1 | /* |
1 | /* |
2 | conf.c -- configuration code |
2 | conf.c -- configuration code |
3 | Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de> |
3 | Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de> |
4 | |
4 | |
5 | This file is part of GVPE. |
5 | This file is part of GVPE. |
6 | |
6 | |
7 | GVPE is free software; you can redistribute it and/or modify |
7 | GVPE is free software; you can redistribute it and/or modify it |
8 | it under the terms of the GNU General Public License as published by |
8 | under the terms of the GNU General Public License as published by the |
9 | the Free Software Foundation; either version 2 of the License, or |
9 | Free Software Foundation; either version 3 of the License, or (at your |
10 | (at your option) any later version. |
10 | option) any later version. |
11 | |
11 | |
12 | This program is distributed in the hope that it will be useful, |
12 | This program is distributed in the hope that it will be useful, but |
13 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
13 | WITHOUT ANY WARRANTY; without even the implied warranty of |
14 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
14 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General |
15 | GNU General Public License for more details. |
15 | Public License for more details. |
16 | |
16 | |
17 | You should have received a copy of the GNU General Public License |
17 | You should have received a copy of the GNU General Public License along |
18 | along with gvpe; if not, write to the Free Software |
18 | with this program; if not, see <http://www.gnu.org/licenses/>. |
19 | Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
19 | |
|
|
20 | Additional permission under GNU GPL version 3 section 7 |
|
|
21 | |
|
|
22 | If you modify this Program, or any covered work, by linking or |
|
|
23 | combining it with the OpenSSL project's OpenSSL library (or a modified |
|
|
24 | version of that library), containing parts covered by the terms of the |
|
|
25 | OpenSSL or SSLeay licenses, the licensors of this Program grant you |
|
|
26 | additional permission to convey the resulting work. Corresponding |
|
|
27 | Source for a non-source form of such a combination shall include the |
|
|
28 | source code for the parts of OpenSSL used as well as that of the |
|
|
29 | covered work. |
20 | */ |
30 | */ |
21 | |
31 | |
22 | #include "config.h" |
32 | #include "config.h" |
23 | |
33 | |
24 | #include <cstdio> |
34 | #include <cstdio> |
… | |
… | |
47 | char *thisnode; |
57 | char *thisnode; |
48 | char *identname; |
58 | char *identname; |
49 | |
59 | |
50 | struct configuration conf; |
60 | struct configuration conf; |
51 | |
61 | |
|
|
62 | u8 |
52 | u8 best_protocol (u8 protset) |
63 | best_protocol (u8 protset) |
53 | { |
64 | { |
54 | if (protset & PROT_IPv4 ) return PROT_IPv4; |
65 | if (protset & PROT_IPv4 ) return PROT_IPv4; |
55 | if (protset & PROT_ICMPv4) return PROT_ICMPv4; |
66 | if (protset & PROT_ICMPv4) return PROT_ICMPv4; |
56 | if (protset & PROT_UDPv4 ) return PROT_UDPv4; |
67 | if (protset & PROT_UDPv4 ) return PROT_UDPv4; |
57 | if (protset & PROT_TCPv4 ) return PROT_TCPv4; |
68 | if (protset & PROT_TCPv4 ) return PROT_TCPv4; |
58 | if (protset & PROT_DNSv4 ) return PROT_DNSv4; |
69 | if (protset & PROT_DNSv4 ) return PROT_DNSv4; |
59 | |
70 | |
60 | return 0; |
71 | return 0; |
61 | } |
72 | } |
62 | |
73 | |
|
|
74 | const char * |
63 | const char *strprotocol (u8 protocol) |
75 | strprotocol (u8 protocol) |
64 | { |
76 | { |
65 | if (protocol & PROT_IPv4 ) return "rawip"; |
77 | if (protocol & PROT_IPv4 ) return "rawip"; |
66 | if (protocol & PROT_ICMPv4) return "icmp"; |
78 | if (protocol & PROT_ICMPv4) return "icmp"; |
67 | if (protocol & PROT_UDPv4 ) return "udp"; |
79 | if (protocol & PROT_UDPv4 ) return "udp"; |
68 | if (protocol & PROT_TCPv4 ) return "tcp"; |
80 | if (protocol & PROT_TCPv4 ) return "tcp"; |
69 | if (protocol & PROT_DNSv4 ) return "dns"; |
81 | if (protocol & PROT_DNSv4 ) return "dns"; |
70 | |
82 | |
71 | return "<unknown>"; |
83 | return "<unknown>"; |
72 | } |
84 | } |
73 | |
85 | |
74 | void |
86 | static bool |
75 | conf_node::print () |
87 | match_list (const vector<const char *> &list, const char *str) |
76 | { |
88 | { |
77 | printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %s%s%d\n", |
89 | for (vector<const char *>::const_iterator i = list.end (); i-- > list.begin (); ) |
78 | id, |
90 | if ((*i)[0] == '*' && !(*i)[1]) |
79 | id >> 8, id & 0xff, |
91 | return true; |
80 | compress ? 'Y' : 'N', |
92 | else if (!strcmp (*i, str)) |
81 | connectmode == C_ONDEMAND ? "ondemand" : |
93 | return true; |
82 | connectmode == C_NEVER ? "never" : |
94 | |
83 | connectmode == C_ALWAYS ? "always" : "", |
95 | return false; |
84 | nodename, |
96 | } |
85 | hostname ? hostname : "", |
97 | |
86 | hostname ? ":" : "", |
98 | bool |
87 | hostname ? udp_port : 0 |
99 | conf_node::may_direct (struct conf_node *other) |
88 | ); |
100 | { |
|
|
101 | if (match_list (allow_direct, other->nodename)) |
|
|
102 | return true; |
|
|
103 | |
|
|
104 | if (match_list (deny_direct, other->nodename)) |
|
|
105 | return false; |
|
|
106 | |
|
|
107 | return true; |
89 | } |
108 | } |
90 | |
109 | |
91 | conf_node::~conf_node () |
110 | conf_node::~conf_node () |
92 | { |
111 | { |
93 | #if 0 |
112 | #if 0 |
… | |
… | |
104 | free (dns_hostname); |
123 | free (dns_hostname); |
105 | #endif |
124 | #endif |
106 | #endif |
125 | #endif |
107 | } |
126 | } |
108 | |
127 | |
|
|
128 | void |
109 | void configuration::init () |
129 | configuration::init () |
110 | { |
130 | { |
111 | memset (this, 0, sizeof (*this)); |
131 | memset (this, 0, sizeof (*this)); |
112 | |
132 | |
113 | mtu = DEFAULT_MTU; |
133 | mtu = DEFAULT_MTU; |
|
|
134 | nfmark = 0; |
114 | rekey = DEFAULT_REKEY; |
135 | rekey = DEFAULT_REKEY; |
115 | keepalive = DEFAULT_KEEPALIVE; |
136 | keepalive = DEFAULT_KEEPALIVE; |
116 | llevel = L_INFO; |
137 | llevel = L_INFO; |
117 | ip_proto = IPPROTO_GRE; |
138 | ip_proto = IPPROTO_GRE; |
118 | #if ENABLE_ICMP |
139 | #if ENABLE_ICMP |
… | |
… | |
123 | default_node.tcp_port = DEFAULT_UDPPORT; // ehrm |
144 | default_node.tcp_port = DEFAULT_UDPPORT; // ehrm |
124 | default_node.connectmode = conf_node::C_ALWAYS; |
145 | default_node.connectmode = conf_node::C_ALWAYS; |
125 | default_node.compress = true; |
146 | default_node.compress = true; |
126 | default_node.protocols = 0; |
147 | default_node.protocols = 0; |
127 | default_node.max_retry = DEFAULT_MAX_RETRY; |
148 | default_node.max_retry = DEFAULT_MAX_RETRY; |
|
|
149 | default_node.max_ttl = DEFAULT_MAX_TTL; |
|
|
150 | default_node.max_queue = DEFAULT_MAX_QUEUE; |
128 | default_node.if_up_data = strdup (""); |
151 | default_node.if_up_data = strdup (""); |
129 | |
152 | |
130 | #if ENABLE_DNS |
153 | #if ENABLE_DNS |
131 | default_node.dns_port = 0; // default is 0 == client |
154 | default_node.dns_port = 0; // default is 0 == client |
132 | |
155 | |
… | |
… | |
139 | #endif |
162 | #endif |
140 | |
163 | |
141 | conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid"); |
164 | conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid"); |
142 | } |
165 | } |
143 | |
166 | |
|
|
167 | void |
144 | void configuration::cleanup() |
168 | configuration::cleanup () |
145 | { |
169 | { |
146 | if (rsa_key) |
170 | if (rsa_key) |
147 | RSA_free (rsa_key); |
171 | RSA_free (rsa_key); |
148 | |
172 | |
149 | rsa_key = 0; |
173 | rsa_key = 0; |
150 | |
174 | |
151 | free (pidfilename); pidfilename = 0; |
175 | free (pidfilename); pidfilename = 0; |
152 | free (ifname); ifname = 0; |
176 | free (ifname); ifname = 0; |
153 | #if ENABLE_HTTP_PROXY |
177 | #if ENABLE_HTTP_PROXY |
154 | free (proxy_host); proxy_host = 0; |
178 | free (proxy_host); proxy_host = 0; |
155 | free (proxy_auth); proxy_auth = 0; |
179 | free (proxy_auth); proxy_auth = 0; |
156 | #endif |
180 | #endif |
157 | #if ENABLE_DNS |
181 | #if ENABLE_DNS |
158 | free (dns_forw_host); dns_forw_host = 0; |
182 | free (dns_forw_host); dns_forw_host = 0; |
159 | #endif |
183 | #endif |
|
|
184 | free (script_if_up); script_if_up = 0; |
|
|
185 | free (script_node_up); script_node_up = 0; |
|
|
186 | free (script_node_change); script_node_change = 0; |
|
|
187 | free (script_node_down); script_node_down = 0; |
160 | } |
188 | } |
161 | |
189 | |
162 | void |
190 | void |
163 | configuration::clear () |
191 | configuration::clear () |
164 | { |
192 | { |
… | |
… | |
292 | conf.rekey = atoi (val); |
320 | conf.rekey = atoi (val); |
293 | else if (!strcmp (var, "keepalive")) |
321 | else if (!strcmp (var, "keepalive")) |
294 | conf.keepalive = atoi (val); |
322 | conf.keepalive = atoi (val); |
295 | else if (!strcmp (var, "mtu")) |
323 | else if (!strcmp (var, "mtu")) |
296 | conf.mtu = atoi (val); |
324 | conf.mtu = atoi (val); |
|
|
325 | else if (!strcmp (var, "nfmark")) |
|
|
326 | conf.nfmark = atoi (val); |
297 | else if (!strcmp (var, "if-up")) |
327 | else if (!strcmp (var, "if-up")) |
298 | free (conf.script_if_up), conf.script_if_up = strdup (val); |
328 | free (conf.script_if_up), conf.script_if_up = strdup (val); |
299 | else if (!strcmp (var, "node-up")) |
329 | else if (!strcmp (var, "node-up")) |
300 | free (conf.script_node_up), conf.script_node_up = strdup (val); |
330 | free (conf.script_node_up), conf.script_node_up = strdup (val); |
|
|
331 | else if (!strcmp (var, "node-change")) |
|
|
332 | free (conf.script_node_change), conf.script_node_change = strdup (val); |
301 | else if (!strcmp (var, "node-down")) |
333 | else if (!strcmp (var, "node-down")) |
302 | free (conf.script_node_down), conf.script_node_down = strdup (val); |
334 | free (conf.script_node_down), conf.script_node_down = strdup (val); |
303 | else if (!strcmp (var, "pid-file")) |
335 | else if (!strcmp (var, "pid-file")) |
304 | free (conf.pidfilename), conf.pidfilename = strdup (val); |
336 | free (conf.pidfilename), conf.pidfilename = strdup (val); |
305 | else if (!strcmp (var, "dns-forw-host")) |
337 | else if (!strcmp (var, "dns-forw-host")) |
… | |
… | |
432 | } |
464 | } |
433 | else if (!strcmp (var, "enable-rawip")) |
465 | else if (!strcmp (var, "enable-rawip")) |
434 | { |
466 | { |
435 | u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v; |
467 | u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v; |
436 | } |
468 | } |
|
|
469 | else if (!strcmp (var, "allow-direct")) |
|
|
470 | node->allow_direct.push_back (strdup (val)); |
|
|
471 | else if (!strcmp (var, "deny-direct")) |
|
|
472 | node->deny_direct.push_back (strdup (val)); |
|
|
473 | else if (!strcmp (var, "max-ttl")) |
|
|
474 | node->max_ttl = atof (val); |
|
|
475 | else if (!strcmp (var, "max-queue")) |
|
|
476 | node->max_queue = atoi (val); |
437 | |
477 | |
438 | // unknown or misplaced |
478 | // unknown or misplaced |
439 | else |
479 | else |
440 | return _("unknown configuration directive. (ignored)"); |
480 | return _("unknown configuration directive. (ignored)"); |
441 | |
481 | |
442 | return 0; |
482 | return 0; |
443 | } |
483 | } |
444 | |
484 | |
|
|
485 | void |
|
|
486 | conf_node::finalise () |
|
|
487 | { |
|
|
488 | if (max_queue < 1) |
|
|
489 | { |
|
|
490 | slog (L_WARN, _("%s: max-queue value invalid, setting it to 1."), nodename); |
|
|
491 | max_queue = 1; |
|
|
492 | } |
|
|
493 | |
|
|
494 | if (routerprio > 1 && (connectmode != C_ALWAYS && connectmode != C_DISABLED)) |
|
|
495 | { |
|
|
496 | //slog (L_WARN, _("%s: has non-zero router-priority but either 'never' or 'ondemand' as connectmode, setting it to 'always'."), nodename); |
|
|
497 | connectmode = C_ALWAYS; |
|
|
498 | } |
|
|
499 | } |
|
|
500 | |
|
|
501 | void |
445 | void configuration_parser::parse_argv () |
502 | configuration_parser::parse_argv () |
446 | { |
503 | { |
447 | for (int i = 0; i < argc; ++i) |
504 | for (int i = 0; i < argc; ++i) |
448 | { |
505 | { |
449 | char *v = argv [i]; |
506 | char *v = argv [i]; |
450 | |
507 | |
… | |
… | |
552 | slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode); |
609 | slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode); |
553 | exit (EXIT_FAILURE); |
610 | exit (EXIT_FAILURE); |
554 | } |
611 | } |
555 | |
612 | |
556 | free (fname); |
613 | free (fname); |
557 | } |
|
|
558 | |
614 | |
|
|
615 | for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i) |
|
|
616 | (*i)->finalise (); |
|
|
617 | } |
|
|
618 | |
|
|
619 | char * |
559 | char *configuration::config_filename (const char *name, const char *dflt) |
620 | configuration::config_filename (const char *name, const char *dflt) |
560 | { |
621 | { |
561 | char *fname; |
622 | char *fname; |
562 | |
623 | |
563 | asprintf (&fname, name ? name : dflt, ::thisnode); |
624 | asprintf (&fname, name ? name : dflt, ::thisnode); |
564 | |
625 | |
… | |
… | |
568 | asprintf (&fname, "%s/%s", confbase, rname); |
629 | asprintf (&fname, "%s/%s", confbase, rname); |
569 | free (rname); |
630 | free (rname); |
570 | } |
631 | } |
571 | |
632 | |
572 | return fname; |
633 | return fname; |
|
|
634 | } |
|
|
635 | |
|
|
636 | void |
|
|
637 | conf_node::print () |
|
|
638 | { |
|
|
639 | printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %02x %s%s%d\n", |
|
|
640 | id, |
|
|
641 | id >> 8, id & 0xff, |
|
|
642 | compress ? 'Y' : 'N', |
|
|
643 | connectmode == C_ONDEMAND ? "ondemand" |
|
|
644 | : connectmode == C_NEVER ? "never" |
|
|
645 | : connectmode == C_ALWAYS ? "always" |
|
|
646 | : connectmode == C_DISABLED ? "disabled" |
|
|
647 | : "", |
|
|
648 | nodename, |
|
|
649 | protocols, |
|
|
650 | hostname ? hostname : "", |
|
|
651 | hostname ? ":" : "", |
|
|
652 | hostname ? udp_port : 0 |
|
|
653 | ); |
573 | } |
654 | } |
574 | |
655 | |
575 | void |
656 | void |
576 | configuration::print () |
657 | configuration::print () |
577 | { |
658 | { |
… | |
… | |
584 | printf (_("interface: %s\n"), ifname); |
665 | printf (_("interface: %s\n"), ifname); |
585 | printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>"); |
666 | printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>"); |
586 | printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1); |
667 | printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1); |
587 | printf ("\n"); |
668 | printf ("\n"); |
588 | |
669 | |
589 | printf ("%4s %-17s %s %-8.8s %-10.10s %s\n", |
670 | printf ("%4s %-17s %s %-8.8s %-10.10s %04s %s\n", |
590 | _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port")); |
671 | _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Prot"), _("Host:Port")); |
591 | |
672 | |
592 | for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i) |
673 | for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i) |
593 | (*i)->print (); |
674 | (*i)->print (); |
594 | |
675 | |
595 | printf ("\n"); |
676 | printf ("\n"); |
… | |
… | |
605 | configuration::~configuration () |
686 | configuration::~configuration () |
606 | { |
687 | { |
607 | cleanup (); |
688 | cleanup (); |
608 | } |
689 | } |
609 | |
690 | |
610 | |
|
|