ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
(Generate patch)

Comparing gvpe/src/conf.C (file contents):
Revision 1.39 by pcg, Sat Mar 26 03:16:24 2005 UTC vs.
Revision 1.51 by pcg, Sat Jul 18 05:59:16 2009 UTC

1/* 1/*
2 conf.c -- configuration code 2 conf.c -- configuration code
3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de> 3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE. 5 This file is part of GVPE.
6 6
7 GVPE is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify it
8 it under the terms of the GNU General Public License as published by 8 under the terms of the GNU General Public License as published by the
9 the Free Software Foundation; either version 2 of the License, or 9 Free Software Foundation; either version 3 of the License, or (at your
10 (at your option) any later version. 10 option) any later version.
11 11
12 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful, but
13 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 GNU General Public License for more details. 15 Public License for more details.
16 16
17 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License along
18 along with gvpe; if not, write to the Free Software 18 with this program; if not, see <http://www.gnu.org/licenses/>.
19 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
20*/ 30*/
21 31
22#include "config.h" 32#include "config.h"
23 33
24#include <cstdio> 34#include <cstdio>
69 if (protocol & PROT_DNSv4 ) return "dns"; 79 if (protocol & PROT_DNSv4 ) return "dns";
70 80
71 return "<unknown>"; 81 return "<unknown>";
72} 82}
73 83
84static bool
85match_list (const vector<const char *> &list, const char *str)
86{
87 for (vector<const char *>::const_iterator i = list.end (); i-- > list.begin (); )
88 if ((*i)[0] == '*' && !(*i)[1])
89 return true;
90 else if (!strcmp (*i, str))
91 return true;
92
93 return false;
94}
95
96bool
97conf_node::may_direct (struct conf_node *other)
98{
99 if (match_list (allow_direct, other->nodename))
100 return true;
101
102 if (match_list (deny_direct, other->nodename))
103 return false;
104
105 return true;
106}
107
74void 108void
75conf_node::print () 109conf_node::print ()
76{ 110{
77 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %s%s%d\n", 111 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %s%s%d\n",
78 id, 112 id,
79 id >> 8, id & 0xff, 113 id >> 8, id & 0xff,
80 compress ? 'Y' : 'N', 114 compress ? 'Y' : 'N',
81 connectmode == C_ONDEMAND ? "ondemand" : 115 connectmode == C_ONDEMAND ? "ondemand"
82 connectmode == C_NEVER ? "never" : 116 : connectmode == C_NEVER ? "never"
83 connectmode == C_ALWAYS ? "always" : "", 117 : connectmode == C_ALWAYS ? "always"
118 : connectmode == C_DISABLED ? "disabled"
119 : "",
84 nodename, 120 nodename,
85 hostname ? hostname : "", 121 hostname ? hostname : "",
86 hostname ? ":" : "", 122 hostname ? ":" : "",
87 hostname ? udp_port : 0 123 hostname ? udp_port : 0
88 ); 124 );
109void configuration::init () 145void configuration::init ()
110{ 146{
111 memset (this, 0, sizeof (*this)); 147 memset (this, 0, sizeof (*this));
112 148
113 mtu = DEFAULT_MTU; 149 mtu = DEFAULT_MTU;
150 nfmark = 0;
114 rekey = DEFAULT_REKEY; 151 rekey = DEFAULT_REKEY;
115 keepalive = DEFAULT_KEEPALIVE; 152 keepalive = DEFAULT_KEEPALIVE;
116 llevel = L_INFO; 153 llevel = L_INFO;
117 ip_proto = IPPROTO_GRE; 154 ip_proto = IPPROTO_GRE;
118#if ENABLE_ICMP 155#if ENABLE_ICMP
123 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm 160 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm
124 default_node.connectmode = conf_node::C_ALWAYS; 161 default_node.connectmode = conf_node::C_ALWAYS;
125 default_node.compress = true; 162 default_node.compress = true;
126 default_node.protocols = 0; 163 default_node.protocols = 0;
127 default_node.max_retry = DEFAULT_MAX_RETRY; 164 default_node.max_retry = DEFAULT_MAX_RETRY;
165 default_node.max_ttl = DEFAULT_MAX_TTL;
166 default_node.max_queue = DEFAULT_MAX_QUEUE;
128 default_node.if_up_data = strdup (""); 167 default_node.if_up_data = strdup ("");
129 168
130#if ENABLE_DNS 169#if ENABLE_DNS
131 default_node.dns_port = 0; // default is 0 == client 170 default_node.dns_port = 0; // default is 0 == client
132 171
146 if (rsa_key) 185 if (rsa_key)
147 RSA_free (rsa_key); 186 RSA_free (rsa_key);
148 187
149 rsa_key = 0; 188 rsa_key = 0;
150 189
151 free (pidfilename); pidfilename = 0; 190 free (pidfilename); pidfilename = 0;
152 free (ifname); ifname = 0; 191 free (ifname); ifname = 0;
153#if ENABLE_HTTP_PROXY 192#if ENABLE_HTTP_PROXY
154 free (proxy_host); proxy_host = 0; 193 free (proxy_host); proxy_host = 0;
155 free (proxy_auth); proxy_auth = 0; 194 free (proxy_auth); proxy_auth = 0;
156#endif 195#endif
157#if ENABLE_DNS 196#if ENABLE_DNS
158 free (dns_forw_host); dns_forw_host = 0; 197 free (dns_forw_host); dns_forw_host = 0;
159#endif 198#endif
199 free (script_if_up); script_if_up = 0;
200 free (script_node_up); script_node_up = 0;
201 free (script_node_change); script_node_change = 0;
202 free (script_node_down); script_node_down = 0;
160} 203}
161 204
162void 205void
163configuration::clear_config () 206configuration::clear ()
164{ 207{
165 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i) 208 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
166 delete *i; 209 delete *i;
167 210
168 nodes.clear (); 211 nodes.clear ();
177 else if (!strcmp (val, "true")) target = trueval; \ 220 else if (!strcmp (val, "true")) target = trueval; \
178 else if (!strcmp (val, "false")) target = falseval; \ 221 else if (!strcmp (val, "false")) target = falseval; \
179 else if (!strcmp (val, "on")) target = trueval; \ 222 else if (!strcmp (val, "on")) target = trueval; \
180 else if (!strcmp (val, "off")) target = falseval; \ 223 else if (!strcmp (val, "off")) target = falseval; \
181 else \ 224 else \
182 slog (L_WARN, \ 225 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed. (ignored)"); \
183 _("illegal value for '%s', only 'yes|true|on' or 'no|false|off' allowed, at '%s' line %d"), \
184 name, var, fname, lineno); \
185} while (0) 226} while (0)
186 227
187void configuration::read_config (bool need_keys) 228const char *
229configuration_parser::parse_line (char *line)
230{
231 {
232 char *end = line + strlen (line);
233
234 while (*end < ' ' && end >= line)
235 end--;
236
237 *++end = 0;
238 }
239
240 char *tok = line;
241 const char *var = strtok (tok, "\t =");
242 tok = 0;
243
244 if (!var || !var[0])
245 return 0; /* no tokens on this line */
246
247 if (var[0] == '#')
248 return 0; /* comment: ignore */
249
250 char *val = strtok (NULL, "\t\n\r =");
251
252 if (!val || val[0] == '#')
253 return _("no value given for variable. (ignored)");
254
255 if (!strcmp (var, "on"))
256 {
257 if (!::thisnode
258 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
259 || !strcmp (val, ::thisnode))
260 return parse_line (strtok (NULL, "\n\r"));
261 else
262 return 0;
263 }
264
265 // truly global
266 if (!strcmp (var, "loglevel"))
267 {
268 loglevel l = string_to_loglevel (val);
269
270 if (l == L_NONE)
271 return _("unknown loglevel. (skipping)");
272 }
273 else if (!strcmp (var, "ip-proto"))
274 conf.ip_proto = atoi (val);
275 else if (!strcmp (var, "icmp-type"))
276 {
277#if ENABLE_ICMP
278 conf.icmp_type = atoi (val);
279#endif
280 }
281
282 // per config
283 else if (!strcmp (var, "node"))
284 {
285 parse_argv ();
286
287 conf.default_node.id++;
288 node = new conf_node (conf.default_node);
289 conf.nodes.push_back (node);
290 node->nodename = strdup (val);
291
292 {
293 char *fname;
294 FILE *f;
295
296 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
297
298 f = fopen (fname, "r");
299 if (f)
300 {
301 node->rsa_key = RSA_new ();
302
303 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
304 {
305 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
306 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
307 exit (EXIT_FAILURE);
308 }
309
310 require (RSA_blinding_on (node->rsa_key, 0));
311
312 fclose (f);
313 }
314 else
315 {
316 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
317
318 if (need_keys)
319 exit (EXIT_FAILURE);
320 }
321
322 free (fname);
323 }
324
325 if (::thisnode && !strcmp (node->nodename, ::thisnode))
326 conf.thisnode = node;
327 }
328 else if (!strcmp (var, "private-key"))
329 free (conf.prikeyfile), conf.prikeyfile = strdup (val);
330 else if (!strcmp (var, "ifpersist"))
331 parse_bool (conf.ifpersist, "ifpersist", true, false);
332 else if (!strcmp (var, "ifname"))
333 free (conf.ifname), conf.ifname = strdup (val);
334 else if (!strcmp (var, "rekey"))
335 conf.rekey = atoi (val);
336 else if (!strcmp (var, "keepalive"))
337 conf.keepalive = atoi (val);
338 else if (!strcmp (var, "mtu"))
339 conf.mtu = atoi (val);
340 else if (!strcmp (var, "nfmark"))
341 conf.nfmark = atoi (val);
342 else if (!strcmp (var, "if-up"))
343 free (conf.script_if_up), conf.script_if_up = strdup (val);
344 else if (!strcmp (var, "node-up"))
345 free (conf.script_node_up), conf.script_node_up = strdup (val);
346 else if (!strcmp (var, "node-change"))
347 free (conf.script_node_change), conf.script_node_change = strdup (val);
348 else if (!strcmp (var, "node-down"))
349 free (conf.script_node_down), conf.script_node_down = strdup (val);
350 else if (!strcmp (var, "pid-file"))
351 free (conf.pidfilename), conf.pidfilename = strdup (val);
352 else if (!strcmp (var, "dns-forw-host"))
353 {
354#if ENABLE_DNS
355 free (conf.dns_forw_host), conf.dns_forw_host = strdup (val);
356#endif
357 }
358 else if (!strcmp (var, "dns-forw-port"))
359 {
360#if ENABLE_DNS
361 conf.dns_forw_port = atoi (val);
362#endif
363 }
364 else if (!strcmp (var, "dns-timeout-factor"))
365 {
366#if ENABLE_DNS
367 conf.dns_timeout_factor = atof (val);
368#endif
369 }
370 else if (!strcmp (var, "dns-send-interval"))
371 {
372#if ENABLE_DNS
373 conf.dns_send_interval = atoi (val);
374#endif
375 }
376 else if (!strcmp (var, "dns-overlap-factor"))
377 {
378#if ENABLE_DNS
379 conf.dns_overlap_factor = atof (val);
380#endif
381 }
382 else if (!strcmp (var, "dns-max-outstanding"))
383 {
384#if ENABLE_DNS
385 conf.dns_max_outstanding = atoi (val);
386#endif
387 }
388 else if (!strcmp (var, "http-proxy-host"))
389 {
390#if ENABLE_HTTP_PROXY
391 free (conf.proxy_host), conf.proxy_host = strdup (val);
392#endif
393 }
394 else if (!strcmp (var, "http-proxy-port"))
395 {
396#if ENABLE_HTTP_PROXY
397 conf.proxy_port = atoi (val);
398#endif
399 }
400 else if (!strcmp (var, "http-proxy-auth"))
401 {
402#if ENABLE_HTTP_PROXY
403 conf.proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
404#endif
405 }
406
407 /* node-specific, non-defaultable */
408 else if (node != &conf.default_node && !strcmp (var, "hostname"))
409 free (node->hostname), node->hostname = strdup (val);
410
411 /* node-specific, defaultable */
412 else if (!strcmp (var, "udp-port"))
413 node->udp_port = atoi (val);
414 else if (!strcmp (var, "tcp-port"))
415 node->tcp_port = atoi (val);
416 else if (!strcmp (var, "dns-hostname"))
417 {
418#if ENABLE_DNS
419 free (node->dns_hostname), node->dns_hostname = strdup (val);
420#endif
421 }
422 else if (!strcmp (var, "dns-port"))
423 {
424#if ENABLE_DNS
425 node->dns_port = atoi (val);
426#endif
427 }
428 else if (!strcmp (var, "dns-domain"))
429 {
430#if ENABLE_DNS
431 free (node->domain), node->domain = strdup (val);
432#endif
433 }
434 else if (!strcmp (var, "if-up-data"))
435 free (node->if_up_data), node->if_up_data = strdup (val);
436 else if (!strcmp (var, "router-priority"))
437 node->routerprio = atoi (val);
438 else if (!strcmp (var, "max-retry"))
439 node->max_retry = atoi (val);
440 else if (!strcmp (var, "connect"))
441 {
442 if (!strcmp (val, "ondemand"))
443 node->connectmode = conf_node::C_ONDEMAND;
444 else if (!strcmp (val, "never"))
445 node->connectmode = conf_node::C_NEVER;
446 else if (!strcmp (val, "always"))
447 node->connectmode = conf_node::C_ALWAYS;
448 else if (!strcmp (val, "disabled"))
449 node->connectmode = conf_node::C_DISABLED;
450 else
451 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled'. (ignored)");
452 }
453 else if (!strcmp (var, "inherit-tos"))
454 parse_bool (node->inherit_tos, "inherit-tos", true, false);
455 else if (!strcmp (var, "compress"))
456 parse_bool (node->compress, "compress", true, false);
457 // all these bool options really really cost a lot of executable size!
458 else if (!strcmp (var, "enable-tcp"))
459 {
460#if ENABLE_TCP
461 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
462#endif
463 }
464 else if (!strcmp (var, "enable-icmp"))
465 {
466#if ENABLE_ICMP
467 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
468#endif
469 }
470 else if (!strcmp (var, "enable-dns"))
471 {
472#if ENABLE_DNS
473 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
474#endif
475 }
476 else if (!strcmp (var, "enable-udp"))
477 {
478 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
479 }
480 else if (!strcmp (var, "enable-rawip"))
481 {
482 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
483 }
484 else if (!strcmp (var, "allow-direct"))
485 node->allow_direct.push_back (strdup (val));
486 else if (!strcmp (var, "deny-direct"))
487 node->deny_direct.push_back (strdup (val));
488 else if (!strcmp (var, "max-ttl"))
489 node->max_ttl = atof (val);
490 else if (!strcmp (var, "max-queue"))
491 node->max_queue = atoi (val);
492
493 // unknown or misplaced
494 else
495 return _("unknown configuration directive. (ignored)");
496
497 return 0;
498}
499
500void conf_node::finalise ()
501{
502 if (max_queue < 1)
503 {
504 slog (L_WARN, _("%s: max-queue value invalid, setting it to 1."), nodename);
505 max_queue = 1;
506 }
507
508 if (routerprio > 1 && (connectmode != C_ALWAYS && connectmode != C_DISABLED))
509 {
510 //slog (L_WARN, _("%s: has non-zero router-priority but either 'never' or 'ondemand' as connectmode, setting it to 'always'."), nodename);
511 connectmode = C_ALWAYS;
512 }
513}
514
515void configuration_parser::parse_argv ()
516{
517 for (int i = 0; i < argc; ++i)
518 {
519 char *v = argv [i];
520
521 if (!*v)
522 continue;
523
524 char *enode = v;
525
526 while (*enode != '.' && *enode > ' ' && *enode != '=' && *enode)
527 enode++;
528
529 if (*enode != '.')
530 enode = 0;
531
532 char *wnode = node == &conf.default_node
533 ? 0
534 : node->nodename;
535
536 if ((!wnode && !enode)
537 || (wnode && enode && !strncmp (wnode, v, enode - v)))
538 {
539 const char *warn = parse_line (enode ? enode + 1 : v);
540
541 if (warn)
542 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v);
543
544 *v = 0;
545 }
546 }
547}
548
549configuration_parser::configuration_parser (configuration &conf,
550 bool need_keys,
551 int argc,
552 char **argv)
553: conf (conf),need_keys (need_keys), argc (argc), argv (argv)
188{ 554{
189 char *fname; 555 char *fname;
190 FILE *f; 556 FILE *f;
191 557
192 clear_config (); 558 conf.clear ();
193 559
194 asprintf (&fname, "%s/gvpe.conf", confbase); 560 asprintf (&fname, "%s/gvpe.conf", confbase);
195 f = fopen (fname, "r"); 561 f = fopen (fname, "r");
196 562
197 if (f) 563 if (f)
198 { 564 {
199 char line[16384]; 565 char line[16384];
200 int lineno = 0; 566 int lineno = 0;
201 char *var, *val; 567 node = &conf.default_node;
202 conf_node *node = &default_node;
203 568
204 while (fgets (line, sizeof (line), f)) 569 while (fgets (line, sizeof (line), f))
205 { 570 {
206 lineno++; 571 lineno++;
207 572
208 { 573 const char *warn = parse_line (line);
209 char *end = line + strlen (line);
210 574
211 while (*end < ' ' && end >= line) 575 if (warn)
212 end--; 576 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
213
214 *++end = 0;
215 }
216
217 char *tok = line;
218
219retry:
220 var = strtok (tok, "\t =");
221 tok = 0;
222
223 if (!var || !var[0])
224 continue; /* no tokens on this line */
225
226 if (var[0] == '#')
227 continue; /* comment: ignore */
228
229 val = strtok (NULL, "\t\n\r =");
230
231 if (!val || val[0] == '#')
232 {
233 slog (L_WARN,
234 _("no value for variable `%s', at '%s' line %d, skipping."),
235 var, fname, lineno);
236 continue;
237 }
238
239 if (!strcmp (var, "on"))
240 {
241 if (!::thisnode
242 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
243 || !strcmp (val, ::thisnode))
244 goto retry;
245
246 continue;
247 }
248
249 // truly global
250 if (!strcmp (var, "loglevel"))
251 {
252 loglevel l = string_to_loglevel (val);
253
254 if (l != L_NONE)
255 llevel = l;
256 else
257 slog (L_WARN, "'%s': %s, at '%s' line %d", val, UNKNOWN_LOGLEVEL, fname, line);
258 }
259 else if (!strcmp (var, "ip-proto"))
260 ip_proto = atoi (val);
261 else if (!strcmp (var, "icmp-type"))
262 {
263#if ENABLE_ICMP
264 icmp_type = atoi (val);
265#endif
266 }
267
268 // per config
269 else if (!strcmp (var, "node"))
270 {
271 default_node.id++;
272
273 node = new conf_node (default_node);
274
275 nodes.push_back (node);
276
277 node->nodename = strdup (val);
278
279 {
280 char *fname;
281 FILE *f;
282
283 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
284
285 f = fopen (fname, "r");
286 if (f)
287 {
288 node->rsa_key = RSA_new ();
289
290 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
291 {
292 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
293 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
294 exit (EXIT_FAILURE);
295 }
296
297 require (RSA_blinding_on (node->rsa_key, 0));
298
299 fclose (f);
300 }
301 else
302 {
303 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
304
305 if (need_keys)
306 exit (EXIT_FAILURE);
307 }
308
309 free (fname);
310 }
311
312 if (::thisnode && !strcmp (node->nodename, ::thisnode))
313 thisnode = node;
314 }
315 else if (!strcmp (var, "private-key"))
316 free (prikeyfile), prikeyfile = strdup (val);
317 else if (!strcmp (var, "ifpersist"))
318 parse_bool (ifpersist, "ifpersist", true, false);
319 else if (!strcmp (var, "ifname"))
320 free (ifname), ifname = strdup (val);
321 else if (!strcmp (var, "rekey"))
322 rekey = atoi (val);
323 else if (!strcmp (var, "keepalive"))
324 keepalive = atoi (val);
325 else if (!strcmp (var, "mtu"))
326 mtu = atoi (val);
327 else if (!strcmp (var, "if-up"))
328 free (script_if_up), script_if_up = strdup (val);
329 else if (!strcmp (var, "node-up"))
330 free (script_node_up), script_node_up = strdup (val);
331 else if (!strcmp (var, "node-down"))
332 free (script_node_down), script_node_down = strdup (val);
333 else if (!strcmp (var, "pid-file"))
334 free (pidfilename), pidfilename = strdup (val);
335 else if (!strcmp (var, "dns-forw-host"))
336 {
337#if ENABLE_DNS
338 free (dns_forw_host), dns_forw_host = strdup (val);
339#endif
340 }
341 else if (!strcmp (var, "dns-forw-port"))
342 {
343#if ENABLE_DNS
344 dns_forw_port = atoi (val);
345#endif
346 }
347 else if (!strcmp (var, "dns-timeout-factor"))
348 {
349#if ENABLE_DNS
350 dns_timeout_factor = atof (val);
351#endif
352 }
353 else if (!strcmp (var, "dns-send-interval"))
354 {
355#if ENABLE_DNS
356 dns_send_interval = atoi (val);
357#endif
358 }
359 else if (!strcmp (var, "dns-overlap-factor"))
360 {
361#if ENABLE_DNS
362 dns_overlap_factor = atof (val);
363#endif
364 }
365 else if (!strcmp (var, "dns-max-outstanding"))
366 {
367#if ENABLE_DNS
368 dns_max_outstanding = atoi (val);
369#endif
370 }
371 else if (!strcmp (var, "http-proxy-host"))
372 {
373#if ENABLE_HTTP_PROXY
374 free (proxy_host), proxy_host = strdup (val);
375#endif
376 }
377 else if (!strcmp (var, "http-proxy-port"))
378 {
379#if ENABLE_HTTP_PROXY
380 proxy_port = atoi (val);
381#endif
382 }
383 else if (!strcmp (var, "http-proxy-auth"))
384 {
385#if ENABLE_HTTP_PROXY
386 proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
387#endif
388 }
389
390 /* node-specific, non-defaultable */
391 else if (node != &default_node && !strcmp (var, "hostname"))
392 free (node->hostname), node->hostname = strdup (val);
393
394 /* node-specific, defaultable */
395 else if (!strcmp (var, "udp-port"))
396 node->udp_port = atoi (val);
397 else if (!strcmp (var, "tcp-port"))
398 node->tcp_port = atoi (val);
399 else if (!strcmp (var, "dns-hostname"))
400 {
401#if ENABLE_DNS
402 free (node->dns_hostname), node->dns_hostname = strdup (val);
403#endif
404 }
405 else if (!strcmp (var, "dns-port"))
406 {
407#if ENABLE_DNS
408 node->dns_port = atoi (val);
409#endif
410 }
411 else if (!strcmp (var, "dns-domain"))
412 {
413#if ENABLE_DNS
414 free (node->domain), node->domain = strdup (val);
415#endif
416 }
417 else if (!strcmp (var, "if-up-data"))
418 free (node->if_up_data), node->if_up_data = strdup (val);
419 else if (!strcmp (var, "router-priority"))
420 node->routerprio = atoi (val);
421 else if (!strcmp (var, "max-retry"))
422 node->max_retry = atoi (val);
423 else if (!strcmp (var, "connect"))
424 {
425 if (!strcmp (val, "ondemand"))
426 node->connectmode = conf_node::C_ONDEMAND;
427 else if (!strcmp (val, "never"))
428 node->connectmode = conf_node::C_NEVER;
429 else if (!strcmp (val, "always"))
430 node->connectmode = conf_node::C_ALWAYS;
431 else if (!strcmp (val, "disabled"))
432 node->connectmode = conf_node::C_DISABLED;
433 else
434 slog (L_WARN,
435 _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', at '%s' line %d, ignoring."),
436 var, fname, lineno);
437 }
438 else if (!strcmp (var, "inherit-tos"))
439 parse_bool (node->inherit_tos, "inherit-tos", true, false);
440 else if (!strcmp (var, "compress"))
441 parse_bool (node->compress, "compress", true, false);
442 // all these bool options really really cost a lot of executable size!
443 else if (!strcmp (var, "enable-tcp"))
444 {
445#if ENABLE_TCP
446 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
447#endif
448 }
449 else if (!strcmp (var, "enable-icmp"))
450 {
451#if ENABLE_ICMP
452 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
453#endif
454 }
455 else if (!strcmp (var, "enable-dns"))
456 {
457#if ENABLE_DNS
458 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
459#endif
460 }
461 else if (!strcmp (var, "enable-udp"))
462 {
463 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
464 }
465 else if (!strcmp (var, "enable-rawip"))
466 {
467 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
468 }
469
470 // unknown or misplaced
471 else
472 slog (L_WARN,
473 _("unknown or misplaced variable `%s', at '%s' line %d, skipping."),
474 var, fname, lineno);
475 } 577 }
476 578
477 fclose (f); 579 fclose (f);
580
581 parse_argv ();
478 } 582 }
479 else 583 else
480 { 584 {
481 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno)); 585 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
482 exit (EXIT_FAILURE); 586 exit (EXIT_FAILURE);
483 } 587 }
484 588
485 free (fname); 589 free (fname);
486 590
487 fname = config_filename (prikeyfile, "hostkey"); 591 fname = conf.config_filename (conf.prikeyfile, "hostkey");
488 592
489 f = fopen (fname, "r"); 593 f = fopen (fname, "r");
490 if (f) 594 if (f)
491 { 595 {
492 rsa_key = RSA_new (); 596 conf.rsa_key = RSA_new ();
493 597
494 if (!PEM_read_RSAPrivateKey (f, &rsa_key, NULL, NULL)) 598 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL))
495 { 599 {
496 ERR_load_RSA_strings (); ERR_load_PEM_strings (); 600 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
497 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0)); 601 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
498 exit (EXIT_FAILURE); 602 exit (EXIT_FAILURE);
499 } 603 }
500 604
501 require (RSA_blinding_on (rsa_key, 0)); 605 require (RSA_blinding_on (conf.rsa_key, 0));
502 606
503 fclose (f); 607 fclose (f);
504 } 608 }
505 else 609 else
506 { 610 {
509 if (need_keys) 613 if (need_keys)
510 exit (EXIT_FAILURE); 614 exit (EXIT_FAILURE);
511 } 615 }
512 616
513 if (need_keys && ::thisnode 617 if (need_keys && ::thisnode
514 && rsa_key && thisnode && thisnode->rsa_key) 618 && conf.rsa_key && conf.thisnode && conf.thisnode->rsa_key)
515 if (BN_cmp (rsa_key->n, thisnode->rsa_key->n) != 0 619 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
516 || BN_cmp (rsa_key->e, thisnode->rsa_key->e) != 0) 620 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
517 { 621 {
518 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode); 622 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
519 exit (EXIT_FAILURE); 623 exit (EXIT_FAILURE);
520 } 624 }
521 625
522 free (fname); 626 free (fname);
627
628 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
629 (*i)->finalise ();
523} 630}
524 631
525char *configuration::config_filename (const char *name, const char *dflt) 632char *configuration::config_filename (const char *name, const char *dflt)
526{ 633{
527 char *fname; 634 char *fname;

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines