--- ansh/src/utils.c 2011/10/13 11:01:37 1.1.1.1.2.5 +++ ansh/src/utils.c 2011/10/14 13:23:49 1.1.1.1.2.13 @@ -3,9 +3,46 @@ * by Michael Pounov * * $Author: misho $ - * $Id: utils.c,v 1.1.1.1.2.5 2011/10/13 11:01:37 misho Exp $ + * $Id: utils.c,v 1.1.1.1.2.13 2011/10/14 13:23:49 misho Exp $ * - *************************************************************************/ + ************************************************************************* +The ELWIX and AITNET software is distributed under the following +terms: + +All of the documentation and software included in the ELWIX and AITNET +Releases is copyrighted by ELWIX - Sofia/Bulgaria + +Copyright 2004, 2005, 2006, 2007, 2008, 2009, 2010, 2011 + by Michael Pounov . All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. +3. All advertising materials mentioning features or use of this software + must display the following acknowledgement: +This product includes software developed by Michael Pounov +ELWIX - Embedded LightWeight unIX and its contributors. +4. Neither the name of AITNET nor the names of its contributors + may be used to endorse or promote products derived from this software + without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY AITNET AND CONTRIBUTORS ``AS IS'' AND +ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE +ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS +OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) +HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT +LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY +OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF +SUCH DAMAGE. +*/ #include "global.h" @@ -60,6 +97,12 @@ PrepareL2(const char *psDev, int *bpflen) close(h); return -1; } + n = USHRT_MAX + 1; + if (ioctl(h, BIOCSBLEN, &n) == -1) { + printf("Error:: set buffer interface %s buffer length #%d - %s\n", psDev, errno, strerror(errno)); + close(h); + return -1; + } strlcpy(ifr.ifr_name, psDev, sizeof ifr.ifr_name); if (ioctl(h, BIOCSETIF, &ifr) == -1) { printf("Error:: bind interface %s to bpf #%d - %s\n", psDev, errno, strerror(errno)); @@ -72,15 +115,13 @@ PrepareL2(const char *psDev, int *bpflen) return -1; } if (ioctl(h, BIOCGBLEN, bpflen) == -1) { - printf("Error:: get interface %s buffer length #%d - %s\n", psDev, errno, strerror(errno)); + printf("Error:: get buffer interface %s buffer length #%d - %s\n", psDev, errno, strerror(errno)); close(h); return -1; } - /* n = fcntl(h, F_GETFL); fcntl(h, F_SETFL, n | O_NONBLOCK); - */ VERB(3) LOG("Openned device handle %d with bpf buflen %d", h, *bpflen); return h; @@ -121,8 +162,8 @@ PrepareL3(const struct sockaddr *sa, int *bpflen) } char -icmpRecv(int s, u_short * __restrict id, u_int * __restrict crypted, u_char * __restrict data, - int * __restrict datlen, struct sockaddr *sa, socklen_t *salen) +icmpRecv(int s, u_int * __restrict seq, u_short * __restrict id, u_int * __restrict crypted, + u_char * __restrict data, int * __restrict datlen, struct sockaddr *sa, socklen_t *salen) { int ret = 0; struct icmp *icmp; @@ -165,6 +206,8 @@ icmpRecv(int s, u_short * __restrict id, u_int * __res VERB(3) LOG("Channel SECURED:: Plain text communication not supported at this moment ..."); return ANSH_FLG_ERR; } + if (ntohl(hdr->ansh_nonce) != *crypted) + VERB(4) LOG("Detect change of nonce from %x to %x", *crypted, ntohl(hdr->ansh_nonce)); *crypted = ntohl(hdr->ansh_nonce); } @@ -185,13 +228,16 @@ icmpRecv(int s, u_short * __restrict id, u_int * __res memcpy(data, buf + sizeof(struct ip) + sizeof(struct icmp) + sizeof(struct ansh_hdr), *datlen); } + if (seq) + *seq = ntohl(hdr->ansh_seq); if (id) *id = ntohs(icmp->icmp_id); return hdr->ansh_flg; } int -icmpSend(int s, u_short id, char flg, u_int crypted, u_char *data, int datlen, struct sockaddr *sa, socklen_t salen) +icmpSend(int s, u_int seq, u_short id, char flg, u_int crypted, u_char *data, int datlen, + struct sockaddr *sa, socklen_t salen) { u_char *pos, buf[USHRT_MAX] = { 0 }; struct icmp *icmp; @@ -212,6 +258,7 @@ icmpSend(int s, u_short id, char flg, u_int crypted, u hdr->ansh_flg = flg; hdr->ansh_len = htons(datlen + sizeof(struct ansh_hdr)); hdr->ansh_nonce = htonl(crypted); + hdr->ansh_seq = htonl(seq); hdr->ansh_crc = 0; hdr->ansh_crc = htonl(crcAdler((u_char*) hdr, ntohs(hdr->ansh_len))); @@ -230,7 +277,7 @@ icmpSend(int s, u_short id, char flg, u_int crypted, u VERB(4) LOG("Put packet with len=%d", ret); if (ret != sizeof(struct icmp) + sizeof(struct ansh_hdr) + datlen) { VERB(3) LOG("Sended data %d is different from source data len %d", ret, - sizeof(struct icmp) + sizeof(struct ansh_hdr) + datlen); + (int) (sizeof(struct icmp) + sizeof(struct ansh_hdr) + datlen)); return ANSH_FLG_ERR; } @@ -238,7 +285,7 @@ icmpSend(int s, u_short id, char flg, u_int crypted, u } static int -_pkt_Send(int s, char flg, u_int crypted, u_char *data, int datlen, struct ether_addr *ea) +_pkt_Send(int s, u_int seq, char flg, u_int crypted, u_char *data, int datlen, struct io_ether_addr *ea) { u_char *pos, buf[USHRT_MAX] = { 0 }; struct ether_header *e = (struct ether_header*) buf; @@ -250,7 +297,7 @@ _pkt_Send(int s, char flg, u_int crypted, u_char *data return ANSH_FLG_ERR; e->ether_type = ntohs(ANSH_ID); - memcpy(e->ether_dhost, ea->octet, ETHER_ADDR_LEN); + memcpy(e->ether_dhost, ea->ether_addr_octet, ETHER_ADDR_LEN); hdr = (struct ansh_hdr*) (buf + ETHER_HDR_LEN); pos = ((u_char*) hdr) + sizeof(struct ansh_hdr); @@ -260,6 +307,7 @@ _pkt_Send(int s, char flg, u_int crypted, u_char *data hdr->ansh_flg = flg; hdr->ansh_len = htons(datlen + sizeof(struct ansh_hdr)); hdr->ansh_nonce = htonl(crypted); + hdr->ansh_seq = htonl(seq); hdr->ansh_crc = 0; hdr->ansh_crc = htonl(crcAdler((u_char*) hdr, ntohs(hdr->ansh_len))); @@ -270,7 +318,7 @@ _pkt_Send(int s, char flg, u_int crypted, u_char *data VERB(4) LOG("Put packet with len=%d", ret); if (ret != ETHER_HDR_LEN + sizeof(struct ansh_hdr) + datlen) { VERB(3) LOG("Sended data %d is different from source data len %d", ret, - ETHER_HDR_LEN + sizeof(struct ansh_hdr) + datlen); + (int) (ETHER_HDR_LEN + sizeof(struct ansh_hdr) + datlen)); return ANSH_FLG_ERR; } @@ -278,13 +326,13 @@ _pkt_Send(int s, char flg, u_int crypted, u_char *data } int -pktSend(int s, char flg, u_int crypted, u_char *data, int datlen, struct ether_addr *ea) +pktSend(int s, u_int seq, char flg, u_int crypted, u_char *data, int datlen, struct io_ether_addr *ea) { int wlen, ret = 0; u_char *pos = data; while (datlen > -1) { - wlen = _pkt_Send(s, flg, crypted, pos, (datlen > 512) ? 512 : datlen, ea); + wlen = _pkt_Send(s, seq, flg, crypted, pos, (datlen > 512) ? 512 : datlen, ea); if (wlen == -1) return -1; else { @@ -298,7 +346,7 @@ pktSend(int s, char flg, u_int crypted, u_char *data, } static char -_pkt_Recv(u_char * __restrict buf, int rlen, u_int * __restrict crypted, +_pkt_Recv(u_char * __restrict buf, int rlen, u_int * __restrict seq, u_int * __restrict crypted, u_char * __restrict data, int * __restrict datlen, u_char ** __restrict next, int * __restrict nextlen) { @@ -338,6 +386,8 @@ _pkt_Recv(u_char * __restrict buf, int rlen, u_int * _ VERB(3) LOG("Channel SECURED:: Plain text communication not supported at this moment ..."); return ANSH_FLG_ERR; } + if (ntohl(hdr->ansh_nonce) != *crypted) + VERB(4) LOG("Detect change of nonce from %x to %x", *crypted, ntohl(hdr->ansh_nonce)); *crypted = ntohl(hdr->ansh_nonce); } @@ -357,21 +407,25 @@ _pkt_Recv(u_char * __restrict buf, int rlen, u_int * _ memcpy(data, buf + bpf->bh_hdrlen + ETHER_HDR_LEN + sizeof(struct ansh_hdr), *datlen); } + if (seq) + *seq = ntohl(hdr->ansh_seq); return hdr->ansh_flg; } char -pktRecv(int s, u_int * __restrict crypted, u_char * __restrict data, int * __restrict datlen, - struct ether_header *eth) +pktRecv(int s, u_int * __restrict seq, u_int * __restrict crypted, u_char * __restrict data, + int * __restrict datlen, struct ether_header *eth) { - u_char *buf, *next, *pos, *ptr; + u_char *buf, *next, *ptr, *pos = data; int nextlen, rlen, buflen, ptrlen; char flg; struct bpf_hdr *bpf; struct ether_header *e; - if (!eth || !datlen) + if (!eth || !data || !datlen) return ANSH_FLG_ERR; + else + memset(data, 0, *datlen); if (!(buf = malloc(*datlen))) { ERR("malloc() #%d - %s", errno, strerror(errno)); @@ -399,9 +453,7 @@ pktRecv(int s, u_int * __restrict crypted, u_char * __ ptr = next = buf; ptrlen = nextlen = rlen; - pos = data; - buflen = *datlen; - if ((flg = _pkt_Recv(ptr, ptrlen, crypted, pos, &buflen, &next, &nextlen)) == -1) { + if ((flg = _pkt_Recv(ptr, ptrlen, seq, crypted, pos, &buflen, &next, &nextlen)) == -1) { free(buf); return ANSH_FLG_ERR; } else { @@ -410,8 +462,9 @@ pktRecv(int s, u_int * __restrict crypted, u_char * __ ptr = next; ptrlen = nextlen; } + /* get additional packets from buffer */ while (next && nextlen > 0) - if (_pkt_Recv(ptr, ptrlen, crypted, pos, &buflen, &next, &nextlen) == -1) + if (_pkt_Recv(ptr, ptrlen, seq, crypted, pos, &buflen, &next, &nextlen) == -1) break; else { pos += buflen; @@ -421,6 +474,7 @@ pktRecv(int s, u_int * __restrict crypted, u_char * __ } free(buf); + return flg; } @@ -457,8 +511,37 @@ cryptBuffer(u_char *buf, int rlen, u_int ctr) memcpy(ivec + 8, &ctr, sizeof ctr); memcpy(ivec + 12, &rctr, sizeof rctr); - if (io_ctr_AES(buf, rlen, &str, (u_char*) "_ansh_ELWIX_", ivec) == -1) + if (io_ctr_AES(buf, rlen, &str, (u_char*) Key, ivec) == -1) return NULL; return str; +} + +int +stopProcess(sched_root_task_t * __restrict root, proc_head_t * __restrict h, pid_t pid, sched_task_func_t func) +{ + struct tagProc *p; + + FTRACE(3); + + SLIST_FOREACH(p, h, proc_next) + if (p->proc_pid == pid) { + break; + } + VERB(3) LOG("pid=%d found=%p\n", pid, p); + if (!p) + return 1; + + ioFreePTY(p->proc_pty, p->proc_ttyname); + if (p->proc_pty) + schedCancelby(root, NULL, CRITERIA_FD, (void*) ((intptr_t) p->proc_pty), NULL); + + p->proc_pty = 0; + p->proc_pid = 0; + p->proc_seq = 0; + p->proc_flg = ANSH_FLG_EOF; + p->proc_rlen_[FD2NET] = 0; + + schedCallOnce(root, func, p, p->proc_sock); + return 0; }