portfwd.c 38 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217
  1. /*
  2. * SSH port forwarding.
  3. */
  4. #include <assert.h>
  5. #include <stdio.h>
  6. #include <stdlib.h>
  7. #include "putty.h"
  8. #include "ssh.h"
  9. #include "sshchan.h"
  10. /*
  11. * Enumeration of values that live in the 'socks_state' field of
  12. * struct PortForwarding.
  13. */
  14. typedef enum {
  15. SOCKS_NONE, /* direct connection (no SOCKS, or SOCKS already done) */
  16. SOCKS_INITIAL, /* don't know if we're SOCKS 4 or 5 yet */
  17. SOCKS_4, /* expect a SOCKS 4 (or 4A) connection message */
  18. SOCKS_5_INITIAL, /* expect a SOCKS 5 preliminary message */
  19. SOCKS_5_CONNECT /* expect a SOCKS 5 connection message */
  20. } SocksState;
  21. typedef struct PortForwarding {
  22. SshChannel *c; /* channel structure held by SSH connection layer */
  23. ConnectionLayer *cl; /* the connection layer itself */
  24. /* Note that ssh need not be filled in if c is non-NULL */
  25. Socket *s;
  26. bool input_wanted;
  27. bool ready;
  28. SocksState socks_state;
  29. /*
  30. * `hostname' and `port' are the real hostname and port, once
  31. * we know what we're connecting to.
  32. */
  33. char *hostname;
  34. int port;
  35. /*
  36. * `socksbuf' is the buffer we use to accumulate the initial SOCKS
  37. * segment of the incoming data, plus anything after that that we
  38. * receive before we're ready to send data to the SSH server.
  39. */
  40. strbuf *socksbuf;
  41. size_t socksbuf_consumed;
  42. Plug plug;
  43. Channel chan;
  44. } PortForwarding;
  45. struct PortListener {
  46. ConnectionLayer *cl;
  47. Socket *s;
  48. bool is_dynamic;
  49. /*
  50. * `hostname' and `port' are the real hostname and port, for
  51. * ordinary forwardings.
  52. */
  53. char *hostname;
  54. int port;
  55. Plug plug;
  56. };
  57. static struct PortForwarding *new_portfwd_state(void)
  58. {
  59. struct PortForwarding *pf = snew(struct PortForwarding);
  60. pf->hostname = NULL;
  61. pf->socksbuf = NULL;
  62. return pf;
  63. }
  64. static void free_portfwd_state(struct PortForwarding *pf)
  65. {
  66. if (!pf)
  67. return;
  68. sfree(pf->hostname);
  69. if (pf->socksbuf)
  70. strbuf_free(pf->socksbuf);
  71. sfree(pf);
  72. }
  73. static struct PortListener *new_portlistener_state(void)
  74. {
  75. struct PortListener *pl = snew(struct PortListener);
  76. pl->hostname = NULL;
  77. return pl;
  78. }
  79. static void free_portlistener_state(struct PortListener *pl)
  80. {
  81. if (!pl)
  82. return;
  83. sfree(pl->hostname);
  84. sfree(pl);
  85. }
  86. static void pfd_log(Plug *plug, PlugLogType type, SockAddr *addr, int port,
  87. const char *error_msg, int error_code)
  88. {
  89. /* we have to dump these since we have no interface to logging.c */
  90. }
  91. static void pfl_log(Plug *plug, PlugLogType type, SockAddr *addr, int port,
  92. const char *error_msg, int error_code)
  93. {
  94. /* we have to dump these since we have no interface to logging.c */
  95. }
  96. static void pfd_close(struct PortForwarding *pf);
  97. static void pfd_closing(Plug *plug, const char *error_msg, int error_code,
  98. bool calling_back)
  99. {
  100. struct PortForwarding *pf =
  101. container_of(plug, struct PortForwarding, plug);
  102. if (error_msg) {
  103. /*
  104. * Socket error. Slam the connection instantly shut.
  105. */
  106. if (pf->c) {
  107. sshfwd_initiate_close(pf->c, error_msg);
  108. } else {
  109. /*
  110. * We might not have an SSH channel, if a socket error
  111. * occurred during SOCKS negotiation. If not, we must
  112. * clean ourself up without sshfwd_initiate_close's call
  113. * back to pfd_close.
  114. */
  115. pfd_close(pf);
  116. }
  117. } else {
  118. /*
  119. * Ordinary EOF received on socket. Send an EOF on the SSH
  120. * channel.
  121. */
  122. if (pf->c)
  123. sshfwd_write_eof(pf->c);
  124. }
  125. }
  126. static void pfl_terminate(struct PortListener *pl);
  127. static void pfl_closing(Plug *plug, const char *error_msg, int error_code,
  128. bool calling_back)
  129. {
  130. struct PortListener *pl = (struct PortListener *) plug;
  131. pfl_terminate(pl);
  132. }
  133. static SshChannel *wrap_lportfwd_open(
  134. ConnectionLayer *cl, const char *hostname, int port,
  135. Socket *s, Channel *chan)
  136. {
  137. SocketPeerInfo *pi;
  138. char *description;
  139. SshChannel *toret;
  140. pi = sk_peer_info(s);
  141. if (pi && pi->log_text) {
  142. description = dupprintf("forwarding from %s", pi->log_text);
  143. } else {
  144. description = dupstr("forwarding");
  145. }
  146. toret = ssh_lportfwd_open(cl, hostname, port, description, pi, chan);
  147. sk_free_peer_info(pi);
  148. sfree(description);
  149. return toret;
  150. }
  151. static char *ipv4_to_string(unsigned ipv4)
  152. {
  153. return dupprintf("%u.%u.%u.%u",
  154. (ipv4 >> 24) & 0xFF, (ipv4 >> 16) & 0xFF,
  155. (ipv4 >> 8) & 0xFF, (ipv4 ) & 0xFF);
  156. }
  157. static char *ipv6_to_string(ptrlen ipv6)
  158. {
  159. const unsigned char *addr = ipv6.ptr;
  160. assert(ipv6.len == 16);
  161. return dupprintf("%04x:%04x:%04x:%04x:%04x:%04x:%04x:%04x",
  162. (unsigned)GET_16BIT_MSB_FIRST(addr + 0),
  163. (unsigned)GET_16BIT_MSB_FIRST(addr + 2),
  164. (unsigned)GET_16BIT_MSB_FIRST(addr + 4),
  165. (unsigned)GET_16BIT_MSB_FIRST(addr + 6),
  166. (unsigned)GET_16BIT_MSB_FIRST(addr + 8),
  167. (unsigned)GET_16BIT_MSB_FIRST(addr + 10),
  168. (unsigned)GET_16BIT_MSB_FIRST(addr + 12),
  169. (unsigned)GET_16BIT_MSB_FIRST(addr + 14));
  170. }
  171. static void pfd_receive(Plug *plug, int urgent, const char *data, size_t len)
  172. {
  173. struct PortForwarding *pf =
  174. container_of(plug, struct PortForwarding, plug);
  175. if (len == 0)
  176. return;
  177. if (pf->socks_state != SOCKS_NONE) {
  178. BinarySource src[1];
  179. /*
  180. * Store all the data we've got in socksbuf.
  181. */
  182. put_data(pf->socksbuf, data, len);
  183. /*
  184. * Check the start of socksbuf to see if it's a valid and
  185. * complete message in the SOCKS exchange.
  186. */
  187. if (pf->socks_state == SOCKS_INITIAL) {
  188. /* Preliminary: check the first byte of the data (which we
  189. * _must_ have by now) to find out which SOCKS major
  190. * version we're speaking. */
  191. switch (pf->socksbuf->u[0]) {
  192. case 4:
  193. pf->socks_state = SOCKS_4;
  194. break;
  195. case 5:
  196. pf->socks_state = SOCKS_5_INITIAL;
  197. break;
  198. default:
  199. pfd_close(pf); /* unrecognised version */
  200. return;
  201. }
  202. }
  203. BinarySource_BARE_INIT(src, pf->socksbuf->u, pf->socksbuf->len);
  204. get_data(src, pf->socksbuf_consumed);
  205. while (pf->socks_state != SOCKS_NONE) {
  206. unsigned socks_version, message_type, reserved_byte;
  207. unsigned reply_code, port, ipv4, method;
  208. ptrlen methods;
  209. const char *socks4_hostname;
  210. strbuf *output;
  211. switch (pf->socks_state) {
  212. case SOCKS_INITIAL:
  213. case SOCKS_NONE:
  214. unreachable("These case values cannot appear");
  215. case SOCKS_4:
  216. /* SOCKS 4/4A connect message */
  217. socks_version = get_byte(src);
  218. message_type = get_byte(src);
  219. if (get_err(src) == BSE_OUT_OF_DATA)
  220. return;
  221. if (socks_version == 4 && message_type == 1) {
  222. /* CONNECT message */
  223. bool name_based = false;
  224. port = get_uint16(src);
  225. ipv4 = get_uint32(src);
  226. if (ipv4 > 0x00000000 && ipv4 < 0x00000100) {
  227. /*
  228. * Addresses in this range indicate the SOCKS 4A
  229. * extension to specify a hostname, which comes
  230. * after the username.
  231. */
  232. name_based = true;
  233. }
  234. get_asciz(src); /* skip username */
  235. socks4_hostname = name_based ? get_asciz(src) : NULL;
  236. if (get_err(src) == BSE_OUT_OF_DATA)
  237. return;
  238. if (get_err(src))
  239. goto socks4_reject;
  240. pf->port = port;
  241. if (name_based) {
  242. pf->hostname = dupstr(socks4_hostname);
  243. } else {
  244. pf->hostname = ipv4_to_string(ipv4);
  245. }
  246. output = strbuf_new();
  247. put_byte(output, 0); /* reply version */
  248. put_byte(output, 90); /* SOCKS 4 'request granted' */
  249. put_uint16(output, 0); /* null port field */
  250. put_uint32(output, 0); /* null address field */
  251. sk_write(pf->s, output->u, output->len);
  252. strbuf_free(output);
  253. pf->socks_state = SOCKS_NONE;
  254. pf->socksbuf_consumed = src->pos;
  255. break;
  256. }
  257. socks4_reject:
  258. output = strbuf_new();
  259. put_byte(output, 0); /* reply version */
  260. put_byte(output, 91); /* SOCKS 4 'request rejected' */
  261. put_uint16(output, 0); /* null port field */
  262. put_uint32(output, 0); /* null address field */
  263. sk_write(pf->s, output->u, output->len);
  264. strbuf_free(output);
  265. pfd_close(pf);
  266. return;
  267. case SOCKS_5_INITIAL:
  268. /* SOCKS 5 initial method list */
  269. socks_version = get_byte(src);
  270. methods = get_pstring(src);
  271. method = 0xFF; /* means 'no usable method found' */
  272. {
  273. int i;
  274. for (i = 0; i < methods.len; i++) {
  275. if (((const unsigned char *)methods.ptr)[i] == 0 ) {
  276. method = 0; /* no auth */
  277. break;
  278. }
  279. }
  280. }
  281. if (get_err(src) == BSE_OUT_OF_DATA)
  282. return;
  283. if (get_err(src))
  284. method = 0xFF;
  285. output = strbuf_new();
  286. put_byte(output, 5); /* SOCKS version */
  287. put_byte(output, method); /* selected auth method */
  288. sk_write(pf->s, output->u, output->len);
  289. strbuf_free(output);
  290. if (method == 0xFF) {
  291. pfd_close(pf);
  292. return;
  293. }
  294. pf->socks_state = SOCKS_5_CONNECT;
  295. pf->socksbuf_consumed = src->pos;
  296. break;
  297. case SOCKS_5_CONNECT:
  298. /* SOCKS 5 connect message */
  299. socks_version = get_byte(src);
  300. message_type = get_byte(src);
  301. reserved_byte = get_byte(src);
  302. if (socks_version == 5 && message_type == 1 &&
  303. reserved_byte == 0) {
  304. reply_code = 0; /* success */
  305. switch (get_byte(src)) {
  306. case 1: /* IPv4 */
  307. pf->hostname = ipv4_to_string(get_uint32(src));
  308. break;
  309. case 4: /* IPv6 */
  310. pf->hostname = ipv6_to_string(get_data(src, 16));
  311. break;
  312. case 3: /* unresolved domain name */
  313. pf->hostname = mkstr(get_pstring(src));
  314. break;
  315. default:
  316. pf->hostname = NULL;
  317. reply_code = 8; /* address type not supported */
  318. break;
  319. }
  320. pf->port = get_uint16(src);
  321. } else {
  322. reply_code = 7; /* command not supported */
  323. }
  324. if (get_err(src) == BSE_OUT_OF_DATA)
  325. return;
  326. if (get_err(src))
  327. reply_code = 1; /* general server failure */
  328. output = strbuf_new();
  329. put_byte(output, 5); /* SOCKS version */
  330. put_byte(output, reply_code);
  331. put_byte(output, 0); /* reserved */
  332. put_byte(output, 1); /* IPv4 address follows */
  333. put_uint32(output, 0); /* bound IPv4 address (unused) */
  334. put_uint16(output, 0); /* bound port number (unused) */
  335. sk_write(pf->s, output->u, output->len);
  336. strbuf_free(output);
  337. if (reply_code != 0) {
  338. pfd_close(pf);
  339. return;
  340. }
  341. pf->socks_state = SOCKS_NONE;
  342. pf->socksbuf_consumed = src->pos;
  343. break;
  344. }
  345. }
  346. /*
  347. * We come here when we're ready to make an actual
  348. * connection.
  349. */
  350. /*
  351. * Freeze the socket until the SSH server confirms the
  352. * connection.
  353. */
  354. sk_set_frozen(pf->s, true);
  355. pf->c = wrap_lportfwd_open(pf->cl, pf->hostname, pf->port, pf->s,
  356. &pf->chan);
  357. }
  358. if (pf->ready)
  359. sshfwd_write(pf->c, data, len);
  360. }
  361. static void pfd_sent(Plug *plug, size_t bufsize)
  362. {
  363. struct PortForwarding *pf =
  364. container_of(plug, struct PortForwarding, plug);
  365. if (pf->c)
  366. sshfwd_unthrottle(pf->c, bufsize);
  367. }
  368. static const PlugVtable PortForwarding_plugvt = {
  369. // WINSCP
  370. /*.log =*/ pfd_log,
  371. /*.closing =*/ pfd_closing,
  372. /*.receive =*/ pfd_receive,
  373. /*.sent =*/ pfd_sent,
  374. NULL,
  375. };
  376. static void pfd_chan_free(Channel *chan);
  377. static void pfd_open_confirmation(Channel *chan);
  378. static void pfd_open_failure(Channel *chan, const char *errtext);
  379. static size_t pfd_send(
  380. Channel *chan, bool is_stderr, const void *data, size_t len);
  381. static void pfd_send_eof(Channel *chan);
  382. static void pfd_set_input_wanted(Channel *chan, bool wanted);
  383. static char *pfd_log_close_msg(Channel *chan);
  384. static const ChannelVtable PortForwarding_channelvt = {
  385. // WINSCP
  386. /*.free =*/ pfd_chan_free,
  387. /*.open_confirmation =*/ pfd_open_confirmation,
  388. /*.open_failed =*/ pfd_open_failure,
  389. /*.send =*/ pfd_send,
  390. /*.send_eof =*/ pfd_send_eof,
  391. /*.set_input_wanted =*/ pfd_set_input_wanted,
  392. /*.log_close_msg =*/ pfd_log_close_msg,
  393. /*.want_close =*/ chan_default_want_close,
  394. /*.rcvd_exit_status =*/ chan_no_exit_status,
  395. /*.rcvd_exit_signal =*/ chan_no_exit_signal,
  396. /*.rcvd_exit_signal_numeric =*/ chan_no_exit_signal_numeric,
  397. /*.run_shell =*/ chan_no_run_shell,
  398. /*.run_command =*/ chan_no_run_command,
  399. /*.run_subsystem =*/ chan_no_run_subsystem,
  400. /*.enable_x11_forwarding =*/ chan_no_enable_x11_forwarding,
  401. /*.enable_agent_forwarding =*/ chan_no_enable_agent_forwarding,
  402. /*.allocate_pty =*/ chan_no_allocate_pty,
  403. /*.set_env =*/ chan_no_set_env,
  404. /*.send_break =*/ chan_no_send_break,
  405. /*.send_signal =*/ chan_no_send_signal,
  406. /*.change_window_size =*/ chan_no_change_window_size,
  407. /*.request_response =*/ chan_no_request_response,
  408. };
  409. Channel *portfwd_raw_new(ConnectionLayer *cl, Plug **plug, bool start_ready)
  410. {
  411. struct PortForwarding *pf;
  412. pf = new_portfwd_state();
  413. pf->plug.vt = &PortForwarding_plugvt;
  414. pf->chan.initial_fixed_window_size = 0;
  415. pf->chan.vt = &PortForwarding_channelvt;
  416. pf->input_wanted = true;
  417. pf->c = NULL;
  418. pf->cl = cl;
  419. pf->input_wanted = true;
  420. pf->ready = start_ready;
  421. pf->socks_state = SOCKS_NONE;
  422. pf->hostname = NULL;
  423. pf->port = 0;
  424. *plug = &pf->plug;
  425. return &pf->chan;
  426. }
  427. void portfwd_raw_free(Channel *pfchan)
  428. {
  429. struct PortForwarding *pf;
  430. assert(pfchan->vt == &PortForwarding_channelvt);
  431. pf = container_of(pfchan, struct PortForwarding, chan);
  432. free_portfwd_state(pf);
  433. }
  434. void portfwd_raw_setup(Channel *pfchan, Socket *s, SshChannel *sc)
  435. {
  436. struct PortForwarding *pf;
  437. assert(pfchan->vt == &PortForwarding_channelvt);
  438. pf = container_of(pfchan, struct PortForwarding, chan);
  439. pf->s = s;
  440. pf->c = sc;
  441. }
  442. /*
  443. called when someone connects to the local port
  444. */
  445. static int pfl_accepting(Plug *p, accept_fn_t constructor, accept_ctx_t ctx)
  446. {
  447. struct PortListener *pl = container_of(p, struct PortListener, plug);
  448. struct PortForwarding *pf;
  449. Channel *chan;
  450. Plug *plug;
  451. Socket *s;
  452. const char *err;
  453. chan = portfwd_raw_new(pl->cl, &plug, false);
  454. s = constructor(ctx, plug);
  455. if ((err = sk_socket_error(s)) != NULL) {
  456. portfwd_raw_free(chan);
  457. return 1;
  458. }
  459. pf = container_of(chan, struct PortForwarding, chan);
  460. if (pl->is_dynamic) {
  461. pf->s = s;
  462. pf->socks_state = SOCKS_INITIAL;
  463. pf->socksbuf = strbuf_new();
  464. pf->socksbuf_consumed = 0;
  465. pf->port = 0; /* "hostname" buffer is so far empty */
  466. sk_set_frozen(s, false); /* we want to receive SOCKS _now_! */
  467. } else {
  468. pf->hostname = dupstr(pl->hostname);
  469. pf->port = pl->port;
  470. portfwd_raw_setup(
  471. chan, s,
  472. wrap_lportfwd_open(pl->cl, pf->hostname, pf->port, s, &pf->chan));
  473. }
  474. return 0;
  475. }
  476. static const PlugVtable PortListener_plugvt = {
  477. // WINSCP
  478. /*.log =*/ pfl_log,
  479. /*.closing =*/ pfl_closing,
  480. NULL,
  481. NULL,
  482. /*.accepting =*/ pfl_accepting,
  483. };
  484. /*
  485. * Add a new port-forwarding listener from srcaddr:port -> desthost:destport.
  486. *
  487. * desthost == NULL indicates dynamic SOCKS port forwarding.
  488. *
  489. * On success, returns NULL and fills in *pl_ret. On error, returns a
  490. * dynamically allocated error message string.
  491. */
  492. static char *pfl_listen(const char *desthost, int destport,
  493. const char *srcaddr, int port,
  494. ConnectionLayer *cl, Conf *conf,
  495. struct PortListener **pl_ret, int address_family)
  496. {
  497. const char *err;
  498. struct PortListener *pl;
  499. /*
  500. * Open socket.
  501. */
  502. pl = *pl_ret = new_portlistener_state();
  503. pl->plug.vt = &PortListener_plugvt;
  504. if (desthost) {
  505. pl->hostname = dupstr(desthost);
  506. pl->port = destport;
  507. pl->is_dynamic = false;
  508. } else
  509. pl->is_dynamic = true;
  510. pl->cl = cl;
  511. pl->s = new_listener(srcaddr, port, &pl->plug,
  512. !conf_get_bool(conf, CONF_lport_acceptall),
  513. conf, address_family);
  514. if ((err = sk_socket_error(pl->s)) != NULL) {
  515. char *err_ret = dupstr(err);
  516. sk_close(pl->s);
  517. free_portlistener_state(pl);
  518. *pl_ret = NULL;
  519. return err_ret;
  520. }
  521. return NULL;
  522. }
  523. static char *pfd_log_close_msg(Channel *chan)
  524. {
  525. return dupstr("Forwarded port closed");
  526. }
  527. static void pfd_close(struct PortForwarding *pf)
  528. {
  529. if (!pf)
  530. return;
  531. sk_close(pf->s);
  532. free_portfwd_state(pf);
  533. }
  534. /*
  535. * Terminate a listener.
  536. */
  537. static void pfl_terminate(struct PortListener *pl)
  538. {
  539. if (!pl)
  540. return;
  541. sk_close(pl->s);
  542. free_portlistener_state(pl);
  543. }
  544. static void pfd_set_input_wanted(Channel *chan, bool wanted)
  545. {
  546. pinitassert(chan->vt == &PortForwarding_channelvt);
  547. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  548. pf->input_wanted = wanted;
  549. sk_set_frozen(pf->s, !pf->input_wanted);
  550. }
  551. static void pfd_chan_free(Channel *chan)
  552. {
  553. pinitassert(chan->vt == &PortForwarding_channelvt);
  554. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  555. pfd_close(pf);
  556. }
  557. /*
  558. * Called to send data down the raw connection.
  559. */
  560. static size_t pfd_send(
  561. Channel *chan, bool is_stderr, const void *data, size_t len)
  562. {
  563. pinitassert(chan->vt == &PortForwarding_channelvt);
  564. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  565. return sk_write(pf->s, data, len);
  566. }
  567. static void pfd_send_eof(Channel *chan)
  568. {
  569. pinitassert(chan->vt == &PortForwarding_channelvt);
  570. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  571. sk_write_eof(pf->s);
  572. }
  573. static void pfd_open_confirmation(Channel *chan)
  574. {
  575. pinitassert(chan->vt == &PortForwarding_channelvt);
  576. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  577. pf->ready = true;
  578. sk_set_frozen(pf->s, false);
  579. sk_write(pf->s, NULL, 0);
  580. if (pf->socksbuf) {
  581. sshfwd_write(pf->c, pf->socksbuf->u + pf->socksbuf_consumed,
  582. pf->socksbuf->len - pf->socksbuf_consumed);
  583. strbuf_free(pf->socksbuf);
  584. pf->socksbuf = NULL;
  585. }
  586. }
  587. static void pfd_open_failure(Channel *chan, const char *errtext)
  588. {
  589. pinitassert(chan->vt == &PortForwarding_channelvt);
  590. PortForwarding *pf = container_of(chan, PortForwarding, chan);
  591. logeventf(pf->cl->logctx,
  592. "Forwarded connection refused by remote%s%s",
  593. errtext ? ": " : "", errtext ? errtext : "");
  594. }
  595. /* ----------------------------------------------------------------------
  596. * Code to manage the complete set of currently active port
  597. * forwardings, and update it from Conf.
  598. */
  599. struct PortFwdRecord {
  600. enum { DESTROY, KEEP, CREATE } status;
  601. int type;
  602. unsigned sport, dport;
  603. char *saddr, *daddr;
  604. char *sserv, *dserv;
  605. struct ssh_rportfwd *remote;
  606. int addressfamily;
  607. struct PortListener *local;
  608. };
  609. static int pfr_cmp(void *av, void *bv)
  610. {
  611. PortFwdRecord *a = (PortFwdRecord *) av;
  612. PortFwdRecord *b = (PortFwdRecord *) bv;
  613. int i;
  614. if (a->type > b->type)
  615. return +1;
  616. if (a->type < b->type)
  617. return -1;
  618. if (a->addressfamily > b->addressfamily)
  619. return +1;
  620. if (a->addressfamily < b->addressfamily)
  621. return -1;
  622. if ( (i = nullstrcmp(a->saddr, b->saddr)) != 0)
  623. return i < 0 ? -1 : +1;
  624. if (a->sport > b->sport)
  625. return +1;
  626. if (a->sport < b->sport)
  627. return -1;
  628. if (a->type != 'D') {
  629. if ( (i = nullstrcmp(a->daddr, b->daddr)) != 0)
  630. return i < 0 ? -1 : +1;
  631. if (a->dport > b->dport)
  632. return +1;
  633. if (a->dport < b->dport)
  634. return -1;
  635. }
  636. return 0;
  637. }
  638. static void pfr_free(PortFwdRecord *pfr)
  639. {
  640. /* Dispose of any listening socket. */
  641. if (pfr->local)
  642. pfl_terminate(pfr->local);
  643. sfree(pfr->saddr);
  644. sfree(pfr->daddr);
  645. sfree(pfr->sserv);
  646. sfree(pfr->dserv);
  647. sfree(pfr);
  648. }
  649. struct PortFwdManager {
  650. ConnectionLayer *cl;
  651. Conf *conf;
  652. tree234 *forwardings;
  653. };
  654. PortFwdManager *portfwdmgr_new(ConnectionLayer *cl)
  655. {
  656. PortFwdManager *mgr = snew(PortFwdManager);
  657. mgr->cl = cl;
  658. mgr->conf = NULL;
  659. mgr->forwardings = newtree234(pfr_cmp);
  660. return mgr;
  661. }
  662. void portfwdmgr_close(PortFwdManager *mgr, PortFwdRecord *pfr)
  663. {
  664. PortFwdRecord *realpfr = del234(mgr->forwardings, pfr);
  665. if (realpfr == pfr)
  666. pfr_free(pfr);
  667. }
  668. void portfwdmgr_close_all(PortFwdManager *mgr)
  669. {
  670. PortFwdRecord *pfr;
  671. while ((pfr = delpos234(mgr->forwardings, 0)) != NULL)
  672. pfr_free(pfr);
  673. }
  674. void portfwdmgr_free(PortFwdManager *mgr)
  675. {
  676. portfwdmgr_close_all(mgr);
  677. freetree234(mgr->forwardings);
  678. if (mgr->conf)
  679. conf_free(mgr->conf);
  680. sfree(mgr);
  681. }
  682. void portfwdmgr_config(PortFwdManager *mgr, Conf *conf)
  683. {
  684. PortFwdRecord *pfr;
  685. int i;
  686. char *key, *val;
  687. if (mgr->conf)
  688. conf_free(mgr->conf);
  689. mgr->conf = conf_copy(conf);
  690. /*
  691. * Go through the existing port forwardings and tag them
  692. * with status==DESTROY. Any that we want to keep will be
  693. * re-enabled (status==KEEP) as we go through the
  694. * configuration and find out which bits are the same as
  695. * they were before.
  696. */
  697. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++)
  698. pfr->status = DESTROY;
  699. for (val = conf_get_str_strs(conf, CONF_portfwd, NULL, &key);
  700. val != NULL;
  701. val = conf_get_str_strs(conf, CONF_portfwd, key, &key)) {
  702. char *kp, *kp2, *vp, *vp2;
  703. char address_family, type;
  704. int sport, dport, sserv, dserv;
  705. char *sports, *dports, *saddr, *host;
  706. kp = key;
  707. address_family = 'A';
  708. type = 'L';
  709. if (*kp == 'A' || *kp == '4' || *kp == '6')
  710. address_family = *kp++;
  711. if (*kp == 'L' || *kp == 'R')
  712. type = *kp++;
  713. if ((kp2 = host_strchr(kp, ':')) != NULL) {
  714. /*
  715. * There's a colon in the middle of the source port
  716. * string, which means that the part before it is
  717. * actually a source address.
  718. */
  719. char *saddr_tmp = dupprintf("%.*s", (int)(kp2 - kp), kp);
  720. saddr = host_strduptrim(saddr_tmp);
  721. sfree(saddr_tmp);
  722. sports = kp2+1;
  723. } else {
  724. saddr = NULL;
  725. sports = kp;
  726. }
  727. sport = atoi(sports);
  728. sserv = 0;
  729. if (sport == 0) {
  730. sserv = 1;
  731. sport = net_service_lookup(sports);
  732. if (!sport) {
  733. logeventf(mgr->cl->logctx, "Service lookup failed for source"
  734. " port \"%s\"", sports);
  735. }
  736. }
  737. if (type == 'L' && !strcmp(val, "D")) {
  738. /* dynamic forwarding */
  739. host = NULL;
  740. dports = NULL;
  741. dport = -1;
  742. dserv = 0;
  743. type = 'D';
  744. } else {
  745. /* ordinary forwarding */
  746. vp = val;
  747. vp2 = vp + host_strcspn(vp, ":");
  748. host = dupprintf("%.*s", (int)(vp2 - vp), vp);
  749. if (*vp2)
  750. vp2++;
  751. dports = vp2;
  752. dport = atoi(dports);
  753. dserv = 0;
  754. if (dport == 0) {
  755. dserv = 1;
  756. dport = net_service_lookup(dports);
  757. if (!dport) {
  758. logeventf(mgr->cl->logctx,
  759. "Service lookup failed for destination"
  760. " port \"%s\"", dports);
  761. }
  762. }
  763. }
  764. if (sport && dport) {
  765. /* Set up a description of the source port. */
  766. pfr = snew(PortFwdRecord);
  767. pfr->type = type;
  768. pfr->saddr = saddr;
  769. pfr->sserv = sserv ? dupstr(sports) : NULL;
  770. pfr->sport = sport;
  771. pfr->daddr = host;
  772. pfr->dserv = dserv ? dupstr(dports) : NULL;
  773. pfr->dport = dport;
  774. pfr->local = NULL;
  775. pfr->remote = NULL;
  776. pfr->addressfamily = (address_family == '4' ? ADDRTYPE_IPV4 :
  777. address_family == '6' ? ADDRTYPE_IPV6 :
  778. ADDRTYPE_UNSPEC);
  779. { // WINSCP
  780. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  781. if (existing != pfr) {
  782. if (existing->status == DESTROY) {
  783. /*
  784. * We already have a port forwarding up and running
  785. * with precisely these parameters. Hence, no need
  786. * to do anything; simply re-tag the existing one
  787. * as KEEP.
  788. */
  789. existing->status = KEEP;
  790. }
  791. /*
  792. * Anything else indicates that there was a duplicate
  793. * in our input, which we'll silently ignore.
  794. */
  795. pfr_free(pfr);
  796. } else {
  797. pfr->status = CREATE;
  798. }
  799. } // WINSCP
  800. } else {
  801. sfree(saddr);
  802. sfree(host);
  803. }
  804. }
  805. /*
  806. * Now go through and destroy any port forwardings which were
  807. * not re-enabled.
  808. */
  809. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  810. if (pfr->status == DESTROY) {
  811. char *message;
  812. message = dupprintf("%s port forwarding from %s%s%d",
  813. pfr->type == 'L' ? "local" :
  814. pfr->type == 'R' ? "remote" : "dynamic",
  815. pfr->saddr ? pfr->saddr : "",
  816. pfr->saddr ? ":" : "",
  817. pfr->sport);
  818. if (pfr->type != 'D') {
  819. char *msg2 = dupprintf("%s to %s:%d", message,
  820. pfr->daddr, pfr->dport);
  821. sfree(message);
  822. message = msg2;
  823. }
  824. logeventf(mgr->cl->logctx, "Cancelling %s", message);
  825. sfree(message);
  826. /* pfr->remote or pfr->local may be NULL if setting up a
  827. * forwarding failed. */
  828. if (pfr->remote) {
  829. /*
  830. * Cancel the port forwarding at the server
  831. * end.
  832. *
  833. * Actually closing the listening port on the server
  834. * side may fail - because in SSH-1 there's no message
  835. * in the protocol to request it!
  836. *
  837. * Instead, we simply remove the record of the
  838. * forwarding from our local end, so that any
  839. * connections the server tries to make on it are
  840. * rejected.
  841. */
  842. ssh_rportfwd_remove(mgr->cl, pfr->remote);
  843. pfr->remote = NULL;
  844. } else if (pfr->local) {
  845. pfl_terminate(pfr->local);
  846. pfr->local = NULL;
  847. }
  848. delpos234(mgr->forwardings, i);
  849. pfr_free(pfr);
  850. i--; /* so we don't skip one in the list */
  851. }
  852. }
  853. /*
  854. * And finally, set up any new port forwardings (status==CREATE).
  855. */
  856. for (i = 0; (pfr = index234(mgr->forwardings, i)) != NULL; i++) {
  857. if (pfr->status == CREATE) {
  858. char *sportdesc, *dportdesc;
  859. sportdesc = dupprintf("%s%s%s%s%d%s",
  860. pfr->saddr ? pfr->saddr : "",
  861. pfr->saddr ? ":" : "",
  862. pfr->sserv ? pfr->sserv : "",
  863. pfr->sserv ? "(" : "",
  864. pfr->sport,
  865. pfr->sserv ? ")" : "");
  866. if (pfr->type == 'D') {
  867. dportdesc = NULL;
  868. } else {
  869. dportdesc = dupprintf("%s:%s%s%d%s",
  870. pfr->daddr,
  871. pfr->dserv ? pfr->dserv : "",
  872. pfr->dserv ? "(" : "",
  873. pfr->dport,
  874. pfr->dserv ? ")" : "");
  875. }
  876. if (pfr->type == 'L') {
  877. char *err = pfl_listen(pfr->daddr, pfr->dport,
  878. pfr->saddr, pfr->sport,
  879. mgr->cl, conf, &pfr->local,
  880. pfr->addressfamily);
  881. logeventf(mgr->cl->logctx,
  882. "Local %sport %s forwarding to %s%s%s",
  883. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  884. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  885. sportdesc, dportdesc,
  886. err ? " failed: " : "", err ? err : "");
  887. if (err)
  888. sfree(err);
  889. } else if (pfr->type == 'D') {
  890. char *err = pfl_listen(NULL, -1, pfr->saddr, pfr->sport,
  891. mgr->cl, conf, &pfr->local,
  892. pfr->addressfamily);
  893. logeventf(mgr->cl->logctx,
  894. "Local %sport %s SOCKS dynamic forwarding%s%s",
  895. pfr->addressfamily == ADDRTYPE_IPV4 ? "IPv4 " :
  896. pfr->addressfamily == ADDRTYPE_IPV6 ? "IPv6 " : "",
  897. sportdesc,
  898. err ? " failed: " : "", err ? err : "");
  899. if (err)
  900. sfree(err);
  901. } else {
  902. const char *shost;
  903. if (pfr->saddr) {
  904. shost = pfr->saddr;
  905. } else if (conf_get_bool(conf, CONF_rport_acceptall)) {
  906. shost = "";
  907. } else {
  908. shost = "localhost";
  909. }
  910. pfr->remote = ssh_rportfwd_alloc(
  911. mgr->cl, shost, pfr->sport, pfr->daddr, pfr->dport,
  912. pfr->addressfamily, sportdesc, pfr, NULL);
  913. if (!pfr->remote) {
  914. logeventf(mgr->cl->logctx,
  915. "Duplicate remote port forwarding to %s:%d",
  916. pfr->daddr, pfr->dport);
  917. pfr_free(pfr);
  918. } else {
  919. logeventf(mgr->cl->logctx, "Requesting remote port %s"
  920. " forward to %s", sportdesc, dportdesc);
  921. }
  922. }
  923. sfree(sportdesc);
  924. sfree(dportdesc);
  925. }
  926. }
  927. }
  928. bool portfwdmgr_listen(PortFwdManager *mgr, const char *host, int port,
  929. const char *keyhost, int keyport, Conf *conf)
  930. {
  931. PortFwdRecord *pfr;
  932. pfr = snew(PortFwdRecord);
  933. pfr->type = 'L';
  934. pfr->saddr = host ? dupstr(host) : NULL;
  935. pfr->daddr = keyhost ? dupstr(keyhost) : NULL;
  936. pfr->sserv = pfr->dserv = NULL;
  937. pfr->sport = port;
  938. pfr->dport = keyport;
  939. pfr->local = NULL;
  940. pfr->remote = NULL;
  941. pfr->addressfamily = ADDRTYPE_UNSPEC;
  942. { // WINSCP
  943. PortFwdRecord *existing = add234(mgr->forwardings, pfr);
  944. if (existing != pfr) {
  945. /*
  946. * We had this record already. Return failure.
  947. */
  948. pfr_free(pfr);
  949. return false;
  950. }
  951. } // WINSCP
  952. { // WINSCP
  953. char *err = pfl_listen(keyhost, keyport, host, port,
  954. mgr->cl, conf, &pfr->local, pfr->addressfamily);
  955. logeventf(mgr->cl->logctx,
  956. "%s on port %s:%d to forward to client%s%s",
  957. err ? "Failed to listen" : "Listening", host, port,
  958. err ? ": " : "", err ? err : "");
  959. if (err) {
  960. sfree(err);
  961. del234(mgr->forwardings, pfr);
  962. pfr_free(pfr);
  963. return false;
  964. }
  965. } // WINSCP
  966. return true;
  967. }
  968. bool portfwdmgr_unlisten(PortFwdManager *mgr, const char *host, int port)
  969. {
  970. PortFwdRecord pfr_key;
  971. pfr_key.type = 'L';
  972. /* Safe to cast the const away here, because it will only be used
  973. * by pfr_cmp, which won't write to the string */
  974. pfr_key.saddr = pfr_key.daddr = (char *)host;
  975. pfr_key.sserv = pfr_key.dserv = NULL;
  976. pfr_key.sport = pfr_key.dport = port;
  977. pfr_key.local = NULL;
  978. pfr_key.remote = NULL;
  979. pfr_key.addressfamily = ADDRTYPE_UNSPEC;
  980. { // WINSCP
  981. PortFwdRecord *pfr = del234(mgr->forwardings, &pfr_key);
  982. if (!pfr)
  983. return false;
  984. logeventf(mgr->cl->logctx, "Closing listening port %s:%d", host, port);
  985. pfr_free(pfr);
  986. } // WINSCP
  987. return true;
  988. }
  989. /*
  990. * Called when receiving a PORT OPEN from the server to make a
  991. * connection to a destination host.
  992. *
  993. * On success, returns NULL and fills in *pf_ret. On error, returns a
  994. * dynamically allocated error message string.
  995. */
  996. char *portfwdmgr_connect(PortFwdManager *mgr, Channel **chan_ret,
  997. char *hostname, int port, SshChannel *c,
  998. int addressfamily)
  999. {
  1000. SockAddr *addr;
  1001. const char *err;
  1002. char *dummy_realhost = NULL;
  1003. struct PortForwarding *pf;
  1004. /*
  1005. * Try to find host.
  1006. */
  1007. addr = name_lookup(hostname, port, &dummy_realhost, mgr->conf,
  1008. addressfamily, NULL, NULL);
  1009. if ((err = sk_addr_error(addr)) != NULL) {
  1010. char *err_ret = dupstr(err);
  1011. sk_addr_free(addr);
  1012. sfree(dummy_realhost);
  1013. return err_ret;
  1014. }
  1015. /*
  1016. * Open socket.
  1017. */
  1018. pf = new_portfwd_state();
  1019. *chan_ret = &pf->chan;
  1020. pf->plug.vt = &PortForwarding_plugvt;
  1021. pf->chan.initial_fixed_window_size = 0;
  1022. pf->chan.vt = &PortForwarding_channelvt;
  1023. pf->input_wanted = true;
  1024. pf->ready = true;
  1025. pf->c = c;
  1026. pf->cl = mgr->cl;
  1027. pf->socks_state = SOCKS_NONE;
  1028. pf->s = new_connection(addr, dummy_realhost, port,
  1029. false, true, false, false, &pf->plug, mgr->conf);
  1030. sfree(dummy_realhost);
  1031. if ((err = sk_socket_error(pf->s)) != NULL) {
  1032. char *err_ret = dupstr(err);
  1033. sk_close(pf->s);
  1034. free_portfwd_state(pf);
  1035. *chan_ret = NULL;
  1036. return err_ret;
  1037. }
  1038. return NULL;
  1039. }
  1040. #ifdef MPEXT
  1041. #include "puttyexp.h"
  1042. int is_pfwd(Plug * plug)
  1043. {
  1044. return
  1045. (plug->vt->closing == pfd_closing) ||
  1046. (plug->vt->closing == pfl_closing);
  1047. }
  1048. Seat * get_pfwd_seat(Plug * plug)
  1049. {
  1050. LogContext * logctx;
  1051. if (plug->vt->closing == pfl_closing)
  1052. {
  1053. struct PortListener *pl = container_of(plug, struct PortListener, plug);
  1054. logctx = pl->cl->logctx;
  1055. }
  1056. else if (plug->vt->closing == pfd_closing)
  1057. {
  1058. struct PortForwarding *pf = container_of(plug, struct PortForwarding, plug);
  1059. logctx = pf->cl->logctx;
  1060. }
  1061. return get_log_seat(logctx);
  1062. }
  1063. #endif