1*0e59d0d1Sclaudio /* $OpenBSD: control.c,v 1.45 2024/11/21 13:35:20 claudio Exp $ */ 245ae9d61Sreyk 345ae9d61Sreyk /* 4fcebd35dSreyk * Copyright (c) 2010-2013 Reyk Floeter <reyk@openbsd.org> 545ae9d61Sreyk * Copyright (c) 2003, 2004 Henning Brauer <henning@openbsd.org> 645ae9d61Sreyk * 745ae9d61Sreyk * Permission to use, copy, modify, and distribute this software for any 845ae9d61Sreyk * purpose with or without fee is hereby granted, provided that the above 945ae9d61Sreyk * copyright notice and this permission notice appear in all copies. 1045ae9d61Sreyk * 1145ae9d61Sreyk * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 1245ae9d61Sreyk * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 1345ae9d61Sreyk * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 1445ae9d61Sreyk * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 1545ae9d61Sreyk * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 1645ae9d61Sreyk * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 1745ae9d61Sreyk * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 1845ae9d61Sreyk */ 1945ae9d61Sreyk 2045ae9d61Sreyk #include <sys/queue.h> 2145ae9d61Sreyk #include <sys/stat.h> 2245ae9d61Sreyk #include <sys/socket.h> 2345ae9d61Sreyk #include <sys/un.h> 2445ae9d61Sreyk #include <sys/tree.h> 2545ae9d61Sreyk 2645ae9d61Sreyk #include <errno.h> 2745ae9d61Sreyk #include <event.h> 2845ae9d61Sreyk #include <fcntl.h> 2945ae9d61Sreyk #include <stdlib.h> 3045ae9d61Sreyk #include <string.h> 3145ae9d61Sreyk #include <unistd.h> 3245ae9d61Sreyk #include <signal.h> 3345ae9d61Sreyk 3445ae9d61Sreyk #include "iked.h" 3545ae9d61Sreyk 3645ae9d61Sreyk #define CONTROL_BACKLOG 5 3745ae9d61Sreyk 38c5fa57f5Sdv struct ctl_connlist ctl_conns = TAILQ_HEAD_INITIALIZER(ctl_conns); 390fbd6532Stobhe uint32_t ctl_peerid; 4045ae9d61Sreyk 4145ae9d61Sreyk void 4245ae9d61Sreyk control_accept(int, short, void *); 4345ae9d61Sreyk struct ctl_conn 4445ae9d61Sreyk *control_connbyfd(int); 4582d0a036Sderaadt void control_close(int, struct control_sock *); 4645ae9d61Sreyk void control_dispatch_imsg(int, short, void *); 4745ae9d61Sreyk void control_imsg_forward(struct imsg *); 480fbd6532Stobhe void control_imsg_forward_peerid(struct imsg *); 49ebfc3693Sreyk void control_run(struct privsep *, struct privsep_proc *, void *); 50969a8793Stobhe int control_dispatch_ikev2(int, struct privsep_proc *, struct imsg *); 516cf0fa19Stobhe int control_dispatch_ca(int, struct privsep_proc *, struct imsg *); 52ebfc3693Sreyk 53ebfc3693Sreyk static struct privsep_proc procs[] = { 548c502e93Stobhe { "parent", PROC_PARENT, NULL }, 55969a8793Stobhe { "ikev2", PROC_IKEV2, control_dispatch_ikev2 }, 566cf0fa19Stobhe { "ca", PROC_CERT, control_dispatch_ca }, 57ebfc3693Sreyk }; 58ebfc3693Sreyk 59a7dbf4aeStobhe void 60ebfc3693Sreyk control(struct privsep *ps, struct privsep_proc *p) 61ebfc3693Sreyk { 62a7dbf4aeStobhe proc_run(ps, p, procs, nitems(procs), control_run, NULL); 63ebfc3693Sreyk } 64ebfc3693Sreyk 65ebfc3693Sreyk void 66ebfc3693Sreyk control_run(struct privsep *ps, struct privsep_proc *p, void *arg) 67ebfc3693Sreyk { 68ebfc3693Sreyk /* 69ebfc3693Sreyk * pledge in the control process: 70ebfc3693Sreyk * stdio - for malloc and basic I/O including events. 71ebfc3693Sreyk * unix - for the control socket. 72ebfc3693Sreyk */ 73a7dbf4aeStobhe if (pledge("stdio unix recvfd", NULL) == -1) 74ebfc3693Sreyk fatal("pledge"); 75ebfc3693Sreyk } 7645ae9d61Sreyk 7745ae9d61Sreyk int 78701048fbSreyk control_init(struct privsep *ps, struct control_sock *cs) 7945ae9d61Sreyk { 80e8e9d77fStobhe struct iked *env = iked_env; 81e84c6478Stobhe struct sockaddr_un s_un; 8245ae9d61Sreyk int fd; 8345ae9d61Sreyk mode_t old_umask, mode; 8445ae9d61Sreyk 8545ae9d61Sreyk if (cs->cs_name == NULL) 8645ae9d61Sreyk return (0); 8745ae9d61Sreyk 8852ab28dfSreyk if ((fd = socket(AF_UNIX, SOCK_STREAM | SOCK_NONBLOCK, 0)) == -1) { 8945ae9d61Sreyk log_warn("%s: socket", __func__); 9045ae9d61Sreyk return (-1); 9145ae9d61Sreyk } 9245ae9d61Sreyk 93e84c6478Stobhe s_un.sun_family = AF_UNIX; 94e84c6478Stobhe if (strlcpy(s_un.sun_path, cs->cs_name, 95e84c6478Stobhe sizeof(s_un.sun_path)) >= sizeof(s_un.sun_path)) { 9645ae9d61Sreyk log_warn("%s: %s name too long", __func__, cs->cs_name); 9745ae9d61Sreyk close(fd); 9845ae9d61Sreyk return (-1); 9945ae9d61Sreyk } 10045ae9d61Sreyk 10145ae9d61Sreyk if (unlink(cs->cs_name) == -1) 10245ae9d61Sreyk if (errno != ENOENT) { 10345ae9d61Sreyk log_warn("%s: unlink %s", __func__, cs->cs_name); 10445ae9d61Sreyk close(fd); 10545ae9d61Sreyk return (-1); 10645ae9d61Sreyk } 10745ae9d61Sreyk 10845ae9d61Sreyk if (cs->cs_restricted) { 10945ae9d61Sreyk old_umask = umask(S_IXUSR|S_IXGRP|S_IXOTH); 11045ae9d61Sreyk mode = S_IRUSR|S_IWUSR|S_IRGRP|S_IWGRP|S_IROTH|S_IWOTH; 11145ae9d61Sreyk } else { 11245ae9d61Sreyk old_umask = umask(S_IXUSR|S_IXGRP|S_IWOTH|S_IROTH|S_IXOTH); 11345ae9d61Sreyk mode = S_IRUSR|S_IWUSR|S_IRGRP|S_IWGRP; 11445ae9d61Sreyk } 11545ae9d61Sreyk 116e84c6478Stobhe if (bind(fd, (struct sockaddr *)&s_un, sizeof(s_un)) == -1) { 11745ae9d61Sreyk log_warn("%s: bind: %s", __func__, cs->cs_name); 11845ae9d61Sreyk close(fd); 11945ae9d61Sreyk (void)umask(old_umask); 12045ae9d61Sreyk return (-1); 12145ae9d61Sreyk } 12245ae9d61Sreyk (void)umask(old_umask); 12345ae9d61Sreyk 12445ae9d61Sreyk if (chmod(cs->cs_name, mode) == -1) { 12545ae9d61Sreyk log_warn("%s: chmod", __func__); 12645ae9d61Sreyk close(fd); 12745ae9d61Sreyk (void)unlink(cs->cs_name); 12845ae9d61Sreyk return (-1); 12945ae9d61Sreyk } 13045ae9d61Sreyk 13145ae9d61Sreyk cs->cs_fd = fd; 13245ae9d61Sreyk cs->cs_env = env; 13345ae9d61Sreyk 13445ae9d61Sreyk return (0); 13545ae9d61Sreyk } 13645ae9d61Sreyk 13745ae9d61Sreyk int 13845ae9d61Sreyk control_listen(struct control_sock *cs) 13945ae9d61Sreyk { 14045ae9d61Sreyk if (cs->cs_name == NULL) 14145ae9d61Sreyk return (0); 14245ae9d61Sreyk 14345ae9d61Sreyk if (listen(cs->cs_fd, CONTROL_BACKLOG) == -1) { 1447eced9f4Smikeb log_warn("%s: listen", __func__); 14545ae9d61Sreyk return (-1); 14645ae9d61Sreyk } 14745ae9d61Sreyk 14882d0a036Sderaadt event_set(&cs->cs_ev, cs->cs_fd, EV_READ, 14982d0a036Sderaadt control_accept, cs); 15045ae9d61Sreyk event_add(&cs->cs_ev, NULL); 15182d0a036Sderaadt evtimer_set(&cs->cs_evt, control_accept, cs); 15245ae9d61Sreyk 15345ae9d61Sreyk return (0); 15445ae9d61Sreyk } 15545ae9d61Sreyk 15645ae9d61Sreyk void 15745ae9d61Sreyk control_accept(int listenfd, short event, void *arg) 15845ae9d61Sreyk { 15982d0a036Sderaadt struct control_sock *cs = arg; 16045ae9d61Sreyk int connfd; 16145ae9d61Sreyk socklen_t len; 162e84c6478Stobhe struct sockaddr_un s_un; 16345ae9d61Sreyk struct ctl_conn *c; 1640fbd6532Stobhe struct ctl_conn *other; 16545ae9d61Sreyk 16682d0a036Sderaadt event_add(&cs->cs_ev, NULL); 16782d0a036Sderaadt if ((event & EV_TIMEOUT)) 16882d0a036Sderaadt return; 16982d0a036Sderaadt 170e84c6478Stobhe len = sizeof(s_un); 17152ab28dfSreyk if ((connfd = accept4(listenfd, 172e84c6478Stobhe (struct sockaddr *)&s_un, &len, SOCK_NONBLOCK)) == -1) { 17382d0a036Sderaadt /* 17482d0a036Sderaadt * Pause accept if we are out of file descriptors, or 17582d0a036Sderaadt * libevent will haunt us here too. 17682d0a036Sderaadt */ 17782d0a036Sderaadt if (errno == ENFILE || errno == EMFILE) { 17882d0a036Sderaadt struct timeval evtpause = { 1, 0 }; 17982d0a036Sderaadt 18082d0a036Sderaadt event_del(&cs->cs_ev); 18182d0a036Sderaadt evtimer_add(&cs->cs_evt, &evtpause); 18262e3c252Sderaadt } else if (errno != EWOULDBLOCK && errno != EINTR && 18362e3c252Sderaadt errno != ECONNABORTED) 1847eced9f4Smikeb log_warn("%s: accept", __func__); 18545ae9d61Sreyk return; 18645ae9d61Sreyk } 18745ae9d61Sreyk 18845ae9d61Sreyk if ((c = calloc(1, sizeof(struct ctl_conn))) == NULL) { 18945ae9d61Sreyk log_warn("%s", __func__); 19045ae9d61Sreyk close(connfd); 19145ae9d61Sreyk return; 19245ae9d61Sreyk } 19345ae9d61Sreyk 194*0e59d0d1Sclaudio if (imsgbuf_init(&c->iev.ibuf, connfd) == -1) { 195*0e59d0d1Sclaudio log_warn("%s", __func__); 196*0e59d0d1Sclaudio close(connfd); 197*0e59d0d1Sclaudio free(c); 198*0e59d0d1Sclaudio return; 199*0e59d0d1Sclaudio } 20045ae9d61Sreyk c->iev.handler = control_dispatch_imsg; 20145ae9d61Sreyk c->iev.events = EV_READ; 20282d0a036Sderaadt c->iev.data = cs; 20345ae9d61Sreyk event_set(&c->iev.ev, c->iev.ibuf.fd, c->iev.events, 204d532b169Sreyk c->iev.handler, c->iev.data); 20545ae9d61Sreyk event_add(&c->iev.ev, NULL); 20645ae9d61Sreyk 2070fbd6532Stobhe /* O(n^2), but n is small */ 2080fbd6532Stobhe c->peerid = ctl_peerid++; 2090fbd6532Stobhe TAILQ_FOREACH(other, &ctl_conns, entry) 2100fbd6532Stobhe if (c->peerid == other->peerid) 2110fbd6532Stobhe c->peerid = ctl_peerid++; 2120fbd6532Stobhe 21345ae9d61Sreyk TAILQ_INSERT_TAIL(&ctl_conns, c, entry); 21445ae9d61Sreyk } 21545ae9d61Sreyk 21645ae9d61Sreyk struct ctl_conn * 21745ae9d61Sreyk control_connbyfd(int fd) 21845ae9d61Sreyk { 21945ae9d61Sreyk struct ctl_conn *c; 22045ae9d61Sreyk 2214ff7cad5Skrw TAILQ_FOREACH(c, &ctl_conns, entry) { 2224ff7cad5Skrw if (c->iev.ibuf.fd == fd) 2234ff7cad5Skrw break; 2244ff7cad5Skrw } 22545ae9d61Sreyk 22645ae9d61Sreyk return (c); 22745ae9d61Sreyk } 22845ae9d61Sreyk 22945ae9d61Sreyk void 23082d0a036Sderaadt control_close(int fd, struct control_sock *cs) 23145ae9d61Sreyk { 23245ae9d61Sreyk struct ctl_conn *c; 23345ae9d61Sreyk 23445ae9d61Sreyk if ((c = control_connbyfd(fd)) == NULL) { 23545ae9d61Sreyk log_warn("%s: fd %d: not found", __func__, fd); 23645ae9d61Sreyk return; 23745ae9d61Sreyk } 23845ae9d61Sreyk 2399cbf9e90Sclaudio imsgbuf_clear(&c->iev.ibuf); 24045ae9d61Sreyk TAILQ_REMOVE(&ctl_conns, c, entry); 24145ae9d61Sreyk 24245ae9d61Sreyk event_del(&c->iev.ev); 24345ae9d61Sreyk close(c->iev.ibuf.fd); 24482d0a036Sderaadt 24582d0a036Sderaadt /* Some file descriptors are available again. */ 24682d0a036Sderaadt if (evtimer_pending(&cs->cs_evt, NULL)) { 24782d0a036Sderaadt evtimer_del(&cs->cs_evt); 24882d0a036Sderaadt event_add(&cs->cs_ev, NULL); 24982d0a036Sderaadt } 25082d0a036Sderaadt 25145ae9d61Sreyk free(c); 25245ae9d61Sreyk } 25345ae9d61Sreyk 25445ae9d61Sreyk void 25545ae9d61Sreyk control_dispatch_imsg(int fd, short event, void *arg) 25645ae9d61Sreyk { 25782d0a036Sderaadt struct control_sock *cs = arg; 25882d0a036Sderaadt struct iked *env = cs->cs_env; 25945ae9d61Sreyk struct ctl_conn *c; 26045ae9d61Sreyk struct imsg imsg; 26145ae9d61Sreyk int n, v; 26245ae9d61Sreyk 26345ae9d61Sreyk if ((c = control_connbyfd(fd)) == NULL) { 26445ae9d61Sreyk log_warn("%s: fd %d: not found", __func__, fd); 26545ae9d61Sreyk return; 26645ae9d61Sreyk } 26745ae9d61Sreyk 2688cb428a7Syasuoka if (event & EV_READ) { 269668e5ba9Sclaudio if (imsgbuf_read(&c->iev.ibuf) != 1) { 27082d0a036Sderaadt control_close(fd, cs); 27145ae9d61Sreyk return; 27245ae9d61Sreyk } 2738cb428a7Syasuoka } 2748cb428a7Syasuoka if (event & EV_WRITE) { 275dd7efffeSclaudio if (imsgbuf_write(&c->iev.ibuf) == -1) { 27682d0a036Sderaadt control_close(fd, cs); 27745ae9d61Sreyk return; 27845ae9d61Sreyk } 27945ae9d61Sreyk } 28045ae9d61Sreyk 28145ae9d61Sreyk for (;;) { 28245ae9d61Sreyk if ((n = imsg_get(&c->iev.ibuf, &imsg)) == -1) { 28382d0a036Sderaadt control_close(fd, cs); 28445ae9d61Sreyk return; 28545ae9d61Sreyk } 28645ae9d61Sreyk 28745ae9d61Sreyk if (n == 0) 28845ae9d61Sreyk break; 28945ae9d61Sreyk 29045ae9d61Sreyk control_imsg_forward(&imsg); 29145ae9d61Sreyk 2920fbd6532Stobhe /* record peerid of connection for reply */ 2930fbd6532Stobhe imsg.hdr.peerid = c->peerid; 2940fbd6532Stobhe 29545ae9d61Sreyk switch (imsg.hdr.type) { 29645ae9d61Sreyk case IMSG_CTL_NOTIFY: 29745ae9d61Sreyk if (c->flags & CTL_CONN_NOTIFY) { 29845ae9d61Sreyk log_debug("%s: " 29945ae9d61Sreyk "client requested notify more than once", 30045ae9d61Sreyk __func__); 30145ae9d61Sreyk imsg_compose_event(&c->iev, IMSG_CTL_FAIL, 30245ae9d61Sreyk 0, 0, -1, NULL, 0); 30345ae9d61Sreyk break; 30445ae9d61Sreyk } 30545ae9d61Sreyk c->flags |= CTL_CONN_NOTIFY; 30645ae9d61Sreyk break; 30745ae9d61Sreyk case IMSG_CTL_VERBOSE: 30845ae9d61Sreyk IMSG_SIZE_CHECK(&imsg, &v); 30945ae9d61Sreyk 31045ae9d61Sreyk memcpy(&v, imsg.data, sizeof(v)); 311871fc12cSreyk log_setverbose(v); 31245ae9d61Sreyk 313bf556abcSreyk proc_forward_imsg(&env->sc_ps, &imsg, PROC_PARENT, -1); 31445ae9d61Sreyk break; 31545ae9d61Sreyk case IMSG_CTL_RELOAD: 31645ae9d61Sreyk case IMSG_CTL_RESET: 317fc20f985Sreyk case IMSG_CTL_COUPLE: 318fc20f985Sreyk case IMSG_CTL_DECOUPLE: 319fc20f985Sreyk case IMSG_CTL_ACTIVE: 320fc20f985Sreyk case IMSG_CTL_PASSIVE: 321bf556abcSreyk proc_forward_imsg(&env->sc_ps, &imsg, PROC_PARENT, -1); 32245ae9d61Sreyk break; 3238c502e93Stobhe case IMSG_CTL_RESET_ID: 3248c502e93Stobhe proc_forward_imsg(&env->sc_ps, &imsg, PROC_IKEV2, -1); 3258e19888cStobhe break; 326969a8793Stobhe case IMSG_CTL_SHOW_SA: 327b41cc0c8Stobhe case IMSG_CTL_SHOW_STATS: 328969a8793Stobhe proc_forward_imsg(&env->sc_ps, &imsg, PROC_IKEV2, -1); 329969a8793Stobhe break; 3306cf0fa19Stobhe case IMSG_CTL_SHOW_CERTSTORE: 3316cf0fa19Stobhe proc_forward_imsg(&env->sc_ps, &imsg, PROC_CERT, -1); 3326cf0fa19Stobhe break; 33345ae9d61Sreyk default: 33445ae9d61Sreyk log_debug("%s: error handling imsg %d", 33545ae9d61Sreyk __func__, imsg.hdr.type); 33645ae9d61Sreyk break; 33745ae9d61Sreyk } 33845ae9d61Sreyk imsg_free(&imsg); 33945ae9d61Sreyk } 34045ae9d61Sreyk 34145ae9d61Sreyk imsg_event_add(&c->iev); 34245ae9d61Sreyk } 34345ae9d61Sreyk 34445ae9d61Sreyk void 34545ae9d61Sreyk control_imsg_forward(struct imsg *imsg) 34645ae9d61Sreyk { 34745ae9d61Sreyk struct ctl_conn *c; 34845ae9d61Sreyk 34945ae9d61Sreyk TAILQ_FOREACH(c, &ctl_conns, entry) 35045ae9d61Sreyk if (c->flags & CTL_CONN_NOTIFY) 3510e18bff8Sreyk imsg_compose_event(&c->iev, imsg->hdr.type, 35245ae9d61Sreyk 0, imsg->hdr.pid, -1, imsg->data, 35345ae9d61Sreyk imsg->hdr.len - IMSG_HEADER_SIZE); 35445ae9d61Sreyk } 355969a8793Stobhe 3560fbd6532Stobhe void 3570fbd6532Stobhe control_imsg_forward_peerid(struct imsg *imsg) 3580fbd6532Stobhe { 3590fbd6532Stobhe struct ctl_conn *c; 3600fbd6532Stobhe 3610fbd6532Stobhe TAILQ_FOREACH(c, &ctl_conns, entry) 3620fbd6532Stobhe if (c->peerid == imsg->hdr.peerid) 3630fbd6532Stobhe imsg_compose_event(&c->iev, imsg->hdr.type, 3640fbd6532Stobhe 0, imsg->hdr.pid, -1, imsg->data, 3650fbd6532Stobhe imsg->hdr.len - IMSG_HEADER_SIZE); 3660fbd6532Stobhe } 3670fbd6532Stobhe 368969a8793Stobhe int 369969a8793Stobhe control_dispatch_ikev2(int fd, struct privsep_proc *p, struct imsg *imsg) 370969a8793Stobhe { 371969a8793Stobhe switch (imsg->hdr.type) { 372969a8793Stobhe case IMSG_CTL_SHOW_SA: 373b41cc0c8Stobhe case IMSG_CTL_SHOW_STATS: 3740fbd6532Stobhe control_imsg_forward_peerid(imsg); 375969a8793Stobhe return (0); 376969a8793Stobhe default: 377969a8793Stobhe break; 378969a8793Stobhe } 379969a8793Stobhe 380969a8793Stobhe return (-1); 381969a8793Stobhe } 3826cf0fa19Stobhe 3836cf0fa19Stobhe int 3846cf0fa19Stobhe control_dispatch_ca(int fd, struct privsep_proc *p, struct imsg *imsg) 3856cf0fa19Stobhe { 3866cf0fa19Stobhe switch (imsg->hdr.type) { 3876cf0fa19Stobhe case IMSG_CTL_SHOW_CERTSTORE: 3880fbd6532Stobhe control_imsg_forward_peerid(imsg); 3896cf0fa19Stobhe return (0); 3906cf0fa19Stobhe default: 3916cf0fa19Stobhe break; 3926cf0fa19Stobhe } 3936cf0fa19Stobhe 3946cf0fa19Stobhe return (-1); 3956cf0fa19Stobhe } 396