ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
(Generate patch)

Comparing gvpe/src/conf.C (file contents):
Revision 1.52 by root, Tue Feb 8 23:11:35 2011 UTC vs.
Revision 1.60 by root, Sat Jul 13 04:10:29 2013 UTC

1/* 1/*
2 conf.c -- configuration code 2 conf.C -- configuration code
3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de> 3 Copyright (C) 2003-2008,2011 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE. 5 This file is part of GVPE.
6 6
7 GVPE is free software; you can redistribute it and/or modify it 7 GVPE is free software; you can redistribute it and/or modify it
8 under the terms of the GNU General Public License as published by the 8 under the terms of the GNU General Public License as published by the
38#include <errno.h> 38#include <errno.h>
39#include <netdb.h> 39#include <netdb.h>
40#include <sys/stat.h> 40#include <sys/stat.h>
41#include <sys/types.h> 41#include <sys/types.h>
42#include <unistd.h> 42#include <unistd.h>
43#include <pwd.h>
43 44
44#include "netcompat.h" 45#include "netcompat.h"
45 46
46#include <openssl/err.h> 47#include <openssl/err.h>
47#include <openssl/pem.h> 48#include <openssl/pem.h>
103 104
104 if (match_list (deny_direct, other->nodename)) 105 if (match_list (deny_direct, other->nodename))
105 return false; 106 return false;
106 107
107 return true; 108 return true;
108}
109
110void
111conf_node::print ()
112{
113 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %s%s%d\n",
114 id,
115 id >> 8, id & 0xff,
116 compress ? 'Y' : 'N',
117 connectmode == C_ONDEMAND ? "ondemand"
118 : connectmode == C_NEVER ? "never"
119 : connectmode == C_ALWAYS ? "always"
120 : connectmode == C_DISABLED ? "disabled"
121 : "",
122 nodename,
123 hostname ? hostname : "",
124 hostname ? ":" : "",
125 hostname ? udp_port : 0
126 );
127} 109}
128 110
129conf_node::~conf_node () 111conf_node::~conf_node ()
130{ 112{
131#if 0 113#if 0
170 default_node.if_up_data = strdup (""); 152 default_node.if_up_data = strdup ("");
171 153
172#if ENABLE_DNS 154#if ENABLE_DNS
173 default_node.dns_port = 0; // default is 0 == client 155 default_node.dns_port = 0; // default is 0 == client
174 156
157 dns_case_preserving = true;
175 dns_forw_host = strdup ("127.0.0.1"); 158 dns_forw_host = strdup ("127.0.0.1");
176 dns_forw_port = 53; 159 dns_forw_port = 53;
177 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR; 160 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR;
178 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL; 161 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL;
179 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR; 162 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR;
180 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING; 163 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING;
181#endif 164#endif
182 165
183 conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid"); 166 pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid");
167 seed_dev = strdup ("/dev/urandom");
168 reseed = DEFAULT_RESEED;
184} 169}
185 170
186void 171void
187configuration::cleanup () 172configuration::cleanup ()
188{ 173{
189 if (rsa_key) 174 if (rsa_key)
190 RSA_free (rsa_key); 175 RSA_free (rsa_key);
191 176
192 rsa_key = 0; 177 rsa_key = 0;
193 178
179 free (seed_dev); seed_dev = 0;
194 free (pidfilename); pidfilename = 0; 180 free (pidfilename); pidfilename = 0;
195 free (ifname); ifname = 0; 181 free (ifname); ifname = 0;
196#if ENABLE_HTTP_PROXY 182#if ENABLE_HTTP_PROXY
197 free (proxy_host); proxy_host = 0; 183 free (proxy_host); proxy_host = 0;
198 free (proxy_auth); proxy_auth = 0; 184 free (proxy_auth); proxy_auth = 0;
199#endif 185#endif
200#if ENABLE_DNS 186#if ENABLE_DNS
201 free (dns_forw_host); dns_forw_host = 0; 187 free (dns_forw_host); dns_forw_host = 0;
202#endif 188#endif
189 free (change_root); change_root = 0;
203 free (script_if_up); script_if_up = 0; 190 free (script_if_up); script_if_up = 0;
204 free (script_node_up); script_node_up = 0; 191 free (script_node_up); script_node_up = 0;
205 free (script_node_change); script_node_change = 0; 192 free (script_node_change); script_node_change = 0;
206 free (script_node_down); script_node_down = 0; 193 free (script_node_down); script_node_down = 0;
207} 194}
215 nodes.clear (); 202 nodes.clear ();
216 203
217 cleanup (); 204 cleanup ();
218 init (); 205 init ();
219} 206}
207
208//static bool
209//is_true (const char *name)
210//{
211 //re
212//}
220 213
221#define parse_bool(target,name,trueval,falseval) do { \ 214#define parse_bool(target,name,trueval,falseval) do { \
222 if (!strcmp (val, "yes")) target = trueval; \ 215 if (!strcmp (val, "yes")) target = trueval; \
223 else if (!strcmp (val, "no")) target = falseval; \ 216 else if (!strcmp (val, "no")) target = falseval; \
224 else if (!strcmp (val, "true")) target = trueval; \ 217 else if (!strcmp (val, "true")) target = trueval; \
225 else if (!strcmp (val, "false")) target = falseval; \ 218 else if (!strcmp (val, "false")) target = falseval; \
226 else if (!strcmp (val, "on")) target = trueval; \ 219 else if (!strcmp (val, "on")) target = trueval; \
227 else if (!strcmp (val, "off")) target = falseval; \ 220 else if (!strcmp (val, "off")) target = falseval; \
228 else \ 221 else \
229 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed. (ignored)"); \ 222 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed, ignored"); \
230} while (0) 223} while (0)
231 224
232const char * 225const char *
233configuration_parser::parse_line (char *line) 226configuration_parser::parse_line (char *line)
234{ 227{
252 return 0; /* comment: ignore */ 245 return 0; /* comment: ignore */
253 246
254 char *val = strtok (NULL, "\t\n\r ="); 247 char *val = strtok (NULL, "\t\n\r =");
255 248
256 if (!val || val[0] == '#') 249 if (!val || val[0] == '#')
257 return _("no value given for variable. (ignored)"); 250 return _("no value given for variable, ignored");
258 251
259 if (!strcmp (var, "on")) 252 else if (!strcmp (var, "on"))
260 { 253 {
261 if (!::thisnode 254 if (::thisnode
262 || (val[0] == '!' && strcmp (val + 1, ::thisnode)) 255 && ((val[0] == '!' && strcmp (val + 1, ::thisnode))
263 || !strcmp (val, ::thisnode)) 256 || !strcmp (val, ::thisnode)))
264 return parse_line (strtok (NULL, "\n\r")); 257 return parse_line (strtok (NULL, "\n\r"));
265 else 258 }
266 return 0; 259
260 else if (!strcmp (var, "include"))
261 {
262 char *fname = conf.config_filename (val);
263 parse_file (fname);
264 free (fname);
267 } 265 }
268 266
269 // truly global 267 // truly global
270 if (!strcmp (var, "loglevel")) 268 else if (!strcmp (var, "loglevel"))
271 { 269 {
272 loglevel l = string_to_loglevel (val); 270 loglevel l = string_to_loglevel (val);
273 271
274 if (l == L_NONE) 272 if (l == L_NONE)
275 return _("unknown loglevel. (skipping)"); 273 return _("unknown loglevel, ignored");
276 } 274 }
277 else if (!strcmp (var, "ip-proto")) 275 else if (!strcmp (var, "ip-proto"))
278 conf.ip_proto = atoi (val); 276 conf.ip_proto = atoi (val);
279 else if (!strcmp (var, "icmp-type")) 277 else if (!strcmp (var, "icmp-type"))
280 { 278 {
281#if ENABLE_ICMP 279#if ENABLE_ICMP
282 conf.icmp_type = atoi (val); 280 conf.icmp_type = atoi (val);
283#endif 281#endif
284 } 282 }
283 else if (!strcmp (var, "chuser"))
284 {
285 struct passwd *pw = getpwnam (val);
286 if (!pw)
287 return _("user specified for chuser not found");
285 288
286 // per config 289 conf.change_uid = pw->pw_uid;
290 conf.change_gid = pw->pw_gid;
291 }
292 else if (!strcmp (var, "chuid"))
293 conf.change_uid = atoi (val);
294 else if (!strcmp (var, "chgid"))
295 conf.change_gid = atoi (val);
296 else if (!strcmp (var, "chroot"))
297 free (conf.change_root), conf.change_root = strdup (val);
298
299 // per node
287 else if (!strcmp (var, "node")) 300 else if (!strcmp (var, "node"))
288 { 301 {
289 parse_argv (); 302 parse_argv ();
290 303
291 conf.default_node.id++; 304 conf.default_node.id++;
341 conf.keepalive = atoi (val); 354 conf.keepalive = atoi (val);
342 else if (!strcmp (var, "mtu")) 355 else if (!strcmp (var, "mtu"))
343 conf.mtu = atoi (val); 356 conf.mtu = atoi (val);
344 else if (!strcmp (var, "nfmark")) 357 else if (!strcmp (var, "nfmark"))
345 conf.nfmark = atoi (val); 358 conf.nfmark = atoi (val);
359 else if (!strcmp (var, "seed-device"))
360 free (conf.seed_dev), conf.seed_dev = strdup (val);
361 else if (!strcmp (var, "seed-interval"))
362 conf.reseed = atoi (val);
346 else if (!strcmp (var, "if-up")) 363 else if (!strcmp (var, "if-up"))
347 free (conf.script_if_up), conf.script_if_up = strdup (val); 364 free (conf.script_if_up), conf.script_if_up = strdup (val);
348 else if (!strcmp (var, "node-up")) 365 else if (!strcmp (var, "node-up"))
349 free (conf.script_node_up), conf.script_node_up = strdup (val); 366 free (conf.script_node_up), conf.script_node_up = strdup (val);
350 else if (!strcmp (var, "node-change")) 367 else if (!strcmp (var, "node-change"))
387 { 404 {
388#if ENABLE_DNS 405#if ENABLE_DNS
389 conf.dns_max_outstanding = atoi (val); 406 conf.dns_max_outstanding = atoi (val);
390#endif 407#endif
391 } 408 }
409 else if (!strcmp (var, "dns-case-preserving"))
410 {
411#if ENABLE_DNS
412 parse_bool (conf.dns_case_preserving, "dns-case-preserving", true, false);
413#endif
414 }
392 else if (!strcmp (var, "http-proxy-host")) 415 else if (!strcmp (var, "http-proxy-host"))
393 { 416 {
394#if ENABLE_HTTP_PROXY 417#if ENABLE_HTTP_PROXY
395 free (conf.proxy_host), conf.proxy_host = strdup (val); 418 free (conf.proxy_host), conf.proxy_host = strdup (val);
396#endif 419#endif
450 else if (!strcmp (val, "always")) 473 else if (!strcmp (val, "always"))
451 node->connectmode = conf_node::C_ALWAYS; 474 node->connectmode = conf_node::C_ALWAYS;
452 else if (!strcmp (val, "disabled")) 475 else if (!strcmp (val, "disabled"))
453 node->connectmode = conf_node::C_DISABLED; 476 node->connectmode = conf_node::C_DISABLED;
454 else 477 else
455 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled'. (ignored)"); 478 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', ignored");
456 } 479 }
457 else if (!strcmp (var, "inherit-tos")) 480 else if (!strcmp (var, "inherit-tos"))
458 parse_bool (node->inherit_tos, "inherit-tos", true, false); 481 parse_bool (node->inherit_tos, "inherit-tos", true, false);
459 else if (!strcmp (var, "compress")) 482 else if (!strcmp (var, "compress"))
460 parse_bool (node->compress, "compress", true, false); 483 parse_bool (node->compress, "compress", true, false);
494 else if (!strcmp (var, "max-queue")) 517 else if (!strcmp (var, "max-queue"))
495 node->max_queue = atoi (val); 518 node->max_queue = atoi (val);
496 519
497 // unknown or misplaced 520 // unknown or misplaced
498 else 521 else
499 return _("unknown configuration directive. (ignored)"); 522 return _("unknown configuration directive - ignored");
500 523
501 return 0; 524 return 0;
502} 525}
503 526
504void 527void
547 if (warn) 570 if (warn)
548 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v); 571 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v);
549 572
550 *v = 0; 573 *v = 0;
551 } 574 }
575 }
576}
577
578void
579configuration_parser::parse_file (const char *fname)
580{
581 if (FILE *f = fopen (fname, "r"))
582 {
583 char line [2048];
584 int lineno = 0;
585
586 while (fgets (line, sizeof (line), f))
587 {
588 lineno++;
589
590 const char *warn = parse_line (line);
591
592 if (warn)
593 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
594 }
595
596 fclose (f);
597
598 parse_argv ();
599 }
600 else
601 {
602 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
603 exit (EXIT_FAILURE);
552 } 604 }
553} 605}
554 606
555configuration_parser::configuration_parser (configuration &conf, 607configuration_parser::configuration_parser (configuration &conf,
556 bool need_keys, 608 bool need_keys,
557 int argc, 609 int argc,
558 char **argv) 610 char **argv)
559: conf (conf),need_keys (need_keys), argc (argc), argv (argv) 611: conf (conf),need_keys (need_keys), argc (argc), argv (argv)
560{ 612{
561 char *fname; 613 char *fname;
562 FILE *f;
563 614
564 conf.clear (); 615 conf.clear ();
616 node = &conf.default_node;
565 617
566 asprintf (&fname, "%s/gvpe.conf", confbase); 618 asprintf (&fname, "%s/gvpe.conf", confbase);
567 f = fopen (fname, "r"); 619 parse_file (fname);
568
569 if (f)
570 {
571 char line[16384];
572 int lineno = 0;
573 node = &conf.default_node;
574
575 while (fgets (line, sizeof (line), f))
576 {
577 lineno++;
578
579 const char *warn = parse_line (line);
580
581 if (warn)
582 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
583 }
584
585 fclose (f);
586
587 parse_argv ();
588 }
589 else
590 {
591 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
592 exit (EXIT_FAILURE);
593 }
594
595 free (fname); 620 free (fname);
596 621
597 fname = conf.config_filename (conf.prikeyfile, "hostkey"); 622 fname = conf.config_filename (conf.prikeyfile, "hostkey");
598 623
599 f = fopen (fname, "r"); 624 if (FILE *f = fopen (fname, "r"))
600 if (f)
601 { 625 {
602 conf.rsa_key = RSA_new (); 626 conf.rsa_key = RSA_new ();
603 627
604 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL)) 628 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL))
605 { 629 {
617 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno)); 641 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
618 642
619 if (need_keys) 643 if (need_keys)
620 exit (EXIT_FAILURE); 644 exit (EXIT_FAILURE);
621 } 645 }
646
647 free (fname);
622 648
623 if (need_keys && ::thisnode 649 if (need_keys && ::thisnode
624 && conf.rsa_key && conf.thisnode && conf.thisnode->rsa_key) 650 && conf.rsa_key && conf.thisnode && conf.thisnode->rsa_key)
625 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0 651 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
626 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0) 652 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
627 { 653 {
628 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode); 654 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
629 exit (EXIT_FAILURE); 655 exit (EXIT_FAILURE);
630 } 656 }
631 657
632 free (fname);
633
634 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i) 658 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
635 (*i)->finalise (); 659 (*i)->finalise ();
636} 660}
637 661
638char * 662char *
648 asprintf (&fname, "%s/%s", confbase, rname); 672 asprintf (&fname, "%s/%s", confbase, rname);
649 free (rname); 673 free (rname);
650 } 674 }
651 675
652 return fname; 676 return fname;
677}
678
679void
680conf_node::print ()
681{
682 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %02x %s%s%d\n",
683 id,
684 id >> 8, id & 0xff,
685 compress ? 'Y' : 'N',
686 connectmode == C_ONDEMAND ? "ondemand"
687 : connectmode == C_NEVER ? "never"
688 : connectmode == C_ALWAYS ? "always"
689 : connectmode == C_DISABLED ? "disabled"
690 : "",
691 nodename,
692 protocols,
693 hostname ? hostname : "",
694 hostname ? ":" : "",
695 hostname ? udp_port : 0
696 );
653} 697}
654 698
655void 699void
656configuration::print () 700configuration::print ()
657{ 701{
664 printf (_("interface: %s\n"), ifname); 708 printf (_("interface: %s\n"), ifname);
665 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>"); 709 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
666 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1); 710 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1);
667 printf ("\n"); 711 printf ("\n");
668 712
669 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n", 713 printf ("%4s %-17s %s %-8.8s %-10.10s %04s %s\n",
670 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port")); 714 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Prot"), _("Host:Port"));
671 715
672 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i) 716 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
673 (*i)->print (); 717 (*i)->print ();
674 718
675 printf ("\n"); 719 printf ("\n");

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines