Skip to content

Commit

Permalink
GUACAMOLE-600: Add support for setting SSH and SFTP timeouts.
Browse files Browse the repository at this point in the history
  • Loading branch information
necouchman committed May 24, 2024
1 parent fe808ce commit e08ff9f
Show file tree
Hide file tree
Showing 11 changed files with 114 additions and 13 deletions.
6 changes: 5 additions & 1 deletion src/common-ssh/common-ssh/ssh.h
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,10 @@ void guac_common_ssh_uninit();
*
* @param user
* The user to authenticate as, once connected.
*
* @param timeout
* The number of seconds to attempt to connect to the SSH server before
* timing out.
*
* @param keepalive
* How frequently the connection should send keepalive packets, in
Expand All @@ -138,7 +142,7 @@ void guac_common_ssh_uninit();
*/
guac_common_ssh_session* guac_common_ssh_create_session(guac_client* client,
const char* hostname, const char* port, guac_common_ssh_user* user,
int keepalive, const char* host_key,
int timeout, int keepalive, const char* host_key,
guac_ssh_credential_handler* credential_handler);

/**
Expand Down
38 changes: 33 additions & 5 deletions src/common-ssh/ssh.c
Original file line number Diff line number Diff line change
Expand Up @@ -35,13 +35,15 @@
#include <openssl/ssl.h>

#include <errno.h>
#include <fcntl.h>
#include <netdb.h>
#include <netinet/in.h>
#include <pthread.h>
#include <pwd.h>
#include <stddef.h>
#include <stdlib.h>
#include <string.h>
#include <sys/select.h>
#include <sys/socket.h>
#include <unistd.h>

Expand Down Expand Up @@ -411,7 +413,7 @@ static int guac_common_ssh_authenticate(guac_common_ssh_session* common_session)

guac_common_ssh_session* guac_common_ssh_create_session(guac_client* client,
const char* hostname, const char* port, guac_common_ssh_user* user,
int keepalive, const char* host_key,
int timeout, int keepalive, const char* host_key,
guac_ssh_credential_handler* credential_handler) {

int retval;
Expand Down Expand Up @@ -459,17 +461,43 @@ guac_common_ssh_session* guac_common_ssh_create_session(guac_client* client,
return NULL;
}

/* Connect */
if (connect(fd, current_address->ai_addr,
current_address->ai_addrlen) == 0) {
/* Set socket to non-blocking */
fcntl(fd, F_SETFL, O_NONBLOCK);

/* Set up timeout. */
fd_set fdset;
FD_ZERO(&fdset);
FD_SET(fd, &fdset);

struct timeval tv;
tv.tv_sec = timeout;
tv.tv_usec = 0;

/* Connect and wait for timeout */
if (connect(fd, current_address->ai_addr, current_address->ai_addrlen) < 0) {
guac_client_abort(client, GUAC_PROTOCOL_STATUS_SERVER_ERROR,
"Unable to connect to socket: %s", strerror(errno));
return NULL;
}

retval = select(fd + 1, NULL, &fdset, NULL, &tv);

/* Timeout has occured - log the failure and move to the next address. */
if (retval == 0) {
guac_client_log(client, GUAC_LOG_DEBUG,
"Timeout connecting to host %s, port %s",
connected_address, connected_port);
continue;
}

/* Connection is successful - log it and break the loop. */
else if (retval > 0) {
guac_client_log(client, GUAC_LOG_DEBUG,
"Successfully connected to host %s, port %s",
connected_address, connected_port);

/* Done if successful connect */
break;

}

/* Otherwise log information regarding bind failure */
Expand Down
4 changes: 2 additions & 2 deletions src/protocols/rdp/rdp.c
Original file line number Diff line number Diff line change
Expand Up @@ -792,8 +792,8 @@ void* guac_rdp_client_thread(void* data) {
/* Attempt SSH connection */
rdp_client->sftp_session =
guac_common_ssh_create_session(client, settings->sftp_hostname,
settings->sftp_port, rdp_client->sftp_user, settings->sftp_server_alive_interval,
settings->sftp_host_key, NULL);
settings->sftp_port, rdp_client->sftp_user, settings->sftp_timeout,
settings->sftp_server_alive_interval, settings->sftp_host_key, NULL);

/* Fail if SSH connection does not succeed */
if (rdp_client->sftp_session == NULL) {
Expand Down
12 changes: 12 additions & 0 deletions src/protocols/rdp/settings.c
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,7 @@ const char* GUAC_RDP_CLIENT_ARGS[] = {
"sftp-hostname",
"sftp-host-key",
"sftp-port",
"sftp-timeout",
"sftp-username",
"sftp-password",
"sftp-private-key",
Expand Down Expand Up @@ -454,6 +455,12 @@ enum RDP_ARGS_IDX {
*/
IDX_SFTP_PORT,

/**
* The number of seconds to attempt to connect to the SSH server before
* timing out.
*/
IDX_SFTP_TIMEOUT,

/**
* The username to provide when authenticating with the SSH server for
* SFTP. If blank, the username provided for the RDP user will be used.
Expand Down Expand Up @@ -1086,6 +1093,11 @@ guac_rdp_settings* guac_rdp_parse_args(guac_user* user,
guac_user_parse_args_string(user, GUAC_RDP_CLIENT_ARGS, argv,
IDX_SFTP_PORT, "22");

/* SFTP timeout */
settings->sftp_timeout =
guac_user_parse_args_int(user, GUAC_RDP_CLIENT_ARGS, argv,
IDX_SFTP_TIMEOUT, RDP_DEFAULT_SFTP_TIMEOUT);

/* Username for SSH/SFTP authentication */
settings->sftp_username =
guac_user_parse_args_string(user, GUAC_RDP_CLIENT_ARGS, argv,
Expand Down
11 changes: 11 additions & 0 deletions src/protocols/rdp/settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,11 @@
*/
#define RDP_DEFAULT_PORT 3389

/**
* The default SFTP connection timeout, in seconds.
*/
#define RDP_DEFAULT_SFTP_TIMEOUT 10

/**
* The default RDP port used by Hyper-V "VMConnect".
*/
Expand Down Expand Up @@ -452,6 +457,12 @@ typedef struct guac_rdp_settings {
*/
char* sftp_port;

/**
* The number of seconds to attempt to connect to the SSH server before
* timing out.
*/
int sftp_timeout;

/**
* The username to provide when authenticating with the SSH server for
* SFTP.
Expand Down
11 changes: 11 additions & 0 deletions src/protocols/ssh/settings.c
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ const char* GUAC_SSH_CLIENT_ARGS[] = {
"hostname",
"host-key",
"port",
"timeout",
"username",
"password",
GUAC_SSH_ARGV_FONT_NAME,
Expand Down Expand Up @@ -99,6 +100,11 @@ enum SSH_ARGS_IDX {
*/
IDX_PORT,

/**
* The timeout of the connection attempt, in seconds. Optional.
*/
IDX_TIMEOUT,

/**
* The name of the user to login as. Optional.
*/
Expand Down Expand Up @@ -454,6 +460,11 @@ guac_ssh_settings* guac_ssh_parse_args(guac_user* user,
guac_user_parse_args_string(user, GUAC_SSH_CLIENT_ARGS, argv,
IDX_PORT, GUAC_SSH_DEFAULT_PORT);

/* Parse the timeout value. */
settings->timeout =
guac_user_parse_args_int(user, GUAC_SSH_CLIENT_ARGS, argv,
IDX_TIMEOUT, GUAC_SSH_DEFAULT_TIMEOUT);

/* Read-only mode */
settings->read_only =
guac_user_parse_args_boolean(user, GUAC_SSH_CLIENT_ARGS, argv,
Expand Down
12 changes: 12 additions & 0 deletions src/protocols/ssh/settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,12 @@
*/
#define GUAC_SSH_DEFAULT_PORT "22"

/**
* The default number of seconds to attempt a connection to the SSH/SFTP
* server before giving up.
*/
#define GUAC_SSH_DEFAULT_TIMEOUT 10

/**
* The filename to use for the typescript, if not specified.
*/
Expand Down Expand Up @@ -69,6 +75,12 @@ typedef struct guac_ssh_settings {
*/
char* port;

/**
* The number of seconds to attempt to connect to the SSH server before
* timing out.
*/
int timeout;

/**
* The name of the user to login as, if any. If no username is specified,
* this will be NULL.
Expand Down
7 changes: 4 additions & 3 deletions src/protocols/ssh/ssh.c
Original file line number Diff line number Diff line change
Expand Up @@ -317,7 +317,8 @@ void* ssh_client_thread(void* data) {

/* Open SSH session */
ssh_client->session = guac_common_ssh_create_session(client,
settings->hostname, settings->port, ssh_client->user, settings->server_alive_interval,
settings->hostname, settings->port, ssh_client->user,
settings->timeout, settings->server_alive_interval,
settings->host_key, guac_ssh_get_credential);
if (ssh_client->session == NULL) {
/* Already aborted within guac_common_ssh_create_session() */
Expand Down Expand Up @@ -368,8 +369,8 @@ void* ssh_client_thread(void* data) {
guac_client_log(client, GUAC_LOG_DEBUG, "Reconnecting for SFTP...");
ssh_client->sftp_session =
guac_common_ssh_create_session(client, settings->hostname,
settings->port, ssh_client->user, settings->server_alive_interval,
settings->host_key, NULL);
settings->port, ssh_client->user, settings->timeout,
settings->server_alive_interval, settings->host_key, NULL);
if (ssh_client->sftp_session == NULL) {
/* Already aborted within guac_common_ssh_create_session() */
return NULL;
Expand Down
12 changes: 12 additions & 0 deletions src/protocols/vnc/settings.c
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,7 @@ const char* GUAC_VNC_CLIENT_ARGS[] = {
"sftp-hostname",
"sftp-host-key",
"sftp-port",
"sftp-timeout",
"sftp-username",
"sftp-password",
"sftp-private-key",
Expand Down Expand Up @@ -232,6 +233,12 @@ enum VNC_ARGS_IDX {
*/
IDX_SFTP_PORT,

/**
* The number of seconds to attempt to connect to the SFTP server before
* timing out.
*/
IDX_SFTP_TIMEOUT,

/**
* The username to provide when authenticating with the SSH server for
* SFTP.
Expand Down Expand Up @@ -551,6 +558,11 @@ guac_vnc_settings* guac_vnc_parse_args(guac_user* user,
guac_user_parse_args_string(user, GUAC_VNC_CLIENT_ARGS, argv,
IDX_SFTP_PORT, "22");

/* SFTP connection timeout */
settings->sftp_timeout =
guac_user_parse_args_int(user, GUAC_VNC_CLIENT_ARGS, argv,
IDX_SFTP_TIMEOUT, GUAC_VNC_DEFAULT_SFTP_TIMEOUT);

/* Username for SSH/SFTP authentication */
settings->sftp_username =
guac_user_parse_args_string(user, GUAC_VNC_CLIENT_ARGS, argv,
Expand Down
10 changes: 10 additions & 0 deletions src/protocols/vnc/settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,11 @@
*/
#define GUAC_VNC_DEFAULT_RECORDING_NAME "recording"

/**
* The default number of seconds to attempt to connect to the SFTP server.
*/
#define GUAC_VNC_DEFAULT_SFTP_TIMEOUT 10

/**
* VNC-specific client data.
*/
Expand Down Expand Up @@ -182,6 +187,11 @@ typedef struct guac_vnc_settings {
*/
char* sftp_port;

/**
* The number of seconds to attempt to connect to the SFTP server.
*/
int sftp_timeout;

/**
* The username to provide when authenticating with the SSH server for
* SFTP.
Expand Down
4 changes: 2 additions & 2 deletions src/protocols/vnc/vnc.c
Original file line number Diff line number Diff line change
Expand Up @@ -376,8 +376,8 @@ void* guac_vnc_client_thread(void* data) {
/* Attempt SSH connection */
vnc_client->sftp_session =
guac_common_ssh_create_session(client, settings->sftp_hostname,
settings->sftp_port, vnc_client->sftp_user, settings->sftp_server_alive_interval,
settings->sftp_host_key, NULL);
settings->sftp_port, vnc_client->sftp_user, settings->sftp_timeout,
settings->sftp_server_alive_interval, settings->sftp_host_key, NULL);

/* Fail if SSH connection does not succeed */
if (vnc_client->sftp_session == NULL) {
Expand Down

0 comments on commit e08ff9f

Please sign in to comment.