123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625 |
- const char control_c_id[] = "$Id$";
- #include "or.h"
- #define CONTROL_CMD_ERROR 0x0000
- #define CONTROL_CMD_DONE 0x0001
- #define CONTROL_CMD_SETCONF 0x0002
- #define CONTROL_CMD_GETCONF 0x0003
- #define CONTROL_CMD_CONFVALUE 0x0004
- #define CONTROL_CMD_SETEVENTS 0x0005
- #define CONTROL_CMD_EVENT 0x0006
- #define CONTROL_CMD_AUTHENTICATE 0x0007
- #define CONTROL_CMD_SAVECONF 0x0008
- #define _CONTROL_CMD_MAX_RECOGNIZED 0x0008
- #define ERR_UNSPECIFIED 0x0000
- #define ERR_INTERNAL 0x0001
- #define ERR_UNRECOGNIZED_TYPE 0x0002
- #define ERR_SYNTAX 0x0003
- #define ERR_UNRECOGNIZED_CONFIG_KEY 0x0004
- #define ERR_INVALID_CONFIG_VALUE 0x0005
- #define ERR_UNRECOGNIZED_EVENT_CODE 0x0006
- #define ERR_UNAUTHORIZED 0x0007
- #define ERR_REJECTED_AUTHENTICATION 0x0008
- #define _EVENT_MIN 0x0001
- #define EVENT_CIRCUIT_STATUS 0x0001
- #define EVENT_STREAM_STATUS 0x0002
- #define EVENT_OR_CONN_STATUS 0x0003
- #define EVENT_BANDWIDTH_USED 0x0004
- #define EVENT_WARNING 0x0005
- #define _EVENT_MAX 0x0005
- static const char * CONTROL_COMMANDS[] = {
- "error",
- "done",
- "setconf",
- "getconf",
- "confvalue",
- "setevents",
- "events",
- "authenticate",
- "saveconf",
- };
- static uint32_t global_event_mask = 0;
- #define EVENT_IS_INTERESTING(e) (global_event_mask & (1<<(e)))
- #define AUTHENTICATION_COOKIE_LEN 32
- static int authentication_cookie_is_set = 0;
- static char authentication_cookie[AUTHENTICATION_COOKIE_LEN];
- static void update_global_event_mask(void);
- static void send_control_message(connection_t *conn, uint16_t type,
- uint16_t len, const char *body);
- static void send_control_done(connection_t *conn);
- static void send_control_error(connection_t *conn, uint16_t error,
- const char *message);
- static void send_control_event(uint16_t event, uint16_t len, const char *body);
- static int handle_control_setconf(connection_t *conn, uint16_t len,
- char *body);
- static int handle_control_getconf(connection_t *conn, uint16_t len,
- const char *body);
- static int handle_control_setevents(connection_t *conn, uint16_t len,
- const char *body);
- static int handle_control_authenticate(connection_t *conn, uint16_t len,
- const char *body);
- static int handle_control_saveconf(connection_t *conn, uint16_t len,
- const char *body);
- static INLINE const char *
- control_cmd_to_string(uint16_t cmd)
- {
- return (cmd<=_CONTROL_CMD_MAX_RECOGNIZED) ? CONTROL_COMMANDS[cmd] : "Unknown";
- }
- static void update_global_event_mask(void)
- {
- connection_t **conns;
- int n_conns, i;
- global_event_mask = 0;
- get_connection_array(&conns, &n_conns);
- for (i = 0; i < n_conns; ++i) {
- if (conns[i]->type == CONN_TYPE_CONTROL &&
- conns[i]->state == CONTROL_CONN_STATE_OPEN) {
- global_event_mask |= conns[i]->event_mask;
- }
- }
- }
- static void
- send_control_message(connection_t *conn, uint16_t type, uint16_t len,
- const char *body)
- {
- char buf[4];
- tor_assert(conn);
- tor_assert(len || !body);
- tor_assert(type <= _CONTROL_CMD_MAX_RECOGNIZED);
- set_uint16(buf, htons(len));
- set_uint16(buf+2, htons(type));
- connection_write_to_buf(buf, 4, conn);
- if (len)
- connection_write_to_buf(body, len, conn);
- }
- static void
- send_control_done(connection_t *conn)
- {
- send_control_message(conn, CONTROL_CMD_DONE, 0, NULL);
- }
- static void
- send_control_error(connection_t *conn, uint16_t error, const char *message)
- {
- char buf[256];
- size_t len;
- set_uint16(buf, htons(error));
- len = strlen(message);
- tor_assert(len < (256-2));
- memcpy(buf+2, message, len);
- send_control_message(conn, CONTROL_CMD_ERROR, (uint16_t)(len+2), buf);
- }
- static void
- send_control_event(uint16_t event, uint16_t len, const char *body)
- {
- connection_t **conns;
- int n_conns, i;
- size_t buflen;
- char *buf;
- buflen = len + 2;
- buf = tor_malloc_zero(buflen);
- set_uint16(buf, htons(event));
- memcpy(buf+2, body, len);
- get_connection_array(&conns, &n_conns);
- for (i = 0; i < n_conns; ++i) {
- if (conns[i]->type == CONN_TYPE_CONTROL &&
- conns[i]->state == CONTROL_CONN_STATE_OPEN &&
- conns[i]->event_mask & (1<<event)) {
- send_control_message(conns[i], CONTROL_CMD_EVENT, (uint16_t)(buflen), buf);
- }
- }
- tor_free(buf);
- }
- static int
- handle_control_setconf(connection_t *conn, uint16_t len, char *body)
- {
- int r;
- struct config_line_t *lines=NULL;
- if (config_get_lines(body, &lines) < 0) {
- log_fn(LOG_WARN,"Controller gave us config lines we can't parse.");
- send_control_error(conn, ERR_SYNTAX, "Couldn't parse configuration");
- return 0;
- }
- if ((r=config_trial_assign(lines, 1)) < 0) {
- log_fn(LOG_WARN,"Controller gave us config lines that didn't validate.");
- if (r==-1) {
- send_control_error(conn, ERR_UNRECOGNIZED_CONFIG_KEY,
- "Unrecognized option");
- } else {
- send_control_error(conn, ERR_INVALID_CONFIG_VALUE,"Invalid option value");
- }
- config_free_lines(lines);
- return 0;
- }
- config_free_lines(lines);
- if (options_act() < 0) {
- log_fn(LOG_ERR,"Acting on config options left us in a broken state. Dying.");
- exit(1);
- }
- send_control_done(conn);
- return 0;
- }
- static int
- handle_control_getconf(connection_t *conn, uint16_t body_len, const char *body)
- {
- smartlist_t *questions = NULL;
- smartlist_t *answers = NULL;
- char *msg = NULL;
- size_t msg_len;
- or_options_t *options = get_options();
- questions = smartlist_create();
- smartlist_split_string(questions, body, "\n",
- SPLIT_SKIP_SPACE|SPLIT_IGNORE_BLANK, 0);
- answers = smartlist_create();
- SMARTLIST_FOREACH(questions, const char *, q,
- {
- int recognized = config_option_is_recognized(q);
- if (!recognized) {
- send_control_error(conn, ERR_UNRECOGNIZED_CONFIG_KEY, body);
- goto done;
- } else {
- struct config_line_t *answer = config_get_assigned_option(options,q);
- while (answer) {
- struct config_line_t *next;
- size_t alen = strlen(answer->key)+strlen(answer->value)+2;
- char *astr = tor_malloc(alen);
- tor_snprintf(astr, alen, "%s %s\n", answer->key, answer->value);
- smartlist_add(answers, astr);
- next = answer->next;
- tor_free(answer->key);
- tor_free(answer->value);
- tor_free(answer);
- answer = next;
- }
- }
- });
- msg = smartlist_join_strings(answers, "", 0, &msg_len);
- send_control_message(conn, CONTROL_CMD_CONFVALUE,
- (uint16_t)msg_len, msg_len?msg:NULL);
- done:
- if (answers) SMARTLIST_FOREACH(answers, char *, cp, tor_free(cp));
- if (questions) SMARTLIST_FOREACH(questions, char *, cp, tor_free(cp));
- smartlist_free(answers);
- smartlist_free(questions);
- tor_free(msg);
- return 0;
- }
- static int
- handle_control_setevents(connection_t *conn, uint16_t len, const char *body)
- {
- uint16_t event_code;
- uint32_t event_mask = 0;
- if (len % 2) {
- send_control_error(conn, ERR_SYNTAX,
- "Odd number of bytes in setevents message");
- return 0;
- }
- for (; len; len -= 2, body += 2) {
- event_code = ntohs(get_uint16(body));
- if (event_code < _EVENT_MIN || event_code > _EVENT_MAX) {
- send_control_error(conn, ERR_UNRECOGNIZED_EVENT_CODE,
- "Unrecognized event code");
- return 0;
- }
- event_mask |= (1 << event_code);
- }
- conn->event_mask = event_mask;
- update_global_event_mask();
- send_control_done(conn);
- return 0;
- }
- int
- decode_hashed_password(char *buf, const char *hashed)
- {
- char decoded[64];
- if (base64_decode(decoded, sizeof(decoded), hashed, strlen(hashed))
- != S2K_SPECIFIER_LEN+DIGEST_LEN) {
- return -1;
- }
- if (buf)
- memcpy(buf, decoded, sizeof(decoded));
- return 0;
- }
- static int
- handle_control_authenticate(connection_t *conn, uint16_t len, const char *body)
- {
- or_options_t *options = get_options();
- if (options->CookieAuthentication) {
- if (len == AUTHENTICATION_COOKIE_LEN &&
- !memcmp(authentication_cookie, body, len)) {
- goto ok;
- }
- } else if (options->HashedControlPassword) {
- char expected[S2K_SPECIFIER_LEN+DIGEST_LEN];
- char received[DIGEST_LEN];
- if (decode_hashed_password(expected, options->HashedControlPassword)<0) {
- log_fn(LOG_WARN,"Couldn't decode HashedControlPassword: invalid base64");
- goto err;
- }
- secret_to_key(received,DIGEST_LEN,body,len,expected);
- if (!memcmp(expected+S2K_SPECIFIER_LEN, received, DIGEST_LEN))
- goto ok;
- goto err;
- } else {
- if (len == 0) {
-
- goto ok;
- }
- goto err;
- }
- err:
- send_control_error(conn, ERR_REJECTED_AUTHENTICATION,"Authentication failed");
- return 0;
- ok:
- log_fn(LOG_INFO, "Authenticated control connection (%d)", conn->s);
- send_control_done(conn);
- conn->state = CONTROL_CONN_STATE_OPEN;
- return 0;
- }
- static int
- handle_control_saveconf(connection_t *conn, uint16_t len,
- const char *body)
- {
- if (save_current_config()<0) {
- send_control_error(conn, ERR_INTERNAL,
- "Unable to write configuration to disk.");
- } else {
- send_control_done(conn);
- }
- return 0;
- }
- int
- connection_control_finished_flushing(connection_t *conn) {
- tor_assert(conn);
- tor_assert(conn->type == CONN_TYPE_CONTROL);
- connection_stop_writing(conn);
- return 0;
- }
- int connection_control_reached_eof(connection_t *conn) {
- log_fn(LOG_INFO,"Control connection reached EOF. Closing.");
- connection_mark_for_close(conn);
- return 0;
- }
- int
- connection_control_process_inbuf(connection_t *conn) {
- uint16_t body_len, command_type;
- char *body;
- tor_assert(conn);
- tor_assert(conn->type == CONN_TYPE_CONTROL);
- again:
-
- switch (fetch_from_buf_control(conn->inbuf, &body_len, &command_type, &body))
- {
- case -1:
- tor_free(body);
- log_fn(LOG_WARN, "Error in control command. Failing.");
- return -1;
- case 0:
-
- return 0;
- case 1:
-
- break;
- default:
- tor_assert(0);
- }
-
- if (conn->state == CONTROL_CONN_STATE_NEEDAUTH &&
- command_type != CONTROL_CMD_AUTHENTICATE) {
- log_fn(LOG_WARN, "Rejecting '%s' command; authentication needed.",
- control_cmd_to_string(command_type));
- send_control_error(conn, ERR_UNAUTHORIZED, "Authentication required");
- tor_free(body);
- goto again;
- }
-
- switch (command_type)
- {
- case CONTROL_CMD_SETCONF:
- if (handle_control_setconf(conn, body_len, body))
- return -1;
- break;
- case CONTROL_CMD_GETCONF:
- if (handle_control_getconf(conn, body_len, body))
- return -1;
- break;
- case CONTROL_CMD_SETEVENTS:
- if (handle_control_setevents(conn, body_len, body))
- return -1;
- break;
- case CONTROL_CMD_AUTHENTICATE:
- if (handle_control_authenticate(conn, body_len, body))
- return -1;
- break;
- case CONTROL_CMD_SAVECONF:
- if (handle_control_saveconf(conn, body_len, body))
- return -1;
- break;
- case CONTROL_CMD_ERROR:
- case CONTROL_CMD_DONE:
- case CONTROL_CMD_CONFVALUE:
- case CONTROL_CMD_EVENT:
- log_fn(LOG_WARN, "Received client-only '%s' command; ignoring.",
- control_cmd_to_string(command_type));
- send_control_error(conn, ERR_UNRECOGNIZED_TYPE,
- "Command type only valid from server to tor client");
- break;
- default:
- log_fn(LOG_WARN, "Received unrecognized command type %d; ignoring.",
- (int)command_type);
- send_control_error(conn, ERR_UNRECOGNIZED_TYPE,
- "Unrecognized command type");
- break;
- }
- tor_free(body);
- goto again;
- }
- int
- control_event_circuit_status(circuit_t *circ, circuit_status_event_t tp)
- {
- char *path, *msg;
- size_t path_len;
- if (!EVENT_IS_INTERESTING(EVENT_CIRCUIT_STATUS))
- return 0;
- tor_assert(circ);
- tor_assert(CIRCUIT_IS_ORIGIN(circ));
- path = circuit_list_path(circ,0);
- path_len = strlen(path);
- msg = tor_malloc(1+4+path_len+1);
- msg[0] = (uint8_t) tp;
- set_uint32(msg+1, htonl(circ->global_identifier));
- strlcpy(msg+5,path,path_len+1);
- send_control_event(EVENT_STREAM_STATUS, (uint16_t)(path_len+6), msg);
- tor_free(path);
- tor_free(msg);
- return 0;
- }
- int
- control_event_stream_status(connection_t *conn, stream_status_event_t tp)
- {
- char *msg;
- size_t len;
- tor_assert(conn->type == CONN_TYPE_AP);
- tor_assert(conn->socks_request);
- if (!EVENT_IS_INTERESTING(EVENT_STREAM_STATUS))
- return 0;
- len = strlen(conn->socks_request->address);
- msg = tor_malloc(5+len+1);
- msg[0] = (uint8_t) tp;
- set_uint32(msg+1, htonl(conn->s));
- strlcpy(msg+5, conn->socks_request->address, len+1);
- send_control_event(EVENT_STREAM_STATUS, (uint16_t)(5+len+1), msg);
- tor_free(msg);
- return 0;
- }
- int
- control_event_or_conn_status(connection_t *conn,or_conn_status_event_t tp)
- {
- char buf[HEX_DIGEST_LEN+3];
- size_t len;
- tor_assert(conn->type == CONN_TYPE_OR);
- if (!EVENT_IS_INTERESTING(EVENT_OR_CONN_STATUS))
- return 0;
- buf[0] = (uint8_t)tp;
- strlcpy(buf+1,conn->nickname,sizeof(buf)-1);
- len = strlen(buf+1);
- send_control_event(EVENT_OR_CONN_STATUS, (uint16_t)(len+1), buf);
- return 0;
- }
- int
- control_event_bandwidth_used(uint32_t n_read, uint32_t n_written)
- {
- char buf[8];
- if (!EVENT_IS_INTERESTING(EVENT_BANDWIDTH_USED))
- return 0;
- set_uint32(buf, htonl(n_read));
- set_uint32(buf+4, htonl(n_written));
- send_control_event(EVENT_BANDWIDTH_USED, 8, buf);
- return 0;
- }
- void
- control_event_logmsg(int severity, const char *msg)
- {
- size_t len;
- if (severity > LOG_NOTICE)
- return;
- if (!EVENT_IS_INTERESTING(EVENT_WARNING))
- return;
- len = strlen(msg);
- send_control_event(EVENT_WARNING, (uint16_t)(len+1), msg);
- }
- int
- init_cookie_authentication(int enabled)
- {
- char fname[512];
- if (!enabled) {
- authentication_cookie_is_set = 0;
- return 0;
- }
- tor_snprintf(fname, sizeof(fname), "%s/control_auth_cookie",
- get_options()->DataDirectory);
- crypto_rand(authentication_cookie, AUTHENTICATION_COOKIE_LEN);
- authentication_cookie_is_set = 1;
- if (write_bytes_to_file(fname, authentication_cookie,
- AUTHENTICATION_COOKIE_LEN, 1)) {
- log_fn(LOG_WARN,"Error writing authentication cookie.");
- return -1;
- }
- return 0;
- }
|