1 | /* |
1 | /* |
2 | gvpe.C -- the main file for gvpe |
2 | gvpe.C -- the main file for gvpe |
3 | Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> |
3 | Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> |
4 | 2000-2002 Guus Sliepen <guus@sliepen.eu.org> |
4 | 2000-2002 Guus Sliepen <guus@sliepen.eu.org> |
5 | 2003-2008 Marc Lehmann <gvpe@schmorp.de> |
5 | 2003-2013 Marc Lehmann <gvpe@schmorp.de> |
6 | |
6 | |
7 | This file is part of GVPE. |
7 | This file is part of GVPE. |
8 | |
8 | |
9 | GVPE is free software; you can redistribute it and/or modify it |
9 | GVPE is free software; you can redistribute it and/or modify it |
10 | under the terms of the GNU General Public License as published by the |
10 | under the terms of the GNU General Public License as published by the |
… | |
… | |
40 | #include <errno.h> |
40 | #include <errno.h> |
41 | #include <fcntl.h> |
41 | #include <fcntl.h> |
42 | #include <getopt.h> |
42 | #include <getopt.h> |
43 | #include <signal.h> |
43 | #include <signal.h> |
44 | #include <sys/types.h> |
44 | #include <sys/types.h> |
|
|
45 | #include <sys/stat.h> |
45 | #include <unistd.h> |
46 | #include <unistd.h> |
46 | #include <signal.h> |
47 | #include <signal.h> |
47 | #include <termios.h> |
48 | #include <termios.h> |
48 | |
49 | |
49 | #if HAVE_SYS_MMAN_H |
50 | #if HAVE_SYS_MMAN_H |
… | |
… | |
59 | #include "conf.h" |
60 | #include "conf.h" |
60 | #include "slog.h" |
61 | #include "slog.h" |
61 | #include "util.h" |
62 | #include "util.h" |
62 | #include "vpn.h" |
63 | #include "vpn.h" |
63 | #include "ev_cpp.h" |
64 | #include "ev_cpp.h" |
|
|
65 | #include "hkdf.h" |
64 | |
66 | |
65 | static loglevel llevel = L_NONE; |
67 | static loglevel llevel = L_NONE; |
66 | |
68 | |
67 | /* If nonzero, display usage information and exit. */ |
69 | /* If nonzero, display usage information and exit. */ |
68 | static int show_help; |
70 | static int show_help; |
… | |
… | |
75 | |
77 | |
76 | /* If zero, don't detach from the terminal. */ |
78 | /* If zero, don't detach from the terminal. */ |
77 | static int do_detach = 1; |
79 | static int do_detach = 1; |
78 | |
80 | |
79 | static struct option const long_options[] = |
81 | static struct option const long_options[] = |
80 | { |
82 | { |
81 | {"config", required_argument, NULL, 'c'}, |
83 | {"config", required_argument, NULL, 'c'}, |
82 | {"help", no_argument, &show_help, 1}, |
84 | {"help", no_argument, &show_help, 1}, |
83 | {"version", no_argument, &show_version, 1}, |
85 | {"version", no_argument, &show_version, 1}, |
84 | {"no-detach", no_argument, &do_detach, 0}, |
86 | {"no-detach", no_argument, &do_detach, 0}, |
85 | {"log-level", required_argument, NULL, 'l'}, |
87 | {"log-level", required_argument, NULL, 'l'}, |
86 | {"mlock", no_argument, &do_mlock, 1}, |
88 | {"mlock", no_argument, &do_mlock, 1}, |
87 | {NULL, 0, NULL, 0} |
89 | {NULL, 0, NULL, 0} |
88 | }; |
90 | }; |
89 | |
91 | |
90 | static void |
92 | static void |
91 | usage (int status) |
93 | usage (int status) |
92 | { |
94 | { |
93 | if (status != 0) |
95 | if (status != 0) |
… | |
… | |
97 | printf (_("Usage: %s [option]... NODENAME\n\n"), get_identity ()); |
99 | printf (_("Usage: %s [option]... NODENAME\n\n"), get_identity ()); |
98 | printf (_ |
100 | printf (_ |
99 | (" -c, --config=DIR Read configuration options from DIR.\n" |
101 | (" -c, --config=DIR Read configuration options from DIR.\n" |
100 | " -D, --no-detach Don't fork and detach.\n" |
102 | " -D, --no-detach Don't fork and detach.\n" |
101 | " -l, --log-level=LEVEL Set logging level (info, notice, warn are common).\n" |
103 | " -l, --log-level=LEVEL Set logging level (info, notice, warn are common).\n" |
102 | " -L, --mlock Lock tinc into main memory.\n" |
104 | " -L, --mlock Lock gvpe into main memory.\n" |
103 | " --help Display this help and exit.\n" |
105 | " --help Display this help and exit.\n" |
104 | " --version Output version information and exit.\n\n")); |
106 | " --version Output version information and exit.\n\n")); |
105 | printf (_("Report bugs to <gvpe@schmorp.de>.\n")); |
107 | printf (_("Report bugs to <gvpe@schmorp.de>.\n")); |
106 | } |
108 | } |
107 | |
109 | |
108 | exit (status); |
110 | exit (status); |
109 | } |
111 | } |
110 | |
112 | |
111 | void |
113 | static void |
112 | parse_options (int argc, char **argv, char **envp) |
114 | parse_options (int argc, char **argv, char **envp) |
113 | { |
115 | { |
114 | int r; |
116 | int r; |
115 | int option_index = 0; |
117 | int option_index = 0; |
116 | |
118 | |
… | |
… | |
149 | break; |
151 | break; |
150 | } |
152 | } |
151 | } |
153 | } |
152 | } |
154 | } |
153 | |
155 | |
154 | /* |
|
|
155 | Close network connections, and terminate neatly |
156 | // close network connections, and terminate neatly |
156 | */ |
157 | static void |
157 | void cleanup_and_exit(int c) |
158 | cleanup_and_exit (int c) |
158 | { |
159 | { |
159 | network.shutdown_all (); |
160 | network.shutdown_all (); |
160 | |
161 | |
161 | if (conf.pidfilename) |
162 | if (conf.pidfilename) |
162 | remove_pid (conf.pidfilename); |
163 | remove_pid (conf.pidfilename); |
… | |
… | |
164 | slog (L_INFO, _("terminating with exit code %d"), c); |
165 | slog (L_INFO, _("terminating with exit code %d"), c); |
165 | |
166 | |
166 | exit (c); |
167 | exit (c); |
167 | } |
168 | } |
168 | |
169 | |
169 | /* |
|
|
170 | Signal handlers. |
170 | // signal handlers |
171 | */ |
171 | static RETSIGTYPE |
172 | RETSIGTYPE |
|
|
173 | sigterm_handler (int a) |
172 | sigterm_handler (int a) |
174 | { |
173 | { |
175 | network.events |= vpn::EVENT_SHUTDOWN; |
174 | network.events |= vpn::EVENT_SHUTDOWN; |
176 | network.event.start (); |
175 | network.event.start (); |
177 | } |
176 | } |
178 | |
177 | |
179 | RETSIGTYPE |
178 | static RETSIGTYPE |
180 | sighup_handler (int a) |
179 | sighup_handler (int a) |
181 | { |
180 | { |
182 | network.events |= vpn::EVENT_RECONNECT; |
181 | network.events |= vpn::EVENT_RECONNECT; |
183 | network.event.start (); |
182 | network.event.start (); |
184 | } |
183 | } |
185 | |
184 | |
186 | RETSIGTYPE |
185 | static RETSIGTYPE |
187 | sigusr1_handler (int a) |
186 | sigusr1_handler (int a) |
188 | { |
187 | { |
189 | network.dump_status (); |
188 | network.dump_status (); |
190 | } |
189 | } |
191 | |
190 | |
192 | RETSIGTYPE |
191 | static RETSIGTYPE |
193 | sigusr2_handler (int a) |
192 | sigusr2_handler (int a) |
194 | { |
193 | { |
195 | } |
194 | } |
196 | |
195 | |
197 | void |
196 | static void |
198 | setup_signals (void) |
197 | setup_signals (void) |
199 | { |
198 | { |
200 | struct sigaction act; |
199 | struct sigaction act; |
201 | |
200 | |
202 | sigfillset (&act.sa_mask); |
201 | sigfillset (&act.sa_mask); |
… | |
… | |
209 | act.sa_flags = SA_RESETHAND; |
208 | act.sa_flags = SA_RESETHAND; |
210 | act.sa_handler = sigterm_handler; sigaction (SIGINT , &act, NULL); |
209 | act.sa_handler = sigterm_handler; sigaction (SIGINT , &act, NULL); |
211 | act.sa_handler = sigterm_handler; sigaction (SIGTERM, &act, NULL); |
210 | act.sa_handler = sigterm_handler; sigaction (SIGTERM, &act, NULL); |
212 | } |
211 | } |
213 | |
212 | |
|
|
213 | static int rand_fd; |
|
|
214 | |
|
|
215 | // antique C++ requires external linkage :/ |
|
|
216 | void |
|
|
217 | reseed_rng (ev::timer &w, int revents) |
|
|
218 | { |
|
|
219 | char buf [SEED_SIZE]; |
|
|
220 | int n = read (rand_fd, buf, sizeof (buf)); |
|
|
221 | |
|
|
222 | if (n > 0) |
|
|
223 | RAND_seed (buf, n); |
|
|
224 | } |
|
|
225 | |
|
|
226 | static void |
|
|
227 | setup_rng (void) |
|
|
228 | { |
|
|
229 | if (!*conf.seed_dev) |
|
|
230 | return; |
|
|
231 | |
|
|
232 | #ifndef O_BINARY |
|
|
233 | # define O_BINARY 0 |
|
|
234 | #endif |
|
|
235 | #ifndef O_NONBLOCK |
|
|
236 | # define O_NONBLOCK 0 |
|
|
237 | #endif |
|
|
238 | |
|
|
239 | rand_fd = open (conf.seed_dev, O_RDONLY | O_NONBLOCK | O_BINARY); |
|
|
240 | |
|
|
241 | if (rand_fd < 0) |
|
|
242 | { |
|
|
243 | slog (L_ERR, _("unable to open seed device '%s': %s, exiting."), conf.seed_dev, strerror (errno)); |
|
|
244 | exit (EXIT_FAILURE); |
|
|
245 | } |
|
|
246 | |
|
|
247 | static ev::timer reseed_timer; |
|
|
248 | |
|
|
249 | if (conf.reseed) |
|
|
250 | { |
|
|
251 | reseed_timer.set<reseed_rng> (); |
|
|
252 | reseed_timer.set (conf.reseed, conf.reseed); |
|
|
253 | reseed_timer.start (EV_DEFAULT); |
|
|
254 | } |
|
|
255 | |
|
|
256 | reseed_rng (reseed_timer, 0); |
|
|
257 | } |
|
|
258 | |
214 | int |
259 | int |
215 | main (int argc, char **argv, char **envp) |
260 | main (int argc, char **argv, char **envp) |
216 | { |
261 | { |
217 | ERR_load_crypto_strings (); // we have the RAM |
262 | ERR_load_crypto_strings (); // we have the RAM |
|
|
263 | |
|
|
264 | // m,ake sure openssl agrees with us on the important bits |
|
|
265 | require (EVP_MD_size (MAC_DIGEST ()) == HASH_SIZE (MAC_DIGEST )); |
|
|
266 | require (EVP_MD_size (AUTH_DIGEST ()) == HASH_SIZE (AUTH_DIGEST)); |
|
|
267 | require (EVP_CIPHER_key_length (CIPHER ()) == KEY_SIZE (CIPHER )); |
|
|
268 | require (EVP_CIPHER_block_size (CIPHER ()) == BLOCK_SIZE (CIPHER )); |
|
|
269 | require (EVP_CIPHER_iv_length (CIPHER ()) == IV_SIZE (CIPHER )); |
|
|
270 | require (EVP_CIPHER_mode (CIPHER ()) == EVP_CIPH_CTR_MODE); |
|
|
271 | |
|
|
272 | curve25519_verify (); |
|
|
273 | hkdf::verify (); |
218 | |
274 | |
219 | set_loglevel (L_INFO); |
275 | set_loglevel (L_INFO); |
220 | set_identity (argv[0]); |
276 | set_identity (argv[0]); |
221 | log_to (LOGTO_SYSLOG | LOGTO_STDERR); |
277 | log_to (LOGTO_SYSLOG | LOGTO_STDERR); |
222 | |
278 | |
… | |
… | |
233 | { |
289 | { |
234 | printf (_("%s version %s (built %s %s, protocol version %d.%d)\n"), get_identity (), |
290 | printf (_("%s version %s (built %s %s, protocol version %d.%d)\n"), get_identity (), |
235 | VERSION, __DATE__, __TIME__, PROTOCOL_MAJOR, PROTOCOL_MINOR); |
291 | VERSION, __DATE__, __TIME__, PROTOCOL_MAJOR, PROTOCOL_MINOR); |
236 | printf (_("Built with kernel interface %s/%s.\n"), IFTYPE, IFSUBTYPE); |
292 | printf (_("Built with kernel interface %s/%s.\n"), IFTYPE, IFSUBTYPE); |
237 | printf (_ |
293 | printf (_ |
238 | ("Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de> and others.\n" |
294 | ("Copyright (C) 2003-2011 Marc Lehmann <gvpe@schmorp.de> and others.\n" |
239 | "See the AUTHORS file for a complete list.\n\n" |
295 | "See the AUTHORS file for a complete list.\n\n" |
240 | "tinc comes with ABSOLUTELY NO WARRANTY. This is free software,\n" |
296 | "GVPE comes with ABSOLUTELY NO WARRANTY. This is free software,\n" |
241 | "and you are welcome to redistribute it under certain conditions;\n" |
297 | "and you are welcome to redistribute it under certain conditions;\n" |
242 | "see the file COPYING for details.\n")); |
298 | "see the file COPYING for details.\n")); |
243 | |
299 | |
244 | return 0; |
300 | return 0; |
245 | } |
301 | } |
… | |
… | |
273 | configuration_parser (conf, true, argc, argv); |
329 | configuration_parser (conf, true, argc, argv); |
274 | } |
330 | } |
275 | |
331 | |
276 | set_loglevel (llevel != L_NONE ? llevel : conf.llevel); |
332 | set_loglevel (llevel != L_NONE ? llevel : conf.llevel); |
277 | |
333 | |
278 | RAND_load_file ("/dev/urandom", 1024); |
334 | setup_rng (); |
279 | |
335 | |
280 | if (!THISNODE) |
336 | if (!THISNODE) |
281 | { |
337 | { |
282 | slog (L_ERR, _("current node not set, or node '%s' not found in configfile, specify the nodename when starting gvpe."), |
338 | slog (L_ERR, _("current node not set, or node '%s' not found in configfile, specify the nodename when starting gvpe."), |
283 | thisnode ? thisnode : "<unset>"); |
339 | thisnode ? thisnode : "<unset>"); |
… | |
… | |
288 | exit (EXIT_SUCCESS); |
344 | exit (EXIT_SUCCESS); |
289 | |
345 | |
290 | setup_signals (); |
346 | setup_signals (); |
291 | |
347 | |
292 | if (!network.setup ()) |
348 | if (!network.setup ()) |
|
|
349 | if (network.drop_privileges ()) |
293 | { |
350 | { |
294 | ev_loop (EV_DEFAULT_ 0); |
351 | ev_run (EV_DEFAULT_ 0); |
295 | cleanup_and_exit (EXIT_FAILURE); |
352 | cleanup_and_exit (EXIT_FAILURE); |
296 | } |
353 | } |
297 | |
354 | |
298 | slog (L_ERR, _("unable to setup network, unrecoverable error, exiting.")); |
355 | slog (L_CRIT, _("unrecoverable error while setting up network, exiting.")); |
299 | cleanup_and_exit (EXIT_FAILURE); |
356 | cleanup_and_exit (EXIT_FAILURE); |
300 | } |
357 | } |
301 | |
358 | |