+defcfg = '''
+[DEFAULT]
+max_batch_down = 65536
+max_queue_time = 10
+max_request_time = 54
+
+[virtual]
+mtu = 1500
+# network
+# [host]
+# [relay]
+
+[server]
+ipif = userv root ipif %(host)s,%(relay)s,%(mtu)s,slip %(network)s
+addrs = 127.0.0.1 ::1
+port = 80
+
+[limits]
+max_batch_down = 262144
+max_queue_time = 121
+max_request_time = 121
+'''
+
+#---------- "router" ----------
+
+def route(packet, daddr):
+ try: client = clients[daddr]
+ except KeyError: dclient = None
+ if dclient is not None:
+ dclient.queue_outbound(packet)
+ elif daddr == host or daddr not in network:
+ queue_inbound(packet)
+ elif daddr == relay:
+ log_discard(packet, saddr, daddr, 'relay')
+ else:
+ log_discard(packet, saddr, daddr, 'no client')
+
+def log_discard(packet, saddr, daddr, why):
+ syslog.syslog(syslog.LOG_DEBUG,
+ 'discarded packet %s -> %s (%s)' % (saddr, daddr, why))
+
+#---------- ipif (slip subprocess) ----------
+
+class IpifProcessProtocol(twisted.internet.protocol.ProcessProtocol):
+ def __init__(self):
+ self._buffer = b''
+ def connectionMade(self): pass
+ def outReceived(self, data):
+ buffer += data
+ packets = slip_decode(buffer)
+ buffer = packets.pop()
+ for packet in packets:
+ (saddr, daddr) = packet_addrs(packet)
+ route(packet, daddr)
+ def processEnded(self, status):
+ status.raiseException()
+
+def start_ipif():
+ global ipif
+ ipif = IpifProcessProtocol()
+ reactor.spawnProcess(ipif,
+ '/bin/sh',['sh','-c', ipif_command],
+ childFDs={0:'w', 1:'r', 2:2})
+
+def queue_inbound(packet):
+ ipif.transport.write(slip_delimiter)
+ ipif.transport.write(slip_encode(packet))
+ ipif.transport.write(slip_delimiter)
+
+#---------- client ----------
+
+class Client():
+ def __init__(self, ip, cs):
+ # instance data members
+ self._ip = ip
+ self._cs = cs
+ self.pw = cfg.get(cs, 'password')
+ self._rq = collections.deque() # requests
+ self._pq = collections.deque() # packets
+ # plus from config:
+ # .max_batch_down
+ # .max_queue_time
+ # .max_request_time
+ for k in ('max_batch_down','max_queue_time','max_request_time'):
+ req = cfg.getint(cs, k)
+ limit = cfg.getint('limits',k)
+ self.__dict__[k] = min(req, limit)
+
+ def process_arriving_data(self, d):
+ for packet in slip_decode(d):
+ (saddr, daddr) = packet_addrs(packet)
+ if saddr != self._ip:
+ raise ValueError('wrong source address %s' % saddr)
+ route(packet, daddr)
+
+ def _req_cancel(self, request):
+ request.finish()
+
+ def _req_error(self, err, request):
+ self._req_cancel(request)
+
+ def queue_outbound(self, packet):
+ self._pq.append((time.monotonic(), packet))
+
+ def http_request(self, request):
+ request.setHeader('Content-Type','application/octet-stream')
+ reactor.callLater(self.max_request_time, self._req_cancel, request)
+ request.notifyFinish().addErrback(self._req_error, request)
+ self._rq.append(request)
+ self._check_outbound()
+
+ def _check_outbound(self):
+ while True:
+ try: request = self._rq[0]
+ except IndexError: request = None
+ if request and request.finished:
+ self._rq.popleft()
+ continue
+
+ # now request is an unfinished request, or None
+ try: (queuetime, packet) = self._pq[0]
+ except IndexError:
+ # no packets, oh well
+ break
+
+ age = time.monotonic() - queuetime
+ if age > self.max_queue_time:
+ self._pq.popleft()
+ continue
+
+ if request is None:
+ # no request
+ break
+
+ # request, and also some non-expired packets
+ while True:
+ try: (dummy, packet) = self._pq[0]
+ except IndexError: break
+
+ encoded = slip_encode(packet)
+
+ if request.sentLength > 0:
+ if (request.sentLength + len(slip_delimiter)
+ + len(encoded) > self.max_batch_down):
+ break
+ request.write(slip_delimiter)
+
+ request.write(encoded)
+ self._pq.popLeft()
+
+ assert(request.sentLength)
+ self._rq.popLeft()
+ request.finish()
+ # round again, looking for more to do
+
+class IphttpResource(twisted.web.resource.Resource):
+ def render_POST(self, request):
+ # find client, update config, etc.
+ ci = ipaddr(request.args['i'])
+ c = clients[ci]
+ pw = request.args['pw']
+ if pw != c.pw: raise ValueError('bad password')
+
+ # update config
+ for r, w in (('mbd', 'max_batch_down'),
+ ('mqt', 'max_queue_time'),
+ ('mrt', 'max_request_time')):
+ try: v = request.args[r]
+ except KeyError: continue
+ v = int(v)
+ c.__dict__[w] = v
+
+ try: d = request.args['d']
+ except KeyError: d = ''
+
+ c.process_arriving_data(d)
+ c.new_request(request)
+
+def start_http():
+ resource = IphttpResource()
+ sitefactory = twisted.web.server.Site(resource)
+ for addrspec in cfg.get('server','addrs').split():
+ try:
+ addr = ipaddress.IPv4Address(addrspec)
+ endpointfactory = twisted.internet.endpoints.TCP4ServerEndpoint
+ except AddressValueError:
+ addr = ipaddress.IPv6Address(addrspec)
+ endpointfactory = twisted.internet.endpoints.TCP6ServerEndpoint
+ ep = endpointfactory(reactor, cfg.getint('server','port'), addr)
+ ep.listen(sitefactory)
+
+#---------- config and setup ----------
+