Coverage Report

Created: 2026-08-14 06:46

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/SockFuzzer/third_party/xnu/bsd/netinet6/dest6.c
Line
Count
Source
1
/*
2
 * Copyright (c) 2020 Apple Inc. All rights reserved.
3
 *
4
 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5
 *
6
 * This file contains Original Code and/or Modifications of Original Code
7
 * as defined in and that are subject to the Apple Public Source License
8
 * Version 2.0 (the 'License'). You may not use this file except in
9
 * compliance with the License. The rights granted to you under the License
10
 * may not be used to create, or enable the creation or redistribution of,
11
 * unlawful or unlicensed copies of an Apple operating system, or to
12
 * circumvent, violate, or enable the circumvention or violation of, any
13
 * terms of an Apple operating system software license agreement.
14
 *
15
 * Please obtain a copy of the License at
16
 * http://www.opensource.apple.com/apsl/ and read it before using this file.
17
 *
18
 * The Original Code and all software distributed under the License are
19
 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20
 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21
 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22
 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23
 * Please see the License for the specific language governing rights and
24
 * limitations under the License.
25
 *
26
 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27
 */
28
/*  $FreeBSD: src/sys/netinet6/dest6.c,v 1.1.2.3 2001/07/03 11:01:49 ume Exp $  */
29
/*  $KAME: dest6.c,v 1.27 2001/03/29 05:34:30 itojun Exp $  */
30
31
/*
32
 * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
33
 * All rights reserved.
34
 *
35
 * Redistribution and use in source and binary forms, with or without
36
 * modification, are permitted provided that the following conditions
37
 * are met:
38
 * 1. Redistributions of source code must retain the above copyright
39
 *    notice, this list of conditions and the following disclaimer.
40
 * 2. Redistributions in binary form must reproduce the above copyright
41
 *    notice, this list of conditions and the following disclaimer in the
42
 *    documentation and/or other materials provided with the distribution.
43
 * 3. Neither the name of the project nor the names of its contributors
44
 *    may be used to endorse or promote products derived from this software
45
 *    without specific prior written permission.
46
 *
47
 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
48
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
49
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
50
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
51
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
52
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
53
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
54
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
55
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
56
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
57
 * SUCH DAMAGE.
58
 */
59
60
#include <sys/param.h>
61
#include <sys/systm.h>
62
#include <sys/malloc.h>
63
#include <sys/mbuf.h>
64
#include <sys/domain.h>
65
#include <sys/protosw.h>
66
#include <sys/socket.h>
67
#include <sys/errno.h>
68
#include <sys/time.h>
69
#include <sys/kernel.h>
70
71
#include <net/if.h>
72
#include <net/route.h>
73
74
#include <netinet/in.h>
75
#include <netinet/in_var.h>
76
#include <netinet/ip6.h>
77
#include <netinet6/ip6_var.h>
78
#include <netinet/icmp6.h>
79
80
/*
81
 * Destination options header processing.
82
 */
83
int
84
dest6_input(struct mbuf **mp, int *offp, int proto)
85
1.87k
{
86
1.87k
#pragma unused(proto)
87
1.87k
  struct mbuf *m = *mp;
88
1.87k
  int off = *offp, dstoptlen = 0, optlen = 0;
89
1.87k
  struct ip6_dest *dstopts = NULL;
90
1.87k
  u_int8_t *opt = NULL;
91
92
  /* validation of the length of the header */
93
1.87k
  IP6_EXTHDR_CHECK(m, off, sizeof(*dstopts), return IPPROTO_DONE);
94
1.37k
  dstopts = (struct ip6_dest *)(mtod(m, caddr_t) + off);
95
1.37k
  dstoptlen = (dstopts->ip6d_len + 1) << 3;
96
97
1.37k
  IP6_EXTHDR_CHECK(m, off, dstoptlen, return IPPROTO_DONE);
98
544
  dstopts = (struct ip6_dest *)(mtod(m, caddr_t) + off);
99
544
  off += dstoptlen;
100
544
  dstoptlen -= sizeof(struct ip6_dest);
101
544
  opt = (u_int8_t *)dstopts + sizeof(struct ip6_dest);
102
103
  /* search header for all options. */
104
1.19k
  for (optlen = 0; dstoptlen > 0; dstoptlen -= optlen, opt += optlen) {
105
1.16k
    if (*opt != IP6OPT_PAD1 &&
106
672
        (dstoptlen < IP6OPT_MINLEN || *(opt + 1) + 2 > dstoptlen)) {
107
462
      ip6stat.ip6s_toosmall++;
108
462
      goto bad;
109
462
    }
110
111
702
    switch (*opt) {
112
492
    case IP6OPT_PAD1:
113
492
      optlen = 1;
114
492
      break;
115
72
    case IP6OPT_PADN:
116
72
      optlen = *(opt + 1) + 2;
117
72
      break;
118
119
138
    default:                /* unknown option */
120
138
      optlen = ip6_unknown_opt(opt, m,
121
138
          opt - mtod(m, u_int8_t *));
122
138
      if (optlen == -1) {
123
52
        return IPPROTO_DONE;
124
52
      }
125
86
      optlen += 2;
126
86
      break;
127
702
    }
128
702
  }
129
30
  *mp = m;
130
30
  *offp = off;
131
30
  return dstopts->ip6d_nxt;
132
133
462
bad:
134
462
  *mp = NULL;
135
462
  m_freem(m);
136
462
  return IPPROTO_DONE;
137
544
}