ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/vpn_tcp.C
(Generate patch)

Comparing gvpe/src/vpn_tcp.C (file contents):
Revision 1.3 by pcg, Sun Apr 6 20:01:53 2003 UTC vs.
Revision 1.25 by pcg, Wed Dec 12 00:17:13 2007 UTC

1/* 1/*
2 vpn_tcp.C -- handle the tcp part of the protocol. 2 vpn_tcp.C -- handle the tcp part of the protocol.
3 Copyright (C) 2003-2007 Marc Lehmann <gvpe@schmorp.de>
3 4
5 This file is part of GVPE.
6
4 This program is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify
5 it under the terms of the GNU General Public License as published by 8 it under the terms of the GNU General Public License as published by
6 the Free Software Foundation; either version 2 of the License, or 9 the Free Software Foundation; either version 2 of the License, or
7 (at your option) any later version. 10 (at your option) any later version.
8 11
9 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details. 15 GNU General Public License for more details.
13 16
14 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License
15 along with this program; if not, write to the Free Software 18 along with gvpe; if not, write to the Free Software
16 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19 Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
17*/ 20*/
18 21
19#include "config.h" 22#include "config.h"
20 23
21#if ENABLE_TCP 24#if ENABLE_TCP
22 25
23// tcp processing is extremely ugly, since the vpe protocol is simply 26// tcp processing is extremely ugly, since the gvpe protocol is simply
24// designed for unreliable datagram networks. tcp is implemented by 27// designed for unreliable datagram networks. tcp is implemented by
25// multiplexing packets over tcp. errors are completely ignored, as we 28// multiplexing packets over tcp. errors are completely ignored, as we
26// rely on the higher level protocol to time out and reconnect. 29// rely on the higher level layers to time out and reconnect.
27 30
28#include <cstring> 31#include <cstring>
29 32
30#include <sys/types.h> 33#include <sys/types.h>
31#include <sys/socket.h> 34#include <sys/socket.h>
32#include <sys/poll.h>
33#include <sys/wait.h> 35#include <sys/wait.h>
34#include <netinet/in.h>
35#include <sys/uio.h> 36#include <sys/uio.h>
36#include <arpa/inet.h>
37#include <errno.h> 37#include <errno.h>
38#include <time.h> 38#include <time.h>
39#include <unistd.h> 39#include <unistd.h>
40#include <fcntl.h>
40 41
41#include <map> 42#include <map>
42#include <unistd.h> 43
43#include <fcntl.h> 44#include "netcompat.h"
44#include <sys/poll.h>
45 45
46#include "vpn.h" 46#include "vpn.h"
47
48#if ENABLE_HTTP_PROXY
49# include "conf.h"
50#endif
47 51
48struct tcp_connection; 52struct tcp_connection;
49 53
50struct lt_sockinfo 54struct lt_sockinfo
51{ 55{
53 { 57 {
54 return *a < *b; 58 return *a < *b;
55 } 59 }
56}; 60};
57 61
58struct tcp_si_map : public map<const sockinfo *, tcp_connection *, lt_sockinfo> { 62struct tcp_si_map : public map<const sockinfo *, tcp_connection *, lt_sockinfo>
59 void cleaner_cb (time_watcher &w); time_watcher cleaner; 63{
64 inline void cleaner_cb (ev::timer &w, int revents); ev::timer cleaner;
60 65
61 tcp_si_map () 66 tcp_si_map ()
62 : cleaner(this, &tcp_si_map::cleaner_cb)
63 { 67 {
64 cleaner.start (0); 68 ev_default_loop (0);
69 cleaner.set<tcp_si_map, &tcp_si_map::cleaner_cb> (this);
70 cleaner.start (::conf.keepalive / 2, ::conf.keepalive / 2);
65 } 71 }
72
66} tcp_si; 73} tcp_si;
67 74
68struct tcp_connection : io_watcher { 75struct tcp_connection : ev::io
76{
77 int tos;
69 tstamp last_activity; 78 tstamp last_activity;
70 const sockinfo si; 79 const sockinfo si;
71 vpn &v; 80 vpn &v;
72 bool active; // this connection has been actively established 81 bool active; // this connection has been actively established
73 enum { ERROR, IDLE, CONNECTING, ESTABLISHED } state; 82 enum { ERROR, IDLE, CONNECTING, CONNECTING_PROXY, ESTABLISHED } state;
74 83
75 vpn_packet *r_pkt; 84 vpn_packet *r_pkt;
76 u32 r_len, r_ofs; 85 u32 r_len, r_ofs;
77 86
78 vpn_packet *w_pkt; 87 vpn_packet *w_pkt;
79 u32 w_len, w_ofs; 88 u32 w_len, w_ofs;
80 89
81 void tcpv4_ev (io_watcher &w, short revents); 90#if ENABLE_HTTP_PROXY
91 char *proxy_req;
92 int proxy_req_len;
93#endif
94
95 inline void tcpv4_ev (ev::io &w, int revents);
82 96
83 bool send_packet (vpn_packet *pkt, int tos); 97 bool send_packet (vpn_packet *pkt, int tos);
84 bool write_packet (); 98 bool write_packet ();
85 99
86 void error (); // abort conenction && cleanup 100 void error (); // abort conenction && cleanup
87 101
88 operator tcp_si_map::value_type() 102 operator tcp_si_map::value_type()
89 { 103 {
90 return tcp_si_map::value_type (&si, this); 104 return tcp_si_map::value_type (&si, this);
91 } 105 }
92 106
93 tcp_connection (int fd_, const sockinfo &si_, vpn &v_); 107 tcp_connection (int fd_, const sockinfo &si_, vpn &v_);
94 ~tcp_connection (); 108 ~tcp_connection ();
95}; 109};
96 110
97void tcp_si_map::cleaner_cb (time_watcher &w) 111void tcp_si_map::cleaner_cb (ev::timer &w, int revents)
98{ 112{
99 w.at = NOW + 600;
100 tstamp to = NOW - ::conf.keepalive - 30 - 60; 113 tstamp to = ev_now () - ::conf.keepalive - 30 - 60;
101 114
102 for (iterator i = begin (); i != end(); ) 115 for (iterator i = begin (); i != end(); )
103 if (i->second->last_activity >= to) 116 if (i->second->last_activity >= to)
104 ++i; 117 ++i;
105 else 118 else
106 { 119 {
120 delete i->second;
107 erase (i); 121 erase (i);
108 i = begin (); 122 i = begin ();
109 } 123 }
110} 124}
111 125
112void 126void
113vpn::tcpv4_ev (io_watcher &w, short revents) 127vpn::tcpv4_ev (ev::io &w, int revents)
114{ 128{
115 if (revents & (POLLIN | POLLERR)) 129 if (revents & EV_READ)
116 { 130 {
117 struct sockaddr_in sa; 131 struct sockaddr_in sa;
118 socklen_t sa_len = sizeof (sa); 132 socklen_t sa_len = sizeof (sa);
119 int len; 133 int len;
120 134
121 int fd = accept (w.fd, (sockaddr *)&sa, &sa_len); 135 int fd = accept (w.fd, (sockaddr *)&sa, &sa_len);
122 136
123 if (fd >= 0) 137 if (fd >= 0)
124 { 138 {
139 fcntl (fd, F_SETFL, O_NONBLOCK);
140 fcntl (fd, F_SETFD, FD_CLOEXEC);
141
125 sockinfo si(sa, PROT_TCPv4); 142 sockinfo si(sa, PROT_TCPv4);
126 143
127 slog (L_DEBUG, _("%s: accepted tcp connection"), (const char *)si);//D 144 slog (L_DEBUG, _("%s: accepted tcp connection"), (const char *)si);//D
128
129 fcntl (fd, F_SETFL, O_NONBLOCK);
130 145
131 tcp_connection *i = new tcp_connection (fd, si, *this); 146 tcp_connection *i = new tcp_connection (fd, si, *this);
132 tcp_si.insert (*i); 147 tcp_si.insert (*i);
133 } 148 }
134 } 149 }
150 i = info->second; 165 i = info->second;
151 166
152 return i->send_packet (pkt, tos); 167 return i->send_packet (pkt, tos);
153} 168}
154 169
155void tcp_connection::error ()
156{
157 if (fd >= 0)
158 {
159 close (fd);
160 fd = -1;
161 }
162
163 delete r_pkt; r_pkt = 0;
164 delete w_pkt; w_pkt = 0;
165
166 stop ();
167 state = active ? IDLE : ERROR;
168}
169
170bool 170bool
171tcp_connection::write_packet () 171tcp_connection::write_packet ()
172{ 172{
173 ssize_t len; 173 ssize_t len;
174 174
175 if (w_ofs < 2) 175 if (w_ofs < 2)
176 { 176 {
177 u16 plen = htons (w_pkt->len); 177 u16 plen = htons (w_pkt->len);
178 178
179 iovec vec[2]; 179 iovec vec[2];
180 //TODO: char* is the right type? hardly...
180 vec[0].iov_base = ((u8 *)&plen) + w_ofs; 181 vec[0].iov_base = (char *)((u8 *)&plen) + w_ofs;
181 vec[0].iov_len = 2 - w_ofs; 182 vec[0].iov_len = 2 - w_ofs;
182 vec[1].iov_base = &((*w_pkt)[0]); 183 vec[1].iov_base = (char *)&((*w_pkt)[0]);
183 vec[1].iov_len = w_len - 2; 184 vec[1].iov_len = w_len - 2;
184 185
185 len = writev (fd, vec, 2); 186 len = writev (fd, vec, 2);
186 } 187 }
187 else 188 else
202 return false; 203 return false;
203 } 204 }
204} 205}
205 206
206void 207void
207tcp_connection::tcpv4_ev (io_watcher &w, short revents) 208tcp_connection::tcpv4_ev (ev::io &w, int revents)
208{ 209{
209 last_activity = NOW; 210 last_activity = ev_now ();
210 211
211 if (revents & (POLLERR | POLLHUP)) 212 if (revents & EV_WRITE)
212 {
213 error ();
214 return;
215 }
216
217 if (revents & POLLOUT)
218 { 213 {
219 if (state == CONNECTING) 214 if (state == CONNECTING)
220 { 215 {
221 state = ESTABLISHED; 216 state = ESTABLISHED;
222 set (POLLIN); 217 set (EV_READ);
218#if ENABLE_HTTP_PROXY
219 if (::conf.proxy_host && ::conf.proxy_port)
220 {
221 state = CONNECTING_PROXY;
222
223 if (write (fd, proxy_req, proxy_req_len) == 0)
224 {
225 error ();
226 return;
227 }
228
229 free (proxy_req); proxy_req = 0;
230 }
231#endif
223 } 232 }
224 else if (state == ESTABLISHED) 233 else if (state == ESTABLISHED)
225 { 234 {
226 if (w_pkt) 235 if (w_pkt)
227 { 236 {
228 if (write_packet ()) 237 if (write_packet ())
229 { 238 {
230 delete w_pkt; w_pkt = 0; 239 delete w_pkt; w_pkt = 0;
231 240
232 set (POLLIN); 241 set (EV_READ);
233 } 242 }
234 } 243 }
235 else 244 else
236 set (POLLIN); 245 set (EV_READ);
237 } 246 }
238 else 247 else
239 set (POLLIN); 248 set (EV_READ);
240 }
241
242 if (revents & POLLIN)
243 { 249 }
250
251 if (revents & EV_READ)
252 {
253 if (state == ESTABLISHED)
244 for (;;) 254 for (;;)
245 { 255 {
246 if (!r_pkt) 256 if (!r_pkt)
247 { 257 {
248 r_pkt = new vpn_packet; 258 r_pkt = new vpn_packet;
249 r_ofs = 0; 259 r_ofs = 0;
250 r_len = 2; // header 260 r_len = 2; // header
251 } 261 }
252 262
253 ssize_t len = read (fd, &((*r_pkt)[r_ofs < 2 ? r_ofs : r_ofs - 2]), r_len); 263 ssize_t len = read (fd, &((*r_pkt)[r_ofs < 2 ? r_ofs : r_ofs - 2]), r_len);
254 264
255 if (len > 0) 265 if (len > 0)
256 { 266 {
257 r_len -= len; 267 r_len -= len;
258 r_ofs += len; 268 r_ofs += len;
259 269
260 if (r_len == 0) 270 if (r_len == 0)
271 {
272 if (r_ofs == 2)
273 {
274 r_len = ntohs (*(u16 *)&((*r_pkt)[0]));
275 r_pkt->len = r_len;
276
277 if (r_len > 0 && r_len < MAXSIZE)
278 continue;
279 }
280 else
281 {
282 v.recv_vpn_packet (r_pkt, si);
283 delete r_pkt;
284 r_pkt = 0;
285
286 continue;
287 }
288 }
289 else
290 break;
291 }
292 else if (len < 0 && (errno == EINTR || errno == EAGAIN))
293 break;
294
295 // len == 0 <-> EOF
296 error ();
297 break;
298 }
299#if ENABLE_HTTP_PROXY
300 else if (state == CONNECTING_PROXY)
301 {
302 fcntl (fd, F_SETFL, 0);
303 char r[1024];
304 int i;
305 bool emptyline = false;
306
307 // we do a blocking read of the response, to hell with it
308 for (i = 0; i < 1023; i++)
309 {
310 int l = read (fd, &r[i], 1);
311
312 if (l <= 0)
261 { 313 {
262 if (r_ofs == 2) 314 error ();
263 { 315 return;
264 r_len = ntohs (*(u16 *)&((*r_pkt)[0]));
265 r_pkt->len = r_len;
266
267 if (r_len > 0 && r_len < MAXSIZE)
268 continue;
269 } 316 }
317
318 if (r[i] == '\012')
319 {
320 if (emptyline)
321 break;
270 else 322 else
271 {
272 v.recv_vpn_packet (r_pkt, si);
273 delete r_pkt;
274 r_pkt = 0;
275
276 continue; 323 emptyline = true;
277 } 324 }
325 else if (r[i] != '\015')
326 emptyline = false;
327 }
328
329 fcntl (fd, F_SETFL, O_NONBLOCK);
330
331 if (i < 12)
332 {
333 slog (L_ERR, _("(%s): unable to do proxy-forwarding, short response"),
334 (const char *)si);
335 error ();
336 }
337 else if (r[0] != 'H' || r[1] != 'T' || r[2] != 'T' || r[3] != 'P' || r[4] != '/'
338 || r[5] != '1' // http-major
339 || r[9] != '2') // response
340 {
341 slog (L_ERR, _("(%s): malformed or unexpected proxy response (%.12s)"),
342 (const char *)si, r);
343 error ();
344 }
345 else
346 state = ESTABLISHED;
347 }
348#endif
349 }
350}
351
352bool
353tcp_connection::send_packet (vpn_packet *pkt, int tos)
354{
355 last_activity = ev_now ();
356
357 if (state == IDLE)
358 {
359 // woaw, the first lost packet ;)
360 fd = socket (PF_INET, SOCK_STREAM, IPPROTO_TCP);
361
362 if (fd >= 0)
363 {
364 const sockinfo *csi = &si;
365
366#if ENABLE_HTTP_PROXY
367 sockinfo psi;
368
369 if (::conf.proxy_host && ::conf.proxy_port)
370 {
371 psi.set (::conf.proxy_host, ::conf.proxy_port, PROT_TCPv4);
372
373 if (psi.valid ())
374 {
375 csi = &psi;
376
377 proxy_req_len = asprintf (&proxy_req,
378 "CONNECT %s:%d HTTP/1.0\015\012"
379 "%s%s%s" // optional proxy-auth
380 "\015\012",
381 si.ntoa (),
382 ntohs (si.port),
383 ::conf.proxy_auth ? "Proxy-Authorization: Basic " : "",
384 ::conf.proxy_auth ? ::conf.proxy_auth : "",
385 ::conf.proxy_auth ? "\015\012" : "");
386
278 } 387 }
279 else 388 else
280 break; 389 slog (L_ERR, _("unable to resolve http proxy hostname '%s', trying direct"),
390 ::conf.proxy_host);
391 }
392#endif
281 } 393
282 else if (len < 0 && (errno == EINTR || errno == EAGAIN))
283 break;
284
285 error ();
286 break;
287 }
288 }
289}
290
291bool
292tcp_connection::send_packet (vpn_packet *pkt, int tos)
293{
294 last_activity = NOW;
295
296 if (state == IDLE)
297 {
298 // woaw, the first lost packet ;)
299 fd = socket (PF_INET, SOCK_STREAM, IPPROTO_TCP);
300
301 if (fd >= 0)
302 {
303 fcntl (fd, F_SETFL, O_NONBLOCK); 394 fcntl (fd, F_SETFL, O_NONBLOCK);
304 395
305 if (connect (fd, si.sav4 (), si.salenv4 ()) >= 0 396 if (connect (fd, csi->sav4 (), csi->salenv4 ()) >= 0
306 || errno == EINPROGRESS) 397 || errno == EINPROGRESS)
307 { 398 {
399 fcntl (fd, F_SETFL, O_NONBLOCK);
400 fcntl (fd, F_SETFD, FD_CLOEXEC);
401
308 state = CONNECTING; 402 state = CONNECTING;
309 start (fd, POLLOUT); 403 start (fd, EV_WRITE);
310 } 404 }
311 else 405 else
312 close (fd); 406 close (fd);
313 } 407 }
314 } 408 }
318 // right thing to do, not using tcp *is* the right thing to do. 412 // right thing to do, not using tcp *is* the right thing to do.
319 if (!w_pkt) 413 if (!w_pkt)
320 { 414 {
321 // how this maps to the underlying tcp packets we don't know 415 // how this maps to the underlying tcp packets we don't know
322 // and we don't care. at least we tried ;) 416 // and we don't care. at least we tried ;)
417#if defined(SOL_IP) && defined(IP_TOS)
418 if (tos != this->tos)
419 {
420 this->tos = tos;
323 setsockopt (fd, SOL_IP, IP_TOS, &tos, sizeof tos); 421 setsockopt (fd, SOL_IP, IP_TOS, &tos, sizeof tos);
422 }
423#endif
324 424
325 w_pkt = pkt; 425 w_pkt = pkt;
326 w_ofs = 0; 426 w_ofs = 0;
327 w_len = pkt->len + 2; // length + size header 427 w_len = pkt->len + 2; // length + size header
328 428
331 else 431 else
332 { 432 {
333 w_pkt = new vpn_packet; 433 w_pkt = new vpn_packet;
334 w_pkt->set (*pkt); 434 w_pkt->set (*pkt);
335 435
336 set (POLLIN | POLLOUT); 436 set (EV_READ | EV_WRITE);
337 } 437 }
338 } 438 }
339 } 439 }
340 440
341 return state != ERROR; 441 return state != ERROR;
342} 442}
343 443
444void tcp_connection::error ()
445{
446 stop ();
447
448 if (fd >= 0)
449 {
450 close (fd);
451 tos = -1;
452 fd = -1;
453 }
454
455 delete r_pkt; r_pkt = 0;
456 delete w_pkt; w_pkt = 0;
457#if ENABLE_HTTP_PROXY
458 free (proxy_req); proxy_req = 0;
459#endif
460
461 state = active ? IDLE : ERROR;
462}
463
344tcp_connection::tcp_connection (int fd_, const sockinfo &si_, vpn &v_) 464tcp_connection::tcp_connection (int fd_, const sockinfo &si_, vpn &v_)
345: v(v_), si(si_), io_watcher(this, &tcp_connection::tcpv4_ev) 465: v(v_), si(si_)
346{ 466{
467 set<tcp_connection, &tcp_connection::tcpv4_ev> (this);
468
347 last_activity = NOW; 469 last_activity = ev_now ();
348 r_pkt = 0; 470 r_pkt = 0;
349 w_pkt = 0; 471 w_pkt = 0;
472 tos = -1;
350 fd = fd_; 473 fd = fd_;
474#if ENABLE_HTTP_PROXY
475 proxy_req = 0;
476#endif
351 477
352 if (fd < 0) 478 if (fd < 0)
353 { 479 {
354 active = true; 480 active = true;
355 state = IDLE; 481 state = IDLE;
356 } 482 }
357 else 483 else
358 { 484 {
359 active = false; 485 active = false;
360 state = ESTABLISHED; 486 state = ESTABLISHED;
361 start (fd, POLLIN); 487 start (fd, EV_READ);
362 } 488 }
363} 489}
364 490
365tcp_connection::~tcp_connection () 491tcp_connection::~tcp_connection ()
366{ 492{

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines