channel.c 37.9 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
/* channel.c
 *
 * $Id$
 */

/* lsh, an implementation of the ssh protocol
 *
 * Copyright (C) 1998 Niels Mller
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
 * published by the Free Software Foundation; either version 2 of the
 * License, or (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
 * General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
J.H.M. Dassen's avatar
J.H.M. Dassen committed
22
 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
Niels Möller's avatar
Niels Möller committed
23
24
25
26
27
 */

#include "channel.h"

#include "format.h"
28
#include "io.h"
Niels Möller's avatar
Niels Möller committed
29
#include "read_data.h"
Niels Möller's avatar
Niels Möller committed
30
31
32
33
34
#include "ssh.h"
#include "werror.h"
#include "xalloc.h"

#include <assert.h>
35
#include <string.h>
Niels Möller's avatar
Niels Möller committed
36

37
#define GABA_DEFINE
38
#include "channel.h.x"
39
#undef GABA_DEFINE
40

41
42
#include "channel.c.x"

43
/* GABA:
44
45
   (class
     (name connection_service)
46
     (super command)
47
48
49
50
     (vars
       ; Supported global requests 
       (global_requests object alist)

51
       (channel_types object alist) ))
52
53
54
55

       ; Initialize connection (for instance, request channels to be 
       ; opened or services to be forwarded).

56
       ; (start object connection_startup)))
57
58
*/

59
/* GABA:
60
61
   (class
     (name global_request_handler)
62
     (super packet_handler)
63
64
65
66
     (vars
       (global_requests object alist)))
*/

67
/* GABA:
68
69
   (class
     (name channel_open_handler)
70
     (super packet_handler)
71
72
73
74
     (vars
       (channel_types object alist)))
*/

75
/* GABA:
76
77
78
79
80
81
82
83
84
   (class
     (name channel_open_response)
     (super channel_open_callback)
     (vars
       (remote_channel_number simple UINT32)
       (window_size simple UINT32)
       (max_packet simple UINT32)))
*/

Niels Möller's avatar
Niels Möller committed
85
86
87
88
89
struct lsh_string *format_global_failure(void)
{
  return ssh_format("%c", SSH_MSG_REQUEST_FAILURE);
}

90
91
92
93
94
struct lsh_string *format_global_success(void)
{
  return ssh_format("%c", SSH_MSG_REQUEST_SUCCESS);
}

95
96
struct lsh_string *format_open_confirmation(struct ssh_channel *channel,
					    UINT32 channel_number,
97
					    const char *format, ...)
98
99
100
101
102
103
{
  va_list args;
  UINT32 l1, l2;
  struct lsh_string *packet;

#define CONFIRM_FORMAT "%c%i%i%i%i"
104
105
#define CONFIRM_ARGS \
  SSH_MSG_CHANNEL_OPEN_CONFIRMATION, channel->channel_number, \
106
107
108
109
110
111
112
113
114
115
116
117
118
  channel_number, channel->rec_window_size, channel->rec_max_packet
    
  l1 = ssh_format_length(CONFIRM_FORMAT, CONFIRM_ARGS);

  va_start(args, format);
  l2 = ssh_vformat_length(format, args);
  va_end(args);

  packet = lsh_string_alloc(l1 + l2);

  ssh_format_write(CONFIRM_FORMAT, l1, packet->data, CONFIRM_ARGS);

  va_start(args, format);
119
  ssh_vformat_write(format, l2, packet->data+l1, args);
120
121
122
123
124
125
126
  va_end(args);

  return packet;
#undef CONFIRM_FORMAT
#undef CONFIRM_ARGS
}

Niels Möller's avatar
Niels Möller committed
127
struct lsh_string *format_open_failure(UINT32 channel, UINT32 reason,
128
				       const char *msg, const char *language)
Niels Möller's avatar
Niels Möller committed
129
130
131
132
133
{
  return ssh_format("%c%i%i%z%z", SSH_MSG_CHANNEL_OPEN_FAILURE,
		    channel, reason, msg, language);
}

134
135
136
137
138
struct lsh_string *format_channel_success(UINT32 channel)
{
  return ssh_format("%c%i", SSH_MSG_CHANNEL_SUCCESS, channel);
}

Niels Möller's avatar
Niels Möller committed
139
140
141
142
143
struct lsh_string *format_channel_failure(UINT32 channel)
{
  return ssh_format("%c%i", SSH_MSG_CHANNEL_FAILURE, channel);
}

144
145
146
147
148
149
150
151
152
153
struct lsh_string *prepare_window_adjust(struct ssh_channel *channel,
					 UINT32 add)
{
  channel->rec_window_size += add;
  
  return ssh_format("%c%i%i",
		    SSH_MSG_CHANNEL_WINDOW_ADJUST,
		    channel->channel_number, add);
}

154
/* Channel objects */
Niels Möller's avatar
Niels Möller committed
155
156
157
158
159

#define INITIAL_CHANNELS 32
/* Arbitrary limit */
#define MAX_CHANNELS (1L<<17)

Niels Möller's avatar
Niels Möller committed
160
struct channel_table *make_channel_table(void)
Niels Möller's avatar
Niels Möller committed
161
{
162
  NEW(channel_table, table);
Niels Möller's avatar
Niels Möller committed
163

164
  table->channels = lsh_space_alloc(sizeof(struct ssh_channel *)
165
				      * INITIAL_CHANNELS);
166
167
168
169
  table->allocated_channels = INITIAL_CHANNELS;
  table->next_channel = 0;
  table->used_channels = 0;
  table->max_channels = MAX_CHANNELS;
Niels Möller's avatar
Niels Möller committed
170

Niels Möller's avatar
Niels Möller committed
171
  table->pending_close = 0;
172
173
174

  object_queue_init(&table->active_global_requests);
  object_queue_init(&table->pending_global_requests);
Niels Möller's avatar
Niels Möller committed
175
  
176
  return table;
Niels Möller's avatar
Niels Möller committed
177
178
179
};

/* Returns -1 if allocation fails */
180
181
182
/* NOTE: This function returns locally chosen channel numbers, which
 * are always small integers. So there's no problem fitting them in
 * a signed int. */
183
int alloc_channel(struct channel_table *table)
Niels Möller's avatar
Niels Möller committed
184
{
185
  UINT32 i;
186
  
187
  for(i = table->next_channel; i < table->used_channels; i++)
Niels Möller's avatar
Niels Möller committed
188
    {
189
      if (!table->channels[i])
Niels Möller's avatar
Niels Möller committed
190
	{
191
	  table->next_channel = i+1;
Niels Möller's avatar
Niels Möller committed
192
193
194
	  return i;
	}
    }
195
  if (i == table->max_channels)
Niels Möller's avatar
Niels Möller committed
196
    return -1;
197

198
  if (i == table->allocated_channels) 
Niels Möller's avatar
Niels Möller committed
199
    {
200
      int new_size = table->allocated_channels * 2;
Niels Möller's avatar
Niels Möller committed
201
      struct ssh_channel **new
202
	= lsh_space_alloc(sizeof(struct ssh_channel *) * new_size);
Niels Möller's avatar
Niels Möller committed
203

204
205
      memcpy(new, table->channels,
	     sizeof(struct ssh_channel *) * table->used_channels);
Niels Möller's avatar
Niels Möller committed
206
      
207
208
      table->channels = new;
      table->allocated_channels = new_size;
Niels Möller's avatar
Niels Möller committed
209
210
    }

211
  table->next_channel = table->used_channels = i+1;
Niels Möller's avatar
Niels Möller committed
212
213
214
215

  return i;
}

216
void dealloc_channel(struct channel_table *table, int i)
Niels Möller's avatar
Niels Möller committed
217
218
{
  assert(i >= 0);
219
  assert( (unsigned) i < table->used_channels);
Niels Möller's avatar
Niels Möller committed
220
  
221
222
  table->channels[i] = NULL;

223
  if ( (unsigned) i < table->next_channel)
224
225
226
    table->next_channel = i;
}

227
228
/* Returns -1 if no channel number can be allocated. See also the note
 * for alloc_channel(). */
229
230
231
232
233
234
int register_channel(struct channel_table *table, struct ssh_channel *channel)
{
  int n = alloc_channel(table);

  if (n >= 0)
    table->channels[n] = channel;
Niels Möller's avatar
Niels Möller committed
235

236
  return n;
Niels Möller's avatar
Niels Möller committed
237
238
}

239
struct ssh_channel *lookup_channel(struct channel_table *table, UINT32 i)
Niels Möller's avatar
Niels Möller committed
240
{
241
242
  return (i < table->used_channels)
    ? table->channels[i] : NULL;
Niels Möller's avatar
Niels Möller committed
243
244
}

245
246
247
static int adjust_rec_window(struct ssh_channel *channel)
{
  if (channel->rec_window_size < channel->max_window / 2)
248
249
250
251
252
    return A_WRITE(channel->write,
		   prepare_window_adjust
		   (channel, channel->max_window - channel->rec_window_size));
  else
    return 0;
253
254
}

255
256
/* Process channel-related status codes. Used by the packet handlers,
 * before returning. */
Niels Möller's avatar
Niels Möller committed
257
258
259
260
static int channel_process_status(struct channel_table *table,
				  int channel,
				  int status)
{
261
262
263
264
  struct ssh_channel *c = table->channels[channel];
  
  while (!LSH_CLOSEDP(status))
    {
265
266
267
268
269
270
271
      if (status & LSH_CHANNEL_CLOSE)
	{ /* Close the channel now */ 
	  if (!c->flags & CHANNEL_SENT_CLOSE)
	    status |= channel_close(c);
	  break;
	}
      
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
      if (status & LSH_CHANNEL_READY_SEND)
	{
	  status &= ~ LSH_CHANNEL_READY_SEND;
	  if (c->send_window_size)
	    status |= CHANNEL_SEND(c);
	}
      else if (status & LSH_CHANNEL_READY_REC)
	{
	  status &= ~ LSH_CHANNEL_READY_REC;
	  status |= adjust_rec_window(c);
	}
      else
	break;
    }
	
Niels Möller's avatar
Niels Möller committed
287
288
289
290
  if (status & LSH_CHANNEL_FINISHED)
    {
      /* Clear this bit */
      status &= ~LSH_CHANNEL_FINISHED;
291

292
      if (c->close)
293
	status |= CHANNEL_CLOSE(c);
Niels Möller's avatar
Niels Möller committed
294
295
296
297
      
      dealloc_channel(table, channel);
    }

298
299
300
301
302
303
304
  if (status & LSH_CHANNEL_PENDING_CLOSE)
    table->pending_close = 1;
  
  /* If this was the last channel, close connection */
  if (table->pending_close && !table->next_channel)
    status |= LSH_CLOSE;

Niels Möller's avatar
Niels Möller committed
305
306
  return status;
}
Niels Möller's avatar
Niels Möller committed
307

308
309
310
311
312
313
314
/* Ugly macros to make it a little simpler to free the input packet at
 * the right time. */

#define START int foo_res
#define RETURN(x) do { foo_res = (x); goto foo_finish; } while(0)
#define END(s) foo_finish: do { lsh_string_free((s)); return foo_res; } while(0)

Niels Möller's avatar
Niels Möller committed
315
/* Channel related messages */
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347

/* GABA:
   (class
     (name global_request_status)
     (vars
       ; -1 for still active requests,
       ; 0 for failure,
       ; 1 for success
       (status . int)))
*/

static struct global_request_status *make_global_request_status(void)
{
  NEW(global_request_status, self);
  self->status = -1;

  return self;
}

/* GABA:
   (class
     (name global_request_response)
     (super global_request_callback)
     (vars
       (active object global_request_status)))
*/

static int
do_global_request_response(struct global_request_callback *c,
			   int success)
{
  CAST(global_request_response, self, c);
348
  struct object_queue *q = &self->super.connection->channels->active_global_requests;
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389

  int res = 0;
  
  assert( self->active->status == -1);
  assert( (success == 0) || (success == 1) );
  assert( !object_queue_is_empty(q));
	  
  self->active->status = success;

  for (;;)
    {
      CAST(global_request_status, n, object_queue_peek_head(q));
      if (!n || (n->status < 0))
	return res;

      object_queue_remove_head(q);
      
      res |= A_WRITE(self->super.connection->write,
		     (n->status
		      ? format_global_success()
		      : format_global_failure()));
      
      if (LSH_CLOSEDP(res))
	return res;
    }
}

static struct global_request_callback *
make_global_request_response(struct ssh_connection *connection,
			     struct global_request_status *active)
{
  NEW(global_request_response, self);

  self->super.connection = connection;
  self->super.response = do_global_request_response;

  self->active = active;

  return &self->super;
}
     
Niels Möller's avatar
Niels Möller committed
390
391
392
393
static int do_global_request(struct packet_handler *c,
			     struct ssh_connection *connection,
			     struct lsh_string *packet)
{
394
  CAST(global_request_handler, closure, c);
Niels Möller's avatar
Niels Möller committed
395
396

  struct simple_buffer buffer;
397
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
398
399
  int name;
  int want_reply;
400
  START;
Niels Möller's avatar
Niels Möller committed
401
402
403
404
405
406
407
408
409
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_GLOBAL_REQUEST)
      && parse_atom(&buffer, &name)
      && parse_boolean(&buffer, &want_reply))
    {
      struct global_request *req;
410
411
      struct global_request_callback *c = NULL;
      
Niels Möller's avatar
Niels Möller committed
412
      if (!name || !(req = ALIST_GET(closure->global_requests, name)))
413
414
	RETURN (A_WRITE(connection->write,
		       format_global_failure()));
Niels Möller's avatar
Niels Möller committed
415

416
417
418
419
      if (want_reply)
	{
	  struct global_request_status *a = make_global_request_status();

420
	  object_queue_add_tail(&connection->channels->active_global_requests,
421
422
423
424
425
				&a->super);
	  
	  c = make_global_request_response(connection, a);
	}
      RETURN (GLOBAL_REQUEST(req, connection, &buffer, c));
Niels Möller's avatar
Niels Möller committed
426
    }
427
  RETURN (LSH_FAIL | LSH_DIE);
Niels Möller's avatar
Niels Möller committed
428

429
  END (packet);
Niels Möller's avatar
Niels Möller committed
430
431
}

432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
/* Callback given to the CHANNEL_OPEN method */
static int do_channel_open_response(struct channel_open_callback *c,
                                    struct ssh_channel *channel,
                                    UINT32 error, char *error_msg,
                                    struct lsh_string *args)
{
  CAST(channel_open_response, closure, c);
  
  int local_channel_number;

  if (!channel)
    {
      if (error)
        return A_WRITE(closure->super.connection->write,
                       format_open_failure(closure->remote_channel_number,
                                           error, error_msg, ""));
        /* The request was invalid */
        return LSH_FAIL | LSH_DIE;
    }

  if ( (local_channel_number
            = register_channel(closure->super.connection->channels,
			       channel)) < 0)
    {
      werror("Could not allocate a channel number for opened channel!\n");
      return A_WRITE(closure->super.connection->write,
                     format_open_failure(closure->remote_channel_number,
                                         SSH_OPEN_RESOURCE_SHORTAGE,
                                         "Could not allocate a channel number "
                                         "(shouldn't happen...)", ""));
    }

464
  /* FIXME: This copying could just as well be done by the
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
   * CHANNEL_OPEN handler? Then we can remove the corresponding fields
   * from the closure as well. */
  channel->send_window_size = closure->window_size;
  channel->send_max_packet = closure->max_packet;
  channel->channel_number = closure->remote_channel_number;

  /* FIXME: Is the channel->write field really needed? */
  channel->write = closure->super.connection->write;

  return A_WRITE(closure->super.connection->write,
                 args
                 ? format_open_confirmation(channel, local_channel_number,
                                            "%lfS", args)
                 : format_open_confirmation(channel, local_channel_number,
                                            ""));
}

static struct channel_open_response *
make_channel_open_response(struct ssh_connection* connection,
			   UINT32 remote_channel_number,
			   UINT32 window_size,
			   UINT32 max_packet)
{
  NEW(channel_open_response, closure);

  closure->super.response = do_channel_open_response;
  closure->super.connection = connection;
  closure->remote_channel_number = remote_channel_number;
  closure->window_size = window_size;
  closure->max_packet = max_packet;

  return closure;
}
498

499

500
501
502
503
504
505
506
507
508
509
510
#if 0
/* ;;GABA:
   (class
     (name channel_open_continuation)
     (super command_continuation)
     (vars
       (connection object ssh_connection)
       (remote_channel_number simple UINT32)
       (window_size simple UINT32)
       (max_packet simple UINT32)))
*/
511

512
513
514
515
516
517
518
519
static int do_channel_open_continue(struct command_continuation *c,
				    struct lsh_object *result)
{
  CAST(channel_open_continuation, self, c);
  CAST_SUBTYPE(channel);
}
#endif
				    
Niels Möller's avatar
Niels Möller committed
520
521
522
523
static int do_channel_open(struct packet_handler *c,
			   struct ssh_connection *connection,
			   struct lsh_string *packet)
{
524
  CAST(channel_open_handler, closure, c);
Niels Möller's avatar
Niels Möller committed
525
526

  struct simple_buffer buffer;
527
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
528
  int type;
529
530
531
  UINT32 remote_channel_number;
  UINT32 window_size;
  UINT32 max_packet;
532
  START;
Niels Möller's avatar
Niels Möller committed
533
534
535
536
537
538
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_OPEN)
      && parse_atom(&buffer, &type)
539
540
541
      && parse_uint32(&buffer, &remote_channel_number)
      && parse_uint32(&buffer, &window_size)
      && parse_uint32(&buffer, &max_packet))
Niels Möller's avatar
Niels Möller committed
542
543
    {
      struct channel_open *open;
544
545
      struct channel_open_response *response;
      int res;
546
      
547
      if (connection->channels->pending_close)
Niels Möller's avatar
Niels Möller committed
548
	/* We are waiting for channels to close. Don't open any new ones. */
549
550
551
552
553
	RETURN
	  (A_WRITE(connection->write,
		   format_open_failure(remote_channel_number,
				       SSH_OPEN_ADMINISTRATIVELY_PROHIBITED,
				       "Waiting for channels to close.", "")));
Niels Möller's avatar
Niels Möller committed
554
555
      
      if (!type || !(open = ALIST_GET(closure->channel_types, type)))
556
557
558
559
	RETURN (A_WRITE(connection->write,
			format_open_failure(remote_channel_number,
					    SSH_OPEN_UNKNOWN_CHANNEL_TYPE,
					    "Unknown channel type", "")));
560

561
562
563
564
565
566
567
568
      response = make_channel_open_response(connection,
					    remote_channel_number,
					    window_size, max_packet);
      /* NOTE: If the channel could be opened immediately, this method
       * will call response right away. */
      res = CHANNEL_OPEN(open, connection, &buffer, &response->super);

      RETURN (res);
Niels Möller's avatar
Niels Möller committed
569
    }
570
  RETURN (LSH_FAIL | LSH_DIE);
Niels Möller's avatar
Niels Möller committed
571

572
  END(packet);
Niels Möller's avatar
Niels Möller committed
573
574
}     

575
static int do_channel_request(struct packet_handler *closure UNUSED,
Niels Möller's avatar
Niels Möller committed
576
577
578
579
			      struct ssh_connection *connection,
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
580
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
581
582
583
  UINT32 channel_number;
  int type;
  int want_reply;
584
585
  START;
  
Niels Möller's avatar
Niels Möller committed
586
587
588
589
590
591
592
593
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_REQUEST)
      && parse_uint32(&buffer, &channel_number)
      && parse_atom(&buffer, &type)
      && parse_boolean(&buffer, &want_reply))
    {
594
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
595
596
						   channel_number);

597
598
599
600
      /* NOTE: We can't free packet yet, because it is not yet fully
       * parsed. There may be some more arguments, which are parsed by
       * the CHANNEL_REQUEST method below. */

Niels Möller's avatar
Niels Möller committed
601
602
603
604
      if (channel)
	{
	  struct channel_request *req;

605
606
	  if (type && channel->request_types 
	      && ( (req = ALIST_GET(channel->request_types, type)) ))
607
608
609
610
	    RETURN
	      (channel_process_status
	       (connection->channels, channel_number,
		CHANNEL_REQUEST(req, channel, connection, want_reply, &buffer)));
611
	  else
612
613
614
615
	    RETURN (want_reply
		    ? A_WRITE(connection->write,
			      format_channel_failure(channel->channel_number))
		    : LSH_OK | LSH_GOON);
616
	  
Niels Möller's avatar
Niels Möller committed
617
	}
618
      werror("SSH_MSG_CHANNEL_REQUEST on nonexistant channel %i\n",
Niels Möller's avatar
Niels Möller committed
619
620
	     channel_number);

621
622
623
624
    }
  RETURN (LSH_FAIL | LSH_DIE);
  
  END(packet);
Niels Möller's avatar
Niels Möller committed
625
626
}
      
627
628
static int do_window_adjust(struct packet_handler *closure UNUSED,
			    struct ssh_connection *connection,
629
			    struct lsh_string *packet)
Niels Möller's avatar
Niels Möller committed
630
631
{
  struct simple_buffer buffer;
632
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
633
634
635
636
637
638
639
  UINT32 channel_number;
  UINT32 size;

  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_WINDOW_ADJUST)
640
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
641
642
643
      && parse_uint32(&buffer, &size)
      && parse_eod(&buffer))
    {
644
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
645
646
647
648
						   channel_number);

      lsh_string_free(packet);
      
Niels Möller's avatar
Niels Möller committed
649
      if (channel
650
651
	  && !(channel->flags & (CHANNEL_RECEIVED_EOF
				 | CHANNEL_RECEIVED_CLOSE)))
Niels Möller's avatar
Niels Möller committed
652
	{
Niels Möller's avatar
Niels Möller committed
653
654
655
656
	  if (! (channel->flags & CHANNEL_SENT_CLOSE))
	    {
	      channel->send_window_size += size;
	      if (channel->send_window_size && channel->send)
657
		return channel_process_status(connection->channels,
Niels Möller's avatar
Niels Möller committed
658
659
					      channel_number,
					      CHANNEL_SEND(channel));
Niels Möller's avatar
Niels Möller committed
660
	    }
Niels Möller's avatar
Niels Möller committed
661
662
663
664
	  return LSH_OK | LSH_GOON;
	}
      /* FIXME: What to do now? Should unknown channel numbers be
       * ignored silently? */
665
666
      werror("SSH_MSG_CHANNEL_WINDOW_ADJUST on nonexistant or closed "
	     "channel %i\n", channel_number);
Niels Möller's avatar
Niels Möller committed
667
668
669
670
671
672
673
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);

  return LSH_FAIL | LSH_DIE;
}

674
675
static int do_channel_data(struct packet_handler *closure UNUSED,
			   struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
676
677
678
			   struct lsh_string *packet)
{
  struct simple_buffer buffer;
679
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
680
681
682
683
684
685
686
  UINT32 channel_number;
  struct lsh_string *data;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_DATA)
687
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
688
689
690
      && ( (data = parse_string_copy(&buffer)) )
      && parse_eod(&buffer))
    {
691
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
692
693
694
695
						   channel_number);

      lsh_string_free(packet);
      
696
      if (channel && channel->receive
697
698
	  && !(channel->flags & (CHANNEL_RECEIVED_EOF
				 | CHANNEL_RECEIVED_CLOSE)))
Niels Möller's avatar
Niels Möller committed
699
	{
Niels Möller's avatar
Niels Möller committed
700
	  if (channel->flags & CHANNEL_SENT_CLOSE)
Niels Möller's avatar
Niels Möller committed
701
	    {
702
	      werror("Ignoring data on channel which is closing\n");
Niels Möller's avatar
Niels Möller committed
703
	      return LSH_OK | LSH_GOON;
Niels Möller's avatar
Niels Möller committed
704
	    }
Niels Möller's avatar
Niels Möller committed
705
706
	  else
	    {
707
708
	      int res = 0;
	      
Niels Möller's avatar
Niels Möller committed
709
710
711
	      if (data->length > channel->rec_window_size)
		{
		  /* Truncate data to fit window */
712
		  werror("Channel data overflow. Extra data ignored.\n"); 
Niels Möller's avatar
Niels Möller committed
713
714
		  data->length = channel->rec_window_size;
		}
715
716
717
718

	      if (!data->length)
		/* Ignore data packet */
		return 0;
719
720
	      channel->rec_window_size -= data->length;

721
	      /* FIXME: Unconditionally adjusting the receive window
722
	       * breaks flow control. We better let the channel's
723
	       * receive method decide whether or not to receive more
724
725
726
	       * data. */
	      res = adjust_rec_window(channel);
	      
727
728
	      if (LSH_CLOSEDP(res))
		return res;
729

Niels Möller's avatar
Niels Möller committed
730
	      return channel_process_status(
731
		connection->channels, channel_number,
732
		res | CHANNEL_RECEIVE(channel, 
Niels Möller's avatar
Niels Möller committed
733
				      CHANNEL_DATA, data));
Niels Möller's avatar
Niels Möller committed
734
735
	    }
	  return LSH_OK | LSH_GOON;
Niels Möller's avatar
Niels Möller committed
736
737
	}
	  
738
      werror("Data on closed or non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
739
740
741
742
743
744
745
746
747
	     channel_number);
      lsh_string_free(data);
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  
  return LSH_FAIL | LSH_DIE;
}

748
749
static int do_channel_extended_data(struct packet_handler *closure UNUSED,
				    struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
750
751
752
				    struct lsh_string *packet)
{
  struct simple_buffer buffer;
753
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
754
755
756
757
758
759
760
761
  UINT32 channel_number;
  UINT32 type;
  struct lsh_string *data;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_EXTENDED_DATA)
762
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
763
764
765
766
      && parse_uint32(&buffer, &type)
      && ( (data = parse_string_copy(&buffer)) )
      && parse_eod(&buffer))
    {
767
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
768
769
770
771
						   channel_number);

      lsh_string_free(packet);
      
772
      if (channel && channel->receive
773
774
	  && !(channel->flags & (CHANNEL_RECEIVED_EOF
				 | CHANNEL_RECEIVED_CLOSE)))
Niels Möller's avatar
Niels Möller committed
775
	{
Niels Möller's avatar
Niels Möller committed
776
	  if (channel->flags & CHANNEL_SENT_CLOSE)
Niels Möller's avatar
Niels Möller committed
777
	    {
778
	      werror("Ignoring extended data on channel which is closing\n");
Niels Möller's avatar
Niels Möller committed
779
	      return LSH_OK | LSH_GOON;
Niels Möller's avatar
Niels Möller committed
780
	    }
Niels Möller's avatar
Niels Möller committed
781
	  else
Niels Möller's avatar
Niels Möller committed
782
	    {
783
784
	      int res = 0;
	      
Niels Möller's avatar
Niels Möller committed
785
786
787
	      if (data->length > channel->rec_window_size)
		{
		  /* Truncate data to fit window */
788
		  werror("Channel extended data overflow. "
Niels Möller's avatar
Niels Möller committed
789
790
791
792
793
			 "Extra data ignored.\n");
		  data->length = channel->rec_window_size;
		}
	      
	      channel->rec_window_size -= data->length;
794

795
796
797
798
799
800
	      /* FIXME: Like for do_channel_data(), unconditionally
	       * adjusting the window breaks flow control. */
	      res = adjust_rec_window(channel);

	      if (LSH_CLOSEDP(res))
		return res;
801

Niels Möller's avatar
Niels Möller committed
802
803
804
	      switch(type)
		{
		case SSH_EXTENDED_DATA_STDERR:
Niels Möller's avatar
Niels Möller committed
805
		  return channel_process_status(
806
		    connection->channels, channel_number,
807
		    res | CHANNEL_RECEIVE(channel, 
Niels Möller's avatar
Niels Möller committed
808
					  CHANNEL_STDERR_DATA, data));
Niels Möller's avatar
Niels Möller committed
809
		default:
810
		  werror("Unknown type %i of extended data.\n",
Niels Möller's avatar
Niels Möller committed
811
812
813
814
			 type);
		  lsh_string_free(data);
		  return LSH_FAIL | LSH_DIE;
		}
Niels Möller's avatar
Niels Möller committed
815
816
	    }
	}
817
      werror("Extended data on closed or non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
818
819
820
821
822
823
824
825
826
	     channel_number);
      lsh_string_free(data);
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  
  return LSH_FAIL | LSH_DIE;
}

827
828
static int do_channel_eof(struct packet_handler *closure UNUSED,
			  struct ssh_connection *connection,
829
			  struct lsh_string *packet)
Niels Möller's avatar
Niels Möller committed
830
831
{
  struct simple_buffer buffer;
832
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
833
834
835
836
837
838
  UINT32 channel_number;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_EOF)
839
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
840
841
      && parse_eod(&buffer))
    {
842
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
843
844
845
846
						   channel_number);

      lsh_string_free(packet);

Niels Möller's avatar
Niels Möller committed
847
848
      if (channel)
	{
849
850
	  int res = 0;
	  
851
	  if (channel->flags & (CHANNEL_RECEIVED_EOF | CHANNEL_RECEIVED_CLOSE))
Niels Möller's avatar
Niels Möller committed
852
	    {
853
	      werror("Receiving EOF on channel on closed channel.\n");
Niels Möller's avatar
Niels Möller committed
854
855
856
	      return LSH_FAIL | LSH_DIE;
	    }

857
	  channel->flags |= CHANNEL_RECEIVED_EOF;
Niels Möller's avatar
Niels Möller committed
858

859
860
	  if (channel->eof)
	    res = CHANNEL_EOF(channel);
861
862
863
	  else
	    /* FIXME: What is a reasonable default behaviour?
	     * Closing the channel may be the right thing to do. */
864
865
866
	    if (! (channel->flags & CHANNEL_SENT_CLOSE))
	      res |= channel_close(channel);
#if 0
867
868
869
	  if (!LSH_CLOSEDP(res)
	      && ! (channel->flags & CHANNEL_SENT_CLOSE)
	      && (channel->flags & CHANNEL_SENT_EOF))
Niels Möller's avatar
Niels Möller committed
870
871
872
	    {
	      /* Both parties have sent EOF. Initiate close, if we
	       * havn't done that already. */
873
874
	      
	      res |= channel_close(channel);
Niels Möller's avatar
Niels Möller committed
875
	    }
876
#endif      
877
	  return channel_process_status(connection->channels, channel_number,
878
879
					res);

Niels Möller's avatar
Niels Möller committed
880
	}
881
      werror("EOF on non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
882
883
	     channel_number);
      return LSH_FAIL | LSH_DIE;
Niels Möller's avatar
Niels Möller committed
884
    }
Niels Möller's avatar
Niels Möller committed
885
      
Niels Möller's avatar
Niels Möller committed
886
887
888
889
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

890
891
static int do_channel_close(struct packet_handler *closure UNUSED,
			    struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
892
893
894
			    struct lsh_string *packet)
{
  struct simple_buffer buffer;
895
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
896
897
898
899
900
901
  UINT32 channel_number;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_CLOSE)
902
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
903
904
      && parse_eod(&buffer))
    {
905
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
906
907
908
909
						   channel_number);

      lsh_string_free(packet);
      
Niels Möller's avatar
Niels Möller committed
910
911
      if (channel)
	{
912
913
	  int res = 0;
	  
914
	  if (channel->flags & CHANNEL_RECEIVED_CLOSE)
Niels Möller's avatar
Niels Möller committed
915
	    {
916
	      werror("Receiving multiple CLOSE on channel.\n");
Niels Möller's avatar
Niels Möller committed
917
918
919
	      return LSH_FAIL | LSH_DIE;
	    }

920
	  channel->flags |= CHANNEL_RECEIVED_CLOSE;
Niels Möller's avatar
Niels Möller committed
921
	  
922
	  if (! (channel->flags & (CHANNEL_RECEIVED_EOF | CHANNEL_SENT_EOF)))
Niels Möller's avatar
Niels Möller committed
923
	    {
924
	      werror("Unexpected channel CLOSE.\n");
Niels Möller's avatar
Niels Möller committed
925
	    }
926

927
	  if (! (channel->flags & (CHANNEL_RECEIVED_EOF))
928
	      && channel->eof)
929
	    res = CHANNEL_EOF(channel);
Niels Möller's avatar
Niels Möller committed
930
	  
Niels Möller's avatar
Niels Möller committed
931
	  return channel_process_status(
932
	    connection->channels, channel_number,
933
934
935
936
	    ( ( (channel->flags & (CHANNEL_SENT_CLOSE))
		? LSH_OK | LSH_CHANNEL_FINISHED
		: channel_close(channel))
	      | res));
Niels Möller's avatar
Niels Möller committed
937
	}
938
      werror("CLOSE on non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
939
940
	     channel_number);
      return LSH_FAIL | LSH_DIE;
Niels Möller's avatar
Niels Möller committed
941
942
943
944
945
946
      
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

947
static int do_channel_open_confirm(struct packet_handler *closure UNUSED,
Niels Möller's avatar
Niels Möller committed
948
949
				   struct ssh_connection *connection,
				   struct lsh_string *packet)
Niels Möller's avatar
Niels Möller committed
950
951
{
  struct simple_buffer buffer;
952
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
  UINT32 local_channel_number;
  UINT32 remote_channel_number;  
  UINT32 window_size;
  UINT32 max_packet;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_OPEN_CONFIRMATION)
      && parse_uint32(&buffer, &local_channel_number)
      && parse_uint32(&buffer, &remote_channel_number)
      && parse_uint32(&buffer, &window_size)
      && parse_uint32(&buffer, &max_packet)
      && parse_eod(&buffer))
    {
968
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
969
970
971
972
						   local_channel_number);

      lsh_string_free(packet);

973
      if (channel && channel->open_continuation)
Niels Möller's avatar
Niels Möller committed
974
975
976
977
978
	{
	  channel->channel_number = remote_channel_number;
	  channel->send_window_size = window_size;
	  channel->send_max_packet = max_packet;

979
980
981
982
	  return channel_process_status
	    (connection->channels,
	     local_channel_number,
	     COMMAND_RETURN(channel->open_continuation, channel));
Niels Möller's avatar
Niels Möller committed
983
	}
984
      werror("Unexpected SSH_MSG_CHANNEL_OPEN_CONFIRMATION on channel %i\n",
Niels Möller's avatar
Niels Möller committed
985
986
987
988
989
990
991
	     local_channel_number);
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

992
993
static int do_channel_open_failure(struct packet_handler *closure UNUSED,
			      struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
994
995
996
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
997
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
998
999
1000
1001
1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016
  UINT32 channel_number;
  UINT32 reason;

  UINT8 *msg;
  UINT32 length;

  UINT8 *language;
  UINT32 language_length;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_OPEN_FAILURE)
      && parse_uint32(&buffer, &channel_number)
      && parse_uint32(&buffer, &reason)
      && parse_string(&buffer, &length, &msg)
      && parse_string(&buffer, &language_length, &language)
      && parse_eod(&buffer))
    {
1017
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
1018
1019
1020
1021
						   channel_number);

      /* lsh_string_free(packet); */

1022
      if (channel && channel->open_continuation)
Niels Möller's avatar
Niels Möller committed
1023
	{
1024
	  int res = COMMAND_RETURN(channel->open_continuation, NULL);
Niels Möller's avatar
Niels Möller committed
1025
1026

	  lsh_string_free(packet);
Niels Möller's avatar
Niels Möller committed
1027

1028
	  return channel_process_status(connection->channels, channel_number,
Niels Möller's avatar
Niels Möller committed
1029
					res | LSH_CHANNEL_FINISHED);
Niels Möller's avatar
Niels Möller committed
1030
	}
1031
      werror("Unexpected SSH_MSG_CHANNEL_OPEN_FAILURE on channel %i\n",
Niels Möller's avatar
Niels Möller committed
1032
1033
1034
1035
1036
1037
1038
1039
1040
	     channel_number);
      lsh_string_free(packet);
      
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1041
1042
static int do_channel_success(struct packet_handler *closure UNUSED,
			      struct ssh_connection *connection,
1043
1044
1045
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
1046
  unsigned msg_number;
1047
  UINT32 channel_number;
1048
1049
  struct ssh_channel *channel;
      
1050
1051
1052
1053
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_SUCCESS)
1054
      && parse_uint32(&buffer, &channel_number)
1055
      && parse_eod(&buffer)
1056
      && (channel = lookup_channel(connection->channels, channel_number)))
1057
1058
    {
      lsh_string_free(packet);
1059

1060
      if (object_queue_is_empty(&channel->pending_requests))
1061
	{
1062
	  werror("do_channel_success: Unexpected message. Ignoring.\n");
1063
1064
	  return LSH_OK | LSH_GOON;
	}
1065
      {
Niels Möller's avatar
Niels Möller committed
1066
	CAST_SUBTYPE(command_continuation, c,
1067
1068
1069
1070
	     object_queue_remove_head(&channel->pending_requests));
	return channel_process_status(connection->channels, channel_number,
				      COMMAND_RETURN(c, channel));
      }
1071
1072
1073
1074
1075
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1076
1077
static int do_channel_failure(struct packet_handler *closure UNUSED,
			      struct ssh_connection *connection,
1078
1079
1080
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
1081
  unsigned msg_number;
1082
  UINT32 channel_number;
1083
  struct ssh_channel *channel;
1084
1085
1086
1087
1088
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_FAILURE)
1089
      && parse_uint32(&buffer, &channel_number)
1090
      && parse_eod(&buffer)
1091
      && (channel = lookup_channel(connection->channels, channel_number)))
1092
1093
1094
    {
      lsh_string_free(packet);
      
1095
      if (object_queue_is_empty(&channel->pending_requests))
1096
1097
1098
1099
	{
	  werror("do_channel_failure: No handler. Ignoring.\n");
	  return LSH_OK | LSH_GOON;
	}
1100
      {
Niels Möller's avatar
Niels Möller committed
1101
	CAST_SUBTYPE(command_continuation, c,
1102
1103
1104
1105
1106
	     object_queue_remove_head(&channel->pending_requests));

	return channel_process_status(connection->channels, channel_number,
				      COMMAND_RETURN(c, NULL));
      }
1107
1108
1109
1110
1111
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1112
1113
1114
static int do_connection_service(struct command *s,
				 struct lsh_object *x,
				 struct command_continuation *c)
Niels Möller's avatar
Niels Möller committed
1115
{
1116
  CAST(connection_service, self, s);
1117
  CAST(ssh_connection, connection, x);
1118

1119
  struct channel_table *table;
Niels Möller's avatar
Niels Möller committed
1120
  
1121
1122
  NEW(global_request_handler, globals);
  NEW(channel_open_handler, open);
1123
  NEW(packet_handler, request);
Niels Möller's avatar
Niels Möller committed
1124

1125
1126
1127
  NEW(packet_handler, adjust);
  NEW(packet_handler, data);
  NEW(packet_handler, extended);
Niels Möller's avatar
Niels Möller committed
1128

1129
1130
  NEW(packet_handler, eof);
  NEW(packet_handler, close);
1131

1132
1133
  NEW(packet_handler, open_confirm);
  NEW(packet_handler, open_failure);
Niels Möller's avatar
Niels Möller committed
1134

1135
1136
  NEW(packet_handler, channel_success);
  NEW(packet_handler, channel_failure);
Niels Möller's avatar
Niels Möller committed
1137

1138
  table = make_channel_table();
Niels Möller's avatar
Niels Möller committed
1139
  
1140
1141
1142
  connection->channels = table;
  
  globals->super.handler = do_global_request;
Niels Möller's avatar
Niels Möller committed
1143
  globals->global_requests = self->global_requests;
1144
  connection->dispatch[SSH_MSG_GLOBAL_REQUEST] = &globals->super;
Niels Möller's avatar
Niels Möller committed
1145
    
1146
  open->super.handler = do_channel_open;