ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/gvpe.C
(Generate patch)

Comparing gvpe/src/gvpe.C (file contents):
Revision 1.3 by pcg, Wed Mar 23 20:07:56 2005 UTC vs.
Revision 1.27 by root, Thu Oct 6 03:25:54 2022 UTC

1/* 1/*
2 vped.C -- the main file for gvpe 2 gvpe.C -- the main file for gvpe
3 Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> 3 Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl>
4 2000-2002 Guus Sliepen <guus@sliepen.eu.org> 4 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
5 2003-2005 Marc Lehmann <gvpe@schmorp.de> 5 2003-2013 Marc Lehmann <gvpe@schmorp.de>
6 6
7 This file is part of GVPE. 7 This file is part of GVPE.
8 8
9 GVPE is free software; you can redistribute it and/or modify 9 GVPE is free software; you can redistribute it and/or modify it
10 it under the terms of the GNU General Public License as published by 10 under the terms of the GNU General Public License as published by the
11 the Free Software Foundation; either version 2 of the License, or 11 Free Software Foundation; either version 3 of the License, or (at your
12 (at your option) any later version. 12 option) any later version.
13 13
14 This program is distributed in the hope that it will be useful, 14 This program is distributed in the hope that it will be useful, but
15 but WITHOUT ANY WARRANTY; without even the implied warranty of 15 WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
17 GNU General Public License for more details. 17 Public License for more details.
18 18
19 You should have received a copy of the GNU General Public License 19 You should have received a copy of the GNU General Public License along
20 along with gvpe; if not, write to the Free Software 20 with this program; if not, see <http://www.gnu.org/licenses/>.
21 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 21
22 Additional permission under GNU GPL version 3 section 7
23
24 If you modify this Program, or any covered work, by linking or
25 combining it with the OpenSSL project's OpenSSL library (or a modified
26 version of that library), containing parts covered by the terms of the
27 OpenSSL or SSLeay licenses, the licensors of this Program grant you
28 additional permission to convey the resulting work. Corresponding
29 Source for a non-source form of such a combination shall include the
30 source code for the parts of OpenSSL used as well as that of the
31 covered work.
22*/ 32*/
23 33
24#include "config.h" 34#include "config.h"
25 35
26#include <cstdio> 36#include <cstdio>
30#include <errno.h> 40#include <errno.h>
31#include <fcntl.h> 41#include <fcntl.h>
32#include <getopt.h> 42#include <getopt.h>
33#include <signal.h> 43#include <signal.h>
34#include <sys/types.h> 44#include <sys/types.h>
45#include <sys/stat.h>
35#include <unistd.h> 46#include <unistd.h>
36#include <signal.h> 47#include <signal.h>
37#include <termios.h> 48#include <termios.h>
38 49
39#if HAVE_SYS_MMAN_H 50#if HAVE_SYS_MMAN_H
48 59
49#include "conf.h" 60#include "conf.h"
50#include "slog.h" 61#include "slog.h"
51#include "util.h" 62#include "util.h"
52#include "vpn.h" 63#include "vpn.h"
64#include "ev_cpp.h"
53#include "iom.h" 65#include "hkdf.h"
54 66
55static loglevel llevel = L_NONE; 67static loglevel llevel = L_NONE;
56 68
57/* If nonzero, display usage information and exit. */ 69/* If nonzero, display usage information and exit. */
58static int show_help; 70static int show_help;
65 77
66/* If zero, don't detach from the terminal. */ 78/* If zero, don't detach from the terminal. */
67static int do_detach = 1; 79static int do_detach = 1;
68 80
69static struct option const long_options[] = 81static struct option const long_options[] =
70 { 82{
71 {"config", required_argument, NULL, 'c'}, 83 {"config", required_argument, NULL, 'c'},
72 {"help", no_argument, &show_help, 1}, 84 {"help", no_argument, &show_help, 1},
73 {"version", no_argument, &show_version, 1}, 85 {"version", no_argument, &show_version, 1},
74 {"no-detach", no_argument, &do_detach, 0}, 86 {"no-detach", no_argument, &do_detach, 0},
75 {"log-level", required_argument, NULL, 'l'}, 87 {"log-level", required_argument, NULL, 'l'},
76 {"mlock", no_argument, &do_mlock, 1}, 88 {"mlock", no_argument, &do_mlock, 1},
77 {NULL, 0, NULL, 0} 89 {NULL, 0, NULL, 0}
78 }; 90};
79 91
80static void 92static void
81usage (int status) 93usage (int status)
82{ 94{
83 if (status != 0) 95 if (status != 0)
87 printf (_("Usage: %s [option]... NODENAME\n\n"), get_identity ()); 99 printf (_("Usage: %s [option]... NODENAME\n\n"), get_identity ());
88 printf (_ 100 printf (_
89 (" -c, --config=DIR Read configuration options from DIR.\n" 101 (" -c, --config=DIR Read configuration options from DIR.\n"
90 " -D, --no-detach Don't fork and detach.\n" 102 " -D, --no-detach Don't fork and detach.\n"
91 " -l, --log-level=LEVEL Set logging level (info, notice, warn are common).\n" 103 " -l, --log-level=LEVEL Set logging level (info, notice, warn are common).\n"
92 " -L, --mlock Lock tinc into main memory.\n" 104 " -L, --mlock Lock gvpe into main memory.\n"
93 " --help Display this help and exit.\n" 105 " --help Display this help and exit.\n"
94 " --version Output version information and exit.\n\n")); 106 " --version Output version information and exit.\n\n"));
95 printf (_("Report bugs to <vpe@plan9.de>.\n")); 107 printf (_("Report bugs to <gvpe@schmorp.de>.\n"));
96 } 108 }
97 109
98 exit (status); 110 exit (status);
99} 111}
100 112
101void 113static void
102parse_options (int argc, char **argv, char **envp) 114parse_options (int argc, char **argv, char **envp)
103{ 115{
104 int r; 116 int r;
105 int option_index = 0; 117 int option_index = 0;
106 118
107 while ((r = getopt_long (argc, argv, "-c:DLl:", long_options, &option_index)) != EOF) 119 while ((r = getopt_long (argc, argv, "c:DLl:", long_options, &option_index)) != EOF)
108 { 120 {
109 switch (r) 121 switch (r)
110 { 122 {
111 case 0: /* long option */ 123 case 0: /* long option */
112 break; 124 break;
113 125
114 case 1: /* this node name */
115 thisnode = strdup (optarg);
116 break;
117
118 case 'c': /* config file */ 126 case 'c': /* config file */
119 confbase = strdup (optarg); 127 confbase = strdup (optarg);
120 break; 128 break;
121 129
122 case 'D': /* no detach */ 130 case 'D': /* no detach */
143 break; 151 break;
144 } 152 }
145 } 153 }
146} 154}
147 155
148/*
149 Close network connections, and terminate neatly 156// close network connections, and terminate neatly
150*/ 157static void
151void cleanup_and_exit(int c) 158cleanup_and_exit (int c)
152{ 159{
153 network.shutdown_all (); 160 network.shutdown_all ();
154 161
155 if (conf.pidfilename) 162 if (conf.pidfilename)
156 remove_pid (conf.pidfilename); 163 remove_pid (conf.pidfilename);
158 slog (L_INFO, _("terminating with exit code %d"), c); 165 slog (L_INFO, _("terminating with exit code %d"), c);
159 166
160 exit (c); 167 exit (c);
161} 168}
162 169
163/*
164 Signal handlers. 170// signal handlers
165*/ 171static void
166RETSIGTYPE
167sigterm_handler (int a) 172sigterm_handler (int a)
168{ 173{
169 network.events |= vpn::EVENT_SHUTDOWN; 174 network.events |= vpn::EVENT_SHUTDOWN;
170 network.event.start (0); 175 network.event.start ();
171} 176}
172 177
173RETSIGTYPE 178static void
174sighup_handler (int a) 179sighup_handler (int a)
175{ 180{
176 network.events |= vpn::EVENT_RECONNECT; 181 network.events |= vpn::EVENT_RECONNECT;
177 network.event.start (0); 182 network.event.start ();
178} 183}
179 184
180RETSIGTYPE 185static void
181sigusr1_handler (int a) 186sigusr1_handler (int a)
182{ 187{
183 network.dump_status (); 188 network.dump_status ();
184} 189}
185 190
186RETSIGTYPE 191static void
187sigusr2_handler (int a) 192sigusr2_handler (int a)
188{ 193{
189} 194}
190 195
191void 196static void
192setup_signals (void) 197setup_signals (void)
193{ 198{
194 struct sigaction act; 199 struct sigaction act;
195 200
196 sigfillset (&act.sa_mask); 201 sigfillset (&act.sa_mask);
197 act.sa_flags = 0; 202 act.sa_flags = 0;
198 203
199 act.sa_handler = sighup_handler; sigaction (SIGHUP , &act, NULL); 204 act.sa_handler = sighup_handler; sigaction (SIGHUP , &act, NULL);
200 act.sa_handler = sigusr1_handler; sigaction (SIGUSR1, &act, NULL); 205 act.sa_handler = sigusr1_handler; sigaction (SIGUSR1, &act, NULL);
201 act.sa_handler = sigusr2_handler; sigaction (SIGUSR2, &act, NULL); 206 act.sa_handler = sigusr2_handler; sigaction (SIGUSR2, &act, NULL);
202 act.sa_handler = SIG_IGN; sigaction (SIGCHLD, &act, NULL);
203 act.sa_handler = SIG_IGN; sigaction (SIGPIPE, &act, NULL); 207 act.sa_handler = SIG_IGN; sigaction (SIGPIPE, &act, NULL);
204 act.sa_flags = SA_RESETHAND; 208 act.sa_flags = SA_RESETHAND;
205 act.sa_handler = sigterm_handler; sigaction (SIGINT , &act, NULL); 209 act.sa_handler = sigterm_handler; sigaction (SIGINT , &act, NULL);
206 act.sa_handler = sigterm_handler; sigaction (SIGTERM, &act, NULL); 210 act.sa_handler = sigterm_handler; sigaction (SIGTERM, &act, NULL);
207} 211}
208 212
213static int rand_fd;
214
215// antique C++ requires external linkage :/
216void
217reseed_rng (ev::timer &w, int revents)
218{
219 char buf [SEED_SIZE];
220 int n = read (rand_fd, buf, sizeof (buf));
221
222 if (n > 0)
223 RAND_seed (buf, n);
224}
225
226static void
227setup_rng (void)
228{
229 if (!*conf.seed_dev)
230 return;
231
232#ifndef O_BINARY
233# define O_BINARY 0
234#endif
235#ifndef O_NONBLOCK
236# define O_NONBLOCK 0
237#endif
238
239 rand_fd = open (conf.seed_dev, O_RDONLY | O_NONBLOCK | O_BINARY);
240
241 if (rand_fd < 0)
242 {
243 slog (L_ERR, _("unable to open seed device '%s': %s, exiting."), conf.seed_dev, strerror (errno));
244 exit (EXIT_FAILURE);
245 }
246
247 static ev::timer reseed_timer;
248
249 if (conf.reseed)
250 {
251 reseed_timer.set<reseed_rng> ();
252 reseed_timer.set (conf.reseed, conf.reseed);
253 reseed_timer.start (EV_DEFAULT);
254 }
255
256 reseed_rng (reseed_timer, 0);
257}
258
209int 259int
210main (int argc, char **argv, char **envp) 260main (int argc, char **argv, char **envp)
211{ 261{
212 ERR_load_crypto_strings (); // we have the RAM 262 ERR_load_crypto_strings (); // we have the RAM
263
264 // m,ake sure openssl agrees with us on the important bits
265 require (EVP_MD_size (MAC_DIGEST ()) == HASH_SIZE (MAC_DIGEST ));
266 require (EVP_MD_size (AUTH_DIGEST ()) == HASH_SIZE (AUTH_DIGEST));
267 require (EVP_CIPHER_key_length (CIPHER ()) == KEY_SIZE (CIPHER ));
268 require (EVP_CIPHER_block_size (CIPHER ()) == BLOCK_SIZE (CIPHER ));
269 require (EVP_CIPHER_iv_length (CIPHER ()) == IV_SIZE (CIPHER ));
270 require (EVP_CIPHER_mode (CIPHER ()) == EVP_CIPH_CTR_MODE);
271
272 curve25519_verify ();
273 hkdf::verify ();
213 274
214 set_loglevel (L_INFO); 275 set_loglevel (L_INFO);
215 set_identity (argv[0]); 276 set_identity (argv[0]);
216 log_to (LOGTO_SYSLOG | LOGTO_STDERR); 277 log_to (LOGTO_SYSLOG | LOGTO_STDERR);
217 278
219 bindtextdomain (PACKAGE, LOCALEDIR); 280 bindtextdomain (PACKAGE, LOCALEDIR);
220 textdomain (PACKAGE); 281 textdomain (PACKAGE);
221 282
222 parse_options (argc, argv, envp); 283 parse_options (argc, argv, envp);
223 284
285 argc -= optind;
286 argv += optind;
287
224 if (show_version) 288 if (show_version)
225 { 289 {
226 printf (_("%s version %s (built %s %s, protocol %d.%d)\n"), get_identity (), 290 printf (_("%s version %s (built %s %s, protocol version %d.%d)\n"), get_identity (),
227 VERSION, __DATE__, __TIME__, PROTOCOL_MAJOR, PROTOCOL_MINOR); 291 VERSION, __DATE__, __TIME__, PROTOCOL_MAJOR, PROTOCOL_MINOR);
228 printf (_("Built with kernel interface %s/%s.\n"), IFTYPE, IFSUBTYPE); 292 printf (_("Built with kernel interface %s/%s.\n"), IFTYPE, IFSUBTYPE);
229 printf (_ 293 printf (_
230 ("Copyright (C) 2003 Marc Lehmann <vpe@plan9.de> and others.\n" 294 ("Copyright (C) 2003-2011 Marc Lehmann <gvpe@schmorp.de> and others.\n"
231 "See the AUTHORS file for a complete list.\n\n" 295 "See the AUTHORS file for a complete list.\n\n"
232 "tinc comes with ABSOLUTELY NO WARRANTY. This is free software,\n" 296 "GVPE comes with ABSOLUTELY NO WARRANTY. This is free software,\n"
233 "and you are welcome to redistribute it under certain conditions;\n" 297 "and you are welcome to redistribute it under certain conditions;\n"
234 "see the file COPYING for details.\n")); 298 "see the file COPYING for details.\n"));
235 299
236 return 0; 300 return 0;
237 } 301 }
247 if (do_mlock) 311 if (do_mlock)
248 if (mlockall (MCL_CURRENT | MCL_FUTURE)) 312 if (mlockall (MCL_CURRENT | MCL_FUTURE))
249 slog (L_ERR, _("system call `%s' failed: %s"), "mlockall", strerror (errno)); 313 slog (L_ERR, _("system call `%s' failed: %s"), "mlockall", strerror (errno));
250#endif 314#endif
251 315
252 conf.read_config (true); 316 if (argc >= 1)
317 {
318 thisnode = *argv++;
319 argc--;
320 }
321
322 if (!ev_default_loop (0))
323 {
324 slog (L_ERR, _("unable to initialise the event loop (bad $LIBEV_METHODS?)"));
325 exit (EXIT_FAILURE);
326 }
327
328 {
329 configuration_parser (conf, true, argc, argv);
330 }
253 331
254 set_loglevel (llevel != L_NONE ? llevel : conf.llevel); 332 set_loglevel (llevel != L_NONE ? llevel : conf.llevel);
255 333
256 RAND_load_file ("/dev/urandom", 1024); 334 setup_rng ();
257 335
258 if (!THISNODE) 336 if (!THISNODE)
259 { 337 {
260 slog (L_ERR, _("current node not set, or node '%s' not found in configfile, specify the nodename when starting gvpe."), 338 slog (L_ERR, _("current node not set, or node '%s' not found in configfile, specify the nodename when starting gvpe."),
261 thisnode ? thisnode : "<unset>"); 339 thisnode ? thisnode : "<unset>");
266 exit (EXIT_SUCCESS); 344 exit (EXIT_SUCCESS);
267 345
268 setup_signals (); 346 setup_signals ();
269 347
270 if (!network.setup ()) 348 if (!network.setup ())
349 if (network.drop_privileges ())
271 { 350 {
272 io_manager::loop (); 351 ev_run (EV_DEFAULT_ 0);
273 cleanup_and_exit (EXIT_FAILURE); 352 cleanup_and_exit (EXIT_FAILURE);
274 } 353 }
275 354
276 slog (L_ERR, _("unable to setup network, unrecoverable error, exiting.")); 355 slog (L_CRIT, _("unrecoverable error while setting up network, exiting."));
277 cleanup_and_exit (EXIT_FAILURE); 356 cleanup_and_exit (EXIT_FAILURE);
278} 357}
279 358

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines