2 * Copyright (c) 1997-2007 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the Institute nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 #include "krb5_locl.h"
36 struct addr_operations {
38 krb5_address_type atype;
39 size_t max_sockaddr_size;
40 krb5_error_code (*sockaddr2addr)(const struct sockaddr *, krb5_address *);
41 krb5_error_code (*sockaddr2port)(const struct sockaddr *, int16_t *);
42 void (*addr2sockaddr)(const krb5_address *, struct sockaddr *,
43 krb5_socklen_t *sa_size, int port);
44 void (*h_addr2sockaddr)(const char *, struct sockaddr *, krb5_socklen_t *, int);
45 krb5_error_code (*h_addr2addr)(const char *, krb5_address *);
46 krb5_boolean (*uninteresting)(const struct sockaddr *);
47 krb5_boolean (*is_loopback)(const struct sockaddr *);
48 void (*anyaddr)(struct sockaddr *, krb5_socklen_t *, int);
49 int (*print_addr)(const krb5_address *, char *, size_t);
50 int (*parse_addr)(krb5_context, const char*, krb5_address *);
51 int (*order_addr)(krb5_context, const krb5_address*, const krb5_address*);
52 int (*free_addr)(krb5_context, krb5_address*);
53 int (*copy_addr)(krb5_context, const krb5_address*, krb5_address*);
54 int (*mask_boundary)(krb5_context, const krb5_address*, unsigned long,
55 krb5_address*, krb5_address*);
59 * AF_INET - aka IPv4 implementation
62 static krb5_error_code
63 ipv4_sockaddr2addr (const struct sockaddr *sa, krb5_address *a)
65 const struct sockaddr_in *sin4 = (const struct sockaddr_in *)sa;
68 a->addr_type = KRB5_ADDRESS_INET;
69 memcpy (buf, &sin4->sin_addr, 4);
70 return krb5_data_copy(&a->address, buf, 4);
73 static krb5_error_code
74 ipv4_sockaddr2port (const struct sockaddr *sa, int16_t *port)
76 const struct sockaddr_in *sin4 = (const struct sockaddr_in *)sa;
78 *port = sin4->sin_port;
83 ipv4_addr2sockaddr (const krb5_address *a,
85 krb5_socklen_t *sa_size,
88 struct sockaddr_in tmp;
90 memset (&tmp, 0, sizeof(tmp));
91 tmp.sin_family = AF_INET;
92 memcpy (&tmp.sin_addr, a->address.data, 4);
94 memcpy(sa, &tmp, min(sizeof(tmp), *sa_size));
95 *sa_size = sizeof(tmp);
99 ipv4_h_addr2sockaddr(const char *addr,
101 krb5_socklen_t *sa_size,
104 struct sockaddr_in tmp;
106 memset (&tmp, 0, sizeof(tmp));
107 tmp.sin_family = AF_INET;
109 tmp.sin_addr = *((const struct in_addr *)addr);
110 memcpy(sa, &tmp, min(sizeof(tmp), *sa_size));
111 *sa_size = sizeof(tmp);
114 static krb5_error_code
115 ipv4_h_addr2addr (const char *addr,
118 unsigned char buf[4];
120 a->addr_type = KRB5_ADDRESS_INET;
121 memcpy(buf, addr, 4);
122 return krb5_data_copy(&a->address, buf, 4);
126 * Are there any addresses that should be considered `uninteresting'?
130 ipv4_uninteresting (const struct sockaddr *sa)
132 const struct sockaddr_in *sin4 = (const struct sockaddr_in *)sa;
134 if (sin4->sin_addr.s_addr == INADDR_ANY)
141 ipv4_is_loopback (const struct sockaddr *sa)
143 const struct sockaddr_in *sin4 = (const struct sockaddr_in *)sa;
145 if ((ntohl(sin4->sin_addr.s_addr) >> 24) == IN_LOOPBACKNET)
152 ipv4_anyaddr (struct sockaddr *sa, krb5_socklen_t *sa_size, int port)
154 struct sockaddr_in tmp;
156 memset (&tmp, 0, sizeof(tmp));
157 tmp.sin_family = AF_INET;
159 tmp.sin_addr.s_addr = INADDR_ANY;
160 memcpy(sa, &tmp, min(sizeof(tmp), *sa_size));
161 *sa_size = sizeof(tmp);
165 ipv4_print_addr (const krb5_address *addr, char *str, size_t len)
169 memcpy (&ia, addr->address.data, 4);
171 return snprintf (str, len, "IPv4:%s", inet_ntoa(ia));
175 ipv4_parse_addr (krb5_context context, const char *address, krb5_address *addr)
180 p = strchr(address, ':');
183 if(strncasecmp(address, "ip:", p - address) != 0 &&
184 strncasecmp(address, "ip4:", p - address) != 0 &&
185 strncasecmp(address, "ipv4:", p - address) != 0 &&
186 strncasecmp(address, "inet:", p - address) != 0)
190 if(inet_aton(p, &a) == 0)
192 addr->addr_type = KRB5_ADDRESS_INET;
193 if(krb5_data_alloc(&addr->address, 4) != 0)
195 _krb5_put_int(addr->address.data, ntohl(a.s_addr), addr->address.length);
200 ipv4_mask_boundary(krb5_context context, const krb5_address *inaddr,
201 unsigned long len, krb5_address *low, krb5_address *high)
204 uint32_t l, h, m = 0xffffffff;
207 krb5_set_error_message(context, KRB5_PROG_ATYPE_NOSUPP,
208 N_("IPv4 prefix too large (%ld)", "len"), len);
209 return KRB5_PROG_ATYPE_NOSUPP;
213 _krb5_get_int(inaddr->address.data, &ia, inaddr->address.length);
218 low->addr_type = KRB5_ADDRESS_INET;
219 if(krb5_data_alloc(&low->address, 4) != 0)
221 _krb5_put_int(low->address.data, l, low->address.length);
223 high->addr_type = KRB5_ADDRESS_INET;
224 if(krb5_data_alloc(&high->address, 4) != 0) {
225 krb5_free_address(context, low);
228 _krb5_put_int(high->address.data, h, high->address.length);
235 * AF_INET6 - aka IPv6 implementation
240 static krb5_error_code
241 ipv6_sockaddr2addr (const struct sockaddr *sa, krb5_address *a)
243 const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
245 if (IN6_IS_ADDR_V4MAPPED(&sin6->sin6_addr)) {
246 unsigned char buf[4];
248 a->addr_type = KRB5_ADDRESS_INET;
249 #ifndef IN6_ADDR_V6_TO_V4
250 #ifdef IN6_EXTRACT_V4ADDR
251 #define IN6_ADDR_V6_TO_V4(x) (&IN6_EXTRACT_V4ADDR(x))
253 #define IN6_ADDR_V6_TO_V4(x) ((const struct in_addr *)&(x)->s6_addr[12])
256 memcpy (buf, IN6_ADDR_V6_TO_V4(&sin6->sin6_addr), 4);
257 return krb5_data_copy(&a->address, buf, 4);
259 a->addr_type = KRB5_ADDRESS_INET6;
260 return krb5_data_copy(&a->address,
262 sizeof(sin6->sin6_addr));
266 static krb5_error_code
267 ipv6_sockaddr2port (const struct sockaddr *sa, int16_t *port)
269 const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
271 *port = sin6->sin6_port;
276 ipv6_addr2sockaddr (const krb5_address *a,
278 krb5_socklen_t *sa_size,
281 struct sockaddr_in6 tmp;
283 memset (&tmp, 0, sizeof(tmp));
284 tmp.sin6_family = AF_INET6;
285 memcpy (&tmp.sin6_addr, a->address.data, sizeof(tmp.sin6_addr));
286 tmp.sin6_port = port;
287 memcpy(sa, &tmp, min(sizeof(tmp), *sa_size));
288 *sa_size = sizeof(tmp);
292 ipv6_h_addr2sockaddr(const char *addr,
294 krb5_socklen_t *sa_size,
297 struct sockaddr_in6 tmp;
299 memset (&tmp, 0, sizeof(tmp));
300 tmp.sin6_family = AF_INET6;
301 tmp.sin6_port = port;
302 tmp.sin6_addr = *((const struct in6_addr *)addr);
303 memcpy(sa, &tmp, min(sizeof(tmp), *sa_size));
304 *sa_size = sizeof(tmp);
307 static krb5_error_code
308 ipv6_h_addr2addr (const char *addr,
311 a->addr_type = KRB5_ADDRESS_INET6;
312 return krb5_data_copy(&a->address, addr, sizeof(struct in6_addr));
320 ipv6_uninteresting (const struct sockaddr *sa)
322 const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
323 const struct in6_addr *in6 = (const struct in6_addr *)&sin6->sin6_addr;
325 return IN6_IS_ADDR_LINKLOCAL(in6)
326 || IN6_IS_ADDR_V4COMPAT(in6);
330 ipv6_is_loopback (const struct sockaddr *sa)
332 const struct sockaddr_in6 *sin6 = (const struct sockaddr_in6 *)sa;
333 const struct in6_addr *in6 = (const struct in6_addr *)&sin6->sin6_addr;
335 return (IN6_IS_ADDR_LOOPBACK(in6));
339 ipv6_anyaddr (struct sockaddr *sa, krb5_socklen_t *sa_size, int port)
341 struct sockaddr_in6 tmp;
343 memset (&tmp, 0, sizeof(tmp));
344 tmp.sin6_family = AF_INET6;
345 tmp.sin6_port = port;
346 tmp.sin6_addr = in6addr_any;
347 *sa_size = sizeof(tmp);
351 ipv6_print_addr (const krb5_address *addr, char *str, size_t len)
353 char buf[128], buf2[3];
354 if(inet_ntop(AF_INET6, addr->address.data, buf, sizeof(buf)) == NULL)
356 /* XXX this is pretty ugly, but better than abort() */
358 unsigned char *p = addr->address.data;
360 for(i = 0; i < addr->address.length; i++) {
361 snprintf(buf2, sizeof(buf2), "%02x", p[i]);
362 if(i > 0 && (i & 1) == 0)
363 strlcat(buf, ":", sizeof(buf));
364 strlcat(buf, buf2, sizeof(buf));
367 return snprintf(str, len, "IPv6:%s", buf);
371 ipv6_parse_addr (krb5_context context, const char *address, krb5_address *addr)
377 p = strchr(address, ':');
380 if(strncasecmp(address, "ip6:", p - address) == 0 ||
381 strncasecmp(address, "ipv6:", p - address) == 0 ||
382 strncasecmp(address, "inet6:", p - address) == 0)
386 ret = inet_pton(AF_INET6, address, &in6.s6_addr);
388 addr->addr_type = KRB5_ADDRESS_INET6;
389 ret = krb5_data_alloc(&addr->address, sizeof(in6.s6_addr));
392 memcpy(addr->address.data, in6.s6_addr, sizeof(in6.s6_addr));
399 ipv6_mask_boundary(krb5_context context, const krb5_address *inaddr,
400 unsigned long len, krb5_address *low, krb5_address *high)
402 struct in6_addr addr, laddr, haddr;
407 krb5_set_error_message(context, KRB5_PROG_ATYPE_NOSUPP,
408 N_("IPv6 prefix too large (%ld)", "length"), len);
409 return KRB5_PROG_ATYPE_NOSUPP;
412 if (inaddr->address.length != sizeof(addr)) {
413 krb5_set_error_message(context, KRB5_PROG_ATYPE_NOSUPP,
414 N_("IPv6 addr bad length", ""));
415 return KRB5_PROG_ATYPE_NOSUPP;
418 memcpy(&addr, inaddr->address.data, inaddr->address.length);
420 for (i = 0; i < 16; i++) {
421 sub_len = min(8, len);
423 m = 0xff << (8 - sub_len);
425 laddr.s6_addr[i] = addr.s6_addr[i] & m;
426 haddr.s6_addr[i] = (addr.s6_addr[i] & m) | ~m;
434 low->addr_type = KRB5_ADDRESS_INET6;
435 if (krb5_data_alloc(&low->address, sizeof(laddr.s6_addr)) != 0)
437 memcpy(low->address.data, laddr.s6_addr, sizeof(laddr.s6_addr));
439 high->addr_type = KRB5_ADDRESS_INET6;
440 if (krb5_data_alloc(&high->address, sizeof(haddr.s6_addr)) != 0) {
441 krb5_free_address(context, low);
444 memcpy(high->address.data, haddr.s6_addr, sizeof(haddr.s6_addr));
451 #ifndef HEIMDAL_SMALLER
457 #define KRB5_ADDRESS_ARANGE (-100)
465 arange_parse_addr (krb5_context context,
466 const char *address, krb5_address *addr)
469 krb5_address low0, high0;
473 if(strncasecmp(address, "RANGE:", 6) != 0)
478 p = strrchr(address, '/');
480 krb5_addresses addrmask;
484 if (strlcpy(buf, address, sizeof(buf)) > sizeof(buf))
486 buf[p - address] = '\0';
487 ret = krb5_parse_address(context, buf, &addrmask);
490 if(addrmask.len != 1) {
491 krb5_free_addresses(context, &addrmask);
495 address += p - address + 1;
497 num = strtol(address, &q, 10);
498 if (q == address || *q != '\0' || num < 0) {
499 krb5_free_addresses(context, &addrmask);
503 ret = krb5_address_prefixlen_boundary(context, &addrmask.val[0], num,
505 krb5_free_addresses(context, &addrmask);
510 krb5_addresses low, high;
512 strsep_copy(&address, "-", buf, sizeof(buf));
513 ret = krb5_parse_address(context, buf, &low);
517 krb5_free_addresses(context, &low);
521 strsep_copy(&address, "-", buf, sizeof(buf));
522 ret = krb5_parse_address(context, buf, &high);
524 krb5_free_addresses(context, &low);
528 if(high.len != 1 && high.val[0].addr_type != low.val[0].addr_type) {
529 krb5_free_addresses(context, &low);
530 krb5_free_addresses(context, &high);
534 ret = krb5_copy_address(context, &high.val[0], &high0);
536 ret = krb5_copy_address(context, &low.val[0], &low0);
538 krb5_free_address(context, &high0);
540 krb5_free_addresses(context, &low);
541 krb5_free_addresses(context, &high);
546 krb5_data_alloc(&addr->address, sizeof(*a));
547 addr->addr_type = KRB5_ADDRESS_ARANGE;
548 a = addr->address.data;
550 if(krb5_address_order(context, &low0, &high0) < 0) {
561 arange_free (krb5_context context, krb5_address *addr)
564 a = addr->address.data;
565 krb5_free_address(context, &a->low);
566 krb5_free_address(context, &a->high);
567 krb5_data_free(&addr->address);
573 arange_copy (krb5_context context, const krb5_address *inaddr,
574 krb5_address *outaddr)
577 struct arange *i, *o;
579 outaddr->addr_type = KRB5_ADDRESS_ARANGE;
580 ret = krb5_data_alloc(&outaddr->address, sizeof(*o));
583 i = inaddr->address.data;
584 o = outaddr->address.data;
585 ret = krb5_copy_address(context, &i->low, &o->low);
587 krb5_data_free(&outaddr->address);
590 ret = krb5_copy_address(context, &i->high, &o->high);
592 krb5_free_address(context, &o->low);
593 krb5_data_free(&outaddr->address);
600 arange_print_addr (const krb5_address *addr, char *str, size_t len)
604 size_t l, size, ret_len;
606 a = addr->address.data;
608 l = strlcpy(str, "RANGE:", len);
614 ret = krb5_print_address (&a->low, str + size, len - size, &l);
623 l = strlcat(str + size, "-", len - size);
630 ret = krb5_print_address (&a->high, str + size, len - size, &l);
639 arange_order_addr(krb5_context context,
640 const krb5_address *addr1,
641 const krb5_address *addr2)
643 int tmp1, tmp2, sign;
645 const krb5_address *a2;
647 if(addr1->addr_type == KRB5_ADDRESS_ARANGE) {
648 a = addr1->address.data;
651 } else if(addr2->addr_type == KRB5_ADDRESS_ARANGE) {
652 a = addr2->address.data;
657 UNREACHABLE(return 0);
660 if(a2->addr_type == KRB5_ADDRESS_ARANGE) {
661 struct arange *b = a2->address.data;
662 tmp1 = krb5_address_order(context, &a->low, &b->low);
665 return sign * krb5_address_order(context, &a->high, &b->high);
666 } else if(a2->addr_type == a->low.addr_type) {
667 tmp1 = krb5_address_order(context, &a->low, a2);
670 tmp2 = krb5_address_order(context, &a->high, a2);
675 return sign * (addr1->addr_type - addr2->addr_type);
679 #endif /* HEIMDAL_SMALLER */
682 addrport_print_addr (const krb5_address *addr, char *str, size_t len)
685 krb5_address addr1, addr2;
687 size_t ret_len = 0, l, size = 0;
690 sp = krb5_storage_from_data((krb5_data*)rk_UNCONST(&addr->address));
694 /* for totally obscure reasons, these are not in network byteorder */
695 krb5_storage_set_byteorder(sp, KRB5_STORAGE_BYTEORDER_LE);
697 krb5_storage_seek(sp, 2, SEEK_CUR); /* skip first two bytes */
698 krb5_ret_address(sp, &addr1);
700 krb5_storage_seek(sp, 2, SEEK_CUR); /* skip two bytes */
701 krb5_ret_address(sp, &addr2);
702 krb5_storage_free(sp);
703 if(addr2.addr_type == KRB5_ADDRESS_IPPORT && addr2.address.length == 2) {
705 _krb5_get_int(addr2.address.data, &value, 2);
708 l = strlcpy(str, "ADDRPORT:", len);
715 ret = krb5_print_address(&addr1, str + size, len - size, &l);
724 ret = snprintf(str + size, len - size, ",PORT=%u", port);
731 static struct addr_operations at[] = {
733 AF_INET, KRB5_ADDRESS_INET, sizeof(struct sockaddr_in),
737 ipv4_h_addr2sockaddr,
751 AF_INET6, KRB5_ADDRESS_INET6, sizeof(struct sockaddr_in6),
755 ipv6_h_addr2sockaddr,
768 #ifndef HEIMDAL_SMALLER
769 /* fake address type */
771 KRB5_ADDRESS_ARANGE, KRB5_ADDRESS_ARANGE, sizeof(struct arange),
789 KRB5_ADDRESS_ADDRPORT, KRB5_ADDRESS_ADDRPORT, 0,
807 static size_t num_addrs = sizeof(at) / sizeof(at[0]);
809 static size_t max_sockaddr_size = 0;
815 static struct addr_operations *
820 for (i = 0; i < num_addrs; i++) {
827 static struct addr_operations *
828 find_atype(krb5_address_type atype)
832 for (i = 0; i < num_addrs; i++) {
833 if (atype == at[i].atype)
840 * krb5_sockaddr2address stores a address a "struct sockaddr" sa in
841 * the krb5_address addr.
843 * @param context a Keberos context
844 * @param sa a struct sockaddr to extract the address from
845 * @param addr an Kerberos 5 address to store the address in.
847 * @return Return an error code or 0.
849 * @ingroup krb5_address
852 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
853 krb5_sockaddr2address (krb5_context context,
854 const struct sockaddr *sa, krb5_address *addr)
856 struct addr_operations *a = find_af(sa->sa_family);
858 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
859 N_("Address family %d not supported", ""),
861 return KRB5_PROG_ATYPE_NOSUPP;
863 return (*a->sockaddr2addr)(sa, addr);
867 * krb5_sockaddr2port extracts a port (if possible) from a "struct
870 * @param context a Keberos context
871 * @param sa a struct sockaddr to extract the port from
872 * @param port a pointer to an int16_t store the port in.
874 * @return Return an error code or 0. Will return
875 * KRB5_PROG_ATYPE_NOSUPP in case address type is not supported.
877 * @ingroup krb5_address
880 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
881 krb5_sockaddr2port (krb5_context context,
882 const struct sockaddr *sa, int16_t *port)
884 struct addr_operations *a = find_af(sa->sa_family);
886 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
887 N_("Address family %d not supported", ""),
889 return KRB5_PROG_ATYPE_NOSUPP;
891 return (*a->sockaddr2port)(sa, port);
895 * krb5_addr2sockaddr sets the "struct sockaddr sockaddr" from addr
896 * and port. The argument sa_size should initially contain the size of
897 * the sa and after the call, it will contain the actual length of the
898 * address. In case of the sa is too small to fit the whole address,
899 * the up to *sa_size will be stored, and then *sa_size will be set to
900 * the required length.
902 * @param context a Keberos context
903 * @param addr the address to copy the from
904 * @param sa the struct sockaddr that will be filled in
905 * @param sa_size pointer to length of sa, and after the call, it will
906 * contain the actual length of the address.
907 * @param port set port in sa.
909 * @return Return an error code or 0. Will return
910 * KRB5_PROG_ATYPE_NOSUPP in case address type is not supported.
912 * @ingroup krb5_address
915 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
916 krb5_addr2sockaddr (krb5_context context,
917 const krb5_address *addr,
919 krb5_socklen_t *sa_size,
922 struct addr_operations *a = find_atype(addr->addr_type);
925 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
926 N_("Address type %d not supported",
927 "krb5_address type"),
929 return KRB5_PROG_ATYPE_NOSUPP;
931 if (a->addr2sockaddr == NULL) {
932 krb5_set_error_message (context,
933 KRB5_PROG_ATYPE_NOSUPP,
934 N_("Can't convert address type %d to sockaddr", ""),
936 return KRB5_PROG_ATYPE_NOSUPP;
938 (*a->addr2sockaddr)(addr, sa, sa_size, port);
943 * krb5_max_sockaddr_size returns the max size of the .Li struct
944 * sockaddr that the Kerberos library will return.
946 * @return Return an size_t of the maximum struct sockaddr.
948 * @ingroup krb5_address
951 KRB5_LIB_FUNCTION size_t KRB5_LIB_CALL
952 krb5_max_sockaddr_size (void)
954 if (max_sockaddr_size == 0) {
957 for (i = 0; i < num_addrs; i++)
958 max_sockaddr_size = max(max_sockaddr_size, at[i].max_sockaddr_size);
960 return max_sockaddr_size;
964 * krb5_sockaddr_uninteresting returns TRUE for all .Fa sa that the
965 * kerberos library thinks are uninteresting. One example are link
968 * @param sa pointer to struct sockaddr that might be interesting.
970 * @return Return a non zero for uninteresting addresses.
972 * @ingroup krb5_address
975 KRB5_LIB_FUNCTION krb5_boolean KRB5_LIB_CALL
976 krb5_sockaddr_uninteresting(const struct sockaddr *sa)
978 struct addr_operations *a = find_af(sa->sa_family);
979 if (a == NULL || a->uninteresting == NULL)
981 return (*a->uninteresting)(sa);
984 KRB5_LIB_FUNCTION krb5_boolean KRB5_LIB_CALL
985 krb5_sockaddr_is_loopback(const struct sockaddr *sa)
987 struct addr_operations *a = find_af(sa->sa_family);
988 if (a == NULL || a->is_loopback == NULL)
990 return (*a->is_loopback)(sa);
994 * krb5_h_addr2sockaddr initializes a "struct sockaddr sa" from af and
995 * the "struct hostent" (see gethostbyname(3) ) h_addr_list
996 * component. The argument sa_size should initially contain the size
997 * of the sa, and after the call, it will contain the actual length of
1000 * @param context a Keberos context
1001 * @param af addresses
1002 * @param addr address
1003 * @param sa returned struct sockaddr
1004 * @param sa_size size of sa
1005 * @param port port to set in sa.
1007 * @return Return an error code or 0.
1009 * @ingroup krb5_address
1012 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1013 krb5_h_addr2sockaddr (krb5_context context,
1015 const char *addr, struct sockaddr *sa,
1016 krb5_socklen_t *sa_size,
1019 struct addr_operations *a = find_af(af);
1021 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
1022 "Address family %d not supported", af);
1023 return KRB5_PROG_ATYPE_NOSUPP;
1025 (*a->h_addr2sockaddr)(addr, sa, sa_size, port);
1030 * krb5_h_addr2addr works like krb5_h_addr2sockaddr with the exception
1031 * that it operates on a krb5_address instead of a struct sockaddr.
1033 * @param context a Keberos context
1034 * @param af address family
1035 * @param haddr host address from struct hostent.
1036 * @param addr returned krb5_address.
1038 * @return Return an error code or 0.
1040 * @ingroup krb5_address
1043 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1044 krb5_h_addr2addr (krb5_context context,
1046 const char *haddr, krb5_address *addr)
1048 struct addr_operations *a = find_af(af);
1050 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
1051 N_("Address family %d not supported", ""), af);
1052 return KRB5_PROG_ATYPE_NOSUPP;
1054 return (*a->h_addr2addr)(haddr, addr);
1058 * krb5_anyaddr fills in a "struct sockaddr sa" that can be used to
1059 * bind(2) to. The argument sa_size should initially contain the size
1060 * of the sa, and after the call, it will contain the actual length
1063 * @param context a Keberos context
1064 * @param af address family
1065 * @param sa sockaddr
1066 * @param sa_size lenght of sa.
1067 * @param port for to fill into sa.
1069 * @return Return an error code or 0.
1071 * @ingroup krb5_address
1074 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1075 krb5_anyaddr (krb5_context context,
1077 struct sockaddr *sa,
1078 krb5_socklen_t *sa_size,
1081 struct addr_operations *a = find_af (af);
1084 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
1085 N_("Address family %d not supported", ""), af);
1086 return KRB5_PROG_ATYPE_NOSUPP;
1089 (*a->anyaddr)(sa, sa_size, port);
1094 * krb5_print_address prints the address in addr to the string string
1095 * that have the length len. If ret_len is not NULL, it will be filled
1096 * with the length of the string if size were unlimited (not including
1099 * @param addr address to be printed
1100 * @param str pointer string to print the address into
1101 * @param len length that will fit into area pointed to by "str".
1102 * @param ret_len return length the str.
1104 * @return Return an error code or 0.
1106 * @ingroup krb5_address
1109 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1110 krb5_print_address (const krb5_address *addr,
1111 char *str, size_t len, size_t *ret_len)
1113 struct addr_operations *a = find_atype(addr->addr_type);
1116 if (a == NULL || a->print_addr == NULL) {
1122 l = snprintf(s, len, "TYPE_%d:", addr->addr_type);
1123 if (l < 0 || (size_t)l >= len)
1127 for(i = 0; i < addr->address.length; i++) {
1128 l = snprintf(s, len, "%02x", ((char*)addr->address.data)[i]);
1129 if (l < 0 || (size_t)l >= len)
1138 ret = (*a->print_addr)(addr, str, len);
1146 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1147 _krb5_parse_address_no_lookup(krb5_context context,
1149 krb5_addresses *addresses)
1154 addresses->val = NULL;
1156 for(i = 0; i < num_addrs; i++) {
1157 if(at[i].parse_addr) {
1159 if((*at[i].parse_addr)(context, string, &addr) == 0) {
1160 ALLOC_SEQ(addresses, 1);
1161 if (addresses->val == NULL)
1162 return krb5_enomem(context);
1163 addresses->val[0] = addr;
1173 * krb5_parse_address returns the resolved hostname in string to the
1174 * krb5_addresses addresses .
1176 * @param context a Keberos context
1180 * @return Return an error code or 0.
1182 * @ingroup krb5_address
1185 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1186 krb5_parse_address(krb5_context context,
1188 krb5_addresses *addresses)
1190 krb5_error_code ret;
1192 struct addrinfo *ai, *a;
1193 struct addrinfo hint;
1198 addresses->val = NULL;
1200 ret = _krb5_parse_address_no_lookup(context, string, addresses);
1201 if (ret == 0 || ret != -1)
1204 /* if not parsed as numeric address, do a name lookup */
1205 memset(&hint, 0, sizeof(hint));
1206 hint.ai_family = AF_UNSPEC;
1207 error = getaddrinfo (string, NULL, &hint, &ai);
1209 krb5_error_code ret2;
1211 ret2 = krb5_eai_to_heim_errno(error, save_errno);
1212 krb5_set_error_message (context, ret2, "%s: %s",
1213 string, gai_strerror(error));
1218 for (a = ai; a != NULL; a = a->ai_next)
1221 ALLOC_SEQ(addresses, n);
1222 if (addresses->val == NULL) {
1224 return krb5_enomem(context);
1228 for (a = ai, i = 0; a != NULL; a = a->ai_next) {
1229 if (krb5_sockaddr2address (context, a->ai_addr, &addresses->val[i]))
1231 if(krb5_address_search(context, &addresses->val[i], addresses)) {
1232 krb5_free_address(context, &addresses->val[i]);
1243 * krb5_address_order compares the addresses addr1 and addr2 so that
1244 * it can be used for sorting addresses. If the addresses are the same
1245 * address krb5_address_order will return 0. Behavies like memcmp(2).
1247 * @param context a Keberos context
1248 * @param addr1 krb5_address to compare
1249 * @param addr2 krb5_address to compare
1251 * @return < 0 if address addr1 in "less" then addr2. 0 if addr1 and
1252 * addr2 is the same address, > 0 if addr2 is "less" then addr1.
1254 * @ingroup krb5_address
1257 KRB5_LIB_FUNCTION int KRB5_LIB_CALL
1258 krb5_address_order(krb5_context context,
1259 const krb5_address *addr1,
1260 const krb5_address *addr2)
1262 /* this sucks; what if both addresses have order functions, which
1263 should we call? this works for now, though */
1264 struct addr_operations *a;
1265 a = find_atype(addr1->addr_type);
1267 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
1268 N_("Address family %d not supported", ""),
1270 return KRB5_PROG_ATYPE_NOSUPP;
1272 if(a->order_addr != NULL)
1273 return (*a->order_addr)(context, addr1, addr2);
1274 a = find_atype(addr2->addr_type);
1276 krb5_set_error_message (context, KRB5_PROG_ATYPE_NOSUPP,
1277 N_("Address family %d not supported", ""),
1279 return KRB5_PROG_ATYPE_NOSUPP;
1281 if(a->order_addr != NULL)
1282 return (*a->order_addr)(context, addr1, addr2);
1284 if(addr1->addr_type != addr2->addr_type)
1285 return addr1->addr_type - addr2->addr_type;
1286 if(addr1->address.length != addr2->address.length)
1287 return addr1->address.length - addr2->address.length;
1288 return memcmp (addr1->address.data,
1289 addr2->address.data,
1290 addr1->address.length);
1294 * krb5_address_compare compares the addresses addr1 and addr2.
1295 * Returns TRUE if the two addresses are the same.
1297 * @param context a Keberos context
1298 * @param addr1 address to compare
1299 * @param addr2 address to compare
1301 * @return Return an TRUE is the address are the same FALSE if not
1303 * @ingroup krb5_address
1306 KRB5_LIB_FUNCTION krb5_boolean KRB5_LIB_CALL
1307 krb5_address_compare(krb5_context context,
1308 const krb5_address *addr1,
1309 const krb5_address *addr2)
1311 return krb5_address_order (context, addr1, addr2) == 0;
1315 * krb5_address_search checks if the address addr is a member of the
1316 * address set list addrlist .
1318 * @param context a Keberos context.
1319 * @param addr address to search for.
1320 * @param addrlist list of addresses to look in for addr.
1322 * @return Return an error code or 0.
1324 * @ingroup krb5_address
1327 KRB5_LIB_FUNCTION krb5_boolean KRB5_LIB_CALL
1328 krb5_address_search(krb5_context context,
1329 const krb5_address *addr,
1330 const krb5_addresses *addrlist)
1334 for (i = 0; i < addrlist->len; ++i)
1335 if (krb5_address_compare (context, addr, &addrlist->val[i]))
1341 * krb5_free_address frees the data stored in the address that is
1342 * alloced with any of the krb5_address functions.
1344 * @param context a Keberos context
1345 * @param address addresss to be freed.
1347 * @return Return an error code or 0.
1349 * @ingroup krb5_address
1352 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1353 krb5_free_address(krb5_context context,
1354 krb5_address *address)
1356 struct addr_operations *a = find_atype (address->addr_type);
1357 if(a != NULL && a->free_addr != NULL)
1358 return (*a->free_addr)(context, address);
1359 krb5_data_free (&address->address);
1360 memset(address, 0, sizeof(*address));
1365 * krb5_free_addresses frees the data stored in the address that is
1366 * alloced with any of the krb5_address functions.
1368 * @param context a Keberos context
1369 * @param addresses addressses to be freed.
1371 * @return Return an error code or 0.
1373 * @ingroup krb5_address
1376 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1377 krb5_free_addresses(krb5_context context,
1378 krb5_addresses *addresses)
1381 for(i = 0; i < addresses->len; i++)
1382 krb5_free_address(context, &addresses->val[i]);
1383 free(addresses->val);
1385 addresses->val = NULL;
1390 * krb5_copy_address copies the content of address
1391 * inaddr to outaddr.
1393 * @param context a Keberos context
1394 * @param inaddr pointer to source address
1395 * @param outaddr pointer to destination address
1397 * @return Return an error code or 0.
1399 * @ingroup krb5_address
1402 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1403 krb5_copy_address(krb5_context context,
1404 const krb5_address *inaddr,
1405 krb5_address *outaddr)
1407 struct addr_operations *a = find_af (inaddr->addr_type);
1408 if(a != NULL && a->copy_addr != NULL)
1409 return (*a->copy_addr)(context, inaddr, outaddr);
1410 return copy_HostAddress(inaddr, outaddr);
1414 * krb5_copy_addresses copies the content of addresses
1415 * inaddr to outaddr.
1417 * @param context a Keberos context
1418 * @param inaddr pointer to source addresses
1419 * @param outaddr pointer to destination addresses
1421 * @return Return an error code or 0.
1423 * @ingroup krb5_address
1426 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1427 krb5_copy_addresses(krb5_context context,
1428 const krb5_addresses *inaddr,
1429 krb5_addresses *outaddr)
1432 ALLOC_SEQ(outaddr, inaddr->len);
1433 if(inaddr->len > 0 && outaddr->val == NULL)
1434 return krb5_enomem(context);
1435 for(i = 0; i < inaddr->len; i++)
1436 krb5_copy_address(context, &inaddr->val[i], &outaddr->val[i]);
1441 * krb5_append_addresses adds the set of addresses in source to
1442 * dest. While copying the addresses, duplicates are also sorted out.
1444 * @param context a Keberos context
1445 * @param dest destination of copy operation
1446 * @param source adresses that are going to be added to dest
1448 * @return Return an error code or 0.
1450 * @ingroup krb5_address
1453 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1454 krb5_append_addresses(krb5_context context,
1455 krb5_addresses *dest,
1456 const krb5_addresses *source)
1459 krb5_error_code ret;
1461 if(source->len > 0) {
1462 tmp = realloc(dest->val, (dest->len + source->len) * sizeof(*tmp));
1464 return krb5_enomem(context);
1466 for(i = 0; i < source->len; i++) {
1467 /* skip duplicates */
1468 if(krb5_address_search(context, &source->val[i], dest))
1470 ret = krb5_copy_address(context,
1472 &dest->val[dest->len]);
1482 * Create an address of type KRB5_ADDRESS_ADDRPORT from (addr, port)
1484 * @param context a Keberos context
1485 * @param res built address from addr/port
1486 * @param addr address to use
1487 * @param port port to use
1489 * @return Return an error code or 0.
1491 * @ingroup krb5_address
1494 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1495 krb5_make_addrport (krb5_context context,
1496 krb5_address **res, const krb5_address *addr, int16_t port)
1498 krb5_error_code ret;
1499 size_t len = addr->address.length + 2 + 4 * 4;
1502 /* XXX Make this assume port == 0 -> port is absent */
1504 *res = malloc (sizeof(**res));
1506 return krb5_enomem(context);
1507 (*res)->addr_type = KRB5_ADDRESS_ADDRPORT;
1508 ret = krb5_data_alloc (&(*res)->address, len);
1512 return krb5_enomem(context);
1514 p = (*res)->address.data;
1517 *p++ = (addr->addr_type ) & 0xFF;
1518 *p++ = (addr->addr_type >> 8) & 0xFF;
1520 *p++ = (addr->address.length ) & 0xFF;
1521 *p++ = (addr->address.length >> 8) & 0xFF;
1522 *p++ = (addr->address.length >> 16) & 0xFF;
1523 *p++ = (addr->address.length >> 24) & 0xFF;
1525 memcpy (p, addr->address.data, addr->address.length);
1526 p += addr->address.length;
1530 *p++ = (KRB5_ADDRESS_IPPORT ) & 0xFF;
1531 *p++ = (KRB5_ADDRESS_IPPORT >> 8) & 0xFF;
1534 *p++ = (2 >> 8) & 0xFF;
1535 *p++ = (2 >> 16) & 0xFF;
1536 *p++ = (2 >> 24) & 0xFF;
1538 memcpy (p, &port, 2);
1544 * Calculate the boundary addresses of `inaddr'/`prefixlen' and store
1545 * them in `low' and `high'.
1547 * @param context a Keberos context
1548 * @param inaddr address in prefixlen that the bondery searched
1549 * @param prefixlen width of boundery
1550 * @param low lowest address
1551 * @param high highest address
1553 * @return Return an error code or 0.
1555 * @ingroup krb5_address
1558 KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
1559 krb5_address_prefixlen_boundary(krb5_context context,
1560 const krb5_address *inaddr,
1561 unsigned long prefixlen,
1565 struct addr_operations *a = find_atype (inaddr->addr_type);
1566 if(a != NULL && a->mask_boundary != NULL)
1567 return (*a->mask_boundary)(context, inaddr, prefixlen, low, high);
1568 krb5_set_error_message(context, KRB5_PROG_ATYPE_NOSUPP,
1569 N_("Address family %d doesn't support "
1570 "address mask operation", ""),
1572 return KRB5_PROG_ATYPE_NOSUPP;