2002-04-18 17:59:21 +00:00
|
|
|
/* $Id: acl.c,v 1.14 2002-04-18 17:59:21 rjkaes Exp $
|
2000-09-12 00:08:48 +00:00
|
|
|
*
|
|
|
|
* This system handles Access Control for use of this daemon. A list of
|
|
|
|
* domains, or IP addresses (including IP blocks) are stored in a list
|
|
|
|
* which is then used to compare incoming connections.
|
|
|
|
*
|
|
|
|
* Copyright (C) 2000 Robert James Kaes (rjkaes@flarenet.com)
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License as published by the
|
|
|
|
* Free Software Foundation; either version 2, or (at your option) any
|
|
|
|
* later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
* General Public License for more details.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "tinyproxy.h"
|
|
|
|
|
|
|
|
#include "acl.h"
|
|
|
|
#include "log.h"
|
|
|
|
#include "sock.h"
|
2001-09-08 18:58:37 +00:00
|
|
|
#include "utils.h"
|
2000-09-12 00:08:48 +00:00
|
|
|
|
|
|
|
struct acl_s {
|
2001-05-27 02:20:54 +00:00
|
|
|
acl_access_t acl_access;
|
2000-09-12 00:08:48 +00:00
|
|
|
enum { ACL_STRING, ACL_NUMERIC } type;
|
|
|
|
char *location;
|
|
|
|
int netmask;
|
|
|
|
struct acl_s *next;
|
|
|
|
};
|
|
|
|
|
|
|
|
static struct acl_s *access_list = NULL;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Take a netmask number (between 0 and 32) and returns a network ordered
|
2002-04-09 19:11:09 +00:00
|
|
|
* value for comparison.
|
2000-09-12 00:08:48 +00:00
|
|
|
*/
|
2001-11-22 00:31:10 +00:00
|
|
|
static in_addr_t
|
|
|
|
make_netmask(int netmask_num)
|
2000-09-12 00:08:48 +00:00
|
|
|
{
|
2001-05-23 17:57:22 +00:00
|
|
|
assert(netmask_num >= 0 && netmask_num <= 32);
|
|
|
|
|
2002-04-09 19:11:09 +00:00
|
|
|
return htonl(~((1 << (32 - netmask_num)) - 1));
|
2000-09-12 00:08:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Inserts a new access control into the list. The function will figure out
|
|
|
|
* whether the location is an IP address (with optional netmask) or a
|
|
|
|
* domain name.
|
|
|
|
*
|
|
|
|
* Returns:
|
|
|
|
* -1 on failure
|
|
|
|
* 0 otherwise.
|
|
|
|
*/
|
2001-11-22 00:31:10 +00:00
|
|
|
int
|
|
|
|
insert_acl(char *location, acl_access_t access_type)
|
2000-09-12 00:08:48 +00:00
|
|
|
{
|
2001-05-27 02:20:54 +00:00
|
|
|
size_t i;
|
2000-09-12 00:08:48 +00:00
|
|
|
struct acl_s **rev_acl_ptr, *acl_ptr, *new_acl_ptr;
|
|
|
|
char *nptr;
|
|
|
|
|
2001-05-23 17:57:22 +00:00
|
|
|
assert(location != NULL);
|
|
|
|
|
2000-09-12 00:08:48 +00:00
|
|
|
/*
|
|
|
|
* First check to see if the location is a string or numeric.
|
|
|
|
*/
|
2001-11-03 06:08:37 +00:00
|
|
|
for (i = 0; location[i] != '\0'; i++) {
|
|
|
|
/*
|
|
|
|
* Numeric strings can not contain letters, so test on it.
|
|
|
|
*/
|
2001-11-22 00:31:10 +00:00
|
|
|
if (isalpha((unsigned char) location[i])) {
|
2000-09-12 00:08:48 +00:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Add a new ACL to the list.
|
|
|
|
*/
|
|
|
|
rev_acl_ptr = &access_list;
|
|
|
|
acl_ptr = access_list;
|
|
|
|
while (acl_ptr) {
|
|
|
|
rev_acl_ptr = &acl_ptr->next;
|
|
|
|
acl_ptr = acl_ptr->next;
|
|
|
|
}
|
2001-09-08 18:58:37 +00:00
|
|
|
new_acl_ptr = safemalloc(sizeof(struct acl_s));
|
2000-09-12 00:08:48 +00:00
|
|
|
if (!new_acl_ptr) {
|
|
|
|
return -1;
|
|
|
|
}
|
2001-11-22 00:31:10 +00:00
|
|
|
|
2001-05-27 02:20:54 +00:00
|
|
|
new_acl_ptr->acl_access = access_type;
|
2001-11-22 00:31:10 +00:00
|
|
|
|
2001-11-03 06:08:37 +00:00
|
|
|
if (location[i] == '\0') {
|
|
|
|
DEBUG2("ACL \"%s\" is a number.", location);
|
|
|
|
|
2001-09-11 04:12:47 +00:00
|
|
|
/*
|
2001-11-03 06:08:37 +00:00
|
|
|
* We did not break early, so this a numeric location.
|
2000-09-12 00:08:48 +00:00
|
|
|
* Check for a netmask.
|
|
|
|
*/
|
|
|
|
new_acl_ptr->type = ACL_NUMERIC;
|
|
|
|
nptr = strchr(location, '/');
|
|
|
|
if (nptr) {
|
|
|
|
*nptr++ = '\0';
|
|
|
|
|
2001-11-03 06:08:37 +00:00
|
|
|
new_acl_ptr->netmask = strtol(nptr, NULL, 10);
|
2001-11-22 00:31:10 +00:00
|
|
|
if (new_acl_ptr->netmask < 0
|
|
|
|
|| new_acl_ptr->netmask > 32) {
|
2000-09-26 04:57:46 +00:00
|
|
|
safefree(new_acl_ptr);
|
2000-09-12 00:08:48 +00:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
new_acl_ptr->netmask = 32;
|
|
|
|
}
|
|
|
|
} else {
|
2001-11-03 06:08:37 +00:00
|
|
|
DEBUG2("ACL \"%s\" is a string.", location);
|
|
|
|
|
2000-09-12 00:08:48 +00:00
|
|
|
new_acl_ptr->type = ACL_STRING;
|
|
|
|
new_acl_ptr->netmask = 32;
|
|
|
|
}
|
|
|
|
|
2002-04-18 17:59:21 +00:00
|
|
|
new_acl_ptr->location = safestrdup(location);
|
2000-09-12 00:08:48 +00:00
|
|
|
if (!new_acl_ptr->location) {
|
2000-09-26 04:57:46 +00:00
|
|
|
safefree(new_acl_ptr);
|
2000-09-12 00:08:48 +00:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
*rev_acl_ptr = new_acl_ptr;
|
|
|
|
new_acl_ptr->next = acl_ptr;
|
2001-11-22 00:31:10 +00:00
|
|
|
|
2000-09-12 00:08:48 +00:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2002-04-17 20:52:45 +00:00
|
|
|
* Checks whether file descriptor is allowed.
|
2000-09-12 00:08:48 +00:00
|
|
|
*
|
|
|
|
* Returns:
|
|
|
|
* 1 if allowed
|
|
|
|
* 0 if denied
|
|
|
|
* -1 if error
|
|
|
|
*/
|
2001-11-22 00:31:10 +00:00
|
|
|
int
|
2002-04-17 20:52:45 +00:00
|
|
|
check_acl(int fd, const char* ip_address, const char* string_address)
|
2000-09-12 00:08:48 +00:00
|
|
|
{
|
|
|
|
struct acl_s *aclptr;
|
|
|
|
|
2001-05-23 17:57:22 +00:00
|
|
|
assert(fd >= 0);
|
2002-04-17 20:52:45 +00:00
|
|
|
assert(ip_address != NULL);
|
|
|
|
assert(string_address != NULL);
|
2001-05-23 17:57:22 +00:00
|
|
|
|
2000-09-12 00:08:48 +00:00
|
|
|
/*
|
|
|
|
* If there is no access list allow everything.
|
|
|
|
*/
|
|
|
|
aclptr = access_list;
|
|
|
|
if (!aclptr)
|
|
|
|
return 1;
|
|
|
|
|
|
|
|
while (aclptr) {
|
|
|
|
if (aclptr->type == ACL_STRING) {
|
2001-05-27 02:20:54 +00:00
|
|
|
size_t test_length = strlen(string_address);
|
|
|
|
size_t match_length = strlen(aclptr->location);
|
2000-09-12 00:08:48 +00:00
|
|
|
|
|
|
|
if (test_length < match_length) {
|
|
|
|
aclptr = aclptr->next;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
2001-11-22 00:31:10 +00:00
|
|
|
if (strcasecmp
|
|
|
|
(string_address + (test_length - match_length),
|
|
|
|
aclptr->location) == 0) {
|
2001-05-27 02:20:54 +00:00
|
|
|
if (aclptr->acl_access == ACL_DENY) {
|
2001-11-22 00:31:10 +00:00
|
|
|
log_message(LOG_NOTICE,
|
|
|
|
"Unauthorized access from \"%s\"",
|
|
|
|
string_address);
|
2000-09-12 00:08:48 +00:00
|
|
|
return 0;
|
|
|
|
} else {
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
struct in_addr test_addr, match_addr;
|
|
|
|
in_addr_t netmask_addr;
|
|
|
|
|
|
|
|
if (ip_address[0] == 0) {
|
|
|
|
aclptr = aclptr->next;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
inet_aton(ip_address, &test_addr);
|
|
|
|
inet_aton(aclptr->location, &match_addr);
|
|
|
|
|
|
|
|
netmask_addr = make_netmask(aclptr->netmask);
|
|
|
|
|
2001-11-22 00:31:10 +00:00
|
|
|
if ((test_addr.s_addr & netmask_addr) ==
|
|
|
|
(match_addr.s_addr & netmask_addr)) {
|
2001-05-27 02:20:54 +00:00
|
|
|
if (aclptr->acl_access == ACL_DENY) {
|
2001-11-22 00:31:10 +00:00
|
|
|
log_message(LOG_NOTICE,
|
|
|
|
"Unauthorized access from [%s].",
|
|
|
|
ip_address);
|
2000-09-12 00:08:48 +00:00
|
|
|
return 0;
|
|
|
|
} else {
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Dropped through... go on to the next one.
|
|
|
|
*/
|
|
|
|
aclptr = aclptr->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Deny all connections by default.
|
|
|
|
*/
|
2001-11-22 00:31:10 +00:00
|
|
|
log_message(LOG_NOTICE, "Unauthorized connection from \"%s\" [%s].",
|
|
|
|
string_address, ip_address);
|
2000-09-12 00:08:48 +00:00
|
|
|
return 0;
|
|
|
|
}
|