act on fatal parse problems
[profile/ivi/libwebsockets.git] / lib / handshake.c
1 /*
2  * libwebsockets - small server side websockets and web server implementation
3  *
4  * Copyright (C) 2010-2013 Andy Green <andy@warmcat.com>
5  *
6  *  This library is free software; you can redistribute it and/or
7  *  modify it under the terms of the GNU Lesser General Public
8  *  License as published by the Free Software Foundation:
9  *  version 2.1 of the License.
10  *
11  *  This library is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14  *  Lesser General Public License for more details.
15  *
16  *  You should have received a copy of the GNU Lesser General Public
17  *  License along with this library; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
19  *  MA  02110-1301  USA
20  */
21
22 #include "private-libwebsockets.h"
23
24 /*
25  * -04 of the protocol (actually the 80th version) has a radically different
26  * handshake.  The 04 spec gives the following idea
27  *
28  *    The handshake from the client looks as follows:
29  *
30  *      GET /chat HTTP/1.1
31  *      Host: server.example.com
32  *      Upgrade: websocket
33  *      Connection: Upgrade
34  *      Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
35  *      Sec-WebSocket-Origin: http://example.com
36  *      Sec-WebSocket-Protocol: chat, superchat
37  *      Sec-WebSocket-Version: 4
38  *
39  *  The handshake from the server looks as follows:
40  *
41  *       HTTP/1.1 101 Switching Protocols
42  *       Upgrade: websocket
43  *       Connection: Upgrade
44  *       Sec-WebSocket-Accept: me89jWimTRKTWwrS3aRrL53YZSo=
45  *       Sec-WebSocket-Nonce: AQIDBAUGBwgJCgsMDQ4PEC==
46  *       Sec-WebSocket-Protocol: chat
47  */
48
49 /*
50  * We have to take care about parsing because the headers may be split
51  * into multiple fragments.  They may contain unknown headers with arbitrary
52  * argument lengths.  So, we parse using a single-character at a time state
53  * machine that is completely independent of packet size.
54  */
55
56 #ifndef LWS_NO_SERVER
57 extern int handshake_0405(struct libwebsocket_context *context, struct libwebsocket *wsi);
58 #endif
59
60 int
61 libwebsocket_read(struct libwebsocket_context *context,
62                      struct libwebsocket *wsi, unsigned char * buf, size_t len)
63 {
64         size_t n;
65
66         switch (wsi->state) {
67         case WSI_STATE_HTTP_ISSUING_FILE:
68         case WSI_STATE_HTTP:
69                 wsi->state = WSI_STATE_HTTP_HEADERS;
70                 wsi->u.hdr.parser_state = WSI_TOKEN_NAME_PART;
71                 wsi->u.hdr.lextable_pos = 0;
72                 /* fallthru */
73         case WSI_STATE_HTTP_HEADERS:
74
75                 lwsl_parser("issuing %d bytes to parser\n", (int)len);
76 #ifdef _DEBUG
77                 //fwrite(buf, 1, len, stderr);
78 #endif
79
80 #ifndef LWS_NO_CLIENT
81
82 //              lwsl_info("mode=%d\n", wsi->mode);
83
84                 switch (wsi->mode) {
85                 case LWS_CONNMODE_WS_CLIENT_WAITING_PROXY_REPLY:
86                 case LWS_CONNMODE_WS_CLIENT_ISSUE_HANDSHAKE:
87                 case LWS_CONNMODE_WS_CLIENT_WAITING_SERVER_REPLY:
88                 case LWS_CONNMODE_WS_CLIENT_WAITING_EXTENSION_CONNECT:
89                 case LWS_CONNMODE_WS_CLIENT:
90                         for (n = 0; n < len; n++)
91                                 if (libwebsocket_client_rx_sm(wsi, *buf++)) {
92                                         lwsl_info("libwebsocket_client_rx_sm failed\n");
93                                         goto bail;
94                                 }
95                         return 0;
96                 default:
97                         break;
98                 }
99 #endif
100 #ifndef LWS_NO_SERVER
101                 /* LWS_CONNMODE_WS_SERVING */
102
103                 for (n = 0; n < len; n++)
104                         if (libwebsocket_parse(wsi, *buf++)) {
105                                 lwsl_info("libwebsocket_parse failed\n");
106                                 goto bail;
107                         }
108
109                 if (wsi->u.hdr.parser_state != WSI_PARSING_COMPLETE)
110                         break;
111
112                 lwsl_parser("libwebsocket_parse sees parsing complete\n");
113
114                 /* is this websocket protocol or normal http 1.0? */
115
116                 if (!wsi->utf8_token[WSI_TOKEN_UPGRADE].token_len ||
117                              !wsi->utf8_token[WSI_TOKEN_CONNECTION].token_len) {
118                         wsi->state = WSI_STATE_HTTP;
119                         if (wsi->protocol->callback)
120                                 if (wsi->protocol->callback(context, wsi,
121                                                 LWS_CALLBACK_HTTP,
122                                                 wsi->user_space,
123                                                 wsi->utf8_token[WSI_TOKEN_GET_URI].token,
124                                                 wsi->utf8_token[WSI_TOKEN_GET_URI].token_len)) {
125                                         lwsl_info("LWS_CALLBACK_HTTP wanted to close\n");
126                                         goto bail;
127                                 }
128                         return 0;
129                 }
130
131                 if (!wsi->protocol)
132                         lwsl_err("NULL protocol at libwebsocket_read\n");
133
134
135                 /*
136                  * It's websocket
137                  *
138                  * Make sure user side is happy about protocol
139                  */
140
141                 while (wsi->protocol->callback) {
142
143                         if (wsi->utf8_token[WSI_TOKEN_PROTOCOL].token == NULL) {
144                                 if (wsi->protocol->name == NULL)
145                                         break;
146                         } else
147                                 if (wsi->protocol->name && strcmp(
148                                      wsi->utf8_token[WSI_TOKEN_PROTOCOL].token,
149                                                       wsi->protocol->name) == 0)
150                                         break;
151
152                         wsi->protocol++;
153                 }
154
155                 /* we didn't find a protocol he wanted? */
156
157                 if (wsi->protocol->callback == NULL) {
158                         if (wsi->utf8_token[WSI_TOKEN_PROTOCOL].token == NULL) {
159                                 lwsl_info("[no protocol] "
160                                         "mapped to protocol 0 handler\n");
161                                 wsi->protocol = &context->protocols[0];
162                         } else {
163                                 lwsl_err("Requested protocol %s "
164                                                 "not supported\n",
165                                      wsi->utf8_token[WSI_TOKEN_PROTOCOL].token);
166                                 goto bail;
167                         }
168                 }
169
170                 /*
171                  * find out which spec version the client is using
172                  * if this header is not given, we default to 00 (aka 76)
173                  */
174
175                 if (wsi->utf8_token[WSI_TOKEN_VERSION].token_len)
176                         wsi->ietf_spec_revision =
177                                  atoi(wsi->utf8_token[WSI_TOKEN_VERSION].token);
178
179                 /*
180                  * Give the user code a chance to study the request and
181                  * have the opportunity to deny it
182                  */
183
184                 if ((wsi->protocol->callback)(wsi->protocol->owning_server, wsi,
185                                 LWS_CALLBACK_FILTER_PROTOCOL_CONNECTION,
186                                                 &wsi->utf8_token[0], NULL, 0)) {
187                         lwsl_warn("User code denied connection\n");
188                         goto bail;
189                 }
190
191
192                 /*
193                  * Perform the handshake according to the protocol version the
194                  * client announced
195                  */
196
197                 switch (wsi->ietf_spec_revision) {
198                 case 13:
199                         lwsl_parser("libwebsocket_parse calling handshake_04\n");
200                         if (handshake_0405(context, wsi)) {
201                                 lwsl_info("handshake_0405 xor 05 has failed the connection\n");
202                                 goto bail;
203                         }
204                         break;
205
206                 default:
207                         lwsl_warn("Unknown client spec version %d\n",
208                                                        wsi->ietf_spec_revision);
209                         goto bail;
210                 }
211
212                 wsi->mode = LWS_CONNMODE_WS_SERVING;
213
214                 /* union transition */
215                 memset(&wsi->u, 0, sizeof wsi->u);
216
217                 lwsl_parser("accepted v%02d connection\n",
218                                                        wsi->ietf_spec_revision);
219 #endif
220                 break;
221
222         case WSI_STATE_AWAITING_CLOSE_ACK:
223         case WSI_STATE_ESTABLISHED:
224 #ifndef LWS_NO_CLIENT
225                 switch (wsi->mode) {
226                 case LWS_CONNMODE_WS_CLIENT:
227                         for (n = 0; n < len; n++)
228                                 if (libwebsocket_client_rx_sm(wsi, *buf++) < 0) {
229                                         lwsl_info("client rx has bailed\n");
230                                         goto bail;
231                                 }
232
233                         return 0;
234                 default:
235                         break;
236                 }
237 #endif
238 #ifndef LWS_NO_SERVER
239                 /* LWS_CONNMODE_WS_SERVING */
240
241                 if (libwebsocket_interpret_incoming_packet(wsi, buf, len) < 0) {
242                         lwsl_info("interpret_incoming_packet has bailed\n");
243                         goto bail;
244                 }
245 #endif
246                 break;
247         default:
248                 lwsl_err("libwebsocket_read: Unhandled state\n");
249                 break;
250         }
251
252         return 0;
253
254 bail:
255         lwsl_info("closing connection at libwebsocket_read bail:\n");
256         libwebsocket_close_and_free_session(context, wsi,
257                                                      LWS_CLOSE_STATUS_NOSTATUS);
258
259         return -1;
260 }