2 * SPDX-License-Identifier: BSD-3-Clause
4 * Copyright (c) 1983, 1993 The Regents of the University of California.
5 * Copyright (c) 2013 Mariusz Zaborski <oshogbo@FreeBSD.org>
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
16 * 3. Neither the name of the University nor the names of its contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
24 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 static const char copyright[] =
35 "@(#) Copyright (c) 1983, 1993\n\
36 The Regents of the University of California. All rights reserved.\n";
41 static char sccsid[] = "@(#)rwhod.c 8.1 (Berkeley) 6/6/93";
45 #include <sys/cdefs.h>
46 #include <sys/param.h>
47 #include <sys/capsicum.h>
48 #include <sys/ioctl.h>
49 #include <sys/procdesc.h>
50 #include <sys/socket.h>
52 #include <sys/signal.h>
53 #include <sys/sysctl.h>
57 #include <net/if_dl.h>
58 #include <net/route.h>
59 #include <netinet/in.h>
60 #include <arpa/inet.h>
61 #include <protocols/rwhod.h>
64 #include <capsicum_helpers.h>
80 #define UNPRIV_USER "daemon"
81 #define UNPRIV_GROUP "daemon"
83 #define NO_MULTICAST 0 /* multicast modes */
84 #define PER_INTERFACE_MULTICAST 1
85 #define SCOPED_MULTICAST 2
87 #define MAX_MULTICAST_SCOPE 32 /* "site-wide", by convention */
89 #define INADDR_WHOD_GROUP (u_long)0xe0000103 /* 224.0.1.3 */
90 /* (belongs in protocols/rwhod.h) */
94 int iff_flag = IFF_POINTOPOINT;
95 int multicast_mode = NO_MULTICAST;
97 struct sockaddr_in multicast_addr =
98 { sizeof(multicast_addr), AF_INET, 0, { 0 }, { 0 } };
101 * Sleep interval. Don't forget to change the down time check in ruptime
102 * if this is changed.
104 #define SL_INTERVAL (3 * 60)
106 char myname[MAXHOSTNAMELEN];
109 * We communicate with each neighbor in a list constructed at the time we're
110 * started up. Neighbors are currently directly connected via a hardware
114 struct neighbor *n_next;
115 char *n_name; /* interface name */
116 struct sockaddr *n_addr; /* who to send to */
117 int n_addrlen; /* size of address */
118 int n_flags; /* should forward?, interface flags */
121 struct neighbor *neighbors;
126 pid_t pid_child_receiver;
128 #define WHDRSIZE (int)(sizeof(mywd) - sizeof(mywd.wd_we))
130 int configure(int so);
131 void getboottime(int signo __unused);
132 void receiver_process(void);
133 void rt_xaddrs(caddr_t cp, caddr_t cplim, struct rt_addrinfo *rtinfo);
134 void run_as(uid_t *uid, gid_t *gid);
135 void quit(const char *msg);
136 void sender_process(void);
137 int verify(char *name, int maxlen);
138 static void usage(void) __dead2;
141 char *interval(int time, char *updown);
142 void Sendto(int s, const void *buf, size_t cc, int flags,
143 const struct sockaddr *to, int tolen);
144 #define sendto Sendto
148 * This version of Berkeley's rwhod has been modified to use IP multicast
149 * datagrams, under control of a new command-line option:
151 * rwhod -m causes rwhod to use IP multicast (instead of
152 * broadcast or unicast) on all interfaces that have
153 * the IFF_MULTICAST flag set in their "ifnet" structs
154 * (excluding the loopback interface). The multicast
155 * reports are sent with a time-to-live of 1, to prevent
156 * forwarding beyond the directly-connected subnet(s).
158 * rwhod -m <ttl> causes rwhod to send IP multicast datagrams with a
159 * time-to-live of <ttl>, via a SINGLE interface rather
160 * than all interfaces. <ttl> must be between 0 and
161 * MAX_MULTICAST_SCOPE, defined below. Note that "-m 1"
162 * is different than "-m", in that "-m 1" specifies
163 * transmission on one interface only.
165 * When "-m" is used without a <ttl> argument, the program accepts multicast
166 * rwhod reports from all multicast-capable interfaces. If a <ttl> argument
167 * is given, it accepts multicast reports from only one interface, the one
168 * on which reports are sent (which may be controlled via the host's routing
169 * table). Regardless of the "-m" option, the program accepts broadcast or
170 * unicast reports from all interfaces. Thus, this program will hear the
171 * reports of old, non-multicasting rwhods, but, if multicasting is used,
172 * those old rwhods won't hear the reports generated by this program.
174 * -- Steve Deering, Stanford University, February 1989
177 main(int argc, char *argv[])
181 struct sockaddr_in soin;
187 errx(1, "not super user");
189 run_as(&unpriv_uid, &unpriv_gid);
193 while (argc > 0 && *argv[0] == '-') {
194 if (strcmp(*argv, "-m") == 0) {
195 if (argc > 1 && isdigit(*(argv + 1)[0])) {
198 multicast_mode = SCOPED_MULTICAST;
199 multicast_scope = atoi(*argv);
200 if (multicast_scope > MAX_MULTICAST_SCOPE) {
201 errx(1, "ttl must not exceed %u",
202 MAX_MULTICAST_SCOPE);
205 multicast_mode = PER_INTERFACE_MULTICAST;
207 } else if (strcmp(*argv, "-i") == 0) {
209 } else if (strcmp(*argv, "-l") == 0) {
211 } else if (strcmp(*argv, "-p") == 0) {
224 (void) signal(SIGHUP, getboottime);
225 openlog("rwhod", LOG_PID | LOG_NDELAY, LOG_DAEMON);
226 sp = getservbyname("who", "udp");
228 syslog(LOG_ERR, "who/udp: unknown service");
231 if (chdir(_PATH_RWHODIR) < 0) {
232 syslog(LOG_ERR, "%s: %m", _PATH_RWHODIR);
236 * Establish host name as returned by system.
238 if (gethostname(myname, sizeof(myname) - 1) < 0) {
239 syslog(LOG_ERR, "gethostname: %m");
242 if ((cp = strchr(myname, '.')) != NULL)
244 strlcpy(mywd.wd_hostname, myname, sizeof(mywd.wd_hostname));
246 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) < 0) {
247 syslog(LOG_ERR, "socket: %m");
250 if (setsockopt(s, SOL_SOCKET, SO_BROADCAST, &on, sizeof(on)) < 0) {
251 syslog(LOG_ERR, "setsockopt SO_BROADCAST: %m");
254 memset(&soin, 0, sizeof(soin));
255 soin.sin_len = sizeof(soin);
256 soin.sin_family = AF_INET;
257 soin.sin_port = sp->s_port;
258 if (bind(s, (struct sockaddr *)&soin, sizeof(soin)) < 0) {
259 syslog(LOG_ERR, "bind: %m");
262 if (setgid(unpriv_gid) != 0) {
263 syslog(LOG_ERR, "setgid: %m");
266 if (setgroups(1, &unpriv_gid) != 0) { /* XXX BOGUS groups[0] = egid */
267 syslog(LOG_ERR, "setgroups: %m");
270 if (setuid(unpriv_uid) != 0) {
271 syslog(LOG_ERR, "setuid: %m");
277 pid_child_receiver = pdfork(&fdp, 0);
278 if (pid_child_receiver == 0) {
280 } else if (pid_child_receiver > 0) {
282 } else if (pid_child_receiver == -1) {
283 if (errno == ENOSYS) {
285 "The pdfork(2) system call is not available - kernel too old.");
287 syslog(LOG_ERR, "pdfork: %m");
300 fprintf(stderr, "usage: rwhod [-i] [-p] [-l] [-m [ttl]]\n");
305 run_as(uid_t *uid, gid_t *gid)
310 pw = getpwnam(UNPRIV_USER);
312 syslog(LOG_ERR, "getpwnam(%s): %m", UNPRIV_USER);
317 gr = getgrnam(UNPRIV_GROUP);
319 syslog(LOG_ERR, "getgrnam(%s): %m", UNPRIV_GROUP);
326 * Check out host name for unprintables
327 * and other funnies before allowing a file
328 * to be created. Sorry, but blanks aren't allowed.
331 verify(char *name, int maxlen)
336 while (*name != '\0' && size < maxlen - 1) {
337 if (!isascii((unsigned char)*name) ||
338 !(isalnum((unsigned char)*name) ||
339 ispunct((unsigned char)*name))) {
350 receiver_process(void)
352 struct sockaddr_in from;
363 dirfd = open(".", O_RDONLY | O_DIRECTORY);
365 syslog(LOG_WARNING, "%s: %m", _PATH_RWHODIR);
368 cap_rights_init(&rights, CAP_CREATE, CAP_FSTAT, CAP_FTRUNCATE,
369 CAP_LOOKUP, CAP_SEEK, CAP_WRITE);
370 if (caph_rights_limit(dirfd, &rights) < 0) {
371 syslog(LOG_WARNING, "cap_rights_limit: %m");
374 if (caph_enter() < 0) {
375 syslog(LOG_ERR, "cap_enter: %m");
379 cc = recvfrom(s, &wd, sizeof(wd), 0, (struct sockaddr *)&from,
382 if (cc < 0 && errno != EINTR)
383 syslog(LOG_WARNING, "recv: %m");
386 if (from.sin_port != sp->s_port && !insecure_mode) {
387 syslog(LOG_WARNING, "%d: bad source port from %s",
388 ntohs(from.sin_port), inet_ntoa(from.sin_addr));
392 syslog(LOG_WARNING, "short packet from %s",
393 inet_ntoa(from.sin_addr));
396 if (wd.wd_vers != WHODVERSION)
398 if (wd.wd_type != WHODTYPE_STATUS)
400 if (!verify(wd.wd_hostname, sizeof(wd.wd_hostname))) {
401 syslog(LOG_WARNING, "malformed host name from %s",
402 inet_ntoa(from.sin_addr));
405 (void) snprintf(path, sizeof(path), "whod.%s", wd.wd_hostname);
407 * Rather than truncating and growing the file each time,
408 * use ftruncate if size is less than previous size.
410 whod = openat(dirfd, path, O_WRONLY | O_CREAT, 0644);
412 syslog(LOG_WARNING, "%s: %m", path);
415 cap_rights_init(&rights, CAP_FSTAT, CAP_FTRUNCATE, CAP_WRITE);
416 if (caph_rights_limit(whod, &rights) < 0) {
417 syslog(LOG_WARNING, "cap_rights_limit: %m");
420 #if ENDIAN != BIG_ENDIAN
425 n = (cc - WHDRSIZE) / sizeof(struct whoent);
426 /* undo header byte swapping before writing to file */
427 wd.wd_sendtime = ntohl(wd.wd_sendtime);
428 for (i = 0; i < 3; i++)
429 wd.wd_loadav[i] = ntohl(wd.wd_loadav[i]);
430 wd.wd_boottime = ntohl(wd.wd_boottime);
432 for (i = 0; i < n; i++) {
433 we->we_idle = ntohl(we->we_idle);
434 we->we_utmp.out_time =
435 ntohl(we->we_utmp.out_time);
441 wd.wd_recvtime = _time_to_int(t);
442 (void) write(whod, (char *)&wd, cc);
443 if (fstat(whod, &st) < 0 || st.st_size > cc)
460 struct whoent *we, *wend;
466 if (sendcount % 10 == 0)
469 wend = &mywd.wd_we[1024 / sizeof(struct whoent)];
471 while ((ut = getutxent()) != NULL && we < wend) {
472 if (ut->ut_type != USER_PROCESS)
474 strncpy(we->we_utmp.out_line, ut->ut_line,
475 sizeof(we->we_utmp.out_line));
476 strncpy(we->we_utmp.out_name, ut->ut_user,
477 sizeof(we->we_utmp.out_name));
478 we->we_utmp.out_time =
479 htonl(_time_to_time32(ut->ut_tv.tv_sec));
484 if (chdir(_PATH_DEV) < 0) {
485 syslog(LOG_ERR, "chdir(%s): %m", _PATH_DEV);
489 for (we = mywd.wd_we; we < wend; we++) {
490 if (stat(we->we_utmp.out_line, &stb) >= 0)
491 we->we_idle = htonl(now - stb.st_atime);
493 (void) getloadavg(avenrun,
494 sizeof(avenrun) / sizeof(avenrun[0]));
495 for (i = 0; i < 3; i++)
496 mywd.wd_loadav[i] = htonl((u_long)(avenrun[i] * 100));
497 cc = (char *)wend - (char *)&mywd;
498 mywd.wd_sendtime = htonl(_time_to_time32(time(NULL)));
499 mywd.wd_vers = WHODVERSION;
500 mywd.wd_type = WHODTYPE_STATUS;
501 if (multicast_mode == SCOPED_MULTICAST) {
502 (void) sendto(s, (char *)&mywd, cc, 0,
503 (struct sockaddr *)&multicast_addr,
504 sizeof(multicast_addr));
506 for (np = neighbors; np != NULL; np = np->n_next) {
507 if (multicast_mode == PER_INTERFACE_MULTICAST &&
508 (np->n_flags & IFF_MULTICAST) != 0) {
510 * Select the outgoing interface for the
513 if (setsockopt(s, IPPROTO_IP,
515 &(((struct sockaddr_in *)np->n_addr)->sin_addr),
516 sizeof(struct in_addr)) < 0) {
518 "setsockopt IP_MULTICAST_IF: %m");
521 (void) sendto(s, (char *)&mywd, cc, 0,
522 (struct sockaddr *)&multicast_addr,
523 sizeof(multicast_addr));
525 (void) sendto(s, (char *)&mywd, cc, 0,
526 np->n_addr, np->n_addrlen);
530 if (chdir(_PATH_RWHODIR) < 0) {
531 syslog(LOG_ERR, "chdir(%s): %m", _PATH_RWHODIR);
534 if (waitpid(pid_child_receiver, &status, WNOHANG) ==
535 pid_child_receiver) {
543 getboottime(int signo __unused)
550 mib[1] = KERN_BOOTTIME;
552 if (sysctl(mib, nitems(mib), &tm, &size, NULL, 0) == -1) {
553 syslog(LOG_ERR, "cannot get boottime: %m");
556 mywd.wd_boottime = htonl(_time_to_time32(tm.tv_sec));
560 quit(const char *msg)
563 syslog(LOG_ERR, "%s", msg);
568 rt_xaddrs(caddr_t cp, caddr_t cplim, struct rt_addrinfo *rtinfo)
573 memset(rtinfo->rti_info, 0, sizeof(rtinfo->rti_info));
574 for (i = 0; i < RTAX_MAX && cp < cplim; i++) {
575 if ((rtinfo->rti_addrs & (1 << i)) == 0)
577 sa = (struct sockaddr *)cp;
578 rtinfo->rti_info[i] = sa;
584 * Figure out device configuration and select
585 * networks which deserve status information.
591 struct if_msghdr *ifm;
592 struct ifa_msghdr *ifam;
593 struct sockaddr_dl *sdl;
595 int mib[6], flags, lflags, len;
596 char *buf, *lim, *next;
597 struct rt_addrinfo info;
600 if (multicast_mode != NO_MULTICAST) {
601 multicast_addr.sin_addr.s_addr = htonl(INADDR_WHOD_GROUP);
602 multicast_addr.sin_port = sp->s_port;
605 if (multicast_mode == SCOPED_MULTICAST) {
609 mreq.imr_multiaddr.s_addr = htonl(INADDR_WHOD_GROUP);
610 mreq.imr_interface.s_addr = htonl(INADDR_ANY);
611 if (setsockopt(so, IPPROTO_IP, IP_ADD_MEMBERSHIP,
612 &mreq, sizeof(mreq)) < 0) {
614 "setsockopt IP_ADD_MEMBERSHIP: %m");
617 ttl = multicast_scope;
618 if (setsockopt(so, IPPROTO_IP, IP_MULTICAST_TTL, &ttl,
621 "setsockopt IP_MULTICAST_TTL: %m");
631 mib[4] = NET_RT_IFLIST;
633 if (sysctl(mib, nitems(mib), NULL, &needed, NULL, 0) < 0)
634 quit("route-sysctl-estimate");
635 if ((buf = malloc(needed)) == NULL)
637 if (sysctl(mib, nitems(mib), buf, &needed, NULL, 0) < 0)
638 quit("actual retrieval of interface table");
641 sdl = NULL; /* XXX just to keep gcc -Wall happy */
642 for (next = buf; next < lim; next += ifm->ifm_msglen) {
643 ifm = (struct if_msghdr *)next;
644 if (ifm->ifm_type == RTM_IFINFO) {
645 sdl = (struct sockaddr_dl *)(ifm + 1);
646 flags = ifm->ifm_flags;
649 if ((flags & IFF_UP) == 0)
651 lflags = IFF_BROADCAST | iff_flag;
652 if (multicast_mode == PER_INTERFACE_MULTICAST)
653 lflags |= IFF_MULTICAST;
654 if ((flags & lflags) == 0)
656 if (ifm->ifm_type != RTM_NEWADDR)
657 quit("out of sync parsing NET_RT_IFLIST");
658 ifam = (struct ifa_msghdr *)ifm;
659 info.rti_addrs = ifam->ifam_addrs;
660 rt_xaddrs((char *)(ifam + 1), ifam->ifam_msglen + (char *)ifam,
662 /* gag, wish we could get rid of Internet dependencies */
663 #define dstaddr info.rti_info[RTAX_BRD]
664 #define ifaddr info.rti_info[RTAX_IFA]
665 #define IPADDR_SA(x) ((struct sockaddr_in *)(x))->sin_addr.s_addr
666 #define PORT_SA(x) ((struct sockaddr_in *)(x))->sin_port
667 if (dstaddr == 0 || dstaddr->sa_family != AF_INET)
669 PORT_SA(dstaddr) = sp->s_port;
670 for (np = neighbors; np != NULL; np = np->n_next) {
671 if (memcmp(sdl->sdl_data, np->n_name,
672 sdl->sdl_nlen) == 0 &&
673 IPADDR_SA(np->n_addr) == IPADDR_SA(dstaddr)) {
679 len = sizeof(*np) + dstaddr->sa_len + sdl->sdl_nlen + 1;
682 quit("malloc of neighbor structure");
685 np->n_addr = (struct sockaddr *)(np + 1);
686 np->n_addrlen = dstaddr->sa_len;
687 np->n_name = np->n_addrlen + (char *)np->n_addr;
688 memcpy((char *)np->n_addr, (char *)dstaddr, np->n_addrlen);
689 memcpy(np->n_name, sdl->sdl_data, sdl->sdl_nlen);
690 if (multicast_mode == PER_INTERFACE_MULTICAST &&
691 (flags & IFF_MULTICAST) != 0 &&
692 (flags & IFF_LOOPBACK) == 0) {
695 memcpy((char *)np->n_addr, (char *)ifaddr,
697 mreq.imr_multiaddr.s_addr = htonl(INADDR_WHOD_GROUP);
698 mreq.imr_interface.s_addr =
699 ((struct sockaddr_in *)np->n_addr)->sin_addr.s_addr;
700 if (setsockopt(s, IPPROTO_IP, IP_ADD_MEMBERSHIP,
701 &mreq, sizeof(mreq)) < 0) {
703 "setsockopt IP_ADD_MEMBERSHIP: %m");
705 /* Fall back to broadcast on this if. */
706 np->n_flags &= ~IFF_MULTICAST;
713 np->n_next = neighbors;
722 Sendto(int s, const void *buf, size_t cc, int flags, const struct sockaddr *to,
727 struct sockaddr_in *sin;
729 w = (struct whod *)buf;
730 sin = (struct sockaddr_in *)to;
731 printf("sendto %x.%d\n", ntohl(sin->sin_addr.s_addr),
732 ntohs(sin->sin_port));
733 printf("hostname %s %s\n", w->wd_hostname,
734 interval(ntohl(w->wd_sendtime) - ntohl(w->wd_boottime), " up"));
735 printf("load %4.2f, %4.2f, %4.2f\n",
736 ntohl(w->wd_loadav[0]) / 100.0, ntohl(w->wd_loadav[1]) / 100.0,
737 ntohl(w->wd_loadav[2]) / 100.0);
739 for (we = w->wd_we, cc /= sizeof(struct whoent); cc > 0; cc--, we++) {
740 time_t t = _time32_to_time(ntohl(we->we_utmp.out_time));
742 printf("%-8.8s %s:%s %.12s", we->we_utmp.out_name,
743 w->wd_hostname, we->we_utmp.out_line, ctime(&t) + 4);
744 we->we_idle = ntohl(we->we_idle) / 60;
745 if (we->we_idle != 0) {
746 if (we->we_idle >= 100 * 60)
747 we->we_idle = 100 * 60 - 1;
748 if (we->we_idle >= 60)
749 printf(" %2d", we->we_idle / 60);
752 printf(":%02d", we->we_idle % 60);
759 interval(int time, char *updown)
761 static char resbuf[32];
762 int days, hours, minutes;
764 if (time < 0 || time > 3 * 30 * 24 * 60 * 60) {
765 (void) sprintf(resbuf, " %s ??:??", updown);
768 minutes = (time + 59) / 60; /* round to minutes */
769 hours = minutes / 60;
774 (void) sprintf(resbuf, "%s %2d+%02d:%02d",
775 updown, days, hours, minutes);
777 (void) sprintf(resbuf, "%s %2d:%02d",
778 updown, hours, minutes);