ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
Revision: 1.56
Committed: Sun Mar 6 21:01:36 2011 UTC (13 years, 2 months ago) by root
Content type: text/plain
Branch: MAIN
Changes since 1.55: +8 -8 lines
Log Message:
*** empty log message ***

File Contents

# Content
1 /*
2 conf.C -- configuration code
3 Copyright (C) 2003-2008,2011 Marc Lehmann <gvpe@schmorp.de>
4
5 This file is part of GVPE.
6
7 GVPE is free software; you can redistribute it and/or modify it
8 under the terms of the GNU General Public License as published by the
9 Free Software Foundation; either version 3 of the License, or (at your
10 option) any later version.
11
12 This program is distributed in the hope that it will be useful, but
13 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 Public License for more details.
16
17 You should have received a copy of the GNU General Public License along
18 with this program; if not, see <http://www.gnu.org/licenses/>.
19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
30 */
31
32 #include "config.h"
33
34 #include <cstdio>
35 #include <cstdlib>
36 #include <cstring>
37
38 #include <errno.h>
39 #include <netdb.h>
40 #include <sys/stat.h>
41 #include <sys/types.h>
42 #include <unistd.h>
43
44 #include "netcompat.h"
45
46 #include <openssl/err.h>
47 #include <openssl/pem.h>
48 #include <openssl/rsa.h>
49 #include <openssl/rand.h>
50 #include <openssl/bn.h>
51
52 #include "conf.h"
53 #include "slog.h"
54 #include "util.h"
55
56 char *confbase;
57 char *thisnode;
58 char *identname;
59
60 struct configuration conf;
61
62 u8
63 best_protocol (u8 protset)
64 {
65 if (protset & PROT_IPv4 ) return PROT_IPv4;
66 if (protset & PROT_ICMPv4) return PROT_ICMPv4;
67 if (protset & PROT_UDPv4 ) return PROT_UDPv4;
68 if (protset & PROT_TCPv4 ) return PROT_TCPv4;
69 if (protset & PROT_DNSv4 ) return PROT_DNSv4;
70
71 return 0;
72 }
73
74 const char *
75 strprotocol (u8 protocol)
76 {
77 if (protocol & PROT_IPv4 ) return "rawip";
78 if (protocol & PROT_ICMPv4) return "icmp";
79 if (protocol & PROT_UDPv4 ) return "udp";
80 if (protocol & PROT_TCPv4 ) return "tcp";
81 if (protocol & PROT_DNSv4 ) return "dns";
82
83 return "<unknown>";
84 }
85
86 static bool
87 match_list (const vector<const char *> &list, const char *str)
88 {
89 for (vector<const char *>::const_iterator i = list.end (); i-- > list.begin (); )
90 if ((*i)[0] == '*' && !(*i)[1])
91 return true;
92 else if (!strcmp (*i, str))
93 return true;
94
95 return false;
96 }
97
98 bool
99 conf_node::may_direct (struct conf_node *other)
100 {
101 if (match_list (allow_direct, other->nodename))
102 return true;
103
104 if (match_list (deny_direct, other->nodename))
105 return false;
106
107 return true;
108 }
109
110 conf_node::~conf_node ()
111 {
112 #if 0
113 // does not work, because string pointers etc. are shared
114 // is not called, however
115 if (rsa_key)
116 RSA_free (rsa_key);
117
118 free (nodename);
119 free (hostname);
120 free (if_up_data);
121 #if ENABLE_DNS
122 free (domain);
123 free (dns_hostname);
124 #endif
125 #endif
126 }
127
128 void
129 configuration::init ()
130 {
131 memset (this, 0, sizeof (*this));
132
133 mtu = DEFAULT_MTU;
134 nfmark = 0;
135 rekey = DEFAULT_REKEY;
136 keepalive = DEFAULT_KEEPALIVE;
137 llevel = L_INFO;
138 ip_proto = IPPROTO_GRE;
139 #if ENABLE_ICMP
140 icmp_type = ICMP_ECHOREPLY;
141 #endif
142
143 default_node.udp_port = DEFAULT_UDPPORT;
144 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm
145 default_node.connectmode = conf_node::C_ALWAYS;
146 default_node.compress = true;
147 default_node.protocols = 0;
148 default_node.max_retry = DEFAULT_MAX_RETRY;
149 default_node.max_ttl = DEFAULT_MAX_TTL;
150 default_node.max_queue = DEFAULT_MAX_QUEUE;
151 default_node.if_up_data = strdup ("");
152
153 #if ENABLE_DNS
154 default_node.dns_port = 0; // default is 0 == client
155
156 dns_case_preserving = true;
157 dns_forw_host = strdup ("127.0.0.1");
158 dns_forw_port = 53;
159 dns_timeout_factor = DEFAULT_DNS_TIMEOUT_FACTOR;
160 dns_send_interval = DEFAULT_DNS_SEND_INTERVAL;
161 dns_overlap_factor = DEFAULT_DNS_OVERLAP_FACTOR;
162 dns_max_outstanding = DEFAULT_DNS_MAX_OUTSTANDING;
163 #endif
164
165 conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid");
166 }
167
168 void
169 configuration::cleanup ()
170 {
171 if (rsa_key)
172 RSA_free (rsa_key);
173
174 rsa_key = 0;
175
176 free (pidfilename); pidfilename = 0;
177 free (ifname); ifname = 0;
178 #if ENABLE_HTTP_PROXY
179 free (proxy_host); proxy_host = 0;
180 free (proxy_auth); proxy_auth = 0;
181 #endif
182 #if ENABLE_DNS
183 free (dns_forw_host); dns_forw_host = 0;
184 #endif
185 free (script_if_up); script_if_up = 0;
186 free (script_node_up); script_node_up = 0;
187 free (script_node_change); script_node_change = 0;
188 free (script_node_down); script_node_down = 0;
189 }
190
191 void
192 configuration::clear ()
193 {
194 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
195 delete *i;
196
197 nodes.clear ();
198
199 cleanup ();
200 init ();
201 }
202
203 //static bool
204 //is_true (const char *name)
205 //{
206 //re
207 //}
208
209 #define parse_bool(target,name,trueval,falseval) do { \
210 if (!strcmp (val, "yes")) target = trueval; \
211 else if (!strcmp (val, "no")) target = falseval; \
212 else if (!strcmp (val, "true")) target = trueval; \
213 else if (!strcmp (val, "false")) target = falseval; \
214 else if (!strcmp (val, "on")) target = trueval; \
215 else if (!strcmp (val, "off")) target = falseval; \
216 else \
217 return _("illegal boolean value, only 'yes|true|on' or 'no|false|off' allowed, ignored"); \
218 } while (0)
219
220 const char *
221 configuration_parser::parse_line (char *line)
222 {
223 {
224 char *end = line + strlen (line);
225
226 while (*end < ' ' && end >= line)
227 end--;
228
229 *++end = 0;
230 }
231
232 char *tok = line;
233 const char *var = strtok (tok, "\t =");
234 tok = 0;
235
236 if (!var || !var[0])
237 return 0; /* no tokens on this line */
238
239 if (var[0] == '#')
240 return 0; /* comment: ignore */
241
242 char *val = strtok (NULL, "\t\n\r =");
243
244 if (!val || val[0] == '#')
245 return _("no value given for variable, ignored");
246
247 else if (!strcmp (var, "on"))
248 {
249 if (::thisnode
250 && ((val[0] == '!' && strcmp (val + 1, ::thisnode))
251 || !strcmp (val, ::thisnode)))
252 return parse_line (strtok (NULL, "\n\r"));
253 }
254
255 else if (!strcmp (var, "include"))
256 {
257 char *fname = conf.config_filename (val);
258 parse_file (fname);
259 free (fname);
260 }
261
262 // truly global
263 else if (!strcmp (var, "loglevel"))
264 {
265 loglevel l = string_to_loglevel (val);
266
267 if (l == L_NONE)
268 return _("unknown loglevel, ignored");
269 }
270 else if (!strcmp (var, "ip-proto"))
271 conf.ip_proto = atoi (val);
272 else if (!strcmp (var, "icmp-type"))
273 {
274 #if ENABLE_ICMP
275 conf.icmp_type = atoi (val);
276 #endif
277 }
278
279 // per config
280 else if (!strcmp (var, "node"))
281 {
282 parse_argv ();
283
284 conf.default_node.id++;
285 node = new conf_node (conf.default_node);
286 conf.nodes.push_back (node);
287 node->nodename = strdup (val);
288
289 {
290 char *fname;
291 FILE *f;
292
293 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
294
295 f = fopen (fname, "r");
296 if (f)
297 {
298 node->rsa_key = RSA_new ();
299
300 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
301 {
302 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
303 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
304 exit (EXIT_FAILURE);
305 }
306
307 require (RSA_blinding_on (node->rsa_key, 0));
308
309 fclose (f);
310 }
311 else
312 {
313 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
314
315 if (need_keys)
316 exit (EXIT_FAILURE);
317 }
318
319 free (fname);
320 }
321
322 if (::thisnode && !strcmp (node->nodename, ::thisnode))
323 conf.thisnode = node;
324 }
325 else if (!strcmp (var, "private-key"))
326 free (conf.prikeyfile), conf.prikeyfile = strdup (val);
327 else if (!strcmp (var, "ifpersist"))
328 parse_bool (conf.ifpersist, "ifpersist", true, false);
329 else if (!strcmp (var, "ifname"))
330 free (conf.ifname), conf.ifname = strdup (val);
331 else if (!strcmp (var, "rekey"))
332 conf.rekey = atoi (val);
333 else if (!strcmp (var, "keepalive"))
334 conf.keepalive = atoi (val);
335 else if (!strcmp (var, "mtu"))
336 conf.mtu = atoi (val);
337 else if (!strcmp (var, "nfmark"))
338 conf.nfmark = atoi (val);
339 else if (!strcmp (var, "if-up"))
340 free (conf.script_if_up), conf.script_if_up = strdup (val);
341 else if (!strcmp (var, "node-up"))
342 free (conf.script_node_up), conf.script_node_up = strdup (val);
343 else if (!strcmp (var, "node-change"))
344 free (conf.script_node_change), conf.script_node_change = strdup (val);
345 else if (!strcmp (var, "node-down"))
346 free (conf.script_node_down), conf.script_node_down = strdup (val);
347 else if (!strcmp (var, "pid-file"))
348 free (conf.pidfilename), conf.pidfilename = strdup (val);
349 else if (!strcmp (var, "dns-forw-host"))
350 {
351 #if ENABLE_DNS
352 free (conf.dns_forw_host), conf.dns_forw_host = strdup (val);
353 #endif
354 }
355 else if (!strcmp (var, "dns-forw-port"))
356 {
357 #if ENABLE_DNS
358 conf.dns_forw_port = atoi (val);
359 #endif
360 }
361 else if (!strcmp (var, "dns-timeout-factor"))
362 {
363 #if ENABLE_DNS
364 conf.dns_timeout_factor = atof (val);
365 #endif
366 }
367 else if (!strcmp (var, "dns-send-interval"))
368 {
369 #if ENABLE_DNS
370 conf.dns_send_interval = atoi (val);
371 #endif
372 }
373 else if (!strcmp (var, "dns-overlap-factor"))
374 {
375 #if ENABLE_DNS
376 conf.dns_overlap_factor = atof (val);
377 #endif
378 }
379 else if (!strcmp (var, "dns-max-outstanding"))
380 {
381 #if ENABLE_DNS
382 conf.dns_max_outstanding = atoi (val);
383 #endif
384 }
385 else if (!strcmp (var, "dns-case-preserving"))
386 {
387 #if ENABLE_DNS
388 parse_bool (conf.dns_case_preserving, "dns-case-preserving", true, false);
389 #endif
390 }
391 else if (!strcmp (var, "http-proxy-host"))
392 {
393 #if ENABLE_HTTP_PROXY
394 free (conf.proxy_host), conf.proxy_host = strdup (val);
395 #endif
396 }
397 else if (!strcmp (var, "http-proxy-port"))
398 {
399 #if ENABLE_HTTP_PROXY
400 conf.proxy_port = atoi (val);
401 #endif
402 }
403 else if (!strcmp (var, "http-proxy-auth"))
404 {
405 #if ENABLE_HTTP_PROXY
406 conf.proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
407 #endif
408 }
409
410 /* node-specific, non-defaultable */
411 else if (node != &conf.default_node && !strcmp (var, "hostname"))
412 free (node->hostname), node->hostname = strdup (val);
413
414 /* node-specific, defaultable */
415 else if (!strcmp (var, "udp-port"))
416 node->udp_port = atoi (val);
417 else if (!strcmp (var, "tcp-port"))
418 node->tcp_port = atoi (val);
419 else if (!strcmp (var, "dns-hostname"))
420 {
421 #if ENABLE_DNS
422 free (node->dns_hostname), node->dns_hostname = strdup (val);
423 #endif
424 }
425 else if (!strcmp (var, "dns-port"))
426 {
427 #if ENABLE_DNS
428 node->dns_port = atoi (val);
429 #endif
430 }
431 else if (!strcmp (var, "dns-domain"))
432 {
433 #if ENABLE_DNS
434 free (node->domain), node->domain = strdup (val);
435 #endif
436 }
437 else if (!strcmp (var, "if-up-data"))
438 free (node->if_up_data), node->if_up_data = strdup (val);
439 else if (!strcmp (var, "router-priority"))
440 node->routerprio = atoi (val);
441 else if (!strcmp (var, "max-retry"))
442 node->max_retry = atoi (val);
443 else if (!strcmp (var, "connect"))
444 {
445 if (!strcmp (val, "ondemand"))
446 node->connectmode = conf_node::C_ONDEMAND;
447 else if (!strcmp (val, "never"))
448 node->connectmode = conf_node::C_NEVER;
449 else if (!strcmp (val, "always"))
450 node->connectmode = conf_node::C_ALWAYS;
451 else if (!strcmp (val, "disabled"))
452 node->connectmode = conf_node::C_DISABLED;
453 else
454 return _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', ignored");
455 }
456 else if (!strcmp (var, "inherit-tos"))
457 parse_bool (node->inherit_tos, "inherit-tos", true, false);
458 else if (!strcmp (var, "compress"))
459 parse_bool (node->compress, "compress", true, false);
460 // all these bool options really really cost a lot of executable size!
461 else if (!strcmp (var, "enable-tcp"))
462 {
463 #if ENABLE_TCP
464 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
465 #endif
466 }
467 else if (!strcmp (var, "enable-icmp"))
468 {
469 #if ENABLE_ICMP
470 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
471 #endif
472 }
473 else if (!strcmp (var, "enable-dns"))
474 {
475 #if ENABLE_DNS
476 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
477 #endif
478 }
479 else if (!strcmp (var, "enable-udp"))
480 {
481 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
482 }
483 else if (!strcmp (var, "enable-rawip"))
484 {
485 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
486 }
487 else if (!strcmp (var, "allow-direct"))
488 node->allow_direct.push_back (strdup (val));
489 else if (!strcmp (var, "deny-direct"))
490 node->deny_direct.push_back (strdup (val));
491 else if (!strcmp (var, "max-ttl"))
492 node->max_ttl = atof (val);
493 else if (!strcmp (var, "max-queue"))
494 node->max_queue = atoi (val);
495
496 // unknown or misplaced
497 else
498 return _("unknown configuration directive - ignored");
499
500 return 0;
501 }
502
503 void
504 conf_node::finalise ()
505 {
506 if (max_queue < 1)
507 {
508 slog (L_WARN, _("%s: max-queue value invalid, setting it to 1."), nodename);
509 max_queue = 1;
510 }
511
512 if (routerprio > 1 && (connectmode != C_ALWAYS && connectmode != C_DISABLED))
513 {
514 //slog (L_WARN, _("%s: has non-zero router-priority but either 'never' or 'ondemand' as connectmode, setting it to 'always'."), nodename);
515 connectmode = C_ALWAYS;
516 }
517 }
518
519 void
520 configuration_parser::parse_argv ()
521 {
522 for (int i = 0; i < argc; ++i)
523 {
524 char *v = argv [i];
525
526 if (!*v)
527 continue;
528
529 char *enode = v;
530
531 while (*enode != '.' && *enode > ' ' && *enode != '=' && *enode)
532 enode++;
533
534 if (*enode != '.')
535 enode = 0;
536
537 char *wnode = node == &conf.default_node
538 ? 0
539 : node->nodename;
540
541 if ((!wnode && !enode)
542 || (wnode && enode && !strncmp (wnode, v, enode - v)))
543 {
544 const char *warn = parse_line (enode ? enode + 1 : v);
545
546 if (warn)
547 slog (L_WARN, _("%s, while parsing command line option '%s'."), warn, v);
548
549 *v = 0;
550 }
551 }
552 }
553
554 void
555 configuration_parser::parse_file (const char *fname)
556 {
557 if (FILE *f = fopen (fname, "r"))
558 {
559 char line [2048];
560 int lineno = 0;
561
562 while (fgets (line, sizeof (line), f))
563 {
564 lineno++;
565
566 const char *warn = parse_line (line);
567
568 if (warn)
569 slog (L_WARN, _("%s, at '%s', line %d."), warn, fname, lineno);
570 }
571
572 fclose (f);
573
574 parse_argv ();
575 }
576 else
577 {
578 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
579 exit (EXIT_FAILURE);
580 }
581 }
582
583 configuration_parser::configuration_parser (configuration &conf,
584 bool need_keys,
585 int argc,
586 char **argv)
587 : conf (conf),need_keys (need_keys), argc (argc), argv (argv)
588 {
589 char *fname;
590
591 conf.clear ();
592 node = &conf.default_node;
593
594 asprintf (&fname, "%s/gvpe.conf", confbase);
595 parse_file (fname);
596 free (fname);
597
598 fname = conf.config_filename (conf.prikeyfile, "hostkey");
599
600 if (FILE *f = fopen (fname, "r"))
601 {
602 conf.rsa_key = RSA_new ();
603
604 if (!PEM_read_RSAPrivateKey (f, &conf.rsa_key, NULL, NULL))
605 {
606 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
607 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
608 exit (EXIT_FAILURE);
609 }
610
611 require (RSA_blinding_on (conf.rsa_key, 0));
612
613 fclose (f);
614 }
615 else
616 {
617 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
618
619 if (need_keys)
620 exit (EXIT_FAILURE);
621 }
622
623 free (fname);
624
625 if (need_keys && ::thisnode
626 && conf.rsa_key && conf.thisnode && conf.thisnode->rsa_key)
627 if (BN_cmp (conf.rsa_key->n, conf.thisnode->rsa_key->n) != 0
628 || BN_cmp (conf.rsa_key->e, conf.thisnode->rsa_key->e) != 0)
629 {
630 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
631 exit (EXIT_FAILURE);
632 }
633
634 for (configuration::node_vector::iterator i = conf.nodes.begin(); i != conf.nodes.end(); ++i)
635 (*i)->finalise ();
636 }
637
638 char *
639 configuration::config_filename (const char *name, const char *dflt)
640 {
641 char *fname;
642
643 asprintf (&fname, name ? name : dflt, ::thisnode);
644
645 if (!ABSOLUTE_PATH (fname))
646 {
647 char *rname = fname;
648 asprintf (&fname, "%s/%s", confbase, rname);
649 free (rname);
650 }
651
652 return fname;
653 }
654
655 void
656 conf_node::print ()
657 {
658 printf ("%4d fe:fd:80:00:0%1x:%02x %c %-8.8s %-10.10s %02x %s%s%d\n",
659 id,
660 id >> 8, id & 0xff,
661 compress ? 'Y' : 'N',
662 connectmode == C_ONDEMAND ? "ondemand"
663 : connectmode == C_NEVER ? "never"
664 : connectmode == C_ALWAYS ? "always"
665 : connectmode == C_DISABLED ? "disabled"
666 : "",
667 nodename,
668 protocols,
669 hostname ? hostname : "",
670 hostname ? ":" : "",
671 hostname ? udp_port : 0
672 );
673 }
674
675 void
676 configuration::print ()
677 {
678 printf (_("\nConfiguration\n\n"));
679 printf (_("# of nodes: %d\n"), nodes.size ());
680 printf (_("this node: %s\n"), thisnode ? thisnode->nodename : "<unset>");
681 printf (_("MTU: %d\n"), mtu);
682 printf (_("rekeying interval: %d\n"), rekey);
683 printf (_("keepalive interval: %d\n"), keepalive);
684 printf (_("interface: %s\n"), ifname);
685 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
686 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1);
687 printf ("\n");
688
689 printf ("%4s %-17s %s %-8.8s %-10.10s %04s %s\n",
690 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Prot"), _("Host:Port"));
691
692 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
693 (*i)->print ();
694
695 printf ("\n");
696 }
697
698 configuration::configuration ()
699 {
700 asprintf (&confbase, "%s/gvpe", CONFDIR);
701
702 init ();
703 }
704
705 configuration::~configuration ()
706 {
707 cleanup ();
708 }
709