Compare commits

..

No commits in common. "5af6147a4116e49398b2a0a9129943930925f24f" and "46d09485c6867890a5a21443c69a516e307c24d7" have entirely different histories.

20 changed files with 12 additions and 200 deletions

View File

@ -27,7 +27,7 @@ jobs:
if: ${{ startsWith(matrix.target, 'ubuntu') }}
run: sudo apt-get update && sudo apt-get install -y libssl-dev libpam-dev libpcre2-dev
- name: make
run: make -f Makefile.Linux MAILPROXY=true FTP=true
run: make -f Makefile.Linux
- name: regression tests
run: python3 tests/run.py
- name: mkdir

View File

@ -70,8 +70,6 @@ option(3PROXY_USE_NETFILTER "Enable Linux netfilter support (Linux only)" ON)
option(3PROXY_USE_TRANSPARENT "Build transparent proxying support (Linux and BSD only)" ON)
option(3PROXY_USE_UNIX_SOCKETS "Enable Unix domain socket support (Unix only)" ON)
option(3PROXY_USE_HTTPSRV "Build the HTTP server and the admin interface on top of it" ON)
option(3PROXY_USE_MAILPROXY "Build the pop3p, imapp and smtpp proxies" OFF)
option(3PROXY_USE_FTP "Build FTP support: the ftppr service and ftp:// in the HTTP proxy" OFF)
if(NOT WIN32 AND NOT APPLE)
option(3PROXY_STATIC_LINK "Statically link libraries using -Wl,-Bstatic (Linux/Unix only)" OFF)
@ -85,13 +83,10 @@ set(3PROXY_BINARY_PREFIX "3proxy_" CACHE STRING "Prefix for standalone module an
option(3PROXY_BUILD_NONE "Do not build standalone binaries" OFF)
option(3PROXY_BUILD_PROXY "Build standalone proxy binary" ON)
option(3PROXY_BUILD_SOCKS "Build standalone socks binary" ON)
# The mail proxies and FTP are asked for rather than assumed: without them
# pop3p, imapp and smtpp are the STARTTLS proxy under those names, and ftp
# is not spoken at all. A standalone binary needs the support it is made of.
option(3PROXY_BUILD_POP3P "Build standalone pop3p binary" OFF)
option(3PROXY_BUILD_IMAPP "Build standalone imapp binary" OFF)
option(3PROXY_BUILD_SMTPP "Build standalone smtpp binary" OFF)
option(3PROXY_BUILD_FTPPR "Build standalone ftppr binary" OFF)
option(3PROXY_BUILD_POP3P "Build standalone pop3p binary" ON)
option(3PROXY_BUILD_IMAPP "Build standalone imapp binary" ON)
option(3PROXY_BUILD_SMTPP "Build standalone smtpp binary" ON)
option(3PROXY_BUILD_FTPPR "Build standalone ftppr binary" ON)
option(3PROXY_BUILD_TCPPM "Build standalone tcppm binary" ON)
option(3PROXY_BUILD_UDPPM "Build standalone udppm binary" ON)
option(3PROXY_BUILD_TLSPR "Build standalone tlspr binary" ON)
@ -255,14 +250,6 @@ else()
)
endif()
if(3PROXY_USE_MAILPROXY)
add_compile_definitions(WITH_POP3P WITH_IMAPP WITH_SMTPP)
endif()
if(3PROXY_USE_FTP)
add_compile_definitions(WITH_FTP)
endif()
if(3PROXY_USE_HTTPSRV)
add_compile_definitions(WITH_HTTPSRV)
endif()
@ -697,15 +684,6 @@ foreach(PROXY_NAME proxy socks pop3p imapp smtpp ftppr tcppm udppm tlspr)
continue()
endif()
# A binary of nothing: without the support built, these files hold the
# stand-in the main binary uses and no service of their own.
if(NOT 3PROXY_USE_MAILPROXY AND PROXY_NAME MATCHES "^(pop3p|imapp|smtpp)$")
continue()
endif()
if(NOT 3PROXY_USE_FTP AND PROXY_NAME STREQUAL "ftppr")
continue()
endif()
if(PROXY_NAME STREQUAL "ftppr" OR PROXY_NAME STREQUAL "proxy")
# ftppr and proxy use ftp_obj
add_executable(${PROXY_NAME}

View File

@ -24,16 +24,6 @@ LDFLAGS += $(EXTRA_LDFLAGS)
# -lpthreads may be reuiured on some platforms instead of -pthreads
# -ldl or -lld may be required for some platforms
DCFLAGS ?= -fPIC
MAILPROXY ?= false
ifeq ($(MAILPROXY),true)
CFLAGS += -DWITH_POP3P -DWITH_IMAPP -DWITH_SMTPP
MAIL_EXES = $(BUILDDIR)$(PREFIX)pop3p$(EXESUFFICS) $(BUILDDIR)$(PREFIX)imapp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)smtpp$(EXESUFFICS)
endif
FTP ?= false
ifeq ($(FTP),true)
CFLAGS += -DWITH_FTP
FTP_EXES = $(BUILDDIR)$(PREFIX)ftppr$(EXESUFFICS)
endif
HTTPSRV ?= true
ifeq ($(HTTPSRV),true)
CFLAGS += -DWITH_HTTPSRV

View File

@ -27,16 +27,6 @@ CFLAGS += $(EXTRA_CFLAGS)
LDFLAGS += $(EXTRA_LDFLAGS)
# The HTTP server serves the endpoints declared by http lines. The admin
# interface is built on top of it, so turning it off removes both.
MAILPROXY ?= false
ifeq ($(MAILPROXY),true)
CFLAGS += -DWITH_POP3P -DWITH_IMAPP -DWITH_SMTPP
MAIL_EXES = $(BUILDDIR)$(PREFIX)pop3p$(EXESUFFICS) $(BUILDDIR)$(PREFIX)imapp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)smtpp$(EXESUFFICS)
endif
FTP ?= false
ifeq ($(FTP),true)
CFLAGS += -DWITH_FTP
FTP_EXES = $(BUILDDIR)$(PREFIX)ftppr$(EXESUFFICS)
endif
HTTPSRV ?= true
ifeq ($(HTTPSRV),true)
CFLAGS += -DWITH_HTTPSRV

View File

@ -14,16 +14,6 @@ COUT = -o ./
LN = $(CC)
LDFLAGS = -xO3
DCFLAGS = -fPIC
MAILPROXY ?= false
ifeq ($(MAILPROXY),true)
CFLAGS += -DWITH_POP3P -DWITH_IMAPP -DWITH_SMTPP
MAIL_EXES = $(BUILDDIR)$(PREFIX)pop3p$(EXESUFFICS) $(BUILDDIR)$(PREFIX)imapp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)smtpp$(EXESUFFICS)
endif
FTP ?= false
ifeq ($(FTP),true)
CFLAGS += -DWITH_FTP
FTP_EXES = $(BUILDDIR)$(PREFIX)ftppr$(EXESUFFICS)
endif
HTTPSRV ?= true
ifeq ($(HTTPSRV),true)
CFLAGS += -DWITH_HTTPSRV

View File

@ -26,16 +26,6 @@ LDFLAGS += $(EXTRA_LDFLAGS)
# -lpthreads may be reuqired on some platforms instead of -pthreads
# -ldl or -lld may be required for some platforms
DCFLAGS ?= -fPIC
MAILPROXY ?= false
ifeq ($(MAILPROXY),true)
CFLAGS += -DWITH_POP3P -DWITH_IMAPP -DWITH_SMTPP
MAIL_EXES = $(BUILDDIR)$(PREFIX)pop3p$(EXESUFFICS) $(BUILDDIR)$(PREFIX)imapp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)smtpp$(EXESUFFICS)
endif
FTP ?= false
ifeq ($(FTP),true)
CFLAGS += -DWITH_FTP
FTP_EXES = $(BUILDDIR)$(PREFIX)ftppr$(EXESUFFICS)
endif
HTTPSRV ?= true
ifeq ($(HTTPSRV),true)
CFLAGS += -DWITH_HTTPSRV

View File

@ -23,16 +23,6 @@ LDFLAGS += -fno-strict-aliasing -mthreads
# makefile, including the += above and the STATIC/LIBSTATIC handling below.
CFLAGS += $(EXTRA_CFLAGS)
LDFLAGS += $(EXTRA_LDFLAGS)
MAILPROXY ?= false
ifeq ($(MAILPROXY),true)
CFLAGS += -DWITH_POP3P -DWITH_IMAPP -DWITH_SMTPP
MAIL_EXES = $(BUILDDIR)$(PREFIX)pop3p$(EXESUFFICS) $(BUILDDIR)$(PREFIX)imapp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)smtpp$(EXESUFFICS)
endif
FTP ?= false
ifeq ($(FTP),true)
CFLAGS += -DWITH_FTP
FTP_EXES = $(BUILDDIR)$(PREFIX)ftppr$(EXESUFFICS)
endif
HTTPSRV ?= true
ifeq ($(HTTPSRV),true)
CFLAGS += -DWITH_HTTPSRV

View File

@ -95,19 +95,16 @@ SNI proxy (destination address is taken from TLS handshake), may be used to redi
Proxy with protocol autoselection between proxy / socks / tlspr
.br
.B pop3p
POP3 proxy (default port 110), in a build which has one: otherwise the
service is \fBtlspr\fR speaking POP3 to negotiate STARTTLS, under this name.
POP3 proxy (default port 110)
.br
.B imapp
IMAPv4 proxy (default port 143), or \fBtlspr\fR speaking IMAP, as above.
IMAPv4 proxy (default port 143)
.br
.B smtpp
SMTP proxy (default port 25), or \fBtlspr\fR speaking SMTP, as above.
SMTP proxy (default port 25)
.br
.B ftppr
FTP proxy (default port 21), in a build with FTP support. Without it the
service is known but answers nothing, and \fBftp://\fR is not a URL the HTTP
proxy fetches.
FTP proxy (default port 21)
.br
.B admin
Web interface (default port 80)
@ -244,12 +241,6 @@ Never ask for username/password
.br
.B -a2
(for proxy) generate Via: and X-Forwarded-For: instead of Forwarded:
.br
.B -Xftp
(for proxy) fetch \fBftp://\fR URLs, in a build with FTP support. Without
this the scheme is not one the service knows, whatever the build: fetching it
opens a second connection and builds a listing, which a service serving http
has no use for.
.br
Also, all options mentioned for
.BR proxy (8)
@ -1582,22 +1573,6 @@ matched if the ACL matches the connection data.
Warning: Regular expressions don't require authentication and cannot replace
authentication and/or allow/deny ACLs.
.SH OPTIONAL SERVICES
The mail proxies and FTP are built when they are asked for, and are not in a
default build. \fBMAILPROXY=true\fR builds \fBpop3p\fR, \fBimapp\fR and
\fBsmtpp\fR, and \fBFTP=true\fR builds \fBftppr\fR and the \fBftp://\fR
scheme of the HTTP proxy, which a \fBproxy\fR service then still has to ask
for with \fB-Xftp\fR; with CMake the switches are
\fB-D3PROXY_USE_MAILPROXY=ON\fR and \fB-D3PROXY_USE_FTP=ON\fR. The standalone
binaries of those services are built with them and not without.
.br
A configuration naming a service which was not built is still read. The three
mail proxies become \fBtlspr\fR negotiating STARTTLS in that protocol, which
is what most of their use amounts to now that the mail protocols are used over
TLS, and a \fBparent\fR chain naming \fBpop3\fR, \fBimap\fR or \fBsmtp\fR
does the same. \fBftppr\fR is answered by nothing: a client reaching it is
turned away and the refusal logged, since there is no protocol to fall back on.
.SH BUILT IN HTTP SERVER
The \fBhttpsrv\fR service answers requests itself instead of forwarding them.
What it does with a request is decided by \fBhttp\fR rules, which are taken in

View File

@ -2,7 +2,7 @@
# 3 proxy common Makefile
#
all: $(BUILDDIR)3proxy$(EXESUFFICS) $(BUILDDIR)$(CRYPT_PREFIX)crypt$(EXESUFFICS) $(MAIL_EXES) $(FTP_EXES) $(BUILDDIR)$(PREFIX)tcppm$(EXESUFFICS) $(BUILDDIR)$(PREFIX)udppm$(EXESUFFICS) $(BUILDDIR)$(PREFIX)tlspr$(EXESUFFICS) $(BUILDDIR)$(PREFIX)socks$(EXESUFFICS) $(BUILDDIR)$(PREFIX)proxy$(EXESUFFICS) allplugins
all: $(BUILDDIR)3proxy$(EXESUFFICS) $(BUILDDIR)$(CRYPT_PREFIX)crypt$(EXESUFFICS) $(BUILDDIR)$(PREFIX)pop3p$(EXESUFFICS) $(BUILDDIR)$(PREFIX)imapp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)smtpp$(EXESUFFICS) $(BUILDDIR)$(PREFIX)ftppr$(EXESUFFICS) $(BUILDDIR)$(PREFIX)tcppm$(EXESUFFICS) $(BUILDDIR)$(PREFIX)udppm$(EXESUFFICS) $(BUILDDIR)$(PREFIX)tlspr$(EXESUFFICS) $(BUILDDIR)$(PREFIX)socks$(EXESUFFICS) $(BUILDDIR)$(PREFIX)proxy$(EXESUFFICS) allplugins
sockmap$(OBJSUFFICS): sockmap.c proxy.h structures.h
$(CC) $(CFLAGS) sockmap.c

View File

@ -187,9 +187,6 @@ static int h_proxy(int argc, unsigned char ** argv){
childdef.port = 3128;
childdef.isudp = 0;
childdef.service = S_PROXY;
#ifdef WITH_FTP
childdef.helpmessage = " -Xftp - fetch ftp:// URLs\n";
#endif
#ifdef NOIPV6
if(!resolvfunc || (resolvfunc == myresolver && !dns_table.poolsize)){
fprintf(stderr, "[line %d] Warning: no nserver/nscache configured, proxy may run very slow\n", linenum);

View File

@ -7,8 +7,6 @@
#include "proxy.h"
#ifdef WITH_FTP
/*
* Read one FTP server response, skipping continuation lines (lines whose
* 4th character is '-' per RFC 959). Returns the line length on success,
@ -251,5 +249,3 @@ SOCKET ftpcommand(struct clientparam *param, unsigned char * command, unsigned c
}
return s;
}
#endif

View File

@ -8,8 +8,6 @@
#include "proxy.h"
#ifdef WITH_FTP
#define RETURN(xxx) { param->res = xxx; goto CLEANRET; }
#define BUFSIZE 2048
@ -347,16 +345,3 @@ struct proxydef childdef = {
};
#include "proxymain.c"
#endif
#else
/* Built without FTP support. The service and the redirect naming it are
still known, so a configuration carrying them is read rather than
refused, and a client reaching one is turned away. */
void * ftpprchild(struct clientparam * param){
param->res = 878;
dolog(param, (unsigned char *)"ftp support is not built in");
return NULL;
}
#endif

View File

@ -8,8 +8,6 @@
#include "proxy.h"
#ifdef WITH_IMAPP
#define RETURN(xxx) { param->res = xxx; goto CLEANRET; }
#define CL_LOGINCMD 0
@ -252,15 +250,3 @@ struct proxydef childdef = {
};
#include "proxymain.c"
#endif
#else
/* Built without this proxy of its own. The command and the redirect
naming it are the STARTTLS proxy speaking that protocol, which
negotiates the same way and passes the session on: what "tlspr -Ximap"
does, under the name a configuration already uses. */
void * imappchild(struct clientparam * param){
param->starttls = S_IMAPP;
return (void *)tlsprchild;
}
#endif

View File

@ -8,8 +8,6 @@
#include "proxy.h"
#ifdef WITH_POP3P
#define RETURN(xxx) { param->res = xxx; goto CLEANRET; }
#ifdef WITHMAIN
@ -90,15 +88,3 @@ struct proxydef childdef = {
};
#include "proxymain.c"
#endif
#else
/* Built without this proxy of its own. The command and the redirect
naming it are the STARTTLS proxy speaking that protocol, which
negotiates the same way and passes the session on: what "tlspr -Xpop3"
does, under the name a configuration already uses. */
void * pop3pchild(struct clientparam * param){
param->starttls = S_POP3P;
return (void *)tlsprchild;
}
#endif

View File

@ -385,13 +385,10 @@ for(;;){
if (!strncasecmp((char *)sb, "http://", 7)) {
sb += 7;
}
#ifdef WITH_FTP
else if (!strncasecmp((char *)sb, "ftp://", 6)) {
if(!param->srv->allowftp) RETURN(513);
ftp = 1;
sb += 6;
}
#endif
else if(*sb == '/') {
param->transparent = 1;
}
@ -715,7 +712,6 @@ for(;;){
#endif
#ifdef WITH_FTP
if(ftp && param->redirtype != R_HTTP){
SOCKET s;
int mode = 0;
@ -967,7 +963,6 @@ for(;;){
}
RETURN(res);
}
#endif
if(isconnect && param->redirtype != R_HTTP) {
if(param->redirectfunc) {
@ -1358,9 +1353,6 @@ struct proxydef childdef = {
S_PROXY,
"-a - anonymous proxy\r\n"
"-a1 - anonymous proxy with random client IP spoofing\r\n"
#ifdef WITH_FTP
"-Xftp - fetch ftp:// URLs\r\n"
#endif
};
#include "proxymain.c"
#endif

View File

@ -584,12 +584,6 @@ int MODULEMAINFUNC (int argc, char** argv){
if(!strncasecmp(argv[i]+2, "imap", 4)) srv.srvstarttls = S_IMAPP;
else if(!strncasecmp(argv[i]+2, "pop3", 4)) srv.srvstarttls = S_POP3P;
else if(!strncasecmp(argv[i]+2, "smtp", 4)) srv.srvstarttls = S_SMTPP;
#ifdef WITH_FTP
/* The http proxy fetches ftp:// only where it was asked to:
the protocol brings a second connection and a listing to
build, which a service serving http has no use for. */
else if(!strncasecmp(argv[i]+2, "ftp", 3)) srv.allowftp = 1;
#endif
else error = 1;
break;
case 'F':

View File

@ -8,8 +8,6 @@
#include "proxy.h"
#ifdef WITH_SMTPP
#define RETURN(xxx) { param->res = xxx; goto CLEANRET; }
#ifdef WITHMAIN
@ -344,15 +342,3 @@ struct proxydef childdef = {
};
#include "proxymain.c"
#endif
#else
/* Built without this proxy of its own. The command and the redirect
naming it are the STARTTLS proxy speaking that protocol, which
negotiates the same way and passes the session on: what "tlspr -Xsmtp"
does, under the name a configuration already uses. */
void * smtppchild(struct clientparam * param){
param->starttls = S_SMTPP;
return (void *)tlsprchild;
}
#endif

View File

@ -611,7 +611,6 @@ struct srvparam {
int haproxy;
int nostarttls;
PROXYSERVICE srvstarttls;
int allowftp; /* the http proxy fetches ftp:// for this service */
uint32_t fakeip;
unsigned char fakeip6[16];
#ifdef WITHSPLICE
@ -760,10 +759,6 @@ struct clientparam {
that a plugin built against an older header still finds the fields it
knows where they were. */
int onerequest;
/* A STARTTLS protocol to speak before the session is wrapped, set for
one connection rather than for the service, which is how a redirect
and a service name standing in for a mail proxy reach tlspr. */
PROXYSERVICE starttls;
};
struct filemon {

View File

@ -334,8 +334,7 @@ void * tlsprchild(struct clientparam* param) {
int lv=-1;
char proto[PROTOLEN]="-";
int snipos = 0;
PROXYSERVICE stlsproto = param->clientstarttls? param->clientstarttls :
(param->starttls? param->starttls : param->srv->srvstarttls);
PROXYSERVICE stlsproto = param->clientstarttls? param->clientstarttls : param->srv->srvstarttls;
if(!param->clientstarttls && stlsproto){
res = clistarttls(param, stlsproto);

View File

@ -14,19 +14,12 @@ def _windows():
net.ipv4.ip_local_port_range; a window outside it is ignored and an
ordinary ephemeral port is used, so a fixed low window would be
measuring the kernel's own choice rather than the setting.
Everywhere else the range is honoured by binding a port out of it at
random, ten times before giving up and letting the system choose. A port
which carried a connection a moment ago cannot be bound again while it
waits out its close - four minutes of it on Windows - so the window has
to be wide enough that ten tries do not all land on one. The window the
kernel picks from on Linux needs no such room, since it skips them.
"""
try:
with open("/proc/sys/net/ipv4/ip_local_port_range") as fp:
low, high = (int(part) for part in fp.read().split()[:2])
except (OSError, ValueError):
return (21400, 21899), (22000, 22499)
return (21400, 21449), (21500, 21549)
base = low + 1000 if low + 1150 <= high else low
return (base, base + 49), (base + 100, base + 149)