#!/usr/bin/perl
# The LearningOnline Network
# lond "LON Daemon" Server (port "LOND" 5663)
# 5/26/99,6/4,6/10,6/11,6/14,6/15,6/26,6/28,6/30,
# 7/8,7/9,7/10,7/12,7/17,7/19,9/21,
# 10/7,10/8,10/9,10/11,10/13,10/15 Gerd Kortemeyer
# based on "Perl Cookbook" ISBN 1-56592-243-3
# preforker - server who forks first
# runs as a daemon
# HUPs
# uses IDEA encryption
use IO::Socket;
use IO::File;
use Apache::File;
use Symbol;
use POSIX;
use Crypt::IDEA;
use LWP::UserAgent();
# ------------------------------------ Read httpd access.conf and get variables
open (CONFIG,"/etc/httpd/conf/access.conf") || die "Can't read access.conf";
while ($configline=<CONFIG>) {
if ($configline =~ /PerlSetVar/) {
my ($dummy,$varname,$varvalue)=split(/\s+/,$configline);
$perlvar{$varname}=$varvalue;
}
}
close(CONFIG);
$PREFORK=4; # number of children to maintain, at least four spare
# ------------------------------------------------------------- Read hosts file
open (CONFIG,"$perlvar{'lonTabDir'}/hosts.tab") || die "Can't read host file";
while ($configline=<CONFIG>) {
my ($id,$domain,$role,$name,$ip)=split(/:/,$configline);
chomp($ip);
$hostid{$ip}=$id;
if ($id eq $perlvar{'lonHostID'}) { $thisserver=$name; }
$PREFORK++;
}
close(CONFIG);
# establish SERVER socket, bind and listen.
$server = IO::Socket::INET->new(LocalPort => $perlvar{'londPort'},
Type => SOCK_STREAM,
Proto => 'tcp',
Reuse => 1,
Listen => 10 )
or die "making socket: $@\n";
# --------------------------------------------------------- Do global variables
# global variables
$MAX_CLIENTS_PER_CHILD = 5; # number of clients each child should
# process
%children = (); # keys are current child process IDs
$children = 0; # current number of children
sub REAPER { # takes care of dead children
$SIG{CHLD} = \&REAPER;
my $pid = wait;
$children --;
&logthis("Child $pid died");
delete $children{$pid};
}
sub HUNTSMAN { # signal handler for SIGINT
local($SIG{CHLD}) = 'IGNORE'; # we're going to kill our children
kill 'INT' => keys %children;
my $execdir=$perlvar{'lonDaemons'};
unlink("$execdir/logs/lond.pid");
&logthis("Shutting down");
exit; # clean up with dignity
}
sub HUPSMAN { # signal handler for SIGHUP
local($SIG{CHLD}) = 'IGNORE'; # we're going to kill our children
kill 'INT' => keys %children;
close($server); # free up socket
&logthis("Restarting");
my $execdir=$perlvar{'lonDaemons'};
exec("$execdir/lond"); # here we go again
}
# --------------------------------------------------------------------- Logging
sub logthis {
my $message=shift;
my $execdir=$perlvar{'lonDaemons'};
my $fh=IO::File->new(">>$execdir/logs/lond.log");
my $now=time;
my $local=localtime($now);
print $fh "$local ($$): $message\n";
}
# ----------------------------------------------------------- Send USR1 to lonc
sub reconlonc {
my $peerfile=shift;
&logthis("Trying to reconnect for $peerfile");
my $loncfile="$perlvar{'lonDaemons'}/logs/lonc.pid";
if (my $fh=IO::File->new("$loncfile")) {
my $loncpid=<$fh>;
chomp($loncpid);
if (kill 0 => $loncpid) {
&logthis("lonc at pid $loncpid responding, sending USR1");
kill USR1 => $loncpid;
sleep 1;
if (-e "$peerfile") { return; }
&logthis("$peerfile still not there, give it another try");
sleep 5;
if (-e "$peerfile") { return; }
&logthis("$peerfile still not there, giving up");
} else {
&logthis("lonc at pid $loncpid not responding, giving up");
}
} else {
&logthis('lonc not running, giving up');
}
}
# -------------------------------------------------- Non-critical communication
sub subreply {
my ($cmd,$server)=@_;
my $peerfile="$perlvar{'lonSockDir'}/$server";
my $sclient=IO::Socket::UNIX->new(Peer =>"$peerfile",
Type => SOCK_STREAM,
Timeout => 10)
or return "con_lost";
print $sclient "$cmd\n";
my $answer=<$sclient>;
chomp($answer);
if (!$answer) { $answer="con_lost"; }
return $answer;
}
sub reply {
my ($cmd,$server)=@_;
my $answer;
if ($server ne $perlvar{'lonHostID'}) {
$answer=subreply($cmd,$server);
if ($answer eq 'con_lost') {
$answer=subreply("ping",$server);
if ($answer ne $server) {
&reconlonc("$perlvar{'lonSockDir'}/$server");
}
$answer=subreply($cmd,$server);
}
} else {
$answer='self_reply';
}
return $answer;
}
# -------------------------------------------- Return path to profile directory
sub propath {
my ($udom,$uname)=@_;
$udom=~s/\W//g;
$uname=~s/\W//g;
my $subdir=$uname;
$subdir =~ s/(.)(.)(.).*/$1\/$2\/$3/;
my $proname="$perlvar{'lonUsersDir'}/$udom/$subdir/$uname";
return $proname;
}
# --------------------------------------- Is this the home server of an author?
sub ishome {
my $author=shift;
$author=~s/\/home\/httpd\/html\/res\/([^\/]*)\/([^\/]*).*/$1\/$2/;
my ($udom,$uname)=split(/\//,$author);
my $proname=propath($udom,$uname);
if (-e $proname) {
return 'owner';
} else {
return 'not_owner';
}
}
# ======================================================= Continue main program
# ---------------------------------------------------- Fork once and dissociate
$fpid=fork;
exit if $fpid;
die "Couldn't fork: $!" unless defined ($fpid);
POSIX::setsid() or die "Can't start new session: $!";
# ------------------------------------------------------- Write our PID on disk
$execdir=$perlvar{'lonDaemons'};
open (PIDSAVE,">$execdir/logs/lond.pid");
print PIDSAVE "$$\n";
close(PIDSAVE);
&logthis("Starting");
# ------------------------------------------------------- Now we are on our own
# Fork off our children.
for (1 .. $PREFORK) {
make_new_child();
}
# ----------------------------------------------------- Install signal handlers
$SIG{CHLD} = \&REAPER;
$SIG{INT} = $SIG{TERM} = \&HUNTSMAN;
$SIG{HUP} = \&HUPSMAN;
# And maintain the population.
while (1) {
sleep; # wait for a signal (i.e., child's death)
for ($i = $children; $i < $PREFORK; $i++) {
make_new_child(); # top up the child pool
}
}
sub make_new_child {
my $pid;
my $cipher;
my $sigset;
&logthis("Attempting to start child");
# block signal for fork
$sigset = POSIX::SigSet->new(SIGINT);
sigprocmask(SIG_BLOCK, $sigset)
or die "Can't block SIGINT for fork: $!\n";
die "fork: $!" unless defined ($pid = fork);
if ($pid) {
# Parent records the child's birth and returns.
sigprocmask(SIG_UNBLOCK, $sigset)
or die "Can't unblock SIGINT for fork: $!\n";
$children{$pid} = 1;
$children++;
return;
} else {
# Child can *not* return from this subroutine.
$SIG{INT} = 'DEFAULT'; # make SIGINT kill us as it did before
# unblock signals
sigprocmask(SIG_UNBLOCK, $sigset)
or die "Can't unblock SIGINT for fork: $!\n";
# handle connections until we've reached $MAX_CLIENTS_PER_CHILD
for ($i=0; $i < $MAX_CLIENTS_PER_CHILD; $i++) {
$client = $server->accept() or last;
# =============================================================================
# do something with the connection
# -----------------------------------------------------------------------------
# see if we know client and check for spoof IP by challenge
my $caller=getpeername($client);
my ($port,$iaddr)=unpack_sockaddr_in($caller);
my $clientip=inet_ntoa($iaddr);
my $clientrec=($hostid{$clientip} ne undef);
&logthis("Connect from $clientip ($hostid{$clientip})");
my $clientok;
if ($clientrec) {
my $remotereq=<$client>;
$remotereq=~s/\W//g;
if ($remotereq eq 'init') {
my $challenge="$$".time;
print $client "$challenge\n";
$remotereq=<$client>;
$remotereq=~s/\W//g;
if ($challenge eq $remotereq) {
$clientok=1;
print $client "ok\n";
} else {
&logthis("$clientip did not reply challenge");
}
} else {
&logthis("$clientip failed to initialize: >$remotereq<");
}
} else {
&logthis("Unknown client $clientip");
}
if ($clientok) {
# ---------------- New known client connecting, could mean machine online again
&reconlonc("$perlvar{'lonSockDir'}/$hostid{$clientip}");
# ------------------------------------------------------------ Process requests
while (my $userinput=<$client>) {
chomp($userinput);
my $wasenc=0;
# ------------------------------------------------------------ See if encrypted
if ($userinput =~ /^enc/) {
if ($cipher) {
my ($cmd,$cmdlength,$encinput)=split(/:/,$userinput);
$userinput='';
for (my $encidx=0;$encidx<length($encinput);$encidx+=16) {
$userinput.=
$cipher->decrypt(
pack("H16",substr($encinput,$encidx,16))
);
}
$userinput=substr($userinput,0,$cmdlength);
$wasenc=1;
}
}
# ------------------------------------------------------------- Normal commands
# ------------------------------------------------------------------------ ping
if ($userinput =~ /^ping/) {
print $client "$perlvar{'lonHostID'}\n";
# ------------------------------------------------------------------------ pong
} elsif ($userinput =~ /^pong/) {
$reply=reply("ping",$hostid{$clientip});
print $client "$perlvar{'lonHostID'}:$reply\n";
# ------------------------------------------------------------------------ ekey
} elsif ($userinput =~ /^ekey/) {
my $buildkey=time.$$.int(rand 100000);
$buildkey=~tr/1-6/A-F/;
$buildkey=int(rand 100000).$buildkey.int(rand 100000);
my $key=$perlvar{'lonHostID'}.$hostid{$clientip};
$key=~tr/a-z/A-Z/;
$key=~tr/G-P/0-9/;
$key=~tr/Q-Z/0-9/;
$key=$key.$buildkey.$key.$buildkey.$key.$buildkey;
$key=substr($key,0,32);
my $cipherkey=pack("H32",$key);
$cipher=new IDEA $cipherkey;
print $client "$buildkey\n";
# ------------------------------------------------------------------------ load
} elsif ($userinput =~ /^load/) {
my $loadavg;
{
my $loadfile=IO::File->new('/proc/loadavg');
$loadavg=<$loadfile>;
}
$loadavg =~ s/\s.*//g;
my $loadpercent=100*$loadavg/$perlvar{'lonLoadLim'};
print $client "$loadpercent\n";
# ------------------------------------------------------------------------ auth
} elsif ($userinput =~ /^auth/) {
if ($wasenc==1) {
my ($cmd,$udom,$uname,$upass)=split(/:/,$userinput);
chomp($upass);
my $proname=propath($udom,$uname);
my $passfilename="$proname/passwd";
if (-e $passfilename) {
my $pf = IO::File->new($passfilename);
my $realpasswd=<$pf>;
chomp($realpasswd);
my ($howpwd,$contentpwd)=split(/:/,$realpasswd);
my $pwdcorrect=0;
if ($howpwd eq 'internal') {
$pwdcorrect=
(crypt($upass,$contentpwd) eq $contentpwd);
} elsif ($howpwd eq 'unix') {
$contentpwd=(getpwnam($uname))[1];
$pwdcorrect=
(crypt($upass,$contentpwd) eq $contentpwd);
}
if ($pwdcorrect) {
print $client "authorized\n";
} else {
print $client "non_authorized\n";
}
} else {
print $client "unknown_user\n";
}
} else {
print $client "refused\n";
}
# ---------------------------------------------------------------------- passwd
} elsif ($userinput =~ /^passwd/) {
if ($wasenc==1) {
my
($cmd,$udom,$uname,$upass,$npass)=split(/:/,$userinput);
chomp($npass);
my $proname=propath($udom,$uname);
my $passfilename="$proname/passwd";
if (-e $passfilename) {
my $realpasswd;
{ my $pf = IO::File->new($passfilename);
$realpasswd=<$pf>; }
chomp($realpasswd);
my ($howpwd,$contentpwd)=split(/:/,$realpasswd);
if ($howpwd eq 'internal') {
if (crypt($upass,$contentpwd) eq $contentpwd) {
my $salt=time;
$salt=substr($salt,6,2);
my $ncpass=crypt($npass,$salt);
{ my $pf = IO::File->new(">$passfilename");
print $pf "internal:$ncpass\n";; }
print $client "ok\n";
} else {
print $client "non_authorized\n";
}
} else {
print $client "auth_mode_error\n";
}
} else {
print $client "unknown_user\n";
}
} else {
print $client "refused\n";
}
# ------------------------------------------------------------------------ home
} elsif ($userinput =~ /^home/) {
my ($cmd,$udom,$uname)=split(/:/,$userinput);
chomp($uname);
my $proname=propath($udom,$uname);
if (-e $proname) {
print $client "found\n";
} else {
print $client "not_found\n";
}
# ---------------------------------------------------------------------- update
} elsif ($userinput =~ /^update/) {
my ($cmd,$fname)=split(/:/,$userinput);
my $ownership=ishome($fname);
if ($ownership eq 'not_owner') {
if (-e $fname) {
my ($dev,$ino,$mode,$nlink,
$uid,$gid,$rdev,$size,
$atime,$mtime,$ctime,
$blksize,$blocks)=stat($fname);
$now=time;
$since=$now-$atime;
if ($since>$perlvar{'lonExpire'}) {
$reply=
reply("unsub:$fname","$hostid{$clientip}");
unlink("$fname");
} else {
my $transname="$fname.in.transfer";
my $remoteurl=
reply("sub:$fname","$hostid{$clientip}");
my $response;
{
my $ua=new LWP::UserAgent;
my $request=new HTTP::Request('GET',"$remoteurl");
$response=$ua->request($request,$transname);
}
if ($response->is_error()) {
unline($transname);
my $message=$response->status_line;
&logthis(
"LWP GET: $message for $fname ($remoteurl)");
} else {
rename($transname,$fname);
}
}
print $client "ok\n";
} else {
print $client "not_found\n";
}
} else {
print $client "rejected\n";
}
# ----------------------------------------------------------------- unsubscribe
} elsif ($userinput =~ /^unsub/) {
my ($cmd,$fname)=split(/:/,$userinput);
if (-e $fname) {
if (unlink("$fname.$hostid{$clientip}")) {
print $client "ok\n";
} else {
print $client "not_subscribed\n";
}
} else {
print $client "not_found\n";
}
# ------------------------------------------------------------------- subscribe
} elsif ($userinput =~ /^sub/) {
my ($cmd,$fname)=split(/:/,$userinput);
my $ownership=ishome($fname);
if ($ownership eq 'owner') {
if (-e $fname) {
$now=time;
{
my $sh=IO::File->new(">$fname.$hostid{$clientip}");
print $sh "$clientip:$now\n";
}
$fname=~s/\/home\/httpd\/html\/res/raw/;
$fname="http://$thisserver/".$fname;
print $client "$fname\n";
} else {
print $client "not_found\n";
}
} else {
print $client "rejected\n";
}
# ------------------------------------------------------------------------- put
} elsif ($userinput =~ /^put/) {
my ($cmd,$udom,$uname,$namespace,$what)
=split(/:/,$userinput);
$namespace=~s/\W//g;
chomp($what);
my $proname=propath($udom,$uname);
my $now=time;
{
my $hfh;
if (
$hfh=IO::File->new(">>$proname/$namespace.hist")
) { print $hfh "P:$now:$what\n"; }
}
my @pairs=split(/\&/,$what);
if (dbmopen(%hash,"$proname/$namespace.db",0644)) {
foreach $pair (@pairs) {
($key,$value)=split(/=/,$pair);
$hash{$key}=$value;
}
if (dbmclose(%hash)) {
print $client "ok\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ------------------------------------------------------------------------- get
} elsif ($userinput =~ /^get/) {
my ($cmd,$udom,$uname,$namespace,$what)
=split(/:/,$userinput);
$namespace=~s/\W//g;
chomp($what);
my @queries=split(/\&/,$what);
my $proname=propath($udom,$uname);
my $qresult='';
if (dbmopen(%hash,"$proname/$namespace.db",0644)) {
for ($i=0;$i<=$#queries;$i++) {
$qresult.="$hash{$queries[$i]}&";
}
if (dbmclose(%hash)) {
$qresult=~s/\&$//;
print $client "$qresult\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ------------------------------------------------------------------------ eget
} elsif ($userinput =~ /^eget/) {
my ($cmd,$udom,$uname,$namespace,$what)
=split(/:/,$userinput);
$namespace=~s/\W//g;
chomp($what);
my @queries=split(/\&/,$what);
my $proname=propath($udom,$uname);
my $qresult='';
if (dbmopen(%hash,"$proname/$namespace.db",0644)) {
for ($i=0;$i<=$#queries;$i++) {
$qresult.="$hash{$queries[$i]}&";
}
if (dbmclose(%hash)) {
$qresult=~s/\&$//;
if ($cipher) {
my $cmdlength=length($qresult);
$qresult.=" ";
my $encqresult='';
for
(my $encidx=0;$encidx<=$cmdlength;$encidx+=8) {
$encqresult.=
unpack("H16",
$cipher->encrypt(substr($qresult,$encidx,8)));
}
print $client "enc:$cmdlength:$encqresult\n";
} else {
print $client "error:no_key\n";
}
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ------------------------------------------------------------------------- del
} elsif ($userinput =~ /^del/) {
my ($cmd,$udom,$uname,$namespace,$what)
=split(/:/,$userinput);
$namespace=~s/\W//g;
chomp($what);
my $proname=propath($udom,$uname);
my $now=time;
{
my $hfh;
if (
$hfh=IO::File->new(">>$proname/$namespace.hist")
) { print $hfh "D:$now:$what\n"; }
}
my @keys=split(/\&/,$what);
if (dbmopen(%hash,"$proname/$namespace.db",0644)) {
foreach $key (@keys) {
delete($hash{$key});
}
if (dbmclose(%hash)) {
print $client "ok\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ------------------------------------------------------------------------ keys
} elsif ($userinput =~ /^keys/) {
my ($cmd,$udom,$uname,$namespace)
=split(/:/,$userinput);
$namespace=~s/\W//g;
chomp($namespace);
my $proname=propath($udom,$uname);
my $qresult='';
if (dbmopen(%hash,"$proname/$namespace.db",0644)) {
foreach $key (keys %hash) {
$qresult.="$key&";
}
if (dbmclose(%hash)) {
$qresult=~s/\&$//;
print $client "$qresult\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ------------------------------------------------------------------------ dump
} elsif ($userinput =~ /^dump/) {
my ($cmd,$udom,$uname,$namespace)
=split(/:/,$userinput);
$namespace=~s/\W//g;
chomp($namespace);
my $proname=propath($udom,$uname);
my $qresult='';
if (dbmopen(%hash,"$proname/$namespace.db",0644)) {
foreach $key (keys %hash) {
$qresult.="$key=$hash{$key}&";
}
if (dbmclose(%hash)) {
$qresult=~s/\&$//;
print $client "$qresult\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ----------------------------------------------------------------------- idput
} elsif ($userinput =~ /^idput/) {
my ($cmd,$udom,$what)=split(/:/,$userinput);
chomp($what);
$udom=~s/\W//g;
my $proname="$perlvar{'lonUsersDir'}/$udom/ids";
my $now=time;
{
my $hfh;
if (
$hfh=IO::File->new(">>$proname.hist")
) { print $hfh "P:$now:$what\n"; }
}
my @pairs=split(/\&/,$what);
if (dbmopen(%hash,"$proname.db",0644)) {
foreach $pair (@pairs) {
($key,$value)=split(/=/,$pair);
$hash{$key}=$value;
}
if (dbmclose(%hash)) {
print $client "ok\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ----------------------------------------------------------------------- idget
} elsif ($userinput =~ /^idget/) {
my ($cmd,$udom,$what)=split(/:/,$userinput);
chomp($what);
$udom=~s/\W//g;
my $proname="$perlvar{'lonUsersDir'}/$udom/ids";
my @queries=split(/\&/,$what);
my $qresult='';
if (dbmopen(%hash,"$proname.db",0644)) {
for ($i=0;$i<=$#queries;$i++) {
$qresult.="$hash{$queries[$i]}&";
}
if (dbmclose(%hash)) {
$qresult=~s/\&$//;
print $client "$qresult\n";
} else {
print $client "error:$!\n";
}
} else {
print $client "error:$!\n";
}
# ------------------------------------------------------------- unknown command
} else {
# unknown command
print $client "unknown_cmd\n";
}
# ------------------------------------------------------ client unknown, refuse
}
} else {
print $client "refused\n";
&logthis("Rejected client $clientip, closing connection");
}
&logthis("Disconnect from $clientip ($hostid{$clientip})");
# =============================================================================
}
# tidy up gracefully and finish
# this exit is VERY important, otherwise the child will become
# a producer of more and more children, forking yourself into
# process death.
exit;
}
}
FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>