Make sure the prefixlength of subnets is sane.
[oweals/tinc.git] / src / subnet.c
index 9d13d7c5cea7621744cd62e085cfe1553fbf4ca2..52ed443713e2147779061bb135b98f3ba28c7eb9 100644 (file)
@@ -1,7 +1,7 @@
 /*
     subnet.c -- handle subnet lookups and lists
-    Copyright (C) 2000-2002 Guus Sliepen <guus@sliepen.warande.net>,
-                  2000-2002 Ivo Timmermans <itimmermans@bigfoot.com>
+    Copyright (C) 2000-2006 Guus Sliepen <guus@tinc-vpn.org>,
+                  2000-2005 Ivo Timmermans
 
     This program is free software; you can redistribute it and/or modify
     it under the terms of the GNU General Public License as published by
     along with this program; if not, write to the Free Software
     Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
 
-    $Id: subnet.c,v 1.1.2.35 2002/04/26 18:13:00 zarq Exp $
+    $Id$
 */
 
-#include "config.h"
-
-#include <stdio.h>
-#include <syslog.h>
-#include <string.h>
-#include <errno.h>
-#include <fcntl.h>
-#include <netdb.h>
-#include <netinet/in.h>
-
-#include <utils.h>
-#include <xalloc.h>
-#include <avl_tree.h>
+#include "system.h"
 
-#include "conf.h"
+#include "avl_tree.h"
+#include "device.h"
+#include "logger.h"
 #include "net.h"
+#include "netutl.h"
 #include "node.h"
+#include "process.h"
 #include "subnet.h"
-#include "netutl.h"
-
-#include "system.h"
+#include "utils.h"
+#include "xalloc.h"
 
 /* lists type of subnet */
 
@@ -48,347 +39,437 @@ avl_tree_t *subnet_tree;
 
 /* Subnet comparison */
 
-int subnet_compare_mac(subnet_t *a, subnet_t *b)
+static int subnet_compare_mac(const subnet_t *a, const subnet_t *b)
 {
-cp
-  return memcmp(&a->net.mac.address, &b->net.mac.address, sizeof(mac_t));
+       int result;
+
+       result = memcmp(&a->net.mac.address, &b->net.mac.address, sizeof(mac_t));
+
+       if(result || !a->owner || !b->owner)
+               return result;
+
+       return strcmp(a->owner->name, b->owner->name);
 }
 
-int subnet_compare_ipv4(subnet_t *a, subnet_t *b)
+static int subnet_compare_ipv4(const subnet_t *a, const subnet_t *b)
 {
-  int result;
-cp
-  result = memcmp(&a->net.ipv4.address, &b->net.ipv4.address, sizeof(ipv4_t));
-  
-  if(result)
-    return result;
-
-  return a->net.ipv4.prefixlength - b->net.ipv4.prefixlength;
+       int result;
+
+       result = memcmp(&a->net.ipv4.address, &b->net.ipv4.address, sizeof(ipv4_t));
+
+       if(result)
+               return result;
+
+       result = a->net.ipv4.prefixlength - b->net.ipv4.prefixlength;
+
+       if(result || !a->owner || !b->owner)
+               return result;
+
+       return strcmp(a->owner->name, b->owner->name);
 }
 
-int subnet_compare_ipv6(subnet_t *a, subnet_t *b)
+static int subnet_compare_ipv6(const subnet_t *a, const subnet_t *b)
 {
-  int result;
-cp
-  result = memcmp(&a->net.ipv6.address, &b->net.ipv6.address, sizeof(ipv6_t));
-  
-  if(result)
-    return result;
-
-  return a->net.ipv6.prefixlength - b->net.ipv6.prefixlength;
+       int result;
+
+       result = memcmp(&a->net.ipv6.address, &b->net.ipv6.address, sizeof(ipv6_t));
+
+       if(result)
+               return result;
+
+       result = a->net.ipv6.prefixlength - b->net.ipv6.prefixlength;
+
+       if(result || !a->owner || !b->owner)
+               return result;
+
+       return strcmp(a->owner->name, b->owner->name);
 }
 
-int subnet_compare(subnet_t *a, subnet_t *b)
+int subnet_compare(const subnet_t *a, const subnet_t *b)
 {
-  int result;
-cp  
-  result = a->type - b->type;
-  if(result)
-    return result;
-    
-  switch(a->type)
-    {
-      case SUBNET_MAC:
-        return subnet_compare_mac(a, b);
-      case SUBNET_IPV4:
-        return subnet_compare_ipv4(a, b);
-      case SUBNET_IPV6:
-        return subnet_compare_ipv6(a, b);
-      default:
-        syslog(LOG_ERR, _("subnet_compare() was called with unknown subnet type %d, exitting!"), a->type);
-        cp_trace();
-        exit(0);
-    }
-
-  return 0;
+       int result;
+
+       result = a->type - b->type;
+
+       if(result)
+               return result;
+
+       switch (a->type) {
+       case SUBNET_MAC:
+               return subnet_compare_mac(a, b);
+       case SUBNET_IPV4:
+               return subnet_compare_ipv4(a, b);
+       case SUBNET_IPV6:
+               return subnet_compare_ipv6(a, b);
+       default:
+               logger(LOG_ERR, _("subnet_compare() was called with unknown subnet type %d, exitting!"),
+                          a->type);
+               cp_trace();
+               exit(0);
+       }
+
+       return 0;
 }
 
 /* Initialising trees */
 
 void init_subnets(void)
 {
-cp
-  subnet_tree = avl_alloc_tree((avl_compare_t)subnet_compare, (avl_action_t)free_subnet);
-cp
+       cp();
+
+       subnet_tree = avl_alloc_tree((avl_compare_t) subnet_compare, (avl_action_t) free_subnet);
 }
 
 void exit_subnets(void)
 {
-cp
-  avl_delete_tree(subnet_tree);
-cp
+       cp();
+
+       avl_delete_tree(subnet_tree);
 }
 
 avl_tree_t *new_subnet_tree(void)
 {
-cp
-  return avl_alloc_tree((avl_compare_t)subnet_compare, NULL);
-cp
+       cp();
+
+       return avl_alloc_tree((avl_compare_t) subnet_compare, NULL);
 }
 
 void free_subnet_tree(avl_tree_t *subnet_tree)
 {
-cp
-  avl_delete_tree(subnet_tree);
-cp
+       cp();
+
+       avl_delete_tree(subnet_tree);
 }
 
 /* Allocating and freeing space for subnets */
 
 subnet_t *new_subnet(void)
 {
-cp
-  return (subnet_t *)xmalloc(sizeof(subnet_t));
+       cp();
+
+       return xmalloc_and_zero(sizeof(subnet_t));
 }
 
 void free_subnet(subnet_t *subnet)
 {
-cp
-  free(subnet);
+       cp();
+
+       free(subnet);
 }
 
 /* Adding and removing subnets */
 
 void subnet_add(node_t *n, subnet_t *subnet)
 {
-cp
-  subnet->owner = n;
+       cp();
+
+       subnet->owner = n;
 
-  avl_insert(subnet_tree, subnet);
-cp
-  avl_insert(n->subnet_tree, subnet);
-cp
+       avl_insert(subnet_tree, subnet);
+       avl_insert(n->subnet_tree, subnet);
 }
 
 void subnet_del(node_t *n, subnet_t *subnet)
 {
-cp
-  avl_delete(n->subnet_tree, subnet);
-cp
-  avl_delete(subnet_tree, subnet);
-cp
+       cp();
+
+       avl_delete(n->subnet_tree, subnet);
+       avl_delete(subnet_tree, subnet);
 }
 
 /* Ascii representation of subnets */
 
-subnet_t *str2net(char *subnetstr)
+bool str2net(subnet_t *subnet, const char *subnetstr)
 {
-  int i, l;
-  subnet_t *subnet;
-  unsigned short int x[8];
-cp
-  subnet = new_subnet();
-cp
-  if(sscanf(subnetstr, "%hu.%hu.%hu.%hu/%d",
-              &x[0], &x[1], &x[2], &x[3],
-              &l) == 5)
-    {
-      subnet->type = SUBNET_IPV4;
-      subnet->net.ipv4.prefixlength = l;
-      for(i = 0; i < 4; i++)
-        subnet->net.ipv4.address.x[i] = x[i];
-      return subnet;
-    }
-             
-  if(sscanf(subnetstr, "%hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx/%d",
-             &x[0], &x[1], &x[2], &x[3], &x[4], &x[5], &x[6], &x[7],
-             &l) == 9)
-    {
-      subnet->type = SUBNET_IPV6;
-      subnet->net.ipv6.prefixlength = l;
-      for(i = 0; i < 8; i++)
-        subnet->net.ipv6.address.x[i] = htons(x[i]);
-      return subnet;
-    }
-
-  if(sscanf(subnetstr, "%hu.%hu.%hu.%hu",
-              &x[0], &x[1], &x[2], &x[3]) == 4)
-    {
-      subnet->type = SUBNET_IPV4;
-      subnet->net.ipv4.prefixlength = 32;
-      for(i = 0; i < 4; i++)
-        subnet->net.ipv4.address.x[i] = x[i];
-      return subnet;
-    }
-             
-  if(sscanf(subnetstr, "%hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx",
-             &x[0], &x[1], &x[2], &x[3], &x[4], &x[5], &x[6], &x[7]) == 8)
-    {
-      subnet->type = SUBNET_IPV6;
-      subnet->net.ipv6.prefixlength = 128;
-      for(i = 0; i < 8; i++)
-        subnet->net.ipv6.address.x[i] = htons(x[i]);
-      return subnet;
-    }
-
-  if(sscanf(subnetstr, "%hx:%hx:%hx:%hx:%hx:%hx",
-              &x[0], &x[1], &x[2], &x[3], &x[4], &x[5]) == 6)
-    {
-      subnet->type = SUBNET_MAC;
-      for(i = 0; i < 6; i++)
-        subnet->net.mac.address.x[i] = x[i];
-      return subnet;
-    }
-
-  free(subnet);
-  return NULL;
+       int i, l;
+       uint16_t x[8];
+
+       cp();
+
+       if(sscanf(subnetstr, "%hu.%hu.%hu.%hu/%d",
+                         &x[0], &x[1], &x[2], &x[3], &l) == 5) {
+               if(l < 0 || l > 32)
+                       return false;
+
+               subnet->type = SUBNET_IPV4;
+               subnet->net.ipv4.prefixlength = l;
+
+               for(i = 0; i < 4; i++) {
+                       if(x[i] > 255)
+                               return false;
+                       subnet->net.ipv4.address.x[i] = x[i];
+               }
+
+               return true;
+       }
+
+       if(sscanf(subnetstr, "%hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx/%d",
+                         &x[0], &x[1], &x[2], &x[3], &x[4], &x[5], &x[6], &x[7],
+                         &l) == 9) {
+               if(l < 0 || l > 128)
+                       return false;
+
+               subnet->type = SUBNET_IPV6;
+               subnet->net.ipv6.prefixlength = l;
+
+               for(i = 0; i < 8; i++)
+                       subnet->net.ipv6.address.x[i] = htons(x[i]);
+
+               return true;
+       }
+
+       if(sscanf(subnetstr, "%hu.%hu.%hu.%hu", &x[0], &x[1], &x[2], &x[3]) == 4) {
+               subnet->type = SUBNET_IPV4;
+               subnet->net.ipv4.prefixlength = 32;
+
+               for(i = 0; i < 4; i++) {
+                       if(x[i] > 255)
+                               return false;
+                       subnet->net.ipv4.address.x[i] = x[i];
+               }
+
+               return true;
+       }
+
+       if(sscanf(subnetstr, "%hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx",
+                         &x[0], &x[1], &x[2], &x[3], &x[4], &x[5], &x[6], &x[7]) == 8) {
+               subnet->type = SUBNET_IPV6;
+               subnet->net.ipv6.prefixlength = 128;
+
+               for(i = 0; i < 8; i++)
+                       subnet->net.ipv6.address.x[i] = htons(x[i]);
+
+               return true;
+       }
+
+       if(sscanf(subnetstr, "%hx:%hx:%hx:%hx:%hx:%hx",
+                         &x[0], &x[1], &x[2], &x[3], &x[4], &x[5]) == 6) {
+               subnet->type = SUBNET_MAC;
+
+               for(i = 0; i < 6; i++)
+                       subnet->net.mac.address.x[i] = x[i];
+
+               return true;
+       }
+
+       return false;
 }
 
-char *net2str(subnet_t *subnet)
+bool net2str(char *netstr, int len, const subnet_t *subnet)
 {
-  char *netstr;
-cp
-  switch(subnet->type)
-    {
-      case SUBNET_MAC:
-        asprintf(&netstr, "%hx:%hx:%hx:%hx:%hx:%hx",
-                   subnet->net.mac.address.x[0],
-                   subnet->net.mac.address.x[1],
-                   subnet->net.mac.address.x[2],
-                   subnet->net.mac.address.x[3],
-                   subnet->net.mac.address.x[4],
-                   subnet->net.mac.address.x[5]);
-        break;
-      case SUBNET_IPV4:
-        asprintf(&netstr, "%hu.%hu.%hu.%hu/%d",
-                  subnet->net.ipv4.address.x[0],
-                  subnet->net.ipv4.address.x[1],
-                  subnet->net.ipv4.address.x[2],
-                  subnet->net.ipv4.address.x[3],
-                  subnet->net.ipv4.prefixlength);
-        break;
-      case SUBNET_IPV6:
-        asprintf(&netstr, "%hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx/%d",
-                   ntohs(subnet->net.ipv6.address.x[0]),
-                   ntohs(subnet->net.ipv6.address.x[1]),
-                   ntohs(subnet->net.ipv6.address.x[2]),
-                   ntohs(subnet->net.ipv6.address.x[3]),
-                   ntohs(subnet->net.ipv6.address.x[4]),
-                   ntohs(subnet->net.ipv6.address.x[5]),
-                   ntohs(subnet->net.ipv6.address.x[6]),
-                   ntohs(subnet->net.ipv6.address.x[7]),
-                   subnet->net.ipv6.prefixlength);
-        break;
-      default:
-        syslog(LOG_ERR, _("net2str() was called with unknown subnet type %d, exiting!"), subnet->type);
-       cp_trace();
-        exit(0);
-    }
-cp
-  return netstr;
+       cp();
+
+       if(!netstr || !subnet) {
+               logger(LOG_ERR, _("net2str() was called with netstr=%p, subnet=%p!\n"), netstr, subnet);
+               return false;
+       }
+
+       switch (subnet->type) {
+               case SUBNET_MAC:
+                       snprintf(netstr, len, "%hx:%hx:%hx:%hx:%hx:%hx",
+                                        subnet->net.mac.address.x[0],
+                                        subnet->net.mac.address.x[1],
+                                        subnet->net.mac.address.x[2],
+                                        subnet->net.mac.address.x[3],
+                                        subnet->net.mac.address.x[4], subnet->net.mac.address.x[5]);
+                       break;
+
+               case SUBNET_IPV4:
+                       snprintf(netstr, len, "%hu.%hu.%hu.%hu/%d",
+                                        subnet->net.ipv4.address.x[0],
+                                        subnet->net.ipv4.address.x[1],
+                                        subnet->net.ipv4.address.x[2],
+                                        subnet->net.ipv4.address.x[3], subnet->net.ipv4.prefixlength);
+                       break;
+
+               case SUBNET_IPV6:
+                       snprintf(netstr, len, "%hx:%hx:%hx:%hx:%hx:%hx:%hx:%hx/%d",
+                                        ntohs(subnet->net.ipv6.address.x[0]),
+                                        ntohs(subnet->net.ipv6.address.x[1]),
+                                        ntohs(subnet->net.ipv6.address.x[2]),
+                                        ntohs(subnet->net.ipv6.address.x[3]),
+                                        ntohs(subnet->net.ipv6.address.x[4]),
+                                        ntohs(subnet->net.ipv6.address.x[5]),
+                                        ntohs(subnet->net.ipv6.address.x[6]),
+                                        ntohs(subnet->net.ipv6.address.x[7]),
+                                        subnet->net.ipv6.prefixlength);
+                       break;
+
+               default:
+                       logger(LOG_ERR,
+                                  _("net2str() was called with unknown subnet type %d, exiting!"),
+                                  subnet->type);
+                       cp_trace();
+                       exit(0);
+       }
+
+       return true;
 }
 
 /* Subnet lookup routines */
 
-subnet_t *lookup_subnet(node_t *owner, subnet_t *subnet)
+subnet_t *lookup_subnet(const node_t *owner, const subnet_t *subnet)
 {
-cp  
-  return avl_search(owner->subnet_tree, subnet);
+       cp();
+
+       return avl_search(owner->subnet_tree, subnet);
 }
 
-subnet_t *lookup_subnet_mac(mac_t *address)
+subnet_t *lookup_subnet_mac(const mac_t *address)
 {
-  subnet_t subnet, *p;
-cp
-  subnet.type = SUBNET_MAC;
-  memcpy(&subnet.net.mac.address, address, sizeof(mac_t));
-
-  p = (subnet_t *)avl_search(subnet_tree, &subnet);
-cp
-  return p;
+       subnet_t *p, subnet = {0};
+
+       cp();
+
+       subnet.type = SUBNET_MAC;
+       subnet.net.mac.address = *address;
+       subnet.owner = NULL;
+
+       p = avl_search(subnet_tree, &subnet);
+
+       return p;
 }
 
-subnet_t *lookup_subnet_ipv4(ipv4_t *address)
+subnet_t *lookup_subnet_ipv4(const ipv4_t *address)
 {
-  subnet_t subnet, *p;
-cp
-  subnet.type = SUBNET_IPV4;
-  memcpy(&subnet.net.ipv4.address, address, sizeof(ipv4_t));
-  subnet.net.ipv4.prefixlength = 32;
-
-  do
-  {
-    /* Go find subnet */
-  
-    p = (subnet_t *)avl_search_closest_smaller(subnet_tree, &subnet);
-
-  /* Check if the found subnet REALLY matches */
-cp
-    if(p)
-      {
-       if(p->type != SUBNET_IPV4)
-         {
-           p = NULL;
-           break;
-         }
-
-        if (!maskcmp((char *)address, (char *)&p->net.ipv4.address, p->net.ipv4.prefixlength, sizeof(ipv4_t)))
-          break;
-        else
-          {
-            /* Otherwise, see if there is a bigger enclosing subnet */
-
-            subnet.net.ipv4.prefixlength = p->net.ipv4.prefixlength - 1;
-            maskcpy((char *)&subnet.net.ipv4.address, (char *)&p->net.ipv4.address, subnet.net.ipv4.prefixlength, sizeof(ipv4_t));
-          }
-      }
-  } while (p);
-cp
-  return p;
+       subnet_t *p, subnet = {0};
+
+       cp();
+
+       subnet.type = SUBNET_IPV4;
+       subnet.net.ipv4.address = *address;
+       subnet.net.ipv4.prefixlength = 32;
+       subnet.owner = NULL;
+
+       do {
+               /* Go find subnet */
+
+               p = avl_search_closest_smaller(subnet_tree, &subnet);
+
+               /* Check if the found subnet REALLY matches */
+
+               if(p) {
+                       if(p->type != SUBNET_IPV4) {
+                               p = NULL;
+                               break;
+                       }
+
+                       if(!maskcmp(address, &p->net.ipv4.address, p->net.ipv4.prefixlength))
+                               break;
+                       else {
+                               /* Otherwise, see if there is a bigger enclosing subnet */
+
+                               subnet.net.ipv4.prefixlength = p->net.ipv4.prefixlength - 1;
+                               if(subnet.net.ipv4.prefixlength < 0 || subnet.net.ipv4.prefixlength > 32)
+                                       return NULL;
+                               maskcpy(&subnet.net.ipv4.address, &p->net.ipv4.address, subnet.net.ipv4.prefixlength, sizeof(ipv4_t));
+                       }
+               }
+       } while(p);
+
+       return p;
 }
 
-subnet_t *lookup_subnet_ipv6(ipv6_t *address)
+subnet_t *lookup_subnet_ipv6(const ipv6_t *address)
 {
-  subnet_t subnet, *p;
-cp
-  subnet.type = SUBNET_IPV6;
-  memcpy(&subnet.net.ipv6.address, address, sizeof(ipv6_t));
-  subnet.net.ipv6.prefixlength = 128;
-  
-  do
-  {
-    /* Go find subnet */
-  
-    p = (subnet_t *)avl_search_closest_smaller(subnet_tree, &subnet);
-
-    /* Check if the found subnet REALLY matches */
-
-cp
-    if(p)
-      {
-       if(p->type != SUBNET_IPV6)
-         return NULL;
-
-        if (!maskcmp((char *)address, (char *)&p->net.ipv6.address, p->net.ipv6.prefixlength, sizeof(ipv6_t)))
-          break;
-        else
-          {
-            /* Otherwise, see if there is a bigger enclosing subnet */
-
-            subnet.net.ipv6.prefixlength = p->net.ipv6.prefixlength - 1;
-            maskcpy((char *)&subnet.net.ipv6.address, (char *)&p->net.ipv6.address, subnet.net.ipv6.prefixlength, sizeof(ipv6_t));
-          }
-      }
-   } while (p);
-cp   
-  return p;
+       subnet_t *p, subnet = {0};
+
+       cp();
+
+       subnet.type = SUBNET_IPV6;
+       subnet.net.ipv6.address = *address;
+       subnet.net.ipv6.prefixlength = 128;
+       subnet.owner = NULL;
+
+       do {
+               /* Go find subnet */
+
+               p = avl_search_closest_smaller(subnet_tree, &subnet);
+
+               /* Check if the found subnet REALLY matches */
+
+               if(p) {
+                       if(p->type != SUBNET_IPV6)
+                               return NULL;
+
+                       if(!maskcmp(address, &p->net.ipv6.address, p->net.ipv6.prefixlength))
+                               break;
+                       else {
+                               /* Otherwise, see if there is a bigger enclosing subnet */
+
+                               subnet.net.ipv6.prefixlength = p->net.ipv6.prefixlength - 1;
+                               if(subnet.net.ipv6.prefixlength < 0 || subnet.net.ipv6.prefixlength > 128)
+                                       return NULL;
+                               maskcpy(&subnet.net.ipv6.address, &p->net.ipv6.address, subnet.net.ipv6.prefixlength, sizeof(ipv6_t));
+                       }
+               }
+       } while(p);
+
+       return p;
+}
+
+void subnet_update(node_t *owner, subnet_t *subnet, bool up) {
+       avl_node_t *node;
+       int i;
+       char *envp[8];
+       char netstr[MAXNETSTR + 7] = "SUBNET=";
+       char *name, *address, *port;
+
+       asprintf(&envp[0], "NETNAME=%s", netname ? : "");
+       asprintf(&envp[1], "DEVICE=%s", device ? : "");
+       asprintf(&envp[2], "INTERFACE=%s", iface ? : "");
+       asprintf(&envp[3], "NODE=%s", owner->name);
+
+       if(owner != myself) {
+               sockaddr2str(&owner->address, &address, &port);
+               asprintf(&envp[4], "REMOTEADDRESS=%s", address);
+               asprintf(&envp[5], "REMOTEPORT=%s", port);
+               envp[6] = netstr;
+               envp[7] = NULL;
+       } else {
+               envp[4] = netstr;
+               envp[5] = NULL;
+       }
+
+       name = up ? "subnet-up" : "subnet-down";
+
+       if(!subnet) {
+               for(node = owner->subnet_tree->head; node; node = node->next) {
+                       subnet = node->data;
+                       if(!net2str(netstr + 7, sizeof netstr - 7, subnet))
+                               continue;
+                       execute_script(name, envp);
+               }
+       } else {
+               if(net2str(netstr + 7, sizeof netstr - 7, subnet))
+                       execute_script(name, envp);
+       }
+
+       for(i = 0; i < (owner != myself ? 6 : 4); i++)
+               free(envp[i]);
+
+       if(owner != myself) {
+               free(address);
+               free(port);
+       }
 }
 
 void dump_subnets(void)
 {
-  char *netstr;
-  subnet_t *subnet;
-  avl_node_t *node;
-cp
-  syslog(LOG_DEBUG, _("Subnet list:"));
-  for(node = subnet_tree->head; node; node = node->next)
-    {
-      subnet = (subnet_t *)node->data;
-      netstr = net2str(subnet);
-      syslog(LOG_DEBUG, _(" %s owner %s"), netstr, subnet->owner->name);
-      free(netstr);
-    }
-  syslog(LOG_DEBUG, _("End of subnet list."));
-cp
+       char netstr[MAXNETSTR];
+       subnet_t *subnet;
+       avl_node_t *node;
+
+       cp();
+
+       logger(LOG_DEBUG, _("Subnet list:"));
+
+       for(node = subnet_tree->head; node; node = node->next) {
+               subnet = node->data;
+               if(!net2str(netstr, sizeof netstr, subnet))
+                       continue;
+               logger(LOG_DEBUG, _(" %s owner %s"), netstr, subnet->owner->name);
+       }
+
+       logger(LOG_DEBUG, _("End of subnet list."));
 }