Home | History | Annotate | Line # | Download | only in ftp
ssl.c revision 1.5
      1  1.5     joerg /*	$NetBSD: ssl.c,v 1.5 2015/09/16 15:32:53 joerg Exp $	*/
      2  1.1  christos 
      3  1.1  christos /*-
      4  1.1  christos  * Copyright (c) 1998-2004 Dag-Erling Codan Smrgrav
      5  1.1  christos  * Copyright (c) 2008, 2010 Joerg Sonnenberger <joerg (at) NetBSD.org>
      6  1.3       wiz  * Copyright (c) 2015 Thomas Klausner <wiz (at) NetBSD.org>
      7  1.1  christos  * All rights reserved.
      8  1.1  christos  *
      9  1.1  christos  * Redistribution and use in source and binary forms, with or without
     10  1.1  christos  * modification, are permitted provided that the following conditions
     11  1.1  christos  * are met:
     12  1.1  christos  * 1. Redistributions of source code must retain the above copyright
     13  1.1  christos  *    notice, this list of conditions and the following disclaimer
     14  1.1  christos  *    in this position and unchanged.
     15  1.1  christos  * 2. Redistributions in binary form must reproduce the above copyright
     16  1.1  christos  *    notice, this list of conditions and the following disclaimer in the
     17  1.1  christos  *    documentation and/or other materials provided with the distribution.
     18  1.1  christos  * 3. The name of the author may not be used to endorse or promote products
     19  1.1  christos  *    derived from this software without specific prior written permission
     20  1.1  christos  *
     21  1.1  christos  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     22  1.1  christos  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     23  1.1  christos  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     24  1.1  christos  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     25  1.1  christos  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     26  1.1  christos  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     27  1.1  christos  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     28  1.1  christos  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     29  1.1  christos  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     30  1.1  christos  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     31  1.1  christos  *
     32  1.1  christos  * $FreeBSD: common.c,v 1.53 2007/12/19 00:26:36 des Exp $
     33  1.1  christos  */
     34  1.1  christos 
     35  1.1  christos #include <sys/cdefs.h>
     36  1.1  christos #ifndef lint
     37  1.5     joerg __RCSID("$NetBSD: ssl.c,v 1.5 2015/09/16 15:32:53 joerg Exp $");
     38  1.1  christos #endif
     39  1.1  christos 
     40  1.1  christos #include <time.h>
     41  1.1  christos #include <unistd.h>
     42  1.1  christos #include <fcntl.h>
     43  1.1  christos 
     44  1.1  christos #include <sys/param.h>
     45  1.1  christos #include <sys/select.h>
     46  1.1  christos #include <sys/uio.h>
     47  1.1  christos 
     48  1.1  christos #include <netinet/tcp.h>
     49  1.1  christos #include <netinet/in.h>
     50  1.1  christos #include <openssl/crypto.h>
     51  1.1  christos #include <openssl/x509.h>
     52  1.1  christos #include <openssl/pem.h>
     53  1.1  christos #include <openssl/ssl.h>
     54  1.1  christos #include <openssl/err.h>
     55  1.1  christos 
     56  1.1  christos #include "ssl.h"
     57  1.1  christos 
     58  1.1  christos extern int quit_time, verbose, ftp_debug;
     59  1.1  christos extern FILE *ttyout;
     60  1.1  christos 
     61  1.1  christos struct fetch_connect {
     62  1.1  christos 	int			 sd;		/* file/socket descriptor */
     63  1.1  christos 	char			*buf;		/* buffer */
     64  1.1  christos 	size_t			 bufsize;	/* buffer size */
     65  1.1  christos 	size_t			 bufpos;	/* position of buffer */
     66  1.1  christos 	size_t			 buflen;	/* length of buffer contents */
     67  1.1  christos 	struct {				/* data cached after an
     68  1.1  christos 						   interrupted read */
     69  1.1  christos 		char	*buf;
     70  1.1  christos 		size_t	 size;
     71  1.1  christos 		size_t	 pos;
     72  1.1  christos 		size_t	 len;
     73  1.1  christos 	} cache;
     74  1.1  christos 	int 			 issock;
     75  1.1  christos 	int			 iserr;
     76  1.1  christos 	int			 iseof;
     77  1.1  christos 	SSL			*ssl;		/* SSL handle */
     78  1.1  christos };
     79  1.1  christos 
     80  1.1  christos /*
     81  1.1  christos  * Write a vector to a connection w/ timeout
     82  1.1  christos  * Note: can modify the iovec.
     83  1.1  christos  */
     84  1.1  christos static ssize_t
     85  1.1  christos fetch_writev(struct fetch_connect *conn, struct iovec *iov, int iovcnt)
     86  1.1  christos {
     87  1.1  christos 	struct timeval now, timeout, delta;
     88  1.1  christos 	fd_set writefds;
     89  1.1  christos 	ssize_t len, total;
     90  1.1  christos 	int r;
     91  1.1  christos 
     92  1.1  christos 	if (quit_time > 0) {
     93  1.1  christos 		FD_ZERO(&writefds);
     94  1.1  christos 		gettimeofday(&timeout, NULL);
     95  1.1  christos 		timeout.tv_sec += quit_time;
     96  1.1  christos 	}
     97  1.1  christos 
     98  1.1  christos 	total = 0;
     99  1.1  christos 	while (iovcnt > 0) {
    100  1.1  christos 		while (quit_time > 0 && !FD_ISSET(conn->sd, &writefds)) {
    101  1.1  christos 			FD_SET(conn->sd, &writefds);
    102  1.1  christos 			gettimeofday(&now, NULL);
    103  1.1  christos 			delta.tv_sec = timeout.tv_sec - now.tv_sec;
    104  1.1  christos 			delta.tv_usec = timeout.tv_usec - now.tv_usec;
    105  1.1  christos 			if (delta.tv_usec < 0) {
    106  1.1  christos 				delta.tv_usec += 1000000;
    107  1.1  christos 				delta.tv_sec--;
    108  1.1  christos 			}
    109  1.1  christos 			if (delta.tv_sec < 0) {
    110  1.1  christos 				errno = ETIMEDOUT;
    111  1.1  christos 				return -1;
    112  1.1  christos 			}
    113  1.1  christos 			errno = 0;
    114  1.1  christos 			r = select(conn->sd + 1, NULL, &writefds, NULL, &delta);
    115  1.1  christos 			if (r == -1) {
    116  1.1  christos 				if (errno == EINTR)
    117  1.1  christos 					continue;
    118  1.1  christos 				return -1;
    119  1.1  christos 			}
    120  1.1  christos 		}
    121  1.1  christos 		errno = 0;
    122  1.1  christos 		if (conn->ssl != NULL)
    123  1.1  christos 			len = SSL_write(conn->ssl, iov->iov_base, iov->iov_len);
    124  1.1  christos 		else
    125  1.1  christos 			len = writev(conn->sd, iov, iovcnt);
    126  1.1  christos 		if (len == 0) {
    127  1.1  christos 			/* we consider a short write a failure */
    128  1.1  christos 			/* XXX perhaps we shouldn't in the SSL case */
    129  1.1  christos 			errno = EPIPE;
    130  1.1  christos 			return -1;
    131  1.1  christos 		}
    132  1.1  christos 		if (len < 0) {
    133  1.1  christos 			if (errno == EINTR)
    134  1.1  christos 				continue;
    135  1.1  christos 			return -1;
    136  1.1  christos 		}
    137  1.1  christos 		total += len;
    138  1.1  christos 		while (iovcnt > 0 && len >= (ssize_t)iov->iov_len) {
    139  1.1  christos 			len -= iov->iov_len;
    140  1.1  christos 			iov++;
    141  1.1  christos 			iovcnt--;
    142  1.1  christos 		}
    143  1.1  christos 		if (iovcnt > 0) {
    144  1.1  christos 			iov->iov_len -= len;
    145  1.1  christos 			iov->iov_base = (char *)iov->iov_base + len;
    146  1.1  christos 		}
    147  1.1  christos 	}
    148  1.1  christos 	return total;
    149  1.1  christos }
    150  1.1  christos 
    151  1.1  christos /*
    152  1.1  christos  * Write to a connection w/ timeout
    153  1.1  christos  */
    154  1.1  christos static int
    155  1.1  christos fetch_write(struct fetch_connect *conn, const char *str, size_t len)
    156  1.1  christos {
    157  1.1  christos 	struct iovec iov[1];
    158  1.1  christos 
    159  1.1  christos 	iov[0].iov_base = (char *)__UNCONST(str);
    160  1.1  christos 	iov[0].iov_len = len;
    161  1.1  christos 	return fetch_writev(conn, iov, 1);
    162  1.1  christos }
    163  1.1  christos 
    164  1.1  christos /*
    165  1.1  christos  * Send a formatted line; optionally echo to terminal
    166  1.1  christos  */
    167  1.1  christos int
    168  1.1  christos fetch_printf(struct fetch_connect *conn, const char *fmt, ...)
    169  1.1  christos {
    170  1.1  christos 	va_list ap;
    171  1.1  christos 	size_t len;
    172  1.1  christos 	char *msg;
    173  1.1  christos 	int r;
    174  1.1  christos 
    175  1.1  christos 	va_start(ap, fmt);
    176  1.1  christos 	len = vasprintf(&msg, fmt, ap);
    177  1.1  christos 	va_end(ap);
    178  1.1  christos 
    179  1.1  christos 	if (msg == NULL) {
    180  1.1  christos 		errno = ENOMEM;
    181  1.1  christos 		return -1;
    182  1.1  christos 	}
    183  1.1  christos 
    184  1.1  christos 	r = fetch_write(conn, msg, len);
    185  1.1  christos 	free(msg);
    186  1.1  christos 	return r;
    187  1.1  christos }
    188  1.1  christos 
    189  1.1  christos int
    190  1.1  christos fetch_fileno(struct fetch_connect *conn)
    191  1.1  christos {
    192  1.1  christos 
    193  1.1  christos 	return conn->sd;
    194  1.1  christos }
    195  1.1  christos 
    196  1.1  christos int
    197  1.1  christos fetch_error(struct fetch_connect *conn)
    198  1.1  christos {
    199  1.1  christos 
    200  1.1  christos 	return conn->iserr;
    201  1.1  christos }
    202  1.1  christos 
    203  1.1  christos static void
    204  1.1  christos fetch_clearerr(struct fetch_connect *conn)
    205  1.1  christos {
    206  1.1  christos 
    207  1.1  christos 	conn->iserr = 0;
    208  1.1  christos }
    209  1.1  christos 
    210  1.1  christos int
    211  1.1  christos fetch_flush(struct fetch_connect *conn)
    212  1.1  christos {
    213  1.1  christos 	int v;
    214  1.1  christos 
    215  1.1  christos 	if (conn->issock) {
    216  1.1  christos #ifdef TCP_NOPUSH
    217  1.1  christos 		v = 0;
    218  1.1  christos 		setsockopt(conn->sd, IPPROTO_TCP, TCP_NOPUSH, &v, sizeof(v));
    219  1.1  christos #endif
    220  1.1  christos 		v = 1;
    221  1.1  christos 		setsockopt(conn->sd, IPPROTO_TCP, TCP_NODELAY, &v, sizeof(v));
    222  1.1  christos 	}
    223  1.1  christos 	return 0;
    224  1.1  christos }
    225  1.1  christos 
    226  1.1  christos /*ARGSUSED*/
    227  1.1  christos struct fetch_connect *
    228  1.1  christos fetch_open(const char *fname, const char *fmode)
    229  1.1  christos {
    230  1.1  christos 	struct fetch_connect *conn;
    231  1.1  christos 	int fd;
    232  1.1  christos 
    233  1.1  christos 	fd = open(fname, O_RDONLY); /* XXX: fmode */
    234  1.1  christos 	if (fd < 0)
    235  1.1  christos 		return NULL;
    236  1.1  christos 
    237  1.1  christos 	if ((conn = calloc(1, sizeof(*conn))) == NULL) {
    238  1.1  christos 		close(fd);
    239  1.1  christos 		return NULL;
    240  1.1  christos 	}
    241  1.1  christos 
    242  1.1  christos 	conn->sd = fd;
    243  1.1  christos 	conn->issock = 0;
    244  1.1  christos 	return conn;
    245  1.1  christos }
    246  1.1  christos 
    247  1.1  christos /*ARGSUSED*/
    248  1.1  christos struct fetch_connect *
    249  1.1  christos fetch_fdopen(int sd, const char *fmode)
    250  1.1  christos {
    251  1.1  christos 	struct fetch_connect *conn;
    252  1.2  christos #if defined(SO_NOSIGPIPE) || defined(TCP_NOPUSH)
    253  1.1  christos 	int opt = 1;
    254  1.2  christos #endif
    255  1.1  christos 
    256  1.1  christos 	if ((conn = calloc(1, sizeof(*conn))) == NULL)
    257  1.1  christos 		return NULL;
    258  1.1  christos 
    259  1.1  christos 	conn->sd = sd;
    260  1.1  christos 	conn->issock = 1;
    261  1.1  christos 	fcntl(sd, F_SETFD, FD_CLOEXEC);
    262  1.2  christos #ifdef SO_NOSIGPIPE
    263  1.1  christos 	setsockopt(sd, SOL_SOCKET, SO_NOSIGPIPE, &opt, sizeof(opt));
    264  1.2  christos #endif
    265  1.1  christos #ifdef TCP_NOPUSH
    266  1.1  christos 	setsockopt(sd, IPPROTO_TCP, TCP_NOPUSH, &opt, sizeof(opt));
    267  1.1  christos #endif
    268  1.1  christos 	return conn;
    269  1.1  christos }
    270  1.1  christos 
    271  1.1  christos int
    272  1.1  christos fetch_close(struct fetch_connect *conn)
    273  1.1  christos {
    274  1.1  christos 	int rv = 0;
    275  1.1  christos 
    276  1.1  christos 	if (conn != NULL) {
    277  1.1  christos 		fetch_flush(conn);
    278  1.1  christos 		SSL_free(conn->ssl);
    279  1.1  christos 		rv = close(conn->sd);
    280  1.1  christos 		if (rv < 0) {
    281  1.1  christos 			errno = rv;
    282  1.1  christos 			rv = EOF;
    283  1.1  christos 		}
    284  1.1  christos 		free(conn->cache.buf);
    285  1.1  christos 		free(conn->buf);
    286  1.1  christos 		free(conn);
    287  1.1  christos 	}
    288  1.1  christos 	return rv;
    289  1.1  christos }
    290  1.1  christos 
    291  1.1  christos #define FETCH_READ_WAIT		-2
    292  1.1  christos #define FETCH_READ_ERROR	-1
    293  1.1  christos 
    294  1.1  christos static ssize_t
    295  1.1  christos fetch_ssl_read(SSL *ssl, void *buf, size_t len)
    296  1.1  christos {
    297  1.1  christos 	ssize_t rlen;
    298  1.1  christos 	int ssl_err;
    299  1.1  christos 
    300  1.1  christos 	rlen = SSL_read(ssl, buf, len);
    301  1.1  christos 	if (rlen < 0) {
    302  1.1  christos 		ssl_err = SSL_get_error(ssl, rlen);
    303  1.1  christos 		if (ssl_err == SSL_ERROR_WANT_READ ||
    304  1.1  christos 		    ssl_err == SSL_ERROR_WANT_WRITE) {
    305  1.1  christos 			return FETCH_READ_WAIT;
    306  1.1  christos 		}
    307  1.1  christos 		ERR_print_errors_fp(ttyout);
    308  1.1  christos 		return FETCH_READ_ERROR;
    309  1.1  christos 	}
    310  1.1  christos 	return rlen;
    311  1.1  christos }
    312  1.1  christos 
    313  1.1  christos static ssize_t
    314  1.1  christos fetch_nonssl_read(int sd, void *buf, size_t len)
    315  1.1  christos {
    316  1.1  christos 	ssize_t rlen;
    317  1.1  christos 
    318  1.1  christos 	rlen = read(sd, buf, len);
    319  1.1  christos 	if (rlen < 0) {
    320  1.1  christos 		if (errno == EAGAIN || errno == EINTR)
    321  1.1  christos 			return FETCH_READ_WAIT;
    322  1.1  christos 		return FETCH_READ_ERROR;
    323  1.1  christos 	}
    324  1.1  christos 	return rlen;
    325  1.1  christos }
    326  1.1  christos 
    327  1.1  christos /*
    328  1.1  christos  * Cache some data that was read from a socket but cannot be immediately
    329  1.1  christos  * returned because of an interrupted system call.
    330  1.1  christos  */
    331  1.1  christos static int
    332  1.1  christos fetch_cache_data(struct fetch_connect *conn, char *src, size_t nbytes)
    333  1.1  christos {
    334  1.1  christos 
    335  1.1  christos 	if (conn->cache.size < nbytes) {
    336  1.1  christos 		char *tmp = realloc(conn->cache.buf, nbytes);
    337  1.1  christos 		if (tmp == NULL)
    338  1.1  christos 			return -1;
    339  1.1  christos 
    340  1.1  christos 		conn->cache.buf = tmp;
    341  1.1  christos 		conn->cache.size = nbytes;
    342  1.1  christos 	}
    343  1.1  christos 
    344  1.1  christos 	memcpy(conn->cache.buf, src, nbytes);
    345  1.1  christos 	conn->cache.len = nbytes;
    346  1.1  christos 	conn->cache.pos = 0;
    347  1.1  christos 	return 0;
    348  1.1  christos }
    349  1.1  christos 
    350  1.1  christos ssize_t
    351  1.1  christos fetch_read(void *ptr, size_t size, size_t nmemb, struct fetch_connect *conn)
    352  1.1  christos {
    353  1.1  christos 	struct timeval now, timeout, delta;
    354  1.1  christos 	fd_set readfds;
    355  1.1  christos 	ssize_t rlen, total;
    356  1.1  christos 	size_t len;
    357  1.1  christos 	char *start, *buf;
    358  1.1  christos 
    359  1.1  christos 	if (quit_time > 0) {
    360  1.1  christos 		gettimeofday(&timeout, NULL);
    361  1.1  christos 		timeout.tv_sec += quit_time;
    362  1.1  christos 	}
    363  1.1  christos 
    364  1.1  christos 	total = 0;
    365  1.1  christos 	start = buf = ptr;
    366  1.1  christos 	len = size * nmemb;
    367  1.1  christos 
    368  1.1  christos 	if (conn->cache.len > 0) {
    369  1.1  christos 		/*
    370  1.1  christos 		 * The last invocation of fetch_read was interrupted by a
    371  1.1  christos 		 * signal after some data had been read from the socket. Copy
    372  1.1  christos 		 * the cached data into the supplied buffer before trying to
    373  1.1  christos 		 * read from the socket again.
    374  1.1  christos 		 */
    375  1.1  christos 		total = (conn->cache.len < len) ? conn->cache.len : len;
    376  1.1  christos 		memcpy(buf, conn->cache.buf, total);
    377  1.1  christos 
    378  1.1  christos 		conn->cache.len -= total;
    379  1.1  christos 		conn->cache.pos += total;
    380  1.1  christos 		len -= total;
    381  1.1  christos 		buf += total;
    382  1.1  christos 	}
    383  1.1  christos 
    384  1.1  christos 	while (len > 0) {
    385  1.1  christos 		/*
    386  1.1  christos 		 * The socket is non-blocking.  Instead of the canonical
    387  1.1  christos 		 * select() -> read(), we do the following:
    388  1.1  christos 		 *
    389  1.1  christos 		 * 1) call read() or SSL_read().
    390  1.1  christos 		 * 2) if an error occurred, return -1.
    391  1.1  christos 		 * 3) if we received data but we still expect more,
    392  1.1  christos 		 *    update our counters and loop.
    393  1.1  christos 		 * 4) if read() or SSL_read() signaled EOF, return.
    394  1.1  christos 		 * 5) if we did not receive any data but we're not at EOF,
    395  1.1  christos 		 *    call select().
    396  1.1  christos 		 *
    397  1.1  christos 		 * In the SSL case, this is necessary because if we
    398  1.1  christos 		 * receive a close notification, we have to call
    399  1.1  christos 		 * SSL_read() one additional time after we've read
    400  1.1  christos 		 * everything we received.
    401  1.1  christos 		 *
    402  1.1  christos 		 * In the non-SSL case, it may improve performance (very
    403  1.1  christos 		 * slightly) when reading small amounts of data.
    404  1.1  christos 		 */
    405  1.1  christos 		if (conn->ssl != NULL)
    406  1.1  christos 			rlen = fetch_ssl_read(conn->ssl, buf, len);
    407  1.1  christos 		else
    408  1.1  christos 			rlen = fetch_nonssl_read(conn->sd, buf, len);
    409  1.1  christos 		if (rlen == 0) {
    410  1.1  christos 			break;
    411  1.1  christos 		} else if (rlen > 0) {
    412  1.1  christos 			len -= rlen;
    413  1.1  christos 			buf += rlen;
    414  1.1  christos 			total += rlen;
    415  1.1  christos 			continue;
    416  1.1  christos 		} else if (rlen == FETCH_READ_ERROR) {
    417  1.1  christos 			if (errno == EINTR)
    418  1.1  christos 				fetch_cache_data(conn, start, total);
    419  1.1  christos 			return -1;
    420  1.1  christos 		}
    421  1.1  christos 		FD_ZERO(&readfds);
    422  1.1  christos 		while (!FD_ISSET(conn->sd, &readfds)) {
    423  1.1  christos 			FD_SET(conn->sd, &readfds);
    424  1.1  christos 			if (quit_time > 0) {
    425  1.1  christos 				gettimeofday(&now, NULL);
    426  1.1  christos 				if (!timercmp(&timeout, &now, >)) {
    427  1.1  christos 					errno = ETIMEDOUT;
    428  1.1  christos 					return -1;
    429  1.1  christos 				}
    430  1.1  christos 				timersub(&timeout, &now, &delta);
    431  1.1  christos 			}
    432  1.1  christos 			errno = 0;
    433  1.1  christos 			if (select(conn->sd + 1, &readfds, NULL, NULL,
    434  1.1  christos 				quit_time > 0 ? &delta : NULL) < 0) {
    435  1.1  christos 				if (errno == EINTR)
    436  1.1  christos 					continue;
    437  1.1  christos 				return -1;
    438  1.1  christos 			}
    439  1.1  christos 		}
    440  1.1  christos 	}
    441  1.1  christos 	return total;
    442  1.1  christos }
    443  1.1  christos 
    444  1.1  christos #define MIN_BUF_SIZE 1024
    445  1.1  christos 
    446  1.1  christos /*
    447  1.1  christos  * Read a line of text from a connection w/ timeout
    448  1.1  christos  */
    449  1.1  christos char *
    450  1.1  christos fetch_getln(char *str, int size, struct fetch_connect *conn)
    451  1.1  christos {
    452  1.1  christos 	size_t tmpsize;
    453  1.1  christos 	ssize_t len;
    454  1.1  christos 	char c;
    455  1.1  christos 
    456  1.1  christos 	if (conn->buf == NULL) {
    457  1.1  christos 		if ((conn->buf = malloc(MIN_BUF_SIZE)) == NULL) {
    458  1.1  christos 			errno = ENOMEM;
    459  1.1  christos 			conn->iserr = 1;
    460  1.1  christos 			return NULL;
    461  1.1  christos 		}
    462  1.1  christos 		conn->bufsize = MIN_BUF_SIZE;
    463  1.1  christos 	}
    464  1.1  christos 
    465  1.1  christos 	if (conn->iserr || conn->iseof)
    466  1.1  christos 		return NULL;
    467  1.1  christos 
    468  1.1  christos 	if (conn->buflen - conn->bufpos > 0)
    469  1.1  christos 		goto done;
    470  1.1  christos 
    471  1.1  christos 	conn->buf[0] = '\0';
    472  1.1  christos 	conn->bufpos = 0;
    473  1.1  christos 	conn->buflen = 0;
    474  1.1  christos 	do {
    475  1.1  christos 		len = fetch_read(&c, sizeof(c), 1, conn);
    476  1.1  christos 		if (len == -1) {
    477  1.1  christos 			conn->iserr = 1;
    478  1.1  christos 			return NULL;
    479  1.1  christos 		}
    480  1.1  christos 		if (len == 0) {
    481  1.1  christos 			conn->iseof = 1;
    482  1.1  christos 			break;
    483  1.1  christos 		}
    484  1.1  christos 		conn->buf[conn->buflen++] = c;
    485  1.1  christos 		if (conn->buflen == conn->bufsize) {
    486  1.1  christos 			char *tmp = conn->buf;
    487  1.1  christos 			tmpsize = conn->bufsize * 2 + 1;
    488  1.1  christos 			if ((tmp = realloc(tmp, tmpsize)) == NULL) {
    489  1.1  christos 				errno = ENOMEM;
    490  1.1  christos 				conn->iserr = 1;
    491  1.1  christos 				return NULL;
    492  1.1  christos 			}
    493  1.1  christos 			conn->buf = tmp;
    494  1.1  christos 			conn->bufsize = tmpsize;
    495  1.1  christos 		}
    496  1.1  christos 	} while (c != '\n');
    497  1.1  christos 
    498  1.1  christos 	if (conn->buflen == 0)
    499  1.1  christos 		return NULL;
    500  1.1  christos  done:
    501  1.1  christos 	tmpsize = MIN(size - 1, (int)(conn->buflen - conn->bufpos));
    502  1.1  christos 	memcpy(str, conn->buf + conn->bufpos, tmpsize);
    503  1.1  christos 	str[tmpsize] = '\0';
    504  1.1  christos 	conn->bufpos += tmpsize;
    505  1.1  christos 	return str;
    506  1.1  christos }
    507  1.1  christos 
    508  1.1  christos int
    509  1.1  christos fetch_getline(struct fetch_connect *conn, char *buf, size_t buflen,
    510  1.1  christos     const char **errormsg)
    511  1.1  christos {
    512  1.1  christos 	size_t len;
    513  1.1  christos 	int rv;
    514  1.1  christos 
    515  1.1  christos 	if (fetch_getln(buf, buflen, conn) == NULL) {
    516  1.1  christos 		if (conn->iseof) {	/* EOF */
    517  1.1  christos 			rv = -2;
    518  1.1  christos 			if (errormsg)
    519  1.1  christos 				*errormsg = "\nEOF received";
    520  1.1  christos 		} else {		/* error */
    521  1.1  christos 			rv = -1;
    522  1.1  christos 			if (errormsg)
    523  1.1  christos 				*errormsg = "Error encountered";
    524  1.1  christos 		}
    525  1.1  christos 		fetch_clearerr(conn);
    526  1.1  christos 		return rv;
    527  1.1  christos 	}
    528  1.1  christos 	len = strlen(buf);
    529  1.1  christos 	if (buf[len - 1] == '\n') {	/* clear any trailing newline */
    530  1.1  christos 		buf[--len] = '\0';
    531  1.1  christos 	} else if (len == buflen - 1) {	/* line too long */
    532  1.1  christos 		while (1) {
    533  1.1  christos 			char c;
    534  1.1  christos 			ssize_t rlen = fetch_read(&c, sizeof(c), 1, conn);
    535  1.1  christos 			if (rlen <= 0 || c == '\n')
    536  1.1  christos 				break;
    537  1.1  christos 		}
    538  1.1  christos 		if (errormsg)
    539  1.1  christos 			*errormsg = "Input line is too long";
    540  1.1  christos 		fetch_clearerr(conn);
    541  1.1  christos 		return -3;
    542  1.1  christos 	}
    543  1.1  christos 	if (errormsg)
    544  1.1  christos 		*errormsg = NULL;
    545  1.1  christos 	return len;
    546  1.1  christos }
    547  1.1  christos 
    548  1.1  christos void *
    549  1.3       wiz fetch_start_ssl(int sock, const char *servername)
    550  1.1  christos {
    551  1.1  christos 	SSL *ssl;
    552  1.1  christos 	SSL_CTX *ctx;
    553  1.1  christos 	int ret, ssl_err;
    554  1.1  christos 
    555  1.1  christos 	/* Init the SSL library and context */
    556  1.1  christos 	if (!SSL_library_init()){
    557  1.1  christos 		fprintf(ttyout, "SSL library init failed\n");
    558  1.1  christos 		return NULL;
    559  1.1  christos 	}
    560  1.1  christos 
    561  1.1  christos 	SSL_load_error_strings();
    562  1.1  christos 
    563  1.1  christos 	ctx = SSL_CTX_new(SSLv23_client_method());
    564  1.1  christos 	SSL_CTX_set_mode(ctx, SSL_MODE_AUTO_RETRY);
    565  1.1  christos 
    566  1.1  christos 	ssl = SSL_new(ctx);
    567  1.1  christos 	if (ssl == NULL){
    568  1.1  christos 		fprintf(ttyout, "SSL context creation failed\n");
    569  1.1  christos 		SSL_CTX_free(ctx);
    570  1.1  christos 		return NULL;
    571  1.1  christos 	}
    572  1.1  christos 	SSL_set_fd(ssl, sock);
    573  1.5     joerg 	if (!SSL_set_tlsext_host_name(ssl, __UNCONST(servername))) {
    574  1.4       wiz 		fprintf(ttyout, "SSL hostname setting failed\n");
    575  1.4       wiz 		SSL_CTX_free(ctx);
    576  1.4       wiz 		return NULL;
    577  1.3       wiz 	}
    578  1.1  christos 	while ((ret = SSL_connect(ssl)) == -1) {
    579  1.1  christos 		ssl_err = SSL_get_error(ssl, ret);
    580  1.1  christos 		if (ssl_err != SSL_ERROR_WANT_READ &&
    581  1.1  christos 		    ssl_err != SSL_ERROR_WANT_WRITE) {
    582  1.1  christos 			ERR_print_errors_fp(ttyout);
    583  1.1  christos 			SSL_free(ssl);
    584  1.1  christos 			return NULL;
    585  1.1  christos 		}
    586  1.1  christos 	}
    587  1.1  christos 
    588  1.1  christos 	if (ftp_debug && verbose) {
    589  1.1  christos 		X509 *cert;
    590  1.1  christos 		X509_NAME *name;
    591  1.1  christos 		char *str;
    592  1.1  christos 
    593  1.1  christos 		fprintf(ttyout, "SSL connection established using %s\n",
    594  1.1  christos 		    SSL_get_cipher(ssl));
    595  1.1  christos 		cert = SSL_get_peer_certificate(ssl);
    596  1.1  christos 		name = X509_get_subject_name(cert);
    597  1.1  christos 		str = X509_NAME_oneline(name, 0, 0);
    598  1.1  christos 		fprintf(ttyout, "Certificate subject: %s\n", str);
    599  1.1  christos 		free(str);
    600  1.1  christos 		name = X509_get_issuer_name(cert);
    601  1.1  christos 		str = X509_NAME_oneline(name, 0, 0);
    602  1.1  christos 		fprintf(ttyout, "Certificate issuer: %s\n", str);
    603  1.1  christos 		free(str);
    604  1.1  christos 	}
    605  1.1  christos 
    606  1.1  christos 	return ssl;
    607  1.1  christos }
    608  1.1  christos 
    609  1.1  christos 
    610  1.1  christos void
    611  1.1  christos fetch_set_ssl(struct fetch_connect *conn, void *ssl)
    612  1.1  christos {
    613  1.1  christos 	conn->ssl = ssl;
    614  1.1  christos }
    615