SocketCore.cc 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056
  1. /* <!-- copyright */
  2. /*
  3. * aria2 - The high speed download utility
  4. *
  5. * Copyright (C) 2006 Tatsuhiro Tsujikawa
  6. *
  7. * This program is free software; you can redistribute it and/or modify
  8. * it under the terms of the GNU General Public License as published by
  9. * the Free Software Foundation; either version 2 of the License, or
  10. * (at your option) any later version.
  11. *
  12. * This program is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU General Public License
  18. * along with this program; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
  20. *
  21. * In addition, as a special exception, the copyright holders give
  22. * permission to link the code of portions of this program with the
  23. * OpenSSL library under certain conditions as described in each
  24. * individual source file, and distribute linked combinations
  25. * including the two.
  26. * You must obey the GNU General Public License in all respects
  27. * for all of the code used other than OpenSSL. If you modify
  28. * file(s) with this exception, you may extend this exception to your
  29. * version of the file(s), but you are not obligated to do so. If you
  30. * do not wish to do so, delete this exception statement from your
  31. * version. If you delete this exception statement from all source
  32. * files in the program, then also delete it here.
  33. */
  34. /* copyright --> */
  35. #include "SocketCore.h"
  36. #include <unistd.h>
  37. #include <cerrno>
  38. #include <cstring>
  39. #ifdef HAVE_LIBGNUTLS
  40. # include <gnutls/x509.h>
  41. #endif // HAVE_LIBGNUTLS
  42. #include "message.h"
  43. #include "a2netcompat.h"
  44. #include "DlRetryEx.h"
  45. #include "DlAbortEx.h"
  46. #include "StringFormat.h"
  47. #include "Util.h"
  48. #include "LogFactory.h"
  49. #include "TimeA2.h"
  50. #include "a2functional.h"
  51. #ifdef ENABLE_SSL
  52. # include "TLSContext.h"
  53. #endif // ENABLE_SSL
  54. #ifndef __MINGW32__
  55. # define SOCKET_ERRNO (errno)
  56. #else
  57. # define SOCKET_ERRNO (WSAGetLastError())
  58. #endif // __MINGW32__
  59. #ifdef __MINGW32__
  60. # define A2_EINPROGRESS WSAEWOULDBLOCK
  61. #else
  62. # define A2_EINPROGRESS EINPROGRESS
  63. #endif // __MINGW32__
  64. #ifdef __MINGW32__
  65. # define CLOSE(X) ::closesocket(X)
  66. #else
  67. # define CLOSE(X) while(close(X) == -1 && errno == EINTR)
  68. #endif // __MINGW32__
  69. namespace aria2 {
  70. #ifdef ENABLE_SSL
  71. SharedHandle<TLSContext> SocketCore::_tlsContext;
  72. void SocketCore::setTLSContext(const SharedHandle<TLSContext>& tlsContext)
  73. {
  74. _tlsContext = tlsContext;
  75. }
  76. #endif // ENABLE_SSL
  77. SocketCore::SocketCore(int sockType):_sockType(sockType), sockfd(-1) {
  78. init();
  79. }
  80. SocketCore::SocketCore(sock_t sockfd, int sockType):_sockType(sockType), sockfd(sockfd) {
  81. init();
  82. }
  83. void SocketCore::init()
  84. {
  85. #ifdef HAVE_EPOLL
  86. _epfd = -1;
  87. #endif // HAVE_EPOLL
  88. blocking = true;
  89. secure = 0;
  90. _wantRead = false;
  91. _wantWrite = false;
  92. #ifdef HAVE_LIBSSL
  93. // for SSL
  94. ssl = NULL;
  95. #endif // HAVE_LIBSSL
  96. #ifdef HAVE_LIBGNUTLS
  97. sslSession = NULL;
  98. peekBufMax = 4096;
  99. peekBuf = 0;
  100. peekBufLength = 0;
  101. #endif //HAVE_LIBGNUTLS
  102. }
  103. SocketCore::~SocketCore() {
  104. closeConnection();
  105. #ifdef HAVE_EPOLL
  106. if(_epfd != -1) {
  107. CLOSE(_epfd);
  108. }
  109. #endif // HAVE_EPOLL
  110. #ifdef HAVE_LIBGNUTLS
  111. delete [] peekBuf;
  112. #endif // HAVE_LIBGNUTLS
  113. }
  114. template<typename T>
  115. std::string uitos(T value)
  116. {
  117. std::string str;
  118. if(value == 0) {
  119. str = "0";
  120. return str;
  121. }
  122. while(value) {
  123. char digit = value%10+'0';
  124. str.insert(str.begin(), digit);
  125. value /= 10;
  126. }
  127. return str;
  128. }
  129. void SocketCore::bind(uint16_t port)
  130. {
  131. closeConnection();
  132. struct addrinfo hints;
  133. struct addrinfo* res;
  134. memset(&hints, 0, sizeof(hints));
  135. hints.ai_family = AF_UNSPEC;
  136. hints.ai_socktype = _sockType;
  137. hints.ai_flags = AI_PASSIVE;
  138. hints.ai_protocol = 0;
  139. int s;
  140. s = getaddrinfo(0, uitos(port).c_str(), &hints, &res);
  141. if(s) {
  142. throw DlAbortEx(StringFormat(EX_SOCKET_BIND, gai_strerror(s)).str());
  143. }
  144. struct addrinfo* rp;
  145. for(rp = res; rp; rp = rp->ai_next) {
  146. sock_t fd = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
  147. if(fd == -1) {
  148. continue;
  149. }
  150. int sockopt = 1;
  151. if(setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, (a2_sockopt_t) &sockopt, sizeof(sockopt)) < 0) {
  152. CLOSE(fd);
  153. continue;
  154. }
  155. if(::bind(fd, rp->ai_addr, rp->ai_addrlen) == -1) {
  156. CLOSE(fd);
  157. continue;
  158. }
  159. sockfd = fd;
  160. break;
  161. }
  162. freeaddrinfo(res);
  163. if(sockfd == -1) {
  164. throw DlAbortEx(StringFormat(EX_SOCKET_BIND, "all addresses failed").str());
  165. }
  166. }
  167. void SocketCore::beginListen()
  168. {
  169. if(listen(sockfd, 1) == -1) {
  170. throw DlAbortEx(StringFormat(EX_SOCKET_LISTEN, errorMsg()).str());
  171. }
  172. }
  173. SocketCore* SocketCore::acceptConnection() const
  174. {
  175. struct sockaddr_storage sockaddr;
  176. socklen_t len = sizeof(sockaddr);
  177. sock_t fd;
  178. while((fd = accept(sockfd, reinterpret_cast<struct sockaddr*>(&sockaddr), &len)) == -1 && SOCKET_ERRNO == EINTR);
  179. if(fd == -1) {
  180. throw DlAbortEx(StringFormat(EX_SOCKET_ACCEPT, errorMsg()).str());
  181. }
  182. return new SocketCore(fd, _sockType);
  183. }
  184. void SocketCore::getAddrInfo(std::pair<std::string, uint16_t>& addrinfo) const
  185. {
  186. struct sockaddr_storage sockaddr;
  187. socklen_t len = sizeof(sockaddr);
  188. struct sockaddr* addrp = reinterpret_cast<struct sockaddr*>(&sockaddr);
  189. if(getsockname(sockfd, addrp, &len) == -1) {
  190. throw DlAbortEx(StringFormat(EX_SOCKET_GET_NAME, errorMsg()).str());
  191. }
  192. addrinfo = Util::getNumericNameInfo(addrp, len);
  193. }
  194. void SocketCore::getPeerInfo(std::pair<std::string, uint16_t>& peerinfo) const
  195. {
  196. struct sockaddr_storage sockaddr;
  197. socklen_t len = sizeof(sockaddr);
  198. struct sockaddr* addrp = reinterpret_cast<struct sockaddr*>(&sockaddr);
  199. if(getpeername(sockfd, addrp, &len) == -1) {
  200. throw DlAbortEx(StringFormat(EX_SOCKET_GET_NAME, errorMsg()).str());
  201. }
  202. peerinfo = Util::getNumericNameInfo(addrp, len);
  203. }
  204. void SocketCore::establishConnection(const std::string& host, uint16_t port)
  205. {
  206. closeConnection();
  207. struct addrinfo hints;
  208. struct addrinfo* res;
  209. memset(&hints, 0, sizeof(hints));
  210. hints.ai_family = AF_UNSPEC;
  211. hints.ai_socktype = _sockType;
  212. hints.ai_flags = 0;
  213. hints.ai_protocol = 0;
  214. int s;
  215. s = getaddrinfo(host.c_str(), uitos(port).c_str(), &hints, &res);
  216. if(s) {
  217. throw DlAbortEx(StringFormat(EX_RESOLVE_HOSTNAME,
  218. host.c_str(), gai_strerror(s)).str());
  219. }
  220. struct addrinfo* rp;
  221. for(rp = res; rp; rp = rp->ai_next) {
  222. sock_t fd = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
  223. if(fd == -1) {
  224. continue;
  225. }
  226. int sockopt = 1;
  227. if(setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, (a2_sockopt_t) &sockopt, sizeof(sockopt)) < 0) {
  228. CLOSE(fd);
  229. continue;
  230. }
  231. sockfd = fd;
  232. // make socket non-blocking mode
  233. setNonBlockingMode();
  234. if(connect(fd, rp->ai_addr, rp->ai_addrlen) == -1 &&
  235. SOCKET_ERRNO != A2_EINPROGRESS) {
  236. CLOSE(sockfd);
  237. sockfd = -1;
  238. continue;
  239. }
  240. // TODO at this point, connection may not be established and it may fail
  241. // later. In such case, next ai_addr should be tried.
  242. break;
  243. }
  244. freeaddrinfo(res);
  245. if(sockfd == -1) {
  246. throw DlAbortEx(StringFormat(EX_SOCKET_CONNECT, host.c_str(),
  247. "all addresses failed").str());
  248. }
  249. }
  250. void SocketCore::setNonBlockingMode()
  251. {
  252. #ifdef __MINGW32__
  253. static u_long flag = 1;
  254. if (::ioctlsocket(sockfd, FIONBIO, &flag) == -1) {
  255. throw DlAbortEx(StringFormat(EX_SOCKET_NONBLOCKING, errorMsg()).str());
  256. }
  257. #else
  258. int flags;
  259. while((flags = fcntl(sockfd, F_GETFL, 0)) == -1 && errno == EINTR);
  260. // TODO add error handling
  261. while(fcntl(sockfd, F_SETFL, flags|O_NONBLOCK) == -1 && errno == EINTR);
  262. #endif // __MINGW32__
  263. blocking = false;
  264. }
  265. void SocketCore::setBlockingMode()
  266. {
  267. #ifdef __MINGW32__
  268. static u_long flag = 0;
  269. if (::ioctlsocket(sockfd, FIONBIO, &flag) == -1) {
  270. throw DlAbortEx(StringFormat(EX_SOCKET_BLOCKING, errorMsg()).str());
  271. }
  272. #else
  273. int flags;
  274. while((flags = fcntl(sockfd, F_GETFL, 0)) == -1 && errno == EINTR);
  275. // TODO add error handling
  276. while(fcntl(sockfd, F_SETFL, flags&(~O_NONBLOCK)) == -1 && errno == EINTR);
  277. #endif // __MINGW32__
  278. blocking = true;
  279. }
  280. void SocketCore::closeConnection()
  281. {
  282. #ifdef HAVE_LIBSSL
  283. // for SSL
  284. if(secure) {
  285. SSL_shutdown(ssl);
  286. }
  287. #endif // HAVE_LIBSSL
  288. #ifdef HAVE_LIBGNUTLS
  289. if(secure) {
  290. gnutls_bye(sslSession, GNUTLS_SHUT_RDWR);
  291. }
  292. #endif // HAVE_LIBGNUTLS
  293. if(sockfd != -1) {
  294. CLOSE(sockfd);
  295. sockfd = -1;
  296. }
  297. #ifdef HAVE_LIBSSL
  298. // for SSL
  299. if(secure) {
  300. SSL_free(ssl);
  301. }
  302. #endif // HAVE_LIBSSL
  303. #ifdef HAVE_LIBGNUTLS
  304. if(secure) {
  305. gnutls_deinit(sslSession);
  306. }
  307. #endif // HAVE_LIBGNUTLS
  308. }
  309. #ifdef HAVE_EPOLL
  310. void SocketCore::initEPOLL()
  311. {
  312. if((_epfd = epoll_create(1)) == -1) {
  313. throw DlRetryEx(StringFormat("epoll_create failed:%s", errorMsg()).str());
  314. }
  315. memset(&_epEvent, 0, sizeof(struct epoll_event));
  316. _epEvent.events = EPOLLIN|EPOLLOUT;
  317. _epEvent.data.fd = sockfd;
  318. if(epoll_ctl(_epfd, EPOLL_CTL_ADD, sockfd, &_epEvent) == -1) {
  319. throw DlRetryEx(StringFormat("epoll_ctl failed:%s", errorMsg()).str());
  320. }
  321. }
  322. #endif // HAVE_EPOLL
  323. bool SocketCore::isWritable(time_t timeout)
  324. {
  325. #ifdef HAVE_EPOLL
  326. if(_epfd == -1) {
  327. initEPOLL();
  328. }
  329. struct epoll_event epEvents[1];
  330. int r;
  331. while((r = epoll_wait(_epfd, epEvents, 1, 0)) == -1 && errno == EINTR);
  332. if(r > 0) {
  333. return epEvents[0].events&(EPOLLOUT|EPOLLHUP|EPOLLERR);
  334. } else if(r == 0) {
  335. return false;
  336. } else {
  337. throw DlRetryEx(StringFormat(EX_SOCKET_CHECK_WRITABLE, errorMsg()).str());
  338. }
  339. #else // !HAVE_EPOLL
  340. fd_set fds;
  341. FD_ZERO(&fds);
  342. FD_SET(sockfd, &fds);
  343. struct timeval tv;
  344. tv.tv_sec = timeout;
  345. tv.tv_usec = 0;
  346. int r = select(sockfd+1, NULL, &fds, NULL, &tv);
  347. if(r == 1) {
  348. return true;
  349. } else if(r == 0) {
  350. // time out
  351. return false;
  352. } else {
  353. if(SOCKET_ERRNO == A2_EINPROGRESS || SOCKET_ERRNO == EINTR) {
  354. return false;
  355. } else {
  356. throw DlRetryEx(StringFormat(EX_SOCKET_CHECK_WRITABLE, errorMsg()).str());
  357. }
  358. }
  359. #endif // !HAVE_EPOLL
  360. }
  361. bool SocketCore::isReadable(time_t timeout)
  362. {
  363. #ifdef HAVE_LIBGNUTLS
  364. if(secure && peekBufLength > 0) {
  365. return true;
  366. }
  367. #endif // HAVE_LIBGNUTLS
  368. #ifdef HAVE_EPOLL
  369. if(_epfd == -1) {
  370. initEPOLL();
  371. }
  372. struct epoll_event epEvents[1];
  373. int r;
  374. while((r = epoll_wait(_epfd, epEvents, 1, 0)) == -1 && errno == EINTR);
  375. if(r > 0) {
  376. return epEvents[0].events&(EPOLLIN|EPOLLHUP|EPOLLERR);
  377. } else if(r == 0) {
  378. return false;
  379. } else {
  380. throw DlRetryEx(StringFormat(EX_SOCKET_CHECK_READABLE, errorMsg()).str());
  381. }
  382. #else // !HAVE_EPOLL
  383. fd_set fds;
  384. FD_ZERO(&fds);
  385. FD_SET(sockfd, &fds);
  386. struct timeval tv;
  387. tv.tv_sec = timeout;
  388. tv.tv_usec = 0;
  389. int r = select(sockfd+1, &fds, NULL, NULL, &tv);
  390. if(r == 1) {
  391. return true;
  392. } else if(r == 0) {
  393. // time out
  394. return false;
  395. } else {
  396. if(SOCKET_ERRNO == A2_EINPROGRESS || SOCKET_ERRNO == EINTR) {
  397. return false;
  398. } else {
  399. throw DlRetryEx(StringFormat(EX_SOCKET_CHECK_READABLE, errorMsg()).str());
  400. }
  401. }
  402. #endif // !HAVE_EPOLL
  403. }
  404. #ifdef HAVE_LIBSSL
  405. int SocketCore::sslHandleEAGAIN(int ret)
  406. {
  407. int error = SSL_get_error(ssl, ret);
  408. if(error == SSL_ERROR_WANT_READ || error == SSL_ERROR_WANT_WRITE) {
  409. ret = 0;
  410. if(error == SSL_ERROR_WANT_READ) {
  411. _wantRead = true;
  412. } else {
  413. _wantWrite = true;
  414. }
  415. }
  416. return ret;
  417. }
  418. #endif // HAVE_LIBSSL
  419. #ifdef HAVE_LIBGNUTLS
  420. void SocketCore::gnutlsRecordCheckDirection()
  421. {
  422. int direction = gnutls_record_get_direction(sslSession);
  423. if(direction == 0) {
  424. _wantRead = true;
  425. } else { // if(direction == 1) {
  426. _wantWrite = true;
  427. }
  428. }
  429. #endif // HAVE_LIBGNUTLS
  430. ssize_t SocketCore::writeData(const char* data, size_t len)
  431. {
  432. ssize_t ret = 0;
  433. _wantRead = false;
  434. _wantWrite = false;
  435. if(!secure) {
  436. while((ret = send(sockfd, data, len, 0)) == -1 && SOCKET_ERRNO == EINTR);
  437. if(ret == -1) {
  438. if(SOCKET_ERRNO == EAGAIN) {
  439. _wantWrite = true;
  440. ret = 0;
  441. } else {
  442. throw DlRetryEx(StringFormat(EX_SOCKET_SEND, errorMsg()).str());
  443. }
  444. }
  445. } else {
  446. #ifdef HAVE_LIBSSL
  447. ret = SSL_write(ssl, data, len);
  448. if(ret == 0) {
  449. throw DlRetryEx
  450. (StringFormat
  451. (EX_SOCKET_SEND, ERR_error_string(SSL_get_error(ssl, ret), 0)).str());
  452. }
  453. if(ret < 0) {
  454. ret = sslHandleEAGAIN(ret);
  455. }
  456. if(ret < 0) {
  457. throw DlRetryEx
  458. (StringFormat
  459. (EX_SOCKET_SEND, ERR_error_string(SSL_get_error(ssl, ret), 0)).str());
  460. }
  461. #endif // HAVE_LIBSSL
  462. #ifdef HAVE_LIBGNUTLS
  463. while((ret = gnutls_record_send(sslSession, data, len)) ==
  464. GNUTLS_E_INTERRUPTED);
  465. if(ret == GNUTLS_E_AGAIN) {
  466. gnutlsRecordCheckDirection();
  467. ret = 0;
  468. } else if(ret < 0) {
  469. throw DlRetryEx(StringFormat(EX_SOCKET_SEND, gnutls_strerror(ret)).str());
  470. }
  471. #endif // HAVE_LIBGNUTLS
  472. }
  473. return ret;
  474. }
  475. void SocketCore::readData(char* data, size_t& len)
  476. {
  477. ssize_t ret = 0;
  478. _wantRead = false;
  479. _wantWrite = false;
  480. if(!secure) {
  481. while((ret = recv(sockfd, data, len, 0)) == -1 && SOCKET_ERRNO == EINTR);
  482. if(ret == -1) {
  483. if(SOCKET_ERRNO == EAGAIN) {
  484. _wantRead = true;
  485. ret = 0;
  486. } else {
  487. throw DlRetryEx(StringFormat(EX_SOCKET_RECV, errorMsg()).str());
  488. }
  489. }
  490. } else {
  491. #ifdef HAVE_LIBSSL
  492. // for SSL
  493. // TODO handling len == 0 case required
  494. ret = SSL_read(ssl, data, len);
  495. if(ret == 0) {
  496. throw DlRetryEx
  497. (StringFormat
  498. (EX_SOCKET_RECV, ERR_error_string(SSL_get_error(ssl, ret), 0)).str());
  499. }
  500. if(ret < 0) {
  501. ret = sslHandleEAGAIN(ret);
  502. }
  503. if(ret < 0) {
  504. throw DlRetryEx
  505. (StringFormat
  506. (EX_SOCKET_RECV, ERR_error_string(SSL_get_error(ssl, ret), 0)).str());
  507. }
  508. #endif // HAVE_LIBSSL
  509. #ifdef HAVE_LIBGNUTLS
  510. ret = gnutlsRecv(data, len);
  511. if(ret == GNUTLS_E_AGAIN) {
  512. gnutlsRecordCheckDirection();
  513. ret = 0;
  514. } else if(ret < 0) {
  515. throw DlRetryEx
  516. (StringFormat(EX_SOCKET_RECV, gnutls_strerror(ret)).str());
  517. }
  518. #endif // HAVE_LIBGNUTLS
  519. }
  520. len = ret;
  521. }
  522. void SocketCore::peekData(char* data, size_t& len)
  523. {
  524. ssize_t ret = 0;
  525. _wantRead = false;
  526. _wantWrite = false;
  527. if(!secure) {
  528. while((ret = recv(sockfd, data, len, MSG_PEEK)) == -1 && SOCKET_ERRNO == EINTR);
  529. if(ret == -1) {
  530. if(SOCKET_ERRNO == EAGAIN) {
  531. _wantRead = true;
  532. ret = 0;
  533. } else {
  534. throw DlRetryEx(StringFormat(EX_SOCKET_PEEK, errorMsg()).str());
  535. }
  536. }
  537. } else {
  538. #ifdef HAVE_LIBSSL
  539. // for SSL
  540. // TODO handling len == 0 case required
  541. ret = SSL_peek(ssl, data, len);
  542. LogFactory::getInstance()->debug("len = %d", ret);
  543. if(ret == 0) {
  544. throw DlRetryEx
  545. (StringFormat(EX_SOCKET_PEEK,
  546. ERR_error_string(SSL_get_error(ssl, ret), 0)).str());
  547. }
  548. if(ret < 0) {
  549. ret = sslHandleEAGAIN(ret);
  550. }
  551. if(ret < 0) {
  552. throw DlRetryEx
  553. (StringFormat(EX_SOCKET_PEEK,
  554. ERR_error_string(SSL_get_error(ssl, ret), 0)).str());
  555. }
  556. #endif // HAVE_LIBSSL
  557. #ifdef HAVE_LIBGNUTLS
  558. ret = gnutlsPeek(data, len);
  559. if(ret == GNUTLS_E_AGAIN) {
  560. gnutlsRecordCheckDirection();
  561. ret = 0;
  562. } else if(ret < 0) {
  563. throw DlRetryEx(StringFormat(EX_SOCKET_PEEK,
  564. gnutls_strerror(ret)).str());
  565. }
  566. #endif // HAVE_LIBGNUTLS
  567. }
  568. len = ret;
  569. }
  570. #ifdef HAVE_LIBGNUTLS
  571. size_t SocketCore::shiftPeekData(char* data, size_t len)
  572. {
  573. if(peekBufLength <= len) {
  574. memcpy(data, peekBuf, peekBufLength);
  575. size_t ret = peekBufLength;
  576. peekBufLength = 0;
  577. return ret;
  578. } else {
  579. memcpy(data, peekBuf, len);
  580. char* temp = new char[peekBufMax];
  581. memcpy(temp, peekBuf+len, peekBufLength-len);
  582. delete [] peekBuf;
  583. peekBuf = temp;
  584. peekBufLength -= len;
  585. return len;
  586. }
  587. }
  588. void SocketCore::addPeekData(char* data, size_t len)
  589. {
  590. if(peekBufLength+len > peekBufMax) {
  591. char* temp = new char[peekBufMax+len];
  592. memcpy(temp, peekBuf, peekBufLength);
  593. delete [] peekBuf;
  594. peekBuf = temp;
  595. peekBufMax = peekBufLength+len;
  596. }
  597. memcpy(peekBuf+peekBufLength, data, len);
  598. peekBufLength += len;
  599. }
  600. static ssize_t GNUTLS_RECORD_RECV_NO_INTERRUPT
  601. (gnutls_session_t sslSession, char* data, size_t len)
  602. {
  603. int ret;
  604. while((ret = gnutls_record_recv(sslSession, data, len)) ==
  605. GNUTLS_E_INTERRUPTED);
  606. if(ret < 0 && ret != GNUTLS_E_AGAIN) {
  607. throw DlRetryEx
  608. (StringFormat(EX_SOCKET_RECV, gnutls_strerror(ret)).str());
  609. }
  610. return ret;
  611. }
  612. ssize_t SocketCore::gnutlsRecv(char* data, size_t len)
  613. {
  614. size_t plen = shiftPeekData(data, len);
  615. if(plen < len) {
  616. ssize_t ret = GNUTLS_RECORD_RECV_NO_INTERRUPT
  617. (sslSession, data+plen, len-plen);
  618. if(ret == GNUTLS_E_AGAIN) {
  619. return GNUTLS_E_AGAIN;
  620. }
  621. return plen+ret;
  622. } else {
  623. return plen;
  624. }
  625. }
  626. ssize_t SocketCore::gnutlsPeek(char* data, size_t len)
  627. {
  628. if(peekBufLength >= len) {
  629. memcpy(data, peekBuf, len);
  630. return len;
  631. } else {
  632. memcpy(data, peekBuf, peekBufLength);
  633. ssize_t ret = GNUTLS_RECORD_RECV_NO_INTERRUPT
  634. (sslSession, data+peekBufLength, len-peekBufLength);
  635. if(ret == GNUTLS_E_AGAIN) {
  636. return GNUTLS_E_AGAIN;
  637. }
  638. addPeekData(data+peekBufLength, ret);
  639. return peekBufLength;
  640. }
  641. }
  642. #endif // HAVE_LIBGNUTLS
  643. void SocketCore::prepareSecureConnection()
  644. {
  645. if(!secure) {
  646. #ifdef HAVE_LIBSSL
  647. // for SSL
  648. ssl = SSL_new(_tlsContext->getSSLCtx());
  649. if(!ssl) {
  650. throw DlAbortEx
  651. (StringFormat(EX_SSL_INIT_FAILURE,
  652. ERR_error_string(ERR_get_error(), 0)).str());
  653. }
  654. if(SSL_set_fd(ssl, sockfd) == 0) {
  655. throw DlAbortEx
  656. (StringFormat(EX_SSL_INIT_FAILURE,
  657. ERR_error_string(ERR_get_error(), 0)).str());
  658. }
  659. #endif // HAVE_LIBSSL
  660. #ifdef HAVE_LIBGNUTLS
  661. const int cert_type_priority[3] = { GNUTLS_CRT_X509,
  662. GNUTLS_CRT_OPENPGP, 0
  663. };
  664. // while we do not support X509 certificate, most web servers require
  665. // X509 stuff.
  666. gnutls_init(&sslSession, GNUTLS_CLIENT);
  667. gnutls_set_default_priority(sslSession);
  668. gnutls_kx_set_priority(sslSession, cert_type_priority);
  669. // put the x509 credentials to the current session
  670. gnutls_credentials_set(sslSession, GNUTLS_CRD_CERTIFICATE,
  671. _tlsContext->getCertCred());
  672. gnutls_transport_set_ptr(sslSession, (gnutls_transport_ptr_t)sockfd);
  673. #endif // HAVE_LIBGNUTLS
  674. secure = 1;
  675. }
  676. }
  677. bool SocketCore::initiateSecureConnection(const std::string& hostname)
  678. {
  679. if(secure == 1) {
  680. _wantRead = false;
  681. _wantWrite = false;
  682. #ifdef HAVE_LIBSSL
  683. int e = SSL_connect(ssl);
  684. if (e <= 0) {
  685. int ssl_error = SSL_get_error(ssl, e);
  686. switch(ssl_error) {
  687. case SSL_ERROR_NONE:
  688. break;
  689. case SSL_ERROR_WANT_READ:
  690. _wantRead = true;
  691. return false;
  692. case SSL_ERROR_WANT_WRITE:
  693. _wantWrite = true;
  694. return false;
  695. case SSL_ERROR_WANT_X509_LOOKUP:
  696. case SSL_ERROR_ZERO_RETURN:
  697. if (blocking) {
  698. throw DlAbortEx
  699. (StringFormat(EX_SSL_CONNECT_ERROR, ssl_error).str());
  700. }
  701. break;
  702. case SSL_ERROR_SYSCALL:
  703. throw DlAbortEx(EX_SSL_IO_ERROR);
  704. case SSL_ERROR_SSL:
  705. throw DlAbortEx(EX_SSL_PROTOCOL_ERROR);
  706. default:
  707. throw DlAbortEx
  708. (StringFormat(EX_SSL_UNKNOWN_ERROR, ssl_error).str());
  709. }
  710. }
  711. if(_tlsContext->peerVerificationEnabled()) {
  712. // verify peer
  713. X509* peerCert = SSL_get_peer_certificate(ssl);
  714. if(!peerCert) {
  715. throw DlAbortEx(MSG_NO_CERT_FOUND);
  716. }
  717. auto_delete<X509*> certDeleter(peerCert, X509_free);
  718. long verifyResult = SSL_get_verify_result(ssl);
  719. if(verifyResult != X509_V_OK) {
  720. throw DlAbortEx
  721. (StringFormat(MSG_CERT_VERIFICATION_FAILED,
  722. X509_verify_cert_error_string(verifyResult)).str());
  723. }
  724. X509_NAME* name = X509_get_subject_name(peerCert);
  725. if(!name) {
  726. throw DlAbortEx("Could not get X509 name object from the certificate.");
  727. }
  728. bool hostnameOK = false;
  729. int lastpos = -1;
  730. while(true) {
  731. lastpos = X509_NAME_get_index_by_NID(name, NID_commonName, lastpos);
  732. if(lastpos == -1) {
  733. break;
  734. }
  735. X509_NAME_ENTRY* entry = X509_NAME_get_entry(name, lastpos);
  736. unsigned char* out;
  737. int outlen = ASN1_STRING_to_UTF8(&out, X509_NAME_ENTRY_get_data(entry));
  738. if(outlen < 0) {
  739. continue;
  740. }
  741. std::string commonName(&out[0], &out[outlen]);
  742. OPENSSL_free(out);
  743. if(commonName == hostname) {
  744. hostnameOK = true;
  745. break;
  746. }
  747. }
  748. if(!hostnameOK) {
  749. throw DlAbortEx(MSG_HOSTNAME_NOT_MATCH);
  750. }
  751. }
  752. #endif // HAVE_LIBSSL
  753. #ifdef HAVE_LIBGNUTLS
  754. int ret = gnutls_handshake(sslSession);
  755. if(ret == GNUTLS_E_AGAIN) {
  756. gnutlsRecordCheckDirection();
  757. return false;
  758. } else if(ret < 0) {
  759. throw DlAbortEx
  760. (StringFormat(EX_SSL_INIT_FAILURE, gnutls_strerror(ret)).str());
  761. }
  762. if(_tlsContext->peerVerificationEnabled()) {
  763. // verify peer
  764. unsigned int status;
  765. ret = gnutls_certificate_verify_peers2(sslSession, &status);
  766. if(ret < 0) {
  767. throw DlAbortEx
  768. (StringFormat("gnutls_certificate_verify_peer2() failed. Cause: %s",
  769. gnutls_strerror(ret)).str());
  770. }
  771. if(status) {
  772. std::string errors;
  773. if(status & GNUTLS_CERT_INVALID) {
  774. errors += " `not signed by known authorities or invalid'";
  775. }
  776. if(status & GNUTLS_CERT_REVOKED) {
  777. errors += " `revoked by its CA'";
  778. }
  779. if(status & GNUTLS_CERT_SIGNER_NOT_FOUND) {
  780. errors += " `issuer is not known'";
  781. }
  782. if(!errors.empty()) {
  783. throw DlAbortEx
  784. (StringFormat(MSG_CERT_VERIFICATION_FAILED, errors.c_str()).str());
  785. }
  786. }
  787. // certificate type: only X509 is allowed.
  788. if(gnutls_certificate_type_get(sslSession) != GNUTLS_CRT_X509) {
  789. throw DlAbortEx("Certificate type is not X509.");
  790. }
  791. unsigned int peerCertsLength;
  792. const gnutls_datum_t* peerCerts = gnutls_certificate_get_peers
  793. (sslSession, &peerCertsLength);
  794. if(!peerCerts) {
  795. throw DlAbortEx(MSG_NO_CERT_FOUND);
  796. }
  797. Time now;
  798. for(unsigned int i = 0; i < peerCertsLength; ++i) {
  799. gnutls_x509_crt_t cert;
  800. ret = gnutls_x509_crt_init(&cert);
  801. if(ret < 0) {
  802. throw DlAbortEx
  803. (StringFormat("gnutls_x509_crt_init() failed. Cause: %s",
  804. gnutls_strerror(ret)).str());
  805. }
  806. auto_delete<gnutls_x509_crt_t> certDeleter
  807. (cert, gnutls_x509_crt_deinit);
  808. ret = gnutls_x509_crt_import(cert, &peerCerts[i], GNUTLS_X509_FMT_DER);
  809. if(ret < 0) {
  810. throw DlAbortEx
  811. (StringFormat("gnutls_x509_crt_import() failed. Cause: %s",
  812. gnutls_strerror(ret)).str());
  813. }
  814. if(i == 0) {
  815. if(!gnutls_x509_crt_check_hostname(cert, hostname.c_str())) {
  816. throw DlAbortEx(MSG_HOSTNAME_NOT_MATCH);
  817. }
  818. }
  819. time_t activationTime = gnutls_x509_crt_get_activation_time(cert);
  820. if(activationTime == -1) {
  821. throw DlAbortEx("Could not get activation time from certificate.");
  822. }
  823. if(now.getTime() < activationTime) {
  824. throw DlAbortEx("Certificate is not activated yet.");
  825. }
  826. time_t expirationTime = gnutls_x509_crt_get_expiration_time(cert);
  827. if(expirationTime == -1) {
  828. throw DlAbortEx("Could not get expiration time from certificate.");
  829. }
  830. if(expirationTime < now.getTime()) {
  831. throw DlAbortEx("Certificate has expired.");
  832. }
  833. }
  834. }
  835. peekBuf = new char[peekBufMax];
  836. #endif // HAVE_LIBGNUTLS
  837. secure = 2;
  838. return true;
  839. } else {
  840. return true;
  841. }
  842. }
  843. /* static */ int SocketCore::error()
  844. {
  845. return SOCKET_ERRNO;
  846. }
  847. /* static */ const char *SocketCore::errorMsg()
  848. {
  849. return errorMsg(SOCKET_ERRNO);
  850. }
  851. /* static */ const char *SocketCore::errorMsg(const int err)
  852. {
  853. #ifndef __MINGW32__
  854. return strerror(err);
  855. #else
  856. static char buf[256];
  857. if (FormatMessage(
  858. FORMAT_MESSAGE_FROM_SYSTEM |
  859. FORMAT_MESSAGE_IGNORE_INSERTS,
  860. NULL,
  861. err,
  862. MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), // Default language
  863. (LPTSTR) &buf,
  864. sizeof(buf),
  865. NULL
  866. ) == 0) {
  867. snprintf(buf, sizeof(buf), EX_SOCKET_UNKNOWN_ERROR, err, err);
  868. }
  869. return buf;
  870. #endif // __MINGW32__
  871. }
  872. ssize_t SocketCore::writeData(const char* data, size_t len,
  873. const std::string& host, uint16_t port)
  874. {
  875. _wantRead = false;
  876. _wantWrite = false;
  877. struct addrinfo hints;
  878. struct addrinfo* res;
  879. memset(&hints, 0, sizeof(hints));
  880. hints.ai_family = AF_UNSPEC;
  881. hints.ai_socktype = _sockType;
  882. hints.ai_flags = 0;
  883. hints.ai_protocol = 0;
  884. int s;
  885. s = getaddrinfo(host.c_str(), uitos(port).c_str(), &hints, &res);
  886. if(s) {
  887. throw DlAbortEx(StringFormat(EX_SOCKET_SEND, gai_strerror(s)).str());
  888. }
  889. struct addrinfo* rp;
  890. ssize_t r = -1;
  891. for(rp = res; rp; rp = rp->ai_next) {
  892. while((r = sendto(sockfd, data, len, 0, rp->ai_addr, rp->ai_addrlen)) == -1 && EINTR == SOCKET_ERRNO);
  893. if(r == static_cast<ssize_t>(len)) {
  894. break;
  895. }
  896. if(r == -1 && SOCKET_ERRNO == EAGAIN) {
  897. _wantWrite = true;
  898. r = 0;
  899. break;
  900. }
  901. }
  902. freeaddrinfo(res);
  903. if(r == -1) {
  904. throw DlAbortEx(StringFormat(EX_SOCKET_SEND, errorMsg()).str());
  905. }
  906. return r;
  907. }
  908. ssize_t SocketCore::readDataFrom(char* data, size_t len,
  909. std::pair<std::string /* numerichost */,
  910. uint16_t /* port */>& sender)
  911. {
  912. _wantRead = false;
  913. _wantWrite = false;
  914. struct sockaddr_storage sockaddr;
  915. socklen_t sockaddrlen = sizeof(struct sockaddr_storage);
  916. struct sockaddr* addrp = reinterpret_cast<struct sockaddr*>(&sockaddr);
  917. ssize_t r;
  918. while((r = recvfrom(sockfd, data, len, 0, addrp, &sockaddrlen)) == -1 &&
  919. EINTR == SOCKET_ERRNO);
  920. if(r == -1) {
  921. if(SOCKET_ERRNO == EAGAIN) {
  922. _wantRead = true;
  923. r = 0;
  924. } else {
  925. throw DlRetryEx(StringFormat(EX_SOCKET_RECV, errorMsg()).str());
  926. }
  927. } else {
  928. sender = Util::getNumericNameInfo(addrp, sockaddrlen);
  929. }
  930. return r;
  931. }
  932. std::string SocketCore::getSocketError() const
  933. {
  934. int error;
  935. socklen_t optlen = sizeof(error);
  936. if(getsockopt(sockfd, SOL_SOCKET, SO_ERROR, (a2_sockopt_t) &error, &optlen) == -1) {
  937. throw DlAbortEx(StringFormat("Failed to get socket error: %s",
  938. errorMsg()).str());
  939. }
  940. if(error != 0) {
  941. return errorMsg(error);
  942. } else {
  943. return "";
  944. }
  945. }
  946. bool SocketCore::wantRead() const
  947. {
  948. return _wantRead;
  949. }
  950. bool SocketCore::wantWrite() const
  951. {
  952. return _wantWrite;
  953. }
  954. } // namespace aria2