1 | /* |
1 | /* |
2 | util.h -- process management and other utility functions |
2 | util.h -- process management and other utility functions |
3 | Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> |
3 | Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> |
4 | 2000-2002 Guus Sliepen <guus@sliepen.eu.org> |
4 | 2000-2002 Guus Sliepen <guus@sliepen.eu.org> |
5 | 2003 Marc Lehmannn <pcg@goof.com> |
5 | 2003 Marc Lehmann <pcg@goof.com> |
6 | |
6 | |
7 | This program is free software; you can redistribute it and/or modify |
7 | This program is free software; you can redistribute it and/or modify |
8 | it under the terms of the GNU General Public License as published by |
8 | it under the terms of the GNU General Public License as published by |
9 | the Free Software Foundation; either version 2 of the License, or |
9 | the Free Software Foundation; either version 2 of the License, or |
10 | (at your option) any later version. |
10 | (at your option) any later version. |
… | |
… | |
20 | */ |
20 | */ |
21 | |
21 | |
22 | #ifndef UTIL_H__ |
22 | #ifndef UTIL_H__ |
23 | #define UTIL_H__ |
23 | #define UTIL_H__ |
24 | |
24 | |
25 | #include <sys/socket.h> |
25 | #include "iom.h" |
26 | #include <netinet/in.h> |
|
|
27 | |
|
|
28 | #include <map> |
|
|
29 | |
|
|
30 | #include "device.h" |
26 | #include "device.h" |
31 | |
|
|
32 | #define SOCKADDR sockaddr_in // this is lame, I know |
|
|
33 | |
27 | |
34 | /* |
28 | /* |
35 | * check for an existing vped for this net, and write pid to pidfile |
29 | * check for an existing vped for this net, and write pid to pidfile |
36 | */ |
30 | */ |
37 | extern int write_pidfile (void); |
31 | extern int write_pidfile (void); |
… | |
… | |
54 | /* |
48 | /* |
55 | * check wether the given path is an absolute pathname |
49 | * check wether the given path is an absolute pathname |
56 | */ |
50 | */ |
57 | #define ABSOLUTE_PATH(c) ((c)[0] == '/') |
51 | #define ABSOLUTE_PATH(c) ((c)[0] == '/') |
58 | |
52 | |
59 | static inline void |
|
|
60 | id2mac (unsigned int id, void *m) |
53 | extern void id2mac (unsigned int id, void *m); |
61 | { |
|
|
62 | mac &p = *(mac *)m; |
|
|
63 | |
54 | |
64 | p[0] = 0xfe; |
55 | #define mac2id(p) ((p)[0] & 0x01 ? 0 : ((p)[4] << 8) | (p)[5]) |
65 | p[1] = 0xfd; |
|
|
66 | p[2] = 0x80; |
|
|
67 | p[3] = 0x00; |
|
|
68 | p[4] = id >> 8; |
|
|
69 | p[5] = id; |
|
|
70 | } |
|
|
71 | |
56 | |
72 | #define mac2id(p) (p[0] & 0x01 ? 0 : (p[4] << 8) | p[5]) |
57 | struct sliding_window { |
|
|
58 | u32 v[(WINDOWSIZE + 31) / 32]; |
|
|
59 | u32 seq; |
73 | |
60 | |
74 | // a very simple fifo pkt-queue |
61 | void reset (u32 seqno) |
75 | class pkt_queue |
|
|
76 | { |
|
|
77 | tap_packet *queue[QUEUEDEPTH]; |
|
|
78 | int i, j; |
|
|
79 | |
|
|
80 | public: |
|
|
81 | |
|
|
82 | void put (tap_packet *p); |
|
|
83 | tap_packet *get (); |
|
|
84 | |
|
|
85 | pkt_queue (); |
|
|
86 | ~pkt_queue (); |
|
|
87 | }; |
|
|
88 | |
|
|
89 | struct sockinfo |
|
|
90 | { |
|
|
91 | u32 host; |
|
|
92 | u16 port; |
|
|
93 | |
|
|
94 | void set (const SOCKADDR *sa) |
|
|
95 | { |
62 | { |
96 | host = sa->sin_addr.s_addr; |
63 | memset (v, -1, sizeof v); |
97 | port = sa->sin_port; |
64 | seq = seqno; |
98 | } |
65 | } |
99 | |
66 | |
100 | sockinfo() |
67 | bool recv_ok (u32 seqno) |
101 | { |
68 | { |
102 | host = port = 0; |
69 | if (seqno <= seq - WINDOWSIZE) |
|
|
70 | slog (L_ERR, _("received duplicate or outdated packet (received %08lx, expected %08lx)\n" |
|
|
71 | "possible replay attack, or just massive packet reordering"), seqno, seq + 1);//D |
|
|
72 | else if (seqno > seq + WINDOWSIZE) |
|
|
73 | slog (L_ERR, _("received duplicate or out-of-sync packet (received %08lx, expected %08lx)\n" |
|
|
74 | "possible replay attack, or just massive packet loss"), seqno, seq + 1);//D |
|
|
75 | else |
|
|
76 | { |
|
|
77 | while (seqno > seq) |
|
|
78 | { |
|
|
79 | seq++; |
|
|
80 | |
|
|
81 | u32 s = seq % WINDOWSIZE; |
|
|
82 | u32 *cell = v + (s >> 5); |
|
|
83 | u32 mask = 1 << (s & 31); |
|
|
84 | |
|
|
85 | *cell &= ~mask; |
|
|
86 | } |
|
|
87 | |
|
|
88 | u32 s = seqno % WINDOWSIZE; |
|
|
89 | u32 *cell = v + (s >> 5); |
|
|
90 | u32 mask = 1 << (s & 31); |
|
|
91 | |
|
|
92 | if (*cell & mask) |
|
|
93 | { |
|
|
94 | slog (L_ERR, _("received duplicate packet (received %08lx, expected %08lx)\n" |
|
|
95 | "possible replay attack, or just packet duplication"), seqno, seq + 1);//D |
|
|
96 | return false; |
|
|
97 | } |
|
|
98 | else |
|
|
99 | { |
|
|
100 | *cell |= mask; |
|
|
101 | return true; |
|
|
102 | } |
|
|
103 | } |
103 | } |
104 | } |
|
|
105 | }; |
104 | |
106 | |
105 | sockinfo(const SOCKADDR &sa) |
107 | typedef callback0<const char *> run_script_cb; |
106 | { |
|
|
107 | set (&sa); |
|
|
108 | } |
|
|
109 | |
108 | |
110 | sockinfo(const SOCKADDR *sa) |
109 | // run a shell script (or actually an external program). |
111 | { |
110 | void run_script (const run_script_cb &cb, bool wait); |
112 | set (sa); |
|
|
113 | } |
|
|
114 | |
111 | |
115 | SOCKADDR *sa() |
112 | #if ENABLE_HTTP_PROXY |
116 | { |
113 | u8 *base64_encode (const u8 *data, unsigned int len); |
117 | static SOCKADDR sa; |
114 | #endif |
118 | |
|
|
119 | sa.sin_family = AF_INET; |
|
|
120 | sa.sin_port = port; |
|
|
121 | sa.sin_addr.s_addr = host; |
|
|
122 | |
|
|
123 | return &sa; |
|
|
124 | } |
|
|
125 | |
|
|
126 | operator const char *(); |
|
|
127 | }; |
|
|
128 | |
|
|
129 | inline bool |
|
|
130 | operator == (const sockinfo &a, const sockinfo &b) |
|
|
131 | { |
|
|
132 | return a.host == b.host && a.port == b.port; |
|
|
133 | } |
|
|
134 | |
|
|
135 | inline bool |
|
|
136 | operator < (const sockinfo &a, const sockinfo &b) |
|
|
137 | { |
|
|
138 | return a.host < b.host |
|
|
139 | || (a.host == b.host && a.port < b.port); |
|
|
140 | } |
|
|
141 | |
|
|
142 | // only do action once every x seconds per host. |
|
|
143 | // currently this is quite a slow implementation, |
|
|
144 | // but suffices for normal operation. |
|
|
145 | struct u32_rate_limiter : private map<u32, time_t> |
|
|
146 | { |
|
|
147 | int every; |
|
|
148 | |
|
|
149 | bool can (u32 host); |
|
|
150 | |
|
|
151 | u32_rate_limiter (time_t every = 1) |
|
|
152 | { |
|
|
153 | this->every = every; |
|
|
154 | } |
|
|
155 | }; |
|
|
156 | |
|
|
157 | struct net_rate_limiter : u32_rate_limiter |
|
|
158 | { |
|
|
159 | bool can (SOCKADDR *sa) { return u32_rate_limiter::can((u32)sa->sin_addr.s_addr); } |
|
|
160 | bool can (sockinfo &si) { return u32_rate_limiter::can((u32)si.host); } |
|
|
161 | |
|
|
162 | net_rate_limiter (time_t every) : u32_rate_limiter (every) {} |
|
|
163 | }; |
|
|
164 | |
115 | |
165 | #endif |
116 | #endif |
166 | |
117 | |