ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
(Generate patch)

Comparing gvpe/src/conf.C (file contents):
Revision 1.25 by pcg, Mon May 10 20:13:09 2004 UTC vs.
Revision 1.63 by root, Thu Jul 18 13:35:16 2013 UTC

1/* 1/*
2 conf.c -- configuration code 2 conf.C -- configuration code
3 Copyright (C) 2003-2004 Marc Lehmann <pcg@goof.com> 3 Copyright (C) 2003-2008,2011 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE.
6
5 This program is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify it
6 it under the terms of the GNU General Public License as published by 8 under the terms of the GNU General Public License as published by the
7 the Free Software Foundation; either version 2 of the License, or 9 Free Software Foundation; either version 3 of the License, or (at your
8 (at your option) any later version. 10 option) any later version.
9 11
10 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful, but
11 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
13 GNU General Public License for more details. 15 Public License for more details.
14 16
15 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License along
16 along with this program; if not, write to the Free Software 18 with this program; if not, see <http://www.gnu.org/licenses/>.
17 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
18*/ 30*/
19 31
20#include "config.h" 32#include "config.h"
21 33
22#include <cstdio> 34#include <cstdio>
26#include <errno.h> 38#include <errno.h>
27#include <netdb.h> 39#include <netdb.h>
28#include <sys/stat.h> 40#include <sys/stat.h>
29#include <sys/types.h> 41#include <sys/types.h>
30#include <unistd.h> 42#include <unistd.h>
43#include <pwd.h>
31 44
32#include "netcompat.h" 45#include "netcompat.h"
33 46
34#include <openssl/err.h> 47#include <openssl/err.h>
35#include <openssl/pem.h> 48#include <openssl/pem.h>
36#include <openssl/rsa.h> 49#include <openssl/rsa.h>
37#include <openssl/rand.h> 50#include <openssl/rand.h>
38#include <openssl/bn.h> 51#include <openssl/bn.h>
39 52
40#include "gettext.h"
41
42#include "conf.h" 53#include "conf.h"
43#include "slog.h" 54#include "slog.h"
44#include "util.h" 55#include "util.h"
45 56
46char *confbase; 57char *confbase;
47char *thisnode; 58char *thisnode;
48char *identname; 59char *identname;
49 60
50struct configuration conf; 61struct configuration conf;
51 62
63u8
52u8 best_protocol (u8 protset) 64best_protocol (u8 protset)
53{ 65{
54 if (protset & PROT_IPv4 ) return PROT_IPv4; 66 if (protset & PROT_IPv4 ) return PROT_IPv4;
55 if (protset & PROT_ICMPv4) return PROT_ICMPv4; 67 if (protset & PROT_ICMPv4) return PROT_ICMPv4;
56 if (protset & PROT_UDPv4 ) return PROT_UDPv4; 68 if (protset & PROT_UDPv4 ) return PROT_UDPv4;
57 if (protset & PROT_TCPv4 ) return PROT_TCPv4; 69 if (protset & PROT_TCPv4 ) return PROT_TCPv4;
58 if (protset & PROT_DNSv4 ) return PROT_DNSv4; 70 if (protset & PROT_DNSv4 ) return PROT_DNSv4;
59 71
60 return 0; 72 return 0;
61} 73}
62 74
75const char *
63const char *strprotocol (u8 protocol) 76strprotocol (u8 protocol)
64{ 77{
65 if (protocol & PROT_IPv4 ) return "rawip"; 78 if (protocol & PROT_IPv4 ) return "rawip";
66 if (protocol & PROT_ICMPv4) return "icmp"; 79 if (protocol & PROT_ICMPv4) return "icmp";
67 if (protocol & PROT_UDPv4 ) return "udp"; 80 if (protocol & PROT_UDPv4 ) return "udp";
68 if (protocol & PROT_TCPv4 ) return "tcp"; 81 if (protocol & PROT_TCPv4 ) return "tcp";
69 if (protocol & PROT_DNSv4 ) return "dns"; 82 if (protocol & PROT_DNSv4 ) return "dns";
70 83
71 return "<unknown>"; 84 return "<unknown>";
72} 85}
73 86
74void 87static bool
75conf_node::print () 88match_list (const vector<const char *> &list, const char *str)
76{ 89{
77 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %s%s%d\n", 90 for (vector<const char *>::const_iterator i = list.end (); i-- > list.begin (); )
78 id, 91 if ((*i)[0] == '*' && !(*i)[1])
79 id >> 8, id & 0xff, 92 return true;
80 compress ? 'Y' : 'N', 93 else if (!strcmp (*i, str))
81 connectmode == C_ONDEMAND ? "ondemand" : 94 return true;
82 connectmode == C_NEVER ? "never" : 95
83 connectmode == C_ALWAYS ? "always" : "", 96 return false;
84 nodename, 97}
85 hostname ? hostname : "", 98
86 hostname ? ":" : "", 99bool
87 hostname ? udp_port : 0 100conf_node::may_direct (struct conf_node *other)
88 ); 101{
102 if (match_list (allow_direct, other->nodename))
103 return true;
104
105 if (match_list (deny_direct, other->nodename))
106 return false;
107
108 return true;
89} 109}
90 110
91conf_node::~conf_node () 111conf_node::~conf_node ()
92{ 112{
113#if 0
114 // does not work, because string pointers etc. are shared
115 // is not called, however
93 if (rsa_key) 116 if (rsa_key)
94 RSA_free (rsa_key); 117 RSA_free (rsa_key);
95 118
96 free (nodename); 119 free (nodename);
97 free (hostname); 120 free (hostname);
121 free (if_up_data);
122#if ENABLE_DNS
123 free (domain);
124 free (dns_hostname);
125#endif
126#endif
98} 127}
99 128
129void
100void configuration::init () 130configuration::init ()
101{ 131{
102 asprintf (&confbase, "%s/vpe", CONFDIR);
103
104 memset (this, 0, sizeof (*this)); 132 memset (this, 0, sizeof (*this));
105 133
106 mtu = DEFAULT_MTU; 134 mtu = DEFAULT_MTU;
135 nfmark = 0;
107 rekey = DEFAULT_REKEY; 136 rekey = DEFAULT_REKEY;
108 keepalive = DEFAULT_KEEPALIVE; 137 keepalive = DEFAULT_KEEPALIVE;
109 llevel = L_INFO; 138 llevel = L_INFO;
110 ip_proto = IPPROTO_GRE; 139 ip_proto = IPPROTO_GRE;
111#if ENABLE_ICMP 140#if ENABLE_ICMP
114 143
115 default_node.udp_port = DEFAULT_UDPPORT; 144 default_node.udp_port = DEFAULT_UDPPORT;
116 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm 145 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm
117 default_node.connectmode = conf_node::C_ALWAYS; 146 default_node.connectmode = conf_node::C_ALWAYS;
118 default_node.compress = true; 147 default_node.compress = true;
119 default_node.protocols = PROT_UDPv4; 148 default_node.protocols = 0;
149 default_node.max_retry = DEFAULT_MAX_RETRY;
150 default_node.max_ttl = DEFAULT_MAX_TTL;
151 default_node.max_queue = DEFAULT_MAX_QUEUE;
152 default_node.if_up_data = strdup ("");
120 153
154#if ENABLE_DNS
155 default_node.dns_port = 0; // default is 0 == client
156
157 dns_case_preserving = true;
158 dns_forw_host = strdup ("127.0.0.1");
159 dns_forw_port = 53;
160 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR;
161 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL;
162 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR;
163 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING;
164#endif
165
121 conf.pidfilename = strdup (LOCALSTATEDIR "/run/vped.pid"); 166 pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid");
167 seed_dev = strdup ("/dev/urandom");
168 reseed = DEFAULT_RESEED;
122} 169}
123 170
171void
124void configuration::cleanup() 172configuration::cleanup ()
125{ 173{
126 if (rsa_key) 174 if (rsa_key)
127 RSA_free (rsa_key); 175 RSA_free (rsa_key);
128 176
129 rsa_key = 0; 177 rsa_key = 0;
130 178
179 free (seed_dev); seed_dev = 0;
131 free (pidfilename); pidfilename = 0; 180 free (pidfilename); pidfilename = 0;
132 free (ifname); ifname = 0; 181 free (ifname); ifname = 0;
133#if ENABLE_HTTP_PROXY 182#if ENABLE_HTTP_PROXY
134 free (proxy_host); proxy_host = 0; 183 free (proxy_host); proxy_host = 0;
135 free (proxy_auth); proxy_auth = 0; 184 free (proxy_auth); proxy_auth = 0;
136#endif 185#endif
186#if ENABLE_DNS
187 free (dns_forw_host); dns_forw_host = 0;
188#endif
189 free (change_root); change_root = 0;
190 free (script_if_up); script_if_up = 0;
191 free (script_node_up); script_node_up = 0;
192 free (script_node_change); script_node_change = 0;
193 free (script_node_down); script_node_down = 0;
137} 194}
138 195
139void 196void
140configuration::clear_config () 197configuration::clear ()
141{ 198{
142 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i) 199 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
143 delete *i; 200 delete *i;
144 201
145 nodes.clear (); 202 nodes.clear ();
146 203
147 cleanup (); 204 cleanup ();
148 init (); 205 init ();
149} 206}
150 207
208conf_node *
209configuration::find_node (const char *name)
210{
211 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
212 if (!strcmp ((*i)->nodename, name))
213 return *i;
214
215 return 0;
216}
217
218//static bool
219//is_true (const char *name)
220//{
221 //re
222//}
223
151#define parse_bool(target,name,trueval,falseval) \ 224#define parse_bool(target,name,trueval,falseval) do { \
152 if (!strcmp (val, "yes")) target = trueval; \ 225 if (!strcmp (val, "yes")) target = trueval; \
153 else if (!strcmp (val, "no")) target = falseval; \ 226 else if (!strcmp (val, "no")) target = falseval; \
154 else if (!strcmp (val, "true")) target = trueval; \ 227 else if (!strcmp (val, "true")) target = trueval; \
155 else if (!strcmp (val, "false")) target = falseval; \ 228 else if (!strcmp (val, "false")) target = falseval; \
156 else if (!strcmp (val, "on")) target = trueval; \ 229 else if (!strcmp (val, "on")) target = trueval; \
157 else if (!strcmp (val, "off")) target = falseval; \ 230 else if (!strcmp (val, "off")) target = falseval; \
158 else \ 231 else \
159 slog (L_WARN, \
160 _("illegal value for '%s', only 'yes|true|on' or 'no|false|off' allowed, at '%s' line %d"), \ 232 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed, ignored"); \
161 name, var, fname, lineno); 233} while (0)
162 234
163void configuration::read_config (bool need_keys) 235const char *
236configuration_parser::parse_line (char *line)
164{ 237{
165 char *fname; 238 {
166 FILE *f; 239 char *end = line + strlen (line);
167 240
168 clear_config (); 241 while (*end < ' ' && end >= line)
242 end--;
169 243
170 asprintf (&fname, "%s/vped.conf", confbase); 244 *++end = 0;
171 f = fopen (fname, "r"); 245 }
172 246
173 if (f) 247 char *tok = line;
248 const char *var = strtok (tok, "\t =");
249 tok = 0;
250
251 if (!var || !var[0])
252 return 0; /* no tokens on this line */
253
254 if (var[0] == '#')
255 return 0; /* comment: ignore */
256
257 if (!strcmp (var, "global"))
258 {
259 node = &conf.default_node;
260 return 0;
174 { 261 }
262
263 char *val = strtok (NULL, "\t\n\r =");
264
265 if (!val || val[0] == '#')
266 return _("no value given for variable, ignored");
267
268 else if (!strcmp (var, "on"))
269 {
270 if (::thisnode
271 && ((val[0] == '!' && strcmp (val + 1, ::thisnode))
272 || !strcmp (val, ::thisnode)))
273 return parse_line (strtok (NULL, "\n\r"));
274 }
275
276 else if (!strcmp (var, "include"))
277 {
278 char *fname = conf.config_filename (val);
279 parse_file (fname);
280 free (fname);
281 }
282
283 // truly global
284 else if (!strcmp (var, "loglevel"))
285 {
286 loglevel l = string_to_loglevel (val);
287
288 if (l == L_NONE)
289 return _("unknown loglevel, ignored");
290 }
291 else if (!strcmp (var, "ip-proto"))
292 conf.ip_proto = atoi (val);
293 else if (!strcmp (var, "icmp-type"))
294 {
295#if ENABLE_ICMP
296 conf.icmp_type = atoi (val);
297#endif
298 }
299 else if (!strcmp (var, "chuser"))
300 {
301 struct passwd *pw = getpwnam (val);
302 if (!pw)
303 return _("user specified for chuser not found");
304
305 conf.change_uid = pw->pw_uid;
306 conf.change_gid = pw->pw_gid;
307 }
308 else if (!strcmp (var, "chuid"))
309 conf.change_uid = atoi (val);
310 else if (!strcmp (var, "chgid"))
311 conf.change_gid = atoi (val);
312 else if (!strcmp (var, "chroot"))
313 free (conf.change_root), conf.change_root = strdup (val);
314
315 // per node
316 else if (!strcmp (var, "node"))
317 {
318 node = conf.find_node (val);
319
320 if (!node)
321 {
322 conf.default_node.id++;
323 node = new conf_node (conf.default_node);
324 conf.nodes.push_back (node);
325 node->nodename = strdup (val);
326 }
327 }
328 else if (!strcmp (var, "private-key"))
329 free (conf.prikeyfile), conf.prikeyfile = strdup (val);
330 else if (!strcmp (var, "ifpersist"))
331 parse_bool (conf.ifpersist, "ifpersist", true, false);
332 else if (!strcmp (var, "ifname"))
333 free (conf.ifname), conf.ifname = strdup (val);
334 else if (!strcmp (var, "rekey"))
335 conf.rekey = atoi (val);
336 else if (!strcmp (var, "keepalive"))
337 conf.keepalive = atoi (val);
338 else if (!strcmp (var, "mtu"))
339 conf.mtu = atoi (val);
340 else if (!strcmp (var, "nfmark"))
341 conf.nfmark = atoi (val);
342 else if (!strcmp (var, "seed-device"))
343 free (conf.seed_dev), conf.seed_dev = strdup (val);
344 else if (!strcmp (var, "seed-interval"))
345 conf.reseed = atoi (val);
346 else if (!strcmp (var, "if-up"))
347 free (conf.script_if_up), conf.script_if_up = strdup (val);
348 else if (!strcmp (var, "node-up"))
349 free (conf.script_node_up), conf.script_node_up = strdup (val);
350 else if (!strcmp (var, "node-change"))
351 free (conf.script_node_change), conf.script_node_change = strdup (val);
352 else if (!strcmp (var, "node-down"))
353 free (conf.script_node_down), conf.script_node_down = strdup (val);
354 else if (!strcmp (var, "pid-file"))
355 free (conf.pidfilename), conf.pidfilename = strdup (val);
356 else if (!strcmp (var, "dns-forw-host"))
357 {
358#if ENABLE_DNS
359 free (conf.dns_forw_host), conf.dns_forw_host = strdup (val);
360#endif
361 }
362 else if (!strcmp (var, "dns-forw-port"))
363 {
364#if ENABLE_DNS
365 conf.dns_forw_port = atoi (val);
366#endif
367 }
368 else if (!strcmp (var, "dns-timeout-factor"))
369 {
370#if ENABLE_DNS
371 conf.dns_timeout_factor = atof (val);
372#endif
373 }
374 else if (!strcmp (var, "dns-send-interval"))
375 {
376#if ENABLE_DNS
377 conf.dns_send_interval = atoi (val);
378#endif
379 }
380 else if (!strcmp (var, "dns-overlap-factor"))
381 {
382#if ENABLE_DNS
383 conf.dns_overlap_factor = atof (val);
384#endif
385 }
386 else if (!strcmp (var, "dns-max-outstanding"))
387 {
388#if ENABLE_DNS
389 conf.dns_max_outstanding = atoi (val);
390#endif
391 }
392 else if (!strcmp (var, "dns-case-preserving"))
393 {
394#if ENABLE_DNS
395 parse_bool (conf.dns_case_preserving, "dns-case-preserving", true, false);
396#endif
397 }
398 else if (!strcmp (var, "http-proxy-host"))
399 {
400#if ENABLE_HTTP_PROXY
401 free (conf.proxy_host), conf.proxy_host = strdup (val);
402#endif
403 }
404 else if (!strcmp (var, "http-proxy-port"))
405 {
406#if ENABLE_HTTP_PROXY
407 conf.proxy_port = atoi (val);
408#endif
409 }
410 else if (!strcmp (var, "http-proxy-auth"))
411 {
412#if ENABLE_HTTP_PROXY
413 conf.proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
414#endif
415 }
416
417 /* node-specific, non-defaultable */
418 else if (node != &conf.default_node && !strcmp (var, "hostname"))
419 free (node->hostname), node->hostname = strdup (val);
420
421 /* node-specific, defaultable */
422 else if (!strcmp (var, "udp-port"))
423 node->udp_port = atoi (val);
424 else if (!strcmp (var, "tcp-port"))
425 node->tcp_port = atoi (val);
426 else if (!strcmp (var, "dns-hostname"))
427 {
428#if ENABLE_DNS
429 free (node->dns_hostname), node->dns_hostname = strdup (val);
430#endif
431 }
432 else if (!strcmp (var, "dns-port"))
433 {
434#if ENABLE_DNS
435 node->dns_port = atoi (val);
436#endif
437 }
438 else if (!strcmp (var, "dns-domain"))
439 {
440#if ENABLE_DNS
441 free (node->domain), node->domain = strdup (val);
442#endif
443 }
444 else if (!strcmp (var, "if-up-data"))
445 free (node->if_up_data), node->if_up_data = strdup (val);
446 else if (!strcmp (var, "router-priority"))
447 node->routerprio = atoi (val);
448 else if (!strcmp (var, "max-retry"))
449 node->max_retry = atoi (val);
450 else if (!strcmp (var, "connect"))
451 {
452 if (!strcmp (val, "ondemand"))
453 node->connectmode = conf_node::C_ONDEMAND;
454 else if (!strcmp (val, "never"))
455 node->connectmode = conf_node::C_NEVER;
456 else if (!strcmp (val, "always"))
457 node->connectmode = conf_node::C_ALWAYS;
458 else if (!strcmp (val, "disabled"))
459 node->connectmode = conf_node::C_DISABLED;
460 else
461 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', ignored");
462 }
463 else if (!strcmp (var, "inherit-tos"))
464 parse_bool (node->inherit_tos, "inherit-tos", true, false);
465 else if (!strcmp (var, "compress"))
466 parse_bool (node->compress, "compress", true, false);
467 // all these bool options really really cost a lot of executable size!
468 else if (!strcmp (var, "enable-tcp"))
469 {
470#if ENABLE_TCP
471 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
472#endif
473 }
474 else if (!strcmp (var, "enable-icmp"))
475 {
476#if ENABLE_ICMP
477 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
478#endif
479 }
480 else if (!strcmp (var, "enable-dns"))
481 {
482#if ENABLE_DNS
483 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
484#endif
485 }
486 else if (!strcmp (var, "enable-udp"))
487 {
488 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
489 }
490 else if (!strcmp (var, "enable-rawip"))
491 {
492 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
493 }
494 else if (!strcmp (var, "allow-direct"))
495 node->allow_direct.push_back (strdup (val));
496 else if (!strcmp (var, "deny-direct"))
497 node->deny_direct.push_back (strdup (val));
498 else if (!strcmp (var, "max-ttl"))
499 node->max_ttl = atof (val);
500 else if (!strcmp (var, "max-queue"))
501 node->max_queue = atoi (val);
502
503 // unknown or misplaced
504 else
505 return _("unknown configuration directive - ignored");
506
507 return 0;
508}
509
510void
511conf_node::finalise ()
512{
513 if (max_queue < 1)
514 {
515 slog (L_WARN, _("%s: max-queue value invalid, setting it to 1."), nodename);
516 max_queue = 1;
517 }
518
519 if (routerprio > 1 && (connectmode != C_ALWAYS && connectmode != C_DISABLED))
520 {
521 //slog (L_WARN, _("%s: has non-zero router-priority but either 'never' or 'ondemand' as connectmode, setting it to 'always'."), nodename);
522 connectmode = C_ALWAYS;
523 }
524}
525
526void
527configuration_parser::parse_file (const char *fname)
528{
529 if (FILE *f = fopen (fname, "r"))
530 {
175 char line[16384]; 531 char line [2048];
176 int lineno = 0; 532 int lineno = 0;
177 char *var, *val;
178 conf_node *node = &default_node;
179 533
180 while (fgets (line, sizeof (line), f)) 534 while (fgets (line, sizeof (line), f))
181 { 535 {
182 lineno++; 536 lineno++;
183 537
184 { 538 const char *warn = parse_line (line);
185 char *end = line + strlen (line);
186 539
187 while (*end < ' ' && end >= line) 540 if (warn)
188 end--; 541 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
189
190 *++end = 0;
191 }
192
193 char *tok = line;
194
195retry:
196 var = strtok (tok, "\t =");
197 tok = 0;
198
199 if (!var || !var[0])
200 continue; /* no tokens on this line */
201
202 if (var[0] == '#')
203 continue; /* comment: ignore */
204
205 val = strtok (NULL, "\t\n\r =");
206
207 if (!val || val[0] == '#')
208 {
209 slog (L_WARN,
210 _("no value for variable `%s', at '%s' line %d"),
211 var, fname, lineno);
212 break;
213 }
214
215 if (!strcmp (var, "on"))
216 {
217 if (!::thisnode
218 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
219 || !strcmp (val, ::thisnode))
220 goto retry;
221
222 continue;
223 }
224
225 // truly global
226 if (!strcmp (var, "loglevel"))
227 {
228 loglevel l = string_to_loglevel (val);
229
230 if (l != L_NONE)
231 llevel = l;
232 else
233 slog (L_WARN, "'%s': %s, at '%s' line %d", val, UNKNOWN_LOGLEVEL, fname, line);
234 }
235 else if (!strcmp (var, "ip-proto"))
236 ip_proto = atoi (val);
237 else if (!strcmp (var, "icmp-type"))
238 {
239#if ENABLE_ICMP
240 icmp_type = atoi (val);
241#endif
242 }
243
244 // per config
245 else if (!strcmp (var, "node"))
246 {
247 default_node.id++;
248
249 node = new conf_node (default_node);
250
251 nodes.push_back (node);
252
253 node->nodename = strdup (val);
254
255 {
256 char *fname;
257 FILE *f;
258
259 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
260
261 f = fopen (fname, "r");
262 if (f)
263 {
264 node->rsa_key = RSA_new ();
265
266 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
267 {
268 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
269 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
270 exit (EXIT_FAILURE);
271 }
272
273 require (RSA_blinding_on (node->rsa_key, 0));
274
275 fclose (f);
276 }
277 else
278 {
279 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
280
281 if (need_keys)
282 exit (EXIT_FAILURE);
283 }
284
285 free (fname);
286 }
287
288 if (::thisnode && !strcmp (node->nodename, ::thisnode))
289 thisnode = node;
290 }
291 else if (!strcmp (var, "private-key"))
292 free (prikeyfile), prikeyfile = strdup (val);
293 else if (!strcmp (var, "ifpersist"))
294 {
295 parse_bool (ifpersist, "ifpersist", true, false);
296 }
297 else if (!strcmp (var, "ifname"))
298 free (ifname), ifname = strdup (val);
299 else if (!strcmp (var, "rekey"))
300 rekey = atoi (val);
301 else if (!strcmp (var, "keepalive"))
302 keepalive = atoi (val);
303 else if (!strcmp (var, "mtu"))
304 mtu = atoi (val);
305 else if (!strcmp (var, "if-up"))
306 free (script_if_up), script_if_up = strdup (val);
307 else if (!strcmp (var, "node-up"))
308 free (script_node_up), script_node_up = strdup (val);
309 else if (!strcmp (var, "node-down"))
310 free (script_node_down), script_node_down = strdup (val);
311 else if (!strcmp (var, "pid-file"))
312 free (pidfilename), pidfilename = strdup (val);
313 else if (!strcmp (var, "http-proxy-host"))
314 {
315#if ENABLE_HTTP_PROXY
316 free (proxy_host), proxy_host = strdup (val);
317#endif
318 }
319 else if (!strcmp (var, "http-proxy-port"))
320 {
321#if ENABLE_HTTP_PROXY
322 proxy_port = atoi (val);
323#endif
324 }
325 else if (!strcmp (var, "http-proxy-auth"))
326 {
327#if ENABLE_HTTP_PROXY
328 proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
329#endif
330 }
331
332 /* node-specific, non-defaultable */
333 else if (node != &default_node && !strcmp (var, "hostname"))
334 free (node->hostname), node->hostname = strdup (val);
335
336 /* node-specific, defaultable */
337 else if (!strcmp (var, "udp-port"))
338 node->udp_port = atoi (val);
339 else if (!strcmp (var, "tcp-port"))
340 node->tcp_port = atoi (val);
341 else if (!strcmp (var, "dns-port"))
342 node->dns_port = atoi (val);
343 else if (!strcmp (var, "router-priority"))
344 node->routerprio = atoi (val);
345 else if (!strcmp (var, "connect"))
346 {
347 if (!strcmp (val, "ondemand"))
348 node->connectmode = conf_node::C_ONDEMAND;
349 else if (!strcmp (val, "never"))
350 node->connectmode = conf_node::C_NEVER;
351 else if (!strcmp (val, "always"))
352 node->connectmode = conf_node::C_ALWAYS;
353 else if (!strcmp (val, "disabled"))
354 node->connectmode = conf_node::C_DISABLED;
355 else
356 slog (L_WARN,
357 _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', at '%s' line %d"),
358 var, fname, lineno);
359 }
360 else if (!strcmp (var, "inherit-tos"))
361 {
362 parse_bool (node->inherit_tos, "inherit-tos", true, false);
363 }
364 else if (!strcmp (var, "compress"))
365 {
366 parse_bool (node->compress, "compress", true, false);
367 }
368 // all these bool options really really cost a lot of executable size!
369 else if (!strcmp (var, "enable-tcp"))
370 {
371#if ENABLE_TCP
372 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
373#endif
374 }
375 else if (!strcmp (var, "enable-icmp"))
376 {
377#if ENABLE_ICMP
378 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
379#endif
380 }
381 else if (!strcmp (var, "enable-dns"))
382 {
383#if ENABLE_DNS
384 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
385#endif
386 }
387 else if (!strcmp (var, "enable-udp"))
388 {
389 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
390 }
391 else if (!strcmp (var, "enable-rawip"))
392 {;
393 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
394 }
395
396 // unknown or misplaced
397 else
398 slog (L_WARN,
399 _("unknown or misplaced variable `%s', at '%s' line %d"),
400 var, fname, lineno);
401 } 542 }
402 543
403 fclose (f); 544 fclose (f);
404 } 545 }
405 else 546 else
406 { 547 {
407 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno)); 548 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
408 exit (EXIT_FAILURE); 549 exit (EXIT_FAILURE);
409 } 550 }
551}
410 552
553configuration_parser::configuration_parser (configuration &conf,
554 bool need_keys,
555 int argc,
556 char **argv)
557: conf (conf), need_keys (need_keys), argc (argc), argv (argv)
558{
559 char *fname;
560
561 conf.clear ();
562 node = &conf.default_node;
563
564 asprintf (&fname, "%s/gvpe.conf", confbase);
565 parse_file (fname);
411 free (fname); 566 free (fname);
412 567
413 fname = config_filename (prikeyfile, "hostkey"); 568 fname = conf.config_filename (conf.prikeyfile, "hostkey");
414 569
415 f = fopen (fname, "r"); 570 if (FILE *f = fopen (fname, "r"))
416 if (f)
417 { 571 {
418 rsa_key = RSA_new (); 572 conf.rsa_key = RSA_new ();
419 573
420 if (!PEM_read_RSAPrivateKey (f, &rsa_key, NULL, NULL)) 574 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL))
421 { 575 {
422 ERR_load_RSA_strings (); ERR_load_PEM_strings (); 576 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
423 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0)); 577 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
424 exit (EXIT_FAILURE); 578 exit (EXIT_FAILURE);
425 } 579 }
426 580
427 require (RSA_blinding_on (rsa_key, 0)); 581 require (RSA_blinding_on (conf.rsa_key, 0));
428 582
429 fclose (f); 583 fclose (f);
430 } 584 }
431 else 585 else
432 { 586 {
433 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
434
435 if (need_keys) 587 if (need_keys)
588 {
589 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
436 exit (EXIT_FAILURE); 590 exit (EXIT_FAILURE);
437 }
438
439 if (need_keys && ::thisnode
440 && rsa_key && thisnode && thisnode->rsa_key)
441 if (BN_cmp (rsa_key->n, thisnode->rsa_key->n) != 0
442 || BN_cmp (rsa_key->e, thisnode->rsa_key->e) != 0)
443 {
444 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
445 exit (EXIT_FAILURE);
446 } 591 }
592 }
447 593
448 free (fname); 594 free (fname);
449}
450 595
596 fname = conf.config_filename (conf.pidfilename);
597 free (conf.pidfilename); conf.pidfilename = fname;
598
599 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
600 {
601 conf_node *node = *i;
602 char *fname;
603 FILE *f;
604
605 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
606
607 f = fopen (fname, "r");
608 if (f)
609 {
610 node->rsa_key = RSA_new ();
611
612 if (!PEM_read_RSAPublicKey (f, &node->rsa_key, NULL, NULL))
613 {
614 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
615 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
616 exit (EXIT_FAILURE);
617 }
618
619 require (RSA_blinding_on (node->rsa_key, 0));
620
621 fclose (f);
622 }
623 else
624 {
625 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
626
627 if (need_keys)
628 exit (EXIT_FAILURE);
629 }
630
631 free (fname);
632
633 (*i)->finalise ();
634 }
635
636 if (::thisnode)
637 {
638 conf.thisnode = conf.find_node (::thisnode);
639
640 if (need_keys)
641 {
642 if (!conf.thisnode)
643 {
644 slog (L_NOTICE, _("local node ('%s') not found in config file, aborting."), ::thisnode);
645 exit (EXIT_FAILURE);
646 }
647
648 if (conf.rsa_key && conf.thisnode->rsa_key)
649 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
650 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
651 {
652 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
653 exit (EXIT_FAILURE);
654 }
655 }
656 }
657
658 parse_argv ();
659}
660
661void
662configuration_parser::parse_argv ()
663{
664 for (int i = 0; i < argc; ++i)
665 {
666 char *v = argv [i];
667
668 if (!*v)
669 continue;
670
671 char *enode = v;
672
673 while (*enode != '.' && *enode > ' ' && *enode != '=' && *enode)
674 enode++;
675
676 if (*enode != '.')
677 enode = 0;
678
679 if (enode)
680 {
681 char *val = strdup (v);
682 val [enode - v] = 0;
683 node = conf.find_node (val);
684 free (val);
685
686 if (!node)
687 {
688 slog (L_WARN, _("command line option '%s' refers to unknown node, ignoring."), v);
689 continue;
690 }
691 }
692 else
693 node = &conf.default_node;
694
695 const char *warn = parse_line (enode ? enode + 1 : v);
696
697 if (warn)
698 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v);
699 }
700}
701
702char *
451char *configuration::config_filename (const char *name, const char *dflt) 703configuration::config_filename (const char *name, const char *dflt)
452{ 704{
453 char *fname; 705 char *fname;
454 706
455 asprintf (&fname, name ? name : dflt, ::thisnode); 707 asprintf (&fname, name ? name : dflt, ::thisnode ? ::thisnode : "<unset>");
456 708
457 if (!ABSOLUTE_PATH (fname)) 709 if (!ABSOLUTE_PATH (fname))
458 { 710 {
459 char *rname = fname; 711 char *rname = fname;
460 asprintf (&fname, "%s/%s", confbase, rname); 712 asprintf (&fname, "%s/%s", confbase, rname);
461 free (rname); 713 free (rname);
462 } 714 }
463 715
464 return fname; 716 return fname;
717}
718
719void
720conf_node::print ()
721{
722 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %02x %s%s%d\n",
723 id,
724 id >> 8, id & 0xff,
725 compress ? 'Y' : 'N',
726 connectmode == C_ONDEMAND ? "ondemand"
727 : connectmode == C_NEVER ? "never"
728 : connectmode == C_ALWAYS ? "always"
729 : connectmode == C_DISABLED ? "disabled"
730 : "",
731 nodename,
732 protocols,
733 hostname ? hostname : "",
734 hostname ? ":" : "",
735 hostname ? udp_port : 0
736 );
465} 737}
466 738
467void 739void
468configuration::print () 740configuration::print ()
469{ 741{
476 printf (_("interface: %s\n"), ifname); 748 printf (_("interface: %s\n"), ifname);
477 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>"); 749 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
478 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1); 750 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1);
479 printf ("\n"); 751 printf ("\n");
480 752
481 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n", 753 printf ("%4s %-17s %s %-8.8s %-10.10s %04s %s\n",
482 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port")); 754 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Prot"), _("Host:Port"));
483 755
484 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i) 756 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
485 (*i)->print (); 757 (*i)->print ();
486 758
487 printf ("\n"); 759 printf ("\n");
488} 760}
489 761
490configuration::configuration () 762configuration::configuration ()
491{ 763{
764 asprintf (&confbase, "%s/gvpe", CONFDIR);
765
492 init (); 766 init ();
493} 767}
494 768
495configuration::~configuration () 769configuration::~configuration ()
496{ 770{
497 cleanup (); 771 cleanup ();
498} 772}
499 773
500

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines