1 /*****************************************************************************
3 *****************************************************************************
4 * Copyright (C) 2005 Rémi Denis-Courmont
7 * Authors: Rémi Denis-Courmont <rem # videolan.org>
9 * This program is free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License as published by
11 * the Free Software Foundation; either version 2 of the License, or
12 * (at your option) any later version.
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Public License for more details.
19 * You should have received a copy of the GNU General Public License
20 * along with this program; if not, write to the Free Software
21 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111, USA.
22 *****************************************************************************/
24 /*****************************************************************************
26 *****************************************************************************/
33 #if defined( WIN32 ) || defined( UNDER_CE )
34 # include <winsock2.h>
35 # include <ws2tcpip.h>
37 # include <sys/socket.h>
38 # include <netinet/in.h>
44 /* FIXME: rwlock on acl, but libvlc doesn't implement rwlock */
45 /* FIXME: move to src/stream_output/whatever */
46 typedef struct vlc_acl_entry_t
49 uint8_t i_bytes_match;
56 vlc_object_t *p_owner;
58 vlc_acl_entry_t *p_entries;
59 vlc_bool_t b_allow_default;
62 static int ACL_Resolve( vlc_object_t *p_this, uint8_t *p_bytes,
65 struct addrinfo hints = { }, *res;
68 hints.ai_socktype = SOCK_STREAM; /* doesn't matter */
69 hints.ai_flags = AI_NUMERICHOST;
71 if( vlc_getaddrinfo( p_this, psz_ip, 0, &hints, &res ) )
73 msg_Err( p_this, "invalid IP address %s", psz_ip );
77 p_bytes[16] = 0; /* avoids overflowing when i_bytes_match = 16 */
79 i_family = res->ai_addr->sa_family;
84 struct sockaddr_in *addr;
86 addr = (struct sockaddr_in *)res->ai_addr;
87 memset( p_bytes, 0, 12 );
88 memcpy( p_bytes + 12, &addr->sin_addr, 4 );
92 #if defined (HAVE_GETADDRINFO) || defined (WIN32)
93 /* unfortunately many people define AF_INET6
94 though they don't have struct sockaddr_in6 */
97 struct sockaddr_in6 *addr;
99 addr = (struct sockaddr_in6 *)res->ai_addr;
100 memcpy( p_bytes, &addr->sin6_addr, 16 );
106 msg_Err( p_this, "IMPOSSIBLE: unknown address family!" );
107 vlc_freeaddrinfo( res );
111 vlc_freeaddrinfo( res );
117 * Returns 0 if allowed, 1 if not, -1 on error.
119 int ACL_Check( vlc_acl_t *p_acl, const char *psz_ip )
121 const vlc_acl_entry_t *p_cur, *p_end;
127 p_cur = p_acl->p_entries;
128 p_end = p_cur + p_acl->i_size;
130 if( ACL_Resolve( p_acl->p_owner, host, psz_ip ) < 0 )
133 while (p_cur < p_end)
137 i = p_cur->i_bytes_match;
138 if( (memcmp( p_cur->host, host, i ) == 0)
139 && (((p_cur->host[i] ^ host[i]) & p_cur->i_bits_mask) == 0) )
140 return !p_cur->b_allow;
145 return !p_acl->b_allow_default;
148 int ACL_AddNet( vlc_acl_t *p_acl, const char *psz_ip, int i_len,
151 vlc_acl_entry_t *p_ent;
156 i_size = p_acl->i_size;
157 p_ent = (vlc_acl_entry_t *)realloc( p_acl->p_entries,
158 ++p_acl->i_size * sizeof( *p_ent ) );
163 i_family = ACL_Resolve( p_acl->p_owner, p_ent->host, psz_ip );
167 * I'm lazy : memory space will be re-used in the next ACL_Add call...
176 if( i_family == AF_INET )
179 p_acl->p_entries = p_ent;
189 i_len = 128; /* ACL_AddHost */
192 p_ent->i_bytes_match = d.quot;
193 p_ent->i_bits_mask = 0xff << (8 - d.rem);
195 p_ent->b_allow = b_allow;
200 vlc_acl_t *__ACL_Create( vlc_object_t *p_this, vlc_bool_t b_allow )
204 p_acl = (vlc_acl_t *)malloc( sizeof( *p_acl ) );
208 vlc_object_yield( p_this );
209 p_acl->p_owner = p_this;
211 p_acl->p_entries = NULL;
212 p_acl->b_allow_default = b_allow;
218 vlc_acl_t *__ACL_Duplicate( vlc_object_t *p_this, const vlc_acl_t *p_acl )
225 p_dupacl = (vlc_acl_t *)malloc( sizeof( *p_dupacl ) );
226 if( p_dupacl == NULL )
229 p_dupacl->p_entries = (vlc_acl_entry_t *)
230 malloc( p_acl->i_size * sizeof( vlc_acl_entry_t ) );
231 if( p_dupacl->p_entries == NULL )
237 vlc_object_yield( p_this );
238 p_dupacl->p_owner = p_this;
239 p_dupacl->i_size = p_acl->i_size;
240 memcpy( p_dupacl->p_entries, p_acl->p_entries,
241 p_dupacl->i_size * sizeof( vlc_acl_entry_t ) );
247 void ACL_Destroy( vlc_acl_t *p_acl )
251 if( p_acl->p_entries != NULL )
252 free( p_acl->p_entries );
254 vlc_object_release( p_acl->p_owner );
260 int ACL_LoadFile( vlc_acl_t *p_acl, const char *psz_path )
267 file = fopen( psz_path, "r" );
271 msg_Dbg( p_acl->p_owner, "find .hosts in dir=%s", psz_path );
273 while( !feof( file ) )
275 char line[1024], *psz_ip, *ptr;
277 if( fgets( line, sizeof( line ) - 1, file ) == NULL )
281 msg_Err( p_acl->p_owner, "Error reading %s : %s\n", psz_path,
291 while( isblank( *psz_ip ) )
294 ptr = strchr( psz_ip, '\n' );
297 msg_Warn( p_acl->p_owner, "Skipping overly long line in %s\n",
301 fgets( line, sizeof( line ) - 1, file );
302 if( ferror( file ) || feof( file ) )
304 msg_Err( p_acl->p_owner, "Error reading %s : %s\n",
305 psz_path, strerror( errno ) );
309 while( strchr( line, '\n' ) == NULL);
311 continue; /* skip unusable line */
314 /* skips comment-only line */
318 /* looks for first space, CR, LF, etc. or end-of-line comment */
319 /* (there is at least a linefeed) */
320 for( ptr = psz_ip; ( *ptr != '#' ) && !isspace( *ptr ); ptr++ );
324 msg_Dbg( p_acl->p_owner, "restricted to %s", psz_ip );
326 ptr = strchr( psz_ip, '/' );
328 *ptr++ = '\0'; /* separate address from mask length */
331 ? ACL_AddNet( p_acl, psz_ip, atoi( ptr ), VLC_TRUE )
332 : ACL_AddHost( p_acl, psz_ip, VLC_TRUE ) )
334 msg_Err( p_acl->p_owner, "cannot add ACL from %s", psz_path );