- bin2hex(hash,hash,SHA_DIGEST_LENGTH);
- hash[SHA_DIGEST_LENGTH*2] = '\0';
-
- /* Send the reply */
-
-cp
- return send_request(c, "%d %s", CHAL_REPLY, hash);
-}
-
-int chal_reply_h(connection_t *c)
-{
- char hishash[MAX_STRING_SIZE];
- char myhash[SHA_DIGEST_LENGTH];
-cp
- if(sscanf(c->buffer, "%*d "MAX_STRING, hishash) != 1)
- {
- syslog(LOG_ERR, _("Got bad %s from %s (%s)"), "CHAL_REPLY", c->name, c->hostname);
- return -1;
- }
-
- /* Check if the length of the hash is all right */
-
- if(strlen(hishash) != SHA_DIGEST_LENGTH*2)
- {
- syslog(LOG_ERR, _("Possible intruder %s (%s): %s"), c->name, c->hostname, _("wrong challenge reply length"));
- return -1;
- }
-
- /* Convert the hash to binary format */
-
- hex2bin(hishash, hishash, SHA_DIGEST_LENGTH);
-
- /* Calculate the hash from the challenge we sent */
-
- SHA1(c->hischallenge, RSA_size(c->rsa_key), myhash);
-
- /* Verify the incoming hash with the calculated hash */
-
- if(memcmp(hishash, myhash, SHA_DIGEST_LENGTH))
- {
- syslog(LOG_ERR, _("Possible intruder %s (%s): %s"), c->name, c->hostname, _("wrong challenge reply"));
- if(debug_lvl >= DEBUG_SCARY_THINGS)
- {
- bin2hex(myhash, hishash, SHA_DIGEST_LENGTH);
- hishash[SHA_DIGEST_LENGTH*2] = '\0';
- syslog(LOG_DEBUG, _("Expected challenge reply: %s"), hishash);
- }
- return -1;
- }
-
- /* Identity has now been positively verified.
- Send an acknowledgement with the rest of the information needed.
- */
-
- c->allow_request = ACK;
-cp
- return send_ack(c);
-}
-
-int send_ack(connection_t *c)
-{
- /* ACK message contains rest of the information the other end needs
- to create node_t and edge_t structures. */
-
- int x;
- char *addrstr;
- struct timeval now;
-cp
- /* Estimate weight */
-
- gettimeofday(&now, NULL);
- c->estimated_weight = (now.tv_sec - c->start.tv_sec) * 1000 + (now.tv_usec - c->start.tv_usec) / 1000;
- addrstr = address2str(c->address);
- x = send_request(c, "%d %hd %s %d %d", ACK, myself->port, addrstr, c->estimated_weight, c->options);
- free(addrstr);
-cp
- return x;
-}
-
-void send_everything(connection_t *c)
-{
- avl_node_t *node, *node2;
- node_t *n;
- subnet_t *s;
- edge_t *e;
-
- /* Send all known subnets */
-
- for(node = node_tree->head; node; node = node->next)
- {
- n = (node_t *)node->data;
-
- for(node2 = n->subnet_tree->head; node2; node2 = node2->next)
- {
- s = (subnet_t *)node2->data;
- send_add_subnet(c, s);
- }
- }
-
- /* Send all known edges */
-
- for(node = edge_tree->head; node; node = node->next)
- {
- e = (edge_t *)node->data;
-
- if(e == c->edge)
- continue;
-
- send_add_edge(c, e);
- }
-}
-
-int ack_h(connection_t *c)
-{
- port_t hisport;
- char addrstr[MAX_STRING_SIZE];
- int weight;
- int options;
- node_t *n;
- connection_t *other;
- avl_node_t *node;
-cp
- if(sscanf(c->buffer, "%*d %hd "MAX_STRING" %d %d", &hisport, addrstr, &weight, &options) != 4)
- {
- syslog(LOG_ERR, _("Got bad %s from %s (%s)"), "ACK", c->name, c->hostname);
- return -1;
- }
-
- /* Check if we already have a node_t for him */
-
- n = lookup_node(c->name);
-
- if(!n)
- {
- n = new_node();
- n->name = xstrdup(c->name);
- n->address = c->address;
- n->hostname = xstrdup(c->hostname);
- n->port = hisport;
-
- /* FIXME: Also check if no other tinc daemon uses the same IP and port for UDP traffic */
-
- node_add(n);
- }
- else
- {
- if(n->connection)
- {
- /* Oh dear, we already have a connection to this node. */
- if(debug_lvl >= DEBUG_CONNECTIONS)
- syslog(LOG_DEBUG, _("Established a second connection with %s (%s), closing old connection"), n->name, n->hostname);
- terminate_connection(n->connection, 0);
- }
-
- /* FIXME: check if information in existing node matches that of the other end of this connection */
- }
-
- n->connection = c;
- c->node = n;
- c->options |= options;
-
- /* Create an edge_t for this connection */
-
- c->edge = new_edge();
-
- c->edge->from.node = myself;
- c->edge->from.address = str2address(addrstr);
- c->edge->from.port = myself->port;
- c->edge->to.node = n;
- c->edge->to.address = c->address;
- c->edge->to.port = hisport;
- c->edge->weight = (weight + c->estimated_weight) / 2;
- c->edge->connection = c;
- c->edge->options = c->options;
-
- edge_add(c->edge);
-
- /* Activate this connection */
-
- c->allow_request = ALL;
- c->status.active = 1;
-
- if(debug_lvl >= DEBUG_CONNECTIONS)
- syslog(LOG_NOTICE, _("Connection with %s (%s) activated"), c->name, c->hostname);
-
-cp
- /* Send him everything we know */
-
- send_everything(c);
-
- /* Notify others of this connection */
-
- for(node = connection_tree->head; node; node = node->next)
- {
- other = (connection_t *)node->data;
-
- if(other->status.active && other != c)
- send_add_edge(other, c->edge);
- }
-
- /* Run MST and SSSP algorithms */
-
- graph();
-
- /* Succesful connection, reset timeout if this is an outgoing connection. */
-
- if(c->outgoing)
- c->outgoing->timeout = 0;
-cp
- return 0;