portfwd.c 33 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069
  1. /*
  2. * SSH port forwarding.
  3. */
  4. #include <assert.h>
  5. #include <stdio.h>
  6. #include <stdlib.h>
  7. #include "putty.h"
  8. #include "ssh.h"
  9. #include "sshchan.h"
  10. static void logeventf(Frontend *frontend, const char *fmt, ...)
  11. {
  12. va_list ap;
  13. char *buf;
  14. va_start(ap, fmt);
  15. buf = dupvprintf(fmt, ap);
  16. va_end(ap);
  17. logevent(frontend, buf);
  18. sfree(buf);
  19. }
  20. /*
  21. * Enumeration of values that live in the 'socks_state' field of
  22. * struct PortForwarding.
  23. */
  24. typedef enum {
  25. SOCKS_NONE, /* direct connection (no SOCKS, or SOCKS already done) */
  26. SOCKS_INITIAL, /* don't know if we're SOCKS 4 or 5 yet */
  27. SOCKS_4, /* expect a SOCKS 4 (or 4A) connection message */
  28. SOCKS_5_INITIAL, /* expect a SOCKS 5 preliminary message */
  29. SOCKS_5_CONNECT /* expect a SOCKS 5 connection message */
  30. } SocksState;
  31. typedef struct PortForwarding {
  32. SshChannel *c; /* channel structure held by SSH connection layer */
  33. ConnectionLayer *cl; /* the connection layer itself */
  34. /* Note that ssh need not be filled in if c is non-NULL */
  35. Socket *s;
  36. int input_wanted;
  37. int ready;
  38. SocksState socks_state;
  39. /*
  40. * `hostname' and `port' are the real hostname and port, once
  41. * we know what we're connecting to.
  42. */
  43. char *hostname;
  44. int port;
  45. /*
  46. * `socksbuf' is the buffer we use to accumulate the initial SOCKS
  47. * segment of the incoming data, plus anything after that that we
  48. * receive before we're ready to send data to the SSH server.
  49. */
  50. strbuf *socksbuf;
  51. size_t socksbuf_consumed;
  52. Plug plug;
  53. Channel chan;
  54. } PortForwarding;
  55. struct PortListener {
  56. ConnectionLayer *cl;
  57. Socket *s;
  58. int is_dynamic;
  59. /*
  60. * `hostname' and `port' are the real hostname and port, for
  61. * ordinary forwardings.
  62. */
  63. char *hostname;
  64. int port;
  65. Plug plug;
  66. };
  67. static struct PortForwarding *new_portfwd_state(void)
  68. {
  69. struct PortForwarding *pf = snew(struct PortForwarding);
  70. pf->hostname = NULL;
  71. pf->socksbuf = NULL;
  72. return pf;
  73. }
  74. static void free_portfwd_state(struct PortForwarding *pf)
  75. {
  76. if (!pf)
  77. return;
  78. sfree(pf->hostname);
  79. if (pf->socksbuf)
  80. strbuf_free(pf->socksbuf);
  81. sfree(pf);
  82. }
  83. static struct PortListener *new_portlistener_state(void)
  84. {
  85. struct PortListener *pl = snew(struct PortListener);
  86. pl->hostname = NULL;
  87. return pl;
  88. }
  89. static void free_portlistener_state(struct PortListener *pl)
  90. {
  91. if (!pl)
  92. return;
  93. sfree(pl->hostname);
  94. sfree(pl);
  95. }
  96. static void pfd_log(Plug *plug, int type, SockAddr *addr, int port,
  97. const char *error_msg, int error_code)
  98. {
  99. /* we have to dump these since we have no interface to logging.c */
  100. }
  101. static void pfl_log(Plug *plug, int type, SockAddr *addr, int port,
  102. const char *error_msg, int error_code)
  103. {
  104. /* we have to dump these since we have no interface to logging.c */
  105. }
  106. static void pfd_close(struct PortForwarding *pf);
  107. static void pfd_closing(Plug *plug, const char *error_msg, int error_code,
  108. int calling_back)
  109. {
  110. struct PortForwarding *pf =
  111. container_of(plug, struct PortForwarding, plug);
  112. if (error_msg) {
  113. /*
  114. * Socket error. Slam the connection instantly shut.
  115. */
  116. if (pf->c) {
  117. sshfwd_unclean_close(pf->c, error_msg);
  118. } else {
  119. /*
  120. * We might not have an SSH channel, if a socket error
  121. * occurred during SOCKS negotiation. If not, we must
  122. * clean ourself up without sshfwd_unclean_close's call
  123. * back to pfd_close.
  124. */
  125. pfd_close(pf);
  126. }
  127. } else {
  128. /*
  129. * Ordinary EOF received on socket. Send an EOF on the SSH
  130. * channel.
  131. */
  132. if (pf->c)
  133. sshfwd_write_eof(pf->c);
  134. }
  135. }
  136. static void pfl_terminate(struct PortListener *pl);
  137. static void pfl_closing(Plug *plug, const char *error_msg, int error_code,
  138. int calling_back)
  139. {
  140. struct PortListener *pl = (struct PortListener *) plug;
  141. pfl_terminate(pl);
  142. }
  143. static SshChannel *wrap_lportfwd_open(
  144. ConnectionLayer *cl, const char *hostname, int port,
  145. Socket *s, Channel *chan)
  146. {
  147. char *peerinfo, *description;
  148. SshChannel *toret;
  149. peerinfo = sk_peer_info(s);
  150. if (peerinfo) {
  151. description = dupprintf("forwarding from %s", peerinfo);
  152. sfree(peerinfo);
  153. } else {
  154. description = dupstr("forwarding");
  155. }
  156. toret = ssh_lportfwd_open(cl, hostname, port, description, chan);
  157. sfree(description);
  158. return toret;
  159. }
  160. static char *ipv4_to_string(unsigned ipv4)
  161. {
  162. return dupprintf("%u.%u.%u.%u",
  163. (ipv4 >> 24) & 0xFF, (ipv4 >> 16) & 0xFF,
  164. (ipv4 >> 8) & 0xFF, (ipv4 ) & 0xFF);
  165. }
  166. static char *ipv6_to_string(ptrlen ipv6)
  167. {
  168. const unsigned char *addr = ipv6.ptr;
  169. assert(ipv6.len == 16);
  170. return dupprintf("%04x:%04x:%04x:%04x:%04x:%04x:%04x:%04x",
  171. (unsigned)GET_16BIT_MSB_FIRST(addr + 0),
  172. (unsigned)GET_16BIT_MSB_FIRST(addr + 2),
  173. (unsigned)GET_16BIT_MSB_FIRST(addr + 4),
  174. (unsigned)GET_16BIT_MSB_FIRST(addr + 6),
  175. (unsigned)GET_16BIT_MSB_FIRST(addr + 8),
  176. (unsigned)GET_16BIT_MSB_FIRST(addr + 10),
  177. (unsigned)GET_16BIT_MSB_FIRST(addr + 12),
  178. (unsigned)GET_16BIT_MSB_FIRST(addr + 14));
  179. }
  180. static void pfd_receive(Plug *plug, int urgent, char *data, int len)
  181. {
  182. struct PortForwarding *pf =
  183. container_of(plug, struct PortForwarding, plug);
  184. if (len == 0)
  185. return;
  186. if (pf->socks_state != SOCKS_NONE) {
  187. BinarySource src[1];
  188. /*
  189. * Store all the data we've got in socksbuf.
  190. */
  191. put_data(pf->socksbuf, data, len);
  192. /*
  193. * Check the start of socksbuf to see if it's a valid and
  194. * complete message in the SOCKS exchange.
  195. */
  196. if (pf->socks_state == SOCKS_INITIAL) {
  197. /* Preliminary: check the first byte of the data (which we
  198. * _must_ have by now) to find out which SOCKS major
  199. * version we're speaking. */
  200. switch (pf->socksbuf->u[0]) {
  201. case 4:
  202. pf->socks_state = SOCKS_4;
  203. break;
  204. case 5:
  205. pf->socks_state = SOCKS_5_INITIAL;
  206. break;
  207. default:
  208. pfd_close(pf); /* unrecognised version */
  209. return;
  210. }
  211. }
  212. BinarySource_BARE_INIT(src, pf->socksbuf->u, pf->socksbuf->len);
  213. get_data(src, pf->socksbuf_consumed);
  214. while (pf->socks_state != SOCKS_NONE) {
  215. unsigned socks_version, message_type, reserved_byte;
  216. unsigned reply_code, port, ipv4, method;
  217. ptrlen methods;
  218. const char *socks4_hostname;
  219. strbuf *output;
  220. switch (pf->socks_state) {
  221. case SOCKS_INITIAL:
  222. case SOCKS_NONE:
  223. assert(0 && "These case values cannot appear");
  224. case SOCKS_4:
  225. /* SOCKS 4/4A connect message */
  226. socks_version = get_byte(src);
  227. message_type = get_byte(src);
  228. if (get_err(src) == BSE_OUT_OF_DATA)
  229. return;
  230. if (socks_version == 4 && message_type == 1) {
  231. /* CONNECT message */
  232. int name_based = FALSE;
  233. port = get_uint16(src);
  234. ipv4 = get_uint32(src);
  235. if (ipv4 > 0x00000000 && ipv4 < 0x00000100) {
  236. /*
  237. * Addresses in this range indicate the SOCKS 4A
  238. * extension to specify a hostname, which comes
  239. * after the username.
  240. */
  241. name_based = TRUE;
  242. }
  243. get_asciz(src); /* skip username */
  244. socks4_hostname = name_based ? get_asciz(src) : NULL;
  245. if (get_err(src) == BSE_OUT_OF_DATA)
  246. return;
  247. if (get_err(src))
  248. goto socks4_reject;
  249. pf->port = port;
  250. if (name_based) {
  251. pf->hostname = dupstr(socks4_hostname);
  252. } else {
  253. pf->hostname = ipv4_to_string(ipv4);
  254. }
  255. output = strbuf_new();
  256. put_byte(output, 0); /* reply version */
  257. put_byte(output, 90); /* SOCKS 4 'request granted' */
  258. put_uint16(output, 0); /* null port field */
  259. put_uint32(output, 0); /* null address field */
  260. sk_write(pf->s, output->u, output->len);
  261. strbuf_free(output);
  262. pf->socks_state = SOCKS_NONE;
  263. pf->socksbuf_consumed = src->pos;
  264. break;
  265. }
  266. socks4_reject:
  267. output = strbuf_new();
  268. put_byte(output, 0); /* reply version */
  269. put_byte(output, 91); /* SOCKS 4 'request rejected' */
  270. put_uint16(output, 0); /* null port field */
  271. put_uint32(output, 0); /* null address field */
  272. sk_write(pf->s, output->u, output->len);
  273. strbuf_free(output);
  274. pfd_close(pf);
  275. return;
  276. case SOCKS_5_INITIAL:
  277. /* SOCKS 5 initial method list */
  278. socks_version = get_byte(src);
  279. methods = get_pstring(src);
  280. method = 0xFF; /* means 'no usable method found' */
  281. {
  282. int i;
  283. for (i = 0; i < methods.len; i++) {
  284. if (((const unsigned char *)methods.ptr)[i] == 0 ) {
  285. method = 0; /* no auth */
  286. break;
  287. }
  288. }
  289. }
  290. if (get_err(src) == BSE_OUT_OF_DATA)
  291. return;
  292. if (get_err(src))
  293. method = 0xFF;
  294. output = strbuf_new();
  295. put_byte(output, 5); /* SOCKS version */
  296. put_byte(output, method); /* selected auth method */
  297. sk_write(pf->s, output->u, output->len);
  298. strbuf_free(output);
  299. if (method == 0xFF) {
  300. pfd_close(pf);
  301. return;
  302. }
  303. pf->socks_state = SOCKS_5_CONNECT;
  304. pf->socksbuf_consumed = src->pos;
  305. break;
  306. case SOCKS_5_CONNECT:
  307. /* SOCKS 5 connect message */
  308. socks_version = get_byte(src);
  309. message_type = get_byte(src);
  310. reserved_byte = get_byte(src);
  311. if (socks_version == 5 && message_type == 1 &&
  312. reserved_byte == 0) {
  313. reply_code = 0; /* success */
  314. switch (get_byte(src)) {
  315. case 1: /* IPv4 */
  316. pf->hostname = ipv4_to_string(get_uint32(src));
  317. break;
  318. case 4: /* IPv6 */
  319. pf->hostname = ipv6_to_string(get_data(src, 16));
  320. break;
  321. case 3: /* unresolved domain name */
  322. pf->hostname = mkstr(get_pstring(src));
  323. break;
  324. default:
  325. pf->hostname = NULL;
  326. reply_code = 8; /* address type not supported */
  327. break;
  328. }
  329. pf->port = get_uint16(src);
  330. } else {
  331. reply_code = 7; /* command not supported */
  332. }
  333. if (get_err(src) == BSE_OUT_OF_DATA)
  334. return;
  335. if (get_err(src))
  336. reply_code = 1; /* general server failure */
  337. output = strbuf_new();
  338. put_byte(output, 5); /* SOCKS version */
  339. put_byte(output, reply_code);
  340. put_byte(output, 0); /* reserved */
  341. put_byte(output, 1); /* IPv4 address follows */
  342. put_uint32(output, 0); /* bound IPv4 address (unused) */
  343. put_uint16(output, 0); /* bound port number (unused) */
  344. sk_write(pf->s, output->u, output->len);
  345. strbuf_free(output);
  346. if (reply_code != 0) {
  347. pfd_close(pf);
  348. return;
  349. }
  350. pf->socks_state = SOCKS_NONE;
  351. pf->socksbuf_consumed = src->pos;
  352. break;
  353. }
  354. }
  355. /*
  356. * We come here when we're ready to make an actual
  357. * connection.
  358. */
  359. /*
  360. * Freeze the socket until the SSH server confirms the
  361. * connection.
  362. */
  363. sk_set_frozen(pf->s, 1);
  364. pf->c = wrap_lportfwd_open(pf->cl, pf->hostname, pf->port, pf->s,
  365. &pf->chan);
  366. }
  367. if (pf->ready)
  368. sshfwd_write(pf->c, data, len);
  369. }
  370. static void pfd_sent(Plug *plug, int bufsize)
  371. {
  372. struct PortForwarding *pf =
  373. container_of(plug, struct PortForwarding, plug);
  374. if (pf->c)
  375. sshfwd_unthrottle(pf->c, bufsize);
  376. }
  377. static const PlugVtable PortForwarding_plugvt = {
  378. pfd_log,
  379. pfd_closing,
  380. pfd_receive,
  381. pfd_sent,
  382. NULL
  383. };
  384. static void pfd_chan_free(Channel *chan);
  385. static void pfd_open_confirmation(Channel *chan);
  386. static void pfd_open_failure(Channel *chan, const char *errtext);
  387. static int pfd_send(Channel *chan, int is_stderr, const void *data, int len);
  388. static void pfd_send_eof(Channel *chan);
  389. static void pfd_set_input_wanted(Channel *chan, int wanted);
  390. static char *pfd_log_close_msg(Channel *chan);
  391. static const struct ChannelVtable PortForwarding_channelvt = {
  392. pfd_chan_free,
  393. pfd_open_confirmation,
  394. pfd_open_failure,
  395. pfd_send,
  396. pfd_send_eof,
  397. pfd_set_input_wanted,
  398. pfd_log_close_msg,
  399. chan_no_eager_close,
  400. };
  401. /*
  402. called when someone connects to the local port
  403. */
  404. static int pfl_accepting(Plug *p, accept_fn_t constructor, accept_ctx_t ctx)
  405. {
  406. struct PortForwarding *pf;
  407. struct PortListener *pl;
  408. Socket *s;
  409. const char *err;
  410. pl = container_of(p, struct PortListener, plug);
  411. pf = new_portfwd_state();
  412. pf->plug.vt = &PortForwarding_plugvt;
  413. pf->chan.initial_fixed_window_size = 0;
  414. pf->chan.vt = &PortForwarding_channelvt;
  415. pf->input_wanted = TRUE;
  416. pf->c = NULL;
  417. pf->cl = pl->cl;
  418. pf->s = s = constructor(ctx, &pf->plug);
  419. if ((err = sk_socket_error(s)) != NULL) {
  420. free_portfwd_state(pf);
  421. return err != NULL;
  422. }
  423. pf->input_wanted = TRUE;
  424. pf->ready = 0;
  425. if (pl->is_dynamic) {
  426. pf->socks_state = SOCKS_INITIAL;
  427. pf->socksbuf = strbuf_new();
  428. pf->socksbuf_consumed = 0;
  429. pf->port = 0; /* "hostname" buffer is so far empty */
  430. sk_set_frozen(s, 0); /* we want to receive SOCKS _now_! */
  431. } else {
  432. pf->socks_state = SOCKS_NONE;
  433. pf->hostname = dupstr(pl->hostname);
  434. pf->port = pl->port;
  435. pf->c = wrap_lportfwd_open(pl->cl, pf->hostname, pf->port,
  436. s, &pf->chan);
  437. }
  438. return 0;
  439. }
  440. static const PlugVtable PortListener_plugvt = {
  441. pfl_log,
  442. pfl_closing,
  443. NULL, /* recv */
  444. NULL, /* send */
  445. pfl_accepting
  446. };
  447. /*
  448. * Add a new port-forwarding listener from srcaddr:port -> desthost:destport.
  449. *
  450. * desthost == NULL indicates dynamic SOCKS port forwarding.
  451. *
  452. * On success, returns NULL and fills in *pl_ret. On error, returns a
  453. * dynamically allocated error message string.
  454. */
  455. static char *pfl_listen(char *desthost, int destport, char *srcaddr,
  456. int port, ConnectionLayer *cl, Conf *conf,
  457. struct PortListener **pl_ret, int address_family)
  458. {
  459. const char *err;
  460. struct PortListener *pl;
  461. /*
  462. * Open socket.
  463. */
  464. pl = *pl_ret = new_portlistener_state();
  465. pl->plug.vt = &PortListener_plugvt;
  466. if (desthost) {
  467. pl->hostname = dupstr(desthost);
  468. pl->port = destport;
  469. pl->is_dynamic = FALSE;
  470. } else
  471. pl->is_dynamic = TRUE;
  472. pl->cl = cl;
  473. pl->s = new_listener(srcaddr, port, &pl->plug,
  474. !conf_get_int(conf, CONF_lport_acceptall),
  475. conf, address_family);
  476. if ((err = sk_socket_error(pl->s)) != NULL) {
  477. char *err_ret = dupstr(err);
  478. sk_close(pl->s);
  479. free_portlistener_state(pl);
  480. *pl_ret = NULL;
  481. return err_ret;
  482. }
  483. return NULL;
  484. }
  485. static char *pfd_log_close_msg(Channel *chan)
  486. {
  487. return dupstr("Forwarded port closed");
  488. }
  489. static void pfd_close(struct PortForwarding *pf)
  490. {
  491. if (!pf)
  492. return;
  493. sk_close(pf->s);
  494. free_portfwd_state(pf);
  495. }
  496. /*
  497. * Terminate a listener.
  498. */
  499. static void pfl_terminate(struct PortListener *pl)
  500. {
  501. if (!pl)
  502. return;
  503. sk_close(pl->s);
  504. free_portlistener_state(pl);
  505. }
  506. static void pfd_set_input_wanted(Channel *chan, int wanted)
  507. {
  508. assert(chan->vt == &PortForwarding_channelvt);
  509. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  510. pf->input_wanted = wanted;
  511. sk_set_frozen(pf->s, !pf->input_wanted);
  512. }
  513. static void pfd_chan_free(Channel *chan)
  514. {
  515. assert(chan->vt == &PortForwarding_channelvt);
  516. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  517. pfd_close(pf);
  518. }
  519. /*
  520. * Called to send data down the raw connection.
  521. */
  522. static int pfd_send(Channel *chan, int is_stderr, const void *data, int len)
  523. {
  524. assert(chan->vt == &PortForwarding_channelvt);
  525. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  526. return sk_write(pf->s, data, len);
  527. }
  528. static void pfd_send_eof(Channel *chan)
  529. {
  530. assert(chan->vt == &PortForwarding_channelvt);
  531. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  532. sk_write_eof(pf->s);
  533. }
  534. static void pfd_open_confirmation(Channel *chan)
  535. {
  536. assert(chan->vt == &PortForwarding_channelvt);
  537. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  538. pf->ready = 1;
  539. sk_set_frozen(pf->s, 0);
  540. sk_write(pf->s, NULL, 0);
  541. if (pf->socksbuf) {
  542. sshfwd_write(pf->c, pf->socksbuf->u + pf->socksbuf_consumed,
  543. pf->socksbuf->len - pf->socksbuf_consumed);
  544. strbuf_free(pf->socksbuf);
  545. pf->socksbuf = NULL;
  546. }
  547. }
  548. static void pfd_open_failure(Channel *chan, const char *errtext)
  549. {
  550. assert(chan->vt == &PortForwarding_channelvt);
  551. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  552. logeventf(pf->cl->frontend,
  553. "Forwarded connection refused by server%s%s",
  554. errtext ? ": " : "", errtext ? errtext : "");
  555. }
  556. /* ----------------------------------------------------------------------
  557. * Code to manage the complete set of currently active port
  558. * forwardings, and update it from Conf.
  559. */
  560. struct PortFwdRecord {
  561. enum { DESTROY, KEEP, CREATE } status;
  562. int type;
  563. unsigned sport, dport;
  564. char *saddr, *daddr;
  565. char *sserv, *dserv;
  566. struct ssh_rportfwd *remote;
  567. int addressfamily;
  568. struct PortListener *local;
  569. };
  570. static int pfr_cmp(void *av, void *bv)
  571. {
  572. PortFwdRecord *a = (PortFwdRecord *) av;
  573. PortFwdRecord *b = (PortFwdRecord *) bv;
  574. int i;
  575. if (a->type > b->type)
  576. return +1;
  577. if (a->type < b->type)
  578. return -1;
  579. if (a->addressfamily > b->addressfamily)
  580. return +1;
  581. if (a->addressfamily < b->addressfamily)
  582. return -1;
  583. if ( (i = nullstrcmp(a->saddr, b->saddr)) != 0)
  584. return i < 0 ? -1 : +1;
  585. if (a->sport > b->sport)
  586. return +1;
  587. if (a->sport < b->sport)
  588. return -1;
  589. if (a->type != 'D') {
  590. if ( (i = nullstrcmp(a->daddr, b->daddr)) != 0)
  591. return i < 0 ? -1 : +1;
  592. if (a->dport > b->dport)
  593. return +1;
  594. if (a->dport < b->dport)
  595. return -1;
  596. }
  597. return 0;
  598. }
  599. void pfr_free(PortFwdRecord *pfr)
  600. {
  601. /* Dispose of any listening socket. */
  602. if (pfr->local)
  603. pfl_terminate(pfr->local);
  604. sfree(pfr->saddr);
  605. sfree(pfr->daddr);
  606. sfree(pfr->sserv);
  607. sfree(pfr->dserv);
  608. sfree(pfr);
  609. }
  610. struct PortFwdManager {
  611. ConnectionLayer *cl;
  612. Conf *conf;
  613. tree234 *forwardings;
  614. };
  615. PortFwdManager *portfwdmgr_new(ConnectionLayer *cl)
  616. {
  617. PortFwdManager *mgr = snew(PortFwdManager);
  618. mgr->cl = cl;
  619. mgr->conf = NULL;
  620. mgr->forwardings = newtree234(pfr_cmp);
  621. return mgr;
  622. }
  623. void portfwdmgr_close(PortFwdManager *mgr, PortFwdRecord *pfr)
  624. {
  625. PortFwdRecord *realpfr = del234(mgr->forwardings, pfr);
  626. if (realpfr == pfr)
  627. pfr_free(pfr);
  628. }
  629. void portfwdmgr_close_all(PortFwdManager *mgr)
  630. {
  631. PortFwdRecord *pfr;
  632. while ((pfr = delpos234(mgr->forwardings, 0)) != NULL)
  633. pfr_free(pfr);
  634. }
  635. void portfwdmgr_free(PortFwdManager *mgr)
  636. {
  637. portfwdmgr_close_all(mgr);
  638. freetree234(mgr->forwardings);
  639. if (mgr->conf)
  640. conf_free(mgr->conf);
  641. sfree(mgr);
  642. }
  643. void portfwdmgr_config(PortFwdManager *mgr, Conf *conf)
  644. {
  645. PortFwdRecord *pfr;
  646. int i;
  647. char *key, *val;
  648. if (mgr->conf)
  649. conf_free(mgr->conf);
  650. mgr->conf = conf_copy(conf);
  651. /*
  652. * Go through the existing port forwardings and tag them
  653. * with status==DESTROY. Any that we want to keep will be
  654. * re-enabled (status==KEEP) as we go through the
  655. * configuration and find out which bits are the same as
  656. * they were before.
  657. */
  658. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++)
  659. pfr->status = DESTROY;
  660. for (val = conf_get_str_strs(conf, CONF_portfwd, NULL, &key);
  661. val != NULL;
  662. val = conf_get_str_strs(conf, CONF_portfwd, key, &key)) {
  663. char *kp, *kp2, *vp, *vp2;
  664. char address_family, type;
  665. int sport, dport, sserv, dserv;
  666. char *sports, *dports, *saddr, *host;
  667. kp = key;
  668. address_family = 'A';
  669. type = 'L';
  670. if (*kp == 'A' || *kp == '4' || *kp == '6')
  671. address_family = *kp++;
  672. if (*kp == 'L' || *kp == 'R')
  673. type = *kp++;
  674. if ((kp2 = host_strchr(kp, ':')) != NULL) {
  675. /*
  676. * There's a colon in the middle of the source port
  677. * string, which means that the part before it is
  678. * actually a source address.
  679. */
  680. char *saddr_tmp = dupprintf("%.*s", (int)(kp2 - kp), kp);
  681. saddr = host_strduptrim(saddr_tmp);
  682. sfree(saddr_tmp);
  683. sports = kp2+1;
  684. } else {
  685. saddr = NULL;
  686. sports = kp;
  687. }
  688. sport = atoi(sports);
  689. sserv = 0;
  690. if (sport == 0) {
  691. sserv = 1;
  692. sport = net_service_lookup(sports);
  693. if (!sport) {
  694. logeventf(mgr->cl->frontend, "Service lookup failed for source"
  695. " port \"%s\"", sports);
  696. }
  697. }
  698. if (type == 'L' && !strcmp(val, "D")) {
  699. /* dynamic forwarding */
  700. host = NULL;
  701. dports = NULL;
  702. dport = -1;
  703. dserv = 0;
  704. type = 'D';
  705. } else {
  706. /* ordinary forwarding */
  707. vp = val;
  708. vp2 = vp + host_strcspn(vp, ":");
  709. host = dupprintf("%.*s", (int)(vp2 - vp), vp);
  710. if (*vp2)
  711. vp2++;
  712. dports = vp2;
  713. dport = atoi(dports);
  714. dserv = 0;
  715. if (dport == 0) {
  716. dserv = 1;
  717. dport = net_service_lookup(dports);
  718. if (!dport) {
  719. logeventf(mgr->cl->frontend,
  720. "Service lookup failed for destination"
  721. " port \"%s\"", dports);
  722. }
  723. }
  724. }
  725. if (sport && dport) {
  726. /* Set up a description of the source port. */
  727. pfr = snew(PortFwdRecord);
  728. pfr->type = type;
  729. pfr->saddr = saddr;
  730. pfr->sserv = sserv ? dupstr(sports) : NULL;
  731. pfr->sport = sport;
  732. pfr->daddr = host;
  733. pfr->dserv = dserv ? dupstr(dports) : NULL;
  734. pfr->dport = dport;
  735. pfr->local = NULL;
  736. pfr->remote = NULL;
  737. pfr->addressfamily = (address_family == '4' ? ADDRTYPE_IPV4 :
  738. address_family == '6' ? ADDRTYPE_IPV6 :
  739. ADDRTYPE_UNSPEC);
  740. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  741. if (existing != pfr) {
  742. if (existing->status == DESTROY) {
  743. /*
  744. * We already have a port forwarding up and running
  745. * with precisely these parameters. Hence, no need
  746. * to do anything; simply re-tag the existing one
  747. * as KEEP.
  748. */
  749. existing->status = KEEP;
  750. }
  751. /*
  752. * Anything else indicates that there was a duplicate
  753. * in our input, which we'll silently ignore.
  754. */
  755. pfr_free(pfr);
  756. } else {
  757. pfr->status = CREATE;
  758. }
  759. } else {
  760. sfree(saddr);
  761. sfree(host);
  762. }
  763. }
  764. /*
  765. * Now go through and destroy any port forwardings which were
  766. * not re-enabled.
  767. */
  768. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  769. if (pfr->status == DESTROY) {
  770. char *message;
  771. message = dupprintf("%s port forwarding from %s%s%d",
  772. pfr->type == 'L' ? "local" :
  773. pfr->type == 'R' ? "remote" : "dynamic",
  774. pfr->saddr ? pfr->saddr : "",
  775. pfr->saddr ? ":" : "",
  776. pfr->sport);
  777. if (pfr->type != 'D') {
  778. char *msg2 = dupprintf("%s to %s:%d", message,
  779. pfr->daddr, pfr->dport);
  780. sfree(message);
  781. message = msg2;
  782. }
  783. logeventf(mgr->cl->frontend, "Cancelling %s", message);
  784. sfree(message);
  785. /* pfr->remote or pfr->local may be NULL if setting up a
  786. * forwarding failed. */
  787. if (pfr->remote) {
  788. /*
  789. * Cancel the port forwarding at the server
  790. * end.
  791. *
  792. * Actually closing the listening port on the server
  793. * side may fail - because in SSH-1 there's no message
  794. * in the protocol to request it!
  795. *
  796. * Instead, we simply remove the record of the
  797. * forwarding from our local end, so that any
  798. * connections the server tries to make on it are
  799. * rejected.
  800. */
  801. ssh_rportfwd_remove(mgr->cl, pfr->remote);
  802. } else if (pfr->local) {
  803. pfl_terminate(pfr->local);
  804. }
  805. delpos234(mgr->forwardings, i);
  806. pfr_free(pfr);
  807. i--; /* so we don't skip one in the list */
  808. }
  809. }
  810. /*
  811. * And finally, set up any new port forwardings (status==CREATE).
  812. */
  813. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  814. if (pfr->status == CREATE) {
  815. char *sportdesc, *dportdesc;
  816. sportdesc = dupprintf("%s%s%s%s%d%s",
  817. pfr->saddr ? pfr->saddr : "",
  818. pfr->saddr ? ":" : "",
  819. pfr->sserv ? pfr->sserv : "",
  820. pfr->sserv ? "(" : "",
  821. pfr->sport,
  822. pfr->sserv ? ")" : "");
  823. if (pfr->type == 'D') {
  824. dportdesc = NULL;
  825. } else {
  826. dportdesc = dupprintf("%s:%s%s%d%s",
  827. pfr->daddr,
  828. pfr->dserv ? pfr->dserv : "",
  829. pfr->dserv ? "(" : "",
  830. pfr->dport,
  831. pfr->dserv ? ")" : "");
  832. }
  833. if (pfr->type == 'L') {
  834. char *err = pfl_listen(pfr->daddr, pfr->dport,
  835. pfr->saddr, pfr->sport,
  836. mgr->cl, conf, &pfr->local,
  837. pfr->addressfamily);
  838. logeventf(mgr->cl->frontend,
  839. "Local %sport %s forwarding to %s%s%s",
  840. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  841. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  842. sportdesc, dportdesc,
  843. err ? " failed: " : "", err ? err : "");
  844. if (err)
  845. sfree(err);
  846. } else if (pfr->type == 'D') {
  847. char *err = pfl_listen(NULL, -1, pfr->saddr, pfr->sport,
  848. mgr->cl, conf, &pfr->local,
  849. pfr->addressfamily);
  850. logeventf(mgr->cl->frontend,
  851. "Local %sport %s SOCKS dynamic forwarding%s%s",
  852. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  853. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  854. sportdesc,
  855. err ? " failed: " : "", err ? err : "");
  856. if (err)
  857. sfree(err);
  858. } else {
  859. const char *shost;
  860. if (pfr->saddr) {
  861. shost = pfr->saddr;
  862. } else if (conf_get_int(conf, CONF_rport_acceptall)) {
  863. shost = "";
  864. } else {
  865. shost = "localhost";
  866. }
  867. pfr->remote = ssh_rportfwd_alloc(
  868. mgr->cl, shost, pfr->sport, pfr->daddr, pfr->dport,
  869. pfr->addressfamily, sportdesc, pfr, NULL);
  870. if (!pfr->remote) {
  871. logeventf(mgr->cl->frontend,
  872. "Duplicate remote port forwarding to %s:%d",
  873. pfr->daddr, pfr->dport);
  874. pfr_free(pfr);
  875. } else {
  876. logeventf(mgr->cl->frontend, "Requesting remote port %s"
  877. " forward to %s", sportdesc, dportdesc);
  878. }
  879. }
  880. sfree(sportdesc);
  881. sfree(dportdesc);
  882. }
  883. }
  884. }
  885. /*
  886. * Called when receiving a PORT OPEN from the server to make a
  887. * connection to a destination host.
  888. *
  889. * On success, returns NULL and fills in *pf_ret. On error, returns a
  890. * dynamically allocated error message string.
  891. */
  892. char *portfwdmgr_connect(PortFwdManager *mgr, Channel **chan_ret,
  893. char *hostname, int port, SshChannel *c,
  894. int addressfamily)
  895. {
  896. SockAddr *addr;
  897. const char *err;
  898. char *dummy_realhost = NULL;
  899. struct PortForwarding *pf;
  900. /*
  901. * Try to find host.
  902. */
  903. addr = name_lookup(hostname, port, &dummy_realhost, mgr->conf,
  904. addressfamily, NULL, NULL);
  905. if ((err = sk_addr_error(addr)) != NULL) {
  906. char *err_ret = dupstr(err);
  907. sk_addr_free(addr);
  908. sfree(dummy_realhost);
  909. return err_ret;
  910. }
  911. /*
  912. * Open socket.
  913. */
  914. pf = new_portfwd_state();
  915. *chan_ret = &pf->chan;
  916. pf->plug.vt = &PortForwarding_plugvt;
  917. pf->chan.initial_fixed_window_size = 0;
  918. pf->chan.vt = &PortForwarding_channelvt;
  919. pf->input_wanted = TRUE;
  920. pf->ready = 1;
  921. pf->c = c;
  922. pf->cl = mgr->cl;
  923. pf->socks_state = SOCKS_NONE;
  924. pf->s = new_connection(addr, dummy_realhost, port,
  925. 0, 1, 0, 0, &pf->plug, mgr->conf);
  926. sfree(dummy_realhost);
  927. if ((err = sk_socket_error(pf->s)) != NULL) {
  928. char *err_ret = dupstr(err);
  929. sk_close(pf->s);
  930. free_portfwd_state(pf);
  931. *chan_ret = NULL;
  932. return err_ret;
  933. }
  934. return NULL;
  935. }