1 /* $OpenBSD: sftp-server.c,v 1.73 2007/05/17 07:55:29 djm Exp $ */
3 * Copyright (c) 2000-2004 Markus Friedl. All rights reserved.
5 * Permission to use, copy, modify, and distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20 #include <sys/types.h>
21 #include <sys/param.h>
23 #ifdef HAVE_SYS_TIME_H
24 # include <sys/time.h>
46 #include "sftp-common.h"
49 #define get_int64() buffer_get_int64(&iqueue);
50 #define get_int() buffer_get_int(&iqueue);
51 #define get_string(lenp) buffer_get_string(&iqueue, lenp);
54 LogLevel log_level
= SYSLOG_LEVEL_ERROR
;
57 struct passwd
*pw
= NULL
;
58 char *client_addr
= NULL
;
60 /* input and output queue */
64 /* Version of client */
67 /* portable attributes, etc. */
69 typedef struct Stat Stat
;
78 errno_to_portable(int unixerrno
)
90 ret
= SSH2_FX_NO_SUCH_FILE
;
95 ret
= SSH2_FX_PERMISSION_DENIED
;
99 ret
= SSH2_FX_BAD_MESSAGE
;
102 ret
= SSH2_FX_FAILURE
;
109 flags_from_portable(int pflags
)
113 if ((pflags
& SSH2_FXF_READ
) &&
114 (pflags
& SSH2_FXF_WRITE
)) {
116 } else if (pflags
& SSH2_FXF_READ
) {
118 } else if (pflags
& SSH2_FXF_WRITE
) {
121 if (pflags
& SSH2_FXF_CREAT
)
123 if (pflags
& SSH2_FXF_TRUNC
)
125 if (pflags
& SSH2_FXF_EXCL
)
131 string_from_portable(int pflags
)
133 static char ret
[128];
137 #define PAPPEND(str) { \
139 strlcat(ret, ",", sizeof(ret)); \
140 strlcat(ret, str, sizeof(ret)); \
143 if (pflags
& SSH2_FXF_READ
)
145 if (pflags
& SSH2_FXF_WRITE
)
147 if (pflags
& SSH2_FXF_CREAT
)
149 if (pflags
& SSH2_FXF_TRUNC
)
151 if (pflags
& SSH2_FXF_EXCL
)
160 return decode_attrib(&iqueue
);
165 typedef struct Handle Handle
;
171 u_int64_t bytes_read
, bytes_write
;
187 for (i
= 0; i
< sizeof(handles
)/sizeof(Handle
); i
++)
188 handles
[i
].use
= HANDLE_UNUSED
;
192 handle_new(int use
, const char *name
, int fd
, DIR *dirp
)
196 for (i
= 0; i
< sizeof(handles
)/sizeof(Handle
); i
++) {
197 if (handles
[i
].use
== HANDLE_UNUSED
) {
198 handles
[i
].use
= use
;
199 handles
[i
].dirp
= dirp
;
201 handles
[i
].name
= xstrdup(name
);
202 handles
[i
].bytes_read
= handles
[i
].bytes_write
= 0;
210 handle_is_ok(int i
, int type
)
212 return i
>= 0 && (u_int
)i
< sizeof(handles
)/sizeof(Handle
) &&
213 handles
[i
].use
== type
;
217 handle_to_string(int handle
, char **stringp
, int *hlenp
)
219 if (stringp
== NULL
|| hlenp
== NULL
)
221 *stringp
= xmalloc(sizeof(int32_t));
222 put_u32(*stringp
, handle
);
223 *hlenp
= sizeof(int32_t);
228 handle_from_string(const char *handle
, u_int hlen
)
232 if (hlen
!= sizeof(int32_t))
234 val
= get_u32(handle
);
235 if (handle_is_ok(val
, HANDLE_FILE
) ||
236 handle_is_ok(val
, HANDLE_DIR
))
242 handle_to_name(int handle
)
244 if (handle_is_ok(handle
, HANDLE_DIR
)||
245 handle_is_ok(handle
, HANDLE_FILE
))
246 return handles
[handle
].name
;
251 handle_to_dir(int handle
)
253 if (handle_is_ok(handle
, HANDLE_DIR
))
254 return handles
[handle
].dirp
;
259 handle_to_fd(int handle
)
261 if (handle_is_ok(handle
, HANDLE_FILE
))
262 return handles
[handle
].fd
;
267 handle_update_read(int handle
, ssize_t bytes
)
269 if (handle_is_ok(handle
, HANDLE_FILE
) && bytes
> 0)
270 handles
[handle
].bytes_read
+= bytes
;
274 handle_update_write(int handle
, ssize_t bytes
)
276 if (handle_is_ok(handle
, HANDLE_FILE
) && bytes
> 0)
277 handles
[handle
].bytes_write
+= bytes
;
281 handle_bytes_read(int handle
)
283 if (handle_is_ok(handle
, HANDLE_FILE
))
284 return (handles
[handle
].bytes_read
);
289 handle_bytes_write(int handle
)
291 if (handle_is_ok(handle
, HANDLE_FILE
))
292 return (handles
[handle
].bytes_write
);
297 handle_close(int handle
)
301 if (handle_is_ok(handle
, HANDLE_FILE
)) {
302 ret
= close(handles
[handle
].fd
);
303 handles
[handle
].use
= HANDLE_UNUSED
;
304 xfree(handles
[handle
].name
);
305 } else if (handle_is_ok(handle
, HANDLE_DIR
)) {
306 ret
= closedir(handles
[handle
].dirp
);
307 handles
[handle
].use
= HANDLE_UNUSED
;
308 xfree(handles
[handle
].name
);
316 handle_log_close(int handle
, char *emsg
)
318 if (handle_is_ok(handle
, HANDLE_FILE
)) {
319 logit("%s%sclose \"%s\" bytes read %llu written %llu",
320 emsg
== NULL
? "" : emsg
, emsg
== NULL
? "" : " ",
321 handle_to_name(handle
),
322 (unsigned long long)handle_bytes_read(handle
),
323 (unsigned long long)handle_bytes_write(handle
));
325 logit("%s%sclosedir \"%s\"",
326 emsg
== NULL
? "" : emsg
, emsg
== NULL
? "" : " ",
327 handle_to_name(handle
));
332 handle_log_exit(void)
336 for (i
= 0; i
< sizeof(handles
)/sizeof(Handle
); i
++)
337 if (handles
[i
].use
!= HANDLE_UNUSED
)
338 handle_log_close(i
, "forced");
348 handle
= get_string(&hlen
);
350 val
= handle_from_string(handle
, hlen
);
360 int mlen
= buffer_len(m
);
362 buffer_put_int(&oqueue
, mlen
);
363 buffer_append(&oqueue
, buffer_ptr(m
), mlen
);
364 buffer_consume(m
, mlen
);
368 status_to_message(u_int32_t status
)
370 const char *status_messages
[] = {
371 "Success", /* SSH_FX_OK */
372 "End of file", /* SSH_FX_EOF */
373 "No such file", /* SSH_FX_NO_SUCH_FILE */
374 "Permission denied", /* SSH_FX_PERMISSION_DENIED */
375 "Failure", /* SSH_FX_FAILURE */
376 "Bad message", /* SSH_FX_BAD_MESSAGE */
377 "No connection", /* SSH_FX_NO_CONNECTION */
378 "Connection lost", /* SSH_FX_CONNECTION_LOST */
379 "Operation unsupported", /* SSH_FX_OP_UNSUPPORTED */
380 "Unknown error" /* Others */
382 return (status_messages
[MIN(status
,SSH2_FX_MAX
)]);
386 send_status(u_int32_t id
, u_int32_t status
)
390 debug3("request %u: sent status %u", id
, status
);
391 if (log_level
> SYSLOG_LEVEL_VERBOSE
||
392 (status
!= SSH2_FX_OK
&& status
!= SSH2_FX_EOF
))
393 logit("sent status %s", status_to_message(status
));
395 buffer_put_char(&msg
, SSH2_FXP_STATUS
);
396 buffer_put_int(&msg
, id
);
397 buffer_put_int(&msg
, status
);
399 buffer_put_cstring(&msg
, status_to_message(status
));
400 buffer_put_cstring(&msg
, "");
406 send_data_or_handle(char type
, u_int32_t id
, const char *data
, int dlen
)
411 buffer_put_char(&msg
, type
);
412 buffer_put_int(&msg
, id
);
413 buffer_put_string(&msg
, data
, dlen
);
419 send_data(u_int32_t id
, const char *data
, int dlen
)
421 debug("request %u: sent data len %d", id
, dlen
);
422 send_data_or_handle(SSH2_FXP_DATA
, id
, data
, dlen
);
426 send_handle(u_int32_t id
, int handle
)
431 handle_to_string(handle
, &string
, &hlen
);
432 debug("request %u: sent handle handle %d", id
, handle
);
433 send_data_or_handle(SSH2_FXP_HANDLE
, id
, string
, hlen
);
438 send_names(u_int32_t id
, int count
, const Stat
*stats
)
444 buffer_put_char(&msg
, SSH2_FXP_NAME
);
445 buffer_put_int(&msg
, id
);
446 buffer_put_int(&msg
, count
);
447 debug("request %u: sent names count %d", id
, count
);
448 for (i
= 0; i
< count
; i
++) {
449 buffer_put_cstring(&msg
, stats
[i
].name
);
450 buffer_put_cstring(&msg
, stats
[i
].long_name
);
451 encode_attrib(&msg
, &stats
[i
].attrib
);
458 send_attrib(u_int32_t id
, const Attrib
*a
)
462 debug("request %u: sent attrib have 0x%x", id
, a
->flags
);
464 buffer_put_char(&msg
, SSH2_FXP_ATTRS
);
465 buffer_put_int(&msg
, id
);
466 encode_attrib(&msg
, a
);
479 verbose("received client version %d", version
);
481 buffer_put_char(&msg
, SSH2_FXP_VERSION
);
482 buffer_put_int(&msg
, SSH2_FILEXFER_VERSION
);
490 u_int32_t id
, pflags
;
493 int handle
, fd
, flags
, mode
, status
= SSH2_FX_FAILURE
;
496 name
= get_string(NULL
);
497 pflags
= get_int(); /* portable flags */
498 debug3("request %u: open flags %d", id
, pflags
);
500 flags
= flags_from_portable(pflags
);
501 mode
= (a
->flags
& SSH2_FILEXFER_ATTR_PERMISSIONS
) ? a
->perm
: 0666;
502 logit("open \"%s\" flags %s mode 0%o",
503 name
, string_from_portable(pflags
), mode
);
504 fd
= open(name
, flags
, mode
);
506 status
= errno_to_portable(errno
);
508 handle
= handle_new(HANDLE_FILE
, name
, fd
, NULL
);
512 send_handle(id
, handle
);
516 if (status
!= SSH2_FX_OK
)
517 send_status(id
, status
);
525 int handle
, ret
, status
= SSH2_FX_FAILURE
;
528 handle
= get_handle();
529 debug3("request %u: close handle %u", id
, handle
);
530 handle_log_close(handle
, NULL
);
531 ret
= handle_close(handle
);
532 status
= (ret
== -1) ? errno_to_portable(errno
) : SSH2_FX_OK
;
533 send_status(id
, status
);
541 int handle
, fd
, ret
, status
= SSH2_FX_FAILURE
;
545 handle
= get_handle();
549 debug("request %u: read \"%s\" (handle %d) off %llu len %d",
550 id
, handle_to_name(handle
), handle
, (unsigned long long)off
, len
);
551 if (len
> sizeof buf
) {
553 debug2("read change len %d", len
);
555 fd
= handle_to_fd(handle
);
557 if (lseek(fd
, off
, SEEK_SET
) < 0) {
558 error("process_read: seek failed");
559 status
= errno_to_portable(errno
);
561 ret
= read(fd
, buf
, len
);
563 status
= errno_to_portable(errno
);
564 } else if (ret
== 0) {
565 status
= SSH2_FX_EOF
;
567 send_data(id
, buf
, ret
);
569 handle_update_read(handle
, ret
);
573 if (status
!= SSH2_FX_OK
)
574 send_status(id
, status
);
583 int handle
, fd
, ret
, status
= SSH2_FX_FAILURE
;
587 handle
= get_handle();
589 data
= get_string(&len
);
591 debug("request %u: write \"%s\" (handle %d) off %llu len %d",
592 id
, handle_to_name(handle
), handle
, (unsigned long long)off
, len
);
593 fd
= handle_to_fd(handle
);
595 if (lseek(fd
, off
, SEEK_SET
) < 0) {
596 status
= errno_to_portable(errno
);
597 error("process_write: seek failed");
600 ret
= write(fd
, data
, len
);
602 error("process_write: write failed");
603 status
= errno_to_portable(errno
);
604 } else if ((size_t)ret
== len
) {
606 handle_update_write(handle
, ret
);
608 debug2("nothing at all written");
612 send_status(id
, status
);
617 process_do_stat(int do_lstat
)
623 int ret
, status
= SSH2_FX_FAILURE
;
626 name
= get_string(NULL
);
627 debug3("request %u: %sstat", id
, do_lstat
? "l" : "");
628 verbose("%sstat name \"%s\"", do_lstat
? "l" : "", name
);
629 ret
= do_lstat
? lstat(name
, &st
) : stat(name
, &st
);
631 status
= errno_to_portable(errno
);
633 stat_to_attrib(&st
, &a
);
637 if (status
!= SSH2_FX_OK
)
638 send_status(id
, status
);
660 int fd
, ret
, handle
, status
= SSH2_FX_FAILURE
;
663 handle
= get_handle();
664 debug("request %u: fstat \"%s\" (handle %u)",
665 id
, handle_to_name(handle
), handle
);
666 fd
= handle_to_fd(handle
);
668 ret
= fstat(fd
, &st
);
670 status
= errno_to_portable(errno
);
672 stat_to_attrib(&st
, &a
);
677 if (status
!= SSH2_FX_OK
)
678 send_status(id
, status
);
681 static struct timeval
*
682 attrib_to_tv(const Attrib
*a
)
684 static struct timeval tv
[2];
686 tv
[0].tv_sec
= a
->atime
;
688 tv
[1].tv_sec
= a
->mtime
;
694 process_setstat(void)
699 int status
= SSH2_FX_OK
, ret
;
702 name
= get_string(NULL
);
704 debug("request %u: setstat name \"%s\"", id
, name
);
705 if (a
->flags
& SSH2_FILEXFER_ATTR_SIZE
) {
706 logit("set \"%s\" size %llu",
707 name
, (unsigned long long)a
->size
);
708 ret
= truncate(name
, a
->size
);
710 status
= errno_to_portable(errno
);
712 if (a
->flags
& SSH2_FILEXFER_ATTR_PERMISSIONS
) {
713 logit("set \"%s\" mode %04o", name
, a
->perm
);
714 ret
= chmod(name
, a
->perm
& 0777);
716 status
= errno_to_portable(errno
);
718 if (a
->flags
& SSH2_FILEXFER_ATTR_ACMODTIME
) {
722 strftime(buf
, sizeof(buf
), "%Y%m%d-%H:%M:%S",
724 logit("set \"%s\" modtime %s", name
, buf
);
725 ret
= utimes(name
, attrib_to_tv(a
));
727 status
= errno_to_portable(errno
);
729 if (a
->flags
& SSH2_FILEXFER_ATTR_UIDGID
) {
730 logit("set \"%s\" owner %lu group %lu", name
,
731 (u_long
)a
->uid
, (u_long
)a
->gid
);
732 ret
= chown(name
, a
->uid
, a
->gid
);
734 status
= errno_to_portable(errno
);
736 send_status(id
, status
);
741 process_fsetstat(void)
746 int status
= SSH2_FX_OK
;
749 handle
= get_handle();
751 debug("request %u: fsetstat handle %d", id
, handle
);
752 fd
= handle_to_fd(handle
);
754 status
= SSH2_FX_FAILURE
;
756 char *name
= handle_to_name(handle
);
758 if (a
->flags
& SSH2_FILEXFER_ATTR_SIZE
) {
759 logit("set \"%s\" size %llu",
760 name
, (unsigned long long)a
->size
);
761 ret
= ftruncate(fd
, a
->size
);
763 status
= errno_to_portable(errno
);
765 if (a
->flags
& SSH2_FILEXFER_ATTR_PERMISSIONS
) {
766 logit("set \"%s\" mode %04o", name
, a
->perm
);
768 ret
= fchmod(fd
, a
->perm
& 0777);
770 ret
= chmod(name
, a
->perm
& 0777);
773 status
= errno_to_portable(errno
);
775 if (a
->flags
& SSH2_FILEXFER_ATTR_ACMODTIME
) {
779 strftime(buf
, sizeof(buf
), "%Y%m%d-%H:%M:%S",
781 logit("set \"%s\" modtime %s", name
, buf
);
783 ret
= futimes(fd
, attrib_to_tv(a
));
785 ret
= utimes(name
, attrib_to_tv(a
));
788 status
= errno_to_portable(errno
);
790 if (a
->flags
& SSH2_FILEXFER_ATTR_UIDGID
) {
791 logit("set \"%s\" owner %lu group %lu", name
,
792 (u_long
)a
->uid
, (u_long
)a
->gid
);
794 ret
= fchown(fd
, a
->uid
, a
->gid
);
796 ret
= chown(name
, a
->uid
, a
->gid
);
799 status
= errno_to_portable(errno
);
802 send_status(id
, status
);
806 process_opendir(void)
810 int handle
, status
= SSH2_FX_FAILURE
;
814 path
= get_string(NULL
);
815 debug3("request %u: opendir", id
);
816 logit("opendir \"%s\"", path
);
817 dirp
= opendir(path
);
819 status
= errno_to_portable(errno
);
821 handle
= handle_new(HANDLE_DIR
, path
, 0, dirp
);
825 send_handle(id
, handle
);
830 if (status
!= SSH2_FX_OK
)
831 send_status(id
, status
);
836 process_readdir(void)
845 handle
= get_handle();
846 debug("request %u: readdir \"%s\" (handle %d)", id
,
847 handle_to_name(handle
), handle
);
848 dirp
= handle_to_dir(handle
);
849 path
= handle_to_name(handle
);
850 if (dirp
== NULL
|| path
== NULL
) {
851 send_status(id
, SSH2_FX_FAILURE
);
854 char pathname
[MAXPATHLEN
];
856 int nstats
= 10, count
= 0, i
;
858 stats
= xcalloc(nstats
, sizeof(Stat
));
859 while ((dp
= readdir(dirp
)) != NULL
) {
860 if (count
>= nstats
) {
862 stats
= xrealloc(stats
, nstats
, sizeof(Stat
));
865 snprintf(pathname
, sizeof pathname
, "%s%s%s", path
,
866 strcmp(path
, "/") ? "/" : "", dp
->d_name
);
867 if (lstat(pathname
, &st
) < 0)
869 stat_to_attrib(&st
, &(stats
[count
].attrib
));
870 stats
[count
].name
= xstrdup(dp
->d_name
);
871 stats
[count
].long_name
= ls_file(dp
->d_name
, &st
, 0);
873 /* send up to 100 entries in one message */
874 /* XXX check packet size instead */
879 send_names(id
, count
, stats
);
880 for (i
= 0; i
< count
; i
++) {
881 xfree(stats
[i
].name
);
882 xfree(stats
[i
].long_name
);
885 send_status(id
, SSH2_FX_EOF
);
896 int status
= SSH2_FX_FAILURE
;
900 name
= get_string(NULL
);
901 debug3("request %u: remove", id
);
902 logit("remove name \"%s\"", name
);
904 status
= (ret
== -1) ? errno_to_portable(errno
) : SSH2_FX_OK
;
905 send_status(id
, status
);
915 int ret
, mode
, status
= SSH2_FX_FAILURE
;
918 name
= get_string(NULL
);
920 mode
= (a
->flags
& SSH2_FILEXFER_ATTR_PERMISSIONS
) ?
921 a
->perm
& 0777 : 0777;
922 debug3("request %u: mkdir", id
);
923 logit("mkdir name \"%s\" mode 0%o", name
, mode
);
924 ret
= mkdir(name
, mode
);
925 status
= (ret
== -1) ? errno_to_portable(errno
) : SSH2_FX_OK
;
926 send_status(id
, status
);
938 name
= get_string(NULL
);
939 debug3("request %u: rmdir", id
);
940 logit("rmdir name \"%s\"", name
);
942 status
= (ret
== -1) ? errno_to_portable(errno
) : SSH2_FX_OK
;
943 send_status(id
, status
);
948 process_realpath(void)
950 char resolvedname
[MAXPATHLEN
];
955 path
= get_string(NULL
);
956 if (path
[0] == '\0') {
960 debug3("request %u: realpath", id
);
961 verbose("realpath \"%s\"", path
);
962 if (realpath(path
, resolvedname
) == NULL
) {
963 send_status(id
, errno_to_portable(errno
));
966 attrib_clear(&s
.attrib
);
967 s
.name
= s
.long_name
= resolvedname
;
968 send_names(id
, 1, &s
);
977 char *oldpath
, *newpath
;
982 oldpath
= get_string(NULL
);
983 newpath
= get_string(NULL
);
984 debug3("request %u: rename", id
);
985 logit("rename old \"%s\" new \"%s\"", oldpath
, newpath
);
986 status
= SSH2_FX_FAILURE
;
987 if (lstat(oldpath
, &sb
) == -1)
988 status
= errno_to_portable(errno
);
989 else if (S_ISREG(sb
.st_mode
)) {
990 /* Race-free rename of regular files */
991 if (link(oldpath
, newpath
) == -1) {
992 if (errno
== EOPNOTSUPP
993 #ifdef LINK_OPNOTSUPP_ERRNO
994 || errno
== LINK_OPNOTSUPP_ERRNO
1000 * fs doesn't support links, so fall back to
1001 * stat+rename. This is racy.
1003 if (stat(newpath
, &st
) == -1) {
1004 if (rename(oldpath
, newpath
) == -1)
1006 errno_to_portable(errno
);
1008 status
= SSH2_FX_OK
;
1011 status
= errno_to_portable(errno
);
1013 } else if (unlink(oldpath
) == -1) {
1014 status
= errno_to_portable(errno
);
1015 /* clean spare link */
1018 status
= SSH2_FX_OK
;
1019 } else if (stat(newpath
, &sb
) == -1) {
1020 if (rename(oldpath
, newpath
) == -1)
1021 status
= errno_to_portable(errno
);
1023 status
= SSH2_FX_OK
;
1025 send_status(id
, status
);
1031 process_readlink(void)
1035 char buf
[MAXPATHLEN
];
1039 path
= get_string(NULL
);
1040 debug3("request %u: readlink", id
);
1041 verbose("readlink \"%s\"", path
);
1042 if ((len
= readlink(path
, buf
, sizeof(buf
) - 1)) == -1)
1043 send_status(id
, errno_to_portable(errno
));
1048 attrib_clear(&s
.attrib
);
1049 s
.name
= s
.long_name
= buf
;
1050 send_names(id
, 1, &s
);
1056 process_symlink(void)
1059 char *oldpath
, *newpath
;
1063 oldpath
= get_string(NULL
);
1064 newpath
= get_string(NULL
);
1065 debug3("request %u: symlink", id
);
1066 logit("symlink old \"%s\" new \"%s\"", oldpath
, newpath
);
1067 /* this will fail if 'newpath' exists */
1068 ret
= symlink(oldpath
, newpath
);
1069 status
= (ret
== -1) ? errno_to_portable(errno
) : SSH2_FX_OK
;
1070 send_status(id
, status
);
1076 process_extended(void)
1082 request
= get_string(NULL
);
1083 send_status(id
, SSH2_FX_OP_UNSUPPORTED
); /* MUST */
1087 /* stolen from ssh-agent */
1098 buf_len
= buffer_len(&iqueue
);
1100 return; /* Incomplete message. */
1101 cp
= buffer_ptr(&iqueue
);
1102 msg_len
= get_u32(cp
);
1103 if (msg_len
> SFTP_MAX_MSG_LENGTH
) {
1104 error("bad message from %s local user %s",
1105 client_addr
, pw
->pw_name
);
1108 if (buf_len
< msg_len
+ 4)
1110 buffer_consume(&iqueue
, 4);
1112 type
= buffer_get_char(&iqueue
);
1120 case SSH2_FXP_CLOSE
:
1126 case SSH2_FXP_WRITE
:
1129 case SSH2_FXP_LSTAT
:
1132 case SSH2_FXP_FSTAT
:
1135 case SSH2_FXP_SETSTAT
:
1138 case SSH2_FXP_FSETSTAT
:
1141 case SSH2_FXP_OPENDIR
:
1144 case SSH2_FXP_READDIR
:
1147 case SSH2_FXP_REMOVE
:
1150 case SSH2_FXP_MKDIR
:
1153 case SSH2_FXP_RMDIR
:
1156 case SSH2_FXP_REALPATH
:
1162 case SSH2_FXP_RENAME
:
1165 case SSH2_FXP_READLINK
:
1168 case SSH2_FXP_SYMLINK
:
1171 case SSH2_FXP_EXTENDED
:
1175 error("Unknown message %d", type
);
1178 /* discard the remaining bytes from the current packet */
1179 if (buf_len
< buffer_len(&iqueue
))
1180 fatal("iqueue grew unexpectedly");
1181 consumed
= buf_len
- buffer_len(&iqueue
);
1182 if (msg_len
< consumed
)
1183 fatal("msg_len %d < consumed %d", msg_len
, consumed
);
1184 if (msg_len
> consumed
)
1185 buffer_consume(&iqueue
, msg_len
- consumed
);
1188 /* Cleanup handler that logs active handles upon normal exit */
1192 if (pw
!= NULL
&& client_addr
!= NULL
) {
1194 logit("session closed for local user %s from [%s]",
1195 pw
->pw_name
, client_addr
);
1203 extern char *__progname
;
1206 "usage: %s [-he] [-l log_level] [-f log_facility]\n", __progname
);
1211 main(int argc
, char **argv
)
1213 fd_set
*rset
, *wset
;
1214 int in
, out
, max
, ch
, skipargs
= 0, log_stderr
= 0;
1215 ssize_t len
, olen
, set_size
;
1216 SyslogFacility log_facility
= SYSLOG_FACILITY_AUTH
;
1217 char *cp
, buf
[4*4096];
1219 extern char *optarg
;
1220 extern char *__progname
;
1222 /* Ensure that fds 0, 1 and 2 are open or directed to /dev/null */
1225 __progname
= ssh_get_progname(argv
[0]);
1226 log_init(__progname
, log_level
, log_facility
, log_stderr
);
1228 while (!skipargs
&& (ch
= getopt(argc
, argv
, "C:f:l:che")) != -1) {
1232 * Ignore all arguments if we are invoked as a
1233 * shell using "sftp-server -c command"
1241 log_level
= log_level_number(optarg
);
1242 if (log_level
== SYSLOG_LEVEL_NOT_SET
)
1243 error("Invalid log level \"%s\"", optarg
);
1246 log_facility
= log_facility_number(optarg
);
1247 if (log_level
== SYSLOG_FACILITY_NOT_SET
)
1248 error("Invalid log facility \"%s\"", optarg
);
1256 log_init(__progname
, log_level
, log_facility
, log_stderr
);
1258 if ((cp
= getenv("SSH_CONNECTION")) != NULL
) {
1259 client_addr
= xstrdup(cp
);
1260 if ((cp
= strchr(client_addr
, ' ')) == NULL
)
1261 fatal("Malformed SSH_CONNECTION variable: \"%s\"",
1262 getenv("SSH_CONNECTION"));
1265 client_addr
= xstrdup("UNKNOWN");
1267 if ((pw
= getpwuid(getuid())) == NULL
)
1268 fatal("No user found for uid %lu", (u_long
)getuid());
1271 logit("session opened for local user %s from [%s]",
1272 pw
->pw_name
, client_addr
);
1276 in
= dup(STDIN_FILENO
);
1277 out
= dup(STDOUT_FILENO
);
1280 setmode(in
, O_BINARY
);
1281 setmode(out
, O_BINARY
);
1290 buffer_init(&iqueue
);
1291 buffer_init(&oqueue
);
1293 set_size
= howmany(max
+ 1, NFDBITS
) * sizeof(fd_mask
);
1294 rset
= (fd_set
*)xmalloc(set_size
);
1295 wset
= (fd_set
*)xmalloc(set_size
);
1298 memset(rset
, 0, set_size
);
1299 memset(wset
, 0, set_size
);
1302 * Ensure that we can read a full buffer and handle
1303 * the worst-case length packet it can generate,
1304 * otherwise apply backpressure by stopping reads.
1306 if (buffer_check_alloc(&iqueue
, sizeof(buf
)) &&
1307 buffer_check_alloc(&oqueue
, SFTP_MAX_MSG_LENGTH
))
1310 olen
= buffer_len(&oqueue
);
1314 if (select(max
+1, rset
, wset
, NULL
, NULL
) < 0) {
1317 error("select: %s", strerror(errno
));
1321 /* copy stdin to iqueue */
1322 if (FD_ISSET(in
, rset
)) {
1323 len
= read(in
, buf
, sizeof buf
);
1327 } else if (len
< 0) {
1328 error("read: %s", strerror(errno
));
1331 buffer_append(&iqueue
, buf
, len
);
1334 /* send oqueue to stdout */
1335 if (FD_ISSET(out
, wset
)) {
1336 len
= write(out
, buffer_ptr(&oqueue
), olen
);
1338 error("write: %s", strerror(errno
));
1341 buffer_consume(&oqueue
, len
);
1346 * Process requests from client if we can fit the results
1347 * into the output buffer, otherwise stop processing input
1348 * and let the output queue drain.
1350 if (buffer_check_alloc(&oqueue
, SFTP_MAX_MSG_LENGTH
))