v2 / thirdparty / mbedtls / library / net_sockets.c
694 lines · 572 sloc · 17.54 KB · 3d9911f887ecec942f9ae2a5be02d064f233b729
Raw
1/*
2 * TCP/IP or UDP/IP networking functions
3 *
4 * Copyright The Mbed TLS Contributors
5 * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
6 */
7
8/* Enable definition of getaddrinfo() even when compiling with -std=c99. Must
9 * be set before mbedtls_config.h, which pulls in glibc's features.h indirectly.
10 * Harmless on other platforms. */
11#ifndef _POSIX_C_SOURCE
12#define _POSIX_C_SOURCE 200112L
13#endif
14#ifndef _XOPEN_SOURCE
15#define _XOPEN_SOURCE 600 /* sockaddr_storage */
16#endif
17
18#include "common.h"
19
20#if defined(MBEDTLS_NET_C)
21
22#if !defined(MBEDTLS_PLATFORM_IS_UNIXLIKE) && !defined(_WIN32)
23#error "This module only works on Unix and Windows, see MBEDTLS_NET_C in mbedtls_config.h"
24#endif
25
26#include "mbedtls/platform.h"
27
28#include "mbedtls/net_sockets.h"
29#include "mbedtls/error.h"
30
31#include <string.h>
32
33#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
34 !defined(EFI32)
35
36#define IS_EINTR(ret) ((ret) == WSAEINTR)
37
38#include <ws2tcpip.h>
39
40#include <winsock2.h>
41#include <windows.h>
42#if (_WIN32_WINNT < 0x0501)
43#include <wspiapi.h>
44#endif
45
46#if defined(_MSC_VER)
47#if defined(_WIN32_WCE)
48#pragma comment( lib, "ws2.lib" )
49#else
50#pragma comment( lib, "ws2_32.lib" )
51#endif
52#endif /* _MSC_VER */
53
54#define read(fd, buf, len) recv(fd, (char *) (buf), (int) (len), 0)
55#define write(fd, buf, len) send(fd, (char *) (buf), (int) (len), 0)
56#define close(fd) closesocket(fd)
57
58static int wsa_init_done = 0;
59
60#else /* ( _WIN32 || _WIN32_WCE ) && !EFIX64 && !EFI32 */
61
62#include <sys/types.h>
63#include <sys/socket.h>
64#include <netinet/in.h>
65#include <arpa/inet.h>
66#include <sys/time.h>
67#include <unistd.h>
68#include <signal.h>
69#include <fcntl.h>
70#include <netdb.h>
71#include <errno.h>
72
73#define IS_EINTR(ret) ((ret) == EINTR)
74#define SOCKET int
75
76#endif /* ( _WIN32 || _WIN32_WCE ) && !EFIX64 && !EFI32 */
77
78/* Some MS functions want int and MSVC warns if we pass size_t,
79 * but the standard functions use socklen_t, so cast only for MSVC */
80#if defined(_MSC_VER)
81#define MSVC_INT_CAST (int)
82#else
83#define MSVC_INT_CAST
84#endif
85
86#include <stdio.h>
87
88#if defined(MBEDTLS_HAVE_TIME)
89#include <time.h>
90#endif
91
92#include <stdint.h>
93
94/*
95 * Prepare for using the sockets interface
96 */
97static int net_prepare(void)
98{
99#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
100 !defined(EFI32)
101 WSADATA wsaData;
102
103 if (wsa_init_done == 0) {
104 if (WSAStartup(MAKEWORD(2, 0), &wsaData) != 0) {
105 return MBEDTLS_ERR_NET_SOCKET_FAILED;
106 }
107
108 wsa_init_done = 1;
109 }
110#else
111#if !defined(EFIX64) && !defined(EFI32)
112 signal(SIGPIPE, SIG_IGN);
113#endif
114#endif
115 return 0;
116}
117
118/*
119 * Return 0 if the file descriptor is valid, an error otherwise.
120 * If for_select != 0, check whether the file descriptor is within the range
121 * allowed for fd_set used for the FD_xxx macros and the select() function.
122 */
123static int check_fd(int fd, int for_select)
124{
125 if (fd < 0) {
126 return MBEDTLS_ERR_NET_INVALID_CONTEXT;
127 }
128
129#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
130 !defined(EFI32)
131 (void) for_select;
132#else
133 /* A limitation of select() is that it only works with file descriptors
134 * that are strictly less than FD_SETSIZE. This is a limitation of the
135 * fd_set type. Error out early, because attempting to call FD_SET on a
136 * large file descriptor is a buffer overflow on typical platforms. */
137 if (for_select && fd >= FD_SETSIZE) {
138 return MBEDTLS_ERR_NET_POLL_FAILED;
139 }
140#endif
141
142 return 0;
143}
144
145/*
146 * Initialize a context
147 */
148void mbedtls_net_init(mbedtls_net_context *ctx)
149{
150 ctx->fd = -1;
151}
152
153/*
154 * Initiate a TCP connection with host:port and the given protocol
155 */
156int mbedtls_net_connect(mbedtls_net_context *ctx, const char *host,
157 const char *port, int proto)
158{
159 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
160 struct addrinfo hints, *addr_list, *cur;
161
162 if ((ret = net_prepare()) != 0) {
163 return ret;
164 }
165
166 /* Do name resolution with both IPv6 and IPv4 */
167 memset(&hints, 0, sizeof(hints));
168 hints.ai_family = AF_UNSPEC;
169 hints.ai_socktype = proto == MBEDTLS_NET_PROTO_UDP ? SOCK_DGRAM : SOCK_STREAM;
170 hints.ai_protocol = proto == MBEDTLS_NET_PROTO_UDP ? IPPROTO_UDP : IPPROTO_TCP;
171
172 if (getaddrinfo(host, port, &hints, &addr_list) != 0) {
173 return MBEDTLS_ERR_NET_UNKNOWN_HOST;
174 }
175
176 /* Try the sockaddrs until a connection succeeds */
177 ret = MBEDTLS_ERR_NET_UNKNOWN_HOST;
178 for (cur = addr_list; cur != NULL; cur = cur->ai_next) {
179 ctx->fd = (int) socket(cur->ai_family, cur->ai_socktype,
180 cur->ai_protocol);
181 if (ctx->fd < 0) {
182 ret = MBEDTLS_ERR_NET_SOCKET_FAILED;
183 continue;
184 }
185
186 if (connect(ctx->fd, cur->ai_addr, MSVC_INT_CAST cur->ai_addrlen) == 0) {
187 ret = 0;
188 break;
189 }
190
191 mbedtls_net_close(ctx);
192 ret = MBEDTLS_ERR_NET_CONNECT_FAILED;
193 }
194
195 freeaddrinfo(addr_list);
196
197 return ret;
198}
199
200/*
201 * Create a listening socket on bind_ip:port
202 */
203int mbedtls_net_bind(mbedtls_net_context *ctx, const char *bind_ip, const char *port, int proto)
204{
205 int n, ret;
206 struct addrinfo hints, *addr_list, *cur;
207
208 if ((ret = net_prepare()) != 0) {
209 return ret;
210 }
211
212 /* Bind to IPv6 and/or IPv4, but only in the desired protocol */
213 memset(&hints, 0, sizeof(hints));
214 hints.ai_family = AF_UNSPEC;
215 hints.ai_socktype = proto == MBEDTLS_NET_PROTO_UDP ? SOCK_DGRAM : SOCK_STREAM;
216 hints.ai_protocol = proto == MBEDTLS_NET_PROTO_UDP ? IPPROTO_UDP : IPPROTO_TCP;
217 if (bind_ip == NULL) {
218 hints.ai_flags = AI_PASSIVE;
219 }
220
221 if (getaddrinfo(bind_ip, port, &hints, &addr_list) != 0) {
222 return MBEDTLS_ERR_NET_UNKNOWN_HOST;
223 }
224
225 /* Try the sockaddrs until a binding succeeds */
226 ret = MBEDTLS_ERR_NET_UNKNOWN_HOST;
227 for (cur = addr_list; cur != NULL; cur = cur->ai_next) {
228 ctx->fd = (int) socket(cur->ai_family, cur->ai_socktype,
229 cur->ai_protocol);
230 if (ctx->fd < 0) {
231 ret = MBEDTLS_ERR_NET_SOCKET_FAILED;
232 continue;
233 }
234
235 n = 1;
236 if (setsockopt(ctx->fd, SOL_SOCKET, SO_REUSEADDR,
237 (const char *) &n, sizeof(n)) != 0) {
238 mbedtls_net_close(ctx);
239 ret = MBEDTLS_ERR_NET_SOCKET_FAILED;
240 continue;
241 }
242
243 if (bind(ctx->fd, cur->ai_addr, MSVC_INT_CAST cur->ai_addrlen) != 0) {
244 mbedtls_net_close(ctx);
245 ret = MBEDTLS_ERR_NET_BIND_FAILED;
246 continue;
247 }
248
249 /* Listen only makes sense for TCP */
250 if (proto == MBEDTLS_NET_PROTO_TCP) {
251 if (listen(ctx->fd, MBEDTLS_NET_LISTEN_BACKLOG) != 0) {
252 mbedtls_net_close(ctx);
253 ret = MBEDTLS_ERR_NET_LISTEN_FAILED;
254 continue;
255 }
256 }
257
258 /* Bind was successful */
259 ret = 0;
260 break;
261 }
262
263 freeaddrinfo(addr_list);
264
265 return ret;
266
267}
268
269#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
270 !defined(EFI32)
271/*
272 * Check if the requested operation would be blocking on a non-blocking socket
273 * and thus 'failed' with a negative return value.
274 */
275static int net_would_block(const mbedtls_net_context *ctx)
276{
277 ((void) ctx);
278 return WSAGetLastError() == WSAEWOULDBLOCK;
279}
280#else
281/*
282 * Check if the requested operation would be blocking on a non-blocking socket
283 * and thus 'failed' with a negative return value.
284 *
285 * Note: on a blocking socket this function always returns 0!
286 */
287static int net_would_block(const mbedtls_net_context *ctx)
288{
289 int err = errno;
290
291 /*
292 * Never return 'WOULD BLOCK' on a blocking socket
293 */
294 if ((fcntl(ctx->fd, F_GETFL) & O_NONBLOCK) != O_NONBLOCK) {
295 errno = err;
296 return 0;
297 }
298
299 switch (errno = err) {
300#if defined EAGAIN
301 case EAGAIN:
302#endif
303#if defined EWOULDBLOCK && EWOULDBLOCK != EAGAIN
304 case EWOULDBLOCK:
305#endif
306 return 1;
307 }
308 return 0;
309}
310#endif /* ( _WIN32 || _WIN32_WCE ) && !EFIX64 && !EFI32 */
311
312/*
313 * Accept a connection from a remote client
314 */
315int mbedtls_net_accept(mbedtls_net_context *bind_ctx,
316 mbedtls_net_context *client_ctx,
317 void *client_ip, size_t buf_size, size_t *cip_len)
318{
319 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
320 int type;
321
322 struct sockaddr_storage client_addr;
323
324#if defined(__socklen_t_defined) || defined(_SOCKLEN_T) || \
325 defined(_SOCKLEN_T_DECLARED) || defined(__DEFINED_socklen_t) || \
326 defined(socklen_t) || (defined(_POSIX_VERSION) && _POSIX_VERSION >= 200112L)
327 socklen_t n = (socklen_t) sizeof(client_addr);
328 socklen_t type_len = (socklen_t) sizeof(type);
329#else
330 int n = (int) sizeof(client_addr);
331 int type_len = (int) sizeof(type);
332#endif
333
334 /* Is this a TCP or UDP socket? */
335 if (getsockopt(bind_ctx->fd, SOL_SOCKET, SO_TYPE,
336 (void *) &type, &type_len) != 0 ||
337 (type != SOCK_STREAM && type != SOCK_DGRAM)) {
338 return MBEDTLS_ERR_NET_ACCEPT_FAILED;
339 }
340
341 if (type == SOCK_STREAM) {
342 /* TCP: actual accept() */
343 ret = client_ctx->fd = (int) accept(bind_ctx->fd,
344 (struct sockaddr *) &client_addr, &n);
345 } else {
346 /* UDP: wait for a message, but keep it in the queue */
347 char buf[1] = { 0 };
348
349 ret = (int) recvfrom(bind_ctx->fd, buf, sizeof(buf), MSG_PEEK,
350 (struct sockaddr *) &client_addr, &n);
351
352#if defined(_WIN32)
353 if (ret == SOCKET_ERROR &&
354 WSAGetLastError() == WSAEMSGSIZE) {
355 /* We know buf is too small, thanks, just peeking here */
356 ret = 0;
357 }
358#endif
359 }
360
361 if (ret < 0) {
362 if (net_would_block(bind_ctx) != 0) {
363 return MBEDTLS_ERR_SSL_WANT_READ;
364 }
365
366 return MBEDTLS_ERR_NET_ACCEPT_FAILED;
367 }
368
369 /* UDP: hijack the listening socket to communicate with the client,
370 * then bind a new socket to accept new connections */
371 if (type != SOCK_STREAM) {
372 struct sockaddr_storage local_addr;
373 int one = 1;
374
375 if (connect(bind_ctx->fd, (struct sockaddr *) &client_addr, n) != 0) {
376 return MBEDTLS_ERR_NET_ACCEPT_FAILED;
377 }
378
379 client_ctx->fd = bind_ctx->fd;
380 bind_ctx->fd = -1; /* In case we exit early */
381
382 n = sizeof(struct sockaddr_storage);
383 if (getsockname(client_ctx->fd,
384 (struct sockaddr *) &local_addr, &n) != 0 ||
385 (bind_ctx->fd = (int) socket(local_addr.ss_family,
386 SOCK_DGRAM, IPPROTO_UDP)) < 0 ||
387 setsockopt(bind_ctx->fd, SOL_SOCKET, SO_REUSEADDR,
388 (const char *) &one, sizeof(one)) != 0) {
389 return MBEDTLS_ERR_NET_SOCKET_FAILED;
390 }
391
392 if (bind(bind_ctx->fd, (struct sockaddr *) &local_addr, n) != 0) {
393 return MBEDTLS_ERR_NET_BIND_FAILED;
394 }
395 }
396
397 if (client_ip != NULL) {
398 if (client_addr.ss_family == AF_INET) {
399 struct sockaddr_in *addr4 = (struct sockaddr_in *) &client_addr;
400 *cip_len = sizeof(addr4->sin_addr.s_addr);
401
402 if (buf_size < *cip_len) {
403 return MBEDTLS_ERR_NET_BUFFER_TOO_SMALL;
404 }
405
406 memcpy(client_ip, &addr4->sin_addr.s_addr, *cip_len);
407 } else {
408 struct sockaddr_in6 *addr6 = (struct sockaddr_in6 *) &client_addr;
409 *cip_len = sizeof(addr6->sin6_addr.s6_addr);
410
411 if (buf_size < *cip_len) {
412 return MBEDTLS_ERR_NET_BUFFER_TOO_SMALL;
413 }
414
415 memcpy(client_ip, &addr6->sin6_addr.s6_addr, *cip_len);
416 }
417 }
418
419 return 0;
420}
421
422/*
423 * Set the socket blocking or non-blocking
424 */
425int mbedtls_net_set_block(mbedtls_net_context *ctx)
426{
427#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
428 !defined(EFI32)
429 u_long n = 0;
430 return ioctlsocket(ctx->fd, FIONBIO, &n);
431#else
432 return fcntl(ctx->fd, F_SETFL, fcntl(ctx->fd, F_GETFL) & ~O_NONBLOCK);
433#endif
434}
435
436int mbedtls_net_set_nonblock(mbedtls_net_context *ctx)
437{
438#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
439 !defined(EFI32)
440 u_long n = 1;
441 return ioctlsocket(ctx->fd, FIONBIO, &n);
442#else
443 return fcntl(ctx->fd, F_SETFL, fcntl(ctx->fd, F_GETFL) | O_NONBLOCK);
444#endif
445}
446
447/*
448 * Check if data is available on the socket
449 */
450
451int mbedtls_net_poll(mbedtls_net_context *ctx, uint32_t rw, uint32_t timeout)
452{
453 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
454 struct timeval tv;
455
456 fd_set read_fds;
457 fd_set write_fds;
458
459 int fd = ctx->fd;
460
461 ret = check_fd(fd, 1);
462 if (ret != 0) {
463 return ret;
464 }
465
466#if defined(__has_feature)
467#if __has_feature(memory_sanitizer)
468 /* Ensure that memory sanitizers consider read_fds and write_fds as
469 * initialized even on platforms such as Glibc/x86_64 where FD_ZERO
470 * is implemented in assembly. */
471 memset(&read_fds, 0, sizeof(read_fds));
472 memset(&write_fds, 0, sizeof(write_fds));
473#endif
474#endif
475
476 FD_ZERO(&read_fds);
477 if (rw & MBEDTLS_NET_POLL_READ) {
478 rw &= ~MBEDTLS_NET_POLL_READ;
479 FD_SET((SOCKET) fd, &read_fds);
480 }
481
482 FD_ZERO(&write_fds);
483 if (rw & MBEDTLS_NET_POLL_WRITE) {
484 rw &= ~MBEDTLS_NET_POLL_WRITE;
485 FD_SET((SOCKET) fd, &write_fds);
486 }
487
488 if (rw != 0) {
489 return MBEDTLS_ERR_NET_BAD_INPUT_DATA;
490 }
491
492 tv.tv_sec = timeout / 1000;
493 tv.tv_usec = (timeout % 1000) * 1000;
494
495 do {
496 ret = select(fd + 1, &read_fds, &write_fds, NULL,
497 timeout == (uint32_t) -1 ? NULL : &tv);
498 } while (IS_EINTR(ret));
499
500 if (ret < 0) {
501 return MBEDTLS_ERR_NET_POLL_FAILED;
502 }
503
504 ret = 0;
505 if (FD_ISSET(fd, &read_fds)) {
506 ret |= MBEDTLS_NET_POLL_READ;
507 }
508 if (FD_ISSET(fd, &write_fds)) {
509 ret |= MBEDTLS_NET_POLL_WRITE;
510 }
511
512 return ret;
513}
514
515/*
516 * Portable usleep helper
517 */
518void mbedtls_net_usleep(unsigned long usec)
519{
520#if defined(_WIN32)
521 Sleep((usec + 999) / 1000);
522#else
523 struct timeval tv;
524 tv.tv_sec = usec / 1000000;
525#if (defined(__unix__) || defined(__unix) || \
526 (defined(__APPLE__) && defined(__MACH__))) && !defined(__DJGPP__)
527 tv.tv_usec = (suseconds_t) usec % 1000000;
528#else
529 tv.tv_usec = usec % 1000000;
530#endif
531 select(0, NULL, NULL, NULL, &tv);
532#endif
533}
534
535/*
536 * Read at most 'len' characters
537 */
538int mbedtls_net_recv(void *ctx, unsigned char *buf, size_t len)
539{
540 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
541 int fd = ((mbedtls_net_context *) ctx)->fd;
542
543 ret = check_fd(fd, 0);
544 if (ret != 0) {
545 return ret;
546 }
547
548 ret = (int) read(fd, buf, len);
549
550 if (ret < 0) {
551 if (net_would_block(ctx) != 0) {
552 return MBEDTLS_ERR_SSL_WANT_READ;
553 }
554
555#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
556 !defined(EFI32)
557 if (WSAGetLastError() == WSAECONNRESET) {
558 return MBEDTLS_ERR_NET_CONN_RESET;
559 }
560#else
561 if (errno == EPIPE || errno == ECONNRESET) {
562 return MBEDTLS_ERR_NET_CONN_RESET;
563 }
564
565 if (errno == EINTR) {
566 return MBEDTLS_ERR_SSL_WANT_READ;
567 }
568#endif
569
570 return MBEDTLS_ERR_NET_RECV_FAILED;
571 }
572
573 return ret;
574}
575
576/*
577 * Read at most 'len' characters, blocking for at most 'timeout' ms
578 */
579int mbedtls_net_recv_timeout(void *ctx, unsigned char *buf,
580 size_t len, uint32_t timeout)
581{
582 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
583 struct timeval tv;
584 fd_set read_fds;
585 int fd = ((mbedtls_net_context *) ctx)->fd;
586
587 ret = check_fd(fd, 1);
588 if (ret != 0) {
589 return ret;
590 }
591
592 FD_ZERO(&read_fds);
593 FD_SET((SOCKET) fd, &read_fds);
594
595 tv.tv_sec = timeout / 1000;
596 tv.tv_usec = (timeout % 1000) * 1000;
597
598 ret = select(fd + 1, &read_fds, NULL, NULL, timeout == 0 ? NULL : &tv);
599
600 /* Zero fds ready means we timed out */
601 if (ret == 0) {
602 return MBEDTLS_ERR_SSL_TIMEOUT;
603 }
604
605 if (ret < 0) {
606#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
607 !defined(EFI32)
608 if (WSAGetLastError() == WSAEINTR) {
609 return MBEDTLS_ERR_SSL_WANT_READ;
610 }
611#else
612 if (errno == EINTR) {
613 return MBEDTLS_ERR_SSL_WANT_READ;
614 }
615#endif
616
617 return MBEDTLS_ERR_NET_RECV_FAILED;
618 }
619
620 /* This call will not block */
621 return mbedtls_net_recv(ctx, buf, len);
622}
623
624/*
625 * Write at most 'len' characters
626 */
627int mbedtls_net_send(void *ctx, const unsigned char *buf, size_t len)
628{
629 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
630 int fd = ((mbedtls_net_context *) ctx)->fd;
631
632 ret = check_fd(fd, 0);
633 if (ret != 0) {
634 return ret;
635 }
636
637 ret = (int) write(fd, buf, len);
638
639 if (ret < 0) {
640 if (net_would_block(ctx) != 0) {
641 return MBEDTLS_ERR_SSL_WANT_WRITE;
642 }
643
644#if (defined(_WIN32) || defined(_WIN32_WCE)) && !defined(EFIX64) && \
645 !defined(EFI32)
646 if (WSAGetLastError() == WSAECONNRESET) {
647 return MBEDTLS_ERR_NET_CONN_RESET;
648 }
649#else
650 if (errno == EPIPE || errno == ECONNRESET) {
651 return MBEDTLS_ERR_NET_CONN_RESET;
652 }
653
654 if (errno == EINTR) {
655 return MBEDTLS_ERR_SSL_WANT_WRITE;
656 }
657#endif
658
659 return MBEDTLS_ERR_NET_SEND_FAILED;
660 }
661
662 return ret;
663}
664
665/*
666 * Close the connection
667 */
668void mbedtls_net_close(mbedtls_net_context *ctx)
669{
670 if (ctx->fd == -1) {
671 return;
672 }
673
674 close(ctx->fd);
675
676 ctx->fd = -1;
677}
678
679/*
680 * Gracefully close the connection
681 */
682void mbedtls_net_free(mbedtls_net_context *ctx)
683{
684 if (ctx == NULL || ctx->fd == -1) {
685 return;
686 }
687
688 shutdown(ctx->fd, 2);
689 close(ctx->fd);
690
691 ctx->fd = -1;
692}
693
694#endif /* MBEDTLS_NET_C */
695