proxymain.c 34 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268
  1. /*
  2. 3APA3A simpliest proxy server
  3. (c) 2002-2017 by Vladimir Dubrovin <3proxy@3proxy.ru>
  4. please read License Agreement
  5. */
  6. #include "proxy.h"
  7. #define param ((struct clientparam *) p)
  8. #ifdef _WIN32
  9. DWORD WINAPI threadfunc(LPVOID p) {
  10. #else
  11. void * threadfunc (void *p) {
  12. #endif
  13. int i = -1;
  14. if(param->srv->cbsock != INVALID_SOCKET){
  15. SASIZETYPE size = sizeof(param->sinsr);
  16. struct pollfd fds;
  17. fds.fd = param->srv->cbsock;
  18. fds.events = POLLIN;
  19. fds.revents = 0;
  20. for(i=5+(param->srv->maxchild>>10); i; i--){
  21. if(so._poll(&fds, 1, 1000*CONNBACK_TO)!=1){
  22. dolog(param, (unsigned char *)"Connect back not received, check connback client");
  23. i = 0;
  24. break;
  25. }
  26. param->remsock = so._accept(param->srv->cbsock, (struct sockaddr*)&param->sinsr, &size);
  27. if(param->remsock == INVALID_SOCKET) {
  28. dolog(param, (unsigned char *)"Connect back accept() failed");
  29. continue;
  30. }
  31. #ifndef WITHMAIN
  32. param->req = param->sinsr;
  33. if(param->srv->preacl) param->res = checkpreACL(param);
  34. if(param->res){
  35. dolog(param, (unsigned char *)"Connect back ACL failed");
  36. so._closesocket(param->remsock);
  37. param->remsock = INVALID_SOCKET;
  38. continue;
  39. }
  40. #endif
  41. if(socksendto(param->remsock, (struct sockaddr*)&param->sinsr, (unsigned char *)"C", 1, CONNBACK_TO) != 1){
  42. dolog(param, (unsigned char *)"Connect back sending command failed");
  43. so._closesocket(param->remsock);
  44. param->remsock = INVALID_SOCKET;
  45. continue;
  46. }
  47. break;
  48. }
  49. }
  50. if(!i){
  51. param->res = 13;
  52. freeparam(param);
  53. }
  54. else {
  55. #ifndef _WIN32
  56. sigset_t mask;
  57. sigfillset(&mask);
  58. if(param->srv->service != S_UDPPM)pthread_sigmask(SIG_SETMASK, &mask, NULL);
  59. #endif
  60. ((struct clientparam *) p)->srv->pf((struct clientparam *)p);
  61. }
  62. #ifdef _WIN32
  63. return 0;
  64. #else
  65. return NULL;
  66. #endif
  67. }
  68. #undef param
  69. struct socketoptions sockopts[] = {
  70. #ifdef TCP_NODELAY
  71. {TCP_NODELAY, "TCP_NODELAY"},
  72. #endif
  73. #ifdef TCP_CORK
  74. {TCP_CORK, "TCP_CORK"},
  75. #endif
  76. #ifdef TCP_DEFER_ACCEPT
  77. {TCP_DEFER_ACCEPT, "TCP_DEFER_ACCEPT"},
  78. #endif
  79. #ifdef TCP_QUICKACK
  80. {TCP_QUICKACK, "TCP_QUICKACK"},
  81. #endif
  82. #ifdef TCP_TIMESTAMPS
  83. {TCP_TIMESTAMPS, "TCP_TIMESTAMPS"},
  84. #endif
  85. #ifdef USE_TCP_FASTOPEN
  86. {USE_TCP_FASTOPEN, "USE_TCP_FASTOPEN"},
  87. #endif
  88. #ifdef SO_REUSEADDR
  89. {SO_REUSEADDR, "SO_REUSEADDR"},
  90. #endif
  91. #ifdef SO_REUSEPORT
  92. {SO_REUSEPORT, "SO_REUSEPORT"},
  93. #endif
  94. #ifdef SO_PORT_SCALABILITY
  95. {SO_PORT_SCALABILITY, "SO_PORT_SCALABILITY"},
  96. #endif
  97. #ifdef SO_REUSE_UNICASTPORT
  98. {SO_REUSE_UNICASTPORT, "SO_REUSE_UNICASTPORT"},
  99. #endif
  100. #ifdef SO_KEEPALIVE
  101. {SO_KEEPALIVE, "SO_KEEPALIVE"},
  102. #endif
  103. #ifdef SO_DONTROUTE
  104. {SO_DONTROUTE, "SO_DONTROUTE"},
  105. #endif
  106. #ifdef IP_TRANSPARENT
  107. {IP_TRANSPARENT, "IP_TRANSPARENT"},
  108. #endif
  109. {0, NULL}
  110. };
  111. char optsbuf[1024];
  112. char * printopts(char *sep){
  113. int i=0, pos=0;
  114. for(; sockopts[i].optname; i++)pos += sprintf(optsbuf+pos,"%s%s",i?sep:"",sockopts[i].optname);
  115. return optsbuf;
  116. }
  117. int getopts(const char *s){
  118. int i=0, ret=0;
  119. for(; sockopts[i].optname; i++)if(strstr(s,sockopts[i].optname)) ret |= (1<<i);
  120. return ret;
  121. }
  122. void setopts(SOCKET s, int opts){
  123. int i, opt, set;
  124. for(i = 0; opts >= (opt = (1<<i)); i++){
  125. set = 1;
  126. if(opts & opt) setsockopt(s, *sockopts[i].optname == 'T'? IPPROTO_TCP:
  127. #ifdef SOL_IP
  128. *sockopts[i].optname == 'I'? SOL_IP:
  129. #endif
  130. SOL_SOCKET, sockopts[i].opt, (char *)&set, sizeof(set));
  131. }
  132. }
  133. #ifndef MODULEMAINFUNC
  134. #define MODULEMAINFUNC main
  135. #define STDMAIN
  136. #ifndef _WINCE
  137. int main (int argc, char** argv){
  138. #else
  139. int WinMain(HINSTANCE hInstance, HINSTANCE hPrevInstance, LPWSTR lpCmdLine, int nCmdShow){
  140. int argc;
  141. char ** argv;
  142. WNDCLASS wc;
  143. HWND hwnd = 0;
  144. #endif
  145. #else
  146. extern int linenum;
  147. extern int haveerror;
  148. int MODULEMAINFUNC (int argc, char** argv){
  149. #endif
  150. SOCKET sock = INVALID_SOCKET, new_sock = INVALID_SOCKET;
  151. int i=0;
  152. SASIZETYPE size;
  153. pthread_t thread;
  154. struct clientparam defparam;
  155. struct srvparam srv;
  156. struct clientparam * newparam;
  157. int error = 0;
  158. unsigned sleeptime;
  159. unsigned char buf[256];
  160. char *hostname=NULL;
  161. int opt = 1, isudp = 0, iscbl = 0, iscbc = 0;
  162. unsigned char *cbc_string = NULL, *cbl_string = NULL;
  163. #ifndef NOIPV6
  164. struct sockaddr_in6 cbsa;
  165. #else
  166. struct sockaddr_in cbsa;
  167. #endif
  168. FILE *fp = NULL;
  169. struct linger lg;
  170. int nlog = 5000;
  171. char loghelp[] =
  172. #ifdef STDMAIN
  173. #ifndef _WIN32
  174. " -I inetd mode (requires real socket, doesn't work with TTY)\n"
  175. " -l@IDENT log to syslog IDENT\n"
  176. #endif
  177. " -d go to background (daemon)\n"
  178. #else
  179. " -u never ask for username\n"
  180. " -u2 always ask for username\n"
  181. #endif
  182. #ifdef SO_BINDTODEVICE
  183. " -Di(DEVICENAME) bind internal interface to device, e.g. eth1\n"
  184. " -De(DEVICENAME) bind external interface to device, e.g. eth1\n"
  185. #endif
  186. #ifdef WITHSLICE
  187. " -s Use slice() - faster proxing, but no filtering for data\n"
  188. #endif
  189. " -fFORMAT logging format (see documentation)\n"
  190. " -l log to stderr\n"
  191. " -lFILENAME log to FILENAME\n"
  192. " -b(BUFSIZE) size of network buffer (default 4096 for TCP, 16384 for UDP)\n"
  193. " -S(STACKSIZE) value to add to default client thread stack size\n"
  194. " -t be silent (do not log service start/stop)\n"
  195. "\n"
  196. " -iIP ip address or internal interface (clients are expected to connect)\n"
  197. " -eIP ip address or external interface (outgoing connection will have this)\n"
  198. " -rHOST:PORT Use IP:port for connect back proxy instead of listen port\n"
  199. " -RHOST:PORT Use PORT to listen connect back proxy connection to pass data to\n"
  200. " -4 Use IPv4 for outgoing connections\n"
  201. " -6 Use IPv6 for outgoing connections\n"
  202. " -46 Prefer IPv4 for outgoing connections, use both IPv4 and IPv6\n"
  203. " -64 Prefer IPv6 for outgoing connections, use both IPv4 and IPv6\n"
  204. " -ocOPTIONS, -osOPTIONS, -olOPTIONS, -orOPTIONS -oROPTIONS - options for\n"
  205. " to-client (oc), to-server (os), listening (ol) socket, connect back client\n"
  206. " (or) socket, connect back server (oR) listening socket\n"
  207. " where possible options are: ";
  208. #ifdef _WIN32
  209. unsigned long ul = 1;
  210. #else
  211. pthread_attr_t pa;
  212. #ifdef STDMAIN
  213. int inetd = 0;
  214. #endif
  215. #endif
  216. #ifdef _WIN32
  217. HANDLE h;
  218. #endif
  219. #ifdef STDMAIN
  220. #ifdef _WINCE
  221. argc = ceparseargs((char *)lpCmdLine);
  222. argv = ceargv;
  223. if(FindWindow(lpCmdLine, lpCmdLine)) return 0;
  224. ZeroMemory(&wc,sizeof(wc));
  225. wc.hbrBackground=(HBRUSH)GetStockObject(BLACK_BRUSH);
  226. wc.hInstance=hInstance;
  227. wc.hCursor=LoadCursor(NULL,IDC_ARROW);
  228. wc.lpfnWndProc=DefWindowProc;
  229. wc.style=CS_HREDRAW|CS_VREDRAW;
  230. wc.lpszClassName=lpCmdLine;
  231. RegisterClass(&wc);
  232. hwnd = CreateWindowEx(WS_EX_TOOLWINDOW,lpCmdLine,lpCmdLine,WS_VISIBLE|WS_POPUP,0,0,0,0,0,0,hInstance,0);
  233. #endif
  234. #ifdef _WIN32
  235. WSADATA wd;
  236. WSAStartup(MAKEWORD( 1, 1 ), &wd);
  237. #endif
  238. #endif
  239. srvinit(&srv, &defparam);
  240. srv.pf = childdef.pf;
  241. isudp = childdef.isudp;
  242. srv.service = defparam.service = childdef.service;
  243. #ifndef STDMAIN
  244. copyacl(conf.acl, &srv);
  245. srv.authfuncs = copyauth(conf.authfuncs);
  246. if(!conf.services){
  247. conf.services = &srv;
  248. }
  249. else {
  250. srv.next = conf.services;
  251. conf.services = conf.services->prev = &srv;
  252. }
  253. #ifndef _WIN32
  254. {
  255. sigset_t mask;
  256. sigfillset(&mask);
  257. pthread_sigmask(SIG_SETMASK, &mask, NULL);
  258. }
  259. #endif
  260. #else
  261. srv.needuser = 0;
  262. initlog();
  263. #endif
  264. for (i=1; i<argc; i++) {
  265. if(*argv[i]=='-') {
  266. switch(argv[i][1]) {
  267. case 'd':
  268. if(!conf.demon)daemonize();
  269. conf.demon = 1;
  270. break;
  271. #ifdef SO_BINDTODEVICE
  272. case 'D':
  273. if(argv[i][2] == 'i') srv.ibindtodevice = mystrdup(argv[i] + 3);
  274. else srv.obindtodevice = mystrdup(argv[i] + 3);
  275. break;
  276. #endif
  277. case 'l':
  278. if(srv.logtarget) myfree(srv.logtarget);
  279. srv.logtarget = (unsigned char *)mystrdup(argv[i] + 2);
  280. if(argv[i][2]) {
  281. if(argv[i][2]=='@'){
  282. #ifdef STDMAIN
  283. #ifndef _WIN32
  284. openlog(argv[i]+3, LOG_PID, LOG_DAEMON);
  285. srv.logfunc = logsyslog;
  286. #endif
  287. #endif
  288. }
  289. else {
  290. fp = fopen(argv[i] + 2, "a");
  291. if (fp) {
  292. srv.stdlog = fp;
  293. fseek(fp, 0L, SEEK_END);
  294. }
  295. }
  296. }
  297. break;
  298. case 'i':
  299. getip46(46, (unsigned char *)argv[i]+2, (struct sockaddr *)&srv.intsa);
  300. break;
  301. case 'e':
  302. {
  303. #ifndef NOIPV6
  304. struct sockaddr_in6 sa6;
  305. memset(&sa6, 0, sizeof(sa6));
  306. error = !getip46(46, (unsigned char *)argv[i]+2, (struct sockaddr *)&sa6);
  307. if(!error) {
  308. if (*SAFAMILY(&sa6)==AF_INET) srv.extsa = sa6;
  309. else srv.extsa6 = sa6;
  310. }
  311. #else
  312. error = !getip46(46, (unsigned char *)argv[i]+2, (struct sockaddr *)&srv.extsa);
  313. #endif
  314. }
  315. break;
  316. case 'N':
  317. getip46(46, (unsigned char *)argv[i]+2, (struct sockaddr *)&srv.extNat);
  318. break;
  319. case 'p':
  320. *SAPORT(&srv.intsa) = htons(atoi(argv[i]+2));
  321. break;
  322. case '4':
  323. case '6':
  324. srv.family = atoi(argv[i]+1);
  325. break;
  326. case 'b':
  327. srv.bufsize = atoi(argv[i]+2);
  328. break;
  329. case 'n':
  330. srv.usentlm = atoi(argv[i]+2);
  331. break;
  332. #ifdef STDMAIN
  333. #ifndef _WIN32
  334. case 'I':
  335. size = sizeof(defparam.sincl);
  336. if(so._getsockname(0, (struct sockaddr*)&defparam.sincl, &size) ||
  337. *SAFAMILY(&defparam.sincl) != AF_INET) error = 1;
  338. else inetd = 1;
  339. break;
  340. #endif
  341. #endif
  342. case 'f':
  343. if(srv.logformat)myfree(srv.logformat);
  344. srv.logformat = (unsigned char *)mystrdup(argv[i] + 2);
  345. break;
  346. case 't':
  347. srv.silent = 1;
  348. break;
  349. case 'h':
  350. hostname = argv[i] + 2;
  351. break;
  352. case 'r':
  353. cbc_string = (unsigned char *)mystrdup(argv[i] + 2);
  354. iscbc = 1;
  355. break;
  356. case 'R':
  357. cbl_string = (unsigned char *)mystrdup(argv[i] + 2);
  358. iscbl = 1;
  359. break;
  360. case 'u':
  361. srv.needuser = 0;
  362. if(*(argv[i] + 2)) srv.needuser = atoi(argv[i] + 2);
  363. break;
  364. case 'T':
  365. srv.transparent = 1;
  366. break;
  367. case 'S':
  368. srv.stacksize = atoi(argv[i]+2);
  369. break;
  370. case 'a':
  371. srv.anonymous = 1 + atoi(argv[i]+2);
  372. break;
  373. case 's':
  374. #ifdef WITHSPLICE
  375. if(isudp || srv.service == S_ADMIN)
  376. #endif
  377. srv.singlepacket = 1 + atoi(argv[i]+2);
  378. #ifdef WITHSPLICE
  379. else
  380. if(*(argv[i]+2)) srv.usesplice = atoi(argv[i]+2);
  381. #endif
  382. break;
  383. case 'o':
  384. switch(argv[i][2]){
  385. case 's':
  386. srv.srvsockopts = getopts(argv[i]+3);
  387. break;
  388. case 'c':
  389. srv.clisockopts = getopts(argv[i]+3);
  390. break;
  391. case 'l':
  392. srv.lissockopts = getopts(argv[i]+3);
  393. break;
  394. case 'r':
  395. srv.cbcsockopts = getopts(argv[i]+3);
  396. break;
  397. case 'R':
  398. srv.cbcsockopts = getopts(argv[i]+3);
  399. break;
  400. default:
  401. error = 1;
  402. }
  403. if(!error) break;
  404. default:
  405. error = 1;
  406. break;
  407. }
  408. }
  409. else break;
  410. }
  411. #ifndef STDMAIN
  412. if(childdef.port) {
  413. #endif
  414. #ifndef PORTMAP
  415. if (error || i!=argc) {
  416. #ifndef STDMAIN
  417. haveerror = 1;
  418. conf.threadinit = 0;
  419. #endif
  420. fprintf(stderr, "%s of %s\n"
  421. "Usage: %s options\n"
  422. "Available options are:\n"
  423. "%s\n"
  424. "\t%s\n"
  425. " -pPORT - service port to accept connections\n"
  426. "%s"
  427. "\tExample: %s -i127.0.0.1\n\n"
  428. "%s",
  429. argv[0],
  430. conf.stringtable?(char *)conf.stringtable[3]: VERSION " (" BUILDDATE ")",
  431. argv[0], loghelp, printopts("\n\t"), childdef.helpmessage, argv[0],
  432. #ifdef STDMAIN
  433. copyright
  434. #else
  435. ""
  436. #endif
  437. );
  438. return (1);
  439. }
  440. #endif
  441. #ifndef STDMAIN
  442. }
  443. else {
  444. #endif
  445. #ifndef NOPORTMAP
  446. if (error || argc != i+3 || *argv[i]=='-'|| (*SAPORT(&srv.intsa) = htons((unsigned short)atoi(argv[i])))==0 || (srv.targetport = htons((unsigned short)atoi(argv[i+2])))==0) {
  447. #ifndef STDMAIN
  448. haveerror = 1;
  449. conf.threadinit = 0;
  450. #endif
  451. fprintf(stderr, "%s of %s\n"
  452. "Usage: %s options"
  453. " [-e<external_ip>] <port_to_bind>"
  454. " <target_hostname> <target_port>\n"
  455. "Available options are:\n"
  456. "%s\n"
  457. "\t%s\n"
  458. "%s"
  459. "\tExample: %s -d -i127.0.0.1 6666 serv.somehost.ru 6666\n\n"
  460. "%s",
  461. argv[0],
  462. conf.stringtable?(char *)conf.stringtable[3]: VERSION " (" BUILDDATE ")",
  463. argv[0], loghelp, printopts("\n\t"), childdef.helpmessage, argv[0],
  464. #ifdef STDMAIN
  465. copyright
  466. #else
  467. ""
  468. #endif
  469. );
  470. return (1);
  471. }
  472. srv.target = (unsigned char *)mystrdup(argv[i+1]);
  473. #endif
  474. #ifndef STDMAIN
  475. }
  476. #else
  477. #ifndef _WIN32
  478. if(inetd) {
  479. fcntl(0,F_SETFL,O_NONBLOCK | fcntl(0,F_GETFL));
  480. if(!isudp){
  481. so._setsockopt(0, SOL_SOCKET, SO_LINGER, (unsigned char *)&lg, sizeof(lg));
  482. so._setsockopt(0, SOL_SOCKET, SO_OOBINLINE, (unsigned char *)&opt, sizeof(int));
  483. }
  484. defparam.clisock = 0;
  485. if(! (newparam = myalloc (sizeof(defparam)))){
  486. return 2;
  487. };
  488. *newparam = defparam;
  489. return((*srv.pf)((void *)newparam)? 1:0);
  490. }
  491. #endif
  492. #endif
  493. srvinit2(&srv, &defparam);
  494. if(!*SAFAMILY(&srv.intsa)) *SAFAMILY(&srv.intsa) = AF_INET;
  495. if(!*SAPORT(&srv.intsa)) *SAPORT(&srv.intsa) = htons(childdef.port);
  496. *SAFAMILY(&srv.extsa) = AF_INET;
  497. #ifndef NOIPV6
  498. *SAFAMILY(&srv.extsa6) = AF_INET6;
  499. #endif
  500. if(hostname)parsehostname(hostname, &defparam, childdef.port);
  501. #ifndef STDMAIN
  502. copyfilter(conf.filters, &srv);
  503. conf.threadinit = 0;
  504. #endif
  505. if (!iscbc) {
  506. if(srv.srvsock == INVALID_SOCKET){
  507. if(!isudp){
  508. lg.l_onoff = 1;
  509. lg.l_linger = conf.timeouts[STRING_L];
  510. sock=so._socket(SASOCK(&srv.intsa), SOCK_STREAM, IPPROTO_TCP);
  511. }
  512. else {
  513. sock=so._socket(SASOCK(&srv.intsa), SOCK_DGRAM, IPPROTO_UDP);
  514. }
  515. if( sock == INVALID_SOCKET) {
  516. perror("socket()");
  517. return -2;
  518. }
  519. setopts(sock, srv.lissockopts);
  520. #ifdef _WIN32
  521. ioctlsocket(sock, FIONBIO, &ul);
  522. #else
  523. fcntl(sock,F_SETFL,O_NONBLOCK | fcntl(sock,F_GETFL));
  524. #endif
  525. srv.srvsock = sock;
  526. opt = 1;
  527. if(so._setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
  528. #ifdef SO_REUSEPORT
  529. opt = 1;
  530. so._setsockopt(sock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
  531. #endif
  532. #ifdef SO_BINDTODEVICE
  533. if(srv.ibindtodevice) so._setsockopt(sock, SOL_SOCKET, SO_BINDTODEVICE, srv.ibindtodevice, strlen(srv.ibindtodevice) + 1);
  534. #endif
  535. }
  536. size = sizeof(srv.intsa);
  537. for(sleeptime = SLEEPTIME * 100; so._bind(sock, (struct sockaddr*)&srv.intsa, SASIZE(&srv.intsa))==-1; usleep(sleeptime)) {
  538. sprintf((char *)buf, "bind(): %s", strerror(errno));
  539. if(!srv.silent)dolog(&defparam, buf);
  540. sleeptime = (sleeptime<<1);
  541. if(!sleeptime) {
  542. so._closesocket(sock);
  543. return -3;
  544. }
  545. }
  546. if(!isudp){
  547. if(so._listen (sock, 1 + (srv.maxchild>>4))==-1) {
  548. sprintf((char *)buf, "listen(): %s", strerror(errno));
  549. if(!srv.silent)dolog(&defparam, buf);
  550. return -4;
  551. }
  552. }
  553. else
  554. defparam.clisock = sock;
  555. if(!srv.silent && !iscbc){
  556. sprintf((char *)buf, "Accepting connections [%u/%u]", (unsigned)getpid(), (unsigned)pthread_self());
  557. dolog(&defparam, buf);
  558. }
  559. }
  560. if(iscbl){
  561. parsehost(srv.family, cbl_string, (struct sockaddr *)&cbsa);
  562. if((srv.cbsock=so._socket(SASOCK(&cbsa), SOCK_STREAM, IPPROTO_TCP))==INVALID_SOCKET) {
  563. dolog(&defparam, (unsigned char *)"Failed to allocate connect back socket");
  564. return -6;
  565. }
  566. opt = 1;
  567. so._setsockopt(srv.cbsock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int));
  568. #ifdef SO_REUSEPORT
  569. opt = 1;
  570. so._setsockopt(srv.cbsock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
  571. #endif
  572. setopts(srv.cbsock, srv.cbssockopts);
  573. if(so._bind(srv.cbsock, (struct sockaddr*)&cbsa, SASIZE(&cbsa))==-1) {
  574. dolog(&defparam, (unsigned char *)"Failed to bind connect back socket");
  575. return -7;
  576. }
  577. if(so._listen(srv.cbsock, 1 + (srv.maxchild>>4))==-1) {
  578. dolog(&defparam, (unsigned char *)"Failed to listen connect back socket");
  579. return -8;
  580. }
  581. }
  582. srv.fds.fd = sock;
  583. srv.fds.events = POLLIN;
  584. #ifndef _WIN32
  585. pthread_attr_init(&pa);
  586. pthread_attr_setstacksize(&pa,PTHREAD_STACK_MIN + (32768 + srv.stacksize));
  587. pthread_attr_setdetachstate(&pa,PTHREAD_CREATE_DETACHED);
  588. #endif
  589. for (;;) {
  590. for(;;){
  591. while((conf.paused == srv.paused && srv.childcount >= srv.maxchild)){
  592. nlog++;
  593. if(!srv.silent && nlog > 5000) {
  594. sprintf((char *)buf, "Warning: too many connected clients (%d/%d)", srv.childcount, srv.maxchild);
  595. dolog(&defparam, buf);
  596. nlog = 0;
  597. }
  598. usleep(SLEEPTIME);
  599. }
  600. if (iscbc) break;
  601. if (conf.paused != srv.paused) break;
  602. if (srv.fds.events & POLLIN) {
  603. error = so._poll(&srv.fds, 1, 1000);
  604. }
  605. else {
  606. usleep(SLEEPTIME);
  607. continue;
  608. }
  609. if (error >= 1) break;
  610. if (error == 0) continue;
  611. if (errno != EAGAIN && errno != EINTR) {
  612. sprintf((char *)buf, "poll(): %s/%d", strerror(errno), errno);
  613. if(!srv.silent)dolog(&defparam, buf);
  614. break;
  615. }
  616. }
  617. if((conf.paused != srv.paused) || (error < 0)) break;
  618. error = 0;
  619. if(!isudp){
  620. size = sizeof(defparam.sincr);
  621. if(iscbc){
  622. new_sock=so._socket(SASOCK(&defparam.sincr), SOCK_STREAM, IPPROTO_TCP);
  623. if(new_sock != INVALID_SOCKET){
  624. setopts(new_sock, srv.cbcsockopts);
  625. parsehost(srv.family, cbc_string, (struct sockaddr *)&defparam.sincr);
  626. if(connectwithpoll(new_sock,(struct sockaddr *)&defparam.sincr,SASIZE(&defparam.sincr),CONNBACK_TO)) {
  627. so._closesocket(new_sock);
  628. new_sock = INVALID_SOCKET;
  629. usleep(SLEEPTIME);
  630. continue;
  631. }
  632. if(sockrecvfrom(new_sock,(struct sockaddr*)&defparam.sincr,buf,1,60) != 1 || *buf!='C') {
  633. so._closesocket(new_sock);
  634. new_sock = INVALID_SOCKET;
  635. usleep(SLEEPTIME);
  636. continue;
  637. }
  638. }
  639. else {
  640. usleep(SLEEPTIME);
  641. continue;
  642. }
  643. }
  644. else {
  645. new_sock = so._accept(sock, (struct sockaddr*)&defparam.sincr, &size);
  646. if(new_sock == INVALID_SOCKET){
  647. #ifdef _WIN32
  648. switch(WSAGetLastError()){
  649. case WSAEMFILE:
  650. case WSAENOBUFS:
  651. case WSAENETDOWN:
  652. usleep(SLEEPTIME * 10);
  653. break;
  654. case WSAEINTR:
  655. error = 1;
  656. break;
  657. default:
  658. break;
  659. }
  660. #else
  661. switch (errno){
  662. #ifdef EMFILE
  663. case EMFILE:
  664. #endif
  665. #ifdef ENFILE
  666. case ENFILE:
  667. #endif
  668. #ifdef ENOBUFS
  669. case ENOBUFS:
  670. #endif
  671. #ifdef ENOMEM
  672. case ENOMEM:
  673. #endif
  674. usleep(SLEEPTIME * 10);
  675. break;
  676. default:
  677. break;
  678. }
  679. #endif
  680. nlog++;
  681. if(!srv.silent && (error || nlog > 5000)) {
  682. sprintf((char *)buf, "accept(): %s", strerror(errno));
  683. dolog(&defparam, buf);
  684. nlog = 0;
  685. }
  686. continue;
  687. }
  688. }
  689. setopts(new_sock, srv.clisockopts);
  690. size = sizeof(defparam.sincl);
  691. if(so._getsockname(new_sock, (struct sockaddr *)&defparam.sincl, &size)){
  692. sprintf((char *)buf, "getsockname(): %s", strerror(errno));
  693. if(!srv.silent)dolog(&defparam, buf);
  694. continue;
  695. }
  696. #ifdef _WIN32
  697. ioctlsocket(new_sock, FIONBIO, &ul);
  698. #else
  699. fcntl(new_sock,F_SETFL,O_NONBLOCK | fcntl(new_sock,F_GETFL));
  700. #endif
  701. so._setsockopt(new_sock, SOL_SOCKET, SO_LINGER, (char *)&lg, sizeof(lg));
  702. so._setsockopt(new_sock, SOL_SOCKET, SO_OOBINLINE, (char *)&opt, sizeof(int));
  703. }
  704. else {
  705. srv.fds.events = 0;
  706. }
  707. #ifndef STDMAIN
  708. if((dopreauth(&defparam)) != 0){
  709. if(!isudp) so._closesocket(new_sock);
  710. continue;
  711. }
  712. #endif
  713. if(! (newparam = myalloc (sizeof(defparam)))){
  714. if(!isudp) so._closesocket(new_sock);
  715. defparam.res = 21;
  716. if(!srv.silent)dolog(&defparam, (unsigned char *)"Memory Allocation Failed");
  717. usleep(SLEEPTIME);
  718. continue;
  719. };
  720. *newparam = defparam;
  721. if(defparam.hostname)newparam->hostname=(unsigned char *)mystrdup((char *)defparam.hostname);
  722. clearstat(newparam);
  723. if(!isudp) newparam->clisock = new_sock;
  724. #ifndef STDMAIN
  725. if(makefilters(&srv, newparam) > CONTINUE){
  726. freeparam(newparam);
  727. continue;
  728. }
  729. #endif
  730. newparam->prev = newparam->next = NULL;
  731. error = 0;
  732. pthread_mutex_lock(&srv.counter_mutex);
  733. if(!srv.child){
  734. srv.child = newparam;
  735. }
  736. else {
  737. newparam->next = srv.child;
  738. srv.child = srv.child->prev = newparam;
  739. }
  740. #ifdef _WIN32
  741. #ifndef _WINCE
  742. h = (HANDLE)_beginthreadex((LPSECURITY_ATTRIBUTES )NULL, (unsigned)(16384 + srv.stacksize), (void *)threadfunc, (void *) newparam, 0, &thread);
  743. #else
  744. h = (HANDLE)CreateThread((LPSECURITY_ATTRIBUTES )NULL, (unsigned)(16384 + srv.stacksize), (void *)threadfunc, (void *) newparam, 0, &thread);
  745. #endif
  746. srv.childcount++;
  747. if (h) {
  748. newparam->threadid = (unsigned)thread;
  749. CloseHandle(h);
  750. }
  751. else {
  752. sprintf((char *)buf, "_beginthreadex(): %s", _strerror(NULL));
  753. if(!srv.silent)dolog(&defparam, buf);
  754. error = 1;
  755. }
  756. #else
  757. error = pthread_create(&thread, &pa, threadfunc, (void *)newparam);
  758. srv.childcount++;
  759. if(error){
  760. sprintf((char *)buf, "pthread_create(): %s", strerror(error));
  761. if(!srv.silent)dolog(&defparam, buf);
  762. }
  763. else {
  764. newparam->threadid = (unsigned)thread;
  765. }
  766. #endif
  767. pthread_mutex_unlock(&srv.counter_mutex);
  768. if(error) freeparam(newparam);
  769. memset(&defparam.sincl, 0, sizeof(defparam.sincl));
  770. memset(&defparam.sincr, 0, sizeof(defparam.sincr));
  771. if(isudp) while(!srv.fds.events)usleep(SLEEPTIME);
  772. }
  773. if(!srv.silent) srv.logfunc(&defparam, (unsigned char *)"Exiting thread");
  774. srvfree(&srv);
  775. #ifndef STDMAIN
  776. pthread_mutex_lock(&config_mutex);
  777. if(srv.next)srv.next->prev = srv.prev;
  778. if(srv.prev)srv.prev->next = srv.next;
  779. else conf.services = srv.next;
  780. pthread_mutex_unlock(&config_mutex);
  781. #endif
  782. #ifndef _WIN32
  783. pthread_attr_destroy(&pa);
  784. #endif
  785. if(defparam.hostname)myfree(defparam.hostname);
  786. if(cbc_string)myfree(cbc_string);
  787. if(cbl_string)myfree(cbl_string);
  788. if(fp) fclose(fp);
  789. return 0;
  790. }
  791. void srvinit(struct srvparam * srv, struct clientparam *param){
  792. memset(srv, 0, sizeof(struct srvparam));
  793. srv->version = conf.version + 1;
  794. srv->paused = conf.paused;
  795. srv->logfunc = havelog?conf.logfunc:NULL;
  796. srv->noforce = conf.noforce;
  797. srv->logformat = conf.logformat? (unsigned char *)mystrdup((char *)conf.logformat) : NULL;
  798. srv->authfunc = conf.authfunc;
  799. srv->usentlm = 0;
  800. srv->maxchild = conf.maxchild;
  801. srv->stacksize = conf.stacksize;
  802. srv->time_start = time(NULL);
  803. if(havelog && conf.logtarget){
  804. srv->logtarget = (unsigned char *)mystrdup((char *)conf.logtarget);
  805. }
  806. srv->srvsock = INVALID_SOCKET;
  807. srv->logdumpsrv = conf.logdumpsrv;
  808. srv->logdumpcli = conf.logdumpcli;
  809. srv->cbsock = INVALID_SOCKET;
  810. srv->needuser = 1;
  811. #ifdef WITHSPLICE
  812. srv->usesplice = 1;
  813. #endif
  814. memset(param, 0, sizeof(struct clientparam));
  815. param->srv = srv;
  816. param->version = srv->version;
  817. param->paused = srv->paused;
  818. param->remsock = param->clisock = param->ctrlsock = param->ctrlsocksrv = INVALID_SOCKET;
  819. *SAFAMILY(&param->req) = *SAFAMILY(&param->sinsl) = *SAFAMILY(&param->sinsr) = *SAFAMILY(&param->sincr) = *SAFAMILY(&param->sincl) = AF_INET;
  820. pthread_mutex_init(&srv->counter_mutex, NULL);
  821. srv->intsa = conf.intsa;
  822. srv->extsa = conf.extsa;
  823. #ifndef NOIPV6
  824. srv->extsa6 = conf.extsa6;
  825. #endif
  826. }
  827. void srvinit2(struct srvparam * srv, struct clientparam *param){
  828. if(srv->logformat){
  829. char *s;
  830. if(*srv->logformat == '-' && (s = strchr((char *)srv->logformat + 1, '+')) && s[1]){
  831. unsigned char* logformat = srv->logformat;
  832. *s = 0;
  833. srv->nonprintable = (unsigned char *)mystrdup((char *)srv->logformat + 1);
  834. srv->replace = s[1];
  835. srv->logformat = (unsigned char *)mystrdup(s + 2);
  836. *s = '+';
  837. myfree(logformat);
  838. }
  839. }
  840. memset(&param->sinsl, 0, sizeof(param->sinsl));
  841. memset(&param->sinsr, 0, sizeof(param->sinsr));
  842. memset(&param->req, 0, sizeof(param->req));
  843. *SAFAMILY(&param->sinsl) = AF_INET;
  844. *SAFAMILY(&param->sinsr) = AF_INET;
  845. *SAFAMILY(&param->req) = AF_INET;
  846. param->sincr = param->sincl = srv->intsa;
  847. #ifndef NOIPV6
  848. if (srv->family == 6 || srv->family == 64) param->sinsr = srv->extsa6;
  849. else
  850. #endif
  851. param->sinsr = srv->extsa;
  852. }
  853. void srvfree(struct srvparam * srv){
  854. if(srv->srvsock != INVALID_SOCKET) so._closesocket(srv->srvsock);
  855. srv->srvsock = INVALID_SOCKET;
  856. if(srv->cbsock != INVALID_SOCKET) so._closesocket(srv->cbsock);
  857. srv->cbsock = INVALID_SOCKET;
  858. srv->service = S_ZOMBIE;
  859. while(srv->child) usleep(SLEEPTIME * 100);
  860. #ifndef STDMAIN
  861. if(srv->filter){
  862. while(srv->nfilters){
  863. srv->nfilters--;
  864. if(srv->filter[srv->nfilters].filter_close){
  865. (*srv->filter[srv->nfilters].filter_close)(srv->filter[srv->nfilters].data);
  866. }
  867. }
  868. myfree(srv->filter);
  869. }
  870. if(srv->acl)freeacl(srv->acl);
  871. if(srv->preacl)freeacl(srv->preacl);
  872. if(srv->authfuncs)freeauth(srv->authfuncs);
  873. #endif
  874. pthread_mutex_destroy(&srv->counter_mutex);
  875. if(srv->target) myfree(srv->target);
  876. if(srv->logtarget) myfree(srv->logtarget);
  877. if(srv->logformat) myfree(srv->logformat);
  878. if(srv->nonprintable) myfree(srv->nonprintable);
  879. #ifdef SO_BINDTODEVICE
  880. if(srv->ibindtodevice) myfree(srv->ibindtodevice);
  881. if(srv->obindtodevice) myfree(srv->obindtodevice);
  882. #endif
  883. }
  884. void freeparam(struct clientparam * param) {
  885. if(param->res == 2) return;
  886. if(param->ctrlsocksrv != INVALID_SOCKET && param->ctrlsocksrv != param->remsock) {
  887. so._shutdown(param->ctrlsocksrv, SHUT_RDWR);
  888. so._closesocket(param->ctrlsocksrv);
  889. }
  890. if(param->ctrlsock != INVALID_SOCKET && param->ctrlsock != param->clisock) {
  891. so._shutdown(param->ctrlsock, SHUT_RDWR);
  892. so._closesocket(param->ctrlsock);
  893. }
  894. if(param->remsock != INVALID_SOCKET) {
  895. so._shutdown(param->remsock, SHUT_RDWR);
  896. so._closesocket(param->remsock);
  897. }
  898. if(param->clisock != INVALID_SOCKET) {
  899. so._shutdown(param->clisock, SHUT_RDWR);
  900. so._closesocket(param->clisock);
  901. }
  902. myfree(param->clibuf);
  903. myfree(param->srvbuf);
  904. if(param->datfilterssrv) myfree(param->datfilterssrv);
  905. #ifndef STDMAIN
  906. if(param->reqfilters) myfree(param->reqfilters);
  907. if(param->hdrfilterscli) myfree(param->hdrfilterscli);
  908. if(param->hdrfilterssrv) myfree(param->hdrfilterssrv);
  909. if(param->predatfilters) myfree(param->predatfilters);
  910. if(param->datfilterscli) myfree(param->datfilterscli);
  911. if(param->filters){
  912. if(param->nfilters)while(param->nfilters--){
  913. if(param->filters[param->nfilters].filter->filter_clear)
  914. (*param->filters[param->nfilters].filter->filter_clear)(param->filters[param->nfilters].data);
  915. }
  916. myfree(param->filters);
  917. }
  918. if(conf.connlimiter && (param->res != 95 || param->remsock != INVALID_SOCKET)) stopconnlims(param);
  919. #endif
  920. if(param->srv){
  921. pthread_mutex_lock(&param->srv->counter_mutex);
  922. if(param->prev){
  923. param->prev->next = param->next;
  924. }
  925. else
  926. param->srv->child = param->next;
  927. if(param->next){
  928. param->next->prev = param->prev;
  929. }
  930. (param->srv->childcount)--;
  931. pthread_mutex_unlock(&param->srv->counter_mutex);
  932. }
  933. if(param->hostname) myfree(param->hostname);
  934. if(param->username) myfree(param->username);
  935. if(param->password) myfree(param->password);
  936. if(param->extusername) myfree(param->extusername);
  937. if(param->extpassword) myfree(param->extpassword);
  938. myfree(param);
  939. }
  940. #ifndef STDMAIN
  941. static void * itcopy (void * from, size_t size){
  942. void * ret;
  943. if(!from) return NULL;
  944. ret = myalloc(size);
  945. if(ret) memcpy(ret, from, size);
  946. return ret;
  947. }
  948. struct auth * copyauth (struct auth * authfuncs){
  949. struct auth * newauth = NULL;
  950. newauth = authfuncs = itcopy(authfuncs, sizeof(struct auth));
  951. for( ; authfuncs; authfuncs = authfuncs->next = itcopy(authfuncs->next, sizeof(struct auth)));
  952. return newauth;
  953. }
  954. void copyacl (struct ace *ac, struct srvparam *srv){
  955. struct iplist *ipl;
  956. struct portlist *pl;
  957. struct userlist *ul;
  958. struct chain *ch;
  959. struct period *pel;
  960. struct hostname *hst;
  961. int preacl = 1;
  962. struct ace *acc;
  963. ac = itcopy(ac, sizeof(struct ace));
  964. for( ; ac; ac = ac->next = itcopy(ac->next, sizeof(struct ace))){
  965. ac->src = itcopy(ac->src, sizeof(struct iplist));
  966. for(ipl = ac->src; ipl; ipl = ipl->next = itcopy(ipl->next, sizeof(struct iplist)));
  967. ac->dst = itcopy(ac->dst, sizeof(struct iplist));
  968. for(ipl = ac->dst; ipl; ipl = ipl->next = itcopy(ipl->next, sizeof(struct iplist)));
  969. ac->ports = itcopy(ac->ports, sizeof(struct portlist));
  970. for(pl = ac->ports; pl; pl = pl->next = itcopy(pl->next, sizeof(struct portlist)));
  971. ac->periods = itcopy(ac->periods, sizeof(struct period));
  972. for(pel = ac->periods; pel; pel = pel->next = itcopy(pel->next, sizeof(struct period)));
  973. ac->users = itcopy(ac->users, sizeof(struct userlist));
  974. for(ul = ac->users; ul; ul = ul->next = itcopy(ul->next, sizeof(struct userlist))){
  975. if(ul->user) ul->user = (unsigned char*)mystrdup((char *)ul->user);
  976. }
  977. ac->dstnames = itcopy(ac->dstnames, sizeof(struct hostname));
  978. for(hst = ac->dstnames; hst; hst = hst->next = itcopy(hst->next, sizeof(struct hostname))){
  979. if(hst->name) hst->name = (unsigned char*)mystrdup((char *)hst->name);
  980. }
  981. ac->chains = itcopy(ac->chains, sizeof(struct chain));
  982. for(ch = ac->chains; ch; ch = ch->next = itcopy(ch->next, sizeof(struct chain))){
  983. if(ch->extuser)ch->extuser = (unsigned char*)mystrdup((char *)ch->extuser);
  984. if(ch->extpass)ch->extpass = (unsigned char*)mystrdup((char *)ch->extpass);
  985. if(ch->exthost)ch->exthost = (unsigned char*)mystrdup((char *)ch->exthost);
  986. }
  987. if(preacl){
  988. if(ac->dst || ac->ports || ac->users || ac->dstnames || ac->chains|| ac->action>1){
  989. preacl = 0;
  990. for(acc = srv->preacl; acc; acc=acc->next)if(acc->next == ac) {
  991. acc->next = NULL;
  992. break;
  993. }
  994. srv->acl = ac;
  995. }
  996. else {
  997. if(!srv->preacl) srv->preacl = ac;
  998. }
  999. }
  1000. }
  1001. }
  1002. void copyfilter (struct filter *filter, struct srvparam *srv){
  1003. int nfilters = 0;
  1004. if(!filter) return;
  1005. for(srv->filter = filter; srv->filter; srv->filter = srv->filter->next) nfilters++;
  1006. srv->filter = myalloc(sizeof(struct filter) * nfilters);
  1007. if(!srv->filter) return;
  1008. for(; filter; filter = filter->next){
  1009. void *data = NULL;
  1010. if(!filter->filter_open || !(data = (*filter->filter_open)(filter->data, srv))) continue;
  1011. srv->filter[srv->nfilters] = *filter;
  1012. srv->filter[srv->nfilters].data = data;
  1013. if(srv->nfilters>0)srv->filter[srv->nfilters - 1].next = srv->filter + srv->nfilters;
  1014. srv->nfilters++;
  1015. if(filter->filter_request)srv->nreqfilters++;
  1016. if(filter->filter_header_srv)srv->nhdrfilterssrv++;
  1017. if(filter->filter_header_cli)srv->nhdrfilterscli++;
  1018. if(filter->filter_predata)srv->npredatfilters++;
  1019. if(filter->filter_data_srv)srv->ndatfilterssrv++;
  1020. if(filter->filter_data_cli)srv->ndatfilterscli++;
  1021. }
  1022. }
  1023. FILTER_ACTION makefilters (struct srvparam *srv, struct clientparam *param){
  1024. FILTER_ACTION res=PASS;
  1025. FILTER_ACTION action;
  1026. int i;
  1027. if(!srv->nfilters) return PASS;
  1028. if(!(param->filters = myalloc(sizeof(struct filterp) * srv->nfilters)) ||
  1029. (srv->nreqfilters && !(param->reqfilters = myalloc(sizeof(struct filterp *) * srv->nreqfilters))) ||
  1030. (srv->nhdrfilterssrv && !(param->hdrfilterssrv = myalloc(sizeof(struct filterp *) * srv->nhdrfilterssrv))) ||
  1031. (srv->nhdrfilterscli && !(param->hdrfilterscli = myalloc(sizeof(struct filterp *) * srv->nhdrfilterscli))) ||
  1032. (srv->npredatfilters && !(param->predatfilters = myalloc(sizeof(struct filterp *) * srv->npredatfilters))) ||
  1033. (srv->ndatfilterssrv && !(param->datfilterssrv = myalloc(sizeof(struct filterp *) * srv->ndatfilterssrv))) ||
  1034. (srv->ndatfilterscli && !(param->datfilterscli = myalloc(sizeof(struct filterp *) * srv->ndatfilterscli)))
  1035. ){
  1036. param->res = 21;
  1037. return REJECT;
  1038. }
  1039. for(i=0; i<srv->nfilters; i++){
  1040. if(!srv->filter[i].filter_client)continue;
  1041. action = (*srv->filter[i].filter_client)(srv->filter[i].data, param, &param->filters[param->nfilters].data);
  1042. if(action == PASS) continue;
  1043. if(action > CONTINUE) return action;
  1044. param->filters[param->nfilters].filter = srv->filter + i;
  1045. if(srv->filter[i].filter_request)param->reqfilters[param->nreqfilters++] = param->filters + param->nfilters;
  1046. if(srv->filter[i].filter_header_cli)param->hdrfilterscli[param->nhdrfilterscli++] = param->filters + param->nfilters;
  1047. if(srv->filter[i].filter_header_srv)param->hdrfilterssrv[param->nhdrfilterssrv++] = param->filters + param->nfilters;
  1048. if(srv->filter[i].filter_predata)param->predatfilters[param->npredatfilters++] = param->filters + param->nfilters;
  1049. if(srv->filter[i].filter_data_cli)param->datfilterscli[param->ndatfilterscli++] = param->filters + param->nfilters;
  1050. if(srv->filter[i].filter_data_srv)param->datfilterssrv[param->ndatfilterssrv++] = param->filters + param->nfilters;
  1051. param->nfilters++;
  1052. }
  1053. return res;
  1054. }
  1055. void * itfree(void *data, void * retval){
  1056. myfree(data);
  1057. return retval;
  1058. }
  1059. void freeauth(struct auth * authfuncs){
  1060. for(; authfuncs; authfuncs = (struct auth *)itfree(authfuncs, authfuncs->next));
  1061. }
  1062. void freeacl(struct ace *ac){
  1063. struct iplist *ipl;
  1064. struct portlist *pl;
  1065. struct userlist *ul;
  1066. struct chain *ch;
  1067. struct period *pel;
  1068. struct hostname *hst;
  1069. for(; ac; ac = (struct ace *) itfree(ac, ac->next)){
  1070. for(ipl = ac->src; ipl; ipl = (struct iplist *)itfree(ipl, ipl->next));
  1071. for(ipl = ac->dst; ipl; ipl = (struct iplist *)itfree(ipl,ipl->next));
  1072. for(pl = ac->ports; pl; pl = (struct portlist *)itfree(pl, pl->next));
  1073. for(pel = ac->periods; pel; pel = (struct period *)itfree(pel, pel->next));
  1074. for(ul = ac->users; ul; ul = (struct userlist *)itfree(ul, ul->next)){
  1075. if(ul->user)myfree(ul->user);
  1076. }
  1077. for(hst = ac->dstnames; hst; hst = (struct hostname *)itfree(hst, hst->next)){
  1078. if(hst->name)myfree(hst->name);
  1079. }
  1080. for(ch = ac->chains; ch; ch = (struct chain *) itfree(ch, ch->next)){
  1081. if(ch->extuser) myfree(ch->extuser);
  1082. if(ch->extpass) myfree(ch->extpass);
  1083. if(ch->exthost) myfree(ch->exthost);
  1084. }
  1085. }
  1086. }
  1087. FILTER_ACTION handlereqfilters(struct clientparam *param, unsigned char ** buf_p, int * bufsize_p, int offset, int * length_p){
  1088. FILTER_ACTION action;
  1089. int i;
  1090. for(i=0; i<param->nreqfilters; i++){
  1091. action = (*param->reqfilters[i]->filter->filter_request)(param->reqfilters[i]->data, param, buf_p, bufsize_p, offset, length_p);
  1092. if(action!=CONTINUE) return action;
  1093. }
  1094. return PASS;
  1095. }
  1096. FILTER_ACTION handlehdrfilterssrv(struct clientparam *param, unsigned char ** buf_p, int * bufsize_p, int offset, int * length_p){
  1097. FILTER_ACTION action;
  1098. int i;
  1099. for(i=0; i<param->nhdrfilterssrv; i++){
  1100. action = (*param->hdrfilterssrv[i]->filter->filter_header_srv)(param->hdrfilterssrv[i]->data, param, buf_p, bufsize_p, offset, length_p);
  1101. if(action!=CONTINUE) return action;
  1102. }
  1103. return PASS;
  1104. }
  1105. FILTER_ACTION handlehdrfilterscli(struct clientparam *param, unsigned char ** buf_p, int * bufsize_p, int offset, int * length_p){
  1106. FILTER_ACTION action;
  1107. int i;
  1108. for(i = 0; i < param->nhdrfilterscli; i++){
  1109. action = (*param->hdrfilterscli[i]->filter->filter_header_cli)(param->hdrfilterscli[i]->data, param, buf_p, bufsize_p, offset, length_p);
  1110. if(action!=CONTINUE) return action;
  1111. }
  1112. return PASS;
  1113. }
  1114. #endif
  1115. FILTER_ACTION handlepredatflt(struct clientparam *cparam){
  1116. #ifndef STDMAIN
  1117. FILTER_ACTION action;
  1118. int i;
  1119. for(i=0; i<cparam->npredatfilters ;i++){
  1120. action = (*cparam->predatfilters[i]->filter->filter_predata)(cparam->predatfilters[i]->data, cparam);
  1121. if(action!=CONTINUE) return action;
  1122. }
  1123. #endif
  1124. return PASS;
  1125. }
  1126. FILTER_ACTION handledatfltcli(struct clientparam *cparam, unsigned char ** buf_p, int * bufsize_p, int offset, int * length_p){
  1127. #ifndef STDMAIN
  1128. FILTER_ACTION action;
  1129. int i;
  1130. for(i=0; i<cparam->ndatfilterscli ;i++){
  1131. action = (*cparam->datfilterscli[i]->filter->filter_data_cli)(cparam->datfilterscli[i]->data, cparam, buf_p, bufsize_p, offset, length_p);
  1132. if(action!=CONTINUE) return action;
  1133. }
  1134. #endif
  1135. return PASS;
  1136. }
  1137. FILTER_ACTION handledatfltsrv(struct clientparam *cparam, unsigned char ** buf_p, int * bufsize_p, int offset, int * length_p){
  1138. FILTER_ACTION action;
  1139. int i;
  1140. for(i=0; i<cparam->ndatfilterssrv; i++){
  1141. action = (*cparam->datfilterssrv[i]->filter->filter_data_srv)(cparam->datfilterssrv[i]->data, cparam, buf_p, bufsize_p, offset, length_p);
  1142. if(action!=CONTINUE) return action;
  1143. }
  1144. return PASS;
  1145. }