The unified diff between revisions [7ad1775e..] and [a9b04966..] is displayed below. It can also be downloaded as a raw diff.

#
#
# patch "options.h"
#  from [c365717890e92696dd8e3f5821531993ec37ff35]
#    to [e22894088c58add5e03c694af3878550101cf465]
#
# patch "runopts.h"
#  from [36768f6323c18233529bb202e8876a3dfbc5d5a5]
#    to [64f3fc0994db48c517325204a54d171ed0dea17e]
#
# patch "svr-main.c"
#  from [7bfc54799240f5085443a31e0dc95c64ab4205b8]
#    to [d9da4aa9891528d28cb671e9750284c018d0c0d0]
#
# patch "svr-runopts.c"
#  from [dddf02f4bdfdd604ebf291af5ce48fa0fb8d6924]
#    to [8be077686a429119b73292c852d26a8064961002]
#
============================================================
--- options.h	c365717890e92696dd8e3f5821531993ec37ff35
+++ options.h	e22894088c58add5e03c694af3878550101cf465
@@ -14,6 +14,11 @@
 #define DROPBEAR_DEFPORT "22"
 #endif

+#ifndef DROPBEAR_DEFADDRESS
+/* Listen on all interfaces */
+#define DROPBEAR_DEFADDRESS ""
+#endif
+
 /* Default hostkey paths - these can be specified on the command line */
 #ifndef DSS_PRIV_FILENAME
 #define DSS_PRIV_FILENAME "/etc/dropbear/dropbear_dss_host_key"
============================================================
--- runopts.h	36768f6323c18233529bb202e8876a3dfbc5d5a5
+++ runopts.h	64f3fc0994db48c517325204a54d171ed0dea17e
@@ -55,6 +55,7 @@ typedef struct svr_runopts {
 	/* ports is an array of the portcount listening ports */
 	char *ports[DROPBEAR_MAX_PORTS];
 	unsigned int portcount;
+	char *addresses[DROPBEAR_MAX_PORTS];

 	int inetdmode;

============================================================
--- svr-main.c	7bfc54799240f5085443a31e0dc95c64ab4205b8
+++ svr-main.c	d9da4aa9891528d28cb671e9750284c018d0c0d0
@@ -397,9 +397,9 @@ static size_t listensockets(int *sock, s

 	for (i = 0; i < svr_opts.portcount; i++) {

-		TRACE(("listening on '%s'", svr_opts.ports[i]))
+		TRACE(("listening on '%s:%s'", svr_opts.addresses[i], svr_opts.ports[i]))

-		nsock = dropbear_listen("", svr_opts.ports[i], &sock[sockpos],
+		nsock = dropbear_listen(svr_opts.addresses[i], svr_opts.ports[i], &sock[sockpos],
 				sockcount - sockpos,
 				&errstring, maxfd);

============================================================
--- svr-runopts.c	dddf02f4bdfdd604ebf291af5ce48fa0fb8d6924
+++ svr-runopts.c	8be077686a429119b73292c852d26a8064961002
@@ -32,6 +32,7 @@ static void printhelp(const char * progn
 svr_runopts svr_opts; /* GLOBAL */

 static void printhelp(const char * progname);
+static void addportandaddress(char* spec);

 static void printhelp(const char * progname) {

@@ -70,8 +71,10 @@ static void printhelp(const char * progn
 					"-k		Disable remote port forwarding\n"
 					"-a		Allow connections to forwarded ports from any host\n"
 #endif
-					"-p port		Listen on specified tcp port, up to %d can be specified\n"
-					"		(default %s if none specified)\n"
+					"-p [address:]port\n"
+					"		Listen on specified tcp port (and optionally address),\n"
+					"		up to %d can be specified\n"
+					"		(default port is %s if none specified)\n"
 #ifdef INETD_MODE
 					"-i		Start for inetd\n"
 #endif
@@ -92,6 +95,7 @@ void svr_getopts(int argc, char ** argv)

 	unsigned int i;
 	char ** next = 0;
+	int nextisport = 0;

 	/* see printhelp() for options */
 	svr_opts.rsakeyfile = NULL;
@@ -126,6 +130,12 @@ void svr_getopts(int argc, char ** argv)
 #endif

 	for (i = 1; i < (unsigned int)argc; i++) {
+		if (nextisport) {
+			addportandaddress(argv[i]);
+			nextisport = 0;
+			continue;
+		}
+
 		if (next) {
 			*next = argv[i];
 			if (*next == NULL) {
@@ -177,14 +187,8 @@ void svr_getopts(int argc, char ** argv)
 					break;
 #endif
 				case 'p':
-					if (svr_opts.portcount < DROPBEAR_MAX_PORTS) {
-						svr_opts.ports[svr_opts.portcount] = NULL;
-						next = &svr_opts.ports[svr_opts.portcount];
-						/* Note: if it doesn't actually get set, we'll
-						 * decrement it after the loop */
-						svr_opts.portcount++;
-					}
-					break;
+				  nextisport = 1;
+				  break;
 #ifdef DO_MOTD
 				/* motd is displayed by default, -m turns it off */
 				case 'm':
@@ -223,15 +227,10 @@ void svr_getopts(int argc, char ** argv)
 	/* Set up listening ports */
 	if (svr_opts.portcount == 0) {
 		svr_opts.ports[0] = m_strdup(DROPBEAR_DEFPORT);
+		svr_opts.addresses[0] = m_strdup(DROPBEAR_DEFADDRESS);
 		svr_opts.portcount = 1;
-	} else {
-		/* we may have been given a -p option but no argument to go with
-		 * it */
-		if (svr_opts.ports[svr_opts.portcount-1] == NULL) {
-			svr_opts.portcount--;
-		}
 	}
-
+
 	if (svr_opts.dsskeyfile == NULL) {
 		svr_opts.dsskeyfile = DSS_PRIV_FILENAME;
 	}
@@ -261,6 +260,42 @@ void svr_getopts(int argc, char ** argv)

 }

+static void addportandaddress(char* spec) {
+
+	char *myspec = NULL;
+
+	if (svr_opts.portcount < DROPBEAR_MAX_PORTS) {
+
+		/* We don't free it, it becomes part of the runopt state */
+		myspec = m_strdup(spec);
+
+		/* search for ':', that separates address and port */
+		svr_opts.ports[svr_opts.portcount] = strchr(myspec, ':');
+
+		if (svr_opts.ports[svr_opts.portcount] == NULL) {
+			/* no ':' -> the whole string specifies just a port */
+			svr_opts.ports[svr_opts.portcount] = myspec;
+		} else {
+			/* Split the address/port */
+			svr_opts.ports[svr_opts.portcount][0] = '\0';
+			svr_opts.ports[svr_opts.portcount]++;
+			svr_opts.addresses[svr_opts.portcount] = myspec;
+		}
+
+		if (svr_opts.addresses[svr_opts.portcount] == NULL) {
+			/* no address given -> fill in the default address */
+			svr_opts.addresses[svr_opts.portcount] = m_strdup(DROPBEAR_DEFADDRESS);
+		}
+
+		if (svr_opts.ports[svr_opts.portcount][0] == '\0') {
+			/* empty port -> exit */
+			dropbear_exit("Bad port");
+		}
+
+		svr_opts.portcount++;
+	}
+}
+
 static void disablekey(int type, const char* filename) {

 	int i;