ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/gvpe.C
(Generate patch)

Comparing gvpe/src/gvpe.C (file contents):
Revision 1.10 by pcg, Sat Nov 10 05:14:22 2007 UTC vs.
Revision 1.26 by root, Thu Jan 29 00:21:39 2015 UTC

1/* 1/*
2 gvpe.C -- the main file for gvpe 2 gvpe.C -- the main file for gvpe
3 Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> 3 Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl>
4 2000-2002 Guus Sliepen <guus@sliepen.eu.org> 4 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
5 2003-2005 Marc Lehmann <gvpe@schmorp.de> 5 2003-2013 Marc Lehmann <gvpe@schmorp.de>
6 6
7 This file is part of GVPE. 7 This file is part of GVPE.
8 8
9 GVPE is free software; you can redistribute it and/or modify 9 GVPE is free software; you can redistribute it and/or modify it
10 it under the terms of the GNU General Public License as published by 10 under the terms of the GNU General Public License as published by the
11 the Free Software Foundation; either version 2 of the License, or 11 Free Software Foundation; either version 3 of the License, or (at your
12 (at your option) any later version. 12 option) any later version.
13 13
14 This program is distributed in the hope that it will be useful, 14 This program is distributed in the hope that it will be useful, but
15 but WITHOUT ANY WARRANTY; without even the implied warranty of 15 WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
17 GNU General Public License for more details. 17 Public License for more details.
18 18
19 You should have received a copy of the GNU General Public License 19 You should have received a copy of the GNU General Public License along
20 along with gvpe; if not, write to the Free Software 20 with this program; if not, see <http://www.gnu.org/licenses/>.
21 Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA 21
22 Additional permission under GNU GPL version 3 section 7
23
24 If you modify this Program, or any covered work, by linking or
25 combining it with the OpenSSL project's OpenSSL library (or a modified
26 version of that library), containing parts covered by the terms of the
27 OpenSSL or SSLeay licenses, the licensors of this Program grant you
28 additional permission to convey the resulting work. Corresponding
29 Source for a non-source form of such a combination shall include the
30 source code for the parts of OpenSSL used as well as that of the
31 covered work.
22*/ 32*/
23 33
24#include "config.h" 34#include "config.h"
25 35
26#include <cstdio> 36#include <cstdio>
30#include <errno.h> 40#include <errno.h>
31#include <fcntl.h> 41#include <fcntl.h>
32#include <getopt.h> 42#include <getopt.h>
33#include <signal.h> 43#include <signal.h>
34#include <sys/types.h> 44#include <sys/types.h>
45#include <sys/stat.h>
35#include <unistd.h> 46#include <unistd.h>
36#include <signal.h> 47#include <signal.h>
37#include <termios.h> 48#include <termios.h>
38 49
39#if HAVE_SYS_MMAN_H 50#if HAVE_SYS_MMAN_H
49#include "conf.h" 60#include "conf.h"
50#include "slog.h" 61#include "slog.h"
51#include "util.h" 62#include "util.h"
52#include "vpn.h" 63#include "vpn.h"
53#include "ev_cpp.h" 64#include "ev_cpp.h"
65#include "hkdf.h"
54 66
55static loglevel llevel = L_NONE; 67static loglevel llevel = L_NONE;
56 68
57/* If nonzero, display usage information and exit. */ 69/* If nonzero, display usage information and exit. */
58static int show_help; 70static int show_help;
65 77
66/* If zero, don't detach from the terminal. */ 78/* If zero, don't detach from the terminal. */
67static int do_detach = 1; 79static int do_detach = 1;
68 80
69static struct option const long_options[] = 81static struct option const long_options[] =
70 { 82{
71 {"config", required_argument, NULL, 'c'}, 83 {"config", required_argument, NULL, 'c'},
72 {"help", no_argument, &show_help, 1}, 84 {"help", no_argument, &show_help, 1},
73 {"version", no_argument, &show_version, 1}, 85 {"version", no_argument, &show_version, 1},
74 {"no-detach", no_argument, &do_detach, 0}, 86 {"no-detach", no_argument, &do_detach, 0},
75 {"log-level", required_argument, NULL, 'l'}, 87 {"log-level", required_argument, NULL, 'l'},
76 {"mlock", no_argument, &do_mlock, 1}, 88 {"mlock", no_argument, &do_mlock, 1},
77 {NULL, 0, NULL, 0} 89 {NULL, 0, NULL, 0}
78 }; 90};
79 91
80static void 92static void
81usage (int status) 93usage (int status)
82{ 94{
83 if (status != 0) 95 if (status != 0)
87 printf (_("Usage: %s [option]... NODENAME\n\n"), get_identity ()); 99 printf (_("Usage: %s [option]... NODENAME\n\n"), get_identity ());
88 printf (_ 100 printf (_
89 (" -c, --config=DIR Read configuration options from DIR.\n" 101 (" -c, --config=DIR Read configuration options from DIR.\n"
90 " -D, --no-detach Don't fork and detach.\n" 102 " -D, --no-detach Don't fork and detach.\n"
91 " -l, --log-level=LEVEL Set logging level (info, notice, warn are common).\n" 103 " -l, --log-level=LEVEL Set logging level (info, notice, warn are common).\n"
92 " -L, --mlock Lock tinc into main memory.\n" 104 " -L, --mlock Lock gvpe into main memory.\n"
93 " --help Display this help and exit.\n" 105 " --help Display this help and exit.\n"
94 " --version Output version information and exit.\n\n")); 106 " --version Output version information and exit.\n\n"));
95 printf (_("Report bugs to <gvpe@schmorp.de>.\n")); 107 printf (_("Report bugs to <gvpe@schmorp.de>.\n"));
96 } 108 }
97 109
98 exit (status); 110 exit (status);
99} 111}
100 112
101void 113static void
102parse_options (int argc, char **argv, char **envp) 114parse_options (int argc, char **argv, char **envp)
103{ 115{
104 int r; 116 int r;
105 int option_index = 0; 117 int option_index = 0;
106 118
139 break; 151 break;
140 } 152 }
141 } 153 }
142} 154}
143 155
144/*
145 Close network connections, and terminate neatly 156// close network connections, and terminate neatly
146*/ 157static void
147void cleanup_and_exit(int c) 158cleanup_and_exit (int c)
148{ 159{
149 network.shutdown_all (); 160 network.shutdown_all ();
150 161
151 if (conf.pidfilename) 162 if (conf.pidfilename)
152 remove_pid (conf.pidfilename); 163 remove_pid (conf.pidfilename);
154 slog (L_INFO, _("terminating with exit code %d"), c); 165 slog (L_INFO, _("terminating with exit code %d"), c);
155 166
156 exit (c); 167 exit (c);
157} 168}
158 169
159/*
160 Signal handlers. 170// signal handlers
161*/ 171static RETSIGTYPE
162RETSIGTYPE
163sigterm_handler (int a) 172sigterm_handler (int a)
164{ 173{
165 network.events |= vpn::EVENT_SHUTDOWN; 174 network.events |= vpn::EVENT_SHUTDOWN;
166 network.event.start (); 175 network.event.start ();
167} 176}
168 177
169RETSIGTYPE 178static RETSIGTYPE
170sighup_handler (int a) 179sighup_handler (int a)
171{ 180{
172 network.events |= vpn::EVENT_RECONNECT; 181 network.events |= vpn::EVENT_RECONNECT;
173 network.event.start (); 182 network.event.start ();
174} 183}
175 184
176RETSIGTYPE 185static RETSIGTYPE
177sigusr1_handler (int a) 186sigusr1_handler (int a)
178{ 187{
179 network.dump_status (); 188 network.dump_status ();
180} 189}
181 190
182RETSIGTYPE 191static RETSIGTYPE
183sigusr2_handler (int a) 192sigusr2_handler (int a)
184{ 193{
185} 194}
186 195
187void 196static void
188setup_signals (void) 197setup_signals (void)
189{ 198{
190 struct sigaction act; 199 struct sigaction act;
191 200
192 sigfillset (&act.sa_mask); 201 sigfillset (&act.sa_mask);
193 act.sa_flags = 0; 202 act.sa_flags = 0;
194 203
195 act.sa_handler = sighup_handler; sigaction (SIGHUP , &act, NULL); 204 act.sa_handler = sighup_handler; sigaction (SIGHUP , &act, NULL);
196 act.sa_handler = sigusr1_handler; sigaction (SIGUSR1, &act, NULL); 205 act.sa_handler = sigusr1_handler; sigaction (SIGUSR1, &act, NULL);
197 act.sa_handler = sigusr2_handler; sigaction (SIGUSR2, &act, NULL); 206 act.sa_handler = sigusr2_handler; sigaction (SIGUSR2, &act, NULL);
198 act.sa_handler = SIG_IGN; sigaction (SIGCHLD, &act, NULL);
199 act.sa_handler = SIG_IGN; sigaction (SIGPIPE, &act, NULL); 207 act.sa_handler = SIG_IGN; sigaction (SIGPIPE, &act, NULL);
200 act.sa_flags = SA_RESETHAND; 208 act.sa_flags = SA_RESETHAND;
201 act.sa_handler = sigterm_handler; sigaction (SIGINT , &act, NULL); 209 act.sa_handler = sigterm_handler; sigaction (SIGINT , &act, NULL);
202 act.sa_handler = sigterm_handler; sigaction (SIGTERM, &act, NULL); 210 act.sa_handler = sigterm_handler; sigaction (SIGTERM, &act, NULL);
203} 211}
204 212
213static int rand_fd;
214
215// antique C++ requires external linkage :/
216void
217reseed_rng (ev::timer &w, int revents)
218{
219 char buf [SEED_SIZE];
220 int n = read (rand_fd, buf, sizeof (buf));
221
222 if (n > 0)
223 RAND_seed (buf, n);
224}
225
226static void
227setup_rng (void)
228{
229 if (!*conf.seed_dev)
230 return;
231
232#ifndef O_BINARY
233# define O_BINARY 0
234#endif
235#ifndef O_NONBLOCK
236# define O_NONBLOCK 0
237#endif
238
239 rand_fd = open (conf.seed_dev, O_RDONLY | O_NONBLOCK | O_BINARY);
240
241 if (rand_fd < 0)
242 {
243 slog (L_ERR, _("unable to open seed device '%s': %s, exiting."), conf.seed_dev, strerror (errno));
244 exit (EXIT_FAILURE);
245 }
246
247 static ev::timer reseed_timer;
248
249 if (conf.reseed)
250 {
251 reseed_timer.set<reseed_rng> ();
252 reseed_timer.set (conf.reseed, conf.reseed);
253 reseed_timer.start (EV_DEFAULT);
254 }
255
256 reseed_rng (reseed_timer, 0);
257}
258
205int 259int
206main (int argc, char **argv, char **envp) 260main (int argc, char **argv, char **envp)
207{ 261{
208 ERR_load_crypto_strings (); // we have the RAM 262 ERR_load_crypto_strings (); // we have the RAM
263
264 // m,ake sure openssl agrees with us on the important bits
265 require (EVP_MD_size (MAC_DIGEST ()) == HASH_SIZE (MAC_DIGEST ));
266 require (EVP_MD_size (AUTH_DIGEST ()) == HASH_SIZE (AUTH_DIGEST));
267 require (EVP_CIPHER_key_length (CIPHER ()) == KEY_SIZE (CIPHER ));
268 require (EVP_CIPHER_block_size (CIPHER ()) == BLOCK_SIZE (CIPHER ));
269 require (EVP_CIPHER_iv_length (CIPHER ()) == IV_SIZE (CIPHER ));
270 require (EVP_CIPHER_mode (CIPHER ()) == EVP_CIPH_CTR_MODE);
271
272 curve25519_verify ();
273 hkdf::verify ();
209 274
210 set_loglevel (L_INFO); 275 set_loglevel (L_INFO);
211 set_identity (argv[0]); 276 set_identity (argv[0]);
212 log_to (LOGTO_SYSLOG | LOGTO_STDERR); 277 log_to (LOGTO_SYSLOG | LOGTO_STDERR);
213 278
224 { 289 {
225 printf (_("%s version %s (built %s %s, protocol version %d.%d)\n"), get_identity (), 290 printf (_("%s version %s (built %s %s, protocol version %d.%d)\n"), get_identity (),
226 VERSION, __DATE__, __TIME__, PROTOCOL_MAJOR, PROTOCOL_MINOR); 291 VERSION, __DATE__, __TIME__, PROTOCOL_MAJOR, PROTOCOL_MINOR);
227 printf (_("Built with kernel interface %s/%s.\n"), IFTYPE, IFSUBTYPE); 292 printf (_("Built with kernel interface %s/%s.\n"), IFTYPE, IFSUBTYPE);
228 printf (_ 293 printf (_
229 ("Copyright (C) 2003 Marc Lehmann <gvpe@schmorp.de> and others.\n" 294 ("Copyright (C) 2003-2011 Marc Lehmann <gvpe@schmorp.de> and others.\n"
230 "See the AUTHORS file for a complete list.\n\n" 295 "See the AUTHORS file for a complete list.\n\n"
231 "tinc comes with ABSOLUTELY NO WARRANTY. This is free software,\n" 296 "GVPE comes with ABSOLUTELY NO WARRANTY. This is free software,\n"
232 "and you are welcome to redistribute it under certain conditions;\n" 297 "and you are welcome to redistribute it under certain conditions;\n"
233 "see the file COPYING for details.\n")); 298 "see the file COPYING for details.\n"));
234 299
235 return 0; 300 return 0;
236 } 301 }
252 { 317 {
253 thisnode = *argv++; 318 thisnode = *argv++;
254 argc--; 319 argc--;
255 } 320 }
256 321
257 if (!ev::ev_default_loop (0)) 322 if (!ev_default_loop (0))
258 { 323 {
259 slog (L_ERR, _("unable to initialise the event loop (bad $LIBEV_METHODS?)")); 324 slog (L_ERR, _("unable to initialise the event loop (bad $LIBEV_METHODS?)"));
260 exit (EXIT_FAILURE); 325 exit (EXIT_FAILURE);
261 } 326 }
262 327
264 configuration_parser (conf, true, argc, argv); 329 configuration_parser (conf, true, argc, argv);
265 } 330 }
266 331
267 set_loglevel (llevel != L_NONE ? llevel : conf.llevel); 332 set_loglevel (llevel != L_NONE ? llevel : conf.llevel);
268 333
269 RAND_load_file ("/dev/urandom", 1024); 334 setup_rng ();
270 335
271 if (!THISNODE) 336 if (!THISNODE)
272 { 337 {
273 slog (L_ERR, _("current node not set, or node '%s' not found in configfile, specify the nodename when starting gvpe."), 338 slog (L_ERR, _("current node not set, or node '%s' not found in configfile, specify the nodename when starting gvpe."),
274 thisnode ? thisnode : "<unset>"); 339 thisnode ? thisnode : "<unset>");
279 exit (EXIT_SUCCESS); 344 exit (EXIT_SUCCESS);
280 345
281 setup_signals (); 346 setup_signals ();
282 347
283 if (!network.setup ()) 348 if (!network.setup ())
349 if (network.drop_privileges ())
284 { 350 {
285 ev::ev_loop (0); 351 ev_run (EV_DEFAULT_ 0);
286 cleanup_and_exit (EXIT_FAILURE); 352 cleanup_and_exit (EXIT_FAILURE);
287 } 353 }
288 354
289 slog (L_ERR, _("unable to setup network, unrecoverable error, exiting.")); 355 slog (L_CRIT, _("unrecoverable error while setting up network, exiting."));
290 cleanup_and_exit (EXIT_FAILURE); 356 cleanup_and_exit (EXIT_FAILURE);
291} 357}
292 358

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines