1*a982d679Sderaadt /* $OpenBSD: portmap.c,v 1.18 2000/07/31 17:28:26 deraadt Exp $ */ 2456a2117Smillert 3df930be7Sderaadt /*- 49d791f75Sderaadt * Copyright (c) 1996, 1997 Theo de Raadt (OpenBSD). All rights reserved. 5df930be7Sderaadt * Copyright (c) 1990 The Regents of the University of California. 6df930be7Sderaadt * All rights reserved. 7df930be7Sderaadt * 8df930be7Sderaadt * Redistribution and use in source and binary forms, with or without 9df930be7Sderaadt * modification, are permitted provided that the following conditions 10df930be7Sderaadt * are met: 11df930be7Sderaadt * 1. Redistributions of source code must retain the above copyright 12df930be7Sderaadt * notice, this list of conditions and the following disclaimer. 13df930be7Sderaadt * 2. Redistributions in binary form must reproduce the above copyright 14df930be7Sderaadt * notice, this list of conditions and the following disclaimer in the 15df930be7Sderaadt * documentation and/or other materials provided with the distribution. 16df930be7Sderaadt * 3. All advertising materials mentioning features or use of this software 17df930be7Sderaadt * must display the following acknowledgement: 18df930be7Sderaadt * This product includes software developed by the University of 19df930be7Sderaadt * California, Berkeley and its contributors. 20df930be7Sderaadt * 4. Neither the name of the University nor the names of its contributors 21df930be7Sderaadt * may be used to endorse or promote products derived from this software 22df930be7Sderaadt * without specific prior written permission. 23df930be7Sderaadt * 24df930be7Sderaadt * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 25df930be7Sderaadt * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 26df930be7Sderaadt * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 27df930be7Sderaadt * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 28df930be7Sderaadt * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 29df930be7Sderaadt * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 30df930be7Sderaadt * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 31df930be7Sderaadt * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 32df930be7Sderaadt * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 33df930be7Sderaadt * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 34df930be7Sderaadt * SUCH DAMAGE. 35df930be7Sderaadt */ 36df930be7Sderaadt 37df930be7Sderaadt #ifndef lint 38df930be7Sderaadt char copyright[] = 39df930be7Sderaadt "@(#) Copyright (c) 1990 The Regents of the University of California.\n\ 40df930be7Sderaadt All rights reserved.\n"; 41df930be7Sderaadt #endif /* not lint */ 42df930be7Sderaadt 43df930be7Sderaadt #ifndef lint 44456a2117Smillert #if 0 45456a2117Smillert static char sccsid[] = "from: @(#)portmap.c 5.4 (Berkeley) 4/19/91"; 46456a2117Smillert #else 47*a982d679Sderaadt static char rcsid[] = "$OpenBSD: portmap.c,v 1.18 2000/07/31 17:28:26 deraadt Exp $"; 48456a2117Smillert #endif 49df930be7Sderaadt #endif /* not lint */ 50df930be7Sderaadt 51df930be7Sderaadt /* 52df930be7Sderaadt @(#)portmap.c 2.3 88/08/11 4.0 RPCSRC 53df930be7Sderaadt static char sccsid[] = "@(#)portmap.c 1.32 87/08/06 Copyr 1984 Sun Micro"; 54df930be7Sderaadt */ 55df930be7Sderaadt 56df930be7Sderaadt /* 57df930be7Sderaadt * portmap.c, Implements the program,version to port number mapping for 58df930be7Sderaadt * rpc. 59df930be7Sderaadt */ 60df930be7Sderaadt 61df930be7Sderaadt /* 62df930be7Sderaadt * Sun RPC is a product of Sun Microsystems, Inc. and is provided for 63df930be7Sderaadt * unrestricted use provided that this legend is included on all tape 64df930be7Sderaadt * media and as a part of the software program in whole or part. Users 65df930be7Sderaadt * may copy or modify Sun RPC without charge, but are not authorized 66df930be7Sderaadt * to license or distribute it to anyone else except as part of a product or 67df930be7Sderaadt * program developed by the user. 68df930be7Sderaadt * 69df930be7Sderaadt * SUN RPC IS PROVIDED AS IS WITH NO WARRANTIES OF ANY KIND INCLUDING THE 70df930be7Sderaadt * WARRANTIES OF DESIGN, MERCHANTIBILITY AND FITNESS FOR A PARTICULAR 71df930be7Sderaadt * PURPOSE, OR ARISING FROM A COURSE OF DEALING, USAGE OR TRADE PRACTICE. 72df930be7Sderaadt * 73df930be7Sderaadt * Sun RPC is provided with no support and without any obligation on the 74df930be7Sderaadt * part of Sun Microsystems, Inc. to assist in its use, correction, 75df930be7Sderaadt * modification or enhancement. 76df930be7Sderaadt * 77df930be7Sderaadt * SUN MICROSYSTEMS, INC. SHALL HAVE NO LIABILITY WITH RESPECT TO THE 78df930be7Sderaadt * INFRINGEMENT OF COPYRIGHTS, TRADE SECRETS OR ANY PATENTS BY SUN RPC 79df930be7Sderaadt * OR ANY PART THEREOF. 80df930be7Sderaadt * 81df930be7Sderaadt * In no event will Sun Microsystems, Inc. be liable for any lost revenue 82df930be7Sderaadt * or profits or other special, indirect and consequential damages, even if 83df930be7Sderaadt * Sun has been advised of the possibility of such damages. 84df930be7Sderaadt * 85df930be7Sderaadt * Sun Microsystems, Inc. 86df930be7Sderaadt * 2550 Garcia Avenue 87df930be7Sderaadt * Mountain View, California 94043 88df930be7Sderaadt */ 89df930be7Sderaadt 90df930be7Sderaadt #include <rpc/rpc.h> 91df930be7Sderaadt #include <rpc/pmap_prot.h> 92df930be7Sderaadt #include <stdio.h> 93df930be7Sderaadt #include <stdlib.h> 94df930be7Sderaadt #include <string.h> 95df930be7Sderaadt #include <syslog.h> 96df930be7Sderaadt #include <unistd.h> 97df930be7Sderaadt #include <netdb.h> 98df930be7Sderaadt #include <sys/socket.h> 99df930be7Sderaadt #include <sys/ioctl.h> 100df930be7Sderaadt #include <sys/wait.h> 101df930be7Sderaadt #include <sys/signal.h> 102df930be7Sderaadt #include <sys/resource.h> 10377baebbfSderaadt #include <rpcsvc/nfs_prot.h> 104d91d7659Sderaadt #include <arpa/inet.h> 105df930be7Sderaadt 106df930be7Sderaadt void reg_service __P((struct svc_req *, SVCXPRT *)); 107d91d7659Sderaadt void reap __P((void)); 108d91d7659Sderaadt void callit __P((struct svc_req *, SVCXPRT *)); 109d91d7659Sderaadt int check_callit __P((struct sockaddr_in *, u_long, u_long, u_long)); 110df930be7Sderaadt 111df930be7Sderaadt struct pmaplist *pmaplist; 112df930be7Sderaadt int debugging = 0; 113df930be7Sderaadt extern int errno; 114df930be7Sderaadt 11577baebbfSderaadt SVCXPRT *ludpxprt, *ltcpxprt; 11677baebbfSderaadt 117d91d7659Sderaadt int 118df930be7Sderaadt main(argc, argv) 119df930be7Sderaadt int argc; 120df930be7Sderaadt char **argv; 121df930be7Sderaadt { 122df930be7Sderaadt SVCXPRT *xprt; 12377baebbfSderaadt int sock, lsock, c; 12477baebbfSderaadt struct sockaddr_in addr, laddr; 12577baebbfSderaadt int on = 1; 126df930be7Sderaadt int len = sizeof(struct sockaddr_in); 127df930be7Sderaadt register struct pmaplist *pml; 128df930be7Sderaadt 12972799b18Smillert while ((c = getopt(argc, argv, "d")) != -1) { 130df930be7Sderaadt switch (c) { 131df930be7Sderaadt 132df930be7Sderaadt case 'd': 133df930be7Sderaadt debugging = 1; 134df930be7Sderaadt break; 135df930be7Sderaadt 136df930be7Sderaadt default: 137df930be7Sderaadt (void) fprintf(stderr, "usage: %s [-d]\n", argv[0]); 138df930be7Sderaadt exit(1); 139df930be7Sderaadt } 140df930be7Sderaadt } 141df930be7Sderaadt 142df930be7Sderaadt if (!debugging && daemon(0, 0)) { 143df930be7Sderaadt (void) fprintf(stderr, "portmap: fork: %s", strerror(errno)); 144df930be7Sderaadt exit(1); 145df930be7Sderaadt } 146df930be7Sderaadt 147df930be7Sderaadt openlog("portmap", debugging ? LOG_PID | LOG_PERROR : LOG_PID, 148df930be7Sderaadt LOG_DAEMON); 149df930be7Sderaadt 15077baebbfSderaadt bzero((char *)&addr, sizeof addr); 15177baebbfSderaadt addr.sin_addr.s_addr = 0; 15277baebbfSderaadt addr.sin_family = AF_INET; 15377baebbfSderaadt addr.sin_addr.s_addr = htonl(INADDR_ANY); 15477baebbfSderaadt addr.sin_port = htons(PMAPPORT); 15577baebbfSderaadt 15677baebbfSderaadt bzero((char *)&laddr, sizeof laddr); 15777baebbfSderaadt laddr.sin_addr.s_addr = 0; 15877baebbfSderaadt laddr.sin_family = AF_INET; 15977baebbfSderaadt laddr.sin_addr.s_addr = htonl(INADDR_LOOPBACK); 16077baebbfSderaadt laddr.sin_port = htons(PMAPPORT); 16177baebbfSderaadt 162df930be7Sderaadt if ((sock = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) { 163df930be7Sderaadt syslog(LOG_ERR, "cannot create udp socket: %m"); 164df930be7Sderaadt exit(1); 165df930be7Sderaadt } 166afeed3b4Sderaadt setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 167df930be7Sderaadt if (bind(sock, (struct sockaddr *)&addr, len) != 0) { 168df930be7Sderaadt syslog(LOG_ERR, "cannot bind udp: %m"); 169df930be7Sderaadt exit(1); 170df930be7Sderaadt } 171df930be7Sderaadt 172df930be7Sderaadt if ((xprt = svcudp_create(sock)) == (SVCXPRT *)NULL) { 173df930be7Sderaadt syslog(LOG_ERR, "couldn't do udp_create"); 174df930be7Sderaadt exit(1); 175df930be7Sderaadt } 17677baebbfSderaadt 17777baebbfSderaadt if ((lsock = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) { 17877baebbfSderaadt syslog(LOG_ERR, "cannot create udp socket: %m"); 17977baebbfSderaadt exit(1); 18077baebbfSderaadt } 18177baebbfSderaadt setsockopt(lsock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 18277baebbfSderaadt if (bind(lsock, (struct sockaddr *)&laddr, len) != 0) { 1837e963911Smickey syslog(LOG_ERR, "cannot bind local udp: %m"); 18477baebbfSderaadt exit(1); 18577baebbfSderaadt } 18677baebbfSderaadt 18777baebbfSderaadt if ((ludpxprt = svcudp_create(lsock)) == (SVCXPRT *)NULL) { 18877baebbfSderaadt syslog(LOG_ERR, "couldn't do udp_create"); 18977baebbfSderaadt exit(1); 19077baebbfSderaadt } 19177baebbfSderaadt 192df930be7Sderaadt /* make an entry for ourself */ 193df930be7Sderaadt pml = (struct pmaplist *)malloc((u_int)sizeof(struct pmaplist)); 194df930be7Sderaadt pml->pml_next = 0; 195df930be7Sderaadt pml->pml_map.pm_prog = PMAPPROG; 196df930be7Sderaadt pml->pml_map.pm_vers = PMAPVERS; 197df930be7Sderaadt pml->pml_map.pm_prot = IPPROTO_UDP; 198df930be7Sderaadt pml->pml_map.pm_port = PMAPPORT; 199df930be7Sderaadt pmaplist = pml; 200df930be7Sderaadt 201df930be7Sderaadt if ((sock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0) { 202df930be7Sderaadt syslog(LOG_ERR, "cannot create tcp socket: %m"); 203df930be7Sderaadt exit(1); 204df930be7Sderaadt } 205afeed3b4Sderaadt setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 206df930be7Sderaadt if (bind(sock, (struct sockaddr *)&addr, len) != 0) { 207da52f073Sderaadt syslog(LOG_ERR, "cannot bind tcp: %m"); 208df930be7Sderaadt exit(1); 209df930be7Sderaadt } 210df930be7Sderaadt if ((xprt = svctcp_create(sock, RPCSMALLMSGSIZE, RPCSMALLMSGSIZE)) 211df930be7Sderaadt == (SVCXPRT *)NULL) { 212df930be7Sderaadt syslog(LOG_ERR, "couldn't do tcp_create"); 213df930be7Sderaadt exit(1); 214df930be7Sderaadt } 21577baebbfSderaadt 21677baebbfSderaadt if ((lsock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) < 0) { 21777baebbfSderaadt syslog(LOG_ERR, "cannot create tcp socket: %m"); 21877baebbfSderaadt exit(1); 21977baebbfSderaadt } 22077baebbfSderaadt setsockopt(lsock, SOL_SOCKET, SO_REUSEADDR, &on, sizeof on); 22177baebbfSderaadt if (bind(lsock, (struct sockaddr *)&laddr, len) != 0) { 222da52f073Sderaadt syslog(LOG_ERR, "cannot bind tcp: %m"); 22377baebbfSderaadt exit(1); 22477baebbfSderaadt } 22577baebbfSderaadt if ((ltcpxprt = svctcp_create(lsock, RPCSMALLMSGSIZE, 22677baebbfSderaadt RPCSMALLMSGSIZE)) == (SVCXPRT *)NULL) { 22777baebbfSderaadt syslog(LOG_ERR, "couldn't do tcp_create"); 22877baebbfSderaadt exit(1); 22977baebbfSderaadt } 23077baebbfSderaadt 231df930be7Sderaadt /* make an entry for ourself */ 232df930be7Sderaadt pml = (struct pmaplist *)malloc((u_int)sizeof(struct pmaplist)); 233df930be7Sderaadt pml->pml_map.pm_prog = PMAPPROG; 234df930be7Sderaadt pml->pml_map.pm_vers = PMAPVERS; 235df930be7Sderaadt pml->pml_map.pm_prot = IPPROTO_TCP; 236df930be7Sderaadt pml->pml_map.pm_port = PMAPPORT; 237df930be7Sderaadt pml->pml_next = pmaplist; 238df930be7Sderaadt pmaplist = pml; 239df930be7Sderaadt 240df930be7Sderaadt (void)svc_register(xprt, PMAPPROG, PMAPVERS, reg_service, FALSE); 241df930be7Sderaadt 242d91d7659Sderaadt (void)signal(SIGCHLD, (void (*)())reap); 243df930be7Sderaadt svc_run(); 244da52f073Sderaadt syslog(LOG_ERR, "svc_run returned unexpectedly"); 245df930be7Sderaadt abort(); 246df930be7Sderaadt } 247df930be7Sderaadt 248df930be7Sderaadt #ifndef lint 249df930be7Sderaadt /* need to override perror calls in rpc library */ 250df930be7Sderaadt void 251df930be7Sderaadt perror(what) 252df930be7Sderaadt const char *what; 253df930be7Sderaadt { 254df930be7Sderaadt 255df930be7Sderaadt syslog(LOG_ERR, "%s: %m", what); 256df930be7Sderaadt } 257df930be7Sderaadt #endif 258df930be7Sderaadt 2593aef48d5Sderaadt struct pmaplist * 260df930be7Sderaadt find_service(prog, vers, prot) 261df930be7Sderaadt u_long prog, vers, prot; 262df930be7Sderaadt { 263df930be7Sderaadt register struct pmaplist *hit = NULL; 264df930be7Sderaadt register struct pmaplist *pml; 265df930be7Sderaadt 266df930be7Sderaadt for (pml = pmaplist; pml != NULL; pml = pml->pml_next) { 267df930be7Sderaadt if ((pml->pml_map.pm_prog != prog) || 268df930be7Sderaadt (pml->pml_map.pm_prot != prot)) 269df930be7Sderaadt continue; 270df930be7Sderaadt hit = pml; 271df930be7Sderaadt if (pml->pml_map.pm_vers == vers) 272df930be7Sderaadt break; 273df930be7Sderaadt } 274df930be7Sderaadt return (hit); 275df930be7Sderaadt } 276df930be7Sderaadt 277df930be7Sderaadt /* 278df930be7Sderaadt * 1 OK, 0 not 279df930be7Sderaadt */ 280df930be7Sderaadt void 281df930be7Sderaadt reg_service(rqstp, xprt) 282df930be7Sderaadt struct svc_req *rqstp; 283df930be7Sderaadt SVCXPRT *xprt; 284df930be7Sderaadt { 285df930be7Sderaadt struct pmap reg; 286df930be7Sderaadt struct pmaplist *pml, *prevpml, *fnd; 28777baebbfSderaadt struct sockaddr_in *fromsin; 28877baebbfSderaadt long ans = 0, port; 289df930be7Sderaadt caddr_t t; 290df930be7Sderaadt 29177baebbfSderaadt fromsin = svc_getcaller(xprt); 29277baebbfSderaadt 293df930be7Sderaadt if (debugging) 294df930be7Sderaadt (void) fprintf(stderr, "server: about to do a switch\n"); 295df930be7Sderaadt switch (rqstp->rq_proc) { 296df930be7Sderaadt 297df930be7Sderaadt case PMAPPROC_NULL: 298df930be7Sderaadt /* 299df930be7Sderaadt * Null proc call 300df930be7Sderaadt */ 301df930be7Sderaadt if (!svc_sendreply(xprt, xdr_void, (caddr_t)0) && debugging) { 302df930be7Sderaadt abort(); 303df930be7Sderaadt } 304df930be7Sderaadt break; 305df930be7Sderaadt 306df930be7Sderaadt case PMAPPROC_SET: 307df930be7Sderaadt /* 308df930be7Sderaadt * Set a program,version to port mapping 309df930be7Sderaadt */ 31077baebbfSderaadt if (xprt != ltcpxprt && xprt != ludpxprt) { 31177baebbfSderaadt syslog(LOG_WARNING, 31277baebbfSderaadt "non-local set attempt (might be from %s)", 3139430a6aeSderaadt inet_ntoa(fromsin->sin_addr)); 31477baebbfSderaadt svcerr_noproc(xprt); 31577baebbfSderaadt return; 31677baebbfSderaadt } 31760cef36bSderaadt if (!svc_getargs(xprt, xdr_pmap, (caddr_t)®)) { 318df930be7Sderaadt svcerr_decode(xprt); 31960cef36bSderaadt break; 32060cef36bSderaadt } 3213aef48d5Sderaadt 322df930be7Sderaadt /* 323df930be7Sderaadt * check to see if already used 324df930be7Sderaadt * find_service returns a hit even if 325df930be7Sderaadt * the versions don't match, so check for it 326df930be7Sderaadt */ 327df930be7Sderaadt fnd = find_service(reg.pm_prog, reg.pm_vers, reg.pm_prot); 328df930be7Sderaadt if (fnd && fnd->pml_map.pm_vers == reg.pm_vers) { 32977baebbfSderaadt if (fnd->pml_map.pm_port == reg.pm_port) 330df930be7Sderaadt ans = 1; 331df930be7Sderaadt goto done; 332df930be7Sderaadt } 33377baebbfSderaadt 334*a982d679Sderaadt if (debugging) 335*a982d679Sderaadt printf("set: prog %u vers %u port %u\n", 336*a982d679Sderaadt reg.pm_prog, reg.pm_vers, reg.pm_port); 337*a982d679Sderaadt 338*a982d679Sderaadt if (reg.pm_port & ~0xffff) 339*a982d679Sderaadt goto done; 340*a982d679Sderaadt 341*a982d679Sderaadt /* 342*a982d679Sderaadt * only permit localhost root to create 343*a982d679Sderaadt * mappings pointing at sensitive ports 344*a982d679Sderaadt */ 345*a982d679Sderaadt if ((reg.pm_port < IPPORT_RESERVED || 346*a982d679Sderaadt reg.pm_port == NFS_PORT) && 34777baebbfSderaadt htons(fromsin->sin_port) >= IPPORT_RESERVED) { 348*a982d679Sderaadt syslog(LOG_WARNING, 349*a982d679Sderaadt "resvport set attempt by non-root"); 350df930be7Sderaadt goto done; 351df930be7Sderaadt } 35277baebbfSderaadt 353df930be7Sderaadt /* 354df930be7Sderaadt * add to END of list 355df930be7Sderaadt */ 35660cef36bSderaadt pml = (struct pmaplist *)malloc(sizeof(struct pmaplist)); 357df930be7Sderaadt pml->pml_map = reg; 358df930be7Sderaadt pml->pml_next = 0; 359df930be7Sderaadt if (pmaplist == 0) { 360df930be7Sderaadt pmaplist = pml; 361df930be7Sderaadt } else { 362df930be7Sderaadt for (fnd = pmaplist; fnd->pml_next != 0; 363df930be7Sderaadt fnd = fnd->pml_next); 364df930be7Sderaadt fnd->pml_next = pml; 365df930be7Sderaadt } 366df930be7Sderaadt ans = 1; 367df930be7Sderaadt done: 368df930be7Sderaadt if ((!svc_sendreply(xprt, xdr_long, (caddr_t)&ans)) && 369df930be7Sderaadt debugging) { 370df930be7Sderaadt (void) fprintf(stderr, "svc_sendreply\n"); 371df930be7Sderaadt abort(); 372df930be7Sderaadt } 373df930be7Sderaadt break; 374df930be7Sderaadt 375df930be7Sderaadt case PMAPPROC_UNSET: 376df930be7Sderaadt /* 377df930be7Sderaadt * Remove a program,version to port mapping. 378df930be7Sderaadt */ 37977baebbfSderaadt if (xprt != ltcpxprt && xprt != ludpxprt) { 38077baebbfSderaadt syslog(LOG_WARNING, 38177baebbfSderaadt "non-local unset attempt (might be from %s)", 3829430a6aeSderaadt inet_ntoa(fromsin->sin_addr)); 38377baebbfSderaadt svcerr_noproc(xprt); 38477baebbfSderaadt return; 38577baebbfSderaadt } 38677baebbfSderaadt if (!svc_getargs(xprt, xdr_pmap, (caddr_t)®)) { 387df930be7Sderaadt svcerr_decode(xprt); 38877baebbfSderaadt break; 38977baebbfSderaadt } 390df930be7Sderaadt for (prevpml = NULL, pml = pmaplist; pml != NULL; ) { 391df930be7Sderaadt if ((pml->pml_map.pm_prog != reg.pm_prog) || 392df930be7Sderaadt (pml->pml_map.pm_vers != reg.pm_vers)) { 393df930be7Sderaadt /* both pml & prevpml move forwards */ 394df930be7Sderaadt prevpml = pml; 395df930be7Sderaadt pml = pml->pml_next; 396df930be7Sderaadt continue; 397df930be7Sderaadt } 39877baebbfSderaadt if ((pml->pml_map.pm_port < IPPORT_RESERVED || 39977baebbfSderaadt pml->pml_map.pm_port == NFS_PORT) && 40077baebbfSderaadt htons(fromsin->sin_port) >= IPPORT_RESERVED) { 40177baebbfSderaadt syslog(LOG_WARNING, 40277baebbfSderaadt "resvport unset attempt by non-root"); 40377baebbfSderaadt break; 40477baebbfSderaadt } 40577baebbfSderaadt 406df930be7Sderaadt /* found it; pml moves forward, prevpml stays */ 407df930be7Sderaadt ans = 1; 408df930be7Sderaadt t = (caddr_t)pml; 409df930be7Sderaadt pml = pml->pml_next; 410df930be7Sderaadt if (prevpml == NULL) 411df930be7Sderaadt pmaplist = pml; 412df930be7Sderaadt else 413df930be7Sderaadt prevpml->pml_next = pml; 414df930be7Sderaadt free(t); 415df930be7Sderaadt } 416df930be7Sderaadt if ((!svc_sendreply(xprt, xdr_long, (caddr_t)&ans)) && 417df930be7Sderaadt debugging) { 41860cef36bSderaadt fprintf(stderr, "svc_sendreply\n"); 419df930be7Sderaadt abort(); 420df930be7Sderaadt } 421df930be7Sderaadt break; 422df930be7Sderaadt 423df930be7Sderaadt case PMAPPROC_GETPORT: 424df930be7Sderaadt /* 425df930be7Sderaadt * Lookup the mapping for a program,version and return its port 426df930be7Sderaadt */ 42760cef36bSderaadt if (!svc_getargs(xprt, xdr_pmap, (caddr_t)®)) { 428df930be7Sderaadt svcerr_decode(xprt); 42960cef36bSderaadt break; 43060cef36bSderaadt } 431df930be7Sderaadt fnd = find_service(reg.pm_prog, reg.pm_vers, reg.pm_prot); 432df930be7Sderaadt if (fnd) 433df930be7Sderaadt port = fnd->pml_map.pm_port; 434df930be7Sderaadt else 435df930be7Sderaadt port = 0; 436df930be7Sderaadt if ((!svc_sendreply(xprt, xdr_long, (caddr_t)&port)) && 437df930be7Sderaadt debugging) { 43860cef36bSderaadt fprintf(stderr, "svc_sendreply\n"); 439df930be7Sderaadt abort(); 440df930be7Sderaadt } 441df930be7Sderaadt break; 442df930be7Sderaadt 443df930be7Sderaadt case PMAPPROC_DUMP: 444df930be7Sderaadt /* 445df930be7Sderaadt * Return the current set of mapped program,version 446df930be7Sderaadt */ 44760cef36bSderaadt if (!svc_getargs(xprt, xdr_void, NULL)) { 448df930be7Sderaadt svcerr_decode(xprt); 44960cef36bSderaadt break; 45060cef36bSderaadt } 45160cef36bSderaadt if (!svc_sendreply(xprt, xdr_pmaplist, (caddr_t)&pmaplist) && 45260cef36bSderaadt debugging) { 45360cef36bSderaadt fprintf(stderr, "svc_sendreply\n"); 454df930be7Sderaadt abort(); 455df930be7Sderaadt } 456df930be7Sderaadt break; 457df930be7Sderaadt 458df930be7Sderaadt case PMAPPROC_CALLIT: 459df930be7Sderaadt /* 460df930be7Sderaadt * Calls a procedure on the local machine. If the requested 461df930be7Sderaadt * procedure is not registered this procedure does not return 462df930be7Sderaadt * error information!! 463df930be7Sderaadt * This procedure is only supported on rpc/udp and calls via 464df930be7Sderaadt * rpc/udp. It passes null authentication parameters. 465df930be7Sderaadt */ 466df930be7Sderaadt callit(rqstp, xprt); 467df930be7Sderaadt break; 468df930be7Sderaadt 469df930be7Sderaadt default: 470df930be7Sderaadt svcerr_noproc(xprt); 471df930be7Sderaadt break; 472df930be7Sderaadt } 473df930be7Sderaadt } 474df930be7Sderaadt 475df930be7Sderaadt 476df930be7Sderaadt /* 477df930be7Sderaadt * Stuff for the rmtcall service 478df930be7Sderaadt */ 479df930be7Sderaadt #define ARGSIZE 9000 480df930be7Sderaadt 481df930be7Sderaadt struct encap_parms { 482df930be7Sderaadt u_int arglen; 483df930be7Sderaadt char *args; 484df930be7Sderaadt }; 485df930be7Sderaadt 486df930be7Sderaadt static bool_t 487df930be7Sderaadt xdr_encap_parms(xdrs, epp) 488df930be7Sderaadt XDR *xdrs; 489df930be7Sderaadt struct encap_parms *epp; 490df930be7Sderaadt { 491df930be7Sderaadt 492df930be7Sderaadt return (xdr_bytes(xdrs, &(epp->args), &(epp->arglen), ARGSIZE)); 493df930be7Sderaadt } 494df930be7Sderaadt 495df930be7Sderaadt struct rmtcallargs { 496df930be7Sderaadt u_long rmt_prog; 497df930be7Sderaadt u_long rmt_vers; 498df930be7Sderaadt u_long rmt_port; 499df930be7Sderaadt u_long rmt_proc; 500df930be7Sderaadt struct encap_parms rmt_args; 501df930be7Sderaadt }; 502df930be7Sderaadt 503df930be7Sderaadt static bool_t 504df930be7Sderaadt xdr_rmtcall_args(xdrs, cap) 505df930be7Sderaadt register XDR *xdrs; 506df930be7Sderaadt register struct rmtcallargs *cap; 507df930be7Sderaadt { 508df930be7Sderaadt 509df930be7Sderaadt /* does not get a port number */ 510df930be7Sderaadt if (xdr_u_long(xdrs, &(cap->rmt_prog)) && 511df930be7Sderaadt xdr_u_long(xdrs, &(cap->rmt_vers)) && 512df930be7Sderaadt xdr_u_long(xdrs, &(cap->rmt_proc))) { 513df930be7Sderaadt return (xdr_encap_parms(xdrs, &(cap->rmt_args))); 514df930be7Sderaadt } 515df930be7Sderaadt return (FALSE); 516df930be7Sderaadt } 517df930be7Sderaadt 518df930be7Sderaadt static bool_t 519df930be7Sderaadt xdr_rmtcall_result(xdrs, cap) 520df930be7Sderaadt register XDR *xdrs; 521df930be7Sderaadt register struct rmtcallargs *cap; 522df930be7Sderaadt { 523df930be7Sderaadt if (xdr_u_long(xdrs, &(cap->rmt_port))) 524df930be7Sderaadt return (xdr_encap_parms(xdrs, &(cap->rmt_args))); 525df930be7Sderaadt return (FALSE); 526df930be7Sderaadt } 527df930be7Sderaadt 528df930be7Sderaadt /* 529df930be7Sderaadt * only worries about the struct encap_parms part of struct rmtcallargs. 530df930be7Sderaadt * The arglen must already be set!! 531df930be7Sderaadt */ 532df930be7Sderaadt static bool_t 533df930be7Sderaadt xdr_opaque_parms(xdrs, cap) 534df930be7Sderaadt XDR *xdrs; 535df930be7Sderaadt struct rmtcallargs *cap; 536df930be7Sderaadt { 537df930be7Sderaadt 538df930be7Sderaadt return (xdr_opaque(xdrs, cap->rmt_args.args, cap->rmt_args.arglen)); 539df930be7Sderaadt } 540df930be7Sderaadt 541df930be7Sderaadt /* 542df930be7Sderaadt * This routine finds and sets the length of incoming opaque paraters 543df930be7Sderaadt * and then calls xdr_opaque_parms. 544df930be7Sderaadt */ 545df930be7Sderaadt static bool_t 546df930be7Sderaadt xdr_len_opaque_parms(xdrs, cap) 547df930be7Sderaadt register XDR *xdrs; 548df930be7Sderaadt struct rmtcallargs *cap; 549df930be7Sderaadt { 550df930be7Sderaadt register u_int beginpos, lowpos, highpos, currpos, pos; 551df930be7Sderaadt 552df930be7Sderaadt beginpos = lowpos = pos = xdr_getpos(xdrs); 553df930be7Sderaadt highpos = lowpos + ARGSIZE; 554df930be7Sderaadt while ((int)(highpos - lowpos) >= 0) { 555df930be7Sderaadt currpos = (lowpos + highpos) / 2; 556df930be7Sderaadt if (xdr_setpos(xdrs, currpos)) { 557df930be7Sderaadt pos = currpos; 558df930be7Sderaadt lowpos = currpos + 1; 559df930be7Sderaadt } else { 560df930be7Sderaadt highpos = currpos - 1; 561df930be7Sderaadt } 562df930be7Sderaadt } 563df930be7Sderaadt xdr_setpos(xdrs, beginpos); 564df930be7Sderaadt cap->rmt_args.arglen = pos - beginpos; 565df930be7Sderaadt return (xdr_opaque_parms(xdrs, cap)); 566df930be7Sderaadt } 567df930be7Sderaadt 568df930be7Sderaadt /* 569df930be7Sderaadt * Call a remote procedure service 570df930be7Sderaadt * This procedure is very quiet when things go wrong. 571df930be7Sderaadt * The proc is written to support broadcast rpc. In the broadcast case, 572df930be7Sderaadt * a machine should shut-up instead of complain, less the requestor be 573df930be7Sderaadt * overrun with complaints at the expense of not hearing a valid reply ... 574df930be7Sderaadt * 575df930be7Sderaadt * This now forks so that the program & process that it calls can call 576df930be7Sderaadt * back to the portmapper. 577df930be7Sderaadt */ 578d91d7659Sderaadt void 579df930be7Sderaadt callit(rqstp, xprt) 580df930be7Sderaadt struct svc_req *rqstp; 581df930be7Sderaadt SVCXPRT *xprt; 582df930be7Sderaadt { 583df930be7Sderaadt struct rmtcallargs a; 584df930be7Sderaadt struct pmaplist *pml; 585df930be7Sderaadt u_short port; 586df930be7Sderaadt struct sockaddr_in me; 58748822293Sderaadt pid_t pid; 58848822293Sderaadt int so = -1, dontblock = 1; 589df930be7Sderaadt CLIENT *client; 590df930be7Sderaadt struct authunix_parms *au = (struct authunix_parms *)rqstp->rq_clntcred; 591df930be7Sderaadt struct timeval timeout; 592df930be7Sderaadt char buf[ARGSIZE]; 593df930be7Sderaadt 594df930be7Sderaadt timeout.tv_sec = 5; 595df930be7Sderaadt timeout.tv_usec = 0; 596df930be7Sderaadt a.rmt_args.args = buf; 597df930be7Sderaadt if (!svc_getargs(xprt, xdr_rmtcall_args, (caddr_t)&a)) 598df930be7Sderaadt return; 599f94670b8Sderaadt if (!check_callit(svc_getcaller(xprt), rqstp->rq_proc, 600f94670b8Sderaadt a.rmt_prog, a.rmt_proc)) 601f94670b8Sderaadt return; 602df930be7Sderaadt if ((pml = find_service(a.rmt_prog, a.rmt_vers, 603df930be7Sderaadt (u_long)IPPROTO_UDP)) == NULL) 604df930be7Sderaadt return; 60577baebbfSderaadt 606df930be7Sderaadt /* 607df930be7Sderaadt * fork a child to do the work. Parent immediately returns. 608df930be7Sderaadt * Child exits upon completion. 609df930be7Sderaadt */ 610df930be7Sderaadt if ((pid = fork()) != 0) { 611df930be7Sderaadt if (pid == -1) 612df930be7Sderaadt syslog(LOG_ERR, "CALLIT (prog %lu): fork: %m", 613df930be7Sderaadt a.rmt_prog); 614df930be7Sderaadt return; 615df930be7Sderaadt } 616df930be7Sderaadt port = pml->pml_map.pm_port; 617df930be7Sderaadt get_myaddress(&me); 618df930be7Sderaadt me.sin_port = htons(port); 619df930be7Sderaadt 620df930be7Sderaadt /* Avoid implicit binding to reserved port by clntudp_create() */ 621df930be7Sderaadt so = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP); 622df930be7Sderaadt if (so == -1) 623df930be7Sderaadt exit(1); 624df930be7Sderaadt if (ioctl(so, FIONBIO, &dontblock) == -1) 625df930be7Sderaadt exit(1); 626df930be7Sderaadt 627df930be7Sderaadt client = clntudp_create(&me, a.rmt_prog, a.rmt_vers, timeout, &so); 628df930be7Sderaadt if (client != (CLIENT *)NULL) { 62977baebbfSderaadt if (rqstp->rq_cred.oa_flavor == AUTH_UNIX) 630df930be7Sderaadt client->cl_auth = authunix_create(au->aup_machname, 631df930be7Sderaadt au->aup_uid, au->aup_gid, au->aup_len, au->aup_gids); 632df930be7Sderaadt a.rmt_port = (u_long)port; 633df930be7Sderaadt if (clnt_call(client, a.rmt_proc, xdr_opaque_parms, &a, 63477baebbfSderaadt xdr_len_opaque_parms, &a, timeout) == RPC_SUCCESS) 635df930be7Sderaadt svc_sendreply(xprt, xdr_rmtcall_result, (caddr_t)&a); 636df930be7Sderaadt AUTH_DESTROY(client->cl_auth); 637df930be7Sderaadt clnt_destroy(client); 638df930be7Sderaadt } 639df930be7Sderaadt (void)close(so); 640df930be7Sderaadt exit(0); 641df930be7Sderaadt } 642df930be7Sderaadt 643df930be7Sderaadt void 644df930be7Sderaadt reap() 645df930be7Sderaadt { 646df930be7Sderaadt int save_errno = errno; 647df930be7Sderaadt 6487af3e1e5Sderaadt while (wait3(NULL, WNOHANG, NULL) > 0) 649df930be7Sderaadt ; 650df930be7Sderaadt errno = save_errno; 651df930be7Sderaadt } 652f94670b8Sderaadt 653f94670b8Sderaadt #define NFSPROG ((u_long) 100003) 654f94670b8Sderaadt #define MOUNTPROG ((u_long) 100005) 655f94670b8Sderaadt #define YPXPROG ((u_long) 100069) 656f94670b8Sderaadt #define YPPROG ((u_long) 100004) 657f94670b8Sderaadt #define YPPROC_DOMAIN_NONACK ((u_long) 2) 658f94670b8Sderaadt #define MOUNTPROC_MNT ((u_long) 1) 6599d791f75Sderaadt #define XXXPROC_NOP ((u_long) 0) 660f94670b8Sderaadt 661f94670b8Sderaadt int 662f94670b8Sderaadt check_callit(addr, proc, prog, aproc) 663f94670b8Sderaadt struct sockaddr_in *addr; 664f94670b8Sderaadt u_long proc; 665f94670b8Sderaadt u_long prog; 666f94670b8Sderaadt u_long aproc; 667f94670b8Sderaadt { 6689d791f75Sderaadt if ((prog == PMAPPROG && aproc != XXXPROC_NOP) || 6699d791f75Sderaadt (prog == NFSPROG && aproc != XXXPROC_NOP) || 6709d791f75Sderaadt (prog == YPXPROG && aproc != XXXPROC_NOP) || 671f94670b8Sderaadt (prog == MOUNTPROG && aproc == MOUNTPROC_MNT) || 672f94670b8Sderaadt (prog == YPPROG && aproc != YPPROC_DOMAIN_NONACK)) { 673f94670b8Sderaadt syslog(LOG_WARNING, 674f94670b8Sderaadt "callit prog %d aproc %d (might be from %s)", 675d91d7659Sderaadt (int)prog, (int)aproc, inet_ntoa(addr->sin_addr)); 676f94670b8Sderaadt return (FALSE); 677f94670b8Sderaadt } 678f94670b8Sderaadt return (TRUE); 679f94670b8Sderaadt } 680