Home | History | Annotate | Line # | Download | only in ftp
ssl.c revision 1.7
      1  1.7  christos /*	$NetBSD: ssl.c,v 1.7 2019/04/04 00:36:09 christos Exp $	*/
      2  1.1  christos 
      3  1.1  christos /*-
      4  1.1  christos  * Copyright (c) 1998-2004 Dag-Erling Codan Smrgrav
      5  1.1  christos  * Copyright (c) 2008, 2010 Joerg Sonnenberger <joerg (at) NetBSD.org>
      6  1.3       wiz  * Copyright (c) 2015 Thomas Klausner <wiz (at) NetBSD.org>
      7  1.1  christos  * All rights reserved.
      8  1.1  christos  *
      9  1.1  christos  * Redistribution and use in source and binary forms, with or without
     10  1.1  christos  * modification, are permitted provided that the following conditions
     11  1.1  christos  * are met:
     12  1.1  christos  * 1. Redistributions of source code must retain the above copyright
     13  1.1  christos  *    notice, this list of conditions and the following disclaimer
     14  1.1  christos  *    in this position and unchanged.
     15  1.1  christos  * 2. Redistributions in binary form must reproduce the above copyright
     16  1.1  christos  *    notice, this list of conditions and the following disclaimer in the
     17  1.1  christos  *    documentation and/or other materials provided with the distribution.
     18  1.1  christos  * 3. The name of the author may not be used to endorse or promote products
     19  1.1  christos  *    derived from this software without specific prior written permission
     20  1.1  christos  *
     21  1.1  christos  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     22  1.1  christos  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     23  1.1  christos  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     24  1.1  christos  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     25  1.1  christos  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     26  1.1  christos  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     27  1.1  christos  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     28  1.1  christos  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     29  1.1  christos  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     30  1.1  christos  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     31  1.1  christos  *
     32  1.1  christos  * $FreeBSD: common.c,v 1.53 2007/12/19 00:26:36 des Exp $
     33  1.1  christos  */
     34  1.1  christos 
     35  1.1  christos #include <sys/cdefs.h>
     36  1.1  christos #ifndef lint
     37  1.7  christos __RCSID("$NetBSD: ssl.c,v 1.7 2019/04/04 00:36:09 christos Exp $");
     38  1.1  christos #endif
     39  1.1  christos 
     40  1.1  christos #include <time.h>
     41  1.1  christos #include <unistd.h>
     42  1.6  christos #include <string.h>
     43  1.1  christos #include <fcntl.h>
     44  1.1  christos 
     45  1.1  christos #include <sys/param.h>
     46  1.1  christos #include <sys/select.h>
     47  1.1  christos #include <sys/uio.h>
     48  1.1  christos 
     49  1.1  christos #include <netinet/tcp.h>
     50  1.1  christos #include <netinet/in.h>
     51  1.1  christos #include <openssl/crypto.h>
     52  1.1  christos #include <openssl/x509.h>
     53  1.1  christos #include <openssl/pem.h>
     54  1.1  christos #include <openssl/ssl.h>
     55  1.1  christos #include <openssl/err.h>
     56  1.1  christos 
     57  1.1  christos #include "ssl.h"
     58  1.1  christos 
     59  1.1  christos extern int quit_time, verbose, ftp_debug;
     60  1.1  christos extern FILE *ttyout;
     61  1.1  christos 
     62  1.1  christos struct fetch_connect {
     63  1.1  christos 	int			 sd;		/* file/socket descriptor */
     64  1.1  christos 	char			*buf;		/* buffer */
     65  1.1  christos 	size_t			 bufsize;	/* buffer size */
     66  1.1  christos 	size_t			 bufpos;	/* position of buffer */
     67  1.1  christos 	size_t			 buflen;	/* length of buffer contents */
     68  1.1  christos 	struct {				/* data cached after an
     69  1.1  christos 						   interrupted read */
     70  1.1  christos 		char	*buf;
     71  1.1  christos 		size_t	 size;
     72  1.1  christos 		size_t	 pos;
     73  1.1  christos 		size_t	 len;
     74  1.1  christos 	} cache;
     75  1.1  christos 	int 			 issock;
     76  1.1  christos 	int			 iserr;
     77  1.1  christos 	int			 iseof;
     78  1.1  christos 	SSL			*ssl;		/* SSL handle */
     79  1.1  christos };
     80  1.1  christos 
     81  1.1  christos /*
     82  1.1  christos  * Write a vector to a connection w/ timeout
     83  1.1  christos  * Note: can modify the iovec.
     84  1.1  christos  */
     85  1.1  christos static ssize_t
     86  1.1  christos fetch_writev(struct fetch_connect *conn, struct iovec *iov, int iovcnt)
     87  1.1  christos {
     88  1.1  christos 	struct timeval now, timeout, delta;
     89  1.1  christos 	fd_set writefds;
     90  1.1  christos 	ssize_t len, total;
     91  1.1  christos 	int r;
     92  1.1  christos 
     93  1.1  christos 	if (quit_time > 0) {
     94  1.1  christos 		FD_ZERO(&writefds);
     95  1.1  christos 		gettimeofday(&timeout, NULL);
     96  1.1  christos 		timeout.tv_sec += quit_time;
     97  1.1  christos 	}
     98  1.1  christos 
     99  1.1  christos 	total = 0;
    100  1.1  christos 	while (iovcnt > 0) {
    101  1.1  christos 		while (quit_time > 0 && !FD_ISSET(conn->sd, &writefds)) {
    102  1.1  christos 			FD_SET(conn->sd, &writefds);
    103  1.1  christos 			gettimeofday(&now, NULL);
    104  1.1  christos 			delta.tv_sec = timeout.tv_sec - now.tv_sec;
    105  1.1  christos 			delta.tv_usec = timeout.tv_usec - now.tv_usec;
    106  1.1  christos 			if (delta.tv_usec < 0) {
    107  1.1  christos 				delta.tv_usec += 1000000;
    108  1.1  christos 				delta.tv_sec--;
    109  1.1  christos 			}
    110  1.1  christos 			if (delta.tv_sec < 0) {
    111  1.1  christos 				errno = ETIMEDOUT;
    112  1.1  christos 				return -1;
    113  1.1  christos 			}
    114  1.1  christos 			errno = 0;
    115  1.1  christos 			r = select(conn->sd + 1, NULL, &writefds, NULL, &delta);
    116  1.1  christos 			if (r == -1) {
    117  1.1  christos 				if (errno == EINTR)
    118  1.1  christos 					continue;
    119  1.1  christos 				return -1;
    120  1.1  christos 			}
    121  1.1  christos 		}
    122  1.1  christos 		errno = 0;
    123  1.1  christos 		if (conn->ssl != NULL)
    124  1.1  christos 			len = SSL_write(conn->ssl, iov->iov_base, iov->iov_len);
    125  1.1  christos 		else
    126  1.1  christos 			len = writev(conn->sd, iov, iovcnt);
    127  1.1  christos 		if (len == 0) {
    128  1.1  christos 			/* we consider a short write a failure */
    129  1.1  christos 			/* XXX perhaps we shouldn't in the SSL case */
    130  1.1  christos 			errno = EPIPE;
    131  1.1  christos 			return -1;
    132  1.1  christos 		}
    133  1.1  christos 		if (len < 0) {
    134  1.1  christos 			if (errno == EINTR)
    135  1.1  christos 				continue;
    136  1.1  christos 			return -1;
    137  1.1  christos 		}
    138  1.1  christos 		total += len;
    139  1.1  christos 		while (iovcnt > 0 && len >= (ssize_t)iov->iov_len) {
    140  1.1  christos 			len -= iov->iov_len;
    141  1.1  christos 			iov++;
    142  1.1  christos 			iovcnt--;
    143  1.1  christos 		}
    144  1.1  christos 		if (iovcnt > 0) {
    145  1.1  christos 			iov->iov_len -= len;
    146  1.1  christos 			iov->iov_base = (char *)iov->iov_base + len;
    147  1.1  christos 		}
    148  1.1  christos 	}
    149  1.1  christos 	return total;
    150  1.1  christos }
    151  1.1  christos 
    152  1.1  christos /*
    153  1.1  christos  * Write to a connection w/ timeout
    154  1.1  christos  */
    155  1.1  christos static int
    156  1.1  christos fetch_write(struct fetch_connect *conn, const char *str, size_t len)
    157  1.1  christos {
    158  1.1  christos 	struct iovec iov[1];
    159  1.1  christos 
    160  1.1  christos 	iov[0].iov_base = (char *)__UNCONST(str);
    161  1.1  christos 	iov[0].iov_len = len;
    162  1.1  christos 	return fetch_writev(conn, iov, 1);
    163  1.1  christos }
    164  1.1  christos 
    165  1.1  christos /*
    166  1.1  christos  * Send a formatted line; optionally echo to terminal
    167  1.1  christos  */
    168  1.1  christos int
    169  1.1  christos fetch_printf(struct fetch_connect *conn, const char *fmt, ...)
    170  1.1  christos {
    171  1.1  christos 	va_list ap;
    172  1.1  christos 	size_t len;
    173  1.1  christos 	char *msg;
    174  1.1  christos 	int r;
    175  1.1  christos 
    176  1.1  christos 	va_start(ap, fmt);
    177  1.1  christos 	len = vasprintf(&msg, fmt, ap);
    178  1.1  christos 	va_end(ap);
    179  1.1  christos 
    180  1.1  christos 	if (msg == NULL) {
    181  1.1  christos 		errno = ENOMEM;
    182  1.1  christos 		return -1;
    183  1.1  christos 	}
    184  1.1  christos 
    185  1.1  christos 	r = fetch_write(conn, msg, len);
    186  1.1  christos 	free(msg);
    187  1.1  christos 	return r;
    188  1.1  christos }
    189  1.1  christos 
    190  1.1  christos int
    191  1.1  christos fetch_fileno(struct fetch_connect *conn)
    192  1.1  christos {
    193  1.1  christos 
    194  1.1  christos 	return conn->sd;
    195  1.1  christos }
    196  1.1  christos 
    197  1.1  christos int
    198  1.1  christos fetch_error(struct fetch_connect *conn)
    199  1.1  christos {
    200  1.1  christos 
    201  1.1  christos 	return conn->iserr;
    202  1.1  christos }
    203  1.1  christos 
    204  1.1  christos static void
    205  1.1  christos fetch_clearerr(struct fetch_connect *conn)
    206  1.1  christos {
    207  1.1  christos 
    208  1.1  christos 	conn->iserr = 0;
    209  1.1  christos }
    210  1.1  christos 
    211  1.1  christos int
    212  1.1  christos fetch_flush(struct fetch_connect *conn)
    213  1.1  christos {
    214  1.1  christos 	int v;
    215  1.1  christos 
    216  1.1  christos 	if (conn->issock) {
    217  1.1  christos #ifdef TCP_NOPUSH
    218  1.1  christos 		v = 0;
    219  1.1  christos 		setsockopt(conn->sd, IPPROTO_TCP, TCP_NOPUSH, &v, sizeof(v));
    220  1.1  christos #endif
    221  1.1  christos 		v = 1;
    222  1.1  christos 		setsockopt(conn->sd, IPPROTO_TCP, TCP_NODELAY, &v, sizeof(v));
    223  1.1  christos 	}
    224  1.1  christos 	return 0;
    225  1.1  christos }
    226  1.1  christos 
    227  1.1  christos /*ARGSUSED*/
    228  1.1  christos struct fetch_connect *
    229  1.1  christos fetch_open(const char *fname, const char *fmode)
    230  1.1  christos {
    231  1.1  christos 	struct fetch_connect *conn;
    232  1.1  christos 	int fd;
    233  1.1  christos 
    234  1.1  christos 	fd = open(fname, O_RDONLY); /* XXX: fmode */
    235  1.1  christos 	if (fd < 0)
    236  1.1  christos 		return NULL;
    237  1.1  christos 
    238  1.1  christos 	if ((conn = calloc(1, sizeof(*conn))) == NULL) {
    239  1.1  christos 		close(fd);
    240  1.1  christos 		return NULL;
    241  1.1  christos 	}
    242  1.1  christos 
    243  1.1  christos 	conn->sd = fd;
    244  1.1  christos 	conn->issock = 0;
    245  1.1  christos 	return conn;
    246  1.1  christos }
    247  1.1  christos 
    248  1.1  christos /*ARGSUSED*/
    249  1.1  christos struct fetch_connect *
    250  1.1  christos fetch_fdopen(int sd, const char *fmode)
    251  1.1  christos {
    252  1.1  christos 	struct fetch_connect *conn;
    253  1.2  christos #if defined(SO_NOSIGPIPE) || defined(TCP_NOPUSH)
    254  1.1  christos 	int opt = 1;
    255  1.2  christos #endif
    256  1.1  christos 
    257  1.1  christos 	if ((conn = calloc(1, sizeof(*conn))) == NULL)
    258  1.1  christos 		return NULL;
    259  1.1  christos 
    260  1.1  christos 	conn->sd = sd;
    261  1.1  christos 	conn->issock = 1;
    262  1.1  christos 	fcntl(sd, F_SETFD, FD_CLOEXEC);
    263  1.2  christos #ifdef SO_NOSIGPIPE
    264  1.1  christos 	setsockopt(sd, SOL_SOCKET, SO_NOSIGPIPE, &opt, sizeof(opt));
    265  1.2  christos #endif
    266  1.1  christos #ifdef TCP_NOPUSH
    267  1.1  christos 	setsockopt(sd, IPPROTO_TCP, TCP_NOPUSH, &opt, sizeof(opt));
    268  1.1  christos #endif
    269  1.1  christos 	return conn;
    270  1.1  christos }
    271  1.1  christos 
    272  1.1  christos int
    273  1.1  christos fetch_close(struct fetch_connect *conn)
    274  1.1  christos {
    275  1.1  christos 	int rv = 0;
    276  1.1  christos 
    277  1.1  christos 	if (conn != NULL) {
    278  1.1  christos 		fetch_flush(conn);
    279  1.1  christos 		SSL_free(conn->ssl);
    280  1.1  christos 		rv = close(conn->sd);
    281  1.1  christos 		if (rv < 0) {
    282  1.1  christos 			errno = rv;
    283  1.1  christos 			rv = EOF;
    284  1.1  christos 		}
    285  1.1  christos 		free(conn->cache.buf);
    286  1.1  christos 		free(conn->buf);
    287  1.1  christos 		free(conn);
    288  1.1  christos 	}
    289  1.1  christos 	return rv;
    290  1.1  christos }
    291  1.1  christos 
    292  1.1  christos #define FETCH_READ_WAIT		-2
    293  1.1  christos #define FETCH_READ_ERROR	-1
    294  1.1  christos 
    295  1.1  christos static ssize_t
    296  1.1  christos fetch_ssl_read(SSL *ssl, void *buf, size_t len)
    297  1.1  christos {
    298  1.1  christos 	ssize_t rlen;
    299  1.1  christos 	int ssl_err;
    300  1.1  christos 
    301  1.1  christos 	rlen = SSL_read(ssl, buf, len);
    302  1.1  christos 	if (rlen < 0) {
    303  1.1  christos 		ssl_err = SSL_get_error(ssl, rlen);
    304  1.1  christos 		if (ssl_err == SSL_ERROR_WANT_READ ||
    305  1.1  christos 		    ssl_err == SSL_ERROR_WANT_WRITE) {
    306  1.1  christos 			return FETCH_READ_WAIT;
    307  1.1  christos 		}
    308  1.1  christos 		ERR_print_errors_fp(ttyout);
    309  1.1  christos 		return FETCH_READ_ERROR;
    310  1.1  christos 	}
    311  1.1  christos 	return rlen;
    312  1.1  christos }
    313  1.1  christos 
    314  1.1  christos static ssize_t
    315  1.1  christos fetch_nonssl_read(int sd, void *buf, size_t len)
    316  1.1  christos {
    317  1.1  christos 	ssize_t rlen;
    318  1.1  christos 
    319  1.1  christos 	rlen = read(sd, buf, len);
    320  1.1  christos 	if (rlen < 0) {
    321  1.1  christos 		if (errno == EAGAIN || errno == EINTR)
    322  1.1  christos 			return FETCH_READ_WAIT;
    323  1.1  christos 		return FETCH_READ_ERROR;
    324  1.1  christos 	}
    325  1.1  christos 	return rlen;
    326  1.1  christos }
    327  1.1  christos 
    328  1.1  christos /*
    329  1.1  christos  * Cache some data that was read from a socket but cannot be immediately
    330  1.1  christos  * returned because of an interrupted system call.
    331  1.1  christos  */
    332  1.1  christos static int
    333  1.1  christos fetch_cache_data(struct fetch_connect *conn, char *src, size_t nbytes)
    334  1.1  christos {
    335  1.1  christos 
    336  1.1  christos 	if (conn->cache.size < nbytes) {
    337  1.1  christos 		char *tmp = realloc(conn->cache.buf, nbytes);
    338  1.1  christos 		if (tmp == NULL)
    339  1.1  christos 			return -1;
    340  1.1  christos 
    341  1.1  christos 		conn->cache.buf = tmp;
    342  1.1  christos 		conn->cache.size = nbytes;
    343  1.1  christos 	}
    344  1.1  christos 
    345  1.1  christos 	memcpy(conn->cache.buf, src, nbytes);
    346  1.1  christos 	conn->cache.len = nbytes;
    347  1.1  christos 	conn->cache.pos = 0;
    348  1.1  christos 	return 0;
    349  1.1  christos }
    350  1.1  christos 
    351  1.7  christos size_t
    352  1.1  christos fetch_read(void *ptr, size_t size, size_t nmemb, struct fetch_connect *conn)
    353  1.1  christos {
    354  1.1  christos 	struct timeval now, timeout, delta;
    355  1.1  christos 	fd_set readfds;
    356  1.1  christos 	ssize_t rlen, total;
    357  1.1  christos 	size_t len;
    358  1.1  christos 	char *start, *buf;
    359  1.1  christos 
    360  1.1  christos 	if (quit_time > 0) {
    361  1.1  christos 		gettimeofday(&timeout, NULL);
    362  1.1  christos 		timeout.tv_sec += quit_time;
    363  1.1  christos 	}
    364  1.1  christos 
    365  1.1  christos 	total = 0;
    366  1.1  christos 	start = buf = ptr;
    367  1.1  christos 	len = size * nmemb;
    368  1.1  christos 
    369  1.1  christos 	if (conn->cache.len > 0) {
    370  1.1  christos 		/*
    371  1.1  christos 		 * The last invocation of fetch_read was interrupted by a
    372  1.1  christos 		 * signal after some data had been read from the socket. Copy
    373  1.1  christos 		 * the cached data into the supplied buffer before trying to
    374  1.1  christos 		 * read from the socket again.
    375  1.1  christos 		 */
    376  1.1  christos 		total = (conn->cache.len < len) ? conn->cache.len : len;
    377  1.1  christos 		memcpy(buf, conn->cache.buf, total);
    378  1.1  christos 
    379  1.1  christos 		conn->cache.len -= total;
    380  1.1  christos 		conn->cache.pos += total;
    381  1.1  christos 		len -= total;
    382  1.1  christos 		buf += total;
    383  1.1  christos 	}
    384  1.1  christos 
    385  1.1  christos 	while (len > 0) {
    386  1.1  christos 		/*
    387  1.1  christos 		 * The socket is non-blocking.  Instead of the canonical
    388  1.1  christos 		 * select() -> read(), we do the following:
    389  1.1  christos 		 *
    390  1.1  christos 		 * 1) call read() or SSL_read().
    391  1.1  christos 		 * 2) if an error occurred, return -1.
    392  1.1  christos 		 * 3) if we received data but we still expect more,
    393  1.1  christos 		 *    update our counters and loop.
    394  1.1  christos 		 * 4) if read() or SSL_read() signaled EOF, return.
    395  1.1  christos 		 * 5) if we did not receive any data but we're not at EOF,
    396  1.1  christos 		 *    call select().
    397  1.1  christos 		 *
    398  1.1  christos 		 * In the SSL case, this is necessary because if we
    399  1.1  christos 		 * receive a close notification, we have to call
    400  1.1  christos 		 * SSL_read() one additional time after we've read
    401  1.1  christos 		 * everything we received.
    402  1.1  christos 		 *
    403  1.1  christos 		 * In the non-SSL case, it may improve performance (very
    404  1.1  christos 		 * slightly) when reading small amounts of data.
    405  1.1  christos 		 */
    406  1.1  christos 		if (conn->ssl != NULL)
    407  1.1  christos 			rlen = fetch_ssl_read(conn->ssl, buf, len);
    408  1.1  christos 		else
    409  1.1  christos 			rlen = fetch_nonssl_read(conn->sd, buf, len);
    410  1.1  christos 		if (rlen == 0) {
    411  1.7  christos 			conn->iseof = 1;
    412  1.1  christos 			break;
    413  1.1  christos 		} else if (rlen > 0) {
    414  1.1  christos 			len -= rlen;
    415  1.1  christos 			buf += rlen;
    416  1.1  christos 			total += rlen;
    417  1.1  christos 			continue;
    418  1.1  christos 		} else if (rlen == FETCH_READ_ERROR) {
    419  1.7  christos 			conn->iserr = errno;
    420  1.1  christos 			if (errno == EINTR)
    421  1.1  christos 				fetch_cache_data(conn, start, total);
    422  1.7  christos 			return 0;
    423  1.1  christos 		}
    424  1.1  christos 		FD_ZERO(&readfds);
    425  1.1  christos 		while (!FD_ISSET(conn->sd, &readfds)) {
    426  1.1  christos 			FD_SET(conn->sd, &readfds);
    427  1.1  christos 			if (quit_time > 0) {
    428  1.1  christos 				gettimeofday(&now, NULL);
    429  1.1  christos 				if (!timercmp(&timeout, &now, >)) {
    430  1.7  christos 					conn->iserr = ETIMEDOUT;
    431  1.7  christos 					return 0;
    432  1.1  christos 				}
    433  1.1  christos 				timersub(&timeout, &now, &delta);
    434  1.1  christos 			}
    435  1.1  christos 			errno = 0;
    436  1.1  christos 			if (select(conn->sd + 1, &readfds, NULL, NULL,
    437  1.1  christos 				quit_time > 0 ? &delta : NULL) < 0) {
    438  1.1  christos 				if (errno == EINTR)
    439  1.1  christos 					continue;
    440  1.7  christos 				conn->iserr = errno;
    441  1.7  christos 				return 0;
    442  1.1  christos 			}
    443  1.1  christos 		}
    444  1.1  christos 	}
    445  1.1  christos 	return total;
    446  1.1  christos }
    447  1.1  christos 
    448  1.1  christos #define MIN_BUF_SIZE 1024
    449  1.1  christos 
    450  1.1  christos /*
    451  1.1  christos  * Read a line of text from a connection w/ timeout
    452  1.1  christos  */
    453  1.1  christos char *
    454  1.1  christos fetch_getln(char *str, int size, struct fetch_connect *conn)
    455  1.1  christos {
    456  1.1  christos 	size_t tmpsize;
    457  1.7  christos 	size_t len;
    458  1.1  christos 	char c;
    459  1.1  christos 
    460  1.1  christos 	if (conn->buf == NULL) {
    461  1.1  christos 		if ((conn->buf = malloc(MIN_BUF_SIZE)) == NULL) {
    462  1.1  christos 			errno = ENOMEM;
    463  1.1  christos 			conn->iserr = 1;
    464  1.1  christos 			return NULL;
    465  1.1  christos 		}
    466  1.1  christos 		conn->bufsize = MIN_BUF_SIZE;
    467  1.1  christos 	}
    468  1.1  christos 
    469  1.1  christos 	if (conn->iserr || conn->iseof)
    470  1.1  christos 		return NULL;
    471  1.1  christos 
    472  1.1  christos 	if (conn->buflen - conn->bufpos > 0)
    473  1.1  christos 		goto done;
    474  1.1  christos 
    475  1.1  christos 	conn->buf[0] = '\0';
    476  1.1  christos 	conn->bufpos = 0;
    477  1.1  christos 	conn->buflen = 0;
    478  1.1  christos 	do {
    479  1.1  christos 		len = fetch_read(&c, sizeof(c), 1, conn);
    480  1.1  christos 		if (len == 0) {
    481  1.7  christos 			if (conn->iserr)
    482  1.7  christos 				return NULL;
    483  1.7  christos 			if (conn->iseof)
    484  1.7  christos 				break;
    485  1.7  christos 			abort();
    486  1.1  christos 		}
    487  1.1  christos 		conn->buf[conn->buflen++] = c;
    488  1.1  christos 		if (conn->buflen == conn->bufsize) {
    489  1.1  christos 			char *tmp = conn->buf;
    490  1.1  christos 			tmpsize = conn->bufsize * 2 + 1;
    491  1.1  christos 			if ((tmp = realloc(tmp, tmpsize)) == NULL) {
    492  1.1  christos 				errno = ENOMEM;
    493  1.1  christos 				conn->iserr = 1;
    494  1.1  christos 				return NULL;
    495  1.1  christos 			}
    496  1.1  christos 			conn->buf = tmp;
    497  1.1  christos 			conn->bufsize = tmpsize;
    498  1.1  christos 		}
    499  1.1  christos 	} while (c != '\n');
    500  1.1  christos 
    501  1.1  christos 	if (conn->buflen == 0)
    502  1.1  christos 		return NULL;
    503  1.1  christos  done:
    504  1.1  christos 	tmpsize = MIN(size - 1, (int)(conn->buflen - conn->bufpos));
    505  1.1  christos 	memcpy(str, conn->buf + conn->bufpos, tmpsize);
    506  1.1  christos 	str[tmpsize] = '\0';
    507  1.1  christos 	conn->bufpos += tmpsize;
    508  1.1  christos 	return str;
    509  1.1  christos }
    510  1.1  christos 
    511  1.1  christos int
    512  1.1  christos fetch_getline(struct fetch_connect *conn, char *buf, size_t buflen,
    513  1.1  christos     const char **errormsg)
    514  1.1  christos {
    515  1.1  christos 	size_t len;
    516  1.1  christos 	int rv;
    517  1.1  christos 
    518  1.1  christos 	if (fetch_getln(buf, buflen, conn) == NULL) {
    519  1.1  christos 		if (conn->iseof) {	/* EOF */
    520  1.1  christos 			rv = -2;
    521  1.1  christos 			if (errormsg)
    522  1.1  christos 				*errormsg = "\nEOF received";
    523  1.1  christos 		} else {		/* error */
    524  1.1  christos 			rv = -1;
    525  1.1  christos 			if (errormsg)
    526  1.1  christos 				*errormsg = "Error encountered";
    527  1.1  christos 		}
    528  1.1  christos 		fetch_clearerr(conn);
    529  1.1  christos 		return rv;
    530  1.1  christos 	}
    531  1.1  christos 	len = strlen(buf);
    532  1.1  christos 	if (buf[len - 1] == '\n') {	/* clear any trailing newline */
    533  1.1  christos 		buf[--len] = '\0';
    534  1.1  christos 	} else if (len == buflen - 1) {	/* line too long */
    535  1.1  christos 		while (1) {
    536  1.1  christos 			char c;
    537  1.7  christos 			size_t rlen = fetch_read(&c, sizeof(c), 1, conn);
    538  1.7  christos 			if (rlen == 0 || c == '\n')
    539  1.1  christos 				break;
    540  1.1  christos 		}
    541  1.1  christos 		if (errormsg)
    542  1.1  christos 			*errormsg = "Input line is too long";
    543  1.1  christos 		fetch_clearerr(conn);
    544  1.1  christos 		return -3;
    545  1.1  christos 	}
    546  1.1  christos 	if (errormsg)
    547  1.1  christos 		*errormsg = NULL;
    548  1.1  christos 	return len;
    549  1.1  christos }
    550  1.1  christos 
    551  1.1  christos void *
    552  1.3       wiz fetch_start_ssl(int sock, const char *servername)
    553  1.1  christos {
    554  1.1  christos 	SSL *ssl;
    555  1.1  christos 	SSL_CTX *ctx;
    556  1.1  christos 	int ret, ssl_err;
    557  1.1  christos 
    558  1.1  christos 	/* Init the SSL library and context */
    559  1.1  christos 	if (!SSL_library_init()){
    560  1.1  christos 		fprintf(ttyout, "SSL library init failed\n");
    561  1.1  christos 		return NULL;
    562  1.1  christos 	}
    563  1.1  christos 
    564  1.1  christos 	SSL_load_error_strings();
    565  1.1  christos 
    566  1.1  christos 	ctx = SSL_CTX_new(SSLv23_client_method());
    567  1.1  christos 	SSL_CTX_set_mode(ctx, SSL_MODE_AUTO_RETRY);
    568  1.1  christos 
    569  1.1  christos 	ssl = SSL_new(ctx);
    570  1.1  christos 	if (ssl == NULL){
    571  1.1  christos 		fprintf(ttyout, "SSL context creation failed\n");
    572  1.1  christos 		SSL_CTX_free(ctx);
    573  1.1  christos 		return NULL;
    574  1.1  christos 	}
    575  1.1  christos 	SSL_set_fd(ssl, sock);
    576  1.5     joerg 	if (!SSL_set_tlsext_host_name(ssl, __UNCONST(servername))) {
    577  1.4       wiz 		fprintf(ttyout, "SSL hostname setting failed\n");
    578  1.4       wiz 		SSL_CTX_free(ctx);
    579  1.4       wiz 		return NULL;
    580  1.3       wiz 	}
    581  1.1  christos 	while ((ret = SSL_connect(ssl)) == -1) {
    582  1.1  christos 		ssl_err = SSL_get_error(ssl, ret);
    583  1.1  christos 		if (ssl_err != SSL_ERROR_WANT_READ &&
    584  1.1  christos 		    ssl_err != SSL_ERROR_WANT_WRITE) {
    585  1.1  christos 			ERR_print_errors_fp(ttyout);
    586  1.1  christos 			SSL_free(ssl);
    587  1.1  christos 			return NULL;
    588  1.1  christos 		}
    589  1.1  christos 	}
    590  1.1  christos 
    591  1.1  christos 	if (ftp_debug && verbose) {
    592  1.1  christos 		X509 *cert;
    593  1.1  christos 		X509_NAME *name;
    594  1.1  christos 		char *str;
    595  1.1  christos 
    596  1.1  christos 		fprintf(ttyout, "SSL connection established using %s\n",
    597  1.1  christos 		    SSL_get_cipher(ssl));
    598  1.1  christos 		cert = SSL_get_peer_certificate(ssl);
    599  1.1  christos 		name = X509_get_subject_name(cert);
    600  1.1  christos 		str = X509_NAME_oneline(name, 0, 0);
    601  1.1  christos 		fprintf(ttyout, "Certificate subject: %s\n", str);
    602  1.1  christos 		free(str);
    603  1.1  christos 		name = X509_get_issuer_name(cert);
    604  1.1  christos 		str = X509_NAME_oneline(name, 0, 0);
    605  1.1  christos 		fprintf(ttyout, "Certificate issuer: %s\n", str);
    606  1.1  christos 		free(str);
    607  1.1  christos 	}
    608  1.1  christos 
    609  1.1  christos 	return ssl;
    610  1.1  christos }
    611  1.1  christos 
    612  1.1  christos 
    613  1.1  christos void
    614  1.1  christos fetch_set_ssl(struct fetch_connect *conn, void *ssl)
    615  1.1  christos {
    616  1.1  christos 	conn->ssl = ssl;
    617  1.1  christos }
    618