diff options
| author | Adam <Adam@anope.org> | 2010-10-01 21:01:49 -0400 |
|---|---|---|
| committer | Adam <Adam@anope.org> | 2010-10-01 21:01:49 -0400 |
| commit | d44f7971b129aa7ba80999f16f17b8c7499686e1 (patch) | |
| tree | a86d08c3e641ed6b499b53b3bbb74e2a7f5b0dfb | |
| parent | 70056dd4689eeab4f7a9b31a921e0d7e40d5ed0d (diff) | |
Rewrote some of the socket code to allow m_ssl to be a service.
This allows modules (xmlrpc) to create and accept SSL connections.
Also fixed unloading m_mysql at certain times and made the threading
engine always work correctly on Windows.
| -rw-r--r-- | include/dns.h | 5 | ||||
| -rw-r--r-- | include/extern.h | 14 | ||||
| -rw-r--r-- | include/modules.h | 8 | ||||
| -rw-r--r-- | include/sockets.h | 260 | ||||
| -rw-r--r-- | include/threadengine.h | 7 | ||||
| -rw-r--r-- | modules/extra/db_mysql.cpp | 2 | ||||
| -rw-r--r-- | modules/extra/m_mysql.cpp | 8 | ||||
| -rw-r--r-- | modules/extra/m_ssl.cpp | 246 | ||||
| -rw-r--r-- | modules/extra/ssl.h | 9 | ||||
| -rw-r--r-- | modules/socketengines/m_socketengine_epoll.cpp | 8 | ||||
| -rw-r--r-- | modules/socketengines/m_socketengine_select.cpp | 26 | ||||
| -rwxr-xr-x | src/bin/mydbgen | 1 | ||||
| -rw-r--r-- | src/dns.cpp | 15 | ||||
| -rw-r--r-- | src/mail.cpp | 4 | ||||
| -rw-r--r-- | src/main.cpp | 40 | ||||
| -rw-r--r-- | src/misc.cpp | 2 | ||||
| -rw-r--r-- | src/modules.cpp | 1 | ||||
| -rw-r--r-- | src/socketengines/socketengine_eventfd.cpp | 41 | ||||
| -rw-r--r-- | src/socketengines/socketengine_pipe.cpp | 3 | ||||
| -rw-r--r-- | src/socketengines/socketengine_win32.cpp | 7 | ||||
| -rw-r--r-- | src/sockets.cpp | 324 | ||||
| -rw-r--r-- | src/threadengine.cpp | 23 | ||||
| -rw-r--r-- | src/threadengines/threadengine_pthread.cpp | 8 | ||||
| -rw-r--r-- | src/threadengines/threadengine_win32.cpp | 6 | ||||
| -rw-r--r-- | src/users.cpp | 1 |
25 files changed, 721 insertions, 348 deletions
diff --git a/include/dns.h b/include/dns.h index 8a7d7a4a2..7bfdac59a 100644 --- a/include/dns.h +++ b/include/dns.h @@ -126,13 +126,14 @@ struct DNSRecord /** The socket used to talk to the nameserver, uses UDP */ -class DNSSocket : public ClientSocket +class DNSSocket : public ConnectionSocket { private: int SendTo(const unsigned char *buf, size_t len) const; int RecvFrom(char *buf, size_t size, sockaddrs &addrs) const; + public: - DNSSocket(const Anope::string &nTargetHost, int Port); + DNSSocket(); virtual ~DNSSocket(); bool ProcessRead(); diff --git a/include/extern.h b/include/extern.h index 249ac6dfb..12fbcbbc5 100644 --- a/include/extern.h +++ b/include/extern.h @@ -183,13 +183,24 @@ E Anope::string quitmsg; E bool save_data; E time_t start_time; -E Socket *UplinkSock; +E ConnectionSocket *UplinkSock; E void save_databases(); E void expire_all(); E void sighandler(int signum); E void do_restart_services(); +/* The socket to our uplink */ +class UplinkSocket : public ConnectionSocket +{ + public: + UplinkSocket(bool ipv6 = false); + + virtual ~UplinkSocket(); + + bool Read(const Anope::string &buf); +}; + /**** memory.c ****/ E void *scalloc(long elsize, long els); @@ -334,6 +345,7 @@ E int exception_add(User *u, const Anope::string &mask, int limit, const Anope:: E SocketEngineBase *SocketEngine; E int32 TotalRead; E int32 TotalWritten; +E SocketIO normalSocketIO; /**** users.c ****/ diff --git a/include/modules.h b/include/modules.h index 53cd81340..ab3472132 100644 --- a/include/modules.h +++ b/include/modules.h @@ -1236,11 +1236,10 @@ class Service : public virtual Base template<typename T> class service_reference : public dynamic_reference<T> { - Module *owner; Anope::string name; public: - service_reference(Module *o, const Anope::string &n) : dynamic_reference<T>(static_cast<T *>(ModuleManager::GetService(this->name))), owner(o), name(n) + service_reference(const Anope::string &n) : dynamic_reference<T>(static_cast<T *>(ModuleManager::GetService(n))), name(n) { } @@ -1263,11 +1262,6 @@ class service_reference : public dynamic_reference<T> } return this->ref; } - - inline T *operator->() - { - return this->ref; - } }; struct Message diff --git a/include/sockets.h b/include/sockets.h index 38060ed78..847e91309 100644 --- a/include/sockets.h +++ b/include/sockets.h @@ -30,6 +30,14 @@ union CoreExport sockaddrs sockaddr_in sa4; sockaddr_in6 sa6; + /** Construct the object, sets everything to 0 + */ + sockaddrs(); + + /** Memset the object to 0 + */ + void clear(); + /** Get the size of the sockaddr we represent * @return The size */ @@ -45,10 +53,6 @@ union CoreExport sockaddrs */ Anope::string addr() const; - /** Construct the object, sets everything to 0 - */ - sockaddrs(); - /** Check if this sockaddr has data in it */ bool operator()() const; @@ -92,6 +96,9 @@ class SocketException : public CoreException enum SocketType { + SOCKTYPE_BASE, + SOCKTYPE_BUFFERED, + SOCKTYPE_CONNECTION, SOCKTYPE_CLIENT, SOCKTYPE_LISTEN }; @@ -102,34 +109,59 @@ enum SocketFlag SF_WRITABLE }; -class CoreExport Socket : public Flags<SocketFlag, 2> +class Socket; +class ClientSocket; +class ListenSocket; +class ConnectionSocket; + +class SocketIO { - protected: - /** Really receive something from the buffer + public: + /** Receive something from the buffer + * @param s The socket * @param buf The buf to read to * @param sz How much to read * @return Number of bytes received */ - virtual int RecvInternal(char *buf, size_t sz) const; + virtual int Recv(Socket *s, char *buf, size_t sz) const; - /** Really write something to the socket + /** Write something to the socket + * @param s The socket * @param buf What to write * @return Number of bytes written */ - virtual int SendInternal(const Anope::string &buf) const; + virtual int Send(Socket *s, const Anope::string &buf) const; + + /** Accept a connection from a socket + * @param s The socket + */ + virtual void Accept(ListenSocket *s); + + /** Connect the socket + * @param s THe socket + * @param target IP to connect to + * @param port to connect to + * @param bindip IP to bind to, if any + */ + virtual void Connect(ConnectionSocket *s, const Anope::string &target, int port, const Anope::string &bindip = ""); + /** Called when the socket is destructing + */ + virtual void Destroy() { } +}; + +class CoreExport Socket : public Flags<SocketFlag, 2>, public virtual Base +{ + protected: /* Socket FD */ int Sock; /* Is this an IPv6 socket? */ bool IPv6; - /* Things to be written to the socket */ - std::string WriteBuffer; - /* Part of a message sent from the server, but not totally received */ - std::string extrabuf; - /* How much data was received from this socket */ - size_t RecvLen; public: + /* I/O functions used for this socket */ + SocketIO *IO; + /* Type this socket is */ SocketType Type; @@ -138,11 +170,11 @@ class CoreExport Socket : public Flags<SocketFlag, 2> Socket(); /** Default constructor - * @param nsock The socket to use, 0 if we need to create our own - * @param nIPv6 true if using ipv6 + * @param sock The socket to use, 0 if we need to create our own + * @param ipv6 true if using ipv6 * @param type The socket type, defaults to SOCK_STREAM */ - Socket(int nsock, bool nIPv6, int type = SOCK_STREAM); + Socket(int sock, bool ipv6, int type = SOCK_STREAM); /** Default destructor */ @@ -151,7 +183,12 @@ class CoreExport Socket : public Flags<SocketFlag, 2> /** Get the socket FD for this socket * @return the fd */ - int GetSock() const; + int GetFD() const; + + /** Check if this socket is IPv6 + * @return true or false + */ + bool IsIPv6() const; /** Mark a socket as blockig * @return true if the socket is now blocking @@ -163,21 +200,6 @@ class CoreExport Socket : public Flags<SocketFlag, 2> */ bool SetNonBlocking(); - /** Check if this socket is IPv6 - * @return true or false - */ - bool IsIPv6() const; - - /** Get the length of the read buffer - * @return The length of the read buffer - */ - size_t ReadBufferLen() const; - - /** Get the length of the write buffer - * @return The length of the write buffer - */ - size_t WriteBufferLen() const; - /** Called when there is something to be received for this socket * @return true on success, false to drop this socket */ @@ -192,6 +214,43 @@ class CoreExport Socket : public Flags<SocketFlag, 2> * @return true on success, false to drop this socket */ virtual void ProcessError(); +}; + +class CoreExport BufferedSocket : public Socket +{ + protected: + /* Things to be written to the socket */ + std::string WriteBuffer; + /* Part of a message sent from the server, but not totally received */ + std::string extrabuf; + /* How much data was received from this socket */ + size_t RecvLen; + + public: + /** Blank constructor + */ + BufferedSocket(); + + /** Constructor + * @param fd FD to use + * @param ipv6 true for ipv6 + * @param type socket type, defaults to SOCK_STREAM + */ + BufferedSocket(int fd, bool ipv6, int type = SOCK_STREAM); + + /** Default destructor + */ + virtual ~BufferedSocket(); + + /** Called when there is something to be received for this socket + * @return true on success, false to drop this socket + */ + bool ProcessRead(); + + /** Called when the socket is ready to be written to + * @return true on success, false to drop this socket + */ + bool ProcessWrite(); /** Called with a line received from the socket * @param buf The line @@ -200,106 +259,119 @@ class CoreExport Socket : public Flags<SocketFlag, 2> virtual bool Read(const Anope::string &buf); /** Write to the socket - * @param message The message - */ + * @param message The message + */ void Write(const char *message, ...); void Write(const Anope::string &message); -}; -class CoreExport Pipe : public Socket -{ - private: - /** The FD of the write pipe (if this isn't evenfd) - * this->Sock is the readfd + /** Get the length of the read buffer + * @return The length of the read buffer */ - int WritePipe; + size_t ReadBufferLen() const; - /** Our overloaded RecvInternal call + /** Get the length of the write buffer + * @return The length of the write buffer */ - int RecvInternal(char *buf, size_t sz) const; + size_t WriteBufferLen() const; +}; - /** Our overloaded SendInternal call - */ - int SendInternal(const Anope::string &buf) const; - public: - /** Constructor - */ - Pipe(); +class CoreExport ListenSocket : public Socket +{ + protected: + /* Sockaddrs for bindip/port */ + sockaddrs listenaddrs; - /** Called when data is to be read + public: + /** Constructor + * @param bindip The IP to bind to + * @param port The port to listen on + * @param ipv6 true for ipv6 */ - bool ProcessRead(); + ListenSocket(const Anope::string &bindip, int port, bool ipv6); - /** Function that calls OnNotify + /** Destructor */ - bool Read(const Anope::string &); + virtual ~ListenSocket(); - /** Called when this pipe needs to be woken up + /** Process what has come in from the connection + * @return false to destory this socket */ - void Notify(); + bool ProcessRead(); - /** Should be overloaded to do something useful + /** Called when a connection is accepted + * @param fd The FD for the new connection + * @param addr The sockaddr for where the connection came from + * @return The new socket */ - virtual void OnNotify(); + virtual ClientSocket *OnAccept(int fd, const sockaddrs &addr); }; -class CoreExport ClientSocket : public Socket +class ConnectionSocket : public BufferedSocket { - protected: + public: /* Sockaddrs for bindip (if there is one) */ - sockaddrs bindaddrs; + sockaddrs bindaddr; /* Sockaddrs for connection ip/port */ - sockaddrs conaddrs; - - public: + sockaddrs conaddr; /** Constructor + * @param ipv6 true to use IPv6 + * @param type The socket type, defaults to SOCK_STREAM + */ + ConnectionSocket(bool ipv6 = false, int type = SOCK_STREAM); + + /** Connect the socket * @param TargetHost The target host to connect to * @param Port The target port to connect to * @param BindHost The host to bind to for connecting - * @param nIPv6 true to use IPv6 - * @param type The socket type, defaults to SOCK_STREAM */ - ClientSocket(const Anope::string &TargetHost, int Port, const Anope::string &BindHost = "", bool nIPv6 = false, int type = SOCK_STREAM); + void Connect(const Anope::string &TargetHost, int Port, const Anope::string &BindHost = ""); +}; - /** Default destructor - */ - virtual ~ClientSocket(); +class ClientSocket : public BufferedSocket +{ + /* Listen socket this connection came from */ + ListenSocket *LS; + /* Clients address */ + sockaddrs clientaddr; + public: - /** Called with a line received from the socket - * @param buf The line - * @return true to continue reading, false to drop the socket + /** Constructor + * @param ls Listen socket this connection is from + * @param fd New FD for this socket + * @param addr Address the connection came from */ - virtual bool Read(const Anope::string &buf); + ClientSocket(ListenSocket *ls, int fd, const sockaddrs &addr); }; -class CoreExport ListenSocket : public Socket +class CoreExport Pipe : public BufferedSocket { - protected: - /* Sockaddrs for bindip/port */ - sockaddrs listenaddrs; + private: + /** The FD of the write pipe (if this isn't evenfd) + * this->Sock is the readfd + */ + int WritePipe; public: - /** Constructor - * @param bindip The IP to bind to - * @param port The port to listen on + /** Constructor */ - ListenSocket(const Anope::string &bindip, int port); + Pipe(); - /** Destructor + /** Called when data is to be read */ - virtual ~ListenSocket(); + bool ProcessRead(); - /** Process what has come in from the connection - * @return false to destory this socket + /** Function that calls OnNotify */ - bool ProcessRead(); + bool Read(const Anope::string &); - /** Called when a connection is accepted - * @param s The socket for the new connection - * @return true if the listen socket should remain alive + /** Called when this pipe needs to be woken up */ - virtual bool OnAccept(Socket *s); + void Notify(); + + /** Should be overloaded to do something useful + */ + virtual void OnNotify(); }; #endif // SOCKET_H diff --git a/include/threadengine.h b/include/threadengine.h index 1337f0c61..764c26242 100644 --- a/include/threadengine.h +++ b/include/threadengine.h @@ -20,6 +20,9 @@ extern CoreExport ThreadEngine threadEngine; class ThreadEngine { public: + /* Vector of threads */ + std::vector<Thread *> threads; + /** Threadengines constructor */ ThreadEngine(); @@ -32,6 +35,10 @@ class ThreadEngine * @param thread A pointer to a newley allocated thread */ void Start(Thread *thread); + + /** Check for finished threads + */ + void Process(); }; class Thread : public Extensible diff --git a/modules/extra/db_mysql.cpp b/modules/extra/db_mysql.cpp index b15ce4de4..274f653b2 100644 --- a/modules/extra/db_mysql.cpp +++ b/modules/extra/db_mysql.cpp @@ -352,7 +352,7 @@ class DBMySQL : public Module return SQL ? SQL->Escape(query) : query; } - DBMySQL(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator), interface(this), SQL(this, "mysql/main") + DBMySQL(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator), interface(this), SQL("mysql/main") { me = this; diff --git a/modules/extra/m_mysql.cpp b/modules/extra/m_mysql.cpp index f641aa655..de855cead 100644 --- a/modules/extra/m_mysql.cpp +++ b/modules/extra/m_mysql.cpp @@ -186,6 +186,7 @@ class ModuleSQL : public Module DThread->SetExitState(); DThread->Wakeup(); DThread->Join(); + delete DThread; delete SQLPipe; } @@ -234,6 +235,7 @@ class ModuleSQL : public Module { MySQLService *ss = new MySQLService(this, connname, database, server, user, password, port); this->MySQLServices.insert(std::make_pair(connname, ss)); + ModuleManager::RegisterService(ss); Log(LOG_NORMAL, "mysql") << "MySQL: Sucessfully connected to server " << connname << " (" << server << ")"; } @@ -284,13 +286,13 @@ MySQLService::~MySQLService() for (unsigned i = me->QueryRequests.size(); i > 0; --i) { - QueryRequest &r = me->QueryRequests[i]; + QueryRequest &r = me->QueryRequests[i - 1]; if (r.service == this) { if (r.interface) r.interface->OnError(SQLResult("", "SQL Interface is going away")); - me->QueryRequests.erase(me->QueryRequests.begin() + i); + me->QueryRequests.erase(me->QueryRequests.begin() + i - 1); } } this->Lock.Unlock(); @@ -373,7 +375,7 @@ void DispatcherThread::Run() r.service->Lock.Unlock(); this->Lock(); - if (me->QueryRequests.front().query == r.query) + if (!me->QueryRequests.empty() && me->QueryRequests.front().query == r.query) { if (r.interface) me->FinishedRequests.push_back(QueryResult(r.interface, sresult)); diff --git a/modules/extra/m_ssl.cpp b/modules/extra/m_ssl.cpp index 5e081c193..9fefb942a 100644 --- a/modules/extra/m_ssl.cpp +++ b/modules/extra/m_ssl.cpp @@ -1,6 +1,7 @@ /* RequiredLibraries: ssl,crypt */ #include "module.h" +#include "ssl.h" #define OPENSSL_NO_SHA512 #include <openssl/bio.h> @@ -12,74 +13,98 @@ #define CERTFILE "anope.cert" #define KEYFILE "anope.key" -static SSL_CTX *ctx; +static SSL_CTX *server_ctx, *client_ctx; -class SSLSocket : public ClientSocket +class MySSLService : public SSLService { - private: - SSL *sslsock; - - int RecvInternal(char *buf, size_t sz) const - { - return SSL_read(sslsock, buf, sz); - } - - int SendInternal(const Anope::string &buf) const - { - return SSL_write(sslsock, buf.c_str(), buf.length()); - } public: - SSLSocket(const Anope::string &nTargetHost, int nPort, const Anope::string &nBindHost = "", bool nIPv6 = false) : ClientSocket(nTargetHost, nPort, nBindHost, nIPv6) - { - this->SetBlocking(); + MySSLService(Module *o, const Anope::string &n); - sslsock = SSL_new(ctx); + /** Initialize a socket to use SSL + * @param s The socket + */ + void Init(Socket *s); +}; - if (!sslsock) - throw CoreException("Unable to initialize SSL socket"); +class SSLSocketIO : public SocketIO +{ + public: + /* The SSL socket for this socket */ + SSL *sslsock; - SSL_set_connect_state(sslsock); - SSL_set_fd(sslsock, Sock); - SSL_connect(sslsock); + /** Constructor + */ + SSLSocketIO(); - UplinkSock = this; + /** Really receive something from the buffer + * @param s The socket + * @param buf The buf to read to + * @param sz How much to read + * @return Number of bytes received + */ + int Recv(Socket *s, char *buf, size_t sz) const; - this->SetNonBlocking(); - } + /** Really write something to the socket + * @param s The socket + * @param buf What to write + * @return Number of bytes written + */ + int Send(Socket *s, const Anope::string &buf) const; - ~SSLSocket() - { - SSL_shutdown(sslsock); - SSL_free(sslsock); + /** Accept a connection from a socket + * @param s The socket + */ + void Accept(ListenSocket *s); - UplinkSock = NULL; - } + /** Connect the socket + * @param s THe socket + * @param target IP to connect to + * @param port to connect to + * @param bindip IP to bind to, if any + */ + void Connect(ConnectionSocket *s, const Anope::string &target, int port, const Anope::string &bindip = ""); - bool Read(const Anope::string &buf) - { - process(buf); - return true; - } + /** Called when the socket is destructing + */ + void Destroy(); }; +class SSLModule; +static SSLModule *me; class SSLModule : public Module { + static int AlwaysAccept(int, X509_STORE_CTX *) + { + return 1; + } + public: - SSLModule(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator) + MySSLService service; + + SSLModule(const Anope::string &modname, const Anope::string &creator) : Module(modname, creator), service(this, "ssl") { + me = this; + + this->SetAuthor("Anope"); + this->SetType(SUPPORTED); + this->SetPermanent(true); + + SSL_library_init(); SSL_load_error_strings(); SSLeay_add_ssl_algorithms(); - ctx = SSL_CTX_new(SSLv23_client_method()); + client_ctx = SSL_CTX_new(SSLv23_client_method()); + server_ctx = SSL_CTX_new(SSLv23_server_method()); - if (!ctx) + if (!client_ctx || !server_ctx) throw ModuleException("Error initializing SSL CTX"); if (IsFile(CERTFILE)) { - if (!SSL_CTX_use_certificate_file(ctx, CERTFILE, SSL_FILETYPE_PEM)) + if (!SSL_CTX_use_certificate_file(client_ctx, CERTFILE, SSL_FILETYPE_PEM) || !SSL_CTX_use_certificate_file(server_ctx, CERTFILE, SSL_FILETYPE_PEM)) { - SSL_CTX_free(ctx); + SSL_CTX_free(client_ctx); + SSL_CTX_free(server_ctx); throw ModuleException("Error loading certificate"); } } @@ -88,9 +113,10 @@ class SSLModule : public Module if (IsFile(KEYFILE)) { - if (!SSL_CTX_use_PrivateKey_file(ctx, KEYFILE, SSL_FILETYPE_PEM)) + if (!SSL_CTX_use_PrivateKey_file(client_ctx, KEYFILE, SSL_FILETYPE_PEM) || !SSL_CTX_use_PrivateKey_file(server_ctx, KEYFILE, SSL_FILETYPE_PEM)) { - SSL_CTX_free(ctx); + SSL_CTX_free(client_ctx); + SSL_CTX_free(server_ctx); throw ModuleException("Error loading private key"); } } @@ -98,26 +124,29 @@ class SSLModule : public Module { if (IsFile(CERTFILE)) { - SSL_CTX_free(ctx); + SSL_CTX_free(client_ctx); + SSL_CTX_free(server_ctx); throw ModuleException("Error loading private key - file not found"); } else Log() << "m_ssl: No private key found"; } - this->SetAuthor("Anope"); - this->SetType(SUPPORTED); - this->SetPermanent(true); + SSL_CTX_set_mode(client_ctx, SSL_MODE_ENABLE_PARTIAL_WRITE | SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER); + SSL_CTX_set_mode(server_ctx, SSL_MODE_ENABLE_PARTIAL_WRITE | SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER); - SSL_CTX_set_options(ctx, SSL_OP_NO_SSLv2); - SSL_CTX_set_options(ctx, SSL_OP_TLS_ROLLBACK_BUG | SSL_OP_ALL); + SSL_CTX_set_verify(client_ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, SSLModule::AlwaysAccept); + SSL_CTX_set_verify(server_ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, SSLModule::AlwaysAccept); + + ModuleManager::RegisterService(&this->service); ModuleManager::Attach(I_OnPreServerConnect, this); } ~SSLModule() { - SSL_CTX_free(ctx); + SSL_CTX_free(client_ctx); + SSL_CTX_free(server_ctx); } EventReturn OnPreServerConnect(Uplink *u, int Number) @@ -128,19 +157,126 @@ class SSLModule : public Module { try { - new SSLSocket(u->host, u->port, Config->LocalHost, u->ipv6); - Log() << "Connected to Server " << Number << " (" << u->host << ":" << u->port << ")"; + new UplinkSocket(uplink_server->ipv6); + this->service.Init(UplinkSock); + UplinkSock->Connect(uplink_server->host, uplink_server->port, Config->LocalHost); + + Log() << "Connected to server " << Number << " (" << u->host << ":" << u->port << ") with SSL"; + return EVENT_ALLOW; } catch (const SocketException &ex) { - Log() << "Unable to connect with SSL to server" << Number << " (" << u->host << ":" << u->port << "), " << ex.GetReason(); + Log() << "Unable to connect with SSL to server " << Number << " (" << u->host << ":" << u->port << "), " << ex.GetReason(); } - return EVENT_ALLOW; + return EVENT_STOP; } return EVENT_CONTINUE; } }; +MySSLService::MySSLService(Module *o, const Anope::string &n) : SSLService(o, n) +{ +} + +void MySSLService::Init(Socket *s) +{ + if (s->IO != &normalSocketIO) + throw CoreException("Socket initializing SSL twice"); + + s->IO = new SSLSocketIO(); +} + +SSLSocketIO::SSLSocketIO() +{ + this->sslsock = NULL; +} + +int SSLSocketIO::Recv(Socket *s, char *buf, size_t sz) const +{ + size_t i = SSL_read(this->sslsock, buf, sz); + TotalRead += i; + return i; +} + +int SSLSocketIO::Send(Socket *s, const Anope::string &buf) const +{ + size_t i = SSL_write(this->sslsock, buf.c_str(), buf.length()); + TotalWritten += i; + return i; +} + +void SSLSocketIO::Accept(ListenSocket *s) +{ + sockaddrs conaddr; + + socklen_t size = conaddr.size(); + int newsock = accept(s->GetFD(), &conaddr.sa, &size); + +#ifndef INVALID_SOCKET +# define INVALID_SOCKET -1 +#endif + if (newsock <= 0 || newsock == INVALID_SOCKET) + throw SocketException("Unable to accept SSL socket: " + Anope::LastError()); + + ClientSocket *newsocket = s->OnAccept(newsock, conaddr); + me->service.Init(newsocket); + SSLSocketIO *IO = debug_cast<SSLSocketIO *>(newsocket->IO); + + IO->sslsock = SSL_new(server_ctx); + if (!IO->sslsock) + throw SocketException("Unable to initialize SSL socket"); + + SSL_set_accept_state(IO->sslsock); + + if (!SSL_set_fd(IO->sslsock, newsock)) + throw SocketException("Unable to set SSL fd"); + + int ret = SSL_accept(IO->sslsock); + if (ret <= 0) + { + int error = SSL_get_error(IO->sslsock, ret); + + if (ret != -1 || (error != SSL_ERROR_WANT_READ && error != SSL_ERROR_WANT_READ)) + throw SocketException("Unable to accept new SSL connection: " + Anope::string(ERR_error_string(ERR_get_error(), NULL))); + } +} + +void SSLSocketIO::Connect(ConnectionSocket *s, const Anope::string &TargetHost, int Port, const Anope::string &BindHost) +{ + if (s->IO == &normalSocketIO) + throw SocketException("Attempting to connect uninitialized socket with SQL"); + + normalSocketIO.Connect(s, TargetHost, Port, BindHost); + + SSLSocketIO *IO = debug_cast<SSLSocketIO *>(s->IO); + + IO->sslsock = SSL_new(client_ctx); + if (!IO->sslsock) + throw SocketException("Unable to initialize SSL socket"); + + if (!SSL_set_fd(IO->sslsock, s->GetFD())) + throw SocketException("Unable to set SSL fd"); + + int ret = SSL_connect(IO->sslsock); + + if (ret <= 0) + { + int error = SSL_get_error(IO->sslsock, ret); + + if (ret != -1 || (error != SSL_ERROR_WANT_READ && error != SSL_ERROR_WANT_READ)) + throw SocketException("Unable to connect to server: " + Anope::string(ERR_error_string(ERR_get_error(), NULL))); + } +} + +void SSLSocketIO::Destroy() +{ + if (this->sslsock) + { + SSL_shutdown(this->sslsock); + SSL_free(this->sslsock); + } +} + MODULE_INIT(SSLModule) diff --git a/modules/extra/ssl.h b/modules/extra/ssl.h new file mode 100644 index 000000000..e25251379 --- /dev/null +++ b/modules/extra/ssl.h @@ -0,0 +1,9 @@ + +class SSLService : public Service +{ + public: + SSLService(Module *o, const Anope::string &n) : Service(o, n) { } + + virtual void Init(Socket *s) = 0; +}; + diff --git a/modules/socketengines/m_socketengine_epoll.cpp b/modules/socketengines/m_socketengine_epoll.cpp index 7b8dbdde5..713c1f0ff 100644 --- a/modules/socketengines/m_socketengine_epoll.cpp +++ b/modules/socketengines/m_socketengine_epoll.cpp @@ -48,7 +48,7 @@ class SocketEngineEPoll : public SocketEngineBase memset(&ev, 0, sizeof(ev)); ev.events = EPOLLIN; - ev.data.fd = s->GetSock(); + ev.data.fd = s->GetFD(); if (epoll_ctl(EngineHandle, EPOLL_CTL_ADD, ev.data.fd, &ev) == -1) { @@ -67,7 +67,7 @@ class SocketEngineEPoll : public SocketEngineBase memset(&ev, 0, sizeof(ev)); - ev.data.fd = s->GetSock(); + ev.data.fd = s->GetFD(); if (epoll_ctl(EngineHandle, EPOLL_CTL_DEL, ev.data.fd, &ev) == -1) { @@ -90,7 +90,7 @@ class SocketEngineEPoll : public SocketEngineBase memset(&ev, 0, sizeof(ev)); ev.events = EPOLLIN | EPOLLOUT; - ev.data.fd = s->GetSock(); + ev.data.fd = s->GetFD(); if (epoll_ctl(EngineHandle, EPOLL_CTL_MOD, ev.data.fd, &ev) == -1) Log() << "Unable to mark fd " << ev.data.fd << " as writable in socketengine epoll: " << Anope::LastError(); @@ -108,7 +108,7 @@ class SocketEngineEPoll : public SocketEngineBase memset(&ev, 0, sizeof(ev)); ev.events = EPOLLIN; - ev.data.fd = s->GetSock(); + ev.data.fd = s->GetFD(); if (epoll_ctl(EngineHandle, EPOLL_CTL_MOD, ev.data.fd, &ev) == -1) Log() << "Unable to mark fd " << ev.data.fd <&l |
