ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/vpn_dns.C
(Generate patch)

Comparing gvpe/src/vpn_dns.C (file contents):
Revision 1.38 by pcg, Tue Apr 19 04:23:38 2005 UTC vs.
Revision 1.48 by pcg, Tue Jul 28 00:42:14 2009 UTC

1/* 1/*
2 vpn_dns.C -- handle the dns tunnel part of the protocol. 2 vpn_dns.C -- handle the dns tunnel part of the protocol.
3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de> 3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de>
4 4
5 This file is part of GVPE. 5 This file is part of GVPE.
6 6
7 GVPE is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify it
8 it under the terms of the GNU General Public License as published by 8 under the terms of the GNU General Public License as published by the
9 the Free Software Foundation; either version 2 of the License, or 9 Free Software Foundation; either version 3 of the License, or (at your
10 (at your option) any later version. 10 option) any later version.
11 11
12 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful, but
13 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
15 GNU General Public License for more details. 15 Public License for more details.
16 16
17 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License along
18 along with gvpe; if not, write to the Free Software 18 with this program; if not, see <http://www.gnu.org/licenses/>.
19 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
20*/ 30*/
21 31
22// TODO: EDNS0 option to increase dns mtu? 32// TODO: EDNS0 option to increase dns mtu?
23// TODO: re-write dns packet parsing/creation using a safe mem-buffer 33// TODO: re-write dns packet parsing/creation using a safe mem-buffer
24// to ensure no buffer overflows or similar problems. 34// to ensure no buffer overflows or similar problems.
42#include <unistd.h> 52#include <unistd.h>
43#include <fcntl.h> 53#include <fcntl.h>
44 54
45#include <map> 55#include <map>
46 56
57#include <cstdio> /* bug in libgmp: gmp.h relies on cstdio being included */
47#include <gmp.h> 58#include <gmp.h>
48 59
49#include "netcompat.h" 60#include "netcompat.h"
50 61
51#include "vpn.h" 62#include "vpn.h"
72#define MAX_PKT_SIZE 512 83#define MAX_PKT_SIZE 512
73 84
74#define RR_TYPE_A 1 85#define RR_TYPE_A 1
75#define RR_TYPE_NULL 10 86#define RR_TYPE_NULL 10
76#define RR_TYPE_TXT 16 87#define RR_TYPE_TXT 16
88#define RR_TYPE_AAAA 28
77#define RR_TYPE_ANY 255 89#define RR_TYPE_ANY 255
78 90
79#define RR_CLASS_IN 1 91#define RR_CLASS_IN 1
80 92
81#define CMD_IP_1 207 93#define CMD_IP_1 207
461 r4 = r5 = r6 = r7 = 0; 473 r4 = r5 = r6 = r7 = 0;
462} 474}
463 475
464bool dns_cfg::valid () 476bool dns_cfg::valid ()
465{ 477{
478 // although the protocol itself allows for some configurability,
479 // only the following encoding/decoding settings are implemented.
466 return id1 == 'G' 480 return id1 == 'G'
467 && id2 == 'V' 481 && id2 == 'V'
468 && id3 == 'P' 482 && id3 == 'P'
469 && id4 == 'E' 483 && id4 == 'E'
470 && seq_cdc == 26 484 && seq_cdc == 26
557 vector<dns_rcv *> rcvpq; 571 vector<dns_rcv *> rcvpq;
558 572
559 byte_stream rcvdq; int rcvseq; int repseq; 573 byte_stream rcvdq; int rcvseq; int repseq;
560 byte_stream snddq; int sndseq; 574 byte_stream snddq; int sndseq;
561 575
562 void time_cb (time_watcher &w); time_watcher tw; 576 inline void time_cb (ev::timer &w, int revents); ev::timer tw;
563 void receive_rep (dns_rcv *r); 577 void receive_rep (dns_rcv *r);
564 578
565 dns_connection (connection *c); 579 dns_connection (connection *c);
566 ~dns_connection (); 580 ~dns_connection ();
567}; 581};
586: dns (dns) 600: dns (dns)
587{ 601{
588 timeout = 0; 602 timeout = 0;
589 retry = 0; 603 retry = 0;
590 seqno = 0; 604 seqno = 0;
591 sent = NOW; 605 sent = ev_now ();
592 stdhdr = false; 606 stdhdr = false;
593 607
594 pkt = new dns_packet; 608 pkt = new dns_packet;
595 609
596 pkt->id = next_id (); 610 pkt->id = next_id ();
627void dns_snd::gen_stream_req (int seqno, byte_stream &stream) 641void dns_snd::gen_stream_req (int seqno, byte_stream &stream)
628{ 642{
629 stdhdr = true; 643 stdhdr = true;
630 this->seqno = seqno; 644 this->seqno = seqno;
631 645
632 timeout = NOW + INITIAL_TIMEOUT; 646 timeout = ev_now () + INITIAL_TIMEOUT;
633 647
634 pkt->flags = htons (DEFAULT_CLIENT_FLAGS); 648 pkt->flags = htons (DEFAULT_CLIENT_FLAGS);
635 pkt->qdcount = htons (1); 649 pkt->qdcount = htons (1);
636 650
637 int offs = 6*2; 651 int offs = 6*2;
672 pkt->len = offs; 686 pkt->len = offs;
673} 687}
674 688
675void dns_snd::gen_syn_req () 689void dns_snd::gen_syn_req ()
676{ 690{
677 timeout = NOW + INITIAL_SYN_TIMEOUT; 691 timeout = ev_now () + INITIAL_SYN_TIMEOUT;
678 692
679 pkt->flags = htons (DEFAULT_CLIENT_FLAGS); 693 pkt->flags = htons (DEFAULT_CLIENT_FLAGS);
680 pkt->qdcount = htons (1); 694 pkt->qdcount = htons (1);
681 695
682 int offs = 6 * 2; 696 int offs = 6 * 2;
722 736
723dns_connection::dns_connection (connection *c) 737dns_connection::dns_connection (connection *c)
724: c (c) 738: c (c)
725, rcvdq (MAX_BACKLOG * 2) 739, rcvdq (MAX_BACKLOG * 2)
726, snddq (MAX_BACKLOG) 740, snddq (MAX_BACKLOG)
727, tw (this, &dns_connection::time_cb)
728{ 741{
742 tw.set<dns_connection, &dns_connection::time_cb> (this);
743
729 vpn = c->vpn; 744 vpn = c->vpn;
730 745
731 established = false; 746 established = false;
732 747
733 rcvseq = repseq = sndseq = 0; 748 rcvseq = repseq = sndseq = 0;
748 763
749void dns_connection::receive_rep (dns_rcv *r) 764void dns_connection::receive_rep (dns_rcv *r)
750{ 765{
751 if (r->datalen) 766 if (r->datalen)
752 { 767 {
753 last_received = NOW; 768 last_received = ev_now ();
754 tw.trigger (); 769 tw ();
755 770
756 poll_interval = send_interval; 771 poll_interval = send_interval;
757 } 772 }
758 else 773 else
759 { 774 {
769 784
770 // find next packet 785 // find next packet
771 for (vector<dns_rcv *>::iterator i = rcvpq.end (); i-- != rcvpq.begin (); ) 786 for (vector<dns_rcv *>::iterator i = rcvpq.end (); i-- != rcvpq.begin (); )
772 if (SEQNO_EQ (rcvseq, (*i)->seqno)) 787 if (SEQNO_EQ (rcvseq, (*i)->seqno))
773 { 788 {
789 //printf ("seqno eq %x %x\n", rcvseq, (*i)->seqno);//D
774 // enter the packet into our input stream 790 // enter the packet into our input stream
775 r = *i; 791 r = *i;
776 792
777 // remove the oldest packet, look forward, as it's oldest first 793 // remove the oldest packet, look forward, as it's oldest first
778 for (vector<dns_rcv *>::iterator j = rcvpq.begin (); j != rcvpq.end (); ++j) 794 for (vector<dns_rcv *>::iterator j = rcvpq.begin (); j != rcvpq.end (); ++j)
779 if (SEQNO_EQ ((*j)->seqno, rcvseq - MAX_WINDOW)) 795 if (SEQNO_EQ ((*j)->seqno, rcvseq - MAX_WINDOW))
780 { 796 {
797 //printf ("seqno RR %x %x\n", (*j)->seqno, rcvseq - MAX_WINDOW);//D
781 delete *j; 798 delete *j;
782 rcvpq.erase (j); 799 rcvpq.erase (j);
783 break; 800 break;
784 } 801 }
785 802
1013 { 1030 {
1014 dns_connection *dns = (*i)->dns; 1031 dns_connection *dns = (*i)->dns;
1015 connection *c = dns->c; 1032 connection *c = dns->c;
1016 int seqno = (*i)->seqno; 1033 int seqno = (*i)->seqno;
1017 u8 data[MAXSIZE], *datap = data; 1034 u8 data[MAXSIZE], *datap = data;
1035 //printf ("rcv pkt %x\n", seqno);//D
1018 1036
1019 if ((*i)->retry) 1037 if ((*i)->retry)
1020 { 1038 {
1021 dns->send_interval *= 1.01; 1039 dns->send_interval *= 1.01;
1022 if (dns->send_interval > MAX_SEND_INTERVAL) 1040 if (dns->send_interval > MAX_SEND_INTERVAL)
1027#if 0 1045#if 0
1028 dns->send_interval *= 0.999; 1046 dns->send_interval *= 0.999;
1029#endif 1047#endif
1030 // the latency surely puts an upper bound on 1048 // the latency surely puts an upper bound on
1031 // the minimum send interval 1049 // the minimum send interval
1032 double latency = NOW - (*i)->sent; 1050 double latency = ev_now () - (*i)->sent;
1033 1051
1034 if (latency < dns->min_latency) 1052 if (latency < dns->min_latency)
1035 dns->min_latency = latency; 1053 dns->min_latency = latency;
1036 1054
1037 if (dns->send_interval > dns->min_latency * conf.dns_overlap_factor) 1055 if (dns->send_interval > dns->min_latency * conf.dns_overlap_factor)
1151 break; 1169 break;
1152 } 1170 }
1153} 1171}
1154 1172
1155void 1173void
1156vpn::dnsv4_ev (io_watcher &w, short revents) 1174vpn::dnsv4_ev (ev::io &w, int revents)
1157{ 1175{
1158 if (revents & EVENT_READ) 1176 if (revents & EV_READ)
1159 { 1177 {
1160 dns_packet *pkt = new dns_packet; 1178 dns_packet *pkt = new dns_packet;
1161 struct sockaddr_in sa; 1179 struct sockaddr_in sa;
1162 socklen_t sa_len = sizeof (sa); 1180 socklen_t sa_len = sizeof (sa);
1163 1181
1189 1207
1190 if (!c->dns) 1208 if (!c->dns)
1191 c->dns = new dns_connection (c); 1209 c->dns = new dns_connection (c);
1192 1210
1193 if (c->dns->snddq.put (pkt)) 1211 if (c->dns->snddq.put (pkt))
1194 c->dns->tw.trigger (); 1212 c->dns->tw ();
1195 1213
1196 // always return true even if the buffer overflows 1214 // always return true even if the buffer overflows
1197 return true; 1215 return true;
1198} 1216}
1199 1217
1204} 1222}
1205 1223
1206#define NEXT(w) do { if (next > (w)) next = w; } while (0) 1224#define NEXT(w) do { if (next > (w)) next = w; } while (0)
1207 1225
1208void 1226void
1209dns_connection::time_cb (time_watcher &w) 1227dns_connection::time_cb (ev::timer &w, int revents)
1210{ 1228{
1211 // servers have to be polled 1229 // servers have to be polled
1212 if (THISNODE->dns_port) 1230 if (THISNODE->dns_port)
1213 return; 1231 return;
1214 1232
1215 // check for timeouts and (re)transmit 1233 // check for timeouts and (re)transmit
1216 tstamp next = NOW + poll_interval; 1234 tstamp next = ev::now () + poll_interval;
1217 dns_snd *send = 0; 1235 dns_snd *send = 0;
1218 1236
1219 for (vector<dns_snd *>::iterator i = vpn->dns_sndpq.begin (); 1237 for (vector<dns_snd *>::iterator i = vpn->dns_sndpq.begin ();
1220 i != vpn->dns_sndpq.end (); 1238 i != vpn->dns_sndpq.end ();
1221 ++i) 1239 ++i)
1222 { 1240 {
1223 dns_snd *r = *i; 1241 dns_snd *r = *i;
1224 1242
1225 if (r->timeout <= NOW) 1243 if (r->timeout <= ev_now ())
1226 { 1244 {
1227 if (!send) 1245 if (!send)
1228 { 1246 {
1229 send = r; 1247 send = r;
1230 1248
1231 r->retry++; 1249 r->retry++;
1232 r->timeout = NOW + (r->retry * min_latency * conf.dns_timeout_factor); 1250 r->timeout = ev_now () + (r->retry * min_latency * conf.dns_timeout_factor);
1251 //printf ("RETRY %x (%d, %f)\n", r->seqno, r->retry, r->timeout - ev_now ());//D
1233 1252
1234 // the following code changes the query section a bit, forcing 1253 // the following code changes the query section a bit, forcing
1235 // the forwarder to generate a new request 1254 // the forwarder to generate a new request
1236 if (r->stdhdr) 1255 if (r->stdhdr)
1237 {
1238 //printf ("reencoded header for ID %d retry %d:%d:%d (%p)\n", htons (r->pkt->id), THISNODE->id, r->seqno, r->retry);
1239 //encode_header ((char *)r->pkt->at (6 * 2 + 1), THISNODE->id, r->seqno, r->retry); 1256 encode_header ((char *)r->pkt->at (6 * 2 + 1), THISNODE->id, r->seqno, r->retry);
1240 }
1241 } 1257 }
1242 } 1258 }
1243 else 1259 else
1244 NEXT (r->timeout); 1260 NEXT (r->timeout);
1245 } 1261 }
1259 } 1275 }
1260 } 1276 }
1261 else if (vpn->dns_sndpq.size () < conf.dns_max_outstanding 1277 else if (vpn->dns_sndpq.size () < conf.dns_max_outstanding
1262 && !SEQNO_EQ (rcvseq, sndseq - (MAX_WINDOW - 1))) 1278 && !SEQNO_EQ (rcvseq, sndseq - (MAX_WINDOW - 1)))
1263 { 1279 {
1264 if (last_sent + send_interval <= NOW) 1280 if (last_sent + send_interval <= ev_now ())
1265 { 1281 {
1266 //printf ("sending data request etc.\n"); //D 1282 //printf ("sending data request etc.\n"); //D
1267 if (!snddq.empty () || last_received + 1. > NOW) 1283 if (!snddq.empty () || last_received + 1. > ev_now ())
1268 { 1284 {
1269 poll_interval = send_interval; 1285 poll_interval = send_interval;
1270 NEXT (NOW + send_interval); 1286 NEXT (ev_now () + send_interval);
1271 } 1287 }
1272 1288
1273 send = new dns_snd (this); 1289 send = new dns_snd (this);
1274 send->gen_stream_req (sndseq, snddq); 1290 send->gen_stream_req (sndseq, snddq);
1275 send->timeout = NOW + min_latency * conf.dns_timeout_factor; 1291 send->timeout = ev_now () + min_latency * conf.dns_timeout_factor;
1292 //printf ("SEND %x (%f)\n", send->seqno, send->timeout - ev_now (), min_latency, conf.dns_timeout_factor);//D
1276 1293
1277 sndseq = (sndseq + 1) & SEQNO_MASK; 1294 sndseq = (sndseq + 1) & SEQNO_MASK;
1278 } 1295 }
1279 else 1296 else
1280 NEXT (last_sent + send_interval); 1297 NEXT (last_sent + send_interval);
1284 vpn->dns_sndpq.push_back (send); 1301 vpn->dns_sndpq.push_back (send);
1285 } 1302 }
1286 1303
1287 if (send) 1304 if (send)
1288 { 1305 {
1289 last_sent = NOW; 1306 last_sent = ev_now ();
1290 sendto (vpn->dnsv4_fd, 1307 sendto (vpn->dnsv4_fd,
1291 send->pkt->at (0), send->pkt->len, 0, 1308 send->pkt->at (0), send->pkt->len, 0,
1292 vpn->dns_forwarder.sav4 (), vpn->dns_forwarder.salenv4 ()); 1309 vpn->dns_forwarder.sav4 (), vpn->dns_forwarder.salenv4 ());
1293 } 1310 }
1294 1311
1295 slog (L_NOISE, "DNS: pi %f si %f N %f (%d:%d %d)", 1312 slog (L_NOISE, "DNS: pi %f si %f N %f (%d:%d %d)",
1296 poll_interval, send_interval, next - NOW, 1313 poll_interval, send_interval, next - ev_now (),
1297 vpn->dns_sndpq.size (), snddq.size (), 1314 vpn->dns_sndpq.size (), snddq.size (),
1298 rcvpq.size ()); 1315 rcvpq.size ());
1299 1316
1300 // TODO: no idea when this happens, but when next < NOW, we have a problem 1317 // TODO: no idea when this happens, but when next < ev_now (), we have a problem
1301 // doesn't seem to happen anymore 1318 // doesn't seem to happen anymore
1302 if (next < NOW + 0.001) 1319 if (next < ev_now () + 0.001)
1303 next = NOW + 0.1; 1320 next = ev_now () + 0.1;
1304 1321
1305 w.start (next); 1322 w.start (next - ev_now ());
1306} 1323}
1307 1324
1308#endif 1325#endif
1309 1326

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines