/[LeafOK_CVS]/lbbs/src/net_server.c
ViewVC logotype

Contents of /lbbs/src/net_server.c

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1.63 - (show annotations)
Sun Jun 22 01:40:03 2025 UTC (8 months, 3 weeks ago) by sysadm
Branch: MAIN
Changes since 1.62: +1 -0 lines
Content type: text/x-csrc
Add ssh-rsa into SSH_BIND_OPTIONS_HOSTKEY_ALGORITHMS for backward compatibility

1 /***************************************************************************
2 net_server.c - description
3 -------------------
4 Copyright : (C) 2004-2025 by Leaflet
5 Email : leaflet@leafok.com
6 ***************************************************************************/
7
8 /***************************************************************************
9 * *
10 * This program is free software; you can redistribute it and/or modify *
11 * it under the terms of the GNU General Public License as published by *
12 * the Free Software Foundation; either version 3 of the License, or *
13 * (at your option) any later version. *
14 * *
15 ***************************************************************************/
16
17 #include "bbs.h"
18 #include "bbs_main.h"
19 #include "common.h"
20 #include "database.h"
21 #include "file_loader.h"
22 #include "io.h"
23 #include "init.h"
24 #include "log.h"
25 #include "login.h"
26 #include "menu.h"
27 #include "net_server.h"
28 #include "section_list_loader.h"
29 #include <errno.h>
30 #include <fcntl.h>
31 #include <signal.h>
32 #include <stdlib.h>
33 #include <string.h>
34 #include <unistd.h>
35 #include <arpa/inet.h>
36 #include <libssh/callbacks.h>
37 #include <libssh/libssh.h>
38 #include <libssh/server.h>
39 #include <netinet/in.h>
40 #include <sys/epoll.h>
41 #include <sys/socket.h>
42 #include <sys/syscall.h>
43 #include <sys/types.h>
44 #include <sys/wait.h>
45 #include <systemd/sd-daemon.h>
46
47 struct process_sockaddr_t
48 {
49 pid_t pid;
50 in_addr_t s_addr;
51 };
52 typedef struct process_sockaddr_t PROCESS_SOCKADDR;
53
54 static PROCESS_SOCKADDR process_sockaddr_pool[MAX_CLIENT_LIMIT];
55
56 #define SSH_AUTH_MAX_DURATION (60 * 1000) // milliseconds
57
58 struct ssl_server_cb_data_t
59 {
60 int tries;
61 int error;
62 };
63
64 static int auth_password(ssh_session session, const char *user,
65 const char *password, void *userdata)
66 {
67 struct ssl_server_cb_data_t *p_data = userdata;
68 int ret;
69
70 if (strcmp(user, "guest") == 0)
71 {
72 ret = load_guest_info();
73 }
74 else
75 {
76 ret = check_user(user, password);
77 }
78
79 if (ret == 0)
80 {
81 return SSH_AUTH_SUCCESS;
82 }
83
84 if ((++(p_data->tries)) >= BBS_login_retry_times)
85 {
86 p_data->error = 1;
87 }
88
89 return SSH_AUTH_DENIED;
90 }
91
92 static int pty_request(ssh_session session, ssh_channel channel, const char *term,
93 int x, int y, int px, int py, void *userdata)
94 {
95 return 0;
96 }
97
98 static int shell_request(ssh_session session, ssh_channel channel, void *userdata)
99 {
100 return 0;
101 }
102
103 static struct ssh_channel_callbacks_struct channel_cb = {
104 .channel_pty_request_function = pty_request,
105 .channel_shell_request_function = shell_request};
106
107 static ssh_channel new_session_channel(ssh_session session, void *userdata)
108 {
109 if (SSH_channel != NULL)
110 {
111 return NULL;
112 }
113
114 SSH_channel = ssh_channel_new(session);
115 ssh_callbacks_init(&channel_cb);
116 ssh_set_channel_callbacks(SSH_channel, &channel_cb);
117
118 return SSH_channel;
119 }
120
121 static int fork_server(void)
122 {
123 ssh_event event;
124 int pid;
125 int i;
126 int ret;
127
128 struct ssl_server_cb_data_t cb_data = {
129 .tries = 0,
130 .error = 0,
131 };
132
133 struct ssh_server_callbacks_struct cb = {
134 .userdata = &cb_data,
135 .auth_password_function = auth_password,
136 .channel_open_request_session_function = new_session_channel,
137 };
138
139 pid = fork();
140
141 if (pid > 0) // Parent process
142 {
143 SYS_child_process_count++;
144 log_common("Child process (%d) start\n", pid);
145 return pid;
146 }
147 else if (pid < 0) // Error
148 {
149 log_error("fork() error (%d)\n", errno);
150 return -1;
151 }
152
153 // Child process
154
155 if (close(socket_server[0]) == -1 || close(socket_server[1]) == -1)
156 {
157 log_error("Close server socket failed\n");
158 }
159
160 SSH_session = ssh_new();
161
162 if (SSH_v2)
163 {
164 if (ssh_bind_accept_fd(sshbind, SSH_session, socket_client) != SSH_OK)
165 {
166 log_error("ssh_bind_accept_fd() error: %s\n", ssh_get_error(SSH_session));
167 goto cleanup;
168 }
169
170 ssh_bind_free(sshbind);
171
172 ssh_callbacks_init(&cb);
173 ssh_set_server_callbacks(SSH_session, &cb);
174
175 if (ssh_handle_key_exchange(SSH_session))
176 {
177 log_error("ssh_handle_key_exchange() error: %s\n", ssh_get_error(SSH_session));
178 goto cleanup;
179 }
180 ssh_set_auth_methods(SSH_session, SSH_AUTH_METHOD_PASSWORD);
181
182 event = ssh_event_new();
183 ssh_event_add_session(event, SSH_session);
184
185 for (i = 0; i < SSH_AUTH_MAX_DURATION && !SYS_server_exit && !cb_data.error && SSH_channel == NULL; i += 100)
186 {
187 ret = ssh_event_dopoll(event, 100); // 0.1 second
188 if (ret == SSH_ERROR)
189 {
190 log_error("ssh_event_dopoll() error: %s\n", ssh_get_error(SSH_session));
191 goto cleanup;
192 }
193 }
194
195 if (cb_data.error)
196 {
197 log_error("SSH auth error, tried %d times\n", cb_data.tries);
198 goto cleanup;
199 }
200 }
201
202 // Redirect Input
203 close(STDIN_FILENO);
204 if (dup2(socket_client, STDIN_FILENO) == -1)
205 {
206 log_error("Redirect stdin to client socket failed\n");
207 goto cleanup;
208 }
209
210 // Redirect Output
211 close(STDOUT_FILENO);
212 if (dup2(socket_client, STDOUT_FILENO) == -1)
213 {
214 log_error("Redirect stdout to client socket failed\n");
215 goto cleanup;
216 }
217
218 SYS_child_process_count = 0;
219
220 bbs_main();
221
222 cleanup:
223 // Child process exit
224 SYS_server_exit = 1;
225
226 if (SSH_v2)
227 {
228 ssh_channel_free(SSH_channel);
229 ssh_disconnect(SSH_session);
230 }
231 else if (close(socket_client) == -1)
232 {
233 log_error("Close client socket failed\n");
234 }
235
236 ssh_free(SSH_session);
237 ssh_finalize();
238
239 // Close Input and Output for client
240 close(STDIN_FILENO);
241 close(STDOUT_FILENO);
242
243 log_common("Process exit normally\n");
244 log_end();
245
246 _exit(0);
247
248 return 0;
249 }
250
251 int net_server(const char *hostaddr, in_port_t port[])
252 {
253 unsigned int addrlen;
254 int ret;
255 int flags[2];
256 struct sockaddr_in sin;
257 struct epoll_event ev, events[MAX_EVENTS];
258 int nfds, epollfd;
259 siginfo_t siginfo;
260 int sd_notify_stopping = 0;
261 MENU_SET *p_bbs_menu_new;
262 int i, j;
263 pid_t pid;
264 int ssh_log_level = SSH_LOG_NOLOG;
265
266 ssh_init();
267
268 sshbind = ssh_bind_new();
269
270 if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDADDR, hostaddr) < 0 ||
271 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDPORT, &port) < 0 ||
272 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_KEYFILE) < 0 ||
273 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY_ALGORITHMS, "ssh-rsa,rsa-sha2-512,rsa-sha2-256") < 0 ||
274 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_LOG_VERBOSITY, &ssh_log_level) < 0)
275 {
276 log_error("Error setting SSH bind options: %s\n", ssh_get_error(sshbind));
277 ssh_bind_free(sshbind);
278 return -1;
279 }
280
281 epollfd = epoll_create1(0);
282 if (epollfd < 0)
283 {
284 log_error("epoll_create1() error (%d)\n", errno);
285 return -1;
286 }
287
288 // Server socket
289 for (i = 0; i < 2; i++)
290 {
291 socket_server[i] = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
292
293 if (socket_server[i] < 0)
294 {
295 log_error("Create socket_server error (%d)\n", errno);
296 return -1;
297 }
298
299 sin.sin_family = AF_INET;
300 sin.sin_addr.s_addr = (hostaddr[0] != '\0' ? inet_addr(hostaddr) : INADDR_ANY);
301 sin.sin_port = htons(port[i]);
302
303 // Reuse address and port
304 flags[i] = 1;
305 if (setsockopt(socket_server[i], SOL_SOCKET, SO_REUSEADDR, &flags[i], sizeof(flags[i])) < 0)
306 {
307 log_error("setsockopt SO_REUSEADDR error (%d)\n", errno);
308 }
309 if (setsockopt(socket_server[i], SOL_SOCKET, SO_REUSEPORT, &flags[i], sizeof(flags[i])) < 0)
310 {
311 log_error("setsockopt SO_REUSEPORT error (%d)\n", errno);
312 }
313
314 if (bind(socket_server[i], (struct sockaddr *)&sin, sizeof(sin)) < 0)
315 {
316 log_error("Bind address %s:%u error (%d)\n",
317 inet_ntoa(sin.sin_addr), ntohs(sin.sin_port), errno);
318 return -1;
319 }
320
321 if (listen(socket_server[i], 10) < 0)
322 {
323 log_error("Telnet socket listen error (%d)\n", errno);
324 return -1;
325 }
326
327 log_common("Listening at %s:%u\n", inet_ntoa(sin.sin_addr), ntohs(sin.sin_port));
328
329 ev.events = EPOLLIN;
330 ev.data.fd = socket_server[i];
331 if (epoll_ctl(epollfd, EPOLL_CTL_ADD, socket_server[i], &ev) == -1)
332 {
333 log_error("epoll_ctl(socket_server[%d]) error (%d)\n", i, errno);
334 if (close(epollfd) < 0)
335 {
336 log_error("close(epoll) error (%d)\n");
337 }
338 return -1;
339 }
340
341 flags[i] = fcntl(socket_server[i], F_GETFL, 0);
342 fcntl(socket_server[i], F_SETFL, flags[i] | O_NONBLOCK);
343 }
344
345 // Startup complete
346 sd_notifyf(0, "READY=1\n"
347 "STATUS=Listening at %s:%d (Telnet) and %s:%d (SSH2)\n"
348 "MAINPID=%d",
349 hostaddr, port[0], hostaddr, port[1], getpid());
350
351 while (!SYS_server_exit || SYS_child_process_count > 0)
352 {
353 if (SYS_server_exit && !sd_notify_stopping)
354 {
355 sd_notify(0, "STOPPING=1");
356 sd_notify_stopping = 1;
357 }
358
359 while ((SYS_child_exit || SYS_server_exit) && SYS_child_process_count > 0)
360 {
361 SYS_child_exit = 0;
362
363 siginfo.si_pid = 0;
364 ret = waitid(P_ALL, 0, &siginfo, WEXITED | WNOHANG);
365 if (ret == 0 && siginfo.si_pid > 0)
366 {
367 SYS_child_exit = 1; // Retry waitid
368
369 SYS_child_process_count--;
370 log_common("Child process (%d) exited\n", siginfo.si_pid);
371
372 if (siginfo.si_pid != section_list_loader_pid)
373 {
374 i = 0;
375 for (; i < BBS_max_client; i++)
376 {
377 if (process_sockaddr_pool[i].pid == siginfo.si_pid)
378 {
379 process_sockaddr_pool[i].pid = 0;
380 break;
381 }
382 }
383 if (i >= BBS_max_client)
384 {
385 log_error("Child process (%d) not found in process sockaddr pool\n", siginfo.si_pid);
386 }
387 }
388 }
389 else if (ret == 0)
390 {
391 break;
392 }
393 else if (ret < 0)
394 {
395 log_error("Error in waitid: %d\n", errno);
396 break;
397 }
398 }
399
400 if (SYS_server_exit && !SYS_child_exit && SYS_child_process_count > 0)
401 {
402 log_common("Notify %d child process to exit\n", SYS_child_process_count);
403 if (kill(0, SIGTERM) < 0)
404 {
405 log_error("Send SIGTERM signal failed (%d)\n", errno);
406 }
407
408 sd_notifyf(0, "STATUS=Waiting for %d child process to exit", SYS_child_process_count);
409 }
410
411 if (SYS_conf_reload && !SYS_server_exit)
412 {
413 SYS_conf_reload = 0;
414 sd_notify(0, "RELOADING=1");
415
416 // Reload configuration
417 if (load_conf(CONF_BBSD) < 0)
418 {
419 log_error("Reload conf failed\n");
420 }
421
422 p_bbs_menu_new = calloc(1, sizeof(MENU_SET));
423 if (p_bbs_menu_new == NULL)
424 {
425 log_error("OOM: calloc(MENU_SET)\n");
426 }
427 else if (load_menu(p_bbs_menu_new, CONF_MENU) < 0)
428 {
429 unload_menu(p_bbs_menu_new);
430 free(p_bbs_menu_new);
431 p_bbs_menu_new = NULL;
432
433 log_error("Reload menu failed\n");
434 }
435 else
436 {
437 unload_menu(p_bbs_menu);
438 free(p_bbs_menu);
439
440 p_bbs_menu = p_bbs_menu_new;
441 p_bbs_menu_new = NULL;
442
443 log_common("Reload menu successfully\n");
444 }
445
446 sd_notify(0, "READY=1");
447 }
448
449 if (SYS_data_file_reload && !SYS_server_exit)
450 {
451 SYS_data_file_reload = 0;
452 sd_notify(0, "RELOADING=1");
453
454 for (int i = 0; i < data_files_load_startup_count; i++)
455 {
456 if (load_file(data_files_load_startup[i]) < 0)
457 {
458 log_error("load_file_mmap(%s) error\n", data_files_load_startup[i]);
459 }
460 }
461
462 log_common("Reload data files successfully\n");
463 sd_notify(0, "READY=1");
464 }
465
466 if (SYS_section_list_reload && !SYS_server_exit)
467 {
468 SYS_section_list_reload = 0;
469
470 if (section_list_loader_reload() < 0)
471 {
472 log_error("ksection_list_loader_reload() failed\n");
473 }
474 }
475
476 nfds = epoll_wait(epollfd, events, MAX_EVENTS, 100); // 0.1 second
477
478 if (nfds < 0)
479 {
480 if (errno != EINTR)
481 {
482 log_error("epoll_wait() error (%d)\n", errno);
483 break;
484 }
485 continue;
486 }
487
488 // Stop accept new connection on exit
489 if (SYS_server_exit)
490 {
491 continue;
492 }
493
494 for (int i = 0; i < nfds; i++)
495 {
496 if (events[i].data.fd == socket_server[0] || events[i].data.fd == socket_server[1])
497 {
498 SSH_v2 = (events[i].data.fd == socket_server[1] ? 1 : 0);
499
500 while (!SYS_server_exit) // Accept all incoming connections until error
501 {
502 addrlen = sizeof(sin);
503 socket_client = accept(socket_server[SSH_v2], (struct sockaddr *)&sin, &addrlen);
504 if (socket_client < 0)
505 {
506 if (errno == EAGAIN || errno == EWOULDBLOCK)
507 {
508 break;
509 }
510 else if (errno == EINTR)
511 {
512 continue;
513 }
514 else
515 {
516 log_error("accept(socket_server) error (%d)\n", errno);
517 break;
518 }
519 }
520
521 strncpy(hostaddr_client, inet_ntoa(sin.sin_addr), sizeof(hostaddr_client) - 1);
522 hostaddr_client[sizeof(hostaddr_client) - 1] = '\0';
523
524 port_client = ntohs(sin.sin_port);
525
526 log_common("Accept %sconnection from %s:%d\n", (SSH_v2 ? "" : "SSH2 "), hostaddr_client, port_client);
527
528 if (SYS_child_process_count - 1 < BBS_max_client)
529 {
530 j = 0;
531 for (i = 0; i < BBS_max_client; i++)
532 {
533 if (process_sockaddr_pool[i].pid != 0 && process_sockaddr_pool[i].s_addr == sin.sin_addr.s_addr)
534 {
535 j++;
536 if (j >= BBS_max_client_per_ip)
537 {
538 log_common("Too many client connections (%d) from %s\n", j, hostaddr_client);
539 break;
540 }
541 }
542 }
543
544 if (j < BBS_max_client_per_ip)
545 {
546 if ((pid = fork_server()) < 0)
547 {
548 log_error("fork_server() error\n");
549 }
550 else if (pid > 0)
551 {
552 i = 0;
553 for (; i < BBS_max_client; i++)
554 {
555 if (process_sockaddr_pool[i].pid == 0)
556 {
557 break;
558 }
559 }
560
561 if (i >= BBS_max_client)
562 {
563 log_error("Process sockaddr pool depleted\n");
564 }
565 else
566 {
567 process_sockaddr_pool[i].pid = pid;
568 process_sockaddr_pool[i].s_addr = sin.sin_addr.s_addr;
569 }
570 }
571 }
572 }
573 else
574 {
575 log_error("Rejected client connection over limit (%d)\n", SYS_child_process_count - 1);
576 }
577
578 if (close(socket_client) == -1)
579 {
580 log_error("close(socket_lient) error (%d)\n", errno);
581 }
582 }
583 }
584 }
585 }
586
587 if (close(epollfd) < 0)
588 {
589 log_error("close(epoll) error (%d)\n");
590 }
591
592 for (i = 0; i < 2; i++)
593 {
594 fcntl(socket_server[i], F_SETFL, flags[i]);
595
596 if (close(socket_server[i]) == -1)
597 {
598 log_error("Close server socket failed\n");
599 }
600 }
601
602 ssh_bind_free(sshbind);
603 ssh_finalize();
604
605 return 0;
606 }

webmaster@leafok.com
ViewVC Help
Powered by ViewVC 1.3.0-beta1