serving: protect file sending from downgrading to waiting pipelined headers
[platform/upstream/libwebsockets.git] / lib / handshake.c
1 /*
2  * libwebsockets - small server side websockets and web server implementation
3  *
4  * Copyright (C) 2010-2015 Andy Green <andy@warmcat.com>
5  *
6  *  This library is free software; you can redistribute it and/or
7  *  modify it under the terms of the GNU Lesser General Public
8  *  License as published by the Free Software Foundation:
9  *  version 2.1 of the License.
10  *
11  *  This library is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14  *  Lesser General Public License for more details.
15  *
16  *  You should have received a copy of the GNU Lesser General Public
17  *  License along with this library; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
19  *  MA  02110-1301  USA
20  */
21
22 #include "private-libwebsockets.h"
23
24 /*
25  * -04 of the protocol (actually the 80th version) has a radically different
26  * handshake.  The 04 spec gives the following idea
27  *
28  *    The handshake from the client looks as follows:
29  *
30  *      GET /chat HTTP/1.1
31  *      Host: server.example.com
32  *      Upgrade: websocket
33  *      Connection: Upgrade
34  *      Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
35  *      Sec-WebSocket-Origin: http://example.com
36  *      Sec-WebSocket-Protocol: chat, superchat
37  *      Sec-WebSocket-Version: 4
38  *
39  *  The handshake from the server looks as follows:
40  *
41  *       HTTP/1.1 101 Switching Protocols
42  *       Upgrade: websocket
43  *       Connection: Upgrade
44  *       Sec-WebSocket-Accept: me89jWimTRKTWwrS3aRrL53YZSo=
45  *       Sec-WebSocket-Nonce: AQIDBAUGBwgJCgsMDQ4PEC==
46  *       Sec-WebSocket-Protocol: chat
47  */
48
49 #ifndef min
50 #define min(a, b) ((a) < (b) ? (a) : (b))
51 #endif
52
53 /*
54  * We have to take care about parsing because the headers may be split
55  * into multiple fragments.  They may contain unknown headers with arbitrary
56  * argument lengths.  So, we parse using a single-character at a time state
57  * machine that is completely independent of packet size.
58  *
59  * Returns <0 for error or length of chars consumed from buf (up to len)
60  */
61
62 LWS_VISIBLE int
63 lws_read(struct lws *wsi, unsigned char *buf, lws_filepos_t len)
64 {
65         unsigned char *last_char, *oldbuf = buf;
66         lws_filepos_t body_chunk_len;
67         size_t n;
68
69         lwsl_debug("%s: incoming len %d  state %d\n", __func__, (int)len, wsi->state);
70
71         switch (wsi->state) {
72 #ifdef LWS_USE_HTTP2
73         case LWSS_HTTP2_AWAIT_CLIENT_PREFACE:
74         case LWSS_HTTP2_ESTABLISHED_PRE_SETTINGS:
75         case LWSS_HTTP2_ESTABLISHED:
76                 n = 0;
77                 while (n < len) {
78                         /*
79                          * we were accepting input but now we stopped doing so
80                          */
81                         if (!(wsi->rxflow_change_to & LWS_RXFLOW_ALLOW)) {
82                                 lws_rxflow_cache(wsi, buf, n, len);
83
84                                 return 1;
85                         }
86
87                         /* account for what we're using in rxflow buffer */
88                         if (wsi->rxflow_buffer)
89                                 wsi->rxflow_pos++;
90                         if (lws_http2_parser(wsi, buf[n++])) {
91                                 lwsl_debug("%s: http2_parser bailed\n", __func__);
92                                 goto bail;
93                         }
94                 }
95                 break;
96 #endif
97
98         case LWSS_HTTP_ISSUING_FILE:
99                 return 0;
100
101         case LWSS_CLIENT_HTTP_ESTABLISHED:
102                 break;
103
104         case LWSS_HTTP:
105                 wsi->hdr_parsing_completed = 0;
106                 /* fallthru */
107
108         case LWSS_HTTP_HEADERS:
109                 if (!wsi->u.hdr.ah) {
110                         lwsl_err("%s: LWSS_HTTP_HEADERS: NULL ah\n", __func__);
111                         assert(0);
112                 }
113                 lwsl_parser("issuing %d bytes to parser\n", (int)len);
114
115                 if (lws_handshake_client(wsi, &buf, (size_t)len))
116                         goto bail;
117
118                 last_char = buf;
119                 if (lws_handshake_server(wsi, &buf, (size_t)len))
120                         /* Handshake indicates this session is done. */
121                         goto bail;
122
123                 /* we might have transitioned to RAW */
124                 if (wsi->mode == LWSCM_RAW)
125                          /* we gave the read buffer to RAW handler already */
126                         goto read_ok;
127
128                 /*
129                  * It's possible that we've exhausted our data already, or
130                  * rx flow control has stopped us dealing with this early,
131                  * but lws_handshake_server doesn't update len for us.
132                  * Figure out how much was read, so that we can proceed
133                  * appropriately:
134                  */
135                 len -= (buf - last_char);
136                 lwsl_debug("%s: thinks we have used %ld\n", __func__, (long)len);
137
138                 if (!wsi->hdr_parsing_completed)
139                         /* More header content on the way */
140                         goto read_ok;
141
142                 switch (wsi->state) {
143                         case LWSS_HTTP:
144                         case LWSS_HTTP_HEADERS:
145                                 goto read_ok;
146                         case LWSS_HTTP_ISSUING_FILE:
147                                 goto read_ok;
148                         case LWSS_HTTP_BODY:
149                                 wsi->u.http.content_remain =
150                                                 wsi->u.http.content_length;
151                                 if (wsi->u.http.content_remain)
152                                         goto http_postbody;
153
154                                 /* there is no POST content */
155                                 goto postbody_completion;
156                         default:
157                                 break;
158                 }
159                 break;
160
161         case LWSS_HTTP_BODY:
162 http_postbody:
163                 while (len && wsi->u.http.content_remain) {
164                         /* Copy as much as possible, up to the limit of:
165                          * what we have in the read buffer (len)
166                          * remaining portion of the POST body (content_remain)
167                          */
168                         body_chunk_len = min(wsi->u.http.content_remain,len);
169                         wsi->u.http.content_remain -= body_chunk_len;
170                         len -= body_chunk_len;
171 #ifdef LWS_WITH_CGI
172                         if (wsi->cgi) {
173                                 struct lws_cgi_args args;
174
175                                 args.ch = LWS_STDIN;
176                                 args.stdwsi = &wsi->cgi->stdwsi[0];
177                                 args.data = buf;
178                                 args.len = body_chunk_len;
179
180                                 /* returns how much used */
181                                 n = user_callback_handle_rxflow(
182                                         wsi->protocol->callback,
183                                         wsi, LWS_CALLBACK_CGI_STDIN_DATA,
184                                         wsi->user_space,
185                                         (void *)&args, 0);
186                                 if ((int)n < 0)
187                                         goto bail;
188                         } else {
189 #endif
190                                 n = wsi->protocol->callback(wsi,
191                                         LWS_CALLBACK_HTTP_BODY, wsi->user_space,
192                                         buf, (size_t)body_chunk_len);
193                                 if (n)
194                                         goto bail;
195                                 n = (size_t)body_chunk_len;
196 #ifdef LWS_WITH_CGI
197                         }
198 #endif
199                         buf += n;
200
201                         if (wsi->u.http.content_remain)  {
202                                 lws_set_timeout(wsi, PENDING_TIMEOUT_HTTP_CONTENT,
203                                                 wsi->context->timeout_secs);
204                                 break;
205                         }
206                         /* he sent all the content in time */
207 postbody_completion:
208 #ifdef LWS_WITH_CGI
209                         /* if we're running a cgi, we can't let him off the hook just because he sent his POST data */
210                         if (wsi->cgi)
211                                 lws_set_timeout(wsi, PENDING_TIMEOUT_CGI, wsi->context->timeout_secs);
212                         else
213 #endif
214                         lws_set_timeout(wsi, NO_PENDING_TIMEOUT, 0);
215 #ifdef LWS_WITH_CGI
216                         if (!wsi->cgi)
217 #endif
218                         {
219                                 n = wsi->protocol->callback(wsi,
220                                         LWS_CALLBACK_HTTP_BODY_COMPLETION,
221                                         wsi->user_space, NULL, 0);
222                                 if (n)
223                                         goto bail;
224                         }
225
226                         break;
227                 }
228                 break;
229
230         case LWSS_ESTABLISHED:
231         case LWSS_AWAITING_CLOSE_ACK:
232         case LWSS_SHUTDOWN:
233                 if (lws_handshake_client(wsi, &buf, (size_t)len))
234                         goto bail;
235                 switch (wsi->mode) {
236                 case LWSCM_WS_SERVING:
237
238                         if (lws_interpret_incoming_packet(wsi, &buf, (size_t)len) < 0) {
239                                 lwsl_info("interpret_incoming_packet has bailed\n");
240                                 goto bail;
241                         }
242                         break;
243                 }
244                 break;
245         default:
246                 lwsl_err("%s: Unhandled state %d\n", __func__, wsi->state);
247                 break;
248         }
249
250 read_ok:
251         /* Nothing more to do for now */
252         lwsl_info("%s: read_ok, used %ld\n", __func__, (long)(buf - oldbuf));
253
254         return buf - oldbuf;
255
256 bail:
257         //lwsl_notice("closing connection at lws_read bail:\n");
258         lws_close_free_wsi(wsi, LWS_CLOSE_STATUS_NOSTATUS);
259
260         return -1;
261 }