1 /* Copyright (c) 2010, Jacob Appelbaum, Steven J. Murdoch.
2 * Copyright (c) 2010-2012, The Tor Project, Inc. */
3 /* See LICENSE for licensing information */
6 * \file tor-fw-helper.c
7 * \brief The main wrapper around our firewall helper logic.
11 * tor-fw-helper is a tool for opening firewalls with NAT-PMP and UPnP; this
12 * tool is designed to be called by hand or by Tor by way of a exec() at a
25 #include "container.h"
31 #include "tor-fw-helper.h"
33 #include "tor-fw-helper-natpmp.h"
36 #include "tor-fw-helper-upnp.h"
39 /** This is our meta storage type - it holds information about each helper
40 including the total number of helper backends, function pointers, and helper
42 typedef struct backends_t
{
43 /** The total number of backends */
45 /** The backend functions as an array */
46 tor_fw_backend_t backend_ops
[MAX_BACKENDS
];
47 /** The internal backend state */
48 void *backend_state
[MAX_BACKENDS
];
51 /** Initialize each backend helper with the user input stored in <b>options</b>
52 * and put the results in the <b>backends</b> struct. */
54 init_backends(tor_fw_options_t
*options
, backends_t
*backends
)
58 tor_fw_backend_t
*backend_ops_list
[MAX_BACKENDS
];
60 /* First, build a list of the working backends. */
63 backend_ops_list
[n
++] = (tor_fw_backend_t
*) tor_fw_get_miniupnp_backend();
66 backend_ops_list
[n
++] = (tor_fw_backend_t
*) tor_fw_get_natpmp_backend();
70 /* Now, for each backend that might work, try to initialize it.
71 * That's how we roll, initialized.
74 for (i
=0; i
<n_available
; ++i
) {
75 data
= calloc(1, backend_ops_list
[i
]->state_len
);
80 r
= backend_ops_list
[i
]->init(options
, data
);
82 backends
->backend_ops
[n
] = *backend_ops_list
[i
];
83 backends
->backend_state
[n
] = data
;
89 backends
->n_backends
= n
;
94 /** Return the proper commandline switches when the user needs information. */
98 fprintf(stderr
, "tor-fw-helper usage:\n"
102 " [-g|--fetch-public-ip]\n"
103 " [-p|--forward-port ([<external port>]:<internal port>])\n");
106 /** Log commandline options to a hardcoded file <b>tor-fw-helper.log</b> in the
107 * current working directory. */
109 log_commandline_options(int argc
, char **argv
)
115 /* Open the log file */
116 logfile
= fopen("tor-fw-helper.log", "a");
120 /* Send all commandline arguments to the file */
122 retval
= fprintf(logfile
, "START: %s\n", ctime(&now
));
123 for (i
= 0; i
< argc
; i
++) {
124 retval
= fprintf(logfile
, "ARG: %d: %s\n", i
, argv
[i
]);
128 retval
= fprintf(stderr
, "ARG: %d: %s\n", i
, argv
[i
]);
133 retval
= fprintf(logfile
, "END: %s\n", ctime(&now
));
135 /* Close and clean up */
136 retval
= fclose(logfile
);
139 /* If there was an error during writing */
145 /** Iterate over over each of the supported <b>backends</b> and attempt to
146 * fetch the public ip. */
148 tor_fw_fetch_public_ip(tor_fw_options_t
*tor_fw_options
,
149 backends_t
*backends
)
154 if (tor_fw_options
->verbose
)
155 fprintf(stderr
, "V: tor_fw_fetch_public_ip\n");
157 for (i
=0; i
<backends
->n_backends
; ++i
) {
158 if (tor_fw_options
->verbose
) {
159 fprintf(stderr
, "V: running backend_state now: %i\n", i
);
160 fprintf(stderr
, "V: size of backend state: %u\n",
161 (int)(backends
->backend_ops
)[i
].state_len
);
162 fprintf(stderr
, "V: backend state name: %s\n",
163 (char *)(backends
->backend_ops
)[i
].name
);
165 r
= backends
->backend_ops
[i
].fetch_public_ip(tor_fw_options
,
166 backends
->backend_state
[i
]);
167 fprintf(stderr
, "tor-fw-helper: tor_fw_fetch_public_ip backend %s "
168 " returned: %i\n", (char *)(backends
->backend_ops
)[i
].name
, r
);
172 /** Print a spec-conformant string to stdout describing the results of
173 * the TCP port forwarding operation from <b>external_port</b> to
174 * <b>internal_port</b>. */
176 tor_fw_helper_report_port_fw_results(uint16_t internal_port
,
177 uint16_t external_port
,
181 char *report_string
= NULL
;
183 tor_asprintf(&report_string
, "%s %s %u %u %s %s\n",
186 external_port
, internal_port
,
187 succeded
? "SUCCESS" : "FAIL",
189 fprintf(stdout
, "%s", report_string
);
191 tor_free(report_string
);
194 #define tor_fw_helper_report_port_fw_fail(i, e, m) \
195 tor_fw_helper_report_port_fw_results((i), (e), 0, (m))
197 #define tor_fw_helper_report_port_fw_success(i, e, m) \
198 tor_fw_helper_report_port_fw_results((i), (e), 1, (m))
200 /** Return a heap-allocated string containing the list of our
201 * backends. It can be used in log messages. Be sure to free it
204 get_list_of_backends_string(backends_t
*backends
)
206 char *backend_names
= NULL
;
208 smartlist_t
*backend_names_sl
= smartlist_new();
210 assert(backends
->n_backends
);
212 for (i
=0; i
<backends
->n_backends
; ++i
)
213 smartlist_add(backend_names_sl
, (char *) backends
->backend_ops
[i
].name
);
215 backend_names
= smartlist_join_strings(backend_names_sl
, ", ", 0, NULL
);
216 smartlist_free(backend_names_sl
);
218 return backend_names
;
221 /** Iterate over each of the supported <b>backends</b> and attempt to add a
222 * port forward for the port stored in <b>tor_fw_options</b>. */
224 tor_fw_add_ports(tor_fw_options_t
*tor_fw_options
,
225 backends_t
*backends
)
231 if (tor_fw_options
->verbose
)
232 fprintf(stderr
, "V: %s\n", __func__
);
234 /** Loop all ports that need to be forwarded, and try to use our
235 * backends for each port. If a backend succeeds, break the loop,
236 * report success and get to the next port. If all backends fail,
237 * report failure for that port. */
238 SMARTLIST_FOREACH_BEGIN(tor_fw_options
->ports_to_forward
,
239 port_to_forward_t
*, port_to_forward
) {
243 for (i
=0; i
<backends
->n_backends
; ++i
) {
244 if (tor_fw_options
->verbose
) {
245 fprintf(stderr
, "V: running backend_state now: %i\n", i
);
246 fprintf(stderr
, "V: size of backend state: %u\n",
247 (int)(backends
->backend_ops
)[i
].state_len
);
248 fprintf(stderr
, "V: backend state name: %s\n",
249 (const char *) backends
->backend_ops
[i
].name
);
253 backends
->backend_ops
[i
].add_tcp_mapping(port_to_forward
->internal_port
,
254 port_to_forward
->external_port
,
255 tor_fw_options
->verbose
,
256 backends
->backend_state
[i
]);
257 if (r
== 0) { /* backend success */
258 tor_fw_helper_report_port_fw_success(port_to_forward
->internal_port
,
259 port_to_forward
->external_port
,
260 backends
->backend_ops
[i
].name
);
265 fprintf(stderr
, "tor-fw-helper: tor_fw_add_port backend %s "
267 (const char *) backends
->backend_ops
[i
].name
, r
);
270 if (!succeeded
) { /* all backends failed */
271 char *list_of_backends_str
= get_list_of_backends_string(backends
);
272 char *fail_msg
= NULL
;
273 tor_asprintf(&fail_msg
, "All port forwarding backends (%s) failed.",
274 list_of_backends_str
);
275 tor_fw_helper_report_port_fw_fail(port_to_forward
->internal_port
,
276 port_to_forward
->external_port
,
278 tor_free(list_of_backends_str
);
282 } SMARTLIST_FOREACH_END(port_to_forward
);
285 /** Called before we make any calls to network-related functions.
286 * (Some operating systems require their network libraries to be
287 * initialized.) (from common/compat.c) */
289 tor_fw_helper_network_init(void)
292 /* This silly exercise is necessary before windows will allow
293 * gethostbyname to work. */
296 r
= WSAStartup(0x101, &WSAData
);
298 fprintf(stderr
, "E: Error initializing Windows network layer "
302 /* WSAData.iMaxSockets might show the max sockets we're allowed to use.
303 * We might use it to complain if we're trying to be a server but have
304 * too few sockets available. */
309 /** Parse the '-p' argument of tor-fw-helper. Its format is
310 * [<external port>]:<internal port>, and <external port> is optional.
311 * Return NULL if <b>arg</b> was c0rrupted. */
312 static port_to_forward_t
*
313 parse_port(const char *arg
)
315 smartlist_t
*sl
= smartlist_new();
316 port_to_forward_t
*port_to_forward
= NULL
;
317 char *port_str
= NULL
;
321 smartlist_split_string(sl
, arg
, ":", 0, 0);
322 if (smartlist_len(sl
) != 2)
325 port_to_forward
= tor_malloc(sizeof(port_to_forward_t
));
326 if (!port_to_forward
)
329 port_str
= smartlist_get(sl
, 0); /* macroify ? */
330 port
= (int)tor_parse_long(port_str
, 10, 1, 65535, &ok
, NULL
);
331 if (!ok
&& strlen(port_str
)) /* ":1555" is valid */
333 port_to_forward
->external_port
= port
;
335 port_str
= smartlist_get(sl
, 1);
336 port
= (int)tor_parse_long(port_str
, 10, 1, 65535, &ok
, NULL
);
339 port_to_forward
->internal_port
= port
;
344 tor_free(port_to_forward
);
347 SMARTLIST_FOREACH(sl
, char *, cp
, tor_free(cp
));
350 return port_to_forward
;
353 /** Report a failure of epic proportions: We didn't manage to
354 * initialize any port forwarding backends. */
356 report_full_fail(const smartlist_t
*ports_to_forward
, backends_t
*backends
)
358 char *list_of_backends_str
= NULL
;
359 char *fail_msg
= NULL
;
361 if (!ports_to_forward
)
364 list_of_backends_str
= get_list_of_backends_string(backends
);
365 tor_asprintf(&fail_msg
,
366 "Port forwarding backends (%s) could not be initialized.",
367 list_of_backends_str
);
369 SMARTLIST_FOREACH_BEGIN(ports_to_forward
,
370 const port_to_forward_t
*, port_to_forward
) {
371 tor_fw_helper_report_port_fw_fail(port_to_forward
->internal_port
,
372 port_to_forward
->external_port
,
374 } SMARTLIST_FOREACH_END(port_to_forward
);
376 tor_free(list_of_backends_str
);
381 main(int argc
, char **argv
)
386 tor_fw_options_t tor_fw_options
;
387 backends_t backend_state
;
389 memset(&tor_fw_options
, 0, sizeof(tor_fw_options
));
390 memset(&backend_state
, 0, sizeof(backend_state
));
392 // Parse CLI arguments.
394 int option_index
= 0;
395 static struct option long_options
[] =
397 {"verbose", 0, 0, 'v'},
400 {"fetch-public-ip", 0, 0, 'g'},
401 {"test-commandline", 0, 0, 'T'},
405 c
= getopt_long(argc
, argv
, "vhp:gT",
406 long_options
, &option_index
);
411 case 'v': tor_fw_options
.verbose
= 1; break;
412 case 'h': tor_fw_options
.help
= 1; usage(); exit(1); break;
414 port_to_forward_t
*port_to_forward
= parse_port(optarg
);
415 if (!port_to_forward
) {
416 fprintf(stderr
, "E: Failed to parse '%s'.\n", optarg
);
421 /* If no external port was given (it's optional), set it to be
422 * equal with the internal port. */
423 if (!port_to_forward
->external_port
) {
424 assert(port_to_forward
->internal_port
);
425 if (tor_fw_options
.verbose
)
426 fprintf(stderr
, "V: No external port was given. Setting to %u.\n",
427 port_to_forward
->internal_port
);
428 port_to_forward
->external_port
= port_to_forward
->internal_port
;
431 if (!tor_fw_options
.ports_to_forward
)
432 tor_fw_options
.ports_to_forward
= smartlist_new();
434 smartlist_add(tor_fw_options
.ports_to_forward
, port_to_forward
);
438 case 'g': tor_fw_options
.fetch_public_ip
= 1; break;
439 case 'T': tor_fw_options
.test_commandline
= 1; break;
441 default : fprintf(stderr
, "Unknown option!\n"); usage(); exit(1);
447 if (tor_fw_options
.verbose
)
448 fprintf(stderr
, "V: tor-fw-helper version %s\n"
449 "V: We were called with the following arguments:\n"
450 "V: verbose = %d, help = %d, fetch_public_ip = %u\n",
451 tor_fw_version
, tor_fw_options
.verbose
, tor_fw_options
.help
,
452 tor_fw_options
.fetch_public_ip
);
454 if (tor_fw_options
.verbose
&& tor_fw_options
.ports_to_forward
) {
455 fprintf(stderr
, "V: TCP forwarding:\n");
456 SMARTLIST_FOREACH(tor_fw_options
.ports_to_forward
,
457 const port_to_forward_t
*, port_to_forward
,
458 fprintf(stderr
, "V: External: %u, Internal: %u\n",
459 port_to_forward
->external_port
,
460 port_to_forward
->internal_port
));
464 if (tor_fw_options
.test_commandline
) {
465 return log_commandline_options(argc
, argv
);
468 // See if the user actually wants us to do something.
469 if (!tor_fw_options
.fetch_public_ip
&& !tor_fw_options
.ports_to_forward
) {
470 fprintf(stderr
, "E: We require a port to be forwarded or "
471 "fetch_public_ip request!\n");
476 // Initialize networking
477 if (tor_fw_helper_network_init())
480 // Initalize the various fw-helper backend helpers
481 r
= init_backends(&tor_fw_options
, &backend_state
);
482 if (!r
) { // all backends failed:
483 // report our failure
484 report_full_fail(tor_fw_options
.ports_to_forward
, &backend_state
);
485 fprintf(stderr
, "V: tor-fw-helper: All backends failed.\n");
487 } else { // some backends succeeded:
488 fprintf(stderr
, "tor-fw-helper: %i NAT traversal helper(s) loaded\n", r
);
491 // Forward TCP ports.
492 if (tor_fw_options
.ports_to_forward
) {
493 tor_fw_add_ports(&tor_fw_options
, &backend_state
);
496 // Fetch our public IP.
497 if (tor_fw_options
.fetch_public_ip
) {
498 tor_fw_fetch_public_ip(&tor_fw_options
, &backend_state
);
502 if (tor_fw_options
.ports_to_forward
) {
503 SMARTLIST_FOREACH(tor_fw_options
.ports_to_forward
,
504 port_to_forward_t
*, port
,
506 smartlist_free(tor_fw_options
.ports_to_forward
);