--- gvpe/src/protocol.h 2003/03/08 10:48:41 1.2 +++ gvpe/src/protocol.h 2003/03/28 16:21:09 1.12 @@ -20,119 +20,146 @@ #define VPE_PROTOCOL_H__ #include +#include // for tos etc. #include #include #include "conf.h" +#include "iom.h" #include "util.h" +#include "sockinfo.h" #include "device.h" -/* Protocol version. Different versions are incompatible, - incompatible version have different protocols. +/* Protocol version. Different major versions are incompatible, + * different minor versions probably are compatible ;) */ -#define PROTOCOL_MAJOR 2 +#define PROTOCOL_MAJOR 0 #define PROTOCOL_MINOR 0 struct vpn; struct vpn_packet; -typedef u8 rsachallenge[RSA_KEYLEN - RSA_OVERHEAD]; // challenge data +struct rsaid { + u8 id[RSA_IDLEN]; // the challenge id +}; + +typedef u8 rsachallenge[RSA_KEYLEN - RSA_OVERHEAD]; // challenge data; typedef u8 rsaencrdata[RSA_KEYLEN]; // encrypted challenge +typedef u8 rsaresponse[RSA_RESLEN]; // the encrypted ripemd160 hash struct crypto_ctx; -enum auth_subtype { AUTH_INIT, AUTH_INITREPLY, AUTH_REPLY }; +// a very simple fifo pkt-queue +class pkt_queue + { + tap_packet *queue[QUEUEDEPTH]; + int i, j; + + public: + + void put (tap_packet *p); + tap_packet *get (); + + pkt_queue (); + ~pkt_queue (); + }; struct connection { conf_node *conf; struct vpn *vpn; - SOCKADDR sa; + sockinfo si; // the current(!) destination ip to send packets to int retry_cnt; - time_t next_retry; // next connection retry - time_t next_rekey; // next rekying (actually current reset + reestablishing) - time_t last_activity; // time of last packet received + tstamp last_activity; // time of last packet received u32 oseqno; - u32 iseqno; - u32 ismask; // bitmask with set bits for each received seqno (input seen mask) + sliding_window iseqno; + + u8 protocol; pkt_queue queue; crypto_ctx *octx, *ictx; enum conf_node::connectmode connectmode; + u8 prot_minor; // minor number of other side void reset_dstaddr (); void shutdown (); void reset_connection (); - void establish_connection (); - void rekey (); - - void send_auth (auth_subtype subtype, SOCKADDR *sa, rsachallenge *k = 0); - void send_reset (SOCKADDR *dsa); - void send_ping (SOCKADDR *dss, u8 pong = 0); + void establish_connection_cb (tstamp &ts); time_watcher establish_connection; + void rekey_cb (tstamp &ts); time_watcher rekey; // next rekying (actually current reset + reestablishing) + void keepalive_cb (tstamp &ts); time_watcher keepalive; // next keepalive probe + + void send_auth_request (const sockinfo &si, bool initiate); + void send_auth_response (const sockinfo &si, const rsaid &id, const rsachallenge &chg); + void send_connect_info (int rid, const sockinfo &rsi, u8 rprotocols); + void send_reset (const sockinfo &dsi); + void send_ping (const sockinfo &dsi, u8 pong = 0); void send_data_packet (tap_packet *pkt, bool broadcast = false); void inject_data_packet (tap_packet *pkt, bool broadcast = false); void connect_request (int id); - void recv_vpn_packet (vpn_packet *pkt, SOCKADDR *rsa); + void send_vpn_packet (vpn_packet *pkt, const sockinfo &si, int tos = IPTOS_RELIABILITY); + void recv_vpn_packet (vpn_packet *pkt, const sockinfo &rsi); - void timer (); + void script_node (); + const char *script_node_up (int); + const char *script_node_down (int); - connection(struct vpn *vpn_) - : vpn(vpn_) - { - octx = ictx = 0; - retry_cnt = 0; - connectmode = conf_node::C_ALWAYS; // initial setting - reset_connection (); - } - - ~connection () - { - shutdown (); - } + void dump_status (); - void script_node (); - const char *script_node_up (); - const char *script_node_down (); + connection(struct vpn *vpn_); + ~connection (); }; struct vpn { - int socket_fd; - int events; + int udpv4_fd; + int ipv4_fd; - tap_device *tap; + int events; enum { EVENT_RECONNECT = 1, EVENT_SHUTDOWN = 2, }; + void event_cb (tstamp &ts); time_watcher event; + + tap_device *tap; + typedef vector conns_vector; conns_vector conns; connection *find_router (); - void send_vpn_packet (vpn_packet *pkt, SOCKADDR *sa); void reconnect_all (); void shutdown_all (); void connect_request (int id); + void tap_ev (short revents); io_watcher tap_ev_watcher; + void ipv4_ev (short revents); io_watcher ipv4_ev_watcher; + void udpv4_ev (short revents); io_watcher udpv4_ev_watcher; + + void recv_vpn_packet (vpn_packet *pkt, const sockinfo &rsi); + + void send_udpv4_packet (vpn_packet *pkt, const sockinfo &si, int tos = IPTOS_RELIABILITY); + void send_ipv4_packet (vpn_packet *pkt, const sockinfo &si, int tos = IPTOS_RELIABILITY); + vpn (); ~vpn (); int setup (); - void main_loop (); - const char *script_if_up (); + void dump_status (); + + const char *script_if_up (int); }; #endif