|
| 1 | +#undef getaddrinfo |
| 2 | + |
| 3 | +#include "socket.h" |
| 4 | +#include <vector> |
| 5 | +#include <map> |
| 6 | +#include <fstream> |
| 7 | +#include <sstream> |
| 8 | +#include <regex> |
| 9 | + |
| 10 | +//Somewhere glua can't read? |
| 11 | +const char* whitelistDir = "../gm_socket_whitelist.txt"; |
| 12 | +std::map<std::string, std::vector<std::regex> > whitelist; |
| 13 | + |
| 14 | +enum : int |
| 15 | +{ |
| 16 | + PARSE_SUCCESS = 0, |
| 17 | + PARSE_CANT_READ = 1, |
| 18 | + PARSE_NO_ENTRIES = 2 |
| 19 | +}; |
| 20 | + |
| 21 | +int parseWhitelist() |
| 22 | +{ |
| 23 | + std::ifstream input(whitelistDir); |
| 24 | + if (input) |
| 25 | + { |
| 26 | + std::stringstream filereader; |
| 27 | + filereader << input.rdbuf(); |
| 28 | + std::string filedata = filereader.str(); |
| 29 | + std::regex line_parser("(?:(?!\r?\n).)+"); |
| 30 | + std::regex entry_parser("^[ \\t]*([\\w\\.\\*-]+)\\:(\\d+)[ \\t]*$"); |
| 31 | + std::regex wildcard("\\*"); |
| 32 | + std::regex dot("\\."); |
| 33 | + for (std::sregex_iterator line = std::sregex_iterator(filedata.begin(), filedata.end(), line_parser), end = std::sregex_iterator(); line != end; ++line) |
| 34 | + { |
| 35 | + const std::string& linestr = line->operator[](0); |
| 36 | + std::smatch match; |
| 37 | + if(std::regex_match(linestr, match, entry_parser)) |
| 38 | + { |
| 39 | + std::string domain = match[1]; |
| 40 | + domain = std::regex_replace(domain, wildcard, "[\\w-]+"); |
| 41 | + domain = std::regex_replace(domain, dot, "\\."); |
| 42 | + whitelist[match[2].str()].push_back(std::regex(domain)); |
| 43 | + } |
| 44 | + } |
| 45 | + if (whitelist.empty()) |
| 46 | + { |
| 47 | + return PARSE_NO_ENTRIES; |
| 48 | + } |
| 49 | + } |
| 50 | + else |
| 51 | + { |
| 52 | + return PARSE_CANT_READ; |
| 53 | + } |
| 54 | + return PARSE_SUCCESS; |
| 55 | +} |
| 56 | + |
| 57 | +void clearWhitelist() |
| 58 | +{ |
| 59 | + whitelist.clear(); |
| 60 | +} |
| 61 | + |
| 62 | +bool isSafe(const char* pNodeName, const char* pServiceName) |
| 63 | +{ |
| 64 | + std::map<std::string, std::vector<std::regex> >::iterator domains = whitelist.find(pServiceName); |
| 65 | + if (domains != whitelist.end()) |
| 66 | + { |
| 67 | + for (auto i = domains->second.begin(), end = domains->second.end(); i != end; ++i) |
| 68 | + { |
| 69 | + if (std::regex_match(pNodeName, *i)) |
| 70 | + { |
| 71 | + return true; |
| 72 | + } |
| 73 | + } |
| 74 | + return false; |
| 75 | + } |
| 76 | + else |
| 77 | + { |
| 78 | + return false; |
| 79 | + } |
| 80 | +} |
| 81 | + |
| 82 | +extern "C" { |
| 83 | + |
| 84 | +#ifdef _WIN32 |
| 85 | + INT WSAAPI __wrap_getaddrinfo( |
| 86 | + _In_opt_ PCSTR pNodeName, |
| 87 | + _In_opt_ PCSTR pServiceName, |
| 88 | + _In_opt_ const ADDRINFOA * pHints, |
| 89 | + _Outptr_result_maybenull_ PADDRINFOA * ppResult |
| 90 | + ) |
| 91 | +#else |
| 92 | + int __wrap_getaddrinfo (__const char *__restrict pNodeName, |
| 93 | + __const char *__restrict pServiceName, |
| 94 | + __const struct addrinfo *__restrict pHints, |
| 95 | + struct addrinfo **__restrict ppResult) |
| 96 | +#endif |
| 97 | + { |
| 98 | + if(isSafe(pNodeName, pServiceName)) |
| 99 | + { |
| 100 | + return getaddrinfo(pNodeName, pServiceName, pHints, ppResult); |
| 101 | + } |
| 102 | + else |
| 103 | + { |
| 104 | + *ppResult = nullptr; |
| 105 | + return EAI_FAIL; |
| 106 | + } |
| 107 | + } |
| 108 | + |
| 109 | +} |
0 commit comments