channel.c 41 KB
Newer Older
Niels Möller's avatar
Niels Möller committed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
/* channel.c
 *
 * $Id$
 */

/* lsh, an implementation of the ssh protocol
 *
 * Copyright (C) 1998 Niels Mller
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License as
 * published by the Free Software Foundation; either version 2 of the
 * License, or (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
 * General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
J.H.M. Dassen's avatar
J.H.M. Dassen committed
22
 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
Niels Möller's avatar
Niels Möller committed
23
24
25
26
27
 */

#include "channel.h"

#include "format.h"
28
#include "io.h"
Niels Möller's avatar
Niels Möller committed
29
#include "read_data.h"
Niels Möller's avatar
Niels Möller committed
30
31
32
33
34
#include "ssh.h"
#include "werror.h"
#include "xalloc.h"

#include <assert.h>
35
#include <string.h>
Niels Möller's avatar
Niels Möller committed
36

37
#define GABA_DEFINE
38
#include "channel.h.x"
39
#undef GABA_DEFINE
40

41
42
#include "channel.c.x"

43
/* GABA:
44
45
   (class
     (name connection_service)
46
     (super command)
47
48
49
50
     (vars
       ; Supported global requests 
       (global_requests object alist)

51
       (channel_types object alist) ))
52
53
54
55

       ; Initialize connection (for instance, request channels to be 
       ; opened or services to be forwarded).

56
       ; (start object connection_startup)))
57
58
*/

59
/* ;; GABA:
60
61
   (class
     (name global_request_handler)
62
     (super packet_handler)
63
64
65
66
     (vars
       (global_requests object alist)))
*/

67
/* ;; GABA:
68
69
   (class
     (name channel_open_handler)
70
     (super packet_handler)
71
72
73
74
     (vars
       (channel_types object alist)))
*/

75
/* GABA:
76
77
78
79
80
81
82
83
84
   (class
     (name channel_open_response)
     (super channel_open_callback)
     (vars
       (remote_channel_number simple UINT32)
       (window_size simple UINT32)
       (max_packet simple UINT32)))
*/

Niels Möller's avatar
Niels Möller committed
85
86
87
88
89
struct lsh_string *format_global_failure(void)
{
  return ssh_format("%c", SSH_MSG_REQUEST_FAILURE);
}

90
91
92
93
94
struct lsh_string *format_global_success(void)
{
  return ssh_format("%c", SSH_MSG_REQUEST_SUCCESS);
}

95
96
struct lsh_string *format_open_confirmation(struct ssh_channel *channel,
					    UINT32 channel_number,
97
					    const char *format, ...)
98
99
100
101
102
103
{
  va_list args;
  UINT32 l1, l2;
  struct lsh_string *packet;

#define CONFIRM_FORMAT "%c%i%i%i%i"
104
105
#define CONFIRM_ARGS \
  SSH_MSG_CHANNEL_OPEN_CONFIRMATION, channel->channel_number, \
106
107
108
109
110
111
112
113
114
115
116
117
118
  channel_number, channel->rec_window_size, channel->rec_max_packet
    
  l1 = ssh_format_length(CONFIRM_FORMAT, CONFIRM_ARGS);

  va_start(args, format);
  l2 = ssh_vformat_length(format, args);
  va_end(args);

  packet = lsh_string_alloc(l1 + l2);

  ssh_format_write(CONFIRM_FORMAT, l1, packet->data, CONFIRM_ARGS);

  va_start(args, format);
119
  ssh_vformat_write(format, l2, packet->data+l1, args);
120
121
122
123
124
125
126
  va_end(args);

  return packet;
#undef CONFIRM_FORMAT
#undef CONFIRM_ARGS
}

Niels Möller's avatar
Niels Möller committed
127
struct lsh_string *format_open_failure(UINT32 channel, UINT32 reason,
128
				       const char *msg, const char *language)
Niels Möller's avatar
Niels Möller committed
129
130
131
132
133
{
  return ssh_format("%c%i%i%z%z", SSH_MSG_CHANNEL_OPEN_FAILURE,
		    channel, reason, msg, language);
}

134
135
136
137
138
struct lsh_string *format_channel_success(UINT32 channel)
{
  return ssh_format("%c%i", SSH_MSG_CHANNEL_SUCCESS, channel);
}

Niels Möller's avatar
Niels Möller committed
139
140
141
142
143
struct lsh_string *format_channel_failure(UINT32 channel)
{
  return ssh_format("%c%i", SSH_MSG_CHANNEL_FAILURE, channel);
}

144
145
146
147
148
149
150
151
152
153
struct lsh_string *prepare_window_adjust(struct ssh_channel *channel,
					 UINT32 add)
{
  channel->rec_window_size += add;
  
  return ssh_format("%c%i%i",
		    SSH_MSG_CHANNEL_WINDOW_ADJUST,
		    channel->channel_number, add);
}

154
/* Channel objects */
Niels Möller's avatar
Niels Möller committed
155
156
157
158
159

#define INITIAL_CHANNELS 32
/* Arbitrary limit */
#define MAX_CHANNELS (1L<<17)

Niels Möller's avatar
Niels Möller committed
160
struct channel_table *make_channel_table(void)
Niels Möller's avatar
Niels Möller committed
161
{
162
  NEW(channel_table, table);
Niels Möller's avatar
Niels Möller committed
163

164
  table->channels = lsh_space_alloc(sizeof(struct ssh_channel *)
165
				      * INITIAL_CHANNELS);
166
167
168
169
  table->allocated_channels = INITIAL_CHANNELS;
  table->next_channel = 0;
  table->used_channels = 0;
  table->max_channels = MAX_CHANNELS;
Niels Möller's avatar
Niels Möller committed
170

Niels Möller's avatar
Niels Möller committed
171
  table->pending_close = 0;
172

173
174
175
  table->global_requests = make_alist(0, -1);
  table->channel_types = make_alist(0, -1);
  
176
177
178
  object_queue_init(&table->local_ports);
  object_queue_init(&table->remote_ports);
  
179
180
  object_queue_init(&table->active_global_requests);
  object_queue_init(&table->pending_global_requests);
Niels Möller's avatar
Niels Möller committed
181
  
182
  return table;
Niels Möller's avatar
Niels Möller committed
183
184
185
};

/* Returns -1 if allocation fails */
186
187
188
/* NOTE: This function returns locally chosen channel numbers, which
 * are always small integers. So there's no problem fitting them in
 * a signed int. */
189
int alloc_channel(struct channel_table *table)
Niels Möller's avatar
Niels Möller committed
190
{
191
  UINT32 i;
192
  
193
  for(i = table->next_channel; i < table->used_channels; i++)
Niels Möller's avatar
Niels Möller committed
194
    {
195
      if (!table->channels[i])
Niels Möller's avatar
Niels Möller committed
196
	{
197
	  table->next_channel = i+1;
Niels Möller's avatar
Niels Möller committed
198
199
200
	  return i;
	}
    }
201
  if (i == table->max_channels)
Niels Möller's avatar
Niels Möller committed
202
    return -1;
203

204
  if (i == table->allocated_channels) 
Niels Möller's avatar
Niels Möller committed
205
    {
206
      int new_size = table->allocated_channels * 2;
Niels Möller's avatar
Niels Möller committed
207
      struct ssh_channel **new
208
	= lsh_space_alloc(sizeof(struct ssh_channel *) * new_size);
Niels Möller's avatar
Niels Möller committed
209

210
211
      memcpy(new, table->channels,
	     sizeof(struct ssh_channel *) * table->used_channels);
Niels Möller's avatar
Niels Möller committed
212
      
213
214
      table->channels = new;
      table->allocated_channels = new_size;
Niels Möller's avatar
Niels Möller committed
215
216
    }

217
  table->next_channel = table->used_channels = i+1;
Niels Möller's avatar
Niels Möller committed
218
219
220
221

  return i;
}

222
void dealloc_channel(struct channel_table *table, int i)
Niels Möller's avatar
Niels Möller committed
223
224
{
  assert(i >= 0);
225
  assert( (unsigned) i < table->used_channels);
Niels Möller's avatar
Niels Möller committed
226
  
227
228
  table->channels[i] = NULL;

229
  if ( (unsigned) i < table->next_channel)
230
231
232
    table->next_channel = i;
}

233
234
/* Returns -1 if no channel number can be allocated. See also the note
 * for alloc_channel(). */
235
236
237
238
239
240
int register_channel(struct channel_table *table, struct ssh_channel *channel)
{
  int n = alloc_channel(table);

  if (n >= 0)
    table->channels[n] = channel;
Niels Möller's avatar
Niels Möller committed
241

242
  return n;
Niels Möller's avatar
Niels Möller committed
243
244
}

245
struct ssh_channel *lookup_channel(struct channel_table *table, UINT32 i)
Niels Möller's avatar
Niels Möller committed
246
{
247
248
  return (i < table->used_channels)
    ? table->channels[i] : NULL;
Niels Möller's avatar
Niels Möller committed
249
250
}

251
252
253
254
255
256
257
258
259
260
/* FIXME: It seems suboptimal to send a window adjust message for *every* write that we do.
 * A better scheme might be as follows:
 *
 * Delay window adjust messages, keeping track of both the locally
 * maintained window size, which is updated after each write, and the
 * size that has been reported to the remote end. When the difference
 * between these two values gets large enough (say, larger than one
 * half or one third of the maximum window size), we send a
 * window_adjust message to sync them. */
static void adjust_rec_window(struct flow_controlled *f, UINT32 written)
261
{
262
263
264
265
266
267
268
269
  CAST_SUBTYPE(ssh_channel, channel, f);

  int res = A_WRITE(channel->write,
		    prepare_window_adjust
		    (channel, written));
  if (res)
    werror("adjust_rec_window: Writing window adjust message failed, ignoring\n"
	   "  (res = %i)\n", res);
270
271
}

272
273
274
275
276
277
278
int channel_start_receive(struct ssh_channel *channel)
{
  return A_WRITE(channel->write,
		 prepare_window_adjust
		 (channel, channel->max_window - channel->rec_window_size));
}

279
280
/* Process channel-related status codes. Used by the packet handlers,
 * before returning. */
Niels Möller's avatar
Niels Möller committed
281
282
283
284
static int channel_process_status(struct channel_table *table,
				  int channel,
				  int status)
{
285
286
287
288
  struct ssh_channel *c = table->channels[channel];
  
  while (!LSH_CLOSEDP(status))
    {
289
290
291
292
293
294
295
      if (status & LSH_CHANNEL_CLOSE)
	{ /* Close the channel now */ 
	  if (!c->flags & CHANNEL_SENT_CLOSE)
	    status |= channel_close(c);
	  break;
	}
      
296
297
298
299
300
301
302
303
304
      if (status & LSH_CHANNEL_READY_SEND)
	{
	  status &= ~ LSH_CHANNEL_READY_SEND;
	  if (c->send_window_size)
	    status |= CHANNEL_SEND(c);
	}
      else if (status & LSH_CHANNEL_READY_REC)
	{
	  status &= ~ LSH_CHANNEL_READY_REC;
305
	  status |= channel_start_receive(c);
306
307
308
309
310
	}
      else
	break;
    }
	
Niels Möller's avatar
Niels Möller committed
311
312
313
314
  if (status & LSH_CHANNEL_FINISHED)
    {
      /* Clear this bit */
      status &= ~LSH_CHANNEL_FINISHED;
315

316
      if (c->close)
317
	status |= CHANNEL_CLOSE(c);
Niels Möller's avatar
Niels Möller committed
318
319
320
321
      
      dealloc_channel(table, channel);
    }

322
323
324
325
326
327
328
  if (status & LSH_CHANNEL_PENDING_CLOSE)
    table->pending_close = 1;
  
  /* If this was the last channel, close connection */
  if (table->pending_close && !table->next_channel)
    status |= LSH_CLOSE;

Niels Möller's avatar
Niels Möller committed
329
330
  return status;
}
Niels Möller's avatar
Niels Möller committed
331

332
333
334
335
336
337
338
/* Ugly macros to make it a little simpler to free the input packet at
 * the right time. */

#define START int foo_res
#define RETURN(x) do { foo_res = (x); goto foo_finish; } while(0)
#define END(s) foo_finish: do { lsh_string_free((s)); return foo_res; } while(0)

Niels Möller's avatar
Niels Möller committed
339
/* Channel related messages */
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371

/* GABA:
   (class
     (name global_request_status)
     (vars
       ; -1 for still active requests,
       ; 0 for failure,
       ; 1 for success
       (status . int)))
*/

static struct global_request_status *make_global_request_status(void)
{
  NEW(global_request_status, self);
  self->status = -1;

  return self;
}

/* GABA:
   (class
     (name global_request_response)
     (super global_request_callback)
     (vars
       (active object global_request_status)))
*/

static int
do_global_request_response(struct global_request_callback *c,
			   int success)
{
  CAST(global_request_response, self, c);
372
  struct object_queue *q = &self->super.connection->channels->active_global_requests;
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413

  int res = 0;
  
  assert( self->active->status == -1);
  assert( (success == 0) || (success == 1) );
  assert( !object_queue_is_empty(q));
	  
  self->active->status = success;

  for (;;)
    {
      CAST(global_request_status, n, object_queue_peek_head(q));
      if (!n || (n->status < 0))
	return res;

      object_queue_remove_head(q);
      
      res |= A_WRITE(self->super.connection->write,
		     (n->status
		      ? format_global_success()
		      : format_global_failure()));
      
      if (LSH_CLOSEDP(res))
	return res;
    }
}

static struct global_request_callback *
make_global_request_response(struct ssh_connection *connection,
			     struct global_request_status *active)
{
  NEW(global_request_response, self);

  self->super.connection = connection;
  self->super.response = do_global_request_response;

  self->active = active;

  return &self->super;
}
     
414
static int do_global_request(struct packet_handler *s UNUSED,
Niels Möller's avatar
Niels Möller committed
415
416
417
			     struct ssh_connection *connection,
			     struct lsh_string *packet)
{
418
  /* CAST(global_request_handler, closure, c); */
Niels Möller's avatar
Niels Möller committed
419
420

  struct simple_buffer buffer;
421
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
422
423
  int name;
  int want_reply;
424
  START;
Niels Möller's avatar
Niels Möller committed
425
426
427
428
429
430
431
432
433
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_GLOBAL_REQUEST)
      && parse_atom(&buffer, &name)
      && parse_boolean(&buffer, &want_reply))
    {
      struct global_request *req;
434
435
      struct global_request_callback *c = NULL;
      
436
437
      if (!name || !(req = ALIST_GET(connection->channels->global_requests,
				     name)))
438
439
	RETURN (A_WRITE(connection->write,
		       format_global_failure()));
Niels Möller's avatar
Niels Möller committed
440

441
442
443
444
      if (want_reply)
	{
	  struct global_request_status *a = make_global_request_status();

445
	  object_queue_add_tail(&connection->channels->active_global_requests,
446
447
448
449
450
				&a->super);
	  
	  c = make_global_request_response(connection, a);
	}
      RETURN (GLOBAL_REQUEST(req, connection, &buffer, c));
Niels Möller's avatar
Niels Möller committed
451
    }
452
  RETURN (LSH_FAIL | LSH_DIE);
Niels Möller's avatar
Niels Möller committed
453

454
  END (packet);
Niels Möller's avatar
Niels Möller committed
455
456
}

457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
static int do_global_request_success(struct packet_handler *s UNUSED,
				     struct ssh_connection *connection,
				     struct lsh_string *packet)
{
  if (packet->length != 1)
    return LSH_FAIL | LSH_DIE;

  assert(packet->data[0] == SSH_MSG_REQUEST_SUCCESS);

  if (object_queue_is_empty(&connection->channels->pending_global_requests))
    {
      werror("do_global_request_success: Unexpected message, ignoring.\n");
      return LSH_OK | LSH_GOON;
    }
  {
    CAST_SUBTYPE(command_continuation, c,
		 object_queue_remove_head(&connection->channels->pending_global_requests));
    return COMMAND_RETURN(c, connection);
  }
}

static int do_global_request_failure(struct packet_handler *s UNUSED,
				     struct ssh_connection *connection,
				     struct lsh_string *packet)
{
  if (packet->length != 1)
    return LSH_FAIL | LSH_DIE;

  assert(packet->data[0] == SSH_MSG_REQUEST_FAILURE);

  if (object_queue_is_empty(&connection->channels->pending_global_requests))
    {
      werror("do_global_request_failure: Unexpected message, ignoring.\n");
      return LSH_OK | LSH_GOON;
    }
  {
    CAST_SUBTYPE(command_continuation, c,
		 object_queue_remove_head(&connection->channels->pending_global_requests));
    return COMMAND_RETURN(c, NULL);
  }
}


500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
/* Callback given to the CHANNEL_OPEN method */
static int do_channel_open_response(struct channel_open_callback *c,
                                    struct ssh_channel *channel,
                                    UINT32 error, char *error_msg,
                                    struct lsh_string *args)
{
  CAST(channel_open_response, closure, c);
  
  int local_channel_number;

  if (!channel)
    {
      if (error)
        return A_WRITE(closure->super.connection->write,
                       format_open_failure(closure->remote_channel_number,
                                           error, error_msg, ""));
516
517
      /* The request was invalid */
      return LSH_FAIL | LSH_DIE;
518
519
520
521
522
523
524
525
526
527
528
529
530
531
    }

  if ( (local_channel_number
            = register_channel(closure->super.connection->channels,
			       channel)) < 0)
    {
      werror("Could not allocate a channel number for opened channel!\n");
      return A_WRITE(closure->super.connection->write,
                     format_open_failure(closure->remote_channel_number,
                                         SSH_OPEN_RESOURCE_SHORTAGE,
                                         "Could not allocate a channel number "
                                         "(shouldn't happen...)", ""));
    }

532
  /* FIXME: This copying could just as well be done by the
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
   * CHANNEL_OPEN handler? Then we can remove the corresponding fields
   * from the closure as well. */
  channel->send_window_size = closure->window_size;
  channel->send_max_packet = closure->max_packet;
  channel->channel_number = closure->remote_channel_number;

  /* FIXME: Is the channel->write field really needed? */
  channel->write = closure->super.connection->write;

  return A_WRITE(closure->super.connection->write,
                 args
                 ? format_open_confirmation(channel, local_channel_number,
                                            "%lfS", args)
                 : format_open_confirmation(channel, local_channel_number,
                                            ""));
}

static struct channel_open_response *
make_channel_open_response(struct ssh_connection* connection,
			   UINT32 remote_channel_number,
			   UINT32 window_size,
			   UINT32 max_packet)
{
  NEW(channel_open_response, closure);

  closure->super.response = do_channel_open_response;
  closure->super.connection = connection;
  closure->remote_channel_number = remote_channel_number;
  closure->window_size = window_size;
  closure->max_packet = max_packet;

  return closure;
}
566

567

568
569
570
571
572
573
574
575
576
577
578
#if 0
/* ;;GABA:
   (class
     (name channel_open_continuation)
     (super command_continuation)
     (vars
       (connection object ssh_connection)
       (remote_channel_number simple UINT32)
       (window_size simple UINT32)
       (max_packet simple UINT32)))
*/
579

580
581
582
583
584
585
586
587
static int do_channel_open_continue(struct command_continuation *c,
				    struct lsh_object *result)
{
  CAST(channel_open_continuation, self, c);
  CAST_SUBTYPE(channel);
}
#endif
				    
588
static int do_channel_open(struct packet_handler *c UNUSED,
Niels Möller's avatar
Niels Möller committed
589
590
591
			   struct ssh_connection *connection,
			   struct lsh_string *packet)
{
592
  /* CAST(channel_open_handler, closure, c); */
Niels Möller's avatar
Niels Möller committed
593
594

  struct simple_buffer buffer;
595
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
596
  int type;
597
598
599
  UINT32 remote_channel_number;
  UINT32 window_size;
  UINT32 max_packet;
600
  START;
Niels Möller's avatar
Niels Möller committed
601
602
603
604
605
606
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_OPEN)
      && parse_atom(&buffer, &type)
607
608
609
      && parse_uint32(&buffer, &remote_channel_number)
      && parse_uint32(&buffer, &window_size)
      && parse_uint32(&buffer, &max_packet))
Niels Möller's avatar
Niels Möller committed
610
611
    {
      struct channel_open *open;
612
613
      struct channel_open_response *response;
      int res;
614
      
615
      if (connection->channels->pending_close)
Niels Möller's avatar
Niels Möller committed
616
	/* We are waiting for channels to close. Don't open any new ones. */
617
618
619
620
621
	RETURN
	  (A_WRITE(connection->write,
		   format_open_failure(remote_channel_number,
				       SSH_OPEN_ADMINISTRATIVELY_PROHIBITED,
				       "Waiting for channels to close.", "")));
Niels Möller's avatar
Niels Möller committed
622
      
623
624
      if (!type || !(open = ALIST_GET(connection->channels->channel_types,
				      type)))
625
626
627
628
	RETURN (A_WRITE(connection->write,
			format_open_failure(remote_channel_number,
					    SSH_OPEN_UNKNOWN_CHANNEL_TYPE,
					    "Unknown channel type", "")));
629

630
631
632
633
634
635
636
637
      response = make_channel_open_response(connection,
					    remote_channel_number,
					    window_size, max_packet);
      /* NOTE: If the channel could be opened immediately, this method
       * will call response right away. */
      res = CHANNEL_OPEN(open, connection, &buffer, &response->super);

      RETURN (res);
Niels Möller's avatar
Niels Möller committed
638
    }
639
  RETURN (LSH_FAIL | LSH_DIE);
Niels Möller's avatar
Niels Möller committed
640

641
  END(packet);
Niels Möller's avatar
Niels Möller committed
642
643
}     

644
static int do_channel_request(struct packet_handler *closure UNUSED,
Niels Möller's avatar
Niels Möller committed
645
646
647
648
			      struct ssh_connection *connection,
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
649
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
650
651
652
  UINT32 channel_number;
  int type;
  int want_reply;
653
654
  START;
  
Niels Möller's avatar
Niels Möller committed
655
656
657
658
659
660
661
662
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_REQUEST)
      && parse_uint32(&buffer, &channel_number)
      && parse_atom(&buffer, &type)
      && parse_boolean(&buffer, &want_reply))
    {
663
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
664
665
						   channel_number);

666
667
668
669
      /* NOTE: We can't free packet yet, because it is not yet fully
       * parsed. There may be some more arguments, which are parsed by
       * the CHANNEL_REQUEST method below. */

Niels Möller's avatar
Niels Möller committed
670
671
672
673
      if (channel)
	{
	  struct channel_request *req;

674
675
	  if (type && channel->request_types 
	      && ( (req = ALIST_GET(channel->request_types, type)) ))
676
677
678
679
	    RETURN
	      (channel_process_status
	       (connection->channels, channel_number,
		CHANNEL_REQUEST(req, channel, connection, want_reply, &buffer)));
680
	  else
681
682
683
684
	    RETURN (want_reply
		    ? A_WRITE(connection->write,
			      format_channel_failure(channel->channel_number))
		    : LSH_OK | LSH_GOON);
685
	  
Niels Möller's avatar
Niels Möller committed
686
	}
687
      werror("SSH_MSG_CHANNEL_REQUEST on nonexistant channel %i\n",
Niels Möller's avatar
Niels Möller committed
688
689
	     channel_number);

690
691
692
693
    }
  RETURN (LSH_FAIL | LSH_DIE);
  
  END(packet);
Niels Möller's avatar
Niels Möller committed
694
695
}
      
696
697
static int do_window_adjust(struct packet_handler *closure UNUSED,
			    struct ssh_connection *connection,
698
			    struct lsh_string *packet)
Niels Möller's avatar
Niels Möller committed
699
700
{
  struct simple_buffer buffer;
701
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
702
703
704
705
706
707
708
  UINT32 channel_number;
  UINT32 size;

  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_WINDOW_ADJUST)
709
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
710
711
712
      && parse_uint32(&buffer, &size)
      && parse_eod(&buffer))
    {
713
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
714
715
716
717
						   channel_number);

      lsh_string_free(packet);
      
Niels Möller's avatar
Niels Möller committed
718
      if (channel
719
720
	  && !(channel->flags & (CHANNEL_RECEIVED_EOF
				 | CHANNEL_RECEIVED_CLOSE)))
Niels Möller's avatar
Niels Möller committed
721
	{
Niels Möller's avatar
Niels Möller committed
722
723
724
725
	  if (! (channel->flags & CHANNEL_SENT_CLOSE))
	    {
	      channel->send_window_size += size;
	      if (channel->send_window_size && channel->send)
726
		return channel_process_status(connection->channels,
Niels Möller's avatar
Niels Möller committed
727
728
					      channel_number,
					      CHANNEL_SEND(channel));
Niels Möller's avatar
Niels Möller committed
729
	    }
Niels Möller's avatar
Niels Möller committed
730
731
732
733
	  return LSH_OK | LSH_GOON;
	}
      /* FIXME: What to do now? Should unknown channel numbers be
       * ignored silently? */
734
735
      werror("SSH_MSG_CHANNEL_WINDOW_ADJUST on nonexistant or closed "
	     "channel %i\n", channel_number);
Niels Möller's avatar
Niels Möller committed
736
737
738
739
740
741
742
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);

  return LSH_FAIL | LSH_DIE;
}

743
744
static int do_channel_data(struct packet_handler *closure UNUSED,
			   struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
745
746
747
			   struct lsh_string *packet)
{
  struct simple_buffer buffer;
748
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
749
750
751
752
753
754
755
  UINT32 channel_number;
  struct lsh_string *data;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_DATA)
756
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
757
758
759
      && ( (data = parse_string_copy(&buffer)) )
      && parse_eod(&buffer))
    {
760
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
761
762
763
764
						   channel_number);

      lsh_string_free(packet);
      
765
      if (channel && channel->receive
766
767
	  && !(channel->flags & (CHANNEL_RECEIVED_EOF
				 | CHANNEL_RECEIVED_CLOSE)))
Niels Möller's avatar
Niels Möller committed
768
	{
Niels Möller's avatar
Niels Möller committed
769
	  if (channel->flags & CHANNEL_SENT_CLOSE)
Niels Möller's avatar
Niels Möller committed
770
	    {
771
	      werror("Ignoring data on channel which is closing\n");
Niels Möller's avatar
Niels Möller committed
772
	      return LSH_OK | LSH_GOON;
Niels Möller's avatar
Niels Möller committed
773
	    }
Niels Möller's avatar
Niels Möller committed
774
775
	  else
	    {
776
777
	      int res = 0;
	      
Niels Möller's avatar
Niels Möller committed
778
779
780
	      if (data->length > channel->rec_window_size)
		{
		  /* Truncate data to fit window */
781
		  werror("Channel data overflow. Extra data ignored.\n"); 
Niels Möller's avatar
Niels Möller committed
782
783
		  data->length = channel->rec_window_size;
		}
784
785
786
787

	      if (!data->length)
		/* Ignore data packet */
		return 0;
788
789
	      channel->rec_window_size -= data->length;

790
#if 0
791
	      /* FIXME: Unconditionally adjusting the receive window
792
	       * breaks flow control. We better let the channel's
793
	       * receive method decide whether or not to receive more
794
795
	       * data. */
	      res = adjust_rec_window(channel);
796

797
798
	      if (LSH_CLOSEDP(res))
		return res;
799
800
#endif
	      
Niels Möller's avatar
Niels Möller committed
801
	      return channel_process_status(
802
		connection->channels, channel_number,
803
		res | CHANNEL_RECEIVE(channel, 
Niels Möller's avatar
Niels Möller committed
804
				      CHANNEL_DATA, data));
Niels Möller's avatar
Niels Möller committed
805
806
	    }
	  return LSH_OK | LSH_GOON;
Niels Möller's avatar
Niels Möller committed
807
808
	}
	  
809
      werror("Data on closed or non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
810
811
812
813
814
815
816
817
818
	     channel_number);
      lsh_string_free(data);
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  
  return LSH_FAIL | LSH_DIE;
}

819
820
static int do_channel_extended_data(struct packet_handler *closure UNUSED,
				    struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
821
822
823
				    struct lsh_string *packet)
{
  struct simple_buffer buffer;
824
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
825
826
827
828
829
830
831
832
  UINT32 channel_number;
  UINT32 type;
  struct lsh_string *data;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_EXTENDED_DATA)
833
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
834
835
836
837
      && parse_uint32(&buffer, &type)
      && ( (data = parse_string_copy(&buffer)) )
      && parse_eod(&buffer))
    {
838
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
839
840
841
842
						   channel_number);

      lsh_string_free(packet);
      
843
      if (channel && channel->receive
844
845
	  && !(channel->flags & (CHANNEL_RECEIVED_EOF
				 | CHANNEL_RECEIVED_CLOSE)))
Niels Möller's avatar
Niels Möller committed
846
	{
Niels Möller's avatar
Niels Möller committed
847
	  if (channel->flags & CHANNEL_SENT_CLOSE)
Niels Möller's avatar
Niels Möller committed
848
	    {
849
	      werror("Ignoring extended data on channel which is closing\n");
Niels Möller's avatar
Niels Möller committed
850
	      return LSH_OK | LSH_GOON;
Niels Möller's avatar
Niels Möller committed
851
	    }
Niels Möller's avatar
Niels Möller committed
852
	  else
Niels Möller's avatar
Niels Möller committed
853
	    {
854
855
	      int res = 0;
	      
Niels Möller's avatar
Niels Möller committed
856
857
858
	      if (data->length > channel->rec_window_size)
		{
		  /* Truncate data to fit window */
859
		  werror("Channel extended data overflow. "
Niels Möller's avatar
Niels Möller committed
860
861
862
863
864
			 "Extra data ignored.\n");
		  data->length = channel->rec_window_size;
		}
	      
	      channel->rec_window_size -= data->length;
865

866
#if 0
867
868
869
870
871
872
	      /* FIXME: Like for do_channel_data(), unconditionally
	       * adjusting the window breaks flow control. */
	      res = adjust_rec_window(channel);

	      if (LSH_CLOSEDP(res))
		return res;
873
#endif
874

Niels Möller's avatar
Niels Möller committed
875
876
877
	      switch(type)
		{
		case SSH_EXTENDED_DATA_STDERR:
Niels Möller's avatar
Niels Möller committed
878
		  return channel_process_status(
879
		    connection->channels, channel_number,
880
		    res | CHANNEL_RECEIVE(channel, 
Niels Möller's avatar
Niels Möller committed
881
					  CHANNEL_STDERR_DATA, data));
Niels Möller's avatar
Niels Möller committed
882
		default:
883
		  werror("Unknown type %i of extended data.\n",
Niels Möller's avatar
Niels Möller committed
884
885
886
887
			 type);
		  lsh_string_free(data);
		  return LSH_FAIL | LSH_DIE;
		}
Niels Möller's avatar
Niels Möller committed
888
889
	    }
	}
890
      werror("Extended data on closed or non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
891
892
893
894
895
896
897
898
899
	     channel_number);
      lsh_string_free(data);
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  
  return LSH_FAIL | LSH_DIE;
}

900
901
static int do_channel_eof(struct packet_handler *closure UNUSED,
			  struct ssh_connection *connection,
902
			  struct lsh_string *packet)
Niels Möller's avatar
Niels Möller committed
903
904
{
  struct simple_buffer buffer;
905
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
906
907
908
909
910
911
  UINT32 channel_number;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_EOF)
912
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
913
914
      && parse_eod(&buffer))
    {
915
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
916
917
918
919
						   channel_number);

      lsh_string_free(packet);

Niels Möller's avatar
Niels Möller committed
920
921
      if (channel)
	{
922
923
	  int res = 0;
	  
924
	  if (channel->flags & (CHANNEL_RECEIVED_EOF | CHANNEL_RECEIVED_CLOSE))
Niels Möller's avatar
Niels Möller committed
925
	    {
926
	      werror("Receiving EOF on channel on closed channel.\n");
Niels Möller's avatar
Niels Möller committed
927
928
929
	      return LSH_FAIL | LSH_DIE;
	    }

930
	  channel->flags |= CHANNEL_RECEIVED_EOF;
Niels Möller's avatar
Niels Möller committed
931

932
933
	  if (channel->eof)
	    res = CHANNEL_EOF(channel);
934
935
936
	  else
	    /* FIXME: What is a reasonable default behaviour?
	     * Closing the channel may be the right thing to do. */
937
938
939
	    if (! (channel->flags & CHANNEL_SENT_CLOSE))
	      res |= channel_close(channel);
#if 0
940
941
942
	  if (!LSH_CLOSEDP(res)
	      && ! (channel->flags & CHANNEL_SENT_CLOSE)
	      && (channel->flags & CHANNEL_SENT_EOF))
Niels Möller's avatar
Niels Möller committed
943
944
945
	    {
	      /* Both parties have sent EOF. Initiate close, if we
	       * havn't done that already. */
946
947
	      
	      res |= channel_close(channel);
Niels Möller's avatar
Niels Möller committed
948
	    }
949
#endif      
950
	  return channel_process_status(connection->channels, channel_number,
951
952
					res);

Niels Möller's avatar
Niels Möller committed
953
	}
954
      werror("EOF on non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
955
956
	     channel_number);
      return LSH_FAIL | LSH_DIE;
Niels Möller's avatar
Niels Möller committed
957
    }
Niels Möller's avatar
Niels Möller committed
958
      
Niels Möller's avatar
Niels Möller committed
959
960
961
962
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

963
964
static int do_channel_close(struct packet_handler *closure UNUSED,
			    struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
965
966
967
			    struct lsh_string *packet)
{
  struct simple_buffer buffer;
968
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
969
970
971
972
973
974
  UINT32 channel_number;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_CLOSE)
975
      && parse_uint32(&buffer, &channel_number)
Niels Möller's avatar
Niels Möller committed
976
977
      && parse_eod(&buffer))
    {
978
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
979
980
981
982
						   channel_number);

      lsh_string_free(packet);
      
Niels Möller's avatar
Niels Möller committed
983
984
      if (channel)
	{
985
986
	  int res = 0;
	  
987
	  if (channel->flags & CHANNEL_RECEIVED_CLOSE)
Niels Möller's avatar
Niels Möller committed
988
	    {
989
	      werror("Receiving multiple CLOSE on channel.\n");
Niels Möller's avatar
Niels Möller committed
990
991
992
	      return LSH_FAIL | LSH_DIE;
	    }

993
	  channel->flags |= CHANNEL_RECEIVED_CLOSE;
Niels Möller's avatar
Niels Möller committed
994
	  
995
	  if (! (channel->flags & (CHANNEL_RECEIVED_EOF | CHANNEL_SENT_EOF)))
Niels Möller's avatar
Niels Möller committed
996
	    {
997
	      werror("Unexpected channel CLOSE.\n");
Niels Möller's avatar
Niels Möller committed
998
	    }
999

1000
	  if (! (channel->flags & (CHANNEL_RECEIVED_EOF))
1001
	      && channel->eof)
1002
	    res = CHANNEL_EOF(channel);
Niels Möller's avatar
Niels Möller committed
1003
	  
Niels Möller's avatar
Niels Möller committed
1004
	  return channel_process_status(
1005
	    connection->channels, channel_number,
1006
1007
1008
1009
	    ( ( (channel->flags & (CHANNEL_SENT_CLOSE))
		? LSH_OK | LSH_CHANNEL_FINISHED
		: channel_close(channel))
	      | res));
Niels Möller's avatar
Niels Möller committed
1010
	}
1011
      werror("CLOSE on non-existant channel %i\n",
Niels Möller's avatar
Niels Möller committed
1012
1013
	     channel_number);
      return LSH_FAIL | LSH_DIE;
Niels Möller's avatar
Niels Möller committed
1014
1015
1016
1017
1018
1019
      
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1020
static int do_channel_open_confirm(struct packet_handler *closure UNUSED,
Niels Möller's avatar
Niels Möller committed
1021
1022
				   struct ssh_connection *connection,
				   struct lsh_string *packet)
Niels Möller's avatar
Niels Möller committed
1023
1024
{
  struct simple_buffer buffer;
1025
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
1026
1027
1028
1029
1030
1031
1032
1033
1034
1035
1036
1037
1038
1039
1040
  UINT32 local_channel_number;
  UINT32 remote_channel_number;  
  UINT32 window_size;
  UINT32 max_packet;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_OPEN_CONFIRMATION)
      && parse_uint32(&buffer, &local_channel_number)
      && parse_uint32(&buffer, &remote_channel_number)
      && parse_uint32(&buffer, &window_size)
      && parse_uint32(&buffer, &max_packet)
      && parse_eod(&buffer))
    {
1041
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
1042
1043
1044
1045
						   local_channel_number);

      lsh_string_free(packet);

1046
      if (channel && channel->open_continuation)
Niels Möller's avatar
Niels Möller committed
1047
	{
1048
1049
1050
	  struct command_continuation *c = channel->open_continuation;
	  channel->open_continuation = NULL;
	  
Niels Möller's avatar
Niels Möller committed
1051
1052
1053
1054
	  channel->channel_number = remote_channel_number;
	  channel->send_window_size = window_size;
	  channel->send_max_packet = max_packet;

1055
1056
1057
	  return channel_process_status
	    (connection->channels,
	     local_channel_number,
1058
	     COMMAND_RETURN(c, channel));
Niels Möller's avatar
Niels Möller committed
1059
	}
1060
      werror("Unexpected SSH_MSG_CHANNEL_OPEN_CONFIRMATION on channel %i\n",
Niels Möller's avatar
Niels Möller committed
1061
1062
1063
1064
1065
1066
1067
	     local_channel_number);
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1068
1069
static int do_channel_open_failure(struct packet_handler *closure UNUSED,
			      struct ssh_connection *connection,
Niels Möller's avatar
Niels Möller committed
1070
1071
1072
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
1073
  unsigned msg_number;
Niels Möller's avatar
Niels Möller committed
1074
1075
1076
1077
1078
1079
1080
1081
1082
1083
1084
1085
1086
1087
1088
1089
1090
1091
1092
  UINT32 channel_number;
  UINT32 reason;

  UINT8 *msg;
  UINT32 length;

  UINT8 *language;
  UINT32 language_length;
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_OPEN_FAILURE)
      && parse_uint32(&buffer, &channel_number)
      && parse_uint32(&buffer, &reason)
      && parse_string(&buffer, &length, &msg)
      && parse_string(&buffer, &language_length, &language)
      && parse_eod(&buffer))
    {
1093
      struct ssh_channel *channel = lookup_channel(connection->channels,
Niels Möller's avatar
Niels Möller committed
1094
1095
						   channel_number);

1096
      lsh_string_free(packet); 
Niels Möller's avatar
Niels Möller committed
1097

1098
      if (channel && channel->open_continuation)
Niels Möller's avatar
Niels Möller committed
1099
	{
1100
1101
1102
	  struct command_continuation *c = channel->open_continuation;
	  channel->open_continuation = NULL;
	  
1103
	  return channel_process_status(connection->channels, channel_number,
1104
					COMMAND_RETURN(c, NULL) | LSH_CHANNEL_FINISHED);
Niels Möller's avatar
Niels Möller committed
1105
	}
1106
      werror("Unexpected SSH_MSG_CHANNEL_OPEN_FAILURE on channel %i\n",
Niels Möller's avatar
Niels Möller committed
1107
1108
1109
1110
1111
1112
1113
1114
	     channel_number);
      
      return LSH_FAIL | LSH_DIE;
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1115
1116
static int do_channel_success(struct packet_handler *closure UNUSED,
			      struct ssh_connection *connection,
1117
1118
1119
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
1120
  unsigned msg_number;
1121
  UINT32 channel_number;
1122
1123
  struct ssh_channel *channel;
      
1124
1125
1126
1127
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_SUCCESS)
1128
      && parse_uint32(&buffer, &channel_number)
1129
      && parse_eod(&buffer)
1130
      && (channel = lookup_channel(connection->channels, channel_number)))
1131
1132
    {
      lsh_string_free(packet);
1133

1134
      if (object_queue_is_empty(&channel->pending_requests))
1135
	{
1136
	  werror("do_channel_success: Unexpected message. Ignoring.\n");
1137
1138
	  return LSH_OK | LSH_GOON;
	}
1139
      {
Niels Möller's avatar
Niels Möller committed
1140
	CAST_SUBTYPE(command_continuation, c,
1141
1142
1143
1144
	     object_queue_remove_head(&channel->pending_requests));
	return channel_process_status(connection->channels, channel_number,
				      COMMAND_RETURN(c, channel));
      }
1145
1146
1147
1148
1149
    }
  lsh_string_free(packet);
  return LSH_FAIL | LSH_DIE;
}

1150
1151
static int do_channel_failure(struct packet_handler *closure UNUSED,
			      struct ssh_connection *connection,
1152
1153
1154
			      struct lsh_string *packet)
{
  struct simple_buffer buffer;
1155
  unsigned msg_number;
1156
  UINT32 channel_number;
1157
  struct ssh_channel *channel;
1158
1159
1160
1161
1162
  
  simple_buffer_init(&buffer, packet->length, packet->data);

  if (parse_uint8(&buffer, &msg_number)
      && (msg_number == SSH_MSG_CHANNEL_FAILURE)
1163
      && parse_uint32(&buffer, &channel_number)
1164
      && parse_eod(&buffer)
1165
      && (channel = lookup_channel(connection->channels, channel_number)))
1166
1167
1168
    {
      lsh_string_free(packet);
      
1169
      if (object_queue_is_empty(&channel->pending_requests))
1170
1171
1172
1173
	{
	  werror("do_channel_failure: No handler. Ignoring.\n");
	  return LSH_OK | LSH_GOON;
	}
1174
      {
Niels Möller's avatar
Niels Möller committed
1175
	CAST_SUBTYPE(command_continuation, c,
1176
1177
1178