SocketCore.cc 42 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501
  1. /* <!-- copyright */
  2. /*
  3. * aria2 - The high speed download utility
  4. *
  5. * Copyright (C) 2006 Tatsuhiro Tsujikawa
  6. *
  7. * This program is free software; you can redistribute it and/or modify
  8. * it under the terms of the GNU General Public License as published by
  9. * the Free Software Foundation; either version 2 of the License, or
  10. * (at your option) any later version.
  11. *
  12. * This program is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  15. * GNU General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU General Public License
  18. * along with this program; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
  20. *
  21. * In addition, as a special exception, the copyright holders give
  22. * permission to link the code of portions of this program with the
  23. * OpenSSL library under certain conditions as described in each
  24. * individual source file, and distribute linked combinations
  25. * including the two.
  26. * You must obey the GNU General Public License in all respects
  27. * for all of the code used other than OpenSSL. If you modify
  28. * file(s) with this exception, you may extend this exception to your
  29. * version of the file(s), but you are not obligated to do so. If you
  30. * do not wish to do so, delete this exception statement from your
  31. * version. If you delete this exception statement from all source
  32. * files in the program, then also delete it here.
  33. */
  34. /* copyright --> */
  35. #include "SocketCore.h"
  36. #include <unistd.h>
  37. #ifdef HAVE_IFADDRS_H
  38. # include <ifaddrs.h>
  39. #endif // HAVE_IFADDRS_H
  40. #include <cerrno>
  41. #include <cstring>
  42. #ifdef HAVE_OPENSSL
  43. # include <openssl/x509.h>
  44. # include <openssl/x509v3.h>
  45. #endif // HAVE_OPENSSL
  46. #ifdef HAVE_LIBGNUTLS
  47. # include <gnutls/x509.h>
  48. #endif // HAVE_LIBGNUTLS
  49. #include "message.h"
  50. #include "DlRetryEx.h"
  51. #include "DlAbortEx.h"
  52. #include "fmt.h"
  53. #include "util.h"
  54. #include "TimeA2.h"
  55. #include "a2functional.h"
  56. #include "LogFactory.h"
  57. #include "A2STR.h"
  58. #ifdef ENABLE_SSL
  59. # include "TLSContext.h"
  60. #endif // ENABLE_SSL
  61. namespace aria2 {
  62. #ifndef __MINGW32__
  63. # define SOCKET_ERRNO (errno)
  64. #else
  65. # define SOCKET_ERRNO (WSAGetLastError())
  66. #endif // __MINGW32__
  67. #ifdef __MINGW32__
  68. # define A2_EINPROGRESS WSAEWOULDBLOCK
  69. # define A2_EWOULDBLOCK WSAEWOULDBLOCK
  70. # define A2_EINTR WSAEINTR
  71. # define A2_WOULDBLOCK(e) (e == WSAEWOULDBLOCK)
  72. #else // !__MINGW32__
  73. # define A2_EINPROGRESS EINPROGRESS
  74. # ifndef EWOULDBLOCK
  75. # define EWOULDBLOCK EAGAIN
  76. # endif // EWOULDBLOCK
  77. # define A2_EWOULDBLOCK EWOULDBLOCK
  78. # define A2_EINTR EINTR
  79. # if EWOULDBLOCK == EAGAIN
  80. # define A2_WOULDBLOCK(e) (e == EWOULDBLOCK)
  81. # else // EWOULDBLOCK != EAGAIN
  82. # define A2_WOULDBLOCK(e) (e == EWOULDBLOCK || e == EAGAIN)
  83. # endif // EWOULDBLOCK != EAGAIN
  84. #endif // !__MINGW32__
  85. #ifdef __MINGW32__
  86. # define CLOSE(X) ::closesocket(X)
  87. #else
  88. # define CLOSE(X) close(X)
  89. #endif // __MINGW32__
  90. namespace {
  91. std::string errorMsg(int errNum)
  92. {
  93. #ifndef __MINGW32__
  94. return util::safeStrerror(errNum);
  95. #else
  96. static char buf[256];
  97. if (FormatMessage(
  98. FORMAT_MESSAGE_FROM_SYSTEM |
  99. FORMAT_MESSAGE_IGNORE_INSERTS,
  100. NULL,
  101. errNum,
  102. MAKELANGID(LANG_ENGLISH, SUBLANG_ENGLISH_US),
  103. (LPTSTR) &buf,
  104. sizeof(buf),
  105. NULL
  106. ) == 0) {
  107. snprintf(buf, sizeof(buf), EX_SOCKET_UNKNOWN_ERROR, errNum, errNum);
  108. }
  109. return buf;
  110. #endif // __MINGW32__
  111. }
  112. } // namespace
  113. namespace {
  114. enum TlsState {
  115. // TLS object is not initialized.
  116. A2_TLS_NONE = 0,
  117. // TLS object is now handshaking.
  118. A2_TLS_HANDSHAKING = 2,
  119. // TLS object is now connected.
  120. A2_TLS_CONNECTED = 3
  121. };
  122. } // namespace
  123. int SocketCore::protocolFamily_ = AF_UNSPEC;
  124. std::vector<std::pair<sockaddr_union, socklen_t> >
  125. SocketCore::bindAddrs_;
  126. #ifdef ENABLE_SSL
  127. SharedHandle<TLSContext> SocketCore::clTlsContext_;
  128. SharedHandle<TLSContext> SocketCore::svTlsContext_;
  129. void SocketCore::setClientTLSContext
  130. (const SharedHandle<TLSContext>& tlsContext)
  131. {
  132. clTlsContext_ = tlsContext;
  133. }
  134. void SocketCore::setServerTLSContext
  135. (const SharedHandle<TLSContext>& tlsContext)
  136. {
  137. svTlsContext_ = tlsContext;
  138. }
  139. #endif // ENABLE_SSL
  140. SocketCore::SocketCore(int sockType)
  141. : sockType_(sockType),
  142. sockfd_(-1)
  143. {
  144. init();
  145. }
  146. SocketCore::SocketCore(sock_t sockfd, int sockType)
  147. : sockType_(sockType),
  148. sockfd_(sockfd)
  149. {
  150. init();
  151. }
  152. void SocketCore::init()
  153. {
  154. blocking_ = true;
  155. secure_ = A2_TLS_NONE;
  156. wantRead_ = false;
  157. wantWrite_ = false;
  158. #ifdef HAVE_OPENSSL
  159. // for SSL
  160. ssl = NULL;
  161. #endif // HAVE_OPENSSL
  162. #ifdef HAVE_LIBGNUTLS
  163. sslSession_ = 0;
  164. #endif //HAVE_LIBGNUTLS
  165. }
  166. SocketCore::~SocketCore() {
  167. closeConnection();
  168. }
  169. void SocketCore::create(int family, int protocol)
  170. {
  171. int errNum;
  172. closeConnection();
  173. sock_t fd = socket(family, sockType_, protocol);
  174. errNum = SOCKET_ERRNO;
  175. if(fd == (sock_t) -1) {
  176. throw DL_ABORT_EX
  177. (fmt("Failed to create socket. Cause:%s", errorMsg(errNum).c_str()));
  178. }
  179. int sockopt = 1;
  180. if(setsockopt(fd, SOL_SOCKET, SO_REUSEADDR,
  181. (a2_sockopt_t) &sockopt, sizeof(sockopt)) < 0) {
  182. errNum = SOCKET_ERRNO;
  183. CLOSE(fd);
  184. throw DL_ABORT_EX
  185. (fmt("Failed to create socket. Cause:%s", errorMsg(errNum).c_str()));
  186. }
  187. sockfd_ = fd;
  188. }
  189. static sock_t bindInternal
  190. (int family, int socktype, int protocol,
  191. const struct sockaddr* addr, socklen_t addrlen,
  192. std::string& error)
  193. {
  194. int errNum;
  195. sock_t fd = socket(family, socktype, protocol);
  196. errNum = SOCKET_ERRNO;
  197. if(fd == (sock_t) -1) {
  198. error = errorMsg(errNum);
  199. return -1;
  200. }
  201. int sockopt = 1;
  202. if(setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, (a2_sockopt_t) &sockopt,
  203. sizeof(sockopt)) < 0) {
  204. errNum = SOCKET_ERRNO;
  205. error = errorMsg(errNum);
  206. CLOSE(fd);
  207. return -1;
  208. }
  209. #ifdef IPV6_V6ONLY
  210. if(family == AF_INET6) {
  211. int sockopt = 1;
  212. if(setsockopt(fd, IPPROTO_IPV6, IPV6_V6ONLY, (a2_sockopt_t) &sockopt,
  213. sizeof(sockopt)) < 0) {
  214. errNum = SOCKET_ERRNO;
  215. error = errorMsg(errNum);
  216. CLOSE(fd);
  217. return -1;
  218. }
  219. }
  220. #endif // IPV6_V6ONLY
  221. if(::bind(fd, addr, addrlen) == -1) {
  222. errNum = SOCKET_ERRNO;
  223. error = errorMsg(errNum);
  224. CLOSE(fd);
  225. return -1;
  226. }
  227. return fd;
  228. }
  229. static sock_t bindTo
  230. (const char* host, uint16_t port, int family, int sockType,
  231. int getaddrinfoFlags, std::string& error)
  232. {
  233. struct addrinfo* res;
  234. int s = callGetaddrinfo(&res, host, util::uitos(port).c_str(),
  235. family, sockType, getaddrinfoFlags, 0);
  236. if(s) {
  237. error = gai_strerror(s);
  238. return -1;
  239. }
  240. WSAAPI_AUTO_DELETE<struct addrinfo*> resDeleter(res, freeaddrinfo);
  241. struct addrinfo* rp;
  242. for(rp = res; rp; rp = rp->ai_next) {
  243. sock_t fd = bindInternal(rp->ai_family, rp->ai_socktype, rp->ai_protocol,
  244. rp->ai_addr, rp->ai_addrlen, error);
  245. if(fd != (sock_t)-1) {
  246. return fd;
  247. }
  248. }
  249. return -1;
  250. }
  251. void SocketCore::bindWithFamily(uint16_t port, int family, int flags)
  252. {
  253. closeConnection();
  254. std::string error;
  255. sock_t fd = bindTo(0, port, family, sockType_, flags, error);
  256. if(fd == (sock_t) -1) {
  257. throw DL_ABORT_EX(fmt(EX_SOCKET_BIND, error.c_str()));
  258. } else {
  259. sockfd_ = fd;
  260. }
  261. }
  262. void SocketCore::bind
  263. (const char* addr, uint16_t port, int family, int flags)
  264. {
  265. closeConnection();
  266. std::string error;
  267. const char* addrp;
  268. if(addr && addr[0]) {
  269. addrp = addr;
  270. } else {
  271. addrp = 0;
  272. }
  273. if(!(flags&AI_PASSIVE) || bindAddrs_.empty()) {
  274. sock_t fd = bindTo(addrp, port, family, sockType_, flags, error);
  275. if(fd != (sock_t) -1) {
  276. sockfd_ = fd;
  277. }
  278. } else {
  279. for(std::vector<std::pair<sockaddr_union, socklen_t> >::
  280. const_iterator i = bindAddrs_.begin(), eoi = bindAddrs_.end();
  281. i != eoi; ++i) {
  282. char host[NI_MAXHOST];
  283. int s;
  284. s = getnameinfo(&(*i).first.sa, (*i).second, host, NI_MAXHOST, 0, 0,
  285. NI_NUMERICHOST);
  286. if(s) {
  287. error = gai_strerror(s);
  288. continue;
  289. }
  290. if(addrp && strcmp(host, addrp) != 0) {
  291. error = "Given address and resolved address do not match.";
  292. continue;
  293. }
  294. sock_t fd = bindTo(host, port, family, sockType_, flags, error);
  295. if(fd != (sock_t)-1) {
  296. sockfd_ = fd;
  297. break;
  298. }
  299. }
  300. }
  301. if(sockfd_ == (sock_t) -1) {
  302. throw DL_ABORT_EX(fmt(EX_SOCKET_BIND, error.c_str()));
  303. }
  304. }
  305. void SocketCore::bind(uint16_t port, int flags)
  306. {
  307. bind(0, port, protocolFamily_, flags);
  308. }
  309. void SocketCore::bind(const struct sockaddr* addr, socklen_t addrlen)
  310. {
  311. closeConnection();
  312. std::string error;
  313. sock_t fd = bindInternal(addr->sa_family, sockType_, 0, addr, addrlen, error);
  314. if(fd != (sock_t)-1) {
  315. sockfd_ = fd;
  316. } else {
  317. throw DL_ABORT_EX(fmt(EX_SOCKET_BIND, error.c_str()));
  318. }
  319. }
  320. void SocketCore::beginListen()
  321. {
  322. if(listen(sockfd_, 1) == -1) {
  323. int errNum = SOCKET_ERRNO;
  324. throw DL_ABORT_EX(fmt(EX_SOCKET_LISTEN, errorMsg(errNum).c_str()));
  325. }
  326. setNonBlockingMode();
  327. }
  328. SharedHandle<SocketCore> SocketCore::acceptConnection() const
  329. {
  330. sockaddr_union sockaddr;
  331. socklen_t len = sizeof(sockaddr);
  332. sock_t fd;
  333. while((fd = accept(sockfd_, &sockaddr.sa, &len)) == (sock_t) -1 &&
  334. SOCKET_ERRNO == A2_EINTR);
  335. int errNum = SOCKET_ERRNO;
  336. if(fd == (sock_t) -1) {
  337. throw DL_ABORT_EX(fmt(EX_SOCKET_ACCEPT, errorMsg(errNum).c_str()));
  338. }
  339. SharedHandle<SocketCore> sock(new SocketCore(fd, sockType_));
  340. sock->setNonBlockingMode();
  341. sock->setTcpNodelay(true);
  342. return sock;
  343. }
  344. int SocketCore::getAddrInfo(std::pair<std::string, uint16_t>& addrinfo) const
  345. {
  346. sockaddr_union sockaddr;
  347. socklen_t len = sizeof(sockaddr);
  348. getAddrInfo(sockaddr, len);
  349. addrinfo = util::getNumericNameInfo(&sockaddr.sa, len);
  350. return sockaddr.storage.ss_family;
  351. }
  352. void SocketCore::getAddrInfo(sockaddr_union& sockaddr, socklen_t& len) const
  353. {
  354. if(getsockname(sockfd_, &sockaddr.sa, &len) == -1) {
  355. int errNum = SOCKET_ERRNO;
  356. throw DL_ABORT_EX(fmt(EX_SOCKET_GET_NAME, errorMsg(errNum).c_str()));
  357. }
  358. }
  359. int SocketCore::getAddressFamily() const
  360. {
  361. sockaddr_union sockaddr;
  362. socklen_t len = sizeof(sockaddr);
  363. getAddrInfo(sockaddr, len);
  364. return sockaddr.storage.ss_family;
  365. }
  366. int SocketCore::getPeerInfo(std::pair<std::string, uint16_t>& peerinfo) const
  367. {
  368. sockaddr_union sockaddr;
  369. socklen_t len = sizeof(sockaddr);
  370. if(getpeername(sockfd_, &sockaddr.sa, &len) == -1) {
  371. int errNum = SOCKET_ERRNO;
  372. throw DL_ABORT_EX(fmt(EX_SOCKET_GET_NAME, errorMsg(errNum).c_str()));
  373. }
  374. peerinfo = util::getNumericNameInfo(&sockaddr.sa, len);
  375. return sockaddr.storage.ss_family;
  376. }
  377. void SocketCore::establishConnection(const std::string& host, uint16_t port)
  378. {
  379. closeConnection();
  380. std::string error;
  381. struct addrinfo* res;
  382. int s;
  383. s = callGetaddrinfo(&res, host.c_str(), util::uitos(port).c_str(),
  384. protocolFamily_, sockType_, 0, 0);
  385. if(s) {
  386. throw DL_ABORT_EX(fmt(EX_RESOLVE_HOSTNAME, host.c_str(), gai_strerror(s)));
  387. }
  388. WSAAPI_AUTO_DELETE<struct addrinfo*> resDeleter(res, freeaddrinfo);
  389. struct addrinfo* rp;
  390. int errNum;
  391. for(rp = res; rp; rp = rp->ai_next) {
  392. sock_t fd = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
  393. errNum = SOCKET_ERRNO;
  394. if(fd == (sock_t) -1) {
  395. error = errorMsg(errNum);
  396. continue;
  397. }
  398. int sockopt = 1;
  399. if(setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, (a2_sockopt_t) &sockopt,
  400. sizeof(sockopt)) < 0) {
  401. errNum = SOCKET_ERRNO;
  402. error = errorMsg(errNum);
  403. CLOSE(fd);
  404. continue;
  405. }
  406. if(!bindAddrs_.empty()) {
  407. bool bindSuccess = false;
  408. for(std::vector<std::pair<sockaddr_union, socklen_t> >::
  409. const_iterator i = bindAddrs_.begin(), eoi = bindAddrs_.end();
  410. i != eoi; ++i) {
  411. if(::bind(fd, &(*i).first.sa, (*i).second) == -1) {
  412. errNum = SOCKET_ERRNO;
  413. error = errorMsg(errNum);
  414. A2_LOG_DEBUG(fmt(EX_SOCKET_BIND, error.c_str()));
  415. } else {
  416. bindSuccess = true;
  417. break;
  418. }
  419. }
  420. if(!bindSuccess) {
  421. CLOSE(fd);
  422. continue;
  423. }
  424. }
  425. sockfd_ = fd;
  426. // make socket non-blocking mode
  427. setNonBlockingMode();
  428. setTcpNodelay(true);
  429. if(connect(fd, rp->ai_addr, rp->ai_addrlen) == -1 &&
  430. SOCKET_ERRNO != A2_EINPROGRESS) {
  431. errNum = SOCKET_ERRNO;
  432. error = errorMsg(errNum);
  433. CLOSE(sockfd_);
  434. sockfd_ = (sock_t) -1;
  435. continue;
  436. }
  437. // TODO at this point, connection may not be established and it may fail
  438. // later. In such case, next ai_addr should be tried.
  439. break;
  440. }
  441. if(sockfd_ == (sock_t) -1) {
  442. throw DL_ABORT_EX(fmt(EX_SOCKET_CONNECT, host.c_str(), error.c_str()));
  443. }
  444. }
  445. void SocketCore::setSockOpt
  446. (int level, int optname, void* optval, socklen_t optlen)
  447. {
  448. if(setsockopt(sockfd_, level, optname, (a2_sockopt_t)optval, optlen) < 0) {
  449. int errNum = SOCKET_ERRNO;
  450. throw DL_ABORT_EX(fmt(EX_SOCKET_SET_OPT, errorMsg(errNum).c_str()));
  451. }
  452. }
  453. void SocketCore::setMulticastInterface(const std::string& localAddr)
  454. {
  455. in_addr addr;
  456. if(localAddr.empty()) {
  457. addr.s_addr = htonl(INADDR_ANY);
  458. } else {
  459. if(inetPton(AF_INET, localAddr.c_str(), &addr) != 0) {
  460. throw DL_ABORT_EX(fmt("%s is not valid IPv4 numeric address",
  461. localAddr.c_str()));
  462. }
  463. }
  464. setSockOpt(IPPROTO_IP, IP_MULTICAST_IF, &addr, sizeof(addr));
  465. }
  466. void SocketCore::setMulticastTtl(unsigned char ttl)
  467. {
  468. setSockOpt(IPPROTO_IP, IP_MULTICAST_TTL, &ttl, sizeof(ttl));
  469. }
  470. void SocketCore::setMulticastLoop(unsigned char loop)
  471. {
  472. setSockOpt(IPPROTO_IP, IP_MULTICAST_LOOP, &loop, sizeof(loop));
  473. }
  474. void SocketCore::joinMulticastGroup
  475. (const std::string& multicastAddr, uint16_t multicastPort,
  476. const std::string& localAddr)
  477. {
  478. in_addr multiAddr;
  479. if(inetPton(AF_INET, multicastAddr.c_str(), &multiAddr) != 0) {
  480. throw DL_ABORT_EX(fmt("%s is not valid IPv4 numeric address",
  481. multicastAddr.c_str()));
  482. }
  483. in_addr ifAddr;
  484. if(localAddr.empty()) {
  485. ifAddr.s_addr = htonl(INADDR_ANY);
  486. } else {
  487. if(inetPton(AF_INET, localAddr.c_str(), &ifAddr) != 0) {
  488. throw DL_ABORT_EX(fmt("%s is not valid IPv4 numeric address",
  489. localAddr.c_str()));
  490. }
  491. }
  492. struct ip_mreq mreq;
  493. memset(&mreq, 0, sizeof(mreq));
  494. mreq.imr_multiaddr = multiAddr;
  495. mreq.imr_interface = ifAddr;
  496. setSockOpt(IPPROTO_IP, IP_ADD_MEMBERSHIP, &mreq, sizeof(mreq));
  497. }
  498. void SocketCore::setTcpNodelay(bool f)
  499. {
  500. int val = f;
  501. setSockOpt(IPPROTO_TCP, TCP_NODELAY, &val, sizeof(val));
  502. }
  503. void SocketCore::setNonBlockingMode()
  504. {
  505. #ifdef __MINGW32__
  506. static u_long flag = 1;
  507. if (::ioctlsocket(sockfd_, FIONBIO, &flag) == -1) {
  508. int errNum = SOCKET_ERRNO;
  509. throw DL_ABORT_EX(fmt(EX_SOCKET_NONBLOCKING, errorMsg(errNum).c_str()));
  510. }
  511. #else
  512. int flags;
  513. while((flags = fcntl(sockfd_, F_GETFL, 0)) == -1 && errno == EINTR);
  514. // TODO add error handling
  515. while(fcntl(sockfd_, F_SETFL, flags|O_NONBLOCK) == -1 && errno == EINTR);
  516. #endif // __MINGW32__
  517. blocking_ = false;
  518. }
  519. void SocketCore::setBlockingMode()
  520. {
  521. #ifdef __MINGW32__
  522. static u_long flag = 0;
  523. if (::ioctlsocket(sockfd_, FIONBIO, &flag) == -1) {
  524. int errNum = SOCKET_ERRNO;
  525. throw DL_ABORT_EX(fmt(EX_SOCKET_BLOCKING, errorMsg(errNum).c_str()));
  526. }
  527. #else
  528. int flags;
  529. while((flags = fcntl(sockfd_, F_GETFL, 0)) == -1 && errno == EINTR);
  530. // TODO add error handling
  531. while(fcntl(sockfd_, F_SETFL, flags&(~O_NONBLOCK)) == -1 && errno == EINTR);
  532. #endif // __MINGW32__
  533. blocking_ = true;
  534. }
  535. void SocketCore::closeConnection()
  536. {
  537. #ifdef HAVE_OPENSSL
  538. // for SSL
  539. if(secure_) {
  540. SSL_shutdown(ssl);
  541. }
  542. #endif // HAVE_OPENSSL
  543. #ifdef HAVE_LIBGNUTLS
  544. if(secure_) {
  545. gnutls_bye(sslSession_, GNUTLS_SHUT_WR);
  546. }
  547. #endif // HAVE_LIBGNUTLS
  548. if(sockfd_ != (sock_t) -1) {
  549. shutdown(sockfd_, SHUT_WR);
  550. CLOSE(sockfd_);
  551. sockfd_ = -1;
  552. }
  553. #ifdef HAVE_OPENSSL
  554. // for SSL
  555. if(secure_) {
  556. SSL_free(ssl);
  557. }
  558. #endif // HAVE_OPENSSL
  559. #ifdef HAVE_LIBGNUTLS
  560. if(secure_) {
  561. gnutls_deinit(sslSession_);
  562. }
  563. #endif // HAVE_LIBGNUTLS
  564. }
  565. #ifndef __MINGW32__
  566. # define CHECK_FD(fd) \
  567. if(fd < 0 || FD_SETSIZE <= fd) { \
  568. logger_->warn("Detected file descriptor >= FD_SETSIZE or < 0. " \
  569. "Download may slow down or fail."); \
  570. return false; \
  571. }
  572. #endif // !__MINGW32__
  573. bool SocketCore::isWritable(time_t timeout)
  574. {
  575. #ifdef HAVE_POLL
  576. struct pollfd p;
  577. p.fd = sockfd_;
  578. p.events = POLLOUT;
  579. int r;
  580. while((r = poll(&p, 1, timeout*1000)) == -1 && errno == EINTR);
  581. int errNum = SOCKET_ERRNO;
  582. if(r > 0) {
  583. return p.revents&(POLLOUT|POLLHUP|POLLERR);
  584. } else if(r == 0) {
  585. return false;
  586. } else {
  587. throw DL_RETRY_EX(fmt(EX_SOCKET_CHECK_WRITABLE, errorMsg(errNum).c_str()));
  588. }
  589. #else // !HAVE_POLL
  590. # ifndef __MINGW32__
  591. CHECK_FD(sockfd_);
  592. # endif // !__MINGW32__
  593. fd_set fds;
  594. FD_ZERO(&fds);
  595. FD_SET(sockfd_, &fds);
  596. struct timeval tv;
  597. tv.tv_sec = timeout;
  598. tv.tv_usec = 0;
  599. int r = select(sockfd_+1, NULL, &fds, NULL, &tv);
  600. int errNum = SOCKET_ERRNO;
  601. if(r == 1) {
  602. return true;
  603. } else if(r == 0) {
  604. // time out
  605. return false;
  606. } else {
  607. if(errNum == A2_EINPROGRESS || errNum == A2_EINTR) {
  608. return false;
  609. } else {
  610. throw DL_RETRY_EX
  611. (fmt(EX_SOCKET_CHECK_WRITABLE, errorMsg(errNum).c_str()));
  612. }
  613. }
  614. #endif // !HAVE_POLL
  615. }
  616. bool SocketCore::isReadable(time_t timeout)
  617. {
  618. #ifdef HAVE_POLL
  619. struct pollfd p;
  620. p.fd = sockfd_;
  621. p.events = POLLIN;
  622. int r;
  623. while((r = poll(&p, 1, timeout*1000)) == -1 && errno == EINTR);
  624. int errNum = SOCKET_ERRNO;
  625. if(r > 0) {
  626. return p.revents&(POLLIN|POLLHUP|POLLERR);
  627. } else if(r == 0) {
  628. return false;
  629. } else {
  630. throw DL_RETRY_EX(fmt(EX_SOCKET_CHECK_READABLE, errorMsg(errNum).c_str()));
  631. }
  632. #else // !HAVE_POLL
  633. # ifndef __MINGW32__
  634. CHECK_FD(sockfd_);
  635. # endif // !__MINGW32__
  636. fd_set fds;
  637. FD_ZERO(&fds);
  638. FD_SET(sockfd_, &fds);
  639. struct timeval tv;
  640. tv.tv_sec = timeout;
  641. tv.tv_usec = 0;
  642. int r = select(sockfd_+1, &fds, NULL, NULL, &tv);
  643. int errNum = SOCKET_ERRNO;
  644. if(r == 1) {
  645. return true;
  646. } else if(r == 0) {
  647. // time out
  648. return false;
  649. } else {
  650. if(errNum == A2_EINPROGRESS || errNum == A2_EINTR) {
  651. return false;
  652. } else {
  653. throw DL_RETRY_EX
  654. (fmt(EX_SOCKET_CHECK_READABLE, errorMsg(errNum).c_str()));
  655. }
  656. }
  657. #endif // !HAVE_POLL
  658. }
  659. #ifdef HAVE_OPENSSL
  660. int SocketCore::sslHandleEAGAIN(int ret)
  661. {
  662. int error = SSL_get_error(ssl, ret);
  663. if(error == SSL_ERROR_WANT_READ || error == SSL_ERROR_WANT_WRITE) {
  664. ret = 0;
  665. if(error == SSL_ERROR_WANT_READ) {
  666. wantRead_ = true;
  667. } else {
  668. wantWrite_ = true;
  669. }
  670. }
  671. return ret;
  672. }
  673. #endif // HAVE_OPENSSL
  674. #ifdef HAVE_LIBGNUTLS
  675. void SocketCore::gnutlsRecordCheckDirection()
  676. {
  677. int direction = gnutls_record_get_direction(sslSession_);
  678. if(direction == 0) {
  679. wantRead_ = true;
  680. } else { // if(direction == 1) {
  681. wantWrite_ = true;
  682. }
  683. }
  684. #endif // HAVE_LIBGNUTLS
  685. ssize_t SocketCore::writeData(const char* data, size_t len)
  686. {
  687. ssize_t ret = 0;
  688. wantRead_ = false;
  689. wantWrite_ = false;
  690. if(!secure_) {
  691. while((ret = send(sockfd_, data, len, 0)) == -1 && SOCKET_ERRNO == A2_EINTR);
  692. int errNum = SOCKET_ERRNO;
  693. if(ret == -1) {
  694. if(A2_WOULDBLOCK(errNum)) {
  695. wantWrite_ = true;
  696. ret = 0;
  697. } else {
  698. throw DL_RETRY_EX(fmt(EX_SOCKET_SEND, errorMsg(errNum).c_str()));
  699. }
  700. }
  701. } else {
  702. #ifdef HAVE_OPENSSL
  703. ERR_clear_error();
  704. ret = SSL_write(ssl, data, len);
  705. if(ret < 0) {
  706. ret = sslHandleEAGAIN(ret);
  707. }
  708. if(ret < 0) {
  709. throw DL_RETRY_EX
  710. (fmt(EX_SOCKET_SEND, ERR_error_string(ERR_get_error(), 0)));
  711. }
  712. #endif // HAVE_OPENSSL
  713. #ifdef HAVE_LIBGNUTLS
  714. while((ret = gnutls_record_send(sslSession_, data, len)) ==
  715. GNUTLS_E_INTERRUPTED);
  716. if(ret == GNUTLS_E_AGAIN) {
  717. gnutlsRecordCheckDirection();
  718. ret = 0;
  719. } else if(ret < 0) {
  720. throw DL_RETRY_EX(fmt(EX_SOCKET_SEND, gnutls_strerror(ret)));
  721. }
  722. #endif // HAVE_LIBGNUTLS
  723. }
  724. return ret;
  725. }
  726. void SocketCore::readData(char* data, size_t& len)
  727. {
  728. ssize_t ret = 0;
  729. wantRead_ = false;
  730. wantWrite_ = false;
  731. if(!secure_) {
  732. while((ret = recv(sockfd_, data, len, 0)) == -1 &&
  733. SOCKET_ERRNO == A2_EINTR);
  734. int errNum = SOCKET_ERRNO;
  735. if(ret == -1) {
  736. if(A2_WOULDBLOCK(errNum)) {
  737. wantRead_ = true;
  738. ret = 0;
  739. } else {
  740. throw DL_RETRY_EX(fmt(EX_SOCKET_RECV, errorMsg(errNum).c_str()));
  741. }
  742. }
  743. } else {
  744. #ifdef HAVE_OPENSSL
  745. // for SSL
  746. // TODO handling len == 0 case required
  747. ERR_clear_error();
  748. ret = SSL_read(ssl, data, len);
  749. if(ret < 0) {
  750. ret = sslHandleEAGAIN(ret);
  751. }
  752. if(ret < 0) {
  753. throw DL_RETRY_EX
  754. (fmt(EX_SOCKET_RECV, ERR_error_string(ERR_get_error(), 0)));
  755. }
  756. #endif // HAVE_OPENSSL
  757. #ifdef HAVE_LIBGNUTLS
  758. while((ret = gnutls_record_recv(sslSession_, data, len)) ==
  759. GNUTLS_E_INTERRUPTED);
  760. if(ret == GNUTLS_E_AGAIN) {
  761. gnutlsRecordCheckDirection();
  762. ret = 0;
  763. } else if(ret < 0) {
  764. throw DL_RETRY_EX(fmt(EX_SOCKET_RECV, gnutls_strerror(ret)));
  765. }
  766. #endif // HAVE_LIBGNUTLS
  767. }
  768. len = ret;
  769. }
  770. #ifdef ENABLE_SSL
  771. bool SocketCore::tlsAccept()
  772. {
  773. return tlsHandshake(svTlsContext_.get(), A2STR::NIL);
  774. }
  775. bool SocketCore::tlsConnect(const std::string& hostname)
  776. {
  777. return tlsHandshake(clTlsContext_.get(), hostname);
  778. }
  779. bool SocketCore::tlsHandshake(TLSContext* tlsctx, const std::string& hostname)
  780. {
  781. wantRead_ = false;
  782. wantWrite_ = false;
  783. #ifdef HAVE_OPENSSL
  784. switch(secure_) {
  785. case A2_TLS_NONE:
  786. ssl = SSL_new(tlsctx->getSSLCtx());
  787. if(!ssl) {
  788. throw DL_ABORT_EX
  789. (fmt(EX_SSL_INIT_FAILURE, ERR_error_string(ERR_get_error(), 0)));
  790. }
  791. if(SSL_set_fd(ssl, sockfd_) == 0) {
  792. throw DL_ABORT_EX
  793. (fmt(EX_SSL_INIT_FAILURE, ERR_error_string(ERR_get_error(), 0)));
  794. }
  795. // Fall through
  796. #ifdef SSL_CTRL_SET_TLSEXT_HOSTNAME
  797. if(tlsctx->getSide() == TLS_CLIENT && !util::isNumericHost(hostname)) {
  798. // TLS extensions: SNI. There is not documentation about the
  799. // return code for this function (actually this is macro
  800. // wrapping SSL_ctrl at the time of this writing).
  801. SSL_set_tlsext_host_name(ssl, hostname.c_str());
  802. }
  803. #endif // SSL_CTRL_SET_TLSEXT_HOSTNAME
  804. secure_ = A2_TLS_HANDSHAKING;
  805. // Fall through
  806. case A2_TLS_HANDSHAKING: {
  807. ERR_clear_error();
  808. int e;
  809. if(tlsctx->getSide() == TLS_CLIENT) {
  810. e = SSL_connect(ssl);
  811. } else {
  812. e = SSL_accept(ssl);
  813. }
  814. if (e <= 0) {
  815. int ssl_error = SSL_get_error(ssl, e);
  816. switch(ssl_error) {
  817. case SSL_ERROR_NONE:
  818. break;
  819. case SSL_ERROR_WANT_READ:
  820. wantRead_ = true;
  821. return false;
  822. case SSL_ERROR_WANT_WRITE:
  823. wantWrite_ = true;
  824. return false;
  825. case SSL_ERROR_WANT_X509_LOOKUP:
  826. case SSL_ERROR_ZERO_RETURN:
  827. if (blocking_) {
  828. throw DL_ABORT_EX(fmt(EX_SSL_CONNECT_ERROR, ssl_error));
  829. }
  830. break;
  831. case SSL_ERROR_SYSCALL: {
  832. int sslErr = ERR_get_error();
  833. if(sslErr == 0) {
  834. if(e == 0) {
  835. throw DL_ABORT_EX("Got EOF in SSL handshake");
  836. } else if(e == -1) {
  837. throw DL_ABORT_EX(fmt("SSL I/O error: %s", strerror(errno)));
  838. } else {
  839. throw DL_ABORT_EX(EX_SSL_IO_ERROR);
  840. }
  841. } else {
  842. throw DL_ABORT_EX(fmt("SSL I/O error: %s",
  843. ERR_error_string(sslErr, 0)));
  844. }
  845. }
  846. case SSL_ERROR_SSL:
  847. throw DL_ABORT_EX(EX_SSL_PROTOCOL_ERROR);
  848. default:
  849. throw DL_ABORT_EX(fmt(EX_SSL_UNKNOWN_ERROR, ssl_error));
  850. }
  851. }
  852. if(tlsctx->getSide() == TLS_CLIENT &&
  853. tlsctx->peerVerificationEnabled()) {
  854. // verify peer
  855. X509* peerCert = SSL_get_peer_certificate(ssl);
  856. if(!peerCert) {
  857. throw DL_ABORT_EX(MSG_NO_CERT_FOUND);
  858. }
  859. auto_delete<X509*> certDeleter(peerCert, X509_free);
  860. long verifyResult = SSL_get_verify_result(ssl);
  861. if(verifyResult != X509_V_OK) {
  862. throw DL_ABORT_EX
  863. (fmt(MSG_CERT_VERIFICATION_FAILED,
  864. X509_verify_cert_error_string(verifyResult)));
  865. }
  866. std::string commonName;
  867. std::vector<std::string> dnsNames;
  868. std::vector<std::string> ipAddrs;
  869. GENERAL_NAMES* altNames;
  870. altNames = reinterpret_cast<GENERAL_NAMES*>
  871. (X509_get_ext_d2i(peerCert, NID_subject_alt_name, NULL, NULL));
  872. if(altNames) {
  873. auto_delete<GENERAL_NAMES*> altNamesDeleter
  874. (altNames, GENERAL_NAMES_free);
  875. size_t n = sk_GENERAL_NAME_num(altNames);
  876. for(size_t i = 0; i < n; ++i) {
  877. const GENERAL_NAME* altName = sk_GENERAL_NAME_value(altNames, i);
  878. if(altName->type == GEN_DNS) {
  879. const char* name =
  880. reinterpret_cast<char*>(ASN1_STRING_data(altName->d.ia5));
  881. if(!name) {
  882. continue;
  883. }
  884. size_t len = ASN1_STRING_length(altName->d.ia5);
  885. dnsNames.push_back(std::string(name, len));
  886. } else if(altName->type == GEN_IPADD) {
  887. const unsigned char* ipAddr = altName->d.iPAddress->data;
  888. if(!ipAddr) {
  889. continue;
  890. }
  891. size_t len = altName->d.iPAddress->length;
  892. ipAddrs.push_back(std::string(reinterpret_cast<const char*>(ipAddr),
  893. len));
  894. }
  895. }
  896. }
  897. X509_NAME* subjectName = X509_get_subject_name(peerCert);
  898. if(!subjectName) {
  899. throw DL_ABORT_EX
  900. ("Could not get X509 name object from the certificate.");
  901. }
  902. int lastpos = -1;
  903. while(1) {
  904. lastpos = X509_NAME_get_index_by_NID(subjectName, NID_commonName,
  905. lastpos);
  906. if(lastpos == -1) {
  907. break;
  908. }
  909. X509_NAME_ENTRY* entry = X509_NAME_get_entry(subjectName, lastpos);
  910. unsigned char* out;
  911. int outlen = ASN1_STRING_to_UTF8(&out,
  912. X509_NAME_ENTRY_get_data(entry));
  913. if(outlen < 0) {
  914. continue;
  915. }
  916. commonName.assign(&out[0], &out[outlen]);
  917. OPENSSL_free(out);
  918. break;
  919. }
  920. if(!net::verifyHostname(hostname, dnsNames, ipAddrs, commonName)) {
  921. throw DL_ABORT_EX(MSG_HOSTNAME_NOT_MATCH);
  922. }
  923. }
  924. secure_ = A2_TLS_CONNECTED;
  925. break;
  926. }
  927. default:
  928. break;
  929. }
  930. #endif // HAVE_OPENSSL
  931. #ifdef HAVE_LIBGNUTLS
  932. switch(secure_) {
  933. case A2_TLS_NONE:
  934. int r;
  935. gnutls_init(&sslSession_,
  936. tlsctx->getSide() == TLS_CLIENT ?
  937. GNUTLS_CLIENT : GNUTLS_SERVER);
  938. // It seems err is not error message, but the argument string
  939. // which causes syntax error.
  940. const char* err;
  941. // For client side, disables TLS1.1 here because there are servers
  942. // that don't understand TLS1.1. TODO Is this still necessary?
  943. r = gnutls_priority_set_direct(sslSession_,
  944. tlsctx->getSide() == TLS_CLIENT ?
  945. "NORMAL:-VERS-TLS1.1" :
  946. "NORMAL",
  947. &err);
  948. if(r != GNUTLS_E_SUCCESS) {
  949. throw DL_ABORT_EX(fmt(EX_SSL_INIT_FAILURE, gnutls_strerror(r)));
  950. }
  951. // put the x509 credentials to the current session
  952. gnutls_credentials_set(sslSession_, GNUTLS_CRD_CERTIFICATE,
  953. tlsctx->getCertCred());
  954. gnutls_transport_set_ptr(sslSession_, (gnutls_transport_ptr_t)sockfd_);
  955. if(tlsctx->getSide() == TLS_CLIENT) {
  956. // Check hostname is not numeric and it includes ".". Setting
  957. // "localhost" will produce TLS alert.
  958. if(!util::isNumericHost(hostname) &&
  959. hostname.find(".") != std::string::npos) {
  960. // TLS extensions: SNI
  961. int ret = gnutls_server_name_set(sslSession_, GNUTLS_NAME_DNS,
  962. hostname.c_str(), hostname.size());
  963. if(ret < 0) {
  964. A2_LOG_WARN(fmt
  965. ("Setting hostname in SNI extension failed. Cause: %s",
  966. gnutls_strerror(ret)));
  967. }
  968. }
  969. }
  970. secure_ = A2_TLS_HANDSHAKING;
  971. // Fall through
  972. case A2_TLS_HANDSHAKING: {
  973. int ret = gnutls_handshake(sslSession_);
  974. if(ret == GNUTLS_E_AGAIN) {
  975. gnutlsRecordCheckDirection();
  976. return false;
  977. } else if(ret < 0) {
  978. throw DL_ABORT_EX(fmt(EX_SSL_INIT_FAILURE, gnutls_strerror(ret)));
  979. }
  980. if(tlsctx->getSide() == TLS_CLIENT && tlsctx->peerVerificationEnabled()) {
  981. // verify peer
  982. unsigned int status;
  983. ret = gnutls_certificate_verify_peers2(sslSession_, &status);
  984. if(ret < 0) {
  985. throw DL_ABORT_EX
  986. (fmt("gnutls_certificate_verify_peer2() failed. Cause: %s",
  987. gnutls_strerror(ret)));
  988. }
  989. if(status) {
  990. std::string errors;
  991. if(status & GNUTLS_CERT_INVALID) {
  992. errors += " `not signed by known authorities or invalid'";
  993. }
  994. if(status & GNUTLS_CERT_REVOKED) {
  995. errors += " `revoked by its CA'";
  996. }
  997. if(status & GNUTLS_CERT_SIGNER_NOT_FOUND) {
  998. errors += " `issuer is not known'";
  999. }
  1000. // TODO should check GNUTLS_CERT_SIGNER_NOT_CA ?
  1001. if(status & GNUTLS_CERT_INSECURE_ALGORITHM) {
  1002. errors += " `insecure algorithm'";
  1003. }
  1004. if(status & GNUTLS_CERT_NOT_ACTIVATED) {
  1005. errors += " `not activated yet'";
  1006. }
  1007. if(status & GNUTLS_CERT_EXPIRED) {
  1008. errors += " `expired'";
  1009. }
  1010. // TODO Add GNUTLS_CERT_SIGNATURE_FAILURE here
  1011. if(!errors.empty()) {
  1012. throw DL_ABORT_EX(fmt(MSG_CERT_VERIFICATION_FAILED, errors.c_str()));
  1013. }
  1014. }
  1015. // certificate type: only X509 is allowed.
  1016. if(gnutls_certificate_type_get(sslSession_) != GNUTLS_CRT_X509) {
  1017. throw DL_ABORT_EX("Certificate type is not X509.");
  1018. }
  1019. unsigned int peerCertsLength;
  1020. const gnutls_datum_t* peerCerts = gnutls_certificate_get_peers
  1021. (sslSession_, &peerCertsLength);
  1022. if(!peerCerts || peerCertsLength == 0 ) {
  1023. throw DL_ABORT_EX(MSG_NO_CERT_FOUND);
  1024. }
  1025. Time now;
  1026. for(unsigned int i = 0; i < peerCertsLength; ++i) {
  1027. gnutls_x509_crt_t cert;
  1028. ret = gnutls_x509_crt_init(&cert);
  1029. if(ret < 0) {
  1030. throw DL_ABORT_EX
  1031. (fmt("gnutls_x509_crt_init() failed. Cause: %s",
  1032. gnutls_strerror(ret)));
  1033. }
  1034. auto_delete<gnutls_x509_crt_t> certDeleter
  1035. (cert, gnutls_x509_crt_deinit);
  1036. ret = gnutls_x509_crt_import(cert, &peerCerts[i], GNUTLS_X509_FMT_DER);
  1037. if(ret < 0) {
  1038. throw DL_ABORT_EX
  1039. (fmt("gnutls_x509_crt_import() failed. Cause: %s",
  1040. gnutls_strerror(ret)));
  1041. }
  1042. if(i == 0) {
  1043. std::string commonName;
  1044. std::vector<std::string> dnsNames;
  1045. std::vector<std::string> ipAddrs;
  1046. int ret = 0;
  1047. char altName[256];
  1048. size_t altNameLen;
  1049. for(int j = 0; !(ret < 0); ++j) {
  1050. altNameLen = sizeof(altName);
  1051. ret = gnutls_x509_crt_get_subject_alt_name(cert, j, altName,
  1052. &altNameLen, 0);
  1053. if(ret == GNUTLS_SAN_DNSNAME) {
  1054. dnsNames.push_back(std::string(altName, altNameLen));
  1055. } else if(ret == GNUTLS_SAN_IPADDRESS) {
  1056. ipAddrs.push_back(std::string(altName, altNameLen));
  1057. }
  1058. }
  1059. altNameLen = sizeof(altName);
  1060. ret = gnutls_x509_crt_get_dn_by_oid(cert,
  1061. GNUTLS_OID_X520_COMMON_NAME, 0, 0,
  1062. altName, &altNameLen);
  1063. if(ret == 0) {
  1064. commonName.assign(altName, altNameLen);
  1065. }
  1066. if(!net::verifyHostname(hostname, dnsNames, ipAddrs, commonName)) {
  1067. throw DL_ABORT_EX(MSG_HOSTNAME_NOT_MATCH);
  1068. }
  1069. }
  1070. time_t activationTime = gnutls_x509_crt_get_activation_time(cert);
  1071. if(activationTime == -1) {
  1072. throw DL_ABORT_EX("Could not get activation time from certificate.");
  1073. }
  1074. if(now.getTime() < activationTime) {
  1075. throw DL_ABORT_EX("Certificate is not activated yet.");
  1076. }
  1077. time_t expirationTime = gnutls_x509_crt_get_expiration_time(cert);
  1078. if(expirationTime == -1) {
  1079. throw DL_ABORT_EX("Could not get expiration time from certificate.");
  1080. }
  1081. if(expirationTime < now.getTime()) {
  1082. throw DL_ABORT_EX("Certificate has expired.");
  1083. }
  1084. }
  1085. }
  1086. secure_ = A2_TLS_CONNECTED;
  1087. break;
  1088. }
  1089. default:
  1090. break;
  1091. }
  1092. #endif // HAVE_LIBGNUTLS
  1093. return true;
  1094. }
  1095. #endif // ENABLE_SSL
  1096. ssize_t SocketCore::writeData(const char* data, size_t len,
  1097. const std::string& host, uint16_t port)
  1098. {
  1099. wantRead_ = false;
  1100. wantWrite_ = false;
  1101. struct addrinfo* res;
  1102. int s;
  1103. s = callGetaddrinfo(&res, host.c_str(), util::uitos(port).c_str(),
  1104. protocolFamily_, sockType_, 0, 0);
  1105. if(s) {
  1106. throw DL_ABORT_EX(fmt(EX_SOCKET_SEND, gai_strerror(s)));
  1107. }
  1108. WSAAPI_AUTO_DELETE<struct addrinfo*> resDeleter(res, freeaddrinfo);
  1109. struct addrinfo* rp;
  1110. ssize_t r = -1;
  1111. int errNum = 0;
  1112. for(rp = res; rp; rp = rp->ai_next) {
  1113. while((r = sendto(sockfd_, data, len, 0, rp->ai_addr, rp->ai_addrlen)) == -1
  1114. && A2_EINTR == SOCKET_ERRNO);
  1115. errNum = SOCKET_ERRNO;
  1116. if(r == static_cast<ssize_t>(len)) {
  1117. break;
  1118. }
  1119. if(r == -1 && A2_WOULDBLOCK(errNum)) {
  1120. wantWrite_ = true;
  1121. r = 0;
  1122. break;
  1123. }
  1124. }
  1125. if(r == -1) {
  1126. throw DL_ABORT_EX(fmt(EX_SOCKET_SEND, errorMsg(errNum).c_str()));
  1127. }
  1128. return r;
  1129. }
  1130. ssize_t SocketCore::readDataFrom(char* data, size_t len,
  1131. std::pair<std::string /* numerichost */,
  1132. uint16_t /* port */>& sender)
  1133. {
  1134. wantRead_ = false;
  1135. wantWrite_ = false;
  1136. sockaddr_union sockaddr;
  1137. socklen_t sockaddrlen = sizeof(sockaddr);
  1138. ssize_t r;
  1139. while((r = recvfrom(sockfd_, data, len, 0, &sockaddr.sa, &sockaddrlen)) == -1
  1140. && A2_EINTR == SOCKET_ERRNO);
  1141. int errNum = SOCKET_ERRNO;
  1142. if(r == -1) {
  1143. if(A2_WOULDBLOCK(errNum)) {
  1144. wantRead_ = true;
  1145. r = 0;
  1146. } else {
  1147. throw DL_RETRY_EX(fmt(EX_SOCKET_RECV, errorMsg(errNum).c_str()));
  1148. }
  1149. } else {
  1150. sender = util::getNumericNameInfo(&sockaddr.sa, sockaddrlen);
  1151. }
  1152. return r;
  1153. }
  1154. std::string SocketCore::getSocketError() const
  1155. {
  1156. int error;
  1157. socklen_t optlen = sizeof(error);
  1158. if(getsockopt(sockfd_, SOL_SOCKET, SO_ERROR,
  1159. (a2_sockopt_t) &error, &optlen) == -1) {
  1160. int errNum = SOCKET_ERRNO;
  1161. throw DL_ABORT_EX
  1162. (fmt("Failed to get socket error: %s", errorMsg(errNum).c_str()));
  1163. }
  1164. if(error != 0) {
  1165. return errorMsg(error);
  1166. } else {
  1167. return "";
  1168. }
  1169. }
  1170. bool SocketCore::wantRead() const
  1171. {
  1172. return wantRead_;
  1173. }
  1174. bool SocketCore::wantWrite() const
  1175. {
  1176. return wantWrite_;
  1177. }
  1178. void SocketCore::bindAddress(const std::string& iface)
  1179. {
  1180. std::vector<std::pair<sockaddr_union, socklen_t> > bindAddrs;
  1181. getInterfaceAddress(bindAddrs, iface, protocolFamily_);
  1182. if(bindAddrs.empty()) {
  1183. throw DL_ABORT_EX
  1184. (fmt(MSG_INTERFACE_NOT_FOUND, iface.c_str(), "not available"));
  1185. } else {
  1186. bindAddrs_.swap(bindAddrs);
  1187. for(std::vector<std::pair<sockaddr_union, socklen_t> >::
  1188. const_iterator i = bindAddrs_.begin(), eoi = bindAddrs_.end();
  1189. i != eoi; ++i) {
  1190. char host[NI_MAXHOST];
  1191. int s;
  1192. s = getnameinfo(&(*i).first.sa, (*i).second, host, NI_MAXHOST, 0, 0,
  1193. NI_NUMERICHOST);
  1194. if(s == 0) {
  1195. A2_LOG_DEBUG(fmt("Sockets will bind to %s", host));
  1196. }
  1197. }
  1198. }
  1199. }
  1200. void getInterfaceAddress
  1201. (std::vector<std::pair<sockaddr_union, socklen_t> >& ifAddrs,
  1202. const std::string& iface, int family, int aiFlags)
  1203. {
  1204. A2_LOG_DEBUG(fmt("Finding interface %s", iface.c_str()));
  1205. #ifdef HAVE_GETIFADDRS
  1206. // First find interface in interface addresses
  1207. struct ifaddrs* ifaddr = 0;
  1208. if(getifaddrs(&ifaddr) == -1) {
  1209. int errNum = SOCKET_ERRNO;
  1210. A2_LOG_INFO(fmt(MSG_INTERFACE_NOT_FOUND,
  1211. iface.c_str(), errorMsg(errNum).c_str()));
  1212. } else {
  1213. auto_delete<ifaddrs*> ifaddrDeleter(ifaddr, freeifaddrs);
  1214. for(ifaddrs* ifa = ifaddr; ifa; ifa = ifa->ifa_next) {
  1215. if(!ifa->ifa_addr) {
  1216. continue;
  1217. }
  1218. int iffamily = ifa->ifa_addr->sa_family;
  1219. if(family == AF_UNSPEC) {
  1220. if(iffamily != AF_INET && iffamily != AF_INET6) {
  1221. continue;
  1222. }
  1223. } else if(family == AF_INET) {
  1224. if(iffamily != AF_INET) {
  1225. continue;
  1226. }
  1227. } else if(family == AF_INET6) {
  1228. if(iffamily != AF_INET6) {
  1229. continue;
  1230. }
  1231. } else {
  1232. continue;
  1233. }
  1234. if(strcmp(iface.c_str(), ifa->ifa_name) == 0) {
  1235. socklen_t bindAddrLen =
  1236. iffamily == AF_INET ? sizeof(sockaddr_in) : sizeof(sockaddr_in6);
  1237. sockaddr_union bindAddr;
  1238. memset(&bindAddr, 0, sizeof(bindAddr));
  1239. memcpy(&bindAddr.storage, ifa->ifa_addr, bindAddrLen);
  1240. ifAddrs.push_back(std::make_pair(bindAddr, bindAddrLen));
  1241. }
  1242. }
  1243. }
  1244. #endif // HAVE_GETIFADDRS
  1245. if(ifAddrs.empty()) {
  1246. addrinfo* res;
  1247. int s;
  1248. s = callGetaddrinfo(&res, iface.c_str(), 0, family, SOCK_STREAM, aiFlags,0);
  1249. if(s) {
  1250. A2_LOG_INFO(fmt(MSG_INTERFACE_NOT_FOUND, iface.c_str(), gai_strerror(s)));
  1251. } else {
  1252. WSAAPI_AUTO_DELETE<addrinfo*> resDeleter(res, freeaddrinfo);
  1253. addrinfo* rp;
  1254. for(rp = res; rp; rp = rp->ai_next) {
  1255. // Try to bind socket with this address. If it fails, the
  1256. // address is not for this machine.
  1257. try {
  1258. SocketCore socket;
  1259. socket.bind(rp->ai_addr, rp->ai_addrlen);
  1260. sockaddr_union bindAddr;
  1261. memset(&bindAddr, 0, sizeof(bindAddr));
  1262. memcpy(&bindAddr.storage, rp->ai_addr, rp->ai_addrlen);
  1263. ifAddrs.push_back(std::make_pair(bindAddr, rp->ai_addrlen));
  1264. } catch(RecoverableException& e) {
  1265. continue;
  1266. }
  1267. }
  1268. }
  1269. }
  1270. }
  1271. namespace {
  1272. int defaultAIFlags = DEFAULT_AI_FLAGS;
  1273. int getDefaultAIFlags()
  1274. {
  1275. return defaultAIFlags;
  1276. }
  1277. } // namespace
  1278. void setDefaultAIFlags(int flags)
  1279. {
  1280. defaultAIFlags = flags;
  1281. }
  1282. int callGetaddrinfo
  1283. (struct addrinfo** resPtr, const char* host, const char* service, int family,
  1284. int sockType, int flags, int protocol)
  1285. {
  1286. struct addrinfo hints;
  1287. memset(&hints, 0, sizeof(hints));
  1288. hints.ai_family = family;
  1289. hints.ai_socktype = sockType;
  1290. hints.ai_flags = getDefaultAIFlags();
  1291. hints.ai_flags |= flags;
  1292. hints.ai_protocol = protocol;
  1293. return getaddrinfo(host, service, &hints, resPtr);
  1294. }
  1295. int inetNtop(int af, const void* src, char* dst, socklen_t size)
  1296. {
  1297. int s;
  1298. sockaddr_union su;
  1299. memset(&su, 0, sizeof(su));
  1300. if(af == AF_INET) {
  1301. su.in.sin_family = AF_INET;
  1302. #ifdef HAVE_SOCKADDR_IN_SIN_LEN
  1303. su.in.sin_len = sizeof(su.in);
  1304. #endif // HAVE_SOCKADDR_IN_SIN_LEN
  1305. memcpy(&su.in.sin_addr, src, sizeof(su.in.sin_addr));
  1306. s = getnameinfo(&su.sa, sizeof(su.in),
  1307. dst, size, 0, 0, NI_NUMERICHOST);
  1308. } else if(af == AF_INET6) {
  1309. su.in6.sin6_family = AF_INET6;
  1310. #ifdef HAVE_SOCKADDR_IN6_SIN6_LEN
  1311. su.in6.sin6_len = sizeof(su.in6);
  1312. #endif // HAVE_SOCKADDR_IN6_SIN6_LEN
  1313. memcpy(&su.in6.sin6_addr, src, sizeof(su.in6.sin6_addr));
  1314. s = getnameinfo(&su.sa, sizeof(su.in6),
  1315. dst, size, 0, 0, NI_NUMERICHOST);
  1316. } else {
  1317. s = EAI_FAMILY;
  1318. }
  1319. return s;
  1320. }
  1321. int inetPton(int af, const char* src, void* dst)
  1322. {
  1323. union {
  1324. uint32_t ipv4_addr;
  1325. unsigned char ipv6_addr[16];
  1326. } binaddr;
  1327. size_t len = net::getBinAddr(binaddr.ipv6_addr, src);
  1328. if(af == AF_INET) {
  1329. if(len != 4) {
  1330. return -1;
  1331. }
  1332. in_addr* addr = reinterpret_cast<in_addr*>(dst);
  1333. addr->s_addr = binaddr.ipv4_addr;
  1334. } else if(af == AF_INET6) {
  1335. if(len != 16) {
  1336. return -1;
  1337. }
  1338. in6_addr* addr = reinterpret_cast<in6_addr*>(dst);
  1339. memcpy(addr->s6_addr, binaddr.ipv6_addr, sizeof(addr->s6_addr));
  1340. } else {
  1341. return -1;
  1342. }
  1343. return 0;
  1344. }
  1345. namespace net {
  1346. size_t getBinAddr(void* dest, const std::string& ip)
  1347. {
  1348. size_t len = 0;
  1349. addrinfo* res;
  1350. if(callGetaddrinfo(&res, ip.c_str(), 0, AF_UNSPEC,
  1351. 0, AI_NUMERICHOST, 0) != 0) {
  1352. return len;
  1353. }
  1354. WSAAPI_AUTO_DELETE<addrinfo*> resDeleter(res, freeaddrinfo);
  1355. for(addrinfo* rp = res; rp; rp = rp->ai_next) {
  1356. sockaddr_union su;
  1357. memcpy(&su, rp->ai_addr, rp->ai_addrlen);
  1358. if(rp->ai_family == AF_INET) {
  1359. len = sizeof(in_addr);
  1360. memcpy(dest, &(su.in.sin_addr), len);
  1361. break;
  1362. } else if(rp->ai_family == AF_INET6) {
  1363. len = sizeof(in6_addr);
  1364. memcpy(dest, &(su.in6.sin6_addr), len);
  1365. break;
  1366. }
  1367. }
  1368. return len;
  1369. }
  1370. bool verifyHostname(const std::string& hostname,
  1371. const std::vector<std::string>& dnsNames,
  1372. const std::vector<std::string>& ipAddrs,
  1373. const std::string& commonName)
  1374. {
  1375. if(util::isNumericHost(hostname)) {
  1376. if(ipAddrs.empty()) {
  1377. return commonName == hostname;
  1378. }
  1379. // We need max 16 bytes to store IPv6 address.
  1380. unsigned char binAddr[16];
  1381. size_t addrLen = getBinAddr(binAddr, hostname);
  1382. if(addrLen == 0) {
  1383. return false;
  1384. }
  1385. for(std::vector<std::string>::const_iterator i = ipAddrs.begin(),
  1386. eoi = ipAddrs.end(); i != eoi; ++i) {
  1387. if(addrLen == (*i).size() &&
  1388. memcmp(binAddr, (*i).c_str(), addrLen) == 0) {
  1389. return true;
  1390. }
  1391. }
  1392. } else {
  1393. if(dnsNames.empty()) {
  1394. return util::tlsHostnameMatch(commonName, hostname);
  1395. }
  1396. for(std::vector<std::string>::const_iterator i = dnsNames.begin(),
  1397. eoi = dnsNames.end(); i != eoi; ++i) {
  1398. if(util::tlsHostnameMatch(*i, hostname)) {
  1399. return true;
  1400. }
  1401. }
  1402. }
  1403. return false;
  1404. }
  1405. } // namespace net
  1406. } // namespace aria2