| 40 |
#include <netinet/in.h> |
#include <netinet/in.h> |
| 41 |
#include <sys/ioctl.h> |
#include <sys/ioctl.h> |
| 42 |
#include <sys/socket.h> |
#include <sys/socket.h> |
| 43 |
|
#include <sys/stat.h> |
| 44 |
#include <sys/types.h> |
#include <sys/types.h> |
| 45 |
#include <sys/wait.h> |
#include <sys/wait.h> |
| 46 |
|
|
| 115 |
else |
else |
| 116 |
{ |
{ |
| 117 |
ret = check_user(user, password); |
ret = check_user(user, password); |
| 118 |
|
if (ret == 2) // Enforce update user agreement |
| 119 |
|
{ |
| 120 |
|
BBS_update_eula = 1; |
| 121 |
|
ret = 0; |
| 122 |
|
} |
| 123 |
} |
} |
| 124 |
|
|
| 125 |
if (ret == 0) |
if (ret == 0) |
| 428 |
log_error("Error setting SSH options: %s\n", ssh_get_error(SSH_session)); |
log_error("Error setting SSH options: %s\n", ssh_get_error(SSH_session)); |
| 429 |
goto cleanup; |
goto cleanup; |
| 430 |
} |
} |
| 431 |
|
|
| 432 |
|
ssh_set_blocking(SSH_session, 0); |
| 433 |
} |
} |
| 434 |
|
|
| 435 |
// Redirect Input |
// Redirect Input |
| 515 |
|
|
| 516 |
int net_server(const char *hostaddr, in_port_t port[]) |
int net_server(const char *hostaddr, in_port_t port[]) |
| 517 |
{ |
{ |
| 518 |
|
struct stat file_stat; |
| 519 |
unsigned int addrlen; |
unsigned int addrlen; |
| 520 |
int ret; |
int ret; |
| 521 |
int flags_server[2]; |
int flags_server[2]; |
| 532 |
time_t tm_notify_child_exit = time(NULL); |
time_t tm_notify_child_exit = time(NULL); |
| 533 |
int i, j; |
int i, j; |
| 534 |
pid_t pid; |
pid_t pid; |
| 535 |
|
int ssh_key_valid = 0; |
| 536 |
int ssh_log_level = SSH_LOG_NOLOG; |
int ssh_log_level = SSH_LOG_NOLOG; |
| 537 |
|
|
| 538 |
#ifdef HAVE_SYSTEMD_SD_DAEMON_H |
#ifdef HAVE_SYSTEMD_SD_DAEMON_H |
| 543 |
|
|
| 544 |
sshbind = ssh_bind_new(); |
sshbind = ssh_bind_new(); |
| 545 |
|
|
| 546 |
|
if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_RSA_KEY_FILE) < 0) |
| 547 |
|
{ |
| 548 |
|
log_error("Error loading SSH RSA key: %s\n", SSH_HOST_RSA_KEY_FILE); |
| 549 |
|
} |
| 550 |
|
else |
| 551 |
|
{ |
| 552 |
|
ssh_key_valid = 1; |
| 553 |
|
} |
| 554 |
|
if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_ED25519_KEY_FILE) < 0) |
| 555 |
|
{ |
| 556 |
|
log_error("Error loading SSH ED25519 key: %s\n", SSH_HOST_ED25519_KEY_FILE); |
| 557 |
|
} |
| 558 |
|
else |
| 559 |
|
{ |
| 560 |
|
ssh_key_valid = 1; |
| 561 |
|
} |
| 562 |
|
if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_ECDSA_KEY_FILE) < 0) |
| 563 |
|
{ |
| 564 |
|
log_error("Error loading SSH ECDSA key: %s\n", SSH_HOST_ECDSA_KEY_FILE); |
| 565 |
|
} |
| 566 |
|
else |
| 567 |
|
{ |
| 568 |
|
ssh_key_valid = 1; |
| 569 |
|
} |
| 570 |
|
|
| 571 |
|
if (!ssh_key_valid) |
| 572 |
|
{ |
| 573 |
|
log_error("Error: no valid SSH host key\n"); |
| 574 |
|
ssh_bind_free(sshbind); |
| 575 |
|
return -1; |
| 576 |
|
} |
| 577 |
|
|
| 578 |
if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDADDR, hostaddr) < 0 || |
if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDADDR, hostaddr) < 0 || |
| 579 |
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDPORT, &port) < 0 || |
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDPORT, &port) < 0 || |
| 580 |
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_KEYFILE) < 0 || |
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY_ALGORITHMS, "+ssh-rsa") < 0 || |
|
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY_ALGORITHMS, "ssh-rsa,rsa-sha2-512,rsa-sha2-256") < 0 || |
|
| 581 |
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_LOG_VERBOSITY, &ssh_log_level) < 0) |
ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_LOG_VERBOSITY, &ssh_log_level) < 0) |
| 582 |
{ |
{ |
| 583 |
log_error("Error setting SSH bind options: %s\n", ssh_get_error(sshbind)); |
log_error("Error setting SSH bind options: %s\n", ssh_get_error(sshbind)); |
| 655 |
fcntl(socket_server[i], F_SETFL, flags_server[i] | O_NONBLOCK); |
fcntl(socket_server[i], F_SETFL, flags_server[i] | O_NONBLOCK); |
| 656 |
} |
} |
| 657 |
|
|
| 658 |
|
ssh_bind_set_blocking(sshbind, 0); |
| 659 |
|
|
| 660 |
hash_dict_pid_sockaddr = hash_dict_create(MAX_CLIENT_LIMIT); |
hash_dict_pid_sockaddr = hash_dict_create(MAX_CLIENT_LIMIT); |
| 661 |
if (hash_dict_pid_sockaddr == NULL) |
if (hash_dict_pid_sockaddr == NULL) |
| 662 |
{ |
{ |
| 721 |
} |
} |
| 722 |
else |
else |
| 723 |
{ |
{ |
| 724 |
ret = hash_dict_inc(hash_dict_sockaddr_count, (uint64_t)j, -1); |
ret = hash_dict_inc(hash_dict_sockaddr_count, (in_addr_t)j, -1); |
| 725 |
if (ret < 0) |
if (ret <= 0) |
| 726 |
{ |
{ |
| 727 |
log_error("hash_dict_inc(hash_dict_sockaddr_count, %d, -1) error\n", j); |
log_error("hash_dict_inc(hash_dict_sockaddr_count, %d, -1) error: %d\n", (in_addr_t)j, ret); |
| 728 |
} |
} |
| 729 |
|
|
| 730 |
ret = hash_dict_del(hash_dict_pid_sockaddr, (uint64_t)pid); |
ret = hash_dict_del(hash_dict_pid_sockaddr, (uint64_t)pid); |
| 810 |
log_error("Reload BWF conf failed\n"); |
log_error("Reload BWF conf failed\n"); |
| 811 |
} |
} |
| 812 |
|
|
| 813 |
|
// Get EULA modification tm |
| 814 |
|
if (stat(DATA_EULA, &file_stat) == -1) |
| 815 |
|
{ |
| 816 |
|
log_error("stat(%s) error\n", DATA_EULA, errno); |
| 817 |
|
} |
| 818 |
|
else |
| 819 |
|
{ |
| 820 |
|
BBS_eula_tm = file_stat.st_mtim.tv_sec; |
| 821 |
|
} |
| 822 |
|
|
| 823 |
if (detach_menu_shm(&bbs_menu) < 0) |
if (detach_menu_shm(&bbs_menu) < 0) |
| 824 |
{ |
{ |
| 825 |
log_error("detach_menu_shm(bbs_menu) error\n"); |
log_error("detach_menu_shm(bbs_menu) error\n"); |
| 839 |
log_error("load_menu(top10_menu) error\n"); |
log_error("load_menu(top10_menu) error\n"); |
| 840 |
unload_menu(&top10_menu); |
unload_menu(&top10_menu); |
| 841 |
} |
} |
| 842 |
|
top10_menu.allow_exit = 1; |
| 843 |
|
|
| 844 |
for (int i = 0; i < data_files_load_startup_count; i++) |
for (int i = 0; i < data_files_load_startup_count; i++) |
| 845 |
{ |
{ |
| 937 |
|
|
| 938 |
port_client = ntohs(sin.sin_port); |
port_client = ntohs(sin.sin_port); |
| 939 |
|
|
|
log_common("Accept %s connection from %s:%d\n", (SSH_v2 ? "SSH" : "telnet"), hostaddr_client, port_client); |
|
|
|
|
| 940 |
if (SYS_child_process_count - 1 < BBS_max_client) |
if (SYS_child_process_count - 1 < BBS_max_client) |
| 941 |
{ |
{ |
| 942 |
j = 0; |
j = 0; |
| 960 |
log_error("hash_dict_set(hash_dict_pid_sockaddr, %d, %s) error\n", pid, hostaddr_client); |
log_error("hash_dict_set(hash_dict_pid_sockaddr, %d, %s) error\n", pid, hostaddr_client); |
| 961 |
} |
} |
| 962 |
|
|
| 963 |
ret = hash_dict_inc(hash_dict_sockaddr_count, (uint64_t)sin.sin_addr.s_addr, 1); |
if (j == 0) |
| 964 |
if (ret < 0) |
{ |
| 965 |
|
// First connection from this IP |
| 966 |
|
log_common("Accept %s connection from %s:%d\n", |
| 967 |
|
(SSH_v2 ? "SSH" : "telnet"), hostaddr_client, port_client); |
| 968 |
|
|
| 969 |
|
ret = hash_dict_set(hash_dict_sockaddr_count, (uint64_t)sin.sin_addr.s_addr, 1); |
| 970 |
|
if (ret < 0) |
| 971 |
|
{ |
| 972 |
|
log_error("hash_dict_set(hash_dict_sockaddr_count, %s, 1) error\n", hostaddr_client); |
| 973 |
|
} |
| 974 |
|
} |
| 975 |
|
else |
| 976 |
{ |
{ |
| 977 |
log_error("hash_dict_inc(hash_dict_sockaddr_count, %s, %d) error\n", hostaddr_client, 1); |
// Increase connection count from this IP |
| 978 |
|
log_common("Accept %s connection from %s:%d, already have %d connections\n", |
| 979 |
|
(SSH_v2 ? "SSH" : "telnet"), hostaddr_client, port_client, j); |
| 980 |
|
|
| 981 |
|
ret = hash_dict_inc(hash_dict_sockaddr_count, (uint64_t)sin.sin_addr.s_addr, 1); |
| 982 |
|
if (ret <= 0) |
| 983 |
|
{ |
| 984 |
|
log_error("hash_dict_inc(hash_dict_sockaddr_count, %s, 1) error: %d\n", hostaddr_client, ret); |
| 985 |
|
} |
| 986 |
} |
} |
| 987 |
} |
} |
| 988 |
} |
} |
| 989 |
else |
else |
| 990 |
{ |
{ |
| 991 |
log_error("Rejected client connection from %s over limit per IP (%d)\n", hostaddr_client, BBS_max_client_per_ip); |
log_error("Rejected %s connection from %s:%d over limit per IP (%d >= %d)\n", |
| 992 |
|
(SSH_v2 ? "SSH" : "telnet"), hostaddr_client, port_client, j, BBS_max_client_per_ip); |
| 993 |
} |
} |
| 994 |
} |
} |
| 995 |
else |
else |
| 996 |
{ |
{ |
| 997 |
log_error("Rejected client connection over limit (%d)\n", SYS_child_process_count - 1); |
log_error("Rejected %s connection from %s:%d over limit (%d >= %d)\n", |
| 998 |
|
(SSH_v2 ? "SSH" : "telnet"), hostaddr_client, port_client, SYS_child_process_count - 1, BBS_max_client); |
| 999 |
} |
} |
| 1000 |
|
|
| 1001 |
if (close(socket_client) == -1) |
if (close(socket_client) == -1) |