C語言實現爲終端程序--webshell基石

之前對ssh一直很困惑它是如何實現的,網上也沒有相關代碼實例,所以自己花了一段時間研究了一下。本篇博客主要寫了兩個程度:服務端和客戶端,通過客戶端可以遠程登錄服務端,執行shell命令。代碼實現的比較糙,但是基本原理一看就明白。

一、主要核心思想:

1)創建pty虛擬終端,即open("/dev/ptmx", O_RDWR | O_NOCTTY),關於pty的介紹網上有很多,這裏簡單說明一下pty類似我們管道,但是pty是全雙工的。pty有master、slave,兩者之間可以進行通信。當我open的時候返回的是master文件描述,那麼slave如何打開呢?調用ptsname(master-fd),返回文件路徑,然後在open即可。注意:ptsname入參一定是master文件描述

2)服務端需要fork一個子進程,然後用exec家族函數進行替換/bin/sh。在替換之前需要通過dup2系統調用,重定向標準輸入、標註輸出、標準錯誤輸出,這裏需要注意,這裏文件描述符一定slave fd,例如:

    /* Duplicate pty slave to be child's stdin, stdout, and stderr */
    dup2(slave, STDIN_FILENO);
    dup2(slave, STDOUT_FILENO);
    dup2(slave, STDERR_FILENO);

3)當然在exec家族函數執行之前我們需要可以進行一些屬性設置,例如:關閉回顯、設置窗口大小等詳細可以參考代碼

二、編譯並運行

[root@localhost epoll-pipe]# gcc Server.c -o ShellServer -g -lpthread
[root@localhost epoll-pipe]# 
[root@localhost epoll-pipe]# ./ShellServer 
[root@localhost epoll-pipe]# gcc -g -o client Client.c  -lpthread
[root@localhost epoll-pipe]# 
[root@localhost epoll-pipe]# ./client 127.0.0.1
sh-4.2# ifconfig 
enp0s31f6: flags=4099<UP,BROADCAST,MULTICAST>  mtu 1500
        ether d4:81:d7:c6:4a:d9  txqueuelen 1000  (Ethernet)
        RX packets 0  bytes 0 (0.0 B)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 0  bytes 0 (0.0 B)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
        device interrupt 16  memory 0xef200000-ef220000  

三、代碼

服務端代碼:

#define _XOPEN_SOURCE
#define _GNU_SOURCE

#include <stdio.h>
#include <stdlib.h>
#include <stdint.h>
#include <string.h>
#include <strings.h>
#include <unistd.h>
#include <fcntl.h>
#include <errno.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#include <sys/socket.h>
#include <sys/epoll.h>
#include <termios.h>
#include <sys/ioctl.h>
#include <fcntl.h>
#include <pthread.h>

#define SERVPORT 9527
#define MAXBUF 10240
#define MAXFDS 5000
#define EVENTSIZE 100

int setnonblocking(int fd)
{
    int opts;
    if( (opts = fcntl(fd, F_GETFL, 0)) == -1) {
        perror("fcntl");
        return -1;
    }

    opts = opts | O_NONBLOCK;
    if( (opts = fcntl(fd, F_SETFL, opts)) == -1) {
        perror("fcntl");
        return -1;
    }

    return 0;
}


int setcloexec(int fd)
{
    int opts;
    if( (opts = fcntl(fd, F_GETFL, 0)) == -1) {
        perror("fcntl");
        return -1;
    }

    opts = opts | FD_CLOEXEC;
    if( (opts = fcntl(fd, F_SETFL, opts)) == -1) {
        perror("fcntl");
        return -1;
    }

    return 0;
}



void* handle_child_output(void* data) {
    char buf[MAXBUF] = {0};
    int sockfd = (*(uint64_t*)data) & 0xFFFFFFF;
    int master = (int)((*(uint64_t*)data) >> 32);
    while(1) {
        int nread = read(master, buf, MAXBUF);
        send(sockfd, buf, nread, 0);
    }
}

int create_pty(char *slavename, size_t length)
{
    int master;
    char *p;

    /* Open pty master */
    master = open("/dev/ptmx", O_RDWR | O_NOCTTY);
    if (master == -1)
        return -1;
    /* Grant access to slave pty */
    if (grantpt(master) == -1) {
        close(master);
        return -1;
    }
    /* Unlock slave pty */
    if (unlockpt(master) == -1) {
        close(master);
        return -1;
    }

    /* Get slave pty name. */
    p = ptsname(master);
    if (p == NULL) {
        close(master);
        return -1;
    }

    if (strlen(p) < length) {
        strncpy(slavename, p, length);
    } else {/* Return an error if buffer too small */
        close(master);
        return -1;
    }

    return master;
}

void child_routine(int sockfd, const char* slavename) {

    /* Start a new session */
    if (setsid() == -1) {
        exit(0);
    }

    /* Becomes controlling tty */
    int slave = open(slavename, O_RDWR);
    if (slave == -1) {
        exit(0);
    }

    /* disable ECHO attribute */
    struct termios termios;
    if (tcgetattr(slave, &termios) == -1)
        exit(0);
    termios.c_lflag &= ~(ECHO);

    if (tcsetattr(slave, TCSANOW, &termios) == -1) {
        exit(0);
    }
#if 0
    struct winsize old_wins;
    if (ioctl(slave, TIOCSWINSZ, &old_wins) == -1) {
        exit(0);
    }
#endif
    //根據客戶窗口代碼進行設置,以便輸出結果能夠優雅
    struct winsize size;
    recv(sockfd, &size, sizeof(struct winsize), 0);
    ioctl(slave, TIOCSWINSZ, &size);
    close(sockfd);

    /* Duplicate pty slave to be child's stdin, stdout, and stderr */
    dup2(slave, STDIN_FILENO);
    dup2(slave, STDOUT_FILENO);
    dup2(slave, STDERR_FILENO);

    if (slave > STDERR_FILENO)        /* Safety check */
        close(slave);                 /* No longer need this fd */

    char *args[] = {"/bin/sh", "-i", NULL};
    execv("/bin/sh", args);
    return;
}

void* service_routine(void* data) {
    int sockfd = *(int*)data;
    char slavename[256] = {0};
    int pty_master = create_pty(slavename, 256);//創建pty虛擬終端
    int pid = vfork();
    if (pid < 0) {
        exit(1);
    } else if (pid == 0) {
        // pty master fd is not useful in child-process.
        close(pty_master);
        child_routine(sockfd, slavename);
    } else {
        char buf[MAXBUF] = {0};
        pthread_t thread_id;
        uint64_t data = pty_master;
        data = data << 32 | sockfd;
        pthread_create(&thread_id, NULL, handle_child_output, &data);

        while (1) {
            int bytes = recv(sockfd, buf, MAXBUF, 0);
            printf("Recv from client: bytes = %d, errno=%d\n", bytes, errno);
            if (bytes > 0) {
                write(pty_master, buf, bytes);
            }
        }
    }
}


int main(void)
{
    char buf[MAXBUF];
    int len, n;

    struct sockaddr_in servaddr;
    int sockfd, listenfd, epollfd, nfds;

    struct epoll_event ev;
    struct epoll_event events[EVENTSIZE];

    bzero(&servaddr, sizeof(servaddr));
    servaddr.sin_family = AF_INET;
    servaddr.sin_addr.s_addr = htonl(INADDR_ANY);
    servaddr.sin_port = htons(SERVPORT);

    if( (epollfd = epoll_create(MAXFDS)) == -1) {
        perror("epoll");
        exit(1);
    }
    if(setcloexec(epollfd) == -1){
        perror("setcloexec");
        exit(1);
    }

    if( (listenfd = socket(AF_INET, SOCK_STREAM, 0)) == -1) {
        perror("socket");
        exit(1);
    }

    if(setcloexec(listenfd) == -1){
        perror("setcloexec");
        exit(1);
    }

    if(bind(listenfd, (struct sockaddr *)&servaddr, sizeof(servaddr)) == -1) {
        perror("bind");
        exit(1);
    }

    if(listen(listenfd, 10) == -1) {
        perror("listen");
        exit(1);
    }

    // listen fd只註冊EPOLLIN事件, EPOLLOUT不需要註冊
    ev.events = EPOLLIN | EPOLLET;
    ev.data.fd = listenfd;
    if(epoll_ctl(epollfd, EPOLL_CTL_ADD, listenfd, &ev) == -1) {
        perror("epoll_ctl");
        exit(1);
    }

    for( ; ; ) {
        if( (nfds = epoll_wait(epollfd, events, EVENTSIZE, -1)) == -1) {
            perror("epoll_wait");
            exit(1);
        }

        for(n = 0; n < nfds; n++) {
            if(events[n].data.fd == listenfd) {
                while( (sockfd = accept(listenfd, (struct sockaddr *)NULL, NULL)) > 0) {
                    //創建服務線程
                    pthread_t thread_id;
                    pthread_create(&thread_id, NULL, service_routine, &sockfd);
                }
                continue;
            }
            printf("Events = 0x%x\n", events[n].events);
            if (events[n].events & (EPOLLIN | EPOLLOUT) == (EPOLLIN | EPOLLOUT)) {
                printf(">> EPOLLIN And EPOLLOUT event, socketfd = %d\n", events[n].data.fd);
            }
            else if (events[n].events & EPOLLIN) {
                printf(">> Only EPOLLIN event, socketfd = %d\n", events[n].data.fd);
            }
            else if (events[n].events & EPOLLOUT) {
                printf(">> Only EPOLLOUT, socketfd = %d\n", events[n].data.fd);
            }
        }
    }
}

客戶端代碼:

#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <strings.h>
#include <errno.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#include <sys/socket.h>
#include <termios.h>
#include <sys/ioctl.h>
#include <fcntl.h>
#include <pthread.h>

#define SERVPORT 9527
#define MAXBUF 10240

int setnonblocking(int fd)
{
    int opts;
    if( (opts = fcntl(fd, F_GETFL, 0)) == -1) {
        perror("fcntl");
        return -1;
    }

    opts = opts | O_NONBLOCK;
    if( (opts = fcntl(fd, F_SETFL, opts)) == -1) {
        perror("fcntl");
        return -1;
    }

    return 0;
}


void* handle_input(void* d) {
    int fd = *(int*)d;
    char buf[MAXBUF];
    while(1) {
        //read cmd from TERMIAL and send it
        int nbytes = read(STDIN_FILENO, buf, MAXBUF);
        buf[nbytes] = '\0';
        //send
        send(fd, buf, nbytes, 0);
        buf[0] = '\0';
    }
    return NULL;
}

int main(int argc, char* argv[])
{
    char buf[MAXBUF];
    struct sockaddr_in servaddr;
    int fd;
    int n, len;

    bzero(&servaddr, sizeof(servaddr));
    servaddr.sin_family = AF_INET;
    if (argc > 1) {
        servaddr.sin_addr.s_addr = inet_addr(argv[1]);
    } else {
        servaddr.sin_addr.s_addr = inet_addr("127.0.0.1");
    }
    servaddr.sin_port = htons(SERVPORT);

    if ((fd = socket(AF_INET, SOCK_STREAM, 0)) == -1) {
        perror("socket");
        exit(1);
    }

    if (connect(fd, (struct sockaddr *)&servaddr, sizeof(servaddr)) == -1) {
        perror("connect");
        exit(1);
    }
    pthread_t thread_id;
    pthread_create(&thread_id, NULL, handle_input, &fd);

    int bytes = 0;
    struct winsize size;
    ioctl(STDIN_FILENO, TIOCGWINSZ, &size);
    bytes = send(fd, &size, sizeof(struct winsize), 0);

    while(1) {
        //resv response
        bytes = recv(fd, buf, MAXBUF, 0);
        write(STDOUT_FILENO, buf, bytes);
    }

    close(fd);// 會出發server端 EPOLLIN和EPOLLOUT
    return 0;
}

四、優化

此代碼寫的比較糙,需要做一些優化,例如:採用多路複用技術減少線程數,支持退格鍵、tab鍵、方向鍵等。這裏啓動拋磚引玉,大家一起學習。

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章