gdhcp: Add option and length checks
[platform/upstream/connman.git] / gdhcp / client.c
1 /*
2  *
3  *  DHCP client library with GLib integration
4  *
5  *  Copyright (C) 2009-2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #define _GNU_SOURCE
27 #include <stdio.h>
28 #include <errno.h>
29 #include <unistd.h>
30 #include <stdlib.h>
31 #include <string.h>
32 #include <sys/ioctl.h>
33 #include <arpa/inet.h>
34
35 #include <netpacket/packet.h>
36 #include <netinet/if_ether.h>
37 #include <net/ethernet.h>
38
39 #include <linux/if.h>
40 #include <linux/filter.h>
41
42 #include <glib.h>
43
44 #include "gdhcp.h"
45 #include "common.h"
46 #include "ipv4ll.h"
47
48 #define DISCOVER_TIMEOUT 3
49 #define DISCOVER_RETRIES 10
50
51 #define REQUEST_TIMEOUT 3
52 #define REQUEST_RETRIES 5
53
54 typedef enum _listen_mode {
55         L_NONE,
56         L2,
57         L3,
58         L_ARP,
59 } ListenMode;
60
61 typedef enum _dhcp_client_state {
62         INIT_SELECTING,
63         REQUESTING,
64         BOUND,
65         RENEWING,
66         REBINDING,
67         RELEASED,
68         IPV4LL_PROBE,
69         IPV4LL_ANNOUNCE,
70         IPV4LL_MONITOR,
71         IPV4LL_DEFEND,
72         INFORMATION_REQ,
73         SOLICITATION,
74         REQUEST,
75         RENEW,
76         REBIND,
77         RELEASE,
78 } ClientState;
79
80 struct _GDHCPClient {
81         int ref_count;
82         GDHCPType type;
83         ClientState state;
84         int ifindex;
85         char *interface;
86         uint8_t mac_address[6];
87         uint32_t xid;
88         uint32_t server_ip;
89         uint32_t requested_ip;
90         char *assigned_ip;
91         time_t start;
92         uint32_t lease_seconds;
93         ListenMode listen_mode;
94         int listener_sockfd;
95         uint8_t retry_times;
96         uint8_t ack_retry_times;
97         uint8_t conflicts;
98         guint timeout;
99         guint listener_watch;
100         GIOChannel *listener_channel;
101         GList *require_list;
102         GList *request_list;
103         GHashTable *code_value_hash;
104         GHashTable *send_value_hash;
105         GDHCPClientEventFunc lease_available_cb;
106         gpointer lease_available_data;
107         GDHCPClientEventFunc ipv4ll_available_cb;
108         gpointer ipv4ll_available_data;
109         GDHCPClientEventFunc no_lease_cb;
110         gpointer no_lease_data;
111         GDHCPClientEventFunc lease_lost_cb;
112         gpointer lease_lost_data;
113         GDHCPClientEventFunc ipv4ll_lost_cb;
114         gpointer ipv4ll_lost_data;
115         GDHCPClientEventFunc address_conflict_cb;
116         gpointer address_conflict_data;
117         GDHCPDebugFunc debug_func;
118         gpointer debug_data;
119         GDHCPClientEventFunc information_req_cb;
120         gpointer information_req_data;
121         GDHCPClientEventFunc solicitation_cb;
122         gpointer solicitation_data;
123         GDHCPClientEventFunc advertise_cb;
124         gpointer advertise_data;
125         GDHCPClientEventFunc request_cb;
126         gpointer request_data;
127         GDHCPClientEventFunc renew_cb;
128         gpointer renew_data;
129         GDHCPClientEventFunc rebind_cb;
130         gpointer rebind_data;
131         GDHCPClientEventFunc release_cb;
132         gpointer release_data;
133         char *last_address;
134         unsigned char *duid;
135         int duid_len;
136         unsigned char *server_duid;
137         int server_duid_len;
138         uint16_t status_code;
139         uint32_t iaid;
140         uint32_t T1, T2;
141         struct in6_addr ia_na;
142         struct in6_addr ia_ta;
143         time_t last_renew;
144         time_t last_rebind;
145         time_t expire;
146 };
147
148 static inline void debug(GDHCPClient *client, const char *format, ...)
149 {
150         char str[256];
151         va_list ap;
152
153         if (client->debug_func == NULL)
154                 return;
155
156         va_start(ap, format);
157
158         if (vsnprintf(str, sizeof(str), format, ap) > 0)
159                 client->debug_func(str, client->debug_data);
160
161         va_end(ap);
162 }
163
164 /* Initialize the packet with the proper defaults */
165 static void init_packet(GDHCPClient *dhcp_client, gpointer pkt, char type)
166 {
167         if (dhcp_client->type == G_DHCP_IPV6)
168                 dhcpv6_init_header(pkt, type);
169         else {
170                 struct dhcp_packet *packet = pkt;
171
172                 dhcp_init_header(packet, type);
173                 memcpy(packet->chaddr, dhcp_client->mac_address, 6);
174         }
175 }
176
177 static void add_request_options(GDHCPClient *dhcp_client,
178                                 struct dhcp_packet *packet)
179 {
180         int len = 0;
181         GList *list;
182         uint8_t code;
183         int end = dhcp_end_option(packet->options);
184
185         for (list = dhcp_client->request_list; list; list = list->next) {
186                 code = (uint8_t) GPOINTER_TO_INT(list->data);
187
188                 packet->options[end + OPT_DATA + len] = code;
189                 len++;
190         }
191
192         if (len) {
193                 packet->options[end + OPT_CODE] = DHCP_PARAM_REQ;
194                 packet->options[end + OPT_LEN] = len;
195                 packet->options[end + OPT_DATA + len] = DHCP_END;
196         }
197 }
198
199 struct hash_params {
200         unsigned char *buf;
201         int max_buf;
202         unsigned char **ptr_buf;
203 };
204
205 static void add_dhcpv6_binary_option(gpointer key, gpointer value,
206                                         gpointer user_data)
207 {
208         uint8_t *option = value;
209         uint16_t len;
210         struct hash_params *params = user_data;
211
212         /* option[0][1] contains option code */
213         len = option[2] << 8 | option[3];
214
215         if ((*params->ptr_buf + len + 2 + 2) > (params->buf + params->max_buf))
216                 return;
217
218         memcpy(*params->ptr_buf, option, len + 2 + 2);
219         (*params->ptr_buf) += len + 2 + 2;
220 }
221
222 static void add_dhcpv6_send_options(GDHCPClient *dhcp_client,
223                                 unsigned char *buf, int max_buf,
224                                 unsigned char **ptr_buf)
225 {
226         struct hash_params params = {
227                 .buf = buf,
228                 .max_buf = max_buf,
229                 .ptr_buf = ptr_buf
230         };
231
232         if (dhcp_client->type == G_DHCP_IPV4)
233                 return;
234
235         g_hash_table_foreach(dhcp_client->send_value_hash,
236                                 add_dhcpv6_binary_option, &params);
237
238         *ptr_buf = *params.ptr_buf;
239 }
240
241 static void copy_option(uint8_t *buf, uint16_t code, uint16_t len,
242                         uint8_t *msg)
243 {
244         buf[0] = code >> 8;
245         buf[1] = code & 0xff;
246         buf[2] = len >> 8;
247         buf[3] = len & 0xff;
248         if (len > 0 && msg != NULL)
249                 memcpy(&buf[4], msg, len);
250 }
251
252 static void add_dhcpv6_request_options(GDHCPClient *dhcp_client,
253                                 struct dhcpv6_packet *packet,
254                                 unsigned char *buf, int max_buf,
255                                 unsigned char **ptr_buf)
256 {
257         GList *list;
258         uint16_t code;
259         int len;
260
261         if (dhcp_client->type == G_DHCP_IPV4)
262                 return;
263
264         for (list = dhcp_client->request_list; list; list = list->next) {
265                 code = (uint16_t) GPOINTER_TO_INT(list->data);
266
267                 switch (code) {
268                 case G_DHCPV6_CLIENTID:
269                         if (dhcp_client->duid == NULL)
270                                 return;
271
272                         len = 2 + 2 + dhcp_client->duid_len;
273                         if ((*ptr_buf + len) > (buf + max_buf)) {
274                                 debug(dhcp_client, "Too long dhcpv6 message "
275                                         "when writing client id option");
276                                 return;
277                         }
278
279                         copy_option(*ptr_buf, G_DHCPV6_CLIENTID,
280                                 dhcp_client->duid_len, dhcp_client->duid);
281                         (*ptr_buf) += len;
282                         break;
283
284                 case G_DHCPV6_SERVERID:
285                         if (dhcp_client->server_duid == NULL)
286                                 return;
287
288                         len = 2 + 2 + dhcp_client->server_duid_len;
289                         if ((*ptr_buf + len) > (buf + max_buf)) {
290                                 debug(dhcp_client, "Too long dhcpv6 message "
291                                         "when writing server id option");
292                                 return;
293                         }
294
295                         copy_option(*ptr_buf, G_DHCPV6_SERVERID,
296                                 dhcp_client->server_duid_len,
297                                 dhcp_client->server_duid);
298                         (*ptr_buf) += len;
299                         break;
300
301                 case G_DHCPV6_RAPID_COMMIT:
302                         len = 2 + 2;
303                         if ((*ptr_buf + len) > (buf + max_buf)) {
304                                 debug(dhcp_client, "Too long dhcpv6 message "
305                                         "when writing rapid commit option");
306                                 return;
307                         }
308
309                         copy_option(*ptr_buf, G_DHCPV6_RAPID_COMMIT, 0, 0);
310                         (*ptr_buf) += len;
311                         break;
312
313                 case G_DHCPV6_ORO:
314                         break;
315
316                 case G_DHCPV6_DNS_SERVERS:
317                         break;
318
319                 case G_DHCPV6_SNTP_SERVERS:
320                         break;
321
322                 default:
323                         break;
324                 }
325         }
326 }
327
328 static void add_binary_option(gpointer key, gpointer value, gpointer user_data)
329 {
330         uint8_t *option = value;
331         struct dhcp_packet *packet = user_data;
332
333         dhcp_add_binary_option(packet, option);
334 }
335
336 static void add_send_options(GDHCPClient *dhcp_client,
337                                 struct dhcp_packet *packet)
338 {
339         g_hash_table_foreach(dhcp_client->send_value_hash,
340                                 add_binary_option, packet);
341 }
342
343 /*
344  * Return an RFC 951- and 2131-complaint BOOTP 'secs' value that
345  * represents the number of seconds elapsed from the start of
346  * attempting DHCP to satisfy some DHCP servers that allow for an
347  * "authoritative" reply before responding.
348  */
349 static uint16_t dhcp_attempt_secs(GDHCPClient *dhcp_client)
350 {
351         return htons(MIN(time(NULL) - dhcp_client->start, UINT16_MAX));
352 }
353
354 static int send_discover(GDHCPClient *dhcp_client, uint32_t requested)
355 {
356         struct dhcp_packet packet;
357
358         debug(dhcp_client, "sending DHCP discover request");
359
360         init_packet(dhcp_client, &packet, DHCPDISCOVER);
361
362         packet.xid = dhcp_client->xid;
363         packet.secs = dhcp_attempt_secs(dhcp_client);
364
365         if (requested)
366                 dhcp_add_simple_option(&packet, DHCP_REQUESTED_IP, requested);
367
368         /* Explicitly saying that we want RFC-compliant packets helps
369          * some buggy DHCP servers to NOT send bigger packets */
370         dhcp_add_simple_option(&packet, DHCP_MAX_SIZE, htons(576));
371
372         add_request_options(dhcp_client, &packet);
373
374         add_send_options(dhcp_client, &packet);
375
376         return dhcp_send_raw_packet(&packet, INADDR_ANY, CLIENT_PORT,
377                                         INADDR_BROADCAST, SERVER_PORT,
378                                         MAC_BCAST_ADDR, dhcp_client->ifindex);
379 }
380
381 static int send_select(GDHCPClient *dhcp_client)
382 {
383         struct dhcp_packet packet;
384
385         debug(dhcp_client, "sending DHCP select request");
386
387         init_packet(dhcp_client, &packet, DHCPREQUEST);
388
389         packet.xid = dhcp_client->xid;
390         packet.secs = dhcp_attempt_secs(dhcp_client);
391
392         dhcp_add_simple_option(&packet, DHCP_REQUESTED_IP,
393                                         dhcp_client->requested_ip);
394         dhcp_add_simple_option(&packet, DHCP_SERVER_ID, dhcp_client->server_ip);
395
396         add_request_options(dhcp_client, &packet);
397
398         add_send_options(dhcp_client, &packet);
399
400         return dhcp_send_raw_packet(&packet, INADDR_ANY, CLIENT_PORT,
401                                         INADDR_BROADCAST, SERVER_PORT,
402                                         MAC_BCAST_ADDR, dhcp_client->ifindex);
403 }
404
405 static int send_renew(GDHCPClient *dhcp_client)
406 {
407         struct dhcp_packet packet;
408
409         debug(dhcp_client, "sending DHCP renew request");
410
411         init_packet(dhcp_client , &packet, DHCPREQUEST);
412         packet.xid = dhcp_client->xid;
413         packet.ciaddr = dhcp_client->requested_ip;
414
415         add_request_options(dhcp_client, &packet);
416
417         add_send_options(dhcp_client, &packet);
418
419         return dhcp_send_kernel_packet(&packet,
420                 dhcp_client->requested_ip, CLIENT_PORT,
421                 dhcp_client->server_ip, SERVER_PORT);
422 }
423
424 static int send_rebound(GDHCPClient *dhcp_client)
425 {
426         struct dhcp_packet packet;
427
428         debug(dhcp_client, "sending DHCP rebound request");
429
430         init_packet(dhcp_client , &packet, DHCPREQUEST);
431         packet.xid = dhcp_client->xid;
432         packet.ciaddr = dhcp_client->requested_ip;
433
434         add_request_options(dhcp_client, &packet);
435
436         add_send_options(dhcp_client, &packet);
437
438         return dhcp_send_raw_packet(&packet, INADDR_ANY, CLIENT_PORT,
439                                         INADDR_BROADCAST, SERVER_PORT,
440                                         MAC_BCAST_ADDR, dhcp_client->ifindex);
441 }
442
443 static int send_release(GDHCPClient *dhcp_client,
444                         uint32_t server, uint32_t ciaddr)
445 {
446         struct dhcp_packet packet;
447
448         debug(dhcp_client, "sending DHCP release request");
449
450         init_packet(dhcp_client, &packet, DHCPRELEASE);
451         packet.xid = rand();
452         packet.ciaddr = ciaddr;
453
454         dhcp_add_simple_option(&packet, DHCP_SERVER_ID, server);
455
456         return dhcp_send_kernel_packet(&packet, ciaddr, CLIENT_PORT,
457                                                 server, SERVER_PORT);
458 }
459
460 static gboolean ipv4ll_probe_timeout(gpointer dhcp_data);
461 static int switch_listening_mode(GDHCPClient *dhcp_client,
462                                         ListenMode listen_mode);
463
464 static gboolean send_probe_packet(gpointer dhcp_data)
465 {
466         GDHCPClient *dhcp_client;
467         guint timeout;
468
469         dhcp_client = dhcp_data;
470         /* if requested_ip is not valid, pick a new address*/
471         if (dhcp_client->requested_ip == 0) {
472                 debug(dhcp_client, "pick a new random address");
473                 dhcp_client->requested_ip = ipv4ll_random_ip(0);
474         }
475
476         debug(dhcp_client, "sending IPV4LL probe request");
477
478         if (dhcp_client->retry_times == 1) {
479                 dhcp_client->state = IPV4LL_PROBE;
480                 switch_listening_mode(dhcp_client, L_ARP);
481         }
482         ipv4ll_send_arp_packet(dhcp_client->mac_address, 0,
483                         dhcp_client->requested_ip, dhcp_client->ifindex);
484
485         if (dhcp_client->retry_times < PROBE_NUM) {
486                 /*add a random timeout in range of PROBE_MIN to PROBE_MAX*/
487                 timeout = ipv4ll_random_delay_ms(PROBE_MAX-PROBE_MIN);
488                 timeout += PROBE_MIN*1000;
489         } else
490                 timeout = (ANNOUNCE_WAIT * 1000);
491
492         dhcp_client->timeout = g_timeout_add_full(G_PRIORITY_HIGH,
493                                                  timeout,
494                                                  ipv4ll_probe_timeout,
495                                                  dhcp_client,
496                                                  NULL);
497         return FALSE;
498 }
499
500 static gboolean ipv4ll_announce_timeout(gpointer dhcp_data);
501 static gboolean ipv4ll_defend_timeout(gpointer dhcp_data);
502
503 static gboolean send_announce_packet(gpointer dhcp_data)
504 {
505         GDHCPClient *dhcp_client;
506
507         dhcp_client = dhcp_data;
508
509         debug(dhcp_client, "sending IPV4LL announce request");
510
511         ipv4ll_send_arp_packet(dhcp_client->mac_address,
512                                 dhcp_client->requested_ip,
513                                 dhcp_client->requested_ip,
514                                 dhcp_client->ifindex);
515
516         if (dhcp_client->timeout > 0)
517                 g_source_remove(dhcp_client->timeout);
518         dhcp_client->timeout = 0;
519
520         if (dhcp_client->state == IPV4LL_DEFEND) {
521                 dhcp_client->timeout =
522                         g_timeout_add_seconds_full(G_PRIORITY_HIGH,
523                                                 DEFEND_INTERVAL,
524                                                 ipv4ll_defend_timeout,
525                                                 dhcp_client,
526                                                 NULL);
527                 return TRUE;
528         } else
529                 dhcp_client->timeout =
530                         g_timeout_add_seconds_full(G_PRIORITY_HIGH,
531                                                 ANNOUNCE_INTERVAL,
532                                                 ipv4ll_announce_timeout,
533                                                 dhcp_client,
534                                                 NULL);
535         return TRUE;
536 }
537
538 static void get_interface_mac_address(int index, uint8_t *mac_address)
539 {
540         struct ifreq ifr;
541         int sk, err;
542
543         sk = socket(PF_INET, SOCK_DGRAM | SOCK_CLOEXEC, 0);
544         if (sk < 0) {
545                 perror("Open socket error");
546                 return;
547         }
548
549         memset(&ifr, 0, sizeof(ifr));
550         ifr.ifr_ifindex = index;
551
552         err = ioctl(sk, SIOCGIFNAME, &ifr);
553         if (err < 0) {
554                 perror("Get interface name error");
555                 goto done;
556         }
557
558         err = ioctl(sk, SIOCGIFHWADDR, &ifr);
559         if (err < 0) {
560                 perror("Get mac address error");
561                 goto done;
562         }
563
564         memcpy(mac_address, ifr.ifr_hwaddr.sa_data, 6);
565
566 done:
567         close(sk);
568 }
569
570 int g_dhcpv6_create_duid(GDHCPDuidType duid_type, int index, int type,
571                         unsigned char **duid, int *duid_len)
572 {
573         time_t duid_time;
574
575         switch (duid_type) {
576         case G_DHCPV6_DUID_LLT:
577                 *duid_len = 2 + 2 + 4 + ETH_ALEN;
578                 *duid = g_try_malloc(*duid_len);
579                 if (*duid == NULL)
580                         return -ENOMEM;
581
582                 (*duid)[0] = 0;
583                 (*duid)[1] = 1;
584                 get_interface_mac_address(index, &(*duid)[2 + 2 + 4]);
585                 (*duid)[2] = 0;
586                 (*duid)[3] = type;
587                 duid_time = time(NULL) - DUID_TIME_EPOCH;
588                 (*duid)[4] = duid_time >> 24;
589                 (*duid)[5] = duid_time >> 16;
590                 (*duid)[6] = duid_time >> 8;
591                 (*duid)[7] = duid_time & 0xff;
592                 break;
593         case G_DHCPV6_DUID_EN:
594                 return -EINVAL;
595         case G_DHCPV6_DUID_LL:
596                 *duid_len = 2 + 2 + ETH_ALEN;
597                 *duid = g_try_malloc(*duid_len);
598                 if (*duid == NULL)
599                         return -ENOMEM;
600
601                 (*duid)[0] = 0;
602                 (*duid)[1] = 3;
603                 get_interface_mac_address(index, &(*duid)[2 + 2]);
604                 (*duid)[2] = 0;
605                 (*duid)[3] = type;
606                 break;
607         }
608
609         return 0;
610 }
611
612 int g_dhcpv6_client_set_duid(GDHCPClient *dhcp_client, unsigned char *duid,
613                         int duid_len)
614 {
615         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
616                 return -EINVAL;
617
618         g_free(dhcp_client->duid);
619
620         dhcp_client->duid = duid;
621         dhcp_client->duid_len = duid_len;
622
623         return 0;
624 }
625
626 uint32_t g_dhcpv6_client_get_iaid(GDHCPClient *dhcp_client)
627 {
628         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
629                 return 0;
630
631         return dhcp_client->iaid;
632 }
633
634 void g_dhcpv6_client_create_iaid(GDHCPClient *dhcp_client, int index,
635                                 unsigned char *iaid)
636 {
637         uint8_t buf[6];
638
639         get_interface_mac_address(index, buf);
640
641         memcpy(iaid, &buf[2], 4);
642         dhcp_client->iaid = iaid[0] << 24 |
643                         iaid[1] << 16 | iaid[2] << 8 | iaid[3];
644 }
645
646 int g_dhcpv6_client_get_timeouts(GDHCPClient *dhcp_client,
647                                 uint32_t *T1, uint32_t *T2,
648                                 time_t *last_renew, time_t *last_rebind,
649                                 time_t *expire)
650 {
651         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
652                 return -EINVAL;
653
654         if (T1 != NULL)
655                 *T1 = dhcp_client->T1;
656
657         if (T2 != NULL)
658                 *T2 = dhcp_client->T2;
659
660         if (last_renew != NULL)
661                 *last_renew = dhcp_client->last_renew;
662
663         if (last_rebind != NULL)
664                 *last_rebind = dhcp_client->last_rebind;
665
666         if (expire != NULL)
667                 *expire = dhcp_client->expire;
668
669         return 0;
670 }
671
672 static uint8_t *create_iaaddr(GDHCPClient *dhcp_client, uint8_t *buf,
673                                 uint16_t len)
674 {
675         buf[0] = 0;
676         buf[1] = G_DHCPV6_IAADDR;
677         buf[2] = 0;
678         buf[3] = len;
679         memcpy(&buf[4], &dhcp_client->ia_na, 16);
680         memset(&buf[20], 0, 4); /* preferred */
681         memset(&buf[24], 0, 4); /* valid */
682         return buf;
683 }
684
685 static void put_iaid(GDHCPClient *dhcp_client, int index, uint8_t *buf)
686 {
687         uint32_t iaid;
688
689         iaid = g_dhcpv6_client_get_iaid(dhcp_client);
690         if (iaid == 0) {
691                 g_dhcpv6_client_create_iaid(dhcp_client, index, buf);
692                 return;
693         }
694
695         buf[0] = iaid >> 24;
696         buf[1] = iaid >> 16;
697         buf[2] = iaid >> 8;
698         buf[3] = iaid;
699 }
700
701 int g_dhcpv6_client_set_ia(GDHCPClient *dhcp_client, int index,
702                         int code, uint32_t *T1, uint32_t *T2,
703                         gboolean add_iaaddr)
704 {
705         if (code == G_DHCPV6_IA_TA) {
706                 uint8_t ia_options[4];
707
708                 put_iaid(dhcp_client, index, ia_options);
709
710                 g_dhcp_client_set_request(dhcp_client, G_DHCPV6_IA_TA);
711                 g_dhcpv6_client_set_send(dhcp_client, G_DHCPV6_IA_TA,
712                                         ia_options, sizeof(ia_options));
713
714         } else if (code == G_DHCPV6_IA_NA) {
715
716                 g_dhcp_client_set_request(dhcp_client, G_DHCPV6_IA_NA);
717
718                 if (add_iaaddr == TRUE) {
719 #define IAADDR_LEN (16+4+4)
720                         uint8_t ia_options[4+4+4+2+2+IAADDR_LEN];
721
722                         put_iaid(dhcp_client, index, ia_options);
723
724                         if (T1 != NULL) {
725                                 ia_options[4] = *T1 >> 24;
726                                 ia_options[5] = *T1 >> 16;
727                                 ia_options[6] = *T1 >> 8;
728                                 ia_options[7] = *T1;
729                         } else
730                                 memset(&ia_options[4], 0x00, 4);
731
732                         if (T2 != NULL) {
733                                 ia_options[8] = *T2 >> 24;
734                                 ia_options[9] = *T2 >> 16;
735                                 ia_options[10] = *T2 >> 8;
736                                 ia_options[11] = *T2;
737                         } else
738                                 memset(&ia_options[8], 0x00, 4);
739
740                         create_iaaddr(dhcp_client, &ia_options[12],
741                                         IAADDR_LEN);
742
743                         g_dhcpv6_client_set_send(dhcp_client, G_DHCPV6_IA_NA,
744                                         ia_options, sizeof(ia_options));
745                 } else {
746                         uint8_t ia_options[4+4+4];
747
748                         put_iaid(dhcp_client, index, ia_options);
749
750                         memset(&ia_options[4], 0x00, 4); /* T1 (4 bytes) */
751                         memset(&ia_options[8], 0x00, 4); /* T2 (4 bytes) */
752
753                         g_dhcpv6_client_set_send(dhcp_client, G_DHCPV6_IA_NA,
754                                         ia_options, sizeof(ia_options));
755                 }
756
757         } else
758                 return -EINVAL;
759
760         return 0;
761 }
762
763 int g_dhcpv6_client_set_oro(GDHCPClient *dhcp_client, int args, ...)
764 {
765         va_list va;
766         int i, j, len = sizeof(uint16_t) * args;
767         uint8_t *values;
768
769         values = g_try_malloc(len);
770         if (values == NULL)
771                 return -ENOMEM;
772
773         va_start(va, args);
774         for (i = 0, j = 0; i < args; i++) {
775                 uint16_t value = va_arg(va, int);
776                 values[j++] = value >> 8;
777                 values[j++] = value & 0xff;
778         }
779         va_end(va);
780
781         g_dhcpv6_client_set_send(dhcp_client, G_DHCPV6_ORO, values, len);
782
783         return 0;
784 }
785
786 static int send_dhcpv6_msg(GDHCPClient *dhcp_client, int type, char *msg)
787 {
788         struct dhcpv6_packet *packet;
789         uint8_t buf[MAX_DHCPV6_PKT_SIZE];
790         unsigned char *ptr;
791         int ret, max_buf;
792
793         memset(buf, 0, sizeof(buf));
794         packet = (struct dhcpv6_packet *)&buf[0];
795         ptr = buf + sizeof(struct dhcpv6_packet);
796
797         debug(dhcp_client, "sending DHCPv6 %s message", msg);
798
799         init_packet(dhcp_client, packet, type);
800
801         dhcp_client->xid = packet->transaction_id[0] << 16 |
802                         packet->transaction_id[1] << 8 |
803                         packet->transaction_id[2];
804
805         max_buf = MAX_DHCPV6_PKT_SIZE - sizeof(struct dhcpv6_packet);
806
807         add_dhcpv6_request_options(dhcp_client, packet, buf, max_buf, &ptr);
808
809         add_dhcpv6_send_options(dhcp_client, buf, max_buf, &ptr);
810
811         ret = dhcpv6_send_packet(dhcp_client->ifindex, packet, ptr - buf);
812
813         debug(dhcp_client, "sent %d pkt %p len %d", ret, packet, ptr - buf);
814         return ret;
815 }
816
817 static int send_solicitation(GDHCPClient *dhcp_client)
818 {
819         return send_dhcpv6_msg(dhcp_client, DHCPV6_SOLICIT, "solicit");
820 }
821
822 static int send_dhcpv6_request(GDHCPClient *dhcp_client)
823 {
824         return send_dhcpv6_msg(dhcp_client, DHCPV6_REQUEST, "request");
825 }
826
827 static int send_dhcpv6_renew(GDHCPClient *dhcp_client)
828 {
829         return send_dhcpv6_msg(dhcp_client, DHCPV6_RENEW, "renew");
830 }
831
832 static int send_dhcpv6_rebind(GDHCPClient *dhcp_client)
833 {
834         return send_dhcpv6_msg(dhcp_client, DHCPV6_REBIND, "rebind");
835 }
836
837 static int send_dhcpv6_release(GDHCPClient *dhcp_client)
838 {
839         return send_dhcpv6_msg(dhcp_client, DHCPV6_RELEASE, "release");
840 }
841
842 static int send_information_req(GDHCPClient *dhcp_client)
843 {
844         return send_dhcpv6_msg(dhcp_client, DHCPV6_INFORMATION_REQ,
845                                 "information-req");
846 }
847
848 static void remove_value(gpointer data, gpointer user_data)
849 {
850         char *value = data;
851         g_free(value);
852 }
853
854 static void remove_option_value(gpointer data)
855 {
856         GList *option_value = data;
857
858         g_list_foreach(option_value, remove_value, NULL);
859 }
860
861 GDHCPClient *g_dhcp_client_new(GDHCPType type,
862                         int ifindex, GDHCPClientError *error)
863 {
864         GDHCPClient *dhcp_client;
865
866         if (ifindex < 0) {
867                 *error = G_DHCP_CLIENT_ERROR_INVALID_INDEX;
868                 return NULL;
869         }
870
871         dhcp_client = g_try_new0(GDHCPClient, 1);
872         if (dhcp_client == NULL) {
873                 *error = G_DHCP_CLIENT_ERROR_NOMEM;
874                 return NULL;
875         }
876
877         dhcp_client->interface = get_interface_name(ifindex);
878         if (dhcp_client->interface == NULL) {
879                 *error = G_DHCP_CLIENT_ERROR_INTERFACE_UNAVAILABLE;
880                 goto error;
881         }
882
883         if (interface_is_up(ifindex) == FALSE) {
884                 *error = G_DHCP_CLIENT_ERROR_INTERFACE_DOWN;
885                 goto error;
886         }
887
888         get_interface_mac_address(ifindex, dhcp_client->mac_address);
889
890         dhcp_client->listener_sockfd = -1;
891         dhcp_client->listener_channel = NULL;
892         dhcp_client->listen_mode = L_NONE;
893         dhcp_client->ref_count = 1;
894         dhcp_client->type = type;
895         dhcp_client->ifindex = ifindex;
896         dhcp_client->lease_available_cb = NULL;
897         dhcp_client->ipv4ll_available_cb = NULL;
898         dhcp_client->no_lease_cb = NULL;
899         dhcp_client->lease_lost_cb = NULL;
900         dhcp_client->ipv4ll_lost_cb = NULL;
901         dhcp_client->address_conflict_cb = NULL;
902         dhcp_client->listener_watch = 0;
903         dhcp_client->retry_times = 0;
904         dhcp_client->ack_retry_times = 0;
905         dhcp_client->code_value_hash = g_hash_table_new_full(g_direct_hash,
906                                 g_direct_equal, NULL, remove_option_value);
907         dhcp_client->send_value_hash = g_hash_table_new_full(g_direct_hash,
908                                 g_direct_equal, NULL, g_free);
909         dhcp_client->request_list = NULL;
910         dhcp_client->require_list = NULL;
911         dhcp_client->duid = NULL;
912         dhcp_client->duid_len = 0;
913         dhcp_client->last_renew = dhcp_client->last_rebind = time(NULL);
914         dhcp_client->expire = 0;
915
916         *error = G_DHCP_CLIENT_ERROR_NONE;
917
918         return dhcp_client;
919
920 error:
921         g_free(dhcp_client->interface);
922         g_free(dhcp_client);
923         return NULL;
924 }
925
926 #define SERVER_AND_CLIENT_PORTS  ((67 << 16) + 68)
927
928 static int dhcp_l2_socket(int ifindex)
929 {
930         int fd;
931         struct sockaddr_ll sock;
932
933         /*
934          * Comment:
935          *
936          *      I've selected not to see LL header, so BPF doesn't see it, too.
937          *      The filter may also pass non-IP and non-ARP packets, but we do
938          *      a more complete check when receiving the message in userspace.
939          *
940          * and filter shamelessly stolen from:
941          *
942          *      http://www.flamewarmaster.de/software/dhcpclient/
943          *
944          * There are a few other interesting ideas on that page (look under
945          * "Motivation").  Use of netlink events is most interesting.  Think
946          * of various network servers listening for events and reconfiguring.
947          * That would obsolete sending HUP signals and/or make use of restarts.
948          *
949          * Copyright: 2006, 2007 Stefan Rompf <sux@loplof.de>.
950          * License: GPL v2.
951          *
952          * TODO: make conditional?
953          */
954         static const struct sock_filter filter_instr[] = {
955                 /* check for udp */
956                 BPF_STMT(BPF_LD|BPF_B|BPF_ABS, 9),
957                 /* L5, L1, is UDP? */
958                 BPF_JUMP(BPF_JMP|BPF_JEQ|BPF_K, IPPROTO_UDP, 2, 0),
959                 /* ugly check for arp on ethernet-like and IPv4 */
960                 BPF_STMT(BPF_LD|BPF_W|BPF_ABS, 2), /* L1: */
961                 BPF_JUMP(BPF_JMP|BPF_JEQ|BPF_K, 0x08000604, 3, 4),/* L3, L4 */
962                 /* skip IP header */
963                 BPF_STMT(BPF_LDX|BPF_B|BPF_MSH, 0), /* L5: */
964                 /* check udp source and destination ports */
965                 BPF_STMT(BPF_LD|BPF_W|BPF_IND, 0),
966                 /* L3, L4 */
967                 BPF_JUMP(BPF_JMP|BPF_JEQ|BPF_K, SERVER_AND_CLIENT_PORTS, 0, 1),
968                 /* returns */
969                 BPF_STMT(BPF_RET|BPF_K, 0x0fffffff), /* L3: pass */
970                 BPF_STMT(BPF_RET|BPF_K, 0), /* L4: reject */
971         };
972
973         static const struct sock_fprog filter_prog = {
974                 .len = sizeof(filter_instr) / sizeof(filter_instr[0]),
975                 /* casting const away: */
976                 .filter = (struct sock_filter *) filter_instr,
977         };
978
979         fd = socket(PF_PACKET, SOCK_DGRAM | SOCK_CLOEXEC, htons(ETH_P_IP));
980         if (fd < 0)
981                 return fd;
982
983         if (SERVER_PORT == 67 && CLIENT_PORT == 68)
984                 /* Use only if standard ports are in use */
985                 setsockopt(fd, SOL_SOCKET, SO_ATTACH_FILTER, &filter_prog,
986                                                         sizeof(filter_prog));
987
988         memset(&sock, 0, sizeof(sock));
989         sock.sll_family = AF_PACKET;
990         sock.sll_protocol = htons(ETH_P_IP);
991         sock.sll_ifindex = ifindex;
992
993         if (bind(fd, (struct sockaddr *) &sock, sizeof(sock)) != 0) {
994                 close(fd);
995                 return -errno;
996         }
997
998         return fd;
999 }
1000
1001 static gboolean sanity_check(struct ip_udp_dhcp_packet *packet, int bytes)
1002 {
1003         if (packet->ip.protocol != IPPROTO_UDP)
1004                 return FALSE;
1005
1006         if (packet->ip.version != IPVERSION)
1007                 return FALSE;
1008
1009         if (packet->ip.ihl != sizeof(packet->ip) >> 2)
1010                 return FALSE;
1011
1012         if (packet->udp.dest != htons(CLIENT_PORT))
1013                 return FALSE;
1014
1015         if (ntohs(packet->udp.len) != (uint16_t)(bytes - sizeof(packet->ip)))
1016                 return FALSE;
1017
1018         return TRUE;
1019 }
1020
1021 static int dhcp_recv_l2_packet(struct dhcp_packet *dhcp_pkt, int fd)
1022 {
1023         int bytes;
1024         struct ip_udp_dhcp_packet packet;
1025         uint16_t check;
1026
1027         memset(&packet, 0, sizeof(packet));
1028
1029         bytes = read(fd, &packet, sizeof(packet));
1030         if (bytes < 0)
1031                 return -1;
1032
1033         if (bytes < (int) (sizeof(packet.ip) + sizeof(packet.udp)))
1034                 return -1;
1035
1036         if (bytes < ntohs(packet.ip.tot_len))
1037                 /* packet is bigger than sizeof(packet), we did partial read */
1038                 return -1;
1039
1040         /* ignore any extra garbage bytes */
1041         bytes = ntohs(packet.ip.tot_len);
1042
1043         if (sanity_check(&packet, bytes) == FALSE)
1044                 return -1;
1045
1046         check = packet.ip.check;
1047         packet.ip.check = 0;
1048         if (check != dhcp_checksum(&packet.ip, sizeof(packet.ip)))
1049                 return -1;
1050
1051         /* verify UDP checksum. IP header has to be modified for this */
1052         memset(&packet.ip, 0, offsetof(struct iphdr, protocol));
1053         /* ip.xx fields which are not memset: protocol, check, saddr, daddr */
1054         packet.ip.tot_len = packet.udp.len; /* yes, this is needed */
1055         check = packet.udp.check;
1056         packet.udp.check = 0;
1057         if (check && check != dhcp_checksum(&packet, bytes))
1058                 return -1;
1059
1060         memcpy(dhcp_pkt, &packet.data, bytes - (sizeof(packet.ip) +
1061                                                         sizeof(packet.udp)));
1062
1063         if (dhcp_pkt->cookie != htonl(DHCP_MAGIC))
1064                 return -1;
1065
1066         return bytes - (sizeof(packet.ip) + sizeof(packet.udp));
1067 }
1068
1069 static void ipv4ll_start(GDHCPClient *dhcp_client)
1070 {
1071         guint timeout;
1072         int seed;
1073
1074         if (dhcp_client->timeout > 0) {
1075                 g_source_remove(dhcp_client->timeout);
1076                 dhcp_client->timeout = 0;
1077         }
1078
1079         switch_listening_mode(dhcp_client, L_NONE);
1080         dhcp_client->type = G_DHCP_IPV4LL;
1081         dhcp_client->retry_times = 0;
1082         dhcp_client->requested_ip = 0;
1083
1084         /*try to start with a based mac address ip*/
1085         seed = (dhcp_client->mac_address[4] << 8 | dhcp_client->mac_address[4]);
1086         dhcp_client->requested_ip = ipv4ll_random_ip(seed);
1087
1088         /*first wait a random delay to avoid storm of arp request on boot*/
1089         timeout = ipv4ll_random_delay_ms(PROBE_WAIT);
1090
1091         dhcp_client->retry_times++;
1092         dhcp_client->timeout = g_timeout_add_full(G_PRIORITY_HIGH,
1093                                                 timeout,
1094                                                 send_probe_packet,
1095                                                 dhcp_client,
1096                                                 NULL);
1097 }
1098
1099 static void ipv4ll_stop(GDHCPClient *dhcp_client)
1100 {
1101
1102         switch_listening_mode(dhcp_client, L_NONE);
1103
1104         if (dhcp_client->timeout > 0)
1105                 g_source_remove(dhcp_client->timeout);
1106
1107         if (dhcp_client->listener_watch > 0) {
1108                 g_source_remove(dhcp_client->listener_watch);
1109                 dhcp_client->listener_watch = 0;
1110         }
1111
1112         dhcp_client->state = IPV4LL_PROBE;
1113         dhcp_client->retry_times = 0;
1114         dhcp_client->requested_ip = 0;
1115
1116         g_free(dhcp_client->assigned_ip);
1117         dhcp_client->assigned_ip = NULL;
1118 }
1119
1120 static int ipv4ll_recv_arp_packet(GDHCPClient *dhcp_client)
1121 {
1122         int bytes;
1123         struct ether_arp arp;
1124         uint32_t ip_requested;
1125         int source_conflict;
1126         int target_conflict;
1127
1128         memset(&arp, 0, sizeof(arp));
1129         bytes = 0;
1130         bytes = read(dhcp_client->listener_sockfd, &arp, sizeof(arp));
1131         if (bytes < 0)
1132                 return bytes;
1133
1134         if (arp.arp_op != htons(ARPOP_REPLY) &&
1135                         arp.arp_op != htons(ARPOP_REQUEST))
1136                 return -EINVAL;
1137
1138         ip_requested = ntohl(dhcp_client->requested_ip);
1139         source_conflict = !memcmp(arp.arp_spa, &ip_requested,
1140                                                 sizeof(ip_requested));
1141
1142         target_conflict = !memcmp(arp.arp_tpa, &ip_requested,
1143                                 sizeof(ip_requested));
1144
1145         if (!source_conflict && !target_conflict)
1146                 return 0;
1147
1148         dhcp_client->conflicts++;
1149
1150         debug(dhcp_client, "IPV4LL conflict detected");
1151
1152         if (dhcp_client->state == IPV4LL_MONITOR) {
1153                 if (!source_conflict)
1154                         return 0;
1155                 dhcp_client->state = IPV4LL_DEFEND;
1156                 debug(dhcp_client, "DEFEND mode conflicts : %d",
1157                         dhcp_client->conflicts);
1158                 /*Try to defend with a single announce*/
1159                 send_announce_packet(dhcp_client);
1160                 return 0;
1161         }
1162
1163         if (dhcp_client->state == IPV4LL_DEFEND) {
1164                 if (!source_conflict)
1165                         return 0;
1166                 else if (dhcp_client->ipv4ll_lost_cb != NULL)
1167                         dhcp_client->ipv4ll_lost_cb(dhcp_client,
1168                                                 dhcp_client->ipv4ll_lost_data);
1169         }
1170
1171         ipv4ll_stop(dhcp_client);
1172
1173         if (dhcp_client->conflicts < MAX_CONFLICTS) {
1174                 /*restart whole state machine*/
1175                 dhcp_client->retry_times++;
1176                 dhcp_client->timeout =
1177                         g_timeout_add_full(G_PRIORITY_HIGH,
1178                                         ipv4ll_random_delay_ms(PROBE_WAIT),
1179                                         send_probe_packet,
1180                                         dhcp_client,
1181                                         NULL);
1182         }
1183         /* Here we got a lot of conflicts, RFC3927 states that we have
1184          * to wait RATE_LIMIT_INTERVAL before retrying,
1185          * but we just report failure.
1186          */
1187         else if (dhcp_client->no_lease_cb != NULL)
1188                         dhcp_client->no_lease_cb(dhcp_client,
1189                                                 dhcp_client->no_lease_data);
1190
1191         return 0;
1192 }
1193
1194 static gboolean check_package_owner(GDHCPClient *dhcp_client, gpointer pkt)
1195 {
1196         if (dhcp_client->type == G_DHCP_IPV6) {
1197                 struct dhcpv6_packet *packet6 = pkt;
1198                 uint32_t xid;
1199
1200                 if (packet6 == NULL)
1201                         return FALSE;
1202
1203                 xid = packet6->transaction_id[0] << 16 |
1204                         packet6->transaction_id[1] << 8 |
1205                         packet6->transaction_id[2];
1206
1207                 if (xid != dhcp_client->xid)
1208                         return FALSE;
1209         } else {
1210                 struct dhcp_packet *packet = pkt;
1211
1212                 if (packet->xid != dhcp_client->xid)
1213                         return FALSE;
1214
1215                 if (packet->hlen != 6)
1216                         return FALSE;
1217
1218                 if (memcmp(packet->chaddr, dhcp_client->mac_address, 6))
1219                         return FALSE;
1220         }
1221
1222         return TRUE;
1223 }
1224
1225 static void start_request(GDHCPClient *dhcp_client);
1226
1227 static gboolean request_timeout(gpointer user_data)
1228 {
1229         GDHCPClient *dhcp_client = user_data;
1230
1231         debug(dhcp_client, "request timeout (retries %d)",
1232                                         dhcp_client->retry_times);
1233
1234         dhcp_client->retry_times++;
1235
1236         start_request(dhcp_client);
1237
1238         return FALSE;
1239 }
1240
1241 static gboolean listener_event(GIOChannel *channel, GIOCondition condition,
1242                                                         gpointer user_data);
1243
1244 static int switch_listening_mode(GDHCPClient *dhcp_client,
1245                                         ListenMode listen_mode)
1246 {
1247         GIOChannel *listener_channel;
1248         int listener_sockfd;
1249
1250         if (dhcp_client->listen_mode == listen_mode)
1251                 return 0;
1252
1253         debug(dhcp_client, "switch listening mode (%d ==> %d)",
1254                                 dhcp_client->listen_mode, listen_mode);
1255
1256         if (dhcp_client->listen_mode != L_NONE) {
1257                 if (dhcp_client->listener_watch > 0)
1258                         g_source_remove(dhcp_client->listener_watch);
1259                 dhcp_client->listener_channel = NULL;
1260                 dhcp_client->listen_mode = L_NONE;
1261                 dhcp_client->listener_sockfd = -1;
1262                 dhcp_client->listener_watch = 0;
1263         }
1264
1265         if (listen_mode == L_NONE)
1266                 return 0;
1267
1268         if (listen_mode == L2)
1269                 listener_sockfd = dhcp_l2_socket(dhcp_client->ifindex);
1270         else if (listen_mode == L3) {
1271                 if (dhcp_client->type == G_DHCP_IPV6)
1272                         listener_sockfd = dhcp_l3_socket(DHCPV6_CLIENT_PORT,
1273                                                         dhcp_client->interface,
1274                                                         AF_INET6);
1275                 else
1276                         listener_sockfd = dhcp_l3_socket(CLIENT_PORT,
1277                                                         dhcp_client->interface,
1278                                                         AF_INET);
1279         } else if (listen_mode == L_ARP)
1280                 listener_sockfd = ipv4ll_arp_socket(dhcp_client->ifindex);
1281         else
1282                 return -EIO;
1283
1284         if (listener_sockfd < 0)
1285                 return -EIO;
1286
1287         listener_channel = g_io_channel_unix_new(listener_sockfd);
1288         if (listener_channel == NULL) {
1289                 /* Failed to create listener channel */
1290                 close(listener_sockfd);
1291                 return -EIO;
1292         }
1293
1294         dhcp_client->listen_mode = listen_mode;
1295         dhcp_client->listener_sockfd = listener_sockfd;
1296         dhcp_client->listener_channel = listener_channel;
1297
1298         g_io_channel_set_close_on_unref(listener_channel, TRUE);
1299         dhcp_client->listener_watch =
1300                         g_io_add_watch_full(listener_channel, G_PRIORITY_HIGH,
1301                                 G_IO_IN | G_IO_NVAL | G_IO_ERR | G_IO_HUP,
1302                                                 listener_event, dhcp_client,
1303                                                                 NULL);
1304         g_io_channel_unref(dhcp_client->listener_channel);
1305
1306         return 0;
1307 }
1308
1309 static void start_request(GDHCPClient *dhcp_client)
1310 {
1311         debug(dhcp_client, "start request (retries %d)",
1312                                         dhcp_client->retry_times);
1313
1314         if (dhcp_client->retry_times == REQUEST_RETRIES) {
1315                 dhcp_client->state = INIT_SELECTING;
1316                 ipv4ll_start(dhcp_client);
1317
1318                 return;
1319         }
1320
1321         if (dhcp_client->retry_times == 0) {
1322                 dhcp_client->state = REQUESTING;
1323                 switch_listening_mode(dhcp_client, L2);
1324         }
1325
1326         send_select(dhcp_client);
1327
1328         dhcp_client->timeout = g_timeout_add_seconds_full(G_PRIORITY_HIGH,
1329                                                         REQUEST_TIMEOUT,
1330                                                         request_timeout,
1331                                                         dhcp_client,
1332                                                         NULL);
1333 }
1334
1335 static uint32_t get_lease(struct dhcp_packet *packet)
1336 {
1337         uint8_t *option_u8;
1338         uint32_t lease_seconds;
1339
1340         option_u8 = dhcp_get_option(packet, DHCP_LEASE_TIME);
1341         if (option_u8 == NULL)
1342                 return 3600;
1343
1344         lease_seconds = dhcp_get_unaligned((uint32_t *) option_u8);
1345         lease_seconds = ntohl(lease_seconds);
1346         /* paranoia: must not be prone to overflows */
1347         lease_seconds &= 0x0fffffff;
1348         if (lease_seconds < 10)
1349                 lease_seconds = 10;
1350
1351         return lease_seconds;
1352 }
1353
1354 static void restart_dhcp(GDHCPClient *dhcp_client, int retry_times)
1355 {
1356         debug(dhcp_client, "restart DHCP (retries %d)", retry_times);
1357
1358         if (dhcp_client->timeout > 0) {
1359                 g_source_remove(dhcp_client->timeout);
1360                 dhcp_client->timeout = 0;
1361         }
1362
1363         dhcp_client->retry_times = retry_times;
1364         dhcp_client->requested_ip = 0;
1365         switch_listening_mode(dhcp_client, L2);
1366
1367         g_dhcp_client_start(dhcp_client, dhcp_client->last_address);
1368 }
1369
1370 static gboolean start_rebound_timeout(gpointer user_data)
1371 {
1372         GDHCPClient *dhcp_client = user_data;
1373
1374         debug(dhcp_client, "start rebound timeout");
1375
1376         switch_listening_mode(dhcp_client, L2);
1377
1378         dhcp_client->lease_seconds >>= 1;
1379
1380         /* We need to have enough time to receive ACK package*/
1381         if (dhcp_client->lease_seconds <= 6) {
1382
1383                 /* ip need to be cleared */
1384                 if (dhcp_client->lease_lost_cb != NULL)
1385                         dhcp_client->lease_lost_cb(dhcp_client,
1386                                         dhcp_client->lease_lost_data);
1387
1388                 restart_dhcp(dhcp_client, 0);
1389         } else {
1390                 send_rebound(dhcp_client);
1391
1392                 dhcp_client->timeout =
1393                                 g_timeout_add_seconds_full(G_PRIORITY_HIGH,
1394                                                 dhcp_client->lease_seconds >> 1,
1395                                                         start_rebound_timeout,
1396                                                                 dhcp_client,
1397                                                                 NULL);
1398         }
1399
1400         return FALSE;
1401 }
1402
1403 static void start_rebound(GDHCPClient *dhcp_client)
1404 {
1405         debug(dhcp_client, "start rebound");
1406
1407         dhcp_client->state = REBINDING;
1408
1409         dhcp_client->timeout = g_timeout_add_seconds_full(G_PRIORITY_HIGH,
1410                                                 dhcp_client->lease_seconds >> 1,
1411                                                         start_rebound_timeout,
1412                                                                 dhcp_client,
1413                                                                 NULL);
1414 }
1415
1416 static gboolean start_renew_timeout(gpointer user_data)
1417 {
1418         GDHCPClient *dhcp_client = user_data;
1419
1420         debug(dhcp_client, "start renew timeout");
1421
1422         dhcp_client->state = RENEWING;
1423
1424         dhcp_client->lease_seconds >>= 1;
1425
1426         switch_listening_mode(dhcp_client, L3);
1427         if (dhcp_client->lease_seconds <= 60)
1428                 start_rebound(dhcp_client);
1429         else {
1430                 send_renew(dhcp_client);
1431
1432                 if (dhcp_client->timeout > 0)
1433                         g_source_remove(dhcp_client->timeout);
1434
1435                 dhcp_client->timeout =
1436                                 g_timeout_add_seconds_full(G_PRIORITY_HIGH,
1437                                                 dhcp_client->lease_seconds >> 1,
1438                                                         start_renew_timeout,
1439                                                                 dhcp_client,
1440                                                                 NULL);
1441         }
1442
1443         return FALSE;
1444 }
1445
1446 static void start_bound(GDHCPClient *dhcp_client)
1447 {
1448         debug(dhcp_client, "start bound");
1449
1450         dhcp_client->state = BOUND;
1451
1452         if (dhcp_client->timeout > 0)
1453                 g_source_remove(dhcp_client->timeout);
1454
1455         dhcp_client->timeout = g_timeout_add_seconds_full(G_PRIORITY_HIGH,
1456                                         dhcp_client->lease_seconds >> 1,
1457                                         start_renew_timeout, dhcp_client,
1458                                                         NULL);
1459 }
1460
1461 static gboolean restart_dhcp_timeout(gpointer user_data)
1462 {
1463         GDHCPClient *dhcp_client = user_data;
1464
1465         debug(dhcp_client, "restart DHCP timeout");
1466
1467         dhcp_client->ack_retry_times++;
1468
1469         restart_dhcp(dhcp_client, dhcp_client->ack_retry_times);
1470
1471         return FALSE;
1472 }
1473
1474 static char *get_ip(uint32_t ip)
1475 {
1476         struct in_addr addr;
1477
1478         addr.s_addr = ip;
1479
1480         return g_strdup(inet_ntoa(addr));
1481 }
1482
1483 /* get a rough idea of how long an option will be */
1484 static const uint8_t len_of_option_as_string[] = {
1485         [OPTION_IP] = sizeof("255.255.255.255 "),
1486         [OPTION_STRING] = 1,
1487         [OPTION_U8] = sizeof("255 "),
1488         [OPTION_U16] = sizeof("65535 "),
1489         [OPTION_U32] = sizeof("4294967295 "),
1490 };
1491
1492 static int sprint_nip(char *dest, const char *pre, const uint8_t *ip)
1493 {
1494         return sprintf(dest, "%s%u.%u.%u.%u", pre, ip[0], ip[1], ip[2], ip[3]);
1495 }
1496
1497 /* Create "opt_value1 option_value2 ..." string */
1498 static char *malloc_option_value_string(uint8_t *option, GDHCPOptionType type)
1499 {
1500         unsigned upper_length;
1501         int len, optlen;
1502         char *dest, *ret;
1503
1504         len = option[OPT_LEN - OPT_DATA];
1505         type &= OPTION_TYPE_MASK;
1506         optlen = dhcp_option_lengths[type];
1507         if (optlen == 0)
1508                 return NULL;
1509         upper_length = len_of_option_as_string[type] *
1510                         ((unsigned)len / (unsigned)optlen);
1511         dest = ret = malloc(upper_length + 1);
1512         if (ret == NULL)
1513                 return NULL;
1514
1515         while (len >= optlen) {
1516                 switch (type) {
1517                 case OPTION_IP:
1518                         dest += sprint_nip(dest, "", option);
1519                         break;
1520                 case OPTION_U16: {
1521                         uint16_t val_u16 = dhcp_get_unaligned(
1522                                                 (uint16_t *) option);
1523                         dest += sprintf(dest, "%u", ntohs(val_u16));
1524                         break;
1525                 }
1526                 case OPTION_U32: {
1527                         uint32_t val_u32 = dhcp_get_unaligned(
1528                                                 (uint32_t *) option);
1529                         dest += sprintf(dest, type == OPTION_U32 ? "%lu" :
1530                                         "%ld", (unsigned long) ntohl(val_u32));
1531                         break;
1532                 }
1533                 case OPTION_STRING:
1534                         memcpy(dest, option, len);
1535                         dest[len] = '\0';
1536                         return ret;
1537                 default:
1538                         break;
1539                 }
1540                 option += optlen;
1541                 len -= optlen;
1542                 if (len <= 0)
1543                         break;
1544                 *dest++ = ' ';
1545                 *dest = '\0';
1546         }
1547
1548         return ret;
1549 }
1550
1551 static GList *get_option_value_list(char *value, GDHCPOptionType type)
1552 {
1553         char *pos = value;
1554         GList *list = NULL;
1555
1556         if (pos == NULL)
1557                 return NULL;
1558
1559         if (type == OPTION_STRING)
1560                 return g_list_append(list, g_strdup(value));
1561
1562         while ((pos = strchr(pos, ' ')) != NULL) {
1563                 *pos = '\0';
1564
1565                 list = g_list_append(list, g_strdup(value));
1566
1567                 value = ++pos;
1568         }
1569
1570         list = g_list_append(list, g_strdup(value));
1571
1572         return list;
1573 }
1574
1575 static inline uint32_t get_uint32(unsigned char *value)
1576 {
1577         return value[0] << 24 | value[1] << 16 |
1578                 value[2] << 8 | value[3];
1579 }
1580
1581 static inline uint16_t get_uint16(unsigned char *value)
1582 {
1583         return value[0] << 8 | value[1];
1584 }
1585
1586 static GList *get_addresses(GDHCPClient *dhcp_client,
1587                                 int code, int len,
1588                                 unsigned char *value,
1589                                 uint16_t *status)
1590 {
1591         GList *list = NULL;
1592         struct in6_addr addr;
1593         uint32_t iaid, T1 = 0, T2 = 0, preferred = 0, valid = 0;
1594         uint16_t option_len, option_code, st = 0, max_len;
1595         int addr_count = 0, i, pos;
1596         uint8_t *option;
1597         char *str;
1598
1599         if (value == NULL || len < 4)
1600                 return NULL;
1601
1602         iaid = get_uint32(&value[0]);
1603         if (dhcp_client->iaid != iaid)
1604                 return NULL;
1605
1606         if (code == G_DHCPV6_IA_NA) {
1607                 T1 = get_uint32(&value[4]);
1608                 T2 = get_uint32(&value[8]);
1609
1610                 if (T1 > T2)
1611                         /* RFC 3315, 22.4 */
1612                         return NULL;
1613
1614                 pos = 12;
1615         } else
1616                 pos = 4;
1617
1618         if (len <= pos)
1619                 return NULL;
1620
1621         max_len = len - pos;
1622
1623         /* We have more sub-options in this packet. */
1624         do {
1625                 option = dhcpv6_get_sub_option(&value[pos], max_len,
1626                                         &option_code, &option_len);
1627
1628                 debug(dhcp_client, "pos %d option %p code %d len %d",
1629                         pos, option, option_code, option_len);
1630
1631                 if (option == NULL)
1632                         break;
1633
1634                 if (pos >= max_len)
1635                         break;
1636
1637                 switch (option_code) {
1638                 case G_DHCPV6_IAADDR:
1639                         i = 0;
1640                         memcpy(&addr, &option[0], sizeof(addr));
1641                         i += sizeof(addr);
1642                         preferred = get_uint32(&option[i]);
1643                         i += 4;
1644                         valid = get_uint32(&option[i]);
1645
1646                         addr_count++;
1647                         break;
1648
1649                 case G_DHCPV6_STATUS_CODE:
1650                         st = get_uint16(&option[0]);
1651                         debug(dhcp_client, "error code %d", st);
1652                         if (option_len > 2) {
1653                                 str = g_strndup((gchar *)&option[2],
1654                                                 option_len - 2);
1655                                 debug(dhcp_client, "error text: %s", str);
1656                                 g_free(str);
1657                         }
1658
1659                         *status = st;
1660                         break;
1661                 }
1662
1663                 pos += 2 + 2 + option_len;
1664
1665         } while (option != NULL);
1666
1667         if (addr_count > 0 && st == 0) {
1668                 /* We only support one address atm */
1669                 char str[INET6_ADDRSTRLEN + 1];
1670
1671                 if (preferred > valid)
1672                         /* RFC 3315, 22.6 */
1673                         return NULL;
1674
1675                 dhcp_client->T1 = T1;
1676                 dhcp_client->T2 = T2;
1677
1678                 inet_ntop(AF_INET6, &addr, str, INET6_ADDRSTRLEN);
1679                 debug(dhcp_client, "count %d addr %s T1 %u T2 %u",
1680                         addr_count, str, T1, T2);
1681
1682                 list = g_list_append(list, g_strdup(str));
1683
1684                 if (code == G_DHCPV6_IA_NA)
1685                         memcpy(&dhcp_client->ia_na, &addr,
1686                                                 sizeof(struct in6_addr));
1687                 else
1688                         memcpy(&dhcp_client->ia_ta, &addr,
1689                                                 sizeof(struct in6_addr));
1690
1691                 g_dhcpv6_client_set_expire(dhcp_client, valid);
1692         }
1693
1694         return list;
1695 }
1696
1697 static GList *get_dhcpv6_option_value_list(GDHCPClient *dhcp_client,
1698                                         int code, int len,
1699                                         unsigned char *value,
1700                                         uint16_t *status)
1701 {
1702         GList *list = NULL;
1703         char *str;
1704         int i;
1705
1706         if (value == NULL)
1707                 return NULL;
1708
1709         switch (code) {
1710         case G_DHCPV6_DNS_SERVERS:      /* RFC 3646, chapter 3 */
1711         case G_DHCPV6_SNTP_SERVERS:     /* RFC 4075, chapter 4 */
1712                 if (len % 16) {
1713                         debug(dhcp_client,
1714                                 "%s server list length (%d) is invalid",
1715                                 code == G_DHCPV6_DNS_SERVERS ? "DNS" : "SNTP",
1716                                 len);
1717                         return NULL;
1718                 }
1719                 for (i = 0; i < len; i += 16) {
1720
1721                         str = g_try_malloc0(INET6_ADDRSTRLEN+1);
1722                         if (str == NULL)
1723                                 return list;
1724
1725                         if (inet_ntop(AF_INET6, &value[i], str,
1726                                         INET6_ADDRSTRLEN) == NULL)
1727                                 g_free(str);
1728                         else
1729                                 list = g_list_append(list, str);
1730                 }
1731                 break;
1732
1733         case G_DHCPV6_IA_NA:            /* RFC 3315, chapter 22.4 */
1734         case G_DHCPV6_IA_TA:            /* RFC 3315, chapter 22.5 */
1735                 list = get_addresses(dhcp_client, code, len, value, status);
1736                 break;
1737
1738         default:
1739                 break;
1740         }
1741
1742         return list;
1743 }
1744
1745 static void get_dhcpv6_request(GDHCPClient *dhcp_client,
1746                                 struct dhcpv6_packet *packet,
1747                                 uint16_t pkt_len, uint16_t *status)
1748 {
1749         GList *list, *value_list;
1750         uint8_t *option;
1751         uint16_t code;
1752         uint16_t option_len;
1753
1754         for (list = dhcp_client->request_list; list; list = list->next) {
1755                 code = (uint16_t) GPOINTER_TO_INT(list->data);
1756
1757                 option = dhcpv6_get_option(packet, pkt_len, code, &option_len,
1758                                                 NULL);
1759                 if (option == NULL) {
1760                         g_hash_table_remove(dhcp_client->code_value_hash,
1761                                                 GINT_TO_POINTER((int) code));
1762                         continue;
1763                 }
1764
1765                 value_list = get_dhcpv6_option_value_list(dhcp_client, code,
1766                                                 option_len, option, status);
1767
1768                 debug(dhcp_client, "code %d %p len %d list %p", code, option,
1769                         option_len, value_list);
1770
1771                 if (value_list == NULL)
1772                         g_hash_table_remove(dhcp_client->code_value_hash,
1773                                                 GINT_TO_POINTER((int) code));
1774                 else
1775                         g_hash_table_insert(dhcp_client->code_value_hash,
1776                                 GINT_TO_POINTER((int) code), value_list);
1777         }
1778 }
1779
1780 static void get_request(GDHCPClient *dhcp_client, struct dhcp_packet *packet)
1781 {
1782         GDHCPOptionType type;
1783         GList *list, *value_list;
1784         char *option_value;
1785         uint8_t *option;
1786         uint8_t code;
1787
1788         for (list = dhcp_client->request_list; list; list = list->next) {
1789                 code = (uint8_t) GPOINTER_TO_INT(list->data);
1790
1791                 option = dhcp_get_option(packet, code);
1792                 if (option == NULL) {
1793                         g_hash_table_remove(dhcp_client->code_value_hash,
1794                                                 GINT_TO_POINTER((int) code));
1795                         continue;
1796                 }
1797
1798                 type =  dhcp_get_code_type(code);
1799
1800                 option_value = malloc_option_value_string(option, type);
1801                 if (option_value == NULL)
1802                         g_hash_table_remove(dhcp_client->code_value_hash,
1803                                                 GINT_TO_POINTER((int) code));
1804
1805                 value_list = get_option_value_list(option_value, type);
1806
1807                 g_free(option_value);
1808
1809                 if (value_list == NULL)
1810                         g_hash_table_remove(dhcp_client->code_value_hash,
1811                                                 GINT_TO_POINTER((int) code));
1812                 else
1813                         g_hash_table_insert(dhcp_client->code_value_hash,
1814                                 GINT_TO_POINTER((int) code), value_list);
1815         }
1816 }
1817
1818 static gboolean listener_event(GIOChannel *channel, GIOCondition condition,
1819                                                         gpointer user_data)
1820 {
1821         GDHCPClient *dhcp_client = user_data;
1822         struct dhcp_packet packet;
1823         struct dhcpv6_packet *packet6 = NULL;
1824         uint8_t *message_type = NULL, *client_id = NULL, *option_u8,
1825                 *server_id = NULL;
1826         uint16_t option_len = 0, status = 0;
1827         gpointer pkt;
1828         unsigned char buf[MAX_DHCPV6_PKT_SIZE];
1829         uint16_t pkt_len = 0;
1830         int count;
1831         int re;
1832
1833         if (condition & (G_IO_NVAL | G_IO_ERR | G_IO_HUP)) {
1834                 dhcp_client->listener_watch = 0;
1835                 return FALSE;
1836         }
1837
1838         if (dhcp_client->listen_mode == L_NONE)
1839                 return FALSE;
1840
1841         pkt = &packet;
1842
1843         if (dhcp_client->listen_mode == L2)
1844                 re = dhcp_recv_l2_packet(&packet,
1845                                         dhcp_client->listener_sockfd);
1846         else if (dhcp_client->listen_mode == L3) {
1847                 if (dhcp_client->type == G_DHCP_IPV6) {
1848                         re = dhcpv6_recv_l3_packet(&packet6, buf, sizeof(buf),
1849                                                 dhcp_client->listener_sockfd);
1850                         pkt_len = re;
1851                         pkt = packet6;
1852                 } else
1853                         re = dhcp_recv_l3_packet(&packet,
1854                                                 dhcp_client->listener_sockfd);
1855         } else if (dhcp_client->listen_mode == L_ARP) {
1856                 re = ipv4ll_recv_arp_packet(dhcp_client);
1857                 return TRUE;
1858         }
1859         else
1860                 re = -EIO;
1861
1862         if (re < 0)
1863                 return TRUE;
1864
1865         if (check_package_owner(dhcp_client, pkt) == FALSE)
1866                 return TRUE;
1867
1868         if (dhcp_client->type == G_DHCP_IPV6) {
1869                 count = 0;
1870                 client_id = dhcpv6_get_option(packet6, pkt_len,
1871                                 G_DHCPV6_CLIENTID, &option_len, &count);
1872
1873                 if (client_id == NULL || count == 0 || option_len == 0 ||
1874                                 memcmp(dhcp_client->duid, client_id,
1875                                         dhcp_client->duid_len) != 0) {
1876                         debug(dhcp_client,
1877                                 "client duid error, discarding msg %p/%d/%d",
1878                                 client_id, option_len, count);
1879                         return TRUE;
1880                 }
1881
1882                 option_u8 = dhcpv6_get_option(packet6, pkt_len,
1883                                 G_DHCPV6_STATUS_CODE, &option_len, NULL);
1884                 if (option_u8 != 0 && option_len > 0) {
1885                         status = option_u8[0]<<8 | option_u8[1];
1886                         if (status != 0) {
1887                                 debug(dhcp_client, "error code %d", status);
1888                                 if (option_len > 2) {
1889                                         gchar *txt = g_strndup(
1890                                                 (gchar *)&option_u8[2],
1891                                                 option_len - 2);
1892                                         debug(dhcp_client, "error text: %s",
1893                                                 txt);
1894                                         g_free(txt);
1895                                 }
1896                         }
1897                         dhcp_client->status_code = status;
1898                 } else
1899                         dhcp_client->status_code = 0;
1900
1901         } else
1902                 message_type = dhcp_get_option(&packet, DHCP_MESSAGE_TYPE);
1903
1904         if (message_type == NULL && client_id == NULL)
1905                 /* No message type / client id option, ignore package */
1906                 return TRUE;
1907
1908         debug(dhcp_client, "received DHCP packet (current state %d)",
1909                                                         dhcp_client->state);
1910
1911         switch (dhcp_client->state) {
1912         case INIT_SELECTING:
1913                 if (*message_type != DHCPOFFER)
1914                         return TRUE;
1915
1916                 g_source_remove(dhcp_client->timeout);
1917                 dhcp_client->timeout = 0;
1918                 dhcp_client->retry_times = 0;
1919
1920                 option_u8 = dhcp_get_option(&packet, DHCP_SERVER_ID);
1921                 dhcp_client->server_ip =
1922                                 dhcp_get_unaligned((uint32_t *) option_u8);
1923                 dhcp_client->requested_ip = packet.yiaddr;
1924
1925                 dhcp_client->state = REQUESTING;
1926
1927                 start_request(dhcp_client);
1928
1929                 return TRUE;
1930         case REQUESTING:
1931         case RENEWING:
1932         case REBINDING:
1933                 if (*message_type == DHCPACK) {
1934                         dhcp_client->retry_times = 0;
1935
1936                         if (dhcp_client->timeout > 0)
1937                                 g_source_remove(dhcp_client->timeout);
1938                         dhcp_client->timeout = 0;
1939
1940                         dhcp_client->lease_seconds = get_lease(&packet);
1941
1942                         get_request(dhcp_client, &packet);
1943
1944                         switch_listening_mode(dhcp_client, L_NONE);
1945
1946                         g_free(dhcp_client->assigned_ip);
1947                         dhcp_client->assigned_ip = get_ip(packet.yiaddr);
1948
1949                         /* Address should be set up here */
1950                         if (dhcp_client->lease_available_cb != NULL)
1951                                 dhcp_client->lease_available_cb(dhcp_client,
1952                                         dhcp_client->lease_available_data);
1953
1954                         start_bound(dhcp_client);
1955                 } else if (*message_type == DHCPNAK) {
1956                         dhcp_client->retry_times = 0;
1957
1958                         if (dhcp_client->timeout > 0)
1959                                 g_source_remove(dhcp_client->timeout);
1960
1961                         dhcp_client->timeout = g_timeout_add_seconds_full(
1962                                                         G_PRIORITY_HIGH, 3,
1963                                                         restart_dhcp_timeout,
1964                                                         dhcp_client,
1965                                                         NULL);
1966                 }
1967
1968                 break;
1969         case SOLICITATION:
1970                 if (dhcp_client->type != G_DHCP_IPV6)
1971                         return TRUE;
1972
1973                 if (packet6->message != DHCPV6_REPLY &&
1974                                 packet6->message != DHCPV6_ADVERTISE)
1975                         return TRUE;
1976
1977                 count = 0;
1978                 server_id = dhcpv6_get_option(packet6, pkt_len,
1979                                 G_DHCPV6_SERVERID, &option_len, &count);
1980                 if (server_id == NULL || count != 1 || option_len == 0) {
1981                         /* RFC 3315, 15.10 */
1982                         debug(dhcp_client,
1983                                 "server duid error, discarding msg %p/%d/%d",
1984                                 server_id, option_len, count);
1985                         return TRUE;
1986                 }
1987                 dhcp_client->server_duid = g_try_malloc(option_len);
1988                 if (dhcp_client->server_duid == NULL)
1989                         return TRUE;
1990                 memcpy(dhcp_client->server_duid, server_id, option_len);
1991                 dhcp_client->server_duid_len = option_len;
1992
1993                 if (packet6->message == DHCPV6_REPLY) {
1994                         uint8_t *rapid_commit;
1995                         count = 0;
1996                         option_len = 0;
1997                         rapid_commit = dhcpv6_get_option(packet6, pkt_len,
1998                                                         G_DHCPV6_RAPID_COMMIT,
1999                                                         &option_len, &count);
2000                         if (rapid_commit == NULL || option_len == 0 ||
2001                                                                 count != 1)
2002                                 /* RFC 3315, 17.1.4 */
2003                                 return TRUE;
2004                 }
2005
2006                 switch_listening_mode(dhcp_client, L_NONE);
2007
2008                 if (dhcp_client->status_code == 0)
2009                         get_dhcpv6_request(dhcp_client, packet6, pkt_len,
2010                                         &dhcp_client->status_code);
2011
2012                 if (packet6->message == DHCPV6_ADVERTISE) {
2013                         if (dhcp_client->advertise_cb != NULL)
2014                                 dhcp_client->advertise_cb(dhcp_client,
2015                                                 dhcp_client->advertise_data);
2016                         return TRUE;
2017                 }
2018
2019                 if (dhcp_client->solicitation_cb != NULL) {
2020                         /*
2021                          * The dhcp_client might not be valid after the
2022                          * callback call so just return immediately.
2023                          */
2024                         dhcp_client->solicitation_cb(dhcp_client,
2025                                         dhcp_client->solicitation_data);
2026                         return TRUE;
2027                 }
2028                 break;
2029         case INFORMATION_REQ:
2030         case REQUEST:
2031         case RENEW:
2032         case REBIND:
2033         case RELEASE:
2034                 if (dhcp_client->type != G_DHCP_IPV6)
2035                         return TRUE;
2036
2037                 if (packet6->message != DHCPV6_REPLY)
2038                         return TRUE;
2039
2040                 count = 0;
2041                 option_len = 0;
2042                 server_id = dhcpv6_get_option(packet6, pkt_len,
2043                                 G_DHCPV6_SERVERID, &option_len, &count);
2044                 if (server_id == NULL || count != 1 || option_len == 0 ||
2045                                 (dhcp_client->server_duid_len > 0 &&
2046                                 memcmp(dhcp_client->server_duid, server_id,
2047                                         dhcp_client->server_duid_len) != 0)) {
2048                         /* RFC 3315, 15.10 */
2049                         debug(dhcp_client,
2050                                 "server duid error, discarding msg %p/%d/%d",
2051                                 server_id, option_len, count);
2052                         return TRUE;
2053                 }
2054
2055                 switch_listening_mode(dhcp_client, L_NONE);
2056
2057                 dhcp_client->status_code = 0;
2058                 get_dhcpv6_request(dhcp_client, packet6, pkt_len,
2059                                                 &dhcp_client->status_code);
2060
2061                 if (dhcp_client->information_req_cb != NULL) {
2062                         /*
2063                          * The dhcp_client might not be valid after the
2064                          * callback call so just return immediately.
2065                          */
2066                         dhcp_client->information_req_cb(dhcp_client,
2067                                         dhcp_client->information_req_data);
2068                         return TRUE;
2069                 }
2070                 if (dhcp_client->request_cb != NULL) {
2071                         dhcp_client->request_cb(dhcp_client,
2072                                         dhcp_client->request_data);
2073                         return TRUE;
2074                 }
2075                 if (dhcp_client->renew_cb != NULL) {
2076                         dhcp_client->renew_cb(dhcp_client,
2077                                         dhcp_client->renew_data);
2078                         return TRUE;
2079                 }
2080                 if (dhcp_client->rebind_cb != NULL) {
2081                         dhcp_client->rebind_cb(dhcp_client,
2082                                         dhcp_client->rebind_data);
2083                         return TRUE;
2084                 }
2085                 if (dhcp_client->release_cb != NULL) {
2086                         dhcp_client->release_cb(dhcp_client,
2087                                         dhcp_client->release_data);
2088                         return TRUE;
2089                 }
2090                 break;
2091         default:
2092                 break;
2093         }
2094
2095         debug(dhcp_client, "processed DHCP packet (new state %d)",
2096                                                         dhcp_client->state);
2097
2098         return TRUE;
2099 }
2100
2101 static gboolean discover_timeout(gpointer user_data)
2102 {
2103         GDHCPClient *dhcp_client = user_data;
2104
2105         dhcp_client->retry_times++;
2106
2107         /*
2108          * We do not send the REQUESTED IP option if we are retrying because
2109          * if the server is non-authoritative it will ignore the request if the
2110          * option is present.
2111          */
2112         g_dhcp_client_start(dhcp_client, NULL);
2113
2114         return FALSE;
2115 }
2116
2117 static gboolean ipv4ll_defend_timeout(gpointer dhcp_data)
2118 {
2119         GDHCPClient *dhcp_client = dhcp_data;
2120
2121         debug(dhcp_client, "back to MONITOR mode");
2122
2123         dhcp_client->conflicts = 0;
2124         dhcp_client->state = IPV4LL_MONITOR;
2125
2126         return FALSE;
2127 }
2128
2129 static gboolean ipv4ll_announce_timeout(gpointer dhcp_data)
2130 {
2131         GDHCPClient *dhcp_client = dhcp_data;
2132         uint32_t ip;
2133
2134         debug(dhcp_client, "request timeout (retries %d)",
2135                dhcp_client->retry_times);
2136
2137         if (dhcp_client->retry_times != ANNOUNCE_NUM){
2138                 dhcp_client->retry_times++;
2139                 send_announce_packet(dhcp_client);
2140                 return FALSE;
2141         }
2142
2143         ip = htonl(dhcp_client->requested_ip);
2144         debug(dhcp_client, "switching to monitor mode");
2145         dhcp_client->state = IPV4LL_MONITOR;
2146         dhcp_client->assigned_ip = get_ip(ip);
2147
2148         if (dhcp_client->ipv4ll_available_cb != NULL)
2149                 dhcp_client->ipv4ll_available_cb(dhcp_client,
2150                                         dhcp_client->ipv4ll_available_data);
2151         dhcp_client->conflicts = 0;
2152
2153         return FALSE;
2154 }
2155
2156 static gboolean ipv4ll_probe_timeout(gpointer dhcp_data)
2157 {
2158
2159         GDHCPClient *dhcp_client = dhcp_data;
2160
2161         debug(dhcp_client, "IPV4LL probe timeout (retries %d)",
2162                dhcp_client->retry_times);
2163
2164         if (dhcp_client->retry_times == PROBE_NUM) {
2165                 dhcp_client->state = IPV4LL_ANNOUNCE;
2166                 dhcp_client->retry_times = 0;
2167
2168                 dhcp_client->retry_times++;
2169                 send_announce_packet(dhcp_client);
2170                 return FALSE;
2171         }
2172         dhcp_client->retry_times++;
2173         send_probe_packet(dhcp_client);
2174
2175         return FALSE;
2176 }
2177
2178 int g_dhcp_client_start(GDHCPClient *dhcp_client, const char *last_address)
2179 {
2180         int re;
2181         uint32_t addr;
2182
2183         if (dhcp_client->type == G_DHCP_IPV6) {
2184                 if (dhcp_client->information_req_cb) {
2185                         dhcp_client->state = INFORMATION_REQ;
2186                         re = switch_listening_mode(dhcp_client, L3);
2187                         if (re != 0) {
2188                                 switch_listening_mode(dhcp_client, L_NONE);
2189                                 dhcp_client->state = 0;
2190                                 return re;
2191                         }
2192                         send_information_req(dhcp_client);
2193
2194                 } else if (dhcp_client->solicitation_cb) {
2195                         dhcp_client->state = SOLICITATION;
2196                         re = switch_listening_mode(dhcp_client, L3);
2197                         if (re != 0) {
2198                                 switch_listening_mode(dhcp_client, L_NONE);
2199                                 dhcp_client->state = 0;
2200                                 return re;
2201                         }
2202                         send_solicitation(dhcp_client);
2203
2204                 } else if (dhcp_client->request_cb) {
2205                         dhcp_client->state = REQUEST;
2206                         re = switch_listening_mode(dhcp_client, L3);
2207                         if (re != 0) {
2208                                 switch_listening_mode(dhcp_client, L_NONE);
2209                                 dhcp_client->state = 0;
2210                                 return re;
2211                         }
2212                         send_dhcpv6_request(dhcp_client);
2213
2214                 } else if (dhcp_client->renew_cb) {
2215                         dhcp_client->state = RENEW;
2216                         re = switch_listening_mode(dhcp_client, L3);
2217                         if (re != 0) {
2218                                 switch_listening_mode(dhcp_client, L_NONE);
2219                                 dhcp_client->state = 0;
2220                                 return re;
2221                         }
2222                         send_dhcpv6_renew(dhcp_client);
2223
2224                 } else if (dhcp_client->rebind_cb) {
2225                         dhcp_client->state = REBIND;
2226                         re = switch_listening_mode(dhcp_client, L3);
2227                         if (re != 0) {
2228                                 switch_listening_mode(dhcp_client, L_NONE);
2229                                 dhcp_client->state = 0;
2230                                 return re;
2231                         }
2232                         send_dhcpv6_rebind(dhcp_client);
2233
2234                 } else if (dhcp_client->release_cb) {
2235                         dhcp_client->state = RENEW;
2236                         re = switch_listening_mode(dhcp_client, L3);
2237                         if (re != 0) {
2238                                 switch_listening_mode(dhcp_client, L_NONE);
2239                                 dhcp_client->state = 0;
2240                                 return re;
2241                         }
2242                         send_dhcpv6_release(dhcp_client);
2243                 }
2244
2245                 return 0;
2246         }
2247
2248         if (dhcp_client->retry_times == DISCOVER_RETRIES) {
2249                 ipv4ll_start(dhcp_client);
2250                 return 0;
2251         }
2252
2253         if (dhcp_client->retry_times == 0) {
2254                 g_free(dhcp_client->assigned_ip);
2255                 dhcp_client->assigned_ip = NULL;
2256
2257                 dhcp_client->state = INIT_SELECTING;
2258                 re = switch_listening_mode(dhcp_client, L2);
2259                 if (re != 0)
2260                         return re;
2261
2262                 dhcp_client->xid = rand();
2263                 dhcp_client->start = time(NULL);
2264         }
2265
2266         if (last_address == NULL) {
2267                 addr = 0;
2268         } else {
2269                 addr = inet_addr(last_address);
2270                 if (addr == 0xFFFFFFFF) {
2271                         addr = 0;
2272                 } else {
2273                         g_free(dhcp_client->last_address);
2274                         dhcp_client->last_address = g_strdup(last_address);
2275                 }
2276         }
2277         send_discover(dhcp_client, addr);
2278
2279         dhcp_client->timeout = g_timeout_add_seconds_full(G_PRIORITY_HIGH,
2280                                                         DISCOVER_TIMEOUT,
2281                                                         discover_timeout,
2282                                                         dhcp_client,
2283                                                         NULL);
2284         return 0;
2285 }
2286
2287 void g_dhcp_client_stop(GDHCPClient *dhcp_client)
2288 {
2289         switch_listening_mode(dhcp_client, L_NONE);
2290
2291         if (dhcp_client->state == BOUND ||
2292                         dhcp_client->state == RENEWING ||
2293                                 dhcp_client->state == REBINDING)
2294                 send_release(dhcp_client, dhcp_client->server_ip,
2295                                         dhcp_client->requested_ip);
2296
2297         if (dhcp_client->timeout > 0) {
2298                 g_source_remove(dhcp_client->timeout);
2299                 dhcp_client->timeout = 0;
2300         }
2301
2302         if (dhcp_client->listener_watch > 0) {
2303                 g_source_remove(dhcp_client->listener_watch);
2304                 dhcp_client->listener_watch = 0;
2305         }
2306
2307         dhcp_client->listener_channel = NULL;
2308
2309         dhcp_client->retry_times = 0;
2310         dhcp_client->ack_retry_times = 0;
2311
2312         dhcp_client->requested_ip = 0;
2313         dhcp_client->state = RELEASED;
2314         dhcp_client->lease_seconds = 0;
2315 }
2316
2317 GList *g_dhcp_client_get_option(GDHCPClient *dhcp_client,
2318                                         unsigned char option_code)
2319 {
2320         return g_hash_table_lookup(dhcp_client->code_value_hash,
2321                                         GINT_TO_POINTER((int) option_code));
2322 }
2323
2324 void g_dhcp_client_register_event(GDHCPClient *dhcp_client,
2325                                         GDHCPClientEvent event,
2326                                         GDHCPClientEventFunc func,
2327                                                         gpointer data)
2328 {
2329         switch (event) {
2330         case G_DHCP_CLIENT_EVENT_LEASE_AVAILABLE:
2331                 dhcp_client->lease_available_cb = func;
2332                 dhcp_client->lease_available_data = data;
2333                 return;
2334         case G_DHCP_CLIENT_EVENT_IPV4LL_AVAILABLE:
2335                 if (dhcp_client->type == G_DHCP_IPV6)
2336                         return;
2337                 dhcp_client->ipv4ll_available_cb = func;
2338                 dhcp_client->ipv4ll_available_data = data;
2339                 return;
2340         case G_DHCP_CLIENT_EVENT_NO_LEASE:
2341                 dhcp_client->no_lease_cb = func;
2342                 dhcp_client->no_lease_data = data;
2343                 return;
2344         case G_DHCP_CLIENT_EVENT_LEASE_LOST:
2345                 dhcp_client->lease_lost_cb = func;
2346                 dhcp_client->lease_lost_data = data;
2347                 return;
2348         case G_DHCP_CLIENT_EVENT_IPV4LL_LOST:
2349                 if (dhcp_client->type == G_DHCP_IPV6)
2350                         return;
2351                 dhcp_client->ipv4ll_lost_cb = func;
2352                 dhcp_client->ipv4ll_lost_data = data;
2353                 return;
2354         case G_DHCP_CLIENT_EVENT_ADDRESS_CONFLICT:
2355                 dhcp_client->address_conflict_cb = func;
2356                 dhcp_client->address_conflict_data = data;
2357                 return;
2358         case G_DHCP_CLIENT_EVENT_INFORMATION_REQ:
2359                 if (dhcp_client->type == G_DHCP_IPV4)
2360                         return;
2361                 dhcp_client->information_req_cb = func;
2362                 dhcp_client->information_req_data = data;
2363                 return;
2364         case G_DHCP_CLIENT_EVENT_SOLICITATION:
2365                 if (dhcp_client->type == G_DHCP_IPV4)
2366                         return;
2367                 dhcp_client->solicitation_cb = func;
2368                 dhcp_client->solicitation_data = data;
2369                 return;
2370         case G_DHCP_CLIENT_EVENT_ADVERTISE:
2371                 if (dhcp_client->type == G_DHCP_IPV4)
2372                         return;
2373                 dhcp_client->advertise_cb = func;
2374                 dhcp_client->advertise_data = data;
2375                 return;
2376         case G_DHCP_CLIENT_EVENT_REQUEST:
2377                 if (dhcp_client->type == G_DHCP_IPV4)
2378                         return;
2379                 dhcp_client->request_cb = func;
2380                 dhcp_client->request_data = data;
2381                 return;
2382         case G_DHCP_CLIENT_EVENT_RENEW:
2383                 if (dhcp_client->type == G_DHCP_IPV4)
2384                         return;
2385                 dhcp_client->renew_cb = func;
2386                 dhcp_client->renew_data = data;
2387                 return;
2388         case G_DHCP_CLIENT_EVENT_REBIND:
2389                 if (dhcp_client->type == G_DHCP_IPV4)
2390                         return;
2391                 dhcp_client->rebind_cb = func;
2392                 dhcp_client->rebind_data = data;
2393                 return;
2394         case G_DHCP_CLIENT_EVENT_RELEASE:
2395                 if (dhcp_client->type == G_DHCP_IPV4)
2396                         return;
2397                 dhcp_client->release_cb = func;
2398                 dhcp_client->release_data = data;
2399                 return;
2400         }
2401 }
2402
2403 int g_dhcp_client_get_index(GDHCPClient *dhcp_client)
2404 {
2405         return dhcp_client->ifindex;
2406 }
2407
2408 char *g_dhcp_client_get_address(GDHCPClient *dhcp_client)
2409 {
2410         return g_strdup(dhcp_client->assigned_ip);
2411 }
2412
2413 char *g_dhcp_client_get_netmask(GDHCPClient *dhcp_client)
2414 {
2415         GList *option = NULL;
2416
2417         if (dhcp_client->type == G_DHCP_IPV6)
2418                 return NULL;
2419
2420         switch (dhcp_client->state) {
2421         case IPV4LL_DEFEND:
2422         case IPV4LL_MONITOR:
2423                 return g_strdup("255.255.0.0");
2424         case BOUND:
2425         case RENEWING:
2426         case REBINDING:
2427                 option = g_dhcp_client_get_option(dhcp_client, G_DHCP_SUBNET);
2428                 if (option != NULL)
2429                         return g_strdup(option->data);
2430         case INIT_SELECTING:
2431         case REQUESTING:
2432         case RELEASED:
2433         case IPV4LL_PROBE:
2434         case IPV4LL_ANNOUNCE:
2435         case INFORMATION_REQ:
2436         case SOLICITATION:
2437         case REQUEST:
2438         case RENEW:
2439         case REBIND:
2440         case RELEASE:
2441                 break;
2442         }
2443         return NULL;
2444 }
2445
2446 GDHCPClientError g_dhcp_client_set_request(GDHCPClient *dhcp_client,
2447                                                 unsigned int option_code)
2448 {
2449         if (g_list_find(dhcp_client->request_list,
2450                         GINT_TO_POINTER((int) option_code)) == NULL)
2451                 dhcp_client->request_list = g_list_prepend(
2452                                         dhcp_client->request_list,
2453                                         (GINT_TO_POINTER((int) option_code)));
2454
2455         return G_DHCP_CLIENT_ERROR_NONE;
2456 }
2457
2458 void g_dhcp_client_clear_requests(GDHCPClient *dhcp_client)
2459 {
2460         g_list_free(dhcp_client->request_list);
2461         dhcp_client->request_list = NULL;
2462 }
2463
2464 void g_dhcp_client_clear_values(GDHCPClient *dhcp_client)
2465 {
2466         g_hash_table_remove_all(dhcp_client->send_value_hash);
2467 }
2468
2469 static uint8_t *alloc_dhcp_option(int code, const uint8_t *data, unsigned size)
2470 {
2471         uint8_t *storage;
2472
2473         storage = g_try_malloc(size + OPT_DATA);
2474         if (storage == NULL)
2475                 return NULL;
2476
2477         storage[OPT_CODE] = code;
2478         storage[OPT_LEN] = size;
2479         memcpy(&storage[OPT_DATA], data, size);
2480
2481         return storage;
2482 }
2483
2484 static uint8_t *alloc_dhcp_data_option(int code, const uint8_t *data, unsigned size)
2485 {
2486         return alloc_dhcp_option(code, data, MIN(size, 255));
2487 }
2488
2489 static uint8_t *alloc_dhcp_string_option(int code, const char *str)
2490 {
2491         return alloc_dhcp_data_option(code, (const uint8_t *)str, strlen(str));
2492 }
2493
2494 GDHCPClientError g_dhcp_client_set_id(GDHCPClient *dhcp_client)
2495 {
2496         const unsigned maclen = 6;
2497         const unsigned idlen = maclen + 1;
2498         const uint8_t option_code = G_DHCP_CLIENT_ID;
2499         uint8_t idbuf[idlen];
2500         uint8_t *data_option;
2501
2502         idbuf[0] = ARPHRD_ETHER;
2503
2504         memcpy(&idbuf[1], dhcp_client->mac_address, maclen);
2505
2506         data_option = alloc_dhcp_data_option(option_code, idbuf, idlen);
2507         if (data_option == NULL)
2508                 return G_DHCP_CLIENT_ERROR_NOMEM;
2509
2510         g_hash_table_insert(dhcp_client->send_value_hash,
2511                 GINT_TO_POINTER((int) option_code), data_option);
2512
2513         return G_DHCP_CLIENT_ERROR_NONE;
2514 }
2515
2516 /* Now only support send hostname */
2517 GDHCPClientError g_dhcp_client_set_send(GDHCPClient *dhcp_client,
2518                 unsigned char option_code, const char *option_value)
2519 {
2520         uint8_t *binary_option;
2521
2522         if (option_code == G_DHCP_HOST_NAME && option_value != NULL) {
2523                 binary_option = alloc_dhcp_string_option(option_code,
2524                                                         option_value);
2525                 if (binary_option == NULL)
2526                         return G_DHCP_CLIENT_ERROR_NOMEM;
2527
2528                 g_hash_table_insert(dhcp_client->send_value_hash,
2529                         GINT_TO_POINTER((int) option_code), binary_option);
2530         }
2531
2532         return G_DHCP_CLIENT_ERROR_NONE;
2533 }
2534
2535 static uint8_t *alloc_dhcpv6_option(uint16_t code, uint8_t *option,
2536                                 uint16_t len)
2537 {
2538         uint8_t *storage;
2539
2540         storage = g_malloc(2 + 2 + len);
2541         if (storage == NULL)
2542                 return NULL;
2543
2544         storage[0] = code >> 8;
2545         storage[1] = code & 0xff;
2546         storage[2] = len >> 8;
2547         storage[3] = len & 0xff;
2548         memcpy(storage + 2 + 2, option, len);
2549
2550         return storage;
2551 }
2552
2553 void g_dhcpv6_client_set_send(GDHCPClient *dhcp_client,
2554                                         uint16_t option_code,
2555                                         uint8_t *option_value,
2556                                         uint16_t option_len)
2557 {
2558         if (option_value != NULL) {
2559                 uint8_t *binary_option;
2560
2561                 debug(dhcp_client, "setting option %d to %p len %d",
2562                         option_code, option_value, option_len);
2563
2564                 binary_option = alloc_dhcpv6_option(option_code, option_value,
2565                                                 option_len);
2566                 if (binary_option != NULL)
2567                         g_hash_table_insert(dhcp_client->send_value_hash,
2568                                         GINT_TO_POINTER((int) option_code),
2569                                         binary_option);
2570         }
2571 }
2572
2573 void g_dhcpv6_client_reset_renew(GDHCPClient *dhcp_client)
2574 {
2575         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
2576                 return;
2577
2578         dhcp_client->last_renew = time(NULL);
2579 }
2580
2581 void g_dhcpv6_client_reset_rebind(GDHCPClient *dhcp_client)
2582 {
2583         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
2584                 return;
2585
2586         dhcp_client->last_rebind = time(NULL);
2587 }
2588
2589 void g_dhcpv6_client_set_expire(GDHCPClient *dhcp_client, uint32_t timeout)
2590 {
2591         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
2592                 return;
2593
2594         dhcp_client->expire = time(NULL) + timeout;
2595 }
2596
2597 uint16_t g_dhcpv6_client_get_status(GDHCPClient *dhcp_client)
2598 {
2599         if (dhcp_client == NULL || dhcp_client->type == G_DHCP_IPV4)
2600                 return 0;
2601
2602         return dhcp_client->status_code;
2603 }
2604
2605 GDHCPClient *g_dhcp_client_ref(GDHCPClient *dhcp_client)
2606 {
2607         if (dhcp_client == NULL)
2608                 return NULL;
2609
2610         __sync_fetch_and_add(&dhcp_client->ref_count, 1);
2611
2612         return dhcp_client;
2613 }
2614
2615 void g_dhcp_client_unref(GDHCPClient *dhcp_client)
2616 {
2617         if (dhcp_client == NULL)
2618                 return;
2619
2620         if (__sync_fetch_and_sub(&dhcp_client->ref_count, 1) != 1)
2621                 return;
2622
2623         g_dhcp_client_stop(dhcp_client);
2624
2625         g_free(dhcp_client->interface);
2626         g_free(dhcp_client->assigned_ip);
2627         g_free(dhcp_client->last_address);
2628         g_free(dhcp_client->duid);
2629         g_free(dhcp_client->server_duid);
2630
2631         g_list_free(dhcp_client->request_list);
2632         g_list_free(dhcp_client->require_list);
2633
2634         g_hash_table_destroy(dhcp_client->code_value_hash);
2635         g_hash_table_destroy(dhcp_client->send_value_hash);
2636
2637         g_free(dhcp_client);
2638 }
2639
2640 void g_dhcp_client_set_debug(GDHCPClient *dhcp_client,
2641                                 GDHCPDebugFunc func, gpointer user_data)
2642 {
2643         if (dhcp_client == NULL)
2644                 return;
2645
2646         dhcp_client->debug_func = func;
2647         dhcp_client->debug_data = user_data;
2648 }