Path: blob/a-new-beginning/SharedDependencies/Sources/libslirp/socket.c
2 views
/* SPDX-License-Identifier: BSD-3-Clause */1/*2* Copyright (c) 1995 Danny Gasparovski.3*/45#include "slirp.h"6#include "ip_icmp.h"7#ifdef __sun__8#include <sys/filio.h>9#endif10#ifdef __linux__11#include <linux/errqueue.h>12#endif1314static void sofcantrcvmore(struct socket *so);15static void sofcantsendmore(struct socket *so);1617struct socket *solookup(struct socket **last, struct socket *head,18struct sockaddr_storage *lhost,19struct sockaddr_storage *fhost)20{21struct socket *so = *last;2223/* Optimisation */24if (so != head && sockaddr_equal(&(so->lhost.ss), lhost) &&25(!fhost || sockaddr_equal(&so->fhost.ss, fhost))) {26return so;27}2829for (so = head->so_next; so != head; so = so->so_next) {30if (sockaddr_equal(&(so->lhost.ss), lhost) &&31(!fhost || sockaddr_equal(&so->fhost.ss, fhost))) {32*last = so;33return so;34}35}3637return (struct socket *)NULL;38}3940/*41* Create a new socket, initialise the fields42* It is the responsibility of the caller to43* slirp_insque() it into the correct linked-list44*/45struct socket *socreate(Slirp *slirp, int type)46{47struct socket *so = g_new(struct socket, 1);4849memset(so, 0, sizeof(struct socket));50so->so_type = type;51so->so_state = SS_NOFDREF;52so->s = -1;53so->s_aux = -1;54so->slirp = slirp;55so->pollfds_idx = -1;5657return so;58}5960/*61* Remove references to so from the given message queue.62*/63static void soqfree(struct socket *so, struct slirp_quehead *qh)64{65struct mbuf *ifq;6667for (ifq = (struct mbuf *)qh->qh_link; (struct slirp_quehead *)ifq != qh;68ifq = ifq->m_next) {69if (ifq->m_so == so) {70struct mbuf *ifm;71ifq->m_so = NULL;72for (ifm = ifq->m_nextpkt; ifm != ifq; ifm = ifm->m_nextpkt) {73ifm->m_so = NULL;74}75}76}77}7879/*80* slirp_remque and free a socket, clobber cache81*/82void sofree(struct socket *so)83{84Slirp *slirp = so->slirp;8586if (so->s_aux != -1) {87closesocket(so->s_aux);88}8990soqfree(so, &slirp->if_fastq);91soqfree(so, &slirp->if_batchq);9293if (so == slirp->tcp_last_so) {94slirp->tcp_last_so = &slirp->tcb;95} else if (so == slirp->udp_last_so) {96slirp->udp_last_so = &slirp->udb;97} else if (so == slirp->icmp_last_so) {98slirp->icmp_last_so = &slirp->icmp;99}100m_free(so->so_m);101102if (so->so_next && so->so_prev)103slirp_remque(so); /* crashes if so is not in a queue */104105if (so->so_tcpcb) {106g_free(so->so_tcpcb);107}108g_free(so);109}110111size_t sopreprbuf(struct socket *so, struct iovec *iov, int *np)112{113int n, lss, total;114struct sbuf *sb = &so->so_snd;115int len = sb->sb_datalen - sb->sb_cc;116int mss = so->so_tcpcb->t_maxseg;117118DEBUG_CALL("sopreprbuf");119DEBUG_ARG("so = %p", so);120121if (len <= 0)122return 0;123124iov[0].iov_base = sb->sb_wptr;125iov[1].iov_base = NULL;126iov[1].iov_len = 0;127if (sb->sb_wptr < sb->sb_rptr) {128iov[0].iov_len = sb->sb_rptr - sb->sb_wptr;129/* Should never succeed, but... */130if (iov[0].iov_len > len)131iov[0].iov_len = len;132if (iov[0].iov_len > mss)133iov[0].iov_len -= iov[0].iov_len % mss;134n = 1;135} else {136iov[0].iov_len = (sb->sb_data + sb->sb_datalen) - sb->sb_wptr;137/* Should never succeed, but... */138if (iov[0].iov_len > len)139iov[0].iov_len = len;140len -= iov[0].iov_len;141if (len) {142iov[1].iov_base = sb->sb_data;143iov[1].iov_len = sb->sb_rptr - sb->sb_data;144if (iov[1].iov_len > len)145iov[1].iov_len = len;146total = iov[0].iov_len + iov[1].iov_len;147if (total > mss) {148lss = total % mss;149if (iov[1].iov_len > lss) {150iov[1].iov_len -= lss;151n = 2;152} else {153lss -= iov[1].iov_len;154iov[0].iov_len -= lss;155n = 1;156}157} else158n = 2;159} else {160if (iov[0].iov_len > mss)161iov[0].iov_len -= iov[0].iov_len % mss;162n = 1;163}164}165if (np)166*np = n;167168return iov[0].iov_len + (n - 1) * iov[1].iov_len;169}170171/*172* Read from so's socket into sb_snd, updating all relevant sbuf fields173* NOTE: This will only be called if it is select()ed for reading, so174* a read() of 0 (or less) means it's disconnected175*/176int soread(struct socket *so)177{178int n, nn;179size_t buf_len;180struct sbuf *sb = &so->so_snd;181struct iovec iov[2];182183DEBUG_CALL("soread");184DEBUG_ARG("so = %p", so);185186/*187* No need to check if there's enough room to read.188* soread wouldn't have been called if there weren't189*/190buf_len = sopreprbuf(so, iov, &n);191assert(buf_len != 0);192193nn = recv(so->s, iov[0].iov_base, iov[0].iov_len, 0);194if (nn <= 0) {195if (nn < 0 && (errno == EINTR || errno == EAGAIN))196return 0;197else {198int err;199socklen_t elen = sizeof err;200struct sockaddr_storage addr;201struct sockaddr *paddr = (struct sockaddr *)&addr;202socklen_t alen = sizeof addr;203204err = errno;205if (nn == 0) {206int shutdown_wr = so->so_state & SS_FCANTSENDMORE;207208if (!shutdown_wr && getpeername(so->s, paddr, &alen) < 0) {209err = errno;210} else {211getsockopt(so->s, SOL_SOCKET, SO_ERROR, &err, &elen);212}213}214215DEBUG_MISC(" --- soread() disconnected, nn = %d, errno = %d-%s", nn,216errno, strerror(errno));217sofcantrcvmore(so);218219if (err == ECONNABORTED || err == ECONNRESET || err == ECONNREFUSED ||220err == ENOTCONN || err == EPIPE) {221tcp_drop(sototcpcb(so), err);222} else {223tcp_sockclosed(sototcpcb(so));224}225return -1;226}227}228229/*230* If there was no error, try and read the second time round231* We read again if n = 2 (ie, there's another part of the buffer)232* and we read as much as we could in the first read233* We don't test for <= 0 this time, because there legitimately234* might not be any more data (since the socket is non-blocking),235* a close will be detected on next iteration.236* A return of -1 won't (shouldn't) happen, since it didn't happen above237*/238if (n == 2 && nn == iov[0].iov_len) {239int ret;240ret = recv(so->s, iov[1].iov_base, iov[1].iov_len, 0);241if (ret > 0)242nn += ret;243}244245DEBUG_MISC(" ... read nn = %d bytes", nn);246247/* Update fields */248sb->sb_cc += nn;249sb->sb_wptr += nn;250if (sb->sb_wptr >= (sb->sb_data + sb->sb_datalen))251sb->sb_wptr -= sb->sb_datalen;252return nn;253}254255int soreadbuf(struct socket *so, const char *buf, int size)256{257int n, nn, copy = size;258struct sbuf *sb = &so->so_snd;259struct iovec iov[2];260261DEBUG_CALL("soreadbuf");262DEBUG_ARG("so = %p", so);263264/*265* No need to check if there's enough room to read.266* soread wouldn't have been called if there weren't267*/268assert(size > 0);269if (sopreprbuf(so, iov, &n) < size)270goto err;271272nn = MIN(iov[0].iov_len, copy);273memcpy(iov[0].iov_base, buf, nn);274275copy -= nn;276buf += nn;277278if (copy == 0)279goto done;280281memcpy(iov[1].iov_base, buf, copy);282283done:284/* Update fields */285sb->sb_cc += size;286sb->sb_wptr += size;287if (sb->sb_wptr >= (sb->sb_data + sb->sb_datalen))288sb->sb_wptr -= sb->sb_datalen;289return size;290err:291292sofcantrcvmore(so);293tcp_sockclosed(sototcpcb(so));294g_critical("soreadbuf buffer too small");295return -1;296}297298/*299* Get urgent data300*301* When the socket is created, we set it SO_OOBINLINE,302* so when OOB data arrives, we soread() it and everything303* in the send buffer is sent as urgent data304*/305int sorecvoob(struct socket *so)306{307struct tcpcb *tp = sototcpcb(so);308int ret;309310DEBUG_CALL("sorecvoob");311DEBUG_ARG("so = %p", so);312313/*314* We take a guess at how much urgent data has arrived.315* In most situations, when urgent data arrives, the next316* read() should get all the urgent data. This guess will317* be wrong however if more data arrives just after the318* urgent data, or the read() doesn't return all the319* urgent data.320*/321ret = soread(so);322if (ret > 0) {323tp->snd_up = tp->snd_una + so->so_snd.sb_cc;324tp->t_force = 1;325tcp_output(tp);326tp->t_force = 0;327}328329return ret;330}331332/*333* Send urgent data334* There's a lot duplicated code here, but...335*/336int sosendoob(struct socket *so)337{338struct sbuf *sb = &so->so_rcv;339char buff[2048]; /* XXX Shouldn't be sending more oob data than this */340341int n;342343DEBUG_CALL("sosendoob");344DEBUG_ARG("so = %p", so);345DEBUG_ARG("sb->sb_cc = %d", sb->sb_cc);346347if (so->so_urgc > sizeof(buff))348so->so_urgc = sizeof(buff); /* XXXX */349350if (sb->sb_rptr < sb->sb_wptr) {351/* We can send it directly */352n = slirp_send(so, sb->sb_rptr, so->so_urgc,353(MSG_OOB)); /* |MSG_DONTWAIT)); */354} else {355/*356* Since there's no sendv or sendtov like writev,357* we must copy all data to a linear buffer then358* send it all359*/360uint32_t urgc = so->so_urgc; /* Amount of room left in buff */361int len = (sb->sb_data + sb->sb_datalen) - sb->sb_rptr;362if (len > urgc) {363len = urgc;364}365memcpy(buff, sb->sb_rptr, len);366urgc -= len;367if (urgc) {368/* We still have some room for the rest */369n = sb->sb_wptr - sb->sb_data;370if (n > urgc) {371n = urgc;372}373memcpy((buff + len), sb->sb_data, n);374len += n;375}376n = slirp_send(so, buff, len, (MSG_OOB)); /* |MSG_DONTWAIT)); */377#ifdef SLIRP_DEBUG378if (n != len) {379DEBUG_ERROR("Didn't send all data urgently XXXXX");380}381#endif382}383384if (n < 0) {385return n;386}387so->so_urgc -= n;388DEBUG_MISC(" ---2 sent %d bytes urgent data, %d urgent bytes left", n,389so->so_urgc);390391sb->sb_cc -= n;392sb->sb_rptr += n;393if (sb->sb_rptr >= (sb->sb_data + sb->sb_datalen))394sb->sb_rptr -= sb->sb_datalen;395396return n;397}398399/*400* Write data from so_rcv to so's socket,401* updating all sbuf field as necessary402*/403int sowrite(struct socket *so)404{405int n, nn;406struct sbuf *sb = &so->so_rcv;407int len = sb->sb_cc;408struct iovec iov[2];409410DEBUG_CALL("sowrite");411DEBUG_ARG("so = %p", so);412413if (so->so_urgc) {414uint32_t expected = so->so_urgc;415if (sosendoob(so) < expected) {416/* Treat a short write as a fatal error too,417* rather than continuing on and sending the urgent418* data as if it were non-urgent and leaving the419* so_urgc count wrong.420*/421goto err_disconnected;422}423if (sb->sb_cc == 0)424return 0;425}426427/*428* No need to check if there's something to write,429* sowrite wouldn't have been called otherwise430*/431432iov[0].iov_base = sb->sb_rptr;433iov[1].iov_base = NULL;434iov[1].iov_len = 0;435if (sb->sb_rptr < sb->sb_wptr) {436iov[0].iov_len = sb->sb_wptr - sb->sb_rptr;437/* Should never succeed, but... */438if (iov[0].iov_len > len)439iov[0].iov_len = len;440n = 1;441} else {442iov[0].iov_len = (sb->sb_data + sb->sb_datalen) - sb->sb_rptr;443if (iov[0].iov_len > len)444iov[0].iov_len = len;445len -= iov[0].iov_len;446if (len) {447iov[1].iov_base = sb->sb_data;448iov[1].iov_len = sb->sb_wptr - sb->sb_data;449if (iov[1].iov_len > len)450iov[1].iov_len = len;451n = 2;452} else453n = 1;454}455/* Check if there's urgent data to send, and if so, send it */456457nn = slirp_send(so, iov[0].iov_base, iov[0].iov_len, 0);458/* This should never happen, but people tell me it does *shrug* */459if (nn < 0 && (errno == EAGAIN || errno == EINTR))460return 0;461462if (nn <= 0) {463goto err_disconnected;464}465466if (n == 2 && nn == iov[0].iov_len) {467int ret;468ret = slirp_send(so, iov[1].iov_base, iov[1].iov_len, 0);469if (ret > 0)470nn += ret;471}472DEBUG_MISC(" ... wrote nn = %d bytes", nn);473474/* Update sbuf */475sb->sb_cc -= nn;476sb->sb_rptr += nn;477if (sb->sb_rptr >= (sb->sb_data + sb->sb_datalen))478sb->sb_rptr -= sb->sb_datalen;479480/*481* If in DRAIN mode, and there's no more data, set482* it CANTSENDMORE483*/484if ((so->so_state & SS_FWDRAIN) && sb->sb_cc == 0)485sofcantsendmore(so);486487return nn;488489err_disconnected:490DEBUG_MISC(" --- sowrite disconnected, so->so_state = %x, errno = %d",491so->so_state, errno);492sofcantsendmore(so);493tcp_sockclosed(sototcpcb(so));494return -1;495}496497/*498* recvfrom() a UDP socket499*/500void sorecvfrom(struct socket *so)501{502struct sockaddr_storage addr;503struct sockaddr_storage saddr, daddr;504socklen_t addrlen = sizeof(struct sockaddr_storage);505char buff[256];506507#ifdef __linux__508ssize_t size;509struct msghdr msg;510struct iovec iov;511char control[1024];512513/* First look for errors */514memset(&msg, 0, sizeof(msg));515msg.msg_name = &saddr;516msg.msg_namelen = sizeof(saddr);517msg.msg_control = control;518msg.msg_controllen = sizeof(control);519iov.iov_base = buff;520iov.iov_len = sizeof(buff);521msg.msg_iov = &iov;522msg.msg_iovlen = 1;523524size = recvmsg(so->s, &msg, MSG_ERRQUEUE);525if (size >= 0) {526struct cmsghdr *cmsg;527for (cmsg = CMSG_FIRSTHDR(&msg); cmsg; cmsg = CMSG_NXTHDR(&msg, cmsg)) {528529if (cmsg->cmsg_level == IPPROTO_IP &&530cmsg->cmsg_type == IP_RECVERR) {531struct sock_extended_err *ee =532(struct sock_extended_err *) CMSG_DATA(cmsg);533534if (ee->ee_origin == SO_EE_ORIGIN_ICMP) {535/* Got an ICMP error, forward it */536struct sockaddr_in *sin;537538sin = (struct sockaddr_in *) SO_EE_OFFENDER(ee);539icmp_forward_error(so->so_m, ee->ee_type, ee->ee_code,5400, NULL, &sin->sin_addr);541}542}543else if (cmsg->cmsg_level == IPPROTO_IPV6 &&544cmsg->cmsg_type == IPV6_RECVERR) {545struct sock_extended_err *ee =546(struct sock_extended_err *) CMSG_DATA(cmsg);547548if (ee->ee_origin == SO_EE_ORIGIN_ICMP6) {549/* Got an ICMPv6 error, forward it */550struct sockaddr_in6 *sin6;551552sin6 = (struct sockaddr_in6 *) SO_EE_OFFENDER(ee);553icmp6_forward_error(so->so_m, ee->ee_type, ee->ee_code,554&sin6->sin6_addr);555}556}557}558return;559}560#endif561562DEBUG_CALL("sorecvfrom");563DEBUG_ARG("so = %p", so);564565if (so->so_type == IPPROTO_ICMP) { /* This is a "ping" reply */566int len;567568len = recvfrom(so->s, buff, 256, 0, (struct sockaddr *)&addr, &addrlen);569/* XXX Check if reply is "correct"? */570571if (len == -1 || len == 0) {572uint8_t code = ICMP_UNREACH_PORT;573574if (errno == EHOSTUNREACH)575code = ICMP_UNREACH_HOST;576else if (errno == ENETUNREACH)577code = ICMP_UNREACH_NET;578579DEBUG_MISC(" udp icmp rx errno = %d-%s", errno, strerror(errno));580icmp_send_error(so->so_m, ICMP_UNREACH, code, 0, strerror(errno));581} else {582icmp_reflect(so->so_m);583so->so_m = NULL; /* Don't m_free() it again! */584}585/* No need for this socket anymore, udp_detach it */586udp_detach(so);587} else if (so->so_type == IPPROTO_ICMPV6) { /* This is a "ping" reply */588int len;589590len = recvfrom(so->s, buff, 256, 0, (struct sockaddr *)&addr, &addrlen);591/* XXX Check if reply is "correct"? */592593if (len == -1 || len == 0) {594uint8_t code = ICMP6_UNREACH_PORT;595596if (errno == EHOSTUNREACH)597code = ICMP6_UNREACH_ADDRESS;598else if (errno == ENETUNREACH)599code = ICMP6_UNREACH_NO_ROUTE;600601DEBUG_MISC(" udp icmp6 rx errno = %d-%s", errno, strerror(errno));602icmp6_send_error(so->so_m, ICMP_UNREACH, code);603} else {604icmp6_reflect(so->so_m);605so->so_m = NULL; /* Don't m_free() it again! */606}607/* No need for this socket anymore, udp_detach it */608udp_detach(so);609} else { /* A "normal" UDP packet */610struct mbuf *m;611int len;612#ifdef _WIN32613unsigned long n;614#else615int n;616#endif617618if (ioctlsocket(so->s, FIONREAD, &n) != 0) {619DEBUG_MISC(" ioctlsocket errno = %d-%s\n", errno, strerror(errno));620return;621}622623m = m_get(so->slirp);624if (!m) {625return;626}627switch (so->so_ffamily) {628case AF_INET:629m->m_data += IF_MAXLINKHDR + sizeof(struct udpiphdr);630break;631case AF_INET6:632m->m_data +=633IF_MAXLINKHDR + sizeof(struct ip6) + sizeof(struct udphdr);634break;635default:636g_assert_not_reached();637}638639/*640* XXX Shouldn't FIONREAD packets destined for port 53,641* but I don't know the max packet size for DNS lookups642*/643len = M_FREEROOM(m);644/* if (so->so_fport != htons(53)) { */645646if (n > len) {647n = (m->m_data - m->m_dat) + m->m_len + n + 1;648m_inc(m, n);649len = M_FREEROOM(m);650}651/* } */652653m->m_len = recvfrom(so->s, m->m_data, len, 0, (struct sockaddr *)&addr,654&addrlen);655DEBUG_MISC(" did recvfrom %d, errno = %d-%s", m->m_len, errno,656strerror(errno));657if (m->m_len < 0) {658if (errno == ENOTCONN) {659/*660* UDP socket got burnt, e.g. by suspend on iOS. Tear it down661* and let it get re-created if the guest still needs it662*/663udp_detach(so);664} else {665/* Report error as ICMP */666switch (so->so_lfamily) {667uint8_t code;668case AF_INET:669code = ICMP_UNREACH_PORT;670671if (errno == EHOSTUNREACH) {672code = ICMP_UNREACH_HOST;673} else if (errno == ENETUNREACH) {674code = ICMP_UNREACH_NET;675}676677DEBUG_MISC(" rx error, tx icmp ICMP_UNREACH:%i", code);678icmp_send_error(so->so_m, ICMP_UNREACH, code, 0,679strerror(errno));680break;681case AF_INET6:682code = ICMP6_UNREACH_PORT;683684if (errno == EHOSTUNREACH) {685code = ICMP6_UNREACH_ADDRESS;686} else if (errno == ENETUNREACH) {687code = ICMP6_UNREACH_NO_ROUTE;688}689690DEBUG_MISC(" rx error, tx icmp6 ICMP_UNREACH:%i", code);691icmp6_send_error(so->so_m, ICMP6_UNREACH, code);692break;693default:694g_assert_not_reached();695}696m_free(m);697}698} else {699/*700* Hack: domain name lookup will be used the most for UDP,701* and since they'll only be used once there's no need702* for the 4 minute (or whatever) timeout... So we time them703* out much quicker (10 seconds for now...)704*/705if (so->so_expire) {706if (so->so_fport == htons(53))707so->so_expire = curtime + SO_EXPIREFAST;708else709so->so_expire = curtime + SO_EXPIRE;710}711712/*713* If this packet was destined for CTL_ADDR,714* make it look like that's where it came from715*/716saddr = addr;717sotranslate_in(so, &saddr);718719/* Perform lazy guest IP address resolution if needed. */720if (so->so_state & SS_HOSTFWD) {721if (soassign_guest_addr_if_needed(so) < 0) {722DEBUG_MISC(" guest address not available yet");723switch (so->so_lfamily) {724case AF_INET:725icmp_send_error(so->so_m, ICMP_UNREACH,726ICMP_UNREACH_HOST, 0,727"guest address not available yet");728break;729case AF_INET6:730icmp6_send_error(so->so_m, ICMP6_UNREACH,731ICMP6_UNREACH_ADDRESS);732break;733default:734g_assert_not_reached();735}736m_free(m);737return;738}739}740daddr = so->lhost.ss;741742switch (so->so_ffamily) {743case AF_INET:744udp_output(so, m, (struct sockaddr_in *)&saddr,745(struct sockaddr_in *)&daddr, so->so_iptos);746break;747case AF_INET6:748udp6_output(so, m, (struct sockaddr_in6 *)&saddr,749(struct sockaddr_in6 *)&daddr);750break;751default:752g_assert_not_reached();753}754} /* rx error */755} /* if ping packet */756}757758/*759* sendto() a socket760*/761int sosendto(struct socket *so, struct mbuf *m)762{763int ret;764struct sockaddr_storage addr;765766DEBUG_CALL("sosendto");767DEBUG_ARG("so = %p", so);768DEBUG_ARG("m = %p", m);769770addr = so->fhost.ss;771DEBUG_CALL(" sendto()ing)");772if (sotranslate_out(so, &addr) < 0) {773return -1;774}775776/* Don't care what port we get */777ret = sendto(so->s, m->m_data, m->m_len, 0, (struct sockaddr *)&addr,778sockaddr_size(&addr));779if (ret < 0)780return -1;781782/*783* Kill the socket if there's no reply in 4 minutes,784* but only if it's an expirable socket785*/786if (so->so_expire)787so->so_expire = curtime + SO_EXPIRE;788so->so_state &= SS_PERSISTENT_MASK;789so->so_state |= SS_ISFCONNECTED; /* So that it gets select()ed */790return 0;791}792793struct socket *tcpx_listen(Slirp *slirp,794const struct sockaddr *haddr, socklen_t haddrlen,795const struct sockaddr *laddr, socklen_t laddrlen,796int flags)797{798struct socket *so;799int s, opt = 1;800socklen_t addrlen;801802DEBUG_CALL("tcpx_listen");803/* AF_INET6 addresses are bigger than AF_INET, so this is big enough. */804char addrstr[INET6_ADDRSTRLEN];805char portstr[6];806int ret;807switch (haddr->sa_family) {808case AF_INET:809case AF_INET6:810ret = getnameinfo(haddr, haddrlen, addrstr, sizeof(addrstr), portstr, sizeof(portstr), NI_NUMERICHOST|NI_NUMERICSERV);811g_assert(ret == 0);812DEBUG_ARG("hfamily = INET");813DEBUG_ARG("haddr = %s", addrstr);814DEBUG_ARG("hport = %s", portstr);815break;816#ifndef _WIN32817case AF_UNIX:818DEBUG_ARG("hfamily = UNIX");819DEBUG_ARG("hpath = %s", ((struct sockaddr_un *) haddr)->sun_path);820break;821#endif822default:823g_assert_not_reached();824}825switch (laddr->sa_family) {826case AF_INET:827case AF_INET6:828ret = getnameinfo(laddr, laddrlen, addrstr, sizeof(addrstr), portstr, sizeof(portstr), NI_NUMERICHOST|NI_NUMERICSERV);829g_assert(ret == 0);830DEBUG_ARG("laddr = %s", addrstr);831DEBUG_ARG("lport = %s", portstr);832break;833default:834g_assert_not_reached();835}836DEBUG_ARG("flags = %x", flags);837838/*839* SS_HOSTFWD sockets can be accepted multiple times, so they can't be840* SS_FACCEPTONCE. Also, SS_HOSTFWD connections can be accepted and841* immediately closed if the guest address isn't available yet, which is842* incompatible with the "accept once" concept. Correct code will never843* request both, so disallow their combination by assertion.844*/845g_assert(!((flags & SS_HOSTFWD) && (flags & SS_FACCEPTONCE)));846847so = socreate(slirp, IPPROTO_TCP);848849/* Don't tcp_attach... we don't need so_snd nor so_rcv */850so->so_tcpcb = tcp_newtcpcb(so);851slirp_insque(so, &slirp->tcb);852853/*854* SS_FACCEPTONCE sockets must time out.855*/856if (flags & SS_FACCEPTONCE)857so->so_tcpcb->t_timer[TCPT_KEEP] = TCPTV_KEEP_INIT * 2;858859so->so_state &= SS_PERSISTENT_MASK;860so->so_state |= (SS_FACCEPTCONN | flags);861862sockaddr_copy(&so->lhost.sa, sizeof(so->lhost), laddr, laddrlen);863864s = slirp_socket(haddr->sa_family, SOCK_STREAM, 0);865if ((s < 0) ||866(haddr->sa_family == AF_INET6 && slirp_socket_set_v6only(s, (flags & SS_HOSTFWD_V6ONLY) != 0) < 0) ||867(slirp_socket_set_fast_reuse(s) < 0) ||868(bind(s, haddr, haddrlen) < 0) ||869(listen(s, 1) < 0)) {870int tmperrno = errno; /* Don't clobber the real reason we failed */871if (s >= 0) {872closesocket(s);873}874sofree(so);875/* Restore the real errno */876#ifdef _WIN32877WSASetLastError(tmperrno);878#else879errno = tmperrno;880#endif881return NULL;882}883setsockopt(s, SOL_SOCKET, SO_OOBINLINE, &opt, sizeof(int));884slirp_socket_set_nodelay(s);885886addrlen = sizeof(so->fhost);887getsockname(s, &so->fhost.sa, &addrlen);888sotranslate_accept(so);889890so->s = s;891return so;892}893894struct socket *tcp_listen(Slirp *slirp, uint32_t haddr, unsigned hport,895uint32_t laddr, unsigned lport, int flags)896{897struct sockaddr_in hsa, lsa;898899memset(&hsa, 0, sizeof(hsa));900hsa.sin_family = AF_INET;901hsa.sin_addr.s_addr = haddr;902hsa.sin_port = hport;903904memset(&lsa, 0, sizeof(lsa));905lsa.sin_family = AF_INET;906lsa.sin_addr.s_addr = laddr;907lsa.sin_port = lport;908909return tcpx_listen(slirp, (const struct sockaddr *) &hsa, sizeof(hsa), (struct sockaddr *) &lsa, sizeof(lsa), flags);910}911912/*913* Various session state calls914* XXX Should be #define's915* The socket state stuff needs work, these often get call 2 or 3916* times each when only 1 was needed917*/918void soisfconnecting(struct socket *so)919{920so->so_state &= ~(SS_NOFDREF | SS_ISFCONNECTED | SS_FCANTRCVMORE |921SS_FCANTSENDMORE | SS_FWDRAIN);922so->so_state |= SS_ISFCONNECTING; /* Clobber other states */923}924925void soisfconnected(struct socket *so)926{927so->so_state &= ~(SS_ISFCONNECTING | SS_FWDRAIN | SS_NOFDREF);928so->so_state |= SS_ISFCONNECTED; /* Clobber other states */929}930931static void sofcantrcvmore(struct socket *so)932{933if ((so->so_state & SS_NOFDREF) == 0) {934shutdown(so->s, 0);935}936so->so_state &= ~(SS_ISFCONNECTING);937if (so->so_state & SS_FCANTSENDMORE) {938so->so_state &= SS_PERSISTENT_MASK;939so->so_state |= SS_NOFDREF; /* Don't select it */940} else {941so->so_state |= SS_FCANTRCVMORE;942}943}944945static void sofcantsendmore(struct socket *so)946{947if ((so->so_state & SS_NOFDREF) == 0) {948shutdown(so->s, 1); /* send FIN to fhost */949}950so->so_state &= ~(SS_ISFCONNECTING);951if (so->so_state & SS_FCANTRCVMORE) {952so->so_state &= SS_PERSISTENT_MASK;953so->so_state |= SS_NOFDREF; /* as above */954} else {955so->so_state |= SS_FCANTSENDMORE;956}957}958959void sofwdrain(struct socket *so)960{961if (so->so_rcv.sb_cc)962so->so_state |= SS_FWDRAIN;963else964sofcantsendmore(so);965}966967static bool sotranslate_out4(Slirp *s, struct socket *so, struct sockaddr_in *sin)968{969if (!s->disable_dns && so->so_faddr.s_addr == s->vnameserver_addr.s_addr) {970return so->so_fport == htons(53) && get_dns_addr(&sin->sin_addr) >= 0;971}972973if (so->so_faddr.s_addr == s->vhost_addr.s_addr ||974so->so_faddr.s_addr == 0xffffffff) {975if (s->disable_host_loopback) {976return false;977}978979sin->sin_addr = loopback_addr;980}981982return true;983}984985static bool sotranslate_out6(Slirp *s, struct socket *so, struct sockaddr_in6 *sin)986{987if (!s->disable_dns && in6_equal(&so->so_faddr6, &s->vnameserver_addr6)) {988uint32_t scope_id;989if (so->so_fport == htons(53) && get_dns6_addr(&sin->sin6_addr, &scope_id) >= 0) {990sin->sin6_scope_id = scope_id;991return true;992}993return false;994}995996if (in6_equal_net(&so->so_faddr6, &s->vprefix_addr6, s->vprefix_len) ||997in6_equal(&so->so_faddr6, &(struct in6_addr)ALLNODES_MULTICAST)) {998if (s->disable_host_loopback) {999return false;1000}10011002sin->sin6_addr = in6addr_loopback;1003}10041005return true;1006}100710081009int sotranslate_out(struct socket *so, struct sockaddr_storage *addr)1010{1011bool ok = true;10121013switch (addr->ss_family) {1014case AF_INET:1015ok = sotranslate_out4(so->slirp, so, (struct sockaddr_in *)addr);1016break;1017case AF_INET6:1018ok = sotranslate_out6(so->slirp, so, (struct sockaddr_in6 *)addr);1019break;1020}10211022if (!ok) {1023errno = EPERM;1024return -1;1025}10261027return 0;1028}10291030void sotranslate_in(struct socket *so, struct sockaddr_storage *addr)1031{1032Slirp *slirp = so->slirp;1033struct sockaddr_in *sin = (struct sockaddr_in *)addr;1034struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)addr;10351036switch (addr->ss_family) {1037case AF_INET:1038if ((so->so_faddr.s_addr & slirp->vnetwork_mask.s_addr) ==1039slirp->vnetwork_addr.s_addr) {1040uint32_t inv_mask = ~slirp->vnetwork_mask.s_addr;10411042if ((so->so_faddr.s_addr & inv_mask) == inv_mask) {1043sin->sin_addr = slirp->vhost_addr;1044} else if (sin->sin_addr.s_addr == loopback_addr.s_addr ||1045so->so_faddr.s_addr != slirp->vhost_addr.s_addr) {1046sin->sin_addr = so->so_faddr;1047}1048}1049break;10501051case AF_INET6:1052if (in6_equal_net(&so->so_faddr6, &slirp->vprefix_addr6,1053slirp->vprefix_len)) {1054if (in6_equal(&sin6->sin6_addr, &in6addr_loopback) ||1055!in6_equal(&so->so_faddr6, &slirp->vhost_addr6)) {1056sin6->sin6_addr = so->so_faddr6;1057}1058}1059break;10601061default:1062break;1063}1064}10651066void sotranslate_accept(struct socket *so)1067{1068Slirp *slirp = so->slirp;10691070switch (so->so_ffamily) {1071case AF_INET:1072if (so->so_faddr.s_addr == INADDR_ANY ||1073(so->so_faddr.s_addr & loopback_mask) ==1074(loopback_addr.s_addr & loopback_mask)) {1075so->so_faddr = slirp->vhost_addr;1076}1077break;10781079case AF_INET6:1080if (in6_equal(&so->so_faddr6, &in6addr_any) ||1081in6_equal(&so->so_faddr6, &in6addr_loopback)) {1082so->so_faddr6 = slirp->vhost_addr6;1083}1084break;10851086case AF_UNIX: {1087/* Translate Unix socket to random ephemeral source port. We obtain1088* this source port by binding to port 0 so that the OS allocates a1089* port for us. If this fails, we fall back to choosing a random port1090* with a random number generator. */1091int s;1092struct sockaddr_in in_addr;1093struct sockaddr_in6 in6_addr;1094socklen_t in_addr_len;10951096if (so->slirp->in_enabled) {1097so->so_ffamily = AF_INET;1098so->so_faddr = slirp->vhost_addr;1099so->so_fport = 0;11001101switch (so->so_type) {1102case IPPROTO_TCP:1103s = slirp_socket(PF_INET, SOCK_STREAM, 0);1104break;1105case IPPROTO_UDP:1106s = slirp_socket(PF_INET, SOCK_DGRAM, 0);1107break;1108default:1109g_assert_not_reached();1110break;1111}1112if (s < 0) {1113g_error("Ephemeral slirp_socket() allocation failed");1114goto unix2inet_cont;1115}1116memset(&in_addr, 0, sizeof(in_addr));1117in_addr.sin_family = AF_INET;1118in_addr.sin_addr.s_addr = htonl(INADDR_LOOPBACK);1119in_addr.sin_port = htons(0);1120if (bind(s, (struct sockaddr *) &in_addr, sizeof(in_addr))) {1121g_error("Ephemeral bind() failed");1122closesocket(s);1123goto unix2inet_cont;1124}1125in_addr_len = sizeof(in_addr);1126if (getsockname(s, (struct sockaddr *) &in_addr, &in_addr_len)) {1127g_error("Ephemeral getsockname() failed");1128closesocket(s);1129goto unix2inet_cont;1130}1131so->s_aux = s;1132so->so_fport = in_addr.sin_port;11331134unix2inet_cont:1135if (!so->so_fport) {1136g_warning("Falling back to random port allocation");1137so->so_fport = htons(g_rand_int_range(slirp->grand, 49152, 65536));1138}1139} else if (so->slirp->in6_enabled) {1140so->so_ffamily = AF_INET6;1141so->so_faddr6 = slirp->vhost_addr6;1142so->so_fport6 = 0;11431144switch (so->so_type) {1145case IPPROTO_TCP:1146s = slirp_socket(PF_INET6, SOCK_STREAM, 0);1147break;1148case IPPROTO_UDP:1149s = slirp_socket(PF_INET6, SOCK_DGRAM, 0);1150break;1151default:1152g_assert_not_reached();1153break;1154}1155if (s < 0) {1156g_error("Ephemeral slirp_socket() allocation failed");1157goto unix2inet6_cont;1158}1159memset(&in6_addr, 0, sizeof(in6_addr));1160in6_addr.sin6_family = AF_INET6;1161in6_addr.sin6_addr = in6addr_loopback;1162in6_addr.sin6_port = htons(0);1163if (bind(s, (struct sockaddr *) &in6_addr, sizeof(in6_addr))) {1164g_error("Ephemeral bind() failed");1165closesocket(s);1166goto unix2inet6_cont;1167}1168in_addr_len = sizeof(in6_addr);1169if (getsockname(s, (struct sockaddr *) &in6_addr, &in_addr_len)) {1170g_error("Ephemeral getsockname() failed");1171closesocket(s);1172goto unix2inet6_cont;1173}1174so->s_aux = s;1175so->so_fport6 = in6_addr.sin6_port;11761177unix2inet6_cont:1178if (!so->so_fport6) {1179g_warning("Falling back to random port allocation");1180so->so_fport6 = htons(g_rand_int_range(slirp->grand, 49152, 65536));1181}1182} else {1183g_assert_not_reached();1184}1185break;1186} /* case AF_UNIX */11871188default:1189break;1190}1191}11921193void sodrop(struct socket *s, int num)1194{1195if (sbdrop(&s->so_snd, num)) {1196s->slirp->cb->notify(s->slirp->opaque);1197}1198}11991200/*1201* Translate "addr-any" in so->lhost to the guest's actual address.1202* Returns 0 for success, or -1 if the guest doesn't have an address yet1203* with errno set to EHOSTUNREACH.1204*1205* The guest address is taken from the first entry in the ARP table for IPv41206* and the first entry in the NDP table for IPv6.1207* Note: The IPv4 path isn't exercised yet as all hostfwd "" guest translations1208* are handled immediately by using slirp->vdhcp_startaddr.1209*/1210int soassign_guest_addr_if_needed(struct socket *so)1211{1212Slirp *slirp = so->slirp;1213/* AF_INET6 addresses are bigger than AF_INET, so this is big enough. */1214char addrstr[INET6_ADDRSTRLEN];1215char portstr[6];12161217g_assert(so->so_state & SS_HOSTFWD);12181219switch (so->so_ffamily) {1220case AF_INET:1221if (so->so_laddr.s_addr == INADDR_ANY) {1222g_assert_not_reached();1223}1224break;12251226case AF_INET6:1227if (in6_zero(&so->so_laddr6)) {1228int ret;1229if (in6_zero(&slirp->ndp_table.guest_in6_addr)) {1230errno = EHOSTUNREACH;1231return -1;1232}1233so->so_laddr6 = slirp->ndp_table.guest_in6_addr;1234ret = getnameinfo((const struct sockaddr *) &so->lhost.ss,1235sizeof(so->lhost.ss), addrstr, sizeof(addrstr),1236portstr, sizeof(portstr),1237NI_NUMERICHOST|NI_NUMERICSERV);1238g_assert(ret == 0);1239DEBUG_MISC("%s: new ip = [%s]:%s", __func__, addrstr, portstr);1240}1241break;12421243default:1244break;1245}12461247return 0;1248}124912501251