VirtualBox

source: vbox/trunk/src/VBox/Devices/Network/slirp/socket.c@ 17145

Last change on this file since 17145 was 17145, checked in by vboxsync, 16 years ago

NAT: preventing attempt of double ICMP packet sends, causing crash.

  • Property svn:eol-style set to native
File size: 30.4 KB
Line 
1/*
2 * Copyright (c) 1995 Danny Gasparovski.
3 *
4 * Please read the file COPYRIGHT for the
5 * terms and conditions of the copyright.
6 */
7
8#define WANT_SYS_IOCTL_H
9#include <slirp.h>
10#include "ip_icmp.h"
11#include "main.h"
12#ifdef __sun__
13#include <sys/filio.h>
14#endif
15#if defined (RT_OS_WINDOWS)
16#include <iphlpapi.h>
17#include <icmpapi.h>
18#endif
19
20
21static void send_icmp_to_guest(PNATState, char *, size_t, struct socket *, const struct sockaddr_in *);
22#ifdef RT_OS_WINDOWS
23static void sorecvfrom_icmp_win(PNATState, struct socket *);
24#else /* RT_OS_WINDOWS */
25static void sorecvfrom_icmp_unix(PNATState, struct socket *);
26#endif /* !RT_OS_WINDOWS */
27
28void
29so_init()
30{
31}
32
33
34struct socket *
35solookup(struct socket *head, struct in_addr laddr,
36 u_int lport, struct in_addr faddr, u_int fport)
37{
38 struct socket *so;
39
40 for (so = head->so_next; so != head; so = so->so_next)
41 {
42 if ( so->so_lport == lport
43 && so->so_laddr.s_addr == laddr.s_addr
44 && so->so_faddr.s_addr == faddr.s_addr
45 && so->so_fport == fport)
46 return so;
47 }
48
49 return (struct socket *)NULL;
50}
51
52/*
53 * Create a new socket, initialise the fields
54 * It is the responsibility of the caller to
55 * insque() it into the correct linked-list
56 */
57struct socket *
58socreate()
59{
60 struct socket *so;
61
62 so = (struct socket *)RTMemAllocZ(sizeof(struct socket));
63 if(so)
64 {
65 so->so_state = SS_NOFDREF;
66 so->s = -1;
67#if defined(VBOX_WITH_SIMPLIFIED_SLIRP_SYNC) && !defined(RT_OS_WINDOWS)
68 so->so_poll_index = -1;
69#endif
70 }
71 return so;
72}
73
74/*
75 * remque and free a socket, clobber cache
76 * VBOX_WITH_SLIRP_MT: before sofree queue should be locked, because
77 * in sofree we don't know from which queue item beeing removed.
78 */
79void
80sofree(PNATState pData, struct socket *so)
81{
82 struct socket *so_prev = NULL;
83 if (so == tcp_last_so)
84 tcp_last_so = &tcb;
85 else if (so == udp_last_so)
86 udp_last_so = &udb;
87
88 /* check if mbuf haven't been already freed */
89 if (so->so_m != NULL)
90 m_free(pData, so->so_m);
91#ifndef VBOX_WITH_SLIRP_MT
92 if(so->so_next && so->so_prev)
93 {
94 remque(pData, so); /* crashes if so is not in a queue */
95 NSOCK_DEC();
96 }
97
98 RTMemFree(so);
99#else
100 so->so_deleted = 1;
101#endif
102}
103
104#ifdef VBOX_WITH_SLIRP_MT
105void
106soread_queue(PNATState pData, struct socket *so, int *ret)
107{
108 *ret = soread(pData, so);
109}
110#endif
111
112/*
113 * Read from so's socket into sb_snd, updating all relevant sbuf fields
114 * NOTE: This will only be called if it is select()ed for reading, so
115 * a read() of 0 (or less) means it's disconnected
116 */
117int
118soread(PNATState pData, struct socket *so)
119{
120 int n, nn, lss, total;
121 struct sbuf *sb = &so->so_snd;
122 size_t len = sb->sb_datalen - sb->sb_cc;
123 struct iovec iov[2];
124 int mss = so->so_tcpcb->t_maxseg;
125 QSOCKET_LOCK(tcb);
126 SOCKET_LOCK(so);
127 QSOCKET_UNLOCK(tcb);
128
129 DEBUG_CALL("soread");
130 DEBUG_ARG("so = %lx", (long )so);
131
132 /*
133 * No need to check if there's enough room to read.
134 * soread wouldn't have been called if there weren't
135 */
136
137 len = sb->sb_datalen - sb->sb_cc;
138
139 iov[0].iov_base = sb->sb_wptr;
140 iov[1].iov_base = 0;
141 iov[1].iov_len = 0;
142 if (sb->sb_wptr < sb->sb_rptr)
143 {
144 iov[0].iov_len = sb->sb_rptr - sb->sb_wptr;
145 /* Should never succeed, but... */
146 if (iov[0].iov_len > len)
147 iov[0].iov_len = len;
148 if (iov[0].iov_len > mss)
149 iov[0].iov_len -= iov[0].iov_len%mss;
150 n = 1;
151 }
152 else
153 {
154 iov[0].iov_len = (sb->sb_data + sb->sb_datalen) - sb->sb_wptr;
155 /* Should never succeed, but... */
156 if (iov[0].iov_len > len)
157 iov[0].iov_len = len;
158 len -= iov[0].iov_len;
159 if (len)
160 {
161 iov[1].iov_base = sb->sb_data;
162 iov[1].iov_len = sb->sb_rptr - sb->sb_data;
163 if(iov[1].iov_len > len)
164 iov[1].iov_len = len;
165 total = iov[0].iov_len + iov[1].iov_len;
166 if (total > mss)
167 {
168 lss = total % mss;
169 if (iov[1].iov_len > lss)
170 {
171 iov[1].iov_len -= lss;
172 n = 2;
173 }
174 else
175 {
176 lss -= iov[1].iov_len;
177 iov[0].iov_len -= lss;
178 n = 1;
179 }
180 }
181 else
182 n = 2;
183 }
184 else
185 {
186 if (iov[0].iov_len > mss)
187 iov[0].iov_len -= iov[0].iov_len%mss;
188 n = 1;
189 }
190 }
191
192#ifdef HAVE_READV
193 nn = readv(so->s, (struct iovec *)iov, n);
194 DEBUG_MISC((dfd, " ... read nn = %d bytes\n", nn));
195#else
196 nn = recv(so->s, iov[0].iov_base, iov[0].iov_len,0);
197#endif
198 if (nn <= 0)
199 {
200#if defined(VBOX_WITH_SIMPLIFIED_SLIRP_SYNC) && defined(RT_OS_WINDOWS)
201 /*
202 * Special case for WSAEnumNetworkEvents: If we receive 0 bytes that
203 * _could_ mean that the connection is closed. But we will receive an
204 * FD_CLOSE event later if the connection was _really_ closed. With
205 * www.youtube.com I see this very often. Closing the socket too early
206 * would be dangerous.
207 */
208 int status, ignored;
209 unsigned long pending = 0;
210 status = WSAIoctl(so->s, FIONREAD, NULL, 0, &pending, sizeof(unsigned long), &ignored, NULL, NULL);
211 if (status < 0)
212 LogRel(("NAT:error in WSAIoctl: %d\n", WSAGetLastError()));
213 if (nn == 0 && (pending != 0))
214 {
215 SOCKET_UNLOCK(so);
216 return 0;
217 }
218#endif
219 if (nn < 0 && (errno == EINTR || errno == EAGAIN || errno == EWOULDBLOCK))
220 {
221 SOCKET_UNLOCK(so);
222 return 0;
223 }
224 else
225 {
226 /* nn == 0 means peer has performed an orderly shutdown */
227 DEBUG_MISC((dfd, " --- soread() disconnected, nn = %d, errno = %d-%s\n",
228 nn, errno,strerror(errno)));
229 sofcantrcvmore(so);
230 tcp_sockclosed(pData, sototcpcb(so));
231 SOCKET_UNLOCK(so);
232 return -1;
233 }
234 }
235
236#ifndef HAVE_READV
237 /*
238 * If there was no error, try and read the second time round
239 * We read again if n = 2 (ie, there's another part of the buffer)
240 * and we read as much as we could in the first read
241 * We don't test for <= 0 this time, because there legitimately
242 * might not be any more data (since the socket is non-blocking),
243 * a close will be detected on next iteration.
244 * A return of -1 wont (shouldn't) happen, since it didn't happen above
245 */
246 if (n == 2 && nn == iov[0].iov_len)
247 {
248 int ret;
249 ret = recv(so->s, iov[1].iov_base, iov[1].iov_len,0);
250 if (ret > 0)
251 nn += ret;
252 }
253
254 DEBUG_MISC((dfd, " ... read nn = %d bytes\n", nn));
255#endif
256
257 /* Update fields */
258 sb->sb_cc += nn;
259 sb->sb_wptr += nn;
260 if (sb->sb_wptr >= (sb->sb_data + sb->sb_datalen))
261 sb->sb_wptr -= sb->sb_datalen;
262 SOCKET_UNLOCK(so);
263 return nn;
264}
265
266/*
267 * Get urgent data
268 *
269 * When the socket is created, we set it SO_OOBINLINE,
270 * so when OOB data arrives, we soread() it and everything
271 * in the send buffer is sent as urgent data
272 */
273void
274sorecvoob(PNATState pData, struct socket *so)
275{
276 struct tcpcb *tp = sototcpcb(so);
277
278 DEBUG_CALL("sorecvoob");
279 DEBUG_ARG("so = %lx", (long)so);
280
281 /*
282 * We take a guess at how much urgent data has arrived.
283 * In most situations, when urgent data arrives, the next
284 * read() should get all the urgent data. This guess will
285 * be wrong however if more data arrives just after the
286 * urgent data, or the read() doesn't return all the
287 * urgent data.
288 */
289 soread(pData, so);
290 tp->snd_up = tp->snd_una + so->so_snd.sb_cc;
291 tp->t_force = 1;
292 tcp_output(pData, tp);
293 tp->t_force = 0;
294}
295
296/*
297 * Send urgent data
298 * There's a lot duplicated code here, but...
299 */
300int
301sosendoob(struct socket *so)
302{
303 struct sbuf *sb = &so->so_rcv;
304 char buff[2048]; /* XXX Shouldn't be sending more oob data than this */
305
306 int n, len;
307
308 DEBUG_CALL("sosendoob");
309 DEBUG_ARG("so = %lx", (long)so);
310 DEBUG_ARG("sb->sb_cc = %d", sb->sb_cc);
311
312 if (so->so_urgc > sizeof(buff))
313 so->so_urgc = sizeof(buff); /* XXX */
314
315 if (sb->sb_rptr < sb->sb_wptr)
316 {
317 /* We can send it directly */
318 n = send(so->s, sb->sb_rptr, so->so_urgc, (MSG_OOB)); /* |MSG_DONTWAIT)); */
319 so->so_urgc -= n;
320
321 DEBUG_MISC((dfd, " --- sent %d bytes urgent data, %d urgent bytes left\n",
322 n, so->so_urgc));
323 }
324 else
325 {
326 /*
327 * Since there's no sendv or sendtov like writev,
328 * we must copy all data to a linear buffer then
329 * send it all
330 */
331 len = (sb->sb_data + sb->sb_datalen) - sb->sb_rptr;
332 if (len > so->so_urgc)
333 len = so->so_urgc;
334 memcpy(buff, sb->sb_rptr, len);
335 so->so_urgc -= len;
336 if (so->so_urgc)
337 {
338 n = sb->sb_wptr - sb->sb_data;
339 if (n > so->so_urgc)
340 n = so->so_urgc;
341 memcpy(buff + len, sb->sb_data, n);
342 so->so_urgc -= n;
343 len += n;
344 }
345 n = send(so->s, buff, len, (MSG_OOB)); /* |MSG_DONTWAIT)); */
346#ifdef DEBUG
347 if (n != len)
348 DEBUG_ERROR((dfd, "Didn't send all data urgently XXXXX\n"));
349#endif
350 DEBUG_MISC((dfd, " ---2 sent %d bytes urgent data, %d urgent bytes left\n",
351 n, so->so_urgc));
352 }
353
354 sb->sb_cc -= n;
355 sb->sb_rptr += n;
356 if (sb->sb_rptr >= (sb->sb_data + sb->sb_datalen))
357 sb->sb_rptr -= sb->sb_datalen;
358
359 return n;
360}
361
362/*
363 * Write data from so_rcv to so's socket,
364 * updating all sbuf field as necessary
365 */
366int
367sowrite(PNATState pData, struct socket *so)
368{
369 int n,nn;
370 struct sbuf *sb = &so->so_rcv;
371 size_t len = sb->sb_cc;
372 struct iovec iov[2];
373
374 DEBUG_CALL("sowrite");
375 DEBUG_ARG("so = %lx", (long)so);
376 QSOCKET_LOCK(tcb);
377 SOCKET_LOCK(so);
378 QSOCKET_UNLOCK(tcb);
379 if (so->so_urgc)
380 {
381 sosendoob(so);
382 if (sb->sb_cc == 0)
383 {
384 SOCKET_UNLOCK(so);
385 return 0;
386 }
387 }
388
389 /*
390 * No need to check if there's something to write,
391 * sowrite wouldn't have been called otherwise
392 */
393
394 len = sb->sb_cc;
395
396 iov[0].iov_base = sb->sb_rptr;
397 iov[1].iov_base = 0;
398 iov[1].iov_len = 0;
399 if (sb->sb_rptr < sb->sb_wptr)
400 {
401 iov[0].iov_len = sb->sb_wptr - sb->sb_rptr;
402 /* Should never succeed, but... */
403 if (iov[0].iov_len > len)
404 iov[0].iov_len = len;
405 n = 1;
406 }
407 else
408 {
409 iov[0].iov_len = (sb->sb_data + sb->sb_datalen) - sb->sb_rptr;
410 if (iov[0].iov_len > len)
411 iov[0].iov_len = len;
412 len -= iov[0].iov_len;
413 if (len)
414 {
415 iov[1].iov_base = sb->sb_data;
416 iov[1].iov_len = sb->sb_wptr - sb->sb_data;
417 if (iov[1].iov_len > len)
418 iov[1].iov_len = len;
419 n = 2;
420 }
421 else
422 n = 1;
423 }
424 /* Check if there's urgent data to send, and if so, send it */
425#ifdef HAVE_READV
426 nn = writev(so->s, (const struct iovec *)iov, n);
427 DEBUG_MISC((dfd, " ... wrote nn = %d bytes\n", nn));
428#else
429 nn = send(so->s, iov[0].iov_base, iov[0].iov_len, 0);
430#endif
431 /* This should never happen, but people tell me it does *shrug* */
432 if (nn < 0 && (errno == EAGAIN || errno == EINTR || errno == EWOULDBLOCK))
433 {
434 SOCKET_UNLOCK(so);
435 return 0;
436 }
437
438 if (nn < 0 || (nn == 0 && iov[0].iov_len > 0))
439 {
440 DEBUG_MISC((dfd, " --- sowrite disconnected, so->so_state = %x, errno = %d\n",
441 so->so_state, errno));
442 sofcantsendmore(so);
443 tcp_sockclosed(pData, sototcpcb(so));
444 SOCKET_UNLOCK(so);
445 return -1;
446 }
447
448#ifndef HAVE_READV
449 if (n == 2 && nn == iov[0].iov_len)
450 {
451 int ret;
452 ret = send(so->s, iov[1].iov_base, iov[1].iov_len,0);
453 if (ret > 0)
454 nn += ret;
455 }
456 DEBUG_MISC((dfd, " ... wrote nn = %d bytes\n", nn));
457#endif
458
459 /* Update sbuf */
460 sb->sb_cc -= nn;
461 sb->sb_rptr += nn;
462 if (sb->sb_rptr >= (sb->sb_data + sb->sb_datalen))
463 sb->sb_rptr -= sb->sb_datalen;
464
465 /*
466 * If in DRAIN mode, and there's no more data, set
467 * it CANTSENDMORE
468 */
469 if ((so->so_state & SS_FWDRAIN) && sb->sb_cc == 0)
470 sofcantsendmore(so);
471
472 SOCKET_UNLOCK(so);
473 return nn;
474}
475
476/*
477 * recvfrom() a UDP socket
478 */
479void
480sorecvfrom(PNATState pData, struct socket *so)
481{
482 struct sockaddr_in addr;
483 socklen_t addrlen = sizeof(struct sockaddr_in);
484
485 DEBUG_CALL("sorecvfrom");
486 DEBUG_ARG("so = %lx", (long)so);
487
488 if (so->so_type == IPPROTO_ICMP)
489 {
490 /* This is a "ping" reply */
491#ifdef RT_OS_WINDOWS
492 sorecvfrom_icmp_win(pData, so);
493#else /* RT_OS_WINDOWS */
494 sorecvfrom_icmp_unix(pData, so);
495#endif /* !RT_OS_WINDOWS */
496 udp_detach(pData, so);
497 }
498 else
499 {
500 /* A "normal" UDP packet */
501 struct mbuf *m;
502 size_t len;
503 u_long n;
504
505 QSOCKET_LOCK(udb);
506 SOCKET_LOCK(so);
507 QSOCKET_UNLOCK(udb);
508
509 if (!(m = m_get(pData)))
510 {
511 SOCKET_UNLOCK(so);
512 return;
513 }
514 m->m_data += if_maxlinkhdr;
515#ifdef VBOX_WITH_SIMPLIFIED_SLIRP_SYNC
516 m->m_data += sizeof(struct udphdr)
517 + sizeof(struct ip); /*XXX: no options atm*/
518#endif
519
520 /*
521 * XXX Shouldn't FIONREAD packets destined for port 53,
522 * but I don't know the max packet size for DNS lookups
523 */
524 len = M_FREEROOM(m);
525 /* if (so->so_fport != htons(53)) */
526 {
527 ioctlsocket(so->s, FIONREAD, &n);
528
529 if (n > len)
530 {
531 n = (m->m_data - m->m_dat) + m->m_len + n + 1;
532 m_inc(m, n);
533 len = M_FREEROOM(m);
534 }
535 }
536
537 m->m_len = recvfrom(so->s, m->m_data, len, 0,
538 (struct sockaddr *)&addr, &addrlen);
539 Log2((" did recvfrom %d, errno = %d-%s\n",
540 m->m_len, errno,strerror(errno)));
541 if(m->m_len < 0)
542 {
543 u_char code = ICMP_UNREACH_PORT;
544
545 if (errno == EHOSTUNREACH)
546 code = ICMP_UNREACH_HOST;
547 else if(errno == ENETUNREACH)
548 code = ICMP_UNREACH_NET;
549
550 Log2((dfd," rx error, tx icmp ICMP_UNREACH:%i\n", code));
551 icmp_error(pData, so->so_m, ICMP_UNREACH,code, 0,strerror(errno));
552 so->so_m = NULL;
553 m_free(pData, m);
554 }
555 else
556 {
557 /*
558 * Hack: domain name lookup will be used the most for UDP,
559 * and since they'll only be used once there's no need
560 * for the 4 minute (or whatever) timeout... So we time them
561 * out much quicker (10 seconds for now...)
562 */
563 if (so->so_expire)
564 {
565 if (so->so_fport == htons(53))
566 so->so_expire = curtime + SO_EXPIREFAST;
567 else
568 so->so_expire = curtime + SO_EXPIRE;
569 }
570
571#if 0
572 if (m->m_len == len)
573 {
574 m_inc(m, MINCSIZE);
575 m->m_len = 0;
576 }
577#endif
578
579 /*
580 * If this packet was destined for CTL_ADDR,
581 * make it look like that's where it came from, done by udp_output
582 */
583 udp_output(pData, so, m, &addr);
584 SOCKET_UNLOCK(so);
585 } /* rx error */
586 } /* if ping packet */
587}
588
589/*
590 * sendto() a socket
591 */
592int
593sosendto(PNATState pData, struct socket *so, struct mbuf *m)
594{
595 int ret;
596 struct sockaddr_in addr;
597#if 0
598 struct sockaddr_in host_addr;
599#endif
600
601 DEBUG_CALL("sosendto");
602 DEBUG_ARG("so = %lx", (long)so);
603 DEBUG_ARG("m = %lx", (long)m);
604
605 addr.sin_family = AF_INET;
606 if ((so->so_faddr.s_addr & htonl(pData->netmask)) == special_addr.s_addr)
607 {
608 /* It's an alias */
609 uint32_t last_byte = ntohl(so->so_faddr.s_addr) & ~pData->netmask;
610 switch(last_byte)
611 {
612#if 0
613 /* handle this case at 'default:' */
614 case CTL_BROADCAST:
615 addr.sin_addr.s_addr = INADDR_BROADCAST;
616 /* Send the packet to host to fully emulate broadcast */
617 /** @todo r=klaus: on Linux host this causes the host to receive
618 * the packet twice for some reason. And I cannot find any place
619 * in the man pages which states that sending a broadcast does not
620 * reach the host itself. */
621 host_addr.sin_family = AF_INET;
622 host_addr.sin_port = so->so_fport;
623 host_addr.sin_addr = our_addr;
624 sendto(so->s, m->m_data, m->m_len, 0,
625 (struct sockaddr *)&host_addr, sizeof (struct sockaddr));
626 break;
627#endif
628 case CTL_DNS:
629#ifndef VBOX_WITH_MULTI_DNS
630 if (!get_dns_addr(pData, &dns_addr))
631 addr.sin_addr = dns_addr;
632 else
633 addr.sin_addr = loopback_addr;
634 break;
635#endif
636 case CTL_ALIAS:
637 default:
638 if (last_byte == ~pData->netmask)
639 addr.sin_addr.s_addr = INADDR_BROADCAST;
640 else
641 addr.sin_addr = loopback_addr;
642 break;
643 }
644 }
645 else
646 addr.sin_addr = so->so_faddr;
647 addr.sin_port = so->so_fport;
648
649 DEBUG_MISC((dfd, " sendto()ing, addr.sin_port=%d, addr.sin_addr.s_addr=%.16s\n",
650 ntohs(addr.sin_port), inet_ntoa(addr.sin_addr)));
651
652 /* Don't care what port we get */
653 ret = sendto(so->s, m->m_data, m->m_len, 0,
654 (struct sockaddr *)&addr, sizeof (struct sockaddr));
655 if (ret < 0)
656 {
657 LogRel(("UDP: sendto fails (%s)\n", strerror(errno)));
658 return -1;
659 }
660
661 /*
662 * Kill the socket if there's no reply in 4 minutes,
663 * but only if it's an expirable socket
664 */
665 if (so->so_expire)
666 so->so_expire = curtime + SO_EXPIRE;
667 so->so_state = SS_ISFCONNECTED; /* So that it gets select()ed */
668 return 0;
669}
670
671/*
672 * XXX This should really be tcp_listen
673 */
674struct socket *
675solisten(PNATState pData, u_int port, u_int32_t laddr, u_int lport, int flags)
676{
677 struct sockaddr_in addr;
678 struct socket *so;
679 socklen_t addrlen = sizeof(addr);
680 int s, opt = 1;
681
682 DEBUG_CALL("solisten");
683 DEBUG_ARG("port = %d", port);
684 DEBUG_ARG("laddr = %x", laddr);
685 DEBUG_ARG("lport = %d", lport);
686 DEBUG_ARG("flags = %x", flags);
687
688 if ((so = socreate()) == NULL)
689 {
690 /* RTMemFree(so); Not sofree() ??? free(NULL) == NOP */
691 return NULL;
692 }
693
694 /* Don't tcp_attach... we don't need so_snd nor so_rcv */
695 if ((so->so_tcpcb = tcp_newtcpcb(pData, so)) == NULL)
696 {
697 RTMemFree(so);
698 return NULL;
699 }
700
701 SOCKET_LOCK_CREATE(so);
702 SOCKET_LOCK(so);
703 QSOCKET_LOCK(tcb);
704 insque(pData, so,&tcb);
705 NSOCK_INC();
706 QSOCKET_UNLOCK(tcb);
707
708 /*
709 * SS_FACCEPTONCE sockets must time out.
710 */
711 if (flags & SS_FACCEPTONCE)
712 so->so_tcpcb->t_timer[TCPT_KEEP] = TCPTV_KEEP_INIT*2;
713
714 so->so_state = (SS_FACCEPTCONN|flags);
715 so->so_lport = lport; /* Kept in network format */
716 so->so_laddr.s_addr = laddr; /* Ditto */
717
718 addr.sin_family = AF_INET;
719 addr.sin_addr.s_addr = INADDR_ANY;
720 addr.sin_port = port;
721
722 if ( ((s = socket(AF_INET,SOCK_STREAM,0)) < 0)
723 || (setsockopt(s,SOL_SOCKET,SO_REUSEADDR,(char *)&opt,sizeof(int)) < 0)
724 || (bind(s,(struct sockaddr *)&addr, sizeof(addr)) < 0)
725 || (listen(s,1) < 0))
726 {
727#ifdef RT_OS_WINDOWS
728 int tmperrno = WSAGetLastError(); /* Don't clobber the real reason we failed */
729 closesocket(s);
730 QSOCKET_LOCK(tcb);
731 sofree(pData, so);
732 QSOCKET_UNLOCK(tcb);
733 /* Restore the real errno */
734 WSASetLastError(tmperrno);
735#else
736 int tmperrno = errno; /* Don't clobber the real reason we failed */
737 close(s);
738 QSOCKET_LOCK(tcb);
739 sofree(pData, so);
740 QSOCKET_UNLOCK(tcb);
741 /* Restore the real errno */
742 errno = tmperrno;
743#endif
744 return NULL;
745 }
746 setsockopt(s,SOL_SOCKET,SO_OOBINLINE,(char *)&opt,sizeof(int));
747
748 getsockname(s,(struct sockaddr *)&addr,&addrlen);
749 so->so_fport = addr.sin_port;
750 if (addr.sin_addr.s_addr == 0 || addr.sin_addr.s_addr == loopback_addr.s_addr)
751 so->so_faddr = alias_addr;
752 else
753 so->so_faddr = addr.sin_addr;
754
755 so->s = s;
756 SOCKET_UNLOCK(so);
757 return so;
758}
759
760/*
761 * Data is available in so_rcv
762 * Just write() the data to the socket
763 * XXX not yet...
764 */
765void
766sorwakeup(struct socket *so)
767{
768#if 0
769 sowrite(so);
770 FD_CLR(so->s,&writefds);
771#endif
772}
773
774/*
775 * Data has been freed in so_snd
776 * We have room for a read() if we want to
777 * For now, don't read, it'll be done in the main loop
778 */
779void
780sowwakeup(struct socket *so)
781{
782}
783
784/*
785 * Various session state calls
786 * XXX Should be #define's
787 * The socket state stuff needs work, these often get call 2 or 3
788 * times each when only 1 was needed
789 */
790void
791soisfconnecting(struct socket *so)
792{
793 so->so_state &= ~(SS_NOFDREF|SS_ISFCONNECTED|SS_FCANTRCVMORE|
794 SS_FCANTSENDMORE|SS_FWDRAIN);
795 so->so_state |= SS_ISFCONNECTING; /* Clobber other states */
796}
797
798void
799soisfconnected(struct socket *so)
800{
801 so->so_state &= ~(SS_ISFCONNECTING|SS_FWDRAIN|SS_NOFDREF);
802 so->so_state |= SS_ISFCONNECTED; /* Clobber other states */
803}
804
805void
806sofcantrcvmore(struct socket *so)
807{
808 if ((so->so_state & SS_NOFDREF) == 0)
809 {
810 shutdown(so->s,0);
811 }
812 so->so_state &= ~(SS_ISFCONNECTING);
813 if (so->so_state & SS_FCANTSENDMORE)
814 so->so_state = SS_NOFDREF; /* Don't select it */
815 /* XXX close() here as well? */
816 else
817 so->so_state |= SS_FCANTRCVMORE;
818}
819
820void
821sofcantsendmore(struct socket *so)
822{
823 if ((so->so_state & SS_NOFDREF) == 0)
824 shutdown(so->s, 1); /* send FIN to fhost */
825
826 so->so_state &= ~(SS_ISFCONNECTING);
827 if (so->so_state & SS_FCANTRCVMORE)
828 so->so_state = SS_NOFDREF; /* as above */
829 else
830 so->so_state |= SS_FCANTSENDMORE;
831}
832
833void
834soisfdisconnected(struct socket *so)
835{
836#if 0
837 so->so_state &= ~(SS_ISFCONNECTING|SS_ISFCONNECTED);
838 close(so->s);
839 so->so_state = SS_ISFDISCONNECTED;
840 /*
841 * XXX Do nothing ... ?
842 */
843#endif
844}
845
846/*
847 * Set write drain mode
848 * Set CANTSENDMORE once all data has been write()n
849 */
850void
851sofwdrain(struct socket *so)
852{
853 if (so->so_rcv.sb_cc)
854 so->so_state |= SS_FWDRAIN;
855 else
856 sofcantsendmore(so);
857}
858
859static void
860send_icmp_to_guest(PNATState pData, char *buff, size_t len, struct socket *so, const struct sockaddr_in *addr)
861{
862 struct ip *ip;
863 uint32_t dst,src;
864 char ip_copy[256];
865 struct icmp *icp;
866 int old_ip_len = 0;
867 int hlen, original_hlen = 0;
868 struct mbuf *m;
869 struct icmp_msg *icm;
870 uint8_t proto;
871 int type = 0;
872
873 ip = (struct ip *)buff;
874 hlen = (ip->ip_hl << 2);
875 icp = (struct icmp *)((char *)ip + hlen);
876
877 Log(("ICMP:received msg(t:%d, c:%d)\n", icp->icmp_type, icp->icmp_code));
878 if ( icp->icmp_type != ICMP_ECHOREPLY
879 && icp->icmp_type != ICMP_TIMXCEED
880 && icp->icmp_type != ICMP_UNREACH)
881 {
882 return;
883 }
884
885 type = icp->icmp_type;
886 if ( type == ICMP_TIMXCEED
887 || type == ICMP_UNREACH)
888 {
889 ip = &icp->icmp_ip;
890 DO_ALIAS(&ip->ip_dst);
891 }
892 else
893 {
894 DO_ALIAS(&ip->ip_src);
895 }
896
897 icm = icmp_find_original_mbuf(pData, ip);
898
899 if (icm == NULL)
900 {
901 Log(("NAT: Can't find the corresponding packet for the received ICMP\n"));
902 return;
903 }
904
905 m = icm->im_m;
906 Assert(m != NULL);
907
908 src = addr->sin_addr.s_addr;
909
910 ip = mtod(m, struct ip *);
911 proto = ip->ip_p;
912 /* Now ip is pointing on header we've sent from guest */
913 if ( icp->icmp_type == ICMP_TIMXCEED
914 || icp->icmp_type == ICMP_UNREACH)
915 {
916 old_ip_len = (ip->ip_hl << 2) + 64;
917 if (old_ip_len > sizeof(ip_copy))
918 old_ip_len = sizeof(ip_copy);
919 memcpy(ip_copy, ip, old_ip_len);
920 }
921
922 /* source address from original IP packet*/
923 dst = ip->ip_src.s_addr;
924
925 /* overide ther tail of old packet */
926 ip = mtod(m, struct ip *); /* ip is from mbuf we've overrided */
927 original_hlen = ip->ip_hl << 2;
928 /* saves original ip header and options */
929 memcpy(m->m_data + original_hlen, buff + hlen, len - hlen);
930 m->m_len = len - hlen + original_hlen;
931 ip->ip_len = m->m_len;
932 ip->ip_p = IPPROTO_ICMP; /* the original package could be whatever, but we're response via ICMP*/
933
934 icp = (struct icmp *)((char *)ip + (ip->ip_hl << 2));
935 type = icp->icmp_type;
936 if ( type == ICMP_TIMXCEED
937 || type == ICMP_UNREACH)
938 {
939 /* according RFC 793 error messages required copy of initial IP header + 64 bit */
940 memcpy(&icp->icmp_ip, ip_copy, old_ip_len);
941 ip->ip_tos = ((ip->ip_tos & 0x1E) | 0xC0); /* high priority for errors */
942 }
943
944 ip->ip_src.s_addr = src;
945 ip->ip_dst.s_addr = dst;
946 icmp_reflect(pData, m);
947 LIST_REMOVE(icm, im_list);
948 /* Don't call m_free here*/
949
950 if ( type == ICMP_TIMXCEED
951 || type == ICMP_UNREACH)
952 {
953 icm->im_so->so_m = NULL;
954 switch (proto)
955 {
956 case IPPROTO_UDP:
957 /*XXX: so->so_m already freed so we shouldn't call sofree */
958 udp_detach(pData, icm->im_so);
959 break;
960 case IPPROTO_TCP:
961 /*close tcp should be here */
962 break;
963 default:
964 /* do nothing */
965 break;
966 }
967 }
968 RTMemFree(icm);
969}
970
971#ifdef RT_OS_WINDOWS
972static void
973sorecvfrom_icmp_win(PNATState pData, struct socket *so)
974{
975 int len;
976 int i;
977 struct ip *ip;
978 struct mbuf *m;
979 struct icmp *icp;
980 struct icmp_msg *icm;
981 struct ip *ip_broken; /* ICMP returns header + 64 bit of packet */
982 uint32_t src;
983 ICMP_ECHO_REPLY *icr;
984 int hlen = 0;
985 int data_len = 0;
986 int nbytes = 0;
987 u_char code = ~0;
988
989 len = pData->pfIcmpParseReplies(pData->pvIcmpBuffer, pData->szIcmpBuffer);
990#ifndef VBOX_WITH_SIMPLIFIED_SLIRP_SYNC
991 fIcmp = 0; /* reply processed */
992#endif
993 if (len < 0)
994 {
995 LogRel(("NAT: Error (%d) occurred on ICMP receiving\n", GetLastError()));
996 return;
997 }
998 if (len == 0)
999 return; /* no error */
1000
1001 icr = (ICMP_ECHO_REPLY *)pData->pvIcmpBuffer;
1002 for (i = 0; i < len; ++i)
1003 {
1004 switch(icr[i].Status)
1005 {
1006 case IP_DEST_HOST_UNREACHABLE:
1007 code = (code != ~0 ? code : ICMP_UNREACH_HOST);
1008 case IP_DEST_NET_UNREACHABLE:
1009 code = (code != ~0 ? code : ICMP_UNREACH_NET);
1010 case IP_DEST_PROT_UNREACHABLE:
1011 code = (code != ~0 ? code : ICMP_UNREACH_PROTOCOL);
1012 /* UNREACH error inject here */
1013 case IP_DEST_PORT_UNREACHABLE:
1014 code = (code != ~0 ? code : ICMP_UNREACH_PORT);
1015 icmp_error(pData, so->so_m, ICMP_UNREACH, code, 0, "Error occurred!!!");
1016 so->so_m = NULL;
1017 break;
1018 case IP_SUCCESS: /* echo replied */
1019 m = m_get(pData);
1020 m->m_data += if_maxlinkhdr;
1021 ip = mtod(m, struct ip *);
1022 ip->ip_src.s_addr = icr[i].Address;
1023 DO_ALIAS(&ip->ip_src);
1024 ip->ip_p = IPPROTO_ICMP;
1025 ip->ip_dst.s_addr = so->so_laddr.s_addr; /*XXX: still the hack*/
1026 data_len = sizeof(struct ip);
1027 ip->ip_hl = data_len >> 2; /* requiered for icmp_reflect, no IP options */
1028 ip->ip_ttl = icr[i].Options.Ttl;
1029
1030 icp = (struct icmp *)&ip[1]; /* no options */
1031 icp->icmp_type = ICMP_ECHOREPLY;
1032 icp->icmp_code = 0;
1033 icp->icmp_id = so->so_icmp_id;
1034 icp->icmp_seq = so->so_icmp_seq;
1035
1036 data_len += ICMP_MINLEN;
1037
1038 nbytes = (data_len + icr[i].DataSize > m->m_size? m->m_size - data_len: icr[i].DataSize);
1039 memcpy(icp->icmp_data, icr[i].Data, nbytes);
1040
1041 data_len += icr[i].DataSize;
1042
1043 ip->ip_len = data_len;
1044 m->m_len = ip->ip_len;
1045
1046 icmp_reflect(pData, m);
1047 break;
1048 case IP_TTL_EXPIRED_TRANSIT: /* TTL expired */
1049
1050 ip_broken = icr[i].Data;
1051 icm = icmp_find_original_mbuf(pData, ip_broken);
1052 if (icm == NULL) {
1053 Log(("ICMP: can't find original package (first double word %x)\n", *(uint32_t *)ip_broken));
1054 return;
1055 }
1056 m = icm->im_m;
1057 ip = mtod(m, struct ip *);
1058 ip->ip_ttl = icr[i].Options.Ttl;
1059 src = ip->ip_src.s_addr;
1060 ip->ip_dst.s_addr = src;
1061 ip->ip_dst.s_addr = icr[i].Address;
1062
1063 hlen = (ip->ip_hl << 2);
1064 icp = (struct icmp *)((char *)ip + hlen);
1065 ip_broken->ip_src.s_addr = src; /*it packet sent from host not from guest*/
1066 data_len = (ip_broken->ip_hl << 2) + 64;
1067
1068 nbytes =(hlen + ICMP_MINLEN + data_len > m->m_size? m->m_size - (hlen + ICMP_MINLEN): data_len);
1069 memcpy(icp->icmp_data, ip_broken, nbytes);
1070 icmp_reflect(pData, m);
1071 break;
1072 default:
1073 Log(("ICMP(default): message with Status: %x was received from %x\n", icr[i].Status, icr[i].Address));
1074 break;
1075 }
1076 }
1077}
1078#else /* RT_OS_WINDOWS */
1079static void sorecvfrom_icmp_unix(PNATState pData, struct socket *so)
1080{
1081 struct sockaddr_in addr;
1082 socklen_t addrlen = sizeof(struct sockaddr_in);
1083 char buff[1500];
1084 int len;
1085 len = recvfrom(so->s, buff, 1500, 0,
1086 (struct sockaddr *)&addr, &addrlen);
1087 /* XXX Check if reply is "correct"? */
1088
1089 if (len == -1 || len == 0)
1090 {
1091 u_char code = ICMP_UNREACH_PORT;
1092
1093 if (errno == EHOSTUNREACH)
1094 code = ICMP_UNREACH_HOST;
1095 else if(errno == ENETUNREACH)
1096 code = ICMP_UNREACH_NET;
1097
1098 DEBUG_MISC((dfd," udp icmp rx errno = %d-%s\n",
1099 errno,strerror(errno)));
1100 icmp_error(pData, so->so_m, ICMP_UNREACH,code, 0,strerror(errno));
1101 so->so_m = NULL;
1102 }
1103 else
1104 {
1105 send_icmp_to_guest(pData, buff, len, so, &addr);
1106 }
1107}
1108#endif /* !RT_OS_WINDOWS */
Note: See TracBrowser for help on using the repository browser.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette