1 /* SPDX-License-Identifier: MIT */
3 * QEMU BOOTP/DHCP server
5 * Copyright (c) 2004 Fabrice Bellard
7 * Permission is hereby granted, free of charge, to any person obtaining a copy
8 * of this software and associated documentation files (the "Software"), to deal
9 * in the Software without restriction, including without limitation the rights
10 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
11 * copies of the Software, and to permit persons to whom the Software is
12 * furnished to do so, subject to the following conditions:
14 * The above copyright notice and this permission notice shall be included in
15 * all copies or substantial portions of the Software.
17 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
18 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
19 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
20 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
21 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
22 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
28 /* Windows ntohl() returns an u_long value.
29 * Add a type cast to match the format strings. */
30 # define ntohl(n) ((uint32_t)ntohl(n))
33 /* XXX: only DHCP is supported */
35 #define LEASE_TIME (24 * 3600)
37 static const uint8_t rfc1533_cookie[] = { RFC1533_COOKIE };
39 #define DPRINTF(fmt, ...) DEBUG_CALL(fmt, ##__VA_ARGS__)
41 static BOOTPClient *get_new_addr(Slirp *slirp, struct in_addr *paddr,
42 const uint8_t *macaddr)
47 for(i = 0; i < NB_BOOTP_CLIENTS; i++) {
48 bc = &slirp->bootp_clients[i];
49 if (!bc->allocated || !memcmp(macaddr, bc->macaddr, 6))
54 bc = &slirp->bootp_clients[i];
56 paddr->s_addr = slirp->vdhcp_startaddr.s_addr + htonl(i);
60 static BOOTPClient *request_addr(Slirp *slirp, const struct in_addr *paddr,
61 const uint8_t *macaddr)
63 uint32_t req_addr = ntohl(paddr->s_addr);
64 uint32_t dhcp_addr = ntohl(slirp->vdhcp_startaddr.s_addr);
67 if (req_addr >= dhcp_addr &&
68 req_addr < (dhcp_addr + NB_BOOTP_CLIENTS)) {
69 bc = &slirp->bootp_clients[req_addr - dhcp_addr];
70 if (!bc->allocated || !memcmp(macaddr, bc->macaddr, 6)) {
78 static BOOTPClient *find_addr(Slirp *slirp, struct in_addr *paddr,
79 const uint8_t *macaddr)
84 for(i = 0; i < NB_BOOTP_CLIENTS; i++) {
85 if (!memcmp(macaddr, slirp->bootp_clients[i].macaddr, 6))
90 bc = &slirp->bootp_clients[i];
92 paddr->s_addr = slirp->vdhcp_startaddr.s_addr + htonl(i);
96 static void dhcp_decode(const struct bootp_t *bp, int *pmsg_type,
97 struct in_addr *preq_addr)
99 const uint8_t *p, *p_end;
103 preq_addr->s_addr = htonl(0L);
106 p_end = p + DHCP_OPT_LEN;
107 if (memcmp(p, rfc1533_cookie, 4) != 0)
112 if (tag == RFC1533_PAD) {
114 } else if (tag == RFC1533_END) {
121 if (p + len > p_end) {
124 DPRINTF("dhcp: tag=%d len=%d\n", tag, len);
127 case RFC2132_MSG_TYPE:
131 case RFC2132_REQ_ADDR:
133 memcpy(&(preq_addr->s_addr), p, 4);
142 if (*pmsg_type == DHCPREQUEST && preq_addr->s_addr == htonl(0L) &&
143 bp->bp_ciaddr.s_addr) {
144 memcpy(&(preq_addr->s_addr), &bp->bp_ciaddr, 4);
148 static void bootp_reply(Slirp *slirp, const struct bootp_t *bp)
150 BOOTPClient *bc = NULL;
153 struct sockaddr_in saddr, daddr;
154 struct in_addr preq_addr;
155 int dhcp_msg_type, val;
158 uint8_t client_ethaddr[ETH_ALEN];
160 /* extract exact DHCP msg type */
161 dhcp_decode(bp, &dhcp_msg_type, &preq_addr);
162 DPRINTF("bootp packet op=%d msgtype=%d", bp->bp_op, dhcp_msg_type);
163 if (preq_addr.s_addr != htonl(0L))
164 DPRINTF(" req_addr=%08" PRIx32 "\n", ntohl(preq_addr.s_addr));
169 if (dhcp_msg_type == 0)
170 dhcp_msg_type = DHCPREQUEST; /* Force reply for old BOOTP clients */
172 if (dhcp_msg_type != DHCPDISCOVER &&
173 dhcp_msg_type != DHCPREQUEST)
176 /* Get client's hardware address from bootp request */
177 memcpy(client_ethaddr, bp->bp_hwaddr, ETH_ALEN);
183 m->m_data += IF_MAXLINKHDR;
184 rbp = (struct bootp_t *)m->m_data;
185 m->m_data += sizeof(struct udpiphdr);
186 memset(rbp, 0, sizeof(struct bootp_t));
188 if (dhcp_msg_type == DHCPDISCOVER) {
189 if (preq_addr.s_addr != htonl(0L)) {
190 bc = request_addr(slirp, &preq_addr, client_ethaddr);
192 daddr.sin_addr = preq_addr;
197 bc = get_new_addr(slirp, &daddr.sin_addr, client_ethaddr);
199 DPRINTF("no address left\n");
203 memcpy(bc->macaddr, client_ethaddr, ETH_ALEN);
204 } else if (preq_addr.s_addr != htonl(0L)) {
205 bc = request_addr(slirp, &preq_addr, client_ethaddr);
207 daddr.sin_addr = preq_addr;
208 memcpy(bc->macaddr, client_ethaddr, ETH_ALEN);
210 /* DHCPNAKs should be sent to broadcast */
211 daddr.sin_addr.s_addr = 0xffffffff;
214 bc = find_addr(slirp, &daddr.sin_addr, bp->bp_hwaddr);
216 /* if never assigned, behaves as if it was already
217 assigned (windows fix because it remembers its address) */
222 /* Update ARP table for this IP address */
223 arp_table_add(slirp, daddr.sin_addr.s_addr, client_ethaddr);
225 saddr.sin_addr = slirp->vhost_addr;
226 saddr.sin_port = htons(BOOTP_SERVER);
228 daddr.sin_port = htons(BOOTP_CLIENT);
230 rbp->bp_op = BOOTP_REPLY;
231 rbp->bp_xid = bp->bp_xid;
234 memcpy(rbp->bp_hwaddr, bp->bp_hwaddr, ETH_ALEN);
236 rbp->bp_yiaddr = daddr.sin_addr; /* Client IP address */
237 rbp->bp_siaddr = saddr.sin_addr; /* Server IP address */
240 end = (uint8_t *)&rbp[1];
241 memcpy(q, rfc1533_cookie, 4);
245 DPRINTF("%s addr=%08" PRIx32 "\n",
246 (dhcp_msg_type == DHCPDISCOVER) ? "offered" : "ack'ed",
247 ntohl(daddr.sin_addr.s_addr));
249 if (dhcp_msg_type == DHCPDISCOVER) {
250 *q++ = RFC2132_MSG_TYPE;
253 } else /* DHCPREQUEST */ {
254 *q++ = RFC2132_MSG_TYPE;
259 if (slirp->bootp_filename)
260 snprintf((char *)rbp->bp_file, sizeof(rbp->bp_file), "%s",
261 slirp->bootp_filename);
263 *q++ = RFC2132_SRV_ID;
265 memcpy(q, &saddr.sin_addr, 4);
268 *q++ = RFC1533_NETMASK;
270 memcpy(q, &slirp->vnetwork_mask, 4);
273 if (!slirp->restricted) {
274 *q++ = RFC1533_GATEWAY;
276 memcpy(q, &saddr.sin_addr, 4);
281 memcpy(q, &slirp->vnameserver_addr, 4);
285 *q++ = RFC2132_LEASE_TIME;
287 val = htonl(LEASE_TIME);
291 if (*slirp->client_hostname) {
292 val = strlen(slirp->client_hostname);
293 if (q + val + 2 >= end) {
294 g_warning("DHCP packet size exceeded, "
295 "omitting host name option.");
297 *q++ = RFC1533_HOSTNAME;
299 memcpy(q, slirp->client_hostname, val);
304 if (slirp->vdomainname) {
305 val = strlen(slirp->vdomainname);
306 if (q + val + 2 >= end) {
307 g_warning("DHCP packet size exceeded, "
308 "omitting domain name option.");
310 *q++ = RFC1533_DOMAINNAME;
312 memcpy(q, slirp->vdomainname, val);
317 if (slirp->tftp_server_name) {
318 val = strlen(slirp->tftp_server_name);
319 if (q + val + 2 >= end) {
320 g_warning("DHCP packet size exceeded, "
321 "omitting tftp-server-name option.");
323 *q++ = RFC2132_TFTP_SERVER_NAME;
325 memcpy(q, slirp->tftp_server_name, val);
330 if (slirp->vdnssearch) {
331 val = slirp->vdnssearch_len;
332 if (q + val >= end) {
333 g_warning("DHCP packet size exceeded, "
334 "omitting domain-search option.");
336 memcpy(q, slirp->vdnssearch, val);
341 static const char nak_msg[] = "requested address not available";
343 DPRINTF("nak'ed addr=%08" PRIx32 "\n", ntohl(preq_addr.s_addr));
345 *q++ = RFC2132_MSG_TYPE;
349 *q++ = RFC2132_MESSAGE;
350 *q++ = sizeof(nak_msg) - 1;
351 memcpy(q, nak_msg, sizeof(nak_msg) - 1);
352 q += sizeof(nak_msg) - 1;
357 daddr.sin_addr.s_addr = 0xffffffffu;
359 m->m_len = sizeof(struct bootp_t) -
360 sizeof(struct ip) - sizeof(struct udphdr);
361 udp_output(NULL, m, &saddr, &daddr, IPTOS_LOWDELAY);
364 void bootp_input(struct mbuf *m)
366 struct bootp_t *bp = mtod(m, struct bootp_t *);
368 if (bp->bp_op == BOOTP_REQUEST) {
369 bootp_reply(m->slirp, bp);