ipc_listener.cpp 8.15 KB
Newer Older
1
/*
2
    Copyright (c) 2007-2015 Contributors as noted in the AUTHORS file
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19

    This file is part of 0MQ.

    0MQ is free software; you can redistribute it and/or modify it under
    the terms of the GNU Lesser General Public License as published by
    the Free Software Foundation; either version 3 of the License, or
    (at your option) any later version.

    0MQ is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU Lesser General Public License for more details.

    You should have received a copy of the GNU Lesser General Public License
    along with this program.  If not, see <http://www.gnu.org/licenses/>.
*/

20 21 22 23
#include "ipc_listener.hpp"

#if !defined ZMQ_HAVE_WINDOWS && !defined ZMQ_HAVE_OPENVMS

24 25 26 27
#include <new>

#include <string.h>

28
#include "stream_engine.hpp"
29
#include "ipc_address.hpp"
30
#include "io_thread.hpp"
31
#include "session_base.hpp"
32 33
#include "config.hpp"
#include "err.hpp"
34
#include "ip.hpp"
35
#include "socket_base.hpp"
36 37 38 39 40 41

#include <unistd.h>
#include <sys/socket.h>
#include <fcntl.h>
#include <sys/un.h>

42 43 44 45 46 47
#if defined ZMQ_HAVE_SO_PEERCRED || defined ZMQ_HAVE_LOCAL_PEERCRED
#   include <sys/types.h>
#endif
#ifdef ZMQ_HAVE_SO_PEERCRED
#   include <pwd.h>
#   include <grp.h>
48 49 50
#   if defined ZMQ_HAVE_OPENBSD
#       define ucred sockpeercred
#   endif
51 52
#endif

53 54 55 56 57 58 59 60 61 62 63 64
zmq::ipc_listener_t::ipc_listener_t (io_thread_t *io_thread_,
      socket_base_t *socket_, const options_t &options_) :
    own_t (io_thread_, options_),
    io_object_t (io_thread_),
    has_file (false),
    s (retired_fd),
    socket (socket_)
{
}

zmq::ipc_listener_t::~ipc_listener_t ()
{
65
    zmq_assert (s == retired_fd);
66 67 68 69 70 71 72 73 74 75 76 77
}

void zmq::ipc_listener_t::process_plug ()
{
    //  Start polling for incoming connections.
    handle = add_fd (s);
    set_pollin (handle);
}

void zmq::ipc_listener_t::process_term (int linger_)
{
    rm_fd (handle);
78
    close ();
79 80 81 82 83 84 85 86 87
    own_t::process_term (linger_);
}

void zmq::ipc_listener_t::in_event ()
{
    fd_t fd = accept ();

    //  If connection was reset by the peer in the meantime, just ignore it.
    //  TODO: Handle specific errors like ENFILE/EMFILE etc.
88
    if (fd == retired_fd) {
89
        socket->event_accept_failed (endpoint, zmq_errno());
90
        return;
91
    }
92 93

    //  Create the engine object for this connection.
94
    stream_engine_t *engine = new (std::nothrow)
95
        stream_engine_t (fd, options, endpoint);
96 97 98 99 100 101 102 103
    alloc_assert (engine);

    //  Choose I/O thread to run connecter in. Given that we are already
    //  running in an I/O thread, there must be at least one available.
    io_thread_t *io_thread = choose_io_thread (options.affinity);
    zmq_assert (io_thread);

    //  Create and launch a session object. 
104
    session_base_t *session = session_base_t::create (io_thread, false, socket,
105
        options, NULL);
106
    errno_assert (session);
107 108 109
    session->inc_seqnum ();
    launch_child (session);
    send_attach (session, engine, false);
110
    socket->event_accepted (endpoint, fd);
111 112
}

113
int zmq::ipc_listener_t::get_address (std::string &addr_)
114
{
115
    struct sockaddr_storage ss;
AJ Lewis's avatar
AJ Lewis committed
116 117 118
#ifdef ZMQ_HAVE_HPUX
    int sl = sizeof (ss);
#else
119
    socklen_t sl = sizeof (ss);
AJ Lewis's avatar
AJ Lewis committed
120
#endif
121
    int rc = getsockname (s, (sockaddr *) &ss, &sl);
122
    if (rc != 0) {
123
        addr_.clear ();
124
        return rc;
125
    }
Mikko Koppanen's avatar
Mikko Koppanen committed
126

127 128
    ipc_address_t addr ((struct sockaddr *) &ss, sl);
    return addr.to_string (addr_);
129 130
}

131
int zmq::ipc_listener_t::set_address (const char *addr_)
132
{
133 134 135 136
    //  Create addr on stack for auto-cleanup
    std::string addr (addr_);

    //  Allow wildcard file
137 138
    if (addr [0] == '*') {
        char buffer [12] = "2134XXXXXX";
139 140
        int fd = mkstemp (buffer);
        if (fd == -1)
141 142
            return -1;
        addr.assign (buffer);
143
        ::close (fd);
144
    }
145

146 147
    //  Get rid of the file associated with the UNIX domain socket that
    //  may have been left behind by the previous run of the application.
148
    ::unlink (addr.c_str());
149
    filename.clear ();
150

151 152
    //  Initialise the address structure.
    ipc_address_t address;
153
    int rc = address.resolve (addr.c_str());
154
    if (rc != 0)
155
        return -1;
156 157

    //  Create a listening socket.
158
    s = open_socket (AF_UNIX, SOCK_STREAM, 0);
159
    if (s == -1)
160 161
        return -1;

162 163
    address.to_string (endpoint);

164
    //  Bind the socket to the file path.
165
    rc = bind (s, address.addr (), address.addrlen ());
166
    if (rc != 0)
167
        goto error;
168

169
    filename.assign (addr.c_str());
170
    has_file = true;
171

172
    //  Listen for incoming connections.
173
    rc = listen (s, options.backlog);
174
    if (rc != 0)
175
        goto error;
176

177
    socket->event_listening (endpoint, s);
178
    return 0;
179 180 181 182 183 184

error:
    int err = errno;
    close ();
    errno = err;
    return -1;
185 186 187 188 189 190
}

int zmq::ipc_listener_t::close ()
{
    zmq_assert (s != retired_fd);
    int rc = ::close (s);
191
    errno_assert (rc == 0);
192

193 194
    s = retired_fd;

195 196
    //  If there's an underlying UNIX domain socket, get rid of the file it
    //  is associated with.
197 198
    if (has_file && !filename.empty ()) {
        rc = ::unlink(filename.c_str ());
199
        if (rc != 0) {
200
            socket->event_close_failed (endpoint, zmq_errno());
201
            return -1;
202
        }
203 204
    }

205
    socket->event_closed (endpoint, s);
206 207 208
    return 0;
}

209 210 211 212 213 214 215 216 217 218 219 220 221 222 223
#if defined ZMQ_HAVE_SO_PEERCRED

bool zmq::ipc_listener_t::filter (fd_t sock)
{
    if (options.ipc_uid_accept_filters.empty () &&
        options.ipc_pid_accept_filters.empty () &&
        options.ipc_gid_accept_filters.empty ())
        return true;

    struct ucred cred;
    socklen_t size = sizeof (cred);

    if (getsockopt (sock, SOL_SOCKET, SO_PEERCRED, &cred, &size))
        return false;
    if (options.ipc_uid_accept_filters.find (cred.uid) != options.ipc_uid_accept_filters.end () ||
224
            options.ipc_gid_accept_filters.find (cred.gid) != options.ipc_gid_accept_filters.end () ||
225 226 227 228 229 230 231 232 233 234 235 236
            options.ipc_pid_accept_filters.find (cred.pid) != options.ipc_pid_accept_filters.end ())
        return true;

    struct passwd *pw;
    struct group *gr;

    if (!(pw = getpwuid (cred.uid)))
        return false;
    for (options_t::ipc_gid_accept_filters_t::const_iterator it = options.ipc_gid_accept_filters.begin ();
            it != options.ipc_gid_accept_filters.end (); it++) {
        if (!(gr = getgrgid (*it)))
            continue;
237
        for (char **mem = gr->gr_mem; *mem; mem++) {
238 239
            if (!strcmp (*mem, pw->pw_name))
                return true;
240
        }
241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271
    }
    return false;
}

#elif defined ZMQ_HAVE_LOCAL_PEERCRED

bool zmq::ipc_listener_t::filter (fd_t sock)
{
    if (options.ipc_uid_accept_filters.empty () &&
        options.ipc_gid_accept_filters.empty ())
        return true;

    struct xucred cred;
    socklen_t size = sizeof (cred);

    if (getsockopt (sock, 0, LOCAL_PEERCRED, &cred, &size))
        return false;
    if (cred.cr_version != XUCRED_VERSION)
        return false;
    if (options.ipc_uid_accept_filters.find (cred.cr_uid) != options.ipc_uid_accept_filters.end ())
        return true;
    for (int i = 0; i < cred.cr_ngroups; i++) {
        if (options.ipc_gid_accept_filters.find (cred.cr_groups[i]) != options.ipc_gid_accept_filters.end ())
            return true;
    }

    return false;
}

#endif

272 273
zmq::fd_t zmq::ipc_listener_t::accept ()
{
274
    //  Accept one connection and deal with different failure modes.
275 276
    //  The situation where connection cannot be accepted due to insufficient
    //  resources is considered valid and treated by ignoring the connection.
277 278
    zmq_assert (s != retired_fd);
    fd_t sock = ::accept (s, NULL, NULL);
279 280
    if (sock == -1) {
        errno_assert (errno == EAGAIN || errno == EWOULDBLOCK ||
281
            errno == EINTR || errno == ECONNABORTED || errno == EPROTO ||
282
            errno == ENFILE);
283
        return retired_fd;
284
    }
285

286 287 288 289 290 291 292
    //  Race condition can cause socket not to be closed (if fork happens
    //  between accept and this point).
#ifdef FD_CLOEXEC
    int rc = fcntl (sock, F_SETFD, FD_CLOEXEC);
    errno_assert (rc != -1);
#endif

293 294 295 296 297 298 299 300 301
    // IPC accept() filters
#if defined ZMQ_HAVE_SO_PEERCRED || defined ZMQ_HAVE_LOCAL_PEERCRED
    if (!filter (sock)) {
        int rc = ::close (sock);
        errno_assert (rc == 0);
        return retired_fd;
    }
#endif

302 303 304 305
    return sock;
}

#endif