portfwd.c 34 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088
  1. /*
  2. * SSH port forwarding.
  3. */
  4. #include <assert.h>
  5. #include <stdio.h>
  6. #include <stdlib.h>
  7. #include "putty.h"
  8. #include "ssh.h"
  9. #include "sshchan.h"
  10. /*
  11. * Enumeration of values that live in the 'socks_state' field of
  12. * struct PortForwarding.
  13. */
  14. typedef enum {
  15. SOCKS_NONE, /* direct connection (no SOCKS, or SOCKS already done) */
  16. SOCKS_INITIAL, /* don't know if we're SOCKS 4 or 5 yet */
  17. SOCKS_4, /* expect a SOCKS 4 (or 4A) connection message */
  18. SOCKS_5_INITIAL, /* expect a SOCKS 5 preliminary message */
  19. SOCKS_5_CONNECT /* expect a SOCKS 5 connection message */
  20. } SocksState;
  21. typedef struct PortForwarding {
  22. SshChannel *c; /* channel structure held by SSH connection layer */
  23. ConnectionLayer *cl; /* the connection layer itself */
  24. /* Note that ssh need not be filled in if c is non-NULL */
  25. Socket *s;
  26. int input_wanted;
  27. int ready;
  28. SocksState socks_state;
  29. /*
  30. * `hostname' and `port' are the real hostname and port, once
  31. * we know what we're connecting to.
  32. */
  33. char *hostname;
  34. int port;
  35. /*
  36. * `socksbuf' is the buffer we use to accumulate the initial SOCKS
  37. * segment of the incoming data, plus anything after that that we
  38. * receive before we're ready to send data to the SSH server.
  39. */
  40. strbuf *socksbuf;
  41. size_t socksbuf_consumed;
  42. Plug plug;
  43. Channel chan;
  44. } PortForwarding;
  45. struct PortListener {
  46. ConnectionLayer *cl;
  47. Socket *s;
  48. int is_dynamic;
  49. /*
  50. * `hostname' and `port' are the real hostname and port, for
  51. * ordinary forwardings.
  52. */
  53. char *hostname;
  54. int port;
  55. Plug plug;
  56. };
  57. static struct PortForwarding *new_portfwd_state(void)
  58. {
  59. struct PortForwarding *pf = snew(struct PortForwarding);
  60. pf->hostname = NULL;
  61. pf->socksbuf = NULL;
  62. return pf;
  63. }
  64. static void free_portfwd_state(struct PortForwarding *pf)
  65. {
  66. if (!pf)
  67. return;
  68. sfree(pf->hostname);
  69. if (pf->socksbuf)
  70. strbuf_free(pf->socksbuf);
  71. sfree(pf);
  72. }
  73. static struct PortListener *new_portlistener_state(void)
  74. {
  75. struct PortListener *pl = snew(struct PortListener);
  76. pl->hostname = NULL;
  77. return pl;
  78. }
  79. static void free_portlistener_state(struct PortListener *pl)
  80. {
  81. if (!pl)
  82. return;
  83. sfree(pl->hostname);
  84. sfree(pl);
  85. }
  86. static void pfd_log(Plug *plug, int type, SockAddr *addr, int port,
  87. const char *error_msg, int error_code)
  88. {
  89. /* we have to dump these since we have no interface to logging.c */
  90. }
  91. static void pfl_log(Plug *plug, int type, SockAddr *addr, int port,
  92. const char *error_msg, int error_code)
  93. {
  94. /* we have to dump these since we have no interface to logging.c */
  95. }
  96. static void pfd_close(struct PortForwarding *pf);
  97. static void pfd_closing(Plug *plug, const char *error_msg, int error_code,
  98. int calling_back)
  99. {
  100. struct PortForwarding *pf =
  101. container_of(plug, struct PortForwarding, plug);
  102. if (error_msg) {
  103. /*
  104. * Socket error. Slam the connection instantly shut.
  105. */
  106. if (pf->c) {
  107. sshfwd_unclean_close(pf->c, error_msg);
  108. } else {
  109. /*
  110. * We might not have an SSH channel, if a socket error
  111. * occurred during SOCKS negotiation. If not, we must
  112. * clean ourself up without sshfwd_unclean_close's call
  113. * back to pfd_close.
  114. */
  115. pfd_close(pf);
  116. }
  117. } else {
  118. /*
  119. * Ordinary EOF received on socket. Send an EOF on the SSH
  120. * channel.
  121. */
  122. if (pf->c)
  123. sshfwd_write_eof(pf->c);
  124. }
  125. }
  126. static void pfl_terminate(struct PortListener *pl);
  127. static void pfl_closing(Plug *plug, const char *error_msg, int error_code,
  128. int calling_back)
  129. {
  130. struct PortListener *pl = (struct PortListener *) plug;
  131. pfl_terminate(pl);
  132. }
  133. static SshChannel *wrap_lportfwd_open(
  134. ConnectionLayer *cl, const char *hostname, int port,
  135. Socket *s, Channel *chan)
  136. {
  137. char *peerinfo, *description;
  138. SshChannel *toret;
  139. peerinfo = sk_peer_info(s);
  140. if (peerinfo) {
  141. description = dupprintf("forwarding from %s", peerinfo);
  142. sfree(peerinfo);
  143. } else {
  144. description = dupstr("forwarding");
  145. }
  146. toret = ssh_lportfwd_open(cl, hostname, port, description, chan);
  147. sfree(description);
  148. return toret;
  149. }
  150. static char *ipv4_to_string(unsigned ipv4)
  151. {
  152. return dupprintf("%u.%u.%u.%u",
  153. (ipv4 >> 24) & 0xFF, (ipv4 >> 16) & 0xFF,
  154. (ipv4 >> 8) & 0xFF, (ipv4 ) & 0xFF);
  155. }
  156. static char *ipv6_to_string(ptrlen ipv6)
  157. {
  158. const unsigned char *addr = ipv6.ptr;
  159. assert(ipv6.len == 16);
  160. return dupprintf("%04x:%04x:%04x:%04x:%04x:%04x:%04x:%04x",
  161. (unsigned)GET_16BIT_MSB_FIRST(addr + 0),
  162. (unsigned)GET_16BIT_MSB_FIRST(addr + 2),
  163. (unsigned)GET_16BIT_MSB_FIRST(addr + 4),
  164. (unsigned)GET_16BIT_MSB_FIRST(addr + 6),
  165. (unsigned)GET_16BIT_MSB_FIRST(addr + 8),
  166. (unsigned)GET_16BIT_MSB_FIRST(addr + 10),
  167. (unsigned)GET_16BIT_MSB_FIRST(addr + 12),
  168. (unsigned)GET_16BIT_MSB_FIRST(addr + 14));
  169. }
  170. static void pfd_receive(Plug *plug, int urgent, char *data, int len)
  171. {
  172. struct PortForwarding *pf =
  173. container_of(plug, struct PortForwarding, plug);
  174. if (len == 0)
  175. return;
  176. if (pf->socks_state != SOCKS_NONE) {
  177. BinarySource src[1];
  178. /*
  179. * Store all the data we've got in socksbuf.
  180. */
  181. put_data(pf->socksbuf, data, len);
  182. /*
  183. * Check the start of socksbuf to see if it's a valid and
  184. * complete message in the SOCKS exchange.
  185. */
  186. if (pf->socks_state == SOCKS_INITIAL) {
  187. /* Preliminary: check the first byte of the data (which we
  188. * _must_ have by now) to find out which SOCKS major
  189. * version we're speaking. */
  190. switch (pf->socksbuf->u[0]) {
  191. case 4:
  192. pf->socks_state = SOCKS_4;
  193. break;
  194. case 5:
  195. pf->socks_state = SOCKS_5_INITIAL;
  196. break;
  197. default:
  198. pfd_close(pf); /* unrecognised version */
  199. return;
  200. }
  201. }
  202. BinarySource_BARE_INIT(src, pf->socksbuf->u, pf->socksbuf->len);
  203. get_data(src, pf->socksbuf_consumed);
  204. while (pf->socks_state != SOCKS_NONE) {
  205. unsigned socks_version, message_type, reserved_byte;
  206. unsigned reply_code, port, ipv4, method;
  207. ptrlen methods;
  208. const char *socks4_hostname;
  209. strbuf *output;
  210. switch (pf->socks_state) {
  211. case SOCKS_INITIAL:
  212. case SOCKS_NONE:
  213. assert(0 && "These case values cannot appear");
  214. case SOCKS_4:
  215. /* SOCKS 4/4A connect message */
  216. socks_version = get_byte(src);
  217. message_type = get_byte(src);
  218. if (get_err(src) == BSE_OUT_OF_DATA)
  219. return;
  220. if (socks_version == 4 && message_type == 1) {
  221. /* CONNECT message */
  222. int name_based = FALSE;
  223. port = get_uint16(src);
  224. ipv4 = get_uint32(src);
  225. if (ipv4 > 0x00000000 && ipv4 < 0x00000100) {
  226. /*
  227. * Addresses in this range indicate the SOCKS 4A
  228. * extension to specify a hostname, which comes
  229. * after the username.
  230. */
  231. name_based = TRUE;
  232. }
  233. get_asciz(src); /* skip username */
  234. socks4_hostname = name_based ? get_asciz(src) : NULL;
  235. if (get_err(src) == BSE_OUT_OF_DATA)
  236. return;
  237. if (get_err(src))
  238. goto socks4_reject;
  239. pf->port = port;
  240. if (name_based) {
  241. pf->hostname = dupstr(socks4_hostname);
  242. } else {
  243. pf->hostname = ipv4_to_string(ipv4);
  244. }
  245. output = strbuf_new();
  246. put_byte(output, 0); /* reply version */
  247. put_byte(output, 90); /* SOCKS 4 'request granted' */
  248. put_uint16(output, 0); /* null port field */
  249. put_uint32(output, 0); /* null address field */
  250. sk_write(pf->s, output->u, output->len);
  251. strbuf_free(output);
  252. pf->socks_state = SOCKS_NONE;
  253. pf->socksbuf_consumed = src->pos;
  254. break;
  255. }
  256. socks4_reject:
  257. output = strbuf_new();
  258. put_byte(output, 0); /* reply version */
  259. put_byte(output, 91); /* SOCKS 4 'request rejected' */
  260. put_uint16(output, 0); /* null port field */
  261. put_uint32(output, 0); /* null address field */
  262. sk_write(pf->s, output->u, output->len);
  263. strbuf_free(output);
  264. pfd_close(pf);
  265. return;
  266. case SOCKS_5_INITIAL:
  267. /* SOCKS 5 initial method list */
  268. socks_version = get_byte(src);
  269. methods = get_pstring(src);
  270. method = 0xFF; /* means 'no usable method found' */
  271. {
  272. int i;
  273. for (i = 0; i < methods.len; i++) {
  274. if (((const unsigned char *)methods.ptr)[i] == 0 ) {
  275. method = 0; /* no auth */
  276. break;
  277. }
  278. }
  279. }
  280. if (get_err(src) == BSE_OUT_OF_DATA)
  281. return;
  282. if (get_err(src))
  283. method = 0xFF;
  284. output = strbuf_new();
  285. put_byte(output, 5); /* SOCKS version */
  286. put_byte(output, method); /* selected auth method */
  287. sk_write(pf->s, output->u, output->len);
  288. strbuf_free(output);
  289. if (method == 0xFF) {
  290. pfd_close(pf);
  291. return;
  292. }
  293. pf->socks_state = SOCKS_5_CONNECT;
  294. pf->socksbuf_consumed = src->pos;
  295. break;
  296. case SOCKS_5_CONNECT:
  297. /* SOCKS 5 connect message */
  298. socks_version = get_byte(src);
  299. message_type = get_byte(src);
  300. reserved_byte = get_byte(src);
  301. if (socks_version == 5 && message_type == 1 &&
  302. reserved_byte == 0) {
  303. reply_code = 0; /* success */
  304. switch (get_byte(src)) {
  305. case 1: /* IPv4 */
  306. pf->hostname = ipv4_to_string(get_uint32(src));
  307. break;
  308. case 4: /* IPv6 */
  309. pf->hostname = ipv6_to_string(get_data(src, 16));
  310. break;
  311. case 3: /* unresolved domain name */
  312. pf->hostname = mkstr(get_pstring(src));
  313. break;
  314. default:
  315. pf->hostname = NULL;
  316. reply_code = 8; /* address type not supported */
  317. break;
  318. }
  319. pf->port = get_uint16(src);
  320. } else {
  321. reply_code = 7; /* command not supported */
  322. }
  323. if (get_err(src) == BSE_OUT_OF_DATA)
  324. return;
  325. if (get_err(src))
  326. reply_code = 1; /* general server failure */
  327. output = strbuf_new();
  328. put_byte(output, 5); /* SOCKS version */
  329. put_byte(output, reply_code);
  330. put_byte(output, 0); /* reserved */
  331. put_byte(output, 1); /* IPv4 address follows */
  332. put_uint32(output, 0); /* bound IPv4 address (unused) */
  333. put_uint16(output, 0); /* bound port number (unused) */
  334. sk_write(pf->s, output->u, output->len);
  335. strbuf_free(output);
  336. if (reply_code != 0) {
  337. pfd_close(pf);
  338. return;
  339. }
  340. pf->socks_state = SOCKS_NONE;
  341. pf->socksbuf_consumed = src->pos;
  342. break;
  343. }
  344. }
  345. /*
  346. * We come here when we're ready to make an actual
  347. * connection.
  348. */
  349. /*
  350. * Freeze the socket until the SSH server confirms the
  351. * connection.
  352. */
  353. sk_set_frozen(pf->s, 1);
  354. pf->c = wrap_lportfwd_open(pf->cl, pf->hostname, pf->port, pf->s,
  355. &pf->chan);
  356. }
  357. if (pf->ready)
  358. sshfwd_write(pf->c, data, len);
  359. }
  360. static void pfd_sent(Plug *plug, int bufsize)
  361. {
  362. struct PortForwarding *pf =
  363. container_of(plug, struct PortForwarding, plug);
  364. if (pf->c)
  365. sshfwd_unthrottle(pf->c, bufsize);
  366. }
  367. static const PlugVtable PortForwarding_plugvt = {
  368. pfd_log,
  369. pfd_closing,
  370. pfd_receive,
  371. pfd_sent,
  372. NULL
  373. };
  374. static void pfd_chan_free(Channel *chan);
  375. static void pfd_open_confirmation(Channel *chan);
  376. static void pfd_open_failure(Channel *chan, const char *errtext);
  377. static int pfd_send(Channel *chan, int is_stderr, const void *data, int len);
  378. static void pfd_send_eof(Channel *chan);
  379. static void pfd_set_input_wanted(Channel *chan, int wanted);
  380. static char *pfd_log_close_msg(Channel *chan);
  381. static const struct ChannelVtable PortForwarding_channelvt = {
  382. pfd_chan_free,
  383. pfd_open_confirmation,
  384. pfd_open_failure,
  385. pfd_send,
  386. pfd_send_eof,
  387. pfd_set_input_wanted,
  388. pfd_log_close_msg,
  389. chan_no_eager_close,
  390. };
  391. /*
  392. called when someone connects to the local port
  393. */
  394. static int pfl_accepting(Plug *p, accept_fn_t constructor, accept_ctx_t ctx)
  395. {
  396. struct PortForwarding *pf;
  397. struct PortListener *pl;
  398. Socket *s;
  399. const char *err;
  400. pl = container_of(p, struct PortListener, plug);
  401. pf = new_portfwd_state();
  402. pf->plug.vt = &PortForwarding_plugvt;
  403. pf->chan.initial_fixed_window_size = 0;
  404. pf->chan.vt = &PortForwarding_channelvt;
  405. pf->input_wanted = TRUE;
  406. pf->c = NULL;
  407. pf->cl = pl->cl;
  408. pf->s = s = constructor(ctx, &pf->plug);
  409. if ((err = sk_socket_error(s)) != NULL) {
  410. free_portfwd_state(pf);
  411. return err != NULL;
  412. }
  413. pf->input_wanted = TRUE;
  414. pf->ready = 0;
  415. if (pl->is_dynamic) {
  416. pf->socks_state = SOCKS_INITIAL;
  417. pf->socksbuf = strbuf_new();
  418. pf->socksbuf_consumed = 0;
  419. pf->port = 0; /* "hostname" buffer is so far empty */
  420. sk_set_frozen(s, 0); /* we want to receive SOCKS _now_! */
  421. } else {
  422. pf->socks_state = SOCKS_NONE;
  423. pf->hostname = dupstr(pl->hostname);
  424. pf->port = pl->port;
  425. pf->c = wrap_lportfwd_open(pl->cl, pf->hostname, pf->port,
  426. s, &pf->chan);
  427. }
  428. return 0;
  429. }
  430. static const PlugVtable PortListener_plugvt = {
  431. pfl_log,
  432. pfl_closing,
  433. NULL, /* recv */
  434. NULL, /* send */
  435. pfl_accepting
  436. };
  437. /*
  438. * Add a new port-forwarding listener from srcaddr:port -> desthost:destport.
  439. *
  440. * desthost == NULL indicates dynamic SOCKS port forwarding.
  441. *
  442. * On success, returns NULL and fills in *pl_ret. On error, returns a
  443. * dynamically allocated error message string.
  444. */
  445. static char *pfl_listen(char *desthost, int destport, char *srcaddr,
  446. int port, ConnectionLayer *cl, Conf *conf,
  447. struct PortListener **pl_ret, int address_family)
  448. {
  449. const char *err;
  450. struct PortListener *pl;
  451. /*
  452. * Open socket.
  453. */
  454. pl = *pl_ret = new_portlistener_state();
  455. pl->plug.vt = &PortListener_plugvt;
  456. if (desthost) {
  457. pl->hostname = dupstr(desthost);
  458. pl->port = destport;
  459. pl->is_dynamic = FALSE;
  460. } else
  461. pl->is_dynamic = TRUE;
  462. pl->cl = cl;
  463. pl->s = new_listener(srcaddr, port, &pl->plug,
  464. !conf_get_int(conf, CONF_lport_acceptall),
  465. conf, address_family);
  466. if ((err = sk_socket_error(pl->s)) != NULL) {
  467. char *err_ret = dupstr(err);
  468. sk_close(pl->s);
  469. free_portlistener_state(pl);
  470. *pl_ret = NULL;
  471. return err_ret;
  472. }
  473. return NULL;
  474. }
  475. static char *pfd_log_close_msg(Channel *chan)
  476. {
  477. return dupstr("Forwarded port closed");
  478. }
  479. static void pfd_close(struct PortForwarding *pf)
  480. {
  481. if (!pf)
  482. return;
  483. sk_close(pf->s);
  484. free_portfwd_state(pf);
  485. }
  486. /*
  487. * Terminate a listener.
  488. */
  489. static void pfl_terminate(struct PortListener *pl)
  490. {
  491. if (!pl)
  492. return;
  493. sk_close(pl->s);
  494. free_portlistener_state(pl);
  495. }
  496. static void pfd_set_input_wanted(Channel *chan, int wanted)
  497. {
  498. pinitassert(chan->vt == &PortForwarding_channelvt);
  499. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  500. pf->input_wanted = wanted;
  501. sk_set_frozen(pf->s, !pf->input_wanted);
  502. }
  503. static void pfd_chan_free(Channel *chan)
  504. {
  505. pinitassert(chan->vt == &PortForwarding_channelvt);
  506. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  507. pfd_close(pf);
  508. }
  509. /*
  510. * Called to send data down the raw connection.
  511. */
  512. static int pfd_send(Channel *chan, int is_stderr, const void *data, int len)
  513. {
  514. pinitassert(chan->vt == &PortForwarding_channelvt);
  515. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  516. return sk_write(pf->s, data, len);
  517. }
  518. static void pfd_send_eof(Channel *chan)
  519. {
  520. pinitassert(chan->vt == &PortForwarding_channelvt);
  521. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  522. sk_write_eof(pf->s);
  523. }
  524. static void pfd_open_confirmation(Channel *chan)
  525. {
  526. pinitassert(chan->vt == &PortForwarding_channelvt);
  527. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  528. pf->ready = 1;
  529. sk_set_frozen(pf->s, 0);
  530. sk_write(pf->s, NULL, 0);
  531. if (pf->socksbuf) {
  532. sshfwd_write(pf->c, pf->socksbuf->u + pf->socksbuf_consumed,
  533. pf->socksbuf->len - pf->socksbuf_consumed);
  534. strbuf_free(pf->socksbuf);
  535. pf->socksbuf = NULL;
  536. }
  537. }
  538. static void pfd_open_failure(Channel *chan, const char *errtext)
  539. {
  540. pinitassert(chan->vt == &PortForwarding_channelvt);
  541. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  542. logeventf(pf->cl->logctx,
  543. "Forwarded connection refused by server%s%s",
  544. errtext ? ": " : "", errtext ? errtext : "");
  545. }
  546. /* ----------------------------------------------------------------------
  547. * Code to manage the complete set of currently active port
  548. * forwardings, and update it from Conf.
  549. */
  550. struct PortFwdRecord {
  551. enum { DESTROY, KEEP, CREATE } status;
  552. int type;
  553. unsigned sport, dport;
  554. char *saddr, *daddr;
  555. char *sserv, *dserv;
  556. struct ssh_rportfwd *remote;
  557. int addressfamily;
  558. struct PortListener *local;
  559. };
  560. static int pfr_cmp(void *av, void *bv)
  561. {
  562. PortFwdRecord *a = (PortFwdRecord *) av;
  563. PortFwdRecord *b = (PortFwdRecord *) bv;
  564. int i;
  565. if (a->type > b->type)
  566. return +1;
  567. if (a->type < b->type)
  568. return -1;
  569. if (a->addressfamily > b->addressfamily)
  570. return +1;
  571. if (a->addressfamily < b->addressfamily)
  572. return -1;
  573. if ( (i = nullstrcmp(a->saddr, b->saddr)) != 0)
  574. return i < 0 ? -1 : +1;
  575. if (a->sport > b->sport)
  576. return +1;
  577. if (a->sport < b->sport)
  578. return -1;
  579. if (a->type != 'D') {
  580. if ( (i = nullstrcmp(a->daddr, b->daddr)) != 0)
  581. return i < 0 ? -1 : +1;
  582. if (a->dport > b->dport)
  583. return +1;
  584. if (a->dport < b->dport)
  585. return -1;
  586. }
  587. return 0;
  588. }
  589. void pfr_free(PortFwdRecord *pfr)
  590. {
  591. /* Dispose of any listening socket. */
  592. if (pfr->local)
  593. pfl_terminate(pfr->local);
  594. sfree(pfr->saddr);
  595. sfree(pfr->daddr);
  596. sfree(pfr->sserv);
  597. sfree(pfr->dserv);
  598. sfree(pfr);
  599. }
  600. struct PortFwdManager {
  601. ConnectionLayer *cl;
  602. Conf *conf;
  603. tree234 *forwardings;
  604. };
  605. PortFwdManager *portfwdmgr_new(ConnectionLayer *cl)
  606. {
  607. PortFwdManager *mgr = snew(PortFwdManager);
  608. mgr->cl = cl;
  609. mgr->conf = NULL;
  610. mgr->forwardings = newtree234(pfr_cmp);
  611. return mgr;
  612. }
  613. void portfwdmgr_close(PortFwdManager *mgr, PortFwdRecord *pfr)
  614. {
  615. PortFwdRecord *realpfr = del234(mgr->forwardings, pfr);
  616. if (realpfr == pfr)
  617. pfr_free(pfr);
  618. }
  619. void portfwdmgr_close_all(PortFwdManager *mgr)
  620. {
  621. PortFwdRecord *pfr;
  622. while ((pfr = delpos234(mgr->forwardings, 0)) != NULL)
  623. pfr_free(pfr);
  624. }
  625. void portfwdmgr_free(PortFwdManager *mgr)
  626. {
  627. portfwdmgr_close_all(mgr);
  628. freetree234(mgr->forwardings);
  629. if (mgr->conf)
  630. conf_free(mgr->conf);
  631. sfree(mgr);
  632. }
  633. void portfwdmgr_config(PortFwdManager *mgr, Conf *conf)
  634. {
  635. PortFwdRecord *pfr;
  636. int i;
  637. char *key, *val;
  638. if (mgr->conf)
  639. conf_free(mgr->conf);
  640. mgr->conf = conf_copy(conf);
  641. /*
  642. * Go through the existing port forwardings and tag them
  643. * with status==DESTROY. Any that we want to keep will be
  644. * re-enabled (status==KEEP) as we go through the
  645. * configuration and find out which bits are the same as
  646. * they were before.
  647. */
  648. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++)
  649. pfr->status = DESTROY;
  650. for (val = conf_get_str_strs(conf, CONF_portfwd, NULL, &key);
  651. val != NULL;
  652. val = conf_get_str_strs(conf, CONF_portfwd, key, &key)) {
  653. char *kp, *kp2, *vp, *vp2;
  654. char address_family, type;
  655. int sport, dport, sserv, dserv;
  656. char *sports, *dports, *saddr, *host;
  657. kp = key;
  658. address_family = 'A';
  659. type = 'L';
  660. if (*kp == 'A' || *kp == '4' || *kp == '6')
  661. address_family = *kp++;
  662. if (*kp == 'L' || *kp == 'R')
  663. type = *kp++;
  664. if ((kp2 = host_strchr(kp, ':')) != NULL) {
  665. /*
  666. * There's a colon in the middle of the source port
  667. * string, which means that the part before it is
  668. * actually a source address.
  669. */
  670. char *saddr_tmp = dupprintf("%.*s", (int)(kp2 - kp), kp);
  671. saddr = host_strduptrim(saddr_tmp);
  672. sfree(saddr_tmp);
  673. sports = kp2+1;
  674. } else {
  675. saddr = NULL;
  676. sports = kp;
  677. }
  678. sport = atoi(sports);
  679. sserv = 0;
  680. if (sport == 0) {
  681. sserv = 1;
  682. sport = net_service_lookup(sports);
  683. if (!sport) {
  684. logeventf(mgr->cl->logctx, "Service lookup failed for source"
  685. " port \"%s\"", sports);
  686. }
  687. }
  688. if (type == 'L' && !strcmp(val, "D")) {
  689. /* dynamic forwarding */
  690. host = NULL;
  691. dports = NULL;
  692. dport = -1;
  693. dserv = 0;
  694. type = 'D';
  695. } else {
  696. /* ordinary forwarding */
  697. vp = val;
  698. vp2 = vp + host_strcspn(vp, ":");
  699. host = dupprintf("%.*s", (int)(vp2 - vp), vp);
  700. if (*vp2)
  701. vp2++;
  702. dports = vp2;
  703. dport = atoi(dports);
  704. dserv = 0;
  705. if (dport == 0) {
  706. dserv = 1;
  707. dport = net_service_lookup(dports);
  708. if (!dport) {
  709. logeventf(mgr->cl->logctx,
  710. "Service lookup failed for destination"
  711. " port \"%s\"", dports);
  712. }
  713. }
  714. }
  715. if (sport && dport) {
  716. /* Set up a description of the source port. */
  717. pfr = snew(PortFwdRecord);
  718. pfr->type = type;
  719. pfr->saddr = saddr;
  720. pfr->sserv = sserv ? dupstr(sports) : NULL;
  721. pfr->sport = sport;
  722. pfr->daddr = host;
  723. pfr->dserv = dserv ? dupstr(dports) : NULL;
  724. pfr->dport = dport;
  725. pfr->local = NULL;
  726. pfr->remote = NULL;
  727. pfr->addressfamily = (address_family == '4' ? ADDRTYPE_IPV4 :
  728. address_family == '6' ? ADDRTYPE_IPV6 :
  729. ADDRTYPE_UNSPEC);
  730. { // WINSCP
  731. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  732. if (existing != pfr) {
  733. if (existing->status == DESTROY) {
  734. /*
  735. * We already have a port forwarding up and running
  736. * with precisely these parameters. Hence, no need
  737. * to do anything; simply re-tag the existing one
  738. * as KEEP.
  739. */
  740. existing->status = KEEP;
  741. }
  742. /*
  743. * Anything else indicates that there was a duplicate
  744. * in our input, which we'll silently ignore.
  745. */
  746. pfr_free(pfr);
  747. } else {
  748. pfr->status = CREATE;
  749. }
  750. } // WINSCP
  751. } else {
  752. sfree(saddr);
  753. sfree(host);
  754. }
  755. }
  756. /*
  757. * Now go through and destroy any port forwardings which were
  758. * not re-enabled.
  759. */
  760. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  761. if (pfr->status == DESTROY) {
  762. char *message;
  763. message = dupprintf("%s port forwarding from %s%s%d",
  764. pfr->type == 'L' ? "local" :
  765. pfr->type == 'R' ? "remote" : "dynamic",
  766. pfr->saddr ? pfr->saddr : "",
  767. pfr->saddr ? ":" : "",
  768. pfr->sport);
  769. if (pfr->type != 'D') {
  770. char *msg2 = dupprintf("%s to %s:%d", message,
  771. pfr->daddr, pfr->dport);
  772. sfree(message);
  773. message = msg2;
  774. }
  775. logeventf(mgr->cl->logctx, "Cancelling %s", message);
  776. sfree(message);
  777. /* pfr->remote or pfr->local may be NULL if setting up a
  778. * forwarding failed. */
  779. if (pfr->remote) {
  780. /*
  781. * Cancel the port forwarding at the server
  782. * end.
  783. *
  784. * Actually closing the listening port on the server
  785. * side may fail - because in SSH-1 there's no message
  786. * in the protocol to request it!
  787. *
  788. * Instead, we simply remove the record of the
  789. * forwarding from our local end, so that any
  790. * connections the server tries to make on it are
  791. * rejected.
  792. */
  793. ssh_rportfwd_remove(mgr->cl, pfr->remote);
  794. } else if (pfr->local) {
  795. pfl_terminate(pfr->local);
  796. }
  797. delpos234(mgr->forwardings, i);
  798. pfr_free(pfr);
  799. i--; /* so we don't skip one in the list */
  800. }
  801. }
  802. /*
  803. * And finally, set up any new port forwardings (status==CREATE).
  804. */
  805. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  806. if (pfr->status == CREATE) {
  807. char *sportdesc, *dportdesc;
  808. sportdesc = dupprintf("%s%s%s%s%d%s",
  809. pfr->saddr ? pfr->saddr : "",
  810. pfr->saddr ? ":" : "",
  811. pfr->sserv ? pfr->sserv : "",
  812. pfr->sserv ? "(" : "",
  813. pfr->sport,
  814. pfr->sserv ? ")" : "");
  815. if (pfr->type == 'D') {
  816. dportdesc = NULL;
  817. } else {
  818. dportdesc = dupprintf("%s:%s%s%d%s",
  819. pfr->daddr,
  820. pfr->dserv ? pfr->dserv : "",
  821. pfr->dserv ? "(" : "",
  822. pfr->dport,
  823. pfr->dserv ? ")" : "");
  824. }
  825. if (pfr->type == 'L') {
  826. char *err = pfl_listen(pfr->daddr, pfr->dport,
  827. pfr->saddr, pfr->sport,
  828. mgr->cl, conf, &pfr->local,
  829. pfr->addressfamily);
  830. logeventf(mgr->cl->logctx,
  831. "Local %sport %s forwarding to %s%s%s",
  832. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  833. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  834. sportdesc, dportdesc,
  835. err ? " failed: " : "", err ? err : "");
  836. if (err)
  837. sfree(err);
  838. } else if (pfr->type == 'D') {
  839. char *err = pfl_listen(NULL, -1, pfr->saddr, pfr->sport,
  840. mgr->cl, conf, &pfr->local,
  841. pfr->addressfamily);
  842. logeventf(mgr->cl->logctx,
  843. "Local %sport %s SOCKS dynamic forwarding%s%s",
  844. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  845. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  846. sportdesc,
  847. err ? " failed: " : "", err ? err : "");
  848. if (err)
  849. sfree(err);
  850. } else {
  851. const char *shost;
  852. if (pfr->saddr) {
  853. shost = pfr->saddr;
  854. } else if (conf_get_int(conf, CONF_rport_acceptall)) {
  855. shost = "";
  856. } else {
  857. shost = "localhost";
  858. }
  859. pfr->remote = ssh_rportfwd_alloc(
  860. mgr->cl, shost, pfr->sport, pfr->daddr, pfr->dport,
  861. pfr->addressfamily, sportdesc, pfr, NULL);
  862. if (!pfr->remote) {
  863. logeventf(mgr->cl->logctx,
  864. "Duplicate remote port forwarding to %s:%d",
  865. pfr->daddr, pfr->dport);
  866. pfr_free(pfr);
  867. } else {
  868. logeventf(mgr->cl->logctx, "Requesting remote port %s"
  869. " forward to %s", sportdesc, dportdesc);
  870. }
  871. }
  872. sfree(sportdesc);
  873. sfree(dportdesc);
  874. }
  875. }
  876. }
  877. /*
  878. * Called when receiving a PORT OPEN from the server to make a
  879. * connection to a destination host.
  880. *
  881. * On success, returns NULL and fills in *pf_ret. On error, returns a
  882. * dynamically allocated error message string.
  883. */
  884. char *portfwdmgr_connect(PortFwdManager *mgr, Channel **chan_ret,
  885. char *hostname, int port, SshChannel *c,
  886. int addressfamily)
  887. {
  888. SockAddr *addr;
  889. const char *err;
  890. char *dummy_realhost = NULL;
  891. struct PortForwarding *pf;
  892. /*
  893. * Try to find host.
  894. */
  895. addr = name_lookup(hostname, port, &dummy_realhost, mgr->conf,
  896. addressfamily, NULL, NULL);
  897. if ((err = sk_addr_error(addr)) != NULL) {
  898. char *err_ret = dupstr(err);
  899. sk_addr_free(addr);
  900. sfree(dummy_realhost);
  901. return err_ret;
  902. }
  903. /*
  904. * Open socket.
  905. */
  906. pf = new_portfwd_state();
  907. *chan_ret = &pf->chan;
  908. pf->plug.vt = &PortForwarding_plugvt;
  909. pf->chan.initial_fixed_window_size = 0;
  910. pf->chan.vt = &PortForwarding_channelvt;
  911. pf->input_wanted = TRUE;
  912. pf->ready = 1;
  913. pf->c = c;
  914. pf->cl = mgr->cl;
  915. pf->socks_state = SOCKS_NONE;
  916. pf->s = new_connection(addr, dummy_realhost, port,
  917. 0, 1, 0, 0, &pf->plug, mgr->conf);
  918. sfree(dummy_realhost);
  919. if ((err = sk_socket_error(pf->s)) != NULL) {
  920. char *err_ret = dupstr(err);
  921. sk_close(pf->s);
  922. free_portfwd_state(pf);
  923. *chan_ret = NULL;
  924. return err_ret;
  925. }
  926. return NULL;
  927. }
  928. #ifdef MPEXT
  929. #include "puttyexp.h"
  930. int is_pfwd(Plug * plug)
  931. {
  932. return
  933. (plug->vt->closing == pfd_closing) ||
  934. (plug->vt->closing == pfl_closing);
  935. }
  936. Frontend * get_pfwd_frontend(Plug * plug)
  937. {
  938. Frontend * frontend = NULL;
  939. if (plug->vt->closing == pfl_closing)
  940. {
  941. struct PortListener *pl = container_of(plug, struct PortListener, plug);
  942. frontend = log_get_frontend(pl->cl->logctx);
  943. }
  944. else if (plug->vt->closing == pfd_closing)
  945. {
  946. struct PortForwarding *pf = container_of(plug, struct PortForwarding, plug);
  947. frontend = log_get_frontend(pf->cl->logctx);
  948. }
  949. return frontend;
  950. }
  951. #endif