9c49c9
From 01b1dcfef129a4eccfaf0f63a216774019f82dca Mon Sep 17 00:00:00 2001
7c0972
From: Pavel Zhukov <pzhukov@redhat.com>
7c0972
Date: Thu, 21 Feb 2019 10:32:35 +0100
9c49c9
Subject: [PATCH 12/26] RFC 3442 - Classless Static Route Option for DHCPv4
7c0972
 (#516325)
7c0972
Cc: pzhukov@redhat.com
7c0972
7c0972
(Submitted to dhcp-bugs@isc.org - [ISC-Bugs #24572])
7c0972
---
7c0972
 client/clparse.c      | 13 ++++++++++--
7c0972
 common/dhcp-options.5 | 43 +++++++++++++++++++++++++++++++++++++++
7c0972
 common/inet.c         | 54 +++++++++++++++++++++++++++++++++++++++++++++++++
7c0972
 common/options.c      | 49 +++++++++++++++++++++++++++++++++++++++++++-
7c0972
 common/parse.c        | 56 ++++++++++++++++++++++++++++++++++++++++++++++++++-
7c0972
 common/tables.c       |  2 ++
7c0972
 includes/dhcp.h       |  1 +
7c0972
 includes/dhcpd.h      |  2 ++
7c0972
 includes/dhctoken.h   |  5 +++--
7c0972
 9 files changed, 219 insertions(+), 6 deletions(-)
7c0972
7c0972
diff --git a/client/clparse.c b/client/clparse.c
7c0972
index 44387ed..862e4f9 100644
7c0972
--- a/client/clparse.c
7c0972
+++ b/client/clparse.c
90936e
@@ -31,7 +31,7 @@
a21bc0
 
a21bc0
 struct client_config top_level_config;
a21bc0
 
a21bc0
-#define NUM_DEFAULT_REQUESTED_OPTS	14
a21bc0
+#define NUM_DEFAULT_REQUESTED_OPTS	15
8173a6
 /* There can be 2 extra requested options for DHCPv4-over-DHCPv6. */
8173a6
 struct option *default_requested_options[NUM_DEFAULT_REQUESTED_OPTS + 2 + 1];
a21bc0
 
8173a6
@@ -87,7 +87,11 @@ isc_result_t read_client_conf ()
a21bc0
 				dhcp_universe.code_hash, &code, 0, MDL);
a21bc0
 
a21bc0
 	/* 4 */
a21bc0
-	code = DHO_ROUTERS;
a21bc0
+	/* The Classless Static Routes option code MUST appear in the parameter
a21bc0
+     * request list prior to both the Router option code and the Static
a21bc0
+     * Routes option code, if present. (RFC3442)
a21bc0
+	 */
a21bc0
+	code = DHO_CLASSLESS_STATIC_ROUTES;
a21bc0
 	option_code_hash_lookup(&default_requested_options[3],
a21bc0
 				dhcp_universe.code_hash, &code, 0, MDL);
a21bc0
 
8173a6
@@ -141,6 +145,11 @@ isc_result_t read_client_conf ()
a21bc0
 	option_code_hash_lookup(&default_requested_options[13],
a21bc0
 				dhcp_universe.code_hash, &code, 0, MDL);
a21bc0
 
a21bc0
+	/* 15 */
a21bc0
+	code = DHO_ROUTERS;
a21bc0
+	option_code_hash_lookup(&default_requested_options[14],
a21bc0
+				dhcp_universe.code_hash, &code, 0, MDL);
a21bc0
+
a21bc0
 	for (code = 0 ; code < NUM_DEFAULT_REQUESTED_OPTS ; code++) {
a21bc0
 		if (default_requested_options[code] == NULL)
a21bc0
 			log_fatal("Unable to find option definition for "
7c0972
diff --git a/common/dhcp-options.5 b/common/dhcp-options.5
7c0972
index d9e1197..2343b19 100644
7c0972
--- a/common/dhcp-options.5
7c0972
+++ b/common/dhcp-options.5
7c0972
@@ -110,6 +110,26 @@ hexadecimal, separated by colons.  For example:
a21bc0
 or
a21bc0
   option dhcp-client-identifier 43:4c:49:45:54:2d:46:4f:4f;
a21bc0
 .fi
a21bc0
+.PP
a21bc0
+The
a21bc0
+.B destination-descriptor
a21bc0
+describe the IP subnet number and subnet mask
a21bc0
+of a particular destination using a compact encoding. This encoding
a21bc0
+consists of one octet describing the width of the subnet mask,
a21bc0
+followed by all the significant octets of the subnet number.
a21bc0
+The following table contains some examples of how various subnet
a21bc0
+number/mask combinations can be encoded:
a21bc0
+.nf
a21bc0
+.sp 1
a21bc0
+Subnet number   Subnet mask      Destination descriptor
a21bc0
+0               0                0
a21bc0
+10.0.0.0        255.0.0.0        8.10
a21bc0
+10.0.0.0        255.255.255.0    24.10.0.0
a21bc0
+10.17.0.0       255.255.0.0      16.10.17
a21bc0
+10.27.129.0     255.255.255.0    24.10.27.129
a21bc0
+10.229.0.128    255.255.255.128  25.10.229.0.128
a21bc0
+10.198.122.47   255.255.255.255  32.10.198.122.47
a21bc0
+.fi
a21bc0
 .SH SETTING OPTION VALUES USING EXPRESSIONS
a21bc0
 Sometimes it's helpful to be able to set the value of a DHCP option
c72a79
 based on some value that the client has sent.  To do this, you can
7c0972
@@ -1086,6 +1106,29 @@ dhclient-script will create routes:
a21bc0
 .RE
a21bc0
 .PP
a21bc0
 .nf
a21bc0
+.B option \fBclassless-static-routes\fR \fIdestination-descriptor ip-address\fR
7b41fd
+                            [\fB,\fR \fIdestination-descriptor ip-address\fR...]\fB;\fR
a21bc0
+.fi
a21bc0
+.RS 0.25i
a21bc0
+.PP
a21bc0
+This option (see RFC3442) specifies a list of classless static routes
a21bc0
+that the client should install in its routing cache.
a21bc0
+.PP
a21bc0
+This option can contain one or more static routes, each of which
a21bc0
+consists of a destination descriptor and the IP address of the router
a21bc0
+that should be used to reach that destination.
a21bc0
+.PP
a21bc0
+Many clients may not implement the Classless Static Routes option.
a21bc0
+DHCP server administrators should therefore configure their DHCP
a21bc0
+servers to send both a Router option and a Classless Static Routes
a21bc0
+option, and should specify the default router(s) both in the Router
a21bc0
+option and in the Classless Static Routes option.
a21bc0
+.PP
a21bc0
+If the DHCP server returns both a Classless Static Routes option and
a21bc0
+a Router option, the DHCP client ignores the Router option.
a21bc0
+.RE
a21bc0
+.PP
a21bc0
+.nf
a21bc0
 .B option \fBstreettalk-directory-assistance-server\fR \fIip-address\fR
a21bc0
                                            [\fB,\fR \fIip-address\fR...]\fB;\fR
a21bc0
 .fi
7c0972
diff --git a/common/inet.c b/common/inet.c
7c0972
index c4da73c..981fb92 100644
7c0972
--- a/common/inet.c
7c0972
+++ b/common/inet.c
7c0972
@@ -519,6 +519,60 @@ free_iaddrcidrnetlist(struct iaddrcidrnetlist **result) {
a21bc0
 	return ISC_R_SUCCESS;
a21bc0
 }
a21bc0
 
a21bc0
+static const char *
a21bc0
+inet_ntopdd(const unsigned char *src, unsigned srclen, char *dst, size_t size)
a21bc0
+{
a21bc0
+	char tmp[sizeof("32.255.255.255.255")];
a21bc0
+	int len;
a21bc0
+
a21bc0
+	switch (srclen) {
a21bc0
+		case 2:
a21bc0
+			len = sprintf (tmp, "%u.%u", src[0], src[1]);
a21bc0
+			break;
a21bc0
+		case 3:
a21bc0
+			len = sprintf (tmp, "%u.%u.%u", src[0], src[1], src[2]);
a21bc0
+			break;
a21bc0
+		case 4:
a21bc0
+			len = sprintf (tmp, "%u.%u.%u.%u", src[0], src[1], src[2], src[3]);
a21bc0
+			break;
a21bc0
+		case 5:
a21bc0
+			len = sprintf (tmp, "%u.%u.%u.%u.%u", src[0], src[1], src[2], src[3], src[4]);
a21bc0
+			break;
a21bc0
+		default:
a21bc0
+			return NULL;
a21bc0
+	}
a21bc0
+	if (len < 0)
a21bc0
+		return NULL;
a21bc0
+
a21bc0
+	if (len > size) {
a21bc0
+		errno = ENOSPC;
a21bc0
+		return NULL;
a21bc0
+	}
a21bc0
+
a21bc0
+	return strcpy (dst, tmp);
a21bc0
+}
a21bc0
+
a21bc0
+/* pdestdesc() turns an iaddr structure into a printable dest. descriptor */
a21bc0
+const char *
a21bc0
+pdestdesc(const struct iaddr addr) {
a21bc0
+	static char pbuf[sizeof("255.255.255.255.255")];
a21bc0
+
a21bc0
+	if (addr.len == 0) {
a21bc0
+		return "<null destination descriptor>";
a21bc0
+	}
a21bc0
+	if (addr.len == 1) {
a21bc0
+		return "0";
a21bc0
+	}
a21bc0
+	if ((addr.len >= 2) && (addr.len <= 5)) {
a21bc0
+		return inet_ntopdd(addr.iabuf, addr.len, pbuf, sizeof(pbuf));
a21bc0
+	}
a21bc0
+
a21bc0
+	log_fatal("pdestdesc():%s:%d: Invalid destination descriptor length %d.",
a21bc0
+		  MDL, addr.len);
a21bc0
+	/* quell compiler warnings */
a21bc0
+	return NULL;
a21bc0
+}
a21bc0
+
a21bc0
 /* piaddr() turns an iaddr structure into a printable address. */
a21bc0
 /* XXX: should use a const pointer rather than passing the structure */
a21bc0
 const char *
7c0972
diff --git a/common/options.c b/common/options.c
7c0972
index fc0e088..3034cf0 100644
7c0972
--- a/common/options.c
7c0972
+++ b/common/options.c
7c0972
@@ -729,7 +729,11 @@ cons_options(struct packet *inpacket, struct dhcp_packet *outpacket,
a21bc0
 		 * packet.
a21bc0
 		 */
a21bc0
 		priority_list[priority_len++] = DHO_SUBNET_MASK;
a21bc0
-		priority_list[priority_len++] = DHO_ROUTERS;
2b40dd
+		if (lookup_option(&dhcp_universe, cfg_options,
2b40dd
+							DHO_CLASSLESS_STATIC_ROUTES))
a21bc0
+			priority_list[priority_len++] = DHO_CLASSLESS_STATIC_ROUTES;
a21bc0
+		else
a21bc0
+			priority_list[priority_len++] = DHO_ROUTERS;
a21bc0
 		priority_list[priority_len++] = DHO_DOMAIN_NAME_SERVERS;
a21bc0
 		priority_list[priority_len++] = DHO_HOST_NAME;
a21bc0
 		priority_list[priority_len++] = DHO_FQDN;
7c0972
@@ -1804,6 +1808,7 @@ const char *pretty_print_option (option, data, len, emit_commas, emit_quotes)
a21bc0
 	unsigned long tval;
c72a79
 	isc_boolean_t a_array = ISC_FALSE;
c72a79
 	int len_used;
c72a79
+	unsigned int octets = 0;
a21bc0
 
a21bc0
 	if (emit_commas)
a21bc0
 		comma = ',';
7c0972
@@ -1812,6 +1817,7 @@ const char *pretty_print_option (option, data, len, emit_commas, emit_quotes)
a21bc0
 
a21bc0
 	memset (enumbuf, 0, sizeof enumbuf);
a21bc0
 
a21bc0
+	if (option->format[0] != 'R') { /* see explanation lower */
a21bc0
 	/* Figure out the size of the data. */
a21bc0
 	for (l = i = 0; option -> format [i]; i++, l++) {
a21bc0
 		if (l >= sizeof(fmtbuf) - 1)
7c0972
@@ -2004,6 +2010,33 @@ const char *pretty_print_option (option, data, len, emit_commas, emit_quotes)
a21bc0
 	if (numhunk < 0)
a21bc0
 		numhunk = 1;
a21bc0
 
a21bc0
+	} else { /* option->format[i] == 'R') */
a21bc0
+		/* R (destination descriptor) has variable length.
a21bc0
+		 * We can find it only in classless static route option,
a21bc0
+		 * so we are for sure parsing classless static route option now.
a21bc0
+		 * We go through whole the option to check whether there are no
a21bc0
+		 * missing/extra bytes.
a21bc0
+		 * I didn't find out how to improve the existing code and that's the
a21bc0
+		 * reason for this separate 'else' where I do my own checkings.
a21bc0
+		 * I know it's little bit unsystematic, but it works.
a21bc0
+		 */
a21bc0
+		numhunk = 0;
a21bc0
+		numelem = 2; /* RI */
a21bc0
+		fmtbuf[0]='R'; fmtbuf[1]='I'; fmtbuf[2]=0;
a21bc0
+		for (i =0; i < len; i = i + octets + 5) {
a21bc0
+			if (data[i] > 32) { /* subnet mask width */
a21bc0
+				log_error ("wrong subnet mask width in destination descriptor");
a21bc0
+				break;
a21bc0
+			}
a21bc0
+			numhunk++;
a21bc0
+			octets = ((data[i]+7) / 8);
a21bc0
+		}
a21bc0
+		if (i != len) {
a21bc0
+			log_error ("classless static routes option has wrong size or "
a21bc0
+					   "there's some garbage in format");
a21bc0
+		}
a21bc0
+	}
a21bc0
+
a21bc0
 	/* Cycle through the array (or hunk) printing the data. */
a21bc0
 	for (i = 0; i < numhunk; i++) {
c72a79
 		if ((a_array == ISC_TRUE) && (i != 0) && (numelem > 0)) {
7c0972
@@ -2159,6 +2192,20 @@ const char *pretty_print_option (option, data, len, emit_commas, emit_quotes)
a21bc0
 				strcpy(op, piaddr(iaddr));
a21bc0
 				dp += 4;
a21bc0
 				break;
a21bc0
+
a21bc0
+			      case 'R':
a21bc0
+				if (dp[0] <= 32)
a21bc0
+					iaddr.len = (((dp[0]+7)/8)+1);
a21bc0
+				else {
a21bc0
+					log_error ("wrong subnet mask width in destination descriptor");
a21bc0
+					return "<error>";
a21bc0
+				}
a21bc0
+
a21bc0
+				memcpy(iaddr.iabuf, dp, iaddr.len);
a21bc0
+				strcpy(op, pdestdesc(iaddr));
a21bc0
+				dp += iaddr.len;
a21bc0
+				break;
a21bc0
+
a21bc0
 			      case '6':
a21bc0
 				iaddr.len = 16;
a21bc0
 				memcpy(iaddr.iabuf, dp, 16);
7c0972
diff --git a/common/parse.c b/common/parse.c
7c0972
index 3ac4ebf..f17bc0b 100644
7c0972
--- a/common/parse.c
7c0972
+++ b/common/parse.c
7c0972
@@ -344,6 +344,39 @@ int parse_ip_addr (cfile, addr)
7c0972
 	return 0;
a21bc0
 }	
a21bc0
 
7c0972
+/*
a21bc0
+ * destination-descriptor :== NUMBER DOT NUMBER |
a21bc0
+ *                            NUMBER DOT NUMBER DOT NUMBER |
a21bc0
+ *                            NUMBER DOT NUMBER DOT NUMBER DOT NUMBER |
a21bc0
+ *                            NUMBER DOT NUMBER DOT NUMBER DOT NUMBER DOT NUMBER
a21bc0
+ */
a21bc0
+
a21bc0
+int parse_destination_descriptor (cfile, addr)
a21bc0
+	struct parse *cfile;
a21bc0
+	struct iaddr *addr;
a21bc0
+{
a21bc0
+		unsigned int mask_width, dest_dest_len;
a21bc0
+		addr -> len = 0;
a21bc0
+		if (parse_numeric_aggregate (cfile, addr -> iabuf,
a21bc0
+									 &addr -> len, DOT, 10, 8)) {
a21bc0
+			mask_width = (unsigned int)addr->iabuf[0];
a21bc0
+			dest_dest_len = (((mask_width+7)/8)+1);
a21bc0
+			if (mask_width > 32) {
a21bc0
+				parse_warn (cfile,
a21bc0
+				"subnet mask width (%u) greater than 32.", mask_width);
a21bc0
+			}
a21bc0
+			else if (dest_dest_len != addr->len) {
a21bc0
+				parse_warn (cfile,
a21bc0
+				"destination descriptor with subnet mask width %u "
a21bc0
+				"should have %u octets, but has %u octets.",
a21bc0
+				mask_width, dest_dest_len, addr->len);
a21bc0
+			}
a21bc0
+
a21bc0
+			return 1;
a21bc0
+		}
a21bc0
+		return 0;
a21bc0
+}
a21bc0
+
7c0972
 /*
a21bc0
  * Return true if every character in the string is hexadecimal.
a21bc0
  */
7c0972
@@ -724,8 +757,10 @@ unsigned char *parse_numeric_aggregate (cfile, buf,
a21bc0
 		if (count) {
a21bc0
 			token = peek_token (&val, (unsigned *)0, cfile);
a21bc0
 			if (token != separator) {
a21bc0
-				if (!*max)
a21bc0
+				if (!*max) {
a21bc0
+					*max = count;
a21bc0
 					break;
a21bc0
+				}
a21bc0
 				if (token != RBRACE && token != LBRACE)
a21bc0
 					token = next_token (&val,
a21bc0
 							    (unsigned *)0,
7c0972
@@ -1672,6 +1707,9 @@ int parse_option_code_definition (cfile, option)
a21bc0
 	      case IP_ADDRESS:
a21bc0
 		type = 'I';
a21bc0
 		break;
a21bc0
+	      case DESTINATION_DESCRIPTOR:
a21bc0
+		type = 'R';
a21bc0
+		break;
a21bc0
 	      case IP6_ADDRESS:
a21bc0
 		type = '6';
a21bc0
 		break;
7c0972
@@ -5101,6 +5139,15 @@ int parse_option_token (rv, cfile, fmt, expr, uniform, lookups)
a21bc0
 		}
a21bc0
 		break;
a21bc0
 
a21bc0
+	      case 'R': /* destination descriptor */
a21bc0
+		if (!parse_destination_descriptor (cfile, &addr)) {
a21bc0
+			return 0;
a21bc0
+		}
a21bc0
+		if (!make_const_data (&t, addr.iabuf, addr.len, 0, 1, MDL)) {
a21bc0
+			return 0;
a21bc0
+		}
a21bc0
+		break;
a21bc0
+
a21bc0
 	      case '6': /* IPv6 address. */
a21bc0
 		if (!parse_ip6_addr(cfile, &addr)) {
a21bc0
 			return 0;
7c0972
@@ -5378,6 +5425,13 @@ int parse_option_decl (oc, cfile)
a21bc0
 					goto exit;
a21bc0
 				len = ip_addr.len;
a21bc0
 				dp = ip_addr.iabuf;
a21bc0
+				goto alloc;
a21bc0
+
a21bc0
+			      case 'R': /* destination descriptor */
a21bc0
+				if (!parse_destination_descriptor (cfile, &ip_addr))
a21bc0
+					goto exit;
a21bc0
+				len = ip_addr.len;
a21bc0
+				dp = ip_addr.iabuf;
a21bc0
 
a21bc0
 			      alloc:
a21bc0
 				if (hunkix + len > sizeof hunkbuf) {
7c0972
diff --git a/common/tables.c b/common/tables.c
7c0972
index d2294c0..f1be07d 100644
7c0972
--- a/common/tables.c
7c0972
+++ b/common/tables.c
7c0972
@@ -45,6 +45,7 @@ HASH_FUNCTIONS (option_code, const unsigned *, struct option,
a21bc0
    Format codes:
a21bc0
 
a21bc0
    I - IPv4 address
a21bc0
+   R - destination descriptor (RFC3442)
a21bc0
    6 - IPv6 address
a21bc0
    l - 32-bit signed integer
a21bc0
    L - 32-bit unsigned integer
8173a6
@@ -216,6 +217,7 @@ static struct option dhcp_options[] = {
90936e
 #endif
a21bc0
 	{ "subnet-selection", "I",		&dhcp_universe, 118, 1 },
90936e
 	{ "domain-search", "D",			&dhcp_universe, 119, 1 },
a21bc0
+	{ "classless-static-routes", "RIA",	&dhcp_universe, 121, 1 },
a21bc0
 	{ "vivco", "Evendor-class.",		&dhcp_universe, 124, 1 },
a21bc0
 	{ "vivso", "Evendor.",			&dhcp_universe, 125, 1 },
a21bc0
 #if 0
7c0972
diff --git a/includes/dhcp.h b/includes/dhcp.h
7c0972
index 0a74137..95bf539 100644
7c0972
--- a/includes/dhcp.h
7c0972
+++ b/includes/dhcp.h
7c0972
@@ -158,6 +158,7 @@ struct dhcp_packet {
7c0972
 #define DHO_ASSOCIATED_IP			92
7c0972
 #define DHO_SUBNET_SELECTION			118 /* RFC3011! */
7c0972
 #define DHO_DOMAIN_SEARCH			119 /* RFC3397 */
7c0972
+#define DHO_CLASSLESS_STATIC_ROUTES		121 /* RFC3442 */
7c0972
 #define DHO_VIVCO_SUBOPTIONS			124
7c0972
 #define DHO_VIVSO_SUBOPTIONS			125
7c0972
 
7c0972
diff --git a/includes/dhcpd.h b/includes/dhcpd.h
7c0972
index 3632a6b..2ac39ae 100644
7c0972
--- a/includes/dhcpd.h
7c0972
+++ b/includes/dhcpd.h
7c0972
@@ -2951,6 +2951,7 @@ isc_result_t range2cidr(struct iaddrcidrnetlist **result,
a21bc0
 			const struct iaddr *lo, const struct iaddr *hi);
a21bc0
 isc_result_t free_iaddrcidrnetlist(struct iaddrcidrnetlist **result);
bb77af
 const char *piaddr (struct iaddr);
bb77af
+const char *pdestdesc (struct iaddr);
a21bc0
 char *piaddrmask(struct iaddr *, struct iaddr *);
a21bc0
 char *piaddrcidr(const struct iaddr *, unsigned int);
a21bc0
 u_int16_t validate_port(char *);
7c0972
@@ -3169,6 +3170,7 @@ void parse_client_lease_declaration (struct parse *,
bb77af
 int parse_option_decl (struct option_cache **, struct parse *);
bb77af
 void parse_string_list (struct parse *, struct string_list **, int);
bb77af
 int parse_ip_addr (struct parse *, struct iaddr *);
bb77af
+int parse_destination_descriptor (struct parse *, struct iaddr *);
a21bc0
 int parse_ip_addr_with_subnet(struct parse *, struct iaddrmatch *);
bb77af
 void parse_reject_statement (struct parse *, struct client_config *);
a21bc0
 
7c0972
diff --git a/includes/dhctoken.h b/includes/dhctoken.h
7c0972
index 7e7215a..b4d93ba 100644
7c0972
--- a/includes/dhctoken.h
7c0972
+++ b/includes/dhctoken.h
7c0972
@@ -376,8 +376,9 @@ enum dhcp_token {
8173a6
 	LEASE_ID_FORMAT = 676,
8173a6
 	TOKEN_HEX = 677,
8173a6
 	TOKEN_OCTAL = 678,
7c0972
-	KEY_ALGORITHM = 679
7c0972
-        BOOTP_BROADCAST_ALWAYS = 680
7c0972
+	KEY_ALGORITHM = 679,
7c0972
+        BOOTP_BROADCAST_ALWAYS = 680,
7c0972
+	DESTINATION_DESCRIPTOR = 681
a21bc0
 };
a21bc0
 
a21bc0
 #define is_identifier(x)	((x) >= FIRST_TOKEN &&	\
7c0972
-- 
7c0972
2.14.5
7c0972