#include #include #include #include #include "pseccomp.h" #include "capabilities.h" #include "log.h" #include "log_colored.h" #include "utils.h" #include "redirector.h" #include "protocol_ssh.h" #include "forward.h" #include "jail.h" #ifdef HAVE_CONFIG_H #include "config.h" #endif static void ssh_protocol_preinit(const char *ssh_ports[], protocol_ctx *ctx[], const char *jail_ports[], const size_t siz); static void ssh_protocol_init(protocol_ctx *ctx[], const size_t siz); static void ssh_protocol_preinit(const char *ssh_ports[], protocol_ctx *ctx[], const char *jail_ports[], const size_t siz) { for (size_t i = 0; i < siz; ++i) { ABORT_ON_FATAL( proto_init_ctx(&ctx[i], ssh_init_cb), "SSH Protocol init" ); ABORT_ON_FATAL( proto_setup(ctx[i], "127.0.0.1", ssh_ports[i], "127.0.0.1", jail_ports[i]), "SSH Protocol setup" ); ABORT_ON_FATAL( proto_validate_ctx(ctx[i]), "SSH validation" ); } } static void ssh_protocol_init(protocol_ctx *ctx[], const size_t siz) { for (size_t i = 0; i < siz; ++i) { ABORT_ON_FATAL( proto_listen(ctx[i]), "SSH Protocol listen" ); } } int main(int argc, char *argv[]) { const size_t rdr_siz = 3; const size_t proto_siz = 2; const size_t jail_siz = 2; const char *rdr_ports[rdr_siz]; const char *proto_ports[proto_siz]; const char *jail_ports[jail_siz]; redirector_ctx *rdr[rdr_siz]; protocol_ctx *ssh_proto[proto_siz]; jail_ctx *jail[jail_siz]; event_ctx *rdr_event = NULL; event_ctx *jail_event = NULL; int proc_status; pid_t daemon_pid, rdr_pid, jail_pid, child_pid; pseccomp_ctx *psc = NULL; (void) argc; (void) argv; arg0 = argv[0]; LOG_SET_FUNCS_VA(LOG_COLORED_FUNCS); #ifdef HAVE_CONFIG_H N("%s (C) 2018 Toni Uhlig (%s)", PACKAGE_STRING, PACKAGE_BUGREPORT); #endif if (geteuid() != 0) { E("%s", "I was made for root!"); exit(EXIT_FAILURE); } caps_default_filter(); pseccomp_init(&psc, 0); if (pseccomp_default_rules(psc)) FATAL("%s", "SECCOMP: adding default rules"); pseccomp_free(&psc); D("%s", "Forking into background/foreground"); daemon_pid = daemonize(1); ABORT_ON_FATAL( daemon_pid > 0, "Forking" ); if (daemon_pid == 0) { set_procname("[potd] main"); } else { FATAL("Forking (fork returned %d)", daemon_pid); } D2("Master pid: %d", getpid()); ABORT_ON_FATAL( set_master_sighandler(), "Master sighandler" ); memset(jail, 0, sizeof(jail)); jail_ports[0] = "33333"; jail_ports[1] = "33334"; for (size_t i = 0; i < jail_siz; ++i) { D("Initialising jail service on port %s", jail_ports[i]); jail_init_ctx(&jail[i], MAX_STACKSIZE); //jail[i]->newroot = strdup("/home/lns/git/busybox/sysroot"); jail[i]->newroot = strdup("/home/toni/git/busybox/_install"); ABORT_ON_FATAL( jail_setup(jail[i], "127.0.0.1", jail_ports[i]), "Jail daemon setup" ); ABORT_ON_FATAL( jail_validate_ctx(jail[i]), "Jail validation" ); } ABORT_ON_FATAL( jail_setup_event( jail, jail_siz, &jail_event ), "Jail daemon epoll setup" ); jail_pid = jail_daemonize(&jail_event, jail, jail_siz); ABORT_ON_FATAL( jail_pid < 1, "Jail daemon startup" ); memset(ssh_proto, 0, sizeof(proto_ports)); proto_ports[0] = "22222"; proto_ports[1] = "22223"; assert(SIZEOF(proto_ports) == SIZEOF(jail_ports)); ssh_protocol_preinit(proto_ports, ssh_proto, jail_ports, proto_siz); ssh_protocol_init(ssh_proto, proto_siz); memset(rdr, 0, sizeof(rdr)); rdr_ports[0] = "2222"; rdr_ports[1] = "2223"; rdr_ports[2] = "22050"; for (size_t i = 0; i < rdr_siz; ++i) { D("Initialising redirector service on port %s", rdr_ports[i]); ABORT_ON_FATAL( redirector_init_ctx(&rdr[i]), "Redirector init" ); ABORT_ON_FATAL( redirector_setup(rdr[i], NULL, rdr_ports[i], "127.0.0.1", "22222"), "Redirector setup" ); ABORT_ON_FATAL( redirector_validate_ctx(rdr[i]), "Redirector validation" ); } D2("%s", "Redirector event setup"); ABORT_ON_FATAL( redirector_setup_event( rdr, rdr_siz, &rdr_event ), "Redirector event setup" ); N("%s", "Redirector epoll mainloop"); rdr_pid = redirector_daemonize( rdr_event, rdr, rdr_siz ); ABORT_ON_FATAL( rdr_pid < 1, "Server epoll mainloop" ); while (1) { child_pid = wait(&proc_status); if (child_pid == jail_pid || child_pid == rdr_pid) { E2("%s daemon with pid %d terminated, exiting", (child_pid == jail_pid ? "Jail" : "Redirector"), (child_pid == jail_pid ? jail_pid : rdr_pid)); kill(0, SIGTERM); break; } } return 0; }