be7Sderaadt 140df930be7Sderaadt if (!debugging && daemon(0, 0)) { 141df930be7Sderaadt (void) fprintf(stderr, "portmap: fork: %s", strerror(errno)); 142df930be7Sderaadt exit(1); 143df930be7Sderaadt } 144df930be7Sderaadt 145df930be7Sderaadt openlog("portmap", debugging ? LOG_PID | LOG_PERROR : LOG_PID, 146df930be7Sderaadt LOG_DAEMON); 147df930be7Sderaadt 14877baebbfSderaadt bzero((char *)&addr, sizeof addr); 14977baebbfSderaadt addr.sin_addr.s_addr = 0; 15077baebbfSderaadt addr.sin_family = AF_INET; 15177baebbfSderaadt addr.sin_addr.s_addr = htonl(INADDR_ANY); 15277baebbfSderaadt addr.sin_port = htons(PMAPPORT); 15377baebbfSderaadt 15477baebbfSderaadt bzero((char *)&laddr, sizeof laddr); 15577baebbfSderaadt laddr.sin_addr.s_addr = 0; 15677baebbfSderaadt laddr.sin_family = AF_INET; 15777baebbfSderaadt laddr.sin_addr.s_addr = htonl(INADDR_LOOPBACK); 15877baebbfSderaadt laddr.sin_port = htons(PMAPPORT); 15977baebbfSderaadt 160df930be7Sderaadt if ((sock = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) { 161df930be7Sderaadt syslog(LOG_ERR, "cannot create udp socket: %m"); 162df930be7Sderaadt exit(1); 163df930be7Sderaadt } 164afeed3b4Sderaadt setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 165df930be7Sderaadt if (bind(sock, (struct sockaddr *)&addr, len) != 0) { 166df930be7Sderaadt syslog(LOG_ERR, "cannot bind udp: %m"); 167df930be7Sderaadt exit(1); 168df930be7Sderaadt } 169df930be7Sderaadt 170df930be7Sderaadt if ((xprt = svcudp_create(sock)) == (SVCXPRT *)NULL) { 171df930be7Sderaadt syslog(LOG_ERR, "couldn't do udp_create"); 172df930be7Sderaadt exit(1); 173df930be7Sderaadt } 17477baebbfSderaadt 17577baebbfSderaadt if ((lsock = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) { 17677baebbfSderaadt syslog(LOG_ERR, "cannot create udp socket: %m"); 17777baebbfSderaadt exit(1); 17877baebbfSderaadt } 17977baebbfSderaadt setsockopt(lsock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 18077baebbfSderaadt if (bind(lsock, (struct sockaddr *)&laddr, len) != 0) { 1817e963911Smickey syslog(LOG_ERR, "cannot bind local udp: %m"); 18277baebbfSderaadt exit(1); 18377baebbfSderaadt } 18477baebbfSderaadt 18577baebbfSderaadt if ((ludpxprt = svcudp_create(lsock)) == (SVCXPRT *)NULL) { 18677baebbfSderaadt syslog(LOG_ERR, "couldn't do udp_create"); 18777baebbfSderaadt exit(1); 18877baebbfSderaadt } 18977baebbfSderaadt 190df930be7Sderaadt /* make an entry for ourself */ 191df930be7Sderaadt pml = (struct pmaplist *)malloc((u_int)sizeof(struct pmaplist)); 192acfba6e6Sderaadt if (pml == NULL) { 193acfba6e6Sderaadt syslog(LOG_ERR, "out of memory"); 194acfba6e6Sderaadt exit(1); 195acfba6e6Sderaadt } 196df930be7Sderaadt pml->pml_next = 0; 197df930be7Sderaadt pml->pml_map.pm_prog = PMAPPROG; 198df930be7Sderaadt pml->pml_map.pm_vers = PMAPVERS; 199df930be7Sderaadt pml->pml_map.pm_prot = IPPROTO_UDP; 200df930be7Sderaadt pml->pml_map.pm_port = PMAPPORT; 201df930be7Sderaadt pmaplist = pml; 202df930be7Sderaadt 203df930be7Sderaadt if ((sock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0) { 204df930be7Sderaadt syslog(LOG_ERR, "cannot create tcp socket: %m"); 205df930be7Sderaadt exit(1); 206df930be7Sderaadt } 207afeed3b4Sderaadt setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 208df930be7Sderaadt if (bind(sock, (struct sockaddr *)&addr, len) != 0) { 209da52f073Sderaadt syslog(LOG_ERR, "cannot bind tcp: %m"); 210df930be7Sderaadt exit(1); 211df930be7Sderaadt } 212df930be7Sderaadt if ((xprt = svctcp_create(sock, RPCSMALLMSGSIZE, RPCSMALLMSGSIZE)) 213df930be7Sderaadt == (SVCXPRT *)NULL) { 214df930be7Sderaadt syslog(LOG_ERR, "couldn't do tcp_create"); 215df930be7Sderaadt exit(1); 216df930be7Sderaadt } 21777baebbfSderaadt 21877baebbfSderaadt if ((lsock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0) { 21977baebbfSderaadt syslog(LOG_ERR, "cannot create tcp socket: %m"); 22077baebbfSderaadt exit(1); 22177baebbfSderaadt } 22277baebbfSderaadt setsockopt(lsock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 22377baebbfSderaadt if (bind(lsock, (struct sockaddr *)&laddr, len) != 0) { 224da52f073Sderaadt syslog(LOG_ERR, "cannot bind tcp: %m"); 22577baebbfSderaadt exit(1); 22677baebbfSderaadt } 22777baebbfSderaadt if ((ltcpxprt = svctcp_create(lsock, RPCSMALLMSGSIZE, 22877baebbfSderaadt RPCSMALLMSGSIZE)) == (SVCXPRT *)NULL) { 22977baebbfSderaadt syslog(LOG_ERR, "couldn't do tcp_create"); 23077baebbfSderaadt exit(1); 23177baebbfSderaadt } 23277baebbfSderaadt 233df930be7Sderaadt /* make an entry for ourself */ 234df930be7Sderaadt pml = (struct pmaplist *)malloc((u_int)sizeof(struct pmaplist)); 235acfba6e6Sderaadt if (pml == NULL) { 236acfba6e6Sderaadt syslog(LOG_ERR, "out of memory"); 237acfba6e6Sderaadt exit(1); 238acfba6e6Sderaadt } 239df930be7Sderaadt pml->pml_map.pm_prog = PMAPPROG; 240df930be7Sderaadt pml->pml_map.pm_vers = PMAPVERS; 241df930be7Sderaadt pml->pml_map.pm_prot = IPPROTO_TCP; 242df930be7Sderaadt pml->pml_map.pm_port = PMAPPORT; 243df930be7Sderaadt pml->pml_next = pmaplist; 244df930be7Sderaadt pmaplist = pml; 245df930be7Sderaadt 246*0f99c42cSderaadt pw = getpwnam("_portmap"); 247*0f99c42cSderaadt if (!pw) 248*0f99c42cSderaadt pw = getpwnam("nobody"); 249*0f99c42cSderaadt if (chroot("/var/empty") == -1) { 250*0f99c42cSderaadt syslog(LOG_ERR, "cannot chdir to /var/empty."); 251*0f99c42cSderaadt exit(1); 252*0f99c42cSderaadt } 253*0f99c42cSderaadt chdir("/"); 254*0f99c42cSderaadt if (pw) { 255*0f99c42cSderaadt setgroups(1, &pw->pw_gid); 256*0f99c42cSderaadt setegid(pw->pw_gid); 257*0f99c42cSderaadt setgid(pw->pw_gid); 258*0f99c42cSderaadt seteuid(pw->pw_uid); 259*0f99c42cSderaadt setuid(pw->pw_uid); 260*0f99c42cSderaadt } 261*0f99c42cSderaadt 262df930be7Sderaadt (void)svc_register(xprt, PMAPPROG, PMAPVERS, reg_service, FALSE); 263df930be7Sderaadt 264d91d7659Sderaadt (void)signal(SIGCHLD, (void (*)())reap); 265df930be7Sderaadt svc_run(); 266da52f073Sderaadt syslog(LOG_ERR, "svc_run returned unexpectedly"); 267df930be7Sderaadt abort(); 268df930be7Sderaadt } 269df930be7Sderaadt 270df930be7Sderaadt #ifndef lint 271df930be7Sderaadt /* need to override perror calls in rpc library */ 272df930be7Sderaadt void 27346aa5dceSderaadt perror(const char *what) 274df930be7Sderaadt { 275df930be7Sderaadt 276df930be7Sderaadt syslog(LOG_ERR, "%s: %m", what); 277df930be7Sderaadt } 278df930be7Sderaadt #endif 279df930be7Sderaadt 2803aef48d5Sderaadt struct pmaplist * 28146aa5dceSderaadt find_service(u_long prog, u_long vers, u_long prot) 282df930be7Sderaadt { 2830ac0d02eSmpech struct pmaplist *hit = NULL; 2840ac0d02eSmpech struct pmaplist *pml; 285df930be7Sderaadt 286df930be7Sderaadt for (pml = pmaplist; pml != NULL; pml = pml->pml_next) { 287df930be7Sderaadt if ((pml->pml_map.pm_prog != prog) || 288df930be7Sderaadt (pml->pml_map.pm_prot != prot)) 289df930be7Sderaadt continue; 290df930be7Sderaadt hit = pml; 291df930be7Sderaadt if (pml->pml_map.pm_vers == vers) 292df930be7Sderaadt break; 293df930be7Sderaadt } 294df930be7Sderaadt return (hit); 295df930be7Sderaadt } 296df930be7Sderaadt 297df930be7Sderaadt /* 298df930be7Sderaadt * 1 OK, 0 not 299df930be7Sderaadt */ 300df930be7Sderaadt void 30146aa5dceSderaadt reg_service(struct svc_req *rqstp, SVCXPRT *xprt) 302df930be7Sderaadt { 303df930be7Sderaadt struct pmap reg; 304df930be7Sderaadt struct pmaplist *pml, *prevpml, *fnd; 30577baebbfSderaadt struct sockaddr_in *fromsin; 30677baebbfSderaadt long ans = 0, port; 307df930be7Sderaadt caddr_t t; 308df930be7Sderaadt 30977baebbfSderaadt fromsin = svc_getcaller(xprt); 31077baebbfSderaadt 311df930be7Sderaadt if (debugging) 312df930be7Sderaadt (void) fprintf(stderr, "server: about to do a switch\n"); 313df930be7Sderaadt switch (rqstp->rq_proc) { 314df930be7Sderaadt 315df930be7Sderaadt case PMAPPROC_NULL: 316df930be7Sderaadt /* 317df930be7Sderaadt * Null proc call 318df930be7Sderaadt */ 319df930be7Sderaadt if (!svc_sendreply(xprt, xdr_void, (caddr_t)0) && debugging) { 320df930be7Sderaadt abort(); 321df930be7Sderaadt } 322df930be7Sderaadt break; 323df930be7Sderaadt 324df930be7Sderaadt case PMAPPROC_SET: 325df930be7Sderaadt /* 326df930be7Sderaadt * Set a program,version to port mapping 327df930be7Sderaadt */ 32877baebbfSderaadt if (xprt != ltcpxprt && xprt != ludpxprt) { 32977baebbfSderaadt syslog(LOG_WARNING, 33077baebbfSderaadt "non-local set attempt (might be from %s)", 3319430a6aeSderaadt inet_ntoa(fromsin->sin_addr)); 33277baebbfSderaadt svcerr_noproc(xprt); 33377baebbfSderaadt return; 33477baebbfSderaadt } 33560cef36bSderaadt if (!svc_getargs(xprt, xdr_pmap, (caddr_t)®)) { 336df930be7Sderaadt svcerr_decode(xprt); 33760cef36bSderaadt break; 33860cef36bSderaadt } 3393aef48d5Sderaadt 340df930be7Sderaadt /* 341df930be7Sderaadt * check to see if already used 342df930be7Sderaadt * find_service returns a hit even if 343df930be7Sderaadt * the versions don't match, so check for it 344df930be7Sderaadt */ 345df930be7Sderaadt fnd = find_service(reg.pm_prog, reg.pm_vers, reg.pm_prot); 346df930be7Sderaadt if (fnd && fnd->pml_map.pm_vers == reg.pm_vers) { 34777baebbfSderaadt if (fnd->pml_map.pm_port == reg.pm_port) 348df930be7Sderaadt ans = 1; 349df930be7Sderaadt goto done; 350df930be7Sderaadt } 35177baebbfSderaadt 352a982d679Sderaadt if (debugging) 35331cea007Spvalchev printf("set: prog %lu vers %lu port %lu\n", 354a982d679Sderaadt reg.pm_prog, reg.pm_vers, reg.pm_port); 355a982d679Sderaadt 356a982d679Sderaadt if (reg.pm_port & ~0xffff) 357a982d679Sderaadt goto done; 358a982d679Sderaadt 359a982d679Sderaadt /* 360a982d679Sderaadt * only permit localhost root to create 361a982d679Sderaadt * mappings pointing at sensitive ports 362a982d679Sderaadt */ 363a982d679Sderaadt if ((reg.pm_port < IPPORT_RESERVED || 364a982d679Sderaadt reg.pm_port == NFS_PORT) && 36577baebbfSderaadt htons(fromsin->sin_port) >= IPPORT_RESERVED) { 366a982d679Sderaadt syslog(LOG_WARNING, 367a982d679Sderaadt "resvport set attempt by non-root"); 368df930be7Sderaadt goto done; 369df930be7Sderaadt } 37077baebbfSderaadt 371df930be7Sderaadt /* 372df930be7Sderaadt * add to END of list 373df930be7Sderaadt */ 37460cef36bSderaadt pml = (struct pmaplist *)malloc(sizeof(struct pmaplist)); 375acfba6e6Sderaadt if (pml == NULL) { 376acfba6e6Sderaadt syslog(LOG_ERR, "out of memory"); 377acfba6e6Sderaadt svcerr_systemerr(xprt); 378acfba6e6Sderaadt return; 379acfba6e6Sderaadt } 380acfba6e6Sderaadt 381df930be7Sderaadt pml->pml_map = reg; 382df930be7Sderaadt pml->pml_next = 0; 383df930be7Sderaadt if (pmaplist == 0) { 384df930be7Sderaadt pmaplist = pml; 385df930be7Sderaadt } else { 386df930be7Sderaadt for (fnd = pmaplist; fnd->pml_next != 0; 387df930be7Sderaadt fnd = fnd->pml_next); 388df930be7Sderaadt fnd->pml_next = pml; 389df930be7Sderaadt } 390df930be7Sderaadt ans = 1; 391df930be7Sderaadt done: 392df930be7Sderaadt if ((!svc_sendreply(xprt, xdr_long, (caddr_t)&ans)) && 393df930be7Sderaadt debugging) { 394df930be7Sderaadt (void) fprintf(stderr, "svc_sendreply\n"); 395df930be7Sderaadt abort(); 396df930be7Sderaadt } 397df930be7Sderaadt break; 398df930be7Sderaadt 399df930be7Sderaadt case PMAPPROC_UNSET: 400df930be7Sderaadt /* 401df930be7Sderaadt * Remove a program,version to port mapping. 402df930be7Sderaadt */ 40377baebbfSderaadt if (xprt != ltcpxprt && xprt != ludpxprt) { 40477baebbfSderaadt syslog(LOG_WARNING, 40577baebbfSderaadt "non-local unset attempt (might be from %s)", 4069430a6aeSderaadt inet_ntoa(fromsin->sin_addr)); 40777baebbfSderaadt svcerr_noproc(xprt); 40877baebbfSderaadt return; 40977baebbfSderaadt } 41077baebbfSderaadt if (!svc_getargs(xprt, xdr_pmap, (caddr_t)®)) { 411df930be7Sderaadt svcerr_decode(xprt); 41277baebbfSderaadt break; 41377baebbfSderaadt } 414df930be7Sderaadt for (prevpml = NULL, pml = pmaplist; pml != NULL; ) { 415df930be7Sderaadt if ((pml->pml_map.pm_prog != reg.pm_prog) || 416df930be7Sderaadt (pml->pml_map.pm_vers != reg.pm_vers)) { 417df930be7Sderaadt /* both pml & prevpml move forwards */ 418df930be7Sderaadt prevpml = pml; 419df930be7Sderaadt pml = pml->pml_next; 420df930be7Sderaadt continue; 421df930be7Sderaadt } 42277baebbfSderaadt if ((pml->pml_map.pm_port < IPPORT_RESERVED || 42377baebbfSderaadt pml->pml_map.pm_port == NFS_PORT) && 42477baebbfSderaadt htons(fromsin->sin_port) >= IPPORT_RESERVED) { 42577baebbfSderaadt syslog(LOG_WARNING, 42677baebbfSderaadt "resvport unset attempt by non-root"); 42777baebbfSderaadt break; 42877baebbfSderaadt } 42977baebbfSderaadt 430df930be7Sderaadt /* found it; pml moves forward, prevpml stays */ 431df930be7Sderaadt ans = 1; 432df930be7Sderaadt t = (caddr_t)pml; 433df930be7Sderaadt pml = pml->pml_next; 434df930be7Sderaadt if (prevpml == NULL) 435df930be7Sderaadt pmaplist = pml; 436df930be7Sderaadt else 437df930be7Sderaadt prevpml->pml_next = pml; 438df930be7Sderaadt free(t); 439df930be7Sderaadt } 440df930be7Sderaadt if ((!svc_sendreply(xprt, xdr_long, (caddr_t)&ans)) && 441df930be7Sderaadt debugging) { 44260cef36bSderaadt fprintf(stderr, "svc_sendreply\n"); 443df930be7Sderaadt abort(); 444df930be7Sderaadt } 445df930be7Sderaadt break; 446df930be7Sderaadt 447df930be7Sderaadt case PMAPPROC_GETPORT: 448df930be7Sderaadt /* 449df930be7Sderaadt * Lookup the mapping for a program,version and return its port 450df930be7Sderaadt */ 45160cef36bSderaadt if (!svc_getargs(xprt, xdr_pmap, (caddr_t)®)) { 452df930be7Sderaadt svcerr_decode(xprt); 45360cef36bSderaadt break; 45460cef36bSderaadt } 455df930be7Sderaadt fnd = find_service(reg.pm_prog, reg.pm_vers, reg.pm_prot); 456df930be7Sderaadt if (fnd) 457df930be7Sderaadt port = fnd->pml_map.pm_port; 458df930be7Sderaadt else 459df930be7Sderaadt port = 0; 460df930be7Sderaadt if ((!svc_sendreply(xprt, xdr_long, (caddr_t)&port)) && 461df930be7Sderaadt debugging) { 46260cef36bSderaadt fprintf(stderr, "svc_sendreply\n"); 463df930be7Sderaadt abort(); 464df930be7Sderaadt } 465df930be7Sderaadt break; 466df930be7Sderaadt 467df930be7Sderaadt case PMAPPROC_DUMP: 468df930be7Sderaadt /* 469df930be7Sderaadt * Return the current set of mapped program,version 470df930be7Sderaadt */ 47160cef36bSderaadt if (!svc_getargs(xprt, xdr_void, NULL)) { 472df930be7Sderaadt svcerr_decode(xprt); 47360cef36bSderaadt break; 47460cef36bSderaadt } 47560cef36bSderaadt if (!svc_sendreply(xprt, xdr_pmaplist, (caddr_t)&pmaplist) && 47660cef36bSderaadt debugging) { 47760cef36bSderaadt fprintf(stderr, "svc_sendreply\n"); 478df930be7Sderaadt abort(); 479df930be7Sderaadt } 480df930be7Sderaadt break; 481df930be7Sderaadt 482df930be7Sderaadt case PMAPPROC_CALLIT: 483df930be7Sderaadt /* 484df930be7Sderaadt * Calls a procedure on the local machine. If the requested 485df930be7Sderaadt * procedure is not registered this procedure does not return 486df930be7Sderaadt * error information!! 487df930be7Sderaadt * This procedure is only supported on rpc/udp and calls via 488df930be7Sderaadt * rpc/udp. It passes null authentication parameters. 489df930be7Sderaadt */ 490df930be7Sderaadt callit(rqstp, xprt); 491df930be7Sderaadt break; 492df930be7Sderaadt 493df930be7Sderaadt default: 494df930be7Sderaadt svcerr_noproc(xprt); 495df930be7Sderaadt break; 496df930be7Sderaadt } 497df930be7Sderaadt } 498df930be7Sderaadt 499df930be7Sderaadt 500df930be7Sderaadt /* 501df930be7Sderaadt * Stuff for the rmtcall service 502df930be7Sderaadt */ 503df930be7Sderaadt #define ARGSIZE 9000 504df930be7Sderaadt 505df930be7Sderaadt struct encap_parms { 506df930be7Sderaadt u_int arglen; 507df930be7Sderaadt char *args; 508df930be7Sderaadt }; 509df930be7Sderaadt 510df930be7Sderaadt static bool_t 51146aa5dceSderaadt xdr_encap_parms(XDR *xdrs, struct encap_parms *epp) 512df930be7Sderaadt { 513df930be7Sderaadt 514df930be7Sderaadt return (xdr_bytes(xdrs, &(epp->args), &(epp->arglen), ARGSIZE)); 515df930be7Sderaadt } 516df930be7Sderaadt 517df930be7Sderaadt struct rmtcallargs { 518df930be7Sderaadt u_long rmt_prog; 519df930be7Sderaadt u_long rmt_vers; 520df930be7Sderaadt u_long rmt_port; 521df930be7Sderaadt u_long rmt_proc; 522df930be7Sderaadt struct encap_parms rmt_args; 523df930be7Sderaadt }; 524df930be7Sderaadt 525df930be7Sderaadt static bool_t 52646aa5dceSderaadt xdr_rmtcall_args(XDR *xdrs, struct rmtcallargs *cap) 527df930be7Sderaadt { 528df930be7Sderaadt 529df930be7Sderaadt /* does not get a port number */ 530df930be7Sderaadt if (xdr_u_long(xdrs, &(cap->rmt_prog)) && 531df930be7Sderaadt xdr_u_long(xdrs, &(cap->rmt_vers)) && 532df930be7Sderaadt xdr_u_long(xdrs, &(cap->rmt_proc))) { 533df930be7Sderaadt return (xdr_encap_parms(xdrs, &(cap->rmt_args))); 534df930be7Sderaadt } 535df930be7Sderaadt return (FALSE); 536df930be7Sderaadt } 537df930be7Sderaadt 538df930be7Sderaadt static bool_t 53946aa5dceSderaadt xdr_rmtcall_result(XDR *xdrs, struct rmtcallargs *cap) 540df930be7Sderaadt { 541df930be7Sderaadt if (xdr_u_long(xdrs, &(cap->rmt_port))) 542df930be7Sderaadt return (xdr_encap_parms(xdrs, &(cap->rmt_args))); 543df930be7Sderaadt return (FALSE); 544df930be7Sderaadt } 545df930be7Sderaadt 546df930be7Sderaadt /* 547df930be7Sderaadt * only worries about the struct encap_parms part of struct rmtcallargs. 548df930be7Sderaadt * The arglen must already be set!! 549df930be7Sderaadt */ 550df930be7Sderaadt static bool_t 55146aa5dceSderaadt xdr_opaque_parms(XDR *xdrs, struct rmtcallargs *cap) 552df930be7Sderaadt { 553df930be7Sderaadt 554df930be7Sderaadt return (xdr_opaque(xdrs, cap->rmt_args.args, cap->rmt_args.arglen)); 555df930be7Sderaadt } 556df930be7Sderaadt 557df930be7Sderaadt /* 558df930be7Sderaadt * This routine finds and sets the length of incoming opaque paraters 559df930be7Sderaadt * and then calls xdr_opaque_parms. 560df930be7Sderaadt */ 561df930be7Sderaadt static bool_t 56246aa5dceSderaadt xdr_len_opaque_parms(XDR *xdrs, struct rmtcallargs *cap) 563df930be7Sderaadt { 5640ac0d02eSmpech u_int beginpos, lowpos, highpos, currpos, pos; 565df930be7Sderaadt 566df930be7Sderaadt beginpos = lowpos = pos = xdr_getpos(xdrs); 567df930be7Sderaadt highpos = lowpos + ARGSIZE; 568df930be7Sderaadt while ((int)(highpos - lowpos) >= 0) { 569df930be7Sderaadt currpos = (lowpos + highpos) / 2; 570df930be7Sderaadt if (xdr_setpos(xdrs, currpos)) { 571df930be7Sderaadt pos = currpos; 572df930be7Sderaadt lowpos = currpos + 1; 573df930be7Sderaadt } else { 574df930be7Sderaadt highpos = currpos - 1; 575df930be7Sderaadt } 576df930be7Sderaadt } 577df930be7Sderaadt xdr_setpos(xdrs, beginpos); 578df930be7Sderaadt cap->rmt_args.arglen = pos - beginpos; 579df930be7Sderaadt return (xdr_opaque_parms(xdrs, cap)); 580df930be7Sderaadt } 581df930be7Sderaadt 582df930be7Sderaadt /* 583df930be7Sderaadt * Call a remote procedure service 584df930be7Sderaadt * This procedure is very quiet when things go wrong. 585df930be7Sderaadt * The proc is written to support broadcast rpc. In the broadcast case, 586df930be7Sderaadt * a machine should shut-up instead of complain, less the requestor be 587df930be7Sderaadt * overrun with complaints at the expense of not hearing a valid reply ... 588df930be7Sderaadt * 589df930be7Sderaadt * This now forks so that the program & process that it calls can call 590df930be7Sderaadt * back to the portmapper. 591df930be7Sderaadt */ 592d91d7659Sderaadt void 59346aa5dceSderaadt callit(struct svc_req *rqstp, SVCXPRT *xprt) 594df930be7Sderaadt { 595df930be7Sderaadt struct rmtcallargs a; 596df930be7Sderaadt struct pmaplist *pml; 597df930be7Sderaadt u_short port; 598df930be7Sderaadt struct sockaddr_in me; 59948822293Sderaadt pid_t pid; 60048822293Sderaadt int so = -1, dontblock = 1; 601df930be7Sderaadt CLIENT *client; 602df930be7Sderaadt struct authunix_parms *au = (struct authunix_parms *)rqstp->rq_clntcred; 603df930be7Sderaadt struct timeval timeout; 604df930be7Sderaadt char buf[ARGSIZE]; 605df930be7Sderaadt 606df930be7Sderaadt timeout.tv_sec = 5; 607df930be7Sderaadt timeout.tv_usec = 0; 608df930be7Sderaadt a.rmt_args.args = buf; 609df930be7Sderaadt if (!svc_getargs(xprt, xdr_rmtcall_args, (caddr_t)&a)) 610df930be7Sderaadt return; 611f94670b8Sderaadt if (!check_callit(svc_getcaller(xprt), rqstp->rq_proc, 612f94670b8Sderaadt a.rmt_prog, a.rmt_proc)) 613f94670b8Sderaadt return; 614df930be7Sderaadt if ((pml = find_service(a.rmt_prog, a.rmt_vers, 615df930be7Sderaadt (u_long)IPPROTO_UDP)) == NULL) 616df930be7Sderaadt return; 61777baebbfSderaadt 618df930be7Sderaadt /* 619df930be7Sderaadt * fork a child to do the work. Parent immediately returns. 620df930be7Sderaadt * Child exits upon completion. 621df930be7Sderaadt */ 622df930be7Sderaadt if ((pid = fork()) != 0) { 623df930be7Sderaadt if (pid == -1) 624df930be7Sderaadt syslog(LOG_ERR, "CALLIT (prog %lu): fork: %m", 625df930be7Sderaadt a.rmt_prog); 626df930be7Sderaadt return; 627df930be7Sderaadt } 628df930be7Sderaadt port = pml->pml_map.pm_port; 629df930be7Sderaadt get_myaddress(&me); 630df930be7Sderaadt me.sin_port = htons(port); 631df930be7Sderaadt 632df930be7Sderaadt /* Avoid implicit binding to reserved port by clntudp_create() */ 633df930be7Sderaadt so = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP); 634df930be7Sderaadt if (so == -1) 635df930be7Sderaadt exit(1); 636df930be7Sderaadt if (ioctl(so, FIONBIO, &dontblock) == -1) 637df930be7Sderaadt exit(1); 638df930be7Sderaadt 639df930be7Sderaadt client = clntudp_create(&me, a.rmt_prog, a.rmt_vers, timeout, &so); 640df930be7Sderaadt if (client != (CLIENT *)NULL) { 64177baebbfSderaadt if (rqstp->rq_cred.oa_flavor == AUTH_UNIX) 642df930be7Sderaadt client->cl_auth = authunix_create(au->aup_machname, 643df930be7Sderaadt au->aup_uid, au->aup_gid, au->aup_len, au->aup_gids); 644df930be7Sderaadt a.rmt_port = (u_long)port; 645df930be7Sderaadt if (clnt_call(client, a.rmt_proc, xdr_opaque_parms, &a, 64677baebbfSderaadt xdr_len_opaque_parms, &a, timeout) == RPC_SUCCESS) 647df930be7Sderaadt svc_sendreply(xprt, xdr_rmtcall_result, (caddr_t)&a); 648df930be7Sderaadt AUTH_DESTROY(client->cl_auth); 649df930be7Sderaadt clnt_destroy(client); 650df930be7Sderaadt } 651df930be7Sderaadt (void)close(so); 652df930be7Sderaadt exit(0); 653df930be7Sderaadt } 654df930be7Sderaadt 655df930be7Sderaadt void 656df930be7Sderaadt reap() 657df930be7Sderaadt { 658df930be7Sderaadt int save_errno = errno; 659df930be7Sderaadt 6607af3e1e5Sderaadt while (wait3(NULL, WNOHANG, NULL) > 0) 661df930be7Sderaadt ; 662df930be7Sderaadt errno = save_errno; 663df930be7Sderaadt } 664f94670b8Sderaadt 665f94670b8Sderaadt #define NFSPROG ((u_long) 100003) 666f94670b8Sderaadt #define MOUNTPROG ((u_long) 100005) 667f94670b8Sderaadt #define YPXPROG ((u_long) 100069) 668f94670b8Sderaadt #define YPPROG ((u_long) 100004) 669f94670b8Sderaadt #define YPPROC_DOMAIN_NONACK ((u_long) 2) 670f94670b8Sderaadt #define MOUNTPROC_MNT ((u_long) 1) 6719d791f75Sderaadt #define XXXPROC_NOP ((u_long) 0) 672f94670b8Sderaadt 673f94670b8Sderaadt int 67446aa5dceSderaadt check_callit(struct sockaddr_in *addr, u_long proc, u_long prog, 67546aa5dceSderaadt u_long aproc) 676f94670b8Sderaadt { 6779d791f75Sderaadt if ((prog == PMAPPROG && aproc != XXXPROC_NOP) || 6789d791f75Sderaadt (prog == NFSPROG && aproc != XXXPROC_NOP) || 6799d791f75Sderaadt (prog == YPXPROG && aproc != XXXPROC_NOP) || 680f94670b8Sderaadt (prog == MOUNTPROG && aproc == MOUNTPROC_MNT) || 681f94670b8Sderaadt (prog == YPPROG && aproc != YPPROC_DOMAIN_NONACK)) { 682f94670b8Sderaadt syslog(LOG_WARNING, 683f94670b8Sderaadt "callit prog %d aproc %d (might be from %s)", 684d91d7659Sderaadt (int)prog, (int)aproc, inet_ntoa(addr->sin_addr)); 685f94670b8Sderaadt return (FALSE); 686f94670b8Sderaadt } 687f94670b8Sderaadt return (TRUE); 688f94670b8Sderaadt } 689