tftpd.c 7.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449
  1. #include <u.h>
  2. #include <libc.h>
  3. #include <auth.h>
  4. #include <bio.h>
  5. #include <ip.h>
  6. #include <ndb.h>
  7. enum
  8. {
  9. Maxpath= 128,
  10. Maxerr= 256,
  11. };
  12. int dbg;
  13. int restricted;
  14. void sendfile(int, char*, char*);
  15. void recvfile(int, char*, char*);
  16. void nak(int, int, char*);
  17. void ack(int, ushort);
  18. void clrcon(void);
  19. void setuser(void);
  20. char* sunkernel(char*);
  21. void remoteaddr(char*, char*, int);
  22. void doserve(int);
  23. char bigbuf[32768];
  24. char raddr[64];
  25. char *dir = "/lib/tftpd";
  26. char *dirsl;
  27. int dirsllen;
  28. char flog[] = "ipboot";
  29. char net[Maxpath];
  30. enum
  31. {
  32. Tftp_READ = 1,
  33. Tftp_WRITE = 2,
  34. Tftp_DATA = 3,
  35. Tftp_ACK = 4,
  36. Tftp_ERROR = 5,
  37. Segsize = 512,
  38. };
  39. void
  40. usage(void)
  41. {
  42. fprint(2, "usage: %s [-dr] [-h homedir] [-s svc] [-x netmtpt]\n",
  43. argv0);
  44. exits("usage");
  45. }
  46. void
  47. main(int argc, char **argv)
  48. {
  49. char buf[64];
  50. char adir[64], ldir[64];
  51. int cfd, lcfd, dfd;
  52. char *p, *svc = "69";
  53. setnetmtpt(net, sizeof(net), nil);
  54. ARGBEGIN{
  55. case 'd':
  56. dbg++;
  57. break;
  58. case 'h':
  59. dir = ARGF();
  60. break;
  61. case 'r':
  62. restricted = 1;
  63. break;
  64. case 's':
  65. svc = EARGF(usage());
  66. break;
  67. case 'x':
  68. p = ARGF();
  69. if(p == nil)
  70. usage();
  71. setnetmtpt(net, sizeof(net), p);
  72. break;
  73. default:
  74. usage();
  75. }ARGEND
  76. snprint(buf, sizeof buf, "%s/", dir);
  77. dirsl = strdup(buf);
  78. dirsllen = strlen(dirsl);
  79. fmtinstall('E', eipfmt);
  80. fmtinstall('I', eipfmt);
  81. if(chdir(dir) < 0)
  82. sysfatal("can't get to directory %s: %r", dir);
  83. if(!dbg)
  84. switch(rfork(RFNOTEG|RFPROC|RFFDG)) {
  85. case -1:
  86. sysfatal("fork: %r");
  87. case 0:
  88. break;
  89. default:
  90. exits(0);
  91. }
  92. snprint(buf, sizeof buf, "%s/udp!*!%s", net, svc);
  93. cfd = announce(buf, adir);
  94. if (cfd < 0)
  95. sysfatal("announcing on %s: %r", buf);
  96. syslog(dbg, flog, "tftpd started on %s dir %s", buf, adir);
  97. // setuser(); Moved to doserve [sape]
  98. for(;;) {
  99. lcfd = listen(adir, ldir);
  100. if(lcfd < 0)
  101. sysfatal("listening on %s: %r", adir);
  102. switch(fork()) {
  103. case -1:
  104. sysfatal("fork: %r");
  105. case 0:
  106. dfd = accept(lcfd, ldir);
  107. if(dfd < 0)
  108. exits(0);
  109. remoteaddr(ldir, raddr, sizeof(raddr));
  110. syslog(0, flog, "tftp connection from %s dir %s",
  111. raddr, ldir);
  112. doserve(dfd);
  113. exits("done");
  114. break;
  115. default:
  116. close(lcfd);
  117. continue;
  118. }
  119. }
  120. }
  121. void
  122. doserve(int fd)
  123. {
  124. int dlen;
  125. char *mode, *p;
  126. short op;
  127. setuser();
  128. dlen = read(fd, bigbuf, sizeof(bigbuf));
  129. if(dlen < 0)
  130. sysfatal("listen read: %r");
  131. op = (bigbuf[0]<<8) | bigbuf[1];
  132. dlen -= 2;
  133. mode = bigbuf+2;
  134. while(*mode != '\0' && dlen--)
  135. mode++;
  136. mode++;
  137. p = mode;
  138. while(*p && dlen--)
  139. p++;
  140. if(dlen == 0) {
  141. nak(fd, 0, "bad tftpmode");
  142. close(fd);
  143. syslog(dbg, flog, "bad mode from %s", raddr);
  144. return;
  145. }
  146. if(op != Tftp_READ && op != Tftp_WRITE) {
  147. nak(fd, 4, "Illegal TFTP operation");
  148. close(fd);
  149. syslog(dbg, flog, "bad request %d %s", op, raddr);
  150. return;
  151. }
  152. if(restricted){
  153. if(bigbuf[2] == '#' ||
  154. strncmp(bigbuf+2, "../", 3)==0 || strstr(bigbuf+2, "/../") ||
  155. (bigbuf[2] == '/' && strncmp(bigbuf+2, dirsl, dirsllen)!=0)){
  156. nak(fd, 4, "Permission denied");
  157. close(fd);
  158. syslog(dbg, flog, "bad request %d from %s file %s", op, raddr, bigbuf+2);
  159. return;
  160. }
  161. }
  162. if(op == Tftp_READ)
  163. sendfile(fd, bigbuf+2, mode);
  164. else
  165. recvfile(fd, bigbuf+2, mode);
  166. }
  167. void
  168. catcher(void *junk, char *msg)
  169. {
  170. USED(junk);
  171. if(strncmp(msg, "exit", 4) == 0)
  172. noted(NDFLT);
  173. noted(NCONT);
  174. }
  175. void
  176. sendfile(int fd, char *name, char *mode)
  177. {
  178. int file;
  179. uchar buf[Segsize+4];
  180. uchar ack[1024];
  181. char errbuf[Maxerr];
  182. int ackblock, block, ret;
  183. int rexmit, n, al, txtry, rxl;
  184. short op;
  185. syslog(dbg, flog, "send file '%s' %s to %s", name, mode, raddr);
  186. name = sunkernel(name);
  187. if(name == 0){
  188. nak(fd, 0, "not in our database");
  189. return;
  190. }
  191. notify(catcher);
  192. file = open(name, OREAD);
  193. if(file < 0) {
  194. errstr(errbuf, sizeof errbuf);
  195. nak(fd, 0, errbuf);
  196. return;
  197. }
  198. block = 0;
  199. rexmit = 0;
  200. n = 0;
  201. for(txtry = 0; txtry < 5;) {
  202. if(rexmit == 0) {
  203. block++;
  204. buf[0] = 0;
  205. buf[1] = Tftp_DATA;
  206. buf[2] = block>>8;
  207. buf[3] = block;
  208. n = read(file, buf+4, Segsize);
  209. if(n < 0) {
  210. errstr(errbuf, sizeof errbuf);
  211. nak(fd, 0, errbuf);
  212. return;
  213. }
  214. txtry = 0;
  215. }
  216. else {
  217. syslog(dbg, flog, "rexmit %d %s:%d to %s", 4+n, name, block, raddr);
  218. txtry++;
  219. }
  220. ret = write(fd, buf, 4+n);
  221. if(ret < 0)
  222. sysfatal("tftpd: network write error: %r");
  223. for(rxl = 0; rxl < 10; rxl++) {
  224. rexmit = 0;
  225. alarm(500);
  226. al = read(fd, ack, sizeof(ack));
  227. alarm(0);
  228. if(al < 0) {
  229. rexmit = 1;
  230. break;
  231. }
  232. op = ack[0]<<8|ack[1];
  233. if(op == Tftp_ERROR)
  234. goto error;
  235. ackblock = ack[2]<<8|ack[3];
  236. if(ackblock == block)
  237. break;
  238. if(ackblock == 0xffff) {
  239. rexmit = 1;
  240. break;
  241. }
  242. }
  243. if(ret != Segsize+4 && rexmit == 0)
  244. break;
  245. }
  246. error:
  247. close(fd);
  248. close(file);
  249. }
  250. void
  251. recvfile(int fd, char *name, char *mode)
  252. {
  253. ushort op, block, inblock;
  254. uchar buf[Segsize+8];
  255. char errbuf[Maxerr];
  256. int n, ret, file;
  257. syslog(dbg, flog, "receive file '%s' %s from %s", name, mode, raddr);
  258. file = create(name, OWRITE, 0666);
  259. if(file < 0) {
  260. errstr(errbuf, sizeof errbuf);
  261. nak(fd, 0, errbuf);
  262. return;
  263. }
  264. block = 0;
  265. ack(fd, block);
  266. block++;
  267. for(;;) {
  268. alarm(15000);
  269. n = read(fd, buf, sizeof(buf));
  270. alarm(0);
  271. if(n < 0)
  272. goto error;
  273. op = buf[0]<<8|buf[1];
  274. if(op == Tftp_ERROR)
  275. goto error;
  276. n -= 4;
  277. inblock = buf[2]<<8|buf[3];
  278. if(op == Tftp_DATA) {
  279. if(inblock == block) {
  280. ret = write(file, buf, n);
  281. if(ret < 0) {
  282. errstr(errbuf, sizeof errbuf);
  283. nak(fd, 0, errbuf);
  284. goto error;
  285. }
  286. ack(fd, block);
  287. block++;
  288. }
  289. ack(fd, 0xffff);
  290. }
  291. }
  292. error:
  293. close(file);
  294. }
  295. void
  296. ack(int fd, ushort block)
  297. {
  298. uchar ack[4];
  299. int n;
  300. ack[0] = 0;
  301. ack[1] = Tftp_ACK;
  302. ack[2] = block>>8;
  303. ack[3] = block;
  304. n = write(fd, ack, 4);
  305. if(n < 0)
  306. sysfatal("network write: %r");
  307. }
  308. void
  309. nak(int fd, int code, char *msg)
  310. {
  311. char buf[128];
  312. int n;
  313. buf[0] = 0;
  314. buf[1] = Tftp_ERROR;
  315. buf[2] = 0;
  316. buf[3] = code;
  317. strcpy(buf+4, msg);
  318. n = strlen(msg) + 4 + 1;
  319. n = write(fd, buf, n);
  320. if(n < 0)
  321. sysfatal("write nak: %r");
  322. }
  323. void
  324. setuser(void)
  325. {
  326. int fd;
  327. fd = open("#c/user", OWRITE);
  328. if(fd < 0 || write(fd, "none", strlen("none")) < 0)
  329. sysfatal("can't become none: %r");
  330. close(fd);
  331. if(newns("none", nil) < 0)
  332. sysfatal("can't build namespace: %r");
  333. }
  334. char*
  335. lookup(char *sattr, char *sval, char *tattr, char *tval, int len)
  336. {
  337. static Ndb *db;
  338. char *attrs[1];
  339. Ndbtuple *t;
  340. if(db == nil)
  341. db = ndbopen(0);
  342. if(db == nil)
  343. return nil;
  344. if(sattr == nil)
  345. sattr = ipattr(sval);
  346. attrs[0] = tattr;
  347. t = ndbipinfo(db, sattr, sval, attrs, 1);
  348. if(t == nil)
  349. return nil;
  350. strncpy(tval, t->val, len);
  351. tval[len-1] = 0;
  352. ndbfree(t);
  353. return tval;
  354. }
  355. /*
  356. * for sun kernel boots, replace the requested file name with
  357. * a one from our database. If the database doesn't specify a file,
  358. * don't answer.
  359. */
  360. char*
  361. sunkernel(char *name)
  362. {
  363. ulong addr;
  364. uchar v4[IPv4addrlen];
  365. uchar v6[IPaddrlen];
  366. char buf[256];
  367. char ipbuf[128];
  368. if(strlen(name) != 14 || strncmp(name + 8, ".SUN", 4) != 0)
  369. return name;
  370. addr = strtoul(name, 0, 16);
  371. v4[0] = addr>>24;
  372. v4[1] = addr>>16;
  373. v4[2] = addr>>8;
  374. v4[3] = addr;
  375. v4tov6(v6, v4);
  376. sprint(ipbuf, "%I", v6);
  377. return lookup("ip", ipbuf, "bootf", buf, sizeof buf);
  378. }
  379. void
  380. remoteaddr(char *dir, char *raddr, int len)
  381. {
  382. char buf[64];
  383. int fd, n;
  384. snprint(buf, sizeof(buf), "%s/remote", dir);
  385. fd = open(buf, OREAD);
  386. if(fd < 0){
  387. snprint(raddr, sizeof(raddr), "unknown");
  388. return;
  389. }
  390. n = read(fd, raddr, len-1);
  391. close(fd);
  392. if(n <= 0){
  393. snprint(raddr, sizeof(raddr), "unknown");
  394. return;
  395. }
  396. if(n > 0)
  397. n--;
  398. raddr[n] = 0;
  399. }