ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/vpn_tcp.C
(Generate patch)

Comparing gvpe/src/vpn_tcp.C (file contents):
Revision 1.3 by pcg, Sun Apr 6 20:01:53 2003 UTC vs.
Revision 1.27 by root, Tue Feb 8 23:11:36 2011 UTC

1/* 1/*
2 vpn_tcp.C -- handle the tcp part of the protocol. 2 vpn_tcp.C -- handle the tcp part of the protocol.
3 Copyright (C) 2003-2008 Marc Lehmann <gvpe@schmorp.de>
3 4
5 This file is part of GVPE.
6
4 This program is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify it
5 it under the terms of the GNU General Public License as published by 8 under the terms of the GNU General Public License as published by the
6 the Free Software Foundation; either version 2 of the License, or 9 Free Software Foundation; either version 3 of the License, or (at your
7 (at your option) any later version. 10 option) any later version.
8 11
9 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful, but
10 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General
12 GNU General Public License for more details. 15 Public License for more details.
13 16
14 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License along
15 along with this program; if not, write to the Free Software 18 with this program; if not, see <http://www.gnu.org/licenses/>.
16 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19
20 Additional permission under GNU GPL version 3 section 7
21
22 If you modify this Program, or any covered work, by linking or
23 combining it with the OpenSSL project's OpenSSL library (or a modified
24 version of that library), containing parts covered by the terms of the
25 OpenSSL or SSLeay licenses, the licensors of this Program grant you
26 additional permission to convey the resulting work. Corresponding
27 Source for a non-source form of such a combination shall include the
28 source code for the parts of OpenSSL used as well as that of the
29 covered work.
17*/ 30*/
18 31
19#include "config.h" 32#include "config.h"
20 33
21#if ENABLE_TCP 34#if ENABLE_TCP
22 35
23// tcp processing is extremely ugly, since the vpe protocol is simply 36// tcp processing is extremely ugly, since the gvpe protocol is simply
24// designed for unreliable datagram networks. tcp is implemented by 37// designed for unreliable datagram networks. tcp is implemented by
25// multiplexing packets over tcp. errors are completely ignored, as we 38// multiplexing packets over tcp. errors are completely ignored, as we
26// rely on the higher level protocol to time out and reconnect. 39// rely on the higher level layers to time out and reconnect.
27 40
28#include <cstring> 41#include <cstring>
29 42
30#include <sys/types.h> 43#include <sys/types.h>
31#include <sys/socket.h> 44#include <sys/socket.h>
32#include <sys/poll.h>
33#include <sys/wait.h> 45#include <sys/wait.h>
34#include <netinet/in.h>
35#include <sys/uio.h> 46#include <sys/uio.h>
36#include <arpa/inet.h>
37#include <errno.h> 47#include <errno.h>
38#include <time.h> 48#include <time.h>
39#include <unistd.h> 49#include <unistd.h>
50#include <fcntl.h>
40 51
41#include <map> 52#include <map>
42#include <unistd.h> 53
43#include <fcntl.h> 54#include "netcompat.h"
44#include <sys/poll.h>
45 55
46#include "vpn.h" 56#include "vpn.h"
57
58#if ENABLE_HTTP_PROXY
59# include "conf.h"
60#endif
47 61
48struct tcp_connection; 62struct tcp_connection;
49 63
50struct lt_sockinfo 64struct lt_sockinfo
51{ 65{
53 { 67 {
54 return *a < *b; 68 return *a < *b;
55 } 69 }
56}; 70};
57 71
58struct tcp_si_map : public map<const sockinfo *, tcp_connection *, lt_sockinfo> { 72struct tcp_si_map : public map<const sockinfo *, tcp_connection *, lt_sockinfo>
59 void cleaner_cb (time_watcher &w); time_watcher cleaner; 73{
74 inline void cleaner_cb (ev::timer &w, int revents); ev::timer cleaner;
60 75
61 tcp_si_map () 76 tcp_si_map ()
62 : cleaner(this, &tcp_si_map::cleaner_cb)
63 { 77 {
64 cleaner.start (0); 78 ev_default_loop (0);
79 cleaner.set<tcp_si_map, &tcp_si_map::cleaner_cb> (this);
80 cleaner.start (::conf.keepalive / 2, ::conf.keepalive / 2);
65 } 81 }
66} tcp_si; 82};
67 83
84static tcp_si_map tcp_si;
85
68struct tcp_connection : io_watcher { 86struct tcp_connection : ev::io
87{
88 int tos;
69 tstamp last_activity; 89 tstamp last_activity;
70 const sockinfo si; 90 const sockinfo si;
71 vpn &v; 91 vpn &v;
72 bool active; // this connection has been actively established 92 bool active; // this connection has been actively established
73 enum { ERROR, IDLE, CONNECTING, ESTABLISHED } state; 93 enum { ERROR, IDLE, CONNECTING, CONNECTING_PROXY, ESTABLISHED } state;
74 94
75 vpn_packet *r_pkt; 95 vpn_packet *r_pkt;
76 u32 r_len, r_ofs; 96 u32 r_len, r_ofs;
77 97
78 vpn_packet *w_pkt; 98 vpn_packet *w_pkt;
79 u32 w_len, w_ofs; 99 u32 w_len, w_ofs;
80 100
81 void tcpv4_ev (io_watcher &w, short revents); 101#if ENABLE_HTTP_PROXY
102 char *proxy_req;
103 int proxy_req_len;
104#endif
105
106 inline void tcpv4_ev (ev::io &w, int revents);
82 107
83 bool send_packet (vpn_packet *pkt, int tos); 108 bool send_packet (vpn_packet *pkt, int tos);
84 bool write_packet (); 109 bool write_packet ();
85 110
86 void error (); // abort conenction && cleanup 111 void error (); // abort conenction && cleanup
87 112
88 operator tcp_si_map::value_type() 113 operator tcp_si_map::value_type()
89 { 114 {
90 return tcp_si_map::value_type (&si, this); 115 return tcp_si_map::value_type (&si, this);
91 } 116 }
92 117
93 tcp_connection (int fd_, const sockinfo &si_, vpn &v_); 118 tcp_connection (int fd_, const sockinfo &si_, vpn &v_);
94 ~tcp_connection (); 119 ~tcp_connection ();
95}; 120};
96 121
97void tcp_si_map::cleaner_cb (time_watcher &w) 122void
123tcp_si_map::cleaner_cb (ev::timer &w, int revents)
98{ 124{
99 w.at = NOW + 600;
100 tstamp to = NOW - ::conf.keepalive - 30 - 60; 125 tstamp to = ev_now () - ::conf.keepalive - 30 - 60;
101 126
102 for (iterator i = begin (); i != end(); ) 127 for (iterator i = begin (); i != end(); )
103 if (i->second->last_activity >= to) 128 if (i->second->last_activity >= to)
104 ++i; 129 ++i;
105 else 130 else
106 { 131 {
132 delete i->second;
107 erase (i); 133 erase (i);
108 i = begin (); 134 i = begin ();
109 } 135 }
110} 136}
111 137
112void 138void
113vpn::tcpv4_ev (io_watcher &w, short revents) 139vpn::tcpv4_ev (ev::io &w, int revents)
114{ 140{
115 if (revents & (POLLIN | POLLERR)) 141 if (revents & EV_READ)
116 { 142 {
117 struct sockaddr_in sa; 143 struct sockaddr_in sa;
118 socklen_t sa_len = sizeof (sa); 144 socklen_t sa_len = sizeof (sa);
119 int len; 145 int len;
120 146
121 int fd = accept (w.fd, (sockaddr *)&sa, &sa_len); 147 int fd = accept (w.fd, (sockaddr *)&sa, &sa_len);
122 148
123 if (fd >= 0) 149 if (fd >= 0)
124 { 150 {
151 fcntl (fd, F_SETFL, O_NONBLOCK);
152 fcntl (fd, F_SETFD, FD_CLOEXEC);
153
125 sockinfo si(sa, PROT_TCPv4); 154 sockinfo si(sa, PROT_TCPv4);
126 155
127 slog (L_DEBUG, _("%s: accepted tcp connection"), (const char *)si);//D 156 slog (L_DEBUG, _("%s: accepted tcp connection"), (const char *)si);//D
128
129 fcntl (fd, F_SETFL, O_NONBLOCK);
130 157
131 tcp_connection *i = new tcp_connection (fd, si, *this); 158 tcp_connection *i = new tcp_connection (fd, si, *this);
132 tcp_si.insert (*i); 159 tcp_si.insert (*i);
133 } 160 }
134 } 161 }
150 i = info->second; 177 i = info->second;
151 178
152 return i->send_packet (pkt, tos); 179 return i->send_packet (pkt, tos);
153} 180}
154 181
155void tcp_connection::error ()
156{
157 if (fd >= 0)
158 {
159 close (fd);
160 fd = -1;
161 }
162
163 delete r_pkt; r_pkt = 0;
164 delete w_pkt; w_pkt = 0;
165
166 stop ();
167 state = active ? IDLE : ERROR;
168}
169
170bool 182bool
171tcp_connection::write_packet () 183tcp_connection::write_packet ()
172{ 184{
173 ssize_t len; 185 ssize_t len;
174 186
175 if (w_ofs < 2) 187 if (w_ofs < 2)
176 { 188 {
177 u16 plen = htons (w_pkt->len); 189 u16 plen = htons (w_pkt->len);
178 190
179 iovec vec[2]; 191 iovec vec[2];
192 //TODO: char* is the right type? hardly...
180 vec[0].iov_base = ((u8 *)&plen) + w_ofs; 193 vec[0].iov_base = (char *)((u8 *)&plen) + w_ofs;
181 vec[0].iov_len = 2 - w_ofs; 194 vec[0].iov_len = 2 - w_ofs;
182 vec[1].iov_base = &((*w_pkt)[0]); 195 vec[1].iov_base = (char *)&((*w_pkt)[0]);
183 vec[1].iov_len = w_len - 2; 196 vec[1].iov_len = w_len - 2;
184 197
185 len = writev (fd, vec, 2); 198 len = writev (fd, vec, 2);
186 } 199 }
187 else 200 else
202 return false; 215 return false;
203 } 216 }
204} 217}
205 218
206void 219void
207tcp_connection::tcpv4_ev (io_watcher &w, short revents) 220tcp_connection::tcpv4_ev (ev::io &w, int revents)
208{ 221{
209 last_activity = NOW; 222 last_activity = ev_now ();
210 223
211 if (revents & (POLLERR | POLLHUP)) 224 if (revents & EV_WRITE)
212 {
213 error ();
214 return;
215 }
216
217 if (revents & POLLOUT)
218 { 225 {
219 if (state == CONNECTING) 226 if (state == CONNECTING)
220 { 227 {
221 state = ESTABLISHED; 228 state = ESTABLISHED;
222 set (POLLIN); 229 set (EV_READ);
230#if ENABLE_HTTP_PROXY
231 if (::conf.proxy_host && ::conf.proxy_port)
232 {
233 state = CONNECTING_PROXY;
234
235 if (write (fd, proxy_req, proxy_req_len) == 0)
236 {
237 error ();
238 return;
239 }
240
241 free (proxy_req); proxy_req = 0;
242 }
243#endif
223 } 244 }
224 else if (state == ESTABLISHED) 245 else if (state == ESTABLISHED)
225 { 246 {
226 if (w_pkt) 247 if (w_pkt)
227 { 248 {
228 if (write_packet ()) 249 if (write_packet ())
229 { 250 {
230 delete w_pkt; w_pkt = 0; 251 delete w_pkt; w_pkt = 0;
231 252
232 set (POLLIN); 253 set (EV_READ);
233 } 254 }
234 } 255 }
235 else 256 else
236 set (POLLIN); 257 set (EV_READ);
237 } 258 }
238 else 259 else
239 set (POLLIN); 260 set (EV_READ);
240 }
241
242 if (revents & POLLIN)
243 { 261 }
262
263 if (revents & EV_READ)
264 {
265 if (state == ESTABLISHED)
244 for (;;) 266 for (;;)
267 {
268 if (!r_pkt)
269 {
270 r_pkt = new vpn_packet;
271 r_ofs = 0;
272 r_len = 2; // header
273 }
274
275 ssize_t len = read (fd, &((*r_pkt)[r_ofs < 2 ? r_ofs : r_ofs - 2]), r_len);
276
277 if (len > 0)
278 {
279 r_len -= len;
280 r_ofs += len;
281
282 if (r_len == 0)
283 {
284 if (r_ofs == 2)
285 {
286 r_len = ntohs (*(u16 *)&((*r_pkt)[0]));
287 r_pkt->len = r_len;
288
289 if (r_len > 0 && r_len < MAXSIZE)
290 continue;
291 }
292 else
293 {
294 v.recv_vpn_packet (r_pkt, si);
295 delete r_pkt;
296 r_pkt = 0;
297
298 continue;
299 }
300 }
301 else
302 break;
303 }
304 else if (len < 0 && (errno == EINTR || errno == EAGAIN))
305 break;
306
307 // len == 0 <-> EOF
308 error ();
309 break;
310 }
311#if ENABLE_HTTP_PROXY
312 else if (state == CONNECTING_PROXY)
245 { 313 {
246 if (!r_pkt) 314 fcntl (fd, F_SETFL, 0);
247 { 315 char r[1024];
248 r_pkt = new vpn_packet; 316 int i;
249 r_ofs = 0; 317 bool emptyline = false;
250 r_len = 2; // header 318
319 // we do a blocking read of the response, to hell with it
320 for (i = 0; i < 1023; i++)
251 } 321 {
322 int l = read (fd, &r[i], 1);
252 323
253 ssize_t len = read (fd, &((*r_pkt)[r_ofs < 2 ? r_ofs : r_ofs - 2]), r_len);
254
255 if (len > 0)
256 {
257 r_len -= len;
258 r_ofs += len;
259
260 if (r_len == 0) 324 if (l <= 0)
261 { 325 {
262 if (r_ofs == 2) 326 error ();
263 { 327 return;
264 r_len = ntohs (*(u16 *)&((*r_pkt)[0]));
265 r_pkt->len = r_len;
266
267 if (r_len > 0 && r_len < MAXSIZE)
268 continue;
269 } 328 }
329
330 if (r[i] == '\012')
331 {
332 if (emptyline)
333 break;
270 else 334 else
271 {
272 v.recv_vpn_packet (r_pkt, si);
273 delete r_pkt;
274 r_pkt = 0;
275
276 continue; 335 emptyline = true;
277 } 336 }
337 else if (r[i] != '\015')
338 emptyline = false;
339 }
340
341 fcntl (fd, F_SETFL, O_NONBLOCK);
342
343 if (i < 12)
344 {
345 slog (L_ERR, _("(%s): unable to do proxy-forwarding, short response"),
346 (const char *)si);
347 error ();
348 }
349 else if (r[0] != 'H' || r[1] != 'T' || r[2] != 'T' || r[3] != 'P' || r[4] != '/'
350 || r[5] != '1' // http-major
351 || r[9] != '2') // response
352 {
353 slog (L_ERR, _("(%s): malformed or unexpected proxy response (%.12s)"),
354 (const char *)si, r);
355 error ();
356 }
357 else
358 state = ESTABLISHED;
359 }
360#endif
361 }
362}
363
364bool
365tcp_connection::send_packet (vpn_packet *pkt, int tos)
366{
367 last_activity = ev_now ();
368
369 if (state == IDLE)
370 {
371 // woaw, the first lost packet ;)
372 fd = socket (PF_INET, SOCK_STREAM, IPPROTO_TCP);
373
374 if (fd >= 0)
375 {
376 const sockinfo *csi = &si;
377
378#if ENABLE_HTTP_PROXY
379 sockinfo psi;
380
381 if (::conf.proxy_host && ::conf.proxy_port)
382 {
383 psi.set (::conf.proxy_host, ::conf.proxy_port, PROT_TCPv4);
384
385 if (psi.valid ())
386 {
387 csi = &psi;
388
389 proxy_req_len = asprintf (&proxy_req,
390 "CONNECT %s:%d HTTP/1.0\015\012"
391 "%s%s%s" // optional proxy-auth
392 "\015\012",
393 si.ntoa (),
394 ntohs (si.port),
395 ::conf.proxy_auth ? "Proxy-Authorization: Basic " : "",
396 ::conf.proxy_auth ? ::conf.proxy_auth : "",
397 ::conf.proxy_auth ? "\015\012" : "");
398
278 } 399 }
279 else 400 else
280 break; 401 slog (L_ERR, _("unable to resolve http proxy hostname '%s', trying direct"),
402 ::conf.proxy_host);
403 }
404#endif
281 } 405
282 else if (len < 0 && (errno == EINTR || errno == EAGAIN))
283 break;
284
285 error ();
286 break;
287 }
288 }
289}
290
291bool
292tcp_connection::send_packet (vpn_packet *pkt, int tos)
293{
294 last_activity = NOW;
295
296 if (state == IDLE)
297 {
298 // woaw, the first lost packet ;)
299 fd = socket (PF_INET, SOCK_STREAM, IPPROTO_TCP);
300
301 if (fd >= 0)
302 {
303 fcntl (fd, F_SETFL, O_NONBLOCK); 406 fcntl (fd, F_SETFL, O_NONBLOCK);
304 407
305 if (connect (fd, si.sav4 (), si.salenv4 ()) >= 0 408 if (connect (fd, csi->sav4 (), csi->salenv4 ()) >= 0
306 || errno == EINPROGRESS) 409 || errno == EINPROGRESS)
307 { 410 {
411 fcntl (fd, F_SETFL, O_NONBLOCK);
412 fcntl (fd, F_SETFD, FD_CLOEXEC);
413
308 state = CONNECTING; 414 state = CONNECTING;
309 start (fd, POLLOUT); 415 start (fd, EV_WRITE);
310 } 416 }
311 else 417 else
312 close (fd); 418 close (fd);
313 } 419 }
314 } 420 }
318 // right thing to do, not using tcp *is* the right thing to do. 424 // right thing to do, not using tcp *is* the right thing to do.
319 if (!w_pkt) 425 if (!w_pkt)
320 { 426 {
321 // how this maps to the underlying tcp packets we don't know 427 // how this maps to the underlying tcp packets we don't know
322 // and we don't care. at least we tried ;) 428 // and we don't care. at least we tried ;)
429#if defined(SOL_IP) && defined(IP_TOS)
430 if (tos != this->tos)
431 {
432 this->tos = tos;
323 setsockopt (fd, SOL_IP, IP_TOS, &tos, sizeof tos); 433 setsockopt (fd, SOL_IP, IP_TOS, &tos, sizeof tos);
434 }
435#endif
324 436
325 w_pkt = pkt; 437 w_pkt = pkt;
326 w_ofs = 0; 438 w_ofs = 0;
327 w_len = pkt->len + 2; // length + size header 439 w_len = pkt->len + 2; // length + size header
328 440
331 else 443 else
332 { 444 {
333 w_pkt = new vpn_packet; 445 w_pkt = new vpn_packet;
334 w_pkt->set (*pkt); 446 w_pkt->set (*pkt);
335 447
336 set (POLLIN | POLLOUT); 448 set (EV_READ | EV_WRITE);
337 } 449 }
338 } 450 }
339 } 451 }
340 452
341 return state != ERROR; 453 return state != ERROR;
342} 454}
343 455
456void
457tcp_connection::error ()
458{
459 stop ();
460
461 if (fd >= 0)
462 {
463 close (fd);
464 tos = -1;
465 fd = -1;
466 }
467
468 delete r_pkt; r_pkt = 0;
469 delete w_pkt; w_pkt = 0;
470#if ENABLE_HTTP_PROXY
471 free (proxy_req); proxy_req = 0;
472#endif
473
474 state = active ? IDLE : ERROR;
475}
476
344tcp_connection::tcp_connection (int fd_, const sockinfo &si_, vpn &v_) 477tcp_connection::tcp_connection (int fd_, const sockinfo &si_, vpn &v_)
345: v(v_), si(si_), io_watcher(this, &tcp_connection::tcpv4_ev) 478: v(v_), si(si_)
346{ 479{
480 set<tcp_connection, &tcp_connection::tcpv4_ev> (this);
481
347 last_activity = NOW; 482 last_activity = ev_now ();
348 r_pkt = 0; 483 r_pkt = 0;
349 w_pkt = 0; 484 w_pkt = 0;
485 tos = -1;
350 fd = fd_; 486 fd = fd_;
487#if ENABLE_HTTP_PROXY
488 proxy_req = 0;
489#endif
351 490
352 if (fd < 0) 491 if (fd < 0)
353 { 492 {
354 active = true; 493 active = true;
355 state = IDLE; 494 state = IDLE;
356 } 495 }
357 else 496 else
358 { 497 {
359 active = false; 498 active = false;
360 state = ESTABLISHED; 499 state = ESTABLISHED;
361 start (fd, POLLIN); 500 start (fd, EV_READ);
362 } 501 }
363} 502}
364 503
365tcp_connection::~tcp_connection () 504tcp_connection::~tcp_connection ()
366{ 505{

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines