ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
(Generate patch)

Comparing gvpe/src/conf.C (file contents):
Revision 1.45 by pcg, Fri Aug 8 16:48:00 2008 UTC vs.
Revision 1.62 by root, Wed Jul 17 16:40:57 2013 UTC

1/* 1/*
2 conf.c -- configuration code 2 conf.C -- configuration code
3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de> 3 Copyright (C) 2003-2008,2011 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE. 5 This file is part of GVPE.
6 6
7 GVPE is free software; you can redistribute it and/or modify it 7 GVPE is free software; you can redistribute it and/or modify it
8 under the terms of the GNU General Public License as published by the 8 under the terms of the GNU General Public License as published by the
38#include <errno.h> 38#include <errno.h>
39#include <netdb.h> 39#include <netdb.h>
40#include <sys/stat.h> 40#include <sys/stat.h>
41#include <sys/types.h> 41#include <sys/types.h>
42#include <unistd.h> 42#include <unistd.h>
43#include <pwd.h>
43 44
44#include "netcompat.h" 45#include "netcompat.h"
45 46
46#include <openssl/err.h> 47#include <openssl/err.h>
47#include <openssl/pem.h> 48#include <openssl/pem.h>
57char *thisnode; 58char *thisnode;
58char *identname; 59char *identname;
59 60
60struct configuration conf; 61struct configuration conf;
61 62
63u8
62u8 best_protocol (u8 protset) 64best_protocol (u8 protset)
63{ 65{
64 if (protset & PROT_IPv4 ) return PROT_IPv4; 66 if (protset & PROT_IPv4 ) return PROT_IPv4;
65 if (protset & PROT_ICMPv4) return PROT_ICMPv4; 67 if (protset & PROT_ICMPv4) return PROT_ICMPv4;
66 if (protset & PROT_UDPv4 ) return PROT_UDPv4; 68 if (protset & PROT_UDPv4 ) return PROT_UDPv4;
67 if (protset & PROT_TCPv4 ) return PROT_TCPv4; 69 if (protset & PROT_TCPv4 ) return PROT_TCPv4;
68 if (protset & PROT_DNSv4 ) return PROT_DNSv4; 70 if (protset & PROT_DNSv4 ) return PROT_DNSv4;
69 71
70 return 0; 72 return 0;
71} 73}
72 74
75const char *
73const char *strprotocol (u8 protocol) 76strprotocol (u8 protocol)
74{ 77{
75 if (protocol & PROT_IPv4 ) return "rawip"; 78 if (protocol & PROT_IPv4 ) return "rawip";
76 if (protocol & PROT_ICMPv4) return "icmp"; 79 if (protocol & PROT_ICMPv4) return "icmp";
77 if (protocol & PROT_UDPv4 ) return "udp"; 80 if (protocol & PROT_UDPv4 ) return "udp";
78 if (protocol & PROT_TCPv4 ) return "tcp"; 81 if (protocol & PROT_TCPv4 ) return "tcp";
92 95
93 return false; 96 return false;
94} 97}
95 98
96bool 99bool
97conf_node::can_direct (struct conf_node *other) 100conf_node::may_direct (struct conf_node *other)
98{ 101{
99 if (match_list (allow_direct, other->nodename)) 102 if (match_list (allow_direct, other->nodename))
100 return true; 103 return true;
101 104
102 if (match_list (deny_direct, other->nodename)) 105 if (match_list (deny_direct, other->nodename))
103 return false; 106 return false;
104 107
105 return true; 108 return true;
106}
107
108void
109conf_node::print ()
110{
111 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %s%s%d\n",
112 id,
113 id >> 8, id & 0xff,
114 compress ? 'Y' : 'N',
115 connectmode == C_ONDEMAND ? "ondemand" :
116 connectmode == C_NEVER ? "never" :
117 connectmode == C_ALWAYS ? "always" : "",
118 nodename,
119 hostname ? hostname : "",
120 hostname ? ":" : "",
121 hostname ? udp_port : 0
122 );
123} 109}
124 110
125conf_node::~conf_node () 111conf_node::~conf_node ()
126{ 112{
127#if 0 113#if 0
138 free (dns_hostname); 124 free (dns_hostname);
139#endif 125#endif
140#endif 126#endif
141} 127}
142 128
129void
143void configuration::init () 130configuration::init ()
144{ 131{
145 memset (this, 0, sizeof (*this)); 132 memset (this, 0, sizeof (*this));
146 133
147 mtu = DEFAULT_MTU; 134 mtu = DEFAULT_MTU;
135 nfmark = 0;
148 rekey = DEFAULT_REKEY; 136 rekey = DEFAULT_REKEY;
149 keepalive = DEFAULT_KEEPALIVE; 137 keepalive = DEFAULT_KEEPALIVE;
150 llevel = L_INFO; 138 llevel = L_INFO;
151 ip_proto = IPPROTO_GRE; 139 ip_proto = IPPROTO_GRE;
152#if ENABLE_ICMP 140#if ENABLE_ICMP
164 default_node.if_up_data = strdup (""); 152 default_node.if_up_data = strdup ("");
165 153
166#if ENABLE_DNS 154#if ENABLE_DNS
167 default_node.dns_port = 0; // default is 0 == client 155 default_node.dns_port = 0; // default is 0 == client
168 156
157 dns_case_preserving = true;
169 dns_forw_host = strdup ("127.0.0.1"); 158 dns_forw_host = strdup ("127.0.0.1");
170 dns_forw_port = 53; 159 dns_forw_port = 53;
171 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR; 160 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR;
172 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL; 161 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL;
173 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR; 162 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR;
174 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING; 163 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING;
175#endif 164#endif
176 165
177 conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid"); 166 pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid");
167 seed_dev = strdup ("/dev/urandom");
168 reseed = DEFAULT_RESEED;
178} 169}
179 170
171void
180void configuration::cleanup() 172configuration::cleanup ()
181{ 173{
182 if (rsa_key) 174 if (rsa_key)
183 RSA_free (rsa_key); 175 RSA_free (rsa_key);
184 176
185 rsa_key = 0; 177 rsa_key = 0;
186 178
179 free (seed_dev); seed_dev = 0;
187 free (pidfilename); pidfilename = 0; 180 free (pidfilename); pidfilename = 0;
188 free (ifname); ifname = 0; 181 free (ifname); ifname = 0;
189#if ENABLE_HTTP_PROXY 182#if ENABLE_HTTP_PROXY
190 free (proxy_host); proxy_host = 0; 183 free (proxy_host); proxy_host = 0;
191 free (proxy_auth); proxy_auth = 0; 184 free (proxy_auth); proxy_auth = 0;
192#endif 185#endif
193#if ENABLE_DNS 186#if ENABLE_DNS
194 free (dns_forw_host); dns_forw_host = 0; 187 free (dns_forw_host); dns_forw_host = 0;
195#endif 188#endif
189 free (change_root); change_root = 0;
190 free (script_if_up); script_if_up = 0;
191 free (script_node_up); script_node_up = 0;
192 free (script_node_change); script_node_change = 0;
193 free (script_node_down); script_node_down = 0;
196} 194}
197 195
198void 196void
199configuration::clear () 197configuration::clear ()
200{ 198{
204 nodes.clear (); 202 nodes.clear ();
205 203
206 cleanup (); 204 cleanup ();
207 init (); 205 init ();
208} 206}
207
208conf_node *
209configuration::find_node (const char *name)
210{
211 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
212 if (!strcmp ((*i)->nodename, name))
213 return *i;
214
215 return 0;
216}
217
218//static bool
219//is_true (const char *name)
220//{
221 //re
222//}
209 223
210#define parse_bool(target,name,trueval,falseval) do { \ 224#define parse_bool(target,name,trueval,falseval) do { \
211 if (!strcmp (val, "yes")) target = trueval; \ 225 if (!strcmp (val, "yes")) target = trueval; \
212 else if (!strcmp (val, "no")) target = falseval; \ 226 else if (!strcmp (val, "no")) target = falseval; \
213 else if (!strcmp (val, "true")) target = trueval; \ 227 else if (!strcmp (val, "true")) target = trueval; \
214 else if (!strcmp (val, "false")) target = falseval; \ 228 else if (!strcmp (val, "false")) target = falseval; \
215 else if (!strcmp (val, "on")) target = trueval; \ 229 else if (!strcmp (val, "on")) target = trueval; \
216 else if (!strcmp (val, "off")) target = falseval; \ 230 else if (!strcmp (val, "off")) target = falseval; \
217 else \ 231 else \
218 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed. (ignored)"); \ 232 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed, ignored"); \
219} while (0) 233} while (0)
220 234
221const char * 235const char *
222configuration_parser::parse_line (char *line) 236configuration_parser::parse_line (char *line)
223{ 237{
241 return 0; /* comment: ignore */ 255 return 0; /* comment: ignore */
242 256
243 char *val = strtok (NULL, "\t\n\r ="); 257 char *val = strtok (NULL, "\t\n\r =");
244 258
245 if (!val || val[0] == '#') 259 if (!val || val[0] == '#')
246 return _("no value given for variable. (ignored)"); 260 return _("no value given for variable, ignored");
247 261
248 if (!strcmp (var, "on")) 262 else if (!strcmp (var, "on"))
249 { 263 {
250 if (!::thisnode 264 if (::thisnode
251 || (val[0] == '!' && strcmp (val + 1, ::thisnode)) 265 && ((val[0] == '!' && strcmp (val + 1, ::thisnode))
252 || !strcmp (val, ::thisnode)) 266 || !strcmp (val, ::thisnode)))
253 return parse_line (strtok (NULL, "\n\r")); 267 return parse_line (strtok (NULL, "\n\r"));
254 else 268 }
255 return 0; 269
270 else if (!strcmp (var, "include"))
271 {
272 char *fname = conf.config_filename (val);
273 parse_file (fname);
274 free (fname);
256 } 275 }
257 276
258 // truly global 277 // truly global
259 if (!strcmp (var, "loglevel")) 278 else if (!strcmp (var, "loglevel"))
260 { 279 {
261 loglevel l = string_to_loglevel (val); 280 loglevel l = string_to_loglevel (val);
262 281
263 if (l == L_NONE) 282 if (l == L_NONE)
264 return _("unknown loglevel. (skipping)"); 283 return _("unknown loglevel, ignored");
265 } 284 }
266 else if (!strcmp (var, "ip-proto")) 285 else if (!strcmp (var, "ip-proto"))
267 conf.ip_proto = atoi (val); 286 conf.ip_proto = atoi (val);
268 else if (!strcmp (var, "icmp-type")) 287 else if (!strcmp (var, "icmp-type"))
269 { 288 {
270#if ENABLE_ICMP 289#if ENABLE_ICMP
271 conf.icmp_type = atoi (val); 290 conf.icmp_type = atoi (val);
272#endif 291#endif
273 } 292 }
293 else if (!strcmp (var, "chuser"))
294 {
295 struct passwd *pw = getpwnam (val);
296 if (!pw)
297 return _("user specified for chuser not found");
274 298
275 // per config 299 conf.change_uid = pw->pw_uid;
300 conf.change_gid = pw->pw_gid;
301 }
302 else if (!strcmp (var, "chuid"))
303 conf.change_uid = atoi (val);
304 else if (!strcmp (var, "chgid"))
305 conf.change_gid = atoi (val);
306 else if (!strcmp (var, "chroot"))
307 free (conf.change_root), conf.change_root = strdup (val);
308
309 // per node
310 else if (!strcmp (var, "global"))
311 node = &conf.default_node;
276 else if (!strcmp (var, "node")) 312 else if (!strcmp (var, "node"))
277 { 313 {
278 parse_argv (); 314 node = conf.find_node (val);
279 315
316 if (!node)
317 {
280 conf.default_node.id++; 318 conf.default_node.id++;
281 node = new conf_node (conf.default_node); 319 node = new conf_node (conf.default_node);
282 conf.nodes.push_back (node); 320 conf.nodes.push_back (node);
283 node->nodename = strdup (val); 321 node->nodename = strdup (val);
284
285 {
286 char *fname;
287 FILE *f;
288
289 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
290
291 f = fopen (fname, "r");
292 if (f)
293 {
294 node->rsa_key = RSA_new ();
295
296 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
297 {
298 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
299 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
300 exit (EXIT_FAILURE);
301 }
302
303 require (RSA_blinding_on (node->rsa_key, 0));
304
305 fclose (f);
306 } 322 }
307 else
308 {
309 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
310
311 if (need_keys)
312 exit (EXIT_FAILURE);
313 }
314
315 free (fname);
316 }
317
318 if (::thisnode && !strcmp (node->nodename, ::thisnode))
319 conf.thisnode = node;
320 } 323 }
321 else if (!strcmp (var, "private-key")) 324 else if (!strcmp (var, "private-key"))
322 free (conf.prikeyfile), conf.prikeyfile = strdup (val); 325 free (conf.prikeyfile), conf.prikeyfile = strdup (val);
323 else if (!strcmp (var, "ifpersist")) 326 else if (!strcmp (var, "ifpersist"))
324 parse_bool (conf.ifpersist, "ifpersist", true, false); 327 parse_bool (conf.ifpersist, "ifpersist", true, false);
328 conf.rekey = atoi (val); 331 conf.rekey = atoi (val);
329 else if (!strcmp (var, "keepalive")) 332 else if (!strcmp (var, "keepalive"))
330 conf.keepalive = atoi (val); 333 conf.keepalive = atoi (val);
331 else if (!strcmp (var, "mtu")) 334 else if (!strcmp (var, "mtu"))
332 conf.mtu = atoi (val); 335 conf.mtu = atoi (val);
336 else if (!strcmp (var, "nfmark"))
337 conf.nfmark = atoi (val);
338 else if (!strcmp (var, "seed-device"))
339 free (conf.seed_dev), conf.seed_dev = strdup (val);
340 else if (!strcmp (var, "seed-interval"))
341 conf.reseed = atoi (val);
333 else if (!strcmp (var, "if-up")) 342 else if (!strcmp (var, "if-up"))
334 free (conf.script_if_up), conf.script_if_up = strdup (val); 343 free (conf.script_if_up), conf.script_if_up = strdup (val);
335 else if (!strcmp (var, "node-up")) 344 else if (!strcmp (var, "node-up"))
336 free (conf.script_node_up), conf.script_node_up = strdup (val); 345 free (conf.script_node_up), conf.script_node_up = strdup (val);
346 else if (!strcmp (var, "node-change"))
347 free (conf.script_node_change), conf.script_node_change = strdup (val);
337 else if (!strcmp (var, "node-down")) 348 else if (!strcmp (var, "node-down"))
338 free (conf.script_node_down), conf.script_node_down = strdup (val); 349 free (conf.script_node_down), conf.script_node_down = strdup (val);
339 else if (!strcmp (var, "pid-file")) 350 else if (!strcmp (var, "pid-file"))
340 free (conf.pidfilename), conf.pidfilename = strdup (val); 351 free (conf.pidfilename), conf.pidfilename = strdup (val);
341 else if (!strcmp (var, "dns-forw-host")) 352 else if (!strcmp (var, "dns-forw-host"))
370 } 381 }
371 else if (!strcmp (var, "dns-max-outstanding")) 382 else if (!strcmp (var, "dns-max-outstanding"))
372 { 383 {
373#if ENABLE_DNS 384#if ENABLE_DNS
374 conf.dns_max_outstanding = atoi (val); 385 conf.dns_max_outstanding = atoi (val);
386#endif
387 }
388 else if (!strcmp (var, "dns-case-preserving"))
389 {
390#if ENABLE_DNS
391 parse_bool (conf.dns_case_preserving, "dns-case-preserving", true, false);
375#endif 392#endif
376 } 393 }
377 else if (!strcmp (var, "http-proxy-host")) 394 else if (!strcmp (var, "http-proxy-host"))
378 { 395 {
379#if ENABLE_HTTP_PROXY 396#if ENABLE_HTTP_PROXY
435 else if (!strcmp (val, "always")) 452 else if (!strcmp (val, "always"))
436 node->connectmode = conf_node::C_ALWAYS; 453 node->connectmode = conf_node::C_ALWAYS;
437 else if (!strcmp (val, "disabled")) 454 else if (!strcmp (val, "disabled"))
438 node->connectmode = conf_node::C_DISABLED; 455 node->connectmode = conf_node::C_DISABLED;
439 else 456 else
440 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled'. (ignored)"); 457 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', ignored");
441 } 458 }
442 else if (!strcmp (var, "inherit-tos")) 459 else if (!strcmp (var, "inherit-tos"))
443 parse_bool (node->inherit_tos, "inherit-tos", true, false); 460 parse_bool (node->inherit_tos, "inherit-tos", true, false);
444 else if (!strcmp (var, "compress")) 461 else if (!strcmp (var, "compress"))
445 parse_bool (node->compress, "compress", true, false); 462 parse_bool (node->compress, "compress", true, false);
475 else if (!strcmp (var, "deny-direct")) 492 else if (!strcmp (var, "deny-direct"))
476 node->deny_direct.push_back (strdup (val)); 493 node->deny_direct.push_back (strdup (val));
477 else if (!strcmp (var, "max-ttl")) 494 else if (!strcmp (var, "max-ttl"))
478 node->max_ttl = atof (val); 495 node->max_ttl = atof (val);
479 else if (!strcmp (var, "max-queue")) 496 else if (!strcmp (var, "max-queue"))
480 {
481 node->max_queue = atoi (val); 497 node->max_queue = atoi (val);
482
483 if (node->max_queue < 1)
484 node->max_queue = 1;
485 }
486 498
487 // unknown or misplaced 499 // unknown or misplaced
488 else 500 else
489 return _("unknown configuration directive. (ignored)"); 501 return _("unknown configuration directive - ignored");
490 502
491 return 0; 503 return 0;
492} 504}
493 505
494void configuration_parser::parse_argv () 506void
507conf_node::finalise ()
495{ 508{
496 for (int i = 0; i < argc; ++i) 509 if (max_queue < 1)
510 {
511 slog (L_WARN, _("%s: max-queue value invalid, setting it to 1."), nodename);
512 max_queue = 1;
497 { 513 }
498 char *v = argv [i];
499 514
500 if (!*v) 515 if (routerprio > 1 && (connectmode != C_ALWAYS && connectmode != C_DISABLED))
501 continue; 516 {
517 //slog (L_WARN, _("%s: has non-zero router-priority but either 'never' or 'ondemand' as connectmode, setting it to 'always'."), nodename);
518 connectmode = C_ALWAYS;
519 }
520}
502 521
503 char *enode = v; 522void
523configuration_parser::parse_file (const char *fname)
524{
525 if (FILE *f = fopen (fname, "r"))
526 {
527 char line [2048];
528 int lineno = 0;
504 529
505 while (*enode != '.' && *enode > ' ' && *enode != '=' && *enode) 530 while (fgets (line, sizeof (line), f))
506 enode++;
507
508 if (*enode != '.')
509 enode = 0;
510
511 char *wnode = node == &conf.default_node
512 ? 0
513 : node->nodename;
514
515 if ((!wnode && !enode)
516 || (wnode && enode && !strncmp (wnode, v, enode - v)))
517 { 531 {
532 lineno++;
533
518 const char *warn = parse_line (enode ? enode + 1 : v); 534 const char *warn = parse_line (line);
519 535
520 if (warn) 536 if (warn)
521 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v); 537 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
522
523 *v = 0;
524 } 538 }
539
540 fclose (f);
541 }
542 else
543 {
544 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
545 exit (EXIT_FAILURE);
525 } 546 }
526} 547}
527 548
528configuration_parser::configuration_parser (configuration &conf, 549configuration_parser::configuration_parser (configuration &conf,
529 bool need_keys, 550 bool need_keys,
530 int argc, 551 int argc,
531 char **argv) 552 char **argv)
532: conf (conf),need_keys (need_keys), argc (argc), argv (argv) 553: conf (conf), need_keys (need_keys), argc (argc), argv (argv)
533{ 554{
534 char *fname; 555 char *fname;
535 FILE *f;
536 556
537 conf.clear (); 557 conf.clear ();
558 node = &conf.default_node;
538 559
539 asprintf (&fname, "%s/gvpe.conf", confbase); 560 asprintf (&fname, "%s/gvpe.conf", confbase);
540 f = fopen (fname, "r"); 561 parse_file (fname);
541
542 if (f)
543 {
544 char line[16384];
545 int lineno = 0;
546 node = &conf.default_node;
547
548 while (fgets (line, sizeof (line), f))
549 {
550 lineno++;
551
552 const char *warn = parse_line (line);
553
554 if (warn)
555 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
556 }
557
558 fclose (f);
559
560 parse_argv ();
561 }
562 else
563 {
564 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
565 exit (EXIT_FAILURE);
566 }
567
568 free (fname); 562 free (fname);
569 563
570 fname = conf.config_filename (conf.prikeyfile, "hostkey"); 564 fname = conf.config_filename (conf.prikeyfile, "hostkey");
571 565
572 f = fopen (fname, "r"); 566 if (FILE *f = fopen (fname, "r"))
573 if (f)
574 { 567 {
575 conf.rsa_key = RSA_new (); 568 conf.rsa_key = RSA_new ();
576 569
577 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL)) 570 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL))
578 { 571 {
585 578
586 fclose (f); 579 fclose (f);
587 } 580 }
588 else 581 else
589 { 582 {
590 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
591
592 if (need_keys) 583 if (need_keys)
584 {
585 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
593 exit (EXIT_FAILURE); 586 exit (EXIT_FAILURE);
594 }
595
596 if (need_keys && ::thisnode
597 && conf.rsa_key && conf.thisnode && conf.thisnode->rsa_key)
598 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
599 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
600 {
601 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
602 exit (EXIT_FAILURE);
603 } 587 }
588 }
604 589
605 free (fname); 590 free (fname);
606}
607 591
592 fname = conf.config_filename (conf.pidfilename);
593 free (conf.pidfilename); conf.pidfilename = fname;
594
595 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
596 {
597 conf_node *node = *i;
598 char *fname;
599 FILE *f;
600
601 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
602
603 f = fopen (fname, "r");
604 if (f)
605 {
606 node->rsa_key = RSA_new ();
607
608 if (!PEM_read_RSAPublicKey (f, &node->rsa_key, NULL, NULL))
609 {
610 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
611 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
612 exit (EXIT_FAILURE);
613 }
614
615 require (RSA_blinding_on (node->rsa_key, 0));
616
617 fclose (f);
618 }
619 else
620 {
621 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
622
623 if (need_keys)
624 exit (EXIT_FAILURE);
625 }
626
627 free (fname);
628
629 (*i)->finalise ();
630 }
631
632 if (::thisnode)
633 {
634 conf.thisnode = conf.find_node (::thisnode);
635
636 if (need_keys)
637 {
638 if (!conf.thisnode)
639 {
640 slog (L_NOTICE, _("local node ('%s') not found in config file, aborting."), ::thisnode);
641 exit (EXIT_FAILURE);
642 }
643
644 if (conf.rsa_key && conf.thisnode->rsa_key)
645 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
646 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
647 {
648 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
649 exit (EXIT_FAILURE);
650 }
651 }
652 }
653
654 parse_argv ();
655}
656
657void
658configuration_parser::parse_argv ()
659{
660 for (int i = 0; i < argc; ++i)
661 {
662 char *v = argv [i];
663
664 if (!*v)
665 continue;
666
667 char *enode = v;
668
669 while (*enode != '.' && *enode > ' ' && *enode != '=' && *enode)
670 enode++;
671
672 if (*enode != '.')
673 enode = 0;
674
675 if (enode)
676 {
677 char *val = strdup (v);
678 val [enode - v] = 0;
679 node = conf.find_node (val);
680 free (val);
681
682 if (!node)
683 {
684 slog (L_WARN, _("command line option '%s' refers to unknown node, ignoring."), v);
685 continue;
686 }
687 }
688 else
689 node = &conf.default_node;
690
691 const char *warn = parse_line (enode ? enode + 1 : v);
692
693 if (warn)
694 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v);
695 }
696}
697
698char *
608char *configuration::config_filename (const char *name, const char *dflt) 699configuration::config_filename (const char *name, const char *dflt)
609{ 700{
610 char *fname; 701 char *fname;
611 702
612 asprintf (&fname, name ? name : dflt, ::thisnode); 703 asprintf (&fname, name ? name : dflt, ::thisnode ? ::thisnode : "<unset>");
613 704
614 if (!ABSOLUTE_PATH (fname)) 705 if (!ABSOLUTE_PATH (fname))
615 { 706 {
616 char *rname = fname; 707 char *rname = fname;
617 asprintf (&fname, "%s/%s", confbase, rname); 708 asprintf (&fname, "%s/%s", confbase, rname);
618 free (rname); 709 free (rname);
619 } 710 }
620 711
621 return fname; 712 return fname;
713}
714
715void
716conf_node::print ()
717{
718 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %02x %s%s%d\n",
719 id,
720 id >> 8, id & 0xff,
721 compress ? 'Y' : 'N',
722 connectmode == C_ONDEMAND ? "ondemand"
723 : connectmode == C_NEVER ? "never"
724 : connectmode == C_ALWAYS ? "always"
725 : connectmode == C_DISABLED ? "disabled"
726 : "",
727 nodename,
728 protocols,
729 hostname ? hostname : "",
730 hostname ? ":" : "",
731 hostname ? udp_port : 0
732 );
622} 733}
623 734
624void 735void
625configuration::print () 736configuration::print ()
626{ 737{
633 printf (_("interface: %s\n"), ifname); 744 printf (_("interface: %s\n"), ifname);
634 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>"); 745 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
635 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1); 746 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1);
636 printf ("\n"); 747 printf ("\n");
637 748
638 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n", 749 printf ("%4s %-17s %s %-8.8s %-10.10s %04s %s\n",
639 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port")); 750 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Prot"), _("Host:Port"));
640 751
641 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i) 752 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
642 (*i)->print (); 753 (*i)->print ();
643 754
644 printf ("\n"); 755 printf ("\n");
654configuration::~configuration () 765configuration::~configuration ()
655{ 766{
656 cleanup (); 767 cleanup ();
657} 768}
658 769
659

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines