2
0

Intercept.c 31 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024
  1. /*
  2. * ZeroTier One - Network Virtualization Everywhere
  3. * Copyright (C) 2011-2015 ZeroTier, Inc.
  4. *
  5. * This program is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. * --
  19. *
  20. * ZeroTier may be used and distributed under the terms of the GPLv3, which
  21. * are available at: http://www.gnu.org/licenses/gpl-3.0.html
  22. *
  23. * If you would like to embed ZeroTier into a commercial application or
  24. * redistribute it in a modified binary form, please contact ZeroTier Networks
  25. * LLC. Start here: http://www.zerotier.com/
  26. */
  27. #ifdef USE_GNU_SOURCE
  28. #define _GNU_SOURCE
  29. #endif
  30. #include <unistd.h>
  31. #include <stdint.h>
  32. #include <stdio.h>
  33. #include <dlfcn.h>
  34. #include <strings.h>
  35. #include <netinet/in.h>
  36. #include <sys/time.h>
  37. #include <pwd.h>
  38. #include <errno.h>
  39. #include <linux/errno.h>
  40. #include <stdarg.h>
  41. #include <netdb.h>
  42. #include <string.h>
  43. #include <sys/syscall.h>
  44. #include <sys/types.h>
  45. #include <sys/socket.h>
  46. #include <sys/poll.h>
  47. #include <sys/un.h>
  48. #include <arpa/inet.h>
  49. #include "Intercept.h"
  50. #include "common.inc.c"
  51. #ifdef CHECKS
  52. #include <sys/resource.h>
  53. #include <linux/net.h> /* for NPROTO */
  54. #define SOCK_MAX (SOCK_PACKET + 1)
  55. #define SOCK_TYPE_MASK 0xf
  56. #endif
  57. /* Global Declarations */
  58. static int (*realconnect)(CONNECT_SIG);
  59. static int (*realbind)(BIND_SIG);
  60. static int (*realaccept)(ACCEPT_SIG);
  61. static int (*reallisten)(LISTEN_SIG);
  62. static int (*realsocket)(SOCKET_SIG);
  63. static int (*realsetsockopt)(SETSOCKOPT_SIG);
  64. static int (*realgetsockopt)(GETSOCKOPT_SIG);
  65. static int (*realaccept4)(ACCEPT4_SIG);
  66. static long (*realsyscall)(SYSCALL_SIG);
  67. static int (*realclose)(CLOSE_SIG);
  68. static int (*realclone)(CLONE_SIG);
  69. static int (*realdup2)(DUP2_SIG);
  70. static int (*realdup3)(DUP3_SIG);
  71. static int (*realgetsockname)(GETSOCKNAME_SIG);
  72. /* Exported Function Prototypes */
  73. void my_init(void);
  74. int connect(CONNECT_SIG);
  75. int bind(BIND_SIG);
  76. int accept(ACCEPT_SIG);
  77. int listen(LISTEN_SIG);
  78. int socket(SOCKET_SIG);
  79. int setsockopt(SETSOCKOPT_SIG);
  80. int getsockopt(GETSOCKOPT_SIG);
  81. int accept4(ACCEPT4_SIG);
  82. long syscall(SYSCALL_SIG);
  83. int close(CLOSE_SIG);
  84. int clone(CLONE_SIG);
  85. int dup2(DUP2_SIG);
  86. int dup3(DUP3_SIG);
  87. int getsockname(GETSOCKNAME_SIG);
  88. static int init_service_connection();
  89. static void load_symbols(void);
  90. static void set_up_intercept();
  91. #define SERVICE_CONNECT_ATTEMPTS 30
  92. #define RPC_FD 1023
  93. static pthread_mutex_t lock;
  94. static ssize_t sock_fd_read(int sock, void *buf, ssize_t bufsize, int *fd);
  95. void handle_error(char *name, char *info, int err)
  96. {
  97. #ifdef ERRORS_ARE_FATAL
  98. if(err < 0) {
  99. dwr(MSG_DEBUG,"handle_error(%s)=%d: FATAL: %s\n", name, err, info);
  100. exit(-1);
  101. }
  102. #endif
  103. #ifdef VERBOSE
  104. dwr(MSG_DEBUG,"%s()=%d\n", name, err);
  105. #endif
  106. }
  107. /*------------------------------------------------------------------------------
  108. ------------------- Intercept<--->Service Comm mechanisms-----------------------
  109. ------------------------------------------------------------------------------*/
  110. static int is_initialized = 0;
  111. static int fdret_sock; /* used for fd-transfers */
  112. static int newfd; /* used for "this_end" socket */
  113. static int thispid = -1;
  114. static int instance_count = 0;
  115. /*
  116. * Check for forking
  117. */
  118. static void checkpid()
  119. {
  120. /* Do noting if not configured (sanity check -- should never get here in this case) */
  121. if (!getenv("ZT_NC_NETWORK"))
  122. return;
  123. if (thispid != getpid()) {
  124. dwr(MSG_DEBUG, "checkpid(): clone/fork detected. Re-initializing this instance.\n");
  125. set_up_intercept();
  126. fdret_sock = init_service_connection();
  127. thispid = getpid();
  128. }
  129. }
  130. /*
  131. * Reads a return value from the service and sets errno (if applicable)
  132. */
  133. static int get_retval()
  134. {
  135. dwr(MSG_DEBUG,"get_retval()\n");
  136. if(fdret_sock >= 0) {
  137. int retval;
  138. int sz = sizeof(char) + sizeof(retval) + sizeof(errno);
  139. char retbuf[BUF_SZ];
  140. memset(&retbuf, '\0', sz);
  141. int n_read = read(fdret_sock, &retbuf, sz);
  142. if(n_read > 0) {
  143. memcpy(&retval, &retbuf[1], sizeof(retval));
  144. memcpy(&errno, &retbuf[1+sizeof(retval)], sizeof(errno));
  145. dwr(MSG_DEBUG, "get_retval(): ret = %d\n", retval);
  146. return retval;
  147. }
  148. }
  149. dwr(MSG_DEBUG,"unable to read return value\n");
  150. return -1;
  151. }
  152. /* Reads a new file descriptor from the service */
  153. static int get_new_fd(int oversock)
  154. {
  155. char buf[BUF_SZ];
  156. int newfd;
  157. ssize_t size = sock_fd_read(oversock, buf, sizeof(buf), &newfd);
  158. if(size > 0){
  159. dwr(MSG_DEBUG, "get_new_fd(): RX: fd = (%d) over (%d)\n", newfd, oversock);
  160. return newfd;
  161. }
  162. dwr(MSG_ERROR, "get_new_fd(): ERROR: unable to read fd over (%d)\n", oversock);
  163. return -1;
  164. }
  165. #ifdef VERBOSE
  166. static unsigned long rpc_count = 0;
  167. #endif
  168. /* Sends an RPC command to the service */
  169. static int send_cmd(int rpc_fd, char *cmd)
  170. {
  171. pthread_mutex_lock(&lock);
  172. char metabuf[BUF_SZ]; // portion of buffer which contains RPC metadata for debugging
  173. #ifdef VERBOSE
  174. /*
  175. #define IDX_PID 0
  176. #define IDX_TID sizeof(pid_t)
  177. #define IDX_COUNT IDX_TID + sizeof(pid_t)
  178. #define IDX_TIME IDX_COUNT + sizeof(int)
  179. #define IDX_CMD IDX_TIME + 20 // 20 being the length of the timestamp string
  180. #define IDX_PAYLOAD IDX_TIME + sizeof(char)
  181. */
  182. /* [pid_t] [pid_t] [rpc_count] [int] [...] */
  183. memset(metabuf, '\0', BUF_SZ);
  184. pid_t pid = syscall(SYS_getpid);
  185. pid_t tid = syscall(SYS_gettid);
  186. rpc_count++;
  187. char timestring[20];
  188. time_t timestamp;
  189. timestamp = time(NULL);
  190. strftime(timestring, sizeof(timestring), "%H:%M:%S", localtime(&timestamp));
  191. memcpy(&metabuf[IDX_PID], &pid, sizeof(pid_t) ); /* pid */
  192. memcpy(&metabuf[IDX_TID], &tid, sizeof(pid_t) ); /* tid */
  193. memcpy(&metabuf[IDX_COUNT], &rpc_count, sizeof(rpc_count) ); /* rpc_count */
  194. memcpy(&metabuf[IDX_TIME], &timestring, 20 ); /* timestamp */
  195. #endif
  196. /* Combine command flag+payload with RPC metadata */
  197. memcpy(&metabuf[IDX_PAYLOAD], cmd, PAYLOAD_SZ);
  198. int n_write = write(rpc_fd, &metabuf, BUF_SZ);
  199. if(n_write < 0){
  200. dwr(MSG_DEBUG,"Error writing command to service (CMD = %d)\n", cmd[0]);
  201. errno = 0;
  202. }
  203. int ret = ERR_OK;
  204. if(n_write > 0) {
  205. if(cmd[0]==RPC_SOCKET) {
  206. ret = get_new_fd(fdret_sock);
  207. }
  208. if(cmd[0]==RPC_MAP_REQ
  209. || cmd[0]==RPC_CONNECT
  210. || cmd[0]==RPC_BIND
  211. || cmd[0]==RPC_LISTEN
  212. || cmd[0]==RPC_MAP) {
  213. ret = get_retval();
  214. }
  215. if(cmd[0]==RPC_GETSOCKNAME) {
  216. ret = n_write;
  217. }
  218. }
  219. else {
  220. ret = -1;
  221. }
  222. pthread_mutex_unlock(&lock);
  223. return ret;
  224. }
  225. /* Check whether the socket is mapped to the service or not. We
  226. need to know if this is a regular AF_LOCAL socket or an end of a socketpair
  227. that the service uses. We don't want to keep state in the intercept, so
  228. we simply ask the service via an RPC */
  229. static int is_mapped_to_service(int sockfd)
  230. {
  231. dwr(MSG_DEBUG,"is_mapped_to_service()\n");
  232. char cmd[BUF_SZ];
  233. memset(cmd, '\0', BUF_SZ);
  234. cmd[0] = RPC_MAP_REQ;
  235. memcpy(&cmd[1], &sockfd, sizeof(sockfd));
  236. return send_cmd(fdret_sock, cmd);
  237. }
  238. /*------------------------------------------------------------------------------
  239. ---------- Unix-domain socket lazy initializer (for fd-transfers)--------------
  240. ------------------------------------------------------------------------------*/
  241. /* Sets up the connection pipes and sockets to the service */
  242. static int init_service_connection()
  243. {
  244. struct sockaddr_un addr;
  245. int tfd = -1, attempts = 0, conn_err = -1;
  246. const char *network_id;
  247. char af_sock_name[1024];
  248. network_id = getenv("ZT_NC_NETWORK");
  249. if (!network_id)
  250. return -1;
  251. strncpy(af_sock_name,network_id,sizeof(af_sock_name));
  252. instance_count++;
  253. dwr(MSG_DEBUG,"init_service_connection()\n");
  254. memset(&addr, 0, sizeof(addr));
  255. addr.sun_family = AF_UNIX;
  256. strncpy(addr.sun_path, af_sock_name, sizeof(addr.sun_path)-1);
  257. if((tfd = realsocket(AF_UNIX, SOCK_STREAM, 0)) == -1)
  258. return -1;
  259. while(conn_err < 0 && attempts < SERVICE_CONNECT_ATTEMPTS) {
  260. conn_err = realconnect(tfd, (struct sockaddr*)&addr, sizeof(addr));
  261. if(conn_err < 0) {
  262. dwr(MSG_DEBUG,"re-attempting connection in %ds\n", 1+attempts);
  263. sleep(1);
  264. }
  265. else {
  266. dwr(MSG_DEBUG,"AF_UNIX connection established: %d\n", tfd);
  267. is_initialized = 1;
  268. int newtfd = realdup2(tfd, RPC_FD-instance_count);
  269. dwr(MSG_DEBUG,"dup'd to rpc_fd = %d\n", newtfd);
  270. close(tfd);
  271. return newtfd;
  272. }
  273. attempts++;
  274. }
  275. return -1;
  276. }
  277. /*------------------------------------------------------------------------------
  278. ------------------------ ctors and dtors (and friends)-------------------------
  279. ------------------------------------------------------------------------------*/
  280. static void my_dest(void) __attribute__ ((destructor));
  281. static void my_dest(void) {
  282. dwr(MSG_DEBUG,"closing connections to service...\n");
  283. pthread_mutex_destroy(&lock);
  284. }
  285. static void load_symbols(void)
  286. {
  287. if(thispid == getpid()) {
  288. dwr(MSG_DEBUG,"detected duplicate call to global constructor (pid=%d).\n", thispid);
  289. }
  290. thispid = getpid();
  291. realconnect = dlsym(RTLD_NEXT, "connect");
  292. realbind = dlsym(RTLD_NEXT, "bind");
  293. realaccept = dlsym(RTLD_NEXT, "accept");
  294. reallisten = dlsym(RTLD_NEXT, "listen");
  295. realsocket = dlsym(RTLD_NEXT, "socket");
  296. realbind = dlsym(RTLD_NEXT, "bind");
  297. realsetsockopt = dlsym(RTLD_NEXT, "setsockopt");
  298. realgetsockopt = dlsym(RTLD_NEXT, "getsockopt");
  299. realaccept4 = dlsym(RTLD_NEXT, "accept4");
  300. realclone = dlsym(RTLD_NEXT, "clone");
  301. realclose = dlsym(RTLD_NEXT, "close");
  302. realsyscall = dlsym(RTLD_NEXT, "syscall");
  303. realdup2 = dlsym(RTLD_NEXT, "dup2");
  304. realdup3 = dlsym(RTLD_NEXT, "dup3");
  305. realgetsockname = dlsym(RTLD_NEXT, "getsockname");
  306. }
  307. /* Private Function Prototypes */
  308. static void _init(void) __attribute__ ((constructor));
  309. static void _init(void) { set_up_intercept(); }
  310. /* get symbols and initialize mutexes */
  311. static void set_up_intercept()
  312. {
  313. if (!getenv("ZT_NC_NETWORK"))
  314. return;
  315. /* Hook/intercept Posix net API symbols */
  316. load_symbols();
  317. if(pthread_mutex_init(&lock, NULL) != 0) {
  318. dwr(MSG_ERROR, "error while initializing service call mutex\n");
  319. }
  320. if(pthread_mutex_init(&loglock, NULL) != 0) {
  321. dwr(MSG_ERROR, "error while initializing log mutex mutex\n");
  322. }
  323. }
  324. /*------------------------------------------------------------------------------
  325. --------------------------------- setsockopt() ---------------------------------
  326. ------------------------------------------------------------------------------*/
  327. /* int socket, int level, int option_name, const void *option_value, socklen_t option_len */
  328. int setsockopt(SETSOCKOPT_SIG)
  329. {
  330. if(realsetsockopt == NULL){
  331. dwr(MSG_ERROR, "setsockopt(): SYMBOL NOT FOUND.\n");
  332. return -1;
  333. }
  334. dwr(MSG_DEBUG,"setsockopt(%d)\n", socket);
  335. /*
  336. if(is_mapped_to_service(socket) < 0) { // First, check if the service manages this
  337. return realsetsockopt(socket, level, option_name, option_value, option_len);
  338. }
  339. */
  340. /* return(realsetsockopt(socket, level, option_name, option_value, option_len)); */
  341. if(level == SOL_IPV6 && option_name == IPV6_V6ONLY)
  342. return 0;
  343. if(level == SOL_IP && option_name == IP_TTL)
  344. return 0;
  345. if(level == IPPROTO_TCP || (level == SOL_SOCKET && option_name == SO_KEEPALIVE))
  346. return 0;
  347. /* make sure we don't touch any standard outputs */
  348. if(socket == STDIN_FILENO || socket == STDOUT_FILENO || socket == STDERR_FILENO)
  349. return(realsetsockopt(socket, level, option_name, option_value, option_len));
  350. int err = realsetsockopt(socket, level, option_name, option_value, option_len);
  351. if(err < 0){
  352. perror("setsockopt():\n");
  353. }
  354. return 0;
  355. }
  356. /*------------------------------------------------------------------------------
  357. --------------------------------- getsockopt() ---------------------------------
  358. ------------------------------------------------------------------------------*/
  359. /* int sockfd, int level, int optname, void *optval, socklen_t *optlen */
  360. int getsockopt(GETSOCKOPT_SIG)
  361. {
  362. if(realgetsockopt == NULL){
  363. dwr(MSG_ERROR, "getsockopt(): SYMBOL NOT FOUND.\n");
  364. return -1;
  365. }
  366. dwr(MSG_DEBUG,"getsockopt(%d)\n", sockfd);
  367. if(is_mapped_to_service(sockfd) <= 0) { // First, check if the service manages this
  368. return realgetsockopt(sockfd, level, optname, optval, optlen);
  369. }
  370. //return 0;
  371. //int err = realgetsockopt(sockfd, level, optname, optval, optlen);
  372. /* TODO: this condition will need a little more intelligence later on
  373. -- we will need to know if this fd is a local we are spoofing, or a true local */
  374. if(optname == SO_TYPE)
  375. {
  376. int* val = (int*)optval;
  377. *val = 2;
  378. optval = (void*)val;
  379. }
  380. /*
  381. if(err < 0){
  382. perror("getsockopt():\n");
  383. }
  384. */
  385. return 0;
  386. }
  387. /*------------------------------------------------------------------------------
  388. ----------------------------------- socket() -----------------------------------
  389. ------------------------------------------------------------------------------*/
  390. /* int socket_family, int socket_type, int protocol
  391. socket() intercept function */
  392. int socket(SOCKET_SIG)
  393. {
  394. if(realsocket == NULL){
  395. dwr(MSG_ERROR, "socket(): SYMBOL NOT FOUND.\n");
  396. return -1;
  397. }
  398. dwr(MSG_DEBUG,"socket():\n");
  399. int err;
  400. #ifdef CHECKS
  401. /* Check that type makes sense */
  402. int flags = socket_type & ~SOCK_TYPE_MASK;
  403. if (flags & ~(SOCK_CLOEXEC | SOCK_NONBLOCK)) {
  404. errno = EINVAL;
  405. handle_error("socket", "", -1);
  406. return -1;
  407. }
  408. socket_type &= SOCK_TYPE_MASK;
  409. /* Check protocol is in range */
  410. if (socket_family < 0 || socket_family >= NPROTO){
  411. errno = EAFNOSUPPORT;
  412. handle_error("socket", "", -1);
  413. return -1;
  414. }
  415. if (socket_type < 0 || socket_type >= SOCK_MAX) {
  416. errno = EINVAL;
  417. handle_error("socket", "", -1);
  418. return -1;
  419. }
  420. /* Check that we haven't hit the soft-limit file descriptors allowed */
  421. /* FIXME: Find number of open fds
  422. struct rlimit rl;
  423. getrlimit(RLIMIT_NOFILE, &rl);
  424. if(sockfd >= rl.rlim_cur){
  425. errno = EMFILE;
  426. return -1;
  427. }
  428. */
  429. /* TODO: detect ENFILE condition */
  430. #endif
  431. char cmd[BUF_SZ];
  432. fdret_sock = !is_initialized ? init_service_connection() : fdret_sock;
  433. if(fdret_sock < 0) {
  434. dwr(MSG_DEBUG,"BAD service connection. exiting.\n");
  435. handle_error("socket", "", -1);
  436. exit(-1);
  437. }
  438. if(socket_family == AF_LOCAL
  439. || socket_family == AF_NETLINK
  440. || socket_family == AF_UNIX) {
  441. int err = realsocket(socket_family, socket_type, protocol);
  442. dwr(MSG_DEBUG,"realsocket, err = %d\n", err);
  443. handle_error("socket", "", err);
  444. return err;
  445. }
  446. /* Assemble and send RPC */
  447. struct socket_st rpc_st;
  448. rpc_st.socket_family = socket_family;
  449. rpc_st.socket_type = socket_type;
  450. rpc_st.protocol = protocol;
  451. rpc_st.__tid = syscall(SYS_gettid);
  452. memset(cmd, '\0', BUF_SZ);
  453. cmd[0] = RPC_SOCKET;
  454. memcpy(&cmd[1], &rpc_st, sizeof(struct socket_st));
  455. /* send command and get new fd */
  456. newfd = send_cmd(fdret_sock, cmd);
  457. if(newfd > 0)
  458. {
  459. dwr(MSG_DEBUG,"sending fd = %d to Service over (%d)\n", newfd, fdret_sock);
  460. /* send our local-fd number back to service so
  461. it can complete its mapping table entry */
  462. memset(cmd, '\0', BUF_SZ);
  463. cmd[0] = RPC_MAP;
  464. memcpy(&cmd[1], &newfd, sizeof(newfd));
  465. /* send fd mapping and get confirmation */
  466. err = send_cmd(fdret_sock, cmd);
  467. if(err > -1) {
  468. errno = ERR_OK;
  469. dwr(MSG_DEBUG, "RXd fd confirmation. Mapped!\n");
  470. return newfd; /* Mapping complete, everything is OK */
  471. }
  472. else{
  473. dwr(MSG_DEBUG,"Error, service sent bad fd.\n");
  474. return err; /* Mapping failed */
  475. }
  476. }
  477. else {
  478. dwr(MSG_DEBUG,"Error while receiving new fd.\n");
  479. return newfd;
  480. }
  481. }
  482. /*------------------------------------------------------------------------------
  483. ---------------------------------- connect() -----------------------------------
  484. ------------------------------------------------------------------------------*/
  485. /* int __fd, const struct sockaddr * __addr, socklen_t __len
  486. connect() intercept function */
  487. int connect(CONNECT_SIG)
  488. {
  489. if(realconnect == NULL){
  490. dwr(MSG_ERROR, "connect(): SYMBOL NOT FOUND.\n");
  491. return -1;
  492. }
  493. dwr(MSG_DEBUG,"connect(%d):\n", __fd);
  494. /* print_addr(__addr); */
  495. struct sockaddr_in *connaddr;
  496. connaddr = (struct sockaddr_in *) __addr;
  497. #ifdef CHECKS
  498. /* Check that this is a valid fd */
  499. if(fcntl(__fd, F_GETFD) < 0) {
  500. errno = EBADF;
  501. handle_error("connect", "EBADF", -1);
  502. return -1;
  503. }
  504. /* Check that it is a socket */
  505. int sock_type;
  506. socklen_t sock_type_len = sizeof(sock_type);
  507. if(getsockopt(__fd, SOL_SOCKET, SO_TYPE, (void *) &sock_type, &sock_type_len) < 0) {
  508. errno = ENOTSOCK;
  509. handle_error("connect", "ENOTSOCK", -1);
  510. return -1;
  511. }
  512. /* Check family */
  513. if (connaddr->sin_family < 0 || connaddr->sin_family >= NPROTO){
  514. errno = EAFNOSUPPORT;
  515. handle_error("connect", "EAFNOSUPPORT", -1);
  516. return -1;
  517. }
  518. /* FIXME: Check that address is in user space, return EFAULT ? */
  519. #endif
  520. /* make sure we don't touch any standard outputs */
  521. if(__fd == STDIN_FILENO || __fd == STDOUT_FILENO || __fd == STDERR_FILENO){
  522. if (realconnect == NULL) {
  523. handle_error("connect", "Unresolved symbol [connect]", -1);
  524. exit(-1);
  525. }
  526. return(realconnect(__fd, __addr, __len));
  527. }
  528. if(__addr != NULL && (connaddr->sin_family == AF_LOCAL
  529. || connaddr->sin_family == PF_NETLINK
  530. || connaddr->sin_family == AF_NETLINK
  531. || connaddr->sin_family == AF_UNIX)) {
  532. int err = realconnect(__fd, __addr, __len);
  533. perror("connect():");
  534. /* handle_error("connect", "Cannot connect to local socket", err); */
  535. return err;
  536. }
  537. /* Assemble and send RPC */
  538. char cmd[BUF_SZ];
  539. memset(cmd, '\0', BUF_SZ);
  540. struct connect_st rpc_st;
  541. rpc_st.__tid = syscall(SYS_gettid);
  542. rpc_st.__fd = __fd;
  543. memcpy(&rpc_st.__addr, __addr, sizeof(struct sockaddr_storage));
  544. memcpy(&rpc_st.__len, &__len, sizeof(socklen_t));
  545. cmd[0] = RPC_CONNECT;
  546. memcpy(&cmd[1], &rpc_st, sizeof(struct connect_st));
  547. return send_cmd(fdret_sock, cmd);
  548. }
  549. /*------------------------------------------------------------------------------
  550. ------------------------------------ bind() ------------------------------------
  551. ------------------------------------------------------------------------------*/
  552. /* int sockfd, const struct sockaddr *addr, socklen_t addrlen
  553. bind() intercept function */
  554. int bind(BIND_SIG)
  555. {
  556. if(realbind == NULL){
  557. dwr(MSG_ERROR, "bind(): SYMBOL NOT FOUND.\n");
  558. return -1;
  559. }
  560. dwr(MSG_DEBUG,"bind(%d):\n", sockfd);
  561. /* print_addr(addr); */
  562. #ifdef CHECKS
  563. /* Check that this is a valid fd */
  564. if(fcntl(sockfd, F_GETFD) < 0) {
  565. errno = EBADF;
  566. handle_error("bind", "EBADF", -1);
  567. return -1;
  568. }
  569. /* Check that it is a socket */
  570. int opt = -1;
  571. socklen_t opt_len;
  572. if(getsockopt(sockfd, SOL_SOCKET, SO_TYPE, (void *) &opt, &opt_len) < 0) {
  573. errno = ENOTSOCK;
  574. handle_error("bind", "ENOTSOCK", -1);
  575. return -1;
  576. }
  577. #endif
  578. /* make sure we don't touch any standard outputs */
  579. if(sockfd == STDIN_FILENO || sockfd == STDOUT_FILENO || sockfd == STDERR_FILENO)
  580. return(realbind(sockfd, addr, addrlen));
  581. /* If local, just use normal syscall */
  582. struct sockaddr_in *connaddr;
  583. connaddr = (struct sockaddr_in *)addr;
  584. if(connaddr->sin_family == AF_LOCAL
  585. || connaddr->sin_family == AF_NETLINK
  586. || connaddr->sin_family == AF_UNIX) {
  587. int err = realbind(sockfd, addr, addrlen);
  588. dwr(MSG_DEBUG,"realbind, err = %d\n", err);
  589. return err;
  590. }
  591. int port = connaddr->sin_port;
  592. int ip = connaddr->sin_addr.s_addr;
  593. unsigned char d[4];
  594. d[0] = ip & 0xFF;
  595. d[1] = (ip >> 8) & 0xFF;
  596. d[2] = (ip >> 16) & 0xFF;
  597. d[3] = (ip >> 24) & 0xFF;
  598. dwr(MSG_DEBUG, "bind(): %d.%d.%d.%d: %d\n", d[0],d[1],d[2],d[3], ntohs(port));
  599. /* Assemble and send RPC */
  600. char cmd[BUF_SZ];
  601. struct bind_st rpc_st;
  602. rpc_st.sockfd = sockfd;
  603. rpc_st.__tid = syscall(SYS_gettid);
  604. memcpy(&rpc_st.addr, addr, sizeof(struct sockaddr_storage));
  605. memcpy(&rpc_st.addrlen, &addrlen, sizeof(socklen_t));
  606. cmd[0]=RPC_BIND;
  607. memcpy(&cmd[1], &rpc_st, sizeof(struct bind_st));
  608. return send_cmd(fdret_sock, cmd);
  609. }
  610. /*------------------------------------------------------------------------------
  611. ----------------------------------- accept4() ----------------------------------
  612. ------------------------------------------------------------------------------*/
  613. /* int sockfd, struct sockaddr *addr, socklen_t *addrlen, int flags */
  614. int accept4(ACCEPT4_SIG)
  615. {
  616. if(realaccept4 == NULL){
  617. dwr(MSG_ERROR, "accept4(): SYMBOL NOT FOUND.\n");
  618. return -1;
  619. }
  620. dwr(MSG_DEBUG,"accept4(%d):\n", sockfd);
  621. if ((flags & SOCK_CLOEXEC))
  622. fcntl(sockfd, F_SETFL, FD_CLOEXEC);
  623. if ((flags & SOCK_NONBLOCK))
  624. fcntl(sockfd, F_SETFL, O_NONBLOCK);
  625. int newfd = accept(sockfd, addr, addrlen);
  626. handle_error("accept4", "", newfd);
  627. return newfd;
  628. }
  629. /*------------------------------------------------------------------------------
  630. ----------------------------------- accept() -----------------------------------
  631. ------------------------------------------------------------------------------*/
  632. /* int sockfd struct sockaddr *addr, socklen_t *addrlen
  633. accept() intercept function */
  634. int accept(ACCEPT_SIG)
  635. {
  636. if(realaccept == NULL){
  637. dwr(MSG_ERROR, "accept(): SYMBOL NOT FOUND.\n");
  638. return -1;
  639. }
  640. dwr(MSG_DEBUG,"accept(%d):\n", sockfd);
  641. #ifdef CHECKS
  642. /* Check that this is a valid fd */
  643. if(fcntl(sockfd, F_GETFD) < 0) {
  644. return -1;
  645. errno = EBADF;
  646. dwr(MSG_DEBUG,"EBADF\n");
  647. handle_error("accept", "EBADF", -1);
  648. return -1;
  649. }
  650. /* Check that it is a socket */
  651. int opt;
  652. socklen_t opt_len;
  653. if(getsockopt(sockfd, SOL_SOCKET, SO_TYPE, (void *) &opt, &opt_len) < 0) {
  654. errno = ENOTSOCK;
  655. dwr(MSG_DEBUG,"ENOTSOCK\n");
  656. handle_error("accept", "ENOTSOCK", -1);
  657. return -1;
  658. }
  659. /* Check that this socket supports accept() */
  660. if(!(opt && (SOCK_STREAM | SOCK_SEQPACKET))) {
  661. errno = EOPNOTSUPP;
  662. dwr(MSG_DEBUG,"EOPNOTSUPP\n");
  663. handle_error("accept", "EOPNOTSUPP", -1);
  664. return -1;
  665. }
  666. /* Check that we haven't hit the soft-limit file descriptors allowed */
  667. struct rlimit rl;
  668. getrlimit(RLIMIT_NOFILE, &rl);
  669. if(sockfd >= rl.rlim_cur){
  670. errno = EMFILE;
  671. dwr(MSG_DEBUG,"EMFILE\n");
  672. handle_error("accept", "EMFILE", -1);
  673. return -1;
  674. }
  675. /* Check address length */
  676. if(addrlen < 0) {
  677. errno = EINVAL;
  678. dwr(MSG_DEBUG,"EINVAL\n");
  679. handle_error("accept", "EINVAL", -1);
  680. return -1;
  681. }
  682. #endif
  683. /* redirect calls for standard I/O descriptors to kernel */
  684. if(sockfd == STDIN_FILENO || sockfd == STDOUT_FILENO || sockfd == STDERR_FILENO){
  685. dwr(MSG_DEBUG,"realaccept():\n");
  686. return(realaccept(sockfd, addr, addrlen));
  687. }
  688. if(addr)
  689. addr->sa_family = AF_INET;
  690. /* TODO: also get address info */
  691. char cmd[BUF_SZ];
  692. /* The following line is required for libuv/nodejs to accept connections properly,
  693. however, this has the side effect of causing certain webservers to max out the CPU
  694. in an accept loop */
  695. //fcntl(sockfd, F_SETFL, SOCK_NONBLOCK);
  696. int new_conn_socket = get_new_fd(sockfd);
  697. if(new_conn_socket > 0)
  698. {
  699. dwr(MSG_DEBUG, "accept(): RX: fd = (%d) over (%d)\n", new_conn_socket, fdret_sock);
  700. /* Send our local-fd number back to service so it can complete its mapping table */
  701. memset(cmd, '\0', BUF_SZ);
  702. cmd[0] = RPC_MAP;
  703. memcpy(&cmd[1], &new_conn_socket, sizeof(new_conn_socket));
  704. dwr(MSG_DEBUG, "accept(): sending perceived fd (%d) to service.\n", new_conn_socket);
  705. send_cmd(fdret_sock, cmd);
  706. /*
  707. if(n_write < 0) {
  708. errno = ECONNABORTED;
  709. handle_error("accept", "ECONNABORTED - Error sending perceived FD to service", -1);
  710. return -1;
  711. }
  712. */
  713. errno = ERR_OK;
  714. dwr(MSG_DEBUG,"accept()=%d\n", new_conn_socket);
  715. return new_conn_socket; /* OK */
  716. }
  717. errno = EAGAIN; /* necessary? */
  718. handle_error("accept", "EAGAIN - Error reading signal byte from service", -1);
  719. return -EAGAIN;
  720. }
  721. /*------------------------------------------------------------------------------
  722. ------------------------------------- listen()----------------------------------
  723. ------------------------------------------------------------------------------*/
  724. /* int sockfd, int backlog */
  725. int listen(LISTEN_SIG)
  726. {
  727. if(reallisten == NULL){
  728. dwr(MSG_ERROR, "listen(): SYMBOL NOT FOUND.\n");
  729. return -1;
  730. }
  731. dwr(MSG_DEBUG,"listen(%d):\n", sockfd);
  732. int sock_type;
  733. socklen_t sock_type_len = sizeof(sock_type);
  734. #ifdef CHECKS
  735. /* Check that this is a valid fd */
  736. if(fcntl(sockfd, F_GETFD) < 0) {
  737. errno = EBADF;
  738. handle_error("listen", "EBADF", -1);
  739. return -1;
  740. }
  741. /* Check that it is a socket */
  742. if(getsockopt(sockfd, SOL_SOCKET, SO_TYPE, (void *) &sock_type, &sock_type_len) < 0) {
  743. errno = ENOTSOCK;
  744. handle_error("listen", "ENOTSOCK", -1);
  745. return -1;
  746. }
  747. /* Check that this socket supports accept() */
  748. if(!(sock_type && (SOCK_STREAM | SOCK_SEQPACKET))) {
  749. errno = EOPNOTSUPP;
  750. handle_error("listen", "EOPNOTSUPP", -1);
  751. return -1;
  752. }
  753. #endif
  754. /* make sure we don't touch any standard outputs */
  755. if(sockfd == STDIN_FILENO || sockfd == STDOUT_FILENO || sockfd == STDERR_FILENO)
  756. return(reallisten(sockfd, backlog));
  757. if(is_mapped_to_service(sockfd) < 0) {
  758. /* We now know this socket is not one of our socketpairs */
  759. int err = reallisten(sockfd, backlog);
  760. dwr(MSG_DEBUG,"reallisten()=%d\n", err);
  761. return err;
  762. }
  763. /* Assemble and send RPC */
  764. char cmd[BUF_SZ];
  765. memset(cmd, '\0', BUF_SZ);
  766. struct listen_st rpc_st;
  767. rpc_st.sockfd = sockfd;
  768. rpc_st.backlog = backlog;
  769. rpc_st.__tid = syscall(SYS_gettid);
  770. cmd[0] = RPC_LISTEN;
  771. memcpy(&cmd[1], &rpc_st, sizeof(struct listen_st));
  772. return send_cmd(fdret_sock, cmd);
  773. }
  774. /*------------------------------------------------------------------------------
  775. -------------------------------------- clone() ---------------------------------
  776. ------------------------------------------------------------------------------*/
  777. /* int (*fn)(void *), void *child_stack, int flags, void *arg, ... */
  778. int clone(CLONE_SIG)
  779. {
  780. if(realclone == NULL){
  781. dwr(MSG_ERROR, "clone(): SYMBOL NOT FOUND.\n");
  782. return -1;
  783. }
  784. dwr(MSG_DEBUG,"clone()\n");
  785. int err = realclone(fn, child_stack, flags, arg);
  786. checkpid();
  787. return err;
  788. }
  789. /*------------------------------------------------------------------------------
  790. ------------------------------------- close() ----------------------------------
  791. ------------------------------------------------------------------------------*/
  792. /* int fd */
  793. int close(CLOSE_SIG)
  794. {
  795. dwr(MSG_DEBUG, "close(%d)\n", fd);
  796. if(realclose == NULL){
  797. checkpid(); // Add for nginx support, remove for apache support.
  798. dwr(MSG_ERROR, "close(%d): SYMBOL NOT FOUND.\n", fd);
  799. return -1;
  800. }
  801. if(fd == fdret_sock)
  802. return -1; /* TODO: Ignore request to shut down our rpc fd, this is *almost always* safe */
  803. if(fd != STDIN_FILENO && fd != STDOUT_FILENO && fd != STDERR_FILENO)
  804. return realclose(fd);
  805. return -1;
  806. }
  807. /*------------------------------------------------------------------------------
  808. -------------------------------------- dup2() ----------------------------------
  809. ------------------------------------------------------------------------------*/
  810. /* int oldfd, int newfd */
  811. int dup2(DUP2_SIG)
  812. {
  813. if(realdup2 == NULL){
  814. dwr(MSG_ERROR, "dup2(): SYMBOL NOT FOUND.\n");
  815. return -1;
  816. }
  817. dwr(MSG_DEBUG,"dup2(%d, %d)\n", oldfd, newfd);
  818. if(oldfd == fdret_sock) {
  819. dwr(MSG_DEBUG,"client application attempted to dup2 RPC socket (%d). This is not allowed.\n", oldfd);
  820. errno = EBADF;
  821. return -1;
  822. }
  823. //if(oldfd != STDIN_FILENO && oldfd != STDOUT_FILENO && oldfd != STDERR_FILENO)
  824. // if(newfd != STDIN_FILENO && newfd != STDOUT_FILENO && newfd != STDERR_FILENO)
  825. return realdup2(oldfd, newfd);
  826. return -1;
  827. }
  828. /*------------------------------------------------------------------------------
  829. -------------------------------------- dup3() ----------------------------------
  830. ------------------------------------------------------------------------------*/
  831. /* int oldfd, int newfd, int flags */
  832. int dup3(DUP3_SIG)
  833. {
  834. if(realdup3 == NULL){
  835. dwr(MSG_ERROR, "dup3(): SYMBOL NOT FOUND.\n");
  836. return -1;
  837. }
  838. dwr(MSG_DEBUG,"dup3(%d, %d, %d)\n", oldfd, newfd, flags);
  839. #ifdef DEBUG
  840. /* Only do this check if we want to debug the intercept, otherwise, dont mess with
  841. the client application's logging methods */
  842. if(newfd == STDIN_FILENO || newfd == STDOUT_FILENO || newfd == STDERR_FILENO)
  843. return newfd; /* FIXME: This is to prevent httpd from dup'ing over our stderr
  844. and preventing us from debugging */
  845. else
  846. #endif
  847. return realdup3(oldfd, newfd, flags);
  848. }
  849. /*------------------------------------------------------------------------------
  850. -------------------------------- getsockname() ---------------------------------
  851. ------------------------------------------------------------------------------*/
  852. /* define GETSOCKNAME_SIG int sockfd, struct sockaddr *addr, socklen_t *addrlen */
  853. int getsockname(GETSOCKNAME_SIG)
  854. {
  855. if (realgetsockname == NULL) {
  856. dwr(MSG_ERROR, "getsockname(): SYMBOL NOT FOUND. \n");
  857. return -1;
  858. }
  859. dwr(MSG_DEBUG, "getsockname(%d)\n", sockfd);
  860. if(!is_mapped_to_service(sockfd))
  861. return realgetsockname(sockfd, addr, addrlen);
  862. /* This is kind of a hack as it stands -- assumes sockaddr is sockaddr_in
  863. * and is an IPv4 address. */
  864. /* assemble and send command */
  865. char cmd[BUF_SZ];
  866. struct getsockname_st rpc_st;
  867. rpc_st.sockfd = sockfd;
  868. memcpy(&rpc_st.addr, addr, *addrlen);
  869. memcpy(&rpc_st.addrlen, &addrlen, sizeof(socklen_t));
  870. cmd[0] = RPC_GETSOCKNAME;
  871. memcpy(&cmd[1], &rpc_st, sizeof(struct getsockname_st));
  872. send_cmd(fdret_sock, cmd);
  873. /* read address info from service */
  874. char addrbuf[sizeof(struct sockaddr_storage)];
  875. memset(&addrbuf, 0, sizeof(struct sockaddr_storage));
  876. read(fdret_sock, &addrbuf, sizeof(struct sockaddr_storage));
  877. struct sockaddr_storage sock_storage;
  878. memcpy(&sock_storage, addrbuf, sizeof(struct sockaddr_storage));
  879. *addrlen = sizeof(struct sockaddr_in);
  880. memcpy(addr, &sock_storage, (*addrlen > sizeof(sock_storage)) ? sizeof(sock_storage) : *addrlen);
  881. addr->sa_family = AF_INET;
  882. return 0;
  883. }
  884. /*------------------------------------------------------------------------------
  885. ------------------------------------ syscall() ---------------------------------
  886. ------------------------------------------------------------------------------*/
  887. long syscall(SYSCALL_SIG){
  888. if(realsyscall == NULL){
  889. dwr(MSG_ERROR, "syscall(): SYMBOL NOT FOUND.\n");
  890. return -1;
  891. }
  892. //dwr(MSG_DEBUG_EXTRA,"syscall(%u, ...):\n", number);
  893. va_list ap;
  894. uintptr_t a,b,c,d,e,f;
  895. va_start(ap, number);
  896. a=va_arg(ap, uintptr_t);
  897. b=va_arg(ap, uintptr_t);
  898. c=va_arg(ap, uintptr_t);
  899. d=va_arg(ap, uintptr_t);
  900. e=va_arg(ap, uintptr_t);
  901. f=va_arg(ap, uintptr_t);
  902. va_end(ap);
  903. #if defined(__i386__)
  904. /* TODO: Implement for 32-bit systems: syscall(__NR_socketcall, 18, args);
  905. args[0] = (unsigned long) fd;
  906. args[1] = (unsigned long) addr;
  907. args[2] = (unsigned long) addrlen;
  908. args[3] = (unsigned long) flags;
  909. */
  910. #else
  911. if(number == __NR_accept4) {
  912. int sockfd = a;
  913. struct sockaddr * addr = (struct sockaddr*)b;
  914. socklen_t * addrlen = (socklen_t*)c;
  915. int flags = d;
  916. int old_errno = errno;
  917. int err = accept4(sockfd, addr, addrlen, flags);
  918. errno = old_errno;
  919. if(err == -EBADF)
  920. err = -EAGAIN;
  921. return err;
  922. }
  923. #endif
  924. return realsyscall(number,a,b,c,d,e,f);
  925. }