Intercept.c 32 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032
  1. /*
  2. * ZeroTier One - Network Virtualization Everywhere
  3. * Copyright (C) 2011-2015 ZeroTier, Inc.
  4. *
  5. * This program is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. * --
  19. *
  20. * ZeroTier may be used and distributed under the terms of the GPLv3, which
  21. * are available at: http://www.gnu.org/licenses/gpl-3.0.html
  22. *
  23. * If you would like to embed ZeroTier into a commercial application or
  24. * redistribute it in a modified binary form, please contact ZeroTier Networks
  25. * LLC. Start here: http://www.zerotier.com/
  26. */
  27. #ifdef USE_GNU_SOURCE
  28. #define _GNU_SOURCE
  29. #endif
  30. #include <unistd.h>
  31. #include <stdint.h>
  32. #include <stdio.h>
  33. #include <dlfcn.h>
  34. #include <strings.h>
  35. #include <netinet/in.h>
  36. #include <sys/time.h>
  37. #include <pwd.h>
  38. #include <errno.h>
  39. #include <linux/errno.h>
  40. #include <stdarg.h>
  41. #include <netdb.h>
  42. #include <string.h>
  43. #include <sys/syscall.h>
  44. #include <sys/types.h>
  45. #include <sys/socket.h>
  46. #include <sys/poll.h>
  47. #include <sys/un.h>
  48. #include <arpa/inet.h>
  49. #include "Intercept.h"
  50. #include "common.inc.c"
  51. #ifdef CHECKS
  52. #include <sys/resource.h>
  53. #include <linux/net.h> /* for NPROTO */
  54. #define SOCK_MAX (SOCK_PACKET + 1)
  55. #define SOCK_TYPE_MASK 0xf
  56. #endif
  57. /* Global Declarations */
  58. static int (*realconnect)(CONNECT_SIG);
  59. static int (*realbind)(BIND_SIG);
  60. static int (*realaccept)(ACCEPT_SIG);
  61. static int (*reallisten)(LISTEN_SIG);
  62. static int (*realsocket)(SOCKET_SIG);
  63. static int (*realsetsockopt)(SETSOCKOPT_SIG);
  64. static int (*realgetsockopt)(GETSOCKOPT_SIG);
  65. static int (*realaccept4)(ACCEPT4_SIG);
  66. static long (*realsyscall)(SYSCALL_SIG);
  67. static int (*realclose)(CLOSE_SIG);
  68. static int (*realclone)(CLONE_SIG);
  69. static int (*realdup2)(DUP2_SIG);
  70. static int (*realdup3)(DUP3_SIG);
  71. static int (*realgetsockname)(GETSOCKNAME_SIG);
  72. /* Exported Function Prototypes */
  73. void my_init(void);
  74. int connect(CONNECT_SIG);
  75. int bind(BIND_SIG);
  76. int accept(ACCEPT_SIG);
  77. int listen(LISTEN_SIG);
  78. int socket(SOCKET_SIG);
  79. int setsockopt(SETSOCKOPT_SIG);
  80. int getsockopt(GETSOCKOPT_SIG);
  81. int accept4(ACCEPT4_SIG);
  82. long syscall(SYSCALL_SIG);
  83. int close(CLOSE_SIG);
  84. int clone(CLONE_SIG);
  85. int dup2(DUP2_SIG);
  86. int dup3(DUP3_SIG);
  87. int getsockname(GETSOCKNAME_SIG);
  88. static int init_service_connection();
  89. static void load_symbols(void);
  90. static void set_up_intercept();
  91. #define SERVICE_CONNECT_ATTEMPTS 30
  92. #define RPC_FD 1023
  93. static pthread_mutex_t lock;
  94. static ssize_t sock_fd_read(int sock, void *buf, ssize_t bufsize, int *fd);
  95. void handle_error(char *name, char *info, int err)
  96. {
  97. #ifdef ERRORS_ARE_FATAL
  98. if(err < 0) {
  99. dwr(MSG_DEBUG,"handle_error(%s)=%d: FATAL: %s\n", name, err, info);
  100. exit(-1);
  101. }
  102. #endif
  103. #ifdef VERBOSE
  104. dwr(MSG_DEBUG,"%s()=%d\n", name, err);
  105. #endif
  106. }
  107. /*------------------------------------------------------------------------------
  108. ------------------- Intercept<--->Service Comm mechanisms-----------------------
  109. ------------------------------------------------------------------------------*/
  110. static int is_initialized = 0;
  111. static int fdret_sock; /* used for fd-transfers */
  112. static int newfd; /* used for "this_end" socket */
  113. static int thispid = -1;
  114. static int instance_count = 0;
  115. /*
  116. * Check for forking
  117. */
  118. static void checkpid()
  119. {
  120. /* Do noting if not configured (sanity check -- should never get here in this case) */
  121. if (!getenv("ZT_NC_NETWORK"))
  122. return;
  123. if (thispid != getpid()) {
  124. dwr(MSG_DEBUG, "checkpid(): clone/fork detected. Re-initializing this instance.\n");
  125. set_up_intercept();
  126. fdret_sock = init_service_connection();
  127. thispid = getpid();
  128. }
  129. }
  130. /*
  131. * Reads a return value from the service and sets errno (if applicable)
  132. */
  133. static int get_retval()
  134. {
  135. dwr(MSG_DEBUG,"get_retval()\n");
  136. if(fdret_sock >= 0) {
  137. int retval;
  138. int sz = sizeof(char) + sizeof(retval) + sizeof(errno);
  139. char retbuf[BUF_SZ];
  140. memset(&retbuf, '\0', sz);
  141. int n_read = read(fdret_sock, &retbuf, sz);
  142. if(n_read > 0) {
  143. memcpy(&retval, &retbuf[1], sizeof(retval));
  144. memcpy(&errno, &retbuf[1+sizeof(retval)], sizeof(errno));
  145. dwr(MSG_DEBUG, "get_retval(): ret = %d\n", retval);
  146. return retval;
  147. }
  148. }
  149. dwr(MSG_DEBUG,"unable to read return value\n");
  150. return -1;
  151. }
  152. /* Reads a new file descriptor from the service */
  153. static int get_new_fd(int oversock)
  154. {
  155. char buf[BUF_SZ];
  156. int newfd;
  157. ssize_t size = sock_fd_read(oversock, buf, sizeof(buf), &newfd);
  158. if(size > 0){
  159. dwr(MSG_DEBUG, "get_new_fd(): RX: fd = (%d) over (%d)\n", newfd, oversock);
  160. return newfd;
  161. }
  162. dwr(MSG_ERROR, "get_new_fd(): ERROR: unable to read fd over (%d)\n", oversock);
  163. return -1;
  164. }
  165. #ifdef VERBOSE
  166. static unsigned long rpc_count = 0;
  167. #endif
  168. /* Sends an RPC command to the service */
  169. static int send_cmd(int rpc_fd, char *cmd)
  170. {
  171. pthread_mutex_lock(&lock);
  172. char metabuf[BUF_SZ]; // portion of buffer which contains RPC metadata for debugging
  173. #ifdef VERBOSE
  174. /*
  175. #define IDX_PID 0
  176. #define IDX_TID sizeof(pid_t)
  177. #define IDX_COUNT IDX_TID + sizeof(pid_t)
  178. #define IDX_TIME IDX_COUNT + sizeof(int)
  179. #define IDX_CMD IDX_TIME + 20 // 20 being the length of the timestamp string
  180. #define IDX_PAYLOAD IDX_TIME + sizeof(char)
  181. */
  182. /* [pid_t] [pid_t] [rpc_count] [int] [...] */
  183. memset(metabuf, '\0', BUF_SZ);
  184. pid_t pid = syscall(SYS_getpid);
  185. pid_t tid = syscall(SYS_gettid);
  186. rpc_count++;
  187. char timestring[20];
  188. time_t timestamp;
  189. timestamp = time(NULL);
  190. strftime(timestring, sizeof(timestring), "%H:%M:%S", localtime(&timestamp));
  191. memcpy(&metabuf[IDX_PID], &pid, sizeof(pid_t) ); /* pid */
  192. memcpy(&metabuf[IDX_TID], &tid, sizeof(pid_t) ); /* tid */
  193. memcpy(&metabuf[IDX_COUNT], &rpc_count, sizeof(rpc_count) ); /* rpc_count */
  194. memcpy(&metabuf[IDX_TIME], &timestring, 20 ); /* timestamp */
  195. #endif
  196. /* Combine command flag+payload with RPC metadata */
  197. memcpy(&metabuf[IDX_PAYLOAD], cmd, PAYLOAD_SZ);
  198. int n_write = write(rpc_fd, &metabuf, BUF_SZ);
  199. if(n_write < 0){
  200. dwr(MSG_DEBUG,"Error writing command to service (CMD = %d)\n", cmd[0]);
  201. errno = 0;
  202. }
  203. int ret = ERR_OK;
  204. if(n_write > 0) {
  205. if(cmd[0]==RPC_SOCKET) {
  206. ret = get_new_fd(fdret_sock);
  207. }
  208. if(cmd[0]==RPC_MAP_REQ
  209. || cmd[0]==RPC_CONNECT
  210. || cmd[0]==RPC_BIND
  211. || cmd[0]==RPC_LISTEN
  212. || cmd[0]==RPC_MAP) {
  213. ret = get_retval();
  214. }
  215. if(cmd[0]==RPC_GETSOCKNAME) {
  216. ret = n_write;
  217. }
  218. }
  219. else {
  220. ret = -1;
  221. }
  222. pthread_mutex_unlock(&lock);
  223. return ret;
  224. }
  225. /* Check whether the socket is mapped to the service or not. We
  226. need to know if this is a regular AF_LOCAL socket or an end of a socketpair
  227. that the service uses. We don't want to keep state in the intercept, so
  228. we simply ask the service via an RPC */
  229. static int is_mapped_to_service(int sockfd)
  230. {
  231. dwr(MSG_DEBUG,"is_mapped_to_service()\n");
  232. char cmd[BUF_SZ];
  233. memset(cmd, '\0', BUF_SZ);
  234. cmd[0] = RPC_MAP_REQ;
  235. memcpy(&cmd[1], &sockfd, sizeof(sockfd));
  236. return send_cmd(fdret_sock, cmd);
  237. }
  238. /*------------------------------------------------------------------------------
  239. ---------- Unix-domain socket lazy initializer (for fd-transfers)--------------
  240. ------------------------------------------------------------------------------*/
  241. /* Sets up the connection pipes and sockets to the service */
  242. static int init_service_connection()
  243. {
  244. struct sockaddr_un addr;
  245. int tfd = -1, attempts = 0, conn_err = -1;
  246. const char *network_id;
  247. char af_sock_name[1024];
  248. network_id = getenv("ZT_NC_NETWORK");
  249. if (!network_id)
  250. return -1;
  251. strncpy(af_sock_name,network_id,sizeof(af_sock_name));
  252. instance_count++;
  253. dwr(MSG_DEBUG,"init_service_connection()\n");
  254. memset(&addr, 0, sizeof(addr));
  255. addr.sun_family = AF_UNIX;
  256. strncpy(addr.sun_path, af_sock_name, sizeof(addr.sun_path)-1);
  257. if((tfd = realsocket(AF_UNIX, SOCK_STREAM, 0)) == -1)
  258. return -1;
  259. while(conn_err < 0 && attempts < SERVICE_CONNECT_ATTEMPTS) {
  260. conn_err = realconnect(tfd, (struct sockaddr*)&addr, sizeof(addr));
  261. if(conn_err < 0) {
  262. dwr(MSG_DEBUG,"re-attempting connection in %ds\n", 1+attempts);
  263. sleep(1);
  264. }
  265. else {
  266. dwr(MSG_DEBUG,"AF_UNIX connection established: %d\n", tfd);
  267. is_initialized = 1;
  268. int newtfd = realdup2(tfd, RPC_FD-instance_count);
  269. dwr(MSG_DEBUG,"dup'd to rpc_fd = %d\n", newtfd);
  270. close(tfd);
  271. return newtfd;
  272. }
  273. attempts++;
  274. }
  275. return -1;
  276. }
  277. /*------------------------------------------------------------------------------
  278. ------------------------ ctors and dtors (and friends)-------------------------
  279. ------------------------------------------------------------------------------*/
  280. static void my_dest(void) __attribute__ ((destructor));
  281. static void my_dest(void) {
  282. dwr(MSG_DEBUG,"closing connections to service...\n");
  283. pthread_mutex_destroy(&lock);
  284. }
  285. static void load_symbols(void)
  286. {
  287. if(thispid == getpid()) {
  288. dwr(MSG_DEBUG,"detected duplicate call to global constructor (pid=%d).\n", thispid);
  289. }
  290. thispid = getpid();
  291. realconnect = dlsym(RTLD_NEXT, "connect");
  292. realbind = dlsym(RTLD_NEXT, "bind");
  293. realaccept = dlsym(RTLD_NEXT, "accept");
  294. reallisten = dlsym(RTLD_NEXT, "listen");
  295. realsocket = dlsym(RTLD_NEXT, "socket");
  296. realbind = dlsym(RTLD_NEXT, "bind");
  297. realsetsockopt = dlsym(RTLD_NEXT, "setsockopt");
  298. realgetsockopt = dlsym(RTLD_NEXT, "getsockopt");
  299. realaccept4 = dlsym(RTLD_NEXT, "accept4");
  300. realclone = dlsym(RTLD_NEXT, "clone");
  301. realclose = dlsym(RTLD_NEXT, "close");
  302. realsyscall = dlsym(RTLD_NEXT, "syscall");
  303. realdup2 = dlsym(RTLD_NEXT, "dup2");
  304. realdup3 = dlsym(RTLD_NEXT, "dup3");
  305. realgetsockname = dlsym(RTLD_NEXT, "getsockname");
  306. }
  307. /* Private Function Prototypes */
  308. static void _init(void) __attribute__ ((constructor));
  309. static void _init(void) { set_up_intercept(); }
  310. /* get symbols and initialize mutexes */
  311. static void set_up_intercept()
  312. {
  313. if (!getenv("ZT_NC_NETWORK"))
  314. return;
  315. /* Hook/intercept Posix net API symbols */
  316. load_symbols();
  317. if(pthread_mutex_init(&lock, NULL) != 0) {
  318. dwr(MSG_ERROR, "error while initializing service call mutex\n");
  319. }
  320. if(pthread_mutex_init(&loglock, NULL) != 0) {
  321. dwr(MSG_ERROR, "error while initializing log mutex mutex\n");
  322. }
  323. }
  324. /*------------------------------------------------------------------------------
  325. --------------------------------- setsockopt() ---------------------------------
  326. ------------------------------------------------------------------------------*/
  327. /* int socket, int level, int option_name, const void *option_value, socklen_t option_len */
  328. int setsockopt(SETSOCKOPT_SIG)
  329. {
  330. if(realsetsockopt == NULL){
  331. dwr(MSG_ERROR, "setsockopt(): SYMBOL NOT FOUND.\n");
  332. return -1;
  333. }
  334. dwr(MSG_DEBUG,"setsockopt(%d)\n", socket);
  335. /*
  336. if(is_mapped_to_service(socket) < 0) { // First, check if the service manages this
  337. return realsetsockopt(socket, level, option_name, option_value, option_len);
  338. }
  339. */
  340. /* return(realsetsockopt(socket, level, option_name, option_value, option_len)); */
  341. if(level == SOL_IPV6 && option_name == IPV6_V6ONLY)
  342. return 0;
  343. if(level == SOL_IP && option_name == IP_TTL)
  344. return 0;
  345. if(level == IPPROTO_TCP || (level == SOL_SOCKET && option_name == SO_KEEPALIVE))
  346. return 0;
  347. /* make sure we don't touch any standard outputs */
  348. if(socket == STDIN_FILENO || socket == STDOUT_FILENO || socket == STDERR_FILENO)
  349. return(realsetsockopt(socket, level, option_name, option_value, option_len));
  350. int err = realsetsockopt(socket, level, option_name, option_value, option_len);
  351. if(err < 0){
  352. perror("setsockopt():\n");
  353. }
  354. return 0;
  355. }
  356. /*------------------------------------------------------------------------------
  357. --------------------------------- getsockopt() ---------------------------------
  358. ------------------------------------------------------------------------------*/
  359. /* int sockfd, int level, int optname, void *optval, socklen_t *optlen */
  360. int getsockopt(GETSOCKOPT_SIG)
  361. {
  362. if(realgetsockopt == NULL){
  363. dwr(MSG_ERROR, "getsockopt(): SYMBOL NOT FOUND.\n");
  364. return -1;
  365. }
  366. dwr(MSG_DEBUG,"getsockopt(%d)\n", sockfd);
  367. if(is_mapped_to_service(sockfd) <= 0) { // First, check if the service manages this
  368. return realgetsockopt(sockfd, level, optname, optval, optlen);
  369. }
  370. //return 0;
  371. //int err = realgetsockopt(sockfd, level, optname, optval, optlen);
  372. /* TODO: this condition will need a little more intelligence later on
  373. -- we will need to know if this fd is a local we are spoofing, or a true local */
  374. if(optname == SO_TYPE)
  375. {
  376. int* val = (int*)optval;
  377. *val = 2;
  378. optval = (void*)val;
  379. }
  380. /*
  381. if(err < 0){
  382. perror("getsockopt():\n");
  383. }
  384. */
  385. return 0;
  386. }
  387. /*------------------------------------------------------------------------------
  388. ----------------------------------- socket() -----------------------------------
  389. ------------------------------------------------------------------------------*/
  390. /* int socket_family, int socket_type, int protocol
  391. socket() intercept function */
  392. int socket(SOCKET_SIG)
  393. {
  394. if(realsocket == NULL){
  395. dwr(MSG_ERROR, "socket(): SYMBOL NOT FOUND.\n");
  396. return -1;
  397. }
  398. dwr(MSG_DEBUG,"socket():\n");
  399. int err;
  400. #ifdef CHECKS
  401. /* Check that type makes sense */
  402. int flags = socket_type & ~SOCK_TYPE_MASK;
  403. if (flags & ~(SOCK_CLOEXEC | SOCK_NONBLOCK)) {
  404. errno = EINVAL;
  405. handle_error("socket", "", -1);
  406. return -1;
  407. }
  408. socket_type &= SOCK_TYPE_MASK;
  409. /* Check protocol is in range */
  410. if (socket_family < 0 || socket_family >= NPROTO){
  411. errno = EAFNOSUPPORT;
  412. handle_error("socket", "", -1);
  413. return -1;
  414. }
  415. if (socket_type < 0 || socket_type >= SOCK_MAX) {
  416. errno = EINVAL;
  417. handle_error("socket", "", -1);
  418. return -1;
  419. }
  420. /* Check that we haven't hit the soft-limit file descriptors allowed */
  421. /* FIXME: Find number of open fds
  422. struct rlimit rl;
  423. getrlimit(RLIMIT_NOFILE, &rl);
  424. if(sockfd >= rl.rlim_cur){
  425. errno = EMFILE;
  426. return -1;
  427. }
  428. */
  429. /* TODO: detect ENFILE condition */
  430. #endif
  431. char cmd[BUF_SZ];
  432. fdret_sock = !is_initialized ? init_service_connection() : fdret_sock;
  433. if(fdret_sock < 0) {
  434. dwr(MSG_DEBUG,"BAD service connection. exiting.\n");
  435. handle_error("socket", "", -1);
  436. exit(-1);
  437. }
  438. if(socket_family == AF_LOCAL
  439. || socket_family == AF_NETLINK
  440. || socket_family == AF_UNIX) {
  441. int err = realsocket(socket_family, socket_type, protocol);
  442. dwr(MSG_DEBUG,"realsocket, err = %d\n", err);
  443. handle_error("socket", "", err);
  444. return err;
  445. }
  446. /* Assemble and send RPC */
  447. struct socket_st rpc_st;
  448. rpc_st.socket_family = socket_family;
  449. rpc_st.socket_type = socket_type;
  450. rpc_st.protocol = protocol;
  451. rpc_st.__tid = syscall(SYS_gettid);
  452. memset(cmd, '\0', BUF_SZ);
  453. cmd[0] = RPC_SOCKET;
  454. memcpy(&cmd[1], &rpc_st, sizeof(struct socket_st));
  455. /* send command and get new fd */
  456. newfd = send_cmd(fdret_sock, cmd);
  457. if(newfd > 0)
  458. {
  459. dwr(MSG_DEBUG,"sending fd = %d to Service over (%d)\n", newfd, fdret_sock);
  460. /* send our local-fd number back to service so
  461. it can complete its mapping table entry */
  462. memset(cmd, '\0', BUF_SZ);
  463. cmd[0] = RPC_MAP;
  464. memcpy(&cmd[1], &newfd, sizeof(newfd));
  465. /* send fd mapping and get confirmation */
  466. err = send_cmd(fdret_sock, cmd);
  467. if(err > -1) {
  468. errno = ERR_OK;
  469. dwr(MSG_DEBUG, "RXd fd confirmation. Mapped!\n");
  470. return newfd; /* Mapping complete, everything is OK */
  471. }
  472. else{
  473. dwr(MSG_DEBUG,"Error, service sent bad fd.\n");
  474. return err; /* Mapping failed */
  475. }
  476. }
  477. else {
  478. dwr(MSG_DEBUG,"Error while receiving new fd.\n");
  479. return newfd;
  480. }
  481. }
  482. /*------------------------------------------------------------------------------
  483. ---------------------------------- connect() -----------------------------------
  484. ------------------------------------------------------------------------------*/
  485. /* int __fd, const struct sockaddr * __addr, socklen_t __len
  486. connect() intercept function */
  487. int connect(CONNECT_SIG)
  488. {
  489. if(realconnect == NULL){
  490. dwr(MSG_ERROR, "connect(): SYMBOL NOT FOUND.\n");
  491. return -1;
  492. }
  493. dwr(MSG_DEBUG,"connect(%d):\n", __fd);
  494. /* print_addr(__addr); */
  495. struct sockaddr_in *connaddr;
  496. connaddr = (struct sockaddr_in *) __addr;
  497. #ifdef CHECKS
  498. /* Check that this is a valid fd */
  499. if(fcntl(__fd, F_GETFD) < 0) {
  500. errno = EBADF;
  501. handle_error("connect", "EBADF", -1);
  502. return -1;
  503. }
  504. /* Check that it is a socket */
  505. int sock_type;
  506. socklen_t sock_type_len = sizeof(sock_type);
  507. if(getsockopt(__fd, SOL_SOCKET, SO_TYPE, (void *) &sock_type, &sock_type_len) < 0) {
  508. errno = ENOTSOCK;
  509. handle_error("connect", "ENOTSOCK", -1);
  510. return -1;
  511. }
  512. /* Check family */
  513. if (connaddr->sin_family < 0 || connaddr->sin_family >= NPROTO){
  514. errno = EAFNOSUPPORT;
  515. handle_error("connect", "EAFNOSUPPORT", -1);
  516. return -1;
  517. }
  518. /* FIXME: Check that address is in user space, return EFAULT ? */
  519. #endif
  520. /* make sure we don't touch any standard outputs */
  521. if(__fd == STDIN_FILENO || __fd == STDOUT_FILENO || __fd == STDERR_FILENO){
  522. if (realconnect == NULL) {
  523. handle_error("connect", "Unresolved symbol [connect]", -1);
  524. exit(-1);
  525. }
  526. return(realconnect(__fd, __addr, __len));
  527. }
  528. if(__addr != NULL && (connaddr->sin_family == AF_LOCAL
  529. || connaddr->sin_family == PF_NETLINK
  530. || connaddr->sin_family == AF_NETLINK
  531. || connaddr->sin_family == AF_UNIX)) {
  532. int err = realconnect(__fd, __addr, __len);
  533. perror("connect():");
  534. /* handle_error("connect", "Cannot connect to local socket", err); */
  535. return err;
  536. }
  537. /* Assemble and send RPC */
  538. char cmd[BUF_SZ];
  539. memset(cmd, '\0', BUF_SZ);
  540. struct connect_st rpc_st;
  541. rpc_st.__tid = syscall(SYS_gettid);
  542. rpc_st.__fd = __fd;
  543. memcpy(&rpc_st.__addr, __addr, sizeof(struct sockaddr_storage));
  544. memcpy(&rpc_st.__len, &__len, sizeof(socklen_t));
  545. cmd[0] = RPC_CONNECT;
  546. memcpy(&cmd[1], &rpc_st, sizeof(struct connect_st));
  547. return send_cmd(fdret_sock, cmd);
  548. }
  549. /*------------------------------------------------------------------------------
  550. ------------------------------------ bind() ------------------------------------
  551. ------------------------------------------------------------------------------*/
  552. /* int sockfd, const struct sockaddr *addr, socklen_t addrlen
  553. bind() intercept function */
  554. int bind(BIND_SIG)
  555. {
  556. if(realbind == NULL){
  557. dwr(MSG_ERROR, "bind(): SYMBOL NOT FOUND.\n");
  558. return -1;
  559. }
  560. dwr(MSG_DEBUG,"bind(%d):\n", sockfd);
  561. /* print_addr(addr); */
  562. #ifdef CHECKS
  563. /* Check that this is a valid fd */
  564. if(fcntl(sockfd, F_GETFD) < 0) {
  565. errno = EBADF;
  566. handle_error("bind", "EBADF", -1);
  567. return -1;
  568. }
  569. /* Check that it is a socket */
  570. int opt = -1;
  571. socklen_t opt_len;
  572. if(getsockopt(sockfd, SOL_SOCKET, SO_TYPE, (void *) &opt, &opt_len) < 0) {
  573. errno = ENOTSOCK;
  574. handle_error("bind", "ENOTSOCK", -1);
  575. return -1;
  576. }
  577. #endif
  578. /* make sure we don't touch any standard outputs */
  579. if(sockfd == STDIN_FILENO || sockfd == STDOUT_FILENO || sockfd == STDERR_FILENO)
  580. return(realbind(sockfd, addr, addrlen));
  581. /* If local, just use normal syscall */
  582. struct sockaddr_in *connaddr;
  583. connaddr = (struct sockaddr_in *)addr;
  584. if(connaddr->sin_family == AF_LOCAL
  585. || connaddr->sin_family == AF_NETLINK
  586. || connaddr->sin_family == AF_UNIX) {
  587. int err = realbind(sockfd, addr, addrlen);
  588. dwr(MSG_DEBUG,"realbind, err = %d\n", err);
  589. return err;
  590. }
  591. int port = connaddr->sin_port;
  592. int ip = connaddr->sin_addr.s_addr;
  593. unsigned char d[4];
  594. d[0] = ip & 0xFF;
  595. d[1] = (ip >> 8) & 0xFF;
  596. d[2] = (ip >> 16) & 0xFF;
  597. d[3] = (ip >> 24) & 0xFF;
  598. dwr(MSG_DEBUG, "bind(): %d.%d.%d.%d: %d\n", d[0],d[1],d[2],d[3], ntohs(port));
  599. /* Assemble and send RPC */
  600. char cmd[BUF_SZ];
  601. struct bind_st rpc_st;
  602. rpc_st.sockfd = sockfd;
  603. rpc_st.__tid = syscall(SYS_gettid);
  604. memcpy(&rpc_st.addr, addr, sizeof(struct sockaddr_storage));
  605. memcpy(&rpc_st.addrlen, &addrlen, sizeof(socklen_t));
  606. cmd[0]=RPC_BIND;
  607. memcpy(&cmd[1], &rpc_st, sizeof(struct bind_st));
  608. return send_cmd(fdret_sock, cmd);
  609. }
  610. /*------------------------------------------------------------------------------
  611. ----------------------------------- accept4() ----------------------------------
  612. ------------------------------------------------------------------------------*/
  613. /* int sockfd, struct sockaddr *addr, socklen_t *addrlen, int flags */
  614. int accept4(ACCEPT4_SIG)
  615. {
  616. if(realaccept4 == NULL){
  617. dwr(MSG_ERROR, "accept4(): SYMBOL NOT FOUND.\n");
  618. return -1;
  619. }
  620. dwr(MSG_DEBUG,"accept4(%d):\n", sockfd);
  621. #ifdef CHECKS
  622. if (flags & ~(SOCK_CLOEXEC | SOCK_NONBLOCK)) {
  623. errno = EINVAL;
  624. return -1;
  625. }
  626. #endif
  627. int newfd = accept(sockfd, addr, addrlen);
  628. if(newfd > 0) {
  629. if(flags & SOCK_CLOEXEC)
  630. fcntl(newfd, F_SETFL, FD_CLOEXEC);
  631. if(flags & SOCK_NONBLOCK)
  632. fcntl(newfd, F_SETFL, O_NONBLOCK);
  633. }
  634. handle_error("accept4", "", newfd);
  635. return newfd;
  636. }
  637. /*------------------------------------------------------------------------------
  638. ----------------------------------- accept() -----------------------------------
  639. ------------------------------------------------------------------------------*/
  640. /* int sockfd struct sockaddr *addr, socklen_t *addrlen
  641. accept() intercept function */
  642. int accept(ACCEPT_SIG)
  643. {
  644. if(realaccept == NULL){
  645. dwr(MSG_ERROR, "accept(): SYMBOL NOT FOUND.\n");
  646. return -1;
  647. }
  648. dwr(MSG_DEBUG,"accept(%d):\n", sockfd);
  649. #ifdef CHECKS
  650. /* Check that this is a valid fd */
  651. if(fcntl(sockfd, F_GETFD) < 0) {
  652. return -1;
  653. errno = EBADF;
  654. dwr(MSG_DEBUG,"EBADF\n");
  655. handle_error("accept", "EBADF", -1);
  656. return -1;
  657. }
  658. /* Check that it is a socket */
  659. int opt;
  660. socklen_t opt_len;
  661. if(getsockopt(sockfd, SOL_SOCKET, SO_TYPE, (void *) &opt, &opt_len) < 0) {
  662. errno = ENOTSOCK;
  663. dwr(MSG_DEBUG,"ENOTSOCK\n");
  664. handle_error("accept", "ENOTSOCK", -1);
  665. return -1;
  666. }
  667. /* Check that this socket supports accept() */
  668. if(!(opt && (SOCK_STREAM | SOCK_SEQPACKET))) {
  669. errno = EOPNOTSUPP;
  670. dwr(MSG_DEBUG,"EOPNOTSUPP\n");
  671. handle_error("accept", "EOPNOTSUPP", -1);
  672. return -1;
  673. }
  674. /* Check that we haven't hit the soft-limit file descriptors allowed */
  675. struct rlimit rl;
  676. getrlimit(RLIMIT_NOFILE, &rl);
  677. if(sockfd >= rl.rlim_cur){
  678. errno = EMFILE;
  679. dwr(MSG_DEBUG,"EMFILE\n");
  680. handle_error("accept", "EMFILE", -1);
  681. return -1;
  682. }
  683. /* Check address length */
  684. if(addrlen < 0) {
  685. errno = EINVAL;
  686. dwr(MSG_DEBUG,"EINVAL\n");
  687. handle_error("accept", "EINVAL", -1);
  688. return -1;
  689. }
  690. #endif
  691. /* redirect calls for standard I/O descriptors to kernel */
  692. if(sockfd == STDIN_FILENO || sockfd == STDOUT_FILENO || sockfd == STDERR_FILENO){
  693. dwr(MSG_DEBUG,"realaccept():\n");
  694. return(realaccept(sockfd, addr, addrlen));
  695. }
  696. if(addr)
  697. addr->sa_family = AF_INET;
  698. /* TODO: also get address info */
  699. char cmd[BUF_SZ];
  700. /* The following line is required for libuv/nodejs to accept connections properly,
  701. however, this has the side effect of causing certain webservers to max out the CPU
  702. in an accept loop */
  703. fcntl(sockfd, F_SETFL, SOCK_NONBLOCK);
  704. int new_conn_socket = get_new_fd(sockfd);
  705. if(new_conn_socket > 0)
  706. {
  707. dwr(MSG_DEBUG, "accept(): RX: fd = (%d) over (%d)\n", new_conn_socket, fdret_sock);
  708. /* Send our local-fd number back to service so it can complete its mapping table */
  709. memset(cmd, '\0', BUF_SZ);
  710. cmd[0] = RPC_MAP;
  711. memcpy(&cmd[1], &new_conn_socket, sizeof(new_conn_socket));
  712. dwr(MSG_DEBUG, "accept(): sending perceived fd (%d) to service.\n", new_conn_socket);
  713. send_cmd(fdret_sock, cmd);
  714. /*
  715. if(n_write < 0) {
  716. errno = ECONNABORTED;
  717. handle_error("accept", "ECONNABORTED - Error sending perceived FD to service", -1);
  718. return -1;
  719. }
  720. */
  721. errno = ERR_OK;
  722. dwr(MSG_DEBUG,"accept()=%d\n", new_conn_socket);
  723. return new_conn_socket; /* OK */
  724. }
  725. errno = EAGAIN; /* necessary? */
  726. handle_error("accept", "EAGAIN - Error reading signal byte from service", -1);
  727. return -EAGAIN;
  728. }
  729. /*------------------------------------------------------------------------------
  730. ------------------------------------- listen()----------------------------------
  731. ------------------------------------------------------------------------------*/
  732. /* int sockfd, int backlog */
  733. int listen(LISTEN_SIG)
  734. {
  735. if(reallisten == NULL){
  736. dwr(MSG_ERROR, "listen(): SYMBOL NOT FOUND.\n");
  737. return -1;
  738. }
  739. dwr(MSG_DEBUG,"listen(%d):\n", sockfd);
  740. int sock_type;
  741. socklen_t sock_type_len = sizeof(sock_type);
  742. #ifdef CHECKS
  743. /* Check that this is a valid fd */
  744. if(fcntl(sockfd, F_GETFD) < 0) {
  745. errno = EBADF;
  746. handle_error("listen", "EBADF", -1);
  747. return -1;
  748. }
  749. /* Check that it is a socket */
  750. if(getsockopt(sockfd, SOL_SOCKET, SO_TYPE, (void *) &sock_type, &sock_type_len) < 0) {
  751. errno = ENOTSOCK;
  752. handle_error("listen", "ENOTSOCK", -1);
  753. return -1;
  754. }
  755. /* Check that this socket supports accept() */
  756. if(!(sock_type && (SOCK_STREAM | SOCK_SEQPACKET))) {
  757. errno = EOPNOTSUPP;
  758. handle_error("listen", "EOPNOTSUPP", -1);
  759. return -1;
  760. }
  761. #endif
  762. /* make sure we don't touch any standard outputs */
  763. if(sockfd == STDIN_FILENO || sockfd == STDOUT_FILENO || sockfd == STDERR_FILENO)
  764. return(reallisten(sockfd, backlog));
  765. if(is_mapped_to_service(sockfd) < 0) {
  766. /* We now know this socket is not one of our socketpairs */
  767. int err = reallisten(sockfd, backlog);
  768. dwr(MSG_DEBUG,"reallisten()=%d\n", err);
  769. return err;
  770. }
  771. /* Assemble and send RPC */
  772. char cmd[BUF_SZ];
  773. memset(cmd, '\0', BUF_SZ);
  774. struct listen_st rpc_st;
  775. rpc_st.sockfd = sockfd;
  776. rpc_st.backlog = backlog;
  777. rpc_st.__tid = syscall(SYS_gettid);
  778. cmd[0] = RPC_LISTEN;
  779. memcpy(&cmd[1], &rpc_st, sizeof(struct listen_st));
  780. return send_cmd(fdret_sock, cmd);
  781. }
  782. /*------------------------------------------------------------------------------
  783. -------------------------------------- clone() ---------------------------------
  784. ------------------------------------------------------------------------------*/
  785. /* int (*fn)(void *), void *child_stack, int flags, void *arg, ... */
  786. int clone(CLONE_SIG)
  787. {
  788. if(realclone == NULL){
  789. dwr(MSG_ERROR, "clone(): SYMBOL NOT FOUND.\n");
  790. return -1;
  791. }
  792. dwr(MSG_DEBUG,"clone()\n");
  793. int err = realclone(fn, child_stack, flags, arg);
  794. checkpid();
  795. return err;
  796. }
  797. /*------------------------------------------------------------------------------
  798. ------------------------------------- close() ----------------------------------
  799. ------------------------------------------------------------------------------*/
  800. /* int fd */
  801. int close(CLOSE_SIG)
  802. {
  803. dwr(MSG_DEBUG, "close(%d)\n", fd);
  804. if(realclose == NULL){
  805. checkpid(); // Add for nginx support, remove for apache support.
  806. dwr(MSG_ERROR, "close(%d): SYMBOL NOT FOUND.\n", fd);
  807. return -1;
  808. }
  809. if(fd == fdret_sock)
  810. return -1; /* TODO: Ignore request to shut down our rpc fd, this is *almost always* safe */
  811. if(fd != STDIN_FILENO && fd != STDOUT_FILENO && fd != STDERR_FILENO)
  812. return realclose(fd);
  813. return -1;
  814. }
  815. /*------------------------------------------------------------------------------
  816. -------------------------------------- dup2() ----------------------------------
  817. ------------------------------------------------------------------------------*/
  818. /* int oldfd, int newfd */
  819. int dup2(DUP2_SIG)
  820. {
  821. if(realdup2 == NULL){
  822. dwr(MSG_ERROR, "dup2(): SYMBOL NOT FOUND.\n");
  823. return -1;
  824. }
  825. dwr(MSG_DEBUG,"dup2(%d, %d)\n", oldfd, newfd);
  826. if(oldfd == fdret_sock) {
  827. dwr(MSG_DEBUG,"client application attempted to dup2 RPC socket (%d). This is not allowed.\n", oldfd);
  828. errno = EBADF;
  829. return -1;
  830. }
  831. //if(oldfd != STDIN_FILENO && oldfd != STDOUT_FILENO && oldfd != STDERR_FILENO)
  832. // if(newfd != STDIN_FILENO && newfd != STDOUT_FILENO && newfd != STDERR_FILENO)
  833. return realdup2(oldfd, newfd);
  834. return -1;
  835. }
  836. /*------------------------------------------------------------------------------
  837. -------------------------------------- dup3() ----------------------------------
  838. ------------------------------------------------------------------------------*/
  839. /* int oldfd, int newfd, int flags */
  840. int dup3(DUP3_SIG)
  841. {
  842. if(realdup3 == NULL){
  843. dwr(MSG_ERROR, "dup3(): SYMBOL NOT FOUND.\n");
  844. return -1;
  845. }
  846. dwr(MSG_DEBUG,"dup3(%d, %d, %d)\n", oldfd, newfd, flags);
  847. #ifdef DEBUG
  848. /* Only do this check if we want to debug the intercept, otherwise, dont mess with
  849. the client application's logging methods */
  850. if(newfd == STDIN_FILENO || newfd == STDOUT_FILENO || newfd == STDERR_FILENO)
  851. return newfd; /* FIXME: This is to prevent httpd from dup'ing over our stderr
  852. and preventing us from debugging */
  853. else
  854. #endif
  855. return realdup3(oldfd, newfd, flags);
  856. }
  857. /*------------------------------------------------------------------------------
  858. -------------------------------- getsockname() ---------------------------------
  859. ------------------------------------------------------------------------------*/
  860. /* define GETSOCKNAME_SIG int sockfd, struct sockaddr *addr, socklen_t *addrlen */
  861. int getsockname(GETSOCKNAME_SIG)
  862. {
  863. if (realgetsockname == NULL) {
  864. dwr(MSG_ERROR, "getsockname(): SYMBOL NOT FOUND. \n");
  865. return -1;
  866. }
  867. dwr(MSG_DEBUG, "getsockname(%d)\n", sockfd);
  868. if(!is_mapped_to_service(sockfd))
  869. return realgetsockname(sockfd, addr, addrlen);
  870. /* This is kind of a hack as it stands -- assumes sockaddr is sockaddr_in
  871. * and is an IPv4 address. */
  872. /* assemble and send command */
  873. char cmd[BUF_SZ];
  874. struct getsockname_st rpc_st;
  875. rpc_st.sockfd = sockfd;
  876. memcpy(&rpc_st.addr, addr, *addrlen);
  877. memcpy(&rpc_st.addrlen, &addrlen, sizeof(socklen_t));
  878. cmd[0] = RPC_GETSOCKNAME;
  879. memcpy(&cmd[1], &rpc_st, sizeof(struct getsockname_st));
  880. send_cmd(fdret_sock, cmd);
  881. /* read address info from service */
  882. char addrbuf[sizeof(struct sockaddr_storage)];
  883. memset(&addrbuf, 0, sizeof(struct sockaddr_storage));
  884. read(fdret_sock, &addrbuf, sizeof(struct sockaddr_storage));
  885. struct sockaddr_storage sock_storage;
  886. memcpy(&sock_storage, addrbuf, sizeof(struct sockaddr_storage));
  887. *addrlen = sizeof(struct sockaddr_in);
  888. memcpy(addr, &sock_storage, (*addrlen > sizeof(sock_storage)) ? sizeof(sock_storage) : *addrlen);
  889. addr->sa_family = AF_INET;
  890. return 0;
  891. }
  892. /*------------------------------------------------------------------------------
  893. ------------------------------------ syscall() ---------------------------------
  894. ------------------------------------------------------------------------------*/
  895. long syscall(SYSCALL_SIG){
  896. if(realsyscall == NULL){
  897. dwr(MSG_ERROR, "syscall(): SYMBOL NOT FOUND.\n");
  898. return -1;
  899. }
  900. //dwr(MSG_DEBUG_EXTRA,"syscall(%u, ...):\n", number);
  901. va_list ap;
  902. uintptr_t a,b,c,d,e,f;
  903. va_start(ap, number);
  904. a=va_arg(ap, uintptr_t);
  905. b=va_arg(ap, uintptr_t);
  906. c=va_arg(ap, uintptr_t);
  907. d=va_arg(ap, uintptr_t);
  908. e=va_arg(ap, uintptr_t);
  909. f=va_arg(ap, uintptr_t);
  910. va_end(ap);
  911. #if defined(__i386__)
  912. /* TODO: Implement for 32-bit systems: syscall(__NR_socketcall, 18, args);
  913. args[0] = (unsigned long) fd;
  914. args[1] = (unsigned long) addr;
  915. args[2] = (unsigned long) addrlen;
  916. args[3] = (unsigned long) flags;
  917. */
  918. #else
  919. if(number == __NR_accept4) {
  920. int sockfd = a;
  921. struct sockaddr * addr = (struct sockaddr*)b;
  922. socklen_t * addrlen = (socklen_t*)c;
  923. int flags = d;
  924. int old_errno = errno;
  925. int err = accept4(sockfd, addr, addrlen, flags);
  926. errno = old_errno;
  927. if(err == -EBADF)
  928. err = -EAGAIN;
  929. return err;
  930. }
  931. #endif
  932. return realsyscall(number,a,b,c,d,e,f);
  933. }