/[LeafOK_CVS]/lbbs/src/net_server.c
ViewVC logotype

Contents of /lbbs/src/net_server.c

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1.99 - (show annotations)
Mon Dec 1 14:01:36 2025 UTC (3 months, 2 weeks ago) by sysadm
Branch: MAIN
Changes since 1.98: +11 -3 lines
Content type: text/x-csrc
Support SSH ECDSA key

1 /* SPDX-License-Identifier: GPL-3.0-or-later */
2 /*
3 * net_server
4 * - network server with SSH support
5 *
6 * Copyright (C) 2004-2025 Leaflet <leaflet@leafok.com>
7 */
8
9 #ifdef HAVE_CONFIG_H
10 #include "config.h"
11 #endif
12
13 #include "bbs.h"
14 #include "bbs_main.h"
15 #include "bwf.h"
16 #include "common.h"
17 #include "database.h"
18 #include "file_loader.h"
19 #include "hash_dict.h"
20 #include "io.h"
21 #include "init.h"
22 #include "log.h"
23 #include "login.h"
24 #include "menu.h"
25 #include "net_server.h"
26 #include "section_list.h"
27 #include "section_list_loader.h"
28 #include <errno.h>
29 #include <fcntl.h>
30 #include <pty.h>
31 #include <signal.h>
32 #include <stdlib.h>
33 #include <string.h>
34 #include <unistd.h>
35 #include <utmp.h>
36 #include <arpa/inet.h>
37 #include <libssh/callbacks.h>
38 #include <libssh/libssh.h>
39 #include <libssh/server.h>
40 #include <netinet/in.h>
41 #include <sys/ioctl.h>
42 #include <sys/socket.h>
43 #include <sys/types.h>
44 #include <sys/wait.h>
45
46 #ifdef HAVE_SYS_EPOLL_H
47 #include <sys/epoll.h>
48 #else
49 #include <poll.h>
50 #endif
51
52 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
53 #include <systemd/sd-daemon.h>
54 #endif
55
56 enum _net_server_constant_t
57 {
58 WAIT_CHILD_PROCESS_EXIT_TIMEOUT = 5, // second
59 WAIT_CHILD_PROCESS_KILL_TIMEOUT = 1, // second
60
61 SSH_AUTH_MAX_DURATION = 60 * 1000, // milliseconds
62 };
63
64 /* A userdata struct for session. */
65 struct session_data_struct
66 {
67 int tries;
68 int error;
69 };
70
71 /* A userdata struct for channel. */
72 struct channel_data_struct
73 {
74 /* pid of the child process the channel will spawn. */
75 pid_t pid;
76 /* For PTY allocation */
77 socket_t pty_master;
78 socket_t pty_slave;
79 /* For communication with the child process. */
80 socket_t child_stdin;
81 socket_t child_stdout;
82 /* Only used for subsystem and exec requests. */
83 socket_t child_stderr;
84 /* Event which is used to poll the above descriptors. */
85 ssh_event event;
86 /* Terminal size struct. */
87 struct winsize *winsize;
88 };
89
90 static int socket_server[2];
91 static int socket_client;
92
93 #ifdef HAVE_SYS_EPOLL_H
94 static int epollfd_server = -1;
95 #endif
96
97 static ssh_bind sshbind;
98
99 static HASH_DICT *hash_dict_pid_sockaddr = NULL;
100 static HASH_DICT *hash_dict_sockaddr_count = NULL;
101
102 static const char SFTP_SERVER_PATH[] = "/usr/lib/sftp-server";
103
104 static int auth_password(ssh_session session, const char *user,
105 const char *password, void *userdata)
106 {
107 struct session_data_struct *sdata = (struct session_data_struct *)userdata;
108 int ret;
109
110 if (strcmp(user, "guest") == 0)
111 {
112 ret = load_guest_info();
113 }
114 else
115 {
116 ret = check_user(user, password);
117 }
118
119 if (ret == 0)
120 {
121 return SSH_AUTH_SUCCESS;
122 }
123
124 if ((++(sdata->tries)) >= BBS_login_retry_times)
125 {
126 sdata->error = 1;
127 }
128
129 return SSH_AUTH_DENIED;
130 }
131
132 static int pty_request(ssh_session session, ssh_channel channel, const char *term,
133 int cols, int rows, int px, int py, void *userdata)
134 {
135 struct channel_data_struct *cdata = (struct channel_data_struct *)userdata;
136 int rc;
137
138 (void)session;
139 (void)channel;
140 (void)term;
141
142 cdata->winsize->ws_row = (unsigned short int)rows;
143 cdata->winsize->ws_col = (unsigned short int)cols;
144 cdata->winsize->ws_xpixel = (unsigned short int)px;
145 cdata->winsize->ws_ypixel = (unsigned short int)py;
146
147 rc = openpty(&cdata->pty_master, &cdata->pty_slave, NULL, NULL, cdata->winsize);
148 if (rc != 0)
149 {
150 log_error("Failed to open pty\n");
151 return SSH_ERROR;
152 }
153
154 return SSH_OK;
155 }
156
157 static int pty_resize(ssh_session session, ssh_channel channel, int cols, int rows,
158 int py, int px, void *userdata)
159 {
160 struct channel_data_struct *cdata = (struct channel_data_struct *)userdata;
161
162 (void)session;
163 (void)channel;
164
165 cdata->winsize->ws_row = (unsigned short int)rows;
166 cdata->winsize->ws_col = (unsigned short int)cols;
167 cdata->winsize->ws_xpixel = (unsigned short int)px;
168 cdata->winsize->ws_ypixel = (unsigned short int)py;
169
170 if (cdata->pty_master != -1)
171 {
172 return ioctl(cdata->pty_master, TIOCSWINSZ, cdata->winsize);
173 }
174
175 return SSH_ERROR;
176 }
177
178 static int exec_pty(const char *mode, const char *command, struct channel_data_struct *cdata)
179 {
180 (void)cdata;
181
182 if (command != NULL)
183 {
184 log_error("Forbid exec /bin/sh %s %s)\n", mode, command);
185 }
186
187 return SSH_OK;
188 }
189
190 static int exec_nopty(const char *command, struct channel_data_struct *cdata)
191 {
192 (void)cdata;
193
194 if (command != NULL)
195 {
196 log_error("Forbid exec /bin/sh -c %s)\n", command);
197 }
198
199 return SSH_OK;
200 }
201
202 static int exec_request(ssh_session session, ssh_channel channel, const char *command, void *userdata)
203 {
204 struct channel_data_struct *cdata = (struct channel_data_struct *)userdata;
205
206 (void)session;
207 (void)channel;
208
209 if (cdata->pid > 0)
210 {
211 return SSH_ERROR;
212 }
213
214 if (cdata->pty_master != -1 && cdata->pty_slave != -1)
215 {
216 return exec_pty("-c", command, cdata);
217 }
218 return exec_nopty(command, cdata);
219 }
220
221 static int shell_request(ssh_session session, ssh_channel channel, void *userdata)
222 {
223 struct channel_data_struct *cdata = (struct channel_data_struct *)userdata;
224
225 (void)session;
226 (void)channel;
227
228 if (cdata->pid > 0)
229 {
230 return SSH_ERROR;
231 }
232
233 if (cdata->pty_master != -1 && cdata->pty_slave != -1)
234 {
235 return exec_pty("-l", NULL, cdata);
236 }
237 /* Client requested a shell without a pty, let's pretend we allow that */
238 return SSH_OK;
239 }
240
241 static int subsystem_request(ssh_session session, ssh_channel channel, const char *subsystem, void *userdata)
242 {
243 (void)session;
244 (void)channel;
245
246 log_error("subsystem_request(subsystem=%s)\n", subsystem);
247
248 /* subsystem requests behave similarly to exec requests. */
249 if (strcmp(subsystem, "sftp") == 0)
250 {
251 return exec_request(session, channel, SFTP_SERVER_PATH, userdata);
252 }
253 return SSH_ERROR;
254 }
255
256 static ssh_channel channel_open(ssh_session session, void *userdata)
257 {
258 (void)userdata;
259
260 if (SSH_channel != NULL)
261 {
262 return NULL;
263 }
264
265 SSH_channel = ssh_channel_new(session);
266
267 return SSH_channel;
268 }
269
270 static int fork_server(void)
271 {
272 ssh_event event;
273 long int ssh_timeout = 0;
274 int pid;
275 int i;
276 int ret;
277
278 /* Structure for storing the pty size. */
279 struct winsize wsize = {
280 .ws_row = 0,
281 .ws_col = 0,
282 .ws_xpixel = 0,
283 .ws_ypixel = 0};
284
285 /* Our struct holding information about the channel. */
286 struct channel_data_struct cdata = {
287 .pid = 0,
288 .pty_master = -1,
289 .pty_slave = -1,
290 .child_stdin = -1,
291 .child_stdout = -1,
292 .child_stderr = -1,
293 .event = NULL,
294 .winsize = &wsize};
295
296 struct session_data_struct cb_data = {
297 .tries = 0,
298 .error = 0,
299 };
300
301 struct ssh_channel_callbacks_struct channel_cb = {
302 .userdata = &cdata,
303 .channel_pty_request_function = pty_request,
304 .channel_pty_window_change_function = pty_resize,
305 .channel_shell_request_function = shell_request,
306 .channel_exec_request_function = exec_request,
307 .channel_subsystem_request_function = subsystem_request};
308
309 struct ssh_server_callbacks_struct server_cb = {
310 .userdata = &cb_data,
311 .auth_password_function = auth_password,
312 .channel_open_request_session_function = channel_open,
313 };
314
315 pid = fork();
316
317 if (pid > 0) // Parent process
318 {
319 SYS_child_process_count++;
320 log_common("Child process (%d) start\n", pid);
321 return pid;
322 }
323 else if (pid < 0) // Error
324 {
325 log_error("fork() error (%d)\n", errno);
326 return -1;
327 }
328
329 // Child process
330 #ifdef HAVE_SYS_EPOLL_H
331 if (close(epollfd_server) < 0)
332 {
333 log_error("close(epollfd_server) error (%d)\n");
334 }
335 #endif
336
337 for (i = 0; i < 2; i++)
338 {
339 if (close(socket_server[i]) == -1)
340 {
341 log_error("Close server socket failed\n");
342 }
343 }
344
345 hash_dict_destroy(hash_dict_pid_sockaddr);
346 hash_dict_destroy(hash_dict_sockaddr_count);
347
348 SSH_session = ssh_new();
349
350 if (SSH_v2)
351 {
352 if (ssh_bind_accept_fd(sshbind, SSH_session, socket_client) != SSH_OK)
353 {
354 log_error("ssh_bind_accept_fd() error: %s\n", ssh_get_error(SSH_session));
355 goto cleanup;
356 }
357
358 ssh_bind_free(sshbind);
359
360 ssh_timeout = 60; // second
361 if (ssh_options_set(SSH_session, SSH_OPTIONS_TIMEOUT, &ssh_timeout) < 0)
362 {
363 log_error("Error setting SSH options: %s\n", ssh_get_error(SSH_session));
364 goto cleanup;
365 }
366
367 ssh_set_auth_methods(SSH_session, SSH_AUTH_METHOD_PASSWORD);
368
369 ssh_callbacks_init(&server_cb);
370 ssh_callbacks_init(&channel_cb);
371
372 ssh_set_server_callbacks(SSH_session, &server_cb);
373
374 if (ssh_handle_key_exchange(SSH_session))
375 {
376 log_error("ssh_handle_key_exchange() error: %s\n", ssh_get_error(SSH_session));
377 goto cleanup;
378 }
379
380 event = ssh_event_new();
381 ssh_event_add_session(event, SSH_session);
382
383 for (i = 0; i < SSH_AUTH_MAX_DURATION && !SYS_server_exit && !cb_data.error && SSH_channel == NULL; i += 100)
384 {
385 ret = ssh_event_dopoll(event, 100); // 0.1 second
386 if (ret == SSH_ERROR)
387 {
388 #ifdef _DEBUG
389 log_error("ssh_event_dopoll() error: %s\n", ssh_get_error(SSH_session));
390 #endif
391 goto cleanup;
392 }
393 }
394
395 if (cb_data.error)
396 {
397 log_error("SSH auth error, tried %d times\n", cb_data.tries);
398 goto cleanup;
399 }
400
401 ssh_set_channel_callbacks(SSH_channel, &channel_cb);
402
403 do
404 {
405 ret = ssh_event_dopoll(event, 100); // 0.1 second
406 if (ret == SSH_ERROR)
407 {
408 ssh_channel_close(SSH_channel);
409 }
410
411 if (ret == SSH_AGAIN) // loop until SSH connection is fully established
412 {
413 /* Executed only once, once the child process starts. */
414 cdata.event = event;
415 break;
416 }
417 } while (ssh_channel_is_open(SSH_channel));
418
419 ssh_timeout = 0;
420 if (ssh_options_set(SSH_session, SSH_OPTIONS_TIMEOUT, &ssh_timeout) < 0)
421 {
422 log_error("Error setting SSH options: %s\n", ssh_get_error(SSH_session));
423 goto cleanup;
424 }
425
426 ssh_set_blocking(SSH_session, 0);
427 }
428
429 // Redirect Input
430 if (dup2(socket_client, STDIN_FILENO) == -1)
431 {
432 log_error("Redirect stdin to client socket failed\n");
433 goto cleanup;
434 }
435
436 // Redirect Output
437 if (dup2(socket_client, STDOUT_FILENO) == -1)
438 {
439 log_error("Redirect stdout to client socket failed\n");
440 goto cleanup;
441 }
442
443 if (io_init() < 0)
444 {
445 log_error("io_init() error\n");
446 goto cleanup;
447 }
448
449 SYS_child_process_count = 0;
450
451 // BWF compile
452 if (bwf_compile() < 0)
453 {
454 log_error("bwf_compile() error\n");
455 goto cleanup;
456 }
457
458 bbs_main();
459
460 cleanup:
461 // Child process exit
462 SYS_server_exit = 1;
463
464 if (SSH_v2)
465 {
466 if (cdata.pty_master != -1)
467 {
468 close(cdata.pty_master);
469 }
470 if (cdata.child_stdin != -1)
471 {
472 close(cdata.child_stdin);
473 }
474 if (cdata.child_stdout != -1)
475 {
476 close(cdata.child_stdout);
477 }
478 if (cdata.child_stderr != -1)
479 {
480 close(cdata.child_stderr);
481 }
482
483 ssh_channel_free(SSH_channel);
484 ssh_disconnect(SSH_session);
485 }
486 else if (close(socket_client) == -1)
487 {
488 log_error("Close client socket failed\n");
489 }
490
491 ssh_free(SSH_session);
492 ssh_finalize();
493
494 // BWF cleanup
495 bwf_cleanup();
496
497 // Close Input and Output for client
498 io_cleanup();
499 close(STDIN_FILENO);
500 close(STDOUT_FILENO);
501
502 log_common("Process exit normally\n");
503 log_end();
504
505 _exit(0);
506
507 return 0;
508 }
509
510 int net_server(const char *hostaddr, in_port_t port[])
511 {
512 unsigned int addrlen;
513 int ret;
514 int flags_server[2];
515 struct sockaddr_in sin;
516
517 #ifdef HAVE_SYS_EPOLL_H
518 struct epoll_event ev, events[MAX_EVENTS];
519 #else
520 struct pollfd pfds[2];
521 #endif
522
523 int nfds;
524 int notify_child_exit = 0;
525 time_t tm_notify_child_exit = time(NULL);
526 int i, j;
527 pid_t pid;
528 int ssh_key_valid = 0;
529 int ssh_log_level = SSH_LOG_NOLOG;
530
531 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
532 int sd_notify_stopping = 0;
533 #endif
534
535 ssh_init();
536
537 sshbind = ssh_bind_new();
538
539 if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_RSA_KEY_FILE) < 0)
540 {
541 log_error("Error loading SSH RSA key: %s\n", SSH_HOST_RSA_KEY_FILE);
542 }
543 else
544 {
545 ssh_key_valid = 1;
546 }
547 if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_ED25519_KEY_FILE) < 0)
548 {
549 log_error("Error loading SSH ED25519 key: %s\n", SSH_HOST_ED25519_KEY_FILE);
550 }
551 else
552 {
553 ssh_key_valid = 1;
554 }
555 if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY, SSH_HOST_ECDSA_KEY_FILE) < 0)
556 {
557 log_error("Error loading SSH ECDSA key: %s\n", SSH_HOST_ECDSA_KEY_FILE);
558 }
559 else
560 {
561 ssh_key_valid = 1;
562 }
563
564 if (!ssh_key_valid)
565 {
566 log_error("Error: no valid SSH host key\n");
567 ssh_bind_free(sshbind);
568 return -1;
569 }
570
571 if (ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDADDR, hostaddr) < 0 ||
572 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_BINDPORT, &port) < 0 ||
573 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_HOSTKEY_ALGORITHMS, "+ssh-rsa") < 0 ||
574 ssh_bind_options_set(sshbind, SSH_BIND_OPTIONS_LOG_VERBOSITY, &ssh_log_level) < 0)
575 {
576 log_error("Error setting SSH bind options: %s\n", ssh_get_error(sshbind));
577 ssh_bind_free(sshbind);
578 return -1;
579 }
580
581 #ifdef HAVE_SYS_EPOLL_H
582 epollfd_server = epoll_create1(0);
583 if (epollfd_server == -1)
584 {
585 log_error("epoll_create1() error (%d)\n", errno);
586 return -1;
587 }
588 #endif
589
590 // Server socket
591 for (i = 0; i < 2; i++)
592 {
593 socket_server[i] = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
594
595 if (socket_server[i] < 0)
596 {
597 log_error("Create socket_server error (%d)\n", errno);
598 return -1;
599 }
600
601 sin.sin_family = AF_INET;
602 sin.sin_addr.s_addr = (hostaddr[0] != '\0' ? inet_addr(hostaddr) : INADDR_ANY);
603 sin.sin_port = htons(port[i]);
604
605 // Reuse address and port
606 flags_server[i] = 1;
607 if (setsockopt(socket_server[i], SOL_SOCKET, SO_REUSEADDR, &flags_server[i], sizeof(flags_server[i])) < 0)
608 {
609 log_error("setsockopt SO_REUSEADDR error (%d)\n", errno);
610 }
611 #if defined(SO_REUSEPORT)
612 if (setsockopt(socket_server[i], SOL_SOCKET, SO_REUSEPORT, &flags_server[i], sizeof(flags_server[i])) < 0)
613 {
614 log_error("setsockopt SO_REUSEPORT error (%d)\n", errno);
615 }
616 #endif
617
618 if (bind(socket_server[i], (struct sockaddr *)&sin, sizeof(sin)) < 0)
619 {
620 log_error("Bind address %s:%u error (%d)\n",
621 inet_ntoa(sin.sin_addr), ntohs(sin.sin_port), errno);
622 return -1;
623 }
624
625 if (listen(socket_server[i], 10) < 0)
626 {
627 log_error("Telnet socket listen error (%d)\n", errno);
628 return -1;
629 }
630
631 log_common("Listening at %s:%u\n", inet_ntoa(sin.sin_addr), ntohs(sin.sin_port));
632
633 #ifdef HAVE_SYS_EPOLL_H
634 ev.events = EPOLLIN;
635 ev.data.fd = socket_server[i];
636 if (epoll_ctl(epollfd_server, EPOLL_CTL_ADD, socket_server[i], &ev) == -1)
637 {
638 log_error("epoll_ctl(socket_server[%d]) error (%d)\n", i, errno);
639 if (close(epollfd_server) < 0)
640 {
641 log_error("close(epoll) error (%d)\n");
642 }
643 return -1;
644 }
645 #endif
646
647 flags_server[i] = fcntl(socket_server[i], F_GETFL, 0);
648 fcntl(socket_server[i], F_SETFL, flags_server[i] | O_NONBLOCK);
649 }
650
651 ssh_bind_set_blocking(sshbind, 0);
652
653 hash_dict_pid_sockaddr = hash_dict_create(MAX_CLIENT_LIMIT);
654 if (hash_dict_pid_sockaddr == NULL)
655 {
656 log_error("hash_dict_create(hash_dict_pid_sockaddr) error\n");
657 return -1;
658 }
659 hash_dict_sockaddr_count = hash_dict_create(MAX_CLIENT_LIMIT);
660 if (hash_dict_sockaddr_count == NULL)
661 {
662 log_error("hash_dict_create(hash_dict_sockaddr_count) error\n");
663 return -1;
664 }
665
666 // Startup complete
667 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
668 sd_notifyf(0, "READY=1\n"
669 "STATUS=Listening at %s:%d (Telnet) and %s:%d (SSH2)\n"
670 "MAINPID=%d",
671 hostaddr, port[0], hostaddr, port[1], getpid());
672 #endif
673
674 while (!SYS_server_exit || SYS_child_process_count > 0)
675 {
676 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
677 if (SYS_server_exit && !sd_notify_stopping)
678 {
679 sd_notify(0, "STOPPING=1");
680 sd_notify_stopping = 1;
681 }
682 #endif
683
684 while ((SYS_child_exit || SYS_server_exit) && SYS_child_process_count > 0)
685 {
686 SYS_child_exit = 0;
687
688 pid = waitpid(-1, &ret, WNOHANG);
689 if (pid > 0)
690 {
691 SYS_child_exit = 1; // Retry waitid
692 SYS_child_process_count--;
693
694 if (WIFEXITED(ret))
695 {
696 log_common("Child process (%d) exited, status=%d\n", pid, WEXITSTATUS(ret));
697 }
698 else if (WIFSIGNALED(ret))
699 {
700 log_common("Child process (%d) is killed, status=%d\n", pid, WTERMSIG(ret));
701 }
702 else
703 {
704 log_common("Child process (%d) exited abnormally, status=%d\n", pid, ret);
705 }
706
707 if (pid != section_list_loader_pid)
708 {
709 j = 0;
710 ret = hash_dict_get(hash_dict_pid_sockaddr, (uint64_t)pid, (int64_t *)&j);
711 if (ret < 0)
712 {
713 log_error("hash_dict_get(hash_dict_pid_sockaddr, %d) error\n", pid);
714 }
715 else
716 {
717 ret = hash_dict_inc(hash_dict_sockaddr_count, (uint64_t)j, -1);
718 if (ret < 0)
719 {
720 log_error("hash_dict_inc(hash_dict_sockaddr_count, %d, -1) error\n", j);
721 }
722
723 ret = hash_dict_del(hash_dict_pid_sockaddr, (uint64_t)pid);
724 if (ret < 0)
725 {
726 log_error("hash_dict_del(hash_dict_pid_sockaddr, %d) error\n", pid);
727 }
728 }
729 }
730 }
731 else if (pid == 0)
732 {
733 break;
734 }
735 else if (pid < 0)
736 {
737 log_error("Error in waitpid(): %d\n", errno);
738 break;
739 }
740 }
741
742 if (SYS_server_exit && !SYS_child_exit && SYS_child_process_count > 0)
743 {
744 if (notify_child_exit == 0)
745 {
746 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
747 sd_notifyf(0, "STATUS=Notify %d child process to exit", SYS_child_process_count);
748 log_common("Notify %d child process to exit\n", SYS_child_process_count);
749 #endif
750
751 if (kill(0, SIGTERM) < 0)
752 {
753 log_error("Send SIGTERM signal failed (%d)\n", errno);
754 }
755
756 notify_child_exit = 1;
757 tm_notify_child_exit = time(NULL);
758 }
759 else if (notify_child_exit == 1 && time(NULL) - tm_notify_child_exit >= WAIT_CHILD_PROCESS_EXIT_TIMEOUT)
760 {
761 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
762 sd_notifyf(0, "STATUS=Kill %d child process", SYS_child_process_count);
763 #endif
764
765 if (kill(0, SIGKILL) < 0)
766 {
767 log_error("Send SIGKILL signal failed (%d)\n", errno);
768 }
769
770 notify_child_exit = 2;
771 tm_notify_child_exit = time(NULL);
772 }
773 else if (notify_child_exit == 2 && time(NULL) - tm_notify_child_exit >= WAIT_CHILD_PROCESS_KILL_TIMEOUT)
774 {
775 log_error("Main process prepare to exit without waiting for %d child process any longer\n", SYS_child_process_count);
776 SYS_child_process_count = 0;
777 }
778 }
779
780 if (SYS_conf_reload && !SYS_server_exit)
781 {
782 SYS_conf_reload = 0;
783
784 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
785 sd_notify(0, "RELOADING=1");
786 #endif
787
788 // Restart log
789 if (log_restart() < 0)
790 {
791 log_error("Restart logging failed\n");
792 }
793
794 // Reload configuration
795 if (load_conf(CONF_BBSD) < 0)
796 {
797 log_error("Reload conf failed\n");
798 }
799
800 // Reload BWF config
801 if (bwf_load(CONF_BWF) < 0)
802 {
803 log_error("Reload BWF conf failed\n");
804 }
805
806 if (detach_menu_shm(&bbs_menu) < 0)
807 {
808 log_error("detach_menu_shm(bbs_menu) error\n");
809 }
810 if (load_menu(&bbs_menu, CONF_MENU) < 0)
811 {
812 log_error("load_menu(bbs_menu) error\n");
813 unload_menu(&bbs_menu);
814 }
815
816 if (detach_menu_shm(&top10_menu) < 0)
817 {
818 log_error("detach_menu_shm(top10_menu) error\n");
819 }
820 if (load_menu(&top10_menu, CONF_TOP10_MENU) < 0)
821 {
822 log_error("load_menu(top10_menu) error\n");
823 unload_menu(&top10_menu);
824 }
825
826 for (int i = 0; i < data_files_load_startup_count; i++)
827 {
828 if (load_file(data_files_load_startup[i]) < 0)
829 {
830 log_error("load_file(%s) error\n", data_files_load_startup[i]);
831 }
832 }
833
834 // Load section config and gen_ex
835 if (load_section_config_from_db(1) < 0)
836 {
837 log_error("load_section_config_from_db(1) error\n");
838 }
839
840 // Notify child processes to reload configuration
841 if (kill(0, SIGUSR1) < 0)
842 {
843 log_error("Send SIGUSR1 signal failed (%d)\n", errno);
844 }
845
846 #ifdef HAVE_SYSTEMD_SD_DAEMON_H
847 sd_notify(0, "READY=1");
848 #endif
849 }
850
851 #ifdef HAVE_SYS_EPOLL_H
852 nfds = epoll_wait(epollfd_server, events, MAX_EVENTS, 100); // 0.1 second
853 ret = nfds;
854 #else
855 pfds[0].fd = socket_server[0];
856 pfds[0].events = POLLIN;
857 pfds[1].fd = socket_server[1];
858 pfds[1].events = POLLIN;
859 nfds = 2;
860 ret = poll(pfds, (nfds_t)nfds, 100); // 0.1 second
861 #endif
862 if (ret < 0)
863 {
864 if (errno != EINTR)
865 {
866 #ifdef HAVE_SYS_EPOLL_H
867 log_error("epoll_wait() error (%d)\n", errno);
868 #else
869 log_error("poll() error (%d)\n", errno);
870 #endif
871 break;
872 }
873 continue;
874 }
875
876 // Stop accept new connection on exit
877 if (SYS_server_exit)
878 {
879 continue;
880 }
881
882 for (int i = 0; i < nfds; i++)
883 {
884 #ifdef HAVE_SYS_EPOLL_H
885 if (events[i].data.fd == socket_server[0] || events[i].data.fd == socket_server[1])
886 #else
887 if ((pfds[i].fd == socket_server[0] || pfds[i].fd == socket_server[1]) && (pfds[i].revents & POLLIN))
888 #endif
889 {
890 #ifdef HAVE_SYS_EPOLL_H
891 SSH_v2 = (events[i].data.fd == socket_server[1] ? 1 : 0);
892 #else
893 SSH_v2 = (pfds[i].fd == socket_server[1] ? 1 : 0);
894 #endif
895
896 while (!SYS_server_exit) // Accept all incoming connections until error
897 {
898 addrlen = sizeof(sin);
899 socket_client = accept(socket_server[SSH_v2], (struct sockaddr *)&sin, (socklen_t *)&addrlen);
900 if (socket_client < 0)
901 {
902 if (errno == EAGAIN || errno == EWOULDBLOCK)
903 {
904 break;
905 }
906 else if (errno == EINTR)
907 {
908 continue;
909 }
910 else
911 {
912 log_error("accept(socket_server) error (%d)\n", errno);
913 break;
914 }
915 }
916
917 strncpy(hostaddr_client, inet_ntoa(sin.sin_addr), sizeof(hostaddr_client) - 1);
918 hostaddr_client[sizeof(hostaddr_client) - 1] = '\0';
919
920 port_client = ntohs(sin.sin_port);
921
922 log_common("Accept %s connection from %s:%d\n", (SSH_v2 ? "SSH" : "telnet"), hostaddr_client, port_client);
923
924 if (SYS_child_process_count - 1 < BBS_max_client)
925 {
926 j = 0;
927 ret = hash_dict_get(hash_dict_sockaddr_count, (uint64_t)sin.sin_addr.s_addr, (int64_t *)&j);
928 if (ret < 0)
929 {
930 log_error("hash_dict_get(hash_dict_sockaddr_count, %s) error\n", hostaddr_client);
931 }
932
933 if (j < BBS_max_client_per_ip)
934 {
935 if ((pid = fork_server()) < 0)
936 {
937 log_error("fork_server() error\n");
938 }
939 else if (pid > 0)
940 {
941 ret = hash_dict_set(hash_dict_pid_sockaddr, (uint64_t)pid, sin.sin_addr.s_addr);
942 if (ret < 0)
943 {
944 log_error("hash_dict_set(hash_dict_pid_sockaddr, %d, %s) error\n", pid, hostaddr_client);
945 }
946
947 ret = hash_dict_inc(hash_dict_sockaddr_count, (uint64_t)sin.sin_addr.s_addr, 1);
948 if (ret < 0)
949 {
950 log_error("hash_dict_inc(hash_dict_sockaddr_count, %s, %d) error\n", hostaddr_client, 1);
951 }
952 }
953 }
954 else
955 {
956 log_error("Rejected client connection from %s over limit per IP (%d)\n", hostaddr_client, BBS_max_client_per_ip);
957 }
958 }
959 else
960 {
961 log_error("Rejected client connection over limit (%d)\n", SYS_child_process_count - 1);
962 }
963
964 if (close(socket_client) == -1)
965 {
966 log_error("close(socket_lient) error (%d)\n", errno);
967 }
968 }
969 }
970 }
971 }
972
973 #ifdef HAVE_SYS_EPOLL_H
974 if (close(epollfd_server) < 0)
975 {
976 log_error("close(epollfd_server) error (%d)\n");
977 }
978 #endif
979
980 for (i = 0; i < 2; i++)
981 {
982 if (close(socket_server[i]) == -1)
983 {
984 log_error("Close server socket failed\n");
985 }
986 }
987
988 hash_dict_destroy(hash_dict_pid_sockaddr);
989 hash_dict_destroy(hash_dict_sockaddr_count);
990
991 ssh_bind_free(sshbind);
992 ssh_finalize();
993
994 return 0;
995 }

webmaster@leafok.com
ViewVC Help
Powered by ViewVC 1.3.0-beta1