1 /* $NetBSD: server.c,v 1.3 2007/03/18 10:00:42 plunky Exp $ */
2 /* $DragonFly: src/usr.sbin/sdpd/server.c,v 1.1 2008/01/06 21:51:30 hasso Exp $ */
5 * Copyright (c) 2006 Itronix Inc.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
16 * 3. The name of Itronix Inc. may not be used to endorse
17 * or promote products derived from this software without specific
18 * prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY ITRONIX INC. ``AS IS'' AND
21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
22 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
23 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL ITRONIX INC. BE LIABLE FOR ANY
24 * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
25 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
26 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
27 * ON ANY THEORY OF LIABILITY, WHETHER IN
28 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
30 * POSSIBILITY OF SUCH DAMAGE.
35 * Copyright (c) 2004 Maksim Yevmenkin <m_evmenkin@yahoo.com>
36 * All rights reserved.
38 * Redistribution and use in source and binary forms, with or without
39 * modification, are permitted provided that the following conditions
41 * 1. Redistributions of source code must retain the above copyright
42 * notice, this list of conditions and the following disclaimer.
43 * 2. Redistributions in binary form must reproduce the above copyright
44 * notice, this list of conditions and the following disclaimer in the
45 * documentation and/or other materials provided with the distribution.
47 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
48 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
49 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
50 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
51 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
52 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
53 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
54 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
55 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
56 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
59 * $Id: server.c,v 1.1.1.1 2007/11/20 11:56:11 griffin Exp $
60 * $FreeBSD: src/usr.sbin/bluetooth/sdpd/server.c,v 1.2 2005/12/06 17:56:36 emax Exp $
63 #include <sys/param.h>
64 #include <sys/select.h>
66 #include <sys/queue.h>
67 #include <sys/ucred.h>
70 #include <netinet/in.h>
71 #include <arpa/inet.h>
73 #include <bluetooth.h>
87 static void server_accept_client (server_p srv
, int32_t fd
);
88 static int32_t server_process_request (server_p srv
, int32_t fd
);
89 static int32_t server_send_error_response (server_p srv
, int32_t fd
,
91 static void server_close_fd (server_p srv
, int32_t fd
);
93 static int server_auth_check (server_p srv
, struct sockcred
*cred
);
95 static int server_auth_check (server_p srv
, struct cmsgcred
*cred
);
102 server_init(server_p srv
, char const *control
, char const *sgroup
)
104 struct sockaddr_un un
;
105 struct sockaddr_bt l2
;
107 int32_t unsock
, l2sock
;
112 assert(control
!= NULL
);
114 memset(srv
, 0, sizeof(srv
));
115 srv
->sgroup
= sgroup
;
117 /* Open control socket */
118 if (unlink(control
) < 0 && errno
!= ENOENT
) {
119 log_crit("Could not unlink(%s). %s (%d)",
120 control
, strerror(errno
), errno
);
124 unsock
= socket(PF_LOCAL
, SOCK_STREAM
, 0);
126 log_crit("Could not create control socket. %s (%d)",
127 strerror(errno
), errno
);
133 if (setsockopt(unsock
, 0, LOCAL_CREDS
, &opt
, sizeof(opt
)) < 0)
134 log_crit("Warning: No credential checks on control socket");
136 memset(&un
, 0, sizeof(un
));
137 un
.sun_len
= sizeof(un
);
138 un
.sun_family
= AF_LOCAL
;
139 strlcpy(un
.sun_path
, control
, sizeof(un
.sun_path
));
141 if (bind(unsock
, (struct sockaddr
*) &un
, sizeof(un
)) < 0) {
142 log_crit("Could not bind control socket. %s (%d)",
143 strerror(errno
), errno
);
148 if (chmod(control
, S_IRUSR
|S_IWUSR
|S_IRGRP
|S_IWGRP
|S_IROTH
|S_IWOTH
) < 0) {
149 log_crit("Could not change permissions on control socket. " \
150 "%s (%d)", strerror(errno
), errno
);
155 if (listen(unsock
, 10) < 0) {
156 log_crit("Could not listen on control socket. %s (%d)",
157 strerror(errno
), errno
);
162 /* Open L2CAP socket */
163 l2sock
= socket(PF_BLUETOOTH
, SOCK_SEQPACKET
, BTPROTO_L2CAP
);
165 log_crit("Could not create L2CAP socket. %s (%d)",
166 strerror(errno
), errno
);
172 if (getsockopt(l2sock
, BTPROTO_L2CAP
, SO_L2CAP_IMTU
, &imtu
, &size
) < 0) {
173 log_crit("Could not get L2CAP IMTU. %s (%d)",
174 strerror(errno
), errno
);
180 memset(&l2
, 0, sizeof(l2
));
181 l2
.bt_len
= sizeof(l2
);
182 l2
.bt_family
= AF_BLUETOOTH
;
183 l2
.bt_psm
= L2CAP_PSM_SDP
;
184 bdaddr_copy(&l2
.bt_bdaddr
, BDADDR_ANY
);
186 if (bind(l2sock
, (struct sockaddr
*) &l2
, sizeof(l2
)) < 0) {
187 log_crit("Could not bind L2CAP socket. %s (%d)",
188 strerror(errno
), errno
);
194 if (listen(l2sock
, 10) < 0) {
195 log_crit("Could not listen on L2CAP socket. %s (%d)",
196 strerror(errno
), errno
);
202 /* Allocate incoming buffer */
203 srv
->imtu
= (imtu
> SDP_LOCAL_MTU
)? imtu
: SDP_LOCAL_MTU
;
204 srv
->req
= (uint8_t *) calloc(srv
->imtu
, sizeof(srv
->req
[0]));
205 if (srv
->req
== NULL
) {
206 log_crit("Could not allocate request buffer");
212 /* Allocate memory for descriptor index */
213 srv
->fdidx
= (fd_idx_p
) calloc(FD_SETSIZE
, sizeof(srv
->fdidx
[0]));
214 if (srv
->fdidx
== NULL
) {
215 log_crit("Could not allocate fd index");
222 /* Register Service Discovery profile (attach it to control socket) */
223 if (provider_register_sd(unsock
) < 0) {
224 log_crit("Could not register Service Discovery profile");
233 * If we got here then everything is fine. Add both control sockets
237 FD_ZERO(&srv
->fdset
);
238 srv
->maxfd
= (unsock
> l2sock
)? unsock
: l2sock
;
240 FD_SET(unsock
, &srv
->fdset
);
241 srv
->fdidx
[unsock
].valid
= 1;
242 srv
->fdidx
[unsock
].server
= 1;
243 srv
->fdidx
[unsock
].control
= 1;
244 srv
->fdidx
[unsock
].priv
= 0;
245 srv
->fdidx
[unsock
].rsp_cs
= 0;
246 srv
->fdidx
[unsock
].rsp_size
= 0;
247 srv
->fdidx
[unsock
].rsp_limit
= 0;
248 srv
->fdidx
[unsock
].omtu
= SDP_LOCAL_MTU
;
249 srv
->fdidx
[unsock
].rsp
= NULL
;
251 FD_SET(l2sock
, &srv
->fdset
);
252 srv
->fdidx
[l2sock
].valid
= 1;
253 srv
->fdidx
[l2sock
].server
= 1;
254 srv
->fdidx
[l2sock
].control
= 0;
255 srv
->fdidx
[l2sock
].priv
= 0;
256 srv
->fdidx
[l2sock
].rsp_cs
= 0;
257 srv
->fdidx
[l2sock
].rsp_size
= 0;
258 srv
->fdidx
[l2sock
].rsp_limit
= 0;
259 srv
->fdidx
[l2sock
].omtu
= 0; /* unknown */
260 srv
->fdidx
[l2sock
].rsp
= NULL
;
270 server_shutdown(server_p srv
)
276 for (fd
= 0; fd
< srv
->maxfd
+ 1; fd
++)
277 if (srv
->fdidx
[fd
].valid
)
278 server_close_fd(srv
, fd
);
283 memset(srv
, 0, sizeof(*srv
));
287 * Do one server iteration
291 server_do(server_p srv
)
298 /* Copy cached version of the fd set and call select */
299 memcpy(&fdset
, &srv
->fdset
, sizeof(fdset
));
300 n
= select(srv
->maxfd
+ 1, &fdset
, NULL
, NULL
, NULL
);
305 log_err("Could not select(%d, %p). %s (%d)",
306 srv
->maxfd
+ 1, &fdset
, strerror(errno
), errno
);
311 /* Process descriptors */
312 for (fd
= 0; fd
< srv
->maxfd
+ 1 && n
> 0; fd
++) {
313 if (!FD_ISSET(fd
, &fdset
))
316 assert(srv
->fdidx
[fd
].valid
);
319 if (srv
->fdidx
[fd
].server
)
320 server_accept_client(srv
, fd
);
321 else if (server_process_request(srv
, fd
) != 0)
322 server_close_fd(srv
, fd
);
330 * Accept new client connection and register it with index
334 server_accept_client(server_p srv
, int32_t fd
)
342 cfd
= accept(fd
, NULL
, NULL
);
343 } while (cfd
< 0 && errno
== EINTR
);
346 log_err("Could not accept connection on %s socket. %s (%d)",
347 srv
->fdidx
[fd
].control
? "control" : "L2CAP",
348 strerror(errno
), errno
);
352 assert(!FD_ISSET(cfd
, &srv
->fdset
));
353 assert(!srv
->fdidx
[cfd
].valid
);
355 if (!srv
->fdidx
[fd
].control
) {
356 /* Get local BD_ADDR */
357 size
= sizeof(srv
->req_sa
);
358 if (getsockname(cfd
,(struct sockaddr
*)&srv
->req_sa
, &size
) < 0) {
359 log_err("Could not get local BD_ADDR. %s (%d)",
360 strerror(errno
), errno
);
365 /* Get outgoing MTU */
367 if (getsockopt(cfd
, BTPROTO_L2CAP
, SO_L2CAP_OMTU
, &omtu
, &size
) < 0) {
368 log_err("Could not get L2CAP OMTU. %s (%d)",
369 strerror(errno
), errno
);
375 * The maximum size of the L2CAP packet is 65536 bytes.
376 * The minimum L2CAP MTU is 43 bytes. That means we need
377 * 65536 / 43 = ~1524 chunks to transfer maximum packet
378 * size with minimum MTU. The "rsp_cs" field in fd_idx_t
379 * is 11 bit wide that gives us upto 2048 chunks.
382 if (omtu
< L2CAP_MTU_MINIMUM
) {
383 log_err("L2CAP OMTU is too small (%d bytes)", omtu
);
388 bdaddr_copy(&srv
->req_sa
.bt_bdaddr
, BDADDR_ANY
);
389 omtu
= srv
->fdidx
[fd
].omtu
;
393 * Allocate buffer. This is an overkill, but we can not know how
394 * big our reply is going to be.
397 rsp
= (uint8_t *) calloc(L2CAP_MTU_MAXIMUM
, sizeof(rsp
[0]));
399 log_crit("Could not allocate response buffer");
404 /* Add client descriptor to the index */
405 FD_SET(cfd
, &srv
->fdset
);
406 if (srv
->maxfd
< cfd
)
408 srv
->fdidx
[cfd
].valid
= 1;
409 srv
->fdidx
[cfd
].server
= 0;
410 srv
->fdidx
[cfd
].control
= srv
->fdidx
[fd
].control
;
411 srv
->fdidx
[cfd
].priv
= 0;
412 srv
->fdidx
[cfd
].rsp_cs
= 0;
413 srv
->fdidx
[cfd
].rsp_size
= 0;
414 srv
->fdidx
[cfd
].rsp_limit
= 0;
415 srv
->fdidx
[cfd
].omtu
= omtu
;
416 srv
->fdidx
[cfd
].rsp
= rsp
;
420 * Process request from the client
424 server_process_request(server_p srv
, int32_t fd
)
427 sdp_pdu_p pdu
= (sdp_pdu_p
) srv
->req
;
431 struct cmsghdr
*cmsg
;
433 assert(srv
->imtu
> 0);
434 assert(srv
->req
!= NULL
);
435 assert(FD_ISSET(fd
, &srv
->fdset
));
436 assert(srv
->fdidx
[fd
].valid
);
437 assert(!srv
->fdidx
[fd
].server
);
438 assert(srv
->fdidx
[fd
].rsp
!= NULL
);
439 assert(srv
->fdidx
[fd
].omtu
>= L2CAP_MTU_MINIMUM
);
441 iov
.iov_base
= srv
->req
;
442 iov
.iov_len
= srv
->imtu
;
448 msg
.msg_control
= ctl
;
449 msg
.msg_controllen
= sizeof(ctl
);
453 len
= recvmsg(fd
, &msg
, 0);
454 } while (len
< 0 && errno
== EINTR
);
457 log_err("Could not receive SDP request from %s socket. %s (%d)",
458 srv
->fdidx
[fd
].control
? "control" : "L2CAP",
459 strerror(errno
), errno
);
463 log_info("Client on %s socket has disconnected",
464 srv
->fdidx
[fd
].control
? "control" : "L2CAP");
469 if ((cmsg
= CMSG_FIRSTHDR(&msg
)) != NULL
470 && cmsg
->cmsg_level
== SOL_SOCKET
471 && cmsg
->cmsg_type
== SCM_CREDS
473 && cmsg
->cmsg_len
>= CMSG_LEN(SOCKCREDSIZE(0))
476 srv
->fdidx
[fd
].priv
=
477 server_auth_check(srv
, (struct cmsgcred
*)CMSG_DATA(cmsg
));
479 server_auth_check(srv
, (struct sockcred
*)CMSG_DATA(cmsg
));
482 srv
->fdidx
[fd
].priv
= 1;
485 if (len
>= sizeof(*pdu
)
486 && (sizeof(*pdu
) + (pdu
->len
= ntohs(pdu
->len
))) == len
) {
488 case SDP_PDU_SERVICE_SEARCH_REQUEST
:
489 error
= server_prepare_service_search_response(srv
, fd
);
492 case SDP_PDU_SERVICE_ATTRIBUTE_REQUEST
:
493 error
= server_prepare_service_attribute_response(srv
, fd
);
496 case SDP_PDU_SERVICE_SEARCH_ATTRIBUTE_REQUEST
:
497 error
= server_prepare_service_search_attribute_response(srv
, fd
);
500 case SDP_PDU_SERVICE_REGISTER_REQUEST
:
501 error
= server_prepare_service_register_response(srv
, fd
);
504 case SDP_PDU_SERVICE_UNREGISTER_REQUEST
:
505 error
= server_prepare_service_unregister_response(srv
, fd
);
508 case SDP_PDU_SERVICE_CHANGE_REQUEST
:
509 error
= server_prepare_service_change_response(srv
, fd
);
513 error
= SDP_ERROR_CODE_INVALID_REQUEST_SYNTAX
;
517 error
= SDP_ERROR_CODE_INVALID_PDU_SIZE
;
521 case SDP_PDU_SERVICE_SEARCH_REQUEST
:
522 error
= server_send_service_search_response(srv
, fd
);
525 case SDP_PDU_SERVICE_ATTRIBUTE_REQUEST
:
526 error
= server_send_service_attribute_response(srv
, fd
);
529 case SDP_PDU_SERVICE_SEARCH_ATTRIBUTE_REQUEST
:
530 error
= server_send_service_search_attribute_response(srv
, fd
);
533 case SDP_PDU_SERVICE_REGISTER_REQUEST
:
534 error
= server_send_service_register_response(srv
, fd
);
537 case SDP_PDU_SERVICE_UNREGISTER_REQUEST
:
538 error
= server_send_service_unregister_response(srv
, fd
);
541 case SDP_PDU_SERVICE_CHANGE_REQUEST
:
542 error
= server_send_service_change_response(srv
, fd
);
546 error
= SDP_ERROR_CODE_INVALID_REQUEST_SYNTAX
;
551 log_err("Could not send SDP response to %s socket, " \
552 "pdu->pid=%d, pdu->tid=%d, error=%d",
553 srv
->fdidx
[fd
].control
? "control" : "L2CAP",
554 pdu
->pid
, ntohs(pdu
->tid
), error
);
556 log_err("Could not process SDP request from %s socket, " \
557 "pdu->pid=%d, pdu->tid=%d, pdu->len=%d, len=%d, " \
559 srv
->fdidx
[fd
].control
? "control" : "L2CAP",
560 pdu
->pid
, ntohs(pdu
->tid
), pdu
->len
, len
, error
);
562 error
= server_send_error_response(srv
, fd
, error
);
564 log_err("Could not send SDP error response to %s " \
565 "socket, pdu->pid=%d, pdu->tid=%d, error=%d",
566 srv
->fdidx
[fd
].control
? "control" : "L2CAP",
567 pdu
->pid
, ntohs(pdu
->tid
), error
);
570 /* On error forget response (if any) */
572 srv
->fdidx
[fd
].rsp_cs
= 0;
573 srv
->fdidx
[fd
].rsp_size
= 0;
574 srv
->fdidx
[fd
].rsp_limit
= 0;
581 * Send SDP_Error_Response PDU
585 server_send_error_response(server_p srv
, int32_t fd
, uint16_t error
)
592 } __attribute__ ((packed
)) rsp
;
594 /* Prepare and send SDP error response */
595 rsp
.pdu
.pid
= SDP_PDU_ERROR_RESPONSE
;
596 rsp
.pdu
.tid
= ((sdp_pdu_p
)(srv
->req
))->tid
;
597 rsp
.pdu
.len
= htons(sizeof(rsp
.error
));
598 rsp
.error
= htons(error
);
601 size
= write(fd
, &rsp
, sizeof(rsp
));
602 } while (size
< 0 && errno
== EINTR
);
604 return ((size
< 0)? errno
: 0);
608 * Close descriptor and remove it from index
612 server_close_fd(server_p srv
, int32_t fd
)
614 provider_p provider
= NULL
, provider_next
= NULL
;
616 assert(FD_ISSET(fd
, &srv
->fdset
));
617 assert(srv
->fdidx
[fd
].valid
);
621 FD_CLR(fd
, &srv
->fdset
);
622 if (fd
== srv
->maxfd
)
625 if (srv
->fdidx
[fd
].rsp
!= NULL
)
626 free(srv
->fdidx
[fd
].rsp
);
628 memset(&srv
->fdidx
[fd
], 0, sizeof(srv
->fdidx
[fd
]));
630 for (provider
= provider_get_first();
632 provider
= provider_next
) {
633 provider_next
= provider_get_next(provider
);
635 if (provider
->fd
== fd
)
636 provider_unregister(provider
);
641 /*server_auth_check(server_p srv, struct sockcred *cred)*/
642 server_auth_check(server_p srv
, struct cmsgcred
*cred
)
650 if (cred
->cmcred_uid
== 0 || cred
->cmcred_euid
== 0)
653 if (srv
->sgroup
== NULL
)
656 grp
= getgrnam(srv
->sgroup
);
658 log_err("No gid for group '%s'", srv
->sgroup
);
664 if (cred
->cmcred_gid
== grp
->gr_gid
)
667 for (n
= 0 ; n
< cred
->cmcred_ngroups
; n
++) {
668 if (cred
->cmcred_groups
[n
] == grp
->gr_gid
)