bss_conn.c 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619
  1. /*
  2. * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <stdio.h>
  10. #include <errno.h>
  11. #include "bio_local.h"
  12. #include "internal/ktls.h"
  13. #ifndef OPENSSL_NO_SOCK
  14. typedef struct bio_connect_st {
  15. int state;
  16. int connect_family;
  17. char *param_hostname;
  18. char *param_service;
  19. int connect_mode;
  20. # ifndef OPENSSL_NO_KTLS
  21. unsigned char record_type;
  22. # endif
  23. BIO_ADDRINFO *addr_first;
  24. const BIO_ADDRINFO *addr_iter;
  25. /*
  26. * int socket; this will be kept in bio->num so that it is compatible
  27. * with the bss_sock bio
  28. */
  29. /*
  30. * called when the connection is initially made callback(BIO,state,ret);
  31. * The callback should return 'ret'. state is for compatibility with the
  32. * ssl info_callback
  33. */
  34. BIO_info_cb *info_callback;
  35. } BIO_CONNECT;
  36. static int conn_write(BIO *h, const char *buf, int num);
  37. static int conn_read(BIO *h, char *buf, int size);
  38. static int conn_puts(BIO *h, const char *str);
  39. static long conn_ctrl(BIO *h, int cmd, long arg1, void *arg2);
  40. static int conn_new(BIO *h);
  41. static int conn_free(BIO *data);
  42. static long conn_callback_ctrl(BIO *h, int cmd, BIO_info_cb *);
  43. static int conn_state(BIO *b, BIO_CONNECT *c);
  44. static void conn_close_socket(BIO *data);
  45. BIO_CONNECT *BIO_CONNECT_new(void);
  46. void BIO_CONNECT_free(BIO_CONNECT *a);
  47. #define BIO_CONN_S_BEFORE 1
  48. #define BIO_CONN_S_GET_ADDR 2
  49. #define BIO_CONN_S_CREATE_SOCKET 3
  50. #define BIO_CONN_S_CONNECT 4
  51. #define BIO_CONN_S_OK 5
  52. #define BIO_CONN_S_BLOCKED_CONNECT 6
  53. #define BIO_CONN_S_CONNECT_ERROR 7
  54. static const BIO_METHOD methods_connectp = {
  55. BIO_TYPE_CONNECT,
  56. "socket connect",
  57. /* TODO: Convert to new style write function */
  58. bwrite_conv,
  59. conn_write,
  60. /* TODO: Convert to new style read function */
  61. bread_conv,
  62. conn_read,
  63. conn_puts,
  64. NULL, /* conn_gets, */
  65. conn_ctrl,
  66. conn_new,
  67. conn_free,
  68. conn_callback_ctrl,
  69. };
  70. static int conn_state(BIO *b, BIO_CONNECT *c)
  71. {
  72. int ret = -1, i;
  73. BIO_info_cb *cb = NULL;
  74. if (c->info_callback != NULL)
  75. cb = c->info_callback;
  76. for (;;) {
  77. switch (c->state) {
  78. case BIO_CONN_S_BEFORE:
  79. if (c->param_hostname == NULL && c->param_service == NULL) {
  80. BIOerr(BIO_F_CONN_STATE, BIO_R_NO_HOSTNAME_OR_SERVICE_SPECIFIED);
  81. ERR_add_error_data(4,
  82. "hostname=", c->param_hostname,
  83. " service=", c->param_service);
  84. goto exit_loop;
  85. }
  86. c->state = BIO_CONN_S_GET_ADDR;
  87. break;
  88. case BIO_CONN_S_GET_ADDR:
  89. {
  90. int family = AF_UNSPEC;
  91. switch (c->connect_family) {
  92. case BIO_FAMILY_IPV6:
  93. if (1) { /* This is a trick we use to avoid bit rot.
  94. * at least the "else" part will always be
  95. * compiled.
  96. */
  97. #ifdef AF_INET6
  98. family = AF_INET6;
  99. } else {
  100. #endif
  101. BIOerr(BIO_F_CONN_STATE, BIO_R_UNAVAILABLE_IP_FAMILY);
  102. goto exit_loop;
  103. }
  104. break;
  105. case BIO_FAMILY_IPV4:
  106. family = AF_INET;
  107. break;
  108. case BIO_FAMILY_IPANY:
  109. family = AF_UNSPEC;
  110. break;
  111. default:
  112. BIOerr(BIO_F_CONN_STATE, BIO_R_UNSUPPORTED_IP_FAMILY);
  113. goto exit_loop;
  114. }
  115. if (BIO_lookup(c->param_hostname, c->param_service,
  116. BIO_LOOKUP_CLIENT,
  117. family, SOCK_STREAM, &c->addr_first) == 0)
  118. goto exit_loop;
  119. }
  120. if (c->addr_first == NULL) {
  121. BIOerr(BIO_F_CONN_STATE, BIO_R_LOOKUP_RETURNED_NOTHING);
  122. goto exit_loop;
  123. }
  124. c->addr_iter = c->addr_first;
  125. c->state = BIO_CONN_S_CREATE_SOCKET;
  126. break;
  127. case BIO_CONN_S_CREATE_SOCKET:
  128. ret = BIO_socket(BIO_ADDRINFO_family(c->addr_iter),
  129. BIO_ADDRINFO_socktype(c->addr_iter),
  130. BIO_ADDRINFO_protocol(c->addr_iter), 0);
  131. if (ret == (int)INVALID_SOCKET) {
  132. ERR_raise_data(ERR_LIB_SYS, get_last_socket_error(),
  133. "calling socket(%s, %s)",
  134. c->param_hostname, c->param_service);
  135. BIOerr(BIO_F_CONN_STATE, BIO_R_UNABLE_TO_CREATE_SOCKET);
  136. goto exit_loop;
  137. }
  138. b->num = ret;
  139. c->state = BIO_CONN_S_CONNECT;
  140. break;
  141. case BIO_CONN_S_CONNECT:
  142. BIO_clear_retry_flags(b);
  143. ret = BIO_connect(b->num, BIO_ADDRINFO_address(c->addr_iter),
  144. BIO_SOCK_KEEPALIVE | c->connect_mode);
  145. b->retry_reason = 0;
  146. if (ret == 0) {
  147. if (BIO_sock_should_retry(ret)) {
  148. BIO_set_retry_special(b);
  149. c->state = BIO_CONN_S_BLOCKED_CONNECT;
  150. b->retry_reason = BIO_RR_CONNECT;
  151. ERR_clear_error();
  152. } else if ((c->addr_iter = BIO_ADDRINFO_next(c->addr_iter))
  153. != NULL) {
  154. /*
  155. * if there are more addresses to try, do that first
  156. */
  157. BIO_closesocket(b->num);
  158. c->state = BIO_CONN_S_CREATE_SOCKET;
  159. ERR_clear_error();
  160. break;
  161. } else {
  162. ERR_raise_data(ERR_LIB_SYS, get_last_socket_error(),
  163. "calling connect(%s, %s)",
  164. c->param_hostname, c->param_service);
  165. c->state = BIO_CONN_S_CONNECT_ERROR;
  166. break;
  167. }
  168. goto exit_loop;
  169. } else {
  170. c->state = BIO_CONN_S_OK;
  171. }
  172. break;
  173. case BIO_CONN_S_BLOCKED_CONNECT:
  174. i = BIO_sock_error(b->num);
  175. if (i != 0) {
  176. BIO_clear_retry_flags(b);
  177. if ((c->addr_iter = BIO_ADDRINFO_next(c->addr_iter)) != NULL) {
  178. /*
  179. * if there are more addresses to try, do that first
  180. */
  181. BIO_closesocket(b->num);
  182. c->state = BIO_CONN_S_CREATE_SOCKET;
  183. ERR_clear_error();
  184. break;
  185. }
  186. ERR_raise_data(ERR_LIB_SYS, i,
  187. "calling connect(%s, %s)",
  188. c->param_hostname, c->param_service);
  189. BIOerr(BIO_F_CONN_STATE, BIO_R_NBIO_CONNECT_ERROR);
  190. ret = 0;
  191. goto exit_loop;
  192. } else
  193. c->state = BIO_CONN_S_OK;
  194. break;
  195. case BIO_CONN_S_CONNECT_ERROR:
  196. BIOerr(BIO_F_CONN_STATE, BIO_R_CONNECT_ERROR);
  197. ret = 0;
  198. goto exit_loop;
  199. case BIO_CONN_S_OK:
  200. ret = 1;
  201. goto exit_loop;
  202. default:
  203. /* abort(); */
  204. goto exit_loop;
  205. }
  206. if (cb != NULL) {
  207. if ((ret = cb((BIO *)b, c->state, ret)) == 0)
  208. goto end;
  209. }
  210. }
  211. /* Loop does not exit */
  212. exit_loop:
  213. if (cb != NULL)
  214. ret = cb((BIO *)b, c->state, ret);
  215. end:
  216. return ret;
  217. }
  218. BIO_CONNECT *BIO_CONNECT_new(void)
  219. {
  220. BIO_CONNECT *ret;
  221. if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL) {
  222. BIOerr(BIO_F_BIO_CONNECT_NEW, ERR_R_MALLOC_FAILURE);
  223. return NULL;
  224. }
  225. ret->state = BIO_CONN_S_BEFORE;
  226. ret->connect_family = BIO_FAMILY_IPANY;
  227. return ret;
  228. }
  229. void BIO_CONNECT_free(BIO_CONNECT *a)
  230. {
  231. if (a == NULL)
  232. return;
  233. OPENSSL_free(a->param_hostname);
  234. OPENSSL_free(a->param_service);
  235. BIO_ADDRINFO_free(a->addr_first);
  236. OPENSSL_free(a);
  237. }
  238. const BIO_METHOD *BIO_s_connect(void)
  239. {
  240. return &methods_connectp;
  241. }
  242. static int conn_new(BIO *bi)
  243. {
  244. bi->init = 0;
  245. bi->num = (int)INVALID_SOCKET;
  246. bi->flags = 0;
  247. if ((bi->ptr = (char *)BIO_CONNECT_new()) == NULL)
  248. return 0;
  249. else
  250. return 1;
  251. }
  252. static void conn_close_socket(BIO *bio)
  253. {
  254. BIO_CONNECT *c;
  255. c = (BIO_CONNECT *)bio->ptr;
  256. if (bio->num != (int)INVALID_SOCKET) {
  257. /* Only do a shutdown if things were established */
  258. if (c->state == BIO_CONN_S_OK)
  259. shutdown(bio->num, 2);
  260. BIO_closesocket(bio->num);
  261. bio->num = (int)INVALID_SOCKET;
  262. }
  263. }
  264. static int conn_free(BIO *a)
  265. {
  266. BIO_CONNECT *data;
  267. if (a == NULL)
  268. return 0;
  269. data = (BIO_CONNECT *)a->ptr;
  270. if (a->shutdown) {
  271. conn_close_socket(a);
  272. BIO_CONNECT_free(data);
  273. a->ptr = NULL;
  274. a->flags = 0;
  275. a->init = 0;
  276. }
  277. return 1;
  278. }
  279. static int conn_read(BIO *b, char *out, int outl)
  280. {
  281. int ret = 0;
  282. BIO_CONNECT *data;
  283. data = (BIO_CONNECT *)b->ptr;
  284. if (data->state != BIO_CONN_S_OK) {
  285. ret = conn_state(b, data);
  286. if (ret <= 0)
  287. return ret;
  288. }
  289. if (out != NULL) {
  290. clear_socket_error();
  291. # ifndef OPENSSL_NO_KTLS
  292. if (BIO_get_ktls_recv(b))
  293. ret = ktls_read_record(b->num, out, outl);
  294. else
  295. # endif
  296. ret = readsocket(b->num, out, outl);
  297. BIO_clear_retry_flags(b);
  298. if (ret <= 0) {
  299. if (BIO_sock_should_retry(ret))
  300. BIO_set_retry_read(b);
  301. else if (ret == 0)
  302. b->flags |= BIO_FLAGS_IN_EOF;
  303. }
  304. }
  305. return ret;
  306. }
  307. static int conn_write(BIO *b, const char *in, int inl)
  308. {
  309. int ret;
  310. BIO_CONNECT *data;
  311. data = (BIO_CONNECT *)b->ptr;
  312. if (data->state != BIO_CONN_S_OK) {
  313. ret = conn_state(b, data);
  314. if (ret <= 0)
  315. return ret;
  316. }
  317. clear_socket_error();
  318. # ifndef OPENSSL_NO_KTLS
  319. if (BIO_should_ktls_ctrl_msg_flag(b)) {
  320. ret = ktls_send_ctrl_message(b->num, data->record_type, in, inl);
  321. if (ret >= 0) {
  322. ret = inl;
  323. BIO_clear_ktls_ctrl_msg_flag(b);
  324. }
  325. } else
  326. # endif
  327. ret = writesocket(b->num, in, inl);
  328. BIO_clear_retry_flags(b);
  329. if (ret <= 0) {
  330. if (BIO_sock_should_retry(ret))
  331. BIO_set_retry_write(b);
  332. }
  333. return ret;
  334. }
  335. static long conn_ctrl(BIO *b, int cmd, long num, void *ptr)
  336. {
  337. BIO *dbio;
  338. int *ip;
  339. const char **pptr = NULL;
  340. long ret = 1;
  341. BIO_CONNECT *data;
  342. # ifndef OPENSSL_NO_KTLS
  343. # ifdef __FreeBSD__
  344. struct tls_enable *crypto_info;
  345. # else
  346. struct tls12_crypto_info_aes_gcm_128 *crypto_info;
  347. # endif
  348. # endif
  349. data = (BIO_CONNECT *)b->ptr;
  350. switch (cmd) {
  351. case BIO_CTRL_RESET:
  352. ret = 0;
  353. data->state = BIO_CONN_S_BEFORE;
  354. conn_close_socket(b);
  355. BIO_ADDRINFO_free(data->addr_first);
  356. data->addr_first = NULL;
  357. b->flags = 0;
  358. break;
  359. case BIO_C_DO_STATE_MACHINE:
  360. /* use this one to start the connection */
  361. if (data->state != BIO_CONN_S_OK)
  362. ret = (long)conn_state(b, data);
  363. else
  364. ret = 1;
  365. break;
  366. case BIO_C_GET_CONNECT:
  367. if (ptr != NULL) {
  368. pptr = (const char **)ptr;
  369. if (num == 0) {
  370. *pptr = data->param_hostname;
  371. } else if (num == 1) {
  372. *pptr = data->param_service;
  373. } else if (num == 2) {
  374. *pptr = (const char *)BIO_ADDRINFO_address(data->addr_iter);
  375. } else if (num == 3) {
  376. switch (BIO_ADDRINFO_family(data->addr_iter)) {
  377. # ifdef AF_INET6
  378. case AF_INET6:
  379. ret = BIO_FAMILY_IPV6;
  380. break;
  381. # endif
  382. case AF_INET:
  383. ret = BIO_FAMILY_IPV4;
  384. break;
  385. case 0:
  386. ret = data->connect_family;
  387. break;
  388. default:
  389. ret = -1;
  390. break;
  391. }
  392. } else {
  393. ret = 0;
  394. }
  395. } else {
  396. ret = 0;
  397. }
  398. break;
  399. case BIO_C_SET_CONNECT:
  400. if (ptr != NULL) {
  401. b->init = 1;
  402. if (num == 0) { /* BIO_set_conn_hostname */
  403. char *hold_service = data->param_service;
  404. /* We affect the hostname regardless. However, the input
  405. * string might contain a host:service spec, so we must
  406. * parse it, which might or might not affect the service
  407. */
  408. OPENSSL_free(data->param_hostname);
  409. data->param_hostname = NULL;
  410. ret = BIO_parse_hostserv(ptr,
  411. &data->param_hostname,
  412. &data->param_service,
  413. BIO_PARSE_PRIO_HOST);
  414. if (hold_service != data->param_service)
  415. OPENSSL_free(hold_service);
  416. } else if (num == 1) { /* BIO_set_conn_port */
  417. OPENSSL_free(data->param_service);
  418. if ((data->param_service = OPENSSL_strdup(ptr)) == NULL)
  419. ret = 0;
  420. } else if (num == 2) { /* BIO_set_conn_address */
  421. const BIO_ADDR *addr = (const BIO_ADDR *)ptr;
  422. char *host = BIO_ADDR_hostname_string(addr, 1);
  423. char *service = BIO_ADDR_service_string(addr, 1);
  424. ret = host != NULL && service != NULL;
  425. if (ret) {
  426. OPENSSL_free(data->param_hostname);
  427. data->param_hostname = host;
  428. OPENSSL_free(data->param_service);
  429. data->param_service = service;
  430. BIO_ADDRINFO_free(data->addr_first);
  431. data->addr_first = NULL;
  432. data->addr_iter = NULL;
  433. } else {
  434. OPENSSL_free(host);
  435. OPENSSL_free(service);
  436. }
  437. } else if (num == 3) { /* BIO_set_conn_ip_family */
  438. data->connect_family = *(int *)ptr;
  439. } else {
  440. ret = 0;
  441. }
  442. }
  443. break;
  444. case BIO_C_SET_NBIO:
  445. if (num != 0)
  446. data->connect_mode |= BIO_SOCK_NONBLOCK;
  447. else
  448. data->connect_mode &= ~BIO_SOCK_NONBLOCK;
  449. break;
  450. case BIO_C_SET_CONNECT_MODE:
  451. data->connect_mode = (int)num;
  452. break;
  453. case BIO_C_GET_FD:
  454. if (b->init) {
  455. ip = (int *)ptr;
  456. if (ip != NULL)
  457. *ip = b->num;
  458. ret = b->num;
  459. } else
  460. ret = -1;
  461. break;
  462. case BIO_CTRL_GET_CLOSE:
  463. ret = b->shutdown;
  464. break;
  465. case BIO_CTRL_SET_CLOSE:
  466. b->shutdown = (int)num;
  467. break;
  468. case BIO_CTRL_PENDING:
  469. case BIO_CTRL_WPENDING:
  470. ret = 0;
  471. break;
  472. case BIO_CTRL_FLUSH:
  473. break;
  474. case BIO_CTRL_DUP:
  475. {
  476. dbio = (BIO *)ptr;
  477. if (data->param_hostname)
  478. BIO_set_conn_hostname(dbio, data->param_hostname);
  479. if (data->param_service)
  480. BIO_set_conn_port(dbio, data->param_service);
  481. BIO_set_conn_ip_family(dbio, data->connect_family);
  482. BIO_set_conn_mode(dbio, data->connect_mode);
  483. /*
  484. * FIXME: the cast of the function seems unlikely to be a good
  485. * idea
  486. */
  487. (void)BIO_set_info_callback(dbio, data->info_callback);
  488. }
  489. break;
  490. case BIO_CTRL_SET_CALLBACK:
  491. ret = 0; /* use callback ctrl */
  492. break;
  493. case BIO_CTRL_GET_CALLBACK:
  494. {
  495. BIO_info_cb **fptr;
  496. fptr = (BIO_info_cb **)ptr;
  497. *fptr = data->info_callback;
  498. }
  499. break;
  500. case BIO_CTRL_EOF:
  501. ret = (b->flags & BIO_FLAGS_IN_EOF) != 0 ? 1 : 0;
  502. break;
  503. # ifndef OPENSSL_NO_KTLS
  504. case BIO_CTRL_SET_KTLS:
  505. # ifdef __FreeBSD__
  506. crypto_info = (struct tls_enable *)ptr;
  507. # else
  508. crypto_info = (struct tls12_crypto_info_aes_gcm_128 *)ptr;
  509. # endif
  510. ret = ktls_start(b->num, crypto_info, sizeof(*crypto_info), num);
  511. if (ret)
  512. BIO_set_ktls_flag(b, num);
  513. break;
  514. case BIO_CTRL_GET_KTLS_SEND:
  515. return BIO_should_ktls_flag(b, 1);
  516. case BIO_CTRL_GET_KTLS_RECV:
  517. return BIO_should_ktls_flag(b, 0);
  518. case BIO_CTRL_SET_KTLS_TX_SEND_CTRL_MSG:
  519. BIO_set_ktls_ctrl_msg_flag(b);
  520. data->record_type = num;
  521. ret = 0;
  522. break;
  523. case BIO_CTRL_CLEAR_KTLS_TX_CTRL_MSG:
  524. BIO_clear_ktls_ctrl_msg_flag(b);
  525. ret = 0;
  526. break;
  527. # endif
  528. default:
  529. ret = 0;
  530. break;
  531. }
  532. return ret;
  533. }
  534. static long conn_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
  535. {
  536. long ret = 1;
  537. BIO_CONNECT *data;
  538. data = (BIO_CONNECT *)b->ptr;
  539. switch (cmd) {
  540. case BIO_CTRL_SET_CALLBACK:
  541. {
  542. data->info_callback = fp;
  543. }
  544. break;
  545. default:
  546. ret = 0;
  547. break;
  548. }
  549. return ret;
  550. }
  551. static int conn_puts(BIO *bp, const char *str)
  552. {
  553. int n, ret;
  554. n = strlen(str);
  555. ret = conn_write(bp, str, n);
  556. return ret;
  557. }
  558. BIO *BIO_new_connect(const char *str)
  559. {
  560. BIO *ret;
  561. ret = BIO_new(BIO_s_connect());
  562. if (ret == NULL)
  563. return NULL;
  564. if (BIO_set_conn_hostname(ret, str))
  565. return ret;
  566. BIO_free(ret);
  567. return NULL;
  568. }
  569. #endif