ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.h
(Generate patch)

Comparing gvpe/src/conf.h (file contents):
Revision 1.31 by pcg, Tue Apr 26 00:55:55 2005 UTC vs.
Revision 1.45 by root, Thu Jul 18 17:35:10 2013 UTC

1/* 1/*
2 conf.h -- configuration database 2 conf.h -- configuration database
3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de> 3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE. 5 This file is part of GVPE.
6 6
7 GVPE is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify it
8 it under the terms of the GNU General Public License as published by 8 under the terms of the GNU General Public License as published by the
9 the Free Software Foundation; either version 2 of the License, or 9 Free Software Foundation; either version 3 of the License, or (at your
10 (at your option) any later version. 10 option) any later version.
11 11
12 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful, but
13 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 GNU General Public License for more details. 15 Public License for more details.
16 16
17 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License along
18 along with gvpe; if not, write to the Free Software 18 with this program; if not, see <http://www.gnu.org/licenses/>.
19 Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA 19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
20*/ 30*/
21 31
22#ifndef GVPE_CONF_H__ 32#ifndef GVPE_CONF_H__
23#define GVPE_CONF_H__ 33#define GVPE_CONF_H__
24 34
27#include <openssl/rsa.h> 37#include <openssl/rsa.h>
28 38
29#include "slog.h" 39#include "slog.h"
30#include "global.h" 40#include "global.h"
31 41
32#define DEFAULT_REKEY 3600 42#define DEFAULT_REKEY 3607 // interval between rekeys
43#define DEFAULT_RESEED 3613 // interval between rng reseeds
33#define DEFAULT_KEEPALIVE 60 // one keepalive/minute (it's just 8 bytes...) 44#define DEFAULT_KEEPALIVE 60 // one keepalive/minute (it's just 8 bytes...)
34#define DEFAULT_UDPPORT 655 // same as tinc, conflicts would be rare 45#define DEFAULT_UDPPORT 655 // same as tinc, conflicts would be rare
35#define DEFAULT_MTU 1500 // let's ether-net 46#define DEFAULT_MTU 1500 // let's ether-net
36#define DEFAULT_MAX_RETRY 3600 // retry at least this often 47#define DEFAULT_MAX_RETRY 3600 // retry at least this often
48#define DEFAULT_MAX_TTL 60 // packets expire after this many seconds
49#define DEFAULT_MAX_QUEUE 512 // never queue more than this many packets
37 50
38#define DEFAULT_DNS_TIMEOUT_FACTOR 8.F // initial retry timeout multiple 51#define DEFAULT_DNS_TIMEOUT_FACTOR 8.F // initial retry timeout multiple
39#define DEFAULT_DNS_SEND_INTERVAL .01F // minimum send interval 52#define DEFAULT_DNS_SEND_INTERVAL .01F // minimum send interval
40#define DEFAULT_DNS_OVERLAP_FACTOR .5F // RTT * LATENCY_FACTOR == sending rate 53#define DEFAULT_DNS_OVERLAP_FACTOR .5F // RTT * LATENCY_FACTOR == sending rate
41#define DEFAULT_DNS_MAX_OUTSTANDING 100 // max. number of outstanding requests 54#define DEFAULT_DNS_MAX_OUTSTANDING 100 // max. number of outstanding requests
45 PROT_UDPv4 = 0x01, // udp over ipv4 58 PROT_UDPv4 = 0x01, // udp over ipv4
46 PROT_IPv4 = 0x02, // generic ip protocol 59 PROT_IPv4 = 0x02, // generic ip protocol
47 PROT_TCPv4 = 0x04, // tcp over ipv4 (server) 60 PROT_TCPv4 = 0x04, // tcp over ipv4 (server)
48 PROT_ICMPv4 = 0x08, // icmp over ipv4 61 PROT_ICMPv4 = 0x08, // icmp over ipv4
49 PROT_DNSv4 = 0x10, // dns tunnel ipv4 (server) 62 PROT_DNSv4 = 0x10, // dns tunnel ipv4 (server)
63 PROT_ALL = 0x1f
50}; 64};
51 65
52#define PROT_RELIABLE (PROT_TCPv4 | PROT_DNSv4) 66#define PROT_RELIABLE (PROT_TCPv4 | PROT_DNSv4)
53#define PROT_SLOW PROT_DNSv4 67#define PROT_SLOW PROT_DNSv4
54 68
71 u16 dns_port; 85 u16 dns_port;
72 86
73 u8 protocols; // protocols this host can send & receive 87 u8 protocols; // protocols this host can send & receive
74 u16 udp_port, tcp_port; // the port to bind to 88 u16 udp_port, tcp_port; // the port to bind to
75 int max_retry; 89 int max_retry;
90 double max_ttl; // packets expire after this many seconds
91 int max_queue; // maixmum send queue length
76 92
77 enum connectmode { C_ONDEMAND, C_NEVER, C_ALWAYS, C_DISABLED } connectmode; 93 enum connectmode { C_ONDEMAND, C_NEVER, C_ALWAYS, C_DISABLED } connectmode;
78 bool compress; 94 bool compress;
79 bool inherit_tos; // inherit TOS in packets send to this destination 95 bool inherit_tos; // inherit TOS in packets send to this destination
80 96
97 vector<const char *> allow_direct;
98 vector<const char *> deny_direct;
99
81 u32 routerprio; 100 u32 routerprio;
101
102 u8 connectable_protocols () const
103 {
104 u8 protocols = this->protocols;
105
106 // mask out endpoints we can't connect to
107 if (!udp_port) protocols &= ~PROT_UDPv4;
108 if (!tcp_port) protocols &= ~PROT_TCPv4;
109 if (!dns_port) protocols &= ~PROT_DNSv4;
110
111 return protocols;
112 }
113
114 bool may_direct (struct conf_node *other);
115 void finalise ();
82 116
83 void print (); 117 void print ();
84 118
85 ~conf_node (); 119 ~conf_node ();
86}; 120};
89{ 123{
90 typedef vector<conf_node *> node_vector; 124 typedef vector<conf_node *> node_vector;
91 node_vector nodes; 125 node_vector nodes;
92 conf_node default_node; 126 conf_node default_node;
93 conf_node *thisnode; 127 conf_node *thisnode;
128 char serial[SERIAL_SIZE];
129 char *seed_dev; // the randomd evice to use for seeding
130 double reseed; // the interval between additional seeds
94 int mtu; // the mtu used for outgoing tunnel packets 131 int mtu; // the mtu used for outgoing tunnel packets
132 int nfmark; // the SO_MARK // netfilter mark // fwmark
95 double rekey; // rekey interval 133 double rekey; // rekey interval
96 double keepalive; // keepalive probes interval 134 double keepalive; // keepalive probes interval
97 char *ifname; // the interface name (tap0 ...) 135 char *ifname; // the interface name (tap0 ...)
98 bool ifpersist; // should the interface be persistent 136 bool ifpersist; // should the interface be persistent
99 char *prikeyfile; 137 char *prikeyfile;
100 RSA *rsa_key; // our private rsa key 138 RSA *rsa_key; // our private rsa key
101 loglevel llevel; 139 loglevel llevel;
102 u8 ip_proto; // the ip protocol to use 140 u8 ip_proto; // the ip protocol to use
141 uid_t change_uid; // the uid of the user to switch to, or 0
142 gid_t change_gid; // the gid of the user to switch to, or 0
143 char *change_root;// the path to chroot to, "/" == anonymous
103#if ENABLE_ICMP 144#if ENABLE_ICMP
104 u8 icmp_type; // the icmp type for the icmp-protocol 145 u8 icmp_type; // the icmp type for the icmp-protocol
105#endif 146#endif
106 147
107 char *script_if_up; 148 char *script_if_up;
108 char *script_node_up; 149 char *script_node_up;
150 char *script_node_change;
109 char *script_node_down; 151 char *script_node_down;
110 char *pidfilename; 152 char *pidfilename;
111 153
112#if ENABLE_HTTP_PROXY 154#if ENABLE_HTTP_PROXY
113 char *proxy_auth; // login:password 155 char *proxy_auth; // login:password
115 u16 proxy_port; // the proxy port, e.g. 3128 157 u16 proxy_port; // the proxy port, e.g. 3128
116#endif 158#endif
117 159
118#if ENABLE_DNS 160#if ENABLE_DNS
119 char *dns_forw_host; 161 char *dns_forw_host;
162 bool dns_case_preserving;
120 u16 dns_forw_port; 163 u16 dns_forw_port;
121 float dns_timeout_factor; 164 float dns_timeout_factor;
122 float dns_send_interval; 165 float dns_send_interval;
123 float dns_overlap_factor; 166 float dns_overlap_factor;
124 int dns_max_outstanding; 167 int dns_max_outstanding;
126 169
127 void init (); 170 void init ();
128 void cleanup (); 171 void cleanup ();
129 void clear (); 172 void clear ();
130 173
174 conf_node *find_node (const char *name);
175
131 // create a filename from string, replacing %s by the nodename 176 // create a filename from string, replacing %s by the nodename
132 // and using relative paths under confbase. 177 // and using relative paths under confbase.
133 char *config_filename (const char *name, const char *dflt); 178 char *config_filename (const char *name, const char *dflt = 0);
134 179
135 void print (); 180 void print ();
136 181
137 configuration (); 182 configuration ();
138 ~configuration (); 183 ~configuration ();
148 int argc; 193 int argc;
149 char **argv; 194 char **argv;
150 195
151 configuration_parser (configuration &conf, bool need_keys, int argc, char **argv); 196 configuration_parser (configuration &conf, bool need_keys, int argc, char **argv);
152 197
198 void parse_file (const char *fname);
153 const char *parse_line (char *line); 199 const char *parse_line (char *line);
154 void parse_argv (); 200 void parse_argv ();
155}; 201};
156 202
157extern struct configuration conf; 203extern struct configuration conf;

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines