ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/vpn_dns.C
(Generate patch)

Comparing gvpe/src/vpn_dns.C (file contents):
Revision 1.37 by pcg, Wed Mar 23 17:03:58 2005 UTC vs.
Revision 1.48 by pcg, Tue Jul 28 00:42:14 2009 UTC

1/* 1/*
2 vpn_dns.C -- handle the dns tunnel part of the protocol. 2 vpn_dns.C -- handle the dns tunnel part of the protocol.
3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de> 3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE. 5 This file is part of GVPE.
6 6
7 GVPE is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify it
8 it under the terms of the GNU General Public License as published by 8 under the terms of the GNU General Public License as published by the
9 the Free Software Foundation; either version 2 of the License, or 9 Free Software Foundation; either version 3 of the License, or (at your
10 (at your option) any later version. 10 option) any later version.
11 11
12 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful, but
13 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 GNU General Public License for more details. 15 Public License for more details.
16 16
17 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License along
18 along with gvpe; if not, write to the Free Software 18 with this program; if not, see <http://www.gnu.org/licenses/>.
19 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
20*/ 30*/
31
32// TODO: EDNS0 option to increase dns mtu?
33// TODO: re-write dns packet parsing/creation using a safe mem-buffer
34// to ensure no buffer overflows or similar problems.
21 35
22#include "config.h" 36#include "config.h"
23 37
24#if ENABLE_DNS 38#if ENABLE_DNS
25 39
38#include <unistd.h> 52#include <unistd.h>
39#include <fcntl.h> 53#include <fcntl.h>
40 54
41#include <map> 55#include <map>
42 56
57#include <cstdio> /* bug in libgmp: gmp.h relies on cstdio being included */
43#include <gmp.h> 58#include <gmp.h>
44 59
45#include "netcompat.h" 60#include "netcompat.h"
46 61
47#include "vpn.h" 62#include "vpn.h"
68#define MAX_PKT_SIZE 512 83#define MAX_PKT_SIZE 512
69 84
70#define RR_TYPE_A 1 85#define RR_TYPE_A 1
71#define RR_TYPE_NULL 10 86#define RR_TYPE_NULL 10
72#define RR_TYPE_TXT 16 87#define RR_TYPE_TXT 16
88#define RR_TYPE_AAAA 28
73#define RR_TYPE_ANY 255 89#define RR_TYPE_ANY 255
74 90
75#define RR_CLASS_IN 1 91#define RR_CLASS_IN 1
76 92
77#define CMD_IP_1 207 93#define CMD_IP_1 207
457 r4 = r5 = r6 = r7 = 0; 473 r4 = r5 = r6 = r7 = 0;
458} 474}
459 475
460bool dns_cfg::valid () 476bool dns_cfg::valid ()
461{ 477{
478 // although the protocol itself allows for some configurability,
479 // only the following encoding/decoding settings are implemented.
462 return id1 == 'G' 480 return id1 == 'G'
463 && id2 == 'V' 481 && id2 == 'V'
464 && id3 == 'P' 482 && id3 == 'P'
465 && id4 == 'E' 483 && id4 == 'E'
466 && seq_cdc == 26 484 && seq_cdc == 26
553 vector<dns_rcv *> rcvpq; 571 vector<dns_rcv *> rcvpq;
554 572
555 byte_stream rcvdq; int rcvseq; int repseq; 573 byte_stream rcvdq; int rcvseq; int repseq;
556 byte_stream snddq; int sndseq; 574 byte_stream snddq; int sndseq;
557 575
558 void time_cb (time_watcher &w); time_watcher tw; 576 inline void time_cb (ev::timer &w, int revents); ev::timer tw;
559 void receive_rep (dns_rcv *r); 577 void receive_rep (dns_rcv *r);
560 578
561 dns_connection (connection *c); 579 dns_connection (connection *c);
562 ~dns_connection (); 580 ~dns_connection ();
563}; 581};
582: dns (dns) 600: dns (dns)
583{ 601{
584 timeout = 0; 602 timeout = 0;
585 retry = 0; 603 retry = 0;
586 seqno = 0; 604 seqno = 0;
587 sent = NOW; 605 sent = ev_now ();
588 stdhdr = false; 606 stdhdr = false;
589 607
590 pkt = new dns_packet; 608 pkt = new dns_packet;
591 609
592 pkt->id = next_id (); 610 pkt->id = next_id ();
623void dns_snd::gen_stream_req (int seqno, byte_stream &stream) 641void dns_snd::gen_stream_req (int seqno, byte_stream &stream)
624{ 642{
625 stdhdr = true; 643 stdhdr = true;
626 this->seqno = seqno; 644 this->seqno = seqno;
627 645
628 timeout = NOW + INITIAL_TIMEOUT; 646 timeout = ev_now () + INITIAL_TIMEOUT;
629 647
630 pkt->flags = htons (DEFAULT_CLIENT_FLAGS); 648 pkt->flags = htons (DEFAULT_CLIENT_FLAGS);
631 pkt->qdcount = htons (1); 649 pkt->qdcount = htons (1);
632 650
633 int offs = 6*2; 651 int offs = 6*2;
668 pkt->len = offs; 686 pkt->len = offs;
669} 687}
670 688
671void dns_snd::gen_syn_req () 689void dns_snd::gen_syn_req ()
672{ 690{
673 timeout = NOW + INITIAL_SYN_TIMEOUT; 691 timeout = ev_now () + INITIAL_SYN_TIMEOUT;
674 692
675 pkt->flags = htons (DEFAULT_CLIENT_FLAGS); 693 pkt->flags = htons (DEFAULT_CLIENT_FLAGS);
676 pkt->qdcount = htons (1); 694 pkt->qdcount = htons (1);
677 695
678 int offs = 6 * 2; 696 int offs = 6 * 2;
718 736
719dns_connection::dns_connection (connection *c) 737dns_connection::dns_connection (connection *c)
720: c (c) 738: c (c)
721, rcvdq (MAX_BACKLOG * 2) 739, rcvdq (MAX_BACKLOG * 2)
722, snddq (MAX_BACKLOG) 740, snddq (MAX_BACKLOG)
723, tw (this, &dns_connection::time_cb)
724{ 741{
742 tw.set<dns_connection, &dns_connection::time_cb> (this);
743
725 vpn = c->vpn; 744 vpn = c->vpn;
726 745
727 established = false; 746 established = false;
728 747
729 rcvseq = repseq = sndseq = 0; 748 rcvseq = repseq = sndseq = 0;
744 763
745void dns_connection::receive_rep (dns_rcv *r) 764void dns_connection::receive_rep (dns_rcv *r)
746{ 765{
747 if (r->datalen) 766 if (r->datalen)
748 { 767 {
749 last_received = NOW; 768 last_received = ev_now ();
750 tw.trigger (); 769 tw ();
751 770
752 poll_interval = send_interval; 771 poll_interval = send_interval;
753 } 772 }
754 else 773 else
755 { 774 {
765 784
766 // find next packet 785 // find next packet
767 for (vector<dns_rcv *>::iterator i = rcvpq.end (); i-- != rcvpq.begin (); ) 786 for (vector<dns_rcv *>::iterator i = rcvpq.end (); i-- != rcvpq.begin (); )
768 if (SEQNO_EQ (rcvseq, (*i)->seqno)) 787 if (SEQNO_EQ (rcvseq, (*i)->seqno))
769 { 788 {
789 //printf ("seqno eq %x %x\n", rcvseq, (*i)->seqno);//D
770 // enter the packet into our input stream 790 // enter the packet into our input stream
771 r = *i; 791 r = *i;
772 792
773 // remove the oldest packet, look forward, as it's oldest first 793 // remove the oldest packet, look forward, as it's oldest first
774 for (vector<dns_rcv *>::iterator j = rcvpq.begin (); j != rcvpq.end (); ++j) 794 for (vector<dns_rcv *>::iterator j = rcvpq.begin (); j != rcvpq.end (); ++j)
775 if (SEQNO_EQ ((*j)->seqno, rcvseq - MAX_WINDOW)) 795 if (SEQNO_EQ ((*j)->seqno, rcvseq - MAX_WINDOW))
776 { 796 {
797 //printf ("seqno RR %x %x\n", (*j)->seqno, rcvseq - MAX_WINDOW);//D
777 delete *j; 798 delete *j;
778 rcvpq.erase (j); 799 rcvpq.erase (j);
779 break; 800 break;
780 } 801 }
781 802
1009 { 1030 {
1010 dns_connection *dns = (*i)->dns; 1031 dns_connection *dns = (*i)->dns;
1011 connection *c = dns->c; 1032 connection *c = dns->c;
1012 int seqno = (*i)->seqno; 1033 int seqno = (*i)->seqno;
1013 u8 data[MAXSIZE], *datap = data; 1034 u8 data[MAXSIZE], *datap = data;
1035 //printf ("rcv pkt %x\n", seqno);//D
1014 1036
1015 if ((*i)->retry) 1037 if ((*i)->retry)
1016 { 1038 {
1017 dns->send_interval *= 1.01; 1039 dns->send_interval *= 1.01;
1018 if (dns->send_interval > MAX_SEND_INTERVAL) 1040 if (dns->send_interval > MAX_SEND_INTERVAL)
1023#if 0 1045#if 0
1024 dns->send_interval *= 0.999; 1046 dns->send_interval *= 0.999;
1025#endif 1047#endif
1026 // the latency surely puts an upper bound on 1048 // the latency surely puts an upper bound on
1027 // the minimum send interval 1049 // the minimum send interval
1028 double latency = NOW - (*i)->sent; 1050 double latency = ev_now () - (*i)->sent;
1029 1051
1030 if (latency < dns->min_latency) 1052 if (latency < dns->min_latency)
1031 dns->min_latency = latency; 1053 dns->min_latency = latency;
1032 1054
1033 if (dns->send_interval > dns->min_latency * conf.dns_overlap_factor) 1055 if (dns->send_interval > dns->min_latency * conf.dns_overlap_factor)
1147 break; 1169 break;
1148 } 1170 }
1149} 1171}
1150 1172
1151void 1173void
1152vpn::dnsv4_ev (io_watcher &w, short revents) 1174vpn::dnsv4_ev (ev::io &w, int revents)
1153{ 1175{
1154 if (revents & EVENT_READ) 1176 if (revents & EV_READ)
1155 { 1177 {
1156 dns_packet *pkt = new dns_packet; 1178 dns_packet *pkt = new dns_packet;
1157 struct sockaddr_in sa; 1179 struct sockaddr_in sa;
1158 socklen_t sa_len = sizeof (sa); 1180 socklen_t sa_len = sizeof (sa);
1159 1181
1185 1207
1186 if (!c->dns) 1208 if (!c->dns)
1187 c->dns = new dns_connection (c); 1209 c->dns = new dns_connection (c);
1188 1210
1189 if (c->dns->snddq.put (pkt)) 1211 if (c->dns->snddq.put (pkt))
1190 c->dns->tw.trigger (); 1212 c->dns->tw ();
1191 1213
1192 // always return true even if the buffer overflows 1214 // always return true even if the buffer overflows
1193 return true; 1215 return true;
1194} 1216}
1195 1217
1200} 1222}
1201 1223
1202#define NEXT(w) do { if (next > (w)) next = w; } while (0) 1224#define NEXT(w) do { if (next > (w)) next = w; } while (0)
1203 1225
1204void 1226void
1205dns_connection::time_cb (time_watcher &w) 1227dns_connection::time_cb (ev::timer &w, int revents)
1206{ 1228{
1207 // servers have to be polled 1229 // servers have to be polled
1208 if (THISNODE->dns_port) 1230 if (THISNODE->dns_port)
1209 return; 1231 return;
1210 1232
1211 // check for timeouts and (re)transmit 1233 // check for timeouts and (re)transmit
1212 tstamp next = NOW + poll_interval; 1234 tstamp next = ev::now () + poll_interval;
1213 dns_snd *send = 0; 1235 dns_snd *send = 0;
1214 1236
1215 for (vector<dns_snd *>::iterator i = vpn->dns_sndpq.begin (); 1237 for (vector<dns_snd *>::iterator i = vpn->dns_sndpq.begin ();
1216 i != vpn->dns_sndpq.end (); 1238 i != vpn->dns_sndpq.end ();
1217 ++i) 1239 ++i)
1218 { 1240 {
1219 dns_snd *r = *i; 1241 dns_snd *r = *i;
1220 1242
1221 if (r->timeout <= NOW) 1243 if (r->timeout <= ev_now ())
1222 { 1244 {
1223 if (!send) 1245 if (!send)
1224 { 1246 {
1225 send = r; 1247 send = r;
1226 1248
1227 r->retry++; 1249 r->retry++;
1228 r->timeout = NOW + (r->retry * min_latency * conf.dns_timeout_factor); 1250 r->timeout = ev_now () + (r->retry * min_latency * conf.dns_timeout_factor);
1251 //printf ("RETRY %x (%d, %f)\n", r->seqno, r->retry, r->timeout - ev_now ());//D
1229 1252
1230 // the following code changes the query section a bit, forcing 1253 // the following code changes the query section a bit, forcing
1231 // the forwarder to generate a new request 1254 // the forwarder to generate a new request
1232 if (r->stdhdr) 1255 if (r->stdhdr)
1233 {
1234 //printf ("reencoded header for ID %d retry %d:%d:%d (%p)\n", htons (r->pkt->id), THISNODE->id, r->seqno, r->retry);
1235 //encode_header ((char *)r->pkt->at (6 * 2 + 1), THISNODE->id, r->seqno, r->retry); 1256 encode_header ((char *)r->pkt->at (6 * 2 + 1), THISNODE->id, r->seqno, r->retry);
1236 }
1237 } 1257 }
1238 } 1258 }
1239 else 1259 else
1240 NEXT (r->timeout); 1260 NEXT (r->timeout);
1241 } 1261 }
1255 } 1275 }
1256 } 1276 }
1257 else if (vpn->dns_sndpq.size () < conf.dns_max_outstanding 1277 else if (vpn->dns_sndpq.size () < conf.dns_max_outstanding
1258 && !SEQNO_EQ (rcvseq, sndseq - (MAX_WINDOW - 1))) 1278 && !SEQNO_EQ (rcvseq, sndseq - (MAX_WINDOW - 1)))
1259 { 1279 {
1260 if (last_sent + send_interval <= NOW) 1280 if (last_sent + send_interval <= ev_now ())
1261 { 1281 {
1262 //printf ("sending data request etc.\n"); //D 1282 //printf ("sending data request etc.\n"); //D
1263 if (!snddq.empty () || last_received + 1. > NOW) 1283 if (!snddq.empty () || last_received + 1. > ev_now ())
1264 { 1284 {
1265 poll_interval = send_interval; 1285 poll_interval = send_interval;
1266 NEXT (NOW + send_interval); 1286 NEXT (ev_now () + send_interval);
1267 } 1287 }
1268 1288
1269 send = new dns_snd (this); 1289 send = new dns_snd (this);
1270 send->gen_stream_req (sndseq, snddq); 1290 send->gen_stream_req (sndseq, snddq);
1271 send->timeout = NOW + min_latency * conf.dns_timeout_factor; 1291 send->timeout = ev_now () + min_latency * conf.dns_timeout_factor;
1292 //printf ("SEND %x (%f)\n", send->seqno, send->timeout - ev_now (), min_latency, conf.dns_timeout_factor);//D
1272 1293
1273 sndseq = (sndseq + 1) & SEQNO_MASK; 1294 sndseq = (sndseq + 1) & SEQNO_MASK;
1274 } 1295 }
1275 else 1296 else
1276 NEXT (last_sent + send_interval); 1297 NEXT (last_sent + send_interval);
1280 vpn->dns_sndpq.push_back (send); 1301 vpn->dns_sndpq.push_back (send);
1281 } 1302 }
1282 1303
1283 if (send) 1304 if (send)
1284 { 1305 {
1285 last_sent = NOW; 1306 last_sent = ev_now ();
1286 sendto (vpn->dnsv4_fd, 1307 sendto (vpn->dnsv4_fd,
1287 send->pkt->at (0), send->pkt->len, 0, 1308 send->pkt->at (0), send->pkt->len, 0,
1288 vpn->dns_forwarder.sav4 (), vpn->dns_forwarder.salenv4 ()); 1309 vpn->dns_forwarder.sav4 (), vpn->dns_forwarder.salenv4 ());
1289 } 1310 }
1290 1311
1291 slog (L_NOISE, "DNS: pi %f si %f N %f (%d:%d %d)", 1312 slog (L_NOISE, "DNS: pi %f si %f N %f (%d:%d %d)",
1292 poll_interval, send_interval, next - NOW, 1313 poll_interval, send_interval, next - ev_now (),
1293 vpn->dns_sndpq.size (), snddq.size (), 1314 vpn->dns_sndpq.size (), snddq.size (),
1294 rcvpq.size ()); 1315 rcvpq.size ());
1295 1316
1296 // TODO: no idea when this happens, but when next < NOW, we have a problem 1317 // TODO: no idea when this happens, but when next < ev_now (), we have a problem
1297 // doesn't seem to happen anymore 1318 // doesn't seem to happen anymore
1298 if (next < NOW + 0.001) 1319 if (next < ev_now () + 0.001)
1299 next = NOW + 0.1; 1320 next = ev_now () + 0.1;
1300 1321
1301 w.start (next); 1322 w.start (next - ev_now ());
1302} 1323}
1303 1324
1304#endif 1325#endif
1305 1326

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines