ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/vpn_tcp.C
Revision: 1.15
Committed: Sat Jul 9 02:43:19 2005 UTC (18 years, 10 months ago) by pcg
Content type: text/plain
Branch: MAIN
Changes since 1.14: +1 -0 lines
Log Message:
*** empty log message ***

File Contents

# Content
1 /*
2 vpn_tcp.C -- handle the tcp part of the protocol.
3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de>
4
5 This file is part of GVPE.
6
7 GVPE is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 2 of the License, or
10 (at your option) any later version.
11
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
16
17 You should have received a copy of the GNU General Public License
18 along with gvpe; if not, write to the Free Software
19 Foundation, Inc. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20 */
21
22 #include "config.h"
23
24 #if ENABLE_TCP
25
26 // tcp processing is extremely ugly, since the vpe protocol is simply
27 // designed for unreliable datagram networks. tcp is implemented by
28 // multiplexing packets over tcp. errors are completely ignored, as we
29 // rely on the higher level protocol to time out and reconnect.
30
31 #include <cstring>
32
33 #include <sys/types.h>
34 #include <sys/socket.h>
35 #include <sys/wait.h>
36 #include <sys/uio.h>
37 #include <errno.h>
38 #include <time.h>
39 #include <unistd.h>
40 #include <fcntl.h>
41
42 #include <map>
43
44 #include "netcompat.h"
45
46 #include "vpn.h"
47
48 #if ENABLE_HTTP_PROXY
49 # include "conf.h"
50 #endif
51
52 struct tcp_connection;
53
54 struct lt_sockinfo
55 {
56 bool operator()(const sockinfo *a, const sockinfo *b) const
57 {
58 return *a < *b;
59 }
60 };
61
62 struct tcp_si_map : public map<const sockinfo *, tcp_connection *, lt_sockinfo> {
63 void cleaner_cb (time_watcher &w); time_watcher cleaner;
64
65 tcp_si_map ()
66 : cleaner(this, &tcp_si_map::cleaner_cb)
67 { }
68
69 } tcp_si;
70
71 struct tcp_connection : io_watcher {
72 tstamp last_activity;
73 const sockinfo si;
74 vpn &v;
75 bool active; // this connection has been actively established
76 enum { ERROR, IDLE, CONNECTING, CONNECTING_PROXY, ESTABLISHED } state;
77
78 vpn_packet *r_pkt;
79 u32 r_len, r_ofs;
80
81 vpn_packet *w_pkt;
82 u32 w_len, w_ofs;
83
84 #if ENABLE_HTTP_PROXY
85 char *proxy_req;
86 int proxy_req_len;
87 #endif
88
89 void tcpv4_ev (io_watcher &w, short revents);
90
91 bool send_packet (vpn_packet *pkt, int tos);
92 bool write_packet ();
93
94 void error (); // abort conenction && cleanup
95
96 operator tcp_si_map::value_type()
97 {
98 return tcp_si_map::value_type (&si, this);
99 }
100
101 tcp_connection (int fd_, const sockinfo &si_, vpn &v_);
102 ~tcp_connection ();
103 };
104
105 void tcp_si_map::cleaner_cb (time_watcher &w)
106 {
107 w.start (NOW + 600);
108
109 tstamp to = NOW - ::conf.keepalive - 30 - 60;
110
111 for (iterator i = begin (); i != end(); )
112 if (i->second->last_activity >= to)
113 ++i;
114 else
115 {
116 erase (i);
117 i = begin ();
118 }
119 }
120
121 void
122 vpn::tcpv4_ev (io_watcher &w, short revents)
123 {
124 if (revents & EVENT_READ)
125 {
126 struct sockaddr_in sa;
127 socklen_t sa_len = sizeof (sa);
128 int len;
129
130 int fd = accept (w.fd, (sockaddr *)&sa, &sa_len);
131
132 if (fd >= 0)
133 {
134 sockinfo si(sa, PROT_TCPv4);
135
136 slog (L_DEBUG, _("%s: accepted tcp connection"), (const char *)si);//D
137
138 fcntl (fd, F_SETFL, O_NONBLOCK);
139 fcntl (fd, F_SETFD, FD_CLOEXEC);
140
141 tcp_connection *i = new tcp_connection (fd, si, *this);
142 tcp_si.insert (*i);
143 }
144 }
145 }
146
147 bool
148 vpn::send_tcpv4_packet (vpn_packet *pkt, const sockinfo &si, int tos)
149 {
150 tcp_si_map::iterator info = tcp_si.find (&si);
151
152 tcp_connection *i;
153
154 if (info == tcp_si.end ())
155 {
156 i = new tcp_connection (-1, si, *this);
157 tcp_si.insert (*i);
158 }
159 else
160 i = info->second;
161
162 return i->send_packet (pkt, tos);
163 }
164
165 bool
166 tcp_connection::write_packet ()
167 {
168 ssize_t len;
169
170 if (w_ofs < 2)
171 {
172 u16 plen = htons (w_pkt->len);
173
174 iovec vec[2];
175 //TODO: char* is the right type? hardly...
176 vec[0].iov_base = (char *)((u8 *)&plen) + w_ofs;
177 vec[0].iov_len = 2 - w_ofs;
178 vec[1].iov_base = (char *)&((*w_pkt)[0]);
179 vec[1].iov_len = w_len - 2;
180
181 len = writev (fd, vec, 2);
182 }
183 else
184 len = write (fd, &((*w_pkt)[w_ofs - 2]), w_len);
185
186 if (len > 0)
187 {
188 w_ofs += len;
189 w_len -= len;
190
191 return w_len == 0;
192 }
193 else if (len < 0 && (errno == EAGAIN || errno == EINTR))
194 return false;
195 else
196 {
197 error ();
198 return false;
199 }
200 }
201
202 void
203 tcp_connection::tcpv4_ev (io_watcher &w, short revents)
204 {
205 last_activity = NOW;
206
207 if (revents & EVENT_WRITE)
208 {
209 if (state == CONNECTING)
210 {
211 state = ESTABLISHED;
212 set (EVENT_READ);
213 #if ENABLE_HTTP_PROXY
214 if (::conf.proxy_host && ::conf.proxy_port)
215 {
216 state = CONNECTING_PROXY;
217
218 if (write (fd, proxy_req, proxy_req_len) == 0)
219 {
220 error ();
221 return;
222 }
223
224 free (proxy_req); proxy_req = 0;
225 }
226 #endif
227 }
228 else if (state == ESTABLISHED)
229 {
230 if (w_pkt)
231 {
232 if (write_packet ())
233 {
234 delete w_pkt; w_pkt = 0;
235
236 set (EVENT_READ);
237 }
238 }
239 else
240 set (EVENT_READ);
241 }
242 else
243 set (EVENT_READ);
244 }
245
246 if (revents & EVENT_READ)
247 {
248 if (state == ESTABLISHED)
249 for (;;)
250 {
251 if (!r_pkt)
252 {
253 r_pkt = new vpn_packet;
254 r_ofs = 0;
255 r_len = 2; // header
256 }
257
258 ssize_t len = read (fd, &((*r_pkt)[r_ofs < 2 ? r_ofs : r_ofs - 2]), r_len);
259
260 if (len > 0)
261 {
262 r_len -= len;
263 r_ofs += len;
264
265 if (r_len == 0)
266 {
267 if (r_ofs == 2)
268 {
269 r_len = ntohs (*(u16 *)&((*r_pkt)[0]));
270 r_pkt->len = r_len;
271
272 if (r_len > 0 && r_len < MAXSIZE)
273 continue;
274 }
275 else
276 {
277 v.recv_vpn_packet (r_pkt, si);
278 delete r_pkt;
279 r_pkt = 0;
280
281 continue;
282 }
283 }
284 else
285 break;
286 }
287 else if (len < 0 && (errno == EINTR || errno == EAGAIN))
288 break;
289
290 // len == 0 <-> EOF
291 error ();
292 break;
293 }
294 #if ENABLE_HTTP_PROXY
295 else if (state == CONNECTING_PROXY)
296 {
297 fcntl (fd, F_SETFL, 0);
298 char r[1024];
299 int i;
300 bool emptyline = false;
301
302 // we do a blocking read of the response, to hell with it
303 for (i = 0; i < 1023; i++)
304 {
305 int l = read (fd, &r[i], 1);
306
307 if (l <= 0)
308 {
309 error ();
310 return;
311 }
312
313 if (r[i] == '\012')
314 {
315 if (emptyline)
316 break;
317 else
318 emptyline = true;
319 }
320 else if (r[i] != '\015')
321 emptyline = false;
322 }
323
324 fcntl (fd, F_SETFL, O_NONBLOCK);
325
326 if (i < 12)
327 {
328 slog (L_ERR, _("(%s): unable to do proxy-forwarding, short response"),
329 (const char *)si);
330 error ();
331 }
332 else if (r[0] != 'H' || r[1] != 'T' || r[2] != 'T' || r[3] != 'P' || r[4] != '/'
333 || r[5] != '1' // http-major
334 || r[9] != '2') // response
335 {
336 slog (L_ERR, _("(%s): malformed or unexpected proxy response (%.12s)"),
337 (const char *)si, r);
338 error ();
339 }
340 else
341 state = ESTABLISHED;
342 }
343 #endif
344 }
345 }
346
347 bool
348 tcp_connection::send_packet (vpn_packet *pkt, int tos)
349 {
350 last_activity = NOW;
351
352 if (state == IDLE)
353 {
354 // woaw, the first lost packet ;)
355 fd = socket (PF_INET, SOCK_STREAM, IPPROTO_TCP);
356
357 if (fd >= 0)
358 {
359 const sockinfo *csi = &si;
360
361 #if ENABLE_HTTP_PROXY
362 sockinfo psi;
363
364 if (::conf.proxy_host && ::conf.proxy_port)
365 {
366 psi.set (::conf.proxy_host, ::conf.proxy_port, PROT_TCPv4);
367
368 if (psi.valid ())
369 {
370 csi = &psi;
371
372 proxy_req_len = asprintf (&proxy_req,
373 "CONNECT %s:%d HTTP/1.0\015\012"
374 "%s%s%s" // optional proxy-auth
375 "\015\012",
376 si.ntoa (),
377 ntohs (si.port),
378 ::conf.proxy_auth ? "Proxy-Authorization: Basic " : "",
379 ::conf.proxy_auth ? ::conf.proxy_auth : "",
380 ::conf.proxy_auth ? "\015\012" : "");
381
382 }
383 else
384 slog (L_ERR, _("unable to resolve http proxy hostname '%s', trying direct"),
385 ::conf.proxy_host);
386 }
387 #endif
388
389 fcntl (fd, F_SETFL, O_NONBLOCK);
390
391 if (connect (fd, csi->sav4 (), csi->salenv4 ()) >= 0
392 || errno == EINPROGRESS)
393 {
394 state = CONNECTING;
395 start (fd, EVENT_WRITE);
396 }
397 else
398 close (fd);
399 }
400 }
401 else if (state == ESTABLISHED)
402 {
403 // drop packet if the tcp write buffer is full. this *is* the
404 // right thing to do, not using tcp *is* the right thing to do.
405 if (!w_pkt)
406 {
407 // how this maps to the underlying tcp packets we don't know
408 // and we don't care. at least we tried ;)
409 #if defined(SOL_IP) && defined(IP_TOS)
410 setsockopt (fd, SOL_IP, IP_TOS, &tos, sizeof tos);
411 #endif
412
413 w_pkt = pkt;
414 w_ofs = 0;
415 w_len = pkt->len + 2; // length + size header
416
417 if (write_packet ())
418 w_pkt = 0;
419 else
420 {
421 w_pkt = new vpn_packet;
422 w_pkt->set (*pkt);
423
424 set (EVENT_READ | EVENT_WRITE);
425 }
426 }
427 }
428
429 return state != ERROR;
430 }
431
432 void tcp_connection::error ()
433 {
434 if (fd >= 0)
435 {
436 close (fd);
437 fd = -1;
438 }
439
440 delete r_pkt; r_pkt = 0;
441 delete w_pkt; w_pkt = 0;
442 #if ENABLE_HTTP_PROXY
443 free (proxy_req); proxy_req = 0;
444 #endif
445
446 stop ();
447 state = active ? IDLE : ERROR;
448 }
449
450 tcp_connection::tcp_connection (int fd_, const sockinfo &si_, vpn &v_)
451 : v(v_), si(si_), io_watcher(this, &tcp_connection::tcpv4_ev)
452 {
453 if (!tcp_si.cleaner.active)
454 tcp_si.cleaner.start (0);
455
456 last_activity = NOW;
457 r_pkt = 0;
458 w_pkt = 0;
459 fd = fd_;
460 #if ENABLE_HTTP_PROXY
461 proxy_req = 0;
462 #endif
463
464 if (fd < 0)
465 {
466 active = true;
467 state = IDLE;
468 }
469 else
470 {
471 active = false;
472 state = ESTABLISHED;
473 start (fd, EVENT_READ);
474 }
475 }
476
477 tcp_connection::~tcp_connection ()
478 {
479 error ();
480 }
481
482 #endif
483