portfwd.c 38 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225
  1. /*
  2. * SSH port forwarding.
  3. */
  4. #include <assert.h>
  5. #include <stdio.h>
  6. #include <stdlib.h>
  7. #include "putty.h"
  8. #include "ssh.h"
  9. #include "channel.h"
  10. #include "proxy/socks.h"
  11. /*
  12. * Enumeration of values that live in the 'socks_state' field of
  13. * struct PortForwarding.
  14. */
  15. typedef enum {
  16. SOCKS_NONE, /* direct connection (no SOCKS, or SOCKS already done) */
  17. SOCKS_INITIAL, /* don't know if we're SOCKS 4 or 5 yet */
  18. SOCKS_4, /* expect a SOCKS 4 (or 4A) connection message */
  19. SOCKS_5_INITIAL, /* expect a SOCKS 5 preliminary message */
  20. SOCKS_5_CONNECT /* expect a SOCKS 5 connection message */
  21. } SocksState;
  22. typedef struct PortForwarding {
  23. SshChannel *c; /* channel structure held by SSH connection layer */
  24. ConnectionLayer *cl; /* the connection layer itself */
  25. /* Note that ssh need not be filled in if c is non-NULL */
  26. Socket *s;
  27. bool input_wanted;
  28. bool ready;
  29. SocksState socks_state;
  30. /*
  31. * `hostname' and `port' are the real hostname and port, once
  32. * we know what we're connecting to.
  33. */
  34. char *hostname;
  35. int port;
  36. /*
  37. * `socksbuf' is the buffer we use to accumulate the initial SOCKS
  38. * segment of the incoming data, plus anything after that that we
  39. * receive before we're ready to send data to the SSH server.
  40. */
  41. strbuf *socksbuf;
  42. size_t socksbuf_consumed;
  43. Plug plug;
  44. Channel chan;
  45. } PortForwarding;
  46. struct PortListener {
  47. ConnectionLayer *cl;
  48. Socket *s;
  49. bool is_dynamic;
  50. /*
  51. * `hostname' and `port' are the real hostname and port, for
  52. * ordinary forwardings.
  53. */
  54. char *hostname;
  55. int port;
  56. Plug plug;
  57. };
  58. static struct PortForwarding *new_portfwd_state(void)
  59. {
  60. struct PortForwarding *pf = snew(struct PortForwarding);
  61. pf->hostname = NULL;
  62. pf->socksbuf = NULL;
  63. return pf;
  64. }
  65. static void free_portfwd_state(struct PortForwarding *pf)
  66. {
  67. if (!pf)
  68. return;
  69. sfree(pf->hostname);
  70. if (pf->socksbuf)
  71. strbuf_free(pf->socksbuf);
  72. sfree(pf);
  73. }
  74. static struct PortListener *new_portlistener_state(void)
  75. {
  76. struct PortListener *pl = snew(struct PortListener);
  77. pl->hostname = NULL;
  78. return pl;
  79. }
  80. static void free_portlistener_state(struct PortListener *pl)
  81. {
  82. if (!pl)
  83. return;
  84. sfree(pl->hostname);
  85. sfree(pl);
  86. }
  87. static void pfd_log(Plug *plug, PlugLogType type, SockAddr *addr, int port,
  88. const char *error_msg, int error_code)
  89. {
  90. /* we have to dump these since we have no interface to logging.c */
  91. }
  92. static void pfl_log(Plug *plug, PlugLogType type, SockAddr *addr, int port,
  93. const char *error_msg, int error_code)
  94. {
  95. /* we have to dump these since we have no interface to logging.c */
  96. }
  97. static void pfd_close(struct PortForwarding *pf);
  98. static void pfd_closing(Plug *plug, PlugCloseType type, const char *error_msg)
  99. {
  100. struct PortForwarding *pf =
  101. container_of(plug, struct PortForwarding, plug);
  102. if (type != PLUGCLOSE_NORMAL) {
  103. /*
  104. * Socket error. Slam the connection instantly shut.
  105. */
  106. if (pf->c) {
  107. sshfwd_initiate_close(pf->c, error_msg);
  108. } else {
  109. /*
  110. * We might not have an SSH channel, if a socket error
  111. * occurred during SOCKS negotiation. If not, we must
  112. * clean ourself up without sshfwd_initiate_close's call
  113. * back to pfd_close.
  114. */
  115. pfd_close(pf);
  116. }
  117. } else {
  118. /*
  119. * Ordinary EOF received on socket. Send an EOF on the SSH
  120. * channel.
  121. */
  122. if (pf->c)
  123. sshfwd_write_eof(pf->c);
  124. }
  125. }
  126. static void pfl_terminate(struct PortListener *pl);
  127. static void pfl_closing(Plug *plug, PlugCloseType type, const char *error_msg)
  128. {
  129. struct PortListener *pl = (struct PortListener *) plug;
  130. pfl_terminate(pl);
  131. }
  132. static SshChannel *wrap_lportfwd_open(
  133. ConnectionLayer *cl, const char *hostname, int port,
  134. Socket *s, Channel *chan)
  135. {
  136. SocketPeerInfo *pi;
  137. char *description;
  138. SshChannel *toret;
  139. pi = sk_peer_info(s);
  140. if (pi && pi->log_text) {
  141. description = dupprintf("forwarding from %s", pi->log_text);
  142. } else {
  143. description = dupstr("forwarding");
  144. }
  145. toret = ssh_lportfwd_open(cl, hostname, port, description, pi, chan);
  146. sk_free_peer_info(pi);
  147. sfree(description);
  148. return toret;
  149. }
  150. static char *ipv4_to_string(unsigned ipv4)
  151. {
  152. return dupprintf("%u.%u.%u.%u",
  153. (ipv4 >> 24) & 0xFF, (ipv4 >> 16) & 0xFF,
  154. (ipv4 >> 8) & 0xFF, (ipv4 ) & 0xFF);
  155. }
  156. static char *ipv6_to_string(ptrlen ipv6)
  157. {
  158. const unsigned char *addr = ipv6.ptr;
  159. assert(ipv6.len == 16);
  160. return dupprintf("%04x:%04x:%04x:%04x:%04x:%04x:%04x:%04x",
  161. (unsigned)GET_16BIT_MSB_FIRST(addr + 0),
  162. (unsigned)GET_16BIT_MSB_FIRST(addr + 2),
  163. (unsigned)GET_16BIT_MSB_FIRST(addr + 4),
  164. (unsigned)GET_16BIT_MSB_FIRST(addr + 6),
  165. (unsigned)GET_16BIT_MSB_FIRST(addr + 8),
  166. (unsigned)GET_16BIT_MSB_FIRST(addr + 10),
  167. (unsigned)GET_16BIT_MSB_FIRST(addr + 12),
  168. (unsigned)GET_16BIT_MSB_FIRST(addr + 14));
  169. }
  170. static void pfd_receive(Plug *plug, int urgent, const char *data, size_t len)
  171. {
  172. struct PortForwarding *pf =
  173. container_of(plug, struct PortForwarding, plug);
  174. if (len == 0)
  175. return;
  176. if (pf->socks_state != SOCKS_NONE) {
  177. BinarySource src[1];
  178. /*
  179. * Store all the data we've got in socksbuf.
  180. */
  181. put_data(pf->socksbuf, data, len);
  182. /*
  183. * Check the start of socksbuf to see if it's a valid and
  184. * complete message in the SOCKS exchange.
  185. */
  186. if (pf->socks_state == SOCKS_INITIAL) {
  187. /* Preliminary: check the first byte of the data (which we
  188. * _must_ have by now) to find out which SOCKS major
  189. * version we're speaking. */
  190. switch (pf->socksbuf->u[0]) {
  191. case SOCKS4_REQUEST_VERSION:
  192. pf->socks_state = SOCKS_4;
  193. break;
  194. case SOCKS5_REQUEST_VERSION:
  195. pf->socks_state = SOCKS_5_INITIAL;
  196. break;
  197. default:
  198. pfd_close(pf); /* unrecognised version */
  199. return;
  200. }
  201. }
  202. BinarySource_BARE_INIT(src, pf->socksbuf->u, pf->socksbuf->len);
  203. get_data(src, pf->socksbuf_consumed);
  204. while (pf->socks_state != SOCKS_NONE) {
  205. unsigned socks_version, message_type, reserved_byte;
  206. unsigned reply_code, port, ipv4, method;
  207. ptrlen methods;
  208. const char *socks4_hostname;
  209. strbuf *output;
  210. switch (pf->socks_state) {
  211. case SOCKS_INITIAL:
  212. case SOCKS_NONE:
  213. unreachable("These case values cannot appear");
  214. case SOCKS_4:
  215. /* SOCKS 4/4A connect message */
  216. socks_version = get_byte(src);
  217. message_type = get_byte(src);
  218. if (get_err(src) == BSE_OUT_OF_DATA)
  219. return;
  220. if (socks_version == SOCKS4_REQUEST_VERSION &&
  221. message_type == SOCKS_CMD_CONNECT) {
  222. /* CONNECT message */
  223. bool name_based = false;
  224. port = get_uint16(src);
  225. ipv4 = get_uint32(src);
  226. if (ipv4 >= SOCKS4A_NAME_FOLLOWS_BASE &&
  227. ipv4 < SOCKS4A_NAME_FOLLOWS_LIMIT) {
  228. /*
  229. * Addresses in this range indicate the SOCKS 4A
  230. * extension to specify a hostname, which comes
  231. * after the username.
  232. */
  233. name_based = true;
  234. }
  235. get_asciz(src); /* skip username */
  236. socks4_hostname = name_based ? get_asciz(src) : NULL;
  237. if (get_err(src) == BSE_OUT_OF_DATA)
  238. return;
  239. if (get_err(src))
  240. goto socks4_reject;
  241. pf->port = port;
  242. if (name_based) {
  243. pf->hostname = dupstr(socks4_hostname);
  244. } else {
  245. pf->hostname = ipv4_to_string(ipv4);
  246. }
  247. output = strbuf_new();
  248. put_byte(output, SOCKS4_REPLY_VERSION);
  249. put_byte(output, SOCKS4_RESP_SUCCESS);
  250. put_uint16(output, 0); /* null port field */
  251. put_uint32(output, 0); /* null address field */
  252. sk_write(pf->s, output->u, output->len);
  253. strbuf_free(output);
  254. pf->socks_state = SOCKS_NONE;
  255. pf->socksbuf_consumed = src->pos;
  256. break;
  257. }
  258. socks4_reject:
  259. output = strbuf_new();
  260. put_byte(output, SOCKS4_REPLY_VERSION);
  261. put_byte(output, SOCKS4_RESP_FAILURE);
  262. put_uint16(output, 0); /* null port field */
  263. put_uint32(output, 0); /* null address field */
  264. sk_write(pf->s, output->u, output->len);
  265. strbuf_free(output);
  266. pfd_close(pf);
  267. return;
  268. case SOCKS_5_INITIAL:
  269. /* SOCKS 5 initial method list */
  270. socks_version = get_byte(src);
  271. methods = get_pstring(src);
  272. method = SOCKS5_AUTH_REJECTED;
  273. /* Search the method list for AUTH_NONE, which is the
  274. * only one this client code can speak */
  275. { // WINSCP
  276. size_t i;
  277. for (i = 0; i < methods.len; i++) {
  278. unsigned char this_method =
  279. ((const unsigned char *)methods.ptr)[i];
  280. if (this_method == SOCKS5_AUTH_NONE) {
  281. method = this_method;
  282. break;
  283. }
  284. }
  285. if (get_err(src) == BSE_OUT_OF_DATA)
  286. return;
  287. if (get_err(src))
  288. method = SOCKS5_AUTH_REJECTED;
  289. output = strbuf_new();
  290. put_byte(output, SOCKS5_REPLY_VERSION);
  291. put_byte(output, method);
  292. sk_write(pf->s, output->u, output->len);
  293. strbuf_free(output);
  294. if (method == SOCKS5_AUTH_REJECTED) {
  295. pfd_close(pf);
  296. return;
  297. }
  298. pf->socks_state = SOCKS_5_CONNECT;
  299. pf->socksbuf_consumed = src->pos;
  300. break;
  301. } // WINSCP
  302. case SOCKS_5_CONNECT:
  303. /* SOCKS 5 connect message */
  304. socks_version = get_byte(src);
  305. message_type = get_byte(src);
  306. reserved_byte = get_byte(src);
  307. if (socks_version == SOCKS5_REQUEST_VERSION &&
  308. message_type == SOCKS_CMD_CONNECT &&
  309. reserved_byte == 0) {
  310. reply_code = SOCKS5_RESP_SUCCESS;
  311. switch (get_byte(src)) {
  312. case SOCKS5_ADDR_IPV4:
  313. pf->hostname = ipv4_to_string(get_uint32(src));
  314. break;
  315. case SOCKS5_ADDR_IPV6:
  316. pf->hostname = ipv6_to_string(get_data(src, 16));
  317. break;
  318. case SOCKS5_ADDR_HOSTNAME:
  319. pf->hostname = mkstr(get_pstring(src));
  320. break;
  321. default:
  322. pf->hostname = NULL;
  323. reply_code = SOCKS5_RESP_ADDRTYPE_NOT_SUPPORTED;
  324. break;
  325. }
  326. pf->port = get_uint16(src);
  327. } else {
  328. reply_code = SOCKS5_RESP_COMMAND_NOT_SUPPORTED;
  329. }
  330. if (get_err(src) == BSE_OUT_OF_DATA)
  331. return;
  332. if (get_err(src))
  333. reply_code = SOCKS5_RESP_FAILURE;
  334. output = strbuf_new();
  335. put_byte(output, SOCKS5_REPLY_VERSION);
  336. put_byte(output, reply_code);
  337. put_byte(output, 0); /* reserved */
  338. put_byte(output, SOCKS5_ADDR_IPV4); /* IPv4 address follows */
  339. put_uint32(output, 0); /* bound IPv4 address (unused) */
  340. put_uint16(output, 0); /* bound port number (unused) */
  341. sk_write(pf->s, output->u, output->len);
  342. strbuf_free(output);
  343. if (reply_code != SOCKS5_RESP_SUCCESS) {
  344. pfd_close(pf);
  345. return;
  346. }
  347. pf->socks_state = SOCKS_NONE;
  348. pf->socksbuf_consumed = src->pos;
  349. break;
  350. }
  351. }
  352. /*
  353. * We come here when we're ready to make an actual
  354. * connection.
  355. */
  356. /*
  357. * Freeze the socket until the SSH server confirms the
  358. * connection.
  359. */
  360. sk_set_frozen(pf->s, true);
  361. pf->c = wrap_lportfwd_open(pf->cl, pf->hostname, pf->port, pf->s,
  362. &pf->chan);
  363. }
  364. if (pf->ready)
  365. sshfwd_write(pf->c, data, len);
  366. }
  367. static void pfd_sent(Plug *plug, size_t bufsize)
  368. {
  369. struct PortForwarding *pf =
  370. container_of(plug, struct PortForwarding, plug);
  371. if (pf->c)
  372. sshfwd_unthrottle(pf->c, bufsize);
  373. }
  374. static const PlugVtable PortForwarding_plugvt = {
  375. // WINSCP
  376. /*.log =*/ pfd_log,
  377. /*.closing =*/ pfd_closing,
  378. /*.receive =*/ pfd_receive,
  379. /*.sent =*/ pfd_sent,
  380. NULL,
  381. };
  382. static void pfd_chan_free(Channel *chan);
  383. static void pfd_open_confirmation(Channel *chan);
  384. static void pfd_open_failure(Channel *chan, const char *errtext);
  385. static size_t pfd_send(
  386. Channel *chan, bool is_stderr, const void *data, size_t len);
  387. static void pfd_send_eof(Channel *chan);
  388. static void pfd_set_input_wanted(Channel *chan, bool wanted);
  389. static char *pfd_log_close_msg(Channel *chan);
  390. static const ChannelVtable PortForwarding_channelvt = {
  391. // WINSCP
  392. /*.free =*/ pfd_chan_free,
  393. /*.open_confirmation =*/ pfd_open_confirmation,
  394. /*.open_failed =*/ pfd_open_failure,
  395. /*.send =*/ pfd_send,
  396. /*.send_eof =*/ pfd_send_eof,
  397. /*.set_input_wanted =*/ pfd_set_input_wanted,
  398. /*.log_close_msg =*/ pfd_log_close_msg,
  399. /*.want_close =*/ chan_default_want_close,
  400. /*.rcvd_exit_status =*/ chan_no_exit_status,
  401. /*.rcvd_exit_signal =*/ chan_no_exit_signal,
  402. /*.rcvd_exit_signal_numeric =*/ chan_no_exit_signal_numeric,
  403. /*.run_shell =*/ chan_no_run_shell,
  404. /*.run_command =*/ chan_no_run_command,
  405. /*.run_subsystem =*/ chan_no_run_subsystem,
  406. /*.enable_x11_forwarding =*/ chan_no_enable_x11_forwarding,
  407. /*.enable_agent_forwarding =*/ chan_no_enable_agent_forwarding,
  408. /*.allocate_pty =*/ chan_no_allocate_pty,
  409. /*.set_env =*/ chan_no_set_env,
  410. /*.send_break =*/ chan_no_send_break,
  411. /*.send_signal =*/ chan_no_send_signal,
  412. /*.change_window_size =*/ chan_no_change_window_size,
  413. /*.request_response =*/ chan_no_request_response,
  414. };
  415. Channel *portfwd_raw_new(ConnectionLayer *cl, Plug **plug, bool start_ready)
  416. {
  417. struct PortForwarding *pf;
  418. pf = new_portfwd_state();
  419. pf->plug.vt = &PortForwarding_plugvt;
  420. pf->chan.initial_fixed_window_size = 0;
  421. pf->chan.vt = &PortForwarding_channelvt;
  422. pf->input_wanted = true;
  423. pf->c = NULL;
  424. pf->cl = cl;
  425. pf->input_wanted = true;
  426. pf->ready = start_ready;
  427. pf->socks_state = SOCKS_NONE;
  428. pf->hostname = NULL;
  429. pf->port = 0;
  430. *plug = &pf->plug;
  431. return &pf->chan;
  432. }
  433. void portfwd_raw_free(Channel *pfchan)
  434. {
  435. struct PortForwarding *pf;
  436. assert(pfchan->vt == &PortForwarding_channelvt);
  437. pf = container_of(pfchan, struct PortForwarding, chan);
  438. free_portfwd_state(pf);
  439. }
  440. void portfwd_raw_setup(Channel *pfchan, Socket *s, SshChannel *sc)
  441. {
  442. struct PortForwarding *pf;
  443. assert(pfchan->vt == &PortForwarding_channelvt);
  444. pf = container_of(pfchan, struct PortForwarding, chan);
  445. pf->s = s;
  446. pf->c = sc;
  447. }
  448. /*
  449. * called when someone connects to the local port
  450. */
  451. static int pfl_accepting(Plug *p, accept_fn_t constructor, accept_ctx_t ctx)
  452. {
  453. struct PortListener *pl = container_of(p, struct PortListener, plug);
  454. struct PortForwarding *pf;
  455. Channel *chan;
  456. Plug *plug;
  457. Socket *s;
  458. const char *err;
  459. chan = portfwd_raw_new(pl->cl, &plug, false);
  460. s = constructor(ctx, plug);
  461. if ((err = sk_socket_error(s)) != NULL) {
  462. portfwd_raw_free(chan);
  463. return 1;
  464. }
  465. pf = container_of(chan, struct PortForwarding, chan);
  466. if (pl->is_dynamic) {
  467. pf->s = s;
  468. pf->socks_state = SOCKS_INITIAL;
  469. pf->socksbuf = strbuf_new();
  470. pf->socksbuf_consumed = 0;
  471. pf->port = 0; /* "hostname" buffer is so far empty */
  472. sk_set_frozen(s, false); /* we want to receive SOCKS _now_! */
  473. } else {
  474. pf->hostname = dupstr(pl->hostname);
  475. pf->port = pl->port;
  476. portfwd_raw_setup(
  477. chan, s,
  478. wrap_lportfwd_open(pl->cl, pf->hostname, pf->port, s, &pf->chan));
  479. }
  480. return 0;
  481. }
  482. static const PlugVtable PortListener_plugvt = {
  483. // WINSCP
  484. /*.log =*/ pfl_log,
  485. /*.closing =*/ pfl_closing,
  486. NULL,
  487. NULL,
  488. /*.accepting =*/ pfl_accepting,
  489. };
  490. /*
  491. * Add a new port-forwarding listener from srcaddr:port -> desthost:destport.
  492. *
  493. * desthost == NULL indicates dynamic SOCKS port forwarding.
  494. *
  495. * On success, returns NULL and fills in *pl_ret. On error, returns a
  496. * dynamically allocated error message string.
  497. */
  498. static char *pfl_listen(const char *desthost, int destport,
  499. const char *srcaddr, int port,
  500. ConnectionLayer *cl, Conf *conf,
  501. struct PortListener **pl_ret, int address_family)
  502. {
  503. const char *err;
  504. struct PortListener *pl;
  505. /*
  506. * Open socket.
  507. */
  508. pl = *pl_ret = new_portlistener_state();
  509. pl->plug.vt = &PortListener_plugvt;
  510. if (desthost) {
  511. pl->hostname = dupstr(desthost);
  512. pl->port = destport;
  513. pl->is_dynamic = false;
  514. } else
  515. pl->is_dynamic = true;
  516. pl->cl = cl;
  517. pl->s = new_listener(srcaddr, port, &pl->plug,
  518. !conf_get_bool(conf, CONF_lport_acceptall),
  519. conf, address_family);
  520. if ((err = sk_socket_error(pl->s)) != NULL) {
  521. char *err_ret = dupstr(err);
  522. sk_close(pl->s);
  523. free_portlistener_state(pl);
  524. *pl_ret = NULL;
  525. return err_ret;
  526. }
  527. return NULL;
  528. }
  529. static char *pfd_log_close_msg(Channel *chan)
  530. {
  531. return dupstr("Forwarded port closed");
  532. }
  533. static void pfd_close(struct PortForwarding *pf)
  534. {
  535. if (!pf)
  536. return;
  537. sk_close(pf->s);
  538. free_portfwd_state(pf);
  539. }
  540. /*
  541. * Terminate a listener.
  542. */
  543. static void pfl_terminate(struct PortListener *pl)
  544. {
  545. if (!pl)
  546. return;
  547. sk_close(pl->s);
  548. free_portlistener_state(pl);
  549. }
  550. static void pfd_set_input_wanted(Channel *chan, bool wanted)
  551. {
  552. pinitassert(chan->vt == &PortForwarding_channelvt);
  553. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  554. pf->input_wanted = wanted;
  555. sk_set_frozen(pf->s, !pf->input_wanted);
  556. }
  557. static void pfd_chan_free(Channel *chan)
  558. {
  559. pinitassert(chan->vt == &PortForwarding_channelvt);
  560. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  561. pfd_close(pf);
  562. }
  563. /*
  564. * Called to send data down the raw connection.
  565. */
  566. static size_t pfd_send(
  567. Channel *chan, bool is_stderr, const void *data, size_t len)
  568. {
  569. pinitassert(chan->vt == &PortForwarding_channelvt);
  570. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  571. return sk_write(pf->s, data, len);
  572. }
  573. static void pfd_send_eof(Channel *chan)
  574. {
  575. pinitassert(chan->vt == &PortForwarding_channelvt);
  576. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  577. sk_write_eof(pf->s);
  578. }
  579. static void pfd_open_confirmation(Channel *chan)
  580. {
  581. pinitassert(chan->vt == &PortForwarding_channelvt);
  582. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  583. pf->ready = true;
  584. sk_set_frozen(pf->s, false);
  585. sk_write(pf->s, NULL, 0);
  586. if (pf->socksbuf) {
  587. sshfwd_write(pf->c, pf->socksbuf->u + pf->socksbuf_consumed,
  588. pf->socksbuf->len - pf->socksbuf_consumed);
  589. strbuf_free(pf->socksbuf);
  590. pf->socksbuf = NULL;
  591. }
  592. }
  593. static void pfd_open_failure(Channel *chan, const char *errtext)
  594. {
  595. pinitassert(chan->vt == &PortForwarding_channelvt);
  596. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  597. logeventf(pf->cl->logctx,
  598. "Forwarded connection refused by remote%s%s",
  599. errtext ? ": " : "", errtext ? errtext : "");
  600. }
  601. /* ----------------------------------------------------------------------
  602. * Code to manage the complete set of currently active port
  603. * forwardings, and update it from Conf.
  604. */
  605. struct PortFwdRecord {
  606. enum { DESTROY, KEEP, CREATE } status;
  607. int type;
  608. unsigned sport, dport;
  609. char *saddr, *daddr;
  610. char *sserv, *dserv;
  611. struct ssh_rportfwd *remote;
  612. int addressfamily;
  613. struct PortListener *local;
  614. };
  615. static int pfr_cmp(void *av, void *bv)
  616. {
  617. PortFwdRecord *a = (PortFwdRecord *) av;
  618. PortFwdRecord *b = (PortFwdRecord *) bv;
  619. int i;
  620. if (a->type > b->type)
  621. return +1;
  622. if (a->type < b->type)
  623. return -1;
  624. if (a->addressfamily > b->addressfamily)
  625. return +1;
  626. if (a->addressfamily < b->addressfamily)
  627. return -1;
  628. if ( (i = nullstrcmp(a->saddr, b->saddr)) != 0)
  629. return i < 0 ? -1 : +1;
  630. if (a->sport > b->sport)
  631. return +1;
  632. if (a->sport < b->sport)
  633. return -1;
  634. if (a->type != 'D') {
  635. if ( (i = nullstrcmp(a->daddr, b->daddr)) != 0)
  636. return i < 0 ? -1 : +1;
  637. if (a->dport > b->dport)
  638. return +1;
  639. if (a->dport < b->dport)
  640. return -1;
  641. }
  642. return 0;
  643. }
  644. static void pfr_free(PortFwdRecord *pfr)
  645. {
  646. /* Dispose of any listening socket. */
  647. if (pfr->local)
  648. pfl_terminate(pfr->local);
  649. sfree(pfr->saddr);
  650. sfree(pfr->daddr);
  651. sfree(pfr->sserv);
  652. sfree(pfr->dserv);
  653. sfree(pfr);
  654. }
  655. struct PortFwdManager {
  656. ConnectionLayer *cl;
  657. Conf *conf;
  658. tree234 *forwardings;
  659. };
  660. PortFwdManager *portfwdmgr_new(ConnectionLayer *cl)
  661. {
  662. PortFwdManager *mgr = snew(PortFwdManager);
  663. mgr->cl = cl;
  664. mgr->conf = NULL;
  665. mgr->forwardings = newtree234(pfr_cmp);
  666. return mgr;
  667. }
  668. void portfwdmgr_close(PortFwdManager *mgr, PortFwdRecord *pfr)
  669. {
  670. PortFwdRecord *realpfr = del234(mgr->forwardings, pfr);
  671. if (realpfr == pfr)
  672. pfr_free(pfr);
  673. }
  674. void portfwdmgr_close_all(PortFwdManager *mgr)
  675. {
  676. PortFwdRecord *pfr;
  677. while ((pfr = delpos234(mgr->forwardings, 0)) != NULL)
  678. pfr_free(pfr);
  679. }
  680. void portfwdmgr_free(PortFwdManager *mgr)
  681. {
  682. portfwdmgr_close_all(mgr);
  683. freetree234(mgr->forwardings);
  684. if (mgr->conf)
  685. conf_free(mgr->conf);
  686. sfree(mgr);
  687. }
  688. void portfwdmgr_config(PortFwdManager *mgr, Conf *conf)
  689. {
  690. PortFwdRecord *pfr;
  691. int i;
  692. char *key, *val;
  693. if (mgr->conf)
  694. conf_free(mgr->conf);
  695. mgr->conf = conf_copy(conf);
  696. /*
  697. * Go through the existing port forwardings and tag them
  698. * with status==DESTROY. Any that we want to keep will be
  699. * re-enabled (status==KEEP) as we go through the
  700. * configuration and find out which bits are the same as
  701. * they were before.
  702. */
  703. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++)
  704. pfr->status = DESTROY;
  705. for (val = conf_get_str_strs(conf, CONF_portfwd, NULL, &key);
  706. val != NULL;
  707. val = conf_get_str_strs(conf, CONF_portfwd, key, &key)) {
  708. char *kp, *kp2, *vp, *vp2;
  709. char address_family, type;
  710. int sport, dport, sserv, dserv;
  711. char *sports, *dports, *saddr, *host;
  712. kp = key;
  713. address_family = 'A';
  714. type = 'L';
  715. if (*kp == 'A' || *kp == '4' || *kp == '6')
  716. address_family = *kp++;
  717. if (*kp == 'L' || *kp == 'R')
  718. type = *kp++;
  719. if ((kp2 = host_strchr(kp, ':')) != NULL) {
  720. /*
  721. * There's a colon in the middle of the source port
  722. * string, which means that the part before it is
  723. * actually a source address.
  724. */
  725. char *saddr_tmp = dupprintf("%.*s", (int)(kp2 - kp), kp);
  726. saddr = host_strduptrim(saddr_tmp);
  727. sfree(saddr_tmp);
  728. sports = kp2+1;
  729. } else {
  730. saddr = NULL;
  731. sports = kp;
  732. }
  733. sport = atoi(sports);
  734. sserv = 0;
  735. if (sport == 0) {
  736. sserv = 1;
  737. sport = net_service_lookup(sports);
  738. if (!sport) {
  739. logeventf(mgr->cl->logctx, "Service lookup failed for source"
  740. " port \"%s\"", sports);
  741. }
  742. }
  743. if (type == 'L' && !strcmp(val, "D")) {
  744. /* dynamic forwarding */
  745. host = NULL;
  746. dports = NULL;
  747. dport = -1;
  748. dserv = 0;
  749. type = 'D';
  750. } else {
  751. /* ordinary forwarding */
  752. vp = val;
  753. vp2 = vp + host_strcspn(vp, ":");
  754. host = dupprintf("%.*s", (int)(vp2 - vp), vp);
  755. if (*vp2)
  756. vp2++;
  757. dports = vp2;
  758. dport = atoi(dports);
  759. dserv = 0;
  760. if (dport == 0) {
  761. dserv = 1;
  762. dport = net_service_lookup(dports);
  763. if (!dport) {
  764. logeventf(mgr->cl->logctx,
  765. "Service lookup failed for destination"
  766. " port \"%s\"", dports);
  767. }
  768. }
  769. }
  770. if (sport && dport) {
  771. /* Set up a description of the source port. */
  772. pfr = snew(PortFwdRecord);
  773. pfr->type = type;
  774. pfr->saddr = saddr;
  775. pfr->sserv = sserv ? dupstr(sports) : NULL;
  776. pfr->sport = sport;
  777. pfr->daddr = host;
  778. pfr->dserv = dserv ? dupstr(dports) : NULL;
  779. pfr->dport = dport;
  780. pfr->local = NULL;
  781. pfr->remote = NULL;
  782. pfr->addressfamily = (address_family == '4' ? ADDRTYPE_IPV4 :
  783. address_family == '6' ? ADDRTYPE_IPV6 :
  784. ADDRTYPE_UNSPEC);
  785. { // WINSCP
  786. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  787. if (existing != pfr) {
  788. if (existing->status == DESTROY) {
  789. /*
  790. * We already have a port forwarding up and running
  791. * with precisely these parameters. Hence, no need
  792. * to do anything; simply re-tag the existing one
  793. * as KEEP.
  794. */
  795. existing->status = KEEP;
  796. }
  797. /*
  798. * Anything else indicates that there was a duplicate
  799. * in our input, which we'll silently ignore.
  800. */
  801. pfr_free(pfr);
  802. } else {
  803. pfr->status = CREATE;
  804. }
  805. } // WINSCP
  806. } else {
  807. sfree(saddr);
  808. sfree(host);
  809. }
  810. }
  811. /*
  812. * Now go through and destroy any port forwardings which were
  813. * not re-enabled.
  814. */
  815. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  816. if (pfr->status == DESTROY) {
  817. char *message;
  818. message = dupprintf("%s port forwarding from %s%s%d",
  819. pfr->type == 'L' ? "local" :
  820. pfr->type == 'R' ? "remote" : "dynamic",
  821. pfr->saddr ? pfr->saddr : "",
  822. pfr->saddr ? ":" : "",
  823. pfr->sport);
  824. if (pfr->type != 'D') {
  825. char *msg2 = dupprintf("%s to %s:%d", message,
  826. pfr->daddr, pfr->dport);
  827. sfree(message);
  828. message = msg2;
  829. }
  830. logeventf(mgr->cl->logctx, "Cancelling %s", message);
  831. sfree(message);
  832. /* pfr->remote or pfr->local may be NULL if setting up a
  833. * forwarding failed. */
  834. if (pfr->remote) {
  835. /*
  836. * Cancel the port forwarding at the server
  837. * end.
  838. *
  839. * Actually closing the listening port on the server
  840. * side may fail - because in SSH-1 there's no message
  841. * in the protocol to request it!
  842. *
  843. * Instead, we simply remove the record of the
  844. * forwarding from our local end, so that any
  845. * connections the server tries to make on it are
  846. * rejected.
  847. */
  848. ssh_rportfwd_remove(mgr->cl, pfr->remote);
  849. pfr->remote = NULL;
  850. } else if (pfr->local) {
  851. pfl_terminate(pfr->local);
  852. pfr->local = NULL;
  853. }
  854. delpos234(mgr->forwardings, i);
  855. pfr_free(pfr);
  856. i--; /* so we don't skip one in the list */
  857. }
  858. }
  859. /*
  860. * And finally, set up any new port forwardings (status==CREATE).
  861. */
  862. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  863. if (pfr->status == CREATE) {
  864. char *sportdesc, *dportdesc;
  865. sportdesc = dupprintf("%s%s%s%s%d%s",
  866. pfr->saddr ? pfr->saddr : "",
  867. pfr->saddr ? ":" : "",
  868. pfr->sserv ? pfr->sserv : "",
  869. pfr->sserv ? "(" : "",
  870. pfr->sport,
  871. pfr->sserv ? ")" : "");
  872. if (pfr->type == 'D') {
  873. dportdesc = NULL;
  874. } else {
  875. dportdesc = dupprintf("%s:%s%s%d%s",
  876. pfr->daddr,
  877. pfr->dserv ? pfr->dserv : "",
  878. pfr->dserv ? "(" : "",
  879. pfr->dport,
  880. pfr->dserv ? ")" : "");
  881. }
  882. if (pfr->type == 'L') {
  883. char *err = pfl_listen(pfr->daddr, pfr->dport,
  884. pfr->saddr, pfr->sport,
  885. mgr->cl, conf, &pfr->local,
  886. pfr->addressfamily);
  887. logeventf(mgr->cl->logctx,
  888. "Local %sport %s forwarding to %s%s%s",
  889. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  890. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  891. sportdesc, dportdesc,
  892. err ? " failed: " : "", err ? err : "");
  893. if (err)
  894. sfree(err);
  895. } else if (pfr->type == 'D') {
  896. char *err = pfl_listen(NULL, -1, pfr->saddr, pfr->sport,
  897. mgr->cl, conf, &pfr->local,
  898. pfr->addressfamily);
  899. logeventf(mgr->cl->logctx,
  900. "Local %sport %s SOCKS dynamic forwarding%s%s",
  901. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  902. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  903. sportdesc,
  904. err ? " failed: " : "", err ? err : "");
  905. if (err)
  906. sfree(err);
  907. } else {
  908. const char *shost;
  909. if (pfr->saddr) {
  910. shost = pfr->saddr;
  911. } else if (conf_get_bool(conf, CONF_rport_acceptall)) {
  912. shost = "";
  913. } else {
  914. shost = "localhost";
  915. }
  916. pfr->remote = ssh_rportfwd_alloc(
  917. mgr->cl, shost, pfr->sport, pfr->daddr, pfr->dport,
  918. pfr->addressfamily, sportdesc, pfr, NULL);
  919. if (!pfr->remote) {
  920. logeventf(mgr->cl->logctx,
  921. "Duplicate remote port forwarding to %s:%d",
  922. pfr->daddr, pfr->dport);
  923. pfr_free(pfr);
  924. } else {
  925. logeventf(mgr->cl->logctx, "Requesting remote port %s"
  926. " forward to %s", sportdesc, dportdesc);
  927. }
  928. }
  929. sfree(sportdesc);
  930. sfree(dportdesc);
  931. }
  932. }
  933. }
  934. bool portfwdmgr_listen(PortFwdManager *mgr, const char *host, int port,
  935. const char *keyhost, int keyport, Conf *conf)
  936. {
  937. PortFwdRecord *pfr;
  938. pfr = snew(PortFwdRecord);
  939. pfr->type = 'L';
  940. pfr->saddr = host ? dupstr(host) : NULL;
  941. pfr->daddr = keyhost ? dupstr(keyhost) : NULL;
  942. pfr->sserv = pfr->dserv = NULL;
  943. pfr->sport = port;
  944. pfr->dport = keyport;
  945. pfr->local = NULL;
  946. pfr->remote = NULL;
  947. pfr->addressfamily = ADDRTYPE_UNSPEC;
  948. { // WINSCP
  949. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  950. if (existing != pfr) {
  951. /*
  952. * We had this record already. Return failure.
  953. */
  954. pfr_free(pfr);
  955. return false;
  956. }
  957. } // WINSCP
  958. { // WINSCP
  959. char *err = pfl_listen(keyhost, keyport, host, port,
  960. mgr->cl, conf, &pfr->local, pfr->addressfamily);
  961. logeventf(mgr->cl->logctx,
  962. "%s on port %s:%d to forward to client%s%s",
  963. err ? "Failed to listen" : "Listening", host, port,
  964. err ? ": " : "", err ? err : "");
  965. if (err) {
  966. sfree(err);
  967. del234(mgr->forwardings, pfr);
  968. pfr_free(pfr);
  969. return false;
  970. }
  971. } // WINSCP
  972. return true;
  973. }
  974. bool portfwdmgr_unlisten(PortFwdManager *mgr, const char *host, int port)
  975. {
  976. PortFwdRecord pfr_key;
  977. pfr_key.type = 'L';
  978. /* Safe to cast the const away here, because it will only be used
  979. * by pfr_cmp, which won't write to the string */
  980. pfr_key.saddr = pfr_key.daddr = (char *)host;
  981. pfr_key.sserv = pfr_key.dserv = NULL;
  982. pfr_key.sport = pfr_key.dport = port;
  983. pfr_key.local = NULL;
  984. pfr_key.remote = NULL;
  985. pfr_key.addressfamily = ADDRTYPE_UNSPEC;
  986. { // WINSCP
  987. PortFwdRecord *pfr = del234(mgr->forwardings, &pfr_key);
  988. if (!pfr)
  989. return false;
  990. logeventf(mgr->cl->logctx, "Closing listening port %s:%d", host, port);
  991. pfr_free(pfr);
  992. } // WINSCP
  993. return true;
  994. }
  995. /*
  996. * Called when receiving a PORT OPEN from the server to make a
  997. * connection to a destination host.
  998. *
  999. * On success, returns NULL and fills in *pf_ret. On error, returns a
  1000. * dynamically allocated error message string.
  1001. */
  1002. char *portfwdmgr_connect(PortFwdManager *mgr, Channel **chan_ret,
  1003. char *hostname, int port, SshChannel *c,
  1004. int addressfamily)
  1005. {
  1006. SockAddr *addr;
  1007. const char *err;
  1008. char *dummy_realhost = NULL;
  1009. struct PortForwarding *pf;
  1010. /*
  1011. * Try to find host.
  1012. */
  1013. addr = name_lookup(hostname, port, &dummy_realhost, mgr->conf,
  1014. addressfamily, NULL, NULL);
  1015. if ((err = sk_addr_error(addr)) != NULL) {
  1016. char *err_ret = dupstr(err);
  1017. sk_addr_free(addr);
  1018. sfree(dummy_realhost);
  1019. return err_ret;
  1020. }
  1021. /*
  1022. * Open socket.
  1023. */
  1024. pf = new_portfwd_state();
  1025. *chan_ret = &pf->chan;
  1026. pf->plug.vt = &PortForwarding_plugvt;
  1027. pf->chan.initial_fixed_window_size = 0;
  1028. pf->chan.vt = &PortForwarding_channelvt;
  1029. pf->input_wanted = true;
  1030. pf->ready = true;
  1031. pf->c = c;
  1032. pf->cl = mgr->cl;
  1033. pf->socks_state = SOCKS_NONE;
  1034. pf->s = new_connection(addr, dummy_realhost, port,
  1035. false, true, false, false, &pf->plug, mgr->conf,
  1036. NULL);
  1037. sfree(dummy_realhost);
  1038. if ((err = sk_socket_error(pf->s)) != NULL) {
  1039. char *err_ret = dupstr(err);
  1040. sk_close(pf->s);
  1041. free_portfwd_state(pf);
  1042. *chan_ret = NULL;
  1043. return err_ret;
  1044. }
  1045. return NULL;
  1046. }
  1047. #ifdef MPEXT
  1048. #include "puttyexp.h"
  1049. int is_pfwd(Plug * plug)
  1050. {
  1051. return
  1052. (plug->vt->closing == pfd_closing) ||
  1053. (plug->vt->closing == pfl_closing);
  1054. }
  1055. Seat * get_pfwd_seat(Plug * plug)
  1056. {
  1057. LogContext * logctx;
  1058. if (plug->vt->closing == pfl_closing)
  1059. {
  1060. struct PortListener *pl = container_of(plug, struct PortListener, plug);
  1061. logctx = pl->cl->logctx;
  1062. }
  1063. else if (plug->vt->closing == pfd_closing)
  1064. {
  1065. struct PortForwarding *pf = container_of(plug, struct PortForwarding, plug);
  1066. logctx = pf->cl->logctx;
  1067. }
  1068. return get_log_seat(logctx);
  1069. }
  1070. #endif