ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/vpn.C
(Generate patch)

Comparing gvpe/src/vpn.C (file contents):
Revision 1.33 by pcg, Wed Mar 23 21:55:39 2005 UTC vs.
Revision 1.41 by pcg, Sun Dec 2 00:20:19 2007 UTC

14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details. 15 GNU General Public License for more details.
16 16
17 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License
18 along with gvpe; if not, write to the Free Software 18 along with gvpe; if not, write to the Free Software
19 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19 Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20*/ 20*/
21 21
22#include "config.h" 22#include "config.h"
23 23
24#include <list> 24#include <list>
46 46
47vpn network; // THE vpn (bad design...) 47vpn network; // THE vpn (bad design...)
48 48
49///////////////////////////////////////////////////////////////////////////// 49/////////////////////////////////////////////////////////////////////////////
50 50
51static void inline
52set_tos (int fd, int &tos_prev, int tos)
53{
54#if defined(SOL_IP) && defined(IP_TOS)
55 if (tos_prev == tos)
56 return;
57
58 tos_prev = tos;
59 setsockopt (fd, SOL_IP, IP_TOS, &tos, sizeof tos);
60#endif
61}
62
51void 63void
52vpn::script_init_env () 64vpn::script_init_env ()
53{ 65{
54 // the tunnel device mtu should be the physical mtu - overhead 66 // the tunnel device mtu should be the physical mtu - overhead
55 // the tricky part is rounding to the cipher key blocksize 67 // the tricky part is rounding to the cipher key blocksize
58 mtu -= mtu % EVP_CIPHER_block_size (CIPHER); // round 70 mtu -= mtu % EVP_CIPHER_block_size (CIPHER); // round
59 mtu -= ETH_OVERHEAD - 6 - 6; // and get interface mtu again 71 mtu -= ETH_OVERHEAD - 6 - 6; // and get interface mtu again
60 72
61 char *env; 73 char *env;
62 asprintf (&env, "CONFBASE=%s", confbase); putenv (env); 74 asprintf (&env, "CONFBASE=%s", confbase); putenv (env);
63 asprintf (&env, "NODENAME=%s", THISNODE->nodename); putenv (env);
64 asprintf (&env, "NODEID=%d", THISNODE->id); putenv (env);
65 asprintf (&env, "IFNAME=%s", tap->interface ()); putenv (env); 75 asprintf (&env, "IFNAME=%s", tap->interface ()); putenv (env);
66 asprintf (&env, "IFTYPE=%s", IFTYPE); putenv (env); 76 asprintf (&env, "IFTYPE=%s", IFTYPE); putenv (env);
67 asprintf (&env, "IFSUBTYPE=%s", IFSUBTYPE); putenv (env); 77 asprintf (&env, "IFSUBTYPE=%s", IFSUBTYPE); putenv (env);
68 asprintf (&env, "MTU=%d", mtu); putenv (env); 78 asprintf (&env, "MTU=%d", mtu); putenv (env);
69 asprintf (&env, "MAC=%02x:%02x:%02x:%02x:%02x:%02x", 79 asprintf (&env, "NODES=%d", conns.size ()); putenv (env);
70 0xfe, 0xfd, 0x80, 0x00, THISNODE->id >> 8, 80 asprintf (&env, "NODEID=%d", THISNODE->id); putenv (env);
71 THISNODE->id & 0xff); putenv (env);
72 81
73 // TODO: info for other nodes, maybe? 82 conns [THISNODE->id - 1]->script_init_env ("");
83
84 for (conns_vector::iterator c = conns.begin (); c != conns.end (); ++c)
85 {
86 char ext[16];
87 snprintf (ext, 16, "_%d", (*c)->conf->id);
88 (*c)->script_init_env (ext);
89 }
74} 90}
75 91
76const char *vpn::script_if_init () 92const char *vpn::script_if_init ()
77{ 93{
78 script_init_env (); 94 script_init_env ();
94} 110}
95 111
96int 112int
97vpn::setup () 113vpn::setup ()
98{ 114{
115 ipv4_tos = -1;
99 ipv4_fd = -1; 116 ipv4_fd = -1;
100 117
101 if (THISNODE->protocols & PROT_IPv4 && ::conf.ip_proto) 118 if (THISNODE->protocols & PROT_IPv4 && ::conf.ip_proto)
102 { 119 {
103 ipv4_fd = socket (PF_INET, SOCK_RAW, ::conf.ip_proto); 120 ipv4_fd = socket (PF_INET, SOCK_RAW, ::conf.ip_proto);
104 121
105 if (ipv4_fd < 0) 122 if (ipv4_fd < 0)
106 return -1; 123 return -1;
107 124
108 fcntl (ipv4_fd, F_SETFL, O_NONBLOCK); 125 fcntl (ipv4_fd, F_SETFL, O_NONBLOCK);
126 fcntl (ipv4_fd, F_SETFD, FD_CLOEXEC);
109 127
110#if defined(SOL_IP) && defined(IP_MTU_DISCOVER) 128#if defined(SOL_IP) && defined(IP_MTU_DISCOVER)
111 // this I really consider a linux bug. I am neither connected 129 // this I really consider a linux bug. I am neither connected
112 // nor do I fragment myself. Linux still sets DF and doesn't 130 // nor do I fragment myself. Linux still sets DF and doesn't
113 // fragment for me sometimes. 131 // fragment for me sometimes.
123 { 141 {
124 slog (L_ERR, _("can't bind ipv4 socket on %s: %s"), (const char *)si, strerror (errno)); 142 slog (L_ERR, _("can't bind ipv4 socket on %s: %s"), (const char *)si, strerror (errno));
125 exit (EXIT_FAILURE); 143 exit (EXIT_FAILURE);
126 } 144 }
127 145
128 ipv4_ev_watcher.start (ipv4_fd, EVENT_READ); 146 ipv4_ev_watcher.start (ipv4_fd, EV_READ);
129 } 147 }
130 148
149 udpv4_tos = -1;
131 udpv4_fd = -1; 150 udpv4_fd = -1;
132 151
133 if (THISNODE->protocols & PROT_UDPv4 && THISNODE->udp_port) 152 if (THISNODE->protocols & PROT_UDPv4 && THISNODE->udp_port)
134 { 153 {
135 udpv4_fd = socket (PF_INET, SOCK_DGRAM, IPPROTO_UDP); 154 udpv4_fd = socket (PF_INET, SOCK_DGRAM, IPPROTO_UDP);
136 155
137 if (udpv4_fd < 0) 156 if (udpv4_fd < 0)
138 return -1; 157 return -1;
139 158
140 fcntl (udpv4_fd, F_SETFL, O_NONBLOCK); 159 fcntl (udpv4_fd, F_SETFL, O_NONBLOCK);
160 fcntl (udpv4_fd, F_SETFD, FD_CLOEXEC);
141 161
142 // standard daemon practise... 162 // standard daemon practise...
143 { 163 {
144 int oval = 1; 164 int oval = 1;
145 setsockopt (udpv4_fd, SOL_SOCKET, SO_REUSEADDR, &oval, sizeof oval); 165 setsockopt (udpv4_fd, SOL_SOCKET, SO_REUSEADDR, &oval, sizeof oval);
161 { 181 {
162 slog (L_ERR, _("can't bind udpv4 on %s: %s"), (const char *)si, strerror (errno)); 182 slog (L_ERR, _("can't bind udpv4 on %s: %s"), (const char *)si, strerror (errno));
163 exit (EXIT_FAILURE); 183 exit (EXIT_FAILURE);
164 } 184 }
165 185
166 udpv4_ev_watcher.start (udpv4_fd, EVENT_READ); 186 udpv4_ev_watcher.start (udpv4_fd, EV_READ);
167 } 187 }
168 188
189 icmpv4_tos = -1;
169 icmpv4_fd = -1; 190 icmpv4_fd = -1;
170 191
171#if ENABLE_ICMP 192#if ENABLE_ICMP
172 if (THISNODE->protocols & PROT_ICMPv4) 193 if (THISNODE->protocols & PROT_ICMPv4)
173 { 194 {
174 icmpv4_fd = socket (PF_INET, SOCK_RAW, IPPROTO_ICMP); 195 icmpv4_fd = socket (PF_INET, SOCK_RAW, IPPROTO_ICMP);
175 196
176 if (icmpv4_fd < 0) 197 if (icmpv4_fd < 0)
177 return -1; 198 return -1;
178 199
179 fcntl (icmpv4_fd, F_SETFL, O_NONBLOCK); 200 fcntl (icmpv4_fd, F_SETFL, O_NONBLOCK);
201 fcntl (icmpv4_fd, F_SETFD, FD_CLOEXEC);
180 202
181#ifdef ICMP_FILTER 203#ifdef ICMP_FILTER
182 { 204 {
183 icmp_filter oval; 205 icmp_filter oval;
184 oval.data = 0xffffffff; 206 oval.data = 0xffffffff;
193 // this I really consider a linux bug. I am neither connected 215 // this I really consider a linux bug. I am neither connected
194 // nor do I fragment myself. Linux still sets DF and doesn't 216 // nor do I fragment myself. Linux still sets DF and doesn't
195 // fragment for me sometimes. 217 // fragment for me sometimes.
196 { 218 {
197 int oval = IP_PMTUDISC_DONT; 219 int oval = IP_PMTUDISC_DONT;
198 setsockopt (udpv4_fd, SOL_IP, IP_MTU_DISCOVER, &oval, sizeof oval); 220 setsockopt (icmpv4_fd, SOL_IP, IP_MTU_DISCOVER, &oval, sizeof oval);
199 } 221 }
200#endif 222#endif
201 223
202 sockinfo si (THISNODE, PROT_ICMPv4); 224 sockinfo si (THISNODE, PROT_ICMPv4);
203 225
205 { 227 {
206 slog (L_ERR, _("can't bind icmpv4 on %s: %s"), (const char *)si, strerror (errno)); 228 slog (L_ERR, _("can't bind icmpv4 on %s: %s"), (const char *)si, strerror (errno));
207 exit (EXIT_FAILURE); 229 exit (EXIT_FAILURE);
208 } 230 }
209 231
210 icmpv4_ev_watcher.start (icmpv4_fd, EVENT_READ); 232 icmpv4_ev_watcher.start (icmpv4_fd, EV_READ);
211 } 233 }
212#endif 234#endif
213 235
214 tcpv4_fd = -1; 236 tcpv4_fd = -1;
215 237
220 242
221 if (tcpv4_fd < 0) 243 if (tcpv4_fd < 0)
222 return -1; 244 return -1;
223 245
224 fcntl (tcpv4_fd, F_SETFL, O_NONBLOCK); 246 fcntl (tcpv4_fd, F_SETFL, O_NONBLOCK);
247 fcntl (tcpv4_fd, F_SETFD, FD_CLOEXEC);
225 248
226 // standard daemon practise... 249 // standard daemon practise...
227 { 250 {
228 int oval = 1; 251 int oval = 1;
229 setsockopt (tcpv4_fd, SOL_SOCKET, SO_REUSEADDR, &oval, sizeof oval); 252 setsockopt (tcpv4_fd, SOL_SOCKET, SO_REUSEADDR, &oval, sizeof oval);
241 { 264 {
242 slog (L_ERR, _("can't listen tcpv4 on %s: %s"), (const char *)si, strerror (errno)); 265 slog (L_ERR, _("can't listen tcpv4 on %s: %s"), (const char *)si, strerror (errno));
243 exit (EXIT_FAILURE); 266 exit (EXIT_FAILURE);
244 } 267 }
245 268
246 tcpv4_ev_watcher.start (tcpv4_fd, EVENT_READ); 269 tcpv4_ev_watcher.start (tcpv4_fd, EV_READ);
247 } 270 }
248#endif 271#endif
272
273 dnsv4_tos = -1;
274 dnsv4_fd = -1;
249 275
250#if ENABLE_DNS 276#if ENABLE_DNS
251 if (THISNODE->protocols & PROT_DNSv4) 277 if (THISNODE->protocols & PROT_DNSv4)
252 { 278 {
253 dns_forwarder.set (::conf.dns_forw_host, ::conf.dns_forw_port, PROT_DNSv4); 279 dns_forwarder.set (::conf.dns_forw_host, ::conf.dns_forw_port, PROT_DNSv4);
255 dnsv4_fd = socket (PF_INET, SOCK_DGRAM, IPPROTO_UDP); 281 dnsv4_fd = socket (PF_INET, SOCK_DGRAM, IPPROTO_UDP);
256 282
257 if (dnsv4_fd < 0) 283 if (dnsv4_fd < 0)
258 return -1; 284 return -1;
259 285
286 fcntl (dnsv4_fd, F_SETFL, O_NONBLOCK);
287 fcntl (dnsv4_fd, F_SETFD, FD_CLOEXEC);
288
260#if defined(SOL_IP) && defined(IP_MTU_DISCOVER) 289# if defined(SOL_IP) && defined(IP_MTU_DISCOVER)
261 // this I really consider a linux bug. I am neither connected 290 // this I really consider a linux bug. I am neither connected
262 // nor do I fragment myself. Linux still sets DF and doesn't 291 // nor do I fragment myself. Linux still sets DF and doesn't
263 // fragment for me sometimes. 292 // fragment for me sometimes.
264 { 293 {
265 int oval = IP_PMTUDISC_DONT; 294 int oval = IP_PMTUDISC_DONT;
266 setsockopt (udpv4_fd, SOL_IP, IP_MTU_DISCOVER, &oval, sizeof oval); 295 setsockopt (dnsv4_fd, SOL_IP, IP_MTU_DISCOVER, &oval, sizeof oval);
267 } 296 }
268#endif 297# endif
269 298
270 // standard daemon practise... 299 // standard daemon practise...
271 { 300 {
272 int oval = 1; 301 int oval = 1;
273 setsockopt (dnsv4_fd, SOL_SOCKET, SO_REUSEADDR, &oval, sizeof oval); 302 setsockopt (dnsv4_fd, SOL_SOCKET, SO_REUSEADDR, &oval, sizeof oval);
281 { 310 {
282 slog (L_ERR, _("can't bind dnsv4 on %s: %s"), (const char *)si, strerror (errno)); 311 slog (L_ERR, _("can't bind dnsv4 on %s: %s"), (const char *)si, strerror (errno));
283 exit (EXIT_FAILURE); 312 exit (EXIT_FAILURE);
284 } 313 }
285 314
286 dnsv4_ev_watcher.start (dnsv4_fd, EVENT_READ); 315 dnsv4_ev_watcher.start (dnsv4_fd, EV_READ);
287 } 316 }
288#endif 317#endif
318
319 /////////////////////////////////////////////////////////////////////////////
320
321 reconnect_all ();
322
323 /////////////////////////////////////////////////////////////////////////////
289 324
290 tap = new tap_device (); 325 tap = new tap_device ();
291 if (!tap) //D this, of course, never catches 326 if (!tap) //D this, of course, never catches
292 { 327 {
293 slog (L_ERR, _("cannot create network interface '%s'"), conf.ifname); 328 slog (L_ERR, _("cannot create network interface '%s'"), conf.ifname);
294 exit (EXIT_FAILURE); 329 exit (EXIT_FAILURE);
295 } 330 }
296 331
332 fcntl (tap->fd, F_SETFD, FD_CLOEXEC);
333
297 if (tap->if_up () && 334 if (tap->if_up () &&
298 !run_script (run_script_cb (this, &vpn::script_if_init), true)) 335 !run_script (run_script_cb (this, &vpn::script_if_init), true))
299 { 336 {
300 slog (L_ERR, _("interface initialization command '%s' failed, exiting."), 337 slog (L_ERR, _("interface initialization command '%s' failed, exiting."),
301 tap->if_up ()); 338 tap->if_up ());
306 { 343 {
307 slog (L_ERR, _("if-up command execution failed, exiting.")); 344 slog (L_ERR, _("if-up command execution failed, exiting."));
308 exit (EXIT_FAILURE); 345 exit (EXIT_FAILURE);
309 } 346 }
310 347
311 tap_ev_watcher.start (tap->fd, EVENT_READ); 348 tap_ev_watcher.start (tap->fd, EV_READ);
312
313 reconnect_all ();
314 349
315 return 0; 350 return 0;
316} 351}
317 352
318bool 353bool
319vpn::send_ipv4_packet (vpn_packet *pkt, const sockinfo &si, int tos) 354vpn::send_ipv4_packet (vpn_packet *pkt, const sockinfo &si, int tos)
320{ 355{
321#if defined(SOL_IP) && defined(IP_TOS) 356 set_tos (ipv4_fd, ipv4_tos, tos);
322 setsockopt (ipv4_fd, SOL_IP, IP_TOS, &tos, sizeof tos);
323#endif
324 sendto (ipv4_fd, &((*pkt)[0]), pkt->len, 0, si.sav4 (), si.salenv4 ()); 357 sendto (ipv4_fd, &((*pkt)[0]), pkt->len, 0, si.sav4 (), si.salenv4 ());
325 358
326 return true; 359 return true;
327} 360}
328 361
351 384
352#if ENABLE_ICMP 385#if ENABLE_ICMP
353bool 386bool
354vpn::send_icmpv4_packet (vpn_packet *pkt, const sockinfo &si, int tos) 387vpn::send_icmpv4_packet (vpn_packet *pkt, const sockinfo &si, int tos)
355{ 388{
356#if defined(SOL_IP) && defined(IP_TOS)
357 setsockopt (icmpv4_fd, SOL_IP, IP_TOS, &tos, sizeof tos);
358#endif
359
360 pkt->unshift_hdr (4); 389 pkt->unshift_hdr (4);
361 390
362 icmp_header *hdr = (icmp_header *)&((*pkt)[0]); 391 icmp_header *hdr = (icmp_header *)&((*pkt)[0]);
363 hdr->type = ::conf.icmp_type; 392 hdr->type = ::conf.icmp_type;
364 hdr->code = 255; 393 hdr->code = 255;
365 hdr->checksum = 0; 394 hdr->checksum = 0;
366 hdr->checksum = ipv4_checksum ((u16 *)hdr, pkt->len); 395 hdr->checksum = ipv4_checksum ((u16 *)hdr, pkt->len);
367 396
397 set_tos (icmpv4_fd, icmpv4_tos, tos);
368 sendto (icmpv4_fd, &((*pkt)[0]), pkt->len, 0, si.sav4 (), si.salenv4 ()); 398 sendto (icmpv4_fd, &((*pkt)[0]), pkt->len, 0, si.sav4 (), si.salenv4 ());
369 399
370 return true; 400 return true;
371} 401}
372#endif 402#endif
373 403
374bool 404bool
375vpn::send_udpv4_packet (vpn_packet *pkt, const sockinfo &si, int tos) 405vpn::send_udpv4_packet (vpn_packet *pkt, const sockinfo &si, int tos)
376{ 406{
377#if defined(SOL_IP) && defined(IP_TOS) 407 set_tos (udpv4_fd, udpv4_tos, tos);
378 setsockopt (udpv4_fd, SOL_IP, IP_TOS, &tos, sizeof tos);
379#endif
380 sendto (udpv4_fd, &((*pkt)[0]), pkt->len, 0, si.sav4 (), si.salenv4 ()); 408 sendto (udpv4_fd, &((*pkt)[0]), pkt->len, 0, si.sav4 (), si.salenv4 ());
381 409
382 return true; 410 return true;
383} 411}
384 412
446{ 474{
447 switch (si.prot) 475 switch (si.prot)
448 { 476 {
449 case PROT_IPv4: 477 case PROT_IPv4:
450 return send_ipv4_packet (pkt, si, tos); 478 return send_ipv4_packet (pkt, si, tos);
479
451 case PROT_UDPv4: 480 case PROT_UDPv4:
452 return send_udpv4_packet (pkt, si, tos); 481 return send_udpv4_packet (pkt, si, tos);
482
453#if ENABLE_TCP 483#if ENABLE_TCP
454 case PROT_TCPv4: 484 case PROT_TCPv4:
455 return send_tcpv4_packet (pkt, si, tos); 485 return send_tcpv4_packet (pkt, si, tos);
456#endif 486#endif
457#if ENABLE_ICMP 487#if ENABLE_ICMP
460#endif 490#endif
461#if ENABLE_DNS 491#if ENABLE_DNS
462 case PROT_DNSv4: 492 case PROT_DNSv4:
463 return send_dnsv4_packet (pkt, si, tos); 493 return send_dnsv4_packet (pkt, si, tos);
464#endif 494#endif
465
466 default: 495 default:
467 slog (L_CRIT, _("%s: FATAL: trying to send packet with unsupported protocol"), (const char *)si); 496 slog (L_CRIT, _("%s: FATAL: trying to send packet with unsupported protocol"), (const char *)si);
468 } 497 }
469 498
470 return false; 499 return false;
471} 500}
472 501
473void 502void
474vpn::ipv4_ev (io_watcher &w, short revents) 503vpn::ipv4_ev (ev::io &w, int revents)
475{ 504{
476 if (revents & EVENT_READ) 505 if (revents & EV_READ)
477 { 506 {
478 vpn_packet *pkt = new vpn_packet; 507 vpn_packet *pkt = new vpn_packet;
479 struct sockaddr_in sa; 508 struct sockaddr_in sa;
480 socklen_t sa_len = sizeof (sa); 509 socklen_t sa_len = sizeof (sa);
481 int len; 510 int len;
510 } 539 }
511} 540}
512 541
513#if ENABLE_ICMP 542#if ENABLE_ICMP
514void 543void
515vpn::icmpv4_ev (io_watcher &w, short revents) 544vpn::icmpv4_ev (ev::io &w, int revents)
516{ 545{
517 if (revents & EVENT_READ) 546 if (revents & EV_READ)
518 { 547 {
519 vpn_packet *pkt = new vpn_packet; 548 vpn_packet *pkt = new vpn_packet;
520 struct sockaddr_in sa; 549 struct sockaddr_in sa;
521 socklen_t sa_len = sizeof (sa); 550 socklen_t sa_len = sizeof (sa);
522 int len; 551 int len;
558 } 587 }
559} 588}
560#endif 589#endif
561 590
562void 591void
563vpn::udpv4_ev (io_watcher &w, short revents) 592vpn::udpv4_ev (ev::io &w, int revents)
564{ 593{
565 if (revents & EVENT_READ) 594 if (revents & EV_READ)
566 { 595 {
567 vpn_packet *pkt = new vpn_packet; 596 vpn_packet *pkt = new vpn_packet;
568 struct sockaddr_in sa; 597 struct sockaddr_in sa;
569 socklen_t sa_len = sizeof (sa); 598 socklen_t sa_len = sizeof (sa);
570 int len; 599 int len;
595 exit (EXIT_FAILURE); 624 exit (EXIT_FAILURE);
596 } 625 }
597} 626}
598 627
599void 628void
600vpn::tap_ev (io_watcher &w, short revents) 629vpn::tap_ev (ev::io &w, int revents)
601{ 630{
602 if (revents & EVENT_READ) 631 if (revents & EV_READ)
603 { 632 {
604 /* process data */ 633 /* process data */
605 tap_packet *pkt; 634 tap_packet *pkt;
606 635
607 pkt = tap->recv (); 636 pkt = tap->recv ();
637 else 666 else
638 abort (); 667 abort ();
639} 668}
640 669
641void 670void
642vpn::event_cb (time_watcher &w) 671vpn::event_cb (ev::timer &w, int)
643{ 672{
644 if (events) 673 if (events)
645 { 674 {
646 if (events & EVENT_SHUTDOWN) 675 if (events & EVENT_SHUTDOWN)
647 { 676 {
738} 767}
739 768
740void 769void
741vpn::dump_status () 770vpn::dump_status ()
742{ 771{
743 slog (L_NOTICE, _("BEGIN status dump (%ld)"), (long)NOW); 772 slog (L_NOTICE, _("BEGIN status dump (%ld)"), (long)ev_now ());
744 773
745 for (conns_vector::iterator c = conns.begin (); c != conns.end (); ++c) 774 for (conns_vector::iterator c = conns.begin (); c != conns.end (); ++c)
746 (*c)->dump_status (); 775 (*c)->dump_status ();
747 776
748 slog (L_NOTICE, _("END status dump")); 777 slog (L_NOTICE, _("END status dump"));

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines