tftpd.c 8.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472
  1. /*
  2. * tftpd - tftp service, see /lib/rfc/rfc783
  3. */
  4. #include <u.h>
  5. #include <libc.h>
  6. #include <auth.h>
  7. #include <bio.h>
  8. #include <ip.h>
  9. #include <ndb.h>
  10. enum
  11. {
  12. Maxpath= 128,
  13. Maxerr= 256,
  14. };
  15. int dbg;
  16. int restricted;
  17. void sendfile(int, char*, char*);
  18. void recvfile(int, char*, char*);
  19. void nak(int, int, char*);
  20. void ack(int, ushort);
  21. void clrcon(void);
  22. void setuser(void);
  23. char* sunkernel(char*);
  24. void remoteaddr(char*, char*, int);
  25. void doserve(int);
  26. char bigbuf[32768];
  27. char raddr[64];
  28. char *dir = "/lib/tftpd";
  29. char *dirsl;
  30. int dirsllen;
  31. char flog[] = "ipboot";
  32. char net[Maxpath];
  33. enum
  34. {
  35. Tftp_READ = 1,
  36. Tftp_WRITE = 2,
  37. Tftp_DATA = 3,
  38. Tftp_ACK = 4,
  39. Tftp_ERROR = 5,
  40. Segsize = 512,
  41. };
  42. void
  43. usage(void)
  44. {
  45. fprint(2, "usage: %s [-dr] [-h homedir] [-s svc] [-x netmtpt]\n",
  46. argv0);
  47. exits("usage");
  48. }
  49. void
  50. main(int argc, char **argv)
  51. {
  52. char buf[64];
  53. char adir[64], ldir[64];
  54. int cfd, lcfd, dfd;
  55. char *svc = "69";
  56. setnetmtpt(net, sizeof net, nil);
  57. ARGBEGIN{
  58. case 'd':
  59. dbg++;
  60. break;
  61. case 'h':
  62. dir = EARGF(usage());
  63. break;
  64. case 'r':
  65. restricted = 1;
  66. break;
  67. case 's':
  68. svc = EARGF(usage());
  69. break;
  70. case 'x':
  71. setnetmtpt(net, sizeof net, EARGF(usage()));
  72. break;
  73. default:
  74. usage();
  75. }ARGEND
  76. snprint(buf, sizeof buf, "%s/", dir);
  77. dirsl = strdup(buf);
  78. dirsllen = strlen(dirsl);
  79. fmtinstall('E', eipfmt);
  80. fmtinstall('I', eipfmt);
  81. /*
  82. * setuser calls newns, and typical /lib/namespace files contain
  83. * "cd /usr/$user", so call setuser before chdir.
  84. */
  85. setuser();
  86. if(chdir(dir) < 0)
  87. sysfatal("can't get to directory %s: %r", dir);
  88. if(!dbg)
  89. switch(rfork(RFNOTEG|RFPROC|RFFDG)) {
  90. case -1:
  91. sysfatal("fork: %r");
  92. case 0:
  93. break;
  94. default:
  95. exits(0);
  96. }
  97. snprint(buf, sizeof buf, "%s/udp!*!%s", net, svc);
  98. cfd = announce(buf, adir);
  99. if (cfd < 0)
  100. sysfatal("announcing on %s: %r", buf);
  101. syslog(dbg, flog, "tftpd started on %s dir %s", buf, adir);
  102. // setuser();
  103. for(;;) {
  104. lcfd = listen(adir, ldir);
  105. if(lcfd < 0)
  106. sysfatal("listening on %s: %r", adir);
  107. switch(fork()) {
  108. case -1:
  109. sysfatal("fork: %r");
  110. case 0:
  111. dfd = accept(lcfd, ldir);
  112. if(dfd < 0)
  113. exits(0);
  114. remoteaddr(ldir, raddr, sizeof(raddr));
  115. syslog(0, flog, "tftp connection from %s dir %s",
  116. raddr, ldir);
  117. doserve(dfd);
  118. exits("done");
  119. break;
  120. default:
  121. close(lcfd);
  122. continue;
  123. }
  124. }
  125. }
  126. void
  127. doserve(int fd)
  128. {
  129. int dlen;
  130. char *mode, *p;
  131. short op;
  132. dlen = read(fd, bigbuf, sizeof(bigbuf));
  133. if(dlen < 0)
  134. sysfatal("listen read: %r");
  135. op = (bigbuf[0]<<8) | bigbuf[1];
  136. dlen -= 2;
  137. mode = bigbuf+2;
  138. while(*mode != '\0' && dlen--)
  139. mode++;
  140. mode++;
  141. p = mode;
  142. while(*p && dlen--)
  143. p++;
  144. if(dlen == 0) {
  145. nak(fd, 0, "bad tftpmode");
  146. close(fd);
  147. syslog(dbg, flog, "bad mode from %s", raddr);
  148. return;
  149. }
  150. if(op != Tftp_READ && op != Tftp_WRITE) {
  151. nak(fd, 4, "Illegal TFTP operation");
  152. close(fd);
  153. syslog(dbg, flog, "bad request %d %s", op, raddr);
  154. return;
  155. }
  156. if(restricted){
  157. if(bigbuf[2] == '#' ||
  158. strncmp(bigbuf+2, "../", 3)==0 || strstr(bigbuf+2, "/../") ||
  159. (bigbuf[2] == '/' && strncmp(bigbuf+2, dirsl, dirsllen)!=0)){
  160. nak(fd, 4, "Permission denied");
  161. close(fd);
  162. syslog(dbg, flog, "bad request %d from %s file %s", op, raddr, bigbuf+2);
  163. return;
  164. }
  165. }
  166. if(op == Tftp_READ)
  167. sendfile(fd, bigbuf+2, mode);
  168. else
  169. recvfile(fd, bigbuf+2, mode);
  170. }
  171. void
  172. catcher(void *junk, char *msg)
  173. {
  174. USED(junk);
  175. if(strncmp(msg, "exit", 4) == 0)
  176. noted(NDFLT);
  177. noted(NCONT);
  178. }
  179. void
  180. sendfile(int fd, char *name, char *mode)
  181. {
  182. int file;
  183. uchar buf[Segsize+4];
  184. uchar ack[1024];
  185. char errbuf[Maxerr];
  186. int ackblock, block, ret;
  187. int rexmit, n, al, txtry, rxl;
  188. short op;
  189. syslog(dbg, flog, "send file '%s' %s to %s", name, mode, raddr);
  190. name = sunkernel(name);
  191. if(name == 0){
  192. nak(fd, 0, "not in our database");
  193. return;
  194. }
  195. notify(catcher);
  196. file = open(name, OREAD);
  197. if(file < 0) {
  198. errstr(errbuf, sizeof errbuf);
  199. nak(fd, 0, errbuf);
  200. return;
  201. }
  202. block = 0;
  203. rexmit = 0;
  204. n = 0;
  205. for(txtry = 0; txtry < 5;) {
  206. if(rexmit == 0) {
  207. block++;
  208. buf[0] = 0;
  209. buf[1] = Tftp_DATA;
  210. buf[2] = block>>8;
  211. buf[3] = block;
  212. n = read(file, buf+4, Segsize);
  213. if(n < 0) {
  214. errstr(errbuf, sizeof errbuf);
  215. nak(fd, 0, errbuf);
  216. return;
  217. }
  218. txtry = 0;
  219. }
  220. else {
  221. syslog(dbg, flog, "rexmit %d %s:%d to %s",
  222. 4+n, name, block, raddr);
  223. txtry++;
  224. }
  225. ret = write(fd, buf, 4+n);
  226. if(ret < 4+n)
  227. sysfatal("tftpd: network write error: %r");
  228. for(rxl = 0; rxl < 10; rxl++) {
  229. rexmit = 0;
  230. alarm(1000);
  231. al = read(fd, ack, sizeof(ack));
  232. alarm(0);
  233. if(al < 0) {
  234. rexmit = 1;
  235. break;
  236. }
  237. op = ack[0]<<8|ack[1];
  238. if(op == Tftp_ERROR)
  239. goto error;
  240. ackblock = ack[2]<<8|ack[3];
  241. if(ackblock == block)
  242. break;
  243. if(ackblock == 0xffff) {
  244. rexmit = 1;
  245. break;
  246. }
  247. }
  248. if(ret != Segsize+4 && rexmit == 0)
  249. break;
  250. }
  251. error:
  252. close(fd);
  253. close(file);
  254. }
  255. enum { Hdrsize = 2 * sizeof(short), }; /* op, block */
  256. void
  257. recvfile(int fd, char *name, char *mode)
  258. {
  259. ushort op, block, inblock;
  260. uchar buf[Segsize+8];
  261. char errbuf[Maxerr];
  262. int n, ret, file;
  263. syslog(dbg, flog, "receive file '%s' %s from %s", name, mode, raddr);
  264. file = create(name, OWRITE, 0666);
  265. if(file < 0) {
  266. errstr(errbuf, sizeof errbuf);
  267. nak(fd, 0, errbuf);
  268. syslog(dbg, flog, "can't create %s: %r", name);
  269. return;
  270. }
  271. block = 0;
  272. ack(fd, block);
  273. block++;
  274. for (;;) {
  275. alarm(15000);
  276. n = read(fd, buf, sizeof(buf));
  277. alarm(0);
  278. if(n < 0) {
  279. syslog(dbg, flog, "tftpd: network error reading %s: %r",
  280. name);
  281. goto error;
  282. }
  283. if(n <= Hdrsize) {
  284. syslog(dbg, flog,
  285. "tftpd: short read from network, reading %s",
  286. name);
  287. goto error;
  288. }
  289. op = buf[0]<<8|buf[1];
  290. if(op == Tftp_ERROR) {
  291. syslog(dbg, flog, "tftpd: tftp error reading %s", name);
  292. goto error;
  293. }
  294. n -= Hdrsize;
  295. inblock = buf[2]<<8|buf[3];
  296. if(op == Tftp_DATA) {
  297. if(inblock == block) {
  298. ret = write(file, buf+Hdrsize, n);
  299. if(ret != n) {
  300. errstr(errbuf, sizeof errbuf);
  301. nak(fd, 0, errbuf);
  302. syslog(dbg, flog,
  303. "tftpd: error writing %s: %s",
  304. name, errbuf);
  305. goto error;
  306. }
  307. ack(fd, block);
  308. block++;
  309. } else
  310. ack(fd, 0xffff); /* tell him to resend */
  311. }
  312. }
  313. error:
  314. close(file);
  315. }
  316. void
  317. ack(int fd, ushort block)
  318. {
  319. uchar ack[4];
  320. int n;
  321. ack[0] = 0;
  322. ack[1] = Tftp_ACK;
  323. ack[2] = block>>8;
  324. ack[3] = block;
  325. n = write(fd, ack, 4);
  326. if(n < 4)
  327. sysfatal("network write: %r");
  328. }
  329. void
  330. nak(int fd, int code, char *msg)
  331. {
  332. char buf[128];
  333. int n;
  334. buf[0] = 0;
  335. buf[1] = Tftp_ERROR;
  336. buf[2] = 0;
  337. buf[3] = code;
  338. strcpy(buf+4, msg);
  339. n = strlen(msg) + 4 + 1;
  340. n = write(fd, buf, n);
  341. if(n < 0)
  342. sysfatal("write nak: %r");
  343. }
  344. void
  345. setuser(void)
  346. {
  347. int fd;
  348. fd = open("#c/user", OWRITE);
  349. if(fd < 0 || write(fd, "none", strlen("none")) < 0)
  350. sysfatal("can't become none: %r");
  351. close(fd);
  352. if(newns("none", nil) < 0)
  353. sysfatal("can't build namespace: %r");
  354. }
  355. char*
  356. lookup(char *sattr, char *sval, char *tattr, char *tval, int len)
  357. {
  358. static Ndb *db;
  359. char *attrs[1];
  360. Ndbtuple *t;
  361. if(db == nil)
  362. db = ndbopen(0);
  363. if(db == nil)
  364. return nil;
  365. if(sattr == nil)
  366. sattr = ipattr(sval);
  367. attrs[0] = tattr;
  368. t = ndbipinfo(db, sattr, sval, attrs, 1);
  369. if(t == nil)
  370. return nil;
  371. strncpy(tval, t->val, len);
  372. tval[len-1] = 0;
  373. ndbfree(t);
  374. return tval;
  375. }
  376. /*
  377. * for sun kernel boots, replace the requested file name with
  378. * a one from our database. If the database doesn't specify a file,
  379. * don't answer.
  380. */
  381. char*
  382. sunkernel(char *name)
  383. {
  384. ulong addr;
  385. uchar v4[IPv4addrlen];
  386. uchar v6[IPaddrlen];
  387. char buf[256];
  388. char ipbuf[128];
  389. char *suffix;
  390. addr = strtoul(name, &suffix, 16);
  391. if(suffix-name != 8 || (strcmp(suffix, "") != 0 && strcmp(suffix, ".SUN") != 0))
  392. return name;
  393. v4[0] = addr>>24;
  394. v4[1] = addr>>16;
  395. v4[2] = addr>>8;
  396. v4[3] = addr;
  397. v4tov6(v6, v4);
  398. sprint(ipbuf, "%I", v6);
  399. return lookup("ip", ipbuf, "bootf", buf, sizeof buf);
  400. }
  401. void
  402. remoteaddr(char *dir, char *raddr, int len)
  403. {
  404. char buf[64];
  405. int fd, n;
  406. snprint(buf, sizeof(buf), "%s/remote", dir);
  407. fd = open(buf, OREAD);
  408. if(fd < 0){
  409. snprint(raddr, sizeof(raddr), "unknown");
  410. return;
  411. }
  412. n = read(fd, raddr, len-1);
  413. close(fd);
  414. if(n <= 0){
  415. snprint(raddr, sizeof(raddr), "unknown");
  416. return;
  417. }
  418. if(n > 0)
  419. n--;
  420. raddr[n] = 0;
  421. }