blob: e7f204113b002a5769f6fc173f67a8ad99009f21 [file] [log] [blame]
Robert Greenwaltc4621772012-01-31 12:46:45 -08001/*
2 * Copyright (C) 2012 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Dan Albertaa1be2b2015-01-06 09:36:17 -080017#include <ctype.h>
18#include <errno.h>
Lorenzo Colitti70afde62013-03-04 17:58:40 +090019#include <fcntl.h>
Lorenzo Colittiba25df92014-06-18 00:22:17 +090020#include <netdb.h>
Dan Albertaa1be2b2015-01-06 09:36:17 -080021#include <net/if.h>
Lorenzo Colittiba25df92014-06-18 00:22:17 +090022#include <netinet/in.h>
23#include <stdlib.h>
Jeff Sharkey8e188ed2012-07-12 18:32:03 -070024#include <string.h>
Rom Lemarchand838ef642013-01-24 15:14:41 -080025#include <sys/wait.h>
Jeff Sharkey8e188ed2012-07-12 18:32:03 -070026
Jeff Sharkeybec6d042012-09-06 15:45:56 -070027#define LOG_TAG "Netd"
28
Lorenzo Colittic1306ea2017-03-27 05:52:31 +090029#include <android-base/stringprintf.h>
Lorenzo Colitti548bbd42017-08-28 23:05:12 +090030#include <cutils/sockets.h>
Logan Chien3f461482018-04-23 14:31:32 +080031#include <log/log.h>
Jeff Sharkey8e188ed2012-07-12 18:32:03 -070032
Narayan Kamatha5ace892017-01-06 15:10:02 +000033#include "Controllers.h"
Robert Greenwaltc4621772012-01-31 12:46:45 -080034#include "NetdConstants.h"
Narayan Kamatha5ace892017-01-06 15:10:02 +000035#include "IptablesRestoreController.h"
Robert Greenwaltc4621772012-01-31 12:46:45 -080036
Lorenzo Colitticd283772017-01-31 19:00:49 +090037int execIptablesRestoreWithOutput(IptablesTarget target, const std::string& commands,
38 std::string *output) {
39 return android::net::gCtls->iptablesRestoreCtrl.execute(target, commands, output);
40}
41
Lorenzo Colitti89faa342016-02-26 11:38:47 +090042int execIptablesRestore(IptablesTarget target, const std::string& commands) {
Lorenzo Colitticd283772017-01-31 19:00:49 +090043 return execIptablesRestoreWithOutput(target, commands, nullptr);
Lorenzo Colitti89faa342016-02-26 11:38:47 +090044}
45
Lorenzo Colittic1306ea2017-03-27 05:52:31 +090046int execIptablesRestoreCommand(IptablesTarget target, const std::string& table,
47 const std::string& command, std::string *output) {
48 std::string fullCmd = android::base::StringPrintf("*%s\n%s\nCOMMIT\n", table.c_str(),
49 command.c_str());
50 return execIptablesRestoreWithOutput(target, fullCmd, output);
51}
52
JP Abgrall69261cb2014-06-19 18:35:24 -070053/*
54 * Check an interface name for plausibility. This should e.g. help against
55 * directory traversal.
56 */
Joel Scherpelzbcad6612017-05-30 10:55:11 +090057bool isIfaceName(const std::string& name) {
JP Abgrall69261cb2014-06-19 18:35:24 -070058 size_t i;
Joel Scherpelzbcad6612017-05-30 10:55:11 +090059 if ((name.empty()) || (name.size() > IFNAMSIZ)) {
JP Abgrall69261cb2014-06-19 18:35:24 -070060 return false;
61 }
62
63 /* First character must be alphanumeric */
64 if (!isalnum(name[0])) {
65 return false;
66 }
67
Joel Scherpelzbcad6612017-05-30 10:55:11 +090068 for (i = 1; i < name.size(); i++) {
JP Abgrall69261cb2014-06-19 18:35:24 -070069 if (!isalnum(name[i]) && (name[i] != '_') && (name[i] != '-') && (name[i] != ':')) {
70 return false;
71 }
72 }
73
74 return true;
75}
Lorenzo Colittiba25df92014-06-18 00:22:17 +090076
cjybyjk7fd85352021-01-22 17:12:21 +080077/*
78 * Check an MAC address for plausibility. This should e.g. help against
79 * directory traversal.
80 */
81bool isMACAddress(const std::string& mac) {
82 size_t i;
83 if ((mac.empty()) || (mac.size() != 17 /* strlen("aa:bb:cc:dd:ee:ff") == 17 */)) {
84 return false;
85 }
86
87 for (i = 0; i < mac.size(); i+=3) {
88 if (!isxdigit(mac[i]) || !isxdigit(mac[i+1]) || (mac[i+2] != ':' && mac[i+2] != 0)) {
89 return false;
90 }
91 }
92
93 return true;
94}
95
Lorenzo Colittiba25df92014-06-18 00:22:17 +090096int parsePrefix(const char *prefix, uint8_t *family, void *address, int size, uint8_t *prefixlen) {
97 if (!prefix || !family || !address || !prefixlen) {
98 return -EFAULT;
99 }
100
101 // Find the '/' separating address from prefix length.
102 const char *slash = strchr(prefix, '/');
103 const char *prefixlenString = slash + 1;
104 if (!slash || !*prefixlenString)
105 return -EINVAL;
106
107 // Convert the prefix length to a uint8_t.
108 char *endptr;
109 unsigned templen;
110 templen = strtoul(prefixlenString, &endptr, 10);
111 if (*endptr || templen > 255) {
112 return -EINVAL;
113 }
114 *prefixlen = templen;
115
116 // Copy the address part of the prefix to a local buffer. We have to copy
117 // because inet_pton and getaddrinfo operate on null-terminated address
118 // strings, but prefix is const and has '/' after the address.
119 std::string addressString(prefix, slash - prefix);
120
121 // Parse the address.
122 addrinfo *res;
123 addrinfo hints = {
124 .ai_flags = AI_NUMERICHOST,
125 };
Yi Kongbdfd57e2018-07-25 13:26:10 -0700126 int ret = getaddrinfo(addressString.c_str(), nullptr, &hints, &res);
Lorenzo Colittiba25df92014-06-18 00:22:17 +0900127 if (ret || !res) {
128 return -EINVAL; // getaddrinfo return values are not errno values.
129 }
130
131 // Convert the address string to raw address bytes.
132 void *rawAddress;
133 int rawLength;
134 switch (res[0].ai_family) {
135 case AF_INET: {
136 if (*prefixlen > 32) {
137 return -EINVAL;
138 }
139 sockaddr_in *sin = (sockaddr_in *) res[0].ai_addr;
140 rawAddress = &sin->sin_addr;
141 rawLength = 4;
142 break;
143 }
144 case AF_INET6: {
145 if (*prefixlen > 128) {
146 return -EINVAL;
147 }
148 sockaddr_in6 *sin6 = (sockaddr_in6 *) res[0].ai_addr;
149 rawAddress = &sin6->sin6_addr;
150 rawLength = 16;
151 break;
152 }
153 default: {
154 freeaddrinfo(res);
155 return -EAFNOSUPPORT;
156 }
157 }
158
159 if (rawLength > size) {
160 freeaddrinfo(res);
161 return -ENOSPC;
162 }
163
164 *family = res[0].ai_family;
165 memcpy(address, rawAddress, rawLength);
166 freeaddrinfo(res);
167
168 return rawLength;
169}
Lorenzo Colitti839d7d62017-04-03 15:37:19 +0900170
171void blockSigpipe() {
172 sigset_t mask;
173
174 sigemptyset(&mask);
175 sigaddset(&mask, SIGPIPE);
Yi Kongbdfd57e2018-07-25 13:26:10 -0700176 if (sigprocmask(SIG_BLOCK, &mask, nullptr) != 0)
Lorenzo Colitti839d7d62017-04-03 15:37:19 +0900177 ALOGW("WARNING: SIGPIPE not blocked\n");
178}
Lorenzo Colitti548bbd42017-08-28 23:05:12 +0900179
180void setCloseOnExec(const char *sock) {
181 int fd = android_get_control_socket(sock);
182 int flags = fcntl(fd, F_GETFD, 0);
183 if (flags == -1) {
184 ALOGE("Can't get fd flags for control socket %s", sock);
185 flags = 0;
186 }
187 flags |= FD_CLOEXEC;
188 if (fcntl(fd, F_SETFD, flags) == -1) {
189 ALOGE("Can't set control socket %s to FD_CLOEXEC", sock);
190 }
191}