clamdscan/proto.c
f6870133
 /*
  *  Copyright (C) 2009 Sourcefire, Inc.
  *
  *  Authors: Tomasz Kojm, aCaB
  *
  *  This program is free software; you can redistribute it and/or modify
  *  it under the terms of the GNU General Public License version 2 as
  *  published by the Free Software Foundation.
  *
  *  This program is distributed in the hope that it will be useful,
  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  *  GNU General Public License for more details.
  *
  *  You should have received a copy of the GNU General Public License
  *  along with this program; if not, write to the Free Software
  *  Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
  *  MA 02110-1301, USA.
  */
 
bfd89d7c
 #if HAVE_CONFIG_H
 #include "clamav-config.h"
 #endif
 
 /* must be first because it may define _XOPEN_SOURCE */
 #include "shared/fdpassing.h"
f6870133
 #include <stdio.h>
 #include <unistd.h>
 #include <string.h>
 #include <errno.h>
5ad17a13
 #include <stdlib.h>
f6870133
 #include <sys/types.h>
 #include <sys/stat.h>
 #include <fcntl.h>
 #include <sys/types.h>
 #include <sys/socket.h>
ea2799a2
 #include <sys/select.h>
f6870133
 #include <arpa/inet.h>
 
 #include "libclamav/others.h"
ee6702ab
 #include "shared/actions.h"
f6870133
 #include "shared/output.h"
 
 #include "proto.h"
 #include "client.h"
 
 extern struct sockaddr *mainsa;
 extern int mainsasz;
9877f2d8
 extern unsigned long int maxstream;
fadd3046
 int printinfected;
f6870133
 
 static const char *scancmd[] = { "CONTSCAN", "MULTISCAN" };
 
 /* Connects to clamd 
  * Returns a FD or -1 on error */
 int dconnect() {
     int sockd;
 
     if((sockd = socket(mainsa->sa_family, SOCK_STREAM, 0)) < 0) {
f592af6c
 	logg("!Can't create the socket: %s\n", strerror(errno));
f6870133
 	return -1;
     }
 
     if(connect(sockd, (struct sockaddr *)mainsa, mainsasz) < 0) {
 	close(sockd);
f592af6c
 	logg("!Can't connect to clamd: %s\n", strerror(errno));
f6870133
 	return -1;
     }
     return sockd;
 }
 
 /* Sends bytes over a socket
  * Returns 0 on success */
 int sendln(int sockd, const char *line, unsigned int len) {
     while(len) {
 	int sent = send(sockd, line, len, 0);
 	if(sent <= 0) {
 	    if(sent && errno == EINTR) continue;
5b1eee09
 	    logg("!Can't send to clamd: %s\n", strerror(errno));
f6870133
 	    return 1;
 	}
 	line += sent;
 	len -= sent;
     }
     return 0;
 }
 
 /* Inits a RECVLN struct before it can be used in recvln() - see below */
 void recvlninit(struct RCVLN *s, int sockd) {
     s->sockd = sockd;
     s->bol = s->cur = s->buf;
     s->r = 0;
 }
 
 /* Receives a full (terminated with \0) line from a socket
  * Sets rbol to the begin of the received line, and optionally 
  * reol to the ond of line.
  * Should be called repeatedly untill all input is conumed
  * Returns 
  * - the lenght of the line (a positive number) on success
  * - 0 if the connection is closed
  * - -1 on error
  */
 int recvln(struct RCVLN *s, char **rbol, char **reol) {
     char *eol;
 
     while(1) {
 	if(!s->r) {
 	    s->r = recv(s->sockd, s->cur, sizeof(s->buf) - (s->cur - s->buf), 0);
 	    if(s->r<=0) {
 		if(s->r && errno == EINTR) {
 		    s->r = 0;
 		    continue;
 		}
 		if(s->r || s->cur!=s->buf) {
5ad17a13
 		    *s->cur = '\0';
 		    if(strcmp(s->buf, "UNKNOWN COMMAND\n"))
 			logg("!Communication error\n");
5b1eee09
 		    else
5ad17a13
 			logg("!Command rejected by clamd (wrong clamd version?)\n");
f6870133
 		    return -1;
 		}
 	        return 0;
 	    }
 	}
 	if((eol = memchr(s->cur, 0, s->r))) {
 	    int ret = 0;
 	    eol++;
 	    s->r -= eol - s->cur;
 	    *rbol = s->bol;
 	    if(reol) *reol = eol;
 	    ret = eol - s->bol;
 	    if(s->r)
 		s->bol = s->cur = eol;
 	    else
 		s->bol = s->cur = s->buf;
 	    return ret;
 	}
 	s->r += s->cur - s->bol;
 	if(!eol && s->r==sizeof(s->buf)) {
 	    logg("!Overlong reply from clamd\n");
 	    return -1;
 	}
 	if(!eol) {
 	    if(s->buf != s->bol) { /* old memmove sux */
 		memmove(s->buf, s->bol, s->r);
 		s->bol = s->buf;
 	    }
 	    s->cur = &s->bol[s->r];
 	    s->r = 0;
 	}
     }
 }
 
 /* Issues an INSTREAM command to clamd and streams the given file
f592af6c
  * Returns >0 on success, 0 soft fail, -1 hard fail */
f6870133
 static int send_stream(int sockd, const char *filename) {
     uint32_t buf[BUFSIZ/sizeof(uint32_t)];
     int fd, len;
83c52f7e
     unsigned long int todo = maxstream;
f6870133
 
     if(filename) {
228d7e19
 	if((fd = open(filename, O_RDONLY))<0) {
f592af6c
 	    logg("~%s: Access denied. ERROR\n", filename);
 	    return 0;
f6870133
 	}
     } else fd = 0;
 
f592af6c
     if(sendln(sockd, "zINSTREAM", 10)) return -1;
f6870133
 
ff989b7d
     while((len = read(fd, &buf[1], sizeof(buf) - sizeof(uint32_t))) > 0) {
9877f2d8
 	if((unsigned int)len > todo) len = todo;
f6870133
 	buf[0] = htonl(len);
83c52f7e
 	if(sendln(sockd, (const char *)buf, len+sizeof(uint32_t))) {
f6870133
 	    close(fd);
f592af6c
 	    return -1;
f6870133
 	}
9877f2d8
 	todo -= len;
 	if(!todo) {
 	    len = 0;
 	    break;
 	}
f6870133
     }
     close(fd);
     if(len) {
5b1eee09
 	logg("!Failed to read from %s.\n", filename ? filename : "STDIN");
f592af6c
 	return 0;
f6870133
     }
83c52f7e
     *buf=0;
     sendln(sockd, (const char *)buf, 4);
f592af6c
     return 1;
f6870133
 }
 
ea2799a2
 #ifdef HAVE_FD_PASSING
f6870133
 /* Issues a FILDES command and pass a FD to clamd
f592af6c
  * Returns >0 on success, 0 soft fail, -1 hard fail */
f6870133
 static int send_fdpass(int sockd, const char *filename) {
     struct iovec iov[1];
     struct msghdr msg;
     struct cmsghdr *cmsg;
     unsigned char fdbuf[CMSG_SPACE(sizeof(int))];
     char dummy[]="";
     int fd;
 
     if(filename) {
284982ca
 	if((fd = open(filename, O_RDONLY))<0) {
f592af6c
 	    logg("~%s: Access denied. ERROR\n", filename);
 	    return 0;
f6870133
 	}
     } else fd = 0;
ea2799a2
     if(sendln(sockd, "zFILDES", 8)) {
       close(fd);
f592af6c
       return -1;
ea2799a2
     }
f6870133
 
     iov[0].iov_base = dummy;
     iov[0].iov_len = 1;
     memset(&msg, 0, sizeof(msg));
     msg.msg_control = fdbuf;
     msg.msg_iov = iov;
     msg.msg_iovlen = 1;
     msg.msg_controllen = CMSG_LEN(sizeof(int));
     cmsg = CMSG_FIRSTHDR(&msg);
     cmsg->cmsg_len = CMSG_LEN(sizeof(int));
     cmsg->cmsg_level = SOL_SOCKET;
     cmsg->cmsg_type = SCM_RIGHTS;
     *(int *)CMSG_DATA(cmsg) = fd;
     if(sendmsg(sockd, &msg, 0) == -1) {
4ca3fc95
 	logg("!FD send failed: %s\n", strerror(errno));
ea2799a2
 	close(fd);
f592af6c
 	return -1;
f6870133
     }
ea2799a2
     close(fd);
f592af6c
     return 1;
f6870133
 }
ea2799a2
 #endif
f6870133
 
 /* Sends a proper scan request to clamd and parses its replies
  * This is used only in non IDSESSION mode
  * Returns the number of infected files or -1 on error */
22446430
 int dsresult(int sockd, int scantype, const char *filename, int *printok) {
5b1eee09
     int infected = 0, len, beenthere = 0;
     char *bol, *eol;
     struct RCVLN rcv;
f6870133
 
     recvlninit(&rcv, sockd);
 
     switch(scantype) {
     case MULTI:
     case CONT:
     len = strlen(filename) + strlen(scancmd[scantype]) + 3;
     if (!(bol = malloc(len))) {
f592af6c
 	logg("!Cannot allocate a command buffer: %s\n", strerror(errno));
f6870133
 	return -1;
     }
     sprintf(bol, "z%s %s", scancmd[scantype], filename);
     if(sendln(sockd, bol, len)) return -1;
     free(bol);
     break;
 
     case STREAM:
f592af6c
 	len = send_stream(sockd, filename);
d9237414
 	break;
f6870133
 #ifdef HAVE_FD_PASSING
     case FILDES:
f592af6c
 	len = send_fdpass(sockd, filename);
f6870133
 	break;
 #endif
     }
 
22446430
     if(len <=0) {
 	*printok = 0;
 	return len;
     }
f592af6c
 
f6870133
     while((len = recvln(&rcv, &bol, &eol))) {
5b1eee09
 	if(len == -1) return -1;
6a779d44
 	beenthere = 1;
f6870133
 	if(!filename) logg("~%s\n", bol);
 	if(len > 7) {
4a9f7873
 	    char *colon = strrchr(bol, ':');
f6870133
 	    if(!colon) {
 		logg("Failed to parse reply\n");
5b1eee09
 		return -1;
f6870133
 	    } else if(!memcmp(eol - 7, " FOUND", 6)) {
22446430
 		*printok = 0;
f6870133
 		infected++;
 		if(filename) {
 		    if(scantype >= STREAM) {
 			logg("~%s%s\n", filename, colon);
 			if(action) action(filename);
 		    } else {
 			logg("~%s\n", bol);
 			*colon = '\0';
 			if(action)
 			    action(bol);
 		    }
 		}
 	    } else if(!memcmp(eol-7, " ERROR", 6)) {
22446430
 		*printok = 0;
f6870133
 		if(filename) {
 		    if(scantype >= STREAM)
 			logg("~%s%s\n", filename, colon);
 		    else
 			logg("~%s\n", bol);
 		}
 	    }
 	}
     }
6a779d44
     if(!beenthere) {
 	logg("~%s: no reply from clamd\n", filename ? filename : "STDIN");
5b1eee09
 	return -1;
6a779d44
     }
5b1eee09
     return infected;
f6870133
 }
 
 
 
 /* Used by serial_callback() */
 struct client_serial_data {
     int infected;
     int scantype;
22446430
     int printok;
f6870133
 };
 
83c52f7e
 /* FTW callback for scanning in non IDSESSION mode
  * Returns SUCCESS or BREAK on success, CL_EXXX on error */
f6870133
 static int serial_callback(struct stat *sb, char *filename, const char *path, enum cli_ftw_reason reason, struct cli_ftw_cbdata *data) {
     struct client_serial_data *c = (struct client_serial_data *)data->data;
     int sockd, ret;
     const char *f = filename;
 
     switch(reason) {
     case error_stat:
4ca3fc95
 	logg("^Can't access file %s\n", path);
f6870133
 	return CL_SUCCESS;
     case error_mem:
 	logg("^Memory allocation failed in ftw\n");
 	return CL_EMEM;
     case warning_skipped_dir:
 	logg("^Directory recursion limit reached\n");
39667b9f
     case warning_skipped_link:
f6870133
 	return CL_SUCCESS;
     case warning_skipped_special:
4ca3fc95
 	logg("~%s: Not supported file type. ERROR\n", path);
f6870133
 	return CL_SUCCESS;
ea2799a2
     case visit_directory_toplev:
 	if(c->scantype >= STREAM)
f6870133
 	    return CL_SUCCESS;
 	f = path;
5b1eee09
 	filename = NULL;
     case visit_file:
ea2799a2
 	break;
f6870133
     }
ea2799a2
 
f6870133
     if((sockd = dconnect()) < 0) {
5b1eee09
 	if(filename) free(filename);
7609af89
 	return CL_EOPEN;
f6870133
     }
22446430
     ret = dsresult(sockd, c->scantype, f, &c->printok);
5b1eee09
     if(filename) free(filename);
f6870133
     close(sockd);
f592af6c
     if(ret < 0) return CL_EOPEN;
5b1eee09
     c->infected += ret;
f6870133
     if(reason == visit_directory_toplev)
 	return CL_BREAK;
     return CL_SUCCESS;
 }
 
 /* Non-IDSESSION handler
83c52f7e
  * Returns non zero for serious errors, zero otherwise */
5b1eee09
 int serial_client_scan(char *file, int scantype, int *infected, int maxlevel, int flags) {
f6870133
     struct cli_ftw_cbdata data;
     struct client_serial_data cdata;
83c52f7e
     int ftw;
f6870133
 
     cdata.infected = 0;
22446430
     cdata.printok = printinfected^1;
f6870133
     cdata.scantype = scantype;
     data.data = &cdata;
 
51bbedb1
     ftw = cli_ftw(file, flags, maxlevel ? maxlevel : INT_MAX, serial_callback, &data, NULL);
f6870133
     *infected += cdata.infected;
83c52f7e
 
     if(ftw == CL_SUCCESS || ftw == CL_BREAK) {
22446430
 	if(cdata.printok)
83c52f7e
 	    logg("~%s: OK\n", file);
 	return 0;
     }
     return 1;
f6870133
 }
 
 /* Used in IDSESSION mode */
 struct client_parallel_data {
     int infected;
     int scantype;
     int sockd;
     int lastid;
22446430
     int printok;
f6870133
     struct SCANID {
 	unsigned int id;
 	const char *file;
 	struct SCANID *next;
     } *ids;
 };
 
 /* Sends a proper scan request to clamd and parses its replies
  * This is used only in IDSESSION mode
  * Returns 0 on success, 1 on hard failures */
0115f12f
 static int dspresult(struct client_parallel_data *c) {
f6870133
     const char *filename;
     char *bol, *eol;
     unsigned int rid;
     int len;
     struct SCANID **id = NULL;
     struct RCVLN rcv;
 
     recvlninit(&rcv, c->sockd);
     do {
 	len = recvln(&rcv, &bol, &eol);
5b1eee09
 	if(len < 0) return 1;
 	if(!len) return 0;
f6870133
 	if((rid = atoi(bol))) {
 	    id = &c->ids;
 	    while(*id) {
 		if((*id)->id == rid) break;
 		id = &((*id)->next);
 	    }
 	    if(!*id) id = NULL;
 	}
 	if(!id) {
 	    logg("!Bogus session id from clamd\n");
83c52f7e
 	    return 1;
f6870133
 	}
 	filename = (*id)->file;
 	if(len > 7) {
4a9f7873
 	    char *colon = strrchr(bol, ':');
f6870133
 	    if(!colon) {
5b1eee09
 		logg("!Failed to parse reply\n");
 		free((void *)filename);
 		return 1;
f6870133
 	    } else if(!memcmp(eol - 7, " FOUND", 6)) {
 		c->infected++;
22446430
 		c->printok = 0;
f6870133
 		logg("~%s%s\n", filename, colon);
 		if(action) action(filename);
 	    } else if(!memcmp(eol-7, " ERROR", 6)) {
22446430
 		c->printok = 0;
5b1eee09
 		logg("~%s%s\n", filename, colon);
f6870133
 	    }
 	}
 	free((void *)filename);
 	bol = (char *)*id;
 	*id = (*id)->next;
 	free(bol);
     } while(rcv.cur != rcv.buf); /* clamd sends whole lines, so, on partial lines, we just assume
 				    more data can be recv()'d with close to zero latency */
     return 0;
 }
 
83c52f7e
 /* FTW callback for scanning in IDSESSION mode
5b1eee09
  * Returns SUCCESS on success, CL_EXXX or BREAK on error */
f6870133
 static int parallel_callback(struct stat *sb, char *filename, const char *path, enum cli_ftw_reason reason, struct cli_ftw_cbdata *data) {
     struct client_parallel_data *c = (struct client_parallel_data *)data->data;
f592af6c
     struct SCANID *cid;
     int res;
f6870133
 
     switch(reason) {
     case error_stat:
fadd3046
 	logg("^Can't access file %s\n", path);
f6870133
 	return CL_SUCCESS;
     case error_mem:
 	logg("^Memory allocation failed in ftw\n");
 	return CL_EMEM;
     case warning_skipped_dir:
 	logg("^Directory recursion limit reached\n");
 	return CL_SUCCESS;
     case warning_skipped_special:
fadd3046
 	logg("~%s: Not supported file type. ERROR\n", path);
5b1eee09
     case warning_skipped_link:
f6870133
     case visit_directory_toplev:
 	return CL_SUCCESS;
5b1eee09
     case visit_file:
f6870133
 	break;
     }
 
     while(1) {
 	/* consume all the available input to let some of the clamd
 	 * threads blocked on send() to be dead.
 	 * by doing so we shouldn't deadlock on the next recv() */
 	fd_set rfds, wfds;
 	FD_ZERO(&rfds);
 	FD_SET(c->sockd, &rfds);
 	FD_ZERO(&wfds);
 	FD_SET(c->sockd, &wfds);
 	if(select(c->sockd + 1, &rfds, &wfds, NULL, NULL) < 0) {
 	    if(errno == EINTR) continue;
 	    free(filename);
f592af6c
 	    logg("!select() failed during session: %s\n", strerror(errno));
83c52f7e
 	    return CL_BREAK;
f6870133
 	}
 	if(FD_ISSET(c->sockd, &rfds)) {
 	    if(dspresult(c)) {
 		free(filename);
 		return CL_BREAK;
 	    } else continue;
 	}
 	if(FD_ISSET(c->sockd, &wfds)) break;
     }
 
fadd3046
     cid = (struct SCANID *)malloc(sizeof(struct SCANID));
83c52f7e
     if(!cid) {
 	free(filename);
22446430
 	logg("!Failed to allocate scanid entry: %s\n", strerror(errno));
83c52f7e
 	return CL_BREAK;
     }
f6870133
     cid->id = ++c->lastid;
     cid->file = filename;
f592af6c
     cid->next = c->ids;
     c->ids = cid;
f6870133
 
     switch(c->scantype) {
b7990b9c
 #ifdef HAVE_FD_PASSING
f6870133
     case FILDES:
f592af6c
 	res = send_fdpass(c->sockd, filename);
f6870133
 	break;
b7990b9c
 #endif
f6870133
     case STREAM:
f592af6c
 	res = send_stream(c->sockd, filename);
f6870133
 	break;
     }
f592af6c
     if(res <= 0) {
22446430
 	c->printok = 0;
f592af6c
 	c->ids = cid->next;
 	c->lastid--;
 	free(cid);
 	free(filename);
 	return res ? CL_BREAK : CL_SUCCESS;
     }
f6870133
     return CL_SUCCESS;
 }
 
b7990b9c
 /* IDSESSION handler
83c52f7e
  * Returns non zero for serious errors, zero otherwise */
5b1eee09
 int parallel_client_scan(char *file, int scantype, int *infected, int maxlevel, int flags) {
f6870133
     struct cli_ftw_cbdata data;
     struct client_parallel_data cdata;
83c52f7e
     int ftw;
f6870133
 
     if((cdata.sockd = dconnect()) < 0)
 	return 1;
 
     if(sendln(cdata.sockd, "zIDSESSION", 11)) {
 	close(cdata.sockd);
 	return 1;
     }
 
     cdata.infected = 0;
     cdata.scantype = scantype;
     cdata.lastid = 0;
4a9f7873
     cdata.ids = NULL;
22446430
     cdata.printok = printinfected^1;
f6870133
     data.data = &cdata;
 
51bbedb1
     ftw = cli_ftw(file, flags, maxlevel ? maxlevel : INT_MAX, parallel_callback, &data, NULL);
83c52f7e
 
5b1eee09
     if(ftw != CL_SUCCESS) {
2097428f
 	*infected += cdata.infected;
83c52f7e
 	close(cdata.sockd);
 	return 1;
     }
f6870133
 
6ef6ea82
     sendln(cdata.sockd, "zEND", 5);
533fa895
     while(cdata.ids && !dspresult(&cdata));
6ef6ea82
     close(cdata.sockd);
 
2097428f
     *infected += cdata.infected;
 
533fa895
     if(cdata.ids) {
5b1eee09
 	logg("!Clamd closed the connection before scanning all files.\n");
83c52f7e
 	return 1;
533fa895
     }
22446430
     if(cdata.printok)
83c52f7e
 	logg("~%s: OK\n", file);
     return 0;
f6870133
 }