1 /* UDP send/receive module for secnet */
3 /* This module enables sites to communicate by sending UDP
4 * packets. When an instance of the module is created we can
5 * optionally bind to a particular local IP address (not implemented
8 * Packets are offered to registered receivers in turn. Once one
9 * accepts it, it isn't offered to any more. */
17 #include <sys/socket.h>
19 #include <netinet/in.h>
20 #include <arpa/inet.h>
23 #include "unaligned.h"
27 static beforepoll_fn udp_beforepoll
;
28 static afterpoll_fn udp_afterpoll
;
29 static comm_request_notify_fn request_notify
;
30 static comm_release_notify_fn release_notify
;
31 static comm_sendmsg_fn udp_sendmsg
;
36 struct notify_list
*next
;
46 struct buffer_if
*rbuf
;
47 struct notify_list
*notify
;
52 static const char *addr_to_string(void *commst
, const struct comm_addr
*ca
) {
53 struct udp
*st
=commst
;
54 static char sbuf
[100];
56 snprintf(sbuf
, sizeof(sbuf
), "udp:%s-%s",
57 iaddr_to_string(&st
->addr
), iaddr_to_string(&ca
->ia
));
61 static int udp_beforepoll(void *state
, struct pollfd
*fds
, int *nfds_io
,
75 static void udp_afterpoll(void *state
, struct pollfd
*fds
, int nfds
)
80 struct notify_list
*n
;
84 if (nfds
&& (fds
->revents
& POLLIN
)) {
88 BUF_ASSERT_FREE(st
->rbuf
);
89 BUF_ALLOC(st
->rbuf
,"udp_afterpoll");
90 buffer_init(st
->rbuf
,calculate_max_start_pad());
91 rv
=recvfrom(st
->fd
, st
->rbuf
->start
,
92 buf_remaining_space(st
->rbuf
),
93 0, &from
.sa
, &fromlen
);
97 /* Check that the packet came from our poxy server;
98 we shouldn't be contacted directly by anybody else
99 (since they can trivially forge source addresses) */
100 if (!iaddr_equal(&from
,&st
->proxy
)) {
101 Message(M_INFO
,"udp: received packet that's not "
106 /* proxy protocol supports ipv4 transport only */
107 from
.sa
.sa_family
=AF_INET
;
108 memcpy(&from
.sin
.sin_addr
,buf_unprepend(st
->rbuf
,4),4);
109 buf_unprepend(st
->rbuf
,2);
110 memcpy(&from
.sin
.sin_port
,buf_unprepend(st
->rbuf
,2),2);
117 for (n
=st
->notify
; n
; n
=n
->next
) {
118 if (n
->fn(n
->state
, st
->rbuf
, &ca
)) {
125 if (st
->rbuf
->size
>12 /* prevents traffic amplification */
126 && ((msgtype
=get_uint32(st
->rbuf
->start
+8))
128 uint32_t source
,dest
;
129 /* Manufacture and send NAK packet */
130 source
=get_uint32(st
->rbuf
->start
); /* Us */
131 dest
=get_uint32(st
->rbuf
->start
+4); /* Them */
132 send_nak(&ca
,source
,dest
,msgtype
,st
->rbuf
,"unwanted");
136 BUF_ASSERT_FREE(st
->rbuf
);
144 static void request_notify(void *commst
, void *nst
, comm_notify_fn
*fn
)
146 struct udp
*st
=commst
;
147 struct notify_list
*n
;
149 n
=safe_malloc(sizeof(*n
),"request_notify");
156 static void release_notify(void *commst
, void *nst
, comm_notify_fn
*fn
)
158 struct udp
*st
=commst
;
159 struct notify_list
*n
, **p
, *t
;
163 for (n
=st
->notify
; n
; )
165 if (n
->state
==nst
&& n
->fn
==fn
) {
177 static bool_t
udp_sendmsg(void *commst
, struct buffer_if
*buf
,
178 const struct comm_addr
*dest
)
180 struct udp
*st
=commst
;
184 sa
=buf_prepend(buf
,8);
185 if (dest
->ia
.sa
.sa_family
!= AF_INET
) {
187 "udp: proxy means dropping outgoing non-IPv4 packet to %s\n",
188 iaddr_to_string(&dest
->ia
));
191 memcpy(sa
,&dest
->ia
.sin
.sin_addr
,4);
193 memcpy(sa
+6,&dest
->ia
.sin
.sin_port
,2);
194 sendto(st
->fd
,sa
,buf
->size
+8,0,&st
->proxy
.sa
,
195 iaddr_socklen(&st
->proxy
));
196 buf_unprepend(buf
,8);
198 sendto(st
->fd
, buf
->start
, buf
->size
, 0,
199 &dest
->ia
.sa
, iaddr_socklen(&dest
->ia
));
205 static void udp_phase_hook(void *sst
, uint32_t new_phase
)
210 st
->fd
=socket(PF_INET
, SOCK_DGRAM
, IPPROTO_UDP
);
212 fatal_perror("udp (%s:%d): socket",st
->loc
.file
,st
->loc
.line
);
214 if (fcntl(st
->fd
, F_SETFL
, fcntl(st
->fd
, F_GETFL
)|O_NONBLOCK
)==-1) {
215 fatal_perror("udp (%s:%d): fcntl(set O_NONBLOCK)",
216 st
->loc
.file
,st
->loc
.line
);
225 /* XXX this fork() and waitpid() business needs to be hidden
226 in some system-specific library functions. */
229 fatal_perror("udp_phase_hook: fork() for authbind");
232 char *argv
[4], addrstr
[9], portstr
[5];
233 switch (addr
.sa
.sa_family
) {
235 sprintf(addrstr
,"%08lX",(long)addr
.sin
.sin_addr
.s_addr
);
236 sprintf(portstr
,"%04X",addr
.sin
.sin_port
);
239 fatal("udp (%s:%d): unsupported address family for authbind",
240 st
->loc
.file
,st
->loc
.line
);
242 argv
[0]=st
->authbind
;
247 execvp(st
->authbind
,argv
);
250 while (waitpid(c
,&status
,0)==-1) {
251 if (errno
==EINTR
) continue;
252 fatal_perror("udp (%s:%d): authbind",st
->loc
.file
,st
->loc
.line
);
254 if (WIFSIGNALED(status
)) {
255 fatal("udp (%s:%d): authbind died on signal %d",st
->loc
.file
,
256 st
->loc
.line
, WTERMSIG(status
));
258 if (WIFEXITED(status
) && WEXITSTATUS(status
)!=0) {
259 fatal("udp (%s:%d): authbind died with status %d",st
->loc
.file
,
260 st
->loc
.line
, WEXITSTATUS(status
));
263 if (bind(st
->fd
, &addr
.sa
, iaddr_socklen(&addr
))!=0) {
264 fatal_perror("udp (%s:%d): bind",st
->loc
.file
,st
->loc
.line
);
268 register_for_poll(st
,udp_beforepoll
,udp_afterpoll
,1,"udp");
271 static list_t
*udp_apply(closure_t
*self
, struct cloc loc
, dict_t
*context
,
280 st
=safe_malloc(sizeof(*st
),"udp_apply(st)");
282 st
->cl
.description
="udp";
285 st
->cl
.interface
=&st
->ops
;
287 st
->ops
.request_notify
=request_notify
;
288 st
->ops
.release_notify
=release_notify
;
289 st
->ops
.sendmsg
=udp_sendmsg
;
290 st
->ops
.addr_to_string
=addr_to_string
;
295 if (!i
|| i
->type
!=t_dict
) {
296 cfgfatal(st
->loc
,"udp","first argument must be a dictionary\n");
300 st
->addr
.sa
.sa_family
=AF_INET
;
301 j
=dict_find_item(d
,"address",False
,"udp",st
->loc
);
302 st
->addr
.sin
.sin_addr
.s_addr
=j?
string_item_to_ipaddr(j
, "udp"):INADDR_ANY
;
303 st
->addr
.sin
.sin_port
=dict_read_number(d
,"port",True
,"udp",st
->loc
,0);
304 st
->rbuf
=find_cl_if(d
,"buffer",CL_BUFFER
,True
,"udp",st
->loc
);
305 st
->authbind
=dict_read_string(d
,"authbind",False
,"udp",st
->loc
);
306 l
=dict_lookup(d
,"proxy");
310 st
->proxy
.sa
.sa_family
=AF_INET
;
312 if (!i
|| i
->type
!=t_string
) {
313 cfgfatal(st
->loc
,"udp","proxy must supply ""addr"",port\n");
315 a
=string_item_to_ipaddr(i
,"proxy");
316 st
->proxy
.sin
.sin_addr
.s_addr
=htonl(a
);
318 if (!i
|| i
->type
!=t_number
) {
319 cfgfatal(st
->loc
,"udp","proxy must supply ""addr"",port\n");
321 st
->proxy
.sin
.sin_port
=htons(i
->data
.number
);
324 update_max_start_pad(&comm_max_start_pad
, st
->use_proxy ?
8 : 0);
326 add_hook(PHASE_GETRESOURCES
,udp_phase_hook
,st
);
328 return new_closure(&st
->cl
);
331 void udp_module(dict_t
*dict
)
333 add_closure(dict
,"udp",udp_apply
);