1 /***************************************************************************
2 * Copyright (C) 2005 by Dominic Rath *
3 * Dominic.Rath@gmx.de *
5 * Copyright (C) 2007,2008 Øyvind Harboe *
6 * oyvind.harboe@zylin.com *
8 * Copyright (C) 2008 by Spencer Oliver *
9 * spen@spen-soft.co.uk *
11 * This program is free software; you can redistribute it and/or modify *
12 * it under the terms of the GNU General Public License as published by *
13 * the Free Software Foundation; either version 2 of the License, or *
14 * (at your option) any later version. *
16 * This program is distributed in the hope that it will be useful, *
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
19 * GNU General Public License for more details. *
21 * You should have received a copy of the GNU General Public License *
22 * along with this program; if not, write to the *
23 * Free Software Foundation, Inc., *
24 * 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. *
25 ***************************************************************************/
30 #include "telnet_server.h"
31 #include "target_request.h"
33 static unsigned short telnet_port
= 4444;
35 int handle_exit_command(struct command_context_s
*cmd_ctx
, char *cmd
, char **args
, int argc
);
36 int handle_telnet_port_command(struct command_context_s
*cmd_ctx
, char *cmd
, char **args
, int argc
);
38 static char *negotiate
=
39 "\xFF\xFB\x03" /* IAC WILL Suppress Go Ahead */
40 "\xFF\xFB\x01" /* IAC WILL Echo */
41 "\xFF\xFD\x03" /* IAC DO Suppress Go Ahead */
42 "\xFF\xFE\x01"; /* IAC DON'T Echo */
44 #define CTRL(c) (c - '@')
46 /* The only way we can detect that the socket is closed is the first time
47 * we write to it, we will fail. Subsequent write operations will
50 int telnet_write(connection_t
*connection
, const void *data
, int len
)
52 telnet_connection_t
*t_con
= connection
->priv
;
54 return ERROR_SERVER_REMOTE_CLOSED
;
56 if (write_socket(connection
->fd
, data
, len
) == len
)
61 return ERROR_SERVER_REMOTE_CLOSED
;
64 int telnet_prompt(connection_t
*connection
)
66 telnet_connection_t
*t_con
= connection
->priv
;
68 telnet_write(connection
, "\r", 1); /* the prompt is always placed at the line beginning */
69 return telnet_write(connection
, t_con
->prompt
, strlen(t_con
->prompt
));
72 int telnet_outputline(connection_t
*connection
, const char *line
)
76 /* process lines in buffer */
78 char *line_end
= strchr(line
, '\n');
85 telnet_write(connection
, line
, len
);
88 telnet_write(connection
, "\r\n", 2);
100 int telnet_output(struct command_context_s
*cmd_ctx
, const char* line
)
102 connection_t
*connection
= cmd_ctx
->output_handler_priv
;
104 return telnet_outputline(connection
, line
);
107 void telnet_log_callback(void *priv
, const char *file
, int line
,
108 const char *function
, const char *string
)
110 connection_t
*connection
= priv
;
111 telnet_connection_t
*t_con
= connection
->priv
;
114 /* if there is no prompt, simply output the message */
115 if (t_con
->line_cursor
< 0)
117 telnet_outputline(connection
, string
);
121 /* clear the command line */
122 telnet_write(connection
, "\r", 1);
123 for (i
= strlen(t_con
->prompt
) + t_con
->line_size
; i
> 0; i
-= 16)
124 telnet_write(connection
, " ", i
> 16 ? 16 : i
);
125 telnet_write(connection
, "\r", 1);
127 /* output the message */
128 telnet_outputline(connection
, string
);
130 /* put the command line to its previous state */
131 telnet_prompt(connection
);
132 telnet_write(connection
, t_con
->line
, t_con
->line_size
);
133 for (i
= t_con
->line_size
; i
> t_con
->line_cursor
; i
--)
134 telnet_write(connection
, "\b", 1);
137 int telnet_new_connection(connection_t
*connection
)
139 telnet_connection_t
*telnet_connection
= malloc(sizeof(telnet_connection_t
));
140 telnet_service_t
*telnet_service
= connection
->service
->priv
;
143 connection
->priv
= telnet_connection
;
145 /* initialize telnet connection information */
146 telnet_connection
->closed
= 0;
147 telnet_connection
->line_size
= 0;
148 telnet_connection
->line_cursor
= 0;
149 telnet_connection
->option_size
= 0;
150 telnet_connection
->prompt
= strdup("> ");
151 telnet_connection
->state
= TELNET_STATE_DATA
;
153 /* output goes through telnet connection */
154 command_set_output_handler(connection
->cmd_ctx
, telnet_output
, connection
);
156 /* negotiate telnet options */
157 telnet_write(connection
, negotiate
, strlen(negotiate
));
159 /* print connection banner */
160 if (telnet_service
->banner
)
162 telnet_write(connection
, telnet_service
->banner
, strlen(telnet_service
->banner
));
163 telnet_write(connection
, "\r\n", 2);
166 telnet_prompt(connection
);
168 /* initialize history */
169 for (i
= 0; i
< TELNET_LINE_HISTORY_SIZE
; i
++)
171 telnet_connection
->history
[i
] = NULL
;
173 telnet_connection
->next_history
= 0;
174 telnet_connection
->current_history
= 0;
176 log_add_callback(telnet_log_callback
, connection
);
181 void telnet_clear_line(connection_t
*connection
, telnet_connection_t
*t_con
)
183 /* move to end of line */
184 if (t_con
->line_cursor
< t_con
->line_size
)
186 telnet_write(connection
, t_con
->line
+ t_con
->line_cursor
, t_con
->line_size
- t_con
->line_cursor
);
189 /* backspace, overwrite with space, backspace */
190 while (t_con
->line_size
> 0)
192 telnet_write(connection
, "\b \b", 3);
195 t_con
->line_cursor
= 0;
198 int telnet_input(connection_t
*connection
)
201 char buffer
[TELNET_BUFFER_SIZE
];
203 telnet_connection_t
*t_con
= connection
->priv
;
204 command_context_t
*command_context
= connection
->cmd_ctx
;
206 bytes_read
= read_socket(connection
->fd
, buffer
, TELNET_BUFFER_SIZE
);
209 return ERROR_SERVER_REMOTE_CLOSED
;
210 else if (bytes_read
== -1)
212 LOG_ERROR("error during read: %s", strerror(errno
));
213 return ERROR_SERVER_REMOTE_CLOSED
;
219 switch (t_con
->state
)
221 case TELNET_STATE_DATA
:
222 if (*buf_p
== '\xff')
224 t_con
->state
= TELNET_STATE_IAC
;
228 if (isprint(*buf_p
)) /* printable character */
230 /* watch buffer size leaving one spare character for string null termination */
231 if (t_con
->line_size
== TELNET_LINE_MAX_SIZE
-1)
233 /* output audible bell if buffer is full */
234 telnet_write(connection
, "\x07", 1); /* "\a" does not work, at least on windows */
236 else if (t_con
->line_cursor
== t_con
->line_size
)
238 telnet_write(connection
, buf_p
, 1);
239 t_con
->line
[t_con
->line_size
++] = *buf_p
;
240 t_con
->line_cursor
++;
245 memmove(t_con
->line
+ t_con
->line_cursor
+ 1, t_con
->line
+ t_con
->line_cursor
, t_con
->line_size
- t_con
->line_cursor
);
246 t_con
->line
[t_con
->line_cursor
] = *buf_p
;
248 telnet_write(connection
, t_con
->line
+ t_con
->line_cursor
, t_con
->line_size
- t_con
->line_cursor
);
249 t_con
->line_cursor
++;
250 for (i
= t_con
->line_cursor
; i
< t_con
->line_size
; i
++)
252 telnet_write(connection
, "\b", 1);
256 else /* non-printable */
258 if (*buf_p
== 0x1b) /* escape */
260 t_con
->state
= TELNET_STATE_ESCAPE
;
261 t_con
->last_escape
= '\x00';
263 else if ((*buf_p
== 0xd) || (*buf_p
== 0xa)) /* CR/LF */
267 /* skip over combinations with CR/LF and NUL characters */
268 if ((bytes_read
> 1) && ((*(buf_p
+ 1) == 0xa) || (*(buf_p
+ 1) == 0xd)))
273 if ((bytes_read
> 1) && (*(buf_p
+ 1) == 0))
278 t_con
->line
[t_con
->line_size
] = 0;
280 telnet_write(connection
, "\r\n\x00", 3);
282 if (strcmp(t_con
->line
, "history") == 0)
285 for (i
= 1; i
< TELNET_LINE_HISTORY_SIZE
; i
++)
287 /* the t_con->next_history line contains empty string (unless NULL), thus it is not printed */
288 char *history_line
= t_con
->history
[(t_con
->next_history
+ i
) % TELNET_LINE_HISTORY_SIZE
];
291 telnet_write(connection
, history_line
, strlen(history_line
));
292 telnet_write(connection
, "\r\n\x00", 3);
295 t_con
->line_size
= 0;
296 t_con
->line_cursor
= 0;
300 /* save only non-blank not repeating lines in the history */
301 char *prev_line
= t_con
->history
[(t_con
->current_history
> 0) ? t_con
->current_history
- 1 : TELNET_LINE_HISTORY_SIZE
-1];
302 if (*t_con
->line
&& (prev_line
== NULL
|| strcmp(t_con
->line
, prev_line
)))
304 /* if the history slot is already taken, free it */
305 if (t_con
->history
[t_con
->next_history
])
307 free(t_con
->history
[t_con
->next_history
]);
310 /* add line to history */
311 t_con
->history
[t_con
->next_history
] = strdup(t_con
->line
);
313 /* wrap history at TELNET_LINE_HISTORY_SIZE */
314 t_con
->next_history
= (t_con
->next_history
+ 1) % TELNET_LINE_HISTORY_SIZE
;
316 /* current history line starts at the new entry */
317 t_con
->current_history
= t_con
->next_history
;
319 if (t_con
->history
[t_con
->current_history
])
321 free(t_con
->history
[t_con
->current_history
]);
323 t_con
->history
[t_con
->current_history
] = strdup("");
326 t_con
->line_size
= 0;
328 t_con
->line_cursor
= -1; /* to supress prompt in log callback during command execution */
330 retval
= command_run_line(command_context
, t_con
->line
);
332 t_con
->line_cursor
= 0;
334 if (retval
== ERROR_COMMAND_CLOSE_CONNECTION
)
335 return ERROR_SERVER_REMOTE_CLOSED
;
337 retval
= telnet_prompt(connection
);
338 if (retval
== ERROR_SERVER_REMOTE_CLOSED
)
339 return ERROR_SERVER_REMOTE_CLOSED
;
342 else if ((*buf_p
== 0x7f) || (*buf_p
== 0x8)) /* delete character */
344 if (t_con
->line_cursor
> 0)
346 if (t_con
->line_cursor
!= t_con
->line_size
)
349 telnet_write(connection
, "\b", 1);
350 t_con
->line_cursor
--;
352 memmove(t_con
->line
+ t_con
->line_cursor
, t_con
->line
+ t_con
->line_cursor
+ 1, t_con
->line_size
- t_con
->line_cursor
);
354 telnet_write(connection
, t_con
->line
+ t_con
->line_cursor
, t_con
->line_size
- t_con
->line_cursor
);
355 telnet_write(connection
, " \b", 2);
356 for (i
= t_con
->line_cursor
; i
< t_con
->line_size
; i
++)
358 telnet_write(connection
, "\b", 1);
364 t_con
->line_cursor
--;
365 /* back space: move the 'printer' head one char back, overwrite with space, move back again */
366 telnet_write(connection
, "\b \b", 3);
370 else if (*buf_p
== 0x15) /* clear line */
372 telnet_clear_line(connection
, t_con
);
374 else if (*buf_p
== CTRL('B')) /* cursor left */
376 if (t_con
->line_cursor
> 0)
378 telnet_write(connection
, "\b", 1);
379 t_con
->line_cursor
--;
381 t_con
->state
= TELNET_STATE_DATA
;
383 else if (*buf_p
== CTRL('F')) /* cursor right */
385 if (t_con
->line_cursor
< t_con
->line_size
)
387 telnet_write(connection
, t_con
->line
+ t_con
->line_cursor
++, 1);
389 t_con
->state
= TELNET_STATE_DATA
;
393 LOG_DEBUG("unhandled nonprintable: %2.2x", *buf_p
);
398 case TELNET_STATE_IAC
:
402 t_con
->state
= TELNET_STATE_DONT
;
405 t_con
->state
= TELNET_STATE_DO
;
408 t_con
->state
= TELNET_STATE_WONT
;
411 t_con
->state
= TELNET_STATE_WILL
;
415 case TELNET_STATE_SB
:
417 case TELNET_STATE_SE
:
419 case TELNET_STATE_WILL
:
420 case TELNET_STATE_WONT
:
421 case TELNET_STATE_DO
:
422 case TELNET_STATE_DONT
:
423 t_con
->state
= TELNET_STATE_DATA
;
425 case TELNET_STATE_ESCAPE
:
426 if (t_con
->last_escape
== '[')
428 if (*buf_p
== 'D') /* cursor left */
430 if (t_con
->line_cursor
> 0)
432 telnet_write(connection
, "\b", 1);
433 t_con
->line_cursor
--;
435 t_con
->state
= TELNET_STATE_DATA
;
437 else if (*buf_p
== 'C') /* cursor right */
439 if (t_con
->line_cursor
< t_con
->line_size
)
441 telnet_write(connection
, t_con
->line
+ t_con
->line_cursor
++, 1);
443 t_con
->state
= TELNET_STATE_DATA
;
445 else if (*buf_p
== 'A') /* cursor up */
447 int last_history
= (t_con
->current_history
> 0) ? t_con
->current_history
- 1 : TELNET_LINE_HISTORY_SIZE
-1;
448 if (t_con
->history
[last_history
])
450 telnet_clear_line(connection
, t_con
);
451 t_con
->line_size
= strlen(t_con
->history
[last_history
]);
452 t_con
->line_cursor
= t_con
->line_size
;
453 memcpy(t_con
->line
, t_con
->history
[last_history
], t_con
->line_size
);
454 telnet_write(connection
, t_con
->line
, t_con
->line_size
);
455 t_con
->current_history
= last_history
;
457 t_con
->state
= TELNET_STATE_DATA
;
459 else if (*buf_p
== 'B') /* cursor down */
461 int next_history
= (t_con
->current_history
+ 1) % TELNET_LINE_HISTORY_SIZE
;
462 if (t_con
->history
[next_history
])
464 telnet_clear_line(connection
, t_con
);
465 t_con
->line_size
= strlen(t_con
->history
[next_history
]);
466 t_con
->line_cursor
= t_con
->line_size
;
467 memcpy(t_con
->line
, t_con
->history
[next_history
], t_con
->line_size
);
468 telnet_write(connection
, t_con
->line
, t_con
->line_size
);
469 t_con
->current_history
= next_history
;
471 t_con
->state
= TELNET_STATE_DATA
;
473 else if (*buf_p
== '3')
475 t_con
->last_escape
= *buf_p
;
479 t_con
->state
= TELNET_STATE_DATA
;
482 else if (t_con
->last_escape
== '3')
484 /* Remove character */
487 if (t_con
->line_cursor
< t_con
->line_size
)
491 /* remove char from line buffer */
492 memmove(t_con
->line
+ t_con
->line_cursor
, t_con
->line
+ t_con
->line_cursor
+ 1, t_con
->line_size
- t_con
->line_cursor
);
494 /* print remainder of buffer */
495 telnet_write(connection
, t_con
->line
+ t_con
->line_cursor
, t_con
->line_size
- t_con
->line_cursor
);
496 /* overwrite last char with whitespace */
497 telnet_write(connection
, " \b", 2);
499 /* move back to cursor position*/
500 for (i
= t_con
->line_cursor
; i
< t_con
->line_size
; i
++)
502 telnet_write(connection
, "\b", 1);
506 t_con
->state
= TELNET_STATE_DATA
;
510 t_con
->state
= TELNET_STATE_DATA
;
513 else if (t_con
->last_escape
== '\x00')
517 t_con
->last_escape
= *buf_p
;
521 t_con
->state
= TELNET_STATE_DATA
;
526 LOG_ERROR("BUG: unexpected value in t_con->last_escape");
527 t_con
->state
= TELNET_STATE_DATA
;
532 LOG_ERROR("unknown telnet state");
543 int telnet_connection_closed(connection_t
*connection
)
545 telnet_connection_t
*t_con
= connection
->priv
;
548 log_remove_callback(telnet_log_callback
, connection
);
553 t_con
->prompt
= NULL
;
556 for (i
= 0; i
< TELNET_LINE_HISTORY_SIZE
; i
++)
558 if (t_con
->history
[i
])
560 free(t_con
->history
[i
]);
561 t_con
->history
[i
] = NULL
;
565 /* if this connection registered a debug-message receiver delete it */
566 delete_debug_msg_receiver(connection
->cmd_ctx
, NULL
);
568 if (connection
->priv
)
570 free(connection
->priv
);
571 connection
->priv
= NULL
;
575 LOG_ERROR("BUG: connection->priv == NULL");
581 int telnet_set_prompt(connection_t
*connection
, char *prompt
)
583 telnet_connection_t
*t_con
= connection
->priv
;
585 if (t_con
->prompt
!= NULL
)
588 t_con
->prompt
= strdup(prompt
);
593 int telnet_init(char *banner
)
595 telnet_service_t
*telnet_service
= malloc(sizeof(telnet_service_t
));
597 if (telnet_port
== 0)
599 LOG_INFO("telnet port disabled");
603 telnet_service
->banner
= banner
;
605 add_service("telnet", CONNECTION_TCP
, telnet_port
, 1, telnet_new_connection
, telnet_input
, telnet_connection_closed
, telnet_service
);
610 int telnet_register_commands(command_context_t
*command_context
)
612 register_command(command_context
, NULL
, "exit", handle_exit_command
,
613 COMMAND_EXEC
, "exit telnet session");
615 register_command(command_context
, NULL
, "telnet_port", handle_telnet_port_command
,
616 COMMAND_ANY
, "port on which to listen for incoming telnet connections");
621 /* daemon configuration command telnet_port */
622 int handle_telnet_port_command(struct command_context_s
*cmd_ctx
, char *cmd
, char **args
, int argc
)
626 command_print(cmd_ctx
, "%d", telnet_port
);
630 telnet_port
= strtoul(args
[0], NULL
, 0);
635 int handle_exit_command(struct command_context_s
*cmd_ctx
, char *cmd
, char **args
, int argc
)
637 return ERROR_COMMAND_CLOSE_CONNECTION
;