From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=R6Qa0wF/; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 7C5455A0627 for ; Tue, 25 Aug 2026 15:26:26 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787664385; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=XNVppWI/bqXdWfzwbgqoT0PugRQO04iiYaX8jP54+AA=; b=R6Qa0wF/ctPE/+BmrgftHl6INd8VpUjrBAiJs1GA5Y/Fr4k9Uialo214znqGqM9GOxgYU6 2cUYyvsayRRgCj9UjRLI9xLJj0GAqZCLc58ugHGhTrBxBHA20IOWVXFZfPmVgDVUJZ7ZnZ AiyjErcWo4LdEfaetwUhk+RBJg43iPA= Received: from mail-lf1-f71.google.com (mail-lf1-f71.google.com [209.85.167.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-691-RC03BtLCNJm0kXRpR4LC7g-1; Tue, 25 Aug 2026 09:26:23 -0400 X-MC-Unique: RC03BtLCNJm0kXRpR4LC7g-1 X-Mimecast-MFC-AGG-ID: RC03BtLCNJm0kXRpR4LC7g_1787664382 Received: by mail-lf1-f71.google.com with SMTP id 2adb3069b0e04-5aeb72bda2aso1092471e87.2 for ; Tue, 25 Aug 2026 06:26:23 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787664382; x=1788269182; h=content-transfer-encoding:content-type:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XNVppWI/bqXdWfzwbgqoT0PugRQO04iiYaX8jP54+AA=; b=D3BVuzsQDdUAGE6ulNcBQnBFtQIU10HwEAXjzoFeVlm+n0Q0H8z5ubzI7cjfz3Lzb7 UuS3WPopDX6KIFKHrNg0xuIag9IFCPrK6KwBYrfHuBRlkMmPotEv7vErIjdF0iZO5Rla DLSasfkwWVjKk4TLBM1WJINAYMBLukTumaGyutdZX0u5HTpmD6/TTkst+GoxngmLg7o2 zvUppS5uC4G9Kv+w8+Ra3L1f3gJcBs3cNUPhd2kCzKrZChEsHsyRfu9iICUk/zWj8GQ7 w6415SGbQbHKgoAwRyPbIBl4G0JCZ44jx8VWO+S4P2tCW6SbgFp+mLgannmSShWMvZKK fAdQ== X-Forwarded-Encrypted: i=1; AHgh+RqpPngW/dCx/tJlA6LZXycwrdRIRUFIiUY7qggpQIRwC6qtCGsy8ZMNuJMl2SRFNVH+QgWyP8FThMU=@passt.top X-Gm-Message-State: AFuF++mGtWsB3TZUz7on+KCQKFg3gkaXwROQKA2yZxWbXXqoKwljLKDo JGIEspPDILhtFWoi8hpSURACtWXFyTNQuTnAbgtKWO9BmWLd1NQ4D3ZKn4ZrdyouVV2JoZyuDah yxoTfla87py2uu/UQgIhYGrwqMid8ka1vkxNvkbf9t6K7QhmJen5c8Wue4UwyIA== X-Gm-Gg: AR+sD105A4eJlu0riKceQtCJsAmg2eVp5RNDnkhd1aG3nH/uZ3GIjf/yVixuSEvAyn3 3HyXEvJjV0nKLE7WOlECtmdPX09BwT6rM3KBgv7i69KCCMYVrodIOLKtzDIDehwjl7Kz/I2UtPm /1gzugTW2wkidIYyt4yZ7uXAQB5ieO2Ew3sbYtTLdtadPWmpjhP6WxaBc+2NJ4KnMubhAx/7++5 R673ZjFquqN2RJ+gCIeCtR/7w3Hv8XntBFdqRHqnG5Q0bOeLjbrg/pUpNndLv9O1GJs3dkHKoz+ Nitf7jtk+BkYMyHsIYST6RbRBB0c+Nzwm/ZzRTNYfni4QCk+5DZ2ejaIwofUjrqB9o+GWEkn2fA Ol1vuZfAptMx75qGWvXoeNS6R/qaBFZWV6HEZcWdxpOE= X-Received: by 2002:a05:6512:398b:b0:5b0:eda:de25 with SMTP id 2adb3069b0e04-5b48b8842c7mr7662867e87.6.1787664381958; Tue, 25 Aug 2026 06:26:21 -0700 (PDT) X-Received: by 2002:a05:6402:274a:b0:6a1:f95b:8cef with SMTP id 4fb4d7f45d1cf-6a582b1476emr31414306a12.4.1787663954445; Tue, 25 Aug 2026 06:19:14 -0700 (PDT) Received: from ?IPV6:2a01:e0a:e10:ef90:d92c:7e4a:47e6:1b23? ([2a01:e0a:e10:ef90:d92c:7e4a:47e6:1b23]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a59e0190d3sm13460920a12.9.2026.08.25.06.19.12 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 25 Aug 2026 06:19:13 -0700 (PDT) Message-ID: <8557a977-dd60-48cd-9bc1-cd20a8043b3c@redhat.com> Date: Tue, 25 Aug 2026 15:19:11 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v3 1/2] dhcpv6: Add --dhcpv6-opt with option type table and value parser To: Anshu Kumari , sbrivio@redhat.com, passt-dev@passt.top References: <20260824121352.244081-1-anskuma@redhat.com> <20260824121352.244081-2-anskuma@redhat.com> From: Laurent Vivier Autocrypt: addr=lvivier@redhat.com; keydata= xsFNBFYFJhkBEAC2me7w2+RizYOKZM+vZCx69GTewOwqzHrrHSG07MUAxJ6AY29/+HYf6EY2 WoeuLWDmXE7A3oJoIsRecD6BXHTb0OYS20lS608anr3B0xn5g0BX7es9Mw+hV/pL+63EOCVm SUVTEQwbGQN62guOKnJJJfphbbv82glIC/Ei4Ky8BwZkUuXd7d5NFJKC9/GDrbWdj75cDNQx UZ9XXbXEKY9MHX83Uy7JFoiFDMOVHn55HnncflUncO0zDzY7CxFeQFwYRbsCXOUL9yBtqLer Ky8/yjBskIlNrp0uQSt9LMoMsdSjYLYhvk1StsNPg74+s4u0Q6z45+l8RAsgLw5OLtTa+ePM JyS7OIGNYxAX6eZk1+91a6tnqfyPcMbduxyBaYXn94HUG162BeuyBkbNoIDkB7pCByed1A7q q9/FbuTDwgVGVLYthYSfTtN0Y60OgNkWCMtFwKxRaXt1WFA5ceqinN/XkgA+vf2Ch72zBkJL RBIhfOPFv5f2Hkkj0MvsUXpOWaOjatiu0fpPo6Hw14UEpywke1zN4NKubApQOlNKZZC4hu6/ 8pv2t4HRi7s0K88jQYBRPObjrN5+owtI51xMaYzvPitHQ2053LmgsOdN9EKOqZeHAYG2SmRW LOxYWKX14YkZI5j/TXfKlTpwSMvXho+efN4kgFvFmP6WT+tPnwARAQABzSNMYXVyZW50IFZp dmllciA8bHZpdmllckByZWRoYXQuY29tPsLBeAQTAQIAIgUCVgVQgAIbAwYLCQgHAwIGFQgC CQoLBBYCAwECHgECF4AACgkQ8ww4vT8vvjwpgg//fSGy0Rs/t8cPFuzoY1cex4limJQfReLr SJXCANg9NOWy/bFK5wunj+h/RCFxIFhZcyXveurkBwYikDPUrBoBRoOJY/BHK0iZo7/WQkur 6H5losVZtrotmKOGnP/lJYZ3H6OWvXzdz8LL5hb3TvGOP68K8Bn8UsIaZJoeiKhaNR0sOJyI YYbgFQPWMHfVwHD/U+/gqRhD7apVysxv5by/pKDln1I5v0cRRH6hd8M8oXgKhF2+rAOL7gvh jEHSSWKUlMjC7YwwjSZmUkL+TQyE18e2XBk85X8Da3FznrLiHZFHQ/NzETYxRjnOzD7/kOVy gKD/o7asyWQVU65mh/ECrtjfhtCBSYmIIVkopoLaVJ/kEbVJQegT2P6NgERC/31kmTF69vn8 uQyW11Hk8tyubicByL3/XVBrq4jZdJW3cePNJbTNaT0d/bjMg5zCWHbMErUib2Nellnbg6bc 2HLDe0NLVPuRZhHUHM9hO/JNnHfvgiRQDh6loNOUnm9Iw2YiVgZNnT4soUehMZ7au8PwSl4I KYE4ulJ8RRiydN7fES3IZWmOPlyskp1QMQBD/w16o+lEtY6HSFEzsK3o0vuBRBVp2WKnssVH qeeV01ZHw0bvWKjxVNOksP98eJfWLfV9l9e7s6TaAeySKRRubtJ+21PRuYAxKsaueBfUE7ZT 7zfOwU0EVgUmGQEQALxSQRbl/QOnmssVDxWhHM5TGxl7oLNJms2zmBpcmlrIsn8nNz0rRyxT 460k2niaTwowSRK8KWVDeAW6ZAaWiYjLlTunoKwvF8vP3JyWpBz0diTxL5o+xpvy/Q6YU3BN efdq8Vy3rFsxgW7mMSrI/CxJ667y8ot5DVugeS2NyHfmZlPGE0Nsy7hlebS4liisXOrN3jFz asKyUws3VXek4V65lHwB23BVzsnFMn/bw/rPliqXGcwl8CoJu8dSyrCcd1Ibs0/Inq9S9+t0 VmWiQWfQkz4rvEeTQkp/VfgZ6z98JRW7S6l6eophoWs0/ZyRfOm+QVSqRfFZdxdP2PlGeIFM C3fXJgygXJkFPyWkVElr76JTbtSHsGWbt6xUlYHKXWo+xf9WgtLeby3cfSkEchACrxDrQpj+ Jt/JFP+q997dybkyZ5IoHWuPkn7uZGBrKIHmBunTco1+cKSuRiSCYpBIXZMHCzPgVDjk4viP brV9NwRkmaOxVvye0vctJeWvJ6KA7NoAURplIGCqkCRwg0MmLrfoZnK/gRqVJ/f6adhU1oo6 z4p2/z3PemA0C0ANatgHgBb90cd16AUxpdEQmOCmdNnNJF/3Zt3inzF+NFzHoM5Vwq6rc1JP jfC3oqRLJzqAEHBDjQFlqNR3IFCIAo4SYQRBdAHBCzkM4rWyRhuVABEBAAHCwV8EGAECAAkF AlYFJhkCGwwACgkQ8ww4vT8vvjwg9w//VQrcnVg3TsjEybxDEUBm8dBmnKqcnTBFmxN5FFtI WlEuY8+YMiWRykd8Ln9RJ/98/ghABHz9TN8TRo2b6WimV64FmlVn17Ri6FgFU3xNt9TTEChq AcNg88eYryKsYpFwegGpwUlaUaaGh1m9OrTzcQy+klVfZWaVJ9Nw0keoGRGb8j4XjVpL8+2x OhXKrM1fzzb8JtAuSbuzZSQPDwQEI5CKKxp7zf76J21YeRrEW4WDznPyVcDTa+tz++q2S/Bp P4W98bXCBIuQgs2m+OflERv5c3Ojldp04/S4NEjXEYRWdiCxN7ca5iPml5gLtuvhJMSy36gl U6IW9kn30IWuSoBpTkgV7rLUEhh9Ms82VWW/h2TxL8enfx40PrfbDtWwqRID3WY8jLrjKfTd R3LW8BnUDNkG+c4FzvvGUs8AvuqxxyHbXAfDx9o/jXfPHVRmJVhSmd+hC3mcQ+4iX5bBPBPM oDqSoLt5w9GoQQ6gDVP2ZjTWqwSRMLzNr37rJjZ1pt0DCMMTbiYIUcrhX8eveCJtY7NGWNyx FCRkhxRuGcpwPmRVDwOl39MB3iTsRighiMnijkbLXiKoJ5CDVvX5yicNqYJPKh5MFXN1bvsB kmYiStMRbrD0HoY1kx5/VozBtc70OU0EB8Wrv9hZD+Ofp0T3KOr1RUHvCZoLURfFhSQ= In-Reply-To: <20260824121352.244081-2-anskuma@redhat.com> X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: BOqX017v6iU9_RsOb_MnWwPFcvBfo01-7hAiZvQISRE_1787664382 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Message-ID-Hash: WU6IRITMU7YBCVZWBGNQJTJUBHX6LX4T X-Message-ID-Hash: WU6IRITMU7YBCVZWBGNQJTJUBHX6LX4T X-MailFrom: lvivier@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: david@gibson.dropbear.id.au, jmaloy@redhat.com X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On 8/24/26 14:13, Anshu Kumari wrote: > Introduce the --dhcpv6-opt flag that allows setting arbitrary DHCPv6 > options from command-line in the form [--dhcpv6-opt CODE,VALUE]. > > Add a type lookup table mapping option codes to value types (IPv6, > IPv6 list, integer, string, vendor class, length-prefixed string > list) and dhcpv6_opt_parse() to convert CLI strings to binary wire > format. If the same option code is given more than once, the > last value wins. > > Link: https://bugs.passt.top/show_bug.cgi?id=192 > Signed-off-by: Anshu Kumari > --- > v3: > - Use parse_unsigned(), parse_literal(), parse_eoi() from parse.c > instead of manual strtoul()/errno/strchr() in dhcpv6_opt_parse() > for UINT and VENDOR_CLASS cases. > - Store options as pre-parsed binary in a static array indexed by > option code, instead of storing raw strings. > - Add dhcpv6_opt_to_str() to render binary option values back to > printable strings for startup logging in conf_print(). > > v2: > - Renamed custom_v6opts to dhcpv6_opts, MAX_CUSTOM_DHCPV6_OPTS > to MAX_DHCPV6_OPTS. > - Dropped val/len from ctx struct. > - Moved dhcpv6_add_option() to conf.c as static > conf_dhcpv6_option(). > - Made dhcpv6_opt_parse() non-static, declared in dhcpv6.h > - Omitted explicit [256] from dhcpv6_opt_types[]. > - Moved chunk declaration into while block. > - Removed redundant !slen check in DHCPV6_OPT_STR case. > - All errors in dhcpv6_opt_parse() return -1, removed die() > calls. > --- > conf.c | 25 ++++- > dhcpv6.c | 326 ++++++++++++++++++++++++++++++++++++++++++++++++++++++- > dhcpv6.h | 2 + > passt.1 | 31 ++++++ > 4 files changed, 382 insertions(+), 2 deletions(-) > > diff --git a/conf.c b/conf.c > index faf2681..17c7c0c 100644 > --- a/conf.c > +++ b/conf.c > @@ -47,6 +47,7 @@ > #include "lineread.h" > #include "isolation.h" > #include "log.h" > +#include "dhcpv6.h" > #include "vhost_user.h" > #include "epoll_ctl.h" > #include "conf.h" > @@ -632,7 +633,8 @@ static void usage(const char *name, FILE *f, int status) > " -S, --search LIST Space-separated list, search domains\n" > " a single, empty option disables the DNS search list\n" > " -H, --hostname NAME Hostname to configure client with\n" > - " --fqdn NAME FQDN to configure client with\n"); > + " --fqdn NAME FQDN to configure client with\n" > + " --dhcpv6-opt CODE,VAL Set DHCPv6 option CODE to VAL\n"); > if (strstr(name, "pasta")) > FPRINTF(f, " default: don't use any search list\n"); > else > @@ -900,6 +902,9 @@ static void conf_print(const struct ctx *c) > info(" our link-local: %s", > inet_ntop(AF_INET6, &c->ip6.our_tap_ll, > buf, sizeof(buf))); > + for (i = 1; i < UINT16_MAX; i++) > + if (dhcpv6_opt_to_str(i, buf, sizeof(buf))) > + info(" option %u: %s", i, buf); > > dns6: > for (i = 0; i < ARRAY_SIZE(c->ip6.dns); i++) { > @@ -1348,6 +1353,7 @@ void conf(struct ctx *c, int argc, char **argv) > {"stats", required_argument, NULL, 31 }, > {"conf-path", required_argument, NULL, 'c' }, > {"chroot-fallback", no_argument, NULL, 32 }, > + {"dhcpv6-opt", required_argument, NULL, 35 }, > { 0 }, > }; > const char *optstring = "+dqfel:hs:c:F:I:p:P:m:a:n:M:g:i:o:D:S:H:461t:u:T:U:"; > @@ -1589,6 +1595,23 @@ void conf(struct ctx *c, int argc, char **argv) > case 32: > c->chroot_fallback = true; > break; > + case 35: { > + unsigned long dhcpv6_opt_code; > + p = optarg; > + > + if (!parse_unsigned(&p, 0, &dhcpv6_opt_code) || > + !parse_literal(&p, ",")) { > + die("--dhcpv6-opt requires CODE,VALUE format"); > + } > + > + if (dhcpv6_opt_code < 1) { > + die("Invalid DHCPv6 option code: %s", > + optarg); > + } dhcpv6_opt_code is unsigned, so "dhcpv6_opt_code < 1" means "dhcpv6_opt_code == 0". You should check also dhcpv6_opt_code < UINT16_MAX because dhcpv6_set_opt() takes an uint16_t for code, and it can be silently truncated: if (dhcpv6_opt_code == 0 || dhcpv6_opt_code > UINT16_MAX) { die("Invalid DHCPv6 option code: %s", optarg); } > + > + dhcpv6_set_opt(dhcpv6_opt_code, p); > + break; > + } > case 'd': > c->debug = 1; > c->quiet = 0; > diff --git a/dhcpv6.c b/dhcpv6.c > index 29c7e32..3964dd9 100644 > --- a/dhcpv6.c > +++ b/dhcpv6.c > @@ -25,12 +25,15 @@ > #include > #include > #include > +#include > > #include "packet.h" > #include "util.h" > #include "passt.h" > #include "tap.h" > #include "log.h" > +#include "inany.h" > +#include "parse.h" > > /** > * struct opt_hdr - DHCPv6 option header > @@ -278,6 +281,328 @@ static struct resp_not_on_link_t { > { 0, }, > }; > > +/** > + * enum dhcpv6_opt_type - DHCPv6 option value types > + * @DHCPV6_OPT_NONE: Unsupported or unknown option > + * @DHCPV6_OPT_STR: Variable-length string > + * @DHCPV6_OPT_IPV6: Single IPv6 address > + * @DHCPV6_OPT_IPV6_LIST: Multiple IPv6 addresses, comma-separated > + * @DHCPV6_OPT_UINT8: Unsigned 8-bit integer > + * @DHCPV6_OPT_UINT16: Unsigned 16-bit integer > + * @DHCPV6_OPT_UINT32: Unsigned 32-bit integer > + * @DHCPV6_OPT_VENDOR_CLASS: Enterprise number + length-prefixed data > + * @DHCPV6_OPT_LEN_STR_LIST: Length-prefixed string list > + */ > +enum dhcpv6_opt_type { > + DHCPV6_OPT_NONE, > + DHCPV6_OPT_STR, > + DHCPV6_OPT_IPV6, > + DHCPV6_OPT_IPV6_LIST, > + DHCPV6_OPT_UINT8, > + DHCPV6_OPT_UINT16, > + DHCPV6_OPT_UINT32, > + DHCPV6_OPT_VENDOR_CLASS, > + DHCPV6_OPT_LEN_STR_LIST, > +}; > + > +/** > + * dhcpv6_opt_types - Maps DHCPv6 option code to value type, indexed by code > + * RFC 8415 Options: 7, 15, 16, 17, 32, 82, 83 > + * RFC 5970 Options: 59, 60 > + * RFC 4075 Options: 31 > + */ > +static const enum dhcpv6_opt_type dhcpv6_opt_types[] = { > + [7] = DHCPV6_OPT_UINT8, /* Preference */ > + [15] = DHCPV6_OPT_LEN_STR_LIST, /* User Class */ > + [16] = DHCPV6_OPT_VENDOR_CLASS, /* Vendor Class */ > + [17] = DHCPV6_OPT_VENDOR_CLASS, /* Vendor Opts */ See below, option 17 cannot be decoded with DHCPV6_OPT_VENDOR_CLASS > + [31] = DHCPV6_OPT_IPV6_LIST, /* SNTP Servers */ > + [32] = DHCPV6_OPT_UINT32, /* Information Refresh Time */ > + [59] = DHCPV6_OPT_STR, /* Boot File URL */ > + [60] = DHCPV6_OPT_LEN_STR_LIST, /* Boot File Params */ > + [82] = DHCPV6_OPT_UINT32, /* SOL_MAX_RT */ > + [83] = DHCPV6_OPT_UINT32, /* INF_MAX_RT */ > +}; > + > +/** > + * dhcpv6_opt_parse() - Parse a DHCPv6 option value string into binary > + * @code: DHCPv6 option code > + * @str: Value string from command line > + * @buf: Output buffer for binary value > + * @buf_len: Size of output buffer > + * > + * Return: number of bytes written to @buf, or -1 on error > + */ > +static int dhcpv6_opt_parse(uint16_t code, const char *str, > + uint8_t *buf, size_t buf_len) > +{ > + enum dhcpv6_opt_type type; > + unsigned long val; > + uint8_t width; > + size_t slen; > + int len; > + > + if (!*str) > + return -1; > + > + if (code >= ARRAY_SIZE(dhcpv6_opt_types)) > + return -1; > + > + type = dhcpv6_opt_types[code]; > + > + switch (type) { > + case DHCPV6_OPT_NONE: > + return -1; > + case DHCPV6_OPT_IPV6: > + case DHCPV6_OPT_IPV6_LIST: { > + union inany_addr addr; > + sa_family_t af; > + > + len = 0; > + > + do { > + if (len + sizeof(struct in6_addr) > buf_len) > + return -1; > + > + if (!parse_inany_(&str, &addr, &af) || > + af != AF_INET6) > + return -1; > + > + memcpy(buf + len, &addr.a6, sizeof(struct in6_addr)); > + len += sizeof(struct in6_addr); > + > + if (type == DHCPV6_OPT_IPV6) > + break; > + } while (parse_literal(&str, ",")); > + > + if (!len || !parse_eoi(str)) > + return -1; > + > + return len; > + } > + case DHCPV6_OPT_UINT8: > + case DHCPV6_OPT_UINT16: > + case DHCPV6_OPT_UINT32: > + if (type == DHCPV6_OPT_UINT8) > + width = 1; > + else if (type == DHCPV6_OPT_UINT16) > + width = 2; > + else > + width = 4; > + > + if (buf_len < width) > + return -1; > + > + if (!parse_unsigned(&str, 0, &val) || > + !parse_eoi(str) || > + val >= (1ULL << (width * 8))) > + return -1; > + > + if (type == DHCPV6_OPT_UINT16) > + *(uint16_t *)buf = htons(val); > + else if (type == DHCPV6_OPT_UINT32) > + *(uint32_t *)buf = htonl(val); I think they could be alignment problem here as buf is uint8_t *. You should use something like: uint16_t v16 = htons(val); memcpy(buf, &v16, sizeof(v16)); and uint32_t v32 = htonl(val); memcpy(buf, &v32, sizeof(v32)); > + else > + buf[0] = val; > + > + return width; > + case DHCPV6_OPT_STR: > + slen = strlen(str); > + > + if (slen >= buf_len) off by one, should be "if (slen > buf_len)" (as the option string is not NUL terminated). > + return -1; > + > + memcpy(buf, str, slen); > + > + return slen; > + case DHCPV6_OPT_VENDOR_CLASS: { > + uint16_t slen_net; > + uint32_t ent; > + > + if (!parse_unsigned(&str, 0, &val) || > + !parse_literal(&str, ":") || > + val > UINT32_MAX) > + return -1; > + > + slen = strlen(str); > + if (!slen) > + return -1; > + > + len = sizeof(uint32_t) + sizeof(uint16_t) + slen; Why to add sizeof(uint32_t) + sizeof(uint16_t)? For option 16, it's length of vendor-class-data/opaque-data (so without the length of enterprise-number and vendor-class-len) > + if ((size_t)len > buf_len) > + return -1; > + > + ent = htonl(val); > + memcpy(buf, &ent, sizeof(ent)); So I guess this is "enterprise-number" > + > + slen_net = htons(slen); > + memcpy(buf + sizeof(uint32_t), &slen_net, sizeof(slen_net)); For option 16, it's vendor-class-len, but for option 17 we have here sub-opt-code, so it doesn't work. I think you cannot use DHCPV6_OPT_VENDOR_CLASS with option 17. > + > + memcpy(buf + sizeof(uint32_t) + sizeof(uint16_t), > + str, slen); > + > + return len; > + } > + case DHCPV6_OPT_LEN_STR_LIST: > + len = 0; > + > + while (*str) { > + uint16_t slen_net; > + > + slen = strcspn(str, ","); > + if (!slen) > + return -1; > + > + if (len + (int)(sizeof(uint16_t) + slen) > (int)buf_len) > + return -1; > + > + slen_net = htons(slen); > + memcpy(buf + len, &slen_net, sizeof(slen_net)); > + len += sizeof(uint16_t); > + > + memcpy(buf + len, str, slen); > + len += slen; > + > + str += slen; > + if (*str == ',') > + str++; > + } > + > + if (!len) > + return -1; > + > + return len; > + } > + > + return -1; > +} > + > +/** > + * struct dhcpv6_user_opts - User-specified DHCPv6 options from --dhcpv6-opt > + * @val: Binary option value in wire format > + * @len: Length of @val in bytes, 0 if not set > + */ > +static struct { > + uint8_t val[UINT16_MAX]; > + int len; > +} dhcpv6_user_opts[ARRAY_SIZE(dhcpv6_opt_types)]; > + > +/** > + * dhcpv6_opt_to_str() - Render a binary DHCPv6 option value to printable string > + * @code: DHCPv6 option code > + * @buf: Output string buffer > + * @buf_len: Size of output buffer > + * > + * Return: pointer to @buf if option is set, NULL otherwise > + */ > +const char *dhcpv6_opt_to_str(uint16_t code, char *buf, size_t buf_len) > +{ > + enum dhcpv6_opt_type type; > + unsigned int i; > + uint16_t slen; > + int off = 0; > + > + if (code >= ARRAY_SIZE(dhcpv6_user_opts) || > + !dhcpv6_user_opts[code].len) > + return NULL; > + > + type = dhcpv6_opt_types[code]; > + > + switch (type) { > + case DHCPV6_OPT_IPV6: > + case DHCPV6_OPT_IPV6_LIST: I think buf from conf_print() is too small to contains a list of in6 addr (char buf[INANY_ADDRSTRLEN]), it can contain only one. > + for (i = 0; i + sizeof(struct in6_addr) <= > + (unsigned int)dhcpv6_user_opts[code].len; > + i += sizeof(struct in6_addr)) { > + if (off) > + off += snprintf(buf + off, buf_len - off, ","); It's simpler to write: if (off) { if (off + 1 >= (int)buf_len) return NULL; buf[off++] = ','; } > + inet_ntop(AF_INET6, dhcpv6_user_opts[code].val + i, > + buf + off, buf_len - off); Return error of inet_ntop() is silently ignored, if buf - off is not big enough, nothing is written. if (!inet_ntop(AF_INET6, dhcpv6_user_opts[code].val + i, buf + off, buf_len - off)) return NULL; > + off = strlen(buf); off += strlen(buff + off) is more efficient. > + } > + return buf; > + case DHCPV6_OPT_UINT8: > + case DHCPV6_OPT_UINT16: > + case DHCPV6_OPT_UINT32: { > + unsigned int val = 0; > + int j; > + > + for (j = 0; j < dhcpv6_user_opts[code].len; j++) > + val = (val << 8) | dhcpv6_user_opts[code].val[j]; > + > + (void)snprintf(buf, buf_len, "%u", val); > + return buf; > + } > + case DHCPV6_OPT_STR: > + (void)snprintf(buf, buf_len, "%.*s", > + dhcpv6_user_opts[code].len, > + dhcpv6_user_opts[code].val); > + return buf; > + case DHCPV6_OPT_VENDOR_CLASS: { > + uint32_t ent; > + int doff; > + > + if (dhcpv6_user_opts[code].len < > + (int)(sizeof(uint32_t) + sizeof(uint16_t))) > + return NULL; > + > + memcpy(&ent, dhcpv6_user_opts[code].val, sizeof(ent)); > + memcpy(&slen, dhcpv6_user_opts[code].val + sizeof(uint32_t), > + sizeof(slen)); > + doff = sizeof(uint32_t) + sizeof(uint16_t); > + > + (void)snprintf(buf, buf_len, "%u:%.*s", > + ntohl(ent), ntohs(slen), > + dhcpv6_user_opts[code].val + doff); > + return buf; > + } > + case DHCPV6_OPT_LEN_STR_LIST: > + off = 0; > + i = 0; > + > + while (i + sizeof(uint16_t) <= > + (unsigned int)dhcpv6_user_opts[code].len) { > + memcpy(&slen, dhcpv6_user_opts[code].val + i, > + sizeof(slen)); > + slen = ntohs(slen); > + i += sizeof(uint16_t); > + > + if (i + slen > (unsigned int)dhcpv6_user_opts[code].len) > + break; > + > + if (off) > + off += snprintf(buf + off, buf_len - off, ","); As previously: if (off) { if (off + 1 >= (int)buf_len) return NULL; buf[off++] = ','; } > + off += snprintf(buf + off, buf_len - off, "%.*s", > + slen, dhcpv6_user_opts[code].val + i); we should check buf_len is big enough to store slen. if (off + slen >= (int)buf_len) return NULL; and as we have the size, mempcpy() seems to be a better choice than snprintf() (and we have checked it fits in buf): memcpy(buf + off, dhcpv6_user_opts[code].val + i, slen); off += slen; buf[off] = '\0'; > + i += slen; > + } > + return buf; > + default: > + return NULL; > + } > +} > + > +/** > + * dhcpv6_set_opt() - Parse and store a user-specified DHCPv6 option > + * @code: DHCPv6 option code > + * @val_str: Value string from command line > + */ > +void dhcpv6_set_opt(uint16_t code, const char *val_str) > +{ > + int ret; > + > + if (code >= ARRAY_SIZE(dhcpv6_user_opts)) > + die("DHCPv6 option code %u out of supported range", code); > + > + ret = dhcpv6_opt_parse(code, val_str, > + dhcpv6_user_opts[code].val, > + sizeof(dhcpv6_user_opts[code].val)); > + if (ret < 0) > + die("Invalid value for DHCPv6 option %u: %s", code, val_str); > + > + dhcpv6_user_opts[code].len = ret; > +} > + > /** > * dhcpv6_opt() - Get option from DHCPv6 message > * @data: Buffer with options, set to matching option on return > @@ -678,7 +1003,6 @@ int dhcpv6(struct ctx *c, struct iov_tail *data, > sizeof(struct opt_hdr) + ntohs(client_id->l); > n = dhcpv6_dns_fill(c, (char *)&resp, n); > n = dhcpv6_client_fqdn_fill(data, c, (char *)&resp, n); > - Seems to be unrelated. > resp.hdr.xid = mh->xid; > > tap_udp6_send(c, src, 547, saddr, 546, mh->xid, &resp, n); > diff --git a/dhcpv6.h b/dhcpv6.h > index 1015a1a..973c477 100644 > --- a/dhcpv6.h > +++ b/dhcpv6.h > @@ -9,5 +9,7 @@ > int dhcpv6(struct ctx *c, struct iov_tail *data, > const struct in6_addr *saddr, const struct in6_addr *daddr); > void dhcpv6_init(const struct ctx *c); > +void dhcpv6_set_opt(uint16_t code, const char *val_str); > +const char *dhcpv6_opt_to_str(uint16_t code, char *buf, size_t buf_len); > > #endif /* DHCPV6_H */ > diff --git a/passt.1 b/passt.1 > index 53e072a..156aa8d 100644 > --- a/passt.1 > +++ b/passt.1 > @@ -440,6 +440,37 @@ Send \fIname\fR as DHCP option 12 (hostname). > FQDN to configure the client with. > Send \fIname\fR as Client FQDN: DHCP option 81 and DHCPv6 option 39. > > +.TP > +.BR \-\-dhcpv6-opt " " \fICODE\fR,\fIVALUE\fR > +Set DHCPv6 option \fICODE\fR to \fIVALUE\fR. The value format depends > +on the option type and is determined automatically from the option code. > +Multiple IPv6 addresses are comma-separated. > +This option can be specified multiple times. If the same option code is > +given more than once, the last value wins. > +.RS > +.TP > +.B String options > +59 (Boot File URL, RFC 5970) > +.TP > +.B Length-prefixed string list options (comma-separated entries) > +15 (User Class, RFC 8415), 60 (Boot File Params, RFC 5970). > +Each comma-separated entry is encoded with a 2-byte length prefix. > +Example: \fB\-\-dhcpv6-opt 15,class1,class2\fR. > +.TP > +.B Vendor class options (ENTERPRISE:DATA format) > +16 (Vendor Class, RFC 8415), 17 (Vendor-specific Info, RFC 8415). > +VALUE is \fIENTERPRISE\fR:\fIDATA\fR where \fIENTERPRISE\fR is the IANA > +Private Enterprise Number and \fIDATA\fR is the vendor class string. > +Example: \fB\-\-dhcpv6-opt 16,0:HTTPClient\fR for UEFI HTTP Boot. > +.TP > +.B IPv6 address list options (comma-separated) > +31 (SNTP Servers) > +.TP > +.B Integer options > +7 (Preference, 8-bit), 32 (Information Refresh Time, 32-bit), > +82 (SOL_MAX_RT, 32-bit), 83 (INF_MAX_RT, 32-bit) > +.RE > + > .TP > .BR \-t ", " \-\-tcp-ports " " \fIspec > Configure TCP port forwarding to guest or namespace. \fIspec\fR can be either: