b23ef7bfb676b6645dea0673d72fb423b1ff4fa4
3 * Communication with the peer
5 * (c) 2001 Straylight/Edgeware
8 /*----- Licensing notice --------------------------------------------------*
10 * This file is part of Trivial IP Encryption (TrIPE).
12 * TrIPE is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU General Public License as published by
14 * the Free Software Foundation; either version 2 of the License, or
15 * (at your option) any later version.
17 * TrIPE is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU General Public License for more details.
22 * You should have received a copy of the GNU General Public License
23 * along with TrIPE; if not, write to the Free Software Foundation,
24 * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
27 /*----- Header files ------------------------------------------------------*/
31 /*----- Static variables --------------------------------------------------*/
33 static sym_table byname
;
34 static addrmap byaddr
;
37 /*----- Tunnel table ------------------------------------------------------*/
39 const tunnel_ops
*tunnels
[] = {
53 /*----- Main code ---------------------------------------------------------*/
55 /* --- @p_pingtype@ --- *
57 * Arguments: @unsigned msg@ = message type
59 * Returns: String to describe the message.
62 static const char *p_pingtype(unsigned msg
)
64 switch (msg
& MSG_TYPEMASK
) {
67 return "transport-ping";
70 return "encrypted-ping";
76 /* --- @p_ponged@ --- *
78 * Arguments: @peer *p@ = peer packet arrived from
79 * @unsigned msg@ = message type
80 * @buf *b@ = buffer containing payload
84 * Use: Processes a ping response.
87 static void p_ponged(peer
*p
, unsigned msg
, buf
*b
)
94 trace(T_PEER
, "peer: received %s reply from %s",
95 p_pingtype(msg
), p
->spec
.name
);
96 trace_block(T_PACKET
, "peer: ping contents", BBASE(b
), BSZ(b
));
99 if (buf_getu32(b
, &id
) ||
100 (magic
= buf_get(b
, sizeof(pg
->magic
))) == 0 ||
102 a_warn("PEER", "?PEER", p
, "malformed-%s", p_pingtype(msg
), A_END
);
106 for (pg
= p
->pings
; pg
; pg
= pg
->next
) {
112 "unexpected-%s", p_pingtype(msg
),
113 "0x%08lx", (unsigned long)id
,
118 if (memcmp(magic
, pg
->magic
, sizeof(pg
->magic
)) != 0) {
119 a_warn("PEER", "?PEER", p
, "corrupt-%s", p_pingtype(msg
), A_END
);
122 p_pingdone(pg
, PING_OK
);
125 /* --- @p_read@ --- *
127 * Arguments: @int fd@ = file descriptor to read from
128 * @unsigned mode@ = what happened
129 * @void *v@ = an uninteresting pointer
133 * Use: Reads a packet from somewhere.
136 static void p_read(int fd
, unsigned mode
, void *v
)
145 /* --- Read the data --- */
149 n
= recvfrom(fd
, buf_i
, sizeof(buf_i
), 0, &a
.sa
, &sz
);
151 a_warn("PEER", "-", "socket-read-error", "?ERRNO", A_END
);
155 /* --- If the packet is a greeting, don't check peers --- */
157 if (n
&& buf_i
[0] == (MSG_MISC
| MISC_GREET
)) {
159 trace(T_PEER
, "peer: greeting received from INET %s %u",
160 inet_ntoa(a
.sin
.sin_addr
),
161 (unsigned)ntohs(a
.sin
.sin_port
));
162 trace_block(T_PACKET
, "peer: greeting contents", buf_i
, n
);
164 buf_init(&b
, buf_i
, n
);
166 if (c_check(&b
) || BLEFT(&b
)) {
167 a_warn("PEER", "-", "invalid-greeting", A_END
);
171 "?B64", buf_i
+ 1, (size_t)(n
- 1),
177 /* --- Find the appropriate peer --- */
179 if ((p
= p_findbyaddr(&a
)) == 0) {
180 a_warn("PEER", "-", "unexpected-source", "?ADDR", &a
, A_END
);
185 trace(T_PEER
, "peer: packet received from `%s'", p
->spec
.name
);
186 trace_block(T_PACKET
, "peer: packet contents", buf_i
, n
);
189 /* --- Pick the packet apart --- */
191 p
->st
.t_last
= time(0);
194 buf_init(&b
, buf_i
, n
);
195 if ((ch
= buf_getbyte(&b
)) < 0) {
196 a_warn("PEER", "?PEER", p
, "bad-packet", "no-type", A_END
);
199 switch (ch
& MSG_CATMASK
) {
201 if (ch
& MSG_TYPEMASK
) {
205 "unknown-type", "0x%02x", ch
,
210 buf_init(&bb
, buf_o
, sizeof(buf_o
));
211 if (ksl_decrypt(&p
->ks
, MSG_PACKET
, &b
, &bb
)) {
213 a_warn("PEER", "?PEER", p
, "decrypt-failed", A_END
);
218 p
->st
.sz_ipin
+= BSZ(&b
);
219 p
->t
->ops
->inject(p
->t
, &bb
);
222 a_warn("PEER", "?PEER", p
, "packet-build-failed", A_END
);
226 kx_message(&p
->kx
, ch
& MSG_TYPEMASK
, &b
);
229 switch (ch
& MSG_TYPEMASK
) {
231 T( trace(T_PEER
, "peer: received NOP packet"); )
234 buf_put(p_txstart(p
, MSG_MISC
| MISC_PONG
), BCUR(&b
), BLEFT(&b
));
238 p_ponged(p
, MISC_PONG
, &b
);
241 buf_init(&bb
, buf_t
, sizeof(buf_t
));
242 if (ksl_decrypt(&p
->ks
, ch
, &b
, &bb
)) {
244 a_warn("PEER", "?PEER", p
, "decrypt-failed", A_END
);
249 if (ksl_encrypt(&p
->ks
, MSG_MISC
| MISC_EPONG
, &bb
,
250 p_txstart(p
, MSG_MISC
| MISC_EPONG
)))
256 buf_init(&bb
, buf_t
, sizeof(buf_t
));
257 if (ksl_decrypt(&p
->ks
, ch
, &b
, &bb
)) {
259 a_warn("PEER", "?PEER", p
, "decrypt-failed", A_END
);
264 p_ponged(p
, MISC_EPONG
, &bb
);
274 "unknown-category" "0x%02x", ch
,
280 /* --- @p_txstart@ --- *
282 * Arguments: @peer *p@ = pointer to peer block
283 * @unsigned msg@ = message type code
285 * Returns: A pointer to a buffer to write to.
287 * Use: Starts sending to a peer. Only one send can happen at a
291 buf
*p_txstart(peer
*p
, unsigned msg
)
293 buf_init(&p
->b
, buf_o
, sizeof(buf_o
));
294 buf_putbyte(&p
->b
, msg
);
298 /* --- @p_txend@ --- *
300 * Arguments: @peer *p@ = pointer to peer block
304 * Use: Sends a packet to the peer.
307 static void p_setkatimer(peer
*);
309 static int p_dotxend(peer
*p
)
312 a_warn("PEER", "?PEER", p
, "packet-build-failed", A_END
);
315 IF_TRACING(T_PEER
, trace_block(T_PACKET
, "peer: sending packet",
316 BBASE(&p
->b
), BLEN(&p
->b
)); )
317 if (sendto(sock
.fd
, BBASE(&p
->b
), BLEN(&p
->b
),
318 0, &p
->spec
.sa
.sa
, p
->spec
.sasz
) < 0) {
319 a_warn("PEER", "?PEER", p
, "socket-write-error", "?ERRNO", A_END
);
323 p
->st
.sz_out
+= BLEN(&p
->b
);
328 void p_txend(peer
*p
)
330 if (p_dotxend(p
) && p
->spec
.t_ka
) {
331 sel_rmtimer(&p
->tka
);
336 /* --- @p_pingwrite@ --- *
338 * Arguments: @ping *p@ = ping structure
339 * @buf *b@ = buffer to write in
343 * Use: Fills in a ping structure and writes the packet payload.
346 static void p_pingwrite(ping
*p
, buf
*b
)
348 static uint32 seq
= 0;
351 GR_FILL(&rand_global
, p
->magic
, sizeof(p
->magic
));
352 buf_putu32(b
, p
->id
);
353 buf_put(b
, p
->magic
, sizeof(p
->magic
));
356 /* --- @p_pingdone@ --- *
358 * Arguments: @ping *p@ = ping structure
359 * @int rc@ = return code to pass on
363 * Use: Disposes of a ping structure, maybe sending a notification.
366 void p_pingdone(ping
*p
, int rc
)
368 if (p
->prev
) p
->prev
->next
= p
->next
;
369 else p
->p
->pings
= p
->next
;
370 if (p
->next
) p
->next
->prev
= p
->prev
;
371 if (rc
!= PING_TIMEOUT
) sel_rmtimer(&p
->t
);
372 T( trace(T_PEER
, "peer: ping 0x%08lx done (rc = %d)",
373 (unsigned long)p
->id
, rc
); )
374 if (rc
>= 0) p
->func(rc
, p
->arg
);
377 /* --- @p_pingtimeout@ --- *
379 * Arguments: @struct timeval *now@ = the time now
380 * @void *pv@ = pointer to ping block
384 * Use: Called when a ping times out.
387 static void p_pingtimeout(struct timeval
*now
, void *pv
)
391 T( trace(T_PEER
, "peer: ping 0x%08lx timed out", (unsigned long)p
->id
); )
392 p_pingdone(p
, PING_TIMEOUT
);
395 /* --- @p_pingsend@ --- *
397 * Arguments: @peer *p@ = destination peer
398 * @ping *pg@ = structure to fill in
399 * @unsigned type@ = message type
400 * @unsigned long timeout@ = how long to wait before giving up
401 * @void (*func)(int, void *)@ = callback function
402 * @void *arg@ = argument for callback
404 * Returns: Zero if successful, nonzero if it failed.
406 * Use: Sends a ping to a peer. Call @func@ with a nonzero argument
407 * if we get an answer within the timeout, or zero if no answer.
410 int p_pingsend(peer
*p
, ping
*pg
, unsigned type
,
411 unsigned long timeout
,
412 void (*func
)(int, void *), void *arg
)
420 b
= p_txstart(p
, MSG_MISC
| MISC_PING
);
425 pg
->msg
= MISC_EPONG
;
426 b
= p_txstart(p
, MSG_MISC
| MISC_EPING
);
427 buf_init(&bb
, buf_t
, sizeof(buf_t
));
428 p_pingwrite(pg
, &bb
);
430 if (ksl_encrypt(&p
->ks
, MSG_MISC
| MISC_EPING
, &bb
, b
))
446 if (p
->pings
) p
->pings
->prev
= pg
;
448 gettimeofday(&tv
, 0);
449 tv
.tv_sec
+= timeout
;
450 sel_addtimer(&sel
, &pg
->t
, &tv
, p_pingtimeout
, pg
);
451 T( trace(T_PEER
, "peer: send %s 0x%08lx to %s",
452 p_pingtype(type
), (unsigned long)pg
->id
, p
->spec
.name
); )
456 /* --- @p_greet@ --- *
458 * Arguments: @peer *p@ = peer to send to
459 * @const void *c@ = pointer to challenge
460 * @size_t sz@ = size of challenge
464 * Use: Sends a greeting packet.
467 void p_greet(peer
*p
, const void *c
, size_t sz
)
469 buf
*b
= p_txstart(p
, MSG_MISC
| MISC_GREET
);
476 * Arguments: @peer *p@ = pointer to peer block
477 * @buf *b@ = buffer containing incoming packet
481 * Use: Handles a packet which needs to be sent to a peer.
484 void p_tun(peer
*p
, buf
*b
)
486 buf
*bb
= p_txstart(p
, MSG_PACKET
);
489 if (ksl_encrypt(&p
->ks
, MSG_PACKET
, b
, bb
))
491 if (BOK(bb
) && BLEN(bb
)) {
493 p
->st
.sz_ipout
+= BLEN(bb
);
498 /* --- @p_keyreload@ --- *
504 * Use: Forces a check of the daemon's keyring files.
507 void p_keyreload(void)
510 FOREACH_PEER(p
, { kx_newkeys(&p
->kx
); });
513 /* --- @p_interval@ --- *
519 * Use: Called periodically to do tidying.
522 void p_interval(void)
525 FOREACH_PEER(p
, { ksl_prune(&p
->ks
); });
528 /* --- @p_stats@ --- *
530 * Arguments: @peer *p@ = pointer to a peer block
532 * Returns: A pointer to the peer's statistics.
535 stats
*p_stats(peer
*p
) { return (&p
->st
); }
537 /* --- @p_ifname@ --- *
539 * Arguments: @peer *p@ = pointer to a peer block
541 * Returns: A pointer to the peer's interface name.
544 const char *p_ifname(peer
*p
) { return (p
->ifname
); }
546 /* --- @p_setifname@ --- *
548 * Arguments: @peer *p@ = pointer to a peer block
549 * @const char *name@ = pointer to the new name
553 * Use: Changes the name held for a peer's interface.
556 void p_setifname(peer
*p
, const char *name
)
559 p
->ifname
= xstrdup(name
);
560 if (p
->spec
.tops
->setifname
)
561 p
->spec
.tops
->setifname(p
->t
, name
);
564 /* --- @p_addr@ --- *
566 * Arguments: @peer *p@ = pointer to a peer block
568 * Returns: A pointer to the peer's address.
571 const addr
*p_addr(peer
*p
) { return (&p
->spec
.sa
); }
573 /* --- @p_init@ --- *
575 * Arguments: @struct in_addr addr@ = address to bind to
576 * @unsigned port@ = port number to listen to
580 * Use: Initializes the peer system; creates the socket.
583 void p_init(struct in_addr addr
, unsigned port
)
586 struct sockaddr_in sin
;
589 /* --- Note on socket buffer sizes --- *
591 * For some bizarre reason, Linux 2.2 (at least) doubles the socket buffer
592 * sizes I pass to @setsockopt@. I'm not putting special-case code here
593 * for Linux: BSD (at least TCPv2) does what I tell it rather than second-
597 if ((fd
= socket(PF_INET
, SOCK_DGRAM
, 0)) < 0)
598 die(EXIT_FAILURE
, "socket creation failed: %s", strerror(errno
));
600 sin
.sin_family
= AF_INET
;
602 sin
.sin_port
= htons(port
);
603 if (bind(fd
, (struct sockaddr
*)&sin
, sizeof(sin
)))
604 die(EXIT_FAILURE
, "bind failed: %s", strerror(errno
));
605 if (setsockopt(fd
, SOL_SOCKET
, SO_RCVBUF
, &len
, sizeof(len
)) ||
606 setsockopt(fd
, SOL_SOCKET
, SO_SNDBUF
, &len
, sizeof(len
))) {
607 die(EXIT_FAILURE
, "failed to set socket buffer sizes: %s",
610 fdflags(fd
, O_NONBLOCK
, O_NONBLOCK
, FD_CLOEXEC
, FD_CLOEXEC
);
611 sel_initfile(&sel
, &sock
, fd
, SEL_READ
, p_read
, 0);
613 T( trace(T_PEER
, "peer: created socket"); )
619 /* --- @p_port@ --- *
623 * Returns: Port number used for socket.
626 unsigned p_port(void)
629 size_t sz
= sizeof(addr
);
631 if (getsockname(sock
.fd
, &a
.sa
, &sz
))
632 die(EXIT_FAILURE
, "couldn't read port number: %s", strerror(errno
));
633 assert(a
.sa
.sa_family
== AF_INET
);
634 return (ntohs(a
.sin
.sin_port
));
637 /* --- @p_keepalive@ --- *
639 * Arguments: @struct timeval *now@ = the current time
640 * @void *pv@ = peer to wake up
644 * Use: Sends a keepalive ping message to its peer.
647 static void p_keepalive(struct timeval
*now
, void *pv
)
650 p_txstart(p
, MSG_MISC
| MISC_NOP
); p_dotxend(p
);
651 T( trace(T_PEER
, "peer: sent keepalive to %s", p
->spec
.name
); )
655 /* --- @p_setkatimer@ --- *
657 * Arguments: @peer *p@ = peer to set
661 * Use: Resets the keepalive timer thing.
664 static void p_setkatimer(peer
*p
)
670 gettimeofday(&tv
, 0);
671 tv
.tv_sec
+= p
->spec
.t_ka
;
672 sel_addtimer(&sel
, &p
->tka
, &tv
, p_keepalive
, p
);
675 /* --- @p_create@ --- *
677 * Arguments: @peerspec *spec@ = information about this peer
679 * Returns: Pointer to the peer block, or null if it failed.
681 * Use: Creates a new named peer block. No peer is actually attached
685 peer
*p_create(peerspec
*spec
)
687 peer
*p
= CREATE(peer
);
690 p
->byname
= sym_find(&byname
, spec
->name
, -1, sizeof(peer_byname
), &f
);
692 p
->byaddr
= am_find(&byaddr
, &spec
->sa
, sizeof(peer_byaddr
), &f
);
694 p
->byname
->p
= p
->byaddr
->p
= p
;
696 T( trace(T_PEER
, "peer: creating new peer `%s'", spec
->name
); )
698 p
->spec
.name
= (/*unconst*/ char *)SYM_NAME(p
->byname
);
702 memset(&p
->st
, 0, sizeof(stats
));
703 p
->st
.t_start
= time(0);
704 if ((p
->t
= spec
->tops
->create(p
, &p
->ifname
)) == 0)
707 if (kx_init(&p
->kx
, p
, &p
->ks
, p
->spec
.kxf
))
712 "?ADDR", &p
->spec
.sa
,
714 if (!(p
->spec
.kxf
& KXF_CORK
)) {
715 a_notify("KXSTART", "?PEER", p
, A_END
);
716 /* Couldn't tell anyone before */
722 sel_rmtimer(&p
->tka
);
724 p
->t
->ops
->destroy(p
->t
);
726 am_remove(&byaddr
, p
->byaddr
);
728 sym_remove(&byname
, p
->byname
);
734 /* --- @p_name@ --- *
736 * Arguments: @peer *p@ = pointer to a peer block
738 * Returns: A pointer to the peer's name.
741 const char *p_name(peer
*p
) { return (p
->spec
.name
); }
743 /* --- @p_spec@ --- *
745 * Arguments: @peer *p@ = pointer to a peer block
747 * Returns: Pointer to the peer's specification
750 const peerspec
*p_spec(peer
*p
) { return (&p
->spec
); }
752 /* --- @p_findbyaddr@ --- *
754 * Arguments: @const addr *a@ = address to look up
756 * Returns: Pointer to the peer block, or null if not found.
758 * Use: Finds a peer by address.
761 peer
*p_findbyaddr(const addr
*a
)
765 if ((pa
= am_find(&byaddr
, a
, 0, 0)) != 0)
770 /* --- @p_find@ --- *
772 * Arguments: @const char *name@ = name to look up
774 * Returns: Pointer to the peer block, or null if not found.
776 * Use: Finds a peer by name.
779 peer
*p_find(const char *name
)
783 if ((pn
= sym_find(&byname
, name
, -1, 0, 0)) != 0)
788 /* --- @p_destroy@ --- *
790 * Arguments: @peer *p@ = pointer to a peer
794 * Use: Destroys a peer.
797 void p_destroy(peer
*p
)
801 T( trace(T_PEER
, "peer: destroying peer `%s'", p
->spec
.name
); )
802 a_notify("KILL", "%s", p
->spec
.name
, A_END
);
807 p
->t
->ops
->destroy(p
->t
);
809 sel_rmtimer(&p
->tka
);
810 for (pg
= p
->pings
; pg
; pg
= ppg
) {
812 p_pingdone(pg
, PING_PEERDIED
);
814 sym_remove(&byname
, p
->byname
);
815 am_remove(&byaddr
, p
->byaddr
);
819 /* --- @p_mkiter@ --- *
821 * Arguments: @peer_iter *i@ = pointer to an iterator
825 * Use: Initializes the iterator.
828 void p_mkiter(peer_iter
*i
) { sym_mkiter(&i
->i
, &byname
); }
830 /* --- @p_next@ --- *
832 * Arguments: @peer_iter *i@ = pointer to an iterator
834 * Returns: Next peer, or null if at the end.
836 * Use: Returns the next peer.
839 peer
*p_next(peer_iter
*i
)
843 if ((pn
= sym_next(&i
->i
)) == 0)
848 /*----- That's all, folks -------------------------------------------------*/