ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
(Generate patch)

Comparing gvpe/src/conf.C (file contents):
Revision 1.3 by pcg, Sun Mar 9 12:40:18 2003 UTC vs.
Revision 1.42 by pcg, Mon Dec 5 12:58:08 2005 UTC

1/* 1/*
2 conf.c -- configuration code 2 conf.c -- configuration code
3 Copyright (C) 1998 Robert van der Meulen 3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de>
4 1998-2002 Ivo Timmermans <ivo@o2w.nl>
5 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
6 2000 Cris van Pelt <tribbel@arise.dhs.org>
7 2003 Marc Lehmann <pcg@goof.com>
8 4
5 This file is part of GVPE.
6
9 This program is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by 8 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 2 of the License, or 9 the Free Software Foundation; either version 2 of the License, or
12 (at your option) any later version. 10 (at your option) any later version.
13 11
14 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details. 15 GNU General Public License for more details.
18 16
19 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License
20 along with this program; if not, write to the Free Software 18 along with gvpe; if not, write to the Free Software
21 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19 Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
22*/ 20*/
23 21
24#include "config.h" 22#include "config.h"
25 23
26#include <cstdio> 24#include <cstdio>
31#include <netdb.h> 29#include <netdb.h>
32#include <sys/stat.h> 30#include <sys/stat.h>
33#include <sys/types.h> 31#include <sys/types.h>
34#include <unistd.h> 32#include <unistd.h>
35 33
34#include "netcompat.h"
35
36#include <openssl/err.h> 36#include <openssl/err.h>
37#include <openssl/pem.h> 37#include <openssl/pem.h>
38#include <openssl/rsa.h> 38#include <openssl/rsa.h>
39#include <openssl/rand.h> 39#include <openssl/rand.h>
40 40#include <openssl/bn.h>
41#include "gettext.h"
42 41
43#include "conf.h" 42#include "conf.h"
44#include "slog.h" 43#include "slog.h"
45#include "util.h" 44#include "util.h"
46 45
47char *confbase; 46char *confbase;
48char *thisnode; 47char *thisnode;
49char *identname; 48char *identname;
50char *pidfilename;
51 49
52struct configuration conf; 50struct configuration conf;
53 51
54configuration::configuration () 52u8 best_protocol (u8 protset)
55{ 53{
56 init (); 54 if (protset & PROT_IPv4 ) return PROT_IPv4;
57} 55 if (protset & PROT_ICMPv4) return PROT_ICMPv4;
56 if (protset & PROT_UDPv4 ) return PROT_UDPv4;
57 if (protset & PROT_TCPv4 ) return PROT_TCPv4;
58 if (protset & PROT_DNSv4 ) return PROT_DNSv4;
58 59
59configuration::~configuration () 60 return 0;
60{
61 cleanup ();
62} 61}
63 62
64void configuration::init () 63const char *strprotocol (u8 protocol)
65{ 64{
66 memset (this, 0, sizeof (*this)); 65 if (protocol & PROT_IPv4 ) return "rawip";
66 if (protocol & PROT_ICMPv4) return "icmp";
67 if (protocol & PROT_UDPv4 ) return "udp";
68 if (protocol & PROT_TCPv4 ) return "tcp";
69 if (protocol & PROT_DNSv4 ) return "dns";
67 70
68 rekey = DEFAULT_REKEY; 71 return "<unknown>";
69 keepalive = DEFAULT_KEEPALIVE;
70 llevel = L_INFO;
71
72 default_node.port = DEFAULT_PORT;
73 default_node.connectmode = conf_node::C_ALWAYS;
74 default_node.compress = true;
75} 72}
76 73
77void configuration::cleanup() 74static bool
75match_list (const vector<const char *> &list, const char *str)
78{ 76{
79 if (rsa_key) 77 for (vector<const char *>::const_iterator i = list.end (); i-- > list.begin (); )
80 RSA_free (rsa_key); 78 if ((*i)[0] == '*' && !(*i)[1])
79 return true;
80 else if (!strcmp (*i, str))
81 return true;
81 82
82 free (ifname);
83
84 rsa_key = 0;
85 ifname = 0;
86}
87
88void
89configuration::clear_config ()
90{
91 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
92 delete *i;
93
94 nodes.clear ();
95
96 cleanup ();
97 init ();
98}
99
100void configuration::read_config (bool need_keys)
101{
102 char *fname;
103 FILE *f;
104
105 clear_config ();
106
107 asprintf (&fname, "%s/vped.conf", confbase);
108 f = fopen (fname, "r");
109
110 if (f)
111 {
112 char line[16384];
113 int lineno = 0;
114 char *var, *val;
115 conf_node *node = &default_node;
116
117 while (fgets (line, sizeof (line), f))
118 {
119 lineno++;
120
121 {
122 char *end = line + strlen (line);
123
124 while (*end < ' ' && end >= line)
125 end--;
126
127 *++end = 0;
128 }
129
130 char *tok = line;
131
132retry:
133 var = strtok (tok, "\t =");
134 tok = 0;
135
136 if (!var || !var[0])
137 continue; /* no tokens on this line */
138
139 if (var[0] == '#')
140 continue; /* comment: ignore */
141
142 val = strtok (NULL, "\t\n\r =");
143
144 if (!val || val[0] == '#')
145 {
146 slog (L_WARN,
147 _("no value for variable `%s', at '%s' line %d"),
148 var, fname, lineno);
149 break;
150 }
151
152 if (!strcmp (var, "on"))
153 {
154 if (!::thisnode
155 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
156 || !strcmp (val, ::thisnode))
157 goto retry;
158
159 continue;
160 }
161
162 // truly global
163 if (!strcmp (var, "loglevel"))
164 {
165 loglevel l = string_to_loglevel (val);
166
167 if (l != L_NONE)
168 llevel = l;
169 else
170 slog (L_WARN, "'%s': %s, at '%s' line %d", val, UNKNOWN_LOGLEVEL, fname, line);
171 }
172
173 // per config
174 else if (!strcmp (var, "node"))
175 {
176 default_node.id++;
177
178 node = new conf_node (default_node);
179
180 nodes.push_back (node);
181
182 node->nodename = strdup (val);
183
184 {
185 char *fname;
186 FILE *f;
187
188 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
189
190 f = fopen (fname, "r");
191 if (f)
192 {
193 node->rsa_key = RSA_new ();
194
195 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
196 {
197 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
198 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
199 exit (1);
200 }
201
202 RSA_blinding_on (node->rsa_key, 0);
203
204 fclose (f);
205 }
206 else
207 {
208 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
209
210 if (need_keys)
211 exit (1);
212 }
213
214 free (fname);
215 }
216
217 if (!::thisnode || !strcmp (node->nodename, ::thisnode))
218 thisnode = node;
219 }
220 else if (!strcmp (var, "private-key"))
221 prikeyfile = strdup (val);
222 else if (!strcmp (var, "ifpersist"))
223 {
224 if (!strcmp (val, "yes"))
225 ifpersist = true;
226 else if (!strcmp (val, "no"))
227 ifpersist = false;
228 else
229 slog (L_WARN,
230 _("illegal value for 'ifpersist', only 'yes' or 'no' allowed, at '%s' line %d"),
231 var, fname, lineno);
232 }
233 else if (!strcmp (var, "ifname"))
234 ifname = strdup (val);
235 else if (!strcmp (var, "rekey"))
236 rekey = atoi (val);
237 else if (!strcmp (var, "keepalive"))
238 keepalive = atoi (val);
239 else if (!strcmp (var, "mtu"))
240 mtu = atoi (val);
241 else if (!strcmp (var, "if-up"))
242 script_if_up = strdup (val);
243 else if (!strcmp (var, "node-up"))
244 script_node_up = strdup (val);
245 else if (!strcmp (var, "node-down"))
246 script_node_down = strdup (val);
247
248 /* node-specific, non-defaultable */
249 else if (node != &default_node && !strcmp (var, "hostname"))
250 {
251 free (node->hostname);
252 node->hostname = strdup (val);
253 }
254
255 /* node-specific, defaultable */
256 else if (!strcmp (var, "port"))
257 node->port = atoi (val);
258 else if (!strcmp (var, "router-priority"))
259 node->routerprio = atoi (val);
260 else if (!strcmp (var, "connect"))
261 {
262 if (!strcmp (val, "ondemand"))
263 node->connectmode = conf_node::C_ONDEMAND;
264 else if (!strcmp (val, "never"))
265 node->connectmode = conf_node::C_NEVER;
266 else if (!strcmp (val, "always"))
267 node->connectmode = conf_node::C_ALWAYS;
268 else
269 slog (L_WARN,
270 _("illegal value for 'connectmode', use one of 'ondemand', 'never' or 'always', at '%s' line %d"),
271 var, fname, lineno);
272 }
273 else if (!strcmp (var, "inherit-tos"))
274 {
275 if (!strcmp (val, "yes"))
276 node->inherit_tos = true;
277 else if (!strcmp (val, "no"))
278 node->inherit_tos = false;
279 else
280 slog (L_WARN,
281 _("illegal value for 'compress', only 'yes' or 'no' allowed, at '%s' line %d"),
282 var, fname, lineno);
283 }
284
285 else if (!strcmp (var, "compress"))
286 {
287 if (!strcmp (val, "yes"))
288 node->compress = true;
289 else if (!strcmp (val, "no"))
290 node->compress = false;
291 else
292 slog (L_WARN,
293 _("illegal value for 'compress', only 'yes' or 'no' allowed, at '%s' line %d"),
294 var, fname, lineno);
295 }
296
297 // unknown or misplaced
298 else
299 {
300 slog (L_WARN,
301 _("unknown or misplaced variable `%s', at '%s' line %d"),
302 var, fname, lineno);
303 }
304 }
305
306 fclose (f);
307 }
308 else
309 {
310 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
311 exit (1);
312 }
313
314 free (fname);
315
316 fname = config_filename (prikeyfile, "hostkey");
317
318 f = fopen (fname, "r");
319 if (f)
320 {
321 rsa_key = RSA_new ();
322
323 if (!PEM_read_RSAPrivateKey (f, &rsa_key, NULL, NULL))
324 {
325 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
326 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
327 exit (1);
328 }
329
330 RSA_blinding_on (rsa_key, 0);
331
332 fclose (f);
333 }
334 else
335 {
336 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
337
338 if (need_keys)
339 exit (1);
340 }
341
342 free (fname);
343}
344
345char *configuration::config_filename (const char *name, const char *dflt)
346{
347 char *fname;
348
349 asprintf (&fname, name ? name : dflt, ::thisnode);
350
351 if (!ABSOLUTE_PATH (fname))
352 {
353 char *rname = fname;
354 asprintf (&fname, "%s/%s", confbase, rname);
355 free (rname);
356 }
357
358 return fname; 83 return false;
359} 84}
360 85
361void 86bool
362configuration::print () 87conf_node::can_direct (struct conf_node *other)
363{ 88{
364 printf (_("\nConfiguration\n\n")); 89 if (match_list (allow_direct, other->nodename))
365 printf (_("# of nodes: %d\n"), nodes.size ()); 90 return true;
366 printf (_("this node: %s\n"), thisnode ? thisnode->nodename : "<unset>");
367 printf (_("MTU: %d\n"), mtu);
368 printf (_("rekeying interval: %d\n"), rekey);
369 printf (_("keepalive interval: %d\n"), keepalive);
370 printf (_("interface: %s\n"), ifname);
371 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
372 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) : -1);
373 printf ("\n");
374 91
375 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n", 92 if (match_list (deny_direct, other->nodename))
376 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port")); 93 return false;
377 94
378 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i) 95 return true;
379 (*i)->print ();
380
381 printf ("\n");
382} 96}
383 97
384void 98void
385conf_node::print () 99conf_node::print ()
386{ 100{
392 connectmode == C_NEVER ? "never" : 106 connectmode == C_NEVER ? "never" :
393 connectmode == C_ALWAYS ? "always" : "", 107 connectmode == C_ALWAYS ? "always" : "",
394 nodename, 108 nodename,
395 hostname ? hostname : "", 109 hostname ? hostname : "",
396 hostname ? ":" : "", 110 hostname ? ":" : "",
397 hostname ? port : 0 111 hostname ? udp_port : 0
398 ); 112 );
399} 113}
400 114
115conf_node::~conf_node ()
116{
117#if 0
118 // does not work, because string pointers etc. are shared
119 // is not called, however
120 if (rsa_key)
121 RSA_free (rsa_key);
122
123 free (nodename);
124 free (hostname);
125 free (if_up_data);
126#if ENABLE_DNS
127 free (domain);
128 free (dns_hostname);
129#endif
130#endif
131}
132
133void configuration::init ()
134{
135 memset (this, 0, sizeof (*this));
136
137 mtu = DEFAULT_MTU;
138 rekey = DEFAULT_REKEY;
139 keepalive = DEFAULT_KEEPALIVE;
140 llevel = L_INFO;
141 ip_proto = IPPROTO_GRE;
142#if ENABLE_ICMP
143 icmp_type = ICMP_ECHOREPLY;
144#endif
145
146 default_node.udp_port = DEFAULT_UDPPORT;
147 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm
148 default_node.connectmode = conf_node::C_ALWAYS;
149 default_node.compress = true;
150 default_node.protocols = 0;
151 default_node.max_retry = DEFAULT_MAX_RETRY;
152 default_node.if_up_data = strdup ("");
153
154#if ENABLE_DNS
155 default_node.dns_port = 0; // default is 0 == client
156
157 dns_forw_host = strdup ("127.0.0.1");
158 dns_forw_port = 53;
159 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR;
160 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL;
161 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR;
162 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING;
163#endif
164
165 conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid");
166}
167
168void configuration::cleanup()
169{
170 if (rsa_key)
171 RSA_free (rsa_key);
172
173 rsa_key = 0;
174
175 free (pidfilename); pidfilename = 0;
176 free (ifname); ifname = 0;
177#if ENABLE_HTTP_PROXY
178 free (proxy_host); proxy_host = 0;
179 free (proxy_auth); proxy_auth = 0;
180#endif
181#if ENABLE_DNS
182 free (dns_forw_host); dns_forw_host = 0;
183#endif
184}
185
186void
187configuration::clear ()
188{
189 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
190 delete *i;
191
192 nodes.clear ();
193
194 cleanup ();
195 init ();
196}
197
198#define parse_bool(target,name,trueval,falseval) do { \
199 if (!strcmp (val, "yes")) target = trueval; \
200 else if (!strcmp (val, "no")) target = falseval; \
201 else if (!strcmp (val, "true")) target = trueval; \
202 else if (!strcmp (val, "false")) target = falseval; \
203 else if (!strcmp (val, "on")) target = trueval; \
204 else if (!strcmp (val, "off")) target = falseval; \
205 else \
206 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed. (ignored)"); \
207} while (0)
208
209const char *
210configuration_parser::parse_line (char *line)
211{
212 {
213 char *end = line + strlen (line);
214
215 while (*end < ' ' && end >= line)
216 end--;
217
218 *++end = 0;
219 }
220
221 char *tok = line;
222 const char *var = strtok (tok, "\t =");
223 tok = 0;
224
225 if (!var || !var[0])
226 return 0; /* no tokens on this line */
227
228 if (var[0] == '#')
229 return 0; /* comment: ignore */
230
231 char *val = strtok (NULL, "\t\n\r =");
232
233 if (!val || val[0] == '#')
234 return _("no value given for variable. (ignored)");
235
236 if (!strcmp (var, "on"))
237 {
238 if (!::thisnode
239 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
240 || !strcmp (val, ::thisnode))
241 return parse_line (strtok (NULL, "\n\r"));
242 else
243 return 0;
244 }
245
246 // truly global
247 if (!strcmp (var, "loglevel"))
248 {
249 loglevel l = string_to_loglevel (val);
250
251 if (l == L_NONE)
252 return _("unknown loglevel. (skipping)");
253 }
254 else if (!strcmp (var, "ip-proto"))
255 conf.ip_proto = atoi (val);
256 else if (!strcmp (var, "icmp-type"))
257 {
258#if ENABLE_ICMP
259 conf.icmp_type = atoi (val);
260#endif
261 }
262
263 // per config
264 else if (!strcmp (var, "node"))
265 {
266 parse_argv ();
267
268 conf.default_node.id++;
269 node = new conf_node (conf.default_node);
270 conf.nodes.push_back (node);
271 node->nodename = strdup (val);
272
273 {
274 char *fname;
275 FILE *f;
276
277 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
278
279 f = fopen (fname, "r");
280 if (f)
281 {
282 node->rsa_key = RSA_new ();
283
284 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
285 {
286 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
287 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
288 exit (EXIT_FAILURE);
289 }
290
291 require (RSA_blinding_on (node->rsa_key, 0));
292
293 fclose (f);
294 }
295 else
296 {
297 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
298
299 if (need_keys)
300 exit (EXIT_FAILURE);
301 }
302
303 free (fname);
304 }
305
306 if (::thisnode && !strcmp (node->nodename, ::thisnode))
307 conf.thisnode = node;
308 }
309 else if (!strcmp (var, "private-key"))
310 free (conf.prikeyfile), conf.prikeyfile = strdup (val);
311 else if (!strcmp (var, "ifpersist"))
312 parse_bool (conf.ifpersist, "ifpersist", true, false);
313 else if (!strcmp (var, "ifname"))
314 free (conf.ifname), conf.ifname = strdup (val);
315 else if (!strcmp (var, "rekey"))
316 conf.rekey = atoi (val);
317 else if (!strcmp (var, "keepalive"))
318 conf.keepalive = atoi (val);
319 else if (!strcmp (var, "mtu"))
320 conf.mtu = atoi (val);
321 else if (!strcmp (var, "if-up"))
322 free (conf.script_if_up), conf.script_if_up = strdup (val);
323 else if (!strcmp (var, "node-up"))
324 free (conf.script_node_up), conf.script_node_up = strdup (val);
325 else if (!strcmp (var, "node-down"))
326 free (conf.script_node_down), conf.script_node_down = strdup (val);
327 else if (!strcmp (var, "pid-file"))
328 free (conf.pidfilename), conf.pidfilename = strdup (val);
329 else if (!strcmp (var, "dns-forw-host"))
330 {
331#if ENABLE_DNS
332 free (conf.dns_forw_host), conf.dns_forw_host = strdup (val);
333#endif
334 }
335 else if (!strcmp (var, "dns-forw-port"))
336 {
337#if ENABLE_DNS
338 conf.dns_forw_port = atoi (val);
339#endif
340 }
341 else if (!strcmp (var, "dns-timeout-factor"))
342 {
343#if ENABLE_DNS
344 conf.dns_timeout_factor = atof (val);
345#endif
346 }
347 else if (!strcmp (var, "dns-send-interval"))
348 {
349#if ENABLE_DNS
350 conf.dns_send_interval = atoi (val);
351#endif
352 }
353 else if (!strcmp (var, "dns-overlap-factor"))
354 {
355#if ENABLE_DNS
356 conf.dns_overlap_factor = atof (val);
357#endif
358 }
359 else if (!strcmp (var, "dns-max-outstanding"))
360 {
361#if ENABLE_DNS
362 conf.dns_max_outstanding = atoi (val);
363#endif
364 }
365 else if (!strcmp (var, "http-proxy-host"))
366 {
367#if ENABLE_HTTP_PROXY
368 free (conf.proxy_host), conf.proxy_host = strdup (val);
369#endif
370 }
371 else if (!strcmp (var, "http-proxy-port"))
372 {
373#if ENABLE_HTTP_PROXY
374 conf.proxy_port = atoi (val);
375#endif
376 }
377 else if (!strcmp (var, "http-proxy-auth"))
378 {
379#if ENABLE_HTTP_PROXY
380 conf.proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
381#endif
382 }
383
384 /* node-specific, non-defaultable */
385 else if (node != &conf.default_node && !strcmp (var, "hostname"))
386 free (node->hostname), node->hostname = strdup (val);
387
388 /* node-specific, defaultable */
389 else if (!strcmp (var, "udp-port"))
390 node->udp_port = atoi (val);
391 else if (!strcmp (var, "tcp-port"))
392 node->tcp_port = atoi (val);
393 else if (!strcmp (var, "dns-hostname"))
394 {
395#if ENABLE_DNS
396 free (node->dns_hostname), node->dns_hostname = strdup (val);
397#endif
398 }
399 else if (!strcmp (var, "dns-port"))
400 {
401#if ENABLE_DNS
402 node->dns_port = atoi (val);
403#endif
404 }
405 else if (!strcmp (var, "dns-domain"))
406 {
407#if ENABLE_DNS
408 free (node->domain), node->domain = strdup (val);
409#endif
410 }
411 else if (!strcmp (var, "if-up-data"))
412 free (node->if_up_data), node->if_up_data = strdup (val);
413 else if (!strcmp (var, "router-priority"))
414 node->routerprio = atoi (val);
415 else if (!strcmp (var, "max-retry"))
416 node->max_retry = atoi (val);
417 else if (!strcmp (var, "connect"))
418 {
419 if (!strcmp (val, "ondemand"))
420 node->connectmode = conf_node::C_ONDEMAND;
421 else if (!strcmp (val, "never"))
422 node->connectmode = conf_node::C_NEVER;
423 else if (!strcmp (val, "always"))
424 node->connectmode = conf_node::C_ALWAYS;
425 else if (!strcmp (val, "disabled"))
426 node->connectmode = conf_node::C_DISABLED;
427 else
428 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled'. (ignored)");
429 }
430 else if (!strcmp (var, "inherit-tos"))
431 parse_bool (node->inherit_tos, "inherit-tos", true, false);
432 else if (!strcmp (var, "compress"))
433 parse_bool (node->compress, "compress", true, false);
434 // all these bool options really really cost a lot of executable size!
435 else if (!strcmp (var, "enable-tcp"))
436 {
437#if ENABLE_TCP
438 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
439#endif
440 }
441 else if (!strcmp (var, "enable-icmp"))
442 {
443#if ENABLE_ICMP
444 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
445#endif
446 }
447 else if (!strcmp (var, "enable-dns"))
448 {
449#if ENABLE_DNS
450 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
451#endif
452 }
453 else if (!strcmp (var, "enable-udp"))
454 {
455 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
456 }
457 else if (!strcmp (var, "enable-rawip"))
458 {
459 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
460 }
461 else if (!strcmp (var, "allow-direct"))
462 node->allow_direct.push_back (strdup (val));
463 else if (!strcmp (var, "deny-direct"))
464 node->deny_direct.push_back (strdup (val));
465
466 // unknown or misplaced
467 else
468 return _("unknown configuration directive. (ignored)");
469
470 return 0;
471}
472
473void configuration_parser::parse_argv ()
474{
475 for (int i = 0; i < argc; ++i)
476 {
477 char *v = argv [i];
478
479 if (!*v)
480 continue;
481
482 char *enode = v;
483
484 while (*enode != '.' && *enode > ' ' && *enode != '=' && *enode)
485 enode++;
486
487 if (*enode != '.')
488 enode = 0;
489
490 char *wnode = node == &conf.default_node
491 ? 0
492 : node->nodename;
493
494 if ((!wnode && !enode)
495 || (wnode && enode && !strncmp (wnode, v, enode - v)))
496 {
497 const char *warn = parse_line (enode ? enode + 1 : v);
498
499 if (warn)
500 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v);
501
502 *v = 0;
503 }
504 }
505}
506
507configuration_parser::configuration_parser (configuration &conf,
508 bool need_keys,
509 int argc,
510 char **argv)
511: conf (conf),need_keys (need_keys), argc (argc), argv (argv)
512{
513 char *fname;
514 FILE *f;
515
516 conf.clear ();
517
518 asprintf (&fname, "%s/gvpe.conf", confbase);
519 f = fopen (fname, "r");
520
521 if (f)
522 {
523 char line[16384];
524 int lineno = 0;
525 node = &conf.default_node;
526
527 while (fgets (line, sizeof (line), f))
528 {
529 lineno++;
530
531 const char *warn = parse_line (line);
532
533 if (warn)
534 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
535 }
536
537 fclose (f);
538
539 parse_argv ();
540 }
541 else
542 {
543 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
544 exit (EXIT_FAILURE);
545 }
546
547 free (fname);
548
549 fname = conf.config_filename (conf.prikeyfile, "hostkey");
550
551 f = fopen (fname, "r");
552 if (f)
553 {
554 conf.rsa_key = RSA_new ();
555
556 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL))
557 {
558 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
559 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
560 exit (EXIT_FAILURE);
561 }
562
563 require (RSA_blinding_on (conf.rsa_key, 0));
564
565 fclose (f);
566 }
567 else
568 {
569 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
570
571 if (need_keys)
572 exit (EXIT_FAILURE);
573 }
574
575 if (need_keys && ::thisnode
576 && conf.rsa_key && conf.thisnode && conf.thisnode->rsa_key)
577 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
578 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
579 {
580 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
581 exit (EXIT_FAILURE);
582 }
583
584 free (fname);
585}
586
587char *configuration::config_filename (const char *name, const char *dflt)
588{
589 char *fname;
590
591 asprintf (&fname, name ? name : dflt, ::thisnode);
592
593 if (!ABSOLUTE_PATH (fname))
594 {
595 char *rname = fname;
596 asprintf (&fname, "%s/%s", confbase, rname);
597 free (rname);
598 }
599
600 return fname;
601}
602
603void
604configuration::print ()
605{
606 printf (_("\nConfiguration\n\n"));
607 printf (_("# of nodes: %d\n"), nodes.size ());
608 printf (_("this node: %s\n"), thisnode ? thisnode->nodename : "<unset>");
609 printf (_("MTU: %d\n"), mtu);
610 printf (_("rekeying interval: %d\n"), rekey);
611 printf (_("keepalive interval: %d\n"), keepalive);
612 printf (_("interface: %s\n"), ifname);
613 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
614 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1);
615 printf ("\n");
616
617 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n",
618 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port"));
619
620 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
621 (*i)->print ();
622
623 printf ("\n");
624}
625
626configuration::configuration ()
627{
628 asprintf (&confbase, "%s/gvpe", CONFDIR);
629
630 init ();
631}
632
633configuration::~configuration ()
634{
635 cleanup ();
636}
637
638

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines