portfwd.c 37 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179
  1. /*
  2. * SSH port forwarding.
  3. */
  4. #include <assert.h>
  5. #include <stdio.h>
  6. #include <stdlib.h>
  7. #include "putty.h"
  8. #include "ssh.h"
  9. #include "channel.h"
  10. #include "proxy/socks.h"
  11. /*
  12. * Enumeration of values that live in the 'socks_state' field of
  13. * struct PortForwarding.
  14. */
  15. typedef enum {
  16. SOCKS_NONE, /* direct connection (no SOCKS, or SOCKS already done) */
  17. SOCKS_INITIAL, /* don't know if we're SOCKS 4 or 5 yet */
  18. SOCKS_4, /* expect a SOCKS 4 (or 4A) connection message */
  19. SOCKS_5_INITIAL, /* expect a SOCKS 5 preliminary message */
  20. SOCKS_5_CONNECT /* expect a SOCKS 5 connection message */
  21. } SocksState;
  22. typedef struct PortForwarding {
  23. SshChannel *c; /* channel structure held by SSH connection layer */
  24. ConnectionLayer *cl; /* the connection layer itself */
  25. /* Note that ssh need not be filled in if c is non-NULL */
  26. Socket *s;
  27. bool input_wanted;
  28. bool ready;
  29. SocksState socks_state;
  30. /*
  31. * `hostname' and `port' are the real hostname and port, once
  32. * we know what we're connecting to.
  33. */
  34. char *hostname;
  35. int port;
  36. /*
  37. * `socksbuf' is the buffer we use to accumulate the initial SOCKS
  38. * segment of the incoming data, plus anything after that that we
  39. * receive before we're ready to send data to the SSH server.
  40. */
  41. strbuf *socksbuf;
  42. size_t socksbuf_consumed;
  43. Plug plug;
  44. Channel chan;
  45. } PortForwarding;
  46. struct PortListener {
  47. ConnectionLayer *cl;
  48. Socket *s;
  49. bool is_dynamic;
  50. /*
  51. * `hostname' and `port' are the real hostname and port, for
  52. * ordinary forwardings.
  53. */
  54. char *hostname;
  55. int port;
  56. Plug plug;
  57. };
  58. static struct PortForwarding *new_portfwd_state(void)
  59. {
  60. struct PortForwarding *pf = snew(struct PortForwarding);
  61. pf->hostname = NULL;
  62. pf->socksbuf = NULL;
  63. return pf;
  64. }
  65. static void free_portfwd_state(struct PortForwarding *pf)
  66. {
  67. if (!pf)
  68. return;
  69. sfree(pf->hostname);
  70. if (pf->socksbuf)
  71. strbuf_free(pf->socksbuf);
  72. sfree(pf);
  73. }
  74. static struct PortListener *new_portlistener_state(void)
  75. {
  76. struct PortListener *pl = snew(struct PortListener);
  77. pl->hostname = NULL;
  78. return pl;
  79. }
  80. static void free_portlistener_state(struct PortListener *pl)
  81. {
  82. if (!pl)
  83. return;
  84. sfree(pl->hostname);
  85. sfree(pl);
  86. }
  87. static void pfd_log(Plug *plug, PlugLogType type, SockAddr *addr, int port,
  88. const char *error_msg, int error_code)
  89. {
  90. /* we have to dump these since we have no interface to logging.c */
  91. }
  92. static void pfl_log(Plug *plug, PlugLogType type, SockAddr *addr, int port,
  93. const char *error_msg, int error_code)
  94. {
  95. /* we have to dump these since we have no interface to logging.c */
  96. }
  97. static void pfd_close(struct PortForwarding *pf);
  98. static void pfd_closing(Plug *plug, PlugCloseType type, const char *error_msg)
  99. {
  100. struct PortForwarding *pf =
  101. container_of(plug, struct PortForwarding, plug);
  102. if (type != PLUGCLOSE_NORMAL) {
  103. /*
  104. * Socket error. Slam the connection instantly shut.
  105. */
  106. if (pf->c) {
  107. sshfwd_initiate_close(pf->c, error_msg);
  108. } else {
  109. /*
  110. * We might not have an SSH channel, if a socket error
  111. * occurred during SOCKS negotiation. If not, we must
  112. * clean ourself up without sshfwd_initiate_close's call
  113. * back to pfd_close.
  114. */
  115. pfd_close(pf);
  116. }
  117. } else {
  118. /*
  119. * Ordinary EOF received on socket. Send an EOF on the SSH
  120. * channel.
  121. */
  122. if (pf->c)
  123. sshfwd_write_eof(pf->c);
  124. }
  125. }
  126. static void pfl_terminate(struct PortListener *pl);
  127. static void pfl_closing(Plug *plug, PlugCloseType type, const char *error_msg)
  128. {
  129. struct PortListener *pl = (struct PortListener *) plug;
  130. pfl_terminate(pl);
  131. }
  132. static SshChannel *wrap_lportfwd_open(
  133. ConnectionLayer *cl, const char *hostname, int port,
  134. Socket *s, Channel *chan)
  135. {
  136. SocketPeerInfo *pi;
  137. char *description;
  138. SshChannel *toret;
  139. pi = sk_peer_info(s);
  140. if (pi && pi->log_text) {
  141. description = dupprintf("forwarding from %s", pi->log_text);
  142. } else {
  143. description = dupstr("forwarding");
  144. }
  145. toret = ssh_lportfwd_open(cl, hostname, port, description, pi, chan);
  146. sk_free_peer_info(pi);
  147. sfree(description);
  148. return toret;
  149. }
  150. static char *ipv4_to_string(unsigned ipv4)
  151. {
  152. return dupprintf("%u.%u.%u.%u",
  153. (ipv4 >> 24) & 0xFF, (ipv4 >> 16) & 0xFF,
  154. (ipv4 >> 8) & 0xFF, (ipv4 ) & 0xFF);
  155. }
  156. static char *ipv6_to_string(ptrlen ipv6)
  157. {
  158. const unsigned char *addr = ipv6.ptr;
  159. assert(ipv6.len == 16);
  160. return dupprintf("%04x:%04x:%04x:%04x:%04x:%04x:%04x:%04x",
  161. (unsigned)GET_16BIT_MSB_FIRST(addr + 0),
  162. (unsigned)GET_16BIT_MSB_FIRST(addr + 2),
  163. (unsigned)GET_16BIT_MSB_FIRST(addr + 4),
  164. (unsigned)GET_16BIT_MSB_FIRST(addr + 6),
  165. (unsigned)GET_16BIT_MSB_FIRST(addr + 8),
  166. (unsigned)GET_16BIT_MSB_FIRST(addr + 10),
  167. (unsigned)GET_16BIT_MSB_FIRST(addr + 12),
  168. (unsigned)GET_16BIT_MSB_FIRST(addr + 14));
  169. }
  170. static void pfd_receive(Plug *plug, int urgent, const char *data, size_t len)
  171. {
  172. struct PortForwarding *pf =
  173. container_of(plug, struct PortForwarding, plug);
  174. if (len == 0)
  175. return;
  176. if (pf->socks_state != SOCKS_NONE) {
  177. BinarySource src[1];
  178. /*
  179. * Store all the data we've got in socksbuf.
  180. */
  181. put_data(pf->socksbuf, data, len);
  182. /*
  183. * Check the start of socksbuf to see if it's a valid and
  184. * complete message in the SOCKS exchange.
  185. */
  186. if (pf->socks_state == SOCKS_INITIAL) {
  187. /* Preliminary: check the first byte of the data (which we
  188. * _must_ have by now) to find out which SOCKS major
  189. * version we're speaking. */
  190. switch (pf->socksbuf->u[0]) {
  191. case SOCKS4_REQUEST_VERSION:
  192. pf->socks_state = SOCKS_4;
  193. break;
  194. case SOCKS5_REQUEST_VERSION:
  195. pf->socks_state = SOCKS_5_INITIAL;
  196. break;
  197. default:
  198. pfd_close(pf); /* unrecognised version */
  199. return;
  200. }
  201. }
  202. BinarySource_BARE_INIT(src, pf->socksbuf->u, pf->socksbuf->len);
  203. get_data(src, pf->socksbuf_consumed);
  204. while (pf->socks_state != SOCKS_NONE) {
  205. unsigned socks_version, message_type, reserved_byte;
  206. unsigned reply_code, port, ipv4, method;
  207. ptrlen methods;
  208. const char *socks4_hostname;
  209. strbuf *output;
  210. switch (pf->socks_state) {
  211. case SOCKS_INITIAL:
  212. case SOCKS_NONE:
  213. unreachable("These case values cannot appear");
  214. case SOCKS_4:
  215. /* SOCKS 4/4A connect message */
  216. socks_version = get_byte(src);
  217. message_type = get_byte(src);
  218. if (get_err(src) == BSE_OUT_OF_DATA)
  219. return;
  220. if (socks_version == SOCKS4_REQUEST_VERSION &&
  221. message_type == SOCKS_CMD_CONNECT) {
  222. /* CONNECT message */
  223. bool name_based = false;
  224. port = get_uint16(src);
  225. ipv4 = get_uint32(src);
  226. if (ipv4 >= SOCKS4A_NAME_FOLLOWS_BASE &&
  227. ipv4 < SOCKS4A_NAME_FOLLOWS_LIMIT) {
  228. /*
  229. * Addresses in this range indicate the SOCKS 4A
  230. * extension to specify a hostname, which comes
  231. * after the username.
  232. */
  233. name_based = true;
  234. }
  235. get_asciz(src); /* skip username */
  236. socks4_hostname = name_based ? get_asciz(src) : NULL;
  237. if (get_err(src) == BSE_OUT_OF_DATA)
  238. return;
  239. if (get_err(src))
  240. goto socks4_reject;
  241. pf->port = port;
  242. if (name_based) {
  243. pf->hostname = dupstr(socks4_hostname);
  244. } else {
  245. pf->hostname = ipv4_to_string(ipv4);
  246. }
  247. output = strbuf_new();
  248. put_byte(output, SOCKS4_REPLY_VERSION);
  249. put_byte(output, SOCKS4_RESP_SUCCESS);
  250. put_uint16(output, 0); /* null port field */
  251. put_uint32(output, 0); /* null address field */
  252. sk_write(pf->s, output->u, output->len);
  253. strbuf_free(output);
  254. pf->socks_state = SOCKS_NONE;
  255. pf->socksbuf_consumed = src->pos;
  256. break;
  257. }
  258. socks4_reject:
  259. output = strbuf_new();
  260. put_byte(output, SOCKS4_REPLY_VERSION);
  261. put_byte(output, SOCKS4_RESP_FAILURE);
  262. put_uint16(output, 0); /* null port field */
  263. put_uint32(output, 0); /* null address field */
  264. sk_write(pf->s, output->u, output->len);
  265. strbuf_free(output);
  266. pfd_close(pf);
  267. return;
  268. case SOCKS_5_INITIAL:
  269. /* SOCKS 5 initial method list */
  270. socks_version = get_byte(src);
  271. methods = get_pstring(src);
  272. method = SOCKS5_AUTH_REJECTED;
  273. /* Search the method list for AUTH_NONE, which is the
  274. * only one this client code can speak */
  275. for (size_t i = 0; i < methods.len; i++) {
  276. unsigned char this_method =
  277. ((const unsigned char *)methods.ptr)[i];
  278. if (this_method == SOCKS5_AUTH_NONE) {
  279. method = this_method;
  280. break;
  281. }
  282. }
  283. if (get_err(src) == BSE_OUT_OF_DATA)
  284. return;
  285. if (get_err(src))
  286. method = SOCKS5_AUTH_REJECTED;
  287. output = strbuf_new();
  288. put_byte(output, SOCKS5_REPLY_VERSION);
  289. put_byte(output, method);
  290. sk_write(pf->s, output->u, output->len);
  291. strbuf_free(output);
  292. if (method == SOCKS5_AUTH_REJECTED) {
  293. pfd_close(pf);
  294. return;
  295. }
  296. pf->socks_state = SOCKS_5_CONNECT;
  297. pf->socksbuf_consumed = src->pos;
  298. break;
  299. case SOCKS_5_CONNECT:
  300. /* SOCKS 5 connect message */
  301. socks_version = get_byte(src);
  302. message_type = get_byte(src);
  303. reserved_byte = get_byte(src);
  304. if (socks_version == SOCKS5_REQUEST_VERSION &&
  305. message_type == SOCKS_CMD_CONNECT &&
  306. reserved_byte == 0) {
  307. reply_code = SOCKS5_RESP_SUCCESS;
  308. switch (get_byte(src)) {
  309. case SOCKS5_ADDR_IPV4:
  310. pf->hostname = ipv4_to_string(get_uint32(src));
  311. break;
  312. case SOCKS5_ADDR_IPV6:
  313. pf->hostname = ipv6_to_string(get_data(src, 16));
  314. break;
  315. case SOCKS5_ADDR_HOSTNAME:
  316. pf->hostname = mkstr(get_pstring(src));
  317. break;
  318. default:
  319. pf->hostname = NULL;
  320. reply_code = SOCKS5_RESP_ADDRTYPE_NOT_SUPPORTED;
  321. break;
  322. }
  323. pf->port = get_uint16(src);
  324. } else {
  325. reply_code = SOCKS5_RESP_COMMAND_NOT_SUPPORTED;
  326. }
  327. if (get_err(src) == BSE_OUT_OF_DATA)
  328. return;
  329. if (get_err(src))
  330. reply_code = SOCKS5_RESP_FAILURE;
  331. output = strbuf_new();
  332. put_byte(output, SOCKS5_REPLY_VERSION);
  333. put_byte(output, reply_code);
  334. put_byte(output, 0); /* reserved */
  335. put_byte(output, SOCKS5_ADDR_IPV4); /* IPv4 address follows */
  336. put_uint32(output, 0); /* bound IPv4 address (unused) */
  337. put_uint16(output, 0); /* bound port number (unused) */
  338. sk_write(pf->s, output->u, output->len);
  339. strbuf_free(output);
  340. if (reply_code != SOCKS5_RESP_SUCCESS) {
  341. pfd_close(pf);
  342. return;
  343. }
  344. pf->socks_state = SOCKS_NONE;
  345. pf->socksbuf_consumed = src->pos;
  346. break;
  347. }
  348. }
  349. /*
  350. * We come here when we're ready to make an actual
  351. * connection.
  352. */
  353. /*
  354. * Freeze the socket until the SSH server confirms the
  355. * connection.
  356. */
  357. sk_set_frozen(pf->s, true);
  358. pf->c = wrap_lportfwd_open(pf->cl, pf->hostname, pf->port, pf->s,
  359. &pf->chan);
  360. }
  361. if (pf->ready)
  362. sshfwd_write(pf->c, data, len);
  363. }
  364. static void pfd_sent(Plug *plug, size_t bufsize)
  365. {
  366. struct PortForwarding *pf =
  367. container_of(plug, struct PortForwarding, plug);
  368. if (pf->c)
  369. sshfwd_unthrottle(pf->c, bufsize);
  370. }
  371. static const PlugVtable PortForwarding_plugvt = {
  372. .log = pfd_log,
  373. .closing = pfd_closing,
  374. .receive = pfd_receive,
  375. .sent = pfd_sent,
  376. };
  377. static void pfd_chan_free(Channel *chan);
  378. static void pfd_open_confirmation(Channel *chan);
  379. static void pfd_open_failure(Channel *chan, const char *errtext);
  380. static size_t pfd_send(
  381. Channel *chan, bool is_stderr, const void *data, size_t len);
  382. static void pfd_send_eof(Channel *chan);
  383. static void pfd_set_input_wanted(Channel *chan, bool wanted);
  384. static char *pfd_log_close_msg(Channel *chan);
  385. static const ChannelVtable PortForwarding_channelvt = {
  386. .free = pfd_chan_free,
  387. .open_confirmation = pfd_open_confirmation,
  388. .open_failed = pfd_open_failure,
  389. .send = pfd_send,
  390. .send_eof = pfd_send_eof,
  391. .set_input_wanted = pfd_set_input_wanted,
  392. .log_close_msg = pfd_log_close_msg,
  393. .want_close = chan_default_want_close,
  394. .rcvd_exit_status = chan_no_exit_status,
  395. .rcvd_exit_signal = chan_no_exit_signal,
  396. .rcvd_exit_signal_numeric = chan_no_exit_signal_numeric,
  397. .run_shell = chan_no_run_shell,
  398. .run_command = chan_no_run_command,
  399. .run_subsystem = chan_no_run_subsystem,
  400. .enable_x11_forwarding = chan_no_enable_x11_forwarding,
  401. .enable_agent_forwarding = chan_no_enable_agent_forwarding,
  402. .allocate_pty = chan_no_allocate_pty,
  403. .set_env = chan_no_set_env,
  404. .send_break = chan_no_send_break,
  405. .send_signal = chan_no_send_signal,
  406. .change_window_size = chan_no_change_window_size,
  407. .request_response = chan_no_request_response,
  408. };
  409. Channel *portfwd_raw_new(ConnectionLayer *cl, Plug **plug, bool start_ready)
  410. {
  411. struct PortForwarding *pf;
  412. pf = new_portfwd_state();
  413. pf->plug.vt = &PortForwarding_plugvt;
  414. pf->chan.initial_fixed_window_size = 0;
  415. pf->chan.vt = &PortForwarding_channelvt;
  416. pf->input_wanted = true;
  417. pf->c = NULL;
  418. pf->cl = cl;
  419. pf->input_wanted = true;
  420. pf->ready = start_ready;
  421. pf->socks_state = SOCKS_NONE;
  422. pf->hostname = NULL;
  423. pf->port = 0;
  424. *plug = &pf->plug;
  425. return &pf->chan;
  426. }
  427. void portfwd_raw_free(Channel *pfchan)
  428. {
  429. struct PortForwarding *pf;
  430. assert(pfchan->vt == &PortForwarding_channelvt);
  431. pf = container_of(pfchan, struct PortForwarding, chan);
  432. free_portfwd_state(pf);
  433. }
  434. void portfwd_raw_setup(Channel *pfchan, Socket *s, SshChannel *sc)
  435. {
  436. struct PortForwarding *pf;
  437. assert(pfchan->vt == &PortForwarding_channelvt);
  438. pf = container_of(pfchan, struct PortForwarding, chan);
  439. pf->s = s;
  440. pf->c = sc;
  441. }
  442. /*
  443. * called when someone connects to the local port
  444. */
  445. static int pfl_accepting(Plug *p, accept_fn_t constructor, accept_ctx_t ctx)
  446. {
  447. struct PortListener *pl = container_of(p, struct PortListener, plug);
  448. struct PortForwarding *pf;
  449. Channel *chan;
  450. Plug *plug;
  451. Socket *s;
  452. const char *err;
  453. chan = portfwd_raw_new(pl->cl, &plug, false);
  454. s = constructor(ctx, plug);
  455. if ((err = sk_socket_error(s)) != NULL) {
  456. portfwd_raw_free(chan);
  457. return 1;
  458. }
  459. pf = container_of(chan, struct PortForwarding, chan);
  460. if (pl->is_dynamic) {
  461. pf->s = s;
  462. pf->socks_state = SOCKS_INITIAL;
  463. pf->socksbuf = strbuf_new();
  464. pf->socksbuf_consumed = 0;
  465. pf->port = 0; /* "hostname" buffer is so far empty */
  466. sk_set_frozen(s, false); /* we want to receive SOCKS _now_! */
  467. } else {
  468. pf->hostname = dupstr(pl->hostname);
  469. pf->port = pl->port;
  470. portfwd_raw_setup(
  471. chan, s,
  472. wrap_lportfwd_open(pl->cl, pf->hostname, pf->port, s, &pf->chan));
  473. }
  474. return 0;
  475. }
  476. static const PlugVtable PortListener_plugvt = {
  477. .log = pfl_log,
  478. .closing = pfl_closing,
  479. .accepting = pfl_accepting,
  480. };
  481. /*
  482. * Add a new port-forwarding listener from srcaddr:port -> desthost:destport.
  483. *
  484. * desthost == NULL indicates dynamic SOCKS port forwarding.
  485. *
  486. * On success, returns NULL and fills in *pl_ret. On error, returns a
  487. * dynamically allocated error message string.
  488. */
  489. static char *pfl_listen(const char *desthost, int destport,
  490. const char *srcaddr, int port,
  491. ConnectionLayer *cl, Conf *conf,
  492. struct PortListener **pl_ret, int address_family)
  493. {
  494. const char *err;
  495. struct PortListener *pl;
  496. /*
  497. * Open socket.
  498. */
  499. pl = *pl_ret = new_portlistener_state();
  500. pl->plug.vt = &PortListener_plugvt;
  501. if (desthost) {
  502. pl->hostname = dupstr(desthost);
  503. pl->port = destport;
  504. pl->is_dynamic = false;
  505. } else
  506. pl->is_dynamic = true;
  507. pl->cl = cl;
  508. pl->s = new_listener(srcaddr, port, &pl->plug,
  509. !conf_get_bool(conf, CONF_lport_acceptall),
  510. conf, address_family);
  511. if ((err = sk_socket_error(pl->s)) != NULL) {
  512. char *err_ret = dupstr(err);
  513. sk_close(pl->s);
  514. free_portlistener_state(pl);
  515. *pl_ret = NULL;
  516. return err_ret;
  517. }
  518. return NULL;
  519. }
  520. static char *pfd_log_close_msg(Channel *chan)
  521. {
  522. return dupstr("Forwarded port closed");
  523. }
  524. static void pfd_close(struct PortForwarding *pf)
  525. {
  526. if (!pf)
  527. return;
  528. sk_close(pf->s);
  529. free_portfwd_state(pf);
  530. }
  531. /*
  532. * Terminate a listener.
  533. */
  534. static void pfl_terminate(struct PortListener *pl)
  535. {
  536. if (!pl)
  537. return;
  538. sk_close(pl->s);
  539. free_portlistener_state(pl);
  540. }
  541. static void pfd_set_input_wanted(Channel *chan, bool wanted)
  542. {
  543. assert(chan->vt == &PortForwarding_channelvt);
  544. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  545. pf->input_wanted = wanted;
  546. sk_set_frozen(pf->s, !pf->input_wanted);
  547. }
  548. static void pfd_chan_free(Channel *chan)
  549. {
  550. assert(chan->vt == &PortForwarding_channelvt);
  551. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  552. pfd_close(pf);
  553. }
  554. /*
  555. * Called to send data down the raw connection.
  556. */
  557. static size_t pfd_send(
  558. Channel *chan, bool is_stderr, const void *data, size_t len)
  559. {
  560. assert(chan->vt == &PortForwarding_channelvt);
  561. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  562. return sk_write(pf->s, data, len);
  563. }
  564. static void pfd_send_eof(Channel *chan)
  565. {
  566. assert(chan->vt == &PortForwarding_channelvt);
  567. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  568. sk_write_eof(pf->s);
  569. }
  570. static void pfd_open_confirmation(Channel *chan)
  571. {
  572. assert(chan->vt == &PortForwarding_channelvt);
  573. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  574. pf->ready = true;
  575. sk_set_frozen(pf->s, false);
  576. sk_write(pf->s, NULL, 0);
  577. if (pf->socksbuf) {
  578. sshfwd_write(pf->c, pf->socksbuf->u + pf->socksbuf_consumed,
  579. pf->socksbuf->len - pf->socksbuf_consumed);
  580. strbuf_free(pf->socksbuf);
  581. pf->socksbuf = NULL;
  582. }
  583. }
  584. static void pfd_open_failure(Channel *chan, const char *errtext)
  585. {
  586. assert(chan->vt == &PortForwarding_channelvt);
  587. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  588. logeventf(pf->cl->logctx,
  589. "Forwarded connection refused by remote%s%s",
  590. errtext ? ": " : "", errtext ? errtext : "");
  591. }
  592. /* ----------------------------------------------------------------------
  593. * Code to manage the complete set of currently active port
  594. * forwardings, and update it from Conf.
  595. */
  596. struct PortFwdRecord {
  597. enum { DESTROY, KEEP, CREATE } status;
  598. int type;
  599. unsigned sport, dport;
  600. char *saddr, *daddr;
  601. char *sserv, *dserv;
  602. struct ssh_rportfwd *remote;
  603. int addressfamily;
  604. struct PortListener *local;
  605. };
  606. static int pfr_cmp(void *av, void *bv)
  607. {
  608. PortFwdRecord *a = (PortFwdRecord *) av;
  609. PortFwdRecord *b = (PortFwdRecord *) bv;
  610. int i;
  611. if (a->type > b->type)
  612. return +1;
  613. if (a->type < b->type)
  614. return -1;
  615. if (a->addressfamily > b->addressfamily)
  616. return +1;
  617. if (a->addressfamily < b->addressfamily)
  618. return -1;
  619. if ( (i = nullstrcmp(a->saddr, b->saddr)) != 0)
  620. return i < 0 ? -1 : +1;
  621. if (a->sport > b->sport)
  622. return +1;
  623. if (a->sport < b->sport)
  624. return -1;
  625. if (a->type != 'D') {
  626. if ( (i = nullstrcmp(a->daddr, b->daddr)) != 0)
  627. return i < 0 ? -1 : +1;
  628. if (a->dport > b->dport)
  629. return +1;
  630. if (a->dport < b->dport)
  631. return -1;
  632. }
  633. return 0;
  634. }
  635. static void pfr_free(PortFwdRecord *pfr)
  636. {
  637. /* Dispose of any listening socket. */
  638. if (pfr->local)
  639. pfl_terminate(pfr->local);
  640. sfree(pfr->saddr);
  641. sfree(pfr->daddr);
  642. sfree(pfr->sserv);
  643. sfree(pfr->dserv);
  644. sfree(pfr);
  645. }
  646. struct PortFwdManager {
  647. ConnectionLayer *cl;
  648. Conf *conf;
  649. tree234 *forwardings;
  650. };
  651. PortFwdManager *portfwdmgr_new(ConnectionLayer *cl)
  652. {
  653. PortFwdManager *mgr = snew(PortFwdManager);
  654. mgr->cl = cl;
  655. mgr->conf = NULL;
  656. mgr->forwardings = newtree234(pfr_cmp);
  657. return mgr;
  658. }
  659. void portfwdmgr_close(PortFwdManager *mgr, PortFwdRecord *pfr)
  660. {
  661. PortFwdRecord *realpfr = del234(mgr->forwardings, pfr);
  662. if (realpfr == pfr)
  663. pfr_free(pfr);
  664. }
  665. void portfwdmgr_close_all(PortFwdManager *mgr)
  666. {
  667. PortFwdRecord *pfr;
  668. while ((pfr = delpos234(mgr->forwardings, 0)) != NULL)
  669. pfr_free(pfr);
  670. }
  671. void portfwdmgr_free(PortFwdManager *mgr)
  672. {
  673. portfwdmgr_close_all(mgr);
  674. freetree234(mgr->forwardings);
  675. if (mgr->conf)
  676. conf_free(mgr->conf);
  677. sfree(mgr);
  678. }
  679. void portfwdmgr_config(PortFwdManager *mgr, Conf *conf)
  680. {
  681. PortFwdRecord *pfr;
  682. int i;
  683. char *key, *val;
  684. if (mgr->conf)
  685. conf_free(mgr->conf);
  686. mgr->conf = conf_copy(conf);
  687. /*
  688. * Go through the existing port forwardings and tag them
  689. * with status==DESTROY. Any that we want to keep will be
  690. * re-enabled (status==KEEP) as we go through the
  691. * configuration and find out which bits are the same as
  692. * they were before.
  693. */
  694. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++)
  695. pfr->status = DESTROY;
  696. for (val = conf_get_str_strs(conf, CONF_portfwd, NULL, &key);
  697. val != NULL;
  698. val = conf_get_str_strs(conf, CONF_portfwd, key, &key)) {
  699. char *kp, *kp2, *vp, *vp2;
  700. char address_family, type;
  701. int sport, dport, sserv, dserv;
  702. char *sports, *dports, *saddr, *host;
  703. kp = key;
  704. address_family = 'A';
  705. type = 'L';
  706. if (*kp == 'A' || *kp == '4' || *kp == '6')
  707. address_family = *kp++;
  708. if (*kp == 'L' || *kp == 'R')
  709. type = *kp++;
  710. if ((kp2 = host_strchr(kp, ':')) != NULL) {
  711. /*
  712. * There's a colon in the middle of the source port
  713. * string, which means that the part before it is
  714. * actually a source address.
  715. */
  716. char *saddr_tmp = dupprintf("%.*s", (int)(kp2 - kp), kp);
  717. saddr = host_strduptrim(saddr_tmp);
  718. sfree(saddr_tmp);
  719. sports = kp2+1;
  720. } else {
  721. saddr = NULL;
  722. sports = kp;
  723. }
  724. sport = atoi(sports);
  725. sserv = 0;
  726. if (sport == 0) {
  727. sserv = 1;
  728. sport = net_service_lookup(sports);
  729. if (!sport) {
  730. logeventf(mgr->cl->logctx, "Service lookup failed for source"
  731. " port \"%s\"", sports);
  732. }
  733. }
  734. if (type == 'L' && !strcmp(val, "D")) {
  735. /* dynamic forwarding */
  736. host = NULL;
  737. dports = NULL;
  738. dport = -1;
  739. dserv = 0;
  740. type = 'D';
  741. } else {
  742. /* ordinary forwarding */
  743. vp = val;
  744. vp2 = vp + host_strcspn(vp, ":");
  745. host = dupprintf("%.*s", (int)(vp2 - vp), vp);
  746. if (*vp2)
  747. vp2++;
  748. dports = vp2;
  749. dport = atoi(dports);
  750. dserv = 0;
  751. if (dport == 0) {
  752. dserv = 1;
  753. dport = net_service_lookup(dports);
  754. if (!dport) {
  755. logeventf(mgr->cl->logctx,
  756. "Service lookup failed for destination"
  757. " port \"%s\"", dports);
  758. }
  759. }
  760. }
  761. if (sport && dport) {
  762. /* Set up a description of the source port. */
  763. pfr = snew(PortFwdRecord);
  764. pfr->type = type;
  765. pfr->saddr = saddr;
  766. pfr->sserv = sserv ? dupstr(sports) : NULL;
  767. pfr->sport = sport;
  768. pfr->daddr = host;
  769. pfr->dserv = dserv ? dupstr(dports) : NULL;
  770. pfr->dport = dport;
  771. pfr->local = NULL;
  772. pfr->remote = NULL;
  773. pfr->addressfamily = (address_family == '4' ? ADDRTYPE_IPV4 :
  774. address_family == '6' ? ADDRTYPE_IPV6 :
  775. ADDRTYPE_UNSPEC);
  776. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  777. if (existing != pfr) {
  778. if (existing->status == DESTROY) {
  779. /*
  780. * We already have a port forwarding up and running
  781. * with precisely these parameters. Hence, no need
  782. * to do anything; simply re-tag the existing one
  783. * as KEEP.
  784. */
  785. existing->status = KEEP;
  786. }
  787. /*
  788. * Anything else indicates that there was a duplicate
  789. * in our input, which we'll silently ignore.
  790. */
  791. pfr_free(pfr);
  792. } else {
  793. pfr->status = CREATE;
  794. }
  795. } else {
  796. sfree(saddr);
  797. sfree(host);
  798. }
  799. }
  800. /*
  801. * Now go through and destroy any port forwardings which were
  802. * not re-enabled.
  803. */
  804. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  805. if (pfr->status == DESTROY) {
  806. char *message;
  807. message = dupprintf("%s port forwarding from %s%s%d",
  808. pfr->type == 'L' ? "local" :
  809. pfr->type == 'R' ? "remote" : "dynamic",
  810. pfr->saddr ? pfr->saddr : "",
  811. pfr->saddr ? ":" : "",
  812. pfr->sport);
  813. if (pfr->type != 'D') {
  814. char *msg2 = dupprintf("%s to %s:%d", message,
  815. pfr->daddr, pfr->dport);
  816. sfree(message);
  817. message = msg2;
  818. }
  819. logeventf(mgr->cl->logctx, "Cancelling %s", message);
  820. sfree(message);
  821. /* pfr->remote or pfr->local may be NULL if setting up a
  822. * forwarding failed. */
  823. if (pfr->remote) {
  824. /*
  825. * Cancel the port forwarding at the server
  826. * end.
  827. *
  828. * Actually closing the listening port on the server
  829. * side may fail - because in SSH-1 there's no message
  830. * in the protocol to request it!
  831. *
  832. * Instead, we simply remove the record of the
  833. * forwarding from our local end, so that any
  834. * connections the server tries to make on it are
  835. * rejected.
  836. */
  837. ssh_rportfwd_remove(mgr->cl, pfr->remote);
  838. pfr->remote = NULL;
  839. } else if (pfr->local) {
  840. pfl_terminate(pfr->local);
  841. pfr->local = NULL;
  842. }
  843. delpos234(mgr->forwardings, i);
  844. pfr_free(pfr);
  845. i--; /* so we don't skip one in the list */
  846. }
  847. }
  848. /*
  849. * And finally, set up any new port forwardings (status==CREATE).
  850. */
  851. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  852. if (pfr->status == CREATE) {
  853. char *sportdesc, *dportdesc;
  854. sportdesc = dupprintf("%s%s%s%s%d%s",
  855. pfr->saddr ? pfr->saddr : "",
  856. pfr->saddr ? ":" : "",
  857. pfr->sserv ? pfr->sserv : "",
  858. pfr->sserv ? "(" : "",
  859. pfr->sport,
  860. pfr->sserv ? ")" : "");
  861. if (pfr->type == 'D') {
  862. dportdesc = NULL;
  863. } else {
  864. dportdesc = dupprintf("%s:%s%s%d%s",
  865. pfr->daddr,
  866. pfr->dserv ? pfr->dserv : "",
  867. pfr->dserv ? "(" : "",
  868. pfr->dport,
  869. pfr->dserv ? ")" : "");
  870. }
  871. if (pfr->type == 'L') {
  872. char *err = pfl_listen(pfr->daddr, pfr->dport,
  873. pfr->saddr, pfr->sport,
  874. mgr->cl, conf, &pfr->local,
  875. pfr->addressfamily);
  876. logeventf(mgr->cl->logctx,
  877. "Local %sport %s forwarding to %s%s%s",
  878. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  879. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  880. sportdesc, dportdesc,
  881. err ? " failed: " : "", err ? err : "");
  882. if (err)
  883. sfree(err);
  884. } else if (pfr->type == 'D') {
  885. char *err = pfl_listen(NULL, -1, pfr->saddr, pfr->sport,
  886. mgr->cl, conf, &pfr->local,
  887. pfr->addressfamily);
  888. logeventf(mgr->cl->logctx,
  889. "Local %sport %s SOCKS dynamic forwarding%s%s",
  890. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  891. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  892. sportdesc,
  893. err ? " failed: " : "", err ? err : "");
  894. if (err)
  895. sfree(err);
  896. } else {
  897. const char *shost;
  898. if (pfr->saddr) {
  899. shost = pfr->saddr;
  900. } else if (conf_get_bool(conf, CONF_rport_acceptall)) {
  901. shost = "";
  902. } else {
  903. shost = "localhost";
  904. }
  905. pfr->remote = ssh_rportfwd_alloc(
  906. mgr->cl, shost, pfr->sport, pfr->daddr, pfr->dport,
  907. pfr->addressfamily, sportdesc, pfr, NULL);
  908. if (!pfr->remote) {
  909. logeventf(mgr->cl->logctx,
  910. "Duplicate remote port forwarding to %s:%d",
  911. pfr->daddr, pfr->dport);
  912. pfr_free(pfr);
  913. } else {
  914. logeventf(mgr->cl->logctx, "Requesting remote port %s"
  915. " forward to %s", sportdesc, dportdesc);
  916. }
  917. }
  918. sfree(sportdesc);
  919. sfree(dportdesc);
  920. }
  921. }
  922. }
  923. bool portfwdmgr_listen(PortFwdManager *mgr, const char *host, int port,
  924. const char *keyhost, int keyport, Conf *conf)
  925. {
  926. PortFwdRecord *pfr;
  927. pfr = snew(PortFwdRecord);
  928. pfr->type = 'L';
  929. pfr->saddr = host ? dupstr(host) : NULL;
  930. pfr->daddr = keyhost ? dupstr(keyhost) : NULL;
  931. pfr->sserv = pfr->dserv = NULL;
  932. pfr->sport = port;
  933. pfr->dport = keyport;
  934. pfr->local = NULL;
  935. pfr->remote = NULL;
  936. pfr->addressfamily = ADDRTYPE_UNSPEC;
  937. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  938. if (existing != pfr) {
  939. /*
  940. * We had this record already. Return failure.
  941. */
  942. pfr_free(pfr);
  943. return false;
  944. }
  945. char *err = pfl_listen(keyhost, keyport, host, port,
  946. mgr->cl, conf, &pfr->local, pfr->addressfamily);
  947. logeventf(mgr->cl->logctx,
  948. "%s on port %s:%d to forward to client%s%s",
  949. err ? "Failed to listen" : "Listening", host, port,
  950. err ? ": " : "", err ? err : "");
  951. if (err) {
  952. sfree(err);
  953. del234(mgr->forwardings, pfr);
  954. pfr_free(pfr);
  955. return false;
  956. }
  957. return true;
  958. }
  959. bool portfwdmgr_unlisten(PortFwdManager *mgr, const char *host, int port)
  960. {
  961. PortFwdRecord pfr_key;
  962. pfr_key.type = 'L';
  963. /* Safe to cast the const away here, because it will only be used
  964. * by pfr_cmp, which won't write to the string */
  965. pfr_key.saddr = pfr_key.daddr = (char *)host;
  966. pfr_key.sserv = pfr_key.dserv = NULL;
  967. pfr_key.sport = pfr_key.dport = port;
  968. pfr_key.local = NULL;
  969. pfr_key.remote = NULL;
  970. pfr_key.addressfamily = ADDRTYPE_UNSPEC;
  971. PortFwdRecord *pfr = del234(mgr->forwardings, &pfr_key);
  972. if (!pfr)
  973. return false;
  974. logeventf(mgr->cl->logctx, "Closing listening port %s:%d", host, port);
  975. pfr_free(pfr);
  976. return true;
  977. }
  978. /*
  979. * Called when receiving a PORT OPEN from the server to make a
  980. * connection to a destination host.
  981. *
  982. * On success, returns NULL and fills in *pf_ret. On error, returns a
  983. * dynamically allocated error message string.
  984. */
  985. char *portfwdmgr_connect(PortFwdManager *mgr, Channel **chan_ret,
  986. char *hostname, int port, SshChannel *c,
  987. int addressfamily)
  988. {
  989. SockAddr *addr;
  990. const char *err;
  991. char *dummy_realhost = NULL;
  992. struct PortForwarding *pf;
  993. /*
  994. * Try to find host.
  995. */
  996. addr = name_lookup(hostname, port, &dummy_realhost, mgr->conf,
  997. addressfamily, NULL, NULL);
  998. if ((err = sk_addr_error(addr)) != NULL) {
  999. char *err_ret = dupstr(err);
  1000. sk_addr_free(addr);
  1001. sfree(dummy_realhost);
  1002. return err_ret;
  1003. }
  1004. /*
  1005. * Open socket.
  1006. */
  1007. pf = new_portfwd_state();
  1008. *chan_ret = &pf->chan;
  1009. pf->plug.vt = &PortForwarding_plugvt;
  1010. pf->chan.initial_fixed_window_size = 0;
  1011. pf->chan.vt = &PortForwarding_channelvt;
  1012. pf->input_wanted = true;
  1013. pf->ready = true;
  1014. pf->c = c;
  1015. pf->cl = mgr->cl;
  1016. pf->socks_state = SOCKS_NONE;
  1017. pf->s = new_connection(addr, dummy_realhost, port,
  1018. false, true, false, false, &pf->plug, mgr->conf,
  1019. NULL);
  1020. sfree(dummy_realhost);
  1021. if ((err = sk_socket_error(pf->s)) != NULL) {
  1022. char *err_ret = dupstr(err);
  1023. sk_close(pf->s);
  1024. free_portfwd_state(pf);
  1025. *chan_ret = NULL;
  1026. return err_ret;
  1027. }
  1028. return NULL;
  1029. }