ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/util.h
(Generate patch)

Comparing gvpe/src/util.h (file contents):
Revision 1.2 by pcg, Mon Mar 17 15:20:18 2003 UTC vs.
Revision 1.25 by pcg, Thu Aug 7 17:54:27 2008 UTC

1/* 1/*
2 util.h -- process management and other utility functions 2 util.h -- process management and other utility functions
3 Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl> 3 Copyright (C) 1998-2002 Ivo Timmermans <ivo@o2w.nl>
4 2000-2002 Guus Sliepen <guus@sliepen.eu.org> 4 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
5 2003 Marc Lehmannn <pcg@goof.com> 5 2003-2008 Marc Lehmann <gvpe@schmorp.de>
6 6
7 This file is part of GVPE.
8
7 This program is free software; you can redistribute it and/or modify 9 GVPE is free software; you can redistribute it and/or modify it
8 it under the terms of the GNU General Public License as published by 10 under the terms of the GNU General Public License as published by the
9 the Free Software Foundation; either version 2 of the License, or 11 Free Software Foundation; either version 3 of the License, or (at your
10 (at your option) any later version. 12 option) any later version.
11 13
12 This program is distributed in the hope that it will be useful, 14 This program is distributed in the hope that it will be useful, but
13 but WITHOUT ANY WARRANTY; without even the implied warranty of 15 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 GNU General Public License for more details. 17 Public License for more details.
16 18
17 You should have received a copy of the GNU General Public License 19 You should have received a copy of the GNU General Public License along
18 along with this program; if not, write to the Free Software 20 with this program; if not, see <http://www.gnu.org/licenses/>.
19 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 21
22 Additional permission under GNU GPL version 3 section 7
23
24 If you modify this Program, or any covered work, by linking or
25 combining it with the OpenSSL project's OpenSSL library (or a modified
26 version of that library), containing parts covered by the terms of the
27 OpenSSL or SSLeay licenses, the licensors of this Program grant you
28 additional permission to convey the resulting work. Corresponding
29 Source for a non-source form of such a combination shall include the
30 source code for the parts of OpenSSL used as well as that of the
31 covered work.
20*/ 32*/
21 33
22#ifndef UTIL_H__ 34#ifndef UTIL_H__
23#define UTIL_H__ 35#define UTIL_H__
24 36
25#include <sys/socket.h> 37#include <cstring>
26#include <netinet/in.h>
27 38
28#include <map> 39#include <openssl/rsa.h>
29 40
30#include "device.h" 41#include "gettext.h"
31 42
32#define SOCKADDR sockaddr_in // this is lame, I know 43#include "slog.h"
44#include "ev_cpp.h"
45#include "callback.h"
46
47typedef ev_tstamp tstamp;
33 48
34/* 49/*
35 * check for an existing vped for this net, and write pid to pidfile 50 * check for an existing gvpe for this net, and write pid to pidfile
36 */ 51 */
37extern int write_pidfile (void); 52extern int write_pidfile (void);
38 53
39/* 54/*
40 * kill older vped 55 * kill older gvpe
41 */ 56 */
42extern int kill_other (int signal); 57extern int kill_other (int signal);
43 58
44/* 59/*
45 * Detach from current terminal, write pidfile, kill parent 60 * Detach from current terminal, write pidfile, kill parent
46 */ 61 */
47extern int detach (int do_detach); 62extern int detach (int do_detach);
48 63
49/* 64/*
50 * Set all files and paths according to netname
51 */
52extern void make_names (void);
53
54/*
55 * check wether the given path is an absolute pathname 65 * check wether the given path is an absolute pathname
56 */ 66 */
57#define ABSOLUTE_PATH(c) ((c)[0] == '/') 67#define ABSOLUTE_PATH(c) ((c)[0] == '/')
58 68
59static inline void 69/*****************************************************************************/
70
71typedef u8 mac[6];
72
60id2mac (unsigned int id, void *m) 73extern void id2mac (unsigned int id, void *m);
74
75#define mac2id(p) ((p)[0] & 0x01 ? 0 : ((p)[4] << 8) | (p)[5])
76
77struct sliding_window
61{ 78{
62 mac &p = *(mac *)m;
63
64 p[0] = 0xfe;
65 p[1] = 0xfd;
66 p[2] = 0x80;
67 p[3] = 0x00;
68 p[4] = id >> 8;
69 p[5] = id;
70}
71
72#define mac2id(p) (p[0] & 0x01 ? 0 : (p[4] << 8) | p[5])
73
74// a very simple fifo pkt-queue
75class pkt_queue
76 {
77 tap_packet *queue[QUEUEDEPTH];
78 int i, j;
79
80 public:
81
82 void put (tap_packet *p);
83 tap_packet *get ();
84
85 pkt_queue ();
86 ~pkt_queue ();
87 };
88
89struct sockinfo
90 {
91 u32 host;
92 u16 port;
93
94 void set (const SOCKADDR *sa)
95 {
96 host = sa->sin_addr.s_addr;
97 port = sa->sin_port;
98 }
99
100 sockinfo()
101 {
102 host = port = 0;
103 }
104
105 sockinfo(const SOCKADDR &sa)
106 {
107 set (&sa);
108 }
109
110 sockinfo(const SOCKADDR *sa)
111 {
112 set (sa);
113 }
114
115 SOCKADDR *sa()
116 {
117 static SOCKADDR sa;
118
119 sa.sin_family = AF_INET;
120 sa.sin_port = port;
121 sa.sin_addr.s_addr = host;
122
123 return &sa;
124 }
125
126 operator const char *();
127 };
128
129inline bool
130operator == (const sockinfo &a, const sockinfo &b)
131{
132 return a.host == b.host && a.port == b.port;
133}
134
135inline bool
136operator < (const sockinfo &a, const sockinfo &b)
137{
138 return a.host < b.host
139 || (a.host == b.host && a.port < b.port);
140}
141
142// only do action once every x seconds per host.
143// currently this is quite a slow implementation,
144// but suffices for normal operation.
145struct u32_rate_limiter : private map<u32, time_t>
146 {
147 int every;
148
149 bool can (u32 host);
150
151 u32_rate_limiter (time_t every = 1)
152 {
153 this->every = every;
154 }
155 };
156
157struct net_rate_limiter : u32_rate_limiter
158 {
159 bool can (SOCKADDR *sa) { return u32_rate_limiter::can((u32)sa->sin_addr.s_addr); }
160 bool can (sockinfo &si) { return u32_rate_limiter::can((u32)si.host); }
161
162 net_rate_limiter (time_t every) : u32_rate_limiter (every) {}
163 };
164
165struct sliding_window {
166 u32 v[(WINDOWSIZE + 31) / 32]; 79 u32 v[(WINDOWSIZE + 31) / 32];
167 u32 seq; 80 u32 seq;
168 81
169 void reset (u32 seqno) 82 void reset (u32 seqno)
170 { 83 {
174 87
175 bool recv_ok (u32 seqno) 88 bool recv_ok (u32 seqno)
176 { 89 {
177 if (seqno <= seq - WINDOWSIZE) 90 if (seqno <= seq - WINDOWSIZE)
178 slog (L_ERR, _("received duplicate or outdated packet (received %08lx, expected %08lx)\n" 91 slog (L_ERR, _("received duplicate or outdated packet (received %08lx, expected %08lx)\n"
179 "possible replay attack, or just massive packet reordering"), seqno, seq + 1);//D 92 "possible replay attack, or just massive packet reordering"), seqno, seq + 1);
180 else if (seqno > seq + WINDOWSIZE) 93 else if (seqno > seq + WINDOWSIZE * 4)
181 slog (L_ERR, _("received duplicate or out-of-sync packet (received %08lx, expected %08lx)\n" 94 slog (L_ERR, _("received duplicate or out-of-sync packet (received %08lx, expected %08lx)\n"
182 "possible replay attack, or just massive packet loss"), seqno, seq + 1);//D 95 "possible replay attack, or just massive packet loss"), seqno, seq + 1);
183 else 96 else
184 { 97 {
185 while (seqno > seq) 98 while (seqno > seq)
186 { 99 {
187 seq++; 100 seq++;
195 108
196 u32 s = seqno % WINDOWSIZE; 109 u32 s = seqno % WINDOWSIZE;
197 u32 *cell = v + (s >> 5); 110 u32 *cell = v + (s >> 5);
198 u32 mask = 1 << (s & 31); 111 u32 mask = 1 << (s & 31);
199 112
200 //printf ("received seqno %08lx, seq %08lx, mask %08lx is %08lx\n", seqno, seq, mask, ismask);
201 if (*cell & mask) 113 if (*cell & mask)
202 {
203 slog (L_ERR, _("received duplicate packet (received %08lx, expected %08lx)\n" 114 slog (L_ERR, _("received duplicate packet (received %08lx, expected %08lx)\n"
204 "possible replay attack, or just packet duplication"), seqno, seq + 1);//D 115 "possible replay attack, or just packet duplication"), seqno, seq + 1);
205 return false;
206 }
207 else 116 else
208 { 117 {
209 *cell |= mask; 118 *cell |= mask;
210 return true; 119 return true;
211 } 120 }
212 } 121 }
122
123 return false;
213 } 124 }
214}; 125};
215 126
127typedef callback<const char * ()> run_script_cb;
128
129// run a shell script (or actually an external program).
130bool run_script (const run_script_cb &cb, bool wait);
131
132#if ENABLE_HTTP_PROXY
133u8 *base64_encode (const u8 *data, unsigned int len);
216#endif 134#endif
217 135
136/*****************************************************************************/
137
138typedef u8 rsaclear[RSA_KEYLEN - RSA_OVERHEAD]; // challenge data;
139typedef u8 rsacrypt[RSA_KEYLEN]; // encrypted challenge
140
141static inline void
142rsa_encrypt (RSA *key, const rsaclear &chg, rsacrypt &encr)
143{
144 if (RSA_public_encrypt (sizeof chg,
145 (unsigned char *)&chg, (unsigned char *)&encr,
146 key, RSA_PKCS1_OAEP_PADDING) < 0)
147 fatal ("RSA_public_encrypt error");
148}
149
150static inline bool
151rsa_decrypt (RSA *key, const rsacrypt &encr, rsaclear &chg)
152{
153 return RSA_private_decrypt (sizeof encr,
154 (unsigned char *)&encr, (unsigned char *)&chg,
155 key, RSA_PKCS1_OAEP_PADDING) > 0;
156}
157
158#endif
159

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines