ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.h
Revision: 1.44
Committed: Wed Jul 17 16:40:57 2013 UTC (10 years, 10 months ago) by root
Content type: text/plain
Branch: MAIN
Changes since 1.43: +2 -0 lines
Log Message:
*** empty log message ***

File Contents

# Content
1 /*
2 conf.h -- configuration database
3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de>
4
5 This file is part of GVPE.
6
7 GVPE is free software; you can redistribute it and/or modify it
8 under the terms of the GNU General Public License as published by the
9 Free Software Foundation; either version 3 of the License, or (at your
10 option) any later version.
11
12 This program is distributed in the hope that it will be useful, but
13 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 Public License for more details.
16
17 You should have received a copy of the GNU General Public License along
18 with this program; if not, see <http://www.gnu.org/licenses/>.
19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
30 */
31
32 #ifndef GVPE_CONF_H__
33 #define GVPE_CONF_H__
34
35 #include <vector>
36
37 #include <openssl/rsa.h>
38
39 #include "slog.h"
40 #include "global.h"
41
42 #define DEFAULT_REKEY 3607 // interval between rekeys
43 #define DEFAULT_RESEED 3613 // interval between rng reseeds
44 #define DEFAULT_KEEPALIVE 60 // one keepalive/minute (it's just 8 bytes...)
45 #define DEFAULT_UDPPORT 655 // same as tinc, conflicts would be rare
46 #define DEFAULT_MTU 1500 // let's ether-net
47 #define DEFAULT_MAX_RETRY 3600 // retry at least this often
48 #define DEFAULT_MAX_TTL 60 // packets expire after this many seconds
49 #define DEFAULT_MAX_QUEUE 512 // never queue more than this many packets
50
51 #define DEFAULT_DNS_TIMEOUT_FACTOR 8.F // initial retry timeout multiple
52 #define DEFAULT_DNS_SEND_INTERVAL .01F // minimum send interval
53 #define DEFAULT_DNS_OVERLAP_FACTOR .5F // RTT * LATENCY_FACTOR == sending rate
54 #define DEFAULT_DNS_MAX_OUTSTANDING 100 // max. number of outstanding requests
55
56 enum
57 {
58 PROT_UDPv4 = 0x01, // udp over ipv4
59 PROT_IPv4 = 0x02, // generic ip protocol
60 PROT_TCPv4 = 0x04, // tcp over ipv4 (server)
61 PROT_ICMPv4 = 0x08, // icmp over ipv4
62 PROT_DNSv4 = 0x10, // dns tunnel ipv4 (server)
63 PROT_ALL = 0x1f
64 };
65
66 #define PROT_RELIABLE (PROT_TCPv4 | PROT_DNSv4)
67 #define PROT_SLOW PROT_DNSv4
68
69 // select the "best" protocol of the available ones
70 u8 best_protocol (u8 protset);
71 const char *strprotocol (u8 protocol);
72
73 struct conf_node
74 {
75 int id; // the id of this node, a 12-bit-number
76
77 RSA *rsa_key; // his public key
78 char *nodename; // nodename, an internal nickname.
79 char *hostname; // hostname, if known, or NULL.
80 char *if_up_data;
81 #if ENABLE_DNS
82 char *domain; // dns tunnel domain
83 #endif
84 char *dns_hostname;
85 u16 dns_port;
86
87 u8 protocols; // protocols this host can send & receive
88 u16 udp_port, tcp_port; // the port to bind to
89 int max_retry;
90 double max_ttl; // packets expire after this many seconds
91 int max_queue; // maixmum send queue length
92
93 enum connectmode { C_ONDEMAND, C_NEVER, C_ALWAYS, C_DISABLED } connectmode;
94 bool compress;
95 bool inherit_tos; // inherit TOS in packets send to this destination
96
97 vector<const char *> allow_direct;
98 vector<const char *> deny_direct;
99
100 u32 routerprio;
101
102 u8 connectable_protocols () const
103 {
104 u8 protocols = this->protocols;
105
106 // mask out endpoints we can't connect to
107 if (!udp_port) protocols &= ~PROT_UDPv4;
108 if (!tcp_port) protocols &= ~PROT_TCPv4;
109 if (!dns_port) protocols &= ~PROT_DNSv4;
110
111 return protocols;
112 }
113
114 bool may_direct (struct conf_node *other);
115 void finalise ();
116
117 void print ();
118
119 ~conf_node ();
120 };
121
122 struct configuration
123 {
124 typedef vector<conf_node *> node_vector;
125 node_vector nodes;
126 conf_node default_node;
127 conf_node *thisnode;
128 char *seed_dev; // the randomd evice to use for seeding
129 double reseed; // the interval between additional seeds
130 int mtu; // the mtu used for outgoing tunnel packets
131 int nfmark; // the SO_MARK // netfilter mark // fwmark
132 double rekey; // rekey interval
133 double keepalive; // keepalive probes interval
134 char *ifname; // the interface name (tap0 ...)
135 bool ifpersist; // should the interface be persistent
136 char *prikeyfile;
137 RSA *rsa_key; // our private rsa key
138 loglevel llevel;
139 u8 ip_proto; // the ip protocol to use
140 uid_t change_uid; // the uid of the user to switch to, or 0
141 gid_t change_gid; // the gid of the user to switch to, or 0
142 char *change_root;// the path to chroot to, "/" == anonymous
143 #if ENABLE_ICMP
144 u8 icmp_type; // the icmp type for the icmp-protocol
145 #endif
146
147 char *script_if_up;
148 char *script_node_up;
149 char *script_node_change;
150 char *script_node_down;
151 char *pidfilename;
152
153 #if ENABLE_HTTP_PROXY
154 char *proxy_auth; // login:password
155 char *proxy_host; // the proxy hostname, e.g. proxy1.example.net
156 u16 proxy_port; // the proxy port, e.g. 3128
157 #endif
158
159 #if ENABLE_DNS
160 char *dns_forw_host;
161 bool dns_case_preserving;
162 u16 dns_forw_port;
163 float dns_timeout_factor;
164 float dns_send_interval;
165 float dns_overlap_factor;
166 int dns_max_outstanding;
167 #endif
168
169 void init ();
170 void cleanup ();
171 void clear ();
172
173 conf_node *find_node (const char *name);
174
175 // create a filename from string, replacing %s by the nodename
176 // and using relative paths under confbase.
177 char *config_filename (const char *name, const char *dflt = 0);
178
179 void print ();
180
181 configuration ();
182 ~configuration ();
183 };
184
185 struct configuration_parser
186 {
187 configuration &conf;
188
189 bool need_keys;
190 conf_node *node;
191
192 int argc;
193 char **argv;
194
195 configuration_parser (configuration &conf, bool need_keys, int argc, char **argv);
196
197 void parse_file (const char *fname);
198 const char *parse_line (char *line);
199 void parse_argv ();
200 };
201
202 extern struct configuration conf;
203
204 #define THISNODE ::conf.thisnode
205
206 #endif
207