1 | /* |
1 | /* |
2 | util.h -- process management and other utility functions |
2 | util.h -- process management and other utility functions |
3 | Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> |
3 | Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> |
4 | 2000-2002 Guus Sliepen <guus@sliepen.eu.org> |
4 | 2000-2002 Guus Sliepen <guus@sliepen.eu.org> |
5 | 2003 Marc Lehmannn <pcg@goof.com> |
5 | 2003 Marc Lehmann <gvpe@schmorp.de> |
6 | |
6 | |
|
|
7 | This file is part of GVPE. |
|
|
8 | |
7 | This program is free software; you can redistribute it and/or modify |
9 | GVPE is free software; you can redistribute it and/or modify |
8 | it under the terms of the GNU General Public License as published by |
10 | it under the terms of the GNU General Public License as published by |
9 | the Free Software Foundation; either version 2 of the License, or |
11 | the Free Software Foundation; either version 2 of the License, or |
10 | (at your option) any later version. |
12 | (at your option) any later version. |
11 | |
13 | |
12 | This program is distributed in the hope that it will be useful, |
14 | This program is distributed in the hope that it will be useful, |
13 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
15 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
14 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
15 | GNU General Public License for more details. |
17 | GNU General Public License for more details. |
16 | |
18 | |
17 | You should have received a copy of the GNU General Public License |
19 | You should have received a copy of the GNU General Public License |
18 | along with this program; if not, write to the Free Software |
20 | along with gvpe; if not, write to the Free Software |
19 | Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA |
21 | Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
20 | */ |
22 | */ |
21 | |
23 | |
22 | #ifndef UTIL_H__ |
24 | #ifndef UTIL_H__ |
23 | #define UTIL_H__ |
25 | #define UTIL_H__ |
24 | |
26 | |
25 | #include <sys/socket.h> |
27 | #include <openssl/rsa.h> |
26 | #include <netinet/in.h> |
|
|
27 | |
28 | |
28 | #include <map> |
29 | #include "gettext.h" |
29 | |
30 | |
30 | #include "iom.h" |
31 | #include "slog.h" |
31 | #include "device.h" |
32 | #include "ev_cpp.h" |
|
|
33 | #include "callback.h" |
32 | |
34 | |
33 | #define SOCKADDR sockaddr_in // this is lame, I know |
35 | typedef ev_tstamp tstamp; |
34 | |
36 | |
35 | /* |
37 | /* |
36 | * check for an existing vped for this net, and write pid to pidfile |
38 | * check for an existing gvpe for this net, and write pid to pidfile |
37 | */ |
39 | */ |
38 | extern int write_pidfile (void); |
40 | extern int write_pidfile (void); |
39 | |
41 | |
40 | /* |
42 | /* |
41 | * kill older vped |
43 | * kill older gvpe |
42 | */ |
44 | */ |
43 | extern int kill_other (int signal); |
45 | extern int kill_other (int signal); |
44 | |
46 | |
45 | /* |
47 | /* |
46 | * Detach from current terminal, write pidfile, kill parent |
48 | * Detach from current terminal, write pidfile, kill parent |
47 | */ |
49 | */ |
48 | extern int detach (int do_detach); |
50 | extern int detach (int do_detach); |
49 | |
51 | |
50 | /* |
52 | /* |
51 | * Set all files and paths according to netname |
|
|
52 | */ |
|
|
53 | extern void make_names (void); |
|
|
54 | |
|
|
55 | /* |
|
|
56 | * check wether the given path is an absolute pathname |
53 | * check wether the given path is an absolute pathname |
57 | */ |
54 | */ |
58 | #define ABSOLUTE_PATH(c) ((c)[0] == '/') |
55 | #define ABSOLUTE_PATH(c) ((c)[0] == '/') |
59 | |
56 | |
60 | static inline void |
57 | /*****************************************************************************/ |
|
|
58 | |
|
|
59 | typedef u8 mac[6]; |
|
|
60 | |
61 | id2mac (unsigned int id, void *m) |
61 | extern void id2mac (unsigned int id, void *m); |
|
|
62 | |
|
|
63 | #define mac2id(p) ((p)[0] & 0x01 ? 0 : ((p)[4] << 8) | (p)[5]) |
|
|
64 | |
|
|
65 | struct sliding_window |
62 | { |
66 | { |
63 | mac &p = *(mac *)m; |
|
|
64 | |
|
|
65 | p[0] = 0xfe; |
|
|
66 | p[1] = 0xfd; |
|
|
67 | p[2] = 0x80; |
|
|
68 | p[3] = 0x00; |
|
|
69 | p[4] = id >> 8; |
|
|
70 | p[5] = id; |
|
|
71 | } |
|
|
72 | |
|
|
73 | #define mac2id(p) (p[0] & 0x01 ? 0 : (p[4] << 8) | p[5]) |
|
|
74 | |
|
|
75 | struct sockinfo |
|
|
76 | { |
|
|
77 | u32 host; |
|
|
78 | u16 port; |
|
|
79 | |
|
|
80 | void set (const SOCKADDR *sa) |
|
|
81 | { |
|
|
82 | host = sa->sin_addr.s_addr; |
|
|
83 | port = sa->sin_port; |
|
|
84 | } |
|
|
85 | |
|
|
86 | sockinfo() |
|
|
87 | { |
|
|
88 | host = port = 0; |
|
|
89 | } |
|
|
90 | |
|
|
91 | sockinfo(const SOCKADDR &sa) |
|
|
92 | { |
|
|
93 | set (&sa); |
|
|
94 | } |
|
|
95 | |
|
|
96 | sockinfo(const SOCKADDR *sa) |
|
|
97 | { |
|
|
98 | set (sa); |
|
|
99 | } |
|
|
100 | |
|
|
101 | SOCKADDR *sa() |
|
|
102 | { |
|
|
103 | static SOCKADDR sa; |
|
|
104 | |
|
|
105 | sa.sin_family = AF_INET; |
|
|
106 | sa.sin_port = port; |
|
|
107 | sa.sin_addr.s_addr = host; |
|
|
108 | |
|
|
109 | return &sa; |
|
|
110 | } |
|
|
111 | |
|
|
112 | operator const char *(); |
|
|
113 | }; |
|
|
114 | |
|
|
115 | inline bool |
|
|
116 | operator == (const sockinfo &a, const sockinfo &b) |
|
|
117 | { |
|
|
118 | return a.host == b.host && a.port == b.port; |
|
|
119 | } |
|
|
120 | |
|
|
121 | inline bool |
|
|
122 | operator < (const sockinfo &a, const sockinfo &b) |
|
|
123 | { |
|
|
124 | return a.host < b.host |
|
|
125 | || (a.host == b.host && a.port < b.port); |
|
|
126 | } |
|
|
127 | |
|
|
128 | struct sliding_window { |
|
|
129 | u32 v[(WINDOWSIZE + 31) / 32]; |
67 | u32 v[(WINDOWSIZE + 31) / 32]; |
130 | u32 seq; |
68 | u32 seq; |
131 | |
69 | |
132 | void reset (u32 seqno) |
70 | void reset (u32 seqno) |
133 | { |
71 | { |
… | |
… | |
137 | |
75 | |
138 | bool recv_ok (u32 seqno) |
76 | bool recv_ok (u32 seqno) |
139 | { |
77 | { |
140 | if (seqno <= seq - WINDOWSIZE) |
78 | if (seqno <= seq - WINDOWSIZE) |
141 | slog (L_ERR, _("received duplicate or outdated packet (received %08lx, expected %08lx)\n" |
79 | slog (L_ERR, _("received duplicate or outdated packet (received %08lx, expected %08lx)\n" |
142 | "possible replay attack, or just massive packet reordering"), seqno, seq + 1);//D |
80 | "possible replay attack, or just massive packet reordering"), seqno, seq + 1); |
143 | else if (seqno > seq + WINDOWSIZE) |
81 | else if (seqno > seq + WINDOWSIZE * 4) |
144 | slog (L_ERR, _("received duplicate or out-of-sync packet (received %08lx, expected %08lx)\n" |
82 | slog (L_ERR, _("received duplicate or out-of-sync packet (received %08lx, expected %08lx)\n" |
145 | "possible replay attack, or just massive packet loss"), seqno, seq + 1);//D |
83 | "possible replay attack, or just massive packet loss"), seqno, seq + 1); |
146 | else |
84 | else |
147 | { |
85 | { |
148 | while (seqno > seq) |
86 | while (seqno > seq) |
149 | { |
87 | { |
150 | seq++; |
88 | seq++; |
… | |
… | |
158 | |
96 | |
159 | u32 s = seqno % WINDOWSIZE; |
97 | u32 s = seqno % WINDOWSIZE; |
160 | u32 *cell = v + (s >> 5); |
98 | u32 *cell = v + (s >> 5); |
161 | u32 mask = 1 << (s & 31); |
99 | u32 mask = 1 << (s & 31); |
162 | |
100 | |
163 | //printf ("received seqno %08lx, seq %08lx, mask %08lx is %08lx\n", seqno, seq, mask, ismask); |
|
|
164 | if (*cell & mask) |
101 | if (*cell & mask) |
165 | { |
|
|
166 | slog (L_ERR, _("received duplicate packet (received %08lx, expected %08lx)\n" |
102 | slog (L_ERR, _("received duplicate packet (received %08lx, expected %08lx)\n" |
167 | "possible replay attack, or just packet duplication"), seqno, seq + 1);//D |
103 | "possible replay attack, or just packet duplication"), seqno, seq + 1); |
168 | return false; |
|
|
169 | } |
|
|
170 | else |
104 | else |
171 | { |
105 | { |
172 | *cell |= mask; |
106 | *cell |= mask; |
173 | return true; |
107 | return true; |
174 | } |
108 | } |
175 | } |
109 | } |
|
|
110 | |
|
|
111 | return false; |
176 | } |
112 | } |
177 | }; |
113 | }; |
178 | |
114 | |
|
|
115 | typedef callback<const char * ()> run_script_cb; |
|
|
116 | |
|
|
117 | // run a shell script (or actually an external program). |
|
|
118 | bool run_script (const run_script_cb &cb, bool wait); |
|
|
119 | |
|
|
120 | #if ENABLE_HTTP_PROXY |
|
|
121 | u8 *base64_encode (const u8 *data, unsigned int len); |
179 | #endif |
122 | #endif |
180 | |
123 | |
|
|
124 | /*****************************************************************************/ |
|
|
125 | |
|
|
126 | typedef u8 rsaclear[RSA_KEYLEN - RSA_OVERHEAD]; // challenge data; |
|
|
127 | typedef u8 rsacrypt[RSA_KEYLEN]; // encrypted challenge |
|
|
128 | |
|
|
129 | static inline void |
|
|
130 | rsa_encrypt (RSA *key, const rsaclear &chg, rsacrypt &encr) |
|
|
131 | { |
|
|
132 | if (RSA_public_encrypt (sizeof chg, |
|
|
133 | (unsigned char *)&chg, (unsigned char *)&encr, |
|
|
134 | key, RSA_PKCS1_OAEP_PADDING) < 0) |
|
|
135 | fatal ("RSA_public_encrypt error"); |
|
|
136 | } |
|
|
137 | |
|
|
138 | static inline bool |
|
|
139 | rsa_decrypt (RSA *key, const rsacrypt &encr, rsaclear &chg) |
|
|
140 | { |
|
|
141 | return RSA_private_decrypt (sizeof encr, |
|
|
142 | (unsigned char *)&encr, (unsigned char *)&chg, |
|
|
143 | key, RSA_PKCS1_OAEP_PADDING) > 0; |
|
|
144 | } |
|
|
145 | |
|
|
146 | #endif |
|
|
147 | |