portfwd.c 34 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097
  1. /*
  2. * SSH port forwarding.
  3. */
  4. #include <assert.h>
  5. #include <stdio.h>
  6. #include <stdlib.h>
  7. #include "putty.h"
  8. #include "ssh.h"
  9. #include "sshchan.h"
  10. static void logeventf(Frontend *frontend, const char *fmt, ...)
  11. {
  12. va_list ap;
  13. char *buf;
  14. va_start(ap, fmt);
  15. buf = dupvprintf(fmt, ap);
  16. va_end(ap);
  17. logevent(frontend, buf);
  18. sfree(buf);
  19. }
  20. /*
  21. * Enumeration of values that live in the 'socks_state' field of
  22. * struct PortForwarding.
  23. */
  24. typedef enum {
  25. SOCKS_NONE, /* direct connection (no SOCKS, or SOCKS already done) */
  26. SOCKS_INITIAL, /* don't know if we're SOCKS 4 or 5 yet */
  27. SOCKS_4, /* expect a SOCKS 4 (or 4A) connection message */
  28. SOCKS_5_INITIAL, /* expect a SOCKS 5 preliminary message */
  29. SOCKS_5_CONNECT /* expect a SOCKS 5 connection message */
  30. } SocksState;
  31. typedef struct PortForwarding {
  32. SshChannel *c; /* channel structure held by SSH connection layer */
  33. ConnectionLayer *cl; /* the connection layer itself */
  34. /* Note that ssh need not be filled in if c is non-NULL */
  35. Socket *s;
  36. int input_wanted;
  37. int ready;
  38. SocksState socks_state;
  39. /*
  40. * `hostname' and `port' are the real hostname and port, once
  41. * we know what we're connecting to.
  42. */
  43. char *hostname;
  44. int port;
  45. /*
  46. * `socksbuf' is the buffer we use to accumulate the initial SOCKS
  47. * segment of the incoming data, plus anything after that that we
  48. * receive before we're ready to send data to the SSH server.
  49. */
  50. strbuf *socksbuf;
  51. size_t socksbuf_consumed;
  52. const Plug_vtable *plugvt;
  53. Channel chan;
  54. } PortForwarding;
  55. struct PortListener {
  56. ConnectionLayer *cl;
  57. Socket *s;
  58. int is_dynamic;
  59. /*
  60. * `hostname' and `port' are the real hostname and port, for
  61. * ordinary forwardings.
  62. */
  63. char *hostname;
  64. int port;
  65. const Plug_vtable *plugvt;
  66. };
  67. static struct PortForwarding *new_portfwd_state(void)
  68. {
  69. struct PortForwarding *pf = snew(struct PortForwarding);
  70. pf->hostname = NULL;
  71. pf->socksbuf = NULL;
  72. return pf;
  73. }
  74. static void free_portfwd_state(struct PortForwarding *pf)
  75. {
  76. if (!pf)
  77. return;
  78. sfree(pf->hostname);
  79. if (pf->socksbuf)
  80. strbuf_free(pf->socksbuf);
  81. sfree(pf);
  82. }
  83. static struct PortListener *new_portlistener_state(void)
  84. {
  85. struct PortListener *pl = snew(struct PortListener);
  86. pl->hostname = NULL;
  87. return pl;
  88. }
  89. static void free_portlistener_state(struct PortListener *pl)
  90. {
  91. if (!pl)
  92. return;
  93. sfree(pl->hostname);
  94. sfree(pl);
  95. }
  96. static void pfd_log(Plug *plug, int type, SockAddr *addr, int port,
  97. const char *error_msg, int error_code)
  98. {
  99. /* we have to dump these since we have no interface to logging.c */
  100. }
  101. static void pfl_log(Plug *plug, int type, SockAddr *addr, int port,
  102. const char *error_msg, int error_code)
  103. {
  104. /* we have to dump these since we have no interface to logging.c */
  105. }
  106. static void pfd_close(struct PortForwarding *pf);
  107. static void pfd_closing(Plug *plug, const char *error_msg, int error_code,
  108. int calling_back)
  109. {
  110. struct PortForwarding *pf = FROMFIELD(plug, struct PortForwarding, plugvt);
  111. if (error_msg) {
  112. /*
  113. * Socket error. Slam the connection instantly shut.
  114. */
  115. if (pf->c) {
  116. sshfwd_unclean_close(pf->c, error_msg);
  117. } else {
  118. /*
  119. * We might not have an SSH channel, if a socket error
  120. * occurred during SOCKS negotiation. If not, we must
  121. * clean ourself up without sshfwd_unclean_close's call
  122. * back to pfd_close.
  123. */
  124. pfd_close(pf);
  125. }
  126. } else {
  127. /*
  128. * Ordinary EOF received on socket. Send an EOF on the SSH
  129. * channel.
  130. */
  131. if (pf->c)
  132. sshfwd_write_eof(pf->c);
  133. }
  134. }
  135. static void pfl_terminate(struct PortListener *pl);
  136. static void pfl_closing(Plug *plug, const char *error_msg, int error_code,
  137. int calling_back)
  138. {
  139. struct PortListener *pl = (struct PortListener *) plug;
  140. pfl_terminate(pl);
  141. }
  142. static SshChannel *wrap_lportfwd_open(
  143. ConnectionLayer *cl, const char *hostname, int port,
  144. Socket *s, Channel *chan)
  145. {
  146. char *peerinfo, *description;
  147. SshChannel *toret;
  148. peerinfo = sk_peer_info(s);
  149. if (peerinfo) {
  150. description = dupprintf("forwarding from %s", peerinfo);
  151. sfree(peerinfo);
  152. } else {
  153. description = dupstr("forwarding");
  154. }
  155. toret = ssh_lportfwd_open(cl, hostname, port, description, chan);
  156. sfree(description);
  157. return toret;
  158. }
  159. static char *ipv4_to_string(unsigned ipv4)
  160. {
  161. return dupprintf("%u.%u.%u.%u",
  162. (ipv4 >> 24) & 0xFF, (ipv4 >> 16) & 0xFF,
  163. (ipv4 >> 8) & 0xFF, (ipv4 ) & 0xFF);
  164. }
  165. static char *ipv6_to_string(ptrlen ipv6)
  166. {
  167. const unsigned char *addr = ipv6.ptr;
  168. assert(ipv6.len == 16);
  169. return dupprintf("%04x:%04x:%04x:%04x:%04x:%04x:%04x:%04x",
  170. (unsigned)GET_16BIT_MSB_FIRST(addr + 0),
  171. (unsigned)GET_16BIT_MSB_FIRST(addr + 2),
  172. (unsigned)GET_16BIT_MSB_FIRST(addr + 4),
  173. (unsigned)GET_16BIT_MSB_FIRST(addr + 6),
  174. (unsigned)GET_16BIT_MSB_FIRST(addr + 8),
  175. (unsigned)GET_16BIT_MSB_FIRST(addr + 10),
  176. (unsigned)GET_16BIT_MSB_FIRST(addr + 12),
  177. (unsigned)GET_16BIT_MSB_FIRST(addr + 14));
  178. }
  179. static void pfd_receive(Plug *plug, int urgent, char *data, int len)
  180. {
  181. struct PortForwarding *pf = FROMFIELD(plug, struct PortForwarding, plugvt);
  182. if (len == 0)
  183. return;
  184. if (pf->socks_state != SOCKS_NONE) {
  185. BinarySource src[1];
  186. /*
  187. * Store all the data we've got in socksbuf.
  188. */
  189. put_data(pf->socksbuf, data, len);
  190. /*
  191. * Check the start of socksbuf to see if it's a valid and
  192. * complete message in the SOCKS exchange.
  193. */
  194. if (pf->socks_state == SOCKS_INITIAL) {
  195. /* Preliminary: check the first byte of the data (which we
  196. * _must_ have by now) to find out which SOCKS major
  197. * version we're speaking. */
  198. switch (pf->socksbuf->u[0]) {
  199. case 4:
  200. pf->socks_state = SOCKS_4;
  201. break;
  202. case 5:
  203. pf->socks_state = SOCKS_5_INITIAL;
  204. break;
  205. default:
  206. pfd_close(pf); /* unrecognised version */
  207. return;
  208. }
  209. }
  210. BinarySource_BARE_INIT(src, pf->socksbuf->u, pf->socksbuf->len);
  211. get_data(src, pf->socksbuf_consumed);
  212. while (pf->socks_state != SOCKS_NONE) {
  213. unsigned socks_version, message_type, reserved_byte;
  214. unsigned reply_code, port, ipv4, method;
  215. ptrlen methods;
  216. const char *socks4_hostname;
  217. strbuf *output;
  218. switch (pf->socks_state) {
  219. case SOCKS_INITIAL:
  220. case SOCKS_NONE:
  221. assert(0 && "These case values cannot appear");
  222. case SOCKS_4:
  223. /* SOCKS 4/4A connect message */
  224. socks_version = get_byte(src);
  225. message_type = get_byte(src);
  226. if (get_err(src) == BSE_OUT_OF_DATA)
  227. return;
  228. if (socks_version == 4 && message_type == 1) {
  229. /* CONNECT message */
  230. int name_based = FALSE;
  231. port = get_uint16(src);
  232. ipv4 = get_uint32(src);
  233. if (ipv4 > 0x00000000 && ipv4 < 0x00000100) {
  234. /*
  235. * Addresses in this range indicate the SOCKS 4A
  236. * extension to specify a hostname, which comes
  237. * after the username.
  238. */
  239. name_based = TRUE;
  240. }
  241. get_asciz(src); /* skip username */
  242. socks4_hostname = name_based ? get_asciz(src) : NULL;
  243. if (get_err(src) == BSE_OUT_OF_DATA)
  244. return;
  245. if (get_err(src))
  246. goto socks4_reject;
  247. pf->port = port;
  248. if (name_based) {
  249. pf->hostname = dupstr(socks4_hostname);
  250. } else {
  251. pf->hostname = ipv4_to_string(ipv4);
  252. }
  253. output = strbuf_new();
  254. put_byte(output, 0); /* reply version */
  255. put_byte(output, 90); /* SOCKS 4 'request granted' */
  256. put_uint16(output, 0); /* null port field */
  257. put_uint32(output, 0); /* null address field */
  258. sk_write(pf->s, output->u, output->len);
  259. strbuf_free(output);
  260. pf->socks_state = SOCKS_NONE;
  261. pf->socksbuf_consumed = src->pos;
  262. break;
  263. }
  264. socks4_reject:
  265. output = strbuf_new();
  266. put_byte(output, 0); /* reply version */
  267. put_byte(output, 91); /* SOCKS 4 'request rejected' */
  268. put_uint16(output, 0); /* null port field */
  269. put_uint32(output, 0); /* null address field */
  270. sk_write(pf->s, output->u, output->len);
  271. strbuf_free(output);
  272. pfd_close(pf);
  273. return;
  274. case SOCKS_5_INITIAL:
  275. /* SOCKS 5 initial method list */
  276. socks_version = get_byte(src);
  277. methods = get_pstring(src);
  278. method = 0xFF; /* means 'no usable method found' */
  279. {
  280. int i;
  281. for (i = 0; i < methods.len; i++) {
  282. if (((const unsigned char *)methods.ptr)[i] == 0 ) {
  283. method = 0; /* no auth */
  284. break;
  285. }
  286. }
  287. }
  288. if (get_err(src) == BSE_OUT_OF_DATA)
  289. return;
  290. if (get_err(src))
  291. method = 0xFF;
  292. output = strbuf_new();
  293. put_byte(output, 5); /* SOCKS version */
  294. put_byte(output, method); /* selected auth method */
  295. sk_write(pf->s, output->u, output->len);
  296. strbuf_free(output);
  297. if (method == 0xFF) {
  298. pfd_close(pf);
  299. return;
  300. }
  301. pf->socks_state = SOCKS_5_CONNECT;
  302. pf->socksbuf_consumed = src->pos;
  303. break;
  304. case SOCKS_5_CONNECT:
  305. /* SOCKS 5 connect message */
  306. socks_version = get_byte(src);
  307. message_type = get_byte(src);
  308. reserved_byte = get_byte(src);
  309. if (socks_version == 5 && message_type == 1 &&
  310. reserved_byte == 0) {
  311. reply_code = 0; /* success */
  312. switch (get_byte(src)) {
  313. case 1: /* IPv4 */
  314. pf->hostname = ipv4_to_string(get_uint32(src));
  315. break;
  316. case 4: /* IPv6 */
  317. pf->hostname = ipv6_to_string(get_data(src, 16));
  318. break;
  319. case 3: /* unresolved domain name */
  320. pf->hostname = mkstr(get_pstring(src));
  321. break;
  322. default:
  323. pf->hostname = NULL;
  324. reply_code = 8; /* address type not supported */
  325. break;
  326. }
  327. pf->port = get_uint16(src);
  328. } else {
  329. reply_code = 7; /* command not supported */
  330. }
  331. if (get_err(src) == BSE_OUT_OF_DATA)
  332. return;
  333. if (get_err(src))
  334. reply_code = 1; /* general server failure */
  335. output = strbuf_new();
  336. put_byte(output, 5); /* SOCKS version */
  337. put_byte(output, reply_code);
  338. put_byte(output, 0); /* reserved */
  339. put_byte(output, 1); /* IPv4 address follows */
  340. put_uint32(output, 0); /* bound IPv4 address (unused) */
  341. put_uint16(output, 0); /* bound port number (unused) */
  342. sk_write(pf->s, output->u, output->len);
  343. strbuf_free(output);
  344. if (reply_code != 0) {
  345. pfd_close(pf);
  346. return;
  347. }
  348. pf->socks_state = SOCKS_NONE;
  349. pf->socksbuf_consumed = src->pos;
  350. break;
  351. }
  352. }
  353. /*
  354. * We come here when we're ready to make an actual
  355. * connection.
  356. */
  357. /*
  358. * Freeze the socket until the SSH server confirms the
  359. * connection.
  360. */
  361. sk_set_frozen(pf->s, 1);
  362. pf->c = wrap_lportfwd_open(pf->cl, pf->hostname, pf->port, pf->s,
  363. &pf->chan);
  364. }
  365. if (pf->ready)
  366. sshfwd_write(pf->c, data, len);
  367. }
  368. static void pfd_sent(Plug *plug, int bufsize)
  369. {
  370. struct PortForwarding *pf = FROMFIELD(plug, struct PortForwarding, plugvt);
  371. if (pf->c)
  372. sshfwd_unthrottle(pf->c, bufsize);
  373. }
  374. static const Plug_vtable PortForwarding_plugvt = {
  375. pfd_log,
  376. pfd_closing,
  377. pfd_receive,
  378. pfd_sent,
  379. NULL
  380. };
  381. static void pfd_chan_free(Channel *chan);
  382. static void pfd_open_confirmation(Channel *chan);
  383. static void pfd_open_failure(Channel *chan, const char *errtext);
  384. static int pfd_send(Channel *chan, int is_stderr, const void *data, int len);
  385. static void pfd_send_eof(Channel *chan);
  386. static void pfd_set_input_wanted(Channel *chan, int wanted);
  387. static char *pfd_log_close_msg(Channel *chan);
  388. static const struct ChannelVtable PortForwarding_channelvt = {
  389. pfd_chan_free,
  390. pfd_open_confirmation,
  391. pfd_open_failure,
  392. pfd_send,
  393. pfd_send_eof,
  394. pfd_set_input_wanted,
  395. pfd_log_close_msg,
  396. chan_no_eager_close,
  397. };
  398. /*
  399. called when someone connects to the local port
  400. */
  401. static int pfl_accepting(Plug *p, accept_fn_t constructor, accept_ctx_t ctx)
  402. {
  403. struct PortForwarding *pf;
  404. struct PortListener *pl;
  405. Socket *s;
  406. const char *err;
  407. pl = FROMFIELD(p, struct PortListener, plugvt);
  408. pf = new_portfwd_state();
  409. pf->plugvt = &PortForwarding_plugvt;
  410. pf->chan.initial_fixed_window_size = 0;
  411. pf->chan.vt = &PortForwarding_channelvt;
  412. pf->input_wanted = TRUE;
  413. pf->c = NULL;
  414. pf->cl = pl->cl;
  415. pf->s = s = constructor(ctx, &pf->plugvt);
  416. if ((err = sk_socket_error(s)) != NULL) {
  417. free_portfwd_state(pf);
  418. return err != NULL;
  419. }
  420. pf->input_wanted = TRUE;
  421. pf->ready = 0;
  422. if (pl->is_dynamic) {
  423. pf->socks_state = SOCKS_INITIAL;
  424. pf->socksbuf = strbuf_new();
  425. pf->socksbuf_consumed = 0;
  426. pf->port = 0; /* "hostname" buffer is so far empty */
  427. sk_set_frozen(s, 0); /* we want to receive SOCKS _now_! */
  428. } else {
  429. pf->socks_state = SOCKS_NONE;
  430. pf->hostname = dupstr(pl->hostname);
  431. pf->port = pl->port;
  432. pf->c = wrap_lportfwd_open(pl->cl, pf->hostname, pf->port,
  433. s, &pf->chan);
  434. }
  435. return 0;
  436. }
  437. static const Plug_vtable PortListener_plugvt = {
  438. pfl_log,
  439. pfl_closing,
  440. NULL, /* recv */
  441. NULL, /* send */
  442. pfl_accepting
  443. };
  444. /*
  445. * Add a new port-forwarding listener from srcaddr:port -> desthost:destport.
  446. *
  447. * desthost == NULL indicates dynamic SOCKS port forwarding.
  448. *
  449. * On success, returns NULL and fills in *pl_ret. On error, returns a
  450. * dynamically allocated error message string.
  451. */
  452. static char *pfl_listen(char *desthost, int destport, char *srcaddr,
  453. int port, ConnectionLayer *cl, Conf *conf,
  454. struct PortListener **pl_ret, int address_family)
  455. {
  456. const char *err;
  457. struct PortListener *pl;
  458. /*
  459. * Open socket.
  460. */
  461. pl = *pl_ret = new_portlistener_state();
  462. pl->plugvt = &PortListener_plugvt;
  463. if (desthost) {
  464. pl->hostname = dupstr(desthost);
  465. pl->port = destport;
  466. pl->is_dynamic = FALSE;
  467. } else
  468. pl->is_dynamic = TRUE;
  469. pl->cl = cl;
  470. pl->s = new_listener(srcaddr, port, &pl->plugvt,
  471. !conf_get_int(conf, CONF_lport_acceptall),
  472. conf, address_family);
  473. if ((err = sk_socket_error(pl->s)) != NULL) {
  474. char *err_ret = dupstr(err);
  475. sk_close(pl->s);
  476. free_portlistener_state(pl);
  477. *pl_ret = NULL;
  478. return err_ret;
  479. }
  480. return NULL;
  481. }
  482. static char *pfd_log_close_msg(Channel *chan)
  483. {
  484. return dupstr("Forwarded port closed");
  485. }
  486. static void pfd_close(struct PortForwarding *pf)
  487. {
  488. if (!pf)
  489. return;
  490. sk_close(pf->s);
  491. free_portfwd_state(pf);
  492. }
  493. /*
  494. * Terminate a listener.
  495. */
  496. static void pfl_terminate(struct PortListener *pl)
  497. {
  498. if (!pl)
  499. return;
  500. sk_close(pl->s);
  501. free_portlistener_state(pl);
  502. }
  503. static void pfd_set_input_wanted(Channel *chan, int wanted)
  504. {
  505. pinitassert(chan->vt == &PortForwarding_channelvt);
  506. PortForwarding *pf = FROMFIELD(chan, PortForwarding, chan);
  507. pf->input_wanted = wanted;
  508. sk_set_frozen(pf->s, !pf->input_wanted);
  509. }
  510. static void pfd_chan_free(Channel *chan)
  511. {
  512. pinitassert(chan->vt == &PortForwarding_channelvt);
  513. PortForwarding *pf = FROMFIELD(chan, PortForwarding, chan);
  514. pfd_close(pf);
  515. }
  516. /*
  517. * Called to send data down the raw connection.
  518. */
  519. static int pfd_send(Channel *chan, int is_stderr, const void *data, int len)
  520. {
  521. pinitassert(chan->vt == &PortForwarding_channelvt);
  522. PortForwarding *pf = FROMFIELD(chan, PortForwarding, chan);
  523. return sk_write(pf->s, data, len);
  524. }
  525. static void pfd_send_eof(Channel *chan)
  526. {
  527. pinitassert(chan->vt == &PortForwarding_channelvt);
  528. PortForwarding *pf = FROMFIELD(chan, PortForwarding, chan);
  529. sk_write_eof(pf->s);
  530. }
  531. static void pfd_open_confirmation(Channel *chan)
  532. {
  533. pinitassert(chan->vt == &PortForwarding_channelvt);
  534. PortForwarding *pf = FROMFIELD(chan, PortForwarding, chan);
  535. pf->ready = 1;
  536. sk_set_frozen(pf->s, 0);
  537. sk_write(pf->s, NULL, 0);
  538. if (pf->socksbuf) {
  539. sshfwd_write(pf->c, pf->socksbuf->u + pf->socksbuf_consumed,
  540. pf->socksbuf->len - pf->socksbuf_consumed);
  541. strbuf_free(pf->socksbuf);
  542. pf->socksbuf = NULL;
  543. }
  544. }
  545. static void pfd_open_failure(Channel *chan, const char *errtext)
  546. {
  547. pinitassert(chan->vt == &PortForwarding_channelvt);
  548. PortForwarding *pf = FROMFIELD(chan, PortForwarding, chan);
  549. logeventf(pf->cl->frontend,
  550. "Forwarded connection refused by server%s%s",
  551. errtext ? ": " : "", errtext ? errtext : "");
  552. }
  553. /* ----------------------------------------------------------------------
  554. * Code to manage the complete set of currently active port
  555. * forwardings, and update it from Conf.
  556. */
  557. struct PortFwdRecord {
  558. enum { DESTROY, KEEP, CREATE } status;
  559. int type;
  560. unsigned sport, dport;
  561. char *saddr, *daddr;
  562. char *sserv, *dserv;
  563. struct ssh_rportfwd *remote;
  564. int addressfamily;
  565. struct PortListener *local;
  566. };
  567. static int pfr_cmp(void *av, void *bv)
  568. {
  569. PortFwdRecord *a = (PortFwdRecord *) av;
  570. PortFwdRecord *b = (PortFwdRecord *) bv;
  571. int i;
  572. if (a->type > b->type)
  573. return +1;
  574. if (a->type < b->type)
  575. return -1;
  576. if (a->addressfamily > b->addressfamily)
  577. return +1;
  578. if (a->addressfamily < b->addressfamily)
  579. return -1;
  580. if ( (i = nullstrcmp(a->saddr, b->saddr)) != 0)
  581. return i < 0 ? -1 : +1;
  582. if (a->sport > b->sport)
  583. return +1;
  584. if (a->sport < b->sport)
  585. return -1;
  586. if (a->type != 'D') {
  587. if ( (i = nullstrcmp(a->daddr, b->daddr)) != 0)
  588. return i < 0 ? -1 : +1;
  589. if (a->dport > b->dport)
  590. return +1;
  591. if (a->dport < b->dport)
  592. return -1;
  593. }
  594. return 0;
  595. }
  596. void pfr_free(PortFwdRecord *pfr)
  597. {
  598. /* Dispose of any listening socket. */
  599. if (pfr->local)
  600. pfl_terminate(pfr->local);
  601. sfree(pfr->saddr);
  602. sfree(pfr->daddr);
  603. sfree(pfr->sserv);
  604. sfree(pfr->dserv);
  605. sfree(pfr);
  606. }
  607. struct PortFwdManager {
  608. ConnectionLayer *cl;
  609. Conf *conf;
  610. tree234 *forwardings;
  611. };
  612. PortFwdManager *portfwdmgr_new(ConnectionLayer *cl)
  613. {
  614. PortFwdManager *mgr = snew(PortFwdManager);
  615. mgr->cl = cl;
  616. mgr->conf = NULL;
  617. mgr->forwardings = newtree234(pfr_cmp);
  618. return mgr;
  619. }
  620. void portfwdmgr_close(PortFwdManager *mgr, PortFwdRecord *pfr)
  621. {
  622. PortFwdRecord *realpfr = del234(mgr->forwardings, pfr);
  623. if (realpfr == pfr)
  624. pfr_free(pfr);
  625. }
  626. void portfwdmgr_close_all(PortFwdManager *mgr)
  627. {
  628. PortFwdRecord *pfr;
  629. while ((pfr = delpos234(mgr->forwardings, 0)) != NULL)
  630. pfr_free(pfr);
  631. }
  632. void portfwdmgr_free(PortFwdManager *mgr)
  633. {
  634. portfwdmgr_close_all(mgr);
  635. freetree234(mgr->forwardings);
  636. if (mgr->conf)
  637. conf_free(mgr->conf);
  638. sfree(mgr);
  639. }
  640. void portfwdmgr_config(PortFwdManager *mgr, Conf *conf)
  641. {
  642. PortFwdRecord *pfr;
  643. int i;
  644. char *key, *val;
  645. if (mgr->conf)
  646. conf_free(mgr->conf);
  647. mgr->conf = conf_copy(conf);
  648. /*
  649. * Go through the existing port forwardings and tag them
  650. * with status==DESTROY. Any that we want to keep will be
  651. * re-enabled (status==KEEP) as we go through the
  652. * configuration and find out which bits are the same as
  653. * they were before.
  654. */
  655. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++)
  656. pfr->status = DESTROY;
  657. for (val = conf_get_str_strs(conf, CONF_portfwd, NULL, &key);
  658. val != NULL;
  659. val = conf_get_str_strs(conf, CONF_portfwd, key, &key)) {
  660. char *kp, *kp2, *vp, *vp2;
  661. char address_family, type;
  662. int sport, dport, sserv, dserv;
  663. char *sports, *dports, *saddr, *host;
  664. kp = key;
  665. address_family = 'A';
  666. type = 'L';
  667. if (*kp == 'A' || *kp == '4' || *kp == '6')
  668. address_family = *kp++;
  669. if (*kp == 'L' || *kp == 'R')
  670. type = *kp++;
  671. if ((kp2 = host_strchr(kp, ':')) != NULL) {
  672. /*
  673. * There's a colon in the middle of the source port
  674. * string, which means that the part before it is
  675. * actually a source address.
  676. */
  677. char *saddr_tmp = dupprintf("%.*s", (int)(kp2 - kp), kp);
  678. saddr = host_strduptrim(saddr_tmp);
  679. sfree(saddr_tmp);
  680. sports = kp2+1;
  681. } else {
  682. saddr = NULL;
  683. sports = kp;
  684. }
  685. sport = atoi(sports);
  686. sserv = 0;
  687. if (sport == 0) {
  688. sserv = 1;
  689. sport = net_service_lookup(sports);
  690. if (!sport) {
  691. logeventf(mgr->cl->frontend, "Service lookup failed for source"
  692. " port \"%s\"", sports);
  693. }
  694. }
  695. if (type == 'L' && !strcmp(val, "D")) {
  696. /* dynamic forwarding */
  697. host = NULL;
  698. dports = NULL;
  699. dport = -1;
  700. dserv = 0;
  701. type = 'D';
  702. } else {
  703. /* ordinary forwarding */
  704. vp = val;
  705. vp2 = vp + host_strcspn(vp, ":");
  706. host = dupprintf("%.*s", (int)(vp2 - vp), vp);
  707. if (*vp2)
  708. vp2++;
  709. dports = vp2;
  710. dport = atoi(dports);
  711. dserv = 0;
  712. if (dport == 0) {
  713. dserv = 1;
  714. dport = net_service_lookup(dports);
  715. if (!dport) {
  716. logeventf(mgr->cl->frontend,
  717. "Service lookup failed for destination"
  718. " port \"%s\"", dports);
  719. }
  720. }
  721. }
  722. if (sport && dport) {
  723. /* Set up a description of the source port. */
  724. pfr = snew(PortFwdRecord);
  725. pfr->type = type;
  726. pfr->saddr = saddr;
  727. pfr->sserv = sserv ? dupstr(sports) : NULL;
  728. pfr->sport = sport;
  729. pfr->daddr = host;
  730. pfr->dserv = dserv ? dupstr(dports) : NULL;
  731. pfr->dport = dport;
  732. pfr->local = NULL;
  733. pfr->remote = NULL;
  734. pfr->addressfamily = (address_family == '4' ? ADDRTYPE_IPV4 :
  735. address_family == '6' ? ADDRTYPE_IPV6 :
  736. ADDRTYPE_UNSPEC);
  737. { // WINSCP
  738. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  739. if (existing != pfr) {
  740. if (existing->status == DESTROY) {
  741. /*
  742. * We already have a port forwarding up and running
  743. * with precisely these parameters. Hence, no need
  744. * to do anything; simply re-tag the existing one
  745. * as KEEP.
  746. */
  747. existing->status = KEEP;
  748. }
  749. /*
  750. * Anything else indicates that there was a duplicate
  751. * in our input, which we'll silently ignore.
  752. */
  753. pfr_free(pfr);
  754. } else {
  755. pfr->status = CREATE;
  756. }
  757. } // WINSCP
  758. } else {
  759. sfree(saddr);
  760. sfree(host);
  761. }
  762. }
  763. /*
  764. * Now go through and destroy any port forwardings which were
  765. * not re-enabled.
  766. */
  767. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  768. if (pfr->status == DESTROY) {
  769. char *message;
  770. message = dupprintf("%s port forwarding from %s%s%d",
  771. pfr->type == 'L' ? "local" :
  772. pfr->type == 'R' ? "remote" : "dynamic",
  773. pfr->saddr ? pfr->saddr : "",
  774. pfr->saddr ? ":" : "",
  775. pfr->sport);
  776. if (pfr->type != 'D') {
  777. char *msg2 = dupprintf("%s to %s:%d", message,
  778. pfr->daddr, pfr->dport);
  779. sfree(message);
  780. message = msg2;
  781. }
  782. logeventf(mgr->cl->frontend, "Cancelling %s", message);
  783. sfree(message);
  784. /* pfr->remote or pfr->local may be NULL if setting up a
  785. * forwarding failed. */
  786. if (pfr->remote) {
  787. /*
  788. * Cancel the port forwarding at the server
  789. * end.
  790. *
  791. * Actually closing the listening port on the server
  792. * side may fail - because in SSH-1 there's no message
  793. * in the protocol to request it!
  794. *
  795. * Instead, we simply remove the record of the
  796. * forwarding from our local end, so that any
  797. * connections the server tries to make on it are
  798. * rejected.
  799. */
  800. ssh_rportfwd_remove(mgr->cl, pfr->remote);
  801. } else if (pfr->local) {
  802. pfl_terminate(pfr->local);
  803. }
  804. delpos234(mgr->forwardings, i);
  805. pfr_free(pfr);
  806. i--; /* so we don't skip one in the list */
  807. }
  808. }
  809. /*
  810. * And finally, set up any new port forwardings (status==CREATE).
  811. */
  812. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  813. if (pfr->status == CREATE) {
  814. char *sportdesc, *dportdesc;
  815. sportdesc = dupprintf("%s%s%s%s%d%s",
  816. pfr->saddr ? pfr->saddr : "",
  817. pfr->saddr ? ":" : "",
  818. pfr->sserv ? pfr->sserv : "",
  819. pfr->sserv ? "(" : "",
  820. pfr->sport,
  821. pfr->sserv ? ")" : "");
  822. if (pfr->type == 'D') {
  823. dportdesc = NULL;
  824. } else {
  825. dportdesc = dupprintf("%s:%s%s%d%s",
  826. pfr->daddr,
  827. pfr->dserv ? pfr->dserv : "",
  828. pfr->dserv ? "(" : "",
  829. pfr->dport,
  830. pfr->dserv ? ")" : "");
  831. }
  832. if (pfr->type == 'L') {
  833. char *err = pfl_listen(pfr->daddr, pfr->dport,
  834. pfr->saddr, pfr->sport,
  835. mgr->cl, conf, &pfr->local,
  836. pfr->addressfamily);
  837. logeventf(mgr->cl->frontend,
  838. "Local %sport %s forwarding to %s%s%s",
  839. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  840. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  841. sportdesc, dportdesc,
  842. err ? " failed: " : "", err ? err : "");
  843. if (err)
  844. sfree(err);
  845. } else if (pfr->type == 'D') {
  846. char *err = pfl_listen(NULL, -1, pfr->saddr, pfr->sport,
  847. mgr->cl, conf, &pfr->local,
  848. pfr->addressfamily);
  849. logeventf(mgr->cl->frontend,
  850. "Local %sport %s SOCKS dynamic forwarding%s%s",
  851. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  852. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  853. sportdesc,
  854. err ? " failed: " : "", err ? err : "");
  855. if (err)
  856. sfree(err);
  857. } else {
  858. const char *shost;
  859. if (pfr->saddr) {
  860. shost = pfr->saddr;
  861. } else if (conf_get_int(conf, CONF_rport_acceptall)) {
  862. shost = "";
  863. } else {
  864. shost = "localhost";
  865. }
  866. pfr->remote = ssh_rportfwd_alloc(
  867. mgr->cl, shost, pfr->sport, pfr->daddr, pfr->dport,
  868. pfr->addressfamily, sportdesc, pfr, NULL);
  869. if (!pfr->remote) {
  870. logeventf(mgr->cl->frontend,
  871. "Duplicate remote port forwarding to %s:%d",
  872. pfr->daddr, pfr->dport);
  873. pfr_free(pfr);
  874. } else {
  875. logeventf(mgr->cl->frontend, "Requesting remote port %s"
  876. " forward to %s", sportdesc, dportdesc);
  877. }
  878. }
  879. sfree(sportdesc);
  880. sfree(dportdesc);
  881. }
  882. }
  883. }
  884. /*
  885. * Called when receiving a PORT OPEN from the server to make a
  886. * connection to a destination host.
  887. *
  888. * On success, returns NULL and fills in *pf_ret. On error, returns a
  889. * dynamically allocated error message string.
  890. */
  891. char *portfwdmgr_connect(PortFwdManager *mgr, Channel **chan_ret,
  892. char *hostname, int port, SshChannel *c,
  893. int addressfamily)
  894. {
  895. SockAddr *addr;
  896. const char *err;
  897. char *dummy_realhost = NULL;
  898. struct PortForwarding *pf;
  899. /*
  900. * Try to find host.
  901. */
  902. addr = name_lookup(hostname, port, &dummy_realhost, mgr->conf,
  903. addressfamily, NULL, NULL);
  904. if ((err = sk_addr_error(addr)) != NULL) {
  905. char *err_ret = dupstr(err);
  906. sk_addr_free(addr);
  907. sfree(dummy_realhost);
  908. return err_ret;
  909. }
  910. /*
  911. * Open socket.
  912. */
  913. pf = new_portfwd_state();
  914. *chan_ret = &pf->chan;
  915. pf->plugvt = &PortForwarding_plugvt;
  916. pf->chan.initial_fixed_window_size = 0;
  917. pf->chan.vt = &PortForwarding_channelvt;
  918. pf->input_wanted = TRUE;
  919. pf->ready = 1;
  920. pf->c = c;
  921. pf->cl = mgr->cl;
  922. pf->socks_state = SOCKS_NONE;
  923. pf->s = new_connection(addr, dummy_realhost, port,
  924. 0, 1, 0, 0, &pf->plugvt, mgr->conf);
  925. sfree(dummy_realhost);
  926. if ((err = sk_socket_error(pf->s)) != NULL) {
  927. char *err_ret = dupstr(err);
  928. sk_close(pf->s);
  929. free_portfwd_state(pf);
  930. *chan_ret = NULL;
  931. return err_ret;
  932. }
  933. return NULL;
  934. }
  935. #ifdef MPEXT
  936. #include "puttyexp.h"
  937. int is_pfwd(Plug plug)
  938. {
  939. return
  940. ((*plug)->closing == pfd_closing) ||
  941. ((*plug)->closing == pfl_closing);
  942. }
  943. Frontend * get_pfwd_frontend(Plug plug)
  944. {
  945. Ssh ssh = NULL;
  946. if ((*plug)->closing == pfl_closing)
  947. {
  948. struct PortListener *pl = FROMFIELD(plug, struct PortListener, plugvt);
  949. ssh = pl->cl->frontend;
  950. }
  951. else if ((*plug)->closing == pfd_closing)
  952. {
  953. struct PortForwarding *pf = FROMFIELD(plug, struct PortForwarding, plugvt);
  954. ssh = pf->cl->frontend;
  955. }
  956. return ssh;
  957. }
  958. #endif