1 ;;; tramp-gw.el --- Tramp utility functions for HTTP tunnels and SOCKS gateways
3 ;; Copyright (C) 2007-2014 Free Software Foundation, Inc.
5 ;; Author: Michael Albinus <michael.albinus@gmx.de>
6 ;; Keywords: comm, processes
9 ;; This file is part of GNU Emacs.
11 ;; GNU Emacs is free software: you can redistribute it and/or modify
12 ;; it under the terms of the GNU General Public License as published by
13 ;; the Free Software Foundation, either version 3 of the License, or
14 ;; (at your option) any later version.
16 ;; GNU Emacs is distributed in the hope that it will be useful,
17 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
18 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 ;; GNU General Public License for more details.
21 ;; You should have received a copy of the GNU General Public License
22 ;; along with GNU Emacs. If not, see <http://www.gnu.org/licenses/>.
26 ;; Access functions for HTTP tunnels and SOCKS gateways from Tramp.
27 ;; SOCKS functionality is implemented by socks.el from the w3 package.
28 ;; HTTP tunnels are partly implemented in socks.el and url-http.el;
29 ;; both implementations are not complete. Therefore, it is
30 ;; implemented in this package.
36 ;; Pacify byte-compiler.
40 (defvar socks-noproxy
)
42 ;; We don't add the following methods to `tramp-methods', in order to
43 ;; exclude them from file name completion.
45 ;; Define HTTP tunnel method ...
47 (defconst tramp-gw-tunnel-method
"tunnel"
48 "Method to connect HTTP gateways.")
51 (defconst tramp-gw-default-tunnel-port
8080
52 "Default port for HTTP gateways.")
54 ;; Define SOCKS method ...
56 (defconst tramp-gw-socks-method
"socks"
57 "Method to connect SOCKS servers.")
60 (defconst tramp-gw-default-socks-port
1080
61 "Default port for SOCKS servers.")
63 ;; Autoload the socks library. It is used only when we access a SOCKS server.
64 (autoload 'socks-open-network-stream
"socks")
65 (defvar socks-username
(user-login-name))
67 (list "Default server" "socks" tramp-gw-default-socks-port
5))
69 ;; Add a default for `tramp-default-user-alist'. Default is the local user.
72 'tramp-default-user-alist
74 (regexp-opt (list tramp-gw-tunnel-method tramp-gw-socks-method
))
76 nil
(user-login-name)))
78 ;; Internal file name functions and variables.
80 (defvar tramp-gw-vector nil
81 "Keeps the remote host identification. Needed for Tramp messages.")
83 (defvar tramp-gw-gw-vector nil
84 "Current gateway identification vector.")
86 (defvar tramp-gw-gw-proc nil
87 "Current gateway process.")
89 ;; This variable keeps the listening process, in order to reuse it for
91 (defvar tramp-gw-aux-proc nil
92 "Process listening on local port, as mediation between SSH and the gateway.")
94 (defun tramp-gw-gw-proc-sentinel (proc _event
)
95 "Delete auxiliary process when we are deleted."
96 (unless (memq (process-status proc
) '(run open
))
98 tramp-gw-vector
4 "Deleting auxiliary process `%s'" tramp-gw-gw-proc
)
99 (let* ((tramp-verbose 0)
100 (p (tramp-get-connection-property proc
"process" nil
)))
101 (when (processp p
) (delete-process p
)))))
103 (defun tramp-gw-aux-proc-sentinel (proc _event
)
104 "Activate the different filters for involved gateway and auxiliary processes."
105 (when (memq (process-status proc
) '(run open
))
106 ;; A new process has been spawned from `tramp-gw-aux-proc'.
109 "Opening auxiliary process `%s', speaking with process `%s'"
110 proc tramp-gw-gw-proc
)
111 (tramp-compat-set-process-query-on-exit-flag proc nil
)
112 ;; We don't want debug messages, because the corresponding debug
113 ;; buffer might be undecided.
114 (let ((tramp-verbose 0))
115 (tramp-set-connection-property tramp-gw-gw-proc
"process" proc
)
116 (tramp-set-connection-property proc
"process" tramp-gw-gw-proc
))
117 ;; Set the process-filter functions for both processes.
118 (set-process-filter proc
'tramp-gw-process-filter
)
119 (set-process-filter tramp-gw-gw-proc
'tramp-gw-process-filter
)
120 ;; There might be already some output from the gateway process.
121 (with-current-buffer (process-buffer tramp-gw-gw-proc
)
122 (unless (= (point-min) (point-max))
123 (let ((s (buffer-string)))
124 (delete-region (point) (point-max))
125 (tramp-gw-process-filter tramp-gw-gw-proc s
))))))
127 (defun tramp-gw-process-filter (proc string
)
128 (let ((tramp-verbose 0))
130 (tramp-get-connection-property proc
"process" nil
) string
)))
133 (defun tramp-gw-open-connection (vec gw-vec target-vec
)
134 "Open a remote connection to VEC (see `tramp-file-name' structure).
135 Take GW-VEC as SOCKS or HTTP gateway, i.e. its method must be a
136 gateway method. TARGET-VEC identifies where to connect to via
137 the gateway, it can be different from VEC when there are more
140 It returns a string like \"localhost#port\", which must be used
141 instead of the host name declared in TARGET-VEC."
143 ;; Remember vectors for property retrieval.
144 (setq tramp-gw-vector vec
145 tramp-gw-gw-vector gw-vec
)
147 ;; Start listening auxiliary process.
148 (unless (and (processp tramp-gw-aux-proc
)
149 (memq (process-status tramp-gw-aux-proc
) '(listen)))
151 (vector "aux" (tramp-file-name-user gw-vec
)
152 (tramp-file-name-host gw-vec
) nil nil
)))
153 (setq tramp-gw-aux-proc
154 (make-network-process
155 :name
(tramp-buffer-name aux-vec
) :buffer nil
:host
'local
156 :server t
:noquery t
:service t
:coding
'binary
))
157 (set-process-sentinel tramp-gw-aux-proc
'tramp-gw-aux-proc-sentinel
)
158 (tramp-compat-set-process-query-on-exit-flag tramp-gw-aux-proc nil
)
160 vec
4 "Opening auxiliary process `%s', listening on port %d"
161 tramp-gw-aux-proc
(process-contact tramp-gw-aux-proc
:service
))))
166 (tramp-file-name-method gw-vec
)
167 (tramp-file-name-user gw-vec
)
168 (tramp-file-name-host gw-vec
))))
171 (tramp-file-name-method gw-vec
)
172 (tramp-file-name-user gw-vec
)
173 (tramp-file-name-host gw-vec
)))
174 ;; Declare the SOCKS server to be used.
176 (list "Tramp temporary socks server list"
178 (tramp-file-name-real-host gw-vec
)
180 (or (tramp-file-name-port gw-vec
)
182 (tunnel tramp-gw-default-tunnel-port
)
183 (socks tramp-gw-default-socks-port
)))
184 ;; Type. We support only http and socks5, NO socks4.
185 ;; 'http could be used when HTTP tunnel works in socks.el.
187 ;; The function to be called.
190 (tunnel 'tramp-gw-open-network-stream
)
191 (socks 'socks-open-network-stream
)))
194 ;; Open SOCKS process.
195 (setq tramp-gw-gw-proc
198 (tramp-get-connection-name gw-vec
)
199 (tramp-get-connection-buffer gw-vec
)
200 (tramp-file-name-real-host target-vec
)
201 (tramp-file-name-port target-vec
)))
202 (set-process-sentinel tramp-gw-gw-proc
'tramp-gw-gw-proc-sentinel
)
203 (tramp-compat-set-process-query-on-exit-flag tramp-gw-gw-proc nil
)
205 vec
4 "Opened %s process `%s'"
206 (case gw-method
('tunnel
"HTTP tunnel") ('socks
"SOCKS"))
209 ;; Return the new host for gateway access.
210 (format "localhost#%d" (process-contact tramp-gw-aux-proc
:service
))))
212 (defun tramp-gw-open-network-stream (name buffer host service
)
213 "Open stream to proxy server HOST:SERVICE.
214 Resulting process has name NAME and buffer BUFFER. If
215 authentication is requested from proxy server, provide it."
216 (let ((command (format (concat
217 "CONNECT %s:%d HTTP/1.1\r\n"
219 "Connection: keep-alive\r\n"
220 "User-Agent: Tramp/%s\r\n")
221 host service host service tramp-version
))
228 (when (processp proc
) (delete-process proc
))
229 (with-current-buffer buffer
(erase-buffer))
230 ;; Open network stream.
231 (setq proc
(open-network-stream
232 name buffer
(nth 1 socks-server
) (nth 2 socks-server
)))
233 (set-process-coding-system proc
'binary
'binary
)
234 (tramp-compat-set-process-query-on-exit-flag proc nil
)
235 ;; Send CONNECT command.
236 (process-send-string proc
(format "%s%s\r\n" command authentication
))
238 tramp-gw-vector
6 "\n%s"
241 (tramp-compat-replace-regexp-in-string ;; no password in trace!
242 "Basic [^\r\n]+" "Basic xxxxx" authentication t
)))
243 (with-current-buffer buffer
244 ;; Trap errors to be traced in the right trace buffer. Often,
245 ;; proxies have a timeout of 60". We wait 65" in order to
246 ;; receive an answer this case.
248 (let ((tramp-verbose 0))
249 (tramp-wait-for-regexp proc
65 "\r?\n\r?\n")))
250 ;; Check return code.
251 (goto-char (point-min))
254 (or (search-forward-regexp "\r?\n\r?\n" nil t
) (point-max)))
255 (tramp-message tramp-gw-vector
6 "\n%s" (buffer-string))
256 (goto-char (point-min))
257 (search-forward-regexp "^HTTP/[1-9]\\.[0-9]" nil t
)
258 (case (condition-case nil
(read (current-buffer)) (error))
261 ;; We need basic authentication.
262 (401 (setq authentication
(tramp-gw-basic-authentication nil first
)))
263 ;; Target host not found.
264 (404 (tramp-error-with-buffer
265 (current-buffer) tramp-gw-vector
'file-error
266 "Host %s not found." host
))
267 ;; We need basic proxy authentication.
268 (407 (setq authentication
(tramp-gw-basic-authentication t first
)))
269 ;; Connection failed.
270 (503 (tramp-error-with-buffer
271 (current-buffer) tramp-gw-vector
'file-error
272 "Connection to %s:%d failed." host service
))
273 ;; That doesn't work at all.
274 (t (tramp-error-with-buffer
275 (current-buffer) tramp-gw-vector
'file-error
276 "Access to HTTP server %s:%d failed."
277 (nth 1 socks-server
) (nth 2 socks-server
))))
278 ;; Remove HTTP headers.
279 (delete-region (point-min) (point-max))
282 ;; Return the process.
285 (defun tramp-gw-basic-authentication (proxy pw-cache
)
286 "Return authentication header for CONNECT, based on server request.
287 PROXY is an indication whether we need a Proxy-Authorization header
288 or an Authorization header. If PW-CACHE is non-nil, check for
289 password in password cache. This is done for the first try only."
291 ;; `tramp-current-*' must be set for `tramp-read-passwd'.
292 (let ((tramp-current-method (tramp-file-name-method tramp-gw-gw-vector
))
293 (tramp-current-user (tramp-file-name-user tramp-gw-gw-vector
))
294 (tramp-current-host (tramp-file-name-host tramp-gw-gw-vector
)))
295 (unless pw-cache
(tramp-clear-passwd tramp-gw-gw-vector
))
296 ;; We are already in the right buffer.
298 tramp-gw-vector
5 "%s required"
299 (if proxy
"Proxy authentication" "Authentication"))
300 ;; Search for request header. We accept only basic authentication.
301 (goto-char (point-min))
302 (search-forward-regexp
303 "^\\(Proxy\\|WWW\\)-Authenticate:\\s-*Basic\\s-+realm=")
304 ;; Return authentication string.
307 (if proxy
"Proxy-Authorization" "Authorization")
308 (base64-encode-string
315 "Password for %s@[%s]: " socks-username
(read (current-buffer)))))))))
317 (add-hook 'tramp-unload-hook
319 (unload-feature 'tramp-gw
'force
)))
325 ;; * Provide descriptive Commentary.
326 ;; * Enable it for several gateway processes in parallel.
328 ;;; tramp-gw.el ends here